mbedtls.h 1.4 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773317743177531776317773177831779317803178131782317833178431785317863178731788317893179031791317923179331794317953179631797317983179931800318013180231803318043180531806318073180831809318103181131812318133181431815318163181731818318193182031821318223182331824318253182631827318283182931830318313183231833318343183531836318373183831839318403184131842318433184431845318463184731848318493185031851318523185331854318553185631857318583185931860318613186231863318643186531866318673186831869318703187131872318733187431875318763187731878318793188031881318823188331884318853188631887318883188931890318913189231893318943189531896318973189831899319003190131902319033190431905319063190731908319093191031911319123191331914319153191631917319183191931920319213192231923319243192531926319273192831929319303193131932319333193431935319363193731938319393194031941319423194331944319453194631947319483194931950319513195231953319543195531956319573195831959319603196131962319633196431965319663196731968319693197031971319723197331974319753197631977319783197931980319813198231983319843198531986319873198831989319903199131992319933199431995319963199731998319993200032001320023200332004320053200632007320083200932010320113201232013320143201532016320173201832019320203202132022320233202432025320263202732028320293203032031320323203332034320353203632037320383203932040320413204232043320443204532046320473204832049320503205132052320533205432055320563205732058320593206032061320623206332064320653206632067320683206932070320713207232073320743207532076320773207832079320803208132082320833208432085320863208732088320893209032091320923209332094320953209632097320983209932100321013210232103321043210532106321073210832109321103211132112321133211432115321163211732118321193212032121321223212332124321253212632127321283212932130321313213232133321343213532136321373213832139321403214132142321433214432145321463214732148321493215032151321523215332154321553215632157321583215932160321613216232163321643216532166321673216832169321703217132172321733217432175321763217732178321793218032181321823218332184321853218632187321883218932190321913219232193321943219532196321973219832199322003220132202322033220432205322063220732208322093221032211322123221332214322153221632217322183221932220322213222232223322243222532226322273222832229322303223132232322333223432235322363223732238322393224032241322423224332244322453224632247322483224932250322513225232253322543225532256322573225832259322603226132262322633226432265322663226732268322693227032271322723227332274322753227632277322783227932280322813228232283322843228532286322873228832289322903229132292322933229432295322963229732298322993230032301323023230332304323053230632307323083230932310323113231232313323143231532316323173231832319323203232132322323233232432325323263232732328323293233032331323323233332334323353233632337323383233932340323413234232343323443234532346323473234832349323503235132352323533235432355323563235732358323593236032361323623236332364323653236632367323683236932370323713237232373323743237532376323773237832379323803238132382323833238432385323863238732388323893239032391323923239332394323953239632397323983239932400324013240232403324043240532406324073240832409324103241132412324133241432415324163241732418324193242032421324223242332424324253242632427324283242932430324313243232433324343243532436324373243832439324403244132442324433244432445324463244732448324493245032451324523245332454324553245632457324583245932460324613246232463324643246532466324673246832469324703247132472324733247432475324763247732478324793248032481324823248332484324853248632487324883248932490324913249232493324943249532496324973249832499325003250132502325033250432505325063250732508325093251032511325123251332514325153251632517325183251932520325213252232523325243252532526325273252832529325303253132532325333253432535325363253732538325393254032541325423254332544325453254632547325483254932550325513255232553325543255532556325573255832559325603256132562325633256432565325663256732568325693257032571325723257332574325753257632577325783257932580325813258232583325843258532586325873258832589325903259132592325933259432595325963259732598325993260032601326023260332604326053260632607326083260932610326113261232613326143261532616326173261832619326203262132622326233262432625326263262732628326293263032631326323263332634326353263632637326383263932640326413264232643326443264532646326473264832649326503265132652326533265432655326563265732658326593266032661326623266332664326653266632667326683266932670326713267232673326743267532676326773267832679326803268132682326833268432685326863268732688326893269032691326923269332694326953269632697326983269932700327013270232703327043270532706327073270832709327103271132712327133271432715327163271732718327193272032721327223272332724327253272632727327283272932730327313273232733327343273532736327373273832739327403274132742327433274432745327463274732748327493275032751327523275332754327553275632757327583275932760327613276232763327643276532766327673276832769327703277132772327733277432775327763277732778327793278032781327823278332784327853278632787327883278932790327913279232793327943279532796327973279832799328003280132802328033280432805328063280732808328093281032811328123281332814328153281632817328183281932820328213282232823328243282532826328273282832829328303283132832328333283432835328363283732838328393284032841328423284332844328453284632847328483284932850328513285232853328543285532856328573285832859328603286132862328633286432865328663286732868328693287032871328723287332874328753287632877328783287932880328813288232883328843288532886328873288832889328903289132892328933289432895328963289732898328993290032901329023290332904329053290632907329083290932910329113291232913329143291532916329173291832919329203292132922329233292432925329263292732928329293293032931329323293332934329353293632937329383293932940329413294232943329443294532946329473294832949329503295132952329533295432955329563295732958329593296032961329623296332964329653296632967329683296932970329713297232973329743297532976329773297832979329803298132982329833298432985329863298732988329893299032991329923299332994329953299632997329983299933000330013300233003330043300533006330073300833009330103301133012330133301433015330163301733018330193302033021330223302333024330253302633027330283302933030330313303233033330343303533036330373303833039330403304133042330433304433045330463304733048330493305033051330523305333054330553305633057330583305933060330613306233063330643306533066330673306833069330703307133072330733307433075330763307733078330793308033081330823308333084330853308633087330883308933090330913309233093330943309533096330973309833099331003310133102331033310433105331063310733108331093311033111331123311333114331153311633117331183311933120331213312233123331243312533126331273312833129331303313133132331333313433135331363313733138331393314033141331423314333144331453314633147331483314933150331513315233153331543315533156331573315833159331603316133162331633316433165331663316733168331693317033171331723317333174331753317633177331783317933180331813318233183331843318533186331873318833189331903319133192331933319433195331963319733198331993320033201332023320333204332053320633207332083320933210332113321233213332143321533216332173321833219332203322133222332233322433225332263322733228332293323033231332323323333234332353323633237332383323933240332413324233243332443324533246332473324833249332503325133252332533325433255332563325733258332593326033261332623326333264332653326633267332683326933270332713327233273332743327533276332773327833279332803328133282332833328433285332863328733288332893329033291332923329333294332953329633297332983329933300333013330233303333043330533306333073330833309333103331133312333133331433315333163331733318333193332033321333223332333324333253332633327333283332933330333313333233333333343333533336333373333833339333403334133342333433334433345333463334733348333493335033351333523335333354333553335633357333583335933360333613336233363333643336533366333673336833369333703337133372333733337433375333763337733378333793338033381333823338333384333853338633387333883338933390333913339233393333943339533396333973339833399334003340133402334033340433405334063340733408334093341033411334123341333414334153341633417334183341933420334213342233423334243342533426334273342833429334303343133432334333343433435334363343733438334393344033441334423344333444334453344633447334483344933450334513345233453334543345533456334573345833459334603346133462334633346433465334663346733468334693347033471334723347333474334753347633477334783347933480334813348233483334843348533486334873348833489334903349133492334933349433495334963349733498334993350033501335023350333504335053350633507335083350933510335113351233513335143351533516335173351833519335203352133522335233352433525335263352733528335293353033531335323353333534335353353633537335383353933540335413354233543335443354533546335473354833549335503355133552335533355433555335563355733558335593356033561335623356333564335653356633567335683356933570335713357233573335743357533576335773357833579335803358133582335833358433585335863358733588335893359033591335923359333594335953359633597335983359933600336013360233603336043360533606336073360833609336103361133612336133361433615336163361733618336193362033621336223362333624336253362633627336283362933630336313363233633336343363533636336373363833639336403364133642336433364433645336463364733648336493365033651336523365333654336553365633657336583365933660336613366233663336643366533666336673366833669336703367133672336733367433675336763367733678336793368033681336823368333684336853368633687336883368933690336913369233693336943369533696336973369833699337003370133702337033370433705337063370733708337093371033711337123371333714337153371633717337183371933720337213372233723337243372533726337273372833729337303373133732337333373433735337363373733738337393374033741337423374333744337453374633747337483374933750337513375233753337543375533756337573375833759337603376133762337633376433765337663376733768337693377033771337723377333774337753377633777337783377933780337813378233783337843378533786337873378833789337903379133792337933379433795337963379733798337993380033801338023380333804338053380633807338083380933810338113381233813338143381533816338173381833819338203382133822338233382433825338263382733828338293383033831338323383333834338353383633837338383383933840338413384233843338443384533846338473384833849338503385133852338533385433855338563385733858338593386033861338623386333864338653386633867338683386933870338713387233873338743387533876338773387833879338803388133882338833388433885338863388733888338893389033891338923389333894338953389633897338983389933900339013390233903339043390533906339073390833909339103391133912339133391433915339163391733918339193392033921339223392333924339253392633927339283392933930339313393233933339343393533936339373393833939339403394133942339433394433945339463394733948339493395033951339523395333954339553395633957339583395933960339613396233963339643396533966339673396833969339703397133972339733397433975339763397733978339793398033981339823398333984339853398633987339883398933990339913399233993339943399533996339973399833999340003400134002340033400434005340063400734008340093401034011340123401334014340153401634017340183401934020340213402234023340243402534026340273402834029340303403134032340333403434035340363403734038340393404034041340423404334044340453404634047340483404934050340513405234053340543405534056340573405834059340603406134062340633406434065340663406734068340693407034071340723407334074340753407634077340783407934080340813408234083340843408534086340873408834089340903409134092340933409434095340963409734098340993410034101341023410334104341053410634107341083410934110341113411234113341143411534116341173411834119341203412134122341233412434125341263412734128341293413034131341323413334134341353413634137341383413934140341413414234143341443414534146341473414834149341503415134152341533415434155341563415734158341593416034161341623416334164341653416634167341683416934170341713417234173341743417534176341773417834179341803418134182341833418434185341863418734188341893419034191341923419334194341953419634197341983419934200342013420234203342043420534206342073420834209342103421134212342133421434215342163421734218342193422034221342223422334224342253422634227342283422934230342313423234233342343423534236342373423834239342403424134242342433424434245342463424734248342493425034251342523425334254342553425634257342583425934260342613426234263342643426534266342673426834269342703427134272342733427434275342763427734278342793428034281342823428334284342853428634287342883428934290342913429234293342943429534296342973429834299343003430134302343033430434305343063430734308343093431034311343123431334314343153431634317343183431934320343213432234323343243432534326343273432834329343303433134332343333433434335343363433734338343393434034341343423434334344343453434634347343483434934350343513435234353343543435534356343573435834359343603436134362343633436434365343663436734368343693437034371343723437334374343753437634377343783437934380343813438234383343843438534386343873438834389343903439134392343933439434395343963439734398343993440034401344023440334404344053440634407344083440934410344113441234413344143441534416344173441834419344203442134422344233442434425344263442734428344293443034431344323443334434344353443634437344383443934440344413444234443344443444534446344473444834449344503445134452344533445434455344563445734458344593446034461344623446334464344653446634467344683446934470344713447234473344743447534476344773447834479344803448134482344833448434485344863448734488344893449034491344923449334494344953449634497344983449934500345013450234503345043450534506345073450834509345103451134512345133451434515345163451734518345193452034521345223452334524345253452634527345283452934530345313453234533345343453534536345373453834539345403454134542345433454434545345463454734548345493455034551345523455334554345553455634557345583455934560345613456234563345643456534566345673456834569345703457134572345733457434575345763457734578345793458034581345823458334584345853458634587345883458934590345913459234593345943459534596345973459834599346003460134602346033460434605346063460734608346093461034611346123461334614346153461634617346183461934620346213462234623346243462534626346273462834629346303463134632346333463434635346363463734638346393464034641346423464334644346453464634647346483464934650346513465234653346543465534656346573465834659346603466134662346633466434665346663466734668346693467034671346723467334674346753467634677346783467934680346813468234683346843468534686346873468834689346903469134692346933469434695346963469734698346993470034701347023470334704347053470634707347083470934710347113471234713347143471534716347173471834719347203472134722347233472434725347263472734728347293473034731347323473334734347353473634737347383473934740347413474234743347443474534746347473474834749347503475134752347533475434755347563475734758347593476034761347623476334764347653476634767347683476934770347713477234773347743477534776347773477834779347803478134782347833478434785347863478734788347893479034791347923479334794347953479634797347983479934800348013480234803348043480534806348073480834809348103481134812348133481434815348163481734818348193482034821348223482334824348253482634827348283482934830348313483234833348343483534836348373483834839348403484134842348433484434845348463484734848348493485034851348523485334854348553485634857348583485934860348613486234863348643486534866348673486834869348703487134872348733487434875348763487734878348793488034881348823488334884348853488634887348883488934890348913489234893348943489534896348973489834899349003490134902349033490434905349063490734908349093491034911349123491334914349153491634917349183491934920349213492234923349243492534926349273492834929349303493134932349333493434935349363493734938349393494034941349423494334944349453494634947349483494934950349513495234953349543495534956349573495834959349603496134962349633496434965349663496734968349693497034971349723497334974349753497634977349783497934980349813498234983349843498534986349873498834989349903499134992349933499434995349963499734998349993500035001350023500335004350053500635007350083500935010350113501235013350143501535016350173501835019350203502135022350233502435025350263502735028350293503035031350323503335034350353503635037350383503935040350413504235043350443504535046350473504835049350503505135052350533505435055350563505735058350593506035061350623506335064350653506635067350683506935070350713507235073350743507535076350773507835079350803508135082350833508435085350863508735088350893509035091350923509335094350953509635097350983509935100351013510235103351043510535106351073510835109351103511135112351133511435115351163511735118351193512035121351223512335124351253512635127351283512935130351313513235133351343513535136351373513835139351403514135142351433514435145351463514735148351493515035151351523515335154351553515635157351583515935160351613516235163351643516535166351673516835169351703517135172351733517435175351763517735178351793518035181351823518335184351853518635187351883518935190351913519235193351943519535196351973519835199352003520135202352033520435205352063520735208352093521035211352123521335214352153521635217352183521935220352213522235223352243522535226352273522835229352303523135232352333523435235352363523735238352393524035241352423524335244352453524635247352483524935250352513525235253352543525535256352573525835259352603526135262352633526435265352663526735268352693527035271352723527335274352753527635277352783527935280352813528235283352843528535286352873528835289352903529135292352933529435295352963529735298352993530035301353023530335304353053530635307353083530935310353113531235313353143531535316353173531835319353203532135322353233532435325353263532735328353293533035331353323533335334353353533635337353383533935340353413534235343353443534535346353473534835349353503535135352353533535435355353563535735358353593536035361353623536335364353653536635367353683536935370353713537235373353743537535376353773537835379353803538135382353833538435385353863538735388353893539035391353923539335394353953539635397353983539935400354013540235403354043540535406354073540835409354103541135412354133541435415354163541735418354193542035421354223542335424354253542635427354283542935430354313543235433354343543535436354373543835439354403544135442354433544435445354463544735448354493545035451354523545335454354553545635457354583545935460354613546235463354643546535466354673546835469354703547135472354733547435475354763547735478354793548035481354823548335484354853548635487354883548935490354913549235493354943549535496354973549835499355003550135502355033550435505355063550735508355093551035511355123551335514355153551635517355183551935520355213552235523355243552535526355273552835529355303553135532355333553435535355363553735538355393554035541355423554335544355453554635547355483554935550355513555235553355543555535556355573555835559355603556135562355633556435565355663556735568355693557035571355723557335574355753557635577355783557935580355813558235583355843558535586355873558835589355903559135592355933559435595355963559735598355993560035601356023560335604356053560635607356083560935610356113561235613356143561535616356173561835619356203562135622356233562435625356263562735628356293563035631356323563335634356353563635637356383563935640356413564235643356443564535646356473564835649356503565135652356533565435655356563565735658356593566035661356623566335664356653566635667356683566935670356713567235673356743567535676356773567835679356803568135682356833568435685356863568735688356893569035691356923569335694356953569635697356983569935700357013570235703357043570535706357073570835709357103571135712357133571435715357163571735718357193572035721357223572335724357253572635727357283572935730357313573235733357343573535736357373573835739357403574135742357433574435745357463574735748357493575035751357523575335754357553575635757357583575935760357613576235763357643576535766357673576835769357703577135772357733577435775357763577735778357793578035781357823578335784357853578635787357883578935790357913579235793357943579535796357973579835799358003580135802358033580435805358063580735808358093581035811358123581335814358153581635817358183581935820358213582235823358243582535826358273582835829358303583135832358333583435835358363583735838358393584035841358423584335844358453584635847358483584935850358513585235853358543585535856358573585835859358603586135862358633586435865358663586735868358693587035871358723587335874358753587635877358783587935880358813588235883358843588535886358873588835889358903589135892358933589435895358963589735898358993590035901359023590335904359053590635907359083590935910359113591235913359143591535916359173591835919359203592135922359233592435925359263592735928359293593035931359323593335934359353593635937359383593935940359413594235943359443594535946359473594835949359503595135952359533595435955359563595735958359593596035961359623596335964359653596635967359683596935970359713597235973359743597535976359773597835979359803598135982359833598435985359863598735988359893599035991359923599335994359953599635997359983599936000360013600236003360043600536006360073600836009360103601136012360133601436015360163601736018360193602036021360223602336024360253602636027360283602936030360313603236033360343603536036360373603836039360403604136042360433604436045360463604736048360493605036051360523605336054360553605636057360583605936060360613606236063360643606536066360673606836069360703607136072360733607436075360763607736078360793608036081360823608336084360853608636087360883608936090360913609236093360943609536096360973609836099361003610136102361033610436105361063610736108361093611036111361123611336114361153611636117361183611936120361213612236123361243612536126361273612836129361303613136132361333613436135361363613736138361393614036141361423614336144361453614636147361483614936150361513615236153361543615536156361573615836159361603616136162361633616436165361663616736168361693617036171361723617336174361753617636177361783617936180361813618236183361843618536186361873618836189361903619136192361933619436195361963619736198361993620036201362023620336204362053620636207362083620936210362113621236213362143621536216362173621836219362203622136222362233622436225362263622736228362293623036231362323623336234362353623636237362383623936240362413624236243362443624536246362473624836249362503625136252362533625436255362563625736258362593626036261362623626336264362653626636267362683626936270362713627236273362743627536276362773627836279362803628136282362833628436285362863628736288362893629036291362923629336294362953629636297362983629936300363013630236303363043630536306363073630836309363103631136312363133631436315363163631736318363193632036321363223632336324363253632636327363283632936330363313633236333363343633536336363373633836339363403634136342363433634436345363463634736348363493635036351363523635336354363553635636357363583635936360363613636236363363643636536366363673636836369363703637136372363733637436375363763637736378363793638036381363823638336384363853638636387363883638936390363913639236393363943639536396363973639836399364003640136402364033640436405364063640736408364093641036411364123641336414364153641636417364183641936420364213642236423364243642536426364273642836429364303643136432364333643436435364363643736438364393644036441364423644336444364453644636447364483644936450364513645236453364543645536456364573645836459364603646136462364633646436465364663646736468364693647036471364723647336474364753647636477364783647936480364813648236483364843648536486364873648836489364903649136492364933649436495364963649736498364993650036501365023650336504365053650636507365083650936510365113651236513365143651536516365173651836519365203652136522365233652436525365263652736528365293653036531365323653336534365353653636537365383653936540365413654236543365443654536546365473654836549365503655136552365533655436555365563655736558365593656036561365623656336564365653656636567365683656936570365713657236573365743657536576365773657836579365803658136582365833658436585365863658736588365893659036591365923659336594365953659636597365983659936600366013660236603366043660536606366073660836609366103661136612366133661436615366163661736618366193662036621366223662336624366253662636627366283662936630366313663236633366343663536636366373663836639366403664136642366433664436645366463664736648366493665036651366523665336654366553665636657366583665936660366613666236663366643666536666366673666836669366703667136672366733667436675366763667736678366793668036681366823668336684366853668636687366883668936690366913669236693366943669536696366973669836699367003670136702367033670436705367063670736708367093671036711367123671336714367153671636717367183671936720367213672236723367243672536726367273672836729367303673136732367333673436735367363673736738367393674036741367423674336744367453674636747367483674936750367513675236753367543675536756367573675836759367603676136762367633676436765367663676736768367693677036771367723677336774367753677636777367783677936780367813678236783367843678536786367873678836789367903679136792367933679436795367963679736798367993680036801368023680336804368053680636807368083680936810368113681236813368143681536816368173681836819368203682136822368233682436825368263682736828368293683036831368323683336834368353683636837368383683936840368413684236843
  1. /*
  2. * MbedTLS Source Code Library Header
  3. */
  4. #include "me.h"
  5. #if ME_COM_MBEDTLS
  6. #if defined(MBEDTLS_CONFIG_FILE)
  7. #include MBEDTLS_CONFIG_FILE
  8. #endif
  9. /********* Start of file library/common.h ************/
  10. /**
  11. * \file common.h
  12. *
  13. * \brief Utility macros for internal use in the library
  14. */
  15. /*
  16. * Copyright The Mbed TLS Contributors
  17. * SPDX-License-Identifier: Apache-2.0
  18. *
  19. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  20. * not use this file except in compliance with the License.
  21. * You may obtain a copy of the License at
  22. *
  23. * http://www.apache.org/licenses/LICENSE-2.0
  24. *
  25. * Unless required by applicable law or agreed to in writing, software
  26. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  27. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  28. * See the License for the specific language governing permissions and
  29. * limitations under the License.
  30. */
  31. #ifndef MBEDTLS_LIBRARY_COMMON_H
  32. #define MBEDTLS_LIBRARY_COMMON_H
  33. #if defined(MBEDTLS_CONFIG_FILE)
  34. #else
  35. #endif
  36. #include <stdint.h>
  37. /** Helper to define a function as static except when building invasive tests.
  38. *
  39. * If a function is only used inside its own source file and should be
  40. * declared `static` to allow the compiler to optimize for code size,
  41. * but that function has unit tests, define it with
  42. * ```
  43. * MBEDTLS_STATIC_TESTABLE int mbedtls_foo(...) { ... }
  44. * ```
  45. * and declare it in a header in the `library/` directory with
  46. * ```
  47. * #if defined(MBEDTLS_TEST_HOOKS)
  48. * int mbedtls_foo(...);
  49. * #endif
  50. * ```
  51. */
  52. #if defined(MBEDTLS_TEST_HOOKS)
  53. #define MBEDTLS_STATIC_TESTABLE
  54. #else
  55. #define MBEDTLS_STATIC_TESTABLE static
  56. #endif
  57. /** Byte Reading Macros
  58. *
  59. * Given a multi-byte integer \p x, MBEDTLS_BYTE_n retrieves the n-th
  60. * byte from x, where byte 0 is the least significant byte.
  61. */
  62. #define MBEDTLS_BYTE_0( x ) ( (uint8_t) ( ( x ) & 0xff ) )
  63. #define MBEDTLS_BYTE_1( x ) ( (uint8_t) ( ( ( x ) >> 8 ) & 0xff ) )
  64. #define MBEDTLS_BYTE_2( x ) ( (uint8_t) ( ( ( x ) >> 16 ) & 0xff ) )
  65. #define MBEDTLS_BYTE_3( x ) ( (uint8_t) ( ( ( x ) >> 24 ) & 0xff ) )
  66. #define MBEDTLS_BYTE_4( x ) ( (uint8_t) ( ( ( x ) >> 32 ) & 0xff ) )
  67. #define MBEDTLS_BYTE_5( x ) ( (uint8_t) ( ( ( x ) >> 40 ) & 0xff ) )
  68. #define MBEDTLS_BYTE_6( x ) ( (uint8_t) ( ( ( x ) >> 48 ) & 0xff ) )
  69. #define MBEDTLS_BYTE_7( x ) ( (uint8_t) ( ( ( x ) >> 56 ) & 0xff ) )
  70. /**
  71. * Get the unsigned 32 bits integer corresponding to four bytes in
  72. * big-endian order (MSB first).
  73. *
  74. * \param data Base address of the memory to get the four bytes from.
  75. * \param offset Offset from \p base of the first and most significant
  76. * byte of the four bytes to build the 32 bits unsigned
  77. * integer from.
  78. */
  79. #ifndef MBEDTLS_GET_UINT32_BE
  80. #define MBEDTLS_GET_UINT32_BE( data , offset ) \
  81. ( \
  82. ( (uint32_t) ( data )[( offset ) ] << 24 ) \
  83. | ( (uint32_t) ( data )[( offset ) + 1] << 16 ) \
  84. | ( (uint32_t) ( data )[( offset ) + 2] << 8 ) \
  85. | ( (uint32_t) ( data )[( offset ) + 3] ) \
  86. )
  87. #endif
  88. /**
  89. * Put in memory a 32 bits unsigned integer in big-endian order.
  90. *
  91. * \param n 32 bits unsigned integer to put in memory.
  92. * \param data Base address of the memory where to put the 32
  93. * bits unsigned integer in.
  94. * \param offset Offset from \p base where to put the most significant
  95. * byte of the 32 bits unsigned integer \p n.
  96. */
  97. #ifndef MBEDTLS_PUT_UINT32_BE
  98. #define MBEDTLS_PUT_UINT32_BE( n, data, offset ) \
  99. { \
  100. ( data )[( offset ) ] = MBEDTLS_BYTE_3( n ); \
  101. ( data )[( offset ) + 1] = MBEDTLS_BYTE_2( n ); \
  102. ( data )[( offset ) + 2] = MBEDTLS_BYTE_1( n ); \
  103. ( data )[( offset ) + 3] = MBEDTLS_BYTE_0( n ); \
  104. }
  105. #endif
  106. /**
  107. * Get the unsigned 32 bits integer corresponding to four bytes in
  108. * little-endian order (LSB first).
  109. *
  110. * \param data Base address of the memory to get the four bytes from.
  111. * \param offset Offset from \p base of the first and least significant
  112. * byte of the four bytes to build the 32 bits unsigned
  113. * integer from.
  114. */
  115. #ifndef MBEDTLS_GET_UINT32_LE
  116. #define MBEDTLS_GET_UINT32_LE( data, offset ) \
  117. ( \
  118. ( (uint32_t) ( data )[( offset ) ] ) \
  119. | ( (uint32_t) ( data )[( offset ) + 1] << 8 ) \
  120. | ( (uint32_t) ( data )[( offset ) + 2] << 16 ) \
  121. | ( (uint32_t) ( data )[( offset ) + 3] << 24 ) \
  122. )
  123. #endif
  124. /**
  125. * Put in memory a 32 bits unsigned integer in little-endian order.
  126. *
  127. * \param n 32 bits unsigned integer to put in memory.
  128. * \param data Base address of the memory where to put the 32
  129. * bits unsigned integer in.
  130. * \param offset Offset from \p base where to put the least significant
  131. * byte of the 32 bits unsigned integer \p n.
  132. */
  133. #ifndef MBEDTLS_PUT_UINT32_LE
  134. #define MBEDTLS_PUT_UINT32_LE( n, data, offset ) \
  135. { \
  136. ( data )[( offset ) ] = MBEDTLS_BYTE_0( n ); \
  137. ( data )[( offset ) + 1] = MBEDTLS_BYTE_1( n ); \
  138. ( data )[( offset ) + 2] = MBEDTLS_BYTE_2( n ); \
  139. ( data )[( offset ) + 3] = MBEDTLS_BYTE_3( n ); \
  140. }
  141. #endif
  142. /**
  143. * Get the unsigned 16 bits integer corresponding to two bytes in
  144. * little-endian order (LSB first).
  145. *
  146. * \param data Base address of the memory to get the two bytes from.
  147. * \param offset Offset from \p base of the first and least significant
  148. * byte of the two bytes to build the 16 bits unsigned
  149. * integer from.
  150. */
  151. #ifndef MBEDTLS_GET_UINT16_LE
  152. #define MBEDTLS_GET_UINT16_LE( data, offset ) \
  153. ( \
  154. ( (uint16_t) ( data )[( offset ) ] ) \
  155. | ( (uint16_t) ( data )[( offset ) + 1] << 8 ) \
  156. )
  157. #endif
  158. /**
  159. * Put in memory a 16 bits unsigned integer in little-endian order.
  160. *
  161. * \param n 16 bits unsigned integer to put in memory.
  162. * \param data Base address of the memory where to put the 16
  163. * bits unsigned integer in.
  164. * \param offset Offset from \p base where to put the least significant
  165. * byte of the 16 bits unsigned integer \p n.
  166. */
  167. #ifndef MBEDTLS_PUT_UINT16_LE
  168. #define MBEDTLS_PUT_UINT16_LE( n, data, offset ) \
  169. { \
  170. ( data )[( offset ) ] = MBEDTLS_BYTE_0( n ); \
  171. ( data )[( offset ) + 1] = MBEDTLS_BYTE_1( n ); \
  172. }
  173. #endif
  174. /**
  175. * Get the unsigned 16 bits integer corresponding to two bytes in
  176. * big-endian order (MSB first).
  177. *
  178. * \param data Base address of the memory to get the two bytes from.
  179. * \param offset Offset from \p base of the first and most significant
  180. * byte of the two bytes to build the 16 bits unsigned
  181. * integer from.
  182. */
  183. #ifndef MBEDTLS_GET_UINT16_BE
  184. #define MBEDTLS_GET_UINT16_BE( data, offset ) \
  185. ( \
  186. ( (uint16_t) ( data )[( offset ) ] << 8 ) \
  187. | ( (uint16_t) ( data )[( offset ) + 1] ) \
  188. )
  189. #endif
  190. /**
  191. * Put in memory a 16 bits unsigned integer in big-endian order.
  192. *
  193. * \param n 16 bits unsigned integer to put in memory.
  194. * \param data Base address of the memory where to put the 16
  195. * bits unsigned integer in.
  196. * \param offset Offset from \p base where to put the most significant
  197. * byte of the 16 bits unsigned integer \p n.
  198. */
  199. #ifndef MBEDTLS_PUT_UINT16_BE
  200. #define MBEDTLS_PUT_UINT16_BE( n, data, offset ) \
  201. { \
  202. ( data )[( offset ) ] = MBEDTLS_BYTE_1( n ); \
  203. ( data )[( offset ) + 1] = MBEDTLS_BYTE_0( n ); \
  204. }
  205. #endif
  206. /**
  207. * Get the unsigned 64 bits integer corresponding to eight bytes in
  208. * big-endian order (MSB first).
  209. *
  210. * \param data Base address of the memory to get the eight bytes from.
  211. * \param offset Offset from \p base of the first and most significant
  212. * byte of the eight bytes to build the 64 bits unsigned
  213. * integer from.
  214. */
  215. #ifndef MBEDTLS_GET_UINT64_BE
  216. #define MBEDTLS_GET_UINT64_BE( data, offset ) \
  217. ( \
  218. ( (uint64_t) ( data )[( offset ) ] << 56 ) \
  219. | ( (uint64_t) ( data )[( offset ) + 1] << 48 ) \
  220. | ( (uint64_t) ( data )[( offset ) + 2] << 40 ) \
  221. | ( (uint64_t) ( data )[( offset ) + 3] << 32 ) \
  222. | ( (uint64_t) ( data )[( offset ) + 4] << 24 ) \
  223. | ( (uint64_t) ( data )[( offset ) + 5] << 16 ) \
  224. | ( (uint64_t) ( data )[( offset ) + 6] << 8 ) \
  225. | ( (uint64_t) ( data )[( offset ) + 7] ) \
  226. )
  227. #endif
  228. /**
  229. * Put in memory a 64 bits unsigned integer in big-endian order.
  230. *
  231. * \param n 64 bits unsigned integer to put in memory.
  232. * \param data Base address of the memory where to put the 64
  233. * bits unsigned integer in.
  234. * \param offset Offset from \p base where to put the most significant
  235. * byte of the 64 bits unsigned integer \p n.
  236. */
  237. #ifndef MBEDTLS_PUT_UINT64_BE
  238. #define MBEDTLS_PUT_UINT64_BE( n, data, offset ) \
  239. { \
  240. ( data )[( offset ) ] = MBEDTLS_BYTE_7( n ); \
  241. ( data )[( offset ) + 1] = MBEDTLS_BYTE_6( n ); \
  242. ( data )[( offset ) + 2] = MBEDTLS_BYTE_5( n ); \
  243. ( data )[( offset ) + 3] = MBEDTLS_BYTE_4( n ); \
  244. ( data )[( offset ) + 4] = MBEDTLS_BYTE_3( n ); \
  245. ( data )[( offset ) + 5] = MBEDTLS_BYTE_2( n ); \
  246. ( data )[( offset ) + 6] = MBEDTLS_BYTE_1( n ); \
  247. ( data )[( offset ) + 7] = MBEDTLS_BYTE_0( n ); \
  248. }
  249. #endif
  250. /**
  251. * Get the unsigned 64 bits integer corresponding to eight bytes in
  252. * little-endian order (LSB first).
  253. *
  254. * \param data Base address of the memory to get the eight bytes from.
  255. * \param offset Offset from \p base of the first and least significant
  256. * byte of the eight bytes to build the 64 bits unsigned
  257. * integer from.
  258. */
  259. #ifndef MBEDTLS_GET_UINT64_LE
  260. #define MBEDTLS_GET_UINT64_LE( data, offset ) \
  261. ( \
  262. ( (uint64_t) ( data )[( offset ) + 7] << 56 ) \
  263. | ( (uint64_t) ( data )[( offset ) + 6] << 48 ) \
  264. | ( (uint64_t) ( data )[( offset ) + 5] << 40 ) \
  265. | ( (uint64_t) ( data )[( offset ) + 4] << 32 ) \
  266. | ( (uint64_t) ( data )[( offset ) + 3] << 24 ) \
  267. | ( (uint64_t) ( data )[( offset ) + 2] << 16 ) \
  268. | ( (uint64_t) ( data )[( offset ) + 1] << 8 ) \
  269. | ( (uint64_t) ( data )[( offset ) ] ) \
  270. )
  271. #endif
  272. /**
  273. * Put in memory a 64 bits unsigned integer in little-endian order.
  274. *
  275. * \param n 64 bits unsigned integer to put in memory.
  276. * \param data Base address of the memory where to put the 64
  277. * bits unsigned integer in.
  278. * \param offset Offset from \p base where to put the least significant
  279. * byte of the 64 bits unsigned integer \p n.
  280. */
  281. #ifndef MBEDTLS_PUT_UINT64_LE
  282. #define MBEDTLS_PUT_UINT64_LE( n, data, offset ) \
  283. { \
  284. ( data )[( offset ) ] = MBEDTLS_BYTE_0( n ); \
  285. ( data )[( offset ) + 1] = MBEDTLS_BYTE_1( n ); \
  286. ( data )[( offset ) + 2] = MBEDTLS_BYTE_2( n ); \
  287. ( data )[( offset ) + 3] = MBEDTLS_BYTE_3( n ); \
  288. ( data )[( offset ) + 4] = MBEDTLS_BYTE_4( n ); \
  289. ( data )[( offset ) + 5] = MBEDTLS_BYTE_5( n ); \
  290. ( data )[( offset ) + 6] = MBEDTLS_BYTE_6( n ); \
  291. ( data )[( offset ) + 7] = MBEDTLS_BYTE_7( n ); \
  292. }
  293. #endif
  294. #endif /* MBEDTLS_LIBRARY_COMMON_H */
  295. /********* Start of file include/mbedtls/config.h ************/
  296. /**
  297. * \file config.h
  298. *
  299. * \brief Configuration options (set of defines)
  300. *
  301. * This set of compile-time options may be used to enable
  302. * or disable features selectively, and reduce the global
  303. * memory footprint.
  304. */
  305. /*
  306. * Copyright The Mbed TLS Contributors
  307. * SPDX-License-Identifier: Apache-2.0
  308. *
  309. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  310. * not use this file except in compliance with the License.
  311. * You may obtain a copy of the License at
  312. *
  313. * http://www.apache.org/licenses/LICENSE-2.0
  314. *
  315. * Unless required by applicable law or agreed to in writing, software
  316. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  317. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  318. * See the License for the specific language governing permissions and
  319. * limitations under the License.
  320. */
  321. #ifndef MBEDTLS_CONFIG_H
  322. #define MBEDTLS_CONFIG_H
  323. #if defined(_MSC_VER) && !defined(_CRT_SECURE_NO_DEPRECATE)
  324. #define _CRT_SECURE_NO_DEPRECATE 1
  325. #endif
  326. /**
  327. * \name SECTION: System support
  328. *
  329. * This section sets system specific settings.
  330. * \{
  331. */
  332. /**
  333. * \def MBEDTLS_HAVE_ASM
  334. *
  335. * The compiler has support for asm().
  336. *
  337. * Requires support for asm() in compiler.
  338. *
  339. * Used in:
  340. * library/aria.c
  341. * library/timing.c
  342. * include/mbedtls/bn_mul.h
  343. *
  344. * Required by:
  345. * MBEDTLS_AESNI_C
  346. * MBEDTLS_PADLOCK_C
  347. *
  348. * Comment to disable the use of assembly code.
  349. */
  350. #define MBEDTLS_HAVE_ASM
  351. /**
  352. * \def MBEDTLS_NO_UDBL_DIVISION
  353. *
  354. * The platform lacks support for double-width integer division (64-bit
  355. * division on a 32-bit platform, 128-bit division on a 64-bit platform).
  356. *
  357. * Used in:
  358. * include/mbedtls/bignum.h
  359. * library/bignum.c
  360. *
  361. * The bignum code uses double-width division to speed up some operations.
  362. * Double-width division is often implemented in software that needs to
  363. * be linked with the program. The presence of a double-width integer
  364. * type is usually detected automatically through preprocessor macros,
  365. * but the automatic detection cannot know whether the code needs to
  366. * and can be linked with an implementation of division for that type.
  367. * By default division is assumed to be usable if the type is present.
  368. * Uncomment this option to prevent the use of double-width division.
  369. *
  370. * Note that division for the native integer type is always required.
  371. * Furthermore, a 64-bit type is always required even on a 32-bit
  372. * platform, but it need not support multiplication or division. In some
  373. * cases it is also desirable to disable some double-width operations. For
  374. * example, if double-width division is implemented in software, disabling
  375. * it can reduce code size in some embedded targets.
  376. */
  377. //#define MBEDTLS_NO_UDBL_DIVISION
  378. /**
  379. * \def MBEDTLS_NO_64BIT_MULTIPLICATION
  380. *
  381. * The platform lacks support for 32x32 -> 64-bit multiplication.
  382. *
  383. * Used in:
  384. * library/poly1305.c
  385. *
  386. * Some parts of the library may use multiplication of two unsigned 32-bit
  387. * operands with a 64-bit result in order to speed up computations. On some
  388. * platforms, this is not available in hardware and has to be implemented in
  389. * software, usually in a library provided by the toolchain.
  390. *
  391. * Sometimes it is not desirable to have to link to that library. This option
  392. * removes the dependency of that library on platforms that lack a hardware
  393. * 64-bit multiplier by embedding a software implementation in Mbed TLS.
  394. *
  395. * Note that depending on the compiler, this may decrease performance compared
  396. * to using the library function provided by the toolchain.
  397. */
  398. //#define MBEDTLS_NO_64BIT_MULTIPLICATION
  399. /**
  400. * \def MBEDTLS_HAVE_SSE2
  401. *
  402. * CPU supports SSE2 instruction set.
  403. *
  404. * Uncomment if the CPU supports SSE2 (IA-32 specific).
  405. */
  406. //#define MBEDTLS_HAVE_SSE2
  407. /**
  408. * \def MBEDTLS_HAVE_TIME
  409. *
  410. * System has time.h and time().
  411. * The time does not need to be correct, only time differences are used,
  412. * by contrast with MBEDTLS_HAVE_TIME_DATE
  413. *
  414. * Defining MBEDTLS_HAVE_TIME allows you to specify MBEDTLS_PLATFORM_TIME_ALT,
  415. * MBEDTLS_PLATFORM_TIME_MACRO, MBEDTLS_PLATFORM_TIME_TYPE_MACRO and
  416. * MBEDTLS_PLATFORM_STD_TIME.
  417. *
  418. * Comment if your system does not support time functions
  419. */
  420. #define MBEDTLS_HAVE_TIME
  421. /**
  422. * \def MBEDTLS_HAVE_TIME_DATE
  423. *
  424. * System has time.h, time(), and an implementation for
  425. * mbedtls_platform_gmtime_r() (see below).
  426. * The time needs to be correct (not necessarily very accurate, but at least
  427. * the date should be correct). This is used to verify the validity period of
  428. * X.509 certificates.
  429. *
  430. * Comment if your system does not have a correct clock.
  431. *
  432. * \note mbedtls_platform_gmtime_r() is an abstraction in platform_util.h that
  433. * behaves similarly to the gmtime_r() function from the C standard. Refer to
  434. * the documentation for mbedtls_platform_gmtime_r() for more information.
  435. *
  436. * \note It is possible to configure an implementation for
  437. * mbedtls_platform_gmtime_r() at compile-time by using the macro
  438. * MBEDTLS_PLATFORM_GMTIME_R_ALT.
  439. */
  440. #define MBEDTLS_HAVE_TIME_DATE
  441. /**
  442. * \def MBEDTLS_PLATFORM_MEMORY
  443. *
  444. * Enable the memory allocation layer.
  445. *
  446. * By default mbed TLS uses the system-provided calloc() and free().
  447. * This allows different allocators (self-implemented or provided) to be
  448. * provided to the platform abstraction layer.
  449. *
  450. * Enabling MBEDTLS_PLATFORM_MEMORY without the
  451. * MBEDTLS_PLATFORM_{FREE,CALLOC}_MACROs will provide
  452. * "mbedtls_platform_set_calloc_free()" allowing you to set an alternative calloc() and
  453. * free() function pointer at runtime.
  454. *
  455. * Enabling MBEDTLS_PLATFORM_MEMORY and specifying
  456. * MBEDTLS_PLATFORM_{CALLOC,FREE}_MACROs will allow you to specify the
  457. * alternate function at compile time.
  458. *
  459. * Requires: MBEDTLS_PLATFORM_C
  460. *
  461. * Enable this layer to allow use of alternative memory allocators.
  462. */
  463. //#define MBEDTLS_PLATFORM_MEMORY
  464. /**
  465. * \def MBEDTLS_PLATFORM_NO_STD_FUNCTIONS
  466. *
  467. * Do not assign standard functions in the platform layer (e.g. calloc() to
  468. * MBEDTLS_PLATFORM_STD_CALLOC and printf() to MBEDTLS_PLATFORM_STD_PRINTF)
  469. *
  470. * This makes sure there are no linking errors on platforms that do not support
  471. * these functions. You will HAVE to provide alternatives, either at runtime
  472. * via the platform_set_xxx() functions or at compile time by setting
  473. * the MBEDTLS_PLATFORM_STD_XXX defines, or enabling a
  474. * MBEDTLS_PLATFORM_XXX_MACRO.
  475. *
  476. * Requires: MBEDTLS_PLATFORM_C
  477. *
  478. * Uncomment to prevent default assignment of standard functions in the
  479. * platform layer.
  480. */
  481. //#define MBEDTLS_PLATFORM_NO_STD_FUNCTIONS
  482. /**
  483. * \def MBEDTLS_PLATFORM_EXIT_ALT
  484. *
  485. * MBEDTLS_PLATFORM_XXX_ALT: Uncomment a macro to let mbed TLS support the
  486. * function in the platform abstraction layer.
  487. *
  488. * Example: In case you uncomment MBEDTLS_PLATFORM_PRINTF_ALT, mbed TLS will
  489. * provide a function "mbedtls_platform_set_printf()" that allows you to set an
  490. * alternative printf function pointer.
  491. *
  492. * All these define require MBEDTLS_PLATFORM_C to be defined!
  493. *
  494. * \note MBEDTLS_PLATFORM_SNPRINTF_ALT is required on Windows;
  495. * it will be enabled automatically by check_config.h
  496. *
  497. * \warning MBEDTLS_PLATFORM_XXX_ALT cannot be defined at the same time as
  498. * MBEDTLS_PLATFORM_XXX_MACRO!
  499. *
  500. * Requires: MBEDTLS_PLATFORM_TIME_ALT requires MBEDTLS_HAVE_TIME
  501. *
  502. * Uncomment a macro to enable alternate implementation of specific base
  503. * platform function
  504. */
  505. //#define MBEDTLS_PLATFORM_EXIT_ALT
  506. //#define MBEDTLS_PLATFORM_TIME_ALT
  507. //#define MBEDTLS_PLATFORM_FPRINTF_ALT
  508. //#define MBEDTLS_PLATFORM_PRINTF_ALT
  509. //#define MBEDTLS_PLATFORM_SNPRINTF_ALT
  510. //#define MBEDTLS_PLATFORM_VSNPRINTF_ALT
  511. //#define MBEDTLS_PLATFORM_NV_SEED_ALT
  512. //#define MBEDTLS_PLATFORM_SETUP_TEARDOWN_ALT
  513. /**
  514. * \def MBEDTLS_DEPRECATED_WARNING
  515. *
  516. * Mark deprecated functions and features so that they generate a warning if
  517. * used. Functionality deprecated in one version will usually be removed in the
  518. * next version. You can enable this to help you prepare the transition to a
  519. * new major version by making sure your code is not using this functionality.
  520. *
  521. * This only works with GCC and Clang. With other compilers, you may want to
  522. * use MBEDTLS_DEPRECATED_REMOVED
  523. *
  524. * Uncomment to get warnings on using deprecated functions and features.
  525. */
  526. //#define MBEDTLS_DEPRECATED_WARNING
  527. /**
  528. * \def MBEDTLS_DEPRECATED_REMOVED
  529. *
  530. * Remove deprecated functions and features so that they generate an error if
  531. * used. Functionality deprecated in one version will usually be removed in the
  532. * next version. You can enable this to help you prepare the transition to a
  533. * new major version by making sure your code is not using this functionality.
  534. *
  535. * Uncomment to get errors on using deprecated functions and features.
  536. */
  537. //#define MBEDTLS_DEPRECATED_REMOVED
  538. /**
  539. * \def MBEDTLS_CHECK_PARAMS
  540. *
  541. * This configuration option controls whether the library validates more of
  542. * the parameters passed to it.
  543. *
  544. * When this flag is not defined, the library only attempts to validate an
  545. * input parameter if: (1) they may come from the outside world (such as the
  546. * network, the filesystem, etc.) or (2) not validating them could result in
  547. * internal memory errors such as overflowing a buffer controlled by the
  548. * library. On the other hand, it doesn't attempt to validate parameters whose
  549. * values are fully controlled by the application (such as pointers).
  550. *
  551. * When this flag is defined, the library additionally attempts to validate
  552. * parameters that are fully controlled by the application, and should always
  553. * be valid if the application code is fully correct and trusted.
  554. *
  555. * For example, when a function accepts as input a pointer to a buffer that may
  556. * contain untrusted data, and its documentation mentions that this pointer
  557. * must not be NULL:
  558. * - The pointer is checked to be non-NULL only if this option is enabled.
  559. * - The content of the buffer is always validated.
  560. *
  561. * When this flag is defined, if a library function receives a parameter that
  562. * is invalid:
  563. * 1. The function will invoke the macro MBEDTLS_PARAM_FAILED().
  564. * 2. If MBEDTLS_PARAM_FAILED() did not terminate the program, the function
  565. * will immediately return. If the function returns an Mbed TLS error code,
  566. * the error code in this case is MBEDTLS_ERR_xxx_BAD_INPUT_DATA.
  567. *
  568. * When defining this flag, you also need to arrange a definition for
  569. * MBEDTLS_PARAM_FAILED(). You can do this by any of the following methods:
  570. * - By default, the library defines MBEDTLS_PARAM_FAILED() to call a
  571. * function mbedtls_param_failed(), but the library does not define this
  572. * function. If you do not make any other arrangements, you must provide
  573. * the function mbedtls_param_failed() in your application.
  574. * See `platform_util.h` for its prototype.
  575. * - If you enable the macro #MBEDTLS_CHECK_PARAMS_ASSERT, then the
  576. * library defines MBEDTLS_PARAM_FAILED(\c cond) to be `assert(cond)`.
  577. * You can still supply an alternative definition of
  578. * MBEDTLS_PARAM_FAILED(), which may call `assert`.
  579. * - If you define a macro MBEDTLS_PARAM_FAILED() before including `config.h`
  580. * or you uncomment the definition of MBEDTLS_PARAM_FAILED() in `config.h`,
  581. * the library will call the macro that you defined and will not supply
  582. * its own version. Note that if MBEDTLS_PARAM_FAILED() calls `assert`,
  583. * you need to enable #MBEDTLS_CHECK_PARAMS_ASSERT so that library source
  584. * files include `<assert.h>`.
  585. *
  586. * Uncomment to enable validation of application-controlled parameters.
  587. */
  588. //#define MBEDTLS_CHECK_PARAMS
  589. /**
  590. * \def MBEDTLS_CHECK_PARAMS_ASSERT
  591. *
  592. * Allow MBEDTLS_PARAM_FAILED() to call `assert`, and make it default to
  593. * `assert`. This macro is only used if #MBEDTLS_CHECK_PARAMS is defined.
  594. *
  595. * If this macro is not defined, then MBEDTLS_PARAM_FAILED() defaults to
  596. * calling a function mbedtls_param_failed(). See the documentation of
  597. * #MBEDTLS_CHECK_PARAMS for details.
  598. *
  599. * Uncomment to allow MBEDTLS_PARAM_FAILED() to call `assert`.
  600. */
  601. //#define MBEDTLS_CHECK_PARAMS_ASSERT
  602. /* \} name SECTION: System support */
  603. /**
  604. * \name SECTION: mbed TLS feature support
  605. *
  606. * This section sets support for features that are or are not needed
  607. * within the modules that are enabled.
  608. * \{
  609. */
  610. /**
  611. * \def MBEDTLS_TIMING_ALT
  612. *
  613. * Uncomment to provide your own alternate implementation for mbedtls_timing_hardclock(),
  614. * mbedtls_timing_get_timer(), mbedtls_set_alarm(), mbedtls_set/get_delay()
  615. *
  616. * Only works if you have MBEDTLS_TIMING_C enabled.
  617. *
  618. * You will need to provide a header "timing_alt.h" and an implementation at
  619. * compile time.
  620. */
  621. //#define MBEDTLS_TIMING_ALT
  622. /**
  623. * \def MBEDTLS_AES_ALT
  624. *
  625. * MBEDTLS__MODULE_NAME__ALT: Uncomment a macro to let mbed TLS use your
  626. * alternate core implementation of a symmetric crypto, an arithmetic or hash
  627. * module (e.g. platform specific assembly optimized implementations). Keep
  628. * in mind that the function prototypes should remain the same.
  629. *
  630. * This replaces the whole module. If you only want to replace one of the
  631. * functions, use one of the MBEDTLS__FUNCTION_NAME__ALT flags.
  632. *
  633. * Example: In case you uncomment MBEDTLS_AES_ALT, mbed TLS will no longer
  634. * provide the "struct mbedtls_aes_context" definition and omit the base
  635. * function declarations and implementations. "aes_alt.h" will be included from
  636. * "aes.h" to include the new function definitions.
  637. *
  638. * Uncomment a macro to enable alternate implementation of the corresponding
  639. * module.
  640. *
  641. * \warning MD2, MD4, MD5, ARC4, DES and SHA-1 are considered weak and their
  642. * use constitutes a security risk. If possible, we recommend
  643. * avoiding dependencies on them, and considering stronger message
  644. * digests and ciphers instead.
  645. *
  646. */
  647. //#define MBEDTLS_AES_ALT
  648. //#define MBEDTLS_ARC4_ALT
  649. //#define MBEDTLS_ARIA_ALT
  650. //#define MBEDTLS_BLOWFISH_ALT
  651. //#define MBEDTLS_CAMELLIA_ALT
  652. //#define MBEDTLS_CCM_ALT
  653. //#define MBEDTLS_CHACHA20_ALT
  654. //#define MBEDTLS_CHACHAPOLY_ALT
  655. //#define MBEDTLS_CMAC_ALT
  656. //#define MBEDTLS_DES_ALT
  657. //#define MBEDTLS_DHM_ALT
  658. //#define MBEDTLS_ECJPAKE_ALT
  659. //#define MBEDTLS_GCM_ALT
  660. //#define MBEDTLS_NIST_KW_ALT
  661. //#define MBEDTLS_MD2_ALT
  662. //#define MBEDTLS_MD4_ALT
  663. //#define MBEDTLS_MD5_ALT
  664. //#define MBEDTLS_POLY1305_ALT
  665. //#define MBEDTLS_RIPEMD160_ALT
  666. //#define MBEDTLS_RSA_ALT
  667. //#define MBEDTLS_SHA1_ALT
  668. //#define MBEDTLS_SHA256_ALT
  669. //#define MBEDTLS_SHA512_ALT
  670. //#define MBEDTLS_XTEA_ALT
  671. /*
  672. * When replacing the elliptic curve module, pleace consider, that it is
  673. * implemented with two .c files:
  674. * - ecp.c
  675. * - ecp_curves.c
  676. * You can replace them very much like all the other MBEDTLS__MODULE_NAME__ALT
  677. * macros as described above. The only difference is that you have to make sure
  678. * that you provide functionality for both .c files.
  679. */
  680. //#define MBEDTLS_ECP_ALT
  681. /**
  682. * \def MBEDTLS_MD2_PROCESS_ALT
  683. *
  684. * MBEDTLS__FUNCTION_NAME__ALT: Uncomment a macro to let mbed TLS use you
  685. * alternate core implementation of symmetric crypto or hash function. Keep in
  686. * mind that function prototypes should remain the same.
  687. *
  688. * This replaces only one function. The header file from mbed TLS is still
  689. * used, in contrast to the MBEDTLS__MODULE_NAME__ALT flags.
  690. *
  691. * Example: In case you uncomment MBEDTLS_SHA256_PROCESS_ALT, mbed TLS will
  692. * no longer provide the mbedtls_sha1_process() function, but it will still provide
  693. * the other function (using your mbedtls_sha1_process() function) and the definition
  694. * of mbedtls_sha1_context, so your implementation of mbedtls_sha1_process must be compatible
  695. * with this definition.
  696. *
  697. * \note Because of a signature change, the core AES encryption and decryption routines are
  698. * currently named mbedtls_aes_internal_encrypt and mbedtls_aes_internal_decrypt,
  699. * respectively. When setting up alternative implementations, these functions should
  700. * be overridden, but the wrapper functions mbedtls_aes_decrypt and mbedtls_aes_encrypt
  701. * must stay untouched.
  702. *
  703. * \note If you use the AES_xxx_ALT macros, then it is recommended to also set
  704. * MBEDTLS_AES_ROM_TABLES in order to help the linker garbage-collect the AES
  705. * tables.
  706. *
  707. * Uncomment a macro to enable alternate implementation of the corresponding
  708. * function.
  709. *
  710. * \warning MD2, MD4, MD5, DES and SHA-1 are considered weak and their use
  711. * constitutes a security risk. If possible, we recommend avoiding
  712. * dependencies on them, and considering stronger message digests
  713. * and ciphers instead.
  714. *
  715. * \warning If both MBEDTLS_ECDSA_SIGN_ALT and MBEDTLS_ECDSA_DETERMINISTIC are
  716. * enabled, then the deterministic ECDH signature functions pass the
  717. * the static HMAC-DRBG as RNG to mbedtls_ecdsa_sign(). Therefore
  718. * alternative implementations should use the RNG only for generating
  719. * the ephemeral key and nothing else. If this is not possible, then
  720. * MBEDTLS_ECDSA_DETERMINISTIC should be disabled and an alternative
  721. * implementation should be provided for mbedtls_ecdsa_sign_det_ext()
  722. * (and for mbedtls_ecdsa_sign_det() too if backward compatibility is
  723. * desirable).
  724. *
  725. */
  726. //#define MBEDTLS_MD2_PROCESS_ALT
  727. //#define MBEDTLS_MD4_PROCESS_ALT
  728. //#define MBEDTLS_MD5_PROCESS_ALT
  729. //#define MBEDTLS_RIPEMD160_PROCESS_ALT
  730. //#define MBEDTLS_SHA1_PROCESS_ALT
  731. //#define MBEDTLS_SHA256_PROCESS_ALT
  732. //#define MBEDTLS_SHA512_PROCESS_ALT
  733. //#define MBEDTLS_DES_SETKEY_ALT
  734. //#define MBEDTLS_DES_CRYPT_ECB_ALT
  735. //#define MBEDTLS_DES3_CRYPT_ECB_ALT
  736. //#define MBEDTLS_AES_SETKEY_ENC_ALT
  737. //#define MBEDTLS_AES_SETKEY_DEC_ALT
  738. //#define MBEDTLS_AES_ENCRYPT_ALT
  739. //#define MBEDTLS_AES_DECRYPT_ALT
  740. //#define MBEDTLS_ECDH_GEN_PUBLIC_ALT
  741. //#define MBEDTLS_ECDH_COMPUTE_SHARED_ALT
  742. //#define MBEDTLS_ECDSA_VERIFY_ALT
  743. //#define MBEDTLS_ECDSA_SIGN_ALT
  744. //#define MBEDTLS_ECDSA_GENKEY_ALT
  745. /**
  746. * \def MBEDTLS_ECP_INTERNAL_ALT
  747. *
  748. * Expose a part of the internal interface of the Elliptic Curve Point module.
  749. *
  750. * MBEDTLS_ECP__FUNCTION_NAME__ALT: Uncomment a macro to let mbed TLS use your
  751. * alternative core implementation of elliptic curve arithmetic. Keep in mind
  752. * that function prototypes should remain the same.
  753. *
  754. * This partially replaces one function. The header file from mbed TLS is still
  755. * used, in contrast to the MBEDTLS_ECP_ALT flag. The original implementation
  756. * is still present and it is used for group structures not supported by the
  757. * alternative.
  758. *
  759. * The original implementation can in addition be removed by setting the
  760. * MBEDTLS_ECP_NO_FALLBACK option, in which case any function for which the
  761. * corresponding MBEDTLS_ECP__FUNCTION_NAME__ALT macro is defined will not be
  762. * able to fallback to curves not supported by the alternative implementation.
  763. *
  764. * Any of these options become available by defining MBEDTLS_ECP_INTERNAL_ALT
  765. * and implementing the following functions:
  766. * unsigned char mbedtls_internal_ecp_grp_capable(
  767. * const mbedtls_ecp_group *grp )
  768. * int mbedtls_internal_ecp_init( const mbedtls_ecp_group *grp )
  769. * void mbedtls_internal_ecp_free( const mbedtls_ecp_group *grp )
  770. * The mbedtls_internal_ecp_grp_capable function should return 1 if the
  771. * replacement functions implement arithmetic for the given group and 0
  772. * otherwise.
  773. * The functions mbedtls_internal_ecp_init and mbedtls_internal_ecp_free are
  774. * called before and after each point operation and provide an opportunity to
  775. * implement optimized set up and tear down instructions.
  776. *
  777. * Example: In case you set MBEDTLS_ECP_INTERNAL_ALT and
  778. * MBEDTLS_ECP_DOUBLE_JAC_ALT, mbed TLS will still provide the ecp_double_jac()
  779. * function, but will use your mbedtls_internal_ecp_double_jac() if the group
  780. * for the operation is supported by your implementation (i.e. your
  781. * mbedtls_internal_ecp_grp_capable() function returns 1 for this group). If the
  782. * group is not supported by your implementation, then the original mbed TLS
  783. * implementation of ecp_double_jac() is used instead, unless this fallback
  784. * behaviour is disabled by setting MBEDTLS_ECP_NO_FALLBACK (in which case
  785. * ecp_double_jac() will return MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE).
  786. *
  787. * The function prototypes and the definition of mbedtls_ecp_group and
  788. * mbedtls_ecp_point will not change based on MBEDTLS_ECP_INTERNAL_ALT, so your
  789. * implementation of mbedtls_internal_ecp__function_name__ must be compatible
  790. * with their definitions.
  791. *
  792. * Uncomment a macro to enable alternate implementation of the corresponding
  793. * function.
  794. */
  795. /* Required for all the functions in this section */
  796. //#define MBEDTLS_ECP_INTERNAL_ALT
  797. /* Turn off software fallback for curves not supported in hardware */
  798. //#define MBEDTLS_ECP_NO_FALLBACK
  799. /* Support for Weierstrass curves with Jacobi representation */
  800. //#define MBEDTLS_ECP_RANDOMIZE_JAC_ALT
  801. //#define MBEDTLS_ECP_ADD_MIXED_ALT
  802. //#define MBEDTLS_ECP_DOUBLE_JAC_ALT
  803. //#define MBEDTLS_ECP_NORMALIZE_JAC_MANY_ALT
  804. //#define MBEDTLS_ECP_NORMALIZE_JAC_ALT
  805. /* Support for curves with Montgomery arithmetic */
  806. //#define MBEDTLS_ECP_DOUBLE_ADD_MXZ_ALT
  807. //#define MBEDTLS_ECP_RANDOMIZE_MXZ_ALT
  808. //#define MBEDTLS_ECP_NORMALIZE_MXZ_ALT
  809. /**
  810. * \def MBEDTLS_TEST_NULL_ENTROPY
  811. *
  812. * Enables testing and use of mbed TLS without any configured entropy sources.
  813. * This permits use of the library on platforms before an entropy source has
  814. * been integrated (see for example the MBEDTLS_ENTROPY_HARDWARE_ALT or the
  815. * MBEDTLS_ENTROPY_NV_SEED switches).
  816. *
  817. * WARNING! This switch MUST be disabled in production builds, and is suitable
  818. * only for development.
  819. * Enabling the switch negates any security provided by the library.
  820. *
  821. * Requires MBEDTLS_ENTROPY_C, MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES
  822. *
  823. */
  824. //#define MBEDTLS_TEST_NULL_ENTROPY
  825. /**
  826. * \def MBEDTLS_ENTROPY_HARDWARE_ALT
  827. *
  828. * Uncomment this macro to let mbed TLS use your own implementation of a
  829. * hardware entropy collector.
  830. *
  831. * Your function must be called \c mbedtls_hardware_poll(), have the same
  832. * prototype as declared in entropy_poll.h, and accept NULL as first argument.
  833. *
  834. * Uncomment to use your own hardware entropy collector.
  835. */
  836. //#define MBEDTLS_ENTROPY_HARDWARE_ALT
  837. /**
  838. * \def MBEDTLS_AES_ROM_TABLES
  839. *
  840. * Use precomputed AES tables stored in ROM.
  841. *
  842. * Uncomment this macro to use precomputed AES tables stored in ROM.
  843. * Comment this macro to generate AES tables in RAM at runtime.
  844. *
  845. * Tradeoff: Using precomputed ROM tables reduces RAM usage by ~8kb
  846. * (or ~2kb if \c MBEDTLS_AES_FEWER_TABLES is used) and reduces the
  847. * initialization time before the first AES operation can be performed.
  848. * It comes at the cost of additional ~8kb ROM use (resp. ~2kb if \c
  849. * MBEDTLS_AES_FEWER_TABLES below is used), and potentially degraded
  850. * performance if ROM access is slower than RAM access.
  851. *
  852. * This option is independent of \c MBEDTLS_AES_FEWER_TABLES.
  853. *
  854. */
  855. //#define MBEDTLS_AES_ROM_TABLES
  856. /**
  857. * \def MBEDTLS_AES_FEWER_TABLES
  858. *
  859. * Use less ROM/RAM for AES tables.
  860. *
  861. * Uncommenting this macro omits 75% of the AES tables from
  862. * ROM / RAM (depending on the value of \c MBEDTLS_AES_ROM_TABLES)
  863. * by computing their values on the fly during operations
  864. * (the tables are entry-wise rotations of one another).
  865. *
  866. * Tradeoff: Uncommenting this reduces the RAM / ROM footprint
  867. * by ~6kb but at the cost of more arithmetic operations during
  868. * runtime. Specifically, one has to compare 4 accesses within
  869. * different tables to 4 accesses with additional arithmetic
  870. * operations within the same table. The performance gain/loss
  871. * depends on the system and memory details.
  872. *
  873. * This option is independent of \c MBEDTLS_AES_ROM_TABLES.
  874. *
  875. */
  876. //#define MBEDTLS_AES_FEWER_TABLES
  877. /**
  878. * \def MBEDTLS_CAMELLIA_SMALL_MEMORY
  879. *
  880. * Use less ROM for the Camellia implementation (saves about 768 bytes).
  881. *
  882. * Uncomment this macro to use less memory for Camellia.
  883. */
  884. //#define MBEDTLS_CAMELLIA_SMALL_MEMORY
  885. /**
  886. * \def MBEDTLS_CHECK_RETURN_WARNING
  887. *
  888. * If this macro is defined, emit a compile-time warning if application code
  889. * calls a function without checking its return value, but the return value
  890. * should generally be checked in portable applications.
  891. *
  892. * This is only supported on platforms where #MBEDTLS_CHECK_RETURN is
  893. * implemented. Otherwise this option has no effect.
  894. *
  895. * Uncomment to get warnings on using fallible functions without checking
  896. * their return value.
  897. *
  898. * \note This feature is a work in progress.
  899. * Warnings will be added to more functions in the future.
  900. *
  901. * \note A few functions are considered critical, and ignoring the return
  902. * value of these functions will trigger a warning even if this
  903. * macro is not defined. To completely disable return value check
  904. * warnings, define #MBEDTLS_CHECK_RETURN with an empty expansion.
  905. */
  906. //#define MBEDTLS_CHECK_RETURN_WARNING
  907. /**
  908. * \def MBEDTLS_CIPHER_MODE_CBC
  909. *
  910. * Enable Cipher Block Chaining mode (CBC) for symmetric ciphers.
  911. */
  912. #define MBEDTLS_CIPHER_MODE_CBC
  913. /**
  914. * \def MBEDTLS_CIPHER_MODE_CFB
  915. *
  916. * Enable Cipher Feedback mode (CFB) for symmetric ciphers.
  917. */
  918. #define MBEDTLS_CIPHER_MODE_CFB
  919. /**
  920. * \def MBEDTLS_CIPHER_MODE_CTR
  921. *
  922. * Enable Counter Block Cipher mode (CTR) for symmetric ciphers.
  923. */
  924. #define MBEDTLS_CIPHER_MODE_CTR
  925. /**
  926. * \def MBEDTLS_CIPHER_MODE_OFB
  927. *
  928. * Enable Output Feedback mode (OFB) for symmetric ciphers.
  929. */
  930. #define MBEDTLS_CIPHER_MODE_OFB
  931. /**
  932. * \def MBEDTLS_CIPHER_MODE_XTS
  933. *
  934. * Enable Xor-encrypt-xor with ciphertext stealing mode (XTS) for AES.
  935. */
  936. #define MBEDTLS_CIPHER_MODE_XTS
  937. /**
  938. * \def MBEDTLS_CIPHER_NULL_CIPHER
  939. *
  940. * Enable NULL cipher.
  941. * Warning: Only do so when you know what you are doing. This allows for
  942. * encryption or channels without any security!
  943. *
  944. * Requires MBEDTLS_ENABLE_WEAK_CIPHERSUITES as well to enable
  945. * the following ciphersuites:
  946. * MBEDTLS_TLS_ECDH_ECDSA_WITH_NULL_SHA
  947. * MBEDTLS_TLS_ECDH_RSA_WITH_NULL_SHA
  948. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_NULL_SHA
  949. * MBEDTLS_TLS_ECDHE_RSA_WITH_NULL_SHA
  950. * MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA384
  951. * MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA256
  952. * MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA
  953. * MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA384
  954. * MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA256
  955. * MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA
  956. * MBEDTLS_TLS_RSA_WITH_NULL_SHA256
  957. * MBEDTLS_TLS_RSA_WITH_NULL_SHA
  958. * MBEDTLS_TLS_RSA_WITH_NULL_MD5
  959. * MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA384
  960. * MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA256
  961. * MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA
  962. * MBEDTLS_TLS_PSK_WITH_NULL_SHA384
  963. * MBEDTLS_TLS_PSK_WITH_NULL_SHA256
  964. * MBEDTLS_TLS_PSK_WITH_NULL_SHA
  965. *
  966. * Uncomment this macro to enable the NULL cipher and ciphersuites
  967. */
  968. //#define MBEDTLS_CIPHER_NULL_CIPHER
  969. /**
  970. * \def MBEDTLS_CIPHER_PADDING_PKCS7
  971. *
  972. * MBEDTLS_CIPHER_PADDING_XXX: Uncomment or comment macros to add support for
  973. * specific padding modes in the cipher layer with cipher modes that support
  974. * padding (e.g. CBC)
  975. *
  976. * If you disable all padding modes, only full blocks can be used with CBC.
  977. *
  978. * Enable padding modes in the cipher layer.
  979. */
  980. #define MBEDTLS_CIPHER_PADDING_PKCS7
  981. #define MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
  982. #define MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
  983. #define MBEDTLS_CIPHER_PADDING_ZEROS
  984. /** \def MBEDTLS_CTR_DRBG_USE_128_BIT_KEY
  985. *
  986. * Uncomment this macro to use a 128-bit key in the CTR_DRBG module.
  987. * By default, CTR_DRBG uses a 256-bit key.
  988. */
  989. //#define MBEDTLS_CTR_DRBG_USE_128_BIT_KEY
  990. /**
  991. * \def MBEDTLS_ENABLE_WEAK_CIPHERSUITES
  992. *
  993. * Enable weak ciphersuites in SSL / TLS.
  994. * Warning: Only do so when you know what you are doing. This allows for
  995. * channels with virtually no security at all!
  996. *
  997. * This enables the following ciphersuites:
  998. * MBEDTLS_TLS_RSA_WITH_DES_CBC_SHA
  999. * MBEDTLS_TLS_DHE_RSA_WITH_DES_CBC_SHA
  1000. *
  1001. * Uncomment this macro to enable weak ciphersuites
  1002. *
  1003. * \warning DES is considered a weak cipher and its use constitutes a
  1004. * security risk. We recommend considering stronger ciphers instead.
  1005. */
  1006. //#define MBEDTLS_ENABLE_WEAK_CIPHERSUITES
  1007. /**
  1008. * \def MBEDTLS_REMOVE_ARC4_CIPHERSUITES
  1009. *
  1010. * Remove RC4 ciphersuites by default in SSL / TLS.
  1011. * This flag removes the ciphersuites based on RC4 from the default list as
  1012. * returned by mbedtls_ssl_list_ciphersuites(). However, it is still possible to
  1013. * enable (some of) them with mbedtls_ssl_conf_ciphersuites() by including them
  1014. * explicitly.
  1015. *
  1016. * Uncomment this macro to remove RC4 ciphersuites by default.
  1017. */
  1018. #define MBEDTLS_REMOVE_ARC4_CIPHERSUITES
  1019. /**
  1020. * \def MBEDTLS_REMOVE_3DES_CIPHERSUITES
  1021. *
  1022. * Remove 3DES ciphersuites by default in SSL / TLS.
  1023. * This flag removes the ciphersuites based on 3DES from the default list as
  1024. * returned by mbedtls_ssl_list_ciphersuites(). However, it is still possible
  1025. * to enable (some of) them with mbedtls_ssl_conf_ciphersuites() by including
  1026. * them explicitly.
  1027. *
  1028. * A man-in-the-browser attacker can recover authentication tokens sent through
  1029. * a TLS connection using a 3DES based cipher suite (see "On the Practical
  1030. * (In-)Security of 64-bit Block Ciphers" by Karthikeyan Bhargavan and Gaëtan
  1031. * Leurent, see https://sweet32.info/SWEET32_CCS16.pdf). If this attack falls
  1032. * in your threat model or you are unsure, then you should keep this option
  1033. * enabled to remove 3DES based cipher suites.
  1034. *
  1035. * Comment this macro to keep 3DES in the default ciphersuite list.
  1036. */
  1037. #define MBEDTLS_REMOVE_3DES_CIPHERSUITES
  1038. /**
  1039. * \def MBEDTLS_ECP_DP_SECP192R1_ENABLED
  1040. *
  1041. * MBEDTLS_ECP_XXXX_ENABLED: Enables specific curves within the Elliptic Curve
  1042. * module. By default all supported curves are enabled.
  1043. *
  1044. * Comment macros to disable the curve and functions for it
  1045. */
  1046. /* Short Weierstrass curves (supporting ECP, ECDH, ECDSA) */
  1047. #define MBEDTLS_ECP_DP_SECP192R1_ENABLED
  1048. #define MBEDTLS_ECP_DP_SECP224R1_ENABLED
  1049. #define MBEDTLS_ECP_DP_SECP256R1_ENABLED
  1050. #define MBEDTLS_ECP_DP_SECP384R1_ENABLED
  1051. #define MBEDTLS_ECP_DP_SECP521R1_ENABLED
  1052. #define MBEDTLS_ECP_DP_SECP192K1_ENABLED
  1053. #define MBEDTLS_ECP_DP_SECP224K1_ENABLED
  1054. #define MBEDTLS_ECP_DP_SECP256K1_ENABLED
  1055. #define MBEDTLS_ECP_DP_BP256R1_ENABLED
  1056. #define MBEDTLS_ECP_DP_BP384R1_ENABLED
  1057. #define MBEDTLS_ECP_DP_BP512R1_ENABLED
  1058. /* Montgomery curves (supporting ECP) */
  1059. #define MBEDTLS_ECP_DP_CURVE25519_ENABLED
  1060. #define MBEDTLS_ECP_DP_CURVE448_ENABLED
  1061. /**
  1062. * \def MBEDTLS_ECP_NIST_OPTIM
  1063. *
  1064. * Enable specific 'modulo p' routines for each NIST prime.
  1065. * Depending on the prime and architecture, makes operations 4 to 8 times
  1066. * faster on the corresponding curve.
  1067. *
  1068. * Comment this macro to disable NIST curves optimisation.
  1069. */
  1070. #define MBEDTLS_ECP_NIST_OPTIM
  1071. /**
  1072. * \def MBEDTLS_ECP_NO_INTERNAL_RNG
  1073. *
  1074. * When this option is disabled, mbedtls_ecp_mul() will make use of an
  1075. * internal RNG when called with a NULL \c f_rng argument, in order to protect
  1076. * against some side-channel attacks.
  1077. *
  1078. * This protection introduces a dependency of the ECP module on one of the
  1079. * DRBG modules. For very constrained implementations that don't require this
  1080. * protection (for example, because you're only doing signature verification,
  1081. * so not manipulating any secret, or because local/physical side-channel
  1082. * attacks are outside your threat model), it might be desirable to get rid of
  1083. * that dependency.
  1084. *
  1085. * \warning Enabling this option makes some uses of ECP vulnerable to some
  1086. * side-channel attacks. Only enable it if you know that's not a problem for
  1087. * your use case.
  1088. *
  1089. * Uncomment this macro to disable some counter-measures in ECP.
  1090. */
  1091. //#define MBEDTLS_ECP_NO_INTERNAL_RNG
  1092. /**
  1093. * \def MBEDTLS_ECP_RESTARTABLE
  1094. *
  1095. * Enable "non-blocking" ECC operations that can return early and be resumed.
  1096. *
  1097. * This allows various functions to pause by returning
  1098. * #MBEDTLS_ERR_ECP_IN_PROGRESS (or, for functions in the SSL module,
  1099. * #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS) and then be called later again in
  1100. * order to further progress and eventually complete their operation. This is
  1101. * controlled through mbedtls_ecp_set_max_ops() which limits the maximum
  1102. * number of ECC operations a function may perform before pausing; see
  1103. * mbedtls_ecp_set_max_ops() for more information.
  1104. *
  1105. * This is useful in non-threaded environments if you want to avoid blocking
  1106. * for too long on ECC (and, hence, X.509 or SSL/TLS) operations.
  1107. *
  1108. * Uncomment this macro to enable restartable ECC computations.
  1109. *
  1110. * \note This option only works with the default software implementation of
  1111. * elliptic curve functionality. It is incompatible with
  1112. * MBEDTLS_ECP_ALT, MBEDTLS_ECDH_XXX_ALT, MBEDTLS_ECDSA_XXX_ALT
  1113. * and MBEDTLS_ECDH_LEGACY_CONTEXT.
  1114. */
  1115. //#define MBEDTLS_ECP_RESTARTABLE
  1116. /**
  1117. * \def MBEDTLS_ECDH_LEGACY_CONTEXT
  1118. *
  1119. * Use a backward compatible ECDH context.
  1120. *
  1121. * Mbed TLS supports two formats for ECDH contexts (#mbedtls_ecdh_context
  1122. * defined in `ecdh.h`). For most applications, the choice of format makes
  1123. * no difference, since all library functions can work with either format,
  1124. * except that the new format is incompatible with MBEDTLS_ECP_RESTARTABLE.
  1125. * The new format used when this option is disabled is smaller
  1126. * (56 bytes on a 32-bit platform). In future versions of the library, it
  1127. * will support alternative implementations of ECDH operations.
  1128. * The new format is incompatible with applications that access
  1129. * context fields directly and with restartable ECP operations.
  1130. *
  1131. * Define this macro if you enable MBEDTLS_ECP_RESTARTABLE or if you
  1132. * want to access ECDH context fields directly. Otherwise you should
  1133. * comment out this macro definition.
  1134. *
  1135. * This option has no effect if #MBEDTLS_ECDH_C is not enabled.
  1136. *
  1137. * \note This configuration option is experimental. Future versions of the
  1138. * library may modify the way the ECDH context layout is configured
  1139. * and may modify the layout of the new context type.
  1140. */
  1141. #define MBEDTLS_ECDH_LEGACY_CONTEXT
  1142. /**
  1143. * \def MBEDTLS_ECDSA_DETERMINISTIC
  1144. *
  1145. * Enable deterministic ECDSA (RFC 6979).
  1146. * Standard ECDSA is "fragile" in the sense that lack of entropy when signing
  1147. * may result in a compromise of the long-term signing key. This is avoided by
  1148. * the deterministic variant.
  1149. *
  1150. * Requires: MBEDTLS_HMAC_DRBG_C, MBEDTLS_ECDSA_C
  1151. *
  1152. * Comment this macro to disable deterministic ECDSA.
  1153. */
  1154. #define MBEDTLS_ECDSA_DETERMINISTIC
  1155. /**
  1156. * \def MBEDTLS_KEY_EXCHANGE_PSK_ENABLED
  1157. *
  1158. * Enable the PSK based ciphersuite modes in SSL / TLS.
  1159. *
  1160. * This enables the following ciphersuites (if other requisites are
  1161. * enabled as well):
  1162. * MBEDTLS_TLS_PSK_WITH_AES_256_GCM_SHA384
  1163. * MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA384
  1164. * MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA
  1165. * MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_GCM_SHA384
  1166. * MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384
  1167. * MBEDTLS_TLS_PSK_WITH_AES_128_GCM_SHA256
  1168. * MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA256
  1169. * MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA
  1170. * MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256
  1171. * MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256
  1172. * MBEDTLS_TLS_PSK_WITH_3DES_EDE_CBC_SHA
  1173. * MBEDTLS_TLS_PSK_WITH_RC4_128_SHA
  1174. */
  1175. #define MBEDTLS_KEY_EXCHANGE_PSK_ENABLED
  1176. /**
  1177. * \def MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED
  1178. *
  1179. * Enable the DHE-PSK based ciphersuite modes in SSL / TLS.
  1180. *
  1181. * Requires: MBEDTLS_DHM_C
  1182. *
  1183. * This enables the following ciphersuites (if other requisites are
  1184. * enabled as well):
  1185. * MBEDTLS_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384
  1186. * MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384
  1187. * MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA
  1188. * MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384
  1189. * MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384
  1190. * MBEDTLS_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256
  1191. * MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256
  1192. * MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA
  1193. * MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256
  1194. * MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256
  1195. * MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA
  1196. * MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA
  1197. *
  1198. * \warning Using DHE constitutes a security risk as it
  1199. * is not possible to validate custom DH parameters.
  1200. * If possible, it is recommended users should consider
  1201. * preferring other methods of key exchange.
  1202. * See dhm.h for more details.
  1203. *
  1204. */
  1205. #define MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED
  1206. /**
  1207. * \def MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED
  1208. *
  1209. * Enable the ECDHE-PSK based ciphersuite modes in SSL / TLS.
  1210. *
  1211. * Requires: MBEDTLS_ECDH_C
  1212. *
  1213. * This enables the following ciphersuites (if other requisites are
  1214. * enabled as well):
  1215. * MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384
  1216. * MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA
  1217. * MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384
  1218. * MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256
  1219. * MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA
  1220. * MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256
  1221. * MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA
  1222. * MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA
  1223. */
  1224. #define MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED
  1225. /**
  1226. * \def MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED
  1227. *
  1228. * Enable the RSA-PSK based ciphersuite modes in SSL / TLS.
  1229. *
  1230. * Requires: MBEDTLS_RSA_C, MBEDTLS_PKCS1_V15,
  1231. * MBEDTLS_X509_CRT_PARSE_C
  1232. *
  1233. * This enables the following ciphersuites (if other requisites are
  1234. * enabled as well):
  1235. * MBEDTLS_TLS_RSA_PSK_WITH_AES_256_GCM_SHA384
  1236. * MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA384
  1237. * MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA
  1238. * MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384
  1239. * MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384
  1240. * MBEDTLS_TLS_RSA_PSK_WITH_AES_128_GCM_SHA256
  1241. * MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA256
  1242. * MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA
  1243. * MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256
  1244. * MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256
  1245. * MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA
  1246. * MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA
  1247. */
  1248. #define MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED
  1249. /**
  1250. * \def MBEDTLS_KEY_EXCHANGE_RSA_ENABLED
  1251. *
  1252. * Enable the RSA-only based ciphersuite modes in SSL / TLS.
  1253. *
  1254. * Requires: MBEDTLS_RSA_C, MBEDTLS_PKCS1_V15,
  1255. * MBEDTLS_X509_CRT_PARSE_C
  1256. *
  1257. * This enables the following ciphersuites (if other requisites are
  1258. * enabled as well):
  1259. * MBEDTLS_TLS_RSA_WITH_AES_256_GCM_SHA384
  1260. * MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA256
  1261. * MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA
  1262. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384
  1263. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256
  1264. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
  1265. * MBEDTLS_TLS_RSA_WITH_AES_128_GCM_SHA256
  1266. * MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA256
  1267. * MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA
  1268. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256
  1269. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
  1270. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
  1271. * MBEDTLS_TLS_RSA_WITH_3DES_EDE_CBC_SHA
  1272. * MBEDTLS_TLS_RSA_WITH_RC4_128_SHA
  1273. * MBEDTLS_TLS_RSA_WITH_RC4_128_MD5
  1274. */
  1275. #define MBEDTLS_KEY_EXCHANGE_RSA_ENABLED
  1276. /**
  1277. * \def MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED
  1278. *
  1279. * Enable the DHE-RSA based ciphersuite modes in SSL / TLS.
  1280. *
  1281. * Requires: MBEDTLS_DHM_C, MBEDTLS_RSA_C, MBEDTLS_PKCS1_V15,
  1282. * MBEDTLS_X509_CRT_PARSE_C
  1283. *
  1284. * This enables the following ciphersuites (if other requisites are
  1285. * enabled as well):
  1286. * MBEDTLS_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
  1287. * MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
  1288. * MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA
  1289. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384
  1290. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
  1291. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
  1292. * MBEDTLS_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
  1293. * MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
  1294. * MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA
  1295. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256
  1296. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
  1297. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
  1298. * MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
  1299. *
  1300. * \warning Using DHE constitutes a security risk as it
  1301. * is not possible to validate custom DH parameters.
  1302. * If possible, it is recommended users should consider
  1303. * preferring other methods of key exchange.
  1304. * See dhm.h for more details.
  1305. *
  1306. */
  1307. #define MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED
  1308. /**
  1309. * \def MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED
  1310. *
  1311. * Enable the ECDHE-RSA based ciphersuite modes in SSL / TLS.
  1312. *
  1313. * Requires: MBEDTLS_ECDH_C, MBEDTLS_RSA_C, MBEDTLS_PKCS1_V15,
  1314. * MBEDTLS_X509_CRT_PARSE_C
  1315. *
  1316. * This enables the following ciphersuites (if other requisites are
  1317. * enabled as well):
  1318. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  1319. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
  1320. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
  1321. * MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384
  1322. * MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384
  1323. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  1324. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
  1325. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
  1326. * MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256
  1327. * MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
  1328. * MBEDTLS_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
  1329. * MBEDTLS_TLS_ECDHE_RSA_WITH_RC4_128_SHA
  1330. */
  1331. #define MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED
  1332. /**
  1333. * \def MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
  1334. *
  1335. * Enable the ECDHE-ECDSA based ciphersuite modes in SSL / TLS.
  1336. *
  1337. * Requires: MBEDTLS_ECDH_C, MBEDTLS_ECDSA_C, MBEDTLS_X509_CRT_PARSE_C,
  1338. *
  1339. * This enables the following ciphersuites (if other requisites are
  1340. * enabled as well):
  1341. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
  1342. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
  1343. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
  1344. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384
  1345. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384
  1346. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
  1347. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
  1348. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
  1349. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256
  1350. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256
  1351. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA
  1352. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA
  1353. */
  1354. #define MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
  1355. /**
  1356. * \def MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED
  1357. *
  1358. * Enable the ECDH-ECDSA based ciphersuite modes in SSL / TLS.
  1359. *
  1360. * Requires: MBEDTLS_ECDH_C, MBEDTLS_ECDSA_C, MBEDTLS_X509_CRT_PARSE_C
  1361. *
  1362. * This enables the following ciphersuites (if other requisites are
  1363. * enabled as well):
  1364. * MBEDTLS_TLS_ECDH_ECDSA_WITH_RC4_128_SHA
  1365. * MBEDTLS_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA
  1366. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA
  1367. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA
  1368. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256
  1369. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384
  1370. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256
  1371. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384
  1372. * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256
  1373. * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384
  1374. * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256
  1375. * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384
  1376. */
  1377. #define MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED
  1378. /**
  1379. * \def MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED
  1380. *
  1381. * Enable the ECDH-RSA based ciphersuite modes in SSL / TLS.
  1382. *
  1383. * Requires: MBEDTLS_ECDH_C, MBEDTLS_RSA_C, MBEDTLS_X509_CRT_PARSE_C
  1384. *
  1385. * This enables the following ciphersuites (if other requisites are
  1386. * enabled as well):
  1387. * MBEDTLS_TLS_ECDH_RSA_WITH_RC4_128_SHA
  1388. * MBEDTLS_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA
  1389. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA
  1390. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA
  1391. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256
  1392. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384
  1393. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256
  1394. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384
  1395. * MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256
  1396. * MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384
  1397. * MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256
  1398. * MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384
  1399. */
  1400. #define MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED
  1401. /**
  1402. * \def MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED
  1403. *
  1404. * Enable the ECJPAKE based ciphersuite modes in SSL / TLS.
  1405. *
  1406. * \warning This is currently experimental. EC J-PAKE support is based on the
  1407. * Thread v1.0.0 specification; incompatible changes to the specification
  1408. * might still happen. For this reason, this is disabled by default.
  1409. *
  1410. * Requires: MBEDTLS_ECJPAKE_C
  1411. * MBEDTLS_SHA256_C
  1412. * MBEDTLS_ECP_DP_SECP256R1_ENABLED
  1413. *
  1414. * This enables the following ciphersuites (if other requisites are
  1415. * enabled as well):
  1416. * MBEDTLS_TLS_ECJPAKE_WITH_AES_128_CCM_8
  1417. */
  1418. //#define MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED
  1419. /**
  1420. * \def MBEDTLS_PK_PARSE_EC_EXTENDED
  1421. *
  1422. * Enhance support for reading EC keys using variants of SEC1 not allowed by
  1423. * RFC 5915 and RFC 5480.
  1424. *
  1425. * Currently this means parsing the SpecifiedECDomain choice of EC
  1426. * parameters (only known groups are supported, not arbitrary domains, to
  1427. * avoid validation issues).
  1428. *
  1429. * Disable if you only need to support RFC 5915 + 5480 key formats.
  1430. */
  1431. #define MBEDTLS_PK_PARSE_EC_EXTENDED
  1432. /**
  1433. * \def MBEDTLS_ERROR_STRERROR_DUMMY
  1434. *
  1435. * Enable a dummy error function to make use of mbedtls_strerror() in
  1436. * third party libraries easier when MBEDTLS_ERROR_C is disabled
  1437. * (no effect when MBEDTLS_ERROR_C is enabled).
  1438. *
  1439. * You can safely disable this if MBEDTLS_ERROR_C is enabled, or if you're
  1440. * not using mbedtls_strerror() or error_strerror() in your application.
  1441. *
  1442. * Disable if you run into name conflicts and want to really remove the
  1443. * mbedtls_strerror()
  1444. */
  1445. #define MBEDTLS_ERROR_STRERROR_DUMMY
  1446. /**
  1447. * \def MBEDTLS_GENPRIME
  1448. *
  1449. * Enable the prime-number generation code.
  1450. *
  1451. * Requires: MBEDTLS_BIGNUM_C
  1452. */
  1453. #define MBEDTLS_GENPRIME
  1454. /**
  1455. * \def MBEDTLS_FS_IO
  1456. *
  1457. * Enable functions that use the filesystem.
  1458. */
  1459. #define MBEDTLS_FS_IO
  1460. /**
  1461. * \def MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES
  1462. *
  1463. * Do not add default entropy sources. These are the platform specific,
  1464. * mbedtls_timing_hardclock and HAVEGE based poll functions.
  1465. *
  1466. * This is useful to have more control over the added entropy sources in an
  1467. * application.
  1468. *
  1469. * Uncomment this macro to prevent loading of default entropy functions.
  1470. */
  1471. //#define MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES
  1472. /**
  1473. * \def MBEDTLS_NO_PLATFORM_ENTROPY
  1474. *
  1475. * Do not use built-in platform entropy functions.
  1476. * This is useful if your platform does not support
  1477. * standards like the /dev/urandom or Windows CryptoAPI.
  1478. *
  1479. * Uncomment this macro to disable the built-in platform entropy functions.
  1480. */
  1481. //#define MBEDTLS_NO_PLATFORM_ENTROPY
  1482. /**
  1483. * \def MBEDTLS_ENTROPY_FORCE_SHA256
  1484. *
  1485. * Force the entropy accumulator to use a SHA-256 accumulator instead of the
  1486. * default SHA-512 based one (if both are available).
  1487. *
  1488. * Requires: MBEDTLS_SHA256_C
  1489. *
  1490. * On 32-bit systems SHA-256 can be much faster than SHA-512. Use this option
  1491. * if you have performance concerns.
  1492. *
  1493. * This option is only useful if both MBEDTLS_SHA256_C and
  1494. * MBEDTLS_SHA512_C are defined. Otherwise the available hash module is used.
  1495. */
  1496. //#define MBEDTLS_ENTROPY_FORCE_SHA256
  1497. /**
  1498. * \def MBEDTLS_ENTROPY_NV_SEED
  1499. *
  1500. * Enable the non-volatile (NV) seed file-based entropy source.
  1501. * (Also enables the NV seed read/write functions in the platform layer)
  1502. *
  1503. * This is crucial (if not required) on systems that do not have a
  1504. * cryptographic entropy source (in hardware or kernel) available.
  1505. *
  1506. * Requires: MBEDTLS_ENTROPY_C, MBEDTLS_PLATFORM_C
  1507. *
  1508. * \note The read/write functions that are used by the entropy source are
  1509. * determined in the platform layer, and can be modified at runtime and/or
  1510. * compile-time depending on the flags (MBEDTLS_PLATFORM_NV_SEED_*) used.
  1511. *
  1512. * \note If you use the default implementation functions that read a seedfile
  1513. * with regular fopen(), please make sure you make a seedfile with the
  1514. * proper name (defined in MBEDTLS_PLATFORM_STD_NV_SEED_FILE) and at
  1515. * least MBEDTLS_ENTROPY_BLOCK_SIZE bytes in size that can be read from
  1516. * and written to or you will get an entropy source error! The default
  1517. * implementation will only use the first MBEDTLS_ENTROPY_BLOCK_SIZE
  1518. * bytes from the file.
  1519. *
  1520. * \note The entropy collector will write to the seed file before entropy is
  1521. * given to an external source, to update it.
  1522. */
  1523. //#define MBEDTLS_ENTROPY_NV_SEED
  1524. /* MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER
  1525. *
  1526. * Enable key identifiers that encode a key owner identifier.
  1527. *
  1528. * The owner of a key is identified by a value of type ::mbedtls_key_owner_id_t
  1529. * which is currently hard-coded to be int32_t.
  1530. *
  1531. * Note that this option is meant for internal use only and may be removed
  1532. * without notice. It is incompatible with MBEDTLS_USE_PSA_CRYPTO.
  1533. */
  1534. //#define MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER
  1535. /**
  1536. * \def MBEDTLS_MEMORY_DEBUG
  1537. *
  1538. * Enable debugging of buffer allocator memory issues. Automatically prints
  1539. * (to stderr) all (fatal) messages on memory allocation issues. Enables
  1540. * function for 'debug output' of allocated memory.
  1541. *
  1542. * Requires: MBEDTLS_MEMORY_BUFFER_ALLOC_C
  1543. *
  1544. * Uncomment this macro to let the buffer allocator print out error messages.
  1545. */
  1546. //#define MBEDTLS_MEMORY_DEBUG
  1547. /**
  1548. * \def MBEDTLS_MEMORY_BACKTRACE
  1549. *
  1550. * Include backtrace information with each allocated block.
  1551. *
  1552. * Requires: MBEDTLS_MEMORY_BUFFER_ALLOC_C
  1553. * GLIBC-compatible backtrace() an backtrace_symbols() support
  1554. *
  1555. * Uncomment this macro to include backtrace information
  1556. */
  1557. //#define MBEDTLS_MEMORY_BACKTRACE
  1558. /**
  1559. * \def MBEDTLS_PK_RSA_ALT_SUPPORT
  1560. *
  1561. * Support external private RSA keys (eg from a HSM) in the PK layer.
  1562. *
  1563. * Comment this macro to disable support for external private RSA keys.
  1564. */
  1565. #define MBEDTLS_PK_RSA_ALT_SUPPORT
  1566. /**
  1567. * \def MBEDTLS_PKCS1_V15
  1568. *
  1569. * Enable support for PKCS#1 v1.5 encoding.
  1570. *
  1571. * Requires: MBEDTLS_RSA_C
  1572. *
  1573. * This enables support for PKCS#1 v1.5 operations.
  1574. */
  1575. #define MBEDTLS_PKCS1_V15
  1576. /**
  1577. * \def MBEDTLS_PKCS1_V21
  1578. *
  1579. * Enable support for PKCS#1 v2.1 encoding.
  1580. *
  1581. * Requires: MBEDTLS_MD_C, MBEDTLS_RSA_C
  1582. *
  1583. * This enables support for RSAES-OAEP and RSASSA-PSS operations.
  1584. */
  1585. #define MBEDTLS_PKCS1_V21
  1586. /** \def MBEDTLS_PSA_CRYPTO_BUILTIN_KEYS
  1587. *
  1588. * Enable support for platform built-in keys. If you enable this feature,
  1589. * you must implement the function mbedtls_psa_platform_get_builtin_key().
  1590. * See the documentation of that function for more information.
  1591. *
  1592. * Built-in keys are typically derived from a hardware unique key or
  1593. * stored in a secure element.
  1594. *
  1595. * Requires: MBEDTLS_PSA_CRYPTO_C.
  1596. *
  1597. * \warning This interface is experimental and may change or be removed
  1598. * without notice.
  1599. */
  1600. //#define MBEDTLS_PSA_CRYPTO_BUILTIN_KEYS
  1601. /** \def MBEDTLS_PSA_CRYPTO_CLIENT
  1602. *
  1603. * Enable support for PSA crypto client.
  1604. *
  1605. * \note This option allows to include the code necessary for a PSA
  1606. * crypto client when the PSA crypto implementation is not included in
  1607. * the library (MBEDTLS_PSA_CRYPTO_C disabled). The code included is the
  1608. * code to set and get PSA key attributes.
  1609. * The development of PSA drivers partially relying on the library to
  1610. * fulfill the hardware gaps is another possible usage of this option.
  1611. *
  1612. * \warning This interface is experimental and may change or be removed
  1613. * without notice.
  1614. */
  1615. //#define MBEDTLS_PSA_CRYPTO_CLIENT
  1616. /** \def MBEDTLS_PSA_CRYPTO_DRIVERS
  1617. *
  1618. * Enable support for the experimental PSA crypto driver interface.
  1619. *
  1620. * Requires: MBEDTLS_PSA_CRYPTO_C
  1621. *
  1622. * \warning This interface is experimental and may change or be removed
  1623. * without notice.
  1624. */
  1625. //#define MBEDTLS_PSA_CRYPTO_DRIVERS
  1626. /** \def MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG
  1627. *
  1628. * Make the PSA Crypto module use an external random generator provided
  1629. * by a driver, instead of Mbed TLS's entropy and DRBG modules.
  1630. *
  1631. * \note This random generator must deliver random numbers with cryptographic
  1632. * quality and high performance. It must supply unpredictable numbers
  1633. * with a uniform distribution. The implementation of this function
  1634. * is responsible for ensuring that the random generator is seeded
  1635. * with sufficient entropy. If you have a hardware TRNG which is slow
  1636. * or delivers non-uniform output, declare it as an entropy source
  1637. * with mbedtls_entropy_add_source() instead of enabling this option.
  1638. *
  1639. * If you enable this option, you must configure the type
  1640. * ::mbedtls_psa_external_random_context_t in psa/crypto_platform.h
  1641. * and define a function called mbedtls_psa_external_get_random()
  1642. * with the following prototype:
  1643. * ```
  1644. * psa_status_t mbedtls_psa_external_get_random(
  1645. * mbedtls_psa_external_random_context_t *context,
  1646. * uint8_t *output, size_t output_size, size_t *output_length);
  1647. * );
  1648. * ```
  1649. * The \c context value is initialized to 0 before the first call.
  1650. * The function must fill the \c output buffer with \p output_size bytes
  1651. * of random data and set \c *output_length to \p output_size.
  1652. *
  1653. * Requires: MBEDTLS_PSA_CRYPTO_C
  1654. *
  1655. * \warning If you enable this option, code that uses the PSA cryptography
  1656. * interface will not use any of the entropy sources set up for
  1657. * the entropy module, nor the NV seed that MBEDTLS_ENTROPY_NV_SEED
  1658. * enables.
  1659. *
  1660. * \note This option is experimental and may be removed without notice.
  1661. */
  1662. //#define MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG
  1663. /**
  1664. * \def MBEDTLS_PSA_CRYPTO_SPM
  1665. *
  1666. * When MBEDTLS_PSA_CRYPTO_SPM is defined, the code is built for SPM (Secure
  1667. * Partition Manager) integration which separates the code into two parts: a
  1668. * NSPE (Non-Secure Process Environment) and an SPE (Secure Process
  1669. * Environment).
  1670. *
  1671. * Module: library/psa_crypto.c
  1672. * Requires: MBEDTLS_PSA_CRYPTO_C
  1673. *
  1674. */
  1675. //#define MBEDTLS_PSA_CRYPTO_SPM
  1676. /**
  1677. * \def MBEDTLS_PSA_INJECT_ENTROPY
  1678. *
  1679. * Enable support for entropy injection at first boot. This feature is
  1680. * required on systems that do not have a built-in entropy source (TRNG).
  1681. * This feature is currently not supported on systems that have a built-in
  1682. * entropy source.
  1683. *
  1684. * Requires: MBEDTLS_PSA_CRYPTO_STORAGE_C, MBEDTLS_ENTROPY_NV_SEED
  1685. *
  1686. */
  1687. //#define MBEDTLS_PSA_INJECT_ENTROPY
  1688. /**
  1689. * \def MBEDTLS_RSA_NO_CRT
  1690. *
  1691. * Do not use the Chinese Remainder Theorem
  1692. * for the RSA private operation.
  1693. *
  1694. * Uncomment this macro to disable the use of CRT in RSA.
  1695. *
  1696. */
  1697. //#define MBEDTLS_RSA_NO_CRT
  1698. /**
  1699. * \def MBEDTLS_SELF_TEST
  1700. *
  1701. * Enable the checkup functions (*_self_test).
  1702. */
  1703. #define MBEDTLS_SELF_TEST
  1704. /**
  1705. * \def MBEDTLS_SHA256_SMALLER
  1706. *
  1707. * Enable an implementation of SHA-256 that has lower ROM footprint but also
  1708. * lower performance.
  1709. *
  1710. * The default implementation is meant to be a reasonnable compromise between
  1711. * performance and size. This version optimizes more aggressively for size at
  1712. * the expense of performance. Eg on Cortex-M4 it reduces the size of
  1713. * mbedtls_sha256_process() from ~2KB to ~0.5KB for a performance hit of about
  1714. * 30%.
  1715. *
  1716. * Uncomment to enable the smaller implementation of SHA256.
  1717. */
  1718. //#define MBEDTLS_SHA256_SMALLER
  1719. /**
  1720. * \def MBEDTLS_SHA512_SMALLER
  1721. *
  1722. * Enable an implementation of SHA-512 that has lower ROM footprint but also
  1723. * lower performance.
  1724. *
  1725. * Uncomment to enable the smaller implementation of SHA512.
  1726. */
  1727. //#define MBEDTLS_SHA512_SMALLER
  1728. /**
  1729. * \def MBEDTLS_SHA512_NO_SHA384
  1730. *
  1731. * Disable the SHA-384 option of the SHA-512 module. Use this to save some
  1732. * code size on devices that don't use SHA-384.
  1733. *
  1734. * Requires: MBEDTLS_SHA512_C
  1735. *
  1736. * Uncomment to disable SHA-384
  1737. */
  1738. //#define MBEDTLS_SHA512_NO_SHA384
  1739. /**
  1740. * \def MBEDTLS_SSL_ALL_ALERT_MESSAGES
  1741. *
  1742. * Enable sending of alert messages in case of encountered errors as per RFC.
  1743. * If you choose not to send the alert messages, mbed TLS can still communicate
  1744. * with other servers, only debugging of failures is harder.
  1745. *
  1746. * The advantage of not sending alert messages, is that no information is given
  1747. * about reasons for failures thus preventing adversaries of gaining intel.
  1748. *
  1749. * Enable sending of all alert messages
  1750. */
  1751. #define MBEDTLS_SSL_ALL_ALERT_MESSAGES
  1752. /**
  1753. * \def MBEDTLS_SSL_RECORD_CHECKING
  1754. *
  1755. * Enable the function mbedtls_ssl_check_record() which can be used to check
  1756. * the validity and authenticity of an incoming record, to verify that it has
  1757. * not been seen before. These checks are performed without modifying the
  1758. * externally visible state of the SSL context.
  1759. *
  1760. * See mbedtls_ssl_check_record() for more information.
  1761. *
  1762. * Uncomment to enable support for record checking.
  1763. */
  1764. #define MBEDTLS_SSL_RECORD_CHECKING
  1765. /**
  1766. * \def MBEDTLS_SSL_DTLS_CONNECTION_ID
  1767. *
  1768. * Enable support for the DTLS Connection ID extension
  1769. * (version draft-ietf-tls-dtls-connection-id-05,
  1770. * https://tools.ietf.org/html/draft-ietf-tls-dtls-connection-id-05)
  1771. * which allows to identify DTLS connections across changes
  1772. * in the underlying transport.
  1773. *
  1774. * Setting this option enables the SSL APIs `mbedtls_ssl_set_cid()`,
  1775. * `mbedtls_ssl_get_peer_cid()` and `mbedtls_ssl_conf_cid()`.
  1776. * See the corresponding documentation for more information.
  1777. *
  1778. * \warning The Connection ID extension is still in draft state.
  1779. * We make no stability promises for the availability
  1780. * or the shape of the API controlled by this option.
  1781. *
  1782. * The maximum lengths of outgoing and incoming CIDs can be configured
  1783. * through the options
  1784. * - MBEDTLS_SSL_CID_OUT_LEN_MAX
  1785. * - MBEDTLS_SSL_CID_IN_LEN_MAX.
  1786. *
  1787. * Requires: MBEDTLS_SSL_PROTO_DTLS
  1788. *
  1789. * Uncomment to enable the Connection ID extension.
  1790. */
  1791. //#define MBEDTLS_SSL_DTLS_CONNECTION_ID
  1792. /**
  1793. * \def MBEDTLS_SSL_ASYNC_PRIVATE
  1794. *
  1795. * Enable asynchronous external private key operations in SSL. This allows
  1796. * you to configure an SSL connection to call an external cryptographic
  1797. * module to perform private key operations instead of performing the
  1798. * operation inside the library.
  1799. *
  1800. */
  1801. //#define MBEDTLS_SSL_ASYNC_PRIVATE
  1802. /**
  1803. * \def MBEDTLS_SSL_CONTEXT_SERIALIZATION
  1804. *
  1805. * Enable serialization of the TLS context structures, through use of the
  1806. * functions mbedtls_ssl_context_save() and mbedtls_ssl_context_load().
  1807. *
  1808. * This pair of functions allows one side of a connection to serialize the
  1809. * context associated with the connection, then free or re-use that context
  1810. * while the serialized state is persisted elsewhere, and finally deserialize
  1811. * that state to a live context for resuming read/write operations on the
  1812. * connection. From a protocol perspective, the state of the connection is
  1813. * unaffected, in particular this is entirely transparent to the peer.
  1814. *
  1815. * Note: this is distinct from TLS session resumption, which is part of the
  1816. * protocol and fully visible by the peer. TLS session resumption enables
  1817. * establishing new connections associated to a saved session with shorter,
  1818. * lighter handshakes, while context serialization is a local optimization in
  1819. * handling a single, potentially long-lived connection.
  1820. *
  1821. * Enabling these APIs makes some SSL structures larger, as 64 extra bytes are
  1822. * saved after the handshake to allow for more efficient serialization, so if
  1823. * you don't need this feature you'll save RAM by disabling it.
  1824. *
  1825. * Comment to disable the context serialization APIs.
  1826. */
  1827. #define MBEDTLS_SSL_CONTEXT_SERIALIZATION
  1828. /**
  1829. * \def MBEDTLS_SSL_DEBUG_ALL
  1830. *
  1831. * Enable the debug messages in SSL module for all issues.
  1832. * Debug messages have been disabled in some places to prevent timing
  1833. * attacks due to (unbalanced) debugging function calls.
  1834. *
  1835. * If you need all error reporting you should enable this during debugging,
  1836. * but remove this for production servers that should log as well.
  1837. *
  1838. * Uncomment this macro to report all debug messages on errors introducing
  1839. * a timing side-channel.
  1840. *
  1841. */
  1842. //#define MBEDTLS_SSL_DEBUG_ALL
  1843. /** \def MBEDTLS_SSL_ENCRYPT_THEN_MAC
  1844. *
  1845. * Enable support for Encrypt-then-MAC, RFC 7366.
  1846. *
  1847. * This allows peers that both support it to use a more robust protection for
  1848. * ciphersuites using CBC, providing deep resistance against timing attacks
  1849. * on the padding or underlying cipher.
  1850. *
  1851. * This only affects CBC ciphersuites, and is useless if none is defined.
  1852. *
  1853. * Requires: MBEDTLS_SSL_PROTO_TLS1 or
  1854. * MBEDTLS_SSL_PROTO_TLS1_1 or
  1855. * MBEDTLS_SSL_PROTO_TLS1_2
  1856. *
  1857. * Comment this macro to disable support for Encrypt-then-MAC
  1858. */
  1859. #define MBEDTLS_SSL_ENCRYPT_THEN_MAC
  1860. /** \def MBEDTLS_SSL_EXTENDED_MASTER_SECRET
  1861. *
  1862. * Enable support for RFC 7627: Session Hash and Extended Master Secret
  1863. * Extension.
  1864. *
  1865. * This was introduced as "the proper fix" to the Triple Handshake familiy of
  1866. * attacks, but it is recommended to always use it (even if you disable
  1867. * renegotiation), since it actually fixes a more fundamental issue in the
  1868. * original SSL/TLS design, and has implications beyond Triple Handshake.
  1869. *
  1870. * Requires: MBEDTLS_SSL_PROTO_TLS1 or
  1871. * MBEDTLS_SSL_PROTO_TLS1_1 or
  1872. * MBEDTLS_SSL_PROTO_TLS1_2
  1873. *
  1874. * Comment this macro to disable support for Extended Master Secret.
  1875. */
  1876. #define MBEDTLS_SSL_EXTENDED_MASTER_SECRET
  1877. /**
  1878. * \def MBEDTLS_SSL_FALLBACK_SCSV
  1879. *
  1880. * Enable support for RFC 7507: Fallback Signaling Cipher Suite Value (SCSV)
  1881. * for Preventing Protocol Downgrade Attacks.
  1882. *
  1883. * For servers, it is recommended to always enable this, unless you support
  1884. * only one version of TLS, or know for sure that none of your clients
  1885. * implements a fallback strategy.
  1886. *
  1887. * For clients, you only need this if you're using a fallback strategy, which
  1888. * is not recommended in the first place, unless you absolutely need it to
  1889. * interoperate with buggy (version-intolerant) servers.
  1890. *
  1891. * Comment this macro to disable support for FALLBACK_SCSV
  1892. */
  1893. #define MBEDTLS_SSL_FALLBACK_SCSV
  1894. /**
  1895. * \def MBEDTLS_SSL_KEEP_PEER_CERTIFICATE
  1896. *
  1897. * This option controls the availability of the API mbedtls_ssl_get_peer_cert()
  1898. * giving access to the peer's certificate after completion of the handshake.
  1899. *
  1900. * Unless you need mbedtls_ssl_peer_cert() in your application, it is
  1901. * recommended to disable this option for reduced RAM usage.
  1902. *
  1903. * \note If this option is disabled, mbedtls_ssl_get_peer_cert() is still
  1904. * defined, but always returns \c NULL.
  1905. *
  1906. * \note This option has no influence on the protection against the
  1907. * triple handshake attack. Even if it is disabled, Mbed TLS will
  1908. * still ensure that certificates do not change during renegotiation,
  1909. * for exaple by keeping a hash of the peer's certificate.
  1910. *
  1911. * Comment this macro to disable storing the peer's certificate
  1912. * after the handshake.
  1913. */
  1914. #define MBEDTLS_SSL_KEEP_PEER_CERTIFICATE
  1915. /**
  1916. * \def MBEDTLS_SSL_HW_RECORD_ACCEL
  1917. *
  1918. * Enable hooking functions in SSL module for hardware acceleration of
  1919. * individual records.
  1920. *
  1921. * \deprecated This option is deprecated and will be removed in a future
  1922. * version of Mbed TLS.
  1923. *
  1924. * Uncomment this macro to enable hooking functions.
  1925. */
  1926. //#define MBEDTLS_SSL_HW_RECORD_ACCEL
  1927. /**
  1928. * \def MBEDTLS_SSL_CBC_RECORD_SPLITTING
  1929. *
  1930. * Enable 1/n-1 record splitting for CBC mode in SSLv3 and TLS 1.0.
  1931. *
  1932. * This is a countermeasure to the BEAST attack, which also minimizes the risk
  1933. * of interoperability issues compared to sending 0-length records.
  1934. *
  1935. * Comment this macro to disable 1/n-1 record splitting.
  1936. */
  1937. #define MBEDTLS_SSL_CBC_RECORD_SPLITTING
  1938. /**
  1939. * \def MBEDTLS_SSL_RENEGOTIATION
  1940. *
  1941. * Enable support for TLS renegotiation.
  1942. *
  1943. * The two main uses of renegotiation are (1) refresh keys on long-lived
  1944. * connections and (2) client authentication after the initial handshake.
  1945. * If you don't need renegotiation, it's probably better to disable it, since
  1946. * it has been associated with security issues in the past and is easy to
  1947. * misuse/misunderstand.
  1948. *
  1949. * Comment this to disable support for renegotiation.
  1950. *
  1951. * \note Even if this option is disabled, both client and server are aware
  1952. * of the Renegotiation Indication Extension (RFC 5746) used to
  1953. * prevent the SSL renegotiation attack (see RFC 5746 Sect. 1).
  1954. * (See \c mbedtls_ssl_conf_legacy_renegotiation for the
  1955. * configuration of this extension).
  1956. *
  1957. */
  1958. #define MBEDTLS_SSL_RENEGOTIATION
  1959. /**
  1960. * \def MBEDTLS_SSL_SRV_SUPPORT_SSLV2_CLIENT_HELLO
  1961. *
  1962. * Enable support for receiving and parsing SSLv2 Client Hello messages for the
  1963. * SSL Server module (MBEDTLS_SSL_SRV_C).
  1964. *
  1965. * \deprecated This option is deprecated and will be removed in a future
  1966. * version of Mbed TLS.
  1967. *
  1968. * Uncomment this macro to enable support for SSLv2 Client Hello messages.
  1969. */
  1970. //#define MBEDTLS_SSL_SRV_SUPPORT_SSLV2_CLIENT_HELLO
  1971. /**
  1972. * \def MBEDTLS_SSL_SRV_RESPECT_CLIENT_PREFERENCE
  1973. *
  1974. * Pick the ciphersuite according to the client's preferences rather than ours
  1975. * in the SSL Server module (MBEDTLS_SSL_SRV_C).
  1976. *
  1977. * Uncomment this macro to respect client's ciphersuite order
  1978. */
  1979. //#define MBEDTLS_SSL_SRV_RESPECT_CLIENT_PREFERENCE
  1980. /**
  1981. * \def MBEDTLS_SSL_MAX_FRAGMENT_LENGTH
  1982. *
  1983. * Enable support for RFC 6066 max_fragment_length extension in SSL.
  1984. *
  1985. * Comment this macro to disable support for the max_fragment_length extension
  1986. */
  1987. #define MBEDTLS_SSL_MAX_FRAGMENT_LENGTH
  1988. /**
  1989. * \def MBEDTLS_SSL_PROTO_SSL3
  1990. *
  1991. * Enable support for SSL 3.0.
  1992. *
  1993. * Requires: MBEDTLS_MD5_C
  1994. * MBEDTLS_SHA1_C
  1995. *
  1996. * \deprecated This option is deprecated and will be removed in a future
  1997. * version of Mbed TLS.
  1998. *
  1999. * Comment this macro to disable support for SSL 3.0
  2000. */
  2001. //#define MBEDTLS_SSL_PROTO_SSL3
  2002. /**
  2003. * \def MBEDTLS_SSL_PROTO_TLS1
  2004. *
  2005. * Enable support for TLS 1.0.
  2006. *
  2007. * Requires: MBEDTLS_MD5_C
  2008. * MBEDTLS_SHA1_C
  2009. *
  2010. * Comment this macro to disable support for TLS 1.0
  2011. */
  2012. #define MBEDTLS_SSL_PROTO_TLS1
  2013. /**
  2014. * \def MBEDTLS_SSL_PROTO_TLS1_1
  2015. *
  2016. * Enable support for TLS 1.1 (and DTLS 1.0 if DTLS is enabled).
  2017. *
  2018. * Requires: MBEDTLS_MD5_C
  2019. * MBEDTLS_SHA1_C
  2020. *
  2021. * Comment this macro to disable support for TLS 1.1 / DTLS 1.0
  2022. */
  2023. #define MBEDTLS_SSL_PROTO_TLS1_1
  2024. /**
  2025. * \def MBEDTLS_SSL_PROTO_TLS1_2
  2026. *
  2027. * Enable support for TLS 1.2 (and DTLS 1.2 if DTLS is enabled).
  2028. *
  2029. * Requires: MBEDTLS_SHA1_C or MBEDTLS_SHA256_C or MBEDTLS_SHA512_C
  2030. * (Depends on ciphersuites)
  2031. *
  2032. * Comment this macro to disable support for TLS 1.2 / DTLS 1.2
  2033. */
  2034. #define MBEDTLS_SSL_PROTO_TLS1_2
  2035. /**
  2036. * \def MBEDTLS_SSL_PROTO_TLS1_3_EXPERIMENTAL
  2037. *
  2038. * This macro is used to selectively enable experimental parts
  2039. * of the code that contribute to the ongoing development of
  2040. * the prototype TLS 1.3 and DTLS 1.3 implementation, and provide
  2041. * no other purpose.
  2042. *
  2043. * \warning TLS 1.3 and DTLS 1.3 aren't yet supported in Mbed TLS,
  2044. * and no feature exposed through this macro is part of the
  2045. * public API. In particular, features under the control
  2046. * of this macro are experimental and don't come with any
  2047. * stability guarantees.
  2048. *
  2049. * Uncomment this macro to enable experimental and partial
  2050. * functionality specific to TLS 1.3.
  2051. */
  2052. //#define MBEDTLS_SSL_PROTO_TLS1_3_EXPERIMENTAL
  2053. /**
  2054. * \def MBEDTLS_SSL_PROTO_DTLS
  2055. *
  2056. * Enable support for DTLS (all available versions).
  2057. *
  2058. * Enable this and MBEDTLS_SSL_PROTO_TLS1_1 to enable DTLS 1.0,
  2059. * and/or this and MBEDTLS_SSL_PROTO_TLS1_2 to enable DTLS 1.2.
  2060. *
  2061. * Requires: MBEDTLS_SSL_PROTO_TLS1_1
  2062. * or MBEDTLS_SSL_PROTO_TLS1_2
  2063. *
  2064. * Comment this macro to disable support for DTLS
  2065. */
  2066. #define MBEDTLS_SSL_PROTO_DTLS
  2067. /**
  2068. * \def MBEDTLS_SSL_ALPN
  2069. *
  2070. * Enable support for RFC 7301 Application Layer Protocol Negotiation.
  2071. *
  2072. * Comment this macro to disable support for ALPN.
  2073. */
  2074. #define MBEDTLS_SSL_ALPN
  2075. /**
  2076. * \def MBEDTLS_SSL_DTLS_ANTI_REPLAY
  2077. *
  2078. * Enable support for the anti-replay mechanism in DTLS.
  2079. *
  2080. * Requires: MBEDTLS_SSL_TLS_C
  2081. * MBEDTLS_SSL_PROTO_DTLS
  2082. *
  2083. * \warning Disabling this is often a security risk!
  2084. * See mbedtls_ssl_conf_dtls_anti_replay() for details.
  2085. *
  2086. * Comment this to disable anti-replay in DTLS.
  2087. */
  2088. #define MBEDTLS_SSL_DTLS_ANTI_REPLAY
  2089. /**
  2090. * \def MBEDTLS_SSL_DTLS_HELLO_VERIFY
  2091. *
  2092. * Enable support for HelloVerifyRequest on DTLS servers.
  2093. *
  2094. * This feature is highly recommended to prevent DTLS servers being used as
  2095. * amplifiers in DoS attacks against other hosts. It should always be enabled
  2096. * unless you know for sure amplification cannot be a problem in the
  2097. * environment in which your server operates.
  2098. *
  2099. * \warning Disabling this can ba a security risk! (see above)
  2100. *
  2101. * Requires: MBEDTLS_SSL_PROTO_DTLS
  2102. *
  2103. * Comment this to disable support for HelloVerifyRequest.
  2104. */
  2105. #define MBEDTLS_SSL_DTLS_HELLO_VERIFY
  2106. /**
  2107. * \def MBEDTLS_SSL_DTLS_SRTP
  2108. *
  2109. * Enable support for negotiation of DTLS-SRTP (RFC 5764)
  2110. * through the use_srtp extension.
  2111. *
  2112. * \note This feature provides the minimum functionality required
  2113. * to negotiate the use of DTLS-SRTP and to allow the derivation of
  2114. * the associated SRTP packet protection key material.
  2115. * In particular, the SRTP packet protection itself, as well as the
  2116. * demultiplexing of RTP and DTLS packets at the datagram layer
  2117. * (see Section 5 of RFC 5764), are not handled by this feature.
  2118. * Instead, after successful completion of a handshake negotiating
  2119. * the use of DTLS-SRTP, the extended key exporter API
  2120. * mbedtls_ssl_conf_export_keys_ext_cb() should be used to implement
  2121. * the key exporter described in Section 4.2 of RFC 5764 and RFC 5705
  2122. * (this is implemented in the SSL example programs).
  2123. * The resulting key should then be passed to an SRTP stack.
  2124. *
  2125. * Setting this option enables the runtime API
  2126. * mbedtls_ssl_conf_dtls_srtp_protection_profiles()
  2127. * through which the supported DTLS-SRTP protection
  2128. * profiles can be configured. You must call this API at
  2129. * runtime if you wish to negotiate the use of DTLS-SRTP.
  2130. *
  2131. * Requires: MBEDTLS_SSL_PROTO_DTLS
  2132. *
  2133. * Uncomment this to enable support for use_srtp extension.
  2134. */
  2135. //#define MBEDTLS_SSL_DTLS_SRTP
  2136. /**
  2137. * \def MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE
  2138. *
  2139. * Enable server-side support for clients that reconnect from the same port.
  2140. *
  2141. * Some clients unexpectedly close the connection and try to reconnect using the
  2142. * same source port. This needs special support from the server to handle the
  2143. * new connection securely, as described in section 4.2.8 of RFC 6347. This
  2144. * flag enables that support.
  2145. *
  2146. * Requires: MBEDTLS_SSL_DTLS_HELLO_VERIFY
  2147. *
  2148. * Comment this to disable support for clients reusing the source port.
  2149. */
  2150. #define MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE
  2151. /**
  2152. * \def MBEDTLS_SSL_DTLS_BADMAC_LIMIT
  2153. *
  2154. * Enable support for a limit of records with bad MAC.
  2155. *
  2156. * See mbedtls_ssl_conf_dtls_badmac_limit().
  2157. *
  2158. * Requires: MBEDTLS_SSL_PROTO_DTLS
  2159. */
  2160. #define MBEDTLS_SSL_DTLS_BADMAC_LIMIT
  2161. /**
  2162. * \def MBEDTLS_SSL_SESSION_TICKETS
  2163. *
  2164. * Enable support for RFC 5077 session tickets in SSL.
  2165. * Client-side, provides full support for session tickets (maintenance of a
  2166. * session store remains the responsibility of the application, though).
  2167. * Server-side, you also need to provide callbacks for writing and parsing
  2168. * tickets, including authenticated encryption and key management. Example
  2169. * callbacks are provided by MBEDTLS_SSL_TICKET_C.
  2170. *
  2171. * Comment this macro to disable support for SSL session tickets
  2172. */
  2173. #define MBEDTLS_SSL_SESSION_TICKETS
  2174. /**
  2175. * \def MBEDTLS_SSL_EXPORT_KEYS
  2176. *
  2177. * Enable support for exporting key block and master secret.
  2178. * This is required for certain users of TLS, e.g. EAP-TLS.
  2179. *
  2180. * Comment this macro to disable support for key export
  2181. */
  2182. #define MBEDTLS_SSL_EXPORT_KEYS
  2183. /**
  2184. * \def MBEDTLS_SSL_SERVER_NAME_INDICATION
  2185. *
  2186. * Enable support for RFC 6066 server name indication (SNI) in SSL.
  2187. *
  2188. * Requires: MBEDTLS_X509_CRT_PARSE_C
  2189. *
  2190. * Comment this macro to disable support for server name indication in SSL
  2191. */
  2192. #define MBEDTLS_SSL_SERVER_NAME_INDICATION
  2193. /**
  2194. * \def MBEDTLS_SSL_TRUNCATED_HMAC
  2195. *
  2196. * Enable support for RFC 6066 truncated HMAC in SSL.
  2197. *
  2198. * Comment this macro to disable support for truncated HMAC in SSL
  2199. */
  2200. #define MBEDTLS_SSL_TRUNCATED_HMAC
  2201. /**
  2202. * \def MBEDTLS_SSL_TRUNCATED_HMAC_COMPAT
  2203. *
  2204. * Fallback to old (pre-2.7), non-conforming implementation of the truncated
  2205. * HMAC extension which also truncates the HMAC key. Note that this option is
  2206. * only meant for a transitory upgrade period and will be removed in a future
  2207. * version of the library.
  2208. *
  2209. * \warning The old implementation is non-compliant and has a security weakness
  2210. * (2^80 brute force attack on the HMAC key used for a single,
  2211. * uninterrupted connection). This should only be enabled temporarily
  2212. * when (1) the use of truncated HMAC is essential in order to save
  2213. * bandwidth, and (2) the peer is an Mbed TLS stack that doesn't use
  2214. * the fixed implementation yet (pre-2.7).
  2215. *
  2216. * \deprecated This option is deprecated and will be removed in a
  2217. * future version of Mbed TLS.
  2218. *
  2219. * Uncomment to fallback to old, non-compliant truncated HMAC implementation.
  2220. *
  2221. * Requires: MBEDTLS_SSL_TRUNCATED_HMAC
  2222. */
  2223. //#define MBEDTLS_SSL_TRUNCATED_HMAC_COMPAT
  2224. /**
  2225. * \def MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH
  2226. *
  2227. * When this option is enabled, the SSL buffer will be resized automatically
  2228. * based on the negotiated maximum fragment length in each direction.
  2229. *
  2230. * Requires: MBEDTLS_SSL_MAX_FRAGMENT_LENGTH
  2231. */
  2232. //#define MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH
  2233. /**
  2234. * \def MBEDTLS_TEST_CONSTANT_FLOW_MEMSAN
  2235. *
  2236. * Enable testing of the constant-flow nature of some sensitive functions with
  2237. * clang's MemorySanitizer. This causes some existing tests to also test
  2238. * this non-functional property of the code under test.
  2239. *
  2240. * This setting requires compiling with clang -fsanitize=memory. The test
  2241. * suites can then be run normally.
  2242. *
  2243. * \warning This macro is only used for extended testing; it is not considered
  2244. * part of the library's API, so it may change or disappear at any time.
  2245. *
  2246. * Uncomment to enable testing of the constant-flow nature of selected code.
  2247. */
  2248. //#define MBEDTLS_TEST_CONSTANT_FLOW_MEMSAN
  2249. /**
  2250. * \def MBEDTLS_TEST_CONSTANT_FLOW_VALGRIND
  2251. *
  2252. * Enable testing of the constant-flow nature of some sensitive functions with
  2253. * valgrind's memcheck tool. This causes some existing tests to also test
  2254. * this non-functional property of the code under test.
  2255. *
  2256. * This setting requires valgrind headers for building, and is only useful for
  2257. * testing if the tests suites are run with valgrind's memcheck. This can be
  2258. * done for an individual test suite with 'valgrind ./test_suite_xxx', or when
  2259. * using CMake, this can be done for all test suites with 'make memcheck'.
  2260. *
  2261. * \warning This macro is only used for extended testing; it is not considered
  2262. * part of the library's API, so it may change or disappear at any time.
  2263. *
  2264. * Uncomment to enable testing of the constant-flow nature of selected code.
  2265. */
  2266. //#define MBEDTLS_TEST_CONSTANT_FLOW_VALGRIND
  2267. /**
  2268. * \def MBEDTLS_TEST_HOOKS
  2269. *
  2270. * Enable features for invasive testing such as introspection functions and
  2271. * hooks for fault injection. This enables additional unit tests.
  2272. *
  2273. * Merely enabling this feature should not change the behavior of the product.
  2274. * It only adds new code, and new branching points where the default behavior
  2275. * is the same as when this feature is disabled.
  2276. * However, this feature increases the attack surface: there is an added
  2277. * risk of vulnerabilities, and more gadgets that can make exploits easier.
  2278. * Therefore this feature must never be enabled in production.
  2279. *
  2280. * See `docs/architecture/testing/mbed-crypto-invasive-testing.md` for more
  2281. * information.
  2282. *
  2283. * Uncomment to enable invasive tests.
  2284. */
  2285. //#define MBEDTLS_TEST_HOOKS
  2286. /**
  2287. * \def MBEDTLS_THREADING_ALT
  2288. *
  2289. * Provide your own alternate threading implementation.
  2290. *
  2291. * Requires: MBEDTLS_THREADING_C
  2292. *
  2293. * Uncomment this to allow your own alternate threading implementation.
  2294. */
  2295. //#define MBEDTLS_THREADING_ALT
  2296. /**
  2297. * \def MBEDTLS_THREADING_PTHREAD
  2298. *
  2299. * Enable the pthread wrapper layer for the threading layer.
  2300. *
  2301. * Requires: MBEDTLS_THREADING_C
  2302. *
  2303. * Uncomment this to enable pthread mutexes.
  2304. */
  2305. //#define MBEDTLS_THREADING_PTHREAD
  2306. /**
  2307. * \def MBEDTLS_USE_PSA_CRYPTO
  2308. *
  2309. * Make the X.509 and TLS library use PSA for cryptographic operations, and
  2310. * enable new APIs for using keys handled by PSA Crypto.
  2311. *
  2312. * \note Development of this option is currently in progress, and parts of Mbed
  2313. * TLS's X.509 and TLS modules are not ported to PSA yet. However, these parts
  2314. * will still continue to work as usual, so enabling this option should not
  2315. * break backwards compatibility.
  2316. *
  2317. * \note See docs/use-psa-crypto.md for a complete description of what this
  2318. * option currently does, and of parts that are not affected by it so far.
  2319. *
  2320. * \warning This option enables new Mbed TLS APIs which are currently
  2321. * considered experimental and may change in incompatible ways at any time.
  2322. * That is, the APIs enabled by this option are not covered by the usual
  2323. * promises of API stability.
  2324. *
  2325. * Requires: MBEDTLS_PSA_CRYPTO_C.
  2326. *
  2327. * Uncomment this to enable internal use of PSA Crypto and new associated APIs.
  2328. */
  2329. //#define MBEDTLS_USE_PSA_CRYPTO
  2330. /**
  2331. * \def MBEDTLS_PSA_CRYPTO_CONFIG
  2332. *
  2333. * This setting allows support for cryptographic mechanisms through the PSA
  2334. * API to be configured separately from support through the mbedtls API.
  2335. *
  2336. * Uncomment this to enable use of PSA Crypto configuration settings which
  2337. * can be found in include/psa/crypto_config.h.
  2338. *
  2339. * If you enable this option and write your own configuration file, you must
  2340. * include mbedtls/config_psa.h in your configuration file. The default
  2341. * provided mbedtls/config.h contains the necessary inclusion.
  2342. *
  2343. * This feature is still experimental and is not ready for production since
  2344. * it is not completed.
  2345. */
  2346. //#define MBEDTLS_PSA_CRYPTO_CONFIG
  2347. /**
  2348. * \def MBEDTLS_VERSION_FEATURES
  2349. *
  2350. * Allow run-time checking of compile-time enabled features. Thus allowing users
  2351. * to check at run-time if the library is for instance compiled with threading
  2352. * support via mbedtls_version_check_feature().
  2353. *
  2354. * Requires: MBEDTLS_VERSION_C
  2355. *
  2356. * Comment this to disable run-time checking and save ROM space
  2357. */
  2358. #define MBEDTLS_VERSION_FEATURES
  2359. /**
  2360. * \def MBEDTLS_X509_ALLOW_EXTENSIONS_NON_V3
  2361. *
  2362. * If set, the X509 parser will not break-off when parsing an X509 certificate
  2363. * and encountering an extension in a v1 or v2 certificate.
  2364. *
  2365. * Uncomment to prevent an error.
  2366. */
  2367. //#define MBEDTLS_X509_ALLOW_EXTENSIONS_NON_V3
  2368. /**
  2369. * \def MBEDTLS_X509_ALLOW_UNSUPPORTED_CRITICAL_EXTENSION
  2370. *
  2371. * If set, the X509 parser will not break-off when parsing an X509 certificate
  2372. * and encountering an unknown critical extension.
  2373. *
  2374. * \warning Depending on your PKI use, enabling this can be a security risk!
  2375. *
  2376. * Uncomment to prevent an error.
  2377. */
  2378. //#define MBEDTLS_X509_ALLOW_UNSUPPORTED_CRITICAL_EXTENSION
  2379. /**
  2380. * \def MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK
  2381. *
  2382. * If set, this enables the X.509 API `mbedtls_x509_crt_verify_with_ca_cb()`
  2383. * and the SSL API `mbedtls_ssl_conf_ca_cb()` which allow users to configure
  2384. * the set of trusted certificates through a callback instead of a linked
  2385. * list.
  2386. *
  2387. * This is useful for example in environments where a large number of trusted
  2388. * certificates is present and storing them in a linked list isn't efficient
  2389. * enough, or when the set of trusted certificates changes frequently.
  2390. *
  2391. * See the documentation of `mbedtls_x509_crt_verify_with_ca_cb()` and
  2392. * `mbedtls_ssl_conf_ca_cb()` for more information.
  2393. *
  2394. * Uncomment to enable trusted certificate callbacks.
  2395. */
  2396. //#define MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK
  2397. /**
  2398. * \def MBEDTLS_X509_CHECK_KEY_USAGE
  2399. *
  2400. * Enable verification of the keyUsage extension (CA and leaf certificates).
  2401. *
  2402. * Disabling this avoids problems with mis-issued and/or misused
  2403. * (intermediate) CA and leaf certificates.
  2404. *
  2405. * \warning Depending on your PKI use, disabling this can be a security risk!
  2406. *
  2407. * Comment to skip keyUsage checking for both CA and leaf certificates.
  2408. */
  2409. #define MBEDTLS_X509_CHECK_KEY_USAGE
  2410. /**
  2411. * \def MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE
  2412. *
  2413. * Enable verification of the extendedKeyUsage extension (leaf certificates).
  2414. *
  2415. * Disabling this avoids problems with mis-issued and/or misused certificates.
  2416. *
  2417. * \warning Depending on your PKI use, disabling this can be a security risk!
  2418. *
  2419. * Comment to skip extendedKeyUsage checking for certificates.
  2420. */
  2421. #define MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE
  2422. /**
  2423. * \def MBEDTLS_X509_RSASSA_PSS_SUPPORT
  2424. *
  2425. * Enable parsing and verification of X.509 certificates, CRLs and CSRS
  2426. * signed with RSASSA-PSS (aka PKCS#1 v2.1).
  2427. *
  2428. * Comment this macro to disallow using RSASSA-PSS in certificates.
  2429. */
  2430. #define MBEDTLS_X509_RSASSA_PSS_SUPPORT
  2431. /**
  2432. * \def MBEDTLS_ZLIB_SUPPORT
  2433. *
  2434. * If set, the SSL/TLS module uses ZLIB to support compression and
  2435. * decompression of packet data.
  2436. *
  2437. * \warning TLS-level compression MAY REDUCE SECURITY! See for example the
  2438. * CRIME attack. Before enabling this option, you should examine with care if
  2439. * CRIME or similar exploits may be applicable to your use case.
  2440. *
  2441. * \note Currently compression can't be used with DTLS.
  2442. *
  2443. * \deprecated This feature is deprecated and will be removed
  2444. * in the next major revision of the library.
  2445. *
  2446. * Used in: library/ssl_tls.c
  2447. * library/ssl_cli.c
  2448. * library/ssl_srv.c
  2449. *
  2450. * This feature requires zlib library and headers to be present.
  2451. *
  2452. * Uncomment to enable use of ZLIB
  2453. */
  2454. //#define MBEDTLS_ZLIB_SUPPORT
  2455. /* \} name SECTION: mbed TLS feature support */
  2456. /**
  2457. * \name SECTION: mbed TLS modules
  2458. *
  2459. * This section enables or disables entire modules in mbed TLS
  2460. * \{
  2461. */
  2462. /**
  2463. * \def MBEDTLS_AESNI_C
  2464. *
  2465. * Enable AES-NI support on x86-64.
  2466. *
  2467. * Module: library/aesni.c
  2468. * Caller: library/aes.c
  2469. *
  2470. * Requires: MBEDTLS_HAVE_ASM
  2471. *
  2472. * This modules adds support for the AES-NI instructions on x86-64
  2473. */
  2474. #define MBEDTLS_AESNI_C
  2475. /**
  2476. * \def MBEDTLS_AES_C
  2477. *
  2478. * Enable the AES block cipher.
  2479. *
  2480. * Module: library/aes.c
  2481. * Caller: library/cipher.c
  2482. * library/pem.c
  2483. * library/ctr_drbg.c
  2484. *
  2485. * This module enables the following ciphersuites (if other requisites are
  2486. * enabled as well):
  2487. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA
  2488. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA
  2489. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA
  2490. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA
  2491. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256
  2492. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384
  2493. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256
  2494. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384
  2495. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256
  2496. * MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384
  2497. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256
  2498. * MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384
  2499. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
  2500. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  2501. * MBEDTLS_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
  2502. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
  2503. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
  2504. * MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
  2505. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
  2506. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
  2507. * MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA
  2508. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
  2509. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  2510. * MBEDTLS_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
  2511. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
  2512. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
  2513. * MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
  2514. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
  2515. * MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
  2516. * MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA
  2517. * MBEDTLS_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384
  2518. * MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384
  2519. * MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384
  2520. * MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA
  2521. * MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA
  2522. * MBEDTLS_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256
  2523. * MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256
  2524. * MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256
  2525. * MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA
  2526. * MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA
  2527. * MBEDTLS_TLS_RSA_WITH_AES_256_GCM_SHA384
  2528. * MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA256
  2529. * MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA
  2530. * MBEDTLS_TLS_RSA_WITH_AES_128_GCM_SHA256
  2531. * MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA256
  2532. * MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA
  2533. * MBEDTLS_TLS_RSA_PSK_WITH_AES_256_GCM_SHA384
  2534. * MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA384
  2535. * MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA
  2536. * MBEDTLS_TLS_RSA_PSK_WITH_AES_128_GCM_SHA256
  2537. * MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA256
  2538. * MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA
  2539. * MBEDTLS_TLS_PSK_WITH_AES_256_GCM_SHA384
  2540. * MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA384
  2541. * MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA
  2542. * MBEDTLS_TLS_PSK_WITH_AES_128_GCM_SHA256
  2543. * MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA256
  2544. * MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA
  2545. *
  2546. * PEM_PARSE uses AES for decrypting encrypted keys.
  2547. */
  2548. #define MBEDTLS_AES_C
  2549. /**
  2550. * \def MBEDTLS_ARC4_C
  2551. *
  2552. * Enable the ARCFOUR stream cipher.
  2553. *
  2554. * Module: library/arc4.c
  2555. * Caller: library/cipher.c
  2556. *
  2557. * This module enables the following ciphersuites (if other requisites are
  2558. * enabled as well):
  2559. * MBEDTLS_TLS_ECDH_ECDSA_WITH_RC4_128_SHA
  2560. * MBEDTLS_TLS_ECDH_RSA_WITH_RC4_128_SHA
  2561. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA
  2562. * MBEDTLS_TLS_ECDHE_RSA_WITH_RC4_128_SHA
  2563. * MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA
  2564. * MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA
  2565. * MBEDTLS_TLS_RSA_WITH_RC4_128_SHA
  2566. * MBEDTLS_TLS_RSA_WITH_RC4_128_MD5
  2567. * MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA
  2568. * MBEDTLS_TLS_PSK_WITH_RC4_128_SHA
  2569. *
  2570. * \warning ARC4 is considered a weak cipher and its use constitutes a
  2571. * security risk. If possible, we recommend avoidng dependencies on
  2572. * it, and considering stronger ciphers instead.
  2573. *
  2574. */
  2575. #define MBEDTLS_ARC4_C
  2576. /**
  2577. * \def MBEDTLS_ASN1_PARSE_C
  2578. *
  2579. * Enable the generic ASN1 parser.
  2580. *
  2581. * Module: library/asn1.c
  2582. * Caller: library/x509.c
  2583. * library/dhm.c
  2584. * library/pkcs12.c
  2585. * library/pkcs5.c
  2586. * library/pkparse.c
  2587. */
  2588. #define MBEDTLS_ASN1_PARSE_C
  2589. /**
  2590. * \def MBEDTLS_ASN1_WRITE_C
  2591. *
  2592. * Enable the generic ASN1 writer.
  2593. *
  2594. * Module: library/asn1write.c
  2595. * Caller: library/ecdsa.c
  2596. * library/pkwrite.c
  2597. * library/x509_create.c
  2598. * library/x509write_crt.c
  2599. * library/x509write_csr.c
  2600. */
  2601. #define MBEDTLS_ASN1_WRITE_C
  2602. /**
  2603. * \def MBEDTLS_BASE64_C
  2604. *
  2605. * Enable the Base64 module.
  2606. *
  2607. * Module: library/base64.c
  2608. * Caller: library/pem.c
  2609. *
  2610. * This module is required for PEM support (required by X.509).
  2611. */
  2612. #define MBEDTLS_BASE64_C
  2613. /**
  2614. * \def MBEDTLS_BIGNUM_C
  2615. *
  2616. * Enable the multi-precision integer library.
  2617. *
  2618. * Module: library/bignum.c
  2619. * Caller: library/dhm.c
  2620. * library/ecp.c
  2621. * library/ecdsa.c
  2622. * library/rsa.c
  2623. * library/rsa_internal.c
  2624. * library/ssl_tls.c
  2625. *
  2626. * This module is required for RSA, DHM and ECC (ECDH, ECDSA) support.
  2627. */
  2628. #define MBEDTLS_BIGNUM_C
  2629. /**
  2630. * \def MBEDTLS_BLOWFISH_C
  2631. *
  2632. * Enable the Blowfish block cipher.
  2633. *
  2634. * Module: library/blowfish.c
  2635. */
  2636. #define MBEDTLS_BLOWFISH_C
  2637. /**
  2638. * \def MBEDTLS_CAMELLIA_C
  2639. *
  2640. * Enable the Camellia block cipher.
  2641. *
  2642. * Module: library/camellia.c
  2643. * Caller: library/cipher.c
  2644. *
  2645. * This module enables the following ciphersuites (if other requisites are
  2646. * enabled as well):
  2647. * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256
  2648. * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384
  2649. * MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256
  2650. * MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384
  2651. * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256
  2652. * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384
  2653. * MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256
  2654. * MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384
  2655. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384
  2656. * MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384
  2657. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384
  2658. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384
  2659. * MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384
  2660. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
  2661. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
  2662. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256
  2663. * MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256
  2664. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256
  2665. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256
  2666. * MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
  2667. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
  2668. * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
  2669. * MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384
  2670. * MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384
  2671. * MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384
  2672. * MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256
  2673. * MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256
  2674. * MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256
  2675. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384
  2676. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256
  2677. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
  2678. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256
  2679. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
  2680. * MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
  2681. * MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384
  2682. * MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384
  2683. * MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256
  2684. * MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256
  2685. * MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_GCM_SHA384
  2686. * MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384
  2687. * MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256
  2688. * MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256
  2689. */
  2690. #define MBEDTLS_CAMELLIA_C
  2691. /**
  2692. * \def MBEDTLS_ARIA_C
  2693. *
  2694. * Enable the ARIA block cipher.
  2695. *
  2696. * Module: library/aria.c
  2697. * Caller: library/cipher.c
  2698. *
  2699. * This module enables the following ciphersuites (if other requisites are
  2700. * enabled as well):
  2701. *
  2702. * MBEDTLS_TLS_RSA_WITH_ARIA_128_CBC_SHA256
  2703. * MBEDTLS_TLS_RSA_WITH_ARIA_256_CBC_SHA384
  2704. * MBEDTLS_TLS_DHE_RSA_WITH_ARIA_128_CBC_SHA256
  2705. * MBEDTLS_TLS_DHE_RSA_WITH_ARIA_256_CBC_SHA384
  2706. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_ARIA_128_CBC_SHA256
  2707. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_ARIA_256_CBC_SHA384
  2708. * MBEDTLS_TLS_ECDH_ECDSA_WITH_ARIA_128_CBC_SHA256
  2709. * MBEDTLS_TLS_ECDH_ECDSA_WITH_ARIA_256_CBC_SHA384
  2710. * MBEDTLS_TLS_ECDHE_RSA_WITH_ARIA_128_CBC_SHA256
  2711. * MBEDTLS_TLS_ECDHE_RSA_WITH_ARIA_256_CBC_SHA384
  2712. * MBEDTLS_TLS_ECDH_RSA_WITH_ARIA_128_CBC_SHA256
  2713. * MBEDTLS_TLS_ECDH_RSA_WITH_ARIA_256_CBC_SHA384
  2714. * MBEDTLS_TLS_RSA_WITH_ARIA_128_GCM_SHA256
  2715. * MBEDTLS_TLS_RSA_WITH_ARIA_256_GCM_SHA384
  2716. * MBEDTLS_TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256
  2717. * MBEDTLS_TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384
  2718. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256
  2719. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384
  2720. * MBEDTLS_TLS_ECDH_ECDSA_WITH_ARIA_128_GCM_SHA256
  2721. * MBEDTLS_TLS_ECDH_ECDSA_WITH_ARIA_256_GCM_SHA384
  2722. * MBEDTLS_TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256
  2723. * MBEDTLS_TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384
  2724. * MBEDTLS_TLS_ECDH_RSA_WITH_ARIA_128_GCM_SHA256
  2725. * MBEDTLS_TLS_ECDH_RSA_WITH_ARIA_256_GCM_SHA384
  2726. * MBEDTLS_TLS_PSK_WITH_ARIA_128_CBC_SHA256
  2727. * MBEDTLS_TLS_PSK_WITH_ARIA_256_CBC_SHA384
  2728. * MBEDTLS_TLS_DHE_PSK_WITH_ARIA_128_CBC_SHA256
  2729. * MBEDTLS_TLS_DHE_PSK_WITH_ARIA_256_CBC_SHA384
  2730. * MBEDTLS_TLS_RSA_PSK_WITH_ARIA_128_CBC_SHA256
  2731. * MBEDTLS_TLS_RSA_PSK_WITH_ARIA_256_CBC_SHA384
  2732. * MBEDTLS_TLS_PSK_WITH_ARIA_128_GCM_SHA256
  2733. * MBEDTLS_TLS_PSK_WITH_ARIA_256_GCM_SHA384
  2734. * MBEDTLS_TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256
  2735. * MBEDTLS_TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384
  2736. * MBEDTLS_TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256
  2737. * MBEDTLS_TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384
  2738. * MBEDTLS_TLS_ECDHE_PSK_WITH_ARIA_128_CBC_SHA256
  2739. * MBEDTLS_TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384
  2740. */
  2741. //#define MBEDTLS_ARIA_C
  2742. /**
  2743. * \def MBEDTLS_CCM_C
  2744. *
  2745. * Enable the Counter with CBC-MAC (CCM) mode for 128-bit block cipher.
  2746. *
  2747. * Module: library/ccm.c
  2748. *
  2749. * Requires: MBEDTLS_AES_C or MBEDTLS_CAMELLIA_C
  2750. *
  2751. * This module enables the AES-CCM ciphersuites, if other requisites are
  2752. * enabled as well.
  2753. */
  2754. #define MBEDTLS_CCM_C
  2755. /**
  2756. * \def MBEDTLS_CERTS_C
  2757. *
  2758. * Enable the test certificates.
  2759. *
  2760. * Module: library/certs.c
  2761. * Caller:
  2762. *
  2763. * This module is used for testing (ssl_client/server).
  2764. */
  2765. #define MBEDTLS_CERTS_C
  2766. /**
  2767. * \def MBEDTLS_CHACHA20_C
  2768. *
  2769. * Enable the ChaCha20 stream cipher.
  2770. *
  2771. * Module: library/chacha20.c
  2772. */
  2773. #define MBEDTLS_CHACHA20_C
  2774. /**
  2775. * \def MBEDTLS_CHACHAPOLY_C
  2776. *
  2777. * Enable the ChaCha20-Poly1305 AEAD algorithm.
  2778. *
  2779. * Module: library/chachapoly.c
  2780. *
  2781. * This module requires: MBEDTLS_CHACHA20_C, MBEDTLS_POLY1305_C
  2782. */
  2783. #define MBEDTLS_CHACHAPOLY_C
  2784. /**
  2785. * \def MBEDTLS_CIPHER_C
  2786. *
  2787. * Enable the generic cipher layer.
  2788. *
  2789. * Module: library/cipher.c
  2790. * Caller: library/ssl_tls.c
  2791. *
  2792. * Uncomment to enable generic cipher wrappers.
  2793. */
  2794. #define MBEDTLS_CIPHER_C
  2795. /**
  2796. * \def MBEDTLS_CMAC_C
  2797. *
  2798. * Enable the CMAC (Cipher-based Message Authentication Code) mode for block
  2799. * ciphers.
  2800. *
  2801. * \note When #MBEDTLS_CMAC_ALT is active, meaning that the underlying
  2802. * implementation of the CMAC algorithm is provided by an alternate
  2803. * implementation, that alternate implementation may opt to not support
  2804. * AES-192 or 3DES as underlying block ciphers for the CMAC operation.
  2805. *
  2806. * Module: library/cmac.c
  2807. *
  2808. * Requires: MBEDTLS_AES_C or MBEDTLS_DES_C
  2809. *
  2810. */
  2811. //#define MBEDTLS_CMAC_C
  2812. /**
  2813. * \def MBEDTLS_CTR_DRBG_C
  2814. *
  2815. * Enable the CTR_DRBG AES-based random generator.
  2816. * The CTR_DRBG generator uses AES-256 by default.
  2817. * To use AES-128 instead, enable \c MBEDTLS_CTR_DRBG_USE_128_BIT_KEY above.
  2818. *
  2819. * \note To achieve a 256-bit security strength with CTR_DRBG,
  2820. * you must use AES-256 *and* use sufficient entropy.
  2821. * See ctr_drbg.h for more details.
  2822. *
  2823. * Module: library/ctr_drbg.c
  2824. * Caller:
  2825. *
  2826. * Requires: MBEDTLS_AES_C
  2827. *
  2828. * This module provides the CTR_DRBG AES random number generator.
  2829. */
  2830. #define MBEDTLS_CTR_DRBG_C
  2831. /**
  2832. * \def MBEDTLS_DEBUG_C
  2833. *
  2834. * Enable the debug functions.
  2835. *
  2836. * Module: library/debug.c
  2837. * Caller: library/ssl_cli.c
  2838. * library/ssl_srv.c
  2839. * library/ssl_tls.c
  2840. *
  2841. * This module provides debugging functions.
  2842. */
  2843. #define MBEDTLS_DEBUG_C
  2844. /**
  2845. * \def MBEDTLS_DES_C
  2846. *
  2847. * Enable the DES block cipher.
  2848. *
  2849. * Module: library/des.c
  2850. * Caller: library/pem.c
  2851. * library/cipher.c
  2852. *
  2853. * This module enables the following ciphersuites (if other requisites are
  2854. * enabled as well):
  2855. * MBEDTLS_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA
  2856. * MBEDTLS_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA
  2857. * MBEDTLS_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA
  2858. * MBEDTLS_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
  2859. * MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
  2860. * MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA
  2861. * MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA
  2862. * MBEDTLS_TLS_RSA_WITH_3DES_EDE_CBC_SHA
  2863. * MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA
  2864. * MBEDTLS_TLS_PSK_WITH_3DES_EDE_CBC_SHA
  2865. *
  2866. * PEM_PARSE uses DES/3DES for decrypting encrypted keys.
  2867. *
  2868. * \warning DES is considered a weak cipher and its use constitutes a
  2869. * security risk. We recommend considering stronger ciphers instead.
  2870. */
  2871. #define MBEDTLS_DES_C
  2872. /**
  2873. * \def MBEDTLS_DHM_C
  2874. *
  2875. * Enable the Diffie-Hellman-Merkle module.
  2876. *
  2877. * Module: library/dhm.c
  2878. * Caller: library/ssl_cli.c
  2879. * library/ssl_srv.c
  2880. *
  2881. * This module is used by the following key exchanges:
  2882. * DHE-RSA, DHE-PSK
  2883. *
  2884. * \warning Using DHE constitutes a security risk as it
  2885. * is not possible to validate custom DH parameters.
  2886. * If possible, it is recommended users should consider
  2887. * preferring other methods of key exchange.
  2888. * See dhm.h for more details.
  2889. *
  2890. */
  2891. #define MBEDTLS_DHM_C
  2892. /**
  2893. * \def MBEDTLS_ECDH_C
  2894. *
  2895. * Enable the elliptic curve Diffie-Hellman library.
  2896. *
  2897. * Module: library/ecdh.c
  2898. * Caller: library/ssl_cli.c
  2899. * library/ssl_srv.c
  2900. *
  2901. * This module is used by the following key exchanges:
  2902. * ECDHE-ECDSA, ECDHE-RSA, DHE-PSK
  2903. *
  2904. * Requires: MBEDTLS_ECP_C
  2905. */
  2906. #define MBEDTLS_ECDH_C
  2907. /**
  2908. * \def MBEDTLS_ECDSA_C
  2909. *
  2910. * Enable the elliptic curve DSA library.
  2911. *
  2912. * Module: library/ecdsa.c
  2913. * Caller:
  2914. *
  2915. * This module is used by the following key exchanges:
  2916. * ECDHE-ECDSA
  2917. *
  2918. * Requires: MBEDTLS_ECP_C, MBEDTLS_ASN1_WRITE_C, MBEDTLS_ASN1_PARSE_C,
  2919. * and at least one MBEDTLS_ECP_DP_XXX_ENABLED for a
  2920. * short Weierstrass curve.
  2921. */
  2922. #define MBEDTLS_ECDSA_C
  2923. /**
  2924. * \def MBEDTLS_ECJPAKE_C
  2925. *
  2926. * Enable the elliptic curve J-PAKE library.
  2927. *
  2928. * \warning This is currently experimental. EC J-PAKE support is based on the
  2929. * Thread v1.0.0 specification; incompatible changes to the specification
  2930. * might still happen. For this reason, this is disabled by default.
  2931. *
  2932. * Module: library/ecjpake.c
  2933. * Caller:
  2934. *
  2935. * This module is used by the following key exchanges:
  2936. * ECJPAKE
  2937. *
  2938. * Requires: MBEDTLS_ECP_C, MBEDTLS_MD_C
  2939. */
  2940. //#define MBEDTLS_ECJPAKE_C
  2941. /**
  2942. * \def MBEDTLS_ECP_C
  2943. *
  2944. * Enable the elliptic curve over GF(p) library.
  2945. *
  2946. * Module: library/ecp.c
  2947. * Caller: library/ecdh.c
  2948. * library/ecdsa.c
  2949. * library/ecjpake.c
  2950. *
  2951. * Requires: MBEDTLS_BIGNUM_C and at least one MBEDTLS_ECP_DP_XXX_ENABLED
  2952. */
  2953. #define MBEDTLS_ECP_C
  2954. /**
  2955. * \def MBEDTLS_ENTROPY_C
  2956. *
  2957. * Enable the platform-specific entropy code.
  2958. *
  2959. * Module: library/entropy.c
  2960. * Caller:
  2961. *
  2962. * Requires: MBEDTLS_SHA512_C or MBEDTLS_SHA256_C
  2963. *
  2964. * This module provides a generic entropy pool
  2965. */
  2966. #define MBEDTLS_ENTROPY_C
  2967. /**
  2968. * \def MBEDTLS_ERROR_C
  2969. *
  2970. * Enable error code to error string conversion.
  2971. *
  2972. * Module: library/error.c
  2973. * Caller:
  2974. *
  2975. * This module enables mbedtls_strerror().
  2976. */
  2977. #define MBEDTLS_ERROR_C
  2978. /**
  2979. * \def MBEDTLS_GCM_C
  2980. *
  2981. * Enable the Galois/Counter Mode (GCM).
  2982. *
  2983. * Module: library/gcm.c
  2984. *
  2985. * Requires: MBEDTLS_AES_C or MBEDTLS_CAMELLIA_C or MBEDTLS_ARIA_C
  2986. *
  2987. * This module enables the AES-GCM and CAMELLIA-GCM ciphersuites, if other
  2988. * requisites are enabled as well.
  2989. */
  2990. #define MBEDTLS_GCM_C
  2991. /**
  2992. * \def MBEDTLS_HAVEGE_C
  2993. *
  2994. * Enable the HAVEGE random generator.
  2995. *
  2996. * Warning: the HAVEGE random generator is not suitable for virtualized
  2997. * environments
  2998. *
  2999. * Warning: the HAVEGE random generator is dependent on timing and specific
  3000. * processor traits. It is therefore not advised to use HAVEGE as
  3001. * your applications primary random generator or primary entropy pool
  3002. * input. As a secondary input to your entropy pool, it IS able add
  3003. * the (limited) extra entropy it provides.
  3004. *
  3005. * Module: library/havege.c
  3006. * Caller:
  3007. *
  3008. * Requires: MBEDTLS_TIMING_C
  3009. *
  3010. * Uncomment to enable the HAVEGE random generator.
  3011. */
  3012. //#define MBEDTLS_HAVEGE_C
  3013. /**
  3014. * \def MBEDTLS_HKDF_C
  3015. *
  3016. * Enable the HKDF algorithm (RFC 5869).
  3017. *
  3018. * Module: library/hkdf.c
  3019. * Caller:
  3020. *
  3021. * Requires: MBEDTLS_MD_C
  3022. *
  3023. * This module adds support for the Hashed Message Authentication Code
  3024. * (HMAC)-based key derivation function (HKDF).
  3025. */
  3026. #define MBEDTLS_HKDF_C
  3027. /**
  3028. * \def MBEDTLS_HMAC_DRBG_C
  3029. *
  3030. * Enable the HMAC_DRBG random generator.
  3031. *
  3032. * Module: library/hmac_drbg.c
  3033. * Caller:
  3034. *
  3035. * Requires: MBEDTLS_MD_C
  3036. *
  3037. * Uncomment to enable the HMAC_DRBG random number geerator.
  3038. */
  3039. #define MBEDTLS_HMAC_DRBG_C
  3040. /**
  3041. * \def MBEDTLS_NIST_KW_C
  3042. *
  3043. * Enable the Key Wrapping mode for 128-bit block ciphers,
  3044. * as defined in NIST SP 800-38F. Only KW and KWP modes
  3045. * are supported. At the moment, only AES is approved by NIST.
  3046. *
  3047. * Module: library/nist_kw.c
  3048. *
  3049. * Requires: MBEDTLS_AES_C and MBEDTLS_CIPHER_C
  3050. */
  3051. //#define MBEDTLS_NIST_KW_C
  3052. /**
  3053. * \def MBEDTLS_MD_C
  3054. *
  3055. * Enable the generic message digest layer.
  3056. *
  3057. * Module: library/md.c
  3058. * Caller:
  3059. *
  3060. * Uncomment to enable generic message digest wrappers.
  3061. */
  3062. #define MBEDTLS_MD_C
  3063. /**
  3064. * \def MBEDTLS_MD2_C
  3065. *
  3066. * Enable the MD2 hash algorithm.
  3067. *
  3068. * Module: library/md2.c
  3069. * Caller:
  3070. *
  3071. * Uncomment to enable support for (rare) MD2-signed X.509 certs.
  3072. *
  3073. * \warning MD2 is considered a weak message digest and its use constitutes a
  3074. * security risk. If possible, we recommend avoiding dependencies on
  3075. * it, and considering stronger message digests instead.
  3076. *
  3077. */
  3078. //#define MBEDTLS_MD2_C
  3079. /**
  3080. * \def MBEDTLS_MD4_C
  3081. *
  3082. * Enable the MD4 hash algorithm.
  3083. *
  3084. * Module: library/md4.c
  3085. * Caller:
  3086. *
  3087. * Uncomment to enable support for (rare) MD4-signed X.509 certs.
  3088. *
  3089. * \warning MD4 is considered a weak message digest and its use constitutes a
  3090. * security risk. If possible, we recommend avoiding dependencies on
  3091. * it, and considering stronger message digests instead.
  3092. *
  3093. */
  3094. //#define MBEDTLS_MD4_C
  3095. /**
  3096. * \def MBEDTLS_MD5_C
  3097. *
  3098. * Enable the MD5 hash algorithm.
  3099. *
  3100. * Module: library/md5.c
  3101. * Caller: library/md.c
  3102. * library/pem.c
  3103. * library/ssl_tls.c
  3104. *
  3105. * This module is required for SSL/TLS up to version 1.1, and for TLS 1.2
  3106. * depending on the handshake parameters. Further, it is used for checking
  3107. * MD5-signed certificates, and for PBKDF1 when decrypting PEM-encoded
  3108. * encrypted keys.
  3109. *
  3110. * \warning MD5 is considered a weak message digest and its use constitutes a
  3111. * security risk. If possible, we recommend avoiding dependencies on
  3112. * it, and considering stronger message digests instead.
  3113. *
  3114. */
  3115. #define MBEDTLS_MD5_C
  3116. /**
  3117. * \def MBEDTLS_MEMORY_BUFFER_ALLOC_C
  3118. *
  3119. * Enable the buffer allocator implementation that makes use of a (stack)
  3120. * based buffer to 'allocate' dynamic memory. (replaces calloc() and free()
  3121. * calls)
  3122. *
  3123. * Module: library/memory_buffer_alloc.c
  3124. *
  3125. * Requires: MBEDTLS_PLATFORM_C
  3126. * MBEDTLS_PLATFORM_MEMORY (to use it within mbed TLS)
  3127. *
  3128. * Enable this module to enable the buffer memory allocator.
  3129. */
  3130. //#define MBEDTLS_MEMORY_BUFFER_ALLOC_C
  3131. /**
  3132. * \def MBEDTLS_NET_C
  3133. *
  3134. * Enable the TCP and UDP over IPv6/IPv4 networking routines.
  3135. *
  3136. * \note This module only works on POSIX/Unix (including Linux, BSD and OS X)
  3137. * and Windows. For other platforms, you'll want to disable it, and write your
  3138. * own networking callbacks to be passed to \c mbedtls_ssl_set_bio().
  3139. *
  3140. * \note See also our Knowledge Base article about porting to a new
  3141. * environment:
  3142. * https://tls.mbed.org/kb/how-to/how-do-i-port-mbed-tls-to-a-new-environment-OS
  3143. *
  3144. * Module: library/net_sockets.c
  3145. *
  3146. * This module provides networking routines.
  3147. */
  3148. #define MBEDTLS_NET_C
  3149. /**
  3150. * \def MBEDTLS_OID_C
  3151. *
  3152. * Enable the OID database.
  3153. *
  3154. * Module: library/oid.c
  3155. * Caller: library/asn1write.c
  3156. * library/pkcs5.c
  3157. * library/pkparse.c
  3158. * library/pkwrite.c
  3159. * library/rsa.c
  3160. * library/x509.c
  3161. * library/x509_create.c
  3162. * library/x509_crl.c
  3163. * library/x509_crt.c
  3164. * library/x509_csr.c
  3165. * library/x509write_crt.c
  3166. * library/x509write_csr.c
  3167. *
  3168. * This modules translates between OIDs and internal values.
  3169. */
  3170. #define MBEDTLS_OID_C
  3171. /**
  3172. * \def MBEDTLS_PADLOCK_C
  3173. *
  3174. * Enable VIA Padlock support on x86.
  3175. *
  3176. * Module: library/padlock.c
  3177. * Caller: library/aes.c
  3178. *
  3179. * Requires: MBEDTLS_HAVE_ASM
  3180. *
  3181. * This modules adds support for the VIA PadLock on x86.
  3182. */
  3183. #define MBEDTLS_PADLOCK_C
  3184. /**
  3185. * \def MBEDTLS_PEM_PARSE_C
  3186. *
  3187. * Enable PEM decoding / parsing.
  3188. *
  3189. * Module: library/pem.c
  3190. * Caller: library/dhm.c
  3191. * library/pkparse.c
  3192. * library/x509_crl.c
  3193. * library/x509_crt.c
  3194. * library/x509_csr.c
  3195. *
  3196. * Requires: MBEDTLS_BASE64_C
  3197. *
  3198. * This modules adds support for decoding / parsing PEM files.
  3199. */
  3200. #define MBEDTLS_PEM_PARSE_C
  3201. /**
  3202. * \def MBEDTLS_PEM_WRITE_C
  3203. *
  3204. * Enable PEM encoding / writing.
  3205. *
  3206. * Module: library/pem.c
  3207. * Caller: library/pkwrite.c
  3208. * library/x509write_crt.c
  3209. * library/x509write_csr.c
  3210. *
  3211. * Requires: MBEDTLS_BASE64_C
  3212. *
  3213. * This modules adds support for encoding / writing PEM files.
  3214. */
  3215. #define MBEDTLS_PEM_WRITE_C
  3216. /**
  3217. * \def MBEDTLS_PK_C
  3218. *
  3219. * Enable the generic public (asymetric) key layer.
  3220. *
  3221. * Module: library/pk.c
  3222. * Caller: library/ssl_tls.c
  3223. * library/ssl_cli.c
  3224. * library/ssl_srv.c
  3225. *
  3226. * Requires: MBEDTLS_RSA_C or MBEDTLS_ECP_C
  3227. *
  3228. * Uncomment to enable generic public key wrappers.
  3229. */
  3230. #define MBEDTLS_PK_C
  3231. /**
  3232. * \def MBEDTLS_PK_PARSE_C
  3233. *
  3234. * Enable the generic public (asymetric) key parser.
  3235. *
  3236. * Module: library/pkparse.c
  3237. * Caller: library/x509_crt.c
  3238. * library/x509_csr.c
  3239. *
  3240. * Requires: MBEDTLS_PK_C
  3241. *
  3242. * Uncomment to enable generic public key parse functions.
  3243. */
  3244. #define MBEDTLS_PK_PARSE_C
  3245. /**
  3246. * \def MBEDTLS_PK_WRITE_C
  3247. *
  3248. * Enable the generic public (asymetric) key writer.
  3249. *
  3250. * Module: library/pkwrite.c
  3251. * Caller: library/x509write.c
  3252. *
  3253. * Requires: MBEDTLS_PK_C
  3254. *
  3255. * Uncomment to enable generic public key write functions.
  3256. */
  3257. #define MBEDTLS_PK_WRITE_C
  3258. /**
  3259. * \def MBEDTLS_PKCS5_C
  3260. *
  3261. * Enable PKCS#5 functions.
  3262. *
  3263. * Module: library/pkcs5.c
  3264. *
  3265. * Requires: MBEDTLS_MD_C
  3266. *
  3267. * This module adds support for the PKCS#5 functions.
  3268. */
  3269. #define MBEDTLS_PKCS5_C
  3270. /**
  3271. * \def MBEDTLS_PKCS11_C
  3272. *
  3273. * Enable wrapper for PKCS#11 smartcard support via the pkcs11-helper library.
  3274. *
  3275. * \deprecated This option is deprecated and will be removed in a future
  3276. * version of Mbed TLS.
  3277. *
  3278. * Module: library/pkcs11.c
  3279. * Caller: library/pk.c
  3280. *
  3281. * Requires: MBEDTLS_PK_C
  3282. *
  3283. * This module enables SSL/TLS PKCS #11 smartcard support.
  3284. * Requires the presence of the PKCS#11 helper library (libpkcs11-helper)
  3285. */
  3286. //#define MBEDTLS_PKCS11_C
  3287. /**
  3288. * \def MBEDTLS_PKCS12_C
  3289. *
  3290. * Enable PKCS#12 PBE functions.
  3291. * Adds algorithms for parsing PKCS#8 encrypted private keys
  3292. *
  3293. * Module: library/pkcs12.c
  3294. * Caller: library/pkparse.c
  3295. *
  3296. * Requires: MBEDTLS_ASN1_PARSE_C, MBEDTLS_CIPHER_C, MBEDTLS_MD_C
  3297. * Can use: MBEDTLS_ARC4_C
  3298. *
  3299. * This module enables PKCS#12 functions.
  3300. */
  3301. #define MBEDTLS_PKCS12_C
  3302. /**
  3303. * \def MBEDTLS_PLATFORM_C
  3304. *
  3305. * Enable the platform abstraction layer that allows you to re-assign
  3306. * functions like calloc(), free(), snprintf(), printf(), fprintf(), exit().
  3307. *
  3308. * Enabling MBEDTLS_PLATFORM_C enables to use of MBEDTLS_PLATFORM_XXX_ALT
  3309. * or MBEDTLS_PLATFORM_XXX_MACRO directives, allowing the functions mentioned
  3310. * above to be specified at runtime or compile time respectively.
  3311. *
  3312. * \note This abstraction layer must be enabled on Windows (including MSYS2)
  3313. * as other module rely on it for a fixed snprintf implementation.
  3314. *
  3315. * Module: library/platform.c
  3316. * Caller: Most other .c files
  3317. *
  3318. * This module enables abstraction of common (libc) functions.
  3319. */
  3320. #define MBEDTLS_PLATFORM_C
  3321. /**
  3322. * \def MBEDTLS_POLY1305_C
  3323. *
  3324. * Enable the Poly1305 MAC algorithm.
  3325. *
  3326. * Module: library/poly1305.c
  3327. * Caller: library/chachapoly.c
  3328. */
  3329. #define MBEDTLS_POLY1305_C
  3330. /**
  3331. * \def MBEDTLS_PSA_CRYPTO_C
  3332. *
  3333. * Enable the Platform Security Architecture cryptography API.
  3334. *
  3335. * Module: library/psa_crypto.c
  3336. *
  3337. * Requires: either MBEDTLS_CTR_DRBG_C and MBEDTLS_ENTROPY_C,
  3338. * or MBEDTLS_HMAC_DRBG_C and MBEDTLS_ENTROPY_C,
  3339. * or MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG.
  3340. *
  3341. */
  3342. #define MBEDTLS_PSA_CRYPTO_C
  3343. /**
  3344. * \def MBEDTLS_PSA_CRYPTO_SE_C
  3345. *
  3346. * Enable secure element support in the Platform Security Architecture
  3347. * cryptography API.
  3348. *
  3349. * \warning This feature is not yet suitable for production. It is provided
  3350. * for API evaluation and testing purposes only.
  3351. *
  3352. * Module: library/psa_crypto_se.c
  3353. *
  3354. * Requires: MBEDTLS_PSA_CRYPTO_C, MBEDTLS_PSA_CRYPTO_STORAGE_C
  3355. *
  3356. */
  3357. //#define MBEDTLS_PSA_CRYPTO_SE_C
  3358. /**
  3359. * \def MBEDTLS_PSA_CRYPTO_STORAGE_C
  3360. *
  3361. * Enable the Platform Security Architecture persistent key storage.
  3362. *
  3363. * Module: library/psa_crypto_storage.c
  3364. *
  3365. * Requires: MBEDTLS_PSA_CRYPTO_C,
  3366. * either MBEDTLS_PSA_ITS_FILE_C or a native implementation of
  3367. * the PSA ITS interface
  3368. */
  3369. #define MBEDTLS_PSA_CRYPTO_STORAGE_C
  3370. /**
  3371. * \def MBEDTLS_PSA_ITS_FILE_C
  3372. *
  3373. * Enable the emulation of the Platform Security Architecture
  3374. * Internal Trusted Storage (PSA ITS) over files.
  3375. *
  3376. * Module: library/psa_its_file.c
  3377. *
  3378. * Requires: MBEDTLS_FS_IO
  3379. */
  3380. #define MBEDTLS_PSA_ITS_FILE_C
  3381. /**
  3382. * \def MBEDTLS_RIPEMD160_C
  3383. *
  3384. * Enable the RIPEMD-160 hash algorithm.
  3385. *
  3386. * Module: library/ripemd160.c
  3387. * Caller: library/md.c
  3388. *
  3389. */
  3390. #define MBEDTLS_RIPEMD160_C
  3391. /**
  3392. * \def MBEDTLS_RSA_C
  3393. *
  3394. * Enable the RSA public-key cryptosystem.
  3395. *
  3396. * Module: library/rsa.c
  3397. * library/rsa_internal.c
  3398. * Caller: library/ssl_cli.c
  3399. * library/ssl_srv.c
  3400. * library/ssl_tls.c
  3401. * library/x509.c
  3402. *
  3403. * This module is used by the following key exchanges:
  3404. * RSA, DHE-RSA, ECDHE-RSA, RSA-PSK
  3405. *
  3406. * Requires: MBEDTLS_BIGNUM_C, MBEDTLS_OID_C
  3407. */
  3408. #define MBEDTLS_RSA_C
  3409. /**
  3410. * \def MBEDTLS_SHA1_C
  3411. *
  3412. * Enable the SHA1 cryptographic hash algorithm.
  3413. *
  3414. * Module: library/sha1.c
  3415. * Caller: library/md.c
  3416. * library/ssl_cli.c
  3417. * library/ssl_srv.c
  3418. * library/ssl_tls.c
  3419. * library/x509write_crt.c
  3420. *
  3421. * This module is required for SSL/TLS up to version 1.1, for TLS 1.2
  3422. * depending on the handshake parameters, and for SHA1-signed certificates.
  3423. *
  3424. * \warning SHA-1 is considered a weak message digest and its use constitutes
  3425. * a security risk. If possible, we recommend avoiding dependencies
  3426. * on it, and considering stronger message digests instead.
  3427. *
  3428. */
  3429. #define MBEDTLS_SHA1_C
  3430. /**
  3431. * \def MBEDTLS_SHA256_C
  3432. *
  3433. * Enable the SHA-224 and SHA-256 cryptographic hash algorithms.
  3434. *
  3435. * Module: library/sha256.c
  3436. * Caller: library/entropy.c
  3437. * library/md.c
  3438. * library/ssl_cli.c
  3439. * library/ssl_srv.c
  3440. * library/ssl_tls.c
  3441. *
  3442. * This module adds support for SHA-224 and SHA-256.
  3443. * This module is required for the SSL/TLS 1.2 PRF function.
  3444. */
  3445. #define MBEDTLS_SHA256_C
  3446. /**
  3447. * \def MBEDTLS_SHA512_C
  3448. *
  3449. * Enable the SHA-384 and SHA-512 cryptographic hash algorithms.
  3450. *
  3451. * Module: library/sha512.c
  3452. * Caller: library/entropy.c
  3453. * library/md.c
  3454. * library/ssl_cli.c
  3455. * library/ssl_srv.c
  3456. *
  3457. * This module adds support for SHA-384 and SHA-512.
  3458. */
  3459. #define MBEDTLS_SHA512_C
  3460. /**
  3461. * \def MBEDTLS_SSL_CACHE_C
  3462. *
  3463. * Enable simple SSL cache implementation.
  3464. *
  3465. * Module: library/ssl_cache.c
  3466. * Caller:
  3467. *
  3468. * Requires: MBEDTLS_SSL_CACHE_C
  3469. */
  3470. #define MBEDTLS_SSL_CACHE_C
  3471. /**
  3472. * \def MBEDTLS_SSL_COOKIE_C
  3473. *
  3474. * Enable basic implementation of DTLS cookies for hello verification.
  3475. *
  3476. * Module: library/ssl_cookie.c
  3477. * Caller:
  3478. */
  3479. #define MBEDTLS_SSL_COOKIE_C
  3480. /**
  3481. * \def MBEDTLS_SSL_TICKET_C
  3482. *
  3483. * Enable an implementation of TLS server-side callbacks for session tickets.
  3484. *
  3485. * Module: library/ssl_ticket.c
  3486. * Caller:
  3487. *
  3488. * Requires: MBEDTLS_CIPHER_C
  3489. */
  3490. #define MBEDTLS_SSL_TICKET_C
  3491. /**
  3492. * \def MBEDTLS_SSL_CLI_C
  3493. *
  3494. * Enable the SSL/TLS client code.
  3495. *
  3496. * Module: library/ssl_cli.c
  3497. * Caller:
  3498. *
  3499. * Requires: MBEDTLS_SSL_TLS_C
  3500. *
  3501. * This module is required for SSL/TLS client support.
  3502. */
  3503. #define MBEDTLS_SSL_CLI_C
  3504. /**
  3505. * \def MBEDTLS_SSL_SRV_C
  3506. *
  3507. * Enable the SSL/TLS server code.
  3508. *
  3509. * Module: library/ssl_srv.c
  3510. * Caller:
  3511. *
  3512. * Requires: MBEDTLS_SSL_TLS_C
  3513. *
  3514. * This module is required for SSL/TLS server support.
  3515. */
  3516. #define MBEDTLS_SSL_SRV_C
  3517. /**
  3518. * \def MBEDTLS_SSL_TLS_C
  3519. *
  3520. * Enable the generic SSL/TLS code.
  3521. *
  3522. * Module: library/ssl_tls.c
  3523. * Caller: library/ssl_cli.c
  3524. * library/ssl_srv.c
  3525. *
  3526. * Requires: MBEDTLS_CIPHER_C, MBEDTLS_MD_C
  3527. * and at least one of the MBEDTLS_SSL_PROTO_XXX defines
  3528. *
  3529. * This module is required for SSL/TLS.
  3530. */
  3531. #define MBEDTLS_SSL_TLS_C
  3532. /**
  3533. * \def MBEDTLS_THREADING_C
  3534. *
  3535. * Enable the threading abstraction layer.
  3536. * By default mbed TLS assumes it is used in a non-threaded environment or that
  3537. * contexts are not shared between threads. If you do intend to use contexts
  3538. * between threads, you will need to enable this layer to prevent race
  3539. * conditions. See also our Knowledge Base article about threading:
  3540. * https://tls.mbed.org/kb/development/thread-safety-and-multi-threading
  3541. *
  3542. * Module: library/threading.c
  3543. *
  3544. * This allows different threading implementations (self-implemented or
  3545. * provided).
  3546. *
  3547. * You will have to enable either MBEDTLS_THREADING_ALT or
  3548. * MBEDTLS_THREADING_PTHREAD.
  3549. *
  3550. * Enable this layer to allow use of mutexes within mbed TLS
  3551. */
  3552. //#define MBEDTLS_THREADING_C
  3553. /**
  3554. * \def MBEDTLS_TIMING_C
  3555. *
  3556. * Enable the semi-portable timing interface.
  3557. *
  3558. * \note The provided implementation only works on POSIX/Unix (including Linux,
  3559. * BSD and OS X) and Windows. On other platforms, you can either disable that
  3560. * module and provide your own implementations of the callbacks needed by
  3561. * \c mbedtls_ssl_set_timer_cb() for DTLS, or leave it enabled and provide
  3562. * your own implementation of the whole module by setting
  3563. * \c MBEDTLS_TIMING_ALT in the current file.
  3564. *
  3565. * \note See also our Knowledge Base article about porting to a new
  3566. * environment:
  3567. * https://tls.mbed.org/kb/how-to/how-do-i-port-mbed-tls-to-a-new-environment-OS
  3568. *
  3569. * Module: library/timing.c
  3570. * Caller: library/havege.c
  3571. *
  3572. * This module is used by the HAVEGE random number generator.
  3573. */
  3574. #define MBEDTLS_TIMING_C
  3575. /**
  3576. * \def MBEDTLS_VERSION_C
  3577. *
  3578. * Enable run-time version information.
  3579. *
  3580. * Module: library/version.c
  3581. *
  3582. * This module provides run-time version information.
  3583. */
  3584. #define MBEDTLS_VERSION_C
  3585. /**
  3586. * \def MBEDTLS_X509_USE_C
  3587. *
  3588. * Enable X.509 core for using certificates.
  3589. *
  3590. * Module: library/x509.c
  3591. * Caller: library/x509_crl.c
  3592. * library/x509_crt.c
  3593. * library/x509_csr.c
  3594. *
  3595. * Requires: MBEDTLS_ASN1_PARSE_C, MBEDTLS_BIGNUM_C, MBEDTLS_OID_C,
  3596. * MBEDTLS_PK_PARSE_C
  3597. *
  3598. * This module is required for the X.509 parsing modules.
  3599. */
  3600. #define MBEDTLS_X509_USE_C
  3601. /**
  3602. * \def MBEDTLS_X509_CRT_PARSE_C
  3603. *
  3604. * Enable X.509 certificate parsing.
  3605. *
  3606. * Module: library/x509_crt.c
  3607. * Caller: library/ssl_cli.c
  3608. * library/ssl_srv.c
  3609. * library/ssl_tls.c
  3610. *
  3611. * Requires: MBEDTLS_X509_USE_C
  3612. *
  3613. * This module is required for X.509 certificate parsing.
  3614. */
  3615. #define MBEDTLS_X509_CRT_PARSE_C
  3616. /**
  3617. * \def MBEDTLS_X509_CRL_PARSE_C
  3618. *
  3619. * Enable X.509 CRL parsing.
  3620. *
  3621. * Module: library/x509_crl.c
  3622. * Caller: library/x509_crt.c
  3623. *
  3624. * Requires: MBEDTLS_X509_USE_C
  3625. *
  3626. * This module is required for X.509 CRL parsing.
  3627. */
  3628. #define MBEDTLS_X509_CRL_PARSE_C
  3629. /**
  3630. * \def MBEDTLS_X509_CSR_PARSE_C
  3631. *
  3632. * Enable X.509 Certificate Signing Request (CSR) parsing.
  3633. *
  3634. * Module: library/x509_csr.c
  3635. * Caller: library/x509_crt_write.c
  3636. *
  3637. * Requires: MBEDTLS_X509_USE_C
  3638. *
  3639. * This module is used for reading X.509 certificate request.
  3640. */
  3641. #define MBEDTLS_X509_CSR_PARSE_C
  3642. /**
  3643. * \def MBEDTLS_X509_CREATE_C
  3644. *
  3645. * Enable X.509 core for creating certificates.
  3646. *
  3647. * Module: library/x509_create.c
  3648. *
  3649. * Requires: MBEDTLS_BIGNUM_C, MBEDTLS_OID_C, MBEDTLS_PK_WRITE_C
  3650. *
  3651. * This module is the basis for creating X.509 certificates and CSRs.
  3652. */
  3653. #define MBEDTLS_X509_CREATE_C
  3654. /**
  3655. * \def MBEDTLS_X509_CRT_WRITE_C
  3656. *
  3657. * Enable creating X.509 certificates.
  3658. *
  3659. * Module: library/x509_crt_write.c
  3660. *
  3661. * Requires: MBEDTLS_X509_CREATE_C
  3662. *
  3663. * This module is required for X.509 certificate creation.
  3664. */
  3665. #define MBEDTLS_X509_CRT_WRITE_C
  3666. /**
  3667. * \def MBEDTLS_X509_CSR_WRITE_C
  3668. *
  3669. * Enable creating X.509 Certificate Signing Requests (CSR).
  3670. *
  3671. * Module: library/x509_csr_write.c
  3672. *
  3673. * Requires: MBEDTLS_X509_CREATE_C
  3674. *
  3675. * This module is required for X.509 certificate request writing.
  3676. */
  3677. #define MBEDTLS_X509_CSR_WRITE_C
  3678. /**
  3679. * \def MBEDTLS_XTEA_C
  3680. *
  3681. * Enable the XTEA block cipher.
  3682. *
  3683. * Module: library/xtea.c
  3684. * Caller:
  3685. */
  3686. #define MBEDTLS_XTEA_C
  3687. /* \} name SECTION: mbed TLS modules */
  3688. /**
  3689. * \name SECTION: Module configuration options
  3690. *
  3691. * This section allows for the setting of module specific sizes and
  3692. * configuration options. The default values are already present in the
  3693. * relevant header files and should suffice for the regular use cases.
  3694. *
  3695. * Our advice is to enable options and change their values here
  3696. * only if you have a good reason and know the consequences.
  3697. *
  3698. * Please check the respective header file for documentation on these
  3699. * parameters (to prevent duplicate documentation).
  3700. * \{
  3701. */
  3702. /* MPI / BIGNUM options */
  3703. //#define MBEDTLS_MPI_WINDOW_SIZE 6 /**< Maximum window size used. */
  3704. //#define MBEDTLS_MPI_MAX_SIZE 1024 /**< Maximum number of bytes for usable MPIs. */
  3705. /* CTR_DRBG options */
  3706. //#define MBEDTLS_CTR_DRBG_ENTROPY_LEN 48 /**< Amount of entropy used per seed by default (48 with SHA-512, 32 with SHA-256) */
  3707. //#define MBEDTLS_CTR_DRBG_RESEED_INTERVAL 10000 /**< Interval before reseed is performed by default */
  3708. //#define MBEDTLS_CTR_DRBG_MAX_INPUT 256 /**< Maximum number of additional input bytes */
  3709. //#define MBEDTLS_CTR_DRBG_MAX_REQUEST 1024 /**< Maximum number of requested bytes per call */
  3710. //#define MBEDTLS_CTR_DRBG_MAX_SEED_INPUT 384 /**< Maximum size of (re)seed buffer */
  3711. /* HMAC_DRBG options */
  3712. //#define MBEDTLS_HMAC_DRBG_RESEED_INTERVAL 10000 /**< Interval before reseed is performed by default */
  3713. //#define MBEDTLS_HMAC_DRBG_MAX_INPUT 256 /**< Maximum number of additional input bytes */
  3714. //#define MBEDTLS_HMAC_DRBG_MAX_REQUEST 1024 /**< Maximum number of requested bytes per call */
  3715. //#define MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT 384 /**< Maximum size of (re)seed buffer */
  3716. /* ECP options */
  3717. //#define MBEDTLS_ECP_MAX_BITS 521 /**< Maximum bit size of groups. Normally determined automatically from the configured curves. */
  3718. //#define MBEDTLS_ECP_WINDOW_SIZE 4 /**< Maximum window size used */
  3719. //#define MBEDTLS_ECP_FIXED_POINT_OPTIM 1 /**< Enable fixed-point speed-up */
  3720. /* Entropy options */
  3721. //#define MBEDTLS_ENTROPY_MAX_SOURCES 20 /**< Maximum number of sources supported */
  3722. //#define MBEDTLS_ENTROPY_MAX_GATHER 128 /**< Maximum amount requested from entropy sources */
  3723. //#define MBEDTLS_ENTROPY_MIN_HARDWARE 32 /**< Default minimum number of bytes required for the hardware entropy source mbedtls_hardware_poll() before entropy is released */
  3724. /* Memory buffer allocator options */
  3725. //#define MBEDTLS_MEMORY_ALIGN_MULTIPLE 4 /**< Align on multiples of this value */
  3726. /* Platform options */
  3727. //#define MBEDTLS_PLATFORM_STD_MEM_HDR <stdlib.h> /**< Header to include if MBEDTLS_PLATFORM_NO_STD_FUNCTIONS is defined. Don't define if no header is needed. */
  3728. //#define MBEDTLS_PLATFORM_STD_CALLOC calloc /**< Default allocator to use, can be undefined */
  3729. //#define MBEDTLS_PLATFORM_STD_FREE free /**< Default free to use, can be undefined */
  3730. //#define MBEDTLS_PLATFORM_STD_EXIT exit /**< Default exit to use, can be undefined */
  3731. //#define MBEDTLS_PLATFORM_STD_TIME time /**< Default time to use, can be undefined. MBEDTLS_HAVE_TIME must be enabled */
  3732. //#define MBEDTLS_PLATFORM_STD_FPRINTF fprintf /**< Default fprintf to use, can be undefined */
  3733. //#define MBEDTLS_PLATFORM_STD_PRINTF printf /**< Default printf to use, can be undefined */
  3734. /* Note: your snprintf must correctly zero-terminate the buffer! */
  3735. //#define MBEDTLS_PLATFORM_STD_SNPRINTF snprintf /**< Default snprintf to use, can be undefined */
  3736. //#define MBEDTLS_PLATFORM_STD_EXIT_SUCCESS 0 /**< Default exit value to use, can be undefined */
  3737. //#define MBEDTLS_PLATFORM_STD_EXIT_FAILURE 1 /**< Default exit value to use, can be undefined */
  3738. //#define MBEDTLS_PLATFORM_STD_NV_SEED_READ mbedtls_platform_std_nv_seed_read /**< Default nv_seed_read function to use, can be undefined */
  3739. //#define MBEDTLS_PLATFORM_STD_NV_SEED_WRITE mbedtls_platform_std_nv_seed_write /**< Default nv_seed_write function to use, can be undefined */
  3740. //#define MBEDTLS_PLATFORM_STD_NV_SEED_FILE "seedfile" /**< Seed file to read/write with default implementation */
  3741. /* To Use Function Macros MBEDTLS_PLATFORM_C must be enabled */
  3742. /* MBEDTLS_PLATFORM_XXX_MACRO and MBEDTLS_PLATFORM_XXX_ALT cannot both be defined */
  3743. //#define MBEDTLS_PLATFORM_CALLOC_MACRO calloc /**< Default allocator macro to use, can be undefined */
  3744. //#define MBEDTLS_PLATFORM_FREE_MACRO free /**< Default free macro to use, can be undefined */
  3745. //#define MBEDTLS_PLATFORM_EXIT_MACRO exit /**< Default exit macro to use, can be undefined */
  3746. //#define MBEDTLS_PLATFORM_TIME_MACRO time /**< Default time macro to use, can be undefined. MBEDTLS_HAVE_TIME must be enabled */
  3747. //#define MBEDTLS_PLATFORM_TIME_TYPE_MACRO time_t /**< Default time macro to use, can be undefined. MBEDTLS_HAVE_TIME must be enabled */
  3748. //#define MBEDTLS_PLATFORM_FPRINTF_MACRO fprintf /**< Default fprintf macro to use, can be undefined */
  3749. //#define MBEDTLS_PLATFORM_PRINTF_MACRO printf /**< Default printf macro to use, can be undefined */
  3750. /* Note: your snprintf must correctly zero-terminate the buffer! */
  3751. //#define MBEDTLS_PLATFORM_SNPRINTF_MACRO snprintf /**< Default snprintf macro to use, can be undefined */
  3752. //#define MBEDTLS_PLATFORM_VSNPRINTF_MACRO vsnprintf /**< Default vsnprintf macro to use, can be undefined */
  3753. //#define MBEDTLS_PLATFORM_NV_SEED_READ_MACRO mbedtls_platform_std_nv_seed_read /**< Default nv_seed_read function to use, can be undefined */
  3754. //#define MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO mbedtls_platform_std_nv_seed_write /**< Default nv_seed_write function to use, can be undefined */
  3755. /**
  3756. * \brief This macro is invoked by the library when an invalid parameter
  3757. * is detected that is only checked with #MBEDTLS_CHECK_PARAMS
  3758. * (see the documentation of that option for context).
  3759. *
  3760. * When you leave this undefined here, the library provides
  3761. * a default definition. If the macro #MBEDTLS_CHECK_PARAMS_ASSERT
  3762. * is defined, the default definition is `assert(cond)`,
  3763. * otherwise the default definition calls a function
  3764. * mbedtls_param_failed(). This function is declared in
  3765. * `platform_util.h` for the benefit of the library, but
  3766. * you need to define in your application.
  3767. *
  3768. * When you define this here, this replaces the default
  3769. * definition in platform_util.h (which no longer declares the
  3770. * function mbedtls_param_failed()) and it is your responsibility
  3771. * to make sure this macro expands to something suitable (in
  3772. * particular, that all the necessary declarations are visible
  3773. * from within the library - you can ensure that by providing
  3774. * them in this file next to the macro definition).
  3775. * If you define this macro to call `assert`, also define
  3776. * #MBEDTLS_CHECK_PARAMS_ASSERT so that library source files
  3777. * include `<assert.h>`.
  3778. *
  3779. * Note that you may define this macro to expand to nothing, in
  3780. * which case you don't have to worry about declarations or
  3781. * definitions. However, you will then be notified about invalid
  3782. * parameters only in non-void functions, and void function will
  3783. * just silently return early on invalid parameters, which
  3784. * partially negates the benefits of enabling
  3785. * #MBEDTLS_CHECK_PARAMS in the first place, so is discouraged.
  3786. *
  3787. * \param cond The expression that should evaluate to true, but doesn't.
  3788. */
  3789. //#define MBEDTLS_PARAM_FAILED( cond ) assert( cond )
  3790. /** \def MBEDTLS_CHECK_RETURN
  3791. *
  3792. * This macro is used at the beginning of the declaration of a function
  3793. * to indicate that its return value should be checked. It should
  3794. * instruct the compiler to emit a warning or an error if the function
  3795. * is called without checking its return value.
  3796. *
  3797. * There is a default implementation for popular compilers in platform_util.h.
  3798. * You can override the default implementation by defining your own here.
  3799. *
  3800. * If the implementation here is empty, this will effectively disable the
  3801. * checking of functions' return values.
  3802. */
  3803. //#define MBEDTLS_CHECK_RETURN __attribute__((__warn_unused_result__))
  3804. /** \def MBEDTLS_IGNORE_RETURN
  3805. *
  3806. * This macro requires one argument, which should be a C function call.
  3807. * If that function call would cause a #MBEDTLS_CHECK_RETURN warning, this
  3808. * warning is suppressed.
  3809. */
  3810. //#define MBEDTLS_IGNORE_RETURN( result ) ((void) !(result))
  3811. /* PSA options */
  3812. /**
  3813. * Use HMAC_DRBG with the specified hash algorithm for HMAC_DRBG for the
  3814. * PSA crypto subsystem.
  3815. *
  3816. * If this option is unset:
  3817. * - If CTR_DRBG is available, the PSA subsystem uses it rather than HMAC_DRBG.
  3818. * - Otherwise, the PSA subsystem uses HMAC_DRBG with either
  3819. * #MBEDTLS_MD_SHA512 or #MBEDTLS_MD_SHA256 based on availability and
  3820. * on unspecified heuristics.
  3821. */
  3822. //#define MBEDTLS_PSA_HMAC_DRBG_MD_TYPE MBEDTLS_MD_SHA256
  3823. /** \def MBEDTLS_PSA_KEY_SLOT_COUNT
  3824. * Restrict the PSA library to supporting a maximum amount of simultaneously
  3825. * loaded keys. A loaded key is a key stored by the PSA Crypto core as a
  3826. * volatile key, or a persistent key which is loaded temporarily by the
  3827. * library as part of a crypto operation in flight.
  3828. *
  3829. * If this option is unset, the library will fall back to a default value of
  3830. * 32 keys.
  3831. */
  3832. //#define MBEDTLS_PSA_KEY_SLOT_COUNT 32
  3833. /* SSL Cache options */
  3834. //#define MBEDTLS_SSL_CACHE_DEFAULT_TIMEOUT 86400 /**< 1 day */
  3835. //#define MBEDTLS_SSL_CACHE_DEFAULT_MAX_ENTRIES 50 /**< Maximum entries in cache */
  3836. /* SSL options */
  3837. /** \def MBEDTLS_SSL_MAX_CONTENT_LEN
  3838. *
  3839. * Maximum length (in bytes) of incoming and outgoing plaintext fragments.
  3840. *
  3841. * This determines the size of both the incoming and outgoing TLS I/O buffers
  3842. * in such a way that both are capable of holding the specified amount of
  3843. * plaintext data, regardless of the protection mechanism used.
  3844. *
  3845. * To configure incoming and outgoing I/O buffers separately, use
  3846. * #MBEDTLS_SSL_IN_CONTENT_LEN and #MBEDTLS_SSL_OUT_CONTENT_LEN,
  3847. * which overwrite the value set by this option.
  3848. *
  3849. * \note When using a value less than the default of 16KB on the client, it is
  3850. * recommended to use the Maximum Fragment Length (MFL) extension to
  3851. * inform the server about this limitation. On the server, there
  3852. * is no supported, standardized way of informing the client about
  3853. * restriction on the maximum size of incoming messages, and unless
  3854. * the limitation has been communicated by other means, it is recommended
  3855. * to only change the outgoing buffer size #MBEDTLS_SSL_OUT_CONTENT_LEN
  3856. * while keeping the default value of 16KB for the incoming buffer.
  3857. *
  3858. * Uncomment to set the maximum plaintext size of both
  3859. * incoming and outgoing I/O buffers.
  3860. */
  3861. //#define MBEDTLS_SSL_MAX_CONTENT_LEN 16384
  3862. /** \def MBEDTLS_SSL_IN_CONTENT_LEN
  3863. *
  3864. * Maximum length (in bytes) of incoming plaintext fragments.
  3865. *
  3866. * This determines the size of the incoming TLS I/O buffer in such a way
  3867. * that it is capable of holding the specified amount of plaintext data,
  3868. * regardless of the protection mechanism used.
  3869. *
  3870. * If this option is undefined, it inherits its value from
  3871. * #MBEDTLS_SSL_MAX_CONTENT_LEN.
  3872. *
  3873. * \note When using a value less than the default of 16KB on the client, it is
  3874. * recommended to use the Maximum Fragment Length (MFL) extension to
  3875. * inform the server about this limitation. On the server, there
  3876. * is no supported, standardized way of informing the client about
  3877. * restriction on the maximum size of incoming messages, and unless
  3878. * the limitation has been communicated by other means, it is recommended
  3879. * to only change the outgoing buffer size #MBEDTLS_SSL_OUT_CONTENT_LEN
  3880. * while keeping the default value of 16KB for the incoming buffer.
  3881. *
  3882. * Uncomment to set the maximum plaintext size of the incoming I/O buffer
  3883. * independently of the outgoing I/O buffer.
  3884. */
  3885. //#define MBEDTLS_SSL_IN_CONTENT_LEN 16384
  3886. /** \def MBEDTLS_SSL_CID_IN_LEN_MAX
  3887. *
  3888. * The maximum length of CIDs used for incoming DTLS messages.
  3889. *
  3890. */
  3891. //#define MBEDTLS_SSL_CID_IN_LEN_MAX 32
  3892. /** \def MBEDTLS_SSL_CID_OUT_LEN_MAX
  3893. *
  3894. * The maximum length of CIDs used for outgoing DTLS messages.
  3895. *
  3896. */
  3897. //#define MBEDTLS_SSL_CID_OUT_LEN_MAX 32
  3898. /** \def MBEDTLS_SSL_CID_PADDING_GRANULARITY
  3899. *
  3900. * This option controls the use of record plaintext padding
  3901. * when using the Connection ID extension in DTLS 1.2.
  3902. *
  3903. * The padding will always be chosen so that the length of the
  3904. * padded plaintext is a multiple of the value of this option.
  3905. *
  3906. * Note: A value of \c 1 means that no padding will be used
  3907. * for outgoing records.
  3908. *
  3909. * Note: On systems lacking division instructions,
  3910. * a power of two should be preferred.
  3911. *
  3912. */
  3913. //#define MBEDTLS_SSL_CID_PADDING_GRANULARITY 16
  3914. /** \def MBEDTLS_SSL_TLS1_3_PADDING_GRANULARITY
  3915. *
  3916. * This option controls the use of record plaintext padding
  3917. * in TLS 1.3.
  3918. *
  3919. * The padding will always be chosen so that the length of the
  3920. * padded plaintext is a multiple of the value of this option.
  3921. *
  3922. * Note: A value of \c 1 means that no padding will be used
  3923. * for outgoing records.
  3924. *
  3925. * Note: On systems lacking division instructions,
  3926. * a power of two should be preferred.
  3927. */
  3928. //#define MBEDTLS_SSL_TLS1_3_PADDING_GRANULARITY 1
  3929. /** \def MBEDTLS_SSL_OUT_CONTENT_LEN
  3930. *
  3931. * Maximum length (in bytes) of outgoing plaintext fragments.
  3932. *
  3933. * This determines the size of the outgoing TLS I/O buffer in such a way
  3934. * that it is capable of holding the specified amount of plaintext data,
  3935. * regardless of the protection mechanism used.
  3936. *
  3937. * If this option undefined, it inherits its value from
  3938. * #MBEDTLS_SSL_MAX_CONTENT_LEN.
  3939. *
  3940. * It is possible to save RAM by setting a smaller outward buffer, while keeping
  3941. * the default inward 16384 byte buffer to conform to the TLS specification.
  3942. *
  3943. * The minimum required outward buffer size is determined by the handshake
  3944. * protocol's usage. Handshaking will fail if the outward buffer is too small.
  3945. * The specific size requirement depends on the configured ciphers and any
  3946. * certificate data which is sent during the handshake.
  3947. *
  3948. * Uncomment to set the maximum plaintext size of the outgoing I/O buffer
  3949. * independently of the incoming I/O buffer.
  3950. */
  3951. //#define MBEDTLS_SSL_OUT_CONTENT_LEN 16384
  3952. /** \def MBEDTLS_SSL_DTLS_MAX_BUFFERING
  3953. *
  3954. * Maximum number of heap-allocated bytes for the purpose of
  3955. * DTLS handshake message reassembly and future message buffering.
  3956. *
  3957. * This should be at least 9/8 * MBEDTLS_SSL_IN_CONTENT_LEN
  3958. * to account for a reassembled handshake message of maximum size,
  3959. * together with its reassembly bitmap.
  3960. *
  3961. * A value of 2 * MBEDTLS_SSL_IN_CONTENT_LEN (32768 by default)
  3962. * should be sufficient for all practical situations as it allows
  3963. * to reassembly a large handshake message (such as a certificate)
  3964. * while buffering multiple smaller handshake messages.
  3965. *
  3966. */
  3967. //#define MBEDTLS_SSL_DTLS_MAX_BUFFERING 32768
  3968. //#define MBEDTLS_SSL_DEFAULT_TICKET_LIFETIME 86400 /**< Lifetime of session tickets (if enabled) */
  3969. //#define MBEDTLS_PSK_MAX_LEN 32 /**< Max size of TLS pre-shared keys, in bytes (default 256 bits) */
  3970. //#define MBEDTLS_SSL_COOKIE_TIMEOUT 60 /**< Default expiration delay of DTLS cookies, in seconds if HAVE_TIME, or in number of cookies issued */
  3971. /** \def MBEDTLS_TLS_EXT_CID
  3972. *
  3973. * At the time of writing, the CID extension has not been assigned its
  3974. * final value. Set this configuration option to make Mbed TLS use a
  3975. * different value.
  3976. *
  3977. * A future minor revision of Mbed TLS may change the default value of
  3978. * this option to match evolving standards and usage.
  3979. */
  3980. //#define MBEDTLS_TLS_EXT_CID 254
  3981. /**
  3982. * Complete list of ciphersuites to use, in order of preference.
  3983. *
  3984. * \warning No dependency checking is done on that field! This option can only
  3985. * be used to restrict the set of available ciphersuites. It is your
  3986. * responsibility to make sure the needed modules are active.
  3987. *
  3988. * Use this to save a few hundred bytes of ROM (default ordering of all
  3989. * available ciphersuites) and a few to a few hundred bytes of RAM.
  3990. *
  3991. * The value below is only an example, not the default.
  3992. */
  3993. //#define MBEDTLS_SSL_CIPHERSUITES MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
  3994. /* X509 options */
  3995. //#define MBEDTLS_X509_MAX_INTERMEDIATE_CA 8 /**< Maximum number of intermediate CAs in a verification chain. */
  3996. //#define MBEDTLS_X509_MAX_FILE_PATH_LEN 512 /**< Maximum length of a path/filename string in bytes including the null terminator character ('\0'). */
  3997. /**
  3998. * Allow SHA-1 in the default TLS configuration for TLS 1.2 handshake
  3999. * signature and ciphersuite selection. Without this build-time option, SHA-1
  4000. * support must be activated explicitly through mbedtls_ssl_conf_sig_hashes.
  4001. * The use of SHA-1 in TLS <= 1.1 and in HMAC-SHA-1 is always allowed by
  4002. * default. At the time of writing, there is no practical attack on the use
  4003. * of SHA-1 in handshake signatures, hence this option is turned on by default
  4004. * to preserve compatibility with existing peers, but the general
  4005. * warning applies nonetheless:
  4006. *
  4007. * \warning SHA-1 is considered a weak message digest and its use constitutes
  4008. * a security risk. If possible, we recommend avoiding dependencies
  4009. * on it, and considering stronger message digests instead.
  4010. *
  4011. */
  4012. //#define MBEDTLS_TLS_DEFAULT_ALLOW_SHA1_IN_KEY_EXCHANGE
  4013. /**
  4014. * Uncomment the macro to let mbed TLS use your alternate implementation of
  4015. * mbedtls_platform_zeroize(). This replaces the default implementation in
  4016. * platform_util.c.
  4017. *
  4018. * mbedtls_platform_zeroize() is a widely used function across the library to
  4019. * zero a block of memory. The implementation is expected to be secure in the
  4020. * sense that it has been written to prevent the compiler from removing calls
  4021. * to mbedtls_platform_zeroize() as part of redundant code elimination
  4022. * optimizations. However, it is difficult to guarantee that calls to
  4023. * mbedtls_platform_zeroize() will not be optimized by the compiler as older
  4024. * versions of the C language standards do not provide a secure implementation
  4025. * of memset(). Therefore, MBEDTLS_PLATFORM_ZEROIZE_ALT enables users to
  4026. * configure their own implementation of mbedtls_platform_zeroize(), for
  4027. * example by using directives specific to their compiler, features from newer
  4028. * C standards (e.g using memset_s() in C11) or calling a secure memset() from
  4029. * their system (e.g explicit_bzero() in BSD).
  4030. */
  4031. //#define MBEDTLS_PLATFORM_ZEROIZE_ALT
  4032. /**
  4033. * Uncomment the macro to let Mbed TLS use your alternate implementation of
  4034. * mbedtls_platform_gmtime_r(). This replaces the default implementation in
  4035. * platform_util.c.
  4036. *
  4037. * gmtime() is not a thread-safe function as defined in the C standard. The
  4038. * library will try to use safer implementations of this function, such as
  4039. * gmtime_r() when available. However, if Mbed TLS cannot identify the target
  4040. * system, the implementation of mbedtls_platform_gmtime_r() will default to
  4041. * using the standard gmtime(). In this case, calls from the library to
  4042. * gmtime() will be guarded by the global mutex mbedtls_threading_gmtime_mutex
  4043. * if MBEDTLS_THREADING_C is enabled. We recommend that calls from outside the
  4044. * library are also guarded with this mutex to avoid race conditions. However,
  4045. * if the macro MBEDTLS_PLATFORM_GMTIME_R_ALT is defined, Mbed TLS will
  4046. * unconditionally use the implementation for mbedtls_platform_gmtime_r()
  4047. * supplied at compile time.
  4048. */
  4049. //#define MBEDTLS_PLATFORM_GMTIME_R_ALT
  4050. /**
  4051. * Enable the verified implementations of ECDH primitives from Project Everest
  4052. * (currently only Curve25519). This feature changes the layout of ECDH
  4053. * contexts and therefore is a compatibility break for applications that access
  4054. * fields of a mbedtls_ecdh_context structure directly. See also
  4055. * MBEDTLS_ECDH_LEGACY_CONTEXT in include/mbedtls/ecdh.h.
  4056. */
  4057. //#define MBEDTLS_ECDH_VARIANT_EVEREST_ENABLED
  4058. /* \} name SECTION: Customisation configuration options */
  4059. /* Target and application specific configurations
  4060. *
  4061. * Allow user to override any previous default.
  4062. *
  4063. */
  4064. #if defined(MBEDTLS_USER_CONFIG_FILE)
  4065. #include MBEDTLS_USER_CONFIG_FILE
  4066. #endif
  4067. #if defined(MBEDTLS_PSA_CRYPTO_CONFIG)
  4068. #endif
  4069. #endif /* MBEDTLS_CONFIG_H */
  4070. /********* Start of file include/mbedtls/check_config.h ************/
  4071. /**
  4072. * \file check_config.h
  4073. *
  4074. * \brief Consistency checks for configuration options
  4075. */
  4076. /*
  4077. * Copyright The Mbed TLS Contributors
  4078. * SPDX-License-Identifier: Apache-2.0
  4079. *
  4080. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  4081. * not use this file except in compliance with the License.
  4082. * You may obtain a copy of the License at
  4083. *
  4084. * http://www.apache.org/licenses/LICENSE-2.0
  4085. *
  4086. * Unless required by applicable law or agreed to in writing, software
  4087. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  4088. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  4089. * See the License for the specific language governing permissions and
  4090. * limitations under the License.
  4091. */
  4092. /*
  4093. * It is recommended to include this file from your config.h
  4094. * in order to catch dependency issues early.
  4095. */
  4096. #ifndef MBEDTLS_CHECK_CONFIG_H
  4097. #define MBEDTLS_CHECK_CONFIG_H
  4098. /*
  4099. * We assume CHAR_BIT is 8 in many places. In practice, this is true on our
  4100. * target platforms, so not an issue, but let's just be extra sure.
  4101. */
  4102. #include <limits.h>
  4103. #if CHAR_BIT != 8
  4104. #error "mbed TLS requires a platform with 8-bit chars"
  4105. #endif
  4106. #if defined(_WIN32)
  4107. #if !defined(MBEDTLS_PLATFORM_C)
  4108. #error "MBEDTLS_PLATFORM_C is required on Windows"
  4109. #endif
  4110. /* Fix the config here. Not convenient to put an #ifdef _WIN32 in config.h as
  4111. * it would confuse config.py. */
  4112. #if !defined(MBEDTLS_PLATFORM_SNPRINTF_ALT) && \
  4113. !defined(MBEDTLS_PLATFORM_SNPRINTF_MACRO)
  4114. #define MBEDTLS_PLATFORM_SNPRINTF_ALT
  4115. #endif
  4116. #if !defined(MBEDTLS_PLATFORM_VSNPRINTF_ALT) && \
  4117. !defined(MBEDTLS_PLATFORM_VSNPRINTF_MACRO)
  4118. #define MBEDTLS_PLATFORM_VSNPRINTF_ALT
  4119. #endif
  4120. #endif /* _WIN32 */
  4121. #if defined(TARGET_LIKE_MBED) && defined(MBEDTLS_NET_C)
  4122. #error "The NET module is not available for mbed OS - please use the network functions provided by Mbed OS"
  4123. #endif
  4124. #if defined(MBEDTLS_DEPRECATED_WARNING) && \
  4125. !defined(__GNUC__) && !defined(__clang__)
  4126. #error "MBEDTLS_DEPRECATED_WARNING only works with GCC and Clang"
  4127. #endif
  4128. #if defined(MBEDTLS_HAVE_TIME_DATE) && !defined(MBEDTLS_HAVE_TIME)
  4129. #error "MBEDTLS_HAVE_TIME_DATE without MBEDTLS_HAVE_TIME does not make sense"
  4130. #endif
  4131. #if defined(MBEDTLS_AESNI_C) && !defined(MBEDTLS_HAVE_ASM)
  4132. #error "MBEDTLS_AESNI_C defined, but not all prerequisites"
  4133. #endif
  4134. #if defined(MBEDTLS_CTR_DRBG_C) && !defined(MBEDTLS_AES_C)
  4135. #error "MBEDTLS_CTR_DRBG_C defined, but not all prerequisites"
  4136. #endif
  4137. #if defined(MBEDTLS_DHM_C) && !defined(MBEDTLS_BIGNUM_C)
  4138. #error "MBEDTLS_DHM_C defined, but not all prerequisites"
  4139. #endif
  4140. #if defined(MBEDTLS_SSL_TRUNCATED_HMAC_COMPAT) && !defined(MBEDTLS_SSL_TRUNCATED_HMAC)
  4141. #error "MBEDTLS_SSL_TRUNCATED_HMAC_COMPAT defined, but not all prerequisites"
  4142. #endif
  4143. #if defined(MBEDTLS_CMAC_C) && \
  4144. !defined(MBEDTLS_AES_C) && !defined(MBEDTLS_DES_C)
  4145. #error "MBEDTLS_CMAC_C defined, but not all prerequisites"
  4146. #endif
  4147. #if defined(MBEDTLS_NIST_KW_C) && \
  4148. ( !defined(MBEDTLS_AES_C) || !defined(MBEDTLS_CIPHER_C) )
  4149. #error "MBEDTLS_NIST_KW_C defined, but not all prerequisites"
  4150. #endif
  4151. #if defined(MBEDTLS_ECDH_C) && !defined(MBEDTLS_ECP_C)
  4152. #error "MBEDTLS_ECDH_C defined, but not all prerequisites"
  4153. #endif
  4154. #if defined(MBEDTLS_ECDSA_C) && \
  4155. ( !defined(MBEDTLS_ECP_C) || \
  4156. !( defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED) || \
  4157. defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED) || \
  4158. defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED) || \
  4159. defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED) || \
  4160. defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED) || \
  4161. defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED) || \
  4162. defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED) || \
  4163. defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED) || \
  4164. defined(MBEDTLS_ECP_DP_BP256R1_ENABLED) || \
  4165. defined(MBEDTLS_ECP_DP_BP384R1_ENABLED) || \
  4166. defined(MBEDTLS_ECP_DP_BP512R1_ENABLED) ) || \
  4167. !defined(MBEDTLS_ASN1_PARSE_C) || \
  4168. !defined(MBEDTLS_ASN1_WRITE_C) )
  4169. #error "MBEDTLS_ECDSA_C defined, but not all prerequisites"
  4170. #endif
  4171. #if defined(MBEDTLS_ECJPAKE_C) && \
  4172. ( !defined(MBEDTLS_ECP_C) || !defined(MBEDTLS_MD_C) )
  4173. #error "MBEDTLS_ECJPAKE_C defined, but not all prerequisites"
  4174. #endif
  4175. #if defined(MBEDTLS_ECP_RESTARTABLE) && \
  4176. ( defined(MBEDTLS_USE_PSA_CRYPTO) || \
  4177. defined(MBEDTLS_ECDH_COMPUTE_SHARED_ALT) || \
  4178. defined(MBEDTLS_ECDH_GEN_PUBLIC_ALT) || \
  4179. defined(MBEDTLS_ECDSA_SIGN_ALT) || \
  4180. defined(MBEDTLS_ECDSA_VERIFY_ALT) || \
  4181. defined(MBEDTLS_ECDSA_GENKEY_ALT) || \
  4182. defined(MBEDTLS_ECP_INTERNAL_ALT) || \
  4183. defined(MBEDTLS_ECP_ALT) )
  4184. #error "MBEDTLS_ECP_RESTARTABLE defined, but it cannot coexist with an alternative or PSA-based ECP implementation"
  4185. #endif
  4186. #if defined(MBEDTLS_ECP_RESTARTABLE) && \
  4187. ! defined(MBEDTLS_ECDH_LEGACY_CONTEXT)
  4188. #error "MBEDTLS_ECP_RESTARTABLE defined, but not MBEDTLS_ECDH_LEGACY_CONTEXT"
  4189. #endif
  4190. #if defined(MBEDTLS_ECDH_VARIANT_EVEREST_ENABLED) && \
  4191. defined(MBEDTLS_ECDH_LEGACY_CONTEXT)
  4192. #error "MBEDTLS_ECDH_VARIANT_EVEREST_ENABLED defined, but MBEDTLS_ECDH_LEGACY_CONTEXT not disabled"
  4193. #endif
  4194. #if defined(MBEDTLS_ECDSA_DETERMINISTIC) && !defined(MBEDTLS_HMAC_DRBG_C)
  4195. #error "MBEDTLS_ECDSA_DETERMINISTIC defined, but not all prerequisites"
  4196. #endif
  4197. #if defined(MBEDTLS_ECP_C) && ( !defined(MBEDTLS_BIGNUM_C) || ( \
  4198. !defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED) && \
  4199. !defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED) && \
  4200. !defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED) && \
  4201. !defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED) && \
  4202. !defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED) && \
  4203. !defined(MBEDTLS_ECP_DP_BP256R1_ENABLED) && \
  4204. !defined(MBEDTLS_ECP_DP_BP384R1_ENABLED) && \
  4205. !defined(MBEDTLS_ECP_DP_BP512R1_ENABLED) && \
  4206. !defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED) && \
  4207. !defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED) && \
  4208. !defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED) && \
  4209. !defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED) && \
  4210. !defined(MBEDTLS_ECP_DP_CURVE448_ENABLED) ) )
  4211. #error "MBEDTLS_ECP_C defined, but not all prerequisites"
  4212. #endif
  4213. #if defined(MBEDTLS_ECP_C) && !( \
  4214. defined(MBEDTLS_ECP_ALT) || \
  4215. defined(MBEDTLS_CTR_DRBG_C) || \
  4216. defined(MBEDTLS_HMAC_DRBG_C) || \
  4217. defined(MBEDTLS_ECP_NO_INTERNAL_RNG))
  4218. #error "MBEDTLS_ECP_C requires a DRBG module unless MBEDTLS_ECP_NO_INTERNAL_RNG is defined or an alternative implementation is used"
  4219. #endif
  4220. #if defined(MBEDTLS_PK_PARSE_C) && !defined(MBEDTLS_ASN1_PARSE_C)
  4221. #error "MBEDTLS_PK_PARSE_C defined, but not all prerequesites"
  4222. #endif
  4223. #if defined(MBEDTLS_ENTROPY_C) && (!defined(MBEDTLS_SHA512_C) && \
  4224. !defined(MBEDTLS_SHA256_C))
  4225. #error "MBEDTLS_ENTROPY_C defined, but not all prerequisites"
  4226. #endif
  4227. #if defined(MBEDTLS_ENTROPY_C) && defined(MBEDTLS_SHA512_C) && \
  4228. defined(MBEDTLS_CTR_DRBG_ENTROPY_LEN) && (MBEDTLS_CTR_DRBG_ENTROPY_LEN > 64)
  4229. #error "MBEDTLS_CTR_DRBG_ENTROPY_LEN value too high"
  4230. #endif
  4231. #if defined(MBEDTLS_ENTROPY_C) && \
  4232. ( !defined(MBEDTLS_SHA512_C) || defined(MBEDTLS_ENTROPY_FORCE_SHA256) ) \
  4233. && defined(MBEDTLS_CTR_DRBG_ENTROPY_LEN) && (MBEDTLS_CTR_DRBG_ENTROPY_LEN > 32)
  4234. #error "MBEDTLS_CTR_DRBG_ENTROPY_LEN value too high"
  4235. #endif
  4236. #if defined(MBEDTLS_ENTROPY_C) && \
  4237. defined(MBEDTLS_ENTROPY_FORCE_SHA256) && !defined(MBEDTLS_SHA256_C)
  4238. #error "MBEDTLS_ENTROPY_FORCE_SHA256 defined, but not all prerequisites"
  4239. #endif
  4240. #if defined(__has_feature)
  4241. #if __has_feature(memory_sanitizer)
  4242. #define MBEDTLS_HAS_MEMSAN
  4243. #endif
  4244. #endif
  4245. #if defined(MBEDTLS_TEST_CONSTANT_FLOW_MEMSAN) && !defined(MBEDTLS_HAS_MEMSAN)
  4246. #error "MBEDTLS_TEST_CONSTANT_FLOW_MEMSAN requires building with MemorySanitizer"
  4247. #endif
  4248. #undef MBEDTLS_HAS_MEMSAN
  4249. #if defined(MBEDTLS_TEST_NULL_ENTROPY) && \
  4250. ( !defined(MBEDTLS_ENTROPY_C) || !defined(MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES) )
  4251. #error "MBEDTLS_TEST_NULL_ENTROPY defined, but not all prerequisites"
  4252. #endif
  4253. #if defined(MBEDTLS_TEST_NULL_ENTROPY) && \
  4254. ( defined(MBEDTLS_ENTROPY_NV_SEED) || defined(MBEDTLS_ENTROPY_HARDWARE_ALT) || \
  4255. defined(MBEDTLS_HAVEGE_C) )
  4256. #error "MBEDTLS_TEST_NULL_ENTROPY defined, but entropy sources too"
  4257. #endif
  4258. #if defined(MBEDTLS_GCM_C) && ( \
  4259. !defined(MBEDTLS_AES_C) && !defined(MBEDTLS_CAMELLIA_C) && !defined(MBEDTLS_ARIA_C) )
  4260. #error "MBEDTLS_GCM_C defined, but not all prerequisites"
  4261. #endif
  4262. #if defined(MBEDTLS_ECP_RANDOMIZE_JAC_ALT) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4263. #error "MBEDTLS_ECP_RANDOMIZE_JAC_ALT defined, but not all prerequisites"
  4264. #endif
  4265. #if defined(MBEDTLS_ECP_ADD_MIXED_ALT) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4266. #error "MBEDTLS_ECP_ADD_MIXED_ALT defined, but not all prerequisites"
  4267. #endif
  4268. #if defined(MBEDTLS_ECP_DOUBLE_JAC_ALT) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4269. #error "MBEDTLS_ECP_DOUBLE_JAC_ALT defined, but not all prerequisites"
  4270. #endif
  4271. #if defined(MBEDTLS_ECP_NORMALIZE_JAC_MANY_ALT) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4272. #error "MBEDTLS_ECP_NORMALIZE_JAC_MANY_ALT defined, but not all prerequisites"
  4273. #endif
  4274. #if defined(MBEDTLS_ECP_NORMALIZE_JAC_ALT) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4275. #error "MBEDTLS_ECP_NORMALIZE_JAC_ALT defined, but not all prerequisites"
  4276. #endif
  4277. #if defined(MBEDTLS_ECP_DOUBLE_ADD_MXZ_ALT) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4278. #error "MBEDTLS_ECP_DOUBLE_ADD_MXZ_ALT defined, but not all prerequisites"
  4279. #endif
  4280. #if defined(MBEDTLS_ECP_RANDOMIZE_MXZ_ALT) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4281. #error "MBEDTLS_ECP_RANDOMIZE_MXZ_ALT defined, but not all prerequisites"
  4282. #endif
  4283. #if defined(MBEDTLS_ECP_NORMALIZE_MXZ_ALT) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4284. #error "MBEDTLS_ECP_NORMALIZE_MXZ_ALT defined, but not all prerequisites"
  4285. #endif
  4286. #if defined(MBEDTLS_ECP_NO_FALLBACK) && !defined(MBEDTLS_ECP_INTERNAL_ALT)
  4287. #error "MBEDTLS_ECP_NO_FALLBACK defined, but no alternative implementation enabled"
  4288. #endif
  4289. #if defined(MBEDTLS_HAVEGE_C) && !defined(MBEDTLS_TIMING_C)
  4290. #error "MBEDTLS_HAVEGE_C defined, but not all prerequisites"
  4291. #endif
  4292. #if defined(MBEDTLS_HKDF_C) && !defined(MBEDTLS_MD_C)
  4293. #error "MBEDTLS_HKDF_C defined, but not all prerequisites"
  4294. #endif
  4295. #if defined(MBEDTLS_HMAC_DRBG_C) && !defined(MBEDTLS_MD_C)
  4296. #error "MBEDTLS_HMAC_DRBG_C defined, but not all prerequisites"
  4297. #endif
  4298. #if defined(MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED) && \
  4299. ( !defined(MBEDTLS_ECDH_C) || !defined(MBEDTLS_ECDSA_C) || \
  4300. !defined(MBEDTLS_X509_CRT_PARSE_C) )
  4301. #error "MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED defined, but not all prerequisites"
  4302. #endif
  4303. #if defined(MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED) && \
  4304. ( !defined(MBEDTLS_ECDH_C) || !defined(MBEDTLS_RSA_C) || \
  4305. !defined(MBEDTLS_X509_CRT_PARSE_C) )
  4306. #error "MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED defined, but not all prerequisites"
  4307. #endif
  4308. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED) && !defined(MBEDTLS_DHM_C)
  4309. #error "MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED defined, but not all prerequisites"
  4310. #endif
  4311. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED) && \
  4312. !defined(MBEDTLS_ECDH_C)
  4313. #error "MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED defined, but not all prerequisites"
  4314. #endif
  4315. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED) && \
  4316. ( !defined(MBEDTLS_DHM_C) || !defined(MBEDTLS_RSA_C) || \
  4317. !defined(MBEDTLS_X509_CRT_PARSE_C) || !defined(MBEDTLS_PKCS1_V15) )
  4318. #error "MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED defined, but not all prerequisites"
  4319. #endif
  4320. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED) && \
  4321. ( !defined(MBEDTLS_ECDH_C) || !defined(MBEDTLS_RSA_C) || \
  4322. !defined(MBEDTLS_X509_CRT_PARSE_C) || !defined(MBEDTLS_PKCS1_V15) )
  4323. #error "MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED defined, but not all prerequisites"
  4324. #endif
  4325. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED) && \
  4326. ( !defined(MBEDTLS_ECDH_C) || !defined(MBEDTLS_ECDSA_C) || \
  4327. !defined(MBEDTLS_X509_CRT_PARSE_C) )
  4328. #error "MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED defined, but not all prerequisites"
  4329. #endif
  4330. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED) && \
  4331. ( !defined(MBEDTLS_RSA_C) || !defined(MBEDTLS_X509_CRT_PARSE_C) || \
  4332. !defined(MBEDTLS_PKCS1_V15) )
  4333. #error "MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED defined, but not all prerequisites"
  4334. #endif
  4335. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED) && \
  4336. ( !defined(MBEDTLS_RSA_C) || !defined(MBEDTLS_X509_CRT_PARSE_C) || \
  4337. !defined(MBEDTLS_PKCS1_V15) )
  4338. #error "MBEDTLS_KEY_EXCHANGE_RSA_ENABLED defined, but not all prerequisites"
  4339. #endif
  4340. #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED) && \
  4341. ( !defined(MBEDTLS_ECJPAKE_C) || !defined(MBEDTLS_SHA256_C) || \
  4342. !defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED) )
  4343. #error "MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED defined, but not all prerequisites"
  4344. #endif
  4345. #if defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED) && \
  4346. !defined(MBEDTLS_SSL_KEEP_PEER_CERTIFICATE) && \
  4347. ( !defined(MBEDTLS_SHA256_C) && \
  4348. !defined(MBEDTLS_SHA512_C) && \
  4349. !defined(MBEDTLS_SHA1_C) )
  4350. #error "!MBEDTLS_SSL_KEEP_PEER_CERTIFICATE requires MBEDTLS_SHA512_C, MBEDTLS_SHA256_C or MBEDTLS_SHA1_C"
  4351. #endif
  4352. #if defined(MBEDTLS_MEMORY_BUFFER_ALLOC_C) && \
  4353. ( !defined(MBEDTLS_PLATFORM_C) || !defined(MBEDTLS_PLATFORM_MEMORY) )
  4354. #error "MBEDTLS_MEMORY_BUFFER_ALLOC_C defined, but not all prerequisites"
  4355. #endif
  4356. #if defined(MBEDTLS_MEMORY_BACKTRACE) && !defined(MBEDTLS_MEMORY_BUFFER_ALLOC_C)
  4357. #error "MBEDTLS_MEMORY_BACKTRACE defined, but not all prerequesites"
  4358. #endif
  4359. #if defined(MBEDTLS_MEMORY_DEBUG) && !defined(MBEDTLS_MEMORY_BUFFER_ALLOC_C)
  4360. #error "MBEDTLS_MEMORY_DEBUG defined, but not all prerequesites"
  4361. #endif
  4362. #if defined(MBEDTLS_PADLOCK_C) && !defined(MBEDTLS_HAVE_ASM)
  4363. #error "MBEDTLS_PADLOCK_C defined, but not all prerequisites"
  4364. #endif
  4365. #if defined(MBEDTLS_PEM_PARSE_C) && !defined(MBEDTLS_BASE64_C)
  4366. #error "MBEDTLS_PEM_PARSE_C defined, but not all prerequisites"
  4367. #endif
  4368. #if defined(MBEDTLS_PEM_WRITE_C) && !defined(MBEDTLS_BASE64_C)
  4369. #error "MBEDTLS_PEM_WRITE_C defined, but not all prerequisites"
  4370. #endif
  4371. #if defined(MBEDTLS_PK_C) && \
  4372. ( !defined(MBEDTLS_RSA_C) && !defined(MBEDTLS_ECP_C) )
  4373. #error "MBEDTLS_PK_C defined, but not all prerequisites"
  4374. #endif
  4375. #if defined(MBEDTLS_PK_PARSE_C) && !defined(MBEDTLS_PK_C)
  4376. #error "MBEDTLS_PK_PARSE_C defined, but not all prerequisites"
  4377. #endif
  4378. #if defined(MBEDTLS_PK_WRITE_C) && !defined(MBEDTLS_PK_C)
  4379. #error "MBEDTLS_PK_WRITE_C defined, but not all prerequisites"
  4380. #endif
  4381. #if defined(MBEDTLS_PKCS11_C) && !defined(MBEDTLS_PK_C)
  4382. #error "MBEDTLS_PKCS11_C defined, but not all prerequisites"
  4383. #endif
  4384. #if defined(MBEDTLS_PKCS11_C)
  4385. #if defined(MBEDTLS_DEPRECATED_REMOVED)
  4386. #error "MBEDTLS_PKCS11_C is deprecated and will be removed in a future version of Mbed TLS"
  4387. #elif defined(MBEDTLS_DEPRECATED_WARNING)
  4388. #warning "MBEDTLS_PKCS11_C is deprecated and will be removed in a future version of Mbed TLS"
  4389. #endif
  4390. #endif /* MBEDTLS_PKCS11_C */
  4391. #if defined(MBEDTLS_PLATFORM_EXIT_ALT) && !defined(MBEDTLS_PLATFORM_C)
  4392. #error "MBEDTLS_PLATFORM_EXIT_ALT defined, but not all prerequisites"
  4393. #endif
  4394. #if defined(MBEDTLS_PLATFORM_EXIT_MACRO) && !defined(MBEDTLS_PLATFORM_C)
  4395. #error "MBEDTLS_PLATFORM_EXIT_MACRO defined, but not all prerequisites"
  4396. #endif
  4397. #if defined(MBEDTLS_PLATFORM_EXIT_MACRO) &&\
  4398. ( defined(MBEDTLS_PLATFORM_STD_EXIT) ||\
  4399. defined(MBEDTLS_PLATFORM_EXIT_ALT) )
  4400. #error "MBEDTLS_PLATFORM_EXIT_MACRO and MBEDTLS_PLATFORM_STD_EXIT/MBEDTLS_PLATFORM_EXIT_ALT cannot be defined simultaneously"
  4401. #endif
  4402. #if defined(MBEDTLS_PLATFORM_TIME_ALT) &&\
  4403. ( !defined(MBEDTLS_PLATFORM_C) ||\
  4404. !defined(MBEDTLS_HAVE_TIME) )
  4405. #error "MBEDTLS_PLATFORM_TIME_ALT defined, but not all prerequisites"
  4406. #endif
  4407. #if defined(MBEDTLS_PLATFORM_TIME_MACRO) &&\
  4408. ( !defined(MBEDTLS_PLATFORM_C) ||\
  4409. !defined(MBEDTLS_HAVE_TIME) )
  4410. #error "MBEDTLS_PLATFORM_TIME_MACRO defined, but not all prerequisites"
  4411. #endif
  4412. #if defined(MBEDTLS_PLATFORM_TIME_TYPE_MACRO) &&\
  4413. ( !defined(MBEDTLS_PLATFORM_C) ||\
  4414. !defined(MBEDTLS_HAVE_TIME) )
  4415. #error "MBEDTLS_PLATFORM_TIME_TYPE_MACRO defined, but not all prerequisites"
  4416. #endif
  4417. #if defined(MBEDTLS_PLATFORM_TIME_MACRO) &&\
  4418. ( defined(MBEDTLS_PLATFORM_STD_TIME) ||\
  4419. defined(MBEDTLS_PLATFORM_TIME_ALT) )
  4420. #error "MBEDTLS_PLATFORM_TIME_MACRO and MBEDTLS_PLATFORM_STD_TIME/MBEDTLS_PLATFORM_TIME_ALT cannot be defined simultaneously"
  4421. #endif
  4422. #if defined(MBEDTLS_PLATFORM_TIME_TYPE_MACRO) &&\
  4423. ( defined(MBEDTLS_PLATFORM_STD_TIME) ||\
  4424. defined(MBEDTLS_PLATFORM_TIME_ALT) )
  4425. #error "MBEDTLS_PLATFORM_TIME_TYPE_MACRO and MBEDTLS_PLATFORM_STD_TIME/MBEDTLS_PLATFORM_TIME_ALT cannot be defined simultaneously"
  4426. #endif
  4427. #if defined(MBEDTLS_PLATFORM_FPRINTF_ALT) && !defined(MBEDTLS_PLATFORM_C)
  4428. #error "MBEDTLS_PLATFORM_FPRINTF_ALT defined, but not all prerequisites"
  4429. #endif
  4430. #if defined(MBEDTLS_PLATFORM_FPRINTF_MACRO) && !defined(MBEDTLS_PLATFORM_C)
  4431. #error "MBEDTLS_PLATFORM_FPRINTF_MACRO defined, but not all prerequisites"
  4432. #endif
  4433. #if defined(MBEDTLS_PLATFORM_FPRINTF_MACRO) &&\
  4434. ( defined(MBEDTLS_PLATFORM_STD_FPRINTF) ||\
  4435. defined(MBEDTLS_PLATFORM_FPRINTF_ALT) )
  4436. #error "MBEDTLS_PLATFORM_FPRINTF_MACRO and MBEDTLS_PLATFORM_STD_FPRINTF/MBEDTLS_PLATFORM_FPRINTF_ALT cannot be defined simultaneously"
  4437. #endif
  4438. #if defined(MBEDTLS_PLATFORM_FREE_MACRO) &&\
  4439. ( !defined(MBEDTLS_PLATFORM_C) || !defined(MBEDTLS_PLATFORM_MEMORY) )
  4440. #error "MBEDTLS_PLATFORM_FREE_MACRO defined, but not all prerequisites"
  4441. #endif
  4442. #if defined(MBEDTLS_PLATFORM_FREE_MACRO) &&\
  4443. defined(MBEDTLS_PLATFORM_STD_FREE)
  4444. #error "MBEDTLS_PLATFORM_FREE_MACRO and MBEDTLS_PLATFORM_STD_FREE cannot be defined simultaneously"
  4445. #endif
  4446. #if defined(MBEDTLS_PLATFORM_FREE_MACRO) && !defined(MBEDTLS_PLATFORM_CALLOC_MACRO)
  4447. #error "MBEDTLS_PLATFORM_CALLOC_MACRO must be defined if MBEDTLS_PLATFORM_FREE_MACRO is"
  4448. #endif
  4449. #if defined(MBEDTLS_PLATFORM_CALLOC_MACRO) &&\
  4450. ( !defined(MBEDTLS_PLATFORM_C) || !defined(MBEDTLS_PLATFORM_MEMORY) )
  4451. #error "MBEDTLS_PLATFORM_CALLOC_MACRO defined, but not all prerequisites"
  4452. #endif
  4453. #if defined(MBEDTLS_PLATFORM_CALLOC_MACRO) &&\
  4454. defined(MBEDTLS_PLATFORM_STD_CALLOC)
  4455. #error "MBEDTLS_PLATFORM_CALLOC_MACRO and MBEDTLS_PLATFORM_STD_CALLOC cannot be defined simultaneously"
  4456. #endif
  4457. #if defined(MBEDTLS_PLATFORM_CALLOC_MACRO) && !defined(MBEDTLS_PLATFORM_FREE_MACRO)
  4458. #error "MBEDTLS_PLATFORM_FREE_MACRO must be defined if MBEDTLS_PLATFORM_CALLOC_MACRO is"
  4459. #endif
  4460. #if defined(MBEDTLS_PLATFORM_MEMORY) && !defined(MBEDTLS_PLATFORM_C)
  4461. #error "MBEDTLS_PLATFORM_MEMORY defined, but not all prerequisites"
  4462. #endif
  4463. #if defined(MBEDTLS_PLATFORM_PRINTF_ALT) && !defined(MBEDTLS_PLATFORM_C)
  4464. #error "MBEDTLS_PLATFORM_PRINTF_ALT defined, but not all prerequisites"
  4465. #endif
  4466. #if defined(MBEDTLS_PLATFORM_PRINTF_MACRO) && !defined(MBEDTLS_PLATFORM_C)
  4467. #error "MBEDTLS_PLATFORM_PRINTF_MACRO defined, but not all prerequisites"
  4468. #endif
  4469. #if defined(MBEDTLS_PLATFORM_PRINTF_MACRO) &&\
  4470. ( defined(MBEDTLS_PLATFORM_STD_PRINTF) ||\
  4471. defined(MBEDTLS_PLATFORM_PRINTF_ALT) )
  4472. #error "MBEDTLS_PLATFORM_PRINTF_MACRO and MBEDTLS_PLATFORM_STD_PRINTF/MBEDTLS_PLATFORM_PRINTF_ALT cannot be defined simultaneously"
  4473. #endif
  4474. #if defined(MBEDTLS_PLATFORM_SNPRINTF_ALT) && !defined(MBEDTLS_PLATFORM_C)
  4475. #error "MBEDTLS_PLATFORM_SNPRINTF_ALT defined, but not all prerequisites"
  4476. #endif
  4477. #if defined(MBEDTLS_PLATFORM_SNPRINTF_MACRO) && !defined(MBEDTLS_PLATFORM_C)
  4478. #error "MBEDTLS_PLATFORM_SNPRINTF_MACRO defined, but not all prerequisites"
  4479. #endif
  4480. #if defined(MBEDTLS_PLATFORM_SNPRINTF_MACRO) &&\
  4481. ( defined(MBEDTLS_PLATFORM_STD_SNPRINTF) ||\
  4482. defined(MBEDTLS_PLATFORM_SNPRINTF_ALT) )
  4483. #error "MBEDTLS_PLATFORM_SNPRINTF_MACRO and MBEDTLS_PLATFORM_STD_SNPRINTF/MBEDTLS_PLATFORM_SNPRINTF_ALT cannot be defined simultaneously"
  4484. #endif
  4485. #if defined(MBEDTLS_PLATFORM_STD_MEM_HDR) &&\
  4486. !defined(MBEDTLS_PLATFORM_NO_STD_FUNCTIONS)
  4487. #error "MBEDTLS_PLATFORM_STD_MEM_HDR defined, but not all prerequisites"
  4488. #endif
  4489. #if defined(MBEDTLS_PLATFORM_STD_CALLOC) && !defined(MBEDTLS_PLATFORM_MEMORY)
  4490. #error "MBEDTLS_PLATFORM_STD_CALLOC defined, but not all prerequisites"
  4491. #endif
  4492. #if defined(MBEDTLS_PLATFORM_STD_FREE) && !defined(MBEDTLS_PLATFORM_MEMORY)
  4493. #error "MBEDTLS_PLATFORM_STD_FREE defined, but not all prerequisites"
  4494. #endif
  4495. #if defined(MBEDTLS_PLATFORM_STD_EXIT) &&\
  4496. !defined(MBEDTLS_PLATFORM_EXIT_ALT)
  4497. #error "MBEDTLS_PLATFORM_STD_EXIT defined, but not all prerequisites"
  4498. #endif
  4499. #if defined(MBEDTLS_PLATFORM_STD_TIME) &&\
  4500. ( !defined(MBEDTLS_PLATFORM_TIME_ALT) ||\
  4501. !defined(MBEDTLS_HAVE_TIME) )
  4502. #error "MBEDTLS_PLATFORM_STD_TIME defined, but not all prerequisites"
  4503. #endif
  4504. #if defined(MBEDTLS_PLATFORM_STD_FPRINTF) &&\
  4505. !defined(MBEDTLS_PLATFORM_FPRINTF_ALT)
  4506. #error "MBEDTLS_PLATFORM_STD_FPRINTF defined, but not all prerequisites"
  4507. #endif
  4508. #if defined(MBEDTLS_PLATFORM_STD_PRINTF) &&\
  4509. !defined(MBEDTLS_PLATFORM_PRINTF_ALT)
  4510. #error "MBEDTLS_PLATFORM_STD_PRINTF defined, but not all prerequisites"
  4511. #endif
  4512. #if defined(MBEDTLS_PLATFORM_STD_SNPRINTF) &&\
  4513. !defined(MBEDTLS_PLATFORM_SNPRINTF_ALT)
  4514. #error "MBEDTLS_PLATFORM_STD_SNPRINTF defined, but not all prerequisites"
  4515. #endif
  4516. #if defined(MBEDTLS_ENTROPY_NV_SEED) &&\
  4517. ( !defined(MBEDTLS_PLATFORM_C) || !defined(MBEDTLS_ENTROPY_C) )
  4518. #error "MBEDTLS_ENTROPY_NV_SEED defined, but not all prerequisites"
  4519. #endif
  4520. #if defined(MBEDTLS_PLATFORM_NV_SEED_ALT) &&\
  4521. !defined(MBEDTLS_ENTROPY_NV_SEED)
  4522. #error "MBEDTLS_PLATFORM_NV_SEED_ALT defined, but not all prerequisites"
  4523. #endif
  4524. #if defined(MBEDTLS_PLATFORM_STD_NV_SEED_READ) &&\
  4525. !defined(MBEDTLS_PLATFORM_NV_SEED_ALT)
  4526. #error "MBEDTLS_PLATFORM_STD_NV_SEED_READ defined, but not all prerequisites"
  4527. #endif
  4528. #if defined(MBEDTLS_PLATFORM_STD_NV_SEED_WRITE) &&\
  4529. !defined(MBEDTLS_PLATFORM_NV_SEED_ALT)
  4530. #error "MBEDTLS_PLATFORM_STD_NV_SEED_WRITE defined, but not all prerequisites"
  4531. #endif
  4532. #if defined(MBEDTLS_PLATFORM_NV_SEED_READ_MACRO) &&\
  4533. ( defined(MBEDTLS_PLATFORM_STD_NV_SEED_READ) ||\
  4534. defined(MBEDTLS_PLATFORM_NV_SEED_ALT) )
  4535. #error "MBEDTLS_PLATFORM_NV_SEED_READ_MACRO and MBEDTLS_PLATFORM_STD_NV_SEED_READ cannot be defined simultaneously"
  4536. #endif
  4537. #if defined(MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO) &&\
  4538. ( defined(MBEDTLS_PLATFORM_STD_NV_SEED_WRITE) ||\
  4539. defined(MBEDTLS_PLATFORM_NV_SEED_ALT) )
  4540. #error "MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO and MBEDTLS_PLATFORM_STD_NV_SEED_WRITE cannot be defined simultaneously"
  4541. #endif
  4542. #if defined(MBEDTLS_PSA_CRYPTO_C) && \
  4543. !( ( ( defined(MBEDTLS_CTR_DRBG_C) || defined(MBEDTLS_HMAC_DRBG_C) ) && \
  4544. defined(MBEDTLS_ENTROPY_C) ) || \
  4545. defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG) )
  4546. #error "MBEDTLS_PSA_CRYPTO_C defined, but not all prerequisites (missing RNG)"
  4547. #endif
  4548. #if defined(MBEDTLS_PSA_CRYPTO_SPM) && !defined(MBEDTLS_PSA_CRYPTO_C)
  4549. #error "MBEDTLS_PSA_CRYPTO_SPM defined, but not all prerequisites"
  4550. #endif
  4551. #if defined(MBEDTLS_PSA_CRYPTO_SE_C) && \
  4552. ! ( defined(MBEDTLS_PSA_CRYPTO_C) && \
  4553. defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) )
  4554. #error "MBEDTLS_PSA_CRYPTO_SE_C defined, but not all prerequisites"
  4555. #endif
  4556. #if defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) && \
  4557. ! defined(MBEDTLS_PSA_CRYPTO_C)
  4558. #error "MBEDTLS_PSA_CRYPTO_STORAGE_C defined, but not all prerequisites"
  4559. #endif
  4560. #if defined(MBEDTLS_PSA_INJECT_ENTROPY) && \
  4561. !( defined(MBEDTLS_PSA_CRYPTO_STORAGE_C) && \
  4562. defined(MBEDTLS_ENTROPY_NV_SEED) )
  4563. #error "MBEDTLS_PSA_INJECT_ENTROPY defined, but not all prerequisites"
  4564. #endif
  4565. #if defined(MBEDTLS_PSA_INJECT_ENTROPY) && \
  4566. !defined(MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES)
  4567. #error "MBEDTLS_PSA_INJECT_ENTROPY is not compatible with actual entropy sources"
  4568. #endif
  4569. #if defined(MBEDTLS_PSA_INJECT_ENTROPY) && \
  4570. defined(MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG)
  4571. #error "MBEDTLS_PSA_INJECT_ENTROPY is not compatible with MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG"
  4572. #endif
  4573. #if defined(MBEDTLS_PSA_ITS_FILE_C) && \
  4574. !defined(MBEDTLS_FS_IO)
  4575. #error "MBEDTLS_PSA_ITS_FILE_C defined, but not all prerequisites"
  4576. #endif
  4577. #if defined(MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER) && \
  4578. defined(MBEDTLS_USE_PSA_CRYPTO)
  4579. #error "MBEDTLS_PSA_CRYPTO_KEY_ID_ENCODES_OWNER defined, but it cannot coexist with MBEDTLS_USE_PSA_CRYPTO."
  4580. #endif
  4581. #if defined(MBEDTLS_RSA_C) && ( !defined(MBEDTLS_BIGNUM_C) || \
  4582. !defined(MBEDTLS_OID_C) )
  4583. #error "MBEDTLS_RSA_C defined, but not all prerequisites"
  4584. #endif
  4585. #if defined(MBEDTLS_RSA_C) && ( !defined(MBEDTLS_PKCS1_V21) && \
  4586. !defined(MBEDTLS_PKCS1_V15) )
  4587. #error "MBEDTLS_RSA_C defined, but none of the PKCS1 versions enabled"
  4588. #endif
  4589. #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT) && \
  4590. ( !defined(MBEDTLS_RSA_C) || !defined(MBEDTLS_PKCS1_V21) )
  4591. #error "MBEDTLS_X509_RSASSA_PSS_SUPPORT defined, but not all prerequisites"
  4592. #endif
  4593. #if defined(MBEDTLS_SHA512_NO_SHA384) && !defined(MBEDTLS_SHA512_C)
  4594. #error "MBEDTLS_SHA512_NO_SHA384 defined without MBEDTLS_SHA512_C"
  4595. #endif
  4596. #if defined(MBEDTLS_SSL_PROTO_SSL3) && ( !defined(MBEDTLS_MD5_C) || \
  4597. !defined(MBEDTLS_SHA1_C) )
  4598. #error "MBEDTLS_SSL_PROTO_SSL3 defined, but not all prerequisites"
  4599. #endif
  4600. #if defined(MBEDTLS_SSL_PROTO_TLS1) && ( !defined(MBEDTLS_MD5_C) || \
  4601. !defined(MBEDTLS_SHA1_C) )
  4602. #error "MBEDTLS_SSL_PROTO_TLS1 defined, but not all prerequisites"
  4603. #endif
  4604. #if defined(MBEDTLS_SSL_PROTO_TLS1_1) && ( !defined(MBEDTLS_MD5_C) || \
  4605. !defined(MBEDTLS_SHA1_C) )
  4606. #error "MBEDTLS_SSL_PROTO_TLS1_1 defined, but not all prerequisites"
  4607. #endif
  4608. #if defined(MBEDTLS_SSL_PROTO_TLS1_2) && ( !defined(MBEDTLS_SHA1_C) && \
  4609. !defined(MBEDTLS_SHA256_C) && !defined(MBEDTLS_SHA512_C) )
  4610. #error "MBEDTLS_SSL_PROTO_TLS1_2 defined, but not all prerequisites"
  4611. #endif
  4612. #if defined(MBEDTLS_SSL_PROTO_TLS1_3_EXPERIMENTAL) && ( !defined(MBEDTLS_HKDF_C) && \
  4613. !defined(MBEDTLS_SHA256_C) && !defined(MBEDTLS_SHA512_C) )
  4614. #error "MBEDTLS_SSL_PROTO_TLS1_3_EXPERIMENTAL defined, but not all prerequisites"
  4615. #endif
  4616. #if (defined(MBEDTLS_SSL_PROTO_SSL3) || defined(MBEDTLS_SSL_PROTO_TLS1) || \
  4617. defined(MBEDTLS_SSL_PROTO_TLS1_1) || defined(MBEDTLS_SSL_PROTO_TLS1_2)) && \
  4618. !(defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED) || \
  4619. defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED) || \
  4620. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED) || \
  4621. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED) || \
  4622. defined(MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED) || \
  4623. defined(MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED) || \
  4624. defined(MBEDTLS_KEY_EXCHANGE_PSK_ENABLED) || \
  4625. defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED) || \
  4626. defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED) || \
  4627. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED) || \
  4628. defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED) )
  4629. #error "One or more versions of the TLS protocol are enabled " \
  4630. "but no key exchange methods defined with MBEDTLS_KEY_EXCHANGE_xxxx"
  4631. #endif
  4632. #if defined(MBEDTLS_SSL_PROTO_DTLS) && \
  4633. !defined(MBEDTLS_SSL_PROTO_TLS1_1) && \
  4634. !defined(MBEDTLS_SSL_PROTO_TLS1_2)
  4635. #error "MBEDTLS_SSL_PROTO_DTLS defined, but not all prerequisites"
  4636. #endif
  4637. #if defined(MBEDTLS_SSL_CLI_C) && !defined(MBEDTLS_SSL_TLS_C)
  4638. #error "MBEDTLS_SSL_CLI_C defined, but not all prerequisites"
  4639. #endif
  4640. #if defined(MBEDTLS_SSL_TLS_C) && ( !defined(MBEDTLS_CIPHER_C) || \
  4641. !defined(MBEDTLS_MD_C) )
  4642. #error "MBEDTLS_SSL_TLS_C defined, but not all prerequisites"
  4643. #endif
  4644. #if defined(MBEDTLS_SSL_SRV_C) && !defined(MBEDTLS_SSL_TLS_C)
  4645. #error "MBEDTLS_SSL_SRV_C defined, but not all prerequisites"
  4646. #endif
  4647. #if defined(MBEDTLS_SSL_TLS_C) && (!defined(MBEDTLS_SSL_PROTO_SSL3) && \
  4648. !defined(MBEDTLS_SSL_PROTO_TLS1) && !defined(MBEDTLS_SSL_PROTO_TLS1_1) && \
  4649. !defined(MBEDTLS_SSL_PROTO_TLS1_2))
  4650. #error "MBEDTLS_SSL_TLS_C defined, but no protocols are active"
  4651. #endif
  4652. #if defined(MBEDTLS_SSL_TLS_C) && (defined(MBEDTLS_SSL_PROTO_SSL3) && \
  4653. defined(MBEDTLS_SSL_PROTO_TLS1_1) && !defined(MBEDTLS_SSL_PROTO_TLS1))
  4654. #error "Illegal protocol selection"
  4655. #endif
  4656. #if defined(MBEDTLS_SSL_TLS_C) && (defined(MBEDTLS_SSL_PROTO_TLS1) && \
  4657. defined(MBEDTLS_SSL_PROTO_TLS1_2) && !defined(MBEDTLS_SSL_PROTO_TLS1_1))
  4658. #error "Illegal protocol selection"
  4659. #endif
  4660. #if defined(MBEDTLS_SSL_TLS_C) && (defined(MBEDTLS_SSL_PROTO_SSL3) && \
  4661. defined(MBEDTLS_SSL_PROTO_TLS1_2) && (!defined(MBEDTLS_SSL_PROTO_TLS1) || \
  4662. !defined(MBEDTLS_SSL_PROTO_TLS1_1)))
  4663. #error "Illegal protocol selection"
  4664. #endif
  4665. #if defined(MBEDTLS_SSL_DTLS_HELLO_VERIFY) && !defined(MBEDTLS_SSL_PROTO_DTLS)
  4666. #error "MBEDTLS_SSL_DTLS_HELLO_VERIFY defined, but not all prerequisites"
  4667. #endif
  4668. #if defined(MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE) && \
  4669. !defined(MBEDTLS_SSL_DTLS_HELLO_VERIFY)
  4670. #error "MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE defined, but not all prerequisites"
  4671. #endif
  4672. #if defined(MBEDTLS_SSL_DTLS_ANTI_REPLAY) && \
  4673. ( !defined(MBEDTLS_SSL_TLS_C) || !defined(MBEDTLS_SSL_PROTO_DTLS) )
  4674. #error "MBEDTLS_SSL_DTLS_ANTI_REPLAY defined, but not all prerequisites"
  4675. #endif
  4676. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) && \
  4677. ( !defined(MBEDTLS_SSL_TLS_C) || !defined(MBEDTLS_SSL_PROTO_DTLS) )
  4678. #error "MBEDTLS_SSL_DTLS_CONNECTION_ID defined, but not all prerequisites"
  4679. #endif
  4680. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) && \
  4681. defined(MBEDTLS_SSL_CID_IN_LEN_MAX) && \
  4682. MBEDTLS_SSL_CID_IN_LEN_MAX > 255
  4683. #error "MBEDTLS_SSL_CID_IN_LEN_MAX too large (max 255)"
  4684. #endif
  4685. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) && \
  4686. defined(MBEDTLS_SSL_CID_OUT_LEN_MAX) && \
  4687. MBEDTLS_SSL_CID_OUT_LEN_MAX > 255
  4688. #error "MBEDTLS_SSL_CID_OUT_LEN_MAX too large (max 255)"
  4689. #endif
  4690. #if defined(MBEDTLS_SSL_DTLS_BADMAC_LIMIT) && \
  4691. ( !defined(MBEDTLS_SSL_TLS_C) || !defined(MBEDTLS_SSL_PROTO_DTLS) )
  4692. #error "MBEDTLS_SSL_DTLS_BADMAC_LIMIT defined, but not all prerequisites"
  4693. #endif
  4694. #if defined(MBEDTLS_SSL_ENCRYPT_THEN_MAC) && \
  4695. !defined(MBEDTLS_SSL_PROTO_TLS1) && \
  4696. !defined(MBEDTLS_SSL_PROTO_TLS1_1) && \
  4697. !defined(MBEDTLS_SSL_PROTO_TLS1_2)
  4698. #error "MBEDTLS_SSL_ENCRYPT_THEN_MAC defined, but not all prerequsites"
  4699. #endif
  4700. #if defined(MBEDTLS_SSL_EXTENDED_MASTER_SECRET) && \
  4701. !defined(MBEDTLS_SSL_PROTO_TLS1) && \
  4702. !defined(MBEDTLS_SSL_PROTO_TLS1_1) && \
  4703. !defined(MBEDTLS_SSL_PROTO_TLS1_2)
  4704. #error "MBEDTLS_SSL_EXTENDED_MASTER_SECRET defined, but not all prerequsites"
  4705. #endif
  4706. #if defined(MBEDTLS_SSL_TICKET_C) && !defined(MBEDTLS_CIPHER_C)
  4707. #error "MBEDTLS_SSL_TICKET_C defined, but not all prerequisites"
  4708. #endif
  4709. #if defined(MBEDTLS_SSL_CBC_RECORD_SPLITTING) && \
  4710. !defined(MBEDTLS_SSL_PROTO_SSL3) && !defined(MBEDTLS_SSL_PROTO_TLS1)
  4711. #error "MBEDTLS_SSL_CBC_RECORD_SPLITTING defined, but not all prerequisites"
  4712. #endif
  4713. #if defined(MBEDTLS_SSL_SERVER_NAME_INDICATION) && \
  4714. !defined(MBEDTLS_X509_CRT_PARSE_C)
  4715. #error "MBEDTLS_SSL_SERVER_NAME_INDICATION defined, but not all prerequisites"
  4716. #endif
  4717. #if defined(MBEDTLS_THREADING_PTHREAD)
  4718. #if !defined(MBEDTLS_THREADING_C) || defined(MBEDTLS_THREADING_IMPL)
  4719. #error "MBEDTLS_THREADING_PTHREAD defined, but not all prerequisites"
  4720. #endif
  4721. #define MBEDTLS_THREADING_IMPL
  4722. #endif
  4723. #if defined(MBEDTLS_THREADING_ALT)
  4724. #if !defined(MBEDTLS_THREADING_C) || defined(MBEDTLS_THREADING_IMPL)
  4725. #error "MBEDTLS_THREADING_ALT defined, but not all prerequisites"
  4726. #endif
  4727. #define MBEDTLS_THREADING_IMPL
  4728. #endif
  4729. #if defined(MBEDTLS_THREADING_C) && !defined(MBEDTLS_THREADING_IMPL)
  4730. #error "MBEDTLS_THREADING_C defined, single threading implementation required"
  4731. #endif
  4732. #undef MBEDTLS_THREADING_IMPL
  4733. #if defined(MBEDTLS_USE_PSA_CRYPTO) && !defined(MBEDTLS_PSA_CRYPTO_C)
  4734. #error "MBEDTLS_USE_PSA_CRYPTO defined, but not all prerequisites"
  4735. #endif
  4736. #if defined(MBEDTLS_VERSION_FEATURES) && !defined(MBEDTLS_VERSION_C)
  4737. #error "MBEDTLS_VERSION_FEATURES defined, but not all prerequisites"
  4738. #endif
  4739. #if defined(MBEDTLS_X509_USE_C) && ( !defined(MBEDTLS_BIGNUM_C) || \
  4740. !defined(MBEDTLS_OID_C) || !defined(MBEDTLS_ASN1_PARSE_C) || \
  4741. !defined(MBEDTLS_PK_PARSE_C) )
  4742. #error "MBEDTLS_X509_USE_C defined, but not all prerequisites"
  4743. #endif
  4744. #if defined(MBEDTLS_X509_CREATE_C) && ( !defined(MBEDTLS_BIGNUM_C) || \
  4745. !defined(MBEDTLS_OID_C) || !defined(MBEDTLS_ASN1_WRITE_C) || \
  4746. !defined(MBEDTLS_PK_WRITE_C) )
  4747. #error "MBEDTLS_X509_CREATE_C defined, but not all prerequisites"
  4748. #endif
  4749. #if defined(MBEDTLS_CERTS_C) && !defined(MBEDTLS_X509_USE_C)
  4750. #error "MBEDTLS_CERTS_C defined, but not all prerequisites"
  4751. #endif
  4752. #if defined(MBEDTLS_X509_CRT_PARSE_C) && ( !defined(MBEDTLS_X509_USE_C) )
  4753. #error "MBEDTLS_X509_CRT_PARSE_C defined, but not all prerequisites"
  4754. #endif
  4755. #if defined(MBEDTLS_X509_CRL_PARSE_C) && ( !defined(MBEDTLS_X509_USE_C) )
  4756. #error "MBEDTLS_X509_CRL_PARSE_C defined, but not all prerequisites"
  4757. #endif
  4758. #if defined(MBEDTLS_X509_CSR_PARSE_C) && ( !defined(MBEDTLS_X509_USE_C) )
  4759. #error "MBEDTLS_X509_CSR_PARSE_C defined, but not all prerequisites"
  4760. #endif
  4761. #if defined(MBEDTLS_X509_CRT_WRITE_C) && ( !defined(MBEDTLS_X509_CREATE_C) )
  4762. #error "MBEDTLS_X509_CRT_WRITE_C defined, but not all prerequisites"
  4763. #endif
  4764. #if defined(MBEDTLS_X509_CSR_WRITE_C) && ( !defined(MBEDTLS_X509_CREATE_C) )
  4765. #error "MBEDTLS_X509_CSR_WRITE_C defined, but not all prerequisites"
  4766. #endif
  4767. #if defined(MBEDTLS_HAVE_INT32) && defined(MBEDTLS_HAVE_INT64)
  4768. #error "MBEDTLS_HAVE_INT32 and MBEDTLS_HAVE_INT64 cannot be defined simultaneously"
  4769. #endif /* MBEDTLS_HAVE_INT32 && MBEDTLS_HAVE_INT64 */
  4770. #if ( defined(MBEDTLS_HAVE_INT32) || defined(MBEDTLS_HAVE_INT64) ) && \
  4771. defined(MBEDTLS_HAVE_ASM)
  4772. #error "MBEDTLS_HAVE_INT32/MBEDTLS_HAVE_INT64 and MBEDTLS_HAVE_ASM cannot be defined simultaneously"
  4773. #endif /* (MBEDTLS_HAVE_INT32 || MBEDTLS_HAVE_INT64) && MBEDTLS_HAVE_ASM */
  4774. #if defined(MBEDTLS_SSL_PROTO_SSL3)
  4775. #if defined(MBEDTLS_DEPRECATED_REMOVED)
  4776. #error "MBEDTLS_SSL_PROTO_SSL3 is deprecated and will be removed in a future version of Mbed TLS"
  4777. #elif defined(MBEDTLS_DEPRECATED_WARNING)
  4778. #warning "MBEDTLS_SSL_PROTO_SSL3 is deprecated and will be removed in a future version of Mbed TLS"
  4779. #endif
  4780. #endif /* MBEDTLS_SSL_PROTO_SSL3 */
  4781. #if defined(MBEDTLS_SSL_SRV_SUPPORT_SSLV2_CLIENT_HELLO)
  4782. #if defined(MBEDTLS_DEPRECATED_REMOVED)
  4783. #error "MBEDTLS_SSL_SRV_SUPPORT_SSLV2_CLIENT_HELLO is deprecated and will be removed in a future version of Mbed TLS"
  4784. #elif defined(MBEDTLS_DEPRECATED_WARNING)
  4785. #warning "MBEDTLS_SSL_SRV_SUPPORT_SSLV2_CLIENT_HELLO is deprecated and will be removed in a future version of Mbed TLS"
  4786. #endif
  4787. #endif /* MBEDTLS_SSL_SRV_SUPPORT_SSLV2_CLIENT_HELLO */
  4788. #if defined(MBEDTLS_SSL_HW_RECORD_ACCEL)
  4789. #if defined(MBEDTLS_DEPRECATED_REMOVED)
  4790. #error "MBEDTLS_SSL_HW_RECORD_ACCEL is deprecated and will be removed in a future version of Mbed TLS"
  4791. #elif defined(MBEDTLS_DEPRECATED_WARNING)
  4792. #warning "MBEDTLS_SSL_HW_RECORD_ACCEL is deprecated and will be removed in a future version of Mbed TLS"
  4793. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  4794. #endif /* MBEDTLS_SSL_HW_RECORD_ACCEL */
  4795. #if defined(MBEDTLS_SSL_DTLS_SRTP) && ( !defined(MBEDTLS_SSL_PROTO_DTLS) )
  4796. #error "MBEDTLS_SSL_DTLS_SRTP defined, but not all prerequisites"
  4797. #endif
  4798. #if defined(MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH) && ( !defined(MBEDTLS_SSL_MAX_FRAGMENT_LENGTH) )
  4799. #error "MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH defined, but not all prerequisites"
  4800. #endif
  4801. /*
  4802. * Avoid warning from -pedantic. This is a convenient place for this
  4803. * workaround since this is included by every single file before the
  4804. * #if defined(MBEDTLS_xxx_C) that results in empty translation units.
  4805. */
  4806. typedef int mbedtls_iso_c_forbids_empty_translation_units;
  4807. #endif /* MBEDTLS_CHECK_CONFIG_H */
  4808. /********* Start of file include/mbedtls/platform.h ************/
  4809. /**
  4810. * \file platform.h
  4811. *
  4812. * \brief This file contains the definitions and functions of the
  4813. * Mbed TLS platform abstraction layer.
  4814. *
  4815. * The platform abstraction layer removes the need for the library
  4816. * to directly link to standard C library functions or operating
  4817. * system services, making the library easier to port and embed.
  4818. * Application developers and users of the library can provide their own
  4819. * implementations of these functions, or implementations specific to
  4820. * their platform, which can be statically linked to the library or
  4821. * dynamically configured at runtime.
  4822. */
  4823. /*
  4824. * Copyright The Mbed TLS Contributors
  4825. * SPDX-License-Identifier: Apache-2.0
  4826. *
  4827. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  4828. * not use this file except in compliance with the License.
  4829. * You may obtain a copy of the License at
  4830. *
  4831. * http://www.apache.org/licenses/LICENSE-2.0
  4832. *
  4833. * Unless required by applicable law or agreed to in writing, software
  4834. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  4835. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  4836. * See the License for the specific language governing permissions and
  4837. * limitations under the License.
  4838. */
  4839. #ifndef MBEDTLS_PLATFORM_H
  4840. #define MBEDTLS_PLATFORM_H
  4841. #if !defined(MBEDTLS_CONFIG_FILE)
  4842. #else
  4843. #endif
  4844. #if defined(MBEDTLS_HAVE_TIME)
  4845. #endif
  4846. /** Hardware accelerator failed */
  4847. #define MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED -0x0070
  4848. /** The requested feature is not supported by the platform */
  4849. #define MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED -0x0072
  4850. #ifdef __cplusplus
  4851. extern "C" {
  4852. #endif
  4853. /**
  4854. * \name SECTION: Module settings
  4855. *
  4856. * The configuration options you can set for this module are in this section.
  4857. * Either change them in config.h or define them on the compiler command line.
  4858. * \{
  4859. */
  4860. /* The older Microsoft Windows common runtime provides non-conforming
  4861. * implementations of some standard library functions, including snprintf
  4862. * and vsnprintf. This affects MSVC and MinGW builds.
  4863. */
  4864. #if defined(__MINGW32__) || (defined(_MSC_VER) && _MSC_VER <= 1900)
  4865. #define MBEDTLS_PLATFORM_HAS_NON_CONFORMING_SNPRINTF
  4866. #define MBEDTLS_PLATFORM_HAS_NON_CONFORMING_VSNPRINTF
  4867. #endif
  4868. #if !defined(MBEDTLS_PLATFORM_NO_STD_FUNCTIONS)
  4869. #include <stdio.h>
  4870. #include <stdlib.h>
  4871. #include <time.h>
  4872. #if !defined(MBEDTLS_PLATFORM_STD_SNPRINTF)
  4873. #if defined(MBEDTLS_PLATFORM_HAS_NON_CONFORMING_SNPRINTF)
  4874. #define MBEDTLS_PLATFORM_STD_SNPRINTF mbedtls_platform_win32_snprintf /**< The default \c snprintf function to use. */
  4875. #else
  4876. #define MBEDTLS_PLATFORM_STD_SNPRINTF snprintf /**< The default \c snprintf function to use. */
  4877. #endif
  4878. #endif
  4879. #if !defined(MBEDTLS_PLATFORM_STD_VSNPRINTF)
  4880. #if defined(MBEDTLS_PLATFORM_HAS_NON_CONFORMING_VSNPRINTF)
  4881. #define MBEDTLS_PLATFORM_STD_VSNPRINTF mbedtls_platform_win32_vsnprintf /**< The default \c vsnprintf function to use. */
  4882. #else
  4883. #define MBEDTLS_PLATFORM_STD_VSNPRINTF vsnprintf /**< The default \c vsnprintf function to use. */
  4884. #endif
  4885. #endif
  4886. #if !defined(MBEDTLS_PLATFORM_STD_PRINTF)
  4887. #define MBEDTLS_PLATFORM_STD_PRINTF printf /**< The default \c printf function to use. */
  4888. #endif
  4889. #if !defined(MBEDTLS_PLATFORM_STD_FPRINTF)
  4890. #define MBEDTLS_PLATFORM_STD_FPRINTF fprintf /**< The default \c fprintf function to use. */
  4891. #endif
  4892. #if !defined(MBEDTLS_PLATFORM_STD_CALLOC)
  4893. #define MBEDTLS_PLATFORM_STD_CALLOC calloc /**< The default \c calloc function to use. */
  4894. #endif
  4895. #if !defined(MBEDTLS_PLATFORM_STD_FREE)
  4896. #define MBEDTLS_PLATFORM_STD_FREE free /**< The default \c free function to use. */
  4897. #endif
  4898. #if !defined(MBEDTLS_PLATFORM_STD_EXIT)
  4899. #define MBEDTLS_PLATFORM_STD_EXIT exit /**< The default \c exit function to use. */
  4900. #endif
  4901. #if !defined(MBEDTLS_PLATFORM_STD_TIME)
  4902. #define MBEDTLS_PLATFORM_STD_TIME time /**< The default \c time function to use. */
  4903. #endif
  4904. #if !defined(MBEDTLS_PLATFORM_STD_EXIT_SUCCESS)
  4905. #define MBEDTLS_PLATFORM_STD_EXIT_SUCCESS EXIT_SUCCESS /**< The default exit value to use. */
  4906. #endif
  4907. #if !defined(MBEDTLS_PLATFORM_STD_EXIT_FAILURE)
  4908. #define MBEDTLS_PLATFORM_STD_EXIT_FAILURE EXIT_FAILURE /**< The default exit value to use. */
  4909. #endif
  4910. #if defined(MBEDTLS_FS_IO)
  4911. #if !defined(MBEDTLS_PLATFORM_STD_NV_SEED_READ)
  4912. #define MBEDTLS_PLATFORM_STD_NV_SEED_READ mbedtls_platform_std_nv_seed_read
  4913. #endif
  4914. #if !defined(MBEDTLS_PLATFORM_STD_NV_SEED_WRITE)
  4915. #define MBEDTLS_PLATFORM_STD_NV_SEED_WRITE mbedtls_platform_std_nv_seed_write
  4916. #endif
  4917. #if !defined(MBEDTLS_PLATFORM_STD_NV_SEED_FILE)
  4918. #define MBEDTLS_PLATFORM_STD_NV_SEED_FILE "seedfile"
  4919. #endif
  4920. #endif /* MBEDTLS_FS_IO */
  4921. #else /* MBEDTLS_PLATFORM_NO_STD_FUNCTIONS */
  4922. #if defined(MBEDTLS_PLATFORM_STD_MEM_HDR)
  4923. #include MBEDTLS_PLATFORM_STD_MEM_HDR
  4924. #endif
  4925. #endif /* MBEDTLS_PLATFORM_NO_STD_FUNCTIONS */
  4926. /* \} name SECTION: Module settings */
  4927. /*
  4928. * The function pointers for calloc and free.
  4929. */
  4930. #if defined(MBEDTLS_PLATFORM_MEMORY)
  4931. #if defined(MBEDTLS_PLATFORM_FREE_MACRO) && \
  4932. defined(MBEDTLS_PLATFORM_CALLOC_MACRO)
  4933. #define mbedtls_free MBEDTLS_PLATFORM_FREE_MACRO
  4934. #define mbedtls_calloc MBEDTLS_PLATFORM_CALLOC_MACRO
  4935. #else
  4936. /* For size_t */
  4937. #include <stddef.h>
  4938. extern void *mbedtls_calloc( size_t n, size_t size );
  4939. extern void mbedtls_free( void *ptr );
  4940. /**
  4941. * \brief This function dynamically sets the memory-management
  4942. * functions used by the library, during runtime.
  4943. *
  4944. * \param calloc_func The \c calloc function implementation.
  4945. * \param free_func The \c free function implementation.
  4946. *
  4947. * \return \c 0.
  4948. */
  4949. int mbedtls_platform_set_calloc_free( void * (*calloc_func)( size_t, size_t ),
  4950. void (*free_func)( void * ) );
  4951. #endif /* MBEDTLS_PLATFORM_FREE_MACRO && MBEDTLS_PLATFORM_CALLOC_MACRO */
  4952. #else /* !MBEDTLS_PLATFORM_MEMORY */
  4953. #define mbedtls_free free
  4954. #define mbedtls_calloc calloc
  4955. #endif /* MBEDTLS_PLATFORM_MEMORY && !MBEDTLS_PLATFORM_{FREE,CALLOC}_MACRO */
  4956. /*
  4957. * The function pointers for fprintf
  4958. */
  4959. #if defined(MBEDTLS_PLATFORM_FPRINTF_ALT)
  4960. /* We need FILE * */
  4961. #include <stdio.h>
  4962. extern int (*mbedtls_fprintf)( FILE *stream, const char *format, ... );
  4963. /**
  4964. * \brief This function dynamically configures the fprintf
  4965. * function that is called when the
  4966. * mbedtls_fprintf() function is invoked by the library.
  4967. *
  4968. * \param fprintf_func The \c fprintf function implementation.
  4969. *
  4970. * \return \c 0.
  4971. */
  4972. int mbedtls_platform_set_fprintf( int (*fprintf_func)( FILE *stream, const char *,
  4973. ... ) );
  4974. #else
  4975. #if defined(MBEDTLS_PLATFORM_FPRINTF_MACRO)
  4976. #define mbedtls_fprintf MBEDTLS_PLATFORM_FPRINTF_MACRO
  4977. #else
  4978. #define mbedtls_fprintf fprintf
  4979. #endif /* MBEDTLS_PLATFORM_FPRINTF_MACRO */
  4980. #endif /* MBEDTLS_PLATFORM_FPRINTF_ALT */
  4981. /*
  4982. * The function pointers for printf
  4983. */
  4984. #if defined(MBEDTLS_PLATFORM_PRINTF_ALT)
  4985. extern int (*mbedtls_printf)( const char *format, ... );
  4986. /**
  4987. * \brief This function dynamically configures the snprintf
  4988. * function that is called when the mbedtls_snprintf()
  4989. * function is invoked by the library.
  4990. *
  4991. * \param printf_func The \c printf function implementation.
  4992. *
  4993. * \return \c 0 on success.
  4994. */
  4995. int mbedtls_platform_set_printf( int (*printf_func)( const char *, ... ) );
  4996. #else /* !MBEDTLS_PLATFORM_PRINTF_ALT */
  4997. #if defined(MBEDTLS_PLATFORM_PRINTF_MACRO)
  4998. #define mbedtls_printf MBEDTLS_PLATFORM_PRINTF_MACRO
  4999. #else
  5000. #define mbedtls_printf printf
  5001. #endif /* MBEDTLS_PLATFORM_PRINTF_MACRO */
  5002. #endif /* MBEDTLS_PLATFORM_PRINTF_ALT */
  5003. /*
  5004. * The function pointers for snprintf
  5005. *
  5006. * The snprintf implementation should conform to C99:
  5007. * - it *must* always correctly zero-terminate the buffer
  5008. * (except when n == 0, then it must leave the buffer untouched)
  5009. * - however it is acceptable to return -1 instead of the required length when
  5010. * the destination buffer is too short.
  5011. */
  5012. #if defined(MBEDTLS_PLATFORM_HAS_NON_CONFORMING_SNPRINTF)
  5013. /* For Windows (inc. MSYS2), we provide our own fixed implementation */
  5014. int mbedtls_platform_win32_snprintf( char *s, size_t n, const char *fmt, ... );
  5015. #endif
  5016. #if defined(MBEDTLS_PLATFORM_SNPRINTF_ALT)
  5017. extern int (*mbedtls_snprintf)( char * s, size_t n, const char * format, ... );
  5018. /**
  5019. * \brief This function allows configuring a custom
  5020. * \c snprintf function pointer.
  5021. *
  5022. * \param snprintf_func The \c snprintf function implementation.
  5023. *
  5024. * \return \c 0 on success.
  5025. */
  5026. int mbedtls_platform_set_snprintf( int (*snprintf_func)( char * s, size_t n,
  5027. const char * format, ... ) );
  5028. #else /* MBEDTLS_PLATFORM_SNPRINTF_ALT */
  5029. #if defined(MBEDTLS_PLATFORM_SNPRINTF_MACRO)
  5030. #define mbedtls_snprintf MBEDTLS_PLATFORM_SNPRINTF_MACRO
  5031. #else
  5032. #define mbedtls_snprintf MBEDTLS_PLATFORM_STD_SNPRINTF
  5033. #endif /* MBEDTLS_PLATFORM_SNPRINTF_MACRO */
  5034. #endif /* MBEDTLS_PLATFORM_SNPRINTF_ALT */
  5035. /*
  5036. * The function pointers for vsnprintf
  5037. *
  5038. * The vsnprintf implementation should conform to C99:
  5039. * - it *must* always correctly zero-terminate the buffer
  5040. * (except when n == 0, then it must leave the buffer untouched)
  5041. * - however it is acceptable to return -1 instead of the required length when
  5042. * the destination buffer is too short.
  5043. */
  5044. #if defined(MBEDTLS_PLATFORM_HAS_NON_CONFORMING_VSNPRINTF)
  5045. #include <stdarg.h>
  5046. /* For Older Windows (inc. MSYS2), we provide our own fixed implementation */
  5047. int mbedtls_platform_win32_vsnprintf( char *s, size_t n, const char *fmt, va_list arg );
  5048. #endif
  5049. #if defined(MBEDTLS_PLATFORM_VSNPRINTF_ALT)
  5050. #include <stdarg.h>
  5051. extern int (*mbedtls_vsnprintf)( char * s, size_t n, const char * format, va_list arg );
  5052. /**
  5053. * \brief Set your own snprintf function pointer
  5054. *
  5055. * \param vsnprintf_func The \c vsnprintf function implementation
  5056. *
  5057. * \return \c 0
  5058. */
  5059. int mbedtls_platform_set_vsnprintf( int (*vsnprintf_func)( char * s, size_t n,
  5060. const char * format, va_list arg ) );
  5061. #else /* MBEDTLS_PLATFORM_VSNPRINTF_ALT */
  5062. #if defined(MBEDTLS_PLATFORM_VSNPRINTF_MACRO)
  5063. #define mbedtls_vsnprintf MBEDTLS_PLATFORM_VSNPRINTF_MACRO
  5064. #else
  5065. #define mbedtls_vsnprintf vsnprintf
  5066. #endif /* MBEDTLS_PLATFORM_VSNPRINTF_MACRO */
  5067. #endif /* MBEDTLS_PLATFORM_VSNPRINTF_ALT */
  5068. /*
  5069. * The function pointers for exit
  5070. */
  5071. #if defined(MBEDTLS_PLATFORM_EXIT_ALT)
  5072. extern void (*mbedtls_exit)( int status );
  5073. /**
  5074. * \brief This function dynamically configures the exit
  5075. * function that is called when the mbedtls_exit()
  5076. * function is invoked by the library.
  5077. *
  5078. * \param exit_func The \c exit function implementation.
  5079. *
  5080. * \return \c 0 on success.
  5081. */
  5082. int mbedtls_platform_set_exit( void (*exit_func)( int status ) );
  5083. #else
  5084. #if defined(MBEDTLS_PLATFORM_EXIT_MACRO)
  5085. #define mbedtls_exit MBEDTLS_PLATFORM_EXIT_MACRO
  5086. #else
  5087. #define mbedtls_exit exit
  5088. #endif /* MBEDTLS_PLATFORM_EXIT_MACRO */
  5089. #endif /* MBEDTLS_PLATFORM_EXIT_ALT */
  5090. /*
  5091. * The default exit values
  5092. */
  5093. #if defined(MBEDTLS_PLATFORM_STD_EXIT_SUCCESS)
  5094. #define MBEDTLS_EXIT_SUCCESS MBEDTLS_PLATFORM_STD_EXIT_SUCCESS
  5095. #else
  5096. #define MBEDTLS_EXIT_SUCCESS 0
  5097. #endif
  5098. #if defined(MBEDTLS_PLATFORM_STD_EXIT_FAILURE)
  5099. #define MBEDTLS_EXIT_FAILURE MBEDTLS_PLATFORM_STD_EXIT_FAILURE
  5100. #else
  5101. #define MBEDTLS_EXIT_FAILURE 1
  5102. #endif
  5103. /*
  5104. * The function pointers for reading from and writing a seed file to
  5105. * Non-Volatile storage (NV) in a platform-independent way
  5106. *
  5107. * Only enabled when the NV seed entropy source is enabled
  5108. */
  5109. #if defined(MBEDTLS_ENTROPY_NV_SEED)
  5110. #if !defined(MBEDTLS_PLATFORM_NO_STD_FUNCTIONS) && defined(MBEDTLS_FS_IO)
  5111. /* Internal standard platform definitions */
  5112. int mbedtls_platform_std_nv_seed_read( unsigned char *buf, size_t buf_len );
  5113. int mbedtls_platform_std_nv_seed_write( unsigned char *buf, size_t buf_len );
  5114. #endif
  5115. #if defined(MBEDTLS_PLATFORM_NV_SEED_ALT)
  5116. extern int (*mbedtls_nv_seed_read)( unsigned char *buf, size_t buf_len );
  5117. extern int (*mbedtls_nv_seed_write)( unsigned char *buf, size_t buf_len );
  5118. /**
  5119. * \brief This function allows configuring custom seed file writing and
  5120. * reading functions.
  5121. *
  5122. * \param nv_seed_read_func The seed reading function implementation.
  5123. * \param nv_seed_write_func The seed writing function implementation.
  5124. *
  5125. * \return \c 0 on success.
  5126. */
  5127. int mbedtls_platform_set_nv_seed(
  5128. int (*nv_seed_read_func)( unsigned char *buf, size_t buf_len ),
  5129. int (*nv_seed_write_func)( unsigned char *buf, size_t buf_len )
  5130. );
  5131. #else
  5132. #if defined(MBEDTLS_PLATFORM_NV_SEED_READ_MACRO) && \
  5133. defined(MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO)
  5134. #define mbedtls_nv_seed_read MBEDTLS_PLATFORM_NV_SEED_READ_MACRO
  5135. #define mbedtls_nv_seed_write MBEDTLS_PLATFORM_NV_SEED_WRITE_MACRO
  5136. #else
  5137. #define mbedtls_nv_seed_read mbedtls_platform_std_nv_seed_read
  5138. #define mbedtls_nv_seed_write mbedtls_platform_std_nv_seed_write
  5139. #endif
  5140. #endif /* MBEDTLS_PLATFORM_NV_SEED_ALT */
  5141. #endif /* MBEDTLS_ENTROPY_NV_SEED */
  5142. #if !defined(MBEDTLS_PLATFORM_SETUP_TEARDOWN_ALT)
  5143. /**
  5144. * \brief The platform context structure.
  5145. *
  5146. * \note This structure may be used to assist platform-specific
  5147. * setup or teardown operations.
  5148. */
  5149. typedef struct mbedtls_platform_context
  5150. {
  5151. char dummy; /**< A placeholder member, as empty structs are not portable. */
  5152. }
  5153. mbedtls_platform_context;
  5154. #else
  5155. #endif /* !MBEDTLS_PLATFORM_SETUP_TEARDOWN_ALT */
  5156. /**
  5157. * \brief This function performs any platform-specific initialization
  5158. * operations.
  5159. *
  5160. * \note This function should be called before any other library functions.
  5161. *
  5162. * Its implementation is platform-specific, and unless
  5163. * platform-specific code is provided, it does nothing.
  5164. *
  5165. * \note The usage and necessity of this function is dependent on the platform.
  5166. *
  5167. * \param ctx The platform context.
  5168. *
  5169. * \return \c 0 on success.
  5170. */
  5171. int mbedtls_platform_setup( mbedtls_platform_context *ctx );
  5172. /**
  5173. * \brief This function performs any platform teardown operations.
  5174. *
  5175. * \note This function should be called after every other Mbed TLS module
  5176. * has been correctly freed using the appropriate free function.
  5177. *
  5178. * Its implementation is platform-specific, and unless
  5179. * platform-specific code is provided, it does nothing.
  5180. *
  5181. * \note The usage and necessity of this function is dependent on the platform.
  5182. *
  5183. * \param ctx The platform context.
  5184. *
  5185. */
  5186. void mbedtls_platform_teardown( mbedtls_platform_context *ctx );
  5187. #ifdef __cplusplus
  5188. }
  5189. #endif
  5190. #endif /* platform.h */
  5191. /********* Start of file include/mbedtls/platform_time.h ************/
  5192. /**
  5193. * \file platform_time.h
  5194. *
  5195. * \brief mbed TLS Platform time abstraction
  5196. */
  5197. /*
  5198. * Copyright The Mbed TLS Contributors
  5199. * SPDX-License-Identifier: Apache-2.0
  5200. *
  5201. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  5202. * not use this file except in compliance with the License.
  5203. * You may obtain a copy of the License at
  5204. *
  5205. * http://www.apache.org/licenses/LICENSE-2.0
  5206. *
  5207. * Unless required by applicable law or agreed to in writing, software
  5208. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  5209. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  5210. * See the License for the specific language governing permissions and
  5211. * limitations under the License.
  5212. */
  5213. #ifndef MBEDTLS_PLATFORM_TIME_H
  5214. #define MBEDTLS_PLATFORM_TIME_H
  5215. #if !defined(MBEDTLS_CONFIG_FILE)
  5216. #else
  5217. #endif
  5218. #ifdef __cplusplus
  5219. extern "C" {
  5220. #endif
  5221. /**
  5222. * \name SECTION: Module settings
  5223. *
  5224. * The configuration options you can set for this module are in this section.
  5225. * Either change them in config.h or define them on the compiler command line.
  5226. * \{
  5227. */
  5228. /*
  5229. * The time_t datatype
  5230. */
  5231. #if defined(MBEDTLS_PLATFORM_TIME_TYPE_MACRO)
  5232. typedef MBEDTLS_PLATFORM_TIME_TYPE_MACRO mbedtls_time_t;
  5233. #else
  5234. /* For time_t */
  5235. #include <time.h>
  5236. typedef time_t mbedtls_time_t;
  5237. #endif /* MBEDTLS_PLATFORM_TIME_TYPE_MACRO */
  5238. /*
  5239. * The function pointers for time
  5240. */
  5241. #if defined(MBEDTLS_PLATFORM_TIME_ALT)
  5242. extern mbedtls_time_t (*mbedtls_time)( mbedtls_time_t* time );
  5243. /**
  5244. * \brief Set your own time function pointer
  5245. *
  5246. * \param time_func the time function implementation
  5247. *
  5248. * \return 0
  5249. */
  5250. int mbedtls_platform_set_time( mbedtls_time_t (*time_func)( mbedtls_time_t* time ) );
  5251. #else
  5252. #if defined(MBEDTLS_PLATFORM_TIME_MACRO)
  5253. #define mbedtls_time MBEDTLS_PLATFORM_TIME_MACRO
  5254. #else
  5255. #define mbedtls_time time
  5256. #endif /* MBEDTLS_PLATFORM_TIME_MACRO */
  5257. #endif /* MBEDTLS_PLATFORM_TIME_ALT */
  5258. #ifdef __cplusplus
  5259. }
  5260. #endif
  5261. #endif /* platform_time.h */
  5262. /********* Start of file include/mbedtls/platform_util.h ************/
  5263. /**
  5264. * \file platform_util.h
  5265. *
  5266. * \brief Common and shared functions used by multiple modules in the Mbed TLS
  5267. * library.
  5268. */
  5269. /*
  5270. * Copyright The Mbed TLS Contributors
  5271. * SPDX-License-Identifier: Apache-2.0
  5272. *
  5273. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  5274. * not use this file except in compliance with the License.
  5275. * You may obtain a copy of the License at
  5276. *
  5277. * http://www.apache.org/licenses/LICENSE-2.0
  5278. *
  5279. * Unless required by applicable law or agreed to in writing, software
  5280. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  5281. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  5282. * See the License for the specific language governing permissions and
  5283. * limitations under the License.
  5284. */
  5285. #ifndef MBEDTLS_PLATFORM_UTIL_H
  5286. #define MBEDTLS_PLATFORM_UTIL_H
  5287. #if !defined(MBEDTLS_CONFIG_FILE)
  5288. #else
  5289. #endif
  5290. #include <stddef.h>
  5291. #if defined(MBEDTLS_HAVE_TIME_DATE)
  5292. #include <time.h>
  5293. #endif /* MBEDTLS_HAVE_TIME_DATE */
  5294. #ifdef __cplusplus
  5295. extern "C" {
  5296. #endif
  5297. #if defined(MBEDTLS_CHECK_PARAMS)
  5298. #if defined(MBEDTLS_CHECK_PARAMS_ASSERT)
  5299. /* Allow the user to define MBEDTLS_PARAM_FAILED to something like assert
  5300. * (which is what our config.h suggests). */
  5301. #include <assert.h>
  5302. #endif /* MBEDTLS_CHECK_PARAMS_ASSERT */
  5303. #if defined(MBEDTLS_PARAM_FAILED)
  5304. /** An alternative definition of MBEDTLS_PARAM_FAILED has been set in config.h.
  5305. *
  5306. * This flag can be used to check whether it is safe to assume that
  5307. * MBEDTLS_PARAM_FAILED() will expand to a call to mbedtls_param_failed().
  5308. */
  5309. #define MBEDTLS_PARAM_FAILED_ALT
  5310. #elif defined(MBEDTLS_CHECK_PARAMS_ASSERT)
  5311. #define MBEDTLS_PARAM_FAILED( cond ) assert( cond )
  5312. #define MBEDTLS_PARAM_FAILED_ALT
  5313. #else /* MBEDTLS_PARAM_FAILED */
  5314. #define MBEDTLS_PARAM_FAILED( cond ) \
  5315. mbedtls_param_failed( #cond, __FILE__, __LINE__ )
  5316. /**
  5317. * \brief User supplied callback function for parameter validation failure.
  5318. * See #MBEDTLS_CHECK_PARAMS for context.
  5319. *
  5320. * This function will be called unless an alternative treatement
  5321. * is defined through the #MBEDTLS_PARAM_FAILED macro.
  5322. *
  5323. * This function can return, and the operation will be aborted, or
  5324. * alternatively, through use of setjmp()/longjmp() can resume
  5325. * execution in the application code.
  5326. *
  5327. * \param failure_condition The assertion that didn't hold.
  5328. * \param file The file where the assertion failed.
  5329. * \param line The line in the file where the assertion failed.
  5330. */
  5331. void mbedtls_param_failed( const char *failure_condition,
  5332. const char *file,
  5333. int line );
  5334. #endif /* MBEDTLS_PARAM_FAILED */
  5335. /* Internal macro meant to be called only from within the library. */
  5336. #define MBEDTLS_INTERNAL_VALIDATE_RET( cond, ret ) \
  5337. do { \
  5338. if( !(cond) ) \
  5339. { \
  5340. MBEDTLS_PARAM_FAILED( cond ); \
  5341. return( ret ); \
  5342. } \
  5343. } while( 0 )
  5344. /* Internal macro meant to be called only from within the library. */
  5345. #define MBEDTLS_INTERNAL_VALIDATE( cond ) \
  5346. do { \
  5347. if( !(cond) ) \
  5348. { \
  5349. MBEDTLS_PARAM_FAILED( cond ); \
  5350. return; \
  5351. } \
  5352. } while( 0 )
  5353. #else /* MBEDTLS_CHECK_PARAMS */
  5354. /* Internal macros meant to be called only from within the library. */
  5355. #define MBEDTLS_INTERNAL_VALIDATE_RET( cond, ret ) do { } while( 0 )
  5356. #define MBEDTLS_INTERNAL_VALIDATE( cond ) do { } while( 0 )
  5357. #endif /* MBEDTLS_CHECK_PARAMS */
  5358. /* Internal helper macros for deprecating API constants. */
  5359. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  5360. #if defined(MBEDTLS_DEPRECATED_WARNING)
  5361. /* Deliberately don't (yet) export MBEDTLS_DEPRECATED here
  5362. * to avoid conflict with other headers which define and use
  5363. * it, too. We might want to move all these definitions here at
  5364. * some point for uniformity. */
  5365. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  5366. MBEDTLS_DEPRECATED typedef char const * mbedtls_deprecated_string_constant_t;
  5367. #define MBEDTLS_DEPRECATED_STRING_CONSTANT( VAL ) \
  5368. ( (mbedtls_deprecated_string_constant_t) ( VAL ) )
  5369. MBEDTLS_DEPRECATED typedef int mbedtls_deprecated_numeric_constant_t;
  5370. #define MBEDTLS_DEPRECATED_NUMERIC_CONSTANT( VAL ) \
  5371. ( (mbedtls_deprecated_numeric_constant_t) ( VAL ) )
  5372. #undef MBEDTLS_DEPRECATED
  5373. #else /* MBEDTLS_DEPRECATED_WARNING */
  5374. #define MBEDTLS_DEPRECATED_STRING_CONSTANT( VAL ) VAL
  5375. #define MBEDTLS_DEPRECATED_NUMERIC_CONSTANT( VAL ) VAL
  5376. #endif /* MBEDTLS_DEPRECATED_WARNING */
  5377. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  5378. /* Implementation of the check-return facility.
  5379. * See the user documentation in config.h.
  5380. *
  5381. * Do not use this macro directly to annotate function: instead,
  5382. * use one of MBEDTLS_CHECK_RETURN_CRITICAL or MBEDTLS_CHECK_RETURN_TYPICAL
  5383. * depending on how important it is to check the return value.
  5384. */
  5385. #if !defined(MBEDTLS_CHECK_RETURN)
  5386. #if defined(__GNUC__)
  5387. #define MBEDTLS_CHECK_RETURN __attribute__((__warn_unused_result__))
  5388. #elif defined(_MSC_VER) && _MSC_VER >= 1700
  5389. #include <sal.h>
  5390. #define MBEDTLS_CHECK_RETURN _Check_return_
  5391. #else
  5392. #define MBEDTLS_CHECK_RETURN
  5393. #endif
  5394. #endif
  5395. /** Critical-failure function
  5396. *
  5397. * This macro appearing at the beginning of the declaration of a function
  5398. * indicates that its return value should be checked in all applications.
  5399. * Omitting the check is very likely to indicate a bug in the application
  5400. * and will result in a compile-time warning if #MBEDTLS_CHECK_RETURN
  5401. * is implemented for the compiler in use.
  5402. *
  5403. * \note The use of this macro is a work in progress.
  5404. * This macro may be added to more functions in the future.
  5405. * Such an extension is not considered an API break, provided that
  5406. * there are near-unavoidable circumstances under which the function
  5407. * can fail. For example, signature/MAC/AEAD verification functions,
  5408. * and functions that require a random generator, are considered
  5409. * return-check-critical.
  5410. */
  5411. #define MBEDTLS_CHECK_RETURN_CRITICAL MBEDTLS_CHECK_RETURN
  5412. /** Ordinary-failure function
  5413. *
  5414. * This macro appearing at the beginning of the declaration of a function
  5415. * indicates that its return value should be generally be checked in portable
  5416. * applications. Omitting the check will result in a compile-time warning if
  5417. * #MBEDTLS_CHECK_RETURN is implemented for the compiler in use and
  5418. * #MBEDTLS_CHECK_RETURN_WARNING is enabled in the compile-time configuration.
  5419. *
  5420. * You can use #MBEDTLS_IGNORE_RETURN to explicitly ignore the return value
  5421. * of a function that is annotated with #MBEDTLS_CHECK_RETURN.
  5422. *
  5423. * \note The use of this macro is a work in progress.
  5424. * This macro will be added to more functions in the future.
  5425. * Eventually this should appear before most functions returning
  5426. * an error code (as \c int in the \c mbedtls_xxx API or
  5427. * as ::psa_status_t in the \c psa_xxx API).
  5428. */
  5429. #if defined(MBEDTLS_CHECK_RETURN_WARNING)
  5430. #define MBEDTLS_CHECK_RETURN_TYPICAL MBEDTLS_CHECK_RETURN
  5431. #else
  5432. #define MBEDTLS_CHECK_RETURN_TYPICAL
  5433. #endif
  5434. /** Benign-failure function
  5435. *
  5436. * This macro appearing at the beginning of the declaration of a function
  5437. * indicates that it is rarely useful to check its return value.
  5438. *
  5439. * This macro has an empty expansion. It exists for documentation purposes:
  5440. * a #MBEDTLS_CHECK_RETURN_OPTIONAL annotation indicates that the function
  5441. * has been analyzed for return-check usefuless, whereas the lack of
  5442. * an annotation indicates that the function has not been analyzed and its
  5443. * return-check usefulness is unknown.
  5444. */
  5445. #define MBEDTLS_CHECK_RETURN_OPTIONAL
  5446. /** \def MBEDTLS_IGNORE_RETURN
  5447. *
  5448. * Call this macro with one argument, a function call, to suppress a warning
  5449. * from #MBEDTLS_CHECK_RETURN due to that function call.
  5450. */
  5451. #if !defined(MBEDTLS_IGNORE_RETURN)
  5452. /* GCC doesn't silence the warning with just (void)(result).
  5453. * (void)!(result) is known to work up at least up to GCC 10, as well
  5454. * as with Clang and MSVC.
  5455. *
  5456. * https://gcc.gnu.org/onlinedocs/gcc-3.4.6/gcc/Non_002dbugs.html
  5457. * https://stackoverflow.com/questions/40576003/ignoring-warning-wunused-result
  5458. * https://gcc.gnu.org/bugzilla/show_bug.cgi?id=66425#c34
  5459. */
  5460. #define MBEDTLS_IGNORE_RETURN(result) ( (void) !( result ) )
  5461. #endif
  5462. /**
  5463. * \brief Securely zeroize a buffer
  5464. *
  5465. * The function is meant to wipe the data contained in a buffer so
  5466. * that it can no longer be recovered even if the program memory
  5467. * is later compromised. Call this function on sensitive data
  5468. * stored on the stack before returning from a function, and on
  5469. * sensitive data stored on the heap before freeing the heap
  5470. * object.
  5471. *
  5472. * It is extremely difficult to guarantee that calls to
  5473. * mbedtls_platform_zeroize() are not removed by aggressive
  5474. * compiler optimizations in a portable way. For this reason, Mbed
  5475. * TLS provides the configuration option
  5476. * MBEDTLS_PLATFORM_ZEROIZE_ALT, which allows users to configure
  5477. * mbedtls_platform_zeroize() to use a suitable implementation for
  5478. * their platform and needs
  5479. *
  5480. * \param buf Buffer to be zeroized
  5481. * \param len Length of the buffer in bytes
  5482. *
  5483. */
  5484. void mbedtls_platform_zeroize( void *buf, size_t len );
  5485. #if defined(MBEDTLS_HAVE_TIME_DATE)
  5486. /**
  5487. * \brief Platform-specific implementation of gmtime_r()
  5488. *
  5489. * The function is a thread-safe abstraction that behaves
  5490. * similarly to the gmtime_r() function from Unix/POSIX.
  5491. *
  5492. * Mbed TLS will try to identify the underlying platform and
  5493. * make use of an appropriate underlying implementation (e.g.
  5494. * gmtime_r() for POSIX and gmtime_s() for Windows). If this is
  5495. * not possible, then gmtime() will be used. In this case, calls
  5496. * from the library to gmtime() will be guarded by the mutex
  5497. * mbedtls_threading_gmtime_mutex if MBEDTLS_THREADING_C is
  5498. * enabled. It is recommended that calls from outside the library
  5499. * are also guarded by this mutex.
  5500. *
  5501. * If MBEDTLS_PLATFORM_GMTIME_R_ALT is defined, then Mbed TLS will
  5502. * unconditionally use the alternative implementation for
  5503. * mbedtls_platform_gmtime_r() supplied by the user at compile time.
  5504. *
  5505. * \param tt Pointer to an object containing time (in seconds) since the
  5506. * epoch to be converted
  5507. * \param tm_buf Pointer to an object where the results will be stored
  5508. *
  5509. * \return Pointer to an object of type struct tm on success, otherwise
  5510. * NULL
  5511. */
  5512. struct tm *mbedtls_platform_gmtime_r( const mbedtls_time_t *tt,
  5513. struct tm *tm_buf );
  5514. #endif /* MBEDTLS_HAVE_TIME_DATE */
  5515. #ifdef __cplusplus
  5516. }
  5517. #endif
  5518. #endif /* MBEDTLS_PLATFORM_UTIL_H */
  5519. /********* Start of file include/mbedtls/threading.h ************/
  5520. /**
  5521. * \file threading.h
  5522. *
  5523. * \brief Threading abstraction layer
  5524. */
  5525. /*
  5526. * Copyright The Mbed TLS Contributors
  5527. * SPDX-License-Identifier: Apache-2.0
  5528. *
  5529. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  5530. * not use this file except in compliance with the License.
  5531. * You may obtain a copy of the License at
  5532. *
  5533. * http://www.apache.org/licenses/LICENSE-2.0
  5534. *
  5535. * Unless required by applicable law or agreed to in writing, software
  5536. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  5537. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  5538. * See the License for the specific language governing permissions and
  5539. * limitations under the License.
  5540. */
  5541. #ifndef MBEDTLS_THREADING_H
  5542. #define MBEDTLS_THREADING_H
  5543. #if !defined(MBEDTLS_CONFIG_FILE)
  5544. #else
  5545. #endif
  5546. #include <stdlib.h>
  5547. #ifdef __cplusplus
  5548. extern "C" {
  5549. #endif
  5550. /* MBEDTLS_ERR_THREADING_FEATURE_UNAVAILABLE is deprecated and should not be
  5551. * used. */
  5552. /** The selected feature is not available. */
  5553. #define MBEDTLS_ERR_THREADING_FEATURE_UNAVAILABLE -0x001A
  5554. /** Bad input parameters to function. */
  5555. #define MBEDTLS_ERR_THREADING_BAD_INPUT_DATA -0x001C
  5556. /** Locking / unlocking / free failed with error code. */
  5557. #define MBEDTLS_ERR_THREADING_MUTEX_ERROR -0x001E
  5558. #if defined(MBEDTLS_THREADING_PTHREAD)
  5559. #include <pthread.h>
  5560. typedef struct mbedtls_threading_mutex_t
  5561. {
  5562. pthread_mutex_t mutex;
  5563. /* is_valid is 0 after a failed init or a free, and nonzero after a
  5564. * successful init. This field is not considered part of the public
  5565. * API of Mbed TLS and may change without notice. */
  5566. char is_valid;
  5567. } mbedtls_threading_mutex_t;
  5568. #endif
  5569. #if defined(MBEDTLS_THREADING_ALT)
  5570. /* You should define the mbedtls_threading_mutex_t type in your header */
  5571. /**
  5572. * \brief Set your alternate threading implementation function
  5573. * pointers and initialize global mutexes. If used, this
  5574. * function must be called once in the main thread before any
  5575. * other mbed TLS function is called, and
  5576. * mbedtls_threading_free_alt() must be called once in the main
  5577. * thread after all other mbed TLS functions.
  5578. *
  5579. * \note mutex_init() and mutex_free() don't return a status code.
  5580. * If mutex_init() fails, it should leave its argument (the
  5581. * mutex) in a state such that mutex_lock() will fail when
  5582. * called with this argument.
  5583. *
  5584. * \param mutex_init the init function implementation
  5585. * \param mutex_free the free function implementation
  5586. * \param mutex_lock the lock function implementation
  5587. * \param mutex_unlock the unlock function implementation
  5588. */
  5589. void mbedtls_threading_set_alt( void (*mutex_init)( mbedtls_threading_mutex_t * ),
  5590. void (*mutex_free)( mbedtls_threading_mutex_t * ),
  5591. int (*mutex_lock)( mbedtls_threading_mutex_t * ),
  5592. int (*mutex_unlock)( mbedtls_threading_mutex_t * ) );
  5593. /**
  5594. * \brief Free global mutexes.
  5595. */
  5596. void mbedtls_threading_free_alt( void );
  5597. #endif /* MBEDTLS_THREADING_ALT */
  5598. #if defined(MBEDTLS_THREADING_C)
  5599. /*
  5600. * The function pointers for mutex_init, mutex_free, mutex_ and mutex_unlock
  5601. *
  5602. * All these functions are expected to work or the result will be undefined.
  5603. */
  5604. extern void (*mbedtls_mutex_init)( mbedtls_threading_mutex_t *mutex );
  5605. extern void (*mbedtls_mutex_free)( mbedtls_threading_mutex_t *mutex );
  5606. extern int (*mbedtls_mutex_lock)( mbedtls_threading_mutex_t *mutex );
  5607. extern int (*mbedtls_mutex_unlock)( mbedtls_threading_mutex_t *mutex );
  5608. /*
  5609. * Global mutexes
  5610. */
  5611. #if defined(MBEDTLS_FS_IO)
  5612. extern mbedtls_threading_mutex_t mbedtls_threading_readdir_mutex;
  5613. #endif
  5614. #if defined(MBEDTLS_HAVE_TIME_DATE) && !defined(MBEDTLS_PLATFORM_GMTIME_R_ALT)
  5615. /* This mutex may or may not be used in the default definition of
  5616. * mbedtls_platform_gmtime_r(), but in order to determine that,
  5617. * we need to check POSIX features, hence modify _POSIX_C_SOURCE.
  5618. * With the current approach, this declaration is orphaned, lacking
  5619. * an accompanying definition, in case mbedtls_platform_gmtime_r()
  5620. * doesn't need it, but that's not a problem. */
  5621. extern mbedtls_threading_mutex_t mbedtls_threading_gmtime_mutex;
  5622. #endif /* MBEDTLS_HAVE_TIME_DATE && !MBEDTLS_PLATFORM_GMTIME_R_ALT */
  5623. #endif /* MBEDTLS_THREADING_C */
  5624. #ifdef __cplusplus
  5625. }
  5626. #endif
  5627. #endif /* threading.h */
  5628. /********* Start of file include/mbedtls/bignum.h ************/
  5629. /**
  5630. * \file bignum.h
  5631. *
  5632. * \brief Multi-precision integer library
  5633. */
  5634. /*
  5635. * Copyright The Mbed TLS Contributors
  5636. * SPDX-License-Identifier: Apache-2.0
  5637. *
  5638. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  5639. * not use this file except in compliance with the License.
  5640. * You may obtain a copy of the License at
  5641. *
  5642. * http://www.apache.org/licenses/LICENSE-2.0
  5643. *
  5644. * Unless required by applicable law or agreed to in writing, software
  5645. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  5646. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  5647. * See the License for the specific language governing permissions and
  5648. * limitations under the License.
  5649. */
  5650. #ifndef MBEDTLS_BIGNUM_H
  5651. #define MBEDTLS_BIGNUM_H
  5652. #if !defined(MBEDTLS_CONFIG_FILE)
  5653. #else
  5654. #endif
  5655. #include <stddef.h>
  5656. #include <stdint.h>
  5657. #if defined(MBEDTLS_FS_IO)
  5658. #include <stdio.h>
  5659. #endif
  5660. /** An error occurred while reading from or writing to a file. */
  5661. #define MBEDTLS_ERR_MPI_FILE_IO_ERROR -0x0002
  5662. /** Bad input parameters to function. */
  5663. #define MBEDTLS_ERR_MPI_BAD_INPUT_DATA -0x0004
  5664. /** There is an invalid character in the digit string. */
  5665. #define MBEDTLS_ERR_MPI_INVALID_CHARACTER -0x0006
  5666. /** The buffer is too small to write to. */
  5667. #define MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL -0x0008
  5668. /** The input arguments are negative or result in illegal output. */
  5669. #define MBEDTLS_ERR_MPI_NEGATIVE_VALUE -0x000A
  5670. /** The input argument for division is zero, which is not allowed. */
  5671. #define MBEDTLS_ERR_MPI_DIVISION_BY_ZERO -0x000C
  5672. /** The input arguments are not acceptable. */
  5673. #define MBEDTLS_ERR_MPI_NOT_ACCEPTABLE -0x000E
  5674. /** Memory allocation failed. */
  5675. #define MBEDTLS_ERR_MPI_ALLOC_FAILED -0x0010
  5676. #define MBEDTLS_MPI_CHK(f) \
  5677. do \
  5678. { \
  5679. if( ( ret = (f) ) != 0 ) \
  5680. goto cleanup; \
  5681. } while( 0 )
  5682. /*
  5683. * Maximum size MPIs are allowed to grow to in number of limbs.
  5684. */
  5685. #define MBEDTLS_MPI_MAX_LIMBS 10000
  5686. #if !defined(MBEDTLS_MPI_WINDOW_SIZE)
  5687. /*
  5688. * Maximum window size used for modular exponentiation. Default: 6
  5689. * Minimum value: 1. Maximum value: 6.
  5690. *
  5691. * Result is an array of ( 2 ** MBEDTLS_MPI_WINDOW_SIZE ) MPIs used
  5692. * for the sliding window calculation. (So 64 by default)
  5693. *
  5694. * Reduction in size, reduces speed.
  5695. */
  5696. #define MBEDTLS_MPI_WINDOW_SIZE 6 /**< Maximum window size used. */
  5697. #endif /* !MBEDTLS_MPI_WINDOW_SIZE */
  5698. #if !defined(MBEDTLS_MPI_MAX_SIZE)
  5699. /*
  5700. * Maximum size of MPIs allowed in bits and bytes for user-MPIs.
  5701. * ( Default: 512 bytes => 4096 bits, Maximum tested: 2048 bytes => 16384 bits )
  5702. *
  5703. * Note: Calculations can temporarily result in larger MPIs. So the number
  5704. * of limbs required (MBEDTLS_MPI_MAX_LIMBS) is higher.
  5705. */
  5706. #define MBEDTLS_MPI_MAX_SIZE 1024 /**< Maximum number of bytes for usable MPIs. */
  5707. #endif /* !MBEDTLS_MPI_MAX_SIZE */
  5708. #define MBEDTLS_MPI_MAX_BITS ( 8 * MBEDTLS_MPI_MAX_SIZE ) /**< Maximum number of bits for usable MPIs. */
  5709. /*
  5710. * When reading from files with mbedtls_mpi_read_file() and writing to files with
  5711. * mbedtls_mpi_write_file() the buffer should have space
  5712. * for a (short) label, the MPI (in the provided radix), the newline
  5713. * characters and the '\0'.
  5714. *
  5715. * By default we assume at least a 10 char label, a minimum radix of 10
  5716. * (decimal) and a maximum of 4096 bit numbers (1234 decimal chars).
  5717. * Autosized at compile time for at least a 10 char label, a minimum radix
  5718. * of 10 (decimal) for a number of MBEDTLS_MPI_MAX_BITS size.
  5719. *
  5720. * This used to be statically sized to 1250 for a maximum of 4096 bit
  5721. * numbers (1234 decimal chars).
  5722. *
  5723. * Calculate using the formula:
  5724. * MBEDTLS_MPI_RW_BUFFER_SIZE = ceil(MBEDTLS_MPI_MAX_BITS / ln(10) * ln(2)) +
  5725. * LabelSize + 6
  5726. */
  5727. #define MBEDTLS_MPI_MAX_BITS_SCALE100 ( 100 * MBEDTLS_MPI_MAX_BITS )
  5728. #define MBEDTLS_LN_2_DIV_LN_10_SCALE100 332
  5729. #define MBEDTLS_MPI_RW_BUFFER_SIZE ( ((MBEDTLS_MPI_MAX_BITS_SCALE100 + MBEDTLS_LN_2_DIV_LN_10_SCALE100 - 1) / MBEDTLS_LN_2_DIV_LN_10_SCALE100) + 10 + 6 )
  5730. /*
  5731. * Define the base integer type, architecture-wise.
  5732. *
  5733. * 32 or 64-bit integer types can be forced regardless of the underlying
  5734. * architecture by defining MBEDTLS_HAVE_INT32 or MBEDTLS_HAVE_INT64
  5735. * respectively and undefining MBEDTLS_HAVE_ASM.
  5736. *
  5737. * Double-width integers (e.g. 128-bit in 64-bit architectures) can be
  5738. * disabled by defining MBEDTLS_NO_UDBL_DIVISION.
  5739. */
  5740. #if !defined(MBEDTLS_HAVE_INT32)
  5741. #if defined(_MSC_VER) && defined(_M_AMD64)
  5742. /* Always choose 64-bit when using MSC */
  5743. #if !defined(MBEDTLS_HAVE_INT64)
  5744. #define MBEDTLS_HAVE_INT64
  5745. #endif /* !MBEDTLS_HAVE_INT64 */
  5746. typedef int64_t mbedtls_mpi_sint;
  5747. typedef uint64_t mbedtls_mpi_uint;
  5748. #elif defined(__GNUC__) && ( \
  5749. defined(__amd64__) || defined(__x86_64__) || \
  5750. defined(__ppc64__) || defined(__powerpc64__) || \
  5751. defined(__ia64__) || defined(__alpha__) || \
  5752. ( defined(__sparc__) && defined(__arch64__) ) || \
  5753. defined(__s390x__) || defined(__mips64) || \
  5754. defined(__aarch64__) )
  5755. #if !defined(MBEDTLS_HAVE_INT64)
  5756. #define MBEDTLS_HAVE_INT64
  5757. #endif /* MBEDTLS_HAVE_INT64 */
  5758. typedef int64_t mbedtls_mpi_sint;
  5759. typedef uint64_t mbedtls_mpi_uint;
  5760. #if !defined(MBEDTLS_NO_UDBL_DIVISION)
  5761. /* mbedtls_t_udbl defined as 128-bit unsigned int */
  5762. typedef unsigned int mbedtls_t_udbl __attribute__((mode(TI)));
  5763. #define MBEDTLS_HAVE_UDBL
  5764. #endif /* !MBEDTLS_NO_UDBL_DIVISION */
  5765. #elif defined(__ARMCC_VERSION) && defined(__aarch64__)
  5766. /*
  5767. * __ARMCC_VERSION is defined for both armcc and armclang and
  5768. * __aarch64__ is only defined by armclang when compiling 64-bit code
  5769. */
  5770. #if !defined(MBEDTLS_HAVE_INT64)
  5771. #define MBEDTLS_HAVE_INT64
  5772. #endif /* !MBEDTLS_HAVE_INT64 */
  5773. typedef int64_t mbedtls_mpi_sint;
  5774. typedef uint64_t mbedtls_mpi_uint;
  5775. #if !defined(MBEDTLS_NO_UDBL_DIVISION)
  5776. /* mbedtls_t_udbl defined as 128-bit unsigned int */
  5777. typedef __uint128_t mbedtls_t_udbl;
  5778. #define MBEDTLS_HAVE_UDBL
  5779. #endif /* !MBEDTLS_NO_UDBL_DIVISION */
  5780. #elif defined(MBEDTLS_HAVE_INT64)
  5781. /* Force 64-bit integers with unknown compiler */
  5782. typedef int64_t mbedtls_mpi_sint;
  5783. typedef uint64_t mbedtls_mpi_uint;
  5784. #endif
  5785. #endif /* !MBEDTLS_HAVE_INT32 */
  5786. #if !defined(MBEDTLS_HAVE_INT64)
  5787. /* Default to 32-bit compilation */
  5788. #if !defined(MBEDTLS_HAVE_INT32)
  5789. #define MBEDTLS_HAVE_INT32
  5790. #endif /* !MBEDTLS_HAVE_INT32 */
  5791. typedef int32_t mbedtls_mpi_sint;
  5792. typedef uint32_t mbedtls_mpi_uint;
  5793. #if !defined(MBEDTLS_NO_UDBL_DIVISION)
  5794. typedef uint64_t mbedtls_t_udbl;
  5795. #define MBEDTLS_HAVE_UDBL
  5796. #endif /* !MBEDTLS_NO_UDBL_DIVISION */
  5797. #endif /* !MBEDTLS_HAVE_INT64 */
  5798. #ifdef __cplusplus
  5799. extern "C" {
  5800. #endif
  5801. /**
  5802. * \brief MPI structure
  5803. */
  5804. typedef struct mbedtls_mpi
  5805. {
  5806. int s; /*!< Sign: -1 if the mpi is negative, 1 otherwise */
  5807. size_t n; /*!< total # of limbs */
  5808. mbedtls_mpi_uint *p; /*!< pointer to limbs */
  5809. }
  5810. mbedtls_mpi;
  5811. /**
  5812. * \brief Initialize an MPI context.
  5813. *
  5814. * This makes the MPI ready to be set or freed,
  5815. * but does not define a value for the MPI.
  5816. *
  5817. * \param X The MPI context to initialize. This must not be \c NULL.
  5818. */
  5819. void mbedtls_mpi_init( mbedtls_mpi *X );
  5820. /**
  5821. * \brief This function frees the components of an MPI context.
  5822. *
  5823. * \param X The MPI context to be cleared. This may be \c NULL,
  5824. * in which case this function is a no-op. If it is
  5825. * not \c NULL, it must point to an initialized MPI.
  5826. */
  5827. void mbedtls_mpi_free( mbedtls_mpi *X );
  5828. /**
  5829. * \brief Enlarge an MPI to the specified number of limbs.
  5830. *
  5831. * \note This function does nothing if the MPI is
  5832. * already large enough.
  5833. *
  5834. * \param X The MPI to grow. It must be initialized.
  5835. * \param nblimbs The target number of limbs.
  5836. *
  5837. * \return \c 0 if successful.
  5838. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  5839. * \return Another negative error code on other kinds of failure.
  5840. */
  5841. int mbedtls_mpi_grow( mbedtls_mpi *X, size_t nblimbs );
  5842. /**
  5843. * \brief This function resizes an MPI downwards, keeping at least the
  5844. * specified number of limbs.
  5845. *
  5846. * If \c X is smaller than \c nblimbs, it is resized up
  5847. * instead.
  5848. *
  5849. * \param X The MPI to shrink. This must point to an initialized MPI.
  5850. * \param nblimbs The minimum number of limbs to keep.
  5851. *
  5852. * \return \c 0 if successful.
  5853. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed
  5854. * (this can only happen when resizing up).
  5855. * \return Another negative error code on other kinds of failure.
  5856. */
  5857. int mbedtls_mpi_shrink( mbedtls_mpi *X, size_t nblimbs );
  5858. /**
  5859. * \brief Make a copy of an MPI.
  5860. *
  5861. * \param X The destination MPI. This must point to an initialized MPI.
  5862. * \param Y The source MPI. This must point to an initialized MPI.
  5863. *
  5864. * \note The limb-buffer in the destination MPI is enlarged
  5865. * if necessary to hold the value in the source MPI.
  5866. *
  5867. * \return \c 0 if successful.
  5868. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  5869. * \return Another negative error code on other kinds of failure.
  5870. */
  5871. int mbedtls_mpi_copy( mbedtls_mpi *X, const mbedtls_mpi *Y );
  5872. /**
  5873. * \brief Swap the contents of two MPIs.
  5874. *
  5875. * \param X The first MPI. It must be initialized.
  5876. * \param Y The second MPI. It must be initialized.
  5877. */
  5878. void mbedtls_mpi_swap( mbedtls_mpi *X, mbedtls_mpi *Y );
  5879. /**
  5880. * \brief Perform a safe conditional copy of MPI which doesn't
  5881. * reveal whether the condition was true or not.
  5882. *
  5883. * \param X The MPI to conditionally assign to. This must point
  5884. * to an initialized MPI.
  5885. * \param Y The MPI to be assigned from. This must point to an
  5886. * initialized MPI.
  5887. * \param assign The condition deciding whether to perform the
  5888. * assignment or not. Possible values:
  5889. * * \c 1: Perform the assignment `X = Y`.
  5890. * * \c 0: Keep the original value of \p X.
  5891. *
  5892. * \note This function is equivalent to
  5893. * `if( assign ) mbedtls_mpi_copy( X, Y );`
  5894. * except that it avoids leaking any information about whether
  5895. * the assignment was done or not (the above code may leak
  5896. * information through branch prediction and/or memory access
  5897. * patterns analysis).
  5898. *
  5899. * \return \c 0 if successful.
  5900. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  5901. * \return Another negative error code on other kinds of failure.
  5902. */
  5903. int mbedtls_mpi_safe_cond_assign( mbedtls_mpi *X, const mbedtls_mpi *Y, unsigned char assign );
  5904. /**
  5905. * \brief Perform a safe conditional swap which doesn't
  5906. * reveal whether the condition was true or not.
  5907. *
  5908. * \param X The first MPI. This must be initialized.
  5909. * \param Y The second MPI. This must be initialized.
  5910. * \param assign The condition deciding whether to perform
  5911. * the swap or not. Possible values:
  5912. * * \c 1: Swap the values of \p X and \p Y.
  5913. * * \c 0: Keep the original values of \p X and \p Y.
  5914. *
  5915. * \note This function is equivalent to
  5916. * if( assign ) mbedtls_mpi_swap( X, Y );
  5917. * except that it avoids leaking any information about whether
  5918. * the assignment was done or not (the above code may leak
  5919. * information through branch prediction and/or memory access
  5920. * patterns analysis).
  5921. *
  5922. * \return \c 0 if successful.
  5923. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  5924. * \return Another negative error code on other kinds of failure.
  5925. *
  5926. */
  5927. int mbedtls_mpi_safe_cond_swap( mbedtls_mpi *X, mbedtls_mpi *Y, unsigned char assign );
  5928. /**
  5929. * \brief Store integer value in MPI.
  5930. *
  5931. * \param X The MPI to set. This must be initialized.
  5932. * \param z The value to use.
  5933. *
  5934. * \return \c 0 if successful.
  5935. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  5936. * \return Another negative error code on other kinds of failure.
  5937. */
  5938. int mbedtls_mpi_lset( mbedtls_mpi *X, mbedtls_mpi_sint z );
  5939. /**
  5940. * \brief Get a specific bit from an MPI.
  5941. *
  5942. * \param X The MPI to query. This must be initialized.
  5943. * \param pos Zero-based index of the bit to query.
  5944. *
  5945. * \return \c 0 or \c 1 on success, depending on whether bit \c pos
  5946. * of \c X is unset or set.
  5947. * \return A negative error code on failure.
  5948. */
  5949. int mbedtls_mpi_get_bit( const mbedtls_mpi *X, size_t pos );
  5950. /**
  5951. * \brief Modify a specific bit in an MPI.
  5952. *
  5953. * \note This function will grow the target MPI if necessary to set a
  5954. * bit to \c 1 in a not yet existing limb. It will not grow if
  5955. * the bit should be set to \c 0.
  5956. *
  5957. * \param X The MPI to modify. This must be initialized.
  5958. * \param pos Zero-based index of the bit to modify.
  5959. * \param val The desired value of bit \c pos: \c 0 or \c 1.
  5960. *
  5961. * \return \c 0 if successful.
  5962. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  5963. * \return Another negative error code on other kinds of failure.
  5964. */
  5965. int mbedtls_mpi_set_bit( mbedtls_mpi *X, size_t pos, unsigned char val );
  5966. /**
  5967. * \brief Return the number of bits of value \c 0 before the
  5968. * least significant bit of value \c 1.
  5969. *
  5970. * \note This is the same as the zero-based index of
  5971. * the least significant bit of value \c 1.
  5972. *
  5973. * \param X The MPI to query.
  5974. *
  5975. * \return The number of bits of value \c 0 before the least significant
  5976. * bit of value \c 1 in \p X.
  5977. */
  5978. size_t mbedtls_mpi_lsb( const mbedtls_mpi *X );
  5979. /**
  5980. * \brief Return the number of bits up to and including the most
  5981. * significant bit of value \c 1.
  5982. *
  5983. * * \note This is same as the one-based index of the most
  5984. * significant bit of value \c 1.
  5985. *
  5986. * \param X The MPI to query. This must point to an initialized MPI.
  5987. *
  5988. * \return The number of bits up to and including the most
  5989. * significant bit of value \c 1.
  5990. */
  5991. size_t mbedtls_mpi_bitlen( const mbedtls_mpi *X );
  5992. /**
  5993. * \brief Return the total size of an MPI value in bytes.
  5994. *
  5995. * \param X The MPI to use. This must point to an initialized MPI.
  5996. *
  5997. * \note The value returned by this function may be less than
  5998. * the number of bytes used to store \p X internally.
  5999. * This happens if and only if there are trailing bytes
  6000. * of value zero.
  6001. *
  6002. * \return The least number of bytes capable of storing
  6003. * the absolute value of \p X.
  6004. */
  6005. size_t mbedtls_mpi_size( const mbedtls_mpi *X );
  6006. /**
  6007. * \brief Import an MPI from an ASCII string.
  6008. *
  6009. * \param X The destination MPI. This must point to an initialized MPI.
  6010. * \param radix The numeric base of the input string.
  6011. * \param s Null-terminated string buffer.
  6012. *
  6013. * \return \c 0 if successful.
  6014. * \return A negative error code on failure.
  6015. */
  6016. int mbedtls_mpi_read_string( mbedtls_mpi *X, int radix, const char *s );
  6017. /**
  6018. * \brief Export an MPI to an ASCII string.
  6019. *
  6020. * \param X The source MPI. This must point to an initialized MPI.
  6021. * \param radix The numeric base of the output string.
  6022. * \param buf The buffer to write the string to. This must be writable
  6023. * buffer of length \p buflen Bytes.
  6024. * \param buflen The available size in Bytes of \p buf.
  6025. * \param olen The address at which to store the length of the string
  6026. * written, including the final \c NULL byte. This must
  6027. * not be \c NULL.
  6028. *
  6029. * \note You can call this function with `buflen == 0` to obtain the
  6030. * minimum required buffer size in `*olen`.
  6031. *
  6032. * \return \c 0 if successful.
  6033. * \return #MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL if the target buffer \p buf
  6034. * is too small to hold the value of \p X in the desired base.
  6035. * In this case, `*olen` is nonetheless updated to contain the
  6036. * size of \p buf required for a successful call.
  6037. * \return Another negative error code on different kinds of failure.
  6038. */
  6039. int mbedtls_mpi_write_string( const mbedtls_mpi *X, int radix,
  6040. char *buf, size_t buflen, size_t *olen );
  6041. #if defined(MBEDTLS_FS_IO)
  6042. /**
  6043. * \brief Read an MPI from a line in an opened file.
  6044. *
  6045. * \param X The destination MPI. This must point to an initialized MPI.
  6046. * \param radix The numeric base of the string representation used
  6047. * in the source line.
  6048. * \param fin The input file handle to use. This must not be \c NULL.
  6049. *
  6050. * \note On success, this function advances the file stream
  6051. * to the end of the current line or to EOF.
  6052. *
  6053. * The function returns \c 0 on an empty line.
  6054. *
  6055. * Leading whitespaces are ignored, as is a
  6056. * '0x' prefix for radix \c 16.
  6057. *
  6058. * \return \c 0 if successful.
  6059. * \return #MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL if the file read buffer
  6060. * is too small.
  6061. * \return Another negative error code on failure.
  6062. */
  6063. int mbedtls_mpi_read_file( mbedtls_mpi *X, int radix, FILE *fin );
  6064. /**
  6065. * \brief Export an MPI into an opened file.
  6066. *
  6067. * \param p A string prefix to emit prior to the MPI data.
  6068. * For example, this might be a label, or "0x" when
  6069. * printing in base \c 16. This may be \c NULL if no prefix
  6070. * is needed.
  6071. * \param X The source MPI. This must point to an initialized MPI.
  6072. * \param radix The numeric base to be used in the emitted string.
  6073. * \param fout The output file handle. This may be \c NULL, in which case
  6074. * the output is written to \c stdout.
  6075. *
  6076. * \return \c 0 if successful.
  6077. * \return A negative error code on failure.
  6078. */
  6079. int mbedtls_mpi_write_file( const char *p, const mbedtls_mpi *X,
  6080. int radix, FILE *fout );
  6081. #endif /* MBEDTLS_FS_IO */
  6082. /**
  6083. * \brief Import an MPI from unsigned big endian binary data.
  6084. *
  6085. * \param X The destination MPI. This must point to an initialized MPI.
  6086. * \param buf The input buffer. This must be a readable buffer of length
  6087. * \p buflen Bytes.
  6088. * \param buflen The length of the input buffer \p p in Bytes.
  6089. *
  6090. * \return \c 0 if successful.
  6091. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  6092. * \return Another negative error code on different kinds of failure.
  6093. */
  6094. int mbedtls_mpi_read_binary( mbedtls_mpi *X, const unsigned char *buf,
  6095. size_t buflen );
  6096. /**
  6097. * \brief Import X from unsigned binary data, little endian
  6098. *
  6099. * \param X The destination MPI. This must point to an initialized MPI.
  6100. * \param buf The input buffer. This must be a readable buffer of length
  6101. * \p buflen Bytes.
  6102. * \param buflen The length of the input buffer \p p in Bytes.
  6103. *
  6104. * \return \c 0 if successful.
  6105. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  6106. * \return Another negative error code on different kinds of failure.
  6107. */
  6108. int mbedtls_mpi_read_binary_le( mbedtls_mpi *X,
  6109. const unsigned char *buf, size_t buflen );
  6110. /**
  6111. * \brief Export X into unsigned binary data, big endian.
  6112. * Always fills the whole buffer, which will start with zeros
  6113. * if the number is smaller.
  6114. *
  6115. * \param X The source MPI. This must point to an initialized MPI.
  6116. * \param buf The output buffer. This must be a writable buffer of length
  6117. * \p buflen Bytes.
  6118. * \param buflen The size of the output buffer \p buf in Bytes.
  6119. *
  6120. * \return \c 0 if successful.
  6121. * \return #MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL if \p buf isn't
  6122. * large enough to hold the value of \p X.
  6123. * \return Another negative error code on different kinds of failure.
  6124. */
  6125. int mbedtls_mpi_write_binary( const mbedtls_mpi *X, unsigned char *buf,
  6126. size_t buflen );
  6127. /**
  6128. * \brief Export X into unsigned binary data, little endian.
  6129. * Always fills the whole buffer, which will end with zeros
  6130. * if the number is smaller.
  6131. *
  6132. * \param X The source MPI. This must point to an initialized MPI.
  6133. * \param buf The output buffer. This must be a writable buffer of length
  6134. * \p buflen Bytes.
  6135. * \param buflen The size of the output buffer \p buf in Bytes.
  6136. *
  6137. * \return \c 0 if successful.
  6138. * \return #MBEDTLS_ERR_MPI_BUFFER_TOO_SMALL if \p buf isn't
  6139. * large enough to hold the value of \p X.
  6140. * \return Another negative error code on different kinds of failure.
  6141. */
  6142. int mbedtls_mpi_write_binary_le( const mbedtls_mpi *X,
  6143. unsigned char *buf, size_t buflen );
  6144. /**
  6145. * \brief Perform a left-shift on an MPI: X <<= count
  6146. *
  6147. * \param X The MPI to shift. This must point to an initialized MPI.
  6148. * \param count The number of bits to shift by.
  6149. *
  6150. * \return \c 0 if successful.
  6151. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6152. * \return Another negative error code on different kinds of failure.
  6153. */
  6154. int mbedtls_mpi_shift_l( mbedtls_mpi *X, size_t count );
  6155. /**
  6156. * \brief Perform a right-shift on an MPI: X >>= count
  6157. *
  6158. * \param X The MPI to shift. This must point to an initialized MPI.
  6159. * \param count The number of bits to shift by.
  6160. *
  6161. * \return \c 0 if successful.
  6162. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6163. * \return Another negative error code on different kinds of failure.
  6164. */
  6165. int mbedtls_mpi_shift_r( mbedtls_mpi *X, size_t count );
  6166. /**
  6167. * \brief Compare the absolute values of two MPIs.
  6168. *
  6169. * \param X The left-hand MPI. This must point to an initialized MPI.
  6170. * \param Y The right-hand MPI. This must point to an initialized MPI.
  6171. *
  6172. * \return \c 1 if `|X|` is greater than `|Y|`.
  6173. * \return \c -1 if `|X|` is lesser than `|Y|`.
  6174. * \return \c 0 if `|X|` is equal to `|Y|`.
  6175. */
  6176. int mbedtls_mpi_cmp_abs( const mbedtls_mpi *X, const mbedtls_mpi *Y );
  6177. /**
  6178. * \brief Compare two MPIs.
  6179. *
  6180. * \param X The left-hand MPI. This must point to an initialized MPI.
  6181. * \param Y The right-hand MPI. This must point to an initialized MPI.
  6182. *
  6183. * \return \c 1 if \p X is greater than \p Y.
  6184. * \return \c -1 if \p X is lesser than \p Y.
  6185. * \return \c 0 if \p X is equal to \p Y.
  6186. */
  6187. int mbedtls_mpi_cmp_mpi( const mbedtls_mpi *X, const mbedtls_mpi *Y );
  6188. /**
  6189. * \brief Check if an MPI is less than the other in constant time.
  6190. *
  6191. * \param X The left-hand MPI. This must point to an initialized MPI
  6192. * with the same allocated length as Y.
  6193. * \param Y The right-hand MPI. This must point to an initialized MPI
  6194. * with the same allocated length as X.
  6195. * \param ret The result of the comparison:
  6196. * \c 1 if \p X is less than \p Y.
  6197. * \c 0 if \p X is greater than or equal to \p Y.
  6198. *
  6199. * \return 0 on success.
  6200. * \return MBEDTLS_ERR_MPI_BAD_INPUT_DATA if the allocated length of
  6201. * the two input MPIs is not the same.
  6202. */
  6203. int mbedtls_mpi_lt_mpi_ct( const mbedtls_mpi *X, const mbedtls_mpi *Y,
  6204. unsigned *ret );
  6205. /**
  6206. * \brief Compare an MPI with an integer.
  6207. *
  6208. * \param X The left-hand MPI. This must point to an initialized MPI.
  6209. * \param z The integer value to compare \p X to.
  6210. *
  6211. * \return \c 1 if \p X is greater than \p z.
  6212. * \return \c -1 if \p X is lesser than \p z.
  6213. * \return \c 0 if \p X is equal to \p z.
  6214. */
  6215. int mbedtls_mpi_cmp_int( const mbedtls_mpi *X, mbedtls_mpi_sint z );
  6216. /**
  6217. * \brief Perform an unsigned addition of MPIs: X = |A| + |B|
  6218. *
  6219. * \param X The destination MPI. This must point to an initialized MPI.
  6220. * \param A The first summand. This must point to an initialized MPI.
  6221. * \param B The second summand. This must point to an initialized MPI.
  6222. *
  6223. * \return \c 0 if successful.
  6224. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6225. * \return Another negative error code on different kinds of failure.
  6226. */
  6227. int mbedtls_mpi_add_abs( mbedtls_mpi *X, const mbedtls_mpi *A,
  6228. const mbedtls_mpi *B );
  6229. /**
  6230. * \brief Perform an unsigned subtraction of MPIs: X = |A| - |B|
  6231. *
  6232. * \param X The destination MPI. This must point to an initialized MPI.
  6233. * \param A The minuend. This must point to an initialized MPI.
  6234. * \param B The subtrahend. This must point to an initialized MPI.
  6235. *
  6236. * \return \c 0 if successful.
  6237. * \return #MBEDTLS_ERR_MPI_NEGATIVE_VALUE if \p B is greater than \p A.
  6238. * \return Another negative error code on different kinds of failure.
  6239. *
  6240. */
  6241. int mbedtls_mpi_sub_abs( mbedtls_mpi *X, const mbedtls_mpi *A,
  6242. const mbedtls_mpi *B );
  6243. /**
  6244. * \brief Perform a signed addition of MPIs: X = A + B
  6245. *
  6246. * \param X The destination MPI. This must point to an initialized MPI.
  6247. * \param A The first summand. This must point to an initialized MPI.
  6248. * \param B The second summand. This must point to an initialized MPI.
  6249. *
  6250. * \return \c 0 if successful.
  6251. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6252. * \return Another negative error code on different kinds of failure.
  6253. */
  6254. int mbedtls_mpi_add_mpi( mbedtls_mpi *X, const mbedtls_mpi *A,
  6255. const mbedtls_mpi *B );
  6256. /**
  6257. * \brief Perform a signed subtraction of MPIs: X = A - B
  6258. *
  6259. * \param X The destination MPI. This must point to an initialized MPI.
  6260. * \param A The minuend. This must point to an initialized MPI.
  6261. * \param B The subtrahend. This must point to an initialized MPI.
  6262. *
  6263. * \return \c 0 if successful.
  6264. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6265. * \return Another negative error code on different kinds of failure.
  6266. */
  6267. int mbedtls_mpi_sub_mpi( mbedtls_mpi *X, const mbedtls_mpi *A,
  6268. const mbedtls_mpi *B );
  6269. /**
  6270. * \brief Perform a signed addition of an MPI and an integer: X = A + b
  6271. *
  6272. * \param X The destination MPI. This must point to an initialized MPI.
  6273. * \param A The first summand. This must point to an initialized MPI.
  6274. * \param b The second summand.
  6275. *
  6276. * \return \c 0 if successful.
  6277. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6278. * \return Another negative error code on different kinds of failure.
  6279. */
  6280. int mbedtls_mpi_add_int( mbedtls_mpi *X, const mbedtls_mpi *A,
  6281. mbedtls_mpi_sint b );
  6282. /**
  6283. * \brief Perform a signed subtraction of an MPI and an integer:
  6284. * X = A - b
  6285. *
  6286. * \param X The destination MPI. This must point to an initialized MPI.
  6287. * \param A The minuend. This must point to an initialized MPI.
  6288. * \param b The subtrahend.
  6289. *
  6290. * \return \c 0 if successful.
  6291. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6292. * \return Another negative error code on different kinds of failure.
  6293. */
  6294. int mbedtls_mpi_sub_int( mbedtls_mpi *X, const mbedtls_mpi *A,
  6295. mbedtls_mpi_sint b );
  6296. /**
  6297. * \brief Perform a multiplication of two MPIs: X = A * B
  6298. *
  6299. * \param X The destination MPI. This must point to an initialized MPI.
  6300. * \param A The first factor. This must point to an initialized MPI.
  6301. * \param B The second factor. This must point to an initialized MPI.
  6302. *
  6303. * \return \c 0 if successful.
  6304. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6305. * \return Another negative error code on different kinds of failure.
  6306. *
  6307. */
  6308. int mbedtls_mpi_mul_mpi( mbedtls_mpi *X, const mbedtls_mpi *A,
  6309. const mbedtls_mpi *B );
  6310. /**
  6311. * \brief Perform a multiplication of an MPI with an unsigned integer:
  6312. * X = A * b
  6313. *
  6314. * \param X The destination MPI. This must point to an initialized MPI.
  6315. * \param A The first factor. This must point to an initialized MPI.
  6316. * \param b The second factor.
  6317. *
  6318. * \return \c 0 if successful.
  6319. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6320. * \return Another negative error code on different kinds of failure.
  6321. *
  6322. */
  6323. int mbedtls_mpi_mul_int( mbedtls_mpi *X, const mbedtls_mpi *A,
  6324. mbedtls_mpi_uint b );
  6325. /**
  6326. * \brief Perform a division with remainder of two MPIs:
  6327. * A = Q * B + R
  6328. *
  6329. * \param Q The destination MPI for the quotient.
  6330. * This may be \c NULL if the value of the
  6331. * quotient is not needed.
  6332. * \param R The destination MPI for the remainder value.
  6333. * This may be \c NULL if the value of the
  6334. * remainder is not needed.
  6335. * \param A The dividend. This must point to an initialized MPi.
  6336. * \param B The divisor. This must point to an initialized MPI.
  6337. *
  6338. * \return \c 0 if successful.
  6339. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  6340. * \return #MBEDTLS_ERR_MPI_DIVISION_BY_ZERO if \p B equals zero.
  6341. * \return Another negative error code on different kinds of failure.
  6342. */
  6343. int mbedtls_mpi_div_mpi( mbedtls_mpi *Q, mbedtls_mpi *R, const mbedtls_mpi *A,
  6344. const mbedtls_mpi *B );
  6345. /**
  6346. * \brief Perform a division with remainder of an MPI by an integer:
  6347. * A = Q * b + R
  6348. *
  6349. * \param Q The destination MPI for the quotient.
  6350. * This may be \c NULL if the value of the
  6351. * quotient is not needed.
  6352. * \param R The destination MPI for the remainder value.
  6353. * This may be \c NULL if the value of the
  6354. * remainder is not needed.
  6355. * \param A The dividend. This must point to an initialized MPi.
  6356. * \param b The divisor.
  6357. *
  6358. * \return \c 0 if successful.
  6359. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  6360. * \return #MBEDTLS_ERR_MPI_DIVISION_BY_ZERO if \p b equals zero.
  6361. * \return Another negative error code on different kinds of failure.
  6362. */
  6363. int mbedtls_mpi_div_int( mbedtls_mpi *Q, mbedtls_mpi *R, const mbedtls_mpi *A,
  6364. mbedtls_mpi_sint b );
  6365. /**
  6366. * \brief Perform a modular reduction. R = A mod B
  6367. *
  6368. * \param R The destination MPI for the residue value.
  6369. * This must point to an initialized MPI.
  6370. * \param A The MPI to compute the residue of.
  6371. * This must point to an initialized MPI.
  6372. * \param B The base of the modular reduction.
  6373. * This must point to an initialized MPI.
  6374. *
  6375. * \return \c 0 if successful.
  6376. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6377. * \return #MBEDTLS_ERR_MPI_DIVISION_BY_ZERO if \p B equals zero.
  6378. * \return #MBEDTLS_ERR_MPI_NEGATIVE_VALUE if \p B is negative.
  6379. * \return Another negative error code on different kinds of failure.
  6380. *
  6381. */
  6382. int mbedtls_mpi_mod_mpi( mbedtls_mpi *R, const mbedtls_mpi *A,
  6383. const mbedtls_mpi *B );
  6384. /**
  6385. * \brief Perform a modular reduction with respect to an integer.
  6386. * r = A mod b
  6387. *
  6388. * \param r The address at which to store the residue.
  6389. * This must not be \c NULL.
  6390. * \param A The MPI to compute the residue of.
  6391. * This must point to an initialized MPi.
  6392. * \param b The integer base of the modular reduction.
  6393. *
  6394. * \return \c 0 if successful.
  6395. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6396. * \return #MBEDTLS_ERR_MPI_DIVISION_BY_ZERO if \p b equals zero.
  6397. * \return #MBEDTLS_ERR_MPI_NEGATIVE_VALUE if \p b is negative.
  6398. * \return Another negative error code on different kinds of failure.
  6399. */
  6400. int mbedtls_mpi_mod_int( mbedtls_mpi_uint *r, const mbedtls_mpi *A,
  6401. mbedtls_mpi_sint b );
  6402. /**
  6403. * \brief Perform a sliding-window exponentiation: X = A^E mod N
  6404. *
  6405. * \param X The destination MPI. This must point to an initialized MPI.
  6406. * \param A The base of the exponentiation.
  6407. * This must point to an initialized MPI.
  6408. * \param E The exponent MPI. This must point to an initialized MPI.
  6409. * \param N The base for the modular reduction. This must point to an
  6410. * initialized MPI.
  6411. * \param prec_RR A helper MPI depending solely on \p N which can be used to
  6412. * speed-up multiple modular exponentiations for the same value
  6413. * of \p N. This may be \c NULL. If it is not \c NULL, it must
  6414. * point to an initialized MPI. If it hasn't been used after
  6415. * the call to mbedtls_mpi_init(), this function will compute
  6416. * the helper value and store it in \p prec_RR for reuse on
  6417. * subsequent calls to this function. Otherwise, the function
  6418. * will assume that \p prec_RR holds the helper value set by a
  6419. * previous call to mbedtls_mpi_exp_mod(), and reuse it.
  6420. *
  6421. * \return \c 0 if successful.
  6422. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6423. * \return #MBEDTLS_ERR_MPI_BAD_INPUT_DATA if \c N is negative or
  6424. * even, or if \c E is negative.
  6425. * \return Another negative error code on different kinds of failures.
  6426. *
  6427. */
  6428. int mbedtls_mpi_exp_mod( mbedtls_mpi *X, const mbedtls_mpi *A,
  6429. const mbedtls_mpi *E, const mbedtls_mpi *N,
  6430. mbedtls_mpi *prec_RR );
  6431. /**
  6432. * \brief Fill an MPI with a number of random bytes.
  6433. *
  6434. * \param X The destination MPI. This must point to an initialized MPI.
  6435. * \param size The number of random bytes to generate.
  6436. * \param f_rng The RNG function to use. This must not be \c NULL.
  6437. * \param p_rng The RNG parameter to be passed to \p f_rng. This may be
  6438. * \c NULL if \p f_rng doesn't need a context argument.
  6439. *
  6440. * \return \c 0 if successful.
  6441. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6442. * \return Another negative error code on failure.
  6443. *
  6444. * \note The bytes obtained from the RNG are interpreted
  6445. * as a big-endian representation of an MPI; this can
  6446. * be relevant in applications like deterministic ECDSA.
  6447. */
  6448. int mbedtls_mpi_fill_random( mbedtls_mpi *X, size_t size,
  6449. int (*f_rng)(void *, unsigned char *, size_t),
  6450. void *p_rng );
  6451. /** Generate a random number uniformly in a range.
  6452. *
  6453. * This function generates a random number between \p min inclusive and
  6454. * \p N exclusive.
  6455. *
  6456. * The procedure complies with RFC 6979 §3.3 (deterministic ECDSA)
  6457. * when the RNG is a suitably parametrized instance of HMAC_DRBG
  6458. * and \p min is \c 1.
  6459. *
  6460. * \note There are `N - min` possible outputs. The lower bound
  6461. * \p min can be reached, but the upper bound \p N cannot.
  6462. *
  6463. * \param X The destination MPI. This must point to an initialized MPI.
  6464. * \param min The minimum value to return.
  6465. * It must be nonnegative.
  6466. * \param N The upper bound of the range, exclusive.
  6467. * In other words, this is one plus the maximum value to return.
  6468. * \p N must be strictly larger than \p min.
  6469. * \param f_rng The RNG function to use. This must not be \c NULL.
  6470. * \param p_rng The RNG parameter to be passed to \p f_rng.
  6471. *
  6472. * \return \c 0 if successful.
  6473. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6474. * \return #MBEDTLS_ERR_MPI_BAD_INPUT_DATA if \p min or \p N is invalid
  6475. * or if they are incompatible.
  6476. * \return #MBEDTLS_ERR_MPI_NOT_ACCEPTABLE if the implementation was
  6477. * unable to find a suitable value within a limited number
  6478. * of attempts. This has a negligible probability if \p N
  6479. * is significantly larger than \p min, which is the case
  6480. * for all usual cryptographic applications.
  6481. * \return Another negative error code on failure.
  6482. */
  6483. int mbedtls_mpi_random( mbedtls_mpi *X,
  6484. mbedtls_mpi_sint min,
  6485. const mbedtls_mpi *N,
  6486. int (*f_rng)(void *, unsigned char *, size_t),
  6487. void *p_rng );
  6488. /**
  6489. * \brief Compute the greatest common divisor: G = gcd(A, B)
  6490. *
  6491. * \param G The destination MPI. This must point to an initialized MPI.
  6492. * \param A The first operand. This must point to an initialized MPI.
  6493. * \param B The second operand. This must point to an initialized MPI.
  6494. *
  6495. * \return \c 0 if successful.
  6496. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6497. * \return Another negative error code on different kinds of failure.
  6498. */
  6499. int mbedtls_mpi_gcd( mbedtls_mpi *G, const mbedtls_mpi *A,
  6500. const mbedtls_mpi *B );
  6501. /**
  6502. * \brief Compute the modular inverse: X = A^-1 mod N
  6503. *
  6504. * \param X The destination MPI. This must point to an initialized MPI.
  6505. * \param A The MPI to calculate the modular inverse of. This must point
  6506. * to an initialized MPI.
  6507. * \param N The base of the modular inversion. This must point to an
  6508. * initialized MPI.
  6509. *
  6510. * \return \c 0 if successful.
  6511. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6512. * \return #MBEDTLS_ERR_MPI_BAD_INPUT_DATA if \p N is less than
  6513. * or equal to one.
  6514. * \return #MBEDTLS_ERR_MPI_NOT_ACCEPTABLE if \p has no modular inverse
  6515. * with respect to \p N.
  6516. */
  6517. int mbedtls_mpi_inv_mod( mbedtls_mpi *X, const mbedtls_mpi *A,
  6518. const mbedtls_mpi *N );
  6519. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  6520. #if defined(MBEDTLS_DEPRECATED_WARNING)
  6521. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  6522. #else
  6523. #define MBEDTLS_DEPRECATED
  6524. #endif
  6525. /**
  6526. * \brief Perform a Miller-Rabin primality test with error
  6527. * probability of 2<sup>-80</sup>.
  6528. *
  6529. * \deprecated Superseded by mbedtls_mpi_is_prime_ext() which allows
  6530. * specifying the number of Miller-Rabin rounds.
  6531. *
  6532. * \param X The MPI to check for primality.
  6533. * This must point to an initialized MPI.
  6534. * \param f_rng The RNG function to use. This must not be \c NULL.
  6535. * \param p_rng The RNG parameter to be passed to \p f_rng.
  6536. * This may be \c NULL if \p f_rng doesn't use a
  6537. * context parameter.
  6538. *
  6539. * \return \c 0 if successful, i.e. \p X is probably prime.
  6540. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6541. * \return #MBEDTLS_ERR_MPI_NOT_ACCEPTABLE if \p X is not prime.
  6542. * \return Another negative error code on other kinds of failure.
  6543. */
  6544. MBEDTLS_DEPRECATED int mbedtls_mpi_is_prime( const mbedtls_mpi *X,
  6545. int (*f_rng)(void *, unsigned char *, size_t),
  6546. void *p_rng );
  6547. #undef MBEDTLS_DEPRECATED
  6548. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  6549. /**
  6550. * \brief Miller-Rabin primality test.
  6551. *
  6552. * \warning If \p X is potentially generated by an adversary, for example
  6553. * when validating cryptographic parameters that you didn't
  6554. * generate yourself and that are supposed to be prime, then
  6555. * \p rounds should be at least the half of the security
  6556. * strength of the cryptographic algorithm. On the other hand,
  6557. * if \p X is chosen uniformly or non-adversially (as is the
  6558. * case when mbedtls_mpi_gen_prime calls this function), then
  6559. * \p rounds can be much lower.
  6560. *
  6561. * \param X The MPI to check for primality.
  6562. * This must point to an initialized MPI.
  6563. * \param rounds The number of bases to perform the Miller-Rabin primality
  6564. * test for. The probability of returning 0 on a composite is
  6565. * at most 2<sup>-2*\p rounds</sup>.
  6566. * \param f_rng The RNG function to use. This must not be \c NULL.
  6567. * \param p_rng The RNG parameter to be passed to \p f_rng.
  6568. * This may be \c NULL if \p f_rng doesn't use
  6569. * a context parameter.
  6570. *
  6571. * \return \c 0 if successful, i.e. \p X is probably prime.
  6572. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6573. * \return #MBEDTLS_ERR_MPI_NOT_ACCEPTABLE if \p X is not prime.
  6574. * \return Another negative error code on other kinds of failure.
  6575. */
  6576. int mbedtls_mpi_is_prime_ext( const mbedtls_mpi *X, int rounds,
  6577. int (*f_rng)(void *, unsigned char *, size_t),
  6578. void *p_rng );
  6579. /**
  6580. * \brief Flags for mbedtls_mpi_gen_prime()
  6581. *
  6582. * Each of these flags is a constraint on the result X returned by
  6583. * mbedtls_mpi_gen_prime().
  6584. */
  6585. typedef enum {
  6586. MBEDTLS_MPI_GEN_PRIME_FLAG_DH = 0x0001, /**< (X-1)/2 is prime too */
  6587. MBEDTLS_MPI_GEN_PRIME_FLAG_LOW_ERR = 0x0002, /**< lower error rate from 2<sup>-80</sup> to 2<sup>-128</sup> */
  6588. } mbedtls_mpi_gen_prime_flag_t;
  6589. /**
  6590. * \brief Generate a prime number.
  6591. *
  6592. * \param X The destination MPI to store the generated prime in.
  6593. * This must point to an initialized MPi.
  6594. * \param nbits The required size of the destination MPI in bits.
  6595. * This must be between \c 3 and #MBEDTLS_MPI_MAX_BITS.
  6596. * \param flags A mask of flags of type #mbedtls_mpi_gen_prime_flag_t.
  6597. * \param f_rng The RNG function to use. This must not be \c NULL.
  6598. * \param p_rng The RNG parameter to be passed to \p f_rng.
  6599. * This may be \c NULL if \p f_rng doesn't use
  6600. * a context parameter.
  6601. *
  6602. * \return \c 0 if successful, in which case \p X holds a
  6603. * probably prime number.
  6604. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if a memory allocation failed.
  6605. * \return #MBEDTLS_ERR_MPI_BAD_INPUT_DATA if `nbits` is not between
  6606. * \c 3 and #MBEDTLS_MPI_MAX_BITS.
  6607. */
  6608. int mbedtls_mpi_gen_prime( mbedtls_mpi *X, size_t nbits, int flags,
  6609. int (*f_rng)(void *, unsigned char *, size_t),
  6610. void *p_rng );
  6611. #if defined(MBEDTLS_SELF_TEST)
  6612. /**
  6613. * \brief Checkup routine
  6614. *
  6615. * \return 0 if successful, or 1 if the test failed
  6616. */
  6617. int mbedtls_mpi_self_test( int verbose );
  6618. #endif /* MBEDTLS_SELF_TEST */
  6619. #ifdef __cplusplus
  6620. }
  6621. #endif
  6622. #endif /* bignum.h */
  6623. /********* Start of file include/mbedtls/constant_time.h ************/
  6624. /**
  6625. * Constant-time functions
  6626. *
  6627. * Copyright The Mbed TLS Contributors
  6628. * SPDX-License-Identifier: Apache-2.0
  6629. *
  6630. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  6631. * not use this file except in compliance with the License.
  6632. * You may obtain a copy of the License at
  6633. *
  6634. * http://www.apache.org/licenses/LICENSE-2.0
  6635. *
  6636. * Unless required by applicable law or agreed to in writing, software
  6637. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  6638. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  6639. * See the License for the specific language governing permissions and
  6640. * limitations under the License.
  6641. */
  6642. #ifndef MBEDTLS_CONSTANT_TIME_H
  6643. #define MBEDTLS_CONSTANT_TIME_H
  6644. #include <stddef.h>
  6645. /** Constant-time buffer comparison without branches.
  6646. *
  6647. * This is equivalent to the standard memcmp function, but is likely to be
  6648. * compiled to code using bitwise operation rather than a branch.
  6649. *
  6650. * This function can be used to write constant-time code by replacing branches
  6651. * with bit operations using masks.
  6652. *
  6653. * \param a Pointer to the first buffer.
  6654. * \param b Pointer to the second buffer.
  6655. * \param n The number of bytes to compare in the buffer.
  6656. *
  6657. * \return Zero if the content of the two buffer is the same,
  6658. * otherwise non-zero.
  6659. */
  6660. int mbedtls_ct_memcmp( const void *a,
  6661. const void *b,
  6662. size_t n );
  6663. #endif /* MBEDTLS_CONSTANT_TIME_H */
  6664. /********* Start of file library/constant_time_internal.h ************/
  6665. /**
  6666. * Constant-time functions
  6667. *
  6668. * Copyright The Mbed TLS Contributors
  6669. * SPDX-License-Identifier: Apache-2.0
  6670. *
  6671. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  6672. * not use this file except in compliance with the License.
  6673. * You may obtain a copy of the License at
  6674. *
  6675. * http://www.apache.org/licenses/LICENSE-2.0
  6676. *
  6677. * Unless required by applicable law or agreed to in writing, software
  6678. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  6679. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  6680. * See the License for the specific language governing permissions and
  6681. * limitations under the License.
  6682. */
  6683. #ifndef MBEDTLS_CONSTANT_TIME_INTERNAL_H
  6684. #define MBEDTLS_CONSTANT_TIME_INTERNAL_H
  6685. #if defined(MBEDTLS_BIGNUM_C)
  6686. #endif
  6687. #if defined(MBEDTLS_SSL_TLS_C)
  6688. #endif
  6689. #include <stddef.h>
  6690. /** Turn a value into a mask:
  6691. * - if \p value == 0, return the all-bits 0 mask, aka 0
  6692. * - otherwise, return the all-bits 1 mask, aka (unsigned) -1
  6693. *
  6694. * This function can be used to write constant-time code by replacing branches
  6695. * with bit operations using masks.
  6696. *
  6697. * \param value The value to analyze.
  6698. *
  6699. * \return Zero if \p value is zero, otherwise all-bits-one.
  6700. */
  6701. unsigned mbedtls_ct_uint_mask( unsigned value );
  6702. #if defined(MBEDTLS_SSL_SOME_SUITES_USE_TLS_CBC)
  6703. /** Turn a value into a mask:
  6704. * - if \p value == 0, return the all-bits 0 mask, aka 0
  6705. * - otherwise, return the all-bits 1 mask, aka (size_t) -1
  6706. *
  6707. * This function can be used to write constant-time code by replacing branches
  6708. * with bit operations using masks.
  6709. *
  6710. * \param value The value to analyze.
  6711. *
  6712. * \return Zero if \p value is zero, otherwise all-bits-one.
  6713. */
  6714. size_t mbedtls_ct_size_mask( size_t value );
  6715. #endif /* MBEDTLS_SSL_SOME_SUITES_USE_TLS_CBC */
  6716. #if defined(MBEDTLS_BIGNUM_C)
  6717. /** Turn a value into a mask:
  6718. * - if \p value == 0, return the all-bits 0 mask, aka 0
  6719. * - otherwise, return the all-bits 1 mask, aka (mbedtls_mpi_uint) -1
  6720. *
  6721. * This function can be used to write constant-time code by replacing branches
  6722. * with bit operations using masks.
  6723. *
  6724. * \param value The value to analyze.
  6725. *
  6726. * \return Zero if \p value is zero, otherwise all-bits-one.
  6727. */
  6728. mbedtls_mpi_uint mbedtls_ct_mpi_uint_mask( mbedtls_mpi_uint value );
  6729. #endif /* MBEDTLS_BIGNUM_C */
  6730. #if defined(MBEDTLS_SSL_SOME_SUITES_USE_TLS_CBC)
  6731. /** Constant-flow mask generation for "greater or equal" comparison:
  6732. * - if \p x >= \p y, return all-bits 1, that is (size_t) -1
  6733. * - otherwise, return all bits 0, that is 0
  6734. *
  6735. * This function can be used to write constant-time code by replacing branches
  6736. * with bit operations using masks.
  6737. *
  6738. * \param x The first value to analyze.
  6739. * \param y The second value to analyze.
  6740. *
  6741. * \return All-bits-one if \p x is greater or equal than \p y,
  6742. * otherwise zero.
  6743. */
  6744. size_t mbedtls_ct_size_mask_ge( size_t x,
  6745. size_t y );
  6746. #endif /* MBEDTLS_SSL_SOME_SUITES_USE_TLS_CBC */
  6747. /** Constant-flow boolean "equal" comparison:
  6748. * return x == y
  6749. *
  6750. * This is equivalent to \p x == \p y, but is likely to be compiled
  6751. * to code using bitwise operation rather than a branch.
  6752. *
  6753. * \param x The first value to analyze.
  6754. * \param y The second value to analyze.
  6755. *
  6756. * \return 1 if \p x equals to \p y, otherwise 0.
  6757. */
  6758. unsigned mbedtls_ct_size_bool_eq( size_t x,
  6759. size_t y );
  6760. #if defined(MBEDTLS_BIGNUM_C)
  6761. /** Decide if an integer is less than the other, without branches.
  6762. *
  6763. * This is equivalent to \p x < \p y, but is likely to be compiled
  6764. * to code using bitwise operation rather than a branch.
  6765. *
  6766. * \param x The first value to analyze.
  6767. * \param y The second value to analyze.
  6768. *
  6769. * \return 1 if \p x is less than \p y, otherwise 0.
  6770. */
  6771. unsigned mbedtls_ct_mpi_uint_lt( const mbedtls_mpi_uint x,
  6772. const mbedtls_mpi_uint y );
  6773. #endif /* MBEDTLS_BIGNUM_C */
  6774. /** Choose between two integer values without branches.
  6775. *
  6776. * This is equivalent to `condition ? if1 : if0`, but is likely to be compiled
  6777. * to code using bitwise operation rather than a branch.
  6778. *
  6779. * \param condition Condition to test.
  6780. * \param if1 Value to use if \p condition is nonzero.
  6781. * \param if0 Value to use if \p condition is zero.
  6782. *
  6783. * \return \c if1 if \p condition is nonzero, otherwise \c if0.
  6784. */
  6785. unsigned mbedtls_ct_uint_if( unsigned condition,
  6786. unsigned if1,
  6787. unsigned if0 );
  6788. #if defined(MBEDTLS_BIGNUM_C)
  6789. /** Conditionally assign a value without branches.
  6790. *
  6791. * This is equivalent to `if ( condition ) dest = src`, but is likely
  6792. * to be compiled to code using bitwise operation rather than a branch.
  6793. *
  6794. * \param n \p dest and \p src must be arrays of limbs of size n.
  6795. * \param dest The MPI to conditionally assign to. This must point
  6796. * to an initialized MPI.
  6797. * \param src The MPI to be assigned from. This must point to an
  6798. * initialized MPI.
  6799. * \param condition Condition to test, must be 0 or 1.
  6800. */
  6801. void mbedtls_ct_mpi_uint_cond_assign( size_t n,
  6802. mbedtls_mpi_uint *dest,
  6803. const mbedtls_mpi_uint *src,
  6804. unsigned char condition );
  6805. #endif /* MBEDTLS_BIGNUM_C */
  6806. #if defined(MBEDTLS_BASE64_C)
  6807. /** Given a value in the range 0..63, return the corresponding Base64 digit.
  6808. *
  6809. * The implementation assumes that letters are consecutive (e.g. ASCII
  6810. * but not EBCDIC).
  6811. *
  6812. * \param value A value in the range 0..63.
  6813. *
  6814. * \return A base64 digit converted from \p value.
  6815. */
  6816. unsigned char mbedtls_ct_base64_enc_char( unsigned char value );
  6817. /** Given a Base64 digit, return its value.
  6818. *
  6819. * If c is not a Base64 digit ('A'..'Z', 'a'..'z', '0'..'9', '+' or '/'),
  6820. * return -1.
  6821. *
  6822. * The implementation assumes that letters are consecutive (e.g. ASCII
  6823. * but not EBCDIC).
  6824. *
  6825. * \param c A base64 digit.
  6826. *
  6827. * \return The value of the base64 digit \p c.
  6828. */
  6829. signed char mbedtls_ct_base64_dec_value( unsigned char c );
  6830. #endif /* MBEDTLS_BASE64_C */
  6831. #if defined(MBEDTLS_SSL_SOME_SUITES_USE_TLS_CBC)
  6832. /** Conditional memcpy without branches.
  6833. *
  6834. * This is equivalent to `if ( c1 == c2 ) memcpy(dest, src, len)`, but is likely
  6835. * to be compiled to code using bitwise operation rather than a branch.
  6836. *
  6837. * \param dest The pointer to conditionally copy to.
  6838. * \param src The pointer to copy from. Shouldn't overlap with \p dest.
  6839. * \param len The number of bytes to copy.
  6840. * \param c1 The first value to analyze in the condition.
  6841. * \param c2 The second value to analyze in the condition.
  6842. */
  6843. void mbedtls_ct_memcpy_if_eq( unsigned char *dest,
  6844. const unsigned char *src,
  6845. size_t len,
  6846. size_t c1, size_t c2 );
  6847. /** Copy data from a secret position with constant flow.
  6848. *
  6849. * This function copies \p len bytes from \p src_base + \p offset_secret to \p
  6850. * dst, with a code flow and memory access pattern that does not depend on \p
  6851. * offset_secret, but only on \p offset_min, \p offset_max and \p len.
  6852. * Functionally equivalent to `memcpy(dst, src + offset_secret, len)`.
  6853. *
  6854. * \param dest The destination buffer. This must point to a writable
  6855. * buffer of at least \p len bytes.
  6856. * \param src The base of the source buffer. This must point to a
  6857. * readable buffer of at least \p offset_max + \p len
  6858. * bytes. Shouldn't overlap with \p dest.
  6859. * \param offset The offset in the source buffer from which to copy.
  6860. * This must be no less than \p offset_min and no greater
  6861. * than \p offset_max.
  6862. * \param offset_min The minimal value of \p offset.
  6863. * \param offset_max The maximal value of \p offset.
  6864. * \param len The number of bytes to copy.
  6865. */
  6866. void mbedtls_ct_memcpy_offset( unsigned char *dest,
  6867. const unsigned char *src,
  6868. size_t offset,
  6869. size_t offset_min,
  6870. size_t offset_max,
  6871. size_t len );
  6872. /** Compute the HMAC of variable-length data with constant flow.
  6873. *
  6874. * This function computes the HMAC of the concatenation of \p add_data and \p
  6875. * data, and does with a code flow and memory access pattern that does not
  6876. * depend on \p data_len_secret, but only on \p min_data_len and \p
  6877. * max_data_len. In particular, this function always reads exactly \p
  6878. * max_data_len bytes from \p data.
  6879. *
  6880. * \param ctx The HMAC context. It must have keys configured
  6881. * with mbedtls_md_hmac_starts() and use one of the
  6882. * following hashes: SHA-384, SHA-256, SHA-1 or MD-5.
  6883. * It is reset using mbedtls_md_hmac_reset() after
  6884. * the computation is complete to prepare for the
  6885. * next computation.
  6886. * \param add_data The first part of the message whose HMAC is being
  6887. * calculated. This must point to a readable buffer
  6888. * of \p add_data_len bytes.
  6889. * \param add_data_len The length of \p add_data in bytes.
  6890. * \param data The buffer containing the second part of the
  6891. * message. This must point to a readable buffer
  6892. * of \p max_data_len bytes.
  6893. * \param data_len_secret The length of the data to process in \p data.
  6894. * This must be no less than \p min_data_len and no
  6895. * greater than \p max_data_len.
  6896. * \param min_data_len The minimal length of the second part of the
  6897. * message, read from \p data.
  6898. * \param max_data_len The maximal length of the second part of the
  6899. * message, read from \p data.
  6900. * \param output The HMAC will be written here. This must point to
  6901. * a writable buffer of sufficient size to hold the
  6902. * HMAC value.
  6903. *
  6904. * \retval 0 on success.
  6905. * \retval #MBEDTLS_ERR_PLATFORM_HW_ACCEL_FAILED
  6906. * The hardware accelerator failed.
  6907. */
  6908. int mbedtls_ct_hmac( mbedtls_md_context_t *ctx,
  6909. const unsigned char *add_data,
  6910. size_t add_data_len,
  6911. const unsigned char *data,
  6912. size_t data_len_secret,
  6913. size_t min_data_len,
  6914. size_t max_data_len,
  6915. unsigned char *output );
  6916. #endif /* MBEDTLS_SSL_SOME_SUITES_USE_TLS_CBC */
  6917. #if defined(MBEDTLS_PKCS1_V15) && defined(MBEDTLS_RSA_C) && !defined(MBEDTLS_RSA_ALT)
  6918. /** This function performs the unpadding part of a PKCS#1 v1.5 decryption
  6919. * operation (EME-PKCS1-v1_5 decoding).
  6920. *
  6921. * \note The return value from this function is a sensitive value
  6922. * (this is unusual). #MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE shouldn't happen
  6923. * in a well-written application, but 0 vs #MBEDTLS_ERR_RSA_INVALID_PADDING
  6924. * is often a situation that an attacker can provoke and leaking which
  6925. * one is the result is precisely the information the attacker wants.
  6926. *
  6927. * \param mode The mode of operation. This must be either
  6928. * #MBEDTLS_RSA_PRIVATE or #MBEDTLS_RSA_PUBLIC (deprecated).
  6929. * \param input The input buffer which is the payload inside PKCS#1v1.5
  6930. * encryption padding, called the "encoded message EM"
  6931. * by the terminology.
  6932. * \param ilen The length of the payload in the \p input buffer.
  6933. * \param output The buffer for the payload, called "message M" by the
  6934. * PKCS#1 terminology. This must be a writable buffer of
  6935. * length \p output_max_len bytes.
  6936. * \param olen The address at which to store the length of
  6937. * the payload. This must not be \c NULL.
  6938. * \param output_max_len The length in bytes of the output buffer \p output.
  6939. *
  6940. * \return \c 0 on success.
  6941. * \return #MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE
  6942. * The output buffer is too small for the unpadded payload.
  6943. * \return #MBEDTLS_ERR_RSA_INVALID_PADDING
  6944. * The input doesn't contain properly formatted padding.
  6945. */
  6946. int mbedtls_ct_rsaes_pkcs1_v15_unpadding( int mode,
  6947. unsigned char *input,
  6948. size_t ilen,
  6949. unsigned char *output,
  6950. size_t output_max_len,
  6951. size_t *olen );
  6952. #endif /* MBEDTLS_PKCS1_V15 && MBEDTLS_RSA_C && ! MBEDTLS_RSA_ALT */
  6953. #endif /* MBEDTLS_CONSTANT_TIME_INTERNAL_H */
  6954. /********* Start of file include/mbedtls/net.h ************/
  6955. /**
  6956. * \file net.h
  6957. *
  6958. * \brief Deprecated header file that includes net_sockets.h
  6959. *
  6960. * \deprecated Superseded by mbedtls/net_sockets.h
  6961. */
  6962. /*
  6963. * Copyright The Mbed TLS Contributors
  6964. * SPDX-License-Identifier: Apache-2.0
  6965. *
  6966. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  6967. * not use this file except in compliance with the License.
  6968. * You may obtain a copy of the License at
  6969. *
  6970. * http://www.apache.org/licenses/LICENSE-2.0
  6971. *
  6972. * Unless required by applicable law or agreed to in writing, software
  6973. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  6974. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  6975. * See the License for the specific language governing permissions and
  6976. * limitations under the License.
  6977. */
  6978. #if !defined(MBEDTLS_CONFIG_FILE)
  6979. #else
  6980. #endif
  6981. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  6982. #if defined(MBEDTLS_DEPRECATED_WARNING)
  6983. #warning "Deprecated header file: Superseded by mbedtls/net_sockets.h"
  6984. #endif /* MBEDTLS_DEPRECATED_WARNING */
  6985. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  6986. /********* Start of file include/mbedtls/net_sockets.h ************/
  6987. /**
  6988. * \file net_sockets.h
  6989. *
  6990. * \brief Network sockets abstraction layer to integrate Mbed TLS into a
  6991. * BSD-style sockets API.
  6992. *
  6993. * The network sockets module provides an example integration of the
  6994. * Mbed TLS library into a BSD sockets implementation. The module is
  6995. * intended to be an example of how Mbed TLS can be integrated into a
  6996. * networking stack, as well as to be Mbed TLS's network integration
  6997. * for its supported platforms.
  6998. *
  6999. * The module is intended only to be used with the Mbed TLS library and
  7000. * is not intended to be used by third party application software
  7001. * directly.
  7002. *
  7003. * The supported platforms are as follows:
  7004. * * Microsoft Windows and Windows CE
  7005. * * POSIX/Unix platforms including Linux, OS X
  7006. *
  7007. */
  7008. /*
  7009. * Copyright The Mbed TLS Contributors
  7010. * SPDX-License-Identifier: Apache-2.0
  7011. *
  7012. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  7013. * not use this file except in compliance with the License.
  7014. * You may obtain a copy of the License at
  7015. *
  7016. * http://www.apache.org/licenses/LICENSE-2.0
  7017. *
  7018. * Unless required by applicable law or agreed to in writing, software
  7019. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  7020. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  7021. * See the License for the specific language governing permissions and
  7022. * limitations under the License.
  7023. */
  7024. #ifndef MBEDTLS_NET_SOCKETS_H
  7025. #define MBEDTLS_NET_SOCKETS_H
  7026. #if !defined(MBEDTLS_CONFIG_FILE)
  7027. #else
  7028. #endif
  7029. #include <stddef.h>
  7030. #include <stdint.h>
  7031. /** Failed to open a socket. */
  7032. #define MBEDTLS_ERR_NET_SOCKET_FAILED -0x0042
  7033. /** The connection to the given server / port failed. */
  7034. #define MBEDTLS_ERR_NET_CONNECT_FAILED -0x0044
  7035. /** Binding of the socket failed. */
  7036. #define MBEDTLS_ERR_NET_BIND_FAILED -0x0046
  7037. /** Could not listen on the socket. */
  7038. #define MBEDTLS_ERR_NET_LISTEN_FAILED -0x0048
  7039. /** Could not accept the incoming connection. */
  7040. #define MBEDTLS_ERR_NET_ACCEPT_FAILED -0x004A
  7041. /** Reading information from the socket failed. */
  7042. #define MBEDTLS_ERR_NET_RECV_FAILED -0x004C
  7043. /** Sending information through the socket failed. */
  7044. #define MBEDTLS_ERR_NET_SEND_FAILED -0x004E
  7045. /** Connection was reset by peer. */
  7046. #define MBEDTLS_ERR_NET_CONN_RESET -0x0050
  7047. /** Failed to get an IP address for the given hostname. */
  7048. #define MBEDTLS_ERR_NET_UNKNOWN_HOST -0x0052
  7049. /** Buffer is too small to hold the data. */
  7050. #define MBEDTLS_ERR_NET_BUFFER_TOO_SMALL -0x0043
  7051. /** The context is invalid, eg because it was free()ed. */
  7052. #define MBEDTLS_ERR_NET_INVALID_CONTEXT -0x0045
  7053. /** Polling the net context failed. */
  7054. #define MBEDTLS_ERR_NET_POLL_FAILED -0x0047
  7055. /** Input invalid. */
  7056. #define MBEDTLS_ERR_NET_BAD_INPUT_DATA -0x0049
  7057. #define MBEDTLS_NET_LISTEN_BACKLOG 10 /**< The backlog that listen() should use. */
  7058. #define MBEDTLS_NET_PROTO_TCP 0 /**< The TCP transport protocol */
  7059. #define MBEDTLS_NET_PROTO_UDP 1 /**< The UDP transport protocol */
  7060. #define MBEDTLS_NET_POLL_READ 1 /**< Used in \c mbedtls_net_poll to check for pending data */
  7061. #define MBEDTLS_NET_POLL_WRITE 2 /**< Used in \c mbedtls_net_poll to check if write possible */
  7062. #ifdef __cplusplus
  7063. extern "C" {
  7064. #endif
  7065. /**
  7066. * Wrapper type for sockets.
  7067. *
  7068. * Currently backed by just a file descriptor, but might be more in the future
  7069. * (eg two file descriptors for combined IPv4 + IPv6 support, or additional
  7070. * structures for hand-made UDP demultiplexing).
  7071. */
  7072. typedef struct mbedtls_net_context
  7073. {
  7074. int fd; /**< The underlying file descriptor */
  7075. }
  7076. mbedtls_net_context;
  7077. /**
  7078. * \brief Initialize a context
  7079. * Just makes the context ready to be used or freed safely.
  7080. *
  7081. * \param ctx Context to initialize
  7082. */
  7083. void mbedtls_net_init( mbedtls_net_context *ctx );
  7084. /**
  7085. * \brief Initiate a connection with host:port in the given protocol
  7086. *
  7087. * \param ctx Socket to use
  7088. * \param host Host to connect to
  7089. * \param port Port to connect to
  7090. * \param proto Protocol: MBEDTLS_NET_PROTO_TCP or MBEDTLS_NET_PROTO_UDP
  7091. *
  7092. * \return 0 if successful, or one of:
  7093. * MBEDTLS_ERR_NET_SOCKET_FAILED,
  7094. * MBEDTLS_ERR_NET_UNKNOWN_HOST,
  7095. * MBEDTLS_ERR_NET_CONNECT_FAILED
  7096. *
  7097. * \note Sets the socket in connected mode even with UDP.
  7098. */
  7099. int mbedtls_net_connect( mbedtls_net_context *ctx, const char *host, const char *port, int proto );
  7100. /**
  7101. * \brief Create a receiving socket on bind_ip:port in the chosen
  7102. * protocol. If bind_ip == NULL, all interfaces are bound.
  7103. *
  7104. * \param ctx Socket to use
  7105. * \param bind_ip IP to bind to, can be NULL
  7106. * \param port Port number to use
  7107. * \param proto Protocol: MBEDTLS_NET_PROTO_TCP or MBEDTLS_NET_PROTO_UDP
  7108. *
  7109. * \return 0 if successful, or one of:
  7110. * MBEDTLS_ERR_NET_SOCKET_FAILED,
  7111. * MBEDTLS_ERR_NET_UNKNOWN_HOST,
  7112. * MBEDTLS_ERR_NET_BIND_FAILED,
  7113. * MBEDTLS_ERR_NET_LISTEN_FAILED
  7114. *
  7115. * \note Regardless of the protocol, opens the sockets and binds it.
  7116. * In addition, make the socket listening if protocol is TCP.
  7117. */
  7118. int mbedtls_net_bind( mbedtls_net_context *ctx, const char *bind_ip, const char *port, int proto );
  7119. /**
  7120. * \brief Accept a connection from a remote client
  7121. *
  7122. * \param bind_ctx Relevant socket
  7123. * \param client_ctx Will contain the connected client socket
  7124. * \param client_ip Will contain the client IP address, can be NULL
  7125. * \param buf_size Size of the client_ip buffer
  7126. * \param ip_len Will receive the size of the client IP written,
  7127. * can be NULL if client_ip is null
  7128. *
  7129. * \return 0 if successful, or
  7130. * MBEDTLS_ERR_NET_SOCKET_FAILED,
  7131. * MBEDTLS_ERR_NET_BIND_FAILED,
  7132. * MBEDTLS_ERR_NET_ACCEPT_FAILED, or
  7133. * MBEDTLS_ERR_NET_BUFFER_TOO_SMALL if buf_size is too small,
  7134. * MBEDTLS_ERR_SSL_WANT_READ if bind_fd was set to
  7135. * non-blocking and accept() would block.
  7136. */
  7137. int mbedtls_net_accept( mbedtls_net_context *bind_ctx,
  7138. mbedtls_net_context *client_ctx,
  7139. void *client_ip, size_t buf_size, size_t *ip_len );
  7140. /**
  7141. * \brief Check and wait for the context to be ready for read/write
  7142. *
  7143. * \note The current implementation of this function uses
  7144. * select() and returns an error if the file descriptor
  7145. * is \c FD_SETSIZE or greater.
  7146. *
  7147. * \param ctx Socket to check
  7148. * \param rw Bitflag composed of MBEDTLS_NET_POLL_READ and
  7149. * MBEDTLS_NET_POLL_WRITE specifying the events
  7150. * to wait for:
  7151. * - If MBEDTLS_NET_POLL_READ is set, the function
  7152. * will return as soon as the net context is available
  7153. * for reading.
  7154. * - If MBEDTLS_NET_POLL_WRITE is set, the function
  7155. * will return as soon as the net context is available
  7156. * for writing.
  7157. * \param timeout Maximal amount of time to wait before returning,
  7158. * in milliseconds. If \c timeout is zero, the
  7159. * function returns immediately. If \c timeout is
  7160. * -1u, the function blocks potentially indefinitely.
  7161. *
  7162. * \return Bitmask composed of MBEDTLS_NET_POLL_READ/WRITE
  7163. * on success or timeout, or a negative return code otherwise.
  7164. */
  7165. int mbedtls_net_poll( mbedtls_net_context *ctx, uint32_t rw, uint32_t timeout );
  7166. /**
  7167. * \brief Set the socket blocking
  7168. *
  7169. * \param ctx Socket to set
  7170. *
  7171. * \return 0 if successful, or a non-zero error code
  7172. */
  7173. int mbedtls_net_set_block( mbedtls_net_context *ctx );
  7174. /**
  7175. * \brief Set the socket non-blocking
  7176. *
  7177. * \param ctx Socket to set
  7178. *
  7179. * \return 0 if successful, or a non-zero error code
  7180. */
  7181. int mbedtls_net_set_nonblock( mbedtls_net_context *ctx );
  7182. /**
  7183. * \brief Portable usleep helper
  7184. *
  7185. * \param usec Amount of microseconds to sleep
  7186. *
  7187. * \note Real amount of time slept will not be less than
  7188. * select()'s timeout granularity (typically, 10ms).
  7189. */
  7190. void mbedtls_net_usleep( unsigned long usec );
  7191. /**
  7192. * \brief Read at most 'len' characters. If no error occurs,
  7193. * the actual amount read is returned.
  7194. *
  7195. * \param ctx Socket
  7196. * \param buf The buffer to write to
  7197. * \param len Maximum length of the buffer
  7198. *
  7199. * \return the number of bytes received,
  7200. * or a non-zero error code; with a non-blocking socket,
  7201. * MBEDTLS_ERR_SSL_WANT_READ indicates read() would block.
  7202. */
  7203. int mbedtls_net_recv( void *ctx, unsigned char *buf, size_t len );
  7204. /**
  7205. * \brief Write at most 'len' characters. If no error occurs,
  7206. * the actual amount read is returned.
  7207. *
  7208. * \param ctx Socket
  7209. * \param buf The buffer to read from
  7210. * \param len The length of the buffer
  7211. *
  7212. * \return the number of bytes sent,
  7213. * or a non-zero error code; with a non-blocking socket,
  7214. * MBEDTLS_ERR_SSL_WANT_WRITE indicates write() would block.
  7215. */
  7216. int mbedtls_net_send( void *ctx, const unsigned char *buf, size_t len );
  7217. /**
  7218. * \brief Read at most 'len' characters, blocking for at most
  7219. * 'timeout' seconds. If no error occurs, the actual amount
  7220. * read is returned.
  7221. *
  7222. * \note The current implementation of this function uses
  7223. * select() and returns an error if the file descriptor
  7224. * is \c FD_SETSIZE or greater.
  7225. *
  7226. * \param ctx Socket
  7227. * \param buf The buffer to write to
  7228. * \param len Maximum length of the buffer
  7229. * \param timeout Maximum number of milliseconds to wait for data
  7230. * 0 means no timeout (wait forever)
  7231. *
  7232. * \return The number of bytes received if successful.
  7233. * MBEDTLS_ERR_SSL_TIMEOUT if the operation timed out.
  7234. * MBEDTLS_ERR_SSL_WANT_READ if interrupted by a signal.
  7235. * Another negative error code (MBEDTLS_ERR_NET_xxx)
  7236. * for other failures.
  7237. *
  7238. * \note This function will block (until data becomes available or
  7239. * timeout is reached) even if the socket is set to
  7240. * non-blocking. Handling timeouts with non-blocking reads
  7241. * requires a different strategy.
  7242. */
  7243. int mbedtls_net_recv_timeout( void *ctx, unsigned char *buf, size_t len,
  7244. uint32_t timeout );
  7245. /**
  7246. * \brief Closes down the connection and free associated data
  7247. *
  7248. * \param ctx The context to close
  7249. */
  7250. void mbedtls_net_close( mbedtls_net_context *ctx );
  7251. /**
  7252. * \brief Gracefully shutdown the connection and free associated data
  7253. *
  7254. * \param ctx The context to free
  7255. */
  7256. void mbedtls_net_free( mbedtls_net_context *ctx );
  7257. #ifdef __cplusplus
  7258. }
  7259. #endif
  7260. #endif /* net_sockets.h */
  7261. /********* Start of file include/mbedtls/dhm.h ************/
  7262. /**
  7263. * \file dhm.h
  7264. *
  7265. * \brief This file contains Diffie-Hellman-Merkle (DHM) key exchange
  7266. * definitions and functions.
  7267. *
  7268. * Diffie-Hellman-Merkle (DHM) key exchange is defined in
  7269. * <em>RFC-2631: Diffie-Hellman Key Agreement Method</em> and
  7270. * <em>Public-Key Cryptography Standards (PKCS) #3: Diffie
  7271. * Hellman Key Agreement Standard</em>.
  7272. *
  7273. * <em>RFC-3526: More Modular Exponential (MODP) Diffie-Hellman groups for
  7274. * Internet Key Exchange (IKE)</em> defines a number of standardized
  7275. * Diffie-Hellman groups for IKE.
  7276. *
  7277. * <em>RFC-5114: Additional Diffie-Hellman Groups for Use with IETF
  7278. * Standards</em> defines a number of standardized Diffie-Hellman
  7279. * groups that can be used.
  7280. *
  7281. * \warning The security of the DHM key exchange relies on the proper choice
  7282. * of prime modulus - optimally, it should be a safe prime. The usage
  7283. * of non-safe primes both decreases the difficulty of the underlying
  7284. * discrete logarithm problem and can lead to small subgroup attacks
  7285. * leaking private exponent bits when invalid public keys are used
  7286. * and not detected. This is especially relevant if the same DHM
  7287. * parameters are reused for multiple key exchanges as in static DHM,
  7288. * while the criticality of small-subgroup attacks is lower for
  7289. * ephemeral DHM.
  7290. *
  7291. * \warning For performance reasons, the code does neither perform primality
  7292. * nor safe primality tests, nor the expensive checks for invalid
  7293. * subgroups. Moreover, even if these were performed, non-standardized
  7294. * primes cannot be trusted because of the possibility of backdoors
  7295. * that can't be effectively checked for.
  7296. *
  7297. * \warning Diffie-Hellman-Merkle is therefore a security risk when not using
  7298. * standardized primes generated using a trustworthy ("nothing up
  7299. * my sleeve") method, such as the RFC 3526 / 7919 primes. In the TLS
  7300. * protocol, DH parameters need to be negotiated, so using the default
  7301. * primes systematically is not always an option. If possible, use
  7302. * Elliptic Curve Diffie-Hellman (ECDH), which has better performance,
  7303. * and for which the TLS protocol mandates the use of standard
  7304. * parameters.
  7305. *
  7306. */
  7307. /*
  7308. * Copyright The Mbed TLS Contributors
  7309. * SPDX-License-Identifier: Apache-2.0
  7310. *
  7311. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  7312. * not use this file except in compliance with the License.
  7313. * You may obtain a copy of the License at
  7314. *
  7315. * http://www.apache.org/licenses/LICENSE-2.0
  7316. *
  7317. * Unless required by applicable law or agreed to in writing, software
  7318. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  7319. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  7320. * See the License for the specific language governing permissions and
  7321. * limitations under the License.
  7322. */
  7323. #ifndef MBEDTLS_DHM_H
  7324. #define MBEDTLS_DHM_H
  7325. #if !defined(MBEDTLS_CONFIG_FILE)
  7326. #else
  7327. #endif
  7328. /*
  7329. * DHM Error codes
  7330. */
  7331. /** Bad input parameters. */
  7332. #define MBEDTLS_ERR_DHM_BAD_INPUT_DATA -0x3080
  7333. /** Reading of the DHM parameters failed. */
  7334. #define MBEDTLS_ERR_DHM_READ_PARAMS_FAILED -0x3100
  7335. /** Making of the DHM parameters failed. */
  7336. #define MBEDTLS_ERR_DHM_MAKE_PARAMS_FAILED -0x3180
  7337. /** Reading of the public values failed. */
  7338. #define MBEDTLS_ERR_DHM_READ_PUBLIC_FAILED -0x3200
  7339. /** Making of the public value failed. */
  7340. #define MBEDTLS_ERR_DHM_MAKE_PUBLIC_FAILED -0x3280
  7341. /** Calculation of the DHM secret failed. */
  7342. #define MBEDTLS_ERR_DHM_CALC_SECRET_FAILED -0x3300
  7343. /** The ASN.1 data is not formatted correctly. */
  7344. #define MBEDTLS_ERR_DHM_INVALID_FORMAT -0x3380
  7345. /** Allocation of memory failed. */
  7346. #define MBEDTLS_ERR_DHM_ALLOC_FAILED -0x3400
  7347. /** Read or write of file failed. */
  7348. #define MBEDTLS_ERR_DHM_FILE_IO_ERROR -0x3480
  7349. /* MBEDTLS_ERR_DHM_HW_ACCEL_FAILED is deprecated and should not be used. */
  7350. /** DHM hardware accelerator failed. */
  7351. #define MBEDTLS_ERR_DHM_HW_ACCEL_FAILED -0x3500
  7352. /** Setting the modulus and generator failed. */
  7353. #define MBEDTLS_ERR_DHM_SET_GROUP_FAILED -0x3580
  7354. #ifdef __cplusplus
  7355. extern "C" {
  7356. #endif
  7357. #if !defined(MBEDTLS_DHM_ALT)
  7358. /**
  7359. * \brief The DHM context structure.
  7360. */
  7361. typedef struct mbedtls_dhm_context
  7362. {
  7363. size_t len; /*!< The size of \p P in Bytes. */
  7364. mbedtls_mpi P; /*!< The prime modulus. */
  7365. mbedtls_mpi G; /*!< The generator. */
  7366. mbedtls_mpi X; /*!< Our secret value. */
  7367. mbedtls_mpi GX; /*!< Our public key = \c G^X mod \c P. */
  7368. mbedtls_mpi GY; /*!< The public key of the peer = \c G^Y mod \c P. */
  7369. mbedtls_mpi K; /*!< The shared secret = \c G^(XY) mod \c P. */
  7370. mbedtls_mpi RP; /*!< The cached value = \c R^2 mod \c P. */
  7371. mbedtls_mpi Vi; /*!< The blinding value. */
  7372. mbedtls_mpi Vf; /*!< The unblinding value. */
  7373. mbedtls_mpi pX; /*!< The previous \c X. */
  7374. }
  7375. mbedtls_dhm_context;
  7376. #else /* MBEDTLS_DHM_ALT */
  7377. #endif /* MBEDTLS_DHM_ALT */
  7378. /**
  7379. * \brief This function initializes the DHM context.
  7380. *
  7381. * \param ctx The DHM context to initialize.
  7382. */
  7383. void mbedtls_dhm_init( mbedtls_dhm_context *ctx );
  7384. /**
  7385. * \brief This function parses the DHM parameters in a
  7386. * TLS ServerKeyExchange handshake message
  7387. * (DHM modulus, generator, and public key).
  7388. *
  7389. * \note In a TLS handshake, this is the how the client
  7390. * sets up its DHM context from the server's public
  7391. * DHM key material.
  7392. *
  7393. * \param ctx The DHM context to use. This must be initialized.
  7394. * \param p On input, *p must be the start of the input buffer.
  7395. * On output, *p is updated to point to the end of the data
  7396. * that has been read. On success, this is the first byte
  7397. * past the end of the ServerKeyExchange parameters.
  7398. * On error, this is the point at which an error has been
  7399. * detected, which is usually not useful except to debug
  7400. * failures.
  7401. * \param end The end of the input buffer.
  7402. *
  7403. * \return \c 0 on success.
  7404. * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
  7405. */
  7406. int mbedtls_dhm_read_params( mbedtls_dhm_context *ctx,
  7407. unsigned char **p,
  7408. const unsigned char *end );
  7409. /**
  7410. * \brief This function generates a DHM key pair and exports its
  7411. * public part together with the DHM parameters in the format
  7412. * used in a TLS ServerKeyExchange handshake message.
  7413. *
  7414. * \note This function assumes that the DHM parameters \c ctx->P
  7415. * and \c ctx->G have already been properly set. For that, use
  7416. * mbedtls_dhm_set_group() below in conjunction with
  7417. * mbedtls_mpi_read_binary() and mbedtls_mpi_read_string().
  7418. *
  7419. * \note In a TLS handshake, this is the how the server generates
  7420. * and exports its DHM key material.
  7421. *
  7422. * \param ctx The DHM context to use. This must be initialized
  7423. * and have the DHM parameters set. It may or may not
  7424. * already have imported the peer's public key.
  7425. * \param x_size The private key size in Bytes.
  7426. * \param olen The address at which to store the number of Bytes
  7427. * written on success. This must not be \c NULL.
  7428. * \param output The destination buffer. This must be a writable buffer of
  7429. * sufficient size to hold the reduced binary presentation of
  7430. * the modulus, the generator and the public key, each wrapped
  7431. * with a 2-byte length field. It is the responsibility of the
  7432. * caller to ensure that enough space is available. Refer to
  7433. * mbedtls_mpi_size() to computing the byte-size of an MPI.
  7434. * \param f_rng The RNG function. Must not be \c NULL.
  7435. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  7436. * \c NULL if \p f_rng doesn't need a context parameter.
  7437. *
  7438. * \return \c 0 on success.
  7439. * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
  7440. */
  7441. int mbedtls_dhm_make_params( mbedtls_dhm_context *ctx, int x_size,
  7442. unsigned char *output, size_t *olen,
  7443. int (*f_rng)(void *, unsigned char *, size_t),
  7444. void *p_rng );
  7445. /**
  7446. * \brief This function sets the prime modulus and generator.
  7447. *
  7448. * \note This function can be used to set \c ctx->P, \c ctx->G
  7449. * in preparation for mbedtls_dhm_make_params().
  7450. *
  7451. * \param ctx The DHM context to configure. This must be initialized.
  7452. * \param P The MPI holding the DHM prime modulus. This must be
  7453. * an initialized MPI.
  7454. * \param G The MPI holding the DHM generator. This must be an
  7455. * initialized MPI.
  7456. *
  7457. * \return \c 0 if successful.
  7458. * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
  7459. */
  7460. int mbedtls_dhm_set_group( mbedtls_dhm_context *ctx,
  7461. const mbedtls_mpi *P,
  7462. const mbedtls_mpi *G );
  7463. /**
  7464. * \brief This function imports the raw public value of the peer.
  7465. *
  7466. * \note In a TLS handshake, this is the how the server imports
  7467. * the Client's public DHM key.
  7468. *
  7469. * \param ctx The DHM context to use. This must be initialized and have
  7470. * its DHM parameters set, e.g. via mbedtls_dhm_set_group().
  7471. * It may or may not already have generated its own private key.
  7472. * \param input The input buffer containing the \c G^Y value of the peer.
  7473. * This must be a readable buffer of size \p ilen Bytes.
  7474. * \param ilen The size of the input buffer \p input in Bytes.
  7475. *
  7476. * \return \c 0 on success.
  7477. * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
  7478. */
  7479. int mbedtls_dhm_read_public( mbedtls_dhm_context *ctx,
  7480. const unsigned char *input, size_t ilen );
  7481. /**
  7482. * \brief This function creates a DHM key pair and exports
  7483. * the raw public key in big-endian format.
  7484. *
  7485. * \note The destination buffer is always fully written
  7486. * so as to contain a big-endian representation of G^X mod P.
  7487. * If it is larger than \c ctx->len, it is padded accordingly
  7488. * with zero-bytes at the beginning.
  7489. *
  7490. * \param ctx The DHM context to use. This must be initialized and
  7491. * have the DHM parameters set. It may or may not already
  7492. * have imported the peer's public key.
  7493. * \param x_size The private key size in Bytes.
  7494. * \param output The destination buffer. This must be a writable buffer of
  7495. * size \p olen Bytes.
  7496. * \param olen The length of the destination buffer. This must be at least
  7497. * equal to `ctx->len` (the size of \c P).
  7498. * \param f_rng The RNG function. This must not be \c NULL.
  7499. * \param p_rng The RNG context to be passed to \p f_rng. This may be \c NULL
  7500. * if \p f_rng doesn't need a context argument.
  7501. *
  7502. * \return \c 0 on success.
  7503. * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
  7504. */
  7505. int mbedtls_dhm_make_public( mbedtls_dhm_context *ctx, int x_size,
  7506. unsigned char *output, size_t olen,
  7507. int (*f_rng)(void *, unsigned char *, size_t),
  7508. void *p_rng );
  7509. /**
  7510. * \brief This function derives and exports the shared secret
  7511. * \c (G^Y)^X mod \c P.
  7512. *
  7513. * \note If \p f_rng is not \c NULL, it is used to blind the input as
  7514. * a countermeasure against timing attacks. Blinding is used
  7515. * only if our private key \c X is re-used, and not used
  7516. * otherwise. We recommend always passing a non-NULL
  7517. * \p f_rng argument.
  7518. *
  7519. * \param ctx The DHM context to use. This must be initialized
  7520. * and have its own private key generated and the peer's
  7521. * public key imported.
  7522. * \param output The buffer to write the generated shared key to. This
  7523. * must be a writable buffer of size \p output_size Bytes.
  7524. * \param output_size The size of the destination buffer. This must be at
  7525. * least the size of \c ctx->len (the size of \c P).
  7526. * \param olen On exit, holds the actual number of Bytes written.
  7527. * \param f_rng The RNG function, for blinding purposes. This may
  7528. * b \c NULL if blinding isn't needed.
  7529. * \param p_rng The RNG context. This may be \c NULL if \p f_rng
  7530. * doesn't need a context argument.
  7531. *
  7532. * \return \c 0 on success.
  7533. * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
  7534. */
  7535. int mbedtls_dhm_calc_secret( mbedtls_dhm_context *ctx,
  7536. unsigned char *output, size_t output_size, size_t *olen,
  7537. int (*f_rng)(void *, unsigned char *, size_t),
  7538. void *p_rng );
  7539. /**
  7540. * \brief This function frees and clears the components
  7541. * of a DHM context.
  7542. *
  7543. * \param ctx The DHM context to free and clear. This may be \c NULL,
  7544. * in which case this function is a no-op. If it is not \c NULL,
  7545. * it must point to an initialized DHM context.
  7546. */
  7547. void mbedtls_dhm_free( mbedtls_dhm_context *ctx );
  7548. #if defined(MBEDTLS_ASN1_PARSE_C)
  7549. /**
  7550. * \brief This function parses DHM parameters in PEM or DER format.
  7551. *
  7552. * \param dhm The DHM context to import the DHM parameters into.
  7553. * This must be initialized.
  7554. * \param dhmin The input buffer. This must be a readable buffer of
  7555. * length \p dhminlen Bytes.
  7556. * \param dhminlen The size of the input buffer \p dhmin, including the
  7557. * terminating \c NULL Byte for PEM data.
  7558. *
  7559. * \return \c 0 on success.
  7560. * \return An \c MBEDTLS_ERR_DHM_XXX or \c MBEDTLS_ERR_PEM_XXX error
  7561. * code on failure.
  7562. */
  7563. int mbedtls_dhm_parse_dhm( mbedtls_dhm_context *dhm, const unsigned char *dhmin,
  7564. size_t dhminlen );
  7565. #if defined(MBEDTLS_FS_IO)
  7566. /**
  7567. * \brief This function loads and parses DHM parameters from a file.
  7568. *
  7569. * \param dhm The DHM context to load the parameters to.
  7570. * This must be initialized.
  7571. * \param path The filename to read the DHM parameters from.
  7572. * This must not be \c NULL.
  7573. *
  7574. * \return \c 0 on success.
  7575. * \return An \c MBEDTLS_ERR_DHM_XXX or \c MBEDTLS_ERR_PEM_XXX
  7576. * error code on failure.
  7577. */
  7578. int mbedtls_dhm_parse_dhmfile( mbedtls_dhm_context *dhm, const char *path );
  7579. #endif /* MBEDTLS_FS_IO */
  7580. #endif /* MBEDTLS_ASN1_PARSE_C */
  7581. #if defined(MBEDTLS_SELF_TEST)
  7582. /**
  7583. * \brief The DMH checkup routine.
  7584. *
  7585. * \return \c 0 on success.
  7586. * \return \c 1 on failure.
  7587. */
  7588. int mbedtls_dhm_self_test( int verbose );
  7589. #endif /* MBEDTLS_SELF_TEST */
  7590. #ifdef __cplusplus
  7591. }
  7592. #endif
  7593. /**
  7594. * RFC 3526, RFC 5114 and RFC 7919 standardize a number of
  7595. * Diffie-Hellman groups, some of which are included here
  7596. * for use within the SSL/TLS module and the user's convenience
  7597. * when configuring the Diffie-Hellman parameters by hand
  7598. * through \c mbedtls_ssl_conf_dh_param.
  7599. *
  7600. * The following lists the source of the above groups in the standards:
  7601. * - RFC 5114 section 2.2: 2048-bit MODP Group with 224-bit Prime Order Subgroup
  7602. * - RFC 3526 section 3: 2048-bit MODP Group
  7603. * - RFC 3526 section 4: 3072-bit MODP Group
  7604. * - RFC 3526 section 5: 4096-bit MODP Group
  7605. * - RFC 7919 section A.1: ffdhe2048
  7606. * - RFC 7919 section A.2: ffdhe3072
  7607. * - RFC 7919 section A.3: ffdhe4096
  7608. * - RFC 7919 section A.4: ffdhe6144
  7609. * - RFC 7919 section A.5: ffdhe8192
  7610. *
  7611. * The constants with suffix "_p" denote the chosen prime moduli, while
  7612. * the constants with suffix "_g" denote the chosen generator
  7613. * of the associated prime field.
  7614. *
  7615. * The constants further suffixed with "_bin" are provided in binary format,
  7616. * while all other constants represent null-terminated strings holding the
  7617. * hexadecimal presentation of the respective numbers.
  7618. *
  7619. * The primes from RFC 3526 and RFC 7919 have been generating by the following
  7620. * trust-worthy procedure:
  7621. * - Fix N in { 2048, 3072, 4096, 6144, 8192 } and consider the N-bit number
  7622. * the first and last 64 bits are all 1, and the remaining N - 128 bits of
  7623. * which are 0x7ff...ff.
  7624. * - Add the smallest multiple of the first N - 129 bits of the binary expansion
  7625. * of pi (for RFC 5236) or e (for RFC 7919) to this intermediate bit-string
  7626. * such that the resulting integer is a safe-prime.
  7627. * - The result is the respective RFC 3526 / 7919 prime, and the corresponding
  7628. * generator is always chosen to be 2 (which is a square for these prime,
  7629. * hence the corresponding subgroup has order (p-1)/2 and avoids leaking a
  7630. * bit in the private exponent).
  7631. *
  7632. */
  7633. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  7634. /**
  7635. * \warning The origin of the primes in RFC 5114 is not documented and
  7636. * their use therefore constitutes a security risk!
  7637. *
  7638. * \deprecated The hex-encoded primes from RFC 5114 are deprecated and are
  7639. * likely to be removed in a future version of the library without
  7640. * replacement.
  7641. */
  7642. /**
  7643. * The hexadecimal presentation of the prime underlying the
  7644. * 2048-bit MODP Group with 224-bit Prime Order Subgroup, as defined
  7645. * in <em>RFC-5114: Additional Diffie-Hellman Groups for Use with
  7646. * IETF Standards</em>.
  7647. */
  7648. #define MBEDTLS_DHM_RFC5114_MODP_2048_P \
  7649. MBEDTLS_DEPRECATED_STRING_CONSTANT( \
  7650. "AD107E1E9123A9D0D660FAA79559C51FA20D64E5683B9FD1" \
  7651. "B54B1597B61D0A75E6FA141DF95A56DBAF9A3C407BA1DF15" \
  7652. "EB3D688A309C180E1DE6B85A1274A0A66D3F8152AD6AC212" \
  7653. "9037C9EDEFDA4DF8D91E8FEF55B7394B7AD5B7D0B6C12207" \
  7654. "C9F98D11ED34DBF6C6BA0B2C8BBC27BE6A00E0A0B9C49708" \
  7655. "B3BF8A317091883681286130BC8985DB1602E714415D9330" \
  7656. "278273C7DE31EFDC7310F7121FD5A07415987D9ADC0A486D" \
  7657. "CDF93ACC44328387315D75E198C641A480CD86A1B9E587E8" \
  7658. "BE60E69CC928B2B9C52172E413042E9B23F10B0E16E79763" \
  7659. "C9B53DCF4BA80A29E3FB73C16B8E75B97EF363E2FFA31F71" \
  7660. "CF9DE5384E71B81C0AC4DFFE0C10E64F" )
  7661. /**
  7662. * The hexadecimal presentation of the chosen generator of the 2048-bit MODP
  7663. * Group with 224-bit Prime Order Subgroup, as defined in <em>RFC-5114:
  7664. * Additional Diffie-Hellman Groups for Use with IETF Standards</em>.
  7665. */
  7666. #define MBEDTLS_DHM_RFC5114_MODP_2048_G \
  7667. MBEDTLS_DEPRECATED_STRING_CONSTANT( \
  7668. "AC4032EF4F2D9AE39DF30B5C8FFDAC506CDEBE7B89998CAF" \
  7669. "74866A08CFE4FFE3A6824A4E10B9A6F0DD921F01A70C4AFA" \
  7670. "AB739D7700C29F52C57DB17C620A8652BE5E9001A8D66AD7" \
  7671. "C17669101999024AF4D027275AC1348BB8A762D0521BC98A" \
  7672. "E247150422EA1ED409939D54DA7460CDB5F6C6B250717CBE" \
  7673. "F180EB34118E98D119529A45D6F834566E3025E316A330EF" \
  7674. "BB77A86F0C1AB15B051AE3D428C8F8ACB70A8137150B8EEB" \
  7675. "10E183EDD19963DDD9E263E4770589EF6AA21E7F5F2FF381" \
  7676. "B539CCE3409D13CD566AFBB48D6C019181E1BCFE94B30269" \
  7677. "EDFE72FE9B6AA4BD7B5A0F1C71CFFF4C19C418E1F6EC0179" \
  7678. "81BC087F2A7065B384B890D3191F2BFA" )
  7679. /**
  7680. * The hexadecimal presentation of the prime underlying the 2048-bit MODP
  7681. * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
  7682. * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
  7683. *
  7684. * \deprecated The hex-encoded primes from RFC 3625 are deprecated and
  7685. * superseded by the corresponding macros providing them as
  7686. * binary constants. Their hex-encoded constants are likely
  7687. * to be removed in a future version of the library.
  7688. *
  7689. */
  7690. #define MBEDTLS_DHM_RFC3526_MODP_2048_P \
  7691. MBEDTLS_DEPRECATED_STRING_CONSTANT( \
  7692. "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
  7693. "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
  7694. "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
  7695. "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
  7696. "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
  7697. "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
  7698. "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
  7699. "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
  7700. "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
  7701. "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
  7702. "15728E5A8AACAA68FFFFFFFFFFFFFFFF" )
  7703. /**
  7704. * The hexadecimal presentation of the chosen generator of the 2048-bit MODP
  7705. * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
  7706. * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
  7707. */
  7708. #define MBEDTLS_DHM_RFC3526_MODP_2048_G \
  7709. MBEDTLS_DEPRECATED_STRING_CONSTANT( "02" )
  7710. /**
  7711. * The hexadecimal presentation of the prime underlying the 3072-bit MODP
  7712. * Group, as defined in <em>RFC-3072: More Modular Exponential (MODP)
  7713. * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
  7714. */
  7715. #define MBEDTLS_DHM_RFC3526_MODP_3072_P \
  7716. MBEDTLS_DEPRECATED_STRING_CONSTANT( \
  7717. "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
  7718. "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
  7719. "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
  7720. "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
  7721. "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
  7722. "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
  7723. "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
  7724. "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
  7725. "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
  7726. "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
  7727. "15728E5A8AAAC42DAD33170D04507A33A85521ABDF1CBA64" \
  7728. "ECFB850458DBEF0A8AEA71575D060C7DB3970F85A6E1E4C7" \
  7729. "ABF5AE8CDB0933D71E8C94E04A25619DCEE3D2261AD2EE6B" \
  7730. "F12FFA06D98A0864D87602733EC86A64521F2B18177B200C" \
  7731. "BBE117577A615D6C770988C0BAD946E208E24FA074E5AB31" \
  7732. "43DB5BFCE0FD108E4B82D120A93AD2CAFFFFFFFFFFFFFFFF" )
  7733. /**
  7734. * The hexadecimal presentation of the chosen generator of the 3072-bit MODP
  7735. * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
  7736. * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
  7737. */
  7738. #define MBEDTLS_DHM_RFC3526_MODP_3072_G \
  7739. MBEDTLS_DEPRECATED_STRING_CONSTANT( "02" )
  7740. /**
  7741. * The hexadecimal presentation of the prime underlying the 4096-bit MODP
  7742. * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
  7743. * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
  7744. */
  7745. #define MBEDTLS_DHM_RFC3526_MODP_4096_P \
  7746. MBEDTLS_DEPRECATED_STRING_CONSTANT( \
  7747. "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
  7748. "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
  7749. "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
  7750. "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
  7751. "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
  7752. "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
  7753. "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
  7754. "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
  7755. "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
  7756. "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
  7757. "15728E5A8AAAC42DAD33170D04507A33A85521ABDF1CBA64" \
  7758. "ECFB850458DBEF0A8AEA71575D060C7DB3970F85A6E1E4C7" \
  7759. "ABF5AE8CDB0933D71E8C94E04A25619DCEE3D2261AD2EE6B" \
  7760. "F12FFA06D98A0864D87602733EC86A64521F2B18177B200C" \
  7761. "BBE117577A615D6C770988C0BAD946E208E24FA074E5AB31" \
  7762. "43DB5BFCE0FD108E4B82D120A92108011A723C12A787E6D7" \
  7763. "88719A10BDBA5B2699C327186AF4E23C1A946834B6150BDA" \
  7764. "2583E9CA2AD44CE8DBBBC2DB04DE8EF92E8EFC141FBECAA6" \
  7765. "287C59474E6BC05D99B2964FA090C3A2233BA186515BE7ED" \
  7766. "1F612970CEE2D7AFB81BDD762170481CD0069127D5B05AA9" \
  7767. "93B4EA988D8FDDC186FFB7DC90A6C08F4DF435C934063199" \
  7768. "FFFFFFFFFFFFFFFF" )
  7769. /**
  7770. * The hexadecimal presentation of the chosen generator of the 4096-bit MODP
  7771. * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
  7772. * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
  7773. */
  7774. #define MBEDTLS_DHM_RFC3526_MODP_4096_G \
  7775. MBEDTLS_DEPRECATED_STRING_CONSTANT( "02" )
  7776. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  7777. /*
  7778. * Trustworthy DHM parameters in binary form
  7779. */
  7780. #define MBEDTLS_DHM_RFC3526_MODP_2048_P_BIN { \
  7781. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
  7782. 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
  7783. 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
  7784. 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
  7785. 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
  7786. 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
  7787. 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
  7788. 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
  7789. 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
  7790. 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
  7791. 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
  7792. 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
  7793. 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
  7794. 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
  7795. 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
  7796. 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
  7797. 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
  7798. 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
  7799. 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
  7800. 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
  7801. 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
  7802. 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
  7803. 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
  7804. 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
  7805. 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
  7806. 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
  7807. 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
  7808. 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
  7809. 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
  7810. 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
  7811. 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAC, 0xAA, 0x68, \
  7812. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
  7813. #define MBEDTLS_DHM_RFC3526_MODP_2048_G_BIN { 0x02 }
  7814. #define MBEDTLS_DHM_RFC3526_MODP_3072_P_BIN { \
  7815. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
  7816. 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
  7817. 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
  7818. 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
  7819. 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
  7820. 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
  7821. 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
  7822. 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
  7823. 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
  7824. 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
  7825. 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
  7826. 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
  7827. 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
  7828. 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
  7829. 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
  7830. 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
  7831. 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
  7832. 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
  7833. 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
  7834. 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
  7835. 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
  7836. 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
  7837. 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
  7838. 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
  7839. 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
  7840. 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
  7841. 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
  7842. 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
  7843. 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
  7844. 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
  7845. 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAA, 0xC4, 0x2D, \
  7846. 0xAD, 0x33, 0x17, 0x0D, 0x04, 0x50, 0x7A, 0x33, \
  7847. 0xA8, 0x55, 0x21, 0xAB, 0xDF, 0x1C, 0xBA, 0x64, \
  7848. 0xEC, 0xFB, 0x85, 0x04, 0x58, 0xDB, 0xEF, 0x0A, \
  7849. 0x8A, 0xEA, 0x71, 0x57, 0x5D, 0x06, 0x0C, 0x7D, \
  7850. 0xB3, 0x97, 0x0F, 0x85, 0xA6, 0xE1, 0xE4, 0xC7, \
  7851. 0xAB, 0xF5, 0xAE, 0x8C, 0xDB, 0x09, 0x33, 0xD7, \
  7852. 0x1E, 0x8C, 0x94, 0xE0, 0x4A, 0x25, 0x61, 0x9D, \
  7853. 0xCE, 0xE3, 0xD2, 0x26, 0x1A, 0xD2, 0xEE, 0x6B, \
  7854. 0xF1, 0x2F, 0xFA, 0x06, 0xD9, 0x8A, 0x08, 0x64, \
  7855. 0xD8, 0x76, 0x02, 0x73, 0x3E, 0xC8, 0x6A, 0x64, \
  7856. 0x52, 0x1F, 0x2B, 0x18, 0x17, 0x7B, 0x20, 0x0C, \
  7857. 0xBB, 0xE1, 0x17, 0x57, 0x7A, 0x61, 0x5D, 0x6C, \
  7858. 0x77, 0x09, 0x88, 0xC0, 0xBA, 0xD9, 0x46, 0xE2, \
  7859. 0x08, 0xE2, 0x4F, 0xA0, 0x74, 0xE5, 0xAB, 0x31, \
  7860. 0x43, 0xDB, 0x5B, 0xFC, 0xE0, 0xFD, 0x10, 0x8E, \
  7861. 0x4B, 0x82, 0xD1, 0x20, 0xA9, 0x3A, 0xD2, 0xCA, \
  7862. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
  7863. #define MBEDTLS_DHM_RFC3526_MODP_3072_G_BIN { 0x02 }
  7864. #define MBEDTLS_DHM_RFC3526_MODP_4096_P_BIN { \
  7865. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
  7866. 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
  7867. 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
  7868. 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
  7869. 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
  7870. 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
  7871. 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
  7872. 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
  7873. 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
  7874. 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
  7875. 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
  7876. 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
  7877. 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
  7878. 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
  7879. 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
  7880. 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
  7881. 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
  7882. 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
  7883. 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
  7884. 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
  7885. 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
  7886. 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
  7887. 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
  7888. 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
  7889. 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
  7890. 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
  7891. 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
  7892. 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
  7893. 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
  7894. 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
  7895. 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAA, 0xC4, 0x2D, \
  7896. 0xAD, 0x33, 0x17, 0x0D, 0x04, 0x50, 0x7A, 0x33, \
  7897. 0xA8, 0x55, 0x21, 0xAB, 0xDF, 0x1C, 0xBA, 0x64, \
  7898. 0xEC, 0xFB, 0x85, 0x04, 0x58, 0xDB, 0xEF, 0x0A, \
  7899. 0x8A, 0xEA, 0x71, 0x57, 0x5D, 0x06, 0x0C, 0x7D, \
  7900. 0xB3, 0x97, 0x0F, 0x85, 0xA6, 0xE1, 0xE4, 0xC7, \
  7901. 0xAB, 0xF5, 0xAE, 0x8C, 0xDB, 0x09, 0x33, 0xD7, \
  7902. 0x1E, 0x8C, 0x94, 0xE0, 0x4A, 0x25, 0x61, 0x9D, \
  7903. 0xCE, 0xE3, 0xD2, 0x26, 0x1A, 0xD2, 0xEE, 0x6B, \
  7904. 0xF1, 0x2F, 0xFA, 0x06, 0xD9, 0x8A, 0x08, 0x64, \
  7905. 0xD8, 0x76, 0x02, 0x73, 0x3E, 0xC8, 0x6A, 0x64, \
  7906. 0x52, 0x1F, 0x2B, 0x18, 0x17, 0x7B, 0x20, 0x0C, \
  7907. 0xBB, 0xE1, 0x17, 0x57, 0x7A, 0x61, 0x5D, 0x6C, \
  7908. 0x77, 0x09, 0x88, 0xC0, 0xBA, 0xD9, 0x46, 0xE2, \
  7909. 0x08, 0xE2, 0x4F, 0xA0, 0x74, 0xE5, 0xAB, 0x31, \
  7910. 0x43, 0xDB, 0x5B, 0xFC, 0xE0, 0xFD, 0x10, 0x8E, \
  7911. 0x4B, 0x82, 0xD1, 0x20, 0xA9, 0x21, 0x08, 0x01, \
  7912. 0x1A, 0x72, 0x3C, 0x12, 0xA7, 0x87, 0xE6, 0xD7, \
  7913. 0x88, 0x71, 0x9A, 0x10, 0xBD, 0xBA, 0x5B, 0x26, \
  7914. 0x99, 0xC3, 0x27, 0x18, 0x6A, 0xF4, 0xE2, 0x3C, \
  7915. 0x1A, 0x94, 0x68, 0x34, 0xB6, 0x15, 0x0B, 0xDA, \
  7916. 0x25, 0x83, 0xE9, 0xCA, 0x2A, 0xD4, 0x4C, 0xE8, \
  7917. 0xDB, 0xBB, 0xC2, 0xDB, 0x04, 0xDE, 0x8E, 0xF9, \
  7918. 0x2E, 0x8E, 0xFC, 0x14, 0x1F, 0xBE, 0xCA, 0xA6, \
  7919. 0x28, 0x7C, 0x59, 0x47, 0x4E, 0x6B, 0xC0, 0x5D, \
  7920. 0x99, 0xB2, 0x96, 0x4F, 0xA0, 0x90, 0xC3, 0xA2, \
  7921. 0x23, 0x3B, 0xA1, 0x86, 0x51, 0x5B, 0xE7, 0xED, \
  7922. 0x1F, 0x61, 0x29, 0x70, 0xCE, 0xE2, 0xD7, 0xAF, \
  7923. 0xB8, 0x1B, 0xDD, 0x76, 0x21, 0x70, 0x48, 0x1C, \
  7924. 0xD0, 0x06, 0x91, 0x27, 0xD5, 0xB0, 0x5A, 0xA9, \
  7925. 0x93, 0xB4, 0xEA, 0x98, 0x8D, 0x8F, 0xDD, 0xC1, \
  7926. 0x86, 0xFF, 0xB7, 0xDC, 0x90, 0xA6, 0xC0, 0x8F, \
  7927. 0x4D, 0xF4, 0x35, 0xC9, 0x34, 0x06, 0x31, 0x99, \
  7928. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
  7929. #define MBEDTLS_DHM_RFC3526_MODP_4096_G_BIN { 0x02 }
  7930. #define MBEDTLS_DHM_RFC7919_FFDHE2048_P_BIN { \
  7931. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
  7932. 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
  7933. 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
  7934. 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
  7935. 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
  7936. 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
  7937. 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
  7938. 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
  7939. 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
  7940. 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
  7941. 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
  7942. 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
  7943. 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
  7944. 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
  7945. 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
  7946. 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
  7947. 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
  7948. 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
  7949. 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
  7950. 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
  7951. 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
  7952. 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
  7953. 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
  7954. 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
  7955. 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
  7956. 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
  7957. 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
  7958. 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
  7959. 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
  7960. 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
  7961. 0x88, 0x6B, 0x42, 0x38, 0x61, 0x28, 0x5C, 0x97, \
  7962. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, }
  7963. #define MBEDTLS_DHM_RFC7919_FFDHE2048_G_BIN { 0x02 }
  7964. #define MBEDTLS_DHM_RFC7919_FFDHE3072_P_BIN { \
  7965. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
  7966. 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
  7967. 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
  7968. 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
  7969. 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
  7970. 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
  7971. 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
  7972. 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
  7973. 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
  7974. 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
  7975. 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
  7976. 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
  7977. 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
  7978. 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
  7979. 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
  7980. 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
  7981. 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
  7982. 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
  7983. 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
  7984. 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
  7985. 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
  7986. 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
  7987. 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
  7988. 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
  7989. 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
  7990. 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
  7991. 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
  7992. 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
  7993. 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
  7994. 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
  7995. 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
  7996. 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
  7997. 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
  7998. 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
  7999. 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
  8000. 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
  8001. 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
  8002. 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
  8003. 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
  8004. 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
  8005. 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
  8006. 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
  8007. 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
  8008. 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
  8009. 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
  8010. 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
  8011. 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0xC6, 0x2E, 0x37, \
  8012. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
  8013. #define MBEDTLS_DHM_RFC7919_FFDHE3072_G_BIN { 0x02 }
  8014. #define MBEDTLS_DHM_RFC7919_FFDHE4096_P_BIN { \
  8015. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
  8016. 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
  8017. 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
  8018. 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
  8019. 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
  8020. 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
  8021. 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
  8022. 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
  8023. 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
  8024. 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
  8025. 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
  8026. 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
  8027. 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
  8028. 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
  8029. 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
  8030. 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
  8031. 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
  8032. 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
  8033. 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
  8034. 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
  8035. 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
  8036. 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
  8037. 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
  8038. 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
  8039. 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
  8040. 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
  8041. 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
  8042. 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
  8043. 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
  8044. 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
  8045. 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
  8046. 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
  8047. 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
  8048. 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
  8049. 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
  8050. 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
  8051. 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
  8052. 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
  8053. 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
  8054. 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
  8055. 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
  8056. 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
  8057. 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
  8058. 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
  8059. 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
  8060. 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
  8061. 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
  8062. 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
  8063. 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
  8064. 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
  8065. 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
  8066. 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
  8067. 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
  8068. 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
  8069. 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
  8070. 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
  8071. 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
  8072. 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
  8073. 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
  8074. 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
  8075. 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
  8076. 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
  8077. 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x65, 0x5F, 0x6A, \
  8078. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
  8079. #define MBEDTLS_DHM_RFC7919_FFDHE4096_G_BIN { 0x02 }
  8080. #define MBEDTLS_DHM_RFC7919_FFDHE6144_P_BIN { \
  8081. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
  8082. 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
  8083. 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
  8084. 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
  8085. 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
  8086. 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
  8087. 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
  8088. 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
  8089. 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
  8090. 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
  8091. 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
  8092. 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
  8093. 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
  8094. 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
  8095. 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
  8096. 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
  8097. 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
  8098. 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
  8099. 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
  8100. 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
  8101. 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
  8102. 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
  8103. 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
  8104. 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
  8105. 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
  8106. 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
  8107. 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
  8108. 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
  8109. 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
  8110. 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
  8111. 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
  8112. 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
  8113. 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
  8114. 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
  8115. 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
  8116. 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
  8117. 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
  8118. 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
  8119. 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
  8120. 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
  8121. 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
  8122. 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
  8123. 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
  8124. 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
  8125. 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
  8126. 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
  8127. 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
  8128. 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
  8129. 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
  8130. 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
  8131. 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
  8132. 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
  8133. 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
  8134. 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
  8135. 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
  8136. 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
  8137. 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
  8138. 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
  8139. 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
  8140. 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
  8141. 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
  8142. 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
  8143. 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x0D, 0xD9, 0x02, \
  8144. 0x0B, 0xFD, 0x64, 0xB6, 0x45, 0x03, 0x6C, 0x7A, \
  8145. 0x4E, 0x67, 0x7D, 0x2C, 0x38, 0x53, 0x2A, 0x3A, \
  8146. 0x23, 0xBA, 0x44, 0x42, 0xCA, 0xF5, 0x3E, 0xA6, \
  8147. 0x3B, 0xB4, 0x54, 0x32, 0x9B, 0x76, 0x24, 0xC8, \
  8148. 0x91, 0x7B, 0xDD, 0x64, 0xB1, 0xC0, 0xFD, 0x4C, \
  8149. 0xB3, 0x8E, 0x8C, 0x33, 0x4C, 0x70, 0x1C, 0x3A, \
  8150. 0xCD, 0xAD, 0x06, 0x57, 0xFC, 0xCF, 0xEC, 0x71, \
  8151. 0x9B, 0x1F, 0x5C, 0x3E, 0x4E, 0x46, 0x04, 0x1F, \
  8152. 0x38, 0x81, 0x47, 0xFB, 0x4C, 0xFD, 0xB4, 0x77, \
  8153. 0xA5, 0x24, 0x71, 0xF7, 0xA9, 0xA9, 0x69, 0x10, \
  8154. 0xB8, 0x55, 0x32, 0x2E, 0xDB, 0x63, 0x40, 0xD8, \
  8155. 0xA0, 0x0E, 0xF0, 0x92, 0x35, 0x05, 0x11, 0xE3, \
  8156. 0x0A, 0xBE, 0xC1, 0xFF, 0xF9, 0xE3, 0xA2, 0x6E, \
  8157. 0x7F, 0xB2, 0x9F, 0x8C, 0x18, 0x30, 0x23, 0xC3, \
  8158. 0x58, 0x7E, 0x38, 0xDA, 0x00, 0x77, 0xD9, 0xB4, \
  8159. 0x76, 0x3E, 0x4E, 0x4B, 0x94, 0xB2, 0xBB, 0xC1, \
  8160. 0x94, 0xC6, 0x65, 0x1E, 0x77, 0xCA, 0xF9, 0x92, \
  8161. 0xEE, 0xAA, 0xC0, 0x23, 0x2A, 0x28, 0x1B, 0xF6, \
  8162. 0xB3, 0xA7, 0x39, 0xC1, 0x22, 0x61, 0x16, 0x82, \
  8163. 0x0A, 0xE8, 0xDB, 0x58, 0x47, 0xA6, 0x7C, 0xBE, \
  8164. 0xF9, 0xC9, 0x09, 0x1B, 0x46, 0x2D, 0x53, 0x8C, \
  8165. 0xD7, 0x2B, 0x03, 0x74, 0x6A, 0xE7, 0x7F, 0x5E, \
  8166. 0x62, 0x29, 0x2C, 0x31, 0x15, 0x62, 0xA8, 0x46, \
  8167. 0x50, 0x5D, 0xC8, 0x2D, 0xB8, 0x54, 0x33, 0x8A, \
  8168. 0xE4, 0x9F, 0x52, 0x35, 0xC9, 0x5B, 0x91, 0x17, \
  8169. 0x8C, 0xCF, 0x2D, 0xD5, 0xCA, 0xCE, 0xF4, 0x03, \
  8170. 0xEC, 0x9D, 0x18, 0x10, 0xC6, 0x27, 0x2B, 0x04, \
  8171. 0x5B, 0x3B, 0x71, 0xF9, 0xDC, 0x6B, 0x80, 0xD6, \
  8172. 0x3F, 0xDD, 0x4A, 0x8E, 0x9A, 0xDB, 0x1E, 0x69, \
  8173. 0x62, 0xA6, 0x95, 0x26, 0xD4, 0x31, 0x61, 0xC1, \
  8174. 0xA4, 0x1D, 0x57, 0x0D, 0x79, 0x38, 0xDA, 0xD4, \
  8175. 0xA4, 0x0E, 0x32, 0x9C, 0xD0, 0xE4, 0x0E, 0x65, \
  8176. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
  8177. #define MBEDTLS_DHM_RFC7919_FFDHE6144_G_BIN { 0x02 }
  8178. #define MBEDTLS_DHM_RFC7919_FFDHE8192_P_BIN { \
  8179. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
  8180. 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
  8181. 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
  8182. 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
  8183. 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
  8184. 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
  8185. 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
  8186. 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
  8187. 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
  8188. 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
  8189. 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
  8190. 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
  8191. 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
  8192. 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
  8193. 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
  8194. 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
  8195. 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
  8196. 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
  8197. 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
  8198. 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
  8199. 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
  8200. 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
  8201. 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
  8202. 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
  8203. 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
  8204. 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
  8205. 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
  8206. 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
  8207. 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
  8208. 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
  8209. 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
  8210. 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
  8211. 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
  8212. 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
  8213. 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
  8214. 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
  8215. 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
  8216. 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
  8217. 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
  8218. 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
  8219. 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
  8220. 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
  8221. 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
  8222. 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
  8223. 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
  8224. 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
  8225. 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
  8226. 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
  8227. 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
  8228. 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
  8229. 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
  8230. 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
  8231. 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
  8232. 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
  8233. 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
  8234. 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
  8235. 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
  8236. 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
  8237. 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
  8238. 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
  8239. 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
  8240. 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
  8241. 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x0D, 0xD9, 0x02, \
  8242. 0x0B, 0xFD, 0x64, 0xB6, 0x45, 0x03, 0x6C, 0x7A, \
  8243. 0x4E, 0x67, 0x7D, 0x2C, 0x38, 0x53, 0x2A, 0x3A, \
  8244. 0x23, 0xBA, 0x44, 0x42, 0xCA, 0xF5, 0x3E, 0xA6, \
  8245. 0x3B, 0xB4, 0x54, 0x32, 0x9B, 0x76, 0x24, 0xC8, \
  8246. 0x91, 0x7B, 0xDD, 0x64, 0xB1, 0xC0, 0xFD, 0x4C, \
  8247. 0xB3, 0x8E, 0x8C, 0x33, 0x4C, 0x70, 0x1C, 0x3A, \
  8248. 0xCD, 0xAD, 0x06, 0x57, 0xFC, 0xCF, 0xEC, 0x71, \
  8249. 0x9B, 0x1F, 0x5C, 0x3E, 0x4E, 0x46, 0x04, 0x1F, \
  8250. 0x38, 0x81, 0x47, 0xFB, 0x4C, 0xFD, 0xB4, 0x77, \
  8251. 0xA5, 0x24, 0x71, 0xF7, 0xA9, 0xA9, 0x69, 0x10, \
  8252. 0xB8, 0x55, 0x32, 0x2E, 0xDB, 0x63, 0x40, 0xD8, \
  8253. 0xA0, 0x0E, 0xF0, 0x92, 0x35, 0x05, 0x11, 0xE3, \
  8254. 0x0A, 0xBE, 0xC1, 0xFF, 0xF9, 0xE3, 0xA2, 0x6E, \
  8255. 0x7F, 0xB2, 0x9F, 0x8C, 0x18, 0x30, 0x23, 0xC3, \
  8256. 0x58, 0x7E, 0x38, 0xDA, 0x00, 0x77, 0xD9, 0xB4, \
  8257. 0x76, 0x3E, 0x4E, 0x4B, 0x94, 0xB2, 0xBB, 0xC1, \
  8258. 0x94, 0xC6, 0x65, 0x1E, 0x77, 0xCA, 0xF9, 0x92, \
  8259. 0xEE, 0xAA, 0xC0, 0x23, 0x2A, 0x28, 0x1B, 0xF6, \
  8260. 0xB3, 0xA7, 0x39, 0xC1, 0x22, 0x61, 0x16, 0x82, \
  8261. 0x0A, 0xE8, 0xDB, 0x58, 0x47, 0xA6, 0x7C, 0xBE, \
  8262. 0xF9, 0xC9, 0x09, 0x1B, 0x46, 0x2D, 0x53, 0x8C, \
  8263. 0xD7, 0x2B, 0x03, 0x74, 0x6A, 0xE7, 0x7F, 0x5E, \
  8264. 0x62, 0x29, 0x2C, 0x31, 0x15, 0x62, 0xA8, 0x46, \
  8265. 0x50, 0x5D, 0xC8, 0x2D, 0xB8, 0x54, 0x33, 0x8A, \
  8266. 0xE4, 0x9F, 0x52, 0x35, 0xC9, 0x5B, 0x91, 0x17, \
  8267. 0x8C, 0xCF, 0x2D, 0xD5, 0xCA, 0xCE, 0xF4, 0x03, \
  8268. 0xEC, 0x9D, 0x18, 0x10, 0xC6, 0x27, 0x2B, 0x04, \
  8269. 0x5B, 0x3B, 0x71, 0xF9, 0xDC, 0x6B, 0x80, 0xD6, \
  8270. 0x3F, 0xDD, 0x4A, 0x8E, 0x9A, 0xDB, 0x1E, 0x69, \
  8271. 0x62, 0xA6, 0x95, 0x26, 0xD4, 0x31, 0x61, 0xC1, \
  8272. 0xA4, 0x1D, 0x57, 0x0D, 0x79, 0x38, 0xDA, 0xD4, \
  8273. 0xA4, 0x0E, 0x32, 0x9C, 0xCF, 0xF4, 0x6A, 0xAA, \
  8274. 0x36, 0xAD, 0x00, 0x4C, 0xF6, 0x00, 0xC8, 0x38, \
  8275. 0x1E, 0x42, 0x5A, 0x31, 0xD9, 0x51, 0xAE, 0x64, \
  8276. 0xFD, 0xB2, 0x3F, 0xCE, 0xC9, 0x50, 0x9D, 0x43, \
  8277. 0x68, 0x7F, 0xEB, 0x69, 0xED, 0xD1, 0xCC, 0x5E, \
  8278. 0x0B, 0x8C, 0xC3, 0xBD, 0xF6, 0x4B, 0x10, 0xEF, \
  8279. 0x86, 0xB6, 0x31, 0x42, 0xA3, 0xAB, 0x88, 0x29, \
  8280. 0x55, 0x5B, 0x2F, 0x74, 0x7C, 0x93, 0x26, 0x65, \
  8281. 0xCB, 0x2C, 0x0F, 0x1C, 0xC0, 0x1B, 0xD7, 0x02, \
  8282. 0x29, 0x38, 0x88, 0x39, 0xD2, 0xAF, 0x05, 0xE4, \
  8283. 0x54, 0x50, 0x4A, 0xC7, 0x8B, 0x75, 0x82, 0x82, \
  8284. 0x28, 0x46, 0xC0, 0xBA, 0x35, 0xC3, 0x5F, 0x5C, \
  8285. 0x59, 0x16, 0x0C, 0xC0, 0x46, 0xFD, 0x82, 0x51, \
  8286. 0x54, 0x1F, 0xC6, 0x8C, 0x9C, 0x86, 0xB0, 0x22, \
  8287. 0xBB, 0x70, 0x99, 0x87, 0x6A, 0x46, 0x0E, 0x74, \
  8288. 0x51, 0xA8, 0xA9, 0x31, 0x09, 0x70, 0x3F, 0xEE, \
  8289. 0x1C, 0x21, 0x7E, 0x6C, 0x38, 0x26, 0xE5, 0x2C, \
  8290. 0x51, 0xAA, 0x69, 0x1E, 0x0E, 0x42, 0x3C, 0xFC, \
  8291. 0x99, 0xE9, 0xE3, 0x16, 0x50, 0xC1, 0x21, 0x7B, \
  8292. 0x62, 0x48, 0x16, 0xCD, 0xAD, 0x9A, 0x95, 0xF9, \
  8293. 0xD5, 0xB8, 0x01, 0x94, 0x88, 0xD9, 0xC0, 0xA0, \
  8294. 0xA1, 0xFE, 0x30, 0x75, 0xA5, 0x77, 0xE2, 0x31, \
  8295. 0x83, 0xF8, 0x1D, 0x4A, 0x3F, 0x2F, 0xA4, 0x57, \
  8296. 0x1E, 0xFC, 0x8C, 0xE0, 0xBA, 0x8A, 0x4F, 0xE8, \
  8297. 0xB6, 0x85, 0x5D, 0xFE, 0x72, 0xB0, 0xA6, 0x6E, \
  8298. 0xDE, 0xD2, 0xFB, 0xAB, 0xFB, 0xE5, 0x8A, 0x30, \
  8299. 0xFA, 0xFA, 0xBE, 0x1C, 0x5D, 0x71, 0xA8, 0x7E, \
  8300. 0x2F, 0x74, 0x1E, 0xF8, 0xC1, 0xFE, 0x86, 0xFE, \
  8301. 0xA6, 0xBB, 0xFD, 0xE5, 0x30, 0x67, 0x7F, 0x0D, \
  8302. 0x97, 0xD1, 0x1D, 0x49, 0xF7, 0xA8, 0x44, 0x3D, \
  8303. 0x08, 0x22, 0xE5, 0x06, 0xA9, 0xF4, 0x61, 0x4E, \
  8304. 0x01, 0x1E, 0x2A, 0x94, 0x83, 0x8F, 0xF8, 0x8C, \
  8305. 0xD6, 0x8C, 0x8B, 0xB7, 0xC5, 0xC6, 0x42, 0x4C, \
  8306. 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
  8307. #define MBEDTLS_DHM_RFC7919_FFDHE8192_G_BIN { 0x02 }
  8308. #endif /* dhm.h */
  8309. /********* Start of file include/mbedtls/error.h ************/
  8310. /**
  8311. * \file error.h
  8312. *
  8313. * \brief Error to string translation
  8314. */
  8315. /*
  8316. * Copyright The Mbed TLS Contributors
  8317. * SPDX-License-Identifier: Apache-2.0
  8318. *
  8319. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  8320. * not use this file except in compliance with the License.
  8321. * You may obtain a copy of the License at
  8322. *
  8323. * http://www.apache.org/licenses/LICENSE-2.0
  8324. *
  8325. * Unless required by applicable law or agreed to in writing, software
  8326. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  8327. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  8328. * See the License for the specific language governing permissions and
  8329. * limitations under the License.
  8330. */
  8331. #ifndef MBEDTLS_ERROR_H
  8332. #define MBEDTLS_ERROR_H
  8333. #if !defined(MBEDTLS_CONFIG_FILE)
  8334. #else
  8335. #endif
  8336. #include <stddef.h>
  8337. #if ( defined(__ARMCC_VERSION) || defined(_MSC_VER) ) && \
  8338. !defined(inline) && !defined(__cplusplus)
  8339. #define inline __inline
  8340. #endif
  8341. /**
  8342. * Error code layout.
  8343. *
  8344. * Currently we try to keep all error codes within the negative space of 16
  8345. * bits signed integers to support all platforms (-0x0001 - -0x7FFF). In
  8346. * addition we'd like to give two layers of information on the error if
  8347. * possible.
  8348. *
  8349. * For that purpose the error codes are segmented in the following manner:
  8350. *
  8351. * 16 bit error code bit-segmentation
  8352. *
  8353. * 1 bit - Unused (sign bit)
  8354. * 3 bits - High level module ID
  8355. * 5 bits - Module-dependent error code
  8356. * 7 bits - Low level module errors
  8357. *
  8358. * For historical reasons, low-level error codes are divided in even and odd,
  8359. * even codes were assigned first, and -1 is reserved for other errors.
  8360. *
  8361. * Low-level module errors (0x0002-0x007E, 0x0001-0x007F)
  8362. *
  8363. * Module Nr Codes assigned
  8364. * ERROR 2 0x006E 0x0001
  8365. * MPI 7 0x0002-0x0010
  8366. * GCM 3 0x0012-0x0014 0x0013-0x0013
  8367. * BLOWFISH 3 0x0016-0x0018 0x0017-0x0017
  8368. * THREADING 3 0x001A-0x001E
  8369. * AES 5 0x0020-0x0022 0x0021-0x0025
  8370. * CAMELLIA 3 0x0024-0x0026 0x0027-0x0027
  8371. * XTEA 2 0x0028-0x0028 0x0029-0x0029
  8372. * BASE64 2 0x002A-0x002C
  8373. * OID 1 0x002E-0x002E 0x000B-0x000B
  8374. * PADLOCK 1 0x0030-0x0030
  8375. * DES 2 0x0032-0x0032 0x0033-0x0033
  8376. * CTR_DBRG 4 0x0034-0x003A
  8377. * ENTROPY 3 0x003C-0x0040 0x003D-0x003F
  8378. * NET 13 0x0042-0x0052 0x0043-0x0049
  8379. * ARIA 4 0x0058-0x005E
  8380. * ASN1 7 0x0060-0x006C
  8381. * CMAC 1 0x007A-0x007A
  8382. * PBKDF2 1 0x007C-0x007C
  8383. * HMAC_DRBG 4 0x0003-0x0009
  8384. * CCM 3 0x000D-0x0011
  8385. * ARC4 1 0x0019-0x0019
  8386. * MD2 1 0x002B-0x002B
  8387. * MD4 1 0x002D-0x002D
  8388. * MD5 1 0x002F-0x002F
  8389. * RIPEMD160 1 0x0031-0x0031
  8390. * SHA1 1 0x0035-0x0035 0x0073-0x0073
  8391. * SHA256 1 0x0037-0x0037 0x0074-0x0074
  8392. * SHA512 1 0x0039-0x0039 0x0075-0x0075
  8393. * CHACHA20 3 0x0051-0x0055
  8394. * POLY1305 3 0x0057-0x005B
  8395. * CHACHAPOLY 2 0x0054-0x0056
  8396. * PLATFORM 2 0x0070-0x0072
  8397. *
  8398. * High-level module nr (3 bits - 0x0...-0x7...)
  8399. * Name ID Nr of Errors
  8400. * PEM 1 9
  8401. * PKCS#12 1 4 (Started from top)
  8402. * X509 2 20
  8403. * PKCS5 2 4 (Started from top)
  8404. * DHM 3 11
  8405. * PK 3 15 (Started from top)
  8406. * RSA 4 11
  8407. * ECP 4 10 (Started from top)
  8408. * MD 5 5
  8409. * HKDF 5 1 (Started from top)
  8410. * SSL 5 2 (Started from 0x5F00)
  8411. * CIPHER 6 8 (Started from 0x6080)
  8412. * SSL 6 24 (Started from top, plus 0x6000)
  8413. * SSL 7 32
  8414. *
  8415. * Module dependent error code (5 bits 0x.00.-0x.F8.)
  8416. */
  8417. #ifdef __cplusplus
  8418. extern "C" {
  8419. #endif
  8420. /** Generic error */
  8421. #define MBEDTLS_ERR_ERROR_GENERIC_ERROR -0x0001
  8422. /** This is a bug in the library */
  8423. #define MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED -0x006E
  8424. /**
  8425. * \brief Combines a high-level and low-level error code together.
  8426. *
  8427. * Wrapper macro for mbedtls_error_add(). See that function for
  8428. * more details.
  8429. */
  8430. #define MBEDTLS_ERROR_ADD( high, low ) \
  8431. mbedtls_error_add( high, low, __FILE__, __LINE__ )
  8432. #if defined(MBEDTLS_TEST_HOOKS)
  8433. /**
  8434. * \brief Testing hook called before adding/combining two error codes together.
  8435. * Only used when invasive testing is enabled via MBEDTLS_TEST_HOOKS.
  8436. */
  8437. extern void (*mbedtls_test_hook_error_add)( int, int, const char *, int );
  8438. #endif
  8439. /**
  8440. * \brief Combines a high-level and low-level error code together.
  8441. *
  8442. * This function can be called directly however it is usually
  8443. * called via the #MBEDTLS_ERROR_ADD macro.
  8444. *
  8445. * While a value of zero is not a negative error code, it is still an
  8446. * error code (that denotes success) and can be combined with both a
  8447. * negative error code or another value of zero.
  8448. *
  8449. * \note When invasive testing is enabled via #MBEDTLS_TEST_HOOKS, also try to
  8450. * call \link mbedtls_test_hook_error_add \endlink.
  8451. *
  8452. * \param high high-level error code. See error.h for more details.
  8453. * \param low low-level error code. See error.h for more details.
  8454. * \param file file where this error code addition occurred.
  8455. * \param line line where this error code addition occurred.
  8456. */
  8457. static inline int mbedtls_error_add( int high, int low,
  8458. const char *file, int line )
  8459. {
  8460. #if defined(MBEDTLS_TEST_HOOKS)
  8461. if( *mbedtls_test_hook_error_add != NULL )
  8462. ( *mbedtls_test_hook_error_add )( high, low, file, line );
  8463. #endif
  8464. (void)file;
  8465. (void)line;
  8466. return( high + low );
  8467. }
  8468. /**
  8469. * \brief Translate a mbed TLS error code into a string representation,
  8470. * Result is truncated if necessary and always includes a terminating
  8471. * null byte.
  8472. *
  8473. * \param errnum error code
  8474. * \param buffer buffer to place representation in
  8475. * \param buflen length of the buffer
  8476. */
  8477. void mbedtls_strerror( int errnum, char *buffer, size_t buflen );
  8478. /**
  8479. * \brief Translate the high-level part of an Mbed TLS error code into a string
  8480. * representation.
  8481. *
  8482. * This function returns a const pointer to an un-modifiable string. The caller
  8483. * must not try to modify the string. It is intended to be used mostly for
  8484. * logging purposes.
  8485. *
  8486. * \param error_code error code
  8487. *
  8488. * \return The string representation of the error code, or \c NULL if the error
  8489. * code is unknown.
  8490. */
  8491. const char * mbedtls_high_level_strerr( int error_code );
  8492. /**
  8493. * \brief Translate the low-level part of an Mbed TLS error code into a string
  8494. * representation.
  8495. *
  8496. * This function returns a const pointer to an un-modifiable string. The caller
  8497. * must not try to modify the string. It is intended to be used mostly for
  8498. * logging purposes.
  8499. *
  8500. * \param error_code error code
  8501. *
  8502. * \return The string representation of the error code, or \c NULL if the error
  8503. * code is unknown.
  8504. */
  8505. const char * mbedtls_low_level_strerr( int error_code );
  8506. #ifdef __cplusplus
  8507. }
  8508. #endif
  8509. #endif /* error.h */
  8510. /********* Start of file include/mbedtls/md.h ************/
  8511. /**
  8512. * \file md.h
  8513. *
  8514. * \brief This file contains the generic message-digest wrapper.
  8515. *
  8516. * \author Adriaan de Jong <dejong@fox-it.com>
  8517. */
  8518. /*
  8519. * Copyright The Mbed TLS Contributors
  8520. * SPDX-License-Identifier: Apache-2.0
  8521. *
  8522. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  8523. * not use this file except in compliance with the License.
  8524. * You may obtain a copy of the License at
  8525. *
  8526. * http://www.apache.org/licenses/LICENSE-2.0
  8527. *
  8528. * Unless required by applicable law or agreed to in writing, software
  8529. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  8530. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  8531. * See the License for the specific language governing permissions and
  8532. * limitations under the License.
  8533. */
  8534. #ifndef MBEDTLS_MD_H
  8535. #define MBEDTLS_MD_H
  8536. #include <stddef.h>
  8537. #if !defined(MBEDTLS_CONFIG_FILE)
  8538. #else
  8539. #endif
  8540. /** The selected feature is not available. */
  8541. #define MBEDTLS_ERR_MD_FEATURE_UNAVAILABLE -0x5080
  8542. /** Bad input parameters to function. */
  8543. #define MBEDTLS_ERR_MD_BAD_INPUT_DATA -0x5100
  8544. /** Failed to allocate memory. */
  8545. #define MBEDTLS_ERR_MD_ALLOC_FAILED -0x5180
  8546. /** Opening or reading of file failed. */
  8547. #define MBEDTLS_ERR_MD_FILE_IO_ERROR -0x5200
  8548. /* MBEDTLS_ERR_MD_HW_ACCEL_FAILED is deprecated and should not be used. */
  8549. /** MD hardware accelerator failed. */
  8550. #define MBEDTLS_ERR_MD_HW_ACCEL_FAILED -0x5280
  8551. #ifdef __cplusplus
  8552. extern "C" {
  8553. #endif
  8554. /**
  8555. * \brief Supported message digests.
  8556. *
  8557. * \warning MD2, MD4, MD5 and SHA-1 are considered weak message digests and
  8558. * their use constitutes a security risk. We recommend considering
  8559. * stronger message digests instead.
  8560. *
  8561. */
  8562. typedef enum {
  8563. MBEDTLS_MD_NONE=0, /**< None. */
  8564. MBEDTLS_MD_MD2, /**< The MD2 message digest. */
  8565. MBEDTLS_MD_MD4, /**< The MD4 message digest. */
  8566. MBEDTLS_MD_MD5, /**< The MD5 message digest. */
  8567. MBEDTLS_MD_SHA1, /**< The SHA-1 message digest. */
  8568. MBEDTLS_MD_SHA224, /**< The SHA-224 message digest. */
  8569. MBEDTLS_MD_SHA256, /**< The SHA-256 message digest. */
  8570. MBEDTLS_MD_SHA384, /**< The SHA-384 message digest. */
  8571. MBEDTLS_MD_SHA512, /**< The SHA-512 message digest. */
  8572. MBEDTLS_MD_RIPEMD160, /**< The RIPEMD-160 message digest. */
  8573. } mbedtls_md_type_t;
  8574. #if defined(MBEDTLS_SHA512_C)
  8575. #define MBEDTLS_MD_MAX_SIZE 64 /* longest known is SHA512 */
  8576. #else
  8577. #define MBEDTLS_MD_MAX_SIZE 32 /* longest known is SHA256 or less */
  8578. #endif
  8579. #if defined(MBEDTLS_SHA512_C)
  8580. #define MBEDTLS_MD_MAX_BLOCK_SIZE 128
  8581. #else
  8582. #define MBEDTLS_MD_MAX_BLOCK_SIZE 64
  8583. #endif
  8584. /**
  8585. * Opaque struct defined in md_internal.h.
  8586. */
  8587. typedef struct mbedtls_md_info_t mbedtls_md_info_t;
  8588. /**
  8589. * The generic message-digest context.
  8590. */
  8591. typedef struct mbedtls_md_context_t
  8592. {
  8593. /** Information about the associated message digest. */
  8594. const mbedtls_md_info_t *md_info;
  8595. /** The digest-specific context. */
  8596. void *md_ctx;
  8597. /** The HMAC part of the context. */
  8598. void *hmac_ctx;
  8599. } mbedtls_md_context_t;
  8600. /**
  8601. * \brief This function returns the list of digests supported by the
  8602. * generic digest module.
  8603. *
  8604. * \note The list starts with the strongest available hashes.
  8605. *
  8606. * \return A statically allocated array of digests. Each element
  8607. * in the returned list is an integer belonging to the
  8608. * message-digest enumeration #mbedtls_md_type_t.
  8609. * The last entry is 0.
  8610. */
  8611. const int *mbedtls_md_list( void );
  8612. /**
  8613. * \brief This function returns the message-digest information
  8614. * associated with the given digest name.
  8615. *
  8616. * \param md_name The name of the digest to search for.
  8617. *
  8618. * \return The message-digest information associated with \p md_name.
  8619. * \return NULL if the associated message-digest information is not found.
  8620. */
  8621. const mbedtls_md_info_t *mbedtls_md_info_from_string( const char *md_name );
  8622. /**
  8623. * \brief This function returns the message-digest information
  8624. * associated with the given digest type.
  8625. *
  8626. * \param md_type The type of digest to search for.
  8627. *
  8628. * \return The message-digest information associated with \p md_type.
  8629. * \return NULL if the associated message-digest information is not found.
  8630. */
  8631. const mbedtls_md_info_t *mbedtls_md_info_from_type( mbedtls_md_type_t md_type );
  8632. /**
  8633. * \brief This function initializes a message-digest context without
  8634. * binding it to a particular message-digest algorithm.
  8635. *
  8636. * This function should always be called first. It prepares the
  8637. * context for mbedtls_md_setup() for binding it to a
  8638. * message-digest algorithm.
  8639. */
  8640. void mbedtls_md_init( mbedtls_md_context_t *ctx );
  8641. /**
  8642. * \brief This function clears the internal structure of \p ctx and
  8643. * frees any embedded internal structure, but does not free
  8644. * \p ctx itself.
  8645. *
  8646. * If you have called mbedtls_md_setup() on \p ctx, you must
  8647. * call mbedtls_md_free() when you are no longer using the
  8648. * context.
  8649. * Calling this function if you have previously
  8650. * called mbedtls_md_init() and nothing else is optional.
  8651. * You must not call this function if you have not called
  8652. * mbedtls_md_init().
  8653. */
  8654. void mbedtls_md_free( mbedtls_md_context_t *ctx );
  8655. #if ! defined(MBEDTLS_DEPRECATED_REMOVED)
  8656. #if defined(MBEDTLS_DEPRECATED_WARNING)
  8657. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  8658. #else
  8659. #define MBEDTLS_DEPRECATED
  8660. #endif
  8661. /**
  8662. * \brief This function selects the message digest algorithm to use,
  8663. * and allocates internal structures.
  8664. *
  8665. * It should be called after mbedtls_md_init() or mbedtls_md_free().
  8666. * Makes it necessary to call mbedtls_md_free() later.
  8667. *
  8668. * \deprecated Superseded by mbedtls_md_setup() in 2.0.0
  8669. *
  8670. * \param ctx The context to set up.
  8671. * \param md_info The information structure of the message-digest algorithm
  8672. * to use.
  8673. *
  8674. * \return \c 0 on success.
  8675. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8676. * failure.
  8677. * \return #MBEDTLS_ERR_MD_ALLOC_FAILED on memory-allocation failure.
  8678. */
  8679. int mbedtls_md_init_ctx( mbedtls_md_context_t *ctx, const mbedtls_md_info_t *md_info ) MBEDTLS_DEPRECATED;
  8680. #undef MBEDTLS_DEPRECATED
  8681. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  8682. /**
  8683. * \brief This function selects the message digest algorithm to use,
  8684. * and allocates internal structures.
  8685. *
  8686. * It should be called after mbedtls_md_init() or
  8687. * mbedtls_md_free(). Makes it necessary to call
  8688. * mbedtls_md_free() later.
  8689. *
  8690. * \param ctx The context to set up.
  8691. * \param md_info The information structure of the message-digest algorithm
  8692. * to use.
  8693. * \param hmac Defines if HMAC is used. 0: HMAC is not used (saves some memory),
  8694. * or non-zero: HMAC is used with this context.
  8695. *
  8696. * \return \c 0 on success.
  8697. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8698. * failure.
  8699. * \return #MBEDTLS_ERR_MD_ALLOC_FAILED on memory-allocation failure.
  8700. */
  8701. MBEDTLS_CHECK_RETURN_TYPICAL
  8702. int mbedtls_md_setup( mbedtls_md_context_t *ctx, const mbedtls_md_info_t *md_info, int hmac );
  8703. /**
  8704. * \brief This function clones the state of an message-digest
  8705. * context.
  8706. *
  8707. * \note You must call mbedtls_md_setup() on \c dst before calling
  8708. * this function.
  8709. *
  8710. * \note The two contexts must have the same type,
  8711. * for example, both are SHA-256.
  8712. *
  8713. * \warning This function clones the message-digest state, not the
  8714. * HMAC state.
  8715. *
  8716. * \param dst The destination context.
  8717. * \param src The context to be cloned.
  8718. *
  8719. * \return \c 0 on success.
  8720. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification failure.
  8721. */
  8722. MBEDTLS_CHECK_RETURN_TYPICAL
  8723. int mbedtls_md_clone( mbedtls_md_context_t *dst,
  8724. const mbedtls_md_context_t *src );
  8725. /**
  8726. * \brief This function extracts the message-digest size from the
  8727. * message-digest information structure.
  8728. *
  8729. * \param md_info The information structure of the message-digest algorithm
  8730. * to use.
  8731. *
  8732. * \return The size of the message-digest output in Bytes.
  8733. */
  8734. unsigned char mbedtls_md_get_size( const mbedtls_md_info_t *md_info );
  8735. /**
  8736. * \brief This function extracts the message-digest type from the
  8737. * message-digest information structure.
  8738. *
  8739. * \param md_info The information structure of the message-digest algorithm
  8740. * to use.
  8741. *
  8742. * \return The type of the message digest.
  8743. */
  8744. mbedtls_md_type_t mbedtls_md_get_type( const mbedtls_md_info_t *md_info );
  8745. /**
  8746. * \brief This function extracts the message-digest name from the
  8747. * message-digest information structure.
  8748. *
  8749. * \param md_info The information structure of the message-digest algorithm
  8750. * to use.
  8751. *
  8752. * \return The name of the message digest.
  8753. */
  8754. const char *mbedtls_md_get_name( const mbedtls_md_info_t *md_info );
  8755. /**
  8756. * \brief This function starts a message-digest computation.
  8757. *
  8758. * You must call this function after setting up the context
  8759. * with mbedtls_md_setup(), and before passing data with
  8760. * mbedtls_md_update().
  8761. *
  8762. * \param ctx The generic message-digest context.
  8763. *
  8764. * \return \c 0 on success.
  8765. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8766. * failure.
  8767. */
  8768. MBEDTLS_CHECK_RETURN_TYPICAL
  8769. int mbedtls_md_starts( mbedtls_md_context_t *ctx );
  8770. /**
  8771. * \brief This function feeds an input buffer into an ongoing
  8772. * message-digest computation.
  8773. *
  8774. * You must call mbedtls_md_starts() before calling this
  8775. * function. You may call this function multiple times.
  8776. * Afterwards, call mbedtls_md_finish().
  8777. *
  8778. * \param ctx The generic message-digest context.
  8779. * \param input The buffer holding the input data.
  8780. * \param ilen The length of the input data.
  8781. *
  8782. * \return \c 0 on success.
  8783. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8784. * failure.
  8785. */
  8786. MBEDTLS_CHECK_RETURN_TYPICAL
  8787. int mbedtls_md_update( mbedtls_md_context_t *ctx, const unsigned char *input, size_t ilen );
  8788. /**
  8789. * \brief This function finishes the digest operation,
  8790. * and writes the result to the output buffer.
  8791. *
  8792. * Call this function after a call to mbedtls_md_starts(),
  8793. * followed by any number of calls to mbedtls_md_update().
  8794. * Afterwards, you may either clear the context with
  8795. * mbedtls_md_free(), or call mbedtls_md_starts() to reuse
  8796. * the context for another digest operation with the same
  8797. * algorithm.
  8798. *
  8799. * \param ctx The generic message-digest context.
  8800. * \param output The buffer for the generic message-digest checksum result.
  8801. *
  8802. * \return \c 0 on success.
  8803. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8804. * failure.
  8805. */
  8806. MBEDTLS_CHECK_RETURN_TYPICAL
  8807. int mbedtls_md_finish( mbedtls_md_context_t *ctx, unsigned char *output );
  8808. /**
  8809. * \brief This function calculates the message-digest of a buffer,
  8810. * with respect to a configurable message-digest algorithm
  8811. * in a single call.
  8812. *
  8813. * The result is calculated as
  8814. * Output = message_digest(input buffer).
  8815. *
  8816. * \param md_info The information structure of the message-digest algorithm
  8817. * to use.
  8818. * \param input The buffer holding the data.
  8819. * \param ilen The length of the input data.
  8820. * \param output The generic message-digest checksum result.
  8821. *
  8822. * \return \c 0 on success.
  8823. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8824. * failure.
  8825. */
  8826. MBEDTLS_CHECK_RETURN_TYPICAL
  8827. int mbedtls_md( const mbedtls_md_info_t *md_info, const unsigned char *input, size_t ilen,
  8828. unsigned char *output );
  8829. #if defined(MBEDTLS_FS_IO)
  8830. /**
  8831. * \brief This function calculates the message-digest checksum
  8832. * result of the contents of the provided file.
  8833. *
  8834. * The result is calculated as
  8835. * Output = message_digest(file contents).
  8836. *
  8837. * \param md_info The information structure of the message-digest algorithm
  8838. * to use.
  8839. * \param path The input file name.
  8840. * \param output The generic message-digest checksum result.
  8841. *
  8842. * \return \c 0 on success.
  8843. * \return #MBEDTLS_ERR_MD_FILE_IO_ERROR on an I/O error accessing
  8844. * the file pointed by \p path.
  8845. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA if \p md_info was NULL.
  8846. */
  8847. MBEDTLS_CHECK_RETURN_TYPICAL
  8848. int mbedtls_md_file( const mbedtls_md_info_t *md_info, const char *path,
  8849. unsigned char *output );
  8850. #endif /* MBEDTLS_FS_IO */
  8851. /**
  8852. * \brief This function sets the HMAC key and prepares to
  8853. * authenticate a new message.
  8854. *
  8855. * Call this function after mbedtls_md_setup(), to use
  8856. * the MD context for an HMAC calculation, then call
  8857. * mbedtls_md_hmac_update() to provide the input data, and
  8858. * mbedtls_md_hmac_finish() to get the HMAC value.
  8859. *
  8860. * \param ctx The message digest context containing an embedded HMAC
  8861. * context.
  8862. * \param key The HMAC secret key.
  8863. * \param keylen The length of the HMAC key in Bytes.
  8864. *
  8865. * \return \c 0 on success.
  8866. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8867. * failure.
  8868. */
  8869. MBEDTLS_CHECK_RETURN_TYPICAL
  8870. int mbedtls_md_hmac_starts( mbedtls_md_context_t *ctx, const unsigned char *key,
  8871. size_t keylen );
  8872. /**
  8873. * \brief This function feeds an input buffer into an ongoing HMAC
  8874. * computation.
  8875. *
  8876. * Call mbedtls_md_hmac_starts() or mbedtls_md_hmac_reset()
  8877. * before calling this function.
  8878. * You may call this function multiple times to pass the
  8879. * input piecewise.
  8880. * Afterwards, call mbedtls_md_hmac_finish().
  8881. *
  8882. * \param ctx The message digest context containing an embedded HMAC
  8883. * context.
  8884. * \param input The buffer holding the input data.
  8885. * \param ilen The length of the input data.
  8886. *
  8887. * \return \c 0 on success.
  8888. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8889. * failure.
  8890. */
  8891. MBEDTLS_CHECK_RETURN_TYPICAL
  8892. int mbedtls_md_hmac_update( mbedtls_md_context_t *ctx, const unsigned char *input,
  8893. size_t ilen );
  8894. /**
  8895. * \brief This function finishes the HMAC operation, and writes
  8896. * the result to the output buffer.
  8897. *
  8898. * Call this function after mbedtls_md_hmac_starts() and
  8899. * mbedtls_md_hmac_update() to get the HMAC value. Afterwards
  8900. * you may either call mbedtls_md_free() to clear the context,
  8901. * or call mbedtls_md_hmac_reset() to reuse the context with
  8902. * the same HMAC key.
  8903. *
  8904. * \param ctx The message digest context containing an embedded HMAC
  8905. * context.
  8906. * \param output The generic HMAC checksum result.
  8907. *
  8908. * \return \c 0 on success.
  8909. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8910. * failure.
  8911. */
  8912. MBEDTLS_CHECK_RETURN_TYPICAL
  8913. int mbedtls_md_hmac_finish( mbedtls_md_context_t *ctx, unsigned char *output);
  8914. /**
  8915. * \brief This function prepares to authenticate a new message with
  8916. * the same key as the previous HMAC operation.
  8917. *
  8918. * You may call this function after mbedtls_md_hmac_finish().
  8919. * Afterwards call mbedtls_md_hmac_update() to pass the new
  8920. * input.
  8921. *
  8922. * \param ctx The message digest context containing an embedded HMAC
  8923. * context.
  8924. *
  8925. * \return \c 0 on success.
  8926. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8927. * failure.
  8928. */
  8929. MBEDTLS_CHECK_RETURN_TYPICAL
  8930. int mbedtls_md_hmac_reset( mbedtls_md_context_t *ctx );
  8931. /**
  8932. * \brief This function calculates the full generic HMAC
  8933. * on the input buffer with the provided key.
  8934. *
  8935. * The function allocates the context, performs the
  8936. * calculation, and frees the context.
  8937. *
  8938. * The HMAC result is calculated as
  8939. * output = generic HMAC(hmac key, input buffer).
  8940. *
  8941. * \param md_info The information structure of the message-digest algorithm
  8942. * to use.
  8943. * \param key The HMAC secret key.
  8944. * \param keylen The length of the HMAC secret key in Bytes.
  8945. * \param input The buffer holding the input data.
  8946. * \param ilen The length of the input data.
  8947. * \param output The generic HMAC result.
  8948. *
  8949. * \return \c 0 on success.
  8950. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA on parameter-verification
  8951. * failure.
  8952. */
  8953. MBEDTLS_CHECK_RETURN_TYPICAL
  8954. int mbedtls_md_hmac( const mbedtls_md_info_t *md_info, const unsigned char *key, size_t keylen,
  8955. const unsigned char *input, size_t ilen,
  8956. unsigned char *output );
  8957. /* Internal use */
  8958. MBEDTLS_CHECK_RETURN_TYPICAL
  8959. int mbedtls_md_process( mbedtls_md_context_t *ctx, const unsigned char *data );
  8960. #ifdef __cplusplus
  8961. }
  8962. #endif
  8963. #endif /* MBEDTLS_MD_H */
  8964. /********* Start of file include/mbedtls/md_internal.h ************/
  8965. /**
  8966. * \file md_internal.h
  8967. *
  8968. * \brief Message digest wrappers.
  8969. *
  8970. * \warning This in an internal header. Do not include directly.
  8971. *
  8972. * \author Adriaan de Jong <dejong@fox-it.com>
  8973. */
  8974. /*
  8975. * Copyright The Mbed TLS Contributors
  8976. * SPDX-License-Identifier: Apache-2.0
  8977. *
  8978. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  8979. * not use this file except in compliance with the License.
  8980. * You may obtain a copy of the License at
  8981. *
  8982. * http://www.apache.org/licenses/LICENSE-2.0
  8983. *
  8984. * Unless required by applicable law or agreed to in writing, software
  8985. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  8986. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  8987. * See the License for the specific language governing permissions and
  8988. * limitations under the License.
  8989. */
  8990. #ifndef MBEDTLS_MD_WRAP_H
  8991. #define MBEDTLS_MD_WRAP_H
  8992. #if !defined(MBEDTLS_CONFIG_FILE)
  8993. #else
  8994. #endif
  8995. #ifdef __cplusplus
  8996. extern "C" {
  8997. #endif
  8998. /**
  8999. * Message digest information.
  9000. * Allows message digest functions to be called in a generic way.
  9001. */
  9002. struct mbedtls_md_info_t
  9003. {
  9004. /** Name of the message digest */
  9005. const char * name;
  9006. /** Digest identifier */
  9007. mbedtls_md_type_t type;
  9008. /** Output length of the digest function in bytes */
  9009. unsigned char size;
  9010. /** Block length of the digest function in bytes */
  9011. unsigned char block_size;
  9012. };
  9013. #if defined(MBEDTLS_MD2_C)
  9014. extern const mbedtls_md_info_t mbedtls_md2_info;
  9015. #endif
  9016. #if defined(MBEDTLS_MD4_C)
  9017. extern const mbedtls_md_info_t mbedtls_md4_info;
  9018. #endif
  9019. #if defined(MBEDTLS_MD5_C)
  9020. extern const mbedtls_md_info_t mbedtls_md5_info;
  9021. #endif
  9022. #if defined(MBEDTLS_RIPEMD160_C)
  9023. extern const mbedtls_md_info_t mbedtls_ripemd160_info;
  9024. #endif
  9025. #if defined(MBEDTLS_SHA1_C)
  9026. extern const mbedtls_md_info_t mbedtls_sha1_info;
  9027. #endif
  9028. #if defined(MBEDTLS_SHA256_C)
  9029. extern const mbedtls_md_info_t mbedtls_sha224_info;
  9030. extern const mbedtls_md_info_t mbedtls_sha256_info;
  9031. #endif
  9032. #if defined(MBEDTLS_SHA512_C)
  9033. #if !defined(MBEDTLS_SHA512_NO_SHA384)
  9034. extern const mbedtls_md_info_t mbedtls_sha384_info;
  9035. #endif
  9036. extern const mbedtls_md_info_t mbedtls_sha512_info;
  9037. #endif
  9038. #ifdef __cplusplus
  9039. }
  9040. #endif
  9041. #endif /* MBEDTLS_MD_WRAP_H */
  9042. /********* Start of file include/mbedtls/md5.h ************/
  9043. /**
  9044. * \file md5.h
  9045. *
  9046. * \brief MD5 message digest algorithm (hash function)
  9047. *
  9048. * \warning MD5 is considered a weak message digest and its use constitutes a
  9049. * security risk. We recommend considering stronger message
  9050. * digests instead.
  9051. */
  9052. /*
  9053. * Copyright The Mbed TLS Contributors
  9054. * SPDX-License-Identifier: Apache-2.0
  9055. *
  9056. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  9057. * not use this file except in compliance with the License.
  9058. * You may obtain a copy of the License at
  9059. *
  9060. * http://www.apache.org/licenses/LICENSE-2.0
  9061. *
  9062. * Unless required by applicable law or agreed to in writing, software
  9063. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  9064. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  9065. * See the License for the specific language governing permissions and
  9066. * limitations under the License.
  9067. */
  9068. #ifndef MBEDTLS_MD5_H
  9069. #define MBEDTLS_MD5_H
  9070. #if !defined(MBEDTLS_CONFIG_FILE)
  9071. #else
  9072. #endif
  9073. #include <stddef.h>
  9074. #include <stdint.h>
  9075. /* MBEDTLS_ERR_MD5_HW_ACCEL_FAILED is deprecated and should not be used. */
  9076. /** MD5 hardware accelerator failed */
  9077. #define MBEDTLS_ERR_MD5_HW_ACCEL_FAILED -0x002F
  9078. #ifdef __cplusplus
  9079. extern "C" {
  9080. #endif
  9081. #if !defined(MBEDTLS_MD5_ALT)
  9082. // Regular implementation
  9083. //
  9084. /**
  9085. * \brief MD5 context structure
  9086. *
  9087. * \warning MD5 is considered a weak message digest and its use
  9088. * constitutes a security risk. We recommend considering
  9089. * stronger message digests instead.
  9090. *
  9091. */
  9092. typedef struct mbedtls_md5_context
  9093. {
  9094. uint32_t total[2]; /*!< number of bytes processed */
  9095. uint32_t state[4]; /*!< intermediate digest state */
  9096. unsigned char buffer[64]; /*!< data block being processed */
  9097. }
  9098. mbedtls_md5_context;
  9099. #else /* MBEDTLS_MD5_ALT */
  9100. #endif /* MBEDTLS_MD5_ALT */
  9101. /**
  9102. * \brief Initialize MD5 context
  9103. *
  9104. * \param ctx MD5 context to be initialized
  9105. *
  9106. * \warning MD5 is considered a weak message digest and its use
  9107. * constitutes a security risk. We recommend considering
  9108. * stronger message digests instead.
  9109. *
  9110. */
  9111. void mbedtls_md5_init( mbedtls_md5_context *ctx );
  9112. /**
  9113. * \brief Clear MD5 context
  9114. *
  9115. * \param ctx MD5 context to be cleared
  9116. *
  9117. * \warning MD5 is considered a weak message digest and its use
  9118. * constitutes a security risk. We recommend considering
  9119. * stronger message digests instead.
  9120. *
  9121. */
  9122. void mbedtls_md5_free( mbedtls_md5_context *ctx );
  9123. /**
  9124. * \brief Clone (the state of) an MD5 context
  9125. *
  9126. * \param dst The destination context
  9127. * \param src The context to be cloned
  9128. *
  9129. * \warning MD5 is considered a weak message digest and its use
  9130. * constitutes a security risk. We recommend considering
  9131. * stronger message digests instead.
  9132. *
  9133. */
  9134. void mbedtls_md5_clone( mbedtls_md5_context *dst,
  9135. const mbedtls_md5_context *src );
  9136. /**
  9137. * \brief MD5 context setup
  9138. *
  9139. * \param ctx context to be initialized
  9140. *
  9141. * \return 0 if successful
  9142. *
  9143. * \warning MD5 is considered a weak message digest and its use
  9144. * constitutes a security risk. We recommend considering
  9145. * stronger message digests instead.
  9146. *
  9147. */
  9148. int mbedtls_md5_starts_ret( mbedtls_md5_context *ctx );
  9149. /**
  9150. * \brief MD5 process buffer
  9151. *
  9152. * \param ctx MD5 context
  9153. * \param input buffer holding the data
  9154. * \param ilen length of the input data
  9155. *
  9156. * \return 0 if successful
  9157. *
  9158. * \warning MD5 is considered a weak message digest and its use
  9159. * constitutes a security risk. We recommend considering
  9160. * stronger message digests instead.
  9161. *
  9162. */
  9163. int mbedtls_md5_update_ret( mbedtls_md5_context *ctx,
  9164. const unsigned char *input,
  9165. size_t ilen );
  9166. /**
  9167. * \brief MD5 final digest
  9168. *
  9169. * \param ctx MD5 context
  9170. * \param output MD5 checksum result
  9171. *
  9172. * \return 0 if successful
  9173. *
  9174. * \warning MD5 is considered a weak message digest and its use
  9175. * constitutes a security risk. We recommend considering
  9176. * stronger message digests instead.
  9177. *
  9178. */
  9179. int mbedtls_md5_finish_ret( mbedtls_md5_context *ctx,
  9180. unsigned char output[16] );
  9181. /**
  9182. * \brief MD5 process data block (internal use only)
  9183. *
  9184. * \param ctx MD5 context
  9185. * \param data buffer holding one block of data
  9186. *
  9187. * \return 0 if successful
  9188. *
  9189. * \warning MD5 is considered a weak message digest and its use
  9190. * constitutes a security risk. We recommend considering
  9191. * stronger message digests instead.
  9192. *
  9193. */
  9194. int mbedtls_internal_md5_process( mbedtls_md5_context *ctx,
  9195. const unsigned char data[64] );
  9196. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  9197. #if defined(MBEDTLS_DEPRECATED_WARNING)
  9198. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  9199. #else
  9200. #define MBEDTLS_DEPRECATED
  9201. #endif
  9202. /**
  9203. * \brief MD5 context setup
  9204. *
  9205. * \deprecated Superseded by mbedtls_md5_starts_ret() in 2.7.0
  9206. *
  9207. * \param ctx context to be initialized
  9208. *
  9209. * \warning MD5 is considered a weak message digest and its use
  9210. * constitutes a security risk. We recommend considering
  9211. * stronger message digests instead.
  9212. *
  9213. */
  9214. MBEDTLS_DEPRECATED void mbedtls_md5_starts( mbedtls_md5_context *ctx );
  9215. /**
  9216. * \brief MD5 process buffer
  9217. *
  9218. * \deprecated Superseded by mbedtls_md5_update_ret() in 2.7.0
  9219. *
  9220. * \param ctx MD5 context
  9221. * \param input buffer holding the data
  9222. * \param ilen length of the input data
  9223. *
  9224. * \warning MD5 is considered a weak message digest and its use
  9225. * constitutes a security risk. We recommend considering
  9226. * stronger message digests instead.
  9227. *
  9228. */
  9229. MBEDTLS_DEPRECATED void mbedtls_md5_update( mbedtls_md5_context *ctx,
  9230. const unsigned char *input,
  9231. size_t ilen );
  9232. /**
  9233. * \brief MD5 final digest
  9234. *
  9235. * \deprecated Superseded by mbedtls_md5_finish_ret() in 2.7.0
  9236. *
  9237. * \param ctx MD5 context
  9238. * \param output MD5 checksum result
  9239. *
  9240. * \warning MD5 is considered a weak message digest and its use
  9241. * constitutes a security risk. We recommend considering
  9242. * stronger message digests instead.
  9243. *
  9244. */
  9245. MBEDTLS_DEPRECATED void mbedtls_md5_finish( mbedtls_md5_context *ctx,
  9246. unsigned char output[16] );
  9247. /**
  9248. * \brief MD5 process data block (internal use only)
  9249. *
  9250. * \deprecated Superseded by mbedtls_internal_md5_process() in 2.7.0
  9251. *
  9252. * \param ctx MD5 context
  9253. * \param data buffer holding one block of data
  9254. *
  9255. * \warning MD5 is considered a weak message digest and its use
  9256. * constitutes a security risk. We recommend considering
  9257. * stronger message digests instead.
  9258. *
  9259. */
  9260. MBEDTLS_DEPRECATED void mbedtls_md5_process( mbedtls_md5_context *ctx,
  9261. const unsigned char data[64] );
  9262. #undef MBEDTLS_DEPRECATED
  9263. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  9264. /**
  9265. * \brief Output = MD5( input buffer )
  9266. *
  9267. * \param input buffer holding the data
  9268. * \param ilen length of the input data
  9269. * \param output MD5 checksum result
  9270. *
  9271. * \return 0 if successful
  9272. *
  9273. * \warning MD5 is considered a weak message digest and its use
  9274. * constitutes a security risk. We recommend considering
  9275. * stronger message digests instead.
  9276. *
  9277. */
  9278. int mbedtls_md5_ret( const unsigned char *input,
  9279. size_t ilen,
  9280. unsigned char output[16] );
  9281. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  9282. #if defined(MBEDTLS_DEPRECATED_WARNING)
  9283. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  9284. #else
  9285. #define MBEDTLS_DEPRECATED
  9286. #endif
  9287. /**
  9288. * \brief Output = MD5( input buffer )
  9289. *
  9290. * \deprecated Superseded by mbedtls_md5_ret() in 2.7.0
  9291. *
  9292. * \param input buffer holding the data
  9293. * \param ilen length of the input data
  9294. * \param output MD5 checksum result
  9295. *
  9296. * \warning MD5 is considered a weak message digest and its use
  9297. * constitutes a security risk. We recommend considering
  9298. * stronger message digests instead.
  9299. *
  9300. */
  9301. MBEDTLS_DEPRECATED void mbedtls_md5( const unsigned char *input,
  9302. size_t ilen,
  9303. unsigned char output[16] );
  9304. #undef MBEDTLS_DEPRECATED
  9305. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  9306. #if defined(MBEDTLS_SELF_TEST)
  9307. /**
  9308. * \brief Checkup routine
  9309. *
  9310. * \return 0 if successful, or 1 if the test failed
  9311. *
  9312. * \warning MD5 is considered a weak message digest and its use
  9313. * constitutes a security risk. We recommend considering
  9314. * stronger message digests instead.
  9315. *
  9316. */
  9317. int mbedtls_md5_self_test( int verbose );
  9318. #endif /* MBEDTLS_SELF_TEST */
  9319. #ifdef __cplusplus
  9320. }
  9321. #endif
  9322. #endif /* mbedtls_md5.h */
  9323. /********* Start of file include/mbedtls/md2.h ************/
  9324. /**
  9325. * \file md2.h
  9326. *
  9327. * \brief MD2 message digest algorithm (hash function)
  9328. *
  9329. * \warning MD2 is considered a weak message digest and its use constitutes a
  9330. * security risk. We recommend considering stronger message digests
  9331. * instead.
  9332. */
  9333. /*
  9334. * Copyright The Mbed TLS Contributors
  9335. * SPDX-License-Identifier: Apache-2.0
  9336. *
  9337. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  9338. * not use this file except in compliance with the License.
  9339. * You may obtain a copy of the License at
  9340. *
  9341. * http://www.apache.org/licenses/LICENSE-2.0
  9342. *
  9343. * Unless required by applicable law or agreed to in writing, software
  9344. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  9345. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  9346. * See the License for the specific language governing permissions and
  9347. * limitations under the License.
  9348. *
  9349. */
  9350. #ifndef MBEDTLS_MD2_H
  9351. #define MBEDTLS_MD2_H
  9352. #if !defined(MBEDTLS_CONFIG_FILE)
  9353. #else
  9354. #endif
  9355. #include <stddef.h>
  9356. /* MBEDTLS_ERR_MD2_HW_ACCEL_FAILED is deprecated and should not be used. */
  9357. /** MD2 hardware accelerator failed */
  9358. #define MBEDTLS_ERR_MD2_HW_ACCEL_FAILED -0x002B
  9359. #ifdef __cplusplus
  9360. extern "C" {
  9361. #endif
  9362. #if !defined(MBEDTLS_MD2_ALT)
  9363. // Regular implementation
  9364. //
  9365. /**
  9366. * \brief MD2 context structure
  9367. *
  9368. * \warning MD2 is considered a weak message digest and its use
  9369. * constitutes a security risk. We recommend considering
  9370. * stronger message digests instead.
  9371. *
  9372. */
  9373. typedef struct mbedtls_md2_context
  9374. {
  9375. unsigned char cksum[16]; /*!< checksum of the data block */
  9376. unsigned char state[48]; /*!< intermediate digest state */
  9377. unsigned char buffer[16]; /*!< data block being processed */
  9378. size_t left; /*!< amount of data in buffer */
  9379. }
  9380. mbedtls_md2_context;
  9381. #else /* MBEDTLS_MD2_ALT */
  9382. #endif /* MBEDTLS_MD2_ALT */
  9383. /**
  9384. * \brief Initialize MD2 context
  9385. *
  9386. * \param ctx MD2 context to be initialized
  9387. *
  9388. * \warning MD2 is considered a weak message digest and its use
  9389. * constitutes a security risk. We recommend considering
  9390. * stronger message digests instead.
  9391. *
  9392. */
  9393. void mbedtls_md2_init( mbedtls_md2_context *ctx );
  9394. /**
  9395. * \brief Clear MD2 context
  9396. *
  9397. * \param ctx MD2 context to be cleared
  9398. *
  9399. * \warning MD2 is considered a weak message digest and its use
  9400. * constitutes a security risk. We recommend considering
  9401. * stronger message digests instead.
  9402. *
  9403. */
  9404. void mbedtls_md2_free( mbedtls_md2_context *ctx );
  9405. /**
  9406. * \brief Clone (the state of) an MD2 context
  9407. *
  9408. * \param dst The destination context
  9409. * \param src The context to be cloned
  9410. *
  9411. * \warning MD2 is considered a weak message digest and its use
  9412. * constitutes a security risk. We recommend considering
  9413. * stronger message digests instead.
  9414. *
  9415. */
  9416. void mbedtls_md2_clone( mbedtls_md2_context *dst,
  9417. const mbedtls_md2_context *src );
  9418. /**
  9419. * \brief MD2 context setup
  9420. *
  9421. * \param ctx context to be initialized
  9422. *
  9423. * \return 0 if successful
  9424. *
  9425. * \warning MD2 is considered a weak message digest and its use
  9426. * constitutes a security risk. We recommend considering
  9427. * stronger message digests instead.
  9428. *
  9429. */
  9430. int mbedtls_md2_starts_ret( mbedtls_md2_context *ctx );
  9431. /**
  9432. * \brief MD2 process buffer
  9433. *
  9434. * \param ctx MD2 context
  9435. * \param input buffer holding the data
  9436. * \param ilen length of the input data
  9437. *
  9438. * \return 0 if successful
  9439. *
  9440. * \warning MD2 is considered a weak message digest and its use
  9441. * constitutes a security risk. We recommend considering
  9442. * stronger message digests instead.
  9443. *
  9444. */
  9445. int mbedtls_md2_update_ret( mbedtls_md2_context *ctx,
  9446. const unsigned char *input,
  9447. size_t ilen );
  9448. /**
  9449. * \brief MD2 final digest
  9450. *
  9451. * \param ctx MD2 context
  9452. * \param output MD2 checksum result
  9453. *
  9454. * \return 0 if successful
  9455. *
  9456. * \warning MD2 is considered a weak message digest and its use
  9457. * constitutes a security risk. We recommend considering
  9458. * stronger message digests instead.
  9459. *
  9460. */
  9461. int mbedtls_md2_finish_ret( mbedtls_md2_context *ctx,
  9462. unsigned char output[16] );
  9463. /**
  9464. * \brief MD2 process data block (internal use only)
  9465. *
  9466. * \param ctx MD2 context
  9467. *
  9468. * \return 0 if successful
  9469. *
  9470. * \warning MD2 is considered a weak message digest and its use
  9471. * constitutes a security risk. We recommend considering
  9472. * stronger message digests instead.
  9473. *
  9474. */
  9475. int mbedtls_internal_md2_process( mbedtls_md2_context *ctx );
  9476. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  9477. #if defined(MBEDTLS_DEPRECATED_WARNING)
  9478. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  9479. #else
  9480. #define MBEDTLS_DEPRECATED
  9481. #endif
  9482. /**
  9483. * \brief MD2 context setup
  9484. *
  9485. * \deprecated Superseded by mbedtls_md2_starts_ret() in 2.7.0
  9486. *
  9487. * \param ctx context to be initialized
  9488. *
  9489. * \warning MD2 is considered a weak message digest and its use
  9490. * constitutes a security risk. We recommend considering
  9491. * stronger message digests instead.
  9492. *
  9493. */
  9494. MBEDTLS_DEPRECATED void mbedtls_md2_starts( mbedtls_md2_context *ctx );
  9495. /**
  9496. * \brief MD2 process buffer
  9497. *
  9498. * \deprecated Superseded by mbedtls_md2_update_ret() in 2.7.0
  9499. *
  9500. * \param ctx MD2 context
  9501. * \param input buffer holding the data
  9502. * \param ilen length of the input data
  9503. *
  9504. * \warning MD2 is considered a weak message digest and its use
  9505. * constitutes a security risk. We recommend considering
  9506. * stronger message digests instead.
  9507. *
  9508. */
  9509. MBEDTLS_DEPRECATED void mbedtls_md2_update( mbedtls_md2_context *ctx,
  9510. const unsigned char *input,
  9511. size_t ilen );
  9512. /**
  9513. * \brief MD2 final digest
  9514. *
  9515. * \deprecated Superseded by mbedtls_md2_finish_ret() in 2.7.0
  9516. *
  9517. * \param ctx MD2 context
  9518. * \param output MD2 checksum result
  9519. *
  9520. * \warning MD2 is considered a weak message digest and its use
  9521. * constitutes a security risk. We recommend considering
  9522. * stronger message digests instead.
  9523. *
  9524. */
  9525. MBEDTLS_DEPRECATED void mbedtls_md2_finish( mbedtls_md2_context *ctx,
  9526. unsigned char output[16] );
  9527. /**
  9528. * \brief MD2 process data block (internal use only)
  9529. *
  9530. * \deprecated Superseded by mbedtls_internal_md2_process() in 2.7.0
  9531. *
  9532. * \param ctx MD2 context
  9533. *
  9534. * \warning MD2 is considered a weak message digest and its use
  9535. * constitutes a security risk. We recommend considering
  9536. * stronger message digests instead.
  9537. *
  9538. */
  9539. MBEDTLS_DEPRECATED void mbedtls_md2_process( mbedtls_md2_context *ctx );
  9540. #undef MBEDTLS_DEPRECATED
  9541. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  9542. /**
  9543. * \brief Output = MD2( input buffer )
  9544. *
  9545. * \param input buffer holding the data
  9546. * \param ilen length of the input data
  9547. * \param output MD2 checksum result
  9548. *
  9549. * \warning MD2 is considered a weak message digest and its use
  9550. * constitutes a security risk. We recommend considering
  9551. * stronger message digests instead.
  9552. *
  9553. */
  9554. int mbedtls_md2_ret( const unsigned char *input,
  9555. size_t ilen,
  9556. unsigned char output[16] );
  9557. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  9558. #if defined(MBEDTLS_DEPRECATED_WARNING)
  9559. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  9560. #else
  9561. #define MBEDTLS_DEPRECATED
  9562. #endif
  9563. /**
  9564. * \brief Output = MD2( input buffer )
  9565. *
  9566. * \deprecated Superseded by mbedtls_md2_ret() in 2.7.0
  9567. *
  9568. * \param input buffer holding the data
  9569. * \param ilen length of the input data
  9570. * \param output MD2 checksum result
  9571. *
  9572. * \warning MD2 is considered a weak message digest and its use
  9573. * constitutes a security risk. We recommend considering
  9574. * stronger message digests instead.
  9575. *
  9576. */
  9577. MBEDTLS_DEPRECATED void mbedtls_md2( const unsigned char *input,
  9578. size_t ilen,
  9579. unsigned char output[16] );
  9580. #undef MBEDTLS_DEPRECATED
  9581. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  9582. #if defined(MBEDTLS_SELF_TEST)
  9583. /**
  9584. * \brief Checkup routine
  9585. *
  9586. * \return 0 if successful, or 1 if the test failed
  9587. *
  9588. * \warning MD2 is considered a weak message digest and its use
  9589. * constitutes a security risk. We recommend considering
  9590. * stronger message digests instead.
  9591. *
  9592. */
  9593. int mbedtls_md2_self_test( int verbose );
  9594. #endif /* MBEDTLS_SELF_TEST */
  9595. #ifdef __cplusplus
  9596. }
  9597. #endif
  9598. #endif /* mbedtls_md2.h */
  9599. /********* Start of file include/mbedtls/md4.h ************/
  9600. /**
  9601. * \file md4.h
  9602. *
  9603. * \brief MD4 message digest algorithm (hash function)
  9604. *
  9605. * \warning MD4 is considered a weak message digest and its use constitutes a
  9606. * security risk. We recommend considering stronger message digests
  9607. * instead.
  9608. */
  9609. /*
  9610. * Copyright The Mbed TLS Contributors
  9611. * SPDX-License-Identifier: Apache-2.0
  9612. *
  9613. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  9614. * not use this file except in compliance with the License.
  9615. * You may obtain a copy of the License at
  9616. *
  9617. * http://www.apache.org/licenses/LICENSE-2.0
  9618. *
  9619. * Unless required by applicable law or agreed to in writing, software
  9620. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  9621. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  9622. * See the License for the specific language governing permissions and
  9623. * limitations under the License.
  9624. *
  9625. */
  9626. #ifndef MBEDTLS_MD4_H
  9627. #define MBEDTLS_MD4_H
  9628. #if !defined(MBEDTLS_CONFIG_FILE)
  9629. #else
  9630. #endif
  9631. #include <stddef.h>
  9632. #include <stdint.h>
  9633. /* MBEDTLS_ERR_MD4_HW_ACCEL_FAILED is deprecated and should not be used. */
  9634. /** MD4 hardware accelerator failed */
  9635. #define MBEDTLS_ERR_MD4_HW_ACCEL_FAILED -0x002D
  9636. #ifdef __cplusplus
  9637. extern "C" {
  9638. #endif
  9639. #if !defined(MBEDTLS_MD4_ALT)
  9640. // Regular implementation
  9641. //
  9642. /**
  9643. * \brief MD4 context structure
  9644. *
  9645. * \warning MD4 is considered a weak message digest and its use
  9646. * constitutes a security risk. We recommend considering
  9647. * stronger message digests instead.
  9648. *
  9649. */
  9650. typedef struct mbedtls_md4_context
  9651. {
  9652. uint32_t total[2]; /*!< number of bytes processed */
  9653. uint32_t state[4]; /*!< intermediate digest state */
  9654. unsigned char buffer[64]; /*!< data block being processed */
  9655. }
  9656. mbedtls_md4_context;
  9657. #else /* MBEDTLS_MD4_ALT */
  9658. #endif /* MBEDTLS_MD4_ALT */
  9659. /**
  9660. * \brief Initialize MD4 context
  9661. *
  9662. * \param ctx MD4 context to be initialized
  9663. *
  9664. * \warning MD4 is considered a weak message digest and its use
  9665. * constitutes a security risk. We recommend considering
  9666. * stronger message digests instead.
  9667. *
  9668. */
  9669. void mbedtls_md4_init( mbedtls_md4_context *ctx );
  9670. /**
  9671. * \brief Clear MD4 context
  9672. *
  9673. * \param ctx MD4 context to be cleared
  9674. *
  9675. * \warning MD4 is considered a weak message digest and its use
  9676. * constitutes a security risk. We recommend considering
  9677. * stronger message digests instead.
  9678. *
  9679. */
  9680. void mbedtls_md4_free( mbedtls_md4_context *ctx );
  9681. /**
  9682. * \brief Clone (the state of) an MD4 context
  9683. *
  9684. * \param dst The destination context
  9685. * \param src The context to be cloned
  9686. *
  9687. * \warning MD4 is considered a weak message digest and its use
  9688. * constitutes a security risk. We recommend considering
  9689. * stronger message digests instead.
  9690. *
  9691. */
  9692. void mbedtls_md4_clone( mbedtls_md4_context *dst,
  9693. const mbedtls_md4_context *src );
  9694. /**
  9695. * \brief MD4 context setup
  9696. *
  9697. * \param ctx context to be initialized
  9698. *
  9699. * \return 0 if successful
  9700. *
  9701. * \warning MD4 is considered a weak message digest and its use
  9702. * constitutes a security risk. We recommend considering
  9703. * stronger message digests instead.
  9704. */
  9705. int mbedtls_md4_starts_ret( mbedtls_md4_context *ctx );
  9706. /**
  9707. * \brief MD4 process buffer
  9708. *
  9709. * \param ctx MD4 context
  9710. * \param input buffer holding the data
  9711. * \param ilen length of the input data
  9712. *
  9713. * \return 0 if successful
  9714. *
  9715. * \warning MD4 is considered a weak message digest and its use
  9716. * constitutes a security risk. We recommend considering
  9717. * stronger message digests instead.
  9718. *
  9719. */
  9720. int mbedtls_md4_update_ret( mbedtls_md4_context *ctx,
  9721. const unsigned char *input,
  9722. size_t ilen );
  9723. /**
  9724. * \brief MD4 final digest
  9725. *
  9726. * \param ctx MD4 context
  9727. * \param output MD4 checksum result
  9728. *
  9729. * \return 0 if successful
  9730. *
  9731. * \warning MD4 is considered a weak message digest and its use
  9732. * constitutes a security risk. We recommend considering
  9733. * stronger message digests instead.
  9734. *
  9735. */
  9736. int mbedtls_md4_finish_ret( mbedtls_md4_context *ctx,
  9737. unsigned char output[16] );
  9738. /**
  9739. * \brief MD4 process data block (internal use only)
  9740. *
  9741. * \param ctx MD4 context
  9742. * \param data buffer holding one block of data
  9743. *
  9744. * \return 0 if successful
  9745. *
  9746. * \warning MD4 is considered a weak message digest and its use
  9747. * constitutes a security risk. We recommend considering
  9748. * stronger message digests instead.
  9749. *
  9750. */
  9751. int mbedtls_internal_md4_process( mbedtls_md4_context *ctx,
  9752. const unsigned char data[64] );
  9753. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  9754. #if defined(MBEDTLS_DEPRECATED_WARNING)
  9755. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  9756. #else
  9757. #define MBEDTLS_DEPRECATED
  9758. #endif
  9759. /**
  9760. * \brief MD4 context setup
  9761. *
  9762. * \deprecated Superseded by mbedtls_md4_starts_ret() in 2.7.0
  9763. *
  9764. * \param ctx context to be initialized
  9765. *
  9766. * \warning MD4 is considered a weak message digest and its use
  9767. * constitutes a security risk. We recommend considering
  9768. * stronger message digests instead.
  9769. *
  9770. */
  9771. MBEDTLS_DEPRECATED void mbedtls_md4_starts( mbedtls_md4_context *ctx );
  9772. /**
  9773. * \brief MD4 process buffer
  9774. *
  9775. * \deprecated Superseded by mbedtls_md4_update_ret() in 2.7.0
  9776. *
  9777. * \param ctx MD4 context
  9778. * \param input buffer holding the data
  9779. * \param ilen length of the input data
  9780. *
  9781. * \warning MD4 is considered a weak message digest and its use
  9782. * constitutes a security risk. We recommend considering
  9783. * stronger message digests instead.
  9784. *
  9785. */
  9786. MBEDTLS_DEPRECATED void mbedtls_md4_update( mbedtls_md4_context *ctx,
  9787. const unsigned char *input,
  9788. size_t ilen );
  9789. /**
  9790. * \brief MD4 final digest
  9791. *
  9792. * \deprecated Superseded by mbedtls_md4_finish_ret() in 2.7.0
  9793. *
  9794. * \param ctx MD4 context
  9795. * \param output MD4 checksum result
  9796. *
  9797. * \warning MD4 is considered a weak message digest and its use
  9798. * constitutes a security risk. We recommend considering
  9799. * stronger message digests instead.
  9800. *
  9801. */
  9802. MBEDTLS_DEPRECATED void mbedtls_md4_finish( mbedtls_md4_context *ctx,
  9803. unsigned char output[16] );
  9804. /**
  9805. * \brief MD4 process data block (internal use only)
  9806. *
  9807. * \deprecated Superseded by mbedtls_internal_md4_process() in 2.7.0
  9808. *
  9809. * \param ctx MD4 context
  9810. * \param data buffer holding one block of data
  9811. *
  9812. * \warning MD4 is considered a weak message digest and its use
  9813. * constitutes a security risk. We recommend considering
  9814. * stronger message digests instead.
  9815. *
  9816. */
  9817. MBEDTLS_DEPRECATED void mbedtls_md4_process( mbedtls_md4_context *ctx,
  9818. const unsigned char data[64] );
  9819. #undef MBEDTLS_DEPRECATED
  9820. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  9821. /**
  9822. * \brief Output = MD4( input buffer )
  9823. *
  9824. * \param input buffer holding the data
  9825. * \param ilen length of the input data
  9826. * \param output MD4 checksum result
  9827. *
  9828. * \return 0 if successful
  9829. *
  9830. * \warning MD4 is considered a weak message digest and its use
  9831. * constitutes a security risk. We recommend considering
  9832. * stronger message digests instead.
  9833. *
  9834. */
  9835. int mbedtls_md4_ret( const unsigned char *input,
  9836. size_t ilen,
  9837. unsigned char output[16] );
  9838. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  9839. #if defined(MBEDTLS_DEPRECATED_WARNING)
  9840. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  9841. #else
  9842. #define MBEDTLS_DEPRECATED
  9843. #endif
  9844. /**
  9845. * \brief Output = MD4( input buffer )
  9846. *
  9847. * \deprecated Superseded by mbedtls_md4_ret() in 2.7.0
  9848. *
  9849. * \param input buffer holding the data
  9850. * \param ilen length of the input data
  9851. * \param output MD4 checksum result
  9852. *
  9853. * \warning MD4 is considered a weak message digest and its use
  9854. * constitutes a security risk. We recommend considering
  9855. * stronger message digests instead.
  9856. *
  9857. */
  9858. MBEDTLS_DEPRECATED void mbedtls_md4( const unsigned char *input,
  9859. size_t ilen,
  9860. unsigned char output[16] );
  9861. #undef MBEDTLS_DEPRECATED
  9862. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  9863. #if defined(MBEDTLS_SELF_TEST)
  9864. /**
  9865. * \brief Checkup routine
  9866. *
  9867. * \return 0 if successful, or 1 if the test failed
  9868. *
  9869. * \warning MD4 is considered a weak message digest and its use
  9870. * constitutes a security risk. We recommend considering
  9871. * stronger message digests instead.
  9872. *
  9873. */
  9874. int mbedtls_md4_self_test( int verbose );
  9875. #endif /* MBEDTLS_SELF_TEST */
  9876. #ifdef __cplusplus
  9877. }
  9878. #endif
  9879. #endif /* mbedtls_md4.h */
  9880. /********* Start of file include/mbedtls/rsa.h ************/
  9881. /**
  9882. * \file rsa.h
  9883. *
  9884. * \brief This file provides an API for the RSA public-key cryptosystem.
  9885. *
  9886. * The RSA public-key cryptosystem is defined in <em>Public-Key
  9887. * Cryptography Standards (PKCS) #1 v1.5: RSA Encryption</em>
  9888. * and <em>Public-Key Cryptography Standards (PKCS) #1 v2.1:
  9889. * RSA Cryptography Specifications</em>.
  9890. *
  9891. */
  9892. /*
  9893. * Copyright The Mbed TLS Contributors
  9894. * SPDX-License-Identifier: Apache-2.0
  9895. *
  9896. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  9897. * not use this file except in compliance with the License.
  9898. * You may obtain a copy of the License at
  9899. *
  9900. * http://www.apache.org/licenses/LICENSE-2.0
  9901. *
  9902. * Unless required by applicable law or agreed to in writing, software
  9903. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  9904. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  9905. * See the License for the specific language governing permissions and
  9906. * limitations under the License.
  9907. */
  9908. #ifndef MBEDTLS_RSA_H
  9909. #define MBEDTLS_RSA_H
  9910. #if !defined(MBEDTLS_CONFIG_FILE)
  9911. #else
  9912. #endif
  9913. #if defined(MBEDTLS_THREADING_C)
  9914. #endif
  9915. /*
  9916. * RSA Error codes
  9917. */
  9918. /** Bad input parameters to function. */
  9919. #define MBEDTLS_ERR_RSA_BAD_INPUT_DATA -0x4080
  9920. /** Input data contains invalid padding and is rejected. */
  9921. #define MBEDTLS_ERR_RSA_INVALID_PADDING -0x4100
  9922. /** Something failed during generation of a key. */
  9923. #define MBEDTLS_ERR_RSA_KEY_GEN_FAILED -0x4180
  9924. /** Key failed to pass the validity check of the library. */
  9925. #define MBEDTLS_ERR_RSA_KEY_CHECK_FAILED -0x4200
  9926. /** The public key operation failed. */
  9927. #define MBEDTLS_ERR_RSA_PUBLIC_FAILED -0x4280
  9928. /** The private key operation failed. */
  9929. #define MBEDTLS_ERR_RSA_PRIVATE_FAILED -0x4300
  9930. /** The PKCS#1 verification failed. */
  9931. #define MBEDTLS_ERR_RSA_VERIFY_FAILED -0x4380
  9932. /** The output buffer for decryption is not large enough. */
  9933. #define MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE -0x4400
  9934. /** The random generator failed to generate non-zeros. */
  9935. #define MBEDTLS_ERR_RSA_RNG_FAILED -0x4480
  9936. /* MBEDTLS_ERR_RSA_UNSUPPORTED_OPERATION is deprecated and should not be used.
  9937. */
  9938. /** The implementation does not offer the requested operation, for example, because of security violations or lack of functionality. */
  9939. #define MBEDTLS_ERR_RSA_UNSUPPORTED_OPERATION -0x4500
  9940. /* MBEDTLS_ERR_RSA_HW_ACCEL_FAILED is deprecated and should not be used. */
  9941. /** RSA hardware accelerator failed. */
  9942. #define MBEDTLS_ERR_RSA_HW_ACCEL_FAILED -0x4580
  9943. /*
  9944. * RSA constants
  9945. */
  9946. #define MBEDTLS_RSA_PUBLIC 0 /**< Request private key operation. */
  9947. #define MBEDTLS_RSA_PRIVATE 1 /**< Request public key operation. */
  9948. #define MBEDTLS_RSA_PKCS_V15 0 /**< Use PKCS#1 v1.5 encoding. */
  9949. #define MBEDTLS_RSA_PKCS_V21 1 /**< Use PKCS#1 v2.1 encoding. */
  9950. #define MBEDTLS_RSA_SIGN 1 /**< Identifier for RSA signature operations. */
  9951. #define MBEDTLS_RSA_CRYPT 2 /**< Identifier for RSA encryption and decryption operations. */
  9952. #define MBEDTLS_RSA_SALT_LEN_ANY -1
  9953. /*
  9954. * The above constants may be used even if the RSA module is compile out,
  9955. * eg for alternative (PKCS#11) RSA implemenations in the PK layers.
  9956. */
  9957. #ifdef __cplusplus
  9958. extern "C" {
  9959. #endif
  9960. #if !defined(MBEDTLS_RSA_ALT)
  9961. // Regular implementation
  9962. //
  9963. /**
  9964. * \brief The RSA context structure.
  9965. *
  9966. * \note Direct manipulation of the members of this structure
  9967. * is deprecated. All manipulation should instead be done through
  9968. * the public interface functions.
  9969. */
  9970. typedef struct mbedtls_rsa_context
  9971. {
  9972. int ver; /*!< Reserved for internal purposes.
  9973. * Do not set this field in application
  9974. * code. Its meaning might change without
  9975. * notice. */
  9976. size_t len; /*!< The size of \p N in Bytes. */
  9977. mbedtls_mpi N; /*!< The public modulus. */
  9978. mbedtls_mpi E; /*!< The public exponent. */
  9979. mbedtls_mpi D; /*!< The private exponent. */
  9980. mbedtls_mpi P; /*!< The first prime factor. */
  9981. mbedtls_mpi Q; /*!< The second prime factor. */
  9982. mbedtls_mpi DP; /*!< <code>D % (P - 1)</code>. */
  9983. mbedtls_mpi DQ; /*!< <code>D % (Q - 1)</code>. */
  9984. mbedtls_mpi QP; /*!< <code>1 / (Q % P)</code>. */
  9985. mbedtls_mpi RN; /*!< cached <code>R^2 mod N</code>. */
  9986. mbedtls_mpi RP; /*!< cached <code>R^2 mod P</code>. */
  9987. mbedtls_mpi RQ; /*!< cached <code>R^2 mod Q</code>. */
  9988. mbedtls_mpi Vi; /*!< The cached blinding value. */
  9989. mbedtls_mpi Vf; /*!< The cached un-blinding value. */
  9990. int padding; /*!< Selects padding mode:
  9991. #MBEDTLS_RSA_PKCS_V15 for 1.5 padding and
  9992. #MBEDTLS_RSA_PKCS_V21 for OAEP or PSS. */
  9993. int hash_id; /*!< Hash identifier of mbedtls_md_type_t type,
  9994. as specified in md.h for use in the MGF
  9995. mask generating function used in the
  9996. EME-OAEP and EMSA-PSS encodings. */
  9997. #if defined(MBEDTLS_THREADING_C)
  9998. /* Invariant: the mutex is initialized iff ver != 0. */
  9999. mbedtls_threading_mutex_t mutex; /*!< Thread-safety mutex. */
  10000. #endif
  10001. }
  10002. mbedtls_rsa_context;
  10003. #else /* MBEDTLS_RSA_ALT */
  10004. #endif /* MBEDTLS_RSA_ALT */
  10005. /**
  10006. * \brief This function initializes an RSA context.
  10007. *
  10008. * \note Set padding to #MBEDTLS_RSA_PKCS_V21 for the RSAES-OAEP
  10009. * encryption scheme and the RSASSA-PSS signature scheme.
  10010. *
  10011. * \note The \p hash_id parameter is ignored when using
  10012. * #MBEDTLS_RSA_PKCS_V15 padding.
  10013. *
  10014. * \note The choice of padding mode is strictly enforced for private key
  10015. * operations, since there might be security concerns in
  10016. * mixing padding modes. For public key operations it is
  10017. * a default value, which can be overridden by calling specific
  10018. * \c rsa_rsaes_xxx or \c rsa_rsassa_xxx functions.
  10019. *
  10020. * \note The hash selected in \p hash_id is always used for OEAP
  10021. * encryption. For PSS signatures, it is always used for
  10022. * making signatures, but can be overridden for verifying them.
  10023. * If set to #MBEDTLS_MD_NONE, it is always overridden.
  10024. *
  10025. * \param ctx The RSA context to initialize. This must not be \c NULL.
  10026. * \param padding The padding mode to use. This must be either
  10027. * #MBEDTLS_RSA_PKCS_V15 or #MBEDTLS_RSA_PKCS_V21.
  10028. * \param hash_id The hash identifier of ::mbedtls_md_type_t type, if
  10029. * \p padding is #MBEDTLS_RSA_PKCS_V21. It is unused
  10030. * otherwise.
  10031. */
  10032. void mbedtls_rsa_init( mbedtls_rsa_context *ctx,
  10033. int padding,
  10034. int hash_id );
  10035. /**
  10036. * \brief This function imports a set of core parameters into an
  10037. * RSA context.
  10038. *
  10039. * \note This function can be called multiple times for successive
  10040. * imports, if the parameters are not simultaneously present.
  10041. *
  10042. * Any sequence of calls to this function should be followed
  10043. * by a call to mbedtls_rsa_complete(), which checks and
  10044. * completes the provided information to a ready-for-use
  10045. * public or private RSA key.
  10046. *
  10047. * \note See mbedtls_rsa_complete() for more information on which
  10048. * parameters are necessary to set up a private or public
  10049. * RSA key.
  10050. *
  10051. * \note The imported parameters are copied and need not be preserved
  10052. * for the lifetime of the RSA context being set up.
  10053. *
  10054. * \param ctx The initialized RSA context to store the parameters in.
  10055. * \param N The RSA modulus. This may be \c NULL.
  10056. * \param P The first prime factor of \p N. This may be \c NULL.
  10057. * \param Q The second prime factor of \p N. This may be \c NULL.
  10058. * \param D The private exponent. This may be \c NULL.
  10059. * \param E The public exponent. This may be \c NULL.
  10060. *
  10061. * \return \c 0 on success.
  10062. * \return A non-zero error code on failure.
  10063. */
  10064. int mbedtls_rsa_import( mbedtls_rsa_context *ctx,
  10065. const mbedtls_mpi *N,
  10066. const mbedtls_mpi *P, const mbedtls_mpi *Q,
  10067. const mbedtls_mpi *D, const mbedtls_mpi *E );
  10068. /**
  10069. * \brief This function imports core RSA parameters, in raw big-endian
  10070. * binary format, into an RSA context.
  10071. *
  10072. * \note This function can be called multiple times for successive
  10073. * imports, if the parameters are not simultaneously present.
  10074. *
  10075. * Any sequence of calls to this function should be followed
  10076. * by a call to mbedtls_rsa_complete(), which checks and
  10077. * completes the provided information to a ready-for-use
  10078. * public or private RSA key.
  10079. *
  10080. * \note See mbedtls_rsa_complete() for more information on which
  10081. * parameters are necessary to set up a private or public
  10082. * RSA key.
  10083. *
  10084. * \note The imported parameters are copied and need not be preserved
  10085. * for the lifetime of the RSA context being set up.
  10086. *
  10087. * \param ctx The initialized RSA context to store the parameters in.
  10088. * \param N The RSA modulus. This may be \c NULL.
  10089. * \param N_len The Byte length of \p N; it is ignored if \p N == NULL.
  10090. * \param P The first prime factor of \p N. This may be \c NULL.
  10091. * \param P_len The Byte length of \p P; it ns ignored if \p P == NULL.
  10092. * \param Q The second prime factor of \p N. This may be \c NULL.
  10093. * \param Q_len The Byte length of \p Q; it is ignored if \p Q == NULL.
  10094. * \param D The private exponent. This may be \c NULL.
  10095. * \param D_len The Byte length of \p D; it is ignored if \p D == NULL.
  10096. * \param E The public exponent. This may be \c NULL.
  10097. * \param E_len The Byte length of \p E; it is ignored if \p E == NULL.
  10098. *
  10099. * \return \c 0 on success.
  10100. * \return A non-zero error code on failure.
  10101. */
  10102. int mbedtls_rsa_import_raw( mbedtls_rsa_context *ctx,
  10103. unsigned char const *N, size_t N_len,
  10104. unsigned char const *P, size_t P_len,
  10105. unsigned char const *Q, size_t Q_len,
  10106. unsigned char const *D, size_t D_len,
  10107. unsigned char const *E, size_t E_len );
  10108. /**
  10109. * \brief This function completes an RSA context from
  10110. * a set of imported core parameters.
  10111. *
  10112. * To setup an RSA public key, precisely \p N and \p E
  10113. * must have been imported.
  10114. *
  10115. * To setup an RSA private key, sufficient information must
  10116. * be present for the other parameters to be derivable.
  10117. *
  10118. * The default implementation supports the following:
  10119. * <ul><li>Derive \p P, \p Q from \p N, \p D, \p E.</li>
  10120. * <li>Derive \p N, \p D from \p P, \p Q, \p E.</li></ul>
  10121. * Alternative implementations need not support these.
  10122. *
  10123. * If this function runs successfully, it guarantees that
  10124. * the RSA context can be used for RSA operations without
  10125. * the risk of failure or crash.
  10126. *
  10127. * \warning This function need not perform consistency checks
  10128. * for the imported parameters. In particular, parameters that
  10129. * are not needed by the implementation might be silently
  10130. * discarded and left unchecked. To check the consistency
  10131. * of the key material, see mbedtls_rsa_check_privkey().
  10132. *
  10133. * \param ctx The initialized RSA context holding imported parameters.
  10134. *
  10135. * \return \c 0 on success.
  10136. * \return #MBEDTLS_ERR_RSA_BAD_INPUT_DATA if the attempted derivations
  10137. * failed.
  10138. *
  10139. */
  10140. int mbedtls_rsa_complete( mbedtls_rsa_context *ctx );
  10141. /**
  10142. * \brief This function exports the core parameters of an RSA key.
  10143. *
  10144. * If this function runs successfully, the non-NULL buffers
  10145. * pointed to by \p N, \p P, \p Q, \p D, and \p E are fully
  10146. * written, with additional unused space filled leading by
  10147. * zero Bytes.
  10148. *
  10149. * Possible reasons for returning
  10150. * #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED:<ul>
  10151. * <li>An alternative RSA implementation is in use, which
  10152. * stores the key externally, and either cannot or should
  10153. * not export it into RAM.</li>
  10154. * <li>A SW or HW implementation might not support a certain
  10155. * deduction. For example, \p P, \p Q from \p N, \p D,
  10156. * and \p E if the former are not part of the
  10157. * implementation.</li></ul>
  10158. *
  10159. * If the function fails due to an unsupported operation,
  10160. * the RSA context stays intact and remains usable.
  10161. *
  10162. * \param ctx The initialized RSA context.
  10163. * \param N The MPI to hold the RSA modulus.
  10164. * This may be \c NULL if this field need not be exported.
  10165. * \param P The MPI to hold the first prime factor of \p N.
  10166. * This may be \c NULL if this field need not be exported.
  10167. * \param Q The MPI to hold the second prime factor of \p N.
  10168. * This may be \c NULL if this field need not be exported.
  10169. * \param D The MPI to hold the private exponent.
  10170. * This may be \c NULL if this field need not be exported.
  10171. * \param E The MPI to hold the public exponent.
  10172. * This may be \c NULL if this field need not be exported.
  10173. *
  10174. * \return \c 0 on success.
  10175. * \return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED if exporting the
  10176. * requested parameters cannot be done due to missing
  10177. * functionality or because of security policies.
  10178. * \return A non-zero return code on any other failure.
  10179. *
  10180. */
  10181. int mbedtls_rsa_export( const mbedtls_rsa_context *ctx,
  10182. mbedtls_mpi *N, mbedtls_mpi *P, mbedtls_mpi *Q,
  10183. mbedtls_mpi *D, mbedtls_mpi *E );
  10184. /**
  10185. * \brief This function exports core parameters of an RSA key
  10186. * in raw big-endian binary format.
  10187. *
  10188. * If this function runs successfully, the non-NULL buffers
  10189. * pointed to by \p N, \p P, \p Q, \p D, and \p E are fully
  10190. * written, with additional unused space filled leading by
  10191. * zero Bytes.
  10192. *
  10193. * Possible reasons for returning
  10194. * #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED:<ul>
  10195. * <li>An alternative RSA implementation is in use, which
  10196. * stores the key externally, and either cannot or should
  10197. * not export it into RAM.</li>
  10198. * <li>A SW or HW implementation might not support a certain
  10199. * deduction. For example, \p P, \p Q from \p N, \p D,
  10200. * and \p E if the former are not part of the
  10201. * implementation.</li></ul>
  10202. * If the function fails due to an unsupported operation,
  10203. * the RSA context stays intact and remains usable.
  10204. *
  10205. * \note The length parameters are ignored if the corresponding
  10206. * buffer pointers are NULL.
  10207. *
  10208. * \param ctx The initialized RSA context.
  10209. * \param N The Byte array to store the RSA modulus,
  10210. * or \c NULL if this field need not be exported.
  10211. * \param N_len The size of the buffer for the modulus.
  10212. * \param P The Byte array to hold the first prime factor of \p N,
  10213. * or \c NULL if this field need not be exported.
  10214. * \param P_len The size of the buffer for the first prime factor.
  10215. * \param Q The Byte array to hold the second prime factor of \p N,
  10216. * or \c NULL if this field need not be exported.
  10217. * \param Q_len The size of the buffer for the second prime factor.
  10218. * \param D The Byte array to hold the private exponent,
  10219. * or \c NULL if this field need not be exported.
  10220. * \param D_len The size of the buffer for the private exponent.
  10221. * \param E The Byte array to hold the public exponent,
  10222. * or \c NULL if this field need not be exported.
  10223. * \param E_len The size of the buffer for the public exponent.
  10224. *
  10225. * \return \c 0 on success.
  10226. * \return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED if exporting the
  10227. * requested parameters cannot be done due to missing
  10228. * functionality or because of security policies.
  10229. * \return A non-zero return code on any other failure.
  10230. */
  10231. int mbedtls_rsa_export_raw( const mbedtls_rsa_context *ctx,
  10232. unsigned char *N, size_t N_len,
  10233. unsigned char *P, size_t P_len,
  10234. unsigned char *Q, size_t Q_len,
  10235. unsigned char *D, size_t D_len,
  10236. unsigned char *E, size_t E_len );
  10237. /**
  10238. * \brief This function exports CRT parameters of a private RSA key.
  10239. *
  10240. * \note Alternative RSA implementations not using CRT-parameters
  10241. * internally can implement this function based on
  10242. * mbedtls_rsa_deduce_opt().
  10243. *
  10244. * \param ctx The initialized RSA context.
  10245. * \param DP The MPI to hold \c D modulo `P-1`,
  10246. * or \c NULL if it need not be exported.
  10247. * \param DQ The MPI to hold \c D modulo `Q-1`,
  10248. * or \c NULL if it need not be exported.
  10249. * \param QP The MPI to hold modular inverse of \c Q modulo \c P,
  10250. * or \c NULL if it need not be exported.
  10251. *
  10252. * \return \c 0 on success.
  10253. * \return A non-zero error code on failure.
  10254. *
  10255. */
  10256. int mbedtls_rsa_export_crt( const mbedtls_rsa_context *ctx,
  10257. mbedtls_mpi *DP, mbedtls_mpi *DQ, mbedtls_mpi *QP );
  10258. /**
  10259. * \brief This function sets padding for an already initialized RSA
  10260. * context. See mbedtls_rsa_init() for details.
  10261. *
  10262. * \param ctx The initialized RSA context to be configured.
  10263. * \param padding The padding mode to use. This must be either
  10264. * #MBEDTLS_RSA_PKCS_V15 or #MBEDTLS_RSA_PKCS_V21.
  10265. * \param hash_id The #MBEDTLS_RSA_PKCS_V21 hash identifier.
  10266. */
  10267. void mbedtls_rsa_set_padding( mbedtls_rsa_context *ctx, int padding,
  10268. int hash_id );
  10269. /**
  10270. * \brief This function retrieves the length of RSA modulus in Bytes.
  10271. *
  10272. * \param ctx The initialized RSA context.
  10273. *
  10274. * \return The length of the RSA modulus in Bytes.
  10275. *
  10276. */
  10277. size_t mbedtls_rsa_get_len( const mbedtls_rsa_context *ctx );
  10278. /**
  10279. * \brief This function generates an RSA keypair.
  10280. *
  10281. * \note mbedtls_rsa_init() must be called before this function,
  10282. * to set up the RSA context.
  10283. *
  10284. * \param ctx The initialized RSA context used to hold the key.
  10285. * \param f_rng The RNG function to be used for key generation.
  10286. * This must not be \c NULL.
  10287. * \param p_rng The RNG context to be passed to \p f_rng.
  10288. * This may be \c NULL if \p f_rng doesn't need a context.
  10289. * \param nbits The size of the public key in bits.
  10290. * \param exponent The public exponent to use. For example, \c 65537.
  10291. * This must be odd and greater than \c 1.
  10292. *
  10293. * \return \c 0 on success.
  10294. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10295. */
  10296. int mbedtls_rsa_gen_key( mbedtls_rsa_context *ctx,
  10297. int (*f_rng)(void *, unsigned char *, size_t),
  10298. void *p_rng,
  10299. unsigned int nbits, int exponent );
  10300. /**
  10301. * \brief This function checks if a context contains at least an RSA
  10302. * public key.
  10303. *
  10304. * If the function runs successfully, it is guaranteed that
  10305. * enough information is present to perform an RSA public key
  10306. * operation using mbedtls_rsa_public().
  10307. *
  10308. * \param ctx The initialized RSA context to check.
  10309. *
  10310. * \return \c 0 on success.
  10311. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10312. *
  10313. */
  10314. int mbedtls_rsa_check_pubkey( const mbedtls_rsa_context *ctx );
  10315. /**
  10316. * \brief This function checks if a context contains an RSA private key
  10317. * and perform basic consistency checks.
  10318. *
  10319. * \note The consistency checks performed by this function not only
  10320. * ensure that mbedtls_rsa_private() can be called successfully
  10321. * on the given context, but that the various parameters are
  10322. * mutually consistent with high probability, in the sense that
  10323. * mbedtls_rsa_public() and mbedtls_rsa_private() are inverses.
  10324. *
  10325. * \warning This function should catch accidental misconfigurations
  10326. * like swapping of parameters, but it cannot establish full
  10327. * trust in neither the quality nor the consistency of the key
  10328. * material that was used to setup the given RSA context:
  10329. * <ul><li>Consistency: Imported parameters that are irrelevant
  10330. * for the implementation might be silently dropped. If dropped,
  10331. * the current function does not have access to them,
  10332. * and therefore cannot check them. See mbedtls_rsa_complete().
  10333. * If you want to check the consistency of the entire
  10334. * content of an PKCS1-encoded RSA private key, for example, you
  10335. * should use mbedtls_rsa_validate_params() before setting
  10336. * up the RSA context.
  10337. * Additionally, if the implementation performs empirical checks,
  10338. * these checks substantiate but do not guarantee consistency.</li>
  10339. * <li>Quality: This function is not expected to perform
  10340. * extended quality assessments like checking that the prime
  10341. * factors are safe. Additionally, it is the responsibility of the
  10342. * user to ensure the trustworthiness of the source of his RSA
  10343. * parameters, which goes beyond what is effectively checkable
  10344. * by the library.</li></ul>
  10345. *
  10346. * \param ctx The initialized RSA context to check.
  10347. *
  10348. * \return \c 0 on success.
  10349. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10350. */
  10351. int mbedtls_rsa_check_privkey( const mbedtls_rsa_context *ctx );
  10352. /**
  10353. * \brief This function checks a public-private RSA key pair.
  10354. *
  10355. * It checks each of the contexts, and makes sure they match.
  10356. *
  10357. * \param pub The initialized RSA context holding the public key.
  10358. * \param prv The initialized RSA context holding the private key.
  10359. *
  10360. * \return \c 0 on success.
  10361. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10362. */
  10363. int mbedtls_rsa_check_pub_priv( const mbedtls_rsa_context *pub,
  10364. const mbedtls_rsa_context *prv );
  10365. /**
  10366. * \brief This function performs an RSA public key operation.
  10367. *
  10368. * \param ctx The initialized RSA context to use.
  10369. * \param input The input buffer. This must be a readable buffer
  10370. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10371. * for an 2048-bit RSA modulus.
  10372. * \param output The output buffer. This must be a writable buffer
  10373. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10374. * for an 2048-bit RSA modulus.
  10375. *
  10376. * \note This function does not handle message padding.
  10377. *
  10378. * \note Make sure to set \p input[0] = 0 or ensure that
  10379. * input is smaller than \p N.
  10380. *
  10381. * \return \c 0 on success.
  10382. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10383. */
  10384. int mbedtls_rsa_public( mbedtls_rsa_context *ctx,
  10385. const unsigned char *input,
  10386. unsigned char *output );
  10387. /**
  10388. * \brief This function performs an RSA private key operation.
  10389. *
  10390. * \note Blinding is used if and only if a PRNG is provided.
  10391. *
  10392. * \note If blinding is used, both the base of exponentation
  10393. * and the exponent are blinded, providing protection
  10394. * against some side-channel attacks.
  10395. *
  10396. * \warning It is deprecated and a security risk to not provide
  10397. * a PRNG here and thereby prevent the use of blinding.
  10398. * Future versions of the library may enforce the presence
  10399. * of a PRNG.
  10400. *
  10401. * \param ctx The initialized RSA context to use.
  10402. * \param f_rng The RNG function, used for blinding. It is discouraged
  10403. * and deprecated to pass \c NULL here, in which case
  10404. * blinding will be omitted.
  10405. * \param p_rng The RNG context to pass to \p f_rng. This may be \c NULL
  10406. * if \p f_rng is \c NULL or if \p f_rng doesn't need a context.
  10407. * \param input The input buffer. This must be a readable buffer
  10408. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10409. * for an 2048-bit RSA modulus.
  10410. * \param output The output buffer. This must be a writable buffer
  10411. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10412. * for an 2048-bit RSA modulus.
  10413. *
  10414. * \return \c 0 on success.
  10415. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10416. *
  10417. */
  10418. int mbedtls_rsa_private( mbedtls_rsa_context *ctx,
  10419. int (*f_rng)(void *, unsigned char *, size_t),
  10420. void *p_rng,
  10421. const unsigned char *input,
  10422. unsigned char *output );
  10423. /**
  10424. * \brief This function adds the message padding, then performs an RSA
  10425. * operation.
  10426. *
  10427. * It is the generic wrapper for performing a PKCS#1 encryption
  10428. * operation using the \p mode from the context.
  10429. *
  10430. * \deprecated It is deprecated and discouraged to call this function
  10431. * in #MBEDTLS_RSA_PRIVATE mode. Future versions of the library
  10432. * are likely to remove the \p mode argument and have it
  10433. * implicitly set to #MBEDTLS_RSA_PUBLIC.
  10434. *
  10435. * \note Alternative implementations of RSA need not support
  10436. * mode being set to #MBEDTLS_RSA_PRIVATE and might instead
  10437. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10438. *
  10439. * \param ctx The initialized RSA context to use.
  10440. * \param f_rng The RNG to use. It is mandatory for PKCS#1 v2.1 padding
  10441. * encoding, and for PKCS#1 v1.5 padding encoding when used
  10442. * with \p mode set to #MBEDTLS_RSA_PUBLIC. For PKCS#1 v1.5
  10443. * padding encoding and \p mode set to #MBEDTLS_RSA_PRIVATE,
  10444. * it is used for blinding and should be provided in this
  10445. * case; see mbedtls_rsa_private() for more.
  10446. * \param p_rng The RNG context to be passed to \p f_rng. May be
  10447. * \c NULL if \p f_rng is \c NULL or if \p f_rng doesn't
  10448. * need a context argument.
  10449. * \param mode The mode of operation. This must be either
  10450. * #MBEDTLS_RSA_PUBLIC or #MBEDTLS_RSA_PRIVATE (deprecated).
  10451. * \param ilen The length of the plaintext in Bytes.
  10452. * \param input The input data to encrypt. This must be a readable
  10453. * buffer of size \p ilen Bytes. It may be \c NULL if
  10454. * `ilen == 0`.
  10455. * \param output The output buffer. This must be a writable buffer
  10456. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10457. * for an 2048-bit RSA modulus.
  10458. *
  10459. * \return \c 0 on success.
  10460. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10461. */
  10462. int mbedtls_rsa_pkcs1_encrypt( mbedtls_rsa_context *ctx,
  10463. int (*f_rng)(void *, unsigned char *, size_t),
  10464. void *p_rng,
  10465. int mode, size_t ilen,
  10466. const unsigned char *input,
  10467. unsigned char *output );
  10468. /**
  10469. * \brief This function performs a PKCS#1 v1.5 encryption operation
  10470. * (RSAES-PKCS1-v1_5-ENCRYPT).
  10471. *
  10472. * \deprecated It is deprecated and discouraged to call this function
  10473. * in #MBEDTLS_RSA_PRIVATE mode. Future versions of the library
  10474. * are likely to remove the \p mode argument and have it
  10475. * implicitly set to #MBEDTLS_RSA_PUBLIC.
  10476. *
  10477. * \note Alternative implementations of RSA need not support
  10478. * mode being set to #MBEDTLS_RSA_PRIVATE and might instead
  10479. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10480. *
  10481. * \param ctx The initialized RSA context to use.
  10482. * \param f_rng The RNG function to use. It is needed for padding generation
  10483. * if \p mode is #MBEDTLS_RSA_PUBLIC. If \p mode is
  10484. * #MBEDTLS_RSA_PRIVATE (discouraged), it is used for
  10485. * blinding and should be provided; see mbedtls_rsa_private().
  10486. * \param p_rng The RNG context to be passed to \p f_rng. This may
  10487. * be \c NULL if \p f_rng is \c NULL or if \p f_rng
  10488. * doesn't need a context argument.
  10489. * \param mode The mode of operation. This must be either
  10490. * #MBEDTLS_RSA_PUBLIC or #MBEDTLS_RSA_PRIVATE (deprecated).
  10491. * \param ilen The length of the plaintext in Bytes.
  10492. * \param input The input data to encrypt. This must be a readable
  10493. * buffer of size \p ilen Bytes. It may be \c NULL if
  10494. * `ilen == 0`.
  10495. * \param output The output buffer. This must be a writable buffer
  10496. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10497. * for an 2048-bit RSA modulus.
  10498. *
  10499. * \return \c 0 on success.
  10500. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10501. */
  10502. int mbedtls_rsa_rsaes_pkcs1_v15_encrypt( mbedtls_rsa_context *ctx,
  10503. int (*f_rng)(void *, unsigned char *, size_t),
  10504. void *p_rng,
  10505. int mode, size_t ilen,
  10506. const unsigned char *input,
  10507. unsigned char *output );
  10508. /**
  10509. * \brief This function performs a PKCS#1 v2.1 OAEP encryption
  10510. * operation (RSAES-OAEP-ENCRYPT).
  10511. *
  10512. * \note The output buffer must be as large as the size
  10513. * of ctx->N. For example, 128 Bytes if RSA-1024 is used.
  10514. *
  10515. * \deprecated It is deprecated and discouraged to call this function
  10516. * in #MBEDTLS_RSA_PRIVATE mode. Future versions of the library
  10517. * are likely to remove the \p mode argument and have it
  10518. * implicitly set to #MBEDTLS_RSA_PUBLIC.
  10519. *
  10520. * \note Alternative implementations of RSA need not support
  10521. * mode being set to #MBEDTLS_RSA_PRIVATE and might instead
  10522. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10523. *
  10524. * \param ctx The initnialized RSA context to use.
  10525. * \param f_rng The RNG function to use. This is needed for padding
  10526. * generation and must be provided.
  10527. * \param p_rng The RNG context to be passed to \p f_rng. This may
  10528. * be \c NULL if \p f_rng doesn't need a context argument.
  10529. * \param mode The mode of operation. This must be either
  10530. * #MBEDTLS_RSA_PUBLIC or #MBEDTLS_RSA_PRIVATE (deprecated).
  10531. * \param label The buffer holding the custom label to use.
  10532. * This must be a readable buffer of length \p label_len
  10533. * Bytes. It may be \c NULL if \p label_len is \c 0.
  10534. * \param label_len The length of the label in Bytes.
  10535. * \param ilen The length of the plaintext buffer \p input in Bytes.
  10536. * \param input The input data to encrypt. This must be a readable
  10537. * buffer of size \p ilen Bytes. It may be \c NULL if
  10538. * `ilen == 0`.
  10539. * \param output The output buffer. This must be a writable buffer
  10540. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10541. * for an 2048-bit RSA modulus.
  10542. *
  10543. * \return \c 0 on success.
  10544. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10545. */
  10546. int mbedtls_rsa_rsaes_oaep_encrypt( mbedtls_rsa_context *ctx,
  10547. int (*f_rng)(void *, unsigned char *, size_t),
  10548. void *p_rng,
  10549. int mode,
  10550. const unsigned char *label, size_t label_len,
  10551. size_t ilen,
  10552. const unsigned char *input,
  10553. unsigned char *output );
  10554. /**
  10555. * \brief This function performs an RSA operation, then removes the
  10556. * message padding.
  10557. *
  10558. * It is the generic wrapper for performing a PKCS#1 decryption
  10559. * operation using the \p mode from the context.
  10560. *
  10561. * \note The output buffer length \c output_max_len should be
  10562. * as large as the size \p ctx->len of \p ctx->N (for example,
  10563. * 128 Bytes if RSA-1024 is used) to be able to hold an
  10564. * arbitrary decrypted message. If it is not large enough to
  10565. * hold the decryption of the particular ciphertext provided,
  10566. * the function returns \c MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE.
  10567. *
  10568. * \deprecated It is deprecated and discouraged to call this function
  10569. * in #MBEDTLS_RSA_PUBLIC mode. Future versions of the library
  10570. * are likely to remove the \p mode argument and have it
  10571. * implicitly set to #MBEDTLS_RSA_PRIVATE.
  10572. *
  10573. * \note Alternative implementations of RSA need not support
  10574. * mode being set to #MBEDTLS_RSA_PUBLIC and might instead
  10575. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10576. *
  10577. * \param ctx The initialized RSA context to use.
  10578. * \param f_rng The RNG function. If \p mode is #MBEDTLS_RSA_PRIVATE,
  10579. * this is used for blinding and should be provided; see
  10580. * mbedtls_rsa_private() for more. If \p mode is
  10581. * #MBEDTLS_RSA_PUBLIC, it is ignored.
  10582. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  10583. * \c NULL if \p f_rng is \c NULL or doesn't need a context.
  10584. * \param mode The mode of operation. This must be either
  10585. * #MBEDTLS_RSA_PRIVATE or #MBEDTLS_RSA_PUBLIC (deprecated).
  10586. * \param olen The address at which to store the length of
  10587. * the plaintext. This must not be \c NULL.
  10588. * \param input The ciphertext buffer. This must be a readable buffer
  10589. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10590. * for an 2048-bit RSA modulus.
  10591. * \param output The buffer used to hold the plaintext. This must
  10592. * be a writable buffer of length \p output_max_len Bytes.
  10593. * \param output_max_len The length in Bytes of the output buffer \p output.
  10594. *
  10595. * \return \c 0 on success.
  10596. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10597. */
  10598. int mbedtls_rsa_pkcs1_decrypt( mbedtls_rsa_context *ctx,
  10599. int (*f_rng)(void *, unsigned char *, size_t),
  10600. void *p_rng,
  10601. int mode, size_t *olen,
  10602. const unsigned char *input,
  10603. unsigned char *output,
  10604. size_t output_max_len );
  10605. /**
  10606. * \brief This function performs a PKCS#1 v1.5 decryption
  10607. * operation (RSAES-PKCS1-v1_5-DECRYPT).
  10608. *
  10609. * \note The output buffer length \c output_max_len should be
  10610. * as large as the size \p ctx->len of \p ctx->N, for example,
  10611. * 128 Bytes if RSA-1024 is used, to be able to hold an
  10612. * arbitrary decrypted message. If it is not large enough to
  10613. * hold the decryption of the particular ciphertext provided,
  10614. * the function returns #MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE.
  10615. *
  10616. * \deprecated It is deprecated and discouraged to call this function
  10617. * in #MBEDTLS_RSA_PUBLIC mode. Future versions of the library
  10618. * are likely to remove the \p mode argument and have it
  10619. * implicitly set to #MBEDTLS_RSA_PRIVATE.
  10620. *
  10621. * \note Alternative implementations of RSA need not support
  10622. * mode being set to #MBEDTLS_RSA_PUBLIC and might instead
  10623. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10624. *
  10625. * \param ctx The initialized RSA context to use.
  10626. * \param f_rng The RNG function. If \p mode is #MBEDTLS_RSA_PRIVATE,
  10627. * this is used for blinding and should be provided; see
  10628. * mbedtls_rsa_private() for more. If \p mode is
  10629. * #MBEDTLS_RSA_PUBLIC, it is ignored.
  10630. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  10631. * \c NULL if \p f_rng is \c NULL or doesn't need a context.
  10632. * \param mode The mode of operation. This must be either
  10633. * #MBEDTLS_RSA_PRIVATE or #MBEDTLS_RSA_PUBLIC (deprecated).
  10634. * \param olen The address at which to store the length of
  10635. * the plaintext. This must not be \c NULL.
  10636. * \param input The ciphertext buffer. This must be a readable buffer
  10637. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10638. * for an 2048-bit RSA modulus.
  10639. * \param output The buffer used to hold the plaintext. This must
  10640. * be a writable buffer of length \p output_max_len Bytes.
  10641. * \param output_max_len The length in Bytes of the output buffer \p output.
  10642. *
  10643. * \return \c 0 on success.
  10644. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10645. *
  10646. */
  10647. int mbedtls_rsa_rsaes_pkcs1_v15_decrypt( mbedtls_rsa_context *ctx,
  10648. int (*f_rng)(void *, unsigned char *, size_t),
  10649. void *p_rng,
  10650. int mode, size_t *olen,
  10651. const unsigned char *input,
  10652. unsigned char *output,
  10653. size_t output_max_len );
  10654. /**
  10655. * \brief This function performs a PKCS#1 v2.1 OAEP decryption
  10656. * operation (RSAES-OAEP-DECRYPT).
  10657. *
  10658. * \note The output buffer length \c output_max_len should be
  10659. * as large as the size \p ctx->len of \p ctx->N, for
  10660. * example, 128 Bytes if RSA-1024 is used, to be able to
  10661. * hold an arbitrary decrypted message. If it is not
  10662. * large enough to hold the decryption of the particular
  10663. * ciphertext provided, the function returns
  10664. * #MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE.
  10665. *
  10666. * \deprecated It is deprecated and discouraged to call this function
  10667. * in #MBEDTLS_RSA_PUBLIC mode. Future versions of the library
  10668. * are likely to remove the \p mode argument and have it
  10669. * implicitly set to #MBEDTLS_RSA_PRIVATE.
  10670. *
  10671. * \note Alternative implementations of RSA need not support
  10672. * mode being set to #MBEDTLS_RSA_PUBLIC and might instead
  10673. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10674. *
  10675. * \param ctx The initialized RSA context to use.
  10676. * \param f_rng The RNG function. If \p mode is #MBEDTLS_RSA_PRIVATE,
  10677. * this is used for blinding and should be provided; see
  10678. * mbedtls_rsa_private() for more. If \p mode is
  10679. * #MBEDTLS_RSA_PUBLIC, it is ignored.
  10680. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  10681. * \c NULL if \p f_rng is \c NULL or doesn't need a context.
  10682. * \param mode The mode of operation. This must be either
  10683. * #MBEDTLS_RSA_PRIVATE or #MBEDTLS_RSA_PUBLIC (deprecated).
  10684. * \param label The buffer holding the custom label to use.
  10685. * This must be a readable buffer of length \p label_len
  10686. * Bytes. It may be \c NULL if \p label_len is \c 0.
  10687. * \param label_len The length of the label in Bytes.
  10688. * \param olen The address at which to store the length of
  10689. * the plaintext. This must not be \c NULL.
  10690. * \param input The ciphertext buffer. This must be a readable buffer
  10691. * of length \c ctx->len Bytes. For example, \c 256 Bytes
  10692. * for an 2048-bit RSA modulus.
  10693. * \param output The buffer used to hold the plaintext. This must
  10694. * be a writable buffer of length \p output_max_len Bytes.
  10695. * \param output_max_len The length in Bytes of the output buffer \p output.
  10696. *
  10697. * \return \c 0 on success.
  10698. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10699. */
  10700. int mbedtls_rsa_rsaes_oaep_decrypt( mbedtls_rsa_context *ctx,
  10701. int (*f_rng)(void *, unsigned char *, size_t),
  10702. void *p_rng,
  10703. int mode,
  10704. const unsigned char *label, size_t label_len,
  10705. size_t *olen,
  10706. const unsigned char *input,
  10707. unsigned char *output,
  10708. size_t output_max_len );
  10709. /**
  10710. * \brief This function performs a private RSA operation to sign
  10711. * a message digest using PKCS#1.
  10712. *
  10713. * It is the generic wrapper for performing a PKCS#1
  10714. * signature using the \p mode from the context.
  10715. *
  10716. * \note The \p sig buffer must be as large as the size
  10717. * of \p ctx->N. For example, 128 Bytes if RSA-1024 is used.
  10718. *
  10719. * \note For PKCS#1 v2.1 encoding, see comments on
  10720. * mbedtls_rsa_rsassa_pss_sign() for details on
  10721. * \p md_alg and \p hash_id.
  10722. *
  10723. * \deprecated It is deprecated and discouraged to call this function
  10724. * in #MBEDTLS_RSA_PUBLIC mode. Future versions of the library
  10725. * are likely to remove the \p mode argument and have it
  10726. * implicitly set to #MBEDTLS_RSA_PRIVATE.
  10727. *
  10728. * \note Alternative implementations of RSA need not support
  10729. * mode being set to #MBEDTLS_RSA_PUBLIC and might instead
  10730. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10731. *
  10732. * \param ctx The initialized RSA context to use.
  10733. * \param f_rng The RNG function to use. If the padding mode is PKCS#1 v2.1,
  10734. * this must be provided. If the padding mode is PKCS#1 v1.5 and
  10735. * \p mode is #MBEDTLS_RSA_PRIVATE, it is used for blinding
  10736. * and should be provided; see mbedtls_rsa_private() for more
  10737. * more. It is ignored otherwise.
  10738. * \param p_rng The RNG context to be passed to \p f_rng. This may be \c NULL
  10739. * if \p f_rng is \c NULL or doesn't need a context argument.
  10740. * \param mode The mode of operation. This must be either
  10741. * #MBEDTLS_RSA_PRIVATE or #MBEDTLS_RSA_PUBLIC (deprecated).
  10742. * \param md_alg The message-digest algorithm used to hash the original data.
  10743. * Use #MBEDTLS_MD_NONE for signing raw data.
  10744. * \param hashlen The length of the message digest.
  10745. * Ths is only used if \p md_alg is #MBEDTLS_MD_NONE.
  10746. * \param hash The buffer holding the message digest or raw data.
  10747. * If \p md_alg is #MBEDTLS_MD_NONE, this must be a readable
  10748. * buffer of length \p hashlen Bytes. If \p md_alg is not
  10749. * #MBEDTLS_MD_NONE, it must be a readable buffer of length
  10750. * the size of the hash corresponding to \p md_alg.
  10751. * \param sig The buffer to hold the signature. This must be a writable
  10752. * buffer of length \c ctx->len Bytes. For example, \c 256 Bytes
  10753. * for an 2048-bit RSA modulus. A buffer length of
  10754. * #MBEDTLS_MPI_MAX_SIZE is always safe.
  10755. *
  10756. * \return \c 0 if the signing operation was successful.
  10757. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10758. */
  10759. int mbedtls_rsa_pkcs1_sign( mbedtls_rsa_context *ctx,
  10760. int (*f_rng)(void *, unsigned char *, size_t),
  10761. void *p_rng,
  10762. int mode,
  10763. mbedtls_md_type_t md_alg,
  10764. unsigned int hashlen,
  10765. const unsigned char *hash,
  10766. unsigned char *sig );
  10767. /**
  10768. * \brief This function performs a PKCS#1 v1.5 signature
  10769. * operation (RSASSA-PKCS1-v1_5-SIGN).
  10770. *
  10771. * \deprecated It is deprecated and discouraged to call this function
  10772. * in #MBEDTLS_RSA_PUBLIC mode. Future versions of the library
  10773. * are likely to remove the \p mode argument and have it
  10774. * implicitly set to #MBEDTLS_RSA_PRIVATE.
  10775. *
  10776. * \note Alternative implementations of RSA need not support
  10777. * mode being set to #MBEDTLS_RSA_PUBLIC and might instead
  10778. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10779. *
  10780. * \param ctx The initialized RSA context to use.
  10781. * \param f_rng The RNG function. If \p mode is #MBEDTLS_RSA_PRIVATE,
  10782. * this is used for blinding and should be provided; see
  10783. * mbedtls_rsa_private() for more. If \p mode is
  10784. * #MBEDTLS_RSA_PUBLIC, it is ignored.
  10785. * \param p_rng The RNG context to be passed to \p f_rng. This may be \c NULL
  10786. * if \p f_rng is \c NULL or doesn't need a context argument.
  10787. * \param mode The mode of operation. This must be either
  10788. * #MBEDTLS_RSA_PRIVATE or #MBEDTLS_RSA_PUBLIC (deprecated).
  10789. * \param md_alg The message-digest algorithm used to hash the original data.
  10790. * Use #MBEDTLS_MD_NONE for signing raw data.
  10791. * \param hashlen The length of the message digest.
  10792. * Ths is only used if \p md_alg is #MBEDTLS_MD_NONE.
  10793. * \param hash The buffer holding the message digest or raw data.
  10794. * If \p md_alg is #MBEDTLS_MD_NONE, this must be a readable
  10795. * buffer of length \p hashlen Bytes. If \p md_alg is not
  10796. * #MBEDTLS_MD_NONE, it must be a readable buffer of length
  10797. * the size of the hash corresponding to \p md_alg.
  10798. * \param sig The buffer to hold the signature. This must be a writable
  10799. * buffer of length \c ctx->len Bytes. For example, \c 256 Bytes
  10800. * for an 2048-bit RSA modulus. A buffer length of
  10801. * #MBEDTLS_MPI_MAX_SIZE is always safe.
  10802. *
  10803. * \return \c 0 if the signing operation was successful.
  10804. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10805. */
  10806. int mbedtls_rsa_rsassa_pkcs1_v15_sign( mbedtls_rsa_context *ctx,
  10807. int (*f_rng)(void *, unsigned char *, size_t),
  10808. void *p_rng,
  10809. int mode,
  10810. mbedtls_md_type_t md_alg,
  10811. unsigned int hashlen,
  10812. const unsigned char *hash,
  10813. unsigned char *sig );
  10814. /**
  10815. * \brief This function performs a PKCS#1 v2.1 PSS signature
  10816. * operation (RSASSA-PSS-SIGN).
  10817. *
  10818. * \note The \c hash_id set in \p ctx (when calling
  10819. * mbedtls_rsa_init() or by calling mbedtls_rsa_set_padding()
  10820. * afterwards) selects the hash used for the
  10821. * encoding operation and for the mask generation function
  10822. * (MGF1). For more details on the encoding operation and the
  10823. * mask generation function, consult <em>RFC-3447: Public-Key
  10824. * Cryptography Standards (PKCS) #1 v2.1: RSA Cryptography
  10825. * Specifications</em>.
  10826. *
  10827. * \note This function enforces that the provided salt length complies
  10828. * with FIPS 186-4 §5.5 (e) and RFC 8017 (PKCS#1 v2.2) §9.1.1
  10829. * step 3. The constraint is that the hash length plus the salt
  10830. * length plus 2 bytes must be at most the key length. If this
  10831. * constraint is not met, this function returns
  10832. * #MBEDTLS_ERR_RSA_BAD_INPUT_DATA.
  10833. *
  10834. * \param ctx The initialized RSA context to use.
  10835. * \param f_rng The RNG function. It must not be \c NULL.
  10836. * \param p_rng The RNG context to be passed to \p f_rng. This may be \c NULL
  10837. * if \p f_rng doesn't need a context argument.
  10838. * \param md_alg The message-digest algorithm used to hash the original data.
  10839. * Use #MBEDTLS_MD_NONE for signing raw data.
  10840. * \param hashlen The length of the message digest.
  10841. * Ths is only used if \p md_alg is #MBEDTLS_MD_NONE.
  10842. * \param hash The buffer holding the message digest or raw data.
  10843. * If \p md_alg is #MBEDTLS_MD_NONE, this must be a readable
  10844. * buffer of length \p hashlen Bytes. If \p md_alg is not
  10845. * #MBEDTLS_MD_NONE, it must be a readable buffer of length
  10846. * the size of the hash corresponding to \p md_alg.
  10847. * \param saltlen The length of the salt that should be used.
  10848. * If passed #MBEDTLS_RSA_SALT_LEN_ANY, the function will use
  10849. * the largest possible salt length up to the hash length,
  10850. * which is the largest permitted by some standards including
  10851. * FIPS 186-4 §5.5.
  10852. * \param sig The buffer to hold the signature. This must be a writable
  10853. * buffer of length \c ctx->len Bytes. For example, \c 256 Bytes
  10854. * for an 2048-bit RSA modulus. A buffer length of
  10855. * #MBEDTLS_MPI_MAX_SIZE is always safe.
  10856. *
  10857. * \return \c 0 if the signing operation was successful.
  10858. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10859. */
  10860. int mbedtls_rsa_rsassa_pss_sign_ext( mbedtls_rsa_context *ctx,
  10861. int (*f_rng)(void *, unsigned char *, size_t),
  10862. void *p_rng,
  10863. mbedtls_md_type_t md_alg,
  10864. unsigned int hashlen,
  10865. const unsigned char *hash,
  10866. int saltlen,
  10867. unsigned char *sig );
  10868. /**
  10869. * \brief This function performs a PKCS#1 v2.1 PSS signature
  10870. * operation (RSASSA-PSS-SIGN).
  10871. *
  10872. * \note The \c hash_id set in \p ctx (when calling
  10873. * mbedtls_rsa_init() or by calling mbedtls_rsa_set_padding()
  10874. * afterwards) selects the hash used for the
  10875. * encoding operation and for the mask generation function
  10876. * (MGF1). For more details on the encoding operation and the
  10877. * mask generation function, consult <em>RFC-3447: Public-Key
  10878. * Cryptography Standards (PKCS) #1 v2.1: RSA Cryptography
  10879. * Specifications</em>.
  10880. *
  10881. * \note This function always uses the maximum possible salt size,
  10882. * up to the length of the payload hash. This choice of salt
  10883. * size complies with FIPS 186-4 §5.5 (e) and RFC 8017 (PKCS#1
  10884. * v2.2) §9.1.1 step 3. Furthermore this function enforces a
  10885. * minimum salt size which is the hash size minus 2 bytes. If
  10886. * this minimum size is too large given the key size (the salt
  10887. * size, plus the hash size, plus 2 bytes must be no more than
  10888. * the key size in bytes), this function returns
  10889. * #MBEDTLS_ERR_RSA_BAD_INPUT_DATA.
  10890. *
  10891. * \deprecated It is deprecated and discouraged to call this function
  10892. * in #MBEDTLS_RSA_PUBLIC mode. Future versions of the library
  10893. * are likely to remove the \p mode argument and have it
  10894. * implicitly set to #MBEDTLS_RSA_PRIVATE.
  10895. *
  10896. * \note Alternative implementations of RSA need not support
  10897. * mode being set to #MBEDTLS_RSA_PUBLIC and might instead
  10898. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10899. *
  10900. * \param ctx The initialized RSA context to use.
  10901. * \param f_rng The RNG function. It must not be \c NULL.
  10902. * \param p_rng The RNG context to be passed to \p f_rng. This may be \c NULL
  10903. * if \p f_rng doesn't need a context argument.
  10904. * \param mode The mode of operation. This must be either
  10905. * #MBEDTLS_RSA_PRIVATE or #MBEDTLS_RSA_PUBLIC (deprecated).
  10906. * \param md_alg The message-digest algorithm used to hash the original data.
  10907. * Use #MBEDTLS_MD_NONE for signing raw data.
  10908. * \param hashlen The length of the message digest.
  10909. * This is only used if \p md_alg is #MBEDTLS_MD_NONE.
  10910. * \param hash The buffer holding the message digest or raw data.
  10911. * If \p md_alg is #MBEDTLS_MD_NONE, this must be a readable
  10912. * buffer of length \p hashlen Bytes. If \p md_alg is not
  10913. * #MBEDTLS_MD_NONE, it must be a readable buffer of length
  10914. * the size of the hash corresponding to \p md_alg.
  10915. * \param sig The buffer to hold the signature. This must be a writable
  10916. * buffer of length \c ctx->len Bytes. For example, \c 256 Bytes
  10917. * for an 2048-bit RSA modulus. A buffer length of
  10918. * #MBEDTLS_MPI_MAX_SIZE is always safe.
  10919. *
  10920. * \return \c 0 if the signing operation was successful.
  10921. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10922. */
  10923. int mbedtls_rsa_rsassa_pss_sign( mbedtls_rsa_context *ctx,
  10924. int (*f_rng)(void *, unsigned char *, size_t),
  10925. void *p_rng,
  10926. int mode,
  10927. mbedtls_md_type_t md_alg,
  10928. unsigned int hashlen,
  10929. const unsigned char *hash,
  10930. unsigned char *sig );
  10931. /**
  10932. * \brief This function performs a public RSA operation and checks
  10933. * the message digest.
  10934. *
  10935. * This is the generic wrapper for performing a PKCS#1
  10936. * verification using the mode from the context.
  10937. *
  10938. * \note For PKCS#1 v2.1 encoding, see comments on
  10939. * mbedtls_rsa_rsassa_pss_verify() about \p md_alg and
  10940. * \p hash_id.
  10941. *
  10942. * \deprecated It is deprecated and discouraged to call this function
  10943. * in #MBEDTLS_RSA_PRIVATE mode. Future versions of the library
  10944. * are likely to remove the \p mode argument and have it
  10945. * set to #MBEDTLS_RSA_PUBLIC.
  10946. *
  10947. * \note Alternative implementations of RSA need not support
  10948. * mode being set to #MBEDTLS_RSA_PRIVATE and might instead
  10949. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10950. *
  10951. * \param ctx The initialized RSA public key context to use.
  10952. * \param f_rng The RNG function to use. If \p mode is #MBEDTLS_RSA_PRIVATE,
  10953. * this is used for blinding and should be provided; see
  10954. * mbedtls_rsa_private() for more. Otherwise, it is ignored.
  10955. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  10956. * \c NULL if \p f_rng is \c NULL or doesn't need a context.
  10957. * \param mode The mode of operation. This must be either
  10958. * #MBEDTLS_RSA_PUBLIC or #MBEDTLS_RSA_PRIVATE (deprecated).
  10959. * \param md_alg The message-digest algorithm used to hash the original data.
  10960. * Use #MBEDTLS_MD_NONE for signing raw data.
  10961. * \param hashlen The length of the message digest.
  10962. * This is only used if \p md_alg is #MBEDTLS_MD_NONE.
  10963. * \param hash The buffer holding the message digest or raw data.
  10964. * If \p md_alg is #MBEDTLS_MD_NONE, this must be a readable
  10965. * buffer of length \p hashlen Bytes. If \p md_alg is not
  10966. * #MBEDTLS_MD_NONE, it must be a readable buffer of length
  10967. * the size of the hash corresponding to \p md_alg.
  10968. * \param sig The buffer holding the signature. This must be a readable
  10969. * buffer of length \c ctx->len Bytes. For example, \c 256 Bytes
  10970. * for an 2048-bit RSA modulus.
  10971. *
  10972. * \return \c 0 if the verify operation was successful.
  10973. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  10974. */
  10975. int mbedtls_rsa_pkcs1_verify( mbedtls_rsa_context *ctx,
  10976. int (*f_rng)(void *, unsigned char *, size_t),
  10977. void *p_rng,
  10978. int mode,
  10979. mbedtls_md_type_t md_alg,
  10980. unsigned int hashlen,
  10981. const unsigned char *hash,
  10982. const unsigned char *sig );
  10983. /**
  10984. * \brief This function performs a PKCS#1 v1.5 verification
  10985. * operation (RSASSA-PKCS1-v1_5-VERIFY).
  10986. *
  10987. * \deprecated It is deprecated and discouraged to call this function
  10988. * in #MBEDTLS_RSA_PRIVATE mode. Future versions of the library
  10989. * are likely to remove the \p mode argument and have it
  10990. * set to #MBEDTLS_RSA_PUBLIC.
  10991. *
  10992. * \note Alternative implementations of RSA need not support
  10993. * mode being set to #MBEDTLS_RSA_PRIVATE and might instead
  10994. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  10995. *
  10996. * \param ctx The initialized RSA public key context to use.
  10997. * \param f_rng The RNG function to use. If \p mode is #MBEDTLS_RSA_PRIVATE,
  10998. * this is used for blinding and should be provided; see
  10999. * mbedtls_rsa_private() for more. Otherwise, it is ignored.
  11000. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  11001. * \c NULL if \p f_rng is \c NULL or doesn't need a context.
  11002. * \param mode The mode of operation. This must be either
  11003. * #MBEDTLS_RSA_PUBLIC or #MBEDTLS_RSA_PRIVATE (deprecated).
  11004. * \param md_alg The message-digest algorithm used to hash the original data.
  11005. * Use #MBEDTLS_MD_NONE for signing raw data.
  11006. * \param hashlen The length of the message digest.
  11007. * This is only used if \p md_alg is #MBEDTLS_MD_NONE.
  11008. * \param hash The buffer holding the message digest or raw data.
  11009. * If \p md_alg is #MBEDTLS_MD_NONE, this must be a readable
  11010. * buffer of length \p hashlen Bytes. If \p md_alg is not
  11011. * #MBEDTLS_MD_NONE, it must be a readable buffer of length
  11012. * the size of the hash corresponding to \p md_alg.
  11013. * \param sig The buffer holding the signature. This must be a readable
  11014. * buffer of length \c ctx->len Bytes. For example, \c 256 Bytes
  11015. * for an 2048-bit RSA modulus.
  11016. *
  11017. * \return \c 0 if the verify operation was successful.
  11018. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  11019. */
  11020. int mbedtls_rsa_rsassa_pkcs1_v15_verify( mbedtls_rsa_context *ctx,
  11021. int (*f_rng)(void *, unsigned char *, size_t),
  11022. void *p_rng,
  11023. int mode,
  11024. mbedtls_md_type_t md_alg,
  11025. unsigned int hashlen,
  11026. const unsigned char *hash,
  11027. const unsigned char *sig );
  11028. /**
  11029. * \brief This function performs a PKCS#1 v2.1 PSS verification
  11030. * operation (RSASSA-PSS-VERIFY).
  11031. *
  11032. * \note The \c hash_id set in \p ctx (when calling
  11033. * mbedtls_rsa_init() or by calling mbedtls_rsa_set_padding()
  11034. * afterwards) selects the hash used for the
  11035. * encoding operation and for the mask generation function
  11036. * (MGF1). For more details on the encoding operation and the
  11037. * mask generation function, consult <em>RFC-3447: Public-Key
  11038. * Cryptography Standards (PKCS) #1 v2.1: RSA Cryptography
  11039. * Specifications</em>. If the \c hash_id set in \p ctx is
  11040. * #MBEDTLS_MD_NONE, the \p md_alg parameter is used.
  11041. *
  11042. * \deprecated It is deprecated and discouraged to call this function
  11043. * in #MBEDTLS_RSA_PRIVATE mode. Future versions of the library
  11044. * are likely to remove the \p mode argument and have it
  11045. * implicitly set to #MBEDTLS_RSA_PUBLIC.
  11046. *
  11047. * \note Alternative implementations of RSA need not support
  11048. * mode being set to #MBEDTLS_RSA_PRIVATE and might instead
  11049. * return #MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED.
  11050. *
  11051. * \param ctx The initialized RSA public key context to use.
  11052. * \param f_rng The RNG function to use. If \p mode is #MBEDTLS_RSA_PRIVATE,
  11053. * this is used for blinding and should be provided; see
  11054. * mbedtls_rsa_private() for more. Otherwise, it is ignored.
  11055. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  11056. * \c NULL if \p f_rng is \c NULL or doesn't need a context.
  11057. * \param mode The mode of operation. This must be either
  11058. * #MBEDTLS_RSA_PUBLIC or #MBEDTLS_RSA_PRIVATE (deprecated).
  11059. * \param md_alg The message-digest algorithm used to hash the original data.
  11060. * Use #MBEDTLS_MD_NONE for signing raw data.
  11061. * \param hashlen The length of the message digest.
  11062. * This is only used if \p md_alg is #MBEDTLS_MD_NONE.
  11063. * \param hash The buffer holding the message digest or raw data.
  11064. * If \p md_alg is #MBEDTLS_MD_NONE, this must be a readable
  11065. * buffer of length \p hashlen Bytes. If \p md_alg is not
  11066. * #MBEDTLS_MD_NONE, it must be a readable buffer of length
  11067. * the size of the hash corresponding to \p md_alg.
  11068. * \param sig The buffer holding the signature. This must be a readable
  11069. * buffer of length \c ctx->len Bytes. For example, \c 256 Bytes
  11070. * for an 2048-bit RSA modulus.
  11071. *
  11072. * \return \c 0 if the verify operation was successful.
  11073. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  11074. */
  11075. int mbedtls_rsa_rsassa_pss_verify( mbedtls_rsa_context *ctx,
  11076. int (*f_rng)(void *, unsigned char *, size_t),
  11077. void *p_rng,
  11078. int mode,
  11079. mbedtls_md_type_t md_alg,
  11080. unsigned int hashlen,
  11081. const unsigned char *hash,
  11082. const unsigned char *sig );
  11083. /**
  11084. * \brief This function performs a PKCS#1 v2.1 PSS verification
  11085. * operation (RSASSA-PSS-VERIFY).
  11086. *
  11087. * \note The \p sig buffer must be as large as the size
  11088. * of \p ctx->N. For example, 128 Bytes if RSA-1024 is used.
  11089. *
  11090. * \note The \c hash_id set in \p ctx (when calling
  11091. * mbedtls_rsa_init() or by calling mbedtls_rsa_set_padding()
  11092. * afterwards) is ignored.
  11093. *
  11094. * \param ctx The initialized RSA public key context to use.
  11095. * \param f_rng The RNG function to use. If \p mode is #MBEDTLS_RSA_PRIVATE,
  11096. * this is used for blinding and should be provided; see
  11097. * mbedtls_rsa_private() for more. Otherwise, it is ignored.
  11098. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  11099. * \c NULL if \p f_rng is \c NULL or doesn't need a context.
  11100. * \param mode The mode of operation. This must be either
  11101. * #MBEDTLS_RSA_PUBLIC or #MBEDTLS_RSA_PRIVATE.
  11102. * \param md_alg The message-digest algorithm used to hash the original data.
  11103. * Use #MBEDTLS_MD_NONE for signing raw data.
  11104. * \param hashlen The length of the message digest.
  11105. * This is only used if \p md_alg is #MBEDTLS_MD_NONE.
  11106. * \param hash The buffer holding the message digest or raw data.
  11107. * If \p md_alg is #MBEDTLS_MD_NONE, this must be a readable
  11108. * buffer of length \p hashlen Bytes. If \p md_alg is not
  11109. * #MBEDTLS_MD_NONE, it must be a readable buffer of length
  11110. * the size of the hash corresponding to \p md_alg.
  11111. * \param mgf1_hash_id The message digest algorithm used for the
  11112. * verification operation and the mask generation
  11113. * function (MGF1). For more details on the encoding
  11114. * operation and the mask generation function, consult
  11115. * <em>RFC-3447: Public-Key Cryptography Standards
  11116. * (PKCS) #1 v2.1: RSA Cryptography
  11117. * Specifications</em>.
  11118. * \param expected_salt_len The length of the salt used in padding. Use
  11119. * #MBEDTLS_RSA_SALT_LEN_ANY to accept any salt length.
  11120. * \param sig The buffer holding the signature. This must be a readable
  11121. * buffer of length \c ctx->len Bytes. For example, \c 256 Bytes
  11122. * for an 2048-bit RSA modulus.
  11123. *
  11124. * \return \c 0 if the verify operation was successful.
  11125. * \return An \c MBEDTLS_ERR_RSA_XXX error code on failure.
  11126. */
  11127. int mbedtls_rsa_rsassa_pss_verify_ext( mbedtls_rsa_context *ctx,
  11128. int (*f_rng)(void *, unsigned char *, size_t),
  11129. void *p_rng,
  11130. int mode,
  11131. mbedtls_md_type_t md_alg,
  11132. unsigned int hashlen,
  11133. const unsigned char *hash,
  11134. mbedtls_md_type_t mgf1_hash_id,
  11135. int expected_salt_len,
  11136. const unsigned char *sig );
  11137. /**
  11138. * \brief This function copies the components of an RSA context.
  11139. *
  11140. * \param dst The destination context. This must be initialized.
  11141. * \param src The source context. This must be initialized.
  11142. *
  11143. * \return \c 0 on success.
  11144. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory allocation failure.
  11145. */
  11146. int mbedtls_rsa_copy( mbedtls_rsa_context *dst, const mbedtls_rsa_context *src );
  11147. /**
  11148. * \brief This function frees the components of an RSA key.
  11149. *
  11150. * \param ctx The RSA context to free. May be \c NULL, in which case
  11151. * this function is a no-op. If it is not \c NULL, it must
  11152. * point to an initialized RSA context.
  11153. */
  11154. void mbedtls_rsa_free( mbedtls_rsa_context *ctx );
  11155. #if defined(MBEDTLS_SELF_TEST)
  11156. /**
  11157. * \brief The RSA checkup routine.
  11158. *
  11159. * \return \c 0 on success.
  11160. * \return \c 1 on failure.
  11161. */
  11162. int mbedtls_rsa_self_test( int verbose );
  11163. #endif /* MBEDTLS_SELF_TEST */
  11164. #ifdef __cplusplus
  11165. }
  11166. #endif
  11167. #endif /* rsa.h */
  11168. /********* Start of file include/mbedtls/rsa_internal.h ************/
  11169. /**
  11170. * \file rsa_internal.h
  11171. *
  11172. * \brief Context-independent RSA helper functions
  11173. *
  11174. * This module declares some RSA-related helper functions useful when
  11175. * implementing the RSA interface. These functions are provided in a separate
  11176. * compilation unit in order to make it easy for designers of alternative RSA
  11177. * implementations to use them in their own code, as it is conceived that the
  11178. * functionality they provide will be necessary for most complete
  11179. * implementations.
  11180. *
  11181. * End-users of Mbed TLS who are not providing their own alternative RSA
  11182. * implementations should not use these functions directly, and should instead
  11183. * use only the functions declared in rsa.h.
  11184. *
  11185. * The interface provided by this module will be maintained through LTS (Long
  11186. * Term Support) branches of Mbed TLS, but may otherwise be subject to change,
  11187. * and must be considered an internal interface of the library.
  11188. *
  11189. * There are two classes of helper functions:
  11190. *
  11191. * (1) Parameter-generating helpers. These are:
  11192. * - mbedtls_rsa_deduce_primes
  11193. * - mbedtls_rsa_deduce_private_exponent
  11194. * - mbedtls_rsa_deduce_crt
  11195. * Each of these functions takes a set of core RSA parameters and
  11196. * generates some other, or CRT related parameters.
  11197. *
  11198. * (2) Parameter-checking helpers. These are:
  11199. * - mbedtls_rsa_validate_params
  11200. * - mbedtls_rsa_validate_crt
  11201. * They take a set of core or CRT related RSA parameters and check their
  11202. * validity.
  11203. *
  11204. */
  11205. /*
  11206. * Copyright The Mbed TLS Contributors
  11207. * SPDX-License-Identifier: Apache-2.0
  11208. *
  11209. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  11210. * not use this file except in compliance with the License.
  11211. * You may obtain a copy of the License at
  11212. *
  11213. * http://www.apache.org/licenses/LICENSE-2.0
  11214. *
  11215. * Unless required by applicable law or agreed to in writing, software
  11216. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  11217. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  11218. * See the License for the specific language governing permissions and
  11219. * limitations under the License.
  11220. *
  11221. */
  11222. #ifndef MBEDTLS_RSA_INTERNAL_H
  11223. #define MBEDTLS_RSA_INTERNAL_H
  11224. #if !defined(MBEDTLS_CONFIG_FILE)
  11225. #else
  11226. #endif
  11227. #ifdef __cplusplus
  11228. extern "C" {
  11229. #endif
  11230. /**
  11231. * \brief Compute RSA prime moduli P, Q from public modulus N=PQ
  11232. * and a pair of private and public key.
  11233. *
  11234. * \note This is a 'static' helper function not operating on
  11235. * an RSA context. Alternative implementations need not
  11236. * overwrite it.
  11237. *
  11238. * \param N RSA modulus N = PQ, with P, Q to be found
  11239. * \param E RSA public exponent
  11240. * \param D RSA private exponent
  11241. * \param P Pointer to MPI holding first prime factor of N on success
  11242. * \param Q Pointer to MPI holding second prime factor of N on success
  11243. *
  11244. * \return
  11245. * - 0 if successful. In this case, P and Q constitute a
  11246. * factorization of N.
  11247. * - A non-zero error code otherwise.
  11248. *
  11249. * \note It is neither checked that P, Q are prime nor that
  11250. * D, E are modular inverses wrt. P-1 and Q-1. For that,
  11251. * use the helper function \c mbedtls_rsa_validate_params.
  11252. *
  11253. */
  11254. int mbedtls_rsa_deduce_primes( mbedtls_mpi const *N, mbedtls_mpi const *E,
  11255. mbedtls_mpi const *D,
  11256. mbedtls_mpi *P, mbedtls_mpi *Q );
  11257. /**
  11258. * \brief Compute RSA private exponent from
  11259. * prime moduli and public key.
  11260. *
  11261. * \note This is a 'static' helper function not operating on
  11262. * an RSA context. Alternative implementations need not
  11263. * overwrite it.
  11264. *
  11265. * \param P First prime factor of RSA modulus
  11266. * \param Q Second prime factor of RSA modulus
  11267. * \param E RSA public exponent
  11268. * \param D Pointer to MPI holding the private exponent on success.
  11269. *
  11270. * \return
  11271. * - 0 if successful. In this case, D is set to a simultaneous
  11272. * modular inverse of E modulo both P-1 and Q-1.
  11273. * - A non-zero error code otherwise.
  11274. *
  11275. * \note This function does not check whether P and Q are primes.
  11276. *
  11277. */
  11278. int mbedtls_rsa_deduce_private_exponent( mbedtls_mpi const *P,
  11279. mbedtls_mpi const *Q,
  11280. mbedtls_mpi const *E,
  11281. mbedtls_mpi *D );
  11282. /**
  11283. * \brief Generate RSA-CRT parameters
  11284. *
  11285. * \note This is a 'static' helper function not operating on
  11286. * an RSA context. Alternative implementations need not
  11287. * overwrite it.
  11288. *
  11289. * \param P First prime factor of N
  11290. * \param Q Second prime factor of N
  11291. * \param D RSA private exponent
  11292. * \param DP Output variable for D modulo P-1
  11293. * \param DQ Output variable for D modulo Q-1
  11294. * \param QP Output variable for the modular inverse of Q modulo P.
  11295. *
  11296. * \return 0 on success, non-zero error code otherwise.
  11297. *
  11298. * \note This function does not check whether P, Q are
  11299. * prime and whether D is a valid private exponent.
  11300. *
  11301. */
  11302. int mbedtls_rsa_deduce_crt( const mbedtls_mpi *P, const mbedtls_mpi *Q,
  11303. const mbedtls_mpi *D, mbedtls_mpi *DP,
  11304. mbedtls_mpi *DQ, mbedtls_mpi *QP );
  11305. /**
  11306. * \brief Check validity of core RSA parameters
  11307. *
  11308. * \note This is a 'static' helper function not operating on
  11309. * an RSA context. Alternative implementations need not
  11310. * overwrite it.
  11311. *
  11312. * \param N RSA modulus N = PQ
  11313. * \param P First prime factor of N
  11314. * \param Q Second prime factor of N
  11315. * \param D RSA private exponent
  11316. * \param E RSA public exponent
  11317. * \param f_rng PRNG to be used for primality check, or NULL
  11318. * \param p_rng PRNG context for f_rng, or NULL
  11319. *
  11320. * \return
  11321. * - 0 if the following conditions are satisfied
  11322. * if all relevant parameters are provided:
  11323. * - P prime if f_rng != NULL (%)
  11324. * - Q prime if f_rng != NULL (%)
  11325. * - 1 < N = P * Q
  11326. * - 1 < D, E < N
  11327. * - D and E are modular inverses modulo P-1 and Q-1
  11328. * (%) This is only done if MBEDTLS_GENPRIME is defined.
  11329. * - A non-zero error code otherwise.
  11330. *
  11331. * \note The function can be used with a restricted set of arguments
  11332. * to perform specific checks only. E.g., calling it with
  11333. * (-,P,-,-,-) and a PRNG amounts to a primality check for P.
  11334. */
  11335. int mbedtls_rsa_validate_params( const mbedtls_mpi *N, const mbedtls_mpi *P,
  11336. const mbedtls_mpi *Q, const mbedtls_mpi *D,
  11337. const mbedtls_mpi *E,
  11338. int (*f_rng)(void *, unsigned char *, size_t),
  11339. void *p_rng );
  11340. /**
  11341. * \brief Check validity of RSA CRT parameters
  11342. *
  11343. * \note This is a 'static' helper function not operating on
  11344. * an RSA context. Alternative implementations need not
  11345. * overwrite it.
  11346. *
  11347. * \param P First prime factor of RSA modulus
  11348. * \param Q Second prime factor of RSA modulus
  11349. * \param D RSA private exponent
  11350. * \param DP MPI to check for D modulo P-1
  11351. * \param DQ MPI to check for D modulo P-1
  11352. * \param QP MPI to check for the modular inverse of Q modulo P.
  11353. *
  11354. * \return
  11355. * - 0 if the following conditions are satisfied:
  11356. * - D = DP mod P-1 if P, D, DP != NULL
  11357. * - Q = DQ mod P-1 if P, D, DQ != NULL
  11358. * - QP = Q^-1 mod P if P, Q, QP != NULL
  11359. * - \c MBEDTLS_ERR_RSA_KEY_CHECK_FAILED if check failed,
  11360. * potentially including \c MBEDTLS_ERR_MPI_XXX if some
  11361. * MPI calculations failed.
  11362. * - \c MBEDTLS_ERR_RSA_BAD_INPUT_DATA if insufficient
  11363. * data was provided to check DP, DQ or QP.
  11364. *
  11365. * \note The function can be used with a restricted set of arguments
  11366. * to perform specific checks only. E.g., calling it with the
  11367. * parameters (P, -, D, DP, -, -) will check DP = D mod P-1.
  11368. */
  11369. int mbedtls_rsa_validate_crt( const mbedtls_mpi *P, const mbedtls_mpi *Q,
  11370. const mbedtls_mpi *D, const mbedtls_mpi *DP,
  11371. const mbedtls_mpi *DQ, const mbedtls_mpi *QP );
  11372. #ifdef __cplusplus
  11373. }
  11374. #endif
  11375. #endif /* rsa_internal.h */
  11376. /********* Start of file include/mbedtls/asn1.h ************/
  11377. /**
  11378. * \file asn1.h
  11379. *
  11380. * \brief Generic ASN.1 parsing
  11381. */
  11382. /*
  11383. * Copyright The Mbed TLS Contributors
  11384. * SPDX-License-Identifier: Apache-2.0
  11385. *
  11386. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  11387. * not use this file except in compliance with the License.
  11388. * You may obtain a copy of the License at
  11389. *
  11390. * http://www.apache.org/licenses/LICENSE-2.0
  11391. *
  11392. * Unless required by applicable law or agreed to in writing, software
  11393. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  11394. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  11395. * See the License for the specific language governing permissions and
  11396. * limitations under the License.
  11397. */
  11398. #ifndef MBEDTLS_ASN1_H
  11399. #define MBEDTLS_ASN1_H
  11400. #if !defined(MBEDTLS_CONFIG_FILE)
  11401. #else
  11402. #endif
  11403. #include <stddef.h>
  11404. #if defined(MBEDTLS_BIGNUM_C)
  11405. #endif
  11406. /**
  11407. * \addtogroup asn1_module
  11408. * \{
  11409. */
  11410. /**
  11411. * \name ASN1 Error codes
  11412. * These error codes are OR'ed to X509 error codes for
  11413. * higher error granularity.
  11414. * ASN1 is a standard to specify data structures.
  11415. * \{
  11416. */
  11417. /** Out of data when parsing an ASN1 data structure. */
  11418. #define MBEDTLS_ERR_ASN1_OUT_OF_DATA -0x0060
  11419. /** ASN1 tag was of an unexpected value. */
  11420. #define MBEDTLS_ERR_ASN1_UNEXPECTED_TAG -0x0062
  11421. /** Error when trying to determine the length or invalid length. */
  11422. #define MBEDTLS_ERR_ASN1_INVALID_LENGTH -0x0064
  11423. /** Actual length differs from expected length. */
  11424. #define MBEDTLS_ERR_ASN1_LENGTH_MISMATCH -0x0066
  11425. /** Data is invalid. */
  11426. #define MBEDTLS_ERR_ASN1_INVALID_DATA -0x0068
  11427. /** Memory allocation failed */
  11428. #define MBEDTLS_ERR_ASN1_ALLOC_FAILED -0x006A
  11429. /** Buffer too small when writing ASN.1 data structure. */
  11430. #define MBEDTLS_ERR_ASN1_BUF_TOO_SMALL -0x006C
  11431. /* \} name */
  11432. /**
  11433. * \name DER constants
  11434. * These constants comply with the DER encoded ASN.1 type tags.
  11435. * DER encoding uses hexadecimal representation.
  11436. * An example DER sequence is:\n
  11437. * - 0x02 -- tag indicating INTEGER
  11438. * - 0x01 -- length in octets
  11439. * - 0x05 -- value
  11440. * Such sequences are typically read into \c ::mbedtls_x509_buf.
  11441. * \{
  11442. */
  11443. #define MBEDTLS_ASN1_BOOLEAN 0x01
  11444. #define MBEDTLS_ASN1_INTEGER 0x02
  11445. #define MBEDTLS_ASN1_BIT_STRING 0x03
  11446. #define MBEDTLS_ASN1_OCTET_STRING 0x04
  11447. #define MBEDTLS_ASN1_NULL 0x05
  11448. #define MBEDTLS_ASN1_OID 0x06
  11449. #define MBEDTLS_ASN1_ENUMERATED 0x0A
  11450. #define MBEDTLS_ASN1_UTF8_STRING 0x0C
  11451. #define MBEDTLS_ASN1_SEQUENCE 0x10
  11452. #define MBEDTLS_ASN1_SET 0x11
  11453. #define MBEDTLS_ASN1_PRINTABLE_STRING 0x13
  11454. #define MBEDTLS_ASN1_T61_STRING 0x14
  11455. #define MBEDTLS_ASN1_IA5_STRING 0x16
  11456. #define MBEDTLS_ASN1_UTC_TIME 0x17
  11457. #define MBEDTLS_ASN1_GENERALIZED_TIME 0x18
  11458. #define MBEDTLS_ASN1_UNIVERSAL_STRING 0x1C
  11459. #define MBEDTLS_ASN1_BMP_STRING 0x1E
  11460. #define MBEDTLS_ASN1_PRIMITIVE 0x00
  11461. #define MBEDTLS_ASN1_CONSTRUCTED 0x20
  11462. #define MBEDTLS_ASN1_CONTEXT_SPECIFIC 0x80
  11463. /* Slightly smaller way to check if tag is a string tag
  11464. * compared to canonical implementation. */
  11465. #define MBEDTLS_ASN1_IS_STRING_TAG( tag ) \
  11466. ( ( tag ) < 32u && ( \
  11467. ( ( 1u << ( tag ) ) & ( ( 1u << MBEDTLS_ASN1_BMP_STRING ) | \
  11468. ( 1u << MBEDTLS_ASN1_UTF8_STRING ) | \
  11469. ( 1u << MBEDTLS_ASN1_T61_STRING ) | \
  11470. ( 1u << MBEDTLS_ASN1_IA5_STRING ) | \
  11471. ( 1u << MBEDTLS_ASN1_UNIVERSAL_STRING ) | \
  11472. ( 1u << MBEDTLS_ASN1_PRINTABLE_STRING ) | \
  11473. ( 1u << MBEDTLS_ASN1_BIT_STRING ) ) ) != 0 ) )
  11474. /*
  11475. * Bit masks for each of the components of an ASN.1 tag as specified in
  11476. * ITU X.690 (08/2015), section 8.1 "General rules for encoding",
  11477. * paragraph 8.1.2.2:
  11478. *
  11479. * Bit 8 7 6 5 1
  11480. * +-------+-----+------------+
  11481. * | Class | P/C | Tag number |
  11482. * +-------+-----+------------+
  11483. */
  11484. #define MBEDTLS_ASN1_TAG_CLASS_MASK 0xC0
  11485. #define MBEDTLS_ASN1_TAG_PC_MASK 0x20
  11486. #define MBEDTLS_ASN1_TAG_VALUE_MASK 0x1F
  11487. /* \} name */
  11488. /* \} addtogroup asn1_module */
  11489. /** Returns the size of the binary string, without the trailing \\0 */
  11490. #define MBEDTLS_OID_SIZE(x) (sizeof(x) - 1)
  11491. /**
  11492. * Compares an mbedtls_asn1_buf structure to a reference OID.
  11493. *
  11494. * Only works for 'defined' oid_str values (MBEDTLS_OID_HMAC_SHA1), you cannot use a
  11495. * 'unsigned char *oid' here!
  11496. */
  11497. #define MBEDTLS_OID_CMP(oid_str, oid_buf) \
  11498. ( ( MBEDTLS_OID_SIZE(oid_str) != (oid_buf)->len ) || \
  11499. memcmp( (oid_str), (oid_buf)->p, (oid_buf)->len) != 0 )
  11500. #define MBEDTLS_OID_CMP_RAW(oid_str, oid_buf, oid_buf_len) \
  11501. ( ( MBEDTLS_OID_SIZE(oid_str) != (oid_buf_len) ) || \
  11502. memcmp( (oid_str), (oid_buf), (oid_buf_len) ) != 0 )
  11503. #ifdef __cplusplus
  11504. extern "C" {
  11505. #endif
  11506. /**
  11507. * \name Functions to parse ASN.1 data structures
  11508. * \{
  11509. */
  11510. /**
  11511. * Type-length-value structure that allows for ASN1 using DER.
  11512. */
  11513. typedef struct mbedtls_asn1_buf
  11514. {
  11515. int tag; /**< ASN1 type, e.g. MBEDTLS_ASN1_UTF8_STRING. */
  11516. size_t len; /**< ASN1 length, in octets. */
  11517. unsigned char *p; /**< ASN1 data, e.g. in ASCII. */
  11518. }
  11519. mbedtls_asn1_buf;
  11520. /**
  11521. * Container for ASN1 bit strings.
  11522. */
  11523. typedef struct mbedtls_asn1_bitstring
  11524. {
  11525. size_t len; /**< ASN1 length, in octets. */
  11526. unsigned char unused_bits; /**< Number of unused bits at the end of the string */
  11527. unsigned char *p; /**< Raw ASN1 data for the bit string */
  11528. }
  11529. mbedtls_asn1_bitstring;
  11530. /**
  11531. * Container for a sequence of ASN.1 items
  11532. */
  11533. typedef struct mbedtls_asn1_sequence
  11534. {
  11535. mbedtls_asn1_buf buf; /**< Buffer containing the given ASN.1 item. */
  11536. struct mbedtls_asn1_sequence *next; /**< The next entry in the sequence. */
  11537. }
  11538. mbedtls_asn1_sequence;
  11539. /**
  11540. * Container for a sequence or list of 'named' ASN.1 data items
  11541. */
  11542. typedef struct mbedtls_asn1_named_data
  11543. {
  11544. mbedtls_asn1_buf oid; /**< The object identifier. */
  11545. mbedtls_asn1_buf val; /**< The named value. */
  11546. struct mbedtls_asn1_named_data *next; /**< The next entry in the sequence. */
  11547. unsigned char next_merged; /**< Merge next item into the current one? */
  11548. }
  11549. mbedtls_asn1_named_data;
  11550. /**
  11551. * \brief Get the length of an ASN.1 element.
  11552. * Updates the pointer to immediately behind the length.
  11553. *
  11554. * \param p On entry, \c *p points to the first byte of the length,
  11555. * i.e. immediately after the tag.
  11556. * On successful completion, \c *p points to the first byte
  11557. * after the length, i.e. the first byte of the content.
  11558. * On error, the value of \c *p is undefined.
  11559. * \param end End of data.
  11560. * \param len On successful completion, \c *len contains the length
  11561. * read from the ASN.1 input.
  11562. *
  11563. * \return 0 if successful.
  11564. * \return #MBEDTLS_ERR_ASN1_OUT_OF_DATA if the ASN.1 element
  11565. * would end beyond \p end.
  11566. * \return #MBEDTLS_ERR_ASN1_INVALID_LENGTH if the length is unparseable.
  11567. */
  11568. int mbedtls_asn1_get_len( unsigned char **p,
  11569. const unsigned char *end,
  11570. size_t *len );
  11571. /**
  11572. * \brief Get the tag and length of the element.
  11573. * Check for the requested tag.
  11574. * Updates the pointer to immediately behind the tag and length.
  11575. *
  11576. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11577. * On successful completion, \c *p points to the first byte
  11578. * after the length, i.e. the first byte of the content.
  11579. * On error, the value of \c *p is undefined.
  11580. * \param end End of data.
  11581. * \param len On successful completion, \c *len contains the length
  11582. * read from the ASN.1 input.
  11583. * \param tag The expected tag.
  11584. *
  11585. * \return 0 if successful.
  11586. * \return #MBEDTLS_ERR_ASN1_UNEXPECTED_TAG if the data does not start
  11587. * with the requested tag.
  11588. * \return #MBEDTLS_ERR_ASN1_OUT_OF_DATA if the ASN.1 element
  11589. * would end beyond \p end.
  11590. * \return #MBEDTLS_ERR_ASN1_INVALID_LENGTH if the length is unparseable.
  11591. */
  11592. int mbedtls_asn1_get_tag( unsigned char **p,
  11593. const unsigned char *end,
  11594. size_t *len, int tag );
  11595. /**
  11596. * \brief Retrieve a boolean ASN.1 tag and its value.
  11597. * Updates the pointer to immediately behind the full tag.
  11598. *
  11599. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11600. * On successful completion, \c *p points to the first byte
  11601. * beyond the ASN.1 element.
  11602. * On error, the value of \c *p is undefined.
  11603. * \param end End of data.
  11604. * \param val On success, the parsed value (\c 0 or \c 1).
  11605. *
  11606. * \return 0 if successful.
  11607. * \return An ASN.1 error code if the input does not start with
  11608. * a valid ASN.1 BOOLEAN.
  11609. */
  11610. int mbedtls_asn1_get_bool( unsigned char **p,
  11611. const unsigned char *end,
  11612. int *val );
  11613. /**
  11614. * \brief Retrieve an integer ASN.1 tag and its value.
  11615. * Updates the pointer to immediately behind the full tag.
  11616. *
  11617. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11618. * On successful completion, \c *p points to the first byte
  11619. * beyond the ASN.1 element.
  11620. * On error, the value of \c *p is undefined.
  11621. * \param end End of data.
  11622. * \param val On success, the parsed value.
  11623. *
  11624. * \return 0 if successful.
  11625. * \return An ASN.1 error code if the input does not start with
  11626. * a valid ASN.1 INTEGER.
  11627. * \return #MBEDTLS_ERR_ASN1_INVALID_LENGTH if the parsed value does
  11628. * not fit in an \c int.
  11629. */
  11630. int mbedtls_asn1_get_int( unsigned char **p,
  11631. const unsigned char *end,
  11632. int *val );
  11633. /**
  11634. * \brief Retrieve an enumerated ASN.1 tag and its value.
  11635. * Updates the pointer to immediately behind the full tag.
  11636. *
  11637. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11638. * On successful completion, \c *p points to the first byte
  11639. * beyond the ASN.1 element.
  11640. * On error, the value of \c *p is undefined.
  11641. * \param end End of data.
  11642. * \param val On success, the parsed value.
  11643. *
  11644. * \return 0 if successful.
  11645. * \return An ASN.1 error code if the input does not start with
  11646. * a valid ASN.1 ENUMERATED.
  11647. * \return #MBEDTLS_ERR_ASN1_INVALID_LENGTH if the parsed value does
  11648. * not fit in an \c int.
  11649. */
  11650. int mbedtls_asn1_get_enum( unsigned char **p,
  11651. const unsigned char *end,
  11652. int *val );
  11653. /**
  11654. * \brief Retrieve a bitstring ASN.1 tag and its value.
  11655. * Updates the pointer to immediately behind the full tag.
  11656. *
  11657. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11658. * On successful completion, \c *p is equal to \p end.
  11659. * On error, the value of \c *p is undefined.
  11660. * \param end End of data.
  11661. * \param bs On success, ::mbedtls_asn1_bitstring information about
  11662. * the parsed value.
  11663. *
  11664. * \return 0 if successful.
  11665. * \return #MBEDTLS_ERR_ASN1_LENGTH_MISMATCH if the input contains
  11666. * extra data after a valid BIT STRING.
  11667. * \return An ASN.1 error code if the input does not start with
  11668. * a valid ASN.1 BIT STRING.
  11669. */
  11670. int mbedtls_asn1_get_bitstring( unsigned char **p, const unsigned char *end,
  11671. mbedtls_asn1_bitstring *bs );
  11672. /**
  11673. * \brief Retrieve a bitstring ASN.1 tag without unused bits and its
  11674. * value.
  11675. * Updates the pointer to the beginning of the bit/octet string.
  11676. *
  11677. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11678. * On successful completion, \c *p points to the first byte
  11679. * of the content of the BIT STRING.
  11680. * On error, the value of \c *p is undefined.
  11681. * \param end End of data.
  11682. * \param len On success, \c *len is the length of the content in bytes.
  11683. *
  11684. * \return 0 if successful.
  11685. * \return #MBEDTLS_ERR_ASN1_INVALID_DATA if the input starts with
  11686. * a valid BIT STRING with a nonzero number of unused bits.
  11687. * \return An ASN.1 error code if the input does not start with
  11688. * a valid ASN.1 BIT STRING.
  11689. */
  11690. int mbedtls_asn1_get_bitstring_null( unsigned char **p,
  11691. const unsigned char *end,
  11692. size_t *len );
  11693. /**
  11694. * \brief Parses and splits an ASN.1 "SEQUENCE OF <tag>".
  11695. * Updates the pointer to immediately behind the full sequence tag.
  11696. *
  11697. * This function allocates memory for the sequence elements. You can free
  11698. * the allocated memory with mbedtls_asn1_sequence_free().
  11699. *
  11700. * \note On error, this function may return a partial list in \p cur.
  11701. * You must set `cur->next = NULL` before calling this function!
  11702. * Otherwise it is impossible to distinguish a previously non-null
  11703. * pointer from a pointer to an object allocated by this function.
  11704. *
  11705. * \note If the sequence is empty, this function does not modify
  11706. * \c *cur. If the sequence is valid and non-empty, this
  11707. * function sets `cur->buf.tag` to \p tag. This allows
  11708. * callers to distinguish between an empty sequence and
  11709. * a one-element sequence.
  11710. *
  11711. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11712. * On successful completion, \c *p is equal to \p end.
  11713. * On error, the value of \c *p is undefined.
  11714. * \param end End of data.
  11715. * \param cur A ::mbedtls_asn1_sequence which this function fills.
  11716. * When this function returns, \c *cur is the head of a linked
  11717. * list. Each node in this list is allocated with
  11718. * mbedtls_calloc() apart from \p cur itself, and should
  11719. * therefore be freed with mbedtls_free().
  11720. * The list describes the content of the sequence.
  11721. * The head of the list (i.e. \c *cur itself) describes the
  11722. * first element, `*cur->next` describes the second element, etc.
  11723. * For each element, `buf.tag == tag`, `buf.len` is the length
  11724. * of the content of the content of the element, and `buf.p`
  11725. * points to the first byte of the content (i.e. immediately
  11726. * past the length of the element).
  11727. * Note that list elements may be allocated even on error.
  11728. * \param tag Each element of the sequence must have this tag.
  11729. *
  11730. * \return 0 if successful.
  11731. * \return #MBEDTLS_ERR_ASN1_LENGTH_MISMATCH if the input contains
  11732. * extra data after a valid SEQUENCE OF \p tag.
  11733. * \return #MBEDTLS_ERR_ASN1_UNEXPECTED_TAG if the input starts with
  11734. * an ASN.1 SEQUENCE in which an element has a tag that
  11735. * is different from \p tag.
  11736. * \return #MBEDTLS_ERR_ASN1_ALLOC_FAILED if a memory allocation failed.
  11737. * \return An ASN.1 error code if the input does not start with
  11738. * a valid ASN.1 SEQUENCE.
  11739. */
  11740. int mbedtls_asn1_get_sequence_of( unsigned char **p,
  11741. const unsigned char *end,
  11742. mbedtls_asn1_sequence *cur,
  11743. int tag );
  11744. /**
  11745. * \brief Free a heap-allocated linked list presentation of
  11746. * an ASN.1 sequence, including the first element.
  11747. *
  11748. * There are two common ways to manage the memory used for the representation
  11749. * of a parsed ASN.1 sequence:
  11750. * - Allocate a head node `mbedtls_asn1_sequence *head` with mbedtls_calloc().
  11751. * Pass this node as the `cur` argument to mbedtls_asn1_get_sequence_of().
  11752. * When you have finished processing the sequence,
  11753. * call mbedtls_asn1_sequence_free() on `head`.
  11754. * - Allocate a head node `mbedtls_asn1_sequence *head` in any manner,
  11755. * for example on the stack. Make sure that `head->next == NULL`.
  11756. * Pass `head` as the `cur` argument to mbedtls_asn1_get_sequence_of().
  11757. * When you have finished processing the sequence,
  11758. * call mbedtls_asn1_sequence_free() on `head->cur`,
  11759. * then free `head` itself in the appropriate manner.
  11760. *
  11761. * \param seq The address of the first sequence component. This may
  11762. * be \c NULL, in which case this functions returns
  11763. * immediately.
  11764. */
  11765. void mbedtls_asn1_sequence_free( mbedtls_asn1_sequence *seq );
  11766. /**
  11767. * \brief Traverse an ASN.1 SEQUENCE container and
  11768. * call a callback for each entry.
  11769. *
  11770. * This function checks that the input is a SEQUENCE of elements that
  11771. * each have a "must" tag, and calls a callback function on the elements
  11772. * that have a "may" tag.
  11773. *
  11774. * For example, to validate that the input is a SEQUENCE of `tag1` and call
  11775. * `cb` on each element, use
  11776. * ```
  11777. * mbedtls_asn1_traverse_sequence_of(&p, end, 0xff, tag1, 0, 0, cb, ctx);
  11778. * ```
  11779. *
  11780. * To validate that the input is a SEQUENCE of ANY and call `cb` on
  11781. * each element, use
  11782. * ```
  11783. * mbedtls_asn1_traverse_sequence_of(&p, end, 0, 0, 0, 0, cb, ctx);
  11784. * ```
  11785. *
  11786. * To validate that the input is a SEQUENCE of CHOICE {NULL, OCTET STRING}
  11787. * and call `cb` on each element that is an OCTET STRING, use
  11788. * ```
  11789. * mbedtls_asn1_traverse_sequence_of(&p, end, 0xfe, 0x04, 0xff, 0x04, cb, ctx);
  11790. * ```
  11791. *
  11792. * The callback is called on the elements with a "may" tag from left to
  11793. * right. If the input is not a valid SEQUENCE of elements with a "must" tag,
  11794. * the callback is called on the elements up to the leftmost point where
  11795. * the input is invalid.
  11796. *
  11797. * \warning This function is still experimental and may change
  11798. * at any time.
  11799. *
  11800. * \param p The address of the pointer to the beginning of
  11801. * the ASN.1 SEQUENCE header. This is updated to
  11802. * point to the end of the ASN.1 SEQUENCE container
  11803. * on a successful invocation.
  11804. * \param end The end of the ASN.1 SEQUENCE container.
  11805. * \param tag_must_mask A mask to be applied to the ASN.1 tags found within
  11806. * the SEQUENCE before comparing to \p tag_must_value.
  11807. * \param tag_must_val The required value of each ASN.1 tag found in the
  11808. * SEQUENCE, after masking with \p tag_must_mask.
  11809. * Mismatching tags lead to an error.
  11810. * For example, a value of \c 0 for both \p tag_must_mask
  11811. * and \p tag_must_val means that every tag is allowed,
  11812. * while a value of \c 0xFF for \p tag_must_mask means
  11813. * that \p tag_must_val is the only allowed tag.
  11814. * \param tag_may_mask A mask to be applied to the ASN.1 tags found within
  11815. * the SEQUENCE before comparing to \p tag_may_value.
  11816. * \param tag_may_val The desired value of each ASN.1 tag found in the
  11817. * SEQUENCE, after masking with \p tag_may_mask.
  11818. * Mismatching tags will be silently ignored.
  11819. * For example, a value of \c 0 for \p tag_may_mask and
  11820. * \p tag_may_val means that any tag will be considered,
  11821. * while a value of \c 0xFF for \p tag_may_mask means
  11822. * that all tags with value different from \p tag_may_val
  11823. * will be ignored.
  11824. * \param cb The callback to trigger for each component
  11825. * in the ASN.1 SEQUENCE that matches \p tag_may_val.
  11826. * The callback function is called with the following
  11827. * parameters:
  11828. * - \p ctx.
  11829. * - The tag of the current element.
  11830. * - A pointer to the start of the current element's
  11831. * content inside the input.
  11832. * - The length of the content of the current element.
  11833. * If the callback returns a non-zero value,
  11834. * the function stops immediately,
  11835. * forwarding the callback's return value.
  11836. * \param ctx The context to be passed to the callback \p cb.
  11837. *
  11838. * \return \c 0 if successful the entire ASN.1 SEQUENCE
  11839. * was traversed without parsing or callback errors.
  11840. * \return #MBEDTLS_ERR_ASN1_LENGTH_MISMATCH if the input
  11841. * contains extra data after a valid SEQUENCE
  11842. * of elements with an accepted tag.
  11843. * \return #MBEDTLS_ERR_ASN1_UNEXPECTED_TAG if the input starts
  11844. * with an ASN.1 SEQUENCE in which an element has a tag
  11845. * that is not accepted.
  11846. * \return An ASN.1 error code if the input does not start with
  11847. * a valid ASN.1 SEQUENCE.
  11848. * \return A non-zero error code forwarded from the callback
  11849. * \p cb in case the latter returns a non-zero value.
  11850. */
  11851. int mbedtls_asn1_traverse_sequence_of(
  11852. unsigned char **p,
  11853. const unsigned char *end,
  11854. unsigned char tag_must_mask, unsigned char tag_must_val,
  11855. unsigned char tag_may_mask, unsigned char tag_may_val,
  11856. int (*cb)( void *ctx, int tag,
  11857. unsigned char* start, size_t len ),
  11858. void *ctx );
  11859. #if defined(MBEDTLS_BIGNUM_C)
  11860. /**
  11861. * \brief Retrieve an integer ASN.1 tag and its value.
  11862. * Updates the pointer to immediately behind the full tag.
  11863. *
  11864. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11865. * On successful completion, \c *p points to the first byte
  11866. * beyond the ASN.1 element.
  11867. * On error, the value of \c *p is undefined.
  11868. * \param end End of data.
  11869. * \param X On success, the parsed value.
  11870. *
  11871. * \return 0 if successful.
  11872. * \return An ASN.1 error code if the input does not start with
  11873. * a valid ASN.1 INTEGER.
  11874. * \return #MBEDTLS_ERR_ASN1_INVALID_LENGTH if the parsed value does
  11875. * not fit in an \c int.
  11876. * \return An MPI error code if the parsed value is too large.
  11877. */
  11878. int mbedtls_asn1_get_mpi( unsigned char **p,
  11879. const unsigned char *end,
  11880. mbedtls_mpi *X );
  11881. #endif /* MBEDTLS_BIGNUM_C */
  11882. /**
  11883. * \brief Retrieve an AlgorithmIdentifier ASN.1 sequence.
  11884. * Updates the pointer to immediately behind the full
  11885. * AlgorithmIdentifier.
  11886. *
  11887. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11888. * On successful completion, \c *p points to the first byte
  11889. * beyond the AlgorithmIdentifier element.
  11890. * On error, the value of \c *p is undefined.
  11891. * \param end End of data.
  11892. * \param alg The buffer to receive the OID.
  11893. * \param params The buffer to receive the parameters.
  11894. * This is zeroized if there are no parameters.
  11895. *
  11896. * \return 0 if successful or a specific ASN.1 or MPI error code.
  11897. */
  11898. int mbedtls_asn1_get_alg( unsigned char **p,
  11899. const unsigned char *end,
  11900. mbedtls_asn1_buf *alg, mbedtls_asn1_buf *params );
  11901. /**
  11902. * \brief Retrieve an AlgorithmIdentifier ASN.1 sequence with NULL or no
  11903. * params.
  11904. * Updates the pointer to immediately behind the full
  11905. * AlgorithmIdentifier.
  11906. *
  11907. * \param p On entry, \c *p points to the start of the ASN.1 element.
  11908. * On successful completion, \c *p points to the first byte
  11909. * beyond the AlgorithmIdentifier element.
  11910. * On error, the value of \c *p is undefined.
  11911. * \param end End of data.
  11912. * \param alg The buffer to receive the OID.
  11913. *
  11914. * \return 0 if successful or a specific ASN.1 or MPI error code.
  11915. */
  11916. int mbedtls_asn1_get_alg_null( unsigned char **p,
  11917. const unsigned char *end,
  11918. mbedtls_asn1_buf *alg );
  11919. /**
  11920. * \brief Find a specific named_data entry in a sequence or list based on
  11921. * the OID.
  11922. *
  11923. * \param list The list to seek through
  11924. * \param oid The OID to look for
  11925. * \param len Size of the OID
  11926. *
  11927. * \return NULL if not found, or a pointer to the existing entry.
  11928. */
  11929. mbedtls_asn1_named_data *mbedtls_asn1_find_named_data( mbedtls_asn1_named_data *list,
  11930. const char *oid, size_t len );
  11931. /**
  11932. * \brief Free a mbedtls_asn1_named_data entry
  11933. *
  11934. * \param entry The named data entry to free.
  11935. * This function calls mbedtls_free() on
  11936. * `entry->oid.p` and `entry->val.p`.
  11937. */
  11938. void mbedtls_asn1_free_named_data( mbedtls_asn1_named_data *entry );
  11939. /**
  11940. * \brief Free all entries in a mbedtls_asn1_named_data list.
  11941. *
  11942. * \param head Pointer to the head of the list of named data entries to free.
  11943. * This function calls mbedtls_asn1_free_named_data() and
  11944. * mbedtls_free() on each list element and
  11945. * sets \c *head to \c NULL.
  11946. */
  11947. void mbedtls_asn1_free_named_data_list( mbedtls_asn1_named_data **head );
  11948. #ifdef __cplusplus
  11949. }
  11950. #endif
  11951. #endif /* asn1.h */
  11952. /********* Start of file include/mbedtls/ecp.h ************/
  11953. /**
  11954. * \file ecp.h
  11955. *
  11956. * \brief This file provides an API for Elliptic Curves over GF(P) (ECP).
  11957. *
  11958. * The use of ECP in cryptography and TLS is defined in
  11959. * <em>Standards for Efficient Cryptography Group (SECG): SEC1
  11960. * Elliptic Curve Cryptography</em> and
  11961. * <em>RFC-4492: Elliptic Curve Cryptography (ECC) Cipher Suites
  11962. * for Transport Layer Security (TLS)</em>.
  11963. *
  11964. * <em>RFC-2409: The Internet Key Exchange (IKE)</em> defines ECP
  11965. * group types.
  11966. *
  11967. */
  11968. /*
  11969. * Copyright The Mbed TLS Contributors
  11970. * SPDX-License-Identifier: Apache-2.0
  11971. *
  11972. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  11973. * not use this file except in compliance with the License.
  11974. * You may obtain a copy of the License at
  11975. *
  11976. * http://www.apache.org/licenses/LICENSE-2.0
  11977. *
  11978. * Unless required by applicable law or agreed to in writing, software
  11979. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  11980. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  11981. * See the License for the specific language governing permissions and
  11982. * limitations under the License.
  11983. */
  11984. #ifndef MBEDTLS_ECP_H
  11985. #define MBEDTLS_ECP_H
  11986. #if !defined(MBEDTLS_CONFIG_FILE)
  11987. #else
  11988. #endif
  11989. /*
  11990. * ECP error codes
  11991. */
  11992. /** Bad input parameters to function. */
  11993. #define MBEDTLS_ERR_ECP_BAD_INPUT_DATA -0x4F80
  11994. /** The buffer is too small to write to. */
  11995. #define MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL -0x4F00
  11996. /** The requested feature is not available, for example, the requested curve is not supported. */
  11997. #define MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE -0x4E80
  11998. /** The signature is not valid. */
  11999. #define MBEDTLS_ERR_ECP_VERIFY_FAILED -0x4E00
  12000. /** Memory allocation failed. */
  12001. #define MBEDTLS_ERR_ECP_ALLOC_FAILED -0x4D80
  12002. /** Generation of random value, such as ephemeral key, failed. */
  12003. #define MBEDTLS_ERR_ECP_RANDOM_FAILED -0x4D00
  12004. /** Invalid private or public key. */
  12005. #define MBEDTLS_ERR_ECP_INVALID_KEY -0x4C80
  12006. /** The buffer contains a valid signature followed by more data. */
  12007. #define MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH -0x4C00
  12008. /* MBEDTLS_ERR_ECP_HW_ACCEL_FAILED is deprecated and should not be used. */
  12009. /** The ECP hardware accelerator failed. */
  12010. #define MBEDTLS_ERR_ECP_HW_ACCEL_FAILED -0x4B80
  12011. /** Operation in progress, call again with the same parameters to continue. */
  12012. #define MBEDTLS_ERR_ECP_IN_PROGRESS -0x4B00
  12013. /* Flags indicating whether to include code that is specific to certain
  12014. * types of curves. These flags are for internal library use only. */
  12015. #if defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED) || \
  12016. defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED) || \
  12017. defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED) || \
  12018. defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED) || \
  12019. defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED) || \
  12020. defined(MBEDTLS_ECP_DP_BP256R1_ENABLED) || \
  12021. defined(MBEDTLS_ECP_DP_BP384R1_ENABLED) || \
  12022. defined(MBEDTLS_ECP_DP_BP512R1_ENABLED) || \
  12023. defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED) || \
  12024. defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED) || \
  12025. defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED)
  12026. #define MBEDTLS_ECP_SHORT_WEIERSTRASS_ENABLED
  12027. #endif
  12028. #if defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED) || \
  12029. defined(MBEDTLS_ECP_DP_CURVE448_ENABLED)
  12030. #define MBEDTLS_ECP_MONTGOMERY_ENABLED
  12031. #endif
  12032. #ifdef __cplusplus
  12033. extern "C" {
  12034. #endif
  12035. /**
  12036. * Domain-parameter identifiers: curve, subgroup, and generator.
  12037. *
  12038. * \note Only curves over prime fields are supported.
  12039. *
  12040. * \warning This library does not support validation of arbitrary domain
  12041. * parameters. Therefore, only standardized domain parameters from trusted
  12042. * sources should be used. See mbedtls_ecp_group_load().
  12043. */
  12044. /* Note: when adding a new curve:
  12045. * - Add it at the end of this enum, otherwise you'll break the ABI by
  12046. * changing the numerical value for existing curves.
  12047. * - Increment MBEDTLS_ECP_DP_MAX below if needed.
  12048. * - Update the calculation of MBEDTLS_ECP_MAX_BITS_MIN below.
  12049. * - Add the corresponding MBEDTLS_ECP_DP_xxx_ENABLED macro definition to
  12050. * config.h.
  12051. * - List the curve as a dependency of MBEDTLS_ECP_C and
  12052. * MBEDTLS_ECDSA_C if supported in check_config.h.
  12053. * - Add the curve to the appropriate curve type macro
  12054. * MBEDTLS_ECP_yyy_ENABLED above.
  12055. * - Add the necessary definitions to ecp_curves.c.
  12056. * - Add the curve to the ecp_supported_curves array in ecp.c.
  12057. * - Add the curve to applicable profiles in x509_crt.c if applicable.
  12058. */
  12059. typedef enum
  12060. {
  12061. MBEDTLS_ECP_DP_NONE = 0, /*!< Curve not defined. */
  12062. MBEDTLS_ECP_DP_SECP192R1, /*!< Domain parameters for the 192-bit curve defined by FIPS 186-4 and SEC1. */
  12063. MBEDTLS_ECP_DP_SECP224R1, /*!< Domain parameters for the 224-bit curve defined by FIPS 186-4 and SEC1. */
  12064. MBEDTLS_ECP_DP_SECP256R1, /*!< Domain parameters for the 256-bit curve defined by FIPS 186-4 and SEC1. */
  12065. MBEDTLS_ECP_DP_SECP384R1, /*!< Domain parameters for the 384-bit curve defined by FIPS 186-4 and SEC1. */
  12066. MBEDTLS_ECP_DP_SECP521R1, /*!< Domain parameters for the 521-bit curve defined by FIPS 186-4 and SEC1. */
  12067. MBEDTLS_ECP_DP_BP256R1, /*!< Domain parameters for 256-bit Brainpool curve. */
  12068. MBEDTLS_ECP_DP_BP384R1, /*!< Domain parameters for 384-bit Brainpool curve. */
  12069. MBEDTLS_ECP_DP_BP512R1, /*!< Domain parameters for 512-bit Brainpool curve. */
  12070. MBEDTLS_ECP_DP_CURVE25519, /*!< Domain parameters for Curve25519. */
  12071. MBEDTLS_ECP_DP_SECP192K1, /*!< Domain parameters for 192-bit "Koblitz" curve. */
  12072. MBEDTLS_ECP_DP_SECP224K1, /*!< Domain parameters for 224-bit "Koblitz" curve. */
  12073. MBEDTLS_ECP_DP_SECP256K1, /*!< Domain parameters for 256-bit "Koblitz" curve. */
  12074. MBEDTLS_ECP_DP_CURVE448, /*!< Domain parameters for Curve448. */
  12075. } mbedtls_ecp_group_id;
  12076. /**
  12077. * The number of supported curves, plus one for #MBEDTLS_ECP_DP_NONE.
  12078. *
  12079. * \note Montgomery curves are currently excluded.
  12080. */
  12081. #define MBEDTLS_ECP_DP_MAX 12
  12082. /*
  12083. * Curve types
  12084. */
  12085. typedef enum
  12086. {
  12087. MBEDTLS_ECP_TYPE_NONE = 0,
  12088. MBEDTLS_ECP_TYPE_SHORT_WEIERSTRASS, /* y^2 = x^3 + a x + b */
  12089. MBEDTLS_ECP_TYPE_MONTGOMERY, /* y^2 = x^3 + a x^2 + x */
  12090. } mbedtls_ecp_curve_type;
  12091. /**
  12092. * Curve information, for use by other modules.
  12093. */
  12094. typedef struct mbedtls_ecp_curve_info
  12095. {
  12096. mbedtls_ecp_group_id grp_id; /*!< An internal identifier. */
  12097. uint16_t tls_id; /*!< The TLS NamedCurve identifier. */
  12098. uint16_t bit_size; /*!< The curve size in bits. */
  12099. const char *name; /*!< A human-friendly name. */
  12100. } mbedtls_ecp_curve_info;
  12101. /**
  12102. * \brief The ECP point structure, in Jacobian coordinates.
  12103. *
  12104. * \note All functions expect and return points satisfying
  12105. * the following condition: <code>Z == 0</code> or
  12106. * <code>Z == 1</code>. Other values of \p Z are
  12107. * used only by internal functions.
  12108. * The point is zero, or "at infinity", if <code>Z == 0</code>.
  12109. * Otherwise, \p X and \p Y are its standard (affine)
  12110. * coordinates.
  12111. */
  12112. typedef struct mbedtls_ecp_point
  12113. {
  12114. mbedtls_mpi X; /*!< The X coordinate of the ECP point. */
  12115. mbedtls_mpi Y; /*!< The Y coordinate of the ECP point. */
  12116. mbedtls_mpi Z; /*!< The Z coordinate of the ECP point. */
  12117. }
  12118. mbedtls_ecp_point;
  12119. /* Determine the minimum safe value of MBEDTLS_ECP_MAX_BITS. */
  12120. #if !defined(MBEDTLS_ECP_C)
  12121. #define MBEDTLS_ECP_MAX_BITS_MIN 0
  12122. /* Note: the curves must be listed in DECREASING size! */
  12123. #elif defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED)
  12124. #define MBEDTLS_ECP_MAX_BITS_MIN 521
  12125. #elif defined(MBEDTLS_ECP_DP_BP512R1_ENABLED)
  12126. #define MBEDTLS_ECP_MAX_BITS_MIN 512
  12127. #elif defined(MBEDTLS_ECP_DP_CURVE448_ENABLED)
  12128. #define MBEDTLS_ECP_MAX_BITS_MIN 448
  12129. #elif defined(MBEDTLS_ECP_DP_BP384R1_ENABLED)
  12130. #define MBEDTLS_ECP_MAX_BITS_MIN 384
  12131. #elif defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED)
  12132. #define MBEDTLS_ECP_MAX_BITS_MIN 384
  12133. #elif defined(MBEDTLS_ECP_DP_BP256R1_ENABLED)
  12134. #define MBEDTLS_ECP_MAX_BITS_MIN 256
  12135. #elif defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED)
  12136. #define MBEDTLS_ECP_MAX_BITS_MIN 256
  12137. #elif defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED)
  12138. #define MBEDTLS_ECP_MAX_BITS_MIN 256
  12139. #elif defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED)
  12140. #define MBEDTLS_ECP_MAX_BITS_MIN 255
  12141. #elif defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED)
  12142. #define MBEDTLS_ECP_MAX_BITS_MIN 225 // n is slightly above 2^224
  12143. #elif defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED)
  12144. #define MBEDTLS_ECP_MAX_BITS_MIN 224
  12145. #elif defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED)
  12146. #define MBEDTLS_ECP_MAX_BITS_MIN 192
  12147. #elif defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED)
  12148. #define MBEDTLS_ECP_MAX_BITS_MIN 192
  12149. #else
  12150. #error "MBEDTLS_ECP_C enabled, but no curve?"
  12151. #endif
  12152. #if !defined(MBEDTLS_ECP_ALT)
  12153. /*
  12154. * default mbed TLS elliptic curve arithmetic implementation
  12155. *
  12156. * (in case MBEDTLS_ECP_ALT is defined then the developer has to provide an
  12157. * alternative implementation for the whole module and it will replace this
  12158. * one.)
  12159. */
  12160. /**
  12161. * \brief The ECP group structure.
  12162. *
  12163. * We consider two types of curve equations:
  12164. * <ul><li>Short Weierstrass: <code>y^2 = x^3 + A x + B mod P</code>
  12165. * (SEC1 + RFC-4492)</li>
  12166. * <li>Montgomery: <code>y^2 = x^3 + A x^2 + x mod P</code> (Curve25519,
  12167. * Curve448)</li></ul>
  12168. * In both cases, the generator (\p G) for a prime-order subgroup is fixed.
  12169. *
  12170. * For Short Weierstrass, this subgroup is the whole curve, and its
  12171. * cardinality is denoted by \p N. Our code requires that \p N is an
  12172. * odd prime as mbedtls_ecp_mul() requires an odd number, and
  12173. * mbedtls_ecdsa_sign() requires that it is prime for blinding purposes.
  12174. *
  12175. * For Montgomery curves, we do not store \p A, but <code>(A + 2) / 4</code>,
  12176. * which is the quantity used in the formulas. Additionally, \p nbits is
  12177. * not the size of \p N but the required size for private keys.
  12178. *
  12179. * If \p modp is NULL, reduction modulo \p P is done using a generic algorithm.
  12180. * Otherwise, \p modp must point to a function that takes an \p mbedtls_mpi in the
  12181. * range of <code>0..2^(2*pbits)-1</code>, and transforms it in-place to an integer
  12182. * which is congruent mod \p P to the given MPI, and is close enough to \p pbits
  12183. * in size, so that it may be efficiently brought in the 0..P-1 range by a few
  12184. * additions or subtractions. Therefore, it is only an approximative modular
  12185. * reduction. It must return 0 on success and non-zero on failure.
  12186. *
  12187. * \note Alternative implementations must keep the group IDs distinct. If
  12188. * two group structures have the same ID, then they must be
  12189. * identical.
  12190. *
  12191. */
  12192. typedef struct mbedtls_ecp_group
  12193. {
  12194. mbedtls_ecp_group_id id; /*!< An internal group identifier. */
  12195. mbedtls_mpi P; /*!< The prime modulus of the base field. */
  12196. mbedtls_mpi A; /*!< For Short Weierstrass: \p A in the equation. For
  12197. Montgomery curves: <code>(A + 2) / 4</code>. */
  12198. mbedtls_mpi B; /*!< For Short Weierstrass: \p B in the equation.
  12199. For Montgomery curves: unused. */
  12200. mbedtls_ecp_point G; /*!< The generator of the subgroup used. */
  12201. mbedtls_mpi N; /*!< The order of \p G. */
  12202. size_t pbits; /*!< The number of bits in \p P.*/
  12203. size_t nbits; /*!< For Short Weierstrass: The number of bits in \p P.
  12204. For Montgomery curves: the number of bits in the
  12205. private keys. */
  12206. unsigned int h; /*!< \internal 1 if the constants are static. */
  12207. int (*modp)(mbedtls_mpi *); /*!< The function for fast pseudo-reduction
  12208. mod \p P (see above).*/
  12209. int (*t_pre)(mbedtls_ecp_point *, void *); /*!< Unused. */
  12210. int (*t_post)(mbedtls_ecp_point *, void *); /*!< Unused. */
  12211. void *t_data; /*!< Unused. */
  12212. mbedtls_ecp_point *T; /*!< Pre-computed points for ecp_mul_comb(). */
  12213. size_t T_size; /*!< The number of pre-computed points. */
  12214. }
  12215. mbedtls_ecp_group;
  12216. /**
  12217. * \name SECTION: Module settings
  12218. *
  12219. * The configuration options you can set for this module are in this section.
  12220. * Either change them in config.h, or define them using the compiler command line.
  12221. * \{
  12222. */
  12223. #if defined(MBEDTLS_ECP_MAX_BITS)
  12224. #if MBEDTLS_ECP_MAX_BITS < MBEDTLS_ECP_MAX_BITS_MIN
  12225. #error "MBEDTLS_ECP_MAX_BITS is smaller than the largest supported curve"
  12226. #endif
  12227. #elif defined(MBEDTLS_ECP_C)
  12228. /**
  12229. * The maximum size of the groups, that is, of \c N and \c P.
  12230. */
  12231. #define MBEDTLS_ECP_MAX_BITS MBEDTLS_ECP_MAX_BITS_MIN
  12232. #else
  12233. /* MBEDTLS_ECP_MAX_BITS is not relevant without MBEDTLS_ECP_C, but set it
  12234. * to a nonzero value so that code that unconditionally allocates an array
  12235. * of a size based on it keeps working if built without ECC support. */
  12236. #define MBEDTLS_ECP_MAX_BITS 1
  12237. #endif
  12238. #define MBEDTLS_ECP_MAX_BYTES ( ( MBEDTLS_ECP_MAX_BITS + 7 ) / 8 )
  12239. #define MBEDTLS_ECP_MAX_PT_LEN ( 2 * MBEDTLS_ECP_MAX_BYTES + 1 )
  12240. #if !defined(MBEDTLS_ECP_WINDOW_SIZE)
  12241. /*
  12242. * Maximum "window" size used for point multiplication.
  12243. * Default: a point where higher memory usage yields disminishing performance
  12244. * returns.
  12245. * Minimum value: 2. Maximum value: 7.
  12246. *
  12247. * Result is an array of at most ( 1 << ( MBEDTLS_ECP_WINDOW_SIZE - 1 ) )
  12248. * points used for point multiplication. This value is directly tied to EC
  12249. * peak memory usage, so decreasing it by one should roughly cut memory usage
  12250. * by two (if large curves are in use).
  12251. *
  12252. * Reduction in size may reduce speed, but larger curves are impacted first.
  12253. * Sample performances (in ECDHE handshakes/s, with FIXED_POINT_OPTIM = 1):
  12254. * w-size: 6 5 4 3 2
  12255. * 521 145 141 135 120 97
  12256. * 384 214 209 198 177 146
  12257. * 256 320 320 303 262 226
  12258. * 224 475 475 453 398 342
  12259. * 192 640 640 633 587 476
  12260. */
  12261. #define MBEDTLS_ECP_WINDOW_SIZE 4 /**< The maximum window size used. */
  12262. #endif /* MBEDTLS_ECP_WINDOW_SIZE */
  12263. #if !defined(MBEDTLS_ECP_FIXED_POINT_OPTIM)
  12264. /*
  12265. * Trade memory for speed on fixed-point multiplication.
  12266. *
  12267. * This speeds up repeated multiplication of the generator (that is, the
  12268. * multiplication in ECDSA signatures, and half of the multiplications in
  12269. * ECDSA verification and ECDHE) by a factor roughly 3 to 4.
  12270. *
  12271. * The cost is increasing EC peak memory usage by a factor roughly 2.
  12272. *
  12273. * Change this value to 0 to reduce peak memory usage.
  12274. */
  12275. #define MBEDTLS_ECP_FIXED_POINT_OPTIM 1 /**< Enable fixed-point speed-up. */
  12276. #endif /* MBEDTLS_ECP_FIXED_POINT_OPTIM */
  12277. /* \} name SECTION: Module settings */
  12278. #else /* MBEDTLS_ECP_ALT */
  12279. #endif /* MBEDTLS_ECP_ALT */
  12280. #if defined(MBEDTLS_ECP_RESTARTABLE)
  12281. /**
  12282. * \brief Internal restart context for multiplication
  12283. *
  12284. * \note Opaque struct
  12285. */
  12286. typedef struct mbedtls_ecp_restart_mul mbedtls_ecp_restart_mul_ctx;
  12287. /**
  12288. * \brief Internal restart context for ecp_muladd()
  12289. *
  12290. * \note Opaque struct
  12291. */
  12292. typedef struct mbedtls_ecp_restart_muladd mbedtls_ecp_restart_muladd_ctx;
  12293. /**
  12294. * \brief General context for resuming ECC operations
  12295. */
  12296. typedef struct
  12297. {
  12298. unsigned ops_done; /*!< current ops count */
  12299. unsigned depth; /*!< call depth (0 = top-level) */
  12300. mbedtls_ecp_restart_mul_ctx *rsm; /*!< ecp_mul_comb() sub-context */
  12301. mbedtls_ecp_restart_muladd_ctx *ma; /*!< ecp_muladd() sub-context */
  12302. } mbedtls_ecp_restart_ctx;
  12303. /*
  12304. * Operation counts for restartable functions
  12305. */
  12306. #define MBEDTLS_ECP_OPS_CHK 3 /*!< basic ops count for ecp_check_pubkey() */
  12307. #define MBEDTLS_ECP_OPS_DBL 8 /*!< basic ops count for ecp_double_jac() */
  12308. #define MBEDTLS_ECP_OPS_ADD 11 /*!< basic ops count for see ecp_add_mixed() */
  12309. #define MBEDTLS_ECP_OPS_INV 120 /*!< empirical equivalent for mpi_mod_inv() */
  12310. /**
  12311. * \brief Internal; for restartable functions in other modules.
  12312. * Check and update basic ops budget.
  12313. *
  12314. * \param grp Group structure
  12315. * \param rs_ctx Restart context
  12316. * \param ops Number of basic ops to do
  12317. *
  12318. * \return \c 0 if doing \p ops basic ops is still allowed,
  12319. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS otherwise.
  12320. */
  12321. int mbedtls_ecp_check_budget( const mbedtls_ecp_group *grp,
  12322. mbedtls_ecp_restart_ctx *rs_ctx,
  12323. unsigned ops );
  12324. /* Utility macro for checking and updating ops budget */
  12325. #define MBEDTLS_ECP_BUDGET( ops ) \
  12326. MBEDTLS_MPI_CHK( mbedtls_ecp_check_budget( grp, rs_ctx, \
  12327. (unsigned) (ops) ) );
  12328. #else /* MBEDTLS_ECP_RESTARTABLE */
  12329. #define MBEDTLS_ECP_BUDGET( ops ) /* no-op; for compatibility */
  12330. /* We want to declare restartable versions of existing functions anyway */
  12331. typedef void mbedtls_ecp_restart_ctx;
  12332. #endif /* MBEDTLS_ECP_RESTARTABLE */
  12333. /**
  12334. * \brief The ECP key-pair structure.
  12335. *
  12336. * A generic key-pair that may be used for ECDSA and fixed ECDH, for example.
  12337. *
  12338. * \note Members are deliberately in the same order as in the
  12339. * ::mbedtls_ecdsa_context structure.
  12340. */
  12341. typedef struct mbedtls_ecp_keypair
  12342. {
  12343. mbedtls_ecp_group grp; /*!< Elliptic curve and base point */
  12344. mbedtls_mpi d; /*!< our secret value */
  12345. mbedtls_ecp_point Q; /*!< our public value */
  12346. }
  12347. mbedtls_ecp_keypair;
  12348. /*
  12349. * Point formats, from RFC 4492's enum ECPointFormat
  12350. */
  12351. #define MBEDTLS_ECP_PF_UNCOMPRESSED 0 /**< Uncompressed point format. */
  12352. #define MBEDTLS_ECP_PF_COMPRESSED 1 /**< Compressed point format. */
  12353. /*
  12354. * Some other constants from RFC 4492
  12355. */
  12356. #define MBEDTLS_ECP_TLS_NAMED_CURVE 3 /**< The named_curve of ECCurveType. */
  12357. #if defined(MBEDTLS_ECP_RESTARTABLE)
  12358. /**
  12359. * \brief Set the maximum number of basic operations done in a row.
  12360. *
  12361. * If more operations are needed to complete a computation,
  12362. * #MBEDTLS_ERR_ECP_IN_PROGRESS will be returned by the
  12363. * function performing the computation. It is then the
  12364. * caller's responsibility to either call again with the same
  12365. * parameters until it returns 0 or an error code; or to free
  12366. * the restart context if the operation is to be aborted.
  12367. *
  12368. * It is strictly required that all input parameters and the
  12369. * restart context be the same on successive calls for the
  12370. * same operation, but output parameters need not be the
  12371. * same; they must not be used until the function finally
  12372. * returns 0.
  12373. *
  12374. * This only applies to functions whose documentation
  12375. * mentions they may return #MBEDTLS_ERR_ECP_IN_PROGRESS (or
  12376. * #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS for functions in the
  12377. * SSL module). For functions that accept a "restart context"
  12378. * argument, passing NULL disables restart and makes the
  12379. * function equivalent to the function with the same name
  12380. * with \c _restartable removed. For functions in the ECDH
  12381. * module, restart is disabled unless the function accepts
  12382. * an "ECDH context" argument and
  12383. * mbedtls_ecdh_enable_restart() was previously called on
  12384. * that context. For function in the SSL module, restart is
  12385. * only enabled for specific sides and key exchanges
  12386. * (currently only for clients and ECDHE-ECDSA).
  12387. *
  12388. * \param max_ops Maximum number of basic operations done in a row.
  12389. * Default: 0 (unlimited).
  12390. * Lower (non-zero) values mean ECC functions will block for
  12391. * a lesser maximum amount of time.
  12392. *
  12393. * \note A "basic operation" is defined as a rough equivalent of a
  12394. * multiplication in GF(p) for the NIST P-256 curve.
  12395. * As an indication, with default settings, a scalar
  12396. * multiplication (full run of \c mbedtls_ecp_mul()) is:
  12397. * - about 3300 basic operations for P-256
  12398. * - about 9400 basic operations for P-384
  12399. *
  12400. * \note Very low values are not always respected: sometimes
  12401. * functions need to block for a minimum number of
  12402. * operations, and will do so even if max_ops is set to a
  12403. * lower value. That minimum depends on the curve size, and
  12404. * can be made lower by decreasing the value of
  12405. * \c MBEDTLS_ECP_WINDOW_SIZE. As an indication, here is the
  12406. * lowest effective value for various curves and values of
  12407. * that parameter (w for short):
  12408. * w=6 w=5 w=4 w=3 w=2
  12409. * P-256 208 208 160 136 124
  12410. * P-384 682 416 320 272 248
  12411. * P-521 1364 832 640 544 496
  12412. *
  12413. * \note This setting is currently ignored by Curve25519.
  12414. */
  12415. void mbedtls_ecp_set_max_ops( unsigned max_ops );
  12416. /**
  12417. * \brief Check if restart is enabled (max_ops != 0)
  12418. *
  12419. * \return \c 0 if \c max_ops == 0 (restart disabled)
  12420. * \return \c 1 otherwise (restart enabled)
  12421. */
  12422. int mbedtls_ecp_restart_is_enabled( void );
  12423. #endif /* MBEDTLS_ECP_RESTARTABLE */
  12424. /*
  12425. * Get the type of a curve
  12426. */
  12427. mbedtls_ecp_curve_type mbedtls_ecp_get_type( const mbedtls_ecp_group *grp );
  12428. /**
  12429. * \brief This function retrieves the information defined in
  12430. * mbedtls_ecp_curve_info() for all supported curves.
  12431. *
  12432. * \note This function returns information about all curves
  12433. * supported by the library. Some curves may not be
  12434. * supported for all algorithms. Call mbedtls_ecdh_can_do()
  12435. * or mbedtls_ecdsa_can_do() to check if a curve is
  12436. * supported for ECDH or ECDSA.
  12437. *
  12438. * \return A statically allocated array. The last entry is 0.
  12439. */
  12440. const mbedtls_ecp_curve_info *mbedtls_ecp_curve_list( void );
  12441. /**
  12442. * \brief This function retrieves the list of internal group
  12443. * identifiers of all supported curves in the order of
  12444. * preference.
  12445. *
  12446. * \note This function returns information about all curves
  12447. * supported by the library. Some curves may not be
  12448. * supported for all algorithms. Call mbedtls_ecdh_can_do()
  12449. * or mbedtls_ecdsa_can_do() to check if a curve is
  12450. * supported for ECDH or ECDSA.
  12451. *
  12452. * \return A statically allocated array,
  12453. * terminated with MBEDTLS_ECP_DP_NONE.
  12454. */
  12455. const mbedtls_ecp_group_id *mbedtls_ecp_grp_id_list( void );
  12456. /**
  12457. * \brief This function retrieves curve information from an internal
  12458. * group identifier.
  12459. *
  12460. * \param grp_id An \c MBEDTLS_ECP_DP_XXX value.
  12461. *
  12462. * \return The associated curve information on success.
  12463. * \return NULL on failure.
  12464. */
  12465. const mbedtls_ecp_curve_info *mbedtls_ecp_curve_info_from_grp_id( mbedtls_ecp_group_id grp_id );
  12466. /**
  12467. * \brief This function retrieves curve information from a TLS
  12468. * NamedCurve value.
  12469. *
  12470. * \param tls_id An \c MBEDTLS_ECP_DP_XXX value.
  12471. *
  12472. * \return The associated curve information on success.
  12473. * \return NULL on failure.
  12474. */
  12475. const mbedtls_ecp_curve_info *mbedtls_ecp_curve_info_from_tls_id( uint16_t tls_id );
  12476. /**
  12477. * \brief This function retrieves curve information from a
  12478. * human-readable name.
  12479. *
  12480. * \param name The human-readable name.
  12481. *
  12482. * \return The associated curve information on success.
  12483. * \return NULL on failure.
  12484. */
  12485. const mbedtls_ecp_curve_info *mbedtls_ecp_curve_info_from_name( const char *name );
  12486. /**
  12487. * \brief This function initializes a point as zero.
  12488. *
  12489. * \param pt The point to initialize.
  12490. */
  12491. void mbedtls_ecp_point_init( mbedtls_ecp_point *pt );
  12492. /**
  12493. * \brief This function initializes an ECP group context
  12494. * without loading any domain parameters.
  12495. *
  12496. * \note After this function is called, domain parameters
  12497. * for various ECP groups can be loaded through the
  12498. * mbedtls_ecp_group_load() or mbedtls_ecp_tls_read_group()
  12499. * functions.
  12500. */
  12501. void mbedtls_ecp_group_init( mbedtls_ecp_group *grp );
  12502. /**
  12503. * \brief This function initializes a key pair as an invalid one.
  12504. *
  12505. * \param key The key pair to initialize.
  12506. */
  12507. void mbedtls_ecp_keypair_init( mbedtls_ecp_keypair *key );
  12508. /**
  12509. * \brief This function frees the components of a point.
  12510. *
  12511. * \param pt The point to free.
  12512. */
  12513. void mbedtls_ecp_point_free( mbedtls_ecp_point *pt );
  12514. /**
  12515. * \brief This function frees the components of an ECP group.
  12516. *
  12517. * \param grp The group to free. This may be \c NULL, in which
  12518. * case this function returns immediately. If it is not
  12519. * \c NULL, it must point to an initialized ECP group.
  12520. */
  12521. void mbedtls_ecp_group_free( mbedtls_ecp_group *grp );
  12522. /**
  12523. * \brief This function frees the components of a key pair.
  12524. *
  12525. * \param key The key pair to free. This may be \c NULL, in which
  12526. * case this function returns immediately. If it is not
  12527. * \c NULL, it must point to an initialized ECP key pair.
  12528. */
  12529. void mbedtls_ecp_keypair_free( mbedtls_ecp_keypair *key );
  12530. #if defined(MBEDTLS_ECP_RESTARTABLE)
  12531. /**
  12532. * \brief Initialize a restart context.
  12533. *
  12534. * \param ctx The restart context to initialize. This must
  12535. * not be \c NULL.
  12536. */
  12537. void mbedtls_ecp_restart_init( mbedtls_ecp_restart_ctx *ctx );
  12538. /**
  12539. * \brief Free the components of a restart context.
  12540. *
  12541. * \param ctx The restart context to free. This may be \c NULL, in which
  12542. * case this function returns immediately. If it is not
  12543. * \c NULL, it must point to an initialized restart context.
  12544. */
  12545. void mbedtls_ecp_restart_free( mbedtls_ecp_restart_ctx *ctx );
  12546. #endif /* MBEDTLS_ECP_RESTARTABLE */
  12547. /**
  12548. * \brief This function copies the contents of point \p Q into
  12549. * point \p P.
  12550. *
  12551. * \param P The destination point. This must be initialized.
  12552. * \param Q The source point. This must be initialized.
  12553. *
  12554. * \return \c 0 on success.
  12555. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
  12556. * \return Another negative error code for other kinds of failure.
  12557. */
  12558. int mbedtls_ecp_copy( mbedtls_ecp_point *P, const mbedtls_ecp_point *Q );
  12559. /**
  12560. * \brief This function copies the contents of group \p src into
  12561. * group \p dst.
  12562. *
  12563. * \param dst The destination group. This must be initialized.
  12564. * \param src The source group. This must be initialized.
  12565. *
  12566. * \return \c 0 on success.
  12567. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
  12568. * \return Another negative error code on other kinds of failure.
  12569. */
  12570. int mbedtls_ecp_group_copy( mbedtls_ecp_group *dst,
  12571. const mbedtls_ecp_group *src );
  12572. /**
  12573. * \brief This function sets a point to the point at infinity.
  12574. *
  12575. * \param pt The point to set. This must be initialized.
  12576. *
  12577. * \return \c 0 on success.
  12578. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
  12579. * \return Another negative error code on other kinds of failure.
  12580. */
  12581. int mbedtls_ecp_set_zero( mbedtls_ecp_point *pt );
  12582. /**
  12583. * \brief This function checks if a point is the point at infinity.
  12584. *
  12585. * \param pt The point to test. This must be initialized.
  12586. *
  12587. * \return \c 1 if the point is zero.
  12588. * \return \c 0 if the point is non-zero.
  12589. * \return A negative error code on failure.
  12590. */
  12591. int mbedtls_ecp_is_zero( mbedtls_ecp_point *pt );
  12592. /**
  12593. * \brief This function compares two points.
  12594. *
  12595. * \note This assumes that the points are normalized. Otherwise,
  12596. * they may compare as "not equal" even if they are.
  12597. *
  12598. * \param P The first point to compare. This must be initialized.
  12599. * \param Q The second point to compare. This must be initialized.
  12600. *
  12601. * \return \c 0 if the points are equal.
  12602. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the points are not equal.
  12603. */
  12604. int mbedtls_ecp_point_cmp( const mbedtls_ecp_point *P,
  12605. const mbedtls_ecp_point *Q );
  12606. /**
  12607. * \brief This function imports a non-zero point from two ASCII
  12608. * strings.
  12609. *
  12610. * \param P The destination point. This must be initialized.
  12611. * \param radix The numeric base of the input.
  12612. * \param x The first affine coordinate, as a null-terminated string.
  12613. * \param y The second affine coordinate, as a null-terminated string.
  12614. *
  12615. * \return \c 0 on success.
  12616. * \return An \c MBEDTLS_ERR_MPI_XXX error code on failure.
  12617. */
  12618. int mbedtls_ecp_point_read_string( mbedtls_ecp_point *P, int radix,
  12619. const char *x, const char *y );
  12620. /**
  12621. * \brief This function exports a point into unsigned binary data.
  12622. *
  12623. * \param grp The group to which the point should belong.
  12624. * This must be initialized and have group parameters
  12625. * set, for example through mbedtls_ecp_group_load().
  12626. * \param P The point to export. This must be initialized.
  12627. * \param format The point format. This must be either
  12628. * #MBEDTLS_ECP_PF_COMPRESSED or #MBEDTLS_ECP_PF_UNCOMPRESSED.
  12629. * (For groups without these formats, this parameter is
  12630. * ignored. But it still has to be either of the above
  12631. * values.)
  12632. * \param olen The address at which to store the length of
  12633. * the output in Bytes. This must not be \c NULL.
  12634. * \param buf The output buffer. This must be a writable buffer
  12635. * of length \p buflen Bytes.
  12636. * \param buflen The length of the output buffer \p buf in Bytes.
  12637. *
  12638. * \return \c 0 on success.
  12639. * \return #MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL if the output buffer
  12640. * is too small to hold the point.
  12641. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the point format
  12642. * or the export for the given group is not implemented.
  12643. * \return Another negative error code on other kinds of failure.
  12644. */
  12645. int mbedtls_ecp_point_write_binary( const mbedtls_ecp_group *grp,
  12646. const mbedtls_ecp_point *P,
  12647. int format, size_t *olen,
  12648. unsigned char *buf, size_t buflen );
  12649. /**
  12650. * \brief This function imports a point from unsigned binary data.
  12651. *
  12652. * \note This function does not check that the point actually
  12653. * belongs to the given group, see mbedtls_ecp_check_pubkey()
  12654. * for that.
  12655. *
  12656. * \param grp The group to which the point should belong.
  12657. * This must be initialized and have group parameters
  12658. * set, for example through mbedtls_ecp_group_load().
  12659. * \param P The destination context to import the point to.
  12660. * This must be initialized.
  12661. * \param buf The input buffer. This must be a readable buffer
  12662. * of length \p ilen Bytes.
  12663. * \param ilen The length of the input buffer \p buf in Bytes.
  12664. *
  12665. * \return \c 0 on success.
  12666. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the input is invalid.
  12667. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
  12668. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the import for the
  12669. * given group is not implemented.
  12670. */
  12671. int mbedtls_ecp_point_read_binary( const mbedtls_ecp_group *grp,
  12672. mbedtls_ecp_point *P,
  12673. const unsigned char *buf, size_t ilen );
  12674. /**
  12675. * \brief This function imports a point from a TLS ECPoint record.
  12676. *
  12677. * \note On function return, \p *buf is updated to point immediately
  12678. * after the ECPoint record.
  12679. *
  12680. * \param grp The ECP group to use.
  12681. * This must be initialized and have group parameters
  12682. * set, for example through mbedtls_ecp_group_load().
  12683. * \param pt The destination point.
  12684. * \param buf The address of the pointer to the start of the input buffer.
  12685. * \param len The length of the buffer.
  12686. *
  12687. * \return \c 0 on success.
  12688. * \return An \c MBEDTLS_ERR_MPI_XXX error code on initialization
  12689. * failure.
  12690. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid.
  12691. */
  12692. int mbedtls_ecp_tls_read_point( const mbedtls_ecp_group *grp,
  12693. mbedtls_ecp_point *pt,
  12694. const unsigned char **buf, size_t len );
  12695. /**
  12696. * \brief This function exports a point as a TLS ECPoint record
  12697. * defined in RFC 4492, Section 5.4.
  12698. *
  12699. * \param grp The ECP group to use.
  12700. * This must be initialized and have group parameters
  12701. * set, for example through mbedtls_ecp_group_load().
  12702. * \param pt The point to be exported. This must be initialized.
  12703. * \param format The point format to use. This must be either
  12704. * #MBEDTLS_ECP_PF_COMPRESSED or #MBEDTLS_ECP_PF_UNCOMPRESSED.
  12705. * \param olen The address at which to store the length in Bytes
  12706. * of the data written.
  12707. * \param buf The target buffer. This must be a writable buffer of
  12708. * length \p blen Bytes.
  12709. * \param blen The length of the target buffer \p buf in Bytes.
  12710. *
  12711. * \return \c 0 on success.
  12712. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the input is invalid.
  12713. * \return #MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL if the target buffer
  12714. * is too small to hold the exported point.
  12715. * \return Another negative error code on other kinds of failure.
  12716. */
  12717. int mbedtls_ecp_tls_write_point( const mbedtls_ecp_group *grp,
  12718. const mbedtls_ecp_point *pt,
  12719. int format, size_t *olen,
  12720. unsigned char *buf, size_t blen );
  12721. /**
  12722. * \brief This function sets up an ECP group context
  12723. * from a standardized set of domain parameters.
  12724. *
  12725. * \note The index should be a value of the NamedCurve enum,
  12726. * as defined in <em>RFC-4492: Elliptic Curve Cryptography
  12727. * (ECC) Cipher Suites for Transport Layer Security (TLS)</em>,
  12728. * usually in the form of an \c MBEDTLS_ECP_DP_XXX macro.
  12729. *
  12730. * \param grp The group context to setup. This must be initialized.
  12731. * \param id The identifier of the domain parameter set to load.
  12732. *
  12733. * \return \c 0 on success.
  12734. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if \p id doesn't
  12735. * correspond to a known group.
  12736. * \return Another negative error code on other kinds of failure.
  12737. */
  12738. int mbedtls_ecp_group_load( mbedtls_ecp_group *grp, mbedtls_ecp_group_id id );
  12739. /**
  12740. * \brief This function sets up an ECP group context from a TLS
  12741. * ECParameters record as defined in RFC 4492, Section 5.4.
  12742. *
  12743. * \note The read pointer \p buf is updated to point right after
  12744. * the ECParameters record on exit.
  12745. *
  12746. * \param grp The group context to setup. This must be initialized.
  12747. * \param buf The address of the pointer to the start of the input buffer.
  12748. * \param len The length of the input buffer \c *buf in Bytes.
  12749. *
  12750. * \return \c 0 on success.
  12751. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid.
  12752. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the group is not
  12753. * recognized.
  12754. * \return Another negative error code on other kinds of failure.
  12755. */
  12756. int mbedtls_ecp_tls_read_group( mbedtls_ecp_group *grp,
  12757. const unsigned char **buf, size_t len );
  12758. /**
  12759. * \brief This function extracts an elliptic curve group ID from a
  12760. * TLS ECParameters record as defined in RFC 4492, Section 5.4.
  12761. *
  12762. * \note The read pointer \p buf is updated to point right after
  12763. * the ECParameters record on exit.
  12764. *
  12765. * \param grp The address at which to store the group id.
  12766. * This must not be \c NULL.
  12767. * \param buf The address of the pointer to the start of the input buffer.
  12768. * \param len The length of the input buffer \c *buf in Bytes.
  12769. *
  12770. * \return \c 0 on success.
  12771. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if input is invalid.
  12772. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the group is not
  12773. * recognized.
  12774. * \return Another negative error code on other kinds of failure.
  12775. */
  12776. int mbedtls_ecp_tls_read_group_id( mbedtls_ecp_group_id *grp,
  12777. const unsigned char **buf,
  12778. size_t len );
  12779. /**
  12780. * \brief This function exports an elliptic curve as a TLS
  12781. * ECParameters record as defined in RFC 4492, Section 5.4.
  12782. *
  12783. * \param grp The ECP group to be exported.
  12784. * This must be initialized and have group parameters
  12785. * set, for example through mbedtls_ecp_group_load().
  12786. * \param olen The address at which to store the number of Bytes written.
  12787. * This must not be \c NULL.
  12788. * \param buf The buffer to write to. This must be a writable buffer
  12789. * of length \p blen Bytes.
  12790. * \param blen The length of the output buffer \p buf in Bytes.
  12791. *
  12792. * \return \c 0 on success.
  12793. * \return #MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL if the output
  12794. * buffer is too small to hold the exported group.
  12795. * \return Another negative error code on other kinds of failure.
  12796. */
  12797. int mbedtls_ecp_tls_write_group( const mbedtls_ecp_group *grp,
  12798. size_t *olen,
  12799. unsigned char *buf, size_t blen );
  12800. /**
  12801. * \brief This function performs a scalar multiplication of a point
  12802. * by an integer: \p R = \p m * \p P.
  12803. *
  12804. * It is not thread-safe to use same group in multiple threads.
  12805. *
  12806. * \note To prevent timing attacks, this function
  12807. * executes the exact same sequence of base-field
  12808. * operations for any valid \p m. It avoids any if-branch or
  12809. * array index depending on the value of \p m.
  12810. *
  12811. * \note If \p f_rng is not NULL, it is used to randomize
  12812. * intermediate results to prevent potential timing attacks
  12813. * targeting these results. We recommend always providing
  12814. * a non-NULL \p f_rng. The overhead is negligible.
  12815. * Note: unless #MBEDTLS_ECP_NO_INTERNAL_RNG is defined, when
  12816. * \p f_rng is NULL, an internal RNG (seeded from the value
  12817. * of \p m) will be used instead.
  12818. *
  12819. * \param grp The ECP group to use.
  12820. * This must be initialized and have group parameters
  12821. * set, for example through mbedtls_ecp_group_load().
  12822. * \param R The point in which to store the result of the calculation.
  12823. * This must be initialized.
  12824. * \param m The integer by which to multiply. This must be initialized.
  12825. * \param P The point to multiply. This must be initialized.
  12826. * \param f_rng The RNG function. This may be \c NULL if randomization
  12827. * of intermediate results isn't desired (discouraged).
  12828. * \param p_rng The RNG context to be passed to \p p_rng.
  12829. *
  12830. * \return \c 0 on success.
  12831. * \return #MBEDTLS_ERR_ECP_INVALID_KEY if \p m is not a valid private
  12832. * key, or \p P is not a valid public key.
  12833. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
  12834. * \return Another negative error code on other kinds of failure.
  12835. */
  12836. int mbedtls_ecp_mul( mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
  12837. const mbedtls_mpi *m, const mbedtls_ecp_point *P,
  12838. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );
  12839. /**
  12840. * \brief This function performs multiplication of a point by
  12841. * an integer: \p R = \p m * \p P in a restartable way.
  12842. *
  12843. * \see mbedtls_ecp_mul()
  12844. *
  12845. * \note This function does the same as \c mbedtls_ecp_mul(), but
  12846. * it can return early and restart according to the limit set
  12847. * with \c mbedtls_ecp_set_max_ops() to reduce blocking.
  12848. *
  12849. * \param grp The ECP group to use.
  12850. * This must be initialized and have group parameters
  12851. * set, for example through mbedtls_ecp_group_load().
  12852. * \param R The point in which to store the result of the calculation.
  12853. * This must be initialized.
  12854. * \param m The integer by which to multiply. This must be initialized.
  12855. * \param P The point to multiply. This must be initialized.
  12856. * \param f_rng The RNG function. This may be \c NULL if randomization
  12857. * of intermediate results isn't desired (discouraged).
  12858. * \param p_rng The RNG context to be passed to \p p_rng.
  12859. * \param rs_ctx The restart context (NULL disables restart).
  12860. *
  12861. * \return \c 0 on success.
  12862. * \return #MBEDTLS_ERR_ECP_INVALID_KEY if \p m is not a valid private
  12863. * key, or \p P is not a valid public key.
  12864. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
  12865. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  12866. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  12867. * \return Another negative error code on other kinds of failure.
  12868. */
  12869. int mbedtls_ecp_mul_restartable( mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
  12870. const mbedtls_mpi *m, const mbedtls_ecp_point *P,
  12871. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
  12872. mbedtls_ecp_restart_ctx *rs_ctx );
  12873. #if defined(MBEDTLS_ECP_SHORT_WEIERSTRASS_ENABLED)
  12874. /**
  12875. * \brief This function performs multiplication and addition of two
  12876. * points by integers: \p R = \p m * \p P + \p n * \p Q
  12877. *
  12878. * It is not thread-safe to use same group in multiple threads.
  12879. *
  12880. * \note In contrast to mbedtls_ecp_mul(), this function does not
  12881. * guarantee a constant execution flow and timing.
  12882. *
  12883. * \note This function is only defined for short Weierstrass curves.
  12884. * It may not be included in builds without any short
  12885. * Weierstrass curve.
  12886. *
  12887. * \param grp The ECP group to use.
  12888. * This must be initialized and have group parameters
  12889. * set, for example through mbedtls_ecp_group_load().
  12890. * \param R The point in which to store the result of the calculation.
  12891. * This must be initialized.
  12892. * \param m The integer by which to multiply \p P.
  12893. * This must be initialized.
  12894. * \param P The point to multiply by \p m. This must be initialized.
  12895. * \param n The integer by which to multiply \p Q.
  12896. * This must be initialized.
  12897. * \param Q The point to be multiplied by \p n.
  12898. * This must be initialized.
  12899. *
  12900. * \return \c 0 on success.
  12901. * \return #MBEDTLS_ERR_ECP_INVALID_KEY if \p m or \p n are not
  12902. * valid private keys, or \p P or \p Q are not valid public
  12903. * keys.
  12904. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
  12905. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if \p grp does not
  12906. * designate a short Weierstrass curve.
  12907. * \return Another negative error code on other kinds of failure.
  12908. */
  12909. int mbedtls_ecp_muladd( mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
  12910. const mbedtls_mpi *m, const mbedtls_ecp_point *P,
  12911. const mbedtls_mpi *n, const mbedtls_ecp_point *Q );
  12912. /**
  12913. * \brief This function performs multiplication and addition of two
  12914. * points by integers: \p R = \p m * \p P + \p n * \p Q in a
  12915. * restartable way.
  12916. *
  12917. * \see \c mbedtls_ecp_muladd()
  12918. *
  12919. * \note This function works the same as \c mbedtls_ecp_muladd(),
  12920. * but it can return early and restart according to the limit
  12921. * set with \c mbedtls_ecp_set_max_ops() to reduce blocking.
  12922. *
  12923. * \note This function is only defined for short Weierstrass curves.
  12924. * It may not be included in builds without any short
  12925. * Weierstrass curve.
  12926. *
  12927. * \param grp The ECP group to use.
  12928. * This must be initialized and have group parameters
  12929. * set, for example through mbedtls_ecp_group_load().
  12930. * \param R The point in which to store the result of the calculation.
  12931. * This must be initialized.
  12932. * \param m The integer by which to multiply \p P.
  12933. * This must be initialized.
  12934. * \param P The point to multiply by \p m. This must be initialized.
  12935. * \param n The integer by which to multiply \p Q.
  12936. * This must be initialized.
  12937. * \param Q The point to be multiplied by \p n.
  12938. * This must be initialized.
  12939. * \param rs_ctx The restart context (NULL disables restart).
  12940. *
  12941. * \return \c 0 on success.
  12942. * \return #MBEDTLS_ERR_ECP_INVALID_KEY if \p m or \p n are not
  12943. * valid private keys, or \p P or \p Q are not valid public
  12944. * keys.
  12945. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED on memory-allocation failure.
  12946. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if \p grp does not
  12947. * designate a short Weierstrass curve.
  12948. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  12949. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  12950. * \return Another negative error code on other kinds of failure.
  12951. */
  12952. int mbedtls_ecp_muladd_restartable(
  12953. mbedtls_ecp_group *grp, mbedtls_ecp_point *R,
  12954. const mbedtls_mpi *m, const mbedtls_ecp_point *P,
  12955. const mbedtls_mpi *n, const mbedtls_ecp_point *Q,
  12956. mbedtls_ecp_restart_ctx *rs_ctx );
  12957. #endif /* MBEDTLS_ECP_SHORT_WEIERSTRASS_ENABLED */
  12958. /**
  12959. * \brief This function checks that a point is a valid public key
  12960. * on this curve.
  12961. *
  12962. * It only checks that the point is non-zero, has
  12963. * valid coordinates and lies on the curve. It does not verify
  12964. * that it is indeed a multiple of \p G. This additional
  12965. * check is computationally more expensive, is not required
  12966. * by standards, and should not be necessary if the group
  12967. * used has a small cofactor. In particular, it is useless for
  12968. * the NIST groups which all have a cofactor of 1.
  12969. *
  12970. * \note This function uses bare components rather than an
  12971. * ::mbedtls_ecp_keypair structure, to ease use with other
  12972. * structures, such as ::mbedtls_ecdh_context or
  12973. * ::mbedtls_ecdsa_context.
  12974. *
  12975. * \param grp The ECP group the point should belong to.
  12976. * This must be initialized and have group parameters
  12977. * set, for example through mbedtls_ecp_group_load().
  12978. * \param pt The point to check. This must be initialized.
  12979. *
  12980. * \return \c 0 if the point is a valid public key.
  12981. * \return #MBEDTLS_ERR_ECP_INVALID_KEY if the point is not
  12982. * a valid public key for the given curve.
  12983. * \return Another negative error code on other kinds of failure.
  12984. */
  12985. int mbedtls_ecp_check_pubkey( const mbedtls_ecp_group *grp,
  12986. const mbedtls_ecp_point *pt );
  12987. /**
  12988. * \brief This function checks that an \p mbedtls_mpi is a
  12989. * valid private key for this curve.
  12990. *
  12991. * \note This function uses bare components rather than an
  12992. * ::mbedtls_ecp_keypair structure to ease use with other
  12993. * structures, such as ::mbedtls_ecdh_context or
  12994. * ::mbedtls_ecdsa_context.
  12995. *
  12996. * \param grp The ECP group the private key should belong to.
  12997. * This must be initialized and have group parameters
  12998. * set, for example through mbedtls_ecp_group_load().
  12999. * \param d The integer to check. This must be initialized.
  13000. *
  13001. * \return \c 0 if the point is a valid private key.
  13002. * \return #MBEDTLS_ERR_ECP_INVALID_KEY if the point is not a valid
  13003. * private key for the given curve.
  13004. * \return Another negative error code on other kinds of failure.
  13005. */
  13006. int mbedtls_ecp_check_privkey( const mbedtls_ecp_group *grp,
  13007. const mbedtls_mpi *d );
  13008. /**
  13009. * \brief This function generates a private key.
  13010. *
  13011. * \param grp The ECP group to generate a private key for.
  13012. * This must be initialized and have group parameters
  13013. * set, for example through mbedtls_ecp_group_load().
  13014. * \param d The destination MPI (secret part). This must be initialized.
  13015. * \param f_rng The RNG function. This must not be \c NULL.
  13016. * \param p_rng The RNG parameter to be passed to \p f_rng. This may be
  13017. * \c NULL if \p f_rng doesn't need a context argument.
  13018. *
  13019. * \return \c 0 on success.
  13020. * \return An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX error code
  13021. * on failure.
  13022. */
  13023. int mbedtls_ecp_gen_privkey( const mbedtls_ecp_group *grp,
  13024. mbedtls_mpi *d,
  13025. int (*f_rng)(void *, unsigned char *, size_t),
  13026. void *p_rng );
  13027. /**
  13028. * \brief This function generates a keypair with a configurable base
  13029. * point.
  13030. *
  13031. * \note This function uses bare components rather than an
  13032. * ::mbedtls_ecp_keypair structure to ease use with other
  13033. * structures, such as ::mbedtls_ecdh_context or
  13034. * ::mbedtls_ecdsa_context.
  13035. *
  13036. * \param grp The ECP group to generate a key pair for.
  13037. * This must be initialized and have group parameters
  13038. * set, for example through mbedtls_ecp_group_load().
  13039. * \param G The base point to use. This must be initialized
  13040. * and belong to \p grp. It replaces the default base
  13041. * point \c grp->G used by mbedtls_ecp_gen_keypair().
  13042. * \param d The destination MPI (secret part).
  13043. * This must be initialized.
  13044. * \param Q The destination point (public part).
  13045. * This must be initialized.
  13046. * \param f_rng The RNG function. This must not be \c NULL.
  13047. * \param p_rng The RNG context to be passed to \p f_rng. This may
  13048. * be \c NULL if \p f_rng doesn't need a context argument.
  13049. *
  13050. * \return \c 0 on success.
  13051. * \return An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX error code
  13052. * on failure.
  13053. */
  13054. int mbedtls_ecp_gen_keypair_base( mbedtls_ecp_group *grp,
  13055. const mbedtls_ecp_point *G,
  13056. mbedtls_mpi *d, mbedtls_ecp_point *Q,
  13057. int (*f_rng)(void *, unsigned char *, size_t),
  13058. void *p_rng );
  13059. /**
  13060. * \brief This function generates an ECP keypair.
  13061. *
  13062. * \note This function uses bare components rather than an
  13063. * ::mbedtls_ecp_keypair structure to ease use with other
  13064. * structures, such as ::mbedtls_ecdh_context or
  13065. * ::mbedtls_ecdsa_context.
  13066. *
  13067. * \param grp The ECP group to generate a key pair for.
  13068. * This must be initialized and have group parameters
  13069. * set, for example through mbedtls_ecp_group_load().
  13070. * \param d The destination MPI (secret part).
  13071. * This must be initialized.
  13072. * \param Q The destination point (public part).
  13073. * This must be initialized.
  13074. * \param f_rng The RNG function. This must not be \c NULL.
  13075. * \param p_rng The RNG context to be passed to \p f_rng. This may
  13076. * be \c NULL if \p f_rng doesn't need a context argument.
  13077. *
  13078. * \return \c 0 on success.
  13079. * \return An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX error code
  13080. * on failure.
  13081. */
  13082. int mbedtls_ecp_gen_keypair( mbedtls_ecp_group *grp, mbedtls_mpi *d,
  13083. mbedtls_ecp_point *Q,
  13084. int (*f_rng)(void *, unsigned char *, size_t),
  13085. void *p_rng );
  13086. /**
  13087. * \brief This function generates an ECP key.
  13088. *
  13089. * \param grp_id The ECP group identifier.
  13090. * \param key The destination key. This must be initialized.
  13091. * \param f_rng The RNG function to use. This must not be \c NULL.
  13092. * \param p_rng The RNG context to be passed to \p f_rng. This may
  13093. * be \c NULL if \p f_rng doesn't need a context argument.
  13094. *
  13095. * \return \c 0 on success.
  13096. * \return An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX error code
  13097. * on failure.
  13098. */
  13099. int mbedtls_ecp_gen_key( mbedtls_ecp_group_id grp_id, mbedtls_ecp_keypair *key,
  13100. int (*f_rng)(void *, unsigned char *, size_t),
  13101. void *p_rng );
  13102. /**
  13103. * \brief This function reads an elliptic curve private key.
  13104. *
  13105. * \param grp_id The ECP group identifier.
  13106. * \param key The destination key.
  13107. * \param buf The buffer containing the binary representation of the
  13108. * key. (Big endian integer for Weierstrass curves, byte
  13109. * string for Montgomery curves.)
  13110. * \param buflen The length of the buffer in bytes.
  13111. *
  13112. * \return \c 0 on success.
  13113. * \return #MBEDTLS_ERR_ECP_INVALID_KEY error if the key is
  13114. * invalid.
  13115. * \return #MBEDTLS_ERR_MPI_ALLOC_FAILED if memory allocation failed.
  13116. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the operation for
  13117. * the group is not implemented.
  13118. * \return Another negative error code on different kinds of failure.
  13119. */
  13120. int mbedtls_ecp_read_key( mbedtls_ecp_group_id grp_id, mbedtls_ecp_keypair *key,
  13121. const unsigned char *buf, size_t buflen );
  13122. /**
  13123. * \brief This function exports an elliptic curve private key.
  13124. *
  13125. * \param key The private key.
  13126. * \param buf The output buffer for containing the binary representation
  13127. * of the key. (Big endian integer for Weierstrass curves, byte
  13128. * string for Montgomery curves.)
  13129. * \param buflen The total length of the buffer in bytes.
  13130. *
  13131. * \return \c 0 on success.
  13132. * \return #MBEDTLS_ERR_ECP_BUFFER_TOO_SMALL if the \p key
  13133. representation is larger than the available space in \p buf.
  13134. * \return #MBEDTLS_ERR_ECP_FEATURE_UNAVAILABLE if the operation for
  13135. * the group is not implemented.
  13136. * \return Another negative error code on different kinds of failure.
  13137. */
  13138. int mbedtls_ecp_write_key( mbedtls_ecp_keypair *key,
  13139. unsigned char *buf, size_t buflen );
  13140. /**
  13141. * \brief This function checks that the keypair objects
  13142. * \p pub and \p prv have the same group and the
  13143. * same public point, and that the private key in
  13144. * \p prv is consistent with the public key.
  13145. *
  13146. * \param pub The keypair structure holding the public key. This
  13147. * must be initialized. If it contains a private key, that
  13148. * part is ignored.
  13149. * \param prv The keypair structure holding the full keypair.
  13150. * This must be initialized.
  13151. *
  13152. * \return \c 0 on success, meaning that the keys are valid and match.
  13153. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the keys are invalid or do not match.
  13154. * \return An \c MBEDTLS_ERR_ECP_XXX or an \c MBEDTLS_ERR_MPI_XXX
  13155. * error code on calculation failure.
  13156. */
  13157. int mbedtls_ecp_check_pub_priv( const mbedtls_ecp_keypair *pub,
  13158. const mbedtls_ecp_keypair *prv );
  13159. #if defined(MBEDTLS_SELF_TEST)
  13160. /**
  13161. * \brief The ECP checkup routine.
  13162. *
  13163. * \return \c 0 on success.
  13164. * \return \c 1 on failure.
  13165. */
  13166. int mbedtls_ecp_self_test( int verbose );
  13167. #endif /* MBEDTLS_SELF_TEST */
  13168. #ifdef __cplusplus
  13169. }
  13170. #endif
  13171. #endif /* ecp.h */
  13172. /********* Start of file include/mbedtls/ecdsa.h ************/
  13173. /**
  13174. * \file ecdsa.h
  13175. *
  13176. * \brief This file contains ECDSA definitions and functions.
  13177. *
  13178. * The Elliptic Curve Digital Signature Algorithm (ECDSA) is defined in
  13179. * <em>Standards for Efficient Cryptography Group (SECG):
  13180. * SEC1 Elliptic Curve Cryptography</em>.
  13181. * The use of ECDSA for TLS is defined in <em>RFC-4492: Elliptic Curve
  13182. * Cryptography (ECC) Cipher Suites for Transport Layer Security (TLS)</em>.
  13183. *
  13184. */
  13185. /*
  13186. * Copyright The Mbed TLS Contributors
  13187. * SPDX-License-Identifier: Apache-2.0
  13188. *
  13189. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  13190. * not use this file except in compliance with the License.
  13191. * You may obtain a copy of the License at
  13192. *
  13193. * http://www.apache.org/licenses/LICENSE-2.0
  13194. *
  13195. * Unless required by applicable law or agreed to in writing, software
  13196. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  13197. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13198. * See the License for the specific language governing permissions and
  13199. * limitations under the License.
  13200. */
  13201. #ifndef MBEDTLS_ECDSA_H
  13202. #define MBEDTLS_ECDSA_H
  13203. #if !defined(MBEDTLS_CONFIG_FILE)
  13204. #else
  13205. #endif
  13206. /**
  13207. * \brief Maximum ECDSA signature size for a given curve bit size
  13208. *
  13209. * \param bits Curve size in bits
  13210. * \return Maximum signature size in bytes
  13211. *
  13212. * \note This macro returns a compile-time constant if its argument
  13213. * is one. It may evaluate its argument multiple times.
  13214. */
  13215. /*
  13216. * Ecdsa-Sig-Value ::= SEQUENCE {
  13217. * r INTEGER,
  13218. * s INTEGER
  13219. * }
  13220. *
  13221. * For each of r and s, the value (V) may include an extra initial "0" bit.
  13222. */
  13223. #define MBEDTLS_ECDSA_MAX_SIG_LEN( bits ) \
  13224. ( /*T,L of SEQUENCE*/ ( ( bits ) >= 61 * 8 ? 3 : 2 ) + \
  13225. /*T,L of r,s*/ 2 * ( ( ( bits ) >= 127 * 8 ? 3 : 2 ) + \
  13226. /*V of r,s*/ ( ( bits ) + 8 ) / 8 ) )
  13227. /** The maximal size of an ECDSA signature in Bytes. */
  13228. #define MBEDTLS_ECDSA_MAX_LEN MBEDTLS_ECDSA_MAX_SIG_LEN( MBEDTLS_ECP_MAX_BITS )
  13229. #ifdef __cplusplus
  13230. extern "C" {
  13231. #endif
  13232. /**
  13233. * \brief The ECDSA context structure.
  13234. *
  13235. * \warning Performing multiple operations concurrently on the same
  13236. * ECDSA context is not supported; objects of this type
  13237. * should not be shared between multiple threads.
  13238. */
  13239. typedef mbedtls_ecp_keypair mbedtls_ecdsa_context;
  13240. #if defined(MBEDTLS_ECP_RESTARTABLE)
  13241. /**
  13242. * \brief Internal restart context for ecdsa_verify()
  13243. *
  13244. * \note Opaque struct, defined in ecdsa.c
  13245. */
  13246. typedef struct mbedtls_ecdsa_restart_ver mbedtls_ecdsa_restart_ver_ctx;
  13247. /**
  13248. * \brief Internal restart context for ecdsa_sign()
  13249. *
  13250. * \note Opaque struct, defined in ecdsa.c
  13251. */
  13252. typedef struct mbedtls_ecdsa_restart_sig mbedtls_ecdsa_restart_sig_ctx;
  13253. #if defined(MBEDTLS_ECDSA_DETERMINISTIC)
  13254. /**
  13255. * \brief Internal restart context for ecdsa_sign_det()
  13256. *
  13257. * \note Opaque struct, defined in ecdsa.c
  13258. */
  13259. typedef struct mbedtls_ecdsa_restart_det mbedtls_ecdsa_restart_det_ctx;
  13260. #endif
  13261. /**
  13262. * \brief General context for resuming ECDSA operations
  13263. */
  13264. typedef struct
  13265. {
  13266. mbedtls_ecp_restart_ctx ecp; /*!< base context for ECP restart and
  13267. shared administrative info */
  13268. mbedtls_ecdsa_restart_ver_ctx *ver; /*!< ecdsa_verify() sub-context */
  13269. mbedtls_ecdsa_restart_sig_ctx *sig; /*!< ecdsa_sign() sub-context */
  13270. #if defined(MBEDTLS_ECDSA_DETERMINISTIC)
  13271. mbedtls_ecdsa_restart_det_ctx *det; /*!< ecdsa_sign_det() sub-context */
  13272. #endif
  13273. } mbedtls_ecdsa_restart_ctx;
  13274. #else /* MBEDTLS_ECP_RESTARTABLE */
  13275. /* Now we can declare functions that take a pointer to that */
  13276. typedef void mbedtls_ecdsa_restart_ctx;
  13277. #endif /* MBEDTLS_ECP_RESTARTABLE */
  13278. /**
  13279. * \brief This function checks whether a given group can be used
  13280. * for ECDSA.
  13281. *
  13282. * \param gid The ECP group ID to check.
  13283. *
  13284. * \return \c 1 if the group can be used, \c 0 otherwise
  13285. */
  13286. int mbedtls_ecdsa_can_do( mbedtls_ecp_group_id gid );
  13287. /**
  13288. * \brief This function computes the ECDSA signature of a
  13289. * previously-hashed message.
  13290. *
  13291. * \note The deterministic version implemented in
  13292. * mbedtls_ecdsa_sign_det() is usually preferred.
  13293. *
  13294. * \note If the bitlength of the message hash is larger than the
  13295. * bitlength of the group order, then the hash is truncated
  13296. * as defined in <em>Standards for Efficient Cryptography Group
  13297. * (SECG): SEC1 Elliptic Curve Cryptography</em>, section
  13298. * 4.1.3, step 5.
  13299. *
  13300. * \see ecp.h
  13301. *
  13302. * \param grp The context for the elliptic curve to use.
  13303. * This must be initialized and have group parameters
  13304. * set, for example through mbedtls_ecp_group_load().
  13305. * \param r The MPI context in which to store the first part
  13306. * the signature. This must be initialized.
  13307. * \param s The MPI context in which to store the second part
  13308. * the signature. This must be initialized.
  13309. * \param d The private signing key. This must be initialized.
  13310. * \param buf The content to be signed. This is usually the hash of
  13311. * the original data to be signed. This must be a readable
  13312. * buffer of length \p blen Bytes. It may be \c NULL if
  13313. * \p blen is zero.
  13314. * \param blen The length of \p buf in Bytes.
  13315. * \param f_rng The RNG function. This must not be \c NULL.
  13316. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  13317. * \c NULL if \p f_rng doesn't need a context parameter.
  13318. *
  13319. * \return \c 0 on success.
  13320. * \return An \c MBEDTLS_ERR_ECP_XXX
  13321. * or \c MBEDTLS_MPI_XXX error code on failure.
  13322. */
  13323. int mbedtls_ecdsa_sign( mbedtls_ecp_group *grp, mbedtls_mpi *r, mbedtls_mpi *s,
  13324. const mbedtls_mpi *d, const unsigned char *buf, size_t blen,
  13325. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );
  13326. #if defined(MBEDTLS_ECDSA_DETERMINISTIC)
  13327. #if ! defined(MBEDTLS_DEPRECATED_REMOVED)
  13328. #if defined(MBEDTLS_DEPRECATED_WARNING)
  13329. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  13330. #else
  13331. #define MBEDTLS_DEPRECATED
  13332. #endif
  13333. /**
  13334. * \brief This function computes the ECDSA signature of a
  13335. * previously-hashed message, deterministic version.
  13336. *
  13337. * For more information, see <em>RFC-6979: Deterministic
  13338. * Usage of the Digital Signature Algorithm (DSA) and Elliptic
  13339. * Curve Digital Signature Algorithm (ECDSA)</em>.
  13340. *
  13341. * \note If the bitlength of the message hash is larger than the
  13342. * bitlength of the group order, then the hash is truncated as
  13343. * defined in <em>Standards for Efficient Cryptography Group
  13344. * (SECG): SEC1 Elliptic Curve Cryptography</em>, section
  13345. * 4.1.3, step 5.
  13346. *
  13347. * \warning Since the output of the internal RNG is always the same for
  13348. * the same key and message, this limits the efficiency of
  13349. * blinding and leaks information through side channels. For
  13350. * secure behavior use mbedtls_ecdsa_sign_det_ext() instead.
  13351. *
  13352. * (Optimally the blinding is a random value that is different
  13353. * on every execution. In this case the blinding is still
  13354. * random from the attackers perspective, but is the same on
  13355. * each execution. This means that this blinding does not
  13356. * prevent attackers from recovering secrets by combining
  13357. * several measurement traces, but may prevent some attacks
  13358. * that exploit relationships between secret data.)
  13359. *
  13360. * \see ecp.h
  13361. *
  13362. * \param grp The context for the elliptic curve to use.
  13363. * This must be initialized and have group parameters
  13364. * set, for example through mbedtls_ecp_group_load().
  13365. * \param r The MPI context in which to store the first part
  13366. * the signature. This must be initialized.
  13367. * \param s The MPI context in which to store the second part
  13368. * the signature. This must be initialized.
  13369. * \param d The private signing key. This must be initialized
  13370. * and setup, for example through mbedtls_ecp_gen_privkey().
  13371. * \param buf The hashed content to be signed. This must be a readable
  13372. * buffer of length \p blen Bytes. It may be \c NULL if
  13373. * \p blen is zero.
  13374. * \param blen The length of \p buf in Bytes.
  13375. * \param md_alg The hash algorithm used to hash the original data.
  13376. *
  13377. * \return \c 0 on success.
  13378. * \return An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX
  13379. * error code on failure.
  13380. */
  13381. int mbedtls_ecdsa_sign_det( mbedtls_ecp_group *grp, mbedtls_mpi *r,
  13382. mbedtls_mpi *s, const mbedtls_mpi *d,
  13383. const unsigned char *buf, size_t blen,
  13384. mbedtls_md_type_t md_alg ) MBEDTLS_DEPRECATED;
  13385. #undef MBEDTLS_DEPRECATED
  13386. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  13387. /**
  13388. * \brief This function computes the ECDSA signature of a
  13389. * previously-hashed message, deterministic version.
  13390. *
  13391. * For more information, see <em>RFC-6979: Deterministic
  13392. * Usage of the Digital Signature Algorithm (DSA) and Elliptic
  13393. * Curve Digital Signature Algorithm (ECDSA)</em>.
  13394. *
  13395. * \note If the bitlength of the message hash is larger than the
  13396. * bitlength of the group order, then the hash is truncated as
  13397. * defined in <em>Standards for Efficient Cryptography Group
  13398. * (SECG): SEC1 Elliptic Curve Cryptography</em>, section
  13399. * 4.1.3, step 5.
  13400. *
  13401. * \see ecp.h
  13402. *
  13403. * \param grp The context for the elliptic curve to use.
  13404. * This must be initialized and have group parameters
  13405. * set, for example through mbedtls_ecp_group_load().
  13406. * \param r The MPI context in which to store the first part
  13407. * the signature. This must be initialized.
  13408. * \param s The MPI context in which to store the second part
  13409. * the signature. This must be initialized.
  13410. * \param d The private signing key. This must be initialized
  13411. * and setup, for example through mbedtls_ecp_gen_privkey().
  13412. * \param buf The hashed content to be signed. This must be a readable
  13413. * buffer of length \p blen Bytes. It may be \c NULL if
  13414. * \p blen is zero.
  13415. * \param blen The length of \p buf in Bytes.
  13416. * \param md_alg The hash algorithm used to hash the original data.
  13417. * \param f_rng_blind The RNG function used for blinding. This must not be
  13418. * \c NULL.
  13419. * \param p_rng_blind The RNG context to be passed to \p f_rng. This may be
  13420. * \c NULL if \p f_rng doesn't need a context parameter.
  13421. *
  13422. * \return \c 0 on success.
  13423. * \return An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX
  13424. * error code on failure.
  13425. */
  13426. int mbedtls_ecdsa_sign_det_ext( mbedtls_ecp_group *grp, mbedtls_mpi *r,
  13427. mbedtls_mpi *s, const mbedtls_mpi *d,
  13428. const unsigned char *buf, size_t blen,
  13429. mbedtls_md_type_t md_alg,
  13430. int (*f_rng_blind)(void *, unsigned char *, size_t),
  13431. void *p_rng_blind );
  13432. #endif /* MBEDTLS_ECDSA_DETERMINISTIC */
  13433. /**
  13434. * \brief This function verifies the ECDSA signature of a
  13435. * previously-hashed message.
  13436. *
  13437. * \note If the bitlength of the message hash is larger than the
  13438. * bitlength of the group order, then the hash is truncated as
  13439. * defined in <em>Standards for Efficient Cryptography Group
  13440. * (SECG): SEC1 Elliptic Curve Cryptography</em>, section
  13441. * 4.1.4, step 3.
  13442. *
  13443. * \see ecp.h
  13444. *
  13445. * \param grp The ECP group to use.
  13446. * This must be initialized and have group parameters
  13447. * set, for example through mbedtls_ecp_group_load().
  13448. * \param buf The hashed content that was signed. This must be a readable
  13449. * buffer of length \p blen Bytes. It may be \c NULL if
  13450. * \p blen is zero.
  13451. * \param blen The length of \p buf in Bytes.
  13452. * \param Q The public key to use for verification. This must be
  13453. * initialized and setup.
  13454. * \param r The first integer of the signature.
  13455. * This must be initialized.
  13456. * \param s The second integer of the signature.
  13457. * This must be initialized.
  13458. *
  13459. * \return \c 0 on success.
  13460. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if the signature
  13461. * is invalid.
  13462. * \return An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_MPI_XXX
  13463. * error code on failure for any other reason.
  13464. */
  13465. int mbedtls_ecdsa_verify( mbedtls_ecp_group *grp,
  13466. const unsigned char *buf, size_t blen,
  13467. const mbedtls_ecp_point *Q, const mbedtls_mpi *r,
  13468. const mbedtls_mpi *s);
  13469. /**
  13470. * \brief This function computes the ECDSA signature and writes it
  13471. * to a buffer, serialized as defined in <em>RFC-4492:
  13472. * Elliptic Curve Cryptography (ECC) Cipher Suites for
  13473. * Transport Layer Security (TLS)</em>.
  13474. *
  13475. * \warning It is not thread-safe to use the same context in
  13476. * multiple threads.
  13477. *
  13478. * \note The deterministic version is used if
  13479. * #MBEDTLS_ECDSA_DETERMINISTIC is defined. For more
  13480. * information, see <em>RFC-6979: Deterministic Usage
  13481. * of the Digital Signature Algorithm (DSA) and Elliptic
  13482. * Curve Digital Signature Algorithm (ECDSA)</em>.
  13483. *
  13484. * \note If the bitlength of the message hash is larger than the
  13485. * bitlength of the group order, then the hash is truncated as
  13486. * defined in <em>Standards for Efficient Cryptography Group
  13487. * (SECG): SEC1 Elliptic Curve Cryptography</em>, section
  13488. * 4.1.3, step 5.
  13489. *
  13490. * \see ecp.h
  13491. *
  13492. * \param ctx The ECDSA context to use. This must be initialized
  13493. * and have a group and private key bound to it, for example
  13494. * via mbedtls_ecdsa_genkey() or mbedtls_ecdsa_from_keypair().
  13495. * \param md_alg The message digest that was used to hash the message.
  13496. * \param hash The message hash to be signed. This must be a readable
  13497. * buffer of length \p blen Bytes.
  13498. * \param hlen The length of the hash \p hash in Bytes.
  13499. * \param sig The buffer to which to write the signature. This must be a
  13500. * writable buffer of length at least twice as large as the
  13501. * size of the curve used, plus 9. For example, 73 Bytes if
  13502. * a 256-bit curve is used. A buffer length of
  13503. * #MBEDTLS_ECDSA_MAX_LEN is always safe.
  13504. * \param slen The address at which to store the actual length of
  13505. * the signature written. Must not be \c NULL.
  13506. * \param f_rng The RNG function. This must not be \c NULL if
  13507. * #MBEDTLS_ECDSA_DETERMINISTIC is unset. Otherwise,
  13508. * it is used only for blinding and may be set to \c NULL, but
  13509. * doing so is DEPRECATED.
  13510. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  13511. * \c NULL if \p f_rng is \c NULL or doesn't use a context.
  13512. *
  13513. * \return \c 0 on success.
  13514. * \return An \c MBEDTLS_ERR_ECP_XXX, \c MBEDTLS_ERR_MPI_XXX or
  13515. * \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  13516. */
  13517. int mbedtls_ecdsa_write_signature( mbedtls_ecdsa_context *ctx,
  13518. mbedtls_md_type_t md_alg,
  13519. const unsigned char *hash, size_t hlen,
  13520. unsigned char *sig, size_t *slen,
  13521. int (*f_rng)(void *, unsigned char *, size_t),
  13522. void *p_rng );
  13523. /**
  13524. * \brief This function computes the ECDSA signature and writes it
  13525. * to a buffer, in a restartable way.
  13526. *
  13527. * \see \c mbedtls_ecdsa_write_signature()
  13528. *
  13529. * \note This function is like \c mbedtls_ecdsa_write_signature()
  13530. * but it can return early and restart according to the limit
  13531. * set with \c mbedtls_ecp_set_max_ops() to reduce blocking.
  13532. *
  13533. * \param ctx The ECDSA context to use. This must be initialized
  13534. * and have a group and private key bound to it, for example
  13535. * via mbedtls_ecdsa_genkey() or mbedtls_ecdsa_from_keypair().
  13536. * \param md_alg The message digest that was used to hash the message.
  13537. * \param hash The message hash to be signed. This must be a readable
  13538. * buffer of length \p blen Bytes.
  13539. * \param hlen The length of the hash \p hash in Bytes.
  13540. * \param sig The buffer to which to write the signature. This must be a
  13541. * writable buffer of length at least twice as large as the
  13542. * size of the curve used, plus 9. For example, 73 Bytes if
  13543. * a 256-bit curve is used. A buffer length of
  13544. * #MBEDTLS_ECDSA_MAX_LEN is always safe.
  13545. * \param slen The address at which to store the actual length of
  13546. * the signature written. Must not be \c NULL.
  13547. * \param f_rng The RNG function. This must not be \c NULL if
  13548. * #MBEDTLS_ECDSA_DETERMINISTIC is unset. Otherwise,
  13549. * it is unused and may be set to \c NULL.
  13550. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  13551. * \c NULL if \p f_rng is \c NULL or doesn't use a context.
  13552. * \param rs_ctx The restart context to use. This may be \c NULL to disable
  13553. * restarting. If it is not \c NULL, it must point to an
  13554. * initialized restart context.
  13555. *
  13556. * \return \c 0 on success.
  13557. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  13558. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  13559. * \return Another \c MBEDTLS_ERR_ECP_XXX, \c MBEDTLS_ERR_MPI_XXX or
  13560. * \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  13561. */
  13562. int mbedtls_ecdsa_write_signature_restartable( mbedtls_ecdsa_context *ctx,
  13563. mbedtls_md_type_t md_alg,
  13564. const unsigned char *hash, size_t hlen,
  13565. unsigned char *sig, size_t *slen,
  13566. int (*f_rng)(void *, unsigned char *, size_t),
  13567. void *p_rng,
  13568. mbedtls_ecdsa_restart_ctx *rs_ctx );
  13569. #if defined(MBEDTLS_ECDSA_DETERMINISTIC)
  13570. #if ! defined(MBEDTLS_DEPRECATED_REMOVED)
  13571. #if defined(MBEDTLS_DEPRECATED_WARNING)
  13572. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  13573. #else
  13574. #define MBEDTLS_DEPRECATED
  13575. #endif
  13576. /**
  13577. * \brief This function computes an ECDSA signature and writes
  13578. * it to a buffer, serialized as defined in <em>RFC-4492:
  13579. * Elliptic Curve Cryptography (ECC) Cipher Suites for
  13580. * Transport Layer Security (TLS)</em>.
  13581. *
  13582. * The deterministic version is defined in <em>RFC-6979:
  13583. * Deterministic Usage of the Digital Signature Algorithm (DSA)
  13584. * and Elliptic Curve Digital Signature Algorithm (ECDSA)</em>.
  13585. *
  13586. * \warning It is not thread-safe to use the same context in
  13587. * multiple threads.
  13588. *
  13589. * \note If the bitlength of the message hash is larger than the
  13590. * bitlength of the group order, then the hash is truncated as
  13591. * defined in <em>Standards for Efficient Cryptography Group
  13592. * (SECG): SEC1 Elliptic Curve Cryptography</em>, section
  13593. * 4.1.3, step 5.
  13594. *
  13595. * \see ecp.h
  13596. *
  13597. * \deprecated Superseded by mbedtls_ecdsa_write_signature() in
  13598. * Mbed TLS version 2.0 and later.
  13599. *
  13600. * \param ctx The ECDSA context to use. This must be initialized
  13601. * and have a group and private key bound to it, for example
  13602. * via mbedtls_ecdsa_genkey() or mbedtls_ecdsa_from_keypair().
  13603. * \param hash The message hash to be signed. This must be a readable
  13604. * buffer of length \p blen Bytes.
  13605. * \param hlen The length of the hash \p hash in Bytes.
  13606. * \param sig The buffer to which to write the signature. This must be a
  13607. * writable buffer of length at least twice as large as the
  13608. * size of the curve used, plus 9. For example, 73 Bytes if
  13609. * a 256-bit curve is used. A buffer length of
  13610. * #MBEDTLS_ECDSA_MAX_LEN is always safe.
  13611. * \param slen The address at which to store the actual length of
  13612. * the signature written. Must not be \c NULL.
  13613. * \param md_alg The message digest that was used to hash the message.
  13614. *
  13615. * \return \c 0 on success.
  13616. * \return An \c MBEDTLS_ERR_ECP_XXX, \c MBEDTLS_ERR_MPI_XXX or
  13617. * \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  13618. */
  13619. int mbedtls_ecdsa_write_signature_det( mbedtls_ecdsa_context *ctx,
  13620. const unsigned char *hash, size_t hlen,
  13621. unsigned char *sig, size_t *slen,
  13622. mbedtls_md_type_t md_alg ) MBEDTLS_DEPRECATED;
  13623. #undef MBEDTLS_DEPRECATED
  13624. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  13625. #endif /* MBEDTLS_ECDSA_DETERMINISTIC */
  13626. /**
  13627. * \brief This function reads and verifies an ECDSA signature.
  13628. *
  13629. * \note If the bitlength of the message hash is larger than the
  13630. * bitlength of the group order, then the hash is truncated as
  13631. * defined in <em>Standards for Efficient Cryptography Group
  13632. * (SECG): SEC1 Elliptic Curve Cryptography</em>, section
  13633. * 4.1.4, step 3.
  13634. *
  13635. * \see ecp.h
  13636. *
  13637. * \param ctx The ECDSA context to use. This must be initialized
  13638. * and have a group and public key bound to it.
  13639. * \param hash The message hash that was signed. This must be a readable
  13640. * buffer of length \p size Bytes.
  13641. * \param hlen The size of the hash \p hash.
  13642. * \param sig The signature to read and verify. This must be a readable
  13643. * buffer of length \p slen Bytes.
  13644. * \param slen The size of \p sig in Bytes.
  13645. *
  13646. * \return \c 0 on success.
  13647. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if signature is invalid.
  13648. * \return #MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH if there is a valid
  13649. * signature in \p sig, but its length is less than \p siglen.
  13650. * \return An \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_ERR_MPI_XXX
  13651. * error code on failure for any other reason.
  13652. */
  13653. int mbedtls_ecdsa_read_signature( mbedtls_ecdsa_context *ctx,
  13654. const unsigned char *hash, size_t hlen,
  13655. const unsigned char *sig, size_t slen );
  13656. /**
  13657. * \brief This function reads and verifies an ECDSA signature,
  13658. * in a restartable way.
  13659. *
  13660. * \see \c mbedtls_ecdsa_read_signature()
  13661. *
  13662. * \note This function is like \c mbedtls_ecdsa_read_signature()
  13663. * but it can return early and restart according to the limit
  13664. * set with \c mbedtls_ecp_set_max_ops() to reduce blocking.
  13665. *
  13666. * \param ctx The ECDSA context to use. This must be initialized
  13667. * and have a group and public key bound to it.
  13668. * \param hash The message hash that was signed. This must be a readable
  13669. * buffer of length \p size Bytes.
  13670. * \param hlen The size of the hash \p hash.
  13671. * \param sig The signature to read and verify. This must be a readable
  13672. * buffer of length \p slen Bytes.
  13673. * \param slen The size of \p sig in Bytes.
  13674. * \param rs_ctx The restart context to use. This may be \c NULL to disable
  13675. * restarting. If it is not \c NULL, it must point to an
  13676. * initialized restart context.
  13677. *
  13678. * \return \c 0 on success.
  13679. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA if signature is invalid.
  13680. * \return #MBEDTLS_ERR_ECP_SIG_LEN_MISMATCH if there is a valid
  13681. * signature in \p sig, but its length is less than \p siglen.
  13682. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  13683. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  13684. * \return Another \c MBEDTLS_ERR_ECP_XXX or \c MBEDTLS_ERR_MPI_XXX
  13685. * error code on failure for any other reason.
  13686. */
  13687. int mbedtls_ecdsa_read_signature_restartable( mbedtls_ecdsa_context *ctx,
  13688. const unsigned char *hash, size_t hlen,
  13689. const unsigned char *sig, size_t slen,
  13690. mbedtls_ecdsa_restart_ctx *rs_ctx );
  13691. /**
  13692. * \brief This function generates an ECDSA keypair on the given curve.
  13693. *
  13694. * \see ecp.h
  13695. *
  13696. * \param ctx The ECDSA context to store the keypair in.
  13697. * This must be initialized.
  13698. * \param gid The elliptic curve to use. One of the various
  13699. * \c MBEDTLS_ECP_DP_XXX macros depending on configuration.
  13700. * \param f_rng The RNG function to use. This must not be \c NULL.
  13701. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  13702. * \c NULL if \p f_rng doesn't need a context argument.
  13703. *
  13704. * \return \c 0 on success.
  13705. * \return An \c MBEDTLS_ERR_ECP_XXX code on failure.
  13706. */
  13707. int mbedtls_ecdsa_genkey( mbedtls_ecdsa_context *ctx, mbedtls_ecp_group_id gid,
  13708. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );
  13709. /**
  13710. * \brief This function sets up an ECDSA context from an EC key pair.
  13711. *
  13712. * \see ecp.h
  13713. *
  13714. * \param ctx The ECDSA context to setup. This must be initialized.
  13715. * \param key The EC key to use. This must be initialized and hold
  13716. * a private-public key pair or a public key. In the former
  13717. * case, the ECDSA context may be used for signature creation
  13718. * and verification after this call. In the latter case, it
  13719. * may be used for signature verification.
  13720. *
  13721. * \return \c 0 on success.
  13722. * \return An \c MBEDTLS_ERR_ECP_XXX code on failure.
  13723. */
  13724. int mbedtls_ecdsa_from_keypair( mbedtls_ecdsa_context *ctx,
  13725. const mbedtls_ecp_keypair *key );
  13726. /**
  13727. * \brief This function initializes an ECDSA context.
  13728. *
  13729. * \param ctx The ECDSA context to initialize.
  13730. * This must not be \c NULL.
  13731. */
  13732. void mbedtls_ecdsa_init( mbedtls_ecdsa_context *ctx );
  13733. /**
  13734. * \brief This function frees an ECDSA context.
  13735. *
  13736. * \param ctx The ECDSA context to free. This may be \c NULL,
  13737. * in which case this function does nothing. If it
  13738. * is not \c NULL, it must be initialized.
  13739. */
  13740. void mbedtls_ecdsa_free( mbedtls_ecdsa_context *ctx );
  13741. #if defined(MBEDTLS_ECP_RESTARTABLE)
  13742. /**
  13743. * \brief Initialize a restart context.
  13744. *
  13745. * \param ctx The restart context to initialize.
  13746. * This must not be \c NULL.
  13747. */
  13748. void mbedtls_ecdsa_restart_init( mbedtls_ecdsa_restart_ctx *ctx );
  13749. /**
  13750. * \brief Free the components of a restart context.
  13751. *
  13752. * \param ctx The restart context to free. This may be \c NULL,
  13753. * in which case this function does nothing. If it
  13754. * is not \c NULL, it must be initialized.
  13755. */
  13756. void mbedtls_ecdsa_restart_free( mbedtls_ecdsa_restart_ctx *ctx );
  13757. #endif /* MBEDTLS_ECP_RESTARTABLE */
  13758. #ifdef __cplusplus
  13759. }
  13760. #endif
  13761. #endif /* ecdsa.h */
  13762. /********* Start of file include/mbedtls/ecjpake.h ************/
  13763. /**
  13764. * \file ecjpake.h
  13765. *
  13766. * \brief Elliptic curve J-PAKE
  13767. */
  13768. /*
  13769. * Copyright The Mbed TLS Contributors
  13770. * SPDX-License-Identifier: Apache-2.0
  13771. *
  13772. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  13773. * not use this file except in compliance with the License.
  13774. * You may obtain a copy of the License at
  13775. *
  13776. * http://www.apache.org/licenses/LICENSE-2.0
  13777. *
  13778. * Unless required by applicable law or agreed to in writing, software
  13779. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  13780. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13781. * See the License for the specific language governing permissions and
  13782. * limitations under the License.
  13783. */
  13784. #ifndef MBEDTLS_ECJPAKE_H
  13785. #define MBEDTLS_ECJPAKE_H
  13786. /*
  13787. * J-PAKE is a password-authenticated key exchange that allows deriving a
  13788. * strong shared secret from a (potentially low entropy) pre-shared
  13789. * passphrase, with forward secrecy and mutual authentication.
  13790. * https://en.wikipedia.org/wiki/Password_Authenticated_Key_Exchange_by_Juggling
  13791. *
  13792. * This file implements the Elliptic Curve variant of J-PAKE,
  13793. * as defined in Chapter 7.4 of the Thread v1.0 Specification,
  13794. * available to members of the Thread Group http://threadgroup.org/
  13795. *
  13796. * As the J-PAKE algorithm is inherently symmetric, so is our API.
  13797. * Each party needs to send its first round message, in any order, to the
  13798. * other party, then each sends its second round message, in any order.
  13799. * The payloads are serialized in a way suitable for use in TLS, but could
  13800. * also be use outside TLS.
  13801. */
  13802. #if !defined(MBEDTLS_CONFIG_FILE)
  13803. #else
  13804. #endif
  13805. #ifdef __cplusplus
  13806. extern "C" {
  13807. #endif
  13808. /**
  13809. * Roles in the EC J-PAKE exchange
  13810. */
  13811. typedef enum {
  13812. MBEDTLS_ECJPAKE_CLIENT = 0, /**< Client */
  13813. MBEDTLS_ECJPAKE_SERVER, /**< Server */
  13814. } mbedtls_ecjpake_role;
  13815. #if !defined(MBEDTLS_ECJPAKE_ALT)
  13816. /**
  13817. * EC J-PAKE context structure.
  13818. *
  13819. * J-PAKE is a symmetric protocol, except for the identifiers used in
  13820. * Zero-Knowledge Proofs, and the serialization of the second message
  13821. * (KeyExchange) as defined by the Thread spec.
  13822. *
  13823. * In order to benefit from this symmetry, we choose a different naming
  13824. * convetion from the Thread v1.0 spec. Correspondance is indicated in the
  13825. * description as a pair C: client name, S: server name
  13826. */
  13827. typedef struct mbedtls_ecjpake_context
  13828. {
  13829. const mbedtls_md_info_t *md_info; /**< Hash to use */
  13830. mbedtls_ecp_group grp; /**< Elliptic curve */
  13831. mbedtls_ecjpake_role role; /**< Are we client or server? */
  13832. int point_format; /**< Format for point export */
  13833. mbedtls_ecp_point Xm1; /**< My public key 1 C: X1, S: X3 */
  13834. mbedtls_ecp_point Xm2; /**< My public key 2 C: X2, S: X4 */
  13835. mbedtls_ecp_point Xp1; /**< Peer public key 1 C: X3, S: X1 */
  13836. mbedtls_ecp_point Xp2; /**< Peer public key 2 C: X4, S: X2 */
  13837. mbedtls_ecp_point Xp; /**< Peer public key C: Xs, S: Xc */
  13838. mbedtls_mpi xm1; /**< My private key 1 C: x1, S: x3 */
  13839. mbedtls_mpi xm2; /**< My private key 2 C: x2, S: x4 */
  13840. mbedtls_mpi s; /**< Pre-shared secret (passphrase) */
  13841. } mbedtls_ecjpake_context;
  13842. #else /* MBEDTLS_ECJPAKE_ALT */
  13843. #endif /* MBEDTLS_ECJPAKE_ALT */
  13844. /**
  13845. * \brief Initialize an ECJPAKE context.
  13846. *
  13847. * \param ctx The ECJPAKE context to initialize.
  13848. * This must not be \c NULL.
  13849. */
  13850. void mbedtls_ecjpake_init( mbedtls_ecjpake_context *ctx );
  13851. /**
  13852. * \brief Set up an ECJPAKE context for use.
  13853. *
  13854. * \note Currently the only values for hash/curve allowed by the
  13855. * standard are #MBEDTLS_MD_SHA256/#MBEDTLS_ECP_DP_SECP256R1.
  13856. *
  13857. * \param ctx The ECJPAKE context to set up. This must be initialized.
  13858. * \param role The role of the caller. This must be either
  13859. * #MBEDTLS_ECJPAKE_CLIENT or #MBEDTLS_ECJPAKE_SERVER.
  13860. * \param hash The identifier of the hash function to use,
  13861. * for example #MBEDTLS_MD_SHA256.
  13862. * \param curve The identifier of the elliptic curve to use,
  13863. * for example #MBEDTLS_ECP_DP_SECP256R1.
  13864. * \param secret The pre-shared secret (passphrase). This must be
  13865. * a readable buffer of length \p len Bytes. It need
  13866. * only be valid for the duration of this call.
  13867. * \param len The length of the pre-shared secret \p secret.
  13868. *
  13869. * \return \c 0 if successful.
  13870. * \return A negative error code on failure.
  13871. */
  13872. int mbedtls_ecjpake_setup( mbedtls_ecjpake_context *ctx,
  13873. mbedtls_ecjpake_role role,
  13874. mbedtls_md_type_t hash,
  13875. mbedtls_ecp_group_id curve,
  13876. const unsigned char *secret,
  13877. size_t len );
  13878. /**
  13879. * \brief Check if an ECJPAKE context is ready for use.
  13880. *
  13881. * \param ctx The ECJPAKE context to check. This must be
  13882. * initialized.
  13883. *
  13884. * \return \c 0 if the context is ready for use.
  13885. * \return #MBEDTLS_ERR_ECP_BAD_INPUT_DATA otherwise.
  13886. */
  13887. int mbedtls_ecjpake_check( const mbedtls_ecjpake_context *ctx );
  13888. /**
  13889. * \brief Generate and write the first round message
  13890. * (TLS: contents of the Client/ServerHello extension,
  13891. * excluding extension type and length bytes).
  13892. *
  13893. * \param ctx The ECJPAKE context to use. This must be
  13894. * initialized and set up.
  13895. * \param buf The buffer to write the contents to. This must be a
  13896. * writable buffer of length \p len Bytes.
  13897. * \param len The length of \p buf in Bytes.
  13898. * \param olen The address at which to store the total number
  13899. * of Bytes written to \p buf. This must not be \c NULL.
  13900. * \param f_rng The RNG function to use. This must not be \c NULL.
  13901. * \param p_rng The RNG parameter to be passed to \p f_rng. This
  13902. * may be \c NULL if \p f_rng doesn't use a context.
  13903. *
  13904. * \return \c 0 if successful.
  13905. * \return A negative error code on failure.
  13906. */
  13907. int mbedtls_ecjpake_write_round_one( mbedtls_ecjpake_context *ctx,
  13908. unsigned char *buf, size_t len, size_t *olen,
  13909. int (*f_rng)(void *, unsigned char *, size_t),
  13910. void *p_rng );
  13911. /**
  13912. * \brief Read and process the first round message
  13913. * (TLS: contents of the Client/ServerHello extension,
  13914. * excluding extension type and length bytes).
  13915. *
  13916. * \param ctx The ECJPAKE context to use. This must be initialized
  13917. * and set up.
  13918. * \param buf The buffer holding the first round message. This must
  13919. * be a readable buffer of length \p len Bytes.
  13920. * \param len The length in Bytes of \p buf.
  13921. *
  13922. * \return \c 0 if successful.
  13923. * \return A negative error code on failure.
  13924. */
  13925. int mbedtls_ecjpake_read_round_one( mbedtls_ecjpake_context *ctx,
  13926. const unsigned char *buf,
  13927. size_t len );
  13928. /**
  13929. * \brief Generate and write the second round message
  13930. * (TLS: contents of the Client/ServerKeyExchange).
  13931. *
  13932. * \param ctx The ECJPAKE context to use. This must be initialized,
  13933. * set up, and already have performed round one.
  13934. * \param buf The buffer to write the round two contents to.
  13935. * This must be a writable buffer of length \p len Bytes.
  13936. * \param len The size of \p buf in Bytes.
  13937. * \param olen The address at which to store the total number of Bytes
  13938. * written to \p buf. This must not be \c NULL.
  13939. * \param f_rng The RNG function to use. This must not be \c NULL.
  13940. * \param p_rng The RNG parameter to be passed to \p f_rng. This
  13941. * may be \c NULL if \p f_rng doesn't use a context.
  13942. *
  13943. * \return \c 0 if successful.
  13944. * \return A negative error code on failure.
  13945. */
  13946. int mbedtls_ecjpake_write_round_two( mbedtls_ecjpake_context *ctx,
  13947. unsigned char *buf, size_t len, size_t *olen,
  13948. int (*f_rng)(void *, unsigned char *, size_t),
  13949. void *p_rng );
  13950. /**
  13951. * \brief Read and process the second round message
  13952. * (TLS: contents of the Client/ServerKeyExchange).
  13953. *
  13954. * \param ctx The ECJPAKE context to use. This must be initialized
  13955. * and set up and already have performed round one.
  13956. * \param buf The buffer holding the second round message. This must
  13957. * be a readable buffer of length \p len Bytes.
  13958. * \param len The length in Bytes of \p buf.
  13959. *
  13960. * \return \c 0 if successful.
  13961. * \return A negative error code on failure.
  13962. */
  13963. int mbedtls_ecjpake_read_round_two( mbedtls_ecjpake_context *ctx,
  13964. const unsigned char *buf,
  13965. size_t len );
  13966. /**
  13967. * \brief Derive the shared secret
  13968. * (TLS: Pre-Master Secret).
  13969. *
  13970. * \param ctx The ECJPAKE context to use. This must be initialized,
  13971. * set up and have performed both round one and two.
  13972. * \param buf The buffer to write the derived secret to. This must
  13973. * be a writable buffer of length \p len Bytes.
  13974. * \param len The length of \p buf in Bytes.
  13975. * \param olen The address at which to store the total number of Bytes
  13976. * written to \p buf. This must not be \c NULL.
  13977. * \param f_rng The RNG function to use. This must not be \c NULL.
  13978. * \param p_rng The RNG parameter to be passed to \p f_rng. This
  13979. * may be \c NULL if \p f_rng doesn't use a context.
  13980. *
  13981. * \return \c 0 if successful.
  13982. * \return A negative error code on failure.
  13983. */
  13984. int mbedtls_ecjpake_derive_secret( mbedtls_ecjpake_context *ctx,
  13985. unsigned char *buf, size_t len, size_t *olen,
  13986. int (*f_rng)(void *, unsigned char *, size_t),
  13987. void *p_rng );
  13988. /**
  13989. * \brief This clears an ECJPAKE context and frees any
  13990. * embedded data structure.
  13991. *
  13992. * \param ctx The ECJPAKE context to free. This may be \c NULL,
  13993. * in which case this function does nothing. If it is not
  13994. * \c NULL, it must point to an initialized ECJPAKE context.
  13995. */
  13996. void mbedtls_ecjpake_free( mbedtls_ecjpake_context *ctx );
  13997. #if defined(MBEDTLS_SELF_TEST)
  13998. /**
  13999. * \brief Checkup routine
  14000. *
  14001. * \return 0 if successful, or 1 if a test failed
  14002. */
  14003. int mbedtls_ecjpake_self_test( int verbose );
  14004. #endif /* MBEDTLS_SELF_TEST */
  14005. #ifdef __cplusplus
  14006. }
  14007. #endif
  14008. #endif /* ecjpake.h */
  14009. /********* Start of file include/mbedtls/pk.h ************/
  14010. /**
  14011. * \file pk.h
  14012. *
  14013. * \brief Public Key abstraction layer
  14014. */
  14015. /*
  14016. * Copyright The Mbed TLS Contributors
  14017. * SPDX-License-Identifier: Apache-2.0
  14018. *
  14019. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  14020. * not use this file except in compliance with the License.
  14021. * You may obtain a copy of the License at
  14022. *
  14023. * http://www.apache.org/licenses/LICENSE-2.0
  14024. *
  14025. * Unless required by applicable law or agreed to in writing, software
  14026. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  14027. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14028. * See the License for the specific language governing permissions and
  14029. * limitations under the License.
  14030. */
  14031. #ifndef MBEDTLS_PK_H
  14032. #define MBEDTLS_PK_H
  14033. #if !defined(MBEDTLS_CONFIG_FILE)
  14034. #else
  14035. #endif
  14036. #if defined(MBEDTLS_RSA_C)
  14037. #endif
  14038. #if defined(MBEDTLS_ECP_C)
  14039. #endif
  14040. #if defined(MBEDTLS_ECDSA_C)
  14041. #endif
  14042. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  14043. #endif
  14044. #if ( defined(__ARMCC_VERSION) || defined(_MSC_VER) ) && \
  14045. !defined(inline) && !defined(__cplusplus)
  14046. #define inline __inline
  14047. #endif
  14048. /** Memory allocation failed. */
  14049. #define MBEDTLS_ERR_PK_ALLOC_FAILED -0x3F80
  14050. /** Type mismatch, eg attempt to encrypt with an ECDSA key */
  14051. #define MBEDTLS_ERR_PK_TYPE_MISMATCH -0x3F00
  14052. /** Bad input parameters to function. */
  14053. #define MBEDTLS_ERR_PK_BAD_INPUT_DATA -0x3E80
  14054. /** Read/write of file failed. */
  14055. #define MBEDTLS_ERR_PK_FILE_IO_ERROR -0x3E00
  14056. /** Unsupported key version */
  14057. #define MBEDTLS_ERR_PK_KEY_INVALID_VERSION -0x3D80
  14058. /** Invalid key tag or value. */
  14059. #define MBEDTLS_ERR_PK_KEY_INVALID_FORMAT -0x3D00
  14060. /** Key algorithm is unsupported (only RSA and EC are supported). */
  14061. #define MBEDTLS_ERR_PK_UNKNOWN_PK_ALG -0x3C80
  14062. /** Private key password can't be empty. */
  14063. #define MBEDTLS_ERR_PK_PASSWORD_REQUIRED -0x3C00
  14064. /** Given private key password does not allow for correct decryption. */
  14065. #define MBEDTLS_ERR_PK_PASSWORD_MISMATCH -0x3B80
  14066. /** The pubkey tag or value is invalid (only RSA and EC are supported). */
  14067. #define MBEDTLS_ERR_PK_INVALID_PUBKEY -0x3B00
  14068. /** The algorithm tag or value is invalid. */
  14069. #define MBEDTLS_ERR_PK_INVALID_ALG -0x3A80
  14070. /** Elliptic curve is unsupported (only NIST curves are supported). */
  14071. #define MBEDTLS_ERR_PK_UNKNOWN_NAMED_CURVE -0x3A00
  14072. /** Unavailable feature, e.g. RSA disabled for RSA key. */
  14073. #define MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE -0x3980
  14074. /** The buffer contains a valid signature followed by more data. */
  14075. #define MBEDTLS_ERR_PK_SIG_LEN_MISMATCH -0x3900
  14076. /* MBEDTLS_ERR_PK_HW_ACCEL_FAILED is deprecated and should not be used. */
  14077. /** PK hardware accelerator failed. */
  14078. #define MBEDTLS_ERR_PK_HW_ACCEL_FAILED -0x3880
  14079. #ifdef __cplusplus
  14080. extern "C" {
  14081. #endif
  14082. /**
  14083. * \brief Public key types
  14084. */
  14085. typedef enum {
  14086. MBEDTLS_PK_NONE=0,
  14087. MBEDTLS_PK_RSA,
  14088. MBEDTLS_PK_ECKEY,
  14089. MBEDTLS_PK_ECKEY_DH,
  14090. MBEDTLS_PK_ECDSA,
  14091. MBEDTLS_PK_RSA_ALT,
  14092. MBEDTLS_PK_RSASSA_PSS,
  14093. MBEDTLS_PK_OPAQUE,
  14094. } mbedtls_pk_type_t;
  14095. /**
  14096. * \brief Options for RSASSA-PSS signature verification.
  14097. * See \c mbedtls_rsa_rsassa_pss_verify_ext()
  14098. */
  14099. typedef struct mbedtls_pk_rsassa_pss_options
  14100. {
  14101. mbedtls_md_type_t mgf1_hash_id;
  14102. int expected_salt_len;
  14103. } mbedtls_pk_rsassa_pss_options;
  14104. /**
  14105. * \brief Maximum size of a signature made by mbedtls_pk_sign().
  14106. */
  14107. /* We need to set MBEDTLS_PK_SIGNATURE_MAX_SIZE to the maximum signature
  14108. * size among the supported signature types. Do it by starting at 0,
  14109. * then incrementally increasing to be large enough for each supported
  14110. * signature mechanism.
  14111. *
  14112. * The resulting value can be 0, for example if MBEDTLS_ECDH_C is enabled
  14113. * (which allows the pk module to be included) but neither MBEDTLS_ECDSA_C
  14114. * nor MBEDTLS_RSA_C nor any opaque signature mechanism (PSA or RSA_ALT).
  14115. */
  14116. #define MBEDTLS_PK_SIGNATURE_MAX_SIZE 0
  14117. #if ( defined(MBEDTLS_RSA_C) || defined(MBEDTLS_PK_RSA_ALT_SUPPORT) ) && \
  14118. MBEDTLS_MPI_MAX_SIZE > MBEDTLS_PK_SIGNATURE_MAX_SIZE
  14119. /* For RSA, the signature can be as large as the bignum module allows.
  14120. * For RSA_ALT, the signature size is not necessarily tied to what the
  14121. * bignum module can do, but in the absence of any specific setting,
  14122. * we use that (rsa_alt_sign_wrap in pk_wrap will check). */
  14123. #undef MBEDTLS_PK_SIGNATURE_MAX_SIZE
  14124. #define MBEDTLS_PK_SIGNATURE_MAX_SIZE MBEDTLS_MPI_MAX_SIZE
  14125. #endif
  14126. #if defined(MBEDTLS_ECDSA_C) && \
  14127. MBEDTLS_ECDSA_MAX_LEN > MBEDTLS_PK_SIGNATURE_MAX_SIZE
  14128. /* For ECDSA, the ecdsa module exports a constant for the maximum
  14129. * signature size. */
  14130. #undef MBEDTLS_PK_SIGNATURE_MAX_SIZE
  14131. #define MBEDTLS_PK_SIGNATURE_MAX_SIZE MBEDTLS_ECDSA_MAX_LEN
  14132. #endif
  14133. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  14134. #if PSA_SIGNATURE_MAX_SIZE > MBEDTLS_PK_SIGNATURE_MAX_SIZE
  14135. /* PSA_SIGNATURE_MAX_SIZE is the maximum size of a signature made
  14136. * through the PSA API in the PSA representation. */
  14137. #undef MBEDTLS_PK_SIGNATURE_MAX_SIZE
  14138. #define MBEDTLS_PK_SIGNATURE_MAX_SIZE PSA_SIGNATURE_MAX_SIZE
  14139. #endif
  14140. #if PSA_VENDOR_ECDSA_SIGNATURE_MAX_SIZE + 11 > MBEDTLS_PK_SIGNATURE_MAX_SIZE
  14141. /* The Mbed TLS representation is different for ECDSA signatures:
  14142. * PSA uses the raw concatenation of r and s,
  14143. * whereas Mbed TLS uses the ASN.1 representation (SEQUENCE of two INTEGERs).
  14144. * Add the overhead of ASN.1: up to (1+2) + 2 * (1+2+1) for the
  14145. * types, lengths (represented by up to 2 bytes), and potential leading
  14146. * zeros of the INTEGERs and the SEQUENCE. */
  14147. #undef MBEDTLS_PK_SIGNATURE_MAX_SIZE
  14148. #define MBEDTLS_PK_SIGNATURE_MAX_SIZE ( PSA_VENDOR_ECDSA_SIGNATURE_MAX_SIZE + 11 )
  14149. #endif
  14150. #endif /* defined(MBEDTLS_USE_PSA_CRYPTO) */
  14151. /**
  14152. * \brief Types for interfacing with the debug module
  14153. */
  14154. typedef enum
  14155. {
  14156. MBEDTLS_PK_DEBUG_NONE = 0,
  14157. MBEDTLS_PK_DEBUG_MPI,
  14158. MBEDTLS_PK_DEBUG_ECP,
  14159. } mbedtls_pk_debug_type;
  14160. /**
  14161. * \brief Item to send to the debug module
  14162. */
  14163. typedef struct mbedtls_pk_debug_item
  14164. {
  14165. mbedtls_pk_debug_type type;
  14166. const char *name;
  14167. void *value;
  14168. } mbedtls_pk_debug_item;
  14169. /** Maximum number of item send for debugging, plus 1 */
  14170. #define MBEDTLS_PK_DEBUG_MAX_ITEMS 3
  14171. /**
  14172. * \brief Public key information and operations
  14173. */
  14174. typedef struct mbedtls_pk_info_t mbedtls_pk_info_t;
  14175. /**
  14176. * \brief Public key container
  14177. */
  14178. typedef struct mbedtls_pk_context
  14179. {
  14180. const mbedtls_pk_info_t * pk_info; /**< Public key information */
  14181. void * pk_ctx; /**< Underlying public key context */
  14182. } mbedtls_pk_context;
  14183. #if defined(MBEDTLS_ECDSA_C) && defined(MBEDTLS_ECP_RESTARTABLE)
  14184. /**
  14185. * \brief Context for resuming operations
  14186. */
  14187. typedef struct
  14188. {
  14189. const mbedtls_pk_info_t * pk_info; /**< Public key information */
  14190. void * rs_ctx; /**< Underlying restart context */
  14191. } mbedtls_pk_restart_ctx;
  14192. #else /* MBEDTLS_ECDSA_C && MBEDTLS_ECP_RESTARTABLE */
  14193. /* Now we can declare functions that take a pointer to that */
  14194. typedef void mbedtls_pk_restart_ctx;
  14195. #endif /* MBEDTLS_ECDSA_C && MBEDTLS_ECP_RESTARTABLE */
  14196. #if defined(MBEDTLS_RSA_C)
  14197. /**
  14198. * Quick access to an RSA context inside a PK context.
  14199. *
  14200. * \warning You must make sure the PK context actually holds an RSA context
  14201. * before using this function!
  14202. */
  14203. static inline mbedtls_rsa_context *mbedtls_pk_rsa( const mbedtls_pk_context pk )
  14204. {
  14205. return( (mbedtls_rsa_context *) (pk).pk_ctx );
  14206. }
  14207. #endif /* MBEDTLS_RSA_C */
  14208. #if defined(MBEDTLS_ECP_C)
  14209. /**
  14210. * Quick access to an EC context inside a PK context.
  14211. *
  14212. * \warning You must make sure the PK context actually holds an EC context
  14213. * before using this function!
  14214. */
  14215. static inline mbedtls_ecp_keypair *mbedtls_pk_ec( const mbedtls_pk_context pk )
  14216. {
  14217. return( (mbedtls_ecp_keypair *) (pk).pk_ctx );
  14218. }
  14219. #endif /* MBEDTLS_ECP_C */
  14220. #if defined(MBEDTLS_PK_RSA_ALT_SUPPORT)
  14221. /**
  14222. * \brief Types for RSA-alt abstraction
  14223. */
  14224. typedef int (*mbedtls_pk_rsa_alt_decrypt_func)( void *ctx, int mode, size_t *olen,
  14225. const unsigned char *input, unsigned char *output,
  14226. size_t output_max_len );
  14227. typedef int (*mbedtls_pk_rsa_alt_sign_func)( void *ctx,
  14228. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
  14229. int mode, mbedtls_md_type_t md_alg, unsigned int hashlen,
  14230. const unsigned char *hash, unsigned char *sig );
  14231. typedef size_t (*mbedtls_pk_rsa_alt_key_len_func)( void *ctx );
  14232. #endif /* MBEDTLS_PK_RSA_ALT_SUPPORT */
  14233. /**
  14234. * \brief Return information associated with the given PK type
  14235. *
  14236. * \param pk_type PK type to search for.
  14237. *
  14238. * \return The PK info associated with the type or NULL if not found.
  14239. */
  14240. const mbedtls_pk_info_t *mbedtls_pk_info_from_type( mbedtls_pk_type_t pk_type );
  14241. /**
  14242. * \brief Initialize a #mbedtls_pk_context (as NONE).
  14243. *
  14244. * \param ctx The context to initialize.
  14245. * This must not be \c NULL.
  14246. */
  14247. void mbedtls_pk_init( mbedtls_pk_context *ctx );
  14248. /**
  14249. * \brief Free the components of a #mbedtls_pk_context.
  14250. *
  14251. * \param ctx The context to clear. It must have been initialized.
  14252. * If this is \c NULL, this function does nothing.
  14253. *
  14254. * \note For contexts that have been set up with
  14255. * mbedtls_pk_setup_opaque(), this does not free the underlying
  14256. * PSA key and you still need to call psa_destroy_key()
  14257. * independently if you want to destroy that key.
  14258. */
  14259. void mbedtls_pk_free( mbedtls_pk_context *ctx );
  14260. #if defined(MBEDTLS_ECDSA_C) && defined(MBEDTLS_ECP_RESTARTABLE)
  14261. /**
  14262. * \brief Initialize a restart context
  14263. *
  14264. * \param ctx The context to initialize.
  14265. * This must not be \c NULL.
  14266. */
  14267. void mbedtls_pk_restart_init( mbedtls_pk_restart_ctx *ctx );
  14268. /**
  14269. * \brief Free the components of a restart context
  14270. *
  14271. * \param ctx The context to clear. It must have been initialized.
  14272. * If this is \c NULL, this function does nothing.
  14273. */
  14274. void mbedtls_pk_restart_free( mbedtls_pk_restart_ctx *ctx );
  14275. #endif /* MBEDTLS_ECDSA_C && MBEDTLS_ECP_RESTARTABLE */
  14276. /**
  14277. * \brief Initialize a PK context with the information given
  14278. * and allocates the type-specific PK subcontext.
  14279. *
  14280. * \param ctx Context to initialize. It must not have been set
  14281. * up yet (type #MBEDTLS_PK_NONE).
  14282. * \param info Information to use
  14283. *
  14284. * \return 0 on success,
  14285. * MBEDTLS_ERR_PK_BAD_INPUT_DATA on invalid input,
  14286. * MBEDTLS_ERR_PK_ALLOC_FAILED on allocation failure.
  14287. *
  14288. * \note For contexts holding an RSA-alt key, use
  14289. * \c mbedtls_pk_setup_rsa_alt() instead.
  14290. */
  14291. int mbedtls_pk_setup( mbedtls_pk_context *ctx, const mbedtls_pk_info_t *info );
  14292. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  14293. /**
  14294. * \brief Initialize a PK context to wrap a PSA key.
  14295. *
  14296. * \note This function replaces mbedtls_pk_setup() for contexts
  14297. * that wrap a (possibly opaque) PSA key instead of
  14298. * storing and manipulating the key material directly.
  14299. *
  14300. * \param ctx The context to initialize. It must be empty (type NONE).
  14301. * \param key The PSA key to wrap, which must hold an ECC key pair
  14302. * (see notes below).
  14303. *
  14304. * \note The wrapped key must remain valid as long as the
  14305. * wrapping PK context is in use, that is at least between
  14306. * the point this function is called and the point
  14307. * mbedtls_pk_free() is called on this context. The wrapped
  14308. * key might then be independently used or destroyed.
  14309. *
  14310. * \note This function is currently only available for ECC key
  14311. * pairs (that is, ECC keys containing private key material).
  14312. * Support for other key types may be added later.
  14313. *
  14314. * \return \c 0 on success.
  14315. * \return #MBEDTLS_ERR_PK_BAD_INPUT_DATA on invalid input
  14316. * (context already used, invalid key identifier).
  14317. * \return #MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE if the key is not an
  14318. * ECC key pair.
  14319. * \return #MBEDTLS_ERR_PK_ALLOC_FAILED on allocation failure.
  14320. */
  14321. int mbedtls_pk_setup_opaque( mbedtls_pk_context *ctx,
  14322. const psa_key_id_t key );
  14323. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  14324. #if defined(MBEDTLS_PK_RSA_ALT_SUPPORT)
  14325. /**
  14326. * \brief Initialize an RSA-alt context
  14327. *
  14328. * \param ctx Context to initialize. It must not have been set
  14329. * up yet (type #MBEDTLS_PK_NONE).
  14330. * \param key RSA key pointer
  14331. * \param decrypt_func Decryption function
  14332. * \param sign_func Signing function
  14333. * \param key_len_func Function returning key length in bytes
  14334. *
  14335. * \return 0 on success, or MBEDTLS_ERR_PK_BAD_INPUT_DATA if the
  14336. * context wasn't already initialized as RSA_ALT.
  14337. *
  14338. * \note This function replaces \c mbedtls_pk_setup() for RSA-alt.
  14339. */
  14340. int mbedtls_pk_setup_rsa_alt( mbedtls_pk_context *ctx, void * key,
  14341. mbedtls_pk_rsa_alt_decrypt_func decrypt_func,
  14342. mbedtls_pk_rsa_alt_sign_func sign_func,
  14343. mbedtls_pk_rsa_alt_key_len_func key_len_func );
  14344. #endif /* MBEDTLS_PK_RSA_ALT_SUPPORT */
  14345. /**
  14346. * \brief Get the size in bits of the underlying key
  14347. *
  14348. * \param ctx The context to query. It must have been initialized.
  14349. *
  14350. * \return Key size in bits, or 0 on error
  14351. */
  14352. size_t mbedtls_pk_get_bitlen( const mbedtls_pk_context *ctx );
  14353. /**
  14354. * \brief Get the length in bytes of the underlying key
  14355. *
  14356. * \param ctx The context to query. It must have been initialized.
  14357. *
  14358. * \return Key length in bytes, or 0 on error
  14359. */
  14360. static inline size_t mbedtls_pk_get_len( const mbedtls_pk_context *ctx )
  14361. {
  14362. return( ( mbedtls_pk_get_bitlen( ctx ) + 7 ) / 8 );
  14363. }
  14364. /**
  14365. * \brief Tell if a context can do the operation given by type
  14366. *
  14367. * \param ctx The context to query. It must have been initialized.
  14368. * \param type The desired type.
  14369. *
  14370. * \return 1 if the context can do operations on the given type.
  14371. * \return 0 if the context cannot do the operations on the given
  14372. * type. This is always the case for a context that has
  14373. * been initialized but not set up, or that has been
  14374. * cleared with mbedtls_pk_free().
  14375. */
  14376. int mbedtls_pk_can_do( const mbedtls_pk_context *ctx, mbedtls_pk_type_t type );
  14377. /**
  14378. * \brief Verify signature (including padding if relevant).
  14379. *
  14380. * \param ctx The PK context to use. It must have been set up.
  14381. * \param md_alg Hash algorithm used (see notes)
  14382. * \param hash Hash of the message to sign
  14383. * \param hash_len Hash length or 0 (see notes)
  14384. * \param sig Signature to verify
  14385. * \param sig_len Signature length
  14386. *
  14387. * \return 0 on success (signature is valid),
  14388. * #MBEDTLS_ERR_PK_SIG_LEN_MISMATCH if there is a valid
  14389. * signature in sig but its length is less than \p siglen,
  14390. * or a specific error code.
  14391. *
  14392. * \note For RSA keys, the default padding type is PKCS#1 v1.5.
  14393. * Use \c mbedtls_pk_verify_ext( MBEDTLS_PK_RSASSA_PSS, ... )
  14394. * to verify RSASSA_PSS signatures.
  14395. *
  14396. * \note If hash_len is 0, then the length associated with md_alg
  14397. * is used instead, or an error returned if it is invalid.
  14398. *
  14399. * \note md_alg may be MBEDTLS_MD_NONE, only if hash_len != 0
  14400. */
  14401. int mbedtls_pk_verify( mbedtls_pk_context *ctx, mbedtls_md_type_t md_alg,
  14402. const unsigned char *hash, size_t hash_len,
  14403. const unsigned char *sig, size_t sig_len );
  14404. /**
  14405. * \brief Restartable version of \c mbedtls_pk_verify()
  14406. *
  14407. * \note Performs the same job as \c mbedtls_pk_verify(), but can
  14408. * return early and restart according to the limit set with
  14409. * \c mbedtls_ecp_set_max_ops() to reduce blocking for ECC
  14410. * operations. For RSA, same as \c mbedtls_pk_verify().
  14411. *
  14412. * \param ctx The PK context to use. It must have been set up.
  14413. * \param md_alg Hash algorithm used (see notes)
  14414. * \param hash Hash of the message to sign
  14415. * \param hash_len Hash length or 0 (see notes)
  14416. * \param sig Signature to verify
  14417. * \param sig_len Signature length
  14418. * \param rs_ctx Restart context (NULL to disable restart)
  14419. *
  14420. * \return See \c mbedtls_pk_verify(), or
  14421. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  14422. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  14423. */
  14424. int mbedtls_pk_verify_restartable( mbedtls_pk_context *ctx,
  14425. mbedtls_md_type_t md_alg,
  14426. const unsigned char *hash, size_t hash_len,
  14427. const unsigned char *sig, size_t sig_len,
  14428. mbedtls_pk_restart_ctx *rs_ctx );
  14429. /**
  14430. * \brief Verify signature, with options.
  14431. * (Includes verification of the padding depending on type.)
  14432. *
  14433. * \param type Signature type (inc. possible padding type) to verify
  14434. * \param options Pointer to type-specific options, or NULL
  14435. * \param ctx The PK context to use. It must have been set up.
  14436. * \param md_alg Hash algorithm used (see notes)
  14437. * \param hash Hash of the message to sign
  14438. * \param hash_len Hash length or 0 (see notes)
  14439. * \param sig Signature to verify
  14440. * \param sig_len Signature length
  14441. *
  14442. * \return 0 on success (signature is valid),
  14443. * #MBEDTLS_ERR_PK_TYPE_MISMATCH if the PK context can't be
  14444. * used for this type of signatures,
  14445. * #MBEDTLS_ERR_PK_SIG_LEN_MISMATCH if there is a valid
  14446. * signature in sig but its length is less than \p siglen,
  14447. * or a specific error code.
  14448. *
  14449. * \note If hash_len is 0, then the length associated with md_alg
  14450. * is used instead, or an error returned if it is invalid.
  14451. *
  14452. * \note md_alg may be MBEDTLS_MD_NONE, only if hash_len != 0
  14453. *
  14454. * \note If type is MBEDTLS_PK_RSASSA_PSS, then options must point
  14455. * to a mbedtls_pk_rsassa_pss_options structure,
  14456. * otherwise it must be NULL.
  14457. */
  14458. int mbedtls_pk_verify_ext( mbedtls_pk_type_t type, const void *options,
  14459. mbedtls_pk_context *ctx, mbedtls_md_type_t md_alg,
  14460. const unsigned char *hash, size_t hash_len,
  14461. const unsigned char *sig, size_t sig_len );
  14462. /**
  14463. * \brief Make signature, including padding if relevant.
  14464. *
  14465. * \param ctx The PK context to use. It must have been set up
  14466. * with a private key.
  14467. * \param md_alg Hash algorithm used (see notes)
  14468. * \param hash Hash of the message to sign
  14469. * \param hash_len Hash length or 0 (see notes)
  14470. * \param sig Place to write the signature.
  14471. * It must have enough room for the signature.
  14472. * #MBEDTLS_PK_SIGNATURE_MAX_SIZE is always enough.
  14473. * You may use a smaller buffer if it is large enough
  14474. * given the key type.
  14475. * \param sig_len On successful return,
  14476. * the number of bytes written to \p sig.
  14477. * \param f_rng RNG function
  14478. * \param p_rng RNG parameter
  14479. *
  14480. * \return 0 on success, or a specific error code.
  14481. *
  14482. * \note For RSA keys, the default padding type is PKCS#1 v1.5.
  14483. * There is no interface in the PK module to make RSASSA-PSS
  14484. * signatures yet.
  14485. *
  14486. * \note If hash_len is 0, then the length associated with md_alg
  14487. * is used instead, or an error returned if it is invalid.
  14488. *
  14489. * \note For RSA, md_alg may be MBEDTLS_MD_NONE if hash_len != 0.
  14490. * For ECDSA, md_alg may never be MBEDTLS_MD_NONE.
  14491. */
  14492. int mbedtls_pk_sign( mbedtls_pk_context *ctx, mbedtls_md_type_t md_alg,
  14493. const unsigned char *hash, size_t hash_len,
  14494. unsigned char *sig, size_t *sig_len,
  14495. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );
  14496. /**
  14497. * \brief Restartable version of \c mbedtls_pk_sign()
  14498. *
  14499. * \note Performs the same job as \c mbedtls_pk_sign(), but can
  14500. * return early and restart according to the limit set with
  14501. * \c mbedtls_ecp_set_max_ops() to reduce blocking for ECC
  14502. * operations. For RSA, same as \c mbedtls_pk_sign().
  14503. *
  14504. * \param ctx The PK context to use. It must have been set up
  14505. * with a private key.
  14506. * \param md_alg Hash algorithm used (see notes for mbedtls_pk_sign())
  14507. * \param hash Hash of the message to sign
  14508. * \param hash_len Hash length or 0 (see notes for mbedtls_pk_sign())
  14509. * \param sig Place to write the signature.
  14510. * It must have enough room for the signature.
  14511. * #MBEDTLS_PK_SIGNATURE_MAX_SIZE is always enough.
  14512. * You may use a smaller buffer if it is large enough
  14513. * given the key type.
  14514. * \param sig_len On successful return,
  14515. * the number of bytes written to \p sig.
  14516. * \param f_rng RNG function
  14517. * \param p_rng RNG parameter
  14518. * \param rs_ctx Restart context (NULL to disable restart)
  14519. *
  14520. * \return See \c mbedtls_pk_sign().
  14521. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  14522. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  14523. */
  14524. int mbedtls_pk_sign_restartable( mbedtls_pk_context *ctx,
  14525. mbedtls_md_type_t md_alg,
  14526. const unsigned char *hash, size_t hash_len,
  14527. unsigned char *sig, size_t *sig_len,
  14528. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
  14529. mbedtls_pk_restart_ctx *rs_ctx );
  14530. /**
  14531. * \brief Decrypt message (including padding if relevant).
  14532. *
  14533. * \param ctx The PK context to use. It must have been set up
  14534. * with a private key.
  14535. * \param input Input to decrypt
  14536. * \param ilen Input size
  14537. * \param output Decrypted output
  14538. * \param olen Decrypted message length
  14539. * \param osize Size of the output buffer
  14540. * \param f_rng RNG function
  14541. * \param p_rng RNG parameter
  14542. *
  14543. * \note For RSA keys, the default padding type is PKCS#1 v1.5.
  14544. *
  14545. * \return 0 on success, or a specific error code.
  14546. */
  14547. int mbedtls_pk_decrypt( mbedtls_pk_context *ctx,
  14548. const unsigned char *input, size_t ilen,
  14549. unsigned char *output, size_t *olen, size_t osize,
  14550. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );
  14551. /**
  14552. * \brief Encrypt message (including padding if relevant).
  14553. *
  14554. * \param ctx The PK context to use. It must have been set up.
  14555. * \param input Message to encrypt
  14556. * \param ilen Message size
  14557. * \param output Encrypted output
  14558. * \param olen Encrypted output length
  14559. * \param osize Size of the output buffer
  14560. * \param f_rng RNG function
  14561. * \param p_rng RNG parameter
  14562. *
  14563. * \note For RSA keys, the default padding type is PKCS#1 v1.5.
  14564. *
  14565. * \return 0 on success, or a specific error code.
  14566. */
  14567. int mbedtls_pk_encrypt( mbedtls_pk_context *ctx,
  14568. const unsigned char *input, size_t ilen,
  14569. unsigned char *output, size_t *olen, size_t osize,
  14570. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng );
  14571. /**
  14572. * \brief Check if a public-private pair of keys matches.
  14573. *
  14574. * \param pub Context holding a public key.
  14575. * \param prv Context holding a private (and public) key.
  14576. *
  14577. * \return \c 0 on success (keys were checked and match each other).
  14578. * \return #MBEDTLS_ERR_PK_FEATURE_UNAVAILABLE if the keys could not
  14579. * be checked - in that case they may or may not match.
  14580. * \return #MBEDTLS_ERR_PK_BAD_INPUT_DATA if a context is invalid.
  14581. * \return Another non-zero value if the keys do not match.
  14582. */
  14583. int mbedtls_pk_check_pair( const mbedtls_pk_context *pub, const mbedtls_pk_context *prv );
  14584. /**
  14585. * \brief Export debug information
  14586. *
  14587. * \param ctx The PK context to use. It must have been initialized.
  14588. * \param items Place to write debug items
  14589. *
  14590. * \return 0 on success or MBEDTLS_ERR_PK_BAD_INPUT_DATA
  14591. */
  14592. int mbedtls_pk_debug( const mbedtls_pk_context *ctx, mbedtls_pk_debug_item *items );
  14593. /**
  14594. * \brief Access the type name
  14595. *
  14596. * \param ctx The PK context to use. It must have been initialized.
  14597. *
  14598. * \return Type name on success, or "invalid PK"
  14599. */
  14600. const char * mbedtls_pk_get_name( const mbedtls_pk_context *ctx );
  14601. /**
  14602. * \brief Get the key type
  14603. *
  14604. * \param ctx The PK context to use. It must have been initialized.
  14605. *
  14606. * \return Type on success.
  14607. * \return #MBEDTLS_PK_NONE for a context that has not been set up.
  14608. */
  14609. mbedtls_pk_type_t mbedtls_pk_get_type( const mbedtls_pk_context *ctx );
  14610. #if defined(MBEDTLS_PK_PARSE_C)
  14611. /** \ingroup pk_module */
  14612. /**
  14613. * \brief Parse a private key in PEM or DER format
  14614. *
  14615. * \param ctx The PK context to fill. It must have been initialized
  14616. * but not set up.
  14617. * \param key Input buffer to parse.
  14618. * The buffer must contain the input exactly, with no
  14619. * extra trailing material. For PEM, the buffer must
  14620. * contain a null-terminated string.
  14621. * \param keylen Size of \b key in bytes.
  14622. * For PEM data, this includes the terminating null byte,
  14623. * so \p keylen must be equal to `strlen(key) + 1`.
  14624. * \param pwd Optional password for decryption.
  14625. * Pass \c NULL if expecting a non-encrypted key.
  14626. * Pass a string of \p pwdlen bytes if expecting an encrypted
  14627. * key; a non-encrypted key will also be accepted.
  14628. * The empty password is not supported.
  14629. * \param pwdlen Size of the password in bytes.
  14630. * Ignored if \p pwd is \c NULL.
  14631. *
  14632. * \note On entry, ctx must be empty, either freshly initialised
  14633. * with mbedtls_pk_init() or reset with mbedtls_pk_free(). If you need a
  14634. * specific key type, check the result with mbedtls_pk_can_do().
  14635. *
  14636. * \note The key is also checked for correctness.
  14637. *
  14638. * \return 0 if successful, or a specific PK or PEM error code
  14639. */
  14640. int mbedtls_pk_parse_key( mbedtls_pk_context *ctx,
  14641. const unsigned char *key, size_t keylen,
  14642. const unsigned char *pwd, size_t pwdlen );
  14643. /** \ingroup pk_module */
  14644. /**
  14645. * \brief Parse a public key in PEM or DER format
  14646. *
  14647. * \param ctx The PK context to fill. It must have been initialized
  14648. * but not set up.
  14649. * \param key Input buffer to parse.
  14650. * The buffer must contain the input exactly, with no
  14651. * extra trailing material. For PEM, the buffer must
  14652. * contain a null-terminated string.
  14653. * \param keylen Size of \b key in bytes.
  14654. * For PEM data, this includes the terminating null byte,
  14655. * so \p keylen must be equal to `strlen(key) + 1`.
  14656. *
  14657. * \note On entry, ctx must be empty, either freshly initialised
  14658. * with mbedtls_pk_init() or reset with mbedtls_pk_free(). If you need a
  14659. * specific key type, check the result with mbedtls_pk_can_do().
  14660. *
  14661. * \note The key is also checked for correctness.
  14662. *
  14663. * \return 0 if successful, or a specific PK or PEM error code
  14664. */
  14665. int mbedtls_pk_parse_public_key( mbedtls_pk_context *ctx,
  14666. const unsigned char *key, size_t keylen );
  14667. #if defined(MBEDTLS_FS_IO)
  14668. /** \ingroup pk_module */
  14669. /**
  14670. * \brief Load and parse a private key
  14671. *
  14672. * \param ctx The PK context to fill. It must have been initialized
  14673. * but not set up.
  14674. * \param path filename to read the private key from
  14675. * \param password Optional password to decrypt the file.
  14676. * Pass \c NULL if expecting a non-encrypted key.
  14677. * Pass a null-terminated string if expecting an encrypted
  14678. * key; a non-encrypted key will also be accepted.
  14679. * The empty password is not supported.
  14680. *
  14681. * \note On entry, ctx must be empty, either freshly initialised
  14682. * with mbedtls_pk_init() or reset with mbedtls_pk_free(). If you need a
  14683. * specific key type, check the result with mbedtls_pk_can_do().
  14684. *
  14685. * \note The key is also checked for correctness.
  14686. *
  14687. * \return 0 if successful, or a specific PK or PEM error code
  14688. */
  14689. int mbedtls_pk_parse_keyfile( mbedtls_pk_context *ctx,
  14690. const char *path, const char *password );
  14691. /** \ingroup pk_module */
  14692. /**
  14693. * \brief Load and parse a public key
  14694. *
  14695. * \param ctx The PK context to fill. It must have been initialized
  14696. * but not set up.
  14697. * \param path filename to read the public key from
  14698. *
  14699. * \note On entry, ctx must be empty, either freshly initialised
  14700. * with mbedtls_pk_init() or reset with mbedtls_pk_free(). If
  14701. * you need a specific key type, check the result with
  14702. * mbedtls_pk_can_do().
  14703. *
  14704. * \note The key is also checked for correctness.
  14705. *
  14706. * \return 0 if successful, or a specific PK or PEM error code
  14707. */
  14708. int mbedtls_pk_parse_public_keyfile( mbedtls_pk_context *ctx, const char *path );
  14709. #endif /* MBEDTLS_FS_IO */
  14710. #endif /* MBEDTLS_PK_PARSE_C */
  14711. #if defined(MBEDTLS_PK_WRITE_C)
  14712. /**
  14713. * \brief Write a private key to a PKCS#1 or SEC1 DER structure
  14714. * Note: data is written at the end of the buffer! Use the
  14715. * return value to determine where you should start
  14716. * using the buffer
  14717. *
  14718. * \param ctx PK context which must contain a valid private key.
  14719. * \param buf buffer to write to
  14720. * \param size size of the buffer
  14721. *
  14722. * \return length of data written if successful, or a specific
  14723. * error code
  14724. */
  14725. int mbedtls_pk_write_key_der( mbedtls_pk_context *ctx, unsigned char *buf, size_t size );
  14726. /**
  14727. * \brief Write a public key to a SubjectPublicKeyInfo DER structure
  14728. * Note: data is written at the end of the buffer! Use the
  14729. * return value to determine where you should start
  14730. * using the buffer
  14731. *
  14732. * \param ctx PK context which must contain a valid public or private key.
  14733. * \param buf buffer to write to
  14734. * \param size size of the buffer
  14735. *
  14736. * \return length of data written if successful, or a specific
  14737. * error code
  14738. */
  14739. int mbedtls_pk_write_pubkey_der( mbedtls_pk_context *ctx, unsigned char *buf, size_t size );
  14740. #if defined(MBEDTLS_PEM_WRITE_C)
  14741. /**
  14742. * \brief Write a public key to a PEM string
  14743. *
  14744. * \param ctx PK context which must contain a valid public or private key.
  14745. * \param buf Buffer to write to. The output includes a
  14746. * terminating null byte.
  14747. * \param size Size of the buffer in bytes.
  14748. *
  14749. * \return 0 if successful, or a specific error code
  14750. */
  14751. int mbedtls_pk_write_pubkey_pem( mbedtls_pk_context *ctx, unsigned char *buf, size_t size );
  14752. /**
  14753. * \brief Write a private key to a PKCS#1 or SEC1 PEM string
  14754. *
  14755. * \param ctx PK context which must contain a valid private key.
  14756. * \param buf Buffer to write to. The output includes a
  14757. * terminating null byte.
  14758. * \param size Size of the buffer in bytes.
  14759. *
  14760. * \return 0 if successful, or a specific error code
  14761. */
  14762. int mbedtls_pk_write_key_pem( mbedtls_pk_context *ctx, unsigned char *buf, size_t size );
  14763. #endif /* MBEDTLS_PEM_WRITE_C */
  14764. #endif /* MBEDTLS_PK_WRITE_C */
  14765. /*
  14766. * WARNING: Low-level functions. You probably do not want to use these unless
  14767. * you are certain you do ;)
  14768. */
  14769. #if defined(MBEDTLS_PK_PARSE_C)
  14770. /**
  14771. * \brief Parse a SubjectPublicKeyInfo DER structure
  14772. *
  14773. * \param p the position in the ASN.1 data
  14774. * \param end end of the buffer
  14775. * \param pk The PK context to fill. It must have been initialized
  14776. * but not set up.
  14777. *
  14778. * \return 0 if successful, or a specific PK error code
  14779. */
  14780. int mbedtls_pk_parse_subpubkey( unsigned char **p, const unsigned char *end,
  14781. mbedtls_pk_context *pk );
  14782. #endif /* MBEDTLS_PK_PARSE_C */
  14783. #if defined(MBEDTLS_PK_WRITE_C)
  14784. /**
  14785. * \brief Write a subjectPublicKey to ASN.1 data
  14786. * Note: function works backwards in data buffer
  14787. *
  14788. * \param p reference to current position pointer
  14789. * \param start start of the buffer (for bounds-checking)
  14790. * \param key PK context which must contain a valid public or private key.
  14791. *
  14792. * \return the length written or a negative error code
  14793. */
  14794. int mbedtls_pk_write_pubkey( unsigned char **p, unsigned char *start,
  14795. const mbedtls_pk_context *key );
  14796. #endif /* MBEDTLS_PK_WRITE_C */
  14797. /*
  14798. * Internal module functions. You probably do not want to use these unless you
  14799. * know you do.
  14800. */
  14801. #if defined(MBEDTLS_FS_IO)
  14802. int mbedtls_pk_load_file( const char *path, unsigned char **buf, size_t *n );
  14803. #endif
  14804. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  14805. /**
  14806. * \brief Turn an EC key into an opaque one.
  14807. *
  14808. * \warning This is a temporary utility function for tests. It might
  14809. * change or be removed at any time without notice.
  14810. *
  14811. * \note Only ECDSA keys are supported so far. Signing with the
  14812. * specified hash is the only allowed use of that key.
  14813. *
  14814. * \param pk Input: the EC key to import to a PSA key.
  14815. * Output: a PK context wrapping that PSA key.
  14816. * \param key Output: a PSA key identifier.
  14817. * It's the caller's responsibility to call
  14818. * psa_destroy_key() on that key identifier after calling
  14819. * mbedtls_pk_free() on the PK context.
  14820. * \param hash_alg The hash algorithm to allow for use with that key.
  14821. *
  14822. * \return \c 0 if successful.
  14823. * \return An Mbed TLS error code otherwise.
  14824. */
  14825. int mbedtls_pk_wrap_as_opaque( mbedtls_pk_context *pk,
  14826. psa_key_id_t *key,
  14827. psa_algorithm_t hash_alg );
  14828. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  14829. #ifdef __cplusplus
  14830. }
  14831. #endif
  14832. #endif /* MBEDTLS_PK_H */
  14833. /********* Start of file include/mbedtls/pk_internal.h ************/
  14834. /**
  14835. * \file pk_internal.h
  14836. *
  14837. * \brief Public Key abstraction layer: wrapper functions
  14838. */
  14839. /*
  14840. * Copyright The Mbed TLS Contributors
  14841. * SPDX-License-Identifier: Apache-2.0
  14842. *
  14843. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  14844. * not use this file except in compliance with the License.
  14845. * You may obtain a copy of the License at
  14846. *
  14847. * http://www.apache.org/licenses/LICENSE-2.0
  14848. *
  14849. * Unless required by applicable law or agreed to in writing, software
  14850. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  14851. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14852. * See the License for the specific language governing permissions and
  14853. * limitations under the License.
  14854. */
  14855. #ifndef MBEDTLS_PK_WRAP_H
  14856. #define MBEDTLS_PK_WRAP_H
  14857. #if !defined(MBEDTLS_CONFIG_FILE)
  14858. #else
  14859. #endif
  14860. struct mbedtls_pk_info_t
  14861. {
  14862. /** Public key type */
  14863. mbedtls_pk_type_t type;
  14864. /** Type name */
  14865. const char *name;
  14866. /** Get key size in bits */
  14867. size_t (*get_bitlen)( const void * );
  14868. /** Tell if the context implements this type (e.g. ECKEY can do ECDSA) */
  14869. int (*can_do)( mbedtls_pk_type_t type );
  14870. /** Verify signature */
  14871. int (*verify_func)( void *ctx, mbedtls_md_type_t md_alg,
  14872. const unsigned char *hash, size_t hash_len,
  14873. const unsigned char *sig, size_t sig_len );
  14874. /** Make signature */
  14875. int (*sign_func)( void *ctx, mbedtls_md_type_t md_alg,
  14876. const unsigned char *hash, size_t hash_len,
  14877. unsigned char *sig, size_t *sig_len,
  14878. int (*f_rng)(void *, unsigned char *, size_t),
  14879. void *p_rng );
  14880. #if defined(MBEDTLS_ECDSA_C) && defined(MBEDTLS_ECP_RESTARTABLE)
  14881. /** Verify signature (restartable) */
  14882. int (*verify_rs_func)( void *ctx, mbedtls_md_type_t md_alg,
  14883. const unsigned char *hash, size_t hash_len,
  14884. const unsigned char *sig, size_t sig_len,
  14885. void *rs_ctx );
  14886. /** Make signature (restartable) */
  14887. int (*sign_rs_func)( void *ctx, mbedtls_md_type_t md_alg,
  14888. const unsigned char *hash, size_t hash_len,
  14889. unsigned char *sig, size_t *sig_len,
  14890. int (*f_rng)(void *, unsigned char *, size_t),
  14891. void *p_rng, void *rs_ctx );
  14892. #endif /* MBEDTLS_ECDSA_C && MBEDTLS_ECP_RESTARTABLE */
  14893. /** Decrypt message */
  14894. int (*decrypt_func)( void *ctx, const unsigned char *input, size_t ilen,
  14895. unsigned char *output, size_t *olen, size_t osize,
  14896. int (*f_rng)(void *, unsigned char *, size_t),
  14897. void *p_rng );
  14898. /** Encrypt message */
  14899. int (*encrypt_func)( void *ctx, const unsigned char *input, size_t ilen,
  14900. unsigned char *output, size_t *olen, size_t osize,
  14901. int (*f_rng)(void *, unsigned char *, size_t),
  14902. void *p_rng );
  14903. /** Check public-private key pair */
  14904. int (*check_pair_func)( const void *pub, const void *prv );
  14905. /** Allocate a new context */
  14906. void * (*ctx_alloc_func)( void );
  14907. /** Free the given context */
  14908. void (*ctx_free_func)( void *ctx );
  14909. #if defined(MBEDTLS_ECDSA_C) && defined(MBEDTLS_ECP_RESTARTABLE)
  14910. /** Allocate the restart context */
  14911. void * (*rs_alloc_func)( void );
  14912. /** Free the restart context */
  14913. void (*rs_free_func)( void *rs_ctx );
  14914. #endif /* MBEDTLS_ECDSA_C && MBEDTLS_ECP_RESTARTABLE */
  14915. /** Interface with the debug module */
  14916. void (*debug_func)( const void *ctx, mbedtls_pk_debug_item *items );
  14917. };
  14918. #if defined(MBEDTLS_PK_RSA_ALT_SUPPORT)
  14919. /* Container for RSA-alt */
  14920. typedef struct
  14921. {
  14922. void *key;
  14923. mbedtls_pk_rsa_alt_decrypt_func decrypt_func;
  14924. mbedtls_pk_rsa_alt_sign_func sign_func;
  14925. mbedtls_pk_rsa_alt_key_len_func key_len_func;
  14926. } mbedtls_rsa_alt_context;
  14927. #endif
  14928. #if defined(MBEDTLS_RSA_C)
  14929. extern const mbedtls_pk_info_t mbedtls_rsa_info;
  14930. #endif
  14931. #if defined(MBEDTLS_ECP_C)
  14932. extern const mbedtls_pk_info_t mbedtls_eckey_info;
  14933. extern const mbedtls_pk_info_t mbedtls_eckeydh_info;
  14934. #endif
  14935. #if defined(MBEDTLS_ECDSA_C)
  14936. extern const mbedtls_pk_info_t mbedtls_ecdsa_info;
  14937. #endif
  14938. #if defined(MBEDTLS_PK_RSA_ALT_SUPPORT)
  14939. extern const mbedtls_pk_info_t mbedtls_rsa_alt_info;
  14940. #endif
  14941. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  14942. extern const mbedtls_pk_info_t mbedtls_pk_opaque_info;
  14943. #endif
  14944. #endif /* MBEDTLS_PK_WRAP_H */
  14945. /********* Start of file include/mbedtls/x509.h ************/
  14946. /**
  14947. * \file x509.h
  14948. *
  14949. * \brief X.509 generic defines and structures
  14950. */
  14951. /*
  14952. * Copyright The Mbed TLS Contributors
  14953. * SPDX-License-Identifier: Apache-2.0
  14954. *
  14955. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  14956. * not use this file except in compliance with the License.
  14957. * You may obtain a copy of the License at
  14958. *
  14959. * http://www.apache.org/licenses/LICENSE-2.0
  14960. *
  14961. * Unless required by applicable law or agreed to in writing, software
  14962. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  14963. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14964. * See the License for the specific language governing permissions and
  14965. * limitations under the License.
  14966. */
  14967. #ifndef MBEDTLS_X509_H
  14968. #define MBEDTLS_X509_H
  14969. #if !defined(MBEDTLS_CONFIG_FILE)
  14970. #else
  14971. #endif
  14972. #if defined(MBEDTLS_RSA_C)
  14973. #endif
  14974. /**
  14975. * \addtogroup x509_module
  14976. * \{
  14977. */
  14978. #if !defined(MBEDTLS_X509_MAX_INTERMEDIATE_CA)
  14979. /**
  14980. * Maximum number of intermediate CAs in a verification chain.
  14981. * That is, maximum length of the chain, excluding the end-entity certificate
  14982. * and the trusted root certificate.
  14983. *
  14984. * Set this to a low value to prevent an adversary from making you waste
  14985. * resources verifying an overlong certificate chain.
  14986. */
  14987. #define MBEDTLS_X509_MAX_INTERMEDIATE_CA 8
  14988. #endif
  14989. /**
  14990. * \name X509 Error codes
  14991. * \{
  14992. */
  14993. /** Unavailable feature, e.g. RSA hashing/encryption combination. */
  14994. #define MBEDTLS_ERR_X509_FEATURE_UNAVAILABLE -0x2080
  14995. /** Requested OID is unknown. */
  14996. #define MBEDTLS_ERR_X509_UNKNOWN_OID -0x2100
  14997. /** The CRT/CRL/CSR format is invalid, e.g. different type expected. */
  14998. #define MBEDTLS_ERR_X509_INVALID_FORMAT -0x2180
  14999. /** The CRT/CRL/CSR version element is invalid. */
  15000. #define MBEDTLS_ERR_X509_INVALID_VERSION -0x2200
  15001. /** The serial tag or value is invalid. */
  15002. #define MBEDTLS_ERR_X509_INVALID_SERIAL -0x2280
  15003. /** The algorithm tag or value is invalid. */
  15004. #define MBEDTLS_ERR_X509_INVALID_ALG -0x2300
  15005. /** The name tag or value is invalid. */
  15006. #define MBEDTLS_ERR_X509_INVALID_NAME -0x2380
  15007. /** The date tag or value is invalid. */
  15008. #define MBEDTLS_ERR_X509_INVALID_DATE -0x2400
  15009. /** The signature tag or value invalid. */
  15010. #define MBEDTLS_ERR_X509_INVALID_SIGNATURE -0x2480
  15011. /** The extension tag or value is invalid. */
  15012. #define MBEDTLS_ERR_X509_INVALID_EXTENSIONS -0x2500
  15013. /** CRT/CRL/CSR has an unsupported version number. */
  15014. #define MBEDTLS_ERR_X509_UNKNOWN_VERSION -0x2580
  15015. /** Signature algorithm (oid) is unsupported. */
  15016. #define MBEDTLS_ERR_X509_UNKNOWN_SIG_ALG -0x2600
  15017. /** Signature algorithms do not match. (see \c ::mbedtls_x509_crt sig_oid) */
  15018. #define MBEDTLS_ERR_X509_SIG_MISMATCH -0x2680
  15019. /** Certificate verification failed, e.g. CRL, CA or signature check failed. */
  15020. #define MBEDTLS_ERR_X509_CERT_VERIFY_FAILED -0x2700
  15021. /** Format not recognized as DER or PEM. */
  15022. #define MBEDTLS_ERR_X509_CERT_UNKNOWN_FORMAT -0x2780
  15023. /** Input invalid. */
  15024. #define MBEDTLS_ERR_X509_BAD_INPUT_DATA -0x2800
  15025. /** Allocation of memory failed. */
  15026. #define MBEDTLS_ERR_X509_ALLOC_FAILED -0x2880
  15027. /** Read/write of file failed. */
  15028. #define MBEDTLS_ERR_X509_FILE_IO_ERROR -0x2900
  15029. /** Destination buffer is too small. */
  15030. #define MBEDTLS_ERR_X509_BUFFER_TOO_SMALL -0x2980
  15031. /** A fatal error occurred, eg the chain is too long or the vrfy callback failed. */
  15032. #define MBEDTLS_ERR_X509_FATAL_ERROR -0x3000
  15033. /* \} name */
  15034. /**
  15035. * \name X509 Verify codes
  15036. * \{
  15037. */
  15038. /* Reminder: update x509_crt_verify_strings[] in library/x509_crt.c */
  15039. #define MBEDTLS_X509_BADCERT_EXPIRED 0x01 /**< The certificate validity has expired. */
  15040. #define MBEDTLS_X509_BADCERT_REVOKED 0x02 /**< The certificate has been revoked (is on a CRL). */
  15041. #define MBEDTLS_X509_BADCERT_CN_MISMATCH 0x04 /**< The certificate Common Name (CN) does not match with the expected CN. */
  15042. #define MBEDTLS_X509_BADCERT_NOT_TRUSTED 0x08 /**< The certificate is not correctly signed by the trusted CA. */
  15043. #define MBEDTLS_X509_BADCRL_NOT_TRUSTED 0x10 /**< The CRL is not correctly signed by the trusted CA. */
  15044. #define MBEDTLS_X509_BADCRL_EXPIRED 0x20 /**< The CRL is expired. */
  15045. #define MBEDTLS_X509_BADCERT_MISSING 0x40 /**< Certificate was missing. */
  15046. #define MBEDTLS_X509_BADCERT_SKIP_VERIFY 0x80 /**< Certificate verification was skipped. */
  15047. #define MBEDTLS_X509_BADCERT_OTHER 0x0100 /**< Other reason (can be used by verify callback) */
  15048. #define MBEDTLS_X509_BADCERT_FUTURE 0x0200 /**< The certificate validity starts in the future. */
  15049. #define MBEDTLS_X509_BADCRL_FUTURE 0x0400 /**< The CRL is from the future */
  15050. #define MBEDTLS_X509_BADCERT_KEY_USAGE 0x0800 /**< Usage does not match the keyUsage extension. */
  15051. #define MBEDTLS_X509_BADCERT_EXT_KEY_USAGE 0x1000 /**< Usage does not match the extendedKeyUsage extension. */
  15052. #define MBEDTLS_X509_BADCERT_NS_CERT_TYPE 0x2000 /**< Usage does not match the nsCertType extension. */
  15053. #define MBEDTLS_X509_BADCERT_BAD_MD 0x4000 /**< The certificate is signed with an unacceptable hash. */
  15054. #define MBEDTLS_X509_BADCERT_BAD_PK 0x8000 /**< The certificate is signed with an unacceptable PK alg (eg RSA vs ECDSA). */
  15055. #define MBEDTLS_X509_BADCERT_BAD_KEY 0x010000 /**< The certificate is signed with an unacceptable key (eg bad curve, RSA too short). */
  15056. #define MBEDTLS_X509_BADCRL_BAD_MD 0x020000 /**< The CRL is signed with an unacceptable hash. */
  15057. #define MBEDTLS_X509_BADCRL_BAD_PK 0x040000 /**< The CRL is signed with an unacceptable PK alg (eg RSA vs ECDSA). */
  15058. #define MBEDTLS_X509_BADCRL_BAD_KEY 0x080000 /**< The CRL is signed with an unacceptable key (eg bad curve, RSA too short). */
  15059. /* \} name */
  15060. /* \} addtogroup x509_module */
  15061. /*
  15062. * X.509 v3 Subject Alternative Name types.
  15063. * otherName [0] OtherName,
  15064. * rfc822Name [1] IA5String,
  15065. * dNSName [2] IA5String,
  15066. * x400Address [3] ORAddress,
  15067. * directoryName [4] Name,
  15068. * ediPartyName [5] EDIPartyName,
  15069. * uniformResourceIdentifier [6] IA5String,
  15070. * iPAddress [7] OCTET STRING,
  15071. * registeredID [8] OBJECT IDENTIFIER
  15072. */
  15073. #define MBEDTLS_X509_SAN_OTHER_NAME 0
  15074. #define MBEDTLS_X509_SAN_RFC822_NAME 1
  15075. #define MBEDTLS_X509_SAN_DNS_NAME 2
  15076. #define MBEDTLS_X509_SAN_X400_ADDRESS_NAME 3
  15077. #define MBEDTLS_X509_SAN_DIRECTORY_NAME 4
  15078. #define MBEDTLS_X509_SAN_EDI_PARTY_NAME 5
  15079. #define MBEDTLS_X509_SAN_UNIFORM_RESOURCE_IDENTIFIER 6
  15080. #define MBEDTLS_X509_SAN_IP_ADDRESS 7
  15081. #define MBEDTLS_X509_SAN_REGISTERED_ID 8
  15082. /*
  15083. * X.509 v3 Key Usage Extension flags
  15084. * Reminder: update x509_info_key_usage() when adding new flags.
  15085. */
  15086. #define MBEDTLS_X509_KU_DIGITAL_SIGNATURE (0x80) /* bit 0 */
  15087. #define MBEDTLS_X509_KU_NON_REPUDIATION (0x40) /* bit 1 */
  15088. #define MBEDTLS_X509_KU_KEY_ENCIPHERMENT (0x20) /* bit 2 */
  15089. #define MBEDTLS_X509_KU_DATA_ENCIPHERMENT (0x10) /* bit 3 */
  15090. #define MBEDTLS_X509_KU_KEY_AGREEMENT (0x08) /* bit 4 */
  15091. #define MBEDTLS_X509_KU_KEY_CERT_SIGN (0x04) /* bit 5 */
  15092. #define MBEDTLS_X509_KU_CRL_SIGN (0x02) /* bit 6 */
  15093. #define MBEDTLS_X509_KU_ENCIPHER_ONLY (0x01) /* bit 7 */
  15094. #define MBEDTLS_X509_KU_DECIPHER_ONLY (0x8000) /* bit 8 */
  15095. /*
  15096. * Netscape certificate types
  15097. * (http://www.mozilla.org/projects/security/pki/nss/tech-notes/tn3.html)
  15098. */
  15099. #define MBEDTLS_X509_NS_CERT_TYPE_SSL_CLIENT (0x80) /* bit 0 */
  15100. #define MBEDTLS_X509_NS_CERT_TYPE_SSL_SERVER (0x40) /* bit 1 */
  15101. #define MBEDTLS_X509_NS_CERT_TYPE_EMAIL (0x20) /* bit 2 */
  15102. #define MBEDTLS_X509_NS_CERT_TYPE_OBJECT_SIGNING (0x10) /* bit 3 */
  15103. #define MBEDTLS_X509_NS_CERT_TYPE_RESERVED (0x08) /* bit 4 */
  15104. #define MBEDTLS_X509_NS_CERT_TYPE_SSL_CA (0x04) /* bit 5 */
  15105. #define MBEDTLS_X509_NS_CERT_TYPE_EMAIL_CA (0x02) /* bit 6 */
  15106. #define MBEDTLS_X509_NS_CERT_TYPE_OBJECT_SIGNING_CA (0x01) /* bit 7 */
  15107. /*
  15108. * X.509 extension types
  15109. *
  15110. * Comments refer to the status for using certificates. Status can be
  15111. * different for writing certificates or reading CRLs or CSRs.
  15112. *
  15113. * Those are defined in oid.h as oid.c needs them in a data structure. Since
  15114. * these were previously defined here, let's have aliases for compatibility.
  15115. */
  15116. #define MBEDTLS_X509_EXT_AUTHORITY_KEY_IDENTIFIER MBEDTLS_OID_X509_EXT_AUTHORITY_KEY_IDENTIFIER
  15117. #define MBEDTLS_X509_EXT_SUBJECT_KEY_IDENTIFIER MBEDTLS_OID_X509_EXT_SUBJECT_KEY_IDENTIFIER
  15118. #define MBEDTLS_X509_EXT_KEY_USAGE MBEDTLS_OID_X509_EXT_KEY_USAGE
  15119. #define MBEDTLS_X509_EXT_CERTIFICATE_POLICIES MBEDTLS_OID_X509_EXT_CERTIFICATE_POLICIES
  15120. #define MBEDTLS_X509_EXT_POLICY_MAPPINGS MBEDTLS_OID_X509_EXT_POLICY_MAPPINGS
  15121. #define MBEDTLS_X509_EXT_SUBJECT_ALT_NAME MBEDTLS_OID_X509_EXT_SUBJECT_ALT_NAME /* Supported (DNS) */
  15122. #define MBEDTLS_X509_EXT_ISSUER_ALT_NAME MBEDTLS_OID_X509_EXT_ISSUER_ALT_NAME
  15123. #define MBEDTLS_X509_EXT_SUBJECT_DIRECTORY_ATTRS MBEDTLS_OID_X509_EXT_SUBJECT_DIRECTORY_ATTRS
  15124. #define MBEDTLS_X509_EXT_BASIC_CONSTRAINTS MBEDTLS_OID_X509_EXT_BASIC_CONSTRAINTS /* Supported */
  15125. #define MBEDTLS_X509_EXT_NAME_CONSTRAINTS MBEDTLS_OID_X509_EXT_NAME_CONSTRAINTS
  15126. #define MBEDTLS_X509_EXT_POLICY_CONSTRAINTS MBEDTLS_OID_X509_EXT_POLICY_CONSTRAINTS
  15127. #define MBEDTLS_X509_EXT_EXTENDED_KEY_USAGE MBEDTLS_OID_X509_EXT_EXTENDED_KEY_USAGE
  15128. #define MBEDTLS_X509_EXT_CRL_DISTRIBUTION_POINTS MBEDTLS_OID_X509_EXT_CRL_DISTRIBUTION_POINTS
  15129. #define MBEDTLS_X509_EXT_INIHIBIT_ANYPOLICY MBEDTLS_OID_X509_EXT_INIHIBIT_ANYPOLICY
  15130. #define MBEDTLS_X509_EXT_FRESHEST_CRL MBEDTLS_OID_X509_EXT_FRESHEST_CRL
  15131. #define MBEDTLS_X509_EXT_NS_CERT_TYPE MBEDTLS_OID_X509_EXT_NS_CERT_TYPE
  15132. /*
  15133. * Storage format identifiers
  15134. * Recognized formats: PEM and DER
  15135. */
  15136. #define MBEDTLS_X509_FORMAT_DER 1
  15137. #define MBEDTLS_X509_FORMAT_PEM 2
  15138. #define MBEDTLS_X509_MAX_DN_NAME_SIZE 256 /**< Maximum value size of a DN entry */
  15139. #ifdef __cplusplus
  15140. extern "C" {
  15141. #endif
  15142. /**
  15143. * \addtogroup x509_module
  15144. * \{ */
  15145. /**
  15146. * \name Structures for parsing X.509 certificates, CRLs and CSRs
  15147. * \{
  15148. */
  15149. /**
  15150. * Type-length-value structure that allows for ASN1 using DER.
  15151. */
  15152. typedef mbedtls_asn1_buf mbedtls_x509_buf;
  15153. /**
  15154. * Container for ASN1 bit strings.
  15155. */
  15156. typedef mbedtls_asn1_bitstring mbedtls_x509_bitstring;
  15157. /**
  15158. * Container for ASN1 named information objects.
  15159. * It allows for Relative Distinguished Names (e.g. cn=localhost,ou=code,etc.).
  15160. */
  15161. typedef mbedtls_asn1_named_data mbedtls_x509_name;
  15162. /**
  15163. * Container for a sequence of ASN.1 items
  15164. */
  15165. typedef mbedtls_asn1_sequence mbedtls_x509_sequence;
  15166. /** Container for date and time (precision in seconds). */
  15167. typedef struct mbedtls_x509_time
  15168. {
  15169. int year, mon, day; /**< Date. */
  15170. int hour, min, sec; /**< Time. */
  15171. }
  15172. mbedtls_x509_time;
  15173. /** \} name Structures for parsing X.509 certificates, CRLs and CSRs */
  15174. /** \} addtogroup x509_module */
  15175. /**
  15176. * \brief Store the certificate DN in printable form into buf;
  15177. * no more than size characters will be written.
  15178. *
  15179. * \param buf Buffer to write to
  15180. * \param size Maximum size of buffer
  15181. * \param dn The X509 name to represent
  15182. *
  15183. * \return The length of the string written (not including the
  15184. * terminated nul byte), or a negative error code.
  15185. */
  15186. int mbedtls_x509_dn_gets( char *buf, size_t size, const mbedtls_x509_name *dn );
  15187. /**
  15188. * \brief Store the certificate serial in printable form into buf;
  15189. * no more than size characters will be written.
  15190. *
  15191. * \param buf Buffer to write to
  15192. * \param size Maximum size of buffer
  15193. * \param serial The X509 serial to represent
  15194. *
  15195. * \return The length of the string written (not including the
  15196. * terminated nul byte), or a negative error code.
  15197. */
  15198. int mbedtls_x509_serial_gets( char *buf, size_t size, const mbedtls_x509_buf *serial );
  15199. /**
  15200. * \brief Check a given mbedtls_x509_time against the system time
  15201. * and tell if it's in the past.
  15202. *
  15203. * \note Intended usage is "if( is_past( valid_to ) ) ERROR".
  15204. * Hence the return value of 1 if on internal errors.
  15205. *
  15206. * \param to mbedtls_x509_time to check
  15207. *
  15208. * \return 1 if the given time is in the past or an error occurred,
  15209. * 0 otherwise.
  15210. */
  15211. int mbedtls_x509_time_is_past( const mbedtls_x509_time *to );
  15212. /**
  15213. * \brief Check a given mbedtls_x509_time against the system time
  15214. * and tell if it's in the future.
  15215. *
  15216. * \note Intended usage is "if( is_future( valid_from ) ) ERROR".
  15217. * Hence the return value of 1 if on internal errors.
  15218. *
  15219. * \param from mbedtls_x509_time to check
  15220. *
  15221. * \return 1 if the given time is in the future or an error occurred,
  15222. * 0 otherwise.
  15223. */
  15224. int mbedtls_x509_time_is_future( const mbedtls_x509_time *from );
  15225. #if defined(MBEDTLS_SELF_TEST)
  15226. /**
  15227. * \brief Checkup routine
  15228. *
  15229. * \return 0 if successful, or 1 if the test failed
  15230. */
  15231. int mbedtls_x509_self_test( int verbose );
  15232. #endif /* MBEDTLS_SELF_TEST */
  15233. /*
  15234. * Internal module functions. You probably do not want to use these unless you
  15235. * know you do.
  15236. */
  15237. int mbedtls_x509_get_name( unsigned char **p, const unsigned char *end,
  15238. mbedtls_x509_name *cur );
  15239. int mbedtls_x509_get_alg_null( unsigned char **p, const unsigned char *end,
  15240. mbedtls_x509_buf *alg );
  15241. int mbedtls_x509_get_alg( unsigned char **p, const unsigned char *end,
  15242. mbedtls_x509_buf *alg, mbedtls_x509_buf *params );
  15243. #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT)
  15244. int mbedtls_x509_get_rsassa_pss_params( const mbedtls_x509_buf *params,
  15245. mbedtls_md_type_t *md_alg, mbedtls_md_type_t *mgf_md,
  15246. int *salt_len );
  15247. #endif
  15248. int mbedtls_x509_get_sig( unsigned char **p, const unsigned char *end, mbedtls_x509_buf *sig );
  15249. int mbedtls_x509_get_sig_alg( const mbedtls_x509_buf *sig_oid, const mbedtls_x509_buf *sig_params,
  15250. mbedtls_md_type_t *md_alg, mbedtls_pk_type_t *pk_alg,
  15251. void **sig_opts );
  15252. int mbedtls_x509_get_time( unsigned char **p, const unsigned char *end,
  15253. mbedtls_x509_time *t );
  15254. int mbedtls_x509_get_serial( unsigned char **p, const unsigned char *end,
  15255. mbedtls_x509_buf *serial );
  15256. int mbedtls_x509_get_ext( unsigned char **p, const unsigned char *end,
  15257. mbedtls_x509_buf *ext, int tag );
  15258. int mbedtls_x509_sig_alg_gets( char *buf, size_t size, const mbedtls_x509_buf *sig_oid,
  15259. mbedtls_pk_type_t pk_alg, mbedtls_md_type_t md_alg,
  15260. const void *sig_opts );
  15261. int mbedtls_x509_key_size_helper( char *buf, size_t buf_size, const char *name );
  15262. int mbedtls_x509_string_to_names( mbedtls_asn1_named_data **head, const char *name );
  15263. int mbedtls_x509_set_extension( mbedtls_asn1_named_data **head, const char *oid, size_t oid_len,
  15264. int critical, const unsigned char *val,
  15265. size_t val_len );
  15266. int mbedtls_x509_write_extensions( unsigned char **p, unsigned char *start,
  15267. mbedtls_asn1_named_data *first );
  15268. int mbedtls_x509_write_names( unsigned char **p, unsigned char *start,
  15269. mbedtls_asn1_named_data *first );
  15270. int mbedtls_x509_write_sig( unsigned char **p, unsigned char *start,
  15271. const char *oid, size_t oid_len,
  15272. unsigned char *sig, size_t size );
  15273. #define MBEDTLS_X509_SAFE_SNPRINTF \
  15274. do { \
  15275. if( ret < 0 || (size_t) ret >= n ) \
  15276. return( MBEDTLS_ERR_X509_BUFFER_TOO_SMALL ); \
  15277. \
  15278. n -= (size_t) ret; \
  15279. p += (size_t) ret; \
  15280. } while( 0 )
  15281. #ifdef __cplusplus
  15282. }
  15283. #endif
  15284. #endif /* x509.h */
  15285. /********* Start of file include/mbedtls/x509_crl.h ************/
  15286. /**
  15287. * \file x509_crl.h
  15288. *
  15289. * \brief X.509 certificate revocation list parsing
  15290. */
  15291. /*
  15292. * Copyright The Mbed TLS Contributors
  15293. * SPDX-License-Identifier: Apache-2.0
  15294. *
  15295. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  15296. * not use this file except in compliance with the License.
  15297. * You may obtain a copy of the License at
  15298. *
  15299. * http://www.apache.org/licenses/LICENSE-2.0
  15300. *
  15301. * Unless required by applicable law or agreed to in writing, software
  15302. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  15303. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  15304. * See the License for the specific language governing permissions and
  15305. * limitations under the License.
  15306. */
  15307. #ifndef MBEDTLS_X509_CRL_H
  15308. #define MBEDTLS_X509_CRL_H
  15309. #if !defined(MBEDTLS_CONFIG_FILE)
  15310. #else
  15311. #endif
  15312. #ifdef __cplusplus
  15313. extern "C" {
  15314. #endif
  15315. /**
  15316. * \addtogroup x509_module
  15317. * \{ */
  15318. /**
  15319. * \name Structures and functions for parsing CRLs
  15320. * \{
  15321. */
  15322. /**
  15323. * Certificate revocation list entry.
  15324. * Contains the CA-specific serial numbers and revocation dates.
  15325. */
  15326. typedef struct mbedtls_x509_crl_entry
  15327. {
  15328. mbedtls_x509_buf raw;
  15329. mbedtls_x509_buf serial;
  15330. mbedtls_x509_time revocation_date;
  15331. mbedtls_x509_buf entry_ext;
  15332. struct mbedtls_x509_crl_entry *next;
  15333. }
  15334. mbedtls_x509_crl_entry;
  15335. /**
  15336. * Certificate revocation list structure.
  15337. * Every CRL may have multiple entries.
  15338. */
  15339. typedef struct mbedtls_x509_crl
  15340. {
  15341. mbedtls_x509_buf raw; /**< The raw certificate data (DER). */
  15342. mbedtls_x509_buf tbs; /**< The raw certificate body (DER). The part that is To Be Signed. */
  15343. int version; /**< CRL version (1=v1, 2=v2) */
  15344. mbedtls_x509_buf sig_oid; /**< CRL signature type identifier */
  15345. mbedtls_x509_buf issuer_raw; /**< The raw issuer data (DER). */
  15346. mbedtls_x509_name issuer; /**< The parsed issuer data (named information object). */
  15347. mbedtls_x509_time this_update;
  15348. mbedtls_x509_time next_update;
  15349. mbedtls_x509_crl_entry entry; /**< The CRL entries containing the certificate revocation times for this CA. */
  15350. mbedtls_x509_buf crl_ext;
  15351. mbedtls_x509_buf sig_oid2;
  15352. mbedtls_x509_buf sig;
  15353. mbedtls_md_type_t sig_md; /**< Internal representation of the MD algorithm of the signature algorithm, e.g. MBEDTLS_MD_SHA256 */
  15354. mbedtls_pk_type_t sig_pk; /**< Internal representation of the Public Key algorithm of the signature algorithm, e.g. MBEDTLS_PK_RSA */
  15355. void *sig_opts; /**< Signature options to be passed to mbedtls_pk_verify_ext(), e.g. for RSASSA-PSS */
  15356. struct mbedtls_x509_crl *next;
  15357. }
  15358. mbedtls_x509_crl;
  15359. /**
  15360. * \brief Parse a DER-encoded CRL and append it to the chained list
  15361. *
  15362. * \param chain points to the start of the chain
  15363. * \param buf buffer holding the CRL data in DER format
  15364. * \param buflen size of the buffer
  15365. * (including the terminating null byte for PEM data)
  15366. *
  15367. * \return 0 if successful, or a specific X509 or PEM error code
  15368. */
  15369. int mbedtls_x509_crl_parse_der( mbedtls_x509_crl *chain,
  15370. const unsigned char *buf, size_t buflen );
  15371. /**
  15372. * \brief Parse one or more CRLs and append them to the chained list
  15373. *
  15374. * \note Multiple CRLs are accepted only if using PEM format
  15375. *
  15376. * \param chain points to the start of the chain
  15377. * \param buf buffer holding the CRL data in PEM or DER format
  15378. * \param buflen size of the buffer
  15379. * (including the terminating null byte for PEM data)
  15380. *
  15381. * \return 0 if successful, or a specific X509 or PEM error code
  15382. */
  15383. int mbedtls_x509_crl_parse( mbedtls_x509_crl *chain, const unsigned char *buf, size_t buflen );
  15384. #if defined(MBEDTLS_FS_IO)
  15385. /**
  15386. * \brief Load one or more CRLs and append them to the chained list
  15387. *
  15388. * \note Multiple CRLs are accepted only if using PEM format
  15389. *
  15390. * \param chain points to the start of the chain
  15391. * \param path filename to read the CRLs from (in PEM or DER encoding)
  15392. *
  15393. * \return 0 if successful, or a specific X509 or PEM error code
  15394. */
  15395. int mbedtls_x509_crl_parse_file( mbedtls_x509_crl *chain, const char *path );
  15396. #endif /* MBEDTLS_FS_IO */
  15397. /**
  15398. * \brief Returns an informational string about the CRL.
  15399. *
  15400. * \param buf Buffer to write to
  15401. * \param size Maximum size of buffer
  15402. * \param prefix A line prefix
  15403. * \param crl The X509 CRL to represent
  15404. *
  15405. * \return The length of the string written (not including the
  15406. * terminated nul byte), or a negative error code.
  15407. */
  15408. int mbedtls_x509_crl_info( char *buf, size_t size, const char *prefix,
  15409. const mbedtls_x509_crl *crl );
  15410. /**
  15411. * \brief Initialize a CRL (chain)
  15412. *
  15413. * \param crl CRL chain to initialize
  15414. */
  15415. void mbedtls_x509_crl_init( mbedtls_x509_crl *crl );
  15416. /**
  15417. * \brief Unallocate all CRL data
  15418. *
  15419. * \param crl CRL chain to free
  15420. */
  15421. void mbedtls_x509_crl_free( mbedtls_x509_crl *crl );
  15422. /* \} name */
  15423. /* \} addtogroup x509_module */
  15424. #ifdef __cplusplus
  15425. }
  15426. #endif
  15427. #endif /* mbedtls_x509_crl.h */
  15428. /********* Start of file include/mbedtls/x509_crt.h ************/
  15429. /**
  15430. * \file x509_crt.h
  15431. *
  15432. * \brief X.509 certificate parsing and writing
  15433. */
  15434. /*
  15435. * Copyright The Mbed TLS Contributors
  15436. * SPDX-License-Identifier: Apache-2.0
  15437. *
  15438. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  15439. * not use this file except in compliance with the License.
  15440. * You may obtain a copy of the License at
  15441. *
  15442. * http://www.apache.org/licenses/LICENSE-2.0
  15443. *
  15444. * Unless required by applicable law or agreed to in writing, software
  15445. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  15446. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  15447. * See the License for the specific language governing permissions and
  15448. * limitations under the License.
  15449. */
  15450. #ifndef MBEDTLS_X509_CRT_H
  15451. #define MBEDTLS_X509_CRT_H
  15452. #if !defined(MBEDTLS_CONFIG_FILE)
  15453. #else
  15454. #endif
  15455. /**
  15456. * \addtogroup x509_module
  15457. * \{
  15458. */
  15459. #ifdef __cplusplus
  15460. extern "C" {
  15461. #endif
  15462. /**
  15463. * \name Structures and functions for parsing and writing X.509 certificates
  15464. * \{
  15465. */
  15466. /**
  15467. * Container for an X.509 certificate. The certificate may be chained.
  15468. */
  15469. typedef struct mbedtls_x509_crt
  15470. {
  15471. int own_buffer; /**< Indicates if \c raw is owned
  15472. * by the structure or not. */
  15473. mbedtls_x509_buf raw; /**< The raw certificate data (DER). */
  15474. mbedtls_x509_buf tbs; /**< The raw certificate body (DER). The part that is To Be Signed. */
  15475. int version; /**< The X.509 version. (1=v1, 2=v2, 3=v3) */
  15476. mbedtls_x509_buf serial; /**< Unique id for certificate issued by a specific CA. */
  15477. mbedtls_x509_buf sig_oid; /**< Signature algorithm, e.g. sha1RSA */
  15478. mbedtls_x509_buf issuer_raw; /**< The raw issuer data (DER). Used for quick comparison. */
  15479. mbedtls_x509_buf subject_raw; /**< The raw subject data (DER). Used for quick comparison. */
  15480. mbedtls_x509_name issuer; /**< The parsed issuer data (named information object). */
  15481. mbedtls_x509_name subject; /**< The parsed subject data (named information object). */
  15482. mbedtls_x509_time valid_from; /**< Start time of certificate validity. */
  15483. mbedtls_x509_time valid_to; /**< End time of certificate validity. */
  15484. mbedtls_x509_buf pk_raw;
  15485. mbedtls_pk_context pk; /**< Container for the public key context. */
  15486. mbedtls_x509_buf issuer_id; /**< Optional X.509 v2/v3 issuer unique identifier. */
  15487. mbedtls_x509_buf subject_id; /**< Optional X.509 v2/v3 subject unique identifier. */
  15488. mbedtls_x509_buf v3_ext; /**< Optional X.509 v3 extensions. */
  15489. mbedtls_x509_sequence subject_alt_names; /**< Optional list of raw entries of Subject Alternative Names extension (currently only dNSName and OtherName are listed). */
  15490. mbedtls_x509_sequence certificate_policies; /**< Optional list of certificate policies (Only anyPolicy is printed and enforced, however the rest of the policies are still listed). */
  15491. int ext_types; /**< Bit string containing detected and parsed extensions */
  15492. int ca_istrue; /**< Optional Basic Constraint extension value: 1 if this certificate belongs to a CA, 0 otherwise. */
  15493. int max_pathlen; /**< Optional Basic Constraint extension value: The maximum path length to the root certificate. Path length is 1 higher than RFC 5280 'meaning', so 1+ */
  15494. unsigned int key_usage; /**< Optional key usage extension value: See the values in x509.h */
  15495. mbedtls_x509_sequence ext_key_usage; /**< Optional list of extended key usage OIDs. */
  15496. unsigned char ns_cert_type; /**< Optional Netscape certificate type extension value: See the values in x509.h */
  15497. mbedtls_x509_buf sig; /**< Signature: hash of the tbs part signed with the private key. */
  15498. mbedtls_md_type_t sig_md; /**< Internal representation of the MD algorithm of the signature algorithm, e.g. MBEDTLS_MD_SHA256 */
  15499. mbedtls_pk_type_t sig_pk; /**< Internal representation of the Public Key algorithm of the signature algorithm, e.g. MBEDTLS_PK_RSA */
  15500. void *sig_opts; /**< Signature options to be passed to mbedtls_pk_verify_ext(), e.g. for RSASSA-PSS */
  15501. struct mbedtls_x509_crt *next; /**< Next certificate in the CA-chain. */
  15502. }
  15503. mbedtls_x509_crt;
  15504. /**
  15505. * From RFC 5280 section 4.2.1.6:
  15506. * OtherName ::= SEQUENCE {
  15507. * type-id OBJECT IDENTIFIER,
  15508. * value [0] EXPLICIT ANY DEFINED BY type-id }
  15509. */
  15510. typedef struct mbedtls_x509_san_other_name
  15511. {
  15512. /**
  15513. * The type_id is an OID as deifned in RFC 5280.
  15514. * To check the value of the type id, you should use
  15515. * \p MBEDTLS_OID_CMP with a known OID mbedtls_x509_buf.
  15516. */
  15517. mbedtls_x509_buf type_id; /**< The type id. */
  15518. union
  15519. {
  15520. /**
  15521. * From RFC 4108 section 5:
  15522. * HardwareModuleName ::= SEQUENCE {
  15523. * hwType OBJECT IDENTIFIER,
  15524. * hwSerialNum OCTET STRING }
  15525. */
  15526. struct
  15527. {
  15528. mbedtls_x509_buf oid; /**< The object identifier. */
  15529. mbedtls_x509_buf val; /**< The named value. */
  15530. }
  15531. hardware_module_name;
  15532. }
  15533. value;
  15534. }
  15535. mbedtls_x509_san_other_name;
  15536. /**
  15537. * A structure for holding the parsed Subject Alternative Name, according to type
  15538. */
  15539. typedef struct mbedtls_x509_subject_alternative_name
  15540. {
  15541. int type; /**< The SAN type, value of MBEDTLS_X509_SAN_XXX. */
  15542. union {
  15543. mbedtls_x509_san_other_name other_name; /**< The otherName supported type. */
  15544. mbedtls_x509_buf unstructured_name; /**< The buffer for the un constructed types. Only dnsName currently supported */
  15545. }
  15546. san; /**< A union of the supported SAN types */
  15547. }
  15548. mbedtls_x509_subject_alternative_name;
  15549. /**
  15550. * Build flag from an algorithm/curve identifier (pk, md, ecp)
  15551. * Since 0 is always XXX_NONE, ignore it.
  15552. */
  15553. #define MBEDTLS_X509_ID_FLAG( id ) ( 1 << ( (id) - 1 ) )
  15554. /**
  15555. * Security profile for certificate verification.
  15556. *
  15557. * All lists are bitfields, built by ORing flags from MBEDTLS_X509_ID_FLAG().
  15558. */
  15559. typedef struct mbedtls_x509_crt_profile
  15560. {
  15561. uint32_t allowed_mds; /**< MDs for signatures */
  15562. uint32_t allowed_pks; /**< PK algs for signatures */
  15563. uint32_t allowed_curves; /**< Elliptic curves for ECDSA */
  15564. uint32_t rsa_min_bitlen; /**< Minimum size for RSA keys */
  15565. }
  15566. mbedtls_x509_crt_profile;
  15567. #define MBEDTLS_X509_CRT_VERSION_1 0
  15568. #define MBEDTLS_X509_CRT_VERSION_2 1
  15569. #define MBEDTLS_X509_CRT_VERSION_3 2
  15570. #define MBEDTLS_X509_RFC5280_MAX_SERIAL_LEN 32
  15571. #define MBEDTLS_X509_RFC5280_UTC_TIME_LEN 15
  15572. #if !defined( MBEDTLS_X509_MAX_FILE_PATH_LEN )
  15573. #define MBEDTLS_X509_MAX_FILE_PATH_LEN 512
  15574. #endif
  15575. /**
  15576. * Container for writing a certificate (CRT)
  15577. */
  15578. typedef struct mbedtls_x509write_cert
  15579. {
  15580. int version;
  15581. mbedtls_mpi serial;
  15582. mbedtls_pk_context *subject_key;
  15583. mbedtls_pk_context *issuer_key;
  15584. mbedtls_asn1_named_data *subject;
  15585. mbedtls_asn1_named_data *issuer;
  15586. mbedtls_md_type_t md_alg;
  15587. char not_before[MBEDTLS_X509_RFC5280_UTC_TIME_LEN + 1];
  15588. char not_after[MBEDTLS_X509_RFC5280_UTC_TIME_LEN + 1];
  15589. mbedtls_asn1_named_data *extensions;
  15590. }
  15591. mbedtls_x509write_cert;
  15592. /**
  15593. * Item in a verification chain: cert and flags for it
  15594. */
  15595. typedef struct {
  15596. mbedtls_x509_crt *crt;
  15597. uint32_t flags;
  15598. } mbedtls_x509_crt_verify_chain_item;
  15599. /**
  15600. * Max size of verification chain: end-entity + intermediates + trusted root
  15601. */
  15602. #define MBEDTLS_X509_MAX_VERIFY_CHAIN_SIZE ( MBEDTLS_X509_MAX_INTERMEDIATE_CA + 2 )
  15603. /**
  15604. * Verification chain as built by \c mbedtls_crt_verify_chain()
  15605. */
  15606. typedef struct
  15607. {
  15608. mbedtls_x509_crt_verify_chain_item items[MBEDTLS_X509_MAX_VERIFY_CHAIN_SIZE];
  15609. unsigned len;
  15610. #if defined(MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK)
  15611. /* This stores the list of potential trusted signers obtained from
  15612. * the CA callback used for the CRT verification, if configured.
  15613. * We must track it somewhere because the callback passes its
  15614. * ownership to the caller. */
  15615. mbedtls_x509_crt *trust_ca_cb_result;
  15616. #endif /* MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK */
  15617. } mbedtls_x509_crt_verify_chain;
  15618. #if defined(MBEDTLS_ECDSA_C) && defined(MBEDTLS_ECP_RESTARTABLE)
  15619. /**
  15620. * \brief Context for resuming X.509 verify operations
  15621. */
  15622. typedef struct
  15623. {
  15624. /* for check_signature() */
  15625. mbedtls_pk_restart_ctx pk;
  15626. /* for find_parent_in() */
  15627. mbedtls_x509_crt *parent; /* non-null iff parent_in in progress */
  15628. mbedtls_x509_crt *fallback_parent;
  15629. int fallback_signature_is_good;
  15630. /* for find_parent() */
  15631. int parent_is_trusted; /* -1 if find_parent is not in progress */
  15632. /* for verify_chain() */
  15633. enum {
  15634. x509_crt_rs_none,
  15635. x509_crt_rs_find_parent,
  15636. } in_progress; /* none if no operation is in progress */
  15637. int self_cnt;
  15638. mbedtls_x509_crt_verify_chain ver_chain;
  15639. } mbedtls_x509_crt_restart_ctx;
  15640. #else /* MBEDTLS_ECDSA_C && MBEDTLS_ECP_RESTARTABLE */
  15641. /* Now we can declare functions that take a pointer to that */
  15642. typedef void mbedtls_x509_crt_restart_ctx;
  15643. #endif /* MBEDTLS_ECDSA_C && MBEDTLS_ECP_RESTARTABLE */
  15644. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  15645. /**
  15646. * Default security profile. Should provide a good balance between security
  15647. * and compatibility with current deployments.
  15648. *
  15649. * This profile permits:
  15650. * - SHA2 hashes.
  15651. * - All supported elliptic curves.
  15652. * - RSA with 2048 bits and above.
  15653. *
  15654. * New minor versions of Mbed TLS may extend this profile, for example if
  15655. * new curves are added to the library. New minor versions of Mbed TLS will
  15656. * not reduce this profile unless serious security concerns require it.
  15657. */
  15658. extern const mbedtls_x509_crt_profile mbedtls_x509_crt_profile_default;
  15659. /**
  15660. * Expected next default profile. Recommended for new deployments.
  15661. * Currently targets a 128-bit security level, except for allowing RSA-2048.
  15662. */
  15663. extern const mbedtls_x509_crt_profile mbedtls_x509_crt_profile_next;
  15664. /**
  15665. * NSA Suite B profile.
  15666. */
  15667. extern const mbedtls_x509_crt_profile mbedtls_x509_crt_profile_suiteb;
  15668. /**
  15669. * \brief Parse a single DER formatted certificate and add it
  15670. * to the end of the provided chained list.
  15671. *
  15672. * \param chain The pointer to the start of the CRT chain to attach to.
  15673. * When parsing the first CRT in a chain, this should point
  15674. * to an instance of ::mbedtls_x509_crt initialized through
  15675. * mbedtls_x509_crt_init().
  15676. * \param buf The buffer holding the DER encoded certificate.
  15677. * \param buflen The size in Bytes of \p buf.
  15678. *
  15679. * \note This function makes an internal copy of the CRT buffer
  15680. * \p buf. In particular, \p buf may be destroyed or reused
  15681. * after this call returns. To avoid duplicating the CRT
  15682. * buffer (at the cost of stricter lifetime constraints),
  15683. * use mbedtls_x509_crt_parse_der_nocopy() instead.
  15684. *
  15685. * \return \c 0 if successful.
  15686. * \return A negative error code on failure.
  15687. */
  15688. int mbedtls_x509_crt_parse_der( mbedtls_x509_crt *chain,
  15689. const unsigned char *buf,
  15690. size_t buflen );
  15691. /**
  15692. * \brief The type of certificate extension callbacks.
  15693. *
  15694. * Callbacks of this type are passed to and used by the
  15695. * mbedtls_x509_crt_parse_der_with_ext_cb() routine when
  15696. * it encounters either an unsupported extension or a
  15697. * "certificate policies" extension containing any
  15698. * unsupported certificate policies.
  15699. * Future versions of the library may invoke the callback
  15700. * in other cases, if and when the need arises.
  15701. *
  15702. * \param p_ctx An opaque context passed to the callback.
  15703. * \param crt The certificate being parsed.
  15704. * \param oid The OID of the extension.
  15705. * \param critical Whether the extension is critical.
  15706. * \param p Pointer to the start of the extension value
  15707. * (the content of the OCTET STRING).
  15708. * \param end End of extension value.
  15709. *
  15710. * \note The callback must fail and return a negative error code
  15711. * if it can not parse or does not support the extension.
  15712. * When the callback fails to parse a critical extension
  15713. * mbedtls_x509_crt_parse_der_with_ext_cb() also fails.
  15714. * When the callback fails to parse a non critical extension
  15715. * mbedtls_x509_crt_parse_der_with_ext_cb() simply skips
  15716. * the extension and continues parsing.
  15717. *
  15718. * \return \c 0 on success.
  15719. * \return A negative error code on failure.
  15720. */
  15721. typedef int (*mbedtls_x509_crt_ext_cb_t)( void *p_ctx,
  15722. mbedtls_x509_crt const *crt,
  15723. mbedtls_x509_buf const *oid,
  15724. int critical,
  15725. const unsigned char *p,
  15726. const unsigned char *end );
  15727. /**
  15728. * \brief Parse a single DER formatted certificate and add it
  15729. * to the end of the provided chained list.
  15730. *
  15731. * \param chain The pointer to the start of the CRT chain to attach to.
  15732. * When parsing the first CRT in a chain, this should point
  15733. * to an instance of ::mbedtls_x509_crt initialized through
  15734. * mbedtls_x509_crt_init().
  15735. * \param buf The buffer holding the DER encoded certificate.
  15736. * \param buflen The size in Bytes of \p buf.
  15737. * \param make_copy When not zero this function makes an internal copy of the
  15738. * CRT buffer \p buf. In particular, \p buf may be destroyed
  15739. * or reused after this call returns.
  15740. * When zero this function avoids duplicating the CRT buffer
  15741. * by taking temporary ownership thereof until the CRT
  15742. * is destroyed (like mbedtls_x509_crt_parse_der_nocopy())
  15743. * \param cb A callback invoked for every unsupported certificate
  15744. * extension.
  15745. * \param p_ctx An opaque context passed to the callback.
  15746. *
  15747. * \note This call is functionally equivalent to
  15748. * mbedtls_x509_crt_parse_der(), and/or
  15749. * mbedtls_x509_crt_parse_der_nocopy()
  15750. * but it calls the callback with every unsupported
  15751. * certificate extension and additionally the
  15752. * "certificate policies" extension if it contains any
  15753. * unsupported certificate policies.
  15754. * The callback must return a negative error code if it
  15755. * does not know how to handle such an extension.
  15756. * When the callback fails to parse a critical extension
  15757. * mbedtls_x509_crt_parse_der_with_ext_cb() also fails.
  15758. * When the callback fails to parse a non critical extension
  15759. * mbedtls_x509_crt_parse_der_with_ext_cb() simply skips
  15760. * the extension and continues parsing.
  15761. * Future versions of the library may invoke the callback
  15762. * in other cases, if and when the need arises.
  15763. *
  15764. * \return \c 0 if successful.
  15765. * \return A negative error code on failure.
  15766. */
  15767. int mbedtls_x509_crt_parse_der_with_ext_cb( mbedtls_x509_crt *chain,
  15768. const unsigned char *buf,
  15769. size_t buflen,
  15770. int make_copy,
  15771. mbedtls_x509_crt_ext_cb_t cb,
  15772. void *p_ctx );
  15773. /**
  15774. * \brief Parse a single DER formatted certificate and add it
  15775. * to the end of the provided chained list. This is a
  15776. * variant of mbedtls_x509_crt_parse_der() which takes
  15777. * temporary ownership of the CRT buffer until the CRT
  15778. * is destroyed.
  15779. *
  15780. * \param chain The pointer to the start of the CRT chain to attach to.
  15781. * When parsing the first CRT in a chain, this should point
  15782. * to an instance of ::mbedtls_x509_crt initialized through
  15783. * mbedtls_x509_crt_init().
  15784. * \param buf The address of the readable buffer holding the DER encoded
  15785. * certificate to use. On success, this buffer must be
  15786. * retained and not be changed for the liftetime of the
  15787. * CRT chain \p chain, that is, until \p chain is destroyed
  15788. * through a call to mbedtls_x509_crt_free().
  15789. * \param buflen The size in Bytes of \p buf.
  15790. *
  15791. * \note This call is functionally equivalent to
  15792. * mbedtls_x509_crt_parse_der(), but it avoids creating a
  15793. * copy of the input buffer at the cost of stronger lifetime
  15794. * constraints. This is useful in constrained environments
  15795. * where duplication of the CRT cannot be tolerated.
  15796. *
  15797. * \return \c 0 if successful.
  15798. * \return A negative error code on failure.
  15799. */
  15800. int mbedtls_x509_crt_parse_der_nocopy( mbedtls_x509_crt *chain,
  15801. const unsigned char *buf,
  15802. size_t buflen );
  15803. /**
  15804. * \brief Parse one DER-encoded or one or more concatenated PEM-encoded
  15805. * certificates and add them to the chained list.
  15806. *
  15807. * For CRTs in PEM encoding, the function parses permissively:
  15808. * if at least one certificate can be parsed, the function
  15809. * returns the number of certificates for which parsing failed
  15810. * (hence \c 0 if all certificates were parsed successfully).
  15811. * If no certificate could be parsed, the function returns
  15812. * the first (negative) error encountered during parsing.
  15813. *
  15814. * PEM encoded certificates may be interleaved by other data
  15815. * such as human readable descriptions of their content, as
  15816. * long as the certificates are enclosed in the PEM specific
  15817. * '-----{BEGIN/END} CERTIFICATE-----' delimiters.
  15818. *
  15819. * \param chain The chain to which to add the parsed certificates.
  15820. * \param buf The buffer holding the certificate data in PEM or DER format.
  15821. * For certificates in PEM encoding, this may be a concatenation
  15822. * of multiple certificates; for DER encoding, the buffer must
  15823. * comprise exactly one certificate.
  15824. * \param buflen The size of \p buf, including the terminating \c NULL byte
  15825. * in case of PEM encoded data.
  15826. *
  15827. * \return \c 0 if all certificates were parsed successfully.
  15828. * \return The (positive) number of certificates that couldn't
  15829. * be parsed if parsing was partly successful (see above).
  15830. * \return A negative X509 or PEM error code otherwise.
  15831. *
  15832. */
  15833. int mbedtls_x509_crt_parse( mbedtls_x509_crt *chain, const unsigned char *buf, size_t buflen );
  15834. #if defined(MBEDTLS_FS_IO)
  15835. /**
  15836. * \brief Load one or more certificates and add them
  15837. * to the chained list. Parses permissively. If some
  15838. * certificates can be parsed, the result is the number
  15839. * of failed certificates it encountered. If none complete
  15840. * correctly, the first error is returned.
  15841. *
  15842. * \param chain points to the start of the chain
  15843. * \param path filename to read the certificates from
  15844. *
  15845. * \return 0 if all certificates parsed successfully, a positive number
  15846. * if partly successful or a specific X509 or PEM error code
  15847. */
  15848. int mbedtls_x509_crt_parse_file( mbedtls_x509_crt *chain, const char *path );
  15849. /**
  15850. * \brief Load one or more certificate files from a path and add them
  15851. * to the chained list. Parses permissively. If some
  15852. * certificates can be parsed, the result is the number
  15853. * of failed certificates it encountered. If none complete
  15854. * correctly, the first error is returned.
  15855. *
  15856. * \param chain points to the start of the chain
  15857. * \param path directory / folder to read the certificate files from
  15858. *
  15859. * \return 0 if all certificates parsed successfully, a positive number
  15860. * if partly successful or a specific X509 or PEM error code
  15861. */
  15862. int mbedtls_x509_crt_parse_path( mbedtls_x509_crt *chain, const char *path );
  15863. #endif /* MBEDTLS_FS_IO */
  15864. /**
  15865. * \brief This function parses an item in the SubjectAlternativeNames
  15866. * extension.
  15867. *
  15868. * \param san_buf The buffer holding the raw data item of the subject
  15869. * alternative name.
  15870. * \param san The target structure to populate with the parsed presentation
  15871. * of the subject alternative name encoded in \p san_raw.
  15872. *
  15873. * \note Only "dnsName" and "otherName" of type hardware_module_name
  15874. * as defined in RFC 4180 is supported.
  15875. *
  15876. * \note This function should be called on a single raw data of
  15877. * subject alternative name. For example, after successful
  15878. * certificate parsing, one must iterate on every item in the
  15879. * \p crt->subject_alt_names sequence, and pass it to
  15880. * this function.
  15881. *
  15882. * \warning The target structure contains pointers to the raw data of the
  15883. * parsed certificate, and its lifetime is restricted by the
  15884. * lifetime of the certificate.
  15885. *
  15886. * \return \c 0 on success
  15887. * \return #MBEDTLS_ERR_X509_FEATURE_UNAVAILABLE for an unsupported
  15888. * SAN type.
  15889. * \return Another negative value for any other failure.
  15890. */
  15891. int mbedtls_x509_parse_subject_alt_name( const mbedtls_x509_buf *san_buf,
  15892. mbedtls_x509_subject_alternative_name *san );
  15893. /**
  15894. * \brief Returns an informational string about the
  15895. * certificate.
  15896. *
  15897. * \param buf Buffer to write to
  15898. * \param size Maximum size of buffer
  15899. * \param prefix A line prefix
  15900. * \param crt The X509 certificate to represent
  15901. *
  15902. * \return The length of the string written (not including the
  15903. * terminated nul byte), or a negative error code.
  15904. */
  15905. int mbedtls_x509_crt_info( char *buf, size_t size, const char *prefix,
  15906. const mbedtls_x509_crt *crt );
  15907. /**
  15908. * \brief Returns an informational string about the
  15909. * verification status of a certificate.
  15910. *
  15911. * \param buf Buffer to write to
  15912. * \param size Maximum size of buffer
  15913. * \param prefix A line prefix
  15914. * \param flags Verification flags created by mbedtls_x509_crt_verify()
  15915. *
  15916. * \return The length of the string written (not including the
  15917. * terminated nul byte), or a negative error code.
  15918. */
  15919. int mbedtls_x509_crt_verify_info( char *buf, size_t size, const char *prefix,
  15920. uint32_t flags );
  15921. /**
  15922. * \brief Verify a chain of certificates.
  15923. *
  15924. * The verify callback is a user-supplied callback that
  15925. * can clear / modify / add flags for a certificate. If set,
  15926. * the verification callback is called for each
  15927. * certificate in the chain (from the trust-ca down to the
  15928. * presented crt). The parameters for the callback are:
  15929. * (void *parameter, mbedtls_x509_crt *crt, int certificate_depth,
  15930. * int *flags). With the flags representing current flags for
  15931. * that specific certificate and the certificate depth from
  15932. * the bottom (Peer cert depth = 0).
  15933. *
  15934. * All flags left after returning from the callback
  15935. * are also returned to the application. The function should
  15936. * return 0 for anything (including invalid certificates)
  15937. * other than fatal error, as a non-zero return code
  15938. * immediately aborts the verification process. For fatal
  15939. * errors, a specific error code should be used (different
  15940. * from MBEDTLS_ERR_X509_CERT_VERIFY_FAILED which should not
  15941. * be returned at this point), or MBEDTLS_ERR_X509_FATAL_ERROR
  15942. * can be used if no better code is available.
  15943. *
  15944. * \note In case verification failed, the results can be displayed
  15945. * using \c mbedtls_x509_crt_verify_info()
  15946. *
  15947. * \note Same as \c mbedtls_x509_crt_verify_with_profile() with the
  15948. * default security profile.
  15949. *
  15950. * \note It is your responsibility to provide up-to-date CRLs for
  15951. * all trusted CAs. If no CRL is provided for the CA that was
  15952. * used to sign the certificate, CRL verification is skipped
  15953. * silently, that is *without* setting any flag.
  15954. *
  15955. * \note The \c trust_ca list can contain two types of certificates:
  15956. * (1) those of trusted root CAs, so that certificates
  15957. * chaining up to those CAs will be trusted, and (2)
  15958. * self-signed end-entity certificates to be trusted (for
  15959. * specific peers you know) - in that case, the self-signed
  15960. * certificate doesn't need to have the CA bit set.
  15961. *
  15962. * \param crt The certificate chain to be verified.
  15963. * \param trust_ca The list of trusted CAs.
  15964. * \param ca_crl The list of CRLs for trusted CAs.
  15965. * \param cn The expected Common Name. This will be checked to be
  15966. * present in the certificate's subjectAltNames extension or,
  15967. * if this extension is absent, as a CN component in its
  15968. * Subject name. Currently only DNS names are supported. This
  15969. * may be \c NULL if the CN need not be verified.
  15970. * \param flags The address at which to store the result of the verification.
  15971. * If the verification couldn't be completed, the flag value is
  15972. * set to (uint32_t) -1.
  15973. * \param f_vrfy The verification callback to use. See the documentation
  15974. * of mbedtls_x509_crt_verify() for more information.
  15975. * \param p_vrfy The context to be passed to \p f_vrfy.
  15976. *
  15977. * \return \c 0 if the chain is valid with respect to the
  15978. * passed CN, CAs, CRLs and security profile.
  15979. * \return #MBEDTLS_ERR_X509_CERT_VERIFY_FAILED in case the
  15980. * certificate chain verification failed. In this case,
  15981. * \c *flags will have one or more
  15982. * \c MBEDTLS_X509_BADCERT_XXX or \c MBEDTLS_X509_BADCRL_XXX
  15983. * flags set.
  15984. * \return Another negative error code in case of a fatal error
  15985. * encountered during the verification process.
  15986. */
  15987. int mbedtls_x509_crt_verify( mbedtls_x509_crt *crt,
  15988. mbedtls_x509_crt *trust_ca,
  15989. mbedtls_x509_crl *ca_crl,
  15990. const char *cn, uint32_t *flags,
  15991. int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *),
  15992. void *p_vrfy );
  15993. /**
  15994. * \brief Verify a chain of certificates with respect to
  15995. * a configurable security profile.
  15996. *
  15997. * \note Same as \c mbedtls_x509_crt_verify(), but with explicit
  15998. * security profile.
  15999. *
  16000. * \note The restrictions on keys (RSA minimum size, allowed curves
  16001. * for ECDSA) apply to all certificates: trusted root,
  16002. * intermediate CAs if any, and end entity certificate.
  16003. *
  16004. * \param crt The certificate chain to be verified.
  16005. * \param trust_ca The list of trusted CAs.
  16006. * \param ca_crl The list of CRLs for trusted CAs.
  16007. * \param profile The security profile to use for the verification.
  16008. * \param cn The expected Common Name. This may be \c NULL if the
  16009. * CN need not be verified.
  16010. * \param flags The address at which to store the result of the verification.
  16011. * If the verification couldn't be completed, the flag value is
  16012. * set to (uint32_t) -1.
  16013. * \param f_vrfy The verification callback to use. See the documentation
  16014. * of mbedtls_x509_crt_verify() for more information.
  16015. * \param p_vrfy The context to be passed to \p f_vrfy.
  16016. *
  16017. * \return \c 0 if the chain is valid with respect to the
  16018. * passed CN, CAs, CRLs and security profile.
  16019. * \return #MBEDTLS_ERR_X509_CERT_VERIFY_FAILED in case the
  16020. * certificate chain verification failed. In this case,
  16021. * \c *flags will have one or more
  16022. * \c MBEDTLS_X509_BADCERT_XXX or \c MBEDTLS_X509_BADCRL_XXX
  16023. * flags set.
  16024. * \return Another negative error code in case of a fatal error
  16025. * encountered during the verification process.
  16026. */
  16027. int mbedtls_x509_crt_verify_with_profile( mbedtls_x509_crt *crt,
  16028. mbedtls_x509_crt *trust_ca,
  16029. mbedtls_x509_crl *ca_crl,
  16030. const mbedtls_x509_crt_profile *profile,
  16031. const char *cn, uint32_t *flags,
  16032. int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *),
  16033. void *p_vrfy );
  16034. /**
  16035. * \brief Restartable version of \c mbedtls_crt_verify_with_profile()
  16036. *
  16037. * \note Performs the same job as \c mbedtls_crt_verify_with_profile()
  16038. * but can return early and restart according to the limit
  16039. * set with \c mbedtls_ecp_set_max_ops() to reduce blocking.
  16040. *
  16041. * \param crt The certificate chain to be verified.
  16042. * \param trust_ca The list of trusted CAs.
  16043. * \param ca_crl The list of CRLs for trusted CAs.
  16044. * \param profile The security profile to use for the verification.
  16045. * \param cn The expected Common Name. This may be \c NULL if the
  16046. * CN need not be verified.
  16047. * \param flags The address at which to store the result of the verification.
  16048. * If the verification couldn't be completed, the flag value is
  16049. * set to (uint32_t) -1.
  16050. * \param f_vrfy The verification callback to use. See the documentation
  16051. * of mbedtls_x509_crt_verify() for more information.
  16052. * \param p_vrfy The context to be passed to \p f_vrfy.
  16053. * \param rs_ctx The restart context to use. This may be set to \c NULL
  16054. * to disable restartable ECC.
  16055. *
  16056. * \return See \c mbedtls_crt_verify_with_profile(), or
  16057. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  16058. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  16059. */
  16060. int mbedtls_x509_crt_verify_restartable( mbedtls_x509_crt *crt,
  16061. mbedtls_x509_crt *trust_ca,
  16062. mbedtls_x509_crl *ca_crl,
  16063. const mbedtls_x509_crt_profile *profile,
  16064. const char *cn, uint32_t *flags,
  16065. int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *),
  16066. void *p_vrfy,
  16067. mbedtls_x509_crt_restart_ctx *rs_ctx );
  16068. /**
  16069. * \brief The type of trusted certificate callbacks.
  16070. *
  16071. * Callbacks of this type are passed to and used by the CRT
  16072. * verification routine mbedtls_x509_crt_verify_with_ca_cb()
  16073. * when looking for trusted signers of a given certificate.
  16074. *
  16075. * On success, the callback returns a list of trusted
  16076. * certificates to be considered as potential signers
  16077. * for the input certificate.
  16078. *
  16079. * \param p_ctx An opaque context passed to the callback.
  16080. * \param child The certificate for which to search a potential signer.
  16081. * This will point to a readable certificate.
  16082. * \param candidate_cas The address at which to store the address of the first
  16083. * entry in the generated linked list of candidate signers.
  16084. * This will not be \c NULL.
  16085. *
  16086. * \note The callback must only return a non-zero value on a
  16087. * fatal error. If, in contrast, the search for a potential
  16088. * signer completes without a single candidate, the
  16089. * callback must return \c 0 and set \c *candidate_cas
  16090. * to \c NULL.
  16091. *
  16092. * \return \c 0 on success. In this case, \c *candidate_cas points
  16093. * to a heap-allocated linked list of instances of
  16094. * ::mbedtls_x509_crt, and ownership of this list is passed
  16095. * to the caller.
  16096. * \return A negative error code on failure.
  16097. */
  16098. typedef int (*mbedtls_x509_crt_ca_cb_t)( void *p_ctx,
  16099. mbedtls_x509_crt const *child,
  16100. mbedtls_x509_crt **candidate_cas );
  16101. #if defined(MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK)
  16102. /**
  16103. * \brief Version of \c mbedtls_x509_crt_verify_with_profile() which
  16104. * uses a callback to acquire the list of trusted CA
  16105. * certificates.
  16106. *
  16107. * \param crt The certificate chain to be verified.
  16108. * \param f_ca_cb The callback to be used to query for potential signers
  16109. * of a given child certificate. See the documentation of
  16110. * ::mbedtls_x509_crt_ca_cb_t for more information.
  16111. * \param p_ca_cb The opaque context to be passed to \p f_ca_cb.
  16112. * \param profile The security profile for the verification.
  16113. * \param cn The expected Common Name. This may be \c NULL if the
  16114. * CN need not be verified.
  16115. * \param flags The address at which to store the result of the verification.
  16116. * If the verification couldn't be completed, the flag value is
  16117. * set to (uint32_t) -1.
  16118. * \param f_vrfy The verification callback to use. See the documentation
  16119. * of mbedtls_x509_crt_verify() for more information.
  16120. * \param p_vrfy The context to be passed to \p f_vrfy.
  16121. *
  16122. * \return See \c mbedtls_crt_verify_with_profile().
  16123. */
  16124. int mbedtls_x509_crt_verify_with_ca_cb( mbedtls_x509_crt *crt,
  16125. mbedtls_x509_crt_ca_cb_t f_ca_cb,
  16126. void *p_ca_cb,
  16127. const mbedtls_x509_crt_profile *profile,
  16128. const char *cn, uint32_t *flags,
  16129. int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *),
  16130. void *p_vrfy );
  16131. #endif /* MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK */
  16132. #if defined(MBEDTLS_X509_CHECK_KEY_USAGE)
  16133. /**
  16134. * \brief Check usage of certificate against keyUsage extension.
  16135. *
  16136. * \param crt Leaf certificate used.
  16137. * \param usage Intended usage(s) (eg MBEDTLS_X509_KU_KEY_ENCIPHERMENT
  16138. * before using the certificate to perform an RSA key
  16139. * exchange).
  16140. *
  16141. * \note Except for decipherOnly and encipherOnly, a bit set in the
  16142. * usage argument means this bit MUST be set in the
  16143. * certificate. For decipherOnly and encipherOnly, it means
  16144. * that bit MAY be set.
  16145. *
  16146. * \return 0 is these uses of the certificate are allowed,
  16147. * MBEDTLS_ERR_X509_BAD_INPUT_DATA if the keyUsage extension
  16148. * is present but does not match the usage argument.
  16149. *
  16150. * \note You should only call this function on leaf certificates, on
  16151. * (intermediate) CAs the keyUsage extension is automatically
  16152. * checked by \c mbedtls_x509_crt_verify().
  16153. */
  16154. int mbedtls_x509_crt_check_key_usage( const mbedtls_x509_crt *crt,
  16155. unsigned int usage );
  16156. #endif /* MBEDTLS_X509_CHECK_KEY_USAGE) */
  16157. #if defined(MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE)
  16158. /**
  16159. * \brief Check usage of certificate against extendedKeyUsage.
  16160. *
  16161. * \param crt Leaf certificate used.
  16162. * \param usage_oid Intended usage (eg MBEDTLS_OID_SERVER_AUTH or
  16163. * MBEDTLS_OID_CLIENT_AUTH).
  16164. * \param usage_len Length of usage_oid (eg given by MBEDTLS_OID_SIZE()).
  16165. *
  16166. * \return 0 if this use of the certificate is allowed,
  16167. * MBEDTLS_ERR_X509_BAD_INPUT_DATA if not.
  16168. *
  16169. * \note Usually only makes sense on leaf certificates.
  16170. */
  16171. int mbedtls_x509_crt_check_extended_key_usage( const mbedtls_x509_crt *crt,
  16172. const char *usage_oid,
  16173. size_t usage_len );
  16174. #endif /* MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE */
  16175. #if defined(MBEDTLS_X509_CRL_PARSE_C)
  16176. /**
  16177. * \brief Verify the certificate revocation status
  16178. *
  16179. * \param crt a certificate to be verified
  16180. * \param crl the CRL to verify against
  16181. *
  16182. * \return 1 if the certificate is revoked, 0 otherwise
  16183. *
  16184. */
  16185. int mbedtls_x509_crt_is_revoked( const mbedtls_x509_crt *crt, const mbedtls_x509_crl *crl );
  16186. #endif /* MBEDTLS_X509_CRL_PARSE_C */
  16187. /**
  16188. * \brief Initialize a certificate (chain)
  16189. *
  16190. * \param crt Certificate chain to initialize
  16191. */
  16192. void mbedtls_x509_crt_init( mbedtls_x509_crt *crt );
  16193. /**
  16194. * \brief Unallocate all certificate data
  16195. *
  16196. * \param crt Certificate chain to free
  16197. */
  16198. void mbedtls_x509_crt_free( mbedtls_x509_crt *crt );
  16199. #if defined(MBEDTLS_ECDSA_C) && defined(MBEDTLS_ECP_RESTARTABLE)
  16200. /**
  16201. * \brief Initialize a restart context
  16202. */
  16203. void mbedtls_x509_crt_restart_init( mbedtls_x509_crt_restart_ctx *ctx );
  16204. /**
  16205. * \brief Free the components of a restart context
  16206. */
  16207. void mbedtls_x509_crt_restart_free( mbedtls_x509_crt_restart_ctx *ctx );
  16208. #endif /* MBEDTLS_ECDSA_C && MBEDTLS_ECP_RESTARTABLE */
  16209. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  16210. /* \} name */
  16211. /* \} addtogroup x509_module */
  16212. #if defined(MBEDTLS_X509_CRT_WRITE_C)
  16213. /**
  16214. * \brief Initialize a CRT writing context
  16215. *
  16216. * \param ctx CRT context to initialize
  16217. */
  16218. void mbedtls_x509write_crt_init( mbedtls_x509write_cert *ctx );
  16219. /**
  16220. * \brief Set the verion for a Certificate
  16221. * Default: MBEDTLS_X509_CRT_VERSION_3
  16222. *
  16223. * \param ctx CRT context to use
  16224. * \param version version to set (MBEDTLS_X509_CRT_VERSION_1, MBEDTLS_X509_CRT_VERSION_2 or
  16225. * MBEDTLS_X509_CRT_VERSION_3)
  16226. */
  16227. void mbedtls_x509write_crt_set_version( mbedtls_x509write_cert *ctx, int version );
  16228. /**
  16229. * \brief Set the serial number for a Certificate.
  16230. *
  16231. * \param ctx CRT context to use
  16232. * \param serial serial number to set
  16233. *
  16234. * \return 0 if successful
  16235. */
  16236. int mbedtls_x509write_crt_set_serial( mbedtls_x509write_cert *ctx, const mbedtls_mpi *serial );
  16237. /**
  16238. * \brief Set the validity period for a Certificate
  16239. * Timestamps should be in string format for UTC timezone
  16240. * i.e. "YYYYMMDDhhmmss"
  16241. * e.g. "20131231235959" for December 31st 2013
  16242. * at 23:59:59
  16243. *
  16244. * \param ctx CRT context to use
  16245. * \param not_before not_before timestamp
  16246. * \param not_after not_after timestamp
  16247. *
  16248. * \return 0 if timestamp was parsed successfully, or
  16249. * a specific error code
  16250. */
  16251. int mbedtls_x509write_crt_set_validity( mbedtls_x509write_cert *ctx, const char *not_before,
  16252. const char *not_after );
  16253. /**
  16254. * \brief Set the issuer name for a Certificate
  16255. * Issuer names should contain a comma-separated list
  16256. * of OID types and values:
  16257. * e.g. "C=UK,O=ARM,CN=mbed TLS CA"
  16258. *
  16259. * \param ctx CRT context to use
  16260. * \param issuer_name issuer name to set
  16261. *
  16262. * \return 0 if issuer name was parsed successfully, or
  16263. * a specific error code
  16264. */
  16265. int mbedtls_x509write_crt_set_issuer_name( mbedtls_x509write_cert *ctx,
  16266. const char *issuer_name );
  16267. /**
  16268. * \brief Set the subject name for a Certificate
  16269. * Subject names should contain a comma-separated list
  16270. * of OID types and values:
  16271. * e.g. "C=UK,O=ARM,CN=mbed TLS Server 1"
  16272. *
  16273. * \param ctx CRT context to use
  16274. * \param subject_name subject name to set
  16275. *
  16276. * \return 0 if subject name was parsed successfully, or
  16277. * a specific error code
  16278. */
  16279. int mbedtls_x509write_crt_set_subject_name( mbedtls_x509write_cert *ctx,
  16280. const char *subject_name );
  16281. /**
  16282. * \brief Set the subject public key for the certificate
  16283. *
  16284. * \param ctx CRT context to use
  16285. * \param key public key to include
  16286. */
  16287. void mbedtls_x509write_crt_set_subject_key( mbedtls_x509write_cert *ctx, mbedtls_pk_context *key );
  16288. /**
  16289. * \brief Set the issuer key used for signing the certificate
  16290. *
  16291. * \param ctx CRT context to use
  16292. * \param key private key to sign with
  16293. */
  16294. void mbedtls_x509write_crt_set_issuer_key( mbedtls_x509write_cert *ctx, mbedtls_pk_context *key );
  16295. /**
  16296. * \brief Set the MD algorithm to use for the signature
  16297. * (e.g. MBEDTLS_MD_SHA1)
  16298. *
  16299. * \param ctx CRT context to use
  16300. * \param md_alg MD algorithm to use
  16301. */
  16302. void mbedtls_x509write_crt_set_md_alg( mbedtls_x509write_cert *ctx, mbedtls_md_type_t md_alg );
  16303. /**
  16304. * \brief Generic function to add to or replace an extension in the
  16305. * CRT
  16306. *
  16307. * \param ctx CRT context to use
  16308. * \param oid OID of the extension
  16309. * \param oid_len length of the OID
  16310. * \param critical if the extension is critical (per the RFC's definition)
  16311. * \param val value of the extension OCTET STRING
  16312. * \param val_len length of the value data
  16313. *
  16314. * \return 0 if successful, or a MBEDTLS_ERR_X509_ALLOC_FAILED
  16315. */
  16316. int mbedtls_x509write_crt_set_extension( mbedtls_x509write_cert *ctx,
  16317. const char *oid, size_t oid_len,
  16318. int critical,
  16319. const unsigned char *val, size_t val_len );
  16320. /**
  16321. * \brief Set the basicConstraints extension for a CRT
  16322. *
  16323. * \param ctx CRT context to use
  16324. * \param is_ca is this a CA certificate
  16325. * \param max_pathlen maximum length of certificate chains below this
  16326. * certificate (only for CA certificates, -1 is
  16327. * inlimited)
  16328. *
  16329. * \return 0 if successful, or a MBEDTLS_ERR_X509_ALLOC_FAILED
  16330. */
  16331. int mbedtls_x509write_crt_set_basic_constraints( mbedtls_x509write_cert *ctx,
  16332. int is_ca, int max_pathlen );
  16333. #if defined(MBEDTLS_SHA1_C)
  16334. /**
  16335. * \brief Set the subjectKeyIdentifier extension for a CRT
  16336. * Requires that mbedtls_x509write_crt_set_subject_key() has been
  16337. * called before
  16338. *
  16339. * \param ctx CRT context to use
  16340. *
  16341. * \return 0 if successful, or a MBEDTLS_ERR_X509_ALLOC_FAILED
  16342. */
  16343. int mbedtls_x509write_crt_set_subject_key_identifier( mbedtls_x509write_cert *ctx );
  16344. /**
  16345. * \brief Set the authorityKeyIdentifier extension for a CRT
  16346. * Requires that mbedtls_x509write_crt_set_issuer_key() has been
  16347. * called before
  16348. *
  16349. * \param ctx CRT context to use
  16350. *
  16351. * \return 0 if successful, or a MBEDTLS_ERR_X509_ALLOC_FAILED
  16352. */
  16353. int mbedtls_x509write_crt_set_authority_key_identifier( mbedtls_x509write_cert *ctx );
  16354. #endif /* MBEDTLS_SHA1_C */
  16355. /**
  16356. * \brief Set the Key Usage Extension flags
  16357. * (e.g. MBEDTLS_X509_KU_DIGITAL_SIGNATURE | MBEDTLS_X509_KU_KEY_CERT_SIGN)
  16358. *
  16359. * \param ctx CRT context to use
  16360. * \param key_usage key usage flags to set
  16361. *
  16362. * \return 0 if successful, or MBEDTLS_ERR_X509_ALLOC_FAILED
  16363. */
  16364. int mbedtls_x509write_crt_set_key_usage( mbedtls_x509write_cert *ctx,
  16365. unsigned int key_usage );
  16366. /**
  16367. * \brief Set the Netscape Cert Type flags
  16368. * (e.g. MBEDTLS_X509_NS_CERT_TYPE_SSL_CLIENT | MBEDTLS_X509_NS_CERT_TYPE_EMAIL)
  16369. *
  16370. * \param ctx CRT context to use
  16371. * \param ns_cert_type Netscape Cert Type flags to set
  16372. *
  16373. * \return 0 if successful, or MBEDTLS_ERR_X509_ALLOC_FAILED
  16374. */
  16375. int mbedtls_x509write_crt_set_ns_cert_type( mbedtls_x509write_cert *ctx,
  16376. unsigned char ns_cert_type );
  16377. /**
  16378. * \brief Free the contents of a CRT write context
  16379. *
  16380. * \param ctx CRT context to free
  16381. */
  16382. void mbedtls_x509write_crt_free( mbedtls_x509write_cert *ctx );
  16383. /**
  16384. * \brief Write a built up certificate to a X509 DER structure
  16385. * Note: data is written at the end of the buffer! Use the
  16386. * return value to determine where you should start
  16387. * using the buffer
  16388. *
  16389. * \param ctx certificate to write away
  16390. * \param buf buffer to write to
  16391. * \param size size of the buffer
  16392. * \param f_rng RNG function (for signature, see note)
  16393. * \param p_rng RNG parameter
  16394. *
  16395. * \return length of data written if successful, or a specific
  16396. * error code
  16397. *
  16398. * \note f_rng may be NULL if RSA is used for signature and the
  16399. * signature is made offline (otherwise f_rng is desirable
  16400. * for countermeasures against timing attacks).
  16401. * ECDSA signatures always require a non-NULL f_rng.
  16402. */
  16403. int mbedtls_x509write_crt_der( mbedtls_x509write_cert *ctx, unsigned char *buf, size_t size,
  16404. int (*f_rng)(void *, unsigned char *, size_t),
  16405. void *p_rng );
  16406. #if defined(MBEDTLS_PEM_WRITE_C)
  16407. /**
  16408. * \brief Write a built up certificate to a X509 PEM string
  16409. *
  16410. * \param ctx certificate to write away
  16411. * \param buf buffer to write to
  16412. * \param size size of the buffer
  16413. * \param f_rng RNG function (for signature, see note)
  16414. * \param p_rng RNG parameter
  16415. *
  16416. * \return 0 if successful, or a specific error code
  16417. *
  16418. * \note f_rng may be NULL if RSA is used for signature and the
  16419. * signature is made offline (otherwise f_rng is desirable
  16420. * for countermeasures against timing attacks).
  16421. * ECDSA signatures always require a non-NULL f_rng.
  16422. */
  16423. int mbedtls_x509write_crt_pem( mbedtls_x509write_cert *ctx, unsigned char *buf, size_t size,
  16424. int (*f_rng)(void *, unsigned char *, size_t),
  16425. void *p_rng );
  16426. #endif /* MBEDTLS_PEM_WRITE_C */
  16427. #endif /* MBEDTLS_X509_CRT_WRITE_C */
  16428. #ifdef __cplusplus
  16429. }
  16430. #endif
  16431. #endif /* mbedtls_x509_crt.h */
  16432. /********* Start of file include/mbedtls/x509_csr.h ************/
  16433. /**
  16434. * \file x509_csr.h
  16435. *
  16436. * \brief X.509 certificate signing request parsing and writing
  16437. */
  16438. /*
  16439. * Copyright The Mbed TLS Contributors
  16440. * SPDX-License-Identifier: Apache-2.0
  16441. *
  16442. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  16443. * not use this file except in compliance with the License.
  16444. * You may obtain a copy of the License at
  16445. *
  16446. * http://www.apache.org/licenses/LICENSE-2.0
  16447. *
  16448. * Unless required by applicable law or agreed to in writing, software
  16449. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  16450. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  16451. * See the License for the specific language governing permissions and
  16452. * limitations under the License.
  16453. */
  16454. #ifndef MBEDTLS_X509_CSR_H
  16455. #define MBEDTLS_X509_CSR_H
  16456. #if !defined(MBEDTLS_CONFIG_FILE)
  16457. #else
  16458. #endif
  16459. #ifdef __cplusplus
  16460. extern "C" {
  16461. #endif
  16462. /**
  16463. * \addtogroup x509_module
  16464. * \{ */
  16465. /**
  16466. * \name Structures and functions for X.509 Certificate Signing Requests (CSR)
  16467. * \{
  16468. */
  16469. /**
  16470. * Certificate Signing Request (CSR) structure.
  16471. */
  16472. typedef struct mbedtls_x509_csr
  16473. {
  16474. mbedtls_x509_buf raw; /**< The raw CSR data (DER). */
  16475. mbedtls_x509_buf cri; /**< The raw CertificateRequestInfo body (DER). */
  16476. int version; /**< CSR version (1=v1). */
  16477. mbedtls_x509_buf subject_raw; /**< The raw subject data (DER). */
  16478. mbedtls_x509_name subject; /**< The parsed subject data (named information object). */
  16479. mbedtls_pk_context pk; /**< Container for the public key context. */
  16480. mbedtls_x509_buf sig_oid;
  16481. mbedtls_x509_buf sig;
  16482. mbedtls_md_type_t sig_md; /**< Internal representation of the MD algorithm of the signature algorithm, e.g. MBEDTLS_MD_SHA256 */
  16483. mbedtls_pk_type_t sig_pk; /**< Internal representation of the Public Key algorithm of the signature algorithm, e.g. MBEDTLS_PK_RSA */
  16484. void *sig_opts; /**< Signature options to be passed to mbedtls_pk_verify_ext(), e.g. for RSASSA-PSS */
  16485. }
  16486. mbedtls_x509_csr;
  16487. /**
  16488. * Container for writing a CSR
  16489. */
  16490. typedef struct mbedtls_x509write_csr
  16491. {
  16492. mbedtls_pk_context *key;
  16493. mbedtls_asn1_named_data *subject;
  16494. mbedtls_md_type_t md_alg;
  16495. mbedtls_asn1_named_data *extensions;
  16496. }
  16497. mbedtls_x509write_csr;
  16498. #if defined(MBEDTLS_X509_CSR_PARSE_C)
  16499. /**
  16500. * \brief Load a Certificate Signing Request (CSR) in DER format
  16501. *
  16502. * \note CSR attributes (if any) are currently silently ignored.
  16503. *
  16504. * \param csr CSR context to fill
  16505. * \param buf buffer holding the CRL data
  16506. * \param buflen size of the buffer
  16507. *
  16508. * \return 0 if successful, or a specific X509 error code
  16509. */
  16510. int mbedtls_x509_csr_parse_der( mbedtls_x509_csr *csr,
  16511. const unsigned char *buf, size_t buflen );
  16512. /**
  16513. * \brief Load a Certificate Signing Request (CSR), DER or PEM format
  16514. *
  16515. * \note See notes for \c mbedtls_x509_csr_parse_der()
  16516. *
  16517. * \param csr CSR context to fill
  16518. * \param buf buffer holding the CRL data
  16519. * \param buflen size of the buffer
  16520. * (including the terminating null byte for PEM data)
  16521. *
  16522. * \return 0 if successful, or a specific X509 or PEM error code
  16523. */
  16524. int mbedtls_x509_csr_parse( mbedtls_x509_csr *csr, const unsigned char *buf, size_t buflen );
  16525. #if defined(MBEDTLS_FS_IO)
  16526. /**
  16527. * \brief Load a Certificate Signing Request (CSR)
  16528. *
  16529. * \note See notes for \c mbedtls_x509_csr_parse()
  16530. *
  16531. * \param csr CSR context to fill
  16532. * \param path filename to read the CSR from
  16533. *
  16534. * \return 0 if successful, or a specific X509 or PEM error code
  16535. */
  16536. int mbedtls_x509_csr_parse_file( mbedtls_x509_csr *csr, const char *path );
  16537. #endif /* MBEDTLS_FS_IO */
  16538. /**
  16539. * \brief Returns an informational string about the
  16540. * CSR.
  16541. *
  16542. * \param buf Buffer to write to
  16543. * \param size Maximum size of buffer
  16544. * \param prefix A line prefix
  16545. * \param csr The X509 CSR to represent
  16546. *
  16547. * \return The length of the string written (not including the
  16548. * terminated nul byte), or a negative error code.
  16549. */
  16550. int mbedtls_x509_csr_info( char *buf, size_t size, const char *prefix,
  16551. const mbedtls_x509_csr *csr );
  16552. /**
  16553. * \brief Initialize a CSR
  16554. *
  16555. * \param csr CSR to initialize
  16556. */
  16557. void mbedtls_x509_csr_init( mbedtls_x509_csr *csr );
  16558. /**
  16559. * \brief Unallocate all CSR data
  16560. *
  16561. * \param csr CSR to free
  16562. */
  16563. void mbedtls_x509_csr_free( mbedtls_x509_csr *csr );
  16564. #endif /* MBEDTLS_X509_CSR_PARSE_C */
  16565. /* \} name */
  16566. /* \} addtogroup x509_module */
  16567. #if defined(MBEDTLS_X509_CSR_WRITE_C)
  16568. /**
  16569. * \brief Initialize a CSR context
  16570. *
  16571. * \param ctx CSR context to initialize
  16572. */
  16573. void mbedtls_x509write_csr_init( mbedtls_x509write_csr *ctx );
  16574. /**
  16575. * \brief Set the subject name for a CSR
  16576. * Subject names should contain a comma-separated list
  16577. * of OID types and values:
  16578. * e.g. "C=UK,O=ARM,CN=mbed TLS Server 1"
  16579. *
  16580. * \param ctx CSR context to use
  16581. * \param subject_name subject name to set
  16582. *
  16583. * \return 0 if subject name was parsed successfully, or
  16584. * a specific error code
  16585. */
  16586. int mbedtls_x509write_csr_set_subject_name( mbedtls_x509write_csr *ctx,
  16587. const char *subject_name );
  16588. /**
  16589. * \brief Set the key for a CSR (public key will be included,
  16590. * private key used to sign the CSR when writing it)
  16591. *
  16592. * \param ctx CSR context to use
  16593. * \param key Asymetric key to include
  16594. */
  16595. void mbedtls_x509write_csr_set_key( mbedtls_x509write_csr *ctx, mbedtls_pk_context *key );
  16596. /**
  16597. * \brief Set the MD algorithm to use for the signature
  16598. * (e.g. MBEDTLS_MD_SHA1)
  16599. *
  16600. * \param ctx CSR context to use
  16601. * \param md_alg MD algorithm to use
  16602. */
  16603. void mbedtls_x509write_csr_set_md_alg( mbedtls_x509write_csr *ctx, mbedtls_md_type_t md_alg );
  16604. /**
  16605. * \brief Set the Key Usage Extension flags
  16606. * (e.g. MBEDTLS_X509_KU_DIGITAL_SIGNATURE | MBEDTLS_X509_KU_KEY_CERT_SIGN)
  16607. *
  16608. * \param ctx CSR context to use
  16609. * \param key_usage key usage flags to set
  16610. *
  16611. * \return 0 if successful, or MBEDTLS_ERR_X509_ALLOC_FAILED
  16612. *
  16613. * \note The <code>decipherOnly</code> flag from the Key Usage
  16614. * extension is represented by bit 8 (i.e.
  16615. * <code>0x8000</code>), which cannot typically be represented
  16616. * in an unsigned char. Therefore, the flag
  16617. * <code>decipherOnly</code> (i.e.
  16618. * #MBEDTLS_X509_KU_DECIPHER_ONLY) cannot be set using this
  16619. * function.
  16620. */
  16621. int mbedtls_x509write_csr_set_key_usage( mbedtls_x509write_csr *ctx, unsigned char key_usage );
  16622. /**
  16623. * \brief Set the Netscape Cert Type flags
  16624. * (e.g. MBEDTLS_X509_NS_CERT_TYPE_SSL_CLIENT | MBEDTLS_X509_NS_CERT_TYPE_EMAIL)
  16625. *
  16626. * \param ctx CSR context to use
  16627. * \param ns_cert_type Netscape Cert Type flags to set
  16628. *
  16629. * \return 0 if successful, or MBEDTLS_ERR_X509_ALLOC_FAILED
  16630. */
  16631. int mbedtls_x509write_csr_set_ns_cert_type( mbedtls_x509write_csr *ctx,
  16632. unsigned char ns_cert_type );
  16633. /**
  16634. * \brief Generic function to add to or replace an extension in the
  16635. * CSR
  16636. *
  16637. * \param ctx CSR context to use
  16638. * \param oid OID of the extension
  16639. * \param oid_len length of the OID
  16640. * \param val value of the extension OCTET STRING
  16641. * \param val_len length of the value data
  16642. *
  16643. * \return 0 if successful, or a MBEDTLS_ERR_X509_ALLOC_FAILED
  16644. */
  16645. int mbedtls_x509write_csr_set_extension( mbedtls_x509write_csr *ctx,
  16646. const char *oid, size_t oid_len,
  16647. const unsigned char *val, size_t val_len );
  16648. /**
  16649. * \brief Free the contents of a CSR context
  16650. *
  16651. * \param ctx CSR context to free
  16652. */
  16653. void mbedtls_x509write_csr_free( mbedtls_x509write_csr *ctx );
  16654. /**
  16655. * \brief Write a CSR (Certificate Signing Request) to a
  16656. * DER structure
  16657. * Note: data is written at the end of the buffer! Use the
  16658. * return value to determine where you should start
  16659. * using the buffer
  16660. *
  16661. * \param ctx CSR to write away
  16662. * \param buf buffer to write to
  16663. * \param size size of the buffer
  16664. * \param f_rng RNG function (for signature, see note)
  16665. * \param p_rng RNG parameter
  16666. *
  16667. * \return length of data written if successful, or a specific
  16668. * error code
  16669. *
  16670. * \note f_rng may be NULL if RSA is used for signature and the
  16671. * signature is made offline (otherwise f_rng is desirable
  16672. * for countermeasures against timing attacks).
  16673. * ECDSA signatures always require a non-NULL f_rng.
  16674. */
  16675. int mbedtls_x509write_csr_der( mbedtls_x509write_csr *ctx, unsigned char *buf, size_t size,
  16676. int (*f_rng)(void *, unsigned char *, size_t),
  16677. void *p_rng );
  16678. #if defined(MBEDTLS_PEM_WRITE_C)
  16679. /**
  16680. * \brief Write a CSR (Certificate Signing Request) to a
  16681. * PEM string
  16682. *
  16683. * \param ctx CSR to write away
  16684. * \param buf buffer to write to
  16685. * \param size size of the buffer
  16686. * \param f_rng RNG function (for signature, see note)
  16687. * \param p_rng RNG parameter
  16688. *
  16689. * \return 0 if successful, or a specific error code
  16690. *
  16691. * \note f_rng may be NULL if RSA is used for signature and the
  16692. * signature is made offline (otherwise f_rng is desirable
  16693. * for countermeasures against timing attacks).
  16694. * ECDSA signatures always require a non-NULL f_rng.
  16695. */
  16696. int mbedtls_x509write_csr_pem( mbedtls_x509write_csr *ctx, unsigned char *buf, size_t size,
  16697. int (*f_rng)(void *, unsigned char *, size_t),
  16698. void *p_rng );
  16699. #endif /* MBEDTLS_PEM_WRITE_C */
  16700. #endif /* MBEDTLS_X509_CSR_WRITE_C */
  16701. #ifdef __cplusplus
  16702. }
  16703. #endif
  16704. #endif /* mbedtls_x509_csr.h */
  16705. /********* Start of file include/mbedtls/cipher.h ************/
  16706. /**
  16707. * \file cipher.h
  16708. *
  16709. * \brief This file contains an abstraction interface for use with the cipher
  16710. * primitives provided by the library. It provides a common interface to all of
  16711. * the available cipher operations.
  16712. *
  16713. * \author Adriaan de Jong <dejong@fox-it.com>
  16714. */
  16715. /*
  16716. * Copyright The Mbed TLS Contributors
  16717. * SPDX-License-Identifier: Apache-2.0
  16718. *
  16719. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  16720. * not use this file except in compliance with the License.
  16721. * You may obtain a copy of the License at
  16722. *
  16723. * http://www.apache.org/licenses/LICENSE-2.0
  16724. *
  16725. * Unless required by applicable law or agreed to in writing, software
  16726. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  16727. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  16728. * See the License for the specific language governing permissions and
  16729. * limitations under the License.
  16730. */
  16731. #ifndef MBEDTLS_CIPHER_H
  16732. #define MBEDTLS_CIPHER_H
  16733. #if !defined(MBEDTLS_CONFIG_FILE)
  16734. #else
  16735. #endif
  16736. #include <stddef.h>
  16737. #if defined(MBEDTLS_GCM_C) || defined(MBEDTLS_CCM_C) || defined(MBEDTLS_CHACHAPOLY_C)
  16738. #define MBEDTLS_CIPHER_MODE_AEAD
  16739. #endif
  16740. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  16741. #define MBEDTLS_CIPHER_MODE_WITH_PADDING
  16742. #endif
  16743. #if defined(MBEDTLS_ARC4_C) || defined(MBEDTLS_CIPHER_NULL_CIPHER) || \
  16744. defined(MBEDTLS_CHACHA20_C)
  16745. #define MBEDTLS_CIPHER_MODE_STREAM
  16746. #endif
  16747. #if ( defined(__ARMCC_VERSION) || defined(_MSC_VER) ) && \
  16748. !defined(inline) && !defined(__cplusplus)
  16749. #define inline __inline
  16750. #endif
  16751. /** The selected feature is not available. */
  16752. #define MBEDTLS_ERR_CIPHER_FEATURE_UNAVAILABLE -0x6080
  16753. /** Bad input parameters. */
  16754. #define MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA -0x6100
  16755. /** Failed to allocate memory. */
  16756. #define MBEDTLS_ERR_CIPHER_ALLOC_FAILED -0x6180
  16757. /** Input data contains invalid padding and is rejected. */
  16758. #define MBEDTLS_ERR_CIPHER_INVALID_PADDING -0x6200
  16759. /** Decryption of block requires a full block. */
  16760. #define MBEDTLS_ERR_CIPHER_FULL_BLOCK_EXPECTED -0x6280
  16761. /** Authentication failed (for AEAD modes). */
  16762. #define MBEDTLS_ERR_CIPHER_AUTH_FAILED -0x6300
  16763. /** The context is invalid. For example, because it was freed. */
  16764. #define MBEDTLS_ERR_CIPHER_INVALID_CONTEXT -0x6380
  16765. /* MBEDTLS_ERR_CIPHER_HW_ACCEL_FAILED is deprecated and should not be used. */
  16766. /** Cipher hardware accelerator failed. */
  16767. #define MBEDTLS_ERR_CIPHER_HW_ACCEL_FAILED -0x6400
  16768. #define MBEDTLS_CIPHER_VARIABLE_IV_LEN 0x01 /**< Cipher accepts IVs of variable length. */
  16769. #define MBEDTLS_CIPHER_VARIABLE_KEY_LEN 0x02 /**< Cipher accepts keys of variable length. */
  16770. #ifdef __cplusplus
  16771. extern "C" {
  16772. #endif
  16773. /**
  16774. * \brief Supported cipher types.
  16775. *
  16776. * \warning RC4 and DES are considered weak ciphers and their use
  16777. * constitutes a security risk. Arm recommends considering stronger
  16778. * ciphers instead.
  16779. */
  16780. typedef enum {
  16781. MBEDTLS_CIPHER_ID_NONE = 0, /**< Placeholder to mark the end of cipher ID lists. */
  16782. MBEDTLS_CIPHER_ID_NULL, /**< The identity cipher, treated as a stream cipher. */
  16783. MBEDTLS_CIPHER_ID_AES, /**< The AES cipher. */
  16784. MBEDTLS_CIPHER_ID_DES, /**< The DES cipher. */
  16785. MBEDTLS_CIPHER_ID_3DES, /**< The Triple DES cipher. */
  16786. MBEDTLS_CIPHER_ID_CAMELLIA, /**< The Camellia cipher. */
  16787. MBEDTLS_CIPHER_ID_BLOWFISH, /**< The Blowfish cipher. */
  16788. MBEDTLS_CIPHER_ID_ARC4, /**< The RC4 cipher. */
  16789. MBEDTLS_CIPHER_ID_ARIA, /**< The Aria cipher. */
  16790. MBEDTLS_CIPHER_ID_CHACHA20, /**< The ChaCha20 cipher. */
  16791. } mbedtls_cipher_id_t;
  16792. /**
  16793. * \brief Supported {cipher type, cipher mode} pairs.
  16794. *
  16795. * \warning RC4 and DES are considered weak ciphers and their use
  16796. * constitutes a security risk. Arm recommends considering stronger
  16797. * ciphers instead.
  16798. */
  16799. typedef enum {
  16800. MBEDTLS_CIPHER_NONE = 0, /**< Placeholder to mark the end of cipher-pair lists. */
  16801. MBEDTLS_CIPHER_NULL, /**< The identity stream cipher. */
  16802. MBEDTLS_CIPHER_AES_128_ECB, /**< AES cipher with 128-bit ECB mode. */
  16803. MBEDTLS_CIPHER_AES_192_ECB, /**< AES cipher with 192-bit ECB mode. */
  16804. MBEDTLS_CIPHER_AES_256_ECB, /**< AES cipher with 256-bit ECB mode. */
  16805. MBEDTLS_CIPHER_AES_128_CBC, /**< AES cipher with 128-bit CBC mode. */
  16806. MBEDTLS_CIPHER_AES_192_CBC, /**< AES cipher with 192-bit CBC mode. */
  16807. MBEDTLS_CIPHER_AES_256_CBC, /**< AES cipher with 256-bit CBC mode. */
  16808. MBEDTLS_CIPHER_AES_128_CFB128, /**< AES cipher with 128-bit CFB128 mode. */
  16809. MBEDTLS_CIPHER_AES_192_CFB128, /**< AES cipher with 192-bit CFB128 mode. */
  16810. MBEDTLS_CIPHER_AES_256_CFB128, /**< AES cipher with 256-bit CFB128 mode. */
  16811. MBEDTLS_CIPHER_AES_128_CTR, /**< AES cipher with 128-bit CTR mode. */
  16812. MBEDTLS_CIPHER_AES_192_CTR, /**< AES cipher with 192-bit CTR mode. */
  16813. MBEDTLS_CIPHER_AES_256_CTR, /**< AES cipher with 256-bit CTR mode. */
  16814. MBEDTLS_CIPHER_AES_128_GCM, /**< AES cipher with 128-bit GCM mode. */
  16815. MBEDTLS_CIPHER_AES_192_GCM, /**< AES cipher with 192-bit GCM mode. */
  16816. MBEDTLS_CIPHER_AES_256_GCM, /**< AES cipher with 256-bit GCM mode. */
  16817. MBEDTLS_CIPHER_CAMELLIA_128_ECB, /**< Camellia cipher with 128-bit ECB mode. */
  16818. MBEDTLS_CIPHER_CAMELLIA_192_ECB, /**< Camellia cipher with 192-bit ECB mode. */
  16819. MBEDTLS_CIPHER_CAMELLIA_256_ECB, /**< Camellia cipher with 256-bit ECB mode. */
  16820. MBEDTLS_CIPHER_CAMELLIA_128_CBC, /**< Camellia cipher with 128-bit CBC mode. */
  16821. MBEDTLS_CIPHER_CAMELLIA_192_CBC, /**< Camellia cipher with 192-bit CBC mode. */
  16822. MBEDTLS_CIPHER_CAMELLIA_256_CBC, /**< Camellia cipher with 256-bit CBC mode. */
  16823. MBEDTLS_CIPHER_CAMELLIA_128_CFB128, /**< Camellia cipher with 128-bit CFB128 mode. */
  16824. MBEDTLS_CIPHER_CAMELLIA_192_CFB128, /**< Camellia cipher with 192-bit CFB128 mode. */
  16825. MBEDTLS_CIPHER_CAMELLIA_256_CFB128, /**< Camellia cipher with 256-bit CFB128 mode. */
  16826. MBEDTLS_CIPHER_CAMELLIA_128_CTR, /**< Camellia cipher with 128-bit CTR mode. */
  16827. MBEDTLS_CIPHER_CAMELLIA_192_CTR, /**< Camellia cipher with 192-bit CTR mode. */
  16828. MBEDTLS_CIPHER_CAMELLIA_256_CTR, /**< Camellia cipher with 256-bit CTR mode. */
  16829. MBEDTLS_CIPHER_CAMELLIA_128_GCM, /**< Camellia cipher with 128-bit GCM mode. */
  16830. MBEDTLS_CIPHER_CAMELLIA_192_GCM, /**< Camellia cipher with 192-bit GCM mode. */
  16831. MBEDTLS_CIPHER_CAMELLIA_256_GCM, /**< Camellia cipher with 256-bit GCM mode. */
  16832. MBEDTLS_CIPHER_DES_ECB, /**< DES cipher with ECB mode. */
  16833. MBEDTLS_CIPHER_DES_CBC, /**< DES cipher with CBC mode. */
  16834. MBEDTLS_CIPHER_DES_EDE_ECB, /**< DES cipher with EDE ECB mode. */
  16835. MBEDTLS_CIPHER_DES_EDE_CBC, /**< DES cipher with EDE CBC mode. */
  16836. MBEDTLS_CIPHER_DES_EDE3_ECB, /**< DES cipher with EDE3 ECB mode. */
  16837. MBEDTLS_CIPHER_DES_EDE3_CBC, /**< DES cipher with EDE3 CBC mode. */
  16838. MBEDTLS_CIPHER_BLOWFISH_ECB, /**< Blowfish cipher with ECB mode. */
  16839. MBEDTLS_CIPHER_BLOWFISH_CBC, /**< Blowfish cipher with CBC mode. */
  16840. MBEDTLS_CIPHER_BLOWFISH_CFB64, /**< Blowfish cipher with CFB64 mode. */
  16841. MBEDTLS_CIPHER_BLOWFISH_CTR, /**< Blowfish cipher with CTR mode. */
  16842. MBEDTLS_CIPHER_ARC4_128, /**< RC4 cipher with 128-bit mode. */
  16843. MBEDTLS_CIPHER_AES_128_CCM, /**< AES cipher with 128-bit CCM mode. */
  16844. MBEDTLS_CIPHER_AES_192_CCM, /**< AES cipher with 192-bit CCM mode. */
  16845. MBEDTLS_CIPHER_AES_256_CCM, /**< AES cipher with 256-bit CCM mode. */
  16846. MBEDTLS_CIPHER_CAMELLIA_128_CCM, /**< Camellia cipher with 128-bit CCM mode. */
  16847. MBEDTLS_CIPHER_CAMELLIA_192_CCM, /**< Camellia cipher with 192-bit CCM mode. */
  16848. MBEDTLS_CIPHER_CAMELLIA_256_CCM, /**< Camellia cipher with 256-bit CCM mode. */
  16849. MBEDTLS_CIPHER_ARIA_128_ECB, /**< Aria cipher with 128-bit key and ECB mode. */
  16850. MBEDTLS_CIPHER_ARIA_192_ECB, /**< Aria cipher with 192-bit key and ECB mode. */
  16851. MBEDTLS_CIPHER_ARIA_256_ECB, /**< Aria cipher with 256-bit key and ECB mode. */
  16852. MBEDTLS_CIPHER_ARIA_128_CBC, /**< Aria cipher with 128-bit key and CBC mode. */
  16853. MBEDTLS_CIPHER_ARIA_192_CBC, /**< Aria cipher with 192-bit key and CBC mode. */
  16854. MBEDTLS_CIPHER_ARIA_256_CBC, /**< Aria cipher with 256-bit key and CBC mode. */
  16855. MBEDTLS_CIPHER_ARIA_128_CFB128, /**< Aria cipher with 128-bit key and CFB-128 mode. */
  16856. MBEDTLS_CIPHER_ARIA_192_CFB128, /**< Aria cipher with 192-bit key and CFB-128 mode. */
  16857. MBEDTLS_CIPHER_ARIA_256_CFB128, /**< Aria cipher with 256-bit key and CFB-128 mode. */
  16858. MBEDTLS_CIPHER_ARIA_128_CTR, /**< Aria cipher with 128-bit key and CTR mode. */
  16859. MBEDTLS_CIPHER_ARIA_192_CTR, /**< Aria cipher with 192-bit key and CTR mode. */
  16860. MBEDTLS_CIPHER_ARIA_256_CTR, /**< Aria cipher with 256-bit key and CTR mode. */
  16861. MBEDTLS_CIPHER_ARIA_128_GCM, /**< Aria cipher with 128-bit key and GCM mode. */
  16862. MBEDTLS_CIPHER_ARIA_192_GCM, /**< Aria cipher with 192-bit key and GCM mode. */
  16863. MBEDTLS_CIPHER_ARIA_256_GCM, /**< Aria cipher with 256-bit key and GCM mode. */
  16864. MBEDTLS_CIPHER_ARIA_128_CCM, /**< Aria cipher with 128-bit key and CCM mode. */
  16865. MBEDTLS_CIPHER_ARIA_192_CCM, /**< Aria cipher with 192-bit key and CCM mode. */
  16866. MBEDTLS_CIPHER_ARIA_256_CCM, /**< Aria cipher with 256-bit key and CCM mode. */
  16867. MBEDTLS_CIPHER_AES_128_OFB, /**< AES 128-bit cipher in OFB mode. */
  16868. MBEDTLS_CIPHER_AES_192_OFB, /**< AES 192-bit cipher in OFB mode. */
  16869. MBEDTLS_CIPHER_AES_256_OFB, /**< AES 256-bit cipher in OFB mode. */
  16870. MBEDTLS_CIPHER_AES_128_XTS, /**< AES 128-bit cipher in XTS block mode. */
  16871. MBEDTLS_CIPHER_AES_256_XTS, /**< AES 256-bit cipher in XTS block mode. */
  16872. MBEDTLS_CIPHER_CHACHA20, /**< ChaCha20 stream cipher. */
  16873. MBEDTLS_CIPHER_CHACHA20_POLY1305, /**< ChaCha20-Poly1305 AEAD cipher. */
  16874. MBEDTLS_CIPHER_AES_128_KW, /**< AES cipher with 128-bit NIST KW mode. */
  16875. MBEDTLS_CIPHER_AES_192_KW, /**< AES cipher with 192-bit NIST KW mode. */
  16876. MBEDTLS_CIPHER_AES_256_KW, /**< AES cipher with 256-bit NIST KW mode. */
  16877. MBEDTLS_CIPHER_AES_128_KWP, /**< AES cipher with 128-bit NIST KWP mode. */
  16878. MBEDTLS_CIPHER_AES_192_KWP, /**< AES cipher with 192-bit NIST KWP mode. */
  16879. MBEDTLS_CIPHER_AES_256_KWP, /**< AES cipher with 256-bit NIST KWP mode. */
  16880. } mbedtls_cipher_type_t;
  16881. /** Supported cipher modes. */
  16882. typedef enum {
  16883. MBEDTLS_MODE_NONE = 0, /**< None. */
  16884. MBEDTLS_MODE_ECB, /**< The ECB cipher mode. */
  16885. MBEDTLS_MODE_CBC, /**< The CBC cipher mode. */
  16886. MBEDTLS_MODE_CFB, /**< The CFB cipher mode. */
  16887. MBEDTLS_MODE_OFB, /**< The OFB cipher mode. */
  16888. MBEDTLS_MODE_CTR, /**< The CTR cipher mode. */
  16889. MBEDTLS_MODE_GCM, /**< The GCM cipher mode. */
  16890. MBEDTLS_MODE_STREAM, /**< The stream cipher mode. */
  16891. MBEDTLS_MODE_CCM, /**< The CCM cipher mode. */
  16892. MBEDTLS_MODE_XTS, /**< The XTS cipher mode. */
  16893. MBEDTLS_MODE_CHACHAPOLY, /**< The ChaCha-Poly cipher mode. */
  16894. MBEDTLS_MODE_KW, /**< The SP800-38F KW mode */
  16895. MBEDTLS_MODE_KWP, /**< The SP800-38F KWP mode */
  16896. } mbedtls_cipher_mode_t;
  16897. /** Supported cipher padding types. */
  16898. typedef enum {
  16899. MBEDTLS_PADDING_PKCS7 = 0, /**< PKCS7 padding (default). */
  16900. MBEDTLS_PADDING_ONE_AND_ZEROS, /**< ISO/IEC 7816-4 padding. */
  16901. MBEDTLS_PADDING_ZEROS_AND_LEN, /**< ANSI X.923 padding. */
  16902. MBEDTLS_PADDING_ZEROS, /**< Zero padding (not reversible). */
  16903. MBEDTLS_PADDING_NONE, /**< Never pad (full blocks only). */
  16904. } mbedtls_cipher_padding_t;
  16905. /** Type of operation. */
  16906. typedef enum {
  16907. MBEDTLS_OPERATION_NONE = -1,
  16908. MBEDTLS_DECRYPT = 0,
  16909. MBEDTLS_ENCRYPT,
  16910. } mbedtls_operation_t;
  16911. enum {
  16912. /** Undefined key length. */
  16913. MBEDTLS_KEY_LENGTH_NONE = 0,
  16914. /** Key length, in bits (including parity), for DES keys. */
  16915. MBEDTLS_KEY_LENGTH_DES = 64,
  16916. /** Key length in bits, including parity, for DES in two-key EDE. */
  16917. MBEDTLS_KEY_LENGTH_DES_EDE = 128,
  16918. /** Key length in bits, including parity, for DES in three-key EDE. */
  16919. MBEDTLS_KEY_LENGTH_DES_EDE3 = 192,
  16920. };
  16921. /** Maximum length of any IV, in Bytes. */
  16922. /* This should ideally be derived automatically from list of ciphers.
  16923. * This should be kept in sync with MBEDTLS_SSL_MAX_IV_LENGTH defined
  16924. * in ssl_internal.h. */
  16925. #define MBEDTLS_MAX_IV_LENGTH 16
  16926. /** Maximum block size of any cipher, in Bytes. */
  16927. /* This should ideally be derived automatically from list of ciphers.
  16928. * This should be kept in sync with MBEDTLS_SSL_MAX_BLOCK_LENGTH defined
  16929. * in ssl_internal.h. */
  16930. #define MBEDTLS_MAX_BLOCK_LENGTH 16
  16931. /** Maximum key length, in Bytes. */
  16932. /* This should ideally be derived automatically from list of ciphers.
  16933. * For now, only check whether XTS is enabled which uses 64 Byte keys,
  16934. * and use 32 Bytes as an upper bound for the maximum key length otherwise.
  16935. * This should be kept in sync with MBEDTLS_SSL_MAX_BLOCK_LENGTH defined
  16936. * in ssl_internal.h, which however deliberately ignores the case of XTS
  16937. * since the latter isn't used in SSL/TLS. */
  16938. #if defined(MBEDTLS_CIPHER_MODE_XTS)
  16939. #define MBEDTLS_MAX_KEY_LENGTH 64
  16940. #else
  16941. #define MBEDTLS_MAX_KEY_LENGTH 32
  16942. #endif /* MBEDTLS_CIPHER_MODE_XTS */
  16943. /**
  16944. * Base cipher information (opaque struct).
  16945. */
  16946. typedef struct mbedtls_cipher_base_t mbedtls_cipher_base_t;
  16947. /**
  16948. * CMAC context (opaque struct).
  16949. */
  16950. typedef struct mbedtls_cmac_context_t mbedtls_cmac_context_t;
  16951. /**
  16952. * Cipher information. Allows calling cipher functions
  16953. * in a generic way.
  16954. */
  16955. typedef struct mbedtls_cipher_info_t
  16956. {
  16957. /** Full cipher identifier. For example,
  16958. * MBEDTLS_CIPHER_AES_256_CBC.
  16959. */
  16960. mbedtls_cipher_type_t type;
  16961. /** The cipher mode. For example, MBEDTLS_MODE_CBC. */
  16962. mbedtls_cipher_mode_t mode;
  16963. /** The cipher key length, in bits. This is the
  16964. * default length for variable sized ciphers.
  16965. * Includes parity bits for ciphers like DES.
  16966. */
  16967. unsigned int key_bitlen;
  16968. /** Name of the cipher. */
  16969. const char * name;
  16970. /** IV or nonce size, in Bytes.
  16971. * For ciphers that accept variable IV sizes,
  16972. * this is the recommended size.
  16973. */
  16974. unsigned int iv_size;
  16975. /** Bitflag comprised of MBEDTLS_CIPHER_VARIABLE_IV_LEN and
  16976. * MBEDTLS_CIPHER_VARIABLE_KEY_LEN indicating whether the
  16977. * cipher supports variable IV or variable key sizes, respectively.
  16978. */
  16979. int flags;
  16980. /** The block size, in Bytes. */
  16981. unsigned int block_size;
  16982. /** Struct for base cipher information and functions. */
  16983. const mbedtls_cipher_base_t *base;
  16984. } mbedtls_cipher_info_t;
  16985. /**
  16986. * Generic cipher context.
  16987. */
  16988. typedef struct mbedtls_cipher_context_t
  16989. {
  16990. /** Information about the associated cipher. */
  16991. const mbedtls_cipher_info_t *cipher_info;
  16992. /** Key length to use. */
  16993. int key_bitlen;
  16994. /** Operation that the key of the context has been
  16995. * initialized for.
  16996. */
  16997. mbedtls_operation_t operation;
  16998. #if defined(MBEDTLS_CIPHER_MODE_WITH_PADDING)
  16999. /** Padding functions to use, if relevant for
  17000. * the specific cipher mode.
  17001. */
  17002. void (*add_padding)( unsigned char *output, size_t olen, size_t data_len );
  17003. int (*get_padding)( unsigned char *input, size_t ilen, size_t *data_len );
  17004. #endif
  17005. /** Buffer for input that has not been processed yet. */
  17006. unsigned char unprocessed_data[MBEDTLS_MAX_BLOCK_LENGTH];
  17007. /** Number of Bytes that have not been processed yet. */
  17008. size_t unprocessed_len;
  17009. /** Current IV or NONCE_COUNTER for CTR-mode, data unit (or sector) number
  17010. * for XTS-mode. */
  17011. unsigned char iv[MBEDTLS_MAX_IV_LENGTH];
  17012. /** IV size in Bytes, for ciphers with variable-length IVs. */
  17013. size_t iv_size;
  17014. /** The cipher-specific context. */
  17015. void *cipher_ctx;
  17016. #if defined(MBEDTLS_CMAC_C)
  17017. /** CMAC-specific context. */
  17018. mbedtls_cmac_context_t *cmac_ctx;
  17019. #endif
  17020. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  17021. /** Indicates whether the cipher operations should be performed
  17022. * by Mbed TLS' own crypto library or an external implementation
  17023. * of the PSA Crypto API.
  17024. * This is unset if the cipher context was established through
  17025. * mbedtls_cipher_setup(), and set if it was established through
  17026. * mbedtls_cipher_setup_psa().
  17027. */
  17028. unsigned char psa_enabled;
  17029. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  17030. } mbedtls_cipher_context_t;
  17031. /**
  17032. * \brief This function retrieves the list of ciphers supported
  17033. * by the generic cipher module.
  17034. *
  17035. * For any cipher identifier in the returned list, you can
  17036. * obtain the corresponding generic cipher information structure
  17037. * via mbedtls_cipher_info_from_type(), which can then be used
  17038. * to prepare a cipher context via mbedtls_cipher_setup().
  17039. *
  17040. *
  17041. * \return A statically-allocated array of cipher identifiers
  17042. * of type cipher_type_t. The last entry is zero.
  17043. */
  17044. const int *mbedtls_cipher_list( void );
  17045. /**
  17046. * \brief This function retrieves the cipher-information
  17047. * structure associated with the given cipher name.
  17048. *
  17049. * \param cipher_name Name of the cipher to search for. This must not be
  17050. * \c NULL.
  17051. *
  17052. * \return The cipher information structure associated with the
  17053. * given \p cipher_name.
  17054. * \return \c NULL if the associated cipher information is not found.
  17055. */
  17056. const mbedtls_cipher_info_t *mbedtls_cipher_info_from_string( const char *cipher_name );
  17057. /**
  17058. * \brief This function retrieves the cipher-information
  17059. * structure associated with the given cipher type.
  17060. *
  17061. * \param cipher_type Type of the cipher to search for.
  17062. *
  17063. * \return The cipher information structure associated with the
  17064. * given \p cipher_type.
  17065. * \return \c NULL if the associated cipher information is not found.
  17066. */
  17067. const mbedtls_cipher_info_t *mbedtls_cipher_info_from_type( const mbedtls_cipher_type_t cipher_type );
  17068. /**
  17069. * \brief This function retrieves the cipher-information
  17070. * structure associated with the given cipher ID,
  17071. * key size and mode.
  17072. *
  17073. * \param cipher_id The ID of the cipher to search for. For example,
  17074. * #MBEDTLS_CIPHER_ID_AES.
  17075. * \param key_bitlen The length of the key in bits.
  17076. * \param mode The cipher mode. For example, #MBEDTLS_MODE_CBC.
  17077. *
  17078. * \return The cipher information structure associated with the
  17079. * given \p cipher_id.
  17080. * \return \c NULL if the associated cipher information is not found.
  17081. */
  17082. const mbedtls_cipher_info_t *mbedtls_cipher_info_from_values( const mbedtls_cipher_id_t cipher_id,
  17083. int key_bitlen,
  17084. const mbedtls_cipher_mode_t mode );
  17085. /**
  17086. * \brief This function initializes a \p cipher_context as NONE.
  17087. *
  17088. * \param ctx The context to be initialized. This must not be \c NULL.
  17089. */
  17090. void mbedtls_cipher_init( mbedtls_cipher_context_t *ctx );
  17091. /**
  17092. * \brief This function frees and clears the cipher-specific
  17093. * context of \p ctx. Freeing \p ctx itself remains the
  17094. * responsibility of the caller.
  17095. *
  17096. * \param ctx The context to be freed. If this is \c NULL, the
  17097. * function has no effect, otherwise this must point to an
  17098. * initialized context.
  17099. */
  17100. void mbedtls_cipher_free( mbedtls_cipher_context_t *ctx );
  17101. /**
  17102. * \brief This function initializes a cipher context for
  17103. * use with the given cipher primitive.
  17104. *
  17105. * \param ctx The context to initialize. This must be initialized.
  17106. * \param cipher_info The cipher to use.
  17107. *
  17108. * \return \c 0 on success.
  17109. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17110. * parameter-verification failure.
  17111. * \return #MBEDTLS_ERR_CIPHER_ALLOC_FAILED if allocation of the
  17112. * cipher-specific context fails.
  17113. *
  17114. * \internal Currently, the function also clears the structure.
  17115. * In future versions, the caller will be required to call
  17116. * mbedtls_cipher_init() on the structure first.
  17117. */
  17118. int mbedtls_cipher_setup( mbedtls_cipher_context_t *ctx,
  17119. const mbedtls_cipher_info_t *cipher_info );
  17120. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  17121. /**
  17122. * \brief This function initializes a cipher context for
  17123. * PSA-based use with the given cipher primitive.
  17124. *
  17125. * \note See #MBEDTLS_USE_PSA_CRYPTO for information on PSA.
  17126. *
  17127. * \param ctx The context to initialize. May not be \c NULL.
  17128. * \param cipher_info The cipher to use.
  17129. * \param taglen For AEAD ciphers, the length in bytes of the
  17130. * authentication tag to use. Subsequent uses of
  17131. * mbedtls_cipher_auth_encrypt() or
  17132. * mbedtls_cipher_auth_decrypt() must provide
  17133. * the same tag length.
  17134. * For non-AEAD ciphers, the value must be \c 0.
  17135. *
  17136. * \return \c 0 on success.
  17137. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17138. * parameter-verification failure.
  17139. * \return #MBEDTLS_ERR_CIPHER_ALLOC_FAILED if allocation of the
  17140. * cipher-specific context fails.
  17141. */
  17142. int mbedtls_cipher_setup_psa( mbedtls_cipher_context_t *ctx,
  17143. const mbedtls_cipher_info_t *cipher_info,
  17144. size_t taglen );
  17145. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  17146. /**
  17147. * \brief This function returns the block size of the given cipher.
  17148. *
  17149. * \param ctx The context of the cipher. This must be initialized.
  17150. *
  17151. * \return The block size of the underlying cipher.
  17152. * \return \c 0 if \p ctx has not been initialized.
  17153. */
  17154. static inline unsigned int mbedtls_cipher_get_block_size(
  17155. const mbedtls_cipher_context_t *ctx )
  17156. {
  17157. MBEDTLS_INTERNAL_VALIDATE_RET( ctx != NULL, 0 );
  17158. if( ctx->cipher_info == NULL )
  17159. return 0;
  17160. return ctx->cipher_info->block_size;
  17161. }
  17162. /**
  17163. * \brief This function returns the mode of operation for
  17164. * the cipher. For example, MBEDTLS_MODE_CBC.
  17165. *
  17166. * \param ctx The context of the cipher. This must be initialized.
  17167. *
  17168. * \return The mode of operation.
  17169. * \return #MBEDTLS_MODE_NONE if \p ctx has not been initialized.
  17170. */
  17171. static inline mbedtls_cipher_mode_t mbedtls_cipher_get_cipher_mode(
  17172. const mbedtls_cipher_context_t *ctx )
  17173. {
  17174. MBEDTLS_INTERNAL_VALIDATE_RET( ctx != NULL, MBEDTLS_MODE_NONE );
  17175. if( ctx->cipher_info == NULL )
  17176. return MBEDTLS_MODE_NONE;
  17177. return ctx->cipher_info->mode;
  17178. }
  17179. /**
  17180. * \brief This function returns the size of the IV or nonce
  17181. * of the cipher, in Bytes.
  17182. *
  17183. * \param ctx The context of the cipher. This must be initialized.
  17184. *
  17185. * \return The recommended IV size if no IV has been set.
  17186. * \return \c 0 for ciphers not using an IV or a nonce.
  17187. * \return The actual size if an IV has been set.
  17188. */
  17189. static inline int mbedtls_cipher_get_iv_size(
  17190. const mbedtls_cipher_context_t *ctx )
  17191. {
  17192. MBEDTLS_INTERNAL_VALIDATE_RET( ctx != NULL, 0 );
  17193. if( ctx->cipher_info == NULL )
  17194. return 0;
  17195. if( ctx->iv_size != 0 )
  17196. return (int) ctx->iv_size;
  17197. return (int) ctx->cipher_info->iv_size;
  17198. }
  17199. /**
  17200. * \brief This function returns the type of the given cipher.
  17201. *
  17202. * \param ctx The context of the cipher. This must be initialized.
  17203. *
  17204. * \return The type of the cipher.
  17205. * \return #MBEDTLS_CIPHER_NONE if \p ctx has not been initialized.
  17206. */
  17207. static inline mbedtls_cipher_type_t mbedtls_cipher_get_type(
  17208. const mbedtls_cipher_context_t *ctx )
  17209. {
  17210. MBEDTLS_INTERNAL_VALIDATE_RET(
  17211. ctx != NULL, MBEDTLS_CIPHER_NONE );
  17212. if( ctx->cipher_info == NULL )
  17213. return MBEDTLS_CIPHER_NONE;
  17214. return ctx->cipher_info->type;
  17215. }
  17216. /**
  17217. * \brief This function returns the name of the given cipher
  17218. * as a string.
  17219. *
  17220. * \param ctx The context of the cipher. This must be initialized.
  17221. *
  17222. * \return The name of the cipher.
  17223. * \return NULL if \p ctx has not been not initialized.
  17224. */
  17225. static inline const char *mbedtls_cipher_get_name(
  17226. const mbedtls_cipher_context_t *ctx )
  17227. {
  17228. MBEDTLS_INTERNAL_VALIDATE_RET( ctx != NULL, 0 );
  17229. if( ctx->cipher_info == NULL )
  17230. return 0;
  17231. return ctx->cipher_info->name;
  17232. }
  17233. /**
  17234. * \brief This function returns the key length of the cipher.
  17235. *
  17236. * \param ctx The context of the cipher. This must be initialized.
  17237. *
  17238. * \return The key length of the cipher in bits.
  17239. * \return #MBEDTLS_KEY_LENGTH_NONE if ctx \p has not been
  17240. * initialized.
  17241. */
  17242. static inline int mbedtls_cipher_get_key_bitlen(
  17243. const mbedtls_cipher_context_t *ctx )
  17244. {
  17245. MBEDTLS_INTERNAL_VALIDATE_RET(
  17246. ctx != NULL, MBEDTLS_KEY_LENGTH_NONE );
  17247. if( ctx->cipher_info == NULL )
  17248. return MBEDTLS_KEY_LENGTH_NONE;
  17249. return (int) ctx->cipher_info->key_bitlen;
  17250. }
  17251. /**
  17252. * \brief This function returns the operation of the given cipher.
  17253. *
  17254. * \param ctx The context of the cipher. This must be initialized.
  17255. *
  17256. * \return The type of operation: #MBEDTLS_ENCRYPT or #MBEDTLS_DECRYPT.
  17257. * \return #MBEDTLS_OPERATION_NONE if \p ctx has not been initialized.
  17258. */
  17259. static inline mbedtls_operation_t mbedtls_cipher_get_operation(
  17260. const mbedtls_cipher_context_t *ctx )
  17261. {
  17262. MBEDTLS_INTERNAL_VALIDATE_RET(
  17263. ctx != NULL, MBEDTLS_OPERATION_NONE );
  17264. if( ctx->cipher_info == NULL )
  17265. return MBEDTLS_OPERATION_NONE;
  17266. return ctx->operation;
  17267. }
  17268. /**
  17269. * \brief This function sets the key to use with the given context.
  17270. *
  17271. * \param ctx The generic cipher context. This must be initialized and
  17272. * bound to a cipher information structure.
  17273. * \param key The key to use. This must be a readable buffer of at
  17274. * least \p key_bitlen Bits.
  17275. * \param key_bitlen The key length to use, in Bits.
  17276. * \param operation The operation that the key will be used for:
  17277. * #MBEDTLS_ENCRYPT or #MBEDTLS_DECRYPT.
  17278. *
  17279. * \return \c 0 on success.
  17280. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17281. * parameter-verification failure.
  17282. * \return A cipher-specific error code on failure.
  17283. */
  17284. int mbedtls_cipher_setkey( mbedtls_cipher_context_t *ctx,
  17285. const unsigned char *key,
  17286. int key_bitlen,
  17287. const mbedtls_operation_t operation );
  17288. #if defined(MBEDTLS_CIPHER_MODE_WITH_PADDING)
  17289. /**
  17290. * \brief This function sets the padding mode, for cipher modes
  17291. * that use padding.
  17292. *
  17293. * The default passing mode is PKCS7 padding.
  17294. *
  17295. * \param ctx The generic cipher context. This must be initialized and
  17296. * bound to a cipher information structure.
  17297. * \param mode The padding mode.
  17298. *
  17299. * \return \c 0 on success.
  17300. * \return #MBEDTLS_ERR_CIPHER_FEATURE_UNAVAILABLE
  17301. * if the selected padding mode is not supported.
  17302. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA if the cipher mode
  17303. * does not support padding.
  17304. */
  17305. int mbedtls_cipher_set_padding_mode( mbedtls_cipher_context_t *ctx,
  17306. mbedtls_cipher_padding_t mode );
  17307. #endif /* MBEDTLS_CIPHER_MODE_WITH_PADDING */
  17308. /**
  17309. * \brief This function sets the initialization vector (IV)
  17310. * or nonce.
  17311. *
  17312. * \note Some ciphers do not use IVs nor nonce. For these
  17313. * ciphers, this function has no effect.
  17314. *
  17315. * \param ctx The generic cipher context. This must be initialized and
  17316. * bound to a cipher information structure.
  17317. * \param iv The IV to use, or NONCE_COUNTER for CTR-mode ciphers. This
  17318. * must be a readable buffer of at least \p iv_len Bytes.
  17319. * \param iv_len The IV length for ciphers with variable-size IV.
  17320. * This parameter is discarded by ciphers with fixed-size IV.
  17321. *
  17322. * \return \c 0 on success.
  17323. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17324. * parameter-verification failure.
  17325. */
  17326. int mbedtls_cipher_set_iv( mbedtls_cipher_context_t *ctx,
  17327. const unsigned char *iv,
  17328. size_t iv_len );
  17329. /**
  17330. * \brief This function resets the cipher state.
  17331. *
  17332. * \param ctx The generic cipher context. This must be initialized.
  17333. *
  17334. * \return \c 0 on success.
  17335. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17336. * parameter-verification failure.
  17337. */
  17338. int mbedtls_cipher_reset( mbedtls_cipher_context_t *ctx );
  17339. #if defined(MBEDTLS_GCM_C) || defined(MBEDTLS_CHACHAPOLY_C)
  17340. /**
  17341. * \brief This function adds additional data for AEAD ciphers.
  17342. * Currently supported with GCM and ChaCha20+Poly1305.
  17343. * This must be called exactly once, after
  17344. * mbedtls_cipher_reset().
  17345. *
  17346. * \param ctx The generic cipher context. This must be initialized.
  17347. * \param ad The additional data to use. This must be a readable
  17348. * buffer of at least \p ad_len Bytes.
  17349. * \param ad_len The length of \p ad in Bytes.
  17350. *
  17351. * \return \c 0 on success.
  17352. * \return A specific error code on failure.
  17353. */
  17354. int mbedtls_cipher_update_ad( mbedtls_cipher_context_t *ctx,
  17355. const unsigned char *ad, size_t ad_len );
  17356. #endif /* MBEDTLS_GCM_C || MBEDTLS_CHACHAPOLY_C */
  17357. /**
  17358. * \brief The generic cipher update function. It encrypts or
  17359. * decrypts using the given cipher context. Writes as
  17360. * many block-sized blocks of data as possible to output.
  17361. * Any data that cannot be written immediately is either
  17362. * added to the next block, or flushed when
  17363. * mbedtls_cipher_finish() is called.
  17364. * Exception: For MBEDTLS_MODE_ECB, expects a single block
  17365. * in size. For example, 16 Bytes for AES.
  17366. *
  17367. * \note If the underlying cipher is used in GCM mode, all calls
  17368. * to this function, except for the last one before
  17369. * mbedtls_cipher_finish(), must have \p ilen as a
  17370. * multiple of the block size of the cipher.
  17371. *
  17372. * \param ctx The generic cipher context. This must be initialized and
  17373. * bound to a key.
  17374. * \param input The buffer holding the input data. This must be a
  17375. * readable buffer of at least \p ilen Bytes.
  17376. * \param ilen The length of the input data.
  17377. * \param output The buffer for the output data. This must be able to
  17378. * hold at least `ilen + block_size`. This must not be the
  17379. * same buffer as \p input.
  17380. * \param olen The length of the output data, to be updated with the
  17381. * actual number of Bytes written. This must not be
  17382. * \c NULL.
  17383. *
  17384. * \return \c 0 on success.
  17385. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17386. * parameter-verification failure.
  17387. * \return #MBEDTLS_ERR_CIPHER_FEATURE_UNAVAILABLE on an
  17388. * unsupported mode for a cipher.
  17389. * \return A cipher-specific error code on failure.
  17390. */
  17391. int mbedtls_cipher_update( mbedtls_cipher_context_t *ctx,
  17392. const unsigned char *input,
  17393. size_t ilen, unsigned char *output,
  17394. size_t *olen );
  17395. /**
  17396. * \brief The generic cipher finalization function. If data still
  17397. * needs to be flushed from an incomplete block, the data
  17398. * contained in it is padded to the size of
  17399. * the last block, and written to the \p output buffer.
  17400. *
  17401. * \param ctx The generic cipher context. This must be initialized and
  17402. * bound to a key.
  17403. * \param output The buffer to write data to. This needs to be a writable
  17404. * buffer of at least \p block_size Bytes.
  17405. * \param olen The length of the data written to the \p output buffer.
  17406. * This may not be \c NULL.
  17407. *
  17408. * \return \c 0 on success.
  17409. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17410. * parameter-verification failure.
  17411. * \return #MBEDTLS_ERR_CIPHER_FULL_BLOCK_EXPECTED on decryption
  17412. * expecting a full block but not receiving one.
  17413. * \return #MBEDTLS_ERR_CIPHER_INVALID_PADDING on invalid padding
  17414. * while decrypting.
  17415. * \return A cipher-specific error code on failure.
  17416. */
  17417. int mbedtls_cipher_finish( mbedtls_cipher_context_t *ctx,
  17418. unsigned char *output, size_t *olen );
  17419. #if defined(MBEDTLS_GCM_C) || defined(MBEDTLS_CHACHAPOLY_C)
  17420. /**
  17421. * \brief This function writes a tag for AEAD ciphers.
  17422. * Currently supported with GCM and ChaCha20+Poly1305.
  17423. * This must be called after mbedtls_cipher_finish().
  17424. *
  17425. * \param ctx The generic cipher context. This must be initialized,
  17426. * bound to a key, and have just completed a cipher
  17427. * operation through mbedtls_cipher_finish() the tag for
  17428. * which should be written.
  17429. * \param tag The buffer to write the tag to. This must be a writable
  17430. * buffer of at least \p tag_len Bytes.
  17431. * \param tag_len The length of the tag to write.
  17432. *
  17433. * \return \c 0 on success.
  17434. * \return A specific error code on failure.
  17435. */
  17436. int mbedtls_cipher_write_tag( mbedtls_cipher_context_t *ctx,
  17437. unsigned char *tag, size_t tag_len );
  17438. /**
  17439. * \brief This function checks the tag for AEAD ciphers.
  17440. * Currently supported with GCM and ChaCha20+Poly1305.
  17441. * This must be called after mbedtls_cipher_finish().
  17442. *
  17443. * \param ctx The generic cipher context. This must be initialized.
  17444. * \param tag The buffer holding the tag. This must be a readable
  17445. * buffer of at least \p tag_len Bytes.
  17446. * \param tag_len The length of the tag to check.
  17447. *
  17448. * \return \c 0 on success.
  17449. * \return A specific error code on failure.
  17450. */
  17451. int mbedtls_cipher_check_tag( mbedtls_cipher_context_t *ctx,
  17452. const unsigned char *tag, size_t tag_len );
  17453. #endif /* MBEDTLS_GCM_C || MBEDTLS_CHACHAPOLY_C */
  17454. /**
  17455. * \brief The generic all-in-one encryption/decryption function,
  17456. * for all ciphers except AEAD constructs.
  17457. *
  17458. * \param ctx The generic cipher context. This must be initialized.
  17459. * \param iv The IV to use, or NONCE_COUNTER for CTR-mode ciphers.
  17460. * This must be a readable buffer of at least \p iv_len
  17461. * Bytes.
  17462. * \param iv_len The IV length for ciphers with variable-size IV.
  17463. * This parameter is discarded by ciphers with fixed-size
  17464. * IV.
  17465. * \param input The buffer holding the input data. This must be a
  17466. * readable buffer of at least \p ilen Bytes.
  17467. * \param ilen The length of the input data in Bytes.
  17468. * \param output The buffer for the output data. This must be able to
  17469. * hold at least `ilen + block_size`. This must not be the
  17470. * same buffer as \p input.
  17471. * \param olen The length of the output data, to be updated with the
  17472. * actual number of Bytes written. This must not be
  17473. * \c NULL.
  17474. *
  17475. * \note Some ciphers do not use IVs nor nonce. For these
  17476. * ciphers, use \p iv = NULL and \p iv_len = 0.
  17477. *
  17478. * \return \c 0 on success.
  17479. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17480. * parameter-verification failure.
  17481. * \return #MBEDTLS_ERR_CIPHER_FULL_BLOCK_EXPECTED on decryption
  17482. * expecting a full block but not receiving one.
  17483. * \return #MBEDTLS_ERR_CIPHER_INVALID_PADDING on invalid padding
  17484. * while decrypting.
  17485. * \return A cipher-specific error code on failure.
  17486. */
  17487. int mbedtls_cipher_crypt( mbedtls_cipher_context_t *ctx,
  17488. const unsigned char *iv, size_t iv_len,
  17489. const unsigned char *input, size_t ilen,
  17490. unsigned char *output, size_t *olen );
  17491. #if defined(MBEDTLS_CIPHER_MODE_AEAD)
  17492. #if ! defined(MBEDTLS_DEPRECATED_REMOVED)
  17493. #if defined(MBEDTLS_DEPRECATED_WARNING)
  17494. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  17495. #else
  17496. #define MBEDTLS_DEPRECATED
  17497. #endif /* MBEDTLS_DEPRECATED_WARNING */
  17498. /**
  17499. * \brief The generic authenticated encryption (AEAD) function.
  17500. *
  17501. * \deprecated Superseded by mbedtls_cipher_auth_encrypt_ext().
  17502. *
  17503. * \note This function only supports AEAD algorithms, not key
  17504. * wrapping algorithms such as NIST_KW; for this, see
  17505. * mbedtls_cipher_auth_encrypt_ext().
  17506. *
  17507. * \param ctx The generic cipher context. This must be initialized and
  17508. * bound to a key associated with an AEAD algorithm.
  17509. * \param iv The nonce to use. This must be a readable buffer of
  17510. * at least \p iv_len Bytes and must not be \c NULL.
  17511. * \param iv_len The length of the nonce. This must satisfy the
  17512. * constraints imposed by the AEAD cipher used.
  17513. * \param ad The additional data to authenticate. This must be a
  17514. * readable buffer of at least \p ad_len Bytes, and may
  17515. * be \c NULL is \p ad_len is \c 0.
  17516. * \param ad_len The length of \p ad.
  17517. * \param input The buffer holding the input data. This must be a
  17518. * readable buffer of at least \p ilen Bytes, and may be
  17519. * \c NULL if \p ilen is \c 0.
  17520. * \param ilen The length of the input data.
  17521. * \param output The buffer for the output data. This must be a
  17522. * writable buffer of at least \p ilen Bytes, and must
  17523. * not be \c NULL.
  17524. * \param olen This will be filled with the actual number of Bytes
  17525. * written to the \p output buffer. This must point to a
  17526. * writable object of type \c size_t.
  17527. * \param tag The buffer for the authentication tag. This must be a
  17528. * writable buffer of at least \p tag_len Bytes. See note
  17529. * below regarding restrictions with PSA-based contexts.
  17530. * \param tag_len The desired length of the authentication tag. This
  17531. * must match the constraints imposed by the AEAD cipher
  17532. * used, and in particular must not be \c 0.
  17533. *
  17534. * \note If the context is based on PSA (that is, it was set up
  17535. * with mbedtls_cipher_setup_psa()), then it is required
  17536. * that \c tag == output + ilen. That is, the tag must be
  17537. * appended to the ciphertext as recommended by RFC 5116.
  17538. *
  17539. * \return \c 0 on success.
  17540. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17541. * parameter-verification failure.
  17542. * \return A cipher-specific error code on failure.
  17543. */
  17544. int mbedtls_cipher_auth_encrypt( mbedtls_cipher_context_t *ctx,
  17545. const unsigned char *iv, size_t iv_len,
  17546. const unsigned char *ad, size_t ad_len,
  17547. const unsigned char *input, size_t ilen,
  17548. unsigned char *output, size_t *olen,
  17549. unsigned char *tag, size_t tag_len )
  17550. MBEDTLS_DEPRECATED;
  17551. /**
  17552. * \brief The generic authenticated decryption (AEAD) function.
  17553. *
  17554. * \deprecated Superseded by mbedtls_cipher_auth_decrypt_ext().
  17555. *
  17556. * \note This function only supports AEAD algorithms, not key
  17557. * wrapping algorithms such as NIST_KW; for this, see
  17558. * mbedtls_cipher_auth_decrypt_ext().
  17559. *
  17560. * \note If the data is not authentic, then the output buffer
  17561. * is zeroed out to prevent the unauthentic plaintext being
  17562. * used, making this interface safer.
  17563. *
  17564. * \param ctx The generic cipher context. This must be initialized and
  17565. * bound to a key associated with an AEAD algorithm.
  17566. * \param iv The nonce to use. This must be a readable buffer of
  17567. * at least \p iv_len Bytes and must not be \c NULL.
  17568. * \param iv_len The length of the nonce. This must satisfy the
  17569. * constraints imposed by the AEAD cipher used.
  17570. * \param ad The additional data to authenticate. This must be a
  17571. * readable buffer of at least \p ad_len Bytes, and may
  17572. * be \c NULL is \p ad_len is \c 0.
  17573. * \param ad_len The length of \p ad.
  17574. * \param input The buffer holding the input data. This must be a
  17575. * readable buffer of at least \p ilen Bytes, and may be
  17576. * \c NULL if \p ilen is \c 0.
  17577. * \param ilen The length of the input data.
  17578. * \param output The buffer for the output data. This must be a
  17579. * writable buffer of at least \p ilen Bytes, and must
  17580. * not be \c NULL.
  17581. * \param olen This will be filled with the actual number of Bytes
  17582. * written to the \p output buffer. This must point to a
  17583. * writable object of type \c size_t.
  17584. * \param tag The buffer for the authentication tag. This must be a
  17585. * readable buffer of at least \p tag_len Bytes. See note
  17586. * below regarding restrictions with PSA-based contexts.
  17587. * \param tag_len The length of the authentication tag. This must match
  17588. * the constraints imposed by the AEAD cipher used, and in
  17589. * particular must not be \c 0.
  17590. *
  17591. * \note If the context is based on PSA (that is, it was set up
  17592. * with mbedtls_cipher_setup_psa()), then it is required
  17593. * that \c tag == input + len. That is, the tag must be
  17594. * appended to the ciphertext as recommended by RFC 5116.
  17595. *
  17596. * \return \c 0 on success.
  17597. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17598. * parameter-verification failure.
  17599. * \return #MBEDTLS_ERR_CIPHER_AUTH_FAILED if data is not authentic.
  17600. * \return A cipher-specific error code on failure.
  17601. */
  17602. int mbedtls_cipher_auth_decrypt( mbedtls_cipher_context_t *ctx,
  17603. const unsigned char *iv, size_t iv_len,
  17604. const unsigned char *ad, size_t ad_len,
  17605. const unsigned char *input, size_t ilen,
  17606. unsigned char *output, size_t *olen,
  17607. const unsigned char *tag, size_t tag_len )
  17608. MBEDTLS_DEPRECATED;
  17609. #undef MBEDTLS_DEPRECATED
  17610. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  17611. #endif /* MBEDTLS_CIPHER_MODE_AEAD */
  17612. #if defined(MBEDTLS_CIPHER_MODE_AEAD) || defined(MBEDTLS_NIST_KW_C)
  17613. /**
  17614. * \brief The authenticated encryption (AEAD/NIST_KW) function.
  17615. *
  17616. * \note For AEAD modes, the tag will be appended to the
  17617. * ciphertext, as recommended by RFC 5116.
  17618. * (NIST_KW doesn't have a separate tag.)
  17619. *
  17620. * \param ctx The generic cipher context. This must be initialized and
  17621. * bound to a key, with an AEAD algorithm or NIST_KW.
  17622. * \param iv The nonce to use. This must be a readable buffer of
  17623. * at least \p iv_len Bytes and may be \c NULL if \p
  17624. * iv_len is \c 0.
  17625. * \param iv_len The length of the nonce. For AEAD ciphers, this must
  17626. * satisfy the constraints imposed by the cipher used.
  17627. * For NIST_KW, this must be \c 0.
  17628. * \param ad The additional data to authenticate. This must be a
  17629. * readable buffer of at least \p ad_len Bytes, and may
  17630. * be \c NULL is \p ad_len is \c 0.
  17631. * \param ad_len The length of \p ad. For NIST_KW, this must be \c 0.
  17632. * \param input The buffer holding the input data. This must be a
  17633. * readable buffer of at least \p ilen Bytes, and may be
  17634. * \c NULL if \p ilen is \c 0.
  17635. * \param ilen The length of the input data.
  17636. * \param output The buffer for the output data. This must be a
  17637. * writable buffer of at least \p output_len Bytes, and
  17638. * must not be \c NULL.
  17639. * \param output_len The length of the \p output buffer in Bytes. For AEAD
  17640. * ciphers, this must be at least \p ilen + \p tag_len.
  17641. * For NIST_KW, this must be at least \p ilen + 8
  17642. * (rounded up to a multiple of 8 if KWP is used);
  17643. * \p ilen + 15 is always a safe value.
  17644. * \param olen This will be filled with the actual number of Bytes
  17645. * written to the \p output buffer. This must point to a
  17646. * writable object of type \c size_t.
  17647. * \param tag_len The desired length of the authentication tag. For AEAD
  17648. * ciphers, this must match the constraints imposed by
  17649. * the cipher used, and in particular must not be \c 0.
  17650. * For NIST_KW, this must be \c 0.
  17651. *
  17652. * \return \c 0 on success.
  17653. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17654. * parameter-verification failure.
  17655. * \return A cipher-specific error code on failure.
  17656. */
  17657. int mbedtls_cipher_auth_encrypt_ext( mbedtls_cipher_context_t *ctx,
  17658. const unsigned char *iv, size_t iv_len,
  17659. const unsigned char *ad, size_t ad_len,
  17660. const unsigned char *input, size_t ilen,
  17661. unsigned char *output, size_t output_len,
  17662. size_t *olen, size_t tag_len );
  17663. /**
  17664. * \brief The authenticated encryption (AEAD/NIST_KW) function.
  17665. *
  17666. * \note If the data is not authentic, then the output buffer
  17667. * is zeroed out to prevent the unauthentic plaintext being
  17668. * used, making this interface safer.
  17669. *
  17670. * \note For AEAD modes, the tag must be appended to the
  17671. * ciphertext, as recommended by RFC 5116.
  17672. * (NIST_KW doesn't have a separate tag.)
  17673. *
  17674. * \param ctx The generic cipher context. This must be initialized and
  17675. * bound to a key, with an AEAD algorithm or NIST_KW.
  17676. * \param iv The nonce to use. This must be a readable buffer of
  17677. * at least \p iv_len Bytes and may be \c NULL if \p
  17678. * iv_len is \c 0.
  17679. * \param iv_len The length of the nonce. For AEAD ciphers, this must
  17680. * satisfy the constraints imposed by the cipher used.
  17681. * For NIST_KW, this must be \c 0.
  17682. * \param ad The additional data to authenticate. This must be a
  17683. * readable buffer of at least \p ad_len Bytes, and may
  17684. * be \c NULL is \p ad_len is \c 0.
  17685. * \param ad_len The length of \p ad. For NIST_KW, this must be \c 0.
  17686. * \param input The buffer holding the input data. This must be a
  17687. * readable buffer of at least \p ilen Bytes, and may be
  17688. * \c NULL if \p ilen is \c 0.
  17689. * \param ilen The length of the input data. For AEAD ciphers this
  17690. * must be at least \p tag_len. For NIST_KW this must be
  17691. * at least \c 8.
  17692. * \param output The buffer for the output data. This must be a
  17693. * writable buffer of at least \p output_len Bytes, and
  17694. * may be \c NULL if \p output_len is \c 0.
  17695. * \param output_len The length of the \p output buffer in Bytes. For AEAD
  17696. * ciphers, this must be at least \p ilen - \p tag_len.
  17697. * For NIST_KW, this must be at least \p ilen - 8.
  17698. * \param olen This will be filled with the actual number of Bytes
  17699. * written to the \p output buffer. This must point to a
  17700. * writable object of type \c size_t.
  17701. * \param tag_len The actual length of the authentication tag. For AEAD
  17702. * ciphers, this must match the constraints imposed by
  17703. * the cipher used, and in particular must not be \c 0.
  17704. * For NIST_KW, this must be \c 0.
  17705. *
  17706. * \return \c 0 on success.
  17707. * \return #MBEDTLS_ERR_CIPHER_BAD_INPUT_DATA on
  17708. * parameter-verification failure.
  17709. * \return #MBEDTLS_ERR_CIPHER_AUTH_FAILED if data is not authentic.
  17710. * \return A cipher-specific error code on failure.
  17711. */
  17712. int mbedtls_cipher_auth_decrypt_ext( mbedtls_cipher_context_t *ctx,
  17713. const unsigned char *iv, size_t iv_len,
  17714. const unsigned char *ad, size_t ad_len,
  17715. const unsigned char *input, size_t ilen,
  17716. unsigned char *output, size_t output_len,
  17717. size_t *olen, size_t tag_len );
  17718. #endif /* MBEDTLS_CIPHER_MODE_AEAD || MBEDTLS_NIST_KW_C */
  17719. #ifdef __cplusplus
  17720. }
  17721. #endif
  17722. #endif /* MBEDTLS_CIPHER_H */
  17723. /********* Start of file include/mbedtls/ssl_ciphersuites.h ************/
  17724. /**
  17725. * \file ssl_ciphersuites.h
  17726. *
  17727. * \brief SSL Ciphersuites for mbed TLS
  17728. */
  17729. /*
  17730. * Copyright The Mbed TLS Contributors
  17731. * SPDX-License-Identifier: Apache-2.0
  17732. *
  17733. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  17734. * not use this file except in compliance with the License.
  17735. * You may obtain a copy of the License at
  17736. *
  17737. * http://www.apache.org/licenses/LICENSE-2.0
  17738. *
  17739. * Unless required by applicable law or agreed to in writing, software
  17740. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  17741. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  17742. * See the License for the specific language governing permissions and
  17743. * limitations under the License.
  17744. */
  17745. #ifndef MBEDTLS_SSL_CIPHERSUITES_H
  17746. #define MBEDTLS_SSL_CIPHERSUITES_H
  17747. #if !defined(MBEDTLS_CONFIG_FILE)
  17748. #else
  17749. #endif
  17750. #ifdef __cplusplus
  17751. extern "C" {
  17752. #endif
  17753. /*
  17754. * Supported ciphersuites (Official IANA names)
  17755. */
  17756. #define MBEDTLS_TLS_RSA_WITH_NULL_MD5 0x01 /**< Weak! */
  17757. #define MBEDTLS_TLS_RSA_WITH_NULL_SHA 0x02 /**< Weak! */
  17758. #define MBEDTLS_TLS_RSA_WITH_RC4_128_MD5 0x04
  17759. #define MBEDTLS_TLS_RSA_WITH_RC4_128_SHA 0x05
  17760. #define MBEDTLS_TLS_RSA_WITH_DES_CBC_SHA 0x09 /**< Weak! Not in TLS 1.2 */
  17761. #define MBEDTLS_TLS_RSA_WITH_3DES_EDE_CBC_SHA 0x0A
  17762. #define MBEDTLS_TLS_DHE_RSA_WITH_DES_CBC_SHA 0x15 /**< Weak! Not in TLS 1.2 */
  17763. #define MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 0x16
  17764. #define MBEDTLS_TLS_PSK_WITH_NULL_SHA 0x2C /**< Weak! */
  17765. #define MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA 0x2D /**< Weak! */
  17766. #define MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA 0x2E /**< Weak! */
  17767. #define MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA 0x2F
  17768. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA 0x33
  17769. #define MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA 0x35
  17770. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA 0x39
  17771. #define MBEDTLS_TLS_RSA_WITH_NULL_SHA256 0x3B /**< Weak! */
  17772. #define MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA256 0x3C /**< TLS 1.2 */
  17773. #define MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA256 0x3D /**< TLS 1.2 */
  17774. #define MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 0x41
  17775. #define MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 0x45
  17776. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 0x67 /**< TLS 1.2 */
  17777. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 0x6B /**< TLS 1.2 */
  17778. #define MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 0x84
  17779. #define MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 0x88
  17780. #define MBEDTLS_TLS_PSK_WITH_RC4_128_SHA 0x8A
  17781. #define MBEDTLS_TLS_PSK_WITH_3DES_EDE_CBC_SHA 0x8B
  17782. #define MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA 0x8C
  17783. #define MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA 0x8D
  17784. #define MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA 0x8E
  17785. #define MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA 0x8F
  17786. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA 0x90
  17787. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA 0x91
  17788. #define MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA 0x92
  17789. #define MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA 0x93
  17790. #define MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA 0x94
  17791. #define MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA 0x95
  17792. #define MBEDTLS_TLS_RSA_WITH_AES_128_GCM_SHA256 0x9C /**< TLS 1.2 */
  17793. #define MBEDTLS_TLS_RSA_WITH_AES_256_GCM_SHA384 0x9D /**< TLS 1.2 */
  17794. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 0x9E /**< TLS 1.2 */
  17795. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 0x9F /**< TLS 1.2 */
  17796. #define MBEDTLS_TLS_PSK_WITH_AES_128_GCM_SHA256 0xA8 /**< TLS 1.2 */
  17797. #define MBEDTLS_TLS_PSK_WITH_AES_256_GCM_SHA384 0xA9 /**< TLS 1.2 */
  17798. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256 0xAA /**< TLS 1.2 */
  17799. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384 0xAB /**< TLS 1.2 */
  17800. #define MBEDTLS_TLS_RSA_PSK_WITH_AES_128_GCM_SHA256 0xAC /**< TLS 1.2 */
  17801. #define MBEDTLS_TLS_RSA_PSK_WITH_AES_256_GCM_SHA384 0xAD /**< TLS 1.2 */
  17802. #define MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA256 0xAE
  17803. #define MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA384 0xAF
  17804. #define MBEDTLS_TLS_PSK_WITH_NULL_SHA256 0xB0 /**< Weak! */
  17805. #define MBEDTLS_TLS_PSK_WITH_NULL_SHA384 0xB1 /**< Weak! */
  17806. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256 0xB2
  17807. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384 0xB3
  17808. #define MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA256 0xB4 /**< Weak! */
  17809. #define MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA384 0xB5 /**< Weak! */
  17810. #define MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA256 0xB6
  17811. #define MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA384 0xB7
  17812. #define MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA256 0xB8 /**< Weak! */
  17813. #define MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA384 0xB9 /**< Weak! */
  17814. #define MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256 0xBA /**< TLS 1.2 */
  17815. #define MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 0xBE /**< TLS 1.2 */
  17816. #define MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256 0xC0 /**< TLS 1.2 */
  17817. #define MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 0xC4 /**< TLS 1.2 */
  17818. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_NULL_SHA 0xC001 /**< Weak! */
  17819. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_RC4_128_SHA 0xC002 /**< Not in SSL3! */
  17820. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA 0xC003 /**< Not in SSL3! */
  17821. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA 0xC004 /**< Not in SSL3! */
  17822. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA 0xC005 /**< Not in SSL3! */
  17823. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_NULL_SHA 0xC006 /**< Weak! */
  17824. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA 0xC007 /**< Not in SSL3! */
  17825. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA 0xC008 /**< Not in SSL3! */
  17826. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA 0xC009 /**< Not in SSL3! */
  17827. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA 0xC00A /**< Not in SSL3! */
  17828. #define MBEDTLS_TLS_ECDH_RSA_WITH_NULL_SHA 0xC00B /**< Weak! */
  17829. #define MBEDTLS_TLS_ECDH_RSA_WITH_RC4_128_SHA 0xC00C /**< Not in SSL3! */
  17830. #define MBEDTLS_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA 0xC00D /**< Not in SSL3! */
  17831. #define MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA 0xC00E /**< Not in SSL3! */
  17832. #define MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA 0xC00F /**< Not in SSL3! */
  17833. #define MBEDTLS_TLS_ECDHE_RSA_WITH_NULL_SHA 0xC010 /**< Weak! */
  17834. #define MBEDTLS_TLS_ECDHE_RSA_WITH_RC4_128_SHA 0xC011 /**< Not in SSL3! */
  17835. #define MBEDTLS_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 0xC012 /**< Not in SSL3! */
  17836. #define MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 0xC013 /**< Not in SSL3! */
  17837. #define MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 0xC014 /**< Not in SSL3! */
  17838. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 0xC023 /**< TLS 1.2 */
  17839. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 0xC024 /**< TLS 1.2 */
  17840. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 0xC025 /**< TLS 1.2 */
  17841. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 0xC026 /**< TLS 1.2 */
  17842. #define MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 0xC027 /**< TLS 1.2 */
  17843. #define MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 0xC028 /**< TLS 1.2 */
  17844. #define MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256 0xC029 /**< TLS 1.2 */
  17845. #define MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384 0xC02A /**< TLS 1.2 */
  17846. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 0xC02B /**< TLS 1.2 */
  17847. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 0xC02C /**< TLS 1.2 */
  17848. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256 0xC02D /**< TLS 1.2 */
  17849. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384 0xC02E /**< TLS 1.2 */
  17850. #define MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 0xC02F /**< TLS 1.2 */
  17851. #define MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 0xC030 /**< TLS 1.2 */
  17852. #define MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256 0xC031 /**< TLS 1.2 */
  17853. #define MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384 0xC032 /**< TLS 1.2 */
  17854. #define MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA 0xC033 /**< Not in SSL3! */
  17855. #define MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA 0xC034 /**< Not in SSL3! */
  17856. #define MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA 0xC035 /**< Not in SSL3! */
  17857. #define MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA 0xC036 /**< Not in SSL3! */
  17858. #define MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256 0xC037 /**< Not in SSL3! */
  17859. #define MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384 0xC038 /**< Not in SSL3! */
  17860. #define MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA 0xC039 /**< Weak! No SSL3! */
  17861. #define MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA256 0xC03A /**< Weak! No SSL3! */
  17862. #define MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA384 0xC03B /**< Weak! No SSL3! */
  17863. #define MBEDTLS_TLS_RSA_WITH_ARIA_128_CBC_SHA256 0xC03C /**< TLS 1.2 */
  17864. #define MBEDTLS_TLS_RSA_WITH_ARIA_256_CBC_SHA384 0xC03D /**< TLS 1.2 */
  17865. #define MBEDTLS_TLS_DHE_RSA_WITH_ARIA_128_CBC_SHA256 0xC044 /**< TLS 1.2 */
  17866. #define MBEDTLS_TLS_DHE_RSA_WITH_ARIA_256_CBC_SHA384 0xC045 /**< TLS 1.2 */
  17867. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_ARIA_128_CBC_SHA256 0xC048 /**< TLS 1.2 */
  17868. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_ARIA_256_CBC_SHA384 0xC049 /**< TLS 1.2 */
  17869. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_ARIA_128_CBC_SHA256 0xC04A /**< TLS 1.2 */
  17870. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_ARIA_256_CBC_SHA384 0xC04B /**< TLS 1.2 */
  17871. #define MBEDTLS_TLS_ECDHE_RSA_WITH_ARIA_128_CBC_SHA256 0xC04C /**< TLS 1.2 */
  17872. #define MBEDTLS_TLS_ECDHE_RSA_WITH_ARIA_256_CBC_SHA384 0xC04D /**< TLS 1.2 */
  17873. #define MBEDTLS_TLS_ECDH_RSA_WITH_ARIA_128_CBC_SHA256 0xC04E /**< TLS 1.2 */
  17874. #define MBEDTLS_TLS_ECDH_RSA_WITH_ARIA_256_CBC_SHA384 0xC04F /**< TLS 1.2 */
  17875. #define MBEDTLS_TLS_RSA_WITH_ARIA_128_GCM_SHA256 0xC050 /**< TLS 1.2 */
  17876. #define MBEDTLS_TLS_RSA_WITH_ARIA_256_GCM_SHA384 0xC051 /**< TLS 1.2 */
  17877. #define MBEDTLS_TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256 0xC052 /**< TLS 1.2 */
  17878. #define MBEDTLS_TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384 0xC053 /**< TLS 1.2 */
  17879. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 0xC05C /**< TLS 1.2 */
  17880. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 0xC05D /**< TLS 1.2 */
  17881. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_ARIA_128_GCM_SHA256 0xC05E /**< TLS 1.2 */
  17882. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_ARIA_256_GCM_SHA384 0xC05F /**< TLS 1.2 */
  17883. #define MBEDTLS_TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 0xC060 /**< TLS 1.2 */
  17884. #define MBEDTLS_TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 0xC061 /**< TLS 1.2 */
  17885. #define MBEDTLS_TLS_ECDH_RSA_WITH_ARIA_128_GCM_SHA256 0xC062 /**< TLS 1.2 */
  17886. #define MBEDTLS_TLS_ECDH_RSA_WITH_ARIA_256_GCM_SHA384 0xC063 /**< TLS 1.2 */
  17887. #define MBEDTLS_TLS_PSK_WITH_ARIA_128_CBC_SHA256 0xC064 /**< TLS 1.2 */
  17888. #define MBEDTLS_TLS_PSK_WITH_ARIA_256_CBC_SHA384 0xC065 /**< TLS 1.2 */
  17889. #define MBEDTLS_TLS_DHE_PSK_WITH_ARIA_128_CBC_SHA256 0xC066 /**< TLS 1.2 */
  17890. #define MBEDTLS_TLS_DHE_PSK_WITH_ARIA_256_CBC_SHA384 0xC067 /**< TLS 1.2 */
  17891. #define MBEDTLS_TLS_RSA_PSK_WITH_ARIA_128_CBC_SHA256 0xC068 /**< TLS 1.2 */
  17892. #define MBEDTLS_TLS_RSA_PSK_WITH_ARIA_256_CBC_SHA384 0xC069 /**< TLS 1.2 */
  17893. #define MBEDTLS_TLS_PSK_WITH_ARIA_128_GCM_SHA256 0xC06A /**< TLS 1.2 */
  17894. #define MBEDTLS_TLS_PSK_WITH_ARIA_256_GCM_SHA384 0xC06B /**< TLS 1.2 */
  17895. #define MBEDTLS_TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256 0xC06C /**< TLS 1.2 */
  17896. #define MBEDTLS_TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384 0xC06D /**< TLS 1.2 */
  17897. #define MBEDTLS_TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256 0xC06E /**< TLS 1.2 */
  17898. #define MBEDTLS_TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384 0xC06F /**< TLS 1.2 */
  17899. #define MBEDTLS_TLS_ECDHE_PSK_WITH_ARIA_128_CBC_SHA256 0xC070 /**< TLS 1.2 */
  17900. #define MBEDTLS_TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384 0xC071 /**< TLS 1.2 */
  17901. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 0xC072 /**< Not in SSL3! */
  17902. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 0xC073 /**< Not in SSL3! */
  17903. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 0xC074 /**< Not in SSL3! */
  17904. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 0xC075 /**< Not in SSL3! */
  17905. #define MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 0xC076 /**< Not in SSL3! */
  17906. #define MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 0xC077 /**< Not in SSL3! */
  17907. #define MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 0xC078 /**< Not in SSL3! */
  17908. #define MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 0xC079 /**< Not in SSL3! */
  17909. #define MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256 0xC07A /**< TLS 1.2 */
  17910. #define MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384 0xC07B /**< TLS 1.2 */
  17911. #define MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256 0xC07C /**< TLS 1.2 */
  17912. #define MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384 0xC07D /**< TLS 1.2 */
  17913. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256 0xC086 /**< TLS 1.2 */
  17914. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384 0xC087 /**< TLS 1.2 */
  17915. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256 0xC088 /**< TLS 1.2 */
  17916. #define MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384 0xC089 /**< TLS 1.2 */
  17917. #define MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256 0xC08A /**< TLS 1.2 */
  17918. #define MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384 0xC08B /**< TLS 1.2 */
  17919. #define MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256 0xC08C /**< TLS 1.2 */
  17920. #define MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384 0xC08D /**< TLS 1.2 */
  17921. #define MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256 0xC08E /**< TLS 1.2 */
  17922. #define MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_GCM_SHA384 0xC08F /**< TLS 1.2 */
  17923. #define MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256 0xC090 /**< TLS 1.2 */
  17924. #define MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384 0xC091 /**< TLS 1.2 */
  17925. #define MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256 0xC092 /**< TLS 1.2 */
  17926. #define MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384 0xC093 /**< TLS 1.2 */
  17927. #define MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256 0xC094
  17928. #define MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384 0xC095
  17929. #define MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0xC096
  17930. #define MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0xC097
  17931. #define MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256 0xC098
  17932. #define MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384 0xC099
  17933. #define MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0xC09A /**< Not in SSL3! */
  17934. #define MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0xC09B /**< Not in SSL3! */
  17935. #define MBEDTLS_TLS_RSA_WITH_AES_128_CCM 0xC09C /**< TLS 1.2 */
  17936. #define MBEDTLS_TLS_RSA_WITH_AES_256_CCM 0xC09D /**< TLS 1.2 */
  17937. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM 0xC09E /**< TLS 1.2 */
  17938. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM 0xC09F /**< TLS 1.2 */
  17939. #define MBEDTLS_TLS_RSA_WITH_AES_128_CCM_8 0xC0A0 /**< TLS 1.2 */
  17940. #define MBEDTLS_TLS_RSA_WITH_AES_256_CCM_8 0xC0A1 /**< TLS 1.2 */
  17941. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM_8 0xC0A2 /**< TLS 1.2 */
  17942. #define MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM_8 0xC0A3 /**< TLS 1.2 */
  17943. #define MBEDTLS_TLS_PSK_WITH_AES_128_CCM 0xC0A4 /**< TLS 1.2 */
  17944. #define MBEDTLS_TLS_PSK_WITH_AES_256_CCM 0xC0A5 /**< TLS 1.2 */
  17945. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM 0xC0A6 /**< TLS 1.2 */
  17946. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM 0xC0A7 /**< TLS 1.2 */
  17947. #define MBEDTLS_TLS_PSK_WITH_AES_128_CCM_8 0xC0A8 /**< TLS 1.2 */
  17948. #define MBEDTLS_TLS_PSK_WITH_AES_256_CCM_8 0xC0A9 /**< TLS 1.2 */
  17949. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM_8 0xC0AA /**< TLS 1.2 */
  17950. #define MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM_8 0xC0AB /**< TLS 1.2 */
  17951. /* The last two are named with PSK_DHE in the RFC, which looks like a typo */
  17952. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM 0xC0AC /**< TLS 1.2 */
  17953. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM 0xC0AD /**< TLS 1.2 */
  17954. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 0xC0AE /**< TLS 1.2 */
  17955. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8 0xC0AF /**< TLS 1.2 */
  17956. #define MBEDTLS_TLS_ECJPAKE_WITH_AES_128_CCM_8 0xC0FF /**< experimental */
  17957. /* RFC 7905 */
  17958. #define MBEDTLS_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 0xCCA8 /**< TLS 1.2 */
  17959. #define MBEDTLS_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 0xCCA9 /**< TLS 1.2 */
  17960. #define MBEDTLS_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 0xCCAA /**< TLS 1.2 */
  17961. #define MBEDTLS_TLS_PSK_WITH_CHACHA20_POLY1305_SHA256 0xCCAB /**< TLS 1.2 */
  17962. #define MBEDTLS_TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 0xCCAC /**< TLS 1.2 */
  17963. #define MBEDTLS_TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256 0xCCAD /**< TLS 1.2 */
  17964. #define MBEDTLS_TLS_RSA_PSK_WITH_CHACHA20_POLY1305_SHA256 0xCCAE /**< TLS 1.2 */
  17965. /* Reminder: update mbedtls_ssl_premaster_secret when adding a new key exchange.
  17966. * Reminder: update MBEDTLS_KEY_EXCHANGE__xxx below
  17967. */
  17968. typedef enum {
  17969. MBEDTLS_KEY_EXCHANGE_NONE = 0,
  17970. MBEDTLS_KEY_EXCHANGE_RSA,
  17971. MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  17972. MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  17973. MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  17974. MBEDTLS_KEY_EXCHANGE_PSK,
  17975. MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  17976. MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  17977. MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  17978. MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  17979. MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  17980. MBEDTLS_KEY_EXCHANGE_ECJPAKE,
  17981. } mbedtls_key_exchange_type_t;
  17982. /* Key exchanges using a certificate */
  17983. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED) || \
  17984. defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED) || \
  17985. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED) || \
  17986. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED) || \
  17987. defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED) || \
  17988. defined(MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED) || \
  17989. defined(MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED)
  17990. #define MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED
  17991. #endif
  17992. /* Key exchanges allowing client certificate requests */
  17993. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED) || \
  17994. defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED) || \
  17995. defined(MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED) || \
  17996. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED) || \
  17997. defined(MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED) || \
  17998. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED)
  17999. #define MBEDTLS_KEY_EXCHANGE_CERT_REQ_ALLOWED_ENABLED
  18000. #endif
  18001. /* Key exchanges involving server signature in ServerKeyExchange */
  18002. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED) || \
  18003. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED) || \
  18004. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED)
  18005. #define MBEDTLS_KEY_EXCHANGE_WITH_SERVER_SIGNATURE_ENABLED
  18006. #endif
  18007. /* Key exchanges using ECDH */
  18008. #if defined(MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED) || \
  18009. defined(MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED)
  18010. #define MBEDTLS_KEY_EXCHANGE_SOME_ECDH_ENABLED
  18011. #endif
  18012. /* Key exchanges that don't involve ephemeral keys */
  18013. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED) || \
  18014. defined(MBEDTLS_KEY_EXCHANGE_PSK_ENABLED) || \
  18015. defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED) || \
  18016. defined(MBEDTLS_KEY_EXCHANGE_SOME_ECDH_ENABLED)
  18017. #define MBEDTLS_KEY_EXCHANGE_SOME_NON_PFS_ENABLED
  18018. #endif
  18019. /* Key exchanges that involve ephemeral keys */
  18020. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED) || \
  18021. defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED) || \
  18022. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED) || \
  18023. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED) || \
  18024. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED) || \
  18025. defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED)
  18026. #define MBEDTLS_KEY_EXCHANGE_SOME_PFS_ENABLED
  18027. #endif
  18028. /* Key exchanges using a PSK */
  18029. #if defined(MBEDTLS_KEY_EXCHANGE_PSK_ENABLED) || \
  18030. defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED) || \
  18031. defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED) || \
  18032. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED)
  18033. #define MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED
  18034. #endif
  18035. /* Key exchanges using DHE */
  18036. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED) || \
  18037. defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED)
  18038. #define MBEDTLS_KEY_EXCHANGE_SOME_DHE_ENABLED
  18039. #endif
  18040. /* Key exchanges using ECDHE */
  18041. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED) || \
  18042. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED) || \
  18043. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED)
  18044. #define MBEDTLS_KEY_EXCHANGE_SOME_ECDHE_ENABLED
  18045. #endif
  18046. typedef struct mbedtls_ssl_ciphersuite_t mbedtls_ssl_ciphersuite_t;
  18047. #define MBEDTLS_CIPHERSUITE_WEAK 0x01 /**< Weak ciphersuite flag */
  18048. #define MBEDTLS_CIPHERSUITE_SHORT_TAG 0x02 /**< Short authentication tag,
  18049. eg for CCM_8 */
  18050. #define MBEDTLS_CIPHERSUITE_NODTLS 0x04 /**< Can't be used with DTLS */
  18051. /**
  18052. * \brief This structure is used for storing ciphersuite information
  18053. */
  18054. struct mbedtls_ssl_ciphersuite_t
  18055. {
  18056. int id;
  18057. const char * name;
  18058. mbedtls_cipher_type_t cipher;
  18059. mbedtls_md_type_t mac;
  18060. mbedtls_key_exchange_type_t key_exchange;
  18061. int min_major_ver;
  18062. int min_minor_ver;
  18063. int max_major_ver;
  18064. int max_minor_ver;
  18065. unsigned char flags;
  18066. };
  18067. const int *mbedtls_ssl_list_ciphersuites( void );
  18068. const mbedtls_ssl_ciphersuite_t *mbedtls_ssl_ciphersuite_from_string( const char *ciphersuite_name );
  18069. const mbedtls_ssl_ciphersuite_t *mbedtls_ssl_ciphersuite_from_id( int ciphersuite_id );
  18070. #if defined(MBEDTLS_PK_C)
  18071. mbedtls_pk_type_t mbedtls_ssl_get_ciphersuite_sig_pk_alg( const mbedtls_ssl_ciphersuite_t *info );
  18072. mbedtls_pk_type_t mbedtls_ssl_get_ciphersuite_sig_alg( const mbedtls_ssl_ciphersuite_t *info );
  18073. #endif
  18074. int mbedtls_ssl_ciphersuite_uses_ec( const mbedtls_ssl_ciphersuite_t *info );
  18075. int mbedtls_ssl_ciphersuite_uses_psk( const mbedtls_ssl_ciphersuite_t *info );
  18076. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_PFS_ENABLED)
  18077. static inline int mbedtls_ssl_ciphersuite_has_pfs( const mbedtls_ssl_ciphersuite_t *info )
  18078. {
  18079. switch( info->key_exchange )
  18080. {
  18081. case MBEDTLS_KEY_EXCHANGE_DHE_RSA:
  18082. case MBEDTLS_KEY_EXCHANGE_DHE_PSK:
  18083. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  18084. case MBEDTLS_KEY_EXCHANGE_ECDHE_PSK:
  18085. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  18086. case MBEDTLS_KEY_EXCHANGE_ECJPAKE:
  18087. return( 1 );
  18088. default:
  18089. return( 0 );
  18090. }
  18091. }
  18092. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_PFS_ENABLED */
  18093. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_NON_PFS_ENABLED)
  18094. static inline int mbedtls_ssl_ciphersuite_no_pfs( const mbedtls_ssl_ciphersuite_t *info )
  18095. {
  18096. switch( info->key_exchange )
  18097. {
  18098. case MBEDTLS_KEY_EXCHANGE_ECDH_RSA:
  18099. case MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA:
  18100. case MBEDTLS_KEY_EXCHANGE_RSA:
  18101. case MBEDTLS_KEY_EXCHANGE_PSK:
  18102. case MBEDTLS_KEY_EXCHANGE_RSA_PSK:
  18103. return( 1 );
  18104. default:
  18105. return( 0 );
  18106. }
  18107. }
  18108. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_NON_PFS_ENABLED */
  18109. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_ECDH_ENABLED)
  18110. static inline int mbedtls_ssl_ciphersuite_uses_ecdh( const mbedtls_ssl_ciphersuite_t *info )
  18111. {
  18112. switch( info->key_exchange )
  18113. {
  18114. case MBEDTLS_KEY_EXCHANGE_ECDH_RSA:
  18115. case MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA:
  18116. return( 1 );
  18117. default:
  18118. return( 0 );
  18119. }
  18120. }
  18121. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_ECDH_ENABLED */
  18122. static inline int mbedtls_ssl_ciphersuite_cert_req_allowed( const mbedtls_ssl_ciphersuite_t *info )
  18123. {
  18124. switch( info->key_exchange )
  18125. {
  18126. case MBEDTLS_KEY_EXCHANGE_RSA:
  18127. case MBEDTLS_KEY_EXCHANGE_DHE_RSA:
  18128. case MBEDTLS_KEY_EXCHANGE_ECDH_RSA:
  18129. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  18130. case MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA:
  18131. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  18132. return( 1 );
  18133. default:
  18134. return( 0 );
  18135. }
  18136. }
  18137. static inline int mbedtls_ssl_ciphersuite_uses_srv_cert( const mbedtls_ssl_ciphersuite_t *info )
  18138. {
  18139. switch( info->key_exchange )
  18140. {
  18141. case MBEDTLS_KEY_EXCHANGE_RSA:
  18142. case MBEDTLS_KEY_EXCHANGE_RSA_PSK:
  18143. case MBEDTLS_KEY_EXCHANGE_DHE_RSA:
  18144. case MBEDTLS_KEY_EXCHANGE_ECDH_RSA:
  18145. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  18146. case MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA:
  18147. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  18148. return( 1 );
  18149. default:
  18150. return( 0 );
  18151. }
  18152. }
  18153. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_DHE_ENABLED)
  18154. static inline int mbedtls_ssl_ciphersuite_uses_dhe( const mbedtls_ssl_ciphersuite_t *info )
  18155. {
  18156. switch( info->key_exchange )
  18157. {
  18158. case MBEDTLS_KEY_EXCHANGE_DHE_RSA:
  18159. case MBEDTLS_KEY_EXCHANGE_DHE_PSK:
  18160. return( 1 );
  18161. default:
  18162. return( 0 );
  18163. }
  18164. }
  18165. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_DHE_ENABLED) */
  18166. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_ECDHE_ENABLED)
  18167. static inline int mbedtls_ssl_ciphersuite_uses_ecdhe( const mbedtls_ssl_ciphersuite_t *info )
  18168. {
  18169. switch( info->key_exchange )
  18170. {
  18171. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  18172. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  18173. case MBEDTLS_KEY_EXCHANGE_ECDHE_PSK:
  18174. return( 1 );
  18175. default:
  18176. return( 0 );
  18177. }
  18178. }
  18179. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_ECDHE_ENABLED) */
  18180. #if defined(MBEDTLS_KEY_EXCHANGE_WITH_SERVER_SIGNATURE_ENABLED)
  18181. static inline int mbedtls_ssl_ciphersuite_uses_server_signature( const mbedtls_ssl_ciphersuite_t *info )
  18182. {
  18183. switch( info->key_exchange )
  18184. {
  18185. case MBEDTLS_KEY_EXCHANGE_DHE_RSA:
  18186. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  18187. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  18188. return( 1 );
  18189. default:
  18190. return( 0 );
  18191. }
  18192. }
  18193. #endif /* MBEDTLS_KEY_EXCHANGE_WITH_SERVER_SIGNATURE_ENABLED */
  18194. #ifdef __cplusplus
  18195. }
  18196. #endif
  18197. #endif /* ssl_ciphersuites.h */
  18198. /********* Start of file include/mbedtls/cipher_internal.h ************/
  18199. /**
  18200. * \file cipher_internal.h
  18201. *
  18202. * \brief Cipher wrappers.
  18203. *
  18204. * \author Adriaan de Jong <dejong@fox-it.com>
  18205. */
  18206. /*
  18207. * Copyright The Mbed TLS Contributors
  18208. * SPDX-License-Identifier: Apache-2.0
  18209. *
  18210. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  18211. * not use this file except in compliance with the License.
  18212. * You may obtain a copy of the License at
  18213. *
  18214. * http://www.apache.org/licenses/LICENSE-2.0
  18215. *
  18216. * Unless required by applicable law or agreed to in writing, software
  18217. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  18218. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  18219. * See the License for the specific language governing permissions and
  18220. * limitations under the License.
  18221. */
  18222. #ifndef MBEDTLS_CIPHER_WRAP_H
  18223. #define MBEDTLS_CIPHER_WRAP_H
  18224. #if !defined(MBEDTLS_CONFIG_FILE)
  18225. #else
  18226. #endif
  18227. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  18228. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  18229. #ifdef __cplusplus
  18230. extern "C" {
  18231. #endif
  18232. /**
  18233. * Base cipher information. The non-mode specific functions and values.
  18234. */
  18235. struct mbedtls_cipher_base_t
  18236. {
  18237. /** Base Cipher type (e.g. MBEDTLS_CIPHER_ID_AES) */
  18238. mbedtls_cipher_id_t cipher;
  18239. /** Encrypt using ECB */
  18240. int (*ecb_func)( void *ctx, mbedtls_operation_t mode,
  18241. const unsigned char *input, unsigned char *output );
  18242. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  18243. /** Encrypt using CBC */
  18244. int (*cbc_func)( void *ctx, mbedtls_operation_t mode, size_t length,
  18245. unsigned char *iv, const unsigned char *input,
  18246. unsigned char *output );
  18247. #endif
  18248. #if defined(MBEDTLS_CIPHER_MODE_CFB)
  18249. /** Encrypt using CFB (Full length) */
  18250. int (*cfb_func)( void *ctx, mbedtls_operation_t mode, size_t length, size_t *iv_off,
  18251. unsigned char *iv, const unsigned char *input,
  18252. unsigned char *output );
  18253. #endif
  18254. #if defined(MBEDTLS_CIPHER_MODE_OFB)
  18255. /** Encrypt using OFB (Full length) */
  18256. int (*ofb_func)( void *ctx, size_t length, size_t *iv_off,
  18257. unsigned char *iv,
  18258. const unsigned char *input,
  18259. unsigned char *output );
  18260. #endif
  18261. #if defined(MBEDTLS_CIPHER_MODE_CTR)
  18262. /** Encrypt using CTR */
  18263. int (*ctr_func)( void *ctx, size_t length, size_t *nc_off,
  18264. unsigned char *nonce_counter, unsigned char *stream_block,
  18265. const unsigned char *input, unsigned char *output );
  18266. #endif
  18267. #if defined(MBEDTLS_CIPHER_MODE_XTS)
  18268. /** Encrypt or decrypt using XTS. */
  18269. int (*xts_func)( void *ctx, mbedtls_operation_t mode, size_t length,
  18270. const unsigned char data_unit[16],
  18271. const unsigned char *input, unsigned char *output );
  18272. #endif
  18273. #if defined(MBEDTLS_CIPHER_MODE_STREAM)
  18274. /** Encrypt using STREAM */
  18275. int (*stream_func)( void *ctx, size_t length,
  18276. const unsigned char *input, unsigned char *output );
  18277. #endif
  18278. /** Set key for encryption purposes */
  18279. int (*setkey_enc_func)( void *ctx, const unsigned char *key,
  18280. unsigned int key_bitlen );
  18281. /** Set key for decryption purposes */
  18282. int (*setkey_dec_func)( void *ctx, const unsigned char *key,
  18283. unsigned int key_bitlen);
  18284. /** Allocate a new context */
  18285. void * (*ctx_alloc_func)( void );
  18286. /** Free the given context */
  18287. void (*ctx_free_func)( void *ctx );
  18288. };
  18289. typedef struct
  18290. {
  18291. mbedtls_cipher_type_t type;
  18292. const mbedtls_cipher_info_t *info;
  18293. } mbedtls_cipher_definition_t;
  18294. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  18295. typedef enum
  18296. {
  18297. MBEDTLS_CIPHER_PSA_KEY_UNSET = 0,
  18298. MBEDTLS_CIPHER_PSA_KEY_OWNED, /* Used for PSA-based cipher contexts which */
  18299. /* use raw key material internally imported */
  18300. /* as a volatile key, and which hence need */
  18301. /* to destroy that key when the context is */
  18302. /* freed. */
  18303. MBEDTLS_CIPHER_PSA_KEY_NOT_OWNED, /* Used for PSA-based cipher contexts */
  18304. /* which use a key provided by the */
  18305. /* user, and which hence will not be */
  18306. /* destroyed when the context is freed. */
  18307. } mbedtls_cipher_psa_key_ownership;
  18308. typedef struct
  18309. {
  18310. psa_algorithm_t alg;
  18311. psa_key_id_t slot;
  18312. mbedtls_cipher_psa_key_ownership slot_state;
  18313. } mbedtls_cipher_context_psa;
  18314. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  18315. extern const mbedtls_cipher_definition_t mbedtls_cipher_definitions[];
  18316. extern int mbedtls_cipher_supported[];
  18317. #ifdef __cplusplus
  18318. }
  18319. #endif
  18320. #endif /* MBEDTLS_CIPHER_WRAP_H */
  18321. /********* Start of file include/mbedtls/ecdh.h ************/
  18322. /**
  18323. * \file ecdh.h
  18324. *
  18325. * \brief This file contains ECDH definitions and functions.
  18326. *
  18327. * The Elliptic Curve Diffie-Hellman (ECDH) protocol is an anonymous
  18328. * key agreement protocol allowing two parties to establish a shared
  18329. * secret over an insecure channel. Each party must have an
  18330. * elliptic-curve public–private key pair.
  18331. *
  18332. * For more information, see <em>NIST SP 800-56A Rev. 2: Recommendation for
  18333. * Pair-Wise Key Establishment Schemes Using Discrete Logarithm
  18334. * Cryptography</em>.
  18335. */
  18336. /*
  18337. * Copyright The Mbed TLS Contributors
  18338. * SPDX-License-Identifier: Apache-2.0
  18339. *
  18340. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  18341. * not use this file except in compliance with the License.
  18342. * You may obtain a copy of the License at
  18343. *
  18344. * http://www.apache.org/licenses/LICENSE-2.0
  18345. *
  18346. * Unless required by applicable law or agreed to in writing, software
  18347. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  18348. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  18349. * See the License for the specific language governing permissions and
  18350. * limitations under the License.
  18351. */
  18352. #ifndef MBEDTLS_ECDH_H
  18353. #define MBEDTLS_ECDH_H
  18354. #if !defined(MBEDTLS_CONFIG_FILE)
  18355. #else
  18356. #endif
  18357. #if defined(MBEDTLS_ECDH_VARIANT_EVEREST_ENABLED)
  18358. #undef MBEDTLS_ECDH_LEGACY_CONTEXT
  18359. #endif
  18360. #ifdef __cplusplus
  18361. extern "C" {
  18362. #endif
  18363. /**
  18364. * Defines the source of the imported EC key.
  18365. */
  18366. typedef enum
  18367. {
  18368. MBEDTLS_ECDH_OURS, /**< Our key. */
  18369. MBEDTLS_ECDH_THEIRS, /**< The key of the peer. */
  18370. } mbedtls_ecdh_side;
  18371. #if !defined(MBEDTLS_ECDH_LEGACY_CONTEXT)
  18372. /**
  18373. * Defines the ECDH implementation used.
  18374. *
  18375. * Later versions of the library may add new variants, therefore users should
  18376. * not make any assumptions about them.
  18377. */
  18378. typedef enum
  18379. {
  18380. MBEDTLS_ECDH_VARIANT_NONE = 0, /*!< Implementation not defined. */
  18381. MBEDTLS_ECDH_VARIANT_MBEDTLS_2_0,/*!< The default Mbed TLS implementation */
  18382. #if defined(MBEDTLS_ECDH_VARIANT_EVEREST_ENABLED)
  18383. MBEDTLS_ECDH_VARIANT_EVEREST /*!< Everest implementation */
  18384. #endif
  18385. } mbedtls_ecdh_variant;
  18386. /**
  18387. * The context used by the default ECDH implementation.
  18388. *
  18389. * Later versions might change the structure of this context, therefore users
  18390. * should not make any assumptions about the structure of
  18391. * mbedtls_ecdh_context_mbed.
  18392. */
  18393. typedef struct mbedtls_ecdh_context_mbed
  18394. {
  18395. mbedtls_ecp_group grp; /*!< The elliptic curve used. */
  18396. mbedtls_mpi d; /*!< The private key. */
  18397. mbedtls_ecp_point Q; /*!< The public key. */
  18398. mbedtls_ecp_point Qp; /*!< The value of the public key of the peer. */
  18399. mbedtls_mpi z; /*!< The shared secret. */
  18400. #if defined(MBEDTLS_ECP_RESTARTABLE)
  18401. mbedtls_ecp_restart_ctx rs; /*!< The restart context for EC computations. */
  18402. #endif
  18403. } mbedtls_ecdh_context_mbed;
  18404. #endif
  18405. /**
  18406. *
  18407. * \warning Performing multiple operations concurrently on the same
  18408. * ECDSA context is not supported; objects of this type
  18409. * should not be shared between multiple threads.
  18410. * \brief The ECDH context structure.
  18411. */
  18412. typedef struct mbedtls_ecdh_context
  18413. {
  18414. #if defined(MBEDTLS_ECDH_LEGACY_CONTEXT)
  18415. mbedtls_ecp_group grp; /*!< The elliptic curve used. */
  18416. mbedtls_mpi d; /*!< The private key. */
  18417. mbedtls_ecp_point Q; /*!< The public key. */
  18418. mbedtls_ecp_point Qp; /*!< The value of the public key of the peer. */
  18419. mbedtls_mpi z; /*!< The shared secret. */
  18420. int point_format; /*!< The format of point export in TLS messages. */
  18421. mbedtls_ecp_point Vi; /*!< The blinding value. */
  18422. mbedtls_ecp_point Vf; /*!< The unblinding value. */
  18423. mbedtls_mpi _d; /*!< The previous \p d. */
  18424. #if defined(MBEDTLS_ECP_RESTARTABLE)
  18425. int restart_enabled; /*!< The flag for restartable mode. */
  18426. mbedtls_ecp_restart_ctx rs; /*!< The restart context for EC computations. */
  18427. #endif /* MBEDTLS_ECP_RESTARTABLE */
  18428. #else
  18429. uint8_t point_format; /*!< The format of point export in TLS messages
  18430. as defined in RFC 4492. */
  18431. mbedtls_ecp_group_id grp_id;/*!< The elliptic curve used. */
  18432. mbedtls_ecdh_variant var; /*!< The ECDH implementation/structure used. */
  18433. union
  18434. {
  18435. mbedtls_ecdh_context_mbed mbed_ecdh;
  18436. #if defined(MBEDTLS_ECDH_VARIANT_EVEREST_ENABLED)
  18437. mbedtls_ecdh_context_everest everest_ecdh;
  18438. #endif
  18439. } ctx; /*!< Implementation-specific context. The
  18440. context in use is specified by the \c var
  18441. field. */
  18442. #if defined(MBEDTLS_ECP_RESTARTABLE)
  18443. uint8_t restart_enabled; /*!< The flag for restartable mode. Functions of
  18444. an alternative implementation not supporting
  18445. restartable mode must return
  18446. MBEDTLS_ERR_PLATFORM_FEATURE_UNSUPPORTED error
  18447. if this flag is set. */
  18448. #endif /* MBEDTLS_ECP_RESTARTABLE */
  18449. #endif /* MBEDTLS_ECDH_LEGACY_CONTEXT */
  18450. }
  18451. mbedtls_ecdh_context;
  18452. /**
  18453. * \brief Check whether a given group can be used for ECDH.
  18454. *
  18455. * \param gid The ECP group ID to check.
  18456. *
  18457. * \return \c 1 if the group can be used, \c 0 otherwise
  18458. */
  18459. int mbedtls_ecdh_can_do( mbedtls_ecp_group_id gid );
  18460. /**
  18461. * \brief This function generates an ECDH keypair on an elliptic
  18462. * curve.
  18463. *
  18464. * This function performs the first of two core computations
  18465. * implemented during the ECDH key exchange. The second core
  18466. * computation is performed by mbedtls_ecdh_compute_shared().
  18467. *
  18468. * \see ecp.h
  18469. *
  18470. * \param grp The ECP group to use. This must be initialized and have
  18471. * domain parameters loaded, for example through
  18472. * mbedtls_ecp_load() or mbedtls_ecp_tls_read_group().
  18473. * \param d The destination MPI (private key).
  18474. * This must be initialized.
  18475. * \param Q The destination point (public key).
  18476. * This must be initialized.
  18477. * \param f_rng The RNG function to use. This must not be \c NULL.
  18478. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  18479. * \c NULL in case \p f_rng doesn't need a context argument.
  18480. *
  18481. * \return \c 0 on success.
  18482. * \return Another \c MBEDTLS_ERR_ECP_XXX or
  18483. * \c MBEDTLS_MPI_XXX error code on failure.
  18484. */
  18485. int mbedtls_ecdh_gen_public( mbedtls_ecp_group *grp, mbedtls_mpi *d, mbedtls_ecp_point *Q,
  18486. int (*f_rng)(void *, unsigned char *, size_t),
  18487. void *p_rng );
  18488. /**
  18489. * \brief This function computes the shared secret.
  18490. *
  18491. * This function performs the second of two core computations
  18492. * implemented during the ECDH key exchange. The first core
  18493. * computation is performed by mbedtls_ecdh_gen_public().
  18494. *
  18495. * \see ecp.h
  18496. *
  18497. * \note If \p f_rng is not NULL, it is used to implement
  18498. * countermeasures against side-channel attacks.
  18499. * For more information, see mbedtls_ecp_mul().
  18500. *
  18501. * \param grp The ECP group to use. This must be initialized and have
  18502. * domain parameters loaded, for example through
  18503. * mbedtls_ecp_load() or mbedtls_ecp_tls_read_group().
  18504. * \param z The destination MPI (shared secret).
  18505. * This must be initialized.
  18506. * \param Q The public key from another party.
  18507. * This must be initialized.
  18508. * \param d Our secret exponent (private key).
  18509. * This must be initialized.
  18510. * \param f_rng The RNG function. This may be \c NULL if randomization
  18511. * of intermediate results during the ECP computations is
  18512. * not needed (discouraged). See the documentation of
  18513. * mbedtls_ecp_mul() for more.
  18514. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  18515. * \c NULL if \p f_rng is \c NULL or doesn't need a
  18516. * context argument.
  18517. *
  18518. * \return \c 0 on success.
  18519. * \return Another \c MBEDTLS_ERR_ECP_XXX or
  18520. * \c MBEDTLS_MPI_XXX error code on failure.
  18521. */
  18522. int mbedtls_ecdh_compute_shared( mbedtls_ecp_group *grp, mbedtls_mpi *z,
  18523. const mbedtls_ecp_point *Q, const mbedtls_mpi *d,
  18524. int (*f_rng)(void *, unsigned char *, size_t),
  18525. void *p_rng );
  18526. /**
  18527. * \brief This function initializes an ECDH context.
  18528. *
  18529. * \param ctx The ECDH context to initialize. This must not be \c NULL.
  18530. */
  18531. void mbedtls_ecdh_init( mbedtls_ecdh_context *ctx );
  18532. /**
  18533. * \brief This function sets up the ECDH context with the information
  18534. * given.
  18535. *
  18536. * This function should be called after mbedtls_ecdh_init() but
  18537. * before mbedtls_ecdh_make_params(). There is no need to call
  18538. * this function before mbedtls_ecdh_read_params().
  18539. *
  18540. * This is the first function used by a TLS server for ECDHE
  18541. * ciphersuites.
  18542. *
  18543. * \param ctx The ECDH context to set up. This must be initialized.
  18544. * \param grp_id The group id of the group to set up the context for.
  18545. *
  18546. * \return \c 0 on success.
  18547. */
  18548. int mbedtls_ecdh_setup( mbedtls_ecdh_context *ctx,
  18549. mbedtls_ecp_group_id grp_id );
  18550. /**
  18551. * \brief This function frees a context.
  18552. *
  18553. * \param ctx The context to free. This may be \c NULL, in which
  18554. * case this function does nothing. If it is not \c NULL,
  18555. * it must point to an initialized ECDH context.
  18556. */
  18557. void mbedtls_ecdh_free( mbedtls_ecdh_context *ctx );
  18558. /**
  18559. * \brief This function generates an EC key pair and exports its
  18560. * in the format used in a TLS ServerKeyExchange handshake
  18561. * message.
  18562. *
  18563. * This is the second function used by a TLS server for ECDHE
  18564. * ciphersuites. (It is called after mbedtls_ecdh_setup().)
  18565. *
  18566. * \see ecp.h
  18567. *
  18568. * \param ctx The ECDH context to use. This must be initialized
  18569. * and bound to a group, for example via mbedtls_ecdh_setup().
  18570. * \param olen The address at which to store the number of Bytes written.
  18571. * \param buf The destination buffer. This must be a writable buffer of
  18572. * length \p blen Bytes.
  18573. * \param blen The length of the destination buffer \p buf in Bytes.
  18574. * \param f_rng The RNG function to use. This must not be \c NULL.
  18575. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  18576. * \c NULL in case \p f_rng doesn't need a context argument.
  18577. *
  18578. * \return \c 0 on success.
  18579. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  18580. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  18581. * \return Another \c MBEDTLS_ERR_ECP_XXX error code on failure.
  18582. */
  18583. int mbedtls_ecdh_make_params( mbedtls_ecdh_context *ctx, size_t *olen,
  18584. unsigned char *buf, size_t blen,
  18585. int (*f_rng)(void *, unsigned char *, size_t),
  18586. void *p_rng );
  18587. /**
  18588. * \brief This function parses the ECDHE parameters in a
  18589. * TLS ServerKeyExchange handshake message.
  18590. *
  18591. * \note In a TLS handshake, this is the how the client
  18592. * sets up its ECDHE context from the server's public
  18593. * ECDHE key material.
  18594. *
  18595. * \see ecp.h
  18596. *
  18597. * \param ctx The ECDHE context to use. This must be initialized.
  18598. * \param buf On input, \c *buf must be the start of the input buffer.
  18599. * On output, \c *buf is updated to point to the end of the
  18600. * data that has been read. On success, this is the first byte
  18601. * past the end of the ServerKeyExchange parameters.
  18602. * On error, this is the point at which an error has been
  18603. * detected, which is usually not useful except to debug
  18604. * failures.
  18605. * \param end The end of the input buffer.
  18606. *
  18607. * \return \c 0 on success.
  18608. * \return An \c MBEDTLS_ERR_ECP_XXX error code on failure.
  18609. *
  18610. */
  18611. int mbedtls_ecdh_read_params( mbedtls_ecdh_context *ctx,
  18612. const unsigned char **buf,
  18613. const unsigned char *end );
  18614. /**
  18615. * \brief This function sets up an ECDH context from an EC key.
  18616. *
  18617. * It is used by clients and servers in place of the
  18618. * ServerKeyEchange for static ECDH, and imports ECDH
  18619. * parameters from the EC key information of a certificate.
  18620. *
  18621. * \see ecp.h
  18622. *
  18623. * \param ctx The ECDH context to set up. This must be initialized.
  18624. * \param key The EC key to use. This must be initialized.
  18625. * \param side Defines the source of the key. Possible values are:
  18626. * - #MBEDTLS_ECDH_OURS: The key is ours.
  18627. * - #MBEDTLS_ECDH_THEIRS: The key is that of the peer.
  18628. *
  18629. * \return \c 0 on success.
  18630. * \return Another \c MBEDTLS_ERR_ECP_XXX error code on failure.
  18631. *
  18632. */
  18633. int mbedtls_ecdh_get_params( mbedtls_ecdh_context *ctx,
  18634. const mbedtls_ecp_keypair *key,
  18635. mbedtls_ecdh_side side );
  18636. /**
  18637. * \brief This function generates a public key and exports it
  18638. * as a TLS ClientKeyExchange payload.
  18639. *
  18640. * This is the second function used by a TLS client for ECDH(E)
  18641. * ciphersuites.
  18642. *
  18643. * \see ecp.h
  18644. *
  18645. * \param ctx The ECDH context to use. This must be initialized
  18646. * and bound to a group, the latter usually by
  18647. * mbedtls_ecdh_read_params().
  18648. * \param olen The address at which to store the number of Bytes written.
  18649. * This must not be \c NULL.
  18650. * \param buf The destination buffer. This must be a writable buffer
  18651. * of length \p blen Bytes.
  18652. * \param blen The size of the destination buffer \p buf in Bytes.
  18653. * \param f_rng The RNG function to use. This must not be \c NULL.
  18654. * \param p_rng The RNG context to be passed to \p f_rng. This may be
  18655. * \c NULL in case \p f_rng doesn't need a context argument.
  18656. *
  18657. * \return \c 0 on success.
  18658. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  18659. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  18660. * \return Another \c MBEDTLS_ERR_ECP_XXX error code on failure.
  18661. */
  18662. int mbedtls_ecdh_make_public( mbedtls_ecdh_context *ctx, size_t *olen,
  18663. unsigned char *buf, size_t blen,
  18664. int (*f_rng)(void *, unsigned char *, size_t),
  18665. void *p_rng );
  18666. /**
  18667. * \brief This function parses and processes the ECDHE payload of a
  18668. * TLS ClientKeyExchange message.
  18669. *
  18670. * This is the third function used by a TLS server for ECDH(E)
  18671. * ciphersuites. (It is called after mbedtls_ecdh_setup() and
  18672. * mbedtls_ecdh_make_params().)
  18673. *
  18674. * \see ecp.h
  18675. *
  18676. * \param ctx The ECDH context to use. This must be initialized
  18677. * and bound to a group, for example via mbedtls_ecdh_setup().
  18678. * \param buf The pointer to the ClientKeyExchange payload. This must
  18679. * be a readable buffer of length \p blen Bytes.
  18680. * \param blen The length of the input buffer \p buf in Bytes.
  18681. *
  18682. * \return \c 0 on success.
  18683. * \return An \c MBEDTLS_ERR_ECP_XXX error code on failure.
  18684. */
  18685. int mbedtls_ecdh_read_public( mbedtls_ecdh_context *ctx,
  18686. const unsigned char *buf, size_t blen );
  18687. /**
  18688. * \brief This function derives and exports the shared secret.
  18689. *
  18690. * This is the last function used by both TLS client
  18691. * and servers.
  18692. *
  18693. * \note If \p f_rng is not NULL, it is used to implement
  18694. * countermeasures against side-channel attacks.
  18695. * For more information, see mbedtls_ecp_mul().
  18696. *
  18697. * \see ecp.h
  18698. * \param ctx The ECDH context to use. This must be initialized
  18699. * and have its own private key generated and the peer's
  18700. * public key imported.
  18701. * \param olen The address at which to store the total number of
  18702. * Bytes written on success. This must not be \c NULL.
  18703. * \param buf The buffer to write the generated shared key to. This
  18704. * must be a writable buffer of size \p blen Bytes.
  18705. * \param blen The length of the destination buffer \p buf in Bytes.
  18706. * \param f_rng The RNG function, for blinding purposes. This may
  18707. * b \c NULL if blinding isn't needed.
  18708. * \param p_rng The RNG context. This may be \c NULL if \p f_rng
  18709. * doesn't need a context argument.
  18710. *
  18711. * \return \c 0 on success.
  18712. * \return #MBEDTLS_ERR_ECP_IN_PROGRESS if maximum number of
  18713. * operations was reached: see \c mbedtls_ecp_set_max_ops().
  18714. * \return Another \c MBEDTLS_ERR_ECP_XXX error code on failure.
  18715. */
  18716. int mbedtls_ecdh_calc_secret( mbedtls_ecdh_context *ctx, size_t *olen,
  18717. unsigned char *buf, size_t blen,
  18718. int (*f_rng)(void *, unsigned char *, size_t),
  18719. void *p_rng );
  18720. #if defined(MBEDTLS_ECP_RESTARTABLE)
  18721. /**
  18722. * \brief This function enables restartable EC computations for this
  18723. * context. (Default: disabled.)
  18724. *
  18725. * \see \c mbedtls_ecp_set_max_ops()
  18726. *
  18727. * \note It is not possible to safely disable restartable
  18728. * computations once enabled, except by free-ing the context,
  18729. * which cancels possible in-progress operations.
  18730. *
  18731. * \param ctx The ECDH context to use. This must be initialized.
  18732. */
  18733. void mbedtls_ecdh_enable_restart( mbedtls_ecdh_context *ctx );
  18734. #endif /* MBEDTLS_ECP_RESTARTABLE */
  18735. #ifdef __cplusplus
  18736. }
  18737. #endif
  18738. #endif /* ecdh.h */
  18739. /********* Start of file include/mbedtls/sha1.h ************/
  18740. /**
  18741. * \file sha1.h
  18742. *
  18743. * \brief This file contains SHA-1 definitions and functions.
  18744. *
  18745. * The Secure Hash Algorithm 1 (SHA-1) cryptographic hash function is defined in
  18746. * <em>FIPS 180-4: Secure Hash Standard (SHS)</em>.
  18747. *
  18748. * \warning SHA-1 is considered a weak message digest and its use constitutes
  18749. * a security risk. We recommend considering stronger message
  18750. * digests instead.
  18751. */
  18752. /*
  18753. * Copyright The Mbed TLS Contributors
  18754. * SPDX-License-Identifier: Apache-2.0
  18755. *
  18756. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  18757. * not use this file except in compliance with the License.
  18758. * You may obtain a copy of the License at
  18759. *
  18760. * http://www.apache.org/licenses/LICENSE-2.0
  18761. *
  18762. * Unless required by applicable law or agreed to in writing, software
  18763. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  18764. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  18765. * See the License for the specific language governing permissions and
  18766. * limitations under the License.
  18767. */
  18768. #ifndef MBEDTLS_SHA1_H
  18769. #define MBEDTLS_SHA1_H
  18770. #if !defined(MBEDTLS_CONFIG_FILE)
  18771. #else
  18772. #endif
  18773. #include <stddef.h>
  18774. #include <stdint.h>
  18775. /* MBEDTLS_ERR_SHA1_HW_ACCEL_FAILED is deprecated and should not be used. */
  18776. /** SHA-1 hardware accelerator failed */
  18777. #define MBEDTLS_ERR_SHA1_HW_ACCEL_FAILED -0x0035
  18778. /** SHA-1 input data was malformed. */
  18779. #define MBEDTLS_ERR_SHA1_BAD_INPUT_DATA -0x0073
  18780. #ifdef __cplusplus
  18781. extern "C" {
  18782. #endif
  18783. #if !defined(MBEDTLS_SHA1_ALT)
  18784. // Regular implementation
  18785. //
  18786. /**
  18787. * \brief The SHA-1 context structure.
  18788. *
  18789. * \warning SHA-1 is considered a weak message digest and its use
  18790. * constitutes a security risk. We recommend considering
  18791. * stronger message digests instead.
  18792. *
  18793. */
  18794. typedef struct mbedtls_sha1_context
  18795. {
  18796. uint32_t total[2]; /*!< The number of Bytes processed. */
  18797. uint32_t state[5]; /*!< The intermediate digest state. */
  18798. unsigned char buffer[64]; /*!< The data block being processed. */
  18799. }
  18800. mbedtls_sha1_context;
  18801. #else /* MBEDTLS_SHA1_ALT */
  18802. #endif /* MBEDTLS_SHA1_ALT */
  18803. /**
  18804. * \brief This function initializes a SHA-1 context.
  18805. *
  18806. * \warning SHA-1 is considered a weak message digest and its use
  18807. * constitutes a security risk. We recommend considering
  18808. * stronger message digests instead.
  18809. *
  18810. * \param ctx The SHA-1 context to initialize.
  18811. * This must not be \c NULL.
  18812. *
  18813. */
  18814. void mbedtls_sha1_init( mbedtls_sha1_context *ctx );
  18815. /**
  18816. * \brief This function clears a SHA-1 context.
  18817. *
  18818. * \warning SHA-1 is considered a weak message digest and its use
  18819. * constitutes a security risk. We recommend considering
  18820. * stronger message digests instead.
  18821. *
  18822. * \param ctx The SHA-1 context to clear. This may be \c NULL,
  18823. * in which case this function does nothing. If it is
  18824. * not \c NULL, it must point to an initialized
  18825. * SHA-1 context.
  18826. *
  18827. */
  18828. void mbedtls_sha1_free( mbedtls_sha1_context *ctx );
  18829. /**
  18830. * \brief This function clones the state of a SHA-1 context.
  18831. *
  18832. * \warning SHA-1 is considered a weak message digest and its use
  18833. * constitutes a security risk. We recommend considering
  18834. * stronger message digests instead.
  18835. *
  18836. * \param dst The SHA-1 context to clone to. This must be initialized.
  18837. * \param src The SHA-1 context to clone from. This must be initialized.
  18838. *
  18839. */
  18840. void mbedtls_sha1_clone( mbedtls_sha1_context *dst,
  18841. const mbedtls_sha1_context *src );
  18842. /**
  18843. * \brief This function starts a SHA-1 checksum calculation.
  18844. *
  18845. * \warning SHA-1 is considered a weak message digest and its use
  18846. * constitutes a security risk. We recommend considering
  18847. * stronger message digests instead.
  18848. *
  18849. * \param ctx The SHA-1 context to initialize. This must be initialized.
  18850. *
  18851. * \return \c 0 on success.
  18852. * \return A negative error code on failure.
  18853. *
  18854. */
  18855. int mbedtls_sha1_starts_ret( mbedtls_sha1_context *ctx );
  18856. /**
  18857. * \brief This function feeds an input buffer into an ongoing SHA-1
  18858. * checksum calculation.
  18859. *
  18860. * \warning SHA-1 is considered a weak message digest and its use
  18861. * constitutes a security risk. We recommend considering
  18862. * stronger message digests instead.
  18863. *
  18864. * \param ctx The SHA-1 context. This must be initialized
  18865. * and have a hash operation started.
  18866. * \param input The buffer holding the input data.
  18867. * This must be a readable buffer of length \p ilen Bytes.
  18868. * \param ilen The length of the input data \p input in Bytes.
  18869. *
  18870. * \return \c 0 on success.
  18871. * \return A negative error code on failure.
  18872. */
  18873. int mbedtls_sha1_update_ret( mbedtls_sha1_context *ctx,
  18874. const unsigned char *input,
  18875. size_t ilen );
  18876. /**
  18877. * \brief This function finishes the SHA-1 operation, and writes
  18878. * the result to the output buffer.
  18879. *
  18880. * \warning SHA-1 is considered a weak message digest and its use
  18881. * constitutes a security risk. We recommend considering
  18882. * stronger message digests instead.
  18883. *
  18884. * \param ctx The SHA-1 context to use. This must be initialized and
  18885. * have a hash operation started.
  18886. * \param output The SHA-1 checksum result. This must be a writable
  18887. * buffer of length \c 20 Bytes.
  18888. *
  18889. * \return \c 0 on success.
  18890. * \return A negative error code on failure.
  18891. */
  18892. int mbedtls_sha1_finish_ret( mbedtls_sha1_context *ctx,
  18893. unsigned char output[20] );
  18894. /**
  18895. * \brief SHA-1 process data block (internal use only).
  18896. *
  18897. * \warning SHA-1 is considered a weak message digest and its use
  18898. * constitutes a security risk. We recommend considering
  18899. * stronger message digests instead.
  18900. *
  18901. * \param ctx The SHA-1 context to use. This must be initialized.
  18902. * \param data The data block being processed. This must be a
  18903. * readable buffer of length \c 64 Bytes.
  18904. *
  18905. * \return \c 0 on success.
  18906. * \return A negative error code on failure.
  18907. *
  18908. */
  18909. int mbedtls_internal_sha1_process( mbedtls_sha1_context *ctx,
  18910. const unsigned char data[64] );
  18911. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  18912. #if defined(MBEDTLS_DEPRECATED_WARNING)
  18913. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  18914. #else
  18915. #define MBEDTLS_DEPRECATED
  18916. #endif
  18917. /**
  18918. * \brief This function starts a SHA-1 checksum calculation.
  18919. *
  18920. * \warning SHA-1 is considered a weak message digest and its use
  18921. * constitutes a security risk. We recommend considering
  18922. * stronger message digests instead.
  18923. *
  18924. * \deprecated Superseded by mbedtls_sha1_starts_ret() in 2.7.0.
  18925. *
  18926. * \param ctx The SHA-1 context to initialize. This must be initialized.
  18927. *
  18928. */
  18929. MBEDTLS_DEPRECATED void mbedtls_sha1_starts( mbedtls_sha1_context *ctx );
  18930. /**
  18931. * \brief This function feeds an input buffer into an ongoing SHA-1
  18932. * checksum calculation.
  18933. *
  18934. * \warning SHA-1 is considered a weak message digest and its use
  18935. * constitutes a security risk. We recommend considering
  18936. * stronger message digests instead.
  18937. *
  18938. * \deprecated Superseded by mbedtls_sha1_update_ret() in 2.7.0.
  18939. *
  18940. * \param ctx The SHA-1 context. This must be initialized and
  18941. * have a hash operation started.
  18942. * \param input The buffer holding the input data.
  18943. * This must be a readable buffer of length \p ilen Bytes.
  18944. * \param ilen The length of the input data \p input in Bytes.
  18945. *
  18946. */
  18947. MBEDTLS_DEPRECATED void mbedtls_sha1_update( mbedtls_sha1_context *ctx,
  18948. const unsigned char *input,
  18949. size_t ilen );
  18950. /**
  18951. * \brief This function finishes the SHA-1 operation, and writes
  18952. * the result to the output buffer.
  18953. *
  18954. * \warning SHA-1 is considered a weak message digest and its use
  18955. * constitutes a security risk. We recommend considering
  18956. * stronger message digests instead.
  18957. *
  18958. * \deprecated Superseded by mbedtls_sha1_finish_ret() in 2.7.0.
  18959. *
  18960. * \param ctx The SHA-1 context. This must be initialized and
  18961. * have a hash operation started.
  18962. * \param output The SHA-1 checksum result.
  18963. * This must be a writable buffer of length \c 20 Bytes.
  18964. */
  18965. MBEDTLS_DEPRECATED void mbedtls_sha1_finish( mbedtls_sha1_context *ctx,
  18966. unsigned char output[20] );
  18967. /**
  18968. * \brief SHA-1 process data block (internal use only).
  18969. *
  18970. * \warning SHA-1 is considered a weak message digest and its use
  18971. * constitutes a security risk. We recommend considering
  18972. * stronger message digests instead.
  18973. *
  18974. * \deprecated Superseded by mbedtls_internal_sha1_process() in 2.7.0.
  18975. *
  18976. * \param ctx The SHA-1 context. This must be initialized.
  18977. * \param data The data block being processed.
  18978. * This must be a readable buffer of length \c 64 bytes.
  18979. *
  18980. */
  18981. MBEDTLS_DEPRECATED void mbedtls_sha1_process( mbedtls_sha1_context *ctx,
  18982. const unsigned char data[64] );
  18983. #undef MBEDTLS_DEPRECATED
  18984. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  18985. /**
  18986. * \brief This function calculates the SHA-1 checksum of a buffer.
  18987. *
  18988. * The function allocates the context, performs the
  18989. * calculation, and frees the context.
  18990. *
  18991. * The SHA-1 result is calculated as
  18992. * output = SHA-1(input buffer).
  18993. *
  18994. * \warning SHA-1 is considered a weak message digest and its use
  18995. * constitutes a security risk. We recommend considering
  18996. * stronger message digests instead.
  18997. *
  18998. * \param input The buffer holding the input data.
  18999. * This must be a readable buffer of length \p ilen Bytes.
  19000. * \param ilen The length of the input data \p input in Bytes.
  19001. * \param output The SHA-1 checksum result.
  19002. * This must be a writable buffer of length \c 20 Bytes.
  19003. *
  19004. * \return \c 0 on success.
  19005. * \return A negative error code on failure.
  19006. *
  19007. */
  19008. int mbedtls_sha1_ret( const unsigned char *input,
  19009. size_t ilen,
  19010. unsigned char output[20] );
  19011. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  19012. #if defined(MBEDTLS_DEPRECATED_WARNING)
  19013. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  19014. #else
  19015. #define MBEDTLS_DEPRECATED
  19016. #endif
  19017. /**
  19018. * \brief This function calculates the SHA-1 checksum of a buffer.
  19019. *
  19020. * The function allocates the context, performs the
  19021. * calculation, and frees the context.
  19022. *
  19023. * The SHA-1 result is calculated as
  19024. * output = SHA-1(input buffer).
  19025. *
  19026. * \warning SHA-1 is considered a weak message digest and its use
  19027. * constitutes a security risk. We recommend considering
  19028. * stronger message digests instead.
  19029. *
  19030. * \deprecated Superseded by mbedtls_sha1_ret() in 2.7.0
  19031. *
  19032. * \param input The buffer holding the input data.
  19033. * This must be a readable buffer of length \p ilen Bytes.
  19034. * \param ilen The length of the input data \p input in Bytes.
  19035. * \param output The SHA-1 checksum result. This must be a writable
  19036. * buffer of size \c 20 Bytes.
  19037. *
  19038. */
  19039. MBEDTLS_DEPRECATED void mbedtls_sha1( const unsigned char *input,
  19040. size_t ilen,
  19041. unsigned char output[20] );
  19042. #undef MBEDTLS_DEPRECATED
  19043. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  19044. #if defined(MBEDTLS_SELF_TEST)
  19045. /**
  19046. * \brief The SHA-1 checkup routine.
  19047. *
  19048. * \warning SHA-1 is considered a weak message digest and its use
  19049. * constitutes a security risk. We recommend considering
  19050. * stronger message digests instead.
  19051. *
  19052. * \return \c 0 on success.
  19053. * \return \c 1 on failure.
  19054. *
  19055. */
  19056. int mbedtls_sha1_self_test( int verbose );
  19057. #endif /* MBEDTLS_SELF_TEST */
  19058. #ifdef __cplusplus
  19059. }
  19060. #endif
  19061. #endif /* mbedtls_sha1.h */
  19062. /********* Start of file include/mbedtls/sha256.h ************/
  19063. /**
  19064. * \file sha256.h
  19065. *
  19066. * \brief This file contains SHA-224 and SHA-256 definitions and functions.
  19067. *
  19068. * The Secure Hash Algorithms 224 and 256 (SHA-224 and SHA-256) cryptographic
  19069. * hash functions are defined in <em>FIPS 180-4: Secure Hash Standard (SHS)</em>.
  19070. */
  19071. /*
  19072. * Copyright The Mbed TLS Contributors
  19073. * SPDX-License-Identifier: Apache-2.0
  19074. *
  19075. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  19076. * not use this file except in compliance with the License.
  19077. * You may obtain a copy of the License at
  19078. *
  19079. * http://www.apache.org/licenses/LICENSE-2.0
  19080. *
  19081. * Unless required by applicable law or agreed to in writing, software
  19082. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  19083. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  19084. * See the License for the specific language governing permissions and
  19085. * limitations under the License.
  19086. */
  19087. #ifndef MBEDTLS_SHA256_H
  19088. #define MBEDTLS_SHA256_H
  19089. #if !defined(MBEDTLS_CONFIG_FILE)
  19090. #else
  19091. #endif
  19092. #include <stddef.h>
  19093. #include <stdint.h>
  19094. /* MBEDTLS_ERR_SHA256_HW_ACCEL_FAILED is deprecated and should not be used. */
  19095. /** SHA-256 hardware accelerator failed */
  19096. #define MBEDTLS_ERR_SHA256_HW_ACCEL_FAILED -0x0037
  19097. /** SHA-256 input data was malformed. */
  19098. #define MBEDTLS_ERR_SHA256_BAD_INPUT_DATA -0x0074
  19099. #ifdef __cplusplus
  19100. extern "C" {
  19101. #endif
  19102. #if !defined(MBEDTLS_SHA256_ALT)
  19103. // Regular implementation
  19104. //
  19105. /**
  19106. * \brief The SHA-256 context structure.
  19107. *
  19108. * The structure is used both for SHA-256 and for SHA-224
  19109. * checksum calculations. The choice between these two is
  19110. * made in the call to mbedtls_sha256_starts_ret().
  19111. */
  19112. typedef struct mbedtls_sha256_context
  19113. {
  19114. uint32_t total[2]; /*!< The number of Bytes processed. */
  19115. uint32_t state[8]; /*!< The intermediate digest state. */
  19116. unsigned char buffer[64]; /*!< The data block being processed. */
  19117. int is224; /*!< Determines which function to use:
  19118. 0: Use SHA-256, or 1: Use SHA-224. */
  19119. }
  19120. mbedtls_sha256_context;
  19121. #else /* MBEDTLS_SHA256_ALT */
  19122. #endif /* MBEDTLS_SHA256_ALT */
  19123. /**
  19124. * \brief This function initializes a SHA-256 context.
  19125. *
  19126. * \param ctx The SHA-256 context to initialize. This must not be \c NULL.
  19127. */
  19128. void mbedtls_sha256_init( mbedtls_sha256_context *ctx );
  19129. /**
  19130. * \brief This function clears a SHA-256 context.
  19131. *
  19132. * \param ctx The SHA-256 context to clear. This may be \c NULL, in which
  19133. * case this function returns immediately. If it is not \c NULL,
  19134. * it must point to an initialized SHA-256 context.
  19135. */
  19136. void mbedtls_sha256_free( mbedtls_sha256_context *ctx );
  19137. /**
  19138. * \brief This function clones the state of a SHA-256 context.
  19139. *
  19140. * \param dst The destination context. This must be initialized.
  19141. * \param src The context to clone. This must be initialized.
  19142. */
  19143. void mbedtls_sha256_clone( mbedtls_sha256_context *dst,
  19144. const mbedtls_sha256_context *src );
  19145. /**
  19146. * \brief This function starts a SHA-224 or SHA-256 checksum
  19147. * calculation.
  19148. *
  19149. * \param ctx The context to use. This must be initialized.
  19150. * \param is224 This determines which function to use. This must be
  19151. * either \c 0 for SHA-256, or \c 1 for SHA-224.
  19152. *
  19153. * \return \c 0 on success.
  19154. * \return A negative error code on failure.
  19155. */
  19156. int mbedtls_sha256_starts_ret( mbedtls_sha256_context *ctx, int is224 );
  19157. /**
  19158. * \brief This function feeds an input buffer into an ongoing
  19159. * SHA-256 checksum calculation.
  19160. *
  19161. * \param ctx The SHA-256 context. This must be initialized
  19162. * and have a hash operation started.
  19163. * \param input The buffer holding the data. This must be a readable
  19164. * buffer of length \p ilen Bytes.
  19165. * \param ilen The length of the input data in Bytes.
  19166. *
  19167. * \return \c 0 on success.
  19168. * \return A negative error code on failure.
  19169. */
  19170. int mbedtls_sha256_update_ret( mbedtls_sha256_context *ctx,
  19171. const unsigned char *input,
  19172. size_t ilen );
  19173. /**
  19174. * \brief This function finishes the SHA-256 operation, and writes
  19175. * the result to the output buffer.
  19176. *
  19177. * \param ctx The SHA-256 context. This must be initialized
  19178. * and have a hash operation started.
  19179. * \param output The SHA-224 or SHA-256 checksum result.
  19180. * This must be a writable buffer of length \c 32 Bytes.
  19181. *
  19182. * \return \c 0 on success.
  19183. * \return A negative error code on failure.
  19184. */
  19185. int mbedtls_sha256_finish_ret( mbedtls_sha256_context *ctx,
  19186. unsigned char output[32] );
  19187. /**
  19188. * \brief This function processes a single data block within
  19189. * the ongoing SHA-256 computation. This function is for
  19190. * internal use only.
  19191. *
  19192. * \param ctx The SHA-256 context. This must be initialized.
  19193. * \param data The buffer holding one block of data. This must
  19194. * be a readable buffer of length \c 64 Bytes.
  19195. *
  19196. * \return \c 0 on success.
  19197. * \return A negative error code on failure.
  19198. */
  19199. int mbedtls_internal_sha256_process( mbedtls_sha256_context *ctx,
  19200. const unsigned char data[64] );
  19201. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  19202. #if defined(MBEDTLS_DEPRECATED_WARNING)
  19203. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  19204. #else
  19205. #define MBEDTLS_DEPRECATED
  19206. #endif
  19207. /**
  19208. * \brief This function starts a SHA-224 or SHA-256 checksum
  19209. * calculation.
  19210. *
  19211. * \deprecated Superseded by mbedtls_sha256_starts_ret() in 2.7.0.
  19212. *
  19213. * \param ctx The context to use. This must be initialized.
  19214. * \param is224 Determines which function to use. This must be
  19215. * either \c 0 for SHA-256, or \c 1 for SHA-224.
  19216. */
  19217. MBEDTLS_DEPRECATED void mbedtls_sha256_starts( mbedtls_sha256_context *ctx,
  19218. int is224 );
  19219. /**
  19220. * \brief This function feeds an input buffer into an ongoing
  19221. * SHA-256 checksum calculation.
  19222. *
  19223. * \deprecated Superseded by mbedtls_sha256_update_ret() in 2.7.0.
  19224. *
  19225. * \param ctx The SHA-256 context to use. This must be
  19226. * initialized and have a hash operation started.
  19227. * \param input The buffer holding the data. This must be a readable
  19228. * buffer of length \p ilen Bytes.
  19229. * \param ilen The length of the input data in Bytes.
  19230. */
  19231. MBEDTLS_DEPRECATED void mbedtls_sha256_update( mbedtls_sha256_context *ctx,
  19232. const unsigned char *input,
  19233. size_t ilen );
  19234. /**
  19235. * \brief This function finishes the SHA-256 operation, and writes
  19236. * the result to the output buffer.
  19237. *
  19238. * \deprecated Superseded by mbedtls_sha256_finish_ret() in 2.7.0.
  19239. *
  19240. * \param ctx The SHA-256 context. This must be initialized and
  19241. * have a hash operation started.
  19242. * \param output The SHA-224 or SHA-256 checksum result. This must be
  19243. * a writable buffer of length \c 32 Bytes.
  19244. */
  19245. MBEDTLS_DEPRECATED void mbedtls_sha256_finish( mbedtls_sha256_context *ctx,
  19246. unsigned char output[32] );
  19247. /**
  19248. * \brief This function processes a single data block within
  19249. * the ongoing SHA-256 computation. This function is for
  19250. * internal use only.
  19251. *
  19252. * \deprecated Superseded by mbedtls_internal_sha256_process() in 2.7.0.
  19253. *
  19254. * \param ctx The SHA-256 context. This must be initialized.
  19255. * \param data The buffer holding one block of data. This must be
  19256. * a readable buffer of size \c 64 Bytes.
  19257. */
  19258. MBEDTLS_DEPRECATED void mbedtls_sha256_process( mbedtls_sha256_context *ctx,
  19259. const unsigned char data[64] );
  19260. #undef MBEDTLS_DEPRECATED
  19261. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  19262. /**
  19263. * \brief This function calculates the SHA-224 or SHA-256
  19264. * checksum of a buffer.
  19265. *
  19266. * The function allocates the context, performs the
  19267. * calculation, and frees the context.
  19268. *
  19269. * The SHA-256 result is calculated as
  19270. * output = SHA-256(input buffer).
  19271. *
  19272. * \param input The buffer holding the data. This must be a readable
  19273. * buffer of length \p ilen Bytes.
  19274. * \param ilen The length of the input data in Bytes.
  19275. * \param output The SHA-224 or SHA-256 checksum result. This must
  19276. * be a writable buffer of length \c 32 Bytes.
  19277. * \param is224 Determines which function to use. This must be
  19278. * either \c 0 for SHA-256, or \c 1 for SHA-224.
  19279. *
  19280. * \return \c 0 on success.
  19281. * \return A negative error code on failure.
  19282. */
  19283. int mbedtls_sha256_ret( const unsigned char *input,
  19284. size_t ilen,
  19285. unsigned char output[32],
  19286. int is224 );
  19287. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  19288. #if defined(MBEDTLS_DEPRECATED_WARNING)
  19289. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  19290. #else
  19291. #define MBEDTLS_DEPRECATED
  19292. #endif
  19293. /**
  19294. * \brief This function calculates the SHA-224 or SHA-256 checksum
  19295. * of a buffer.
  19296. *
  19297. * The function allocates the context, performs the
  19298. * calculation, and frees the context.
  19299. *
  19300. * The SHA-256 result is calculated as
  19301. * output = SHA-256(input buffer).
  19302. *
  19303. * \deprecated Superseded by mbedtls_sha256_ret() in 2.7.0.
  19304. *
  19305. * \param input The buffer holding the data. This must be a readable
  19306. * buffer of length \p ilen Bytes.
  19307. * \param ilen The length of the input data in Bytes.
  19308. * \param output The SHA-224 or SHA-256 checksum result. This must be
  19309. * a writable buffer of length \c 32 Bytes.
  19310. * \param is224 Determines which function to use. This must be either
  19311. * \c 0 for SHA-256, or \c 1 for SHA-224.
  19312. */
  19313. MBEDTLS_DEPRECATED void mbedtls_sha256( const unsigned char *input,
  19314. size_t ilen,
  19315. unsigned char output[32],
  19316. int is224 );
  19317. #undef MBEDTLS_DEPRECATED
  19318. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  19319. #if defined(MBEDTLS_SELF_TEST)
  19320. /**
  19321. * \brief The SHA-224 and SHA-256 checkup routine.
  19322. *
  19323. * \return \c 0 on success.
  19324. * \return \c 1 on failure.
  19325. */
  19326. int mbedtls_sha256_self_test( int verbose );
  19327. #endif /* MBEDTLS_SELF_TEST */
  19328. #ifdef __cplusplus
  19329. }
  19330. #endif
  19331. #endif /* mbedtls_sha256.h */
  19332. /********* Start of file include/mbedtls/sha512.h ************/
  19333. /**
  19334. * \file sha512.h
  19335. * \brief This file contains SHA-384 and SHA-512 definitions and functions.
  19336. *
  19337. * The Secure Hash Algorithms 384 and 512 (SHA-384 and SHA-512) cryptographic
  19338. * hash functions are defined in <em>FIPS 180-4: Secure Hash Standard (SHS)</em>.
  19339. */
  19340. /*
  19341. * Copyright The Mbed TLS Contributors
  19342. * SPDX-License-Identifier: Apache-2.0
  19343. *
  19344. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  19345. * not use this file except in compliance with the License.
  19346. * You may obtain a copy of the License at
  19347. *
  19348. * http://www.apache.org/licenses/LICENSE-2.0
  19349. *
  19350. * Unless required by applicable law or agreed to in writing, software
  19351. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  19352. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  19353. * See the License for the specific language governing permissions and
  19354. * limitations under the License.
  19355. */
  19356. #ifndef MBEDTLS_SHA512_H
  19357. #define MBEDTLS_SHA512_H
  19358. #if !defined(MBEDTLS_CONFIG_FILE)
  19359. #else
  19360. #endif
  19361. #include <stddef.h>
  19362. #include <stdint.h>
  19363. /* MBEDTLS_ERR_SHA512_HW_ACCEL_FAILED is deprecated and should not be used. */
  19364. /** SHA-512 hardware accelerator failed */
  19365. #define MBEDTLS_ERR_SHA512_HW_ACCEL_FAILED -0x0039
  19366. /** SHA-512 input data was malformed. */
  19367. #define MBEDTLS_ERR_SHA512_BAD_INPUT_DATA -0x0075
  19368. #ifdef __cplusplus
  19369. extern "C" {
  19370. #endif
  19371. #if !defined(MBEDTLS_SHA512_ALT)
  19372. // Regular implementation
  19373. //
  19374. /**
  19375. * \brief The SHA-512 context structure.
  19376. *
  19377. * The structure is used both for SHA-384 and for SHA-512
  19378. * checksum calculations. The choice between these two is
  19379. * made in the call to mbedtls_sha512_starts_ret().
  19380. */
  19381. typedef struct mbedtls_sha512_context
  19382. {
  19383. uint64_t total[2]; /*!< The number of Bytes processed. */
  19384. uint64_t state[8]; /*!< The intermediate digest state. */
  19385. unsigned char buffer[128]; /*!< The data block being processed. */
  19386. #if !defined(MBEDTLS_SHA512_NO_SHA384)
  19387. int is384; /*!< Determines which function to use:
  19388. 0: Use SHA-512, or 1: Use SHA-384. */
  19389. #endif
  19390. }
  19391. mbedtls_sha512_context;
  19392. #else /* MBEDTLS_SHA512_ALT */
  19393. #endif /* MBEDTLS_SHA512_ALT */
  19394. /**
  19395. * \brief This function initializes a SHA-512 context.
  19396. *
  19397. * \param ctx The SHA-512 context to initialize. This must
  19398. * not be \c NULL.
  19399. */
  19400. void mbedtls_sha512_init( mbedtls_sha512_context *ctx );
  19401. /**
  19402. * \brief This function clears a SHA-512 context.
  19403. *
  19404. * \param ctx The SHA-512 context to clear. This may be \c NULL,
  19405. * in which case this function does nothing. If it
  19406. * is not \c NULL, it must point to an initialized
  19407. * SHA-512 context.
  19408. */
  19409. void mbedtls_sha512_free( mbedtls_sha512_context *ctx );
  19410. /**
  19411. * \brief This function clones the state of a SHA-512 context.
  19412. *
  19413. * \param dst The destination context. This must be initialized.
  19414. * \param src The context to clone. This must be initialized.
  19415. */
  19416. void mbedtls_sha512_clone( mbedtls_sha512_context *dst,
  19417. const mbedtls_sha512_context *src );
  19418. /**
  19419. * \brief This function starts a SHA-384 or SHA-512 checksum
  19420. * calculation.
  19421. *
  19422. * \param ctx The SHA-512 context to use. This must be initialized.
  19423. * \param is384 Determines which function to use. This must be
  19424. * either \c 0 for SHA-512, or \c 1 for SHA-384.
  19425. *
  19426. * \note When \c MBEDTLS_SHA512_NO_SHA384 is defined, \p is384 must
  19427. * be \c 0, or the function will return
  19428. * #MBEDTLS_ERR_SHA512_BAD_INPUT_DATA.
  19429. *
  19430. * \return \c 0 on success.
  19431. * \return A negative error code on failure.
  19432. */
  19433. int mbedtls_sha512_starts_ret( mbedtls_sha512_context *ctx, int is384 );
  19434. /**
  19435. * \brief This function feeds an input buffer into an ongoing
  19436. * SHA-512 checksum calculation.
  19437. *
  19438. * \param ctx The SHA-512 context. This must be initialized
  19439. * and have a hash operation started.
  19440. * \param input The buffer holding the input data. This must
  19441. * be a readable buffer of length \p ilen Bytes.
  19442. * \param ilen The length of the input data in Bytes.
  19443. *
  19444. * \return \c 0 on success.
  19445. * \return A negative error code on failure.
  19446. */
  19447. int mbedtls_sha512_update_ret( mbedtls_sha512_context *ctx,
  19448. const unsigned char *input,
  19449. size_t ilen );
  19450. /**
  19451. * \brief This function finishes the SHA-512 operation, and writes
  19452. * the result to the output buffer.
  19453. *
  19454. * \param ctx The SHA-512 context. This must be initialized
  19455. * and have a hash operation started.
  19456. * \param output The SHA-384 or SHA-512 checksum result.
  19457. * This must be a writable buffer of length \c 64 Bytes.
  19458. *
  19459. * \return \c 0 on success.
  19460. * \return A negative error code on failure.
  19461. */
  19462. int mbedtls_sha512_finish_ret( mbedtls_sha512_context *ctx,
  19463. unsigned char output[64] );
  19464. /**
  19465. * \brief This function processes a single data block within
  19466. * the ongoing SHA-512 computation.
  19467. * This function is for internal use only.
  19468. *
  19469. * \param ctx The SHA-512 context. This must be initialized.
  19470. * \param data The buffer holding one block of data. This
  19471. * must be a readable buffer of length \c 128 Bytes.
  19472. *
  19473. * \return \c 0 on success.
  19474. * \return A negative error code on failure.
  19475. */
  19476. int mbedtls_internal_sha512_process( mbedtls_sha512_context *ctx,
  19477. const unsigned char data[128] );
  19478. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  19479. #if defined(MBEDTLS_DEPRECATED_WARNING)
  19480. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  19481. #else
  19482. #define MBEDTLS_DEPRECATED
  19483. #endif
  19484. /**
  19485. * \brief This function starts a SHA-384 or SHA-512 checksum
  19486. * calculation.
  19487. *
  19488. * \deprecated Superseded by mbedtls_sha512_starts_ret() in 2.7.0
  19489. *
  19490. * \param ctx The SHA-512 context to use. This must be initialized.
  19491. * \param is384 Determines which function to use. This must be either
  19492. * \c 0 for SHA-512 or \c 1 for SHA-384.
  19493. *
  19494. * \note When \c MBEDTLS_SHA512_NO_SHA384 is defined, \p is384 must
  19495. * be \c 0, or the function will fail to work.
  19496. */
  19497. MBEDTLS_DEPRECATED void mbedtls_sha512_starts( mbedtls_sha512_context *ctx,
  19498. int is384 );
  19499. /**
  19500. * \brief This function feeds an input buffer into an ongoing
  19501. * SHA-512 checksum calculation.
  19502. *
  19503. * \deprecated Superseded by mbedtls_sha512_update_ret() in 2.7.0.
  19504. *
  19505. * \param ctx The SHA-512 context. This must be initialized
  19506. * and have a hash operation started.
  19507. * \param input The buffer holding the data. This must be a readable
  19508. * buffer of length \p ilen Bytes.
  19509. * \param ilen The length of the input data in Bytes.
  19510. */
  19511. MBEDTLS_DEPRECATED void mbedtls_sha512_update( mbedtls_sha512_context *ctx,
  19512. const unsigned char *input,
  19513. size_t ilen );
  19514. /**
  19515. * \brief This function finishes the SHA-512 operation, and writes
  19516. * the result to the output buffer.
  19517. *
  19518. * \deprecated Superseded by mbedtls_sha512_finish_ret() in 2.7.0.
  19519. *
  19520. * \param ctx The SHA-512 context. This must be initialized
  19521. * and have a hash operation started.
  19522. * \param output The SHA-384 or SHA-512 checksum result. This must
  19523. * be a writable buffer of size \c 64 Bytes.
  19524. */
  19525. MBEDTLS_DEPRECATED void mbedtls_sha512_finish( mbedtls_sha512_context *ctx,
  19526. unsigned char output[64] );
  19527. /**
  19528. * \brief This function processes a single data block within
  19529. * the ongoing SHA-512 computation. This function is for
  19530. * internal use only.
  19531. *
  19532. * \deprecated Superseded by mbedtls_internal_sha512_process() in 2.7.0.
  19533. *
  19534. * \param ctx The SHA-512 context. This must be initialized.
  19535. * \param data The buffer holding one block of data. This must be
  19536. * a readable buffer of length \c 128 Bytes.
  19537. */
  19538. MBEDTLS_DEPRECATED void mbedtls_sha512_process(
  19539. mbedtls_sha512_context *ctx,
  19540. const unsigned char data[128] );
  19541. #undef MBEDTLS_DEPRECATED
  19542. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  19543. /**
  19544. * \brief This function calculates the SHA-512 or SHA-384
  19545. * checksum of a buffer.
  19546. *
  19547. * The function allocates the context, performs the
  19548. * calculation, and frees the context.
  19549. *
  19550. * The SHA-512 result is calculated as
  19551. * output = SHA-512(input buffer).
  19552. *
  19553. * \param input The buffer holding the input data. This must be
  19554. * a readable buffer of length \p ilen Bytes.
  19555. * \param ilen The length of the input data in Bytes.
  19556. * \param output The SHA-384 or SHA-512 checksum result.
  19557. * This must be a writable buffer of length \c 64 Bytes.
  19558. * \param is384 Determines which function to use. This must be either
  19559. * \c 0 for SHA-512, or \c 1 for SHA-384.
  19560. *
  19561. * \note When \c MBEDTLS_SHA512_NO_SHA384 is defined, \p is384 must
  19562. * be \c 0, or the function will return
  19563. * #MBEDTLS_ERR_SHA512_BAD_INPUT_DATA.
  19564. *
  19565. * \return \c 0 on success.
  19566. * \return A negative error code on failure.
  19567. */
  19568. int mbedtls_sha512_ret( const unsigned char *input,
  19569. size_t ilen,
  19570. unsigned char output[64],
  19571. int is384 );
  19572. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  19573. #if defined(MBEDTLS_DEPRECATED_WARNING)
  19574. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  19575. #else
  19576. #define MBEDTLS_DEPRECATED
  19577. #endif
  19578. /**
  19579. * \brief This function calculates the SHA-512 or SHA-384
  19580. * checksum of a buffer.
  19581. *
  19582. * The function allocates the context, performs the
  19583. * calculation, and frees the context.
  19584. *
  19585. * The SHA-512 result is calculated as
  19586. * output = SHA-512(input buffer).
  19587. *
  19588. * \deprecated Superseded by mbedtls_sha512_ret() in 2.7.0
  19589. *
  19590. * \param input The buffer holding the data. This must be a
  19591. * readable buffer of length \p ilen Bytes.
  19592. * \param ilen The length of the input data in Bytes.
  19593. * \param output The SHA-384 or SHA-512 checksum result. This must
  19594. * be a writable buffer of length \c 64 Bytes.
  19595. * \param is384 Determines which function to use. This must be either
  19596. * \c 0 for SHA-512, or \c 1 for SHA-384.
  19597. *
  19598. * \note When \c MBEDTLS_SHA512_NO_SHA384 is defined, \p is384 must
  19599. * be \c 0, or the function will fail to work.
  19600. */
  19601. MBEDTLS_DEPRECATED void mbedtls_sha512( const unsigned char *input,
  19602. size_t ilen,
  19603. unsigned char output[64],
  19604. int is384 );
  19605. #undef MBEDTLS_DEPRECATED
  19606. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  19607. #if defined(MBEDTLS_SELF_TEST)
  19608. /**
  19609. * \brief The SHA-384 or SHA-512 checkup routine.
  19610. *
  19611. * \return \c 0 on success.
  19612. * \return \c 1 on failure.
  19613. */
  19614. int mbedtls_sha512_self_test( int verbose );
  19615. #endif /* MBEDTLS_SELF_TEST */
  19616. #ifdef __cplusplus
  19617. }
  19618. #endif
  19619. #endif /* mbedtls_sha512.h */
  19620. /********* Start of file include/mbedtls/aes.h ************/
  19621. /**
  19622. * \file aes.h
  19623. *
  19624. * \brief This file contains AES definitions and functions.
  19625. *
  19626. * The Advanced Encryption Standard (AES) specifies a FIPS-approved
  19627. * cryptographic algorithm that can be used to protect electronic
  19628. * data.
  19629. *
  19630. * The AES algorithm is a symmetric block cipher that can
  19631. * encrypt and decrypt information. For more information, see
  19632. * <em>FIPS Publication 197: Advanced Encryption Standard</em> and
  19633. * <em>ISO/IEC 18033-2:2006: Information technology -- Security
  19634. * techniques -- Encryption algorithms -- Part 2: Asymmetric
  19635. * ciphers</em>.
  19636. *
  19637. * The AES-XTS block mode is standardized by NIST SP 800-38E
  19638. * <https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-38e.pdf>
  19639. * and described in detail by IEEE P1619
  19640. * <https://ieeexplore.ieee.org/servlet/opac?punumber=4375278>.
  19641. */
  19642. /*
  19643. * Copyright The Mbed TLS Contributors
  19644. * SPDX-License-Identifier: Apache-2.0
  19645. *
  19646. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  19647. * not use this file except in compliance with the License.
  19648. * You may obtain a copy of the License at
  19649. *
  19650. * http://www.apache.org/licenses/LICENSE-2.0
  19651. *
  19652. * Unless required by applicable law or agreed to in writing, software
  19653. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  19654. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  19655. * See the License for the specific language governing permissions and
  19656. * limitations under the License.
  19657. */
  19658. #ifndef MBEDTLS_AES_H
  19659. #define MBEDTLS_AES_H
  19660. #if !defined(MBEDTLS_CONFIG_FILE)
  19661. #else
  19662. #endif
  19663. #include <stddef.h>
  19664. #include <stdint.h>
  19665. /* padlock.c and aesni.c rely on these values! */
  19666. #define MBEDTLS_AES_ENCRYPT 1 /**< AES encryption. */
  19667. #define MBEDTLS_AES_DECRYPT 0 /**< AES decryption. */
  19668. /* Error codes in range 0x0020-0x0022 */
  19669. /** Invalid key length. */
  19670. #define MBEDTLS_ERR_AES_INVALID_KEY_LENGTH -0x0020
  19671. /** Invalid data input length. */
  19672. #define MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH -0x0022
  19673. /* Error codes in range 0x0021-0x0025 */
  19674. /** Invalid input data. */
  19675. #define MBEDTLS_ERR_AES_BAD_INPUT_DATA -0x0021
  19676. /* MBEDTLS_ERR_AES_FEATURE_UNAVAILABLE is deprecated and should not be used. */
  19677. /** Feature not available. For example, an unsupported AES key size. */
  19678. #define MBEDTLS_ERR_AES_FEATURE_UNAVAILABLE -0x0023
  19679. /* MBEDTLS_ERR_AES_HW_ACCEL_FAILED is deprecated and should not be used. */
  19680. /** AES hardware accelerator failed. */
  19681. #define MBEDTLS_ERR_AES_HW_ACCEL_FAILED -0x0025
  19682. #if ( defined(__ARMCC_VERSION) || defined(_MSC_VER) ) && \
  19683. !defined(inline) && !defined(__cplusplus)
  19684. #define inline __inline
  19685. #endif
  19686. #ifdef __cplusplus
  19687. extern "C" {
  19688. #endif
  19689. #if !defined(MBEDTLS_AES_ALT)
  19690. // Regular implementation
  19691. //
  19692. /**
  19693. * \brief The AES context-type definition.
  19694. */
  19695. typedef struct mbedtls_aes_context
  19696. {
  19697. int nr; /*!< The number of rounds. */
  19698. uint32_t *rk; /*!< AES round keys. */
  19699. uint32_t buf[68]; /*!< Unaligned data buffer. This buffer can
  19700. hold 32 extra Bytes, which can be used for
  19701. one of the following purposes:
  19702. <ul><li>Alignment if VIA padlock is
  19703. used.</li>
  19704. <li>Simplifying key expansion in the 256-bit
  19705. case by generating an extra round key.
  19706. </li></ul> */
  19707. }
  19708. mbedtls_aes_context;
  19709. #if defined(MBEDTLS_CIPHER_MODE_XTS)
  19710. /**
  19711. * \brief The AES XTS context-type definition.
  19712. */
  19713. typedef struct mbedtls_aes_xts_context
  19714. {
  19715. mbedtls_aes_context crypt; /*!< The AES context to use for AES block
  19716. encryption or decryption. */
  19717. mbedtls_aes_context tweak; /*!< The AES context used for tweak
  19718. computation. */
  19719. } mbedtls_aes_xts_context;
  19720. #endif /* MBEDTLS_CIPHER_MODE_XTS */
  19721. #else /* MBEDTLS_AES_ALT */
  19722. #endif /* MBEDTLS_AES_ALT */
  19723. /**
  19724. * \brief This function initializes the specified AES context.
  19725. *
  19726. * It must be the first API called before using
  19727. * the context.
  19728. *
  19729. * \param ctx The AES context to initialize. This must not be \c NULL.
  19730. */
  19731. void mbedtls_aes_init( mbedtls_aes_context *ctx );
  19732. /**
  19733. * \brief This function releases and clears the specified AES context.
  19734. *
  19735. * \param ctx The AES context to clear.
  19736. * If this is \c NULL, this function does nothing.
  19737. * Otherwise, the context must have been at least initialized.
  19738. */
  19739. void mbedtls_aes_free( mbedtls_aes_context *ctx );
  19740. #if defined(MBEDTLS_CIPHER_MODE_XTS)
  19741. /**
  19742. * \brief This function initializes the specified AES XTS context.
  19743. *
  19744. * It must be the first API called before using
  19745. * the context.
  19746. *
  19747. * \param ctx The AES XTS context to initialize. This must not be \c NULL.
  19748. */
  19749. void mbedtls_aes_xts_init( mbedtls_aes_xts_context *ctx );
  19750. /**
  19751. * \brief This function releases and clears the specified AES XTS context.
  19752. *
  19753. * \param ctx The AES XTS context to clear.
  19754. * If this is \c NULL, this function does nothing.
  19755. * Otherwise, the context must have been at least initialized.
  19756. */
  19757. void mbedtls_aes_xts_free( mbedtls_aes_xts_context *ctx );
  19758. #endif /* MBEDTLS_CIPHER_MODE_XTS */
  19759. /**
  19760. * \brief This function sets the encryption key.
  19761. *
  19762. * \param ctx The AES context to which the key should be bound.
  19763. * It must be initialized.
  19764. * \param key The encryption key.
  19765. * This must be a readable buffer of size \p keybits bits.
  19766. * \param keybits The size of data passed in bits. Valid options are:
  19767. * <ul><li>128 bits</li>
  19768. * <li>192 bits</li>
  19769. * <li>256 bits</li></ul>
  19770. *
  19771. * \return \c 0 on success.
  19772. * \return #MBEDTLS_ERR_AES_INVALID_KEY_LENGTH on failure.
  19773. */
  19774. MBEDTLS_CHECK_RETURN_TYPICAL
  19775. int mbedtls_aes_setkey_enc( mbedtls_aes_context *ctx, const unsigned char *key,
  19776. unsigned int keybits );
  19777. /**
  19778. * \brief This function sets the decryption key.
  19779. *
  19780. * \param ctx The AES context to which the key should be bound.
  19781. * It must be initialized.
  19782. * \param key The decryption key.
  19783. * This must be a readable buffer of size \p keybits bits.
  19784. * \param keybits The size of data passed. Valid options are:
  19785. * <ul><li>128 bits</li>
  19786. * <li>192 bits</li>
  19787. * <li>256 bits</li></ul>
  19788. *
  19789. * \return \c 0 on success.
  19790. * \return #MBEDTLS_ERR_AES_INVALID_KEY_LENGTH on failure.
  19791. */
  19792. MBEDTLS_CHECK_RETURN_TYPICAL
  19793. int mbedtls_aes_setkey_dec( mbedtls_aes_context *ctx, const unsigned char *key,
  19794. unsigned int keybits );
  19795. #if defined(MBEDTLS_CIPHER_MODE_XTS)
  19796. /**
  19797. * \brief This function prepares an XTS context for encryption and
  19798. * sets the encryption key.
  19799. *
  19800. * \param ctx The AES XTS context to which the key should be bound.
  19801. * It must be initialized.
  19802. * \param key The encryption key. This is comprised of the XTS key1
  19803. * concatenated with the XTS key2.
  19804. * This must be a readable buffer of size \p keybits bits.
  19805. * \param keybits The size of \p key passed in bits. Valid options are:
  19806. * <ul><li>256 bits (each of key1 and key2 is a 128-bit key)</li>
  19807. * <li>512 bits (each of key1 and key2 is a 256-bit key)</li></ul>
  19808. *
  19809. * \return \c 0 on success.
  19810. * \return #MBEDTLS_ERR_AES_INVALID_KEY_LENGTH on failure.
  19811. */
  19812. MBEDTLS_CHECK_RETURN_TYPICAL
  19813. int mbedtls_aes_xts_setkey_enc( mbedtls_aes_xts_context *ctx,
  19814. const unsigned char *key,
  19815. unsigned int keybits );
  19816. /**
  19817. * \brief This function prepares an XTS context for decryption and
  19818. * sets the decryption key.
  19819. *
  19820. * \param ctx The AES XTS context to which the key should be bound.
  19821. * It must be initialized.
  19822. * \param key The decryption key. This is comprised of the XTS key1
  19823. * concatenated with the XTS key2.
  19824. * This must be a readable buffer of size \p keybits bits.
  19825. * \param keybits The size of \p key passed in bits. Valid options are:
  19826. * <ul><li>256 bits (each of key1 and key2 is a 128-bit key)</li>
  19827. * <li>512 bits (each of key1 and key2 is a 256-bit key)</li></ul>
  19828. *
  19829. * \return \c 0 on success.
  19830. * \return #MBEDTLS_ERR_AES_INVALID_KEY_LENGTH on failure.
  19831. */
  19832. MBEDTLS_CHECK_RETURN_TYPICAL
  19833. int mbedtls_aes_xts_setkey_dec( mbedtls_aes_xts_context *ctx,
  19834. const unsigned char *key,
  19835. unsigned int keybits );
  19836. #endif /* MBEDTLS_CIPHER_MODE_XTS */
  19837. /**
  19838. * \brief This function performs an AES single-block encryption or
  19839. * decryption operation.
  19840. *
  19841. * It performs the operation defined in the \p mode parameter
  19842. * (encrypt or decrypt), on the input data buffer defined in
  19843. * the \p input parameter.
  19844. *
  19845. * mbedtls_aes_init(), and either mbedtls_aes_setkey_enc() or
  19846. * mbedtls_aes_setkey_dec() must be called before the first
  19847. * call to this API with the same context.
  19848. *
  19849. * \param ctx The AES context to use for encryption or decryption.
  19850. * It must be initialized and bound to a key.
  19851. * \param mode The AES operation: #MBEDTLS_AES_ENCRYPT or
  19852. * #MBEDTLS_AES_DECRYPT.
  19853. * \param input The buffer holding the input data.
  19854. * It must be readable and at least \c 16 Bytes long.
  19855. * \param output The buffer where the output data will be written.
  19856. * It must be writeable and at least \c 16 Bytes long.
  19857. * \return \c 0 on success.
  19858. */
  19859. MBEDTLS_CHECK_RETURN_TYPICAL
  19860. int mbedtls_aes_crypt_ecb( mbedtls_aes_context *ctx,
  19861. int mode,
  19862. const unsigned char input[16],
  19863. unsigned char output[16] );
  19864. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  19865. /**
  19866. * \brief This function performs an AES-CBC encryption or decryption operation
  19867. * on full blocks.
  19868. *
  19869. * It performs the operation defined in the \p mode
  19870. * parameter (encrypt/decrypt), on the input data buffer defined in
  19871. * the \p input parameter.
  19872. *
  19873. * It can be called as many times as needed, until all the input
  19874. * data is processed. mbedtls_aes_init(), and either
  19875. * mbedtls_aes_setkey_enc() or mbedtls_aes_setkey_dec() must be called
  19876. * before the first call to this API with the same context.
  19877. *
  19878. * \note This function operates on full blocks, that is, the input size
  19879. * must be a multiple of the AES block size of \c 16 Bytes.
  19880. *
  19881. * \note Upon exit, the content of the IV is updated so that you can
  19882. * call the same function again on the next
  19883. * block(s) of data and get the same result as if it was
  19884. * encrypted in one call. This allows a "streaming" usage.
  19885. * If you need to retain the contents of the IV, you should
  19886. * either save it manually or use the cipher module instead.
  19887. *
  19888. *
  19889. * \param ctx The AES context to use for encryption or decryption.
  19890. * It must be initialized and bound to a key.
  19891. * \param mode The AES operation: #MBEDTLS_AES_ENCRYPT or
  19892. * #MBEDTLS_AES_DECRYPT.
  19893. * \param length The length of the input data in Bytes. This must be a
  19894. * multiple of the block size (\c 16 Bytes).
  19895. * \param iv Initialization vector (updated after use).
  19896. * It must be a readable and writeable buffer of \c 16 Bytes.
  19897. * \param input The buffer holding the input data.
  19898. * It must be readable and of size \p length Bytes.
  19899. * \param output The buffer holding the output data.
  19900. * It must be writeable and of size \p length Bytes.
  19901. *
  19902. * \return \c 0 on success.
  19903. * \return #MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH
  19904. * on failure.
  19905. */
  19906. MBEDTLS_CHECK_RETURN_TYPICAL
  19907. int mbedtls_aes_crypt_cbc( mbedtls_aes_context *ctx,
  19908. int mode,
  19909. size_t length,
  19910. unsigned char iv[16],
  19911. const unsigned char *input,
  19912. unsigned char *output );
  19913. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  19914. #if defined(MBEDTLS_CIPHER_MODE_XTS)
  19915. /**
  19916. * \brief This function performs an AES-XTS encryption or decryption
  19917. * operation for an entire XTS data unit.
  19918. *
  19919. * AES-XTS encrypts or decrypts blocks based on their location as
  19920. * defined by a data unit number. The data unit number must be
  19921. * provided by \p data_unit.
  19922. *
  19923. * NIST SP 800-38E limits the maximum size of a data unit to 2^20
  19924. * AES blocks. If the data unit is larger than this, this function
  19925. * returns #MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH.
  19926. *
  19927. * \param ctx The AES XTS context to use for AES XTS operations.
  19928. * It must be initialized and bound to a key.
  19929. * \param mode The AES operation: #MBEDTLS_AES_ENCRYPT or
  19930. * #MBEDTLS_AES_DECRYPT.
  19931. * \param length The length of a data unit in Bytes. This can be any
  19932. * length between 16 bytes and 2^24 bytes inclusive
  19933. * (between 1 and 2^20 block cipher blocks).
  19934. * \param data_unit The address of the data unit encoded as an array of 16
  19935. * bytes in little-endian format. For disk encryption, this
  19936. * is typically the index of the block device sector that
  19937. * contains the data.
  19938. * \param input The buffer holding the input data (which is an entire
  19939. * data unit). This function reads \p length Bytes from \p
  19940. * input.
  19941. * \param output The buffer holding the output data (which is an entire
  19942. * data unit). This function writes \p length Bytes to \p
  19943. * output.
  19944. *
  19945. * \return \c 0 on success.
  19946. * \return #MBEDTLS_ERR_AES_INVALID_INPUT_LENGTH if \p length is
  19947. * smaller than an AES block in size (16 Bytes) or if \p
  19948. * length is larger than 2^20 blocks (16 MiB).
  19949. */
  19950. MBEDTLS_CHECK_RETURN_TYPICAL
  19951. int mbedtls_aes_crypt_xts( mbedtls_aes_xts_context *ctx,
  19952. int mode,
  19953. size_t length,
  19954. const unsigned char data_unit[16],
  19955. const unsigned char *input,
  19956. unsigned char *output );
  19957. #endif /* MBEDTLS_CIPHER_MODE_XTS */
  19958. #if defined(MBEDTLS_CIPHER_MODE_CFB)
  19959. /**
  19960. * \brief This function performs an AES-CFB128 encryption or decryption
  19961. * operation.
  19962. *
  19963. * It performs the operation defined in the \p mode
  19964. * parameter (encrypt or decrypt), on the input data buffer
  19965. * defined in the \p input parameter.
  19966. *
  19967. * For CFB, you must set up the context with mbedtls_aes_setkey_enc(),
  19968. * regardless of whether you are performing an encryption or decryption
  19969. * operation, that is, regardless of the \p mode parameter. This is
  19970. * because CFB mode uses the same key schedule for encryption and
  19971. * decryption.
  19972. *
  19973. * \note Upon exit, the content of the IV is updated so that you can
  19974. * call the same function again on the next
  19975. * block(s) of data and get the same result as if it was
  19976. * encrypted in one call. This allows a "streaming" usage.
  19977. * If you need to retain the contents of the
  19978. * IV, you must either save it manually or use the cipher
  19979. * module instead.
  19980. *
  19981. *
  19982. * \param ctx The AES context to use for encryption or decryption.
  19983. * It must be initialized and bound to a key.
  19984. * \param mode The AES operation: #MBEDTLS_AES_ENCRYPT or
  19985. * #MBEDTLS_AES_DECRYPT.
  19986. * \param length The length of the input data in Bytes.
  19987. * \param iv_off The offset in IV (updated after use).
  19988. * It must point to a valid \c size_t.
  19989. * \param iv The initialization vector (updated after use).
  19990. * It must be a readable and writeable buffer of \c 16 Bytes.
  19991. * \param input The buffer holding the input data.
  19992. * It must be readable and of size \p length Bytes.
  19993. * \param output The buffer holding the output data.
  19994. * It must be writeable and of size \p length Bytes.
  19995. *
  19996. * \return \c 0 on success.
  19997. */
  19998. MBEDTLS_CHECK_RETURN_TYPICAL
  19999. int mbedtls_aes_crypt_cfb128( mbedtls_aes_context *ctx,
  20000. int mode,
  20001. size_t length,
  20002. size_t *iv_off,
  20003. unsigned char iv[16],
  20004. const unsigned char *input,
  20005. unsigned char *output );
  20006. /**
  20007. * \brief This function performs an AES-CFB8 encryption or decryption
  20008. * operation.
  20009. *
  20010. * It performs the operation defined in the \p mode
  20011. * parameter (encrypt/decrypt), on the input data buffer defined
  20012. * in the \p input parameter.
  20013. *
  20014. * Due to the nature of CFB, you must use the same key schedule for
  20015. * both encryption and decryption operations. Therefore, you must
  20016. * use the context initialized with mbedtls_aes_setkey_enc() for
  20017. * both #MBEDTLS_AES_ENCRYPT and #MBEDTLS_AES_DECRYPT.
  20018. *
  20019. * \note Upon exit, the content of the IV is updated so that you can
  20020. * call the same function again on the next
  20021. * block(s) of data and get the same result as if it was
  20022. * encrypted in one call. This allows a "streaming" usage.
  20023. * If you need to retain the contents of the
  20024. * IV, you should either save it manually or use the cipher
  20025. * module instead.
  20026. *
  20027. *
  20028. * \param ctx The AES context to use for encryption or decryption.
  20029. * It must be initialized and bound to a key.
  20030. * \param mode The AES operation: #MBEDTLS_AES_ENCRYPT or
  20031. * #MBEDTLS_AES_DECRYPT
  20032. * \param length The length of the input data.
  20033. * \param iv The initialization vector (updated after use).
  20034. * It must be a readable and writeable buffer of \c 16 Bytes.
  20035. * \param input The buffer holding the input data.
  20036. * It must be readable and of size \p length Bytes.
  20037. * \param output The buffer holding the output data.
  20038. * It must be writeable and of size \p length Bytes.
  20039. *
  20040. * \return \c 0 on success.
  20041. */
  20042. MBEDTLS_CHECK_RETURN_TYPICAL
  20043. int mbedtls_aes_crypt_cfb8( mbedtls_aes_context *ctx,
  20044. int mode,
  20045. size_t length,
  20046. unsigned char iv[16],
  20047. const unsigned char *input,
  20048. unsigned char *output );
  20049. #endif /*MBEDTLS_CIPHER_MODE_CFB */
  20050. #if defined(MBEDTLS_CIPHER_MODE_OFB)
  20051. /**
  20052. * \brief This function performs an AES-OFB (Output Feedback Mode)
  20053. * encryption or decryption operation.
  20054. *
  20055. * For OFB, you must set up the context with
  20056. * mbedtls_aes_setkey_enc(), regardless of whether you are
  20057. * performing an encryption or decryption operation. This is
  20058. * because OFB mode uses the same key schedule for encryption and
  20059. * decryption.
  20060. *
  20061. * The OFB operation is identical for encryption or decryption,
  20062. * therefore no operation mode needs to be specified.
  20063. *
  20064. * \note Upon exit, the content of iv, the Initialisation Vector, is
  20065. * updated so that you can call the same function again on the next
  20066. * block(s) of data and get the same result as if it was encrypted
  20067. * in one call. This allows a "streaming" usage, by initialising
  20068. * iv_off to 0 before the first call, and preserving its value
  20069. * between calls.
  20070. *
  20071. * For non-streaming use, the iv should be initialised on each call
  20072. * to a unique value, and iv_off set to 0 on each call.
  20073. *
  20074. * If you need to retain the contents of the initialisation vector,
  20075. * you must either save it manually or use the cipher module
  20076. * instead.
  20077. *
  20078. * \warning For the OFB mode, the initialisation vector must be unique
  20079. * every encryption operation. Reuse of an initialisation vector
  20080. * will compromise security.
  20081. *
  20082. * \param ctx The AES context to use for encryption or decryption.
  20083. * It must be initialized and bound to a key.
  20084. * \param length The length of the input data.
  20085. * \param iv_off The offset in IV (updated after use).
  20086. * It must point to a valid \c size_t.
  20087. * \param iv The initialization vector (updated after use).
  20088. * It must be a readable and writeable buffer of \c 16 Bytes.
  20089. * \param input The buffer holding the input data.
  20090. * It must be readable and of size \p length Bytes.
  20091. * \param output The buffer holding the output data.
  20092. * It must be writeable and of size \p length Bytes.
  20093. *
  20094. * \return \c 0 on success.
  20095. */
  20096. MBEDTLS_CHECK_RETURN_TYPICAL
  20097. int mbedtls_aes_crypt_ofb( mbedtls_aes_context *ctx,
  20098. size_t length,
  20099. size_t *iv_off,
  20100. unsigned char iv[16],
  20101. const unsigned char *input,
  20102. unsigned char *output );
  20103. #endif /* MBEDTLS_CIPHER_MODE_OFB */
  20104. #if defined(MBEDTLS_CIPHER_MODE_CTR)
  20105. /**
  20106. * \brief This function performs an AES-CTR encryption or decryption
  20107. * operation.
  20108. *
  20109. * Due to the nature of CTR, you must use the same key schedule
  20110. * for both encryption and decryption operations. Therefore, you
  20111. * must use the context initialized with mbedtls_aes_setkey_enc()
  20112. * for both #MBEDTLS_AES_ENCRYPT and #MBEDTLS_AES_DECRYPT.
  20113. *
  20114. * \warning You must never reuse a nonce value with the same key. Doing so
  20115. * would void the encryption for the two messages encrypted with
  20116. * the same nonce and key.
  20117. *
  20118. * There are two common strategies for managing nonces with CTR:
  20119. *
  20120. * 1. You can handle everything as a single message processed over
  20121. * successive calls to this function. In that case, you want to
  20122. * set \p nonce_counter and \p nc_off to 0 for the first call, and
  20123. * then preserve the values of \p nonce_counter, \p nc_off and \p
  20124. * stream_block across calls to this function as they will be
  20125. * updated by this function.
  20126. *
  20127. * With this strategy, you must not encrypt more than 2**128
  20128. * blocks of data with the same key.
  20129. *
  20130. * 2. You can encrypt separate messages by dividing the \p
  20131. * nonce_counter buffer in two areas: the first one used for a
  20132. * per-message nonce, handled by yourself, and the second one
  20133. * updated by this function internally.
  20134. *
  20135. * For example, you might reserve the first 12 bytes for the
  20136. * per-message nonce, and the last 4 bytes for internal use. In that
  20137. * case, before calling this function on a new message you need to
  20138. * set the first 12 bytes of \p nonce_counter to your chosen nonce
  20139. * value, the last 4 to 0, and \p nc_off to 0 (which will cause \p
  20140. * stream_block to be ignored). That way, you can encrypt at most
  20141. * 2**96 messages of up to 2**32 blocks each with the same key.
  20142. *
  20143. * The per-message nonce (or information sufficient to reconstruct
  20144. * it) needs to be communicated with the ciphertext and must be unique.
  20145. * The recommended way to ensure uniqueness is to use a message
  20146. * counter. An alternative is to generate random nonces, but this
  20147. * limits the number of messages that can be securely encrypted:
  20148. * for example, with 96-bit random nonces, you should not encrypt
  20149. * more than 2**32 messages with the same key.
  20150. *
  20151. * Note that for both stategies, sizes are measured in blocks and
  20152. * that an AES block is 16 bytes.
  20153. *
  20154. * \warning Upon return, \p stream_block contains sensitive data. Its
  20155. * content must not be written to insecure storage and should be
  20156. * securely discarded as soon as it's no longer needed.
  20157. *
  20158. * \param ctx The AES context to use for encryption or decryption.
  20159. * It must be initialized and bound to a key.
  20160. * \param length The length of the input data.
  20161. * \param nc_off The offset in the current \p stream_block, for
  20162. * resuming within the current cipher stream. The
  20163. * offset pointer should be 0 at the start of a stream.
  20164. * It must point to a valid \c size_t.
  20165. * \param nonce_counter The 128-bit nonce and counter.
  20166. * It must be a readable-writeable buffer of \c 16 Bytes.
  20167. * \param stream_block The saved stream block for resuming. This is
  20168. * overwritten by the function.
  20169. * It must be a readable-writeable buffer of \c 16 Bytes.
  20170. * \param input The buffer holding the input data.
  20171. * It must be readable and of size \p length Bytes.
  20172. * \param output The buffer holding the output data.
  20173. * It must be writeable and of size \p length Bytes.
  20174. *
  20175. * \return \c 0 on success.
  20176. */
  20177. MBEDTLS_CHECK_RETURN_TYPICAL
  20178. int mbedtls_aes_crypt_ctr( mbedtls_aes_context *ctx,
  20179. size_t length,
  20180. size_t *nc_off,
  20181. unsigned char nonce_counter[16],
  20182. unsigned char stream_block[16],
  20183. const unsigned char *input,
  20184. unsigned char *output );
  20185. #endif /* MBEDTLS_CIPHER_MODE_CTR */
  20186. /**
  20187. * \brief Internal AES block encryption function. This is only
  20188. * exposed to allow overriding it using
  20189. * \c MBEDTLS_AES_ENCRYPT_ALT.
  20190. *
  20191. * \param ctx The AES context to use for encryption.
  20192. * \param input The plaintext block.
  20193. * \param output The output (ciphertext) block.
  20194. *
  20195. * \return \c 0 on success.
  20196. */
  20197. MBEDTLS_CHECK_RETURN_TYPICAL
  20198. int mbedtls_internal_aes_encrypt( mbedtls_aes_context *ctx,
  20199. const unsigned char input[16],
  20200. unsigned char output[16] );
  20201. /**
  20202. * \brief Internal AES block decryption function. This is only
  20203. * exposed to allow overriding it using see
  20204. * \c MBEDTLS_AES_DECRYPT_ALT.
  20205. *
  20206. * \param ctx The AES context to use for decryption.
  20207. * \param input The ciphertext block.
  20208. * \param output The output (plaintext) block.
  20209. *
  20210. * \return \c 0 on success.
  20211. */
  20212. MBEDTLS_CHECK_RETURN_TYPICAL
  20213. int mbedtls_internal_aes_decrypt( mbedtls_aes_context *ctx,
  20214. const unsigned char input[16],
  20215. unsigned char output[16] );
  20216. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  20217. #if defined(MBEDTLS_DEPRECATED_WARNING)
  20218. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  20219. #else
  20220. #define MBEDTLS_DEPRECATED
  20221. #endif
  20222. /**
  20223. * \brief Deprecated internal AES block encryption function
  20224. * without return value.
  20225. *
  20226. * \deprecated Superseded by mbedtls_internal_aes_encrypt()
  20227. *
  20228. * \param ctx The AES context to use for encryption.
  20229. * \param input Plaintext block.
  20230. * \param output Output (ciphertext) block.
  20231. */
  20232. MBEDTLS_DEPRECATED void mbedtls_aes_encrypt( mbedtls_aes_context *ctx,
  20233. const unsigned char input[16],
  20234. unsigned char output[16] );
  20235. /**
  20236. * \brief Deprecated internal AES block decryption function
  20237. * without return value.
  20238. *
  20239. * \deprecated Superseded by mbedtls_internal_aes_decrypt()
  20240. *
  20241. * \param ctx The AES context to use for decryption.
  20242. * \param input Ciphertext block.
  20243. * \param output Output (plaintext) block.
  20244. */
  20245. MBEDTLS_DEPRECATED void mbedtls_aes_decrypt( mbedtls_aes_context *ctx,
  20246. const unsigned char input[16],
  20247. unsigned char output[16] );
  20248. #undef MBEDTLS_DEPRECATED
  20249. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  20250. #if defined(MBEDTLS_SELF_TEST)
  20251. /**
  20252. * \brief Checkup routine.
  20253. *
  20254. * \return \c 0 on success.
  20255. * \return \c 1 on failure.
  20256. */
  20257. MBEDTLS_CHECK_RETURN_CRITICAL
  20258. int mbedtls_aes_self_test( int verbose );
  20259. #endif /* MBEDTLS_SELF_TEST */
  20260. #ifdef __cplusplus
  20261. }
  20262. #endif
  20263. #endif /* aes.h */
  20264. /********* Start of file include/mbedtls/aesni.h ************/
  20265. /**
  20266. * \file aesni.h
  20267. *
  20268. * \brief AES-NI for hardware AES acceleration on some Intel processors
  20269. *
  20270. * \warning These functions are only for internal use by other library
  20271. * functions; you must not call them directly.
  20272. */
  20273. /*
  20274. * Copyright The Mbed TLS Contributors
  20275. * SPDX-License-Identifier: Apache-2.0
  20276. *
  20277. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  20278. * not use this file except in compliance with the License.
  20279. * You may obtain a copy of the License at
  20280. *
  20281. * http://www.apache.org/licenses/LICENSE-2.0
  20282. *
  20283. * Unless required by applicable law or agreed to in writing, software
  20284. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  20285. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  20286. * See the License for the specific language governing permissions and
  20287. * limitations under the License.
  20288. */
  20289. #ifndef MBEDTLS_AESNI_H
  20290. #define MBEDTLS_AESNI_H
  20291. #if !defined(MBEDTLS_CONFIG_FILE)
  20292. #else
  20293. #endif
  20294. #define MBEDTLS_AESNI_AES 0x02000000u
  20295. #define MBEDTLS_AESNI_CLMUL 0x00000002u
  20296. #if defined(MBEDTLS_HAVE_ASM) && defined(__GNUC__) && \
  20297. ( defined(__amd64__) || defined(__x86_64__) ) && \
  20298. ! defined(MBEDTLS_HAVE_X86_64)
  20299. #define MBEDTLS_HAVE_X86_64
  20300. #endif
  20301. #if defined(MBEDTLS_HAVE_X86_64)
  20302. #ifdef __cplusplus
  20303. extern "C" {
  20304. #endif
  20305. /**
  20306. * \brief Internal function to detect the AES-NI feature in CPUs.
  20307. *
  20308. * \note This function is only for internal use by other library
  20309. * functions; you must not call it directly.
  20310. *
  20311. * \param what The feature to detect
  20312. * (MBEDTLS_AESNI_AES or MBEDTLS_AESNI_CLMUL)
  20313. *
  20314. * \return 1 if CPU has support for the feature, 0 otherwise
  20315. */
  20316. int mbedtls_aesni_has_support( unsigned int what );
  20317. /**
  20318. * \brief Internal AES-NI AES-ECB block encryption and decryption
  20319. *
  20320. * \note This function is only for internal use by other library
  20321. * functions; you must not call it directly.
  20322. *
  20323. * \param ctx AES context
  20324. * \param mode MBEDTLS_AES_ENCRYPT or MBEDTLS_AES_DECRYPT
  20325. * \param input 16-byte input block
  20326. * \param output 16-byte output block
  20327. *
  20328. * \return 0 on success (cannot fail)
  20329. */
  20330. int mbedtls_aesni_crypt_ecb( mbedtls_aes_context *ctx,
  20331. int mode,
  20332. const unsigned char input[16],
  20333. unsigned char output[16] );
  20334. /**
  20335. * \brief Internal GCM multiplication: c = a * b in GF(2^128)
  20336. *
  20337. * \note This function is only for internal use by other library
  20338. * functions; you must not call it directly.
  20339. *
  20340. * \param c Result
  20341. * \param a First operand
  20342. * \param b Second operand
  20343. *
  20344. * \note Both operands and result are bit strings interpreted as
  20345. * elements of GF(2^128) as per the GCM spec.
  20346. */
  20347. void mbedtls_aesni_gcm_mult( unsigned char c[16],
  20348. const unsigned char a[16],
  20349. const unsigned char b[16] );
  20350. /**
  20351. * \brief Internal round key inversion. This function computes
  20352. * decryption round keys from the encryption round keys.
  20353. *
  20354. * \note This function is only for internal use by other library
  20355. * functions; you must not call it directly.
  20356. *
  20357. * \param invkey Round keys for the equivalent inverse cipher
  20358. * \param fwdkey Original round keys (for encryption)
  20359. * \param nr Number of rounds (that is, number of round keys minus one)
  20360. */
  20361. void mbedtls_aesni_inverse_key( unsigned char *invkey,
  20362. const unsigned char *fwdkey,
  20363. int nr );
  20364. /**
  20365. * \brief Internal key expansion for encryption
  20366. *
  20367. * \note This function is only for internal use by other library
  20368. * functions; you must not call it directly.
  20369. *
  20370. * \param rk Destination buffer where the round keys are written
  20371. * \param key Encryption key
  20372. * \param bits Key size in bits (must be 128, 192 or 256)
  20373. *
  20374. * \return 0 if successful, or MBEDTLS_ERR_AES_INVALID_KEY_LENGTH
  20375. */
  20376. int mbedtls_aesni_setkey_enc( unsigned char *rk,
  20377. const unsigned char *key,
  20378. size_t bits );
  20379. #ifdef __cplusplus
  20380. }
  20381. #endif
  20382. #endif /* MBEDTLS_HAVE_X86_64 */
  20383. #endif /* MBEDTLS_AESNI_H */
  20384. /********* Start of file include/mbedtls/arc4.h ************/
  20385. /**
  20386. * \file arc4.h
  20387. *
  20388. * \brief The ARCFOUR stream cipher
  20389. *
  20390. * \warning ARC4 is considered a weak cipher and its use constitutes a
  20391. * security risk. We recommend considering stronger ciphers instead.
  20392. */
  20393. /*
  20394. * Copyright The Mbed TLS Contributors
  20395. * SPDX-License-Identifier: Apache-2.0
  20396. *
  20397. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  20398. * not use this file except in compliance with the License.
  20399. * You may obtain a copy of the License at
  20400. *
  20401. * http://www.apache.org/licenses/LICENSE-2.0
  20402. *
  20403. * Unless required by applicable law or agreed to in writing, software
  20404. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  20405. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  20406. * See the License for the specific language governing permissions and
  20407. * limitations under the License.
  20408. *
  20409. */
  20410. #ifndef MBEDTLS_ARC4_H
  20411. #define MBEDTLS_ARC4_H
  20412. #if !defined(MBEDTLS_CONFIG_FILE)
  20413. #else
  20414. #endif
  20415. #include <stddef.h>
  20416. /* MBEDTLS_ERR_ARC4_HW_ACCEL_FAILED is deprecated and should not be used. */
  20417. /** ARC4 hardware accelerator failed. */
  20418. #define MBEDTLS_ERR_ARC4_HW_ACCEL_FAILED -0x0019
  20419. #ifdef __cplusplus
  20420. extern "C" {
  20421. #endif
  20422. #if !defined(MBEDTLS_ARC4_ALT)
  20423. // Regular implementation
  20424. //
  20425. /**
  20426. * \brief ARC4 context structure
  20427. *
  20428. * \warning ARC4 is considered a weak cipher and its use constitutes a
  20429. * security risk. We recommend considering stronger ciphers instead.
  20430. *
  20431. */
  20432. typedef struct mbedtls_arc4_context
  20433. {
  20434. int x; /*!< permutation index */
  20435. int y; /*!< permutation index */
  20436. unsigned char m[256]; /*!< permutation table */
  20437. }
  20438. mbedtls_arc4_context;
  20439. #else /* MBEDTLS_ARC4_ALT */
  20440. #endif /* MBEDTLS_ARC4_ALT */
  20441. /**
  20442. * \brief Initialize ARC4 context
  20443. *
  20444. * \param ctx ARC4 context to be initialized
  20445. *
  20446. * \warning ARC4 is considered a weak cipher and its use constitutes a
  20447. * security risk. We recommend considering stronger ciphers
  20448. * instead.
  20449. *
  20450. */
  20451. void mbedtls_arc4_init( mbedtls_arc4_context *ctx );
  20452. /**
  20453. * \brief Clear ARC4 context
  20454. *
  20455. * \param ctx ARC4 context to be cleared
  20456. *
  20457. * \warning ARC4 is considered a weak cipher and its use constitutes a
  20458. * security risk. We recommend considering stronger ciphers
  20459. * instead.
  20460. *
  20461. */
  20462. void mbedtls_arc4_free( mbedtls_arc4_context *ctx );
  20463. /**
  20464. * \brief ARC4 key schedule
  20465. *
  20466. * \param ctx ARC4 context to be setup
  20467. * \param key the secret key
  20468. * \param keylen length of the key, in bytes
  20469. *
  20470. * \warning ARC4 is considered a weak cipher and its use constitutes a
  20471. * security risk. We recommend considering stronger ciphers
  20472. * instead.
  20473. *
  20474. */
  20475. void mbedtls_arc4_setup( mbedtls_arc4_context *ctx, const unsigned char *key,
  20476. unsigned int keylen );
  20477. /**
  20478. * \brief ARC4 cipher function
  20479. *
  20480. * \param ctx ARC4 context
  20481. * \param length length of the input data
  20482. * \param input buffer holding the input data
  20483. * \param output buffer for the output data
  20484. *
  20485. * \return 0 if successful
  20486. *
  20487. * \warning ARC4 is considered a weak cipher and its use constitutes a
  20488. * security risk. We recommend considering stronger ciphers
  20489. * instead.
  20490. *
  20491. */
  20492. int mbedtls_arc4_crypt( mbedtls_arc4_context *ctx, size_t length, const unsigned char *input,
  20493. unsigned char *output );
  20494. #if defined(MBEDTLS_SELF_TEST)
  20495. /**
  20496. * \brief Checkup routine
  20497. *
  20498. * \return 0 if successful, or 1 if the test failed
  20499. *
  20500. * \warning ARC4 is considered a weak cipher and its use constitutes a
  20501. * security risk. We recommend considering stronger ciphers
  20502. * instead.
  20503. *
  20504. */
  20505. int mbedtls_arc4_self_test( int verbose );
  20506. #endif /* MBEDTLS_SELF_TEST */
  20507. #ifdef __cplusplus
  20508. }
  20509. #endif
  20510. #endif /* arc4.h */
  20511. /********* Start of file include/mbedtls/base64.h ************/
  20512. /**
  20513. * \file base64.h
  20514. *
  20515. * \brief RFC 1521 base64 encoding/decoding
  20516. */
  20517. /*
  20518. * Copyright The Mbed TLS Contributors
  20519. * SPDX-License-Identifier: Apache-2.0
  20520. *
  20521. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  20522. * not use this file except in compliance with the License.
  20523. * You may obtain a copy of the License at
  20524. *
  20525. * http://www.apache.org/licenses/LICENSE-2.0
  20526. *
  20527. * Unless required by applicable law or agreed to in writing, software
  20528. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  20529. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  20530. * See the License for the specific language governing permissions and
  20531. * limitations under the License.
  20532. */
  20533. #ifndef MBEDTLS_BASE64_H
  20534. #define MBEDTLS_BASE64_H
  20535. #if !defined(MBEDTLS_CONFIG_FILE)
  20536. #else
  20537. #endif
  20538. #include <stddef.h>
  20539. /** Output buffer too small. */
  20540. #define MBEDTLS_ERR_BASE64_BUFFER_TOO_SMALL -0x002A
  20541. /** Invalid character in input. */
  20542. #define MBEDTLS_ERR_BASE64_INVALID_CHARACTER -0x002C
  20543. #ifdef __cplusplus
  20544. extern "C" {
  20545. #endif
  20546. /**
  20547. * \brief Encode a buffer into base64 format
  20548. *
  20549. * \param dst destination buffer
  20550. * \param dlen size of the destination buffer
  20551. * \param olen number of bytes written
  20552. * \param src source buffer
  20553. * \param slen amount of data to be encoded
  20554. *
  20555. * \return 0 if successful, or MBEDTLS_ERR_BASE64_BUFFER_TOO_SMALL.
  20556. * *olen is always updated to reflect the amount
  20557. * of data that has (or would have) been written.
  20558. * If that length cannot be represented, then no data is
  20559. * written to the buffer and *olen is set to the maximum
  20560. * length representable as a size_t.
  20561. *
  20562. * \note Call this function with dlen = 0 to obtain the
  20563. * required buffer size in *olen
  20564. */
  20565. int mbedtls_base64_encode( unsigned char *dst, size_t dlen, size_t *olen,
  20566. const unsigned char *src, size_t slen );
  20567. /**
  20568. * \brief Decode a base64-formatted buffer
  20569. *
  20570. * \param dst destination buffer (can be NULL for checking size)
  20571. * \param dlen size of the destination buffer
  20572. * \param olen number of bytes written
  20573. * \param src source buffer
  20574. * \param slen amount of data to be decoded
  20575. *
  20576. * \return 0 if successful, MBEDTLS_ERR_BASE64_BUFFER_TOO_SMALL, or
  20577. * MBEDTLS_ERR_BASE64_INVALID_CHARACTER if the input data is
  20578. * not correct. *olen is always updated to reflect the amount
  20579. * of data that has (or would have) been written.
  20580. *
  20581. * \note Call this function with *dst = NULL or dlen = 0 to obtain
  20582. * the required buffer size in *olen
  20583. */
  20584. int mbedtls_base64_decode( unsigned char *dst, size_t dlen, size_t *olen,
  20585. const unsigned char *src, size_t slen );
  20586. #if defined(MBEDTLS_SELF_TEST)
  20587. /**
  20588. * \brief Checkup routine
  20589. *
  20590. * \return 0 if successful, or 1 if the test failed
  20591. */
  20592. int mbedtls_base64_self_test( int verbose );
  20593. #endif /* MBEDTLS_SELF_TEST */
  20594. #ifdef __cplusplus
  20595. }
  20596. #endif
  20597. #endif /* base64.h */
  20598. /********* Start of file include/mbedtls/bn_mul.h ************/
  20599. /**
  20600. * \file bn_mul.h
  20601. *
  20602. * \brief Multi-precision integer library
  20603. */
  20604. /*
  20605. * Copyright The Mbed TLS Contributors
  20606. * SPDX-License-Identifier: Apache-2.0
  20607. *
  20608. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  20609. * not use this file except in compliance with the License.
  20610. * You may obtain a copy of the License at
  20611. *
  20612. * http://www.apache.org/licenses/LICENSE-2.0
  20613. *
  20614. * Unless required by applicable law or agreed to in writing, software
  20615. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  20616. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  20617. * See the License for the specific language governing permissions and
  20618. * limitations under the License.
  20619. */
  20620. /*
  20621. * Multiply source vector [s] with b, add result
  20622. * to destination vector [d] and set carry c.
  20623. *
  20624. * Currently supports:
  20625. *
  20626. * . IA-32 (386+) . AMD64 / EM64T
  20627. * . IA-32 (SSE2) . Motorola 68000
  20628. * . PowerPC, 32-bit . MicroBlaze
  20629. * . PowerPC, 64-bit . TriCore
  20630. * . SPARC v8 . ARM v3+
  20631. * . Alpha . MIPS32
  20632. * . C, longlong . C, generic
  20633. */
  20634. #ifndef MBEDTLS_BN_MUL_H
  20635. #define MBEDTLS_BN_MUL_H
  20636. #if !defined(MBEDTLS_CONFIG_FILE)
  20637. #else
  20638. #endif
  20639. /*
  20640. * Conversion macros for embedded constants:
  20641. * build lists of mbedtls_mpi_uint's from lists of unsigned char's grouped by 8, 4 or 2
  20642. */
  20643. #if defined(MBEDTLS_HAVE_INT32)
  20644. #define MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ) \
  20645. ( (mbedtls_mpi_uint) (a) << 0 ) | \
  20646. ( (mbedtls_mpi_uint) (b) << 8 ) | \
  20647. ( (mbedtls_mpi_uint) (c) << 16 ) | \
  20648. ( (mbedtls_mpi_uint) (d) << 24 )
  20649. #define MBEDTLS_BYTES_TO_T_UINT_2( a, b ) \
  20650. MBEDTLS_BYTES_TO_T_UINT_4( a, b, 0, 0 )
  20651. #define MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
  20652. MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ), \
  20653. MBEDTLS_BYTES_TO_T_UINT_4( e, f, g, h )
  20654. #else /* 64-bits */
  20655. #define MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
  20656. ( (mbedtls_mpi_uint) (a) << 0 ) | \
  20657. ( (mbedtls_mpi_uint) (b) << 8 ) | \
  20658. ( (mbedtls_mpi_uint) (c) << 16 ) | \
  20659. ( (mbedtls_mpi_uint) (d) << 24 ) | \
  20660. ( (mbedtls_mpi_uint) (e) << 32 ) | \
  20661. ( (mbedtls_mpi_uint) (f) << 40 ) | \
  20662. ( (mbedtls_mpi_uint) (g) << 48 ) | \
  20663. ( (mbedtls_mpi_uint) (h) << 56 )
  20664. #define MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ) \
  20665. MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, 0, 0, 0, 0 )
  20666. #define MBEDTLS_BYTES_TO_T_UINT_2( a, b ) \
  20667. MBEDTLS_BYTES_TO_T_UINT_8( a, b, 0, 0, 0, 0, 0, 0 )
  20668. #endif /* bits in mbedtls_mpi_uint */
  20669. #if defined(MBEDTLS_HAVE_ASM)
  20670. #ifndef asm
  20671. #define asm __asm
  20672. #endif
  20673. /* armcc5 --gnu defines __GNUC__ but doesn't support GNU's extended asm */
  20674. #if defined(__GNUC__) && \
  20675. ( !defined(__ARMCC_VERSION) || __ARMCC_VERSION >= 6000000 )
  20676. /*
  20677. * Disable use of the i386 assembly code below if option -O0, to disable all
  20678. * compiler optimisations, is passed, detected with __OPTIMIZE__
  20679. * This is done as the number of registers used in the assembly code doesn't
  20680. * work with the -O0 option.
  20681. */
  20682. #if defined(__i386__) && defined(__OPTIMIZE__)
  20683. #define MULADDC_INIT \
  20684. asm( \
  20685. "movl %%ebx, %0 \n\t" \
  20686. "movl %5, %%esi \n\t" \
  20687. "movl %6, %%edi \n\t" \
  20688. "movl %7, %%ecx \n\t" \
  20689. "movl %8, %%ebx \n\t"
  20690. #define MULADDC_CORE \
  20691. "lodsl \n\t" \
  20692. "mull %%ebx \n\t" \
  20693. "addl %%ecx, %%eax \n\t" \
  20694. "adcl $0, %%edx \n\t" \
  20695. "addl (%%edi), %%eax \n\t" \
  20696. "adcl $0, %%edx \n\t" \
  20697. "movl %%edx, %%ecx \n\t" \
  20698. "stosl \n\t"
  20699. #if defined(MBEDTLS_HAVE_SSE2)
  20700. #define MULADDC_HUIT \
  20701. "movd %%ecx, %%mm1 \n\t" \
  20702. "movd %%ebx, %%mm0 \n\t" \
  20703. "movd (%%edi), %%mm3 \n\t" \
  20704. "paddq %%mm3, %%mm1 \n\t" \
  20705. "movd (%%esi), %%mm2 \n\t" \
  20706. "pmuludq %%mm0, %%mm2 \n\t" \
  20707. "movd 4(%%esi), %%mm4 \n\t" \
  20708. "pmuludq %%mm0, %%mm4 \n\t" \
  20709. "movd 8(%%esi), %%mm6 \n\t" \
  20710. "pmuludq %%mm0, %%mm6 \n\t" \
  20711. "movd 12(%%esi), %%mm7 \n\t" \
  20712. "pmuludq %%mm0, %%mm7 \n\t" \
  20713. "paddq %%mm2, %%mm1 \n\t" \
  20714. "movd 4(%%edi), %%mm3 \n\t" \
  20715. "paddq %%mm4, %%mm3 \n\t" \
  20716. "movd 8(%%edi), %%mm5 \n\t" \
  20717. "paddq %%mm6, %%mm5 \n\t" \
  20718. "movd 12(%%edi), %%mm4 \n\t" \
  20719. "paddq %%mm4, %%mm7 \n\t" \
  20720. "movd %%mm1, (%%edi) \n\t" \
  20721. "movd 16(%%esi), %%mm2 \n\t" \
  20722. "pmuludq %%mm0, %%mm2 \n\t" \
  20723. "psrlq $32, %%mm1 \n\t" \
  20724. "movd 20(%%esi), %%mm4 \n\t" \
  20725. "pmuludq %%mm0, %%mm4 \n\t" \
  20726. "paddq %%mm3, %%mm1 \n\t" \
  20727. "movd 24(%%esi), %%mm6 \n\t" \
  20728. "pmuludq %%mm0, %%mm6 \n\t" \
  20729. "movd %%mm1, 4(%%edi) \n\t" \
  20730. "psrlq $32, %%mm1 \n\t" \
  20731. "movd 28(%%esi), %%mm3 \n\t" \
  20732. "pmuludq %%mm0, %%mm3 \n\t" \
  20733. "paddq %%mm5, %%mm1 \n\t" \
  20734. "movd 16(%%edi), %%mm5 \n\t" \
  20735. "paddq %%mm5, %%mm2 \n\t" \
  20736. "movd %%mm1, 8(%%edi) \n\t" \
  20737. "psrlq $32, %%mm1 \n\t" \
  20738. "paddq %%mm7, %%mm1 \n\t" \
  20739. "movd 20(%%edi), %%mm5 \n\t" \
  20740. "paddq %%mm5, %%mm4 \n\t" \
  20741. "movd %%mm1, 12(%%edi) \n\t" \
  20742. "psrlq $32, %%mm1 \n\t" \
  20743. "paddq %%mm2, %%mm1 \n\t" \
  20744. "movd 24(%%edi), %%mm5 \n\t" \
  20745. "paddq %%mm5, %%mm6 \n\t" \
  20746. "movd %%mm1, 16(%%edi) \n\t" \
  20747. "psrlq $32, %%mm1 \n\t" \
  20748. "paddq %%mm4, %%mm1 \n\t" \
  20749. "movd 28(%%edi), %%mm5 \n\t" \
  20750. "paddq %%mm5, %%mm3 \n\t" \
  20751. "movd %%mm1, 20(%%edi) \n\t" \
  20752. "psrlq $32, %%mm1 \n\t" \
  20753. "paddq %%mm6, %%mm1 \n\t" \
  20754. "movd %%mm1, 24(%%edi) \n\t" \
  20755. "psrlq $32, %%mm1 \n\t" \
  20756. "paddq %%mm3, %%mm1 \n\t" \
  20757. "movd %%mm1, 28(%%edi) \n\t" \
  20758. "addl $32, %%edi \n\t" \
  20759. "addl $32, %%esi \n\t" \
  20760. "psrlq $32, %%mm1 \n\t" \
  20761. "movd %%mm1, %%ecx \n\t"
  20762. #define MULADDC_STOP \
  20763. "emms \n\t" \
  20764. "movl %4, %%ebx \n\t" \
  20765. "movl %%ecx, %1 \n\t" \
  20766. "movl %%edi, %2 \n\t" \
  20767. "movl %%esi, %3 \n\t" \
  20768. : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
  20769. : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
  20770. : "eax", "ebx", "ecx", "edx", "esi", "edi" \
  20771. );
  20772. #else
  20773. #define MULADDC_STOP \
  20774. "movl %4, %%ebx \n\t" \
  20775. "movl %%ecx, %1 \n\t" \
  20776. "movl %%edi, %2 \n\t" \
  20777. "movl %%esi, %3 \n\t" \
  20778. : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
  20779. : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
  20780. : "eax", "ebx", "ecx", "edx", "esi", "edi" \
  20781. );
  20782. #endif /* SSE2 */
  20783. #endif /* i386 */
  20784. #if defined(__amd64__) || defined (__x86_64__)
  20785. #define MULADDC_INIT \
  20786. asm( \
  20787. "xorq %%r8, %%r8\n"
  20788. #define MULADDC_CORE \
  20789. "movq (%%rsi), %%rax\n" \
  20790. "mulq %%rbx\n" \
  20791. "addq $8, %%rsi\n" \
  20792. "addq %%rcx, %%rax\n" \
  20793. "movq %%r8, %%rcx\n" \
  20794. "adcq $0, %%rdx\n" \
  20795. "nop \n" \
  20796. "addq %%rax, (%%rdi)\n" \
  20797. "adcq %%rdx, %%rcx\n" \
  20798. "addq $8, %%rdi\n"
  20799. #define MULADDC_STOP \
  20800. : "+c" (c), "+D" (d), "+S" (s), "+m" (*(uint64_t (*)[16]) d) \
  20801. : "b" (b), "m" (*(const uint64_t (*)[16]) s) \
  20802. : "rax", "rdx", "r8" \
  20803. );
  20804. #endif /* AMD64 */
  20805. #if defined(__aarch64__)
  20806. #define MULADDC_INIT \
  20807. asm(
  20808. #define MULADDC_CORE \
  20809. "ldr x4, [%2], #8 \n\t" \
  20810. "ldr x5, [%1] \n\t" \
  20811. "mul x6, x4, %4 \n\t" \
  20812. "umulh x7, x4, %4 \n\t" \
  20813. "adds x5, x5, x6 \n\t" \
  20814. "adc x7, x7, xzr \n\t" \
  20815. "adds x5, x5, %0 \n\t" \
  20816. "adc %0, x7, xzr \n\t" \
  20817. "str x5, [%1], #8 \n\t"
  20818. #define MULADDC_STOP \
  20819. : "+r" (c), "+r" (d), "+r" (s), "+m" (*(uint64_t (*)[16]) d) \
  20820. : "r" (b), "m" (*(const uint64_t (*)[16]) s) \
  20821. : "x4", "x5", "x6", "x7", "cc" \
  20822. );
  20823. #endif /* Aarch64 */
  20824. #if defined(__mc68020__) || defined(__mcpu32__)
  20825. #define MULADDC_INIT \
  20826. asm( \
  20827. "movl %3, %%a2 \n\t" \
  20828. "movl %4, %%a3 \n\t" \
  20829. "movl %5, %%d3 \n\t" \
  20830. "movl %6, %%d2 \n\t" \
  20831. "moveq #0, %%d0 \n\t"
  20832. #define MULADDC_CORE \
  20833. "movel %%a2@+, %%d1 \n\t" \
  20834. "mulul %%d2, %%d4:%%d1 \n\t" \
  20835. "addl %%d3, %%d1 \n\t" \
  20836. "addxl %%d0, %%d4 \n\t" \
  20837. "moveq #0, %%d3 \n\t" \
  20838. "addl %%d1, %%a3@+ \n\t" \
  20839. "addxl %%d4, %%d3 \n\t"
  20840. #define MULADDC_STOP \
  20841. "movl %%d3, %0 \n\t" \
  20842. "movl %%a3, %1 \n\t" \
  20843. "movl %%a2, %2 \n\t" \
  20844. : "=m" (c), "=m" (d), "=m" (s) \
  20845. : "m" (s), "m" (d), "m" (c), "m" (b) \
  20846. : "d0", "d1", "d2", "d3", "d4", "a2", "a3" \
  20847. );
  20848. #define MULADDC_HUIT \
  20849. "movel %%a2@+, %%d1 \n\t" \
  20850. "mulul %%d2, %%d4:%%d1 \n\t" \
  20851. "addxl %%d3, %%d1 \n\t" \
  20852. "addxl %%d0, %%d4 \n\t" \
  20853. "addl %%d1, %%a3@+ \n\t" \
  20854. "movel %%a2@+, %%d1 \n\t" \
  20855. "mulul %%d2, %%d3:%%d1 \n\t" \
  20856. "addxl %%d4, %%d1 \n\t" \
  20857. "addxl %%d0, %%d3 \n\t" \
  20858. "addl %%d1, %%a3@+ \n\t" \
  20859. "movel %%a2@+, %%d1 \n\t" \
  20860. "mulul %%d2, %%d4:%%d1 \n\t" \
  20861. "addxl %%d3, %%d1 \n\t" \
  20862. "addxl %%d0, %%d4 \n\t" \
  20863. "addl %%d1, %%a3@+ \n\t" \
  20864. "movel %%a2@+, %%d1 \n\t" \
  20865. "mulul %%d2, %%d3:%%d1 \n\t" \
  20866. "addxl %%d4, %%d1 \n\t" \
  20867. "addxl %%d0, %%d3 \n\t" \
  20868. "addl %%d1, %%a3@+ \n\t" \
  20869. "movel %%a2@+, %%d1 \n\t" \
  20870. "mulul %%d2, %%d4:%%d1 \n\t" \
  20871. "addxl %%d3, %%d1 \n\t" \
  20872. "addxl %%d0, %%d4 \n\t" \
  20873. "addl %%d1, %%a3@+ \n\t" \
  20874. "movel %%a2@+, %%d1 \n\t" \
  20875. "mulul %%d2, %%d3:%%d1 \n\t" \
  20876. "addxl %%d4, %%d1 \n\t" \
  20877. "addxl %%d0, %%d3 \n\t" \
  20878. "addl %%d1, %%a3@+ \n\t" \
  20879. "movel %%a2@+, %%d1 \n\t" \
  20880. "mulul %%d2, %%d4:%%d1 \n\t" \
  20881. "addxl %%d3, %%d1 \n\t" \
  20882. "addxl %%d0, %%d4 \n\t" \
  20883. "addl %%d1, %%a3@+ \n\t" \
  20884. "movel %%a2@+, %%d1 \n\t" \
  20885. "mulul %%d2, %%d3:%%d1 \n\t" \
  20886. "addxl %%d4, %%d1 \n\t" \
  20887. "addxl %%d0, %%d3 \n\t" \
  20888. "addl %%d1, %%a3@+ \n\t" \
  20889. "addxl %%d0, %%d3 \n\t"
  20890. #endif /* MC68000 */
  20891. #if defined(__powerpc64__) || defined(__ppc64__)
  20892. #if defined(__MACH__) && defined(__APPLE__)
  20893. #define MULADDC_INIT \
  20894. asm( \
  20895. "ld r3, %3 \n\t" \
  20896. "ld r4, %4 \n\t" \
  20897. "ld r5, %5 \n\t" \
  20898. "ld r6, %6 \n\t" \
  20899. "addi r3, r3, -8 \n\t" \
  20900. "addi r4, r4, -8 \n\t" \
  20901. "addic r5, r5, 0 \n\t"
  20902. #define MULADDC_CORE \
  20903. "ldu r7, 8(r3) \n\t" \
  20904. "mulld r8, r7, r6 \n\t" \
  20905. "mulhdu r9, r7, r6 \n\t" \
  20906. "adde r8, r8, r5 \n\t" \
  20907. "ld r7, 8(r4) \n\t" \
  20908. "addze r5, r9 \n\t" \
  20909. "addc r8, r8, r7 \n\t" \
  20910. "stdu r8, 8(r4) \n\t"
  20911. #define MULADDC_STOP \
  20912. "addze r5, r5 \n\t" \
  20913. "addi r4, r4, 8 \n\t" \
  20914. "addi r3, r3, 8 \n\t" \
  20915. "std r5, %0 \n\t" \
  20916. "std r4, %1 \n\t" \
  20917. "std r3, %2 \n\t" \
  20918. : "=m" (c), "=m" (d), "=m" (s) \
  20919. : "m" (s), "m" (d), "m" (c), "m" (b) \
  20920. : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
  20921. );
  20922. #else /* __MACH__ && __APPLE__ */
  20923. #define MULADDC_INIT \
  20924. asm( \
  20925. "ld %%r3, %3 \n\t" \
  20926. "ld %%r4, %4 \n\t" \
  20927. "ld %%r5, %5 \n\t" \
  20928. "ld %%r6, %6 \n\t" \
  20929. "addi %%r3, %%r3, -8 \n\t" \
  20930. "addi %%r4, %%r4, -8 \n\t" \
  20931. "addic %%r5, %%r5, 0 \n\t"
  20932. #define MULADDC_CORE \
  20933. "ldu %%r7, 8(%%r3) \n\t" \
  20934. "mulld %%r8, %%r7, %%r6 \n\t" \
  20935. "mulhdu %%r9, %%r7, %%r6 \n\t" \
  20936. "adde %%r8, %%r8, %%r5 \n\t" \
  20937. "ld %%r7, 8(%%r4) \n\t" \
  20938. "addze %%r5, %%r9 \n\t" \
  20939. "addc %%r8, %%r8, %%r7 \n\t" \
  20940. "stdu %%r8, 8(%%r4) \n\t"
  20941. #define MULADDC_STOP \
  20942. "addze %%r5, %%r5 \n\t" \
  20943. "addi %%r4, %%r4, 8 \n\t" \
  20944. "addi %%r3, %%r3, 8 \n\t" \
  20945. "std %%r5, %0 \n\t" \
  20946. "std %%r4, %1 \n\t" \
  20947. "std %%r3, %2 \n\t" \
  20948. : "=m" (c), "=m" (d), "=m" (s) \
  20949. : "m" (s), "m" (d), "m" (c), "m" (b) \
  20950. : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
  20951. );
  20952. #endif /* __MACH__ && __APPLE__ */
  20953. #elif defined(__powerpc__) || defined(__ppc__) /* end PPC64/begin PPC32 */
  20954. #if defined(__MACH__) && defined(__APPLE__)
  20955. #define MULADDC_INIT \
  20956. asm( \
  20957. "lwz r3, %3 \n\t" \
  20958. "lwz r4, %4 \n\t" \
  20959. "lwz r5, %5 \n\t" \
  20960. "lwz r6, %6 \n\t" \
  20961. "addi r3, r3, -4 \n\t" \
  20962. "addi r4, r4, -4 \n\t" \
  20963. "addic r5, r5, 0 \n\t"
  20964. #define MULADDC_CORE \
  20965. "lwzu r7, 4(r3) \n\t" \
  20966. "mullw r8, r7, r6 \n\t" \
  20967. "mulhwu r9, r7, r6 \n\t" \
  20968. "adde r8, r8, r5 \n\t" \
  20969. "lwz r7, 4(r4) \n\t" \
  20970. "addze r5, r9 \n\t" \
  20971. "addc r8, r8, r7 \n\t" \
  20972. "stwu r8, 4(r4) \n\t"
  20973. #define MULADDC_STOP \
  20974. "addze r5, r5 \n\t" \
  20975. "addi r4, r4, 4 \n\t" \
  20976. "addi r3, r3, 4 \n\t" \
  20977. "stw r5, %0 \n\t" \
  20978. "stw r4, %1 \n\t" \
  20979. "stw r3, %2 \n\t" \
  20980. : "=m" (c), "=m" (d), "=m" (s) \
  20981. : "m" (s), "m" (d), "m" (c), "m" (b) \
  20982. : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
  20983. );
  20984. #else /* __MACH__ && __APPLE__ */
  20985. #define MULADDC_INIT \
  20986. asm( \
  20987. "lwz %%r3, %3 \n\t" \
  20988. "lwz %%r4, %4 \n\t" \
  20989. "lwz %%r5, %5 \n\t" \
  20990. "lwz %%r6, %6 \n\t" \
  20991. "addi %%r3, %%r3, -4 \n\t" \
  20992. "addi %%r4, %%r4, -4 \n\t" \
  20993. "addic %%r5, %%r5, 0 \n\t"
  20994. #define MULADDC_CORE \
  20995. "lwzu %%r7, 4(%%r3) \n\t" \
  20996. "mullw %%r8, %%r7, %%r6 \n\t" \
  20997. "mulhwu %%r9, %%r7, %%r6 \n\t" \
  20998. "adde %%r8, %%r8, %%r5 \n\t" \
  20999. "lwz %%r7, 4(%%r4) \n\t" \
  21000. "addze %%r5, %%r9 \n\t" \
  21001. "addc %%r8, %%r8, %%r7 \n\t" \
  21002. "stwu %%r8, 4(%%r4) \n\t"
  21003. #define MULADDC_STOP \
  21004. "addze %%r5, %%r5 \n\t" \
  21005. "addi %%r4, %%r4, 4 \n\t" \
  21006. "addi %%r3, %%r3, 4 \n\t" \
  21007. "stw %%r5, %0 \n\t" \
  21008. "stw %%r4, %1 \n\t" \
  21009. "stw %%r3, %2 \n\t" \
  21010. : "=m" (c), "=m" (d), "=m" (s) \
  21011. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21012. : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
  21013. );
  21014. #endif /* __MACH__ && __APPLE__ */
  21015. #endif /* PPC32 */
  21016. /*
  21017. * The Sparc(64) assembly is reported to be broken.
  21018. * Disable it for now, until we're able to fix it.
  21019. */
  21020. #if 0 && defined(__sparc__)
  21021. #if defined(__sparc64__)
  21022. #define MULADDC_INIT \
  21023. asm( \
  21024. "ldx %3, %%o0 \n\t" \
  21025. "ldx %4, %%o1 \n\t" \
  21026. "ld %5, %%o2 \n\t" \
  21027. "ld %6, %%o3 \n\t"
  21028. #define MULADDC_CORE \
  21029. "ld [%%o0], %%o4 \n\t" \
  21030. "inc 4, %%o0 \n\t" \
  21031. "ld [%%o1], %%o5 \n\t" \
  21032. "umul %%o3, %%o4, %%o4 \n\t" \
  21033. "addcc %%o4, %%o2, %%o4 \n\t" \
  21034. "rd %%y, %%g1 \n\t" \
  21035. "addx %%g1, 0, %%g1 \n\t" \
  21036. "addcc %%o4, %%o5, %%o4 \n\t" \
  21037. "st %%o4, [%%o1] \n\t" \
  21038. "addx %%g1, 0, %%o2 \n\t" \
  21039. "inc 4, %%o1 \n\t"
  21040. #define MULADDC_STOP \
  21041. "st %%o2, %0 \n\t" \
  21042. "stx %%o1, %1 \n\t" \
  21043. "stx %%o0, %2 \n\t" \
  21044. : "=m" (c), "=m" (d), "=m" (s) \
  21045. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21046. : "g1", "o0", "o1", "o2", "o3", "o4", \
  21047. "o5" \
  21048. );
  21049. #else /* __sparc64__ */
  21050. #define MULADDC_INIT \
  21051. asm( \
  21052. "ld %3, %%o0 \n\t" \
  21053. "ld %4, %%o1 \n\t" \
  21054. "ld %5, %%o2 \n\t" \
  21055. "ld %6, %%o3 \n\t"
  21056. #define MULADDC_CORE \
  21057. "ld [%%o0], %%o4 \n\t" \
  21058. "inc 4, %%o0 \n\t" \
  21059. "ld [%%o1], %%o5 \n\t" \
  21060. "umul %%o3, %%o4, %%o4 \n\t" \
  21061. "addcc %%o4, %%o2, %%o4 \n\t" \
  21062. "rd %%y, %%g1 \n\t" \
  21063. "addx %%g1, 0, %%g1 \n\t" \
  21064. "addcc %%o4, %%o5, %%o4 \n\t" \
  21065. "st %%o4, [%%o1] \n\t" \
  21066. "addx %%g1, 0, %%o2 \n\t" \
  21067. "inc 4, %%o1 \n\t"
  21068. #define MULADDC_STOP \
  21069. "st %%o2, %0 \n\t" \
  21070. "st %%o1, %1 \n\t" \
  21071. "st %%o0, %2 \n\t" \
  21072. : "=m" (c), "=m" (d), "=m" (s) \
  21073. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21074. : "g1", "o0", "o1", "o2", "o3", "o4", \
  21075. "o5" \
  21076. );
  21077. #endif /* __sparc64__ */
  21078. #endif /* __sparc__ */
  21079. #if defined(__microblaze__) || defined(microblaze)
  21080. #define MULADDC_INIT \
  21081. asm( \
  21082. "lwi r3, %3 \n\t" \
  21083. "lwi r4, %4 \n\t" \
  21084. "lwi r5, %5 \n\t" \
  21085. "lwi r6, %6 \n\t" \
  21086. "andi r7, r6, 0xffff \n\t" \
  21087. "bsrli r6, r6, 16 \n\t"
  21088. #define MULADDC_CORE \
  21089. "lhui r8, r3, 0 \n\t" \
  21090. "addi r3, r3, 2 \n\t" \
  21091. "lhui r9, r3, 0 \n\t" \
  21092. "addi r3, r3, 2 \n\t" \
  21093. "mul r10, r9, r6 \n\t" \
  21094. "mul r11, r8, r7 \n\t" \
  21095. "mul r12, r9, r7 \n\t" \
  21096. "mul r13, r8, r6 \n\t" \
  21097. "bsrli r8, r10, 16 \n\t" \
  21098. "bsrli r9, r11, 16 \n\t" \
  21099. "add r13, r13, r8 \n\t" \
  21100. "add r13, r13, r9 \n\t" \
  21101. "bslli r10, r10, 16 \n\t" \
  21102. "bslli r11, r11, 16 \n\t" \
  21103. "add r12, r12, r10 \n\t" \
  21104. "addc r13, r13, r0 \n\t" \
  21105. "add r12, r12, r11 \n\t" \
  21106. "addc r13, r13, r0 \n\t" \
  21107. "lwi r10, r4, 0 \n\t" \
  21108. "add r12, r12, r10 \n\t" \
  21109. "addc r13, r13, r0 \n\t" \
  21110. "add r12, r12, r5 \n\t" \
  21111. "addc r5, r13, r0 \n\t" \
  21112. "swi r12, r4, 0 \n\t" \
  21113. "addi r4, r4, 4 \n\t"
  21114. #define MULADDC_STOP \
  21115. "swi r5, %0 \n\t" \
  21116. "swi r4, %1 \n\t" \
  21117. "swi r3, %2 \n\t" \
  21118. : "=m" (c), "=m" (d), "=m" (s) \
  21119. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21120. : "r3", "r4", "r5", "r6", "r7", "r8", \
  21121. "r9", "r10", "r11", "r12", "r13" \
  21122. );
  21123. #endif /* MicroBlaze */
  21124. #if defined(__tricore__)
  21125. #define MULADDC_INIT \
  21126. asm( \
  21127. "ld.a %%a2, %3 \n\t" \
  21128. "ld.a %%a3, %4 \n\t" \
  21129. "ld.w %%d4, %5 \n\t" \
  21130. "ld.w %%d1, %6 \n\t" \
  21131. "xor %%d5, %%d5 \n\t"
  21132. #define MULADDC_CORE \
  21133. "ld.w %%d0, [%%a2+] \n\t" \
  21134. "madd.u %%e2, %%e4, %%d0, %%d1 \n\t" \
  21135. "ld.w %%d0, [%%a3] \n\t" \
  21136. "addx %%d2, %%d2, %%d0 \n\t" \
  21137. "addc %%d3, %%d3, 0 \n\t" \
  21138. "mov %%d4, %%d3 \n\t" \
  21139. "st.w [%%a3+], %%d2 \n\t"
  21140. #define MULADDC_STOP \
  21141. "st.w %0, %%d4 \n\t" \
  21142. "st.a %1, %%a3 \n\t" \
  21143. "st.a %2, %%a2 \n\t" \
  21144. : "=m" (c), "=m" (d), "=m" (s) \
  21145. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21146. : "d0", "d1", "e2", "d4", "a2", "a3" \
  21147. );
  21148. #endif /* TriCore */
  21149. /*
  21150. * Note, gcc -O0 by default uses r7 for the frame pointer, so it complains about
  21151. * our use of r7 below, unless -fomit-frame-pointer is passed.
  21152. *
  21153. * On the other hand, -fomit-frame-pointer is implied by any -Ox options with
  21154. * x !=0, which we can detect using __OPTIMIZE__ (which is also defined by
  21155. * clang and armcc5 under the same conditions).
  21156. *
  21157. * So, only use the optimized assembly below for optimized build, which avoids
  21158. * the build error and is pretty reasonable anyway.
  21159. */
  21160. #if defined(__GNUC__) && !defined(__OPTIMIZE__)
  21161. #define MULADDC_CANNOT_USE_R7
  21162. #endif
  21163. #if defined(__arm__) && !defined(MULADDC_CANNOT_USE_R7)
  21164. #if defined(__thumb__) && !defined(__thumb2__)
  21165. #define MULADDC_INIT \
  21166. asm( \
  21167. "ldr r0, %3 \n\t" \
  21168. "ldr r1, %4 \n\t" \
  21169. "ldr r2, %5 \n\t" \
  21170. "ldr r3, %6 \n\t" \
  21171. "lsr r7, r3, #16 \n\t" \
  21172. "mov r9, r7 \n\t" \
  21173. "lsl r7, r3, #16 \n\t" \
  21174. "lsr r7, r7, #16 \n\t" \
  21175. "mov r8, r7 \n\t"
  21176. #define MULADDC_CORE \
  21177. "ldmia r0!, {r6} \n\t" \
  21178. "lsr r7, r6, #16 \n\t" \
  21179. "lsl r6, r6, #16 \n\t" \
  21180. "lsr r6, r6, #16 \n\t" \
  21181. "mov r4, r8 \n\t" \
  21182. "mul r4, r6 \n\t" \
  21183. "mov r3, r9 \n\t" \
  21184. "mul r6, r3 \n\t" \
  21185. "mov r5, r9 \n\t" \
  21186. "mul r5, r7 \n\t" \
  21187. "mov r3, r8 \n\t" \
  21188. "mul r7, r3 \n\t" \
  21189. "lsr r3, r6, #16 \n\t" \
  21190. "add r5, r5, r3 \n\t" \
  21191. "lsr r3, r7, #16 \n\t" \
  21192. "add r5, r5, r3 \n\t" \
  21193. "add r4, r4, r2 \n\t" \
  21194. "mov r2, #0 \n\t" \
  21195. "adc r5, r2 \n\t" \
  21196. "lsl r3, r6, #16 \n\t" \
  21197. "add r4, r4, r3 \n\t" \
  21198. "adc r5, r2 \n\t" \
  21199. "lsl r3, r7, #16 \n\t" \
  21200. "add r4, r4, r3 \n\t" \
  21201. "adc r5, r2 \n\t" \
  21202. "ldr r3, [r1] \n\t" \
  21203. "add r4, r4, r3 \n\t" \
  21204. "adc r2, r5 \n\t" \
  21205. "stmia r1!, {r4} \n\t"
  21206. #define MULADDC_STOP \
  21207. "str r2, %0 \n\t" \
  21208. "str r1, %1 \n\t" \
  21209. "str r0, %2 \n\t" \
  21210. : "=m" (c), "=m" (d), "=m" (s) \
  21211. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21212. : "r0", "r1", "r2", "r3", "r4", "r5", \
  21213. "r6", "r7", "r8", "r9", "cc" \
  21214. );
  21215. #elif (__ARM_ARCH >= 6) && \
  21216. defined (__ARM_FEATURE_DSP) && (__ARM_FEATURE_DSP == 1)
  21217. #define MULADDC_INIT \
  21218. asm(
  21219. #define MULADDC_CORE \
  21220. "ldr r0, [%0], #4 \n\t" \
  21221. "ldr r1, [%1] \n\t" \
  21222. "umaal r1, %2, %3, r0 \n\t" \
  21223. "str r1, [%1], #4 \n\t"
  21224. #define MULADDC_STOP \
  21225. : "=r" (s), "=r" (d), "=r" (c) \
  21226. : "r" (b), "0" (s), "1" (d), "2" (c) \
  21227. : "r0", "r1", "memory" \
  21228. );
  21229. #else
  21230. #define MULADDC_INIT \
  21231. asm( \
  21232. "ldr r0, %3 \n\t" \
  21233. "ldr r1, %4 \n\t" \
  21234. "ldr r2, %5 \n\t" \
  21235. "ldr r3, %6 \n\t"
  21236. #define MULADDC_CORE \
  21237. "ldr r4, [r0], #4 \n\t" \
  21238. "mov r5, #0 \n\t" \
  21239. "ldr r6, [r1] \n\t" \
  21240. "umlal r2, r5, r3, r4 \n\t" \
  21241. "adds r7, r6, r2 \n\t" \
  21242. "adc r2, r5, #0 \n\t" \
  21243. "str r7, [r1], #4 \n\t"
  21244. #define MULADDC_STOP \
  21245. "str r2, %0 \n\t" \
  21246. "str r1, %1 \n\t" \
  21247. "str r0, %2 \n\t" \
  21248. : "=m" (c), "=m" (d), "=m" (s) \
  21249. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21250. : "r0", "r1", "r2", "r3", "r4", "r5", \
  21251. "r6", "r7", "cc" \
  21252. );
  21253. #endif /* Thumb */
  21254. #endif /* ARMv3 */
  21255. #if defined(__alpha__)
  21256. #define MULADDC_INIT \
  21257. asm( \
  21258. "ldq $1, %3 \n\t" \
  21259. "ldq $2, %4 \n\t" \
  21260. "ldq $3, %5 \n\t" \
  21261. "ldq $4, %6 \n\t"
  21262. #define MULADDC_CORE \
  21263. "ldq $6, 0($1) \n\t" \
  21264. "addq $1, 8, $1 \n\t" \
  21265. "mulq $6, $4, $7 \n\t" \
  21266. "umulh $6, $4, $6 \n\t" \
  21267. "addq $7, $3, $7 \n\t" \
  21268. "cmpult $7, $3, $3 \n\t" \
  21269. "ldq $5, 0($2) \n\t" \
  21270. "addq $7, $5, $7 \n\t" \
  21271. "cmpult $7, $5, $5 \n\t" \
  21272. "stq $7, 0($2) \n\t" \
  21273. "addq $2, 8, $2 \n\t" \
  21274. "addq $6, $3, $3 \n\t" \
  21275. "addq $5, $3, $3 \n\t"
  21276. #define MULADDC_STOP \
  21277. "stq $3, %0 \n\t" \
  21278. "stq $2, %1 \n\t" \
  21279. "stq $1, %2 \n\t" \
  21280. : "=m" (c), "=m" (d), "=m" (s) \
  21281. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21282. : "$1", "$2", "$3", "$4", "$5", "$6", "$7" \
  21283. );
  21284. #endif /* Alpha */
  21285. #if defined(__mips__) && !defined(__mips64)
  21286. #define MULADDC_INIT \
  21287. asm( \
  21288. "lw $10, %3 \n\t" \
  21289. "lw $11, %4 \n\t" \
  21290. "lw $12, %5 \n\t" \
  21291. "lw $13, %6 \n\t"
  21292. #define MULADDC_CORE \
  21293. "lw $14, 0($10) \n\t" \
  21294. "multu $13, $14 \n\t" \
  21295. "addi $10, $10, 4 \n\t" \
  21296. "mflo $14 \n\t" \
  21297. "mfhi $9 \n\t" \
  21298. "addu $14, $12, $14 \n\t" \
  21299. "lw $15, 0($11) \n\t" \
  21300. "sltu $12, $14, $12 \n\t" \
  21301. "addu $15, $14, $15 \n\t" \
  21302. "sltu $14, $15, $14 \n\t" \
  21303. "addu $12, $12, $9 \n\t" \
  21304. "sw $15, 0($11) \n\t" \
  21305. "addu $12, $12, $14 \n\t" \
  21306. "addi $11, $11, 4 \n\t"
  21307. #define MULADDC_STOP \
  21308. "sw $12, %0 \n\t" \
  21309. "sw $11, %1 \n\t" \
  21310. "sw $10, %2 \n\t" \
  21311. : "=m" (c), "=m" (d), "=m" (s) \
  21312. : "m" (s), "m" (d), "m" (c), "m" (b) \
  21313. : "$9", "$10", "$11", "$12", "$13", "$14", "$15", "lo", "hi" \
  21314. );
  21315. #endif /* MIPS */
  21316. #endif /* GNUC */
  21317. #if (defined(_MSC_VER) && defined(_M_IX86)) || defined(__WATCOMC__)
  21318. #define MULADDC_INIT \
  21319. __asm mov esi, s \
  21320. __asm mov edi, d \
  21321. __asm mov ecx, c \
  21322. __asm mov ebx, b
  21323. #define MULADDC_CORE \
  21324. __asm lodsd \
  21325. __asm mul ebx \
  21326. __asm add eax, ecx \
  21327. __asm adc edx, 0 \
  21328. __asm add eax, [edi] \
  21329. __asm adc edx, 0 \
  21330. __asm mov ecx, edx \
  21331. __asm stosd
  21332. #if defined(MBEDTLS_HAVE_SSE2)
  21333. #define EMIT __asm _emit
  21334. #define MULADDC_HUIT \
  21335. EMIT 0x0F EMIT 0x6E EMIT 0xC9 \
  21336. EMIT 0x0F EMIT 0x6E EMIT 0xC3 \
  21337. EMIT 0x0F EMIT 0x6E EMIT 0x1F \
  21338. EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
  21339. EMIT 0x0F EMIT 0x6E EMIT 0x16 \
  21340. EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
  21341. EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x04 \
  21342. EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
  21343. EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x08 \
  21344. EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
  21345. EMIT 0x0F EMIT 0x6E EMIT 0x7E EMIT 0x0C \
  21346. EMIT 0x0F EMIT 0xF4 EMIT 0xF8 \
  21347. EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
  21348. EMIT 0x0F EMIT 0x6E EMIT 0x5F EMIT 0x04 \
  21349. EMIT 0x0F EMIT 0xD4 EMIT 0xDC \
  21350. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x08 \
  21351. EMIT 0x0F EMIT 0xD4 EMIT 0xEE \
  21352. EMIT 0x0F EMIT 0x6E EMIT 0x67 EMIT 0x0C \
  21353. EMIT 0x0F EMIT 0xD4 EMIT 0xFC \
  21354. EMIT 0x0F EMIT 0x7E EMIT 0x0F \
  21355. EMIT 0x0F EMIT 0x6E EMIT 0x56 EMIT 0x10 \
  21356. EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
  21357. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  21358. EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x14 \
  21359. EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
  21360. EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
  21361. EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x18 \
  21362. EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
  21363. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x04 \
  21364. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  21365. EMIT 0x0F EMIT 0x6E EMIT 0x5E EMIT 0x1C \
  21366. EMIT 0x0F EMIT 0xF4 EMIT 0xD8 \
  21367. EMIT 0x0F EMIT 0xD4 EMIT 0xCD \
  21368. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x10 \
  21369. EMIT 0x0F EMIT 0xD4 EMIT 0xD5 \
  21370. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x08 \
  21371. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  21372. EMIT 0x0F EMIT 0xD4 EMIT 0xCF \
  21373. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x14 \
  21374. EMIT 0x0F EMIT 0xD4 EMIT 0xE5 \
  21375. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x0C \
  21376. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  21377. EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
  21378. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x18 \
  21379. EMIT 0x0F EMIT 0xD4 EMIT 0xF5 \
  21380. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x10 \
  21381. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  21382. EMIT 0x0F EMIT 0xD4 EMIT 0xCC \
  21383. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x1C \
  21384. EMIT 0x0F EMIT 0xD4 EMIT 0xDD \
  21385. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x14 \
  21386. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  21387. EMIT 0x0F EMIT 0xD4 EMIT 0xCE \
  21388. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x18 \
  21389. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  21390. EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
  21391. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x1C \
  21392. EMIT 0x83 EMIT 0xC7 EMIT 0x20 \
  21393. EMIT 0x83 EMIT 0xC6 EMIT 0x20 \
  21394. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  21395. EMIT 0x0F EMIT 0x7E EMIT 0xC9
  21396. #define MULADDC_STOP \
  21397. EMIT 0x0F EMIT 0x77 \
  21398. __asm mov c, ecx \
  21399. __asm mov d, edi \
  21400. __asm mov s, esi \
  21401. #else
  21402. #define MULADDC_STOP \
  21403. __asm mov c, ecx \
  21404. __asm mov d, edi \
  21405. __asm mov s, esi \
  21406. #endif /* SSE2 */
  21407. #endif /* MSVC */
  21408. #endif /* MBEDTLS_HAVE_ASM */
  21409. #if !defined(MULADDC_CORE)
  21410. #if defined(MBEDTLS_HAVE_UDBL)
  21411. #define MULADDC_INIT \
  21412. { \
  21413. mbedtls_t_udbl r; \
  21414. mbedtls_mpi_uint r0, r1;
  21415. #define MULADDC_CORE \
  21416. r = *(s++) * (mbedtls_t_udbl) b; \
  21417. r0 = (mbedtls_mpi_uint) r; \
  21418. r1 = (mbedtls_mpi_uint)( r >> biL ); \
  21419. r0 += c; r1 += (r0 < c); \
  21420. r0 += *d; r1 += (r0 < *d); \
  21421. c = r1; *(d++) = r0;
  21422. #define MULADDC_STOP \
  21423. }
  21424. #else
  21425. #define MULADDC_INIT \
  21426. { \
  21427. mbedtls_mpi_uint s0, s1, b0, b1; \
  21428. mbedtls_mpi_uint r0, r1, rx, ry; \
  21429. b0 = ( b << biH ) >> biH; \
  21430. b1 = ( b >> biH );
  21431. #define MULADDC_CORE \
  21432. s0 = ( *s << biH ) >> biH; \
  21433. s1 = ( *s >> biH ); s++; \
  21434. rx = s0 * b1; r0 = s0 * b0; \
  21435. ry = s1 * b0; r1 = s1 * b1; \
  21436. r1 += ( rx >> biH ); \
  21437. r1 += ( ry >> biH ); \
  21438. rx <<= biH; ry <<= biH; \
  21439. r0 += rx; r1 += (r0 < rx); \
  21440. r0 += ry; r1 += (r0 < ry); \
  21441. r0 += c; r1 += (r0 < c); \
  21442. r0 += *d; r1 += (r0 < *d); \
  21443. c = r1; *(d++) = r0;
  21444. #define MULADDC_STOP \
  21445. }
  21446. #endif /* C (generic) */
  21447. #endif /* C (longlong) */
  21448. #endif /* bn_mul.h */
  21449. /********* Start of file include/mbedtls/chacha20.h ************/
  21450. /**
  21451. * \file chacha20.h
  21452. *
  21453. * \brief This file contains ChaCha20 definitions and functions.
  21454. *
  21455. * ChaCha20 is a stream cipher that can encrypt and decrypt
  21456. * information. ChaCha was created by Daniel Bernstein as a variant of
  21457. * its Salsa cipher https://cr.yp.to/chacha/chacha-20080128.pdf
  21458. * ChaCha20 is the variant with 20 rounds, that was also standardized
  21459. * in RFC 7539.
  21460. *
  21461. * \author Daniel King <damaki.gh@gmail.com>
  21462. */
  21463. /*
  21464. * Copyright The Mbed TLS Contributors
  21465. * SPDX-License-Identifier: Apache-2.0
  21466. *
  21467. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  21468. * not use this file except in compliance with the License.
  21469. * You may obtain a copy of the License at
  21470. *
  21471. * http://www.apache.org/licenses/LICENSE-2.0
  21472. *
  21473. * Unless required by applicable law or agreed to in writing, software
  21474. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  21475. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  21476. * See the License for the specific language governing permissions and
  21477. * limitations under the License.
  21478. */
  21479. #ifndef MBEDTLS_CHACHA20_H
  21480. #define MBEDTLS_CHACHA20_H
  21481. #if !defined(MBEDTLS_CONFIG_FILE)
  21482. #else
  21483. #endif
  21484. #include <stdint.h>
  21485. #include <stddef.h>
  21486. /** Invalid input parameter(s). */
  21487. #define MBEDTLS_ERR_CHACHA20_BAD_INPUT_DATA -0x0051
  21488. /* MBEDTLS_ERR_CHACHA20_FEATURE_UNAVAILABLE is deprecated and should not be
  21489. * used. */
  21490. /** Feature not available. For example, s part of the API is not implemented. */
  21491. #define MBEDTLS_ERR_CHACHA20_FEATURE_UNAVAILABLE -0x0053
  21492. /* MBEDTLS_ERR_CHACHA20_HW_ACCEL_FAILED is deprecated and should not be used.
  21493. */
  21494. /** Chacha20 hardware accelerator failed. */
  21495. #define MBEDTLS_ERR_CHACHA20_HW_ACCEL_FAILED -0x0055
  21496. #ifdef __cplusplus
  21497. extern "C" {
  21498. #endif
  21499. #if !defined(MBEDTLS_CHACHA20_ALT)
  21500. typedef struct mbedtls_chacha20_context
  21501. {
  21502. uint32_t state[16]; /*! The state (before round operations). */
  21503. uint8_t keystream8[64]; /*! Leftover keystream bytes. */
  21504. size_t keystream_bytes_used; /*! Number of keystream bytes already used. */
  21505. }
  21506. mbedtls_chacha20_context;
  21507. #else /* MBEDTLS_CHACHA20_ALT */
  21508. #endif /* MBEDTLS_CHACHA20_ALT */
  21509. /**
  21510. * \brief This function initializes the specified ChaCha20 context.
  21511. *
  21512. * It must be the first API called before using
  21513. * the context.
  21514. *
  21515. * It is usually followed by calls to
  21516. * \c mbedtls_chacha20_setkey() and
  21517. * \c mbedtls_chacha20_starts(), then one or more calls to
  21518. * to \c mbedtls_chacha20_update(), and finally to
  21519. * \c mbedtls_chacha20_free().
  21520. *
  21521. * \param ctx The ChaCha20 context to initialize.
  21522. * This must not be \c NULL.
  21523. */
  21524. void mbedtls_chacha20_init( mbedtls_chacha20_context *ctx );
  21525. /**
  21526. * \brief This function releases and clears the specified
  21527. * ChaCha20 context.
  21528. *
  21529. * \param ctx The ChaCha20 context to clear. This may be \c NULL,
  21530. * in which case this function is a no-op. If it is not
  21531. * \c NULL, it must point to an initialized context.
  21532. *
  21533. */
  21534. void mbedtls_chacha20_free( mbedtls_chacha20_context *ctx );
  21535. /**
  21536. * \brief This function sets the encryption/decryption key.
  21537. *
  21538. * \note After using this function, you must also call
  21539. * \c mbedtls_chacha20_starts() to set a nonce before you
  21540. * start encrypting/decrypting data with
  21541. * \c mbedtls_chacha_update().
  21542. *
  21543. * \param ctx The ChaCha20 context to which the key should be bound.
  21544. * It must be initialized.
  21545. * \param key The encryption/decryption key. This must be \c 32 Bytes
  21546. * in length.
  21547. *
  21548. * \return \c 0 on success.
  21549. * \return #MBEDTLS_ERR_CHACHA20_BAD_INPUT_DATA if ctx or key is NULL.
  21550. */
  21551. int mbedtls_chacha20_setkey( mbedtls_chacha20_context *ctx,
  21552. const unsigned char key[32] );
  21553. /**
  21554. * \brief This function sets the nonce and initial counter value.
  21555. *
  21556. * \note A ChaCha20 context can be re-used with the same key by
  21557. * calling this function to change the nonce.
  21558. *
  21559. * \warning You must never use the same nonce twice with the same key.
  21560. * This would void any confidentiality guarantees for the
  21561. * messages encrypted with the same nonce and key.
  21562. *
  21563. * \param ctx The ChaCha20 context to which the nonce should be bound.
  21564. * It must be initialized and bound to a key.
  21565. * \param nonce The nonce. This must be \c 12 Bytes in size.
  21566. * \param counter The initial counter value. This is usually \c 0.
  21567. *
  21568. * \return \c 0 on success.
  21569. * \return #MBEDTLS_ERR_CHACHA20_BAD_INPUT_DATA if ctx or nonce is
  21570. * NULL.
  21571. */
  21572. int mbedtls_chacha20_starts( mbedtls_chacha20_context* ctx,
  21573. const unsigned char nonce[12],
  21574. uint32_t counter );
  21575. /**
  21576. * \brief This function encrypts or decrypts data.
  21577. *
  21578. * Since ChaCha20 is a stream cipher, the same operation is
  21579. * used for encrypting and decrypting data.
  21580. *
  21581. * \note The \p input and \p output pointers must either be equal or
  21582. * point to non-overlapping buffers.
  21583. *
  21584. * \note \c mbedtls_chacha20_setkey() and
  21585. * \c mbedtls_chacha20_starts() must be called at least once
  21586. * to setup the context before this function can be called.
  21587. *
  21588. * \note This function can be called multiple times in a row in
  21589. * order to encrypt of decrypt data piecewise with the same
  21590. * key and nonce.
  21591. *
  21592. * \param ctx The ChaCha20 context to use for encryption or decryption.
  21593. * It must be initialized and bound to a key and nonce.
  21594. * \param size The length of the input data in Bytes.
  21595. * \param input The buffer holding the input data.
  21596. * This pointer can be \c NULL if `size == 0`.
  21597. * \param output The buffer holding the output data.
  21598. * This must be able to hold \p size Bytes.
  21599. * This pointer can be \c NULL if `size == 0`.
  21600. *
  21601. * \return \c 0 on success.
  21602. * \return A negative error code on failure.
  21603. */
  21604. int mbedtls_chacha20_update( mbedtls_chacha20_context *ctx,
  21605. size_t size,
  21606. const unsigned char *input,
  21607. unsigned char *output );
  21608. /**
  21609. * \brief This function encrypts or decrypts data with ChaCha20 and
  21610. * the given key and nonce.
  21611. *
  21612. * Since ChaCha20 is a stream cipher, the same operation is
  21613. * used for encrypting and decrypting data.
  21614. *
  21615. * \warning You must never use the same (key, nonce) pair more than
  21616. * once. This would void any confidentiality guarantees for
  21617. * the messages encrypted with the same nonce and key.
  21618. *
  21619. * \note The \p input and \p output pointers must either be equal or
  21620. * point to non-overlapping buffers.
  21621. *
  21622. * \param key The encryption/decryption key.
  21623. * This must be \c 32 Bytes in length.
  21624. * \param nonce The nonce. This must be \c 12 Bytes in size.
  21625. * \param counter The initial counter value. This is usually \c 0.
  21626. * \param size The length of the input data in Bytes.
  21627. * \param input The buffer holding the input data.
  21628. * This pointer can be \c NULL if `size == 0`.
  21629. * \param output The buffer holding the output data.
  21630. * This must be able to hold \p size Bytes.
  21631. * This pointer can be \c NULL if `size == 0`.
  21632. *
  21633. * \return \c 0 on success.
  21634. * \return A negative error code on failure.
  21635. */
  21636. int mbedtls_chacha20_crypt( const unsigned char key[32],
  21637. const unsigned char nonce[12],
  21638. uint32_t counter,
  21639. size_t size,
  21640. const unsigned char* input,
  21641. unsigned char* output );
  21642. #if defined(MBEDTLS_SELF_TEST)
  21643. /**
  21644. * \brief The ChaCha20 checkup routine.
  21645. *
  21646. * \return \c 0 on success.
  21647. * \return \c 1 on failure.
  21648. */
  21649. int mbedtls_chacha20_self_test( int verbose );
  21650. #endif /* MBEDTLS_SELF_TEST */
  21651. #ifdef __cplusplus
  21652. }
  21653. #endif
  21654. #endif /* MBEDTLS_CHACHA20_H */
  21655. /********* Start of file include/mbedtls/poly1305.h ************/
  21656. /**
  21657. * \file poly1305.h
  21658. *
  21659. * \brief This file contains Poly1305 definitions and functions.
  21660. *
  21661. * Poly1305 is a one-time message authenticator that can be used to
  21662. * authenticate messages. Poly1305-AES was created by Daniel
  21663. * Bernstein https://cr.yp.to/mac/poly1305-20050329.pdf The generic
  21664. * Poly1305 algorithm (not tied to AES) was also standardized in RFC
  21665. * 7539.
  21666. *
  21667. * \author Daniel King <damaki.gh@gmail.com>
  21668. */
  21669. /*
  21670. * Copyright The Mbed TLS Contributors
  21671. * SPDX-License-Identifier: Apache-2.0
  21672. *
  21673. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  21674. * not use this file except in compliance with the License.
  21675. * You may obtain a copy of the License at
  21676. *
  21677. * http://www.apache.org/licenses/LICENSE-2.0
  21678. *
  21679. * Unless required by applicable law or agreed to in writing, software
  21680. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  21681. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  21682. * See the License for the specific language governing permissions and
  21683. * limitations under the License.
  21684. */
  21685. #ifndef MBEDTLS_POLY1305_H
  21686. #define MBEDTLS_POLY1305_H
  21687. #if !defined(MBEDTLS_CONFIG_FILE)
  21688. #else
  21689. #endif
  21690. #include <stdint.h>
  21691. #include <stddef.h>
  21692. /** Invalid input parameter(s). */
  21693. #define MBEDTLS_ERR_POLY1305_BAD_INPUT_DATA -0x0057
  21694. /* MBEDTLS_ERR_POLY1305_FEATURE_UNAVAILABLE is deprecated and should not be
  21695. * used. */
  21696. /** Feature not available. For example, s part of the API is not implemented. */
  21697. #define MBEDTLS_ERR_POLY1305_FEATURE_UNAVAILABLE -0x0059
  21698. /* MBEDTLS_ERR_POLY1305_HW_ACCEL_FAILED is deprecated and should not be used.
  21699. */
  21700. /** Poly1305 hardware accelerator failed. */
  21701. #define MBEDTLS_ERR_POLY1305_HW_ACCEL_FAILED -0x005B
  21702. #ifdef __cplusplus
  21703. extern "C" {
  21704. #endif
  21705. #if !defined(MBEDTLS_POLY1305_ALT)
  21706. typedef struct mbedtls_poly1305_context
  21707. {
  21708. uint32_t r[4]; /** The value for 'r' (low 128 bits of the key). */
  21709. uint32_t s[4]; /** The value for 's' (high 128 bits of the key). */
  21710. uint32_t acc[5]; /** The accumulator number. */
  21711. uint8_t queue[16]; /** The current partial block of data. */
  21712. size_t queue_len; /** The number of bytes stored in 'queue'. */
  21713. }
  21714. mbedtls_poly1305_context;
  21715. #else /* MBEDTLS_POLY1305_ALT */
  21716. #endif /* MBEDTLS_POLY1305_ALT */
  21717. /**
  21718. * \brief This function initializes the specified Poly1305 context.
  21719. *
  21720. * It must be the first API called before using
  21721. * the context.
  21722. *
  21723. * It is usually followed by a call to
  21724. * \c mbedtls_poly1305_starts(), then one or more calls to
  21725. * \c mbedtls_poly1305_update(), then one call to
  21726. * \c mbedtls_poly1305_finish(), then finally
  21727. * \c mbedtls_poly1305_free().
  21728. *
  21729. * \param ctx The Poly1305 context to initialize. This must
  21730. * not be \c NULL.
  21731. */
  21732. void mbedtls_poly1305_init( mbedtls_poly1305_context *ctx );
  21733. /**
  21734. * \brief This function releases and clears the specified
  21735. * Poly1305 context.
  21736. *
  21737. * \param ctx The Poly1305 context to clear. This may be \c NULL, in which
  21738. * case this function is a no-op. If it is not \c NULL, it must
  21739. * point to an initialized Poly1305 context.
  21740. */
  21741. void mbedtls_poly1305_free( mbedtls_poly1305_context *ctx );
  21742. /**
  21743. * \brief This function sets the one-time authentication key.
  21744. *
  21745. * \warning The key must be unique and unpredictable for each
  21746. * invocation of Poly1305.
  21747. *
  21748. * \param ctx The Poly1305 context to which the key should be bound.
  21749. * This must be initialized.
  21750. * \param key The buffer containing the \c 32 Byte (\c 256 Bit) key.
  21751. *
  21752. * \return \c 0 on success.
  21753. * \return A negative error code on failure.
  21754. */
  21755. int mbedtls_poly1305_starts( mbedtls_poly1305_context *ctx,
  21756. const unsigned char key[32] );
  21757. /**
  21758. * \brief This functions feeds an input buffer into an ongoing
  21759. * Poly1305 computation.
  21760. *
  21761. * It is called between \c mbedtls_cipher_poly1305_starts() and
  21762. * \c mbedtls_cipher_poly1305_finish().
  21763. * It can be called repeatedly to process a stream of data.
  21764. *
  21765. * \param ctx The Poly1305 context to use for the Poly1305 operation.
  21766. * This must be initialized and bound to a key.
  21767. * \param ilen The length of the input data in Bytes.
  21768. * Any value is accepted.
  21769. * \param input The buffer holding the input data.
  21770. * This pointer can be \c NULL if `ilen == 0`.
  21771. *
  21772. * \return \c 0 on success.
  21773. * \return A negative error code on failure.
  21774. */
  21775. int mbedtls_poly1305_update( mbedtls_poly1305_context *ctx,
  21776. const unsigned char *input,
  21777. size_t ilen );
  21778. /**
  21779. * \brief This function generates the Poly1305 Message
  21780. * Authentication Code (MAC).
  21781. *
  21782. * \param ctx The Poly1305 context to use for the Poly1305 operation.
  21783. * This must be initialized and bound to a key.
  21784. * \param mac The buffer to where the MAC is written. This must
  21785. * be a writable buffer of length \c 16 Bytes.
  21786. *
  21787. * \return \c 0 on success.
  21788. * \return A negative error code on failure.
  21789. */
  21790. int mbedtls_poly1305_finish( mbedtls_poly1305_context *ctx,
  21791. unsigned char mac[16] );
  21792. /**
  21793. * \brief This function calculates the Poly1305 MAC of the input
  21794. * buffer with the provided key.
  21795. *
  21796. * \warning The key must be unique and unpredictable for each
  21797. * invocation of Poly1305.
  21798. *
  21799. * \param key The buffer containing the \c 32 Byte (\c 256 Bit) key.
  21800. * \param ilen The length of the input data in Bytes.
  21801. * Any value is accepted.
  21802. * \param input The buffer holding the input data.
  21803. * This pointer can be \c NULL if `ilen == 0`.
  21804. * \param mac The buffer to where the MAC is written. This must be
  21805. * a writable buffer of length \c 16 Bytes.
  21806. *
  21807. * \return \c 0 on success.
  21808. * \return A negative error code on failure.
  21809. */
  21810. int mbedtls_poly1305_mac( const unsigned char key[32],
  21811. const unsigned char *input,
  21812. size_t ilen,
  21813. unsigned char mac[16] );
  21814. #if defined(MBEDTLS_SELF_TEST)
  21815. /**
  21816. * \brief The Poly1305 checkup routine.
  21817. *
  21818. * \return \c 0 on success.
  21819. * \return \c 1 on failure.
  21820. */
  21821. int mbedtls_poly1305_self_test( int verbose );
  21822. #endif /* MBEDTLS_SELF_TEST */
  21823. #ifdef __cplusplus
  21824. }
  21825. #endif
  21826. #endif /* MBEDTLS_POLY1305_H */
  21827. /********* Start of file include/mbedtls/chachapoly.h ************/
  21828. /**
  21829. * \file chachapoly.h
  21830. *
  21831. * \brief This file contains the AEAD-ChaCha20-Poly1305 definitions and
  21832. * functions.
  21833. *
  21834. * ChaCha20-Poly1305 is an algorithm for Authenticated Encryption
  21835. * with Associated Data (AEAD) that can be used to encrypt and
  21836. * authenticate data. It is based on ChaCha20 and Poly1305 by Daniel
  21837. * Bernstein and was standardized in RFC 7539.
  21838. *
  21839. * \author Daniel King <damaki.gh@gmail.com>
  21840. */
  21841. /*
  21842. * Copyright The Mbed TLS Contributors
  21843. * SPDX-License-Identifier: Apache-2.0
  21844. *
  21845. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  21846. * not use this file except in compliance with the License.
  21847. * You may obtain a copy of the License at
  21848. *
  21849. * http://www.apache.org/licenses/LICENSE-2.0
  21850. *
  21851. * Unless required by applicable law or agreed to in writing, software
  21852. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  21853. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  21854. * See the License for the specific language governing permissions and
  21855. * limitations under the License.
  21856. */
  21857. #ifndef MBEDTLS_CHACHAPOLY_H
  21858. #define MBEDTLS_CHACHAPOLY_H
  21859. #if !defined(MBEDTLS_CONFIG_FILE)
  21860. #else
  21861. #endif
  21862. /* for shared error codes */
  21863. /** The requested operation is not permitted in the current state. */
  21864. #define MBEDTLS_ERR_CHACHAPOLY_BAD_STATE -0x0054
  21865. /** Authenticated decryption failed: data was not authentic. */
  21866. #define MBEDTLS_ERR_CHACHAPOLY_AUTH_FAILED -0x0056
  21867. #ifdef __cplusplus
  21868. extern "C" {
  21869. #endif
  21870. typedef enum
  21871. {
  21872. MBEDTLS_CHACHAPOLY_ENCRYPT, /**< The mode value for performing encryption. */
  21873. MBEDTLS_CHACHAPOLY_DECRYPT /**< The mode value for performing decryption. */
  21874. }
  21875. mbedtls_chachapoly_mode_t;
  21876. #if !defined(MBEDTLS_CHACHAPOLY_ALT)
  21877. typedef struct mbedtls_chachapoly_context
  21878. {
  21879. mbedtls_chacha20_context chacha20_ctx; /**< The ChaCha20 context. */
  21880. mbedtls_poly1305_context poly1305_ctx; /**< The Poly1305 context. */
  21881. uint64_t aad_len; /**< The length (bytes) of the Additional Authenticated Data. */
  21882. uint64_t ciphertext_len; /**< The length (bytes) of the ciphertext. */
  21883. int state; /**< The current state of the context. */
  21884. mbedtls_chachapoly_mode_t mode; /**< Cipher mode (encrypt or decrypt). */
  21885. }
  21886. mbedtls_chachapoly_context;
  21887. #else /* !MBEDTLS_CHACHAPOLY_ALT */
  21888. #endif /* !MBEDTLS_CHACHAPOLY_ALT */
  21889. /**
  21890. * \brief This function initializes the specified ChaCha20-Poly1305 context.
  21891. *
  21892. * It must be the first API called before using
  21893. * the context. It must be followed by a call to
  21894. * \c mbedtls_chachapoly_setkey() before any operation can be
  21895. * done, and to \c mbedtls_chachapoly_free() once all
  21896. * operations with that context have been finished.
  21897. *
  21898. * In order to encrypt or decrypt full messages at once, for
  21899. * each message you should make a single call to
  21900. * \c mbedtls_chachapoly_crypt_and_tag() or
  21901. * \c mbedtls_chachapoly_auth_decrypt().
  21902. *
  21903. * In order to encrypt messages piecewise, for each
  21904. * message you should make a call to
  21905. * \c mbedtls_chachapoly_starts(), then 0 or more calls to
  21906. * \c mbedtls_chachapoly_update_aad(), then 0 or more calls to
  21907. * \c mbedtls_chachapoly_update(), then one call to
  21908. * \c mbedtls_chachapoly_finish().
  21909. *
  21910. * \warning Decryption with the piecewise API is discouraged! Always
  21911. * use \c mbedtls_chachapoly_auth_decrypt() when possible!
  21912. *
  21913. * If however this is not possible because the data is too
  21914. * large to fit in memory, you need to:
  21915. *
  21916. * - call \c mbedtls_chachapoly_starts() and (if needed)
  21917. * \c mbedtls_chachapoly_update_aad() as above,
  21918. * - call \c mbedtls_chachapoly_update() multiple times and
  21919. * ensure its output (the plaintext) is NOT used in any other
  21920. * way than placing it in temporary storage at this point,
  21921. * - call \c mbedtls_chachapoly_finish() to compute the
  21922. * authentication tag and compared it in constant time to the
  21923. * tag received with the ciphertext.
  21924. *
  21925. * If the tags are not equal, you must immediately discard
  21926. * all previous outputs of \c mbedtls_chachapoly_update(),
  21927. * otherwise you can now safely use the plaintext.
  21928. *
  21929. * \param ctx The ChachaPoly context to initialize. Must not be \c NULL.
  21930. */
  21931. void mbedtls_chachapoly_init( mbedtls_chachapoly_context *ctx );
  21932. /**
  21933. * \brief This function releases and clears the specified
  21934. * ChaCha20-Poly1305 context.
  21935. *
  21936. * \param ctx The ChachaPoly context to clear. This may be \c NULL, in which
  21937. * case this function is a no-op.
  21938. */
  21939. void mbedtls_chachapoly_free( mbedtls_chachapoly_context *ctx );
  21940. /**
  21941. * \brief This function sets the ChaCha20-Poly1305
  21942. * symmetric encryption key.
  21943. *
  21944. * \param ctx The ChaCha20-Poly1305 context to which the key should be
  21945. * bound. This must be initialized.
  21946. * \param key The \c 256 Bit (\c 32 Bytes) key.
  21947. *
  21948. * \return \c 0 on success.
  21949. * \return A negative error code on failure.
  21950. */
  21951. int mbedtls_chachapoly_setkey( mbedtls_chachapoly_context *ctx,
  21952. const unsigned char key[32] );
  21953. /**
  21954. * \brief This function starts a ChaCha20-Poly1305 encryption or
  21955. * decryption operation.
  21956. *
  21957. * \warning You must never use the same nonce twice with the same key.
  21958. * This would void any confidentiality and authenticity
  21959. * guarantees for the messages encrypted with the same nonce
  21960. * and key.
  21961. *
  21962. * \note If the context is being used for AAD only (no data to
  21963. * encrypt or decrypt) then \p mode can be set to any value.
  21964. *
  21965. * \warning Decryption with the piecewise API is discouraged, see the
  21966. * warning on \c mbedtls_chachapoly_init().
  21967. *
  21968. * \param ctx The ChaCha20-Poly1305 context. This must be initialized
  21969. * and bound to a key.
  21970. * \param nonce The nonce/IV to use for the message.
  21971. * This must be a redable buffer of length \c 12 Bytes.
  21972. * \param mode The operation to perform: #MBEDTLS_CHACHAPOLY_ENCRYPT or
  21973. * #MBEDTLS_CHACHAPOLY_DECRYPT (discouraged, see warning).
  21974. *
  21975. * \return \c 0 on success.
  21976. * \return A negative error code on failure.
  21977. */
  21978. int mbedtls_chachapoly_starts( mbedtls_chachapoly_context *ctx,
  21979. const unsigned char nonce[12],
  21980. mbedtls_chachapoly_mode_t mode );
  21981. /**
  21982. * \brief This function feeds additional data to be authenticated
  21983. * into an ongoing ChaCha20-Poly1305 operation.
  21984. *
  21985. * The Additional Authenticated Data (AAD), also called
  21986. * Associated Data (AD) is only authenticated but not
  21987. * encrypted nor included in the encrypted output. It is
  21988. * usually transmitted separately from the ciphertext or
  21989. * computed locally by each party.
  21990. *
  21991. * \note This function is called before data is encrypted/decrypted.
  21992. * I.e. call this function to process the AAD before calling
  21993. * \c mbedtls_chachapoly_update().
  21994. *
  21995. * You may call this function multiple times to process
  21996. * an arbitrary amount of AAD. It is permitted to call
  21997. * this function 0 times, if no AAD is used.
  21998. *
  21999. * This function cannot be called any more if data has
  22000. * been processed by \c mbedtls_chachapoly_update(),
  22001. * or if the context has been finished.
  22002. *
  22003. * \warning Decryption with the piecewise API is discouraged, see the
  22004. * warning on \c mbedtls_chachapoly_init().
  22005. *
  22006. * \param ctx The ChaCha20-Poly1305 context. This must be initialized
  22007. * and bound to a key.
  22008. * \param aad_len The length in Bytes of the AAD. The length has no
  22009. * restrictions.
  22010. * \param aad Buffer containing the AAD.
  22011. * This pointer can be \c NULL if `aad_len == 0`.
  22012. *
  22013. * \return \c 0 on success.
  22014. * \return #MBEDTLS_ERR_POLY1305_BAD_INPUT_DATA
  22015. * if \p ctx or \p aad are NULL.
  22016. * \return #MBEDTLS_ERR_CHACHAPOLY_BAD_STATE
  22017. * if the operations has not been started or has been
  22018. * finished, or if the AAD has been finished.
  22019. */
  22020. int mbedtls_chachapoly_update_aad( mbedtls_chachapoly_context *ctx,
  22021. const unsigned char *aad,
  22022. size_t aad_len );
  22023. /**
  22024. * \brief Thus function feeds data to be encrypted or decrypted
  22025. * into an on-going ChaCha20-Poly1305
  22026. * operation.
  22027. *
  22028. * The direction (encryption or decryption) depends on the
  22029. * mode that was given when calling
  22030. * \c mbedtls_chachapoly_starts().
  22031. *
  22032. * You may call this function multiple times to process
  22033. * an arbitrary amount of data. It is permitted to call
  22034. * this function 0 times, if no data is to be encrypted
  22035. * or decrypted.
  22036. *
  22037. * \warning Decryption with the piecewise API is discouraged, see the
  22038. * warning on \c mbedtls_chachapoly_init().
  22039. *
  22040. * \param ctx The ChaCha20-Poly1305 context to use. This must be initialized.
  22041. * \param len The length (in bytes) of the data to encrypt or decrypt.
  22042. * \param input The buffer containing the data to encrypt or decrypt.
  22043. * This pointer can be \c NULL if `len == 0`.
  22044. * \param output The buffer to where the encrypted or decrypted data is
  22045. * written. This must be able to hold \p len bytes.
  22046. * This pointer can be \c NULL if `len == 0`.
  22047. *
  22048. * \return \c 0 on success.
  22049. * \return #MBEDTLS_ERR_CHACHAPOLY_BAD_STATE
  22050. * if the operation has not been started or has been
  22051. * finished.
  22052. * \return Another negative error code on other kinds of failure.
  22053. */
  22054. int mbedtls_chachapoly_update( mbedtls_chachapoly_context *ctx,
  22055. size_t len,
  22056. const unsigned char *input,
  22057. unsigned char *output );
  22058. /**
  22059. * \brief This function finished the ChaCha20-Poly1305 operation and
  22060. * generates the MAC (authentication tag).
  22061. *
  22062. * \param ctx The ChaCha20-Poly1305 context to use. This must be initialized.
  22063. * \param mac The buffer to where the 128-bit (16 bytes) MAC is written.
  22064. *
  22065. * \warning Decryption with the piecewise API is discouraged, see the
  22066. * warning on \c mbedtls_chachapoly_init().
  22067. *
  22068. * \return \c 0 on success.
  22069. * \return #MBEDTLS_ERR_CHACHAPOLY_BAD_STATE
  22070. * if the operation has not been started or has been
  22071. * finished.
  22072. * \return Another negative error code on other kinds of failure.
  22073. */
  22074. int mbedtls_chachapoly_finish( mbedtls_chachapoly_context *ctx,
  22075. unsigned char mac[16] );
  22076. /**
  22077. * \brief This function performs a complete ChaCha20-Poly1305
  22078. * authenticated encryption with the previously-set key.
  22079. *
  22080. * \note Before using this function, you must set the key with
  22081. * \c mbedtls_chachapoly_setkey().
  22082. *
  22083. * \warning You must never use the same nonce twice with the same key.
  22084. * This would void any confidentiality and authenticity
  22085. * guarantees for the messages encrypted with the same nonce
  22086. * and key.
  22087. *
  22088. * \param ctx The ChaCha20-Poly1305 context to use (holds the key).
  22089. * This must be initialized.
  22090. * \param length The length (in bytes) of the data to encrypt or decrypt.
  22091. * \param nonce The 96-bit (12 bytes) nonce/IV to use.
  22092. * \param aad The buffer containing the additional authenticated
  22093. * data (AAD). This pointer can be \c NULL if `aad_len == 0`.
  22094. * \param aad_len The length (in bytes) of the AAD data to process.
  22095. * \param input The buffer containing the data to encrypt or decrypt.
  22096. * This pointer can be \c NULL if `ilen == 0`.
  22097. * \param output The buffer to where the encrypted or decrypted data
  22098. * is written. This pointer can be \c NULL if `ilen == 0`.
  22099. * \param tag The buffer to where the computed 128-bit (16 bytes) MAC
  22100. * is written. This must not be \c NULL.
  22101. *
  22102. * \return \c 0 on success.
  22103. * \return A negative error code on failure.
  22104. */
  22105. int mbedtls_chachapoly_encrypt_and_tag( mbedtls_chachapoly_context *ctx,
  22106. size_t length,
  22107. const unsigned char nonce[12],
  22108. const unsigned char *aad,
  22109. size_t aad_len,
  22110. const unsigned char *input,
  22111. unsigned char *output,
  22112. unsigned char tag[16] );
  22113. /**
  22114. * \brief This function performs a complete ChaCha20-Poly1305
  22115. * authenticated decryption with the previously-set key.
  22116. *
  22117. * \note Before using this function, you must set the key with
  22118. * \c mbedtls_chachapoly_setkey().
  22119. *
  22120. * \param ctx The ChaCha20-Poly1305 context to use (holds the key).
  22121. * \param length The length (in Bytes) of the data to decrypt.
  22122. * \param nonce The \c 96 Bit (\c 12 bytes) nonce/IV to use.
  22123. * \param aad The buffer containing the additional authenticated data (AAD).
  22124. * This pointer can be \c NULL if `aad_len == 0`.
  22125. * \param aad_len The length (in bytes) of the AAD data to process.
  22126. * \param tag The buffer holding the authentication tag.
  22127. * This must be a readable buffer of length \c 16 Bytes.
  22128. * \param input The buffer containing the data to decrypt.
  22129. * This pointer can be \c NULL if `ilen == 0`.
  22130. * \param output The buffer to where the decrypted data is written.
  22131. * This pointer can be \c NULL if `ilen == 0`.
  22132. *
  22133. * \return \c 0 on success.
  22134. * \return #MBEDTLS_ERR_CHACHAPOLY_AUTH_FAILED
  22135. * if the data was not authentic.
  22136. * \return Another negative error code on other kinds of failure.
  22137. */
  22138. int mbedtls_chachapoly_auth_decrypt( mbedtls_chachapoly_context *ctx,
  22139. size_t length,
  22140. const unsigned char nonce[12],
  22141. const unsigned char *aad,
  22142. size_t aad_len,
  22143. const unsigned char tag[16],
  22144. const unsigned char *input,
  22145. unsigned char *output );
  22146. #if defined(MBEDTLS_SELF_TEST)
  22147. /**
  22148. * \brief The ChaCha20-Poly1305 checkup routine.
  22149. *
  22150. * \return \c 0 on success.
  22151. * \return \c 1 on failure.
  22152. */
  22153. int mbedtls_chachapoly_self_test( int verbose );
  22154. #endif /* MBEDTLS_SELF_TEST */
  22155. #ifdef __cplusplus
  22156. }
  22157. #endif
  22158. #endif /* MBEDTLS_CHACHAPOLY_H */
  22159. /********* Start of file include/mbedtls/camellia.h ************/
  22160. /**
  22161. * \file camellia.h
  22162. *
  22163. * \brief Camellia block cipher
  22164. */
  22165. /*
  22166. * Copyright The Mbed TLS Contributors
  22167. * SPDX-License-Identifier: Apache-2.0
  22168. *
  22169. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  22170. * not use this file except in compliance with the License.
  22171. * You may obtain a copy of the License at
  22172. *
  22173. * http://www.apache.org/licenses/LICENSE-2.0
  22174. *
  22175. * Unless required by applicable law or agreed to in writing, software
  22176. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  22177. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  22178. * See the License for the specific language governing permissions and
  22179. * limitations under the License.
  22180. */
  22181. #ifndef MBEDTLS_CAMELLIA_H
  22182. #define MBEDTLS_CAMELLIA_H
  22183. #if !defined(MBEDTLS_CONFIG_FILE)
  22184. #else
  22185. #endif
  22186. #include <stddef.h>
  22187. #include <stdint.h>
  22188. #define MBEDTLS_CAMELLIA_ENCRYPT 1
  22189. #define MBEDTLS_CAMELLIA_DECRYPT 0
  22190. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  22191. #define MBEDTLS_ERR_CAMELLIA_INVALID_KEY_LENGTH MBEDTLS_DEPRECATED_NUMERIC_CONSTANT( -0x0024 )
  22192. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  22193. /** Bad input data. */
  22194. #define MBEDTLS_ERR_CAMELLIA_BAD_INPUT_DATA -0x0024
  22195. /** Invalid data input length. */
  22196. #define MBEDTLS_ERR_CAMELLIA_INVALID_INPUT_LENGTH -0x0026
  22197. /* MBEDTLS_ERR_CAMELLIA_HW_ACCEL_FAILED is deprecated and should not be used.
  22198. */
  22199. /** Camellia hardware accelerator failed. */
  22200. #define MBEDTLS_ERR_CAMELLIA_HW_ACCEL_FAILED -0x0027
  22201. #ifdef __cplusplus
  22202. extern "C" {
  22203. #endif
  22204. #if !defined(MBEDTLS_CAMELLIA_ALT)
  22205. // Regular implementation
  22206. //
  22207. /**
  22208. * \brief CAMELLIA context structure
  22209. */
  22210. typedef struct mbedtls_camellia_context
  22211. {
  22212. int nr; /*!< number of rounds */
  22213. uint32_t rk[68]; /*!< CAMELLIA round keys */
  22214. }
  22215. mbedtls_camellia_context;
  22216. #else /* MBEDTLS_CAMELLIA_ALT */
  22217. #endif /* MBEDTLS_CAMELLIA_ALT */
  22218. /**
  22219. * \brief Initialize a CAMELLIA context.
  22220. *
  22221. * \param ctx The CAMELLIA context to be initialized.
  22222. * This must not be \c NULL.
  22223. */
  22224. void mbedtls_camellia_init( mbedtls_camellia_context *ctx );
  22225. /**
  22226. * \brief Clear a CAMELLIA context.
  22227. *
  22228. * \param ctx The CAMELLIA context to be cleared. This may be \c NULL,
  22229. * in which case this function returns immediately. If it is not
  22230. * \c NULL, it must be initialized.
  22231. */
  22232. void mbedtls_camellia_free( mbedtls_camellia_context *ctx );
  22233. /**
  22234. * \brief Perform a CAMELLIA key schedule operation for encryption.
  22235. *
  22236. * \param ctx The CAMELLIA context to use. This must be initialized.
  22237. * \param key The encryption key to use. This must be a readable buffer
  22238. * of size \p keybits Bits.
  22239. * \param keybits The length of \p key in Bits. This must be either \c 128,
  22240. * \c 192 or \c 256.
  22241. *
  22242. * \return \c 0 if successful.
  22243. * \return A negative error code on failure.
  22244. */
  22245. int mbedtls_camellia_setkey_enc( mbedtls_camellia_context *ctx,
  22246. const unsigned char *key,
  22247. unsigned int keybits );
  22248. /**
  22249. * \brief Perform a CAMELLIA key schedule operation for decryption.
  22250. *
  22251. * \param ctx The CAMELLIA context to use. This must be initialized.
  22252. * \param key The decryption key. This must be a readable buffer
  22253. * of size \p keybits Bits.
  22254. * \param keybits The length of \p key in Bits. This must be either \c 128,
  22255. * \c 192 or \c 256.
  22256. *
  22257. * \return \c 0 if successful.
  22258. * \return A negative error code on failure.
  22259. */
  22260. int mbedtls_camellia_setkey_dec( mbedtls_camellia_context *ctx,
  22261. const unsigned char *key,
  22262. unsigned int keybits );
  22263. /**
  22264. * \brief Perform a CAMELLIA-ECB block encryption/decryption operation.
  22265. *
  22266. * \param ctx The CAMELLIA context to use. This must be initialized
  22267. * and bound to a key.
  22268. * \param mode The mode of operation. This must be either
  22269. * #MBEDTLS_CAMELLIA_ENCRYPT or #MBEDTLS_CAMELLIA_DECRYPT.
  22270. * \param input The input block. This must be a readable buffer
  22271. * of size \c 16 Bytes.
  22272. * \param output The output block. This must be a writable buffer
  22273. * of size \c 16 Bytes.
  22274. *
  22275. * \return \c 0 if successful.
  22276. * \return A negative error code on failure.
  22277. */
  22278. int mbedtls_camellia_crypt_ecb( mbedtls_camellia_context *ctx,
  22279. int mode,
  22280. const unsigned char input[16],
  22281. unsigned char output[16] );
  22282. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  22283. /**
  22284. * \brief Perform a CAMELLIA-CBC buffer encryption/decryption operation.
  22285. *
  22286. * \note Upon exit, the content of the IV is updated so that you can
  22287. * call the function same function again on the following
  22288. * block(s) of data and get the same result as if it was
  22289. * encrypted in one call. This allows a "streaming" usage.
  22290. * If on the other hand you need to retain the contents of the
  22291. * IV, you should either save it manually or use the cipher
  22292. * module instead.
  22293. *
  22294. * \param ctx The CAMELLIA context to use. This must be initialized
  22295. * and bound to a key.
  22296. * \param mode The mode of operation. This must be either
  22297. * #MBEDTLS_CAMELLIA_ENCRYPT or #MBEDTLS_CAMELLIA_DECRYPT.
  22298. * \param length The length in Bytes of the input data \p input.
  22299. * This must be a multiple of \c 16 Bytes.
  22300. * \param iv The initialization vector. This must be a read/write buffer
  22301. * of length \c 16 Bytes. It is updated to allow streaming
  22302. * use as explained above.
  22303. * \param input The buffer holding the input data. This must point to a
  22304. * readable buffer of length \p length Bytes.
  22305. * \param output The buffer holding the output data. This must point to a
  22306. * writable buffer of length \p length Bytes.
  22307. *
  22308. * \return \c 0 if successful.
  22309. * \return A negative error code on failure.
  22310. */
  22311. int mbedtls_camellia_crypt_cbc( mbedtls_camellia_context *ctx,
  22312. int mode,
  22313. size_t length,
  22314. unsigned char iv[16],
  22315. const unsigned char *input,
  22316. unsigned char *output );
  22317. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  22318. #if defined(MBEDTLS_CIPHER_MODE_CFB)
  22319. /**
  22320. * \brief Perform a CAMELLIA-CFB128 buffer encryption/decryption
  22321. * operation.
  22322. *
  22323. * \note Due to the nature of CFB mode, you should use the same
  22324. * key for both encryption and decryption. In particular, calls
  22325. * to this function should be preceded by a key-schedule via
  22326. * mbedtls_camellia_setkey_enc() regardless of whether \p mode
  22327. * is #MBEDTLS_CAMELLIA_ENCRYPT or #MBEDTLS_CAMELLIA_DECRYPT.
  22328. *
  22329. * \note Upon exit, the content of the IV is updated so that you can
  22330. * call the function same function again on the following
  22331. * block(s) of data and get the same result as if it was
  22332. * encrypted in one call. This allows a "streaming" usage.
  22333. * If on the other hand you need to retain the contents of the
  22334. * IV, you should either save it manually or use the cipher
  22335. * module instead.
  22336. *
  22337. * \param ctx The CAMELLIA context to use. This must be initialized
  22338. * and bound to a key.
  22339. * \param mode The mode of operation. This must be either
  22340. * #MBEDTLS_CAMELLIA_ENCRYPT or #MBEDTLS_CAMELLIA_DECRYPT.
  22341. * \param length The length of the input data \p input. Any value is allowed.
  22342. * \param iv_off The current offset in the IV. This must be smaller
  22343. * than \c 16 Bytes. It is updated after this call to allow
  22344. * the aforementioned streaming usage.
  22345. * \param iv The initialization vector. This must be a read/write buffer
  22346. * of length \c 16 Bytes. It is updated after this call to
  22347. * allow the aforementioned streaming usage.
  22348. * \param input The buffer holding the input data. This must be a readable
  22349. * buffer of size \p length Bytes.
  22350. * \param output The buffer to hold the output data. This must be a writable
  22351. * buffer of length \p length Bytes.
  22352. *
  22353. * \return \c 0 if successful.
  22354. * \return A negative error code on failure.
  22355. */
  22356. int mbedtls_camellia_crypt_cfb128( mbedtls_camellia_context *ctx,
  22357. int mode,
  22358. size_t length,
  22359. size_t *iv_off,
  22360. unsigned char iv[16],
  22361. const unsigned char *input,
  22362. unsigned char *output );
  22363. #endif /* MBEDTLS_CIPHER_MODE_CFB */
  22364. #if defined(MBEDTLS_CIPHER_MODE_CTR)
  22365. /**
  22366. * \brief Perform a CAMELLIA-CTR buffer encryption/decryption operation.
  22367. *
  22368. * *note Due to the nature of CTR mode, you should use the same
  22369. * key for both encryption and decryption. In particular, calls
  22370. * to this function should be preceded by a key-schedule via
  22371. * mbedtls_camellia_setkey_enc() regardless of whether \p mode
  22372. * is #MBEDTLS_CAMELLIA_ENCRYPT or #MBEDTLS_CAMELLIA_DECRYPT.
  22373. *
  22374. * \warning You must never reuse a nonce value with the same key. Doing so
  22375. * would void the encryption for the two messages encrypted with
  22376. * the same nonce and key.
  22377. *
  22378. * There are two common strategies for managing nonces with CTR:
  22379. *
  22380. * 1. You can handle everything as a single message processed over
  22381. * successive calls to this function. In that case, you want to
  22382. * set \p nonce_counter and \p nc_off to 0 for the first call, and
  22383. * then preserve the values of \p nonce_counter, \p nc_off and \p
  22384. * stream_block across calls to this function as they will be
  22385. * updated by this function.
  22386. *
  22387. * With this strategy, you must not encrypt more than 2**128
  22388. * blocks of data with the same key.
  22389. *
  22390. * 2. You can encrypt separate messages by dividing the \p
  22391. * nonce_counter buffer in two areas: the first one used for a
  22392. * per-message nonce, handled by yourself, and the second one
  22393. * updated by this function internally.
  22394. *
  22395. * For example, you might reserve the first \c 12 Bytes for the
  22396. * per-message nonce, and the last \c 4 Bytes for internal use.
  22397. * In that case, before calling this function on a new message you
  22398. * need to set the first \c 12 Bytes of \p nonce_counter to your
  22399. * chosen nonce value, the last four to \c 0, and \p nc_off to \c 0
  22400. * (which will cause \p stream_block to be ignored). That way, you
  22401. * can encrypt at most \c 2**96 messages of up to \c 2**32 blocks
  22402. * each with the same key.
  22403. *
  22404. * The per-message nonce (or information sufficient to reconstruct
  22405. * it) needs to be communicated with the ciphertext and must be
  22406. * unique. The recommended way to ensure uniqueness is to use a
  22407. * message counter. An alternative is to generate random nonces,
  22408. * but this limits the number of messages that can be securely
  22409. * encrypted: for example, with 96-bit random nonces, you should
  22410. * not encrypt more than 2**32 messages with the same key.
  22411. *
  22412. * Note that for both stategies, sizes are measured in blocks and
  22413. * that a CAMELLIA block is \c 16 Bytes.
  22414. *
  22415. * \warning Upon return, \p stream_block contains sensitive data. Its
  22416. * content must not be written to insecure storage and should be
  22417. * securely discarded as soon as it's no longer needed.
  22418. *
  22419. * \param ctx The CAMELLIA context to use. This must be initialized
  22420. * and bound to a key.
  22421. * \param length The length of the input data \p input in Bytes.
  22422. * Any value is allowed.
  22423. * \param nc_off The offset in the current \p stream_block (for resuming
  22424. * within current cipher stream). The offset pointer to
  22425. * should be \c 0 at the start of a stream. It is updated
  22426. * at the end of this call.
  22427. * \param nonce_counter The 128-bit nonce and counter. This must be a read/write
  22428. * buffer of length \c 16 Bytes.
  22429. * \param stream_block The saved stream-block for resuming. This must be a
  22430. * read/write buffer of length \c 16 Bytes.
  22431. * \param input The input data stream. This must be a readable buffer of
  22432. * size \p length Bytes.
  22433. * \param output The output data stream. This must be a writable buffer
  22434. * of size \p length Bytes.
  22435. *
  22436. * \return \c 0 if successful.
  22437. * \return A negative error code on failure.
  22438. */
  22439. int mbedtls_camellia_crypt_ctr( mbedtls_camellia_context *ctx,
  22440. size_t length,
  22441. size_t *nc_off,
  22442. unsigned char nonce_counter[16],
  22443. unsigned char stream_block[16],
  22444. const unsigned char *input,
  22445. unsigned char *output );
  22446. #endif /* MBEDTLS_CIPHER_MODE_CTR */
  22447. #if defined(MBEDTLS_SELF_TEST)
  22448. /**
  22449. * \brief Checkup routine
  22450. *
  22451. * \return 0 if successful, or 1 if the test failed
  22452. */
  22453. int mbedtls_camellia_self_test( int verbose );
  22454. #endif /* MBEDTLS_SELF_TEST */
  22455. #ifdef __cplusplus
  22456. }
  22457. #endif
  22458. #endif /* camellia.h */
  22459. /********* Start of file include/mbedtls/ctr_drbg.h ************/
  22460. /**
  22461. * \file ctr_drbg.h
  22462. *
  22463. * \brief This file contains definitions and functions for the
  22464. * CTR_DRBG pseudorandom generator.
  22465. *
  22466. * CTR_DRBG is a standardized way of building a PRNG from a block-cipher
  22467. * in counter mode operation, as defined in <em>NIST SP 800-90A:
  22468. * Recommendation for Random Number Generation Using Deterministic Random
  22469. * Bit Generators</em>.
  22470. *
  22471. * The Mbed TLS implementation of CTR_DRBG uses AES-256 (default) or AES-128
  22472. * (if \c MBEDTLS_CTR_DRBG_USE_128_BIT_KEY is enabled at compile time)
  22473. * as the underlying block cipher, with a derivation function.
  22474. *
  22475. * The security strength as defined in NIST SP 800-90A is
  22476. * 128 bits when AES-128 is used (\c MBEDTLS_CTR_DRBG_USE_128_BIT_KEY enabled)
  22477. * and 256 bits otherwise, provided that #MBEDTLS_CTR_DRBG_ENTROPY_LEN is
  22478. * kept at its default value (and not overridden in config.h) and that the
  22479. * DRBG instance is set up with default parameters.
  22480. * See the documentation of mbedtls_ctr_drbg_seed() for more
  22481. * information.
  22482. */
  22483. /*
  22484. * Copyright The Mbed TLS Contributors
  22485. * SPDX-License-Identifier: Apache-2.0
  22486. *
  22487. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  22488. * not use this file except in compliance with the License.
  22489. * You may obtain a copy of the License at
  22490. *
  22491. * http://www.apache.org/licenses/LICENSE-2.0
  22492. *
  22493. * Unless required by applicable law or agreed to in writing, software
  22494. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  22495. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  22496. * See the License for the specific language governing permissions and
  22497. * limitations under the License.
  22498. */
  22499. #ifndef MBEDTLS_CTR_DRBG_H
  22500. #define MBEDTLS_CTR_DRBG_H
  22501. #if !defined(MBEDTLS_CONFIG_FILE)
  22502. #else
  22503. #endif
  22504. #if defined(MBEDTLS_THREADING_C)
  22505. #endif
  22506. /** The entropy source failed. */
  22507. #define MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED -0x0034
  22508. /** The requested random buffer length is too big. */
  22509. #define MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG -0x0036
  22510. /** The input (entropy + additional data) is too large. */
  22511. #define MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG -0x0038
  22512. /** Read or write error in file. */
  22513. #define MBEDTLS_ERR_CTR_DRBG_FILE_IO_ERROR -0x003A
  22514. #define MBEDTLS_CTR_DRBG_BLOCKSIZE 16 /**< The block size used by the cipher. */
  22515. #if defined(MBEDTLS_CTR_DRBG_USE_128_BIT_KEY)
  22516. #define MBEDTLS_CTR_DRBG_KEYSIZE 16
  22517. /**< The key size in bytes used by the cipher.
  22518. *
  22519. * Compile-time choice: 16 bytes (128 bits)
  22520. * because #MBEDTLS_CTR_DRBG_USE_128_BIT_KEY is enabled.
  22521. */
  22522. #else
  22523. #define MBEDTLS_CTR_DRBG_KEYSIZE 32
  22524. /**< The key size in bytes used by the cipher.
  22525. *
  22526. * Compile-time choice: 32 bytes (256 bits)
  22527. * because \c MBEDTLS_CTR_DRBG_USE_128_BIT_KEY is disabled.
  22528. */
  22529. #endif
  22530. #define MBEDTLS_CTR_DRBG_KEYBITS ( MBEDTLS_CTR_DRBG_KEYSIZE * 8 ) /**< The key size for the DRBG operation, in bits. */
  22531. #define MBEDTLS_CTR_DRBG_SEEDLEN ( MBEDTLS_CTR_DRBG_KEYSIZE + MBEDTLS_CTR_DRBG_BLOCKSIZE ) /**< The seed length, calculated as (counter + AES key). */
  22532. /**
  22533. * \name SECTION: Module settings
  22534. *
  22535. * The configuration options you can set for this module are in this section.
  22536. * Either change them in config.h or define them using the compiler command
  22537. * line.
  22538. * \{
  22539. */
  22540. /** \def MBEDTLS_CTR_DRBG_ENTROPY_LEN
  22541. *
  22542. * \brief The amount of entropy used per seed by default, in bytes.
  22543. */
  22544. #if !defined(MBEDTLS_CTR_DRBG_ENTROPY_LEN)
  22545. #if defined(MBEDTLS_SHA512_C) && !defined(MBEDTLS_ENTROPY_FORCE_SHA256)
  22546. /** This is 48 bytes because the entropy module uses SHA-512
  22547. * (\c MBEDTLS_ENTROPY_FORCE_SHA256 is disabled).
  22548. */
  22549. #define MBEDTLS_CTR_DRBG_ENTROPY_LEN 48
  22550. #else /* defined(MBEDTLS_SHA512_C) && !defined(MBEDTLS_ENTROPY_FORCE_SHA256) */
  22551. /** This is 32 bytes because the entropy module uses SHA-256
  22552. * (the SHA512 module is disabled or
  22553. * \c MBEDTLS_ENTROPY_FORCE_SHA256 is enabled).
  22554. */
  22555. #if !defined(MBEDTLS_CTR_DRBG_USE_128_BIT_KEY)
  22556. /** \warning To achieve a 256-bit security strength, you must pass a nonce
  22557. * to mbedtls_ctr_drbg_seed().
  22558. */
  22559. #endif /* !defined(MBEDTLS_CTR_DRBG_USE_128_BIT_KEY) */
  22560. #define MBEDTLS_CTR_DRBG_ENTROPY_LEN 32
  22561. #endif /* defined(MBEDTLS_SHA512_C) && !defined(MBEDTLS_ENTROPY_FORCE_SHA256) */
  22562. #endif /* !defined(MBEDTLS_CTR_DRBG_ENTROPY_LEN) */
  22563. #if !defined(MBEDTLS_CTR_DRBG_RESEED_INTERVAL)
  22564. #define MBEDTLS_CTR_DRBG_RESEED_INTERVAL 10000
  22565. /**< The interval before reseed is performed by default. */
  22566. #endif
  22567. #if !defined(MBEDTLS_CTR_DRBG_MAX_INPUT)
  22568. #define MBEDTLS_CTR_DRBG_MAX_INPUT 256
  22569. /**< The maximum number of additional input Bytes. */
  22570. #endif
  22571. #if !defined(MBEDTLS_CTR_DRBG_MAX_REQUEST)
  22572. #define MBEDTLS_CTR_DRBG_MAX_REQUEST 1024
  22573. /**< The maximum number of requested Bytes per call. */
  22574. #endif
  22575. #if !defined(MBEDTLS_CTR_DRBG_MAX_SEED_INPUT)
  22576. #define MBEDTLS_CTR_DRBG_MAX_SEED_INPUT 384
  22577. /**< The maximum size of seed or reseed buffer in bytes. */
  22578. #endif
  22579. /* \} name SECTION: Module settings */
  22580. #define MBEDTLS_CTR_DRBG_PR_OFF 0
  22581. /**< Prediction resistance is disabled. */
  22582. #define MBEDTLS_CTR_DRBG_PR_ON 1
  22583. /**< Prediction resistance is enabled. */
  22584. #ifdef __cplusplus
  22585. extern "C" {
  22586. #endif
  22587. #if MBEDTLS_CTR_DRBG_ENTROPY_LEN >= MBEDTLS_CTR_DRBG_KEYSIZE * 3 / 2
  22588. /** The default length of the nonce read from the entropy source.
  22589. *
  22590. * This is \c 0 because a single read from the entropy source is sufficient
  22591. * to include a nonce.
  22592. * See the documentation of mbedtls_ctr_drbg_seed() for more information.
  22593. */
  22594. #define MBEDTLS_CTR_DRBG_ENTROPY_NONCE_LEN 0
  22595. #else
  22596. /** The default length of the nonce read from the entropy source.
  22597. *
  22598. * This is half of the default entropy length because a single read from
  22599. * the entropy source does not provide enough material to form a nonce.
  22600. * See the documentation of mbedtls_ctr_drbg_seed() for more information.
  22601. */
  22602. #define MBEDTLS_CTR_DRBG_ENTROPY_NONCE_LEN ( MBEDTLS_CTR_DRBG_ENTROPY_LEN + 1 ) / 2
  22603. #endif
  22604. /**
  22605. * \brief The CTR_DRBG context structure.
  22606. */
  22607. typedef struct mbedtls_ctr_drbg_context
  22608. {
  22609. unsigned char counter[16]; /*!< The counter (V). */
  22610. int reseed_counter; /*!< The reseed counter.
  22611. * This is the number of requests that have
  22612. * been made since the last (re)seeding,
  22613. * minus one.
  22614. * Before the initial seeding, this field
  22615. * contains the amount of entropy in bytes
  22616. * to use as a nonce for the initial seeding,
  22617. * or -1 if no nonce length has been explicitly
  22618. * set (see mbedtls_ctr_drbg_set_nonce_len()).
  22619. */
  22620. int prediction_resistance; /*!< This determines whether prediction
  22621. resistance is enabled, that is
  22622. whether to systematically reseed before
  22623. each random generation. */
  22624. size_t entropy_len; /*!< The amount of entropy grabbed on each
  22625. seed or reseed operation, in bytes. */
  22626. int reseed_interval; /*!< The reseed interval.
  22627. * This is the maximum number of requests
  22628. * that can be made between reseedings. */
  22629. mbedtls_aes_context aes_ctx; /*!< The AES context. */
  22630. /*
  22631. * Callbacks (Entropy)
  22632. */
  22633. int (*f_entropy)(void *, unsigned char *, size_t);
  22634. /*!< The entropy callback function. */
  22635. void *p_entropy; /*!< The context for the entropy function. */
  22636. #if defined(MBEDTLS_THREADING_C)
  22637. /* Invariant: the mutex is initialized if and only if f_entropy != NULL.
  22638. * This means that the mutex is initialized during the initial seeding
  22639. * in mbedtls_ctr_drbg_seed() and freed in mbedtls_ctr_drbg_free().
  22640. *
  22641. * Note that this invariant may change without notice. Do not rely on it
  22642. * and do not access the mutex directly in application code.
  22643. */
  22644. mbedtls_threading_mutex_t mutex;
  22645. #endif
  22646. }
  22647. mbedtls_ctr_drbg_context;
  22648. /**
  22649. * \brief This function initializes the CTR_DRBG context,
  22650. * and prepares it for mbedtls_ctr_drbg_seed()
  22651. * or mbedtls_ctr_drbg_free().
  22652. *
  22653. * \note The reseed interval is
  22654. * #MBEDTLS_CTR_DRBG_RESEED_INTERVAL by default.
  22655. * You can override it by calling
  22656. * mbedtls_ctr_drbg_set_reseed_interval().
  22657. *
  22658. * \param ctx The CTR_DRBG context to initialize.
  22659. */
  22660. void mbedtls_ctr_drbg_init( mbedtls_ctr_drbg_context *ctx );
  22661. /**
  22662. * \brief This function seeds and sets up the CTR_DRBG
  22663. * entropy source for future reseeds.
  22664. *
  22665. * A typical choice for the \p f_entropy and \p p_entropy parameters is
  22666. * to use the entropy module:
  22667. * - \p f_entropy is mbedtls_entropy_func();
  22668. * - \p p_entropy is an instance of ::mbedtls_entropy_context initialized
  22669. * with mbedtls_entropy_init() (which registers the platform's default
  22670. * entropy sources).
  22671. *
  22672. * The entropy length is #MBEDTLS_CTR_DRBG_ENTROPY_LEN by default.
  22673. * You can override it by calling mbedtls_ctr_drbg_set_entropy_len().
  22674. *
  22675. * The entropy nonce length is:
  22676. * - \c 0 if the entropy length is at least 3/2 times the entropy length,
  22677. * which guarantees that the security strength is the maximum permitted
  22678. * by the key size and entropy length according to NIST SP 800-90A §10.2.1;
  22679. * - Half the entropy length otherwise.
  22680. * You can override it by calling mbedtls_ctr_drbg_set_nonce_len().
  22681. * With the default entropy length, the entropy nonce length is
  22682. * #MBEDTLS_CTR_DRBG_ENTROPY_NONCE_LEN.
  22683. *
  22684. * You can provide a nonce and personalization string in addition to the
  22685. * entropy source, to make this instantiation as unique as possible.
  22686. * See SP 800-90A §8.6.7 for more details about nonces.
  22687. *
  22688. * The _seed_material_ value passed to the derivation function in
  22689. * the CTR_DRBG Instantiate Process described in NIST SP 800-90A §10.2.1.3.2
  22690. * is the concatenation of the following strings:
  22691. * - A string obtained by calling \p f_entropy function for the entropy
  22692. * length.
  22693. */
  22694. #if MBEDTLS_CTR_DRBG_ENTROPY_NONCE_LEN == 0
  22695. /**
  22696. * - If mbedtls_ctr_drbg_set_nonce_len() has been called, a string
  22697. * obtained by calling \p f_entropy function for the specified length.
  22698. */
  22699. #else
  22700. /**
  22701. * - A string obtained by calling \p f_entropy function for the entropy nonce
  22702. * length. If the entropy nonce length is \c 0, this function does not
  22703. * make a second call to \p f_entropy.
  22704. */
  22705. #endif
  22706. #if defined(MBEDTLS_THREADING_C)
  22707. /**
  22708. * \note When Mbed TLS is built with threading support,
  22709. * after this function returns successfully,
  22710. * it is safe to call mbedtls_ctr_drbg_random()
  22711. * from multiple threads. Other operations, including
  22712. * reseeding, are not thread-safe.
  22713. */
  22714. #endif /* MBEDTLS_THREADING_C */
  22715. /**
  22716. * - The \p custom string.
  22717. *
  22718. * \note To achieve the nominal security strength permitted
  22719. * by CTR_DRBG, the entropy length must be:
  22720. * - at least 16 bytes for a 128-bit strength
  22721. * (maximum achievable strength when using AES-128);
  22722. * - at least 32 bytes for a 256-bit strength
  22723. * (maximum achievable strength when using AES-256).
  22724. *
  22725. * In addition, if you do not pass a nonce in \p custom,
  22726. * the sum of the entropy length
  22727. * and the entropy nonce length must be:
  22728. * - at least 24 bytes for a 128-bit strength
  22729. * (maximum achievable strength when using AES-128);
  22730. * - at least 48 bytes for a 256-bit strength
  22731. * (maximum achievable strength when using AES-256).
  22732. *
  22733. * \param ctx The CTR_DRBG context to seed.
  22734. * It must have been initialized with
  22735. * mbedtls_ctr_drbg_init().
  22736. * After a successful call to mbedtls_ctr_drbg_seed(),
  22737. * you may not call mbedtls_ctr_drbg_seed() again on
  22738. * the same context unless you call
  22739. * mbedtls_ctr_drbg_free() and mbedtls_ctr_drbg_init()
  22740. * again first.
  22741. * After a failed call to mbedtls_ctr_drbg_seed(),
  22742. * you must call mbedtls_ctr_drbg_free().
  22743. * \param f_entropy The entropy callback, taking as arguments the
  22744. * \p p_entropy context, the buffer to fill, and the
  22745. * length of the buffer.
  22746. * \p f_entropy is always called with a buffer size
  22747. * less than or equal to the entropy length.
  22748. * \param p_entropy The entropy context to pass to \p f_entropy.
  22749. * \param custom The personalization string.
  22750. * This can be \c NULL, in which case the personalization
  22751. * string is empty regardless of the value of \p len.
  22752. * \param len The length of the personalization string.
  22753. * This must be at most
  22754. * #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT
  22755. * - #MBEDTLS_CTR_DRBG_ENTROPY_LEN.
  22756. *
  22757. * \return \c 0 on success.
  22758. * \return #MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED on failure.
  22759. */
  22760. int mbedtls_ctr_drbg_seed( mbedtls_ctr_drbg_context *ctx,
  22761. int (*f_entropy)(void *, unsigned char *, size_t),
  22762. void *p_entropy,
  22763. const unsigned char *custom,
  22764. size_t len );
  22765. /**
  22766. * \brief This function resets CTR_DRBG context to the state immediately
  22767. * after initial call of mbedtls_ctr_drbg_init().
  22768. *
  22769. * \param ctx The CTR_DRBG context to clear.
  22770. */
  22771. void mbedtls_ctr_drbg_free( mbedtls_ctr_drbg_context *ctx );
  22772. /**
  22773. * \brief This function turns prediction resistance on or off.
  22774. * The default value is off.
  22775. *
  22776. * \note If enabled, entropy is gathered at the beginning of
  22777. * every call to mbedtls_ctr_drbg_random_with_add()
  22778. * or mbedtls_ctr_drbg_random().
  22779. * Only use this if your entropy source has sufficient
  22780. * throughput.
  22781. *
  22782. * \param ctx The CTR_DRBG context.
  22783. * \param resistance #MBEDTLS_CTR_DRBG_PR_ON or #MBEDTLS_CTR_DRBG_PR_OFF.
  22784. */
  22785. void mbedtls_ctr_drbg_set_prediction_resistance( mbedtls_ctr_drbg_context *ctx,
  22786. int resistance );
  22787. /**
  22788. * \brief This function sets the amount of entropy grabbed on each
  22789. * seed or reseed.
  22790. *
  22791. * The default value is #MBEDTLS_CTR_DRBG_ENTROPY_LEN.
  22792. *
  22793. * \note The security strength of CTR_DRBG is bounded by the
  22794. * entropy length. Thus:
  22795. * - When using AES-256
  22796. * (\c MBEDTLS_CTR_DRBG_USE_128_BIT_KEY is disabled,
  22797. * which is the default),
  22798. * \p len must be at least 32 (in bytes)
  22799. * to achieve a 256-bit strength.
  22800. * - When using AES-128
  22801. * (\c MBEDTLS_CTR_DRBG_USE_128_BIT_KEY is enabled)
  22802. * \p len must be at least 16 (in bytes)
  22803. * to achieve a 128-bit strength.
  22804. *
  22805. * \param ctx The CTR_DRBG context.
  22806. * \param len The amount of entropy to grab, in bytes.
  22807. * This must be at most #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT
  22808. * and at most the maximum length accepted by the
  22809. * entropy function that is set in the context.
  22810. */
  22811. void mbedtls_ctr_drbg_set_entropy_len( mbedtls_ctr_drbg_context *ctx,
  22812. size_t len );
  22813. /**
  22814. * \brief This function sets the amount of entropy grabbed
  22815. * as a nonce for the initial seeding.
  22816. *
  22817. * Call this function before calling mbedtls_ctr_drbg_seed() to read
  22818. * a nonce from the entropy source during the initial seeding.
  22819. *
  22820. * \param ctx The CTR_DRBG context.
  22821. * \param len The amount of entropy to grab for the nonce, in bytes.
  22822. * This must be at most #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT
  22823. * and at most the maximum length accepted by the
  22824. * entropy function that is set in the context.
  22825. *
  22826. * \return \c 0 on success.
  22827. * \return #MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG if \p len is
  22828. * more than #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT.
  22829. * \return #MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED
  22830. * if the initial seeding has already taken place.
  22831. */
  22832. int mbedtls_ctr_drbg_set_nonce_len( mbedtls_ctr_drbg_context *ctx,
  22833. size_t len );
  22834. /**
  22835. * \brief This function sets the reseed interval.
  22836. *
  22837. * The reseed interval is the number of calls to mbedtls_ctr_drbg_random()
  22838. * or mbedtls_ctr_drbg_random_with_add() after which the entropy function
  22839. * is called again.
  22840. *
  22841. * The default value is #MBEDTLS_CTR_DRBG_RESEED_INTERVAL.
  22842. *
  22843. * \param ctx The CTR_DRBG context.
  22844. * \param interval The reseed interval.
  22845. */
  22846. void mbedtls_ctr_drbg_set_reseed_interval( mbedtls_ctr_drbg_context *ctx,
  22847. int interval );
  22848. /**
  22849. * \brief This function reseeds the CTR_DRBG context, that is
  22850. * extracts data from the entropy source.
  22851. *
  22852. * \note This function is not thread-safe. It is not safe
  22853. * to call this function if another thread might be
  22854. * concurrently obtaining random numbers from the same
  22855. * context or updating or reseeding the same context.
  22856. *
  22857. * \param ctx The CTR_DRBG context.
  22858. * \param additional Additional data to add to the state. Can be \c NULL.
  22859. * \param len The length of the additional data.
  22860. * This must be less than
  22861. * #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT - \c entropy_len
  22862. * where \c entropy_len is the entropy length
  22863. * configured for the context.
  22864. *
  22865. * \return \c 0 on success.
  22866. * \return #MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED on failure.
  22867. */
  22868. int mbedtls_ctr_drbg_reseed( mbedtls_ctr_drbg_context *ctx,
  22869. const unsigned char *additional, size_t len );
  22870. /**
  22871. * \brief This function updates the state of the CTR_DRBG context.
  22872. *
  22873. * \note This function is not thread-safe. It is not safe
  22874. * to call this function if another thread might be
  22875. * concurrently obtaining random numbers from the same
  22876. * context or updating or reseeding the same context.
  22877. *
  22878. * \param ctx The CTR_DRBG context.
  22879. * \param additional The data to update the state with. This must not be
  22880. * \c NULL unless \p add_len is \c 0.
  22881. * \param add_len Length of \p additional in bytes. This must be at
  22882. * most #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT.
  22883. *
  22884. * \return \c 0 on success.
  22885. * \return #MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG if
  22886. * \p add_len is more than
  22887. * #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT.
  22888. * \return An error from the underlying AES cipher on failure.
  22889. */
  22890. int mbedtls_ctr_drbg_update_ret( mbedtls_ctr_drbg_context *ctx,
  22891. const unsigned char *additional,
  22892. size_t add_len );
  22893. /**
  22894. * \brief This function updates a CTR_DRBG instance with additional
  22895. * data and uses it to generate random data.
  22896. *
  22897. * This function automatically reseeds if the reseed counter is exceeded
  22898. * or prediction resistance is enabled.
  22899. *
  22900. * \note This function is not thread-safe. It is not safe
  22901. * to call this function if another thread might be
  22902. * concurrently obtaining random numbers from the same
  22903. * context or updating or reseeding the same context.
  22904. *
  22905. * \param p_rng The CTR_DRBG context. This must be a pointer to a
  22906. * #mbedtls_ctr_drbg_context structure.
  22907. * \param output The buffer to fill.
  22908. * \param output_len The length of the buffer in bytes.
  22909. * \param additional Additional data to update. Can be \c NULL, in which
  22910. * case the additional data is empty regardless of
  22911. * the value of \p add_len.
  22912. * \param add_len The length of the additional data
  22913. * if \p additional is not \c NULL.
  22914. * This must be less than #MBEDTLS_CTR_DRBG_MAX_INPUT
  22915. * and less than
  22916. * #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT - \c entropy_len
  22917. * where \c entropy_len is the entropy length
  22918. * configured for the context.
  22919. *
  22920. * \return \c 0 on success.
  22921. * \return #MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED or
  22922. * #MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG on failure.
  22923. */
  22924. int mbedtls_ctr_drbg_random_with_add( void *p_rng,
  22925. unsigned char *output, size_t output_len,
  22926. const unsigned char *additional, size_t add_len );
  22927. /**
  22928. * \brief This function uses CTR_DRBG to generate random data.
  22929. *
  22930. * This function automatically reseeds if the reseed counter is exceeded
  22931. * or prediction resistance is enabled.
  22932. */
  22933. #if defined(MBEDTLS_THREADING_C)
  22934. /**
  22935. * \note When Mbed TLS is built with threading support,
  22936. * it is safe to call mbedtls_ctr_drbg_random()
  22937. * from multiple threads. Other operations, including
  22938. * reseeding, are not thread-safe.
  22939. */
  22940. #endif /* MBEDTLS_THREADING_C */
  22941. /**
  22942. * \param p_rng The CTR_DRBG context. This must be a pointer to a
  22943. * #mbedtls_ctr_drbg_context structure.
  22944. * \param output The buffer to fill.
  22945. * \param output_len The length of the buffer in bytes.
  22946. *
  22947. * \return \c 0 on success.
  22948. * \return #MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED or
  22949. * #MBEDTLS_ERR_CTR_DRBG_REQUEST_TOO_BIG on failure.
  22950. */
  22951. int mbedtls_ctr_drbg_random( void *p_rng,
  22952. unsigned char *output, size_t output_len );
  22953. #if ! defined(MBEDTLS_DEPRECATED_REMOVED)
  22954. #if defined(MBEDTLS_DEPRECATED_WARNING)
  22955. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  22956. #else
  22957. #define MBEDTLS_DEPRECATED
  22958. #endif
  22959. /**
  22960. * \brief This function updates the state of the CTR_DRBG context.
  22961. *
  22962. * \deprecated Superseded by mbedtls_ctr_drbg_update_ret()
  22963. * in 2.16.0.
  22964. *
  22965. * \note If \p add_len is greater than
  22966. * #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT, only the first
  22967. * #MBEDTLS_CTR_DRBG_MAX_SEED_INPUT Bytes are used.
  22968. * The remaining Bytes are silently discarded.
  22969. *
  22970. * \param ctx The CTR_DRBG context.
  22971. * \param additional The data to update the state with.
  22972. * \param add_len Length of \p additional data.
  22973. */
  22974. MBEDTLS_DEPRECATED void mbedtls_ctr_drbg_update(
  22975. mbedtls_ctr_drbg_context *ctx,
  22976. const unsigned char *additional,
  22977. size_t add_len );
  22978. #undef MBEDTLS_DEPRECATED
  22979. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  22980. #if defined(MBEDTLS_FS_IO)
  22981. /**
  22982. * \brief This function writes a seed file.
  22983. *
  22984. * \param ctx The CTR_DRBG context.
  22985. * \param path The name of the file.
  22986. *
  22987. * \return \c 0 on success.
  22988. * \return #MBEDTLS_ERR_CTR_DRBG_FILE_IO_ERROR on file error.
  22989. * \return #MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED on reseed
  22990. * failure.
  22991. */
  22992. int mbedtls_ctr_drbg_write_seed_file( mbedtls_ctr_drbg_context *ctx, const char *path );
  22993. /**
  22994. * \brief This function reads and updates a seed file. The seed
  22995. * is added to this instance.
  22996. *
  22997. * \param ctx The CTR_DRBG context.
  22998. * \param path The name of the file.
  22999. *
  23000. * \return \c 0 on success.
  23001. * \return #MBEDTLS_ERR_CTR_DRBG_FILE_IO_ERROR on file error.
  23002. * \return #MBEDTLS_ERR_CTR_DRBG_ENTROPY_SOURCE_FAILED on
  23003. * reseed failure.
  23004. * \return #MBEDTLS_ERR_CTR_DRBG_INPUT_TOO_BIG if the existing
  23005. * seed file is too large.
  23006. */
  23007. int mbedtls_ctr_drbg_update_seed_file( mbedtls_ctr_drbg_context *ctx, const char *path );
  23008. #endif /* MBEDTLS_FS_IO */
  23009. #if defined(MBEDTLS_SELF_TEST)
  23010. /**
  23011. * \brief The CTR_DRBG checkup routine.
  23012. *
  23013. * \return \c 0 on success.
  23014. * \return \c 1 on failure.
  23015. */
  23016. int mbedtls_ctr_drbg_self_test( int verbose );
  23017. #endif /* MBEDTLS_SELF_TEST */
  23018. #ifdef __cplusplus
  23019. }
  23020. #endif
  23021. #endif /* ctr_drbg.h */
  23022. /********* Start of file include/mbedtls/des.h ************/
  23023. /**
  23024. * \file des.h
  23025. *
  23026. * \brief DES block cipher
  23027. *
  23028. * \warning DES is considered a weak cipher and its use constitutes a
  23029. * security risk. We recommend considering stronger ciphers
  23030. * instead.
  23031. */
  23032. /*
  23033. * Copyright The Mbed TLS Contributors
  23034. * SPDX-License-Identifier: Apache-2.0
  23035. *
  23036. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  23037. * not use this file except in compliance with the License.
  23038. * You may obtain a copy of the License at
  23039. *
  23040. * http://www.apache.org/licenses/LICENSE-2.0
  23041. *
  23042. * Unless required by applicable law or agreed to in writing, software
  23043. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  23044. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  23045. * See the License for the specific language governing permissions and
  23046. * limitations under the License.
  23047. *
  23048. */
  23049. #ifndef MBEDTLS_DES_H
  23050. #define MBEDTLS_DES_H
  23051. #if !defined(MBEDTLS_CONFIG_FILE)
  23052. #else
  23053. #endif
  23054. #include <stddef.h>
  23055. #include <stdint.h>
  23056. #define MBEDTLS_DES_ENCRYPT 1
  23057. #define MBEDTLS_DES_DECRYPT 0
  23058. /** The data input has an invalid length. */
  23059. #define MBEDTLS_ERR_DES_INVALID_INPUT_LENGTH -0x0032
  23060. /* MBEDTLS_ERR_DES_HW_ACCEL_FAILED is deprecated and should not be used. */
  23061. /** DES hardware accelerator failed. */
  23062. #define MBEDTLS_ERR_DES_HW_ACCEL_FAILED -0x0033
  23063. #define MBEDTLS_DES_KEY_SIZE 8
  23064. #ifdef __cplusplus
  23065. extern "C" {
  23066. #endif
  23067. #if !defined(MBEDTLS_DES_ALT)
  23068. // Regular implementation
  23069. //
  23070. /**
  23071. * \brief DES context structure
  23072. *
  23073. * \warning DES is considered a weak cipher and its use constitutes a
  23074. * security risk. We recommend considering stronger ciphers
  23075. * instead.
  23076. */
  23077. typedef struct mbedtls_des_context
  23078. {
  23079. uint32_t sk[32]; /*!< DES subkeys */
  23080. }
  23081. mbedtls_des_context;
  23082. /**
  23083. * \brief Triple-DES context structure
  23084. */
  23085. typedef struct mbedtls_des3_context
  23086. {
  23087. uint32_t sk[96]; /*!< 3DES subkeys */
  23088. }
  23089. mbedtls_des3_context;
  23090. #else /* MBEDTLS_DES_ALT */
  23091. #endif /* MBEDTLS_DES_ALT */
  23092. /**
  23093. * \brief Initialize DES context
  23094. *
  23095. * \param ctx DES context to be initialized
  23096. *
  23097. * \warning DES is considered a weak cipher and its use constitutes a
  23098. * security risk. We recommend considering stronger ciphers
  23099. * instead.
  23100. */
  23101. void mbedtls_des_init( mbedtls_des_context *ctx );
  23102. /**
  23103. * \brief Clear DES context
  23104. *
  23105. * \param ctx DES context to be cleared
  23106. *
  23107. * \warning DES is considered a weak cipher and its use constitutes a
  23108. * security risk. We recommend considering stronger ciphers
  23109. * instead.
  23110. */
  23111. void mbedtls_des_free( mbedtls_des_context *ctx );
  23112. /**
  23113. * \brief Initialize Triple-DES context
  23114. *
  23115. * \param ctx DES3 context to be initialized
  23116. */
  23117. void mbedtls_des3_init( mbedtls_des3_context *ctx );
  23118. /**
  23119. * \brief Clear Triple-DES context
  23120. *
  23121. * \param ctx DES3 context to be cleared
  23122. */
  23123. void mbedtls_des3_free( mbedtls_des3_context *ctx );
  23124. /**
  23125. * \brief Set key parity on the given key to odd.
  23126. *
  23127. * DES keys are 56 bits long, but each byte is padded with
  23128. * a parity bit to allow verification.
  23129. *
  23130. * \param key 8-byte secret key
  23131. *
  23132. * \warning DES is considered a weak cipher and its use constitutes a
  23133. * security risk. We recommend considering stronger ciphers
  23134. * instead.
  23135. */
  23136. void mbedtls_des_key_set_parity( unsigned char key[MBEDTLS_DES_KEY_SIZE] );
  23137. /**
  23138. * \brief Check that key parity on the given key is odd.
  23139. *
  23140. * DES keys are 56 bits long, but each byte is padded with
  23141. * a parity bit to allow verification.
  23142. *
  23143. * \param key 8-byte secret key
  23144. *
  23145. * \return 0 is parity was ok, 1 if parity was not correct.
  23146. *
  23147. * \warning DES is considered a weak cipher and its use constitutes a
  23148. * security risk. We recommend considering stronger ciphers
  23149. * instead.
  23150. */
  23151. MBEDTLS_CHECK_RETURN_TYPICAL
  23152. int mbedtls_des_key_check_key_parity( const unsigned char key[MBEDTLS_DES_KEY_SIZE] );
  23153. /**
  23154. * \brief Check that key is not a weak or semi-weak DES key
  23155. *
  23156. * \param key 8-byte secret key
  23157. *
  23158. * \return 0 if no weak key was found, 1 if a weak key was identified.
  23159. *
  23160. * \warning DES is considered a weak cipher and its use constitutes a
  23161. * security risk. We recommend considering stronger ciphers
  23162. * instead.
  23163. */
  23164. MBEDTLS_CHECK_RETURN_TYPICAL
  23165. int mbedtls_des_key_check_weak( const unsigned char key[MBEDTLS_DES_KEY_SIZE] );
  23166. /**
  23167. * \brief DES key schedule (56-bit, encryption)
  23168. *
  23169. * \param ctx DES context to be initialized
  23170. * \param key 8-byte secret key
  23171. *
  23172. * \return 0
  23173. *
  23174. * \warning DES is considered a weak cipher and its use constitutes a
  23175. * security risk. We recommend considering stronger ciphers
  23176. * instead.
  23177. */
  23178. MBEDTLS_CHECK_RETURN_TYPICAL
  23179. int mbedtls_des_setkey_enc( mbedtls_des_context *ctx, const unsigned char key[MBEDTLS_DES_KEY_SIZE] );
  23180. /**
  23181. * \brief DES key schedule (56-bit, decryption)
  23182. *
  23183. * \param ctx DES context to be initialized
  23184. * \param key 8-byte secret key
  23185. *
  23186. * \return 0
  23187. *
  23188. * \warning DES is considered a weak cipher and its use constitutes a
  23189. * security risk. We recommend considering stronger ciphers
  23190. * instead.
  23191. */
  23192. MBEDTLS_CHECK_RETURN_TYPICAL
  23193. int mbedtls_des_setkey_dec( mbedtls_des_context *ctx, const unsigned char key[MBEDTLS_DES_KEY_SIZE] );
  23194. /**
  23195. * \brief Triple-DES key schedule (112-bit, encryption)
  23196. *
  23197. * \param ctx 3DES context to be initialized
  23198. * \param key 16-byte secret key
  23199. *
  23200. * \return 0
  23201. */
  23202. MBEDTLS_CHECK_RETURN_TYPICAL
  23203. int mbedtls_des3_set2key_enc( mbedtls_des3_context *ctx,
  23204. const unsigned char key[MBEDTLS_DES_KEY_SIZE * 2] );
  23205. /**
  23206. * \brief Triple-DES key schedule (112-bit, decryption)
  23207. *
  23208. * \param ctx 3DES context to be initialized
  23209. * \param key 16-byte secret key
  23210. *
  23211. * \return 0
  23212. */
  23213. MBEDTLS_CHECK_RETURN_TYPICAL
  23214. int mbedtls_des3_set2key_dec( mbedtls_des3_context *ctx,
  23215. const unsigned char key[MBEDTLS_DES_KEY_SIZE * 2] );
  23216. /**
  23217. * \brief Triple-DES key schedule (168-bit, encryption)
  23218. *
  23219. * \param ctx 3DES context to be initialized
  23220. * \param key 24-byte secret key
  23221. *
  23222. * \return 0
  23223. */
  23224. MBEDTLS_CHECK_RETURN_TYPICAL
  23225. int mbedtls_des3_set3key_enc( mbedtls_des3_context *ctx,
  23226. const unsigned char key[MBEDTLS_DES_KEY_SIZE * 3] );
  23227. /**
  23228. * \brief Triple-DES key schedule (168-bit, decryption)
  23229. *
  23230. * \param ctx 3DES context to be initialized
  23231. * \param key 24-byte secret key
  23232. *
  23233. * \return 0
  23234. */
  23235. MBEDTLS_CHECK_RETURN_TYPICAL
  23236. int mbedtls_des3_set3key_dec( mbedtls_des3_context *ctx,
  23237. const unsigned char key[MBEDTLS_DES_KEY_SIZE * 3] );
  23238. /**
  23239. * \brief DES-ECB block encryption/decryption
  23240. *
  23241. * \param ctx DES context
  23242. * \param input 64-bit input block
  23243. * \param output 64-bit output block
  23244. *
  23245. * \return 0 if successful
  23246. *
  23247. * \warning DES is considered a weak cipher and its use constitutes a
  23248. * security risk. We recommend considering stronger ciphers
  23249. * instead.
  23250. */
  23251. MBEDTLS_CHECK_RETURN_TYPICAL
  23252. int mbedtls_des_crypt_ecb( mbedtls_des_context *ctx,
  23253. const unsigned char input[8],
  23254. unsigned char output[8] );
  23255. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  23256. /**
  23257. * \brief DES-CBC buffer encryption/decryption
  23258. *
  23259. * \note Upon exit, the content of the IV is updated so that you can
  23260. * call the function same function again on the following
  23261. * block(s) of data and get the same result as if it was
  23262. * encrypted in one call. This allows a "streaming" usage.
  23263. * If on the other hand you need to retain the contents of the
  23264. * IV, you should either save it manually or use the cipher
  23265. * module instead.
  23266. *
  23267. * \param ctx DES context
  23268. * \param mode MBEDTLS_DES_ENCRYPT or MBEDTLS_DES_DECRYPT
  23269. * \param length length of the input data
  23270. * \param iv initialization vector (updated after use)
  23271. * \param input buffer holding the input data
  23272. * \param output buffer holding the output data
  23273. *
  23274. * \warning DES is considered a weak cipher and its use constitutes a
  23275. * security risk. We recommend considering stronger ciphers
  23276. * instead.
  23277. */
  23278. MBEDTLS_CHECK_RETURN_TYPICAL
  23279. int mbedtls_des_crypt_cbc( mbedtls_des_context *ctx,
  23280. int mode,
  23281. size_t length,
  23282. unsigned char iv[8],
  23283. const unsigned char *input,
  23284. unsigned char *output );
  23285. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  23286. /**
  23287. * \brief 3DES-ECB block encryption/decryption
  23288. *
  23289. * \param ctx 3DES context
  23290. * \param input 64-bit input block
  23291. * \param output 64-bit output block
  23292. *
  23293. * \return 0 if successful
  23294. */
  23295. MBEDTLS_CHECK_RETURN_TYPICAL
  23296. int mbedtls_des3_crypt_ecb( mbedtls_des3_context *ctx,
  23297. const unsigned char input[8],
  23298. unsigned char output[8] );
  23299. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  23300. /**
  23301. * \brief 3DES-CBC buffer encryption/decryption
  23302. *
  23303. * \note Upon exit, the content of the IV is updated so that you can
  23304. * call the function same function again on the following
  23305. * block(s) of data and get the same result as if it was
  23306. * encrypted in one call. This allows a "streaming" usage.
  23307. * If on the other hand you need to retain the contents of the
  23308. * IV, you should either save it manually or use the cipher
  23309. * module instead.
  23310. *
  23311. * \param ctx 3DES context
  23312. * \param mode MBEDTLS_DES_ENCRYPT or MBEDTLS_DES_DECRYPT
  23313. * \param length length of the input data
  23314. * \param iv initialization vector (updated after use)
  23315. * \param input buffer holding the input data
  23316. * \param output buffer holding the output data
  23317. *
  23318. * \return 0 if successful, or MBEDTLS_ERR_DES_INVALID_INPUT_LENGTH
  23319. */
  23320. MBEDTLS_CHECK_RETURN_TYPICAL
  23321. int mbedtls_des3_crypt_cbc( mbedtls_des3_context *ctx,
  23322. int mode,
  23323. size_t length,
  23324. unsigned char iv[8],
  23325. const unsigned char *input,
  23326. unsigned char *output );
  23327. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  23328. /**
  23329. * \brief Internal function for key expansion.
  23330. * (Only exposed to allow overriding it,
  23331. * see MBEDTLS_DES_SETKEY_ALT)
  23332. *
  23333. * \param SK Round keys
  23334. * \param key Base key
  23335. *
  23336. * \warning DES is considered a weak cipher and its use constitutes a
  23337. * security risk. We recommend considering stronger ciphers
  23338. * instead.
  23339. */
  23340. void mbedtls_des_setkey( uint32_t SK[32],
  23341. const unsigned char key[MBEDTLS_DES_KEY_SIZE] );
  23342. #if defined(MBEDTLS_SELF_TEST)
  23343. /**
  23344. * \brief Checkup routine
  23345. *
  23346. * \return 0 if successful, or 1 if the test failed
  23347. */
  23348. MBEDTLS_CHECK_RETURN_CRITICAL
  23349. int mbedtls_des_self_test( int verbose );
  23350. #endif /* MBEDTLS_SELF_TEST */
  23351. #ifdef __cplusplus
  23352. }
  23353. #endif
  23354. #endif /* des.h */
  23355. /********* Start of file include/mbedtls/entropy.h ************/
  23356. /**
  23357. * \file entropy.h
  23358. *
  23359. * \brief Entropy accumulator implementation
  23360. */
  23361. /*
  23362. * Copyright The Mbed TLS Contributors
  23363. * SPDX-License-Identifier: Apache-2.0
  23364. *
  23365. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  23366. * not use this file except in compliance with the License.
  23367. * You may obtain a copy of the License at
  23368. *
  23369. * http://www.apache.org/licenses/LICENSE-2.0
  23370. *
  23371. * Unless required by applicable law or agreed to in writing, software
  23372. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  23373. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  23374. * See the License for the specific language governing permissions and
  23375. * limitations under the License.
  23376. */
  23377. #ifndef MBEDTLS_ENTROPY_H
  23378. #define MBEDTLS_ENTROPY_H
  23379. #if !defined(MBEDTLS_CONFIG_FILE)
  23380. #else
  23381. #endif
  23382. #include <stddef.h>
  23383. #if defined(MBEDTLS_SHA512_C) && !defined(MBEDTLS_ENTROPY_FORCE_SHA256)
  23384. #define MBEDTLS_ENTROPY_SHA512_ACCUMULATOR
  23385. #else
  23386. #if defined(MBEDTLS_SHA256_C)
  23387. #define MBEDTLS_ENTROPY_SHA256_ACCUMULATOR
  23388. #endif
  23389. #endif
  23390. #if defined(MBEDTLS_THREADING_C)
  23391. #endif
  23392. #if defined(MBEDTLS_HAVEGE_C)
  23393. #endif
  23394. /** Critical entropy source failure. */
  23395. #define MBEDTLS_ERR_ENTROPY_SOURCE_FAILED -0x003C
  23396. /** No more sources can be added. */
  23397. #define MBEDTLS_ERR_ENTROPY_MAX_SOURCES -0x003E
  23398. /** No sources have been added to poll. */
  23399. #define MBEDTLS_ERR_ENTROPY_NO_SOURCES_DEFINED -0x0040
  23400. /** No strong sources have been added to poll. */
  23401. #define MBEDTLS_ERR_ENTROPY_NO_STRONG_SOURCE -0x003D
  23402. /** Read/write error in file. */
  23403. #define MBEDTLS_ERR_ENTROPY_FILE_IO_ERROR -0x003F
  23404. /**
  23405. * \name SECTION: Module settings
  23406. *
  23407. * The configuration options you can set for this module are in this section.
  23408. * Either change them in config.h or define them on the compiler command line.
  23409. * \{
  23410. */
  23411. #if !defined(MBEDTLS_ENTROPY_MAX_SOURCES)
  23412. #define MBEDTLS_ENTROPY_MAX_SOURCES 20 /**< Maximum number of sources supported */
  23413. #endif
  23414. #if !defined(MBEDTLS_ENTROPY_MAX_GATHER)
  23415. #define MBEDTLS_ENTROPY_MAX_GATHER 128 /**< Maximum amount requested from entropy sources */
  23416. #endif
  23417. /* \} name SECTION: Module settings */
  23418. #if defined(MBEDTLS_ENTROPY_SHA512_ACCUMULATOR)
  23419. #define MBEDTLS_ENTROPY_BLOCK_SIZE 64 /**< Block size of entropy accumulator (SHA-512) */
  23420. #else
  23421. #define MBEDTLS_ENTROPY_BLOCK_SIZE 32 /**< Block size of entropy accumulator (SHA-256) */
  23422. #endif
  23423. #define MBEDTLS_ENTROPY_MAX_SEED_SIZE 1024 /**< Maximum size of seed we read from seed file */
  23424. #define MBEDTLS_ENTROPY_SOURCE_MANUAL MBEDTLS_ENTROPY_MAX_SOURCES
  23425. #define MBEDTLS_ENTROPY_SOURCE_STRONG 1 /**< Entropy source is strong */
  23426. #define MBEDTLS_ENTROPY_SOURCE_WEAK 0 /**< Entropy source is weak */
  23427. #ifdef __cplusplus
  23428. extern "C" {
  23429. #endif
  23430. /**
  23431. * \brief Entropy poll callback pointer
  23432. *
  23433. * \param data Callback-specific data pointer
  23434. * \param output Data to fill
  23435. * \param len Maximum size to provide
  23436. * \param olen The actual amount of bytes put into the buffer (Can be 0)
  23437. *
  23438. * \return 0 if no critical failures occurred,
  23439. * MBEDTLS_ERR_ENTROPY_SOURCE_FAILED otherwise
  23440. */
  23441. typedef int (*mbedtls_entropy_f_source_ptr)(void *data, unsigned char *output, size_t len,
  23442. size_t *olen);
  23443. /**
  23444. * \brief Entropy source state
  23445. */
  23446. typedef struct mbedtls_entropy_source_state
  23447. {
  23448. mbedtls_entropy_f_source_ptr f_source; /**< The entropy source callback */
  23449. void * p_source; /**< The callback data pointer */
  23450. size_t size; /**< Amount received in bytes */
  23451. size_t threshold; /**< Minimum bytes required before release */
  23452. int strong; /**< Is the source strong? */
  23453. }
  23454. mbedtls_entropy_source_state;
  23455. /**
  23456. * \brief Entropy context structure
  23457. */
  23458. typedef struct mbedtls_entropy_context
  23459. {
  23460. int accumulator_started; /* 0 after init.
  23461. * 1 after the first update.
  23462. * -1 after free. */
  23463. #if defined(MBEDTLS_ENTROPY_SHA512_ACCUMULATOR)
  23464. mbedtls_sha512_context accumulator;
  23465. #elif defined(MBEDTLS_ENTROPY_SHA256_ACCUMULATOR)
  23466. mbedtls_sha256_context accumulator;
  23467. #endif
  23468. int source_count; /* Number of entries used in source. */
  23469. mbedtls_entropy_source_state source[MBEDTLS_ENTROPY_MAX_SOURCES];
  23470. #if defined(MBEDTLS_HAVEGE_C)
  23471. mbedtls_havege_state havege_data;
  23472. #endif
  23473. #if defined(MBEDTLS_THREADING_C)
  23474. mbedtls_threading_mutex_t mutex; /*!< mutex */
  23475. #endif
  23476. #if defined(MBEDTLS_ENTROPY_NV_SEED)
  23477. int initial_entropy_run;
  23478. #endif
  23479. }
  23480. mbedtls_entropy_context;
  23481. /**
  23482. * \brief Initialize the context
  23483. *
  23484. * \param ctx Entropy context to initialize
  23485. */
  23486. void mbedtls_entropy_init( mbedtls_entropy_context *ctx );
  23487. /**
  23488. * \brief Free the data in the context
  23489. *
  23490. * \param ctx Entropy context to free
  23491. */
  23492. void mbedtls_entropy_free( mbedtls_entropy_context *ctx );
  23493. /**
  23494. * \brief Adds an entropy source to poll
  23495. * (Thread-safe if MBEDTLS_THREADING_C is enabled)
  23496. *
  23497. * \param ctx Entropy context
  23498. * \param f_source Entropy function
  23499. * \param p_source Function data
  23500. * \param threshold Minimum required from source before entropy is released
  23501. * ( with mbedtls_entropy_func() ) (in bytes)
  23502. * \param strong MBEDTLS_ENTROPY_SOURCE_STRONG or
  23503. * MBEDTLS_ENTROPY_SOURCE_WEAK.
  23504. * At least one strong source needs to be added.
  23505. * Weaker sources (such as the cycle counter) can be used as
  23506. * a complement.
  23507. *
  23508. * \return 0 if successful or MBEDTLS_ERR_ENTROPY_MAX_SOURCES
  23509. */
  23510. int mbedtls_entropy_add_source( mbedtls_entropy_context *ctx,
  23511. mbedtls_entropy_f_source_ptr f_source, void *p_source,
  23512. size_t threshold, int strong );
  23513. /**
  23514. * \brief Trigger an extra gather poll for the accumulator
  23515. * (Thread-safe if MBEDTLS_THREADING_C is enabled)
  23516. *
  23517. * \param ctx Entropy context
  23518. *
  23519. * \return 0 if successful, or MBEDTLS_ERR_ENTROPY_SOURCE_FAILED
  23520. */
  23521. int mbedtls_entropy_gather( mbedtls_entropy_context *ctx );
  23522. /**
  23523. * \brief Retrieve entropy from the accumulator
  23524. * (Maximum length: MBEDTLS_ENTROPY_BLOCK_SIZE)
  23525. * (Thread-safe if MBEDTLS_THREADING_C is enabled)
  23526. *
  23527. * \param data Entropy context
  23528. * \param output Buffer to fill
  23529. * \param len Number of bytes desired, must be at most MBEDTLS_ENTROPY_BLOCK_SIZE
  23530. *
  23531. * \return 0 if successful, or MBEDTLS_ERR_ENTROPY_SOURCE_FAILED
  23532. */
  23533. int mbedtls_entropy_func( void *data, unsigned char *output, size_t len );
  23534. /**
  23535. * \brief Add data to the accumulator manually
  23536. * (Thread-safe if MBEDTLS_THREADING_C is enabled)
  23537. *
  23538. * \param ctx Entropy context
  23539. * \param data Data to add
  23540. * \param len Length of data
  23541. *
  23542. * \return 0 if successful
  23543. */
  23544. int mbedtls_entropy_update_manual( mbedtls_entropy_context *ctx,
  23545. const unsigned char *data, size_t len );
  23546. #if defined(MBEDTLS_ENTROPY_NV_SEED)
  23547. /**
  23548. * \brief Trigger an update of the seed file in NV by using the
  23549. * current entropy pool.
  23550. *
  23551. * \param ctx Entropy context
  23552. *
  23553. * \return 0 if successful
  23554. */
  23555. int mbedtls_entropy_update_nv_seed( mbedtls_entropy_context *ctx );
  23556. #endif /* MBEDTLS_ENTROPY_NV_SEED */
  23557. #if defined(MBEDTLS_FS_IO)
  23558. /**
  23559. * \brief Write a seed file
  23560. *
  23561. * \param ctx Entropy context
  23562. * \param path Name of the file
  23563. *
  23564. * \return 0 if successful,
  23565. * MBEDTLS_ERR_ENTROPY_FILE_IO_ERROR on file error, or
  23566. * MBEDTLS_ERR_ENTROPY_SOURCE_FAILED
  23567. */
  23568. int mbedtls_entropy_write_seed_file( mbedtls_entropy_context *ctx, const char *path );
  23569. /**
  23570. * \brief Read and update a seed file. Seed is added to this
  23571. * instance. No more than MBEDTLS_ENTROPY_MAX_SEED_SIZE bytes are
  23572. * read from the seed file. The rest is ignored.
  23573. *
  23574. * \param ctx Entropy context
  23575. * \param path Name of the file
  23576. *
  23577. * \return 0 if successful,
  23578. * MBEDTLS_ERR_ENTROPY_FILE_IO_ERROR on file error,
  23579. * MBEDTLS_ERR_ENTROPY_SOURCE_FAILED
  23580. */
  23581. int mbedtls_entropy_update_seed_file( mbedtls_entropy_context *ctx, const char *path );
  23582. #endif /* MBEDTLS_FS_IO */
  23583. #if defined(MBEDTLS_SELF_TEST)
  23584. /**
  23585. * \brief Checkup routine
  23586. *
  23587. * This module self-test also calls the entropy self-test,
  23588. * mbedtls_entropy_source_self_test();
  23589. *
  23590. * \return 0 if successful, or 1 if a test failed
  23591. */
  23592. int mbedtls_entropy_self_test( int verbose );
  23593. #if defined(MBEDTLS_ENTROPY_HARDWARE_ALT)
  23594. /**
  23595. * \brief Checkup routine
  23596. *
  23597. * Verifies the integrity of the hardware entropy source
  23598. * provided by the function 'mbedtls_hardware_poll()'.
  23599. *
  23600. * Note this is the only hardware entropy source that is known
  23601. * at link time, and other entropy sources configured
  23602. * dynamically at runtime by the function
  23603. * mbedtls_entropy_add_source() will not be tested.
  23604. *
  23605. * \return 0 if successful, or 1 if a test failed
  23606. */
  23607. int mbedtls_entropy_source_self_test( int verbose );
  23608. #endif /* MBEDTLS_ENTROPY_HARDWARE_ALT */
  23609. #endif /* MBEDTLS_SELF_TEST */
  23610. #ifdef __cplusplus
  23611. }
  23612. #endif
  23613. #endif /* entropy.h */
  23614. /********* Start of file include/mbedtls/entropy_poll.h ************/
  23615. /**
  23616. * \file entropy_poll.h
  23617. *
  23618. * \brief Platform-specific and custom entropy polling functions
  23619. */
  23620. /*
  23621. * Copyright The Mbed TLS Contributors
  23622. * SPDX-License-Identifier: Apache-2.0
  23623. *
  23624. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  23625. * not use this file except in compliance with the License.
  23626. * You may obtain a copy of the License at
  23627. *
  23628. * http://www.apache.org/licenses/LICENSE-2.0
  23629. *
  23630. * Unless required by applicable law or agreed to in writing, software
  23631. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  23632. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  23633. * See the License for the specific language governing permissions and
  23634. * limitations under the License.
  23635. */
  23636. #ifndef MBEDTLS_ENTROPY_POLL_H
  23637. #define MBEDTLS_ENTROPY_POLL_H
  23638. #if !defined(MBEDTLS_CONFIG_FILE)
  23639. #else
  23640. #endif
  23641. #include <stddef.h>
  23642. #ifdef __cplusplus
  23643. extern "C" {
  23644. #endif
  23645. /*
  23646. * Default thresholds for built-in sources, in bytes
  23647. */
  23648. #define MBEDTLS_ENTROPY_MIN_PLATFORM 32 /**< Minimum for platform source */
  23649. #define MBEDTLS_ENTROPY_MIN_HAVEGE 32 /**< Minimum for HAVEGE */
  23650. #define MBEDTLS_ENTROPY_MIN_HARDCLOCK 4 /**< Minimum for mbedtls_timing_hardclock() */
  23651. #if !defined(MBEDTLS_ENTROPY_MIN_HARDWARE)
  23652. #define MBEDTLS_ENTROPY_MIN_HARDWARE 32 /**< Minimum for the hardware source */
  23653. #endif
  23654. /**
  23655. * \brief Entropy poll callback that provides 0 entropy.
  23656. */
  23657. #if defined(MBEDTLS_TEST_NULL_ENTROPY)
  23658. int mbedtls_null_entropy_poll( void *data,
  23659. unsigned char *output, size_t len, size_t *olen );
  23660. #endif
  23661. #if !defined(MBEDTLS_NO_PLATFORM_ENTROPY)
  23662. /**
  23663. * \brief Platform-specific entropy poll callback
  23664. */
  23665. int mbedtls_platform_entropy_poll( void *data,
  23666. unsigned char *output, size_t len, size_t *olen );
  23667. #endif
  23668. #if defined(MBEDTLS_HAVEGE_C)
  23669. /**
  23670. * \brief HAVEGE based entropy poll callback
  23671. *
  23672. * Requires an HAVEGE state as its data pointer.
  23673. */
  23674. int mbedtls_havege_poll( void *data,
  23675. unsigned char *output, size_t len, size_t *olen );
  23676. #endif
  23677. #if defined(MBEDTLS_TIMING_C)
  23678. /**
  23679. * \brief mbedtls_timing_hardclock-based entropy poll callback
  23680. */
  23681. int mbedtls_hardclock_poll( void *data,
  23682. unsigned char *output, size_t len, size_t *olen );
  23683. #endif
  23684. #if defined(MBEDTLS_ENTROPY_HARDWARE_ALT)
  23685. /**
  23686. * \brief Entropy poll callback for a hardware source
  23687. *
  23688. * \warning This is not provided by mbed TLS!
  23689. * See \c MBEDTLS_ENTROPY_HARDWARE_ALT in config.h.
  23690. *
  23691. * \note This must accept NULL as its first argument.
  23692. */
  23693. int mbedtls_hardware_poll( void *data,
  23694. unsigned char *output, size_t len, size_t *olen );
  23695. #endif
  23696. #if defined(MBEDTLS_ENTROPY_NV_SEED)
  23697. /**
  23698. * \brief Entropy poll callback for a non-volatile seed file
  23699. *
  23700. * \note This must accept NULL as its first argument.
  23701. */
  23702. int mbedtls_nv_seed_poll( void *data,
  23703. unsigned char *output, size_t len, size_t *olen );
  23704. #endif
  23705. #ifdef __cplusplus
  23706. }
  23707. #endif
  23708. #endif /* entropy_poll.h */
  23709. /********* Start of file include/mbedtls/havege.h ************/
  23710. /**
  23711. * \file havege.h
  23712. *
  23713. * \brief HAVEGE: HArdware Volatile Entropy Gathering and Expansion
  23714. */
  23715. /*
  23716. * Copyright The Mbed TLS Contributors
  23717. * SPDX-License-Identifier: Apache-2.0
  23718. *
  23719. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  23720. * not use this file except in compliance with the License.
  23721. * You may obtain a copy of the License at
  23722. *
  23723. * http://www.apache.org/licenses/LICENSE-2.0
  23724. *
  23725. * Unless required by applicable law or agreed to in writing, software
  23726. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  23727. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  23728. * See the License for the specific language governing permissions and
  23729. * limitations under the License.
  23730. */
  23731. #ifndef MBEDTLS_HAVEGE_H
  23732. #define MBEDTLS_HAVEGE_H
  23733. #if !defined(MBEDTLS_CONFIG_FILE)
  23734. #else
  23735. #endif
  23736. #include <stddef.h>
  23737. #include <stdint.h>
  23738. #define MBEDTLS_HAVEGE_COLLECT_SIZE 1024
  23739. #ifdef __cplusplus
  23740. extern "C" {
  23741. #endif
  23742. /**
  23743. * \brief HAVEGE state structure
  23744. */
  23745. typedef struct mbedtls_havege_state
  23746. {
  23747. uint32_t PT1, PT2, offset[2];
  23748. uint32_t pool[MBEDTLS_HAVEGE_COLLECT_SIZE];
  23749. uint32_t WALK[8192];
  23750. }
  23751. mbedtls_havege_state;
  23752. /**
  23753. * \brief HAVEGE initialization
  23754. *
  23755. * \param hs HAVEGE state to be initialized
  23756. */
  23757. void mbedtls_havege_init( mbedtls_havege_state *hs );
  23758. /**
  23759. * \brief Clear HAVEGE state
  23760. *
  23761. * \param hs HAVEGE state to be cleared
  23762. */
  23763. void mbedtls_havege_free( mbedtls_havege_state *hs );
  23764. /**
  23765. * \brief HAVEGE rand function
  23766. *
  23767. * \param p_rng A HAVEGE state
  23768. * \param output Buffer to fill
  23769. * \param len Length of buffer
  23770. *
  23771. * \return 0
  23772. */
  23773. int mbedtls_havege_random( void *p_rng, unsigned char *output, size_t len );
  23774. #ifdef __cplusplus
  23775. }
  23776. #endif
  23777. #endif /* havege.h */
  23778. /********* Start of file include/mbedtls/memory_buffer_alloc.h ************/
  23779. /**
  23780. * \file memory_buffer_alloc.h
  23781. *
  23782. * \brief Buffer-based memory allocator
  23783. */
  23784. /*
  23785. * Copyright The Mbed TLS Contributors
  23786. * SPDX-License-Identifier: Apache-2.0
  23787. *
  23788. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  23789. * not use this file except in compliance with the License.
  23790. * You may obtain a copy of the License at
  23791. *
  23792. * http://www.apache.org/licenses/LICENSE-2.0
  23793. *
  23794. * Unless required by applicable law or agreed to in writing, software
  23795. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  23796. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  23797. * See the License for the specific language governing permissions and
  23798. * limitations under the License.
  23799. */
  23800. #ifndef MBEDTLS_MEMORY_BUFFER_ALLOC_H
  23801. #define MBEDTLS_MEMORY_BUFFER_ALLOC_H
  23802. #if !defined(MBEDTLS_CONFIG_FILE)
  23803. #else
  23804. #endif
  23805. #include <stddef.h>
  23806. /**
  23807. * \name SECTION: Module settings
  23808. *
  23809. * The configuration options you can set for this module are in this section.
  23810. * Either change them in config.h or define them on the compiler command line.
  23811. * \{
  23812. */
  23813. #if !defined(MBEDTLS_MEMORY_ALIGN_MULTIPLE)
  23814. #define MBEDTLS_MEMORY_ALIGN_MULTIPLE 4 /**< Align on multiples of this value */
  23815. #endif
  23816. /* \} name SECTION: Module settings */
  23817. #define MBEDTLS_MEMORY_VERIFY_NONE 0
  23818. #define MBEDTLS_MEMORY_VERIFY_ALLOC (1 << 0)
  23819. #define MBEDTLS_MEMORY_VERIFY_FREE (1 << 1)
  23820. #define MBEDTLS_MEMORY_VERIFY_ALWAYS (MBEDTLS_MEMORY_VERIFY_ALLOC | MBEDTLS_MEMORY_VERIFY_FREE)
  23821. #ifdef __cplusplus
  23822. extern "C" {
  23823. #endif
  23824. /**
  23825. * \brief Initialize use of stack-based memory allocator.
  23826. * The stack-based allocator does memory management inside the
  23827. * presented buffer and does not call calloc() and free().
  23828. * It sets the global mbedtls_calloc() and mbedtls_free() pointers
  23829. * to its own functions.
  23830. * (Provided mbedtls_calloc() and mbedtls_free() are thread-safe if
  23831. * MBEDTLS_THREADING_C is defined)
  23832. *
  23833. * \note This code is not optimized and provides a straight-forward
  23834. * implementation of a stack-based memory allocator.
  23835. *
  23836. * \param buf buffer to use as heap
  23837. * \param len size of the buffer
  23838. */
  23839. void mbedtls_memory_buffer_alloc_init( unsigned char *buf, size_t len );
  23840. /**
  23841. * \brief Free the mutex for thread-safety and clear remaining memory
  23842. */
  23843. void mbedtls_memory_buffer_alloc_free( void );
  23844. /**
  23845. * \brief Determine when the allocator should automatically verify the state
  23846. * of the entire chain of headers / meta-data.
  23847. * (Default: MBEDTLS_MEMORY_VERIFY_NONE)
  23848. *
  23849. * \param verify One of MBEDTLS_MEMORY_VERIFY_NONE, MBEDTLS_MEMORY_VERIFY_ALLOC,
  23850. * MBEDTLS_MEMORY_VERIFY_FREE or MBEDTLS_MEMORY_VERIFY_ALWAYS
  23851. */
  23852. void mbedtls_memory_buffer_set_verify( int verify );
  23853. #if defined(MBEDTLS_MEMORY_DEBUG)
  23854. /**
  23855. * \brief Print out the status of the allocated memory (primarily for use
  23856. * after a program should have de-allocated all memory)
  23857. * Prints out a list of 'still allocated' blocks and their stack
  23858. * trace if MBEDTLS_MEMORY_BACKTRACE is defined.
  23859. */
  23860. void mbedtls_memory_buffer_alloc_status( void );
  23861. /**
  23862. * \brief Get the peak heap usage so far
  23863. *
  23864. * \param max_used Peak number of bytes in use or committed. This
  23865. * includes bytes in allocated blocks too small to split
  23866. * into smaller blocks but larger than the requested size.
  23867. * \param max_blocks Peak number of blocks in use, including free and used
  23868. */
  23869. void mbedtls_memory_buffer_alloc_max_get( size_t *max_used, size_t *max_blocks );
  23870. /**
  23871. * \brief Reset peak statistics
  23872. */
  23873. void mbedtls_memory_buffer_alloc_max_reset( void );
  23874. /**
  23875. * \brief Get the current heap usage
  23876. *
  23877. * \param cur_used Current number of bytes in use or committed. This
  23878. * includes bytes in allocated blocks too small to split
  23879. * into smaller blocks but larger than the requested size.
  23880. * \param cur_blocks Current number of blocks in use, including free and used
  23881. */
  23882. void mbedtls_memory_buffer_alloc_cur_get( size_t *cur_used, size_t *cur_blocks );
  23883. #endif /* MBEDTLS_MEMORY_DEBUG */
  23884. /**
  23885. * \brief Verifies that all headers in the memory buffer are correct
  23886. * and contain sane values. Helps debug buffer-overflow errors.
  23887. *
  23888. * Prints out first failure if MBEDTLS_MEMORY_DEBUG is defined.
  23889. * Prints out full header information if MBEDTLS_MEMORY_DEBUG
  23890. * is defined. (Includes stack trace information for each block if
  23891. * MBEDTLS_MEMORY_BACKTRACE is defined as well).
  23892. *
  23893. * \return 0 if verified, 1 otherwise
  23894. */
  23895. int mbedtls_memory_buffer_alloc_verify( void );
  23896. #if defined(MBEDTLS_SELF_TEST)
  23897. /**
  23898. * \brief Checkup routine
  23899. *
  23900. * \return 0 if successful, or 1 if a test failed
  23901. */
  23902. int mbedtls_memory_buffer_alloc_self_test( int verbose );
  23903. #endif
  23904. #ifdef __cplusplus
  23905. }
  23906. #endif
  23907. #endif /* memory_buffer_alloc.h */
  23908. /********* Start of file include/mbedtls/padlock.h ************/
  23909. /**
  23910. * \file padlock.h
  23911. *
  23912. * \brief VIA PadLock ACE for HW encryption/decryption supported by some
  23913. * processors
  23914. *
  23915. * \warning These functions are only for internal use by other library
  23916. * functions; you must not call them directly.
  23917. */
  23918. /*
  23919. * Copyright The Mbed TLS Contributors
  23920. * SPDX-License-Identifier: Apache-2.0
  23921. *
  23922. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  23923. * not use this file except in compliance with the License.
  23924. * You may obtain a copy of the License at
  23925. *
  23926. * http://www.apache.org/licenses/LICENSE-2.0
  23927. *
  23928. * Unless required by applicable law or agreed to in writing, software
  23929. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  23930. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  23931. * See the License for the specific language governing permissions and
  23932. * limitations under the License.
  23933. */
  23934. #ifndef MBEDTLS_PADLOCK_H
  23935. #define MBEDTLS_PADLOCK_H
  23936. #if !defined(MBEDTLS_CONFIG_FILE)
  23937. #else
  23938. #endif
  23939. /** Input data should be aligned. */
  23940. #define MBEDTLS_ERR_PADLOCK_DATA_MISALIGNED -0x0030
  23941. #if defined(__has_feature)
  23942. #if __has_feature(address_sanitizer)
  23943. #define MBEDTLS_HAVE_ASAN
  23944. #endif
  23945. #endif
  23946. /* Some versions of ASan result in errors about not enough registers */
  23947. #if defined(MBEDTLS_HAVE_ASM) && defined(__GNUC__) && defined(__i386__) && \
  23948. !defined(MBEDTLS_HAVE_ASAN)
  23949. #ifndef MBEDTLS_HAVE_X86
  23950. #define MBEDTLS_HAVE_X86
  23951. #endif
  23952. #include <stdint.h>
  23953. #define MBEDTLS_PADLOCK_RNG 0x000C
  23954. #define MBEDTLS_PADLOCK_ACE 0x00C0
  23955. #define MBEDTLS_PADLOCK_PHE 0x0C00
  23956. #define MBEDTLS_PADLOCK_PMM 0x3000
  23957. #define MBEDTLS_PADLOCK_ALIGN16(x) (uint32_t *) (16 + ((int32_t) (x) & ~15))
  23958. #ifdef __cplusplus
  23959. extern "C" {
  23960. #endif
  23961. /**
  23962. * \brief Internal PadLock detection routine
  23963. *
  23964. * \note This function is only for internal use by other library
  23965. * functions; you must not call it directly.
  23966. *
  23967. * \param feature The feature to detect
  23968. *
  23969. * \return non-zero if CPU has support for the feature, 0 otherwise
  23970. */
  23971. int mbedtls_padlock_has_support( int feature );
  23972. /**
  23973. * \brief Internal PadLock AES-ECB block en(de)cryption
  23974. *
  23975. * \note This function is only for internal use by other library
  23976. * functions; you must not call it directly.
  23977. *
  23978. * \param ctx AES context
  23979. * \param mode MBEDTLS_AES_ENCRYPT or MBEDTLS_AES_DECRYPT
  23980. * \param input 16-byte input block
  23981. * \param output 16-byte output block
  23982. *
  23983. * \return 0 if success, 1 if operation failed
  23984. */
  23985. int mbedtls_padlock_xcryptecb( mbedtls_aes_context *ctx,
  23986. int mode,
  23987. const unsigned char input[16],
  23988. unsigned char output[16] );
  23989. /**
  23990. * \brief Internal PadLock AES-CBC buffer en(de)cryption
  23991. *
  23992. * \note This function is only for internal use by other library
  23993. * functions; you must not call it directly.
  23994. *
  23995. * \param ctx AES context
  23996. * \param mode MBEDTLS_AES_ENCRYPT or MBEDTLS_AES_DECRYPT
  23997. * \param length length of the input data
  23998. * \param iv initialization vector (updated after use)
  23999. * \param input buffer holding the input data
  24000. * \param output buffer holding the output data
  24001. *
  24002. * \return 0 if success, 1 if operation failed
  24003. */
  24004. int mbedtls_padlock_xcryptcbc( mbedtls_aes_context *ctx,
  24005. int mode,
  24006. size_t length,
  24007. unsigned char iv[16],
  24008. const unsigned char *input,
  24009. unsigned char *output );
  24010. #ifdef __cplusplus
  24011. }
  24012. #endif
  24013. #endif /* HAVE_X86 */
  24014. #endif /* padlock.h */
  24015. /********* Start of file include/mbedtls/timing.h ************/
  24016. /**
  24017. * \file timing.h
  24018. *
  24019. * \brief Portable interface to timeouts and to the CPU cycle counter
  24020. */
  24021. /*
  24022. * Copyright The Mbed TLS Contributors
  24023. * SPDX-License-Identifier: Apache-2.0
  24024. *
  24025. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  24026. * not use this file except in compliance with the License.
  24027. * You may obtain a copy of the License at
  24028. *
  24029. * http://www.apache.org/licenses/LICENSE-2.0
  24030. *
  24031. * Unless required by applicable law or agreed to in writing, software
  24032. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  24033. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  24034. * See the License for the specific language governing permissions and
  24035. * limitations under the License.
  24036. */
  24037. #ifndef MBEDTLS_TIMING_H
  24038. #define MBEDTLS_TIMING_H
  24039. #if !defined(MBEDTLS_CONFIG_FILE)
  24040. #else
  24041. #endif
  24042. #include <stdint.h>
  24043. #ifdef __cplusplus
  24044. extern "C" {
  24045. #endif
  24046. #if !defined(MBEDTLS_TIMING_ALT)
  24047. // Regular implementation
  24048. //
  24049. /**
  24050. * \brief timer structure
  24051. */
  24052. struct mbedtls_timing_hr_time
  24053. {
  24054. unsigned char opaque[32];
  24055. };
  24056. /**
  24057. * \brief Context for mbedtls_timing_set/get_delay()
  24058. */
  24059. typedef struct mbedtls_timing_delay_context
  24060. {
  24061. struct mbedtls_timing_hr_time timer;
  24062. uint32_t int_ms;
  24063. uint32_t fin_ms;
  24064. } mbedtls_timing_delay_context;
  24065. #else /* MBEDTLS_TIMING_ALT */
  24066. #endif /* MBEDTLS_TIMING_ALT */
  24067. extern volatile int mbedtls_timing_alarmed;
  24068. /**
  24069. * \brief Return the CPU cycle counter value
  24070. *
  24071. * \warning This is only a best effort! Do not rely on this!
  24072. * In particular, it is known to be unreliable on virtual
  24073. * machines.
  24074. *
  24075. * \note This value starts at an unspecified origin and
  24076. * may wrap around.
  24077. */
  24078. unsigned long mbedtls_timing_hardclock( void );
  24079. /**
  24080. * \brief Return the elapsed time in milliseconds
  24081. *
  24082. * \param val points to a timer structure
  24083. * \param reset If 0, query the elapsed time. Otherwise (re)start the timer.
  24084. *
  24085. * \return Elapsed time since the previous reset in ms. When
  24086. * restarting, this is always 0.
  24087. *
  24088. * \note To initialize a timer, call this function with reset=1.
  24089. *
  24090. * Determining the elapsed time and resetting the timer is not
  24091. * atomic on all platforms, so after the sequence
  24092. * `{ get_timer(1); ...; time1 = get_timer(1); ...; time2 =
  24093. * get_timer(0) }` the value time1+time2 is only approximately
  24094. * the delay since the first reset.
  24095. */
  24096. unsigned long mbedtls_timing_get_timer( struct mbedtls_timing_hr_time *val, int reset );
  24097. /**
  24098. * \brief Setup an alarm clock
  24099. *
  24100. * \param seconds delay before the "mbedtls_timing_alarmed" flag is set
  24101. * (must be >=0)
  24102. *
  24103. * \warning Only one alarm at a time is supported. In a threaded
  24104. * context, this means one for the whole process, not one per
  24105. * thread.
  24106. */
  24107. void mbedtls_set_alarm( int seconds );
  24108. /**
  24109. * \brief Set a pair of delays to watch
  24110. * (See \c mbedtls_timing_get_delay().)
  24111. *
  24112. * \param data Pointer to timing data.
  24113. * Must point to a valid \c mbedtls_timing_delay_context struct.
  24114. * \param int_ms First (intermediate) delay in milliseconds.
  24115. * The effect if int_ms > fin_ms is unspecified.
  24116. * \param fin_ms Second (final) delay in milliseconds.
  24117. * Pass 0 to cancel the current delay.
  24118. *
  24119. * \note To set a single delay, either use \c mbedtls_timing_set_timer
  24120. * directly or use this function with int_ms == fin_ms.
  24121. */
  24122. void mbedtls_timing_set_delay( void *data, uint32_t int_ms, uint32_t fin_ms );
  24123. /**
  24124. * \brief Get the status of delays
  24125. * (Memory helper: number of delays passed.)
  24126. *
  24127. * \param data Pointer to timing data
  24128. * Must point to a valid \c mbedtls_timing_delay_context struct.
  24129. *
  24130. * \return -1 if cancelled (fin_ms = 0),
  24131. * 0 if none of the delays are passed,
  24132. * 1 if only the intermediate delay is passed,
  24133. * 2 if the final delay is passed.
  24134. */
  24135. int mbedtls_timing_get_delay( void *data );
  24136. #if defined(MBEDTLS_SELF_TEST)
  24137. /**
  24138. * \brief Checkup routine
  24139. *
  24140. * \return 0 if successful, or 1 if a test failed
  24141. */
  24142. int mbedtls_timing_self_test( int verbose );
  24143. #endif
  24144. #ifdef __cplusplus
  24145. }
  24146. #endif
  24147. #endif /* timing.h */
  24148. /********* Start of file include/mbedtls/xtea.h ************/
  24149. /**
  24150. * \file xtea.h
  24151. *
  24152. * \brief XTEA block cipher (32-bit)
  24153. */
  24154. /*
  24155. * Copyright The Mbed TLS Contributors
  24156. * SPDX-License-Identifier: Apache-2.0
  24157. *
  24158. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  24159. * not use this file except in compliance with the License.
  24160. * You may obtain a copy of the License at
  24161. *
  24162. * http://www.apache.org/licenses/LICENSE-2.0
  24163. *
  24164. * Unless required by applicable law or agreed to in writing, software
  24165. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  24166. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  24167. * See the License for the specific language governing permissions and
  24168. * limitations under the License.
  24169. */
  24170. #ifndef MBEDTLS_XTEA_H
  24171. #define MBEDTLS_XTEA_H
  24172. #if !defined(MBEDTLS_CONFIG_FILE)
  24173. #else
  24174. #endif
  24175. #include <stddef.h>
  24176. #include <stdint.h>
  24177. #define MBEDTLS_XTEA_ENCRYPT 1
  24178. #define MBEDTLS_XTEA_DECRYPT 0
  24179. /** The data input has an invalid length. */
  24180. #define MBEDTLS_ERR_XTEA_INVALID_INPUT_LENGTH -0x0028
  24181. /* MBEDTLS_ERR_XTEA_HW_ACCEL_FAILED is deprecated and should not be used. */
  24182. /** XTEA hardware accelerator failed. */
  24183. #define MBEDTLS_ERR_XTEA_HW_ACCEL_FAILED -0x0029
  24184. #ifdef __cplusplus
  24185. extern "C" {
  24186. #endif
  24187. #if !defined(MBEDTLS_XTEA_ALT)
  24188. // Regular implementation
  24189. //
  24190. /**
  24191. * \brief XTEA context structure
  24192. */
  24193. typedef struct mbedtls_xtea_context
  24194. {
  24195. uint32_t k[4]; /*!< key */
  24196. }
  24197. mbedtls_xtea_context;
  24198. #else /* MBEDTLS_XTEA_ALT */
  24199. #endif /* MBEDTLS_XTEA_ALT */
  24200. /**
  24201. * \brief Initialize XTEA context
  24202. *
  24203. * \param ctx XTEA context to be initialized
  24204. */
  24205. void mbedtls_xtea_init( mbedtls_xtea_context *ctx );
  24206. /**
  24207. * \brief Clear XTEA context
  24208. *
  24209. * \param ctx XTEA context to be cleared
  24210. */
  24211. void mbedtls_xtea_free( mbedtls_xtea_context *ctx );
  24212. /**
  24213. * \brief XTEA key schedule
  24214. *
  24215. * \param ctx XTEA context to be initialized
  24216. * \param key the secret key
  24217. */
  24218. void mbedtls_xtea_setup( mbedtls_xtea_context *ctx, const unsigned char key[16] );
  24219. /**
  24220. * \brief XTEA cipher function
  24221. *
  24222. * \param ctx XTEA context
  24223. * \param mode MBEDTLS_XTEA_ENCRYPT or MBEDTLS_XTEA_DECRYPT
  24224. * \param input 8-byte input block
  24225. * \param output 8-byte output block
  24226. *
  24227. * \return 0 if successful
  24228. */
  24229. int mbedtls_xtea_crypt_ecb( mbedtls_xtea_context *ctx,
  24230. int mode,
  24231. const unsigned char input[8],
  24232. unsigned char output[8] );
  24233. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  24234. /**
  24235. * \brief XTEA CBC cipher function
  24236. *
  24237. * \param ctx XTEA context
  24238. * \param mode MBEDTLS_XTEA_ENCRYPT or MBEDTLS_XTEA_DECRYPT
  24239. * \param length the length of input, multiple of 8
  24240. * \param iv initialization vector for CBC mode
  24241. * \param input input block
  24242. * \param output output block
  24243. *
  24244. * \return 0 if successful,
  24245. * MBEDTLS_ERR_XTEA_INVALID_INPUT_LENGTH if the length % 8 != 0
  24246. */
  24247. int mbedtls_xtea_crypt_cbc( mbedtls_xtea_context *ctx,
  24248. int mode,
  24249. size_t length,
  24250. unsigned char iv[8],
  24251. const unsigned char *input,
  24252. unsigned char *output);
  24253. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  24254. #if defined(MBEDTLS_SELF_TEST)
  24255. /**
  24256. * \brief Checkup routine
  24257. *
  24258. * \return 0 if successful, or 1 if the test failed
  24259. */
  24260. int mbedtls_xtea_self_test( int verbose );
  24261. #endif /* MBEDTLS_SELF_TEST */
  24262. #ifdef __cplusplus
  24263. }
  24264. #endif
  24265. #endif /* xtea.h */
  24266. /********* Start of file include/mbedtls/ssl.h ************/
  24267. /**
  24268. * \file ssl.h
  24269. *
  24270. * \brief SSL/TLS functions.
  24271. */
  24272. /*
  24273. * Copyright The Mbed TLS Contributors
  24274. * SPDX-License-Identifier: Apache-2.0
  24275. *
  24276. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  24277. * not use this file except in compliance with the License.
  24278. * You may obtain a copy of the License at
  24279. *
  24280. * http://www.apache.org/licenses/LICENSE-2.0
  24281. *
  24282. * Unless required by applicable law or agreed to in writing, software
  24283. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  24284. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  24285. * See the License for the specific language governing permissions and
  24286. * limitations under the License.
  24287. */
  24288. #ifndef MBEDTLS_SSL_H
  24289. #define MBEDTLS_SSL_H
  24290. #if !defined(MBEDTLS_CONFIG_FILE)
  24291. #else
  24292. #endif
  24293. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  24294. #endif
  24295. #if defined(MBEDTLS_DHM_C)
  24296. #endif
  24297. /* Adding guard for MBEDTLS_ECDSA_C to ensure no compile errors due
  24298. * to guards also being in ssl_srv.c and ssl_cli.c. There is a gap
  24299. * in functionality that access to ecdh_ctx structure is needed for
  24300. * MBEDTLS_ECDSA_C which does not seem correct.
  24301. */
  24302. #if defined(MBEDTLS_ECDH_C) || defined(MBEDTLS_ECDSA_C)
  24303. #endif
  24304. #if defined(MBEDTLS_ZLIB_SUPPORT)
  24305. #if defined(MBEDTLS_DEPRECATED_WARNING)
  24306. #warning "Record compression support via MBEDTLS_ZLIB_SUPPORT is deprecated and will be removed in the next major revision of the library"
  24307. #endif
  24308. #if defined(MBEDTLS_DEPRECATED_REMOVED)
  24309. #error "Record compression support via MBEDTLS_ZLIB_SUPPORT is deprecated and cannot be used if MBEDTLS_DEPRECATED_REMOVED is set"
  24310. #endif
  24311. #endif
  24312. #if defined(MBEDTLS_HAVE_TIME)
  24313. #endif
  24314. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  24315. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  24316. /*
  24317. * SSL Error codes
  24318. */
  24319. /** The requested feature is not available. */
  24320. #define MBEDTLS_ERR_SSL_FEATURE_UNAVAILABLE -0x7080
  24321. /** Bad input parameters to function. */
  24322. #define MBEDTLS_ERR_SSL_BAD_INPUT_DATA -0x7100
  24323. /** Verification of the message MAC failed. */
  24324. #define MBEDTLS_ERR_SSL_INVALID_MAC -0x7180
  24325. /** An invalid SSL record was received. */
  24326. #define MBEDTLS_ERR_SSL_INVALID_RECORD -0x7200
  24327. /** The connection indicated an EOF. */
  24328. #define MBEDTLS_ERR_SSL_CONN_EOF -0x7280
  24329. /** An unknown cipher was received. */
  24330. #define MBEDTLS_ERR_SSL_UNKNOWN_CIPHER -0x7300
  24331. /** The server has no ciphersuites in common with the client. */
  24332. #define MBEDTLS_ERR_SSL_NO_CIPHER_CHOSEN -0x7380
  24333. /** No RNG was provided to the SSL module. */
  24334. #define MBEDTLS_ERR_SSL_NO_RNG -0x7400
  24335. /** No client certification received from the client, but required by the authentication mode. */
  24336. #define MBEDTLS_ERR_SSL_NO_CLIENT_CERTIFICATE -0x7480
  24337. /** Our own certificate(s) is/are too large to send in an SSL message. */
  24338. #define MBEDTLS_ERR_SSL_CERTIFICATE_TOO_LARGE -0x7500
  24339. /** The own certificate is not set, but needed by the server. */
  24340. #define MBEDTLS_ERR_SSL_CERTIFICATE_REQUIRED -0x7580
  24341. /** The own private key or pre-shared key is not set, but needed. */
  24342. #define MBEDTLS_ERR_SSL_PRIVATE_KEY_REQUIRED -0x7600
  24343. /** No CA Chain is set, but required to operate. */
  24344. #define MBEDTLS_ERR_SSL_CA_CHAIN_REQUIRED -0x7680
  24345. /** An unexpected message was received from our peer. */
  24346. #define MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE -0x7700
  24347. /** A fatal alert message was received from our peer. */
  24348. #define MBEDTLS_ERR_SSL_FATAL_ALERT_MESSAGE -0x7780
  24349. /** Verification of our peer failed. */
  24350. #define MBEDTLS_ERR_SSL_PEER_VERIFY_FAILED -0x7800
  24351. /** The peer notified us that the connection is going to be closed. */
  24352. #define MBEDTLS_ERR_SSL_PEER_CLOSE_NOTIFY -0x7880
  24353. /** Processing of the ClientHello handshake message failed. */
  24354. #define MBEDTLS_ERR_SSL_BAD_HS_CLIENT_HELLO -0x7900
  24355. /** Processing of the ServerHello handshake message failed. */
  24356. #define MBEDTLS_ERR_SSL_BAD_HS_SERVER_HELLO -0x7980
  24357. /** Processing of the Certificate handshake message failed. */
  24358. #define MBEDTLS_ERR_SSL_BAD_HS_CERTIFICATE -0x7A00
  24359. /** Processing of the CertificateRequest handshake message failed. */
  24360. #define MBEDTLS_ERR_SSL_BAD_HS_CERTIFICATE_REQUEST -0x7A80
  24361. /** Processing of the ServerKeyExchange handshake message failed. */
  24362. #define MBEDTLS_ERR_SSL_BAD_HS_SERVER_KEY_EXCHANGE -0x7B00
  24363. /** Processing of the ServerHelloDone handshake message failed. */
  24364. #define MBEDTLS_ERR_SSL_BAD_HS_SERVER_HELLO_DONE -0x7B80
  24365. /** Processing of the ClientKeyExchange handshake message failed. */
  24366. #define MBEDTLS_ERR_SSL_BAD_HS_CLIENT_KEY_EXCHANGE -0x7C00
  24367. /** Processing of the ClientKeyExchange handshake message failed in DHM / ECDH Read Public. */
  24368. #define MBEDTLS_ERR_SSL_BAD_HS_CLIENT_KEY_EXCHANGE_RP -0x7C80
  24369. /** Processing of the ClientKeyExchange handshake message failed in DHM / ECDH Calculate Secret. */
  24370. #define MBEDTLS_ERR_SSL_BAD_HS_CLIENT_KEY_EXCHANGE_CS -0x7D00
  24371. /** Processing of the CertificateVerify handshake message failed. */
  24372. #define MBEDTLS_ERR_SSL_BAD_HS_CERTIFICATE_VERIFY -0x7D80
  24373. /** Processing of the ChangeCipherSpec handshake message failed. */
  24374. #define MBEDTLS_ERR_SSL_BAD_HS_CHANGE_CIPHER_SPEC -0x7E00
  24375. /** Processing of the Finished handshake message failed. */
  24376. #define MBEDTLS_ERR_SSL_BAD_HS_FINISHED -0x7E80
  24377. /** Memory allocation failed */
  24378. #define MBEDTLS_ERR_SSL_ALLOC_FAILED -0x7F00
  24379. /** Hardware acceleration function returned with error */
  24380. #define MBEDTLS_ERR_SSL_HW_ACCEL_FAILED -0x7F80
  24381. /** Hardware acceleration function skipped / left alone data */
  24382. #define MBEDTLS_ERR_SSL_HW_ACCEL_FALLTHROUGH -0x6F80
  24383. /** Processing of the compression / decompression failed */
  24384. #define MBEDTLS_ERR_SSL_COMPRESSION_FAILED -0x6F00
  24385. /** Handshake protocol not within min/max boundaries */
  24386. #define MBEDTLS_ERR_SSL_BAD_HS_PROTOCOL_VERSION -0x6E80
  24387. /** Processing of the NewSessionTicket handshake message failed. */
  24388. #define MBEDTLS_ERR_SSL_BAD_HS_NEW_SESSION_TICKET -0x6E00
  24389. /** Session ticket has expired. */
  24390. #define MBEDTLS_ERR_SSL_SESSION_TICKET_EXPIRED -0x6D80
  24391. /** Public key type mismatch (eg, asked for RSA key exchange and presented EC key) */
  24392. #define MBEDTLS_ERR_SSL_PK_TYPE_MISMATCH -0x6D00
  24393. /** Unknown identity received (eg, PSK identity) */
  24394. #define MBEDTLS_ERR_SSL_UNKNOWN_IDENTITY -0x6C80
  24395. /** Internal error (eg, unexpected failure in lower-level module) */
  24396. #define MBEDTLS_ERR_SSL_INTERNAL_ERROR -0x6C00
  24397. /** A counter would wrap (eg, too many messages exchanged). */
  24398. #define MBEDTLS_ERR_SSL_COUNTER_WRAPPING -0x6B80
  24399. /** Unexpected message at ServerHello in renegotiation. */
  24400. #define MBEDTLS_ERR_SSL_WAITING_SERVER_HELLO_RENEGO -0x6B00
  24401. /** DTLS client must retry for hello verification */
  24402. #define MBEDTLS_ERR_SSL_HELLO_VERIFY_REQUIRED -0x6A80
  24403. /** A buffer is too small to receive or write a message */
  24404. #define MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL -0x6A00
  24405. /** None of the common ciphersuites is usable (eg, no suitable certificate, see debug messages). */
  24406. #define MBEDTLS_ERR_SSL_NO_USABLE_CIPHERSUITE -0x6980
  24407. /** No data of requested type currently available on underlying transport. */
  24408. #define MBEDTLS_ERR_SSL_WANT_READ -0x6900
  24409. /** Connection requires a write call. */
  24410. #define MBEDTLS_ERR_SSL_WANT_WRITE -0x6880
  24411. /** The operation timed out. */
  24412. #define MBEDTLS_ERR_SSL_TIMEOUT -0x6800
  24413. /** The client initiated a reconnect from the same port. */
  24414. #define MBEDTLS_ERR_SSL_CLIENT_RECONNECT -0x6780
  24415. /** Record header looks valid but is not expected. */
  24416. #define MBEDTLS_ERR_SSL_UNEXPECTED_RECORD -0x6700
  24417. /** The alert message received indicates a non-fatal error. */
  24418. #define MBEDTLS_ERR_SSL_NON_FATAL -0x6680
  24419. /** Couldn't set the hash for verifying CertificateVerify */
  24420. #define MBEDTLS_ERR_SSL_INVALID_VERIFY_HASH -0x6600
  24421. /** Internal-only message signaling that further message-processing should be done */
  24422. #define MBEDTLS_ERR_SSL_CONTINUE_PROCESSING -0x6580
  24423. /** The asynchronous operation is not completed yet. */
  24424. #define MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS -0x6500
  24425. /** Internal-only message signaling that a message arrived early. */
  24426. #define MBEDTLS_ERR_SSL_EARLY_MESSAGE -0x6480
  24427. /** An encrypted DTLS-frame with an unexpected CID was received. */
  24428. #define MBEDTLS_ERR_SSL_UNEXPECTED_CID -0x6000
  24429. /** An operation failed due to an unexpected version or configuration. */
  24430. #define MBEDTLS_ERR_SSL_VERSION_MISMATCH -0x5F00
  24431. /** A cryptographic operation is in progress. Try again later. */
  24432. #define MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS -0x7000
  24433. /** Invalid value in SSL config */
  24434. #define MBEDTLS_ERR_SSL_BAD_CONFIG -0x5E80
  24435. /*
  24436. * Various constants
  24437. */
  24438. #define MBEDTLS_SSL_MAJOR_VERSION_3 3
  24439. #define MBEDTLS_SSL_MINOR_VERSION_0 0 /*!< SSL v3.0 */
  24440. #define MBEDTLS_SSL_MINOR_VERSION_1 1 /*!< TLS v1.0 */
  24441. #define MBEDTLS_SSL_MINOR_VERSION_2 2 /*!< TLS v1.1 */
  24442. #define MBEDTLS_SSL_MINOR_VERSION_3 3 /*!< TLS v1.2 */
  24443. #define MBEDTLS_SSL_MINOR_VERSION_4 4 /*!< TLS v1.3 (experimental) */
  24444. #define MBEDTLS_SSL_TRANSPORT_STREAM 0 /*!< TLS */
  24445. #define MBEDTLS_SSL_TRANSPORT_DATAGRAM 1 /*!< DTLS */
  24446. #define MBEDTLS_SSL_MAX_HOST_NAME_LEN 255 /*!< Maximum host name defined in RFC 1035 */
  24447. #define MBEDTLS_SSL_MAX_ALPN_NAME_LEN 255 /*!< Maximum size in bytes of a protocol name in alpn ext., RFC 7301 */
  24448. #define MBEDTLS_SSL_MAX_ALPN_LIST_LEN 65535 /*!< Maximum size in bytes of list in alpn ext., RFC 7301 */
  24449. /* RFC 6066 section 4, see also mfl_code_to_length in ssl_tls.c
  24450. * NONE must be zero so that memset()ing structure to zero works */
  24451. #define MBEDTLS_SSL_MAX_FRAG_LEN_NONE 0 /*!< don't use this extension */
  24452. #define MBEDTLS_SSL_MAX_FRAG_LEN_512 1 /*!< MaxFragmentLength 2^9 */
  24453. #define MBEDTLS_SSL_MAX_FRAG_LEN_1024 2 /*!< MaxFragmentLength 2^10 */
  24454. #define MBEDTLS_SSL_MAX_FRAG_LEN_2048 3 /*!< MaxFragmentLength 2^11 */
  24455. #define MBEDTLS_SSL_MAX_FRAG_LEN_4096 4 /*!< MaxFragmentLength 2^12 */
  24456. #define MBEDTLS_SSL_MAX_FRAG_LEN_INVALID 5 /*!< first invalid value */
  24457. #define MBEDTLS_SSL_IS_CLIENT 0
  24458. #define MBEDTLS_SSL_IS_SERVER 1
  24459. #define MBEDTLS_SSL_IS_NOT_FALLBACK 0
  24460. #define MBEDTLS_SSL_IS_FALLBACK 1
  24461. #define MBEDTLS_SSL_EXTENDED_MS_DISABLED 0
  24462. #define MBEDTLS_SSL_EXTENDED_MS_ENABLED 1
  24463. #define MBEDTLS_SSL_CID_DISABLED 0
  24464. #define MBEDTLS_SSL_CID_ENABLED 1
  24465. #define MBEDTLS_SSL_ETM_DISABLED 0
  24466. #define MBEDTLS_SSL_ETM_ENABLED 1
  24467. #define MBEDTLS_SSL_COMPRESS_NULL 0
  24468. #define MBEDTLS_SSL_COMPRESS_DEFLATE 1
  24469. #define MBEDTLS_SSL_VERIFY_NONE 0
  24470. #define MBEDTLS_SSL_VERIFY_OPTIONAL 1
  24471. #define MBEDTLS_SSL_VERIFY_REQUIRED 2
  24472. #define MBEDTLS_SSL_VERIFY_UNSET 3 /* Used only for sni_authmode */
  24473. #define MBEDTLS_SSL_LEGACY_RENEGOTIATION 0
  24474. #define MBEDTLS_SSL_SECURE_RENEGOTIATION 1
  24475. #define MBEDTLS_SSL_RENEGOTIATION_DISABLED 0
  24476. #define MBEDTLS_SSL_RENEGOTIATION_ENABLED 1
  24477. #define MBEDTLS_SSL_ANTI_REPLAY_DISABLED 0
  24478. #define MBEDTLS_SSL_ANTI_REPLAY_ENABLED 1
  24479. #define MBEDTLS_SSL_RENEGOTIATION_NOT_ENFORCED -1
  24480. #define MBEDTLS_SSL_RENEGO_MAX_RECORDS_DEFAULT 16
  24481. #define MBEDTLS_SSL_LEGACY_NO_RENEGOTIATION 0
  24482. #define MBEDTLS_SSL_LEGACY_ALLOW_RENEGOTIATION 1
  24483. #define MBEDTLS_SSL_LEGACY_BREAK_HANDSHAKE 2
  24484. #define MBEDTLS_SSL_TRUNC_HMAC_DISABLED 0
  24485. #define MBEDTLS_SSL_TRUNC_HMAC_ENABLED 1
  24486. #define MBEDTLS_SSL_TRUNCATED_HMAC_LEN 10 /* 80 bits, rfc 6066 section 7 */
  24487. #define MBEDTLS_SSL_SESSION_TICKETS_DISABLED 0
  24488. #define MBEDTLS_SSL_SESSION_TICKETS_ENABLED 1
  24489. #define MBEDTLS_SSL_CBC_RECORD_SPLITTING_DISABLED 0
  24490. #define MBEDTLS_SSL_CBC_RECORD_SPLITTING_ENABLED 1
  24491. #define MBEDTLS_SSL_ARC4_ENABLED 0
  24492. #define MBEDTLS_SSL_ARC4_DISABLED 1
  24493. #define MBEDTLS_SSL_PRESET_DEFAULT 0
  24494. #define MBEDTLS_SSL_PRESET_SUITEB 2
  24495. #define MBEDTLS_SSL_CERT_REQ_CA_LIST_ENABLED 1
  24496. #define MBEDTLS_SSL_CERT_REQ_CA_LIST_DISABLED 0
  24497. #define MBEDTLS_SSL_DTLS_SRTP_MKI_UNSUPPORTED 0
  24498. #define MBEDTLS_SSL_DTLS_SRTP_MKI_SUPPORTED 1
  24499. /*
  24500. * Default range for DTLS retransmission timer value, in milliseconds.
  24501. * RFC 6347 4.2.4.1 says from 1 second to 60 seconds.
  24502. */
  24503. #define MBEDTLS_SSL_DTLS_TIMEOUT_DFL_MIN 1000
  24504. #define MBEDTLS_SSL_DTLS_TIMEOUT_DFL_MAX 60000
  24505. /**
  24506. * \name SECTION: Module settings
  24507. *
  24508. * The configuration options you can set for this module are in this section.
  24509. * Either change them in config.h or define them on the compiler command line.
  24510. * \{
  24511. */
  24512. #if !defined(MBEDTLS_SSL_DEFAULT_TICKET_LIFETIME)
  24513. #define MBEDTLS_SSL_DEFAULT_TICKET_LIFETIME 86400 /**< Lifetime of session tickets (if enabled) */
  24514. #endif
  24515. /*
  24516. * Maximum fragment length in bytes,
  24517. * determines the size of each of the two internal I/O buffers.
  24518. *
  24519. * Note: the RFC defines the default size of SSL / TLS messages. If you
  24520. * change the value here, other clients / servers may not be able to
  24521. * communicate with you anymore. Only change this value if you control
  24522. * both sides of the connection and have it reduced at both sides, or
  24523. * if you're using the Max Fragment Length extension and you know all your
  24524. * peers are using it too!
  24525. */
  24526. #if !defined(MBEDTLS_SSL_MAX_CONTENT_LEN)
  24527. #define MBEDTLS_SSL_MAX_CONTENT_LEN 16384 /**< Size of the input / output buffer */
  24528. #endif
  24529. #if !defined(MBEDTLS_SSL_IN_CONTENT_LEN)
  24530. #define MBEDTLS_SSL_IN_CONTENT_LEN MBEDTLS_SSL_MAX_CONTENT_LEN
  24531. #endif
  24532. #if !defined(MBEDTLS_SSL_OUT_CONTENT_LEN)
  24533. #define MBEDTLS_SSL_OUT_CONTENT_LEN MBEDTLS_SSL_MAX_CONTENT_LEN
  24534. #endif
  24535. /*
  24536. * Maximum number of heap-allocated bytes for the purpose of
  24537. * DTLS handshake message reassembly and future message buffering.
  24538. */
  24539. #if !defined(MBEDTLS_SSL_DTLS_MAX_BUFFERING)
  24540. #define MBEDTLS_SSL_DTLS_MAX_BUFFERING 32768
  24541. #endif
  24542. /*
  24543. * Maximum length of CIDs for incoming and outgoing messages.
  24544. */
  24545. #if !defined(MBEDTLS_SSL_CID_IN_LEN_MAX)
  24546. #define MBEDTLS_SSL_CID_IN_LEN_MAX 32
  24547. #endif
  24548. #if !defined(MBEDTLS_SSL_CID_OUT_LEN_MAX)
  24549. #define MBEDTLS_SSL_CID_OUT_LEN_MAX 32
  24550. #endif
  24551. #if !defined(MBEDTLS_SSL_CID_PADDING_GRANULARITY)
  24552. #define MBEDTLS_SSL_CID_PADDING_GRANULARITY 16
  24553. #endif
  24554. #if !defined(MBEDTLS_SSL_TLS1_3_PADDING_GRANULARITY)
  24555. #define MBEDTLS_SSL_TLS1_3_PADDING_GRANULARITY 1
  24556. #endif
  24557. /* \} name SECTION: Module settings */
  24558. /*
  24559. * Length of the verify data for secure renegotiation
  24560. */
  24561. #if defined(MBEDTLS_SSL_PROTO_SSL3)
  24562. #define MBEDTLS_SSL_VERIFY_DATA_MAX_LEN 36
  24563. #else
  24564. #define MBEDTLS_SSL_VERIFY_DATA_MAX_LEN 12
  24565. #endif
  24566. /*
  24567. * Signaling ciphersuite values (SCSV)
  24568. */
  24569. #define MBEDTLS_SSL_EMPTY_RENEGOTIATION_INFO 0xFF /**< renegotiation info ext */
  24570. #define MBEDTLS_SSL_FALLBACK_SCSV_VALUE 0x5600 /**< RFC 7507 section 2 */
  24571. /*
  24572. * Supported Signature and Hash algorithms (For TLS 1.2)
  24573. * RFC 5246 section 7.4.1.4.1
  24574. */
  24575. #define MBEDTLS_SSL_HASH_NONE 0
  24576. #define MBEDTLS_SSL_HASH_MD5 1
  24577. #define MBEDTLS_SSL_HASH_SHA1 2
  24578. #define MBEDTLS_SSL_HASH_SHA224 3
  24579. #define MBEDTLS_SSL_HASH_SHA256 4
  24580. #define MBEDTLS_SSL_HASH_SHA384 5
  24581. #define MBEDTLS_SSL_HASH_SHA512 6
  24582. #define MBEDTLS_SSL_SIG_ANON 0
  24583. #define MBEDTLS_SSL_SIG_RSA 1
  24584. #define MBEDTLS_SSL_SIG_ECDSA 3
  24585. /*
  24586. * Client Certificate Types
  24587. * RFC 5246 section 7.4.4 plus RFC 4492 section 5.5
  24588. */
  24589. #define MBEDTLS_SSL_CERT_TYPE_RSA_SIGN 1
  24590. #define MBEDTLS_SSL_CERT_TYPE_ECDSA_SIGN 64
  24591. /*
  24592. * Message, alert and handshake types
  24593. */
  24594. #define MBEDTLS_SSL_MSG_CHANGE_CIPHER_SPEC 20
  24595. #define MBEDTLS_SSL_MSG_ALERT 21
  24596. #define MBEDTLS_SSL_MSG_HANDSHAKE 22
  24597. #define MBEDTLS_SSL_MSG_APPLICATION_DATA 23
  24598. #define MBEDTLS_SSL_MSG_CID 25
  24599. #define MBEDTLS_SSL_ALERT_LEVEL_WARNING 1
  24600. #define MBEDTLS_SSL_ALERT_LEVEL_FATAL 2
  24601. #define MBEDTLS_SSL_ALERT_MSG_CLOSE_NOTIFY 0 /* 0x00 */
  24602. #define MBEDTLS_SSL_ALERT_MSG_UNEXPECTED_MESSAGE 10 /* 0x0A */
  24603. #define MBEDTLS_SSL_ALERT_MSG_BAD_RECORD_MAC 20 /* 0x14 */
  24604. #define MBEDTLS_SSL_ALERT_MSG_DECRYPTION_FAILED 21 /* 0x15 */
  24605. #define MBEDTLS_SSL_ALERT_MSG_RECORD_OVERFLOW 22 /* 0x16 */
  24606. #define MBEDTLS_SSL_ALERT_MSG_DECOMPRESSION_FAILURE 30 /* 0x1E */
  24607. #define MBEDTLS_SSL_ALERT_MSG_HANDSHAKE_FAILURE 40 /* 0x28 */
  24608. #define MBEDTLS_SSL_ALERT_MSG_NO_CERT 41 /* 0x29 */
  24609. #define MBEDTLS_SSL_ALERT_MSG_BAD_CERT 42 /* 0x2A */
  24610. #define MBEDTLS_SSL_ALERT_MSG_UNSUPPORTED_CERT 43 /* 0x2B */
  24611. #define MBEDTLS_SSL_ALERT_MSG_CERT_REVOKED 44 /* 0x2C */
  24612. #define MBEDTLS_SSL_ALERT_MSG_CERT_EXPIRED 45 /* 0x2D */
  24613. #define MBEDTLS_SSL_ALERT_MSG_CERT_UNKNOWN 46 /* 0x2E */
  24614. #define MBEDTLS_SSL_ALERT_MSG_ILLEGAL_PARAMETER 47 /* 0x2F */
  24615. #define MBEDTLS_SSL_ALERT_MSG_UNKNOWN_CA 48 /* 0x30 */
  24616. #define MBEDTLS_SSL_ALERT_MSG_ACCESS_DENIED 49 /* 0x31 */
  24617. #define MBEDTLS_SSL_ALERT_MSG_DECODE_ERROR 50 /* 0x32 */
  24618. #define MBEDTLS_SSL_ALERT_MSG_DECRYPT_ERROR 51 /* 0x33 */
  24619. #define MBEDTLS_SSL_ALERT_MSG_EXPORT_RESTRICTION 60 /* 0x3C */
  24620. #define MBEDTLS_SSL_ALERT_MSG_PROTOCOL_VERSION 70 /* 0x46 */
  24621. #define MBEDTLS_SSL_ALERT_MSG_INSUFFICIENT_SECURITY 71 /* 0x47 */
  24622. #define MBEDTLS_SSL_ALERT_MSG_INTERNAL_ERROR 80 /* 0x50 */
  24623. #define MBEDTLS_SSL_ALERT_MSG_INAPROPRIATE_FALLBACK 86 /* 0x56 */
  24624. #define MBEDTLS_SSL_ALERT_MSG_USER_CANCELED 90 /* 0x5A */
  24625. #define MBEDTLS_SSL_ALERT_MSG_NO_RENEGOTIATION 100 /* 0x64 */
  24626. #define MBEDTLS_SSL_ALERT_MSG_UNSUPPORTED_EXT 110 /* 0x6E */
  24627. #define MBEDTLS_SSL_ALERT_MSG_UNRECOGNIZED_NAME 112 /* 0x70 */
  24628. #define MBEDTLS_SSL_ALERT_MSG_UNKNOWN_PSK_IDENTITY 115 /* 0x73 */
  24629. #define MBEDTLS_SSL_ALERT_MSG_NO_APPLICATION_PROTOCOL 120 /* 0x78 */
  24630. #define MBEDTLS_SSL_HS_HELLO_REQUEST 0
  24631. #define MBEDTLS_SSL_HS_CLIENT_HELLO 1
  24632. #define MBEDTLS_SSL_HS_SERVER_HELLO 2
  24633. #define MBEDTLS_SSL_HS_HELLO_VERIFY_REQUEST 3
  24634. #define MBEDTLS_SSL_HS_NEW_SESSION_TICKET 4
  24635. #define MBEDTLS_SSL_HS_CERTIFICATE 11
  24636. #define MBEDTLS_SSL_HS_SERVER_KEY_EXCHANGE 12
  24637. #define MBEDTLS_SSL_HS_CERTIFICATE_REQUEST 13
  24638. #define MBEDTLS_SSL_HS_SERVER_HELLO_DONE 14
  24639. #define MBEDTLS_SSL_HS_CERTIFICATE_VERIFY 15
  24640. #define MBEDTLS_SSL_HS_CLIENT_KEY_EXCHANGE 16
  24641. #define MBEDTLS_SSL_HS_FINISHED 20
  24642. /*
  24643. * TLS extensions
  24644. */
  24645. #define MBEDTLS_TLS_EXT_SERVERNAME 0
  24646. #define MBEDTLS_TLS_EXT_SERVERNAME_HOSTNAME 0
  24647. #define MBEDTLS_TLS_EXT_MAX_FRAGMENT_LENGTH 1
  24648. #define MBEDTLS_TLS_EXT_TRUNCATED_HMAC 4
  24649. #define MBEDTLS_TLS_EXT_SUPPORTED_ELLIPTIC_CURVES 10
  24650. #define MBEDTLS_TLS_EXT_SUPPORTED_POINT_FORMATS 11
  24651. #define MBEDTLS_TLS_EXT_SIG_ALG 13
  24652. #define MBEDTLS_TLS_EXT_USE_SRTP 14
  24653. #define MBEDTLS_TLS_EXT_ALPN 16
  24654. #define MBEDTLS_TLS_EXT_ENCRYPT_THEN_MAC 22 /* 0x16 */
  24655. #define MBEDTLS_TLS_EXT_EXTENDED_MASTER_SECRET 0x0017 /* 23 */
  24656. #define MBEDTLS_TLS_EXT_SESSION_TICKET 35
  24657. /* The value of the CID extension is still TBD as of
  24658. * draft-ietf-tls-dtls-connection-id-05
  24659. * (https://tools.ietf.org/html/draft-ietf-tls-dtls-connection-id-05).
  24660. *
  24661. * A future minor revision of Mbed TLS may change the default value of
  24662. * this option to match evolving standards and usage.
  24663. */
  24664. #if !defined(MBEDTLS_TLS_EXT_CID)
  24665. #define MBEDTLS_TLS_EXT_CID 254 /* TBD */
  24666. #endif
  24667. #define MBEDTLS_TLS_EXT_ECJPAKE_KKPP 256 /* experimental */
  24668. #define MBEDTLS_TLS_EXT_RENEGOTIATION_INFO 0xFF01
  24669. /*
  24670. * Size defines
  24671. */
  24672. #if !defined(MBEDTLS_PSK_MAX_LEN)
  24673. #define MBEDTLS_PSK_MAX_LEN 32 /* 256 bits */
  24674. #endif
  24675. /* Dummy type used only for its size */
  24676. union mbedtls_ssl_premaster_secret
  24677. {
  24678. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED)
  24679. unsigned char _pms_rsa[48]; /* RFC 5246 8.1.1 */
  24680. #endif
  24681. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED)
  24682. unsigned char _pms_dhm[MBEDTLS_MPI_MAX_SIZE]; /* RFC 5246 8.1.2 */
  24683. #endif
  24684. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED) || \
  24685. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED) || \
  24686. defined(MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED) || \
  24687. defined(MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED)
  24688. unsigned char _pms_ecdh[MBEDTLS_ECP_MAX_BYTES]; /* RFC 4492 5.10 */
  24689. #endif
  24690. #if defined(MBEDTLS_KEY_EXCHANGE_PSK_ENABLED)
  24691. unsigned char _pms_psk[4 + 2 * MBEDTLS_PSK_MAX_LEN]; /* RFC 4279 2 */
  24692. #endif
  24693. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED)
  24694. unsigned char _pms_dhe_psk[4 + MBEDTLS_MPI_MAX_SIZE
  24695. + MBEDTLS_PSK_MAX_LEN]; /* RFC 4279 3 */
  24696. #endif
  24697. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED)
  24698. unsigned char _pms_rsa_psk[52 + MBEDTLS_PSK_MAX_LEN]; /* RFC 4279 4 */
  24699. #endif
  24700. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED)
  24701. unsigned char _pms_ecdhe_psk[4 + MBEDTLS_ECP_MAX_BYTES
  24702. + MBEDTLS_PSK_MAX_LEN]; /* RFC 5489 2 */
  24703. #endif
  24704. #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED)
  24705. unsigned char _pms_ecjpake[32]; /* Thread spec: SHA-256 output */
  24706. #endif
  24707. };
  24708. #define MBEDTLS_PREMASTER_SIZE sizeof( union mbedtls_ssl_premaster_secret )
  24709. #ifdef __cplusplus
  24710. extern "C" {
  24711. #endif
  24712. /*
  24713. * SSL state machine
  24714. */
  24715. typedef enum
  24716. {
  24717. MBEDTLS_SSL_HELLO_REQUEST,
  24718. MBEDTLS_SSL_CLIENT_HELLO,
  24719. MBEDTLS_SSL_SERVER_HELLO,
  24720. MBEDTLS_SSL_SERVER_CERTIFICATE,
  24721. MBEDTLS_SSL_SERVER_KEY_EXCHANGE,
  24722. MBEDTLS_SSL_CERTIFICATE_REQUEST,
  24723. MBEDTLS_SSL_SERVER_HELLO_DONE,
  24724. MBEDTLS_SSL_CLIENT_CERTIFICATE,
  24725. MBEDTLS_SSL_CLIENT_KEY_EXCHANGE,
  24726. MBEDTLS_SSL_CERTIFICATE_VERIFY,
  24727. MBEDTLS_SSL_CLIENT_CHANGE_CIPHER_SPEC,
  24728. MBEDTLS_SSL_CLIENT_FINISHED,
  24729. MBEDTLS_SSL_SERVER_CHANGE_CIPHER_SPEC,
  24730. MBEDTLS_SSL_SERVER_FINISHED,
  24731. MBEDTLS_SSL_FLUSH_BUFFERS,
  24732. MBEDTLS_SSL_HANDSHAKE_WRAPUP,
  24733. MBEDTLS_SSL_HANDSHAKE_OVER,
  24734. MBEDTLS_SSL_SERVER_NEW_SESSION_TICKET,
  24735. MBEDTLS_SSL_SERVER_HELLO_VERIFY_REQUEST_SENT,
  24736. }
  24737. mbedtls_ssl_states;
  24738. /*
  24739. * The tls_prf function types.
  24740. */
  24741. typedef enum
  24742. {
  24743. MBEDTLS_SSL_TLS_PRF_NONE,
  24744. MBEDTLS_SSL_TLS_PRF_SSL3,
  24745. MBEDTLS_SSL_TLS_PRF_TLS1,
  24746. MBEDTLS_SSL_TLS_PRF_SHA384,
  24747. MBEDTLS_SSL_TLS_PRF_SHA256
  24748. }
  24749. mbedtls_tls_prf_types;
  24750. /**
  24751. * \brief Callback type: send data on the network.
  24752. *
  24753. * \note That callback may be either blocking or non-blocking.
  24754. *
  24755. * \param ctx Context for the send callback (typically a file descriptor)
  24756. * \param buf Buffer holding the data to send
  24757. * \param len Length of the data to send
  24758. *
  24759. * \return The callback must return the number of bytes sent if any,
  24760. * or a non-zero error code.
  24761. * If performing non-blocking I/O, \c MBEDTLS_ERR_SSL_WANT_WRITE
  24762. * must be returned when the operation would block.
  24763. *
  24764. * \note The callback is allowed to send fewer bytes than requested.
  24765. * It must always return the number of bytes actually sent.
  24766. */
  24767. typedef int mbedtls_ssl_send_t( void *ctx,
  24768. const unsigned char *buf,
  24769. size_t len );
  24770. /**
  24771. * \brief Callback type: receive data from the network.
  24772. *
  24773. * \note That callback may be either blocking or non-blocking.
  24774. *
  24775. * \param ctx Context for the receive callback (typically a file
  24776. * descriptor)
  24777. * \param buf Buffer to write the received data to
  24778. * \param len Length of the receive buffer
  24779. *
  24780. * \returns If data has been received, the positive number of bytes received.
  24781. * \returns \c 0 if the connection has been closed.
  24782. * \returns If performing non-blocking I/O, \c MBEDTLS_ERR_SSL_WANT_READ
  24783. * must be returned when the operation would block.
  24784. * \returns Another negative error code on other kinds of failures.
  24785. *
  24786. * \note The callback may receive fewer bytes than the length of the
  24787. * buffer. It must always return the number of bytes actually
  24788. * received and written to the buffer.
  24789. */
  24790. typedef int mbedtls_ssl_recv_t( void *ctx,
  24791. unsigned char *buf,
  24792. size_t len );
  24793. /**
  24794. * \brief Callback type: receive data from the network, with timeout
  24795. *
  24796. * \note That callback must block until data is received, or the
  24797. * timeout delay expires, or the operation is interrupted by a
  24798. * signal.
  24799. *
  24800. * \param ctx Context for the receive callback (typically a file descriptor)
  24801. * \param buf Buffer to write the received data to
  24802. * \param len Length of the receive buffer
  24803. * \param timeout Maximum nomber of millisecondes to wait for data
  24804. * 0 means no timeout (potentially waiting forever)
  24805. *
  24806. * \return The callback must return the number of bytes received,
  24807. * or a non-zero error code:
  24808. * \c MBEDTLS_ERR_SSL_TIMEOUT if the operation timed out,
  24809. * \c MBEDTLS_ERR_SSL_WANT_READ if interrupted by a signal.
  24810. *
  24811. * \note The callback may receive fewer bytes than the length of the
  24812. * buffer. It must always return the number of bytes actually
  24813. * received and written to the buffer.
  24814. */
  24815. typedef int mbedtls_ssl_recv_timeout_t( void *ctx,
  24816. unsigned char *buf,
  24817. size_t len,
  24818. uint32_t timeout );
  24819. /**
  24820. * \brief Callback type: set a pair of timers/delays to watch
  24821. *
  24822. * \param ctx Context pointer
  24823. * \param int_ms Intermediate delay in milliseconds
  24824. * \param fin_ms Final delay in milliseconds
  24825. * 0 cancels the current timer.
  24826. *
  24827. * \note This callback must at least store the necessary information
  24828. * for the associated \c mbedtls_ssl_get_timer_t callback to
  24829. * return correct information.
  24830. *
  24831. * \note If using a event-driven style of programming, an event must
  24832. * be generated when the final delay is passed. The event must
  24833. * cause a call to \c mbedtls_ssl_handshake() with the proper
  24834. * SSL context to be scheduled. Care must be taken to ensure
  24835. * that at most one such call happens at a time.
  24836. *
  24837. * \note Only one timer at a time must be running. Calling this
  24838. * function while a timer is running must cancel it. Cancelled
  24839. * timers must not generate any event.
  24840. */
  24841. typedef void mbedtls_ssl_set_timer_t( void * ctx,
  24842. uint32_t int_ms,
  24843. uint32_t fin_ms );
  24844. /**
  24845. * \brief Callback type: get status of timers/delays
  24846. *
  24847. * \param ctx Context pointer
  24848. *
  24849. * \return This callback must return:
  24850. * -1 if cancelled (fin_ms == 0),
  24851. * 0 if none of the delays have passed,
  24852. * 1 if only the intermediate delay has passed,
  24853. * 2 if the final delay has passed.
  24854. */
  24855. typedef int mbedtls_ssl_get_timer_t( void * ctx );
  24856. /* Defined below */
  24857. typedef struct mbedtls_ssl_session mbedtls_ssl_session;
  24858. typedef struct mbedtls_ssl_context mbedtls_ssl_context;
  24859. typedef struct mbedtls_ssl_config mbedtls_ssl_config;
  24860. /* Defined in ssl_internal.h */
  24861. typedef struct mbedtls_ssl_transform mbedtls_ssl_transform;
  24862. typedef struct mbedtls_ssl_handshake_params mbedtls_ssl_handshake_params;
  24863. typedef struct mbedtls_ssl_sig_hash_set_t mbedtls_ssl_sig_hash_set_t;
  24864. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  24865. typedef struct mbedtls_ssl_key_cert mbedtls_ssl_key_cert;
  24866. #endif
  24867. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  24868. typedef struct mbedtls_ssl_flight_item mbedtls_ssl_flight_item;
  24869. #endif
  24870. #if defined(MBEDTLS_SSL_ASYNC_PRIVATE)
  24871. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  24872. /**
  24873. * \brief Callback type: start external signature operation.
  24874. *
  24875. * This callback is called during an SSL handshake to start
  24876. * a signature decryption operation using an
  24877. * external processor. The parameter \p cert contains
  24878. * the public key; it is up to the callback function to
  24879. * determine how to access the associated private key.
  24880. *
  24881. * This function typically sends or enqueues a request, and
  24882. * does not wait for the operation to complete. This allows
  24883. * the handshake step to be non-blocking.
  24884. *
  24885. * The parameters \p ssl and \p cert are guaranteed to remain
  24886. * valid throughout the handshake. On the other hand, this
  24887. * function must save the contents of \p hash if the value
  24888. * is needed for later processing, because the \p hash buffer
  24889. * is no longer valid after this function returns.
  24890. *
  24891. * This function may call mbedtls_ssl_set_async_operation_data()
  24892. * to store an operation context for later retrieval
  24893. * by the resume or cancel callback.
  24894. *
  24895. * \note For RSA signatures, this function must produce output
  24896. * that is consistent with PKCS#1 v1.5 in the same way as
  24897. * mbedtls_rsa_pkcs1_sign(). Before the private key operation,
  24898. * apply the padding steps described in RFC 8017, section 9.2
  24899. * "EMSA-PKCS1-v1_5" as follows.
  24900. * - If \p md_alg is #MBEDTLS_MD_NONE, apply the PKCS#1 v1.5
  24901. * encoding, treating \p hash as the DigestInfo to be
  24902. * padded. In other words, apply EMSA-PKCS1-v1_5 starting
  24903. * from step 3, with `T = hash` and `tLen = hash_len`.
  24904. * - If `md_alg != MBEDTLS_MD_NONE`, apply the PKCS#1 v1.5
  24905. * encoding, treating \p hash as the hash to be encoded and
  24906. * padded. In other words, apply EMSA-PKCS1-v1_5 starting
  24907. * from step 2, with `digestAlgorithm` obtained by calling
  24908. * mbedtls_oid_get_oid_by_md() on \p md_alg.
  24909. *
  24910. * \note For ECDSA signatures, the output format is the DER encoding
  24911. * `Ecdsa-Sig-Value` defined in
  24912. * [RFC 4492 section 5.4](https://tools.ietf.org/html/rfc4492#section-5.4).
  24913. *
  24914. * \param ssl The SSL connection instance. It should not be
  24915. * modified other than via
  24916. * mbedtls_ssl_set_async_operation_data().
  24917. * \param cert Certificate containing the public key.
  24918. * In simple cases, this is one of the pointers passed to
  24919. * mbedtls_ssl_conf_own_cert() when configuring the SSL
  24920. * connection. However, if other callbacks are used, this
  24921. * property may not hold. For example, if an SNI callback
  24922. * is registered with mbedtls_ssl_conf_sni(), then
  24923. * this callback determines what certificate is used.
  24924. * \param md_alg Hash algorithm.
  24925. * \param hash Buffer containing the hash. This buffer is
  24926. * no longer valid when the function returns.
  24927. * \param hash_len Size of the \c hash buffer in bytes.
  24928. *
  24929. * \return 0 if the operation was started successfully and the SSL
  24930. * stack should call the resume callback immediately.
  24931. * \return #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS if the operation
  24932. * was started successfully and the SSL stack should return
  24933. * immediately without calling the resume callback yet.
  24934. * \return #MBEDTLS_ERR_SSL_HW_ACCEL_FALLTHROUGH if the external
  24935. * processor does not support this key. The SSL stack will
  24936. * use the private key object instead.
  24937. * \return Any other error indicates a fatal failure and is
  24938. * propagated up the call chain. The callback should
  24939. * use \c MBEDTLS_ERR_PK_xxx error codes, and <b>must not</b>
  24940. * use \c MBEDTLS_ERR_SSL_xxx error codes except as
  24941. * directed in the documentation of this callback.
  24942. */
  24943. typedef int mbedtls_ssl_async_sign_t( mbedtls_ssl_context *ssl,
  24944. mbedtls_x509_crt *cert,
  24945. mbedtls_md_type_t md_alg,
  24946. const unsigned char *hash,
  24947. size_t hash_len );
  24948. /**
  24949. * \brief Callback type: start external decryption operation.
  24950. *
  24951. * This callback is called during an SSL handshake to start
  24952. * an RSA decryption operation using an
  24953. * external processor. The parameter \p cert contains
  24954. * the public key; it is up to the callback function to
  24955. * determine how to access the associated private key.
  24956. *
  24957. * This function typically sends or enqueues a request, and
  24958. * does not wait for the operation to complete. This allows
  24959. * the handshake step to be non-blocking.
  24960. *
  24961. * The parameters \p ssl and \p cert are guaranteed to remain
  24962. * valid throughout the handshake. On the other hand, this
  24963. * function must save the contents of \p input if the value
  24964. * is needed for later processing, because the \p input buffer
  24965. * is no longer valid after this function returns.
  24966. *
  24967. * This function may call mbedtls_ssl_set_async_operation_data()
  24968. * to store an operation context for later retrieval
  24969. * by the resume or cancel callback.
  24970. *
  24971. * \warning RSA decryption as used in TLS is subject to a potential
  24972. * timing side channel attack first discovered by Bleichenbacher
  24973. * in 1998. This attack can be remotely exploitable
  24974. * in practice. To avoid this attack, you must ensure that
  24975. * if the callback performs an RSA decryption, the time it
  24976. * takes to execute and return the result does not depend
  24977. * on whether the RSA decryption succeeded or reported
  24978. * invalid padding.
  24979. *
  24980. * \param ssl The SSL connection instance. It should not be
  24981. * modified other than via
  24982. * mbedtls_ssl_set_async_operation_data().
  24983. * \param cert Certificate containing the public key.
  24984. * In simple cases, this is one of the pointers passed to
  24985. * mbedtls_ssl_conf_own_cert() when configuring the SSL
  24986. * connection. However, if other callbacks are used, this
  24987. * property may not hold. For example, if an SNI callback
  24988. * is registered with mbedtls_ssl_conf_sni(), then
  24989. * this callback determines what certificate is used.
  24990. * \param input Buffer containing the input ciphertext. This buffer
  24991. * is no longer valid when the function returns.
  24992. * \param input_len Size of the \p input buffer in bytes.
  24993. *
  24994. * \return 0 if the operation was started successfully and the SSL
  24995. * stack should call the resume callback immediately.
  24996. * \return #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS if the operation
  24997. * was started successfully and the SSL stack should return
  24998. * immediately without calling the resume callback yet.
  24999. * \return #MBEDTLS_ERR_SSL_HW_ACCEL_FALLTHROUGH if the external
  25000. * processor does not support this key. The SSL stack will
  25001. * use the private key object instead.
  25002. * \return Any other error indicates a fatal failure and is
  25003. * propagated up the call chain. The callback should
  25004. * use \c MBEDTLS_ERR_PK_xxx error codes, and <b>must not</b>
  25005. * use \c MBEDTLS_ERR_SSL_xxx error codes except as
  25006. * directed in the documentation of this callback.
  25007. */
  25008. typedef int mbedtls_ssl_async_decrypt_t( mbedtls_ssl_context *ssl,
  25009. mbedtls_x509_crt *cert,
  25010. const unsigned char *input,
  25011. size_t input_len );
  25012. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  25013. /**
  25014. * \brief Callback type: resume external operation.
  25015. *
  25016. * This callback is called during an SSL handshake to resume
  25017. * an external operation started by the
  25018. * ::mbedtls_ssl_async_sign_t or
  25019. * ::mbedtls_ssl_async_decrypt_t callback.
  25020. *
  25021. * This function typically checks the status of a pending
  25022. * request or causes the request queue to make progress, and
  25023. * does not wait for the operation to complete. This allows
  25024. * the handshake step to be non-blocking.
  25025. *
  25026. * This function may call mbedtls_ssl_get_async_operation_data()
  25027. * to retrieve an operation context set by the start callback.
  25028. * It may call mbedtls_ssl_set_async_operation_data() to modify
  25029. * this context.
  25030. *
  25031. * Note that when this function returns a status other than
  25032. * #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS, it must free any
  25033. * resources associated with the operation.
  25034. *
  25035. * \param ssl The SSL connection instance. It should not be
  25036. * modified other than via
  25037. * mbedtls_ssl_set_async_operation_data().
  25038. * \param output Buffer containing the output (signature or decrypted
  25039. * data) on success.
  25040. * \param output_len On success, number of bytes written to \p output.
  25041. * \param output_size Size of the \p output buffer in bytes.
  25042. *
  25043. * \return 0 if output of the operation is available in the
  25044. * \p output buffer.
  25045. * \return #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS if the operation
  25046. * is still in progress. Subsequent requests for progress
  25047. * on the SSL connection will call the resume callback
  25048. * again.
  25049. * \return Any other error means that the operation is aborted.
  25050. * The SSL handshake is aborted. The callback should
  25051. * use \c MBEDTLS_ERR_PK_xxx error codes, and <b>must not</b>
  25052. * use \c MBEDTLS_ERR_SSL_xxx error codes except as
  25053. * directed in the documentation of this callback.
  25054. */
  25055. typedef int mbedtls_ssl_async_resume_t( mbedtls_ssl_context *ssl,
  25056. unsigned char *output,
  25057. size_t *output_len,
  25058. size_t output_size );
  25059. /**
  25060. * \brief Callback type: cancel external operation.
  25061. *
  25062. * This callback is called if an SSL connection is closed
  25063. * while an asynchronous operation is in progress. Note that
  25064. * this callback is not called if the
  25065. * ::mbedtls_ssl_async_resume_t callback has run and has
  25066. * returned a value other than
  25067. * #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS, since in that case
  25068. * the asynchronous operation has already completed.
  25069. *
  25070. * This function may call mbedtls_ssl_get_async_operation_data()
  25071. * to retrieve an operation context set by the start callback.
  25072. *
  25073. * \param ssl The SSL connection instance. It should not be
  25074. * modified.
  25075. */
  25076. typedef void mbedtls_ssl_async_cancel_t( mbedtls_ssl_context *ssl );
  25077. #endif /* MBEDTLS_SSL_ASYNC_PRIVATE */
  25078. #if defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED) && \
  25079. !defined(MBEDTLS_SSL_KEEP_PEER_CERTIFICATE)
  25080. #define MBEDTLS_SSL_PEER_CERT_DIGEST_MAX_LEN 48
  25081. #if defined(MBEDTLS_SHA256_C)
  25082. #define MBEDTLS_SSL_PEER_CERT_DIGEST_DFL_TYPE MBEDTLS_MD_SHA256
  25083. #define MBEDTLS_SSL_PEER_CERT_DIGEST_DFL_LEN 32
  25084. #elif defined(MBEDTLS_SHA512_C)
  25085. #define MBEDTLS_SSL_PEER_CERT_DIGEST_DFL_TYPE MBEDTLS_MD_SHA384
  25086. #define MBEDTLS_SSL_PEER_CERT_DIGEST_DFL_LEN 48
  25087. #elif defined(MBEDTLS_SHA1_C)
  25088. #define MBEDTLS_SSL_PEER_CERT_DIGEST_DFL_TYPE MBEDTLS_MD_SHA1
  25089. #define MBEDTLS_SSL_PEER_CERT_DIGEST_DFL_LEN 20
  25090. #else
  25091. /* This is already checked in check_config.h, but be sure. */
  25092. #error "Bad configuration - need SHA-1, SHA-256 or SHA-512 enabled to compute digest of peer CRT."
  25093. #endif
  25094. #endif /* MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED &&
  25095. !MBEDTLS_SSL_KEEP_PEER_CERTIFICATE */
  25096. #if defined(MBEDTLS_SSL_DTLS_SRTP)
  25097. #define MBEDTLS_TLS_SRTP_MAX_MKI_LENGTH 255
  25098. #define MBEDTLS_TLS_SRTP_MAX_PROFILE_LIST_LENGTH 4
  25099. /*
  25100. * For code readability use a typedef for DTLS-SRTP profiles
  25101. *
  25102. * Use_srtp extension protection profiles values as defined in
  25103. * http://www.iana.org/assignments/srtp-protection/srtp-protection.xhtml
  25104. *
  25105. * Reminder: if this list is expanded mbedtls_ssl_check_srtp_profile_value
  25106. * must be updated too.
  25107. */
  25108. #define MBEDTLS_TLS_SRTP_AES128_CM_HMAC_SHA1_80 ( (uint16_t) 0x0001)
  25109. #define MBEDTLS_TLS_SRTP_AES128_CM_HMAC_SHA1_32 ( (uint16_t) 0x0002)
  25110. #define MBEDTLS_TLS_SRTP_NULL_HMAC_SHA1_80 ( (uint16_t) 0x0005)
  25111. #define MBEDTLS_TLS_SRTP_NULL_HMAC_SHA1_32 ( (uint16_t) 0x0006)
  25112. /* This one is not iana defined, but for code readability. */
  25113. #define MBEDTLS_TLS_SRTP_UNSET ( (uint16_t) 0x0000)
  25114. typedef uint16_t mbedtls_ssl_srtp_profile;
  25115. typedef struct mbedtls_dtls_srtp_info_t
  25116. {
  25117. /*! The SRTP profile that was negotiated. */
  25118. mbedtls_ssl_srtp_profile chosen_dtls_srtp_profile;
  25119. /*! The length of mki_value. */
  25120. uint16_t mki_len;
  25121. /*! The mki_value used, with max size of 256 bytes. */
  25122. unsigned char mki_value[MBEDTLS_TLS_SRTP_MAX_MKI_LENGTH];
  25123. }
  25124. mbedtls_dtls_srtp_info;
  25125. #endif /* MBEDTLS_SSL_DTLS_SRTP */
  25126. /*
  25127. * This structure is used for storing current session data.
  25128. *
  25129. * Note: when changing this definition, we need to check and update:
  25130. * - in tests/suites/test_suite_ssl.function:
  25131. * ssl_populate_session() and ssl_serialize_session_save_load()
  25132. * - in library/ssl_tls.c:
  25133. * mbedtls_ssl_session_init() and mbedtls_ssl_session_free()
  25134. * mbedtls_ssl_session_save() and ssl_session_load()
  25135. * ssl_session_copy()
  25136. */
  25137. struct mbedtls_ssl_session
  25138. {
  25139. #if defined(MBEDTLS_SSL_MAX_FRAGMENT_LENGTH)
  25140. unsigned char mfl_code; /*!< MaxFragmentLength negotiated by peer */
  25141. #endif /* MBEDTLS_SSL_MAX_FRAGMENT_LENGTH */
  25142. #if defined(MBEDTLS_HAVE_TIME)
  25143. mbedtls_time_t start; /*!< starting time */
  25144. #endif
  25145. int ciphersuite; /*!< chosen ciphersuite */
  25146. int compression; /*!< chosen compression */
  25147. size_t id_len; /*!< session id length */
  25148. unsigned char id[32]; /*!< session identifier */
  25149. unsigned char master[48]; /*!< the master secret */
  25150. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  25151. #if defined(MBEDTLS_SSL_KEEP_PEER_CERTIFICATE)
  25152. mbedtls_x509_crt *peer_cert; /*!< peer X.509 cert chain */
  25153. #else /* MBEDTLS_SSL_KEEP_PEER_CERTIFICATE */
  25154. /*! The digest of the peer's end-CRT. This must be kept to detect CRT
  25155. * changes during renegotiation, mitigating the triple handshake attack. */
  25156. unsigned char *peer_cert_digest;
  25157. size_t peer_cert_digest_len;
  25158. mbedtls_md_type_t peer_cert_digest_type;
  25159. #endif /* !MBEDTLS_SSL_KEEP_PEER_CERTIFICATE */
  25160. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  25161. uint32_t verify_result; /*!< verification result */
  25162. #if defined(MBEDTLS_SSL_SESSION_TICKETS) && defined(MBEDTLS_SSL_CLI_C)
  25163. unsigned char *ticket; /*!< RFC 5077 session ticket */
  25164. size_t ticket_len; /*!< session ticket length */
  25165. uint32_t ticket_lifetime; /*!< ticket lifetime hint */
  25166. #endif /* MBEDTLS_SSL_SESSION_TICKETS && MBEDTLS_SSL_CLI_C */
  25167. #if defined(MBEDTLS_SSL_TRUNCATED_HMAC)
  25168. int trunc_hmac; /*!< flag for truncated hmac activation */
  25169. #endif /* MBEDTLS_SSL_TRUNCATED_HMAC */
  25170. #if defined(MBEDTLS_SSL_ENCRYPT_THEN_MAC)
  25171. int encrypt_then_mac; /*!< flag for EtM activation */
  25172. #endif
  25173. };
  25174. /**
  25175. * SSL/TLS configuration to be shared between mbedtls_ssl_context structures.
  25176. */
  25177. struct mbedtls_ssl_config
  25178. {
  25179. /* Group items by size and reorder them to maximize usage of immediate offset access. */
  25180. /*
  25181. * Numerical settings (char)
  25182. */
  25183. unsigned char max_major_ver; /*!< max. major version used */
  25184. unsigned char max_minor_ver; /*!< max. minor version used */
  25185. unsigned char min_major_ver; /*!< min. major version used */
  25186. unsigned char min_minor_ver; /*!< min. minor version used */
  25187. /*
  25188. * Flags (could be bit-fields to save RAM, but separate bytes make
  25189. * the code smaller on architectures with an instruction for direct
  25190. * byte access).
  25191. */
  25192. uint8_t endpoint /*bool*/; /*!< 0: client, 1: server */
  25193. uint8_t transport /*bool*/; /*!< stream (TLS) or datagram (DTLS) */
  25194. uint8_t authmode /*2 bits*/; /*!< MBEDTLS_SSL_VERIFY_XXX */
  25195. /* needed even with renego disabled for LEGACY_BREAK_HANDSHAKE */
  25196. uint8_t allow_legacy_renegotiation /*2 bits*/; /*!< MBEDTLS_LEGACY_XXX */
  25197. #if defined(MBEDTLS_ARC4_C)
  25198. uint8_t arc4_disabled /*bool*/; /*!< blacklist RC4 ciphersuites? */
  25199. #endif
  25200. #if defined(MBEDTLS_SSL_MAX_FRAGMENT_LENGTH)
  25201. uint8_t mfl_code /*3 bits*/; /*!< desired fragment length */
  25202. #endif
  25203. #if defined(MBEDTLS_SSL_ENCRYPT_THEN_MAC)
  25204. uint8_t encrypt_then_mac /*bool*/; /*!< negotiate encrypt-then-mac? */
  25205. #endif
  25206. #if defined(MBEDTLS_SSL_EXTENDED_MASTER_SECRET)
  25207. uint8_t extended_ms /*bool*/; /*!< negotiate extended master secret? */
  25208. #endif
  25209. #if defined(MBEDTLS_SSL_DTLS_ANTI_REPLAY)
  25210. uint8_t anti_replay /*bool*/; /*!< detect and prevent replay? */
  25211. #endif
  25212. #if defined(MBEDTLS_SSL_CBC_RECORD_SPLITTING)
  25213. uint8_t cbc_record_splitting /*bool*/; /*!< do cbc record splitting */
  25214. #endif
  25215. #if defined(MBEDTLS_SSL_RENEGOTIATION)
  25216. uint8_t disable_renegotiation /*bool*/; /*!< disable renegotiation? */
  25217. #endif
  25218. #if defined(MBEDTLS_SSL_TRUNCATED_HMAC)
  25219. uint8_t trunc_hmac /*bool*/; /*!< negotiate truncated hmac? */
  25220. #endif
  25221. #if defined(MBEDTLS_SSL_SESSION_TICKETS)
  25222. uint8_t session_tickets /*bool*/; /*!< use session tickets? */
  25223. #endif
  25224. #if defined(MBEDTLS_SSL_FALLBACK_SCSV) && defined(MBEDTLS_SSL_CLI_C)
  25225. uint8_t fallback /*bool*/; /*!< is this a fallback? */
  25226. #endif
  25227. #if defined(MBEDTLS_SSL_SRV_C)
  25228. uint8_t cert_req_ca_list /*bool*/; /*!< enable sending CA list in
  25229. Certificate Request messages? */
  25230. #endif
  25231. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  25232. uint8_t ignore_unexpected_cid /*bool*/; /*!< Determines whether DTLS
  25233. * record with unexpected CID
  25234. * should lead to failure. */
  25235. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  25236. #if defined(MBEDTLS_SSL_DTLS_SRTP)
  25237. uint8_t dtls_srtp_mki_support /*bool*/; /*!< support having mki_value
  25238. in the use_srtp extension? */
  25239. #endif
  25240. /*
  25241. * Numerical settings (int or larger)
  25242. */
  25243. uint32_t read_timeout; /*!< timeout for mbedtls_ssl_read (ms) */
  25244. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  25245. uint32_t hs_timeout_min; /*!< initial value of the handshake
  25246. retransmission timeout (ms) */
  25247. uint32_t hs_timeout_max; /*!< maximum value of the handshake
  25248. retransmission timeout (ms) */
  25249. #endif
  25250. #if defined(MBEDTLS_SSL_RENEGOTIATION)
  25251. int renego_max_records; /*!< grace period for renegotiation */
  25252. unsigned char renego_period[8]; /*!< value of the record counters
  25253. that triggers renegotiation */
  25254. #endif
  25255. #if defined(MBEDTLS_SSL_DTLS_BADMAC_LIMIT)
  25256. unsigned int badmac_limit; /*!< limit of records with a bad MAC */
  25257. #endif
  25258. #if defined(MBEDTLS_DHM_C) && defined(MBEDTLS_SSL_CLI_C)
  25259. unsigned int dhm_min_bitlen; /*!< min. bit length of the DHM prime */
  25260. #endif
  25261. /*
  25262. * Pointers
  25263. */
  25264. const int *ciphersuite_list[4]; /*!< allowed ciphersuites per version */
  25265. /** Callback for printing debug output */
  25266. void (*f_dbg)(void *, int, const char *, int, const char *);
  25267. void *p_dbg; /*!< context for the debug function */
  25268. /** Callback for getting (pseudo-)random numbers */
  25269. int (*f_rng)(void *, unsigned char *, size_t);
  25270. void *p_rng; /*!< context for the RNG function */
  25271. /** Callback to retrieve a session from the cache */
  25272. int (*f_get_cache)(void *, mbedtls_ssl_session *);
  25273. /** Callback to store a session into the cache */
  25274. int (*f_set_cache)(void *, const mbedtls_ssl_session *);
  25275. void *p_cache; /*!< context for cache callbacks */
  25276. #if defined(MBEDTLS_SSL_SERVER_NAME_INDICATION)
  25277. /** Callback for setting cert according to SNI extension */
  25278. int (*f_sni)(void *, mbedtls_ssl_context *, const unsigned char *, size_t);
  25279. void *p_sni; /*!< context for SNI callback */
  25280. #endif
  25281. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  25282. /** Callback to customize X.509 certificate chain verification */
  25283. int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *);
  25284. void *p_vrfy; /*!< context for X.509 verify calllback */
  25285. #endif
  25286. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED)
  25287. /** Callback to retrieve PSK key from identity */
  25288. int (*f_psk)(void *, mbedtls_ssl_context *, const unsigned char *, size_t);
  25289. void *p_psk; /*!< context for PSK callback */
  25290. #endif
  25291. #if defined(MBEDTLS_SSL_DTLS_HELLO_VERIFY) && defined(MBEDTLS_SSL_SRV_C)
  25292. /** Callback to create & write a cookie for ClientHello veirifcation */
  25293. int (*f_cookie_write)( void *, unsigned char **, unsigned char *,
  25294. const unsigned char *, size_t );
  25295. /** Callback to verify validity of a ClientHello cookie */
  25296. int (*f_cookie_check)( void *, const unsigned char *, size_t,
  25297. const unsigned char *, size_t );
  25298. void *p_cookie; /*!< context for the cookie callbacks */
  25299. #endif
  25300. #if defined(MBEDTLS_SSL_SESSION_TICKETS) && defined(MBEDTLS_SSL_SRV_C)
  25301. /** Callback to create & write a session ticket */
  25302. int (*f_ticket_write)( void *, const mbedtls_ssl_session *,
  25303. unsigned char *, const unsigned char *, size_t *, uint32_t * );
  25304. /** Callback to parse a session ticket into a session structure */
  25305. int (*f_ticket_parse)( void *, mbedtls_ssl_session *, unsigned char *, size_t);
  25306. void *p_ticket; /*!< context for the ticket callbacks */
  25307. #endif /* MBEDTLS_SSL_SESSION_TICKETS && MBEDTLS_SSL_SRV_C */
  25308. #if defined(MBEDTLS_SSL_EXPORT_KEYS)
  25309. /** Callback to export key block and master secret */
  25310. int (*f_export_keys)( void *, const unsigned char *,
  25311. const unsigned char *, size_t, size_t, size_t );
  25312. /** Callback to export key block, master secret,
  25313. * tls_prf and random bytes. Should replace f_export_keys */
  25314. int (*f_export_keys_ext)( void *, const unsigned char *,
  25315. const unsigned char *, size_t, size_t, size_t,
  25316. const unsigned char[32], const unsigned char[32],
  25317. mbedtls_tls_prf_types );
  25318. void *p_export_keys; /*!< context for key export callback */
  25319. #endif
  25320. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  25321. size_t cid_len; /*!< The length of CIDs for incoming DTLS records. */
  25322. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  25323. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  25324. const mbedtls_x509_crt_profile *cert_profile; /*!< verification profile */
  25325. mbedtls_ssl_key_cert *key_cert; /*!< own certificate/key pair(s) */
  25326. mbedtls_x509_crt *ca_chain; /*!< trusted CAs */
  25327. mbedtls_x509_crl *ca_crl; /*!< trusted CAs CRLs */
  25328. #if defined(MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK)
  25329. mbedtls_x509_crt_ca_cb_t f_ca_cb;
  25330. void *p_ca_cb;
  25331. #endif /* MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK */
  25332. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  25333. #if defined(MBEDTLS_SSL_ASYNC_PRIVATE)
  25334. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  25335. mbedtls_ssl_async_sign_t *f_async_sign_start; /*!< start asynchronous signature operation */
  25336. mbedtls_ssl_async_decrypt_t *f_async_decrypt_start; /*!< start asynchronous decryption operation */
  25337. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  25338. mbedtls_ssl_async_resume_t *f_async_resume; /*!< resume asynchronous operation */
  25339. mbedtls_ssl_async_cancel_t *f_async_cancel; /*!< cancel asynchronous operation */
  25340. void *p_async_config_data; /*!< Configuration data set by mbedtls_ssl_conf_async_private_cb(). */
  25341. #endif /* MBEDTLS_SSL_ASYNC_PRIVATE */
  25342. #if defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED)
  25343. const int *sig_hashes; /*!< allowed signature hashes */
  25344. #endif
  25345. #if defined(MBEDTLS_ECP_C)
  25346. const mbedtls_ecp_group_id *curve_list; /*!< allowed curves */
  25347. #endif
  25348. #if defined(MBEDTLS_DHM_C)
  25349. mbedtls_mpi dhm_P; /*!< prime modulus for DHM */
  25350. mbedtls_mpi dhm_G; /*!< generator for DHM */
  25351. #endif
  25352. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED)
  25353. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  25354. psa_key_id_t psk_opaque; /*!< PSA key slot holding opaque PSK. This field
  25355. * should only be set via
  25356. * mbedtls_ssl_conf_psk_opaque().
  25357. * If either no PSK or a raw PSK have been
  25358. * configured, this has value \c 0.
  25359. */
  25360. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  25361. unsigned char *psk; /*!< The raw pre-shared key. This field should
  25362. * only be set via mbedtls_ssl_conf_psk().
  25363. * If either no PSK or an opaque PSK
  25364. * have been configured, this has value NULL. */
  25365. size_t psk_len; /*!< The length of the raw pre-shared key.
  25366. * This field should only be set via
  25367. * mbedtls_ssl_conf_psk().
  25368. * Its value is non-zero if and only if
  25369. * \c psk is not \c NULL. */
  25370. unsigned char *psk_identity; /*!< The PSK identity for PSK negotiation.
  25371. * This field should only be set via
  25372. * mbedtls_ssl_conf_psk().
  25373. * This is set if and only if either
  25374. * \c psk or \c psk_opaque are set. */
  25375. size_t psk_identity_len;/*!< The length of PSK identity.
  25376. * This field should only be set via
  25377. * mbedtls_ssl_conf_psk().
  25378. * Its value is non-zero if and only if
  25379. * \c psk is not \c NULL or \c psk_opaque
  25380. * is not \c 0. */
  25381. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED */
  25382. #if defined(MBEDTLS_SSL_ALPN)
  25383. const char **alpn_list; /*!< ordered list of protocols */
  25384. #endif
  25385. #if defined(MBEDTLS_SSL_DTLS_SRTP)
  25386. /*! ordered list of supported srtp profile */
  25387. const mbedtls_ssl_srtp_profile *dtls_srtp_profile_list;
  25388. /*! number of supported profiles */
  25389. size_t dtls_srtp_profile_list_len;
  25390. #endif /* MBEDTLS_SSL_DTLS_SRTP */
  25391. };
  25392. struct mbedtls_ssl_context
  25393. {
  25394. const mbedtls_ssl_config *conf; /*!< configuration information */
  25395. /*
  25396. * Miscellaneous
  25397. */
  25398. int state; /*!< SSL handshake: current state */
  25399. #if defined(MBEDTLS_SSL_RENEGOTIATION)
  25400. int renego_status; /*!< Initial, in progress, pending? */
  25401. int renego_records_seen; /*!< Records since renego request, or with DTLS,
  25402. number of retransmissions of request if
  25403. renego_max_records is < 0 */
  25404. #endif /* MBEDTLS_SSL_RENEGOTIATION */
  25405. int major_ver; /*!< equal to MBEDTLS_SSL_MAJOR_VERSION_3 */
  25406. int minor_ver; /*!< either 0 (SSL3) or 1 (TLS1.0) */
  25407. #if defined(MBEDTLS_SSL_DTLS_BADMAC_LIMIT)
  25408. unsigned badmac_seen; /*!< records with a bad MAC received */
  25409. #endif /* MBEDTLS_SSL_DTLS_BADMAC_LIMIT */
  25410. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  25411. /** Callback to customize X.509 certificate chain verification */
  25412. int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *);
  25413. void *p_vrfy; /*!< context for X.509 verify callback */
  25414. #endif
  25415. mbedtls_ssl_send_t *f_send; /*!< Callback for network send */
  25416. mbedtls_ssl_recv_t *f_recv; /*!< Callback for network receive */
  25417. mbedtls_ssl_recv_timeout_t *f_recv_timeout;
  25418. /*!< Callback for network receive with timeout */
  25419. void *p_bio; /*!< context for I/O operations */
  25420. /*
  25421. * Session layer
  25422. */
  25423. mbedtls_ssl_session *session_in; /*!< current session data (in) */
  25424. mbedtls_ssl_session *session_out; /*!< current session data (out) */
  25425. mbedtls_ssl_session *session; /*!< negotiated session data */
  25426. mbedtls_ssl_session *session_negotiate; /*!< session data in negotiation */
  25427. mbedtls_ssl_handshake_params *handshake; /*!< params required only during
  25428. the handshake process */
  25429. /*
  25430. * Record layer transformations
  25431. */
  25432. mbedtls_ssl_transform *transform_in; /*!< current transform params (in) */
  25433. mbedtls_ssl_transform *transform_out; /*!< current transform params (in) */
  25434. mbedtls_ssl_transform *transform; /*!< negotiated transform params */
  25435. mbedtls_ssl_transform *transform_negotiate; /*!< transform params in negotiation */
  25436. /*
  25437. * Timers
  25438. */
  25439. void *p_timer; /*!< context for the timer callbacks */
  25440. mbedtls_ssl_set_timer_t *f_set_timer; /*!< set timer callback */
  25441. mbedtls_ssl_get_timer_t *f_get_timer; /*!< get timer callback */
  25442. /*
  25443. * Record layer (incoming data)
  25444. */
  25445. unsigned char *in_buf; /*!< input buffer */
  25446. unsigned char *in_ctr; /*!< 64-bit incoming message counter
  25447. TLS: maintained by us
  25448. DTLS: read from peer */
  25449. unsigned char *in_hdr; /*!< start of record header */
  25450. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  25451. unsigned char *in_cid; /*!< The start of the CID;
  25452. * (the end is marked by in_len). */
  25453. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  25454. unsigned char *in_len; /*!< two-bytes message length field */
  25455. unsigned char *in_iv; /*!< ivlen-byte IV */
  25456. unsigned char *in_msg; /*!< message contents (in_iv+ivlen) */
  25457. unsigned char *in_offt; /*!< read offset in application data */
  25458. int in_msgtype; /*!< record header: message type */
  25459. size_t in_msglen; /*!< record header: message length */
  25460. size_t in_left; /*!< amount of data read so far */
  25461. #if defined(MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH)
  25462. size_t in_buf_len; /*!< length of input buffer */
  25463. #endif
  25464. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  25465. uint16_t in_epoch; /*!< DTLS epoch for incoming records */
  25466. size_t next_record_offset; /*!< offset of the next record in datagram
  25467. (equal to in_left if none) */
  25468. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  25469. #if defined(MBEDTLS_SSL_DTLS_ANTI_REPLAY)
  25470. uint64_t in_window_top; /*!< last validated record seq_num */
  25471. uint64_t in_window; /*!< bitmask for replay detection */
  25472. #endif /* MBEDTLS_SSL_DTLS_ANTI_REPLAY */
  25473. size_t in_hslen; /*!< current handshake message length,
  25474. including the handshake header */
  25475. int nb_zero; /*!< # of 0-length encrypted messages */
  25476. int keep_current_message; /*!< drop or reuse current message
  25477. on next call to record layer? */
  25478. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  25479. uint8_t disable_datagram_packing; /*!< Disable packing multiple records
  25480. * within a single datagram. */
  25481. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  25482. /*
  25483. * Record layer (outgoing data)
  25484. */
  25485. unsigned char *out_buf; /*!< output buffer */
  25486. unsigned char *out_ctr; /*!< 64-bit outgoing message counter */
  25487. unsigned char *out_hdr; /*!< start of record header */
  25488. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  25489. unsigned char *out_cid; /*!< The start of the CID;
  25490. * (the end is marked by in_len). */
  25491. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  25492. unsigned char *out_len; /*!< two-bytes message length field */
  25493. unsigned char *out_iv; /*!< ivlen-byte IV */
  25494. unsigned char *out_msg; /*!< message contents (out_iv+ivlen) */
  25495. int out_msgtype; /*!< record header: message type */
  25496. size_t out_msglen; /*!< record header: message length */
  25497. size_t out_left; /*!< amount of data not yet written */
  25498. #if defined(MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH)
  25499. size_t out_buf_len; /*!< length of output buffer */
  25500. #endif
  25501. unsigned char cur_out_ctr[8]; /*!< Outgoing record sequence number. */
  25502. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  25503. uint16_t mtu; /*!< path mtu, used to fragment outgoing messages */
  25504. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  25505. #if defined(MBEDTLS_ZLIB_SUPPORT)
  25506. unsigned char *compress_buf; /*!< zlib data buffer */
  25507. #endif /* MBEDTLS_ZLIB_SUPPORT */
  25508. #if defined(MBEDTLS_SSL_CBC_RECORD_SPLITTING)
  25509. signed char split_done; /*!< current record already splitted? */
  25510. #endif /* MBEDTLS_SSL_CBC_RECORD_SPLITTING */
  25511. /*
  25512. * PKI layer
  25513. */
  25514. int client_auth; /*!< flag for client auth. */
  25515. /*
  25516. * User settings
  25517. */
  25518. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  25519. char *hostname; /*!< expected peer CN for verification
  25520. (and SNI if available) */
  25521. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  25522. #if defined(MBEDTLS_SSL_ALPN)
  25523. const char *alpn_chosen; /*!< negotiated protocol */
  25524. #endif /* MBEDTLS_SSL_ALPN */
  25525. #if defined(MBEDTLS_SSL_DTLS_SRTP)
  25526. /*
  25527. * use_srtp extension
  25528. */
  25529. mbedtls_dtls_srtp_info dtls_srtp_info;
  25530. #endif /* MBEDTLS_SSL_DTLS_SRTP */
  25531. /*
  25532. * Information for DTLS hello verify
  25533. */
  25534. #if defined(MBEDTLS_SSL_DTLS_HELLO_VERIFY) && defined(MBEDTLS_SSL_SRV_C)
  25535. unsigned char *cli_id; /*!< transport-level ID of the client */
  25536. size_t cli_id_len; /*!< length of cli_id */
  25537. #endif /* MBEDTLS_SSL_DTLS_HELLO_VERIFY && MBEDTLS_SSL_SRV_C */
  25538. /*
  25539. * Secure renegotiation
  25540. */
  25541. /* needed to know when to send extension on server */
  25542. int secure_renegotiation; /*!< does peer support legacy or
  25543. secure renegotiation */
  25544. #if defined(MBEDTLS_SSL_RENEGOTIATION)
  25545. size_t verify_data_len; /*!< length of verify data stored */
  25546. char own_verify_data[MBEDTLS_SSL_VERIFY_DATA_MAX_LEN]; /*!< previous handshake verify data */
  25547. char peer_verify_data[MBEDTLS_SSL_VERIFY_DATA_MAX_LEN]; /*!< previous handshake verify data */
  25548. #endif /* MBEDTLS_SSL_RENEGOTIATION */
  25549. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  25550. /* CID configuration to use in subsequent handshakes. */
  25551. /*! The next incoming CID, chosen by the user and applying to
  25552. * all subsequent handshakes. This may be different from the
  25553. * CID currently used in case the user has re-configured the CID
  25554. * after an initial handshake. */
  25555. unsigned char own_cid[ MBEDTLS_SSL_CID_IN_LEN_MAX ];
  25556. uint8_t own_cid_len; /*!< The length of \c own_cid. */
  25557. uint8_t negotiate_cid; /*!< This indicates whether the CID extension should
  25558. * be negotiated in the next handshake or not.
  25559. * Possible values are #MBEDTLS_SSL_CID_ENABLED
  25560. * and #MBEDTLS_SSL_CID_DISABLED. */
  25561. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  25562. void *appData;
  25563. };
  25564. #if defined(MBEDTLS_SSL_HW_RECORD_ACCEL)
  25565. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  25566. #define MBEDTLS_SSL_CHANNEL_OUTBOUND MBEDTLS_DEPRECATED_NUMERIC_CONSTANT( 0 )
  25567. #define MBEDTLS_SSL_CHANNEL_INBOUND MBEDTLS_DEPRECATED_NUMERIC_CONSTANT( 1 )
  25568. #if defined(MBEDTLS_DEPRECATED_WARNING)
  25569. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  25570. #else
  25571. #define MBEDTLS_DEPRECATED
  25572. #endif /* MBEDTLS_DEPRECATED_WARNING */
  25573. MBEDTLS_DEPRECATED extern int (*mbedtls_ssl_hw_record_init)(
  25574. mbedtls_ssl_context *ssl,
  25575. const unsigned char *key_enc, const unsigned char *key_dec,
  25576. size_t keylen,
  25577. const unsigned char *iv_enc, const unsigned char *iv_dec,
  25578. size_t ivlen,
  25579. const unsigned char *mac_enc, const unsigned char *mac_dec,
  25580. size_t maclen);
  25581. MBEDTLS_DEPRECATED extern int (*mbedtls_ssl_hw_record_activate)(
  25582. mbedtls_ssl_context *ssl,
  25583. int direction );
  25584. MBEDTLS_DEPRECATED extern int (*mbedtls_ssl_hw_record_reset)(
  25585. mbedtls_ssl_context *ssl );
  25586. MBEDTLS_DEPRECATED extern int (*mbedtls_ssl_hw_record_write)(
  25587. mbedtls_ssl_context *ssl );
  25588. MBEDTLS_DEPRECATED extern int (*mbedtls_ssl_hw_record_read)(
  25589. mbedtls_ssl_context *ssl );
  25590. MBEDTLS_DEPRECATED extern int (*mbedtls_ssl_hw_record_finish)(
  25591. mbedtls_ssl_context *ssl );
  25592. #undef MBEDTLS_DEPRECATED
  25593. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  25594. #endif /* MBEDTLS_SSL_HW_RECORD_ACCEL */
  25595. /**
  25596. * \brief Return the name of the ciphersuite associated with the
  25597. * given ID
  25598. *
  25599. * \param ciphersuite_id SSL ciphersuite ID
  25600. *
  25601. * \return a string containing the ciphersuite name
  25602. */
  25603. const char *mbedtls_ssl_get_ciphersuite_name( const int ciphersuite_id );
  25604. /**
  25605. * \brief Return the ID of the ciphersuite associated with the
  25606. * given name
  25607. *
  25608. * \param ciphersuite_name SSL ciphersuite name
  25609. *
  25610. * \return the ID with the ciphersuite or 0 if not found
  25611. */
  25612. int mbedtls_ssl_get_ciphersuite_id( const char *ciphersuite_name );
  25613. /**
  25614. * \brief Initialize an SSL context
  25615. * Just makes the context ready for mbedtls_ssl_setup() or
  25616. * mbedtls_ssl_free()
  25617. *
  25618. * \param ssl SSL context
  25619. */
  25620. void mbedtls_ssl_init( mbedtls_ssl_context *ssl );
  25621. /**
  25622. * \brief Set up an SSL context for use
  25623. *
  25624. * \note No copy of the configuration context is made, it can be
  25625. * shared by many mbedtls_ssl_context structures.
  25626. *
  25627. * \warning The conf structure will be accessed during the session.
  25628. * It must not be modified or freed as long as the session
  25629. * is active.
  25630. *
  25631. * \warning This function must be called exactly once per context.
  25632. * Calling mbedtls_ssl_setup again is not supported, even
  25633. * if no session is active.
  25634. *
  25635. * \param ssl SSL context
  25636. * \param conf SSL configuration to use
  25637. *
  25638. * \return 0 if successful, or MBEDTLS_ERR_SSL_ALLOC_FAILED if
  25639. * memory allocation failed
  25640. */
  25641. int mbedtls_ssl_setup( mbedtls_ssl_context *ssl,
  25642. const mbedtls_ssl_config *conf );
  25643. /**
  25644. * \brief Reset an already initialized SSL context for re-use
  25645. * while retaining application-set variables, function
  25646. * pointers and data.
  25647. *
  25648. * \param ssl SSL context
  25649. * \return 0 if successful, or MBEDTLS_ERR_SSL_ALLOC_FAILED,
  25650. MBEDTLS_ERR_SSL_HW_ACCEL_FAILED or
  25651. * MBEDTLS_ERR_SSL_COMPRESSION_FAILED
  25652. */
  25653. int mbedtls_ssl_session_reset( mbedtls_ssl_context *ssl );
  25654. /**
  25655. * \brief Set the current endpoint type
  25656. *
  25657. * \param conf SSL configuration
  25658. * \param endpoint must be MBEDTLS_SSL_IS_CLIENT or MBEDTLS_SSL_IS_SERVER
  25659. */
  25660. void mbedtls_ssl_conf_endpoint( mbedtls_ssl_config *conf, int endpoint );
  25661. /**
  25662. * \brief Set the transport type (TLS or DTLS).
  25663. * Default: TLS
  25664. *
  25665. * \note For DTLS, you must either provide a recv callback that
  25666. * doesn't block, or one that handles timeouts, see
  25667. * \c mbedtls_ssl_set_bio(). You also need to provide timer
  25668. * callbacks with \c mbedtls_ssl_set_timer_cb().
  25669. *
  25670. * \param conf SSL configuration
  25671. * \param transport transport type:
  25672. * MBEDTLS_SSL_TRANSPORT_STREAM for TLS,
  25673. * MBEDTLS_SSL_TRANSPORT_DATAGRAM for DTLS.
  25674. */
  25675. void mbedtls_ssl_conf_transport( mbedtls_ssl_config *conf, int transport );
  25676. /**
  25677. * \brief Set the certificate verification mode
  25678. * Default: NONE on server, REQUIRED on client
  25679. *
  25680. * \param conf SSL configuration
  25681. * \param authmode can be:
  25682. *
  25683. * MBEDTLS_SSL_VERIFY_NONE: peer certificate is not checked
  25684. * (default on server)
  25685. * (insecure on client)
  25686. *
  25687. * MBEDTLS_SSL_VERIFY_OPTIONAL: peer certificate is checked, however the
  25688. * handshake continues even if verification failed;
  25689. * mbedtls_ssl_get_verify_result() can be called after the
  25690. * handshake is complete.
  25691. *
  25692. * MBEDTLS_SSL_VERIFY_REQUIRED: peer *must* present a valid certificate,
  25693. * handshake is aborted if verification failed.
  25694. * (default on client)
  25695. *
  25696. * \note On client, MBEDTLS_SSL_VERIFY_REQUIRED is the recommended mode.
  25697. * With MBEDTLS_SSL_VERIFY_OPTIONAL, the user needs to call mbedtls_ssl_get_verify_result() at
  25698. * the right time(s), which may not be obvious, while REQUIRED always perform
  25699. * the verification as soon as possible. For example, REQUIRED was protecting
  25700. * against the "triple handshake" attack even before it was found.
  25701. */
  25702. void mbedtls_ssl_conf_authmode( mbedtls_ssl_config *conf, int authmode );
  25703. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  25704. /**
  25705. * \brief Set the verification callback (Optional).
  25706. *
  25707. * If set, the provided verify callback is called for each
  25708. * certificate in the peer's CRT chain, including the trusted
  25709. * root. For more information, please see the documentation of
  25710. * \c mbedtls_x509_crt_verify().
  25711. *
  25712. * \note For per context callbacks and contexts, please use
  25713. * mbedtls_ssl_set_verify() instead.
  25714. *
  25715. * \param conf The SSL configuration to use.
  25716. * \param f_vrfy The verification callback to use during CRT verification.
  25717. * \param p_vrfy The opaque context to be passed to the callback.
  25718. */
  25719. void mbedtls_ssl_conf_verify( mbedtls_ssl_config *conf,
  25720. int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *),
  25721. void *p_vrfy );
  25722. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  25723. /**
  25724. * \brief Set the random number generator callback
  25725. *
  25726. * \param conf SSL configuration
  25727. * \param f_rng RNG function
  25728. * \param p_rng RNG parameter
  25729. */
  25730. void mbedtls_ssl_conf_rng( mbedtls_ssl_config *conf,
  25731. int (*f_rng)(void *, unsigned char *, size_t),
  25732. void *p_rng );
  25733. /**
  25734. * \brief Set the debug callback
  25735. *
  25736. * The callback has the following argument:
  25737. * void * opaque context for the callback
  25738. * int debug level
  25739. * const char * file name
  25740. * int line number
  25741. * const char * message
  25742. *
  25743. * \param conf SSL configuration
  25744. * \param f_dbg debug function
  25745. * \param p_dbg debug parameter
  25746. */
  25747. void mbedtls_ssl_conf_dbg( mbedtls_ssl_config *conf,
  25748. void (*f_dbg)(void *, int, const char *, int, const char *),
  25749. void *p_dbg );
  25750. /**
  25751. * \brief Set the underlying BIO callbacks for write, read and
  25752. * read-with-timeout.
  25753. *
  25754. * \param ssl SSL context
  25755. * \param p_bio parameter (context) shared by BIO callbacks
  25756. * \param f_send write callback
  25757. * \param f_recv read callback
  25758. * \param f_recv_timeout blocking read callback with timeout.
  25759. *
  25760. * \note One of f_recv or f_recv_timeout can be NULL, in which case
  25761. * the other is used. If both are non-NULL, f_recv_timeout is
  25762. * used and f_recv is ignored (as if it were NULL).
  25763. *
  25764. * \note The two most common use cases are:
  25765. * - non-blocking I/O, f_recv != NULL, f_recv_timeout == NULL
  25766. * - blocking I/O, f_recv == NULL, f_recv_timout != NULL
  25767. *
  25768. * \note For DTLS, you need to provide either a non-NULL
  25769. * f_recv_timeout callback, or a f_recv that doesn't block.
  25770. *
  25771. * \note See the documentations of \c mbedtls_ssl_send_t,
  25772. * \c mbedtls_ssl_recv_t and \c mbedtls_ssl_recv_timeout_t for
  25773. * the conventions those callbacks must follow.
  25774. *
  25775. * \note On some platforms, net_sockets.c provides
  25776. * \c mbedtls_net_send(), \c mbedtls_net_recv() and
  25777. * \c mbedtls_net_recv_timeout() that are suitable to be used
  25778. * here.
  25779. */
  25780. void mbedtls_ssl_set_bio( mbedtls_ssl_context *ssl,
  25781. void *p_bio,
  25782. mbedtls_ssl_send_t *f_send,
  25783. mbedtls_ssl_recv_t *f_recv,
  25784. mbedtls_ssl_recv_timeout_t *f_recv_timeout );
  25785. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  25786. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  25787. /**
  25788. * \brief Configure the use of the Connection ID (CID)
  25789. * extension in the next handshake.
  25790. *
  25791. * Reference: draft-ietf-tls-dtls-connection-id-05
  25792. * https://tools.ietf.org/html/draft-ietf-tls-dtls-connection-id-05
  25793. *
  25794. * The DTLS CID extension allows the reliable association of
  25795. * DTLS records to DTLS connections across changes in the
  25796. * underlying transport (changed IP and Port metadata) by
  25797. * adding explicit connection identifiers (CIDs) to the
  25798. * headers of encrypted DTLS records. The desired CIDs are
  25799. * configured by the application layer and are exchanged in
  25800. * new `ClientHello` / `ServerHello` extensions during the
  25801. * handshake, where each side indicates the CID it wants the
  25802. * peer to use when writing encrypted messages. The CIDs are
  25803. * put to use once records get encrypted: the stack discards
  25804. * any incoming records that don't include the configured CID
  25805. * in their header, and adds the peer's requested CID to the
  25806. * headers of outgoing messages.
  25807. *
  25808. * This API enables or disables the use of the CID extension
  25809. * in the next handshake and sets the value of the CID to
  25810. * be used for incoming messages.
  25811. *
  25812. * \param ssl The SSL context to configure. This must be initialized.
  25813. * \param enable This value determines whether the CID extension should
  25814. * be used or not. Possible values are:
  25815. * - MBEDTLS_SSL_CID_ENABLED to enable the use of the CID.
  25816. * - MBEDTLS_SSL_CID_DISABLED (default) to disable the use
  25817. * of the CID.
  25818. * \param own_cid The address of the readable buffer holding the CID we want
  25819. * the peer to use when sending encrypted messages to us.
  25820. * This may be \c NULL if \p own_cid_len is \c 0.
  25821. * This parameter is unused if \p enabled is set to
  25822. * MBEDTLS_SSL_CID_DISABLED.
  25823. * \param own_cid_len The length of \p own_cid.
  25824. * This parameter is unused if \p enabled is set to
  25825. * MBEDTLS_SSL_CID_DISABLED.
  25826. *
  25827. * \note The value of \p own_cid_len must match the value of the
  25828. * \c len parameter passed to mbedtls_ssl_conf_cid()
  25829. * when configuring the ::mbedtls_ssl_config that \p ssl
  25830. * is bound to.
  25831. *
  25832. * \note This CID configuration applies to subsequent handshakes
  25833. * performed on the SSL context \p ssl, but does not trigger
  25834. * one. You still have to call `mbedtls_ssl_handshake()`
  25835. * (for the initial handshake) or `mbedtls_ssl_renegotiate()`
  25836. * (for a renegotiation handshake) explicitly after a
  25837. * successful call to this function to run the handshake.
  25838. *
  25839. * \note This call cannot guarantee that the use of the CID
  25840. * will be successfully negotiated in the next handshake,
  25841. * because the peer might not support it. Specifically:
  25842. * - On the Client, enabling the use of the CID through
  25843. * this call implies that the `ClientHello` in the next
  25844. * handshake will include the CID extension, thereby
  25845. * offering the use of the CID to the server. Only if
  25846. * the `ServerHello` contains the CID extension, too,
  25847. * the CID extension will actually be put to use.
  25848. * - On the Server, enabling the use of the CID through
  25849. * this call implies that that the server will look for
  25850. * the CID extension in a `ClientHello` from the client,
  25851. * and, if present, reply with a CID extension in its
  25852. * `ServerHello`.
  25853. *
  25854. * \note To check whether the use of the CID was negotiated
  25855. * after the subsequent handshake has completed, please
  25856. * use the API mbedtls_ssl_get_peer_cid().
  25857. *
  25858. * \warning If the use of the CID extension is enabled in this call
  25859. * and the subsequent handshake negotiates its use, Mbed TLS
  25860. * will silently drop every packet whose CID does not match
  25861. * the CID configured in \p own_cid. It is the responsibility
  25862. * of the user to adapt the underlying transport to take care
  25863. * of CID-based demultiplexing before handing datagrams to
  25864. * Mbed TLS.
  25865. *
  25866. * \return \c 0 on success. In this case, the CID configuration
  25867. * applies to the next handshake.
  25868. * \return A negative error code on failure.
  25869. */
  25870. int mbedtls_ssl_set_cid( mbedtls_ssl_context *ssl,
  25871. int enable,
  25872. unsigned char const *own_cid,
  25873. size_t own_cid_len );
  25874. /**
  25875. * \brief Get information about the use of the CID extension
  25876. * in the current connection.
  25877. *
  25878. * \param ssl The SSL context to query.
  25879. * \param enabled The address at which to store whether the CID extension
  25880. * is currently in use or not. If the CID is in use,
  25881. * `*enabled` is set to MBEDTLS_SSL_CID_ENABLED;
  25882. * otherwise, it is set to MBEDTLS_SSL_CID_DISABLED.
  25883. * \param peer_cid The address of the buffer in which to store the CID
  25884. * chosen by the peer (if the CID extension is used).
  25885. * This may be \c NULL in case the value of peer CID
  25886. * isn't needed. If it is not \c NULL, \p peer_cid_len
  25887. * must not be \c NULL.
  25888. * \param peer_cid_len The address at which to store the size of the CID
  25889. * chosen by the peer (if the CID extension is used).
  25890. * This is also the number of Bytes in \p peer_cid that
  25891. * have been written.
  25892. * This may be \c NULL in case the length of the peer CID
  25893. * isn't needed. If it is \c NULL, \p peer_cid must be
  25894. * \c NULL, too.
  25895. *
  25896. * \note This applies to the state of the CID negotiated in
  25897. * the last complete handshake. If a handshake is in
  25898. * progress, this function will attempt to complete
  25899. * the handshake first.
  25900. *
  25901. * \note If CID extensions have been exchanged but both client
  25902. * and server chose to use an empty CID, this function
  25903. * sets `*enabled` to #MBEDTLS_SSL_CID_DISABLED
  25904. * (the rationale for this is that the resulting
  25905. * communication is the same as if the CID extensions
  25906. * hadn't been used).
  25907. *
  25908. * \return \c 0 on success.
  25909. * \return A negative error code on failure.
  25910. */
  25911. int mbedtls_ssl_get_peer_cid( mbedtls_ssl_context *ssl,
  25912. int *enabled,
  25913. unsigned char peer_cid[ MBEDTLS_SSL_CID_OUT_LEN_MAX ],
  25914. size_t *peer_cid_len );
  25915. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  25916. /**
  25917. * \brief Set the Maximum Tranport Unit (MTU).
  25918. * Special value: 0 means unset (no limit).
  25919. * This represents the maximum size of a datagram payload
  25920. * handled by the transport layer (usually UDP) as determined
  25921. * by the network link and stack. In practice, this controls
  25922. * the maximum size datagram the DTLS layer will pass to the
  25923. * \c f_send() callback set using \c mbedtls_ssl_set_bio().
  25924. *
  25925. * \note The limit on datagram size is converted to a limit on
  25926. * record payload by subtracting the current overhead of
  25927. * encapsulation and encryption/authentication if any.
  25928. *
  25929. * \note This can be called at any point during the connection, for
  25930. * example when a Path Maximum Transfer Unit (PMTU)
  25931. * estimate becomes available from other sources,
  25932. * such as lower (or higher) protocol layers.
  25933. *
  25934. * \note This setting only controls the size of the packets we send,
  25935. * and does not restrict the size of the datagrams we're
  25936. * willing to receive. Client-side, you can request the
  25937. * server to use smaller records with \c
  25938. * mbedtls_ssl_conf_max_frag_len().
  25939. *
  25940. * \note If both a MTU and a maximum fragment length have been
  25941. * configured (or negotiated with the peer), the resulting
  25942. * lower limit on record payload (see first note) is used.
  25943. *
  25944. * \note This can only be used to decrease the maximum size
  25945. * of datagrams (hence records, see first note) sent. It
  25946. * cannot be used to increase the maximum size of records over
  25947. * the limit set by #MBEDTLS_SSL_OUT_CONTENT_LEN.
  25948. *
  25949. * \note Values lower than the current record layer expansion will
  25950. * result in an error when trying to send data.
  25951. *
  25952. * \note Using record compression together with a non-zero MTU value
  25953. * will result in an error when trying to send data.
  25954. *
  25955. * \param ssl SSL context
  25956. * \param mtu Value of the path MTU in bytes
  25957. */
  25958. void mbedtls_ssl_set_mtu( mbedtls_ssl_context *ssl, uint16_t mtu );
  25959. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  25960. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  25961. /**
  25962. * \brief Set a connection-specific verification callback (optional).
  25963. *
  25964. * If set, the provided verify callback is called for each
  25965. * certificate in the peer's CRT chain, including the trusted
  25966. * root. For more information, please see the documentation of
  25967. * \c mbedtls_x509_crt_verify().
  25968. *
  25969. * \note This call is analogous to mbedtls_ssl_conf_verify() but
  25970. * binds the verification callback and context to an SSL context
  25971. * as opposed to an SSL configuration.
  25972. * If mbedtls_ssl_conf_verify() and mbedtls_ssl_set_verify()
  25973. * are both used, mbedtls_ssl_set_verify() takes precedence.
  25974. *
  25975. * \param ssl The SSL context to use.
  25976. * \param f_vrfy The verification callback to use during CRT verification.
  25977. * \param p_vrfy The opaque context to be passed to the callback.
  25978. */
  25979. void mbedtls_ssl_set_verify( mbedtls_ssl_context *ssl,
  25980. int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *),
  25981. void *p_vrfy );
  25982. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  25983. /**
  25984. * \brief Set the timeout period for mbedtls_ssl_read()
  25985. * (Default: no timeout.)
  25986. *
  25987. * \param conf SSL configuration context
  25988. * \param timeout Timeout value in milliseconds.
  25989. * Use 0 for no timeout (default).
  25990. *
  25991. * \note With blocking I/O, this will only work if a non-NULL
  25992. * \c f_recv_timeout was set with \c mbedtls_ssl_set_bio().
  25993. * With non-blocking I/O, this will only work if timer
  25994. * callbacks were set with \c mbedtls_ssl_set_timer_cb().
  25995. *
  25996. * \note With non-blocking I/O, you may also skip this function
  25997. * altogether and handle timeouts at the application layer.
  25998. */
  25999. void mbedtls_ssl_conf_read_timeout( mbedtls_ssl_config *conf, uint32_t timeout );
  26000. #if defined(MBEDTLS_SSL_RECORD_CHECKING)
  26001. /**
  26002. * \brief Check whether a buffer contains a valid and authentic record
  26003. * that has not been seen before. (DTLS only).
  26004. *
  26005. * This function does not change the user-visible state
  26006. * of the SSL context. Its sole purpose is to provide
  26007. * an indication of the legitimacy of an incoming record.
  26008. *
  26009. * This can be useful e.g. in distributed server environments
  26010. * using the DTLS Connection ID feature, in which connections
  26011. * might need to be passed between service instances on a change
  26012. * of peer address, but where such disruptive operations should
  26013. * only happen after the validity of incoming records has been
  26014. * confirmed.
  26015. *
  26016. * \param ssl The SSL context to use.
  26017. * \param buf The address of the buffer holding the record to be checked.
  26018. * This must be a read/write buffer of length \p buflen Bytes.
  26019. * \param buflen The length of \p buf in Bytes.
  26020. *
  26021. * \note This routine only checks whether the provided buffer begins
  26022. * with a valid and authentic record that has not been seen
  26023. * before, but does not check potential data following the
  26024. * initial record. In particular, it is possible to pass DTLS
  26025. * datagrams containing multiple records, in which case only
  26026. * the first record is checked.
  26027. *
  26028. * \note This function modifies the input buffer \p buf. If you need
  26029. * to preserve the original record, you have to maintain a copy.
  26030. *
  26031. * \return \c 0 if the record is valid and authentic and has not been
  26032. * seen before.
  26033. * \return MBEDTLS_ERR_SSL_INVALID_MAC if the check completed
  26034. * successfully but the record was found to be not authentic.
  26035. * \return MBEDTLS_ERR_SSL_INVALID_RECORD if the check completed
  26036. * successfully but the record was found to be invalid for
  26037. * a reason different from authenticity checking.
  26038. * \return MBEDTLS_ERR_SSL_UNEXPECTED_RECORD if the check completed
  26039. * successfully but the record was found to be unexpected
  26040. * in the state of the SSL context, including replayed records.
  26041. * \return Another negative error code on different kinds of failure.
  26042. * In this case, the SSL context becomes unusable and needs
  26043. * to be freed or reset before reuse.
  26044. */
  26045. int mbedtls_ssl_check_record( mbedtls_ssl_context const *ssl,
  26046. unsigned char *buf,
  26047. size_t buflen );
  26048. #endif /* MBEDTLS_SSL_RECORD_CHECKING */
  26049. /**
  26050. * \brief Set the timer callbacks (Mandatory for DTLS.)
  26051. *
  26052. * \param ssl SSL context
  26053. * \param p_timer parameter (context) shared by timer callbacks
  26054. * \param f_set_timer set timer callback
  26055. * \param f_get_timer get timer callback. Must return:
  26056. *
  26057. * \note See the documentation of \c mbedtls_ssl_set_timer_t and
  26058. * \c mbedtls_ssl_get_timer_t for the conventions this pair of
  26059. * callbacks must follow.
  26060. *
  26061. * \note On some platforms, timing.c provides
  26062. * \c mbedtls_timing_set_delay() and
  26063. * \c mbedtls_timing_get_delay() that are suitable for using
  26064. * here, except if using an event-driven style.
  26065. *
  26066. * \note See also the "DTLS tutorial" article in our knowledge base.
  26067. * https://tls.mbed.org/kb/how-to/dtls-tutorial
  26068. */
  26069. void mbedtls_ssl_set_timer_cb( mbedtls_ssl_context *ssl,
  26070. void *p_timer,
  26071. mbedtls_ssl_set_timer_t *f_set_timer,
  26072. mbedtls_ssl_get_timer_t *f_get_timer );
  26073. /**
  26074. * \brief Callback type: generate and write session ticket
  26075. *
  26076. * \note This describes what a callback implementation should do.
  26077. * This callback should generate an encrypted and
  26078. * authenticated ticket for the session and write it to the
  26079. * output buffer. Here, ticket means the opaque ticket part
  26080. * of the NewSessionTicket structure of RFC 5077.
  26081. *
  26082. * \param p_ticket Context for the callback
  26083. * \param session SSL session to be written in the ticket
  26084. * \param start Start of the output buffer
  26085. * \param end End of the output buffer
  26086. * \param tlen On exit, holds the length written
  26087. * \param lifetime On exit, holds the lifetime of the ticket in seconds
  26088. *
  26089. * \return 0 if successful, or
  26090. * a specific MBEDTLS_ERR_XXX code.
  26091. */
  26092. typedef int mbedtls_ssl_ticket_write_t( void *p_ticket,
  26093. const mbedtls_ssl_session *session,
  26094. unsigned char *start,
  26095. const unsigned char *end,
  26096. size_t *tlen,
  26097. uint32_t *lifetime );
  26098. #if defined(MBEDTLS_SSL_EXPORT_KEYS)
  26099. /**
  26100. * \brief Callback type: Export key block and master secret
  26101. *
  26102. * \note This is required for certain uses of TLS, e.g. EAP-TLS
  26103. * (RFC 5216) and Thread. The key pointers are ephemeral and
  26104. * therefore must not be stored. The master secret and keys
  26105. * should not be used directly except as an input to a key
  26106. * derivation function.
  26107. *
  26108. * \param p_expkey Context for the callback
  26109. * \param ms Pointer to master secret (fixed length: 48 bytes)
  26110. * \param kb Pointer to key block, see RFC 5246 section 6.3
  26111. * (variable length: 2 * maclen + 2 * keylen + 2 * ivlen).
  26112. * \param maclen MAC length
  26113. * \param keylen Key length
  26114. * \param ivlen IV length
  26115. *
  26116. * \return 0 if successful, or
  26117. * a specific MBEDTLS_ERR_XXX code.
  26118. */
  26119. typedef int mbedtls_ssl_export_keys_t( void *p_expkey,
  26120. const unsigned char *ms,
  26121. const unsigned char *kb,
  26122. size_t maclen,
  26123. size_t keylen,
  26124. size_t ivlen );
  26125. /**
  26126. * \brief Callback type: Export key block, master secret,
  26127. * handshake randbytes and the tls_prf function
  26128. * used to derive keys.
  26129. *
  26130. * \note This is required for certain uses of TLS, e.g. EAP-TLS
  26131. * (RFC 5216) and Thread. The key pointers are ephemeral and
  26132. * therefore must not be stored. The master secret and keys
  26133. * should not be used directly except as an input to a key
  26134. * derivation function.
  26135. *
  26136. * \param p_expkey Context for the callback.
  26137. * \param ms Pointer to master secret (fixed length: 48 bytes).
  26138. * \param kb Pointer to key block, see RFC 5246 section 6.3.
  26139. * (variable length: 2 * maclen + 2 * keylen + 2 * ivlen).
  26140. * \param maclen MAC length.
  26141. * \param keylen Key length.
  26142. * \param ivlen IV length.
  26143. * \param client_random The client random bytes.
  26144. * \param server_random The server random bytes.
  26145. * \param tls_prf_type The tls_prf enum type.
  26146. *
  26147. * \return 0 if successful, or
  26148. * a specific MBEDTLS_ERR_XXX code.
  26149. */
  26150. typedef int mbedtls_ssl_export_keys_ext_t( void *p_expkey,
  26151. const unsigned char *ms,
  26152. const unsigned char *kb,
  26153. size_t maclen,
  26154. size_t keylen,
  26155. size_t ivlen,
  26156. const unsigned char client_random[32],
  26157. const unsigned char server_random[32],
  26158. mbedtls_tls_prf_types tls_prf_type );
  26159. #endif /* MBEDTLS_SSL_EXPORT_KEYS */
  26160. /**
  26161. * \brief Callback type: parse and load session ticket
  26162. *
  26163. * \note This describes what a callback implementation should do.
  26164. * This callback should parse a session ticket as generated
  26165. * by the corresponding mbedtls_ssl_ticket_write_t function,
  26166. * and, if the ticket is authentic and valid, load the
  26167. * session.
  26168. *
  26169. * \note The implementation is allowed to modify the first len
  26170. * bytes of the input buffer, eg to use it as a temporary
  26171. * area for the decrypted ticket contents.
  26172. *
  26173. * \param p_ticket Context for the callback
  26174. * \param session SSL session to be loaded
  26175. * \param buf Start of the buffer containing the ticket
  26176. * \param len Length of the ticket.
  26177. *
  26178. * \return 0 if successful, or
  26179. * MBEDTLS_ERR_SSL_INVALID_MAC if not authentic, or
  26180. * MBEDTLS_ERR_SSL_SESSION_TICKET_EXPIRED if expired, or
  26181. * any other non-zero code for other failures.
  26182. */
  26183. typedef int mbedtls_ssl_ticket_parse_t( void *p_ticket,
  26184. mbedtls_ssl_session *session,
  26185. unsigned char *buf,
  26186. size_t len );
  26187. #if defined(MBEDTLS_SSL_SESSION_TICKETS) && defined(MBEDTLS_SSL_SRV_C)
  26188. /**
  26189. * \brief Configure SSL session ticket callbacks (server only).
  26190. * (Default: none.)
  26191. *
  26192. * \note On server, session tickets are enabled by providing
  26193. * non-NULL callbacks.
  26194. *
  26195. * \note On client, use \c mbedtls_ssl_conf_session_tickets().
  26196. *
  26197. * \param conf SSL configuration context
  26198. * \param f_ticket_write Callback for writing a ticket
  26199. * \param f_ticket_parse Callback for parsing a ticket
  26200. * \param p_ticket Context shared by the two callbacks
  26201. */
  26202. void mbedtls_ssl_conf_session_tickets_cb( mbedtls_ssl_config *conf,
  26203. mbedtls_ssl_ticket_write_t *f_ticket_write,
  26204. mbedtls_ssl_ticket_parse_t *f_ticket_parse,
  26205. void *p_ticket );
  26206. #endif /* MBEDTLS_SSL_SESSION_TICKETS && MBEDTLS_SSL_SRV_C */
  26207. #if defined(MBEDTLS_SSL_EXPORT_KEYS)
  26208. /**
  26209. * \brief Configure key export callback.
  26210. * (Default: none.)
  26211. *
  26212. * \note See \c mbedtls_ssl_export_keys_t.
  26213. *
  26214. * \param conf SSL configuration context
  26215. * \param f_export_keys Callback for exporting keys
  26216. * \param p_export_keys Context for the callback
  26217. */
  26218. void mbedtls_ssl_conf_export_keys_cb( mbedtls_ssl_config *conf,
  26219. mbedtls_ssl_export_keys_t *f_export_keys,
  26220. void *p_export_keys );
  26221. /**
  26222. * \brief Configure extended key export callback.
  26223. * (Default: none.)
  26224. *
  26225. * \note See \c mbedtls_ssl_export_keys_ext_t.
  26226. * \warning Exported key material must not be used for any purpose
  26227. * before the (D)TLS handshake is completed
  26228. *
  26229. * \param conf SSL configuration context
  26230. * \param f_export_keys_ext Callback for exporting keys
  26231. * \param p_export_keys Context for the callback
  26232. */
  26233. void mbedtls_ssl_conf_export_keys_ext_cb( mbedtls_ssl_config *conf,
  26234. mbedtls_ssl_export_keys_ext_t *f_export_keys_ext,
  26235. void *p_export_keys );
  26236. #endif /* MBEDTLS_SSL_EXPORT_KEYS */
  26237. #if defined(MBEDTLS_SSL_ASYNC_PRIVATE)
  26238. /**
  26239. * \brief Configure asynchronous private key operation callbacks.
  26240. *
  26241. * \param conf SSL configuration context
  26242. * \param f_async_sign Callback to start a signature operation. See
  26243. * the description of ::mbedtls_ssl_async_sign_t
  26244. * for more information. This may be \c NULL if the
  26245. * external processor does not support any signature
  26246. * operation; in this case the private key object
  26247. * associated with the certificate will be used.
  26248. * \param f_async_decrypt Callback to start a decryption operation. See
  26249. * the description of ::mbedtls_ssl_async_decrypt_t
  26250. * for more information. This may be \c NULL if the
  26251. * external processor does not support any decryption
  26252. * operation; in this case the private key object
  26253. * associated with the certificate will be used.
  26254. * \param f_async_resume Callback to resume an asynchronous operation. See
  26255. * the description of ::mbedtls_ssl_async_resume_t
  26256. * for more information. This may not be \c NULL unless
  26257. * \p f_async_sign and \p f_async_decrypt are both
  26258. * \c NULL.
  26259. * \param f_async_cancel Callback to cancel an asynchronous operation. See
  26260. * the description of ::mbedtls_ssl_async_cancel_t
  26261. * for more information. This may be \c NULL if
  26262. * no cleanup is needed.
  26263. * \param config_data A pointer to configuration data which can be
  26264. * retrieved with
  26265. * mbedtls_ssl_conf_get_async_config_data(). The
  26266. * library stores this value without dereferencing it.
  26267. */
  26268. void mbedtls_ssl_conf_async_private_cb( mbedtls_ssl_config *conf,
  26269. mbedtls_ssl_async_sign_t *f_async_sign,
  26270. mbedtls_ssl_async_decrypt_t *f_async_decrypt,
  26271. mbedtls_ssl_async_resume_t *f_async_resume,
  26272. mbedtls_ssl_async_cancel_t *f_async_cancel,
  26273. void *config_data );
  26274. /**
  26275. * \brief Retrieve the configuration data set by
  26276. * mbedtls_ssl_conf_async_private_cb().
  26277. *
  26278. * \param conf SSL configuration context
  26279. * \return The configuration data set by
  26280. * mbedtls_ssl_conf_async_private_cb().
  26281. */
  26282. void *mbedtls_ssl_conf_get_async_config_data( const mbedtls_ssl_config *conf );
  26283. /**
  26284. * \brief Retrieve the asynchronous operation user context.
  26285. *
  26286. * \note This function may only be called while a handshake
  26287. * is in progress.
  26288. *
  26289. * \param ssl The SSL context to access.
  26290. *
  26291. * \return The asynchronous operation user context that was last
  26292. * set during the current handshake. If
  26293. * mbedtls_ssl_set_async_operation_data() has not yet been
  26294. * called during the current handshake, this function returns
  26295. * \c NULL.
  26296. */
  26297. void *mbedtls_ssl_get_async_operation_data( const mbedtls_ssl_context *ssl );
  26298. /**
  26299. * \brief Retrieve the asynchronous operation user context.
  26300. *
  26301. * \note This function may only be called while a handshake
  26302. * is in progress.
  26303. *
  26304. * \param ssl The SSL context to access.
  26305. * \param ctx The new value of the asynchronous operation user context.
  26306. * Call mbedtls_ssl_get_async_operation_data() later during the
  26307. * same handshake to retrieve this value.
  26308. */
  26309. void mbedtls_ssl_set_async_operation_data( mbedtls_ssl_context *ssl,
  26310. void *ctx );
  26311. #endif /* MBEDTLS_SSL_ASYNC_PRIVATE */
  26312. /**
  26313. * \brief Callback type: generate a cookie
  26314. *
  26315. * \param ctx Context for the callback
  26316. * \param p Buffer to write to,
  26317. * must be updated to point right after the cookie
  26318. * \param end Pointer to one past the end of the output buffer
  26319. * \param info Client ID info that was passed to
  26320. * \c mbedtls_ssl_set_client_transport_id()
  26321. * \param ilen Length of info in bytes
  26322. *
  26323. * \return The callback must return 0 on success,
  26324. * or a negative error code.
  26325. */
  26326. typedef int mbedtls_ssl_cookie_write_t( void *ctx,
  26327. unsigned char **p, unsigned char *end,
  26328. const unsigned char *info, size_t ilen );
  26329. /**
  26330. * \brief Callback type: verify a cookie
  26331. *
  26332. * \param ctx Context for the callback
  26333. * \param cookie Cookie to verify
  26334. * \param clen Length of cookie
  26335. * \param info Client ID info that was passed to
  26336. * \c mbedtls_ssl_set_client_transport_id()
  26337. * \param ilen Length of info in bytes
  26338. *
  26339. * \return The callback must return 0 if cookie is valid,
  26340. * or a negative error code.
  26341. */
  26342. typedef int mbedtls_ssl_cookie_check_t( void *ctx,
  26343. const unsigned char *cookie, size_t clen,
  26344. const unsigned char *info, size_t ilen );
  26345. #if defined(MBEDTLS_SSL_DTLS_HELLO_VERIFY) && defined(MBEDTLS_SSL_SRV_C)
  26346. /**
  26347. * \brief Register callbacks for DTLS cookies
  26348. * (Server only. DTLS only.)
  26349. *
  26350. * Default: dummy callbacks that fail, in order to force you to
  26351. * register working callbacks (and initialize their context).
  26352. *
  26353. * To disable HelloVerifyRequest, register NULL callbacks.
  26354. *
  26355. * \warning Disabling hello verification allows your server to be used
  26356. * for amplification in DoS attacks against other hosts.
  26357. * Only disable if you known this can't happen in your
  26358. * particular environment.
  26359. *
  26360. * \note See comments on \c mbedtls_ssl_handshake() about handling
  26361. * the MBEDTLS_ERR_SSL_HELLO_VERIFY_REQUIRED that is expected
  26362. * on the first handshake attempt when this is enabled.
  26363. *
  26364. * \note This is also necessary to handle client reconnection from
  26365. * the same port as described in RFC 6347 section 4.2.8 (only
  26366. * the variant with cookies is supported currently). See
  26367. * comments on \c mbedtls_ssl_read() for details.
  26368. *
  26369. * \param conf SSL configuration
  26370. * \param f_cookie_write Cookie write callback
  26371. * \param f_cookie_check Cookie check callback
  26372. * \param p_cookie Context for both callbacks
  26373. */
  26374. void mbedtls_ssl_conf_dtls_cookies( mbedtls_ssl_config *conf,
  26375. mbedtls_ssl_cookie_write_t *f_cookie_write,
  26376. mbedtls_ssl_cookie_check_t *f_cookie_check,
  26377. void *p_cookie );
  26378. /**
  26379. * \brief Set client's transport-level identification info.
  26380. * (Server only. DTLS only.)
  26381. *
  26382. * This is usually the IP address (and port), but could be
  26383. * anything identify the client depending on the underlying
  26384. * network stack. Used for HelloVerifyRequest with DTLS.
  26385. * This is *not* used to route the actual packets.
  26386. *
  26387. * \param ssl SSL context
  26388. * \param info Transport-level info identifying the client (eg IP + port)
  26389. * \param ilen Length of info in bytes
  26390. *
  26391. * \note An internal copy is made, so the info buffer can be reused.
  26392. *
  26393. * \return 0 on success,
  26394. * MBEDTLS_ERR_SSL_BAD_INPUT_DATA if used on client,
  26395. * MBEDTLS_ERR_SSL_ALLOC_FAILED if out of memory.
  26396. */
  26397. int mbedtls_ssl_set_client_transport_id( mbedtls_ssl_context *ssl,
  26398. const unsigned char *info,
  26399. size_t ilen );
  26400. #endif /* MBEDTLS_SSL_DTLS_HELLO_VERIFY && MBEDTLS_SSL_SRV_C */
  26401. #if defined(MBEDTLS_SSL_DTLS_ANTI_REPLAY)
  26402. /**
  26403. * \brief Enable or disable anti-replay protection for DTLS.
  26404. * (DTLS only, no effect on TLS.)
  26405. * Default: enabled.
  26406. *
  26407. * \param conf SSL configuration
  26408. * \param mode MBEDTLS_SSL_ANTI_REPLAY_ENABLED or MBEDTLS_SSL_ANTI_REPLAY_DISABLED.
  26409. *
  26410. * \warning Disabling this is a security risk unless the application
  26411. * protocol handles duplicated packets in a safe way. You
  26412. * should not disable this without careful consideration.
  26413. * However, if your application already detects duplicated
  26414. * packets and needs information about them to adjust its
  26415. * transmission strategy, then you'll want to disable this.
  26416. */
  26417. void mbedtls_ssl_conf_dtls_anti_replay( mbedtls_ssl_config *conf, char mode );
  26418. #endif /* MBEDTLS_SSL_DTLS_ANTI_REPLAY */
  26419. #if defined(MBEDTLS_SSL_DTLS_BADMAC_LIMIT)
  26420. /**
  26421. * \brief Set a limit on the number of records with a bad MAC
  26422. * before terminating the connection.
  26423. * (DTLS only, no effect on TLS.)
  26424. * Default: 0 (disabled).
  26425. *
  26426. * \param conf SSL configuration
  26427. * \param limit Limit, or 0 to disable.
  26428. *
  26429. * \note If the limit is N, then the connection is terminated when
  26430. * the Nth non-authentic record is seen.
  26431. *
  26432. * \note Records with an invalid header are not counted, only the
  26433. * ones going through the authentication-decryption phase.
  26434. *
  26435. * \note This is a security trade-off related to the fact that it's
  26436. * often relatively easy for an active attacker ot inject UDP
  26437. * datagrams. On one hand, setting a low limit here makes it
  26438. * easier for such an attacker to forcibly terminated a
  26439. * connection. On the other hand, a high limit or no limit
  26440. * might make us waste resources checking authentication on
  26441. * many bogus packets.
  26442. */
  26443. void mbedtls_ssl_conf_dtls_badmac_limit( mbedtls_ssl_config *conf, unsigned limit );
  26444. #endif /* MBEDTLS_SSL_DTLS_BADMAC_LIMIT */
  26445. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  26446. /**
  26447. * \brief Allow or disallow packing of multiple handshake records
  26448. * within a single datagram.
  26449. *
  26450. * \param ssl The SSL context to configure.
  26451. * \param allow_packing This determines whether datagram packing may
  26452. * be used or not. A value of \c 0 means that every
  26453. * record will be sent in a separate datagram; a
  26454. * value of \c 1 means that, if space permits,
  26455. * multiple handshake messages (including CCS) belonging to
  26456. * a single flight may be packed within a single datagram.
  26457. *
  26458. * \note This is enabled by default and should only be disabled
  26459. * for test purposes, or if datagram packing causes
  26460. * interoperability issues with peers that don't support it.
  26461. *
  26462. * \note Allowing datagram packing reduces the network load since
  26463. * there's less overhead if multiple messages share the same
  26464. * datagram. Also, it increases the handshake efficiency
  26465. * since messages belonging to a single datagram will not
  26466. * be reordered in transit, and so future message buffering
  26467. * or flight retransmission (if no buffering is used) as
  26468. * means to deal with reordering are needed less frequently.
  26469. *
  26470. * \note Application records are not affected by this option and
  26471. * are currently always sent in separate datagrams.
  26472. *
  26473. */
  26474. void mbedtls_ssl_set_datagram_packing( mbedtls_ssl_context *ssl,
  26475. unsigned allow_packing );
  26476. /**
  26477. * \brief Set retransmit timeout values for the DTLS handshake.
  26478. * (DTLS only, no effect on TLS.)
  26479. *
  26480. * \param conf SSL configuration
  26481. * \param min Initial timeout value in milliseconds.
  26482. * Default: 1000 (1 second).
  26483. * \param max Maximum timeout value in milliseconds.
  26484. * Default: 60000 (60 seconds).
  26485. *
  26486. * \note Default values are from RFC 6347 section 4.2.4.1.
  26487. *
  26488. * \note The 'min' value should typically be slightly above the
  26489. * expected round-trip time to your peer, plus whatever time
  26490. * it takes for the peer to process the message. For example,
  26491. * if your RTT is about 600ms and you peer needs up to 1s to
  26492. * do the cryptographic operations in the handshake, then you
  26493. * should set 'min' slightly above 1600. Lower values of 'min'
  26494. * might cause spurious resends which waste network resources,
  26495. * while larger value of 'min' will increase overall latency
  26496. * on unreliable network links.
  26497. *
  26498. * \note The more unreliable your network connection is, the larger
  26499. * your max / min ratio needs to be in order to achieve
  26500. * reliable handshakes.
  26501. *
  26502. * \note Messages are retransmitted up to log2(ceil(max/min)) times.
  26503. * For example, if min = 1s and max = 5s, the retransmit plan
  26504. * goes: send ... 1s -> resend ... 2s -> resend ... 4s ->
  26505. * resend ... 5s -> give up and return a timeout error.
  26506. */
  26507. void mbedtls_ssl_conf_handshake_timeout( mbedtls_ssl_config *conf, uint32_t min, uint32_t max );
  26508. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  26509. #if defined(MBEDTLS_SSL_SRV_C)
  26510. /**
  26511. * \brief Set the session cache callbacks (server-side only)
  26512. * If not set, no session resuming is done (except if session
  26513. * tickets are enabled too).
  26514. *
  26515. * The session cache has the responsibility to check for stale
  26516. * entries based on timeout. See RFC 5246 for recommendations.
  26517. *
  26518. * Warning: session.peer_cert is cleared by the SSL/TLS layer on
  26519. * connection shutdown, so do not cache the pointer! Either set
  26520. * it to NULL or make a full copy of the certificate.
  26521. *
  26522. * The get callback is called once during the initial handshake
  26523. * to enable session resuming. The get function has the
  26524. * following parameters: (void *parameter, mbedtls_ssl_session *session)
  26525. * If a valid entry is found, it should fill the master of
  26526. * the session object with the cached values and return 0,
  26527. * return 1 otherwise. Optionally peer_cert can be set as well
  26528. * if it is properly present in cache entry.
  26529. *
  26530. * The set callback is called once during the initial handshake
  26531. * to enable session resuming after the entire handshake has
  26532. * been finished. The set function has the following parameters:
  26533. * (void *parameter, const mbedtls_ssl_session *session). The function
  26534. * should create a cache entry for future retrieval based on
  26535. * the data in the session structure and should keep in mind
  26536. * that the mbedtls_ssl_session object presented (and all its referenced
  26537. * data) is cleared by the SSL/TLS layer when the connection is
  26538. * terminated. It is recommended to add metadata to determine if
  26539. * an entry is still valid in the future. Return 0 if
  26540. * successfully cached, return 1 otherwise.
  26541. *
  26542. * \param conf SSL configuration
  26543. * \param p_cache parmater (context) for both callbacks
  26544. * \param f_get_cache session get callback
  26545. * \param f_set_cache session set callback
  26546. */
  26547. void mbedtls_ssl_conf_session_cache( mbedtls_ssl_config *conf,
  26548. void *p_cache,
  26549. int (*f_get_cache)(void *, mbedtls_ssl_session *),
  26550. int (*f_set_cache)(void *, const mbedtls_ssl_session *) );
  26551. #endif /* MBEDTLS_SSL_SRV_C */
  26552. #if defined(MBEDTLS_SSL_CLI_C)
  26553. /**
  26554. * \brief Request resumption of session (client-side only)
  26555. * Session data is copied from presented session structure.
  26556. *
  26557. * \param ssl SSL context
  26558. * \param session session context
  26559. *
  26560. * \return 0 if successful,
  26561. * MBEDTLS_ERR_SSL_ALLOC_FAILED if memory allocation failed,
  26562. * MBEDTLS_ERR_SSL_BAD_INPUT_DATA if used server-side or
  26563. * arguments are otherwise invalid
  26564. *
  26565. * \sa mbedtls_ssl_get_session()
  26566. */
  26567. int mbedtls_ssl_set_session( mbedtls_ssl_context *ssl, const mbedtls_ssl_session *session );
  26568. #endif /* MBEDTLS_SSL_CLI_C */
  26569. /**
  26570. * \brief Load serialized session data into a session structure.
  26571. * On client, this can be used for loading saved sessions
  26572. * before resuming them with mbedstls_ssl_set_session().
  26573. * On server, this can be used for alternative implementations
  26574. * of session cache or session tickets.
  26575. *
  26576. * \warning If a peer certificate chain is associated with the session,
  26577. * the serialized state will only contain the peer's
  26578. * end-entity certificate and the result of the chain
  26579. * verification (unless verification was disabled), but not
  26580. * the rest of the chain.
  26581. *
  26582. * \see mbedtls_ssl_session_save()
  26583. * \see mbedtls_ssl_set_session()
  26584. *
  26585. * \param session The session structure to be populated. It must have been
  26586. * initialised with mbedtls_ssl_session_init() but not
  26587. * populated yet.
  26588. * \param buf The buffer holding the serialized session data. It must be a
  26589. * readable buffer of at least \p len bytes.
  26590. * \param len The size of the serialized data in bytes.
  26591. *
  26592. * \return \c 0 if successful.
  26593. * \return #MBEDTLS_ERR_SSL_ALLOC_FAILED if memory allocation failed.
  26594. * \return #MBEDTLS_ERR_SSL_BAD_INPUT_DATA if input data is invalid.
  26595. * \return #MBEDTLS_ERR_SSL_VERSION_MISMATCH if the serialized data
  26596. * was generated in a different version or configuration of
  26597. * Mbed TLS.
  26598. * \return Another negative value for other kinds of errors (for
  26599. * example, unsupported features in the embedded certificate).
  26600. */
  26601. int mbedtls_ssl_session_load( mbedtls_ssl_session *session,
  26602. const unsigned char *buf,
  26603. size_t len );
  26604. /**
  26605. * \brief Save session structure as serialized data in a buffer.
  26606. * On client, this can be used for saving session data,
  26607. * potentially in non-volatile storage, for resuming later.
  26608. * On server, this can be used for alternative implementations
  26609. * of session cache or session tickets.
  26610. *
  26611. * \see mbedtls_ssl_session_load()
  26612. * \see mbedtls_ssl_get_session_pointer()
  26613. *
  26614. * \param session The session structure to be saved.
  26615. * \param buf The buffer to write the serialized data to. It must be a
  26616. * writeable buffer of at least \p len bytes, or may be \c
  26617. * NULL if \p len is \c 0.
  26618. * \param buf_len The number of bytes available for writing in \p buf.
  26619. * \param olen The size in bytes of the data that has been or would have
  26620. * been written. It must point to a valid \c size_t.
  26621. *
  26622. * \note \p olen is updated to the correct value regardless of
  26623. * whether \p buf_len was large enough. This makes it possible
  26624. * to determine the necessary size by calling this function
  26625. * with \p buf set to \c NULL and \p buf_len to \c 0.
  26626. *
  26627. * \return \c 0 if successful.
  26628. * \return #MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL if \p buf is too small.
  26629. */
  26630. int mbedtls_ssl_session_save( const mbedtls_ssl_session *session,
  26631. unsigned char *buf,
  26632. size_t buf_len,
  26633. size_t *olen );
  26634. /**
  26635. * \brief Get a pointer to the current session structure, for example
  26636. * to serialize it.
  26637. *
  26638. * \warning Ownership of the session remains with the SSL context, and
  26639. * the returned pointer is only guaranteed to be valid until
  26640. * the next API call operating on the same \p ssl context.
  26641. *
  26642. * \see mbedtls_ssl_session_save()
  26643. *
  26644. * \param ssl The SSL context.
  26645. *
  26646. * \return A pointer to the current session if successful.
  26647. * \return \c NULL if no session is active.
  26648. */
  26649. const mbedtls_ssl_session *mbedtls_ssl_get_session_pointer( const mbedtls_ssl_context *ssl );
  26650. /**
  26651. * \brief Set the list of allowed ciphersuites and the preference
  26652. * order. First in the list has the highest preference.
  26653. * (Overrides all version-specific lists)
  26654. *
  26655. * The ciphersuites array is not copied, and must remain
  26656. * valid for the lifetime of the ssl_config.
  26657. *
  26658. * Note: The server uses its own preferences
  26659. * over the preference of the client unless
  26660. * MBEDTLS_SSL_SRV_RESPECT_CLIENT_PREFERENCE is defined!
  26661. *
  26662. * \param conf SSL configuration
  26663. * \param ciphersuites 0-terminated list of allowed ciphersuites
  26664. */
  26665. void mbedtls_ssl_conf_ciphersuites( mbedtls_ssl_config *conf,
  26666. const int *ciphersuites );
  26667. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  26668. #define MBEDTLS_SSL_UNEXPECTED_CID_IGNORE 0
  26669. #define MBEDTLS_SSL_UNEXPECTED_CID_FAIL 1
  26670. /**
  26671. * \brief Specify the length of Connection IDs for incoming
  26672. * encrypted DTLS records, as well as the behaviour
  26673. * on unexpected CIDs.
  26674. *
  26675. * By default, the CID length is set to \c 0,
  26676. * and unexpected CIDs are silently ignored.
  26677. *
  26678. * \param conf The SSL configuration to modify.
  26679. * \param len The length in Bytes of the CID fields in encrypted
  26680. * DTLS records using the CID mechanism. This must
  26681. * not be larger than #MBEDTLS_SSL_CID_OUT_LEN_MAX.
  26682. * \param ignore_other_cids This determines the stack's behaviour when
  26683. * receiving a record with an unexpected CID.
  26684. * Possible values are:
  26685. * - #MBEDTLS_SSL_UNEXPECTED_CID_IGNORE
  26686. * In this case, the record is silently ignored.
  26687. * - #MBEDTLS_SSL_UNEXPECTED_CID_FAIL
  26688. * In this case, the stack fails with the specific
  26689. * error code #MBEDTLS_ERR_SSL_UNEXPECTED_CID.
  26690. *
  26691. * \note The CID specification allows implementations to either
  26692. * use a common length for all incoming connection IDs or
  26693. * allow variable-length incoming IDs. Mbed TLS currently
  26694. * requires a common length for all connections sharing the
  26695. * same SSL configuration; this allows simpler parsing of
  26696. * record headers.
  26697. *
  26698. * \return \c 0 on success.
  26699. * \return #MBEDTLS_ERR_SSL_BAD_INPUT_DATA if \p own_cid_len
  26700. * is too large.
  26701. */
  26702. int mbedtls_ssl_conf_cid( mbedtls_ssl_config *conf, size_t len,
  26703. int ignore_other_cids );
  26704. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  26705. /**
  26706. * \brief Set the list of allowed ciphersuites and the
  26707. * preference order for a specific version of the protocol.
  26708. * (Only useful on the server side)
  26709. *
  26710. * The ciphersuites array is not copied, and must remain
  26711. * valid for the lifetime of the ssl_config.
  26712. *
  26713. * \param conf SSL configuration
  26714. * \param ciphersuites 0-terminated list of allowed ciphersuites
  26715. * \param major Major version number (only MBEDTLS_SSL_MAJOR_VERSION_3
  26716. * supported)
  26717. * \param minor Minor version number (MBEDTLS_SSL_MINOR_VERSION_0,
  26718. * MBEDTLS_SSL_MINOR_VERSION_1 and MBEDTLS_SSL_MINOR_VERSION_2,
  26719. * MBEDTLS_SSL_MINOR_VERSION_3 supported)
  26720. *
  26721. * \note With DTLS, use MBEDTLS_SSL_MINOR_VERSION_2 for DTLS 1.0
  26722. * and MBEDTLS_SSL_MINOR_VERSION_3 for DTLS 1.2
  26723. */
  26724. void mbedtls_ssl_conf_ciphersuites_for_version( mbedtls_ssl_config *conf,
  26725. const int *ciphersuites,
  26726. int major, int minor );
  26727. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  26728. /**
  26729. * \brief Set the X.509 security profile used for verification
  26730. *
  26731. * \note The restrictions are enforced for all certificates in the
  26732. * chain. However, signatures in the handshake are not covered
  26733. * by this setting but by \b mbedtls_ssl_conf_sig_hashes().
  26734. *
  26735. * \param conf SSL configuration
  26736. * \param profile Profile to use
  26737. */
  26738. void mbedtls_ssl_conf_cert_profile( mbedtls_ssl_config *conf,
  26739. const mbedtls_x509_crt_profile *profile );
  26740. /**
  26741. * \brief Set the data required to verify peer certificate
  26742. *
  26743. * \note See \c mbedtls_x509_crt_verify() for notes regarding the
  26744. * parameters ca_chain (maps to trust_ca for that function)
  26745. * and ca_crl.
  26746. *
  26747. * \param conf SSL configuration
  26748. * \param ca_chain trusted CA chain (meaning all fully trusted top-level CAs)
  26749. * \param ca_crl trusted CA CRLs
  26750. */
  26751. void mbedtls_ssl_conf_ca_chain( mbedtls_ssl_config *conf,
  26752. mbedtls_x509_crt *ca_chain,
  26753. mbedtls_x509_crl *ca_crl );
  26754. #if defined(MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK)
  26755. /**
  26756. * \brief Set the trusted certificate callback.
  26757. *
  26758. * This API allows to register the set of trusted certificates
  26759. * through a callback, instead of a linked list as configured
  26760. * by mbedtls_ssl_conf_ca_chain().
  26761. *
  26762. * This is useful for example in contexts where a large number
  26763. * of CAs are used, and the inefficiency of maintaining them
  26764. * in a linked list cannot be tolerated. It is also useful when
  26765. * the set of trusted CAs needs to be modified frequently.
  26766. *
  26767. * See the documentation of `mbedtls_x509_crt_ca_cb_t` for
  26768. * more information.
  26769. *
  26770. * \param conf The SSL configuration to register the callback with.
  26771. * \param f_ca_cb The trusted certificate callback to use when verifying
  26772. * certificate chains.
  26773. * \param p_ca_cb The context to be passed to \p f_ca_cb (for example,
  26774. * a reference to a trusted CA database).
  26775. *
  26776. * \note This API is incompatible with mbedtls_ssl_conf_ca_chain():
  26777. * Any call to this function overwrites the values set through
  26778. * earlier calls to mbedtls_ssl_conf_ca_chain() or
  26779. * mbedtls_ssl_conf_ca_cb().
  26780. *
  26781. * \note This API is incompatible with CA indication in
  26782. * CertificateRequest messages: A server-side SSL context which
  26783. * is bound to an SSL configuration that uses a CA callback
  26784. * configured via mbedtls_ssl_conf_ca_cb(), and which requires
  26785. * client authentication, will send an empty CA list in the
  26786. * corresponding CertificateRequest message.
  26787. *
  26788. * \note This API is incompatible with mbedtls_ssl_set_hs_ca_chain():
  26789. * If an SSL context is bound to an SSL configuration which uses
  26790. * CA callbacks configured via mbedtls_ssl_conf_ca_cb(), then
  26791. * calls to mbedtls_ssl_set_hs_ca_chain() have no effect.
  26792. *
  26793. * \note The use of this API disables the use of restartable ECC
  26794. * during X.509 CRT signature verification (but doesn't affect
  26795. * other uses).
  26796. *
  26797. * \warning This API is incompatible with the use of CRLs. Any call to
  26798. * mbedtls_ssl_conf_ca_cb() unsets CRLs configured through
  26799. * earlier calls to mbedtls_ssl_conf_ca_chain().
  26800. *
  26801. * \warning In multi-threaded environments, the callback \p f_ca_cb
  26802. * must be thread-safe, and it is the user's responsibility
  26803. * to guarantee this (for example through a mutex
  26804. * contained in the callback context pointed to by \p p_ca_cb).
  26805. */
  26806. void mbedtls_ssl_conf_ca_cb( mbedtls_ssl_config *conf,
  26807. mbedtls_x509_crt_ca_cb_t f_ca_cb,
  26808. void *p_ca_cb );
  26809. #endif /* MBEDTLS_X509_TRUSTED_CERTIFICATE_CALLBACK */
  26810. /**
  26811. * \brief Set own certificate chain and private key
  26812. *
  26813. * \note own_cert should contain in order from the bottom up your
  26814. * certificate chain. The top certificate (self-signed)
  26815. * can be omitted.
  26816. *
  26817. * \note On server, this function can be called multiple times to
  26818. * provision more than one cert/key pair (eg one ECDSA, one
  26819. * RSA with SHA-256, one RSA with SHA-1). An adequate
  26820. * certificate will be selected according to the client's
  26821. * advertised capabilities. In case multiple certificates are
  26822. * adequate, preference is given to the one set by the first
  26823. * call to this function, then second, etc.
  26824. *
  26825. * \note On client, only the first call has any effect. That is,
  26826. * only one client certificate can be provisioned. The
  26827. * server's preferences in its CertficateRequest message will
  26828. * be ignored and our only cert will be sent regardless of
  26829. * whether it matches those preferences - the server can then
  26830. * decide what it wants to do with it.
  26831. *
  26832. * \note The provided \p pk_key needs to match the public key in the
  26833. * first certificate in \p own_cert, or all handshakes using
  26834. * that certificate will fail. It is your responsibility
  26835. * to ensure that; this function will not perform any check.
  26836. * You may use mbedtls_pk_check_pair() in order to perform
  26837. * this check yourself, but be aware that this function can
  26838. * be computationally expensive on some key types.
  26839. *
  26840. * \param conf SSL configuration
  26841. * \param own_cert own public certificate chain
  26842. * \param pk_key own private key
  26843. *
  26844. * \return 0 on success or MBEDTLS_ERR_SSL_ALLOC_FAILED
  26845. */
  26846. int mbedtls_ssl_conf_own_cert( mbedtls_ssl_config *conf,
  26847. mbedtls_x509_crt *own_cert,
  26848. mbedtls_pk_context *pk_key );
  26849. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  26850. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED)
  26851. /**
  26852. * \brief Configure a pre-shared key (PSK) and identity
  26853. * to be used in PSK-based ciphersuites.
  26854. *
  26855. * \note This is mainly useful for clients. Servers will usually
  26856. * want to use \c mbedtls_ssl_conf_psk_cb() instead.
  26857. *
  26858. * \note A PSK set by \c mbedtls_ssl_set_hs_psk() in the PSK callback
  26859. * takes precedence over a PSK configured by this function.
  26860. *
  26861. * \warning Currently, clients can only register a single pre-shared key.
  26862. * Calling this function or mbedtls_ssl_conf_psk_opaque() more
  26863. * than once will overwrite values configured in previous calls.
  26864. * Support for setting multiple PSKs on clients and selecting
  26865. * one based on the identity hint is not a planned feature,
  26866. * but feedback is welcomed.
  26867. *
  26868. * \param conf The SSL configuration to register the PSK with.
  26869. * \param psk The pointer to the pre-shared key to use.
  26870. * \param psk_len The length of the pre-shared key in bytes.
  26871. * \param psk_identity The pointer to the pre-shared key identity.
  26872. * \param psk_identity_len The length of the pre-shared key identity
  26873. * in bytes.
  26874. *
  26875. * \note The PSK and its identity are copied internally and
  26876. * hence need not be preserved by the caller for the lifetime
  26877. * of the SSL configuration.
  26878. *
  26879. * \return \c 0 if successful.
  26880. * \return An \c MBEDTLS_ERR_SSL_XXX error code on failure.
  26881. */
  26882. int mbedtls_ssl_conf_psk( mbedtls_ssl_config *conf,
  26883. const unsigned char *psk, size_t psk_len,
  26884. const unsigned char *psk_identity, size_t psk_identity_len );
  26885. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  26886. /**
  26887. * \brief Configure an opaque pre-shared key (PSK) and identity
  26888. * to be used in PSK-based ciphersuites.
  26889. *
  26890. * \note This is mainly useful for clients. Servers will usually
  26891. * want to use \c mbedtls_ssl_conf_psk_cb() instead.
  26892. *
  26893. * \note An opaque PSK set by \c mbedtls_ssl_set_hs_psk_opaque() in
  26894. * the PSK callback takes precedence over an opaque PSK
  26895. * configured by this function.
  26896. *
  26897. * \warning Currently, clients can only register a single pre-shared key.
  26898. * Calling this function or mbedtls_ssl_conf_psk() more than
  26899. * once will overwrite values configured in previous calls.
  26900. * Support for setting multiple PSKs on clients and selecting
  26901. * one based on the identity hint is not a planned feature,
  26902. * but feedback is welcomed.
  26903. *
  26904. * \param conf The SSL configuration to register the PSK with.
  26905. * \param psk The identifier of the key slot holding the PSK.
  26906. * Until \p conf is destroyed or this function is successfully
  26907. * called again, the key slot \p psk must be populated with a
  26908. * key of type PSA_ALG_CATEGORY_KEY_DERIVATION whose policy
  26909. * allows its use for the key derivation algorithm applied
  26910. * in the handshake.
  26911. * \param psk_identity The pointer to the pre-shared key identity.
  26912. * \param psk_identity_len The length of the pre-shared key identity
  26913. * in bytes.
  26914. *
  26915. * \note The PSK identity hint is copied internally and hence need
  26916. * not be preserved by the caller for the lifetime of the
  26917. * SSL configuration.
  26918. *
  26919. * \return \c 0 if successful.
  26920. * \return An \c MBEDTLS_ERR_SSL_XXX error code on failure.
  26921. */
  26922. int mbedtls_ssl_conf_psk_opaque( mbedtls_ssl_config *conf,
  26923. psa_key_id_t psk,
  26924. const unsigned char *psk_identity,
  26925. size_t psk_identity_len );
  26926. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  26927. /**
  26928. * \brief Set the pre-shared Key (PSK) for the current handshake.
  26929. *
  26930. * \note This should only be called inside the PSK callback,
  26931. * i.e. the function passed to \c mbedtls_ssl_conf_psk_cb().
  26932. *
  26933. * \note A PSK set by this function takes precedence over a PSK
  26934. * configured by \c mbedtls_ssl_conf_psk().
  26935. *
  26936. * \param ssl The SSL context to configure a PSK for.
  26937. * \param psk The pointer to the pre-shared key.
  26938. * \param psk_len The length of the pre-shared key in bytes.
  26939. *
  26940. * \return \c 0 if successful.
  26941. * \return An \c MBEDTLS_ERR_SSL_XXX error code on failure.
  26942. */
  26943. int mbedtls_ssl_set_hs_psk( mbedtls_ssl_context *ssl,
  26944. const unsigned char *psk, size_t psk_len );
  26945. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  26946. /**
  26947. * \brief Set an opaque pre-shared Key (PSK) for the current handshake.
  26948. *
  26949. * \note This should only be called inside the PSK callback,
  26950. * i.e. the function passed to \c mbedtls_ssl_conf_psk_cb().
  26951. *
  26952. * \note An opaque PSK set by this function takes precedence over an
  26953. * opaque PSK configured by \c mbedtls_ssl_conf_psk_opaque().
  26954. *
  26955. * \param ssl The SSL context to configure a PSK for.
  26956. * \param psk The identifier of the key slot holding the PSK.
  26957. * For the duration of the current handshake, the key slot
  26958. * must be populated with a key of type
  26959. * PSA_ALG_CATEGORY_KEY_DERIVATION whose policy allows its
  26960. * use for the key derivation algorithm
  26961. * applied in the handshake.
  26962. *
  26963. * \return \c 0 if successful.
  26964. * \return An \c MBEDTLS_ERR_SSL_XXX error code on failure.
  26965. */
  26966. int mbedtls_ssl_set_hs_psk_opaque( mbedtls_ssl_context *ssl,
  26967. psa_key_id_t psk );
  26968. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  26969. /**
  26970. * \brief Set the PSK callback (server-side only).
  26971. *
  26972. * If set, the PSK callback is called for each
  26973. * handshake where a PSK-based ciphersuite was negotiated.
  26974. * The caller provides the identity received and wants to
  26975. * receive the actual PSK data and length.
  26976. *
  26977. * The callback has the following parameters:
  26978. * - \c void*: The opaque pointer \p p_psk.
  26979. * - \c mbedtls_ssl_context*: The SSL context to which
  26980. * the operation applies.
  26981. * - \c const unsigned char*: The PSK identity
  26982. * selected by the client.
  26983. * - \c size_t: The length of the PSK identity
  26984. * selected by the client.
  26985. *
  26986. * If a valid PSK identity is found, the callback should use
  26987. * \c mbedtls_ssl_set_hs_psk() or
  26988. * \c mbedtls_ssl_set_hs_psk_opaque()
  26989. * on the SSL context to set the correct PSK and return \c 0.
  26990. * Any other return value will result in a denied PSK identity.
  26991. *
  26992. * \note A dynamic PSK (i.e. set by the PSK callback) takes
  26993. * precedence over a static PSK (i.e. set by
  26994. * \c mbedtls_ssl_conf_psk() or
  26995. * \c mbedtls_ssl_conf_psk_opaque()).
  26996. * This means that if you set a PSK callback using this
  26997. * function, you don't need to set a PSK using
  26998. * \c mbedtls_ssl_conf_psk() or
  26999. * \c mbedtls_ssl_conf_psk_opaque()).
  27000. *
  27001. * \param conf The SSL configuration to register the callback with.
  27002. * \param f_psk The callback for selecting and setting the PSK based
  27003. * in the PSK identity chosen by the client.
  27004. * \param p_psk A pointer to an opaque structure to be passed to
  27005. * the callback, for example a PSK store.
  27006. */
  27007. void mbedtls_ssl_conf_psk_cb( mbedtls_ssl_config *conf,
  27008. int (*f_psk)(void *, mbedtls_ssl_context *, const unsigned char *,
  27009. size_t),
  27010. void *p_psk );
  27011. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED */
  27012. #if defined(MBEDTLS_DHM_C) && defined(MBEDTLS_SSL_SRV_C)
  27013. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  27014. #if defined(MBEDTLS_DEPRECATED_WARNING)
  27015. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  27016. #else
  27017. #define MBEDTLS_DEPRECATED
  27018. #endif
  27019. /**
  27020. * \brief Set the Diffie-Hellman public P and G values,
  27021. * read as hexadecimal strings (server-side only)
  27022. * (Default values: MBEDTLS_DHM_RFC3526_MODP_2048_[PG])
  27023. *
  27024. * \param conf SSL configuration
  27025. * \param dhm_P Diffie-Hellman-Merkle modulus
  27026. * \param dhm_G Diffie-Hellman-Merkle generator
  27027. *
  27028. * \deprecated Superseded by \c mbedtls_ssl_conf_dh_param_bin.
  27029. *
  27030. * \return 0 if successful
  27031. */
  27032. MBEDTLS_DEPRECATED int mbedtls_ssl_conf_dh_param( mbedtls_ssl_config *conf,
  27033. const char *dhm_P,
  27034. const char *dhm_G );
  27035. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  27036. /**
  27037. * \brief Set the Diffie-Hellman public P and G values
  27038. * from big-endian binary presentations.
  27039. * (Default values: MBEDTLS_DHM_RFC3526_MODP_2048_[PG]_BIN)
  27040. *
  27041. * \param conf SSL configuration
  27042. * \param dhm_P Diffie-Hellman-Merkle modulus in big-endian binary form
  27043. * \param P_len Length of DHM modulus
  27044. * \param dhm_G Diffie-Hellman-Merkle generator in big-endian binary form
  27045. * \param G_len Length of DHM generator
  27046. *
  27047. * \return 0 if successful
  27048. */
  27049. int mbedtls_ssl_conf_dh_param_bin( mbedtls_ssl_config *conf,
  27050. const unsigned char *dhm_P, size_t P_len,
  27051. const unsigned char *dhm_G, size_t G_len );
  27052. /**
  27053. * \brief Set the Diffie-Hellman public P and G values,
  27054. * read from existing context (server-side only)
  27055. *
  27056. * \param conf SSL configuration
  27057. * \param dhm_ctx Diffie-Hellman-Merkle context
  27058. *
  27059. * \return 0 if successful
  27060. */
  27061. int mbedtls_ssl_conf_dh_param_ctx( mbedtls_ssl_config *conf, mbedtls_dhm_context *dhm_ctx );
  27062. #endif /* MBEDTLS_DHM_C && defined(MBEDTLS_SSL_SRV_C) */
  27063. #if defined(MBEDTLS_DHM_C) && defined(MBEDTLS_SSL_CLI_C)
  27064. /**
  27065. * \brief Set the minimum length for Diffie-Hellman parameters.
  27066. * (Client-side only.)
  27067. * (Default: 1024 bits.)
  27068. *
  27069. * \param conf SSL configuration
  27070. * \param bitlen Minimum bit length of the DHM prime
  27071. */
  27072. void mbedtls_ssl_conf_dhm_min_bitlen( mbedtls_ssl_config *conf,
  27073. unsigned int bitlen );
  27074. #endif /* MBEDTLS_DHM_C && MBEDTLS_SSL_CLI_C */
  27075. #if defined(MBEDTLS_ECP_C)
  27076. /**
  27077. * \brief Set the allowed curves in order of preference.
  27078. * (Default: all defined curves in order of decreasing size,
  27079. * except that Montgomery curves come last. This order
  27080. * is likely to change in a future version.)
  27081. *
  27082. * On server: this only affects selection of the ECDHE curve;
  27083. * the curves used for ECDH and ECDSA are determined by the
  27084. * list of available certificates instead.
  27085. *
  27086. * On client: this affects the list of curves offered for any
  27087. * use. The server can override our preference order.
  27088. *
  27089. * Both sides: limits the set of curves accepted for use in
  27090. * ECDHE and in the peer's end-entity certificate.
  27091. *
  27092. * \note This has no influence on which curves are allowed inside the
  27093. * certificate chains, see \c mbedtls_ssl_conf_cert_profile()
  27094. * for that. For the end-entity certificate however, the key
  27095. * will be accepted only if it is allowed both by this list
  27096. * and by the cert profile.
  27097. *
  27098. * \note This list should be ordered by decreasing preference
  27099. * (preferred curve first).
  27100. *
  27101. * \param conf SSL configuration
  27102. * \param curves Ordered list of allowed curves,
  27103. * terminated by MBEDTLS_ECP_DP_NONE.
  27104. */
  27105. void mbedtls_ssl_conf_curves( mbedtls_ssl_config *conf,
  27106. const mbedtls_ecp_group_id *curves );
  27107. #endif /* MBEDTLS_ECP_C */
  27108. #if defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED)
  27109. /**
  27110. * \brief Set the allowed hashes for signatures during the handshake.
  27111. * (Default: all SHA-2 hashes, largest first. Also SHA-1 if
  27112. * the compile-time option
  27113. * `MBEDTLS_TLS_DEFAULT_ALLOW_SHA1_IN_KEY_EXCHANGE` is enabled.)
  27114. *
  27115. * \note This only affects which hashes are offered and can be used
  27116. * for signatures during the handshake. Hashes for message
  27117. * authentication and the TLS PRF are controlled by the
  27118. * ciphersuite, see \c mbedtls_ssl_conf_ciphersuites(). Hashes
  27119. * used for certificate signature are controlled by the
  27120. * verification profile, see \c mbedtls_ssl_conf_cert_profile().
  27121. *
  27122. * \note This list should be ordered by decreasing preference
  27123. * (preferred hash first).
  27124. *
  27125. * \param conf SSL configuration
  27126. * \param hashes Ordered list of allowed signature hashes,
  27127. * terminated by \c MBEDTLS_MD_NONE.
  27128. */
  27129. void mbedtls_ssl_conf_sig_hashes( mbedtls_ssl_config *conf,
  27130. const int *hashes );
  27131. #endif /* MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED */
  27132. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  27133. /**
  27134. * \brief Set or reset the hostname to check against the received
  27135. * server certificate. It sets the ServerName TLS extension,
  27136. * too, if that extension is enabled. (client-side only)
  27137. *
  27138. * \param ssl SSL context
  27139. * \param hostname the server hostname, may be NULL to clear hostname
  27140. * \note Maximum hostname length MBEDTLS_SSL_MAX_HOST_NAME_LEN.
  27141. *
  27142. * \return 0 if successful, MBEDTLS_ERR_SSL_ALLOC_FAILED on
  27143. * allocation failure, MBEDTLS_ERR_SSL_BAD_INPUT_DATA on
  27144. * too long input hostname.
  27145. *
  27146. * Hostname set to the one provided on success (cleared
  27147. * when NULL). On allocation failure hostname is cleared.
  27148. * On too long input failure, old hostname is unchanged.
  27149. */
  27150. int mbedtls_ssl_set_hostname( mbedtls_ssl_context *ssl, const char *hostname );
  27151. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  27152. #if defined(MBEDTLS_SSL_SERVER_NAME_INDICATION)
  27153. /**
  27154. * \brief Set own certificate and key for the current handshake
  27155. *
  27156. * \note Same as \c mbedtls_ssl_conf_own_cert() but for use within
  27157. * the SNI callback.
  27158. *
  27159. * \param ssl SSL context
  27160. * \param own_cert own public certificate chain
  27161. * \param pk_key own private key
  27162. *
  27163. * \return 0 on success or MBEDTLS_ERR_SSL_ALLOC_FAILED
  27164. */
  27165. int mbedtls_ssl_set_hs_own_cert( mbedtls_ssl_context *ssl,
  27166. mbedtls_x509_crt *own_cert,
  27167. mbedtls_pk_context *pk_key );
  27168. /**
  27169. * \brief Set the data required to verify peer certificate for the
  27170. * current handshake
  27171. *
  27172. * \note Same as \c mbedtls_ssl_conf_ca_chain() but for use within
  27173. * the SNI callback.
  27174. *
  27175. * \param ssl SSL context
  27176. * \param ca_chain trusted CA chain (meaning all fully trusted top-level CAs)
  27177. * \param ca_crl trusted CA CRLs
  27178. */
  27179. void mbedtls_ssl_set_hs_ca_chain( mbedtls_ssl_context *ssl,
  27180. mbedtls_x509_crt *ca_chain,
  27181. mbedtls_x509_crl *ca_crl );
  27182. /**
  27183. * \brief Set authmode for the current handshake.
  27184. *
  27185. * \note Same as \c mbedtls_ssl_conf_authmode() but for use within
  27186. * the SNI callback.
  27187. *
  27188. * \param ssl SSL context
  27189. * \param authmode MBEDTLS_SSL_VERIFY_NONE, MBEDTLS_SSL_VERIFY_OPTIONAL or
  27190. * MBEDTLS_SSL_VERIFY_REQUIRED
  27191. */
  27192. void mbedtls_ssl_set_hs_authmode( mbedtls_ssl_context *ssl,
  27193. int authmode );
  27194. /**
  27195. * \brief Set server side ServerName TLS extension callback
  27196. * (optional, server-side only).
  27197. *
  27198. * If set, the ServerName callback is called whenever the
  27199. * server receives a ServerName TLS extension from the client
  27200. * during a handshake. The ServerName callback has the
  27201. * following parameters: (void *parameter, mbedtls_ssl_context *ssl,
  27202. * const unsigned char *hostname, size_t len). If a suitable
  27203. * certificate is found, the callback must set the
  27204. * certificate(s) and key(s) to use with \c
  27205. * mbedtls_ssl_set_hs_own_cert() (can be called repeatedly),
  27206. * and may optionally adjust the CA and associated CRL with \c
  27207. * mbedtls_ssl_set_hs_ca_chain() as well as the client
  27208. * authentication mode with \c mbedtls_ssl_set_hs_authmode(),
  27209. * then must return 0. If no matching name is found, the
  27210. * callback must either set a default cert, or
  27211. * return non-zero to abort the handshake at this point.
  27212. *
  27213. * \param conf SSL configuration
  27214. * \param f_sni verification function
  27215. * \param p_sni verification parameter
  27216. */
  27217. void mbedtls_ssl_conf_sni( mbedtls_ssl_config *conf,
  27218. int (*f_sni)(void *, mbedtls_ssl_context *, const unsigned char *,
  27219. size_t),
  27220. void *p_sni );
  27221. #endif /* MBEDTLS_SSL_SERVER_NAME_INDICATION */
  27222. #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED)
  27223. /**
  27224. * \brief Set the EC J-PAKE password for current handshake.
  27225. *
  27226. * \note An internal copy is made, and destroyed as soon as the
  27227. * handshake is completed, or when the SSL context is reset or
  27228. * freed.
  27229. *
  27230. * \note The SSL context needs to be already set up. The right place
  27231. * to call this function is between \c mbedtls_ssl_setup() or
  27232. * \c mbedtls_ssl_reset() and \c mbedtls_ssl_handshake().
  27233. *
  27234. * \param ssl SSL context
  27235. * \param pw EC J-PAKE password (pre-shared secret)
  27236. * \param pw_len length of pw in bytes
  27237. *
  27238. * \return 0 on success, or a negative error code.
  27239. */
  27240. int mbedtls_ssl_set_hs_ecjpake_password( mbedtls_ssl_context *ssl,
  27241. const unsigned char *pw,
  27242. size_t pw_len );
  27243. #endif /*MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED */
  27244. #if defined(MBEDTLS_SSL_ALPN)
  27245. /**
  27246. * \brief Set the supported Application Layer Protocols.
  27247. *
  27248. * \param conf SSL configuration
  27249. * \param protos Pointer to a NULL-terminated list of supported protocols,
  27250. * in decreasing preference order. The pointer to the list is
  27251. * recorded by the library for later reference as required, so
  27252. * the lifetime of the table must be atleast as long as the
  27253. * lifetime of the SSL configuration structure.
  27254. *
  27255. * \return 0 on success, or MBEDTLS_ERR_SSL_BAD_INPUT_DATA.
  27256. */
  27257. int mbedtls_ssl_conf_alpn_protocols( mbedtls_ssl_config *conf, const char **protos );
  27258. /**
  27259. * \brief Get the name of the negotiated Application Layer Protocol.
  27260. * This function should be called after the handshake is
  27261. * completed.
  27262. *
  27263. * \param ssl SSL context
  27264. *
  27265. * \return Protcol name, or NULL if no protocol was negotiated.
  27266. */
  27267. const char *mbedtls_ssl_get_alpn_protocol( const mbedtls_ssl_context *ssl );
  27268. #endif /* MBEDTLS_SSL_ALPN */
  27269. #if defined(MBEDTLS_SSL_DTLS_SRTP)
  27270. #if defined(MBEDTLS_DEBUG_C)
  27271. static inline const char *mbedtls_ssl_get_srtp_profile_as_string( mbedtls_ssl_srtp_profile profile )
  27272. {
  27273. switch( profile )
  27274. {
  27275. case MBEDTLS_TLS_SRTP_AES128_CM_HMAC_SHA1_80:
  27276. return( "MBEDTLS_TLS_SRTP_AES128_CM_HMAC_SHA1_80" );
  27277. case MBEDTLS_TLS_SRTP_AES128_CM_HMAC_SHA1_32:
  27278. return( "MBEDTLS_TLS_SRTP_AES128_CM_HMAC_SHA1_32" );
  27279. case MBEDTLS_TLS_SRTP_NULL_HMAC_SHA1_80:
  27280. return( "MBEDTLS_TLS_SRTP_NULL_HMAC_SHA1_80" );
  27281. case MBEDTLS_TLS_SRTP_NULL_HMAC_SHA1_32:
  27282. return( "MBEDTLS_TLS_SRTP_NULL_HMAC_SHA1_32" );
  27283. default: break;
  27284. }
  27285. return( "" );
  27286. }
  27287. #endif /* MBEDTLS_DEBUG_C */
  27288. /**
  27289. * \brief Manage support for mki(master key id) value
  27290. * in use_srtp extension.
  27291. * MKI is an optional part of SRTP used for key management
  27292. * and re-keying. See RFC3711 section 3.1 for details.
  27293. * The default value is
  27294. * #MBEDTLS_SSL_DTLS_SRTP_MKI_UNSUPPORTED.
  27295. *
  27296. * \param conf The SSL configuration to manage mki support.
  27297. * \param support_mki_value Enable or disable mki usage. Values are
  27298. * #MBEDTLS_SSL_DTLS_SRTP_MKI_UNSUPPORTED
  27299. * or #MBEDTLS_SSL_DTLS_SRTP_MKI_SUPPORTED.
  27300. */
  27301. void mbedtls_ssl_conf_srtp_mki_value_supported( mbedtls_ssl_config *conf,
  27302. int support_mki_value );
  27303. /**
  27304. * \brief Set the supported DTLS-SRTP protection profiles.
  27305. *
  27306. * \param conf SSL configuration
  27307. * \param profiles Pointer to a List of MBEDTLS_TLS_SRTP_UNSET terminated
  27308. * supported protection profiles
  27309. * in decreasing preference order.
  27310. * The pointer to the list is recorded by the library
  27311. * for later reference as required, so the lifetime
  27312. * of the table must be at least as long as the lifetime
  27313. * of the SSL configuration structure.
  27314. * The list must not hold more than
  27315. * MBEDTLS_TLS_SRTP_MAX_PROFILE_LIST_LENGTH elements
  27316. * (excluding the terminating MBEDTLS_TLS_SRTP_UNSET).
  27317. *
  27318. * \return 0 on success
  27319. * \return #MBEDTLS_ERR_SSL_BAD_INPUT_DATA when the list of
  27320. * protection profiles is incorrect.
  27321. */
  27322. int mbedtls_ssl_conf_dtls_srtp_protection_profiles
  27323. ( mbedtls_ssl_config *conf,
  27324. const mbedtls_ssl_srtp_profile *profiles );
  27325. /**
  27326. * \brief Set the mki_value for the current DTLS-SRTP session.
  27327. *
  27328. * \param ssl SSL context to use.
  27329. * \param mki_value The MKI value to set.
  27330. * \param mki_len The length of the MKI value.
  27331. *
  27332. * \note This function is relevant on client side only.
  27333. * The server discovers the mki value during handshake.
  27334. * A mki value set on server side using this function
  27335. * is ignored.
  27336. *
  27337. * \return 0 on success
  27338. * \return #MBEDTLS_ERR_SSL_BAD_INPUT_DATA
  27339. * \return #MBEDTLS_ERR_SSL_FEATURE_UNAVAILABLE
  27340. */
  27341. int mbedtls_ssl_dtls_srtp_set_mki_value( mbedtls_ssl_context *ssl,
  27342. unsigned char *mki_value,
  27343. uint16_t mki_len );
  27344. /**
  27345. * \brief Get the negotiated DTLS-SRTP informations:
  27346. * Protection profile and MKI value.
  27347. *
  27348. * \warning This function must be called after the handshake is
  27349. * completed. The value returned by this function must
  27350. * not be trusted or acted upon before the handshake completes.
  27351. *
  27352. * \param ssl The SSL context to query.
  27353. * \param dtls_srtp_info The negotiated DTLS-SRTP informations:
  27354. * - Protection profile in use.
  27355. * A direct mapping of the iana defined value for protection
  27356. * profile on an uint16_t.
  27357. http://www.iana.org/assignments/srtp-protection/srtp-protection.xhtml
  27358. * #MBEDTLS_TLS_SRTP_UNSET if the use of SRTP was not negotiated
  27359. * or peer's Hello packet was not parsed yet.
  27360. * - mki size and value( if size is > 0 ).
  27361. */
  27362. void mbedtls_ssl_get_dtls_srtp_negotiation_result( const mbedtls_ssl_context *ssl,
  27363. mbedtls_dtls_srtp_info *dtls_srtp_info );
  27364. #endif /* MBEDTLS_SSL_DTLS_SRTP */
  27365. /**
  27366. * \brief Set the maximum supported version sent from the client side
  27367. * and/or accepted at the server side
  27368. * (Default: MBEDTLS_SSL_MAX_MAJOR_VERSION, MBEDTLS_SSL_MAX_MINOR_VERSION)
  27369. *
  27370. * \note This ignores ciphersuites from higher versions.
  27371. *
  27372. * \note With DTLS, use MBEDTLS_SSL_MINOR_VERSION_2 for DTLS 1.0 and
  27373. * MBEDTLS_SSL_MINOR_VERSION_3 for DTLS 1.2
  27374. *
  27375. * \param conf SSL configuration
  27376. * \param major Major version number (only MBEDTLS_SSL_MAJOR_VERSION_3 supported)
  27377. * \param minor Minor version number (MBEDTLS_SSL_MINOR_VERSION_0,
  27378. * MBEDTLS_SSL_MINOR_VERSION_1 and MBEDTLS_SSL_MINOR_VERSION_2,
  27379. * MBEDTLS_SSL_MINOR_VERSION_3 supported)
  27380. */
  27381. void mbedtls_ssl_conf_max_version( mbedtls_ssl_config *conf, int major, int minor );
  27382. /**
  27383. * \brief Set the minimum accepted SSL/TLS protocol version
  27384. * (Default: TLS 1.0)
  27385. *
  27386. * \note Input outside of the SSL_MAX_XXXXX_VERSION and
  27387. * SSL_MIN_XXXXX_VERSION range is ignored.
  27388. *
  27389. * \note MBEDTLS_SSL_MINOR_VERSION_0 (SSL v3) should be avoided.
  27390. *
  27391. * \note With DTLS, use MBEDTLS_SSL_MINOR_VERSION_2 for DTLS 1.0 and
  27392. * MBEDTLS_SSL_MINOR_VERSION_3 for DTLS 1.2
  27393. *
  27394. * \param conf SSL configuration
  27395. * \param major Major version number (only MBEDTLS_SSL_MAJOR_VERSION_3 supported)
  27396. * \param minor Minor version number (MBEDTLS_SSL_MINOR_VERSION_0,
  27397. * MBEDTLS_SSL_MINOR_VERSION_1 and MBEDTLS_SSL_MINOR_VERSION_2,
  27398. * MBEDTLS_SSL_MINOR_VERSION_3 supported)
  27399. */
  27400. void mbedtls_ssl_conf_min_version( mbedtls_ssl_config *conf, int major, int minor );
  27401. #if defined(MBEDTLS_SSL_FALLBACK_SCSV) && defined(MBEDTLS_SSL_CLI_C)
  27402. /**
  27403. * \brief Set the fallback flag (client-side only).
  27404. * (Default: MBEDTLS_SSL_IS_NOT_FALLBACK).
  27405. *
  27406. * \note Set to MBEDTLS_SSL_IS_FALLBACK when preparing a fallback
  27407. * connection, that is a connection with max_version set to a
  27408. * lower value than the value you're willing to use. Such
  27409. * fallback connections are not recommended but are sometimes
  27410. * necessary to interoperate with buggy (version-intolerant)
  27411. * servers.
  27412. *
  27413. * \warning You should NOT set this to MBEDTLS_SSL_IS_FALLBACK for
  27414. * non-fallback connections! This would appear to work for a
  27415. * while, then cause failures when the server is upgraded to
  27416. * support a newer TLS version.
  27417. *
  27418. * \param conf SSL configuration
  27419. * \param fallback MBEDTLS_SSL_IS_NOT_FALLBACK or MBEDTLS_SSL_IS_FALLBACK
  27420. */
  27421. void mbedtls_ssl_conf_fallback( mbedtls_ssl_config *conf, char fallback );
  27422. #endif /* MBEDTLS_SSL_FALLBACK_SCSV && MBEDTLS_SSL_CLI_C */
  27423. #if defined(MBEDTLS_SSL_ENCRYPT_THEN_MAC)
  27424. /**
  27425. * \brief Enable or disable Encrypt-then-MAC
  27426. * (Default: MBEDTLS_SSL_ETM_ENABLED)
  27427. *
  27428. * \note This should always be enabled, it is a security
  27429. * improvement, and should not cause any interoperability
  27430. * issue (used only if the peer supports it too).
  27431. *
  27432. * \param conf SSL configuration
  27433. * \param etm MBEDTLS_SSL_ETM_ENABLED or MBEDTLS_SSL_ETM_DISABLED
  27434. */
  27435. void mbedtls_ssl_conf_encrypt_then_mac( mbedtls_ssl_config *conf, char etm );
  27436. #endif /* MBEDTLS_SSL_ENCRYPT_THEN_MAC */
  27437. #if defined(MBEDTLS_SSL_EXTENDED_MASTER_SECRET)
  27438. /**
  27439. * \brief Enable or disable Extended Master Secret negotiation.
  27440. * (Default: MBEDTLS_SSL_EXTENDED_MS_ENABLED)
  27441. *
  27442. * \note This should always be enabled, it is a security fix to the
  27443. * protocol, and should not cause any interoperability issue
  27444. * (used only if the peer supports it too).
  27445. *
  27446. * \param conf SSL configuration
  27447. * \param ems MBEDTLS_SSL_EXTENDED_MS_ENABLED or MBEDTLS_SSL_EXTENDED_MS_DISABLED
  27448. */
  27449. void mbedtls_ssl_conf_extended_master_secret( mbedtls_ssl_config *conf, char ems );
  27450. #endif /* MBEDTLS_SSL_EXTENDED_MASTER_SECRET */
  27451. #if defined(MBEDTLS_ARC4_C)
  27452. /**
  27453. * \brief Disable or enable support for RC4
  27454. * (Default: MBEDTLS_SSL_ARC4_DISABLED)
  27455. *
  27456. * \warning Use of RC4 in DTLS/TLS has been prohibited by RFC 7465
  27457. * for security reasons. Use at your own risk.
  27458. *
  27459. * \note This function is deprecated and will be removed in
  27460. * a future version of the library.
  27461. * RC4 is disabled by default at compile time and needs to be
  27462. * actively enabled for use with legacy systems.
  27463. *
  27464. * \param conf SSL configuration
  27465. * \param arc4 MBEDTLS_SSL_ARC4_ENABLED or MBEDTLS_SSL_ARC4_DISABLED
  27466. */
  27467. void mbedtls_ssl_conf_arc4_support( mbedtls_ssl_config *conf, char arc4 );
  27468. #endif /* MBEDTLS_ARC4_C */
  27469. #if defined(MBEDTLS_SSL_SRV_C)
  27470. /**
  27471. * \brief Whether to send a list of acceptable CAs in
  27472. * CertificateRequest messages.
  27473. * (Default: do send)
  27474. *
  27475. * \param conf SSL configuration
  27476. * \param cert_req_ca_list MBEDTLS_SSL_CERT_REQ_CA_LIST_ENABLED or
  27477. * MBEDTLS_SSL_CERT_REQ_CA_LIST_DISABLED
  27478. */
  27479. void mbedtls_ssl_conf_cert_req_ca_list( mbedtls_ssl_config *conf,
  27480. char cert_req_ca_list );
  27481. #endif /* MBEDTLS_SSL_SRV_C */
  27482. #if defined(MBEDTLS_SSL_MAX_FRAGMENT_LENGTH)
  27483. /**
  27484. * \brief Set the maximum fragment length to emit and/or negotiate.
  27485. * (Typical: the smaller of #MBEDTLS_SSL_IN_CONTENT_LEN and
  27486. * #MBEDTLS_SSL_OUT_CONTENT_LEN, usually `2^14` bytes)
  27487. * (Server: set maximum fragment length to emit,
  27488. * usually negotiated by the client during handshake)
  27489. * (Client: set maximum fragment length to emit *and*
  27490. * negotiate with the server during handshake)
  27491. * (Default: #MBEDTLS_SSL_MAX_FRAG_LEN_NONE)
  27492. *
  27493. * \note On the client side, the maximum fragment length extension
  27494. * *will not* be used, unless the maximum fragment length has
  27495. * been set via this function to a value different than
  27496. * #MBEDTLS_SSL_MAX_FRAG_LEN_NONE.
  27497. *
  27498. * \note With TLS, this currently only affects ApplicationData (sent
  27499. * with \c mbedtls_ssl_read()), not handshake messages.
  27500. * With DTLS, this affects both ApplicationData and handshake.
  27501. *
  27502. * \note This sets the maximum length for a record's payload,
  27503. * excluding record overhead that will be added to it, see
  27504. * \c mbedtls_ssl_get_record_expansion().
  27505. *
  27506. * \note For DTLS, it is also possible to set a limit for the total
  27507. * size of daragrams passed to the transport layer, including
  27508. * record overhead, see \c mbedtls_ssl_set_mtu().
  27509. *
  27510. * \param conf SSL configuration
  27511. * \param mfl_code Code for maximum fragment length (allowed values:
  27512. * MBEDTLS_SSL_MAX_FRAG_LEN_512, MBEDTLS_SSL_MAX_FRAG_LEN_1024,
  27513. * MBEDTLS_SSL_MAX_FRAG_LEN_2048, MBEDTLS_SSL_MAX_FRAG_LEN_4096)
  27514. *
  27515. * \return 0 if successful or MBEDTLS_ERR_SSL_BAD_INPUT_DATA
  27516. */
  27517. int mbedtls_ssl_conf_max_frag_len( mbedtls_ssl_config *conf, unsigned char mfl_code );
  27518. #endif /* MBEDTLS_SSL_MAX_FRAGMENT_LENGTH */
  27519. #if defined(MBEDTLS_SSL_TRUNCATED_HMAC)
  27520. /**
  27521. * \brief Activate negotiation of truncated HMAC
  27522. * (Default: MBEDTLS_SSL_TRUNC_HMAC_DISABLED)
  27523. *
  27524. * \param conf SSL configuration
  27525. * \param truncate Enable or disable (MBEDTLS_SSL_TRUNC_HMAC_ENABLED or
  27526. * MBEDTLS_SSL_TRUNC_HMAC_DISABLED)
  27527. */
  27528. void mbedtls_ssl_conf_truncated_hmac( mbedtls_ssl_config *conf, int truncate );
  27529. #endif /* MBEDTLS_SSL_TRUNCATED_HMAC */
  27530. #if defined(MBEDTLS_SSL_CBC_RECORD_SPLITTING)
  27531. /**
  27532. * \brief Enable / Disable 1/n-1 record splitting
  27533. * (Default: MBEDTLS_SSL_CBC_RECORD_SPLITTING_ENABLED)
  27534. *
  27535. * \note Only affects SSLv3 and TLS 1.0, not higher versions.
  27536. * Does not affect non-CBC ciphersuites in any version.
  27537. *
  27538. * \param conf SSL configuration
  27539. * \param split MBEDTLS_SSL_CBC_RECORD_SPLITTING_ENABLED or
  27540. * MBEDTLS_SSL_CBC_RECORD_SPLITTING_DISABLED
  27541. */
  27542. void mbedtls_ssl_conf_cbc_record_splitting( mbedtls_ssl_config *conf, char split );
  27543. #endif /* MBEDTLS_SSL_CBC_RECORD_SPLITTING */
  27544. #if defined(MBEDTLS_SSL_SESSION_TICKETS) && defined(MBEDTLS_SSL_CLI_C)
  27545. /**
  27546. * \brief Enable / Disable session tickets (client only).
  27547. * (Default: MBEDTLS_SSL_SESSION_TICKETS_ENABLED.)
  27548. *
  27549. * \note On server, use \c mbedtls_ssl_conf_session_tickets_cb().
  27550. *
  27551. * \param conf SSL configuration
  27552. * \param use_tickets Enable or disable (MBEDTLS_SSL_SESSION_TICKETS_ENABLED or
  27553. * MBEDTLS_SSL_SESSION_TICKETS_DISABLED)
  27554. */
  27555. void mbedtls_ssl_conf_session_tickets( mbedtls_ssl_config *conf, int use_tickets );
  27556. #endif /* MBEDTLS_SSL_SESSION_TICKETS && MBEDTLS_SSL_CLI_C */
  27557. #if defined(MBEDTLS_SSL_RENEGOTIATION)
  27558. /**
  27559. * \brief Enable / Disable renegotiation support for connection when
  27560. * initiated by peer
  27561. * (Default: MBEDTLS_SSL_RENEGOTIATION_DISABLED)
  27562. *
  27563. * \warning It is recommended to always disable renegotation unless you
  27564. * know you need it and you know what you're doing. In the
  27565. * past, there have been several issues associated with
  27566. * renegotiation or a poor understanding of its properties.
  27567. *
  27568. * \note Server-side, enabling renegotiation also makes the server
  27569. * susceptible to a resource DoS by a malicious client.
  27570. *
  27571. * \param conf SSL configuration
  27572. * \param renegotiation Enable or disable (MBEDTLS_SSL_RENEGOTIATION_ENABLED or
  27573. * MBEDTLS_SSL_RENEGOTIATION_DISABLED)
  27574. */
  27575. void mbedtls_ssl_conf_renegotiation( mbedtls_ssl_config *conf, int renegotiation );
  27576. #endif /* MBEDTLS_SSL_RENEGOTIATION */
  27577. /**
  27578. * \brief Prevent or allow legacy renegotiation.
  27579. * (Default: MBEDTLS_SSL_LEGACY_NO_RENEGOTIATION)
  27580. *
  27581. * MBEDTLS_SSL_LEGACY_NO_RENEGOTIATION allows connections to
  27582. * be established even if the peer does not support
  27583. * secure renegotiation, but does not allow renegotiation
  27584. * to take place if not secure.
  27585. * (Interoperable and secure option)
  27586. *
  27587. * MBEDTLS_SSL_LEGACY_ALLOW_RENEGOTIATION allows renegotiations
  27588. * with non-upgraded peers. Allowing legacy renegotiation
  27589. * makes the connection vulnerable to specific man in the
  27590. * middle attacks. (See RFC 5746)
  27591. * (Most interoperable and least secure option)
  27592. *
  27593. * MBEDTLS_SSL_LEGACY_BREAK_HANDSHAKE breaks off connections
  27594. * if peer does not support secure renegotiation. Results
  27595. * in interoperability issues with non-upgraded peers
  27596. * that do not support renegotiation altogether.
  27597. * (Most secure option, interoperability issues)
  27598. *
  27599. * \param conf SSL configuration
  27600. * \param allow_legacy Prevent or allow (SSL_NO_LEGACY_RENEGOTIATION,
  27601. * SSL_ALLOW_LEGACY_RENEGOTIATION or
  27602. * MBEDTLS_SSL_LEGACY_BREAK_HANDSHAKE)
  27603. */
  27604. void mbedtls_ssl_conf_legacy_renegotiation( mbedtls_ssl_config *conf, int allow_legacy );
  27605. #if defined(MBEDTLS_SSL_RENEGOTIATION)
  27606. /**
  27607. * \brief Enforce renegotiation requests.
  27608. * (Default: enforced, max_records = 16)
  27609. *
  27610. * When we request a renegotiation, the peer can comply or
  27611. * ignore the request. This function allows us to decide
  27612. * whether to enforce our renegotiation requests by closing
  27613. * the connection if the peer doesn't comply.
  27614. *
  27615. * However, records could already be in transit from the peer
  27616. * when the request is emitted. In order to increase
  27617. * reliability, we can accept a number of records before the
  27618. * expected handshake records.
  27619. *
  27620. * The optimal value is highly dependent on the specific usage
  27621. * scenario.
  27622. *
  27623. * \note With DTLS and server-initiated renegotiation, the
  27624. * HelloRequest is retransmited every time mbedtls_ssl_read() times
  27625. * out or receives Application Data, until:
  27626. * - max_records records have beens seen, if it is >= 0, or
  27627. * - the number of retransmits that would happen during an
  27628. * actual handshake has been reached.
  27629. * Please remember the request might be lost a few times
  27630. * if you consider setting max_records to a really low value.
  27631. *
  27632. * \warning On client, the grace period can only happen during
  27633. * mbedtls_ssl_read(), as opposed to mbedtls_ssl_write() and mbedtls_ssl_renegotiate()
  27634. * which always behave as if max_record was 0. The reason is,
  27635. * if we receive application data from the server, we need a
  27636. * place to write it, which only happens during mbedtls_ssl_read().
  27637. *
  27638. * \param conf SSL configuration
  27639. * \param max_records Use MBEDTLS_SSL_RENEGOTIATION_NOT_ENFORCED if you don't want to
  27640. * enforce renegotiation, or a non-negative value to enforce
  27641. * it but allow for a grace period of max_records records.
  27642. */
  27643. void mbedtls_ssl_conf_renegotiation_enforced( mbedtls_ssl_config *conf, int max_records );
  27644. /**
  27645. * \brief Set record counter threshold for periodic renegotiation.
  27646. * (Default: 2^48 - 1)
  27647. *
  27648. * Renegotiation is automatically triggered when a record
  27649. * counter (outgoing or incoming) crosses the defined
  27650. * threshold. The default value is meant to prevent the
  27651. * connection from being closed when the counter is about to
  27652. * reached its maximal value (it is not allowed to wrap).
  27653. *
  27654. * Lower values can be used to enforce policies such as "keys
  27655. * must be refreshed every N packets with cipher X".
  27656. *
  27657. * The renegotiation period can be disabled by setting
  27658. * conf->disable_renegotiation to
  27659. * MBEDTLS_SSL_RENEGOTIATION_DISABLED.
  27660. *
  27661. * \note When the configured transport is
  27662. * MBEDTLS_SSL_TRANSPORT_DATAGRAM the maximum renegotiation
  27663. * period is 2^48 - 1, and for MBEDTLS_SSL_TRANSPORT_STREAM,
  27664. * the maximum renegotiation period is 2^64 - 1.
  27665. *
  27666. * \param conf SSL configuration
  27667. * \param period The threshold value: a big-endian 64-bit number.
  27668. */
  27669. void mbedtls_ssl_conf_renegotiation_period( mbedtls_ssl_config *conf,
  27670. const unsigned char period[8] );
  27671. #endif /* MBEDTLS_SSL_RENEGOTIATION */
  27672. /**
  27673. * \brief Check if there is data already read from the
  27674. * underlying transport but not yet processed.
  27675. *
  27676. * \param ssl SSL context
  27677. *
  27678. * \return 0 if nothing's pending, 1 otherwise.
  27679. *
  27680. * \note This is different in purpose and behaviour from
  27681. * \c mbedtls_ssl_get_bytes_avail in that it considers
  27682. * any kind of unprocessed data, not only unread
  27683. * application data. If \c mbedtls_ssl_get_bytes
  27684. * returns a non-zero value, this function will
  27685. * also signal pending data, but the converse does
  27686. * not hold. For example, in DTLS there might be
  27687. * further records waiting to be processed from
  27688. * the current underlying transport's datagram.
  27689. *
  27690. * \note If this function returns 1 (data pending), this
  27691. * does not imply that a subsequent call to
  27692. * \c mbedtls_ssl_read will provide any data;
  27693. * e.g., the unprocessed data might turn out
  27694. * to be an alert or a handshake message.
  27695. *
  27696. * \note This function is useful in the following situation:
  27697. * If the SSL/TLS module successfully returns from an
  27698. * operation - e.g. a handshake or an application record
  27699. * read - and you're awaiting incoming data next, you
  27700. * must not immediately idle on the underlying transport
  27701. * to have data ready, but you need to check the value
  27702. * of this function first. The reason is that the desired
  27703. * data might already be read but not yet processed.
  27704. * If, in contrast, a previous call to the SSL/TLS module
  27705. * returned MBEDTLS_ERR_SSL_WANT_READ, it is not necessary
  27706. * to call this function, as the latter error code entails
  27707. * that all internal data has been processed.
  27708. *
  27709. */
  27710. int mbedtls_ssl_check_pending( const mbedtls_ssl_context *ssl );
  27711. /**
  27712. * \brief Return the number of application data bytes
  27713. * remaining to be read from the current record.
  27714. *
  27715. * \param ssl SSL context
  27716. *
  27717. * \return How many bytes are available in the application
  27718. * data record read buffer.
  27719. *
  27720. * \note When working over a datagram transport, this is
  27721. * useful to detect the current datagram's boundary
  27722. * in case \c mbedtls_ssl_read has written the maximal
  27723. * amount of data fitting into the input buffer.
  27724. *
  27725. */
  27726. size_t mbedtls_ssl_get_bytes_avail( const mbedtls_ssl_context *ssl );
  27727. /**
  27728. * \brief Return the result of the certificate verification
  27729. *
  27730. * \param ssl The SSL context to use.
  27731. *
  27732. * \return \c 0 if the certificate verification was successful.
  27733. * \return \c -1u if the result is not available. This may happen
  27734. * e.g. if the handshake aborts early, or a verification
  27735. * callback returned a fatal error.
  27736. * \return A bitwise combination of \c MBEDTLS_X509_BADCERT_XXX
  27737. * and \c MBEDTLS_X509_BADCRL_XXX failure flags; see x509.h.
  27738. */
  27739. uint32_t mbedtls_ssl_get_verify_result( const mbedtls_ssl_context *ssl );
  27740. /**
  27741. * \brief Return the name of the current ciphersuite
  27742. *
  27743. * \param ssl SSL context
  27744. *
  27745. * \return a string containing the ciphersuite name
  27746. */
  27747. const char *mbedtls_ssl_get_ciphersuite( const mbedtls_ssl_context *ssl );
  27748. /**
  27749. * \brief Return the current SSL version (SSLv3/TLSv1/etc)
  27750. *
  27751. * \param ssl SSL context
  27752. *
  27753. * \return a string containing the SSL version
  27754. */
  27755. const char *mbedtls_ssl_get_version( const mbedtls_ssl_context *ssl );
  27756. /**
  27757. * \brief Return the (maximum) number of bytes added by the record
  27758. * layer: header + encryption/MAC overhead (inc. padding)
  27759. *
  27760. * \note This function is not available (always returns an error)
  27761. * when record compression is enabled.
  27762. *
  27763. * \param ssl SSL context
  27764. *
  27765. * \return Current maximum record expansion in bytes, or
  27766. * MBEDTLS_ERR_SSL_FEATURE_UNAVAILABLE if compression is
  27767. * enabled, which makes expansion much less predictable
  27768. */
  27769. int mbedtls_ssl_get_record_expansion( const mbedtls_ssl_context *ssl );
  27770. #if defined(MBEDTLS_SSL_MAX_FRAGMENT_LENGTH)
  27771. /**
  27772. * \brief Return the maximum fragment length (payload, in bytes) for
  27773. * the output buffer. For the client, this is the configured
  27774. * value. For the server, it is the minimum of two - the
  27775. * configured value and the negotiated one.
  27776. *
  27777. * \sa mbedtls_ssl_conf_max_frag_len()
  27778. * \sa mbedtls_ssl_get_max_record_payload()
  27779. *
  27780. * \param ssl SSL context
  27781. *
  27782. * \return Current maximum fragment length for the output buffer.
  27783. */
  27784. size_t mbedtls_ssl_get_output_max_frag_len( const mbedtls_ssl_context *ssl );
  27785. /**
  27786. * \brief Return the maximum fragment length (payload, in bytes) for
  27787. * the input buffer. This is the negotiated maximum fragment
  27788. * length, or, if there is none, MBEDTLS_SSL_MAX_CONTENT_LEN.
  27789. * If it is not defined either, the value is 2^14. This function
  27790. * works as its predecessor, \c mbedtls_ssl_get_max_frag_len().
  27791. *
  27792. * \sa mbedtls_ssl_conf_max_frag_len()
  27793. * \sa mbedtls_ssl_get_max_record_payload()
  27794. *
  27795. * \param ssl SSL context
  27796. *
  27797. * \return Current maximum fragment length for the output buffer.
  27798. */
  27799. size_t mbedtls_ssl_get_input_max_frag_len( const mbedtls_ssl_context *ssl );
  27800. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  27801. #if defined(MBEDTLS_DEPRECATED_WARNING)
  27802. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  27803. #else
  27804. #define MBEDTLS_DEPRECATED
  27805. #endif
  27806. /**
  27807. * \brief This function is a deprecated approach to getting the max
  27808. * fragment length. Its an alias for
  27809. * \c mbedtls_ssl_get_output_max_frag_len(), as the behaviour
  27810. * is the same. See \c mbedtls_ssl_get_output_max_frag_len() for
  27811. * more detail.
  27812. *
  27813. * \sa mbedtls_ssl_get_input_max_frag_len()
  27814. * \sa mbedtls_ssl_get_output_max_frag_len()
  27815. *
  27816. * \param ssl SSL context
  27817. *
  27818. * \return Current maximum fragment length for the output buffer.
  27819. */
  27820. MBEDTLS_DEPRECATED size_t mbedtls_ssl_get_max_frag_len(
  27821. const mbedtls_ssl_context *ssl );
  27822. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  27823. #endif /* MBEDTLS_SSL_MAX_FRAGMENT_LENGTH */
  27824. /**
  27825. * \brief Return the current maximum outgoing record payload in bytes.
  27826. * This takes into account the config.h setting \c
  27827. * MBEDTLS_SSL_OUT_CONTENT_LEN, the configured and negotiated
  27828. * max fragment length extension if used, and for DTLS the
  27829. * path MTU as configured and current record expansion.
  27830. *
  27831. * \note With DTLS, \c mbedtls_ssl_write() will return an error if
  27832. * called with a larger length value.
  27833. * With TLS, \c mbedtls_ssl_write() will fragment the input if
  27834. * necessary and return the number of bytes written; it is up
  27835. * to the caller to call \c mbedtls_ssl_write() again in
  27836. * order to send the remaining bytes if any.
  27837. *
  27838. * \note This function is not available (always returns an error)
  27839. * when record compression is enabled.
  27840. *
  27841. * \sa mbedtls_ssl_set_mtu()
  27842. * \sa mbedtls_ssl_get_output_max_frag_len()
  27843. * \sa mbedtls_ssl_get_input_max_frag_len()
  27844. * \sa mbedtls_ssl_get_record_expansion()
  27845. *
  27846. * \param ssl SSL context
  27847. *
  27848. * \return Current maximum payload for an outgoing record,
  27849. * or a negative error code.
  27850. */
  27851. int mbedtls_ssl_get_max_out_record_payload( const mbedtls_ssl_context *ssl );
  27852. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  27853. /**
  27854. * \brief Return the peer certificate from the current connection.
  27855. *
  27856. * \param ssl The SSL context to use. This must be initialized and setup.
  27857. *
  27858. * \return The current peer certificate, if available.
  27859. * The returned certificate is owned by the SSL context and
  27860. * is valid only until the next call to the SSL API.
  27861. * \return \c NULL if no peer certificate is available. This might
  27862. * be because the chosen ciphersuite doesn't use CRTs
  27863. * (PSK-based ciphersuites, for example), or because
  27864. * #MBEDTLS_SSL_KEEP_PEER_CERTIFICATE has been disabled,
  27865. * allowing the stack to free the peer's CRT to save memory.
  27866. *
  27867. * \note For one-time inspection of the peer's certificate during
  27868. * the handshake, consider registering an X.509 CRT verification
  27869. * callback through mbedtls_ssl_conf_verify() instead of calling
  27870. * this function. Using mbedtls_ssl_conf_verify() also comes at
  27871. * the benefit of allowing you to influence the verification
  27872. * process, for example by masking expected and tolerated
  27873. * verification failures.
  27874. *
  27875. * \warning You must not use the pointer returned by this function
  27876. * after any further call to the SSL API, including
  27877. * mbedtls_ssl_read() and mbedtls_ssl_write(); this is
  27878. * because the pointer might change during renegotiation,
  27879. * which happens transparently to the user.
  27880. * If you want to use the certificate across API calls,
  27881. * you must make a copy.
  27882. */
  27883. const mbedtls_x509_crt *mbedtls_ssl_get_peer_cert( const mbedtls_ssl_context *ssl );
  27884. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  27885. #if defined(MBEDTLS_SSL_CLI_C)
  27886. /**
  27887. * \brief Save session in order to resume it later (client-side only)
  27888. * Session data is copied to presented session structure.
  27889. *
  27890. *
  27891. * \param ssl SSL context
  27892. * \param session session context
  27893. *
  27894. * \return 0 if successful,
  27895. * MBEDTLS_ERR_SSL_ALLOC_FAILED if memory allocation failed,
  27896. * MBEDTLS_ERR_SSL_BAD_INPUT_DATA if used server-side or
  27897. * arguments are otherwise invalid.
  27898. *
  27899. * \note Only the server certificate is copied, and not the full chain,
  27900. * so you should not attempt to validate the certificate again
  27901. * by calling \c mbedtls_x509_crt_verify() on it.
  27902. * Instead, you should use the results from the verification
  27903. * in the original handshake by calling \c mbedtls_ssl_get_verify_result()
  27904. * after loading the session again into a new SSL context
  27905. * using \c mbedtls_ssl_set_session().
  27906. *
  27907. * \note Once the session object is not needed anymore, you should
  27908. * free it by calling \c mbedtls_ssl_session_free().
  27909. *
  27910. * \sa mbedtls_ssl_set_session()
  27911. */
  27912. int mbedtls_ssl_get_session( const mbedtls_ssl_context *ssl, mbedtls_ssl_session *session );
  27913. #endif /* MBEDTLS_SSL_CLI_C */
  27914. /**
  27915. * \brief Perform the SSL handshake
  27916. *
  27917. * \param ssl SSL context
  27918. *
  27919. * \return \c 0 if successful.
  27920. * \return #MBEDTLS_ERR_SSL_WANT_READ or #MBEDTLS_ERR_SSL_WANT_WRITE
  27921. * if the handshake is incomplete and waiting for data to
  27922. * be available for reading from or writing to the underlying
  27923. * transport - in this case you must call this function again
  27924. * when the underlying transport is ready for the operation.
  27925. * \return #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS if an asynchronous
  27926. * operation is in progress (see
  27927. * mbedtls_ssl_conf_async_private_cb()) - in this case you
  27928. * must call this function again when the operation is ready.
  27929. * \return #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS if a cryptographic
  27930. * operation is in progress (see mbedtls_ecp_set_max_ops()) -
  27931. * in this case you must call this function again to complete
  27932. * the handshake when you're done attending other tasks.
  27933. * \return #MBEDTLS_ERR_SSL_HELLO_VERIFY_REQUIRED if DTLS is in use
  27934. * and the client did not demonstrate reachability yet - in
  27935. * this case you must stop using the context (see below).
  27936. * \return Another SSL error code - in this case you must stop using
  27937. * the context (see below).
  27938. *
  27939. * \warning If this function returns something other than
  27940. * \c 0,
  27941. * #MBEDTLS_ERR_SSL_WANT_READ,
  27942. * #MBEDTLS_ERR_SSL_WANT_WRITE,
  27943. * #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS or
  27944. * #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS,
  27945. * you must stop using the SSL context for reading or writing,
  27946. * and either free it or call \c mbedtls_ssl_session_reset()
  27947. * on it before re-using it for a new connection; the current
  27948. * connection must be closed.
  27949. *
  27950. * \note If DTLS is in use, then you may choose to handle
  27951. * #MBEDTLS_ERR_SSL_HELLO_VERIFY_REQUIRED specially for logging
  27952. * purposes, as it is an expected return value rather than an
  27953. * actual error, but you still need to reset/free the context.
  27954. *
  27955. * \note Remarks regarding event-driven DTLS:
  27956. * If the function returns #MBEDTLS_ERR_SSL_WANT_READ, no datagram
  27957. * from the underlying transport layer is currently being processed,
  27958. * and it is safe to idle until the timer or the underlying transport
  27959. * signal a new event. This is not true for a successful handshake,
  27960. * in which case the datagram of the underlying transport that is
  27961. * currently being processed might or might not contain further
  27962. * DTLS records.
  27963. */
  27964. int mbedtls_ssl_handshake( mbedtls_ssl_context *ssl );
  27965. /**
  27966. * \brief Perform a single step of the SSL handshake
  27967. *
  27968. * \note The state of the context (ssl->state) will be at
  27969. * the next state after this function returns \c 0. Do not
  27970. * call this function if state is MBEDTLS_SSL_HANDSHAKE_OVER.
  27971. *
  27972. * \param ssl SSL context
  27973. *
  27974. * \return See mbedtls_ssl_handshake().
  27975. *
  27976. * \warning If this function returns something other than \c 0,
  27977. * #MBEDTLS_ERR_SSL_WANT_READ, #MBEDTLS_ERR_SSL_WANT_WRITE,
  27978. * #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS or
  27979. * #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS, you must stop using
  27980. * the SSL context for reading or writing, and either free it
  27981. * or call \c mbedtls_ssl_session_reset() on it before
  27982. * re-using it for a new connection; the current connection
  27983. * must be closed.
  27984. */
  27985. int mbedtls_ssl_handshake_step( mbedtls_ssl_context *ssl );
  27986. #if defined(MBEDTLS_SSL_RENEGOTIATION)
  27987. /**
  27988. * \brief Initiate an SSL renegotiation on the running connection.
  27989. * Client: perform the renegotiation right now.
  27990. * Server: request renegotiation, which will be performed
  27991. * during the next call to mbedtls_ssl_read() if honored by
  27992. * client.
  27993. *
  27994. * \param ssl SSL context
  27995. *
  27996. * \return 0 if successful, or any mbedtls_ssl_handshake() return
  27997. * value except #MBEDTLS_ERR_SSL_CLIENT_RECONNECT that can't
  27998. * happen during a renegotiation.
  27999. *
  28000. * \warning If this function returns something other than \c 0,
  28001. * #MBEDTLS_ERR_SSL_WANT_READ, #MBEDTLS_ERR_SSL_WANT_WRITE,
  28002. * #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS or
  28003. * #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS, you must stop using
  28004. * the SSL context for reading or writing, and either free it
  28005. * or call \c mbedtls_ssl_session_reset() on it before
  28006. * re-using it for a new connection; the current connection
  28007. * must be closed.
  28008. *
  28009. */
  28010. int mbedtls_ssl_renegotiate( mbedtls_ssl_context *ssl );
  28011. #endif /* MBEDTLS_SSL_RENEGOTIATION */
  28012. /**
  28013. * \brief Read at most 'len' application data bytes
  28014. *
  28015. * \param ssl SSL context
  28016. * \param buf buffer that will hold the data
  28017. * \param len maximum number of bytes to read
  28018. *
  28019. * \return The (positive) number of bytes read if successful.
  28020. * \return \c 0 if the read end of the underlying transport was closed
  28021. * without sending a CloseNotify beforehand, which might happen
  28022. * because of various reasons (internal error of an underlying
  28023. * stack, non-conformant peer not sending a CloseNotify and
  28024. * such) - in this case you must stop using the context
  28025. * (see below).
  28026. * \return #MBEDTLS_ERR_SSL_PEER_CLOSE_NOTIFY if the underlying
  28027. * transport is still functional, but the peer has
  28028. * acknowledged to not send anything anymore.
  28029. * \return #MBEDTLS_ERR_SSL_WANT_READ or #MBEDTLS_ERR_SSL_WANT_WRITE
  28030. * if the handshake is incomplete and waiting for data to
  28031. * be available for reading from or writing to the underlying
  28032. * transport - in this case you must call this function again
  28033. * when the underlying transport is ready for the operation.
  28034. * \return #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS if an asynchronous
  28035. * operation is in progress (see
  28036. * mbedtls_ssl_conf_async_private_cb()) - in this case you
  28037. * must call this function again when the operation is ready.
  28038. * \return #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS if a cryptographic
  28039. * operation is in progress (see mbedtls_ecp_set_max_ops()) -
  28040. * in this case you must call this function again to complete
  28041. * the handshake when you're done attending other tasks.
  28042. * \return #MBEDTLS_ERR_SSL_CLIENT_RECONNECT if we're at the server
  28043. * side of a DTLS connection and the client is initiating a
  28044. * new connection using the same source port. See below.
  28045. * \return Another SSL error code - in this case you must stop using
  28046. * the context (see below).
  28047. *
  28048. * \warning If this function returns something other than
  28049. * a positive value,
  28050. * #MBEDTLS_ERR_SSL_WANT_READ,
  28051. * #MBEDTLS_ERR_SSL_WANT_WRITE,
  28052. * #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS,
  28053. * #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS or
  28054. * #MBEDTLS_ERR_SSL_CLIENT_RECONNECT,
  28055. * you must stop using the SSL context for reading or writing,
  28056. * and either free it or call \c mbedtls_ssl_session_reset()
  28057. * on it before re-using it for a new connection; the current
  28058. * connection must be closed.
  28059. *
  28060. * \note When this function returns #MBEDTLS_ERR_SSL_CLIENT_RECONNECT
  28061. * (which can only happen server-side), it means that a client
  28062. * is initiating a new connection using the same source port.
  28063. * You can either treat that as a connection close and wait
  28064. * for the client to resend a ClientHello, or directly
  28065. * continue with \c mbedtls_ssl_handshake() with the same
  28066. * context (as it has been reset internally). Either way, you
  28067. * must make sure this is seen by the application as a new
  28068. * connection: application state, if any, should be reset, and
  28069. * most importantly the identity of the client must be checked
  28070. * again. WARNING: not validating the identity of the client
  28071. * again, or not transmitting the new identity to the
  28072. * application layer, would allow authentication bypass!
  28073. *
  28074. * \note Remarks regarding event-driven DTLS:
  28075. * - If the function returns #MBEDTLS_ERR_SSL_WANT_READ, no datagram
  28076. * from the underlying transport layer is currently being processed,
  28077. * and it is safe to idle until the timer or the underlying transport
  28078. * signal a new event.
  28079. * - This function may return MBEDTLS_ERR_SSL_WANT_READ even if data was
  28080. * initially available on the underlying transport, as this data may have
  28081. * been only e.g. duplicated messages or a renegotiation request.
  28082. * Therefore, you must be prepared to receive MBEDTLS_ERR_SSL_WANT_READ even
  28083. * when reacting to an incoming-data event from the underlying transport.
  28084. * - On success, the datagram of the underlying transport that is currently
  28085. * being processed may contain further DTLS records. You should call
  28086. * \c mbedtls_ssl_check_pending to check for remaining records.
  28087. *
  28088. */
  28089. int mbedtls_ssl_read( mbedtls_ssl_context *ssl, unsigned char *buf, size_t len );
  28090. /**
  28091. * \brief Try to write exactly 'len' application data bytes
  28092. *
  28093. * \warning This function will do partial writes in some cases. If the
  28094. * return value is non-negative but less than length, the
  28095. * function must be called again with updated arguments:
  28096. * buf + ret, len - ret (if ret is the return value) until
  28097. * it returns a value equal to the last 'len' argument.
  28098. *
  28099. * \param ssl SSL context
  28100. * \param buf buffer holding the data
  28101. * \param len how many bytes must be written
  28102. *
  28103. * \return The (non-negative) number of bytes actually written if
  28104. * successful (may be less than \p len).
  28105. * \return #MBEDTLS_ERR_SSL_WANT_READ or #MBEDTLS_ERR_SSL_WANT_WRITE
  28106. * if the handshake is incomplete and waiting for data to
  28107. * be available for reading from or writing to the underlying
  28108. * transport - in this case you must call this function again
  28109. * when the underlying transport is ready for the operation.
  28110. * \return #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS if an asynchronous
  28111. * operation is in progress (see
  28112. * mbedtls_ssl_conf_async_private_cb()) - in this case you
  28113. * must call this function again when the operation is ready.
  28114. * \return #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS if a cryptographic
  28115. * operation is in progress (see mbedtls_ecp_set_max_ops()) -
  28116. * in this case you must call this function again to complete
  28117. * the handshake when you're done attending other tasks.
  28118. * \return Another SSL error code - in this case you must stop using
  28119. * the context (see below).
  28120. *
  28121. * \warning If this function returns something other than
  28122. * a non-negative value,
  28123. * #MBEDTLS_ERR_SSL_WANT_READ,
  28124. * #MBEDTLS_ERR_SSL_WANT_WRITE,
  28125. * #MBEDTLS_ERR_SSL_ASYNC_IN_PROGRESS or
  28126. * #MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS,
  28127. * you must stop using the SSL context for reading or writing,
  28128. * and either free it or call \c mbedtls_ssl_session_reset()
  28129. * on it before re-using it for a new connection; the current
  28130. * connection must be closed.
  28131. *
  28132. * \note When this function returns #MBEDTLS_ERR_SSL_WANT_WRITE/READ,
  28133. * it must be called later with the *same* arguments,
  28134. * until it returns a value greater that or equal to 0. When
  28135. * the function returns #MBEDTLS_ERR_SSL_WANT_WRITE there may be
  28136. * some partial data in the output buffer, however this is not
  28137. * yet sent.
  28138. *
  28139. * \note If the requested length is greater than the maximum
  28140. * fragment length (either the built-in limit or the one set
  28141. * or negotiated with the peer), then:
  28142. * - with TLS, less bytes than requested are written.
  28143. * - with DTLS, MBEDTLS_ERR_SSL_BAD_INPUT_DATA is returned.
  28144. * \c mbedtls_ssl_get_output_max_frag_len() may be used to
  28145. * query the active maximum fragment length.
  28146. *
  28147. * \note Attempting to write 0 bytes will result in an empty TLS
  28148. * application record being sent.
  28149. */
  28150. int mbedtls_ssl_write( mbedtls_ssl_context *ssl, const unsigned char *buf, size_t len );
  28151. /**
  28152. * \brief Send an alert message
  28153. *
  28154. * \param ssl SSL context
  28155. * \param level The alert level of the message
  28156. * (MBEDTLS_SSL_ALERT_LEVEL_WARNING or MBEDTLS_SSL_ALERT_LEVEL_FATAL)
  28157. * \param message The alert message (SSL_ALERT_MSG_*)
  28158. *
  28159. * \return 0 if successful, or a specific SSL error code.
  28160. *
  28161. * \note If this function returns something other than 0 or
  28162. * MBEDTLS_ERR_SSL_WANT_READ/WRITE, you must stop using
  28163. * the SSL context for reading or writing, and either free it or
  28164. * call \c mbedtls_ssl_session_reset() on it before re-using it
  28165. * for a new connection; the current connection must be closed.
  28166. */
  28167. int mbedtls_ssl_send_alert_message( mbedtls_ssl_context *ssl,
  28168. unsigned char level,
  28169. unsigned char message );
  28170. /**
  28171. * \brief Notify the peer that the connection is being closed
  28172. *
  28173. * \param ssl SSL context
  28174. *
  28175. * \return 0 if successful, or a specific SSL error code.
  28176. *
  28177. * \note If this function returns something other than 0 or
  28178. * MBEDTLS_ERR_SSL_WANT_READ/WRITE, you must stop using
  28179. * the SSL context for reading or writing, and either free it or
  28180. * call \c mbedtls_ssl_session_reset() on it before re-using it
  28181. * for a new connection; the current connection must be closed.
  28182. */
  28183. int mbedtls_ssl_close_notify( mbedtls_ssl_context *ssl );
  28184. /**
  28185. * \brief Free referenced items in an SSL context and clear memory
  28186. *
  28187. * \param ssl SSL context
  28188. */
  28189. void mbedtls_ssl_free( mbedtls_ssl_context *ssl );
  28190. #if defined(MBEDTLS_SSL_CONTEXT_SERIALIZATION)
  28191. /**
  28192. * \brief Save an active connection as serialized data in a buffer.
  28193. * This allows the freeing or re-using of the SSL context
  28194. * while still picking up the connection later in a way that
  28195. * it entirely transparent to the peer.
  28196. *
  28197. * \see mbedtls_ssl_context_load()
  28198. *
  28199. * \note This feature is currently only available under certain
  28200. * conditions, see the documentation of the return value
  28201. * #MBEDTLS_ERR_SSL_BAD_INPUT_DATA for details.
  28202. *
  28203. * \note When this function succeeds, it calls
  28204. * mbedtls_ssl_session_reset() on \p ssl which as a result is
  28205. * no longer associated with the connection that has been
  28206. * serialized. This avoids creating copies of the connection
  28207. * state. You're then free to either re-use the context
  28208. * structure for a different connection, or call
  28209. * mbedtls_ssl_free() on it. See the documentation of
  28210. * mbedtls_ssl_session_reset() for more details.
  28211. *
  28212. * \param ssl The SSL context to save. On success, it is no longer
  28213. * associated with the connection that has been serialized.
  28214. * \param buf The buffer to write the serialized data to. It must be a
  28215. * writeable buffer of at least \p buf_len bytes, or may be \c
  28216. * NULL if \p buf_len is \c 0.
  28217. * \param buf_len The number of bytes available for writing in \p buf.
  28218. * \param olen The size in bytes of the data that has been or would have
  28219. * been written. It must point to a valid \c size_t.
  28220. *
  28221. * \note \p olen is updated to the correct value regardless of
  28222. * whether \p buf_len was large enough. This makes it possible
  28223. * to determine the necessary size by calling this function
  28224. * with \p buf set to \c NULL and \p buf_len to \c 0. However,
  28225. * the value of \p olen is only guaranteed to be correct when
  28226. * the function returns #MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL or
  28227. * \c 0. If the return value is different, then the value of
  28228. * \p olen is undefined.
  28229. *
  28230. * \return \c 0 if successful.
  28231. * \return #MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL if \p buf is too small.
  28232. * \return #MBEDTLS_ERR_SSL_ALLOC_FAILED if memory allocation failed
  28233. * while reseting the context.
  28234. * \return #MBEDTLS_ERR_SSL_BAD_INPUT_DATA if a handshake is in
  28235. * progress, or there is pending data for reading or sending,
  28236. * or the connection does not use DTLS 1.2 with an AEAD
  28237. * ciphersuite, or renegotiation is enabled.
  28238. */
  28239. int mbedtls_ssl_context_save( mbedtls_ssl_context *ssl,
  28240. unsigned char *buf,
  28241. size_t buf_len,
  28242. size_t *olen );
  28243. /**
  28244. * \brief Load serialized connection data to an SSL context.
  28245. *
  28246. * \see mbedtls_ssl_context_save()
  28247. *
  28248. * \warning The same serialized data must never be loaded into more
  28249. * that one context. In order to ensure that, after
  28250. * successfully loading serialized data to an SSL context, you
  28251. * should immediately destroy or invalidate all copies of the
  28252. * serialized data that was loaded. Loading the same data in
  28253. * more than one context would cause severe security failures
  28254. * including but not limited to loss of confidentiality.
  28255. *
  28256. * \note Before calling this function, the SSL context must be
  28257. * prepared in one of the two following ways. The first way is
  28258. * to take a context freshly initialised with
  28259. * mbedtls_ssl_init() and call mbedtls_ssl_setup() on it with
  28260. * the same ::mbedtls_ssl_config structure that was used in
  28261. * the original connection. The second way is to
  28262. * call mbedtls_ssl_session_reset() on a context that was
  28263. * previously prepared as above but used in the meantime.
  28264. * Either way, you must not use the context to perform a
  28265. * handshake between calling mbedtls_ssl_setup() or
  28266. * mbedtls_ssl_session_reset() and calling this function. You
  28267. * may however call other setter functions in that time frame
  28268. * as indicated in the note below.
  28269. *
  28270. * \note Before or after calling this function successfully, you
  28271. * also need to configure some connection-specific callbacks
  28272. * and settings before you can use the connection again
  28273. * (unless they were already set before calling
  28274. * mbedtls_ssl_session_reset() and the values are suitable for
  28275. * the present connection). Specifically, you want to call
  28276. * at least mbedtls_ssl_set_bio() and
  28277. * mbedtls_ssl_set_timer_cb(). All other SSL setter functions
  28278. * are not necessary to call, either because they're only used
  28279. * in handshakes, or because the setting is already saved. You
  28280. * might choose to call them anyway, for example in order to
  28281. * share code between the cases of establishing a new
  28282. * connection and the case of loading an already-established
  28283. * connection.
  28284. *
  28285. * \note If you have new information about the path MTU, you want to
  28286. * call mbedtls_ssl_set_mtu() after calling this function, as
  28287. * otherwise this function would overwrite your
  28288. * newly-configured value with the value that was active when
  28289. * the context was saved.
  28290. *
  28291. * \note When this function returns an error code, it calls
  28292. * mbedtls_ssl_free() on \p ssl. In this case, you need to
  28293. * prepare the context with the usual sequence starting with a
  28294. * call to mbedtls_ssl_init() if you want to use it again.
  28295. *
  28296. * \param ssl The SSL context structure to be populated. It must have
  28297. * been prepared as described in the note above.
  28298. * \param buf The buffer holding the serialized connection data. It must
  28299. * be a readable buffer of at least \p len bytes.
  28300. * \param len The size of the serialized data in bytes.
  28301. *
  28302. * \return \c 0 if successful.
  28303. * \return #MBEDTLS_ERR_SSL_ALLOC_FAILED if memory allocation failed.
  28304. * \return #MBEDTLS_ERR_SSL_VERSION_MISMATCH if the serialized data
  28305. * comes from a different Mbed TLS version or build.
  28306. * \return #MBEDTLS_ERR_SSL_BAD_INPUT_DATA if input data is invalid.
  28307. */
  28308. int mbedtls_ssl_context_load( mbedtls_ssl_context *ssl,
  28309. const unsigned char *buf,
  28310. size_t len );
  28311. #endif /* MBEDTLS_SSL_CONTEXT_SERIALIZATION */
  28312. /**
  28313. * \brief Initialize an SSL configuration context
  28314. * Just makes the context ready for
  28315. * mbedtls_ssl_config_defaults() or mbedtls_ssl_config_free().
  28316. *
  28317. * \note You need to call mbedtls_ssl_config_defaults() unless you
  28318. * manually set all of the relevant fields yourself.
  28319. *
  28320. * \param conf SSL configuration context
  28321. */
  28322. void mbedtls_ssl_config_init( mbedtls_ssl_config *conf );
  28323. /**
  28324. * \brief Load reasonnable default SSL configuration values.
  28325. * (You need to call mbedtls_ssl_config_init() first.)
  28326. *
  28327. * \param conf SSL configuration context
  28328. * \param endpoint MBEDTLS_SSL_IS_CLIENT or MBEDTLS_SSL_IS_SERVER
  28329. * \param transport MBEDTLS_SSL_TRANSPORT_STREAM for TLS, or
  28330. * MBEDTLS_SSL_TRANSPORT_DATAGRAM for DTLS
  28331. * \param preset a MBEDTLS_SSL_PRESET_XXX value
  28332. *
  28333. * \note See \c mbedtls_ssl_conf_transport() for notes on DTLS.
  28334. *
  28335. * \return 0 if successful, or
  28336. * MBEDTLS_ERR_XXX_ALLOC_FAILED on memory allocation error.
  28337. */
  28338. int mbedtls_ssl_config_defaults( mbedtls_ssl_config *conf,
  28339. int endpoint, int transport, int preset );
  28340. /**
  28341. * \brief Free an SSL configuration context
  28342. *
  28343. * \param conf SSL configuration context
  28344. */
  28345. void mbedtls_ssl_config_free( mbedtls_ssl_config *conf );
  28346. /**
  28347. * \brief Initialize SSL session structure
  28348. *
  28349. * \param session SSL session
  28350. */
  28351. void mbedtls_ssl_session_init( mbedtls_ssl_session *session );
  28352. /**
  28353. * \brief Free referenced items in an SSL session including the
  28354. * peer certificate and clear memory
  28355. *
  28356. * \note A session object can be freed even if the SSL context
  28357. * that was used to retrieve the session is still in use.
  28358. *
  28359. * \param session SSL session
  28360. */
  28361. void mbedtls_ssl_session_free( mbedtls_ssl_session *session );
  28362. /**
  28363. * \brief TLS-PRF function for key derivation.
  28364. *
  28365. * \param prf The tls_prf type function type to be used.
  28366. * \param secret Secret for the key derivation function.
  28367. * \param slen Length of the secret.
  28368. * \param label String label for the key derivation function,
  28369. * terminated with null character.
  28370. * \param random Random bytes.
  28371. * \param rlen Length of the random bytes buffer.
  28372. * \param dstbuf The buffer holding the derived key.
  28373. * \param dlen Length of the output buffer.
  28374. *
  28375. * \return 0 on success. An SSL specific error on failure.
  28376. */
  28377. int mbedtls_ssl_tls_prf( const mbedtls_tls_prf_types prf,
  28378. const unsigned char *secret, size_t slen,
  28379. const char *label,
  28380. const unsigned char *random, size_t rlen,
  28381. unsigned char *dstbuf, size_t dlen );
  28382. #ifdef __cplusplus
  28383. }
  28384. #endif
  28385. #endif /* ssl.h */
  28386. /********* Start of file include/mbedtls/ssl_cookie.h ************/
  28387. /**
  28388. * \file ssl_cookie.h
  28389. *
  28390. * \brief DTLS cookie callbacks implementation
  28391. */
  28392. /*
  28393. * Copyright The Mbed TLS Contributors
  28394. * SPDX-License-Identifier: Apache-2.0
  28395. *
  28396. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  28397. * not use this file except in compliance with the License.
  28398. * You may obtain a copy of the License at
  28399. *
  28400. * http://www.apache.org/licenses/LICENSE-2.0
  28401. *
  28402. * Unless required by applicable law or agreed to in writing, software
  28403. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  28404. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  28405. * See the License for the specific language governing permissions and
  28406. * limitations under the License.
  28407. */
  28408. #ifndef MBEDTLS_SSL_COOKIE_H
  28409. #define MBEDTLS_SSL_COOKIE_H
  28410. #if !defined(MBEDTLS_CONFIG_FILE)
  28411. #else
  28412. #endif
  28413. #if defined(MBEDTLS_THREADING_C)
  28414. #endif
  28415. /**
  28416. * \name SECTION: Module settings
  28417. *
  28418. * The configuration options you can set for this module are in this section.
  28419. * Either change them in config.h or define them on the compiler command line.
  28420. * \{
  28421. */
  28422. #ifndef MBEDTLS_SSL_COOKIE_TIMEOUT
  28423. #define MBEDTLS_SSL_COOKIE_TIMEOUT 60 /**< Default expiration delay of DTLS cookies, in seconds if HAVE_TIME, or in number of cookies issued */
  28424. #endif
  28425. /* \} name SECTION: Module settings */
  28426. #ifdef __cplusplus
  28427. extern "C" {
  28428. #endif
  28429. /**
  28430. * \brief Context for the default cookie functions.
  28431. */
  28432. typedef struct mbedtls_ssl_cookie_ctx
  28433. {
  28434. mbedtls_md_context_t hmac_ctx; /*!< context for the HMAC portion */
  28435. #if !defined(MBEDTLS_HAVE_TIME)
  28436. unsigned long serial; /*!< serial number for expiration */
  28437. #endif
  28438. unsigned long timeout; /*!< timeout delay, in seconds if HAVE_TIME,
  28439. or in number of tickets issued */
  28440. #if defined(MBEDTLS_THREADING_C)
  28441. mbedtls_threading_mutex_t mutex;
  28442. #endif
  28443. } mbedtls_ssl_cookie_ctx;
  28444. /**
  28445. * \brief Initialize cookie context
  28446. */
  28447. void mbedtls_ssl_cookie_init( mbedtls_ssl_cookie_ctx *ctx );
  28448. /**
  28449. * \brief Setup cookie context (generate keys)
  28450. */
  28451. int mbedtls_ssl_cookie_setup( mbedtls_ssl_cookie_ctx *ctx,
  28452. int (*f_rng)(void *, unsigned char *, size_t),
  28453. void *p_rng );
  28454. /**
  28455. * \brief Set expiration delay for cookies
  28456. * (Default MBEDTLS_SSL_COOKIE_TIMEOUT)
  28457. *
  28458. * \param ctx Cookie contex
  28459. * \param delay Delay, in seconds if HAVE_TIME, or in number of cookies
  28460. * issued in the meantime.
  28461. * 0 to disable expiration (NOT recommended)
  28462. */
  28463. void mbedtls_ssl_cookie_set_timeout( mbedtls_ssl_cookie_ctx *ctx, unsigned long delay );
  28464. /**
  28465. * \brief Free cookie context
  28466. */
  28467. void mbedtls_ssl_cookie_free( mbedtls_ssl_cookie_ctx *ctx );
  28468. /**
  28469. * \brief Generate cookie, see \c mbedtls_ssl_cookie_write_t
  28470. */
  28471. mbedtls_ssl_cookie_write_t mbedtls_ssl_cookie_write;
  28472. /**
  28473. * \brief Verify cookie, see \c mbedtls_ssl_cookie_write_t
  28474. */
  28475. mbedtls_ssl_cookie_check_t mbedtls_ssl_cookie_check;
  28476. #ifdef __cplusplus
  28477. }
  28478. #endif
  28479. #endif /* ssl_cookie.h */
  28480. /********* Start of file include/mbedtls/ssl_internal.h ************/
  28481. /**
  28482. * \file ssl_internal.h
  28483. *
  28484. * \brief Internal functions shared by the SSL modules
  28485. */
  28486. /*
  28487. * Copyright The Mbed TLS Contributors
  28488. * SPDX-License-Identifier: Apache-2.0
  28489. *
  28490. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  28491. * not use this file except in compliance with the License.
  28492. * You may obtain a copy of the License at
  28493. *
  28494. * http://www.apache.org/licenses/LICENSE-2.0
  28495. *
  28496. * Unless required by applicable law or agreed to in writing, software
  28497. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  28498. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  28499. * See the License for the specific language governing permissions and
  28500. * limitations under the License.
  28501. */
  28502. #ifndef MBEDTLS_SSL_INTERNAL_H
  28503. #define MBEDTLS_SSL_INTERNAL_H
  28504. #if !defined(MBEDTLS_CONFIG_FILE)
  28505. #else
  28506. #endif
  28507. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  28508. #endif
  28509. #if defined(MBEDTLS_MD5_C)
  28510. #endif
  28511. #if defined(MBEDTLS_SHA1_C)
  28512. #endif
  28513. #if defined(MBEDTLS_SHA256_C)
  28514. #endif
  28515. #if defined(MBEDTLS_SHA512_C)
  28516. #endif
  28517. #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED)
  28518. #endif
  28519. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  28520. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  28521. #if ( defined(__ARMCC_VERSION) || defined(_MSC_VER) ) && \
  28522. !defined(inline) && !defined(__cplusplus)
  28523. #define inline __inline
  28524. #endif
  28525. /* Determine minimum supported version */
  28526. #define MBEDTLS_SSL_MIN_MAJOR_VERSION MBEDTLS_SSL_MAJOR_VERSION_3
  28527. #if defined(MBEDTLS_SSL_PROTO_SSL3)
  28528. #define MBEDTLS_SSL_MIN_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_0
  28529. #else
  28530. #if defined(MBEDTLS_SSL_PROTO_TLS1)
  28531. #define MBEDTLS_SSL_MIN_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_1
  28532. #else
  28533. #if defined(MBEDTLS_SSL_PROTO_TLS1_1)
  28534. #define MBEDTLS_SSL_MIN_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_2
  28535. #else
  28536. #if defined(MBEDTLS_SSL_PROTO_TLS1_2)
  28537. #define MBEDTLS_SSL_MIN_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_3
  28538. #endif /* MBEDTLS_SSL_PROTO_TLS1_2 */
  28539. #endif /* MBEDTLS_SSL_PROTO_TLS1_1 */
  28540. #endif /* MBEDTLS_SSL_PROTO_TLS1 */
  28541. #endif /* MBEDTLS_SSL_PROTO_SSL3 */
  28542. #define MBEDTLS_SSL_MIN_VALID_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_1
  28543. #define MBEDTLS_SSL_MIN_VALID_MAJOR_VERSION MBEDTLS_SSL_MAJOR_VERSION_3
  28544. /* Determine maximum supported version */
  28545. #define MBEDTLS_SSL_MAX_MAJOR_VERSION MBEDTLS_SSL_MAJOR_VERSION_3
  28546. #if defined(MBEDTLS_SSL_PROTO_TLS1_2)
  28547. #define MBEDTLS_SSL_MAX_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_3
  28548. #else
  28549. #if defined(MBEDTLS_SSL_PROTO_TLS1_1)
  28550. #define MBEDTLS_SSL_MAX_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_2
  28551. #else
  28552. #if defined(MBEDTLS_SSL_PROTO_TLS1)
  28553. #define MBEDTLS_SSL_MAX_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_1
  28554. #else
  28555. #if defined(MBEDTLS_SSL_PROTO_SSL3)
  28556. #define MBEDTLS_SSL_MAX_MINOR_VERSION MBEDTLS_SSL_MINOR_VERSION_0
  28557. #endif /* MBEDTLS_SSL_PROTO_SSL3 */
  28558. #endif /* MBEDTLS_SSL_PROTO_TLS1 */
  28559. #endif /* MBEDTLS_SSL_PROTO_TLS1_1 */
  28560. #endif /* MBEDTLS_SSL_PROTO_TLS1_2 */
  28561. /* Shorthand for restartable ECC */
  28562. #if defined(MBEDTLS_ECP_RESTARTABLE) && \
  28563. defined(MBEDTLS_SSL_CLI_C) && \
  28564. defined(MBEDTLS_SSL_PROTO_TLS1_2) && \
  28565. defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED)
  28566. #define MBEDTLS_SSL_ECP_RESTARTABLE_ENABLED
  28567. #endif
  28568. #define MBEDTLS_SSL_INITIAL_HANDSHAKE 0
  28569. #define MBEDTLS_SSL_RENEGOTIATION_IN_PROGRESS 1 /* In progress */
  28570. #define MBEDTLS_SSL_RENEGOTIATION_DONE 2 /* Done or aborted */
  28571. #define MBEDTLS_SSL_RENEGOTIATION_PENDING 3 /* Requested (server only) */
  28572. /*
  28573. * DTLS retransmission states, see RFC 6347 4.2.4
  28574. *
  28575. * The SENDING state is merged in PREPARING for initial sends,
  28576. * but is distinct for resends.
  28577. *
  28578. * Note: initial state is wrong for server, but is not used anyway.
  28579. */
  28580. #define MBEDTLS_SSL_RETRANS_PREPARING 0
  28581. #define MBEDTLS_SSL_RETRANS_SENDING 1
  28582. #define MBEDTLS_SSL_RETRANS_WAITING 2
  28583. #define MBEDTLS_SSL_RETRANS_FINISHED 3
  28584. /*
  28585. * Allow extra bytes for record, authentication and encryption overhead:
  28586. * counter (8) + header (5) + IV(16) + MAC (16-48) + padding (0-256)
  28587. * and allow for a maximum of 1024 of compression expansion if
  28588. * enabled.
  28589. */
  28590. #if defined(MBEDTLS_ZLIB_SUPPORT)
  28591. #define MBEDTLS_SSL_COMPRESSION_ADD 1024
  28592. #else
  28593. #define MBEDTLS_SSL_COMPRESSION_ADD 0
  28594. #endif
  28595. /* This macro determines whether CBC is supported. */
  28596. #if defined(MBEDTLS_CIPHER_MODE_CBC) && \
  28597. ( defined(MBEDTLS_AES_C) || \
  28598. defined(MBEDTLS_CAMELLIA_C) || \
  28599. defined(MBEDTLS_ARIA_C) || \
  28600. defined(MBEDTLS_DES_C) )
  28601. #define MBEDTLS_SSL_SOME_SUITES_USE_CBC
  28602. #endif
  28603. /* This macro determines whether the CBC construct used in TLS 1.0-1.2 (as
  28604. * opposed to the very different CBC construct used in SSLv3) is supported. */
  28605. #if defined(MBEDTLS_SSL_SOME_SUITES_USE_CBC) && \
  28606. ( defined(MBEDTLS_SSL_PROTO_TLS1) || \
  28607. defined(MBEDTLS_SSL_PROTO_TLS1_1) || \
  28608. defined(MBEDTLS_SSL_PROTO_TLS1_2) )
  28609. #define MBEDTLS_SSL_SOME_SUITES_USE_TLS_CBC
  28610. #endif
  28611. #if defined(MBEDTLS_ARC4_C) || defined(MBEDTLS_CIPHER_NULL_CIPHER) || \
  28612. defined(MBEDTLS_SSL_SOME_SUITES_USE_CBC)
  28613. #define MBEDTLS_SSL_SOME_MODES_USE_MAC
  28614. #endif
  28615. #if defined(MBEDTLS_SSL_SOME_MODES_USE_MAC)
  28616. /* Ciphersuites using HMAC */
  28617. #if defined(MBEDTLS_SHA512_C)
  28618. #define MBEDTLS_SSL_MAC_ADD 48 /* SHA-384 used for HMAC */
  28619. #elif defined(MBEDTLS_SHA256_C)
  28620. #define MBEDTLS_SSL_MAC_ADD 32 /* SHA-256 used for HMAC */
  28621. #else
  28622. #define MBEDTLS_SSL_MAC_ADD 20 /* SHA-1 used for HMAC */
  28623. #endif
  28624. #else /* MBEDTLS_SSL_SOME_MODES_USE_MAC */
  28625. /* AEAD ciphersuites: GCM and CCM use a 128 bits tag */
  28626. #define MBEDTLS_SSL_MAC_ADD 16
  28627. #endif
  28628. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  28629. #define MBEDTLS_SSL_PADDING_ADD 256
  28630. #else
  28631. #define MBEDTLS_SSL_PADDING_ADD 0
  28632. #endif
  28633. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  28634. #define MBEDTLS_SSL_MAX_CID_EXPANSION MBEDTLS_SSL_CID_PADDING_GRANULARITY
  28635. #else
  28636. #define MBEDTLS_SSL_MAX_CID_EXPANSION 0
  28637. #endif
  28638. #define MBEDTLS_SSL_PAYLOAD_OVERHEAD ( MBEDTLS_SSL_COMPRESSION_ADD + \
  28639. MBEDTLS_MAX_IV_LENGTH + \
  28640. MBEDTLS_SSL_MAC_ADD + \
  28641. MBEDTLS_SSL_PADDING_ADD + \
  28642. MBEDTLS_SSL_MAX_CID_EXPANSION \
  28643. )
  28644. #define MBEDTLS_SSL_IN_PAYLOAD_LEN ( MBEDTLS_SSL_PAYLOAD_OVERHEAD + \
  28645. ( MBEDTLS_SSL_IN_CONTENT_LEN ) )
  28646. #define MBEDTLS_SSL_OUT_PAYLOAD_LEN ( MBEDTLS_SSL_PAYLOAD_OVERHEAD + \
  28647. ( MBEDTLS_SSL_OUT_CONTENT_LEN ) )
  28648. /* The maximum number of buffered handshake messages. */
  28649. #define MBEDTLS_SSL_MAX_BUFFERED_HS 4
  28650. /* Maximum length we can advertise as our max content length for
  28651. RFC 6066 max_fragment_length extension negotiation purposes
  28652. (the lesser of both sizes, if they are unequal.)
  28653. */
  28654. #define MBEDTLS_TLS_EXT_ADV_CONTENT_LEN ( \
  28655. (MBEDTLS_SSL_IN_CONTENT_LEN > MBEDTLS_SSL_OUT_CONTENT_LEN) \
  28656. ? ( MBEDTLS_SSL_OUT_CONTENT_LEN ) \
  28657. : ( MBEDTLS_SSL_IN_CONTENT_LEN ) \
  28658. )
  28659. /* Maximum size in bytes of list in sig-hash algorithm ext., RFC 5246 */
  28660. #define MBEDTLS_SSL_MAX_SIG_HASH_ALG_LIST_LEN 65534
  28661. /* Maximum size in bytes of list in supported elliptic curve ext., RFC 4492 */
  28662. #define MBEDTLS_SSL_MAX_CURVE_LIST_LEN 65535
  28663. /*
  28664. * Check that we obey the standard's message size bounds
  28665. */
  28666. #if MBEDTLS_SSL_MAX_CONTENT_LEN > 16384
  28667. #error "Bad configuration - record content too large."
  28668. #endif
  28669. #if MBEDTLS_SSL_IN_CONTENT_LEN > MBEDTLS_SSL_MAX_CONTENT_LEN
  28670. #error "Bad configuration - incoming record content should not be larger than MBEDTLS_SSL_MAX_CONTENT_LEN."
  28671. #endif
  28672. #if MBEDTLS_SSL_OUT_CONTENT_LEN > MBEDTLS_SSL_MAX_CONTENT_LEN
  28673. #error "Bad configuration - outgoing record content should not be larger than MBEDTLS_SSL_MAX_CONTENT_LEN."
  28674. #endif
  28675. #if MBEDTLS_SSL_IN_PAYLOAD_LEN > MBEDTLS_SSL_MAX_CONTENT_LEN + 2048
  28676. #error "Bad configuration - incoming protected record payload too large."
  28677. #endif
  28678. #if MBEDTLS_SSL_OUT_PAYLOAD_LEN > MBEDTLS_SSL_MAX_CONTENT_LEN + 2048
  28679. #error "Bad configuration - outgoing protected record payload too large."
  28680. #endif
  28681. /* Calculate buffer sizes */
  28682. /* Note: Even though the TLS record header is only 5 bytes
  28683. long, we're internally using 8 bytes to store the
  28684. implicit sequence number. */
  28685. #define MBEDTLS_SSL_HEADER_LEN 13
  28686. #if !defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  28687. #define MBEDTLS_SSL_IN_BUFFER_LEN \
  28688. ( ( MBEDTLS_SSL_HEADER_LEN ) + ( MBEDTLS_SSL_IN_PAYLOAD_LEN ) )
  28689. #else
  28690. #define MBEDTLS_SSL_IN_BUFFER_LEN \
  28691. ( ( MBEDTLS_SSL_HEADER_LEN ) + ( MBEDTLS_SSL_IN_PAYLOAD_LEN ) \
  28692. + ( MBEDTLS_SSL_CID_IN_LEN_MAX ) )
  28693. #endif
  28694. #if !defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  28695. #define MBEDTLS_SSL_OUT_BUFFER_LEN \
  28696. ( ( MBEDTLS_SSL_HEADER_LEN ) + ( MBEDTLS_SSL_OUT_PAYLOAD_LEN ) )
  28697. #else
  28698. #define MBEDTLS_SSL_OUT_BUFFER_LEN \
  28699. ( ( MBEDTLS_SSL_HEADER_LEN ) + ( MBEDTLS_SSL_OUT_PAYLOAD_LEN ) \
  28700. + ( MBEDTLS_SSL_CID_OUT_LEN_MAX ) )
  28701. #endif
  28702. #if defined(MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH)
  28703. static inline size_t mbedtls_ssl_get_output_buflen( const mbedtls_ssl_context *ctx )
  28704. {
  28705. #if defined (MBEDTLS_SSL_DTLS_CONNECTION_ID)
  28706. return mbedtls_ssl_get_output_max_frag_len( ctx )
  28707. + MBEDTLS_SSL_HEADER_LEN + MBEDTLS_SSL_PAYLOAD_OVERHEAD
  28708. + MBEDTLS_SSL_CID_OUT_LEN_MAX;
  28709. #else
  28710. return mbedtls_ssl_get_output_max_frag_len( ctx )
  28711. + MBEDTLS_SSL_HEADER_LEN + MBEDTLS_SSL_PAYLOAD_OVERHEAD;
  28712. #endif
  28713. }
  28714. static inline size_t mbedtls_ssl_get_input_buflen( const mbedtls_ssl_context *ctx )
  28715. {
  28716. #if defined (MBEDTLS_SSL_DTLS_CONNECTION_ID)
  28717. return mbedtls_ssl_get_input_max_frag_len( ctx )
  28718. + MBEDTLS_SSL_HEADER_LEN + MBEDTLS_SSL_PAYLOAD_OVERHEAD
  28719. + MBEDTLS_SSL_CID_IN_LEN_MAX;
  28720. #else
  28721. return mbedtls_ssl_get_input_max_frag_len( ctx )
  28722. + MBEDTLS_SSL_HEADER_LEN + MBEDTLS_SSL_PAYLOAD_OVERHEAD;
  28723. #endif
  28724. }
  28725. #endif
  28726. #ifdef MBEDTLS_ZLIB_SUPPORT
  28727. /* Compression buffer holds both IN and OUT buffers, so should be size of the larger */
  28728. #define MBEDTLS_SSL_COMPRESS_BUFFER_LEN ( \
  28729. ( MBEDTLS_SSL_IN_BUFFER_LEN > MBEDTLS_SSL_OUT_BUFFER_LEN ) \
  28730. ? MBEDTLS_SSL_IN_BUFFER_LEN \
  28731. : MBEDTLS_SSL_OUT_BUFFER_LEN \
  28732. )
  28733. #endif
  28734. /*
  28735. * TLS extension flags (for extensions with outgoing ServerHello content
  28736. * that need it (e.g. for RENEGOTIATION_INFO the server already knows because
  28737. * of state of the renegotiation flag, so no indicator is required)
  28738. */
  28739. #define MBEDTLS_TLS_EXT_SUPPORTED_POINT_FORMATS_PRESENT (1 << 0)
  28740. #define MBEDTLS_TLS_EXT_ECJPAKE_KKPP_OK (1 << 1)
  28741. /**
  28742. * \brief This function checks if the remaining size in a buffer is
  28743. * greater or equal than a needed space.
  28744. *
  28745. * \param cur Pointer to the current position in the buffer.
  28746. * \param end Pointer to one past the end of the buffer.
  28747. * \param need Needed space in bytes.
  28748. *
  28749. * \return Zero if the needed space is available in the buffer, non-zero
  28750. * otherwise.
  28751. */
  28752. static inline int mbedtls_ssl_chk_buf_ptr( const uint8_t *cur,
  28753. const uint8_t *end, size_t need )
  28754. {
  28755. return( ( cur > end ) || ( need > (size_t)( end - cur ) ) );
  28756. }
  28757. /**
  28758. * \brief This macro checks if the remaining size in a buffer is
  28759. * greater or equal than a needed space. If it is not the case,
  28760. * it returns an SSL_BUFFER_TOO_SMALL error.
  28761. *
  28762. * \param cur Pointer to the current position in the buffer.
  28763. * \param end Pointer to one past the end of the buffer.
  28764. * \param need Needed space in bytes.
  28765. *
  28766. */
  28767. #define MBEDTLS_SSL_CHK_BUF_PTR( cur, end, need ) \
  28768. do { \
  28769. if( mbedtls_ssl_chk_buf_ptr( ( cur ), ( end ), ( need ) ) != 0 ) \
  28770. { \
  28771. return( MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL ); \
  28772. } \
  28773. } while( 0 )
  28774. #ifdef __cplusplus
  28775. extern "C" {
  28776. #endif
  28777. #if defined(MBEDTLS_SSL_PROTO_TLS1_2) && \
  28778. defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED)
  28779. /*
  28780. * Abstraction for a grid of allowed signature-hash-algorithm pairs.
  28781. */
  28782. struct mbedtls_ssl_sig_hash_set_t
  28783. {
  28784. /* At the moment, we only need to remember a single suitable
  28785. * hash algorithm per signature algorithm. As long as that's
  28786. * the case - and we don't need a general lookup function -
  28787. * we can implement the sig-hash-set as a map from signatures
  28788. * to hash algorithms. */
  28789. mbedtls_md_type_t rsa;
  28790. mbedtls_md_type_t ecdsa;
  28791. };
  28792. #endif /* MBEDTLS_SSL_PROTO_TLS1_2 &&
  28793. MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED */
  28794. typedef int mbedtls_ssl_tls_prf_cb( const unsigned char *secret, size_t slen,
  28795. const char *label,
  28796. const unsigned char *random, size_t rlen,
  28797. unsigned char *dstbuf, size_t dlen );
  28798. /* cipher.h exports the maximum IV, key and block length from
  28799. * all ciphers enabled in the config, regardless of whether those
  28800. * ciphers are actually usable in SSL/TLS. Notably, XTS is enabled
  28801. * in the default configuration and uses 64 Byte keys, but it is
  28802. * not used for record protection in SSL/TLS.
  28803. *
  28804. * In order to prevent unnecessary inflation of key structures,
  28805. * we introduce SSL-specific variants of the max-{key,block,IV}
  28806. * macros here which are meant to only take those ciphers into
  28807. * account which can be negotiated in SSL/TLS.
  28808. *
  28809. * Since the current definitions of MBEDTLS_MAX_{KEY|BLOCK|IV}_LENGTH
  28810. * in cipher.h are rough overapproximations of the real maxima, here
  28811. * we content ourselves with replicating those overapproximations
  28812. * for the maximum block and IV length, and excluding XTS from the
  28813. * computation of the maximum key length. */
  28814. #define MBEDTLS_SSL_MAX_BLOCK_LENGTH 16
  28815. #define MBEDTLS_SSL_MAX_IV_LENGTH 16
  28816. #define MBEDTLS_SSL_MAX_KEY_LENGTH 32
  28817. /**
  28818. * \brief The data structure holding the cryptographic material (key and IV)
  28819. * used for record protection in TLS 1.3.
  28820. */
  28821. struct mbedtls_ssl_key_set
  28822. {
  28823. /*! The key for client->server records. */
  28824. unsigned char client_write_key[ MBEDTLS_SSL_MAX_KEY_LENGTH ];
  28825. /*! The key for server->client records. */
  28826. unsigned char server_write_key[ MBEDTLS_SSL_MAX_KEY_LENGTH ];
  28827. /*! The IV for client->server records. */
  28828. unsigned char client_write_iv[ MBEDTLS_SSL_MAX_IV_LENGTH ];
  28829. /*! The IV for server->client records. */
  28830. unsigned char server_write_iv[ MBEDTLS_SSL_MAX_IV_LENGTH ];
  28831. size_t key_len; /*!< The length of client_write_key and
  28832. * server_write_key, in Bytes. */
  28833. size_t iv_len; /*!< The length of client_write_iv and
  28834. * server_write_iv, in Bytes. */
  28835. };
  28836. typedef struct mbedtls_ssl_key_set mbedtls_ssl_key_set;
  28837. /*
  28838. * This structure contains the parameters only needed during handshake.
  28839. */
  28840. struct mbedtls_ssl_handshake_params
  28841. {
  28842. /*
  28843. * Handshake specific crypto variables
  28844. */
  28845. uint8_t max_major_ver; /*!< max. major version client*/
  28846. uint8_t max_minor_ver; /*!< max. minor version client*/
  28847. uint8_t resume; /*!< session resume indicator*/
  28848. uint8_t cli_exts; /*!< client extension presence*/
  28849. #if defined(MBEDTLS_X509_CRT_PARSE_C) && \
  28850. defined(MBEDTLS_SSL_SERVER_NAME_INDICATION)
  28851. uint8_t sni_authmode; /*!< authmode from SNI callback */
  28852. #endif
  28853. #if defined(MBEDTLS_SSL_SESSION_TICKETS)
  28854. uint8_t new_session_ticket; /*!< use NewSessionTicket? */
  28855. #endif /* MBEDTLS_SSL_SESSION_TICKETS */
  28856. #if defined(MBEDTLS_SSL_EXTENDED_MASTER_SECRET)
  28857. uint8_t extended_ms; /*!< use Extended Master Secret? */
  28858. #endif
  28859. #if defined(MBEDTLS_SSL_ASYNC_PRIVATE)
  28860. uint8_t async_in_progress; /*!< an asynchronous operation is in progress */
  28861. #endif /* MBEDTLS_SSL_ASYNC_PRIVATE */
  28862. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  28863. unsigned char retransmit_state; /*!< Retransmission state */
  28864. #endif
  28865. #if defined(MBEDTLS_SSL_ECP_RESTARTABLE_ENABLED)
  28866. uint8_t ecrs_enabled; /*!< Handshake supports EC restart? */
  28867. enum { /* this complements ssl->state with info on intra-state operations */
  28868. ssl_ecrs_none = 0, /*!< nothing going on (yet) */
  28869. ssl_ecrs_crt_verify, /*!< Certificate: crt_verify() */
  28870. ssl_ecrs_ske_start_processing, /*!< ServerKeyExchange: pk_verify() */
  28871. ssl_ecrs_cke_ecdh_calc_secret, /*!< ClientKeyExchange: ECDH step 2 */
  28872. ssl_ecrs_crt_vrfy_sign, /*!< CertificateVerify: pk_sign() */
  28873. } ecrs_state; /*!< current (or last) operation */
  28874. mbedtls_x509_crt *ecrs_peer_cert; /*!< The peer's CRT chain. */
  28875. size_t ecrs_n; /*!< place for saving a length */
  28876. #endif
  28877. #if defined(MBEDTLS_SSL_PROTO_TLS1_2) && \
  28878. defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED)
  28879. mbedtls_ssl_sig_hash_set_t hash_algs; /*!< Set of suitable sig-hash pairs */
  28880. #endif
  28881. size_t pmslen; /*!< premaster length */
  28882. mbedtls_ssl_ciphersuite_t const *ciphersuite_info;
  28883. void (*update_checksum)(mbedtls_ssl_context *, const unsigned char *, size_t);
  28884. void (*calc_verify)(const mbedtls_ssl_context *, unsigned char *, size_t *);
  28885. void (*calc_finished)(mbedtls_ssl_context *, unsigned char *, int);
  28886. mbedtls_ssl_tls_prf_cb *tls_prf;
  28887. #if defined(MBEDTLS_DHM_C)
  28888. mbedtls_dhm_context dhm_ctx; /*!< DHM key exchange */
  28889. #endif
  28890. /* Adding guard for MBEDTLS_ECDSA_C to ensure no compile errors due
  28891. * to guards also being in ssl_srv.c and ssl_cli.c. There is a gap
  28892. * in functionality that access to ecdh_ctx structure is needed for
  28893. * MBEDTLS_ECDSA_C which does not seem correct.
  28894. */
  28895. #if defined(MBEDTLS_ECDH_C) || defined(MBEDTLS_ECDSA_C)
  28896. mbedtls_ecdh_context ecdh_ctx; /*!< ECDH key exchange */
  28897. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  28898. psa_key_type_t ecdh_psa_type;
  28899. uint16_t ecdh_bits;
  28900. psa_key_id_t ecdh_psa_privkey;
  28901. unsigned char ecdh_psa_peerkey[MBEDTLS_PSA_MAX_EC_PUBKEY_LENGTH];
  28902. size_t ecdh_psa_peerkey_len;
  28903. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  28904. #endif /* MBEDTLS_ECDH_C || MBEDTLS_ECDSA_C */
  28905. #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED)
  28906. mbedtls_ecjpake_context ecjpake_ctx; /*!< EC J-PAKE key exchange */
  28907. #if defined(MBEDTLS_SSL_CLI_C)
  28908. unsigned char *ecjpake_cache; /*!< Cache for ClientHello ext */
  28909. size_t ecjpake_cache_len; /*!< Length of cached data */
  28910. #endif
  28911. #endif /* MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED */
  28912. #if defined(MBEDTLS_ECDH_C) || defined(MBEDTLS_ECDSA_C) || \
  28913. defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED)
  28914. const mbedtls_ecp_curve_info **curves; /*!< Supported elliptic curves */
  28915. #endif
  28916. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED)
  28917. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  28918. psa_key_id_t psk_opaque; /*!< Opaque PSK from the callback */
  28919. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  28920. unsigned char *psk; /*!< PSK from the callback */
  28921. size_t psk_len; /*!< Length of PSK from callback */
  28922. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED */
  28923. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  28924. mbedtls_ssl_key_cert *key_cert; /*!< chosen key/cert pair (server) */
  28925. #if defined(MBEDTLS_SSL_SERVER_NAME_INDICATION)
  28926. mbedtls_ssl_key_cert *sni_key_cert; /*!< key/cert list from SNI */
  28927. mbedtls_x509_crt *sni_ca_chain; /*!< trusted CAs from SNI callback */
  28928. mbedtls_x509_crl *sni_ca_crl; /*!< trusted CAs CRLs from SNI */
  28929. #endif /* MBEDTLS_SSL_SERVER_NAME_INDICATION */
  28930. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  28931. #if defined(MBEDTLS_SSL_ECP_RESTARTABLE_ENABLED)
  28932. mbedtls_x509_crt_restart_ctx ecrs_ctx; /*!< restart context */
  28933. #endif
  28934. #if defined(MBEDTLS_X509_CRT_PARSE_C) && \
  28935. !defined(MBEDTLS_SSL_KEEP_PEER_CERTIFICATE)
  28936. mbedtls_pk_context peer_pubkey; /*!< The public key from the peer. */
  28937. #endif /* MBEDTLS_X509_CRT_PARSE_C && !MBEDTLS_SSL_KEEP_PEER_CERTIFICATE */
  28938. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  28939. struct
  28940. {
  28941. size_t total_bytes_buffered; /*!< Cumulative size of heap allocated
  28942. * buffers used for message buffering. */
  28943. uint8_t seen_ccs; /*!< Indicates if a CCS message has
  28944. * been seen in the current flight. */
  28945. struct mbedtls_ssl_hs_buffer
  28946. {
  28947. unsigned is_valid : 1;
  28948. unsigned is_fragmented : 1;
  28949. unsigned is_complete : 1;
  28950. unsigned char *data;
  28951. size_t data_len;
  28952. } hs[MBEDTLS_SSL_MAX_BUFFERED_HS];
  28953. struct
  28954. {
  28955. unsigned char *data;
  28956. size_t len;
  28957. unsigned epoch;
  28958. } future_record;
  28959. } buffering;
  28960. unsigned int out_msg_seq; /*!< Outgoing handshake sequence number */
  28961. unsigned int in_msg_seq; /*!< Incoming handshake sequence number */
  28962. unsigned char *verify_cookie; /*!< Cli: HelloVerifyRequest cookie
  28963. Srv: unused */
  28964. unsigned char verify_cookie_len; /*!< Cli: cookie length
  28965. Srv: flag for sending a cookie */
  28966. uint32_t retransmit_timeout; /*!< Current value of timeout */
  28967. mbedtls_ssl_flight_item *flight; /*!< Current outgoing flight */
  28968. mbedtls_ssl_flight_item *cur_msg; /*!< Current message in flight */
  28969. unsigned char *cur_msg_p; /*!< Position in current message */
  28970. unsigned int in_flight_start_seq; /*!< Minimum message sequence in the
  28971. flight being received */
  28972. mbedtls_ssl_transform *alt_transform_out; /*!< Alternative transform for
  28973. resending messages */
  28974. unsigned char alt_out_ctr[8]; /*!< Alternative record epoch/counter
  28975. for resending messages */
  28976. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  28977. /* The state of CID configuration in this handshake. */
  28978. uint8_t cid_in_use; /*!< This indicates whether the use of the CID extension
  28979. * has been negotiated. Possible values are
  28980. * #MBEDTLS_SSL_CID_ENABLED and
  28981. * #MBEDTLS_SSL_CID_DISABLED. */
  28982. unsigned char peer_cid[ MBEDTLS_SSL_CID_OUT_LEN_MAX ]; /*! The peer's CID */
  28983. uint8_t peer_cid_len; /*!< The length of
  28984. * \c peer_cid. */
  28985. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  28986. uint16_t mtu; /*!< Handshake mtu, used to fragment outgoing messages */
  28987. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  28988. /*
  28989. * Checksum contexts
  28990. */
  28991. #if defined(MBEDTLS_SSL_PROTO_SSL3) || defined(MBEDTLS_SSL_PROTO_TLS1) || \
  28992. defined(MBEDTLS_SSL_PROTO_TLS1_1)
  28993. mbedtls_md5_context fin_md5;
  28994. mbedtls_sha1_context fin_sha1;
  28995. #endif
  28996. #if defined(MBEDTLS_SSL_PROTO_TLS1_2)
  28997. #if defined(MBEDTLS_SHA256_C)
  28998. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  28999. psa_hash_operation_t fin_sha256_psa;
  29000. #else
  29001. mbedtls_sha256_context fin_sha256;
  29002. #endif
  29003. #endif
  29004. #if defined(MBEDTLS_SHA512_C)
  29005. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  29006. psa_hash_operation_t fin_sha384_psa;
  29007. #else
  29008. mbedtls_sha512_context fin_sha512;
  29009. #endif
  29010. #endif
  29011. #endif /* MBEDTLS_SSL_PROTO_TLS1_2 */
  29012. unsigned char randbytes[64]; /*!< random bytes */
  29013. unsigned char premaster[MBEDTLS_PREMASTER_SIZE];
  29014. /*!< premaster secret */
  29015. #if defined(MBEDTLS_SSL_ASYNC_PRIVATE)
  29016. /** Asynchronous operation context. This field is meant for use by the
  29017. * asynchronous operation callbacks (mbedtls_ssl_config::f_async_sign_start,
  29018. * mbedtls_ssl_config::f_async_decrypt_start,
  29019. * mbedtls_ssl_config::f_async_resume, mbedtls_ssl_config::f_async_cancel).
  29020. * The library does not use it internally. */
  29021. void *user_async_ctx;
  29022. #endif /* MBEDTLS_SSL_ASYNC_PRIVATE */
  29023. };
  29024. typedef struct mbedtls_ssl_hs_buffer mbedtls_ssl_hs_buffer;
  29025. /*
  29026. * Representation of decryption/encryption transformations on records
  29027. *
  29028. * There are the following general types of record transformations:
  29029. * - Stream transformations (TLS versions <= 1.2 only)
  29030. * Transformation adding a MAC and applying a stream-cipher
  29031. * to the authenticated message.
  29032. * - CBC block cipher transformations ([D]TLS versions <= 1.2 only)
  29033. * In addition to the distinction of the order of encryption and
  29034. * authentication, there's a fundamental difference between the
  29035. * handling in SSL3 & TLS 1.0 and TLS 1.1 and TLS 1.2: For SSL3
  29036. * and TLS 1.0, the final IV after processing a record is used
  29037. * as the IV for the next record. No explicit IV is contained
  29038. * in an encrypted record. The IV for the first record is extracted
  29039. * at key extraction time. In contrast, for TLS 1.1 and 1.2, no
  29040. * IV is generated at key extraction time, but every encrypted
  29041. * record is explicitly prefixed by the IV with which it was encrypted.
  29042. * - AEAD transformations ([D]TLS versions >= 1.2 only)
  29043. * These come in two fundamentally different versions, the first one
  29044. * used in TLS 1.2, excluding ChaChaPoly ciphersuites, and the second
  29045. * one used for ChaChaPoly ciphersuites in TLS 1.2 as well as for TLS 1.3.
  29046. * In the first transformation, the IV to be used for a record is obtained
  29047. * as the concatenation of an explicit, static 4-byte IV and the 8-byte
  29048. * record sequence number, and explicitly prepending this sequence number
  29049. * to the encrypted record. In contrast, in the second transformation
  29050. * the IV is obtained by XOR'ing a static IV obtained at key extraction
  29051. * time with the 8-byte record sequence number, without prepending the
  29052. * latter to the encrypted record.
  29053. *
  29054. * Additionally, DTLS 1.2 + CID as well as TLS 1.3 use an inner plaintext
  29055. * which allows to add flexible length padding and to hide a record's true
  29056. * content type.
  29057. *
  29058. * In addition to type and version, the following parameters are relevant:
  29059. * - The symmetric cipher algorithm to be used.
  29060. * - The (static) encryption/decryption keys for the cipher.
  29061. * - For stream/CBC, the type of message digest to be used.
  29062. * - For stream/CBC, (static) encryption/decryption keys for the digest.
  29063. * - For AEAD transformations, the size (potentially 0) of an explicit,
  29064. * random initialization vector placed in encrypted records.
  29065. * - For some transformations (currently AEAD and CBC in SSL3 and TLS 1.0)
  29066. * an implicit IV. It may be static (e.g. AEAD) or dynamic (e.g. CBC)
  29067. * and (if present) is combined with the explicit IV in a transformation-
  29068. * dependent way (e.g. appending in TLS 1.2 and XOR'ing in TLS 1.3).
  29069. * - For stream/CBC, a flag determining the order of encryption and MAC.
  29070. * - The details of the transformation depend on the SSL/TLS version.
  29071. * - The length of the authentication tag.
  29072. *
  29073. * Note: Except for CBC in SSL3 and TLS 1.0, these parameters are
  29074. * constant across multiple encryption/decryption operations.
  29075. * For CBC, the implicit IV needs to be updated after each
  29076. * operation.
  29077. *
  29078. * The struct below refines this abstract view as follows:
  29079. * - The cipher underlying the transformation is managed in
  29080. * cipher contexts cipher_ctx_{enc/dec}, which must have the
  29081. * same cipher type. The mode of these cipher contexts determines
  29082. * the type of the transformation in the sense above: e.g., if
  29083. * the type is MBEDTLS_CIPHER_AES_256_CBC resp. MBEDTLS_CIPHER_AES_192_GCM
  29084. * then the transformation has type CBC resp. AEAD.
  29085. * - The cipher keys are never stored explicitly but
  29086. * are maintained within cipher_ctx_{enc/dec}.
  29087. * - For stream/CBC transformations, the message digest contexts
  29088. * used for the MAC's are stored in md_ctx_{enc/dec}. These contexts
  29089. * are unused for AEAD transformations.
  29090. * - For stream/CBC transformations and versions > SSL3, the
  29091. * MAC keys are not stored explicitly but maintained within
  29092. * md_ctx_{enc/dec}.
  29093. * - For stream/CBC transformations and version SSL3, the MAC
  29094. * keys are stored explicitly in mac_enc, mac_dec and have
  29095. * a fixed size of 20 bytes. These fields are unused for
  29096. * AEAD transformations or transformations >= TLS 1.0.
  29097. * - For transformations using an implicit IV maintained within
  29098. * the transformation context, its contents are stored within
  29099. * iv_{enc/dec}.
  29100. * - The value of ivlen indicates the length of the IV.
  29101. * This is redundant in case of stream/CBC transformations
  29102. * which always use 0 resp. the cipher's block length as the
  29103. * IV length, but is needed for AEAD ciphers and may be
  29104. * different from the underlying cipher's block length
  29105. * in this case.
  29106. * - The field fixed_ivlen is nonzero for AEAD transformations only
  29107. * and indicates the length of the static part of the IV which is
  29108. * constant throughout the communication, and which is stored in
  29109. * the first fixed_ivlen bytes of the iv_{enc/dec} arrays.
  29110. * Note: For CBC in SSL3 and TLS 1.0, the fields iv_{enc/dec}
  29111. * still store IV's for continued use across multiple transformations,
  29112. * so it is not true that fixed_ivlen == 0 means that iv_{enc/dec} are
  29113. * not being used!
  29114. * - minor_ver denotes the SSL/TLS version
  29115. * - For stream/CBC transformations, maclen denotes the length of the
  29116. * authentication tag, while taglen is unused and 0.
  29117. * - For AEAD transformations, taglen denotes the length of the
  29118. * authentication tag, while maclen is unused and 0.
  29119. * - For CBC transformations, encrypt_then_mac determines the
  29120. * order of encryption and authentication. This field is unused
  29121. * in other transformations.
  29122. *
  29123. */
  29124. struct mbedtls_ssl_transform
  29125. {
  29126. /*
  29127. * Session specific crypto layer
  29128. */
  29129. size_t minlen; /*!< min. ciphertext length */
  29130. size_t ivlen; /*!< IV length */
  29131. size_t fixed_ivlen; /*!< Fixed part of IV (AEAD) */
  29132. size_t maclen; /*!< MAC(CBC) len */
  29133. size_t taglen; /*!< TAG(AEAD) len */
  29134. unsigned char iv_enc[16]; /*!< IV (encryption) */
  29135. unsigned char iv_dec[16]; /*!< IV (decryption) */
  29136. #if defined(MBEDTLS_SSL_SOME_MODES_USE_MAC)
  29137. #if defined(MBEDTLS_SSL_PROTO_SSL3)
  29138. /* Needed only for SSL v3.0 secret */
  29139. unsigned char mac_enc[20]; /*!< SSL v3.0 secret (enc) */
  29140. unsigned char mac_dec[20]; /*!< SSL v3.0 secret (dec) */
  29141. #endif /* MBEDTLS_SSL_PROTO_SSL3 */
  29142. mbedtls_md_context_t md_ctx_enc; /*!< MAC (encryption) */
  29143. mbedtls_md_context_t md_ctx_dec; /*!< MAC (decryption) */
  29144. #if defined(MBEDTLS_SSL_ENCRYPT_THEN_MAC)
  29145. int encrypt_then_mac; /*!< flag for EtM activation */
  29146. #endif
  29147. #endif /* MBEDTLS_SSL_SOME_MODES_USE_MAC */
  29148. mbedtls_cipher_context_t cipher_ctx_enc; /*!< encryption context */
  29149. mbedtls_cipher_context_t cipher_ctx_dec; /*!< decryption context */
  29150. int minor_ver;
  29151. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  29152. uint8_t in_cid_len;
  29153. uint8_t out_cid_len;
  29154. unsigned char in_cid [ MBEDTLS_SSL_CID_OUT_LEN_MAX ];
  29155. unsigned char out_cid[ MBEDTLS_SSL_CID_OUT_LEN_MAX ];
  29156. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  29157. /*
  29158. * Session specific compression layer
  29159. */
  29160. #if defined(MBEDTLS_ZLIB_SUPPORT)
  29161. z_stream ctx_deflate; /*!< compression context */
  29162. z_stream ctx_inflate; /*!< decompression context */
  29163. #endif
  29164. #if defined(MBEDTLS_SSL_CONTEXT_SERIALIZATION)
  29165. /* We need the Hello random bytes in order to re-derive keys from the
  29166. * Master Secret and other session info, see ssl_populate_transform() */
  29167. unsigned char randbytes[64]; /*!< ServerHello.random+ClientHello.random */
  29168. #endif /* MBEDTLS_SSL_CONTEXT_SERIALIZATION */
  29169. };
  29170. /*
  29171. * Return 1 if the transform uses an AEAD cipher, 0 otherwise.
  29172. * Equivalently, return 0 if a separate MAC is used, 1 otherwise.
  29173. */
  29174. static inline int mbedtls_ssl_transform_uses_aead(
  29175. const mbedtls_ssl_transform *transform )
  29176. {
  29177. #if defined(MBEDTLS_SSL_SOME_MODES_USE_MAC)
  29178. return( transform->maclen == 0 && transform->taglen != 0 );
  29179. #else
  29180. (void) transform;
  29181. return( 1 );
  29182. #endif
  29183. }
  29184. /*
  29185. * Internal representation of record frames
  29186. *
  29187. * Instances come in two flavors:
  29188. * (1) Encrypted
  29189. * These always have data_offset = 0
  29190. * (2) Unencrypted
  29191. * These have data_offset set to the amount of
  29192. * pre-expansion during record protection. Concretely,
  29193. * this is the length of the fixed part of the explicit IV
  29194. * used for encryption, or 0 if no explicit IV is used
  29195. * (e.g. for CBC in TLS 1.0, or stream ciphers).
  29196. *
  29197. * The reason for the data_offset in the unencrypted case
  29198. * is to allow for in-place conversion of an unencrypted to
  29199. * an encrypted record. If the offset wasn't included, the
  29200. * encrypted content would need to be shifted afterwards to
  29201. * make space for the fixed IV.
  29202. *
  29203. */
  29204. #if MBEDTLS_SSL_CID_OUT_LEN_MAX > MBEDTLS_SSL_CID_IN_LEN_MAX
  29205. #define MBEDTLS_SSL_CID_LEN_MAX MBEDTLS_SSL_CID_OUT_LEN_MAX
  29206. #else
  29207. #define MBEDTLS_SSL_CID_LEN_MAX MBEDTLS_SSL_CID_IN_LEN_MAX
  29208. #endif
  29209. typedef struct
  29210. {
  29211. uint8_t ctr[8]; /* In TLS: The implicit record sequence number.
  29212. * In DTLS: The 2-byte epoch followed by
  29213. * the 6-byte sequence number.
  29214. * This is stored as a raw big endian byte array
  29215. * as opposed to a uint64_t because we rarely
  29216. * need to perform arithmetic on this, but do
  29217. * need it as a Byte array for the purpose of
  29218. * MAC computations. */
  29219. uint8_t type; /* The record content type. */
  29220. uint8_t ver[2]; /* SSL/TLS version as present on the wire.
  29221. * Convert to internal presentation of versions
  29222. * using mbedtls_ssl_read_version() and
  29223. * mbedtls_ssl_write_version().
  29224. * Keep wire-format for MAC computations. */
  29225. unsigned char *buf; /* Memory buffer enclosing the record content */
  29226. size_t buf_len; /* Buffer length */
  29227. size_t data_offset; /* Offset of record content */
  29228. size_t data_len; /* Length of record content */
  29229. #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID)
  29230. uint8_t cid_len; /* Length of the CID (0 if not present) */
  29231. unsigned char cid[ MBEDTLS_SSL_CID_LEN_MAX ]; /* The CID */
  29232. #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */
  29233. } mbedtls_record;
  29234. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  29235. /*
  29236. * List of certificate + private key pairs
  29237. */
  29238. struct mbedtls_ssl_key_cert
  29239. {
  29240. mbedtls_x509_crt *cert; /*!< cert */
  29241. mbedtls_pk_context *key; /*!< private key */
  29242. mbedtls_ssl_key_cert *next; /*!< next key/cert pair */
  29243. };
  29244. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  29245. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  29246. /*
  29247. * List of handshake messages kept around for resending
  29248. */
  29249. struct mbedtls_ssl_flight_item
  29250. {
  29251. unsigned char *p; /*!< message, including handshake headers */
  29252. size_t len; /*!< length of p */
  29253. unsigned char type; /*!< type of the message: handshake or CCS */
  29254. mbedtls_ssl_flight_item *next; /*!< next handshake message(s) */
  29255. };
  29256. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  29257. #if defined(MBEDTLS_SSL_PROTO_TLS1_2) && \
  29258. defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED)
  29259. /* Find an entry in a signature-hash set matching a given hash algorithm. */
  29260. mbedtls_md_type_t mbedtls_ssl_sig_hash_set_find( mbedtls_ssl_sig_hash_set_t *set,
  29261. mbedtls_pk_type_t sig_alg );
  29262. /* Add a signature-hash-pair to a signature-hash set */
  29263. void mbedtls_ssl_sig_hash_set_add( mbedtls_ssl_sig_hash_set_t *set,
  29264. mbedtls_pk_type_t sig_alg,
  29265. mbedtls_md_type_t md_alg );
  29266. /* Allow exactly one hash algorithm for each signature. */
  29267. void mbedtls_ssl_sig_hash_set_const_hash( mbedtls_ssl_sig_hash_set_t *set,
  29268. mbedtls_md_type_t md_alg );
  29269. /* Setup an empty signature-hash set */
  29270. static inline void mbedtls_ssl_sig_hash_set_init( mbedtls_ssl_sig_hash_set_t *set )
  29271. {
  29272. mbedtls_ssl_sig_hash_set_const_hash( set, MBEDTLS_MD_NONE );
  29273. }
  29274. #endif /* MBEDTLS_SSL_PROTO_TLS1_2) &&
  29275. MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED */
  29276. /**
  29277. * \brief Free referenced items in an SSL transform context and clear
  29278. * memory
  29279. *
  29280. * \param transform SSL transform context
  29281. */
  29282. void mbedtls_ssl_transform_free( mbedtls_ssl_transform *transform );
  29283. /**
  29284. * \brief Free referenced items in an SSL handshake context and clear
  29285. * memory
  29286. *
  29287. * \param ssl SSL context
  29288. */
  29289. void mbedtls_ssl_handshake_free( mbedtls_ssl_context *ssl );
  29290. int mbedtls_ssl_handshake_client_step( mbedtls_ssl_context *ssl );
  29291. int mbedtls_ssl_handshake_server_step( mbedtls_ssl_context *ssl );
  29292. void mbedtls_ssl_handshake_wrapup( mbedtls_ssl_context *ssl );
  29293. int mbedtls_ssl_send_fatal_handshake_failure( mbedtls_ssl_context *ssl );
  29294. void mbedtls_ssl_reset_checksum( mbedtls_ssl_context *ssl );
  29295. int mbedtls_ssl_derive_keys( mbedtls_ssl_context *ssl );
  29296. int mbedtls_ssl_handle_message_type( mbedtls_ssl_context *ssl );
  29297. int mbedtls_ssl_prepare_handshake_record( mbedtls_ssl_context *ssl );
  29298. void mbedtls_ssl_update_handshake_status( mbedtls_ssl_context *ssl );
  29299. /**
  29300. * \brief Update record layer
  29301. *
  29302. * This function roughly separates the implementation
  29303. * of the logic of (D)TLS from the implementation
  29304. * of the secure transport.
  29305. *
  29306. * \param ssl The SSL context to use.
  29307. * \param update_hs_digest This indicates if the handshake digest
  29308. * should be automatically updated in case
  29309. * a handshake message is found.
  29310. *
  29311. * \return 0 or non-zero error code.
  29312. *
  29313. * \note A clarification on what is called 'record layer' here
  29314. * is in order, as many sensible definitions are possible:
  29315. *
  29316. * The record layer takes as input an untrusted underlying
  29317. * transport (stream or datagram) and transforms it into
  29318. * a serially multiplexed, secure transport, which
  29319. * conceptually provides the following:
  29320. *
  29321. * (1) Three datagram based, content-agnostic transports
  29322. * for handshake, alert and CCS messages.
  29323. * (2) One stream- or datagram-based transport
  29324. * for application data.
  29325. * (3) Functionality for changing the underlying transform
  29326. * securing the contents.
  29327. *
  29328. * The interface to this functionality is given as follows:
  29329. *
  29330. * a Updating
  29331. * [Currently implemented by mbedtls_ssl_read_record]
  29332. *
  29333. * Check if and on which of the four 'ports' data is pending:
  29334. * Nothing, a controlling datagram of type (1), or application
  29335. * data (2). In any case data is present, internal buffers
  29336. * provide access to the data for the user to process it.
  29337. * Consumption of type (1) datagrams is done automatically
  29338. * on the next update, invalidating that the internal buffers
  29339. * for previous datagrams, while consumption of application
  29340. * data (2) is user-controlled.
  29341. *
  29342. * b Reading of application data
  29343. * [Currently manual adaption of ssl->in_offt pointer]
  29344. *
  29345. * As mentioned in the last paragraph, consumption of data
  29346. * is different from the automatic consumption of control
  29347. * datagrams (1) because application data is treated as a stream.
  29348. *
  29349. * c Tracking availability of application data
  29350. * [Currently manually through decreasing ssl->in_msglen]
  29351. *
  29352. * For efficiency and to retain datagram semantics for
  29353. * application data in case of DTLS, the record layer
  29354. * provides functionality for checking how much application
  29355. * data is still available in the internal buffer.
  29356. *
  29357. * d Changing the transformation securing the communication.
  29358. *
  29359. * Given an opaque implementation of the record layer in the
  29360. * above sense, it should be possible to implement the logic
  29361. * of (D)TLS on top of it without the need to know anything
  29362. * about the record layer's internals. This is done e.g.
  29363. * in all the handshake handling functions, and in the
  29364. * application data reading function mbedtls_ssl_read.
  29365. *
  29366. * \note The above tries to give a conceptual picture of the
  29367. * record layer, but the current implementation deviates
  29368. * from it in some places. For example, our implementation of
  29369. * the update functionality through mbedtls_ssl_read_record
  29370. * discards datagrams depending on the current state, which
  29371. * wouldn't fall under the record layer's responsibility
  29372. * following the above definition.
  29373. *
  29374. */
  29375. int mbedtls_ssl_read_record( mbedtls_ssl_context *ssl,
  29376. unsigned update_hs_digest );
  29377. int mbedtls_ssl_fetch_input( mbedtls_ssl_context *ssl, size_t nb_want );
  29378. int mbedtls_ssl_write_handshake_msg( mbedtls_ssl_context *ssl );
  29379. int mbedtls_ssl_write_record( mbedtls_ssl_context *ssl, uint8_t force_flush );
  29380. int mbedtls_ssl_flush_output( mbedtls_ssl_context *ssl );
  29381. int mbedtls_ssl_parse_certificate( mbedtls_ssl_context *ssl );
  29382. int mbedtls_ssl_write_certificate( mbedtls_ssl_context *ssl );
  29383. int mbedtls_ssl_parse_change_cipher_spec( mbedtls_ssl_context *ssl );
  29384. int mbedtls_ssl_write_change_cipher_spec( mbedtls_ssl_context *ssl );
  29385. int mbedtls_ssl_parse_finished( mbedtls_ssl_context *ssl );
  29386. int mbedtls_ssl_write_finished( mbedtls_ssl_context *ssl );
  29387. void mbedtls_ssl_optimize_checksum( mbedtls_ssl_context *ssl,
  29388. const mbedtls_ssl_ciphersuite_t *ciphersuite_info );
  29389. #if defined(MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED)
  29390. int mbedtls_ssl_psk_derive_premaster( mbedtls_ssl_context *ssl, mbedtls_key_exchange_type_t key_ex );
  29391. /**
  29392. * Get the first defined PSK by order of precedence:
  29393. * 1. handshake PSK set by \c mbedtls_ssl_set_hs_psk() in the PSK callback
  29394. * 2. static PSK configured by \c mbedtls_ssl_conf_psk()
  29395. * Return a code and update the pair (PSK, PSK length) passed to this function
  29396. */
  29397. static inline int mbedtls_ssl_get_psk( const mbedtls_ssl_context *ssl,
  29398. const unsigned char **psk, size_t *psk_len )
  29399. {
  29400. if( ssl->handshake->psk != NULL && ssl->handshake->psk_len > 0 )
  29401. {
  29402. *psk = ssl->handshake->psk;
  29403. *psk_len = ssl->handshake->psk_len;
  29404. }
  29405. else if( ssl->conf->psk != NULL && ssl->conf->psk_len > 0 )
  29406. {
  29407. *psk = ssl->conf->psk;
  29408. *psk_len = ssl->conf->psk_len;
  29409. }
  29410. else
  29411. {
  29412. *psk = NULL;
  29413. *psk_len = 0;
  29414. return( MBEDTLS_ERR_SSL_PRIVATE_KEY_REQUIRED );
  29415. }
  29416. return( 0 );
  29417. }
  29418. #if defined(MBEDTLS_USE_PSA_CRYPTO)
  29419. /**
  29420. * Get the first defined opaque PSK by order of precedence:
  29421. * 1. handshake PSK set by \c mbedtls_ssl_set_hs_psk_opaque() in the PSK
  29422. * callback
  29423. * 2. static PSK configured by \c mbedtls_ssl_conf_psk_opaque()
  29424. * Return an opaque PSK
  29425. */
  29426. static inline psa_key_id_t mbedtls_ssl_get_opaque_psk(
  29427. const mbedtls_ssl_context *ssl )
  29428. {
  29429. if( ! mbedtls_svc_key_id_is_null( ssl->handshake->psk_opaque ) )
  29430. return( ssl->handshake->psk_opaque );
  29431. if( ! mbedtls_svc_key_id_is_null( ssl->conf->psk_opaque ) )
  29432. return( ssl->conf->psk_opaque );
  29433. return( MBEDTLS_SVC_KEY_ID_INIT );
  29434. }
  29435. #endif /* MBEDTLS_USE_PSA_CRYPTO */
  29436. #endif /* MBEDTLS_KEY_EXCHANGE_SOME_PSK_ENABLED */
  29437. #if defined(MBEDTLS_PK_C)
  29438. unsigned char mbedtls_ssl_sig_from_pk( mbedtls_pk_context *pk );
  29439. unsigned char mbedtls_ssl_sig_from_pk_alg( mbedtls_pk_type_t type );
  29440. mbedtls_pk_type_t mbedtls_ssl_pk_alg_from_sig( unsigned char sig );
  29441. #endif
  29442. mbedtls_md_type_t mbedtls_ssl_md_alg_from_hash( unsigned char hash );
  29443. unsigned char mbedtls_ssl_hash_from_md_alg( int md );
  29444. int mbedtls_ssl_set_calc_verify_md( mbedtls_ssl_context *ssl, int md );
  29445. #if defined(MBEDTLS_ECP_C)
  29446. int mbedtls_ssl_check_curve( const mbedtls_ssl_context *ssl, mbedtls_ecp_group_id grp_id );
  29447. #endif
  29448. #if defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED)
  29449. int mbedtls_ssl_check_sig_hash( const mbedtls_ssl_context *ssl,
  29450. mbedtls_md_type_t md );
  29451. #endif
  29452. #if defined(MBEDTLS_SSL_DTLS_SRTP)
  29453. static inline mbedtls_ssl_srtp_profile mbedtls_ssl_check_srtp_profile_value
  29454. ( const uint16_t srtp_profile_value )
  29455. {
  29456. switch( srtp_profile_value )
  29457. {
  29458. case MBEDTLS_TLS_SRTP_AES128_CM_HMAC_SHA1_80:
  29459. case MBEDTLS_TLS_SRTP_AES128_CM_HMAC_SHA1_32:
  29460. case MBEDTLS_TLS_SRTP_NULL_HMAC_SHA1_80:
  29461. case MBEDTLS_TLS_SRTP_NULL_HMAC_SHA1_32:
  29462. return srtp_profile_value;
  29463. default: break;
  29464. }
  29465. return( MBEDTLS_TLS_SRTP_UNSET );
  29466. }
  29467. #endif
  29468. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  29469. static inline mbedtls_pk_context *mbedtls_ssl_own_key( mbedtls_ssl_context *ssl )
  29470. {
  29471. mbedtls_ssl_key_cert *key_cert;
  29472. if( ssl->handshake != NULL && ssl->handshake->key_cert != NULL )
  29473. key_cert = ssl->handshake->key_cert;
  29474. else
  29475. key_cert = ssl->conf->key_cert;
  29476. return( key_cert == NULL ? NULL : key_cert->key );
  29477. }
  29478. static inline mbedtls_x509_crt *mbedtls_ssl_own_cert( mbedtls_ssl_context *ssl )
  29479. {
  29480. mbedtls_ssl_key_cert *key_cert;
  29481. if( ssl->handshake != NULL && ssl->handshake->key_cert != NULL )
  29482. key_cert = ssl->handshake->key_cert;
  29483. else
  29484. key_cert = ssl->conf->key_cert;
  29485. return( key_cert == NULL ? NULL : key_cert->cert );
  29486. }
  29487. /*
  29488. * Check usage of a certificate wrt extensions:
  29489. * keyUsage, extendedKeyUsage (later), and nSCertType (later).
  29490. *
  29491. * Warning: cert_endpoint is the endpoint of the cert (ie, of our peer when we
  29492. * check a cert we received from them)!
  29493. *
  29494. * Return 0 if everything is OK, -1 if not.
  29495. */
  29496. int mbedtls_ssl_check_cert_usage( const mbedtls_x509_crt *cert,
  29497. const mbedtls_ssl_ciphersuite_t *ciphersuite,
  29498. int cert_endpoint,
  29499. uint32_t *flags );
  29500. #endif /* MBEDTLS_X509_CRT_PARSE_C */
  29501. void mbedtls_ssl_write_version( int major, int minor, int transport,
  29502. unsigned char ver[2] );
  29503. void mbedtls_ssl_read_version( int *major, int *minor, int transport,
  29504. const unsigned char ver[2] );
  29505. static inline size_t mbedtls_ssl_in_hdr_len( const mbedtls_ssl_context *ssl )
  29506. {
  29507. #if !defined(MBEDTLS_SSL_PROTO_DTLS)
  29508. ((void) ssl);
  29509. #endif
  29510. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  29511. if( ssl->conf->transport == MBEDTLS_SSL_TRANSPORT_DATAGRAM )
  29512. {
  29513. return( 13 );
  29514. }
  29515. else
  29516. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  29517. {
  29518. return( 5 );
  29519. }
  29520. }
  29521. static inline size_t mbedtls_ssl_out_hdr_len( const mbedtls_ssl_context *ssl )
  29522. {
  29523. return( (size_t) ( ssl->out_iv - ssl->out_hdr ) );
  29524. }
  29525. static inline size_t mbedtls_ssl_hs_hdr_len( const mbedtls_ssl_context *ssl )
  29526. {
  29527. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  29528. if( ssl->conf->transport == MBEDTLS_SSL_TRANSPORT_DATAGRAM )
  29529. return( 12 );
  29530. #else
  29531. ((void) ssl);
  29532. #endif
  29533. return( 4 );
  29534. }
  29535. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  29536. void mbedtls_ssl_send_flight_completed( mbedtls_ssl_context *ssl );
  29537. void mbedtls_ssl_recv_flight_completed( mbedtls_ssl_context *ssl );
  29538. int mbedtls_ssl_resend( mbedtls_ssl_context *ssl );
  29539. int mbedtls_ssl_flight_transmit( mbedtls_ssl_context *ssl );
  29540. #endif
  29541. /* Visible for testing purposes only */
  29542. #if defined(MBEDTLS_SSL_DTLS_ANTI_REPLAY)
  29543. int mbedtls_ssl_dtls_replay_check( mbedtls_ssl_context const *ssl );
  29544. void mbedtls_ssl_dtls_replay_update( mbedtls_ssl_context *ssl );
  29545. #endif
  29546. int mbedtls_ssl_session_copy( mbedtls_ssl_session *dst,
  29547. const mbedtls_ssl_session *src );
  29548. #if defined(MBEDTLS_SSL_PROTO_SSL3) || defined(MBEDTLS_SSL_PROTO_TLS1) || \
  29549. defined(MBEDTLS_SSL_PROTO_TLS1_1)
  29550. int mbedtls_ssl_get_key_exchange_md_ssl_tls( mbedtls_ssl_context *ssl,
  29551. unsigned char *output,
  29552. unsigned char *data, size_t data_len );
  29553. #endif /* MBEDTLS_SSL_PROTO_SSL3 || MBEDTLS_SSL_PROTO_TLS1 || \
  29554. MBEDTLS_SSL_PROTO_TLS1_1 */
  29555. #if defined(MBEDTLS_SSL_PROTO_TLS1) || defined(MBEDTLS_SSL_PROTO_TLS1_1) || \
  29556. defined(MBEDTLS_SSL_PROTO_TLS1_2)
  29557. /* The hash buffer must have at least MBEDTLS_MD_MAX_SIZE bytes of length. */
  29558. int mbedtls_ssl_get_key_exchange_md_tls1_2( mbedtls_ssl_context *ssl,
  29559. unsigned char *hash, size_t *hashlen,
  29560. unsigned char *data, size_t data_len,
  29561. mbedtls_md_type_t md_alg );
  29562. #endif /* MBEDTLS_SSL_PROTO_TLS1 || MBEDTLS_SSL_PROTO_TLS1_1 || \
  29563. MBEDTLS_SSL_PROTO_TLS1_2 */
  29564. #ifdef __cplusplus
  29565. }
  29566. #endif
  29567. void mbedtls_ssl_transform_init( mbedtls_ssl_transform *transform );
  29568. int mbedtls_ssl_encrypt_buf( mbedtls_ssl_context *ssl,
  29569. mbedtls_ssl_transform *transform,
  29570. mbedtls_record *rec,
  29571. int (*f_rng)(void *, unsigned char *, size_t),
  29572. void *p_rng );
  29573. int mbedtls_ssl_decrypt_buf( mbedtls_ssl_context const *ssl,
  29574. mbedtls_ssl_transform *transform,
  29575. mbedtls_record *rec );
  29576. /* Length of the "epoch" field in the record header */
  29577. static inline size_t mbedtls_ssl_ep_len( const mbedtls_ssl_context *ssl )
  29578. {
  29579. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  29580. if( ssl->conf->transport == MBEDTLS_SSL_TRANSPORT_DATAGRAM )
  29581. return( 2 );
  29582. #else
  29583. ((void) ssl);
  29584. #endif
  29585. return( 0 );
  29586. }
  29587. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  29588. int mbedtls_ssl_resend_hello_request( mbedtls_ssl_context *ssl );
  29589. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  29590. void mbedtls_ssl_set_timer( mbedtls_ssl_context *ssl, uint32_t millisecs );
  29591. int mbedtls_ssl_check_timer( mbedtls_ssl_context *ssl );
  29592. void mbedtls_ssl_reset_in_out_pointers( mbedtls_ssl_context *ssl );
  29593. void mbedtls_ssl_update_out_pointers( mbedtls_ssl_context *ssl,
  29594. mbedtls_ssl_transform *transform );
  29595. void mbedtls_ssl_update_in_pointers( mbedtls_ssl_context *ssl );
  29596. int mbedtls_ssl_session_reset_int( mbedtls_ssl_context *ssl, int partial );
  29597. #if defined(MBEDTLS_SSL_DTLS_ANTI_REPLAY)
  29598. void mbedtls_ssl_dtls_replay_reset( mbedtls_ssl_context *ssl );
  29599. #endif
  29600. void mbedtls_ssl_handshake_wrapup_free_hs_transform( mbedtls_ssl_context *ssl );
  29601. #if defined(MBEDTLS_SSL_RENEGOTIATION)
  29602. int mbedtls_ssl_start_renegotiation( mbedtls_ssl_context *ssl );
  29603. #endif /* MBEDTLS_SSL_RENEGOTIATION */
  29604. #if defined(MBEDTLS_SSL_PROTO_DTLS)
  29605. size_t mbedtls_ssl_get_current_mtu( const mbedtls_ssl_context *ssl );
  29606. void mbedtls_ssl_buffering_free( mbedtls_ssl_context *ssl );
  29607. void mbedtls_ssl_flight_free( mbedtls_ssl_flight_item *flight );
  29608. #endif /* MBEDTLS_SSL_PROTO_DTLS */
  29609. #endif /* ssl_internal.h */
  29610. /********* Start of file include/mbedtls/ssl_cache.h ************/
  29611. /**
  29612. * \file ssl_cache.h
  29613. *
  29614. * \brief SSL session cache implementation
  29615. */
  29616. /*
  29617. * Copyright The Mbed TLS Contributors
  29618. * SPDX-License-Identifier: Apache-2.0
  29619. *
  29620. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  29621. * not use this file except in compliance with the License.
  29622. * You may obtain a copy of the License at
  29623. *
  29624. * http://www.apache.org/licenses/LICENSE-2.0
  29625. *
  29626. * Unless required by applicable law or agreed to in writing, software
  29627. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  29628. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  29629. * See the License for the specific language governing permissions and
  29630. * limitations under the License.
  29631. */
  29632. #ifndef MBEDTLS_SSL_CACHE_H
  29633. #define MBEDTLS_SSL_CACHE_H
  29634. #if !defined(MBEDTLS_CONFIG_FILE)
  29635. #else
  29636. #endif
  29637. #if defined(MBEDTLS_THREADING_C)
  29638. #endif
  29639. /**
  29640. * \name SECTION: Module settings
  29641. *
  29642. * The configuration options you can set for this module are in this section.
  29643. * Either change them in config.h or define them on the compiler command line.
  29644. * \{
  29645. */
  29646. #if !defined(MBEDTLS_SSL_CACHE_DEFAULT_TIMEOUT)
  29647. #define MBEDTLS_SSL_CACHE_DEFAULT_TIMEOUT 86400 /*!< 1 day */
  29648. #endif
  29649. #if !defined(MBEDTLS_SSL_CACHE_DEFAULT_MAX_ENTRIES)
  29650. #define MBEDTLS_SSL_CACHE_DEFAULT_MAX_ENTRIES 50 /*!< Maximum entries in cache */
  29651. #endif
  29652. /* \} name SECTION: Module settings */
  29653. #ifdef __cplusplus
  29654. extern "C" {
  29655. #endif
  29656. typedef struct mbedtls_ssl_cache_context mbedtls_ssl_cache_context;
  29657. typedef struct mbedtls_ssl_cache_entry mbedtls_ssl_cache_entry;
  29658. /**
  29659. * \brief This structure is used for storing cache entries
  29660. */
  29661. struct mbedtls_ssl_cache_entry
  29662. {
  29663. #if defined(MBEDTLS_HAVE_TIME)
  29664. mbedtls_time_t timestamp; /*!< entry timestamp */
  29665. #endif
  29666. mbedtls_ssl_session session; /*!< entry session */
  29667. #if defined(MBEDTLS_X509_CRT_PARSE_C) && \
  29668. defined(MBEDTLS_SSL_KEEP_PEER_CERTIFICATE)
  29669. mbedtls_x509_buf peer_cert; /*!< entry peer_cert */
  29670. #endif
  29671. mbedtls_ssl_cache_entry *next; /*!< chain pointer */
  29672. };
  29673. /**
  29674. * \brief Cache context
  29675. */
  29676. struct mbedtls_ssl_cache_context
  29677. {
  29678. mbedtls_ssl_cache_entry *chain; /*!< start of the chain */
  29679. int timeout; /*!< cache entry timeout */
  29680. int max_entries; /*!< maximum entries */
  29681. #if defined(MBEDTLS_THREADING_C)
  29682. mbedtls_threading_mutex_t mutex; /*!< mutex */
  29683. #endif
  29684. };
  29685. /**
  29686. * \brief Initialize an SSL cache context
  29687. *
  29688. * \param cache SSL cache context
  29689. */
  29690. void mbedtls_ssl_cache_init( mbedtls_ssl_cache_context *cache );
  29691. /**
  29692. * \brief Cache get callback implementation
  29693. * (Thread-safe if MBEDTLS_THREADING_C is enabled)
  29694. *
  29695. * \param data SSL cache context
  29696. * \param session session to retrieve entry for
  29697. */
  29698. int mbedtls_ssl_cache_get( void *data, mbedtls_ssl_session *session );
  29699. /**
  29700. * \brief Cache set callback implementation
  29701. * (Thread-safe if MBEDTLS_THREADING_C is enabled)
  29702. *
  29703. * \param data SSL cache context
  29704. * \param session session to store entry for
  29705. */
  29706. int mbedtls_ssl_cache_set( void *data, const mbedtls_ssl_session *session );
  29707. #if defined(MBEDTLS_HAVE_TIME)
  29708. /**
  29709. * \brief Set the cache timeout
  29710. * (Default: MBEDTLS_SSL_CACHE_DEFAULT_TIMEOUT (1 day))
  29711. *
  29712. * A timeout of 0 indicates no timeout.
  29713. *
  29714. * \param cache SSL cache context
  29715. * \param timeout cache entry timeout in seconds
  29716. */
  29717. void mbedtls_ssl_cache_set_timeout( mbedtls_ssl_cache_context *cache, int timeout );
  29718. #endif /* MBEDTLS_HAVE_TIME */
  29719. /**
  29720. * \brief Set the maximum number of cache entries
  29721. * (Default: MBEDTLS_SSL_CACHE_DEFAULT_MAX_ENTRIES (50))
  29722. *
  29723. * \param cache SSL cache context
  29724. * \param max cache entry maximum
  29725. */
  29726. void mbedtls_ssl_cache_set_max_entries( mbedtls_ssl_cache_context *cache, int max );
  29727. /**
  29728. * \brief Free referenced items in a cache context and clear memory
  29729. *
  29730. * \param cache SSL cache context
  29731. */
  29732. void mbedtls_ssl_cache_free( mbedtls_ssl_cache_context *cache );
  29733. #ifdef __cplusplus
  29734. }
  29735. #endif
  29736. #endif /* ssl_cache.h */
  29737. /********* Start of file include/mbedtls/ssl_ticket.h ************/
  29738. /**
  29739. * \file ssl_ticket.h
  29740. *
  29741. * \brief TLS server ticket callbacks implementation
  29742. */
  29743. /*
  29744. * Copyright The Mbed TLS Contributors
  29745. * SPDX-License-Identifier: Apache-2.0
  29746. *
  29747. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  29748. * not use this file except in compliance with the License.
  29749. * You may obtain a copy of the License at
  29750. *
  29751. * http://www.apache.org/licenses/LICENSE-2.0
  29752. *
  29753. * Unless required by applicable law or agreed to in writing, software
  29754. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  29755. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  29756. * See the License for the specific language governing permissions and
  29757. * limitations under the License.
  29758. */
  29759. #ifndef MBEDTLS_SSL_TICKET_H
  29760. #define MBEDTLS_SSL_TICKET_H
  29761. #if !defined(MBEDTLS_CONFIG_FILE)
  29762. #else
  29763. #endif
  29764. /*
  29765. * This implementation of the session ticket callbacks includes key
  29766. * management, rotating the keys periodically in order to preserve forward
  29767. * secrecy, when MBEDTLS_HAVE_TIME is defined.
  29768. */
  29769. #if defined(MBEDTLS_THREADING_C)
  29770. #endif
  29771. #ifdef __cplusplus
  29772. extern "C" {
  29773. #endif
  29774. /**
  29775. * \brief Information for session ticket protection
  29776. */
  29777. typedef struct mbedtls_ssl_ticket_key
  29778. {
  29779. unsigned char name[4]; /*!< random key identifier */
  29780. uint32_t generation_time; /*!< key generation timestamp (seconds) */
  29781. mbedtls_cipher_context_t ctx; /*!< context for auth enc/decryption */
  29782. }
  29783. mbedtls_ssl_ticket_key;
  29784. /**
  29785. * \brief Context for session ticket handling functions
  29786. */
  29787. typedef struct mbedtls_ssl_ticket_context
  29788. {
  29789. mbedtls_ssl_ticket_key keys[2]; /*!< ticket protection keys */
  29790. unsigned char active; /*!< index of the currently active key */
  29791. uint32_t ticket_lifetime; /*!< lifetime of tickets in seconds */
  29792. /** Callback for getting (pseudo-)random numbers */
  29793. int (*f_rng)(void *, unsigned char *, size_t);
  29794. void *p_rng; /*!< context for the RNG function */
  29795. #if defined(MBEDTLS_THREADING_C)
  29796. mbedtls_threading_mutex_t mutex;
  29797. #endif
  29798. }
  29799. mbedtls_ssl_ticket_context;
  29800. /**
  29801. * \brief Initialize a ticket context.
  29802. * (Just make it ready for mbedtls_ssl_ticket_setup()
  29803. * or mbedtls_ssl_ticket_free().)
  29804. *
  29805. * \param ctx Context to be initialized
  29806. */
  29807. void mbedtls_ssl_ticket_init( mbedtls_ssl_ticket_context *ctx );
  29808. /**
  29809. * \brief Prepare context to be actually used
  29810. *
  29811. * \param ctx Context to be set up
  29812. * \param f_rng RNG callback function
  29813. * \param p_rng RNG callback context
  29814. * \param cipher AEAD cipher to use for ticket protection.
  29815. * Recommended value: MBEDTLS_CIPHER_AES_256_GCM.
  29816. * \param lifetime Tickets lifetime in seconds
  29817. * Recommended value: 86400 (one day).
  29818. *
  29819. * \note It is highly recommended to select a cipher that is at
  29820. * least as strong as the strongest ciphersuite
  29821. * supported. Usually that means a 256-bit key.
  29822. *
  29823. * \note The lifetime of the keys is twice the lifetime of tickets.
  29824. * It is recommended to pick a reasonnable lifetime so as not
  29825. * to negate the benefits of forward secrecy.
  29826. *
  29827. * \return 0 if successful,
  29828. * or a specific MBEDTLS_ERR_XXX error code
  29829. */
  29830. int mbedtls_ssl_ticket_setup( mbedtls_ssl_ticket_context *ctx,
  29831. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
  29832. mbedtls_cipher_type_t cipher,
  29833. uint32_t lifetime );
  29834. /**
  29835. * \brief Implementation of the ticket write callback
  29836. *
  29837. * \note See \c mbedtls_ssl_ticket_write_t for description
  29838. */
  29839. mbedtls_ssl_ticket_write_t mbedtls_ssl_ticket_write;
  29840. /**
  29841. * \brief Implementation of the ticket parse callback
  29842. *
  29843. * \note See \c mbedtls_ssl_ticket_parse_t for description
  29844. */
  29845. mbedtls_ssl_ticket_parse_t mbedtls_ssl_ticket_parse;
  29846. /**
  29847. * \brief Free a context's content and zeroize it.
  29848. *
  29849. * \param ctx Context to be cleaned up
  29850. */
  29851. void mbedtls_ssl_ticket_free( mbedtls_ssl_ticket_context *ctx );
  29852. #ifdef __cplusplus
  29853. }
  29854. #endif
  29855. #endif /* ssl_ticket.h */
  29856. /********* Start of file include/mbedtls/debug.h ************/
  29857. /**
  29858. * \file debug.h
  29859. *
  29860. * \brief Functions for controlling and providing debug output from the library.
  29861. */
  29862. /*
  29863. * Copyright The Mbed TLS Contributors
  29864. * SPDX-License-Identifier: Apache-2.0
  29865. *
  29866. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  29867. * not use this file except in compliance with the License.
  29868. * You may obtain a copy of the License at
  29869. *
  29870. * http://www.apache.org/licenses/LICENSE-2.0
  29871. *
  29872. * Unless required by applicable law or agreed to in writing, software
  29873. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  29874. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  29875. * See the License for the specific language governing permissions and
  29876. * limitations under the License.
  29877. */
  29878. #ifndef MBEDTLS_DEBUG_H
  29879. #define MBEDTLS_DEBUG_H
  29880. #if !defined(MBEDTLS_CONFIG_FILE)
  29881. #else
  29882. #endif
  29883. #if defined(MBEDTLS_ECP_C)
  29884. #endif
  29885. #if defined(MBEDTLS_DEBUG_C)
  29886. #define MBEDTLS_DEBUG_STRIP_PARENS( ... ) __VA_ARGS__
  29887. #define MBEDTLS_SSL_DEBUG_MSG( level, args ) \
  29888. mbedtls_debug_print_msg( ssl, level, __FILE__, __LINE__, \
  29889. MBEDTLS_DEBUG_STRIP_PARENS args )
  29890. #define MBEDTLS_SSL_DEBUG_RET( level, text, ret ) \
  29891. mbedtls_debug_print_ret( ssl, level, __FILE__, __LINE__, text, ret )
  29892. #define MBEDTLS_SSL_DEBUG_BUF( level, text, buf, len ) \
  29893. mbedtls_debug_print_buf( ssl, level, __FILE__, __LINE__, text, buf, len )
  29894. #if defined(MBEDTLS_BIGNUM_C)
  29895. #define MBEDTLS_SSL_DEBUG_MPI( level, text, X ) \
  29896. mbedtls_debug_print_mpi( ssl, level, __FILE__, __LINE__, text, X )
  29897. #endif
  29898. #if defined(MBEDTLS_ECP_C)
  29899. #define MBEDTLS_SSL_DEBUG_ECP( level, text, X ) \
  29900. mbedtls_debug_print_ecp( ssl, level, __FILE__, __LINE__, text, X )
  29901. #endif
  29902. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  29903. #define MBEDTLS_SSL_DEBUG_CRT( level, text, crt ) \
  29904. mbedtls_debug_print_crt( ssl, level, __FILE__, __LINE__, text, crt )
  29905. #endif
  29906. #if defined(MBEDTLS_ECDH_C)
  29907. #define MBEDTLS_SSL_DEBUG_ECDH( level, ecdh, attr ) \
  29908. mbedtls_debug_printf_ecdh( ssl, level, __FILE__, __LINE__, ecdh, attr )
  29909. #endif
  29910. #else /* MBEDTLS_DEBUG_C */
  29911. #define MBEDTLS_SSL_DEBUG_MSG( level, args ) do { } while( 0 )
  29912. #define MBEDTLS_SSL_DEBUG_RET( level, text, ret ) do { } while( 0 )
  29913. #define MBEDTLS_SSL_DEBUG_BUF( level, text, buf, len ) do { } while( 0 )
  29914. #define MBEDTLS_SSL_DEBUG_MPI( level, text, X ) do { } while( 0 )
  29915. #define MBEDTLS_SSL_DEBUG_ECP( level, text, X ) do { } while( 0 )
  29916. #define MBEDTLS_SSL_DEBUG_CRT( level, text, crt ) do { } while( 0 )
  29917. #define MBEDTLS_SSL_DEBUG_ECDH( level, ecdh, attr ) do { } while( 0 )
  29918. #endif /* MBEDTLS_DEBUG_C */
  29919. /**
  29920. * \def MBEDTLS_PRINTF_ATTRIBUTE
  29921. *
  29922. * Mark a function as having printf attributes, and thus enable checking
  29923. * via -wFormat and other flags. This does nothing on builds with compilers
  29924. * that do not support the format attribute
  29925. *
  29926. * Module: library/debug.c
  29927. * Caller:
  29928. *
  29929. * This module provides debugging functions.
  29930. */
  29931. #if defined(__has_attribute)
  29932. #if __has_attribute(format)
  29933. #if defined(__MINGW32__) && __USE_MINGW_ANSI_STDIO == 1
  29934. #define MBEDTLS_PRINTF_ATTRIBUTE(string_index, first_to_check) \
  29935. __attribute__((__format__ (gnu_printf, string_index, first_to_check)))
  29936. #else /* defined(__MINGW32__) && __USE_MINGW_ANSI_STDIO == 1 */
  29937. #define MBEDTLS_PRINTF_ATTRIBUTE(string_index, first_to_check) \
  29938. __attribute__((format(printf, string_index, first_to_check)))
  29939. #endif
  29940. #else /* __has_attribute(format) */
  29941. #define MBEDTLS_PRINTF_ATTRIBUTE(string_index, first_to_check)
  29942. #endif /* __has_attribute(format) */
  29943. #else /* defined(__has_attribute) */
  29944. #define MBEDTLS_PRINTF_ATTRIBUTE(string_index, first_to_check)
  29945. #endif
  29946. /**
  29947. * \def MBEDTLS_PRINTF_SIZET
  29948. *
  29949. * MBEDTLS_PRINTF_xxx: Due to issues with older window compilers
  29950. * and MinGW we need to define the printf specifier for size_t
  29951. * and long long per platform.
  29952. *
  29953. * Module: library/debug.c
  29954. * Caller:
  29955. *
  29956. * This module provides debugging functions.
  29957. */
  29958. #if (defined(__MINGW32__) && __USE_MINGW_ANSI_STDIO == 0) || (defined(_MSC_VER) && _MSC_VER < 1800)
  29959. #include <inttypes.h>
  29960. #define MBEDTLS_PRINTF_SIZET PRIuPTR
  29961. #define MBEDTLS_PRINTF_LONGLONG "I64d"
  29962. #else /* (defined(__MINGW32__) && __USE_MINGW_ANSI_STDIO == 0) || (defined(_MSC_VER) && _MSC_VER < 1800) */
  29963. #define MBEDTLS_PRINTF_SIZET "zu"
  29964. #define MBEDTLS_PRINTF_LONGLONG "lld"
  29965. #endif /* (defined(__MINGW32__) && __USE_MINGW_ANSI_STDIO == 0) || (defined(_MSC_VER) && _MSC_VER < 1800) */
  29966. #ifdef __cplusplus
  29967. extern "C" {
  29968. #endif
  29969. /**
  29970. * \brief Set the threshold error level to handle globally all debug output.
  29971. * Debug messages that have a level over the threshold value are
  29972. * discarded.
  29973. * (Default value: 0 = No debug )
  29974. *
  29975. * \param threshold theshold level of messages to filter on. Messages at a
  29976. * higher level will be discarded.
  29977. * - Debug levels
  29978. * - 0 No debug
  29979. * - 1 Error
  29980. * - 2 State change
  29981. * - 3 Informational
  29982. * - 4 Verbose
  29983. */
  29984. void mbedtls_debug_set_threshold( int threshold );
  29985. /**
  29986. * \brief Print a message to the debug output. This function is always used
  29987. * through the MBEDTLS_SSL_DEBUG_MSG() macro, which supplies the ssl
  29988. * context, file and line number parameters.
  29989. *
  29990. * \param ssl SSL context
  29991. * \param level error level of the debug message
  29992. * \param file file the message has occurred in
  29993. * \param line line number the message has occurred at
  29994. * \param format format specifier, in printf format
  29995. * \param ... variables used by the format specifier
  29996. *
  29997. * \attention This function is intended for INTERNAL usage within the
  29998. * library only.
  29999. */
  30000. void mbedtls_debug_print_msg( const mbedtls_ssl_context *ssl, int level,
  30001. const char *file, int line,
  30002. const char *format, ... ) MBEDTLS_PRINTF_ATTRIBUTE(5, 6);
  30003. /**
  30004. * \brief Print the return value of a function to the debug output. This
  30005. * function is always used through the MBEDTLS_SSL_DEBUG_RET() macro,
  30006. * which supplies the ssl context, file and line number parameters.
  30007. *
  30008. * \param ssl SSL context
  30009. * \param level error level of the debug message
  30010. * \param file file the error has occurred in
  30011. * \param line line number the error has occurred in
  30012. * \param text the name of the function that returned the error
  30013. * \param ret the return code value
  30014. *
  30015. * \attention This function is intended for INTERNAL usage within the
  30016. * library only.
  30017. */
  30018. void mbedtls_debug_print_ret( const mbedtls_ssl_context *ssl, int level,
  30019. const char *file, int line,
  30020. const char *text, int ret );
  30021. /**
  30022. * \brief Output a buffer of size len bytes to the debug output. This function
  30023. * is always used through the MBEDTLS_SSL_DEBUG_BUF() macro,
  30024. * which supplies the ssl context, file and line number parameters.
  30025. *
  30026. * \param ssl SSL context
  30027. * \param level error level of the debug message
  30028. * \param file file the error has occurred in
  30029. * \param line line number the error has occurred in
  30030. * \param text a name or label for the buffer being dumped. Normally the
  30031. * variable or buffer name
  30032. * \param buf the buffer to be outputted
  30033. * \param len length of the buffer
  30034. *
  30035. * \attention This function is intended for INTERNAL usage within the
  30036. * library only.
  30037. */
  30038. void mbedtls_debug_print_buf( const mbedtls_ssl_context *ssl, int level,
  30039. const char *file, int line, const char *text,
  30040. const unsigned char *buf, size_t len );
  30041. #if defined(MBEDTLS_BIGNUM_C)
  30042. /**
  30043. * \brief Print a MPI variable to the debug output. This function is always
  30044. * used through the MBEDTLS_SSL_DEBUG_MPI() macro, which supplies the
  30045. * ssl context, file and line number parameters.
  30046. *
  30047. * \param ssl SSL context
  30048. * \param level error level of the debug message
  30049. * \param file file the error has occurred in
  30050. * \param line line number the error has occurred in
  30051. * \param text a name or label for the MPI being output. Normally the
  30052. * variable name
  30053. * \param X the MPI variable
  30054. *
  30055. * \attention This function is intended for INTERNAL usage within the
  30056. * library only.
  30057. */
  30058. void mbedtls_debug_print_mpi( const mbedtls_ssl_context *ssl, int level,
  30059. const char *file, int line,
  30060. const char *text, const mbedtls_mpi *X );
  30061. #endif
  30062. #if defined(MBEDTLS_ECP_C)
  30063. /**
  30064. * \brief Print an ECP point to the debug output. This function is always
  30065. * used through the MBEDTLS_SSL_DEBUG_ECP() macro, which supplies the
  30066. * ssl context, file and line number parameters.
  30067. *
  30068. * \param ssl SSL context
  30069. * \param level error level of the debug message
  30070. * \param file file the error has occurred in
  30071. * \param line line number the error has occurred in
  30072. * \param text a name or label for the ECP point being output. Normally the
  30073. * variable name
  30074. * \param X the ECP point
  30075. *
  30076. * \attention This function is intended for INTERNAL usage within the
  30077. * library only.
  30078. */
  30079. void mbedtls_debug_print_ecp( const mbedtls_ssl_context *ssl, int level,
  30080. const char *file, int line,
  30081. const char *text, const mbedtls_ecp_point *X );
  30082. #endif
  30083. #if defined(MBEDTLS_X509_CRT_PARSE_C)
  30084. /**
  30085. * \brief Print a X.509 certificate structure to the debug output. This
  30086. * function is always used through the MBEDTLS_SSL_DEBUG_CRT() macro,
  30087. * which supplies the ssl context, file and line number parameters.
  30088. *
  30089. * \param ssl SSL context
  30090. * \param level error level of the debug message
  30091. * \param file file the error has occurred in
  30092. * \param line line number the error has occurred in
  30093. * \param text a name or label for the certificate being output
  30094. * \param crt X.509 certificate structure
  30095. *
  30096. * \attention This function is intended for INTERNAL usage within the
  30097. * library only.
  30098. */
  30099. void mbedtls_debug_print_crt( const mbedtls_ssl_context *ssl, int level,
  30100. const char *file, int line,
  30101. const char *text, const mbedtls_x509_crt *crt );
  30102. #endif
  30103. #if defined(MBEDTLS_ECDH_C)
  30104. typedef enum
  30105. {
  30106. MBEDTLS_DEBUG_ECDH_Q,
  30107. MBEDTLS_DEBUG_ECDH_QP,
  30108. MBEDTLS_DEBUG_ECDH_Z,
  30109. } mbedtls_debug_ecdh_attr;
  30110. /**
  30111. * \brief Print a field of the ECDH structure in the SSL context to the debug
  30112. * output. This function is always used through the
  30113. * MBEDTLS_SSL_DEBUG_ECDH() macro, which supplies the ssl context, file
  30114. * and line number parameters.
  30115. *
  30116. * \param ssl SSL context
  30117. * \param level error level of the debug message
  30118. * \param file file the error has occurred in
  30119. * \param line line number the error has occurred in
  30120. * \param ecdh the ECDH context
  30121. * \param attr the identifier of the attribute being output
  30122. *
  30123. * \attention This function is intended for INTERNAL usage within the
  30124. * library only.
  30125. */
  30126. void mbedtls_debug_printf_ecdh( const mbedtls_ssl_context *ssl, int level,
  30127. const char *file, int line,
  30128. const mbedtls_ecdh_context *ecdh,
  30129. mbedtls_debug_ecdh_attr attr );
  30130. #endif
  30131. #ifdef __cplusplus
  30132. }
  30133. #endif
  30134. #endif /* debug.h */
  30135. /********* Start of file include/mbedtls/blowfish.h ************/
  30136. /**
  30137. * \file blowfish.h
  30138. *
  30139. * \brief Blowfish block cipher
  30140. */
  30141. /*
  30142. * Copyright The Mbed TLS Contributors
  30143. * SPDX-License-Identifier: Apache-2.0
  30144. *
  30145. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  30146. * not use this file except in compliance with the License.
  30147. * You may obtain a copy of the License at
  30148. *
  30149. * http://www.apache.org/licenses/LICENSE-2.0
  30150. *
  30151. * Unless required by applicable law or agreed to in writing, software
  30152. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  30153. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  30154. * See the License for the specific language governing permissions and
  30155. * limitations under the License.
  30156. */
  30157. #ifndef MBEDTLS_BLOWFISH_H
  30158. #define MBEDTLS_BLOWFISH_H
  30159. #if !defined(MBEDTLS_CONFIG_FILE)
  30160. #else
  30161. #endif
  30162. #include <stddef.h>
  30163. #include <stdint.h>
  30164. #define MBEDTLS_BLOWFISH_ENCRYPT 1
  30165. #define MBEDTLS_BLOWFISH_DECRYPT 0
  30166. #define MBEDTLS_BLOWFISH_MAX_KEY_BITS 448
  30167. #define MBEDTLS_BLOWFISH_MIN_KEY_BITS 32
  30168. #define MBEDTLS_BLOWFISH_ROUNDS 16 /**< Rounds to use. When increasing this value, make sure to extend the initialisation vectors */
  30169. #define MBEDTLS_BLOWFISH_BLOCKSIZE 8 /* Blowfish uses 64 bit blocks */
  30170. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  30171. #define MBEDTLS_ERR_BLOWFISH_INVALID_KEY_LENGTH MBEDTLS_DEPRECATED_NUMERIC_CONSTANT( -0x0016 )
  30172. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  30173. /** Bad input data. */
  30174. #define MBEDTLS_ERR_BLOWFISH_BAD_INPUT_DATA -0x0016
  30175. /** Invalid data input length. */
  30176. #define MBEDTLS_ERR_BLOWFISH_INVALID_INPUT_LENGTH -0x0018
  30177. /* MBEDTLS_ERR_BLOWFISH_HW_ACCEL_FAILED is deprecated and should not be used.
  30178. */
  30179. /** Blowfish hardware accelerator failed. */
  30180. #define MBEDTLS_ERR_BLOWFISH_HW_ACCEL_FAILED -0x0017
  30181. #ifdef __cplusplus
  30182. extern "C" {
  30183. #endif
  30184. #if !defined(MBEDTLS_BLOWFISH_ALT)
  30185. // Regular implementation
  30186. //
  30187. /**
  30188. * \brief Blowfish context structure
  30189. */
  30190. typedef struct mbedtls_blowfish_context
  30191. {
  30192. uint32_t P[MBEDTLS_BLOWFISH_ROUNDS + 2]; /*!< Blowfish round keys */
  30193. uint32_t S[4][256]; /*!< key dependent S-boxes */
  30194. }
  30195. mbedtls_blowfish_context;
  30196. #else /* MBEDTLS_BLOWFISH_ALT */
  30197. #endif /* MBEDTLS_BLOWFISH_ALT */
  30198. /**
  30199. * \brief Initialize a Blowfish context.
  30200. *
  30201. * \param ctx The Blowfish context to be initialized.
  30202. * This must not be \c NULL.
  30203. */
  30204. void mbedtls_blowfish_init( mbedtls_blowfish_context *ctx );
  30205. /**
  30206. * \brief Clear a Blowfish context.
  30207. *
  30208. * \param ctx The Blowfish context to be cleared.
  30209. * This may be \c NULL, in which case this function
  30210. * returns immediately. If it is not \c NULL, it must
  30211. * point to an initialized Blowfish context.
  30212. */
  30213. void mbedtls_blowfish_free( mbedtls_blowfish_context *ctx );
  30214. /**
  30215. * \brief Perform a Blowfish key schedule operation.
  30216. *
  30217. * \param ctx The Blowfish context to perform the key schedule on.
  30218. * \param key The encryption key. This must be a readable buffer of
  30219. * length \p keybits Bits.
  30220. * \param keybits The length of \p key in Bits. This must be between
  30221. * \c 32 and \c 448 and a multiple of \c 8.
  30222. *
  30223. * \return \c 0 if successful.
  30224. * \return A negative error code on failure.
  30225. */
  30226. int mbedtls_blowfish_setkey( mbedtls_blowfish_context *ctx, const unsigned char *key,
  30227. unsigned int keybits );
  30228. /**
  30229. * \brief Perform a Blowfish-ECB block encryption/decryption operation.
  30230. *
  30231. * \param ctx The Blowfish context to use. This must be initialized
  30232. * and bound to a key.
  30233. * \param mode The mode of operation. Possible values are
  30234. * #MBEDTLS_BLOWFISH_ENCRYPT for encryption, or
  30235. * #MBEDTLS_BLOWFISH_DECRYPT for decryption.
  30236. * \param input The input block. This must be a readable buffer
  30237. * of size \c 8 Bytes.
  30238. * \param output The output block. This must be a writable buffer
  30239. * of size \c 8 Bytes.
  30240. *
  30241. * \return \c 0 if successful.
  30242. * \return A negative error code on failure.
  30243. */
  30244. int mbedtls_blowfish_crypt_ecb( mbedtls_blowfish_context *ctx,
  30245. int mode,
  30246. const unsigned char input[MBEDTLS_BLOWFISH_BLOCKSIZE],
  30247. unsigned char output[MBEDTLS_BLOWFISH_BLOCKSIZE] );
  30248. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  30249. /**
  30250. * \brief Perform a Blowfish-CBC buffer encryption/decryption operation.
  30251. *
  30252. * \note Upon exit, the content of the IV is updated so that you can
  30253. * call the function same function again on the following
  30254. * block(s) of data and get the same result as if it was
  30255. * encrypted in one call. This allows a "streaming" usage.
  30256. * If on the other hand you need to retain the contents of the
  30257. * IV, you should either save it manually or use the cipher
  30258. * module instead.
  30259. *
  30260. * \param ctx The Blowfish context to use. This must be initialized
  30261. * and bound to a key.
  30262. * \param mode The mode of operation. Possible values are
  30263. * #MBEDTLS_BLOWFISH_ENCRYPT for encryption, or
  30264. * #MBEDTLS_BLOWFISH_DECRYPT for decryption.
  30265. * \param length The length of the input data in Bytes. This must be
  30266. * multiple of \c 8.
  30267. * \param iv The initialization vector. This must be a read/write buffer
  30268. * of length \c 8 Bytes. It is updated by this function.
  30269. * \param input The input data. This must be a readable buffer of length
  30270. * \p length Bytes.
  30271. * \param output The output data. This must be a writable buffer of length
  30272. * \p length Bytes.
  30273. *
  30274. * \return \c 0 if successful.
  30275. * \return A negative error code on failure.
  30276. */
  30277. int mbedtls_blowfish_crypt_cbc( mbedtls_blowfish_context *ctx,
  30278. int mode,
  30279. size_t length,
  30280. unsigned char iv[MBEDTLS_BLOWFISH_BLOCKSIZE],
  30281. const unsigned char *input,
  30282. unsigned char *output );
  30283. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  30284. #if defined(MBEDTLS_CIPHER_MODE_CFB)
  30285. /**
  30286. * \brief Perform a Blowfish CFB buffer encryption/decryption operation.
  30287. *
  30288. * \note Upon exit, the content of the IV is updated so that you can
  30289. * call the function same function again on the following
  30290. * block(s) of data and get the same result as if it was
  30291. * encrypted in one call. This allows a "streaming" usage.
  30292. * If on the other hand you need to retain the contents of the
  30293. * IV, you should either save it manually or use the cipher
  30294. * module instead.
  30295. *
  30296. * \param ctx The Blowfish context to use. This must be initialized
  30297. * and bound to a key.
  30298. * \param mode The mode of operation. Possible values are
  30299. * #MBEDTLS_BLOWFISH_ENCRYPT for encryption, or
  30300. * #MBEDTLS_BLOWFISH_DECRYPT for decryption.
  30301. * \param length The length of the input data in Bytes.
  30302. * \param iv_off The offset in the initialiation vector.
  30303. * The value pointed to must be smaller than \c 8 Bytes.
  30304. * It is updated by this function to support the aforementioned
  30305. * streaming usage.
  30306. * \param iv The initialization vector. This must be a read/write buffer
  30307. * of size \c 8 Bytes. It is updated after use.
  30308. * \param input The input data. This must be a readable buffer of length
  30309. * \p length Bytes.
  30310. * \param output The output data. This must be a writable buffer of length
  30311. * \p length Bytes.
  30312. *
  30313. * \return \c 0 if successful.
  30314. * \return A negative error code on failure.
  30315. */
  30316. int mbedtls_blowfish_crypt_cfb64( mbedtls_blowfish_context *ctx,
  30317. int mode,
  30318. size_t length,
  30319. size_t *iv_off,
  30320. unsigned char iv[MBEDTLS_BLOWFISH_BLOCKSIZE],
  30321. const unsigned char *input,
  30322. unsigned char *output );
  30323. #endif /*MBEDTLS_CIPHER_MODE_CFB */
  30324. #if defined(MBEDTLS_CIPHER_MODE_CTR)
  30325. /**
  30326. * \brief Perform a Blowfish-CTR buffer encryption/decryption operation.
  30327. *
  30328. * \warning You must never reuse a nonce value with the same key. Doing so
  30329. * would void the encryption for the two messages encrypted with
  30330. * the same nonce and key.
  30331. *
  30332. * There are two common strategies for managing nonces with CTR:
  30333. *
  30334. * 1. You can handle everything as a single message processed over
  30335. * successive calls to this function. In that case, you want to
  30336. * set \p nonce_counter and \p nc_off to 0 for the first call, and
  30337. * then preserve the values of \p nonce_counter, \p nc_off and \p
  30338. * stream_block across calls to this function as they will be
  30339. * updated by this function.
  30340. *
  30341. * With this strategy, you must not encrypt more than 2**64
  30342. * blocks of data with the same key.
  30343. *
  30344. * 2. You can encrypt separate messages by dividing the \p
  30345. * nonce_counter buffer in two areas: the first one used for a
  30346. * per-message nonce, handled by yourself, and the second one
  30347. * updated by this function internally.
  30348. *
  30349. * For example, you might reserve the first 4 bytes for the
  30350. * per-message nonce, and the last 4 bytes for internal use. In that
  30351. * case, before calling this function on a new message you need to
  30352. * set the first 4 bytes of \p nonce_counter to your chosen nonce
  30353. * value, the last 4 to 0, and \p nc_off to 0 (which will cause \p
  30354. * stream_block to be ignored). That way, you can encrypt at most
  30355. * 2**32 messages of up to 2**32 blocks each with the same key.
  30356. *
  30357. * The per-message nonce (or information sufficient to reconstruct
  30358. * it) needs to be communicated with the ciphertext and must be unique.
  30359. * The recommended way to ensure uniqueness is to use a message
  30360. * counter.
  30361. *
  30362. * Note that for both stategies, sizes are measured in blocks and
  30363. * that a Blowfish block is 8 bytes.
  30364. *
  30365. * \warning Upon return, \p stream_block contains sensitive data. Its
  30366. * content must not be written to insecure storage and should be
  30367. * securely discarded as soon as it's no longer needed.
  30368. *
  30369. * \param ctx The Blowfish context to use. This must be initialized
  30370. * and bound to a key.
  30371. * \param length The length of the input data in Bytes.
  30372. * \param nc_off The offset in the current stream_block (for resuming
  30373. * within current cipher stream). The offset pointer
  30374. * should be \c 0 at the start of a stream and must be
  30375. * smaller than \c 8. It is updated by this function.
  30376. * \param nonce_counter The 64-bit nonce and counter. This must point to a
  30377. * read/write buffer of length \c 8 Bytes.
  30378. * \param stream_block The saved stream-block for resuming. This must point to
  30379. * a read/write buffer of length \c 8 Bytes.
  30380. * \param input The input data. This must be a readable buffer of
  30381. * length \p length Bytes.
  30382. * \param output The output data. This must be a writable buffer of
  30383. * length \p length Bytes.
  30384. *
  30385. * \return \c 0 if successful.
  30386. * \return A negative error code on failure.
  30387. */
  30388. int mbedtls_blowfish_crypt_ctr( mbedtls_blowfish_context *ctx,
  30389. size_t length,
  30390. size_t *nc_off,
  30391. unsigned char nonce_counter[MBEDTLS_BLOWFISH_BLOCKSIZE],
  30392. unsigned char stream_block[MBEDTLS_BLOWFISH_BLOCKSIZE],
  30393. const unsigned char *input,
  30394. unsigned char *output );
  30395. #endif /* MBEDTLS_CIPHER_MODE_CTR */
  30396. #ifdef __cplusplus
  30397. }
  30398. #endif
  30399. #endif /* blowfish.h */
  30400. /********* Start of file include/mbedtls/ccm.h ************/
  30401. /**
  30402. * \file ccm.h
  30403. *
  30404. * \brief This file provides an API for the CCM authenticated encryption
  30405. * mode for block ciphers.
  30406. *
  30407. * CCM combines Counter mode encryption with CBC-MAC authentication
  30408. * for 128-bit block ciphers.
  30409. *
  30410. * Input to CCM includes the following elements:
  30411. * <ul><li>Payload - data that is both authenticated and encrypted.</li>
  30412. * <li>Associated data (Adata) - data that is authenticated but not
  30413. * encrypted, For example, a header.</li>
  30414. * <li>Nonce - A unique value that is assigned to the payload and the
  30415. * associated data.</li></ul>
  30416. *
  30417. * Definition of CCM:
  30418. * http://csrc.nist.gov/publications/nistpubs/800-38C/SP800-38C_updated-July20_2007.pdf
  30419. * RFC 3610 "Counter with CBC-MAC (CCM)"
  30420. *
  30421. * Related:
  30422. * RFC 5116 "An Interface and Algorithms for Authenticated Encryption"
  30423. *
  30424. * Definition of CCM*:
  30425. * IEEE 802.15.4 - IEEE Standard for Local and metropolitan area networks
  30426. * Integer representation is fixed most-significant-octet-first order and
  30427. * the representation of octets is most-significant-bit-first order. This is
  30428. * consistent with RFC 3610.
  30429. */
  30430. /*
  30431. * Copyright The Mbed TLS Contributors
  30432. * SPDX-License-Identifier: Apache-2.0
  30433. *
  30434. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  30435. * not use this file except in compliance with the License.
  30436. * You may obtain a copy of the License at
  30437. *
  30438. * http://www.apache.org/licenses/LICENSE-2.0
  30439. *
  30440. * Unless required by applicable law or agreed to in writing, software
  30441. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  30442. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  30443. * See the License for the specific language governing permissions and
  30444. * limitations under the License.
  30445. */
  30446. #ifndef MBEDTLS_CCM_H
  30447. #define MBEDTLS_CCM_H
  30448. #if !defined(MBEDTLS_CONFIG_FILE)
  30449. #else
  30450. #endif
  30451. /** Bad input parameters to the function. */
  30452. #define MBEDTLS_ERR_CCM_BAD_INPUT -0x000D
  30453. /** Authenticated decryption failed. */
  30454. #define MBEDTLS_ERR_CCM_AUTH_FAILED -0x000F
  30455. /* MBEDTLS_ERR_CCM_HW_ACCEL_FAILED is deprecated and should not be used. */
  30456. /** CCM hardware accelerator failed. */
  30457. #define MBEDTLS_ERR_CCM_HW_ACCEL_FAILED -0x0011
  30458. #ifdef __cplusplus
  30459. extern "C" {
  30460. #endif
  30461. #if !defined(MBEDTLS_CCM_ALT)
  30462. // Regular implementation
  30463. //
  30464. /**
  30465. * \brief The CCM context-type definition. The CCM context is passed
  30466. * to the APIs called.
  30467. */
  30468. typedef struct mbedtls_ccm_context
  30469. {
  30470. mbedtls_cipher_context_t cipher_ctx; /*!< The cipher context used. */
  30471. }
  30472. mbedtls_ccm_context;
  30473. #else /* MBEDTLS_CCM_ALT */
  30474. #endif /* MBEDTLS_CCM_ALT */
  30475. /**
  30476. * \brief This function initializes the specified CCM context,
  30477. * to make references valid, and prepare the context
  30478. * for mbedtls_ccm_setkey() or mbedtls_ccm_free().
  30479. *
  30480. * \param ctx The CCM context to initialize. This must not be \c NULL.
  30481. */
  30482. void mbedtls_ccm_init( mbedtls_ccm_context *ctx );
  30483. /**
  30484. * \brief This function initializes the CCM context set in the
  30485. * \p ctx parameter and sets the encryption key.
  30486. *
  30487. * \param ctx The CCM context to initialize. This must be an initialized
  30488. * context.
  30489. * \param cipher The 128-bit block cipher to use.
  30490. * \param key The encryption key. This must not be \c NULL.
  30491. * \param keybits The key size in bits. This must be acceptable by the cipher.
  30492. *
  30493. * \return \c 0 on success.
  30494. * \return A CCM or cipher-specific error code on failure.
  30495. */
  30496. int mbedtls_ccm_setkey( mbedtls_ccm_context *ctx,
  30497. mbedtls_cipher_id_t cipher,
  30498. const unsigned char *key,
  30499. unsigned int keybits );
  30500. /**
  30501. * \brief This function releases and clears the specified CCM context
  30502. * and underlying cipher sub-context.
  30503. *
  30504. * \param ctx The CCM context to clear. If this is \c NULL, the function
  30505. * has no effect. Otherwise, this must be initialized.
  30506. */
  30507. void mbedtls_ccm_free( mbedtls_ccm_context *ctx );
  30508. /**
  30509. * \brief This function encrypts a buffer using CCM.
  30510. *
  30511. * \note The tag is written to a separate buffer. To concatenate
  30512. * the \p tag with the \p output, as done in <em>RFC-3610:
  30513. * Counter with CBC-MAC (CCM)</em>, use
  30514. * \p tag = \p output + \p length, and make sure that the
  30515. * output buffer is at least \p length + \p tag_len wide.
  30516. *
  30517. * \param ctx The CCM context to use for encryption. This must be
  30518. * initialized and bound to a key.
  30519. * \param length The length of the input data in Bytes.
  30520. * \param iv The initialization vector (nonce). This must be a readable
  30521. * buffer of at least \p iv_len Bytes.
  30522. * \param iv_len The length of the nonce in Bytes: 7, 8, 9, 10, 11, 12,
  30523. * or 13. The length L of the message length field is
  30524. * 15 - \p iv_len.
  30525. * \param add The additional data field. If \p add_len is greater than
  30526. * zero, \p add must be a readable buffer of at least that
  30527. * length.
  30528. * \param add_len The length of additional data in Bytes.
  30529. * This must be less than `2^16 - 2^8`.
  30530. * \param input The buffer holding the input data. If \p length is greater
  30531. * than zero, \p input must be a readable buffer of at least
  30532. * that length.
  30533. * \param output The buffer holding the output data. If \p length is greater
  30534. * than zero, \p output must be a writable buffer of at least
  30535. * that length.
  30536. * \param tag The buffer holding the authentication field. This must be a
  30537. * writable buffer of at least \p tag_len Bytes.
  30538. * \param tag_len The length of the authentication field to generate in Bytes:
  30539. * 4, 6, 8, 10, 12, 14 or 16.
  30540. *
  30541. * \return \c 0 on success.
  30542. * \return A CCM or cipher-specific error code on failure.
  30543. */
  30544. int mbedtls_ccm_encrypt_and_tag( mbedtls_ccm_context *ctx, size_t length,
  30545. const unsigned char *iv, size_t iv_len,
  30546. const unsigned char *add, size_t add_len,
  30547. const unsigned char *input, unsigned char *output,
  30548. unsigned char *tag, size_t tag_len );
  30549. /**
  30550. * \brief This function encrypts a buffer using CCM*.
  30551. *
  30552. * \note The tag is written to a separate buffer. To concatenate
  30553. * the \p tag with the \p output, as done in <em>RFC-3610:
  30554. * Counter with CBC-MAC (CCM)</em>, use
  30555. * \p tag = \p output + \p length, and make sure that the
  30556. * output buffer is at least \p length + \p tag_len wide.
  30557. *
  30558. * \note When using this function in a variable tag length context,
  30559. * the tag length has to be encoded into the \p iv passed to
  30560. * this function.
  30561. *
  30562. * \param ctx The CCM context to use for encryption. This must be
  30563. * initialized and bound to a key.
  30564. * \param length The length of the input data in Bytes.
  30565. * \param iv The initialization vector (nonce). This must be a readable
  30566. * buffer of at least \p iv_len Bytes.
  30567. * \param iv_len The length of the nonce in Bytes: 7, 8, 9, 10, 11, 12,
  30568. * or 13. The length L of the message length field is
  30569. * 15 - \p iv_len.
  30570. * \param add The additional data field. This must be a readable buffer of
  30571. * at least \p add_len Bytes.
  30572. * \param add_len The length of additional data in Bytes.
  30573. * This must be less than 2^16 - 2^8.
  30574. * \param input The buffer holding the input data. If \p length is greater
  30575. * than zero, \p input must be a readable buffer of at least
  30576. * that length.
  30577. * \param output The buffer holding the output data. If \p length is greater
  30578. * than zero, \p output must be a writable buffer of at least
  30579. * that length.
  30580. * \param tag The buffer holding the authentication field. This must be a
  30581. * writable buffer of at least \p tag_len Bytes.
  30582. * \param tag_len The length of the authentication field to generate in Bytes:
  30583. * 0, 4, 6, 8, 10, 12, 14 or 16.
  30584. *
  30585. * \warning Passing \c 0 as \p tag_len means that the message is no
  30586. * longer authenticated.
  30587. *
  30588. * \return \c 0 on success.
  30589. * \return A CCM or cipher-specific error code on failure.
  30590. */
  30591. int mbedtls_ccm_star_encrypt_and_tag( mbedtls_ccm_context *ctx, size_t length,
  30592. const unsigned char *iv, size_t iv_len,
  30593. const unsigned char *add, size_t add_len,
  30594. const unsigned char *input, unsigned char *output,
  30595. unsigned char *tag, size_t tag_len );
  30596. /**
  30597. * \brief This function performs a CCM authenticated decryption of a
  30598. * buffer.
  30599. *
  30600. * \param ctx The CCM context to use for decryption. This must be
  30601. * initialized and bound to a key.
  30602. * \param length The length of the input data in Bytes.
  30603. * \param iv The initialization vector (nonce). This must be a readable
  30604. * buffer of at least \p iv_len Bytes.
  30605. * \param iv_len The length of the nonce in Bytes: 7, 8, 9, 10, 11, 12,
  30606. * or 13. The length L of the message length field is
  30607. * 15 - \p iv_len.
  30608. * \param add The additional data field. This must be a readable buffer
  30609. * of at least that \p add_len Bytes..
  30610. * \param add_len The length of additional data in Bytes.
  30611. * This must be less than 2^16 - 2^8.
  30612. * \param input The buffer holding the input data. If \p length is greater
  30613. * than zero, \p input must be a readable buffer of at least
  30614. * that length.
  30615. * \param output The buffer holding the output data. If \p length is greater
  30616. * than zero, \p output must be a writable buffer of at least
  30617. * that length.
  30618. * \param tag The buffer holding the authentication field. This must be a
  30619. * readable buffer of at least \p tag_len Bytes.
  30620. * \param tag_len The length of the authentication field to generate in Bytes:
  30621. * 4, 6, 8, 10, 12, 14 or 16.
  30622. *
  30623. * \return \c 0 on success. This indicates that the message is authentic.
  30624. * \return #MBEDTLS_ERR_CCM_AUTH_FAILED if the tag does not match.
  30625. * \return A cipher-specific error code on calculation failure.
  30626. */
  30627. int mbedtls_ccm_auth_decrypt( mbedtls_ccm_context *ctx, size_t length,
  30628. const unsigned char *iv, size_t iv_len,
  30629. const unsigned char *add, size_t add_len,
  30630. const unsigned char *input, unsigned char *output,
  30631. const unsigned char *tag, size_t tag_len );
  30632. /**
  30633. * \brief This function performs a CCM* authenticated decryption of a
  30634. * buffer.
  30635. *
  30636. * \note When using this function in a variable tag length context,
  30637. * the tag length has to be decoded from \p iv and passed to
  30638. * this function as \p tag_len. (\p tag needs to be adjusted
  30639. * accordingly.)
  30640. *
  30641. * \param ctx The CCM context to use for decryption. This must be
  30642. * initialized and bound to a key.
  30643. * \param length The length of the input data in Bytes.
  30644. * \param iv The initialization vector (nonce). This must be a readable
  30645. * buffer of at least \p iv_len Bytes.
  30646. * \param iv_len The length of the nonce in Bytes: 7, 8, 9, 10, 11, 12,
  30647. * or 13. The length L of the message length field is
  30648. * 15 - \p iv_len.
  30649. * \param add The additional data field. This must be a readable buffer of
  30650. * at least that \p add_len Bytes.
  30651. * \param add_len The length of additional data in Bytes.
  30652. * This must be less than 2^16 - 2^8.
  30653. * \param input The buffer holding the input data. If \p length is greater
  30654. * than zero, \p input must be a readable buffer of at least
  30655. * that length.
  30656. * \param output The buffer holding the output data. If \p length is greater
  30657. * than zero, \p output must be a writable buffer of at least
  30658. * that length.
  30659. * \param tag The buffer holding the authentication field. This must be a
  30660. * readable buffer of at least \p tag_len Bytes.
  30661. * \param tag_len The length of the authentication field in Bytes.
  30662. * 0, 4, 6, 8, 10, 12, 14 or 16.
  30663. *
  30664. * \warning Passing \c 0 as \p tag_len means that the message is nos
  30665. * longer authenticated.
  30666. *
  30667. * \return \c 0 on success.
  30668. * \return #MBEDTLS_ERR_CCM_AUTH_FAILED if the tag does not match.
  30669. * \return A cipher-specific error code on calculation failure.
  30670. */
  30671. int mbedtls_ccm_star_auth_decrypt( mbedtls_ccm_context *ctx, size_t length,
  30672. const unsigned char *iv, size_t iv_len,
  30673. const unsigned char *add, size_t add_len,
  30674. const unsigned char *input, unsigned char *output,
  30675. const unsigned char *tag, size_t tag_len );
  30676. #if defined(MBEDTLS_SELF_TEST) && defined(MBEDTLS_AES_C)
  30677. /**
  30678. * \brief The CCM checkup routine.
  30679. *
  30680. * \return \c 0 on success.
  30681. * \return \c 1 on failure.
  30682. */
  30683. int mbedtls_ccm_self_test( int verbose );
  30684. #endif /* MBEDTLS_SELF_TEST && MBEDTLS_AES_C */
  30685. #ifdef __cplusplus
  30686. }
  30687. #endif
  30688. #endif /* MBEDTLS_CCM_H */
  30689. /********* Start of file include/mbedtls/gcm.h ************/
  30690. /**
  30691. * \file gcm.h
  30692. *
  30693. * \brief This file contains GCM definitions and functions.
  30694. *
  30695. * The Galois/Counter Mode (GCM) for 128-bit block ciphers is defined
  30696. * in <em>D. McGrew, J. Viega, The Galois/Counter Mode of Operation
  30697. * (GCM), Natl. Inst. Stand. Technol.</em>
  30698. *
  30699. * For more information on GCM, see <em>NIST SP 800-38D: Recommendation for
  30700. * Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC</em>.
  30701. *
  30702. */
  30703. /*
  30704. * Copyright The Mbed TLS Contributors
  30705. * SPDX-License-Identifier: Apache-2.0
  30706. *
  30707. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  30708. * not use this file except in compliance with the License.
  30709. * You may obtain a copy of the License at
  30710. *
  30711. * http://www.apache.org/licenses/LICENSE-2.0
  30712. *
  30713. * Unless required by applicable law or agreed to in writing, software
  30714. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  30715. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  30716. * See the License for the specific language governing permissions and
  30717. * limitations under the License.
  30718. */
  30719. #ifndef MBEDTLS_GCM_H
  30720. #define MBEDTLS_GCM_H
  30721. #if !defined(MBEDTLS_CONFIG_FILE)
  30722. #else
  30723. #endif
  30724. #include <stdint.h>
  30725. #define MBEDTLS_GCM_ENCRYPT 1
  30726. #define MBEDTLS_GCM_DECRYPT 0
  30727. /** Authenticated decryption failed. */
  30728. #define MBEDTLS_ERR_GCM_AUTH_FAILED -0x0012
  30729. /* MBEDTLS_ERR_GCM_HW_ACCEL_FAILED is deprecated and should not be used. */
  30730. /** GCM hardware accelerator failed. */
  30731. #define MBEDTLS_ERR_GCM_HW_ACCEL_FAILED -0x0013
  30732. /** Bad input parameters to function. */
  30733. #define MBEDTLS_ERR_GCM_BAD_INPUT -0x0014
  30734. #ifdef __cplusplus
  30735. extern "C" {
  30736. #endif
  30737. #if !defined(MBEDTLS_GCM_ALT)
  30738. /**
  30739. * \brief The GCM context structure.
  30740. */
  30741. typedef struct mbedtls_gcm_context
  30742. {
  30743. mbedtls_cipher_context_t cipher_ctx; /*!< The cipher context used. */
  30744. uint64_t HL[16]; /*!< Precalculated HTable low. */
  30745. uint64_t HH[16]; /*!< Precalculated HTable high. */
  30746. uint64_t len; /*!< The total length of the encrypted data. */
  30747. uint64_t add_len; /*!< The total length of the additional data. */
  30748. unsigned char base_ectr[16]; /*!< The first ECTR for tag. */
  30749. unsigned char y[16]; /*!< The Y working value. */
  30750. unsigned char buf[16]; /*!< The buf working value. */
  30751. int mode; /*!< The operation to perform:
  30752. #MBEDTLS_GCM_ENCRYPT or
  30753. #MBEDTLS_GCM_DECRYPT. */
  30754. }
  30755. mbedtls_gcm_context;
  30756. #else /* !MBEDTLS_GCM_ALT */
  30757. #endif /* !MBEDTLS_GCM_ALT */
  30758. /**
  30759. * \brief This function initializes the specified GCM context,
  30760. * to make references valid, and prepares the context
  30761. * for mbedtls_gcm_setkey() or mbedtls_gcm_free().
  30762. *
  30763. * The function does not bind the GCM context to a particular
  30764. * cipher, nor set the key. For this purpose, use
  30765. * mbedtls_gcm_setkey().
  30766. *
  30767. * \param ctx The GCM context to initialize. This must not be \c NULL.
  30768. */
  30769. void mbedtls_gcm_init( mbedtls_gcm_context *ctx );
  30770. /**
  30771. * \brief This function associates a GCM context with a
  30772. * cipher algorithm and a key.
  30773. *
  30774. * \param ctx The GCM context. This must be initialized.
  30775. * \param cipher The 128-bit block cipher to use.
  30776. * \param key The encryption key. This must be a readable buffer of at
  30777. * least \p keybits bits.
  30778. * \param keybits The key size in bits. Valid options are:
  30779. * <ul><li>128 bits</li>
  30780. * <li>192 bits</li>
  30781. * <li>256 bits</li></ul>
  30782. *
  30783. * \return \c 0 on success.
  30784. * \return A cipher-specific error code on failure.
  30785. */
  30786. int mbedtls_gcm_setkey( mbedtls_gcm_context *ctx,
  30787. mbedtls_cipher_id_t cipher,
  30788. const unsigned char *key,
  30789. unsigned int keybits );
  30790. /**
  30791. * \brief This function performs GCM encryption or decryption of a buffer.
  30792. *
  30793. * \note For encryption, the output buffer can be the same as the
  30794. * input buffer. For decryption, the output buffer cannot be
  30795. * the same as input buffer. If the buffers overlap, the output
  30796. * buffer must trail at least 8 Bytes behind the input buffer.
  30797. *
  30798. * \warning When this function performs a decryption, it outputs the
  30799. * authentication tag and does not verify that the data is
  30800. * authentic. You should use this function to perform encryption
  30801. * only. For decryption, use mbedtls_gcm_auth_decrypt() instead.
  30802. *
  30803. * \param ctx The GCM context to use for encryption or decryption. This
  30804. * must be initialized.
  30805. * \param mode The operation to perform:
  30806. * - #MBEDTLS_GCM_ENCRYPT to perform authenticated encryption.
  30807. * The ciphertext is written to \p output and the
  30808. * authentication tag is written to \p tag.
  30809. * - #MBEDTLS_GCM_DECRYPT to perform decryption.
  30810. * The plaintext is written to \p output and the
  30811. * authentication tag is written to \p tag.
  30812. * Note that this mode is not recommended, because it does
  30813. * not verify the authenticity of the data. For this reason,
  30814. * you should use mbedtls_gcm_auth_decrypt() instead of
  30815. * calling this function in decryption mode.
  30816. * \param length The length of the input data, which is equal to the length
  30817. * of the output data.
  30818. * \param iv The initialization vector. This must be a readable buffer of
  30819. * at least \p iv_len Bytes.
  30820. * \param iv_len The length of the IV.
  30821. * \param add The buffer holding the additional data. This must be of at
  30822. * least that size in Bytes.
  30823. * \param add_len The length of the additional data.
  30824. * \param input The buffer holding the input data. If \p length is greater
  30825. * than zero, this must be a readable buffer of at least that
  30826. * size in Bytes.
  30827. * \param output The buffer for holding the output data. If \p length is greater
  30828. * than zero, this must be a writable buffer of at least that
  30829. * size in Bytes.
  30830. * \param tag_len The length of the tag to generate.
  30831. * \param tag The buffer for holding the tag. This must be a writable
  30832. * buffer of at least \p tag_len Bytes.
  30833. *
  30834. * \return \c 0 if the encryption or decryption was performed
  30835. * successfully. Note that in #MBEDTLS_GCM_DECRYPT mode,
  30836. * this does not indicate that the data is authentic.
  30837. * \return #MBEDTLS_ERR_GCM_BAD_INPUT if the lengths or pointers are
  30838. * not valid or a cipher-specific error code if the encryption
  30839. * or decryption failed.
  30840. */
  30841. int mbedtls_gcm_crypt_and_tag( mbedtls_gcm_context *ctx,
  30842. int mode,
  30843. size_t length,
  30844. const unsigned char *iv,
  30845. size_t iv_len,
  30846. const unsigned char *add,
  30847. size_t add_len,
  30848. const unsigned char *input,
  30849. unsigned char *output,
  30850. size_t tag_len,
  30851. unsigned char *tag );
  30852. /**
  30853. * \brief This function performs a GCM authenticated decryption of a
  30854. * buffer.
  30855. *
  30856. * \note For decryption, the output buffer cannot be the same as
  30857. * input buffer. If the buffers overlap, the output buffer
  30858. * must trail at least 8 Bytes behind the input buffer.
  30859. *
  30860. * \param ctx The GCM context. This must be initialized.
  30861. * \param length The length of the ciphertext to decrypt, which is also
  30862. * the length of the decrypted plaintext.
  30863. * \param iv The initialization vector. This must be a readable buffer
  30864. * of at least \p iv_len Bytes.
  30865. * \param iv_len The length of the IV.
  30866. * \param add The buffer holding the additional data. This must be of at
  30867. * least that size in Bytes.
  30868. * \param add_len The length of the additional data.
  30869. * \param tag The buffer holding the tag to verify. This must be a
  30870. * readable buffer of at least \p tag_len Bytes.
  30871. * \param tag_len The length of the tag to verify.
  30872. * \param input The buffer holding the ciphertext. If \p length is greater
  30873. * than zero, this must be a readable buffer of at least that
  30874. * size.
  30875. * \param output The buffer for holding the decrypted plaintext. If \p length
  30876. * is greater than zero, this must be a writable buffer of at
  30877. * least that size.
  30878. *
  30879. * \return \c 0 if successful and authenticated.
  30880. * \return #MBEDTLS_ERR_GCM_AUTH_FAILED if the tag does not match.
  30881. * \return #MBEDTLS_ERR_GCM_BAD_INPUT if the lengths or pointers are
  30882. * not valid or a cipher-specific error code if the decryption
  30883. * failed.
  30884. */
  30885. int mbedtls_gcm_auth_decrypt( mbedtls_gcm_context *ctx,
  30886. size_t length,
  30887. const unsigned char *iv,
  30888. size_t iv_len,
  30889. const unsigned char *add,
  30890. size_t add_len,
  30891. const unsigned char *tag,
  30892. size_t tag_len,
  30893. const unsigned char *input,
  30894. unsigned char *output );
  30895. /**
  30896. * \brief This function starts a GCM encryption or decryption
  30897. * operation.
  30898. *
  30899. * \param ctx The GCM context. This must be initialized.
  30900. * \param mode The operation to perform: #MBEDTLS_GCM_ENCRYPT or
  30901. * #MBEDTLS_GCM_DECRYPT.
  30902. * \param iv The initialization vector. This must be a readable buffer of
  30903. * at least \p iv_len Bytes.
  30904. * \param iv_len The length of the IV.
  30905. * \param add The buffer holding the additional data, or \c NULL
  30906. * if \p add_len is \c 0.
  30907. * \param add_len The length of the additional data. If \c 0,
  30908. * \p add may be \c NULL.
  30909. *
  30910. * \return \c 0 on success.
  30911. */
  30912. int mbedtls_gcm_starts( mbedtls_gcm_context *ctx,
  30913. int mode,
  30914. const unsigned char *iv,
  30915. size_t iv_len,
  30916. const unsigned char *add,
  30917. size_t add_len );
  30918. /**
  30919. * \brief This function feeds an input buffer into an ongoing GCM
  30920. * encryption or decryption operation.
  30921. *
  30922. * ` The function expects input to be a multiple of 16
  30923. * Bytes. Only the last call before calling
  30924. * mbedtls_gcm_finish() can be less than 16 Bytes.
  30925. *
  30926. * \note For decryption, the output buffer cannot be the same as
  30927. * input buffer. If the buffers overlap, the output buffer
  30928. * must trail at least 8 Bytes behind the input buffer.
  30929. *
  30930. * \param ctx The GCM context. This must be initialized.
  30931. * \param length The length of the input data. This must be a multiple of
  30932. * 16 except in the last call before mbedtls_gcm_finish().
  30933. * \param input The buffer holding the input data. If \p length is greater
  30934. * than zero, this must be a readable buffer of at least that
  30935. * size in Bytes.
  30936. * \param output The buffer for holding the output data. If \p length is
  30937. * greater than zero, this must be a writable buffer of at
  30938. * least that size in Bytes.
  30939. *
  30940. * \return \c 0 on success.
  30941. * \return #MBEDTLS_ERR_GCM_BAD_INPUT on failure.
  30942. */
  30943. int mbedtls_gcm_update( mbedtls_gcm_context *ctx,
  30944. size_t length,
  30945. const unsigned char *input,
  30946. unsigned char *output );
  30947. /**
  30948. * \brief This function finishes the GCM operation and generates
  30949. * the authentication tag.
  30950. *
  30951. * It wraps up the GCM stream, and generates the
  30952. * tag. The tag can have a maximum length of 16 Bytes.
  30953. *
  30954. * \param ctx The GCM context. This must be initialized.
  30955. * \param tag The buffer for holding the tag. This must be a writable
  30956. * buffer of at least \p tag_len Bytes.
  30957. * \param tag_len The length of the tag to generate. This must be at least
  30958. * four.
  30959. *
  30960. * \return \c 0 on success.
  30961. * \return #MBEDTLS_ERR_GCM_BAD_INPUT on failure.
  30962. */
  30963. int mbedtls_gcm_finish( mbedtls_gcm_context *ctx,
  30964. unsigned char *tag,
  30965. size_t tag_len );
  30966. /**
  30967. * \brief This function clears a GCM context and the underlying
  30968. * cipher sub-context.
  30969. *
  30970. * \param ctx The GCM context to clear. If this is \c NULL, the call has
  30971. * no effect. Otherwise, this must be initialized.
  30972. */
  30973. void mbedtls_gcm_free( mbedtls_gcm_context *ctx );
  30974. #if defined(MBEDTLS_SELF_TEST)
  30975. /**
  30976. * \brief The GCM checkup routine.
  30977. *
  30978. * \return \c 0 on success.
  30979. * \return \c 1 on failure.
  30980. */
  30981. int mbedtls_gcm_self_test( int verbose );
  30982. #endif /* MBEDTLS_SELF_TEST */
  30983. #ifdef __cplusplus
  30984. }
  30985. #endif
  30986. #endif /* gcm.h */
  30987. /********* Start of file include/mbedtls/pem.h ************/
  30988. /**
  30989. * \file pem.h
  30990. *
  30991. * \brief Privacy Enhanced Mail (PEM) decoding
  30992. */
  30993. /*
  30994. * Copyright The Mbed TLS Contributors
  30995. * SPDX-License-Identifier: Apache-2.0
  30996. *
  30997. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  30998. * not use this file except in compliance with the License.
  30999. * You may obtain a copy of the License at
  31000. *
  31001. * http://www.apache.org/licenses/LICENSE-2.0
  31002. *
  31003. * Unless required by applicable law or agreed to in writing, software
  31004. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  31005. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  31006. * See the License for the specific language governing permissions and
  31007. * limitations under the License.
  31008. */
  31009. #ifndef MBEDTLS_PEM_H
  31010. #define MBEDTLS_PEM_H
  31011. #if !defined(MBEDTLS_CONFIG_FILE)
  31012. #else
  31013. #endif
  31014. #include <stddef.h>
  31015. /**
  31016. * \name PEM Error codes
  31017. * These error codes are returned in case of errors reading the
  31018. * PEM data.
  31019. * \{
  31020. */
  31021. /** No PEM header or footer found. */
  31022. #define MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT -0x1080
  31023. /** PEM string is not as expected. */
  31024. #define MBEDTLS_ERR_PEM_INVALID_DATA -0x1100
  31025. /** Failed to allocate memory. */
  31026. #define MBEDTLS_ERR_PEM_ALLOC_FAILED -0x1180
  31027. /** RSA IV is not in hex-format. */
  31028. #define MBEDTLS_ERR_PEM_INVALID_ENC_IV -0x1200
  31029. /** Unsupported key encryption algorithm. */
  31030. #define MBEDTLS_ERR_PEM_UNKNOWN_ENC_ALG -0x1280
  31031. /** Private key password can't be empty. */
  31032. #define MBEDTLS_ERR_PEM_PASSWORD_REQUIRED -0x1300
  31033. /** Given private key password does not allow for correct decryption. */
  31034. #define MBEDTLS_ERR_PEM_PASSWORD_MISMATCH -0x1380
  31035. /** Unavailable feature, e.g. hashing/encryption combination. */
  31036. #define MBEDTLS_ERR_PEM_FEATURE_UNAVAILABLE -0x1400
  31037. /** Bad input parameters to function. */
  31038. #define MBEDTLS_ERR_PEM_BAD_INPUT_DATA -0x1480
  31039. /* \} name */
  31040. #ifdef __cplusplus
  31041. extern "C" {
  31042. #endif
  31043. #if defined(MBEDTLS_PEM_PARSE_C)
  31044. /**
  31045. * \brief PEM context structure
  31046. */
  31047. typedef struct mbedtls_pem_context
  31048. {
  31049. unsigned char *buf; /*!< buffer for decoded data */
  31050. size_t buflen; /*!< length of the buffer */
  31051. unsigned char *info; /*!< buffer for extra header information */
  31052. }
  31053. mbedtls_pem_context;
  31054. /**
  31055. * \brief PEM context setup
  31056. *
  31057. * \param ctx context to be initialized
  31058. */
  31059. void mbedtls_pem_init( mbedtls_pem_context *ctx );
  31060. /**
  31061. * \brief Read a buffer for PEM information and store the resulting
  31062. * data into the specified context buffers.
  31063. *
  31064. * \param ctx context to use
  31065. * \param header header string to seek and expect
  31066. * \param footer footer string to seek and expect
  31067. * \param data source data to look in (must be nul-terminated)
  31068. * \param pwd password for decryption (can be NULL)
  31069. * \param pwdlen length of password
  31070. * \param use_len destination for total length used (set after header is
  31071. * correctly read, so unless you get
  31072. * MBEDTLS_ERR_PEM_BAD_INPUT_DATA or
  31073. * MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT, use_len is
  31074. * the length to skip)
  31075. *
  31076. * \note Attempts to check password correctness by verifying if
  31077. * the decrypted text starts with an ASN.1 sequence of
  31078. * appropriate length
  31079. *
  31080. * \return 0 on success, or a specific PEM error code
  31081. */
  31082. int mbedtls_pem_read_buffer( mbedtls_pem_context *ctx, const char *header, const char *footer,
  31083. const unsigned char *data,
  31084. const unsigned char *pwd,
  31085. size_t pwdlen, size_t *use_len );
  31086. /**
  31087. * \brief PEM context memory freeing
  31088. *
  31089. * \param ctx context to be freed
  31090. */
  31091. void mbedtls_pem_free( mbedtls_pem_context *ctx );
  31092. #endif /* MBEDTLS_PEM_PARSE_C */
  31093. #if defined(MBEDTLS_PEM_WRITE_C)
  31094. /**
  31095. * \brief Write a buffer of PEM information from a DER encoded
  31096. * buffer.
  31097. *
  31098. * \param header The header string to write.
  31099. * \param footer The footer string to write.
  31100. * \param der_data The DER data to encode.
  31101. * \param der_len The length of the DER data \p der_data in Bytes.
  31102. * \param buf The buffer to write to.
  31103. * \param buf_len The length of the output buffer \p buf in Bytes.
  31104. * \param olen The address at which to store the total length written
  31105. * or required (if \p buf_len is not enough).
  31106. *
  31107. * \note You may pass \c NULL for \p buf and \c 0 for \p buf_len
  31108. * to request the length of the resulting PEM buffer in
  31109. * `*olen`.
  31110. *
  31111. * \note This function may be called with overlapping \p der_data
  31112. * and \p buf buffers.
  31113. *
  31114. * \return \c 0 on success.
  31115. * \return #MBEDTLS_ERR_BASE64_BUFFER_TOO_SMALL if \p buf isn't large
  31116. * enough to hold the PEM buffer. In this case, `*olen` holds
  31117. * the required minimum size of \p buf.
  31118. * \return Another PEM or BASE64 error code on other kinds of failure.
  31119. */
  31120. int mbedtls_pem_write_buffer( const char *header, const char *footer,
  31121. const unsigned char *der_data, size_t der_len,
  31122. unsigned char *buf, size_t buf_len, size_t *olen );
  31123. #endif /* MBEDTLS_PEM_WRITE_C */
  31124. #ifdef __cplusplus
  31125. }
  31126. #endif
  31127. #endif /* pem.h */
  31128. /********* Start of file include/mbedtls/asn1write.h ************/
  31129. /**
  31130. * \file asn1write.h
  31131. *
  31132. * \brief ASN.1 buffer writing functionality
  31133. */
  31134. /*
  31135. * Copyright The Mbed TLS Contributors
  31136. * SPDX-License-Identifier: Apache-2.0
  31137. *
  31138. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  31139. * not use this file except in compliance with the License.
  31140. * You may obtain a copy of the License at
  31141. *
  31142. * http://www.apache.org/licenses/LICENSE-2.0
  31143. *
  31144. * Unless required by applicable law or agreed to in writing, software
  31145. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  31146. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  31147. * See the License for the specific language governing permissions and
  31148. * limitations under the License.
  31149. */
  31150. #ifndef MBEDTLS_ASN1_WRITE_H
  31151. #define MBEDTLS_ASN1_WRITE_H
  31152. #if !defined(MBEDTLS_CONFIG_FILE)
  31153. #else
  31154. #endif
  31155. #define MBEDTLS_ASN1_CHK_ADD(g, f) \
  31156. do \
  31157. { \
  31158. if( ( ret = (f) ) < 0 ) \
  31159. return( ret ); \
  31160. else \
  31161. (g) += ret; \
  31162. } while( 0 )
  31163. #ifdef __cplusplus
  31164. extern "C" {
  31165. #endif
  31166. /**
  31167. * \brief Write a length field in ASN.1 format.
  31168. *
  31169. * \note This function works backwards in data buffer.
  31170. *
  31171. * \param p The reference to the current position pointer.
  31172. * \param start The start of the buffer, for bounds-checking.
  31173. * \param len The length value to write.
  31174. *
  31175. * \return The number of bytes written to \p p on success.
  31176. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31177. */
  31178. int mbedtls_asn1_write_len( unsigned char **p, unsigned char *start,
  31179. size_t len );
  31180. /**
  31181. * \brief Write an ASN.1 tag in ASN.1 format.
  31182. *
  31183. * \note This function works backwards in data buffer.
  31184. *
  31185. * \param p The reference to the current position pointer.
  31186. * \param start The start of the buffer, for bounds-checking.
  31187. * \param tag The tag to write.
  31188. *
  31189. * \return The number of bytes written to \p p on success.
  31190. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31191. */
  31192. int mbedtls_asn1_write_tag( unsigned char **p, unsigned char *start,
  31193. unsigned char tag );
  31194. /**
  31195. * \brief Write raw buffer data.
  31196. *
  31197. * \note This function works backwards in data buffer.
  31198. *
  31199. * \param p The reference to the current position pointer.
  31200. * \param start The start of the buffer, for bounds-checking.
  31201. * \param buf The data buffer to write.
  31202. * \param size The length of the data buffer.
  31203. *
  31204. * \return The number of bytes written to \p p on success.
  31205. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31206. */
  31207. int mbedtls_asn1_write_raw_buffer( unsigned char **p, unsigned char *start,
  31208. const unsigned char *buf, size_t size );
  31209. #if defined(MBEDTLS_BIGNUM_C)
  31210. /**
  31211. * \brief Write a arbitrary-precision number (#MBEDTLS_ASN1_INTEGER)
  31212. * in ASN.1 format.
  31213. *
  31214. * \note This function works backwards in data buffer.
  31215. *
  31216. * \param p The reference to the current position pointer.
  31217. * \param start The start of the buffer, for bounds-checking.
  31218. * \param X The MPI to write.
  31219. * It must be non-negative.
  31220. *
  31221. * \return The number of bytes written to \p p on success.
  31222. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31223. */
  31224. int mbedtls_asn1_write_mpi( unsigned char **p, unsigned char *start,
  31225. const mbedtls_mpi *X );
  31226. #endif /* MBEDTLS_BIGNUM_C */
  31227. /**
  31228. * \brief Write a NULL tag (#MBEDTLS_ASN1_NULL) with zero data
  31229. * in ASN.1 format.
  31230. *
  31231. * \note This function works backwards in data buffer.
  31232. *
  31233. * \param p The reference to the current position pointer.
  31234. * \param start The start of the buffer, for bounds-checking.
  31235. *
  31236. * \return The number of bytes written to \p p on success.
  31237. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31238. */
  31239. int mbedtls_asn1_write_null( unsigned char **p, unsigned char *start );
  31240. /**
  31241. * \brief Write an OID tag (#MBEDTLS_ASN1_OID) and data
  31242. * in ASN.1 format.
  31243. *
  31244. * \note This function works backwards in data buffer.
  31245. *
  31246. * \param p The reference to the current position pointer.
  31247. * \param start The start of the buffer, for bounds-checking.
  31248. * \param oid The OID to write.
  31249. * \param oid_len The length of the OID.
  31250. *
  31251. * \return The number of bytes written to \p p on success.
  31252. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31253. */
  31254. int mbedtls_asn1_write_oid( unsigned char **p, unsigned char *start,
  31255. const char *oid, size_t oid_len );
  31256. /**
  31257. * \brief Write an AlgorithmIdentifier sequence in ASN.1 format.
  31258. *
  31259. * \note This function works backwards in data buffer.
  31260. *
  31261. * \param p The reference to the current position pointer.
  31262. * \param start The start of the buffer, for bounds-checking.
  31263. * \param oid The OID of the algorithm to write.
  31264. * \param oid_len The length of the algorithm's OID.
  31265. * \param par_len The length of the parameters, which must be already written.
  31266. * If 0, NULL parameters are added
  31267. *
  31268. * \return The number of bytes written to \p p on success.
  31269. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31270. */
  31271. int mbedtls_asn1_write_algorithm_identifier( unsigned char **p,
  31272. unsigned char *start,
  31273. const char *oid, size_t oid_len,
  31274. size_t par_len );
  31275. /**
  31276. * \brief Write a boolean tag (#MBEDTLS_ASN1_BOOLEAN) and value
  31277. * in ASN.1 format.
  31278. *
  31279. * \note This function works backwards in data buffer.
  31280. *
  31281. * \param p The reference to the current position pointer.
  31282. * \param start The start of the buffer, for bounds-checking.
  31283. * \param boolean The boolean value to write, either \c 0 or \c 1.
  31284. *
  31285. * \return The number of bytes written to \p p on success.
  31286. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31287. */
  31288. int mbedtls_asn1_write_bool( unsigned char **p, unsigned char *start,
  31289. int boolean );
  31290. /**
  31291. * \brief Write an int tag (#MBEDTLS_ASN1_INTEGER) and value
  31292. * in ASN.1 format.
  31293. *
  31294. * \note This function works backwards in data buffer.
  31295. *
  31296. * \param p The reference to the current position pointer.
  31297. * \param start The start of the buffer, for bounds-checking.
  31298. * \param val The integer value to write.
  31299. * It must be non-negative.
  31300. *
  31301. * \return The number of bytes written to \p p on success.
  31302. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31303. */
  31304. int mbedtls_asn1_write_int( unsigned char **p, unsigned char *start, int val );
  31305. /**
  31306. * \brief Write an enum tag (#MBEDTLS_ASN1_ENUMERATED) and value
  31307. * in ASN.1 format.
  31308. *
  31309. * \note This function works backwards in data buffer.
  31310. *
  31311. * \param p The reference to the current position pointer.
  31312. * \param start The start of the buffer, for bounds-checking.
  31313. * \param val The integer value to write.
  31314. *
  31315. * \return The number of bytes written to \p p on success.
  31316. * \return A negative \c MBEDTLS_ERR_ASN1_XXX error code on failure.
  31317. */
  31318. int mbedtls_asn1_write_enum( unsigned char **p, unsigned char *start, int val );
  31319. /**
  31320. * \brief Write a string in ASN.1 format using a specific
  31321. * string encoding tag.
  31322. * \note This function works backwards in data buffer.
  31323. *
  31324. * \param p The reference to the current position pointer.
  31325. * \param start The start of the buffer, for bounds-checking.
  31326. * \param tag The string encoding tag to write, e.g.
  31327. * #MBEDTLS_ASN1_UTF8_STRING.
  31328. * \param text The string to write.
  31329. * \param text_len The length of \p text in bytes (which might
  31330. * be strictly larger than the number of characters).
  31331. *
  31332. * \return The number of bytes written to \p p on success.
  31333. * \return A negative error code on failure.
  31334. */
  31335. int mbedtls_asn1_write_tagged_string( unsigned char **p, unsigned char *start,
  31336. int tag, const char *text,
  31337. size_t text_len );
  31338. /**
  31339. * \brief Write a string in ASN.1 format using the PrintableString
  31340. * string encoding tag (#MBEDTLS_ASN1_PRINTABLE_STRING).
  31341. *
  31342. * \note This function works backwards in data buffer.
  31343. *
  31344. * \param p The reference to the current position pointer.
  31345. * \param start The start of the buffer, for bounds-checking.
  31346. * \param text The string to write.
  31347. * \param text_len The length of \p text in bytes (which might
  31348. * be strictly larger than the number of characters).
  31349. *
  31350. * \return The number of bytes written to \p p on success.
  31351. * \return A negative error code on failure.
  31352. */
  31353. int mbedtls_asn1_write_printable_string( unsigned char **p,
  31354. unsigned char *start,
  31355. const char *text, size_t text_len );
  31356. /**
  31357. * \brief Write a UTF8 string in ASN.1 format using the UTF8String
  31358. * string encoding tag (#MBEDTLS_ASN1_UTF8_STRING).
  31359. *
  31360. * \note This function works backwards in data buffer.
  31361. *
  31362. * \param p The reference to the current position pointer.
  31363. * \param start The start of the buffer, for bounds-checking.
  31364. * \param text The string to write.
  31365. * \param text_len The length of \p text in bytes (which might
  31366. * be strictly larger than the number of characters).
  31367. *
  31368. * \return The number of bytes written to \p p on success.
  31369. * \return A negative error code on failure.
  31370. */
  31371. int mbedtls_asn1_write_utf8_string( unsigned char **p, unsigned char *start,
  31372. const char *text, size_t text_len );
  31373. /**
  31374. * \brief Write a string in ASN.1 format using the IA5String
  31375. * string encoding tag (#MBEDTLS_ASN1_IA5_STRING).
  31376. *
  31377. * \note This function works backwards in data buffer.
  31378. *
  31379. * \param p The reference to the current position pointer.
  31380. * \param start The start of the buffer, for bounds-checking.
  31381. * \param text The string to write.
  31382. * \param text_len The length of \p text in bytes (which might
  31383. * be strictly larger than the number of characters).
  31384. *
  31385. * \return The number of bytes written to \p p on success.
  31386. * \return A negative error code on failure.
  31387. */
  31388. int mbedtls_asn1_write_ia5_string( unsigned char **p, unsigned char *start,
  31389. const char *text, size_t text_len );
  31390. /**
  31391. * \brief Write a bitstring tag (#MBEDTLS_ASN1_BIT_STRING) and
  31392. * value in ASN.1 format.
  31393. *
  31394. * \note This function works backwards in data buffer.
  31395. *
  31396. * \param p The reference to the current position pointer.
  31397. * \param start The start of the buffer, for bounds-checking.
  31398. * \param buf The bitstring to write.
  31399. * \param bits The total number of bits in the bitstring.
  31400. *
  31401. * \return The number of bytes written to \p p on success.
  31402. * \return A negative error code on failure.
  31403. */
  31404. int mbedtls_asn1_write_bitstring( unsigned char **p, unsigned char *start,
  31405. const unsigned char *buf, size_t bits );
  31406. /**
  31407. * \brief This function writes a named bitstring tag
  31408. * (#MBEDTLS_ASN1_BIT_STRING) and value in ASN.1 format.
  31409. *
  31410. * As stated in RFC 5280 Appendix B, trailing zeroes are
  31411. * omitted when encoding named bitstrings in DER.
  31412. *
  31413. * \note This function works backwards within the data buffer.
  31414. *
  31415. * \param p The reference to the current position pointer.
  31416. * \param start The start of the buffer which is used for bounds-checking.
  31417. * \param buf The bitstring to write.
  31418. * \param bits The total number of bits in the bitstring.
  31419. *
  31420. * \return The number of bytes written to \p p on success.
  31421. * \return A negative error code on failure.
  31422. */
  31423. int mbedtls_asn1_write_named_bitstring( unsigned char **p,
  31424. unsigned char *start,
  31425. const unsigned char *buf,
  31426. size_t bits );
  31427. /**
  31428. * \brief Write an octet string tag (#MBEDTLS_ASN1_OCTET_STRING)
  31429. * and value in ASN.1 format.
  31430. *
  31431. * \note This function works backwards in data buffer.
  31432. *
  31433. * \param p The reference to the current position pointer.
  31434. * \param start The start of the buffer, for bounds-checking.
  31435. * \param buf The buffer holding the data to write.
  31436. * \param size The length of the data buffer \p buf.
  31437. *
  31438. * \return The number of bytes written to \p p on success.
  31439. * \return A negative error code on failure.
  31440. */
  31441. int mbedtls_asn1_write_octet_string( unsigned char **p, unsigned char *start,
  31442. const unsigned char *buf, size_t size );
  31443. /**
  31444. * \brief Create or find a specific named_data entry for writing in a
  31445. * sequence or list based on the OID. If not already in there,
  31446. * a new entry is added to the head of the list.
  31447. * Warning: Destructive behaviour for the val data!
  31448. *
  31449. * \param list The pointer to the location of the head of the list to seek
  31450. * through (will be updated in case of a new entry).
  31451. * \param oid The OID to look for.
  31452. * \param oid_len The size of the OID.
  31453. * \param val The associated data to store. If this is \c NULL,
  31454. * no data is copied to the new or existing buffer.
  31455. * \param val_len The minimum length of the data buffer needed.
  31456. * If this is 0, do not allocate a buffer for the associated
  31457. * data.
  31458. * If the OID was already present, enlarge, shrink or free
  31459. * the existing buffer to fit \p val_len.
  31460. *
  31461. * \return A pointer to the new / existing entry on success.
  31462. * \return \c NULL if if there was a memory allocation error.
  31463. */
  31464. mbedtls_asn1_named_data *mbedtls_asn1_store_named_data( mbedtls_asn1_named_data **list,
  31465. const char *oid, size_t oid_len,
  31466. const unsigned char *val,
  31467. size_t val_len );
  31468. #ifdef __cplusplus
  31469. }
  31470. #endif
  31471. #endif /* MBEDTLS_ASN1_WRITE_H */
  31472. /********* Start of file include/mbedtls/hmac_drbg.h ************/
  31473. /**
  31474. * \file hmac_drbg.h
  31475. *
  31476. * \brief The HMAC_DRBG pseudorandom generator.
  31477. *
  31478. * This module implements the HMAC_DRBG pseudorandom generator described
  31479. * in <em>NIST SP 800-90A: Recommendation for Random Number Generation Using
  31480. * Deterministic Random Bit Generators</em>.
  31481. */
  31482. /*
  31483. * Copyright The Mbed TLS Contributors
  31484. * SPDX-License-Identifier: Apache-2.0
  31485. *
  31486. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  31487. * not use this file except in compliance with the License.
  31488. * You may obtain a copy of the License at
  31489. *
  31490. * http://www.apache.org/licenses/LICENSE-2.0
  31491. *
  31492. * Unless required by applicable law or agreed to in writing, software
  31493. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  31494. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  31495. * See the License for the specific language governing permissions and
  31496. * limitations under the License.
  31497. */
  31498. #ifndef MBEDTLS_HMAC_DRBG_H
  31499. #define MBEDTLS_HMAC_DRBG_H
  31500. #if !defined(MBEDTLS_CONFIG_FILE)
  31501. #else
  31502. #endif
  31503. #if defined(MBEDTLS_THREADING_C)
  31504. #endif
  31505. /*
  31506. * Error codes
  31507. */
  31508. /** Too many random requested in single call. */
  31509. #define MBEDTLS_ERR_HMAC_DRBG_REQUEST_TOO_BIG -0x0003
  31510. /** Input too large (Entropy + additional). */
  31511. #define MBEDTLS_ERR_HMAC_DRBG_INPUT_TOO_BIG -0x0005
  31512. /** Read/write error in file. */
  31513. #define MBEDTLS_ERR_HMAC_DRBG_FILE_IO_ERROR -0x0007
  31514. /** The entropy source failed. */
  31515. #define MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED -0x0009
  31516. /**
  31517. * \name SECTION: Module settings
  31518. *
  31519. * The configuration options you can set for this module are in this section.
  31520. * Either change them in config.h or define them on the compiler command line.
  31521. * \{
  31522. */
  31523. #if !defined(MBEDTLS_HMAC_DRBG_RESEED_INTERVAL)
  31524. #define MBEDTLS_HMAC_DRBG_RESEED_INTERVAL 10000 /**< Interval before reseed is performed by default */
  31525. #endif
  31526. #if !defined(MBEDTLS_HMAC_DRBG_MAX_INPUT)
  31527. #define MBEDTLS_HMAC_DRBG_MAX_INPUT 256 /**< Maximum number of additional input bytes */
  31528. #endif
  31529. #if !defined(MBEDTLS_HMAC_DRBG_MAX_REQUEST)
  31530. #define MBEDTLS_HMAC_DRBG_MAX_REQUEST 1024 /**< Maximum number of requested bytes per call */
  31531. #endif
  31532. #if !defined(MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT)
  31533. #define MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT 384 /**< Maximum size of (re)seed buffer */
  31534. #endif
  31535. /* \} name SECTION: Module settings */
  31536. #define MBEDTLS_HMAC_DRBG_PR_OFF 0 /**< No prediction resistance */
  31537. #define MBEDTLS_HMAC_DRBG_PR_ON 1 /**< Prediction resistance enabled */
  31538. #ifdef __cplusplus
  31539. extern "C" {
  31540. #endif
  31541. /**
  31542. * HMAC_DRBG context.
  31543. */
  31544. typedef struct mbedtls_hmac_drbg_context
  31545. {
  31546. /* Working state: the key K is not stored explicitly,
  31547. * but is implied by the HMAC context */
  31548. mbedtls_md_context_t md_ctx; /*!< HMAC context (inc. K) */
  31549. unsigned char V[MBEDTLS_MD_MAX_SIZE]; /*!< V in the spec */
  31550. int reseed_counter; /*!< reseed counter */
  31551. /* Administrative state */
  31552. size_t entropy_len; /*!< entropy bytes grabbed on each (re)seed */
  31553. int prediction_resistance; /*!< enable prediction resistance (Automatic
  31554. reseed before every random generation) */
  31555. int reseed_interval; /*!< reseed interval */
  31556. /* Callbacks */
  31557. int (*f_entropy)(void *, unsigned char *, size_t); /*!< entropy function */
  31558. void *p_entropy; /*!< context for the entropy function */
  31559. #if defined(MBEDTLS_THREADING_C)
  31560. /* Invariant: the mutex is initialized if and only if
  31561. * md_ctx->md_info != NULL. This means that the mutex is initialized
  31562. * during the initial seeding in mbedtls_hmac_drbg_seed() or
  31563. * mbedtls_hmac_drbg_seed_buf() and freed in mbedtls_ctr_drbg_free().
  31564. *
  31565. * Note that this invariant may change without notice. Do not rely on it
  31566. * and do not access the mutex directly in application code.
  31567. */
  31568. mbedtls_threading_mutex_t mutex;
  31569. #endif
  31570. } mbedtls_hmac_drbg_context;
  31571. /**
  31572. * \brief HMAC_DRBG context initialization.
  31573. *
  31574. * This function makes the context ready for mbedtls_hmac_drbg_seed(),
  31575. * mbedtls_hmac_drbg_seed_buf() or mbedtls_hmac_drbg_free().
  31576. *
  31577. * \note The reseed interval is #MBEDTLS_HMAC_DRBG_RESEED_INTERVAL
  31578. * by default. Override this value by calling
  31579. * mbedtls_hmac_drbg_set_reseed_interval().
  31580. *
  31581. * \param ctx HMAC_DRBG context to be initialized.
  31582. */
  31583. void mbedtls_hmac_drbg_init( mbedtls_hmac_drbg_context *ctx );
  31584. /**
  31585. * \brief HMAC_DRBG initial seeding.
  31586. *
  31587. * Set the initial seed and set up the entropy source for future reseeds.
  31588. *
  31589. * A typical choice for the \p f_entropy and \p p_entropy parameters is
  31590. * to use the entropy module:
  31591. * - \p f_entropy is mbedtls_entropy_func();
  31592. * - \p p_entropy is an instance of ::mbedtls_entropy_context initialized
  31593. * with mbedtls_entropy_init() (which registers the platform's default
  31594. * entropy sources).
  31595. *
  31596. * You can provide a personalization string in addition to the
  31597. * entropy source, to make this instantiation as unique as possible.
  31598. *
  31599. * \note By default, the security strength as defined by NIST is:
  31600. * - 128 bits if \p md_info is SHA-1;
  31601. * - 192 bits if \p md_info is SHA-224;
  31602. * - 256 bits if \p md_info is SHA-256, SHA-384 or SHA-512.
  31603. * Note that SHA-256 is just as efficient as SHA-224.
  31604. * The security strength can be reduced if a smaller
  31605. * entropy length is set with
  31606. * mbedtls_hmac_drbg_set_entropy_len().
  31607. *
  31608. * \note The default entropy length is the security strength
  31609. * (converted from bits to bytes). You can override
  31610. * it by calling mbedtls_hmac_drbg_set_entropy_len().
  31611. *
  31612. * \note During the initial seeding, this function calls
  31613. * the entropy source to obtain a nonce
  31614. * whose length is half the entropy length.
  31615. */
  31616. #if defined(MBEDTLS_THREADING_C)
  31617. /**
  31618. * \note When Mbed TLS is built with threading support,
  31619. * after this function returns successfully,
  31620. * it is safe to call mbedtls_hmac_drbg_random()
  31621. * from multiple threads. Other operations, including
  31622. * reseeding, are not thread-safe.
  31623. */
  31624. #endif /* MBEDTLS_THREADING_C */
  31625. /**
  31626. * \param ctx HMAC_DRBG context to be seeded.
  31627. * \param md_info MD algorithm to use for HMAC_DRBG.
  31628. * \param f_entropy The entropy callback, taking as arguments the
  31629. * \p p_entropy context, the buffer to fill, and the
  31630. * length of the buffer.
  31631. * \p f_entropy is always called with a length that is
  31632. * less than or equal to the entropy length.
  31633. * \param p_entropy The entropy context to pass to \p f_entropy.
  31634. * \param custom The personalization string.
  31635. * This can be \c NULL, in which case the personalization
  31636. * string is empty regardless of the value of \p len.
  31637. * \param len The length of the personalization string.
  31638. * This must be at most #MBEDTLS_HMAC_DRBG_MAX_INPUT
  31639. * and also at most
  31640. * #MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT - \p entropy_len * 3 / 2
  31641. * where \p entropy_len is the entropy length
  31642. * described above.
  31643. *
  31644. * \return \c 0 if successful.
  31645. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA if \p md_info is
  31646. * invalid.
  31647. * \return #MBEDTLS_ERR_MD_ALLOC_FAILED if there was not enough
  31648. * memory to allocate context data.
  31649. * \return #MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED
  31650. * if the call to \p f_entropy failed.
  31651. */
  31652. int mbedtls_hmac_drbg_seed( mbedtls_hmac_drbg_context *ctx,
  31653. const mbedtls_md_info_t * md_info,
  31654. int (*f_entropy)(void *, unsigned char *, size_t),
  31655. void *p_entropy,
  31656. const unsigned char *custom,
  31657. size_t len );
  31658. /**
  31659. * \brief Initilisation of simpified HMAC_DRBG (never reseeds).
  31660. *
  31661. * This function is meant for use in algorithms that need a pseudorandom
  31662. * input such as deterministic ECDSA.
  31663. */
  31664. #if defined(MBEDTLS_THREADING_C)
  31665. /**
  31666. * \note When Mbed TLS is built with threading support,
  31667. * after this function returns successfully,
  31668. * it is safe to call mbedtls_hmac_drbg_random()
  31669. * from multiple threads. Other operations, including
  31670. * reseeding, are not thread-safe.
  31671. */
  31672. #endif /* MBEDTLS_THREADING_C */
  31673. /**
  31674. * \param ctx HMAC_DRBG context to be initialised.
  31675. * \param md_info MD algorithm to use for HMAC_DRBG.
  31676. * \param data Concatenation of the initial entropy string and
  31677. * the additional data.
  31678. * \param data_len Length of \p data in bytes.
  31679. *
  31680. * \return \c 0 if successful. or
  31681. * \return #MBEDTLS_ERR_MD_BAD_INPUT_DATA if \p md_info is
  31682. * invalid.
  31683. * \return #MBEDTLS_ERR_MD_ALLOC_FAILED if there was not enough
  31684. * memory to allocate context data.
  31685. */
  31686. int mbedtls_hmac_drbg_seed_buf( mbedtls_hmac_drbg_context *ctx,
  31687. const mbedtls_md_info_t * md_info,
  31688. const unsigned char *data, size_t data_len );
  31689. /**
  31690. * \brief This function turns prediction resistance on or off.
  31691. * The default value is off.
  31692. *
  31693. * \note If enabled, entropy is gathered at the beginning of
  31694. * every call to mbedtls_hmac_drbg_random_with_add()
  31695. * or mbedtls_hmac_drbg_random().
  31696. * Only use this if your entropy source has sufficient
  31697. * throughput.
  31698. *
  31699. * \param ctx The HMAC_DRBG context.
  31700. * \param resistance #MBEDTLS_HMAC_DRBG_PR_ON or #MBEDTLS_HMAC_DRBG_PR_OFF.
  31701. */
  31702. void mbedtls_hmac_drbg_set_prediction_resistance( mbedtls_hmac_drbg_context *ctx,
  31703. int resistance );
  31704. /**
  31705. * \brief This function sets the amount of entropy grabbed on each
  31706. * seed or reseed.
  31707. *
  31708. * See the documentation of mbedtls_hmac_drbg_seed() for the default value.
  31709. *
  31710. * \param ctx The HMAC_DRBG context.
  31711. * \param len The amount of entropy to grab, in bytes.
  31712. */
  31713. void mbedtls_hmac_drbg_set_entropy_len( mbedtls_hmac_drbg_context *ctx,
  31714. size_t len );
  31715. /**
  31716. * \brief Set the reseed interval.
  31717. *
  31718. * The reseed interval is the number of calls to mbedtls_hmac_drbg_random()
  31719. * or mbedtls_hmac_drbg_random_with_add() after which the entropy function
  31720. * is called again.
  31721. *
  31722. * The default value is #MBEDTLS_HMAC_DRBG_RESEED_INTERVAL.
  31723. *
  31724. * \param ctx The HMAC_DRBG context.
  31725. * \param interval The reseed interval.
  31726. */
  31727. void mbedtls_hmac_drbg_set_reseed_interval( mbedtls_hmac_drbg_context *ctx,
  31728. int interval );
  31729. /**
  31730. * \brief This function updates the state of the HMAC_DRBG context.
  31731. *
  31732. * \note This function is not thread-safe. It is not safe
  31733. * to call this function if another thread might be
  31734. * concurrently obtaining random numbers from the same
  31735. * context or updating or reseeding the same context.
  31736. *
  31737. * \param ctx The HMAC_DRBG context.
  31738. * \param additional The data to update the state with.
  31739. * If this is \c NULL, there is no additional data.
  31740. * \param add_len Length of \p additional in bytes.
  31741. * Unused if \p additional is \c NULL.
  31742. *
  31743. * \return \c 0 on success, or an error from the underlying
  31744. * hash calculation.
  31745. */
  31746. int mbedtls_hmac_drbg_update_ret( mbedtls_hmac_drbg_context *ctx,
  31747. const unsigned char *additional, size_t add_len );
  31748. /**
  31749. * \brief This function reseeds the HMAC_DRBG context, that is
  31750. * extracts data from the entropy source.
  31751. *
  31752. * \note This function is not thread-safe. It is not safe
  31753. * to call this function if another thread might be
  31754. * concurrently obtaining random numbers from the same
  31755. * context or updating or reseeding the same context.
  31756. *
  31757. * \param ctx The HMAC_DRBG context.
  31758. * \param additional Additional data to add to the state.
  31759. * If this is \c NULL, there is no additional data
  31760. * and \p len should be \c 0.
  31761. * \param len The length of the additional data.
  31762. * This must be at most #MBEDTLS_HMAC_DRBG_MAX_INPUT
  31763. * and also at most
  31764. * #MBEDTLS_HMAC_DRBG_MAX_SEED_INPUT - \p entropy_len
  31765. * where \p entropy_len is the entropy length
  31766. * (see mbedtls_hmac_drbg_set_entropy_len()).
  31767. *
  31768. * \return \c 0 if successful.
  31769. * \return #MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED
  31770. * if a call to the entropy function failed.
  31771. */
  31772. int mbedtls_hmac_drbg_reseed( mbedtls_hmac_drbg_context *ctx,
  31773. const unsigned char *additional, size_t len );
  31774. /**
  31775. * \brief This function updates an HMAC_DRBG instance with additional
  31776. * data and uses it to generate random data.
  31777. *
  31778. * This function automatically reseeds if the reseed counter is exceeded
  31779. * or prediction resistance is enabled.
  31780. *
  31781. * \note This function is not thread-safe. It is not safe
  31782. * to call this function if another thread might be
  31783. * concurrently obtaining random numbers from the same
  31784. * context or updating or reseeding the same context.
  31785. *
  31786. * \param p_rng The HMAC_DRBG context. This must be a pointer to a
  31787. * #mbedtls_hmac_drbg_context structure.
  31788. * \param output The buffer to fill.
  31789. * \param output_len The length of the buffer in bytes.
  31790. * This must be at most #MBEDTLS_HMAC_DRBG_MAX_REQUEST.
  31791. * \param additional Additional data to update with.
  31792. * If this is \c NULL, there is no additional data
  31793. * and \p add_len should be \c 0.
  31794. * \param add_len The length of the additional data.
  31795. * This must be at most #MBEDTLS_HMAC_DRBG_MAX_INPUT.
  31796. *
  31797. * \return \c 0 if successful.
  31798. * \return #MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED
  31799. * if a call to the entropy source failed.
  31800. * \return #MBEDTLS_ERR_HMAC_DRBG_REQUEST_TOO_BIG if
  31801. * \p output_len > #MBEDTLS_HMAC_DRBG_MAX_REQUEST.
  31802. * \return #MBEDTLS_ERR_HMAC_DRBG_INPUT_TOO_BIG if
  31803. * \p add_len > #MBEDTLS_HMAC_DRBG_MAX_INPUT.
  31804. */
  31805. int mbedtls_hmac_drbg_random_with_add( void *p_rng,
  31806. unsigned char *output, size_t output_len,
  31807. const unsigned char *additional,
  31808. size_t add_len );
  31809. /**
  31810. * \brief This function uses HMAC_DRBG to generate random data.
  31811. *
  31812. * This function automatically reseeds if the reseed counter is exceeded
  31813. * or prediction resistance is enabled.
  31814. */
  31815. #if defined(MBEDTLS_THREADING_C)
  31816. /**
  31817. * \note When Mbed TLS is built with threading support,
  31818. * it is safe to call mbedtls_ctr_drbg_random()
  31819. * from multiple threads. Other operations, including
  31820. * reseeding, are not thread-safe.
  31821. */
  31822. #endif /* MBEDTLS_THREADING_C */
  31823. /**
  31824. * \param p_rng The HMAC_DRBG context. This must be a pointer to a
  31825. * #mbedtls_hmac_drbg_context structure.
  31826. * \param output The buffer to fill.
  31827. * \param out_len The length of the buffer in bytes.
  31828. * This must be at most #MBEDTLS_HMAC_DRBG_MAX_REQUEST.
  31829. *
  31830. * \return \c 0 if successful.
  31831. * \return #MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED
  31832. * if a call to the entropy source failed.
  31833. * \return #MBEDTLS_ERR_HMAC_DRBG_REQUEST_TOO_BIG if
  31834. * \p out_len > #MBEDTLS_HMAC_DRBG_MAX_REQUEST.
  31835. */
  31836. int mbedtls_hmac_drbg_random( void *p_rng, unsigned char *output, size_t out_len );
  31837. /**
  31838. * \brief This function resets HMAC_DRBG context to the state immediately
  31839. * after initial call of mbedtls_hmac_drbg_init().
  31840. *
  31841. * \param ctx The HMAC_DRBG context to free.
  31842. */
  31843. void mbedtls_hmac_drbg_free( mbedtls_hmac_drbg_context *ctx );
  31844. #if ! defined(MBEDTLS_DEPRECATED_REMOVED)
  31845. #if defined(MBEDTLS_DEPRECATED_WARNING)
  31846. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  31847. #else
  31848. #define MBEDTLS_DEPRECATED
  31849. #endif
  31850. /**
  31851. * \brief This function updates the state of the HMAC_DRBG context.
  31852. *
  31853. * \deprecated Superseded by mbedtls_hmac_drbg_update_ret()
  31854. * in 2.16.0.
  31855. *
  31856. * \param ctx The HMAC_DRBG context.
  31857. * \param additional The data to update the state with.
  31858. * If this is \c NULL, there is no additional data.
  31859. * \param add_len Length of \p additional in bytes.
  31860. * Unused if \p additional is \c NULL.
  31861. */
  31862. MBEDTLS_DEPRECATED void mbedtls_hmac_drbg_update(
  31863. mbedtls_hmac_drbg_context *ctx,
  31864. const unsigned char *additional, size_t add_len );
  31865. #undef MBEDTLS_DEPRECATED
  31866. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  31867. #if defined(MBEDTLS_FS_IO)
  31868. /**
  31869. * \brief This function writes a seed file.
  31870. *
  31871. * \param ctx The HMAC_DRBG context.
  31872. * \param path The name of the file.
  31873. *
  31874. * \return \c 0 on success.
  31875. * \return #MBEDTLS_ERR_HMAC_DRBG_FILE_IO_ERROR on file error.
  31876. * \return #MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED on reseed
  31877. * failure.
  31878. */
  31879. int mbedtls_hmac_drbg_write_seed_file( mbedtls_hmac_drbg_context *ctx, const char *path );
  31880. /**
  31881. * \brief This function reads and updates a seed file. The seed
  31882. * is added to this instance.
  31883. *
  31884. * \param ctx The HMAC_DRBG context.
  31885. * \param path The name of the file.
  31886. *
  31887. * \return \c 0 on success.
  31888. * \return #MBEDTLS_ERR_HMAC_DRBG_FILE_IO_ERROR on file error.
  31889. * \return #MBEDTLS_ERR_HMAC_DRBG_ENTROPY_SOURCE_FAILED on
  31890. * reseed failure.
  31891. * \return #MBEDTLS_ERR_HMAC_DRBG_INPUT_TOO_BIG if the existing
  31892. * seed file is too large.
  31893. */
  31894. int mbedtls_hmac_drbg_update_seed_file( mbedtls_hmac_drbg_context *ctx, const char *path );
  31895. #endif /* MBEDTLS_FS_IO */
  31896. #if defined(MBEDTLS_SELF_TEST)
  31897. /**
  31898. * \brief The HMAC_DRBG Checkup routine.
  31899. *
  31900. * \return \c 0 if successful.
  31901. * \return \c 1 if the test failed.
  31902. */
  31903. int mbedtls_hmac_drbg_self_test( int verbose );
  31904. #endif
  31905. #ifdef __cplusplus
  31906. }
  31907. #endif
  31908. #endif /* hmac_drbg.h */
  31909. /********* Start of file include/mbedtls/pkcs12.h ************/
  31910. /**
  31911. * \file pkcs12.h
  31912. *
  31913. * \brief PKCS#12 Personal Information Exchange Syntax
  31914. */
  31915. /*
  31916. * Copyright The Mbed TLS Contributors
  31917. * SPDX-License-Identifier: Apache-2.0
  31918. *
  31919. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  31920. * not use this file except in compliance with the License.
  31921. * You may obtain a copy of the License at
  31922. *
  31923. * http://www.apache.org/licenses/LICENSE-2.0
  31924. *
  31925. * Unless required by applicable law or agreed to in writing, software
  31926. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  31927. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  31928. * See the License for the specific language governing permissions and
  31929. * limitations under the License.
  31930. */
  31931. #ifndef MBEDTLS_PKCS12_H
  31932. #define MBEDTLS_PKCS12_H
  31933. #if !defined(MBEDTLS_CONFIG_FILE)
  31934. #else
  31935. #endif
  31936. #include <stddef.h>
  31937. /** Bad input parameters to function. */
  31938. #define MBEDTLS_ERR_PKCS12_BAD_INPUT_DATA -0x1F80
  31939. /** Feature not available, e.g. unsupported encryption scheme. */
  31940. #define MBEDTLS_ERR_PKCS12_FEATURE_UNAVAILABLE -0x1F00
  31941. /** PBE ASN.1 data not as expected. */
  31942. #define MBEDTLS_ERR_PKCS12_PBE_INVALID_FORMAT -0x1E80
  31943. /** Given private key password does not allow for correct decryption. */
  31944. #define MBEDTLS_ERR_PKCS12_PASSWORD_MISMATCH -0x1E00
  31945. #define MBEDTLS_PKCS12_DERIVE_KEY 1 /**< encryption/decryption key */
  31946. #define MBEDTLS_PKCS12_DERIVE_IV 2 /**< initialization vector */
  31947. #define MBEDTLS_PKCS12_DERIVE_MAC_KEY 3 /**< integrity / MAC key */
  31948. #define MBEDTLS_PKCS12_PBE_DECRYPT 0
  31949. #define MBEDTLS_PKCS12_PBE_ENCRYPT 1
  31950. #ifdef __cplusplus
  31951. extern "C" {
  31952. #endif
  31953. #if defined(MBEDTLS_ASN1_PARSE_C)
  31954. /**
  31955. * \brief PKCS12 Password Based function (encryption / decryption)
  31956. * for pbeWithSHAAnd128BitRC4
  31957. *
  31958. * \param pbe_params an ASN1 buffer containing the pkcs-12PbeParams structure
  31959. * \param mode either MBEDTLS_PKCS12_PBE_ENCRYPT or MBEDTLS_PKCS12_PBE_DECRYPT
  31960. * \param pwd the password used (may be NULL if no password is used)
  31961. * \param pwdlen length of the password (may be 0)
  31962. * \param input the input data
  31963. * \param len data length
  31964. * \param output the output buffer
  31965. *
  31966. * \return 0 if successful, or a MBEDTLS_ERR_XXX code
  31967. */
  31968. int mbedtls_pkcs12_pbe_sha1_rc4_128( mbedtls_asn1_buf *pbe_params, int mode,
  31969. const unsigned char *pwd, size_t pwdlen,
  31970. const unsigned char *input, size_t len,
  31971. unsigned char *output );
  31972. /**
  31973. * \brief PKCS12 Password Based function (encryption / decryption)
  31974. * for cipher-based and mbedtls_md-based PBE's
  31975. *
  31976. * \param pbe_params an ASN1 buffer containing the pkcs-12 PbeParams structure
  31977. * \param mode either #MBEDTLS_PKCS12_PBE_ENCRYPT or
  31978. * #MBEDTLS_PKCS12_PBE_DECRYPT
  31979. * \param cipher_type the cipher used
  31980. * \param md_type the mbedtls_md used
  31981. * \param pwd Latin1-encoded password used. This may only be \c NULL when
  31982. * \p pwdlen is 0. No null terminator should be used.
  31983. * \param pwdlen length of the password (may be 0)
  31984. * \param input the input data
  31985. * \param len data length
  31986. * \param output the output buffer
  31987. *
  31988. * \return 0 if successful, or a MBEDTLS_ERR_XXX code
  31989. */
  31990. int mbedtls_pkcs12_pbe( mbedtls_asn1_buf *pbe_params, int mode,
  31991. mbedtls_cipher_type_t cipher_type, mbedtls_md_type_t md_type,
  31992. const unsigned char *pwd, size_t pwdlen,
  31993. const unsigned char *input, size_t len,
  31994. unsigned char *output );
  31995. #endif /* MBEDTLS_ASN1_PARSE_C */
  31996. /**
  31997. * \brief The PKCS#12 derivation function uses a password and a salt
  31998. * to produce pseudo-random bits for a particular "purpose".
  31999. *
  32000. * Depending on the given id, this function can produce an
  32001. * encryption/decryption key, an initialization vector or an
  32002. * integrity key.
  32003. *
  32004. * \param data buffer to store the derived data in
  32005. * \param datalen length of buffer to fill
  32006. * \param pwd The password to use. For compliance with PKCS#12 §B.1, this
  32007. * should be a BMPString, i.e. a Unicode string where each
  32008. * character is encoded as 2 bytes in big-endian order, with
  32009. * no byte order mark and with a null terminator (i.e. the
  32010. * last two bytes should be 0x00 0x00).
  32011. * \param pwdlen length of the password (may be 0).
  32012. * \param salt Salt buffer to use This may only be \c NULL when
  32013. * \p saltlen is 0.
  32014. * \param saltlen length of the salt (may be zero)
  32015. * \param mbedtls_md mbedtls_md type to use during the derivation
  32016. * \param id id that describes the purpose (can be
  32017. * #MBEDTLS_PKCS12_DERIVE_KEY, #MBEDTLS_PKCS12_DERIVE_IV or
  32018. * #MBEDTLS_PKCS12_DERIVE_MAC_KEY)
  32019. * \param iterations number of iterations
  32020. *
  32021. * \return 0 if successful, or a MD, BIGNUM type error.
  32022. */
  32023. int mbedtls_pkcs12_derivation( unsigned char *data, size_t datalen,
  32024. const unsigned char *pwd, size_t pwdlen,
  32025. const unsigned char *salt, size_t saltlen,
  32026. mbedtls_md_type_t mbedtls_md, int id, int iterations );
  32027. #ifdef __cplusplus
  32028. }
  32029. #endif
  32030. #endif /* pkcs12.h */
  32031. /********* Start of file include/mbedtls/pkcs11.h ************/
  32032. /**
  32033. * \file pkcs11.h
  32034. *
  32035. * \brief Wrapper for PKCS#11 library libpkcs11-helper
  32036. *
  32037. * \author Adriaan de Jong <dejong@fox-it.com>
  32038. */
  32039. /*
  32040. * Copyright The Mbed TLS Contributors
  32041. * SPDX-License-Identifier: Apache-2.0
  32042. *
  32043. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  32044. * not use this file except in compliance with the License.
  32045. * You may obtain a copy of the License at
  32046. *
  32047. * http://www.apache.org/licenses/LICENSE-2.0
  32048. *
  32049. * Unless required by applicable law or agreed to in writing, software
  32050. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  32051. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  32052. * See the License for the specific language governing permissions and
  32053. * limitations under the License.
  32054. */
  32055. #ifndef MBEDTLS_PKCS11_H
  32056. #define MBEDTLS_PKCS11_H
  32057. #if !defined(MBEDTLS_CONFIG_FILE)
  32058. #else
  32059. #endif
  32060. #if defined(MBEDTLS_PKCS11_C)
  32061. #include <pkcs11-helper-1.0/pkcs11h-certificate.h>
  32062. #if ( defined(__ARMCC_VERSION) || defined(_MSC_VER) ) && \
  32063. !defined(inline) && !defined(__cplusplus)
  32064. #define inline __inline
  32065. #endif
  32066. #ifdef __cplusplus
  32067. extern "C" {
  32068. #endif
  32069. #if defined(MBEDTLS_DEPRECATED_REMOVED)
  32070. /**
  32071. * Context for PKCS #11 private keys.
  32072. */
  32073. typedef struct mbedtls_pkcs11_context
  32074. {
  32075. pkcs11h_certificate_t pkcs11h_cert;
  32076. int len;
  32077. } mbedtls_pkcs11_context;
  32078. #if defined(MBEDTLS_DEPRECATED_WARNING)
  32079. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  32080. #else
  32081. #define MBEDTLS_DEPRECATED
  32082. #endif
  32083. /**
  32084. * Initialize a mbedtls_pkcs11_context.
  32085. * (Just making memory references valid.)
  32086. *
  32087. * \deprecated This function is deprecated and will be removed in a
  32088. * future version of the library.
  32089. */
  32090. MBEDTLS_DEPRECATED void mbedtls_pkcs11_init( mbedtls_pkcs11_context *ctx );
  32091. /**
  32092. * Fill in a mbed TLS certificate, based on the given PKCS11 helper certificate.
  32093. *
  32094. * \deprecated This function is deprecated and will be removed in a
  32095. * future version of the library.
  32096. *
  32097. * \param cert X.509 certificate to fill
  32098. * \param pkcs11h_cert PKCS #11 helper certificate
  32099. *
  32100. * \return 0 on success.
  32101. */
  32102. MBEDTLS_DEPRECATED int mbedtls_pkcs11_x509_cert_bind( mbedtls_x509_crt *cert,
  32103. pkcs11h_certificate_t pkcs11h_cert );
  32104. /**
  32105. * Set up a mbedtls_pkcs11_context storing the given certificate. Note that the
  32106. * mbedtls_pkcs11_context will take over control of the certificate, freeing it when
  32107. * done.
  32108. *
  32109. * \deprecated This function is deprecated and will be removed in a
  32110. * future version of the library.
  32111. *
  32112. * \param priv_key Private key structure to fill.
  32113. * \param pkcs11_cert PKCS #11 helper certificate
  32114. *
  32115. * \return 0 on success
  32116. */
  32117. MBEDTLS_DEPRECATED int mbedtls_pkcs11_priv_key_bind(
  32118. mbedtls_pkcs11_context *priv_key,
  32119. pkcs11h_certificate_t pkcs11_cert );
  32120. /**
  32121. * Free the contents of the given private key context. Note that the structure
  32122. * itself is not freed.
  32123. *
  32124. * \deprecated This function is deprecated and will be removed in a
  32125. * future version of the library.
  32126. *
  32127. * \param priv_key Private key structure to cleanup
  32128. */
  32129. MBEDTLS_DEPRECATED void mbedtls_pkcs11_priv_key_free(
  32130. mbedtls_pkcs11_context *priv_key );
  32131. /**
  32132. * \brief Do an RSA private key decrypt, then remove the message
  32133. * padding
  32134. *
  32135. * \deprecated This function is deprecated and will be removed in a future
  32136. * version of the library.
  32137. *
  32138. * \param ctx PKCS #11 context
  32139. * \param mode must be MBEDTLS_RSA_PRIVATE, for compatibility with rsa.c's signature
  32140. * \param input buffer holding the encrypted data
  32141. * \param output buffer that will hold the plaintext
  32142. * \param olen will contain the plaintext length
  32143. * \param output_max_len maximum length of the output buffer
  32144. *
  32145. * \return 0 if successful, or an MBEDTLS_ERR_RSA_XXX error code
  32146. *
  32147. * \note The output buffer must be as large as the size
  32148. * of ctx->N (eg. 128 bytes if RSA-1024 is used) otherwise
  32149. * an error is thrown.
  32150. */
  32151. MBEDTLS_DEPRECATED int mbedtls_pkcs11_decrypt( mbedtls_pkcs11_context *ctx,
  32152. int mode, size_t *olen,
  32153. const unsigned char *input,
  32154. unsigned char *output,
  32155. size_t output_max_len );
  32156. /**
  32157. * \brief Do a private RSA to sign a message digest
  32158. *
  32159. * \deprecated This function is deprecated and will be removed in a future
  32160. * version of the library.
  32161. *
  32162. * \param ctx PKCS #11 context
  32163. * \param mode must be MBEDTLS_RSA_PRIVATE, for compatibility with rsa.c's signature
  32164. * \param md_alg a MBEDTLS_MD_XXX (use MBEDTLS_MD_NONE for signing raw data)
  32165. * \param hashlen message digest length (for MBEDTLS_MD_NONE only)
  32166. * \param hash buffer holding the message digest
  32167. * \param sig buffer that will hold the ciphertext
  32168. *
  32169. * \return 0 if the signing operation was successful,
  32170. * or an MBEDTLS_ERR_RSA_XXX error code
  32171. *
  32172. * \note The "sig" buffer must be as large as the size
  32173. * of ctx->N (eg. 128 bytes if RSA-1024 is used).
  32174. */
  32175. MBEDTLS_DEPRECATED int mbedtls_pkcs11_sign( mbedtls_pkcs11_context *ctx,
  32176. int mode,
  32177. mbedtls_md_type_t md_alg,
  32178. unsigned int hashlen,
  32179. const unsigned char *hash,
  32180. unsigned char *sig );
  32181. /**
  32182. * SSL/TLS wrappers for PKCS#11 functions
  32183. *
  32184. * \deprecated This function is deprecated and will be removed in a future
  32185. * version of the library.
  32186. */
  32187. MBEDTLS_DEPRECATED static inline int mbedtls_ssl_pkcs11_decrypt( void *ctx,
  32188. int mode, size_t *olen,
  32189. const unsigned char *input, unsigned char *output,
  32190. size_t output_max_len )
  32191. {
  32192. return mbedtls_pkcs11_decrypt( (mbedtls_pkcs11_context *) ctx, mode, olen, input, output,
  32193. output_max_len );
  32194. }
  32195. /**
  32196. * \brief This function signs a message digest using RSA.
  32197. *
  32198. * \deprecated This function is deprecated and will be removed in a future
  32199. * version of the library.
  32200. *
  32201. * \param ctx The PKCS #11 context.
  32202. * \param f_rng The RNG function. This parameter is unused.
  32203. * \param p_rng The RNG context. This parameter is unused.
  32204. * \param mode The operation to run. This must be set to
  32205. * MBEDTLS_RSA_PRIVATE, for compatibility with rsa.c's
  32206. * signature.
  32207. * \param md_alg The message digest algorithm. One of the MBEDTLS_MD_XXX
  32208. * must be passed to this function and MBEDTLS_MD_NONE can be
  32209. * used for signing raw data.
  32210. * \param hashlen The message digest length (for MBEDTLS_MD_NONE only).
  32211. * \param hash The buffer holding the message digest.
  32212. * \param sig The buffer that will hold the ciphertext.
  32213. *
  32214. * \return \c 0 if the signing operation was successful.
  32215. * \return A non-zero error code on failure.
  32216. *
  32217. * \note The \p sig buffer must be as large as the size of
  32218. * <code>ctx->N</code>. For example, 128 bytes if RSA-1024 is
  32219. * used.
  32220. */
  32221. MBEDTLS_DEPRECATED static inline int mbedtls_ssl_pkcs11_sign( void *ctx,
  32222. int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
  32223. int mode, mbedtls_md_type_t md_alg, unsigned int hashlen,
  32224. const unsigned char *hash, unsigned char *sig )
  32225. {
  32226. ((void) f_rng);
  32227. ((void) p_rng);
  32228. return mbedtls_pkcs11_sign( (mbedtls_pkcs11_context *) ctx, mode, md_alg,
  32229. hashlen, hash, sig );
  32230. }
  32231. /**
  32232. * This function gets the length of the private key.
  32233. *
  32234. * \deprecated This function is deprecated and will be removed in a future
  32235. * version of the library.
  32236. *
  32237. * \param ctx The PKCS #11 context.
  32238. *
  32239. * \return The length of the private key.
  32240. */
  32241. MBEDTLS_DEPRECATED static inline size_t mbedtls_ssl_pkcs11_key_len( void *ctx )
  32242. {
  32243. return ( (mbedtls_pkcs11_context *) ctx )->len;
  32244. }
  32245. #undef MBEDTLS_DEPRECATED
  32246. #endif /* MBEDTLS_DEPRECATED_REMOVED */
  32247. #ifdef __cplusplus
  32248. }
  32249. #endif
  32250. #endif /* MBEDTLS_PKCS11_C */
  32251. #endif /* MBEDTLS_PKCS11_H */
  32252. /********* Start of file include/mbedtls/pkcs5.h ************/
  32253. /**
  32254. * \file pkcs5.h
  32255. *
  32256. * \brief PKCS#5 functions
  32257. *
  32258. * \author Mathias Olsson <mathias@kompetensum.com>
  32259. */
  32260. /*
  32261. * Copyright The Mbed TLS Contributors
  32262. * SPDX-License-Identifier: Apache-2.0
  32263. *
  32264. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  32265. * not use this file except in compliance with the License.
  32266. * You may obtain a copy of the License at
  32267. *
  32268. * http://www.apache.org/licenses/LICENSE-2.0
  32269. *
  32270. * Unless required by applicable law or agreed to in writing, software
  32271. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  32272. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  32273. * See the License for the specific language governing permissions and
  32274. * limitations under the License.
  32275. */
  32276. #ifndef MBEDTLS_PKCS5_H
  32277. #define MBEDTLS_PKCS5_H
  32278. #if !defined(MBEDTLS_CONFIG_FILE)
  32279. #else
  32280. #endif
  32281. #include <stddef.h>
  32282. #include <stdint.h>
  32283. /** Bad input parameters to function. */
  32284. #define MBEDTLS_ERR_PKCS5_BAD_INPUT_DATA -0x2f80
  32285. /** Unexpected ASN.1 data. */
  32286. #define MBEDTLS_ERR_PKCS5_INVALID_FORMAT -0x2f00
  32287. /** Requested encryption or digest alg not available. */
  32288. #define MBEDTLS_ERR_PKCS5_FEATURE_UNAVAILABLE -0x2e80
  32289. /** Given private key password does not allow for correct decryption. */
  32290. #define MBEDTLS_ERR_PKCS5_PASSWORD_MISMATCH -0x2e00
  32291. #define MBEDTLS_PKCS5_DECRYPT 0
  32292. #define MBEDTLS_PKCS5_ENCRYPT 1
  32293. #ifdef __cplusplus
  32294. extern "C" {
  32295. #endif
  32296. #if defined(MBEDTLS_ASN1_PARSE_C)
  32297. /**
  32298. * \brief PKCS#5 PBES2 function
  32299. *
  32300. * \param pbe_params the ASN.1 algorithm parameters
  32301. * \param mode either MBEDTLS_PKCS5_DECRYPT or MBEDTLS_PKCS5_ENCRYPT
  32302. * \param pwd password to use when generating key
  32303. * \param pwdlen length of password
  32304. * \param data data to process
  32305. * \param datalen length of data
  32306. * \param output output buffer
  32307. *
  32308. * \returns 0 on success, or a MBEDTLS_ERR_XXX code if verification fails.
  32309. */
  32310. int mbedtls_pkcs5_pbes2( const mbedtls_asn1_buf *pbe_params, int mode,
  32311. const unsigned char *pwd, size_t pwdlen,
  32312. const unsigned char *data, size_t datalen,
  32313. unsigned char *output );
  32314. #endif /* MBEDTLS_ASN1_PARSE_C */
  32315. /**
  32316. * \brief PKCS#5 PBKDF2 using HMAC
  32317. *
  32318. * \param ctx Generic HMAC context
  32319. * \param password Password to use when generating key
  32320. * \param plen Length of password
  32321. * \param salt Salt to use when generating key
  32322. * \param slen Length of salt
  32323. * \param iteration_count Iteration count
  32324. * \param key_length Length of generated key in bytes
  32325. * \param output Generated key. Must be at least as big as key_length
  32326. *
  32327. * \returns 0 on success, or a MBEDTLS_ERR_XXX code if verification fails.
  32328. */
  32329. int mbedtls_pkcs5_pbkdf2_hmac( mbedtls_md_context_t *ctx, const unsigned char *password,
  32330. size_t plen, const unsigned char *salt, size_t slen,
  32331. unsigned int iteration_count,
  32332. uint32_t key_length, unsigned char *output );
  32333. #if defined(MBEDTLS_SELF_TEST)
  32334. /**
  32335. * \brief Checkup routine
  32336. *
  32337. * \return 0 if successful, or 1 if the test failed
  32338. */
  32339. int mbedtls_pkcs5_self_test( int verbose );
  32340. #endif /* MBEDTLS_SELF_TEST */
  32341. #ifdef __cplusplus
  32342. }
  32343. #endif
  32344. #endif /* pkcs5.h */
  32345. /********* Start of file include/mbedtls/oid.h ************/
  32346. /**
  32347. * \file oid.h
  32348. *
  32349. * \brief Object Identifier (OID) database
  32350. */
  32351. /*
  32352. * Copyright The Mbed TLS Contributors
  32353. * SPDX-License-Identifier: Apache-2.0
  32354. *
  32355. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  32356. * not use this file except in compliance with the License.
  32357. * You may obtain a copy of the License at
  32358. *
  32359. * http://www.apache.org/licenses/LICENSE-2.0
  32360. *
  32361. * Unless required by applicable law or agreed to in writing, software
  32362. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  32363. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  32364. * See the License for the specific language governing permissions and
  32365. * limitations under the License.
  32366. */
  32367. #ifndef MBEDTLS_OID_H
  32368. #define MBEDTLS_OID_H
  32369. #if !defined(MBEDTLS_CONFIG_FILE)
  32370. #else
  32371. #endif
  32372. #include <stddef.h>
  32373. #if defined(MBEDTLS_CIPHER_C)
  32374. #endif
  32375. #if defined(MBEDTLS_MD_C)
  32376. #endif
  32377. /** OID is not found. */
  32378. #define MBEDTLS_ERR_OID_NOT_FOUND -0x002E
  32379. /** output buffer is too small */
  32380. #define MBEDTLS_ERR_OID_BUF_TOO_SMALL -0x000B
  32381. /* This is for the benefit of X.509, but defined here in order to avoid
  32382. * having a "backwards" include of x.509.h here */
  32383. /*
  32384. * X.509 extension types (internal, arbitrary values for bitsets)
  32385. */
  32386. #define MBEDTLS_OID_X509_EXT_AUTHORITY_KEY_IDENTIFIER (1 << 0)
  32387. #define MBEDTLS_OID_X509_EXT_SUBJECT_KEY_IDENTIFIER (1 << 1)
  32388. #define MBEDTLS_OID_X509_EXT_KEY_USAGE (1 << 2)
  32389. #define MBEDTLS_OID_X509_EXT_CERTIFICATE_POLICIES (1 << 3)
  32390. #define MBEDTLS_OID_X509_EXT_POLICY_MAPPINGS (1 << 4)
  32391. #define MBEDTLS_OID_X509_EXT_SUBJECT_ALT_NAME (1 << 5)
  32392. #define MBEDTLS_OID_X509_EXT_ISSUER_ALT_NAME (1 << 6)
  32393. #define MBEDTLS_OID_X509_EXT_SUBJECT_DIRECTORY_ATTRS (1 << 7)
  32394. #define MBEDTLS_OID_X509_EXT_BASIC_CONSTRAINTS (1 << 8)
  32395. #define MBEDTLS_OID_X509_EXT_NAME_CONSTRAINTS (1 << 9)
  32396. #define MBEDTLS_OID_X509_EXT_POLICY_CONSTRAINTS (1 << 10)
  32397. #define MBEDTLS_OID_X509_EXT_EXTENDED_KEY_USAGE (1 << 11)
  32398. #define MBEDTLS_OID_X509_EXT_CRL_DISTRIBUTION_POINTS (1 << 12)
  32399. #define MBEDTLS_OID_X509_EXT_INIHIBIT_ANYPOLICY (1 << 13)
  32400. #define MBEDTLS_OID_X509_EXT_FRESHEST_CRL (1 << 14)
  32401. #define MBEDTLS_OID_X509_EXT_NS_CERT_TYPE (1 << 16)
  32402. /*
  32403. * Top level OID tuples
  32404. */
  32405. #define MBEDTLS_OID_ISO_MEMBER_BODIES "\x2a" /* {iso(1) member-body(2)} */
  32406. #define MBEDTLS_OID_ISO_IDENTIFIED_ORG "\x2b" /* {iso(1) identified-organization(3)} */
  32407. #define MBEDTLS_OID_ISO_CCITT_DS "\x55" /* {joint-iso-ccitt(2) ds(5)} */
  32408. #define MBEDTLS_OID_ISO_ITU_COUNTRY "\x60" /* {joint-iso-itu-t(2) country(16)} */
  32409. /*
  32410. * ISO Member bodies OID parts
  32411. */
  32412. #define MBEDTLS_OID_COUNTRY_US "\x86\x48" /* {us(840)} */
  32413. #define MBEDTLS_OID_ORG_RSA_DATA_SECURITY "\x86\xf7\x0d" /* {rsadsi(113549)} */
  32414. #define MBEDTLS_OID_RSA_COMPANY MBEDTLS_OID_ISO_MEMBER_BODIES MBEDTLS_OID_COUNTRY_US \
  32415. MBEDTLS_OID_ORG_RSA_DATA_SECURITY /* {iso(1) member-body(2) us(840) rsadsi(113549)} */
  32416. #define MBEDTLS_OID_ORG_ANSI_X9_62 "\xce\x3d" /* ansi-X9-62(10045) */
  32417. #define MBEDTLS_OID_ANSI_X9_62 MBEDTLS_OID_ISO_MEMBER_BODIES MBEDTLS_OID_COUNTRY_US \
  32418. MBEDTLS_OID_ORG_ANSI_X9_62
  32419. /*
  32420. * ISO Identified organization OID parts
  32421. */
  32422. #define MBEDTLS_OID_ORG_DOD "\x06" /* {dod(6)} */
  32423. #define MBEDTLS_OID_ORG_OIW "\x0e"
  32424. #define MBEDTLS_OID_OIW_SECSIG MBEDTLS_OID_ORG_OIW "\x03"
  32425. #define MBEDTLS_OID_OIW_SECSIG_ALG MBEDTLS_OID_OIW_SECSIG "\x02"
  32426. #define MBEDTLS_OID_OIW_SECSIG_SHA1 MBEDTLS_OID_OIW_SECSIG_ALG "\x1a"
  32427. #define MBEDTLS_OID_ORG_CERTICOM "\x81\x04" /* certicom(132) */
  32428. #define MBEDTLS_OID_CERTICOM MBEDTLS_OID_ISO_IDENTIFIED_ORG MBEDTLS_OID_ORG_CERTICOM
  32429. #define MBEDTLS_OID_ORG_TELETRUST "\x24" /* teletrust(36) */
  32430. #define MBEDTLS_OID_TELETRUST MBEDTLS_OID_ISO_IDENTIFIED_ORG MBEDTLS_OID_ORG_TELETRUST
  32431. /*
  32432. * ISO ITU OID parts
  32433. */
  32434. #define MBEDTLS_OID_ORGANIZATION "\x01" /* {organization(1)} */
  32435. #define MBEDTLS_OID_ISO_ITU_US_ORG MBEDTLS_OID_ISO_ITU_COUNTRY MBEDTLS_OID_COUNTRY_US MBEDTLS_OID_ORGANIZATION /* {joint-iso-itu-t(2) country(16) us(840) organization(1)} */
  32436. #define MBEDTLS_OID_ORG_GOV "\x65" /* {gov(101)} */
  32437. #define MBEDTLS_OID_GOV MBEDTLS_OID_ISO_ITU_US_ORG MBEDTLS_OID_ORG_GOV /* {joint-iso-itu-t(2) country(16) us(840) organization(1) gov(101)} */
  32438. #define MBEDTLS_OID_ORG_NETSCAPE "\x86\xF8\x42" /* {netscape(113730)} */
  32439. #define MBEDTLS_OID_NETSCAPE MBEDTLS_OID_ISO_ITU_US_ORG MBEDTLS_OID_ORG_NETSCAPE /* Netscape OID {joint-iso-itu-t(2) country(16) us(840) organization(1) netscape(113730)} */
  32440. /* ISO arc for standard certificate and CRL extensions */
  32441. #define MBEDTLS_OID_ID_CE MBEDTLS_OID_ISO_CCITT_DS "\x1D" /**< id-ce OBJECT IDENTIFIER ::= {joint-iso-ccitt(2) ds(5) 29} */
  32442. #define MBEDTLS_OID_NIST_ALG MBEDTLS_OID_GOV "\x03\x04" /** { joint-iso-itu-t(2) country(16) us(840) organization(1) gov(101) csor(3) nistAlgorithm(4) */
  32443. /**
  32444. * Private Internet Extensions
  32445. * { iso(1) identified-organization(3) dod(6) internet(1)
  32446. * security(5) mechanisms(5) pkix(7) }
  32447. */
  32448. #define MBEDTLS_OID_INTERNET MBEDTLS_OID_ISO_IDENTIFIED_ORG MBEDTLS_OID_ORG_DOD "\x01"
  32449. #define MBEDTLS_OID_PKIX MBEDTLS_OID_INTERNET "\x05\x05\x07"
  32450. /*
  32451. * Arc for standard naming attributes
  32452. */
  32453. #define MBEDTLS_OID_AT MBEDTLS_OID_ISO_CCITT_DS "\x04" /**< id-at OBJECT IDENTIFIER ::= {joint-iso-ccitt(2) ds(5) 4} */
  32454. #define MBEDTLS_OID_AT_CN MBEDTLS_OID_AT "\x03" /**< id-at-commonName AttributeType:= {id-at 3} */
  32455. #define MBEDTLS_OID_AT_SUR_NAME MBEDTLS_OID_AT "\x04" /**< id-at-surName AttributeType:= {id-at 4} */
  32456. #define MBEDTLS_OID_AT_SERIAL_NUMBER MBEDTLS_OID_AT "\x05" /**< id-at-serialNumber AttributeType:= {id-at 5} */
  32457. #define MBEDTLS_OID_AT_COUNTRY MBEDTLS_OID_AT "\x06" /**< id-at-countryName AttributeType:= {id-at 6} */
  32458. #define MBEDTLS_OID_AT_LOCALITY MBEDTLS_OID_AT "\x07" /**< id-at-locality AttributeType:= {id-at 7} */
  32459. #define MBEDTLS_OID_AT_STATE MBEDTLS_OID_AT "\x08" /**< id-at-state AttributeType:= {id-at 8} */
  32460. #define MBEDTLS_OID_AT_ORGANIZATION MBEDTLS_OID_AT "\x0A" /**< id-at-organizationName AttributeType:= {id-at 10} */
  32461. #define MBEDTLS_OID_AT_ORG_UNIT MBEDTLS_OID_AT "\x0B" /**< id-at-organizationalUnitName AttributeType:= {id-at 11} */
  32462. #define MBEDTLS_OID_AT_TITLE MBEDTLS_OID_AT "\x0C" /**< id-at-title AttributeType:= {id-at 12} */
  32463. #define MBEDTLS_OID_AT_POSTAL_ADDRESS MBEDTLS_OID_AT "\x10" /**< id-at-postalAddress AttributeType:= {id-at 16} */
  32464. #define MBEDTLS_OID_AT_POSTAL_CODE MBEDTLS_OID_AT "\x11" /**< id-at-postalCode AttributeType:= {id-at 17} */
  32465. #define MBEDTLS_OID_AT_GIVEN_NAME MBEDTLS_OID_AT "\x2A" /**< id-at-givenName AttributeType:= {id-at 42} */
  32466. #define MBEDTLS_OID_AT_INITIALS MBEDTLS_OID_AT "\x2B" /**< id-at-initials AttributeType:= {id-at 43} */
  32467. #define MBEDTLS_OID_AT_GENERATION_QUALIFIER MBEDTLS_OID_AT "\x2C" /**< id-at-generationQualifier AttributeType:= {id-at 44} */
  32468. #define MBEDTLS_OID_AT_UNIQUE_IDENTIFIER MBEDTLS_OID_AT "\x2D" /**< id-at-uniqueIdentifier AttributType:= {id-at 45} */
  32469. #define MBEDTLS_OID_AT_DN_QUALIFIER MBEDTLS_OID_AT "\x2E" /**< id-at-dnQualifier AttributeType:= {id-at 46} */
  32470. #define MBEDTLS_OID_AT_PSEUDONYM MBEDTLS_OID_AT "\x41" /**< id-at-pseudonym AttributeType:= {id-at 65} */
  32471. #define MBEDTLS_OID_DOMAIN_COMPONENT "\x09\x92\x26\x89\x93\xF2\x2C\x64\x01\x19" /** id-domainComponent AttributeType:= {itu-t(0) data(9) pss(2342) ucl(19200300) pilot(100) pilotAttributeType(1) domainComponent(25)} */
  32472. /*
  32473. * OIDs for standard certificate extensions
  32474. */
  32475. #define MBEDTLS_OID_AUTHORITY_KEY_IDENTIFIER MBEDTLS_OID_ID_CE "\x23" /**< id-ce-authorityKeyIdentifier OBJECT IDENTIFIER ::= { id-ce 35 } */
  32476. #define MBEDTLS_OID_SUBJECT_KEY_IDENTIFIER MBEDTLS_OID_ID_CE "\x0E" /**< id-ce-subjectKeyIdentifier OBJECT IDENTIFIER ::= { id-ce 14 } */
  32477. #define MBEDTLS_OID_KEY_USAGE MBEDTLS_OID_ID_CE "\x0F" /**< id-ce-keyUsage OBJECT IDENTIFIER ::= { id-ce 15 } */
  32478. #define MBEDTLS_OID_CERTIFICATE_POLICIES MBEDTLS_OID_ID_CE "\x20" /**< id-ce-certificatePolicies OBJECT IDENTIFIER ::= { id-ce 32 } */
  32479. #define MBEDTLS_OID_POLICY_MAPPINGS MBEDTLS_OID_ID_CE "\x21" /**< id-ce-policyMappings OBJECT IDENTIFIER ::= { id-ce 33 } */
  32480. #define MBEDTLS_OID_SUBJECT_ALT_NAME MBEDTLS_OID_ID_CE "\x11" /**< id-ce-subjectAltName OBJECT IDENTIFIER ::= { id-ce 17 } */
  32481. #define MBEDTLS_OID_ISSUER_ALT_NAME MBEDTLS_OID_ID_CE "\x12" /**< id-ce-issuerAltName OBJECT IDENTIFIER ::= { id-ce 18 } */
  32482. #define MBEDTLS_OID_SUBJECT_DIRECTORY_ATTRS MBEDTLS_OID_ID_CE "\x09" /**< id-ce-subjectDirectoryAttributes OBJECT IDENTIFIER ::= { id-ce 9 } */
  32483. #define MBEDTLS_OID_BASIC_CONSTRAINTS MBEDTLS_OID_ID_CE "\x13" /**< id-ce-basicConstraints OBJECT IDENTIFIER ::= { id-ce 19 } */
  32484. #define MBEDTLS_OID_NAME_CONSTRAINTS MBEDTLS_OID_ID_CE "\x1E" /**< id-ce-nameConstraints OBJECT IDENTIFIER ::= { id-ce 30 } */
  32485. #define MBEDTLS_OID_POLICY_CONSTRAINTS MBEDTLS_OID_ID_CE "\x24" /**< id-ce-policyConstraints OBJECT IDENTIFIER ::= { id-ce 36 } */
  32486. #define MBEDTLS_OID_EXTENDED_KEY_USAGE MBEDTLS_OID_ID_CE "\x25" /**< id-ce-extKeyUsage OBJECT IDENTIFIER ::= { id-ce 37 } */
  32487. #define MBEDTLS_OID_CRL_DISTRIBUTION_POINTS MBEDTLS_OID_ID_CE "\x1F" /**< id-ce-cRLDistributionPoints OBJECT IDENTIFIER ::= { id-ce 31 } */
  32488. #define MBEDTLS_OID_INIHIBIT_ANYPOLICY MBEDTLS_OID_ID_CE "\x36" /**< id-ce-inhibitAnyPolicy OBJECT IDENTIFIER ::= { id-ce 54 } */
  32489. #define MBEDTLS_OID_FRESHEST_CRL MBEDTLS_OID_ID_CE "\x2E" /**< id-ce-freshestCRL OBJECT IDENTIFIER ::= { id-ce 46 } */
  32490. /*
  32491. * Certificate policies
  32492. */
  32493. #define MBEDTLS_OID_ANY_POLICY MBEDTLS_OID_CERTIFICATE_POLICIES "\x00" /**< anyPolicy OBJECT IDENTIFIER ::= { id-ce-certificatePolicies 0 } */
  32494. /*
  32495. * Netscape certificate extensions
  32496. */
  32497. #define MBEDTLS_OID_NS_CERT MBEDTLS_OID_NETSCAPE "\x01"
  32498. #define MBEDTLS_OID_NS_CERT_TYPE MBEDTLS_OID_NS_CERT "\x01"
  32499. #define MBEDTLS_OID_NS_BASE_URL MBEDTLS_OID_NS_CERT "\x02"
  32500. #define MBEDTLS_OID_NS_REVOCATION_URL MBEDTLS_OID_NS_CERT "\x03"
  32501. #define MBEDTLS_OID_NS_CA_REVOCATION_URL MBEDTLS_OID_NS_CERT "\x04"
  32502. #define MBEDTLS_OID_NS_RENEWAL_URL MBEDTLS_OID_NS_CERT "\x07"
  32503. #define MBEDTLS_OID_NS_CA_POLICY_URL MBEDTLS_OID_NS_CERT "\x08"
  32504. #define MBEDTLS_OID_NS_SSL_SERVER_NAME MBEDTLS_OID_NS_CERT "\x0C"
  32505. #define MBEDTLS_OID_NS_COMMENT MBEDTLS_OID_NS_CERT "\x0D"
  32506. #define MBEDTLS_OID_NS_DATA_TYPE MBEDTLS_OID_NETSCAPE "\x02"
  32507. #define MBEDTLS_OID_NS_CERT_SEQUENCE MBEDTLS_OID_NS_DATA_TYPE "\x05"
  32508. /*
  32509. * OIDs for CRL extensions
  32510. */
  32511. #define MBEDTLS_OID_PRIVATE_KEY_USAGE_PERIOD MBEDTLS_OID_ID_CE "\x10"
  32512. #define MBEDTLS_OID_CRL_NUMBER MBEDTLS_OID_ID_CE "\x14" /**< id-ce-cRLNumber OBJECT IDENTIFIER ::= { id-ce 20 } */
  32513. /*
  32514. * X.509 v3 Extended key usage OIDs
  32515. */
  32516. #define MBEDTLS_OID_ANY_EXTENDED_KEY_USAGE MBEDTLS_OID_EXTENDED_KEY_USAGE "\x00" /**< anyExtendedKeyUsage OBJECT IDENTIFIER ::= { id-ce-extKeyUsage 0 } */
  32517. #define MBEDTLS_OID_KP MBEDTLS_OID_PKIX "\x03" /**< id-kp OBJECT IDENTIFIER ::= { id-pkix 3 } */
  32518. #define MBEDTLS_OID_SERVER_AUTH MBEDTLS_OID_KP "\x01" /**< id-kp-serverAuth OBJECT IDENTIFIER ::= { id-kp 1 } */
  32519. #define MBEDTLS_OID_CLIENT_AUTH MBEDTLS_OID_KP "\x02" /**< id-kp-clientAuth OBJECT IDENTIFIER ::= { id-kp 2 } */
  32520. #define MBEDTLS_OID_CODE_SIGNING MBEDTLS_OID_KP "\x03" /**< id-kp-codeSigning OBJECT IDENTIFIER ::= { id-kp 3 } */
  32521. #define MBEDTLS_OID_EMAIL_PROTECTION MBEDTLS_OID_KP "\x04" /**< id-kp-emailProtection OBJECT IDENTIFIER ::= { id-kp 4 } */
  32522. #define MBEDTLS_OID_TIME_STAMPING MBEDTLS_OID_KP "\x08" /**< id-kp-timeStamping OBJECT IDENTIFIER ::= { id-kp 8 } */
  32523. #define MBEDTLS_OID_OCSP_SIGNING MBEDTLS_OID_KP "\x09" /**< id-kp-OCSPSigning OBJECT IDENTIFIER ::= { id-kp 9 } */
  32524. /**
  32525. * Wi-SUN Alliance Field Area Network
  32526. * { iso(1) identified-organization(3) dod(6) internet(1)
  32527. * private(4) enterprise(1) WiSUN(45605) FieldAreaNetwork(1) }
  32528. */
  32529. #define MBEDTLS_OID_WISUN_FAN MBEDTLS_OID_INTERNET "\x04\x01\x82\xe4\x25\x01"
  32530. #define MBEDTLS_OID_ON MBEDTLS_OID_PKIX "\x08" /**< id-on OBJECT IDENTIFIER ::= { id-pkix 8 } */
  32531. #define MBEDTLS_OID_ON_HW_MODULE_NAME MBEDTLS_OID_ON "\x04" /**< id-on-hardwareModuleName OBJECT IDENTIFIER ::= { id-on 4 } */
  32532. /*
  32533. * PKCS definition OIDs
  32534. */
  32535. #define MBEDTLS_OID_PKCS MBEDTLS_OID_RSA_COMPANY "\x01" /**< pkcs OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) 1 } */
  32536. #define MBEDTLS_OID_PKCS1 MBEDTLS_OID_PKCS "\x01" /**< pkcs-1 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) 1 } */
  32537. #define MBEDTLS_OID_PKCS5 MBEDTLS_OID_PKCS "\x05" /**< pkcs-5 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) 5 } */
  32538. #define MBEDTLS_OID_PKCS9 MBEDTLS_OID_PKCS "\x09" /**< pkcs-9 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) 9 } */
  32539. #define MBEDTLS_OID_PKCS12 MBEDTLS_OID_PKCS "\x0c" /**< pkcs-12 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) pkcs(1) 12 } */
  32540. /*
  32541. * PKCS#1 OIDs
  32542. */
  32543. #define MBEDTLS_OID_PKCS1_RSA MBEDTLS_OID_PKCS1 "\x01" /**< rsaEncryption OBJECT IDENTIFIER ::= { pkcs-1 1 } */
  32544. #define MBEDTLS_OID_PKCS1_MD2 MBEDTLS_OID_PKCS1 "\x02" /**< md2WithRSAEncryption ::= { pkcs-1 2 } */
  32545. #define MBEDTLS_OID_PKCS1_MD4 MBEDTLS_OID_PKCS1 "\x03" /**< md4WithRSAEncryption ::= { pkcs-1 3 } */
  32546. #define MBEDTLS_OID_PKCS1_MD5 MBEDTLS_OID_PKCS1 "\x04" /**< md5WithRSAEncryption ::= { pkcs-1 4 } */
  32547. #define MBEDTLS_OID_PKCS1_SHA1 MBEDTLS_OID_PKCS1 "\x05" /**< sha1WithRSAEncryption ::= { pkcs-1 5 } */
  32548. #define MBEDTLS_OID_PKCS1_SHA224 MBEDTLS_OID_PKCS1 "\x0e" /**< sha224WithRSAEncryption ::= { pkcs-1 14 } */
  32549. #define MBEDTLS_OID_PKCS1_SHA256 MBEDTLS_OID_PKCS1 "\x0b" /**< sha256WithRSAEncryption ::= { pkcs-1 11 } */
  32550. #define MBEDTLS_OID_PKCS1_SHA384 MBEDTLS_OID_PKCS1 "\x0c" /**< sha384WithRSAEncryption ::= { pkcs-1 12 } */
  32551. #define MBEDTLS_OID_PKCS1_SHA512 MBEDTLS_OID_PKCS1 "\x0d" /**< sha512WithRSAEncryption ::= { pkcs-1 13 } */
  32552. #define MBEDTLS_OID_RSA_SHA_OBS "\x2B\x0E\x03\x02\x1D"
  32553. #define MBEDTLS_OID_PKCS9_EMAIL MBEDTLS_OID_PKCS9 "\x01" /**< emailAddress AttributeType ::= { pkcs-9 1 } */
  32554. /* RFC 4055 */
  32555. #define MBEDTLS_OID_RSASSA_PSS MBEDTLS_OID_PKCS1 "\x0a" /**< id-RSASSA-PSS ::= { pkcs-1 10 } */
  32556. #define MBEDTLS_OID_MGF1 MBEDTLS_OID_PKCS1 "\x08" /**< id-mgf1 ::= { pkcs-1 8 } */
  32557. /*
  32558. * Digest algorithms
  32559. */
  32560. #define MBEDTLS_OID_DIGEST_ALG_MD2 MBEDTLS_OID_RSA_COMPANY "\x02\x02" /**< id-mbedtls_md2 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) digestAlgorithm(2) 2 } */
  32561. #define MBEDTLS_OID_DIGEST_ALG_MD4 MBEDTLS_OID_RSA_COMPANY "\x02\x04" /**< id-mbedtls_md4 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) digestAlgorithm(2) 4 } */
  32562. #define MBEDTLS_OID_DIGEST_ALG_MD5 MBEDTLS_OID_RSA_COMPANY "\x02\x05" /**< id-mbedtls_md5 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) digestAlgorithm(2) 5 } */
  32563. #define MBEDTLS_OID_DIGEST_ALG_SHA1 MBEDTLS_OID_ISO_IDENTIFIED_ORG MBEDTLS_OID_OIW_SECSIG_SHA1 /**< id-mbedtls_sha1 OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) oiw(14) secsig(3) algorithms(2) 26 } */
  32564. #define MBEDTLS_OID_DIGEST_ALG_SHA224 MBEDTLS_OID_NIST_ALG "\x02\x04" /**< id-sha224 OBJECT IDENTIFIER ::= { joint-iso-itu-t(2) country(16) us(840) organization(1) gov(101) csor(3) nistalgorithm(4) hashalgs(2) 4 } */
  32565. #define MBEDTLS_OID_DIGEST_ALG_SHA256 MBEDTLS_OID_NIST_ALG "\x02\x01" /**< id-mbedtls_sha256 OBJECT IDENTIFIER ::= { joint-iso-itu-t(2) country(16) us(840) organization(1) gov(101) csor(3) nistalgorithm(4) hashalgs(2) 1 } */
  32566. #define MBEDTLS_OID_DIGEST_ALG_SHA384 MBEDTLS_OID_NIST_ALG "\x02\x02" /**< id-sha384 OBJECT IDENTIFIER ::= { joint-iso-itu-t(2) country(16) us(840) organization(1) gov(101) csor(3) nistalgorithm(4) hashalgs(2) 2 } */
  32567. #define MBEDTLS_OID_DIGEST_ALG_SHA512 MBEDTLS_OID_NIST_ALG "\x02\x03" /**< id-mbedtls_sha512 OBJECT IDENTIFIER ::= { joint-iso-itu-t(2) country(16) us(840) organization(1) gov(101) csor(3) nistalgorithm(4) hashalgs(2) 3 } */
  32568. #define MBEDTLS_OID_DIGEST_ALG_RIPEMD160 MBEDTLS_OID_TELETRUST "\x03\x02\x01" /**< id-ripemd160 OBJECT IDENTIFIER :: { iso(1) identified-organization(3) teletrust(36) algorithm(3) hashAlgorithm(2) ripemd160(1) } */
  32569. #define MBEDTLS_OID_HMAC_SHA1 MBEDTLS_OID_RSA_COMPANY "\x02\x07" /**< id-hmacWithSHA1 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) digestAlgorithm(2) 7 } */
  32570. #define MBEDTLS_OID_HMAC_SHA224 MBEDTLS_OID_RSA_COMPANY "\x02\x08" /**< id-hmacWithSHA224 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) digestAlgorithm(2) 8 } */
  32571. #define MBEDTLS_OID_HMAC_SHA256 MBEDTLS_OID_RSA_COMPANY "\x02\x09" /**< id-hmacWithSHA256 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) digestAlgorithm(2) 9 } */
  32572. #define MBEDTLS_OID_HMAC_SHA384 MBEDTLS_OID_RSA_COMPANY "\x02\x0A" /**< id-hmacWithSHA384 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) digestAlgorithm(2) 10 } */
  32573. #define MBEDTLS_OID_HMAC_SHA512 MBEDTLS_OID_RSA_COMPANY "\x02\x0B" /**< id-hmacWithSHA512 OBJECT IDENTIFIER ::= { iso(1) member-body(2) us(840) rsadsi(113549) digestAlgorithm(2) 11 } */
  32574. /*
  32575. * Encryption algorithms
  32576. */
  32577. #define MBEDTLS_OID_DES_CBC MBEDTLS_OID_ISO_IDENTIFIED_ORG MBEDTLS_OID_OIW_SECSIG_ALG "\x07" /**< desCBC OBJECT IDENTIFIER ::= { iso(1) identified-organization(3) oiw(14) secsig(3) algorithms(2) 7 } */
  32578. #define MBEDTLS_OID_DES_EDE3_CBC MBEDTLS_OID_RSA_COMPANY "\x03\x07" /**< des-ede3-cbc OBJECT IDENTIFIER ::= { iso(1) member-body(2) -- us(840) rsadsi(113549) encryptionAlgorithm(3) 7 } */
  32579. #define MBEDTLS_OID_AES MBEDTLS_OID_NIST_ALG "\x01" /** aes OBJECT IDENTIFIER ::= { joint-iso-itu-t(2) country(16) us(840) organization(1) gov(101) csor(3) nistAlgorithm(4) 1 } */
  32580. /*
  32581. * Key Wrapping algorithms
  32582. */
  32583. /*
  32584. * RFC 5649
  32585. */
  32586. #define MBEDTLS_OID_AES128_KW MBEDTLS_OID_AES "\x05" /** id-aes128-wrap OBJECT IDENTIFIER ::= { aes 5 } */
  32587. #define MBEDTLS_OID_AES128_KWP MBEDTLS_OID_AES "\x08" /** id-aes128-wrap-pad OBJECT IDENTIFIER ::= { aes 8 } */
  32588. #define MBEDTLS_OID_AES192_KW MBEDTLS_OID_AES "\x19" /** id-aes192-wrap OBJECT IDENTIFIER ::= { aes 25 } */
  32589. #define MBEDTLS_OID_AES192_KWP MBEDTLS_OID_AES "\x1c" /** id-aes192-wrap-pad OBJECT IDENTIFIER ::= { aes 28 } */
  32590. #define MBEDTLS_OID_AES256_KW MBEDTLS_OID_AES "\x2d" /** id-aes256-wrap OBJECT IDENTIFIER ::= { aes 45 } */
  32591. #define MBEDTLS_OID_AES256_KWP MBEDTLS_OID_AES "\x30" /** id-aes256-wrap-pad OBJECT IDENTIFIER ::= { aes 48 } */
  32592. /*
  32593. * PKCS#5 OIDs
  32594. */
  32595. #define MBEDTLS_OID_PKCS5_PBKDF2 MBEDTLS_OID_PKCS5 "\x0c" /**< id-PBKDF2 OBJECT IDENTIFIER ::= {pkcs-5 12} */
  32596. #define MBEDTLS_OID_PKCS5_PBES2 MBEDTLS_OID_PKCS5 "\x0d" /**< id-PBES2 OBJECT IDENTIFIER ::= {pkcs-5 13} */
  32597. #define MBEDTLS_OID_PKCS5_PBMAC1 MBEDTLS_OID_PKCS5 "\x0e" /**< id-PBMAC1 OBJECT IDENTIFIER ::= {pkcs-5 14} */
  32598. /*
  32599. * PKCS#5 PBES1 algorithms
  32600. */
  32601. #define MBEDTLS_OID_PKCS5_PBE_MD2_DES_CBC MBEDTLS_OID_PKCS5 "\x01" /**< pbeWithMD2AndDES-CBC OBJECT IDENTIFIER ::= {pkcs-5 1} */
  32602. #define MBEDTLS_OID_PKCS5_PBE_MD2_RC2_CBC MBEDTLS_OID_PKCS5 "\x04" /**< pbeWithMD2AndRC2-CBC OBJECT IDENTIFIER ::= {pkcs-5 4} */
  32603. #define MBEDTLS_OID_PKCS5_PBE_MD5_DES_CBC MBEDTLS_OID_PKCS5 "\x03" /**< pbeWithMD5AndDES-CBC OBJECT IDENTIFIER ::= {pkcs-5 3} */
  32604. #define MBEDTLS_OID_PKCS5_PBE_MD5_RC2_CBC MBEDTLS_OID_PKCS5 "\x06" /**< pbeWithMD5AndRC2-CBC OBJECT IDENTIFIER ::= {pkcs-5 6} */
  32605. #define MBEDTLS_OID_PKCS5_PBE_SHA1_DES_CBC MBEDTLS_OID_PKCS5 "\x0a" /**< pbeWithSHA1AndDES-CBC OBJECT IDENTIFIER ::= {pkcs-5 10} */
  32606. #define MBEDTLS_OID_PKCS5_PBE_SHA1_RC2_CBC MBEDTLS_OID_PKCS5 "\x0b" /**< pbeWithSHA1AndRC2-CBC OBJECT IDENTIFIER ::= {pkcs-5 11} */
  32607. /*
  32608. * PKCS#8 OIDs
  32609. */
  32610. #define MBEDTLS_OID_PKCS9_CSR_EXT_REQ MBEDTLS_OID_PKCS9 "\x0e" /**< extensionRequest OBJECT IDENTIFIER ::= {pkcs-9 14} */
  32611. /*
  32612. * PKCS#12 PBE OIDs
  32613. */
  32614. #define MBEDTLS_OID_PKCS12_PBE MBEDTLS_OID_PKCS12 "\x01" /**< pkcs-12PbeIds OBJECT IDENTIFIER ::= {pkcs-12 1} */
  32615. #define MBEDTLS_OID_PKCS12_PBE_SHA1_RC4_128 MBEDTLS_OID_PKCS12_PBE "\x01" /**< pbeWithSHAAnd128BitRC4 OBJECT IDENTIFIER ::= {pkcs-12PbeIds 1} */
  32616. #define MBEDTLS_OID_PKCS12_PBE_SHA1_RC4_40 MBEDTLS_OID_PKCS12_PBE "\x02" /**< pbeWithSHAAnd40BitRC4 OBJECT IDENTIFIER ::= {pkcs-12PbeIds 2} */
  32617. #define MBEDTLS_OID_PKCS12_PBE_SHA1_DES3_EDE_CBC MBEDTLS_OID_PKCS12_PBE "\x03" /**< pbeWithSHAAnd3-KeyTripleDES-CBC OBJECT IDENTIFIER ::= {pkcs-12PbeIds 3} */
  32618. #define MBEDTLS_OID_PKCS12_PBE_SHA1_DES2_EDE_CBC MBEDTLS_OID_PKCS12_PBE "\x04" /**< pbeWithSHAAnd2-KeyTripleDES-CBC OBJECT IDENTIFIER ::= {pkcs-12PbeIds 4} */
  32619. #define MBEDTLS_OID_PKCS12_PBE_SHA1_RC2_128_CBC MBEDTLS_OID_PKCS12_PBE "\x05" /**< pbeWithSHAAnd128BitRC2-CBC OBJECT IDENTIFIER ::= {pkcs-12PbeIds 5} */
  32620. #define MBEDTLS_OID_PKCS12_PBE_SHA1_RC2_40_CBC MBEDTLS_OID_PKCS12_PBE "\x06" /**< pbeWithSHAAnd40BitRC2-CBC OBJECT IDENTIFIER ::= {pkcs-12PbeIds 6} */
  32621. /*
  32622. * EC key algorithms from RFC 5480
  32623. */
  32624. /* id-ecPublicKey OBJECT IDENTIFIER ::= {
  32625. * iso(1) member-body(2) us(840) ansi-X9-62(10045) keyType(2) 1 } */
  32626. #define MBEDTLS_OID_EC_ALG_UNRESTRICTED MBEDTLS_OID_ANSI_X9_62 "\x02\01"
  32627. /* id-ecDH OBJECT IDENTIFIER ::= {
  32628. * iso(1) identified-organization(3) certicom(132)
  32629. * schemes(1) ecdh(12) } */
  32630. #define MBEDTLS_OID_EC_ALG_ECDH MBEDTLS_OID_CERTICOM "\x01\x0c"
  32631. /*
  32632. * ECParameters namedCurve identifiers, from RFC 5480, RFC 5639, and SEC2
  32633. */
  32634. /* secp192r1 OBJECT IDENTIFIER ::= {
  32635. * iso(1) member-body(2) us(840) ansi-X9-62(10045) curves(3) prime(1) 1 } */
  32636. #define MBEDTLS_OID_EC_GRP_SECP192R1 MBEDTLS_OID_ANSI_X9_62 "\x03\x01\x01"
  32637. /* secp224r1 OBJECT IDENTIFIER ::= {
  32638. * iso(1) identified-organization(3) certicom(132) curve(0) 33 } */
  32639. #define MBEDTLS_OID_EC_GRP_SECP224R1 MBEDTLS_OID_CERTICOM "\x00\x21"
  32640. /* secp256r1 OBJECT IDENTIFIER ::= {
  32641. * iso(1) member-body(2) us(840) ansi-X9-62(10045) curves(3) prime(1) 7 } */
  32642. #define MBEDTLS_OID_EC_GRP_SECP256R1 MBEDTLS_OID_ANSI_X9_62 "\x03\x01\x07"
  32643. /* secp384r1 OBJECT IDENTIFIER ::= {
  32644. * iso(1) identified-organization(3) certicom(132) curve(0) 34 } */
  32645. #define MBEDTLS_OID_EC_GRP_SECP384R1 MBEDTLS_OID_CERTICOM "\x00\x22"
  32646. /* secp521r1 OBJECT IDENTIFIER ::= {
  32647. * iso(1) identified-organization(3) certicom(132) curve(0) 35 } */
  32648. #define MBEDTLS_OID_EC_GRP_SECP521R1 MBEDTLS_OID_CERTICOM "\x00\x23"
  32649. /* secp192k1 OBJECT IDENTIFIER ::= {
  32650. * iso(1) identified-organization(3) certicom(132) curve(0) 31 } */
  32651. #define MBEDTLS_OID_EC_GRP_SECP192K1 MBEDTLS_OID_CERTICOM "\x00\x1f"
  32652. /* secp224k1 OBJECT IDENTIFIER ::= {
  32653. * iso(1) identified-organization(3) certicom(132) curve(0) 32 } */
  32654. #define MBEDTLS_OID_EC_GRP_SECP224K1 MBEDTLS_OID_CERTICOM "\x00\x20"
  32655. /* secp256k1 OBJECT IDENTIFIER ::= {
  32656. * iso(1) identified-organization(3) certicom(132) curve(0) 10 } */
  32657. #define MBEDTLS_OID_EC_GRP_SECP256K1 MBEDTLS_OID_CERTICOM "\x00\x0a"
  32658. /* RFC 5639 4.1
  32659. * ecStdCurvesAndGeneration OBJECT IDENTIFIER::= {iso(1)
  32660. * identified-organization(3) teletrust(36) algorithm(3) signature-
  32661. * algorithm(3) ecSign(2) 8}
  32662. * ellipticCurve OBJECT IDENTIFIER ::= {ecStdCurvesAndGeneration 1}
  32663. * versionOne OBJECT IDENTIFIER ::= {ellipticCurve 1} */
  32664. #define MBEDTLS_OID_EC_BRAINPOOL_V1 MBEDTLS_OID_TELETRUST "\x03\x03\x02\x08\x01\x01"
  32665. /* brainpoolP256r1 OBJECT IDENTIFIER ::= {versionOne 7} */
  32666. #define MBEDTLS_OID_EC_GRP_BP256R1 MBEDTLS_OID_EC_BRAINPOOL_V1 "\x07"
  32667. /* brainpoolP384r1 OBJECT IDENTIFIER ::= {versionOne 11} */
  32668. #define MBEDTLS_OID_EC_GRP_BP384R1 MBEDTLS_OID_EC_BRAINPOOL_V1 "\x0B"
  32669. /* brainpoolP512r1 OBJECT IDENTIFIER ::= {versionOne 13} */
  32670. #define MBEDTLS_OID_EC_GRP_BP512R1 MBEDTLS_OID_EC_BRAINPOOL_V1 "\x0D"
  32671. /*
  32672. * SEC1 C.1
  32673. *
  32674. * prime-field OBJECT IDENTIFIER ::= { id-fieldType 1 }
  32675. * id-fieldType OBJECT IDENTIFIER ::= { ansi-X9-62 fieldType(1)}
  32676. */
  32677. #define MBEDTLS_OID_ANSI_X9_62_FIELD_TYPE MBEDTLS_OID_ANSI_X9_62 "\x01"
  32678. #define MBEDTLS_OID_ANSI_X9_62_PRIME_FIELD MBEDTLS_OID_ANSI_X9_62_FIELD_TYPE "\x01"
  32679. /*
  32680. * ECDSA signature identifiers, from RFC 5480
  32681. */
  32682. #define MBEDTLS_OID_ANSI_X9_62_SIG MBEDTLS_OID_ANSI_X9_62 "\x04" /* signatures(4) */
  32683. #define MBEDTLS_OID_ANSI_X9_62_SIG_SHA2 MBEDTLS_OID_ANSI_X9_62_SIG "\x03" /* ecdsa-with-SHA2(3) */
  32684. /* ecdsa-with-SHA1 OBJECT IDENTIFIER ::= {
  32685. * iso(1) member-body(2) us(840) ansi-X9-62(10045) signatures(4) 1 } */
  32686. #define MBEDTLS_OID_ECDSA_SHA1 MBEDTLS_OID_ANSI_X9_62_SIG "\x01"
  32687. /* ecdsa-with-SHA224 OBJECT IDENTIFIER ::= {
  32688. * iso(1) member-body(2) us(840) ansi-X9-62(10045) signatures(4)
  32689. * ecdsa-with-SHA2(3) 1 } */
  32690. #define MBEDTLS_OID_ECDSA_SHA224 MBEDTLS_OID_ANSI_X9_62_SIG_SHA2 "\x01"
  32691. /* ecdsa-with-SHA256 OBJECT IDENTIFIER ::= {
  32692. * iso(1) member-body(2) us(840) ansi-X9-62(10045) signatures(4)
  32693. * ecdsa-with-SHA2(3) 2 } */
  32694. #define MBEDTLS_OID_ECDSA_SHA256 MBEDTLS_OID_ANSI_X9_62_SIG_SHA2 "\x02"
  32695. /* ecdsa-with-SHA384 OBJECT IDENTIFIER ::= {
  32696. * iso(1) member-body(2) us(840) ansi-X9-62(10045) signatures(4)
  32697. * ecdsa-with-SHA2(3) 3 } */
  32698. #define MBEDTLS_OID_ECDSA_SHA384 MBEDTLS_OID_ANSI_X9_62_SIG_SHA2 "\x03"
  32699. /* ecdsa-with-SHA512 OBJECT IDENTIFIER ::= {
  32700. * iso(1) member-body(2) us(840) ansi-X9-62(10045) signatures(4)
  32701. * ecdsa-with-SHA2(3) 4 } */
  32702. #define MBEDTLS_OID_ECDSA_SHA512 MBEDTLS_OID_ANSI_X9_62_SIG_SHA2 "\x04"
  32703. #ifdef __cplusplus
  32704. extern "C" {
  32705. #endif
  32706. /**
  32707. * \brief Base OID descriptor structure
  32708. */
  32709. typedef struct mbedtls_oid_descriptor_t
  32710. {
  32711. const char *asn1; /*!< OID ASN.1 representation */
  32712. size_t asn1_len; /*!< length of asn1 */
  32713. const char *name; /*!< official name (e.g. from RFC) */
  32714. const char *description; /*!< human friendly description */
  32715. } mbedtls_oid_descriptor_t;
  32716. /**
  32717. * \brief Translate an ASN.1 OID into its numeric representation
  32718. * (e.g. "\x2A\x86\x48\x86\xF7\x0D" into "1.2.840.113549")
  32719. *
  32720. * \param buf buffer to put representation in
  32721. * \param size size of the buffer
  32722. * \param oid OID to translate
  32723. *
  32724. * \return Length of the string written (excluding final NULL) or
  32725. * MBEDTLS_ERR_OID_BUF_TOO_SMALL in case of error
  32726. */
  32727. int mbedtls_oid_get_numeric_string( char *buf, size_t size, const mbedtls_asn1_buf *oid );
  32728. /**
  32729. * \brief Translate an X.509 extension OID into local values
  32730. *
  32731. * \param oid OID to use
  32732. * \param ext_type place to store the extension type
  32733. *
  32734. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32735. */
  32736. int mbedtls_oid_get_x509_ext_type( const mbedtls_asn1_buf *oid, int *ext_type );
  32737. /**
  32738. * \brief Translate an X.509 attribute type OID into the short name
  32739. * (e.g. the OID for an X520 Common Name into "CN")
  32740. *
  32741. * \param oid OID to use
  32742. * \param short_name place to store the string pointer
  32743. *
  32744. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32745. */
  32746. int mbedtls_oid_get_attr_short_name( const mbedtls_asn1_buf *oid, const char **short_name );
  32747. /**
  32748. * \brief Translate PublicKeyAlgorithm OID into pk_type
  32749. *
  32750. * \param oid OID to use
  32751. * \param pk_alg place to store public key algorithm
  32752. *
  32753. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32754. */
  32755. int mbedtls_oid_get_pk_alg( const mbedtls_asn1_buf *oid, mbedtls_pk_type_t *pk_alg );
  32756. /**
  32757. * \brief Translate pk_type into PublicKeyAlgorithm OID
  32758. *
  32759. * \param pk_alg Public key type to look for
  32760. * \param oid place to store ASN.1 OID string pointer
  32761. * \param olen length of the OID
  32762. *
  32763. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32764. */
  32765. int mbedtls_oid_get_oid_by_pk_alg( mbedtls_pk_type_t pk_alg,
  32766. const char **oid, size_t *olen );
  32767. #if defined(MBEDTLS_ECP_C)
  32768. /**
  32769. * \brief Translate NamedCurve OID into an EC group identifier
  32770. *
  32771. * \param oid OID to use
  32772. * \param grp_id place to store group id
  32773. *
  32774. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32775. */
  32776. int mbedtls_oid_get_ec_grp( const mbedtls_asn1_buf *oid, mbedtls_ecp_group_id *grp_id );
  32777. /**
  32778. * \brief Translate EC group identifier into NamedCurve OID
  32779. *
  32780. * \param grp_id EC group identifier
  32781. * \param oid place to store ASN.1 OID string pointer
  32782. * \param olen length of the OID
  32783. *
  32784. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32785. */
  32786. int mbedtls_oid_get_oid_by_ec_grp( mbedtls_ecp_group_id grp_id,
  32787. const char **oid, size_t *olen );
  32788. #endif /* MBEDTLS_ECP_C */
  32789. #if defined(MBEDTLS_MD_C)
  32790. /**
  32791. * \brief Translate SignatureAlgorithm OID into md_type and pk_type
  32792. *
  32793. * \param oid OID to use
  32794. * \param md_alg place to store message digest algorithm
  32795. * \param pk_alg place to store public key algorithm
  32796. *
  32797. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32798. */
  32799. int mbedtls_oid_get_sig_alg( const mbedtls_asn1_buf *oid,
  32800. mbedtls_md_type_t *md_alg, mbedtls_pk_type_t *pk_alg );
  32801. /**
  32802. * \brief Translate SignatureAlgorithm OID into description
  32803. *
  32804. * \param oid OID to use
  32805. * \param desc place to store string pointer
  32806. *
  32807. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32808. */
  32809. int mbedtls_oid_get_sig_alg_desc( const mbedtls_asn1_buf *oid, const char **desc );
  32810. /**
  32811. * \brief Translate md_type and pk_type into SignatureAlgorithm OID
  32812. *
  32813. * \param md_alg message digest algorithm
  32814. * \param pk_alg public key algorithm
  32815. * \param oid place to store ASN.1 OID string pointer
  32816. * \param olen length of the OID
  32817. *
  32818. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32819. */
  32820. int mbedtls_oid_get_oid_by_sig_alg( mbedtls_pk_type_t pk_alg, mbedtls_md_type_t md_alg,
  32821. const char **oid, size_t *olen );
  32822. /**
  32823. * \brief Translate hash algorithm OID into md_type
  32824. *
  32825. * \param oid OID to use
  32826. * \param md_alg place to store message digest algorithm
  32827. *
  32828. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32829. */
  32830. int mbedtls_oid_get_md_alg( const mbedtls_asn1_buf *oid, mbedtls_md_type_t *md_alg );
  32831. /**
  32832. * \brief Translate hmac algorithm OID into md_type
  32833. *
  32834. * \param oid OID to use
  32835. * \param md_hmac place to store message hmac algorithm
  32836. *
  32837. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32838. */
  32839. int mbedtls_oid_get_md_hmac( const mbedtls_asn1_buf *oid, mbedtls_md_type_t *md_hmac );
  32840. #endif /* MBEDTLS_MD_C */
  32841. /**
  32842. * \brief Translate Extended Key Usage OID into description
  32843. *
  32844. * \param oid OID to use
  32845. * \param desc place to store string pointer
  32846. *
  32847. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32848. */
  32849. int mbedtls_oid_get_extended_key_usage( const mbedtls_asn1_buf *oid, const char **desc );
  32850. /**
  32851. * \brief Translate certificate policies OID into description
  32852. *
  32853. * \param oid OID to use
  32854. * \param desc place to store string pointer
  32855. *
  32856. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32857. */
  32858. int mbedtls_oid_get_certificate_policies( const mbedtls_asn1_buf *oid, const char **desc );
  32859. /**
  32860. * \brief Translate md_type into hash algorithm OID
  32861. *
  32862. * \param md_alg message digest algorithm
  32863. * \param oid place to store ASN.1 OID string pointer
  32864. * \param olen length of the OID
  32865. *
  32866. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32867. */
  32868. int mbedtls_oid_get_oid_by_md( mbedtls_md_type_t md_alg, const char **oid, size_t *olen );
  32869. #if defined(MBEDTLS_CIPHER_C)
  32870. /**
  32871. * \brief Translate encryption algorithm OID into cipher_type
  32872. *
  32873. * \param oid OID to use
  32874. * \param cipher_alg place to store cipher algorithm
  32875. *
  32876. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32877. */
  32878. int mbedtls_oid_get_cipher_alg( const mbedtls_asn1_buf *oid, mbedtls_cipher_type_t *cipher_alg );
  32879. #endif /* MBEDTLS_CIPHER_C */
  32880. #if defined(MBEDTLS_PKCS12_C)
  32881. /**
  32882. * \brief Translate PKCS#12 PBE algorithm OID into md_type and
  32883. * cipher_type
  32884. *
  32885. * \param oid OID to use
  32886. * \param md_alg place to store message digest algorithm
  32887. * \param cipher_alg place to store cipher algorithm
  32888. *
  32889. * \return 0 if successful, or MBEDTLS_ERR_OID_NOT_FOUND
  32890. */
  32891. int mbedtls_oid_get_pkcs12_pbe_alg( const mbedtls_asn1_buf *oid, mbedtls_md_type_t *md_alg,
  32892. mbedtls_cipher_type_t *cipher_alg );
  32893. #endif /* MBEDTLS_PKCS12_C */
  32894. #ifdef __cplusplus
  32895. }
  32896. #endif
  32897. #endif /* oid.h */
  32898. /********* Start of file include/mbedtls/ripemd160.h ************/
  32899. /**
  32900. * \file ripemd160.h
  32901. *
  32902. * \brief RIPE MD-160 message digest
  32903. */
  32904. /*
  32905. * Copyright The Mbed TLS Contributors
  32906. * SPDX-License-Identifier: Apache-2.0
  32907. *
  32908. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  32909. * not use this file except in compliance with the License.
  32910. * You may obtain a copy of the License at
  32911. *
  32912. * http://www.apache.org/licenses/LICENSE-2.0
  32913. *
  32914. * Unless required by applicable law or agreed to in writing, software
  32915. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  32916. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  32917. * See the License for the specific language governing permissions and
  32918. * limitations under the License.
  32919. */
  32920. #ifndef MBEDTLS_RIPEMD160_H
  32921. #define MBEDTLS_RIPEMD160_H
  32922. #if !defined(MBEDTLS_CONFIG_FILE)
  32923. #else
  32924. #endif
  32925. #include <stddef.h>
  32926. #include <stdint.h>
  32927. /* MBEDTLS_ERR_RIPEMD160_HW_ACCEL_FAILED is deprecated and should not be used.
  32928. */
  32929. /** RIPEMD160 hardware accelerator failed */
  32930. #define MBEDTLS_ERR_RIPEMD160_HW_ACCEL_FAILED -0x0031
  32931. #ifdef __cplusplus
  32932. extern "C" {
  32933. #endif
  32934. #if !defined(MBEDTLS_RIPEMD160_ALT)
  32935. // Regular implementation
  32936. //
  32937. /**
  32938. * \brief RIPEMD-160 context structure
  32939. */
  32940. typedef struct mbedtls_ripemd160_context
  32941. {
  32942. uint32_t total[2]; /*!< number of bytes processed */
  32943. uint32_t state[5]; /*!< intermediate digest state */
  32944. unsigned char buffer[64]; /*!< data block being processed */
  32945. }
  32946. mbedtls_ripemd160_context;
  32947. #else /* MBEDTLS_RIPEMD160_ALT */
  32948. #endif /* MBEDTLS_RIPEMD160_ALT */
  32949. /**
  32950. * \brief Initialize RIPEMD-160 context
  32951. *
  32952. * \param ctx RIPEMD-160 context to be initialized
  32953. */
  32954. void mbedtls_ripemd160_init( mbedtls_ripemd160_context *ctx );
  32955. /**
  32956. * \brief Clear RIPEMD-160 context
  32957. *
  32958. * \param ctx RIPEMD-160 context to be cleared
  32959. */
  32960. void mbedtls_ripemd160_free( mbedtls_ripemd160_context *ctx );
  32961. /**
  32962. * \brief Clone (the state of) an RIPEMD-160 context
  32963. *
  32964. * \param dst The destination context
  32965. * \param src The context to be cloned
  32966. */
  32967. void mbedtls_ripemd160_clone( mbedtls_ripemd160_context *dst,
  32968. const mbedtls_ripemd160_context *src );
  32969. /**
  32970. * \brief RIPEMD-160 context setup
  32971. *
  32972. * \param ctx context to be initialized
  32973. *
  32974. * \return 0 if successful
  32975. */
  32976. int mbedtls_ripemd160_starts_ret( mbedtls_ripemd160_context *ctx );
  32977. /**
  32978. * \brief RIPEMD-160 process buffer
  32979. *
  32980. * \param ctx RIPEMD-160 context
  32981. * \param input buffer holding the data
  32982. * \param ilen length of the input data
  32983. *
  32984. * \return 0 if successful
  32985. */
  32986. int mbedtls_ripemd160_update_ret( mbedtls_ripemd160_context *ctx,
  32987. const unsigned char *input,
  32988. size_t ilen );
  32989. /**
  32990. * \brief RIPEMD-160 final digest
  32991. *
  32992. * \param ctx RIPEMD-160 context
  32993. * \param output RIPEMD-160 checksum result
  32994. *
  32995. * \return 0 if successful
  32996. */
  32997. int mbedtls_ripemd160_finish_ret( mbedtls_ripemd160_context *ctx,
  32998. unsigned char output[20] );
  32999. /**
  33000. * \brief RIPEMD-160 process data block (internal use only)
  33001. *
  33002. * \param ctx RIPEMD-160 context
  33003. * \param data buffer holding one block of data
  33004. *
  33005. * \return 0 if successful
  33006. */
  33007. int mbedtls_internal_ripemd160_process( mbedtls_ripemd160_context *ctx,
  33008. const unsigned char data[64] );
  33009. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  33010. #if defined(MBEDTLS_DEPRECATED_WARNING)
  33011. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  33012. #else
  33013. #define MBEDTLS_DEPRECATED
  33014. #endif
  33015. /**
  33016. * \brief RIPEMD-160 context setup
  33017. *
  33018. * \deprecated Superseded by mbedtls_ripemd160_starts_ret() in 2.7.0
  33019. *
  33020. * \param ctx context to be initialized
  33021. */
  33022. MBEDTLS_DEPRECATED void mbedtls_ripemd160_starts(
  33023. mbedtls_ripemd160_context *ctx );
  33024. /**
  33025. * \brief RIPEMD-160 process buffer
  33026. *
  33027. * \deprecated Superseded by mbedtls_ripemd160_update_ret() in 2.7.0
  33028. *
  33029. * \param ctx RIPEMD-160 context
  33030. * \param input buffer holding the data
  33031. * \param ilen length of the input data
  33032. */
  33033. MBEDTLS_DEPRECATED void mbedtls_ripemd160_update(
  33034. mbedtls_ripemd160_context *ctx,
  33035. const unsigned char *input,
  33036. size_t ilen );
  33037. /**
  33038. * \brief RIPEMD-160 final digest
  33039. *
  33040. * \deprecated Superseded by mbedtls_ripemd160_finish_ret() in 2.7.0
  33041. *
  33042. * \param ctx RIPEMD-160 context
  33043. * \param output RIPEMD-160 checksum result
  33044. */
  33045. MBEDTLS_DEPRECATED void mbedtls_ripemd160_finish(
  33046. mbedtls_ripemd160_context *ctx,
  33047. unsigned char output[20] );
  33048. /**
  33049. * \brief RIPEMD-160 process data block (internal use only)
  33050. *
  33051. * \deprecated Superseded by mbedtls_internal_ripemd160_process() in 2.7.0
  33052. *
  33053. * \param ctx RIPEMD-160 context
  33054. * \param data buffer holding one block of data
  33055. */
  33056. MBEDTLS_DEPRECATED void mbedtls_ripemd160_process(
  33057. mbedtls_ripemd160_context *ctx,
  33058. const unsigned char data[64] );
  33059. #undef MBEDTLS_DEPRECATED
  33060. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  33061. /**
  33062. * \brief Output = RIPEMD-160( input buffer )
  33063. *
  33064. * \param input buffer holding the data
  33065. * \param ilen length of the input data
  33066. * \param output RIPEMD-160 checksum result
  33067. *
  33068. * \return 0 if successful
  33069. */
  33070. int mbedtls_ripemd160_ret( const unsigned char *input,
  33071. size_t ilen,
  33072. unsigned char output[20] );
  33073. #if !defined(MBEDTLS_DEPRECATED_REMOVED)
  33074. #if defined(MBEDTLS_DEPRECATED_WARNING)
  33075. #define MBEDTLS_DEPRECATED __attribute__((deprecated))
  33076. #else
  33077. #define MBEDTLS_DEPRECATED
  33078. #endif
  33079. /**
  33080. * \brief Output = RIPEMD-160( input buffer )
  33081. *
  33082. * \deprecated Superseded by mbedtls_ripemd160_ret() in 2.7.0
  33083. *
  33084. * \param input buffer holding the data
  33085. * \param ilen length of the input data
  33086. * \param output RIPEMD-160 checksum result
  33087. */
  33088. MBEDTLS_DEPRECATED void mbedtls_ripemd160( const unsigned char *input,
  33089. size_t ilen,
  33090. unsigned char output[20] );
  33091. #undef MBEDTLS_DEPRECATED
  33092. #endif /* !MBEDTLS_DEPRECATED_REMOVED */
  33093. #if defined(MBEDTLS_SELF_TEST)
  33094. /**
  33095. * \brief Checkup routine
  33096. *
  33097. * \return 0 if successful, or 1 if the test failed
  33098. */
  33099. int mbedtls_ripemd160_self_test( int verbose );
  33100. #endif /* MBEDTLS_SELF_TEST */
  33101. #ifdef __cplusplus
  33102. }
  33103. #endif
  33104. #endif /* mbedtls_ripemd160.h */
  33105. /********* Start of file include/mbedtls/hkdf.h ************/
  33106. /**
  33107. * \file hkdf.h
  33108. *
  33109. * \brief This file contains the HKDF interface.
  33110. *
  33111. * The HMAC-based Extract-and-Expand Key Derivation Function (HKDF) is
  33112. * specified by RFC 5869.
  33113. */
  33114. /*
  33115. * Copyright The Mbed TLS Contributors
  33116. * SPDX-License-Identifier: Apache-2.0
  33117. *
  33118. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  33119. * not use this file except in compliance with the License.
  33120. * You may obtain a copy of the License at
  33121. *
  33122. * http://www.apache.org/licenses/LICENSE-2.0
  33123. *
  33124. * Unless required by applicable law or agreed to in writing, software
  33125. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  33126. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  33127. * See the License for the specific language governing permissions and
  33128. * limitations under the License.
  33129. */
  33130. #ifndef MBEDTLS_HKDF_H
  33131. #define MBEDTLS_HKDF_H
  33132. #if !defined(MBEDTLS_CONFIG_FILE)
  33133. #else
  33134. #endif
  33135. /**
  33136. * \name HKDF Error codes
  33137. * \{
  33138. */
  33139. /** Bad input parameters to function. */
  33140. #define MBEDTLS_ERR_HKDF_BAD_INPUT_DATA -0x5F80
  33141. /* \} name */
  33142. #ifdef __cplusplus
  33143. extern "C" {
  33144. #endif
  33145. /**
  33146. * \brief This is the HMAC-based Extract-and-Expand Key Derivation Function
  33147. * (HKDF).
  33148. *
  33149. * \param md A hash function; md.size denotes the length of the hash
  33150. * function output in bytes.
  33151. * \param salt An optional salt value (a non-secret random value);
  33152. * if the salt is not provided, a string of all zeros of
  33153. * md.size length is used as the salt.
  33154. * \param salt_len The length in bytes of the optional \p salt.
  33155. * \param ikm The input keying material.
  33156. * \param ikm_len The length in bytes of \p ikm.
  33157. * \param info An optional context and application specific information
  33158. * string. This can be a zero-length string.
  33159. * \param info_len The length of \p info in bytes.
  33160. * \param okm The output keying material of \p okm_len bytes.
  33161. * \param okm_len The length of the output keying material in bytes. This
  33162. * must be less than or equal to 255 * md.size bytes.
  33163. *
  33164. * \return 0 on success.
  33165. * \return #MBEDTLS_ERR_HKDF_BAD_INPUT_DATA when the parameters are invalid.
  33166. * \return An MBEDTLS_ERR_MD_* error for errors returned from the underlying
  33167. * MD layer.
  33168. */
  33169. int mbedtls_hkdf( const mbedtls_md_info_t *md, const unsigned char *salt,
  33170. size_t salt_len, const unsigned char *ikm, size_t ikm_len,
  33171. const unsigned char *info, size_t info_len,
  33172. unsigned char *okm, size_t okm_len );
  33173. /**
  33174. * \brief Take the input keying material \p ikm and extract from it a
  33175. * fixed-length pseudorandom key \p prk.
  33176. *
  33177. * \warning This function should only be used if the security of it has been
  33178. * studied and established in that particular context (eg. TLS 1.3
  33179. * key schedule). For standard HKDF security guarantees use
  33180. * \c mbedtls_hkdf instead.
  33181. *
  33182. * \param md A hash function; md.size denotes the length of the
  33183. * hash function output in bytes.
  33184. * \param salt An optional salt value (a non-secret random value);
  33185. * if the salt is not provided, a string of all zeros
  33186. * of md.size length is used as the salt.
  33187. * \param salt_len The length in bytes of the optional \p salt.
  33188. * \param ikm The input keying material.
  33189. * \param ikm_len The length in bytes of \p ikm.
  33190. * \param[out] prk A pseudorandom key of at least md.size bytes.
  33191. *
  33192. * \return 0 on success.
  33193. * \return #MBEDTLS_ERR_HKDF_BAD_INPUT_DATA when the parameters are invalid.
  33194. * \return An MBEDTLS_ERR_MD_* error for errors returned from the underlying
  33195. * MD layer.
  33196. */
  33197. int mbedtls_hkdf_extract( const mbedtls_md_info_t *md,
  33198. const unsigned char *salt, size_t salt_len,
  33199. const unsigned char *ikm, size_t ikm_len,
  33200. unsigned char *prk );
  33201. /**
  33202. * \brief Expand the supplied \p prk into several additional pseudorandom
  33203. * keys, which is the output of the HKDF.
  33204. *
  33205. * \warning This function should only be used if the security of it has been
  33206. * studied and established in that particular context (eg. TLS 1.3
  33207. * key schedule). For standard HKDF security guarantees use
  33208. * \c mbedtls_hkdf instead.
  33209. *
  33210. * \param md A hash function; md.size denotes the length of the hash
  33211. * function output in bytes.
  33212. * \param prk A pseudorandom key of at least md.size bytes. \p prk is
  33213. * usually the output from the HKDF extract step.
  33214. * \param prk_len The length in bytes of \p prk.
  33215. * \param info An optional context and application specific information
  33216. * string. This can be a zero-length string.
  33217. * \param info_len The length of \p info in bytes.
  33218. * \param okm The output keying material of \p okm_len bytes.
  33219. * \param okm_len The length of the output keying material in bytes. This
  33220. * must be less than or equal to 255 * md.size bytes.
  33221. *
  33222. * \return 0 on success.
  33223. * \return #MBEDTLS_ERR_HKDF_BAD_INPUT_DATA when the parameters are invalid.
  33224. * \return An MBEDTLS_ERR_MD_* error for errors returned from the underlying
  33225. * MD layer.
  33226. */
  33227. int mbedtls_hkdf_expand( const mbedtls_md_info_t *md, const unsigned char *prk,
  33228. size_t prk_len, const unsigned char *info,
  33229. size_t info_len, unsigned char *okm, size_t okm_len );
  33230. #ifdef __cplusplus
  33231. }
  33232. #endif
  33233. #endif /* hkdf.h */
  33234. /********* Start of file include/mbedtls/version.h ************/
  33235. /**
  33236. * \file version.h
  33237. *
  33238. * \brief Run-time version information
  33239. */
  33240. /*
  33241. * Copyright The Mbed TLS Contributors
  33242. * SPDX-License-Identifier: Apache-2.0
  33243. *
  33244. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  33245. * not use this file except in compliance with the License.
  33246. * You may obtain a copy of the License at
  33247. *
  33248. * http://www.apache.org/licenses/LICENSE-2.0
  33249. *
  33250. * Unless required by applicable law or agreed to in writing, software
  33251. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  33252. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  33253. * See the License for the specific language governing permissions and
  33254. * limitations under the License.
  33255. */
  33256. /*
  33257. * This set of compile-time defines and run-time variables can be used to
  33258. * determine the version number of the mbed TLS library used.
  33259. */
  33260. #ifndef MBEDTLS_VERSION_H
  33261. #define MBEDTLS_VERSION_H
  33262. #if !defined(MBEDTLS_CONFIG_FILE)
  33263. #else
  33264. #endif
  33265. /**
  33266. * The version number x.y.z is split into three parts.
  33267. * Major, Minor, Patchlevel
  33268. */
  33269. #define MBEDTLS_VERSION_MAJOR 2
  33270. #define MBEDTLS_VERSION_MINOR 28
  33271. #define MBEDTLS_VERSION_PATCH 0
  33272. /**
  33273. * The single version number has the following structure:
  33274. * MMNNPP00
  33275. * Major version | Minor version | Patch version
  33276. */
  33277. #define MBEDTLS_VERSION_NUMBER 0x021C0000
  33278. #define MBEDTLS_VERSION_STRING "2.28.0"
  33279. #define MBEDTLS_VERSION_STRING_FULL "mbed TLS 2.28.0"
  33280. #if defined(MBEDTLS_VERSION_C)
  33281. #ifdef __cplusplus
  33282. extern "C" {
  33283. #endif
  33284. /**
  33285. * Get the version number.
  33286. *
  33287. * \return The constructed version number in the format
  33288. * MMNNPP00 (Major, Minor, Patch).
  33289. */
  33290. unsigned int mbedtls_version_get_number( void );
  33291. /**
  33292. * Get the version string ("x.y.z").
  33293. *
  33294. * \param string The string that will receive the value.
  33295. * (Should be at least 9 bytes in size)
  33296. */
  33297. void mbedtls_version_get_string( char *string );
  33298. /**
  33299. * Get the full version string ("mbed TLS x.y.z").
  33300. *
  33301. * \param string The string that will receive the value. The mbed TLS version
  33302. * string will use 18 bytes AT MOST including a terminating
  33303. * null byte.
  33304. * (So the buffer should be at least 18 bytes to receive this
  33305. * version string).
  33306. */
  33307. void mbedtls_version_get_string_full( char *string );
  33308. /**
  33309. * \brief Check if support for a feature was compiled into this
  33310. * mbed TLS binary. This allows you to see at runtime if the
  33311. * library was for instance compiled with or without
  33312. * Multi-threading support.
  33313. *
  33314. * \note only checks against defines in the sections "System
  33315. * support", "mbed TLS modules" and "mbed TLS feature
  33316. * support" in config.h
  33317. *
  33318. * \param feature The string for the define to check (e.g. "MBEDTLS_AES_C")
  33319. *
  33320. * \return 0 if the feature is present,
  33321. * -1 if the feature is not present and
  33322. * -2 if support for feature checking as a whole was not
  33323. * compiled in.
  33324. */
  33325. int mbedtls_version_check_feature( const char *feature );
  33326. #ifdef __cplusplus
  33327. }
  33328. #endif
  33329. #endif /* MBEDTLS_VERSION_C */
  33330. #endif /* version.h */
  33331. #endif /* ME_COM_MBEDTLS */