Compare commits
46
Commits
1f0a65b72a
...
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
da20efd1ee | ||
|
|
9415e29441
|
||
|
|
d25e5ef537
|
||
|
|
abb9401c34
|
||
|
|
3ea9038acb
|
||
|
|
076468ca4a
|
||
|
|
3495b70412
|
||
|
|
2c19ec2ec7 | ||
|
|
acdbe31456 | ||
|
|
e3bd4a833f
|
||
|
|
95e30192f0
|
||
|
|
36464cea00
|
||
|
|
3816667720
|
||
|
|
6889043035
|
||
|
|
e76cdf9b20 | ||
|
|
7bde14612b | ||
|
|
90c03d280a
|
||
|
|
ece2c60b3f
|
||
|
|
0e64ff0bd8
|
||
|
|
777dd976b1
|
||
|
|
c4a1577ba3
|
||
|
|
9f3181c9cf | ||
|
|
2523b97d0e | ||
|
|
716bfaab47
|
||
|
|
5b12c8c524
|
||
|
|
b842b7a80d
|
||
|
|
fe74be9b86
|
||
|
|
bdb1946ba9
|
||
|
|
0be1005050 | ||
|
|
0c8fc308e4
|
||
|
|
006a0d3590 | ||
|
|
740a88a76f
|
||
|
|
5a0228c942
|
||
|
|
9fe32abaee
|
||
|
|
699b65b844
|
||
|
|
3908119bcf
|
||
|
|
1161c69f16
|
||
|
|
5d35e1d54f
|
||
|
|
1b2097f40e
|
||
|
|
ca1b2c5829
|
||
|
|
fc97123fd6
|
||
|
|
5afa2a3e6c
|
||
|
|
89c8eedc85
|
||
|
|
2a6d9226d4
|
||
|
|
f9e90d2843
|
||
|
|
9f21151c15
|
@@ -9,12 +9,14 @@
|
||||
- [HPACK Patch](https://github.com/cloudflare/sslconfig/blob/master/patches/nginx_1.13.1_http2_hpack.patch) by [Cloudflare](https://github.com/cloudflare/sslconfig)
|
||||
- [nginx Strict-SNI Patch](https://github.com/hakasenyang/openssl-patch/issues/1#issuecomment-421551872) by [@JemmyLoveJenny](https://github.com/JemmyLoveJenny)
|
||||
- [OpenSSL OLD-CHACHA20-POLY1305](https://github.com/JemmyLoveJenny/ngx_ossl_patches) by [@JemmyLoveJenny](https://github.com/JemmyLoveJenny)
|
||||
- [OpenSSL 1.1.1c PrioritizeChacha Patch](https://github.com/hakasenyang/openssl-patch/pull/17) by [@felixbuenemann](https://github.com/felixbuenemann)
|
||||
- [nginx io_uring support Patch](https://github.com/hakasenyang/openssl-patch/pull/22) by [@CarterLi](https://github.com/CarterLi)
|
||||
|
||||
## Information
|
||||
|
||||
- [Test Page - (TLS 1.3 final)](https://ssl.hakase.io/)
|
||||
- [SSL Test Result - testssl.sh](https://ssl.hakase.io/ssltest/hakase.io.html)
|
||||
- [SSL Test Result - dev.ssllabs.com](https://dev.ssllabs.com/ssltest/analyze.html?d=hakase.io)
|
||||
- [Test Page - (TLS 1.3 final)](https://ssl.haka.se/)
|
||||
- [SSL Test Result - testssl.sh](https://ssl.haka.se/ssltest/haka.se.html)
|
||||
- [SSL Test Result - dev.ssllabs.com](https://dev.ssllabs.com/ssltest/analyze.html?d=haka.se)
|
||||
- **If you link site to a browser that supports final, you'll see a TLS 1.3 message.**
|
||||
|
||||
Displays TLSv1.3 support for large sites.
|
||||
@@ -23,13 +25,15 @@ Default support is in bold type.
|
||||
- [Baidu(China)](https://baidu.cn/) : **TLSv1.2**
|
||||
- [Naver(Korea)](https://naver.com/) : **TLSv1.2**
|
||||
- [Twitter](https://twitter.com/) : **TLSv1.2**
|
||||
- [**My Site**](https://hakase.io/) : _TLSv1.3_ **final**
|
||||
- [**My Site**](https://haka.se/) : _TLSv1.3_ **final**
|
||||
- [Facebook](https://facebook.com/) : _TLSv1.3_ draft 23, 26, 28, **final**
|
||||
- [Cloudflare](https://cloudflare.com/) : _TLSv1.3_ **final**
|
||||
- [Google(Gmail)](https://gmail.com/) : _TLSv1.3_ **final**
|
||||
- [NSS TLS 1.3(Mozilla)](https://tls13.crypto.mozilla.org/) : _TLSv1.3_ **final**
|
||||
|
||||
[Compatible OpenSSL-3.0.0-dev (OpenSSL, 23431 commits)](https://github.com/openssl/openssl/tree/4089b4340701e3c13e07169e67a7d14519c98658)
|
||||
[Compatible OpenSSL-3.0.0-dev (OpenSSL, 25375 commits)](https://github.com/openssl/openssl/tree/7fa8bcfe4342df41919f5564b315f9c85d0a02d6)
|
||||
|
||||
[Compatible OpenSSL-3.0.0-dev-**revert** (OpenSSL, 25746 commits)](https://github.com/openssl/openssl/tree/3cb55fe47c3398b81956e4fe20c4004524d47519)
|
||||
|
||||
## Patch files
|
||||
|
||||
@@ -43,12 +47,16 @@ Here is the basic patch content.
|
||||
|
||||
| Patch file name | Patch list |
|
||||
| :--- | :--- |
|
||||
| openssl-equal-1.1.1a.patch<br>openssl-equal-3.0.0-dev.patch | Support **final (TLS 1.3)**, TLS 1.3 cipher settings **_can not_** be changed on _nginx_. |
|
||||
| openssl-equal-1.1.1a_ciphers.patch<br>openssl-equal-3.0.0-dev_ciphers.patch | Support **final (TLS 1.3)**, TLS 1.3 cipher settings **_can_** be changed on _nginx_. |
|
||||
| openssl-1.1.1a-chacha_draft.patch<br>openssl-3.0.0-dev-chacha_draft.patch | A draft version of chacha20-poly1305 is available. [View issue](https://github.com/hakasenyang/openssl-patch/issues/1#issuecomment-427554824) |
|
||||
| openssl-equal-1.1.1(x).patch<br>openssl-equal-3.0.0-dev.patch | Support **final (TLS 1.3)**, TLS 1.3 cipher settings **_can not_** be changed on _nginx_. |
|
||||
| openssl-equal-1.1.1(x)_ciphers.patch<br>openssl-equal-3.0.0-dev_ciphers.patch | Support **final (TLS 1.3)**, TLS 1.3 cipher settings **_can_** be changed on _nginx_. |
|
||||
| openssl-1.1.1(x)-chacha_draft.patch<br>openssl-3.0.0-dev-chacha_draft.patch | A draft version of chacha20-poly1305 is available. [View issue](https://github.com/hakasenyang/openssl-patch/issues/1#issuecomment-427554824) |
|
||||
| openssl-1.1.1a-tls13_draft.patch | Only for **TLS 1.3 draft 23, 26, 28, final support patch**. |
|
||||
| openssl-1.1.1a-tls13_nginx_config.patch | You can set TLS 1.3 ciphere in nginx. ex) TLS13+AESGCM+AES128 |
|
||||
| openssl-1.1.1c-prioritize_chacha_draft.patch | Priority applied patch for CHACHA20 and CHACHA20-DRAFT. [View Pull Request](https://github.com/hakasenyang/openssl-patch/pull/17) |
|
||||
| openssl-3.0.0-session_tls13.patch | For TLS 1.2 and below, the existing session timeout value is written. For TLS 1.3, 172800 (2 days) is fixed. |
|
||||
| openssl-3.0.0-dev_version_error.patch | **TEST** This is a way to fix nginx when the following errors occur during the build:<br>Error: missing binary operator before token "("<br>Maybe patched: [https://github.com/openssl/openssl/pull/7839](https://github.com/openssl/openssl/pull/7839)<br>Patched : [https://github.com/openssl/openssl/commit/5d609f22d28615c45685d9da871d432e9cb81127](https://github.com/openssl/openssl/commit/5d609f22d28615c45685d9da871d432e9cb81127) |
|
||||
| openssl-3.0.0-dev_revert.patch | **TEST** This file will revert the patch to use the old OpenSSL API. (This is an unsafe temporary measure.) |
|
||||
| openssl-3.0.0-dev-chacha_draft_revert.patch<br>openssl-equal-3.0.0-dev_ciphers_revert.patch<br>openssl-equal-3.0.0-dev_revert.patch | **TEST** These patches should be used after patching the **openssl-3.0.0-dev_revert.patch** file **first.** |
|
||||
|
||||
**The "_ciphers" patch file is a temporary change to the TLS 1.3 configuration.**
|
||||
|
||||
@@ -70,6 +78,8 @@ Example of setting TLS 1.3 cipher in nginx:
|
||||
| nginx_hpack_remove_server_header_1.15.3.patch | HPACK + Remove nginx server header. (http2, http1.1) |
|
||||
| nginx_strict-sni.patch | Enable **Strict-SNI**. Thanks [@JemmyLoveJenny](https://github.com/JemmyLoveJenny). [View issue](https://github.com/hakasenyang/openssl-patch/issues/1#issuecomment-421551872) |
|
||||
| nginx_openssl-1.1.x_renegotiation_bugfix.patch | Bugfix **Secure Client-Initiated Renegotiation**. (Check testssl.sh) OpenSSL >= 1.1.x, nginx = 1.15.4<br>[Patched nginx 1.15.5](https://github.com/nginx/nginx/commit/53803b4780be15d8014be183d4161091fd5f3376) |
|
||||
| nginx_ocsp.sh | Some of the parts that can not get OCSP Stapling value at nginx start or reload are solved.<br>OCSP stapling in nginx is made up of a callback, so you only need to connect at least once to get the value.<br>This file is a temporary file and may not work normally. |
|
||||
| nginx_io_uring.patch | Add **io_uring** support patch. Thanks [@CarterLi](https://github.com/CarterLi). [View how to install](https://github.com/hakasenyang/openssl-patch/pull/22) |
|
||||
|
||||
## How To Use?
|
||||
|
||||
@@ -131,6 +141,7 @@ This is a condition for using strict sni. [View issue.](https://github.com/hakas
|
||||
- strict_sni_header : if you do not want to respond to invalid headers. (**only with strict_sni**)
|
||||
- Strict SNI requires at least two ssl server (fake) settings (server { listen 443 ssl }).
|
||||
- It does not matter what kind of certificate or duplicate.
|
||||
- (>1.15.10) If no SNI is required, print the certificate without applying strict-SNI.
|
||||
|
||||
Thanks [@JemmyLoveJenny](https://github.com/hakasenyang/openssl-patch/issues/1#issuecomment-427040319), [@NewBugger](https://github.com/hakasenyang/openssl-patch/issues/7#issuecomment-427831677)!
|
||||
|
||||
@@ -142,6 +153,10 @@ Run it from the nginx directory.
|
||||
|
||||
``curl https://raw.githubusercontent.com/hakasenyang/openssl-patch/master/nginx_openssl-1.1.x_renegotiation_bugfix.patch | patch -p1``
|
||||
|
||||
### io_uring Patch
|
||||
|
||||
[View this link.](https://github.com/hakasenyang/openssl-patch/pull/22)
|
||||
|
||||
## nginx Configuration
|
||||
|
||||
### HPACK Patch
|
||||
@@ -165,3 +180,18 @@ ssl_prefer_server_ciphers on;
|
||||
```
|
||||
[TLS13+AESGCM+AES128|TLS13+AESGCM+AES256|TLS13+CHACHA20]:[EECDH+ECDSA+AESGCM+AES128|EECDH+ECDSA+CHACHA20]:EECDH+ECDSA+AESGCM+AES256:EECDH+ECDSA+AES128+SHA:EECDH+ECDSA+AES256+SHA:[EECDH+aRSA+AESGCM+AES128|EECDH+aRSA+CHACHA20]:EECDH+aRSA+AESGCM+AES256:EECDH+aRSA+AES128+SHA:EECDH+aRSA+AES256+SHA:RSA+AES128+SHA:RSA+AES256+SHA:RSA+3DES
|
||||
```
|
||||
|
||||
## Other.
|
||||
|
||||
### nginx ocsp shell
|
||||
|
||||
The configuration file recognizes the ***.conf** file in **/etc/nginx**.
|
||||
|
||||
Precedence settings in **nginx.conf** are as follows:
|
||||
|
||||
worker_processes 1 - **If this number is high, the remaining worker processes do not have OCSP Stapling values.**
|
||||
|
||||
After reload or restart, execute the corresponding shell. That's it!
|
||||
|
||||
I tried to edit nginx, but I have not found a good way yet. :(
|
||||
|
||||
@@ -0,0 +1,506 @@
|
||||
From da87b6048f6a66da7d23d77e4009be5090b5a995 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?=E6=9D=8E=E9=80=9A=E6=B4=B2?= <carter.li@eoitek.com>
|
||||
Date: Tue, 3 Dec 2019 15:00:52 +0800
|
||||
Subject: [PATCH] Add io_uring support
|
||||
|
||||
---
|
||||
auto/unix | 39 ++---
|
||||
src/core/ngx_open_file_cache.c | 6 +-
|
||||
src/event/modules/ngx_epoll_module.c | 218 +++++----------------------
|
||||
src/event/ngx_event.h | 4 +-
|
||||
src/os/unix/ngx_linux_aio_read.c | 44 +++---
|
||||
src/os/unix/ngx_linux_config.h | 3 +-
|
||||
6 files changed, 72 insertions(+), 242 deletions(-)
|
||||
|
||||
diff --git a/auto/unix b/auto/unix
|
||||
index ff9697a..2e2f63a 100644
|
||||
--- a/auto/unix
|
||||
+++ b/auto/unix
|
||||
@@ -532,44 +532,23 @@ if [ $NGX_FILE_AIO = YES ]; then
|
||||
|
||||
if [ $ngx_found = no ]; then
|
||||
|
||||
- ngx_feature="Linux AIO support"
|
||||
+ ngx_feature="Linux io_uring support (liburing)"
|
||||
ngx_feature_name="NGX_HAVE_FILE_AIO"
|
||||
ngx_feature_run=no
|
||||
- ngx_feature_incs="#include <linux/aio_abi.h>
|
||||
- #include <sys/eventfd.h>"
|
||||
+ ngx_feature_incs="#include <liburing.h>"
|
||||
ngx_feature_path=
|
||||
- ngx_feature_libs=
|
||||
- ngx_feature_test="struct iocb iocb;
|
||||
- iocb.aio_lio_opcode = IOCB_CMD_PREAD;
|
||||
- iocb.aio_flags = IOCB_FLAG_RESFD;
|
||||
- iocb.aio_resfd = -1;
|
||||
- (void) iocb;
|
||||
- (void) eventfd(0, 0)"
|
||||
+ ngx_feature_libs="-luring"
|
||||
+ ngx_feature_test="struct io_uring ring;
|
||||
+ int ret = io_uring_queue_init(64, &ring, 0);
|
||||
+ if (ret < 0) return 1;
|
||||
+ io_uring_queue_exit(&ring);"
|
||||
. auto/feature
|
||||
|
||||
if [ $ngx_found = yes ]; then
|
||||
have=NGX_HAVE_EVENTFD . auto/have
|
||||
have=NGX_HAVE_SYS_EVENTFD_H . auto/have
|
||||
CORE_SRCS="$CORE_SRCS $LINUX_AIO_SRCS"
|
||||
- fi
|
||||
- fi
|
||||
-
|
||||
- if [ $ngx_found = no ]; then
|
||||
-
|
||||
- ngx_feature="Linux AIO support (SYS_eventfd)"
|
||||
- ngx_feature_incs="#include <linux/aio_abi.h>
|
||||
- #include <sys/syscall.h>"
|
||||
- ngx_feature_test="struct iocb iocb;
|
||||
- iocb.aio_lio_opcode = IOCB_CMD_PREAD;
|
||||
- iocb.aio_flags = IOCB_FLAG_RESFD;
|
||||
- iocb.aio_resfd = -1;
|
||||
- (void) iocb;
|
||||
- (void) SYS_eventfd"
|
||||
- . auto/feature
|
||||
-
|
||||
- if [ $ngx_found = yes ]; then
|
||||
- have=NGX_HAVE_EVENTFD . auto/have
|
||||
- CORE_SRCS="$CORE_SRCS $LINUX_AIO_SRCS"
|
||||
+ CORE_LIBS="$CORE_LIBS -luring"
|
||||
fi
|
||||
fi
|
||||
|
||||
@@ -577,7 +556,7 @@ if [ $NGX_FILE_AIO = YES ]; then
|
||||
cat << END
|
||||
|
||||
$0: no supported file AIO was found
|
||||
-Currently file AIO is supported on FreeBSD 4.3+ and Linux 2.6.22+ only
|
||||
+Currently file AIO is supported on FreeBSD 4.3+ and Linux 5.1.0+ (requires liburing) only
|
||||
|
||||
END
|
||||
exit 1
|
||||
diff --git a/src/core/ngx_open_file_cache.c b/src/core/ngx_open_file_cache.c
|
||||
index b23ee78..682d48c 100644
|
||||
--- a/src/core/ngx_open_file_cache.c
|
||||
+++ b/src/core/ngx_open_file_cache.c
|
||||
@@ -869,11 +869,11 @@ ngx_open_and_stat_file(ngx_str_t *name, ngx_open_file_info_t *of,
|
||||
if (!of->log) {
|
||||
|
||||
/*
|
||||
- * Use non-blocking open() not to hang on FIFO files, etc.
|
||||
- * This flag has no effect on a regular files.
|
||||
+ * Differs from plain read, IORING_OP_READV with O_NONBLOCK
|
||||
+ * will return -EAGAIN if the operation may block.
|
||||
*/
|
||||
|
||||
- fd = ngx_open_file_wrapper(name, of, NGX_FILE_RDONLY|NGX_FILE_NONBLOCK,
|
||||
+ fd = ngx_open_file_wrapper(name, of, NGX_FILE_RDONLY,
|
||||
NGX_FILE_OPEN, 0, log);
|
||||
|
||||
} else {
|
||||
diff --git a/src/event/modules/ngx_epoll_module.c b/src/event/modules/ngx_epoll_module.c
|
||||
index 98e3ce7..2f0bd26 100644
|
||||
--- a/src/event/modules/ngx_epoll_module.c
|
||||
+++ b/src/event/modules/ngx_epoll_module.c
|
||||
@@ -75,23 +75,6 @@ int epoll_wait(int epfd, struct epoll_event *events, int nevents, int timeout)
|
||||
#define SYS_eventfd 323
|
||||
#endif
|
||||
|
||||
-#if (NGX_HAVE_FILE_AIO)
|
||||
-
|
||||
-#define SYS_io_setup 245
|
||||
-#define SYS_io_destroy 246
|
||||
-#define SYS_io_getevents 247
|
||||
-
|
||||
-typedef u_int aio_context_t;
|
||||
-
|
||||
-struct io_event {
|
||||
- uint64_t data; /* the data field from the iocb */
|
||||
- uint64_t obj; /* what iocb this event came from */
|
||||
- int64_t res; /* result code for this event */
|
||||
- int64_t res2; /* secondary result */
|
||||
-};
|
||||
-
|
||||
-
|
||||
-#endif
|
||||
#endif /* NGX_TEST_BUILD_EPOLL */
|
||||
|
||||
|
||||
@@ -124,7 +107,7 @@ static ngx_int_t ngx_epoll_process_events(ngx_cycle_t *cycle, ngx_msec_t timer,
|
||||
ngx_uint_t flags);
|
||||
|
||||
#if (NGX_HAVE_FILE_AIO)
|
||||
-static void ngx_epoll_eventfd_handler(ngx_event_t *ev);
|
||||
+static void ngx_epoll_io_uring_handler(ngx_event_t *ev);
|
||||
#endif
|
||||
|
||||
static void *ngx_epoll_create_conf(ngx_cycle_t *cycle);
|
||||
@@ -141,13 +124,10 @@ static ngx_connection_t notify_conn;
|
||||
#endif
|
||||
|
||||
#if (NGX_HAVE_FILE_AIO)
|
||||
+struct io_uring ngx_ring;
|
||||
|
||||
-int ngx_eventfd = -1;
|
||||
-aio_context_t ngx_aio_ctx = 0;
|
||||
-
|
||||
-static ngx_event_t ngx_eventfd_event;
|
||||
-static ngx_connection_t ngx_eventfd_conn;
|
||||
-
|
||||
+static ngx_event_t ngx_ring_event;
|
||||
+static ngx_connection_t ngx_ring_conn;
|
||||
#endif
|
||||
|
||||
#if (NGX_HAVE_EPOLLRDHUP)
|
||||
@@ -217,102 +197,40 @@ ngx_module_t ngx_epoll_module = {
|
||||
|
||||
#if (NGX_HAVE_FILE_AIO)
|
||||
|
||||
-/*
|
||||
- * We call io_setup(), io_destroy() io_submit(), and io_getevents() directly
|
||||
- * as syscalls instead of libaio usage, because the library header file
|
||||
- * supports eventfd() since 0.3.107 version only.
|
||||
- */
|
||||
-
|
||||
-static int
|
||||
-io_setup(u_int nr_reqs, aio_context_t *ctx)
|
||||
-{
|
||||
- return syscall(SYS_io_setup, nr_reqs, ctx);
|
||||
-}
|
||||
-
|
||||
-
|
||||
-static int
|
||||
-io_destroy(aio_context_t ctx)
|
||||
-{
|
||||
- return syscall(SYS_io_destroy, ctx);
|
||||
-}
|
||||
-
|
||||
-
|
||||
-static int
|
||||
-io_getevents(aio_context_t ctx, long min_nr, long nr, struct io_event *events,
|
||||
- struct timespec *tmo)
|
||||
-{
|
||||
- return syscall(SYS_io_getevents, ctx, min_nr, nr, events, tmo);
|
||||
-}
|
||||
-
|
||||
-
|
||||
static void
|
||||
ngx_epoll_aio_init(ngx_cycle_t *cycle, ngx_epoll_conf_t *epcf)
|
||||
{
|
||||
- int n;
|
||||
struct epoll_event ee;
|
||||
|
||||
-#if (NGX_HAVE_SYS_EVENTFD_H)
|
||||
- ngx_eventfd = eventfd(0, 0);
|
||||
-#else
|
||||
- ngx_eventfd = syscall(SYS_eventfd, 0);
|
||||
-#endif
|
||||
-
|
||||
- if (ngx_eventfd == -1) {
|
||||
- ngx_log_error(NGX_LOG_EMERG, cycle->log, ngx_errno,
|
||||
- "eventfd() failed");
|
||||
- ngx_file_aio = 0;
|
||||
- return;
|
||||
- }
|
||||
-
|
||||
- ngx_log_debug1(NGX_LOG_DEBUG_EVENT, cycle->log, 0,
|
||||
- "eventfd: %d", ngx_eventfd);
|
||||
-
|
||||
- n = 1;
|
||||
-
|
||||
- if (ioctl(ngx_eventfd, FIONBIO, &n) == -1) {
|
||||
- ngx_log_error(NGX_LOG_EMERG, cycle->log, ngx_errno,
|
||||
- "ioctl(eventfd, FIONBIO) failed");
|
||||
- goto failed;
|
||||
- }
|
||||
-
|
||||
- if (io_setup(epcf->aio_requests, &ngx_aio_ctx) == -1) {
|
||||
+ if (io_uring_queue_init(64, &ngx_ring, 0) < 0) {
|
||||
ngx_log_error(NGX_LOG_EMERG, cycle->log, ngx_errno,
|
||||
- "io_setup() failed");
|
||||
+ "io_uring_queue_init() failed");
|
||||
goto failed;
|
||||
}
|
||||
|
||||
- ngx_eventfd_event.data = &ngx_eventfd_conn;
|
||||
- ngx_eventfd_event.handler = ngx_epoll_eventfd_handler;
|
||||
- ngx_eventfd_event.log = cycle->log;
|
||||
- ngx_eventfd_event.active = 1;
|
||||
- ngx_eventfd_conn.fd = ngx_eventfd;
|
||||
- ngx_eventfd_conn.read = &ngx_eventfd_event;
|
||||
- ngx_eventfd_conn.log = cycle->log;
|
||||
+ ngx_ring_event.data = &ngx_ring_conn;
|
||||
+ ngx_ring_event.handler = ngx_epoll_io_uring_handler;
|
||||
+ ngx_ring_event.log = cycle->log;
|
||||
+ ngx_ring_event.active = 1;
|
||||
+ ngx_ring_conn.fd = ngx_ring.ring_fd;
|
||||
+ ngx_ring_conn.read = &ngx_ring_event;
|
||||
+ ngx_ring_conn.log = cycle->log;
|
||||
|
||||
ee.events = EPOLLIN|EPOLLET;
|
||||
- ee.data.ptr = &ngx_eventfd_conn;
|
||||
+ ee.data.ptr = &ngx_ring_conn;
|
||||
|
||||
- if (epoll_ctl(ep, EPOLL_CTL_ADD, ngx_eventfd, &ee) != -1) {
|
||||
+ if (epoll_ctl(ep, EPOLL_CTL_ADD, ngx_ring.ring_fd, &ee) != -1) {
|
||||
return;
|
||||
}
|
||||
|
||||
ngx_log_error(NGX_LOG_EMERG, cycle->log, ngx_errno,
|
||||
"epoll_ctl(EPOLL_CTL_ADD, eventfd) failed");
|
||||
|
||||
- if (io_destroy(ngx_aio_ctx) == -1) {
|
||||
- ngx_log_error(NGX_LOG_ALERT, cycle->log, ngx_errno,
|
||||
- "io_destroy() failed");
|
||||
- }
|
||||
+ io_uring_queue_exit(&ngx_ring);
|
||||
|
||||
failed:
|
||||
|
||||
- if (close(ngx_eventfd) == -1) {
|
||||
- ngx_log_error(NGX_LOG_ALERT, cycle->log, ngx_errno,
|
||||
- "eventfd close() failed");
|
||||
- }
|
||||
-
|
||||
- ngx_eventfd = -1;
|
||||
- ngx_aio_ctx = 0;
|
||||
+ ngx_ring.ring_fd = 0;
|
||||
ngx_file_aio = 0;
|
||||
}
|
||||
|
||||
@@ -549,23 +467,11 @@ ngx_epoll_done(ngx_cycle_t *cycle)
|
||||
|
||||
#if (NGX_HAVE_FILE_AIO)
|
||||
|
||||
- if (ngx_eventfd != -1) {
|
||||
-
|
||||
- if (io_destroy(ngx_aio_ctx) == -1) {
|
||||
- ngx_log_error(NGX_LOG_ALERT, cycle->log, ngx_errno,
|
||||
- "io_destroy() failed");
|
||||
- }
|
||||
-
|
||||
- if (close(ngx_eventfd) == -1) {
|
||||
- ngx_log_error(NGX_LOG_ALERT, cycle->log, ngx_errno,
|
||||
- "eventfd close() failed");
|
||||
- }
|
||||
-
|
||||
- ngx_eventfd = -1;
|
||||
+ if (ngx_ring.ring_fd != 0) {
|
||||
+ io_uring_queue_exit(&ngx_ring);
|
||||
+ ngx_ring.ring_fd = 0;
|
||||
}
|
||||
|
||||
- ngx_aio_ctx = 0;
|
||||
-
|
||||
#endif
|
||||
|
||||
ngx_free(event_list);
|
||||
@@ -939,83 +845,31 @@ ngx_epoll_process_events(ngx_cycle_t *cycle, ngx_msec_t timer, ngx_uint_t flags)
|
||||
#if (NGX_HAVE_FILE_AIO)
|
||||
|
||||
static void
|
||||
-ngx_epoll_eventfd_handler(ngx_event_t *ev)
|
||||
+ngx_epoll_io_uring_handler(ngx_event_t *ev)
|
||||
{
|
||||
- int n, events;
|
||||
- long i;
|
||||
- uint64_t ready;
|
||||
- ngx_err_t err;
|
||||
ngx_event_t *e;
|
||||
+ struct io_uring_cqe *cqe;
|
||||
ngx_event_aio_t *aio;
|
||||
- struct io_event event[64];
|
||||
- struct timespec ts;
|
||||
-
|
||||
- ngx_log_debug0(NGX_LOG_DEBUG_EVENT, ev->log, 0, "eventfd handler");
|
||||
-
|
||||
- n = read(ngx_eventfd, &ready, 8);
|
||||
|
||||
- err = ngx_errno;
|
||||
-
|
||||
- ngx_log_debug1(NGX_LOG_DEBUG_EVENT, ev->log, 0, "eventfd: %d", n);
|
||||
-
|
||||
- if (n != 8) {
|
||||
- if (n == -1) {
|
||||
- if (err == NGX_EAGAIN) {
|
||||
- return;
|
||||
- }
|
||||
-
|
||||
- ngx_log_error(NGX_LOG_ALERT, ev->log, err, "read(eventfd) failed");
|
||||
- return;
|
||||
- }
|
||||
+ ngx_log_debug(NGX_LOG_DEBUG_EVENT, ev->log, 0,
|
||||
+ "io_uring_peek_cqe: START");
|
||||
|
||||
- ngx_log_error(NGX_LOG_ALERT, ev->log, 0,
|
||||
- "read(eventfd) returned only %d bytes", n);
|
||||
- return;
|
||||
- }
|
||||
-
|
||||
- ts.tv_sec = 0;
|
||||
- ts.tv_nsec = 0;
|
||||
-
|
||||
- while (ready) {
|
||||
-
|
||||
- events = io_getevents(ngx_aio_ctx, 1, 64, event, &ts);
|
||||
-
|
||||
- ngx_log_debug1(NGX_LOG_DEBUG_EVENT, ev->log, 0,
|
||||
- "io_getevents: %d", events);
|
||||
-
|
||||
- if (events > 0) {
|
||||
- ready -= events;
|
||||
-
|
||||
- for (i = 0; i < events; i++) {
|
||||
-
|
||||
- ngx_log_debug4(NGX_LOG_DEBUG_EVENT, ev->log, 0,
|
||||
- "io_event: %XL %XL %L %L",
|
||||
- event[i].data, event[i].obj,
|
||||
- event[i].res, event[i].res2);
|
||||
-
|
||||
- e = (ngx_event_t *) (uintptr_t) event[i].data;
|
||||
-
|
||||
- e->complete = 1;
|
||||
- e->active = 0;
|
||||
- e->ready = 1;
|
||||
+ while (io_uring_peek_cqe(&ngx_ring, &cqe) >= 0 && cqe) {
|
||||
+ ngx_log_debug3(NGX_LOG_DEBUG_EVENT, ev->log, 0,
|
||||
+ "io_event: %p %d %d",
|
||||
+ cqe->user_data, cqe->res, cqe->flags);
|
||||
|
||||
- aio = e->data;
|
||||
- aio->res = event[i].res;
|
||||
+ e = (ngx_event_t *) io_uring_cqe_get_data(cqe);
|
||||
+ e->complete = 1;
|
||||
+ e->active = 0;
|
||||
+ e->ready = 1;
|
||||
|
||||
- ngx_post_event(e, &ngx_posted_events);
|
||||
- }
|
||||
+ aio = e->data;
|
||||
+ aio->res = cqe->res;
|
||||
|
||||
- continue;
|
||||
- }
|
||||
+ io_uring_cqe_seen(&ngx_ring, cqe);
|
||||
|
||||
- if (events == 0) {
|
||||
- return;
|
||||
- }
|
||||
-
|
||||
- /* events == -1 */
|
||||
- ngx_log_error(NGX_LOG_ALERT, ev->log, ngx_errno,
|
||||
- "io_getevents() failed");
|
||||
- return;
|
||||
+ ngx_post_event(e, &ngx_posted_events);
|
||||
}
|
||||
}
|
||||
|
||||
diff --git a/src/event/ngx_event.h b/src/event/ngx_event.h
|
||||
index 97f9673..eb17346 100644
|
||||
--- a/src/event/ngx_event.h
|
||||
+++ b/src/event/ngx_event.h
|
||||
@@ -160,7 +160,9 @@ struct ngx_event_aio_s {
|
||||
size_t nbytes;
|
||||
#endif
|
||||
|
||||
- ngx_aiocb_t aiocb;
|
||||
+ /* Make sure that this iov has the same lifecycle with its associated aio event */
|
||||
+ struct iovec iov;
|
||||
+
|
||||
ngx_event_t event;
|
||||
};
|
||||
|
||||
diff --git a/src/os/unix/ngx_linux_aio_read.c b/src/os/unix/ngx_linux_aio_read.c
|
||||
index 9f0a6c1..52849e3 100644
|
||||
--- a/src/os/unix/ngx_linux_aio_read.c
|
||||
+++ b/src/os/unix/ngx_linux_aio_read.c
|
||||
@@ -10,19 +10,12 @@
|
||||
#include <ngx_event.h>
|
||||
|
||||
|
||||
-extern int ngx_eventfd;
|
||||
-extern aio_context_t ngx_aio_ctx;
|
||||
+extern struct io_uring ngx_ring;
|
||||
|
||||
|
||||
static void ngx_file_aio_event_handler(ngx_event_t *ev);
|
||||
|
||||
|
||||
-static int
|
||||
-io_submit(aio_context_t ctx, long n, struct iocb **paiocb)
|
||||
-{
|
||||
- return syscall(SYS_io_submit, ctx, n, paiocb);
|
||||
-}
|
||||
-
|
||||
|
||||
ngx_int_t
|
||||
ngx_file_aio_init(ngx_file_t *file, ngx_pool_t *pool)
|
||||
@@ -50,10 +43,10 @@ ssize_t
|
||||
ngx_file_aio_read(ngx_file_t *file, u_char *buf, size_t size, off_t offset,
|
||||
ngx_pool_t *pool)
|
||||
{
|
||||
- ngx_err_t err;
|
||||
- struct iocb *piocb[1];
|
||||
- ngx_event_t *ev;
|
||||
- ngx_event_aio_t *aio;
|
||||
+ ngx_err_t err;
|
||||
+ ngx_event_t *ev;
|
||||
+ ngx_event_aio_t *aio;
|
||||
+ struct io_uring_sqe *sqe;
|
||||
|
||||
if (!ngx_file_aio) {
|
||||
return ngx_read_file(file, buf, size, offset);
|
||||
@@ -93,22 +86,25 @@ ngx_file_aio_read(ngx_file_t *file, u_char *buf, size_t size, off_t offset,
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
- ngx_memzero(&aio->aiocb, sizeof(struct iocb));
|
||||
+ sqe = io_uring_get_sqe(&ngx_ring);
|
||||
|
||||
- aio->aiocb.aio_data = (uint64_t) (uintptr_t) ev;
|
||||
- aio->aiocb.aio_lio_opcode = IOCB_CMD_PREAD;
|
||||
- aio->aiocb.aio_fildes = file->fd;
|
||||
- aio->aiocb.aio_buf = (uint64_t) (uintptr_t) buf;
|
||||
- aio->aiocb.aio_nbytes = size;
|
||||
- aio->aiocb.aio_offset = offset;
|
||||
- aio->aiocb.aio_flags = IOCB_FLAG_RESFD;
|
||||
- aio->aiocb.aio_resfd = ngx_eventfd;
|
||||
+ if (!sqe) {
|
||||
+ ngx_log_debug4(NGX_LOG_DEBUG_CORE, file->log, 0,
|
||||
+ "aio no sqe left:%d @%O:%uz %V",
|
||||
+ ev->complete, offset, size, &file->name);
|
||||
+ return ngx_read_file(file, buf, size, offset);
|
||||
+ }
|
||||
|
||||
- ev->handler = ngx_file_aio_event_handler;
|
||||
+ /* We must store iov into heap to prevent kernel from returning -EFAULT */
|
||||
+ aio->iov.iov_base = buf;
|
||||
+ aio->iov.iov_len = size;
|
||||
+ io_uring_prep_readv(sqe, file->fd, &aio->iov, 1, offset);
|
||||
+ io_uring_sqe_set_data(sqe, ev);
|
||||
|
||||
- piocb[0] = &aio->aiocb;
|
||||
|
||||
- if (io_submit(ngx_aio_ctx, 1, piocb) == 1) {
|
||||
+ ev->handler = ngx_file_aio_event_handler;
|
||||
+
|
||||
+ if (io_uring_submit(&ngx_ring) == 1) {
|
||||
ev->active = 1;
|
||||
ev->ready = 0;
|
||||
ev->complete = 0;
|
||||
diff --git a/src/os/unix/ngx_linux_config.h b/src/os/unix/ngx_linux_config.h
|
||||
index 3036cae..daf5b4c 100644
|
||||
--- a/src/os/unix/ngx_linux_config.h
|
||||
+++ b/src/os/unix/ngx_linux_config.h
|
||||
@@ -94,8 +94,7 @@ extern ssize_t sendfile(int s, int fd, int32_t *offset, size_t size);
|
||||
#endif
|
||||
#include <sys/syscall.h>
|
||||
#if (NGX_HAVE_FILE_AIO)
|
||||
-#include <linux/aio_abi.h>
|
||||
-typedef struct iocb ngx_aiocb_t;
|
||||
+#include <liburing.h>
|
||||
#endif
|
||||
|
||||
|
||||
--
|
||||
2.24.0
|
||||
|
||||
Executable
+44
@@ -0,0 +1,44 @@
|
||||
#!/bin/bash
|
||||
|
||||
gets() {
|
||||
if [ ! -z "$2" ]; then
|
||||
port=$2
|
||||
else
|
||||
port=443
|
||||
fi
|
||||
echo QUIT | openssl s_client -connect 127.0.0.1:${2} -servername ${1} -tls1_2 -cipher ECDH -status > /dev/null 2>&1
|
||||
echo QUIT | openssl s_client -connect 127.0.0.1:${2} -servername ${1} -tls1_2 -cipher aRSA:RSA -status > /dev/null 2>&1
|
||||
}
|
||||
|
||||
file=`find /etc/nginx -name "*.conf"`
|
||||
|
||||
for names in $file; do
|
||||
# csplit source : https://stackoverflow.com/questions/9634953/how-to-split-a-nginx-virtual-host-config-file-into-small-ones-using-shell/38635284
|
||||
rm /tmp/ngx_ocsp*.tmp > /dev/null 2>&1
|
||||
csplit -z -f /tmp/ngx_ocsp -b %d.tmp $names '/^\s*server\s*{*$/' {*} > /dev/null 2>&1
|
||||
|
||||
for i in /tmp/ngx_ocsp*.tmp; do
|
||||
result=`grep -oP '(?<=server_name ).+(?=;)' $i`
|
||||
if [ ! -z "$result" ]; then
|
||||
port=`grep -oP '(?<=listen ).+(?=ssl).+(?=;)' $i`
|
||||
new_name=`echo $result|awk '{print $1}'`
|
||||
new_name=${new_name%';'}
|
||||
port=`echo $port|sed 's/[^0-9]/ /g'|awk '{print $1}'`
|
||||
port=${port%';'}
|
||||
if [ ! -z "$port" ]; then
|
||||
hosts=(${hosts[@]} $new_name:$port)
|
||||
fi
|
||||
fi
|
||||
done
|
||||
done
|
||||
|
||||
rm /rmp/ocsp*.tmp > /dev/null 2>&1
|
||||
|
||||
FINALS=`echo ${hosts[@]} | tr " " "\n" | sed -e "s/^*//g" | sed -e "s/*/wildcards/g" | sort -u`
|
||||
|
||||
for conn in $FINALS; do
|
||||
data1=`echo $conn | awk -F: '{print $1}'`
|
||||
data2=`echo $conn | awk -F: '{print $2}'`
|
||||
echo OCSP : $data1 - $data2
|
||||
gets $data1 $data2
|
||||
done
|
||||
@@ -0,0 +1,215 @@
|
||||
diff --git a/src/event/ngx_event_openssl.c b/src/event/ngx_event_openssl.c
|
||||
index 7be4fb4c..e16b8c1a 100644
|
||||
--- a/src/event/ngx_event_openssl.c
|
||||
+++ b/src/event/ngx_event_openssl.c
|
||||
@@ -2818,6 +2818,9 @@ ngx_ssl_connection_error(ngx_connection_t *c, int sslerr, ngx_err_t err,
|
||||
char *text)
|
||||
{
|
||||
int n;
|
||||
+#if (defined SSL_R_CALLBACK_FAILED && defined SSL_F_FINAL_SERVER_NAME)
|
||||
+ int f;
|
||||
+#endif
|
||||
ngx_uint_t level;
|
||||
|
||||
level = NGX_LOG_CRIT;
|
||||
@@ -2854,6 +2857,24 @@ ngx_ssl_connection_error(ngx_connection_t *c, int sslerr, ngx_err_t err,
|
||||
|
||||
n = ERR_GET_REASON(ERR_peek_error());
|
||||
|
||||
+ /* Strict SNI Error Patch
|
||||
+ * https://github.com/hakasenyang/openssl-patch/issues/1#issuecomment-427040319
|
||||
+ * https://github.com/hakasenyang/openssl-patch/issues/7#issuecomment-427872934
|
||||
+ */
|
||||
+#if (defined SSL_R_CALLBACK_FAILED && defined SSL_F_FINAL_SERVER_NAME)
|
||||
+ if (n == SSL_R_CALLBACK_FAILED) {
|
||||
+ f = ERR_GET_FUNC(ERR_peek_error());
|
||||
+ if (f == SSL_F_FINAL_SERVER_NAME) {
|
||||
+ while (ERR_peek_error()) {
|
||||
+ ngx_ssl_error(NGX_LOG_DEBUG, c->log, 0,
|
||||
+ "ignoring ssl error at STRICT SNI block");
|
||||
+ }
|
||||
+ ERR_clear_error();
|
||||
+ return;
|
||||
+ }
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
/* handshake failures */
|
||||
if (n == SSL_R_BAD_CHANGE_CIPHER_SPEC /* 103 */
|
||||
#ifdef SSL_R_NO_SUITABLE_KEY_SHARE
|
||||
diff --git a/src/http/ngx_http_core_module.c b/src/http/ngx_http_core_module.c
|
||||
index cb49ef74..34935834 100644
|
||||
--- a/src/http/ngx_http_core_module.c
|
||||
+++ b/src/http/ngx_http_core_module.c
|
||||
@@ -441,6 +441,20 @@ static ngx_command_t ngx_http_core_commands[] = {
|
||||
offsetof(ngx_http_core_loc_conf_t, directio_alignment),
|
||||
NULL },
|
||||
|
||||
+ { ngx_string("strict_sni"),
|
||||
+ NGX_HTTP_MAIN_CONF|NGX_CONF_FLAG,
|
||||
+ ngx_conf_set_flag_slot,
|
||||
+ NGX_HTTP_LOC_CONF_OFFSET,
|
||||
+ offsetof(ngx_http_core_loc_conf_t, strict_sni),
|
||||
+ NULL },
|
||||
+
|
||||
+ { ngx_string("strict_sni_header"),
|
||||
+ NGX_HTTP_MAIN_CONF|NGX_CONF_FLAG,
|
||||
+ ngx_conf_set_flag_slot,
|
||||
+ NGX_HTTP_LOC_CONF_OFFSET,
|
||||
+ offsetof(ngx_http_core_loc_conf_t, strict_sni_header),
|
||||
+ NULL },
|
||||
+
|
||||
{ ngx_string("tcp_nopush"),
|
||||
NGX_HTTP_MAIN_CONF|NGX_HTTP_SRV_CONF|NGX_HTTP_LOC_CONF|NGX_CONF_FLAG,
|
||||
ngx_conf_set_flag_slot,
|
||||
@@ -3412,6 +3426,8 @@ ngx_http_core_create_loc_conf(ngx_conf_t *cf)
|
||||
clcf->read_ahead = NGX_CONF_UNSET_SIZE;
|
||||
clcf->directio = NGX_CONF_UNSET;
|
||||
clcf->directio_alignment = NGX_CONF_UNSET;
|
||||
+ clcf->strict_sni = NGX_CONF_UNSET;
|
||||
+ clcf->strict_sni_header = NGX_CONF_UNSET;
|
||||
clcf->tcp_nopush = NGX_CONF_UNSET;
|
||||
clcf->tcp_nodelay = NGX_CONF_UNSET;
|
||||
clcf->send_timeout = NGX_CONF_UNSET_MSEC;
|
||||
@@ -3640,6 +3656,8 @@ ngx_http_core_merge_loc_conf(ngx_conf_t *cf, void *parent, void *child)
|
||||
NGX_OPEN_FILE_DIRECTIO_OFF);
|
||||
ngx_conf_merge_off_value(conf->directio_alignment, prev->directio_alignment,
|
||||
512);
|
||||
+ ngx_conf_merge_value(conf->strict_sni, prev->strict_sni, 0);
|
||||
+ ngx_conf_merge_value(conf->strict_sni_header, prev->strict_sni_header, 0);
|
||||
ngx_conf_merge_value(conf->tcp_nopush, prev->tcp_nopush, 0);
|
||||
ngx_conf_merge_value(conf->tcp_nodelay, prev->tcp_nodelay, 1);
|
||||
|
||||
diff --git a/src/http/ngx_http_core_module.h b/src/http/ngx_http_core_module.h
|
||||
index 85f6d66d..eb2e165b 100644
|
||||
--- a/src/http/ngx_http_core_module.h
|
||||
+++ b/src/http/ngx_http_core_module.h
|
||||
@@ -381,6 +381,8 @@ struct ngx_http_core_loc_conf_s {
|
||||
ngx_flag_t sendfile; /* sendfile */
|
||||
ngx_flag_t aio; /* aio */
|
||||
ngx_flag_t aio_write; /* aio_write */
|
||||
+ ngx_flag_t strict_sni; /* strict_sni */
|
||||
+ ngx_flag_t strict_sni_header; /* strict_sni_header */
|
||||
ngx_flag_t tcp_nopush; /* tcp_nopush */
|
||||
ngx_flag_t tcp_nodelay; /* tcp_nodelay */
|
||||
ngx_flag_t reset_timedout_connection; /* reset_timedout_connection */
|
||||
diff --git a/src/http/ngx_http_request.c b/src/http/ngx_http_request.c
|
||||
index 80c19656..218291ab 100644
|
||||
--- a/src/http/ngx_http_request.c
|
||||
+++ b/src/http/ngx_http_request.c
|
||||
@@ -866,6 +866,10 @@ ngx_http_ssl_servername(ngx_ssl_conn_t *ssl_conn, int *ad, void *arg)
|
||||
|
||||
c = ngx_ssl_get_connection(ssl_conn);
|
||||
|
||||
+ hc = c->data;
|
||||
+
|
||||
+ clcf = ngx_http_get_module_loc_conf(hc->conf_ctx, ngx_http_core_module);
|
||||
+
|
||||
if (c->ssl->handshaked) {
|
||||
*ad = SSL_AD_NO_RENEGOTIATION;
|
||||
return SSL_TLSEXT_ERR_ALERT_FATAL;
|
||||
@@ -874,7 +878,7 @@ ngx_http_ssl_servername(ngx_ssl_conn_t *ssl_conn, int *ad, void *arg)
|
||||
servername = SSL_get_servername(ssl_conn, TLSEXT_NAMETYPE_host_name);
|
||||
|
||||
if (servername == NULL) {
|
||||
- return SSL_TLSEXT_ERR_OK;
|
||||
+ return (clcf->strict_sni) ? SSL_TLSEXT_ERR_ALERT_FATAL : SSL_TLSEXT_ERR_OK;
|
||||
}
|
||||
|
||||
ngx_log_debug1(NGX_LOG_DEBUG_HTTP, c->log, 0,
|
||||
@@ -883,7 +887,7 @@ ngx_http_ssl_servername(ngx_ssl_conn_t *ssl_conn, int *ad, void *arg)
|
||||
host.len = ngx_strlen(servername);
|
||||
|
||||
if (host.len == 0) {
|
||||
- return SSL_TLSEXT_ERR_OK;
|
||||
+ return (clcf->strict_sni) ? SSL_TLSEXT_ERR_ALERT_FATAL : SSL_TLSEXT_ERR_OK;
|
||||
}
|
||||
|
||||
host.data = (u_char *) servername;
|
||||
@@ -899,8 +903,6 @@ ngx_http_ssl_servername(ngx_ssl_conn_t *ssl_conn, int *ad, void *arg)
|
||||
return SSL_TLSEXT_ERR_OK;
|
||||
}
|
||||
|
||||
- hc = c->data;
|
||||
-
|
||||
rc = ngx_http_find_virtual_server(c, hc->addr_conf->virtual_names, &host,
|
||||
NULL, &cscf);
|
||||
|
||||
@@ -910,7 +912,11 @@ ngx_http_ssl_servername(ngx_ssl_conn_t *ssl_conn, int *ad, void *arg)
|
||||
}
|
||||
|
||||
if (rc == NGX_DECLINED) {
|
||||
- return SSL_TLSEXT_ERR_OK;
|
||||
+ // If SNI is not needed (1 server, etc.), do not apply.
|
||||
+ if (hc->addr_conf->virtual_names == NULL) {
|
||||
+ return SSL_TLSEXT_ERR_OK;
|
||||
+ }
|
||||
+ return (clcf->strict_sni) ? SSL_TLSEXT_ERR_ALERT_FATAL : SSL_TLSEXT_ERR_OK;
|
||||
}
|
||||
|
||||
hc->ssl_servername = ngx_palloc(c->pool, sizeof(ngx_str_t));
|
||||
@@ -923,8 +929,6 @@ ngx_http_ssl_servername(ngx_ssl_conn_t *ssl_conn, int *ad, void *arg)
|
||||
|
||||
hc->conf_ctx = cscf->ctx;
|
||||
|
||||
- clcf = ngx_http_get_module_loc_conf(hc->conf_ctx, ngx_http_core_module);
|
||||
-
|
||||
ngx_set_connection_log(c, clcf->error_log);
|
||||
|
||||
sscf = ngx_http_get_module_srv_conf(hc->conf_ctx, ngx_http_ssl_module);
|
||||
@@ -1037,15 +1041,18 @@ failed:
|
||||
static void
|
||||
ngx_http_process_request_line(ngx_event_t *rev)
|
||||
{
|
||||
- ssize_t n;
|
||||
- ngx_int_t rc, rv;
|
||||
- ngx_str_t host;
|
||||
- ngx_connection_t *c;
|
||||
- ngx_http_request_t *r;
|
||||
+ ssize_t n;
|
||||
+ ngx_int_t rc, rv;
|
||||
+ ngx_str_t host;
|
||||
+ ngx_connection_t *c;
|
||||
+ ngx_http_core_loc_conf_t *clcf;
|
||||
+ ngx_http_request_t *r;
|
||||
|
||||
c = rev->data;
|
||||
r = c->data;
|
||||
|
||||
+ clcf = ngx_http_get_module_loc_conf(r, ngx_http_core_module);
|
||||
+
|
||||
ngx_log_debug0(NGX_LOG_DEBUG_HTTP, rev->log, 0,
|
||||
"http process request line");
|
||||
|
||||
@@ -1161,10 +1168,10 @@ ngx_http_process_request_line(ngx_event_t *rev)
|
||||
ngx_http_client_errors[rc - NGX_HTTP_CLIENT_ERROR]);
|
||||
|
||||
if (rc == NGX_HTTP_PARSE_INVALID_VERSION) {
|
||||
- ngx_http_finalize_request(r, NGX_HTTP_VERSION_NOT_SUPPORTED);
|
||||
+ (r->http_connection->ssl && clcf->strict_sni && clcf->strict_sni_header) ? ngx_http_terminate_request(r, 0) : ngx_http_finalize_request(r, NGX_HTTP_VERSION_NOT_SUPPORTED);
|
||||
|
||||
} else {
|
||||
- ngx_http_finalize_request(r, NGX_HTTP_BAD_REQUEST);
|
||||
+ (r->http_connection->ssl && clcf->strict_sni && clcf->strict_sni_header) ? ngx_http_terminate_request(r, 0) : ngx_http_finalize_request(r, NGX_HTTP_BAD_REQUEST);
|
||||
}
|
||||
|
||||
break;
|
||||
@@ -1909,6 +1916,9 @@ ngx_http_process_multi_header_lines(ngx_http_request_t *r, ngx_table_elt_t *h,
|
||||
ngx_int_t
|
||||
ngx_http_process_request_header(ngx_http_request_t *r)
|
||||
{
|
||||
+ ngx_http_core_loc_conf_t *clcf;
|
||||
+ clcf = ngx_http_get_module_loc_conf(r, ngx_http_core_module);
|
||||
+
|
||||
if (r->headers_in.server.len == 0
|
||||
&& ngx_http_set_virtual_server(r, &r->headers_in.server)
|
||||
== NGX_ERROR)
|
||||
@@ -1919,7 +1929,7 @@ ngx_http_process_request_header(ngx_http_request_t *r)
|
||||
if (r->headers_in.host == NULL && r->http_version > NGX_HTTP_VERSION_10) {
|
||||
ngx_log_error(NGX_LOG_INFO, r->connection->log, 0,
|
||||
"client sent HTTP/1.1 request without \"Host\" header");
|
||||
- ngx_http_finalize_request(r, NGX_HTTP_BAD_REQUEST);
|
||||
+ (r->http_connection->ssl && clcf->strict_sni && clcf->strict_sni_header) ? ngx_http_terminate_request(r, 0) : ngx_http_finalize_request(r, NGX_HTTP_BAD_REQUEST);
|
||||
return NGX_ERROR;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,509 @@
|
||||
diff --git a/crypto/evp/c_allc.c b/crypto/evp/c_allc.c
|
||||
index 086b3c4d51..5699901f7d 100644
|
||||
--- a/crypto/evp/c_allc.c
|
||||
+++ b/crypto/evp/c_allc.c
|
||||
@@ -261,6 +261,7 @@ void openssl_add_all_ciphers_int(void)
|
||||
EVP_add_cipher(EVP_chacha20());
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
EVP_add_cipher(EVP_chacha20_poly1305());
|
||||
+ EVP_add_cipher(EVP_chacha20_poly1305_draft());
|
||||
# endif
|
||||
#endif
|
||||
}
|
||||
diff --git a/crypto/evp/e_chacha20_poly1305.c b/crypto/evp/e_chacha20_poly1305.c
|
||||
index d3e2c622a1..e61c9e1bea 100644
|
||||
--- a/crypto/evp/e_chacha20_poly1305.c
|
||||
+++ b/crypto/evp/e_chacha20_poly1305.c
|
||||
@@ -156,6 +156,7 @@ typedef struct {
|
||||
struct { uint64_t aad, text; } len;
|
||||
int aad, mac_inited, tag_len, nonce_len;
|
||||
size_t tls_payload_length;
|
||||
+ unsigned char draft:1;
|
||||
} EVP_CHACHA_AEAD_CTX;
|
||||
|
||||
# define NO_TLS_PAYLOAD_LENGTH ((size_t)-1)
|
||||
@@ -176,6 +177,7 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
actx->aad = 0;
|
||||
actx->mac_inited = 0;
|
||||
actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 0;
|
||||
|
||||
if (iv != NULL) {
|
||||
unsigned char temp[CHACHA_CTR_SIZE] = { 0 };
|
||||
@@ -197,6 +199,27 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
return 1;
|
||||
}
|
||||
|
||||
+static int chacha20_poly1305_draft_init_key(EVP_CIPHER_CTX *ctx,
|
||||
+ const unsigned char *inkey,
|
||||
+ const unsigned char *iv, int enc)
|
||||
+{
|
||||
+ EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
+
|
||||
+ if (!inkey)
|
||||
+ return 1;
|
||||
+
|
||||
+ actx->len.aad = 0;
|
||||
+ actx->len.text = 0;
|
||||
+ actx->aad = 0;
|
||||
+ actx->mac_inited = 0;
|
||||
+ actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 1;
|
||||
+
|
||||
+ chacha_init_key(ctx, inkey, NULL, enc);
|
||||
+
|
||||
+ return 1;
|
||||
+}
|
||||
+
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
|
||||
# if defined(POLY1305_ASM) && (defined(__x86_64) || defined(__x86_64__) || \
|
||||
@@ -367,10 +390,11 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
{
|
||||
EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
size_t rem, plen = actx->tls_payload_length;
|
||||
+ uint64_t thirteen = EVP_AEAD_TLS1_AAD_LEN;
|
||||
|
||||
if (!actx->mac_inited) {
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
- if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL)
|
||||
+ if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL && !actx->draft)
|
||||
return chacha20_poly1305_tls_cipher(ctx, out, in, len);
|
||||
# endif
|
||||
actx->key.counter[0] = 0;
|
||||
@@ -397,9 +421,14 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
return len;
|
||||
} else { /* plain- or ciphertext */
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
@@ -432,40 +461,52 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
} is_endian = { 1 };
|
||||
unsigned char temp[POLY1305_BLOCK_SIZE];
|
||||
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.text;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ }
|
||||
+
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
- if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (!actx->draft) {
|
||||
+ if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
|
||||
- if (is_endian.little) {
|
||||
- Poly1305_Update(POLY1305_ctx(actx),
|
||||
- (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
- } else {
|
||||
- temp[0] = (unsigned char)(actx->len.aad);
|
||||
- temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
- temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
- temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
- temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
- temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
- temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
- temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
-
|
||||
- temp[8] = (unsigned char)(actx->len.text);
|
||||
- temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
- temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
- temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
- temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
- temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
- temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
- temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
-
|
||||
- Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ if (is_endian.little) {
|
||||
+ Poly1305_Update(POLY1305_ctx(actx),
|
||||
+ (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
+ } else {
|
||||
+ temp[0] = (unsigned char)(actx->len.aad);
|
||||
+ temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
+ temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
+ temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
+ temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
+ temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
+ temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
+ temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
+
|
||||
+ temp[8] = (unsigned char)(actx->len.text);
|
||||
+ temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
+ temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
+ temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
+ temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
+ temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
+ temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
+ temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
+
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ }
|
||||
}
|
||||
Poly1305_Final(POLY1305_ctx(actx), ctx->encrypt ? actx->tag
|
||||
: temp);
|
||||
@@ -535,12 +576,14 @@ static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IVLEN:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg <= 0 || arg > CHACHA20_POLY1305_MAX_IVLEN)
|
||||
return 0;
|
||||
actx->nonce_len = arg;
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IV_FIXED:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg != 12)
|
||||
return 0;
|
||||
actx->nonce[0] = actx->key.counter[1]
|
||||
@@ -624,9 +667,32 @@ static EVP_CIPHER chacha20_poly1305 = {
|
||||
NULL /* app_data */
|
||||
};
|
||||
|
||||
+static EVP_CIPHER chacha20_poly1305_draft = {
|
||||
+ NID_chacha20_poly1305_draft,
|
||||
+ 1, /* block_size */
|
||||
+ CHACHA_KEY_SIZE, /* key_len */
|
||||
+ 0, /* iv_len, none */
|
||||
+ EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_CUSTOM_IV |
|
||||
+ EVP_CIPH_ALWAYS_CALL_INIT | EVP_CIPH_CTRL_INIT |
|
||||
+ EVP_CIPH_CUSTOM_COPY | EVP_CIPH_FLAG_CUSTOM_CIPHER,
|
||||
+ chacha20_poly1305_draft_init_key,
|
||||
+ chacha20_poly1305_cipher,
|
||||
+ chacha20_poly1305_cleanup,
|
||||
+ 0, /* 0 moves context-specific structure allocation to ctrl */
|
||||
+ NULL, /* set_asn1_parameters */
|
||||
+ NULL, /* get_asn1_parameters */
|
||||
+ chacha20_poly1305_ctrl,
|
||||
+ NULL /* app_data */
|
||||
+};
|
||||
+
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void)
|
||||
{
|
||||
return(&chacha20_poly1305);
|
||||
}
|
||||
+
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void)
|
||||
+{
|
||||
+ return(&chacha20_poly1305_draft);
|
||||
+}
|
||||
# endif
|
||||
#endif
|
||||
diff --git a/crypto/objects/obj_dat.h b/crypto/objects/obj_dat.h
|
||||
index 9ab1a14b9e..ba3e602186 100644
|
||||
--- a/crypto/objects/obj_dat.h
|
||||
+++ b/crypto/objects/obj_dat.h
|
||||
@@ -1078,7 +1078,7 @@ static const unsigned char so[7762] = {
|
||||
0x2A,0x86,0x48,0x86,0xF7,0x0D,0x02,0x0D, /* [ 7753] OBJ_hmacWithSHA512_256 */
|
||||
};
|
||||
|
||||
-#define NUM_NID 1195
|
||||
+#define NUM_NID 1196
|
||||
static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"UNDEF", "undefined", NID_undef},
|
||||
{"rsadsi", "RSA Data Security, Inc.", NID_rsadsi, 6, &so[0]},
|
||||
@@ -2275,9 +2275,10 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"magma-mac", "magma-mac", NID_magma_mac},
|
||||
{"hmacWithSHA512-224", "hmacWithSHA512-224", NID_hmacWithSHA512_224, 8, &so[7745]},
|
||||
{"hmacWithSHA512-256", "hmacWithSHA512-256", NID_hmacWithSHA512_256, 8, &so[7753]},
|
||||
+ {"ChaCha20-Poly1305-D", "chacha20-poly1305-draft", NID_chacha20_poly1305_draft},
|
||||
};
|
||||
|
||||
-#define NUM_SN 1186
|
||||
+#define NUM_SN 1187
|
||||
static const unsigned int sn_objs[NUM_SN] = {
|
||||
364, /* "AD_DVCS" */
|
||||
419, /* "AES-128-CBC" */
|
||||
@@ -2395,6 +2396,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
417, /* "CSPName" */
|
||||
1019, /* "ChaCha20" */
|
||||
1018, /* "ChaCha20-Poly1305" */
|
||||
+ 1195, /* "ChaCha20-Poly1305-D" */
|
||||
367, /* "CrlID" */
|
||||
391, /* "DC" */
|
||||
31, /* "DES-CBC" */
|
||||
@@ -3467,7 +3469,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
1093, /* "x509ExtAdmission" */
|
||||
};
|
||||
|
||||
-#define NUM_LN 1186
|
||||
+#define NUM_LN 1187
|
||||
static const unsigned int ln_objs[NUM_LN] = {
|
||||
363, /* "AD Time Stamping" */
|
||||
405, /* "ANSI X9.62" */
|
||||
@@ -3846,6 +3848,7 @@ static const unsigned int ln_objs[NUM_LN] = {
|
||||
883, /* "certificateRevocationList" */
|
||||
1019, /* "chacha20" */
|
||||
1018, /* "chacha20-poly1305" */
|
||||
+ 1195, /* "chacha20-poly1305-draft" */
|
||||
54, /* "challengePassword" */
|
||||
407, /* "characteristic-two-field" */
|
||||
395, /* "clearance" */
|
||||
diff --git a/crypto/objects/obj_mac.num b/crypto/objects/obj_mac.num
|
||||
index 1b6a9c61a1..c81ca25a53 100644
|
||||
--- a/crypto/objects/obj_mac.num
|
||||
+++ b/crypto/objects/obj_mac.num
|
||||
@@ -1192,3 +1192,4 @@ magma_cfb 1191
|
||||
magma_mac 1192
|
||||
hmacWithSHA512_224 1193
|
||||
hmacWithSHA512_256 1194
|
||||
+chacha20_poly1305_draft 1195
|
||||
diff --git a/crypto/objects/objects.txt b/crypto/objects/objects.txt
|
||||
index 6dbc41ce37..581169eda8 100644
|
||||
--- a/crypto/objects/objects.txt
|
||||
+++ b/crypto/objects/objects.txt
|
||||
@@ -1534,6 +1534,7 @@ sm-scheme 104 7 : SM4-CTR : sm4-ctr
|
||||
: AES-192-CBC-HMAC-SHA256 : aes-192-cbc-hmac-sha256
|
||||
: AES-256-CBC-HMAC-SHA256 : aes-256-cbc-hmac-sha256
|
||||
: ChaCha20-Poly1305 : chacha20-poly1305
|
||||
+ : ChaCha20-Poly1305-D : chacha20-poly1305-draft
|
||||
: ChaCha20 : chacha20
|
||||
|
||||
ISO-US 10046 2 1 : dhpublicnumber : X9.42 DH
|
||||
diff --git a/include/openssl/evp.h b/include/openssl/evp.h
|
||||
index dd1117d0fe..accc766b3b 100644
|
||||
--- a/include/openssl/evp.h
|
||||
+++ b/include/openssl/evp.h
|
||||
@@ -915,6 +915,7 @@ const EVP_CIPHER *EVP_camellia_256_ctr(void);
|
||||
const EVP_CIPHER *EVP_chacha20(void);
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void);
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void);
|
||||
# endif
|
||||
# endif
|
||||
|
||||
diff --git a/include/openssl/obj_mac.h b/include/openssl/obj_mac.h
|
||||
index 31fad4640f..f3669a46c9 100644
|
||||
--- a/include/openssl/obj_mac.h
|
||||
+++ b/include/openssl/obj_mac.h
|
||||
@@ -4807,6 +4807,10 @@
|
||||
#define LN_chacha20_poly1305 "chacha20-poly1305"
|
||||
#define NID_chacha20_poly1305 1018
|
||||
|
||||
+#define SN_chacha20_poly1305_draft "ChaCha20-Poly1305-D"
|
||||
+#define LN_chacha20_poly1305_draft "chacha20-poly1305-draft"
|
||||
+#define NID_chacha20_poly1305_draft 1195
|
||||
+
|
||||
#define SN_chacha20 "ChaCha20"
|
||||
#define LN_chacha20 "chacha20"
|
||||
#define NID_chacha20 1019
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 48e1152a27..524614cca2 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -125,6 +125,7 @@ extern "C" {
|
||||
# define SSL_TXT_CAMELLIA256 "CAMELLIA256"
|
||||
# define SSL_TXT_CAMELLIA "CAMELLIA"
|
||||
# define SSL_TXT_CHACHA20 "CHACHA20"
|
||||
+# define SSL_TXT_CHACHA20_D "CHACHA20-D"
|
||||
# define SSL_TXT_GOST "GOST89"
|
||||
# define SSL_TXT_ARIA "ARIA"
|
||||
# define SSL_TXT_ARIA_GCM "ARIAGCM"
|
||||
diff --git a/include/openssl/tls1.h b/include/openssl/tls1.h
|
||||
index e13b5dd4bc..53d43c121e 100644
|
||||
--- a/include/openssl/tls1.h
|
||||
+++ b/include/openssl/tls1.h
|
||||
@@ -597,7 +597,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0x0300C09A
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0x0300C09B
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC13
|
||||
+# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D 0x0300CC14
|
||||
+# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC15
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCA8
|
||||
# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 0x0300CCA9
|
||||
# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCAA
|
||||
@@ -762,6 +767,9 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305 "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_PSK_WITH_CHACHA20_POLY1305 "TLS_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_PSK_WITH_CHACHA20_POLY1305 "TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_DHE_PSK_WITH_CHACHA20_POLY1305 "TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
@@ -1090,7 +1098,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 "ECDH-RSA-CAMELLIA128-SHA256"
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 "ECDH-RSA-CAMELLIA256-SHA384"
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "ECDHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "ECDHE-ECDSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D "DHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305 "ECDHE-RSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "ECDHE-ECDSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305 "DHE-RSA-CHACHA20-POLY1305"
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 99ae48199c..7e36a0d7ea 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -2082,6 +2082,54 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
256,
|
||||
256,
|
||||
},
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aECDSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
{
|
||||
1,
|
||||
TLS1_TXT_PSK_WITH_CHACHA20_POLY1305,
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index b60d67aa0d..ce750c4425 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -43,7 +43,8 @@
|
||||
#define SSL_ENC_CHACHA_IDX 19
|
||||
#define SSL_ENC_ARIA128GCM_IDX 20
|
||||
#define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-#define SSL_ENC_NUM_IDX 22
|
||||
+#define SSL_ENC_CHACHA20_D_IDX 22
|
||||
+#define SSL_ENC_NUM_IDX 23
|
||||
|
||||
/* NB: make sure indices in these tables match values above */
|
||||
|
||||
@@ -76,6 +77,7 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
{SSL_CHACHA20POLY1305, NID_chacha20_poly1305}, /* SSL_ENC_CHACHA_IDX 19 */
|
||||
{SSL_ARIA128GCM, NID_aria_128_gcm}, /* SSL_ENC_ARIA128GCM_IDX 20 */
|
||||
{SSL_ARIA256GCM, NID_aria_256_gcm}, /* SSL_ENC_ARIA256GCM_IDX 21 */
|
||||
+ {SSL_CHACHA20POLY1305_D, NID_chacha20_poly1305_draft}, /* SSL_ENC_CHACHA20POLY1305_IDX 22 */
|
||||
};
|
||||
|
||||
static const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
@@ -275,6 +277,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_CAMELLIA256, NULL, 0, 0, 0, SSL_CAMELLIA256},
|
||||
{0, SSL_TXT_CAMELLIA, NULL, 0, 0, 0, SSL_CAMELLIA},
|
||||
{0, SSL_TXT_CHACHA20, NULL, 0, 0, 0, SSL_CHACHA20},
|
||||
+ {0, SSL_TXT_CHACHA20_D, NULL, 0, 0, 0, SSL_CHACHA20POLY1305_D},
|
||||
|
||||
{0, SSL_TXT_ARIA, NULL, 0, 0, 0, SSL_ARIA},
|
||||
{0, SSL_TXT_ARIA_GCM, NULL, 0, 0, 0, SSL_ARIA128GCM | SSL_ARIA256GCM},
|
||||
@@ -1791,6 +1794,9 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
case SSL_CHACHA20POLY1305:
|
||||
enc = "CHACHA20/POLY1305(256)";
|
||||
break;
|
||||
+ case SSL_CHACHA20POLY1305_D:
|
||||
+ enc = "CHACHA20/POLY1305-Draft(256)";
|
||||
+ break;
|
||||
default:
|
||||
enc = "unknown";
|
||||
break;
|
||||
@@ -2115,7 +2121,7 @@ int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 16;
|
||||
} else if (c->algorithm_enc & (SSL_AES128CCM8 | SSL_AES256CCM8)) {
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 8;
|
||||
- } else if (c->algorithm_enc & SSL_CHACHA20POLY1305) {
|
||||
+ } else if (c->algorithm_enc & (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)) {
|
||||
out = 16;
|
||||
} else if (c->algorithm_mac & SSL_AEAD) {
|
||||
/* We're supposed to have handled all the AEAD modes above */
|
||||
diff --git a/ssl/ssl_locl.h b/ssl/ssl_locl.h
|
||||
index 33db1460ab..00c5ee4cff 100644
|
||||
--- a/ssl/ssl_locl.h
|
||||
+++ b/ssl/ssl_locl.h
|
||||
@@ -230,12 +230,13 @@
|
||||
# define SSL_CHACHA20POLY1305 0x00080000U
|
||||
# define SSL_ARIA128GCM 0x00100000U
|
||||
# define SSL_ARIA256GCM 0x00200000U
|
||||
+# define SSL_CHACHA20POLY1305_D 0x00400000U
|
||||
|
||||
# define SSL_AESGCM (SSL_AES128GCM | SSL_AES256GCM)
|
||||
# define SSL_AESCCM (SSL_AES128CCM | SSL_AES256CCM | SSL_AES128CCM8 | SSL_AES256CCM8)
|
||||
# define SSL_AES (SSL_AES128|SSL_AES256|SSL_AESGCM|SSL_AESCCM)
|
||||
# define SSL_CAMELLIA (SSL_CAMELLIA128|SSL_CAMELLIA256)
|
||||
-# define SSL_CHACHA20 (SSL_CHACHA20POLY1305)
|
||||
+# define SSL_CHACHA20 (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)
|
||||
# define SSL_ARIAGCM (SSL_ARIA128GCM | SSL_ARIA256GCM)
|
||||
# define SSL_ARIA (SSL_ARIAGCM)
|
||||
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index 474f9f950d..196c8f0ea4 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -4580,3 +4580,4 @@ EVP_PKEY_meth_get_digest_custom 4533 1_1_1 EXIST::FUNCTION:
|
||||
OPENSSL_INIT_set_config_filename 4534 1_1_1b EXIST::FUNCTION:STDIO
|
||||
OPENSSL_INIT_set_config_file_flags 4535 1_1_1b EXIST::FUNCTION:STDIO
|
||||
EVP_PKEY_get0_engine 4536 1_1_1c EXIST::FUNCTION:ENGINE
|
||||
+EVP_chacha20_poly1305_draft 4537 1_1_1c EXIST::FUNCTION:CHACHA,POLY1305
|
||||
@@ -0,0 +1,34 @@
|
||||
--- a/ssl/s3_lib.c 2019-04-25 00:17:46.000000000 +0200
|
||||
+++ b/ssl/s3_lib.c 2019-04-25 00:50:25.000000000 +0200
|
||||
@@ -4181,13 +4181,13 @@
|
||||
temporarily prioritize all ChaCha20 ciphers in the servers list. */
|
||||
if (s->options & SSL_OP_PRIORITIZE_CHACHA && sk_SSL_CIPHER_num(clnt) > 0) {
|
||||
c = sk_SSL_CIPHER_value(clnt, 0);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
+ if (c->algorithm_enc & SSL_CHACHA20) {
|
||||
/* ChaCha20 is client preferred, check server... */
|
||||
int num = sk_SSL_CIPHER_num(srvr);
|
||||
int found = 0;
|
||||
for (i = 0; i < num; i++) {
|
||||
c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
+ if (c->algorithm_enc & SSL_CHACHA20) {
|
||||
found = 1;
|
||||
break;
|
||||
}
|
||||
@@ -4200,13 +4200,13 @@
|
||||
sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
for (i++; i < num; i++) {
|
||||
c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305)
|
||||
+ if (c->algorithm_enc & SSL_CHACHA20)
|
||||
sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
}
|
||||
/* Pull in the rest */
|
||||
for (i = 0; i < num; i++) {
|
||||
c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc != SSL_CHACHA20POLY1305)
|
||||
+ if (!(c->algorithm_enc & SSL_CHACHA20))
|
||||
sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
}
|
||||
prio = prio_chacha;
|
||||
@@ -0,0 +1,509 @@
|
||||
diff --git a/crypto/evp/c_allc.c b/crypto/evp/c_allc.c
|
||||
index 086b3c4d51..5699901f7d 100644
|
||||
--- a/crypto/evp/c_allc.c
|
||||
+++ b/crypto/evp/c_allc.c
|
||||
@@ -261,6 +261,7 @@ void openssl_add_all_ciphers_int(void)
|
||||
EVP_add_cipher(EVP_chacha20());
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
EVP_add_cipher(EVP_chacha20_poly1305());
|
||||
+ EVP_add_cipher(EVP_chacha20_poly1305_draft());
|
||||
# endif
|
||||
#endif
|
||||
}
|
||||
diff --git a/crypto/evp/e_chacha20_poly1305.c b/crypto/evp/e_chacha20_poly1305.c
|
||||
index 600365d2f0..fce66d074d 100644
|
||||
--- a/crypto/evp/e_chacha20_poly1305.c
|
||||
+++ b/crypto/evp/e_chacha20_poly1305.c
|
||||
@@ -156,6 +156,7 @@ typedef struct {
|
||||
struct { uint64_t aad, text; } len;
|
||||
int aad, mac_inited, tag_len, nonce_len;
|
||||
size_t tls_payload_length;
|
||||
+ unsigned char draft:1;
|
||||
} EVP_CHACHA_AEAD_CTX;
|
||||
|
||||
# define NO_TLS_PAYLOAD_LENGTH ((size_t)-1)
|
||||
@@ -176,6 +177,7 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
actx->aad = 0;
|
||||
actx->mac_inited = 0;
|
||||
actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 0;
|
||||
|
||||
if (iv != NULL) {
|
||||
unsigned char temp[CHACHA_CTR_SIZE] = { 0 };
|
||||
@@ -197,6 +199,27 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
return 1;
|
||||
}
|
||||
|
||||
+static int chacha20_poly1305_draft_init_key(EVP_CIPHER_CTX *ctx,
|
||||
+ const unsigned char *inkey,
|
||||
+ const unsigned char *iv, int enc)
|
||||
+{
|
||||
+ EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
+
|
||||
+ if (!inkey)
|
||||
+ return 1;
|
||||
+
|
||||
+ actx->len.aad = 0;
|
||||
+ actx->len.text = 0;
|
||||
+ actx->aad = 0;
|
||||
+ actx->mac_inited = 0;
|
||||
+ actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 1;
|
||||
+
|
||||
+ chacha_init_key(ctx, inkey, NULL, enc);
|
||||
+
|
||||
+ return 1;
|
||||
+}
|
||||
+
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
|
||||
# if defined(POLY1305_ASM) && (defined(__x86_64) || defined(__x86_64__) || \
|
||||
@@ -367,10 +390,11 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
{
|
||||
EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
size_t rem, plen = actx->tls_payload_length;
|
||||
+ uint64_t thirteen = EVP_AEAD_TLS1_AAD_LEN;
|
||||
|
||||
if (!actx->mac_inited) {
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
- if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL)
|
||||
+ if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL && !actx->draft)
|
||||
return chacha20_poly1305_tls_cipher(ctx, out, in, len);
|
||||
# endif
|
||||
actx->key.counter[0] = 0;
|
||||
@@ -397,9 +421,14 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
return len;
|
||||
} else { /* plain- or ciphertext */
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
@@ -432,40 +461,52 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
} is_endian = { 1 };
|
||||
unsigned char temp[POLY1305_BLOCK_SIZE];
|
||||
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.text;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ }
|
||||
+
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
- if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (!actx->draft) {
|
||||
+ if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
|
||||
- if (is_endian.little) {
|
||||
- Poly1305_Update(POLY1305_ctx(actx),
|
||||
- (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
- } else {
|
||||
- temp[0] = (unsigned char)(actx->len.aad);
|
||||
- temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
- temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
- temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
- temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
- temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
- temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
- temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
-
|
||||
- temp[8] = (unsigned char)(actx->len.text);
|
||||
- temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
- temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
- temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
- temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
- temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
- temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
- temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
-
|
||||
- Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ if (is_endian.little) {
|
||||
+ Poly1305_Update(POLY1305_ctx(actx),
|
||||
+ (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
+ } else {
|
||||
+ temp[0] = (unsigned char)(actx->len.aad);
|
||||
+ temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
+ temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
+ temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
+ temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
+ temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
+ temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
+ temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
+
|
||||
+ temp[8] = (unsigned char)(actx->len.text);
|
||||
+ temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
+ temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
+ temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
+ temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
+ temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
+ temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
+ temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
+
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ }
|
||||
}
|
||||
Poly1305_Final(POLY1305_ctx(actx), ctx->encrypt ? actx->tag
|
||||
: temp);
|
||||
@@ -535,12 +576,14 @@ static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IVLEN:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg <= 0 || arg > CHACHA20_POLY1305_MAX_IVLEN)
|
||||
return 0;
|
||||
actx->nonce_len = arg;
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IV_FIXED:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg != 12)
|
||||
return 0;
|
||||
actx->nonce[0] = actx->key.counter[1]
|
||||
@@ -624,9 +667,32 @@ static EVP_CIPHER chacha20_poly1305 = {
|
||||
NULL /* app_data */
|
||||
};
|
||||
|
||||
+static EVP_CIPHER chacha20_poly1305_draft = {
|
||||
+ NID_chacha20_poly1305_draft,
|
||||
+ 1, /* block_size */
|
||||
+ CHACHA_KEY_SIZE, /* key_len */
|
||||
+ 0, /* iv_len, none */
|
||||
+ EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_CUSTOM_IV |
|
||||
+ EVP_CIPH_ALWAYS_CALL_INIT | EVP_CIPH_CTRL_INIT |
|
||||
+ EVP_CIPH_CUSTOM_COPY | EVP_CIPH_FLAG_CUSTOM_CIPHER,
|
||||
+ chacha20_poly1305_draft_init_key,
|
||||
+ chacha20_poly1305_cipher,
|
||||
+ chacha20_poly1305_cleanup,
|
||||
+ 0, /* 0 moves context-specific structure allocation to ctrl */
|
||||
+ NULL, /* set_asn1_parameters */
|
||||
+ NULL, /* get_asn1_parameters */
|
||||
+ chacha20_poly1305_ctrl,
|
||||
+ NULL /* app_data */
|
||||
+};
|
||||
+
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void)
|
||||
{
|
||||
return(&chacha20_poly1305);
|
||||
}
|
||||
+
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void)
|
||||
+{
|
||||
+ return(&chacha20_poly1305_draft);
|
||||
+}
|
||||
# endif
|
||||
#endif
|
||||
diff --git a/crypto/objects/obj_dat.h b/crypto/objects/obj_dat.h
|
||||
index ea91db660b..f2479dcfb8 100644
|
||||
--- a/crypto/objects/obj_dat.h
|
||||
+++ b/crypto/objects/obj_dat.h
|
||||
@@ -1078,7 +1078,7 @@ static const unsigned char so[7762] = {
|
||||
0x2A,0x86,0x48,0x86,0xF7,0x0D,0x02,0x0D, /* [ 7753] OBJ_hmacWithSHA512_256 */
|
||||
};
|
||||
|
||||
-#define NUM_NID 1195
|
||||
+#define NUM_NID 1196
|
||||
static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"UNDEF", "undefined", NID_undef},
|
||||
{"rsadsi", "RSA Data Security, Inc.", NID_rsadsi, 6, &so[0]},
|
||||
@@ -2275,9 +2275,10 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"magma-mac", "magma-mac", NID_magma_mac},
|
||||
{"hmacWithSHA512-224", "hmacWithSHA512-224", NID_hmacWithSHA512_224, 8, &so[7745]},
|
||||
{"hmacWithSHA512-256", "hmacWithSHA512-256", NID_hmacWithSHA512_256, 8, &so[7753]},
|
||||
+ {"ChaCha20-Poly1305-D", "chacha20-poly1305-draft", NID_chacha20_poly1305_draft},
|
||||
};
|
||||
|
||||
-#define NUM_SN 1186
|
||||
+#define NUM_SN 1187
|
||||
static const unsigned int sn_objs[NUM_SN] = {
|
||||
364, /* "AD_DVCS" */
|
||||
419, /* "AES-128-CBC" */
|
||||
@@ -2395,6 +2396,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
417, /* "CSPName" */
|
||||
1019, /* "ChaCha20" */
|
||||
1018, /* "ChaCha20-Poly1305" */
|
||||
+ 1195, /* "ChaCha20-Poly1305-D" */
|
||||
367, /* "CrlID" */
|
||||
391, /* "DC" */
|
||||
31, /* "DES-CBC" */
|
||||
@@ -3467,7 +3469,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
1093, /* "x509ExtAdmission" */
|
||||
};
|
||||
|
||||
-#define NUM_LN 1186
|
||||
+#define NUM_LN 1187
|
||||
static const unsigned int ln_objs[NUM_LN] = {
|
||||
363, /* "AD Time Stamping" */
|
||||
405, /* "ANSI X9.62" */
|
||||
@@ -3846,6 +3848,7 @@ static const unsigned int ln_objs[NUM_LN] = {
|
||||
883, /* "certificateRevocationList" */
|
||||
1019, /* "chacha20" */
|
||||
1018, /* "chacha20-poly1305" */
|
||||
+ 1195, /* "chacha20-poly1305-draft" */
|
||||
54, /* "challengePassword" */
|
||||
407, /* "characteristic-two-field" */
|
||||
395, /* "clearance" */
|
||||
diff --git a/crypto/objects/obj_mac.num b/crypto/objects/obj_mac.num
|
||||
index 1b6a9c61a1..c81ca25a53 100644
|
||||
--- a/crypto/objects/obj_mac.num
|
||||
+++ b/crypto/objects/obj_mac.num
|
||||
@@ -1192,3 +1192,4 @@ magma_cfb 1191
|
||||
magma_mac 1192
|
||||
hmacWithSHA512_224 1193
|
||||
hmacWithSHA512_256 1194
|
||||
+chacha20_poly1305_draft 1195
|
||||
diff --git a/crypto/objects/objects.txt b/crypto/objects/objects.txt
|
||||
index 5b2bb54eb9..b6523a6993 100644
|
||||
--- a/crypto/objects/objects.txt
|
||||
+++ b/crypto/objects/objects.txt
|
||||
@@ -1534,6 +1534,7 @@ sm-scheme 104 7 : SM4-CTR : sm4-ctr
|
||||
: AES-192-CBC-HMAC-SHA256 : aes-192-cbc-hmac-sha256
|
||||
: AES-256-CBC-HMAC-SHA256 : aes-256-cbc-hmac-sha256
|
||||
: ChaCha20-Poly1305 : chacha20-poly1305
|
||||
+ : ChaCha20-Poly1305-D : chacha20-poly1305-draft
|
||||
: ChaCha20 : chacha20
|
||||
|
||||
ISO-US 10046 2 1 : dhpublicnumber : X9.42 DH
|
||||
diff --git a/include/openssl/evp.h b/include/openssl/evp.h
|
||||
index dd1117d0fe..accc766b3b 100644
|
||||
--- a/include/openssl/evp.h
|
||||
+++ b/include/openssl/evp.h
|
||||
@@ -915,6 +915,7 @@ const EVP_CIPHER *EVP_camellia_256_ctr(void);
|
||||
const EVP_CIPHER *EVP_chacha20(void);
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void);
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void);
|
||||
# endif
|
||||
# endif
|
||||
|
||||
diff --git a/include/openssl/obj_mac.h b/include/openssl/obj_mac.h
|
||||
index 47dafe48d0..18805c7562 100644
|
||||
--- a/include/openssl/obj_mac.h
|
||||
+++ b/include/openssl/obj_mac.h
|
||||
@@ -4807,6 +4807,10 @@
|
||||
#define LN_chacha20_poly1305 "chacha20-poly1305"
|
||||
#define NID_chacha20_poly1305 1018
|
||||
|
||||
+#define SN_chacha20_poly1305_draft "ChaCha20-Poly1305-D"
|
||||
+#define LN_chacha20_poly1305_draft "chacha20-poly1305-draft"
|
||||
+#define NID_chacha20_poly1305_draft 1195
|
||||
+
|
||||
#define SN_chacha20 "ChaCha20"
|
||||
#define LN_chacha20 "chacha20"
|
||||
#define NID_chacha20 1019
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 6724ccf2d2..0365760200 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -125,6 +125,7 @@ extern "C" {
|
||||
# define SSL_TXT_CAMELLIA256 "CAMELLIA256"
|
||||
# define SSL_TXT_CAMELLIA "CAMELLIA"
|
||||
# define SSL_TXT_CHACHA20 "CHACHA20"
|
||||
+# define SSL_TXT_CHACHA20_D "CHACHA20-D"
|
||||
# define SSL_TXT_GOST "GOST89"
|
||||
# define SSL_TXT_ARIA "ARIA"
|
||||
# define SSL_TXT_ARIA_GCM "ARIAGCM"
|
||||
diff --git a/include/openssl/tls1.h b/include/openssl/tls1.h
|
||||
index e13b5dd4bc..53d43c121e 100644
|
||||
--- a/include/openssl/tls1.h
|
||||
+++ b/include/openssl/tls1.h
|
||||
@@ -597,7 +597,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0x0300C09A
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0x0300C09B
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC13
|
||||
+# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D 0x0300CC14
|
||||
+# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC15
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCA8
|
||||
# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 0x0300CCA9
|
||||
# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCAA
|
||||
@@ -762,6 +767,9 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305 "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_PSK_WITH_CHACHA20_POLY1305 "TLS_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_PSK_WITH_CHACHA20_POLY1305 "TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_DHE_PSK_WITH_CHACHA20_POLY1305 "TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
@@ -1090,7 +1098,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 "ECDH-RSA-CAMELLIA128-SHA256"
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 "ECDH-RSA-CAMELLIA256-SHA384"
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "ECDHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "ECDHE-ECDSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D "DHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305 "ECDHE-RSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "ECDHE-ECDSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305 "DHE-RSA-CHACHA20-POLY1305"
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index d7dbf99954..ee3293b5ce 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -2082,6 +2082,54 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
256,
|
||||
256,
|
||||
},
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aECDSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
{
|
||||
1,
|
||||
TLS1_TXT_PSK_WITH_CHACHA20_POLY1305,
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index b60d67aa0d..ce750c4425 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -43,7 +43,8 @@
|
||||
#define SSL_ENC_CHACHA_IDX 19
|
||||
#define SSL_ENC_ARIA128GCM_IDX 20
|
||||
#define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-#define SSL_ENC_NUM_IDX 22
|
||||
+#define SSL_ENC_CHACHA20_D_IDX 22
|
||||
+#define SSL_ENC_NUM_IDX 23
|
||||
|
||||
/* NB: make sure indices in these tables match values above */
|
||||
|
||||
@@ -76,6 +77,7 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
{SSL_CHACHA20POLY1305, NID_chacha20_poly1305}, /* SSL_ENC_CHACHA_IDX 19 */
|
||||
{SSL_ARIA128GCM, NID_aria_128_gcm}, /* SSL_ENC_ARIA128GCM_IDX 20 */
|
||||
{SSL_ARIA256GCM, NID_aria_256_gcm}, /* SSL_ENC_ARIA256GCM_IDX 21 */
|
||||
+ {SSL_CHACHA20POLY1305_D, NID_chacha20_poly1305_draft}, /* SSL_ENC_CHACHA20POLY1305_IDX 22 */
|
||||
};
|
||||
|
||||
static const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
@@ -275,6 +277,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_CAMELLIA256, NULL, 0, 0, 0, SSL_CAMELLIA256},
|
||||
{0, SSL_TXT_CAMELLIA, NULL, 0, 0, 0, SSL_CAMELLIA},
|
||||
{0, SSL_TXT_CHACHA20, NULL, 0, 0, 0, SSL_CHACHA20},
|
||||
+ {0, SSL_TXT_CHACHA20_D, NULL, 0, 0, 0, SSL_CHACHA20POLY1305_D},
|
||||
|
||||
{0, SSL_TXT_ARIA, NULL, 0, 0, 0, SSL_ARIA},
|
||||
{0, SSL_TXT_ARIA_GCM, NULL, 0, 0, 0, SSL_ARIA128GCM | SSL_ARIA256GCM},
|
||||
@@ -1791,6 +1794,9 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
case SSL_CHACHA20POLY1305:
|
||||
enc = "CHACHA20/POLY1305(256)";
|
||||
break;
|
||||
+ case SSL_CHACHA20POLY1305_D:
|
||||
+ enc = "CHACHA20/POLY1305-Draft(256)";
|
||||
+ break;
|
||||
default:
|
||||
enc = "unknown";
|
||||
break;
|
||||
@@ -2115,7 +2121,7 @@ int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 16;
|
||||
} else if (c->algorithm_enc & (SSL_AES128CCM8 | SSL_AES256CCM8)) {
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 8;
|
||||
- } else if (c->algorithm_enc & SSL_CHACHA20POLY1305) {
|
||||
+ } else if (c->algorithm_enc & (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)) {
|
||||
out = 16;
|
||||
} else if (c->algorithm_mac & SSL_AEAD) {
|
||||
/* We're supposed to have handled all the AEAD modes above */
|
||||
diff --git a/ssl/ssl_locl.h b/ssl/ssl_locl.h
|
||||
index fa0f6d018c..f2a95c263a 100644
|
||||
--- a/ssl/ssl_locl.h
|
||||
+++ b/ssl/ssl_locl.h
|
||||
@@ -230,12 +230,13 @@
|
||||
# define SSL_CHACHA20POLY1305 0x00080000U
|
||||
# define SSL_ARIA128GCM 0x00100000U
|
||||
# define SSL_ARIA256GCM 0x00200000U
|
||||
+# define SSL_CHACHA20POLY1305_D 0x00400000U
|
||||
|
||||
# define SSL_AESGCM (SSL_AES128GCM | SSL_AES256GCM)
|
||||
# define SSL_AESCCM (SSL_AES128CCM | SSL_AES256CCM | SSL_AES128CCM8 | SSL_AES256CCM8)
|
||||
# define SSL_AES (SSL_AES128|SSL_AES256|SSL_AESGCM|SSL_AESCCM)
|
||||
# define SSL_CAMELLIA (SSL_CAMELLIA128|SSL_CAMELLIA256)
|
||||
-# define SSL_CHACHA20 (SSL_CHACHA20POLY1305)
|
||||
+# define SSL_CHACHA20 (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)
|
||||
# define SSL_ARIAGCM (SSL_ARIA128GCM | SSL_ARIA256GCM)
|
||||
# define SSL_ARIA (SSL_ARIAGCM)
|
||||
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index bf8b803c4c..d90d510096 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -4582,3 +4582,4 @@ OPENSSL_INIT_set_config_file_flags 4535 1_1_1b EXIST::FUNCTION:STDIO
|
||||
EVP_PKEY_get0_engine 4536 1_1_1c EXIST::FUNCTION:ENGINE
|
||||
X509_get0_authority_serial 4537 1_1_1d EXIST::FUNCTION:
|
||||
X509_get0_authority_issuer 4538 1_1_1d EXIST::FUNCTION:
|
||||
+EVP_chacha20_poly1305_draft 4539 1_1_1d EXIST::FUNCTION:CHACHA,POLY1305
|
||||
@@ -0,0 +1,509 @@
|
||||
diff --git a/crypto/evp/c_allc.c b/crypto/evp/c_allc.c
|
||||
index 086b3c4d51..5699901f7d 100644
|
||||
--- a/crypto/evp/c_allc.c
|
||||
+++ b/crypto/evp/c_allc.c
|
||||
@@ -261,6 +261,7 @@ void openssl_add_all_ciphers_int(void)
|
||||
EVP_add_cipher(EVP_chacha20());
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
EVP_add_cipher(EVP_chacha20_poly1305());
|
||||
+ EVP_add_cipher(EVP_chacha20_poly1305_draft());
|
||||
# endif
|
||||
#endif
|
||||
}
|
||||
diff --git a/crypto/evp/e_chacha20_poly1305.c b/crypto/evp/e_chacha20_poly1305.c
|
||||
index 600365d2f0..fce66d074d 100644
|
||||
--- a/crypto/evp/e_chacha20_poly1305.c
|
||||
+++ b/crypto/evp/e_chacha20_poly1305.c
|
||||
@@ -156,6 +156,7 @@ typedef struct {
|
||||
struct { uint64_t aad, text; } len;
|
||||
int aad, mac_inited, tag_len, nonce_len;
|
||||
size_t tls_payload_length;
|
||||
+ unsigned char draft:1;
|
||||
} EVP_CHACHA_AEAD_CTX;
|
||||
|
||||
# define NO_TLS_PAYLOAD_LENGTH ((size_t)-1)
|
||||
@@ -176,6 +177,7 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
actx->aad = 0;
|
||||
actx->mac_inited = 0;
|
||||
actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 0;
|
||||
|
||||
if (iv != NULL) {
|
||||
unsigned char temp[CHACHA_CTR_SIZE] = { 0 };
|
||||
@@ -197,6 +199,27 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
return 1;
|
||||
}
|
||||
|
||||
+static int chacha20_poly1305_draft_init_key(EVP_CIPHER_CTX *ctx,
|
||||
+ const unsigned char *inkey,
|
||||
+ const unsigned char *iv, int enc)
|
||||
+{
|
||||
+ EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
+
|
||||
+ if (!inkey)
|
||||
+ return 1;
|
||||
+
|
||||
+ actx->len.aad = 0;
|
||||
+ actx->len.text = 0;
|
||||
+ actx->aad = 0;
|
||||
+ actx->mac_inited = 0;
|
||||
+ actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 1;
|
||||
+
|
||||
+ chacha_init_key(ctx, inkey, NULL, enc);
|
||||
+
|
||||
+ return 1;
|
||||
+}
|
||||
+
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
|
||||
# if defined(POLY1305_ASM) && (defined(__x86_64) || defined(__x86_64__) || \
|
||||
@@ -367,10 +390,11 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
{
|
||||
EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
size_t rem, plen = actx->tls_payload_length;
|
||||
+ uint64_t thirteen = EVP_AEAD_TLS1_AAD_LEN;
|
||||
|
||||
if (!actx->mac_inited) {
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
- if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL)
|
||||
+ if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL && !actx->draft)
|
||||
return chacha20_poly1305_tls_cipher(ctx, out, in, len);
|
||||
# endif
|
||||
actx->key.counter[0] = 0;
|
||||
@@ -397,9 +421,14 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
return len;
|
||||
} else { /* plain- or ciphertext */
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
@@ -432,40 +461,52 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
} is_endian = { 1 };
|
||||
unsigned char temp[POLY1305_BLOCK_SIZE];
|
||||
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.text;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ }
|
||||
+
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
- if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (!actx->draft) {
|
||||
+ if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
|
||||
- if (is_endian.little) {
|
||||
- Poly1305_Update(POLY1305_ctx(actx),
|
||||
- (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
- } else {
|
||||
- temp[0] = (unsigned char)(actx->len.aad);
|
||||
- temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
- temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
- temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
- temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
- temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
- temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
- temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
-
|
||||
- temp[8] = (unsigned char)(actx->len.text);
|
||||
- temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
- temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
- temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
- temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
- temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
- temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
- temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
-
|
||||
- Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ if (is_endian.little) {
|
||||
+ Poly1305_Update(POLY1305_ctx(actx),
|
||||
+ (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
+ } else {
|
||||
+ temp[0] = (unsigned char)(actx->len.aad);
|
||||
+ temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
+ temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
+ temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
+ temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
+ temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
+ temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
+ temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
+
|
||||
+ temp[8] = (unsigned char)(actx->len.text);
|
||||
+ temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
+ temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
+ temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
+ temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
+ temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
+ temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
+ temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
+
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ }
|
||||
}
|
||||
Poly1305_Final(POLY1305_ctx(actx), ctx->encrypt ? actx->tag
|
||||
: temp);
|
||||
@@ -535,12 +576,14 @@ static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IVLEN:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg <= 0 || arg > CHACHA20_POLY1305_MAX_IVLEN)
|
||||
return 0;
|
||||
actx->nonce_len = arg;
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IV_FIXED:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg != 12)
|
||||
return 0;
|
||||
actx->nonce[0] = actx->key.counter[1]
|
||||
@@ -624,9 +667,32 @@ static EVP_CIPHER chacha20_poly1305 = {
|
||||
NULL /* app_data */
|
||||
};
|
||||
|
||||
+static EVP_CIPHER chacha20_poly1305_draft = {
|
||||
+ NID_chacha20_poly1305_draft,
|
||||
+ 1, /* block_size */
|
||||
+ CHACHA_KEY_SIZE, /* key_len */
|
||||
+ 0, /* iv_len, none */
|
||||
+ EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_CUSTOM_IV |
|
||||
+ EVP_CIPH_ALWAYS_CALL_INIT | EVP_CIPH_CTRL_INIT |
|
||||
+ EVP_CIPH_CUSTOM_COPY | EVP_CIPH_FLAG_CUSTOM_CIPHER,
|
||||
+ chacha20_poly1305_draft_init_key,
|
||||
+ chacha20_poly1305_cipher,
|
||||
+ chacha20_poly1305_cleanup,
|
||||
+ 0, /* 0 moves context-specific structure allocation to ctrl */
|
||||
+ NULL, /* set_asn1_parameters */
|
||||
+ NULL, /* get_asn1_parameters */
|
||||
+ chacha20_poly1305_ctrl,
|
||||
+ NULL /* app_data */
|
||||
+};
|
||||
+
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void)
|
||||
{
|
||||
return(&chacha20_poly1305);
|
||||
}
|
||||
+
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void)
|
||||
+{
|
||||
+ return(&chacha20_poly1305_draft);
|
||||
+}
|
||||
# endif
|
||||
#endif
|
||||
diff --git a/crypto/objects/obj_dat.h b/crypto/objects/obj_dat.h
|
||||
index ea91db660b..f2479dcfb8 100644
|
||||
--- a/crypto/objects/obj_dat.h
|
||||
+++ b/crypto/objects/obj_dat.h
|
||||
@@ -1078,7 +1078,7 @@ static const unsigned char so[7762] = {
|
||||
0x2A,0x86,0x48,0x86,0xF7,0x0D,0x02,0x0D, /* [ 7753] OBJ_hmacWithSHA512_256 */
|
||||
};
|
||||
|
||||
-#define NUM_NID 1195
|
||||
+#define NUM_NID 1196
|
||||
static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"UNDEF", "undefined", NID_undef},
|
||||
{"rsadsi", "RSA Data Security, Inc.", NID_rsadsi, 6, &so[0]},
|
||||
@@ -2275,9 +2275,10 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"magma-mac", "magma-mac", NID_magma_mac},
|
||||
{"hmacWithSHA512-224", "hmacWithSHA512-224", NID_hmacWithSHA512_224, 8, &so[7745]},
|
||||
{"hmacWithSHA512-256", "hmacWithSHA512-256", NID_hmacWithSHA512_256, 8, &so[7753]},
|
||||
+ {"ChaCha20-Poly1305-D", "chacha20-poly1305-draft", NID_chacha20_poly1305_draft},
|
||||
};
|
||||
|
||||
-#define NUM_SN 1186
|
||||
+#define NUM_SN 1187
|
||||
static const unsigned int sn_objs[NUM_SN] = {
|
||||
364, /* "AD_DVCS" */
|
||||
419, /* "AES-128-CBC" */
|
||||
@@ -2395,6 +2396,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
417, /* "CSPName" */
|
||||
1019, /* "ChaCha20" */
|
||||
1018, /* "ChaCha20-Poly1305" */
|
||||
+ 1195, /* "ChaCha20-Poly1305-D" */
|
||||
367, /* "CrlID" */
|
||||
391, /* "DC" */
|
||||
31, /* "DES-CBC" */
|
||||
@@ -3467,7 +3469,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
1093, /* "x509ExtAdmission" */
|
||||
};
|
||||
|
||||
-#define NUM_LN 1186
|
||||
+#define NUM_LN 1187
|
||||
static const unsigned int ln_objs[NUM_LN] = {
|
||||
363, /* "AD Time Stamping" */
|
||||
405, /* "ANSI X9.62" */
|
||||
@@ -3846,6 +3848,7 @@ static const unsigned int ln_objs[NUM_LN] = {
|
||||
883, /* "certificateRevocationList" */
|
||||
1019, /* "chacha20" */
|
||||
1018, /* "chacha20-poly1305" */
|
||||
+ 1195, /* "chacha20-poly1305-draft" */
|
||||
54, /* "challengePassword" */
|
||||
407, /* "characteristic-two-field" */
|
||||
395, /* "clearance" */
|
||||
diff --git a/crypto/objects/obj_mac.num b/crypto/objects/obj_mac.num
|
||||
index 1b6a9c61a1..c81ca25a53 100644
|
||||
--- a/crypto/objects/obj_mac.num
|
||||
+++ b/crypto/objects/obj_mac.num
|
||||
@@ -1192,3 +1192,4 @@ magma_cfb 1191
|
||||
magma_mac 1192
|
||||
hmacWithSHA512_224 1193
|
||||
hmacWithSHA512_256 1194
|
||||
+chacha20_poly1305_draft 1195
|
||||
diff --git a/crypto/objects/objects.txt b/crypto/objects/objects.txt
|
||||
index 5b2bb54eb9..b6523a6993 100644
|
||||
--- a/crypto/objects/objects.txt
|
||||
+++ b/crypto/objects/objects.txt
|
||||
@@ -1534,6 +1534,7 @@ sm-scheme 104 7 : SM4-CTR : sm4-ctr
|
||||
: AES-192-CBC-HMAC-SHA256 : aes-192-cbc-hmac-sha256
|
||||
: AES-256-CBC-HMAC-SHA256 : aes-256-cbc-hmac-sha256
|
||||
: ChaCha20-Poly1305 : chacha20-poly1305
|
||||
+ : ChaCha20-Poly1305-D : chacha20-poly1305-draft
|
||||
: ChaCha20 : chacha20
|
||||
|
||||
ISO-US 10046 2 1 : dhpublicnumber : X9.42 DH
|
||||
diff --git a/include/openssl/evp.h b/include/openssl/evp.h
|
||||
index dd1117d0fe..accc766b3b 100644
|
||||
--- a/include/openssl/evp.h
|
||||
+++ b/include/openssl/evp.h
|
||||
@@ -915,6 +915,7 @@ const EVP_CIPHER *EVP_camellia_256_ctr(void);
|
||||
const EVP_CIPHER *EVP_chacha20(void);
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void);
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void);
|
||||
# endif
|
||||
# endif
|
||||
|
||||
diff --git a/include/openssl/obj_mac.h b/include/openssl/obj_mac.h
|
||||
index 47dafe48d0..18805c7562 100644
|
||||
--- a/include/openssl/obj_mac.h
|
||||
+++ b/include/openssl/obj_mac.h
|
||||
@@ -4807,6 +4807,10 @@
|
||||
#define LN_chacha20_poly1305 "chacha20-poly1305"
|
||||
#define NID_chacha20_poly1305 1018
|
||||
|
||||
+#define SN_chacha20_poly1305_draft "ChaCha20-Poly1305-D"
|
||||
+#define LN_chacha20_poly1305_draft "chacha20-poly1305-draft"
|
||||
+#define NID_chacha20_poly1305_draft 1195
|
||||
+
|
||||
#define SN_chacha20 "ChaCha20"
|
||||
#define LN_chacha20 "chacha20"
|
||||
#define NID_chacha20 1019
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 6724ccf2d2..0365760200 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -125,6 +125,7 @@ extern "C" {
|
||||
# define SSL_TXT_CAMELLIA256 "CAMELLIA256"
|
||||
# define SSL_TXT_CAMELLIA "CAMELLIA"
|
||||
# define SSL_TXT_CHACHA20 "CHACHA20"
|
||||
+# define SSL_TXT_CHACHA20_D "CHACHA20-D"
|
||||
# define SSL_TXT_GOST "GOST89"
|
||||
# define SSL_TXT_ARIA "ARIA"
|
||||
# define SSL_TXT_ARIA_GCM "ARIAGCM"
|
||||
diff --git a/include/openssl/tls1.h b/include/openssl/tls1.h
|
||||
index e13b5dd4bc..53d43c121e 100644
|
||||
--- a/include/openssl/tls1.h
|
||||
+++ b/include/openssl/tls1.h
|
||||
@@ -597,7 +597,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0x0300C09A
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0x0300C09B
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC13
|
||||
+# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D 0x0300CC14
|
||||
+# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC15
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCA8
|
||||
# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 0x0300CCA9
|
||||
# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCAA
|
||||
@@ -762,6 +767,9 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305 "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_PSK_WITH_CHACHA20_POLY1305 "TLS_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_PSK_WITH_CHACHA20_POLY1305 "TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_DHE_PSK_WITH_CHACHA20_POLY1305 "TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
@@ -1090,7 +1098,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 "ECDH-RSA-CAMELLIA128-SHA256"
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 "ECDH-RSA-CAMELLIA256-SHA384"
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "ECDHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "ECDHE-ECDSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D "DHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305 "ECDHE-RSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "ECDHE-ECDSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305 "DHE-RSA-CHACHA20-POLY1305"
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index d7dbf99954..ee3293b5ce 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -2082,6 +2082,54 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
256,
|
||||
256,
|
||||
},
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aECDSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
{
|
||||
1,
|
||||
TLS1_TXT_PSK_WITH_CHACHA20_POLY1305,
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index b60d67aa0d..ce750c4425 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -43,7 +43,8 @@
|
||||
#define SSL_ENC_CHACHA_IDX 19
|
||||
#define SSL_ENC_ARIA128GCM_IDX 20
|
||||
#define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-#define SSL_ENC_NUM_IDX 22
|
||||
+#define SSL_ENC_CHACHA20_D_IDX 22
|
||||
+#define SSL_ENC_NUM_IDX 23
|
||||
|
||||
/* NB: make sure indices in these tables match values above */
|
||||
|
||||
@@ -76,6 +77,7 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
{SSL_CHACHA20POLY1305, NID_chacha20_poly1305}, /* SSL_ENC_CHACHA_IDX 19 */
|
||||
{SSL_ARIA128GCM, NID_aria_128_gcm}, /* SSL_ENC_ARIA128GCM_IDX 20 */
|
||||
{SSL_ARIA256GCM, NID_aria_256_gcm}, /* SSL_ENC_ARIA256GCM_IDX 21 */
|
||||
+ {SSL_CHACHA20POLY1305_D, NID_chacha20_poly1305_draft}, /* SSL_ENC_CHACHA20POLY1305_IDX 22 */
|
||||
};
|
||||
|
||||
static const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
@@ -275,6 +277,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_CAMELLIA256, NULL, 0, 0, 0, SSL_CAMELLIA256},
|
||||
{0, SSL_TXT_CAMELLIA, NULL, 0, 0, 0, SSL_CAMELLIA},
|
||||
{0, SSL_TXT_CHACHA20, NULL, 0, 0, 0, SSL_CHACHA20},
|
||||
+ {0, SSL_TXT_CHACHA20_D, NULL, 0, 0, 0, SSL_CHACHA20POLY1305_D},
|
||||
|
||||
{0, SSL_TXT_ARIA, NULL, 0, 0, 0, SSL_ARIA},
|
||||
{0, SSL_TXT_ARIA_GCM, NULL, 0, 0, 0, SSL_ARIA128GCM | SSL_ARIA256GCM},
|
||||
@@ -1791,6 +1794,9 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
case SSL_CHACHA20POLY1305:
|
||||
enc = "CHACHA20/POLY1305(256)";
|
||||
break;
|
||||
+ case SSL_CHACHA20POLY1305_D:
|
||||
+ enc = "CHACHA20/POLY1305-Draft(256)";
|
||||
+ break;
|
||||
default:
|
||||
enc = "unknown";
|
||||
break;
|
||||
@@ -2115,7 +2121,7 @@ int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 16;
|
||||
} else if (c->algorithm_enc & (SSL_AES128CCM8 | SSL_AES256CCM8)) {
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 8;
|
||||
- } else if (c->algorithm_enc & SSL_CHACHA20POLY1305) {
|
||||
+ } else if (c->algorithm_enc & (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)) {
|
||||
out = 16;
|
||||
} else if (c->algorithm_mac & SSL_AEAD) {
|
||||
/* We're supposed to have handled all the AEAD modes above */
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index fa0f6d018c..f2a95c263a 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -230,12 +230,13 @@
|
||||
# define SSL_CHACHA20POLY1305 0x00080000U
|
||||
# define SSL_ARIA128GCM 0x00100000U
|
||||
# define SSL_ARIA256GCM 0x00200000U
|
||||
+# define SSL_CHACHA20POLY1305_D 0x00400000U
|
||||
|
||||
# define SSL_AESGCM (SSL_AES128GCM | SSL_AES256GCM)
|
||||
# define SSL_AESCCM (SSL_AES128CCM | SSL_AES256CCM | SSL_AES128CCM8 | SSL_AES256CCM8)
|
||||
# define SSL_AES (SSL_AES128|SSL_AES256|SSL_AESGCM|SSL_AESCCM)
|
||||
# define SSL_CAMELLIA (SSL_CAMELLIA128|SSL_CAMELLIA256)
|
||||
-# define SSL_CHACHA20 (SSL_CHACHA20POLY1305)
|
||||
+# define SSL_CHACHA20 (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)
|
||||
# define SSL_ARIAGCM (SSL_ARIA128GCM | SSL_ARIA256GCM)
|
||||
# define SSL_ARIA (SSL_ARIAGCM)
|
||||
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index bf8b803c4c..d90d510096 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -4582,3 +4582,4 @@ OPENSSL_INIT_set_config_file_flags 4535 1_1_1b EXIST::FUNCTION:STDIO
|
||||
EVP_PKEY_get0_engine 4536 1_1_1c EXIST::FUNCTION:ENGINE
|
||||
X509_get0_authority_serial 4537 1_1_1d EXIST::FUNCTION:
|
||||
X509_get0_authority_issuer 4538 1_1_1d EXIST::FUNCTION:
|
||||
+EVP_chacha20_poly1305_draft 4539 1_1_1d EXIST::FUNCTION:CHACHA,POLY1305
|
||||
@@ -0,0 +1,509 @@
|
||||
diff --git a/crypto/evp/c_allc.c b/crypto/evp/c_allc.c
|
||||
index 22fdcc409c..2286caafae 100644
|
||||
--- a/crypto/evp/c_allc.c
|
||||
+++ b/crypto/evp/c_allc.c
|
||||
@@ -261,6 +261,7 @@ void openssl_add_all_ciphers_int(void)
|
||||
EVP_add_cipher(EVP_chacha20());
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
EVP_add_cipher(EVP_chacha20_poly1305());
|
||||
+ EVP_add_cipher(EVP_chacha20_poly1305_draft());
|
||||
# endif
|
||||
#endif
|
||||
}
|
||||
diff --git a/crypto/evp/e_chacha20_poly1305.c b/crypto/evp/e_chacha20_poly1305.c
|
||||
index bdc406bb69..233f25b26c 100644
|
||||
--- a/crypto/evp/e_chacha20_poly1305.c
|
||||
+++ b/crypto/evp/e_chacha20_poly1305.c
|
||||
@@ -156,6 +156,7 @@ typedef struct {
|
||||
struct { uint64_t aad, text; } len;
|
||||
int aad, mac_inited, tag_len, nonce_len;
|
||||
size_t tls_payload_length;
|
||||
+ unsigned char draft:1;
|
||||
} EVP_CHACHA_AEAD_CTX;
|
||||
|
||||
# define NO_TLS_PAYLOAD_LENGTH ((size_t)-1)
|
||||
@@ -176,6 +177,7 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
actx->aad = 0;
|
||||
actx->mac_inited = 0;
|
||||
actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 0;
|
||||
|
||||
if (iv != NULL) {
|
||||
unsigned char temp[CHACHA_CTR_SIZE] = { 0 };
|
||||
@@ -197,6 +199,27 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
return 1;
|
||||
}
|
||||
|
||||
+static int chacha20_poly1305_draft_init_key(EVP_CIPHER_CTX *ctx,
|
||||
+ const unsigned char *inkey,
|
||||
+ const unsigned char *iv, int enc)
|
||||
+{
|
||||
+ EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
+
|
||||
+ if (!inkey)
|
||||
+ return 1;
|
||||
+
|
||||
+ actx->len.aad = 0;
|
||||
+ actx->len.text = 0;
|
||||
+ actx->aad = 0;
|
||||
+ actx->mac_inited = 0;
|
||||
+ actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 1;
|
||||
+
|
||||
+ chacha_init_key(ctx, inkey, NULL, enc);
|
||||
+
|
||||
+ return 1;
|
||||
+}
|
||||
+
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
|
||||
# if defined(POLY1305_ASM) && (defined(__x86_64) || defined(__x86_64__) || \
|
||||
@@ -367,10 +390,11 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
{
|
||||
EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
size_t rem, plen = actx->tls_payload_length;
|
||||
+ uint64_t thirteen = EVP_AEAD_TLS1_AAD_LEN;
|
||||
|
||||
if (!actx->mac_inited) {
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
- if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL)
|
||||
+ if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL && !actx->draft)
|
||||
return chacha20_poly1305_tls_cipher(ctx, out, in, len);
|
||||
# endif
|
||||
actx->key.counter[0] = 0;
|
||||
@@ -397,9 +421,14 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
return len;
|
||||
} else { /* plain- or ciphertext */
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
@@ -432,40 +461,52 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
} is_endian = { 1 };
|
||||
unsigned char temp[POLY1305_BLOCK_SIZE];
|
||||
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.text;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ }
|
||||
+
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
- if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (!actx->draft) {
|
||||
+ if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
|
||||
- if (is_endian.little) {
|
||||
- Poly1305_Update(POLY1305_ctx(actx),
|
||||
- (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
- } else {
|
||||
- temp[0] = (unsigned char)(actx->len.aad);
|
||||
- temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
- temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
- temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
- temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
- temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
- temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
- temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
-
|
||||
- temp[8] = (unsigned char)(actx->len.text);
|
||||
- temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
- temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
- temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
- temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
- temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
- temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
- temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
-
|
||||
- Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ if (is_endian.little) {
|
||||
+ Poly1305_Update(POLY1305_ctx(actx),
|
||||
+ (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
+ } else {
|
||||
+ temp[0] = (unsigned char)(actx->len.aad);
|
||||
+ temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
+ temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
+ temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
+ temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
+ temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
+ temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
+ temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
+
|
||||
+ temp[8] = (unsigned char)(actx->len.text);
|
||||
+ temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
+ temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
+ temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
+ temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
+ temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
+ temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
+ temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
+
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ }
|
||||
}
|
||||
Poly1305_Final(POLY1305_ctx(actx), ctx->encrypt ? actx->tag
|
||||
: temp);
|
||||
@@ -539,12 +580,14 @@ static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IVLEN:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg <= 0 || arg > CHACHA20_POLY1305_MAX_IVLEN)
|
||||
return 0;
|
||||
actx->nonce_len = arg;
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IV_FIXED:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg != 12)
|
||||
return 0;
|
||||
actx->nonce[0] = actx->key.counter[1]
|
||||
@@ -629,9 +672,32 @@ static EVP_CIPHER chacha20_poly1305 = {
|
||||
NULL /* app_data */
|
||||
};
|
||||
|
||||
+static EVP_CIPHER chacha20_poly1305_draft = {
|
||||
+ NID_chacha20_poly1305_draft,
|
||||
+ 1, /* block_size */
|
||||
+ CHACHA_KEY_SIZE, /* key_len */
|
||||
+ 0, /* iv_len, none */
|
||||
+ EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_CUSTOM_IV |
|
||||
+ EVP_CIPH_ALWAYS_CALL_INIT | EVP_CIPH_CTRL_INIT |
|
||||
+ EVP_CIPH_CUSTOM_COPY | EVP_CIPH_FLAG_CUSTOM_CIPHER,
|
||||
+ chacha20_poly1305_draft_init_key,
|
||||
+ chacha20_poly1305_cipher,
|
||||
+ chacha20_poly1305_cleanup,
|
||||
+ 0, /* 0 moves context-specific structure allocation to ctrl */
|
||||
+ NULL, /* set_asn1_parameters */
|
||||
+ NULL, /* get_asn1_parameters */
|
||||
+ chacha20_poly1305_ctrl,
|
||||
+ NULL /* app_data */
|
||||
+};
|
||||
+
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void)
|
||||
{
|
||||
return(&chacha20_poly1305);
|
||||
}
|
||||
+
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void)
|
||||
+{
|
||||
+ return(&chacha20_poly1305_draft);
|
||||
+}
|
||||
# endif
|
||||
#endif
|
||||
diff --git a/crypto/objects/obj_dat.h b/crypto/objects/obj_dat.h
|
||||
index d1b1bc7faf..f6a8ada915 100644
|
||||
--- a/crypto/objects/obj_dat.h
|
||||
+++ b/crypto/objects/obj_dat.h
|
||||
@@ -1078,7 +1078,7 @@ static const unsigned char so[7762] = {
|
||||
0x2A,0x86,0x48,0x86,0xF7,0x0D,0x02,0x0D, /* [ 7753] OBJ_hmacWithSHA512_256 */
|
||||
};
|
||||
|
||||
-#define NUM_NID 1195
|
||||
+#define NUM_NID 1196
|
||||
static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"UNDEF", "undefined", NID_undef},
|
||||
{"rsadsi", "RSA Data Security, Inc.", NID_rsadsi, 6, &so[0]},
|
||||
@@ -2275,9 +2275,10 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"magma-mac", "magma-mac", NID_magma_mac},
|
||||
{"hmacWithSHA512-224", "hmacWithSHA512-224", NID_hmacWithSHA512_224, 8, &so[7745]},
|
||||
{"hmacWithSHA512-256", "hmacWithSHA512-256", NID_hmacWithSHA512_256, 8, &so[7753]},
|
||||
+ {"ChaCha20-Poly1305-D", "chacha20-poly1305-draft", NID_chacha20_poly1305_draft},
|
||||
};
|
||||
|
||||
-#define NUM_SN 1186
|
||||
+#define NUM_SN 1187
|
||||
static const unsigned int sn_objs[NUM_SN] = {
|
||||
364, /* "AD_DVCS" */
|
||||
419, /* "AES-128-CBC" */
|
||||
@@ -2395,6 +2396,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
417, /* "CSPName" */
|
||||
1019, /* "ChaCha20" */
|
||||
1018, /* "ChaCha20-Poly1305" */
|
||||
+ 1195, /* "ChaCha20-Poly1305-D" */
|
||||
367, /* "CrlID" */
|
||||
391, /* "DC" */
|
||||
31, /* "DES-CBC" */
|
||||
@@ -3467,7 +3469,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
1093, /* "x509ExtAdmission" */
|
||||
};
|
||||
|
||||
-#define NUM_LN 1186
|
||||
+#define NUM_LN 1187
|
||||
static const unsigned int ln_objs[NUM_LN] = {
|
||||
363, /* "AD Time Stamping" */
|
||||
405, /* "ANSI X9.62" */
|
||||
@@ -3846,6 +3848,7 @@ static const unsigned int ln_objs[NUM_LN] = {
|
||||
883, /* "certificateRevocationList" */
|
||||
1019, /* "chacha20" */
|
||||
1018, /* "chacha20-poly1305" */
|
||||
+ 1195, /* "chacha20-poly1305-draft" */
|
||||
54, /* "challengePassword" */
|
||||
407, /* "characteristic-two-field" */
|
||||
395, /* "clearance" */
|
||||
diff --git a/crypto/objects/obj_mac.num b/crypto/objects/obj_mac.num
|
||||
index 1b6a9c61a1..c81ca25a53 100644
|
||||
--- a/crypto/objects/obj_mac.num
|
||||
+++ b/crypto/objects/obj_mac.num
|
||||
@@ -1192,3 +1192,4 @@ magma_cfb 1191
|
||||
magma_mac 1192
|
||||
hmacWithSHA512_224 1193
|
||||
hmacWithSHA512_256 1194
|
||||
+chacha20_poly1305_draft 1195
|
||||
diff --git a/crypto/objects/objects.txt b/crypto/objects/objects.txt
|
||||
index c49d4c568b..bbf02995a9 100644
|
||||
--- a/crypto/objects/objects.txt
|
||||
+++ b/crypto/objects/objects.txt
|
||||
@@ -1534,6 +1534,7 @@ sm-scheme 104 7 : SM4-CTR : sm4-ctr
|
||||
: AES-192-CBC-HMAC-SHA256 : aes-192-cbc-hmac-sha256
|
||||
: AES-256-CBC-HMAC-SHA256 : aes-256-cbc-hmac-sha256
|
||||
: ChaCha20-Poly1305 : chacha20-poly1305
|
||||
+ : ChaCha20-Poly1305-D : chacha20-poly1305-draft
|
||||
: ChaCha20 : chacha20
|
||||
|
||||
ISO-US 10046 2 1 : dhpublicnumber : X9.42 DH
|
||||
diff --git a/include/openssl/evp.h b/include/openssl/evp.h
|
||||
index a411f3f2f9..502720466c 100644
|
||||
--- a/include/openssl/evp.h
|
||||
+++ b/include/openssl/evp.h
|
||||
@@ -919,6 +919,7 @@ const EVP_CIPHER *EVP_camellia_256_ctr(void);
|
||||
const EVP_CIPHER *EVP_chacha20(void);
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void);
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void);
|
||||
# endif
|
||||
# endif
|
||||
|
||||
diff --git a/include/openssl/obj_mac.h b/include/openssl/obj_mac.h
|
||||
index 483fc0509e..2e3fc93259 100644
|
||||
--- a/include/openssl/obj_mac.h
|
||||
+++ b/include/openssl/obj_mac.h
|
||||
@@ -4807,6 +4807,10 @@
|
||||
#define LN_chacha20_poly1305 "chacha20-poly1305"
|
||||
#define NID_chacha20_poly1305 1018
|
||||
|
||||
+#define SN_chacha20_poly1305_draft "ChaCha20-Poly1305-D"
|
||||
+#define LN_chacha20_poly1305_draft "chacha20-poly1305-draft"
|
||||
+#define NID_chacha20_poly1305_draft 1195
|
||||
+
|
||||
#define SN_chacha20 "ChaCha20"
|
||||
#define LN_chacha20 "chacha20"
|
||||
#define NID_chacha20 1019
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 6724ccf2d2..0365760200 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -125,6 +125,7 @@ extern "C" {
|
||||
# define SSL_TXT_CAMELLIA256 "CAMELLIA256"
|
||||
# define SSL_TXT_CAMELLIA "CAMELLIA"
|
||||
# define SSL_TXT_CHACHA20 "CHACHA20"
|
||||
+# define SSL_TXT_CHACHA20_D "CHACHA20-D"
|
||||
# define SSL_TXT_GOST "GOST89"
|
||||
# define SSL_TXT_ARIA "ARIA"
|
||||
# define SSL_TXT_ARIA_GCM "ARIAGCM"
|
||||
diff --git a/include/openssl/tls1.h b/include/openssl/tls1.h
|
||||
index 76d9fda46e..9cf04607c6 100644
|
||||
--- a/include/openssl/tls1.h
|
||||
+++ b/include/openssl/tls1.h
|
||||
@@ -597,7 +597,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0x0300C09A
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0x0300C09B
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC13
|
||||
+# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D 0x0300CC14
|
||||
+# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC15
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCA8
|
||||
# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 0x0300CCA9
|
||||
# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCAA
|
||||
@@ -762,6 +767,9 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305 "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_PSK_WITH_CHACHA20_POLY1305 "TLS_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_PSK_WITH_CHACHA20_POLY1305 "TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_DHE_PSK_WITH_CHACHA20_POLY1305 "TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
@@ -1090,7 +1098,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 "ECDH-RSA-CAMELLIA128-SHA256"
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 "ECDH-RSA-CAMELLIA256-SHA384"
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "ECDHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "ECDHE-ECDSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D "DHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305 "ECDHE-RSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "ECDHE-ECDSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305 "DHE-RSA-CHACHA20-POLY1305"
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index a987604bcd..ada87e965a 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -2082,6 +2082,54 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
256,
|
||||
256,
|
||||
},
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aECDSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
{
|
||||
1,
|
||||
TLS1_TXT_PSK_WITH_CHACHA20_POLY1305,
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 735a483c64..aced63c50c 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -43,7 +43,8 @@
|
||||
#define SSL_ENC_CHACHA_IDX 19
|
||||
#define SSL_ENC_ARIA128GCM_IDX 20
|
||||
#define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-#define SSL_ENC_NUM_IDX 22
|
||||
+#define SSL_ENC_CHACHA20_D_IDX 22
|
||||
+#define SSL_ENC_NUM_IDX 23
|
||||
|
||||
/* NB: make sure indices in these tables match values above */
|
||||
|
||||
@@ -76,6 +77,7 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
{SSL_CHACHA20POLY1305, NID_chacha20_poly1305}, /* SSL_ENC_CHACHA_IDX 19 */
|
||||
{SSL_ARIA128GCM, NID_aria_128_gcm}, /* SSL_ENC_ARIA128GCM_IDX 20 */
|
||||
{SSL_ARIA256GCM, NID_aria_256_gcm}, /* SSL_ENC_ARIA256GCM_IDX 21 */
|
||||
+ {SSL_CHACHA20POLY1305_D, NID_chacha20_poly1305_draft}, /* SSL_ENC_CHACHA20POLY1305_IDX 22 */
|
||||
};
|
||||
|
||||
static const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
@@ -275,6 +277,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_CAMELLIA256, NULL, 0, 0, 0, SSL_CAMELLIA256},
|
||||
{0, SSL_TXT_CAMELLIA, NULL, 0, 0, 0, SSL_CAMELLIA},
|
||||
{0, SSL_TXT_CHACHA20, NULL, 0, 0, 0, SSL_CHACHA20},
|
||||
+ {0, SSL_TXT_CHACHA20_D, NULL, 0, 0, 0, SSL_CHACHA20POLY1305_D},
|
||||
|
||||
{0, SSL_TXT_ARIA, NULL, 0, 0, 0, SSL_ARIA},
|
||||
{0, SSL_TXT_ARIA_GCM, NULL, 0, 0, 0, SSL_ARIA128GCM | SSL_ARIA256GCM},
|
||||
@@ -1792,6 +1795,9 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
case SSL_CHACHA20POLY1305:
|
||||
enc = "CHACHA20/POLY1305(256)";
|
||||
break;
|
||||
+ case SSL_CHACHA20POLY1305_D:
|
||||
+ enc = "CHACHA20/POLY1305-Draft(256)";
|
||||
+ break;
|
||||
default:
|
||||
enc = "unknown";
|
||||
break;
|
||||
@@ -2116,7 +2122,7 @@ int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 16;
|
||||
} else if (c->algorithm_enc & (SSL_AES128CCM8 | SSL_AES256CCM8)) {
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 8;
|
||||
- } else if (c->algorithm_enc & SSL_CHACHA20POLY1305) {
|
||||
+ } else if (c->algorithm_enc & (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)) {
|
||||
out = 16;
|
||||
} else if (c->algorithm_mac & SSL_AEAD) {
|
||||
/* We're supposed to have handled all the AEAD modes above */
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index 8ddbde7729..9ef6ea092a 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -230,12 +230,13 @@
|
||||
# define SSL_CHACHA20POLY1305 0x00080000U
|
||||
# define SSL_ARIA128GCM 0x00100000U
|
||||
# define SSL_ARIA256GCM 0x00200000U
|
||||
+# define SSL_CHACHA20POLY1305_D 0x00400000U
|
||||
|
||||
# define SSL_AESGCM (SSL_AES128GCM | SSL_AES256GCM)
|
||||
# define SSL_AESCCM (SSL_AES128CCM | SSL_AES256CCM | SSL_AES128CCM8 | SSL_AES256CCM8)
|
||||
# define SSL_AES (SSL_AES128|SSL_AES256|SSL_AESGCM|SSL_AESCCM)
|
||||
# define SSL_CAMELLIA (SSL_CAMELLIA128|SSL_CAMELLIA256)
|
||||
-# define SSL_CHACHA20 (SSL_CHACHA20POLY1305)
|
||||
+# define SSL_CHACHA20 (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)
|
||||
# define SSL_ARIAGCM (SSL_ARIA128GCM | SSL_ARIA256GCM)
|
||||
# define SSL_ARIA (SSL_ARIAGCM)
|
||||
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index 876b7ca710..14fc37999f 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -4587,3 +4587,4 @@ EVP_PKEY_meth_set_digestverify 4540 1_1_1e EXIST::FUNCTION:
|
||||
EVP_PKEY_meth_get_digestverify 4541 1_1_1e EXIST::FUNCTION:
|
||||
EVP_PKEY_meth_get_digestsign 4542 1_1_1e EXIST::FUNCTION:
|
||||
RSA_get0_pss_params 4543 1_1_1e EXIST::FUNCTION:RSA
|
||||
+EVP_chacha20_poly1305_draft 4544 1_1_1f EXIST::FUNCTION:CHACHA,POLY1305
|
||||
@@ -0,0 +1,509 @@
|
||||
diff --git a/crypto/evp/c_allc.c b/crypto/evp/c_allc.c
|
||||
index 22fdcc409c..2286caafae 100644
|
||||
--- a/crypto/evp/c_allc.c
|
||||
+++ b/crypto/evp/c_allc.c
|
||||
@@ -261,6 +261,7 @@ void openssl_add_all_ciphers_int(void)
|
||||
EVP_add_cipher(EVP_chacha20());
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
EVP_add_cipher(EVP_chacha20_poly1305());
|
||||
+ EVP_add_cipher(EVP_chacha20_poly1305_draft());
|
||||
# endif
|
||||
#endif
|
||||
}
|
||||
diff --git a/crypto/evp/e_chacha20_poly1305.c b/crypto/evp/e_chacha20_poly1305.c
|
||||
index bdc406bb69..233f25b26c 100644
|
||||
--- a/crypto/evp/e_chacha20_poly1305.c
|
||||
+++ b/crypto/evp/e_chacha20_poly1305.c
|
||||
@@ -156,6 +156,7 @@ typedef struct {
|
||||
struct { uint64_t aad, text; } len;
|
||||
int aad, mac_inited, tag_len, nonce_len;
|
||||
size_t tls_payload_length;
|
||||
+ unsigned char draft:1;
|
||||
} EVP_CHACHA_AEAD_CTX;
|
||||
|
||||
# define NO_TLS_PAYLOAD_LENGTH ((size_t)-1)
|
||||
@@ -176,6 +177,7 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
actx->aad = 0;
|
||||
actx->mac_inited = 0;
|
||||
actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 0;
|
||||
|
||||
if (iv != NULL) {
|
||||
unsigned char temp[CHACHA_CTR_SIZE] = { 0 };
|
||||
@@ -197,6 +199,27 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
return 1;
|
||||
}
|
||||
|
||||
+static int chacha20_poly1305_draft_init_key(EVP_CIPHER_CTX *ctx,
|
||||
+ const unsigned char *inkey,
|
||||
+ const unsigned char *iv, int enc)
|
||||
+{
|
||||
+ EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
+
|
||||
+ if (!inkey)
|
||||
+ return 1;
|
||||
+
|
||||
+ actx->len.aad = 0;
|
||||
+ actx->len.text = 0;
|
||||
+ actx->aad = 0;
|
||||
+ actx->mac_inited = 0;
|
||||
+ actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 1;
|
||||
+
|
||||
+ chacha_init_key(ctx, inkey, NULL, enc);
|
||||
+
|
||||
+ return 1;
|
||||
+}
|
||||
+
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
|
||||
# if defined(POLY1305_ASM) && (defined(__x86_64) || defined(__x86_64__) || \
|
||||
@@ -367,10 +390,11 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
{
|
||||
EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
size_t rem, plen = actx->tls_payload_length;
|
||||
+ uint64_t thirteen = EVP_AEAD_TLS1_AAD_LEN;
|
||||
|
||||
if (!actx->mac_inited) {
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
- if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL)
|
||||
+ if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL && !actx->draft)
|
||||
return chacha20_poly1305_tls_cipher(ctx, out, in, len);
|
||||
# endif
|
||||
actx->key.counter[0] = 0;
|
||||
@@ -397,9 +421,14 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
return len;
|
||||
} else { /* plain- or ciphertext */
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
@@ -432,40 +461,52 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
} is_endian = { 1 };
|
||||
unsigned char temp[POLY1305_BLOCK_SIZE];
|
||||
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.text;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ }
|
||||
+
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
- if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (!actx->draft) {
|
||||
+ if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
|
||||
- if (is_endian.little) {
|
||||
- Poly1305_Update(POLY1305_ctx(actx),
|
||||
- (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
- } else {
|
||||
- temp[0] = (unsigned char)(actx->len.aad);
|
||||
- temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
- temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
- temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
- temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
- temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
- temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
- temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
-
|
||||
- temp[8] = (unsigned char)(actx->len.text);
|
||||
- temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
- temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
- temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
- temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
- temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
- temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
- temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
-
|
||||
- Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ if (is_endian.little) {
|
||||
+ Poly1305_Update(POLY1305_ctx(actx),
|
||||
+ (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
+ } else {
|
||||
+ temp[0] = (unsigned char)(actx->len.aad);
|
||||
+ temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
+ temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
+ temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
+ temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
+ temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
+ temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
+ temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
+
|
||||
+ temp[8] = (unsigned char)(actx->len.text);
|
||||
+ temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
+ temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
+ temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
+ temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
+ temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
+ temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
+ temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
+
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ }
|
||||
}
|
||||
Poly1305_Final(POLY1305_ctx(actx), ctx->encrypt ? actx->tag
|
||||
: temp);
|
||||
@@ -539,12 +580,14 @@ static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IVLEN:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg <= 0 || arg > CHACHA20_POLY1305_MAX_IVLEN)
|
||||
return 0;
|
||||
actx->nonce_len = arg;
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IV_FIXED:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg != 12)
|
||||
return 0;
|
||||
actx->nonce[0] = actx->key.counter[1]
|
||||
@@ -629,9 +672,32 @@ static EVP_CIPHER chacha20_poly1305 = {
|
||||
NULL /* app_data */
|
||||
};
|
||||
|
||||
+static EVP_CIPHER chacha20_poly1305_draft = {
|
||||
+ NID_chacha20_poly1305_draft,
|
||||
+ 1, /* block_size */
|
||||
+ CHACHA_KEY_SIZE, /* key_len */
|
||||
+ 0, /* iv_len, none */
|
||||
+ EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_CUSTOM_IV |
|
||||
+ EVP_CIPH_ALWAYS_CALL_INIT | EVP_CIPH_CTRL_INIT |
|
||||
+ EVP_CIPH_CUSTOM_COPY | EVP_CIPH_FLAG_CUSTOM_CIPHER,
|
||||
+ chacha20_poly1305_draft_init_key,
|
||||
+ chacha20_poly1305_cipher,
|
||||
+ chacha20_poly1305_cleanup,
|
||||
+ 0, /* 0 moves context-specific structure allocation to ctrl */
|
||||
+ NULL, /* set_asn1_parameters */
|
||||
+ NULL, /* get_asn1_parameters */
|
||||
+ chacha20_poly1305_ctrl,
|
||||
+ NULL /* app_data */
|
||||
+};
|
||||
+
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void)
|
||||
{
|
||||
return(&chacha20_poly1305);
|
||||
}
|
||||
+
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void)
|
||||
+{
|
||||
+ return(&chacha20_poly1305_draft);
|
||||
+}
|
||||
# endif
|
||||
#endif
|
||||
diff --git a/crypto/objects/obj_dat.h b/crypto/objects/obj_dat.h
|
||||
index d1b1bc7faf..f6a8ada915 100644
|
||||
--- a/crypto/objects/obj_dat.h
|
||||
+++ b/crypto/objects/obj_dat.h
|
||||
@@ -1078,7 +1078,7 @@ static const unsigned char so[7762] = {
|
||||
0x2A,0x86,0x48,0x86,0xF7,0x0D,0x02,0x0D, /* [ 7753] OBJ_hmacWithSHA512_256 */
|
||||
};
|
||||
|
||||
-#define NUM_NID 1195
|
||||
+#define NUM_NID 1196
|
||||
static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"UNDEF", "undefined", NID_undef},
|
||||
{"rsadsi", "RSA Data Security, Inc.", NID_rsadsi, 6, &so[0]},
|
||||
@@ -2275,9 +2275,10 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"magma-mac", "magma-mac", NID_magma_mac},
|
||||
{"hmacWithSHA512-224", "hmacWithSHA512-224", NID_hmacWithSHA512_224, 8, &so[7745]},
|
||||
{"hmacWithSHA512-256", "hmacWithSHA512-256", NID_hmacWithSHA512_256, 8, &so[7753]},
|
||||
+ {"ChaCha20-Poly1305-D", "chacha20-poly1305-draft", NID_chacha20_poly1305_draft},
|
||||
};
|
||||
|
||||
-#define NUM_SN 1186
|
||||
+#define NUM_SN 1187
|
||||
static const unsigned int sn_objs[NUM_SN] = {
|
||||
364, /* "AD_DVCS" */
|
||||
419, /* "AES-128-CBC" */
|
||||
@@ -2395,6 +2396,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
417, /* "CSPName" */
|
||||
1019, /* "ChaCha20" */
|
||||
1018, /* "ChaCha20-Poly1305" */
|
||||
+ 1195, /* "ChaCha20-Poly1305-D" */
|
||||
367, /* "CrlID" */
|
||||
391, /* "DC" */
|
||||
31, /* "DES-CBC" */
|
||||
@@ -3467,7 +3469,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
1093, /* "x509ExtAdmission" */
|
||||
};
|
||||
|
||||
-#define NUM_LN 1186
|
||||
+#define NUM_LN 1187
|
||||
static const unsigned int ln_objs[NUM_LN] = {
|
||||
363, /* "AD Time Stamping" */
|
||||
405, /* "ANSI X9.62" */
|
||||
@@ -3846,6 +3848,7 @@ static const unsigned int ln_objs[NUM_LN] = {
|
||||
883, /* "certificateRevocationList" */
|
||||
1019, /* "chacha20" */
|
||||
1018, /* "chacha20-poly1305" */
|
||||
+ 1195, /* "chacha20-poly1305-draft" */
|
||||
54, /* "challengePassword" */
|
||||
407, /* "characteristic-two-field" */
|
||||
395, /* "clearance" */
|
||||
diff --git a/crypto/objects/obj_mac.num b/crypto/objects/obj_mac.num
|
||||
index 1b6a9c61a1..c81ca25a53 100644
|
||||
--- a/crypto/objects/obj_mac.num
|
||||
+++ b/crypto/objects/obj_mac.num
|
||||
@@ -1192,3 +1192,4 @@ magma_cfb 1191
|
||||
magma_mac 1192
|
||||
hmacWithSHA512_224 1193
|
||||
hmacWithSHA512_256 1194
|
||||
+chacha20_poly1305_draft 1195
|
||||
diff --git a/crypto/objects/objects.txt b/crypto/objects/objects.txt
|
||||
index c49d4c568b..bbf02995a9 100644
|
||||
--- a/crypto/objects/objects.txt
|
||||
+++ b/crypto/objects/objects.txt
|
||||
@@ -1534,6 +1534,7 @@ sm-scheme 104 7 : SM4-CTR : sm4-ctr
|
||||
: AES-192-CBC-HMAC-SHA256 : aes-192-cbc-hmac-sha256
|
||||
: AES-256-CBC-HMAC-SHA256 : aes-256-cbc-hmac-sha256
|
||||
: ChaCha20-Poly1305 : chacha20-poly1305
|
||||
+ : ChaCha20-Poly1305-D : chacha20-poly1305-draft
|
||||
: ChaCha20 : chacha20
|
||||
|
||||
ISO-US 10046 2 1 : dhpublicnumber : X9.42 DH
|
||||
diff --git a/include/openssl/evp.h b/include/openssl/evp.h
|
||||
index a411f3f2f9..502720466c 100644
|
||||
--- a/include/openssl/evp.h
|
||||
+++ b/include/openssl/evp.h
|
||||
@@ -919,6 +919,7 @@ const EVP_CIPHER *EVP_camellia_256_ctr(void);
|
||||
const EVP_CIPHER *EVP_chacha20(void);
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void);
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void);
|
||||
# endif
|
||||
# endif
|
||||
|
||||
diff --git a/include/openssl/obj_mac.h b/include/openssl/obj_mac.h
|
||||
index 483fc0509e..2e3fc93259 100644
|
||||
--- a/include/openssl/obj_mac.h
|
||||
+++ b/include/openssl/obj_mac.h
|
||||
@@ -4807,6 +4807,10 @@
|
||||
#define LN_chacha20_poly1305 "chacha20-poly1305"
|
||||
#define NID_chacha20_poly1305 1018
|
||||
|
||||
+#define SN_chacha20_poly1305_draft "ChaCha20-Poly1305-D"
|
||||
+#define LN_chacha20_poly1305_draft "chacha20-poly1305-draft"
|
||||
+#define NID_chacha20_poly1305_draft 1195
|
||||
+
|
||||
#define SN_chacha20 "ChaCha20"
|
||||
#define LN_chacha20 "chacha20"
|
||||
#define NID_chacha20 1019
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 6724ccf2d2..0365760200 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -125,6 +125,7 @@ extern "C" {
|
||||
# define SSL_TXT_CAMELLIA256 "CAMELLIA256"
|
||||
# define SSL_TXT_CAMELLIA "CAMELLIA"
|
||||
# define SSL_TXT_CHACHA20 "CHACHA20"
|
||||
+# define SSL_TXT_CHACHA20_D "CHACHA20-D"
|
||||
# define SSL_TXT_GOST "GOST89"
|
||||
# define SSL_TXT_ARIA "ARIA"
|
||||
# define SSL_TXT_ARIA_GCM "ARIAGCM"
|
||||
diff --git a/include/openssl/tls1.h b/include/openssl/tls1.h
|
||||
index 76d9fda46e..9cf04607c6 100644
|
||||
--- a/include/openssl/tls1.h
|
||||
+++ b/include/openssl/tls1.h
|
||||
@@ -597,7 +597,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0x0300C09A
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0x0300C09B
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC13
|
||||
+# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D 0x0300CC14
|
||||
+# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC15
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCA8
|
||||
# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 0x0300CCA9
|
||||
# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCAA
|
||||
@@ -762,6 +767,9 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305 "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_PSK_WITH_CHACHA20_POLY1305 "TLS_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_PSK_WITH_CHACHA20_POLY1305 "TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_DHE_PSK_WITH_CHACHA20_POLY1305 "TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
@@ -1090,7 +1098,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 "ECDH-RSA-CAMELLIA128-SHA256"
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 "ECDH-RSA-CAMELLIA256-SHA384"
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "ECDHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "ECDHE-ECDSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D "DHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305 "ECDHE-RSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "ECDHE-ECDSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305 "DHE-RSA-CHACHA20-POLY1305"
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index a987604bcd..ada87e965a 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -2082,6 +2082,54 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
256,
|
||||
256,
|
||||
},
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aECDSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
{
|
||||
1,
|
||||
TLS1_TXT_PSK_WITH_CHACHA20_POLY1305,
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 735a483c64..aced63c50c 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -43,7 +43,8 @@
|
||||
#define SSL_ENC_CHACHA_IDX 19
|
||||
#define SSL_ENC_ARIA128GCM_IDX 20
|
||||
#define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-#define SSL_ENC_NUM_IDX 22
|
||||
+#define SSL_ENC_CHACHA20_D_IDX 22
|
||||
+#define SSL_ENC_NUM_IDX 23
|
||||
|
||||
/* NB: make sure indices in these tables match values above */
|
||||
|
||||
@@ -76,6 +77,7 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
{SSL_CHACHA20POLY1305, NID_chacha20_poly1305}, /* SSL_ENC_CHACHA_IDX 19 */
|
||||
{SSL_ARIA128GCM, NID_aria_128_gcm}, /* SSL_ENC_ARIA128GCM_IDX 20 */
|
||||
{SSL_ARIA256GCM, NID_aria_256_gcm}, /* SSL_ENC_ARIA256GCM_IDX 21 */
|
||||
+ {SSL_CHACHA20POLY1305_D, NID_chacha20_poly1305_draft}, /* SSL_ENC_CHACHA20POLY1305_IDX 22 */
|
||||
};
|
||||
|
||||
static const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
@@ -275,6 +277,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_CAMELLIA256, NULL, 0, 0, 0, SSL_CAMELLIA256},
|
||||
{0, SSL_TXT_CAMELLIA, NULL, 0, 0, 0, SSL_CAMELLIA},
|
||||
{0, SSL_TXT_CHACHA20, NULL, 0, 0, 0, SSL_CHACHA20},
|
||||
+ {0, SSL_TXT_CHACHA20_D, NULL, 0, 0, 0, SSL_CHACHA20POLY1305_D},
|
||||
|
||||
{0, SSL_TXT_ARIA, NULL, 0, 0, 0, SSL_ARIA},
|
||||
{0, SSL_TXT_ARIA_GCM, NULL, 0, 0, 0, SSL_ARIA128GCM | SSL_ARIA256GCM},
|
||||
@@ -1792,6 +1795,9 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
case SSL_CHACHA20POLY1305:
|
||||
enc = "CHACHA20/POLY1305(256)";
|
||||
break;
|
||||
+ case SSL_CHACHA20POLY1305_D:
|
||||
+ enc = "CHACHA20/POLY1305-Draft(256)";
|
||||
+ break;
|
||||
default:
|
||||
enc = "unknown";
|
||||
break;
|
||||
@@ -2116,7 +2122,7 @@ int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 16;
|
||||
} else if (c->algorithm_enc & (SSL_AES128CCM8 | SSL_AES256CCM8)) {
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 8;
|
||||
- } else if (c->algorithm_enc & SSL_CHACHA20POLY1305) {
|
||||
+ } else if (c->algorithm_enc & (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)) {
|
||||
out = 16;
|
||||
} else if (c->algorithm_mac & SSL_AEAD) {
|
||||
/* We're supposed to have handled all the AEAD modes above */
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index 8ddbde7729..9ef6ea092a 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -230,12 +230,13 @@
|
||||
# define SSL_CHACHA20POLY1305 0x00080000U
|
||||
# define SSL_ARIA128GCM 0x00100000U
|
||||
# define SSL_ARIA256GCM 0x00200000U
|
||||
+# define SSL_CHACHA20POLY1305_D 0x00400000U
|
||||
|
||||
# define SSL_AESGCM (SSL_AES128GCM | SSL_AES256GCM)
|
||||
# define SSL_AESCCM (SSL_AES128CCM | SSL_AES256CCM | SSL_AES128CCM8 | SSL_AES256CCM8)
|
||||
# define SSL_AES (SSL_AES128|SSL_AES256|SSL_AESGCM|SSL_AESCCM)
|
||||
# define SSL_CAMELLIA (SSL_CAMELLIA128|SSL_CAMELLIA256)
|
||||
-# define SSL_CHACHA20 (SSL_CHACHA20POLY1305)
|
||||
+# define SSL_CHACHA20 (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)
|
||||
# define SSL_ARIAGCM (SSL_ARIA128GCM | SSL_ARIA256GCM)
|
||||
# define SSL_ARIA (SSL_ARIAGCM)
|
||||
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index e16b836eb2..a8241cae78 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -4590,3 +4590,4 @@ RSA_get0_pss_params 4543 1_1_1e EXIST::FUNCTION:RSA
|
||||
X509_ALGOR_copy 4544 1_1_1h EXIST::FUNCTION:
|
||||
X509_REQ_set0_signature 4545 1_1_1h EXIST::FUNCTION:
|
||||
X509_REQ_set1_signature_algo 4546 1_1_1h EXIST::FUNCTION:
|
||||
+EVP_chacha20_poly1305_draft 4547 1_1_1h EXIST::FUNCTION:CHACHA,POLY1305
|
||||
@@ -1,5 +1,5 @@
|
||||
diff --git a/crypto/evp/c_allc.c b/crypto/evp/c_allc.c
|
||||
index a97eaa1685..24112723f0 100644
|
||||
index df8e5a5bcb..81bab72bcf 100644
|
||||
--- a/crypto/evp/c_allc.c
|
||||
+++ b/crypto/evp/c_allc.c
|
||||
@@ -265,6 +265,7 @@ void openssl_add_all_ciphers_int(void)
|
||||
@@ -11,10 +11,10 @@ index a97eaa1685..24112723f0 100644
|
||||
#endif
|
||||
}
|
||||
diff --git a/crypto/evp/e_chacha20_poly1305.c b/crypto/evp/e_chacha20_poly1305.c
|
||||
index e8a323f3be..9b1b36f832 100644
|
||||
index b7340b147d..4080db7554 100644
|
||||
--- a/crypto/evp/e_chacha20_poly1305.c
|
||||
+++ b/crypto/evp/e_chacha20_poly1305.c
|
||||
@@ -154,6 +154,7 @@ typedef struct {
|
||||
@@ -156,6 +156,7 @@ typedef struct {
|
||||
struct { uint64_t aad, text; } len;
|
||||
int aad, mac_inited, tag_len, nonce_len;
|
||||
size_t tls_payload_length;
|
||||
@@ -22,7 +22,7 @@ index e8a323f3be..9b1b36f832 100644
|
||||
} EVP_CHACHA_AEAD_CTX;
|
||||
|
||||
# define NO_TLS_PAYLOAD_LENGTH ((size_t)-1)
|
||||
@@ -174,6 +175,7 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
@@ -176,6 +177,7 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
actx->aad = 0;
|
||||
actx->mac_inited = 0;
|
||||
actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
@@ -30,7 +30,7 @@ index e8a323f3be..9b1b36f832 100644
|
||||
|
||||
if (iv != NULL) {
|
||||
unsigned char temp[CHACHA_CTR_SIZE] = { 0 };
|
||||
@@ -195,6 +197,27 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
@@ -197,6 +199,27 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -58,7 +58,7 @@ index e8a323f3be..9b1b36f832 100644
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
|
||||
# if defined(POLY1305_ASM) && (defined(__x86_64) || defined(__x86_64__) || \
|
||||
@@ -365,10 +388,11 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
@@ -367,10 +390,11 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
{
|
||||
EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
size_t rem, plen = actx->tls_payload_length;
|
||||
@@ -71,7 +71,7 @@ index e8a323f3be..9b1b36f832 100644
|
||||
return chacha20_poly1305_tls_cipher(ctx, out, in, len);
|
||||
# endif
|
||||
actx->key.counter[0] = 0;
|
||||
@@ -395,9 +419,14 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
@@ -397,9 +421,14 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
return len;
|
||||
} else { /* plain- or ciphertext */
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
@@ -89,7 +89,7 @@ index e8a323f3be..9b1b36f832 100644
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
@@ -430,40 +459,52 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
@@ -432,40 +461,52 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
} is_endian = { 1 };
|
||||
unsigned char temp[POLY1305_BLOCK_SIZE];
|
||||
|
||||
@@ -171,12 +171,12 @@ index e8a323f3be..9b1b36f832 100644
|
||||
}
|
||||
Poly1305_Final(POLY1305_ctx(actx), ctx->encrypt ? actx->tag
|
||||
: temp);
|
||||
@@ -533,12 +574,14 @@ static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
@@ -539,12 +580,14 @@ static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IVLEN:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg <= 0 || arg > CHACHA_CTR_SIZE)
|
||||
if (arg <= 0 || arg > CHACHA20_POLY1305_MAX_IVLEN)
|
||||
return 0;
|
||||
actx->nonce_len = arg;
|
||||
return 1;
|
||||
@@ -186,7 +186,7 @@ index e8a323f3be..9b1b36f832 100644
|
||||
if (arg != 12)
|
||||
return 0;
|
||||
actx->nonce[0] = actx->key.counter[1]
|
||||
@@ -622,9 +665,32 @@ static EVP_CIPHER chacha20_poly1305 = {
|
||||
@@ -629,9 +672,32 @@ static EVP_CIPHER chacha20_poly1305 = {
|
||||
NULL /* app_data */
|
||||
};
|
||||
|
||||
@@ -220,69 +220,69 @@ index e8a323f3be..9b1b36f832 100644
|
||||
# endif
|
||||
#endif
|
||||
diff --git a/crypto/objects/obj_dat.h b/crypto/objects/obj_dat.h
|
||||
index 78a9e7acaf..134d7b8c70 100644
|
||||
index 77b4418cd4..6b3d7f9085 100644
|
||||
--- a/crypto/objects/obj_dat.h
|
||||
+++ b/crypto/objects/obj_dat.h
|
||||
@@ -1079,7 +1079,7 @@ static const unsigned char so[7767] = {
|
||||
0x28,0xCC,0x45,0x03,0x04, /* [ 7761] OBJ_gmac */
|
||||
@@ -1088,7 +1088,7 @@ static const unsigned char so[7845] = {
|
||||
0x2B,0x06,0x01,0x05,0x05,0x07,0x08,0x08, /* [ 7836] OBJ_NAIRealm */
|
||||
};
|
||||
|
||||
-#define NUM_NID 1203
|
||||
+#define NUM_NID 1204
|
||||
-#define NUM_NID 1218
|
||||
+#define NUM_NID 1219
|
||||
static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"UNDEF", "undefined", NID_undef},
|
||||
{"rsadsi", "RSA Data Security, Inc.", NID_rsadsi, 6, &so[0]},
|
||||
@@ -2284,9 +2284,10 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"AES-256-SIV", "aes-256-siv", NID_aes_256_siv},
|
||||
{"BLAKE2BMAC", "blake2bmac", NID_blake2bmac},
|
||||
{"BLAKE2SMAC", "blake2smac", NID_blake2smac},
|
||||
@@ -2308,9 +2308,10 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"modp_4096", "modp_4096", NID_modp_4096},
|
||||
{"modp_6144", "modp_6144", NID_modp_6144},
|
||||
{"modp_8192", "modp_8192", NID_modp_8192},
|
||||
+ {"ChaCha20-Poly1305-D", "chacha20-poly1305-draft", NID_chacha20_poly1305_draft},
|
||||
};
|
||||
|
||||
-#define NUM_SN 1194
|
||||
+#define NUM_SN 1195
|
||||
-#define NUM_SN 1209
|
||||
+#define NUM_SN 1210
|
||||
static const unsigned int sn_objs[NUM_SN] = {
|
||||
364, /* "AD_DVCS" */
|
||||
419, /* "AES-128-CBC" */
|
||||
@@ -2409,6 +2410,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
@@ -2433,6 +2434,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
417, /* "CSPName" */
|
||||
1019, /* "ChaCha20" */
|
||||
1018, /* "ChaCha20-Poly1305" */
|
||||
+ 1203, /* "ChaCha20-Poly1305-D" */
|
||||
+ 1218, /* "ChaCha20-Poly1305-D" */
|
||||
367, /* "CrlID" */
|
||||
391, /* "DC" */
|
||||
31, /* "DES-CBC" */
|
||||
@@ -3484,7 +3486,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
@@ -3523,7 +3525,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
1093, /* "x509ExtAdmission" */
|
||||
};
|
||||
|
||||
-#define NUM_LN 1194
|
||||
+#define NUM_LN 1195
|
||||
-#define NUM_LN 1209
|
||||
+#define NUM_LN 1210
|
||||
static const unsigned int ln_objs[NUM_LN] = {
|
||||
363, /* "AD Time Stamping" */
|
||||
405, /* "ANSI X9.62" */
|
||||
@@ -3868,6 +3870,7 @@ static const unsigned int ln_objs[NUM_LN] = {
|
||||
@@ -3912,6 +3914,7 @@ static const unsigned int ln_objs[NUM_LN] = {
|
||||
883, /* "certificateRevocationList" */
|
||||
1019, /* "chacha20" */
|
||||
1018, /* "chacha20-poly1305" */
|
||||
+ 1203, /* "chacha20-poly1305-draft" */
|
||||
+ 1218, /* "chacha20-poly1305-draft" */
|
||||
54, /* "challengePassword" */
|
||||
407, /* "characteristic-two-field" */
|
||||
395, /* "clearance" */
|
||||
diff --git a/crypto/objects/obj_mac.num b/crypto/objects/obj_mac.num
|
||||
index 87790200d4..94d033c158 100644
|
||||
index 15aa1e9772..6fb028c1e8 100644
|
||||
--- a/crypto/objects/obj_mac.num
|
||||
+++ b/crypto/objects/obj_mac.num
|
||||
@@ -1200,3 +1200,4 @@ aes_192_siv 1199
|
||||
aes_256_siv 1200
|
||||
blake2bmac 1201
|
||||
blake2smac 1202
|
||||
+chacha20_poly1305_draft 1203
|
||||
@@ -1215,3 +1215,4 @@ modp_3072 1214
|
||||
modp_4096 1215
|
||||
modp_6144 1216
|
||||
modp_8192 1217
|
||||
+chacha20_poly1305_draft 1218
|
||||
diff --git a/crypto/objects/objects.txt b/crypto/objects/objects.txt
|
||||
index 344b67b395..21653d9b87 100644
|
||||
index 9819c539b7..bb4a9958d0 100644
|
||||
--- a/crypto/objects/objects.txt
|
||||
+++ b/crypto/objects/objects.txt
|
||||
@@ -1543,6 +1543,7 @@ sm-scheme 104 7 : SM4-CTR : sm4-ctr
|
||||
@@ -1549,6 +1549,7 @@ sm-scheme 104 7 : SM4-CTR : sm4-ctr
|
||||
: AES-192-CBC-HMAC-SHA256 : aes-192-cbc-hmac-sha256
|
||||
: AES-256-CBC-HMAC-SHA256 : aes-256-cbc-hmac-sha256
|
||||
: ChaCha20-Poly1305 : chacha20-poly1305
|
||||
@@ -291,10 +291,10 @@ index 344b67b395..21653d9b87 100644
|
||||
|
||||
ISO-US 10046 2 1 : dhpublicnumber : X9.42 DH
|
||||
diff --git a/include/openssl/evp.h b/include/openssl/evp.h
|
||||
index 23f07eaa05..c90c6435bd 100644
|
||||
index 7aa56b3e93..da87052bfa 100644
|
||||
--- a/include/openssl/evp.h
|
||||
+++ b/include/openssl/evp.h
|
||||
@@ -928,6 +928,7 @@ const EVP_CIPHER *EVP_camellia_256_ctr(void);
|
||||
@@ -985,6 +985,7 @@ const EVP_CIPHER *EVP_camellia_256_ctr(void);
|
||||
const EVP_CIPHER *EVP_chacha20(void);
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void);
|
||||
@@ -303,25 +303,25 @@ index 23f07eaa05..c90c6435bd 100644
|
||||
# endif
|
||||
|
||||
diff --git a/include/openssl/obj_mac.h b/include/openssl/obj_mac.h
|
||||
index 97b2204ba6..fc254cfa61 100644
|
||||
index 0e564ac6d2..3a074d62cb 100644
|
||||
--- a/include/openssl/obj_mac.h
|
||||
+++ b/include/openssl/obj_mac.h
|
||||
@@ -4828,6 +4828,10 @@
|
||||
@@ -4857,6 +4857,10 @@
|
||||
#define LN_chacha20_poly1305 "chacha20-poly1305"
|
||||
#define NID_chacha20_poly1305 1018
|
||||
|
||||
+#define SN_chacha20_poly1305_draft "ChaCha20-Poly1305-D"
|
||||
+#define LN_chacha20_poly1305_draft "chacha20-poly1305-draft"
|
||||
+#define NID_chacha20_poly1305_draft 1203
|
||||
+#define NID_chacha20_poly1305_draft 1218
|
||||
+
|
||||
#define SN_chacha20 "ChaCha20"
|
||||
#define LN_chacha20 "chacha20"
|
||||
#define NID_chacha20 1019
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 9d6e1c5024..5692cfab31 100644
|
||||
index c1b6b8e5dc..4f1717c14d 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -125,6 +125,7 @@ extern "C" {
|
||||
@@ -131,6 +131,7 @@ extern "C" {
|
||||
# define SSL_TXT_CAMELLIA256 "CAMELLIA256"
|
||||
# define SSL_TXT_CAMELLIA "CAMELLIA"
|
||||
# define SSL_TXT_CHACHA20 "CHACHA20"
|
||||
@@ -330,10 +330,10 @@ index 9d6e1c5024..5692cfab31 100644
|
||||
# define SSL_TXT_ARIA "ARIA"
|
||||
# define SSL_TXT_ARIA_GCM "ARIAGCM"
|
||||
diff --git a/include/openssl/tls1.h b/include/openssl/tls1.h
|
||||
index 166f15ad5c..4fa1d8a32d 100644
|
||||
index 9181e0d2c1..0244b1ab99 100644
|
||||
--- a/include/openssl/tls1.h
|
||||
+++ b/include/openssl/tls1.h
|
||||
@@ -599,7 +599,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
@@ -578,7 +578,12 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0x0300C09A
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0x0300C09B
|
||||
|
||||
@@ -347,7 +347,7 @@ index 166f15ad5c..4fa1d8a32d 100644
|
||||
# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCA8
|
||||
# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 0x0300CCA9
|
||||
# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCAA
|
||||
@@ -764,6 +769,9 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
@@ -743,6 +748,9 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb
|
||||
# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305 "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
@@ -357,7 +357,7 @@ index 166f15ad5c..4fa1d8a32d 100644
|
||||
# define TLS1_RFC_PSK_WITH_CHACHA20_POLY1305 "TLS_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_PSK_WITH_CHACHA20_POLY1305 "TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_DHE_PSK_WITH_CHACHA20_POLY1305 "TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
@@ -1092,7 +1100,12 @@ __owur int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain)
|
||||
@@ -1071,7 +1079,12 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 "ECDH-RSA-CAMELLIA128-SHA256"
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 "ECDH-RSA-CAMELLIA256-SHA384"
|
||||
|
||||
@@ -372,10 +372,10 @@ index 166f15ad5c..4fa1d8a32d 100644
|
||||
# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "ECDHE-ECDSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305 "DHE-RSA-CHACHA20-POLY1305"
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index a5b3dbbfd5..a5a7993065 100644
|
||||
index 706290be9b..9733581b0c 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -2082,6 +2082,54 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
@@ -2083,6 +2083,54 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
256,
|
||||
256,
|
||||
},
|
||||
@@ -431,28 +431,18 @@ index a5b3dbbfd5..a5a7993065 100644
|
||||
1,
|
||||
TLS1_TXT_PSK_WITH_CHACHA20_POLY1305,
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 461a9debab..84f90c1621 100644
|
||||
index 64c791636a..55f744dc53 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -43,7 +43,8 @@
|
||||
#define SSL_ENC_CHACHA_IDX 19
|
||||
#define SSL_ENC_ARIA128GCM_IDX 20
|
||||
#define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-#define SSL_ENC_NUM_IDX 22
|
||||
+#define SSL_ENC_CHACHA20_D_IDX 22
|
||||
+#define SSL_ENC_NUM_IDX 23
|
||||
|
||||
/* NB: make sure indices in these tables match values above */
|
||||
|
||||
@@ -76,6 +77,7 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
@@ -53,6 +53,7 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
{SSL_CHACHA20POLY1305, NID_chacha20_poly1305}, /* SSL_ENC_CHACHA_IDX 19 */
|
||||
{SSL_ARIA128GCM, NID_aria_128_gcm}, /* SSL_ENC_ARIA128GCM_IDX 20 */
|
||||
{SSL_ARIA256GCM, NID_aria_256_gcm}, /* SSL_ENC_ARIA256GCM_IDX 21 */
|
||||
+ {SSL_CHACHA20POLY1305_D, NID_chacha20_poly1305_draft}, /* SSL_ENC_CHACHA20POLY1305_IDX 22 */
|
||||
};
|
||||
|
||||
static const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
@@ -275,6 +277,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
#define SSL_COMP_NULL_IDX 0
|
||||
@@ -237,6 +238,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_CAMELLIA256, NULL, 0, 0, 0, SSL_CAMELLIA256},
|
||||
{0, SSL_TXT_CAMELLIA, NULL, 0, 0, 0, SSL_CAMELLIA},
|
||||
{0, SSL_TXT_CHACHA20, NULL, 0, 0, 0, SSL_CHACHA20},
|
||||
@@ -460,7 +450,7 @@ index 461a9debab..84f90c1621 100644
|
||||
|
||||
{0, SSL_TXT_ARIA, NULL, 0, 0, 0, SSL_ARIA},
|
||||
{0, SSL_TXT_ARIA_GCM, NULL, 0, 0, 0, SSL_ARIA128GCM | SSL_ARIA256GCM},
|
||||
@@ -1791,6 +1794,9 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
@@ -1776,6 +1778,9 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
case SSL_CHACHA20POLY1305:
|
||||
enc = "CHACHA20/POLY1305(256)";
|
||||
break;
|
||||
@@ -470,7 +460,7 @@ index 461a9debab..84f90c1621 100644
|
||||
default:
|
||||
enc = "unknown";
|
||||
break;
|
||||
@@ -2115,7 +2121,7 @@ int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
@@ -2095,7 +2100,7 @@ int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 16;
|
||||
} else if (c->algorithm_enc & (SSL_AES128CCM8 | SSL_AES256CCM8)) {
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 8;
|
||||
@@ -479,10 +469,10 @@ index 461a9debab..84f90c1621 100644
|
||||
out = 16;
|
||||
} else if (c->algorithm_mac & SSL_AEAD) {
|
||||
/* We're supposed to have handled all the AEAD modes above */
|
||||
diff --git a/ssl/ssl_locl.h b/ssl/ssl_locl.h
|
||||
index ae6417b592..c783031ea2 100644
|
||||
--- a/ssl/ssl_locl.h
|
||||
+++ b/ssl/ssl_locl.h
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index 31c01328ce..d9aee332f1 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -234,12 +234,13 @@
|
||||
# define SSL_CHACHA20POLY1305 0x00080000U
|
||||
# define SSL_ARIA128GCM 0x00100000U
|
||||
@@ -498,12 +488,22 @@ index ae6417b592..c783031ea2 100644
|
||||
# define SSL_ARIAGCM (SSL_ARIA128GCM | SSL_ARIA256GCM)
|
||||
# define SSL_ARIA (SSL_ARIAGCM)
|
||||
|
||||
@@ -413,7 +414,8 @@
|
||||
# define SSL_ENC_CHACHA_IDX 19
|
||||
# define SSL_ENC_ARIA128GCM_IDX 20
|
||||
# define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-# define SSL_ENC_NUM_IDX 22
|
||||
+# define SSL_ENC_CHACHA20_D_IDX 22
|
||||
+# define SSL_ENC_NUM_IDX 23
|
||||
|
||||
/*-
|
||||
* SSL_kRSA <- RSA_ENC
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index 9957cf80f6..21ea627067 100644
|
||||
index dc6515cfc9..8d8fc45acf 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -4646,3 +4646,4 @@ OPENSSL_CTX_free 4601 3_0_0 EXIST::FUNCTION:
|
||||
OPENSSL_LH_flush 4602 3_0_0 EXIST::FUNCTION:
|
||||
BN_native2bn 4603 3_0_0 EXIST::FUNCTION:
|
||||
BN_bn2nativepad 4604 3_0_0 EXIST::FUNCTION:
|
||||
+EVP_chacha20_poly1305_draft 4605 3_0_0 EXIST::FUNCTION:CHACHA,POLY1305
|
||||
@@ -4918,3 +4918,4 @@ PKCS8_pkey_add1_attr_by_OBJ ? 3_0_0 EXIST::FUNCTION:
|
||||
EVP_PKEY_private_check ? 3_0_0 EXIST::FUNCTION:
|
||||
EVP_PKEY_pairwise_check ? 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_item_verify_ctx ? 3_0_0 EXIST::FUNCTION:
|
||||
+EVP_chacha20_poly1305_draft ? 3_0_0 EXIST::FUNCTION:CHACHA,POLY1305
|
||||
@@ -0,0 +1,512 @@
|
||||
diff --git a/crypto/evp/c_allc.c b/crypto/evp/c_allc.c
|
||||
index df8e5a5bcb..81bab72bcf 100644
|
||||
--- a/crypto/evp/c_allc.c
|
||||
+++ b/crypto/evp/c_allc.c
|
||||
@@ -265,6 +265,7 @@ void openssl_add_all_ciphers_int(void)
|
||||
EVP_add_cipher(EVP_chacha20());
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
EVP_add_cipher(EVP_chacha20_poly1305());
|
||||
+ EVP_add_cipher(EVP_chacha20_poly1305_draft());
|
||||
# endif
|
||||
#endif
|
||||
}
|
||||
diff --git a/crypto/evp/e_chacha20_poly1305.c b/crypto/evp/e_chacha20_poly1305.c
|
||||
index b7340b147d..4080db7554 100644
|
||||
--- a/crypto/evp/e_chacha20_poly1305.c
|
||||
+++ b/crypto/evp/e_chacha20_poly1305.c
|
||||
@@ -156,6 +156,7 @@ typedef struct {
|
||||
struct { uint64_t aad, text; } len;
|
||||
int aad, mac_inited, tag_len, nonce_len;
|
||||
size_t tls_payload_length;
|
||||
+ unsigned char draft:1;
|
||||
} EVP_CHACHA_AEAD_CTX;
|
||||
|
||||
# define NO_TLS_PAYLOAD_LENGTH ((size_t)-1)
|
||||
@@ -176,6 +177,7 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
actx->aad = 0;
|
||||
actx->mac_inited = 0;
|
||||
actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 0;
|
||||
|
||||
if (iv != NULL) {
|
||||
unsigned char temp[CHACHA_CTR_SIZE] = { 0 };
|
||||
@@ -197,6 +199,27 @@ static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
|
||||
return 1;
|
||||
}
|
||||
|
||||
+static int chacha20_poly1305_draft_init_key(EVP_CIPHER_CTX *ctx,
|
||||
+ const unsigned char *inkey,
|
||||
+ const unsigned char *iv, int enc)
|
||||
+{
|
||||
+ EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
+
|
||||
+ if (!inkey)
|
||||
+ return 1;
|
||||
+
|
||||
+ actx->len.aad = 0;
|
||||
+ actx->len.text = 0;
|
||||
+ actx->aad = 0;
|
||||
+ actx->mac_inited = 0;
|
||||
+ actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
|
||||
+ actx->draft = 1;
|
||||
+
|
||||
+ chacha_init_key(ctx, inkey, NULL, enc);
|
||||
+
|
||||
+ return 1;
|
||||
+}
|
||||
+
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
|
||||
# if defined(POLY1305_ASM) && (defined(__x86_64) || defined(__x86_64__) || \
|
||||
@@ -367,10 +390,11 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
{
|
||||
EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
|
||||
size_t rem, plen = actx->tls_payload_length;
|
||||
+ uint64_t thirteen = EVP_AEAD_TLS1_AAD_LEN;
|
||||
|
||||
if (!actx->mac_inited) {
|
||||
# if !defined(OPENSSL_SMALL_FOOTPRINT)
|
||||
- if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL)
|
||||
+ if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL && !actx->draft)
|
||||
return chacha20_poly1305_tls_cipher(ctx, out, in, len);
|
||||
# endif
|
||||
actx->key.counter[0] = 0;
|
||||
@@ -397,9 +421,14 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
return len;
|
||||
} else { /* plain- or ciphertext */
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
@@ -432,40 +461,52 @@ static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
|
||||
} is_endian = { 1 };
|
||||
unsigned char temp[POLY1305_BLOCK_SIZE];
|
||||
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.text;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ }
|
||||
+
|
||||
if (actx->aad) { /* wrap up aad */
|
||||
- if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (actx->draft) {
|
||||
+ thirteen = actx->len.aad;
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), (const unsigned char *)&thirteen, sizeof(thirteen));
|
||||
+ } else {
|
||||
+ if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
+ }
|
||||
actx->aad = 0;
|
||||
}
|
||||
|
||||
- if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
- Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
- POLY1305_BLOCK_SIZE - rem);
|
||||
+ if (!actx->draft) {
|
||||
+ if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), zero,
|
||||
+ POLY1305_BLOCK_SIZE - rem);
|
||||
|
||||
- if (is_endian.little) {
|
||||
- Poly1305_Update(POLY1305_ctx(actx),
|
||||
- (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
- } else {
|
||||
- temp[0] = (unsigned char)(actx->len.aad);
|
||||
- temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
- temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
- temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
- temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
- temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
- temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
- temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
-
|
||||
- temp[8] = (unsigned char)(actx->len.text);
|
||||
- temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
- temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
- temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
- temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
- temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
- temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
- temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
-
|
||||
- Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ if (is_endian.little) {
|
||||
+ Poly1305_Update(POLY1305_ctx(actx),
|
||||
+ (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
|
||||
+ } else {
|
||||
+ temp[0] = (unsigned char)(actx->len.aad);
|
||||
+ temp[1] = (unsigned char)(actx->len.aad>>8);
|
||||
+ temp[2] = (unsigned char)(actx->len.aad>>16);
|
||||
+ temp[3] = (unsigned char)(actx->len.aad>>24);
|
||||
+ temp[4] = (unsigned char)(actx->len.aad>>32);
|
||||
+ temp[5] = (unsigned char)(actx->len.aad>>40);
|
||||
+ temp[6] = (unsigned char)(actx->len.aad>>48);
|
||||
+ temp[7] = (unsigned char)(actx->len.aad>>56);
|
||||
+
|
||||
+ temp[8] = (unsigned char)(actx->len.text);
|
||||
+ temp[9] = (unsigned char)(actx->len.text>>8);
|
||||
+ temp[10] = (unsigned char)(actx->len.text>>16);
|
||||
+ temp[11] = (unsigned char)(actx->len.text>>24);
|
||||
+ temp[12] = (unsigned char)(actx->len.text>>32);
|
||||
+ temp[13] = (unsigned char)(actx->len.text>>40);
|
||||
+ temp[14] = (unsigned char)(actx->len.text>>48);
|
||||
+ temp[15] = (unsigned char)(actx->len.text>>56);
|
||||
+
|
||||
+ Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
|
||||
+ }
|
||||
}
|
||||
Poly1305_Final(POLY1305_ctx(actx), ctx->encrypt ? actx->tag
|
||||
: temp);
|
||||
@@ -539,12 +580,14 @@ static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IVLEN:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg <= 0 || arg > CHACHA20_POLY1305_MAX_IVLEN)
|
||||
return 0;
|
||||
actx->nonce_len = arg;
|
||||
return 1;
|
||||
|
||||
case EVP_CTRL_AEAD_SET_IV_FIXED:
|
||||
+ if (actx->draft) return -1;
|
||||
if (arg != 12)
|
||||
return 0;
|
||||
actx->nonce[0] = actx->key.counter[1]
|
||||
@@ -629,9 +672,32 @@ static EVP_CIPHER chacha20_poly1305 = {
|
||||
NULL /* app_data */
|
||||
};
|
||||
|
||||
+static EVP_CIPHER chacha20_poly1305_draft = {
|
||||
+ NID_chacha20_poly1305_draft,
|
||||
+ 1, /* block_size */
|
||||
+ CHACHA_KEY_SIZE, /* key_len */
|
||||
+ 0, /* iv_len, none */
|
||||
+ EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_CUSTOM_IV |
|
||||
+ EVP_CIPH_ALWAYS_CALL_INIT | EVP_CIPH_CTRL_INIT |
|
||||
+ EVP_CIPH_CUSTOM_COPY | EVP_CIPH_FLAG_CUSTOM_CIPHER,
|
||||
+ chacha20_poly1305_draft_init_key,
|
||||
+ chacha20_poly1305_cipher,
|
||||
+ chacha20_poly1305_cleanup,
|
||||
+ 0, /* 0 moves context-specific structure allocation to ctrl */
|
||||
+ NULL, /* set_asn1_parameters */
|
||||
+ NULL, /* get_asn1_parameters */
|
||||
+ chacha20_poly1305_ctrl,
|
||||
+ NULL /* app_data */
|
||||
+};
|
||||
+
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void)
|
||||
{
|
||||
return(&chacha20_poly1305);
|
||||
}
|
||||
+
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void)
|
||||
+{
|
||||
+ return(&chacha20_poly1305_draft);
|
||||
+}
|
||||
# endif
|
||||
#endif
|
||||
diff --git a/crypto/objects/obj_dat.h b/crypto/objects/obj_dat.h
|
||||
index 77b4418cd4..6b3d7f9085 100644
|
||||
--- a/crypto/objects/obj_dat.h
|
||||
+++ b/crypto/objects/obj_dat.h
|
||||
@@ -1088,7 +1088,7 @@ static const unsigned char so[7845] = {
|
||||
0x2B,0x06,0x01,0x05,0x05,0x07,0x08,0x08, /* [ 7836] OBJ_NAIRealm */
|
||||
};
|
||||
|
||||
-#define NUM_NID 1218
|
||||
+#define NUM_NID 1219
|
||||
static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"UNDEF", "undefined", NID_undef},
|
||||
{"rsadsi", "RSA Data Security, Inc.", NID_rsadsi, 6, &so[0]},
|
||||
@@ -2308,9 +2308,10 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
|
||||
{"modp_4096", "modp_4096", NID_modp_4096},
|
||||
{"modp_6144", "modp_6144", NID_modp_6144},
|
||||
{"modp_8192", "modp_8192", NID_modp_8192},
|
||||
+ {"ChaCha20-Poly1305-D", "chacha20-poly1305-draft", NID_chacha20_poly1305_draft},
|
||||
};
|
||||
|
||||
-#define NUM_SN 1209
|
||||
+#define NUM_SN 1210
|
||||
static const unsigned int sn_objs[NUM_SN] = {
|
||||
364, /* "AD_DVCS" */
|
||||
419, /* "AES-128-CBC" */
|
||||
@@ -2433,6 +2434,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
417, /* "CSPName" */
|
||||
1019, /* "ChaCha20" */
|
||||
1018, /* "ChaCha20-Poly1305" */
|
||||
+ 1218, /* "ChaCha20-Poly1305-D" */
|
||||
367, /* "CrlID" */
|
||||
391, /* "DC" */
|
||||
31, /* "DES-CBC" */
|
||||
@@ -3523,7 +3525,7 @@ static const unsigned int sn_objs[NUM_SN] = {
|
||||
1093, /* "x509ExtAdmission" */
|
||||
};
|
||||
|
||||
-#define NUM_LN 1209
|
||||
+#define NUM_LN 1210
|
||||
static const unsigned int ln_objs[NUM_LN] = {
|
||||
363, /* "AD Time Stamping" */
|
||||
405, /* "ANSI X9.62" */
|
||||
@@ -3912,6 +3914,7 @@ static const unsigned int ln_objs[NUM_LN] = {
|
||||
883, /* "certificateRevocationList" */
|
||||
1019, /* "chacha20" */
|
||||
1018, /* "chacha20-poly1305" */
|
||||
+ 1218, /* "chacha20-poly1305-draft" */
|
||||
54, /* "challengePassword" */
|
||||
407, /* "characteristic-two-field" */
|
||||
395, /* "clearance" */
|
||||
diff --git a/crypto/objects/obj_mac.num b/crypto/objects/obj_mac.num
|
||||
index 15aa1e9772..6fb028c1e8 100644
|
||||
--- a/crypto/objects/obj_mac.num
|
||||
+++ b/crypto/objects/obj_mac.num
|
||||
@@ -1215,3 +1215,4 @@ modp_3072 1214
|
||||
modp_4096 1215
|
||||
modp_6144 1216
|
||||
modp_8192 1217
|
||||
+chacha20_poly1305_draft 1218
|
||||
diff --git a/crypto/objects/objects.txt b/crypto/objects/objects.txt
|
||||
index 9819c539b7..bb4a9958d0 100644
|
||||
--- a/crypto/objects/objects.txt
|
||||
+++ b/crypto/objects/objects.txt
|
||||
@@ -1549,6 +1549,7 @@ sm-scheme 104 7 : SM4-CTR : sm4-ctr
|
||||
: AES-192-CBC-HMAC-SHA256 : aes-192-cbc-hmac-sha256
|
||||
: AES-256-CBC-HMAC-SHA256 : aes-256-cbc-hmac-sha256
|
||||
: ChaCha20-Poly1305 : chacha20-poly1305
|
||||
+ : ChaCha20-Poly1305-D : chacha20-poly1305-draft
|
||||
: ChaCha20 : chacha20
|
||||
|
||||
ISO-US 10046 2 1 : dhpublicnumber : X9.42 DH
|
||||
diff --git a/include/openssl/evp.h b/include/openssl/evp.h
|
||||
index 4903fc5f42..97a6e9bfee 100644
|
||||
--- a/include/openssl/evp.h
|
||||
+++ b/include/openssl/evp.h
|
||||
@@ -993,6 +993,7 @@ const EVP_CIPHER *EVP_camellia_256_ctr(void);
|
||||
const EVP_CIPHER *EVP_chacha20(void);
|
||||
# ifndef OPENSSL_NO_POLY1305
|
||||
const EVP_CIPHER *EVP_chacha20_poly1305(void);
|
||||
+const EVP_CIPHER *EVP_chacha20_poly1305_draft(void);
|
||||
# endif
|
||||
# endif
|
||||
|
||||
diff --git a/include/openssl/obj_mac.h b/include/openssl/obj_mac.h
|
||||
index 0e564ac6d2..3a074d62cb 100644
|
||||
--- a/include/openssl/obj_mac.h
|
||||
+++ b/include/openssl/obj_mac.h
|
||||
@@ -4857,6 +4857,10 @@
|
||||
#define LN_chacha20_poly1305 "chacha20-poly1305"
|
||||
#define NID_chacha20_poly1305 1018
|
||||
|
||||
+#define SN_chacha20_poly1305_draft "ChaCha20-Poly1305-D"
|
||||
+#define LN_chacha20_poly1305_draft "chacha20-poly1305-draft"
|
||||
+#define NID_chacha20_poly1305_draft 1218
|
||||
+
|
||||
#define SN_chacha20 "ChaCha20"
|
||||
#define LN_chacha20 "chacha20"
|
||||
#define NID_chacha20 1019
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index e75394676f..cedfbe26c6 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -131,6 +131,7 @@ extern "C" {
|
||||
# define SSL_TXT_CAMELLIA256 "CAMELLIA256"
|
||||
# define SSL_TXT_CAMELLIA "CAMELLIA"
|
||||
# define SSL_TXT_CHACHA20 "CHACHA20"
|
||||
+# define SSL_TXT_CHACHA20_D "CHACHA20-D"
|
||||
# define SSL_TXT_GOST "GOST89"
|
||||
# define SSL_TXT_ARIA "ARIA"
|
||||
# define SSL_TXT_ARIA_GCM "ARIAGCM"
|
||||
diff --git a/include/openssl/tls1.h b/include/openssl/tls1.h
|
||||
index 9181e0d2c1..0244b1ab99 100644
|
||||
--- a/include/openssl/tls1.h
|
||||
+++ b/include/openssl/tls1.h
|
||||
@@ -578,7 +578,12 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 0x0300C09A
|
||||
# define TLS1_CK_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 0x0300C09B
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC13
|
||||
+# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D 0x0300CC14
|
||||
+# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D 0x0300CC15
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCA8
|
||||
# define TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 0x0300CCA9
|
||||
# define TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305 0x0300CCAA
|
||||
@@ -743,6 +748,9 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb
|
||||
# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305 "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
+# define TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "OLD_TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_PSK_WITH_CHACHA20_POLY1305 "TLS_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_ECDHE_PSK_WITH_CHACHA20_POLY1305 "TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
# define TLS1_RFC_DHE_PSK_WITH_CHACHA20_POLY1305 "TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256"
|
||||
@@ -1071,7 +1079,12 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 "ECDH-RSA-CAMELLIA128-SHA256"
|
||||
# define TLS1_TXT_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 "ECDH-RSA-CAMELLIA256-SHA384"
|
||||
|
||||
-/* draft-ietf-tls-chacha20-poly1305-03 */
|
||||
+/* Chacha20-Poly1305-Draft ciphersuites from draft-agl-tls-chacha20poly1305-04 */
|
||||
+# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D "ECDHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D "ECDHE-ECDSA-CHACHA20-POLY1305-OLD"
|
||||
+# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D "DHE-RSA-CHACHA20-POLY1305-OLD"
|
||||
+
|
||||
+/* Chacha20-Poly1305 ciphersuites from RFC7905 */
|
||||
# define TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305 "ECDHE-RSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 "ECDHE-ECDSA-CHACHA20-POLY1305"
|
||||
# define TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305 "DHE-RSA-CHACHA20-POLY1305"
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 26f19108ee..25ad398f7e 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -2084,6 +2084,54 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
256,
|
||||
256,
|
||||
},
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_DHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_RSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aRSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
+ {
|
||||
+ 1,
|
||||
+ TLS1_TXT_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ TLS1_CK_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_D,
|
||||
+ SSL_kECDHE,
|
||||
+ SSL_aECDSA,
|
||||
+ SSL_CHACHA20POLY1305_D,
|
||||
+ SSL_AEAD,
|
||||
+ TLS1_2_VERSION, TLS1_2_VERSION,
|
||||
+ DTLS1_2_VERSION, DTLS1_2_VERSION,
|
||||
+ SSL_HIGH,
|
||||
+ SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
|
||||
+ 256,
|
||||
+ 256,
|
||||
+ },
|
||||
{
|
||||
1,
|
||||
TLS1_TXT_PSK_WITH_CHACHA20_POLY1305,
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 04ffae325c..b04abb0df7 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -44,7 +44,8 @@
|
||||
#define SSL_ENC_CHACHA_IDX 19
|
||||
#define SSL_ENC_ARIA128GCM_IDX 20
|
||||
#define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-#define SSL_ENC_NUM_IDX 22
|
||||
+#define SSL_ENC_CHACHA20_D_IDX 22
|
||||
+#define SSL_ENC_NUM_IDX 23
|
||||
|
||||
/* NB: make sure indices in these tables match values above */
|
||||
|
||||
@@ -77,6 +78,7 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
{SSL_CHACHA20POLY1305, NID_chacha20_poly1305}, /* SSL_ENC_CHACHA_IDX 19 */
|
||||
{SSL_ARIA128GCM, NID_aria_128_gcm}, /* SSL_ENC_ARIA128GCM_IDX 20 */
|
||||
{SSL_ARIA256GCM, NID_aria_256_gcm}, /* SSL_ENC_ARIA256GCM_IDX 21 */
|
||||
+ {SSL_CHACHA20POLY1305_D, NID_chacha20_poly1305_draft}, /* SSL_ENC_CHACHA20POLY1305_IDX 22 */
|
||||
};
|
||||
|
||||
static const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
@@ -276,6 +278,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_CAMELLIA256, NULL, 0, 0, 0, SSL_CAMELLIA256},
|
||||
{0, SSL_TXT_CAMELLIA, NULL, 0, 0, 0, SSL_CAMELLIA},
|
||||
{0, SSL_TXT_CHACHA20, NULL, 0, 0, 0, SSL_CHACHA20},
|
||||
+ {0, SSL_TXT_CHACHA20_D, NULL, 0, 0, 0, SSL_CHACHA20POLY1305_D},
|
||||
{0, SSL_TXT_GOST2012_GOST8912_GOST8912, NULL, 0, 0, 0, SSL_eGOST2814789CNT12},
|
||||
|
||||
{0, SSL_TXT_ARIA, NULL, 0, 0, 0, SSL_ARIA},
|
||||
@@ -1798,6 +1801,9 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
case SSL_CHACHA20POLY1305:
|
||||
enc = "CHACHA20/POLY1305(256)";
|
||||
break;
|
||||
+ case SSL_CHACHA20POLY1305_D:
|
||||
+ enc = "CHACHA20/POLY1305-Draft(256)";
|
||||
+ break;
|
||||
default:
|
||||
enc = "unknown";
|
||||
break;
|
||||
@@ -2117,7 +2123,7 @@ int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 16;
|
||||
} else if (c->algorithm_enc & (SSL_AES128CCM8 | SSL_AES256CCM8)) {
|
||||
out = EVP_CCM_TLS_EXPLICIT_IV_LEN + 8;
|
||||
- } else if (c->algorithm_enc & SSL_CHACHA20POLY1305) {
|
||||
+ } else if (c->algorithm_enc & (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)) {
|
||||
out = 16;
|
||||
} else if (c->algorithm_mac & SSL_AEAD) {
|
||||
/* We're supposed to have handled all the AEAD modes above */
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index f0f0a53ecf..e3935b4edb 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -234,12 +234,13 @@
|
||||
# define SSL_CHACHA20POLY1305 0x00080000U
|
||||
# define SSL_ARIA128GCM 0x00100000U
|
||||
# define SSL_ARIA256GCM 0x00200000U
|
||||
+# define SSL_CHACHA20POLY1305_D 0x00400000U
|
||||
|
||||
# define SSL_AESGCM (SSL_AES128GCM | SSL_AES256GCM)
|
||||
# define SSL_AESCCM (SSL_AES128CCM | SSL_AES256CCM | SSL_AES128CCM8 | SSL_AES256CCM8)
|
||||
# define SSL_AES (SSL_AES128|SSL_AES256|SSL_AESGCM|SSL_AESCCM)
|
||||
# define SSL_CAMELLIA (SSL_CAMELLIA128|SSL_CAMELLIA256)
|
||||
-# define SSL_CHACHA20 (SSL_CHACHA20POLY1305)
|
||||
+# define SSL_CHACHA20 (SSL_CHACHA20POLY1305 | SSL_CHACHA20POLY1305_D)
|
||||
# define SSL_ARIAGCM (SSL_ARIA128GCM | SSL_ARIA256GCM)
|
||||
# define SSL_ARIA (SSL_ARIAGCM)
|
||||
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index f81fefb9b2..e7ab97676c 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -4622,6 +4622,7 @@ i2d_KeyParams ? 3_0_0 EXIST::FUNCTION:
|
||||
d2i_KeyParams ? 3_0_0 EXIST::FUNCTION:
|
||||
i2d_KeyParams_bio ? 3_0_0 EXIST::FUNCTION:
|
||||
d2i_KeyParams_bio ? 3_0_0 EXIST::FUNCTION:
|
||||
+EVP_chacha20_poly1305_draft ? 3_0_0 EXIST::FUNCTION:CHACHA,POLY1305
|
||||
OSSL_CMP_PKISTATUS_it ? 3_0_0 EXIST::FUNCTION:CMP
|
||||
d2i_OSSL_CMP_PKIHEADER ? 3_0_0 EXIST::FUNCTION:CMP
|
||||
i2d_OSSL_CMP_PKIHEADER ? 3_0_0 EXIST::FUNCTION:CMP
|
||||
@@ -0,0 +1,3699 @@
|
||||
diff --git a/apps/build.info b/apps/build.info
|
||||
index 2186de3a27..ee934e1fb1 100644
|
||||
--- a/apps/build.info
|
||||
+++ b/apps/build.info
|
||||
@@ -14,14 +14,14 @@ $OPENSSLSRC=\
|
||||
openssl.c progs.c \
|
||||
asn1pars.c ca.c ciphers.c cms.c crl.c crl2p7.c dgst.c \
|
||||
ec.c ecparam.c enc.c engine.c errstr.c \
|
||||
- genpkey.c kdf.c mac.c nseq.c ocsp.c passwd.c pkcs12.c pkcs7.c \
|
||||
- pkcs8.c pkey.c pkeyparam.c pkeyutl.c prime.c rand.c req.c \
|
||||
- s_client.c s_server.c s_time.c sess_id.c smime.c speed.c \
|
||||
+ genpkey.c genrsa.c kdf.c mac.c nseq.c ocsp.c passwd.c pkcs12.c pkcs7.c \
|
||||
+ pkcs8.c pkey.c pkeyparam.c pkeyutl.c prime.c rand.c req.c rsa.c \
|
||||
+ rsautl.c s_client.c s_server.c s_time.c sess_id.c smime.c speed.c \
|
||||
spkac.c srp.c ts.c verify.c version.c x509.c rehash.c storeutl.c \
|
||||
list.c info.c provider.c fipsinstall.c
|
||||
IF[{- !$disabled{'deprecated-3.0'} -}]
|
||||
$OPENSSLSRC=$OPENSSLSRC \
|
||||
- dhparam.c dsa.c dsaparam.c gendsa.c rsa.c rsautl.c genrsa.c
|
||||
+ dhparam.c dsa.c dsaparam.c gendsa.c
|
||||
ENDIF
|
||||
IF[{- !$disabled{'cmp'} -}]
|
||||
$OPENSSLSRC=$OPENSSLSRC cmp_mock_srv.c
|
||||
diff --git a/apps/genrsa.c b/apps/genrsa.c
|
||||
index 3f76d9bada..a7d04fed30 100644
|
||||
--- a/apps/genrsa.c
|
||||
+++ b/apps/genrsa.c
|
||||
@@ -7,9 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/* We need to use the deprecated RSA low level calls */
|
||||
-#define OPENSSL_SUPPRESS_DEPRECATED
|
||||
-
|
||||
#include <openssl/opensslconf.h>
|
||||
#ifdef OPENSSL_NO_RSA
|
||||
NON_EMPTY_TRANSLATION_UNIT
|
||||
diff --git a/apps/rsa.c b/apps/rsa.c
|
||||
index d626bbb31a..539b0144ab 100644
|
||||
--- a/apps/rsa.c
|
||||
+++ b/apps/rsa.c
|
||||
@@ -7,9 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/* We need to use the deprecated RSA low level calls */
|
||||
-#define OPENSSL_SUPPRESS_DEPRECATED
|
||||
-
|
||||
#include <openssl/opensslconf.h>
|
||||
#ifdef OPENSSL_NO_RSA
|
||||
NON_EMPTY_TRANSLATION_UNIT
|
||||
diff --git a/apps/rsautl.c b/apps/rsautl.c
|
||||
index b72f527ce4..ddd507ce9a 100644
|
||||
--- a/apps/rsautl.c
|
||||
+++ b/apps/rsautl.c
|
||||
@@ -7,9 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/* We need to use the deprecated RSA low level calls */
|
||||
-#define OPENSSL_SUPPRESS_DEPRECATED
|
||||
-
|
||||
#include <openssl/opensslconf.h>
|
||||
#ifdef OPENSSL_NO_RSA
|
||||
NON_EMPTY_TRANSLATION_UNIT
|
||||
diff --git a/apps/speed.c b/apps/speed.c
|
||||
index 9d4ab2c330..c735ad2031 100644
|
||||
--- a/apps/speed.c
|
||||
+++ b/apps/speed.c
|
||||
@@ -94,7 +94,7 @@
|
||||
#ifndef OPENSSL_NO_CAST
|
||||
# include <openssl/cast.h>
|
||||
#endif
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
# include <openssl/rsa.h>
|
||||
# include "./testrsa.h"
|
||||
#endif
|
||||
@@ -417,7 +417,7 @@ static const OPT_PAIR dsa_choices[DSA_NUM] = {
|
||||
static double dsa_results[DSA_NUM][2]; /* 2 ops: sign then verify */
|
||||
#endif /* OPENSSL_NO_DSA */
|
||||
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
enum {
|
||||
R_RSA_512, R_RSA_1024, R_RSA_2048, R_RSA_3072, R_RSA_4096, R_RSA_7680,
|
||||
R_RSA_15360, RSA_NUM
|
||||
@@ -543,7 +543,7 @@ typedef struct loopargs_st {
|
||||
unsigned char *key;
|
||||
unsigned int siglen;
|
||||
size_t sigsize;
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
RSA *rsa_key[RSA_NUM];
|
||||
#endif
|
||||
#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
@@ -1022,7 +1022,7 @@ static int EVP_CMAC_loop(void *args)
|
||||
}
|
||||
#endif
|
||||
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
static long rsa_c[RSA_NUM][2]; /* # RSA iteration test */
|
||||
|
||||
static int RSA_sign_loop(void *args)
|
||||
@@ -1504,7 +1504,7 @@ int speed_main(int argc, char **argv)
|
||||
#if !defined(OPENSSL_NO_CAMELLIA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
CAMELLIA_KEY camellia_ks[3];
|
||||
#endif
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
static const struct {
|
||||
const unsigned char *data;
|
||||
unsigned int length;
|
||||
@@ -1712,10 +1712,8 @@ int speed_main(int argc, char **argv)
|
||||
goto end;
|
||||
break;
|
||||
case OPT_PRIMES:
|
||||
-#ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
if (!opt_int(opt_arg(), &primes))
|
||||
goto end;
|
||||
-#endif
|
||||
break;
|
||||
case OPT_SECONDS:
|
||||
seconds.sym = seconds.rsa = seconds.dsa = seconds.ecdsa
|
||||
@@ -1753,7 +1751,7 @@ int speed_main(int argc, char **argv)
|
||||
doit[D_SHA1] = doit[D_SHA256] = doit[D_SHA512] = 1;
|
||||
continue;
|
||||
}
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
if (strcmp(algo, "openssl") == 0) /* just for compatibility */
|
||||
continue;
|
||||
if (strncmp(algo, "rsa", 3) == 0) {
|
||||
@@ -1916,7 +1914,7 @@ int speed_main(int argc, char **argv)
|
||||
if (argc == 0 && !doit[D_EVP] && !doit[D_EVP_HMAC] && !doit[D_EVP_CMAC]) {
|
||||
memset(doit, 1, sizeof(doit));
|
||||
doit[D_EVP] = doit[D_EVP_HMAC] = doit[D_EVP_CMAC] = 0;
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
memset(rsa_doit, 1, sizeof(rsa_doit));
|
||||
#endif
|
||||
#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
@@ -1940,7 +1938,7 @@ int speed_main(int argc, char **argv)
|
||||
"You have chosen to measure elapsed time "
|
||||
"instead of user CPU time.\n");
|
||||
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
for (i = 0; i < loopargs_len; i++) {
|
||||
if (primes > RSA_DEFAULT_PRIME_NUM) {
|
||||
/* for multi-prime RSA, skip this */
|
||||
@@ -2110,7 +2108,7 @@ int speed_main(int argc, char **argv)
|
||||
c[D_IGE_256_AES][i] = c[D_IGE_256_AES][i - 1] * l0 / l1;
|
||||
}
|
||||
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+# ifndef OPENSSL_NO_RSA
|
||||
rsa_c[R_RSA_512][0] = count / 2000;
|
||||
rsa_c[R_RSA_512][1] = count / 400;
|
||||
for (i = 1; i < RSA_NUM; i++) {
|
||||
@@ -2866,7 +2864,7 @@ int speed_main(int argc, char **argv)
|
||||
if (RAND_bytes(loopargs[i].buf, 36) <= 0)
|
||||
goto end;
|
||||
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
for (testnum = 0; testnum < RSA_NUM; testnum++) {
|
||||
int st = 0;
|
||||
if (!rsa_doit[testnum])
|
||||
@@ -3571,7 +3569,7 @@ int speed_main(int argc, char **argv)
|
||||
}
|
||||
printf("\n");
|
||||
}
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
testnum = 1;
|
||||
for (k = 0; k < RSA_NUM; k++) {
|
||||
if (!rsa_doit[k])
|
||||
@@ -3698,7 +3696,7 @@ int speed_main(int argc, char **argv)
|
||||
OPENSSL_free(loopargs[i].buf_malloc);
|
||||
OPENSSL_free(loopargs[i].buf2_malloc);
|
||||
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
+#ifndef OPENSSL_NO_RSA
|
||||
for (k = 0; k < RSA_NUM; k++)
|
||||
RSA_free(loopargs[i].rsa_key[k]);
|
||||
#endif
|
||||
@@ -3894,9 +3892,7 @@ static int do_multi(int multi, int size_num)
|
||||
sstrsep(&p, sep);
|
||||
for (j = 0; j < size_num; ++j)
|
||||
results[alg][j] += atof(sstrsep(&p, sep));
|
||||
- }
|
||||
-#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
- else if (strncmp(buf, "+F2:", 4) == 0) {
|
||||
+ } else if (strncmp(buf, "+F2:", 4) == 0) {
|
||||
int k;
|
||||
double d;
|
||||
|
||||
@@ -3910,7 +3906,6 @@ static int do_multi(int multi, int size_num)
|
||||
d = atof(sstrsep(&p, sep));
|
||||
rsa_results[k][1] += d;
|
||||
}
|
||||
-#endif
|
||||
#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
else if (strncmp(buf, "+F3:", 4) == 0) {
|
||||
int k;
|
||||
diff --git a/crypto/evp/p_dec.c b/crypto/evp/p_dec.c
|
||||
index 9a6f271000..d1d8b0b59e 100644
|
||||
--- a/crypto/evp/p_dec.c
|
||||
+++ b/crypto/evp/p_dec.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/rsa.h>
|
||||
diff --git a/crypto/evp/p_enc.c b/crypto/evp/p_enc.c
|
||||
index 349eabde4c..4c169857c2 100644
|
||||
--- a/crypto/evp/p_enc.c
|
||||
+++ b/crypto/evp/p_enc.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/rsa.h>
|
||||
diff --git a/crypto/rsa/rsa_ameth.c b/crypto/rsa/rsa_ameth.c
|
||||
index fb378ae039..f4a5a06e5d 100644
|
||||
--- a/crypto/rsa/rsa_ameth.c
|
||||
+++ b/crypto/rsa/rsa_ameth.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/asn1t.h>
|
||||
diff --git a/crypto/rsa/rsa_asn1.c b/crypto/rsa/rsa_asn1.c
|
||||
index 8798bd52d6..e6b81253fa 100644
|
||||
--- a/crypto/rsa/rsa_asn1.c
|
||||
+++ b/crypto/rsa/rsa_asn1.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/bn.h>
|
||||
diff --git a/crypto/rsa/rsa_chk.c b/crypto/rsa/rsa_chk.c
|
||||
index e6b700bc0d..6ba0010c77 100644
|
||||
--- a/crypto/rsa/rsa_chk.c
|
||||
+++ b/crypto/rsa/rsa_chk.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <openssl/bn.h>
|
||||
#include <openssl/err.h>
|
||||
#include "crypto/rsa.h"
|
||||
diff --git a/crypto/rsa/rsa_crpt.c b/crypto/rsa/rsa_crpt.c
|
||||
index 83cae46103..6abee298c6 100644
|
||||
--- a/crypto/rsa/rsa_crpt.c
|
||||
+++ b/crypto/rsa/rsa_crpt.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include <openssl/crypto.h>
|
||||
#include "internal/cryptlib.h"
|
||||
diff --git a/crypto/rsa/rsa_depr.c b/crypto/rsa/rsa_depr.c
|
||||
index 8ba6e8c2ee..ed63262645 100644
|
||||
--- a/crypto/rsa/rsa_depr.c
|
||||
+++ b/crypto/rsa/rsa_depr.c
|
||||
@@ -12,12 +12,6 @@
|
||||
* "new" versions).
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <openssl/opensslconf.h>
|
||||
#ifdef OPENSSL_NO_DEPRECATED_0_9_8
|
||||
NON_EMPTY_TRANSLATION_UNIT
|
||||
diff --git a/crypto/rsa/rsa_gen.c b/crypto/rsa/rsa_gen.c
|
||||
index 5d82ae6f34..b74f43f8a1 100644
|
||||
--- a/crypto/rsa/rsa_gen.c
|
||||
+++ b/crypto/rsa/rsa_gen.c
|
||||
@@ -13,12 +13,6 @@
|
||||
* Geoff
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include <time.h>
|
||||
#include "internal/cryptlib.h"
|
||||
diff --git a/crypto/rsa/rsa_lib.c b/crypto/rsa/rsa_lib.c
|
||||
index e9a5b48fbc..51fd3c5ca0 100644
|
||||
--- a/crypto/rsa/rsa_lib.c
|
||||
+++ b/crypto/rsa/rsa_lib.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include <openssl/crypto.h>
|
||||
#include <openssl/core_names.h>
|
||||
diff --git a/crypto/rsa/rsa_meth.c b/crypto/rsa/rsa_meth.c
|
||||
index 6bbe21814e..a2a0426ee4 100644
|
||||
--- a/crypto/rsa/rsa_meth.c
|
||||
+++ b/crypto/rsa/rsa_meth.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <string.h>
|
||||
#include "rsa_local.h"
|
||||
#include <openssl/err.h>
|
||||
diff --git a/crypto/rsa/rsa_none.c b/crypto/rsa/rsa_none.c
|
||||
index 5298ca7328..833ab94028 100644
|
||||
--- a/crypto/rsa/rsa_none.c
|
||||
+++ b/crypto/rsa/rsa_none.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/bn.h>
|
||||
#include <openssl/rsa.h>
|
||||
diff --git a/crypto/rsa/rsa_oaep.c b/crypto/rsa/rsa_oaep.c
|
||||
index ed486acbe6..a0af741183 100644
|
||||
--- a/crypto/rsa/rsa_oaep.c
|
||||
+++ b/crypto/rsa/rsa_oaep.c
|
||||
@@ -20,12 +20,6 @@
|
||||
* one-wayness. For the RSA function, this is an equivalent notion.
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include "internal/constant_time.h"
|
||||
|
||||
#include <stdio.h>
|
||||
diff --git a/crypto/rsa/rsa_ossl.c b/crypto/rsa/rsa_ossl.c
|
||||
index 504ad82f17..7746f6d961 100644
|
||||
--- a/crypto/rsa/rsa_ossl.c
|
||||
+++ b/crypto/rsa/rsa_ossl.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include "internal/cryptlib.h"
|
||||
#include "crypto/bn.h"
|
||||
#include "rsa_local.h"
|
||||
diff --git a/crypto/rsa/rsa_pk1.c b/crypto/rsa/rsa_pk1.c
|
||||
index b8aa49d701..c6bbf2dcd6 100644
|
||||
--- a/crypto/rsa/rsa_pk1.c
|
||||
+++ b/crypto/rsa/rsa_pk1.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include "internal/constant_time.h"
|
||||
|
||||
#include <stdio.h>
|
||||
diff --git a/crypto/rsa/rsa_pmeth.c b/crypto/rsa/rsa_pmeth.c
|
||||
index 7a298d5d93..96937ae059 100644
|
||||
--- a/crypto/rsa/rsa_pmeth.c
|
||||
+++ b/crypto/rsa/rsa_pmeth.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include "internal/constant_time.h"
|
||||
|
||||
#include <stdio.h>
|
||||
diff --git a/crypto/rsa/rsa_prn.c b/crypto/rsa/rsa_prn.c
|
||||
index 1e52e9e3e6..5e4c098a16 100644
|
||||
--- a/crypto/rsa/rsa_prn.c
|
||||
+++ b/crypto/rsa/rsa_prn.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/rsa.h>
|
||||
diff --git a/crypto/rsa/rsa_pss.c b/crypto/rsa/rsa_pss.c
|
||||
index 999fc3122f..bd82faf54a 100644
|
||||
--- a/crypto/rsa/rsa_pss.c
|
||||
+++ b/crypto/rsa/rsa_pss.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/bn.h>
|
||||
diff --git a/crypto/rsa/rsa_saos.c b/crypto/rsa/rsa_saos.c
|
||||
index e7041ca2ae..7041535cc0 100644
|
||||
--- a/crypto/rsa/rsa_saos.c
|
||||
+++ b/crypto/rsa/rsa_saos.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/bn.h>
|
||||
diff --git a/crypto/rsa/rsa_sign.c b/crypto/rsa/rsa_sign.c
|
||||
index 544cca446e..3d89a8db54 100644
|
||||
--- a/crypto/rsa/rsa_sign.c
|
||||
+++ b/crypto/rsa/rsa_sign.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/bn.h>
|
||||
diff --git a/crypto/rsa/rsa_ssl.c b/crypto/rsa/rsa_ssl.c
|
||||
index 0309665338..49005a54a4 100644
|
||||
--- a/crypto/rsa/rsa_ssl.c
|
||||
+++ b/crypto/rsa/rsa_ssl.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/bn.h>
|
||||
diff --git a/crypto/rsa/rsa_x931.c b/crypto/rsa/rsa_x931.c
|
||||
index 7a1503752f..3caafb699f 100644
|
||||
--- a/crypto/rsa/rsa_x931.c
|
||||
+++ b/crypto/rsa/rsa_x931.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/bn.h>
|
||||
diff --git a/crypto/rsa/rsa_x931g.c b/crypto/rsa/rsa_x931g.c
|
||||
index 7b65133ec8..1f6042a3d2 100644
|
||||
--- a/crypto/rsa/rsa_x931g.c
|
||||
+++ b/crypto/rsa/rsa_x931g.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
#include <time.h>
|
||||
diff --git a/engines/build.info b/engines/build.info
|
||||
index 3bfe1dc057..fca41358e9 100644
|
||||
--- a/engines/build.info
|
||||
+++ b/engines/build.info
|
||||
@@ -78,7 +78,6 @@ IF[{- !$disabled{"engine"} -}]
|
||||
SOURCE[dasync]=dasync.ld
|
||||
GENERATE[dasync.ld]=../util/engines.num
|
||||
ENDIF
|
||||
-
|
||||
SOURCE[ossltest]=e_ossltest.c
|
||||
DEPEND[ossltest]=../libcrypto
|
||||
INCLUDE[ossltest]=../include
|
||||
diff --git a/engines/e_dasync.c b/engines/e_dasync.c
|
||||
index 446680e535..c5d58ded09 100644
|
||||
--- a/engines/e_dasync.c
|
||||
+++ b/engines/e_dasync.c
|
||||
@@ -15,7 +15,6 @@
|
||||
*/
|
||||
#include "internal/deprecated.h"
|
||||
|
||||
-#include <openssl/opensslconf.h>
|
||||
#if defined(_WIN32)
|
||||
# include <windows.h>
|
||||
#endif
|
||||
@@ -102,29 +101,22 @@ static int dasync_digest_nids(const int **nids)
|
||||
}
|
||||
|
||||
/* RSA */
|
||||
-static int dasync_pkey(ENGINE *e, EVP_PKEY_METHOD **pmeth,
|
||||
- const int **pnids, int nid);
|
||||
-
|
||||
-static int dasync_rsa_init(EVP_PKEY_CTX *ctx);
|
||||
-static void dasync_rsa_cleanup(EVP_PKEY_CTX *ctx);
|
||||
-static int dasync_rsa_paramgen_init(EVP_PKEY_CTX *ctx);
|
||||
-static int dasync_rsa_paramgen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey);
|
||||
-static int dasync_rsa_keygen_init(EVP_PKEY_CTX *ctx);
|
||||
-static int dasync_rsa_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey);
|
||||
-static int dasync_rsa_encrypt_init(EVP_PKEY_CTX *ctx);
|
||||
-static int dasync_rsa_encrypt(EVP_PKEY_CTX *ctx, unsigned char *out,
|
||||
- size_t *outlen, const unsigned char *in,
|
||||
- size_t inlen);
|
||||
-static int dasync_rsa_decrypt_init(EVP_PKEY_CTX *ctx);
|
||||
-static int dasync_rsa_decrypt(EVP_PKEY_CTX *ctx, unsigned char *out,
|
||||
- size_t *outlen, const unsigned char *in,
|
||||
- size_t inlen);
|
||||
-static int dasync_rsa_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2);
|
||||
-static int dasync_rsa_ctrl_str(EVP_PKEY_CTX *ctx, const char *type,
|
||||
- const char *value);
|
||||
-
|
||||
-static EVP_PKEY_METHOD *dasync_rsa;
|
||||
-static const EVP_PKEY_METHOD *dasync_rsa_orig;
|
||||
+
|
||||
+static int dasync_pub_enc(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+static int dasync_pub_dec(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+static int dasync_rsa_priv_enc(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+static int dasync_rsa_priv_dec(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+static int dasync_rsa_mod_exp(BIGNUM *r0, const BIGNUM *I, RSA *rsa,
|
||||
+ BN_CTX *ctx);
|
||||
+
|
||||
+static int dasync_rsa_init(RSA *rsa);
|
||||
+static int dasync_rsa_finish(RSA *rsa);
|
||||
+
|
||||
+static RSA_METHOD *dasync_rsa_method = NULL;
|
||||
|
||||
/* AES */
|
||||
|
||||
@@ -205,30 +197,26 @@ static int dasync_cipher_nids[] = {
|
||||
|
||||
static int bind_dasync(ENGINE *e)
|
||||
{
|
||||
- /* Setup RSA */
|
||||
- ;
|
||||
- if ((dasync_rsa_orig = EVP_PKEY_meth_find(EVP_PKEY_RSA)) == NULL
|
||||
- || (dasync_rsa = EVP_PKEY_meth_new(EVP_PKEY_RSA, 0)) == NULL)
|
||||
+ /* Setup RSA_METHOD */
|
||||
+ if ((dasync_rsa_method = RSA_meth_new("Dummy Async RSA method", 0)) == NULL
|
||||
+ || RSA_meth_set_pub_enc(dasync_rsa_method, dasync_pub_enc) == 0
|
||||
+ || RSA_meth_set_pub_dec(dasync_rsa_method, dasync_pub_dec) == 0
|
||||
+ || RSA_meth_set_priv_enc(dasync_rsa_method, dasync_rsa_priv_enc) == 0
|
||||
+ || RSA_meth_set_priv_dec(dasync_rsa_method, dasync_rsa_priv_dec) == 0
|
||||
+ || RSA_meth_set_mod_exp(dasync_rsa_method, dasync_rsa_mod_exp) == 0
|
||||
+ || RSA_meth_set_bn_mod_exp(dasync_rsa_method, BN_mod_exp_mont) == 0
|
||||
+ || RSA_meth_set_init(dasync_rsa_method, dasync_rsa_init) == 0
|
||||
+ || RSA_meth_set_finish(dasync_rsa_method, dasync_rsa_finish) == 0) {
|
||||
+ DASYNCerr(DASYNC_F_BIND_DASYNC, DASYNC_R_INIT_FAILED);
|
||||
return 0;
|
||||
- EVP_PKEY_meth_set_init(dasync_rsa, dasync_rsa_init);
|
||||
- EVP_PKEY_meth_set_cleanup(dasync_rsa, dasync_rsa_cleanup);
|
||||
- EVP_PKEY_meth_set_paramgen(dasync_rsa, dasync_rsa_paramgen_init,
|
||||
- dasync_rsa_paramgen);
|
||||
- EVP_PKEY_meth_set_keygen(dasync_rsa, dasync_rsa_keygen_init,
|
||||
- dasync_rsa_keygen);
|
||||
- EVP_PKEY_meth_set_encrypt(dasync_rsa, dasync_rsa_encrypt_init,
|
||||
- dasync_rsa_encrypt);
|
||||
- EVP_PKEY_meth_set_decrypt(dasync_rsa, dasync_rsa_decrypt_init,
|
||||
- dasync_rsa_decrypt);
|
||||
- EVP_PKEY_meth_set_ctrl(dasync_rsa, dasync_rsa_ctrl,
|
||||
- dasync_rsa_ctrl_str);
|
||||
+ }
|
||||
|
||||
/* Ensure the dasync error handling is set up */
|
||||
ERR_load_DASYNC_strings();
|
||||
|
||||
if (!ENGINE_set_id(e, engine_dasync_id)
|
||||
|| !ENGINE_set_name(e, engine_dasync_name)
|
||||
- || !ENGINE_set_pkey_meths(e, dasync_pkey)
|
||||
+ || !ENGINE_set_RSA(e, dasync_rsa_method)
|
||||
|| !ENGINE_set_digests(e, dasync_digests)
|
||||
|| !ENGINE_set_ciphers(e, dasync_ciphers)
|
||||
|| !ENGINE_set_destroy_function(e, dasync_destroy)
|
||||
@@ -307,13 +295,6 @@ static int bind_dasync(ENGINE *e)
|
||||
return 1;
|
||||
}
|
||||
|
||||
-static void destroy_pkey(void)
|
||||
-{
|
||||
- EVP_PKEY_meth_free(dasync_rsa);
|
||||
- dasync_rsa_orig = NULL;
|
||||
- dasync_rsa = NULL;
|
||||
-}
|
||||
-
|
||||
# ifndef OPENSSL_NO_DYNAMIC_ENGINE
|
||||
static int bind_helper(ENGINE *e, const char *id)
|
||||
{
|
||||
@@ -366,30 +347,11 @@ static int dasync_destroy(ENGINE *e)
|
||||
{
|
||||
destroy_digests();
|
||||
destroy_ciphers();
|
||||
- destroy_pkey();
|
||||
+ RSA_meth_free(dasync_rsa_method);
|
||||
ERR_unload_DASYNC_strings();
|
||||
return 1;
|
||||
}
|
||||
|
||||
-static int dasync_pkey(ENGINE *e, EVP_PKEY_METHOD **pmeth,
|
||||
- const int **pnids, int nid)
|
||||
-{
|
||||
- static const int rnid = EVP_PKEY_RSA;
|
||||
-
|
||||
- if (pmeth == NULL) {
|
||||
- *pnids = &rnid;
|
||||
- return 1;
|
||||
- }
|
||||
-
|
||||
- if (nid == EVP_PKEY_RSA) {
|
||||
- *pmeth = dasync_rsa;
|
||||
- return 1;
|
||||
- }
|
||||
-
|
||||
- *pmeth = NULL;
|
||||
- return 0;
|
||||
-}
|
||||
-
|
||||
static int dasync_digests(ENGINE *e, const EVP_MD **digest,
|
||||
const int **nids, int nid)
|
||||
{
|
||||
@@ -560,6 +522,60 @@ static int dasync_sha1_final(EVP_MD_CTX *ctx, unsigned char *md)
|
||||
return EVP_MD_meth_get_final(EVP_sha1())(ctx, md);
|
||||
}
|
||||
|
||||
+/*
|
||||
+ * RSA implementation
|
||||
+ */
|
||||
+
|
||||
+static int dasync_pub_enc(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding) {
|
||||
+ /* Ignore errors - we carry on anyway */
|
||||
+ dummy_pause_job();
|
||||
+ return RSA_meth_get_pub_enc(RSA_PKCS1_OpenSSL())
|
||||
+ (flen, from, to, rsa, padding);
|
||||
+}
|
||||
+
|
||||
+static int dasync_pub_dec(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding) {
|
||||
+ /* Ignore errors - we carry on anyway */
|
||||
+ dummy_pause_job();
|
||||
+ return RSA_meth_get_pub_dec(RSA_PKCS1_OpenSSL())
|
||||
+ (flen, from, to, rsa, padding);
|
||||
+}
|
||||
+
|
||||
+static int dasync_rsa_priv_enc(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding)
|
||||
+{
|
||||
+ /* Ignore errors - we carry on anyway */
|
||||
+ dummy_pause_job();
|
||||
+ return RSA_meth_get_priv_enc(RSA_PKCS1_OpenSSL())
|
||||
+ (flen, from, to, rsa, padding);
|
||||
+}
|
||||
+
|
||||
+static int dasync_rsa_priv_dec(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding)
|
||||
+{
|
||||
+ /* Ignore errors - we carry on anyway */
|
||||
+ dummy_pause_job();
|
||||
+ return RSA_meth_get_priv_dec(RSA_PKCS1_OpenSSL())
|
||||
+ (flen, from, to, rsa, padding);
|
||||
+}
|
||||
+
|
||||
+static int dasync_rsa_mod_exp(BIGNUM *r0, const BIGNUM *I, RSA *rsa, BN_CTX *ctx)
|
||||
+{
|
||||
+ /* Ignore errors - we carry on anyway */
|
||||
+ dummy_pause_job();
|
||||
+ return RSA_meth_get_mod_exp(RSA_PKCS1_OpenSSL())(r0, I, rsa, ctx);
|
||||
+}
|
||||
+
|
||||
+static int dasync_rsa_init(RSA *rsa)
|
||||
+{
|
||||
+ return RSA_meth_get_init(RSA_PKCS1_OpenSSL())(rsa);
|
||||
+}
|
||||
+static int dasync_rsa_finish(RSA *rsa)
|
||||
+{
|
||||
+ return RSA_meth_get_finish(RSA_PKCS1_OpenSSL())(rsa);
|
||||
+}
|
||||
+
|
||||
/* Cipher helper functions */
|
||||
|
||||
static int dasync_cipher_ctrl_helper(EVP_CIPHER_CTX *ctx, int type, int arg,
|
||||
@@ -787,125 +803,3 @@ static int dasync_aes128_cbc_hmac_sha1_cleanup(EVP_CIPHER_CTX *ctx)
|
||||
*/
|
||||
return dasync_cipher_cleanup_helper(ctx, EVP_aes_128_cbc_hmac_sha1());
|
||||
}
|
||||
-
|
||||
-
|
||||
-/*
|
||||
- * RSA implementation
|
||||
- */
|
||||
-static int dasync_rsa_init(EVP_PKEY_CTX *ctx)
|
||||
-{
|
||||
- static int (*pinit)(EVP_PKEY_CTX *ctx);
|
||||
-
|
||||
- if (pinit == NULL)
|
||||
- EVP_PKEY_meth_get_init(dasync_rsa_orig, &pinit);
|
||||
- return pinit(ctx);
|
||||
-}
|
||||
-
|
||||
-static void dasync_rsa_cleanup(EVP_PKEY_CTX *ctx)
|
||||
-{
|
||||
- static void (*pcleanup)(EVP_PKEY_CTX *ctx);
|
||||
-
|
||||
- if (pcleanup == NULL)
|
||||
- EVP_PKEY_meth_get_cleanup(dasync_rsa_orig, &pcleanup);
|
||||
- pcleanup(ctx);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_paramgen_init(EVP_PKEY_CTX *ctx)
|
||||
-{
|
||||
- static int (*pparamgen_init)(EVP_PKEY_CTX *ctx);
|
||||
-
|
||||
- if (pparamgen_init == NULL)
|
||||
- EVP_PKEY_meth_get_paramgen(dasync_rsa_orig, &pparamgen_init, NULL);
|
||||
- return pparamgen_init(ctx);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_paramgen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
|
||||
-{
|
||||
- static int (*pparamgen)(EVP_PKEY_CTX *c, EVP_PKEY *pkey);
|
||||
-
|
||||
- if (pparamgen == NULL)
|
||||
- EVP_PKEY_meth_get_paramgen(dasync_rsa_orig, NULL, &pparamgen);
|
||||
- return pparamgen(ctx, pkey);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_keygen_init(EVP_PKEY_CTX *ctx)
|
||||
-{
|
||||
- static int (*pkeygen_init)(EVP_PKEY_CTX *ctx);
|
||||
-
|
||||
- if (pkeygen_init == NULL)
|
||||
- EVP_PKEY_meth_get_keygen(dasync_rsa_orig, &pkeygen_init, NULL);
|
||||
- return pkeygen_init(ctx);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
|
||||
-{
|
||||
- static int (*pkeygen)(EVP_PKEY_CTX *c, EVP_PKEY *pkey);
|
||||
-
|
||||
- if (pkeygen == NULL)
|
||||
- EVP_PKEY_meth_get_keygen(dasync_rsa_orig, NULL, &pkeygen);
|
||||
- return pkeygen(ctx, pkey);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_encrypt_init(EVP_PKEY_CTX *ctx)
|
||||
-{
|
||||
- static int (*pencrypt_init)(EVP_PKEY_CTX *ctx);
|
||||
-
|
||||
- if (pencrypt_init == NULL)
|
||||
- EVP_PKEY_meth_get_encrypt(dasync_rsa_orig, &pencrypt_init, NULL);
|
||||
- return pencrypt_init(ctx);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_encrypt(EVP_PKEY_CTX *ctx, unsigned char *out,
|
||||
- size_t *outlen, const unsigned char *in,
|
||||
- size_t inlen)
|
||||
-{
|
||||
- static int (*pencryptfn)(EVP_PKEY_CTX *ctx, unsigned char *out,
|
||||
- size_t *outlen, const unsigned char *in,
|
||||
- size_t inlen);
|
||||
-
|
||||
- if (pencryptfn == NULL)
|
||||
- EVP_PKEY_meth_get_encrypt(dasync_rsa_orig, NULL, &pencryptfn);
|
||||
- return pencryptfn(ctx, out, outlen, in, inlen);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_decrypt_init(EVP_PKEY_CTX *ctx)
|
||||
-{
|
||||
- static int (*pdecrypt_init)(EVP_PKEY_CTX *ctx);
|
||||
-
|
||||
- if (pdecrypt_init == NULL)
|
||||
- EVP_PKEY_meth_get_decrypt(dasync_rsa_orig, &pdecrypt_init, NULL);
|
||||
- return pdecrypt_init(ctx);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_decrypt(EVP_PKEY_CTX *ctx, unsigned char *out,
|
||||
- size_t *outlen, const unsigned char *in,
|
||||
- size_t inlen)
|
||||
-{
|
||||
- static int (*pdecrypt)(EVP_PKEY_CTX *ctx, unsigned char *out,
|
||||
- size_t *outlen, const unsigned char *in,
|
||||
- size_t inlen);
|
||||
-
|
||||
- if (pdecrypt == NULL)
|
||||
- EVP_PKEY_meth_get_encrypt(dasync_rsa_orig, NULL, &pdecrypt);
|
||||
- return pdecrypt(ctx, out, outlen, in, inlen);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
|
||||
-{
|
||||
- static int (*pctrl)(EVP_PKEY_CTX *ctx, int type, int p1, void *p2);
|
||||
-
|
||||
- if (pctrl == NULL)
|
||||
- EVP_PKEY_meth_get_ctrl(dasync_rsa_orig, &pctrl, NULL);
|
||||
- return pctrl(ctx, type, p1, p2);
|
||||
-}
|
||||
-
|
||||
-static int dasync_rsa_ctrl_str(EVP_PKEY_CTX *ctx, const char *type,
|
||||
- const char *value)
|
||||
-{
|
||||
- static int (*pctrl_str)(EVP_PKEY_CTX *ctx, const char *type,
|
||||
- const char *value);
|
||||
-
|
||||
- if (pctrl_str == NULL)
|
||||
- EVP_PKEY_meth_get_ctrl(dasync_rsa_orig, NULL, &pctrl_str);
|
||||
- return pctrl_str(ctx, type, value);
|
||||
-}
|
||||
diff --git a/fuzz/asn1.c b/fuzz/asn1.c
|
||||
index 0858bee91d..0212e5674d 100644
|
||||
--- a/fuzz/asn1.c
|
||||
+++ b/fuzz/asn1.c
|
||||
@@ -338,7 +338,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len)
|
||||
DO_TEST_NO_PRINT(DSA, d2i_DSAPublicKey, i2d_DSAPublicKey);
|
||||
DO_TEST_NO_PRINT(DSA, d2i_DSAparams, i2d_DSAparams);
|
||||
#endif
|
||||
- DO_TEST_NO_PRINT(RSA, d2i_RSAPublicKey, i2d_RSAPublicKey);
|
||||
+ DO_TEST_PRINT_OFFSET(RSA, d2i_RSAPublicKey, i2d_RSAPublicKey, RSA_print);
|
||||
#ifndef OPENSSL_NO_EC
|
||||
DO_TEST_PRINT_OFFSET(EC_GROUP, d2i_ECPKParameters, i2d_ECPKParameters, ECPKParameters_print);
|
||||
DO_TEST_PRINT_OFFSET(EC_KEY, d2i_ECPrivateKey, i2d_ECPrivateKey, EC_KEY_print);
|
||||
diff --git a/include/openssl/rsa.h b/include/openssl/rsa.h
|
||||
index 49040bf7e6..1df1c08eb3 100644
|
||||
--- a/include/openssl/rsa.h
|
||||
+++ b/include/openssl/rsa.h
|
||||
@@ -33,50 +33,46 @@
|
||||
extern "C" {
|
||||
# endif
|
||||
|
||||
+/* The types RSA and RSA_METHOD are defined in ossl_typ.h */
|
||||
+
|
||||
# ifndef OPENSSL_RSA_MAX_MODULUS_BITS
|
||||
# define OPENSSL_RSA_MAX_MODULUS_BITS 16384
|
||||
# endif
|
||||
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
-/* The types RSA and RSA_METHOD are defined in ossl_typ.h */
|
||||
-
|
||||
-# define OPENSSL_RSA_FIPS_MIN_MODULUS_BITS 1024
|
||||
+# define OPENSSL_RSA_FIPS_MIN_MODULUS_BITS 1024
|
||||
|
||||
-# ifndef OPENSSL_RSA_SMALL_MODULUS_BITS
|
||||
-# define OPENSSL_RSA_SMALL_MODULUS_BITS 3072
|
||||
-# endif
|
||||
+# ifndef OPENSSL_RSA_SMALL_MODULUS_BITS
|
||||
+# define OPENSSL_RSA_SMALL_MODULUS_BITS 3072
|
||||
+# endif
|
||||
+# ifndef OPENSSL_RSA_MAX_PUBEXP_BITS
|
||||
|
||||
/* exponent limit enforced for "large" modulus only */
|
||||
-# ifndef OPENSSL_RSA_MAX_PUBEXP_BITS
|
||||
-# define OPENSSL_RSA_MAX_PUBEXP_BITS 64
|
||||
-# endif
|
||||
+# define OPENSSL_RSA_MAX_PUBEXP_BITS 64
|
||||
+# endif
|
||||
|
||||
-# define RSA_3 0x3L
|
||||
-# define RSA_F4 0x10001L
|
||||
+# define RSA_3 0x3L
|
||||
+# define RSA_F4 0x10001L
|
||||
|
||||
/* based on RFC 8017 appendix A.1.2 */
|
||||
-# define RSA_ASN1_VERSION_DEFAULT 0
|
||||
-# define RSA_ASN1_VERSION_MULTI 1
|
||||
+# define RSA_ASN1_VERSION_DEFAULT 0
|
||||
+# define RSA_ASN1_VERSION_MULTI 1
|
||||
|
||||
-# define RSA_DEFAULT_PRIME_NUM 2
|
||||
-# endif /* OPENSSL_NO_DEPRECATED_3_0 */
|
||||
+# define RSA_DEFAULT_PRIME_NUM 2
|
||||
|
||||
/* Don't check pub/private match */
|
||||
-/* TODO(3.0): deprecate this? It is exposed for sls/t1_lib.c's use */
|
||||
# define RSA_METHOD_FLAG_NO_CHECK 0x0001
|
||||
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
-# define RSA_FLAG_CACHE_PUBLIC 0x0002
|
||||
-# define RSA_FLAG_CACHE_PRIVATE 0x0004
|
||||
-# define RSA_FLAG_BLINDING 0x0008
|
||||
-# define RSA_FLAG_THREAD_SAFE 0x0010
|
||||
+# define RSA_FLAG_CACHE_PUBLIC 0x0002
|
||||
+# define RSA_FLAG_CACHE_PRIVATE 0x0004
|
||||
+# define RSA_FLAG_BLINDING 0x0008
|
||||
+# define RSA_FLAG_THREAD_SAFE 0x0010
|
||||
/*
|
||||
* This flag means the private key operations will be handled by rsa_mod_exp
|
||||
* and that they do not depend on the private key components being present:
|
||||
* for example a key stored in external hardware. Without this flag
|
||||
* bn_mod_exp gets called when private key components are absent.
|
||||
*/
|
||||
-# define RSA_FLAG_EXT_PKEY 0x0020
|
||||
+# define RSA_FLAG_EXT_PKEY 0x0020
|
||||
|
||||
/*
|
||||
* new with 0.9.6j and 0.9.7b; the built-in
|
||||
@@ -84,14 +80,14 @@ extern "C" {
|
||||
* default (ignoring RSA_FLAG_BLINDING),
|
||||
* but other engines might not need it
|
||||
*/
|
||||
-# define RSA_FLAG_NO_BLINDING 0x0080
|
||||
-# endif /* OPENSSL_NO_DEPRECATED_3_0 */
|
||||
+# define RSA_FLAG_NO_BLINDING 0x0080
|
||||
+# ifndef OPENSSL_NO_DEPRECATED_1_1_0
|
||||
/*
|
||||
* Does nothing. Previously this switched off constant time behaviour.
|
||||
*/
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_1_1_0
|
||||
# define RSA_FLAG_NO_CONSTTIME 0x0000
|
||||
# endif
|
||||
+# ifndef OPENSSL_NO_DEPRECATED_0_9_8
|
||||
/* deprecated name for the flag*/
|
||||
/*
|
||||
* new with 0.9.7h; the built-in RSA
|
||||
@@ -101,7 +97,6 @@ extern "C" {
|
||||
* faster variable sliding window method to
|
||||
* be used for all exponents.
|
||||
*/
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_0_9_8
|
||||
# define RSA_FLAG_NO_EXP_CONSTTIME RSA_FLAG_NO_CONSTTIME
|
||||
# endif
|
||||
|
||||
@@ -135,6 +130,7 @@ int EVP_PKEY_CTX_get_rsa_mgf1_md(EVP_PKEY_CTX *ctx, const EVP_MD **md);
|
||||
int EVP_PKEY_CTX_get_rsa_mgf1_md_name(EVP_PKEY_CTX *ctx, char *name,
|
||||
size_t namelen);
|
||||
|
||||
+
|
||||
# define EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md(ctx, md) \
|
||||
EVP_PKEY_CTX_ctrl(ctx, EVP_PKEY_RSA_PSS, EVP_PKEY_OP_KEYGEN, \
|
||||
EVP_PKEY_CTRL_RSA_MGF1_MD, 0, (void *)(md))
|
||||
@@ -145,7 +141,8 @@ int EVP_PKEY_CTX_set_rsa_oaep_md_name(EVP_PKEY_CTX *ctx, const char *mdname,
|
||||
int EVP_PKEY_CTX_get_rsa_oaep_md(EVP_PKEY_CTX *ctx, const EVP_MD **md);
|
||||
int EVP_PKEY_CTX_get_rsa_oaep_md_name(EVP_PKEY_CTX *ctx, char *name,
|
||||
size_t namelen);
|
||||
-int EVP_PKEY_CTX_set0_rsa_oaep_label(EVP_PKEY_CTX *ctx, void *label, int llen);
|
||||
+int EVP_PKEY_CTX_set0_rsa_oaep_label(EVP_PKEY_CTX *ctx, void *label,
|
||||
+ int llen);
|
||||
int EVP_PKEY_CTX_get0_rsa_oaep_label(EVP_PKEY_CTX *ctx, unsigned char **label);
|
||||
|
||||
# define EVP_PKEY_CTX_set_rsa_pss_keygen_md(ctx, md) \
|
||||
@@ -189,10 +186,10 @@ int EVP_PKEY_CTX_get0_rsa_oaep_label(EVP_PKEY_CTX *ctx, unsigned char **label);
|
||||
# define RSA_get_app_data(s) RSA_get_ex_data(s,0)
|
||||
|
||||
RSA *RSA_new(void);
|
||||
-DEPRECATEDIN_3_0(RSA *RSA_new_method(ENGINE *engine))
|
||||
-DEPRECATEDIN_3_0(int RSA_bits(const RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_size(const RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_security_bits(const RSA *rsa))
|
||||
+RSA *RSA_new_method(ENGINE *engine);
|
||||
+int RSA_bits(const RSA *rsa);
|
||||
+int RSA_size(const RSA *rsa);
|
||||
+int RSA_security_bits(const RSA *rsa);
|
||||
|
||||
int RSA_set0_key(RSA *r, BIGNUM *n, BIGNUM *e, BIGNUM *d);
|
||||
int RSA_set0_factors(RSA *r, BIGNUM *p, BIGNUM *q);
|
||||
@@ -217,12 +214,12 @@ const BIGNUM *RSA_get0_q(const RSA *d);
|
||||
const BIGNUM *RSA_get0_dmp1(const RSA *r);
|
||||
const BIGNUM *RSA_get0_dmq1(const RSA *r);
|
||||
const BIGNUM *RSA_get0_iqmp(const RSA *r);
|
||||
-DEPRECATEDIN_3_0(const RSA_PSS_PARAMS *RSA_get0_pss_params(const RSA *r))
|
||||
+const RSA_PSS_PARAMS *RSA_get0_pss_params(const RSA *r);
|
||||
void RSA_clear_flags(RSA *r, int flags);
|
||||
int RSA_test_flags(const RSA *r, int flags);
|
||||
void RSA_set_flags(RSA *r, int flags);
|
||||
-DEPRECATEDIN_3_0(int RSA_get_version(RSA *r))
|
||||
-DEPRECATEDIN_3_0(ENGINE *RSA_get0_engine(const RSA *r))
|
||||
+int RSA_get_version(RSA *r);
|
||||
+ENGINE *RSA_get0_engine(const RSA *r);
|
||||
|
||||
/* Deprecated version */
|
||||
DEPRECATEDIN_0_9_8(RSA *RSA_generate_key(int bits, unsigned long e, void
|
||||
@@ -230,52 +227,43 @@ DEPRECATEDIN_0_9_8(RSA *RSA_generate_key(int bits, unsigned long e, void
|
||||
void *cb_arg))
|
||||
|
||||
/* New version */
|
||||
-DEPRECATEDIN_3_0(int RSA_generate_key_ex(RSA *rsa, int bits, BIGNUM *e,
|
||||
- BN_GENCB *cb))
|
||||
+int RSA_generate_key_ex(RSA *rsa, int bits, BIGNUM *e, BN_GENCB *cb);
|
||||
/* Multi-prime version */
|
||||
-DEPRECATEDIN_3_0(int RSA_generate_multi_prime_key(RSA *rsa, int bits,
|
||||
- int primes, BIGNUM *e,
|
||||
- BN_GENCB *cb))
|
||||
-
|
||||
-DEPRECATEDIN_3_0(int RSA_X931_derive_ex(RSA *rsa, BIGNUM *p1, BIGNUM *p2,
|
||||
- BIGNUM *q1, BIGNUM *q2,
|
||||
- const BIGNUM *Xp1, const BIGNUM *Xp2,
|
||||
- const BIGNUM *Xp, const BIGNUM *Xq1,
|
||||
- const BIGNUM *Xq2, const BIGNUM *Xq,
|
||||
- const BIGNUM *e, BN_GENCB *cb))
|
||||
-DEPRECATEDIN_3_0(int RSA_X931_generate_key_ex(RSA *rsa, int bits,
|
||||
- const BIGNUM *e, BN_GENCB *cb))
|
||||
-
|
||||
-DEPRECATEDIN_3_0(int RSA_check_key(const RSA *))
|
||||
-DEPRECATEDIN_3_0(int RSA_check_key_ex(const RSA *, BN_GENCB *cb))
|
||||
+int RSA_generate_multi_prime_key(RSA *rsa, int bits, int primes,
|
||||
+ BIGNUM *e, BN_GENCB *cb);
|
||||
+
|
||||
+int RSA_X931_derive_ex(RSA *rsa, BIGNUM *p1, BIGNUM *p2, BIGNUM *q1,
|
||||
+ BIGNUM *q2, const BIGNUM *Xp1, const BIGNUM *Xp2,
|
||||
+ const BIGNUM *Xp, const BIGNUM *Xq1, const BIGNUM *Xq2,
|
||||
+ const BIGNUM *Xq, const BIGNUM *e, BN_GENCB *cb);
|
||||
+int RSA_X931_generate_key_ex(RSA *rsa, int bits, const BIGNUM *e,
|
||||
+ BN_GENCB *cb);
|
||||
+
|
||||
+int RSA_check_key(const RSA *);
|
||||
+int RSA_check_key_ex(const RSA *, BN_GENCB *cb);
|
||||
/* next 4 return -1 on error */
|
||||
-DEPRECATEDIN_3_0(int RSA_public_encrypt(int flen, const unsigned char *from,
|
||||
- unsigned char *to, RSA *rsa,
|
||||
- int padding))
|
||||
-DEPRECATEDIN_3_0(int RSA_private_encrypt(int flen, const unsigned char *from,
|
||||
- unsigned char *to, RSA *rsa,
|
||||
- int padding))
|
||||
-DEPRECATEDIN_3_0(int RSA_public_decrypt(int flen, const unsigned char *from,
|
||||
- unsigned char *to, RSA *rsa,
|
||||
- int padding))
|
||||
-DEPRECATEDIN_3_0(int RSA_private_decrypt(int flen, const unsigned char *from,
|
||||
- unsigned char *to, RSA *rsa,
|
||||
- int padding))
|
||||
+int RSA_public_encrypt(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+int RSA_private_encrypt(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+int RSA_public_decrypt(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+int RSA_private_decrypt(int flen, const unsigned char *from,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
void RSA_free(RSA *r);
|
||||
/* "up" the RSA object's reference count */
|
||||
int RSA_up_ref(RSA *r);
|
||||
|
||||
-/* TODO(3.0): deprecate this one ssl/ssl_rsa.c can be changed to avoid it */
|
||||
int RSA_flags(const RSA *r);
|
||||
|
||||
-DEPRECATEDIN_3_0(void RSA_set_default_method(const RSA_METHOD *meth))
|
||||
-DEPRECATEDIN_3_0(const RSA_METHOD *RSA_get_default_method(void))
|
||||
-DEPRECATEDIN_3_0(const RSA_METHOD *RSA_null_method(void))
|
||||
-DEPRECATEDIN_3_0(const RSA_METHOD *RSA_get_method(const RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_set_method(RSA *rsa, const RSA_METHOD *meth))
|
||||
+void RSA_set_default_method(const RSA_METHOD *meth);
|
||||
+const RSA_METHOD *RSA_get_default_method(void);
|
||||
+const RSA_METHOD *RSA_null_method(void);
|
||||
+const RSA_METHOD *RSA_get_method(const RSA *rsa);
|
||||
+int RSA_set_method(RSA *rsa, const RSA_METHOD *meth);
|
||||
|
||||
/* these are the actual RSA functions */
|
||||
-DEPRECATEDIN_3_0(const RSA_METHOD *RSA_PKCS1_OpenSSL(void))
|
||||
+const RSA_METHOD *RSA_PKCS1_OpenSSL(void);
|
||||
|
||||
int RSA_pkey_ctx_ctrl(EVP_PKEY_CTX *ctx, int optype, int cmd, int p1, void *p2);
|
||||
|
||||
@@ -304,129 +292,101 @@ typedef struct rsa_oaep_params_st {
|
||||
DECLARE_ASN1_FUNCTIONS(RSA_OAEP_PARAMS)
|
||||
|
||||
# ifndef OPENSSL_NO_STDIO
|
||||
-DEPRECATEDIN_3_0(int RSA_print_fp(FILE *fp, const RSA *r, int offset))
|
||||
+int RSA_print_fp(FILE *fp, const RSA *r, int offset);
|
||||
# endif
|
||||
|
||||
-DEPRECATEDIN_3_0(int RSA_print(BIO *bp, const RSA *r, int offset))
|
||||
+int RSA_print(BIO *bp, const RSA *r, int offset);
|
||||
|
||||
/*
|
||||
* The following 2 functions sign and verify a X509_SIG ASN1 object inside
|
||||
* PKCS#1 padded RSA encryption
|
||||
*/
|
||||
-DEPRECATEDIN_3_0(int RSA_sign(int type, const unsigned char *m,
|
||||
- unsigned int m_length, unsigned char *sigret,
|
||||
- unsigned int *siglen, RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_verify(int type, const unsigned char *m,
|
||||
- unsigned int m_length,
|
||||
- const unsigned char *sigbuf,
|
||||
- unsigned int siglen, RSA *rsa))
|
||||
+int RSA_sign(int type, const unsigned char *m, unsigned int m_length,
|
||||
+ unsigned char *sigret, unsigned int *siglen, RSA *rsa);
|
||||
+int RSA_verify(int type, const unsigned char *m, unsigned int m_length,
|
||||
+ const unsigned char *sigbuf, unsigned int siglen, RSA *rsa);
|
||||
|
||||
/*
|
||||
* The following 2 function sign and verify a ASN1_OCTET_STRING object inside
|
||||
* PKCS#1 padded RSA encryption
|
||||
*/
|
||||
-DEPRECATEDIN_3_0(int RSA_sign_ASN1_OCTET_STRING(int type,
|
||||
- const unsigned char *m,
|
||||
- unsigned int m_length,
|
||||
- unsigned char *sigret,
|
||||
- unsigned int *siglen, RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_verify_ASN1_OCTET_STRING(int type,
|
||||
- const unsigned char *m,
|
||||
- unsigned int m_length,
|
||||
- unsigned char *sigbuf,
|
||||
- unsigned int siglen,
|
||||
- RSA *rsa))
|
||||
-
|
||||
-/* TODO(3.0): figure out how to deprecate these two */
|
||||
+int RSA_sign_ASN1_OCTET_STRING(int type,
|
||||
+ const unsigned char *m, unsigned int m_length,
|
||||
+ unsigned char *sigret, unsigned int *siglen,
|
||||
+ RSA *rsa);
|
||||
+int RSA_verify_ASN1_OCTET_STRING(int type, const unsigned char *m,
|
||||
+ unsigned int m_length, unsigned char *sigbuf,
|
||||
+ unsigned int siglen, RSA *rsa);
|
||||
+
|
||||
int RSA_blinding_on(RSA *rsa, BN_CTX *ctx);
|
||||
void RSA_blinding_off(RSA *rsa);
|
||||
-DEPRECATEDIN_3_0(BN_BLINDING *RSA_setup_blinding(RSA *rsa, BN_CTX *ctx))
|
||||
-
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_PKCS1_type_1(unsigned char *to, int tlen,
|
||||
- const unsigned char *f,
|
||||
- int fl))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_check_PKCS1_type_1(unsigned char *to, int tlen,
|
||||
- const unsigned char *f,
|
||||
- int fl, int rsa_len))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_PKCS1_type_2(unsigned char *to, int tlen,
|
||||
- const unsigned char *f,
|
||||
- int fl))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_check_PKCS1_type_2(unsigned char *to, int tlen,
|
||||
- const unsigned char *f,
|
||||
- int fl, int rsa_len))
|
||||
-DEPRECATEDIN_3_0(int PKCS1_MGF1(unsigned char *mask, long len,
|
||||
- const unsigned char *seed, long seedlen,
|
||||
- const EVP_MD *dgst))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_PKCS1_OAEP(unsigned char *to, int tlen,
|
||||
- const unsigned char *f, int fl,
|
||||
- const unsigned char *p, int pl))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_check_PKCS1_OAEP(unsigned char *to, int tlen,
|
||||
- const unsigned char *f,
|
||||
- int fl, int rsa_len,
|
||||
- const unsigned char *p,
|
||||
- int pl))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_PKCS1_OAEP_mgf1(unsigned char *to,
|
||||
- int tlen,
|
||||
- const unsigned char *from,
|
||||
- int flen,
|
||||
- const unsigned char *param,
|
||||
- int plen,
|
||||
- const EVP_MD *md,
|
||||
- const EVP_MD *mgf1md))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_check_PKCS1_OAEP_mgf1(unsigned char *to,
|
||||
- int tlen,
|
||||
- const unsigned char *from,
|
||||
- int flen, int num,
|
||||
- const unsigned char *param,
|
||||
- int plen, const EVP_MD *md,
|
||||
- const EVP_MD *mgf1md))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_SSLv23(unsigned char *to, int tlen,
|
||||
- const unsigned char *f, int fl))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_check_SSLv23(unsigned char *to, int tlen,
|
||||
- const unsigned char *f, int fl,
|
||||
- int rsa_len))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_none(unsigned char *to, int tlen,
|
||||
- const unsigned char *f, int fl))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_check_none(unsigned char *to, int tlen,
|
||||
- const unsigned char *f, int fl,
|
||||
- int rsa_len))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_X931(unsigned char *to, int tlen,
|
||||
- const unsigned char *f, int fl))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_check_X931(unsigned char *to, int tlen,
|
||||
- const unsigned char *f, int fl,
|
||||
- int rsa_len))
|
||||
-DEPRECATEDIN_3_0(int RSA_X931_hash_id(int nid))
|
||||
-
|
||||
-DEPRECATEDIN_3_0(int RSA_verify_PKCS1_PSS(RSA *rsa, const unsigned char *mHash,
|
||||
- const EVP_MD *Hash,
|
||||
- const unsigned char *EM, int sLen))
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_PKCS1_PSS(RSA *rsa, unsigned char *EM,
|
||||
- const unsigned char *mHash,
|
||||
- const EVP_MD *Hash, int sLen))
|
||||
-
|
||||
-DEPRECATEDIN_3_0(int RSA_verify_PKCS1_PSS_mgf1(RSA *rsa,
|
||||
- const unsigned char *mHash,
|
||||
- const EVP_MD *Hash,
|
||||
- const EVP_MD *mgf1Hash,
|
||||
- const unsigned char *EM,
|
||||
- int sLen))
|
||||
-
|
||||
-DEPRECATEDIN_3_0(int RSA_padding_add_PKCS1_PSS_mgf1(RSA *rsa,
|
||||
- unsigned char *EM,
|
||||
- const unsigned char *mHash,
|
||||
- const EVP_MD *Hash,
|
||||
- const EVP_MD *mgf1Hash,
|
||||
- int sLen))
|
||||
+BN_BLINDING *RSA_setup_blinding(RSA *rsa, BN_CTX *ctx);
|
||||
+
|
||||
+int RSA_padding_add_PKCS1_type_1(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl);
|
||||
+int RSA_padding_check_PKCS1_type_1(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl,
|
||||
+ int rsa_len);
|
||||
+int RSA_padding_add_PKCS1_type_2(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl);
|
||||
+int RSA_padding_check_PKCS1_type_2(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl,
|
||||
+ int rsa_len);
|
||||
+int PKCS1_MGF1(unsigned char *mask, long len, const unsigned char *seed,
|
||||
+ long seedlen, const EVP_MD *dgst);
|
||||
+int RSA_padding_add_PKCS1_OAEP(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl,
|
||||
+ const unsigned char *p, int pl);
|
||||
+int RSA_padding_check_PKCS1_OAEP(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl, int rsa_len,
|
||||
+ const unsigned char *p, int pl);
|
||||
+int RSA_padding_add_PKCS1_OAEP_mgf1(unsigned char *to, int tlen,
|
||||
+ const unsigned char *from, int flen,
|
||||
+ const unsigned char *param, int plen,
|
||||
+ const EVP_MD *md, const EVP_MD *mgf1md);
|
||||
+int RSA_padding_check_PKCS1_OAEP_mgf1(unsigned char *to, int tlen,
|
||||
+ const unsigned char *from, int flen,
|
||||
+ int num, const unsigned char *param,
|
||||
+ int plen, const EVP_MD *md,
|
||||
+ const EVP_MD *mgf1md);
|
||||
+int RSA_padding_add_SSLv23(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl);
|
||||
+int RSA_padding_check_SSLv23(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl, int rsa_len);
|
||||
+int RSA_padding_add_none(unsigned char *to, int tlen, const unsigned char *f,
|
||||
+ int fl);
|
||||
+int RSA_padding_check_none(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl, int rsa_len);
|
||||
+int RSA_padding_add_X931(unsigned char *to, int tlen, const unsigned char *f,
|
||||
+ int fl);
|
||||
+int RSA_padding_check_X931(unsigned char *to, int tlen,
|
||||
+ const unsigned char *f, int fl, int rsa_len);
|
||||
+int RSA_X931_hash_id(int nid);
|
||||
+
|
||||
+int RSA_verify_PKCS1_PSS(RSA *rsa, const unsigned char *mHash,
|
||||
+ const EVP_MD *Hash, const unsigned char *EM,
|
||||
+ int sLen);
|
||||
+int RSA_padding_add_PKCS1_PSS(RSA *rsa, unsigned char *EM,
|
||||
+ const unsigned char *mHash, const EVP_MD *Hash,
|
||||
+ int sLen);
|
||||
+
|
||||
+int RSA_verify_PKCS1_PSS_mgf1(RSA *rsa, const unsigned char *mHash,
|
||||
+ const EVP_MD *Hash, const EVP_MD *mgf1Hash,
|
||||
+ const unsigned char *EM, int sLen);
|
||||
+
|
||||
+int RSA_padding_add_PKCS1_PSS_mgf1(RSA *rsa, unsigned char *EM,
|
||||
+ const unsigned char *mHash,
|
||||
+ const EVP_MD *Hash, const EVP_MD *mgf1Hash,
|
||||
+ int sLen);
|
||||
|
||||
# define RSA_get_ex_new_index(l, p, newf, dupf, freef) \
|
||||
CRYPTO_get_ex_new_index(CRYPTO_EX_INDEX_RSA, l, p, newf, dupf, freef)
|
||||
-DEPRECATEDIN_3_0(int RSA_set_ex_data(RSA *r, int idx, void *arg))
|
||||
-DEPRECATEDIN_3_0(void *RSA_get_ex_data(const RSA *r, int idx))
|
||||
+int RSA_set_ex_data(RSA *r, int idx, void *arg);
|
||||
+void *RSA_get_ex_data(const RSA *r, int idx);
|
||||
|
||||
DECLARE_ASN1_DUP_FUNCTION_name(RSA, RSAPublicKey)
|
||||
DECLARE_ASN1_DUP_FUNCTION_name(RSA, RSAPrivateKey)
|
||||
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
/*
|
||||
* If this flag is set the RSA method is FIPS compliant and can be used in
|
||||
* FIPS mode. This is set in the validated module method. If an application
|
||||
@@ -434,7 +394,7 @@ DECLARE_ASN1_DUP_FUNCTION_name(RSA, RSAPrivateKey)
|
||||
* result is compliant.
|
||||
*/
|
||||
|
||||
-# define RSA_FLAG_FIPS_METHOD 0x0400
|
||||
+# define RSA_FLAG_FIPS_METHOD 0x0400
|
||||
|
||||
/*
|
||||
* If this flag is set the operations normally disabled in FIPS mode are
|
||||
@@ -442,101 +402,99 @@ DECLARE_ASN1_DUP_FUNCTION_name(RSA, RSAPrivateKey)
|
||||
* usage is compliant.
|
||||
*/
|
||||
|
||||
-# define RSA_FLAG_NON_FIPS_ALLOW 0x0400
|
||||
+# define RSA_FLAG_NON_FIPS_ALLOW 0x0400
|
||||
/*
|
||||
* Application has decided PRNG is good enough to generate a key: don't
|
||||
* check.
|
||||
*/
|
||||
-# define RSA_FLAG_CHECKED 0x0800
|
||||
-# endif /* OPENSSL_NO_DEPRECATED_3_0 */
|
||||
-
|
||||
-DEPRECATEDIN_3_0(RSA_METHOD *RSA_meth_new(const char *name, int flags))
|
||||
-DEPRECATEDIN_3_0(void RSA_meth_free(RSA_METHOD *meth))
|
||||
-DEPRECATEDIN_3_0(RSA_METHOD *RSA_meth_dup(const RSA_METHOD *meth))
|
||||
-DEPRECATEDIN_3_0(const char *RSA_meth_get0_name(const RSA_METHOD *meth))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set1_name(RSA_METHOD *meth, const char *name))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_get_flags(const RSA_METHOD *meth))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_flags(RSA_METHOD *meth, int flags))
|
||||
-DEPRECATEDIN_3_0(void *RSA_meth_get0_app_data(const RSA_METHOD *meth))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set0_app_data(RSA_METHOD *meth, void *app_data))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_pub_enc(const RSA_METHOD *meth))
|
||||
+# define RSA_FLAG_CHECKED 0x0800
|
||||
+
|
||||
+RSA_METHOD *RSA_meth_new(const char *name, int flags);
|
||||
+void RSA_meth_free(RSA_METHOD *meth);
|
||||
+RSA_METHOD *RSA_meth_dup(const RSA_METHOD *meth);
|
||||
+const char *RSA_meth_get0_name(const RSA_METHOD *meth);
|
||||
+int RSA_meth_set1_name(RSA_METHOD *meth, const char *name);
|
||||
+int RSA_meth_get_flags(const RSA_METHOD *meth);
|
||||
+int RSA_meth_set_flags(RSA_METHOD *meth, int flags);
|
||||
+void *RSA_meth_get0_app_data(const RSA_METHOD *meth);
|
||||
+int RSA_meth_set0_app_data(RSA_METHOD *meth, void *app_data);
|
||||
+int (*RSA_meth_get_pub_enc(const RSA_METHOD *meth))
|
||||
(int flen, const unsigned char *from,
|
||||
- unsigned char *to, RSA *rsa, int padding))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_pub_enc(RSA_METHOD *rsa,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+int RSA_meth_set_pub_enc(RSA_METHOD *rsa,
|
||||
int (*pub_enc) (int flen, const unsigned char *from,
|
||||
unsigned char *to, RSA *rsa,
|
||||
- int padding)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_pub_dec(const RSA_METHOD *meth))
|
||||
+ int padding));
|
||||
+int (*RSA_meth_get_pub_dec(const RSA_METHOD *meth))
|
||||
(int flen, const unsigned char *from,
|
||||
- unsigned char *to, RSA *rsa, int padding))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_pub_dec(RSA_METHOD *rsa,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+int RSA_meth_set_pub_dec(RSA_METHOD *rsa,
|
||||
int (*pub_dec) (int flen, const unsigned char *from,
|
||||
unsigned char *to, RSA *rsa,
|
||||
- int padding)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_priv_enc(const RSA_METHOD *meth))
|
||||
+ int padding));
|
||||
+int (*RSA_meth_get_priv_enc(const RSA_METHOD *meth))
|
||||
(int flen, const unsigned char *from,
|
||||
- unsigned char *to, RSA *rsa, int padding))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_priv_enc(RSA_METHOD *rsa,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+int RSA_meth_set_priv_enc(RSA_METHOD *rsa,
|
||||
int (*priv_enc) (int flen, const unsigned char *from,
|
||||
unsigned char *to, RSA *rsa,
|
||||
- int padding)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_priv_dec(const RSA_METHOD *meth))
|
||||
+ int padding));
|
||||
+int (*RSA_meth_get_priv_dec(const RSA_METHOD *meth))
|
||||
(int flen, const unsigned char *from,
|
||||
- unsigned char *to, RSA *rsa, int padding))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_priv_dec(RSA_METHOD *rsa,
|
||||
+ unsigned char *to, RSA *rsa, int padding);
|
||||
+int RSA_meth_set_priv_dec(RSA_METHOD *rsa,
|
||||
int (*priv_dec) (int flen, const unsigned char *from,
|
||||
unsigned char *to, RSA *rsa,
|
||||
- int padding)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_mod_exp(const RSA_METHOD *meth))
|
||||
- (BIGNUM *r0, const BIGNUM *i, RSA *rsa, BN_CTX *ctx))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_mod_exp(RSA_METHOD *rsa,
|
||||
+ int padding));
|
||||
+int (*RSA_meth_get_mod_exp(const RSA_METHOD *meth))
|
||||
+ (BIGNUM *r0, const BIGNUM *i, RSA *rsa, BN_CTX *ctx);
|
||||
+int RSA_meth_set_mod_exp(RSA_METHOD *rsa,
|
||||
int (*mod_exp) (BIGNUM *r0, const BIGNUM *i, RSA *rsa,
|
||||
- BN_CTX *ctx)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_bn_mod_exp(const RSA_METHOD *meth))
|
||||
+ BN_CTX *ctx));
|
||||
+int (*RSA_meth_get_bn_mod_exp(const RSA_METHOD *meth))
|
||||
(BIGNUM *r, const BIGNUM *a, const BIGNUM *p,
|
||||
- const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *m_ctx))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_bn_mod_exp(RSA_METHOD *rsa,
|
||||
+ const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *m_ctx);
|
||||
+int RSA_meth_set_bn_mod_exp(RSA_METHOD *rsa,
|
||||
int (*bn_mod_exp) (BIGNUM *r,
|
||||
const BIGNUM *a,
|
||||
const BIGNUM *p,
|
||||
const BIGNUM *m,
|
||||
BN_CTX *ctx,
|
||||
- BN_MONT_CTX *m_ctx)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_init(const RSA_METHOD *meth)) (RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_init(RSA_METHOD *rsa, int (*init) (RSA *rsa)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_finish(const RSA_METHOD *meth)) (RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_finish(RSA_METHOD *rsa,
|
||||
- int (*finish) (RSA *rsa)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_sign(const RSA_METHOD *meth))
|
||||
+ BN_MONT_CTX *m_ctx));
|
||||
+int (*RSA_meth_get_init(const RSA_METHOD *meth)) (RSA *rsa);
|
||||
+int RSA_meth_set_init(RSA_METHOD *rsa, int (*init) (RSA *rsa));
|
||||
+int (*RSA_meth_get_finish(const RSA_METHOD *meth)) (RSA *rsa);
|
||||
+int RSA_meth_set_finish(RSA_METHOD *rsa, int (*finish) (RSA *rsa));
|
||||
+int (*RSA_meth_get_sign(const RSA_METHOD *meth))
|
||||
(int type,
|
||||
const unsigned char *m, unsigned int m_length,
|
||||
unsigned char *sigret, unsigned int *siglen,
|
||||
- const RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_sign(RSA_METHOD *rsa,
|
||||
+ const RSA *rsa);
|
||||
+int RSA_meth_set_sign(RSA_METHOD *rsa,
|
||||
int (*sign) (int type, const unsigned char *m,
|
||||
unsigned int m_length,
|
||||
unsigned char *sigret, unsigned int *siglen,
|
||||
- const RSA *rsa)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_verify(const RSA_METHOD *meth))
|
||||
+ const RSA *rsa));
|
||||
+int (*RSA_meth_get_verify(const RSA_METHOD *meth))
|
||||
(int dtype, const unsigned char *m,
|
||||
unsigned int m_length, const unsigned char *sigbuf,
|
||||
- unsigned int siglen, const RSA *rsa))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_verify(RSA_METHOD *rsa,
|
||||
+ unsigned int siglen, const RSA *rsa);
|
||||
+int RSA_meth_set_verify(RSA_METHOD *rsa,
|
||||
int (*verify) (int dtype, const unsigned char *m,
|
||||
unsigned int m_length,
|
||||
const unsigned char *sigbuf,
|
||||
- unsigned int siglen, const RSA *rsa)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_keygen(const RSA_METHOD *meth))
|
||||
- (RSA *rsa, int bits, BIGNUM *e, BN_GENCB *cb))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_keygen(RSA_METHOD *rsa,
|
||||
+ unsigned int siglen, const RSA *rsa));
|
||||
+int (*RSA_meth_get_keygen(const RSA_METHOD *meth))
|
||||
+ (RSA *rsa, int bits, BIGNUM *e, BN_GENCB *cb);
|
||||
+int RSA_meth_set_keygen(RSA_METHOD *rsa,
|
||||
int (*keygen) (RSA *rsa, int bits, BIGNUM *e,
|
||||
- BN_GENCB *cb)))
|
||||
-DEPRECATEDIN_3_0(int (*RSA_meth_get_multi_prime_keygen(const RSA_METHOD *meth))
|
||||
- (RSA *rsa, int bits, int primes, BIGNUM *e, BN_GENCB *cb))
|
||||
-DEPRECATEDIN_3_0(int RSA_meth_set_multi_prime_keygen(RSA_METHOD *meth,
|
||||
+ BN_GENCB *cb));
|
||||
+int (*RSA_meth_get_multi_prime_keygen(const RSA_METHOD *meth))
|
||||
+ (RSA *rsa, int bits, int primes, BIGNUM *e, BN_GENCB *cb);
|
||||
+int RSA_meth_set_multi_prime_keygen(RSA_METHOD *meth,
|
||||
int (*keygen) (RSA *rsa, int bits,
|
||||
int primes, BIGNUM *e,
|
||||
- BN_GENCB *cb)))
|
||||
+ BN_GENCB *cb));
|
||||
|
||||
# ifdef __cplusplus
|
||||
}
|
||||
diff --git a/providers/implementations/asymciphers/rsa_enc.c b/providers/implementations/asymciphers/rsa_enc.c
|
||||
index 5f05d1810b..dad9edf962 100644
|
||||
--- a/providers/implementations/asymciphers/rsa_enc.c
|
||||
+++ b/providers/implementations/asymciphers/rsa_enc.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <openssl/crypto.h>
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/core_numbers.h>
|
||||
diff --git a/providers/implementations/keymgmt/rsa_kmgmt.c b/providers/implementations/keymgmt/rsa_kmgmt.c
|
||||
index 8ea394115b..f117d99001 100644
|
||||
--- a/providers/implementations/keymgmt/rsa_kmgmt.c
|
||||
+++ b/providers/implementations/keymgmt/rsa_kmgmt.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <openssl/core_numbers.h>
|
||||
#include <openssl/core_names.h>
|
||||
#include <openssl/bn.h>
|
||||
diff --git a/providers/implementations/serializers/serializer_rsa.c b/providers/implementations/serializers/serializer_rsa.c
|
||||
index 21898f9e3d..594c3d758f 100644
|
||||
--- a/providers/implementations/serializers/serializer_rsa.c
|
||||
+++ b/providers/implementations/serializers/serializer_rsa.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include "crypto/rsa.h" /* rsa_get0_all_params() */
|
||||
#include "prov/bio.h" /* ossl_prov_bio_printf() */
|
||||
#include "prov/implementations.h" /* rsa_keymgmt_functions */
|
||||
diff --git a/providers/implementations/serializers/serializer_rsa_priv.c b/providers/implementations/serializers/serializer_rsa_priv.c
|
||||
index 23042041de..af0aadcda1 100644
|
||||
--- a/providers/implementations/serializers/serializer_rsa_priv.c
|
||||
+++ b/providers/implementations/serializers/serializer_rsa_priv.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <openssl/core_numbers.h>
|
||||
#include <openssl/core_names.h>
|
||||
#include <openssl/err.h>
|
||||
diff --git a/providers/implementations/serializers/serializer_rsa_pub.c b/providers/implementations/serializers/serializer_rsa_pub.c
|
||||
index 3ee0501ee1..f7eccf7624 100644
|
||||
--- a/providers/implementations/serializers/serializer_rsa_pub.c
|
||||
+++ b/providers/implementations/serializers/serializer_rsa_pub.c
|
||||
@@ -7,12 +7,6 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <openssl/core_numbers.h>
|
||||
#include <openssl/pem.h>
|
||||
#include <openssl/rsa.h>
|
||||
diff --git a/ssl/s3_enc.c b/ssl/s3_enc.c
|
||||
index 76bea32dbd..ea0fb750f1 100644
|
||||
--- a/ssl/s3_enc.c
|
||||
+++ b/ssl/s3_enc.c
|
||||
@@ -86,7 +86,7 @@ static int ssl3_generate_key_block(SSL *s, unsigned char *km, int num)
|
||||
err:
|
||||
EVP_MD_CTX_free(m5);
|
||||
EVP_MD_CTX_free(s1);
|
||||
- ssl_evp_md_free(md5);
|
||||
+ EVP_MD_free(md5);
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -257,16 +257,13 @@ int ssl3_setup_key_block(SSL *s)
|
||||
if (s->s3.tmp.key_block_length != 0)
|
||||
return 1;
|
||||
|
||||
- if (!ssl_cipher_get_evp(s->ctx, s->session, &c, &hash, NULL, NULL, &comp,
|
||||
- 0)) {
|
||||
+ if (!ssl_cipher_get_evp(s->session, &c, &hash, NULL, NULL, &comp, 0)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_SSL3_SETUP_KEY_BLOCK,
|
||||
SSL_R_CIPHER_OR_HASH_UNAVAILABLE);
|
||||
return 0;
|
||||
}
|
||||
|
||||
- ssl_evp_cipher_free(s->s3.tmp.new_sym_enc);
|
||||
s->s3.tmp.new_sym_enc = c;
|
||||
- ssl_evp_md_free(s->s3.tmp.new_hash);
|
||||
s->s3.tmp.new_hash = hash;
|
||||
#ifdef OPENSSL_NO_COMP
|
||||
s->s3.tmp.new_compression = NULL;
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 9902fa3811..26f19108ee 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -3334,9 +3334,6 @@ void ssl3_free(SSL *s)
|
||||
s->s3.tmp.pkey = NULL;
|
||||
#endif
|
||||
|
||||
- ssl_evp_cipher_free(s->s3.tmp.new_sym_enc);
|
||||
- ssl_evp_md_free(s->s3.tmp.new_hash);
|
||||
-
|
||||
OPENSSL_free(s->s3.tmp.ctype);
|
||||
sk_X509_NAME_pop_free(s->s3.tmp.peer_ca_names, X509_NAME_free);
|
||||
OPENSSL_free(s->s3.tmp.ciphers_raw);
|
||||
@@ -4160,6 +4157,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
STACK_OF(SSL_CIPHER) *prio, *allow;
|
||||
int i, ii, ok, prefer_sha256 = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
+ const EVP_MD *mdsha256 = EVP_sha256();
|
||||
#ifndef OPENSSL_NO_CHACHA
|
||||
STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
#endif
|
||||
@@ -4333,12 +4331,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
- /*
|
||||
- * TODO: When there are no more legacy digests we can just use
|
||||
- * OSSL_DIGEST_NAME_SHA2_256 instead of calling OBJ_nid2sn
|
||||
- */
|
||||
- if (EVP_MD_is_a(ssl_md(s->ctx, tmp->algorithm2),
|
||||
- OBJ_nid2sn(NID_sha256))) {
|
||||
+ if (ssl_md(tmp->algorithm2) == mdsha256) {
|
||||
ret = tmp;
|
||||
break;
|
||||
}
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 066c38a7cc..04ffae325c 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -22,6 +22,30 @@
|
||||
#include "internal/thread_once.h"
|
||||
#include "internal/cryptlib.h"
|
||||
|
||||
+#define SSL_ENC_DES_IDX 0
|
||||
+#define SSL_ENC_3DES_IDX 1
|
||||
+#define SSL_ENC_RC4_IDX 2
|
||||
+#define SSL_ENC_RC2_IDX 3
|
||||
+#define SSL_ENC_IDEA_IDX 4
|
||||
+#define SSL_ENC_NULL_IDX 5
|
||||
+#define SSL_ENC_AES128_IDX 6
|
||||
+#define SSL_ENC_AES256_IDX 7
|
||||
+#define SSL_ENC_CAMELLIA128_IDX 8
|
||||
+#define SSL_ENC_CAMELLIA256_IDX 9
|
||||
+#define SSL_ENC_GOST89_IDX 10
|
||||
+#define SSL_ENC_SEED_IDX 11
|
||||
+#define SSL_ENC_AES128GCM_IDX 12
|
||||
+#define SSL_ENC_AES256GCM_IDX 13
|
||||
+#define SSL_ENC_AES128CCM_IDX 14
|
||||
+#define SSL_ENC_AES256CCM_IDX 15
|
||||
+#define SSL_ENC_AES128CCM8_IDX 16
|
||||
+#define SSL_ENC_AES256CCM8_IDX 17
|
||||
+#define SSL_ENC_GOST8912_IDX 18
|
||||
+#define SSL_ENC_CHACHA_IDX 19
|
||||
+#define SSL_ENC_ARIA128GCM_IDX 20
|
||||
+#define SSL_ENC_ARIA256GCM_IDX 21
|
||||
+#define SSL_ENC_NUM_IDX 22
|
||||
+
|
||||
/* NB: make sure indices in these tables match values above */
|
||||
|
||||
typedef struct {
|
||||
@@ -55,6 +79,8 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = {
|
||||
{SSL_ARIA256GCM, NID_aria_256_gcm}, /* SSL_ENC_ARIA256GCM_IDX 21 */
|
||||
};
|
||||
|
||||
+static const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
+
|
||||
#define SSL_COMP_NULL_IDX 0
|
||||
#define SSL_COMP_ZLIB_IDX 1
|
||||
#define SSL_COMP_NUM_IDX 2
|
||||
@@ -65,6 +91,13 @@ static STACK_OF(SSL_COMP) *ssl_comp_methods = NULL;
|
||||
static CRYPTO_ONCE ssl_load_builtin_comp_once = CRYPTO_ONCE_STATIC_INIT;
|
||||
#endif
|
||||
|
||||
+/*
|
||||
+ * Constant SSL_MAX_DIGEST equal to size of digests array should be defined
|
||||
+ * in the ssl_local.h
|
||||
+ */
|
||||
+
|
||||
+#define SSL_MD_NUM_IDX SSL_MAX_DIGEST
|
||||
+
|
||||
/* NB: make sure indices in this table matches values above */
|
||||
static const ssl_cipher_table ssl_cipher_table_mac[SSL_MD_NUM_IDX] = {
|
||||
{SSL_MD5, NID_md5}, /* SSL_MD_MD5_IDX 0 */
|
||||
@@ -81,6 +114,10 @@ static const ssl_cipher_table ssl_cipher_table_mac[SSL_MD_NUM_IDX] = {
|
||||
{0, NID_sha512} /* SSL_MD_SHA512_IDX 11 */
|
||||
};
|
||||
|
||||
+static const EVP_MD *ssl_digest_methods[SSL_MD_NUM_IDX] = {
|
||||
+ NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL
|
||||
+};
|
||||
+
|
||||
/* *INDENT-OFF* */
|
||||
static const ssl_cipher_table ssl_cipher_table_kx[] = {
|
||||
{SSL_kRSA, NID_kx_rsa},
|
||||
@@ -139,6 +176,8 @@ static int ssl_mac_pkey_id[SSL_MD_NUM_IDX] = {
|
||||
NID_undef, NID_undef, NID_undef
|
||||
};
|
||||
|
||||
+static size_t ssl_mac_secret_size[SSL_MD_NUM_IDX];
|
||||
+
|
||||
#define CIPHER_ADD 1
|
||||
#define CIPHER_KILL 2
|
||||
#define CIPHER_DEL 3
|
||||
@@ -317,37 +356,41 @@ static uint32_t disabled_mac_mask;
|
||||
static uint32_t disabled_mkey_mask;
|
||||
static uint32_t disabled_auth_mask;
|
||||
|
||||
-int ssl_load_ciphers(SSL_CTX *ctx)
|
||||
+int ssl_load_ciphers(void)
|
||||
{
|
||||
size_t i;
|
||||
const ssl_cipher_table *t;
|
||||
|
||||
disabled_enc_mask = 0;
|
||||
+ ssl_sort_cipher_list();
|
||||
for (i = 0, t = ssl_cipher_table_cipher; i < SSL_ENC_NUM_IDX; i++, t++) {
|
||||
- if (t->nid != NID_undef) {
|
||||
- const EVP_CIPHER *cipher
|
||||
- = ssl_evp_cipher_fetch(ctx->libctx, t->nid, ctx->propq);
|
||||
-
|
||||
- ctx->ssl_cipher_methods[i] = cipher;
|
||||
+ if (t->nid == NID_undef) {
|
||||
+ ssl_cipher_methods[i] = NULL;
|
||||
+ } else {
|
||||
+ const EVP_CIPHER *cipher = EVP_get_cipherbynid(t->nid);
|
||||
+ ssl_cipher_methods[i] = cipher;
|
||||
if (cipher == NULL)
|
||||
disabled_enc_mask |= t->mask;
|
||||
}
|
||||
}
|
||||
disabled_mac_mask = 0;
|
||||
for (i = 0, t = ssl_cipher_table_mac; i < SSL_MD_NUM_IDX; i++, t++) {
|
||||
- const EVP_MD *md
|
||||
- = ssl_evp_md_fetch(ctx->libctx, t->nid, ctx->propq);
|
||||
-
|
||||
- ctx->ssl_digest_methods[i] = md;
|
||||
+ const EVP_MD *md = EVP_get_digestbynid(t->nid);
|
||||
+ ssl_digest_methods[i] = md;
|
||||
if (md == NULL) {
|
||||
disabled_mac_mask |= t->mask;
|
||||
} else {
|
||||
int tmpsize = EVP_MD_size(md);
|
||||
if (!ossl_assert(tmpsize >= 0))
|
||||
return 0;
|
||||
- ctx->ssl_mac_secret_size[i] = tmpsize;
|
||||
+ ssl_mac_secret_size[i] = tmpsize;
|
||||
}
|
||||
}
|
||||
+ /* Make sure we can access MD5 and SHA1 */
|
||||
+ if (!ossl_assert(ssl_digest_methods[SSL_MD_MD5_IDX] != NULL))
|
||||
+ return 0;
|
||||
+ if (!ossl_assert(ssl_digest_methods[SSL_MD_SHA1_IDX] != NULL))
|
||||
+ return 0;
|
||||
|
||||
disabled_mkey_mask = 0;
|
||||
disabled_auth_mask = 0;
|
||||
@@ -380,14 +423,14 @@ int ssl_load_ciphers(SSL_CTX *ctx)
|
||||
*/
|
||||
ssl_mac_pkey_id[SSL_MD_GOST89MAC_IDX] = get_optional_pkey_id("gost-mac");
|
||||
if (ssl_mac_pkey_id[SSL_MD_GOST89MAC_IDX])
|
||||
- ctx->ssl_mac_secret_size[SSL_MD_GOST89MAC_IDX] = 32;
|
||||
+ ssl_mac_secret_size[SSL_MD_GOST89MAC_IDX] = 32;
|
||||
else
|
||||
disabled_mac_mask |= SSL_GOST89MAC;
|
||||
|
||||
ssl_mac_pkey_id[SSL_MD_GOST89MAC12_IDX] =
|
||||
get_optional_pkey_id("gost-mac-12");
|
||||
if (ssl_mac_pkey_id[SSL_MD_GOST89MAC12_IDX])
|
||||
- ctx->ssl_mac_secret_size[SSL_MD_GOST89MAC12_IDX] = 32;
|
||||
+ ssl_mac_secret_size[SSL_MD_GOST89MAC12_IDX] = 32;
|
||||
else
|
||||
disabled_mac_mask |= SSL_GOST89MAC12;
|
||||
|
||||
@@ -440,39 +483,9 @@ static int load_builtin_compressions(void)
|
||||
}
|
||||
#endif
|
||||
|
||||
-int ssl_cipher_get_evp_cipher(SSL_CTX *ctx, const SSL_CIPHER *sslc,
|
||||
- const EVP_CIPHER **enc)
|
||||
-{
|
||||
- int i = ssl_cipher_info_lookup(ssl_cipher_table_cipher, sslc->algorithm_enc);
|
||||
-
|
||||
- if (i == -1) {
|
||||
- *enc = NULL;
|
||||
- } else {
|
||||
- if (i == SSL_ENC_NULL_IDX) {
|
||||
- /*
|
||||
- * We assume we don't care about this coming from an ENGINE so
|
||||
- * just do a normal EVP_CIPHER_fetch instead of
|
||||
- * ssl_evp_cipher_fetch()
|
||||
- */
|
||||
- *enc = EVP_CIPHER_fetch(ctx->libctx, "NULL", ctx->propq);
|
||||
- if (*enc == NULL)
|
||||
- return 0;
|
||||
- } else {
|
||||
- const EVP_CIPHER *cipher = ctx->ssl_cipher_methods[i];
|
||||
-
|
||||
- if (cipher == NULL
|
||||
- || !ssl_evp_cipher_up_ref(cipher))
|
||||
- return 0;
|
||||
- *enc = ctx->ssl_cipher_methods[i];
|
||||
- }
|
||||
- }
|
||||
- return 1;
|
||||
-}
|
||||
-
|
||||
-int ssl_cipher_get_evp(SSL_CTX *ctx, const SSL_SESSION *s,
|
||||
- const EVP_CIPHER **enc, const EVP_MD **md,
|
||||
- int *mac_pkey_type, size_t *mac_secret_size,
|
||||
- SSL_COMP **comp, int use_etm)
|
||||
+int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
+ const EVP_MD **md, int *mac_pkey_type,
|
||||
+ size_t *mac_secret_size, SSL_COMP **comp, int use_etm)
|
||||
{
|
||||
int i;
|
||||
const SSL_CIPHER *c;
|
||||
@@ -504,8 +517,16 @@ int ssl_cipher_get_evp(SSL_CTX *ctx, const SSL_SESSION *s,
|
||||
if ((enc == NULL) || (md == NULL))
|
||||
return 0;
|
||||
|
||||
- if (!ssl_cipher_get_evp_cipher(ctx, c, enc))
|
||||
- return 0;
|
||||
+ i = ssl_cipher_info_lookup(ssl_cipher_table_cipher, c->algorithm_enc);
|
||||
+
|
||||
+ if (i == -1) {
|
||||
+ *enc = NULL;
|
||||
+ } else {
|
||||
+ if (i == SSL_ENC_NULL_IDX)
|
||||
+ *enc = EVP_enc_null();
|
||||
+ else
|
||||
+ *enc = ssl_cipher_methods[i];
|
||||
+ }
|
||||
|
||||
i = ssl_cipher_info_lookup(ssl_cipher_table_mac, c->algorithm_mac);
|
||||
if (i == -1) {
|
||||
@@ -517,80 +538,67 @@ int ssl_cipher_get_evp(SSL_CTX *ctx, const SSL_SESSION *s,
|
||||
if (c->algorithm_mac == SSL_AEAD)
|
||||
mac_pkey_type = NULL;
|
||||
} else {
|
||||
- if (!ssl_evp_md_up_ref(ctx->ssl_digest_methods[i])) {
|
||||
- ssl_evp_cipher_free(*enc);
|
||||
- return 0;
|
||||
- }
|
||||
- *md = ctx->ssl_digest_methods[i];
|
||||
+ *md = ssl_digest_methods[i];
|
||||
if (mac_pkey_type != NULL)
|
||||
*mac_pkey_type = ssl_mac_pkey_id[i];
|
||||
if (mac_secret_size != NULL)
|
||||
- *mac_secret_size = ctx->ssl_mac_secret_size[i];
|
||||
+ *mac_secret_size = ssl_mac_secret_size[i];
|
||||
}
|
||||
|
||||
if ((*enc != NULL) &&
|
||||
(*md != NULL || (EVP_CIPHER_flags(*enc) & EVP_CIPH_FLAG_AEAD_CIPHER))
|
||||
&& (!mac_pkey_type || *mac_pkey_type != NID_undef)) {
|
||||
- const EVP_CIPHER *evp = NULL;
|
||||
+ const EVP_CIPHER *evp;
|
||||
|
||||
- if (use_etm
|
||||
- || s->ssl_version >> 8 != TLS1_VERSION_MAJOR
|
||||
- || s->ssl_version < TLS1_VERSION)
|
||||
+ if (use_etm)
|
||||
return 1;
|
||||
|
||||
- if (c->algorithm_enc == SSL_RC4
|
||||
- && c->algorithm_mac == SSL_MD5)
|
||||
- evp = ssl_evp_cipher_fetch(ctx->libctx, NID_rc4_hmac_md5,
|
||||
- ctx->propq);
|
||||
- else if (c->algorithm_enc == SSL_AES128
|
||||
- && c->algorithm_mac == SSL_SHA1)
|
||||
- evp = ssl_evp_cipher_fetch(ctx->libctx,
|
||||
- NID_aes_128_cbc_hmac_sha1,
|
||||
- ctx->propq);
|
||||
- else if (c->algorithm_enc == SSL_AES256
|
||||
- && c->algorithm_mac == SSL_SHA1)
|
||||
- evp = ssl_evp_cipher_fetch(ctx->libctx,
|
||||
- NID_aes_256_cbc_hmac_sha1,
|
||||
- ctx->propq);
|
||||
- else if (c->algorithm_enc == SSL_AES128
|
||||
- && c->algorithm_mac == SSL_SHA256)
|
||||
- evp = ssl_evp_cipher_fetch(ctx->libctx,
|
||||
- NID_aes_128_cbc_hmac_sha256,
|
||||
- ctx->propq);
|
||||
- else if (c->algorithm_enc == SSL_AES256
|
||||
- && c->algorithm_mac == SSL_SHA256)
|
||||
- evp = ssl_evp_cipher_fetch(ctx->libctx,
|
||||
- NID_aes_256_cbc_hmac_sha256,
|
||||
- ctx->propq);
|
||||
-
|
||||
- if (evp != NULL) {
|
||||
- ssl_evp_cipher_free(*enc);
|
||||
- ssl_evp_md_free(*md);
|
||||
- *enc = evp;
|
||||
- *md = NULL;
|
||||
- }
|
||||
+ if (s->ssl_version >> 8 != TLS1_VERSION_MAJOR ||
|
||||
+ s->ssl_version < TLS1_VERSION)
|
||||
+ return 1;
|
||||
+
|
||||
+ if (c->algorithm_enc == SSL_RC4 &&
|
||||
+ c->algorithm_mac == SSL_MD5 &&
|
||||
+ (evp = EVP_get_cipherbyname("RC4-HMAC-MD5")))
|
||||
+ *enc = evp, *md = NULL;
|
||||
+ else if (c->algorithm_enc == SSL_AES128 &&
|
||||
+ c->algorithm_mac == SSL_SHA1 &&
|
||||
+ (evp = EVP_get_cipherbyname("AES-128-CBC-HMAC-SHA1")))
|
||||
+ *enc = evp, *md = NULL;
|
||||
+ else if (c->algorithm_enc == SSL_AES256 &&
|
||||
+ c->algorithm_mac == SSL_SHA1 &&
|
||||
+ (evp = EVP_get_cipherbyname("AES-256-CBC-HMAC-SHA1")))
|
||||
+ *enc = evp, *md = NULL;
|
||||
+ else if (c->algorithm_enc == SSL_AES128 &&
|
||||
+ c->algorithm_mac == SSL_SHA256 &&
|
||||
+ (evp = EVP_get_cipherbyname("AES-128-CBC-HMAC-SHA256")))
|
||||
+ *enc = evp, *md = NULL;
|
||||
+ else if (c->algorithm_enc == SSL_AES256 &&
|
||||
+ c->algorithm_mac == SSL_SHA256 &&
|
||||
+ (evp = EVP_get_cipherbyname("AES-256-CBC-HMAC-SHA256")))
|
||||
+ *enc = evp, *md = NULL;
|
||||
return 1;
|
||||
+ } else {
|
||||
+ return 0;
|
||||
}
|
||||
-
|
||||
- return 0;
|
||||
}
|
||||
|
||||
-const EVP_MD *ssl_md(SSL_CTX *ctx, int idx)
|
||||
+const EVP_MD *ssl_md(int idx)
|
||||
{
|
||||
idx &= SSL_HANDSHAKE_MAC_MASK;
|
||||
if (idx < 0 || idx >= SSL_MD_NUM_IDX)
|
||||
return NULL;
|
||||
- return ctx->ssl_digest_methods[idx];
|
||||
+ return ssl_digest_methods[idx];
|
||||
}
|
||||
|
||||
const EVP_MD *ssl_handshake_md(SSL *s)
|
||||
{
|
||||
- return ssl_md(s->ctx, ssl_get_algorithm2(s));
|
||||
+ return ssl_md(ssl_get_algorithm2(s));
|
||||
}
|
||||
|
||||
const EVP_MD *ssl_prf_md(SSL *s)
|
||||
{
|
||||
- return ssl_md(s->ctx, ssl_get_algorithm2(s) >> TLS1_PRF_DGST_SHIFT);
|
||||
+ return ssl_md(ssl_get_algorithm2(s) >> TLS1_PRF_DGST_SHIFT);
|
||||
}
|
||||
|
||||
#define ITEM_SEP(a) \
|
||||
@@ -2087,7 +2095,7 @@ const EVP_MD *SSL_CIPHER_get_handshake_digest(const SSL_CIPHER *c)
|
||||
|
||||
if (idx < 0 || idx >= SSL_MD_NUM_IDX)
|
||||
return NULL;
|
||||
- return EVP_get_digestbynid(ssl_cipher_table_mac[idx].nid);
|
||||
+ return ssl_digest_methods[idx];
|
||||
}
|
||||
|
||||
int SSL_CIPHER_is_aead(const SSL_CIPHER *c)
|
||||
diff --git a/ssl/ssl_init.c b/ssl/ssl_init.c
|
||||
index 2ccbda7fa3..3e85426112 100644
|
||||
--- a/ssl/ssl_init.c
|
||||
+++ b/ssl/ssl_init.c
|
||||
@@ -94,7 +94,10 @@ DEFINE_RUN_ONCE_STATIC(ossl_init_ssl_base)
|
||||
*/
|
||||
SSL_COMP_get_compression_methods();
|
||||
#endif
|
||||
- ssl_sort_cipher_list();
|
||||
+ /* initialize cipher/digest methods table */
|
||||
+ if (!ssl_load_ciphers())
|
||||
+ return 0;
|
||||
+
|
||||
OSSL_TRACE(INIT,"ossl_init_ssl_base: SSL_add_ssl_module()\n");
|
||||
/*
|
||||
* We ignore an error return here. Not much we can do - but not that bad
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index a08ddb138b..b5239d6eb2 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -3146,10 +3146,6 @@ SSL_CTX *SSL_CTX_new_with_libctx(OPENSSL_CTX *libctx, const char *propq,
|
||||
goto err;
|
||||
#endif
|
||||
|
||||
- /* initialize cipher/digest methods table */
|
||||
- if (!ssl_load_ciphers(ret))
|
||||
- goto err2;
|
||||
-
|
||||
if (!SSL_CTX_set_ciphersuites(ret, OSSL_default_ciphersuites()))
|
||||
goto err;
|
||||
|
||||
@@ -3166,12 +3162,14 @@ SSL_CTX *SSL_CTX_new_with_libctx(OPENSSL_CTX *libctx, const char *propq,
|
||||
if (ret->param == NULL)
|
||||
goto err;
|
||||
|
||||
- /*
|
||||
- * If these aren't available from the provider we'll get NULL returns.
|
||||
- * That's fine but will cause errors later if SSLv3 is negotiated
|
||||
- */
|
||||
- ret->md5 = ssl_evp_md_fetch(libctx, NID_md5, propq);
|
||||
- ret->sha1 = ssl_evp_md_fetch(libctx, NID_sha1, propq);
|
||||
+ if ((ret->md5 = EVP_get_digestbyname("ssl3-md5")) == NULL) {
|
||||
+ SSLerr(0, SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES);
|
||||
+ goto err2;
|
||||
+ }
|
||||
+ if ((ret->sha1 = EVP_get_digestbyname("ssl3-sha1")) == NULL) {
|
||||
+ SSLerr(0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES);
|
||||
+ goto err2;
|
||||
+ }
|
||||
|
||||
if ((ret->ca_names = sk_X509_NAME_new_null()) == NULL)
|
||||
goto err;
|
||||
@@ -3361,14 +3359,6 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
OPENSSL_free(a->ext.alpn);
|
||||
OPENSSL_secure_free(a->ext.secure);
|
||||
|
||||
- ssl_evp_md_free(a->md5);
|
||||
- ssl_evp_md_free(a->sha1);
|
||||
-
|
||||
- for (i = 0; i < SSL_ENC_NUM_IDX; i++)
|
||||
- ssl_evp_cipher_free(a->ssl_cipher_methods[i]);
|
||||
- for (i = 0; i < SSL_MD_NUM_IDX; i++)
|
||||
- ssl_evp_md_free(a->ssl_digest_methods[i]);
|
||||
-
|
||||
CRYPTO_THREAD_lock_free(a->lock);
|
||||
|
||||
OPENSSL_free(a->propq);
|
||||
@@ -5843,112 +5833,3 @@ void SSL_set_allow_early_data_cb(SSL *s,
|
||||
s->allow_early_data_cb = cb;
|
||||
s->allow_early_data_cb_data = arg;
|
||||
}
|
||||
-
|
||||
-const EVP_CIPHER *ssl_evp_cipher_fetch(OPENSSL_CTX *libctx,
|
||||
- int nid,
|
||||
- const char *properties)
|
||||
-{
|
||||
- EVP_CIPHER *ciph;
|
||||
-
|
||||
-#ifndef OPENSSL_NO_ENGINE
|
||||
- ENGINE *eng;
|
||||
-
|
||||
- /*
|
||||
- * If there is an Engine available for this cipher we use the "implicit"
|
||||
- * form to ensure we use that engine later.
|
||||
- */
|
||||
- eng = ENGINE_get_cipher_engine(nid);
|
||||
- if (eng != NULL) {
|
||||
- ENGINE_finish(eng);
|
||||
- return EVP_get_cipherbynid(nid);
|
||||
- }
|
||||
-#endif
|
||||
-
|
||||
- /* Otherwise we do an explicit fetch. This may fail and that could be ok */
|
||||
- ERR_set_mark();
|
||||
- ciph = EVP_CIPHER_fetch(libctx, OBJ_nid2sn(nid), properties);
|
||||
- ERR_pop_to_mark();
|
||||
- return ciph;
|
||||
-}
|
||||
-
|
||||
-
|
||||
-int ssl_evp_cipher_up_ref(const EVP_CIPHER *cipher)
|
||||
-{
|
||||
- /* Don't up-ref an implicit EVP_CIPHER */
|
||||
- if (EVP_CIPHER_provider(cipher) == NULL)
|
||||
- return 1;
|
||||
-
|
||||
- /*
|
||||
- * The cipher was explicitly fetched and therefore it is safe to cast
|
||||
- * away the const
|
||||
- */
|
||||
- return EVP_CIPHER_up_ref((EVP_CIPHER *)cipher);
|
||||
-}
|
||||
-
|
||||
-void ssl_evp_cipher_free(const EVP_CIPHER *cipher)
|
||||
-{
|
||||
- if (cipher == NULL)
|
||||
- return;
|
||||
-
|
||||
- if (EVP_CIPHER_provider(cipher) != NULL) {
|
||||
- /*
|
||||
- * The cipher was explicitly fetched and therefore it is safe to cast
|
||||
- * away the const
|
||||
- */
|
||||
- EVP_CIPHER_free((EVP_CIPHER *)cipher);
|
||||
- }
|
||||
-}
|
||||
-
|
||||
-const EVP_MD *ssl_evp_md_fetch(OPENSSL_CTX *libctx,
|
||||
- int nid,
|
||||
- const char *properties)
|
||||
-{
|
||||
- EVP_MD *md;
|
||||
-
|
||||
-#ifndef OPENSSL_NO_ENGINE
|
||||
- ENGINE *eng;
|
||||
-
|
||||
- /*
|
||||
- * If there is an Engine available for this digest we use the "implicit"
|
||||
- * form to ensure we use that engine later.
|
||||
- */
|
||||
- eng = ENGINE_get_digest_engine(nid);
|
||||
- if (eng != NULL) {
|
||||
- ENGINE_finish(eng);
|
||||
- return EVP_get_digestbynid(nid);
|
||||
- }
|
||||
-#endif
|
||||
-
|
||||
- /* Otherwise we do an explicit fetch */
|
||||
- ERR_set_mark();
|
||||
- md = EVP_MD_fetch(libctx, OBJ_nid2sn(nid), properties);
|
||||
- ERR_pop_to_mark();
|
||||
- return md;
|
||||
-}
|
||||
-
|
||||
-int ssl_evp_md_up_ref(const EVP_MD *md)
|
||||
-{
|
||||
- /* Don't up-ref an implicit EVP_MD */
|
||||
- if (EVP_MD_provider(md) == NULL)
|
||||
- return 1;
|
||||
-
|
||||
- /*
|
||||
- * The digest was explicitly fetched and therefore it is safe to cast
|
||||
- * away the const
|
||||
- */
|
||||
- return EVP_MD_up_ref((EVP_MD *)md);
|
||||
-}
|
||||
-
|
||||
-void ssl_evp_md_free(const EVP_MD *md)
|
||||
-{
|
||||
- if (md == NULL)
|
||||
- return;
|
||||
-
|
||||
- if (EVP_MD_provider(md) != NULL) {
|
||||
- /*
|
||||
- * The digest was explicitly fetched and therefore it is safe to cast
|
||||
- * away the const
|
||||
- */
|
||||
- EVP_MD_free((EVP_MD *)md);
|
||||
- }
|
||||
-}
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index c48bcb9a9a..f0f0a53ecf 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -276,8 +276,6 @@
|
||||
# define SSL_MD_SHA512_IDX 11
|
||||
# define SSL_MAX_DIGEST 12
|
||||
|
||||
-#define SSL_MD_NUM_IDX SSL_MAX_DIGEST
|
||||
-
|
||||
/* Bits for algorithm2 (handshake digests and other extra flags) */
|
||||
|
||||
/* Bits 0-7 are handshake MAC */
|
||||
@@ -391,30 +389,6 @@
|
||||
# define SSL_PKEY_ED448 8
|
||||
# define SSL_PKEY_NUM 9
|
||||
|
||||
-# define SSL_ENC_DES_IDX 0
|
||||
-# define SSL_ENC_3DES_IDX 1
|
||||
-# define SSL_ENC_RC4_IDX 2
|
||||
-# define SSL_ENC_RC2_IDX 3
|
||||
-# define SSL_ENC_IDEA_IDX 4
|
||||
-# define SSL_ENC_NULL_IDX 5
|
||||
-# define SSL_ENC_AES128_IDX 6
|
||||
-# define SSL_ENC_AES256_IDX 7
|
||||
-# define SSL_ENC_CAMELLIA128_IDX 8
|
||||
-# define SSL_ENC_CAMELLIA256_IDX 9
|
||||
-# define SSL_ENC_GOST89_IDX 10
|
||||
-# define SSL_ENC_SEED_IDX 11
|
||||
-# define SSL_ENC_AES128GCM_IDX 12
|
||||
-# define SSL_ENC_AES256GCM_IDX 13
|
||||
-# define SSL_ENC_AES128CCM_IDX 14
|
||||
-# define SSL_ENC_AES256CCM_IDX 15
|
||||
-# define SSL_ENC_AES128CCM8_IDX 16
|
||||
-# define SSL_ENC_AES256CCM8_IDX 17
|
||||
-# define SSL_ENC_GOST8912_IDX 18
|
||||
-# define SSL_ENC_CHACHA_IDX 19
|
||||
-# define SSL_ENC_ARIA128GCM_IDX 20
|
||||
-# define SSL_ENC_ARIA256GCM_IDX 21
|
||||
-# define SSL_ENC_NUM_IDX 22
|
||||
-
|
||||
/*-
|
||||
* SSL_kRSA <- RSA_ENC
|
||||
* SSL_kDH <- DH_ENC & (RSA_ENC | RSA_SIGN | DSA_SIGN)
|
||||
@@ -891,7 +865,7 @@ struct ssl_ctx_st {
|
||||
CRYPTO_EX_DATA ex_data;
|
||||
|
||||
const EVP_MD *md5; /* For SSLv3/TLSv1 'ssl3-md5' */
|
||||
- const EVP_MD *sha1; /* For SSLv3/TLSv1 'ssl3-sha1' */
|
||||
+ const EVP_MD *sha1; /* For SSLv3/TLSv1 'ssl3->sha1' */
|
||||
|
||||
STACK_OF(X509) *extra_certs;
|
||||
STACK_OF(SSL_COMP) *comp_methods; /* stack of SSL_COMP, SSLv3/TLSv1 */
|
||||
@@ -1135,10 +1109,6 @@ struct ssl_ctx_st {
|
||||
void *async_cb_arg;
|
||||
|
||||
char *propq;
|
||||
-
|
||||
- const EVP_CIPHER *ssl_cipher_methods[SSL_ENC_NUM_IDX];
|
||||
- const EVP_MD *ssl_digest_methods[SSL_MD_NUM_IDX];
|
||||
- size_t ssl_mac_secret_size[SSL_MD_NUM_IDX];
|
||||
};
|
||||
|
||||
typedef struct cert_pkey_st CERT_PKEY;
|
||||
@@ -2363,12 +2333,10 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
-__owur int ssl_cipher_get_evp_cipher(SSL_CTX *ctx, const SSL_CIPHER *sslc,
|
||||
- const EVP_CIPHER **enc);
|
||||
-__owur int ssl_cipher_get_evp(SSL_CTX *ctxc, const SSL_SESSION *s,
|
||||
- const EVP_CIPHER **enc, const EVP_MD **md,
|
||||
- int *mac_pkey_type, size_t *mac_secret_size,
|
||||
- SSL_COMP **comp, int use_etm);
|
||||
+__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
+ const EVP_MD **md, int *mac_pkey_type,
|
||||
+ size_t *mac_secret_size, SSL_COMP **comp,
|
||||
+ int use_etm);
|
||||
__owur int ssl_cipher_get_overhead(const SSL_CIPHER *c, size_t *mac_overhead,
|
||||
size_t *int_overhead, size_t *blocksize,
|
||||
size_t *ext_overhead);
|
||||
@@ -2408,7 +2376,7 @@ void ssl_set_masks(SSL *s);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_get_ciphers_by_id(SSL *s);
|
||||
__owur int ssl_x509err2alert(int type);
|
||||
void ssl_sort_cipher_list(void);
|
||||
-int ssl_load_ciphers(SSL_CTX *ctx);
|
||||
+int ssl_load_ciphers(void);
|
||||
__owur int ssl_fill_hello_random(SSL *s, int server, unsigned char *field,
|
||||
size_t len, DOWNGRADE dgrd);
|
||||
__owur int ssl_generate_master_secret(SSL *s, unsigned char *pms, size_t pmslen,
|
||||
@@ -2663,8 +2631,7 @@ __owur int tls1_save_u16(PACKET *pkt, uint16_t **pdest, size_t *pdestlen);
|
||||
__owur int tls1_save_sigalgs(SSL *s, PACKET *pkt, int cert);
|
||||
__owur int tls1_process_sigalgs(SSL *s);
|
||||
__owur int tls1_set_peer_legacy_sigalg(SSL *s, const EVP_PKEY *pkey);
|
||||
-__owur int tls1_lookup_md(SSL_CTX *ctx, const SIGALG_LOOKUP *lu,
|
||||
- const EVP_MD **pmd);
|
||||
+__owur int tls1_lookup_md(const SIGALG_LOOKUP *lu, const EVP_MD **pmd);
|
||||
__owur size_t tls12_get_psigalgs(SSL *s, int sent, const uint16_t **psigs);
|
||||
# ifndef OPENSSL_NO_EC
|
||||
__owur int tls_check_sigalg_curve(const SSL *s, int curve);
|
||||
@@ -2675,7 +2642,7 @@ __owur int ssl_cipher_disabled(const SSL *s, const SSL_CIPHER *c, int op, int ec
|
||||
|
||||
__owur int ssl_handshake_hash(SSL *s, unsigned char *out, size_t outlen,
|
||||
size_t *hashlen);
|
||||
-__owur const EVP_MD *ssl_md(SSL_CTX *ctx, int idx);
|
||||
+__owur const EVP_MD *ssl_md(int idx);
|
||||
__owur const EVP_MD *ssl_handshake_md(SSL *s);
|
||||
__owur const EVP_MD *ssl_prf_md(SSL *s);
|
||||
|
||||
@@ -2753,18 +2720,6 @@ void ssl_comp_free_compression_methods_int(void);
|
||||
/* ssl_mcnf.c */
|
||||
void ssl_ctx_system_config(SSL_CTX *ctx);
|
||||
|
||||
-const EVP_CIPHER *ssl_evp_cipher_fetch(OPENSSL_CTX *libctx,
|
||||
- int nid,
|
||||
- const char *properties);
|
||||
-int ssl_evp_cipher_up_ref(const EVP_CIPHER *cipher);
|
||||
-void ssl_evp_cipher_free(const EVP_CIPHER *cipher);
|
||||
-const EVP_MD *ssl_evp_md_fetch(OPENSSL_CTX *libctx,
|
||||
- int nid,
|
||||
- const char *properties);
|
||||
-int ssl_evp_md_up_ref(const EVP_MD *md);
|
||||
-void ssl_evp_md_free(const EVP_MD *md);
|
||||
-
|
||||
-
|
||||
# else /* OPENSSL_UNIT_TEST */
|
||||
|
||||
# define ssl_init_wbio_buffer SSL_test_functions()->p_ssl_init_wbio_buffer
|
||||
diff --git a/ssl/ssl_txt.c b/ssl/ssl_txt.c
|
||||
index 09d00bacbe..bc3fcfbd1d 100644
|
||||
--- a/ssl/ssl_txt.c
|
||||
+++ b/ssl/ssl_txt.c
|
||||
@@ -117,7 +117,7 @@ int SSL_SESSION_print(BIO *bp, const SSL_SESSION *x)
|
||||
if (x->compress_meth != 0) {
|
||||
SSL_COMP *comp = NULL;
|
||||
|
||||
- if (!ssl_cipher_get_evp(NULL, x, NULL, NULL, NULL, NULL, &comp, 0))
|
||||
+ if (!ssl_cipher_get_evp(x, NULL, NULL, NULL, NULL, &comp, 0))
|
||||
goto err;
|
||||
if (comp == NULL) {
|
||||
if (BIO_printf(bp, "\n Compression: %d", x->compress_meth) <= 0)
|
||||
diff --git a/ssl/statem/extensions_clnt.c b/ssl/statem/extensions_clnt.c
|
||||
index 776473e659..75fecdeaa6 100644
|
||||
--- a/ssl/statem/extensions_clnt.c
|
||||
+++ b/ssl/statem/extensions_clnt.c
|
||||
@@ -981,7 +981,7 @@ EXT_RETURN tls_construct_ctos_padding(SSL *s, WPACKET *pkt,
|
||||
if (s->session->ssl_version == TLS1_3_VERSION
|
||||
&& s->session->ext.ticklen != 0
|
||||
&& s->session->cipher != NULL) {
|
||||
- const EVP_MD *md = ssl_md(s->ctx, s->session->cipher->algorithm2);
|
||||
+ const EVP_MD *md = ssl_md(s->session->cipher->algorithm2);
|
||||
|
||||
if (md != NULL) {
|
||||
/*
|
||||
@@ -1059,7 +1059,7 @@ EXT_RETURN tls_construct_ctos_psk(SSL *s, WPACKET *pkt, unsigned int context,
|
||||
ERR_R_INTERNAL_ERROR);
|
||||
return EXT_RETURN_FAIL;
|
||||
}
|
||||
- mdres = ssl_md(s->ctx, s->session->cipher->algorithm2);
|
||||
+ mdres = ssl_md(s->session->cipher->algorithm2);
|
||||
if (mdres == NULL) {
|
||||
/*
|
||||
* Don't recognize this cipher so we can't use the session.
|
||||
@@ -1132,7 +1132,7 @@ EXT_RETURN tls_construct_ctos_psk(SSL *s, WPACKET *pkt, unsigned int context,
|
||||
return EXT_RETURN_NOT_SENT;
|
||||
|
||||
if (s->psksession != NULL) {
|
||||
- mdpsk = ssl_md(s->ctx, s->psksession->cipher->algorithm2);
|
||||
+ mdpsk = ssl_md(s->psksession->cipher->algorithm2);
|
||||
if (mdpsk == NULL) {
|
||||
/*
|
||||
* Don't recognize this cipher so we can't use the session.
|
||||
diff --git a/ssl/statem/extensions_srvr.c b/ssl/statem/extensions_srvr.c
|
||||
index 549a207430..756ceafb50 100644
|
||||
--- a/ssl/statem/extensions_srvr.c
|
||||
+++ b/ssl/statem/extensions_srvr.c
|
||||
@@ -1239,9 +1239,8 @@ int tls_parse_ctos_psk(SSL *s, PACKET *pkt, unsigned int context, X509 *x,
|
||||
}
|
||||
}
|
||||
|
||||
- md = ssl_md(s->ctx, sess->cipher->algorithm2);
|
||||
- if (!EVP_MD_is_a(md,
|
||||
- EVP_MD_name(ssl_md(s->ctx, s->s3.tmp.new_cipher->algorithm2)))) {
|
||||
+ md = ssl_md(sess->cipher->algorithm2);
|
||||
+ if (md != ssl_md(s->s3.tmp.new_cipher->algorithm2)) {
|
||||
/* The ciphersuite is not compatible with this session. */
|
||||
SSL_SESSION_free(sess);
|
||||
sess = NULL;
|
||||
diff --git a/ssl/statem/statem_clnt.c b/ssl/statem/statem_clnt.c
|
||||
index cdd413d1ef..8d843099f9 100644
|
||||
--- a/ssl/statem/statem_clnt.c
|
||||
+++ b/ssl/statem/statem_clnt.c
|
||||
@@ -1376,8 +1376,8 @@ static int set_client_ciphersuite(SSL *s, const unsigned char *cipherchars)
|
||||
* In TLSv1.3 it is valid for the server to select a different
|
||||
* ciphersuite as long as the hash is the same.
|
||||
*/
|
||||
- if (ssl_md(s->ctx, c->algorithm2)
|
||||
- != ssl_md(s->ctx, s->session->cipher->algorithm2)) {
|
||||
+ if (ssl_md(c->algorithm2)
|
||||
+ != ssl_md(s->session->cipher->algorithm2)) {
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER,
|
||||
SSL_F_SET_CLIENT_CIPHERSUITE,
|
||||
SSL_R_CIPHERSUITE_DIGEST_HAS_CHANGED);
|
||||
@@ -2339,7 +2339,7 @@ MSG_PROCESS_RETURN tls_process_key_exchange(SSL *s, PACKET *pkt)
|
||||
goto err;
|
||||
}
|
||||
|
||||
- if (!tls1_lookup_md(s->ctx, s->s3.tmp.peer_sigalg, &md)) {
|
||||
+ if (!tls1_lookup_md(s->s3.tmp.peer_sigalg, &md)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS_PROCESS_KEY_EXCHANGE,
|
||||
ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
diff --git a/ssl/statem/statem_lib.c b/ssl/statem/statem_lib.c
|
||||
index e9cfee027e..b89566d840 100644
|
||||
--- a/ssl/statem/statem_lib.c
|
||||
+++ b/ssl/statem/statem_lib.c
|
||||
@@ -247,7 +247,7 @@ int tls_construct_cert_verify(SSL *s, WPACKET *pkt)
|
||||
}
|
||||
pkey = s->s3.tmp.cert->privatekey;
|
||||
|
||||
- if (pkey == NULL || !tls1_lookup_md(s->ctx, lu, &md)) {
|
||||
+ if (pkey == NULL || !tls1_lookup_md(lu, &md)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS_CONSTRUCT_CERT_VERIFY,
|
||||
ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
@@ -422,7 +422,7 @@ MSG_PROCESS_RETURN tls_process_cert_verify(SSL *s, PACKET *pkt)
|
||||
goto err;
|
||||
}
|
||||
|
||||
- if (!tls1_lookup_md(s->ctx, s->s3.tmp.peer_sigalg, &md)) {
|
||||
+ if (!tls1_lookup_md(s->s3.tmp.peer_sigalg, &md)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS_PROCESS_CERT_VERIFY,
|
||||
ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index 43f9811163..a23187290e 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -2773,7 +2773,7 @@ int tls_construct_server_key_exchange(SSL *s, WPACKET *pkt)
|
||||
unsigned char *sigbytes1, *sigbytes2, *tbs;
|
||||
size_t siglen = 0, tbslen;
|
||||
|
||||
- if (pkey == NULL || !tls1_lookup_md(s->ctx, lu, &md)) {
|
||||
+ if (pkey == NULL || !tls1_lookup_md(lu, &md)) {
|
||||
/* Should never happen */
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR,
|
||||
SSL_F_TLS_CONSTRUCT_SERVER_KEY_EXCHANGE,
|
||||
diff --git a/ssl/t1_enc.c b/ssl/t1_enc.c
|
||||
index c50905589b..0a5c770a84 100644
|
||||
--- a/ssl/t1_enc.c
|
||||
+++ b/ssl/t1_enc.c
|
||||
@@ -540,16 +540,14 @@ int tls1_setup_key_block(SSL *s)
|
||||
if (s->s3.tmp.key_block_length != 0)
|
||||
return 1;
|
||||
|
||||
- if (!ssl_cipher_get_evp(s->ctx, s->session, &c, &hash, &mac_type,
|
||||
- &mac_secret_size, &comp, s->ext.use_etm)) {
|
||||
+ if (!ssl_cipher_get_evp(s->session, &c, &hash, &mac_type, &mac_secret_size,
|
||||
+ &comp, s->ext.use_etm)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS1_SETUP_KEY_BLOCK,
|
||||
SSL_R_CIPHER_OR_HASH_UNAVAILABLE);
|
||||
return 0;
|
||||
}
|
||||
|
||||
- ssl_evp_cipher_free(s->s3.tmp.new_sym_enc);
|
||||
s->s3.tmp.new_sym_enc = c;
|
||||
- ssl_evp_md_free(s->s3.tmp.new_hash);
|
||||
s->s3.tmp.new_hash = hash;
|
||||
s->s3.tmp.new_mac_pkey_type = mac_type;
|
||||
s->s3.tmp.new_mac_secret_size = mac_secret_size;
|
||||
diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c
|
||||
index 624add64a8..235f5661ad 100644
|
||||
--- a/ssl/t1_lib.c
|
||||
+++ b/ssl/t1_lib.c
|
||||
@@ -893,7 +893,7 @@ static const SIGALG_LOOKUP *tls1_lookup_sigalg(uint16_t sigalg)
|
||||
return NULL;
|
||||
}
|
||||
/* Lookup hash: return 0 if invalid or not enabled */
|
||||
-int tls1_lookup_md(SSL_CTX *ctx, const SIGALG_LOOKUP *lu, const EVP_MD **pmd)
|
||||
+int tls1_lookup_md(const SIGALG_LOOKUP *lu, const EVP_MD **pmd)
|
||||
{
|
||||
const EVP_MD *md;
|
||||
if (lu == NULL)
|
||||
@@ -902,7 +902,7 @@ int tls1_lookup_md(SSL_CTX *ctx, const SIGALG_LOOKUP *lu, const EVP_MD **pmd)
|
||||
if (lu->hash == NID_undef) {
|
||||
md = NULL;
|
||||
} else {
|
||||
- md = ssl_md(ctx, lu->hash_idx);
|
||||
+ md = ssl_md(lu->hash_idx);
|
||||
if (md == NULL)
|
||||
return 0;
|
||||
}
|
||||
@@ -919,16 +919,15 @@ int tls1_lookup_md(SSL_CTX *ctx, const SIGALG_LOOKUP *lu, const EVP_MD **pmd)
|
||||
* with a 128 byte (1024 bit) key.
|
||||
*/
|
||||
#define RSA_PSS_MINIMUM_KEY_SIZE(md) (2 * EVP_MD_size(md) + 2)
|
||||
-static int rsa_pss_check_min_key_size(SSL_CTX *ctx, const EVP_PKEY *pkey,
|
||||
- const SIGALG_LOOKUP *lu)
|
||||
+static int rsa_pss_check_min_key_size(const RSA *rsa, const SIGALG_LOOKUP *lu)
|
||||
{
|
||||
const EVP_MD *md;
|
||||
|
||||
- if (pkey == NULL)
|
||||
+ if (rsa == NULL)
|
||||
return 0;
|
||||
- if (!tls1_lookup_md(ctx, lu, &md) || md == NULL)
|
||||
+ if (!tls1_lookup_md(lu, &md) || md == NULL)
|
||||
return 0;
|
||||
- if (EVP_PKEY_size(pkey) < RSA_PSS_MINIMUM_KEY_SIZE(md))
|
||||
+ if (RSA_size(rsa) < RSA_PSS_MINIMUM_KEY_SIZE(md))
|
||||
return 0;
|
||||
return 1;
|
||||
}
|
||||
@@ -979,7 +978,7 @@ static const SIGALG_LOOKUP *tls1_get_legacy_sigalg(const SSL *s, int idx)
|
||||
if (SSL_USE_SIGALGS(s) || idx != SSL_PKEY_RSA) {
|
||||
const SIGALG_LOOKUP *lu = tls1_lookup_sigalg(tls_default_sigalg[idx]);
|
||||
|
||||
- if (!tls1_lookup_md(s->ctx, lu, NULL))
|
||||
+ if (!tls1_lookup_md(lu, NULL))
|
||||
return NULL;
|
||||
if (!tls12_sigalg_allowed(s, SSL_SECOP_SIGALG_SUPPORTED, lu))
|
||||
return NULL;
|
||||
@@ -1075,31 +1074,6 @@ int tls_check_sigalg_curve(const SSL *s, int curve)
|
||||
}
|
||||
#endif
|
||||
|
||||
-/*
|
||||
- * Return the number of security bits for the signature algorithm, or 0 on
|
||||
- * error.
|
||||
- */
|
||||
-static int sigalg_security_bits(SSL_CTX *ctx, const SIGALG_LOOKUP *lu)
|
||||
-{
|
||||
- const EVP_MD *md = NULL;
|
||||
- int secbits = 0;
|
||||
-
|
||||
- if (!tls1_lookup_md(ctx, lu, &md))
|
||||
- return 0;
|
||||
- if (md != NULL)
|
||||
- {
|
||||
- /* Security bits: half digest bits */
|
||||
- secbits = EVP_MD_size(md) * 4;
|
||||
- } else {
|
||||
- /* Values from https://tools.ietf.org/html/rfc8032#section-8.5 */
|
||||
- if (lu->sigalg == TLSEXT_SIGALG_ed25519)
|
||||
- secbits = 128;
|
||||
- else if (lu->sigalg == TLSEXT_SIGALG_ed448)
|
||||
- secbits = 224;
|
||||
- }
|
||||
- return secbits;
|
||||
-}
|
||||
-
|
||||
/*
|
||||
* Check signature algorithm is consistent with sent supported signature
|
||||
* algorithms and if so set relevant digest and signature scheme in
|
||||
@@ -1113,7 +1087,6 @@ int tls12_check_peer_sigalg(SSL *s, uint16_t sig, EVP_PKEY *pkey)
|
||||
size_t sent_sigslen, i, cidx;
|
||||
int pkeyid = EVP_PKEY_id(pkey);
|
||||
const SIGALG_LOOKUP *lu;
|
||||
- int secbits = 0;
|
||||
|
||||
/* Should never happen */
|
||||
if (pkeyid == -1)
|
||||
@@ -1210,25 +1183,25 @@ int tls12_check_peer_sigalg(SSL *s, uint16_t sig, EVP_PKEY *pkey)
|
||||
SSL_R_WRONG_SIGNATURE_TYPE);
|
||||
return 0;
|
||||
}
|
||||
- if (!tls1_lookup_md(s->ctx, lu, &md)) {
|
||||
+ if (!tls1_lookup_md(lu, &md)) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_F_TLS12_CHECK_PEER_SIGALG,
|
||||
SSL_R_UNKNOWN_DIGEST);
|
||||
return 0;
|
||||
}
|
||||
- /*
|
||||
- * Make sure security callback allows algorithm. For historical
|
||||
- * reasons we have to pass the sigalg as a two byte char array.
|
||||
- */
|
||||
- sigalgstr[0] = (sig >> 8) & 0xff;
|
||||
- sigalgstr[1] = sig & 0xff;
|
||||
- secbits = sigalg_security_bits(s->ctx, lu);
|
||||
- if (secbits == 0 ||
|
||||
- !ssl_security(s, SSL_SECOP_SIGALG_CHECK, secbits,
|
||||
- md != NULL ? EVP_MD_type(md) : NID_undef,
|
||||
- (void *)sigalgstr)) {
|
||||
- SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_F_TLS12_CHECK_PEER_SIGALG,
|
||||
- SSL_R_WRONG_SIGNATURE_TYPE);
|
||||
- return 0;
|
||||
+ if (md != NULL) {
|
||||
+ /*
|
||||
+ * Make sure security callback allows algorithm. For historical
|
||||
+ * reasons we have to pass the sigalg as a two byte char array.
|
||||
+ */
|
||||
+ sigalgstr[0] = (sig >> 8) & 0xff;
|
||||
+ sigalgstr[1] = sig & 0xff;
|
||||
+ if (!ssl_security(s, SSL_SECOP_SIGALG_CHECK,
|
||||
+ EVP_MD_size(md) * 4, EVP_MD_type(md),
|
||||
+ (void *)sigalgstr)) {
|
||||
+ SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_F_TLS12_CHECK_PEER_SIGALG,
|
||||
+ SSL_R_WRONG_SIGNATURE_TYPE);
|
||||
+ return 0;
|
||||
+ }
|
||||
}
|
||||
/* Store the sigalg the peer uses */
|
||||
s->s3.tmp.peer_sigalg = lu;
|
||||
@@ -1705,7 +1678,7 @@ static int tls12_sigalg_allowed(const SSL *s, int op, const SIGALG_LOOKUP *lu)
|
||||
int secbits;
|
||||
|
||||
/* See if sigalgs is recognised and if hash is enabled */
|
||||
- if (!tls1_lookup_md(s->ctx, lu, NULL))
|
||||
+ if (!tls1_lookup_md(lu, NULL))
|
||||
return 0;
|
||||
/* DSA is not allowed in TLS 1.3 */
|
||||
if (SSL_IS_TLS13(s) && lu->sig == EVP_PKEY_DSA)
|
||||
@@ -1760,8 +1733,11 @@ static int tls12_sigalg_allowed(const SSL *s, int op, const SIGALG_LOOKUP *lu)
|
||||
}
|
||||
}
|
||||
|
||||
+ if (lu->hash == NID_undef)
|
||||
+ return 1;
|
||||
+ /* Security bits: half digest bits */
|
||||
+ secbits = EVP_MD_size(ssl_md(lu->hash_idx)) * 4;
|
||||
/* Finally see if security callback allows it */
|
||||
- secbits = sigalg_security_bits(s->ctx, lu);
|
||||
sigalgstr[0] = (lu->sigalg >> 8) & 0xff;
|
||||
sigalgstr[1] = lu->sigalg & 0xff;
|
||||
return ssl_security(s, op, secbits, lu->hash, (void *)sigalgstr);
|
||||
@@ -2809,7 +2785,7 @@ static const SIGALG_LOOKUP *find_sig_alg(SSL *s, X509 *x, EVP_PKEY *pkey)
|
||||
|| lu->sig == EVP_PKEY_RSA)
|
||||
continue;
|
||||
/* Check that we have a cert, and signature_algorithms_cert */
|
||||
- if (!tls1_lookup_md(s->ctx, lu, NULL))
|
||||
+ if (!tls1_lookup_md(lu, NULL))
|
||||
continue;
|
||||
if ((pkey == NULL && !has_usable_cert(s, lu, -1))
|
||||
|| (pkey != NULL && !is_cert_usable(s, lu, x, pkey)))
|
||||
@@ -2831,7 +2807,7 @@ static const SIGALG_LOOKUP *find_sig_alg(SSL *s, X509 *x, EVP_PKEY *pkey)
|
||||
#endif
|
||||
} else if (lu->sig == EVP_PKEY_RSA_PSS) {
|
||||
/* validate that key is large enough for the signature algorithm */
|
||||
- if (!rsa_pss_check_min_key_size(s->ctx, tmppkey, lu))
|
||||
+ if (!rsa_pss_check_min_key_size(EVP_PKEY_get0(tmppkey), lu))
|
||||
continue;
|
||||
}
|
||||
break;
|
||||
@@ -2917,7 +2893,7 @@ int tls_choose_sigalg(SSL *s, int fatalerrs)
|
||||
/* validate that key is large enough for the signature algorithm */
|
||||
EVP_PKEY *pkey = s->cert->pkeys[sig_idx].privatekey;
|
||||
|
||||
- if (!rsa_pss_check_min_key_size(s->ctx, pkey, lu))
|
||||
+ if (!rsa_pss_check_min_key_size(EVP_PKEY_get0(pkey), lu))
|
||||
continue;
|
||||
}
|
||||
#ifndef OPENSSL_NO_EC
|
||||
diff --git a/ssl/tls13_enc.c b/ssl/tls13_enc.c
|
||||
index fba12fe5e4..181f3920a1 100644
|
||||
--- a/ssl/tls13_enc.c
|
||||
+++ b/ssl/tls13_enc.c
|
||||
@@ -36,8 +36,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret,
|
||||
#else
|
||||
static const unsigned char label_prefix[] = "tls13 ";
|
||||
#endif
|
||||
- EVP_KDF *kdf = EVP_KDF_fetch(s->ctx->libctx, OSSL_KDF_NAME_HKDF,
|
||||
- s->ctx->propq);
|
||||
+ EVP_KDF *kdf = EVP_KDF_fetch(NULL, OSSL_KDF_NAME_HKDF, NULL);
|
||||
EVP_KDF_CTX *kctx;
|
||||
OSSL_PARAM params[5], *p = params;
|
||||
int mode = EVP_PKEY_HKDEF_MODE_EXPAND_ONLY;
|
||||
@@ -195,7 +194,7 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md,
|
||||
#endif
|
||||
unsigned char preextractsec[EVP_MAX_MD_SIZE];
|
||||
|
||||
- kdf = EVP_KDF_fetch(s->ctx->libctx, OSSL_KDF_NAME_HKDF, s->ctx->propq);
|
||||
+ kdf = EVP_KDF_fetch(NULL, OSSL_KDF_NAME_HKDF, NULL);
|
||||
kctx = EVP_KDF_CTX_new(kdf);
|
||||
EVP_KDF_free(kdf);
|
||||
if (kctx == NULL) {
|
||||
@@ -312,27 +311,11 @@ int tls13_generate_master_secret(SSL *s, unsigned char *out,
|
||||
size_t tls13_final_finish_mac(SSL *s, const char *str, size_t slen,
|
||||
unsigned char *out)
|
||||
{
|
||||
- const char *mdname = EVP_MD_name(ssl_handshake_md(s));
|
||||
- EVP_MAC *hmac = EVP_MAC_fetch(s->ctx->libctx, "HMAC", s->ctx->propq);
|
||||
+ const EVP_MD *md = ssl_handshake_md(s);
|
||||
unsigned char hash[EVP_MAX_MD_SIZE];
|
||||
- unsigned char finsecret[EVP_MAX_MD_SIZE];
|
||||
size_t hashlen, ret = 0;
|
||||
- EVP_MAC_CTX *ctx = NULL;
|
||||
- OSSL_PARAM params[4], *p = params;
|
||||
-
|
||||
- if (hmac == NULL) {
|
||||
- SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_FINAL_FINISH_MAC,
|
||||
- ERR_R_INTERNAL_ERROR);
|
||||
- goto err;
|
||||
- }
|
||||
-
|
||||
- /* Safe to cast away const here since we're not "getting" any data */
|
||||
- *p++ = OSSL_PARAM_construct_utf8_string(OSSL_ALG_PARAM_DIGEST,
|
||||
- (char *)mdname, 0);
|
||||
- if (s->ctx->propq != NULL)
|
||||
- *p++ = OSSL_PARAM_construct_utf8_string(OSSL_ALG_PARAM_PROPERTIES,
|
||||
- (char *)s->ctx->propq,
|
||||
- 0);
|
||||
+ EVP_PKEY *key = NULL;
|
||||
+ EVP_MD_CTX *ctx = EVP_MD_CTX_new();
|
||||
|
||||
if (!ssl_handshake_hash(s, hash, sizeof(hash), &hashlen)) {
|
||||
/* SSLfatal() already called */
|
||||
@@ -340,31 +323,29 @@ size_t tls13_final_finish_mac(SSL *s, const char *str, size_t slen,
|
||||
}
|
||||
|
||||
if (str == s->method->ssl3_enc->server_finished_label) {
|
||||
- *p++ = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY,
|
||||
- s->server_finished_secret,
|
||||
- hashlen);
|
||||
+ key = EVP_PKEY_new_raw_private_key(EVP_PKEY_HMAC, NULL,
|
||||
+ s->server_finished_secret, hashlen);
|
||||
} else if (SSL_IS_FIRST_HANDSHAKE(s)) {
|
||||
- *p++ = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY,
|
||||
- s->client_finished_secret,
|
||||
- hashlen);
|
||||
+ key = EVP_PKEY_new_raw_private_key(EVP_PKEY_HMAC, NULL,
|
||||
+ s->client_finished_secret, hashlen);
|
||||
} else {
|
||||
+ unsigned char finsecret[EVP_MAX_MD_SIZE];
|
||||
+
|
||||
if (!tls13_derive_finishedkey(s, ssl_handshake_md(s),
|
||||
s->client_app_traffic_secret,
|
||||
finsecret, hashlen))
|
||||
goto err;
|
||||
|
||||
- *p++ = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY, finsecret,
|
||||
- hashlen);
|
||||
+ key = EVP_PKEY_new_raw_private_key(EVP_PKEY_HMAC, NULL, finsecret,
|
||||
+ hashlen);
|
||||
+ OPENSSL_cleanse(finsecret, sizeof(finsecret));
|
||||
}
|
||||
- *p++ = OSSL_PARAM_construct_end();
|
||||
|
||||
- ctx = EVP_MAC_CTX_new(hmac);
|
||||
- if (ctx == NULL
|
||||
- || !EVP_MAC_CTX_set_params(ctx, params)
|
||||
- || !EVP_MAC_init(ctx)
|
||||
- || !EVP_MAC_update(ctx, hash, hashlen)
|
||||
- /* outsize as per sizeof(peer_finish_md) */
|
||||
- || !EVP_MAC_final(ctx, out, &hashlen, EVP_MAX_MD_SIZE * 2)) {
|
||||
+ if (key == NULL
|
||||
+ || ctx == NULL
|
||||
+ || EVP_DigestSignInit(ctx, NULL, md, NULL, key) <= 0
|
||||
+ || EVP_DigestSignUpdate(ctx, hash, hashlen) <= 0
|
||||
+ || EVP_DigestSignFinal(ctx, out, &hashlen) <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_FINAL_FINISH_MAC,
|
||||
ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
@@ -372,9 +353,8 @@ size_t tls13_final_finish_mac(SSL *s, const char *str, size_t slen,
|
||||
|
||||
ret = hashlen;
|
||||
err:
|
||||
- OPENSSL_cleanse(finsecret, sizeof(finsecret));
|
||||
- EVP_MAC_CTX_free(ctx);
|
||||
- EVP_MAC_free(hmac);
|
||||
+ EVP_PKEY_free(key);
|
||||
+ EVP_MD_CTX_free(ctx);
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -388,16 +368,13 @@ int tls13_setup_key_block(SSL *s)
|
||||
const EVP_MD *hash;
|
||||
|
||||
s->session->cipher = s->s3.tmp.new_cipher;
|
||||
- if (!ssl_cipher_get_evp(s->ctx, s->session, &c, &hash, NULL, NULL, NULL,
|
||||
- 0)) {
|
||||
+ if (!ssl_cipher_get_evp(s->session, &c, &hash, NULL, NULL, NULL, 0)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_SETUP_KEY_BLOCK,
|
||||
SSL_R_CIPHER_OR_HASH_UNAVAILABLE);
|
||||
return 0;
|
||||
}
|
||||
|
||||
- ssl_evp_cipher_free(s->s3.tmp.new_sym_enc);
|
||||
s->s3.tmp.new_sym_enc = c;
|
||||
- ssl_evp_md_free(s->s3.tmp.new_hash);
|
||||
s->s3.tmp.new_hash = hash;
|
||||
|
||||
return 1;
|
||||
@@ -599,19 +576,8 @@ int tls13_change_cipher_state(SSL *s, int which)
|
||||
SSL_F_TLS13_CHANGE_CIPHER_STATE, ERR_R_MALLOC_FAILURE);
|
||||
goto err;
|
||||
}
|
||||
-
|
||||
- /*
|
||||
- * This ups the ref count on cipher so we better make sure we free
|
||||
- * it again
|
||||
- */
|
||||
- if (!ssl_cipher_get_evp_cipher(s->ctx, sslcipher, &cipher)) {
|
||||
- SSLfatal(s, SSL_AD_INTERNAL_ERROR,
|
||||
- SSL_F_TLS13_CHANGE_CIPHER_STATE,
|
||||
- SSL_R_ALGORITHM_FETCH_FAILED);
|
||||
- goto err;
|
||||
- }
|
||||
-
|
||||
- md = ssl_md(s->ctx, sslcipher->algorithm2);
|
||||
+ cipher = EVP_get_cipherbynid(SSL_CIPHER_get_cipher_nid(sslcipher));
|
||||
+ md = ssl_md(sslcipher->algorithm2);
|
||||
if (md == NULL || !EVP_DigestInit_ex(mdctx, md, NULL)
|
||||
|| !EVP_DigestUpdate(mdctx, hdata, handlen)
|
||||
|| !EVP_DigestFinal_ex(mdctx, hashval, &hashlenui)) {
|
||||
@@ -766,10 +732,6 @@ int tls13_change_cipher_state(SSL *s, int which)
|
||||
s->statem.enc_write_state = ENC_WRITE_STATE_VALID;
|
||||
ret = 1;
|
||||
err:
|
||||
- if ((which & SSL3_CC_EARLY) != 0) {
|
||||
- /* We up-refed this so now we need to down ref */
|
||||
- ssl_evp_cipher_free(cipher);
|
||||
- }
|
||||
OPENSSL_cleanse(secret, sizeof(secret));
|
||||
return ret;
|
||||
}
|
||||
@@ -900,7 +862,7 @@ int tls13_export_keying_material_early(SSL *s, unsigned char *out, size_t olen,
|
||||
else
|
||||
sslcipher = SSL_SESSION_get0_cipher(s->session);
|
||||
|
||||
- md = ssl_md(s->ctx, sslcipher->algorithm2);
|
||||
+ md = ssl_md(sslcipher->algorithm2);
|
||||
|
||||
/*
|
||||
* Calculate the hash value and store it in |data|. The reason why
|
||||
diff --git a/test/build.info b/test/build.info
|
||||
index 6d670ea175..f7ccdd5d9c 100644
|
||||
--- a/test/build.info
|
||||
+++ b/test/build.info
|
||||
@@ -35,6 +35,7 @@ IF[{- !$disabled{tests} -}]
|
||||
ectest ecstresstest gmdifftest pbelutest \
|
||||
destest mdc2test \
|
||||
enginetest exptest \
|
||||
+ ssltest_old exptest rsa_test \
|
||||
evp_pkey_provided_test evp_test evp_extra_test evp_fetch_prov_test \
|
||||
v3nametest v3ext \
|
||||
crltest danetest bad_dtls_test lhash_test sparse_array_test \
|
||||
@@ -115,6 +116,14 @@ IF[{- !$disabled{tests} -}]
|
||||
INCLUDE[exptest]=../include ../apps/include
|
||||
DEPEND[exptest]=../libcrypto libtestutil.a
|
||||
|
||||
+ SOURCE[rsa_test]=rsa_test.c
|
||||
+ INCLUDE[rsa_test]=../include ../apps/include
|
||||
+ DEPEND[rsa_test]=../libcrypto libtestutil.a
|
||||
+
|
||||
+ SOURCE[rsa_mp_test]=rsa_mp_test.c
|
||||
+ INCLUDE[rsa_mp_test]=../include ../apps/include
|
||||
+ DEPEND[rsa_mp_test]=../libcrypto.a libtestutil.a
|
||||
+
|
||||
SOURCE[fatalerrtest]=fatalerrtest.c ssltestlib.c
|
||||
INCLUDE[fatalerrtest]=../include ../apps/include
|
||||
DEPEND[fatalerrtest]=../libcrypto ../libssl libtestutil.a
|
||||
@@ -494,8 +503,8 @@ IF[{- !$disabled{tests} -}]
|
||||
IF[1]
|
||||
PROGRAMS{noinst}=asn1_internal_test modes_internal_test x509_internal_test \
|
||||
tls13encryptiontest wpackettest ctype_internal_test \
|
||||
- rdrand_sanitytest property_test ideatest rsa_mp_test \
|
||||
- rsa_sp800_56b_test bn_internal_test ecdsatest rsa_test \
|
||||
+ rdrand_sanitytest property_test ideatest \
|
||||
+ rsa_sp800_56b_test bn_internal_test ecdsatest \
|
||||
rc2test rc4test rc5test hmactest ffc_internal_test \
|
||||
asn1_dsa_internal_test dsatest dsa_no_digest_size_test \
|
||||
dhtest ssltest_old
|
||||
@@ -539,13 +548,6 @@ IF[{- !$disabled{tests} -}]
|
||||
INCLUDE[x509_internal_test]=.. ../include ../apps/include
|
||||
DEPEND[x509_internal_test]=../libcrypto.a libtestutil.a
|
||||
|
||||
- SOURCE[rsa_test]=rsa_test.c
|
||||
- INCLUDE[rsa_test]=../include ../apps/include
|
||||
- DEPEND[rsa_test]=../libcrypto.a libtestutil.a
|
||||
-
|
||||
- SOURCE[rsa_mp_test]=rsa_mp_test.c
|
||||
- INCLUDE[rsa_mp_test]=../include ../apps/include
|
||||
- DEPEND[rsa_mp_test]=../libcrypto.a libtestutil.a
|
||||
|
||||
SOURCE[ecdsatest]=ecdsatest.c
|
||||
INCLUDE[ecdsatest]=../include ../apps/include
|
||||
diff --git a/test/recipes/15-test_genrsa.t b/test/recipes/15-test_genrsa.t
|
||||
index 0ec0e65f18..d7d146a1d9 100644
|
||||
--- a/test/recipes/15-test_genrsa.t
|
||||
+++ b/test/recipes/15-test_genrsa.t
|
||||
@@ -16,18 +16,10 @@ use OpenSSL::Test::Utils;
|
||||
|
||||
setup("test_genrsa");
|
||||
|
||||
-plan tests => 9;
|
||||
+plan tests => 5;
|
||||
|
||||
# We want to know that an absurdly small number of bits isn't support
|
||||
-if (disabled("deprecated-3.0")) {
|
||||
- is(run(app([ 'openssl', 'genpkey', '-out', 'genrsatest.pem',
|
||||
- '-algorithm', 'RSA', '-pkeyopt', 'rsa_keygen_bits:8',
|
||||
- '-pkeyopt', 'rsa_keygen_pubexp:3'])),
|
||||
- 0, "genrsa -3 8");
|
||||
-} else {
|
||||
- is(run(app([ 'openssl', 'genrsa', '-3', '-out', 'genrsatest.pem', '8'])),
|
||||
- 0, "genrsa -3 8");
|
||||
-}
|
||||
+is(run(app([ 'openssl', 'genrsa', '-3', '-out', 'genrsatest.pem', '8'])), 0, "genrsa -3 8");
|
||||
|
||||
# Depending on the shared library, we might have different lower limits.
|
||||
# Let's find it! This is a simple binary search
|
||||
@@ -37,21 +29,10 @@ if (disabled("deprecated-3.0")) {
|
||||
note "Looking for lowest amount of bits";
|
||||
my $bad = 3; # Log2 of number of bits (2 << 3 == 8)
|
||||
my $good = 11; # Log2 of number of bits (2 << 11 == 2048)
|
||||
-my $fin;
|
||||
while ($good > $bad + 1) {
|
||||
my $checked = int(($good + $bad + 1) / 2);
|
||||
- my $bits = 2 ** $checked;
|
||||
- if (disabled("deprecated-3.0")) {
|
||||
- $fin = run(app([ 'openssl', 'genpkey', '-out', 'genrsatest.pem',
|
||||
- '-algorithm', 'RSA', '-pkeyopt', 'rsa_keygen_pubexp:3',
|
||||
- '-pkeyopt', "rsa_keygen_bits:$bits",
|
||||
- ], stderr => undef));
|
||||
- } else {
|
||||
- $fin = run(app([ 'openssl', 'genrsa', '-3', '-out', 'genrsatest.pem',
|
||||
- $bits
|
||||
- ], stderr => undef));
|
||||
- }
|
||||
- if ($fin) {
|
||||
+ if (run(app([ 'openssl', 'genrsa', '-3', '-out', 'genrsatest.pem',
|
||||
+ 2 ** $checked ], stderr => undef))) {
|
||||
note 2 ** $checked, " bits is good";
|
||||
$good = $checked;
|
||||
} else {
|
||||
@@ -63,30 +44,11 @@ $good++ if $good == $bad;
|
||||
$good = 2 ** $good;
|
||||
note "Found lowest allowed amount of bits to be $good";
|
||||
|
||||
-ok(run(app([ 'openssl', 'genpkey', '-algorithm', 'RSA',
|
||||
- '-pkeyopt', 'rsa_keygen_pubexp:3',
|
||||
- '-pkeyopt', "rsa_keygen_bits:$good",
|
||||
- '-out', 'genrsatest.pem' ])),
|
||||
- "genpkey -3 $good");
|
||||
-ok(run(app([ 'openssl', 'pkey', '-check', '-in', 'genrsatest.pem', '-noout' ])),
|
||||
- "pkey -check");
|
||||
-ok(run(app([ 'openssl', 'genpkey', '-algorithm', 'RSA',
|
||||
- '-pkeyopt', 'rsa_keygen_pubexp:65537',
|
||||
- '-pkeyopt', "rsa_keygen_bits:$good",
|
||||
- '-out', 'genrsatest.pem' ])),
|
||||
- "genpkey -f4 $good");
|
||||
-ok(run(app([ 'openssl', 'pkey', '-check', '-in', 'genrsatest.pem', '-noout' ])),
|
||||
- "pkey -check");
|
||||
-
|
||||
- SKIP: {
|
||||
- skip "Skipping rsa command line test", 4 if disabled("deprecated-3.0");
|
||||
-
|
||||
- ok(run(app([ 'openssl', 'genrsa', '-3', '-out', 'genrsatest.pem', $good ])),
|
||||
- "genrsa -3 $good");
|
||||
- ok(run(app([ 'openssl', 'rsa', '-check', '-in', 'genrsatest.pem', '-noout' ])),
|
||||
- "rsa -check");
|
||||
- ok(run(app([ 'openssl', 'genrsa', '-f4', '-out', 'genrsatest.pem', $good ])),
|
||||
- "genrsa -f4 $good");
|
||||
- ok(run(app([ 'openssl', 'rsa', '-check', '-in', 'genrsatest.pem', '-noout' ])),
|
||||
- "rsa -check");
|
||||
-}
|
||||
+ok(run(app([ 'openssl', 'genrsa', '-3', '-out', 'genrsatest.pem', $good ])),
|
||||
+ "genrsa -3 $good");
|
||||
+ok(run(app([ 'openssl', 'rsa', '-check', '-in', 'genrsatest.pem', '-noout' ])),
|
||||
+ "rsa -check");
|
||||
+ok(run(app([ 'openssl', 'genrsa', '-f4', '-out', 'genrsatest.pem', $good ])),
|
||||
+ "genrsa -f4 $good");
|
||||
+ok(run(app([ 'openssl', 'rsa', '-check', '-in', 'genrsatest.pem', '-noout' ])),
|
||||
+ "rsa -check");
|
||||
diff --git a/test/recipes/15-test_mp_rsa.t b/test/recipes/15-test_mp_rsa.t
|
||||
index 6ecf80c4e2..4a4ac3569d 100644
|
||||
--- a/test/recipes/15-test_mp_rsa.t
|
||||
+++ b/test/recipes/15-test_mp_rsa.t
|
||||
@@ -17,6 +17,12 @@ use OpenSSL::Test::Utils;
|
||||
|
||||
setup("test_mp_rsa");
|
||||
|
||||
+plan tests => 31;
|
||||
+
|
||||
+ok(run(test(["rsa_mp_test"])), "running rsa multi prime test");
|
||||
+
|
||||
+my $cleartext = data_file("plain_text");
|
||||
+
|
||||
my @test_param = (
|
||||
# 3 primes, 2048-bit
|
||||
{
|
||||
@@ -35,14 +41,8 @@ my @test_param = (
|
||||
},
|
||||
);
|
||||
|
||||
-plan tests => 1 + scalar(@test_param) * 5 * (disabled('deprecated-3.0') ? 1 : 2);
|
||||
-
|
||||
-ok(run(test(["rsa_mp_test"])), "running rsa multi prime test");
|
||||
-
|
||||
-my $cleartext = data_file("plain_text");
|
||||
-
|
||||
# genrsa
|
||||
-run_mp_tests(0) if !disabled('deprecated-3.0');
|
||||
+run_mp_tests(0);
|
||||
# evp
|
||||
run_mp_tests(1);
|
||||
|
||||
@@ -60,9 +60,17 @@ sub run_mp_tests {
|
||||
'-pkeyopt', "rsa_keygen_primes:$primes",
|
||||
'-pkeyopt', "rsa_keygen_bits:$bits"])),
|
||||
"genrsa $name");
|
||||
- ok(run(app([ 'openssl', 'pkey', '-check',
|
||||
- '-in', "rsamptest-$name.pem", '-noout'])),
|
||||
- "rsa -check $name");
|
||||
+ } else {
|
||||
+ ok(run(app([ 'openssl', 'genrsa', '-out', "rsamptest-$name.pem",
|
||||
+ '-primes', $primes, $bits])),
|
||||
+ "genrsa $name");
|
||||
+ }
|
||||
+
|
||||
+ ok(run(app([ 'openssl', 'rsa', '-check', '-in', "rsamptest-$name.pem",
|
||||
+ '-noout'])),
|
||||
+ "rsa -check $name");
|
||||
+
|
||||
+ if ($evp) {
|
||||
ok(run(app([ 'openssl', 'pkeyutl', '-inkey', "rsamptest-$name.pem",
|
||||
'-encrypt', '-in', $cleartext,
|
||||
'-out', "rsamptest-$name.enc" ])),
|
||||
@@ -72,11 +80,6 @@ sub run_mp_tests {
|
||||
'-out', "rsamptest-$name.dec" ])),
|
||||
"rsa $name decrypt");
|
||||
} else {
|
||||
- ok(run(app([ 'openssl', 'genrsa', '-out', "rsamptest-$name.pem",
|
||||
- '-primes', $primes, $bits])), "genrsa $name");
|
||||
- ok(run(app([ 'openssl', 'rsa', '-check',
|
||||
- '-in', "rsamptest-$name.pem", '-noout'])),
|
||||
- "rsa -check $name");
|
||||
ok(run(app([ 'openssl', 'rsautl', '-inkey', "rsamptest-$name.pem",
|
||||
'-encrypt', '-in', $cleartext,
|
||||
'-out', "rsamptest-$name.enc" ])),
|
||||
@@ -86,6 +89,7 @@ sub run_mp_tests {
|
||||
'-out', "rsamptest-$name.dec" ])),
|
||||
"rsa $name decrypt");
|
||||
}
|
||||
+
|
||||
ok(check_msg("rsamptest-$name.dec"), "rsa $name check result");
|
||||
}
|
||||
}
|
||||
diff --git a/test/recipes/15-test_rsa.t b/test/recipes/15-test_rsa.t
|
||||
index 2e8afa8213..3b1a0fcd5d 100644
|
||||
--- a/test/recipes/15-test_rsa.t
|
||||
+++ b/test/recipes/15-test_rsa.t
|
||||
@@ -16,48 +16,32 @@ use OpenSSL::Test::Utils;
|
||||
|
||||
setup("test_rsa");
|
||||
|
||||
-#plan skip_all => "RSA command line tool not built"
|
||||
-# if disabled("deprecated-3.0");
|
||||
+plan tests => 6;
|
||||
|
||||
-plan tests => 10;
|
||||
-
|
||||
-require_ok(srctop_file('test', 'recipes', 'tconversion.pl'));
|
||||
+require_ok(srctop_file('test','recipes','tconversion.pl'));
|
||||
|
||||
ok(run(test(["rsa_test"])), "running rsatest");
|
||||
|
||||
-run_rsa_tests("pkey");
|
||||
+ok(run(app([ 'openssl', 'rsa', '-check', '-in', srctop_file('test', 'testrsa.pem'), '-noout'])), "rsa -check");
|
||||
|
||||
SKIP: {
|
||||
- skip "Skipping rsa command line tests", 4 if disabled('deprecated-3.0');
|
||||
-
|
||||
- run_rsa_tests("rsa");
|
||||
+ skip "Skipping rsa conversion test", 3
|
||||
+ if disabled("rsa");
|
||||
+
|
||||
+ subtest 'rsa conversions -- private key' => sub {
|
||||
+ tconversion("rsa", srctop_file("test","testrsa.pem"));
|
||||
+ };
|
||||
+ subtest 'rsa conversions -- private key PKCS#8' => sub {
|
||||
+ tconversion("rsa", srctop_file("test","testrsa.pem"), "pkey");
|
||||
+ };
|
||||
}
|
||||
|
||||
-sub run_rsa_tests {
|
||||
- my $cmd = shift;
|
||||
-
|
||||
- ok(run(app([ 'openssl', $cmd, '-check', '-in', srctop_file('test', 'testrsa.pem'), '-noout'])),
|
||||
- "$cmd -check" );
|
||||
-
|
||||
- SKIP: {
|
||||
- skip "Skipping $cmd conversion test", 3
|
||||
- if disabled("rsa");
|
||||
-
|
||||
- subtest "$cmd conversions -- private key" => sub {
|
||||
- tconversion($cmd, srctop_file("test", "testrsa.pem"));
|
||||
- };
|
||||
- subtest "$cmd conversions -- private key PKCS#8" => sub {
|
||||
- tconversion($cmd, srctop_file("test", "testrsa.pem"), "pkey");
|
||||
- };
|
||||
- }
|
||||
-
|
||||
- SKIP: {
|
||||
- skip "Skipping msblob conversion test", 1
|
||||
- if disabled($cmd) || disabled("dsa") || $cmd == 'pkey';
|
||||
-
|
||||
- subtest "$cmd conversions -- public key" => sub {
|
||||
- tconversion("msb", srctop_file("test", "testrsapub.pem"), "rsa",
|
||||
- "-pubin", "-pubout");
|
||||
- };
|
||||
- }
|
||||
+ SKIP: {
|
||||
+ skip "Skipping msblob conversion test", 1
|
||||
+ if disabled("rsa") || disabled("dsa");
|
||||
+
|
||||
+ subtest 'rsa conversions -- public key' => sub {
|
||||
+ tconversion("msb", srctop_file("test","testrsapub.pem"), "rsa",
|
||||
+ "-pubin", "-pubout");
|
||||
+ };
|
||||
}
|
||||
diff --git a/test/rsa_mp_test.c b/test/rsa_mp_test.c
|
||||
index 53e2966997..baa9dd2272 100644
|
||||
--- a/test/rsa_mp_test.c
|
||||
+++ b/test/rsa_mp_test.c
|
||||
@@ -10,12 +10,6 @@
|
||||
|
||||
/* This aims to test the setting functions, including internal ones */
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
|
||||
diff --git a/test/rsa_test.c b/test/rsa_test.c
|
||||
index 1fbfe821cb..084f533ac1 100644
|
||||
--- a/test/rsa_test.c
|
||||
+++ b/test/rsa_test.c
|
||||
@@ -9,12 +9,6 @@
|
||||
|
||||
/* test vectors from p1ovect1.txt */
|
||||
|
||||
-/*
|
||||
- * RSA low level APIs are deprecated for public use, but still ok for
|
||||
- * internal use.
|
||||
- */
|
||||
-#include "internal/deprecated.h"
|
||||
-
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
|
||||
diff --git a/test/tls13secretstest.c b/test/tls13secretstest.c
|
||||
index c6f65eaded..def78b9920 100644
|
||||
--- a/test/tls13secretstest.c
|
||||
+++ b/test/tls13secretstest.c
|
||||
@@ -165,16 +165,9 @@ void RECORD_LAYER_reset_write_sequence(RECORD_LAYER *rl)
|
||||
{
|
||||
}
|
||||
|
||||
-int ssl_cipher_get_evp_cipher(SSL_CTX *ctx, const SSL_CIPHER *sslc,
|
||||
- const EVP_CIPHER **enc)
|
||||
-{
|
||||
- return 0;
|
||||
-}
|
||||
-
|
||||
-int ssl_cipher_get_evp(SSL_CTX *ctx, const SSL_SESSION *s,
|
||||
- const EVP_CIPHER **enc, const EVP_MD **md,
|
||||
- int *mac_pkey_type, size_t *mac_secret_size,
|
||||
- SSL_COMP **comp, int use_etm)
|
||||
+int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
+ const EVP_MD **md, int *mac_pkey_type,
|
||||
+ size_t *mac_secret_size, SSL_COMP **comp, int use_etm)
|
||||
|
||||
{
|
||||
return 0;
|
||||
@@ -193,7 +186,7 @@ int ssl_log_secret(SSL *ssl,
|
||||
return 1;
|
||||
}
|
||||
|
||||
-const EVP_MD *ssl_md(SSL_CTX *ctx, int idx)
|
||||
+const EVP_MD *ssl_md(int idx)
|
||||
{
|
||||
return EVP_sha256();
|
||||
}
|
||||
@@ -213,14 +206,6 @@ int ossl_statem_export_early_allowed(SSL *s)
|
||||
return 1;
|
||||
}
|
||||
|
||||
-void ssl_evp_cipher_free(const EVP_CIPHER *cipher)
|
||||
-{
|
||||
-}
|
||||
-
|
||||
-void ssl_evp_md_free(const EVP_MD *md)
|
||||
-{
|
||||
-}
|
||||
-
|
||||
/* End of mocked out code */
|
||||
|
||||
static int test_secret(SSL *s, unsigned char *prk,
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index 12761e4adc..f81fefb9b2 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -205,7 +205,7 @@ d2i_CRL_DIST_POINTS 208 3_0_0 EXIST::FUNCTION:
|
||||
X509_CRL_INFO_free 209 3_0_0 EXIST::FUNCTION:
|
||||
ERR_load_UI_strings 210 3_0_0 EXIST::FUNCTION:
|
||||
ERR_load_strings 211 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_X931_hash_id 212 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_X931_hash_id 212 3_0_0 EXIST::FUNCTION:RSA
|
||||
EC_KEY_set_method 213 3_0_0 EXIST::FUNCTION:EC
|
||||
PEM_write_PKCS8_PRIV_KEY_INFO 214 3_0_0 EXIST::FUNCTION:STDIO
|
||||
X509at_get0_data_by_OBJ 215 3_0_0 EXIST::FUNCTION:
|
||||
@@ -241,7 +241,7 @@ MDC2 245 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3
|
||||
BN_clear_free 246 3_0_0 EXIST::FUNCTION:
|
||||
ENGINE_get_pkey_asn1_meths 247 3_0_0 EXIST::FUNCTION:ENGINE
|
||||
DSO_merge 248 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_get_ex_data 249 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_get_ex_data 249 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_PKEY_meth_get_decrypt 250 3_0_0 EXIST::FUNCTION:
|
||||
DES_cfb_encrypt 251 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES
|
||||
CMS_SignerInfo_set1_signer_cert 252 3_0_0 EXIST::FUNCTION:CMS
|
||||
@@ -275,7 +275,7 @@ d2i_PKCS7_ENC_CONTENT 280 3_0_0 EXIST::FUNCTION:
|
||||
BUF_MEM_grow 281 3_0_0 EXIST::FUNCTION:
|
||||
TS_REQ_free 282 3_0_0 EXIST::FUNCTION:TS
|
||||
PEM_read_DHparams 283 3_0_0 EXIST::FUNCTION:DH,STDIO
|
||||
-RSA_private_decrypt 284 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_private_decrypt 284 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509V3_EXT_get_nid 285 3_0_0 EXIST::FUNCTION:
|
||||
BIO_s_log 286 3_0_0 EXIST::FUNCTION:
|
||||
EC_POINT_set_to_infinity 287 3_0_0 EXIST::FUNCTION:EC
|
||||
@@ -345,7 +345,7 @@ RC4 350 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3
|
||||
PKCS7_stream 352 3_0_0 EXIST::FUNCTION:
|
||||
i2t_ASN1_OBJECT 353 3_0_0 EXIST::FUNCTION:
|
||||
EC_GROUP_get0_generator 354 3_0_0 EXIST::FUNCTION:EC
|
||||
-RSA_padding_add_PKCS1_PSS_mgf1 355 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_PKCS1_PSS_mgf1 355 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_MD_meth_set_init 356 3_0_0 EXIST::FUNCTION:
|
||||
X509_get_issuer_name 357 3_0_0 EXIST::FUNCTION:
|
||||
EVP_SignFinal 358 3_0_0 EXIST::FUNCTION:
|
||||
@@ -367,7 +367,7 @@ BIO_new_mem_buf 373 3_0_0 EXIST::FUNCTION:
|
||||
UI_get_input_flags 374 3_0_0 EXIST::FUNCTION:
|
||||
X509V3_EXT_REQ_add_nconf 375 3_0_0 EXIST::FUNCTION:
|
||||
X509v3_asid_subset 376 3_0_0 EXIST::FUNCTION:RFC3779
|
||||
-RSA_check_key_ex 377 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_check_key_ex 377 3_0_0 EXIST::FUNCTION:RSA
|
||||
d2i_TS_MSG_IMPRINT_bio 378 3_0_0 EXIST::FUNCTION:TS
|
||||
i2d_ASN1_TYPE 379 3_0_0 EXIST::FUNCTION:
|
||||
EVP_aes_256_wrap_pad 380 3_0_0 EXIST::FUNCTION:
|
||||
@@ -440,7 +440,7 @@ X509_get_default_private_dir 447 3_0_0 EXIST::FUNCTION:
|
||||
X509_STORE_CTX_set0_dane 448 3_0_0 EXIST::FUNCTION:
|
||||
EVP_des_ecb 449 3_0_0 EXIST::FUNCTION:DES
|
||||
OCSP_resp_get0 450 3_0_0 EXIST::FUNCTION:OCSP
|
||||
-RSA_X931_generate_key_ex 452 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_X931_generate_key_ex 452 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509_get_serialNumber 453 3_0_0 EXIST::FUNCTION:
|
||||
BIO_sock_should_retry 454 3_0_0 EXIST::FUNCTION:SOCK
|
||||
ENGINE_get_digests 455 3_0_0 EXIST::FUNCTION:ENGINE
|
||||
@@ -533,7 +533,7 @@ CONF_get_number 544 3_0_0 EXIST::FUNCTION:
|
||||
X509_EXTENSION_get_object 545 3_0_0 EXIST::FUNCTION:
|
||||
X509_EXTENSIONS_it 546 3_0_0 EXIST::FUNCTION:
|
||||
EC_POINT_set_compressed_coordinates_GF2m 547 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M
|
||||
-RSA_sign_ASN1_OCTET_STRING 548 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_sign_ASN1_OCTET_STRING 548 3_0_0 EXIST::FUNCTION:RSA
|
||||
d2i_X509_CRL_fp 549 3_0_0 EXIST::FUNCTION:STDIO
|
||||
i2d_RSA_PUBKEY 550 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_aes_128_ccm 551 3_0_0 EXIST::FUNCTION:
|
||||
@@ -553,7 +553,7 @@ X509_EXTENSION_free 564 3_0_0 EXIST::FUNCTION:
|
||||
EVP_DigestSignInit 565 3_0_0 EXIST::FUNCTION:
|
||||
CT_POLICY_EVAL_CTX_get0_issuer 566 3_0_0 EXIST::FUNCTION:CT
|
||||
TLS_FEATURE_new 567 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_get_default_method 568 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_get_default_method 568 3_0_0 EXIST::FUNCTION:RSA
|
||||
CRYPTO_cts128_encrypt_block 569 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_digest 570 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0
|
||||
ERR_load_X509V3_strings 571 3_0_0 EXIST::FUNCTION:
|
||||
@@ -726,7 +726,7 @@ BN_set_params 744 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_0
|
||||
BN_add 745 3_0_0 EXIST::FUNCTION:
|
||||
OPENSSL_sk_free 746 3_0_0 EXIST::FUNCTION:
|
||||
TS_TST_INFO_get_ext_d2i 747 3_0_0 EXIST::FUNCTION:TS
|
||||
-RSA_check_key 748 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_check_key 748 3_0_0 EXIST::FUNCTION:RSA
|
||||
TS_MSG_IMPRINT_set_algo 749 3_0_0 EXIST::FUNCTION:TS
|
||||
BN_nist_mod_521 750 3_0_0 EXIST::FUNCTION:
|
||||
CRYPTO_THREAD_get_local 751 3_0_0 EXIST::FUNCTION:
|
||||
@@ -838,18 +838,18 @@ X509_STORE_free 858 3_0_0 EXIST::FUNCTION:
|
||||
ECDSA_sign_ex 859 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC
|
||||
TXT_DB_insert 860 3_0_0 EXIST::FUNCTION:
|
||||
EC_POINTs_make_affine 861 3_0_0 EXIST::FUNCTION:EC
|
||||
-RSA_padding_add_PKCS1_PSS 862 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_PKCS1_PSS 862 3_0_0 EXIST::FUNCTION:RSA
|
||||
BF_options 863 3_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0
|
||||
OCSP_BASICRESP_it 864 3_0_0 EXIST::FUNCTION:OCSP
|
||||
X509_VERIFY_PARAM_get0_name 865 3_0_0 EXIST::FUNCTION:
|
||||
TS_RESP_CTX_set_signer_digest 866 3_0_0 EXIST::FUNCTION:TS
|
||||
X509_VERIFY_PARAM_set1_email 867 3_0_0 EXIST::FUNCTION:
|
||||
BIO_sock_error 868 3_0_0 EXIST::FUNCTION:SOCK
|
||||
-RSA_set_default_method 869 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_set_default_method 869 3_0_0 EXIST::FUNCTION:RSA
|
||||
BN_GF2m_mod_sqrt_arr 870 3_0_0 EXIST::FUNCTION:EC2M
|
||||
X509_get0_extensions 871 3_0_0 EXIST::FUNCTION:
|
||||
TS_STATUS_INFO_set_status 872 3_0_0 EXIST::FUNCTION:TS
|
||||
-RSA_verify 873 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_verify 873 3_0_0 EXIST::FUNCTION:RSA
|
||||
ASN1_FBOOLEAN_it 874 3_0_0 EXIST::FUNCTION:
|
||||
d2i_ASN1_TIME 875 3_0_0 EXIST::FUNCTION:
|
||||
EVP_PKEY_meth_get_signctx 876 3_0_0 EXIST::FUNCTION:
|
||||
@@ -899,7 +899,7 @@ CONF_set_default_method 920 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_PCTX_get_nm_flags 921 3_0_0 EXIST::FUNCTION:
|
||||
X509_add1_ext_i2d 922 3_0_0 EXIST::FUNCTION:
|
||||
i2d_PKCS7_RECIP_INFO 924 3_0_0 EXIST::FUNCTION:
|
||||
-PKCS1_MGF1 925 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+PKCS1_MGF1 925 3_0_0 EXIST::FUNCTION:RSA
|
||||
BIO_vsnprintf 926 3_0_0 EXIST::FUNCTION:
|
||||
X509_STORE_CTX_get0_current_issuer 927 3_0_0 EXIST::FUNCTION:
|
||||
CRYPTO_secure_malloc_initialized 928 3_0_0 EXIST::FUNCTION:
|
||||
@@ -936,7 +936,7 @@ PKEY_USAGE_PERIOD_new 959 3_0_0 EXIST::FUNCTION:
|
||||
OBJ_NAME_init 960 3_0_0 EXIST::FUNCTION:
|
||||
EVP_PKEY_meth_set_keygen 961 3_0_0 EXIST::FUNCTION:
|
||||
RSA_PSS_PARAMS_new 962 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_sign 963 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_sign 963 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_DigestVerifyFinal 964 3_0_0 EXIST::FUNCTION:
|
||||
d2i_RSA_PUBKEY_bio 965 3_0_0 EXIST::FUNCTION:RSA
|
||||
TS_RESP_dup 966 3_0_0 EXIST::FUNCTION:TS
|
||||
@@ -1078,7 +1078,7 @@ PEM_read_bio_EC_PUBKEY 1104 3_0_0 EXIST::FUNCTION:EC
|
||||
BN_MONT_CTX_set 1105 3_0_0 EXIST::FUNCTION:
|
||||
TS_CONF_set_serial 1106 3_0_0 EXIST::FUNCTION:TS
|
||||
X509_NAME_ENTRY_new 1107 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_security_bits 1108 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_security_bits 1108 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509v3_addr_add_prefix 1109 3_0_0 EXIST::FUNCTION:RFC3779
|
||||
X509_REQ_print_fp 1110 3_0_0 EXIST::FUNCTION:STDIO
|
||||
ASN1_item_ex_new 1111 3_0_0 EXIST::FUNCTION:
|
||||
@@ -1089,7 +1089,7 @@ ASN1_TYPE_get 1115 3_0_0 EXIST::FUNCTION:
|
||||
i2d_X509_EXTENSIONS 1116 3_0_0 EXIST::FUNCTION:
|
||||
X509_STORE_CTX_get0_store 1117 3_0_0 EXIST::FUNCTION:
|
||||
PKCS12_pack_p7data 1118 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_print_fp 1119 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA,STDIO
|
||||
+RSA_print_fp 1119 3_0_0 EXIST::FUNCTION:RSA,STDIO
|
||||
OPENSSL_INIT_set_config_appname 1120 3_0_0 EXIST::FUNCTION:STDIO
|
||||
EC_KEY_print_fp 1121 3_0_0 EXIST::FUNCTION:EC,STDIO
|
||||
BIO_dup_chain 1122 3_0_0 EXIST::FUNCTION:
|
||||
@@ -1192,7 +1192,7 @@ OCSP_CERTSTATUS_it 1218 3_0_0 EXIST::FUNCTION:OCSP
|
||||
BIO_f_reliable 1219 3_0_0 EXIST::FUNCTION:
|
||||
OCSP_resp_count 1220 3_0_0 EXIST::FUNCTION:OCSP
|
||||
i2d_X509_AUX 1221 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_verify_PKCS1_PSS_mgf1 1222 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_verify_PKCS1_PSS_mgf1 1222 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509_time_adj 1223 3_0_0 EXIST::FUNCTION:
|
||||
EVP_PKEY_asn1_find_str 1224 3_0_0 EXIST::FUNCTION:
|
||||
X509_VERIFY_PARAM_get_flags 1225 3_0_0 EXIST::FUNCTION:
|
||||
@@ -1209,7 +1209,7 @@ X509_NAME_hash_old 1235 3_0_0 EXIST::FUNCTION:
|
||||
PBKDF2PARAM_free 1236 3_0_0 EXIST::FUNCTION:
|
||||
i2d_CMS_ContentInfo 1237 3_0_0 EXIST::FUNCTION:CMS
|
||||
EVP_CIPHER_meth_set_ctrl 1238 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_public_decrypt 1239 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_public_decrypt 1239 3_0_0 EXIST::FUNCTION:RSA
|
||||
ENGINE_get_id 1240 3_0_0 EXIST::FUNCTION:ENGINE
|
||||
PKCS12_item_decrypt_d2i 1241 3_0_0 EXIST::FUNCTION:
|
||||
PEM_read_bio_DSAparams 1242 3_0_0 EXIST::FUNCTION:DSA
|
||||
@@ -1299,7 +1299,7 @@ EVP_CIPHER_do_all 1327 3_0_0 EXIST::FUNCTION:
|
||||
POLICY_MAPPINGS_it 1328 3_0_0 EXIST::FUNCTION:
|
||||
SCT_set0_log_id 1329 3_0_0 EXIST::FUNCTION:CT
|
||||
CRYPTO_cfb128_encrypt 1330 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_add_PKCS1_type_2 1331 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_PKCS1_type_2 1331 3_0_0 EXIST::FUNCTION:RSA
|
||||
TS_CONF_set_signer_cert 1332 3_0_0 EXIST::FUNCTION:TS
|
||||
i2d_ASN1_OBJECT 1333 3_0_0 EXIST::FUNCTION:
|
||||
d2i_PKCS8_PRIV_KEY_INFO_bio 1334 3_0_0 EXIST::FUNCTION:
|
||||
@@ -1392,7 +1392,7 @@ EVP_PBE_get 1424 3_0_0 EXIST::FUNCTION:
|
||||
CRYPTO_nistcts128_encrypt 1425 3_0_0 EXIST::FUNCTION:
|
||||
CONF_modules_finish 1426 3_0_0 EXIST::FUNCTION:
|
||||
BN_value_one 1427 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_add_SSLv23 1428 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_SSLv23 1428 3_0_0 EXIST::FUNCTION:RSA
|
||||
OCSP_RESPBYTES_it 1429 3_0_0 EXIST::FUNCTION:OCSP
|
||||
EVP_aes_192_wrap 1430 3_0_0 EXIST::FUNCTION:
|
||||
OCSP_CERTID_it 1431 3_0_0 EXIST::FUNCTION:OCSP
|
||||
@@ -1559,7 +1559,7 @@ CTLOG_get0_name 1593 3_0_0 EXIST::FUNCTION:CT
|
||||
ASN1_TBOOLEAN_it 1594 3_0_0 EXIST::FUNCTION:
|
||||
RC2_set_key 1595 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2
|
||||
X509_REVOKED_get_ext_by_NID 1596 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_add_none 1597 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_none 1597 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_rc5_32_12_16_cbc 1599 3_0_0 EXIST::FUNCTION:RC5
|
||||
PEM_dek_info 1600 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_SCTX_get_template 1601 3_0_0 EXIST::FUNCTION:
|
||||
@@ -1613,7 +1613,7 @@ i2d_EDIPARTYNAME 1649 3_0_0 EXIST::FUNCTION:
|
||||
X509_policy_tree_get0_policies 1650 3_0_0 EXIST::FUNCTION:
|
||||
X509at_add1_attr 1651 3_0_0 EXIST::FUNCTION:
|
||||
X509_get_ex_data 1653 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_set_method 1654 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_set_method 1654 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509_REVOKED_dup 1655 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_TIME_new 1656 3_0_0 EXIST::FUNCTION:
|
||||
PEM_write_NETSCAPE_CERT_SEQUENCE 1657 3_0_0 EXIST::FUNCTION:STDIO
|
||||
@@ -1664,7 +1664,7 @@ ESS_SIGNING_CERT_dup 1701 3_0_0 EXIST::FUNCTION:
|
||||
ENGINE_set_default_DSA 1702 3_0_0 EXIST::FUNCTION:ENGINE
|
||||
X509_REVOKED_new 1703 3_0_0 EXIST::FUNCTION:
|
||||
NCONF_WIN32 1704 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0
|
||||
-RSA_padding_check_PKCS1_OAEP_mgf1 1705 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_check_PKCS1_OAEP_mgf1 1705 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509_policy_tree_get0_level 1706 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_parse_dump 1708 3_0_0 EXIST::FUNCTION:
|
||||
BIO_vfree 1709 3_0_0 EXIST::FUNCTION:
|
||||
@@ -1831,7 +1831,7 @@ OCSP_single_get0_status 1873 3_0_0 EXIST::FUNCTION:OCSP
|
||||
d2i_AUTHORITY_INFO_ACCESS 1874 3_0_0 EXIST::FUNCTION:
|
||||
PEM_read_RSAPrivateKey 1875 3_0_0 EXIST::FUNCTION:RSA,STDIO
|
||||
BIO_closesocket 1876 3_0_0 EXIST::FUNCTION:SOCK
|
||||
-RSA_verify_ASN1_OCTET_STRING 1877 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_verify_ASN1_OCTET_STRING 1877 3_0_0 EXIST::FUNCTION:RSA
|
||||
SCT_set_log_entry_type 1878 3_0_0 EXIST::FUNCTION:CT
|
||||
BN_new 1879 3_0_0 EXIST::FUNCTION:
|
||||
X509_OBJECT_retrieve_by_subject 1880 3_0_0 EXIST::FUNCTION:
|
||||
@@ -2070,7 +2070,7 @@ i2d_ASIdentifiers 2115 3_0_0 EXIST::FUNCTION:RFC3779
|
||||
X509V3_EXT_cleanup 2116 3_0_0 EXIST::FUNCTION:
|
||||
CAST_ecb_encrypt 2117 3_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0
|
||||
BIO_s_file 2118 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_X931_derive_ex 2119 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_X931_derive_ex 2119 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_PKEY_decrypt_init 2120 3_0_0 EXIST::FUNCTION:
|
||||
ENGINE_get_destroy_function 2121 3_0_0 EXIST::FUNCTION:ENGINE
|
||||
SHA224_Init 2122 3_0_0 EXIST::FUNCTION:
|
||||
@@ -2252,7 +2252,7 @@ ESS_ISSUER_SERIAL_free 2299 3_0_0 EXIST::FUNCTION:
|
||||
BN_mod_exp_mont_word 2300 3_0_0 EXIST::FUNCTION:
|
||||
X509V3_EXT_nconf_nid 2301 3_0_0 EXIST::FUNCTION:
|
||||
UTF8_putc 2302 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_private_encrypt 2303 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_private_encrypt 2303 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509_LOOKUP_shutdown 2304 3_0_0 EXIST::FUNCTION:
|
||||
TS_TST_INFO_set_accuracy 2305 3_0_0 EXIST::FUNCTION:TS
|
||||
OCSP_basic_verify 2306 3_0_0 EXIST::FUNCTION:OCSP
|
||||
@@ -2348,7 +2348,7 @@ X509_LOOKUP_by_alias 2396 3_0_0 EXIST::FUNCTION:
|
||||
EC_KEY_set_conv_form 2397 3_0_0 EXIST::FUNCTION:EC
|
||||
X509_TRUST_get_count 2399 3_0_0 EXIST::FUNCTION:
|
||||
IPAddressOrRange_free 2400 3_0_0 EXIST::FUNCTION:RFC3779
|
||||
-RSA_padding_add_PKCS1_OAEP 2401 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_PKCS1_OAEP 2401 3_0_0 EXIST::FUNCTION:RSA
|
||||
EC_KEY_set_ex_data 2402 3_0_0 EXIST::FUNCTION:EC
|
||||
SRP_VBASE_new 2403 3_0_0 EXIST::FUNCTION:SRP
|
||||
i2d_ECDSA_SIG 2404 3_0_0 EXIST::FUNCTION:EC
|
||||
@@ -2375,7 +2375,7 @@ ASN1_GENERALIZEDTIME_it 2425 3_0_0 EXIST::FUNCTION:
|
||||
PKCS8_pkey_get0 2426 3_0_0 EXIST::FUNCTION:
|
||||
OCSP_sendreq_new 2427 3_0_0 EXIST::FUNCTION:OCSP
|
||||
EVP_aes_256_cfb128 2428 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_set_ex_data 2429 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_set_ex_data 2429 3_0_0 EXIST::FUNCTION:RSA
|
||||
BN_GENCB_call 2430 3_0_0 EXIST::FUNCTION:
|
||||
X509V3_EXT_add_nconf_sk 2431 3_0_0 EXIST::FUNCTION:
|
||||
i2d_TS_MSG_IMPRINT_fp 2432 3_0_0 EXIST::FUNCTION:STDIO,TS
|
||||
@@ -2521,7 +2521,7 @@ EVP_CIPHER_meth_get_cleanup 2574 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_item_ex_d2i 2575 3_0_0 EXIST::FUNCTION:
|
||||
EVP_MD_meth_free 2576 3_0_0 EXIST::FUNCTION:
|
||||
EVP_PKEY_meth_new 2577 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_check_PKCS1_OAEP 2578 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_check_PKCS1_OAEP 2578 3_0_0 EXIST::FUNCTION:RSA
|
||||
OCSP_SERVICELOC_it 2579 3_0_0 EXIST::FUNCTION:OCSP
|
||||
PKCS12_SAFEBAG_get_nid 2580 3_0_0 EXIST::FUNCTION:
|
||||
EVP_MD_CTX_set_update_fn 2581 3_0_0 EXIST::FUNCTION:
|
||||
@@ -2586,7 +2586,7 @@ d2i_PBKDF2PARAM 2640 3_0_0 EXIST::FUNCTION:
|
||||
ERR_load_COMP_strings 2641 3_0_0 EXIST::FUNCTION:COMP
|
||||
EVP_PKEY_meth_add0 2642 3_0_0 EXIST::FUNCTION:
|
||||
EVP_rc4_40 2643 3_0_0 EXIST::FUNCTION:RC4
|
||||
-RSA_bits 2645 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_bits 2645 3_0_0 EXIST::FUNCTION:RSA
|
||||
ASN1_item_dup 2646 3_0_0 EXIST::FUNCTION:
|
||||
GENERAL_NAMES_it 2647 3_0_0 EXIST::FUNCTION:
|
||||
X509_issuer_name_hash 2648 3_0_0 EXIST::FUNCTION:
|
||||
@@ -2610,7 +2610,7 @@ X509_load_cert_file 2665 3_0_0 EXIST::FUNCTION:
|
||||
EC_GFp_nistp521_method 2667 3_0_0 EXIST::FUNCTION:EC,EC_NISTP_64_GCC_128
|
||||
ECDSA_SIG_free 2668 3_0_0 EXIST::FUNCTION:EC
|
||||
d2i_PKCS12_BAGS 2669 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_public_encrypt 2670 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_public_encrypt 2670 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509_CRL_get0_extensions 2671 3_0_0 EXIST::FUNCTION:
|
||||
CMS_digest_verify 2672 3_0_0 EXIST::FUNCTION:CMS
|
||||
ASN1_GENERALIZEDTIME_set 2673 3_0_0 EXIST::FUNCTION:
|
||||
@@ -2839,7 +2839,7 @@ ENGINE_get_last 2900 3_0_0 EXIST::FUNCTION:ENGINE
|
||||
EVP_PKEY_encrypt_init 2901 3_0_0 EXIST::FUNCTION:
|
||||
i2d_RSAPrivateKey_fp 2902 3_0_0 EXIST::FUNCTION:RSA,STDIO
|
||||
X509_REQ_print 2903 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_size 2904 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_size 2904 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_CIPHER_CTX_iv_noconst 2905 3_0_0 EXIST::FUNCTION:
|
||||
DH_set_default_method 2906 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
X509_ALGOR_new 2907 3_0_0 EXIST::FUNCTION:
|
||||
@@ -2933,7 +2933,7 @@ SHA384 2995 3_0_0 EXIST::FUNCTION:
|
||||
NCONF_get_string 2996 3_0_0 EXIST::FUNCTION:
|
||||
d2i_PROXY_CERT_INFO_EXTENSION 2997 3_0_0 EXIST::FUNCTION:
|
||||
EC_POINT_point2buf 2998 3_0_0 EXIST::FUNCTION:EC
|
||||
-RSA_padding_add_PKCS1_OAEP_mgf1 2999 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_PKCS1_OAEP_mgf1 2999 3_0_0 EXIST::FUNCTION:RSA
|
||||
COMP_CTX_get_type 3000 3_0_0 EXIST::FUNCTION:COMP
|
||||
TS_RESP_CTX_set_status_info 3001 3_0_0 EXIST::FUNCTION:TS
|
||||
BIO_f_nbio_test 3002 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3014,7 +3014,7 @@ ENGINE_load_private_key 3078 3_0_0 EXIST::FUNCTION:ENGINE
|
||||
GENERAL_NAMES_new 3079 3_0_0 EXIST::FUNCTION:
|
||||
i2d_POLICYQUALINFO 3080 3_0_0 EXIST::FUNCTION:
|
||||
EC_GF2m_simple_method 3081 3_0_0 EXIST::FUNCTION:EC,EC2M
|
||||
-RSA_get_method 3082 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_get_method 3082 3_0_0 EXIST::FUNCTION:RSA
|
||||
d2i_ASRange 3083 3_0_0 EXIST::FUNCTION:RFC3779
|
||||
CMS_ContentInfo_new 3084 3_0_0 EXIST::FUNCTION:CMS
|
||||
OPENSSL_init_crypto 3085 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3053,7 +3053,7 @@ i2d_RSA_PSS_PARAMS 3117 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_aes_128_wrap_pad 3118 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_BIT_STRING_set 3119 3_0_0 EXIST::FUNCTION:
|
||||
PKCS5_PBKDF2_HMAC_SHA1 3120 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_check_PKCS1_type_2 3121 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_check_PKCS1_type_2 3121 3_0_0 EXIST::FUNCTION:RSA
|
||||
EVP_des_ede3_ecb 3122 3_0_0 EXIST::FUNCTION:DES
|
||||
CBIGNUM_it 3123 3_0_0 EXIST::FUNCTION:
|
||||
BIO_new_NDEF 3124 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3124,7 +3124,7 @@ BN_mod_add 3189 3_0_0 EXIST::FUNCTION:
|
||||
EC_POINT_set_affine_coordinates_GFp 3190 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC
|
||||
X509_get_default_cert_file 3191 3_0_0 EXIST::FUNCTION:
|
||||
UI_method_set_flusher 3192 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_new_method 3193 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_new_method 3193 3_0_0 EXIST::FUNCTION:RSA
|
||||
OCSP_request_verify 3194 3_0_0 EXIST::FUNCTION:OCSP
|
||||
CRYPTO_THREAD_run_once 3195 3_0_0 EXIST::FUNCTION:
|
||||
TS_REQ_print_bio 3196 3_0_0 EXIST::FUNCTION:TS
|
||||
@@ -3211,7 +3211,7 @@ POLICY_CONSTRAINTS_free 3277 3_0_0 EXIST::FUNCTION:
|
||||
EVP_aes_256_cfb8 3278 3_0_0 EXIST::FUNCTION:
|
||||
d2i_DSA_PUBKEY_bio 3279 3_0_0 EXIST::FUNCTION:DSA
|
||||
X509_NAME_get_text_by_OBJ 3280 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_check_none 3281 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_check_none 3281 3_0_0 EXIST::FUNCTION:RSA
|
||||
CRYPTO_set_mem_debug 3282 3_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0
|
||||
TS_VERIFY_CTX_init 3283 3_0_0 EXIST::FUNCTION:TS
|
||||
OCSP_cert_id_new 3284 3_0_0 EXIST::FUNCTION:OCSP
|
||||
@@ -3265,7 +3265,7 @@ X509_PKEY_free 3332 3_0_0 EXIST::FUNCTION:
|
||||
OCSP_CRLID_new 3333 3_0_0 EXIST::FUNCTION:OCSP
|
||||
CONF_dump_bio 3334 3_0_0 EXIST::FUNCTION:
|
||||
d2i_PKCS8PrivateKey_fp 3335 3_0_0 EXIST::FUNCTION:STDIO
|
||||
-RSA_setup_blinding 3336 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_setup_blinding 3336 3_0_0 EXIST::FUNCTION:RSA
|
||||
ERR_peek_error_line 3337 3_0_0 EXIST::FUNCTION:
|
||||
d2i_PKCS7 3338 3_0_0 EXIST::FUNCTION:
|
||||
ERR_reason_error_string 3339 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3286,7 +3286,7 @@ OPENSSL_sk_is_sorted 3353 3_0_0 EXIST::FUNCTION:
|
||||
OCSP_SIGNATURE_new 3354 3_0_0 EXIST::FUNCTION:OCSP
|
||||
EVP_PKEY_meth_get_paramgen 3355 3_0_0 EXIST::FUNCTION:
|
||||
X509_ATTRIBUTE_create_by_OBJ 3356 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_generate_key_ex 3357 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_generate_key_ex 3357 3_0_0 EXIST::FUNCTION:RSA
|
||||
CMS_SignerInfo_get0_algs 3358 3_0_0 EXIST::FUNCTION:CMS
|
||||
DIST_POINT_free 3359 3_0_0 EXIST::FUNCTION:
|
||||
ESS_SIGNING_CERT_free 3360 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3302,7 +3302,7 @@ PKCS7_ENVELOPE_new 3369 3_0_0 EXIST::FUNCTION:
|
||||
EDIPARTYNAME_new 3370 3_0_0 EXIST::FUNCTION:
|
||||
CMS_add1_cert 3371 3_0_0 EXIST::FUNCTION:CMS
|
||||
DSO_convert_filename 3372 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_check_SSLv23 3373 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_check_SSLv23 3373 3_0_0 EXIST::FUNCTION:RSA
|
||||
CRYPTO_gcm128_finish 3374 3_0_0 EXIST::FUNCTION:
|
||||
PKCS12_SAFEBAGS_it 3375 3_0_0 EXIST::FUNCTION:
|
||||
PKCS12_PBE_add 3376 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3393,7 +3393,7 @@ BIO_number_written 3463 3_0_0 EXIST::FUNCTION:
|
||||
TS_TST_INFO_set_msg_imprint 3464 3_0_0 EXIST::FUNCTION:TS
|
||||
CRYPTO_get_ex_data 3465 3_0_0 EXIST::FUNCTION:
|
||||
X509_PURPOSE_get0_sname 3466 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_verify_PKCS1_PSS 3467 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_verify_PKCS1_PSS 3467 3_0_0 EXIST::FUNCTION:RSA
|
||||
HMAC_CTX_reset 3468 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0
|
||||
EVP_PKEY_meth_set_init 3469 3_0_0 EXIST::FUNCTION:
|
||||
X509_REQ_extension_nid 3470 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3558,7 +3558,7 @@ SHA384_Update 3635 3_0_0 EXIST::FUNCTION:
|
||||
CRYPTO_cfb128_1_encrypt 3636 3_0_0 EXIST::FUNCTION:
|
||||
BIO_set_cipher 3637 3_0_0 EXIST::FUNCTION:
|
||||
PEM_read_PUBKEY 3638 3_0_0 EXIST::FUNCTION:STDIO
|
||||
-RSA_PKCS1_OpenSSL 3639 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_PKCS1_OpenSSL 3639 3_0_0 EXIST::FUNCTION:RSA
|
||||
AUTHORITY_INFO_ACCESS_free 3640 3_0_0 EXIST::FUNCTION:
|
||||
SCT_get0_signature 3641 3_0_0 EXIST::FUNCTION:CT
|
||||
DISPLAYTEXT_it 3643 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3569,7 +3569,7 @@ X509_REQ_set_extension_nids 3647 3_0_0 EXIST::FUNCTION:
|
||||
X509_free 3648 3_0_0 EXIST::FUNCTION:
|
||||
ERR_load_ERR_strings 3649 3_0_0 EXIST::FUNCTION:
|
||||
ASN1_const_check_infinite_end 3650 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_null_method 3651 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_null_method 3651 3_0_0 EXIST::FUNCTION:RSA
|
||||
TS_REQ_ext_free 3652 3_0_0 EXIST::FUNCTION:TS
|
||||
EVP_PKEY_meth_get_encrypt 3653 3_0_0 EXIST::FUNCTION:
|
||||
Camellia_ecb_encrypt 3654 3_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0
|
||||
@@ -3604,7 +3604,7 @@ BIO_ADDR_free 3683 3_0_0 EXIST::FUNCTION:SOCK
|
||||
ASN1_STRING_free 3684 3_0_0 EXIST::FUNCTION:
|
||||
X509_VERIFY_PARAM_inherit 3685 3_0_0 EXIST::FUNCTION:
|
||||
EC_GROUP_get_curve_name 3686 3_0_0 EXIST::FUNCTION:EC
|
||||
-RSA_print 3687 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_print 3687 3_0_0 EXIST::FUNCTION:RSA
|
||||
i2d_ASN1_BMPSTRING 3688 3_0_0 EXIST::FUNCTION:
|
||||
EVP_PKEY_decrypt_old 3689 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0
|
||||
ASN1_UTCTIME_cmp_time_t 3690 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3678,7 +3678,7 @@ BIO_set_callback 3757 3_0_0 EXIST::FUNCTION:
|
||||
BN_GF2m_poly2arr 3758 3_0_0 EXIST::FUNCTION:EC2M
|
||||
CMS_unsigned_get_attr_count 3759 3_0_0 EXIST::FUNCTION:CMS
|
||||
EVP_aes_256_gcm 3760 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_check_X931 3761 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_check_X931 3761 3_0_0 EXIST::FUNCTION:RSA
|
||||
ECDH_compute_key 3762 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC
|
||||
ASN1_TIME_print 3763 3_0_0 EXIST::FUNCTION:
|
||||
EVP_PKEY_CTX_get0_peerkey 3764 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3759,7 +3759,7 @@ i2d_ASN1_INTEGER 3840 3_0_0 EXIST::FUNCTION:
|
||||
OCSP_SINGLERESP_add1_ext_i2d 3841 3_0_0 EXIST::FUNCTION:OCSP
|
||||
PKCS7_add_signed_attribute 3842 3_0_0 EXIST::FUNCTION:
|
||||
i2d_PrivateKey_bio 3843 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_add_PKCS1_type_1 3844 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_PKCS1_type_1 3844 3_0_0 EXIST::FUNCTION:RSA
|
||||
i2d_re_X509_tbs 3845 3_0_0 EXIST::FUNCTION:
|
||||
EVP_CIPHER_iv_length 3846 3_0_0 EXIST::FUNCTION:
|
||||
OCSP_REQ_CTX_get0_mem_bio 3847 3_0_0 EXIST::FUNCTION:
|
||||
@@ -3908,44 +3908,44 @@ X509_VERIFY_PARAM_set_auth_level 3991 3_0_0 EXIST::FUNCTION:
|
||||
X509_VERIFY_PARAM_get_auth_level 3992 3_0_0 EXIST::FUNCTION:
|
||||
X509_REQ_get0_pubkey 3993 3_0_0 EXIST::FUNCTION:
|
||||
RSA_set0_key 3994 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_meth_get_flags 3995 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_finish 3996 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_priv_dec 3997 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_sign 3998 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_bn_mod_exp 3999 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_meth_get_flags 3995 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_finish 3996 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_priv_dec 3997 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_sign 3998 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_bn_mod_exp 3999 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_test_flags 4000 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_meth_new 4001 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get0_app_data 4002 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_dup 4003 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set1_name 4004 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set0_app_data 4005 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_meth_new 4001 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get0_app_data 4002 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_dup 4003 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set1_name 4004 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set0_app_data 4005 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_set_flags 4006 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_meth_set_sign 4007 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_meth_set_sign 4007 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_clear_flags 4008 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_meth_get_keygen 4009 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_keygen 4010 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_pub_dec 4011 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_finish 4012 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_meth_get_keygen 4009 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_keygen 4010 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_pub_dec 4011 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_finish 4012 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_get0_key 4013 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_get0_engine 4014 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_priv_enc 4015 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_verify 4016 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_get0_engine 4014 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_priv_enc 4015 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_verify 4016 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_get0_factors 4017 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_meth_get0_name 4018 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_mod_exp 4019 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_flags 4020 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_pub_dec 4021 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_bn_mod_exp 4022 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_init 4023 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_free 4024 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_pub_enc 4025 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_mod_exp 4026 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_meth_get0_name 4018 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_mod_exp 4019 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_flags 4020 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_pub_dec 4021 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_bn_mod_exp 4022 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_init 4023 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_free 4024 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_pub_enc 4025 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_mod_exp 4026 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_set0_factors 4027 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_meth_set_pub_enc 4028 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_priv_dec 4029 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_verify 4030 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_init 4031 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_priv_enc 4032 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_meth_set_pub_enc 4028 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_priv_dec 4029 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_verify 4030 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_init 4031 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_priv_enc 4032 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_set0_crt_params 4037 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_get0_crt_params 4038 3_0_0 EXIST::FUNCTION:RSA
|
||||
DH_set0_pqg 4039 3_0_0 EXIST::FUNCTION:DH
|
||||
@@ -4899,7 +4899,7 @@ d2i_X509_PUBKEY_fp ? 3_0_0 EXIST::FUNCTION:STDIO
|
||||
i2d_X509_PUBKEY_fp ? 3_0_0 EXIST::FUNCTION:STDIO
|
||||
d2i_X509_PUBKEY_bio ? 3_0_0 EXIST::FUNCTION:
|
||||
i2d_X509_PUBKEY_bio ? 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_get0_pss_params ? 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_get0_pss_params ? 3_0_0 EXIST::FUNCTION:RSA
|
||||
X509_cmp_timeframe ? 3_0_0 EXIST::FUNCTION:
|
||||
OSSL_CMP_MSG_get0_header ? 3_0_0 EXIST::FUNCTION:CMP
|
||||
BIO_f_prefix ? 3_0_0 EXIST::FUNCTION:
|
||||
@@ -0,0 +1,29 @@
|
||||
diff --git a/ssl/ssl_sess.c b/ssl/ssl_sess.c
|
||||
index d04b4fab77..d240f3595c 100644
|
||||
--- a/ssl/ssl_sess.c
|
||||
+++ b/ssl/ssl_sess.c
|
||||
@@ -403,7 +403,10 @@ int ssl_get_new_session(SSL *s, int session)
|
||||
if (s->session_ctx->session_timeout == 0)
|
||||
ss->timeout = SSL_get_default_timeout(s);
|
||||
else
|
||||
- ss->timeout = s->session_ctx->session_timeout;
|
||||
+ if (SSL_IS_TLS13(s))
|
||||
+ ss->timeout = (60 * 60 * 24 * 2); /* 172800 = 2 days */
|
||||
+ else
|
||||
+ ss->timeout = s->session_ctx->session_timeout;
|
||||
|
||||
SSL_SESSION_free(s->session);
|
||||
s->session = NULL;
|
||||
@@ -1019,8 +1022,11 @@ long SSL_CTX_set_timeout(SSL_CTX *s, long t)
|
||||
long l;
|
||||
if (s == NULL)
|
||||
return 0;
|
||||
+ if (SSL_IS_TLS13(s))
|
||||
+ s->session_timeout = 60 * 60 * 24 * 2; /* 172800 */
|
||||
+ else
|
||||
+ s->session_timeout = t;
|
||||
l = s->session_timeout;
|
||||
- s->session_timeout = t;
|
||||
return l;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,1075 @@
|
||||
diff --git a/doc/man1/ciphers.pod b/doc/man1/ciphers.pod
|
||||
index faf9e53814..428df515f1 100644
|
||||
--- a/doc/man1/ciphers.pod
|
||||
+++ b/doc/man1/ciphers.pod
|
||||
@@ -400,6 +400,21 @@ permissible.
|
||||
|
||||
=back
|
||||
|
||||
+=head1 EQUAL PREFERENCE GROUPS
|
||||
+
|
||||
+If configuring a server, one may also configure equal-preference groups to
|
||||
+partially respect the client's preferences when
|
||||
+B<SSL_OP_CIPHER_SERVER_PREFERENCE> is enabled. Ciphers in an equal-preference
|
||||
+group have equal priority and use the client order. This may be used to
|
||||
+enforce that AEADs are preferred but select AES-GCM vs. ChaCha20-Poly1305
|
||||
+based on client preferences. An equal-preference is specified with square
|
||||
+brackets, combining multiple selectors separated by |. For example:
|
||||
+
|
||||
+ [ECDHE-ECDSA-CHACHA20-POLY1305|ECDHE-ECDSA-AES128-GCM-SHA256]
|
||||
+
|
||||
+ Once an equal-preference group is used, future directives must be
|
||||
+ opcode-less.
|
||||
+
|
||||
=head1 CIPHER SUITE NAMES
|
||||
|
||||
The following lists give the SSL or TLS cipher suites names from the
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 6724ccf2d2..81a5538977 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -173,12 +173,12 @@ extern "C" {
|
||||
# define SSL_DEFAULT_CIPHER_LIST "ALL:!COMPLEMENTOFDEFAULT:!eNULL"
|
||||
/* This is the default set of TLSv1.3 ciphersuites */
|
||||
# if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305)
|
||||
-# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_256_GCM_SHA384:" \
|
||||
+# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_128_GCM_SHA256:" \
|
||||
"TLS_CHACHA20_POLY1305_SHA256:" \
|
||||
- "TLS_AES_128_GCM_SHA256"
|
||||
+ "TLS_AES_256_GCM_SHA384"
|
||||
# else
|
||||
-# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_256_GCM_SHA384:" \
|
||||
- "TLS_AES_128_GCM_SHA256"
|
||||
+# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_128_GCM_SHA256:" \
|
||||
+ "TLS_AES_256_GCM_SHA384"
|
||||
#endif
|
||||
/*
|
||||
* As of OpenSSL 1.0.0, ssl_create_cipher_list() in ssl/ssl_ciph.c always
|
||||
diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h
|
||||
index 3d6850dea3..a3ab4b925f 100644
|
||||
--- a/include/openssl/sslerr.h
|
||||
+++ b/include/openssl/sslerr.h
|
||||
@@ -600,6 +600,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_SUPPORTED_GROUPS_EXTENSION 209
|
||||
# define SSL_R_MISSING_TMP_DH_KEY 171
|
||||
# define SSL_R_MISSING_TMP_ECDH_KEY 311
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 101
|
||||
+# define SSL_R_NESTED_GROUP 108
|
||||
# define SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA 293
|
||||
# define SSL_R_NOT_ON_RECORD_BOUNDARY 182
|
||||
# define SSL_R_NOT_REPLACING_CERTIFICATE 289
|
||||
@@ -731,9 +733,11 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS 239
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES 242
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES 243
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 109
|
||||
# define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
# define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
# define SSL_R_UNEXPECTED_MESSAGE 244
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 110
|
||||
# define SSL_R_UNEXPECTED_RECORD 245
|
||||
# define SSL_R_UNINITIALIZED 276
|
||||
# define SSL_R_UNKNOWN_ALERT_TYPE 246
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 066bf47221..517eda6630 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -167,7 +167,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -232,7 +232,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -296,7 +296,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4124,6 +4124,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
return 1;
|
||||
}
|
||||
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s)
|
||||
+{
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ return (s->cipher_list);
|
||||
+
|
||||
+ if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL))
|
||||
+ return (s->ctx->cipher_list);
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* ssl3_choose_cipher - choose a cipher from those offered by the client
|
||||
* @s: SSL connection
|
||||
@@ -4133,16 +4144,24 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
* Returns the selected cipher or NULL when no common ciphers.
|
||||
*/
|
||||
const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr)
|
||||
+ struct ssl_cipher_preference_list_st
|
||||
+ *server_pref)
|
||||
{
|
||||
const SSL_CIPHER *c, *ret = NULL;
|
||||
- STACK_OF(SSL_CIPHER) *prio, *allow;
|
||||
- int i, ii, ok, prefer_sha256 = 0;
|
||||
+ STACK_OF(SSL_CIPHER) *srvr = server_pref->ciphers, *prio, *allow;
|
||||
+ int i, ii, ok, prefer_sha256 = 0, safari_ec = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
const EVP_MD *mdsha256 = EVP_sha256();
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
-#endif
|
||||
+
|
||||
+ /* in_group_flags will either be NULL, or will point to an array of
|
||||
+ * bytes which indicate equal-preference groups in the |prio| stack.
|
||||
+ * See the comment about |in_group_flags| in the
|
||||
+ * |ssl_cipher_preference_list_st| struct. */
|
||||
+ const uint8_t *in_group_flags;
|
||||
+
|
||||
+ /* group_min contains the minimal index so far found in a group, or -1
|
||||
+ * if no such value exists yet. */
|
||||
+ int group_min = -1;
|
||||
|
||||
/* Let's see which ciphers we can support */
|
||||
|
||||
@@ -4169,54 +4188,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#endif
|
||||
|
||||
/* SUITE-B takes precedence over server preference and ChaCha priortiy */
|
||||
- if (tls1_suiteb(s)) {
|
||||
+ if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE || tls1_suiteb(s)) {
|
||||
prio = srvr;
|
||||
+ in_group_flags = server_pref->in_group_flags;
|
||||
allow = clnt;
|
||||
- } else if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE) {
|
||||
- prio = srvr;
|
||||
- allow = clnt;
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- /* If ChaCha20 is at the top of the client preference list,
|
||||
- and there are ChaCha20 ciphers in the server list, then
|
||||
- temporarily prioritize all ChaCha20 ciphers in the servers list. */
|
||||
- if (s->options & SSL_OP_PRIORITIZE_CHACHA && sk_SSL_CIPHER_num(clnt) > 0) {
|
||||
- c = sk_SSL_CIPHER_value(clnt, 0);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- /* ChaCha20 is client preferred, check server... */
|
||||
- int num = sk_SSL_CIPHER_num(srvr);
|
||||
- int found = 0;
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- found = 1;
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
- if (found) {
|
||||
- prio_chacha = sk_SSL_CIPHER_new_reserve(NULL, num);
|
||||
- /* if reserve fails, then there's likely a memory issue */
|
||||
- if (prio_chacha != NULL) {
|
||||
- /* Put all ChaCha20 at the top, starting with the one we just found */
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- for (i++; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- /* Pull in the rest */
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc != SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- prio = prio_chacha;
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
-# endif
|
||||
} else {
|
||||
prio = clnt;
|
||||
+ in_group_flags = NULL;
|
||||
allow = srvr;
|
||||
}
|
||||
|
||||
@@ -4247,14 +4225,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
|
||||
c = sk_SSL_CIPHER_value(prio, i);
|
||||
|
||||
+ ok = 1;
|
||||
+
|
||||
/* Skip ciphers not supported by the protocol version */
|
||||
if (!SSL_IS_DTLS(s) &&
|
||||
((s->version < c->min_tls) || (s->version > c->max_tls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
if (SSL_IS_DTLS(s) &&
|
||||
(DTLS_VERSION_LT(s->version, c->min_dtls) ||
|
||||
DTLS_VERSION_GT(s->version, c->max_dtls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
|
||||
/*
|
||||
* Since TLS 1.3 ciphersuites can be used with any auth or
|
||||
@@ -4276,10 +4256,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
/* with PSK there must be server callback set */
|
||||
if ((alg_k & SSL_PSK) && s->psk_server_callback == NULL)
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
#endif /* OPENSSL_NO_PSK */
|
||||
|
||||
- ok = (alg_k & mask_k) && (alg_a & mask_a);
|
||||
+ ok = ok && (alg_k & mask_k) && (alg_a & mask_a);
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n", ok, alg_k,
|
||||
alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4296,6 +4276,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
|
||||
if (!ok)
|
||||
continue;
|
||||
+
|
||||
+ safari_ec = 0;
|
||||
+#if !defined(OPENSSL_NO_EC)
|
||||
+ if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)) {
|
||||
+ if (s->s3->is_probably_safari)
|
||||
+ safari_ec = 1;
|
||||
+ }
|
||||
+#endif
|
||||
}
|
||||
ii = sk_SSL_CIPHER_find(allow, c);
|
||||
if (ii >= 0) {
|
||||
@@ -4303,14 +4291,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (!ssl_security(s, SSL_SECOP_CIPHER_SHARED,
|
||||
c->strength_bits, 0, (void *)c))
|
||||
continue;
|
||||
-#if !defined(OPENSSL_NO_EC)
|
||||
- if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)
|
||||
- && s->s3->is_probably_safari) {
|
||||
- if (!ret)
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
- continue;
|
||||
- }
|
||||
-#endif
|
||||
+
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
@@ -4322,13 +4303,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
ret = tmp;
|
||||
continue;
|
||||
}
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+
|
||||
+ if (in_group_flags != NULL && in_group_flags[i] == 1) {
|
||||
+ /* This element of |prio| is in a group. Update
|
||||
+ * the minimum index found so far and continue
|
||||
+ * looking. */
|
||||
+ if (group_min == -1 || group_min > ii)
|
||||
+ group_min = ii;
|
||||
+ } else {
|
||||
+ if (group_min != -1 && group_min < ii)
|
||||
+ ii = group_min;
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (in_group_flags != NULL && !in_group_flags[i] && group_min != -1) {
|
||||
+ /* We are about to leave a group, but we found a match
|
||||
+ * in it, so that's our answer. */
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
break;
|
||||
}
|
||||
}
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- sk_SSL_CIPHER_free(prio_chacha);
|
||||
-#endif
|
||||
return ret;
|
||||
}
|
||||
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 27a1b2ec68..9880a0b363 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -192,6 +192,7 @@ typedef struct cipher_order_st {
|
||||
const SSL_CIPHER *cipher;
|
||||
int active;
|
||||
int dead;
|
||||
+ int in_group;
|
||||
struct cipher_order_st *next, *prev;
|
||||
} CIPHER_ORDER;
|
||||
|
||||
@@ -681,6 +682,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
co_list[co_list_num].next = NULL;
|
||||
co_list[co_list_num].prev = NULL;
|
||||
co_list[co_list_num].active = 0;
|
||||
+ co_list[co_list_num].in_group = 0;
|
||||
co_list_num++;
|
||||
}
|
||||
|
||||
@@ -774,8 +776,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
uint32_t alg_auth, uint32_t alg_enc,
|
||||
uint32_t alg_mac, int min_tls,
|
||||
uint32_t algo_strength, int rule,
|
||||
- int32_t strength_bits, CIPHER_ORDER **head_p,
|
||||
- CIPHER_ORDER **tail_p)
|
||||
+ int32_t strength_bits, int in_group,
|
||||
+ CIPHER_ORDER **head_p, CIPHER_ORDER **tail_p)
|
||||
{
|
||||
CIPHER_ORDER *head, *tail, *curr, *next, *last;
|
||||
const SSL_CIPHER *cp;
|
||||
@@ -783,9 +785,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr,
|
||||
- "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d)\n",
|
||||
+ "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d) g:%d\n",
|
||||
rule, alg_mkey, alg_auth, alg_enc, alg_mac, min_tls,
|
||||
- algo_strength, strength_bits);
|
||||
+ algo_strength, strength_bits, in_group);
|
||||
#endif
|
||||
|
||||
if (rule == CIPHER_DEL || rule == CIPHER_BUMP)
|
||||
@@ -862,6 +864,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
if (!curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
curr->active = 1;
|
||||
+ curr->in_group = in_group;
|
||||
}
|
||||
}
|
||||
/* Move the added cipher to this location */
|
||||
@@ -869,6 +872,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
/* reverse == 0 */
|
||||
if (curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_DEL) {
|
||||
/* reverse == 1 */
|
||||
@@ -880,6 +884,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
*/
|
||||
ll_append_head(&head, curr, &tail);
|
||||
curr->active = 0;
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_BUMP) {
|
||||
if (curr->active)
|
||||
@@ -947,8 +952,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
*/
|
||||
for (i = max_strength_bits; i >= 0; i--)
|
||||
if (number_uses[i] > 0)
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, head_p,
|
||||
- tail_p);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, 0,
|
||||
+ head_p, tail_p);
|
||||
|
||||
OPENSSL_free(number_uses);
|
||||
return 1;
|
||||
@@ -962,7 +967,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
uint32_t alg_mkey, alg_auth, alg_enc, alg_mac, algo_strength;
|
||||
int min_tls;
|
||||
const char *l, *buf;
|
||||
- int j, multi, found, rule, retval, ok, buflen;
|
||||
+ int j, multi, found, rule, retval, ok, buflen, in_group = 0, has_group = 0;
|
||||
uint32_t cipher_id = 0;
|
||||
char ch;
|
||||
|
||||
@@ -973,18 +978,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
|
||||
if (ch == '\0')
|
||||
break; /* done */
|
||||
- if (ch == '-') {
|
||||
+ if (in_group) {
|
||||
+ if (ch == ']') {
|
||||
+ if (!in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_GROUP_CLOSE);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ if (*tail_p)
|
||||
+ (*tail_p)->in_group = 0;
|
||||
+ in_group = 0;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ }
|
||||
+ if (ch == '|') {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ } else if (!(ch >= 'a' && ch <= 'z')
|
||||
+ && !(ch >= 'A' && ch <= 'Z')
|
||||
+ && !(ch >= '0' && ch <= '9')) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_OPERATOR_IN_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ } else {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ }
|
||||
+ } else if (ch == '-') {
|
||||
rule = CIPHER_DEL;
|
||||
l++;
|
||||
} else if (ch == '+') {
|
||||
rule = CIPHER_ORD;
|
||||
l++;
|
||||
+ } else if (ch == '!' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '!') {
|
||||
rule = CIPHER_KILL;
|
||||
l++;
|
||||
+ } else if (ch == '@' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '@') {
|
||||
rule = CIPHER_SPECIAL;
|
||||
l++;
|
||||
+ } else if (ch == '[') {
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_NESTED_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ in_group = 1;
|
||||
+ has_group = 1;
|
||||
+ l++;
|
||||
+ continue;
|
||||
} else {
|
||||
rule = CIPHER_ADD;
|
||||
}
|
||||
@@ -1026,7 +1079,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
* alphanumeric, so we call this an error.
|
||||
*/
|
||||
SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
- retval = found = 0;
|
||||
+ retval = found = in_group = 0;
|
||||
l++;
|
||||
break;
|
||||
}
|
||||
@@ -1205,8 +1258,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
} else if (found) {
|
||||
ssl_cipher_apply_rule(cipher_id,
|
||||
alg_mkey, alg_auth, alg_enc, alg_mac,
|
||||
- min_tls, algo_strength, rule, -1, head_p,
|
||||
- tail_p);
|
||||
+ min_tls, algo_strength, rule, -1, in_group,
|
||||
+ head_p, tail_p);
|
||||
} else {
|
||||
while ((*l != '\0') && !ITEM_SEP(*l))
|
||||
l++;
|
||||
@@ -1215,6 +1268,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
break; /* done */
|
||||
}
|
||||
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
+ retval = 0;
|
||||
+ }
|
||||
+
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1378,7 +1436,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
int ret = set_ciphersuites(&(ctx->tls13_ciphersuites), str);
|
||||
|
||||
if (ret && ctx->cipher_list != NULL)
|
||||
- return update_cipher_list(&ctx->cipher_list, &ctx->cipher_list_by_id,
|
||||
+ return update_cipher_list(&ctx->cipher_list->ciphers, &ctx->cipher_list_by_id,
|
||||
ctx->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1391,10 +1449,10 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (s->cipher_list == NULL) {
|
||||
if ((cipher_list = SSL_get_ciphers(s)) != NULL)
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(cipher_list);
|
||||
+ s->cipher_list->ciphers = sk_SSL_CIPHER_dup(cipher_list);
|
||||
}
|
||||
if (ret && s->cipher_list != NULL)
|
||||
- return update_cipher_list(&s->cipher_list, &s->cipher_list_by_id,
|
||||
+ return update_cipher_list(&s->cipher_list->ciphers, &s->cipher_list_by_id,
|
||||
s->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1402,17 +1460,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c)
|
||||
{
|
||||
- int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i;
|
||||
+ int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i, tls13_len;
|
||||
uint32_t disabled_mkey, disabled_auth, disabled_enc, disabled_mac;
|
||||
- STACK_OF(SSL_CIPHER) *cipherstack;
|
||||
+ STACK_OF(SSL_CIPHER) *cipherstack = NULL;
|
||||
const char *rule_p;
|
||||
CIPHER_ORDER *co_list = NULL, *head = NULL, *tail = NULL, *curr;
|
||||
- const SSL_CIPHER **ca_list = NULL;
|
||||
+ const SSL_CIPHER **ca_list = NULL, *tmp = NULL;
|
||||
+ uint8_t *in_group_flags = NULL;
|
||||
+ unsigned int num_in_group_flags = 0;
|
||||
+ struct ssl_cipher_preference_list_st *pref_list = NULL;
|
||||
|
||||
/*
|
||||
* Return with error if nothing to do.
|
||||
@@ -1461,16 +1522,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* preference).
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, SSL_kECDHE, SSL_aECDSA, 0, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head,
|
||||
- &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head,
|
||||
- &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
+ &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Within each strength group, we prefer GCM over CHACHA... */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1479,13 +1540,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* strength.
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, 0, 0, SSL_AES ^ SSL_AESGCM, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
|
||||
/* Temporarily enable everything else for sorting */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0, &head, &tail);
|
||||
|
||||
/* Low priority for MD5 */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1493,16 +1554,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* disabled. (For applications that allow them, they aren't too bad, but
|
||||
* we prefer authenticated ciphers.)
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
- ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/* RC4 is sort-of broken -- move to the end */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1518,7 +1579,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Partially overrule strength sort to prefer TLS 1.2 ciphers/PRFs.
|
||||
* TODO(openssl-team): is there an easier way to accomplish all this?
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1534,15 +1595,15 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Because we now bump ciphers to the top of the list, we proceed in
|
||||
* reverse order of preference.
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, 0, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, SSL_AEAD, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
|
||||
/* Now disable everything (maintaining the ordering!) */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0, &head, &tail);
|
||||
|
||||
/*
|
||||
* We also need cipher aliases for selecting based on the rule_str.
|
||||
@@ -1556,9 +1617,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
num_of_alias_max = num_of_ciphers + num_of_group_aliases + 1;
|
||||
ca_list = OPENSSL_malloc(sizeof(*ca_list) * num_of_alias_max);
|
||||
if (ca_list == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
SSLerr(SSL_F_SSL_CREATE_CIPHER_LIST, ERR_R_MALLOC_FAILURE);
|
||||
- return NULL; /* Failure */
|
||||
+ goto err; /* Failure */
|
||||
}
|
||||
ssl_cipher_collect_aliases(ca_list, num_of_group_aliases,
|
||||
disabled_mkey, disabled_auth, disabled_enc,
|
||||
@@ -1583,27 +1643,35 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
|
||||
OPENSSL_free(ca_list); /* Not needed anymore */
|
||||
|
||||
- if (!ok) { /* Rule processing failure */
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!ok)
|
||||
+ goto err; /* Rule processing failure */
|
||||
|
||||
/*
|
||||
* Allocate new "cipherstack" for the result, return with error
|
||||
* if we cannot get one.
|
||||
*/
|
||||
- if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL)
|
||||
+ goto err;
|
||||
+
|
||||
+ in_group_flags = OPENSSL_malloc(num_of_ciphers);
|
||||
+ if (!in_group_flags)
|
||||
+ goto err;
|
||||
|
||||
/* Add TLSv1.3 ciphers first - we always prefer those if possible */
|
||||
- for (i = 0; i < sk_SSL_CIPHER_num(tls13_ciphersuites); i++) {
|
||||
+ tls13_len = sk_SSL_CIPHER_num(tls13_ciphersuites);
|
||||
+ for (i = 0; i < tls13_len; i++) {
|
||||
+ tmp = sk_SSL_CIPHER_value(tls13_ciphersuites, i);
|
||||
if (!sk_SSL_CIPHER_push(cipherstack,
|
||||
- sk_SSL_CIPHER_value(tls13_ciphersuites, i))) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
+ tmp))
|
||||
+ goto err;
|
||||
+ /* Temporary - AES128, CHACHA20 priority adjustment of TLS 1.3. */
|
||||
+ if (tmp->algorithm_enc == SSL_AES128GCM &&
|
||||
+ tls13_len > (i + 1)) {
|
||||
+ tmp = sk_SSL_CIPHER_value(tls13_ciphersuites, i + 1);
|
||||
+ in_group_flags[num_in_group_flags++] = (tmp->algorithm_enc == SSL_CHACHA20POLY1305) ? 1 : 0;
|
||||
}
|
||||
+ else
|
||||
+ in_group_flags[num_in_group_flags++] = 0;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -1612,26 +1680,50 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
*/
|
||||
for (curr = head; curr != NULL; curr = curr->next) {
|
||||
if (curr->active) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
- OPENSSL_free(co_list);
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher))
|
||||
+ goto err;
|
||||
+ in_group_flags[num_in_group_flags++] = curr->in_group;
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "<%s>\n", curr->cipher->name);
|
||||
#endif
|
||||
}
|
||||
}
|
||||
- OPENSSL_free(co_list); /* Not needed any longer */
|
||||
|
||||
- if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack)) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- sk_SSL_CIPHER_free(*cipher_list);
|
||||
- *cipher_list = cipherstack;
|
||||
+ OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
+
|
||||
+ if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack))
|
||||
+ goto err;
|
||||
+
|
||||
+ pref_list = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!pref_list)
|
||||
+ goto err;
|
||||
+ pref_list->ciphers = cipherstack;
|
||||
+ pref_list->in_group_flags = OPENSSL_malloc(num_in_group_flags);
|
||||
+ if (!pref_list->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(pref_list->in_group_flags, in_group_flags, num_in_group_flags);
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ in_group_flags = NULL;
|
||||
+ if (*cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(*cipher_list);
|
||||
+ *cipher_list = pref_list;
|
||||
+ pref_list = NULL;
|
||||
|
||||
return cipherstack;
|
||||
+
|
||||
+err:
|
||||
+ if (co_list)
|
||||
+ OPENSSL_free(co_list);
|
||||
+ if (in_group_flags)
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ if (cipherstack)
|
||||
+ sk_SSL_CIPHER_free(cipherstack);
|
||||
+ if (pref_list && pref_list->in_group_flags)
|
||||
+ OPENSSL_free(pref_list->in_group_flags);
|
||||
+ if (pref_list)
|
||||
+ OPENSSL_free(pref_list);
|
||||
+ return NULL;
|
||||
}
|
||||
|
||||
char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
diff --git a/ssl/ssl_err.c b/ssl/ssl_err.c
|
||||
index 4b12ed1485..cd1a95d1d2 100644
|
||||
--- a/ssl/ssl_err.c
|
||||
+++ b/ssl/ssl_err.c
|
||||
@@ -965,6 +965,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_DH_KEY), "missing tmp dh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_ECDH_KEY),
|
||||
"missing tmp ecdh key"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS),
|
||||
+ "mixed special operator with groups"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NESTED_GROUP), "nested group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_ON_RECORD_BOUNDARY),
|
||||
@@ -1201,11 +1204,14 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unable to load ssl3 md5 routines"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES),
|
||||
"unable to load ssl3 sha1 routines"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE), "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_CCS_MESSAGE),
|
||||
"unexpected ccs message"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_END_OF_EARLY_DATA),
|
||||
"unexpected end of early data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_MESSAGE), "unexpected message"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP),
|
||||
+ "unexpected operator in group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_RECORD), "unexpected record"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNINITIALIZED), "uninitialized"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNKNOWN_ALERT_TYPE), "unknown alert type"},
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index ac820cf9fe..141308584c 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -1122,6 +1122,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
return X509_VERIFY_PARAM_set1(ssl->param, vpm);
|
||||
}
|
||||
|
||||
+void ssl_cipher_preference_list_free(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ sk_SSL_CIPHER_free(cipher_list->ciphers);
|
||||
+ OPENSSL_free(cipher_list->in_group_flags);
|
||||
+ OPENSSL_free(cipher_list);
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_dup(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(cipher_list->ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(cipher_list->ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(ret->in_group_flags, cipher_list->in_group_flags, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_from_ciphers(STACK_OF(SSL_CIPHER) *ciphers)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memset(ret->in_group_flags, 0, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx)
|
||||
{
|
||||
return ctx->param;
|
||||
@@ -1162,7 +1227,8 @@ void SSL_free(SSL *s)
|
||||
BUF_MEM_free(s->init_buf);
|
||||
|
||||
/* add extra stuff */
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(s->tls13_ciphersuites);
|
||||
sk_SSL_CIPHER_free(s->peer_ciphers);
|
||||
@@ -2436,9 +2502,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
{
|
||||
if (s != NULL) {
|
||||
if (s->cipher_list != NULL) {
|
||||
- return s->cipher_list;
|
||||
+ return (s->cipher_list->ciphers);
|
||||
} else if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL)) {
|
||||
- return s->ctx->cipher_list;
|
||||
+ return (s->ctx->cipher_list->ciphers);
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
@@ -2512,8 +2578,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
* preference */
|
||||
STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx)
|
||||
{
|
||||
- if (ctx != NULL)
|
||||
- return ctx->cipher_list;
|
||||
+ if (ctx != NULL && ctx->cipher_list != NULL)
|
||||
+ return ctx->cipher_list->ciphers;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -2963,7 +3029,7 @@ SSL_CTX *SSL_CTX_new(const SSL_METHOD *meth)
|
||||
ret->tls13_ciphersuites,
|
||||
&ret->cipher_list, &ret->cipher_list_by_id,
|
||||
SSL_DEFAULT_CIPHER_LIST, ret->cert)
|
||||
- || sk_SSL_CIPHER_num(ret->cipher_list) <= 0) {
|
||||
+ || sk_SSL_CIPHER_num(ret->cipher_list->ciphers) <= 0) {
|
||||
SSLerr(SSL_F_SSL_CTX_NEW, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
goto err2;
|
||||
}
|
||||
@@ -3139,7 +3205,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
#ifndef OPENSSL_NO_CT
|
||||
CTLOG_STORE_free(a->ctlog_store);
|
||||
#endif
|
||||
- sk_SSL_CIPHER_free(a->cipher_list);
|
||||
+ ssl_cipher_preference_list_free(a->cipher_list);
|
||||
sk_SSL_CIPHER_free(a->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(a->tls13_ciphersuites);
|
||||
ssl_cert_free(a->cert);
|
||||
@@ -3817,13 +3883,15 @@ SSL *SSL_dup(SSL *s)
|
||||
|
||||
/* dup the cipher_list and cipher_list_by_id stacks */
|
||||
if (s->cipher_list != NULL) {
|
||||
- if ((ret->cipher_list = sk_SSL_CIPHER_dup(s->cipher_list)) == NULL)
|
||||
+ ret->cipher_list = ssl_cipher_preference_list_dup(s->cipher_list);
|
||||
+ if (ret->cipher_list == NULL)
|
||||
goto err;
|
||||
}
|
||||
- if (s->cipher_list_by_id != NULL)
|
||||
- if ((ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id))
|
||||
- == NULL)
|
||||
+ if (s->cipher_list_by_id != NULL) {
|
||||
+ ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id);
|
||||
+ if (ret->cipher_list_by_id == NULL)
|
||||
goto err;
|
||||
+ }
|
||||
|
||||
/* Dup the client_CA list */
|
||||
if (!dup_ca_names(&ret->ca_names, s->ca_names)
|
||||
diff --git a/ssl/ssl_locl.h b/ssl/ssl_locl.h
|
||||
index 25875c9f6d..23a6093580 100644
|
||||
--- a/ssl/ssl_locl.h
|
||||
+++ b/ssl/ssl_locl.h
|
||||
@@ -733,9 +733,46 @@ typedef struct ssl_ctx_ext_secure_st {
|
||||
unsigned char tick_aes_key[TLSEXT_TICK_KEY_LENGTH];
|
||||
} SSL_CTX_EXT_SECURE;
|
||||
|
||||
+/* ssl_cipher_preference_list_st contains a list of SSL_CIPHERs with
|
||||
+ * equal-preference groups. For TLS clients, the groups are moot because the
|
||||
+ * server picks the cipher and groups cannot be expressed on the wire. However,
|
||||
+ * for servers, the equal-preference groups allow the client's preferences to
|
||||
+ * be partially respected. (This only has an effect with
|
||||
+ * SSL_OP_CIPHER_SERVER_PREFERENCE).
|
||||
+ *
|
||||
+ * The equal-preference groups are expressed by grouping SSL_CIPHERs together.
|
||||
+ * All elements of a group have the same priority: no ordering is expressed
|
||||
+ * within a group.
|
||||
+ *
|
||||
+ * The values in |ciphers| are in one-to-one correspondence with
|
||||
+ * |in_group_flags|. (That is, sk_SSL_CIPHER_num(ciphers) is the number of
|
||||
+ * bytes in |in_group_flags|.) The bytes in |in_group_flags| are either 1, to
|
||||
+ * indicate that the corresponding SSL_CIPHER is not the last element of a
|
||||
+ * group, or 0 to indicate that it is.
|
||||
+ *
|
||||
+ * For example, if |in_group_flags| contains all zeros then that indicates a
|
||||
+ * traditional, fully-ordered preference. Every SSL_CIPHER is the last element
|
||||
+ * of the group (i.e. they are all in a one-element group).
|
||||
+ *
|
||||
+ * For a more complex example, consider:
|
||||
+ * ciphers: A B C D E F
|
||||
+ * in_group_flags: 1 1 0 0 1 0
|
||||
+ *
|
||||
+ * That would express the following, order:
|
||||
+ *
|
||||
+ * A E
|
||||
+ * B -> D -> F
|
||||
+ * C
|
||||
+ */
|
||||
+struct ssl_cipher_preference_list_st {
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers;
|
||||
+ uint8_t *in_group_flags;
|
||||
+};
|
||||
+
|
||||
+
|
||||
struct ssl_ctx_st {
|
||||
const SSL_METHOD *method;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
/* same as above but sorted for lookup */
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
@@ -1131,7 +1168,7 @@ struct ssl_st {
|
||||
SSL_DANE dane;
|
||||
/* crypto */
|
||||
STACK_OF(SSL_CIPHER) *peer_ciphers;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites;
|
||||
@@ -2269,7 +2306,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
const SSL_CIPHER *const *bp);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c);
|
||||
@@ -2279,6 +2316,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_dup(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+void ssl_cipher_preference_list_free(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_from_ciphers(
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers);
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s);
|
||||
__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
const EVP_MD **md, int *mac_pkey_type,
|
||||
size_t *mac_secret_size, SSL_COMP **comp,
|
||||
@@ -2362,7 +2406,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
CERT_PKEY *cpk);
|
||||
__owur const SSL_CIPHER *ssl3_choose_cipher(SSL *ssl,
|
||||
STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr);
|
||||
+ struct ssl_cipher_preference_list_st *srvr);
|
||||
__owur int ssl3_digest_cached_records(SSL *s, int keep);
|
||||
__owur int ssl3_new(SSL *s);
|
||||
void ssl3_free(SSL *s);
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index 8cf9c40d15..46391a7f05 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -1748,7 +1748,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* For TLSv1.3 we must select the ciphersuite *before* session resumption */
|
||||
if (SSL_IS_TLS13(s)) {
|
||||
const SSL_CIPHER *cipher =
|
||||
- ssl3_choose_cipher(s, ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1929,7 +1929,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* check if some cipher was preferred by call back */
|
||||
if (pref_cipher == NULL)
|
||||
pref_cipher = ssl3_choose_cipher(s, s->peer_ciphers,
|
||||
- SSL_get_ciphers(s));
|
||||
+ ssl_get_cipher_preferences(s));
|
||||
if (pref_cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_F_TLS_EARLY_POST_PROCESS_CLIENT_HELLO,
|
||||
@@ -1938,8 +1938,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
}
|
||||
|
||||
s->session->cipher = pref_cipher;
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
+ s->cipher_list = ssl_cipher_preference_list_from_ciphers(
|
||||
+ s->peer_ciphers);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
}
|
||||
@@ -2251,7 +2252,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
/* In TLSv1.3 we selected the ciphersuite before resumption */
|
||||
if (!SSL_IS_TLS13(s)) {
|
||||
cipher =
|
||||
- ssl3_choose_cipher(s, s->peer_ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->peer_ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -0,0 +1,1110 @@
|
||||
diff --git a/doc/man1/ciphers.pod b/doc/man1/ciphers.pod
|
||||
index faf9e53814..428df515f1 100644
|
||||
--- a/doc/man1/ciphers.pod
|
||||
+++ b/doc/man1/ciphers.pod
|
||||
@@ -400,6 +400,21 @@ permissible.
|
||||
|
||||
=back
|
||||
|
||||
+=head1 EQUAL PREFERENCE GROUPS
|
||||
+
|
||||
+If configuring a server, one may also configure equal-preference groups to
|
||||
+partially respect the client's preferences when
|
||||
+B<SSL_OP_CIPHER_SERVER_PREFERENCE> is enabled. Ciphers in an equal-preference
|
||||
+group have equal priority and use the client order. This may be used to
|
||||
+enforce that AEADs are preferred but select AES-GCM vs. ChaCha20-Poly1305
|
||||
+based on client preferences. An equal-preference is specified with square
|
||||
+brackets, combining multiple selectors separated by |. For example:
|
||||
+
|
||||
+ [ECDHE-ECDSA-CHACHA20-POLY1305|ECDHE-ECDSA-AES128-GCM-SHA256]
|
||||
+
|
||||
+ Once an equal-preference group is used, future directives must be
|
||||
+ opcode-less.
|
||||
+
|
||||
=head1 CIPHER SUITE NAMES
|
||||
|
||||
The following lists give the SSL or TLS cipher suites names from the
|
||||
diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h
|
||||
index 3d6850dea3..a3ab4b925f 100644
|
||||
--- a/include/openssl/sslerr.h
|
||||
+++ b/include/openssl/sslerr.h
|
||||
@@ -600,6 +600,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_SUPPORTED_GROUPS_EXTENSION 209
|
||||
# define SSL_R_MISSING_TMP_DH_KEY 171
|
||||
# define SSL_R_MISSING_TMP_ECDH_KEY 311
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 101
|
||||
+# define SSL_R_NESTED_GROUP 108
|
||||
# define SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA 293
|
||||
# define SSL_R_NOT_ON_RECORD_BOUNDARY 182
|
||||
# define SSL_R_NOT_REPLACING_CERTIFICATE 289
|
||||
@@ -731,9 +733,11 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS 239
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES 242
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES 243
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 109
|
||||
# define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
# define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
# define SSL_R_UNEXPECTED_MESSAGE 244
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 110
|
||||
# define SSL_R_UNEXPECTED_RECORD 245
|
||||
# define SSL_R_UNINITIALIZED 276
|
||||
# define SSL_R_UNKNOWN_ALERT_TYPE 246
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 066bf47221..6d56b27473 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -31,7 +31,25 @@ const unsigned char tls12downgrade[] = {
|
||||
};
|
||||
|
||||
/* The list of available TLSv1.3 ciphers */
|
||||
+/* Since nginx can not set the TLS 1.3 cipher, remove it temporarily. */
|
||||
static SSL_CIPHER tls13_ciphers[] = {
|
||||
+ {
|
||||
+ 0,
|
||||
+ }
|
||||
+};
|
||||
+
|
||||
+/*
|
||||
+ * The list of available ciphers, mostly organized into the following
|
||||
+ * groups:
|
||||
+ * Always there
|
||||
+ * EC
|
||||
+ * PSK
|
||||
+ * SRP (within that: RSA EC PSK)
|
||||
+ * Cipher families: Chacha/poly, Camellia, Gost, IDEA, SEED
|
||||
+ * Weak ciphers
|
||||
+ */
|
||||
+static SSL_CIPHER ssl3_ciphers[] = {
|
||||
+ /* TLSv1.3 ciphers */
|
||||
{
|
||||
1,
|
||||
TLS1_3_RFC_AES_128_GCM_SHA256,
|
||||
@@ -111,20 +129,8 @@ static SSL_CIPHER tls13_ciphers[] = {
|
||||
SSL_HANDSHAKE_MAC_SHA256,
|
||||
128,
|
||||
128,
|
||||
- }
|
||||
-};
|
||||
-
|
||||
-/*
|
||||
- * The list of available ciphers, mostly organized into the following
|
||||
- * groups:
|
||||
- * Always there
|
||||
- * EC
|
||||
- * PSK
|
||||
- * SRP (within that: RSA EC PSK)
|
||||
- * Cipher families: Chacha/poly, Camellia, Gost, IDEA, SEED
|
||||
- * Weak ciphers
|
||||
- */
|
||||
-static SSL_CIPHER ssl3_ciphers[] = {
|
||||
+ },
|
||||
+ /* List of cipher below TLSv1.3 */
|
||||
{
|
||||
1,
|
||||
SSL3_TXT_RSA_NULL_MD5,
|
||||
@@ -167,7 +173,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -232,7 +238,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -296,7 +302,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4124,6 +4130,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
return 1;
|
||||
}
|
||||
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s)
|
||||
+{
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ return (s->cipher_list);
|
||||
+
|
||||
+ if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL))
|
||||
+ return (s->ctx->cipher_list);
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* ssl3_choose_cipher - choose a cipher from those offered by the client
|
||||
* @s: SSL connection
|
||||
@@ -4133,16 +4150,24 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
* Returns the selected cipher or NULL when no common ciphers.
|
||||
*/
|
||||
const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr)
|
||||
+ struct ssl_cipher_preference_list_st
|
||||
+ *server_pref)
|
||||
{
|
||||
const SSL_CIPHER *c, *ret = NULL;
|
||||
- STACK_OF(SSL_CIPHER) *prio, *allow;
|
||||
- int i, ii, ok, prefer_sha256 = 0;
|
||||
+ STACK_OF(SSL_CIPHER) *srvr = server_pref->ciphers, *prio, *allow;
|
||||
+ int i, ii, ok, prefer_sha256 = 0, safari_ec = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
const EVP_MD *mdsha256 = EVP_sha256();
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
-#endif
|
||||
+
|
||||
+ /* in_group_flags will either be NULL, or will point to an array of
|
||||
+ * bytes which indicate equal-preference groups in the |prio| stack.
|
||||
+ * See the comment about |in_group_flags| in the
|
||||
+ * |ssl_cipher_preference_list_st| struct. */
|
||||
+ const uint8_t *in_group_flags;
|
||||
+
|
||||
+ /* group_min contains the minimal index so far found in a group, or -1
|
||||
+ * if no such value exists yet. */
|
||||
+ int group_min = -1;
|
||||
|
||||
/* Let's see which ciphers we can support */
|
||||
|
||||
@@ -4169,54 +4194,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#endif
|
||||
|
||||
/* SUITE-B takes precedence over server preference and ChaCha priortiy */
|
||||
- if (tls1_suiteb(s)) {
|
||||
+ if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE || tls1_suiteb(s)) {
|
||||
prio = srvr;
|
||||
+ in_group_flags = server_pref->in_group_flags;
|
||||
allow = clnt;
|
||||
- } else if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE) {
|
||||
- prio = srvr;
|
||||
- allow = clnt;
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- /* If ChaCha20 is at the top of the client preference list,
|
||||
- and there are ChaCha20 ciphers in the server list, then
|
||||
- temporarily prioritize all ChaCha20 ciphers in the servers list. */
|
||||
- if (s->options & SSL_OP_PRIORITIZE_CHACHA && sk_SSL_CIPHER_num(clnt) > 0) {
|
||||
- c = sk_SSL_CIPHER_value(clnt, 0);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- /* ChaCha20 is client preferred, check server... */
|
||||
- int num = sk_SSL_CIPHER_num(srvr);
|
||||
- int found = 0;
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- found = 1;
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
- if (found) {
|
||||
- prio_chacha = sk_SSL_CIPHER_new_reserve(NULL, num);
|
||||
- /* if reserve fails, then there's likely a memory issue */
|
||||
- if (prio_chacha != NULL) {
|
||||
- /* Put all ChaCha20 at the top, starting with the one we just found */
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- for (i++; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- /* Pull in the rest */
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc != SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- prio = prio_chacha;
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
-# endif
|
||||
} else {
|
||||
prio = clnt;
|
||||
+ in_group_flags = NULL;
|
||||
allow = srvr;
|
||||
}
|
||||
|
||||
@@ -4247,14 +4231,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
|
||||
c = sk_SSL_CIPHER_value(prio, i);
|
||||
|
||||
+ ok = 1;
|
||||
+
|
||||
/* Skip ciphers not supported by the protocol version */
|
||||
if (!SSL_IS_DTLS(s) &&
|
||||
((s->version < c->min_tls) || (s->version > c->max_tls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
if (SSL_IS_DTLS(s) &&
|
||||
(DTLS_VERSION_LT(s->version, c->min_dtls) ||
|
||||
DTLS_VERSION_GT(s->version, c->max_dtls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
|
||||
/*
|
||||
* Since TLS 1.3 ciphersuites can be used with any auth or
|
||||
@@ -4276,10 +4262,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
/* with PSK there must be server callback set */
|
||||
if ((alg_k & SSL_PSK) && s->psk_server_callback == NULL)
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
#endif /* OPENSSL_NO_PSK */
|
||||
|
||||
- ok = (alg_k & mask_k) && (alg_a & mask_a);
|
||||
+ ok = ok && (alg_k & mask_k) && (alg_a & mask_a);
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n", ok, alg_k,
|
||||
alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4296,6 +4282,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
|
||||
if (!ok)
|
||||
continue;
|
||||
+
|
||||
+ safari_ec = 0;
|
||||
+#if !defined(OPENSSL_NO_EC)
|
||||
+ if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)) {
|
||||
+ if (s->s3->is_probably_safari)
|
||||
+ safari_ec = 1;
|
||||
+ }
|
||||
+#endif
|
||||
}
|
||||
ii = sk_SSL_CIPHER_find(allow, c);
|
||||
if (ii >= 0) {
|
||||
@@ -4303,14 +4297,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (!ssl_security(s, SSL_SECOP_CIPHER_SHARED,
|
||||
c->strength_bits, 0, (void *)c))
|
||||
continue;
|
||||
-#if !defined(OPENSSL_NO_EC)
|
||||
- if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)
|
||||
- && s->s3->is_probably_safari) {
|
||||
- if (!ret)
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
- continue;
|
||||
- }
|
||||
-#endif
|
||||
+
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
@@ -4322,13 +4309,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
ret = tmp;
|
||||
continue;
|
||||
}
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+
|
||||
+ if (in_group_flags != NULL && in_group_flags[i] == 1) {
|
||||
+ /* This element of |prio| is in a group. Update
|
||||
+ * the minimum index found so far and continue
|
||||
+ * looking. */
|
||||
+ if (group_min == -1 || group_min > ii)
|
||||
+ group_min = ii;
|
||||
+ } else {
|
||||
+ if (group_min != -1 && group_min < ii)
|
||||
+ ii = group_min;
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (in_group_flags != NULL && !in_group_flags[i] && group_min != -1) {
|
||||
+ /* We are about to leave a group, but we found a match
|
||||
+ * in it, so that's our answer. */
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
break;
|
||||
}
|
||||
}
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- sk_SSL_CIPHER_free(prio_chacha);
|
||||
-#endif
|
||||
return ret;
|
||||
}
|
||||
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 27a1b2ec68..111a39229a 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -192,6 +192,7 @@ typedef struct cipher_order_st {
|
||||
const SSL_CIPHER *cipher;
|
||||
int active;
|
||||
int dead;
|
||||
+ int in_group;
|
||||
struct cipher_order_st *next, *prev;
|
||||
} CIPHER_ORDER;
|
||||
|
||||
@@ -296,6 +297,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_TLSV1, NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, "TLSv1.0", NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, SSL_TXT_TLSV1_2, NULL, 0, 0, 0, 0, 0, TLS1_2_VERSION},
|
||||
+ {0, "TLS13", NULL, 0, 0, 0, 0, 0, TLS1_3_VERSION},
|
||||
|
||||
/* strength classes */
|
||||
{0, SSL_TXT_LOW, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_LOW},
|
||||
@@ -681,6 +683,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
co_list[co_list_num].next = NULL;
|
||||
co_list[co_list_num].prev = NULL;
|
||||
co_list[co_list_num].active = 0;
|
||||
+ co_list[co_list_num].in_group = 0;
|
||||
co_list_num++;
|
||||
}
|
||||
|
||||
@@ -774,8 +777,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
uint32_t alg_auth, uint32_t alg_enc,
|
||||
uint32_t alg_mac, int min_tls,
|
||||
uint32_t algo_strength, int rule,
|
||||
- int32_t strength_bits, CIPHER_ORDER **head_p,
|
||||
- CIPHER_ORDER **tail_p)
|
||||
+ int32_t strength_bits, int in_group,
|
||||
+ CIPHER_ORDER **head_p, CIPHER_ORDER **tail_p)
|
||||
{
|
||||
CIPHER_ORDER *head, *tail, *curr, *next, *last;
|
||||
const SSL_CIPHER *cp;
|
||||
@@ -783,9 +786,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr,
|
||||
- "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d)\n",
|
||||
+ "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d) g:%d\n",
|
||||
rule, alg_mkey, alg_auth, alg_enc, alg_mac, min_tls,
|
||||
- algo_strength, strength_bits);
|
||||
+ algo_strength, strength_bits, in_group);
|
||||
#endif
|
||||
|
||||
if (rule == CIPHER_DEL || rule == CIPHER_BUMP)
|
||||
@@ -862,6 +865,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
if (!curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
curr->active = 1;
|
||||
+ curr->in_group = in_group;
|
||||
}
|
||||
}
|
||||
/* Move the added cipher to this location */
|
||||
@@ -869,6 +873,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
/* reverse == 0 */
|
||||
if (curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_DEL) {
|
||||
/* reverse == 1 */
|
||||
@@ -880,6 +885,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
*/
|
||||
ll_append_head(&head, curr, &tail);
|
||||
curr->active = 0;
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_BUMP) {
|
||||
if (curr->active)
|
||||
@@ -947,8 +953,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
*/
|
||||
for (i = max_strength_bits; i >= 0; i--)
|
||||
if (number_uses[i] > 0)
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, head_p,
|
||||
- tail_p);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, 0,
|
||||
+ head_p, tail_p);
|
||||
|
||||
OPENSSL_free(number_uses);
|
||||
return 1;
|
||||
@@ -962,7 +968,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
uint32_t alg_mkey, alg_auth, alg_enc, alg_mac, algo_strength;
|
||||
int min_tls;
|
||||
const char *l, *buf;
|
||||
- int j, multi, found, rule, retval, ok, buflen;
|
||||
+ int j, multi, found, rule, retval, ok, buflen, in_group = 0, has_group = 0;
|
||||
uint32_t cipher_id = 0;
|
||||
char ch;
|
||||
|
||||
@@ -973,18 +979,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
|
||||
if (ch == '\0')
|
||||
break; /* done */
|
||||
- if (ch == '-') {
|
||||
+ if (in_group) {
|
||||
+ if (ch == ']') {
|
||||
+ if (!in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_GROUP_CLOSE);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ if (*tail_p)
|
||||
+ (*tail_p)->in_group = 0;
|
||||
+ in_group = 0;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ }
|
||||
+ if (ch == '|') {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ } else if (!(ch >= 'a' && ch <= 'z')
|
||||
+ && !(ch >= 'A' && ch <= 'Z')
|
||||
+ && !(ch >= '0' && ch <= '9')) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_OPERATOR_IN_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ } else {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ }
|
||||
+ } else if (ch == '-') {
|
||||
rule = CIPHER_DEL;
|
||||
l++;
|
||||
} else if (ch == '+') {
|
||||
rule = CIPHER_ORD;
|
||||
l++;
|
||||
+ } else if (ch == '!' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '!') {
|
||||
rule = CIPHER_KILL;
|
||||
l++;
|
||||
+ } else if (ch == '@' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '@') {
|
||||
rule = CIPHER_SPECIAL;
|
||||
l++;
|
||||
+ } else if (ch == '[') {
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_NESTED_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ in_group = 1;
|
||||
+ has_group = 1;
|
||||
+ l++;
|
||||
+ continue;
|
||||
} else {
|
||||
rule = CIPHER_ADD;
|
||||
}
|
||||
@@ -1009,7 +1063,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
while (((ch >= 'A') && (ch <= 'Z')) ||
|
||||
((ch >= '0') && (ch <= '9')) ||
|
||||
((ch >= 'a') && (ch <= 'z')) ||
|
||||
- (ch == '-') || (ch == '.') || (ch == '='))
|
||||
+ (ch == '-') || (ch == '.') || (ch == '=') || (ch == '_'))
|
||||
#else
|
||||
while (isalnum((unsigned char)ch) || (ch == '-') || (ch == '.')
|
||||
|| (ch == '='))
|
||||
@@ -1026,7 +1080,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
* alphanumeric, so we call this an error.
|
||||
*/
|
||||
SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
- retval = found = 0;
|
||||
+ retval = found = in_group = 0;
|
||||
l++;
|
||||
break;
|
||||
}
|
||||
@@ -1205,8 +1259,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
} else if (found) {
|
||||
ssl_cipher_apply_rule(cipher_id,
|
||||
alg_mkey, alg_auth, alg_enc, alg_mac,
|
||||
- min_tls, algo_strength, rule, -1, head_p,
|
||||
- tail_p);
|
||||
+ min_tls, algo_strength, rule, -1, in_group,
|
||||
+ head_p, tail_p);
|
||||
} else {
|
||||
while ((*l != '\0') && !ITEM_SEP(*l))
|
||||
l++;
|
||||
@@ -1215,6 +1269,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
break; /* done */
|
||||
}
|
||||
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
+ retval = 0;
|
||||
+ }
|
||||
+
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1378,7 +1437,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
int ret = set_ciphersuites(&(ctx->tls13_ciphersuites), str);
|
||||
|
||||
if (ret && ctx->cipher_list != NULL)
|
||||
- return update_cipher_list(&ctx->cipher_list, &ctx->cipher_list_by_id,
|
||||
+ return update_cipher_list(&ctx->cipher_list->ciphers, &ctx->cipher_list_by_id,
|
||||
ctx->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1391,10 +1450,10 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (s->cipher_list == NULL) {
|
||||
if ((cipher_list = SSL_get_ciphers(s)) != NULL)
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(cipher_list);
|
||||
+ s->cipher_list->ciphers = sk_SSL_CIPHER_dup(cipher_list);
|
||||
}
|
||||
if (ret && s->cipher_list != NULL)
|
||||
- return update_cipher_list(&s->cipher_list, &s->cipher_list_by_id,
|
||||
+ return update_cipher_list(&s->cipher_list->ciphers, &s->cipher_list_by_id,
|
||||
s->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1402,17 +1461,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c)
|
||||
{
|
||||
- int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i;
|
||||
+ int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases;
|
||||
uint32_t disabled_mkey, disabled_auth, disabled_enc, disabled_mac;
|
||||
- STACK_OF(SSL_CIPHER) *cipherstack;
|
||||
+ STACK_OF(SSL_CIPHER) *cipherstack = NULL;
|
||||
const char *rule_p;
|
||||
CIPHER_ORDER *co_list = NULL, *head = NULL, *tail = NULL, *curr;
|
||||
const SSL_CIPHER **ca_list = NULL;
|
||||
+ uint8_t *in_group_flags = NULL;
|
||||
+ unsigned int num_in_group_flags = 0;
|
||||
+ struct ssl_cipher_preference_list_st *pref_list = NULL;
|
||||
|
||||
/*
|
||||
* Return with error if nothing to do.
|
||||
@@ -1461,16 +1523,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* preference).
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, SSL_kECDHE, SSL_aECDSA, 0, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head,
|
||||
- &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head,
|
||||
- &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
+ &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Within each strength group, we prefer GCM over CHACHA... */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1479,13 +1541,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* strength.
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, 0, 0, SSL_AES ^ SSL_AESGCM, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
|
||||
/* Temporarily enable everything else for sorting */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0, &head, &tail);
|
||||
|
||||
/* Low priority for MD5 */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1493,16 +1555,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* disabled. (For applications that allow them, they aren't too bad, but
|
||||
* we prefer authenticated ciphers.)
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
- ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/* RC4 is sort-of broken -- move to the end */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1518,7 +1580,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Partially overrule strength sort to prefer TLS 1.2 ciphers/PRFs.
|
||||
* TODO(openssl-team): is there an easier way to accomplish all this?
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1534,15 +1596,18 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Because we now bump ciphers to the top of the list, we proceed in
|
||||
* reverse order of preference.
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, 0, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, SSL_AEAD, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
+
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_3_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Now disable everything (maintaining the ordering!) */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0, &head, &tail);
|
||||
|
||||
/*
|
||||
* We also need cipher aliases for selecting based on the rule_str.
|
||||
@@ -1556,9 +1621,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
num_of_alias_max = num_of_ciphers + num_of_group_aliases + 1;
|
||||
ca_list = OPENSSL_malloc(sizeof(*ca_list) * num_of_alias_max);
|
||||
if (ca_list == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
SSLerr(SSL_F_SSL_CREATE_CIPHER_LIST, ERR_R_MALLOC_FAILURE);
|
||||
- return NULL; /* Failure */
|
||||
+ goto err; /* Failure */
|
||||
}
|
||||
ssl_cipher_collect_aliases(ca_list, num_of_group_aliases,
|
||||
disabled_mkey, disabled_auth, disabled_enc,
|
||||
@@ -1583,28 +1647,19 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
|
||||
OPENSSL_free(ca_list); /* Not needed anymore */
|
||||
|
||||
- if (!ok) { /* Rule processing failure */
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!ok)
|
||||
+ goto err; /* Rule processing failure */
|
||||
|
||||
/*
|
||||
* Allocate new "cipherstack" for the result, return with error
|
||||
* if we cannot get one.
|
||||
*/
|
||||
- if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL)
|
||||
+ goto err;
|
||||
|
||||
- /* Add TLSv1.3 ciphers first - we always prefer those if possible */
|
||||
- for (i = 0; i < sk_SSL_CIPHER_num(tls13_ciphersuites); i++) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack,
|
||||
- sk_SSL_CIPHER_value(tls13_ciphersuites, i))) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- }
|
||||
+ in_group_flags = OPENSSL_malloc(num_of_ciphers);
|
||||
+ if (!in_group_flags)
|
||||
+ goto err;
|
||||
|
||||
/*
|
||||
* The cipher selection for the list is done. The ciphers are added
|
||||
@@ -1612,26 +1667,50 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
*/
|
||||
for (curr = head; curr != NULL; curr = curr->next) {
|
||||
if (curr->active) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
- OPENSSL_free(co_list);
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher))
|
||||
+ goto err;
|
||||
+ in_group_flags[num_in_group_flags++] = curr->in_group;
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "<%s>\n", curr->cipher->name);
|
||||
#endif
|
||||
}
|
||||
}
|
||||
- OPENSSL_free(co_list); /* Not needed any longer */
|
||||
|
||||
- if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack)) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- sk_SSL_CIPHER_free(*cipher_list);
|
||||
- *cipher_list = cipherstack;
|
||||
+ OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
+
|
||||
+ if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack))
|
||||
+ goto err;
|
||||
+
|
||||
+ pref_list = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!pref_list)
|
||||
+ goto err;
|
||||
+ pref_list->ciphers = cipherstack;
|
||||
+ pref_list->in_group_flags = OPENSSL_malloc(num_in_group_flags);
|
||||
+ if (!pref_list->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(pref_list->in_group_flags, in_group_flags, num_in_group_flags);
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ in_group_flags = NULL;
|
||||
+ if (*cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(*cipher_list);
|
||||
+ *cipher_list = pref_list;
|
||||
+ pref_list = NULL;
|
||||
|
||||
return cipherstack;
|
||||
+
|
||||
+err:
|
||||
+ if (co_list)
|
||||
+ OPENSSL_free(co_list);
|
||||
+ if (in_group_flags)
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ if (cipherstack)
|
||||
+ sk_SSL_CIPHER_free(cipherstack);
|
||||
+ if (pref_list && pref_list->in_group_flags)
|
||||
+ OPENSSL_free(pref_list->in_group_flags);
|
||||
+ if (pref_list)
|
||||
+ OPENSSL_free(pref_list);
|
||||
+ return NULL;
|
||||
}
|
||||
|
||||
char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
diff --git a/ssl/ssl_err.c b/ssl/ssl_err.c
|
||||
index 4b12ed1485..cd1a95d1d2 100644
|
||||
--- a/ssl/ssl_err.c
|
||||
+++ b/ssl/ssl_err.c
|
||||
@@ -965,6 +965,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_DH_KEY), "missing tmp dh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_ECDH_KEY),
|
||||
"missing tmp ecdh key"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS),
|
||||
+ "mixed special operator with groups"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NESTED_GROUP), "nested group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_ON_RECORD_BOUNDARY),
|
||||
@@ -1201,11 +1204,14 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unable to load ssl3 md5 routines"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES),
|
||||
"unable to load ssl3 sha1 routines"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE), "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_CCS_MESSAGE),
|
||||
"unexpected ccs message"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_END_OF_EARLY_DATA),
|
||||
"unexpected end of early data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_MESSAGE), "unexpected message"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP),
|
||||
+ "unexpected operator in group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_RECORD), "unexpected record"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNINITIALIZED), "uninitialized"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNKNOWN_ALERT_TYPE), "unknown alert type"},
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index ac820cf9fe..141308584c 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -1122,6 +1122,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
return X509_VERIFY_PARAM_set1(ssl->param, vpm);
|
||||
}
|
||||
|
||||
+void ssl_cipher_preference_list_free(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ sk_SSL_CIPHER_free(cipher_list->ciphers);
|
||||
+ OPENSSL_free(cipher_list->in_group_flags);
|
||||
+ OPENSSL_free(cipher_list);
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_dup(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(cipher_list->ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(cipher_list->ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(ret->in_group_flags, cipher_list->in_group_flags, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_from_ciphers(STACK_OF(SSL_CIPHER) *ciphers)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memset(ret->in_group_flags, 0, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx)
|
||||
{
|
||||
return ctx->param;
|
||||
@@ -1162,7 +1227,8 @@ void SSL_free(SSL *s)
|
||||
BUF_MEM_free(s->init_buf);
|
||||
|
||||
/* add extra stuff */
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(s->tls13_ciphersuites);
|
||||
sk_SSL_CIPHER_free(s->peer_ciphers);
|
||||
@@ -2436,9 +2502,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
{
|
||||
if (s != NULL) {
|
||||
if (s->cipher_list != NULL) {
|
||||
- return s->cipher_list;
|
||||
+ return (s->cipher_list->ciphers);
|
||||
} else if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL)) {
|
||||
- return s->ctx->cipher_list;
|
||||
+ return (s->ctx->cipher_list->ciphers);
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
@@ -2512,8 +2578,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
* preference */
|
||||
STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx)
|
||||
{
|
||||
- if (ctx != NULL)
|
||||
- return ctx->cipher_list;
|
||||
+ if (ctx != NULL && ctx->cipher_list != NULL)
|
||||
+ return ctx->cipher_list->ciphers;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -2963,7 +3029,7 @@ SSL_CTX *SSL_CTX_new(const SSL_METHOD *meth)
|
||||
ret->tls13_ciphersuites,
|
||||
&ret->cipher_list, &ret->cipher_list_by_id,
|
||||
SSL_DEFAULT_CIPHER_LIST, ret->cert)
|
||||
- || sk_SSL_CIPHER_num(ret->cipher_list) <= 0) {
|
||||
+ || sk_SSL_CIPHER_num(ret->cipher_list->ciphers) <= 0) {
|
||||
SSLerr(SSL_F_SSL_CTX_NEW, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
goto err2;
|
||||
}
|
||||
@@ -3139,7 +3205,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
#ifndef OPENSSL_NO_CT
|
||||
CTLOG_STORE_free(a->ctlog_store);
|
||||
#endif
|
||||
- sk_SSL_CIPHER_free(a->cipher_list);
|
||||
+ ssl_cipher_preference_list_free(a->cipher_list);
|
||||
sk_SSL_CIPHER_free(a->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(a->tls13_ciphersuites);
|
||||
ssl_cert_free(a->cert);
|
||||
@@ -3817,13 +3883,15 @@ SSL *SSL_dup(SSL *s)
|
||||
|
||||
/* dup the cipher_list and cipher_list_by_id stacks */
|
||||
if (s->cipher_list != NULL) {
|
||||
- if ((ret->cipher_list = sk_SSL_CIPHER_dup(s->cipher_list)) == NULL)
|
||||
+ ret->cipher_list = ssl_cipher_preference_list_dup(s->cipher_list);
|
||||
+ if (ret->cipher_list == NULL)
|
||||
goto err;
|
||||
}
|
||||
- if (s->cipher_list_by_id != NULL)
|
||||
- if ((ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id))
|
||||
- == NULL)
|
||||
+ if (s->cipher_list_by_id != NULL) {
|
||||
+ ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id);
|
||||
+ if (ret->cipher_list_by_id == NULL)
|
||||
goto err;
|
||||
+ }
|
||||
|
||||
/* Dup the client_CA list */
|
||||
if (!dup_ca_names(&ret->ca_names, s->ca_names)
|
||||
diff --git a/ssl/ssl_locl.h b/ssl/ssl_locl.h
|
||||
index 25875c9f6d..23a6093580 100644
|
||||
--- a/ssl/ssl_locl.h
|
||||
+++ b/ssl/ssl_locl.h
|
||||
@@ -733,9 +733,46 @@ typedef struct ssl_ctx_ext_secure_st {
|
||||
unsigned char tick_aes_key[TLSEXT_TICK_KEY_LENGTH];
|
||||
} SSL_CTX_EXT_SECURE;
|
||||
|
||||
+/* ssl_cipher_preference_list_st contains a list of SSL_CIPHERs with
|
||||
+ * equal-preference groups. For TLS clients, the groups are moot because the
|
||||
+ * server picks the cipher and groups cannot be expressed on the wire. However,
|
||||
+ * for servers, the equal-preference groups allow the client's preferences to
|
||||
+ * be partially respected. (This only has an effect with
|
||||
+ * SSL_OP_CIPHER_SERVER_PREFERENCE).
|
||||
+ *
|
||||
+ * The equal-preference groups are expressed by grouping SSL_CIPHERs together.
|
||||
+ * All elements of a group have the same priority: no ordering is expressed
|
||||
+ * within a group.
|
||||
+ *
|
||||
+ * The values in |ciphers| are in one-to-one correspondence with
|
||||
+ * |in_group_flags|. (That is, sk_SSL_CIPHER_num(ciphers) is the number of
|
||||
+ * bytes in |in_group_flags|.) The bytes in |in_group_flags| are either 1, to
|
||||
+ * indicate that the corresponding SSL_CIPHER is not the last element of a
|
||||
+ * group, or 0 to indicate that it is.
|
||||
+ *
|
||||
+ * For example, if |in_group_flags| contains all zeros then that indicates a
|
||||
+ * traditional, fully-ordered preference. Every SSL_CIPHER is the last element
|
||||
+ * of the group (i.e. they are all in a one-element group).
|
||||
+ *
|
||||
+ * For a more complex example, consider:
|
||||
+ * ciphers: A B C D E F
|
||||
+ * in_group_flags: 1 1 0 0 1 0
|
||||
+ *
|
||||
+ * That would express the following, order:
|
||||
+ *
|
||||
+ * A E
|
||||
+ * B -> D -> F
|
||||
+ * C
|
||||
+ */
|
||||
+struct ssl_cipher_preference_list_st {
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers;
|
||||
+ uint8_t *in_group_flags;
|
||||
+};
|
||||
+
|
||||
+
|
||||
struct ssl_ctx_st {
|
||||
const SSL_METHOD *method;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
/* same as above but sorted for lookup */
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
@@ -1131,7 +1168,7 @@ struct ssl_st {
|
||||
SSL_DANE dane;
|
||||
/* crypto */
|
||||
STACK_OF(SSL_CIPHER) *peer_ciphers;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites;
|
||||
@@ -2269,7 +2306,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
const SSL_CIPHER *const *bp);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c);
|
||||
@@ -2279,6 +2316,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_dup(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+void ssl_cipher_preference_list_free(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_from_ciphers(
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers);
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s);
|
||||
__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
const EVP_MD **md, int *mac_pkey_type,
|
||||
size_t *mac_secret_size, SSL_COMP **comp,
|
||||
@@ -2362,7 +2406,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
CERT_PKEY *cpk);
|
||||
__owur const SSL_CIPHER *ssl3_choose_cipher(SSL *ssl,
|
||||
STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr);
|
||||
+ struct ssl_cipher_preference_list_st *srvr);
|
||||
__owur int ssl3_digest_cached_records(SSL *s, int keep);
|
||||
__owur int ssl3_new(SSL *s);
|
||||
void ssl3_free(SSL *s);
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index 8cf9c40d15..46391a7f05 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -1748,7 +1748,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* For TLSv1.3 we must select the ciphersuite *before* session resumption */
|
||||
if (SSL_IS_TLS13(s)) {
|
||||
const SSL_CIPHER *cipher =
|
||||
- ssl3_choose_cipher(s, ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1929,7 +1929,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* check if some cipher was preferred by call back */
|
||||
if (pref_cipher == NULL)
|
||||
pref_cipher = ssl3_choose_cipher(s, s->peer_ciphers,
|
||||
- SSL_get_ciphers(s));
|
||||
+ ssl_get_cipher_preferences(s));
|
||||
if (pref_cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_F_TLS_EARLY_POST_PROCESS_CLIENT_HELLO,
|
||||
@@ -1938,8 +1938,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
}
|
||||
|
||||
s->session->cipher = pref_cipher;
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
+ s->cipher_list = ssl_cipher_preference_list_from_ciphers(
|
||||
+ s->peer_ciphers);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
}
|
||||
@@ -2251,7 +2252,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
/* In TLSv1.3 we selected the ciphersuite before resumption */
|
||||
if (!SSL_IS_TLS13(s)) {
|
||||
cipher =
|
||||
- ssl3_choose_cipher(s, s->peer_ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->peer_ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -0,0 +1,1075 @@
|
||||
diff --git a/doc/man1/ciphers.pod b/doc/man1/ciphers.pod
|
||||
index faf9e53814..428df515f1 100644
|
||||
--- a/doc/man1/ciphers.pod
|
||||
+++ b/doc/man1/ciphers.pod
|
||||
@@ -400,6 +400,21 @@ permissible.
|
||||
|
||||
=back
|
||||
|
||||
+=head1 EQUAL PREFERENCE GROUPS
|
||||
+
|
||||
+If configuring a server, one may also configure equal-preference groups to
|
||||
+partially respect the client's preferences when
|
||||
+B<SSL_OP_CIPHER_SERVER_PREFERENCE> is enabled. Ciphers in an equal-preference
|
||||
+group have equal priority and use the client order. This may be used to
|
||||
+enforce that AEADs are preferred but select AES-GCM vs. ChaCha20-Poly1305
|
||||
+based on client preferences. An equal-preference is specified with square
|
||||
+brackets, combining multiple selectors separated by |. For example:
|
||||
+
|
||||
+ [ECDHE-ECDSA-CHACHA20-POLY1305|ECDHE-ECDSA-AES128-GCM-SHA256]
|
||||
+
|
||||
+ Once an equal-preference group is used, future directives must be
|
||||
+ opcode-less.
|
||||
+
|
||||
=head1 CIPHER SUITE NAMES
|
||||
|
||||
The following lists give the SSL or TLS cipher suites names from the
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 6724ccf2d2..81a5538977 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -173,12 +173,12 @@ extern "C" {
|
||||
# define SSL_DEFAULT_CIPHER_LIST "ALL:!COMPLEMENTOFDEFAULT:!eNULL"
|
||||
/* This is the default set of TLSv1.3 ciphersuites */
|
||||
# if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305)
|
||||
-# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_256_GCM_SHA384:" \
|
||||
+# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_128_GCM_SHA256:" \
|
||||
"TLS_CHACHA20_POLY1305_SHA256:" \
|
||||
- "TLS_AES_128_GCM_SHA256"
|
||||
+ "TLS_AES_256_GCM_SHA384"
|
||||
# else
|
||||
-# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_256_GCM_SHA384:" \
|
||||
- "TLS_AES_128_GCM_SHA256"
|
||||
+# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_128_GCM_SHA256:" \
|
||||
+ "TLS_AES_256_GCM_SHA384"
|
||||
#endif
|
||||
/*
|
||||
* As of OpenSSL 1.0.0, ssl_create_cipher_list() in ssl/ssl_ciph.c always
|
||||
diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h
|
||||
index 3d6850dea3..a3ab4b925f 100644
|
||||
--- a/include/openssl/sslerr.h
|
||||
+++ b/include/openssl/sslerr.h
|
||||
@@ -600,6 +600,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_SUPPORTED_GROUPS_EXTENSION 209
|
||||
# define SSL_R_MISSING_TMP_DH_KEY 171
|
||||
# define SSL_R_MISSING_TMP_ECDH_KEY 311
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 101
|
||||
+# define SSL_R_NESTED_GROUP 108
|
||||
# define SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA 293
|
||||
# define SSL_R_NOT_ON_RECORD_BOUNDARY 182
|
||||
# define SSL_R_NOT_REPLACING_CERTIFICATE 289
|
||||
@@ -731,9 +733,11 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS 239
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES 242
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES 243
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 109
|
||||
# define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
# define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
# define SSL_R_UNEXPECTED_MESSAGE 244
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 110
|
||||
# define SSL_R_UNEXPECTED_RECORD 245
|
||||
# define SSL_R_UNINITIALIZED 276
|
||||
# define SSL_R_UNKNOWN_ALERT_TYPE 246
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 066bf47221..517eda6630 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -167,7 +167,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -232,7 +232,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -296,7 +296,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4124,6 +4124,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
return 1;
|
||||
}
|
||||
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s)
|
||||
+{
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ return (s->cipher_list);
|
||||
+
|
||||
+ if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL))
|
||||
+ return (s->ctx->cipher_list);
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* ssl3_choose_cipher - choose a cipher from those offered by the client
|
||||
* @s: SSL connection
|
||||
@@ -4133,16 +4144,24 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
* Returns the selected cipher or NULL when no common ciphers.
|
||||
*/
|
||||
const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr)
|
||||
+ struct ssl_cipher_preference_list_st
|
||||
+ *server_pref)
|
||||
{
|
||||
const SSL_CIPHER *c, *ret = NULL;
|
||||
- STACK_OF(SSL_CIPHER) *prio, *allow;
|
||||
- int i, ii, ok, prefer_sha256 = 0;
|
||||
+ STACK_OF(SSL_CIPHER) *srvr = server_pref->ciphers, *prio, *allow;
|
||||
+ int i, ii, ok, prefer_sha256 = 0, safari_ec = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
const EVP_MD *mdsha256 = EVP_sha256();
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
-#endif
|
||||
+
|
||||
+ /* in_group_flags will either be NULL, or will point to an array of
|
||||
+ * bytes which indicate equal-preference groups in the |prio| stack.
|
||||
+ * See the comment about |in_group_flags| in the
|
||||
+ * |ssl_cipher_preference_list_st| struct. */
|
||||
+ const uint8_t *in_group_flags;
|
||||
+
|
||||
+ /* group_min contains the minimal index so far found in a group, or -1
|
||||
+ * if no such value exists yet. */
|
||||
+ int group_min = -1;
|
||||
|
||||
/* Let's see which ciphers we can support */
|
||||
|
||||
@@ -4169,54 +4188,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#endif
|
||||
|
||||
/* SUITE-B takes precedence over server preference and ChaCha priortiy */
|
||||
- if (tls1_suiteb(s)) {
|
||||
+ if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE || tls1_suiteb(s)) {
|
||||
prio = srvr;
|
||||
+ in_group_flags = server_pref->in_group_flags;
|
||||
allow = clnt;
|
||||
- } else if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE) {
|
||||
- prio = srvr;
|
||||
- allow = clnt;
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- /* If ChaCha20 is at the top of the client preference list,
|
||||
- and there are ChaCha20 ciphers in the server list, then
|
||||
- temporarily prioritize all ChaCha20 ciphers in the servers list. */
|
||||
- if (s->options & SSL_OP_PRIORITIZE_CHACHA && sk_SSL_CIPHER_num(clnt) > 0) {
|
||||
- c = sk_SSL_CIPHER_value(clnt, 0);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- /* ChaCha20 is client preferred, check server... */
|
||||
- int num = sk_SSL_CIPHER_num(srvr);
|
||||
- int found = 0;
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- found = 1;
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
- if (found) {
|
||||
- prio_chacha = sk_SSL_CIPHER_new_reserve(NULL, num);
|
||||
- /* if reserve fails, then there's likely a memory issue */
|
||||
- if (prio_chacha != NULL) {
|
||||
- /* Put all ChaCha20 at the top, starting with the one we just found */
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- for (i++; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- /* Pull in the rest */
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc != SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- prio = prio_chacha;
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
-# endif
|
||||
} else {
|
||||
prio = clnt;
|
||||
+ in_group_flags = NULL;
|
||||
allow = srvr;
|
||||
}
|
||||
|
||||
@@ -4247,14 +4225,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
|
||||
c = sk_SSL_CIPHER_value(prio, i);
|
||||
|
||||
+ ok = 1;
|
||||
+
|
||||
/* Skip ciphers not supported by the protocol version */
|
||||
if (!SSL_IS_DTLS(s) &&
|
||||
((s->version < c->min_tls) || (s->version > c->max_tls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
if (SSL_IS_DTLS(s) &&
|
||||
(DTLS_VERSION_LT(s->version, c->min_dtls) ||
|
||||
DTLS_VERSION_GT(s->version, c->max_dtls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
|
||||
/*
|
||||
* Since TLS 1.3 ciphersuites can be used with any auth or
|
||||
@@ -4276,10 +4256,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
/* with PSK there must be server callback set */
|
||||
if ((alg_k & SSL_PSK) && s->psk_server_callback == NULL)
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
#endif /* OPENSSL_NO_PSK */
|
||||
|
||||
- ok = (alg_k & mask_k) && (alg_a & mask_a);
|
||||
+ ok = ok && (alg_k & mask_k) && (alg_a & mask_a);
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n", ok, alg_k,
|
||||
alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4296,6 +4276,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
|
||||
if (!ok)
|
||||
continue;
|
||||
+
|
||||
+ safari_ec = 0;
|
||||
+#if !defined(OPENSSL_NO_EC)
|
||||
+ if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)) {
|
||||
+ if (s->s3->is_probably_safari)
|
||||
+ safari_ec = 1;
|
||||
+ }
|
||||
+#endif
|
||||
}
|
||||
ii = sk_SSL_CIPHER_find(allow, c);
|
||||
if (ii >= 0) {
|
||||
@@ -4303,14 +4291,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (!ssl_security(s, SSL_SECOP_CIPHER_SHARED,
|
||||
c->strength_bits, 0, (void *)c))
|
||||
continue;
|
||||
-#if !defined(OPENSSL_NO_EC)
|
||||
- if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)
|
||||
- && s->s3->is_probably_safari) {
|
||||
- if (!ret)
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
- continue;
|
||||
- }
|
||||
-#endif
|
||||
+
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
@@ -4322,13 +4303,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
ret = tmp;
|
||||
continue;
|
||||
}
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+
|
||||
+ if (in_group_flags != NULL && in_group_flags[i] == 1) {
|
||||
+ /* This element of |prio| is in a group. Update
|
||||
+ * the minimum index found so far and continue
|
||||
+ * looking. */
|
||||
+ if (group_min == -1 || group_min > ii)
|
||||
+ group_min = ii;
|
||||
+ } else {
|
||||
+ if (group_min != -1 && group_min < ii)
|
||||
+ ii = group_min;
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (in_group_flags != NULL && !in_group_flags[i] && group_min != -1) {
|
||||
+ /* We are about to leave a group, but we found a match
|
||||
+ * in it, so that's our answer. */
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
break;
|
||||
}
|
||||
}
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- sk_SSL_CIPHER_free(prio_chacha);
|
||||
-#endif
|
||||
return ret;
|
||||
}
|
||||
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 27a1b2ec68..9880a0b363 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -192,6 +192,7 @@ typedef struct cipher_order_st {
|
||||
const SSL_CIPHER *cipher;
|
||||
int active;
|
||||
int dead;
|
||||
+ int in_group;
|
||||
struct cipher_order_st *next, *prev;
|
||||
} CIPHER_ORDER;
|
||||
|
||||
@@ -681,6 +682,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
co_list[co_list_num].next = NULL;
|
||||
co_list[co_list_num].prev = NULL;
|
||||
co_list[co_list_num].active = 0;
|
||||
+ co_list[co_list_num].in_group = 0;
|
||||
co_list_num++;
|
||||
}
|
||||
|
||||
@@ -774,8 +776,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
uint32_t alg_auth, uint32_t alg_enc,
|
||||
uint32_t alg_mac, int min_tls,
|
||||
uint32_t algo_strength, int rule,
|
||||
- int32_t strength_bits, CIPHER_ORDER **head_p,
|
||||
- CIPHER_ORDER **tail_p)
|
||||
+ int32_t strength_bits, int in_group,
|
||||
+ CIPHER_ORDER **head_p, CIPHER_ORDER **tail_p)
|
||||
{
|
||||
CIPHER_ORDER *head, *tail, *curr, *next, *last;
|
||||
const SSL_CIPHER *cp;
|
||||
@@ -783,9 +785,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr,
|
||||
- "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d)\n",
|
||||
+ "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d) g:%d\n",
|
||||
rule, alg_mkey, alg_auth, alg_enc, alg_mac, min_tls,
|
||||
- algo_strength, strength_bits);
|
||||
+ algo_strength, strength_bits, in_group);
|
||||
#endif
|
||||
|
||||
if (rule == CIPHER_DEL || rule == CIPHER_BUMP)
|
||||
@@ -862,6 +864,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
if (!curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
curr->active = 1;
|
||||
+ curr->in_group = in_group;
|
||||
}
|
||||
}
|
||||
/* Move the added cipher to this location */
|
||||
@@ -869,6 +872,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
/* reverse == 0 */
|
||||
if (curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_DEL) {
|
||||
/* reverse == 1 */
|
||||
@@ -880,6 +884,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
*/
|
||||
ll_append_head(&head, curr, &tail);
|
||||
curr->active = 0;
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_BUMP) {
|
||||
if (curr->active)
|
||||
@@ -947,8 +952,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
*/
|
||||
for (i = max_strength_bits; i >= 0; i--)
|
||||
if (number_uses[i] > 0)
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, head_p,
|
||||
- tail_p);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, 0,
|
||||
+ head_p, tail_p);
|
||||
|
||||
OPENSSL_free(number_uses);
|
||||
return 1;
|
||||
@@ -962,7 +967,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
uint32_t alg_mkey, alg_auth, alg_enc, alg_mac, algo_strength;
|
||||
int min_tls;
|
||||
const char *l, *buf;
|
||||
- int j, multi, found, rule, retval, ok, buflen;
|
||||
+ int j, multi, found, rule, retval, ok, buflen, in_group = 0, has_group = 0;
|
||||
uint32_t cipher_id = 0;
|
||||
char ch;
|
||||
|
||||
@@ -973,18 +978,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
|
||||
if (ch == '\0')
|
||||
break; /* done */
|
||||
- if (ch == '-') {
|
||||
+ if (in_group) {
|
||||
+ if (ch == ']') {
|
||||
+ if (!in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_GROUP_CLOSE);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ if (*tail_p)
|
||||
+ (*tail_p)->in_group = 0;
|
||||
+ in_group = 0;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ }
|
||||
+ if (ch == '|') {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ } else if (!(ch >= 'a' && ch <= 'z')
|
||||
+ && !(ch >= 'A' && ch <= 'Z')
|
||||
+ && !(ch >= '0' && ch <= '9')) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_OPERATOR_IN_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ } else {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ }
|
||||
+ } else if (ch == '-') {
|
||||
rule = CIPHER_DEL;
|
||||
l++;
|
||||
} else if (ch == '+') {
|
||||
rule = CIPHER_ORD;
|
||||
l++;
|
||||
+ } else if (ch == '!' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '!') {
|
||||
rule = CIPHER_KILL;
|
||||
l++;
|
||||
+ } else if (ch == '@' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '@') {
|
||||
rule = CIPHER_SPECIAL;
|
||||
l++;
|
||||
+ } else if (ch == '[') {
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_NESTED_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ in_group = 1;
|
||||
+ has_group = 1;
|
||||
+ l++;
|
||||
+ continue;
|
||||
} else {
|
||||
rule = CIPHER_ADD;
|
||||
}
|
||||
@@ -1026,7 +1079,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
* alphanumeric, so we call this an error.
|
||||
*/
|
||||
SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
- retval = found = 0;
|
||||
+ retval = found = in_group = 0;
|
||||
l++;
|
||||
break;
|
||||
}
|
||||
@@ -1205,8 +1258,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
} else if (found) {
|
||||
ssl_cipher_apply_rule(cipher_id,
|
||||
alg_mkey, alg_auth, alg_enc, alg_mac,
|
||||
- min_tls, algo_strength, rule, -1, head_p,
|
||||
- tail_p);
|
||||
+ min_tls, algo_strength, rule, -1, in_group,
|
||||
+ head_p, tail_p);
|
||||
} else {
|
||||
while ((*l != '\0') && !ITEM_SEP(*l))
|
||||
l++;
|
||||
@@ -1215,6 +1268,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
break; /* done */
|
||||
}
|
||||
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
+ retval = 0;
|
||||
+ }
|
||||
+
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1378,7 +1436,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
int ret = set_ciphersuites(&(ctx->tls13_ciphersuites), str);
|
||||
|
||||
if (ret && ctx->cipher_list != NULL)
|
||||
- return update_cipher_list(&ctx->cipher_list, &ctx->cipher_list_by_id,
|
||||
+ return update_cipher_list(&ctx->cipher_list->ciphers, &ctx->cipher_list_by_id,
|
||||
ctx->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1391,10 +1449,10 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (s->cipher_list == NULL) {
|
||||
if ((cipher_list = SSL_get_ciphers(s)) != NULL)
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(cipher_list);
|
||||
+ s->cipher_list->ciphers = sk_SSL_CIPHER_dup(cipher_list);
|
||||
}
|
||||
if (ret && s->cipher_list != NULL)
|
||||
- return update_cipher_list(&s->cipher_list, &s->cipher_list_by_id,
|
||||
+ return update_cipher_list(&s->cipher_list->ciphers, &s->cipher_list_by_id,
|
||||
s->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1402,17 +1460,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c)
|
||||
{
|
||||
- int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i;
|
||||
+ int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i, tls13_len;
|
||||
uint32_t disabled_mkey, disabled_auth, disabled_enc, disabled_mac;
|
||||
- STACK_OF(SSL_CIPHER) *cipherstack;
|
||||
+ STACK_OF(SSL_CIPHER) *cipherstack = NULL;
|
||||
const char *rule_p;
|
||||
CIPHER_ORDER *co_list = NULL, *head = NULL, *tail = NULL, *curr;
|
||||
- const SSL_CIPHER **ca_list = NULL;
|
||||
+ const SSL_CIPHER **ca_list = NULL, *tmp = NULL;
|
||||
+ uint8_t *in_group_flags = NULL;
|
||||
+ unsigned int num_in_group_flags = 0;
|
||||
+ struct ssl_cipher_preference_list_st *pref_list = NULL;
|
||||
|
||||
/*
|
||||
* Return with error if nothing to do.
|
||||
@@ -1461,16 +1522,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* preference).
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, SSL_kECDHE, SSL_aECDSA, 0, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head,
|
||||
- &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head,
|
||||
- &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
+ &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Within each strength group, we prefer GCM over CHACHA... */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1479,13 +1540,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* strength.
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, 0, 0, SSL_AES ^ SSL_AESGCM, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
|
||||
/* Temporarily enable everything else for sorting */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0, &head, &tail);
|
||||
|
||||
/* Low priority for MD5 */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1493,16 +1554,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* disabled. (For applications that allow them, they aren't too bad, but
|
||||
* we prefer authenticated ciphers.)
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
- ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/* RC4 is sort-of broken -- move to the end */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1518,7 +1579,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Partially overrule strength sort to prefer TLS 1.2 ciphers/PRFs.
|
||||
* TODO(openssl-team): is there an easier way to accomplish all this?
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1534,15 +1595,15 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Because we now bump ciphers to the top of the list, we proceed in
|
||||
* reverse order of preference.
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, 0, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, SSL_AEAD, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
|
||||
/* Now disable everything (maintaining the ordering!) */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0, &head, &tail);
|
||||
|
||||
/*
|
||||
* We also need cipher aliases for selecting based on the rule_str.
|
||||
@@ -1556,9 +1617,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
num_of_alias_max = num_of_ciphers + num_of_group_aliases + 1;
|
||||
ca_list = OPENSSL_malloc(sizeof(*ca_list) * num_of_alias_max);
|
||||
if (ca_list == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
SSLerr(SSL_F_SSL_CREATE_CIPHER_LIST, ERR_R_MALLOC_FAILURE);
|
||||
- return NULL; /* Failure */
|
||||
+ goto err; /* Failure */
|
||||
}
|
||||
ssl_cipher_collect_aliases(ca_list, num_of_group_aliases,
|
||||
disabled_mkey, disabled_auth, disabled_enc,
|
||||
@@ -1583,27 +1643,35 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
|
||||
OPENSSL_free(ca_list); /* Not needed anymore */
|
||||
|
||||
- if (!ok) { /* Rule processing failure */
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!ok)
|
||||
+ goto err; /* Rule processing failure */
|
||||
|
||||
/*
|
||||
* Allocate new "cipherstack" for the result, return with error
|
||||
* if we cannot get one.
|
||||
*/
|
||||
- if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL)
|
||||
+ goto err;
|
||||
+
|
||||
+ in_group_flags = OPENSSL_malloc(num_of_ciphers);
|
||||
+ if (!in_group_flags)
|
||||
+ goto err;
|
||||
|
||||
/* Add TLSv1.3 ciphers first - we always prefer those if possible */
|
||||
- for (i = 0; i < sk_SSL_CIPHER_num(tls13_ciphersuites); i++) {
|
||||
+ tls13_len = sk_SSL_CIPHER_num(tls13_ciphersuites);
|
||||
+ for (i = 0; i < tls13_len; i++) {
|
||||
+ tmp = sk_SSL_CIPHER_value(tls13_ciphersuites, i);
|
||||
if (!sk_SSL_CIPHER_push(cipherstack,
|
||||
- sk_SSL_CIPHER_value(tls13_ciphersuites, i))) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
+ tmp))
|
||||
+ goto err;
|
||||
+ /* Temporary - AES128, CHACHA20 priority adjustment of TLS 1.3. */
|
||||
+ if (tmp->algorithm_enc == SSL_AES128GCM &&
|
||||
+ tls13_len > (i + 1)) {
|
||||
+ tmp = sk_SSL_CIPHER_value(tls13_ciphersuites, i + 1);
|
||||
+ in_group_flags[num_in_group_flags++] = (tmp->algorithm_enc == SSL_CHACHA20POLY1305) ? 1 : 0;
|
||||
}
|
||||
+ else
|
||||
+ in_group_flags[num_in_group_flags++] = 0;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -1612,26 +1680,50 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
*/
|
||||
for (curr = head; curr != NULL; curr = curr->next) {
|
||||
if (curr->active) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
- OPENSSL_free(co_list);
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher))
|
||||
+ goto err;
|
||||
+ in_group_flags[num_in_group_flags++] = curr->in_group;
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "<%s>\n", curr->cipher->name);
|
||||
#endif
|
||||
}
|
||||
}
|
||||
- OPENSSL_free(co_list); /* Not needed any longer */
|
||||
|
||||
- if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack)) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- sk_SSL_CIPHER_free(*cipher_list);
|
||||
- *cipher_list = cipherstack;
|
||||
+ OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
+
|
||||
+ if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack))
|
||||
+ goto err;
|
||||
+
|
||||
+ pref_list = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!pref_list)
|
||||
+ goto err;
|
||||
+ pref_list->ciphers = cipherstack;
|
||||
+ pref_list->in_group_flags = OPENSSL_malloc(num_in_group_flags);
|
||||
+ if (!pref_list->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(pref_list->in_group_flags, in_group_flags, num_in_group_flags);
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ in_group_flags = NULL;
|
||||
+ if (*cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(*cipher_list);
|
||||
+ *cipher_list = pref_list;
|
||||
+ pref_list = NULL;
|
||||
|
||||
return cipherstack;
|
||||
+
|
||||
+err:
|
||||
+ if (co_list)
|
||||
+ OPENSSL_free(co_list);
|
||||
+ if (in_group_flags)
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ if (cipherstack)
|
||||
+ sk_SSL_CIPHER_free(cipherstack);
|
||||
+ if (pref_list && pref_list->in_group_flags)
|
||||
+ OPENSSL_free(pref_list->in_group_flags);
|
||||
+ if (pref_list)
|
||||
+ OPENSSL_free(pref_list);
|
||||
+ return NULL;
|
||||
}
|
||||
|
||||
char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
diff --git a/ssl/ssl_err.c b/ssl/ssl_err.c
|
||||
index 4b12ed1485..cd1a95d1d2 100644
|
||||
--- a/ssl/ssl_err.c
|
||||
+++ b/ssl/ssl_err.c
|
||||
@@ -965,6 +965,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_DH_KEY), "missing tmp dh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_ECDH_KEY),
|
||||
"missing tmp ecdh key"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS),
|
||||
+ "mixed special operator with groups"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NESTED_GROUP), "nested group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_ON_RECORD_BOUNDARY),
|
||||
@@ -1201,11 +1204,14 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unable to load ssl3 md5 routines"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES),
|
||||
"unable to load ssl3 sha1 routines"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE), "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_CCS_MESSAGE),
|
||||
"unexpected ccs message"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_END_OF_EARLY_DATA),
|
||||
"unexpected end of early data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_MESSAGE), "unexpected message"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP),
|
||||
+ "unexpected operator in group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_RECORD), "unexpected record"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNINITIALIZED), "uninitialized"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNKNOWN_ALERT_TYPE), "unknown alert type"},
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index ac820cf9fe..141308584c 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -1122,6 +1122,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
return X509_VERIFY_PARAM_set1(ssl->param, vpm);
|
||||
}
|
||||
|
||||
+void ssl_cipher_preference_list_free(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ sk_SSL_CIPHER_free(cipher_list->ciphers);
|
||||
+ OPENSSL_free(cipher_list->in_group_flags);
|
||||
+ OPENSSL_free(cipher_list);
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_dup(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(cipher_list->ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(cipher_list->ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(ret->in_group_flags, cipher_list->in_group_flags, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_from_ciphers(STACK_OF(SSL_CIPHER) *ciphers)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memset(ret->in_group_flags, 0, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx)
|
||||
{
|
||||
return ctx->param;
|
||||
@@ -1162,7 +1227,8 @@ void SSL_free(SSL *s)
|
||||
BUF_MEM_free(s->init_buf);
|
||||
|
||||
/* add extra stuff */
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(s->tls13_ciphersuites);
|
||||
sk_SSL_CIPHER_free(s->peer_ciphers);
|
||||
@@ -2436,9 +2502,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
{
|
||||
if (s != NULL) {
|
||||
if (s->cipher_list != NULL) {
|
||||
- return s->cipher_list;
|
||||
+ return (s->cipher_list->ciphers);
|
||||
} else if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL)) {
|
||||
- return s->ctx->cipher_list;
|
||||
+ return (s->ctx->cipher_list->ciphers);
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
@@ -2512,8 +2578,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
* preference */
|
||||
STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx)
|
||||
{
|
||||
- if (ctx != NULL)
|
||||
- return ctx->cipher_list;
|
||||
+ if (ctx != NULL && ctx->cipher_list != NULL)
|
||||
+ return ctx->cipher_list->ciphers;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -2963,7 +3029,7 @@ SSL_CTX *SSL_CTX_new(const SSL_METHOD *meth)
|
||||
ret->tls13_ciphersuites,
|
||||
&ret->cipher_list, &ret->cipher_list_by_id,
|
||||
SSL_DEFAULT_CIPHER_LIST, ret->cert)
|
||||
- || sk_SSL_CIPHER_num(ret->cipher_list) <= 0) {
|
||||
+ || sk_SSL_CIPHER_num(ret->cipher_list->ciphers) <= 0) {
|
||||
SSLerr(SSL_F_SSL_CTX_NEW, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
goto err2;
|
||||
}
|
||||
@@ -3139,7 +3205,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
#ifndef OPENSSL_NO_CT
|
||||
CTLOG_STORE_free(a->ctlog_store);
|
||||
#endif
|
||||
- sk_SSL_CIPHER_free(a->cipher_list);
|
||||
+ ssl_cipher_preference_list_free(a->cipher_list);
|
||||
sk_SSL_CIPHER_free(a->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(a->tls13_ciphersuites);
|
||||
ssl_cert_free(a->cert);
|
||||
@@ -3817,13 +3883,15 @@ SSL *SSL_dup(SSL *s)
|
||||
|
||||
/* dup the cipher_list and cipher_list_by_id stacks */
|
||||
if (s->cipher_list != NULL) {
|
||||
- if ((ret->cipher_list = sk_SSL_CIPHER_dup(s->cipher_list)) == NULL)
|
||||
+ ret->cipher_list = ssl_cipher_preference_list_dup(s->cipher_list);
|
||||
+ if (ret->cipher_list == NULL)
|
||||
goto err;
|
||||
}
|
||||
- if (s->cipher_list_by_id != NULL)
|
||||
- if ((ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id))
|
||||
- == NULL)
|
||||
+ if (s->cipher_list_by_id != NULL) {
|
||||
+ ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id);
|
||||
+ if (ret->cipher_list_by_id == NULL)
|
||||
goto err;
|
||||
+ }
|
||||
|
||||
/* Dup the client_CA list */
|
||||
if (!dup_ca_names(&ret->ca_names, s->ca_names)
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index 25875c9f6d..23a6093580 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -733,9 +733,46 @@ typedef struct ssl_ctx_ext_secure_st {
|
||||
unsigned char tick_aes_key[TLSEXT_TICK_KEY_LENGTH];
|
||||
} SSL_CTX_EXT_SECURE;
|
||||
|
||||
+/* ssl_cipher_preference_list_st contains a list of SSL_CIPHERs with
|
||||
+ * equal-preference groups. For TLS clients, the groups are moot because the
|
||||
+ * server picks the cipher and groups cannot be expressed on the wire. However,
|
||||
+ * for servers, the equal-preference groups allow the client's preferences to
|
||||
+ * be partially respected. (This only has an effect with
|
||||
+ * SSL_OP_CIPHER_SERVER_PREFERENCE).
|
||||
+ *
|
||||
+ * The equal-preference groups are expressed by grouping SSL_CIPHERs together.
|
||||
+ * All elements of a group have the same priority: no ordering is expressed
|
||||
+ * within a group.
|
||||
+ *
|
||||
+ * The values in |ciphers| are in one-to-one correspondence with
|
||||
+ * |in_group_flags|. (That is, sk_SSL_CIPHER_num(ciphers) is the number of
|
||||
+ * bytes in |in_group_flags|.) The bytes in |in_group_flags| are either 1, to
|
||||
+ * indicate that the corresponding SSL_CIPHER is not the last element of a
|
||||
+ * group, or 0 to indicate that it is.
|
||||
+ *
|
||||
+ * For example, if |in_group_flags| contains all zeros then that indicates a
|
||||
+ * traditional, fully-ordered preference. Every SSL_CIPHER is the last element
|
||||
+ * of the group (i.e. they are all in a one-element group).
|
||||
+ *
|
||||
+ * For a more complex example, consider:
|
||||
+ * ciphers: A B C D E F
|
||||
+ * in_group_flags: 1 1 0 0 1 0
|
||||
+ *
|
||||
+ * That would express the following, order:
|
||||
+ *
|
||||
+ * A E
|
||||
+ * B -> D -> F
|
||||
+ * C
|
||||
+ */
|
||||
+struct ssl_cipher_preference_list_st {
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers;
|
||||
+ uint8_t *in_group_flags;
|
||||
+};
|
||||
+
|
||||
+
|
||||
struct ssl_ctx_st {
|
||||
const SSL_METHOD *method;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
/* same as above but sorted for lookup */
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
@@ -1131,7 +1168,7 @@ struct ssl_st {
|
||||
SSL_DANE dane;
|
||||
/* crypto */
|
||||
STACK_OF(SSL_CIPHER) *peer_ciphers;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites;
|
||||
@@ -2269,7 +2306,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
const SSL_CIPHER *const *bp);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c);
|
||||
@@ -2279,6 +2316,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_dup(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+void ssl_cipher_preference_list_free(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_from_ciphers(
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers);
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s);
|
||||
__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
const EVP_MD **md, int *mac_pkey_type,
|
||||
size_t *mac_secret_size, SSL_COMP **comp,
|
||||
@@ -2362,7 +2406,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
CERT_PKEY *cpk);
|
||||
__owur const SSL_CIPHER *ssl3_choose_cipher(SSL *ssl,
|
||||
STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr);
|
||||
+ struct ssl_cipher_preference_list_st *srvr);
|
||||
__owur int ssl3_digest_cached_records(SSL *s, int keep);
|
||||
__owur int ssl3_new(SSL *s);
|
||||
void ssl3_free(SSL *s);
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index 8cf9c40d15..46391a7f05 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -1748,7 +1748,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* For TLSv1.3 we must select the ciphersuite *before* session resumption */
|
||||
if (SSL_IS_TLS13(s)) {
|
||||
const SSL_CIPHER *cipher =
|
||||
- ssl3_choose_cipher(s, ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1929,7 +1929,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* check if some cipher was preferred by call back */
|
||||
if (pref_cipher == NULL)
|
||||
pref_cipher = ssl3_choose_cipher(s, s->peer_ciphers,
|
||||
- SSL_get_ciphers(s));
|
||||
+ ssl_get_cipher_preferences(s));
|
||||
if (pref_cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_F_TLS_EARLY_POST_PROCESS_CLIENT_HELLO,
|
||||
@@ -1938,8 +1938,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
}
|
||||
|
||||
s->session->cipher = pref_cipher;
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
+ s->cipher_list = ssl_cipher_preference_list_from_ciphers(
|
||||
+ s->peer_ciphers);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
}
|
||||
@@ -2251,7 +2252,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
/* In TLSv1.3 we selected the ciphersuite before resumption */
|
||||
if (!SSL_IS_TLS13(s)) {
|
||||
cipher =
|
||||
- ssl3_choose_cipher(s, s->peer_ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->peer_ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -0,0 +1,1110 @@
|
||||
diff --git a/doc/man1/ciphers.pod b/doc/man1/ciphers.pod
|
||||
index faf9e53814..428df515f1 100644
|
||||
--- a/doc/man1/ciphers.pod
|
||||
+++ b/doc/man1/ciphers.pod
|
||||
@@ -400,6 +400,21 @@ permissible.
|
||||
|
||||
=back
|
||||
|
||||
+=head1 EQUAL PREFERENCE GROUPS
|
||||
+
|
||||
+If configuring a server, one may also configure equal-preference groups to
|
||||
+partially respect the client's preferences when
|
||||
+B<SSL_OP_CIPHER_SERVER_PREFERENCE> is enabled. Ciphers in an equal-preference
|
||||
+group have equal priority and use the client order. This may be used to
|
||||
+enforce that AEADs are preferred but select AES-GCM vs. ChaCha20-Poly1305
|
||||
+based on client preferences. An equal-preference is specified with square
|
||||
+brackets, combining multiple selectors separated by |. For example:
|
||||
+
|
||||
+ [ECDHE-ECDSA-CHACHA20-POLY1305|ECDHE-ECDSA-AES128-GCM-SHA256]
|
||||
+
|
||||
+ Once an equal-preference group is used, future directives must be
|
||||
+ opcode-less.
|
||||
+
|
||||
=head1 CIPHER SUITE NAMES
|
||||
|
||||
The following lists give the SSL or TLS cipher suites names from the
|
||||
diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h
|
||||
index 3d6850dea3..a3ab4b925f 100644
|
||||
--- a/include/openssl/sslerr.h
|
||||
+++ b/include/openssl/sslerr.h
|
||||
@@ -600,6 +600,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_SUPPORTED_GROUPS_EXTENSION 209
|
||||
# define SSL_R_MISSING_TMP_DH_KEY 171
|
||||
# define SSL_R_MISSING_TMP_ECDH_KEY 311
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 101
|
||||
+# define SSL_R_NESTED_GROUP 108
|
||||
# define SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA 293
|
||||
# define SSL_R_NOT_ON_RECORD_BOUNDARY 182
|
||||
# define SSL_R_NOT_REPLACING_CERTIFICATE 289
|
||||
@@ -731,9 +733,11 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS 239
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES 242
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES 243
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 109
|
||||
# define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
# define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
# define SSL_R_UNEXPECTED_MESSAGE 244
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 110
|
||||
# define SSL_R_UNEXPECTED_RECORD 245
|
||||
# define SSL_R_UNINITIALIZED 276
|
||||
# define SSL_R_UNKNOWN_ALERT_TYPE 246
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 066bf47221..6d56b27473 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -31,7 +31,25 @@ const unsigned char tls12downgrade[] = {
|
||||
};
|
||||
|
||||
/* The list of available TLSv1.3 ciphers */
|
||||
+/* Since nginx can not set the TLS 1.3 cipher, remove it temporarily. */
|
||||
static SSL_CIPHER tls13_ciphers[] = {
|
||||
+ {
|
||||
+ 0,
|
||||
+ }
|
||||
+};
|
||||
+
|
||||
+/*
|
||||
+ * The list of available ciphers, mostly organized into the following
|
||||
+ * groups:
|
||||
+ * Always there
|
||||
+ * EC
|
||||
+ * PSK
|
||||
+ * SRP (within that: RSA EC PSK)
|
||||
+ * Cipher families: Chacha/poly, Camellia, Gost, IDEA, SEED
|
||||
+ * Weak ciphers
|
||||
+ */
|
||||
+static SSL_CIPHER ssl3_ciphers[] = {
|
||||
+ /* TLSv1.3 ciphers */
|
||||
{
|
||||
1,
|
||||
TLS1_3_RFC_AES_128_GCM_SHA256,
|
||||
@@ -111,20 +129,8 @@ static SSL_CIPHER tls13_ciphers[] = {
|
||||
SSL_HANDSHAKE_MAC_SHA256,
|
||||
128,
|
||||
128,
|
||||
- }
|
||||
-};
|
||||
-
|
||||
-/*
|
||||
- * The list of available ciphers, mostly organized into the following
|
||||
- * groups:
|
||||
- * Always there
|
||||
- * EC
|
||||
- * PSK
|
||||
- * SRP (within that: RSA EC PSK)
|
||||
- * Cipher families: Chacha/poly, Camellia, Gost, IDEA, SEED
|
||||
- * Weak ciphers
|
||||
- */
|
||||
-static SSL_CIPHER ssl3_ciphers[] = {
|
||||
+ },
|
||||
+ /* List of cipher below TLSv1.3 */
|
||||
{
|
||||
1,
|
||||
SSL3_TXT_RSA_NULL_MD5,
|
||||
@@ -167,7 +173,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -232,7 +238,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -296,7 +302,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4124,6 +4130,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
return 1;
|
||||
}
|
||||
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s)
|
||||
+{
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ return (s->cipher_list);
|
||||
+
|
||||
+ if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL))
|
||||
+ return (s->ctx->cipher_list);
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* ssl3_choose_cipher - choose a cipher from those offered by the client
|
||||
* @s: SSL connection
|
||||
@@ -4133,16 +4150,24 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
* Returns the selected cipher or NULL when no common ciphers.
|
||||
*/
|
||||
const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr)
|
||||
+ struct ssl_cipher_preference_list_st
|
||||
+ *server_pref)
|
||||
{
|
||||
const SSL_CIPHER *c, *ret = NULL;
|
||||
- STACK_OF(SSL_CIPHER) *prio, *allow;
|
||||
- int i, ii, ok, prefer_sha256 = 0;
|
||||
+ STACK_OF(SSL_CIPHER) *srvr = server_pref->ciphers, *prio, *allow;
|
||||
+ int i, ii, ok, prefer_sha256 = 0, safari_ec = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
const EVP_MD *mdsha256 = EVP_sha256();
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
-#endif
|
||||
+
|
||||
+ /* in_group_flags will either be NULL, or will point to an array of
|
||||
+ * bytes which indicate equal-preference groups in the |prio| stack.
|
||||
+ * See the comment about |in_group_flags| in the
|
||||
+ * |ssl_cipher_preference_list_st| struct. */
|
||||
+ const uint8_t *in_group_flags;
|
||||
+
|
||||
+ /* group_min contains the minimal index so far found in a group, or -1
|
||||
+ * if no such value exists yet. */
|
||||
+ int group_min = -1;
|
||||
|
||||
/* Let's see which ciphers we can support */
|
||||
|
||||
@@ -4169,54 +4194,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#endif
|
||||
|
||||
/* SUITE-B takes precedence over server preference and ChaCha priortiy */
|
||||
- if (tls1_suiteb(s)) {
|
||||
+ if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE || tls1_suiteb(s)) {
|
||||
prio = srvr;
|
||||
+ in_group_flags = server_pref->in_group_flags;
|
||||
allow = clnt;
|
||||
- } else if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE) {
|
||||
- prio = srvr;
|
||||
- allow = clnt;
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- /* If ChaCha20 is at the top of the client preference list,
|
||||
- and there are ChaCha20 ciphers in the server list, then
|
||||
- temporarily prioritize all ChaCha20 ciphers in the servers list. */
|
||||
- if (s->options & SSL_OP_PRIORITIZE_CHACHA && sk_SSL_CIPHER_num(clnt) > 0) {
|
||||
- c = sk_SSL_CIPHER_value(clnt, 0);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- /* ChaCha20 is client preferred, check server... */
|
||||
- int num = sk_SSL_CIPHER_num(srvr);
|
||||
- int found = 0;
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- found = 1;
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
- if (found) {
|
||||
- prio_chacha = sk_SSL_CIPHER_new_reserve(NULL, num);
|
||||
- /* if reserve fails, then there's likely a memory issue */
|
||||
- if (prio_chacha != NULL) {
|
||||
- /* Put all ChaCha20 at the top, starting with the one we just found */
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- for (i++; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- /* Pull in the rest */
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc != SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- prio = prio_chacha;
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
-# endif
|
||||
} else {
|
||||
prio = clnt;
|
||||
+ in_group_flags = NULL;
|
||||
allow = srvr;
|
||||
}
|
||||
|
||||
@@ -4247,14 +4231,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
|
||||
c = sk_SSL_CIPHER_value(prio, i);
|
||||
|
||||
+ ok = 1;
|
||||
+
|
||||
/* Skip ciphers not supported by the protocol version */
|
||||
if (!SSL_IS_DTLS(s) &&
|
||||
((s->version < c->min_tls) || (s->version > c->max_tls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
if (SSL_IS_DTLS(s) &&
|
||||
(DTLS_VERSION_LT(s->version, c->min_dtls) ||
|
||||
DTLS_VERSION_GT(s->version, c->max_dtls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
|
||||
/*
|
||||
* Since TLS 1.3 ciphersuites can be used with any auth or
|
||||
@@ -4276,10 +4262,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
/* with PSK there must be server callback set */
|
||||
if ((alg_k & SSL_PSK) && s->psk_server_callback == NULL)
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
#endif /* OPENSSL_NO_PSK */
|
||||
|
||||
- ok = (alg_k & mask_k) && (alg_a & mask_a);
|
||||
+ ok = ok && (alg_k & mask_k) && (alg_a & mask_a);
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n", ok, alg_k,
|
||||
alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4296,6 +4282,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
|
||||
if (!ok)
|
||||
continue;
|
||||
+
|
||||
+ safari_ec = 0;
|
||||
+#if !defined(OPENSSL_NO_EC)
|
||||
+ if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)) {
|
||||
+ if (s->s3->is_probably_safari)
|
||||
+ safari_ec = 1;
|
||||
+ }
|
||||
+#endif
|
||||
}
|
||||
ii = sk_SSL_CIPHER_find(allow, c);
|
||||
if (ii >= 0) {
|
||||
@@ -4303,14 +4297,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (!ssl_security(s, SSL_SECOP_CIPHER_SHARED,
|
||||
c->strength_bits, 0, (void *)c))
|
||||
continue;
|
||||
-#if !defined(OPENSSL_NO_EC)
|
||||
- if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)
|
||||
- && s->s3->is_probably_safari) {
|
||||
- if (!ret)
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
- continue;
|
||||
- }
|
||||
-#endif
|
||||
+
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
@@ -4322,13 +4309,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
ret = tmp;
|
||||
continue;
|
||||
}
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+
|
||||
+ if (in_group_flags != NULL && in_group_flags[i] == 1) {
|
||||
+ /* This element of |prio| is in a group. Update
|
||||
+ * the minimum index found so far and continue
|
||||
+ * looking. */
|
||||
+ if (group_min == -1 || group_min > ii)
|
||||
+ group_min = ii;
|
||||
+ } else {
|
||||
+ if (group_min != -1 && group_min < ii)
|
||||
+ ii = group_min;
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (in_group_flags != NULL && !in_group_flags[i] && group_min != -1) {
|
||||
+ /* We are about to leave a group, but we found a match
|
||||
+ * in it, so that's our answer. */
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
break;
|
||||
}
|
||||
}
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- sk_SSL_CIPHER_free(prio_chacha);
|
||||
-#endif
|
||||
return ret;
|
||||
}
|
||||
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 27a1b2ec68..111a39229a 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -192,6 +192,7 @@ typedef struct cipher_order_st {
|
||||
const SSL_CIPHER *cipher;
|
||||
int active;
|
||||
int dead;
|
||||
+ int in_group;
|
||||
struct cipher_order_st *next, *prev;
|
||||
} CIPHER_ORDER;
|
||||
|
||||
@@ -296,6 +297,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_TLSV1, NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, "TLSv1.0", NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, SSL_TXT_TLSV1_2, NULL, 0, 0, 0, 0, 0, TLS1_2_VERSION},
|
||||
+ {0, "TLS13", NULL, 0, 0, 0, 0, 0, TLS1_3_VERSION},
|
||||
|
||||
/* strength classes */
|
||||
{0, SSL_TXT_LOW, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_LOW},
|
||||
@@ -681,6 +683,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
co_list[co_list_num].next = NULL;
|
||||
co_list[co_list_num].prev = NULL;
|
||||
co_list[co_list_num].active = 0;
|
||||
+ co_list[co_list_num].in_group = 0;
|
||||
co_list_num++;
|
||||
}
|
||||
|
||||
@@ -774,8 +777,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
uint32_t alg_auth, uint32_t alg_enc,
|
||||
uint32_t alg_mac, int min_tls,
|
||||
uint32_t algo_strength, int rule,
|
||||
- int32_t strength_bits, CIPHER_ORDER **head_p,
|
||||
- CIPHER_ORDER **tail_p)
|
||||
+ int32_t strength_bits, int in_group,
|
||||
+ CIPHER_ORDER **head_p, CIPHER_ORDER **tail_p)
|
||||
{
|
||||
CIPHER_ORDER *head, *tail, *curr, *next, *last;
|
||||
const SSL_CIPHER *cp;
|
||||
@@ -783,9 +786,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr,
|
||||
- "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d)\n",
|
||||
+ "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d) g:%d\n",
|
||||
rule, alg_mkey, alg_auth, alg_enc, alg_mac, min_tls,
|
||||
- algo_strength, strength_bits);
|
||||
+ algo_strength, strength_bits, in_group);
|
||||
#endif
|
||||
|
||||
if (rule == CIPHER_DEL || rule == CIPHER_BUMP)
|
||||
@@ -862,6 +865,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
if (!curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
curr->active = 1;
|
||||
+ curr->in_group = in_group;
|
||||
}
|
||||
}
|
||||
/* Move the added cipher to this location */
|
||||
@@ -869,6 +873,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
/* reverse == 0 */
|
||||
if (curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_DEL) {
|
||||
/* reverse == 1 */
|
||||
@@ -880,6 +885,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
*/
|
||||
ll_append_head(&head, curr, &tail);
|
||||
curr->active = 0;
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_BUMP) {
|
||||
if (curr->active)
|
||||
@@ -947,8 +953,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
*/
|
||||
for (i = max_strength_bits; i >= 0; i--)
|
||||
if (number_uses[i] > 0)
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, head_p,
|
||||
- tail_p);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, 0,
|
||||
+ head_p, tail_p);
|
||||
|
||||
OPENSSL_free(number_uses);
|
||||
return 1;
|
||||
@@ -962,7 +968,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
uint32_t alg_mkey, alg_auth, alg_enc, alg_mac, algo_strength;
|
||||
int min_tls;
|
||||
const char *l, *buf;
|
||||
- int j, multi, found, rule, retval, ok, buflen;
|
||||
+ int j, multi, found, rule, retval, ok, buflen, in_group = 0, has_group = 0;
|
||||
uint32_t cipher_id = 0;
|
||||
char ch;
|
||||
|
||||
@@ -973,18 +979,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
|
||||
if (ch == '\0')
|
||||
break; /* done */
|
||||
- if (ch == '-') {
|
||||
+ if (in_group) {
|
||||
+ if (ch == ']') {
|
||||
+ if (!in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_GROUP_CLOSE);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ if (*tail_p)
|
||||
+ (*tail_p)->in_group = 0;
|
||||
+ in_group = 0;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ }
|
||||
+ if (ch == '|') {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ } else if (!(ch >= 'a' && ch <= 'z')
|
||||
+ && !(ch >= 'A' && ch <= 'Z')
|
||||
+ && !(ch >= '0' && ch <= '9')) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_OPERATOR_IN_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ } else {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ }
|
||||
+ } else if (ch == '-') {
|
||||
rule = CIPHER_DEL;
|
||||
l++;
|
||||
} else if (ch == '+') {
|
||||
rule = CIPHER_ORD;
|
||||
l++;
|
||||
+ } else if (ch == '!' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '!') {
|
||||
rule = CIPHER_KILL;
|
||||
l++;
|
||||
+ } else if (ch == '@' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '@') {
|
||||
rule = CIPHER_SPECIAL;
|
||||
l++;
|
||||
+ } else if (ch == '[') {
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_NESTED_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ in_group = 1;
|
||||
+ has_group = 1;
|
||||
+ l++;
|
||||
+ continue;
|
||||
} else {
|
||||
rule = CIPHER_ADD;
|
||||
}
|
||||
@@ -1009,7 +1063,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
while (((ch >= 'A') && (ch <= 'Z')) ||
|
||||
((ch >= '0') && (ch <= '9')) ||
|
||||
((ch >= 'a') && (ch <= 'z')) ||
|
||||
- (ch == '-') || (ch == '.') || (ch == '='))
|
||||
+ (ch == '-') || (ch == '.') || (ch == '=') || (ch == '_'))
|
||||
#else
|
||||
while (isalnum((unsigned char)ch) || (ch == '-') || (ch == '.')
|
||||
|| (ch == '='))
|
||||
@@ -1026,7 +1080,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
* alphanumeric, so we call this an error.
|
||||
*/
|
||||
SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
- retval = found = 0;
|
||||
+ retval = found = in_group = 0;
|
||||
l++;
|
||||
break;
|
||||
}
|
||||
@@ -1205,8 +1259,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
} else if (found) {
|
||||
ssl_cipher_apply_rule(cipher_id,
|
||||
alg_mkey, alg_auth, alg_enc, alg_mac,
|
||||
- min_tls, algo_strength, rule, -1, head_p,
|
||||
- tail_p);
|
||||
+ min_tls, algo_strength, rule, -1, in_group,
|
||||
+ head_p, tail_p);
|
||||
} else {
|
||||
while ((*l != '\0') && !ITEM_SEP(*l))
|
||||
l++;
|
||||
@@ -1215,6 +1269,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
break; /* done */
|
||||
}
|
||||
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
+ retval = 0;
|
||||
+ }
|
||||
+
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1378,7 +1437,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
int ret = set_ciphersuites(&(ctx->tls13_ciphersuites), str);
|
||||
|
||||
if (ret && ctx->cipher_list != NULL)
|
||||
- return update_cipher_list(&ctx->cipher_list, &ctx->cipher_list_by_id,
|
||||
+ return update_cipher_list(&ctx->cipher_list->ciphers, &ctx->cipher_list_by_id,
|
||||
ctx->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1391,10 +1450,10 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (s->cipher_list == NULL) {
|
||||
if ((cipher_list = SSL_get_ciphers(s)) != NULL)
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(cipher_list);
|
||||
+ s->cipher_list->ciphers = sk_SSL_CIPHER_dup(cipher_list);
|
||||
}
|
||||
if (ret && s->cipher_list != NULL)
|
||||
- return update_cipher_list(&s->cipher_list, &s->cipher_list_by_id,
|
||||
+ return update_cipher_list(&s->cipher_list->ciphers, &s->cipher_list_by_id,
|
||||
s->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1402,17 +1461,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c)
|
||||
{
|
||||
- int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i;
|
||||
+ int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases;
|
||||
uint32_t disabled_mkey, disabled_auth, disabled_enc, disabled_mac;
|
||||
- STACK_OF(SSL_CIPHER) *cipherstack;
|
||||
+ STACK_OF(SSL_CIPHER) *cipherstack = NULL;
|
||||
const char *rule_p;
|
||||
CIPHER_ORDER *co_list = NULL, *head = NULL, *tail = NULL, *curr;
|
||||
const SSL_CIPHER **ca_list = NULL;
|
||||
+ uint8_t *in_group_flags = NULL;
|
||||
+ unsigned int num_in_group_flags = 0;
|
||||
+ struct ssl_cipher_preference_list_st *pref_list = NULL;
|
||||
|
||||
/*
|
||||
* Return with error if nothing to do.
|
||||
@@ -1461,16 +1523,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* preference).
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, SSL_kECDHE, SSL_aECDSA, 0, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head,
|
||||
- &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head,
|
||||
- &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
+ &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Within each strength group, we prefer GCM over CHACHA... */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1479,13 +1541,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* strength.
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, 0, 0, SSL_AES ^ SSL_AESGCM, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
|
||||
/* Temporarily enable everything else for sorting */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0, &head, &tail);
|
||||
|
||||
/* Low priority for MD5 */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1493,16 +1555,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* disabled. (For applications that allow them, they aren't too bad, but
|
||||
* we prefer authenticated ciphers.)
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
- ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/* RC4 is sort-of broken -- move to the end */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1518,7 +1580,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Partially overrule strength sort to prefer TLS 1.2 ciphers/PRFs.
|
||||
* TODO(openssl-team): is there an easier way to accomplish all this?
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1534,15 +1596,18 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Because we now bump ciphers to the top of the list, we proceed in
|
||||
* reverse order of preference.
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, 0, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, SSL_AEAD, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
+
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_3_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Now disable everything (maintaining the ordering!) */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0, &head, &tail);
|
||||
|
||||
/*
|
||||
* We also need cipher aliases for selecting based on the rule_str.
|
||||
@@ -1556,9 +1621,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
num_of_alias_max = num_of_ciphers + num_of_group_aliases + 1;
|
||||
ca_list = OPENSSL_malloc(sizeof(*ca_list) * num_of_alias_max);
|
||||
if (ca_list == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
SSLerr(SSL_F_SSL_CREATE_CIPHER_LIST, ERR_R_MALLOC_FAILURE);
|
||||
- return NULL; /* Failure */
|
||||
+ goto err; /* Failure */
|
||||
}
|
||||
ssl_cipher_collect_aliases(ca_list, num_of_group_aliases,
|
||||
disabled_mkey, disabled_auth, disabled_enc,
|
||||
@@ -1583,28 +1647,19 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
|
||||
OPENSSL_free(ca_list); /* Not needed anymore */
|
||||
|
||||
- if (!ok) { /* Rule processing failure */
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!ok)
|
||||
+ goto err; /* Rule processing failure */
|
||||
|
||||
/*
|
||||
* Allocate new "cipherstack" for the result, return with error
|
||||
* if we cannot get one.
|
||||
*/
|
||||
- if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL)
|
||||
+ goto err;
|
||||
|
||||
- /* Add TLSv1.3 ciphers first - we always prefer those if possible */
|
||||
- for (i = 0; i < sk_SSL_CIPHER_num(tls13_ciphersuites); i++) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack,
|
||||
- sk_SSL_CIPHER_value(tls13_ciphersuites, i))) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- }
|
||||
+ in_group_flags = OPENSSL_malloc(num_of_ciphers);
|
||||
+ if (!in_group_flags)
|
||||
+ goto err;
|
||||
|
||||
/*
|
||||
* The cipher selection for the list is done. The ciphers are added
|
||||
@@ -1612,26 +1667,50 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
*/
|
||||
for (curr = head; curr != NULL; curr = curr->next) {
|
||||
if (curr->active) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
- OPENSSL_free(co_list);
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher))
|
||||
+ goto err;
|
||||
+ in_group_flags[num_in_group_flags++] = curr->in_group;
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "<%s>\n", curr->cipher->name);
|
||||
#endif
|
||||
}
|
||||
}
|
||||
- OPENSSL_free(co_list); /* Not needed any longer */
|
||||
|
||||
- if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack)) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- sk_SSL_CIPHER_free(*cipher_list);
|
||||
- *cipher_list = cipherstack;
|
||||
+ OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
+
|
||||
+ if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack))
|
||||
+ goto err;
|
||||
+
|
||||
+ pref_list = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!pref_list)
|
||||
+ goto err;
|
||||
+ pref_list->ciphers = cipherstack;
|
||||
+ pref_list->in_group_flags = OPENSSL_malloc(num_in_group_flags);
|
||||
+ if (!pref_list->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(pref_list->in_group_flags, in_group_flags, num_in_group_flags);
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ in_group_flags = NULL;
|
||||
+ if (*cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(*cipher_list);
|
||||
+ *cipher_list = pref_list;
|
||||
+ pref_list = NULL;
|
||||
|
||||
return cipherstack;
|
||||
+
|
||||
+err:
|
||||
+ if (co_list)
|
||||
+ OPENSSL_free(co_list);
|
||||
+ if (in_group_flags)
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ if (cipherstack)
|
||||
+ sk_SSL_CIPHER_free(cipherstack);
|
||||
+ if (pref_list && pref_list->in_group_flags)
|
||||
+ OPENSSL_free(pref_list->in_group_flags);
|
||||
+ if (pref_list)
|
||||
+ OPENSSL_free(pref_list);
|
||||
+ return NULL;
|
||||
}
|
||||
|
||||
char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
diff --git a/ssl/ssl_err.c b/ssl/ssl_err.c
|
||||
index 4b12ed1485..cd1a95d1d2 100644
|
||||
--- a/ssl/ssl_err.c
|
||||
+++ b/ssl/ssl_err.c
|
||||
@@ -965,6 +965,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_DH_KEY), "missing tmp dh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_ECDH_KEY),
|
||||
"missing tmp ecdh key"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS),
|
||||
+ "mixed special operator with groups"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NESTED_GROUP), "nested group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_ON_RECORD_BOUNDARY),
|
||||
@@ -1201,11 +1204,14 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unable to load ssl3 md5 routines"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES),
|
||||
"unable to load ssl3 sha1 routines"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE), "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_CCS_MESSAGE),
|
||||
"unexpected ccs message"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_END_OF_EARLY_DATA),
|
||||
"unexpected end of early data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_MESSAGE), "unexpected message"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP),
|
||||
+ "unexpected operator in group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_RECORD), "unexpected record"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNINITIALIZED), "uninitialized"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNKNOWN_ALERT_TYPE), "unknown alert type"},
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index ac820cf9fe..141308584c 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -1122,6 +1122,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
return X509_VERIFY_PARAM_set1(ssl->param, vpm);
|
||||
}
|
||||
|
||||
+void ssl_cipher_preference_list_free(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ sk_SSL_CIPHER_free(cipher_list->ciphers);
|
||||
+ OPENSSL_free(cipher_list->in_group_flags);
|
||||
+ OPENSSL_free(cipher_list);
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_dup(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(cipher_list->ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(cipher_list->ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(ret->in_group_flags, cipher_list->in_group_flags, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_from_ciphers(STACK_OF(SSL_CIPHER) *ciphers)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memset(ret->in_group_flags, 0, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx)
|
||||
{
|
||||
return ctx->param;
|
||||
@@ -1162,7 +1227,8 @@ void SSL_free(SSL *s)
|
||||
BUF_MEM_free(s->init_buf);
|
||||
|
||||
/* add extra stuff */
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(s->tls13_ciphersuites);
|
||||
sk_SSL_CIPHER_free(s->peer_ciphers);
|
||||
@@ -2436,9 +2502,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
{
|
||||
if (s != NULL) {
|
||||
if (s->cipher_list != NULL) {
|
||||
- return s->cipher_list;
|
||||
+ return (s->cipher_list->ciphers);
|
||||
} else if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL)) {
|
||||
- return s->ctx->cipher_list;
|
||||
+ return (s->ctx->cipher_list->ciphers);
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
@@ -2512,8 +2578,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
* preference */
|
||||
STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx)
|
||||
{
|
||||
- if (ctx != NULL)
|
||||
- return ctx->cipher_list;
|
||||
+ if (ctx != NULL && ctx->cipher_list != NULL)
|
||||
+ return ctx->cipher_list->ciphers;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -2963,7 +3029,7 @@ SSL_CTX *SSL_CTX_new(const SSL_METHOD *meth)
|
||||
ret->tls13_ciphersuites,
|
||||
&ret->cipher_list, &ret->cipher_list_by_id,
|
||||
SSL_DEFAULT_CIPHER_LIST, ret->cert)
|
||||
- || sk_SSL_CIPHER_num(ret->cipher_list) <= 0) {
|
||||
+ || sk_SSL_CIPHER_num(ret->cipher_list->ciphers) <= 0) {
|
||||
SSLerr(SSL_F_SSL_CTX_NEW, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
goto err2;
|
||||
}
|
||||
@@ -3139,7 +3205,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
#ifndef OPENSSL_NO_CT
|
||||
CTLOG_STORE_free(a->ctlog_store);
|
||||
#endif
|
||||
- sk_SSL_CIPHER_free(a->cipher_list);
|
||||
+ ssl_cipher_preference_list_free(a->cipher_list);
|
||||
sk_SSL_CIPHER_free(a->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(a->tls13_ciphersuites);
|
||||
ssl_cert_free(a->cert);
|
||||
@@ -3817,13 +3883,15 @@ SSL *SSL_dup(SSL *s)
|
||||
|
||||
/* dup the cipher_list and cipher_list_by_id stacks */
|
||||
if (s->cipher_list != NULL) {
|
||||
- if ((ret->cipher_list = sk_SSL_CIPHER_dup(s->cipher_list)) == NULL)
|
||||
+ ret->cipher_list = ssl_cipher_preference_list_dup(s->cipher_list);
|
||||
+ if (ret->cipher_list == NULL)
|
||||
goto err;
|
||||
}
|
||||
- if (s->cipher_list_by_id != NULL)
|
||||
- if ((ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id))
|
||||
- == NULL)
|
||||
+ if (s->cipher_list_by_id != NULL) {
|
||||
+ ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id);
|
||||
+ if (ret->cipher_list_by_id == NULL)
|
||||
goto err;
|
||||
+ }
|
||||
|
||||
/* Dup the client_CA list */
|
||||
if (!dup_ca_names(&ret->ca_names, s->ca_names)
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index 25875c9f6d..23a6093580 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -733,9 +733,46 @@ typedef struct ssl_ctx_ext_secure_st {
|
||||
unsigned char tick_aes_key[TLSEXT_TICK_KEY_LENGTH];
|
||||
} SSL_CTX_EXT_SECURE;
|
||||
|
||||
+/* ssl_cipher_preference_list_st contains a list of SSL_CIPHERs with
|
||||
+ * equal-preference groups. For TLS clients, the groups are moot because the
|
||||
+ * server picks the cipher and groups cannot be expressed on the wire. However,
|
||||
+ * for servers, the equal-preference groups allow the client's preferences to
|
||||
+ * be partially respected. (This only has an effect with
|
||||
+ * SSL_OP_CIPHER_SERVER_PREFERENCE).
|
||||
+ *
|
||||
+ * The equal-preference groups are expressed by grouping SSL_CIPHERs together.
|
||||
+ * All elements of a group have the same priority: no ordering is expressed
|
||||
+ * within a group.
|
||||
+ *
|
||||
+ * The values in |ciphers| are in one-to-one correspondence with
|
||||
+ * |in_group_flags|. (That is, sk_SSL_CIPHER_num(ciphers) is the number of
|
||||
+ * bytes in |in_group_flags|.) The bytes in |in_group_flags| are either 1, to
|
||||
+ * indicate that the corresponding SSL_CIPHER is not the last element of a
|
||||
+ * group, or 0 to indicate that it is.
|
||||
+ *
|
||||
+ * For example, if |in_group_flags| contains all zeros then that indicates a
|
||||
+ * traditional, fully-ordered preference. Every SSL_CIPHER is the last element
|
||||
+ * of the group (i.e. they are all in a one-element group).
|
||||
+ *
|
||||
+ * For a more complex example, consider:
|
||||
+ * ciphers: A B C D E F
|
||||
+ * in_group_flags: 1 1 0 0 1 0
|
||||
+ *
|
||||
+ * That would express the following, order:
|
||||
+ *
|
||||
+ * A E
|
||||
+ * B -> D -> F
|
||||
+ * C
|
||||
+ */
|
||||
+struct ssl_cipher_preference_list_st {
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers;
|
||||
+ uint8_t *in_group_flags;
|
||||
+};
|
||||
+
|
||||
+
|
||||
struct ssl_ctx_st {
|
||||
const SSL_METHOD *method;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
/* same as above but sorted for lookup */
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
@@ -1131,7 +1168,7 @@ struct ssl_st {
|
||||
SSL_DANE dane;
|
||||
/* crypto */
|
||||
STACK_OF(SSL_CIPHER) *peer_ciphers;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites;
|
||||
@@ -2269,7 +2306,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
const SSL_CIPHER *const *bp);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c);
|
||||
@@ -2279,6 +2316,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_dup(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+void ssl_cipher_preference_list_free(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_from_ciphers(
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers);
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s);
|
||||
__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
const EVP_MD **md, int *mac_pkey_type,
|
||||
size_t *mac_secret_size, SSL_COMP **comp,
|
||||
@@ -2362,7 +2406,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
CERT_PKEY *cpk);
|
||||
__owur const SSL_CIPHER *ssl3_choose_cipher(SSL *ssl,
|
||||
STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr);
|
||||
+ struct ssl_cipher_preference_list_st *srvr);
|
||||
__owur int ssl3_digest_cached_records(SSL *s, int keep);
|
||||
__owur int ssl3_new(SSL *s);
|
||||
void ssl3_free(SSL *s);
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index 8cf9c40d15..46391a7f05 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -1748,7 +1748,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* For TLSv1.3 we must select the ciphersuite *before* session resumption */
|
||||
if (SSL_IS_TLS13(s)) {
|
||||
const SSL_CIPHER *cipher =
|
||||
- ssl3_choose_cipher(s, ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1929,7 +1929,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* check if some cipher was preferred by call back */
|
||||
if (pref_cipher == NULL)
|
||||
pref_cipher = ssl3_choose_cipher(s, s->peer_ciphers,
|
||||
- SSL_get_ciphers(s));
|
||||
+ ssl_get_cipher_preferences(s));
|
||||
if (pref_cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_F_TLS_EARLY_POST_PROCESS_CLIENT_HELLO,
|
||||
@@ -1938,8 +1938,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
}
|
||||
|
||||
s->session->cipher = pref_cipher;
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
+ s->cipher_list = ssl_cipher_preference_list_from_ciphers(
|
||||
+ s->peer_ciphers);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
}
|
||||
@@ -2251,7 +2252,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
/* In TLSv1.3 we selected the ciphersuite before resumption */
|
||||
if (!SSL_IS_TLS13(s)) {
|
||||
cipher =
|
||||
- ssl3_choose_cipher(s, s->peer_ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->peer_ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
+249
-179
@@ -1,8 +1,47 @@
|
||||
diff --git a/doc/man1/ciphers.pod b/doc/man1/ciphers.pod
|
||||
index e29c5d7ced..b5bca974c9 100644
|
||||
--- a/doc/man1/ciphers.pod
|
||||
+++ b/doc/man1/ciphers.pod
|
||||
@@ -400,6 +400,21 @@ permissible.
|
||||
diff --git a/crypto/err/openssl.txt b/crypto/err/openssl.txt
|
||||
index f467ea909f..76cc311ba8 100644
|
||||
--- a/crypto/err/openssl.txt
|
||||
+++ b/crypto/err/openssl.txt
|
||||
@@ -3009,6 +3009,7 @@ SM2_R_INVALID_ENCODING:104:invalid encoding
|
||||
SM2_R_INVALID_FIELD:105:invalid field
|
||||
SM2_R_NO_PARAMETERS_SET:109:no parameters set
|
||||
SM2_R_USER_ID_TOO_LARGE:106:user id too large
|
||||
+SSL_R_ALGORITHM_FETCH_FAILED:295:algorithm fetch failed
|
||||
SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY:291:\
|
||||
application data after close notify
|
||||
SSL_R_APP_DATA_IN_HANDSHAKE:100:app data in handshake
|
||||
@@ -3115,7 +3116,6 @@ SSL_R_EXTENSION_NOT_RECEIVED:279:extension not received
|
||||
SSL_R_EXTRA_DATA_IN_MESSAGE:153:extra data in message
|
||||
SSL_R_EXT_LENGTH_MISMATCH:163:ext length mismatch
|
||||
SSL_R_FAILED_TO_INIT_ASYNC:405:failed to init async
|
||||
-SSL_R_ALGORITHM_FETCH_FAILED:295:algorithm fetch failed
|
||||
SSL_R_FRAGMENTED_CLIENT_HELLO:401:fragmented client hello
|
||||
SSL_R_GOT_A_FIN_BEFORE_A_CCS:154:got a fin before a ccs
|
||||
SSL_R_HTTPS_PROXY_REQUEST:155:https proxy request
|
||||
@@ -3166,6 +3166,8 @@ SSL_R_MISSING_TMP_DH_KEY:171:missing tmp dh key
|
||||
SSL_R_MISSING_TMP_ECDH_KEY:311:missing tmp ecdh key
|
||||
SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA:293:\
|
||||
mixed handshake and non handshake data
|
||||
+SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS:296:mixed special operator with groups
|
||||
+SSL_R_NESTED_GROUP:297:nested group
|
||||
SSL_R_NOT_ON_RECORD_BOUNDARY:182:not on record boundary
|
||||
SSL_R_NOT_REPLACING_CERTIFICATE:289:not replacing certificate
|
||||
SSL_R_NOT_SERVER:284:not server
|
||||
@@ -3273,7 +3275,9 @@ SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES:243:unable to load ssl3 sha1 routines
|
||||
SSL_R_UNEXPECTED_CCS_MESSAGE:262:unexpected ccs message
|
||||
SSL_R_UNEXPECTED_END_OF_EARLY_DATA:178:unexpected end of early data
|
||||
SSL_R_UNEXPECTED_EOF_WHILE_READING:294:unexpected eof while reading
|
||||
+SSL_R_UNEXPECTED_GROUP_CLOSE:299:unexpected group close
|
||||
SSL_R_UNEXPECTED_MESSAGE:244:unexpected message
|
||||
+SSL_R_UNEXPECTED_OPERATOR_IN_GROUP:305:unexpected operator in group
|
||||
SSL_R_UNEXPECTED_RECORD:245:unexpected record
|
||||
SSL_R_UNINITIALIZED:276:uninitialized
|
||||
SSL_R_UNKNOWN_ALERT_TYPE:246:unknown alert type
|
||||
diff --git a/doc/man1/openssl-ciphers.pod.in b/doc/man1/openssl-ciphers.pod.in
|
||||
index 9e5224579a..020bdcbcb9 100644
|
||||
--- a/doc/man1/openssl-ciphers.pod.in
|
||||
+++ b/doc/man1/openssl-ciphers.pod.in
|
||||
@@ -405,6 +405,21 @@ permissible.
|
||||
|
||||
=back
|
||||
|
||||
@@ -24,57 +63,63 @@ index e29c5d7ced..b5bca974c9 100644
|
||||
=head1 CIPHER SUITE NAMES
|
||||
|
||||
The following lists give the SSL or TLS cipher suites names from the
|
||||
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
|
||||
index 9d6e1c5024..cee7db9a25 100644
|
||||
--- a/include/openssl/ssl.h
|
||||
+++ b/include/openssl/ssl.h
|
||||
@@ -173,12 +173,12 @@ extern "C" {
|
||||
# define SSL_DEFAULT_CIPHER_LIST "ALL:!COMPLEMENTOFDEFAULT:!eNULL"
|
||||
/* This is the default set of TLSv1.3 ciphersuites */
|
||||
# if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305)
|
||||
-# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_256_GCM_SHA384:" \
|
||||
+# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_128_GCM_SHA256:" \
|
||||
"TLS_CHACHA20_POLY1305_SHA256:" \
|
||||
- "TLS_AES_128_GCM_SHA256"
|
||||
+ "TLS_AES_256_GCM_SHA384"
|
||||
# else
|
||||
-# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_256_GCM_SHA384:" \
|
||||
- "TLS_AES_128_GCM_SHA256"
|
||||
+# define TLS_DEFAULT_CIPHERSUITES "TLS_AES_128_GCM_SHA256:" \
|
||||
+ "TLS_AES_256_GCM_SHA384"
|
||||
#endif
|
||||
/*
|
||||
* As of OpenSSL 1.0.0, ssl_create_cipher_list() in ssl/ssl_ciph.c always
|
||||
diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h
|
||||
index 63057517dc..97ccb41d43 100644
|
||||
index e1617aae45..a04a3e1552 100644
|
||||
--- a/include/openssl/sslerr.h
|
||||
+++ b/include/openssl/sslerr.h
|
||||
@@ -596,6 +596,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_SUPPORTED_GROUPS_EXTENSION 209
|
||||
@@ -10,12 +10,6 @@
|
||||
|
||||
#ifndef OPENSSL_SSLERR_H
|
||||
# define OPENSSL_SSLERR_H
|
||||
-# pragma once
|
||||
-
|
||||
-# include <openssl/macros.h>
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
-# define HEADER_SSLERR_H
|
||||
-# endif
|
||||
|
||||
# include <openssl/opensslconf.h>
|
||||
# include <openssl/symhacks.h>
|
||||
@@ -462,6 +456,7 @@ int ERR_load_SSL_strings(void);
|
||||
/*
|
||||
* SSL reason codes.
|
||||
*/
|
||||
+# define SSL_R_ALGORITHM_FETCH_FAILED 295
|
||||
# define SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY 291
|
||||
# define SSL_R_APP_DATA_IN_HANDSHAKE 100
|
||||
# define SSL_R_ATTEMPT_TO_REUSE_SESSION_IN_DIFFERENT_CONTEXT 272
|
||||
@@ -561,7 +556,6 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_EXTRA_DATA_IN_MESSAGE 153
|
||||
# define SSL_R_EXT_LENGTH_MISMATCH 163
|
||||
# define SSL_R_FAILED_TO_INIT_ASYNC 405
|
||||
-# define SSL_R_ALGORITHM_FETCH_FAILED 295
|
||||
# define SSL_R_FRAGMENTED_CLIENT_HELLO 401
|
||||
# define SSL_R_GOT_A_FIN_BEFORE_A_CCS 154
|
||||
# define SSL_R_HTTPS_PROXY_REQUEST 155
|
||||
@@ -611,6 +605,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_TMP_DH_KEY 171
|
||||
# define SSL_R_MISSING_TMP_ECDH_KEY 311
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 101
|
||||
+# define SSL_R_NESTED_GROUP 108
|
||||
# define SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA 293
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 296
|
||||
+# define SSL_R_NESTED_GROUP 297
|
||||
# define SSL_R_NOT_ON_RECORD_BOUNDARY 182
|
||||
# define SSL_R_NOT_REPLACING_CERTIFICATE 289
|
||||
@@ -727,9 +729,11 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS 239
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES 242
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES 243
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 109
|
||||
# define SSL_R_NOT_SERVER 284
|
||||
@@ -742,7 +738,9 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
# define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
# define SSL_R_UNEXPECTED_EOF_WHILE_READING 294
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 299
|
||||
# define SSL_R_UNEXPECTED_MESSAGE 244
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 110
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 305
|
||||
# define SSL_R_UNEXPECTED_RECORD 245
|
||||
# define SSL_R_UNINITIALIZED 276
|
||||
# define SSL_R_UNKNOWN_ALERT_TYPE 246
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index a5b3dbbfd5..505c32d18e 100644
|
||||
index 9902fa3811..3033ba3b3a 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -167,7 +167,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
@@ -169,7 +169,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
@@ -83,7 +128,7 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -232,7 +232,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
@@ -234,7 +234,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
@@ -92,7 +137,7 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -296,7 +296,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
@@ -298,7 +298,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
@@ -101,7 +146,7 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4124,6 +4124,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
@@ -4145,6 +4145,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -119,7 +164,7 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
/*
|
||||
* ssl3_choose_cipher - choose a cipher from those offered by the client
|
||||
* @s: SSL connection
|
||||
@@ -4133,16 +4144,24 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
@@ -4154,15 +4165,23 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
* Returns the selected cipher or NULL when no common ciphers.
|
||||
*/
|
||||
const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -133,7 +178,6 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
+ STACK_OF(SSL_CIPHER) *srvr = server_pref->ciphers, *prio, *allow;
|
||||
+ int i, ii, ok, prefer_sha256 = 0, safari_ec = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
const EVP_MD *mdsha256 = EVP_sha256();
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
-#endif
|
||||
@@ -150,8 +194,8 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
|
||||
/* Let's see which ciphers we can support */
|
||||
|
||||
@@ -4169,54 +4188,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#endif
|
||||
@@ -4189,54 +4208,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
} OSSL_TRACE_END(TLS_CIPHER);
|
||||
|
||||
/* SUITE-B takes precedence over server preference and ChaCha priortiy */
|
||||
- if (tls1_suiteb(s)) {
|
||||
@@ -208,7 +252,7 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
allow = srvr;
|
||||
}
|
||||
|
||||
@@ -4247,14 +4225,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -4267,14 +4245,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
|
||||
c = sk_SSL_CIPHER_value(prio, i);
|
||||
|
||||
@@ -227,7 +271,7 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
|
||||
/*
|
||||
* Since TLS 1.3 ciphersuites can be used with any auth or
|
||||
@@ -4276,10 +4256,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -4296,10 +4276,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
/* with PSK there must be server callback set */
|
||||
if ((alg_k & SSL_PSK) && s->psk_server_callback == NULL)
|
||||
@@ -237,10 +281,10 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
|
||||
- ok = (alg_k & mask_k) && (alg_a & mask_a);
|
||||
+ ok = ok && (alg_k & mask_k) && (alg_a & mask_a);
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n", ok, alg_k,
|
||||
alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4296,6 +4276,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
OSSL_TRACE7(TLS_CIPHER,
|
||||
"%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n",
|
||||
ok, alg_k, alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4315,6 +4295,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
|
||||
if (!ok)
|
||||
continue;
|
||||
@@ -248,20 +292,20 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
+ safari_ec = 0;
|
||||
+#if !defined(OPENSSL_NO_EC)
|
||||
+ if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)) {
|
||||
+ if (s->s3->is_probably_safari)
|
||||
+ if (s->s3.is_probably_safari)
|
||||
+ safari_ec = 1;
|
||||
+ }
|
||||
+#endif
|
||||
}
|
||||
ii = sk_SSL_CIPHER_find(allow, c);
|
||||
if (ii >= 0) {
|
||||
@@ -4303,14 +4291,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -4322,14 +4310,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (!ssl_security(s, SSL_SECOP_CIPHER_SHARED,
|
||||
c->strength_bits, 0, (void *)c))
|
||||
continue;
|
||||
-#if !defined(OPENSSL_NO_EC)
|
||||
- if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)
|
||||
- && s->s3->is_probably_safari) {
|
||||
- && s->s3.is_probably_safari) {
|
||||
- if (!ret)
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
- continue;
|
||||
@@ -271,7 +315,7 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
@@ -4322,13 +4303,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -4346,13 +4327,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
ret = tmp;
|
||||
continue;
|
||||
}
|
||||
@@ -315,10 +359,10 @@ index a5b3dbbfd5..505c32d18e 100644
|
||||
}
|
||||
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 461a9debab..c8d8517735 100644
|
||||
index 066c38a7cc..f1e3d1cbe2 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -192,6 +192,7 @@ typedef struct cipher_order_st {
|
||||
@@ -154,6 +154,7 @@ typedef struct cipher_order_st {
|
||||
const SSL_CIPHER *cipher;
|
||||
int active;
|
||||
int dead;
|
||||
@@ -326,7 +370,15 @@ index 461a9debab..c8d8517735 100644
|
||||
struct cipher_order_st *next, *prev;
|
||||
} CIPHER_ORDER;
|
||||
|
||||
@@ -681,6 +682,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
@@ -259,6 +260,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_TLSV1, NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, "TLSv1.0", NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, SSL_TXT_TLSV1_2, NULL, 0, 0, 0, 0, 0, TLS1_2_VERSION},
|
||||
+ {0, "TLS13", NULL, 0, 0, 0, 0, 0, TLS1_3_VERSION},
|
||||
|
||||
/* strength classes */
|
||||
{0, SSL_TXT_LOW, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_LOW},
|
||||
@@ -673,6 +675,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
co_list[co_list_num].next = NULL;
|
||||
co_list[co_list_num].prev = NULL;
|
||||
co_list[co_list_num].active = 0;
|
||||
@@ -334,7 +386,7 @@ index 461a9debab..c8d8517735 100644
|
||||
co_list_num++;
|
||||
}
|
||||
|
||||
@@ -774,8 +776,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -766,8 +769,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
uint32_t alg_auth, uint32_t alg_enc,
|
||||
uint32_t alg_mac, int min_tls,
|
||||
uint32_t algo_strength, int rule,
|
||||
@@ -345,19 +397,19 @@ index 461a9debab..c8d8517735 100644
|
||||
{
|
||||
CIPHER_ORDER *head, *tail, *curr, *next, *last;
|
||||
const SSL_CIPHER *cp;
|
||||
@@ -783,9 +785,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -775,9 +778,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr,
|
||||
OSSL_TRACE_BEGIN(TLS_CIPHER){
|
||||
BIO_printf(trc_out,
|
||||
- "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d)\n",
|
||||
+ "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d) g:%d\n",
|
||||
rule, alg_mkey, alg_auth, alg_enc, alg_mac, min_tls,
|
||||
- algo_strength, strength_bits);
|
||||
+ algo_strength, strength_bits, in_group);
|
||||
#endif
|
||||
}
|
||||
|
||||
if (rule == CIPHER_DEL || rule == CIPHER_BUMP)
|
||||
@@ -862,6 +864,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -854,6 +857,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
if (!curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
curr->active = 1;
|
||||
@@ -365,7 +417,7 @@ index 461a9debab..c8d8517735 100644
|
||||
}
|
||||
}
|
||||
/* Move the added cipher to this location */
|
||||
@@ -869,6 +872,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -861,6 +865,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
/* reverse == 0 */
|
||||
if (curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
@@ -373,7 +425,7 @@ index 461a9debab..c8d8517735 100644
|
||||
}
|
||||
} else if (rule == CIPHER_DEL) {
|
||||
/* reverse == 1 */
|
||||
@@ -880,6 +884,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -872,6 +877,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
*/
|
||||
ll_append_head(&head, curr, &tail);
|
||||
curr->active = 0;
|
||||
@@ -381,7 +433,7 @@ index 461a9debab..c8d8517735 100644
|
||||
}
|
||||
} else if (rule == CIPHER_BUMP) {
|
||||
if (curr->active)
|
||||
@@ -947,8 +952,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
@@ -941,8 +947,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
*/
|
||||
for (i = max_strength_bits; i >= 0; i--)
|
||||
if (number_uses[i] > 0)
|
||||
@@ -392,7 +444,7 @@ index 461a9debab..c8d8517735 100644
|
||||
|
||||
OPENSSL_free(number_uses);
|
||||
return 1;
|
||||
@@ -962,7 +967,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -956,7 +962,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
uint32_t alg_mkey, alg_auth, alg_enc, alg_mac, algo_strength;
|
||||
int min_tls;
|
||||
const char *l, *buf;
|
||||
@@ -401,7 +453,7 @@ index 461a9debab..c8d8517735 100644
|
||||
uint32_t cipher_id = 0;
|
||||
char ch;
|
||||
|
||||
@@ -973,18 +978,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -967,18 +973,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
|
||||
if (ch == '\0')
|
||||
break; /* done */
|
||||
@@ -469,7 +521,16 @@ index 461a9debab..c8d8517735 100644
|
||||
} else {
|
||||
rule = CIPHER_ADD;
|
||||
}
|
||||
@@ -1026,7 +1079,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -1003,7 +1057,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
while (((ch >= 'A') && (ch <= 'Z')) ||
|
||||
((ch >= '0') && (ch <= '9')) ||
|
||||
((ch >= 'a') && (ch <= 'z')) ||
|
||||
- (ch == '-') || (ch == '.') || (ch == '='))
|
||||
+ (ch == '-') || (ch == '.') || (ch == '=') || (ch == '_'))
|
||||
#else
|
||||
while (isalnum((unsigned char)ch) || (ch == '-') || (ch == '.')
|
||||
|| (ch == '='))
|
||||
@@ -1020,7 +1074,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
* alphanumeric, so we call this an error.
|
||||
*/
|
||||
SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
@@ -478,7 +539,7 @@ index 461a9debab..c8d8517735 100644
|
||||
l++;
|
||||
break;
|
||||
}
|
||||
@@ -1205,8 +1258,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -1199,8 +1253,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
} else if (found) {
|
||||
ssl_cipher_apply_rule(cipher_id,
|
||||
alg_mkey, alg_auth, alg_enc, alg_mac,
|
||||
@@ -489,7 +550,7 @@ index 461a9debab..c8d8517735 100644
|
||||
} else {
|
||||
while ((*l != '\0') && !ITEM_SEP(*l))
|
||||
l++;
|
||||
@@ -1215,6 +1268,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -1209,6 +1263,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
break; /* done */
|
||||
}
|
||||
|
||||
@@ -501,25 +562,29 @@ index 461a9debab..c8d8517735 100644
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1379,7 +1437,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
@@ -1372,7 +1431,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
int ret = set_ciphersuites(&(ctx->tls13_ciphersuites), str);
|
||||
|
||||
if (ret && ctx->cipher_list != NULL) {
|
||||
/* We already have a cipher_list, so we need to update it */
|
||||
if (ret && ctx->cipher_list != NULL)
|
||||
- return update_cipher_list(&ctx->cipher_list, &ctx->cipher_list_by_id,
|
||||
+ return update_cipher_list(&ctx->cipher_list->ciphers, &ctx->cipher_list_by_id,
|
||||
ctx->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1385,10 +1444,10 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (s->cipher_list == NULL) {
|
||||
if ((cipher_list = SSL_get_ciphers(s)) != NULL)
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(cipher_list);
|
||||
+ s->cipher_list->ciphers = sk_SSL_CIPHER_dup(cipher_list);
|
||||
}
|
||||
|
||||
@@ -1392,7 +1450,7 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (ret && s->cipher_list != NULL) {
|
||||
/* We already have a cipher_list, so we need to update it */
|
||||
if (ret && s->cipher_list != NULL)
|
||||
- return update_cipher_list(&s->cipher_list, &s->cipher_list_by_id,
|
||||
+ return update_cipher_list(&s->cipher_list->ciphers, &s->cipher_list_by_id,
|
||||
s->tls13_ciphersuites);
|
||||
}
|
||||
|
||||
@@ -1401,17 +1459,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
return ret;
|
||||
@@ -1396,17 +1455,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
@@ -530,21 +595,20 @@ index 461a9debab..c8d8517735 100644
|
||||
CERT *c)
|
||||
{
|
||||
- int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i;
|
||||
+ int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i, tls13_len;
|
||||
+ int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases;
|
||||
uint32_t disabled_mkey, disabled_auth, disabled_enc, disabled_mac;
|
||||
- STACK_OF(SSL_CIPHER) *cipherstack;
|
||||
+ STACK_OF(SSL_CIPHER) *cipherstack = NULL;
|
||||
const char *rule_p;
|
||||
CIPHER_ORDER *co_list = NULL, *head = NULL, *tail = NULL, *curr;
|
||||
- const SSL_CIPHER **ca_list = NULL;
|
||||
+ const SSL_CIPHER **ca_list = NULL, *tmp = NULL;
|
||||
const SSL_CIPHER **ca_list = NULL;
|
||||
+ uint8_t *in_group_flags = NULL;
|
||||
+ unsigned int num_in_group_flags = 0;
|
||||
+ struct ssl_cipher_preference_list_st *pref_list = NULL;
|
||||
|
||||
/*
|
||||
* Return with error if nothing to do.
|
||||
@@ -1460,16 +1521,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1455,16 +1517,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* preference).
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, SSL_kECDHE, SSL_aECDSA, 0, 0, 0, 0, CIPHER_ADD,
|
||||
@@ -568,7 +632,7 @@ index 461a9debab..c8d8517735 100644
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1478,13 +1539,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1473,13 +1535,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* strength.
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, 0, 0, SSL_AES ^ SSL_AESGCM, 0, 0, 0, CIPHER_ADD,
|
||||
@@ -585,7 +649,7 @@ index 461a9debab..c8d8517735 100644
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1492,16 +1553,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1487,16 +1549,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* disabled. (For applications that allow them, they aren't too bad, but
|
||||
* we prefer authenticated ciphers.)
|
||||
*/
|
||||
@@ -606,7 +670,7 @@ index 461a9debab..c8d8517735 100644
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1517,7 +1578,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1512,7 +1574,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Partially overrule strength sort to prefer TLS 1.2 ciphers/PRFs.
|
||||
* TODO(openssl-team): is there an easier way to accomplish all this?
|
||||
*/
|
||||
@@ -615,7 +679,7 @@ index 461a9debab..c8d8517735 100644
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1533,15 +1594,15 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1528,15 +1590,18 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Because we now bump ciphers to the top of the list, we proceed in
|
||||
* reverse order of preference.
|
||||
*/
|
||||
@@ -628,6 +692,9 @@ index 461a9debab..c8d8517735 100644
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, SSL_AEAD, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
+
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_3_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Now disable everything (maintaining the ordering!) */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head, &tail);
|
||||
@@ -635,7 +702,7 @@ index 461a9debab..c8d8517735 100644
|
||||
|
||||
/*
|
||||
* We also need cipher aliases for selecting based on the rule_str.
|
||||
@@ -1555,9 +1616,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1550,9 +1615,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
num_of_alias_max = num_of_ciphers + num_of_group_aliases + 1;
|
||||
ca_list = OPENSSL_malloc(sizeof(*ca_list) * num_of_alias_max);
|
||||
if (ca_list == NULL) {
|
||||
@@ -646,7 +713,7 @@ index 461a9debab..c8d8517735 100644
|
||||
}
|
||||
ssl_cipher_collect_aliases(ca_list, num_of_group_aliases,
|
||||
disabled_mkey, disabled_auth, disabled_enc,
|
||||
@@ -1582,27 +1642,35 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1577,28 +1641,19 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
|
||||
OPENSSL_free(ca_list); /* Not needed anymore */
|
||||
|
||||
@@ -667,51 +734,39 @@ index 461a9debab..c8d8517735 100644
|
||||
- }
|
||||
+ if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL)
|
||||
+ goto err;
|
||||
+
|
||||
|
||||
- /* Add TLSv1.3 ciphers first - we always prefer those if possible */
|
||||
- for (i = 0; i < sk_SSL_CIPHER_num(tls13_ciphersuites); i++) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack,
|
||||
- sk_SSL_CIPHER_value(tls13_ciphersuites, i))) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- }
|
||||
+ in_group_flags = OPENSSL_malloc(num_of_ciphers);
|
||||
+ if (!in_group_flags)
|
||||
+ goto err;
|
||||
|
||||
/* Add TLSv1.3 ciphers first - we always prefer those if possible */
|
||||
- for (i = 0; i < sk_SSL_CIPHER_num(tls13_ciphersuites); i++) {
|
||||
+ tls13_len = sk_SSL_CIPHER_num(tls13_ciphersuites);
|
||||
+ for (i = 0; i < tls13_len; i++) {
|
||||
+ tmp = sk_SSL_CIPHER_value(tls13_ciphersuites, i);
|
||||
if (!sk_SSL_CIPHER_push(cipherstack,
|
||||
- sk_SSL_CIPHER_value(tls13_ciphersuites, i))) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
+ tmp))
|
||||
+ goto err;
|
||||
+ /* Temporary - AES128, CHACHA20 priority adjustment of TLS 1.3. */
|
||||
+ if (tmp->algorithm_enc == SSL_AES128GCM &&
|
||||
+ tls13_len > (i + 1)) {
|
||||
+ tmp = sk_SSL_CIPHER_value(tls13_ciphersuites, i + 1);
|
||||
+ in_group_flags[num_in_group_flags++] = (tmp->algorithm_enc == SSL_CHACHA20POLY1305) ? 1 : 0;
|
||||
}
|
||||
+ else
|
||||
+ in_group_flags[num_in_group_flags++] = 0;
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -1611,26 +1679,50 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
*/
|
||||
OSSL_TRACE_BEGIN(TLS_CIPHER) {
|
||||
BIO_printf(trc_out, "cipher selection:\n");
|
||||
@@ -1610,26 +1665,51 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
for (curr = head; curr != NULL; curr = curr->next) {
|
||||
if (curr->active) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
- OPENSSL_free(co_list);
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
OSSL_TRACE_CANCEL(TLS_CIPHER);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher))
|
||||
+ goto err;
|
||||
}
|
||||
+ in_group_flags[num_in_group_flags++] = curr->in_group;
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "<%s>\n", curr->cipher->name);
|
||||
#endif
|
||||
if (trc_out != NULL)
|
||||
BIO_printf(trc_out, "<%s>\n", curr->cipher->name);
|
||||
}
|
||||
}
|
||||
- OPENSSL_free(co_list); /* Not needed any longer */
|
||||
OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
OSSL_TRACE_END(TLS_CIPHER);
|
||||
|
||||
- if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack)) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
@@ -719,9 +774,6 @@ index 461a9debab..c8d8517735 100644
|
||||
- }
|
||||
- sk_SSL_CIPHER_free(*cipher_list);
|
||||
- *cipher_list = cipherstack;
|
||||
+ OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
+
|
||||
+ if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack))
|
||||
+ goto err;
|
||||
+
|
||||
@@ -754,32 +806,48 @@ index 461a9debab..c8d8517735 100644
|
||||
+ if (pref_list)
|
||||
+ OPENSSL_free(pref_list);
|
||||
+ return NULL;
|
||||
+
|
||||
}
|
||||
|
||||
char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
diff --git a/ssl/ssl_err.c b/ssl/ssl_err.c
|
||||
index ceae87bbc9..46521b7136 100644
|
||||
index 85d9dd8448..64f7577a90 100644
|
||||
--- a/ssl/ssl_err.c
|
||||
+++ b/ssl/ssl_err.c
|
||||
@@ -965,6 +965,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_DH_KEY), "missing tmp dh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_ECDH_KEY),
|
||||
@@ -14,6 +14,8 @@
|
||||
#ifndef OPENSSL_NO_ERR
|
||||
|
||||
static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ALGORITHM_FETCH_FAILED),
|
||||
+ "algorithm fetch failed"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY),
|
||||
"application data after close notify"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_APP_DATA_IN_HANDSHAKE),
|
||||
@@ -171,8 +173,6 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"ext length mismatch"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_FAILED_TO_INIT_ASYNC),
|
||||
"failed to init async"},
|
||||
- {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ALGORITHM_FETCH_FAILED),
|
||||
- "algorithm fetch failed"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_FRAGMENTED_CLIENT_HELLO),
|
||||
"fragmented client hello"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_GOT_A_FIN_BEFORE_A_CCS),
|
||||
@@ -257,6 +257,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"missing tmp ecdh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS),
|
||||
+ "mixed special operator with groups"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NESTED_GROUP), "nested group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_ON_RECORD_BOUNDARY),
|
||||
@@ -1201,11 +1204,14 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unable to load ssl3 md5 routines"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES),
|
||||
"unable to load ssl3 sha1 routines"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE), "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_CCS_MESSAGE),
|
||||
"unexpected ccs message"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_END_OF_EARLY_DATA),
|
||||
"not on record boundary"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_REPLACING_CERTIFICATE),
|
||||
@@ -493,7 +496,11 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unexpected end of early data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_EOF_WHILE_READING),
|
||||
"unexpected eof while reading"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE),
|
||||
+ "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_MESSAGE), "unexpected message"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP),
|
||||
+ "unexpected operator in group"},
|
||||
@@ -787,10 +855,10 @@ index ceae87bbc9..46521b7136 100644
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNINITIALIZED), "uninitialized"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNKNOWN_ALERT_TYPE), "unknown alert type"},
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index 322a4381b0..ac33c35560 100644
|
||||
index a08ddb138b..fc6d1ac2a3 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -1119,6 +1119,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
@@ -1127,6 +1127,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
return X509_VERIFY_PARAM_set1(ssl->param, vpm);
|
||||
}
|
||||
|
||||
@@ -862,7 +930,7 @@ index 322a4381b0..ac33c35560 100644
|
||||
X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx)
|
||||
{
|
||||
return ctx->param;
|
||||
@@ -1163,7 +1228,8 @@ void SSL_free(SSL *s)
|
||||
@@ -1171,7 +1236,8 @@ void SSL_free(SSL *s)
|
||||
BUF_MEM_free(s->init_buf);
|
||||
|
||||
/* add extra stuff */
|
||||
@@ -871,8 +939,8 @@ index 322a4381b0..ac33c35560 100644
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(s->tls13_ciphersuites);
|
||||
|
||||
@@ -2498,9 +2564,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
sk_SSL_CIPHER_free(s->peer_ciphers);
|
||||
@@ -2566,9 +2632,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
{
|
||||
if (s != NULL) {
|
||||
if (s->cipher_list != NULL) {
|
||||
@@ -884,7 +952,7 @@ index 322a4381b0..ac33c35560 100644
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
@@ -2574,8 +2640,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
@@ -2642,8 +2708,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
* preference */
|
||||
STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx)
|
||||
{
|
||||
@@ -895,16 +963,16 @@ index 322a4381b0..ac33c35560 100644
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -3026,7 +3092,7 @@ SSL_CTX *SSL_CTX_new(const SSL_METHOD *meth)
|
||||
@@ -3157,7 +3223,7 @@ SSL_CTX *SSL_CTX_new_with_libctx(OPENSSL_CTX *libctx, const char *propq,
|
||||
ret->tls13_ciphersuites,
|
||||
&ret->cipher_list, &ret->cipher_list_by_id,
|
||||
SSL_DEFAULT_CIPHER_LIST, ret->cert)
|
||||
OSSL_default_cipher_list(), ret->cert)
|
||||
- || sk_SSL_CIPHER_num(ret->cipher_list) <= 0) {
|
||||
+ || sk_SSL_CIPHER_num(ret->cipher_list->ciphers) <= 0) {
|
||||
SSLerr(SSL_F_SSL_CTX_NEW, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
SSLerr(0, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
goto err2;
|
||||
}
|
||||
@@ -3202,7 +3268,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
@@ -3336,7 +3402,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
#ifndef OPENSSL_NO_CT
|
||||
CTLOG_STORE_free(a->ctlog_store);
|
||||
#endif
|
||||
@@ -913,7 +981,7 @@ index 322a4381b0..ac33c35560 100644
|
||||
sk_SSL_CIPHER_free(a->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(a->tls13_ciphersuites);
|
||||
ssl_cert_free(a->cert);
|
||||
@@ -3880,13 +3946,15 @@ SSL *SSL_dup(SSL *s)
|
||||
@@ -4022,13 +4088,15 @@ SSL *SSL_dup(SSL *s)
|
||||
|
||||
/* dup the cipher_list and cipher_list_by_id stacks */
|
||||
if (s->cipher_list != NULL) {
|
||||
@@ -933,13 +1001,13 @@ index 322a4381b0..ac33c35560 100644
|
||||
|
||||
/* Dup the client_CA list */
|
||||
if (!dup_ca_names(&ret->ca_names, s->ca_names)
|
||||
diff --git a/ssl/ssl_locl.h b/ssl/ssl_locl.h
|
||||
index ae6417b592..9f839acc74 100644
|
||||
--- a/ssl/ssl_locl.h
|
||||
+++ b/ssl/ssl_locl.h
|
||||
@@ -745,9 +745,46 @@ typedef struct ssl_ctx_ext_secure_st {
|
||||
unsigned char tick_aes_key[TLSEXT_TICK_KEY_LENGTH];
|
||||
} SSL_CTX_EXT_SECURE;
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index c48bcb9a9a..dfb3e13464 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -789,11 +789,48 @@ int ssl_hmac_final(SSL_HMAC *ctx, unsigned char *md, size_t *len,
|
||||
size_t max_size);
|
||||
size_t ssl_hmac_size(const SSL_HMAC *ctx);
|
||||
|
||||
+/* ssl_cipher_preference_list_st contains a list of SSL_CIPHERs with
|
||||
+ * equal-preference groups. For TLS clients, the groups are moot because the
|
||||
@@ -979,22 +1047,24 @@ index ae6417b592..9f839acc74 100644
|
||||
+
|
||||
+
|
||||
struct ssl_ctx_st {
|
||||
OPENSSL_CTX *libctx;
|
||||
|
||||
const SSL_METHOD *method;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
/* same as above but sorted for lookup */
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
@@ -1146,7 +1183,7 @@ struct ssl_st {
|
||||
/* Per connection DANE state */
|
||||
@@ -1380,7 +1417,7 @@ struct ssl_st {
|
||||
SSL_DANE dane;
|
||||
/* crypto */
|
||||
STACK_OF(SSL_CIPHER) *peer_ciphers;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites;
|
||||
@@ -2275,7 +2312,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
@@ -2353,7 +2390,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
const SSL_CIPHER *const *bp);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
@@ -1003,7 +1073,7 @@ index ae6417b592..9f839acc74 100644
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c);
|
||||
@@ -2285,6 +2322,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
@@ -2363,6 +2400,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
@@ -1014,10 +1084,10 @@ index ae6417b592..9f839acc74 100644
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_from_ciphers(
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers);
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s);
|
||||
__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
const EVP_MD **md, int *mac_pkey_type,
|
||||
size_t *mac_secret_size, SSL_COMP **comp,
|
||||
@@ -2368,7 +2412,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
__owur int ssl_cipher_get_evp_cipher(SSL_CTX *ctx, const SSL_CIPHER *sslc,
|
||||
const EVP_CIPHER **enc);
|
||||
__owur int ssl_cipher_get_evp(SSL_CTX *ctxc, const SSL_SESSION *s,
|
||||
@@ -2450,7 +2494,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
CERT_PKEY *cpk);
|
||||
__owur const SSL_CIPHER *ssl3_choose_cipher(SSL *ssl,
|
||||
STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -1027,10 +1097,10 @@ index ae6417b592..9f839acc74 100644
|
||||
__owur int ssl3_new(SSL *s);
|
||||
void ssl3_free(SSL *s);
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index bf1819d356..ebb6224b5e 100644
|
||||
index 43f9811163..769f0c7eb6 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -1750,7 +1750,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
@@ -1774,7 +1774,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* For TLSv1.3 we must select the ciphersuite *before* session resumption */
|
||||
if (SSL_IS_TLS13(s)) {
|
||||
const SSL_CIPHER *cipher =
|
||||
@@ -1039,33 +1109,33 @@ index bf1819d356..ebb6224b5e 100644
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1931,7 +1931,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
@@ -1957,7 +1957,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* check if some cipher was preferred by call back */
|
||||
if (pref_cipher == NULL)
|
||||
pref_cipher = ssl3_choose_cipher(s, s->session->ciphers,
|
||||
pref_cipher = ssl3_choose_cipher(s, s->peer_ciphers,
|
||||
- SSL_get_ciphers(s));
|
||||
+ ssl_get_cipher_preferences(s));
|
||||
if (pref_cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_F_TLS_EARLY_POST_PROCESS_CLIENT_HELLO,
|
||||
@@ -1940,8 +1940,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
@@ -1966,8 +1966,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
}
|
||||
|
||||
s->session->cipher = pref_cipher;
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->session->ciphers);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
+ s->cipher_list = ssl_cipher_preference_list_from_ciphers(
|
||||
+ s->session->ciphers);
|
||||
+ s->peer_ciphers);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->session->ciphers);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
}
|
||||
@@ -2255,7 +2256,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
@@ -2279,7 +2280,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
/* In TLSv1.3 we selected the ciphersuite before resumption */
|
||||
if (!SSL_IS_TLS13(s)) {
|
||||
cipher =
|
||||
- ssl3_choose_cipher(s, s->session->ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->session->ciphers, ssl_get_cipher_preferences(s));
|
||||
- ssl3_choose_cipher(s, s->peer_ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->peer_ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1,8 +1,47 @@
|
||||
diff --git a/doc/man1/ciphers.pod b/doc/man1/ciphers.pod
|
||||
index e29c5d7ced..b5bca974c9 100644
|
||||
--- a/doc/man1/ciphers.pod
|
||||
+++ b/doc/man1/ciphers.pod
|
||||
@@ -400,6 +400,21 @@ permissible.
|
||||
diff --git a/crypto/err/openssl.txt b/crypto/err/openssl.txt
|
||||
index f467ea909f..76cc311ba8 100644
|
||||
--- a/crypto/err/openssl.txt
|
||||
+++ b/crypto/err/openssl.txt
|
||||
@@ -3009,6 +3009,7 @@ SM2_R_INVALID_ENCODING:104:invalid encoding
|
||||
SM2_R_INVALID_FIELD:105:invalid field
|
||||
SM2_R_NO_PARAMETERS_SET:109:no parameters set
|
||||
SM2_R_USER_ID_TOO_LARGE:106:user id too large
|
||||
+SSL_R_ALGORITHM_FETCH_FAILED:295:algorithm fetch failed
|
||||
SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY:291:\
|
||||
application data after close notify
|
||||
SSL_R_APP_DATA_IN_HANDSHAKE:100:app data in handshake
|
||||
@@ -3115,7 +3116,6 @@ SSL_R_EXTENSION_NOT_RECEIVED:279:extension not received
|
||||
SSL_R_EXTRA_DATA_IN_MESSAGE:153:extra data in message
|
||||
SSL_R_EXT_LENGTH_MISMATCH:163:ext length mismatch
|
||||
SSL_R_FAILED_TO_INIT_ASYNC:405:failed to init async
|
||||
-SSL_R_ALGORITHM_FETCH_FAILED:295:algorithm fetch failed
|
||||
SSL_R_FRAGMENTED_CLIENT_HELLO:401:fragmented client hello
|
||||
SSL_R_GOT_A_FIN_BEFORE_A_CCS:154:got a fin before a ccs
|
||||
SSL_R_HTTPS_PROXY_REQUEST:155:https proxy request
|
||||
@@ -3166,6 +3166,8 @@ SSL_R_MISSING_TMP_DH_KEY:171:missing tmp dh key
|
||||
SSL_R_MISSING_TMP_ECDH_KEY:311:missing tmp ecdh key
|
||||
SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA:293:\
|
||||
mixed handshake and non handshake data
|
||||
+SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS:296:mixed special operator with groups
|
||||
+SSL_R_NESTED_GROUP:297:nested group
|
||||
SSL_R_NOT_ON_RECORD_BOUNDARY:182:not on record boundary
|
||||
SSL_R_NOT_REPLACING_CERTIFICATE:289:not replacing certificate
|
||||
SSL_R_NOT_SERVER:284:not server
|
||||
@@ -3273,7 +3275,9 @@ SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES:243:unable to load ssl3 sha1 routines
|
||||
SSL_R_UNEXPECTED_CCS_MESSAGE:262:unexpected ccs message
|
||||
SSL_R_UNEXPECTED_END_OF_EARLY_DATA:178:unexpected end of early data
|
||||
SSL_R_UNEXPECTED_EOF_WHILE_READING:294:unexpected eof while reading
|
||||
+SSL_R_UNEXPECTED_GROUP_CLOSE:299:unexpected group close
|
||||
SSL_R_UNEXPECTED_MESSAGE:244:unexpected message
|
||||
+SSL_R_UNEXPECTED_OPERATOR_IN_GROUP:305:unexpected operator in group
|
||||
SSL_R_UNEXPECTED_RECORD:245:unexpected record
|
||||
SSL_R_UNINITIALIZED:276:uninitialized
|
||||
SSL_R_UNKNOWN_ALERT_TYPE:246:unknown alert type
|
||||
diff --git a/doc/man1/openssl-ciphers.pod.in b/doc/man1/openssl-ciphers.pod.in
|
||||
index 9e5224579a..020bdcbcb9 100644
|
||||
--- a/doc/man1/openssl-ciphers.pod.in
|
||||
+++ b/doc/man1/openssl-ciphers.pod.in
|
||||
@@ -405,6 +405,21 @@ permissible.
|
||||
|
||||
=back
|
||||
|
||||
@@ -25,35 +64,62 @@ index e29c5d7ced..b5bca974c9 100644
|
||||
|
||||
The following lists give the SSL or TLS cipher suites names from the
|
||||
diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h
|
||||
index 63057517dc..97ccb41d43 100644
|
||||
index e1617aae45..a04a3e1552 100644
|
||||
--- a/include/openssl/sslerr.h
|
||||
+++ b/include/openssl/sslerr.h
|
||||
@@ -596,6 +596,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_SUPPORTED_GROUPS_EXTENSION 209
|
||||
@@ -10,12 +10,6 @@
|
||||
|
||||
#ifndef OPENSSL_SSLERR_H
|
||||
# define OPENSSL_SSLERR_H
|
||||
-# pragma once
|
||||
-
|
||||
-# include <openssl/macros.h>
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
-# define HEADER_SSLERR_H
|
||||
-# endif
|
||||
|
||||
# include <openssl/opensslconf.h>
|
||||
# include <openssl/symhacks.h>
|
||||
@@ -462,6 +456,7 @@ int ERR_load_SSL_strings(void);
|
||||
/*
|
||||
* SSL reason codes.
|
||||
*/
|
||||
+# define SSL_R_ALGORITHM_FETCH_FAILED 295
|
||||
# define SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY 291
|
||||
# define SSL_R_APP_DATA_IN_HANDSHAKE 100
|
||||
# define SSL_R_ATTEMPT_TO_REUSE_SESSION_IN_DIFFERENT_CONTEXT 272
|
||||
@@ -561,7 +556,6 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_EXTRA_DATA_IN_MESSAGE 153
|
||||
# define SSL_R_EXT_LENGTH_MISMATCH 163
|
||||
# define SSL_R_FAILED_TO_INIT_ASYNC 405
|
||||
-# define SSL_R_ALGORITHM_FETCH_FAILED 295
|
||||
# define SSL_R_FRAGMENTED_CLIENT_HELLO 401
|
||||
# define SSL_R_GOT_A_FIN_BEFORE_A_CCS 154
|
||||
# define SSL_R_HTTPS_PROXY_REQUEST 155
|
||||
@@ -611,6 +605,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_TMP_DH_KEY 171
|
||||
# define SSL_R_MISSING_TMP_ECDH_KEY 311
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 101
|
||||
+# define SSL_R_NESTED_GROUP 108
|
||||
# define SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA 293
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 296
|
||||
+# define SSL_R_NESTED_GROUP 297
|
||||
# define SSL_R_NOT_ON_RECORD_BOUNDARY 182
|
||||
# define SSL_R_NOT_REPLACING_CERTIFICATE 289
|
||||
@@ -727,9 +729,11 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS 239
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES 242
|
||||
# define SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES 243
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 109
|
||||
# define SSL_R_NOT_SERVER 284
|
||||
@@ -742,7 +738,9 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
# define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
# define SSL_R_UNEXPECTED_EOF_WHILE_READING 294
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 299
|
||||
# define SSL_R_UNEXPECTED_MESSAGE 244
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 110
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 305
|
||||
# define SSL_R_UNEXPECTED_RECORD 245
|
||||
# define SSL_R_UNINITIALIZED 276
|
||||
# define SSL_R_UNKNOWN_ALERT_TYPE 246
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
index 9902fa3811..0fc41e29f0 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -31,7 +31,25 @@ const unsigned char tls12downgrade[] = {
|
||||
@@ -33,7 +33,25 @@ const unsigned char tls12downgrade[] = {
|
||||
};
|
||||
|
||||
/* The list of available TLSv1.3 ciphers */
|
||||
@@ -79,7 +145,7 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
{
|
||||
1,
|
||||
TLS1_3_RFC_AES_128_GCM_SHA256,
|
||||
@@ -111,20 +129,8 @@ static SSL_CIPHER tls13_ciphers[] = {
|
||||
@@ -113,20 +131,8 @@ static SSL_CIPHER tls13_ciphers[] = {
|
||||
SSL_HANDSHAKE_MAC_SHA256,
|
||||
128,
|
||||
128,
|
||||
@@ -102,7 +168,7 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
{
|
||||
1,
|
||||
SSL3_TXT_RSA_NULL_MD5,
|
||||
@@ -167,7 +173,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
@@ -169,7 +175,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
@@ -111,7 +177,16 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -232,7 +238,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
@@ -201,7 +207,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -234,7 +240,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
@@ -120,7 +195,16 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -296,7 +302,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
@@ -266,7 +272,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -298,7 +304,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
@@ -129,7 +213,16 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4124,6 +4130,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
@@ -330,7 +336,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4145,6 +4151,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -147,7 +240,7 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
/*
|
||||
* ssl3_choose_cipher - choose a cipher from those offered by the client
|
||||
* @s: SSL connection
|
||||
@@ -4133,16 +4150,24 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
@@ -4154,15 +4171,23 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
* Returns the selected cipher or NULL when no common ciphers.
|
||||
*/
|
||||
const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -161,7 +254,6 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
+ STACK_OF(SSL_CIPHER) *srvr = server_pref->ciphers, *prio, *allow;
|
||||
+ int i, ii, ok, prefer_sha256 = 0, safari_ec = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
const EVP_MD *mdsha256 = EVP_sha256();
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
-#endif
|
||||
@@ -178,8 +270,8 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
|
||||
/* Let's see which ciphers we can support */
|
||||
|
||||
@@ -4169,54 +4194,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#endif
|
||||
@@ -4189,54 +4214,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
} OSSL_TRACE_END(TLS_CIPHER);
|
||||
|
||||
/* SUITE-B takes precedence over server preference and ChaCha priortiy */
|
||||
- if (tls1_suiteb(s)) {
|
||||
@@ -236,7 +328,7 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
allow = srvr;
|
||||
}
|
||||
|
||||
@@ -4247,14 +4231,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -4267,14 +4251,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
|
||||
c = sk_SSL_CIPHER_value(prio, i);
|
||||
|
||||
@@ -255,7 +347,7 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
|
||||
/*
|
||||
* Since TLS 1.3 ciphersuites can be used with any auth or
|
||||
@@ -4276,10 +4262,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -4296,10 +4282,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
/* with PSK there must be server callback set */
|
||||
if ((alg_k & SSL_PSK) && s->psk_server_callback == NULL)
|
||||
@@ -265,10 +357,10 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
|
||||
- ok = (alg_k & mask_k) && (alg_a & mask_a);
|
||||
+ ok = ok && (alg_k & mask_k) && (alg_a & mask_a);
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n", ok, alg_k,
|
||||
alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4296,6 +4282,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
OSSL_TRACE7(TLS_CIPHER,
|
||||
"%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n",
|
||||
ok, alg_k, alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4315,6 +4301,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
|
||||
if (!ok)
|
||||
continue;
|
||||
@@ -276,20 +368,20 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
+ safari_ec = 0;
|
||||
+#if !defined(OPENSSL_NO_EC)
|
||||
+ if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)) {
|
||||
+ if (s->s3->is_probably_safari)
|
||||
+ if (s->s3.is_probably_safari)
|
||||
+ safari_ec = 1;
|
||||
+ }
|
||||
+#endif
|
||||
}
|
||||
ii = sk_SSL_CIPHER_find(allow, c);
|
||||
if (ii >= 0) {
|
||||
@@ -4303,14 +4297,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -4322,14 +4316,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (!ssl_security(s, SSL_SECOP_CIPHER_SHARED,
|
||||
c->strength_bits, 0, (void *)c))
|
||||
continue;
|
||||
-#if !defined(OPENSSL_NO_EC)
|
||||
- if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)
|
||||
- && s->s3->is_probably_safari) {
|
||||
- && s->s3.is_probably_safari) {
|
||||
- if (!ret)
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
- continue;
|
||||
@@ -299,7 +391,7 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
@@ -4322,13 +4309,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -4346,13 +4333,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
ret = tmp;
|
||||
continue;
|
||||
}
|
||||
@@ -343,10 +435,10 @@ index a5b3dbbfd5..6dd4ad4b68 100644
|
||||
}
|
||||
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 461a9debab..8eb18f0e28 100644
|
||||
index 066c38a7cc..f1e3d1cbe2 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -192,6 +192,7 @@ typedef struct cipher_order_st {
|
||||
@@ -154,6 +154,7 @@ typedef struct cipher_order_st {
|
||||
const SSL_CIPHER *cipher;
|
||||
int active;
|
||||
int dead;
|
||||
@@ -354,7 +446,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
struct cipher_order_st *next, *prev;
|
||||
} CIPHER_ORDER;
|
||||
|
||||
@@ -296,6 +297,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
@@ -259,6 +260,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_TLSV1, NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, "TLSv1.0", NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, SSL_TXT_TLSV1_2, NULL, 0, 0, 0, 0, 0, TLS1_2_VERSION},
|
||||
@@ -362,7 +454,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
|
||||
/* strength classes */
|
||||
{0, SSL_TXT_LOW, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_LOW},
|
||||
@@ -681,6 +683,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
@@ -673,6 +675,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
co_list[co_list_num].next = NULL;
|
||||
co_list[co_list_num].prev = NULL;
|
||||
co_list[co_list_num].active = 0;
|
||||
@@ -370,7 +462,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
co_list_num++;
|
||||
}
|
||||
|
||||
@@ -774,8 +777,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -766,8 +769,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
uint32_t alg_auth, uint32_t alg_enc,
|
||||
uint32_t alg_mac, int min_tls,
|
||||
uint32_t algo_strength, int rule,
|
||||
@@ -381,19 +473,19 @@ index 461a9debab..8eb18f0e28 100644
|
||||
{
|
||||
CIPHER_ORDER *head, *tail, *curr, *next, *last;
|
||||
const SSL_CIPHER *cp;
|
||||
@@ -783,9 +786,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -775,9 +778,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr,
|
||||
OSSL_TRACE_BEGIN(TLS_CIPHER){
|
||||
BIO_printf(trc_out,
|
||||
- "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d)\n",
|
||||
+ "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d) g:%d\n",
|
||||
rule, alg_mkey, alg_auth, alg_enc, alg_mac, min_tls,
|
||||
- algo_strength, strength_bits);
|
||||
+ algo_strength, strength_bits, in_group);
|
||||
#endif
|
||||
}
|
||||
|
||||
if (rule == CIPHER_DEL || rule == CIPHER_BUMP)
|
||||
@@ -862,6 +865,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -854,6 +857,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
if (!curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
curr->active = 1;
|
||||
@@ -401,7 +493,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
}
|
||||
}
|
||||
/* Move the added cipher to this location */
|
||||
@@ -869,6 +873,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -861,6 +865,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
/* reverse == 0 */
|
||||
if (curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
@@ -409,7 +501,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
}
|
||||
} else if (rule == CIPHER_DEL) {
|
||||
/* reverse == 1 */
|
||||
@@ -880,6 +885,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
@@ -872,6 +877,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
*/
|
||||
ll_append_head(&head, curr, &tail);
|
||||
curr->active = 0;
|
||||
@@ -417,7 +509,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
}
|
||||
} else if (rule == CIPHER_BUMP) {
|
||||
if (curr->active)
|
||||
@@ -947,8 +953,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
@@ -941,8 +947,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
*/
|
||||
for (i = max_strength_bits; i >= 0; i--)
|
||||
if (number_uses[i] > 0)
|
||||
@@ -428,7 +520,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
|
||||
OPENSSL_free(number_uses);
|
||||
return 1;
|
||||
@@ -962,7 +968,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -956,7 +962,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
uint32_t alg_mkey, alg_auth, alg_enc, alg_mac, algo_strength;
|
||||
int min_tls;
|
||||
const char *l, *buf;
|
||||
@@ -437,7 +529,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
uint32_t cipher_id = 0;
|
||||
char ch;
|
||||
|
||||
@@ -973,18 +979,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -967,18 +973,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
|
||||
if (ch == '\0')
|
||||
break; /* done */
|
||||
@@ -505,7 +597,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
} else {
|
||||
rule = CIPHER_ADD;
|
||||
}
|
||||
@@ -1009,7 +1063,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -1003,7 +1057,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
while (((ch >= 'A') && (ch <= 'Z')) ||
|
||||
((ch >= '0') && (ch <= '9')) ||
|
||||
((ch >= 'a') && (ch <= 'z')) ||
|
||||
@@ -514,7 +606,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
#else
|
||||
while (isalnum((unsigned char)ch) || (ch == '-') || (ch == '.')
|
||||
|| (ch == '='))
|
||||
@@ -1026,7 +1080,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -1020,7 +1074,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
* alphanumeric, so we call this an error.
|
||||
*/
|
||||
SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
@@ -523,7 +615,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
l++;
|
||||
break;
|
||||
}
|
||||
@@ -1205,8 +1259,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -1199,8 +1253,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
} else if (found) {
|
||||
ssl_cipher_apply_rule(cipher_id,
|
||||
alg_mkey, alg_auth, alg_enc, alg_mac,
|
||||
@@ -534,7 +626,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
} else {
|
||||
while ((*l != '\0') && !ITEM_SEP(*l))
|
||||
l++;
|
||||
@@ -1215,6 +1269,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
@@ -1209,6 +1263,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
break; /* done */
|
||||
}
|
||||
|
||||
@@ -546,25 +638,29 @@ index 461a9debab..8eb18f0e28 100644
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1379,7 +1438,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
@@ -1372,7 +1431,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
int ret = set_ciphersuites(&(ctx->tls13_ciphersuites), str);
|
||||
|
||||
if (ret && ctx->cipher_list != NULL) {
|
||||
/* We already have a cipher_list, so we need to update it */
|
||||
if (ret && ctx->cipher_list != NULL)
|
||||
- return update_cipher_list(&ctx->cipher_list, &ctx->cipher_list_by_id,
|
||||
+ return update_cipher_list(&ctx->cipher_list->ciphers, &ctx->cipher_list_by_id,
|
||||
ctx->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1385,10 +1444,10 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (s->cipher_list == NULL) {
|
||||
if ((cipher_list = SSL_get_ciphers(s)) != NULL)
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(cipher_list);
|
||||
+ s->cipher_list->ciphers = sk_SSL_CIPHER_dup(cipher_list);
|
||||
}
|
||||
|
||||
@@ -1392,7 +1451,7 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (ret && s->cipher_list != NULL) {
|
||||
/* We already have a cipher_list, so we need to update it */
|
||||
if (ret && s->cipher_list != NULL)
|
||||
- return update_cipher_list(&s->cipher_list, &s->cipher_list_by_id,
|
||||
+ return update_cipher_list(&s->cipher_list->ciphers, &s->cipher_list_by_id,
|
||||
s->tls13_ciphersuites);
|
||||
}
|
||||
|
||||
@@ -1401,17 +1460,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
return ret;
|
||||
@@ -1396,17 +1455,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
@@ -588,7 +684,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
|
||||
/*
|
||||
* Return with error if nothing to do.
|
||||
@@ -1460,16 +1522,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1455,16 +1517,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* preference).
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, SSL_kECDHE, SSL_aECDSA, 0, 0, 0, 0, CIPHER_ADD,
|
||||
@@ -612,7 +708,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1478,13 +1540,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1473,13 +1535,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* strength.
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, 0, 0, SSL_AES ^ SSL_AESGCM, 0, 0, 0, CIPHER_ADD,
|
||||
@@ -629,7 +725,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1492,16 +1554,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1487,16 +1549,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* disabled. (For applications that allow them, they aren't too bad, but
|
||||
* we prefer authenticated ciphers.)
|
||||
*/
|
||||
@@ -650,7 +746,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1517,7 +1579,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1512,7 +1574,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Partially overrule strength sort to prefer TLS 1.2 ciphers/PRFs.
|
||||
* TODO(openssl-team): is there an easier way to accomplish all this?
|
||||
*/
|
||||
@@ -659,7 +755,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1533,15 +1595,18 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1528,15 +1590,18 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Because we now bump ciphers to the top of the list, we proceed in
|
||||
* reverse order of preference.
|
||||
*/
|
||||
@@ -682,7 +778,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
|
||||
/*
|
||||
* We also need cipher aliases for selecting based on the rule_str.
|
||||
@@ -1555,9 +1620,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1550,9 +1615,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
num_of_alias_max = num_of_ciphers + num_of_group_aliases + 1;
|
||||
ca_list = OPENSSL_malloc(sizeof(*ca_list) * num_of_alias_max);
|
||||
if (ca_list == NULL) {
|
||||
@@ -693,7 +789,7 @@ index 461a9debab..8eb18f0e28 100644
|
||||
}
|
||||
ssl_cipher_collect_aliases(ca_list, num_of_group_aliases,
|
||||
disabled_mkey, disabled_auth, disabled_enc,
|
||||
@@ -1582,28 +1646,19 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
@@ -1577,28 +1641,19 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
|
||||
OPENSSL_free(ca_list); /* Not needed anymore */
|
||||
|
||||
@@ -727,26 +823,26 @@ index 461a9debab..8eb18f0e28 100644
|
||||
+ if (!in_group_flags)
|
||||
+ goto err;
|
||||
|
||||
/*
|
||||
* The cipher selection for the list is done. The ciphers are added
|
||||
@@ -1611,26 +1666,50 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
*/
|
||||
OSSL_TRACE_BEGIN(TLS_CIPHER) {
|
||||
BIO_printf(trc_out, "cipher selection:\n");
|
||||
@@ -1610,26 +1665,51 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
for (curr = head; curr != NULL; curr = curr->next) {
|
||||
if (curr->active) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
- OPENSSL_free(co_list);
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
OSSL_TRACE_CANCEL(TLS_CIPHER);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher))
|
||||
+ goto err;
|
||||
}
|
||||
+ in_group_flags[num_in_group_flags++] = curr->in_group;
|
||||
#ifdef CIPHER_DEBUG
|
||||
fprintf(stderr, "<%s>\n", curr->cipher->name);
|
||||
#endif
|
||||
if (trc_out != NULL)
|
||||
BIO_printf(trc_out, "<%s>\n", curr->cipher->name);
|
||||
}
|
||||
}
|
||||
- OPENSSL_free(co_list); /* Not needed any longer */
|
||||
OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
OSSL_TRACE_END(TLS_CIPHER);
|
||||
|
||||
- if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack)) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
@@ -754,9 +850,6 @@ index 461a9debab..8eb18f0e28 100644
|
||||
- }
|
||||
- sk_SSL_CIPHER_free(*cipher_list);
|
||||
- *cipher_list = cipherstack;
|
||||
+ OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
+
|
||||
+ if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack))
|
||||
+ goto err;
|
||||
+
|
||||
@@ -789,32 +882,48 @@ index 461a9debab..8eb18f0e28 100644
|
||||
+ if (pref_list)
|
||||
+ OPENSSL_free(pref_list);
|
||||
+ return NULL;
|
||||
+
|
||||
}
|
||||
|
||||
char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
diff --git a/ssl/ssl_err.c b/ssl/ssl_err.c
|
||||
index ceae87bbc9..46521b7136 100644
|
||||
index 85d9dd8448..64f7577a90 100644
|
||||
--- a/ssl/ssl_err.c
|
||||
+++ b/ssl/ssl_err.c
|
||||
@@ -965,6 +965,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_DH_KEY), "missing tmp dh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MISSING_TMP_ECDH_KEY),
|
||||
@@ -14,6 +14,8 @@
|
||||
#ifndef OPENSSL_NO_ERR
|
||||
|
||||
static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ALGORITHM_FETCH_FAILED),
|
||||
+ "algorithm fetch failed"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY),
|
||||
"application data after close notify"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_APP_DATA_IN_HANDSHAKE),
|
||||
@@ -171,8 +173,6 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"ext length mismatch"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_FAILED_TO_INIT_ASYNC),
|
||||
"failed to init async"},
|
||||
- {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ALGORITHM_FETCH_FAILED),
|
||||
- "algorithm fetch failed"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_FRAGMENTED_CLIENT_HELLO),
|
||||
"fragmented client hello"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_GOT_A_FIN_BEFORE_A_CCS),
|
||||
@@ -257,6 +257,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"missing tmp ecdh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS),
|
||||
+ "mixed special operator with groups"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NESTED_GROUP), "nested group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_ON_RECORD_BOUNDARY),
|
||||
@@ -1201,11 +1204,14 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unable to load ssl3 md5 routines"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES),
|
||||
"unable to load ssl3 sha1 routines"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE), "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_CCS_MESSAGE),
|
||||
"unexpected ccs message"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_END_OF_EARLY_DATA),
|
||||
"not on record boundary"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_REPLACING_CERTIFICATE),
|
||||
@@ -493,7 +496,11 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unexpected end of early data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_EOF_WHILE_READING),
|
||||
"unexpected eof while reading"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE),
|
||||
+ "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_MESSAGE), "unexpected message"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP),
|
||||
+ "unexpected operator in group"},
|
||||
@@ -822,10 +931,10 @@ index ceae87bbc9..46521b7136 100644
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNINITIALIZED), "uninitialized"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNKNOWN_ALERT_TYPE), "unknown alert type"},
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index 322a4381b0..ac33c35560 100644
|
||||
index a08ddb138b..fc6d1ac2a3 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -1119,6 +1119,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
@@ -1127,6 +1127,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
return X509_VERIFY_PARAM_set1(ssl->param, vpm);
|
||||
}
|
||||
|
||||
@@ -897,7 +1006,7 @@ index 322a4381b0..ac33c35560 100644
|
||||
X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx)
|
||||
{
|
||||
return ctx->param;
|
||||
@@ -1163,7 +1228,8 @@ void SSL_free(SSL *s)
|
||||
@@ -1171,7 +1236,8 @@ void SSL_free(SSL *s)
|
||||
BUF_MEM_free(s->init_buf);
|
||||
|
||||
/* add extra stuff */
|
||||
@@ -906,8 +1015,8 @@ index 322a4381b0..ac33c35560 100644
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(s->tls13_ciphersuites);
|
||||
|
||||
@@ -2498,9 +2564,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
sk_SSL_CIPHER_free(s->peer_ciphers);
|
||||
@@ -2566,9 +2632,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
{
|
||||
if (s != NULL) {
|
||||
if (s->cipher_list != NULL) {
|
||||
@@ -919,7 +1028,7 @@ index 322a4381b0..ac33c35560 100644
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
@@ -2574,8 +2640,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
@@ -2642,8 +2708,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
* preference */
|
||||
STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx)
|
||||
{
|
||||
@@ -930,16 +1039,16 @@ index 322a4381b0..ac33c35560 100644
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -3026,7 +3092,7 @@ SSL_CTX *SSL_CTX_new(const SSL_METHOD *meth)
|
||||
@@ -3157,7 +3223,7 @@ SSL_CTX *SSL_CTX_new_with_libctx(OPENSSL_CTX *libctx, const char *propq,
|
||||
ret->tls13_ciphersuites,
|
||||
&ret->cipher_list, &ret->cipher_list_by_id,
|
||||
SSL_DEFAULT_CIPHER_LIST, ret->cert)
|
||||
OSSL_default_cipher_list(), ret->cert)
|
||||
- || sk_SSL_CIPHER_num(ret->cipher_list) <= 0) {
|
||||
+ || sk_SSL_CIPHER_num(ret->cipher_list->ciphers) <= 0) {
|
||||
SSLerr(SSL_F_SSL_CTX_NEW, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
SSLerr(0, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
goto err2;
|
||||
}
|
||||
@@ -3202,7 +3268,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
@@ -3336,7 +3402,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
#ifndef OPENSSL_NO_CT
|
||||
CTLOG_STORE_free(a->ctlog_store);
|
||||
#endif
|
||||
@@ -948,7 +1057,7 @@ index 322a4381b0..ac33c35560 100644
|
||||
sk_SSL_CIPHER_free(a->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(a->tls13_ciphersuites);
|
||||
ssl_cert_free(a->cert);
|
||||
@@ -3880,13 +3946,15 @@ SSL *SSL_dup(SSL *s)
|
||||
@@ -4022,13 +4088,15 @@ SSL *SSL_dup(SSL *s)
|
||||
|
||||
/* dup the cipher_list and cipher_list_by_id stacks */
|
||||
if (s->cipher_list != NULL) {
|
||||
@@ -968,13 +1077,13 @@ index 322a4381b0..ac33c35560 100644
|
||||
|
||||
/* Dup the client_CA list */
|
||||
if (!dup_ca_names(&ret->ca_names, s->ca_names)
|
||||
diff --git a/ssl/ssl_locl.h b/ssl/ssl_locl.h
|
||||
index ae6417b592..9f839acc74 100644
|
||||
--- a/ssl/ssl_locl.h
|
||||
+++ b/ssl/ssl_locl.h
|
||||
@@ -745,9 +745,46 @@ typedef struct ssl_ctx_ext_secure_st {
|
||||
unsigned char tick_aes_key[TLSEXT_TICK_KEY_LENGTH];
|
||||
} SSL_CTX_EXT_SECURE;
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index c48bcb9a9a..dfb3e13464 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -789,11 +789,48 @@ int ssl_hmac_final(SSL_HMAC *ctx, unsigned char *md, size_t *len,
|
||||
size_t max_size);
|
||||
size_t ssl_hmac_size(const SSL_HMAC *ctx);
|
||||
|
||||
+/* ssl_cipher_preference_list_st contains a list of SSL_CIPHERs with
|
||||
+ * equal-preference groups. For TLS clients, the groups are moot because the
|
||||
@@ -1014,22 +1123,24 @@ index ae6417b592..9f839acc74 100644
|
||||
+
|
||||
+
|
||||
struct ssl_ctx_st {
|
||||
OPENSSL_CTX *libctx;
|
||||
|
||||
const SSL_METHOD *method;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
/* same as above but sorted for lookup */
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
@@ -1146,7 +1183,7 @@ struct ssl_st {
|
||||
/* Per connection DANE state */
|
||||
@@ -1380,7 +1417,7 @@ struct ssl_st {
|
||||
SSL_DANE dane;
|
||||
/* crypto */
|
||||
STACK_OF(SSL_CIPHER) *peer_ciphers;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites;
|
||||
@@ -2275,7 +2312,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
@@ -2353,7 +2390,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
const SSL_CIPHER *const *bp);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
@@ -1038,7 +1149,7 @@ index ae6417b592..9f839acc74 100644
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c);
|
||||
@@ -2285,6 +2322,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
@@ -2363,6 +2400,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
@@ -1049,10 +1160,10 @@ index ae6417b592..9f839acc74 100644
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_from_ciphers(
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers);
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s);
|
||||
__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
const EVP_MD **md, int *mac_pkey_type,
|
||||
size_t *mac_secret_size, SSL_COMP **comp,
|
||||
@@ -2368,7 +2412,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
__owur int ssl_cipher_get_evp_cipher(SSL_CTX *ctx, const SSL_CIPHER *sslc,
|
||||
const EVP_CIPHER **enc);
|
||||
__owur int ssl_cipher_get_evp(SSL_CTX *ctxc, const SSL_SESSION *s,
|
||||
@@ -2450,7 +2494,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
CERT_PKEY *cpk);
|
||||
__owur const SSL_CIPHER *ssl3_choose_cipher(SSL *ssl,
|
||||
STACK_OF(SSL_CIPHER) *clnt,
|
||||
@@ -1062,10 +1173,10 @@ index ae6417b592..9f839acc74 100644
|
||||
__owur int ssl3_new(SSL *s);
|
||||
void ssl3_free(SSL *s);
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index bf1819d356..ebb6224b5e 100644
|
||||
index 43f9811163..769f0c7eb6 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -1750,7 +1750,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
@@ -1774,7 +1774,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* For TLSv1.3 we must select the ciphersuite *before* session resumption */
|
||||
if (SSL_IS_TLS13(s)) {
|
||||
const SSL_CIPHER *cipher =
|
||||
@@ -1074,33 +1185,33 @@ index bf1819d356..ebb6224b5e 100644
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1931,7 +1931,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
@@ -1957,7 +1957,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* check if some cipher was preferred by call back */
|
||||
if (pref_cipher == NULL)
|
||||
pref_cipher = ssl3_choose_cipher(s, s->session->ciphers,
|
||||
pref_cipher = ssl3_choose_cipher(s, s->peer_ciphers,
|
||||
- SSL_get_ciphers(s));
|
||||
+ ssl_get_cipher_preferences(s));
|
||||
if (pref_cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_F_TLS_EARLY_POST_PROCESS_CLIENT_HELLO,
|
||||
@@ -1940,8 +1940,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
@@ -1966,8 +1966,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
}
|
||||
|
||||
s->session->cipher = pref_cipher;
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->session->ciphers);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
+ s->cipher_list = ssl_cipher_preference_list_from_ciphers(
|
||||
+ s->session->ciphers);
|
||||
+ s->peer_ciphers);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->session->ciphers);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
}
|
||||
@@ -2255,7 +2256,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
@@ -2279,7 +2280,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
/* In TLSv1.3 we selected the ciphersuite before resumption */
|
||||
if (!SSL_IS_TLS13(s)) {
|
||||
cipher =
|
||||
- ssl3_choose_cipher(s, s->session->ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->session->ciphers, ssl_get_cipher_preferences(s));
|
||||
- ssl3_choose_cipher(s, s->peer_ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->peer_ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -0,0 +1,1258 @@
|
||||
diff --git a/crypto/err/openssl.txt b/crypto/err/openssl.txt
|
||||
index f467ea909f..76cc311ba8 100644
|
||||
--- a/crypto/err/openssl.txt
|
||||
+++ b/crypto/err/openssl.txt
|
||||
@@ -3009,6 +3009,7 @@ SM2_R_INVALID_ENCODING:104:invalid encoding
|
||||
SM2_R_INVALID_FIELD:105:invalid field
|
||||
SM2_R_NO_PARAMETERS_SET:109:no parameters set
|
||||
SM2_R_USER_ID_TOO_LARGE:106:user id too large
|
||||
+SSL_R_ALGORITHM_FETCH_FAILED:295:algorithm fetch failed
|
||||
SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY:291:\
|
||||
application data after close notify
|
||||
SSL_R_APP_DATA_IN_HANDSHAKE:100:app data in handshake
|
||||
@@ -3115,7 +3116,6 @@ SSL_R_EXTENSION_NOT_RECEIVED:279:extension not received
|
||||
SSL_R_EXTRA_DATA_IN_MESSAGE:153:extra data in message
|
||||
SSL_R_EXT_LENGTH_MISMATCH:163:ext length mismatch
|
||||
SSL_R_FAILED_TO_INIT_ASYNC:405:failed to init async
|
||||
-SSL_R_ALGORITHM_FETCH_FAILED:295:algorithm fetch failed
|
||||
SSL_R_FRAGMENTED_CLIENT_HELLO:401:fragmented client hello
|
||||
SSL_R_GOT_A_FIN_BEFORE_A_CCS:154:got a fin before a ccs
|
||||
SSL_R_HTTPS_PROXY_REQUEST:155:https proxy request
|
||||
@@ -3166,6 +3166,8 @@ SSL_R_MISSING_TMP_DH_KEY:171:missing tmp dh key
|
||||
SSL_R_MISSING_TMP_ECDH_KEY:311:missing tmp ecdh key
|
||||
SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA:293:\
|
||||
mixed handshake and non handshake data
|
||||
+SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS:296:mixed special operator with groups
|
||||
+SSL_R_NESTED_GROUP:297:nested group
|
||||
SSL_R_NOT_ON_RECORD_BOUNDARY:182:not on record boundary
|
||||
SSL_R_NOT_REPLACING_CERTIFICATE:289:not replacing certificate
|
||||
SSL_R_NOT_SERVER:284:not server
|
||||
@@ -3273,7 +3275,9 @@ SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES:243:unable to load ssl3 sha1 routines
|
||||
SSL_R_UNEXPECTED_CCS_MESSAGE:262:unexpected ccs message
|
||||
SSL_R_UNEXPECTED_END_OF_EARLY_DATA:178:unexpected end of early data
|
||||
SSL_R_UNEXPECTED_EOF_WHILE_READING:294:unexpected eof while reading
|
||||
+SSL_R_UNEXPECTED_GROUP_CLOSE:299:unexpected group close
|
||||
SSL_R_UNEXPECTED_MESSAGE:244:unexpected message
|
||||
+SSL_R_UNEXPECTED_OPERATOR_IN_GROUP:305:unexpected operator in group
|
||||
SSL_R_UNEXPECTED_RECORD:245:unexpected record
|
||||
SSL_R_UNINITIALIZED:276:uninitialized
|
||||
SSL_R_UNKNOWN_ALERT_TYPE:246:unknown alert type
|
||||
diff --git a/doc/man1/openssl-ciphers.pod.in b/doc/man1/openssl-ciphers.pod.in
|
||||
index 9e5224579a..020bdcbcb9 100644
|
||||
--- a/doc/man1/openssl-ciphers.pod.in
|
||||
+++ b/doc/man1/openssl-ciphers.pod.in
|
||||
@@ -405,6 +405,21 @@ permissible.
|
||||
|
||||
=back
|
||||
|
||||
+=head1 EQUAL PREFERENCE GROUPS
|
||||
+
|
||||
+If configuring a server, one may also configure equal-preference groups to
|
||||
+partially respect the client's preferences when
|
||||
+B<SSL_OP_CIPHER_SERVER_PREFERENCE> is enabled. Ciphers in an equal-preference
|
||||
+group have equal priority and use the client order. This may be used to
|
||||
+enforce that AEADs are preferred but select AES-GCM vs. ChaCha20-Poly1305
|
||||
+based on client preferences. An equal-preference is specified with square
|
||||
+brackets, combining multiple selectors separated by |. For example:
|
||||
+
|
||||
+ [ECDHE-ECDSA-CHACHA20-POLY1305|ECDHE-ECDSA-AES128-GCM-SHA256]
|
||||
+
|
||||
+ Once an equal-preference group is used, future directives must be
|
||||
+ opcode-less.
|
||||
+
|
||||
=head1 CIPHER SUITE NAMES
|
||||
|
||||
The following lists give the SSL or TLS cipher suites names from the
|
||||
diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h
|
||||
index e1617aae45..a04a3e1552 100644
|
||||
--- a/include/openssl/sslerr.h
|
||||
+++ b/include/openssl/sslerr.h
|
||||
@@ -10,12 +10,6 @@
|
||||
|
||||
#ifndef OPENSSL_SSLERR_H
|
||||
# define OPENSSL_SSLERR_H
|
||||
-# pragma once
|
||||
-
|
||||
-# include <openssl/macros.h>
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
-# define HEADER_SSLERR_H
|
||||
-# endif
|
||||
|
||||
# include <openssl/opensslconf.h>
|
||||
# include <openssl/symhacks.h>
|
||||
@@ -462,6 +456,7 @@ int ERR_load_SSL_strings(void);
|
||||
/*
|
||||
* SSL reason codes.
|
||||
*/
|
||||
+# define SSL_R_ALGORITHM_FETCH_FAILED 295
|
||||
# define SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY 291
|
||||
# define SSL_R_APP_DATA_IN_HANDSHAKE 100
|
||||
# define SSL_R_ATTEMPT_TO_REUSE_SESSION_IN_DIFFERENT_CONTEXT 272
|
||||
@@ -561,7 +556,6 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_EXTRA_DATA_IN_MESSAGE 153
|
||||
# define SSL_R_EXT_LENGTH_MISMATCH 163
|
||||
# define SSL_R_FAILED_TO_INIT_ASYNC 405
|
||||
-# define SSL_R_ALGORITHM_FETCH_FAILED 295
|
||||
# define SSL_R_FRAGMENTED_CLIENT_HELLO 401
|
||||
# define SSL_R_GOT_A_FIN_BEFORE_A_CCS 154
|
||||
# define SSL_R_HTTPS_PROXY_REQUEST 155
|
||||
@@ -611,6 +605,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_TMP_DH_KEY 171
|
||||
# define SSL_R_MISSING_TMP_ECDH_KEY 311
|
||||
# define SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA 293
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 296
|
||||
+# define SSL_R_NESTED_GROUP 297
|
||||
# define SSL_R_NOT_ON_RECORD_BOUNDARY 182
|
||||
# define SSL_R_NOT_REPLACING_CERTIFICATE 289
|
||||
# define SSL_R_NOT_SERVER 284
|
||||
@@ -742,7 +738,9 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
# define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
# define SSL_R_UNEXPECTED_EOF_WHILE_READING 294
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 299
|
||||
# define SSL_R_UNEXPECTED_MESSAGE 244
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 305
|
||||
# define SSL_R_UNEXPECTED_RECORD 245
|
||||
# define SSL_R_UNINITIALIZED 276
|
||||
# define SSL_R_UNKNOWN_ALERT_TYPE 246
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 26f19108ee..41bf523363 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -33,7 +33,25 @@ const unsigned char tls12downgrade[] = {
|
||||
};
|
||||
|
||||
/* The list of available TLSv1.3 ciphers */
|
||||
+/* Since nginx can not set the TLS 1.3 cipher, remove it temporarily. */
|
||||
static SSL_CIPHER tls13_ciphers[] = {
|
||||
+ {
|
||||
+ 0,
|
||||
+ }
|
||||
+};
|
||||
+
|
||||
+/*
|
||||
+ * The list of available ciphers, mostly organized into the following
|
||||
+ * groups:
|
||||
+ * Always there
|
||||
+ * EC
|
||||
+ * PSK
|
||||
+ * SRP (within that: RSA EC PSK)
|
||||
+ * Cipher families: Chacha/poly, Camellia, Gost, IDEA, SEED
|
||||
+ * Weak ciphers
|
||||
+ */
|
||||
+static SSL_CIPHER ssl3_ciphers[] = {
|
||||
+ /* TLSv1.3 ciphers */
|
||||
{
|
||||
1,
|
||||
TLS1_3_RFC_AES_128_GCM_SHA256,
|
||||
@@ -113,20 +131,8 @@ static SSL_CIPHER tls13_ciphers[] = {
|
||||
SSL_HANDSHAKE_MAC_SHA256,
|
||||
128,
|
||||
128,
|
||||
- }
|
||||
-};
|
||||
-
|
||||
-/*
|
||||
- * The list of available ciphers, mostly organized into the following
|
||||
- * groups:
|
||||
- * Always there
|
||||
- * EC
|
||||
- * PSK
|
||||
- * SRP (within that: RSA EC PSK)
|
||||
- * Cipher families: Chacha/poly, Camellia, Gost, IDEA, SEED
|
||||
- * Weak ciphers
|
||||
- */
|
||||
-static SSL_CIPHER ssl3_ciphers[] = {
|
||||
+ },
|
||||
+ /* List of cipher below TLSv1.3 */
|
||||
{
|
||||
1,
|
||||
SSL3_TXT_RSA_NULL_MD5,
|
||||
@@ -169,7 +175,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -201,7 +207,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -234,7 +240,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -266,7 +272,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -298,7 +304,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -330,7 +336,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4142,6 +4148,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
return 1;
|
||||
}
|
||||
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s)
|
||||
+{
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ return (s->cipher_list);
|
||||
+
|
||||
+ if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL))
|
||||
+ return (s->ctx->cipher_list);
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* ssl3_choose_cipher - choose a cipher from those offered by the client
|
||||
* @s: SSL connection
|
||||
@@ -4151,16 +4168,24 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
* Returns the selected cipher or NULL when no common ciphers.
|
||||
*/
|
||||
const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr)
|
||||
+ struct ssl_cipher_preference_list_st
|
||||
+ *server_pref)
|
||||
{
|
||||
const SSL_CIPHER *c, *ret = NULL;
|
||||
- STACK_OF(SSL_CIPHER) *prio, *allow;
|
||||
- int i, ii, ok, prefer_sha256 = 0;
|
||||
+ STACK_OF(SSL_CIPHER) *srvr = server_pref->ciphers, *prio, *allow;
|
||||
+ int i, ii, ok, prefer_sha256 = 0, safari_ec = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
const EVP_MD *mdsha256 = EVP_sha256();
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
-#endif
|
||||
+
|
||||
+ /* in_group_flags will either be NULL, or will point to an array of
|
||||
+ * bytes which indicate equal-preference groups in the |prio| stack.
|
||||
+ * See the comment about |in_group_flags| in the
|
||||
+ * |ssl_cipher_preference_list_st| struct. */
|
||||
+ const uint8_t *in_group_flags;
|
||||
+
|
||||
+ /* group_min contains the minimal index so far found in a group, or -1
|
||||
+ * if no such value exists yet. */
|
||||
+ int group_min = -1;
|
||||
|
||||
/* Let's see which ciphers we can support */
|
||||
|
||||
@@ -4187,54 +4212,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
} OSSL_TRACE_END(TLS_CIPHER);
|
||||
|
||||
/* SUITE-B takes precedence over server preference and ChaCha priortiy */
|
||||
- if (tls1_suiteb(s)) {
|
||||
+ if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE || tls1_suiteb(s)) {
|
||||
prio = srvr;
|
||||
+ in_group_flags = server_pref->in_group_flags;
|
||||
allow = clnt;
|
||||
- } else if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE) {
|
||||
- prio = srvr;
|
||||
- allow = clnt;
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- /* If ChaCha20 is at the top of the client preference list,
|
||||
- and there are ChaCha20 ciphers in the server list, then
|
||||
- temporarily prioritize all ChaCha20 ciphers in the servers list. */
|
||||
- if (s->options & SSL_OP_PRIORITIZE_CHACHA && sk_SSL_CIPHER_num(clnt) > 0) {
|
||||
- c = sk_SSL_CIPHER_value(clnt, 0);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- /* ChaCha20 is client preferred, check server... */
|
||||
- int num = sk_SSL_CIPHER_num(srvr);
|
||||
- int found = 0;
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- found = 1;
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
- if (found) {
|
||||
- prio_chacha = sk_SSL_CIPHER_new_reserve(NULL, num);
|
||||
- /* if reserve fails, then there's likely a memory issue */
|
||||
- if (prio_chacha != NULL) {
|
||||
- /* Put all ChaCha20 at the top, starting with the one we just found */
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- for (i++; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- /* Pull in the rest */
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc != SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- prio = prio_chacha;
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
-# endif
|
||||
} else {
|
||||
prio = clnt;
|
||||
+ in_group_flags = NULL;
|
||||
allow = srvr;
|
||||
}
|
||||
|
||||
@@ -4265,14 +4249,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
|
||||
c = sk_SSL_CIPHER_value(prio, i);
|
||||
|
||||
+ ok = 1;
|
||||
+
|
||||
/* Skip ciphers not supported by the protocol version */
|
||||
if (!SSL_IS_DTLS(s) &&
|
||||
((s->version < c->min_tls) || (s->version > c->max_tls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
if (SSL_IS_DTLS(s) &&
|
||||
(DTLS_VERSION_LT(s->version, c->min_dtls) ||
|
||||
DTLS_VERSION_GT(s->version, c->max_dtls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
|
||||
/*
|
||||
* Since TLS 1.3 ciphersuites can be used with any auth or
|
||||
@@ -4294,10 +4280,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
/* with PSK there must be server callback set */
|
||||
if ((alg_k & SSL_PSK) && s->psk_server_callback == NULL)
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
#endif /* OPENSSL_NO_PSK */
|
||||
|
||||
- ok = (alg_k & mask_k) && (alg_a & mask_a);
|
||||
+ ok = ok && (alg_k & mask_k) && (alg_a & mask_a);
|
||||
OSSL_TRACE7(TLS_CIPHER,
|
||||
"%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n",
|
||||
ok, alg_k, alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4313,6 +4299,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
|
||||
if (!ok)
|
||||
continue;
|
||||
+
|
||||
+ safari_ec = 0;
|
||||
+#if !defined(OPENSSL_NO_EC)
|
||||
+ if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)) {
|
||||
+ if (s->s3.is_probably_safari)
|
||||
+ safari_ec = 1;
|
||||
+ }
|
||||
+#endif
|
||||
}
|
||||
ii = sk_SSL_CIPHER_find(allow, c);
|
||||
if (ii >= 0) {
|
||||
@@ -4320,14 +4314,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (!ssl_security(s, SSL_SECOP_CIPHER_SHARED,
|
||||
c->strength_bits, 0, (void *)c))
|
||||
continue;
|
||||
-#if !defined(OPENSSL_NO_EC)
|
||||
- if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)
|
||||
- && s->s3.is_probably_safari) {
|
||||
- if (!ret)
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
- continue;
|
||||
- }
|
||||
-#endif
|
||||
+
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
@@ -4339,13 +4326,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
ret = tmp;
|
||||
continue;
|
||||
}
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+
|
||||
+ if (in_group_flags != NULL && in_group_flags[i] == 1) {
|
||||
+ /* This element of |prio| is in a group. Update
|
||||
+ * the minimum index found so far and continue
|
||||
+ * looking. */
|
||||
+ if (group_min == -1 || group_min > ii)
|
||||
+ group_min = ii;
|
||||
+ } else {
|
||||
+ if (group_min != -1 && group_min < ii)
|
||||
+ ii = group_min;
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (in_group_flags != NULL && !in_group_flags[i] && group_min != -1) {
|
||||
+ /* We are about to leave a group, but we found a match
|
||||
+ * in it, so that's our answer. */
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
break;
|
||||
}
|
||||
}
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- sk_SSL_CIPHER_free(prio_chacha);
|
||||
-#endif
|
||||
return ret;
|
||||
}
|
||||
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 04ffae325c..b67369f639 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -193,6 +193,7 @@ typedef struct cipher_order_st {
|
||||
const SSL_CIPHER *cipher;
|
||||
int active;
|
||||
int dead;
|
||||
+ int in_group;
|
||||
struct cipher_order_st *next, *prev;
|
||||
} CIPHER_ORDER;
|
||||
|
||||
@@ -298,6 +299,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_TLSV1, NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, "TLSv1.0", NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, SSL_TXT_TLSV1_2, NULL, 0, 0, 0, 0, 0, TLS1_2_VERSION},
|
||||
+ {0, "TLS13", NULL, 0, 0, 0, 0, 0, TLS1_3_VERSION},
|
||||
|
||||
/* strength classes */
|
||||
{0, SSL_TXT_LOW, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_LOW},
|
||||
@@ -681,6 +683,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
co_list[co_list_num].next = NULL;
|
||||
co_list[co_list_num].prev = NULL;
|
||||
co_list[co_list_num].active = 0;
|
||||
+ co_list[co_list_num].in_group = 0;
|
||||
co_list_num++;
|
||||
}
|
||||
|
||||
@@ -774,8 +777,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
uint32_t alg_auth, uint32_t alg_enc,
|
||||
uint32_t alg_mac, int min_tls,
|
||||
uint32_t algo_strength, int rule,
|
||||
- int32_t strength_bits, CIPHER_ORDER **head_p,
|
||||
- CIPHER_ORDER **tail_p)
|
||||
+ int32_t strength_bits, int in_group,
|
||||
+ CIPHER_ORDER **head_p, CIPHER_ORDER **tail_p)
|
||||
{
|
||||
CIPHER_ORDER *head, *tail, *curr, *next, *last;
|
||||
const SSL_CIPHER *cp;
|
||||
@@ -783,9 +786,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
|
||||
OSSL_TRACE_BEGIN(TLS_CIPHER){
|
||||
BIO_printf(trc_out,
|
||||
- "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d)\n",
|
||||
+ "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d) g:%d\n",
|
||||
rule, alg_mkey, alg_auth, alg_enc, alg_mac, min_tls,
|
||||
- algo_strength, strength_bits);
|
||||
+ algo_strength, strength_bits, in_group);
|
||||
}
|
||||
|
||||
if (rule == CIPHER_DEL || rule == CIPHER_BUMP)
|
||||
@@ -862,6 +865,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
if (!curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
curr->active = 1;
|
||||
+ curr->in_group = in_group;
|
||||
}
|
||||
}
|
||||
/* Move the added cipher to this location */
|
||||
@@ -869,6 +873,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
/* reverse == 0 */
|
||||
if (curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_DEL) {
|
||||
/* reverse == 1 */
|
||||
@@ -880,6 +885,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
*/
|
||||
ll_append_head(&head, curr, &tail);
|
||||
curr->active = 0;
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_BUMP) {
|
||||
if (curr->active)
|
||||
@@ -949,8 +955,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
*/
|
||||
for (i = max_strength_bits; i >= 0; i--)
|
||||
if (number_uses[i] > 0)
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, head_p,
|
||||
- tail_p);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, 0,
|
||||
+ head_p, tail_p);
|
||||
|
||||
OPENSSL_free(number_uses);
|
||||
return 1;
|
||||
@@ -964,7 +970,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
uint32_t alg_mkey, alg_auth, alg_enc, alg_mac, algo_strength;
|
||||
int min_tls;
|
||||
const char *l, *buf;
|
||||
- int j, multi, found, rule, retval, ok, buflen;
|
||||
+ int j, multi, found, rule, retval, ok, buflen, in_group = 0, has_group = 0;
|
||||
uint32_t cipher_id = 0;
|
||||
char ch;
|
||||
|
||||
@@ -975,18 +981,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
|
||||
if (ch == '\0')
|
||||
break; /* done */
|
||||
- if (ch == '-') {
|
||||
+ if (in_group) {
|
||||
+ if (ch == ']') {
|
||||
+ if (!in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_GROUP_CLOSE);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ if (*tail_p)
|
||||
+ (*tail_p)->in_group = 0;
|
||||
+ in_group = 0;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ }
|
||||
+ if (ch == '|') {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ } else if (!(ch >= 'a' && ch <= 'z')
|
||||
+ && !(ch >= 'A' && ch <= 'Z')
|
||||
+ && !(ch >= '0' && ch <= '9')) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_OPERATOR_IN_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ } else {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ }
|
||||
+ } else if (ch == '-') {
|
||||
rule = CIPHER_DEL;
|
||||
l++;
|
||||
} else if (ch == '+') {
|
||||
rule = CIPHER_ORD;
|
||||
l++;
|
||||
+ } else if (ch == '!' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '!') {
|
||||
rule = CIPHER_KILL;
|
||||
l++;
|
||||
+ } else if (ch == '@' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '@') {
|
||||
rule = CIPHER_SPECIAL;
|
||||
l++;
|
||||
+ } else if (ch == '[') {
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_NESTED_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ in_group = 1;
|
||||
+ has_group = 1;
|
||||
+ l++;
|
||||
+ continue;
|
||||
} else {
|
||||
rule = CIPHER_ADD;
|
||||
}
|
||||
@@ -1011,7 +1065,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
while (((ch >= 'A') && (ch <= 'Z')) ||
|
||||
((ch >= '0') && (ch <= '9')) ||
|
||||
((ch >= 'a') && (ch <= 'z')) ||
|
||||
- (ch == '-') || (ch == '.') || (ch == '='))
|
||||
+ (ch == '-') || (ch == '.') || (ch == '=') || (ch == '_'))
|
||||
#else
|
||||
while (isalnum((unsigned char)ch) || (ch == '-') || (ch == '.')
|
||||
|| (ch == '='))
|
||||
@@ -1028,7 +1082,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
* alphanumeric, so we call this an error.
|
||||
*/
|
||||
SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
- retval = found = 0;
|
||||
+ retval = found = in_group = 0;
|
||||
l++;
|
||||
break;
|
||||
}
|
||||
@@ -1207,8 +1261,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
} else if (found) {
|
||||
ssl_cipher_apply_rule(cipher_id,
|
||||
alg_mkey, alg_auth, alg_enc, alg_mac,
|
||||
- min_tls, algo_strength, rule, -1, head_p,
|
||||
- tail_p);
|
||||
+ min_tls, algo_strength, rule, -1, in_group,
|
||||
+ head_p, tail_p);
|
||||
} else {
|
||||
while ((*l != '\0') && !ITEM_SEP(*l))
|
||||
l++;
|
||||
@@ -1217,6 +1271,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
break; /* done */
|
||||
}
|
||||
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
+ retval = 0;
|
||||
+ }
|
||||
+
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1380,7 +1439,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
int ret = set_ciphersuites(&(ctx->tls13_ciphersuites), str);
|
||||
|
||||
if (ret && ctx->cipher_list != NULL)
|
||||
- return update_cipher_list(&ctx->cipher_list, &ctx->cipher_list_by_id,
|
||||
+ return update_cipher_list(&ctx->cipher_list->ciphers, &ctx->cipher_list_by_id,
|
||||
ctx->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1393,10 +1452,10 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (s->cipher_list == NULL) {
|
||||
if ((cipher_list = SSL_get_ciphers(s)) != NULL)
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(cipher_list);
|
||||
+ s->cipher_list->ciphers = sk_SSL_CIPHER_dup(cipher_list);
|
||||
}
|
||||
if (ret && s->cipher_list != NULL)
|
||||
- return update_cipher_list(&s->cipher_list, &s->cipher_list_by_id,
|
||||
+ return update_cipher_list(&s->cipher_list->ciphers, &s->cipher_list_by_id,
|
||||
s->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1404,17 +1463,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c)
|
||||
{
|
||||
- int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i;
|
||||
+ int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases;
|
||||
uint32_t disabled_mkey, disabled_auth, disabled_enc, disabled_mac;
|
||||
- STACK_OF(SSL_CIPHER) *cipherstack;
|
||||
+ STACK_OF(SSL_CIPHER) *cipherstack = NULL;
|
||||
const char *rule_p;
|
||||
CIPHER_ORDER *co_list = NULL, *head = NULL, *tail = NULL, *curr;
|
||||
const SSL_CIPHER **ca_list = NULL;
|
||||
+ uint8_t *in_group_flags = NULL;
|
||||
+ unsigned int num_in_group_flags = 0;
|
||||
+ struct ssl_cipher_preference_list_st *pref_list = NULL;
|
||||
|
||||
/*
|
||||
* Return with error if nothing to do.
|
||||
@@ -1463,16 +1525,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* preference).
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, SSL_kECDHE, SSL_aECDSA, 0, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head,
|
||||
- &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head,
|
||||
- &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
+ &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Within each strength group, we prefer GCM over CHACHA... */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1481,13 +1543,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* strength.
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, 0, 0, SSL_AES ^ SSL_AESGCM, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
|
||||
/* Temporarily enable everything else for sorting */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0, &head, &tail);
|
||||
|
||||
/* Low priority for MD5 */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1495,16 +1557,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* disabled. (For applications that allow them, they aren't too bad, but
|
||||
* we prefer authenticated ciphers.)
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
- ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/* RC4 is sort-of broken -- move to the end */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1520,7 +1582,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Partially overrule strength sort to prefer TLS 1.2 ciphers/PRFs.
|
||||
* TODO(openssl-team): is there an easier way to accomplish all this?
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1536,15 +1598,18 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Because we now bump ciphers to the top of the list, we proceed in
|
||||
* reverse order of preference.
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, 0, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, SSL_AEAD, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
+
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_3_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Now disable everything (maintaining the ordering!) */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0, &head, &tail);
|
||||
|
||||
/*
|
||||
* We also need cipher aliases for selecting based on the rule_str.
|
||||
@@ -1558,9 +1623,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
num_of_alias_max = num_of_ciphers + num_of_group_aliases + 1;
|
||||
ca_list = OPENSSL_malloc(sizeof(*ca_list) * num_of_alias_max);
|
||||
if (ca_list == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
SSLerr(SSL_F_SSL_CREATE_CIPHER_LIST, ERR_R_MALLOC_FAILURE);
|
||||
- return NULL; /* Failure */
|
||||
+ goto err; /* Failure */
|
||||
}
|
||||
ssl_cipher_collect_aliases(ca_list, num_of_group_aliases,
|
||||
disabled_mkey, disabled_auth, disabled_enc,
|
||||
@@ -1585,28 +1649,19 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
|
||||
OPENSSL_free(ca_list); /* Not needed anymore */
|
||||
|
||||
- if (!ok) { /* Rule processing failure */
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!ok)
|
||||
+ goto err; /* Rule processing failure */
|
||||
|
||||
/*
|
||||
* Allocate new "cipherstack" for the result, return with error
|
||||
* if we cannot get one.
|
||||
*/
|
||||
- if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL)
|
||||
+ goto err;
|
||||
|
||||
- /* Add TLSv1.3 ciphers first - we always prefer those if possible */
|
||||
- for (i = 0; i < sk_SSL_CIPHER_num(tls13_ciphersuites); i++) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack,
|
||||
- sk_SSL_CIPHER_value(tls13_ciphersuites, i))) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- }
|
||||
+ in_group_flags = OPENSSL_malloc(num_of_ciphers);
|
||||
+ if (!in_group_flags)
|
||||
+ goto err;
|
||||
|
||||
OSSL_TRACE_BEGIN(TLS_CIPHER) {
|
||||
BIO_printf(trc_out, "cipher selection:\n");
|
||||
@@ -1618,26 +1673,51 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
for (curr = head; curr != NULL; curr = curr->next) {
|
||||
if (curr->active) {
|
||||
if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
- OPENSSL_free(co_list);
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
OSSL_TRACE_CANCEL(TLS_CIPHER);
|
||||
- return NULL;
|
||||
+ goto err;
|
||||
}
|
||||
+ in_group_flags[num_in_group_flags++] = curr->in_group;
|
||||
if (trc_out != NULL)
|
||||
BIO_printf(trc_out, "<%s>\n", curr->cipher->name);
|
||||
}
|
||||
}
|
||||
OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
OSSL_TRACE_END(TLS_CIPHER);
|
||||
|
||||
- if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack)) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- sk_SSL_CIPHER_free(*cipher_list);
|
||||
- *cipher_list = cipherstack;
|
||||
+ if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack))
|
||||
+ goto err;
|
||||
+
|
||||
+ pref_list = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!pref_list)
|
||||
+ goto err;
|
||||
+ pref_list->ciphers = cipherstack;
|
||||
+ pref_list->in_group_flags = OPENSSL_malloc(num_in_group_flags);
|
||||
+ if (!pref_list->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(pref_list->in_group_flags, in_group_flags, num_in_group_flags);
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ in_group_flags = NULL;
|
||||
+ if (*cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(*cipher_list);
|
||||
+ *cipher_list = pref_list;
|
||||
+ pref_list = NULL;
|
||||
|
||||
return cipherstack;
|
||||
+
|
||||
+err:
|
||||
+ if (co_list)
|
||||
+ OPENSSL_free(co_list);
|
||||
+ if (in_group_flags)
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ if (cipherstack)
|
||||
+ sk_SSL_CIPHER_free(cipherstack);
|
||||
+ if (pref_list && pref_list->in_group_flags)
|
||||
+ OPENSSL_free(pref_list->in_group_flags);
|
||||
+ if (pref_list)
|
||||
+ OPENSSL_free(pref_list);
|
||||
+ return NULL;
|
||||
+
|
||||
}
|
||||
|
||||
char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
diff --git a/ssl/ssl_err.c b/ssl/ssl_err.c
|
||||
index 85d9dd8448..64f7577a90 100644
|
||||
--- a/ssl/ssl_err.c
|
||||
+++ b/ssl/ssl_err.c
|
||||
@@ -14,6 +14,8 @@
|
||||
#ifndef OPENSSL_NO_ERR
|
||||
|
||||
static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ALGORITHM_FETCH_FAILED),
|
||||
+ "algorithm fetch failed"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY),
|
||||
"application data after close notify"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_APP_DATA_IN_HANDSHAKE),
|
||||
@@ -171,8 +173,6 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"ext length mismatch"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_FAILED_TO_INIT_ASYNC),
|
||||
"failed to init async"},
|
||||
- {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ALGORITHM_FETCH_FAILED),
|
||||
- "algorithm fetch failed"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_FRAGMENTED_CLIENT_HELLO),
|
||||
"fragmented client hello"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_GOT_A_FIN_BEFORE_A_CCS),
|
||||
@@ -257,6 +257,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"missing tmp ecdh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS),
|
||||
+ "mixed special operator with groups"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NESTED_GROUP), "nested group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_ON_RECORD_BOUNDARY),
|
||||
"not on record boundary"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_REPLACING_CERTIFICATE),
|
||||
@@ -493,7 +496,11 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unexpected end of early data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_EOF_WHILE_READING),
|
||||
"unexpected eof while reading"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE),
|
||||
+ "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_MESSAGE), "unexpected message"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP),
|
||||
+ "unexpected operator in group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_RECORD), "unexpected record"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNINITIALIZED), "uninitialized"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNKNOWN_ALERT_TYPE), "unknown alert type"},
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index b5239d6eb2..fcd5547f48 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -1127,6 +1127,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
return X509_VERIFY_PARAM_set1(ssl->param, vpm);
|
||||
}
|
||||
|
||||
+void ssl_cipher_preference_list_free(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ sk_SSL_CIPHER_free(cipher_list->ciphers);
|
||||
+ OPENSSL_free(cipher_list->in_group_flags);
|
||||
+ OPENSSL_free(cipher_list);
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_dup(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(cipher_list->ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(cipher_list->ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(ret->in_group_flags, cipher_list->in_group_flags, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_from_ciphers(STACK_OF(SSL_CIPHER) *ciphers)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memset(ret->in_group_flags, 0, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx)
|
||||
{
|
||||
return ctx->param;
|
||||
@@ -1171,7 +1236,8 @@ void SSL_free(SSL *s)
|
||||
BUF_MEM_free(s->init_buf);
|
||||
|
||||
/* add extra stuff */
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(s->tls13_ciphersuites);
|
||||
sk_SSL_CIPHER_free(s->peer_ciphers);
|
||||
@@ -2566,9 +2632,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
{
|
||||
if (s != NULL) {
|
||||
if (s->cipher_list != NULL) {
|
||||
- return s->cipher_list;
|
||||
+ return (s->cipher_list->ciphers);
|
||||
} else if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL)) {
|
||||
- return s->ctx->cipher_list;
|
||||
+ return (s->ctx->cipher_list->ciphers);
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
@@ -2642,8 +2708,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
* preference */
|
||||
STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx)
|
||||
{
|
||||
- if (ctx != NULL)
|
||||
- return ctx->cipher_list;
|
||||
+ if (ctx != NULL && ctx->cipher_list != NULL)
|
||||
+ return ctx->cipher_list->ciphers;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -3153,7 +3219,7 @@ SSL_CTX *SSL_CTX_new_with_libctx(OPENSSL_CTX *libctx, const char *propq,
|
||||
ret->tls13_ciphersuites,
|
||||
&ret->cipher_list, &ret->cipher_list_by_id,
|
||||
OSSL_default_cipher_list(), ret->cert)
|
||||
- || sk_SSL_CIPHER_num(ret->cipher_list) <= 0) {
|
||||
+ || sk_SSL_CIPHER_num(ret->cipher_list->ciphers) <= 0) {
|
||||
SSLerr(0, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
goto err2;
|
||||
}
|
||||
@@ -3334,7 +3400,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
#ifndef OPENSSL_NO_CT
|
||||
CTLOG_STORE_free(a->ctlog_store);
|
||||
#endif
|
||||
- sk_SSL_CIPHER_free(a->cipher_list);
|
||||
+ ssl_cipher_preference_list_free(a->cipher_list);
|
||||
sk_SSL_CIPHER_free(a->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(a->tls13_ciphersuites);
|
||||
ssl_cert_free(a->cert);
|
||||
@@ -4012,13 +4078,15 @@ SSL *SSL_dup(SSL *s)
|
||||
|
||||
/* dup the cipher_list and cipher_list_by_id stacks */
|
||||
if (s->cipher_list != NULL) {
|
||||
- if ((ret->cipher_list = sk_SSL_CIPHER_dup(s->cipher_list)) == NULL)
|
||||
+ ret->cipher_list = ssl_cipher_preference_list_dup(s->cipher_list);
|
||||
+ if (ret->cipher_list == NULL)
|
||||
goto err;
|
||||
}
|
||||
- if (s->cipher_list_by_id != NULL)
|
||||
- if ((ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id))
|
||||
- == NULL)
|
||||
+ if (s->cipher_list_by_id != NULL) {
|
||||
+ ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id);
|
||||
+ if (ret->cipher_list_by_id == NULL)
|
||||
goto err;
|
||||
+ }
|
||||
|
||||
/* Dup the client_CA list */
|
||||
if (!dup_ca_names(&ret->ca_names, s->ca_names)
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index f0f0a53ecf..56eed2c1c1 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -763,11 +763,48 @@ int ssl_hmac_final(SSL_HMAC *ctx, unsigned char *md, size_t *len,
|
||||
size_t max_size);
|
||||
size_t ssl_hmac_size(const SSL_HMAC *ctx);
|
||||
|
||||
+/* ssl_cipher_preference_list_st contains a list of SSL_CIPHERs with
|
||||
+ * equal-preference groups. For TLS clients, the groups are moot because the
|
||||
+ * server picks the cipher and groups cannot be expressed on the wire. However,
|
||||
+ * for servers, the equal-preference groups allow the client's preferences to
|
||||
+ * be partially respected. (This only has an effect with
|
||||
+ * SSL_OP_CIPHER_SERVER_PREFERENCE).
|
||||
+ *
|
||||
+ * The equal-preference groups are expressed by grouping SSL_CIPHERs together.
|
||||
+ * All elements of a group have the same priority: no ordering is expressed
|
||||
+ * within a group.
|
||||
+ *
|
||||
+ * The values in |ciphers| are in one-to-one correspondence with
|
||||
+ * |in_group_flags|. (That is, sk_SSL_CIPHER_num(ciphers) is the number of
|
||||
+ * bytes in |in_group_flags|.) The bytes in |in_group_flags| are either 1, to
|
||||
+ * indicate that the corresponding SSL_CIPHER is not the last element of a
|
||||
+ * group, or 0 to indicate that it is.
|
||||
+ *
|
||||
+ * For example, if |in_group_flags| contains all zeros then that indicates a
|
||||
+ * traditional, fully-ordered preference. Every SSL_CIPHER is the last element
|
||||
+ * of the group (i.e. they are all in a one-element group).
|
||||
+ *
|
||||
+ * For a more complex example, consider:
|
||||
+ * ciphers: A B C D E F
|
||||
+ * in_group_flags: 1 1 0 0 1 0
|
||||
+ *
|
||||
+ * That would express the following, order:
|
||||
+ *
|
||||
+ * A E
|
||||
+ * B -> D -> F
|
||||
+ * C
|
||||
+ */
|
||||
+struct ssl_cipher_preference_list_st {
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers;
|
||||
+ uint8_t *in_group_flags;
|
||||
+};
|
||||
+
|
||||
+
|
||||
struct ssl_ctx_st {
|
||||
OPENSSL_CTX *libctx;
|
||||
|
||||
const SSL_METHOD *method;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
/* same as above but sorted for lookup */
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
@@ -1350,7 +1387,7 @@ struct ssl_st {
|
||||
SSL_DANE dane;
|
||||
/* crypto */
|
||||
STACK_OF(SSL_CIPHER) *peer_ciphers;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites;
|
||||
@@ -2323,7 +2360,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
const SSL_CIPHER *const *bp);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c);
|
||||
@@ -2333,6 +2370,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_dup(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+void ssl_cipher_preference_list_free(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_from_ciphers(
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers);
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s);
|
||||
__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
const EVP_MD **md, int *mac_pkey_type,
|
||||
size_t *mac_secret_size, SSL_COMP **comp,
|
||||
@@ -2418,7 +2462,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
CERT_PKEY *cpk);
|
||||
__owur const SSL_CIPHER *ssl3_choose_cipher(SSL *ssl,
|
||||
STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr);
|
||||
+ struct ssl_cipher_preference_list_st *srvr);
|
||||
__owur int ssl3_digest_cached_records(SSL *s, int keep);
|
||||
__owur int ssl3_new(SSL *s);
|
||||
void ssl3_free(SSL *s);
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index a23187290e..6348f1f9b6 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -1774,7 +1774,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* For TLSv1.3 we must select the ciphersuite *before* session resumption */
|
||||
if (SSL_IS_TLS13(s)) {
|
||||
const SSL_CIPHER *cipher =
|
||||
- ssl3_choose_cipher(s, ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1957,7 +1957,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* check if some cipher was preferred by call back */
|
||||
if (pref_cipher == NULL)
|
||||
pref_cipher = ssl3_choose_cipher(s, s->peer_ciphers,
|
||||
- SSL_get_ciphers(s));
|
||||
+ ssl_get_cipher_preferences(s));
|
||||
if (pref_cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_F_TLS_EARLY_POST_PROCESS_CLIENT_HELLO,
|
||||
@@ -1966,8 +1966,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
}
|
||||
|
||||
s->session->cipher = pref_cipher;
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
+ s->cipher_list = ssl_cipher_preference_list_from_ciphers(
|
||||
+ s->peer_ciphers);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
}
|
||||
@@ -2279,7 +2280,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
/* In TLSv1.3 we selected the ciphersuite before resumption */
|
||||
if (!SSL_IS_TLS13(s)) {
|
||||
cipher =
|
||||
- ssl3_choose_cipher(s, s->peer_ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->peer_ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index f81fefb9b2..7d36cf81fe 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -3340,14 +3340,14 @@ CRYPTO_new_ex_data 3409 3_0_0 EXIST::FUNCTION:
|
||||
PEM_read_PKCS8_PRIV_KEY_INFO 3410 3_0_0 EXIST::FUNCTION:STDIO
|
||||
TS_VERIFY_CTX_new 3411 3_0_0 EXIST::FUNCTION:TS
|
||||
BUF_MEM_new_ex 3412 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_add_X931 3413 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_X931 3413 3_0_0 EXIST::FUNCTION:RSA
|
||||
BN_get0_nist_prime_256 3414 3_0_0 EXIST::FUNCTION:
|
||||
CRYPTO_memcmp 3415 3_0_0 EXIST::FUNCTION:
|
||||
DH_check_pub_key 3416 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
ASN1_mbstring_copy 3417 3_0_0 EXIST::FUNCTION:
|
||||
PKCS7_set_type 3418 3_0_0 EXIST::FUNCTION:
|
||||
BIO_gets 3419 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_check_PKCS1_type_1 3420 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_check_PKCS1_type_1 3420 3_0_0 EXIST::FUNCTION:RSA
|
||||
UI_ctrl 3421 3_0_0 EXIST::FUNCTION:
|
||||
i2d_X509_REQ_fp 3422 3_0_0 EXIST::FUNCTION:STDIO
|
||||
BN_BLINDING_convert_ex 3423 3_0_0 EXIST::FUNCTION:
|
||||
@@ -4273,14 +4273,14 @@ EVP_PKEY_asn1_set_param_check 4368 3_0_0 EXIST::FUNCTION:
|
||||
DH_check_ex 4369 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
DH_check_pub_key_ex 4370 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
DH_check_params_ex 4371 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
-RSA_generate_multi_prime_key 4372 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_generate_multi_prime_key 4372 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_get_multi_prime_extra_count 4373 3_0_0 EXIST::FUNCTION:RSA
|
||||
OCSP_resp_get0_signer 4374 3_0_0 EXIST::FUNCTION:OCSP
|
||||
RSA_get0_multi_prime_crt_params 4375 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_set0_multi_prime_params 4376 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_get_version 4377 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_multi_prime_keygen 4378 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_multi_prime_keygen 4379 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_get_version 4377 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_multi_prime_keygen 4378 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_multi_prime_keygen 4379 3_0_0 EXIST::FUNCTION:RSA
|
||||
RAND_DRBG_get0_master 4380 3_0_0 EXIST::FUNCTION:
|
||||
RAND_DRBG_set_reseed_time_interval 4381 3_0_0 EXIST::FUNCTION:
|
||||
PROFESSION_INFO_get0_addProfessionInfo 4382 3_0_0 EXIST::FUNCTION:
|
||||
@@ -0,0 +1,1182 @@
|
||||
diff --git a/crypto/err/openssl.txt b/crypto/err/openssl.txt
|
||||
index f467ea909f..76cc311ba8 100644
|
||||
--- a/crypto/err/openssl.txt
|
||||
+++ b/crypto/err/openssl.txt
|
||||
@@ -3009,6 +3009,7 @@ SM2_R_INVALID_ENCODING:104:invalid encoding
|
||||
SM2_R_INVALID_FIELD:105:invalid field
|
||||
SM2_R_NO_PARAMETERS_SET:109:no parameters set
|
||||
SM2_R_USER_ID_TOO_LARGE:106:user id too large
|
||||
+SSL_R_ALGORITHM_FETCH_FAILED:295:algorithm fetch failed
|
||||
SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY:291:\
|
||||
application data after close notify
|
||||
SSL_R_APP_DATA_IN_HANDSHAKE:100:app data in handshake
|
||||
@@ -3115,7 +3116,6 @@ SSL_R_EXTENSION_NOT_RECEIVED:279:extension not received
|
||||
SSL_R_EXTRA_DATA_IN_MESSAGE:153:extra data in message
|
||||
SSL_R_EXT_LENGTH_MISMATCH:163:ext length mismatch
|
||||
SSL_R_FAILED_TO_INIT_ASYNC:405:failed to init async
|
||||
-SSL_R_ALGORITHM_FETCH_FAILED:295:algorithm fetch failed
|
||||
SSL_R_FRAGMENTED_CLIENT_HELLO:401:fragmented client hello
|
||||
SSL_R_GOT_A_FIN_BEFORE_A_CCS:154:got a fin before a ccs
|
||||
SSL_R_HTTPS_PROXY_REQUEST:155:https proxy request
|
||||
@@ -3166,6 +3166,8 @@ SSL_R_MISSING_TMP_DH_KEY:171:missing tmp dh key
|
||||
SSL_R_MISSING_TMP_ECDH_KEY:311:missing tmp ecdh key
|
||||
SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA:293:\
|
||||
mixed handshake and non handshake data
|
||||
+SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS:296:mixed special operator with groups
|
||||
+SSL_R_NESTED_GROUP:297:nested group
|
||||
SSL_R_NOT_ON_RECORD_BOUNDARY:182:not on record boundary
|
||||
SSL_R_NOT_REPLACING_CERTIFICATE:289:not replacing certificate
|
||||
SSL_R_NOT_SERVER:284:not server
|
||||
@@ -3273,7 +3275,9 @@ SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES:243:unable to load ssl3 sha1 routines
|
||||
SSL_R_UNEXPECTED_CCS_MESSAGE:262:unexpected ccs message
|
||||
SSL_R_UNEXPECTED_END_OF_EARLY_DATA:178:unexpected end of early data
|
||||
SSL_R_UNEXPECTED_EOF_WHILE_READING:294:unexpected eof while reading
|
||||
+SSL_R_UNEXPECTED_GROUP_CLOSE:299:unexpected group close
|
||||
SSL_R_UNEXPECTED_MESSAGE:244:unexpected message
|
||||
+SSL_R_UNEXPECTED_OPERATOR_IN_GROUP:305:unexpected operator in group
|
||||
SSL_R_UNEXPECTED_RECORD:245:unexpected record
|
||||
SSL_R_UNINITIALIZED:276:uninitialized
|
||||
SSL_R_UNKNOWN_ALERT_TYPE:246:unknown alert type
|
||||
diff --git a/doc/man1/openssl-ciphers.pod.in b/doc/man1/openssl-ciphers.pod.in
|
||||
index 9e5224579a..020bdcbcb9 100644
|
||||
--- a/doc/man1/openssl-ciphers.pod.in
|
||||
+++ b/doc/man1/openssl-ciphers.pod.in
|
||||
@@ -405,6 +405,21 @@ permissible.
|
||||
|
||||
=back
|
||||
|
||||
+=head1 EQUAL PREFERENCE GROUPS
|
||||
+
|
||||
+If configuring a server, one may also configure equal-preference groups to
|
||||
+partially respect the client's preferences when
|
||||
+B<SSL_OP_CIPHER_SERVER_PREFERENCE> is enabled. Ciphers in an equal-preference
|
||||
+group have equal priority and use the client order. This may be used to
|
||||
+enforce that AEADs are preferred but select AES-GCM vs. ChaCha20-Poly1305
|
||||
+based on client preferences. An equal-preference is specified with square
|
||||
+brackets, combining multiple selectors separated by |. For example:
|
||||
+
|
||||
+ [ECDHE-ECDSA-CHACHA20-POLY1305|ECDHE-ECDSA-AES128-GCM-SHA256]
|
||||
+
|
||||
+ Once an equal-preference group is used, future directives must be
|
||||
+ opcode-less.
|
||||
+
|
||||
=head1 CIPHER SUITE NAMES
|
||||
|
||||
The following lists give the SSL or TLS cipher suites names from the
|
||||
diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h
|
||||
index e1617aae45..a04a3e1552 100644
|
||||
--- a/include/openssl/sslerr.h
|
||||
+++ b/include/openssl/sslerr.h
|
||||
@@ -10,12 +10,6 @@
|
||||
|
||||
#ifndef OPENSSL_SSLERR_H
|
||||
# define OPENSSL_SSLERR_H
|
||||
-# pragma once
|
||||
-
|
||||
-# include <openssl/macros.h>
|
||||
-# ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
-# define HEADER_SSLERR_H
|
||||
-# endif
|
||||
|
||||
# include <openssl/opensslconf.h>
|
||||
# include <openssl/symhacks.h>
|
||||
@@ -462,6 +456,7 @@ int ERR_load_SSL_strings(void);
|
||||
/*
|
||||
* SSL reason codes.
|
||||
*/
|
||||
+# define SSL_R_ALGORITHM_FETCH_FAILED 295
|
||||
# define SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY 291
|
||||
# define SSL_R_APP_DATA_IN_HANDSHAKE 100
|
||||
# define SSL_R_ATTEMPT_TO_REUSE_SESSION_IN_DIFFERENT_CONTEXT 272
|
||||
@@ -561,7 +556,6 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_EXTRA_DATA_IN_MESSAGE 153
|
||||
# define SSL_R_EXT_LENGTH_MISMATCH 163
|
||||
# define SSL_R_FAILED_TO_INIT_ASYNC 405
|
||||
-# define SSL_R_ALGORITHM_FETCH_FAILED 295
|
||||
# define SSL_R_FRAGMENTED_CLIENT_HELLO 401
|
||||
# define SSL_R_GOT_A_FIN_BEFORE_A_CCS 154
|
||||
# define SSL_R_HTTPS_PROXY_REQUEST 155
|
||||
@@ -611,6 +605,8 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_MISSING_TMP_DH_KEY 171
|
||||
# define SSL_R_MISSING_TMP_ECDH_KEY 311
|
||||
# define SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA 293
|
||||
+# define SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS 296
|
||||
+# define SSL_R_NESTED_GROUP 297
|
||||
# define SSL_R_NOT_ON_RECORD_BOUNDARY 182
|
||||
# define SSL_R_NOT_REPLACING_CERTIFICATE 289
|
||||
# define SSL_R_NOT_SERVER 284
|
||||
@@ -742,7 +738,9 @@ int ERR_load_SSL_strings(void);
|
||||
# define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
# define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
# define SSL_R_UNEXPECTED_EOF_WHILE_READING 294
|
||||
+# define SSL_R_UNEXPECTED_GROUP_CLOSE 299
|
||||
# define SSL_R_UNEXPECTED_MESSAGE 244
|
||||
+# define SSL_R_UNEXPECTED_OPERATOR_IN_GROUP 305
|
||||
# define SSL_R_UNEXPECTED_RECORD 245
|
||||
# define SSL_R_UNINITIALIZED 276
|
||||
# define SSL_R_UNKNOWN_ALERT_TYPE 246
|
||||
diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c
|
||||
index 26f19108ee..5402a57524 100644
|
||||
--- a/ssl/s3_lib.c
|
||||
+++ b/ssl/s3_lib.c
|
||||
@@ -169,7 +169,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_3DES,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -234,7 +234,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES128,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -298,7 +298,7 @@ static SSL_CIPHER ssl3_ciphers[] = {
|
||||
SSL_aRSA,
|
||||
SSL_AES256,
|
||||
SSL_SHA1,
|
||||
- SSL3_VERSION, TLS1_2_VERSION,
|
||||
+ SSL3_VERSION, TLS1_VERSION,
|
||||
DTLS1_BAD_VER, DTLS1_2_VERSION,
|
||||
SSL_HIGH | SSL_FIPS,
|
||||
SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
|
||||
@@ -4142,6 +4142,17 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
return 1;
|
||||
}
|
||||
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s)
|
||||
+{
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ return (s->cipher_list);
|
||||
+
|
||||
+ if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL))
|
||||
+ return (s->ctx->cipher_list);
|
||||
+
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
/*
|
||||
* ssl3_choose_cipher - choose a cipher from those offered by the client
|
||||
* @s: SSL connection
|
||||
@@ -4151,16 +4162,24 @@ int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len)
|
||||
* Returns the selected cipher or NULL when no common ciphers.
|
||||
*/
|
||||
const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr)
|
||||
+ struct ssl_cipher_preference_list_st
|
||||
+ *server_pref)
|
||||
{
|
||||
const SSL_CIPHER *c, *ret = NULL;
|
||||
- STACK_OF(SSL_CIPHER) *prio, *allow;
|
||||
- int i, ii, ok, prefer_sha256 = 0;
|
||||
+ STACK_OF(SSL_CIPHER) *srvr = server_pref->ciphers, *prio, *allow;
|
||||
+ int i, ii, ok, prefer_sha256 = 0, safari_ec = 0;
|
||||
unsigned long alg_k = 0, alg_a = 0, mask_k = 0, mask_a = 0;
|
||||
const EVP_MD *mdsha256 = EVP_sha256();
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- STACK_OF(SSL_CIPHER) *prio_chacha = NULL;
|
||||
-#endif
|
||||
+
|
||||
+ /* in_group_flags will either be NULL, or will point to an array of
|
||||
+ * bytes which indicate equal-preference groups in the |prio| stack.
|
||||
+ * See the comment about |in_group_flags| in the
|
||||
+ * |ssl_cipher_preference_list_st| struct. */
|
||||
+ const uint8_t *in_group_flags;
|
||||
+
|
||||
+ /* group_min contains the minimal index so far found in a group, or -1
|
||||
+ * if no such value exists yet. */
|
||||
+ int group_min = -1;
|
||||
|
||||
/* Let's see which ciphers we can support */
|
||||
|
||||
@@ -4187,54 +4206,13 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
} OSSL_TRACE_END(TLS_CIPHER);
|
||||
|
||||
/* SUITE-B takes precedence over server preference and ChaCha priortiy */
|
||||
- if (tls1_suiteb(s)) {
|
||||
+ if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE || tls1_suiteb(s)) {
|
||||
prio = srvr;
|
||||
+ in_group_flags = server_pref->in_group_flags;
|
||||
allow = clnt;
|
||||
- } else if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE) {
|
||||
- prio = srvr;
|
||||
- allow = clnt;
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- /* If ChaCha20 is at the top of the client preference list,
|
||||
- and there are ChaCha20 ciphers in the server list, then
|
||||
- temporarily prioritize all ChaCha20 ciphers in the servers list. */
|
||||
- if (s->options & SSL_OP_PRIORITIZE_CHACHA && sk_SSL_CIPHER_num(clnt) > 0) {
|
||||
- c = sk_SSL_CIPHER_value(clnt, 0);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- /* ChaCha20 is client preferred, check server... */
|
||||
- int num = sk_SSL_CIPHER_num(srvr);
|
||||
- int found = 0;
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305) {
|
||||
- found = 1;
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
- if (found) {
|
||||
- prio_chacha = sk_SSL_CIPHER_new_reserve(NULL, num);
|
||||
- /* if reserve fails, then there's likely a memory issue */
|
||||
- if (prio_chacha != NULL) {
|
||||
- /* Put all ChaCha20 at the top, starting with the one we just found */
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- for (i++; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc == SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- /* Pull in the rest */
|
||||
- for (i = 0; i < num; i++) {
|
||||
- c = sk_SSL_CIPHER_value(srvr, i);
|
||||
- if (c->algorithm_enc != SSL_CHACHA20POLY1305)
|
||||
- sk_SSL_CIPHER_push(prio_chacha, c);
|
||||
- }
|
||||
- prio = prio_chacha;
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
- }
|
||||
-# endif
|
||||
} else {
|
||||
prio = clnt;
|
||||
+ in_group_flags = NULL;
|
||||
allow = srvr;
|
||||
}
|
||||
|
||||
@@ -4265,14 +4243,16 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
|
||||
c = sk_SSL_CIPHER_value(prio, i);
|
||||
|
||||
+ ok = 1;
|
||||
+
|
||||
/* Skip ciphers not supported by the protocol version */
|
||||
if (!SSL_IS_DTLS(s) &&
|
||||
((s->version < c->min_tls) || (s->version > c->max_tls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
if (SSL_IS_DTLS(s) &&
|
||||
(DTLS_VERSION_LT(s->version, c->min_dtls) ||
|
||||
DTLS_VERSION_GT(s->version, c->max_dtls)))
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
|
||||
/*
|
||||
* Since TLS 1.3 ciphersuites can be used with any auth or
|
||||
@@ -4294,10 +4274,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
/* with PSK there must be server callback set */
|
||||
if ((alg_k & SSL_PSK) && s->psk_server_callback == NULL)
|
||||
- continue;
|
||||
+ ok = 0;
|
||||
#endif /* OPENSSL_NO_PSK */
|
||||
|
||||
- ok = (alg_k & mask_k) && (alg_a & mask_a);
|
||||
+ ok = ok && (alg_k & mask_k) && (alg_a & mask_a);
|
||||
OSSL_TRACE7(TLS_CIPHER,
|
||||
"%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n",
|
||||
ok, alg_k, alg_a, mask_k, mask_a, (void *)c, c->name);
|
||||
@@ -4313,6 +4293,14 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
|
||||
if (!ok)
|
||||
continue;
|
||||
+
|
||||
+ safari_ec = 0;
|
||||
+#if !defined(OPENSSL_NO_EC)
|
||||
+ if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)) {
|
||||
+ if (s->s3.is_probably_safari)
|
||||
+ safari_ec = 1;
|
||||
+ }
|
||||
+#endif
|
||||
}
|
||||
ii = sk_SSL_CIPHER_find(allow, c);
|
||||
if (ii >= 0) {
|
||||
@@ -4320,14 +4308,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
if (!ssl_security(s, SSL_SECOP_CIPHER_SHARED,
|
||||
c->strength_bits, 0, (void *)c))
|
||||
continue;
|
||||
-#if !defined(OPENSSL_NO_EC)
|
||||
- if ((alg_k & SSL_kECDHE) && (alg_a & SSL_aECDSA)
|
||||
- && s->s3.is_probably_safari) {
|
||||
- if (!ret)
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
- continue;
|
||||
- }
|
||||
-#endif
|
||||
+
|
||||
if (prefer_sha256) {
|
||||
const SSL_CIPHER *tmp = sk_SSL_CIPHER_value(allow, ii);
|
||||
|
||||
@@ -4339,13 +4320,38 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
|
||||
ret = tmp;
|
||||
continue;
|
||||
}
|
||||
- ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+
|
||||
+ if (in_group_flags != NULL && in_group_flags[i] == 1) {
|
||||
+ /* This element of |prio| is in a group. Update
|
||||
+ * the minimum index found so far and continue
|
||||
+ * looking. */
|
||||
+ if (group_min == -1 || group_min > ii)
|
||||
+ group_min = ii;
|
||||
+ } else {
|
||||
+ if (group_min != -1 && group_min < ii)
|
||||
+ ii = group_min;
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, ii);
|
||||
+ break;
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ if (in_group_flags != NULL && !in_group_flags[i] && group_min != -1) {
|
||||
+ /* We are about to leave a group, but we found a match
|
||||
+ * in it, so that's our answer. */
|
||||
+ if (safari_ec) {
|
||||
+ if (!ret)
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
+ continue;
|
||||
+ }
|
||||
+ ret = sk_SSL_CIPHER_value(allow, group_min);
|
||||
break;
|
||||
}
|
||||
}
|
||||
-#ifndef OPENSSL_NO_CHACHA
|
||||
- sk_SSL_CIPHER_free(prio_chacha);
|
||||
-#endif
|
||||
return ret;
|
||||
}
|
||||
|
||||
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
|
||||
index 04ffae325c..b67369f639 100644
|
||||
--- a/ssl/ssl_ciph.c
|
||||
+++ b/ssl/ssl_ciph.c
|
||||
@@ -193,6 +193,7 @@ typedef struct cipher_order_st {
|
||||
const SSL_CIPHER *cipher;
|
||||
int active;
|
||||
int dead;
|
||||
+ int in_group;
|
||||
struct cipher_order_st *next, *prev;
|
||||
} CIPHER_ORDER;
|
||||
|
||||
@@ -298,6 +299,7 @@ static const SSL_CIPHER cipher_aliases[] = {
|
||||
{0, SSL_TXT_TLSV1, NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, "TLSv1.0", NULL, 0, 0, 0, 0, 0, TLS1_VERSION},
|
||||
{0, SSL_TXT_TLSV1_2, NULL, 0, 0, 0, 0, 0, TLS1_2_VERSION},
|
||||
+ {0, "TLS13", NULL, 0, 0, 0, 0, 0, TLS1_3_VERSION},
|
||||
|
||||
/* strength classes */
|
||||
{0, SSL_TXT_LOW, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_LOW},
|
||||
@@ -681,6 +683,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method,
|
||||
co_list[co_list_num].next = NULL;
|
||||
co_list[co_list_num].prev = NULL;
|
||||
co_list[co_list_num].active = 0;
|
||||
+ co_list[co_list_num].in_group = 0;
|
||||
co_list_num++;
|
||||
}
|
||||
|
||||
@@ -774,8 +777,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
uint32_t alg_auth, uint32_t alg_enc,
|
||||
uint32_t alg_mac, int min_tls,
|
||||
uint32_t algo_strength, int rule,
|
||||
- int32_t strength_bits, CIPHER_ORDER **head_p,
|
||||
- CIPHER_ORDER **tail_p)
|
||||
+ int32_t strength_bits, int in_group,
|
||||
+ CIPHER_ORDER **head_p, CIPHER_ORDER **tail_p)
|
||||
{
|
||||
CIPHER_ORDER *head, *tail, *curr, *next, *last;
|
||||
const SSL_CIPHER *cp;
|
||||
@@ -783,9 +786,9 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
|
||||
OSSL_TRACE_BEGIN(TLS_CIPHER){
|
||||
BIO_printf(trc_out,
|
||||
- "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d)\n",
|
||||
+ "Applying rule %d with %08x/%08x/%08x/%08x/%08x %08x (%d) g:%d\n",
|
||||
rule, alg_mkey, alg_auth, alg_enc, alg_mac, min_tls,
|
||||
- algo_strength, strength_bits);
|
||||
+ algo_strength, strength_bits, in_group);
|
||||
}
|
||||
|
||||
if (rule == CIPHER_DEL || rule == CIPHER_BUMP)
|
||||
@@ -862,6 +865,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
if (!curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
curr->active = 1;
|
||||
+ curr->in_group = in_group;
|
||||
}
|
||||
}
|
||||
/* Move the added cipher to this location */
|
||||
@@ -869,6 +873,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
/* reverse == 0 */
|
||||
if (curr->active) {
|
||||
ll_append_tail(&head, curr, &tail);
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_DEL) {
|
||||
/* reverse == 1 */
|
||||
@@ -880,6 +885,7 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
||||
*/
|
||||
ll_append_head(&head, curr, &tail);
|
||||
curr->active = 0;
|
||||
+ curr->in_group = 0;
|
||||
}
|
||||
} else if (rule == CIPHER_BUMP) {
|
||||
if (curr->active)
|
||||
@@ -949,8 +955,8 @@ static int ssl_cipher_strength_sort(CIPHER_ORDER **head_p,
|
||||
*/
|
||||
for (i = max_strength_bits; i >= 0; i--)
|
||||
if (number_uses[i] > 0)
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, head_p,
|
||||
- tail_p);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ORD, i, 0,
|
||||
+ head_p, tail_p);
|
||||
|
||||
OPENSSL_free(number_uses);
|
||||
return 1;
|
||||
@@ -964,7 +970,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
uint32_t alg_mkey, alg_auth, alg_enc, alg_mac, algo_strength;
|
||||
int min_tls;
|
||||
const char *l, *buf;
|
||||
- int j, multi, found, rule, retval, ok, buflen;
|
||||
+ int j, multi, found, rule, retval, ok, buflen, in_group = 0, has_group = 0;
|
||||
uint32_t cipher_id = 0;
|
||||
char ch;
|
||||
|
||||
@@ -975,18 +981,66 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
|
||||
if (ch == '\0')
|
||||
break; /* done */
|
||||
- if (ch == '-') {
|
||||
+ if (in_group) {
|
||||
+ if (ch == ']') {
|
||||
+ if (!in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_GROUP_CLOSE);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ if (*tail_p)
|
||||
+ (*tail_p)->in_group = 0;
|
||||
+ in_group = 0;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ }
|
||||
+ if (ch == '|') {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ l++;
|
||||
+ continue;
|
||||
+ } else if (!(ch >= 'a' && ch <= 'z')
|
||||
+ && !(ch >= 'A' && ch <= 'Z')
|
||||
+ && !(ch >= '0' && ch <= '9')) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_UNEXPECTED_OPERATOR_IN_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ } else {
|
||||
+ rule = CIPHER_ADD;
|
||||
+ }
|
||||
+ } else if (ch == '-') {
|
||||
rule = CIPHER_DEL;
|
||||
l++;
|
||||
} else if (ch == '+') {
|
||||
rule = CIPHER_ORD;
|
||||
l++;
|
||||
+ } else if (ch == '!' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '!') {
|
||||
rule = CIPHER_KILL;
|
||||
l++;
|
||||
+ } else if (ch == '@' && has_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR,
|
||||
+ SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
} else if (ch == '@') {
|
||||
rule = CIPHER_SPECIAL;
|
||||
l++;
|
||||
+ } else if (ch == '[') {
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_NESTED_GROUP);
|
||||
+ retval = found = in_group = 0;
|
||||
+ break;
|
||||
+ }
|
||||
+ in_group = 1;
|
||||
+ has_group = 1;
|
||||
+ l++;
|
||||
+ continue;
|
||||
} else {
|
||||
rule = CIPHER_ADD;
|
||||
}
|
||||
@@ -1011,7 +1065,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
while (((ch >= 'A') && (ch <= 'Z')) ||
|
||||
((ch >= '0') && (ch <= '9')) ||
|
||||
((ch >= 'a') && (ch <= 'z')) ||
|
||||
- (ch == '-') || (ch == '.') || (ch == '='))
|
||||
+ (ch == '-') || (ch == '.') || (ch == '=') || (ch == '_'))
|
||||
#else
|
||||
while (isalnum((unsigned char)ch) || (ch == '-') || (ch == '.')
|
||||
|| (ch == '='))
|
||||
@@ -1028,7 +1082,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
* alphanumeric, so we call this an error.
|
||||
*/
|
||||
SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
- retval = found = 0;
|
||||
+ retval = found = in_group = 0;
|
||||
l++;
|
||||
break;
|
||||
}
|
||||
@@ -1207,8 +1261,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
} else if (found) {
|
||||
ssl_cipher_apply_rule(cipher_id,
|
||||
alg_mkey, alg_auth, alg_enc, alg_mac,
|
||||
- min_tls, algo_strength, rule, -1, head_p,
|
||||
- tail_p);
|
||||
+ min_tls, algo_strength, rule, -1, in_group,
|
||||
+ head_p, tail_p);
|
||||
} else {
|
||||
while ((*l != '\0') && !ITEM_SEP(*l))
|
||||
l++;
|
||||
@@ -1217,6 +1271,11 @@ static int ssl_cipher_process_rulestr(const char *rule_str,
|
||||
break; /* done */
|
||||
}
|
||||
|
||||
+ if (in_group) {
|
||||
+ SSLerr(SSL_F_SSL_CIPHER_PROCESS_RULESTR, SSL_R_INVALID_COMMAND);
|
||||
+ retval = 0;
|
||||
+ }
|
||||
+
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -1380,7 +1439,7 @@ int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str)
|
||||
int ret = set_ciphersuites(&(ctx->tls13_ciphersuites), str);
|
||||
|
||||
if (ret && ctx->cipher_list != NULL)
|
||||
- return update_cipher_list(&ctx->cipher_list, &ctx->cipher_list_by_id,
|
||||
+ return update_cipher_list(&ctx->cipher_list->ciphers, &ctx->cipher_list_by_id,
|
||||
ctx->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1393,10 +1452,10 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
if (s->cipher_list == NULL) {
|
||||
if ((cipher_list = SSL_get_ciphers(s)) != NULL)
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(cipher_list);
|
||||
+ s->cipher_list->ciphers = sk_SSL_CIPHER_dup(cipher_list);
|
||||
}
|
||||
if (ret && s->cipher_list != NULL)
|
||||
- return update_cipher_list(&s->cipher_list, &s->cipher_list_by_id,
|
||||
+ return update_cipher_list(&s->cipher_list->ciphers, &s->cipher_list_by_id,
|
||||
s->tls13_ciphersuites);
|
||||
|
||||
return ret;
|
||||
@@ -1404,17 +1463,20 @@ int SSL_set_ciphersuites(SSL *s, const char *str)
|
||||
|
||||
STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c)
|
||||
{
|
||||
- int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases, i;
|
||||
+ int ok, num_of_ciphers, num_of_alias_max, num_of_group_aliases;
|
||||
uint32_t disabled_mkey, disabled_auth, disabled_enc, disabled_mac;
|
||||
- STACK_OF(SSL_CIPHER) *cipherstack;
|
||||
+ STACK_OF(SSL_CIPHER) *cipherstack = NULL;
|
||||
const char *rule_p;
|
||||
CIPHER_ORDER *co_list = NULL, *head = NULL, *tail = NULL, *curr;
|
||||
const SSL_CIPHER **ca_list = NULL;
|
||||
+ uint8_t *in_group_flags = NULL;
|
||||
+ unsigned int num_in_group_flags = 0;
|
||||
+ struct ssl_cipher_preference_list_st *pref_list = NULL;
|
||||
|
||||
/*
|
||||
* Return with error if nothing to do.
|
||||
@@ -1463,16 +1525,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* preference).
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, SSL_kECDHE, SSL_aECDSA, 0, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head,
|
||||
- &tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head,
|
||||
- &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
+ &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, SSL_kECDHE, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Within each strength group, we prefer GCM over CHACHA... */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_AESGCM, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_CHACHA20, 0, 0, 0, CIPHER_ADD, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1481,13 +1543,13 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* strength.
|
||||
*/
|
||||
ssl_cipher_apply_rule(0, 0, 0, SSL_AES ^ SSL_AESGCM, 0, 0, 0, CIPHER_ADD,
|
||||
- -1, &head, &tail);
|
||||
+ -1, 0, &head, &tail);
|
||||
|
||||
/* Temporarily enable everything else for sorting */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_ADD, -1, 0, &head, &tail);
|
||||
|
||||
/* Low priority for MD5 */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_MD5, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1495,16 +1557,16 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* disabled. (For applications that allow them, they aren't too bad, but
|
||||
* we prefer authenticated ciphers.)
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, SSL_aNULL, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
- ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kRSA, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
- ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, SSL_kPSK, 0, 0, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/* RC4 is sort-of broken -- move to the end */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, &head,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, SSL_RC4, 0, 0, 0, CIPHER_ORD, -1, 0, &head,
|
||||
&tail);
|
||||
|
||||
/*
|
||||
@@ -1520,7 +1582,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Partially overrule strength sort to prefer TLS 1.2 ciphers/PRFs.
|
||||
* TODO(openssl-team): is there an easier way to accomplish all this?
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_2_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
|
||||
/*
|
||||
@@ -1536,15 +1598,18 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
* Because we now bump ciphers to the top of the list, we proceed in
|
||||
* reverse order of preference.
|
||||
*/
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1,
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, SSL_AEAD, 0, 0, CIPHER_BUMP, -1, 0,
|
||||
&head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, 0, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
ssl_cipher_apply_rule(0, SSL_kDHE | SSL_kECDHE, 0, 0, SSL_AEAD, 0, 0,
|
||||
- CIPHER_BUMP, -1, &head, &tail);
|
||||
+ CIPHER_BUMP, -1, 0, &head, &tail);
|
||||
+
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, TLS1_3_VERSION, 0, CIPHER_BUMP, -1, 0,
|
||||
+ &head, &tail);
|
||||
|
||||
/* Now disable everything (maintaining the ordering!) */
|
||||
- ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, &head, &tail);
|
||||
+ ssl_cipher_apply_rule(0, 0, 0, 0, 0, 0, 0, CIPHER_DEL, -1, 0, &head, &tail);
|
||||
|
||||
/*
|
||||
* We also need cipher aliases for selecting based on the rule_str.
|
||||
@@ -1558,9 +1623,8 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
num_of_alias_max = num_of_ciphers + num_of_group_aliases + 1;
|
||||
ca_list = OPENSSL_malloc(sizeof(*ca_list) * num_of_alias_max);
|
||||
if (ca_list == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
SSLerr(SSL_F_SSL_CREATE_CIPHER_LIST, ERR_R_MALLOC_FAILURE);
|
||||
- return NULL; /* Failure */
|
||||
+ goto err; /* Failure */
|
||||
}
|
||||
ssl_cipher_collect_aliases(ca_list, num_of_group_aliases,
|
||||
disabled_mkey, disabled_auth, disabled_enc,
|
||||
@@ -1585,28 +1649,19 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
|
||||
OPENSSL_free(ca_list); /* Not needed anymore */
|
||||
|
||||
- if (!ok) { /* Rule processing failure */
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if (!ok)
|
||||
+ goto err; /* Rule processing failure */
|
||||
|
||||
/*
|
||||
* Allocate new "cipherstack" for the result, return with error
|
||||
* if we cannot get one.
|
||||
*/
|
||||
- if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL) {
|
||||
- OPENSSL_free(co_list);
|
||||
- return NULL;
|
||||
- }
|
||||
+ if ((cipherstack = sk_SSL_CIPHER_new_null()) == NULL)
|
||||
+ goto err;
|
||||
|
||||
- /* Add TLSv1.3 ciphers first - we always prefer those if possible */
|
||||
- for (i = 0; i < sk_SSL_CIPHER_num(tls13_ciphersuites); i++) {
|
||||
- if (!sk_SSL_CIPHER_push(cipherstack,
|
||||
- sk_SSL_CIPHER_value(tls13_ciphersuites, i))) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- }
|
||||
+ in_group_flags = OPENSSL_malloc(num_of_ciphers);
|
||||
+ if (!in_group_flags)
|
||||
+ goto err;
|
||||
|
||||
OSSL_TRACE_BEGIN(TLS_CIPHER) {
|
||||
BIO_printf(trc_out, "cipher selection:\n");
|
||||
@@ -1618,26 +1673,51 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
for (curr = head; curr != NULL; curr = curr->next) {
|
||||
if (curr->active) {
|
||||
if (!sk_SSL_CIPHER_push(cipherstack, curr->cipher)) {
|
||||
- OPENSSL_free(co_list);
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
OSSL_TRACE_CANCEL(TLS_CIPHER);
|
||||
- return NULL;
|
||||
+ goto err;
|
||||
}
|
||||
+ in_group_flags[num_in_group_flags++] = curr->in_group;
|
||||
if (trc_out != NULL)
|
||||
BIO_printf(trc_out, "<%s>\n", curr->cipher->name);
|
||||
}
|
||||
}
|
||||
OPENSSL_free(co_list); /* Not needed any longer */
|
||||
+ co_list = NULL;
|
||||
OSSL_TRACE_END(TLS_CIPHER);
|
||||
|
||||
- if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack)) {
|
||||
- sk_SSL_CIPHER_free(cipherstack);
|
||||
- return NULL;
|
||||
- }
|
||||
- sk_SSL_CIPHER_free(*cipher_list);
|
||||
- *cipher_list = cipherstack;
|
||||
+ if (!update_cipher_list_by_id(cipher_list_by_id, cipherstack))
|
||||
+ goto err;
|
||||
+
|
||||
+ pref_list = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!pref_list)
|
||||
+ goto err;
|
||||
+ pref_list->ciphers = cipherstack;
|
||||
+ pref_list->in_group_flags = OPENSSL_malloc(num_in_group_flags);
|
||||
+ if (!pref_list->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(pref_list->in_group_flags, in_group_flags, num_in_group_flags);
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ in_group_flags = NULL;
|
||||
+ if (*cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(*cipher_list);
|
||||
+ *cipher_list = pref_list;
|
||||
+ pref_list = NULL;
|
||||
|
||||
return cipherstack;
|
||||
+
|
||||
+err:
|
||||
+ if (co_list)
|
||||
+ OPENSSL_free(co_list);
|
||||
+ if (in_group_flags)
|
||||
+ OPENSSL_free(in_group_flags);
|
||||
+ if (cipherstack)
|
||||
+ sk_SSL_CIPHER_free(cipherstack);
|
||||
+ if (pref_list && pref_list->in_group_flags)
|
||||
+ OPENSSL_free(pref_list->in_group_flags);
|
||||
+ if (pref_list)
|
||||
+ OPENSSL_free(pref_list);
|
||||
+ return NULL;
|
||||
+
|
||||
}
|
||||
|
||||
char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len)
|
||||
diff --git a/ssl/ssl_err.c b/ssl/ssl_err.c
|
||||
index 85d9dd8448..64f7577a90 100644
|
||||
--- a/ssl/ssl_err.c
|
||||
+++ b/ssl/ssl_err.c
|
||||
@@ -14,6 +14,8 @@
|
||||
#ifndef OPENSSL_NO_ERR
|
||||
|
||||
static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ALGORITHM_FETCH_FAILED),
|
||||
+ "algorithm fetch failed"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_APPLICATION_DATA_AFTER_CLOSE_NOTIFY),
|
||||
"application data after close notify"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_APP_DATA_IN_HANDSHAKE),
|
||||
@@ -171,8 +173,6 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"ext length mismatch"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_FAILED_TO_INIT_ASYNC),
|
||||
"failed to init async"},
|
||||
- {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ALGORITHM_FETCH_FAILED),
|
||||
- "algorithm fetch failed"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_FRAGMENTED_CLIENT_HELLO),
|
||||
"fragmented client hello"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_GOT_A_FIN_BEFORE_A_CCS),
|
||||
@@ -257,6 +257,9 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"missing tmp ecdh key"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_HANDSHAKE_AND_NON_HANDSHAKE_DATA),
|
||||
"mixed handshake and non handshake data"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS),
|
||||
+ "mixed special operator with groups"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NESTED_GROUP), "nested group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_ON_RECORD_BOUNDARY),
|
||||
"not on record boundary"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_NOT_REPLACING_CERTIFICATE),
|
||||
@@ -493,7 +496,11 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
||||
"unexpected end of early data"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_EOF_WHILE_READING),
|
||||
"unexpected eof while reading"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_GROUP_CLOSE),
|
||||
+ "unexpected group close"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_MESSAGE), "unexpected message"},
|
||||
+ {ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_OPERATOR_IN_GROUP),
|
||||
+ "unexpected operator in group"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_RECORD), "unexpected record"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNINITIALIZED), "uninitialized"},
|
||||
{ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNKNOWN_ALERT_TYPE), "unknown alert type"},
|
||||
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
|
||||
index b5239d6eb2..fcd5547f48 100644
|
||||
--- a/ssl/ssl_lib.c
|
||||
+++ b/ssl/ssl_lib.c
|
||||
@@ -1127,6 +1127,71 @@ int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm)
|
||||
return X509_VERIFY_PARAM_set1(ssl->param, vpm);
|
||||
}
|
||||
|
||||
+void ssl_cipher_preference_list_free(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ sk_SSL_CIPHER_free(cipher_list->ciphers);
|
||||
+ OPENSSL_free(cipher_list->in_group_flags);
|
||||
+ OPENSSL_free(cipher_list);
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_dup(struct ssl_cipher_preference_list_st
|
||||
+ *cipher_list)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(cipher_list->ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(cipher_list->ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memcpy(ret->in_group_flags, cipher_list->in_group_flags, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
+struct ssl_cipher_preference_list_st*
|
||||
+ssl_cipher_preference_list_from_ciphers(STACK_OF(SSL_CIPHER) *ciphers)
|
||||
+{
|
||||
+ struct ssl_cipher_preference_list_st* ret = NULL;
|
||||
+ size_t n = sk_SSL_CIPHER_num(ciphers);
|
||||
+
|
||||
+ ret = OPENSSL_malloc(sizeof(struct ssl_cipher_preference_list_st));
|
||||
+ if (!ret)
|
||||
+ goto err;
|
||||
+ ret->ciphers = NULL;
|
||||
+ ret->in_group_flags = NULL;
|
||||
+ ret->ciphers = sk_SSL_CIPHER_dup(ciphers);
|
||||
+ if (!ret->ciphers)
|
||||
+ goto err;
|
||||
+ ret->in_group_flags = OPENSSL_malloc(n);
|
||||
+ if (!ret->in_group_flags)
|
||||
+ goto err;
|
||||
+ memset(ret->in_group_flags, 0, n);
|
||||
+ return ret;
|
||||
+
|
||||
+err:
|
||||
+ if (ret->ciphers)
|
||||
+ sk_SSL_CIPHER_free(ret->ciphers);
|
||||
+ if (ret)
|
||||
+ OPENSSL_free(ret);
|
||||
+ return NULL;
|
||||
+}
|
||||
+
|
||||
X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx)
|
||||
{
|
||||
return ctx->param;
|
||||
@@ -1171,7 +1236,8 @@ void SSL_free(SSL *s)
|
||||
BUF_MEM_free(s->init_buf);
|
||||
|
||||
/* add extra stuff */
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
+ if (s->cipher_list != NULL)
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(s->tls13_ciphersuites);
|
||||
sk_SSL_CIPHER_free(s->peer_ciphers);
|
||||
@@ -2566,9 +2632,9 @@ STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *s)
|
||||
{
|
||||
if (s != NULL) {
|
||||
if (s->cipher_list != NULL) {
|
||||
- return s->cipher_list;
|
||||
+ return (s->cipher_list->ciphers);
|
||||
} else if ((s->ctx != NULL) && (s->ctx->cipher_list != NULL)) {
|
||||
- return s->ctx->cipher_list;
|
||||
+ return (s->ctx->cipher_list->ciphers);
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
@@ -2642,8 +2708,8 @@ const char *SSL_get_cipher_list(const SSL *s, int n)
|
||||
* preference */
|
||||
STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx)
|
||||
{
|
||||
- if (ctx != NULL)
|
||||
- return ctx->cipher_list;
|
||||
+ if (ctx != NULL && ctx->cipher_list != NULL)
|
||||
+ return ctx->cipher_list->ciphers;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -3153,7 +3219,7 @@ SSL_CTX *SSL_CTX_new_with_libctx(OPENSSL_CTX *libctx, const char *propq,
|
||||
ret->tls13_ciphersuites,
|
||||
&ret->cipher_list, &ret->cipher_list_by_id,
|
||||
OSSL_default_cipher_list(), ret->cert)
|
||||
- || sk_SSL_CIPHER_num(ret->cipher_list) <= 0) {
|
||||
+ || sk_SSL_CIPHER_num(ret->cipher_list->ciphers) <= 0) {
|
||||
SSLerr(0, SSL_R_LIBRARY_HAS_NO_CIPHERS);
|
||||
goto err2;
|
||||
}
|
||||
@@ -3334,7 +3400,7 @@ void SSL_CTX_free(SSL_CTX *a)
|
||||
#ifndef OPENSSL_NO_CT
|
||||
CTLOG_STORE_free(a->ctlog_store);
|
||||
#endif
|
||||
- sk_SSL_CIPHER_free(a->cipher_list);
|
||||
+ ssl_cipher_preference_list_free(a->cipher_list);
|
||||
sk_SSL_CIPHER_free(a->cipher_list_by_id);
|
||||
sk_SSL_CIPHER_free(a->tls13_ciphersuites);
|
||||
ssl_cert_free(a->cert);
|
||||
@@ -4012,13 +4078,15 @@ SSL *SSL_dup(SSL *s)
|
||||
|
||||
/* dup the cipher_list and cipher_list_by_id stacks */
|
||||
if (s->cipher_list != NULL) {
|
||||
- if ((ret->cipher_list = sk_SSL_CIPHER_dup(s->cipher_list)) == NULL)
|
||||
+ ret->cipher_list = ssl_cipher_preference_list_dup(s->cipher_list);
|
||||
+ if (ret->cipher_list == NULL)
|
||||
goto err;
|
||||
}
|
||||
- if (s->cipher_list_by_id != NULL)
|
||||
- if ((ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id))
|
||||
- == NULL)
|
||||
+ if (s->cipher_list_by_id != NULL) {
|
||||
+ ret->cipher_list_by_id = sk_SSL_CIPHER_dup(s->cipher_list_by_id);
|
||||
+ if (ret->cipher_list_by_id == NULL)
|
||||
goto err;
|
||||
+ }
|
||||
|
||||
/* Dup the client_CA list */
|
||||
if (!dup_ca_names(&ret->ca_names, s->ca_names)
|
||||
diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h
|
||||
index f0f0a53ecf..56eed2c1c1 100644
|
||||
--- a/ssl/ssl_local.h
|
||||
+++ b/ssl/ssl_local.h
|
||||
@@ -763,11 +763,48 @@ int ssl_hmac_final(SSL_HMAC *ctx, unsigned char *md, size_t *len,
|
||||
size_t max_size);
|
||||
size_t ssl_hmac_size(const SSL_HMAC *ctx);
|
||||
|
||||
+/* ssl_cipher_preference_list_st contains a list of SSL_CIPHERs with
|
||||
+ * equal-preference groups. For TLS clients, the groups are moot because the
|
||||
+ * server picks the cipher and groups cannot be expressed on the wire. However,
|
||||
+ * for servers, the equal-preference groups allow the client's preferences to
|
||||
+ * be partially respected. (This only has an effect with
|
||||
+ * SSL_OP_CIPHER_SERVER_PREFERENCE).
|
||||
+ *
|
||||
+ * The equal-preference groups are expressed by grouping SSL_CIPHERs together.
|
||||
+ * All elements of a group have the same priority: no ordering is expressed
|
||||
+ * within a group.
|
||||
+ *
|
||||
+ * The values in |ciphers| are in one-to-one correspondence with
|
||||
+ * |in_group_flags|. (That is, sk_SSL_CIPHER_num(ciphers) is the number of
|
||||
+ * bytes in |in_group_flags|.) The bytes in |in_group_flags| are either 1, to
|
||||
+ * indicate that the corresponding SSL_CIPHER is not the last element of a
|
||||
+ * group, or 0 to indicate that it is.
|
||||
+ *
|
||||
+ * For example, if |in_group_flags| contains all zeros then that indicates a
|
||||
+ * traditional, fully-ordered preference. Every SSL_CIPHER is the last element
|
||||
+ * of the group (i.e. they are all in a one-element group).
|
||||
+ *
|
||||
+ * For a more complex example, consider:
|
||||
+ * ciphers: A B C D E F
|
||||
+ * in_group_flags: 1 1 0 0 1 0
|
||||
+ *
|
||||
+ * That would express the following, order:
|
||||
+ *
|
||||
+ * A E
|
||||
+ * B -> D -> F
|
||||
+ * C
|
||||
+ */
|
||||
+struct ssl_cipher_preference_list_st {
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers;
|
||||
+ uint8_t *in_group_flags;
|
||||
+};
|
||||
+
|
||||
+
|
||||
struct ssl_ctx_st {
|
||||
OPENSSL_CTX *libctx;
|
||||
|
||||
const SSL_METHOD *method;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
/* same as above but sorted for lookup */
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
@@ -1350,7 +1387,7 @@ struct ssl_st {
|
||||
SSL_DANE dane;
|
||||
/* crypto */
|
||||
STACK_OF(SSL_CIPHER) *peer_ciphers;
|
||||
- STACK_OF(SSL_CIPHER) *cipher_list;
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list;
|
||||
STACK_OF(SSL_CIPHER) *cipher_list_by_id;
|
||||
/* TLSv1.3 specific ciphersuites */
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites;
|
||||
@@ -2323,7 +2360,7 @@ __owur int ssl_cipher_ptr_id_cmp(const SSL_CIPHER *const *ap,
|
||||
const SSL_CIPHER *const *bp);
|
||||
__owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(const SSL_METHOD *ssl_method,
|
||||
STACK_OF(SSL_CIPHER) *tls13_ciphersuites,
|
||||
- STACK_OF(SSL_CIPHER) **cipher_list,
|
||||
+ struct ssl_cipher_preference_list_st **cipher_list,
|
||||
STACK_OF(SSL_CIPHER) **cipher_list_by_id,
|
||||
const char *rule_str,
|
||||
CERT *c);
|
||||
@@ -2333,6 +2370,13 @@ __owur int bytes_to_cipher_list(SSL *s, PACKET *cipher_suites,
|
||||
STACK_OF(SSL_CIPHER) **scsvs, int sslv2format,
|
||||
int fatal);
|
||||
void ssl_update_cache(SSL *s, int mode);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_dup(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+void ssl_cipher_preference_list_free(
|
||||
+ struct ssl_cipher_preference_list_st *cipher_list);
|
||||
+struct ssl_cipher_preference_list_st* ssl_cipher_preference_list_from_ciphers(
|
||||
+ STACK_OF(SSL_CIPHER) *ciphers);
|
||||
+struct ssl_cipher_preference_list_st* ssl_get_cipher_preferences(SSL *s);
|
||||
__owur int ssl_cipher_get_evp(const SSL_SESSION *s, const EVP_CIPHER **enc,
|
||||
const EVP_MD **md, int *mac_pkey_type,
|
||||
size_t *mac_secret_size, SSL_COMP **comp,
|
||||
@@ -2418,7 +2462,7 @@ __owur unsigned long ssl3_output_cert_chain(SSL *s, WPACKET *pkt,
|
||||
CERT_PKEY *cpk);
|
||||
__owur const SSL_CIPHER *ssl3_choose_cipher(SSL *ssl,
|
||||
STACK_OF(SSL_CIPHER) *clnt,
|
||||
- STACK_OF(SSL_CIPHER) *srvr);
|
||||
+ struct ssl_cipher_preference_list_st *srvr);
|
||||
__owur int ssl3_digest_cached_records(SSL *s, int keep);
|
||||
__owur int ssl3_new(SSL *s);
|
||||
void ssl3_free(SSL *s);
|
||||
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
|
||||
index a23187290e..6348f1f9b6 100644
|
||||
--- a/ssl/statem/statem_srvr.c
|
||||
+++ b/ssl/statem/statem_srvr.c
|
||||
@@ -1774,7 +1774,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* For TLSv1.3 we must select the ciphersuite *before* session resumption */
|
||||
if (SSL_IS_TLS13(s)) {
|
||||
const SSL_CIPHER *cipher =
|
||||
- ssl3_choose_cipher(s, ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
@@ -1957,7 +1957,7 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
/* check if some cipher was preferred by call back */
|
||||
if (pref_cipher == NULL)
|
||||
pref_cipher = ssl3_choose_cipher(s, s->peer_ciphers,
|
||||
- SSL_get_ciphers(s));
|
||||
+ ssl_get_cipher_preferences(s));
|
||||
if (pref_cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_F_TLS_EARLY_POST_PROCESS_CLIENT_HELLO,
|
||||
@@ -1966,8 +1966,9 @@ static int tls_early_post_process_client_hello(SSL *s)
|
||||
}
|
||||
|
||||
s->session->cipher = pref_cipher;
|
||||
- sk_SSL_CIPHER_free(s->cipher_list);
|
||||
- s->cipher_list = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
+ ssl_cipher_preference_list_free(s->cipher_list);
|
||||
+ s->cipher_list = ssl_cipher_preference_list_from_ciphers(
|
||||
+ s->peer_ciphers);
|
||||
sk_SSL_CIPHER_free(s->cipher_list_by_id);
|
||||
s->cipher_list_by_id = sk_SSL_CIPHER_dup(s->peer_ciphers);
|
||||
}
|
||||
@@ -2279,7 +2280,7 @@ WORK_STATE tls_post_process_client_hello(SSL *s, WORK_STATE wst)
|
||||
/* In TLSv1.3 we selected the ciphersuite before resumption */
|
||||
if (!SSL_IS_TLS13(s)) {
|
||||
cipher =
|
||||
- ssl3_choose_cipher(s, s->peer_ciphers, SSL_get_ciphers(s));
|
||||
+ ssl3_choose_cipher(s, s->peer_ciphers, ssl_get_cipher_preferences(s));
|
||||
|
||||
if (cipher == NULL) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
diff --git a/util/libcrypto.num b/util/libcrypto.num
|
||||
index f81fefb9b2..7d36cf81fe 100644
|
||||
--- a/util/libcrypto.num
|
||||
+++ b/util/libcrypto.num
|
||||
@@ -3340,14 +3340,14 @@ CRYPTO_new_ex_data 3409 3_0_0 EXIST::FUNCTION:
|
||||
PEM_read_PKCS8_PRIV_KEY_INFO 3410 3_0_0 EXIST::FUNCTION:STDIO
|
||||
TS_VERIFY_CTX_new 3411 3_0_0 EXIST::FUNCTION:TS
|
||||
BUF_MEM_new_ex 3412 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_add_X931 3413 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_add_X931 3413 3_0_0 EXIST::FUNCTION:RSA
|
||||
BN_get0_nist_prime_256 3414 3_0_0 EXIST::FUNCTION:
|
||||
CRYPTO_memcmp 3415 3_0_0 EXIST::FUNCTION:
|
||||
DH_check_pub_key 3416 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
ASN1_mbstring_copy 3417 3_0_0 EXIST::FUNCTION:
|
||||
PKCS7_set_type 3418 3_0_0 EXIST::FUNCTION:
|
||||
BIO_gets 3419 3_0_0 EXIST::FUNCTION:
|
||||
-RSA_padding_check_PKCS1_type_1 3420 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_padding_check_PKCS1_type_1 3420 3_0_0 EXIST::FUNCTION:RSA
|
||||
UI_ctrl 3421 3_0_0 EXIST::FUNCTION:
|
||||
i2d_X509_REQ_fp 3422 3_0_0 EXIST::FUNCTION:STDIO
|
||||
BN_BLINDING_convert_ex 3423 3_0_0 EXIST::FUNCTION:
|
||||
@@ -4273,14 +4273,14 @@ EVP_PKEY_asn1_set_param_check 4368 3_0_0 EXIST::FUNCTION:
|
||||
DH_check_ex 4369 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
DH_check_pub_key_ex 4370 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
DH_check_params_ex 4371 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH
|
||||
-RSA_generate_multi_prime_key 4372 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_generate_multi_prime_key 4372 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_get_multi_prime_extra_count 4373 3_0_0 EXIST::FUNCTION:RSA
|
||||
OCSP_resp_get0_signer 4374 3_0_0 EXIST::FUNCTION:OCSP
|
||||
RSA_get0_multi_prime_crt_params 4375 3_0_0 EXIST::FUNCTION:RSA
|
||||
RSA_set0_multi_prime_params 4376 3_0_0 EXIST::FUNCTION:RSA
|
||||
-RSA_get_version 4377 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_get_multi_prime_keygen 4378 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
-RSA_meth_set_multi_prime_keygen 4379 3_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RSA
|
||||
+RSA_get_version 4377 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_get_multi_prime_keygen 4378 3_0_0 EXIST::FUNCTION:RSA
|
||||
+RSA_meth_set_multi_prime_keygen 4379 3_0_0 EXIST::FUNCTION:RSA
|
||||
RAND_DRBG_get0_master 4380 3_0_0 EXIST::FUNCTION:
|
||||
RAND_DRBG_set_reseed_time_interval 4381 3_0_0 EXIST::FUNCTION:
|
||||
PROFESSION_INFO_get0_addProfessionInfo 4382 3_0_0 EXIST::FUNCTION:
|
||||
Reference in New Issue
Block a user