tls.h
Go to the documentation of this file.
1 /**
2  * @file tls.h
3  * @brief TLS (Transport Layer Security)
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2026 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneSSL Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.6.6
29  **/
30 
31 #ifndef _TLS_H
32 #define _TLS_H
33 
34 //Forward declaration of TlsContext structure
35 struct _TlsContext;
36 #define TlsContext struct _TlsContext
37 
38 //Forward declaration of TlsEncryptionEngine structure
40 #define TlsEncryptionEngine struct _TlsEncryptionEngine
41 
42 //Dependencies
43 #include "core/crypto.h"
44 #include "mac/hmac.h"
46 #include "aead/aead_algorithms.h"
48 #include "pkc/rsa.h"
49 #include "pkc/dsa.h"
50 #include "ecc/ecdsa.h"
51 #include "pkix/x509_common.h"
52 #include "tls_config.h"
53 #include "tls/tls_legacy.h"
54 #include "tls13/tls13_misc.h"
55 #include "dtls/dtls_misc.h"
56 #include "dtls13/dtls13_misc.h"
57 
58 
59 /*
60  * CycloneSSL Open is licensed under GPL version 2. In particular:
61  *
62  * - If you link your program to CycloneSSL Open, the result is a derivative
63  * work that can only be distributed under the same GPL license terms.
64  *
65  * - If additions or changes to CycloneSSL Open are made, the result is a
66  * derivative work that can only be distributed under the same license terms.
67  *
68  * - The GPL license requires that you make the source code available to
69  * whoever you make the binary available to.
70  *
71  * - If you sell or distribute a hardware product that runs CycloneSSL Open,
72  * the GPL license requires you to provide public and full access to all
73  * source code on a nondiscriminatory basis.
74  *
75  * If you fully understand and accept the terms of the GPL license, then edit
76  * the os_port_config.h header and add the following directive:
77  *
78  * #define GPL_LICENSE_TERMS_ACCEPTED
79  */
80 
81 #ifndef GPL_LICENSE_TERMS_ACCEPTED
82  #error Before compiling CycloneSSL Open, you must accept the terms of the GPL license
83 #endif
84 
85 //Version string
86 #define CYCLONE_SSL_VERSION_STRING "2.6.6"
87 //Major version
88 #define CYCLONE_SSL_MAJOR_VERSION 2
89 //Minor version
90 #define CYCLONE_SSL_MINOR_VERSION 6
91 //Revision number
92 #define CYCLONE_SSL_REV_NUMBER 6
93 
94 //TLS version numbers
95 #define SSL_VERSION_3_0 0x0300
96 #define TLS_VERSION_1_0 0x0301
97 #define TLS_VERSION_1_1 0x0302
98 #define TLS_VERSION_1_2 0x0303
99 #define TLS_VERSION_1_3 0x0304
100 
101 //TLS support
102 #ifndef TLS_SUPPORT
103  #define TLS_SUPPORT ENABLED
104 #elif (TLS_SUPPORT != ENABLED && TLS_SUPPORT != DISABLED)
105  #error TLS_SUPPORT parameter is not valid
106 #endif
107 
108 //QUIC support
109 #ifndef TLS_QUIC_SUPPORT
110  #define TLS_QUIC_SUPPORT DISABLED
111 #elif (TLS_QUIC_SUPPORT != ENABLED && TLS_QUIC_SUPPORT != DISABLED)
112  #error TLS_QUIC_SUPPORT parameter is not valid
113 #endif
114 
115 //Client mode of operation
116 #ifndef TLS_CLIENT_SUPPORT
117  #define TLS_CLIENT_SUPPORT ENABLED
118 #elif (TLS_CLIENT_SUPPORT != ENABLED && TLS_CLIENT_SUPPORT != DISABLED)
119  #error TLS_CLIENT_SUPPORT parameter is not valid
120 #endif
121 
122 //Server mode of operation
123 #ifndef TLS_SERVER_SUPPORT
124  #define TLS_SERVER_SUPPORT ENABLED
125 #elif (TLS_SERVER_SUPPORT != ENABLED && TLS_SERVER_SUPPORT != DISABLED)
126  #error TLS_SERVER_SUPPORT parameter is not valid
127 #endif
128 
129 //Minimum TLS version that can be negotiated
130 #ifndef TLS_MIN_VERSION
131  #define TLS_MIN_VERSION TLS_VERSION_1_2
132 #elif (TLS_MIN_VERSION < TLS_VERSION_1_0)
133  #error TLS_MIN_VERSION parameter is not valid
134 #endif
135 
136 //Maximum TLS version that can be negotiated
137 #ifndef TLS_MAX_VERSION
138  #define TLS_MAX_VERSION TLS_VERSION_1_3
139 #elif (TLS_MAX_VERSION > TLS_VERSION_1_3 || TLS_MAX_VERSION < TLS_MIN_VERSION)
140  #error TLS_MAX_VERSION parameter is not valid
141 #endif
142 
143 //RTOS support
144 #ifndef TLS_RTOS_SUPPORT
145  #define TLS_RTOS_SUPPORT ENABLED
146 #elif (TLS_RTOS_SUPPORT != ENABLED && TLS_RTOS_SUPPORT != DISABLED)
147  #error TLS_RTOS_SUPPORT parameter is not valid
148 #endif
149 
150 //Session resumption mechanism
151 #ifndef TLS_SESSION_RESUME_SUPPORT
152  #define TLS_SESSION_RESUME_SUPPORT ENABLED
153 #elif (TLS_SESSION_RESUME_SUPPORT != ENABLED && TLS_SESSION_RESUME_SUPPORT != DISABLED)
154  #error TLS_SESSION_RESUME_SUPPORT parameter is not valid
155 #endif
156 
157 //Lifetime of session cache entries
158 #ifndef TLS_SESSION_CACHE_LIFETIME
159  #define TLS_SESSION_CACHE_LIFETIME 3600000
160 #elif (TLS_SESSION_CACHE_LIFETIME < 1000)
161  #error TLS_SESSION_CACHE_LIFETIME parameter is not valid
162 #endif
163 
164 //Session ticket mechanism
165 #ifndef TLS_TICKET_SUPPORT
166  #define TLS_TICKET_SUPPORT DISABLED
167 #elif (TLS_TICKET_SUPPORT != ENABLED && TLS_TICKET_SUPPORT != DISABLED)
168  #error TLS_TICKET_SUPPORT parameter is not valid
169 #endif
170 
171 //Maximum size for session tickets
172 #ifndef TLS_MAX_TICKET_SIZE
173  #define TLS_MAX_TICKET_SIZE 1024
174 #elif (TLS_MAX_TICKET_SIZE < 32)
175  #error TLS_MAX_TICKET_SIZE parameter is not valid
176 #endif
177 
178 //Lifetime of session tickets
179 #ifndef TLS_TICKET_LIFETIME
180  #define TLS_TICKET_LIFETIME 3600000
181 #elif (TLS_TICKET_LIFETIME < 0)
182  #error TLS_TICKET_LIFETIME parameter is not valid
183 #endif
184 
185 //SNI (Server Name Indication) extension
186 #ifndef TLS_SNI_SUPPORT
187  #define TLS_SNI_SUPPORT ENABLED
188 #elif (TLS_SNI_SUPPORT != ENABLED && TLS_SNI_SUPPORT != DISABLED)
189  #error TLS_SNI_SUPPORT parameter is not valid
190 #endif
191 
192 //Maximum Fragment Length extension
193 #ifndef TLS_MAX_FRAG_LEN_SUPPORT
194  #define TLS_MAX_FRAG_LEN_SUPPORT DISABLED
195 #elif (TLS_MAX_FRAG_LEN_SUPPORT != ENABLED && TLS_MAX_FRAG_LEN_SUPPORT != DISABLED)
196  #error TLS_MAX_FRAG_LEN_SUPPORT parameter is not valid
197 #endif
198 
199 //Record Size Limit extension
200 #ifndef TLS_RECORD_SIZE_LIMIT_SUPPORT
201  #define TLS_RECORD_SIZE_LIMIT_SUPPORT ENABLED
202 #elif (TLS_RECORD_SIZE_LIMIT_SUPPORT != ENABLED && TLS_RECORD_SIZE_LIMIT_SUPPORT != DISABLED)
203  #error TLS_RECORD_SIZE_LIMIT_SUPPORT parameter is not valid
204 #endif
205 
206 //ALPN (Application-Layer Protocol Negotiation) extension
207 #ifndef TLS_ALPN_SUPPORT
208  #define TLS_ALPN_SUPPORT DISABLED
209 #elif (TLS_ALPN_SUPPORT != ENABLED && TLS_ALPN_SUPPORT != DISABLED)
210  #error TLS_ALPN_SUPPORT parameter is not valid
211 #endif
212 
213 //Encrypt-then-MAC extension
214 #ifndef TLS_ENCRYPT_THEN_MAC_SUPPORT
215  #define TLS_ENCRYPT_THEN_MAC_SUPPORT ENABLED
216 #elif (TLS_ENCRYPT_THEN_MAC_SUPPORT != ENABLED && TLS_ENCRYPT_THEN_MAC_SUPPORT != DISABLED)
217  #error TLS_ENCRYPT_THEN_MAC_SUPPORT parameter is not valid
218 #endif
219 
220 //Extended Master Secret extension
221 #ifndef TLS_EXT_MASTER_SECRET_SUPPORT
222  #define TLS_EXT_MASTER_SECRET_SUPPORT ENABLED
223 #elif (TLS_EXT_MASTER_SECRET_SUPPORT != ENABLED && TLS_EXT_MASTER_SECRET_SUPPORT != DISABLED)
224  #error TLS_EXT_MASTER_SECRET_SUPPORT parameter is not valid
225 #endif
226 
227 //ClientHello Padding extension
228 #ifndef TLS_CLIENT_HELLO_PADDING_SUPPORT
229  #define TLS_CLIENT_HELLO_PADDING_SUPPORT ENABLED
230 #elif (TLS_CLIENT_HELLO_PADDING_SUPPORT != ENABLED && TLS_CLIENT_HELLO_PADDING_SUPPORT != DISABLED)
231  #error TLS_CLIENT_HELLO_PADDING_SUPPORT parameter is not valid
232 #endif
233 
234 //Trusted CA Keys extension
235 #ifndef TLS_TRUSTED_CA_KEYS_SUPPORT
236  #define TLS_TRUSTED_CA_KEYS_SUPPORT DISABLED
237 #elif (TLS_TRUSTED_CA_KEYS_SUPPORT != ENABLED && TLS_TRUSTED_CA_KEYS_SUPPORT != DISABLED)
238  #error TLS_TRUSTED_CA_KEYS_SUPPORT parameter is not valid
239 #endif
240 
241 //Certificate Authorities extension
242 #ifndef TLS_CERT_AUTHORITIES_SUPPORT
243  #define TLS_CERT_AUTHORITIES_SUPPORT DISABLED
244 #elif (TLS_CERT_AUTHORITIES_SUPPORT != ENABLED && TLS_CERT_AUTHORITIES_SUPPORT != DISABLED)
245  #error TLS_CERT_AUTHORITIES_SUPPORT parameter is not valid
246 #endif
247 
248 //Signature Algorithms Certificate extension
249 #ifndef TLS_SIGN_ALGOS_CERT_SUPPORT
250  #define TLS_SIGN_ALGOS_CERT_SUPPORT ENABLED
251 #elif (TLS_SIGN_ALGOS_CERT_SUPPORT != ENABLED && TLS_SIGN_ALGOS_CERT_SUPPORT != DISABLED)
252  #error TLS_SIGN_ALGOS_CERT_SUPPORT parameter is not valid
253 #endif
254 
255 //RPK (Raw Public Key) support
256 #ifndef TLS_RAW_PUBLIC_KEY_SUPPORT
257  #define TLS_RAW_PUBLIC_KEY_SUPPORT DISABLED
258 #elif (TLS_RAW_PUBLIC_KEY_SUPPORT != ENABLED && TLS_RAW_PUBLIC_KEY_SUPPORT != DISABLED)
259  #error TLS_RAW_PUBLIC_KEY_SUPPORT parameter is not valid
260 #endif
261 
262 //Secure renegotiation support
263 #ifndef TLS_SECURE_RENEGOTIATION_SUPPORT
264  #define TLS_SECURE_RENEGOTIATION_SUPPORT ENABLED
265 #elif (TLS_SECURE_RENEGOTIATION_SUPPORT != ENABLED && TLS_SECURE_RENEGOTIATION_SUPPORT != DISABLED)
266  #error TLS_SECURE_RENEGOTIATION_SUPPORT parameter is not valid
267 #endif
268 
269 //Fallback SCSV support
270 #ifndef TLS_FALLBACK_SCSV_SUPPORT
271  #define TLS_FALLBACK_SCSV_SUPPORT DISABLED
272 #elif (TLS_FALLBACK_SCSV_SUPPORT != ENABLED && TLS_FALLBACK_SCSV_SUPPORT != DISABLED)
273  #error TLS_FALLBACK_SCSV_SUPPORT parameter is not valid
274 #endif
275 
276 //ECC callback functions
277 #ifndef TLS_ECC_CALLBACK_SUPPORT
278  #define TLS_ECC_CALLBACK_SUPPORT DISABLED
279 #elif (TLS_ECC_CALLBACK_SUPPORT != ENABLED && TLS_ECC_CALLBACK_SUPPORT != DISABLED)
280  #error TLS_ECC_CALLBACK_SUPPORT parameter is not valid
281 #endif
282 
283 //Maximum number of certificates the end entity can load
284 #ifndef TLS_MAX_CERTIFICATES
285  #define TLS_MAX_CERTIFICATES 3
286 #elif (TLS_MAX_CERTIFICATES < 1)
287  #error TLS_MAX_CERTIFICATES parameter is not valid
288 #endif
289 
290 //RSA key exchange support
291 #ifndef TLS_RSA_KE_SUPPORT
292  #define TLS_RSA_KE_SUPPORT DISABLED
293 #elif (TLS_RSA_KE_SUPPORT != ENABLED && TLS_RSA_KE_SUPPORT != DISABLED)
294  #error TLS_RSA_KE_SUPPORT parameter is not valid
295 #endif
296 
297 //DHE_RSA key exchange support
298 #ifndef TLS_DHE_RSA_KE_SUPPORT
299  #define TLS_DHE_RSA_KE_SUPPORT DISABLED
300 #elif (TLS_DHE_RSA_KE_SUPPORT != ENABLED && TLS_DHE_RSA_KE_SUPPORT != DISABLED)
301  #error TLS_DHE_RSA_KE_SUPPORT parameter is not valid
302 #endif
303 
304 //DHE_DSS key exchange support
305 #ifndef TLS_DHE_DSS_KE_SUPPORT
306  #define TLS_DHE_DSS_KE_SUPPORT DISABLED
307 #elif (TLS_DHE_DSS_KE_SUPPORT != ENABLED && TLS_DHE_DSS_KE_SUPPORT != DISABLED)
308  #error TLS_DHE_DSS_KE_SUPPORT parameter is not valid
309 #endif
310 
311 //DH_anon key exchange support (insecure)
312 #ifndef TLS_DH_ANON_KE_SUPPORT
313  #define TLS_DH_ANON_KE_SUPPORT DISABLED
314 #elif (TLS_DH_ANON_KE_SUPPORT != ENABLED && TLS_DH_ANON_KE_SUPPORT != DISABLED)
315  #error TLS_DH_ANON_KE_SUPPORT parameter is not valid
316 #endif
317 
318 //ECDHE_RSA key exchange support
319 #ifndef TLS_ECDHE_RSA_KE_SUPPORT
320  #define TLS_ECDHE_RSA_KE_SUPPORT ENABLED
321 #elif (TLS_ECDHE_RSA_KE_SUPPORT != ENABLED && TLS_ECDHE_RSA_KE_SUPPORT != DISABLED)
322  #error TLS_ECDHE_RSA_KE_SUPPORT parameter is not valid
323 #endif
324 
325 //ECDHE_ECDSA key exchange support
326 #ifndef TLS_ECDHE_ECDSA_KE_SUPPORT
327  #define TLS_ECDHE_ECDSA_KE_SUPPORT ENABLED
328 #elif (TLS_ECDHE_ECDSA_KE_SUPPORT != ENABLED && TLS_ECDHE_ECDSA_KE_SUPPORT != DISABLED)
329  #error TLS_ECDHE_ECDSA_KE_SUPPORT parameter is not valid
330 #endif
331 
332 //ECDH_anon key exchange support (insecure)
333 #ifndef TLS_ECDH_ANON_KE_SUPPORT
334  #define TLS_ECDH_ANON_KE_SUPPORT DISABLED
335 #elif (TLS_ECDH_ANON_KE_SUPPORT != ENABLED && TLS_ECDH_ANON_KE_SUPPORT != DISABLED)
336  #error TLS_ECDH_ANON_KE_SUPPORT parameter is not valid
337 #endif
338 
339 //PSK key exchange support
340 #ifndef TLS_PSK_KE_SUPPORT
341  #define TLS_PSK_KE_SUPPORT DISABLED
342 #elif (TLS_PSK_KE_SUPPORT != ENABLED && TLS_PSK_KE_SUPPORT != DISABLED)
343  #error TLS_PSK_KE_SUPPORT parameter is not valid
344 #endif
345 
346 //RSA_PSK key exchange support
347 #ifndef TLS_RSA_PSK_KE_SUPPORT
348  #define TLS_RSA_PSK_KE_SUPPORT DISABLED
349 #elif (TLS_RSA_PSK_KE_SUPPORT != ENABLED && TLS_RSA_PSK_KE_SUPPORT != DISABLED)
350  #error TLS_RSA_PSK_KE_SUPPORT parameter is not valid
351 #endif
352 
353 //DHE_PSK key exchange support
354 #ifndef TLS_DHE_PSK_KE_SUPPORT
355  #define TLS_DHE_PSK_KE_SUPPORT DISABLED
356 #elif (TLS_DHE_PSK_KE_SUPPORT != ENABLED && TLS_DHE_PSK_KE_SUPPORT != DISABLED)
357  #error TLS_DHE_PSK_KE_SUPPORT parameter is not valid
358 #endif
359 
360 //ECDHE_PSK key exchange support
361 #ifndef TLS_ECDHE_PSK_KE_SUPPORT
362  #define TLS_ECDHE_PSK_KE_SUPPORT DISABLED
363 #elif (TLS_ECDHE_PSK_KE_SUPPORT != ENABLED && TLS_ECDHE_PSK_KE_SUPPORT != DISABLED)
364  #error TLS_ECDHE_PSK_KE_SUPPORT parameter is not valid
365 #endif
366 
367 //RSA signature capability
368 #ifndef TLS_RSA_SIGN_SUPPORT
369  #define TLS_RSA_SIGN_SUPPORT ENABLED
370 #elif (TLS_RSA_SIGN_SUPPORT != ENABLED && TLS_RSA_SIGN_SUPPORT != DISABLED)
371  #error TLS_RSA_SIGN_SUPPORT parameter is not valid
372 #endif
373 
374 //RSA-PSS signature capability
375 #ifndef TLS_RSA_PSS_SIGN_SUPPORT
376  #define TLS_RSA_PSS_SIGN_SUPPORT ENABLED
377 #elif (TLS_RSA_PSS_SIGN_SUPPORT != ENABLED && TLS_RSA_PSS_SIGN_SUPPORT != DISABLED)
378  #error TLS_RSA_PSS_SIGN_SUPPORT parameter is not valid
379 #endif
380 
381 //DSA signature capability
382 #ifndef TLS_DSA_SIGN_SUPPORT
383  #define TLS_DSA_SIGN_SUPPORT DISABLED
384 #elif (TLS_DSA_SIGN_SUPPORT != ENABLED && TLS_DSA_SIGN_SUPPORT != DISABLED)
385  #error TLS_DSA_SIGN_SUPPORT parameter is not valid
386 #endif
387 
388 //ECDSA signature capability
389 #ifndef TLS_ECDSA_SIGN_SUPPORT
390  #define TLS_ECDSA_SIGN_SUPPORT ENABLED
391 #elif (TLS_ECDSA_SIGN_SUPPORT != ENABLED && TLS_ECDSA_SIGN_SUPPORT != DISABLED)
392  #error TLS_ECDSA_SIGN_SUPPORT parameter is not valid
393 #endif
394 
395 //SM2 signature capability (not recommended by the IETF)
396 #ifndef TLS_SM2_SIGN_SUPPORT
397  #define TLS_SM2_SIGN_SUPPORT DISABLED
398 #elif (TLS_SM2_SIGN_SUPPORT != ENABLED && TLS_SM2_SIGN_SUPPORT != DISABLED)
399  #error TLS_SM2_SIGN_SUPPORT parameter is not valid
400 #endif
401 
402 //Ed25519 signature capability
403 #ifndef TLS_ED25519_SIGN_SUPPORT
404  #define TLS_ED25519_SIGN_SUPPORT DISABLED
405 #elif (TLS_ED25519_SIGN_SUPPORT != ENABLED && TLS_ED25519_SIGN_SUPPORT != DISABLED)
406  #error TLS_ED25519_SIGN_SUPPORT parameter is not valid
407 #endif
408 
409 //Ed448 signature capability
410 #ifndef TLS_ED448_SIGN_SUPPORT
411  #define TLS_ED448_SIGN_SUPPORT DISABLED
412 #elif (TLS_ED448_SIGN_SUPPORT != ENABLED && TLS_ED448_SIGN_SUPPORT != DISABLED)
413  #error TLS_ED448_SIGN_SUPPORT parameter is not valid
414 #endif
415 
416 //ML-DSA-44 signature capability
417 #ifndef TLS_MLDSA44_SIGN_SUPPORT
418  #define TLS_MLDSA44_SIGN_SUPPORT DISABLED
419 #elif (TLS_MLDSA44_SIGN_SUPPORT != ENABLED && TLS_MLDSA44_SIGN_SUPPORT != DISABLED)
420  #error TLS_MLDSA44_SIGN_SUPPORT parameter is not valid
421 #endif
422 
423 //ML-DSA-65 signature capability
424 #ifndef TLS_MLDSA65_SIGN_SUPPORT
425  #define TLS_MLDSA65_SIGN_SUPPORT DISABLED
426 #elif (TLS_MLDSA65_SIGN_SUPPORT != ENABLED && TLS_MLDSA65_SIGN_SUPPORT != DISABLED)
427  #error TLS_MLDSA65_SIGN_SUPPORT parameter is not valid
428 #endif
429 
430 //ML-DSA-87 signature capability
431 #ifndef TLS_MLDSA87_SIGN_SUPPORT
432  #define TLS_MLDSA87_SIGN_SUPPORT DISABLED
433 #elif (TLS_MLDSA87_SIGN_SUPPORT != ENABLED && TLS_MLDSA87_SIGN_SUPPORT != DISABLED)
434  #error TLS_MLDSA87_SIGN_SUPPORT parameter is not valid
435 #endif
436 
437 //NULL cipher support (insecure)
438 #ifndef TLS_NULL_CIPHER_SUPPORT
439  #define TLS_NULL_CIPHER_SUPPORT DISABLED
440 #elif (TLS_NULL_CIPHER_SUPPORT != ENABLED && TLS_NULL_CIPHER_SUPPORT != DISABLED)
441  #error TLS_NULL_CIPHER_SUPPORT parameter is not valid
442 #endif
443 
444 //Stream cipher support
445 #ifndef TLS_STREAM_CIPHER_SUPPORT
446  #define TLS_STREAM_CIPHER_SUPPORT DISABLED
447 #elif (TLS_STREAM_CIPHER_SUPPORT != ENABLED && TLS_STREAM_CIPHER_SUPPORT != DISABLED)
448  #error TLS_STREAM_CIPHER_SUPPORT parameter is not valid
449 #endif
450 
451 //CBC block cipher support
452 #ifndef TLS_CBC_CIPHER_SUPPORT
453  #define TLS_CBC_CIPHER_SUPPORT ENABLED
454 #elif (TLS_CBC_CIPHER_SUPPORT != ENABLED && TLS_CBC_CIPHER_SUPPORT != DISABLED)
455  #error TLS_CBC_CIPHER_SUPPORT parameter is not valid
456 #endif
457 
458 //CCM AEAD support
459 #ifndef TLS_CCM_CIPHER_SUPPORT
460  #define TLS_CCM_CIPHER_SUPPORT DISABLED
461 #elif (TLS_CCM_CIPHER_SUPPORT != ENABLED && TLS_CCM_CIPHER_SUPPORT != DISABLED)
462  #error TLS_CCM_CIPHER_SUPPORT parameter is not valid
463 #endif
464 
465 //CCM_8 AEAD support
466 #ifndef TLS_CCM_8_CIPHER_SUPPORT
467  #define TLS_CCM_8_CIPHER_SUPPORT DISABLED
468 #elif (TLS_CCM_8_CIPHER_SUPPORT != ENABLED && TLS_CCM_8_CIPHER_SUPPORT != DISABLED)
469  #error TLS_CCM_8_CIPHER_SUPPORT parameter is not valid
470 #endif
471 
472 //GCM AEAD support
473 #ifndef TLS_GCM_CIPHER_SUPPORT
474  #define TLS_GCM_CIPHER_SUPPORT ENABLED
475 #elif (TLS_GCM_CIPHER_SUPPORT != ENABLED && TLS_GCM_CIPHER_SUPPORT != DISABLED)
476  #error TLS_GCM_CIPHER_SUPPORT parameter is not valid
477 #endif
478 
479 //ChaCha20Poly1305 AEAD support
480 #ifndef TLS_CHACHA20_POLY1305_SUPPORT
481  #define TLS_CHACHA20_POLY1305_SUPPORT DISABLED
482 #elif (TLS_CHACHA20_POLY1305_SUPPORT != ENABLED && TLS_CHACHA20_POLY1305_SUPPORT != DISABLED)
483  #error TLS_CHACHA20_POLY1305_SUPPORT parameter is not valid
484 #endif
485 
486 //RC4 cipher support (insecure)
487 #ifndef TLS_RC4_SUPPORT
488  #define TLS_RC4_SUPPORT DISABLED
489 #elif (TLS_RC4_SUPPORT != ENABLED && TLS_RC4_SUPPORT != DISABLED)
490  #error TLS_RC4_SUPPORT parameter is not valid
491 #endif
492 
493 //IDEA cipher support (insecure)
494 #ifndef TLS_IDEA_SUPPORT
495  #define TLS_IDEA_SUPPORT DISABLED
496 #elif (TLS_IDEA_SUPPORT != ENABLED && TLS_IDEA_SUPPORT != DISABLED)
497  #error TLS_IDEA_SUPPORT parameter is not valid
498 #endif
499 
500 //DES cipher support (insecure)
501 #ifndef TLS_DES_SUPPORT
502  #define TLS_DES_SUPPORT DISABLED
503 #elif (TLS_DES_SUPPORT != ENABLED && TLS_DES_SUPPORT != DISABLED)
504  #error TLS_DES_SUPPORT parameter is not valid
505 #endif
506 
507 //Triple DES cipher support (weak)
508 #ifndef TLS_3DES_SUPPORT
509  #define TLS_3DES_SUPPORT DISABLED
510 #elif (TLS_3DES_SUPPORT != ENABLED && TLS_3DES_SUPPORT != DISABLED)
511  #error TLS_3DES_SUPPORT parameter is not valid
512 #endif
513 
514 //AES 128-bit cipher support
515 #ifndef TLS_AES_128_SUPPORT
516  #define TLS_AES_128_SUPPORT ENABLED
517 #elif (TLS_AES_128_SUPPORT != ENABLED && TLS_AES_128_SUPPORT != DISABLED)
518  #error TLS_AES_128_SUPPORT parameter is not valid
519 #endif
520 
521 //AES 256-bit cipher support
522 #ifndef TLS_AES_256_SUPPORT
523  #define TLS_AES_256_SUPPORT ENABLED
524 #elif (TLS_AES_256_SUPPORT != ENABLED && TLS_AES_256_SUPPORT != DISABLED)
525  #error TLS_AES_256_SUPPORT parameter is not valid
526 #endif
527 
528 //Camellia 128-bit cipher support
529 #ifndef TLS_CAMELLIA_128_SUPPORT
530  #define TLS_CAMELLIA_128_SUPPORT DISABLED
531 #elif (TLS_CAMELLIA_128_SUPPORT != ENABLED && TLS_CAMELLIA_128_SUPPORT != DISABLED)
532  #error TLS_CAMELLIA_128_SUPPORT parameter is not valid
533 #endif
534 
535 //Camellia 256-bit cipher support
536 #ifndef TLS_CAMELLIA_256_SUPPORT
537  #define TLS_CAMELLIA_256_SUPPORT DISABLED
538 #elif (TLS_CAMELLIA_256_SUPPORT != ENABLED && TLS_CAMELLIA_256_SUPPORT != DISABLED)
539  #error TLS_CAMELLIA_256_SUPPORT parameter is not valid
540 #endif
541 
542 //ARIA 128-bit cipher support
543 #ifndef TLS_ARIA_128_SUPPORT
544  #define TLS_ARIA_128_SUPPORT DISABLED
545 #elif (TLS_ARIA_128_SUPPORT != ENABLED && TLS_ARIA_128_SUPPORT != DISABLED)
546  #error TLS_ARIA_128_SUPPORT parameter is not valid
547 #endif
548 
549 //ARIA 256-bit cipher support
550 #ifndef TLS_ARIA_256_SUPPORT
551  #define TLS_ARIA_256_SUPPORT DISABLED
552 #elif (TLS_ARIA_256_SUPPORT != ENABLED && TLS_ARIA_256_SUPPORT != DISABLED)
553  #error TLS_ARIA_256_SUPPORT parameter is not valid
554 #endif
555 
556 //SEED cipher support (weak)
557 #ifndef TLS_SEED_SUPPORT
558  #define TLS_SEED_SUPPORT DISABLED
559 #elif (TLS_SEED_SUPPORT != ENABLED && TLS_SEED_SUPPORT != DISABLED)
560  #error TLS_SEED_SUPPORT parameter is not valid
561 #endif
562 
563 //SM4 cipher support (not recommended by the IETF)
564 #ifndef TLS_SM4_SUPPORT
565  #define TLS_SM4_SUPPORT DISABLED
566 #elif (TLS_SM4_SUPPORT != ENABLED && TLS_SM4_SUPPORT != DISABLED)
567  #error TLS_SM4_SUPPORT parameter is not valid
568 #endif
569 
570 //MD5 hash support (insecure)
571 #ifndef TLS_MD5_SUPPORT
572  #define TLS_MD5_SUPPORT DISABLED
573 #elif (TLS_MD5_SUPPORT != ENABLED && TLS_MD5_SUPPORT != DISABLED)
574  #error TLS_MD5_SUPPORT parameter is not valid
575 #endif
576 
577 //SHA-1 hash support (weak)
578 #ifndef TLS_SHA1_SUPPORT
579  #define TLS_SHA1_SUPPORT DISABLED
580 #elif (TLS_SHA1_SUPPORT != ENABLED && TLS_SHA1_SUPPORT != DISABLED)
581  #error TLS_SHA1_SUPPORT parameter is not valid
582 #endif
583 
584 //SHA-224 hash support (weak)
585 #ifndef TLS_SHA224_SUPPORT
586  #define TLS_SHA224_SUPPORT DISABLED
587 #elif (TLS_SHA224_SUPPORT != ENABLED && TLS_SHA224_SUPPORT != DISABLED)
588  #error TLS_SHA224_SUPPORT parameter is not valid
589 #endif
590 
591 //SHA-256 hash support
592 #ifndef TLS_SHA256_SUPPORT
593  #define TLS_SHA256_SUPPORT ENABLED
594 #elif (TLS_SHA256_SUPPORT != ENABLED && TLS_SHA256_SUPPORT != DISABLED)
595  #error TLS_SHA256_SUPPORT parameter is not valid
596 #endif
597 
598 //SHA-384 hash support
599 #ifndef TLS_SHA384_SUPPORT
600  #define TLS_SHA384_SUPPORT ENABLED
601 #elif (TLS_SHA384_SUPPORT != ENABLED && TLS_SHA384_SUPPORT != DISABLED)
602  #error TLS_SHA384_SUPPORT parameter is not valid
603 #endif
604 
605 //SHA-512 hash support
606 #ifndef TLS_SHA512_SUPPORT
607  #define TLS_SHA512_SUPPORT DISABLED
608 #elif (TLS_SHA512_SUPPORT != ENABLED && TLS_SHA512_SUPPORT != DISABLED)
609  #error TLS_SHA512_SUPPORT parameter is not valid
610 #endif
611 
612 //SM3 hash support (not recommended by the IETF)
613 #ifndef TLS_SM3_SUPPORT
614  #define TLS_SM3_SUPPORT DISABLED
615 #elif (TLS_SM3_SUPPORT != ENABLED && TLS_SM3_SUPPORT != DISABLED)
616  #error TLS_SM3_SUPPORT parameter is not valid
617 #endif
618 
619 //FFDHE key exchange mechanism
620 #ifndef TLS_FFDHE_SUPPORT
621  #define TLS_FFDHE_SUPPORT DISABLED
622 #elif (TLS_FFDHE_SUPPORT != ENABLED && TLS_FFDHE_SUPPORT != DISABLED)
623  #error TLS_FFDHE_SUPPORT parameter is not valid
624 #endif
625 
626 //ffdhe2048 group support
627 #ifndef TLS_FFDHE2048_SUPPORT
628  #define TLS_FFDHE2048_SUPPORT ENABLED
629 #elif (TLS_FFDHE2048_SUPPORT != ENABLED && TLS_FFDHE2048_SUPPORT != DISABLED)
630  #error TLS_FFDHE2048_SUPPORT parameter is not valid
631 #endif
632 
633 //ffdhe3072 group support
634 #ifndef TLS_FFDHE3072_SUPPORT
635  #define TLS_FFDHE3072_SUPPORT DISABLED
636 #elif (TLS_FFDHE3072_SUPPORT != ENABLED && TLS_FFDHE3072_SUPPORT != DISABLED)
637  #error TLS_FFDHE3072_SUPPORT parameter is not valid
638 #endif
639 
640 //ffdhe4096 group support
641 #ifndef TLS_FFDHE4096_SUPPORT
642  #define TLS_FFDHE4096_SUPPORT DISABLED
643 #elif (TLS_FFDHE4096_SUPPORT != ENABLED && TLS_FFDHE4096_SUPPORT != DISABLED)
644  #error TLS_FFDHE4096_SUPPORT parameter is not valid
645 #endif
646 
647 //secp160k1 elliptic curve support (weak)
648 #ifndef TLS_SECP160K1_SUPPORT
649  #define TLS_SECP160K1_SUPPORT DISABLED
650 #elif (TLS_SECP160K1_SUPPORT != ENABLED && TLS_SECP160K1_SUPPORT != DISABLED)
651  #error TLS_SECP160K1_SUPPORT parameter is not valid
652 #endif
653 
654 //secp160r1 elliptic curve support (weak)
655 #ifndef TLS_SECP160R1_SUPPORT
656  #define TLS_SECP160R1_SUPPORT DISABLED
657 #elif (TLS_SECP160R1_SUPPORT != ENABLED && TLS_SECP160R1_SUPPORT != DISABLED)
658  #error TLS_SECP160R1_SUPPORT parameter is not valid
659 #endif
660 
661 //secp160r2 elliptic curve support (weak)
662 #ifndef TLS_SECP160R2_SUPPORT
663  #define TLS_SECP160R2_SUPPORT DISABLED
664 #elif (TLS_SECP160R2_SUPPORT != ENABLED && TLS_SECP160R2_SUPPORT != DISABLED)
665  #error TLS_SECP160R2_SUPPORT parameter is not valid
666 #endif
667 
668 //secp192k1 elliptic curve support (weak)
669 #ifndef TLS_SECP192K1_SUPPORT
670  #define TLS_SECP192K1_SUPPORT DISABLED
671 #elif (TLS_SECP192K1_SUPPORT != ENABLED && TLS_SECP192K1_SUPPORT != DISABLED)
672  #error TLS_SECP192K1_SUPPORT parameter is not valid
673 #endif
674 
675 //secp192r1 elliptic curve support (weak)
676 #ifndef TLS_SECP192R1_SUPPORT
677  #define TLS_SECP192R1_SUPPORT DISABLED
678 #elif (TLS_SECP192R1_SUPPORT != ENABLED && TLS_SECP192R1_SUPPORT != DISABLED)
679  #error TLS_SECP192R1_SUPPORT parameter is not valid
680 #endif
681 
682 //secp224k1 elliptic curve support (weak)
683 #ifndef TLS_SECP224K1_SUPPORT
684  #define TLS_SECP224K1_SUPPORT DISABLED
685 #elif (TLS_SECP224K1_SUPPORT != ENABLED && TLS_SECP224K1_SUPPORT != DISABLED)
686  #error TLS_SECP224K1_SUPPORT parameter is not valid
687 #endif
688 
689 //secp224r1 elliptic curve support (weak)
690 #ifndef TLS_SECP224R1_SUPPORT
691  #define TLS_SECP224R1_SUPPORT DISABLED
692 #elif (TLS_SECP224R1_SUPPORT != ENABLED && TLS_SECP224R1_SUPPORT != DISABLED)
693  #error TLS_SECP224R1_SUPPORT parameter is not valid
694 #endif
695 
696 //secp256k1 elliptic curve support
697 #ifndef TLS_SECP256K1_SUPPORT
698  #define TLS_SECP256K1_SUPPORT DISABLED
699 #elif (TLS_SECP256K1_SUPPORT != ENABLED && TLS_SECP256K1_SUPPORT != DISABLED)
700  #error TLS_SECP256K1_SUPPORT parameter is not valid
701 #endif
702 
703 //secp256r1 elliptic curve support
704 #ifndef TLS_SECP256R1_SUPPORT
705  #define TLS_SECP256R1_SUPPORT ENABLED
706 #elif (TLS_SECP256R1_SUPPORT != ENABLED && TLS_SECP256R1_SUPPORT != DISABLED)
707  #error TLS_SECP256R1_SUPPORT parameter is not valid
708 #endif
709 
710 //secp384r1 elliptic curve support
711 #ifndef TLS_SECP384R1_SUPPORT
712  #define TLS_SECP384R1_SUPPORT ENABLED
713 #elif (TLS_SECP384R1_SUPPORT != ENABLED && TLS_SECP384R1_SUPPORT != DISABLED)
714  #error TLS_SECP384R1_SUPPORT parameter is not valid
715 #endif
716 
717 //secp521r1 elliptic curve support
718 #ifndef TLS_SECP521R1_SUPPORT
719  #define TLS_SECP521R1_SUPPORT DISABLED
720 #elif (TLS_SECP521R1_SUPPORT != ENABLED && TLS_SECP521R1_SUPPORT != DISABLED)
721  #error TLS_SECP521R1_SUPPORT parameter is not valid
722 #endif
723 
724 //brainpoolP256r1 elliptic curve support
725 #ifndef TLS_BRAINPOOLP256R1_SUPPORT
726  #define TLS_BRAINPOOLP256R1_SUPPORT DISABLED
727 #elif (TLS_BRAINPOOLP256R1_SUPPORT != ENABLED && TLS_BRAINPOOLP256R1_SUPPORT != DISABLED)
728  #error TLS_BRAINPOOLP256R1_SUPPORT parameter is not valid
729 #endif
730 
731 //brainpoolP384r1 elliptic curve support
732 #ifndef TLS_BRAINPOOLP384R1_SUPPORT
733  #define TLS_BRAINPOOLP384R1_SUPPORT DISABLED
734 #elif (TLS_BRAINPOOLP384R1_SUPPORT != ENABLED && TLS_BRAINPOOLP384R1_SUPPORT != DISABLED)
735  #error TLS_BRAINPOOLP384R1_SUPPORT parameter is not valid
736 #endif
737 
738 //brainpoolP512r1 elliptic curve support
739 #ifndef TLS_BRAINPOOLP512R1_SUPPORT
740  #define TLS_BRAINPOOLP512R1_SUPPORT DISABLED
741 #elif (TLS_BRAINPOOLP512R1_SUPPORT != ENABLED && TLS_BRAINPOOLP512R1_SUPPORT != DISABLED)
742  #error TLS_BRAINPOOLP512R1_SUPPORT parameter is not valid
743 #endif
744 
745 //SM2 elliptic curve support (not recommended by the IETF)
746 #ifndef TLS_SM2_SUPPORT
747  #define TLS_SM2_SUPPORT DISABLED
748 #elif (TLS_SM2_SUPPORT != ENABLED && TLS_SM2_SUPPORT != DISABLED)
749  #error TLS_SM2_SUPPORT parameter is not valid
750 #endif
751 
752 //Curve25519 elliptic curve support
753 #ifndef TLS_X25519_SUPPORT
754  #define TLS_X25519_SUPPORT ENABLED
755 #elif (TLS_X25519_SUPPORT != ENABLED && TLS_X25519_SUPPORT != DISABLED)
756  #error TLS_X25519_SUPPORT parameter is not valid
757 #endif
758 
759 //Curve448 elliptic curve support
760 #ifndef TLS_X448_SUPPORT
761  #define TLS_X448_SUPPORT DISABLED
762 #elif (TLS_X448_SUPPORT != ENABLED && TLS_X448_SUPPORT != DISABLED)
763  #error TLS_X448_SUPPORT parameter is not valid
764 #endif
765 
766 //ML-KEM-512 key encapsulation mechanism support
767 #ifndef TLS_MLKEM512_SUPPORT
768  #define TLS_MLKEM512_SUPPORT DISABLED
769 #elif (TLS_MLKEM512_SUPPORT != ENABLED && TLS_MLKEM512_SUPPORT != DISABLED)
770  #error TLS_MLKEM512_SUPPORT parameter is not valid
771 #endif
772 
773 //ML-KEM-768 key encapsulation mechanism support
774 #ifndef TLS_MLKEM768_SUPPORT
775  #define TLS_MLKEM768_SUPPORT DISABLED
776 #elif (TLS_MLKEM768_SUPPORT != ENABLED && TLS_MLKEM768_SUPPORT != DISABLED)
777  #error TLS_MLKEM768_SUPPORT parameter is not valid
778 #endif
779 
780 //ML-KEM-1024 key encapsulation mechanism support
781 #ifndef TLS_MLKEM1024_SUPPORT
782  #define TLS_MLKEM1024_SUPPORT DISABLED
783 #elif (TLS_MLKEM1024_SUPPORT != ENABLED && TLS_MLKEM1024_SUPPORT != DISABLED)
784  #error TLS_MLKEM1024_SUPPORT parameter is not valid
785 #endif
786 
787 //Certificate key usage verification
788 #ifndef TLS_CERT_KEY_USAGE_SUPPORT
789  #define TLS_CERT_KEY_USAGE_SUPPORT ENABLED
790 #elif (TLS_CERT_KEY_USAGE_SUPPORT != ENABLED && TLS_CERT_KEY_USAGE_SUPPORT != DISABLED)
791  #error TLS_CERT_KEY_USAGE_SUPPORT parameter is not valid
792 #endif
793 
794 //Key logging (for debugging purpose only)
795 #ifndef TLS_KEY_LOG_SUPPORT
796  #define TLS_KEY_LOG_SUPPORT DISABLED
797 #elif (TLS_KEY_LOG_SUPPORT != ENABLED && TLS_KEY_LOG_SUPPORT != DISABLED)
798  #error TLS_KEY_LOG_SUPPORT parameter is not valid
799 #endif
800 
801 //Maximum length of server name
802 #ifndef TLS_MAX_SERVER_NAME_LEN
803  #define TLS_MAX_SERVER_NAME_LEN 255
804 #elif (TLS_MAX_SERVER_NAME_LEN < 1)
805  #error TLS_MAX_SERVER_NAME_LEN parameter is not valid
806 #endif
807 
808 //Maximum length of password
809 #ifndef TLS_MAX_PASSWORD_LEN
810  #define TLS_MAX_PASSWORD_LEN 32
811 #elif (TLS_MAX_PASSWORD_LEN < 0)
812  #error TLS_MAX_PASSWORD_LEN parameter is not valid
813 #endif
814 
815 //Minimum acceptable size for Diffie-Hellman prime modulus
816 #ifndef TLS_MIN_DH_MODULUS_SIZE
817  #define TLS_MIN_DH_MODULUS_SIZE 2048
818 #elif (TLS_MIN_DH_MODULUS_SIZE < 1024)
819  #error TLS_MIN_DH_MODULUS_SIZE parameter is not valid
820 #endif
821 
822 //Maximum acceptable size for Diffie-Hellman prime modulus
823 #ifndef TLS_MAX_DH_MODULUS_SIZE
824  #define TLS_MAX_DH_MODULUS_SIZE 2048
825 #elif (TLS_MAX_DH_MODULUS_SIZE < TLS_MIN_DH_MODULUS_SIZE)
826  #error TLS_MAX_DH_MODULUS_SIZE parameter is not valid
827 #endif
828 
829 //Minimum acceptable size for RSA modulus
830 #ifndef TLS_MIN_RSA_MODULUS_SIZE
831  #define TLS_MIN_RSA_MODULUS_SIZE 2048
832 #elif (TLS_MIN_RSA_MODULUS_SIZE < 1024)
833  #error TLS_MIN_RSA_MODULUS_SIZE parameter is not valid
834 #endif
835 
836 //Maximum acceptable size for RSA modulus
837 #ifndef TLS_MAX_RSA_MODULUS_SIZE
838  #define TLS_MAX_RSA_MODULUS_SIZE 4096
839 #elif (TLS_MAX_RSA_MODULUS_SIZE < TLS_MIN_RSA_MODULUS_SIZE)
840  #error TLS_MAX_RSA_MODULUS_SIZE parameter is not valid
841 #endif
842 
843 //Minimum acceptable size for DSA prime modulus
844 #ifndef TLS_MIN_DSA_MODULUS_SIZE
845  #define TLS_MIN_DSA_MODULUS_SIZE 2048
846 #elif (TLS_MIN_DSA_MODULUS_SIZE < 1024)
847  #error TLS_MIN_DSA_MODULUS_SIZE parameter is not valid
848 #endif
849 
850 //Maximum acceptable size for DSA prime modulus
851 #ifndef TLS_MAX_DSA_MODULUS_SIZE
852  #define TLS_MAX_DSA_MODULUS_SIZE 4096
853 #elif (TLS_MAX_DSA_MODULUS_SIZE < TLS_MIN_DSA_MODULUS_SIZE)
854  #error TLS_MAX_DSA_MODULUS_SIZE parameter is not valid
855 #endif
856 
857 //Master secret size
858 #ifndef TLS_MASTER_SECRET_SIZE
859  #define TLS_MASTER_SECRET_SIZE 48
860 #elif (TLS_MASTER_SECRET_SIZE < 48)
861  #error TLS_MASTER_SECRET_SIZE parameter is not valid
862 #endif
863 
864 //Maximum size for premaster secret
865 #ifndef TLS_PREMASTER_SECRET_SIZE
866  #define TLS_PREMASTER_SECRET_SIZE (TLS_MAX_DH_MODULUS_SIZE / 8)
867 #elif (TLS_PREMASTER_SECRET_SIZE < 48)
868  #error TLS_PREMASTER_SECRET_SIZE parameter is not valid
869 #endif
870 
871 //Maximum number of consecutive warning alerts
872 #ifndef TLS_MAX_WARNING_ALERTS
873  #define TLS_MAX_WARNING_ALERTS 5
874 #elif (TLS_MAX_WARNING_ALERTS < 0)
875  #error TLS_MAX_WARNING_ALERTS parameter is not valid
876 #endif
877 
878 //Maximum number of consecutive empty records
879 #ifndef TLS_MAX_EMPTY_RECORDS
880  #define TLS_MAX_EMPTY_RECORDS 10
881 #elif (TLS_MAX_EMPTY_RECORDS < 0)
882  #error TLS_MAX_EMPTY_RECORDS parameter is not valid
883 #endif
884 
885 //Maximum number of consecutive ChangeCipherSpec messages
886 #ifndef TLS_MAX_CHANGE_CIPHER_SPEC_MESSAGES
887  #define TLS_MAX_CHANGE_CIPHER_SPEC_MESSAGES 5
888 #elif (TLS_MAX_CHANGE_CIPHER_SPEC_MESSAGES < 0)
889  #error TLS_MAX_CHANGE_CIPHER_SPEC_MESSAGES parameter is not valid
890 #endif
891 
892 //Maximum number of consecutive KeyUpdate messages
893 #ifndef TLS_MAX_KEY_UPDATE_MESSAGES
894  #define TLS_MAX_KEY_UPDATE_MESSAGES 5
895 #elif (TLS_MAX_KEY_UPDATE_MESSAGES < 0)
896  #error TLS_MAX_KEY_UPDATE_MESSAGES parameter is not valid
897 #endif
898 
899 //Application specific context (TLS context)
900 #ifndef TLS_CONTEXT_PRIVATE
901  #define TLS_CONTEXT_PRIVATE
902 #endif
903 
904 //Application specific context (encryption engine)
905 #ifndef TLS_PRIVATE_ENCRYPTION_ENGINE
906  #define TLS_PRIVATE_ENCRYPTION_ENGINE
907 #endif
908 
909 //Allocate memory block
910 #ifndef tlsAllocMem
911  #define tlsAllocMem(size) osAllocMem(size)
912 #endif
913 
914 //Deallocate memory block
915 #ifndef tlsFreeMem
916  #define tlsFreeMem(p) osFreeMem(p)
917 #endif
918 
919 //Support for Diffie-Hellman key exchange?
920 #if ((TLS_MAX_VERSION >= TLS_VERSION_1_0 && TLS_MIN_VERSION <= TLS_VERSION_1_2) && \
921  (TLS_DH_ANON_KE_SUPPORT == ENABLED || TLS_DHE_RSA_KE_SUPPORT == ENABLED || \
922  TLS_DHE_DSS_KE_SUPPORT == ENABLED || TLS_DHE_PSK_KE_SUPPORT == ENABLED))
923  #define TLS_DH_SUPPORT ENABLED
924 #elif ((TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3) && \
925  (TLS13_DHE_KE_SUPPORT == ENABLED || TLS13_PSK_DHE_KE_SUPPORT == ENABLED))
926  #define TLS_DH_SUPPORT ENABLED
927 #else
928  #define TLS_DH_SUPPORT DISABLED
929 #endif
930 
931 //Support for ECDH key exchange?
932 #if ((TLS_MAX_VERSION >= TLS_VERSION_1_0 && TLS_MIN_VERSION <= TLS_VERSION_1_2) && \
933  (TLS_ECDH_ANON_KE_SUPPORT == ENABLED || TLS_ECDHE_RSA_KE_SUPPORT == ENABLED || \
934  TLS_ECDHE_ECDSA_KE_SUPPORT == ENABLED || TLS_ECDHE_PSK_KE_SUPPORT == ENABLED))
935  #define TLS_ECDH_SUPPORT ENABLED
936 #elif ((TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3) && \
937  (TLS13_ECDHE_KE_SUPPORT == ENABLED || TLS13_PSK_ECDHE_KE_SUPPORT == ENABLED))
938  #define TLS_ECDH_SUPPORT ENABLED
939 #else
940  #define TLS_ECDH_SUPPORT DISABLED
941 #endif
942 
943 //Support for ML-KEM key exchange?
944 #if ((TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3) && \
945  (TLS13_MLKEM_KE_SUPPORT == ENABLED || TLS13_PSK_MLKEM_KE_SUPPORT == ENABLED))
946  #define TLS_MLKEM_SUPPORT ENABLED
947 #else
948  #define TLS_MLKEM_SUPPORT DISABLED
949 #endif
950 
951 //Support for hybrid key exchange?
952 #if ((TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3) && \
953  (TLS13_HYBRID_KE_SUPPORT == ENABLED || TLS13_PSK_HYBRID_KE_SUPPORT == ENABLED))
954  #define TLS_HYBRID_SUPPORT ENABLED
955 #else
956  #define TLS_HYBRID_SUPPORT DISABLED
957 #endif
958 
959 //Support for RSA?
960 #if ((TLS_MAX_VERSION >= TLS_VERSION_1_0 && TLS_MIN_VERSION <= TLS_VERSION_1_2) && \
961  (TLS_RSA_SIGN_SUPPORT == ENABLED || TLS_RSA_PSS_SIGN_SUPPORT == ENABLED || \
962  TLS_RSA_KE_SUPPORT == ENABLED || TLS_DHE_RSA_KE_SUPPORT == ENABLED || \
963  TLS_ECDHE_RSA_KE_SUPPORT == ENABLED || TLS_RSA_PSK_KE_SUPPORT == ENABLED))
964  #define TLS_RSA_SUPPORT ENABLED
965 #elif ((TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3) && \
966  (TLS_RSA_SIGN_SUPPORT == ENABLED || TLS_RSA_PSS_SIGN_SUPPORT == ENABLED))
967  #define TLS_RSA_SUPPORT ENABLED
968 #else
969  #define TLS_RSA_SUPPORT DISABLED
970 #endif
971 
972 //Support for PSK?
973 #if ((TLS_MAX_VERSION >= TLS_VERSION_1_0 && TLS_MIN_VERSION <= TLS_VERSION_1_2) && \
974  (TLS_PSK_KE_SUPPORT == ENABLED || TLS_RSA_PSK_KE_SUPPORT == ENABLED || \
975  TLS_DHE_PSK_KE_SUPPORT == ENABLED || TLS_ECDHE_PSK_KE_SUPPORT == ENABLED))
976  #define TLS_PSK_SUPPORT ENABLED
977 #elif ((TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3) && \
978  (TLS13_PSK_KE_SUPPORT == ENABLED || TLS13_PSK_DHE_KE_SUPPORT == ENABLED || \
979  TLS13_PSK_ECDHE_KE_SUPPORT == ENABLED || TLS13_PSK_HYBRID_KE_SUPPORT == ENABLED))
980  #define TLS_PSK_SUPPORT ENABLED
981 #else
982  #define TLS_PSK_SUPPORT DISABLED
983 #endif
984 
985 //Maximum size for HKDF digests
986 #if (TLS_SHA384_SUPPORT == ENABLED)
987  #define TLS_MAX_HKDF_DIGEST_SIZE 48
988 #else
989  #define TLS_MAX_HKDF_DIGEST_SIZE 32
990 #endif
991 
992 //Number of encryption engines
993 #if (DTLS_SUPPORT == ENABLED && TLS_MAX_VERSION >= TLS_VERSION_1_3)
994  #define TLS_MAX_ENCRYPTION_ENGINES 3
995 #elif (DTLS_SUPPORT == ENABLED && TLS_MAX_VERSION <= TLS_VERSION_1_2)
996  #define TLS_MAX_ENCRYPTION_ENGINES 2
997 #else
998  #define TLS_MAX_ENCRYPTION_ENGINES 1
999 #endif
1000 
1001 //Number of decryption engines
1002 #if (DTLS_SUPPORT == ENABLED && TLS_MAX_VERSION >= TLS_VERSION_1_3)
1003  #define TLS_MAX_DECRYPTION_ENGINES 2
1004 #else
1005  #define TLS_MAX_DECRYPTION_ENGINES 1
1006 #endif
1007 
1008 //Bind TLS to a particular socket
1009 #define tlsSetSocket(context, socket) tlsSetSocketCallbacks(context, \
1010  (TlsSocketSendCallback) socketSend, (TlsSocketReceiveCallback) socketReceive, \
1011  (TlsSocketHandle) socket)
1012 
1013 //Minimum plaintext record length
1014 #define TLS_MIN_RECORD_LENGTH 512
1015 //Maximum plaintext record length
1016 #define TLS_MAX_RECORD_LENGTH 16384
1017 //Data overhead caused by record encryption
1018 #define TLS_MAX_RECORD_OVERHEAD 512
1019 //Size of client and server random values
1020 #define TLS_RANDOM_SIZE 32
1021 
1022 //TLS signature scheme definition
1023 #define TLS_SIGN_SCHEME(signAlgo, hashAlgo) \
1024  ((TlsSignatureScheme) (((hashAlgo) << 8) | (signAlgo)))
1025 
1026 //C++ guard
1027 #ifdef __cplusplus
1028 extern "C" {
1029 #endif
1030 
1031 
1032 /**
1033  * @brief TLS transport protocols
1034  **/
1035 
1036 typedef enum
1037 {
1043 
1044 
1045 /**
1046  * @brief TLS connection end
1047  **/
1048 
1049 typedef enum
1050 {
1054 
1055 
1056 /**
1057  * @brief Client authentication mode
1058  **/
1059 
1060 typedef enum
1061 {
1066 
1067 
1068 /**
1069  * @brief Early data status
1070  **/
1071 
1072 typedef enum
1073 {
1077 
1078 
1079 /**
1080  * @brief Flags used by read and write functions
1081  **/
1082 
1083 typedef enum
1084 {
1085  TLS_FLAG_PEEK = 0x0200,
1091  TLS_FLAG_DELAY = 0x8000
1093 
1094 
1095 //The TLS_FLAG_BREAK macro causes the read function to stop reading
1096 //data whenever the specified break character is encountered
1097 #define TLS_FLAG_BREAK(c) (TLS_FLAG_BREAK_CHAR | LSB(c))
1098 
1099 
1100 /**
1101  * @brief Content type
1102  **/
1103 
1104 typedef enum
1105 {
1113  TLS_TYPE_ACK = 26
1115 
1116 
1117 /**
1118  * @brief Handshake message type
1119  **/
1120 
1121 typedef enum
1122 {
1146  TLS_TYPE_MESSAGE_HASH = 254
1148 
1149 
1150 /**
1151  * @brief Alert level
1152  **/
1153 
1154 typedef enum
1155 {
1158 } TlsAlertLevel;
1159 
1160 
1161 /**
1162  * @brief Alert description
1163  **/
1164 
1165 typedef enum
1166 {
1205 
1206 
1207 /**
1208  * @brief Compression methods
1209  **/
1210 
1211 typedef enum
1212 {
1216 
1217 
1218 /**
1219  * @brief Key exchange methods
1220  **/
1221 
1222 typedef enum
1223 {
1253 
1254 
1255 /**
1256  * @brief Certificate formats
1257  **/
1258 
1259 typedef enum
1260 {
1266 
1267 
1268 /**
1269  * @brief Certificate types
1270  **/
1271 
1272 typedef enum
1273 {
1287  TLS_CERT_RSA_PSS_SIGN = 256, //For internal use only
1288  TLS_CERT_SM2_SIGN = 257, //For internal use only
1289  TLS_CERT_ED25519_SIGN = 258, //For internal use only
1290  TLS_CERT_ED448_SIGN = 259, //For internal use only
1291  TLS_CERT_MLDSA44_SIGN = 260, //For internal use only
1292  TLS_CERT_MLDSA65_SIGN = 261, //For internal use only
1293  TLS_CERT_MLDSA87_SIGN = 262 //For internal use only
1295 
1296 
1297 /**
1298  * @brief Hash algorithms
1299  **/
1300 
1301 typedef enum
1302 {
1311  TLS_HASH_ALGO_SM3 = 256 //For internal use only
1313 
1314 
1315 /**
1316  * @brief Signature algorithms
1317  **/
1318 
1319 typedef enum
1320 {
1330 
1331 
1332 /**
1333  * @brief Signature schemes
1334  **/
1335 
1336 typedef enum
1337 {
1385 
1386 
1387 /**
1388  * @brief TLS extension types
1389  **/
1390 
1391 typedef enum
1392 {
1450 
1451 
1452 /**
1453  * @brief Name types
1454  **/
1455 
1456 typedef enum
1457 {
1460 
1461 
1462 /**
1463  * @brief Maximum fragment length
1464  **/
1465 
1466 typedef enum
1467 {
1473 
1474 
1475 /**
1476  * @brief CA root key identifier type
1477  **/
1478 
1479 typedef enum
1480 {
1486 
1487 
1488 /**
1489  * @brief Named groups
1490  **/
1491 
1492 typedef enum
1493 {
1495  TLS_GROUP_SECT163K1 = 1, //RFC 4492
1496  TLS_GROUP_SECT163R1 = 2, //RFC 4492
1497  TLS_GROUP_SECT163R2 = 3, //RFC 4492
1498  TLS_GROUP_SECT193R1 = 4, //RFC 4492
1499  TLS_GROUP_SECT193R2 = 5, //RFC 4492
1500  TLS_GROUP_SECT233K1 = 6, //RFC 4492
1501  TLS_GROUP_SECT233R1 = 7, //RFC 4492
1502  TLS_GROUP_SECT239K1 = 8, //RFC 4492
1503  TLS_GROUP_SECT283K1 = 9, //RFC 4492
1504  TLS_GROUP_SECT283R1 = 10, //RFC 4492
1505  TLS_GROUP_SECT409K1 = 11, //RFC 4492
1506  TLS_GROUP_SECT409R1 = 12, //RFC 4492
1507  TLS_GROUP_SECT571K1 = 13, //RFC 4492
1508  TLS_GROUP_SECT571R1 = 14, //RFC 4492
1509  TLS_GROUP_SECP160K1 = 15, //RFC 4492
1510  TLS_GROUP_SECP160R1 = 16, //RFC 4492
1511  TLS_GROUP_SECP160R2 = 17, //RFC 4492
1512  TLS_GROUP_SECP192K1 = 18, //RFC 4492
1513  TLS_GROUP_SECP192R1 = 19, //RFC 4492
1514  TLS_GROUP_SECP224K1 = 20, //RFC 4492
1515  TLS_GROUP_SECP224R1 = 21, //RFC 4492
1516  TLS_GROUP_SECP256K1 = 22, //RFC 4492
1517  TLS_GROUP_SECP256R1 = 23, //RFC 4492
1518  TLS_GROUP_SECP384R1 = 24, //RFC 4492
1519  TLS_GROUP_SECP521R1 = 25, //RFC 4492
1520  TLS_GROUP_BRAINPOOLP256R1 = 26, //RFC 7027
1521  TLS_GROUP_BRAINPOOLP384R1 = 27, //RFC 7027
1522  TLS_GROUP_BRAINPOOLP512R1 = 28, //RFC 7027
1523  TLS_GROUP_X25519 = 29, //RFC 8422
1524  TLS_GROUP_X448 = 30, //RFC 8422
1528  TLS_GROUP_GC256A = 34, //RFC 9189
1529  TLS_GROUP_GC256B = 35, //RFC 9189
1530  TLS_GROUP_GC256C = 36, //RFC 9189
1531  TLS_GROUP_GC256D = 37, //RFC 9189
1532  TLS_GROUP_GC512A = 38, //RFC 9189
1533  TLS_GROUP_GC512B = 39, //RFC 9189
1534  TLS_GROUP_GC512C = 40, //RFC 9189
1535  TLS_GROUP_CURVE_SM2 = 41, //RFC 8998
1536  TLS_GROUP_FFDHE2048 = 256, //RFC 7919
1537  TLS_GROUP_FFDHE3072 = 257, //RFC 7919
1538  TLS_GROUP_FFDHE4096 = 258, //RFC 7919
1539  TLS_GROUP_FFDHE6144 = 259, //RFC 7919
1540  TLS_GROUP_FFDHE8192 = 260, //RFC 7919
1541  TLS_GROUP_FFDHE_MAX = 511, //RFC 7919
1542  TLS_GROUP_MLKEM512 = 512, //Draft
1543  TLS_GROUP_MLKEM768 = 513, //Draft
1544  TLS_GROUP_MLKEM1024 = 514, //Draft
1545  TLS_GROUP_SECP256R1_MLKEM768 = 4587, //RFC 10024
1546  TLS_GROUP_X25519_MLKEM768 = 4588, //RFC 10024
1547  TLS_GROUP_SECP384R1_MLKEM1024 = 4589, //RFC 10024
1550  TLS_GROUP_EXPLICIT_CHAR2_CURVE = 65282 //RFC 4492
1552 
1553 
1554 /**
1555  * @brief EC point formats
1556  **/
1557 
1558 typedef enum
1559 {
1564 
1565 
1566 /**
1567  * @brief EC curve types
1568  **/
1569 
1570 typedef enum
1571 {
1576 
1577 
1578 /**
1579  * @brief TLS FSM states
1580  **/
1581 
1582 typedef enum
1583 {
1621  TLS_STATE_CLOSED = 37
1623 
1624 
1625 /**
1626  * @brief Encryption level
1627  **/
1628 
1629 typedef enum
1630 {
1636 
1637 
1638 //CC-RX, CodeWarrior or Win32 compiler?
1639 #if defined(__CCRX__)
1640  #pragma pack
1641 #elif defined(__CWCC__) || defined(_WIN32)
1642  #pragma pack(push, 1)
1643 #endif
1644 
1645 
1646 /**
1647  * @brief Sequence number
1648  **/
1649 
1651 {
1652  uint8_t b[8];
1654 
1655 
1656 /**
1657  * @brief Cipher suites
1658  **/
1659 
1660 typedef __packed_struct
1661 {
1662  uint16_t length; //0-1
1663  uint16_t value[]; //2
1665 
1666 
1667 /**
1668  * @brief Compression methods
1669  **/
1670 
1671 typedef __packed_struct
1672 {
1673  uint8_t length; //0
1674  uint8_t value[]; //1
1676 
1677 
1678 /**
1679  * @brief List of signature schemes
1680  **/
1681 
1682 typedef __packed_struct
1683 {
1684  uint16_t length; //0-1
1685  uint16_t value[]; //2
1687 
1688 
1689 /**
1690  * @brief List of certificates
1691  **/
1692 
1693 typedef __packed_struct
1694 {
1695  uint8_t length[3]; //0-2
1696  uint8_t value[]; //3
1698 
1699 
1700 /**
1701  * @brief List of certificate authorities
1702  **/
1703 
1704 typedef __packed_struct
1705 {
1706  uint16_t length; //0-1
1707  uint8_t value[]; //2
1709 
1710 
1711 /**
1712  * @brief Trusted authority
1713  **/
1714 
1715 typedef __packed_struct
1716 {
1717  uint8_t type; //0
1718  uint8_t identifier[]; //1
1720 
1721 
1722 /**
1723  * @brief List of trusted authorities
1724  **/
1725 
1726 typedef __packed_struct
1727 {
1728  uint16_t length; //0-1
1729  uint8_t value[]; //2
1731 
1732 
1733 /**
1734  * @brief TLS extension
1735  **/
1736 
1737 typedef __packed_struct
1738 {
1739  uint16_t type; //0-1
1740  uint16_t length; //2-3
1741  uint8_t value[]; //4
1743 
1744 
1745 /**
1746  * @brief List of TLS extensions
1747  **/
1748 
1749 typedef __packed_struct
1750 {
1751  uint16_t length; //0-1
1752  uint8_t value[]; //2
1754 
1755 
1756 /**
1757  * @brief List of supported versions
1758  **/
1759 
1760 typedef __packed_struct
1761 {
1762  uint8_t length; //0
1763  uint16_t value[]; //1
1765 
1766 
1767 /**
1768  * @brief Server name
1769  **/
1770 
1771 typedef __packed_struct
1772 {
1773  uint8_t type; //0
1774  uint16_t length; //1-2
1777 
1778 
1779 /**
1780  * @brief List of server names
1781  **/
1782 
1783 typedef __packed_struct
1784 {
1785  uint16_t length; //0-1
1786  uint8_t value[]; //2
1788 
1789 
1790 /**
1791  * @brief Protocol name
1792  **/
1793 
1794 typedef __packed_struct
1795 {
1796  uint8_t length; //0
1797  char_t value[]; //1
1799 
1800 
1801 /**
1802  * @brief List of protocol names
1803  **/
1804 
1805 typedef __packed_struct
1806 {
1807  uint16_t length; //0-1
1808  uint8_t value[]; //2
1810 
1811 
1812 /**
1813  * @brief List of supported groups
1814  **/
1815 
1816 typedef __packed_struct
1817 {
1818  uint16_t length; //0-1
1819  uint16_t value[]; //2
1821 
1822 
1823 /**
1824  * @brief List of supported EC point formats
1825  **/
1826 
1827 typedef __packed_struct
1828 {
1829  uint8_t length; //0
1830  uint8_t value[]; //1
1832 
1833 
1834 /**
1835  * @brief List of supported certificate types
1836  **/
1837 
1838 typedef __packed_struct
1839 {
1840  uint8_t length; //0
1841  uint8_t value[]; //1
1843 
1844 
1845 /**
1846  * @brief Renegotiated connection
1847  **/
1848 
1849 typedef __packed_struct
1850 {
1851  uint8_t length; //0
1852  uint8_t value[]; //1
1854 
1855 
1856 /**
1857  * @brief PSK identity
1858  **/
1859 
1860 typedef __packed_struct
1861 {
1862  uint16_t length; //0-1
1863  uint8_t value[]; //2
1865 
1866 
1867 /**
1868  * @brief PSK identity hint
1869  **/
1870 
1871 typedef __packed_struct
1872 {
1873  uint16_t length; //0-1
1874  uint8_t value[]; //2
1876 
1877 
1878 /**
1879  * @brief Digitally-signed element (TLS 1.0 and TLS 1.1)
1880  **/
1881 
1882 typedef __packed_struct
1883 {
1884  uint16_t length; //0-1
1885  uint8_t value[]; //2
1887 
1888 
1889 /**
1890  * @brief Digitally-signed element (TLS 1.2)
1891  **/
1892 
1893 typedef __packed_struct
1894 {
1895  uint16_t algorithm; //0-1
1896  uint16_t length; //2-3
1897  uint8_t value[]; //4
1899 
1900 
1901 /**
1902  * @brief TLS record
1903  **/
1904 
1905 typedef __packed_struct
1906 {
1907  uint8_t type; //0
1908  uint16_t version; //1-2
1909  uint16_t length; //3-4
1910  uint8_t data[]; //5
1912 
1913 
1914 /**
1915  * @brief TLS handshake message
1916  **/
1917 
1918 typedef __packed_struct
1919 {
1920  uint8_t msgType; //0
1921  uint8_t length[3]; //1-3
1922  uint8_t data[]; //4
1924 
1925 
1926 /**
1927  * @brief HelloRequest message
1928  **/
1929 
1930 typedef void TlsHelloRequest;
1931 
1932 
1933 /**
1934  * @brief ClientHello message
1935  **/
1936 
1937 typedef __packed_struct
1938 {
1939  uint16_t clientVersion; //0-1
1940  uint8_t random[32]; //2-33
1941  uint8_t sessionIdLen; //34
1942  uint8_t sessionId[]; //35
1944 
1945 
1946 /**
1947  * @brief ServerHello message
1948  **/
1949 
1950 typedef __packed_struct
1951 {
1952  uint16_t serverVersion; //0-1
1953  uint8_t random[32]; //2-33
1954  uint8_t sessionIdLen; //34
1955  uint8_t sessionId[]; //35
1957 
1958 
1959 /**
1960  * @brief Certificate message
1961  **/
1962 
1963 typedef void TlsCertificate;
1964 
1965 
1966 /**
1967  * @brief ServerKeyExchange message
1968  **/
1969 
1971 
1972 
1973 /**
1974  * @brief CertificateRequest message
1975  **/
1976 
1977 typedef __packed_struct
1978 {
1979  uint8_t certificateTypesLen; //0
1980  uint8_t certificateTypes[]; //1
1982 
1983 
1984 /**
1985  * @brief ServerHelloDone message
1986  **/
1987 
1988 typedef void TlsServerHelloDone;
1989 
1990 
1991 /**
1992  * @brief ClientKeyExchange message
1993  **/
1994 
1996 
1997 
1998 /**
1999  * @brief CertificateVerify message
2000  **/
2001 
2003 
2004 
2005 /**
2006  * @brief NewSessionTicket message
2007  **/
2008 
2009 typedef __packed_struct
2010 {
2011  uint32_t ticketLifetimeHint; //0-3
2012  uint16_t ticketLen; //4-5
2013  uint8_t ticket[]; //6
2015 
2016 
2017 /**
2018  * @brief Finished message
2019  **/
2020 
2021 typedef void TlsFinished;
2022 
2023 
2024 /**
2025  * @brief ChangeCipherSpec message
2026  **/
2027 
2028 typedef __packed_struct
2029 {
2030  uint8_t type; //0
2032 
2033 
2034 /**
2035  * @brief Alert message
2036  **/
2037 
2038 typedef __packed_struct
2039 {
2040  uint8_t level; //0
2041  uint8_t description; //1
2043 
2044 
2045 /**
2046  * @brief Session state information
2047  **/
2048 
2049 typedef __packed_struct
2050 {
2051  uint16_t version; ///<Protocol version
2052  uint16_t cipherSuite; ///<Cipher suite identifier
2053  uint8_t secret[TLS_MASTER_SECRET_SIZE]; ///<Master secret
2054  systime_t ticketTimestamp; ///<Timestamp to manage ticket lifetime
2055  uint32_t ticketLifetime; ///<Lifetime of the ticket
2056 #if (TLS_EXT_MASTER_SECRET_SUPPORT == ENABLED)
2057  bool_t extendedMasterSecret; ///<Extended master secret computation
2058 #endif
2060 
2061 
2062 //CC-RX, CodeWarrior or Win32 compiler?
2063 #if defined(__CCRX__)
2064  #pragma unpack
2065 #elif defined(__CWCC__) || defined(_WIN32)
2066  #pragma pack(pop)
2067 #endif
2068 
2069 
2070 /**
2071  * @brief Socket handle
2072  **/
2073 
2074 typedef void *TlsSocketHandle;
2075 
2076 
2077 /**
2078  * @brief TLS state change callback
2079  **/
2080 
2081 typedef void (*TlsStateChangeCallback)(TlsContext *context, TlsState state);
2082 
2083 
2084 /**
2085  * @brief Socket send callback function
2086  **/
2087 
2089  const void *data, size_t length, size_t *written, uint_t flags);
2090 
2091 
2092 /**
2093  * @brief Socket receive callback function
2094  **/
2095 
2097  void *data, size_t size, size_t *received, uint_t flags);
2098 
2099 
2100 /**
2101  * @brief ALPN callback function
2102  **/
2103 
2104 typedef error_t (*TlsAlpnCallback)(TlsContext *context,
2105  const char_t *selectedProtocol);
2106 
2107 
2108 /**
2109  * @brief Pre-shared key callback function
2110  **/
2111 
2112 typedef error_t (*TlsPskCallback)(TlsContext *context,
2113  const uint8_t *pskIdentity, size_t pskIdentityLen);
2114 
2115 
2116 /**
2117  * @brief Certificate verification callback function
2118  **/
2119 
2121  const X509CertInfo *certInfo, uint_t pathLen, void *param);
2122 
2123 
2124 /**
2125  * @brief Raw public key verification callback function
2126  **/
2127 
2129  const uint8_t *rawPublicKey, size_t rawPublicKeyLen);
2130 
2131 
2132 /**
2133  * @brief Ticket encryption callback function
2134  **/
2135 
2137  const uint8_t *plaintext, size_t plaintextLen, uint8_t *ciphertext,
2138  size_t *ciphertextLen, void *param);
2139 
2140 
2141 /**
2142  * @brief Ticket decryption callback function
2143  **/
2144 
2146  const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *plaintext,
2147  size_t *plaintextLen, void *param);
2148 
2149 
2150 /**
2151  * @brief ECDH key agreement callback function
2152  **/
2153 
2154 typedef error_t (*TlsEcdhCallback)(TlsContext *context);
2155 
2156 
2157 /**
2158  * @brief ECDSA signature generation callback function
2159  **/
2160 
2162  const uint8_t *digest, size_t digestLen, EcdsaSignature *signature);
2163 
2164 
2165 /**
2166  * @brief ECDSA signature verification callback function
2167  **/
2168 
2170  const uint8_t *digest, size_t digestLen, EcdsaSignature *signature);
2171 
2172 
2173 /**
2174  * @brief Key logging callback function (for debugging purpose only)
2175  **/
2176 
2177 typedef void (*TlsKeyLogCallback)(TlsContext *context, const char_t *key);
2178 
2179 
2180 /**
2181  * @brief Encryption key update callback function
2182  **/
2183 
2185  TlsEncryptionLevel level, const uint8_t *txKey, const uint8_t *rxKey,
2186  size_t keyLen, void *param);
2187 
2188 
2189 /**
2190  * @brief Handshake message sending callback function
2191  **/
2192 
2194  TlsEncryptionLevel level, const uint8_t *data, size_t length, void *param);
2195 
2196 
2197 /**
2198  * @brief Alert message sending callback function
2199  **/
2200 
2202  uint8_t description, void *param);
2203 
2204 
2205 /**
2206  * @brief QUIC callback functions
2207  **/
2208 
2209 typedef struct
2210 {
2215 
2216 
2217 /**
2218  * @brief Structure describing a cipher suite
2219  **/
2220 
2221 typedef struct
2222 {
2223  uint16_t identifier;
2224  const char_t *name;
2230  uint8_t macKeyLen;
2231  uint8_t encKeyLen;
2232  uint8_t fixedIvLen;
2233  uint8_t recordIvLen;
2234  uint8_t authTagLen;
2235  uint8_t verifyDataLen;
2237 
2238 
2239 /**
2240  * @brief TLS session state
2241  **/
2242 
2243 typedef struct
2244 {
2245  uint16_t version; ///<TLS protocol version
2246  uint16_t cipherSuite; ///<Cipher suite identifier
2247  systime_t timestamp; ///<Time stamp to manage entry lifetime
2248  uint8_t secret[TLS_MASTER_SECRET_SIZE]; ///<Master secret (TLS 1.2) or ticket PSK (TLS 1.3)
2249 #if (TLS_MAX_VERSION >= TLS_VERSION_1_0 && TLS_MIN_VERSION <= TLS_VERSION_1_2)
2250  uint8_t sessionId[32]; ///<Session identifier
2251  size_t sessionIdLen; ///<Length of the session identifier
2252  bool_t extendedMasterSecret; ///<Extended master secret computation
2253 #endif
2254  uint8_t *ticket; ///<Session ticket
2255  size_t ticketLen; ///<Length of the session ticket
2256 #if (TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3)
2257  systime_t ticketTimestamp; ///<Timestamp to manage ticket lifetime
2258  uint32_t ticketLifetime; ///<Lifetime of the ticket
2259  uint32_t ticketAgeAdd; ///<Random value used to obscure the age of the ticket
2260  TlsHashAlgo ticketHashAlgo; ///<Hash algorithm associated with the ticket
2261  char_t *ticketAlpn; ///<ALPN protocol associated with the ticket
2262  uint32_t maxEarlyDataSize; ///<Maximum amount of 0-RTT data that the client is allowed to send
2263 #endif
2264 #if (TLS_SNI_SUPPORT == ENABLED)
2265  char_t *serverName; ///<ServerName extension
2266 #endif
2267 } TlsSessionState;
2268 
2269 
2270 /**
2271  * @brief Session cache
2272  **/
2273 
2274 typedef struct
2275 {
2276  OsMutex mutex; ///<Mutex preventing simultaneous access to the cache
2277  uint_t size; ///<Maximum number of entries
2278  TlsSessionState sessions[]; ///<Cache entries
2279 } TlsCache;
2280 
2281 
2282 /**
2283  * @brief Certificate descriptor
2284  **/
2285 
2286 typedef struct
2287 {
2288  const char_t *certChain; ///<End entity certificate chain (PEM format)
2289  size_t certChainLen; ///<Length of the certificate chain
2290  const char_t *privateKey; ///<Private key (PEM format)
2291  size_t privateKeyLen; ///<Length of the private key
2292  char_t password[TLS_MAX_PASSWORD_LEN + 1]; ///<Password used to decrypt the private key
2293  TlsCertificateType type; ///<End entity certificate type
2294  TlsSignatureScheme signScheme; ///<Signature scheme used to sign the end entity certificate
2295  TlsNamedGroup namedCurve; ///<Named curve used to generate the EC public key
2296 } TlsCertDesc;
2297 
2298 
2299 /**
2300  * @brief Hello extensions
2301  **/
2302 
2303 typedef struct
2304 {
2305  const TlsSupportedVersionList *supportedVersionList; ///<SupportedVersions extension (ClientHello)
2306  const TlsExtension *selectedVersion; ///<SupportedVersions extension (ServerHello)
2307  const TlsServerNameList *serverNameList; ///<ServerName extension
2308  const TlsSupportedGroupList *supportedGroupList; ///<SupportedGroups extension
2309  const TlsEcPointFormatList *ecPointFormatList; ///<EcPointFormats extension
2310  const TlsSignSchemeList *signAlgoList; ///<SignatureAlgorithms extension
2311  const TlsSignSchemeList *certSignAlgoList; ///<SignatureAlgorithmsCert extension
2312 #if (TLS_MAX_FRAG_LEN_SUPPORT == ENABLED)
2313  const TlsExtension *maxFragLen; ///<MaxFragmentLength extension
2314 #endif
2315 #if (TLS_RECORD_SIZE_LIMIT_SUPPORT == ENABLED)
2316  const TlsExtension *recordSizeLimit; ///<RecordSizeLimit extension
2317 #endif
2318 #if (TLS_ALPN_SUPPORT == ENABLED)
2319  const TlsProtocolNameList *protocolNameList; ///<ALPN extension
2320 #endif
2321 #if (TLS_RAW_PUBLIC_KEY_SUPPORT == ENABLED)
2322  const TlsCertTypeList *clientCertTypeList; ///<ClientCertType extension
2324  const TlsCertTypeList *serverCertTypeList; ///<ServerCertType extension
2326 #endif
2327 #if (TLS_ENCRYPT_THEN_MAC_SUPPORT == ENABLED)
2328  const TlsExtension *encryptThenMac; ///<EncryptThenMac extension
2329 #endif
2330 #if (TLS_EXT_MASTER_SECRET_SUPPORT == ENABLED)
2331  const TlsExtension *extendedMasterSecret; ///<ExtendedMasterSecret extension
2332 #endif
2333 #if (TLS_TICKET_SUPPORT == ENABLED)
2334  const TlsExtension *sessionTicket; ///<SessionTicket extension
2335 #endif
2336 #if (TLS_SECURE_RENEGOTIATION_SUPPORT == ENABLED)
2337  const TlsRenegoInfo *renegoInfo; ///<RenegotiationInfo extension
2338 #endif
2339 #if (TLS_QUIC_SUPPORT == ENABLED)
2340  const TlsExtension *quicTransportParams; ///<QUIC transport parameters extension
2341 #endif
2342 #if (TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3)
2343  const Tls13Cookie *cookie; ///<Cookie extension
2344  const TlsCertAuthorities *certAuthorities; ///<CertificateAuthorities extension
2345  const Tls13KeyShareList *keyShareList; ///<KeyShare extension (ClientHello)
2346  const TlsExtension *selectedGroup; ///<KeyShare extension (HelloRetryRequest)
2347  const Tls13KeyShareEntry *serverShare; ///<KeyShare extension (ServerHello)
2348  const Tls13PskKeModeList *pskKeModeList; ///<PskKeyExchangeModes extension
2349  const Tls13PskIdentityList *identityList; ///<PreSharedKey extension (ClientHello)
2351  const TlsExtension *selectedIdentity; ///<PreSharedKey extension (ServerHello)
2352  const TlsExtension *earlyDataIndication; ///<EarlyData extension
2353 #endif
2355 
2356 
2357 /**
2358  * @brief Encryption engine
2359  **/
2360 
2362 {
2363  bool_t active; ///<Operational state of the encryption engine
2364  systime_t timestamp; ///<Timestamp to manage lifetime
2365  systime_t lifetime; ///<Lifetime of the encryption engine
2366  uint16_t version; ///<Negotiated TLS version
2367  uint8_t macKey[48]; ///<MAC key
2368  size_t macKeyLen; ///<Length of the MAC key
2369  uint8_t encKey[48]; ///<Encryption key
2370  size_t encKeyLen; ///<Length of the encryption key
2371  uint8_t iv[48]; ///<Initialization vector
2372  size_t fixedIvLen; ///<Length of the fixed part of the IV
2373  size_t recordIvLen; ///<Length of the IV
2374  size_t authTagLen; ///<Length of the authentication tag
2375  const CipherAlgo *cipherAlgo; ///<Cipher algorithm
2376  void *cipherContext; ///<Cipher context
2377  CipherMode cipherMode; ///<Cipher mode of operation
2378  const HashAlgo *hashAlgo; ///<Hash algorithm for MAC operations
2379  HmacContext *hmacContext; ///<HMAC context
2380 #if (TLS_GCM_CIPHER_SUPPORT == ENABLED)
2381  GcmContext *gcmContext; ///<GCM context
2382 #endif
2383  TlsSequenceNumber seqNum; ///<TLS sequence number
2384 #if (DTLS_SUPPORT == ENABLED)
2385  uint16_t epoch; ///<Counter value incremented on every cipher state change
2386  DtlsSequenceNumber dtlsSeqNum; ///<Record sequence number
2387 #endif
2388 #if (DTLS_SUPPORT == ENABLED && DTLS_REPLAY_DETECTION_SUPPORT == ENABLED)
2389  uint32_t replayWindow[(DTLS_REPLAY_WINDOW_SIZE + 31) / 32]; ///<Replay window
2390 #endif
2391 #if (DTLS_SUPPORT == ENABLED && TLS_MAX_VERSION >= TLS_VERSION_1_3)
2392  uint8_t snKey[32]; ///<Sequence number encryption key
2393  void *snCipherContext; ///<Sequence number encryption context
2394  Dtls13RetransmitState retransmitState; ///<Retransmission state
2395 #endif
2396 #if (TLS_QUIC_SUPPORT == ENABLED)
2397  TlsEncryptionLevel level; ///<Encryption level
2398 #endif
2399 #if (TLS_RECORD_SIZE_LIMIT_SUPPORT == ENABLED)
2400  size_t recordSizeLimit; ///<Maximum size of record in octets
2401 #endif
2402 #if (TLS_ENCRYPT_THEN_MAC_SUPPORT == ENABLED)
2403  bool_t encryptThenMac; ///<Encrypt-then-MAC construction
2404 #endif
2405  TLS_PRIVATE_ENCRYPTION_ENGINE ///<Application specific context
2406 };
2407 
2408 
2409 /**
2410  * @brief TLS context
2411  *
2412  * An opaque data structure that represents a TLS connection
2413  *
2414  **/
2415 
2417 {
2418  TlsState state; ///<TLS handshake finite state machine
2419  TlsTransportProtocol transportProtocol; ///<Transport protocol (stream or datagram)
2420  TlsConnectionEnd entity; ///<Client or server operation
2421 
2422  TlsStateChangeCallback stateChangeCallback; ///<TLS state change callback function
2423 
2424  TlsSocketHandle socketHandle; ///<Socket handle
2425  TlsSocketSendCallback socketSendCallback; ///<Socket send callback function
2426  TlsSocketReceiveCallback socketReceiveCallback; ///<Socket receive callback function
2427 
2428  const PrngAlgo *prngAlgo; ///<Pseudo-random number generator to be used
2429  void *prngContext; ///<Pseudo-random number generator context
2430 
2431  const uint16_t *cipherSuites; ///<List of supported cipher suites
2432  uint_t numCipherSuites; ///<Number of cipher suites in the list
2433 
2434  const uint16_t *supportedGroups; ///<List of supported named groups
2435  uint_t numSupportedGroups; ///<Number of named groups in the list
2436 
2437  char_t *serverName; ///<Fully qualified DNS hostname of the server
2438 
2439 #if (TLS_ECC_CALLBACK_SUPPORT == ENABLED)
2443 #endif
2444 
2445  TlsCertDesc certs[TLS_MAX_CERTIFICATES]; ///<End entity certificates (PEM format)
2446  const char_t *trustedCaList; ///<Trusted CA list (PEM format)
2447  size_t trustedCaListLen; ///<Total length of the trusted CA list
2448  TlsCertVerifyCallback certVerifyCallback; ///<Certificate verification callback function
2449  void *certVerifyParam; ///<Opaque pointer passed to the certificate verification callback
2450  TlsCertDesc *cert; ///<Pointer to the currently selected certificate
2451 
2452  TlsCache *cache; ///<TLS session cache
2453  uint8_t sessionId[32]; ///<Session identifier
2454  size_t sessionIdLen; ///<Length of the session identifier
2455 
2456  uint16_t clientVersion; ///<Latest version supported by the client
2457  uint16_t version; ///<Negotiated TLS version
2458  uint16_t versionMin; ///<Minimum version accepted by the implementation
2459  uint16_t versionMax; ///<Maximum version accepted by the implementation
2460 
2461  uint8_t *cookie; ///<Cookie
2462  size_t cookieLen; ///<Length of the cookie
2463  bool_t wrongCookie; ///<Invalid cookie
2464 
2465  uint8_t *ticket; ///<Session ticket
2466  size_t ticketLen; ///<Length of the session ticket
2467  systime_t ticketTimestamp; ///<Timestamp to manage ticket lifetime
2468  uint32_t ticketLifetime; ///<Lifetime of the ticket
2469 
2470  uint_t cipherSuiteTypes; ///<Types of cipher suites proposed by the client
2471  TlsCipherSuiteInfo cipherSuite; ///<Negotiated cipher suite
2472  TlsKeyExchMethod keyExchMethod; ///<Key exchange method
2473  TlsSignatureScheme signScheme; ///<Signature scheme to be used
2474  uint16_t namedGroup; ///<ECDHE or FFDHE named group
2475  bool_t wrongKeyShare; ///<Invalid key share
2476 
2477  TlsCertificateType peerCertType; ///<Peer's certificate type
2478  TlsClientAuthMode clientAuthMode; ///<Client authentication mode
2479  bool_t clientCertRequested; ///<This flag tells whether the client certificate is requested
2480 
2481  bool_t resume; ///<The connection is established by resuming a session
2482  bool_t fatalAlertSent; ///<A fatal alert message has been sent
2483  bool_t fatalAlertReceived; ///<A fatal alert message has been received from the peer
2484  bool_t closeNotifySent; ///<A closure alert has been sent
2485  bool_t closeNotifyReceived; ///<A closure alert has been received from the peer
2486 
2487  uint8_t *txBuffer; ///<TX buffer
2488  size_t txBufferSize; ///<TX buffer size
2489  size_t txBufferMaxLen; ///<Maximum number of plaintext data the TX buffer can hold
2490  TlsContentType txBufferType; ///<Type of data that resides in the TX buffer
2491  size_t txBufferLen; ///<Number of bytes that are pending to be sent
2492  size_t txBufferPos; ///<Current position in TX buffer
2493  size_t txRecordLen; ///<Length of the TLS record
2494  size_t txRecordPos; ///<Current position in the TLS record
2495 
2496  uint8_t *rxBuffer; ///<RX buffer
2497  size_t rxBufferSize; ///<RX buffer size
2498  size_t rxBufferMaxLen; ///<Maximum number of plaintext data the RX buffer can hold
2499  TlsContentType rxBufferType; ///<Type of data that resides in the RX buffer
2500  size_t rxBufferLen; ///<Number of bytes available for reading
2501  size_t rxBufferPos; ///<Current position in RX buffer
2502  size_t rxRecordLen; ///<Length of the TLS record
2503  size_t rxRecordPos; ///<Current position in the TLS record
2504 
2505  uint8_t clientRandom[TLS_RANDOM_SIZE]; ///<Client random value
2506  uint8_t serverRandom[TLS_RANDOM_SIZE]; ///<Server random value
2507  uint8_t premasterSecret[TLS_PREMASTER_SECRET_SIZE]; ///<Premaster secret
2508  size_t premasterSecretLen; ///<Length of the premaster secret
2509  uint8_t clientVerifyData[64]; ///<Client verify data
2510  size_t clientVerifyDataLen; ///<Length of the client verify data
2511  uint8_t serverVerifyData[64]; ///<Server verify data
2512  size_t serverVerifyDataLen; ///<Length of the server verify data
2513 
2516 
2517 #if (TLS_MAX_VERSION >= TLS_VERSION_1_0 && TLS_MIN_VERSION <= TLS_VERSION_1_0)
2518  size_t txLastRecordLen; ///<Length of the previous TLS record
2519 #endif
2520 
2521 #if (TLS_MAX_VERSION >= TLS_VERSION_1_0 && TLS_MIN_VERSION <= TLS_VERSION_1_1)
2522  Md5Context *transcriptMd5Context; ///<MD5 context used to compute verify data
2523 #endif
2524 
2525 #if (TLS_MAX_VERSION >= TLS_VERSION_1_0 && TLS_MIN_VERSION <= TLS_VERSION_1_2)
2526  uint8_t masterSecret[TLS_MASTER_SECRET_SIZE]; ///<Master secret
2527  uint8_t keyBlock[192]; ///<Key material
2528  HmacContext hmacContext; ///<HMAC context
2529  Sha1Context *transcriptSha1Context; ///<SHA-1 context used to compute verify data
2530 #endif
2531 
2532 #if (TLS_MAX_VERSION >= TLS_VERSION_1_2 && TLS_MIN_VERSION <= TLS_VERSION_1_3)
2533  const uint16_t *supportedSignAlgos; ///<List of supported signature algorithms
2534  uint_t numSupportedSignAlgos; ///<Number of signature algorithms in the list
2535 
2536  HashContext *transcriptHashContext; ///<Hash context used to compute verify data
2537 #endif
2538 
2539 #if (TLS_MAX_VERSION >= TLS_VERSION_1_3 && TLS_MIN_VERSION <= TLS_VERSION_1_3)
2540  uint16_t preferredGroup; ///<Preferred ECDHE or FFDHE named group
2541  systime_t clientHelloTimestamp; ///<Time at which the ClientHello message was sent
2542  bool_t updatedClientHelloReceived; ///<An updated ClientHello message has been received
2543  uint8_t *certRequestContext; ///<Certificate request context
2544  size_t certRequestContextLen; ///<Length of the certificate request context
2545  int_t selectedIdentity; ///<Selected PSK identity
2546  bool_t pskKeModeSupported; ///<PSK key establishment supported by the client
2547 
2556 
2557  uint_t newSessionTicketCount; ///<Number of NewSessionTicket messages that have been sent
2558 
2559  uint8_t ticketPsk[TLS_MAX_HKDF_DIGEST_SIZE]; ///<PSK associated with the ticket
2560  size_t ticketPskLen; ///<Length of the PSK associated with the ticket
2561  uint32_t ticketAgeAdd; ///<Random value used to obscure the age of the ticket
2562  uint32_t ticketNonce; ///<A per-ticket value that is unique across all tickets issued
2563  uint16_t ticketCipherSuite; ///<Cipher suite associated with the ticket
2564  TlsHashAlgo ticketHashAlgo; ///<Hash algorithm associated with the ticket
2565  char_t *ticketAlpn; ///<ALPN protocol associated with the ticket
2566 
2567  size_t maxEarlyDataSize; ///<Maximum amount of 0-RTT data that the client is allowed to send
2568  size_t earlyDataLen; ///<Total amount of 0-RTT data that have been sent by the client
2569  bool_t earlyDataEnabled; ///<EarlyData is enabled
2570  bool_t earlyDataRejected; ///<The 0-RTT data have been rejected by the server
2571  bool_t earlyDataExtReceived; ///<The EarlyData extension has been received
2572  TlsSequenceNumber earlyDataSeqNum; ///<Early data sequence number
2573 #endif
2574 
2575 #if (TLS_DH_SUPPORT == ENABLED)
2576  DhContext dhContext; ///<Diffie-Hellman context
2577 #endif
2578 
2579 #if (TLS_ECDH_SUPPORT == ENABLED || TLS_HYBRID_SUPPORT == ENABLED)
2580  EcdhContext ecdhContext; ///<ECDH context
2581  bool_t ecPointFormatsExtReceived; ///<The EcPointFormats extension has been received
2582 #endif
2583 
2584 #if (TLS_MLKEM_SUPPORT == ENABLED || TLS_HYBRID_SUPPORT == ENABLED)
2585  KemContext kemContext; ///<KEM context
2586 #endif
2587 
2588 #if (TLS_RSA_SUPPORT == ENABLED)
2589  RsaPublicKey peerRsaPublicKey; ///<Peer's RSA public key
2590 #endif
2591 
2592 #if (TLS_DSA_SIGN_SUPPORT == ENABLED)
2593  DsaPublicKey peerDsaPublicKey; ///<Peer's DSA public key
2594 #endif
2595 
2596 #if (TLS_ECDSA_SIGN_SUPPORT == ENABLED || TLS_SM2_SIGN_SUPPORT == ENABLED)
2597  EcPublicKey peerEcPublicKey; ///<Peer's EC public key
2598 #endif
2599 
2600 #if (TLS_ED25519_SIGN_SUPPORT == ENABLED || TLS_ED448_SIGN_SUPPORT == ENABLED)
2601  EddsaPublicKey peerEddsaPublicKey; ///<Peer's EdDSA public key
2602 #endif
2603 
2604 #if (TLS_MLDSA44_SIGN_SUPPORT == ENABLED || TLS_MLDSA65_SIGN_SUPPORT == ENABLED || \
2605  TLS_MLDSA87_SIGN_SUPPORT == ENABLED)
2606  MldsaPublicKey peerMldsaPublicKey; ///<Peer's ML-DSA public key
2607 #endif
2608 
2609 #if (TLS_PSK_SUPPORT == ENABLED)
2610  uint8_t *psk; ///<Pre-shared key
2611  size_t pskLen; ///<Length of the pre-shared key, in bytes
2612  char_t *pskIdentity; ///<PSK identity
2613  char_t *pskIdentityHint; ///<PSK identity hint
2614  TlsPskCallback pskCallback; ///<PSK callback function
2615  uint16_t pskCipherSuite; ///<Cipher suite associated with the PSK
2616  TlsHashAlgo pskHashAlgo; ///<Hash algorithm associated with the PSK
2617 #endif
2618 
2619 #if (TLS_MAX_FRAG_LEN_SUPPORT == ENABLED)
2620  size_t maxFragLen; ///<Maximum plaintext fragment length
2621  bool_t maxFragLenExtReceived; ///<The MaxFragmentLength extension has been received
2622 #endif
2623 
2624 #if (TLS_RECORD_SIZE_LIMIT_SUPPORT == ENABLED)
2625  size_t recordSizeLimit; ///<Maximum record size the peer is willing to receive
2626  bool_t recordSizeLimitExtReceived; ///<The RecordSizeLimit extension has been received
2627 #endif
2628 
2629 #if (TLS_ALPN_SUPPORT == ENABLED)
2630  bool_t unknownProtocolsAllowed; ///<Unknown ALPN protocols allowed
2631  char_t *protocolList; ///<List of supported ALPN protocols
2632  char_t *selectedProtocol; ///<Selected ALPN protocol
2633  TlsAlpnCallback alpnCallback; ///<ALPN callback function
2634 #endif
2635 
2636 #if (TLS_ENCRYPT_THEN_MAC_SUPPORT == ENABLED)
2637  bool_t etmExtReceived; ///<The EncryptThenMac extension has been received
2638 #endif
2639 
2640 #if (TLS_EXT_MASTER_SECRET_SUPPORT == ENABLED)
2641  bool_t emsExtReceived; ///<The ExtendedMasterSecret extension has been received
2642 #endif
2643 
2644 #if (TLS_RAW_PUBLIC_KEY_SUPPORT == ENABLED)
2645  TlsCertificateFormat certFormat; ///<Certificate format
2646  TlsCertificateFormat peerCertFormat; ///<Peer's certificate format
2647  TlsRpkVerifyCallback rpkVerifyCallback; ///<Raw public key verification callback function
2648  bool_t clientCertTypeExtReceived; ///<The ClientCertType extension has been received
2649  bool_t serverCertTypeExtReceived; ///<The ServerCertType extension has been received
2650 #endif
2651 
2652 #if (TLS_TICKET_SUPPORT == ENABLED)
2653  bool_t sessionTicketEnabled; ///<Session ticket mechanism enabled
2654  bool_t sessionTicketExtReceived; ///<The SessionTicket extension has been received
2655  bool_t sessionTicketExtSent; ///<The SessionTicket extension has been sent
2656  TlsTicketEncryptCallback ticketEncryptCallback; ///<Ticket encryption callback function
2657  TlsTicketDecryptCallback ticketDecryptCallback; ///<Ticket decryption callback function
2658  void *ticketParam; ///<Opaque pointer passed to the ticket callbacks
2659 #endif
2660 
2661 #if (TLS_TRUSTED_CA_KEYS_SUPPORT == ENABLED)
2662  bool_t trustedCaKeysEnabled; ///<Support for TrustedCaKeys extension
2663 #endif
2664 
2665 #if (TLS_CERT_AUTHORITIES_SUPPORT == ENABLED)
2666  bool_t certAuthoritiesEnabled; ///<Support for CertificateAuthorities extension
2667 #endif
2668 
2669 #if (TLS_SECURE_RENEGOTIATION_SUPPORT == ENABLED)
2670  bool_t secureRenegoEnabled; ///<Secure renegotiation enabled
2671  bool_t secureRenegoFlag; ///<Secure renegotiation flag
2672 #endif
2673 
2674 #if (TLS_FALLBACK_SCSV_SUPPORT == ENABLED)
2675  bool_t fallbackScsvEnabled; ///<Support for FALLBACK_SCSV
2676 #endif
2677 
2678 #if (TLS_KEY_LOG_SUPPORT == ENABLED)
2679  TlsKeyLogCallback keyLogCallback; ///<Key logging callback (for debugging purpose only)
2680 #endif
2681 
2682 #if (TLS_MAX_WARNING_ALERTS > 0)
2683  uint_t alertCount; ///<Count of consecutive warning alerts
2684 #endif
2685 
2686 #if (TLS_MAX_EMPTY_RECORDS > 0)
2687  uint_t emptyRecordCount; ///<Count of consecutive empty records
2688 #endif
2689 
2690 #if (TLS_MAX_CHANGE_CIPHER_SPEC_MESSAGES > 0)
2691  uint_t changeCipherSpecCount; ///<Count of consecutive ChangeCipherSpec messages
2692 #endif
2693 
2694 #if (TLS_MAX_KEY_UPDATE_MESSAGES > 0)
2695  uint_t keyUpdateCount; ///<Count of consecutive KeyUpdate messages
2696 #endif
2697 
2698 #if (DTLS_SUPPORT == ENABLED)
2699  size_t pmtu; ///<PMTU value
2700  systime_t timeout; ///<Timeout for blocking calls
2702 
2703  DtlsCookieGenerateCallback cookieGenerateCallback; ///<Cookie generation callback function
2704  DtlsCookieVerifyCallback cookieVerifyCallback; ///<Cookie verification callback function
2705  void *cookieParam; ///<Opaque pointer passed to the cookie callbacks
2706 
2707  uint_t retransmitCount; ///<Retransmission counter
2708  systime_t retransmitTimestamp; ///<Time at which the datagram was sent
2709  systime_t retransmitTimeout; ///<Retransmission timeout
2710 
2711  uint16_t txMsgSeq; ///<Send sequence number
2712  size_t txDatagramLen; ///<Length of the outgoing datagram, in bytes
2713 
2714  uint16_t rxMsgSeq; ///<Next receive sequence number
2715  size_t rxFragQueueLen; ///<Length of the reassembly queue
2716  size_t rxDatagramLen; ///<Length of the incoming datagram, in bytes
2718  uint16_t rxRecordVersion; ///<Version of the incoming record
2719 
2720  bool_t replayDetectionEnabled; ///<Anti-replay mechanism enabled
2721 #endif
2722 
2723 #if (DTLS_SUPPORT == ENABLED && TLS_MAX_VERSION >= TLS_VERSION_1_3)
2724  uint8_t clientHelloDigest[48]; ///<Hash(ClientHello1)
2725  size_t clientHelloDigestLen; ///<Length of Hash(ClientHello1)
2726  Dtls13RecordNumber rxRecordNum; ///<Epoch/sequence number pair
2727  Dtls13RecordNumber ackRecords[DTLS13_MAX_ACK_RECORDS]; ///<List of records received and processed
2728  uint_t numAckRecords; ///<Number of records in the list
2729  bool_t ackTimerRunning; ///<The ACK timer is running
2730  systime_t ackTimestamp; ///<Time at which the ACK timer started
2731 #endif
2732 
2733 #if (TLS_QUIC_SUPPORT == ENABLED)
2734  TlsQuicCallbacks quicCallbacks; ///<QUIC-specific callback functions
2735  void *quicHandle; ///<Opaque pointer passed to the QUIC-specific callbacks
2736  uint8_t *localQuicTransportParams; ///<Local QUIC transport parameters
2737  size_t localQuicTransportParamsLen; ///<Length of the local QUIC transport parameters
2738  uint8_t *remoteQuicTransportParams; ///<Remote QUIC transport parameters
2739  size_t remoteQuicTransportParamsLen; ///<Length of the remote QUIC transport parameters
2740 #endif
2741 
2742  TLS_CONTEXT_PRIVATE ///<Application specific context
2743 };
2744 
2745 
2746 //TLS application programming interface (API)
2747 TlsContext *tlsInit(void);
2748 TlsState tlsGetState(TlsContext *context);
2749 
2751  TlsStateChangeCallback stateChangeCallback);
2752 
2754  TlsSocketSendCallback socketSendCallback,
2755  TlsSocketReceiveCallback socketReceiveCallback, TlsSocketHandle handle);
2756 
2757 error_t tlsSetVersion(TlsContext *context, uint16_t versionMin,
2758  uint16_t versionMax);
2759 
2761  TlsTransportProtocol transportProtocol);
2762 
2764 
2765 error_t tlsSetPrng(TlsContext *context, const PrngAlgo *prngAlgo,
2766  void *prngContext);
2767 
2768 error_t tlsSetServerName(TlsContext *context, const char_t *serverName);
2769 const char_t *tlsGetServerName(TlsContext *context);
2770 
2771 error_t tlsSetCache(TlsContext *context, TlsCache *cache);
2773 
2774 error_t tlsSetBufferSize(TlsContext *context, size_t txBufferSize,
2775  size_t rxBufferSize);
2776 
2777 error_t tlsSetMaxFragmentLength(TlsContext *context, size_t maxFragLen);
2778 
2779 error_t tlsSetCipherSuites(TlsContext *context, const uint16_t *cipherSuites,
2780  uint_t length);
2781 
2782 error_t tlsSetSupportedGroups(TlsContext *context, const uint16_t *groups,
2783  uint_t length);
2784 
2785 error_t tlsSetPreferredGroup(TlsContext *context, uint16_t group);
2786 
2788  const uint16_t *signAlgos, uint_t length);
2789 
2790 error_t tlsSetDhParameters(TlsContext *context, const char_t *params,
2791  size_t length);
2792 
2793 error_t tlsSetEcdhCallback(TlsContext *context, TlsEcdhCallback ecdhCallback);
2794 
2796  TlsEcdsaSignCallback ecdsaSignCallback);
2797 
2799  TlsEcdsaVerifyCallback ecdsaVerifyCallback);
2800 
2802  TlsKeyLogCallback keyLogCallback);
2803 
2805 error_t tlsSetAlpnProtocolList(TlsContext *context, const char_t *protocolList);
2806 error_t tlsSetAlpnCallback(TlsContext *context, TlsAlpnCallback alpnCallback);
2807 const char_t *tlsGetAlpnProtocol(TlsContext *context);
2808 
2809 error_t tlsSetPsk(TlsContext *context, const uint8_t *psk, size_t length);
2810 error_t tlsSetPskIdentity(TlsContext *context, const char_t *pskIdentity);
2811 error_t tlsSetPskIdentityHint(TlsContext *context, const char_t *pskIdentityHint);
2812 error_t tlsSetPskCallback(TlsContext *context, TlsPskCallback pskCallback);
2813 
2815  TlsRpkVerifyCallback rpkVerifyCallback);
2816 
2817 error_t tlsSetTrustedCaList(TlsContext *context, const char_t *trustedCaList,
2818  size_t length);
2819 
2821  const char_t *certChain, size_t certChainLen, const char_t *privateKey,
2822  size_t privateKeyLen, const char_t *password);
2823 
2825  TlsCertVerifyCallback certVerifyCallback, void *param);
2826 
2828 error_t tlsEnableTrustedCaKeys(TlsContext *context, bool_t enabled);
2831 error_t tlsEnableFallbackScsv(TlsContext *context, bool_t enabled);
2832 
2834  TlsTicketEncryptCallback ticketEncryptCallback,
2835  TlsTicketDecryptCallback ticketDecryptCallback, void *param);
2836 
2837 error_t tlsSetPmtu(TlsContext *context, size_t pmtu);
2838 error_t tlsSetTimeout(TlsContext *context, systime_t timeout);
2839 
2841  DtlsCookieGenerateCallback cookieGenerateCallback,
2842  DtlsCookieVerifyCallback cookieVerifyCallback, void *param);
2843 
2845 
2846 error_t tlsSetMaxEarlyDataSize(TlsContext *context, size_t maxEarlyDataSize);
2847 
2848 error_t tlsWriteEarlyData(TlsContext *context, const void *data,
2849  size_t length, size_t *written, uint_t flags);
2850 
2851 error_t tlsConnect(TlsContext *context);
2852 
2854 
2855 error_t tlsExportKeyingMaterial(TlsContext *context, const char_t *label,
2856  bool_t useContextValue, const uint8_t *contextValue,
2857  size_t contextValueLen, uint8_t *output, size_t outputLen);
2858 
2860  uint8_t *output, size_t *length);
2861 
2862 error_t tlsWrite(TlsContext *context, const void *data, size_t length,
2863  size_t *written, uint_t flags);
2864 
2865 error_t tlsRead(TlsContext *context, void *data, size_t size, size_t *received,
2866  uint_t flags);
2867 
2868 bool_t tlsIsTxReady(TlsContext *context);
2869 bool_t tlsIsRxReady(TlsContext *context);
2870 
2871 error_t tlsShutdown(TlsContext *context);
2872 error_t tlsShutdownEx(TlsContext *context, bool_t waitForCloseNotify);
2873 
2874 error_t tlsTick(TlsContext *context);
2875 
2876 void tlsFree(TlsContext *context);
2877 
2879 
2880 error_t tlsSaveSessionState(const TlsContext *context,
2881  TlsSessionState *session);
2882 
2884  const TlsSessionState *session);
2885 
2886 void tlsFreeSessionState(TlsSessionState *session);
2887 
2889 void tlsFreeCache(TlsCache *cache);
2890 
2891 //C++ guard
2892 #ifdef __cplusplus
2893 }
2894 #endif
2895 
2896 #endif
@ TLS_GROUP_X25519_MLKEM768
Definition: tls.h:1546
@ TLS_CERT_ECDSA_FIXED_ECDH
Definition: tls.h:1284
error_t tlsSetCertificateVerifyCallback(TlsContext *context, TlsCertVerifyCallback certVerifyCallback, void *param)
Register certificate verification callback function.
Definition: tls.c:1400
@ TLS13_KEY_EXCH_PSK
Definition: tls.h:1247
TlsRpkVerifyCallback rpkVerifyCallback
Raw public key verification callback function.
Definition: tls.h:2647
@ TLS_EXT_PSK_KEY_EXCHANGE_MODES
Definition: tls.h:1432
@ TLS_GROUP_BRAINPOOLP512R1_TLS13
Definition: tls.h:1527
size_t ticketLen
Length of the session ticket.
Definition: tls.h:2255
@ TLS_TYPE_MESSAGE_HASH
Definition: tls.h:1146
@ TLS_EXT_MAX_FRAGMENT_LENGTH
Definition: tls.h:1394
DTLS (Datagram Transport Layer Security)
ECDSA signature.
Definition: ecdsa.h:63
@ TLS_SIGN_ALGO_DSA
Definition: tls.h:1323
uint8_t sessionId[32]
Session identifier.
Definition: tls.h:2453
@ TLS_CERT_FORMAT_RAW_PUBLIC_KEY
Definition: tls.h:1263
X.509 common definitions.
uint8_t masterSecret[TLS_MASTER_SECRET_SIZE]
Master secret.
Definition: tls.h:2526
@ TLS_SIGN_SCHEME_ECDSA_BP256R1_TLS13_SHA256
Definition: tls.h:1356
TlsServerName
Definition: tls.h:1776
@ TLS_ALERT_DECODE_ERROR
Definition: tls.h:1183
@ TLS_GROUP_SECT163R2
Definition: tls.h:1497
size_t sessionIdLen
Length of the session identifier.
Definition: tls.h:2454
@ TLS_ALERT_UNEXPECTED_MESSAGE
Definition: tls.h:1168
EcPublicKey peerEcPublicKey
Peer's EC public key.
Definition: tls.h:2597
Collection of key exchange algorithms.
@ TLS_GROUP_BRAINPOOLP256R1_TLS13
Definition: tls.h:1525
bool_t ecPointFormatsExtReceived
The EcPointFormats extension has been received.
Definition: tls.h:2581
Generic hash algorithm context.
uint16_t length
Definition: tls.h:1740
TlsHashAlgo ticketHashAlgo
Hash algorithm associated with the ticket.
Definition: tls.h:2564
@ TLS_TRANSPORT_PROTOCOL_QUIC
Definition: tls.h:1040
Tls13PskBinderList
Definition: tls13_misc.h:275
uint8_t secret[TLS_MAX_HKDF_DIGEST_SIZE]
Definition: tls.h:2548
@ TLS_SIGN_SCHEME_MLDSA44_ECDSA_SECP256R1_SHA256
Definition: tls.h:1372
@ TLS_STATE_HELLO_RETRY_REQUEST
Definition: tls.h:1589
int bool_t
Definition: compiler_port.h:63
uint8_t sessionId[]
Definition: tls.h:1942
uint8_t b
Definition: nbns_common.h:122
@ TLS_GROUP_SECP160R2
Definition: tls.h:1511
HMAC algorithm context.
Definition: hmac.h:59
uint_t numSupportedGroups
Number of named groups in the list.
Definition: tls.h:2435
uint8_t encKey[48]
Encryption key.
Definition: tls.h:2369
uint16_t cipherSuite
Cipher suite identifier.
Definition: tls.h:2052
error_t tlsEnableTrustedCaKeys(TlsContext *context, bool_t enabled)
Enable TrustedCaKeys extension.
Definition: tls.c:1450
@ TLS_CA_ROOT_KEY_ID_TYPE_KEY_SHA1_HASH
Definition: tls.h:1482
@ TLS_EXT_OID_FILTERS
Definition: tls.h:1434
@ TLS_TYPE_NEW_CONNECTION_ID
Definition: tls.h:1132
@ TLS_ALERT_CERTIFICATE_REQUIRED
Definition: tls.h:1200
error_t(* TlsTicketEncryptCallback)(TlsContext *context, const uint8_t *plaintext, size_t plaintextLen, uint8_t *ciphertext, size_t *ciphertextLen, void *param)
Ticket encryption callback function.
Definition: tls.h:2136
MldsaPublicKey peerMldsaPublicKey
Peer's ML-DSA public key.
Definition: tls.h:2606
uint8_t * cookie
Cookie.
Definition: tls.h:2461
char_t * pskIdentity
PSK identity.
Definition: tls.h:2612
const Tls13PskKeModeList * pskKeModeList
PskKeyExchangeModes extension.
Definition: tls.h:2348
@ TLS_ALERT_CLOSE_NOTIFY
Definition: tls.h:1167
error_t tlsConnect(TlsContext *context)
Initiate the TLS handshake.
Definition: tls.c:1805
TlsDigitalSignature
Definition: tls.h:1886
@ TLS_ALERT_NO_RENEGOTIATION
Definition: tls.h:1192
@ TLS13_KEY_EXCH_MLKEM
Definition: tls.h:1245
@ TLS_SIGN_ALGO_ANONYMOUS
Definition: tls.h:1321
systime_t ticketTimestamp
Timestamp to manage ticket lifetime.
Definition: tls.h:2257
void TlsServerHelloDone
ServerHelloDone message.
Definition: tls.h:1988
bool_t secureRenegoFlag
Secure renegotiation flag.
Definition: tls.h:2671
@ TLS13_KEY_EXCH_PSK_DHE
Definition: tls.h:1248
error_t(* TlsEcdsaVerifyCallback)(TlsContext *context, const uint8_t *digest, size_t digestLen, EcdsaSignature *signature)
ECDSA signature verification callback function.
Definition: tls.h:2169
Tls13Cookie
Definition: tls13_misc.h:197
@ TLS_SIGN_SCHEME_RSA_PSS_RSAE_SHA256
Definition: tls.h:1346
@ TLS_SIGN_SCHEME_MLDSA65_ED25519
Definition: tls.h:1376
error_t tlsSetEcdsaSignCallback(TlsContext *context, TlsEcdsaSignCallback ecdsaSignCallback)
Register ECDSA signature generation callback function.
Definition: tls.c:799
signed int int_t
Definition: compiler_port.h:56
DtlsSequenceNumber dtlsSeqNum
Record sequence number.
Definition: tls.h:2386
#define TLS_MAX_PASSWORD_LEN
Definition: tls.h:810
@ TLS_CERT_FORMAT_OPENPGP
Definition: tls.h:1262
@ TLS_STATE_SERVER_KEY_EXCHANGE
Definition: tls.h:1596
const TlsExtension * sessionTicket
SessionTicket extension.
Definition: tls.h:2334
@ TLS_TYPE_SERVER_HELLO_DONE
Definition: tls.h:1136
size_t premasterSecretLen
Length of the premaster secret.
Definition: tls.h:2508
@ TLS_COMPRESSION_METHOD_NULL
Definition: tls.h:1213
@ TLS_SIGN_ALGO_GOSTR34102012_256
Definition: tls.h:1327
@ TLS_ALERT_ILLEGAL_PARAMETER
Definition: tls.h:1180
@ TLS_GROUP_SECT571K1
Definition: tls.h:1507
@ TLS_SIGN_SCHEME_MLDSA65_RSA4096_PSS_PSS_SHA384
Definition: tls.h:1382
TlsKeyExchMethod keyExchMethod
Key exchange method.
Definition: tls.h:2472
@ TLS_SIGN_SCHEME_RSA_PKCS1_SHA384_LEGACY
Definition: tls.h:1344
TlsEcPointFormat
EC point formats.
Definition: tls.h:1559
@ TLS_CERT_MLDSA44_SIGN
Definition: tls.h:1291
uint8_t * ticket
Session ticket.
Definition: tls.h:2254
#define PrngAlgo
Definition: crypto.h:1140
@ TLS_EXT_CLIENT_AUTHZ
Definition: tls.h:1400
@ TLS_EARLY_DATA_REJECTED
Definition: tls.h:1074
uint32_t ticketLifetime
Lifetime of the ticket.
Definition: tls.h:2468
@ TLS_EXT_PWD_PROTECT
Definition: tls.h:1421
TlsCache * tlsInitCache(uint_t size)
Session cache initialization.
Definition: tls_cache.c:50
error_t tlsShutdownEx(TlsContext *context, bool_t waitForCloseNotify)
Gracefully close TLS session.
Definition: tls.c:2634
@ TLS_ALERT_UNSUPPORTED_EXTENSION
Definition: tls.h:1194
TlsState
TLS FSM states.
Definition: tls.h:1583
uint8_t algorithm
@ TLS_TYPE_CERTIFICATE_STATUS
Definition: tls.h:1141
@ TLS_ALERT_GENERAL_ERROR
Definition: tls.h:1201
const Tls13PskBinderList * binderList
Definition: tls.h:2350
uint8_t clientRandom[TLS_RANDOM_SIZE]
Client random value.
Definition: tls.h:2505
size_t rxBufferSize
RX buffer size.
Definition: tls.h:2497
bool_t closeNotifySent
A closure alert has been sent.
Definition: tls.h:2484
@ TLS_EXT_SUPPORTED_VERSIONS
Definition: tls.h:1430
ECDSA (Elliptic Curve Digital Signature Algorithm)
@ TLS_EXT_RRC
Definition: tls.h:1446
@ TLS_SIGN_SCHEME_MLDSA44_ED25519
Definition: tls.h:1375
uint16_t versionMin
Minimum version accepted by the implementation.
Definition: tls.h:2458
bool_t maxFragLenExtReceived
The MaxFragmentLength extension has been received.
Definition: tls.h:2621
TlsState tlsGetState(TlsContext *context)
Retrieve current TLS state.
Definition: tls.c:220
TlsCertificateRequest
Definition: tls.h:1981
@ TLS_SIGN_SCHEME_MLDSA44
Definition: tls.h:1369
@ TLS_ALERT_RECORD_OVERFLOW
Definition: tls.h:1171
@ TLS_SIGN_SCHEME_MLDSA65_RSA3072_PSS_PSS_SHA256
Definition: tls.h:1381
uint16_t version
Definition: tls.h:1908
@ TLS_SIGN_SCHEME_RSA_PKCS1_SHA512_LEGACY
Definition: tls.h:1345
TlsTransportProtocol transportProtocol
Transport protocol (stream or datagram)
Definition: tls.h:2419
size_t txRecordPos
Current position in the TLS record.
Definition: tls.h:2494
@ TLS_EXT_EXTERNAL_ID_HASH
Definition: tls.h:1440
const TlsSignSchemeList * signAlgoList
SignatureAlgorithms extension.
Definition: tls.h:2310
TlsConnectionEnd
TLS connection end.
Definition: tls.h:1050
size_t rxDatagramPos
Definition: tls.h:2717
const TlsExtension * selectedGroup
KeyShare extension (HelloRetryRequest)
Definition: tls.h:2346
systime_t timestamp
Time stamp to manage entry lifetime.
Definition: tls.h:2247
systime_t lifetime
Lifetime of the encryption engine.
Definition: tls.h:2365
@ TLS_GROUP_SECP256K1
Definition: tls.h:1516
uint8_t * txBuffer
TX buffer.
Definition: tls.h:2487
TlsContext * tlsInit(void)
TLS context initialization.
Definition: tls.c:68
error_t tlsSetStateChangeCallback(TlsContext *context, TlsStateChangeCallback stateChangeCallback)
Register TLS state change callback.
Definition: tls.c:246
bool_t fatalAlertSent
A fatal alert message has been sent.
Definition: tls.h:2482
HashContext * transcriptHashContext
Hash context used to compute verify data.
Definition: tls.h:2536
uint8_t clientHsTrafficSecret[TLS_MAX_HKDF_DIGEST_SIZE]
Definition: tls.h:2550
@ TLS_GROUP_EXPLICIT_CHAR2_CURVE
Definition: tls.h:1550
error_t(* DtlsCookieGenerateCallback)(TlsContext *context, const DtlsClientParameters *clientParams, uint8_t *cookie, size_t *length, void *param)
DTLS cookie generation callback function.
Definition: dtls_misc.h:247
TlsConnectionEnd entity
Client or server operation.
Definition: tls.h:2420
@ TLS_EXT_PWD_CLEAR
Definition: tls.h:1422
TlsCertificateFormat peerCertFormat
Peer's certificate format.
Definition: tls.h:2646
systime_t ackTimestamp
Time at which the ACK timer started.
Definition: tls.h:2730
@ TLS_STATE_CERTIFICATE_REQUEST
Definition: tls.h:1598
void * cookieParam
Opaque pointer passed to the cookie callbacks.
Definition: tls.h:2705
@ TLS_ENCRYPTION_LEVEL_INITIAL
Definition: tls.h:1631
@ TLS_TYPE_CHANGE_CIPHER_SPEC
Definition: tls.h:1107
size_t maxFragLen
Maximum plaintext fragment length.
Definition: tls.h:2620
const TlsProtocolNameList * protocolNameList
ALPN extension.
Definition: tls.h:2319
@ TLS_GROUP_SECP256R1
Definition: tls.h:1517
const TlsExtension * earlyDataIndication
EarlyData extension.
Definition: tls.h:2352
error_t tlsRestoreSessionState(TlsContext *context, const TlsSessionState *session)
Restore TLS session.
Definition: tls.c:3073
error_t tlsSetSupportedSignAlgos(TlsContext *context, const uint16_t *signAlgos, uint_t length)
Specify the list of allowed signature algorithms.
Definition: tls.c:711
@ TLS_TYPE_HANDSHAKE
Definition: tls.h:1109
TlsEcPointFormatList
Definition: tls.h:1831
@ TLS_GROUP_CURVE_SM2
Definition: tls.h:1535
error_t tlsSetAlpnCallback(TlsContext *context, TlsAlpnCallback alpnCallback)
Register ALPN callback function.
Definition: tls.c:955
Dtls13RecordNumber rxRecordNum
Epoch/sequence number pair.
Definition: tls.h:2726
#define TLS_PRIVATE_ENCRYPTION_ENGINE
Definition: tls.h:906
error_t(* TlsSocketReceiveCallback)(TlsSocketHandle handle, void *data, size_t size, size_t *received, uint_t flags)
Socket receive callback function.
Definition: tls.h:2096
@ TLS_GROUP_SECP224K1
Definition: tls.h:1514
uint8_t * remoteQuicTransportParams
Remote QUIC transport parameters.
Definition: tls.h:2738
@ TLS_EXT_CONNECTION_ID
Definition: tls.h:1439
TlsTicketDecryptCallback ticketDecryptCallback
Ticket decryption callback function.
Definition: tls.h:2657
TlsCertificateType type
End entity certificate type.
Definition: tls.h:2293
@ TLS_SIGN_SCHEME_GOSTR34102012_256A
Definition: tls.h:1362
@ TLS_GROUP_SECT239K1
Definition: tls.h:1502
bool_t clientCertTypeExtReceived
The ClientCertType extension has been received.
Definition: tls.h:2648
size_t pmtu
PMTU value.
Definition: tls.h:2699
@ TLS_TRANSPORT_PROTOCOL_DATAGRAM
Definition: tls.h:1039
@ TLS_TYPE_COMPRESSED_CERTIFICATE
Definition: tls.h:1144
@ TLS_ALERT_ACCESS_DENIED
Definition: tls.h:1182
TlsRenegoInfo
Definition: tls.h:1853
@ TLS_KEY_EXCH_SRP_SHA_RSA
Definition: tls.h:1241
@ TLS_ALERT_INSUFFICIENT_SECURITY
Definition: tls.h:1188
#define DTLS_REPLAY_WINDOW_SIZE
Definition: dtls_misc.h:69
TlsPskIdentity
Definition: tls.h:1864
@ TLS_CERT_FORTEZZA_DMS
Definition: tls.h:1281
HmacContext * hmacContext
HMAC context.
Definition: tls.h:2379
TlsMessageType
Handshake message type.
Definition: tls.h:1122
@ TLS_SIGN_SCHEME_RSA_PSS_PSS_SHA512
Definition: tls.h:1351
TlsSocketHandle socketHandle
Socket handle.
Definition: tls.h:2424
@ TLS13_KEY_EXCH_PSK_MLKEM
Definition: tls.h:1250
const char_t * name
Definition: tls.h:2224
Structure describing a cipher suite.
Definition: tls.h:2222
@ TLS_ALERT_BAD_CERTIFICATE_HASH_VALUE
Definition: tls.h:1198
@ TLS_HASH_ALGO_SHA1
Definition: tls.h:1305
@ TLS_STATE_APPLICATION_DATA
Definition: tls.h:1615
@ TLS_COMPRESSION_METHOD_DEFLATE
Definition: tls.h:1214
size_t txDatagramLen
Length of the outgoing datagram, in bytes.
Definition: tls.h:2712
size_t sessionIdLen
Length of the session identifier.
Definition: tls.h:2251
size_t authTagLen
Length of the authentication tag.
Definition: tls.h:2374
@ TLS_GROUP_GC512A
Definition: tls.h:1532
@ TLS_ALERT_DECOMPRESSION_FAILURE
Definition: tls.h:1172
const TlsCertTypeList * clientCertTypeList
ClientCertType extension.
Definition: tls.h:2322
bool_t secureRenegoEnabled
Secure renegotiation enabled.
Definition: tls.h:2670
uint8_t type
Definition: coap_common.h:176
@ TLS_GROUP_GC256D
Definition: tls.h:1531
error_t tlsSetVersion(TlsContext *context, uint16_t versionMin, uint16_t versionMax)
Set minimum and maximum versions permitted.
Definition: tls.c:302
@ TLS_KEY_EXCH_DH_DSS
Definition: tls.h:1228
TlsHashAlgo
Hash algorithms.
Definition: tls.h:1302
bool_t closeNotifyReceived
A closure alert has been received from the peer.
Definition: tls.h:2485
error_t tlsSetMaxFragmentLength(TlsContext *context, size_t maxFragLen)
Set maximum fragment length.
Definition: tls.c:591
@ TLS_ALERT_CERTIFICATE_UNOBTAINABLE
Definition: tls.h:1195
const HashAlgo * hashAlgo
Hash algorithm for MAC operations.
Definition: tls.h:2378
@ TLS_ALERT_NO_CERTIFICATE
Definition: tls.h:1174
@ TLS_TYPE_ACK
Definition: tls.h:1113
TlsAlpnCallback alpnCallback
ALPN callback function.
Definition: tls.h:2633
TlsStateChangeCallback stateChangeCallback
TLS state change callback function.
Definition: tls.h:2422
@ TLS13_KEY_EXCH_ECDHE
Definition: tls.h:1244
@ TLS_STATE_SERVER_APP_TRAFFIC_KEYS
Definition: tls.h:1613
@ TLS_CERT_DSS_SIGN
Definition: tls.h:1276
@ TLS_KEY_EXCH_SRP_SHA_DSS
Definition: tls.h:1242
@ TLS_SIGN_SCHEME_RSA_PSS_RSAE_SHA512
Definition: tls.h:1348
@ TLS_SIGN_SCHEME_NONE
Definition: tls.h:1338
bool_t active
Operational state of the encryption engine.
Definition: tls.h:2363
void * prngContext
Pseudo-random number generator context.
Definition: tls.h:2429
TlsAlertDescription
Alert description.
Definition: tls.h:1166
CipherMode cipherMode
Definition: tls.h:2227
error_t tlsSetAlpnProtocolList(TlsContext *context, const char_t *protocolList)
Set the list of supported ALPN protocols.
Definition: tls.c:906
uint16_t value[]
Definition: tls.h:1663
@ TLS_SIGN_SCHEME_ED25519
Definition: tls.h:1360
OsMutex mutex
Mutex preventing simultaneous access to the cache.
Definition: tls.h:2276
@ TLS_EXT_TICKET_PINNING
Definition: tls.h:1424
uint8_t clientVerifyData[64]
Client verify data.
Definition: tls.h:2509
DhContext dhContext
Diffie-Hellman context.
Definition: tls.h:2576
void * snCipherContext
Sequence number encryption context.
Definition: tls.h:2393
@ TLS_EXT_SERVER_AUTHZ
Definition: tls.h:1401
TlsProtocolNameList
Definition: tls.h:1809
Tls13KeyShareEntry
Definition: tls13_misc.h:209
@ TLS_ALERT_DECRYPT_ERROR
Definition: tls.h:1184
@ TLS_KEY_EXCH_ECDH_RSA
Definition: tls.h:1231
char_t * ticketAlpn
ALPN protocol associated with the ticket.
Definition: tls.h:2565
TlsContentType txBufferType
Type of data that resides in the TX buffer.
Definition: tls.h:2490
Session cache.
Definition: tls.h:2275
TlsTicketEncryptCallback ticketEncryptCallback
Ticket encryption callback function.
Definition: tls.h:2656
TlsChangeCipherSpec
Definition: tls.h:2031
Dtls13RecordNumber
Definition: dtls13_misc.h:73
size_t rxDatagramLen
Length of the incoming datagram, in bytes.
Definition: tls.h:2716
const TlsSupportedVersionList * supportedVersionList
SupportedVersions extension (ClientHello)
Definition: tls.h:2305
TlsExtension
Definition: tls.h:1742
systime_t retransmitTimeout
Retransmission timeout.
Definition: tls.h:2709
size_t pskLen
Length of the pre-shared key, in bytes.
Definition: tls.h:2611
uint16_t rxMsgSeq
Next receive sequence number.
Definition: tls.h:2714
uint_t cipherSuiteTypes
Types of cipher suites proposed by the client.
Definition: tls.h:2470
@ TLS_ENCRYPTION_LEVEL_EARLY_DATA
Definition: tls.h:1632
uint8_t certificateTypes[]
Definition: tls.h:1980
uint8_t * psk
Pre-shared key.
Definition: tls.h:2610
uint_t emptyRecordCount
Count of consecutive empty records.
Definition: tls.h:2687
uint32_t replayWindow[(DTLS_REPLAY_WINDOW_SIZE+31)/32]
Replay window.
Definition: tls.h:2389
size_t earlyDataLen
Total amount of 0-RTT data that have been sent by the client.
Definition: tls.h:2568
#define TLS_RANDOM_SIZE
Definition: tls.h:1020
@ TLS_GROUP_BRAINPOOLP256R1
Definition: tls.h:1520
bool_t wrongCookie
Invalid cookie.
Definition: tls.h:2463
@ TLS_SIGN_SCHEME_GOSTR34102012_256B
Definition: tls.h:1363
@ TLS_EXT_COMPRESS_CERTIFICATE
Definition: tls.h:1419
size_t fixedIvLen
Length of the fixed part of the IV.
Definition: tls.h:2372
@ TLS_EXT_EARLY_DATA
Definition: tls.h:1429
@ TLS_EXT_TRUNCATED_HMAC
Definition: tls.h:1397
@ TLS_EXT_SESSION_TICKET
Definition: tls.h:1426
@ TLS_TYPE_END_OF_EARLY_DATA
Definition: tls.h:1128
uint8_t authTagLen
Definition: tls.h:2234
@ TLS_ENCRYPTION_LEVEL_HANDSHAKE
Definition: tls.h:1633
@ TLS_GROUP_X448
Definition: tls.h:1524
error_t(* TlsSocketSendCallback)(TlsSocketHandle handle, const void *data, size_t length, size_t *written, uint_t flags)
Socket send callback function.
Definition: tls.h:2088
@ TLS13_KEY_EXCH_PSK_HYBRID
Definition: tls.h:1251
@ TLS_GROUP_FFDHE6144
Definition: tls.h:1539
TlsPskIdentityHint
Definition: tls.h:1875
@ TLS_SIGN_SCHEME_RSA_PSS_PSS_SHA384
Definition: tls.h:1350
@ TLS_SIGN_SCHEME_MLDSA65_RSA3072_PKCS1_SHA256
Definition: tls.h:1378
error_t tlsAllowUnknownAlpnProtocols(TlsContext *context, bool_t allowed)
Allow unknown ALPN protocols.
Definition: tls.c:880
@ TLS_SIGN_SCHEME_RSA_PSS_RSAE_SHA384
Definition: tls.h:1347
TlsEncryptionEngine encryptionEngine[TLS_MAX_ENCRYPTION_ENGINES]
Encryption engines.
Definition: tls.h:2514
@ TLS_SIGN_ALGO_ED448
Definition: tls.h:1326
@ TLS_MAX_FRAGMENT_LENGTH_4096
Definition: tls.h:1471
@ TLS_HASH_ALGO_NONE
Definition: tls.h:1303
error_t tlsSetTimeout(TlsContext *context, systime_t timeout)
Set timeout for blocking calls (for DTLS only)
Definition: tls.c:1619
uint16_t preferredGroup
Preferred ECDHE or FFDHE named group.
Definition: tls.h:2540
size_t maxEarlyDataSize
Maximum amount of 0-RTT data that the client is allowed to send.
Definition: tls.h:2567
#define DTLS13_MAX_ACK_RECORDS
Definition: dtls13_misc.h:39
Retransmission state.
Definition: dtls13_misc.h:100
const Tls13Cookie * cookie
Cookie extension.
Definition: tls.h:2343
@ TLS_EXT_QUIC_TRANSPORT_PARAMETERS
Definition: tls.h:1442
TlsKeyExchMethod keyExchMethod
Definition: tls.h:2225
error_t tlsSetCache(TlsContext *context, TlsCache *cache)
Set session cache.
Definition: tls.c:500
uint8_t sessionIdLen
Definition: tls.h:1941
uint8_t serverVerifyData[64]
Server verify data.
Definition: tls.h:2511
@ TLS_STATE_CLIENT_HELLO
Definition: tls.h:1585
bool_t extendedMasterSecret
Extended master secret computation.
Definition: tls.h:2057
@ TLS_SIGN_SCHEME_MLDSA65
Definition: tls.h:1370
@ TLS_ALERT_EXPORT_RESTRICTION
Definition: tls.h:1186
error_t tlsSetPsk(TlsContext *context, const uint8_t *psk, size_t length)
Set the pre-shared key to be used.
Definition: tls.c:1008
uint8_t * rxBuffer
RX buffer.
Definition: tls.h:2496
TLS 1.3 helper functions.
const Tls13KeyShareEntry * serverShare
KeyShare extension (ServerHello)
Definition: tls.h:2347
@ TLS_SIGN_SCHEME_MLDSA44_RSA2048_PKCS1_SHA256
Definition: tls.h:1377
@ TLS_EXT_SERVER_NAME
Definition: tls.h:1393
@ TLS_EXT_SIGNATURE_ALGORITHMS_CERT
Definition: tls.h:1436
@ TLS_HASH_ALGO_SHA224
Definition: tls.h:1306
@ TLS_KEY_EXCH_RSA
Definition: tls.h:1225
const Tls13KeyShareList * keyShareList
KeyShare extension (ClientHello)
Definition: tls.h:2345
uint8_t resumptionMasterSecret[TLS_MAX_HKDF_DIGEST_SIZE]
Definition: tls.h:2555
CipherMode cipherMode
Cipher mode of operation.
Definition: tls.h:2377
@ TLS_EXT_CERT_TYPE
Definition: tls.h:1402
@ TLS_SIGN_SCHEME_MLDSA87
Definition: tls.h:1371
error_t(* TlsAlpnCallback)(TlsContext *context, const char_t *selectedProtocol)
ALPN callback function.
Definition: tls.h:2104
@ TLS_GROUP_CURVE_SM2_MLKEM768
Definition: tls.h:1548
@ TLS_EXT_SUPPORTED_EKT_CIPHERS
Definition: tls.h:1427
@ TLS_TYPE_CERTIFICATE
Definition: tls.h:1133
Encryption engine.
Definition: tls.h:2362
TlsExtensionList
Definition: tls.h:1753
@ TLS_CERT_RSA_EPHEMERAL_DH
Definition: tls.h:1279
@ TLS_ALERT_UNKNOWN_CA
Definition: tls.h:1181
void TlsFinished
Finished message.
Definition: tls.h:2021
TlsCipherSuites
Definition: tls.h:1664
@ TLS_STATE_SERVER_HELLO
Definition: tls.h:1590
@ TLS_STATE_HELLO_VERIFY_REQUEST
Definition: tls.h:1588
@ TLS_EXT_TRUSTED_CA_KEYS
Definition: tls.h:1396
error_t(* TlsRpkVerifyCallback)(TlsContext *context, const uint8_t *rawPublicKey, size_t rawPublicKeyLen)
Raw public key verification callback function.
Definition: tls.h:2128
uint32_t ticketNonce
A per-ticket value that is unique across all tickets issued.
Definition: tls.h:2562
KemContext kemContext
KEM context.
Definition: tls.h:2585
const TlsCertTypeList * serverCertTypeList
ServerCertType extension.
Definition: tls.h:2324
size_t recordSizeLimit
Maximum record size the peer is willing to receive.
Definition: tls.h:2625
@ TLS_ALERT_LEVEL_WARNING
Definition: tls.h:1156
TlsEncryptionLevel
Encryption level.
Definition: tls.h:1630
size_t txBufferSize
TX buffer size.
Definition: tls.h:2488
@ TLS_HASH_ALGO_SHA512
Definition: tls.h:1309
uint16_t cipherSuite
Cipher suite identifier.
Definition: tls.h:2246
@ TLS_ALERT_UNKNOWN_PSK_IDENTITY
Definition: tls.h:1199
const TlsExtension * maxFragLen
MaxFragmentLength extension.
Definition: tls.h:2313
@ TLS_KEY_EXCH_ECDHE_ECDSA
Definition: tls.h:1234
error_t tlsSetSocketCallbacks(TlsContext *context, TlsSocketSendCallback socketSendCallback, TlsSocketReceiveCallback socketReceiveCallback, TlsSocketHandle handle)
Set socket send and receive callbacks.
Definition: tls.c:270
TlsKeyLogCallback keyLogCallback
Key logging callback (for debugging purpose only)
Definition: tls.h:2679
@ TLS_STATE_KEY_UPDATE
Definition: tls.h:1618
@ TLS_CERT_FORMAT_1609DOT2
Definition: tls.h:1264
@ TLS_KEY_EXCH_ECDHE_RSA
Definition: tls.h:1232
const TlsEcPointFormatList * ecPointFormatList
EcPointFormats extension.
Definition: tls.h:2309
uint16_t version
Negotiated TLS version.
Definition: tls.h:2457
@ TLS_SIGN_SCHEME_RSA_PKCS1_SHA1
Definition: tls.h:1339
size_t certChainLen
Length of the certificate chain.
Definition: tls.h:2289
Diffie-Hellman context.
Definition: dh.h:60
TlsHandshake
Definition: tls.h:1923
@ TLS_KEY_EXCH_ECDH_ANON
Definition: tls.h:1235
uint_t numAckRecords
Number of records in the list.
Definition: tls.h:2728
uint8_t premasterSecret[TLS_PREMASTER_SECRET_SIZE]
Premaster secret.
Definition: tls.h:2507
ML-DSA public key.
Definition: mldsa.h:82
uint8_t identifier[]
Definition: tls.h:1718
size_t rxRecordLen
Length of the TLS record.
Definition: tls.h:2502
DSA public key.
Definition: dsa.h:61
HmacContext hmacContext
HMAC context.
Definition: tls.h:2528
uint8_t serverHsTrafficSecret[TLS_MAX_HKDF_DIGEST_SIZE]
Definition: tls.h:2551
@ TLS_FLAG_PEEK
Definition: tls.h:1085
const char_t * trustedCaList
Trusted CA list (PEM format)
Definition: tls.h:2446
uint32_t ticketAgeAdd
Random value used to obscure the age of the ticket.
Definition: tls.h:2561
TlsCertAuthorities
Definition: tls.h:1708
uint8_t * ticket
Session ticket.
Definition: tls.h:2465
@ TLS_GROUP_GC256B
Definition: tls.h:1529
@ TLS_EXT_SEQ_NUM_ENCRYPTION_ALGOS
Definition: tls.h:1445
size_t clientVerifyDataLen
Length of the client verify data.
Definition: tls.h:2510
X.509 certificate.
Definition: x509_common.h:1194
@ TLS_SIGN_SCHEME_MLDSA44_RSA2048_PSS_PSS_SHA256
Definition: tls.h:1380
TlsCertificateFormat
Certificate formats.
Definition: tls.h:1260
@ TLS_EXT_CLIENT_CERT_TYPE
Definition: tls.h:1412
@ TLS_HASH_ALGO_SM3
Definition: tls.h:1311
#define TlsContext
Definition: tls.h:36
error_t
Error codes.
Definition: error.h:43
@ TLS_SIGN_SCHEME_RSA_PSS_PSS_SHA256
Definition: tls.h:1349
@ TLS_ALERT_BAD_RECORD_MAC
Definition: tls.h:1169
error_t tlsShutdown(TlsContext *context)
Gracefully close TLS session.
Definition: tls.c:2621
@ TLS_SIGN_SCHEME_ECDSA_SECP521R1_SHA512
Definition: tls.h:1355
TlsSendQuicAlertMessageCallback sendAlertMessage
Definition: tls.h:2213
size_t txRecordLen
Length of the TLS record.
Definition: tls.h:2493
@ TLS_EXT_EXTENDED_MASTER_SECRET
Definition: tls.h:1416
#define TLS_MAX_DECRYPTION_ENGINES
Definition: tls.h:1003
KEM context.
Definition: kem.h:68
@ TLS_CERT_ED25519_SIGN
Definition: tls.h:1289
@ TLS_CONNECTION_END_SERVER
Definition: tls.h:1052
size_t cookieLen
Length of the cookie.
Definition: tls.h:2462
void tlsFreeSessionState(TlsSessionState *session)
Properly dispose a session state.
Definition: tls.c:3126
@ TLS_GROUP_SECP256R1_MLKEM768
Definition: tls.h:1545
@ TLS_EXT_TOKEN_BINDING
Definition: tls.h:1417
void(* TlsStateChangeCallback)(TlsContext *context, TlsState state)
TLS state change callback.
Definition: tls.h:2081
@ TLS_CERT_MLDSA65_SIGN
Definition: tls.h:1292
EdDSA public key.
Definition: eddsa.h:64
TlsClientAuthMode
Client authentication mode.
Definition: tls.h:1061
TlsKeyExchMethod
Key exchange methods.
Definition: tls.h:1223
@ TLS_EXT_SUPPORTED_GROUPS
Definition: tls.h:1403
bool_t fallbackScsvEnabled
Support for FALLBACK_SCSV.
Definition: tls.h:2675
@ TLS_SIGN_SCHEME_MLDSA87_ED448
Definition: tls.h:1383
error_t tlsSetSupportedGroups(TlsContext *context, const uint16_t *groups, uint_t length)
Specify the list of allowed ECDHE and FFDHE groups.
Definition: tls.c:656
@ TLS_EXT_HEARTBEAT
Definition: tls.h:1408
@ TLS_FLAG_WAIT_ALL
Definition: tls.h:1086
#define TLS_PREMASTER_SECRET_SIZE
Definition: tls.h:866
@ TLS_GROUP_NONE
Definition: tls.h:1494
@ TLS_GROUP_GC512B
Definition: tls.h:1533
void TlsCertificateVerify
CertificateVerify message.
Definition: tls.h:2002
uint8_t keyBlock[192]
Key material.
Definition: tls.h:2527
@ TLS_KEY_EXCH_DH_ANON
Definition: tls.h:1230
error_t(* TlsEcdhCallback)(TlsContext *context)
ECDH key agreement callback function.
Definition: tls.h:2154
const CipherAlgo * cipherAlgo
Definition: tls.h:2226
size_t rxBufferPos
Current position in RX buffer.
Definition: tls.h:2501
@ TLS_EXT_RENEGOTIATION_INFO
Definition: tls.h:1448
@ TLS_GROUP_SECT283K1
Definition: tls.h:1503
@ TLS_GROUP_SECT409K1
Definition: tls.h:1505
@ TLS_GROUP_EXPLICIT_PRIME_CURVE
Definition: tls.h:1549
error_t tlsSetClientAuthMode(TlsContext *context, TlsClientAuthMode mode)
Set client authentication mode (for servers only)
Definition: tls.c:521
@ TLS13_KEY_EXCH_DHE
Definition: tls.h:1243
bool_t encryptThenMac
Encrypt-then-MAC construction.
Definition: tls.h:2403
TlsAlert
Definition: tls.h:2042
TlsCertificateFormat certFormat
Certificate format.
Definition: tls.h:2645
@ TLS_HASH_ALGO_INTRINSIC
Definition: tls.h:1310
@ TLS_KEY_EXCH_ECDH_ECDSA
Definition: tls.h:1233
const char_t * tlsGetAlpnProtocol(TlsContext *context)
Get the name of the selected ALPN protocol.
Definition: tls.c:980
@ TLS_EXT_ENCRYPT_THEN_MAC
Definition: tls.h:1415
@ TLS_GROUP_FFDHE4096
Definition: tls.h:1538
RSA public key.
Definition: rsa.h:57
@ TLS_TYPE_APPLICATION_DATA
Definition: tls.h:1110
@ TLS_TYPE_CLIENT_HELLO
Definition: tls.h:1124
uint8_t fixedIvLen
Definition: tls.h:2232
@ TLS_CERT_GOST_SIGN256
Definition: tls.h:1285
@ TLS_STATE_SERVER_FINISHED
Definition: tls.h:1611
@ TLS_EXT_KEY_SHARE
Definition: tls.h:1437
Tls12DigitalSignature
Definition: tls.h:1898
uint16_t identifier
Definition: tls.h:2223
error_t tlsEnableReplayDetection(TlsContext *context, bool_t enabled)
Enable anti-replay mechanism (for DTLS only)
Definition: tls.c:1683
@ TLS_GROUP_SECT163K1
Definition: tls.h:1495
@ TLS_SIGN_SCHEME_GOSTR34102012_512B
Definition: tls.h:1367
error_t tlsSetBufferSize(TlsContext *context, size_t txBufferSize, size_t rxBufferSize)
Set TLS buffer size.
Definition: tls.c:543
DTLS 1.3 (Datagram Transport Layer Security)
@ TLS_EC_CURVE_TYPE_EXPLICIT_PRIME
Definition: tls.h:1572
@ TLS_ALERT_UNSUPPORTED_CERTIFICATE
Definition: tls.h:1176
size_t serverVerifyDataLen
Length of the server verify data.
Definition: tls.h:2512
error_t tlsSetServerName(TlsContext *context, const char_t *serverName)
Set the server name.
Definition: tls.c:425
@ TLS_TYPE_REQUEST_CONNECTION_ID
Definition: tls.h:1131
TlsEncryptionLevel level
Encryption level.
Definition: tls.h:2397
uint16_t epoch
Counter value incremented on every cipher state change.
Definition: tls.h:2385
bool_t fatalAlertReceived
A fatal alert message has been received from the peer.
Definition: tls.h:2483
@ TLS_TYPE_ALERT
Definition: tls.h:1108
error_t tlsSetCookieCallbacks(TlsContext *context, DtlsCookieGenerateCallback cookieGenerateCallback, DtlsCookieVerifyCallback cookieVerifyCallback, void *param)
Set cookie generation/verification callbacks (for DTLS only)
Definition: tls.c:1647
@ TLS_STATE_EARLY_DATA
Definition: tls.h:1587
size_t txBufferPos
Current position in TX buffer.
Definition: tls.h:2492
@ TLS_TYPE_SERVER_HELLO
Definition: tls.h:1125
@ TLS_HASH_ALGO_SHA384
Definition: tls.h:1308
TlsServerNameList
Definition: tls.h:1787
TlsClientAuthMode clientAuthMode
Client authentication mode.
Definition: tls.h:2478
uint32_t ticketLifetime
Lifetime of the ticket.
Definition: tls.h:2055
@ TLS_CERT_RSA_PSS_SIGN
Definition: tls.h:1287
@ TLS_SIGN_SCHEME_ECDSA_SHA1
Definition: tls.h:1352
uint8_t ticketPsk[TLS_MAX_HKDF_DIGEST_SIZE]
PSK associated with the ticket.
Definition: tls.h:2559
@ TLS_GROUP_GC256C
Definition: tls.h:1530
error_t tlsSetPrng(TlsContext *context, const PrngAlgo *prngAlgo, void *prngContext)
Set the pseudo-random number generator to be used.
Definition: tls.c:397
TlsSignatureScheme signScheme
Signature scheme used to sign the end entity certificate.
Definition: tls.h:2294
const char_t * tlsGetServerName(TlsContext *context)
Get the server name.
Definition: tls.c:475
@ TLS_TYPE_ENCRYPTED_EXTENSIONS
Definition: tls.h:1130
@ TLS_GROUP_SECT233K1
Definition: tls.h:1500
TlsSequenceNumber earlyDataSeqNum
Early data sequence number.
Definition: tls.h:2572
@ TLS_MAX_FRAGMENT_LENGTH_2048
Definition: tls.h:1470
error_t tlsSetPmtu(TlsContext *context, size_t pmtu)
Set PMTU value (for DTLS only)
Definition: tls.c:1589
@ TLS_SIGN_SCHEME_RSA_PKCS1_SHA256
Definition: tls.h:1340
error_t(* TlsSendQuicHandshakeMessageCallback)(TlsContext *context, TlsEncryptionLevel level, const uint8_t *data, size_t length, void *param)
Handshake message sending callback function.
Definition: tls.h:2193
@ TLS_CERT_DSS_EPHEMERAL_DH
Definition: tls.h:1280
size_t ticketLen
Length of the session ticket.
Definition: tls.h:2466
@ TLS_GROUP_SECP384R1
Definition: tls.h:1518
General definitions for cryptographic algorithms.
@ TLS_GROUP_SECP192K1
Definition: tls.h:1512
size_t remoteQuicTransportParamsLen
Length of the remote QUIC transport parameters.
Definition: tls.h:2739
uint8_t exporterMasterSecret[TLS_MAX_HKDF_DIGEST_SIZE]
Definition: tls.h:2554
RSA public-key cryptography standard.
size_t rxBufferMaxLen
Maximum number of plaintext data the RX buffer can hold.
Definition: tls.h:2498
uint16_t clientVersion
Latest version supported by the client.
Definition: tls.h:2456
@ TLS_FLAG_WAIT_ACK
Definition: tls.h:1089
@ TLS_CERT_MLDSA87_SIGN
Definition: tls.h:1293
@ TLS_ALERT_UNRECOGNIZED_NAME
Definition: tls.h:1196
@ TLS_EXT_COOKIE
Definition: tls.h:1431
error_t tlsSaveSessionState(const TlsContext *context, TlsSessionState *session)
Save TLS session.
Definition: tls.c:3004
@ TLS_STATE_CLIENT_CERTIFICATE_VERIFY
Definition: tls.h:1602
@ TLS_SIGN_SCHEME_ECDSA_BP512R1_TLS13_SHA512
Definition: tls.h:1358
@ TLS_TYPE_CERTIFICATE_VERIFY
Definition: tls.h:1137
@ TLS_STATE_SERVER_CHANGE_CIPHER_SPEC
Definition: tls.h:1609
EcdhContext ecdhContext
ECDH context.
Definition: tls.h:2580
const TlsRenegoInfo * renegoInfo
RenegotiationInfo extension.
Definition: tls.h:2337
void * quicHandle
Opaque pointer passed to the QUIC-specific callbacks.
Definition: tls.h:2735
@ TLS_EXT_CLIENT_CERTIFICATE_URL
Definition: tls.h:1395
@ TLS_ALERT_MISSING_EXTENSION
Definition: tls.h:1193
#define TLS_MAX_CERTIFICATES
Definition: tls.h:285
DsaPublicKey peerDsaPublicKey
Peer's DSA public key.
Definition: tls.h:2593
size_t recordSizeLimit
Maximum size of record in octets.
Definition: tls.h:2400
TlsSignSchemeList
Definition: tls.h:1686
uint8_t recordIvLen
Definition: tls.h:2233
@ TLS_SIGN_ALGO_ED25519
Definition: tls.h:1325
typedef __packed_struct
Sequence number.
Definition: tls.h:1651
MD5 algorithm context.
Definition: md5.h:62
DSA (Digital Signature Algorithm)
@ TLS_TRANSPORT_PROTOCOL_EAP
Definition: tls.h:1041
@ TLS_GROUP_SECT283R1
Definition: tls.h:1504
uint_t numCipherSuites
Number of cipher suites in the list.
Definition: tls.h:2432
TlsProtocolName
Definition: tls.h:1798
@ TLS_STATE_SERVER_HELLO_3
Definition: tls.h:1592
@ TLS_HASH_ALGO_SHA256
Definition: tls.h:1307
TlsExtensionType
TLS extension types.
Definition: tls.h:1392
uint_t numSupportedSignAlgos
Number of signature algorithms in the list.
Definition: tls.h:2534
@ TLS_ALERT_USER_CANCELED
Definition: tls.h:1191
@ TLS_CERT_ED448_SIGN
Definition: tls.h:1290
bool_t ackTimerRunning
The ACK timer is running.
Definition: tls.h:2729
Block cipher modes of operation.
uint8_t * localQuicTransportParams
Local QUIC transport parameters.
Definition: tls.h:2736
systime_t ticketTimestamp
Timestamp to manage ticket lifetime.
Definition: tls.h:2467
@ TLS_EXT_CERTIFICATE_AUTHORITIES
Definition: tls.h:1433
@ TLS_STATE_END_OF_EARLY_DATA
Definition: tls.h:1612
@ TLS_FLAG_NO_DELAY
Definition: tls.h:1090
const uint16_t * supportedSignAlgos
List of supported signature algorithms.
Definition: tls.h:2533
error_t tlsSetEcdhCallback(TlsContext *context, TlsEcdhCallback ecdhCallback)
Register ECDH key agreement callback function.
Definition: tls.c:773
bool_t pskKeModeSupported
PSK key establishment supported by the client.
Definition: tls.h:2546
@ TLS_EXT_TICKET_REQUEST
Definition: tls.h:1443
@ TLS_EC_CURVE_TYPE_EXPLICIT_CHAR2
Definition: tls.h:1573
@ TLS_CERT_RSA_SIGN
Definition: tls.h:1275
@ TLS_EC_POINT_FORMAT_UNCOMPRESSED
Definition: tls.h:1560
@ TLS_EXT_DNSSEC_CHAIN
Definition: tls.h:1444
Dtls13RecordNumber ackRecords[DTLS13_MAX_ACK_RECORDS]
List of records received and processed.
Definition: tls.h:2727
@ TLS_KEY_EXCH_SRP_SHA
Definition: tls.h:1240
error_t tlsSetTicketCallbacks(TlsContext *context, TlsTicketEncryptCallback ticketEncryptCallback, TlsTicketDecryptCallback ticketDecryptCallback, void *param)
Set ticket encryption/decryption callbacks.
Definition: tls.c:1557
@ TLS_GROUP_SECT409R1
Definition: tls.h:1506
@ TLS_FLAG_BREAK_CRLF
Definition: tls.h:1088
@ TLS_SIGN_SCHEME_GOSTR34102012_512C
Definition: tls.h:1368
@ TLS_GROUP_BRAINPOOLP512R1
Definition: tls.h:1522
TlsSocketReceiveCallback socketReceiveCallback
Socket receive callback function.
Definition: tls.h:2426
@ TLS_GROUP_FFDHE2048
Definition: tls.h:1536
error_t tlsWrite(TlsContext *context, const void *data, size_t length, size_t *written, uint_t flags)
Send application data to the remote host using TLS.
Definition: tls.c:2145
@ TLS_STATE_CLIENT_APP_TRAFFIC_KEYS
Definition: tls.h:1606
bool_t sessionTicketEnabled
Session ticket mechanism enabled.
Definition: tls.h:2653
const TlsExtension * extendedMasterSecret
ExtendedMasterSecret extension.
Definition: tls.h:2331
@ TLS_CLIENT_AUTH_NONE
Definition: tls.h:1062
@ TLS_TYPE_HELLO_VERIFY_REQUEST
Definition: tls.h:1126
@ TLS_GROUP_SECP160K1
Definition: tls.h:1509
#define TLS_CONTEXT_PRIVATE
Definition: tls.h:901
@ TLS_TYPE_CLIENT_KEY_EXCHANGE
Definition: tls.h:1138
@ TLS_KEY_EXCH_DHE_PSK
Definition: tls.h:1238
uint_t keyUpdateCount
Count of consecutive KeyUpdate messages.
Definition: tls.h:2695
@ TLS_STATE_NEW_SESSION_TICKET
Definition: tls.h:1607
bool_t resume
The connection is established by resuming a session.
Definition: tls.h:2481
uint32_t ticketAgeAdd
Random value used to obscure the age of the ticket.
Definition: tls.h:2259
@ TLS_CERT_SM2_SIGN
Definition: tls.h:1288
@ TLS_FLAG_DELAY
Definition: tls.h:1091
TlsCompressMethods
Definition: tls.h:1675
size_t clientHelloDigestLen
Length of Hash(ClientHello1)
Definition: tls.h:2725
systime_t ticketTimestamp
Timestamp to manage ticket lifetime.
Definition: tls.h:2054
@ TLS_CA_ROOT_KEY_ID_TYPE_PRE_AGREED
Definition: tls.h:1481
@ TLS_EXT_TRANSPARENCY_INFO
Definition: tls.h:1438
@ TLS_EXT_STATUS_REQUEST_V2
Definition: tls.h:1410
size_t txBufferMaxLen
Maximum number of plaintext data the TX buffer can hold.
Definition: tls.h:2489
@ TLS_GROUP_MLKEM512
Definition: tls.h:1542
TlsMaxFragmentLength
Maximum fragment length.
Definition: tls.h:1467
@ TLS_STATE_CLIENT_CHANGE_CIPHER_SPEC
Definition: tls.h:1603
bool_t certAuthoritiesEnabled
Support for CertificateAuthorities extension.
Definition: tls.h:2666
error_t(* TlsCertVerifyCallback)(TlsContext *context, const X509CertInfo *certInfo, uint_t pathLen, void *param)
Certificate verification callback function.
Definition: tls.h:2120
@ TLS_ALERT_TOO_MANY_CIDS_REQUESTED
Definition: tls.h:1185
TlsCertList
Definition: tls.h:1697
@ TLS_EXT_EC_POINT_FORMATS
Definition: tls.h:1404
TlsCompressMethod
Compression methods.
Definition: tls.h:1212
void * ticketParam
Opaque pointer passed to the ticket callbacks.
Definition: tls.h:2658
@ TLS_EXT_TLS_CERT_WITH_EXTERN_PSK
Definition: tls.h:1425
@ TLS_SIGN_ALGO_GOSTR34102012_512
Definition: tls.h:1328
@ TLS_STATE_NEW_SESSION_TICKET_2
Definition: tls.h:1608
@ TLS_GROUP_SECP521R1
Definition: tls.h:1519
@ TLS_GROUP_SECP192R1
Definition: tls.h:1513
@ TLS_CERT_GOST_SIGN512
Definition: tls.h:1286
@ TLS_EXT_ALPN
Definition: tls.h:1409
@ TLS_GROUP_FFDHE3072
Definition: tls.h:1537
@ TLS_ALERT_PROTOCOL_VERSION
Definition: tls.h:1187
Hello extensions.
Definition: tls.h:2304
Tls13KeyShareList
Definition: tls13_misc.h:220
@ TLS_GROUP_SECP160R1
Definition: tls.h:1510
@ TLS_ALERT_DECRYPTION_FAILED
Definition: tls.h:1170
TlsCertificateType
Certificate types.
Definition: tls.h:1273
TlsCertDesc * cert
Pointer to the currently selected certificate.
Definition: tls.h:2450
size_t encKeyLen
Length of the encryption key.
Definition: tls.h:2370
#define TLS_MASTER_SECRET_SIZE
Definition: tls.h:859
size_t privateKeyLen
Length of the private key.
Definition: tls.h:2291
@ TLS_GROUP_BRAINPOOLP384R1_TLS13
Definition: tls.h:1526
@ TLS_HASH_ALGO_MD5
Definition: tls.h:1304
Certificate descriptor.
Definition: tls.h:2287
const TlsExtension * quicTransportParams
QUIC transport parameters extension.
Definition: tls.h:2340
uint8_t secret[TLS_MASTER_SECRET_SIZE]
Master secret.
Definition: tls.h:2053
uint_t size
Maximum number of entries.
Definition: tls.h:2277
@ TLS_SIGN_SCHEME_GOSTR34102012_256C
Definition: tls.h:1364
TlsHashAlgo pskHashAlgo
Hash algorithm associated with the PSK.
Definition: tls.h:2616
uint8_t random[32]
Definition: tls.h:1940
@ TLS_STATE_HANDSHAKE_TRAFFIC_KEYS
Definition: tls.h:1593
@ TLS_KEY_EXCH_RSA_PSK
Definition: tls.h:1237
@ TLS_FLAG_BREAK_CHAR
Definition: tls.h:1087
Mutex object.
@ TLS_EXT_USER_MAPPING
Definition: tls.h:1399
Sha1Context * transcriptSha1Context
SHA-1 context used to compute verify data.
Definition: tls.h:2529
char_t * serverName
ServerName extension.
Definition: tls.h:2265
error_t tlsSetConnectionEnd(TlsContext *context, TlsConnectionEnd entity)
Set operation mode (client or server)
Definition: tls.c:371
uint32_t systime_t
System time.
@ TLS_CLIENT_AUTH_OPTIONAL
Definition: tls.h:1063
error_t tlsSetMaxEarlyDataSize(TlsContext *context, size_t maxEarlyDataSize)
Send the maximum amount of 0-RTT data the server can accept.
Definition: tls.c:1711
Collection of AEAD algorithms.
EC public key.
Definition: ec.h:421
size_t ticketPskLen
Length of the PSK associated with the ticket.
Definition: tls.h:2560
TlsRecord
Definition: tls.h:1911
TlsQuicCallbacks quicCallbacks
QUIC-specific callback functions.
Definition: tls.h:2734
uint8_t snKey[32]
Sequence number encryption key.
Definition: tls.h:2392
@ TLS_TYPE_SERVER_KEY_EXCHANGE
Definition: tls.h:1134
uint8_t clientHelloDigest[48]
Hash(ClientHello1)
Definition: tls.h:2724
@ TLS_GROUP_GC512C
Definition: tls.h:1534
DtlsCookieGenerateCallback cookieGenerateCallback
Cookie generation callback function.
Definition: tls.h:2703
TlsPskCallback pskCallback
PSK callback function.
Definition: tls.h:2614
@ TLS_EC_CURVE_TYPE_NAMED_CURVE
Definition: tls.h:1574
@ TLS_TYPE_NONE
Definition: tls.h:1106
uint32_t maxEarlyDataSize
Maximum amount of 0-RTT data that the client is allowed to send.
Definition: tls.h:2262
const TlsExtension * selectedIdentity
PreSharedKey extension (ServerHello)
Definition: tls.h:2351
@ TLS_TYPE_EKT_KEY
Definition: tls.h:1145
uint16_t namedGroup
ECDHE or FFDHE named group.
Definition: tls.h:2474
error_t(* TlsEcdsaSignCallback)(TlsContext *context, const uint8_t *digest, size_t digestLen, EcdsaSignature *signature)
ECDSA signature generation callback function.
Definition: tls.h:2161
const uint16_t * cipherSuites
List of supported cipher suites.
Definition: tls.h:2431
char char_t
Definition: compiler_port.h:55
error_t(* TlsSendQuicAlertMessageCallback)(TlsContext *context, uint8_t description, void *param)
Alert message sending callback function.
Definition: tls.h:2201
uint16_t ticketCipherSuite
Cipher suite associated with the ticket.
Definition: tls.h:2563
uint16_t txMsgSeq
Send sequence number.
Definition: tls.h:2711
@ TLS_GROUP_SECP224R1
Definition: tls.h:1515
GCM context.
Definition: gcm.h:64
uint8_t ticket[]
Definition: tls.h:2013
@ TLS_KEY_EXCH_NONE
Definition: tls.h:1224
TlsNameType
Name types.
Definition: tls.h:1457
const TlsExtension * clientCertType
Definition: tls.h:2323
size_t localQuicTransportParamsLen
Length of the local QUIC transport parameters.
Definition: tls.h:2737
@ TLS_CA_ROOT_KEY_ID_TYPE_CERT_SHA1_HASH
Definition: tls.h:1484
@ TLS13_KEY_EXCH_PSK_ECDHE
Definition: tls.h:1249
@ TLS_ENCRYPTION_LEVEL_APPLICATION
Definition: tls.h:1634
@ TLS_STATE_CLIENT_HELLO_2
Definition: tls.h:1586
@ TLS_ALERT_BAD_CERTIFICATE
Definition: tls.h:1175
bool_t replayDetectionEnabled
Anti-replay mechanism enabled.
Definition: tls.h:2720
const HashAlgo * hashAlgo
Definition: tls.h:2228
TlsContentType
Content type.
Definition: tls.h:1105
@ TLS_STATE_CLOSING
Definition: tls.h:1620
@ TLS_STATE_SERVER_CERTIFICATE_VERIFY
Definition: tls.h:1597
size_t rxBufferLen
Number of bytes available for reading.
Definition: tls.h:2500
@ TLS_EXT_EXTERNAL_SESSION_ID
Definition: tls.h:1441
@ TLS_ALERT_INAPPROPRIATE_FALLBACK
Definition: tls.h:1190
uint8_t msgType
@ TLS_EARLY_DATA_ACCEPTED
Definition: tls.h:1075
error_t tlsSetRpkVerifyCallback(TlsContext *context, TlsRpkVerifyCallback rpkVerifyCallback)
Register the raw public key verification callback function.
Definition: tls.c:1193
uint8_t macKey[48]
MAC key.
Definition: tls.h:2367
@ TLS_CA_ROOT_KEY_ID_TYPE_X509_NAME
Definition: tls.h:1483
TlsServerHello
Definition: tls.h:1956
void TlsClientKeyExchange
ClientKeyExchange message.
Definition: tls.h:1995
@ TLS_STATE_SERVER_CERTIFICATE
Definition: tls.h:1595
TlsEcCurveType
EC curve types.
Definition: tls.h:1571
@ TLS_SIGN_SCHEME_RSA_PKCS1_SHA256_LEGACY
Definition: tls.h:1343
error_t tlsTick(TlsContext *context)
Handle periodic operations.
Definition: tls.c:2787
TlsPlaintextSessionState
Definition: tls.h:2059
@ TLS_CLIENT_AUTH_REQUIRED
Definition: tls.h:1064
error_t tlsExportChannelBinding(TlsContext *context, const char_t *type, uint8_t *output, size_t *length)
Export channel binding value.
Definition: tls.c:2044
@ TLS_EXT_PADDING
Definition: tls.h:1414
@ TLS_ALERT_LEVEL_FATAL
Definition: tls.h:1157
TLS session state.
Definition: tls.h:2244
error_t tlsInitSessionState(TlsSessionState *session)
Initialize session state.
Definition: tls.c:2983
size_t rxFragQueueLen
Length of the reassembly queue.
Definition: tls.h:2715
TlsSetQuicEncryptionKeyCallback setEncryptionKeys
Definition: tls.h:2211
@ TLS_GROUP_MLKEM1024
Definition: tls.h:1544
@ TLS_GROUP_SECT193R2
Definition: tls.h:1499
uint16_t versionMax
Maximum version accepted by the implementation.
Definition: tls.h:2459
const TlsSignSchemeList * certSignAlgoList
SignatureAlgorithmsCert extension.
Definition: tls.h:2311
@ TLS_STATE_CLIENT_KEY_EXCHANGE
Definition: tls.h:1601
const CipherAlgo * cipherAlgo
Cipher algorithm.
Definition: tls.h:2375
uint8_t verifyDataLen
Definition: tls.h:2235
error_t tlsSetCipherSuites(TlsContext *context, const uint16_t *cipherSuites, uint_t length)
Specify the list of allowed cipher suites.
Definition: tls.c:627
TlsTransportProtocol
TLS transport protocols.
Definition: tls.h:1037
error_t(* DtlsCookieVerifyCallback)(TlsContext *context, const DtlsClientParameters *clientParams, const uint8_t *cookie, size_t length, void *param)
DTLS cookie verification callback function.
Definition: dtls_misc.h:256
@ TLS_SIGN_SCHEME_SM2SIG_SM3
Definition: tls.h:1359
@ TLS_TYPE_FINISHED
Definition: tls.h:1139
void TlsHelloRequest
HelloRequest message.
Definition: tls.h:1930
@ TLS_GROUP_SECT193R1
Definition: tls.h:1498
@ TLS_SIGN_SCHEME_RSA_PKCS1_SHA512
Definition: tls.h:1342
bool_t serverCertTypeExtReceived
The ServerCertType extension has been received.
Definition: tls.h:2649
TlsCaRootKeyIdType
CA root key identifier type.
Definition: tls.h:1480
@ TLS_STATE_CLIENT_CERTIFICATE
Definition: tls.h:1600
@ TLS_SIGN_SCHEME_ECDSA_BP384R1_TLS13_SHA384
Definition: tls.h:1357
TlsCertVerifyCallback certVerifyCallback
Certificate verification callback function.
Definition: tls.h:2448
void * certVerifyParam
Opaque pointer passed to the certificate verification callback.
Definition: tls.h:2449
@ TLS_SIGN_SCHEME_ED448
Definition: tls.h:1361
error_t tlsWriteEarlyData(TlsContext *context, const void *data, size_t length, size_t *written, uint_t flags)
Send early data to the remote TLS server.
Definition: tls.c:1740
@ TLS_STATE_CLIENT_CHANGE_CIPHER_SPEC_2
Definition: tls.h:1604
@ TLS13_KEY_EXCH_HYBRID
Definition: tls.h:1246
TlsHashAlgo ticketHashAlgo
Hash algorithm associated with the ticket.
Definition: tls.h:2260
uint_t alertCount
Count of consecutive warning alerts.
Definition: tls.h:2683
error_t tlsSetDhParameters(TlsContext *context, const char_t *params, size_t length)
Import Diffie-Hellman parameters.
Definition: tls.c:745
@ TLS_ALERT_CERTIFICATE_EXPIRED
Definition: tls.h:1178
@ TLS_STATE_ENCRYPTED_EXTENSIONS
Definition: tls.h:1594
@ TLS_EXT_SERVER_CERT_TYPE
Definition: tls.h:1413
@ TLS_KEY_EXCH_PSK
Definition: tls.h:1236
@ TLS_STATE_INIT
Definition: tls.h:1584
uint8_t * certRequestContext
Certificate request context.
Definition: tls.h:2543
@ TLS_EXT_PASSWORD_SALT
Definition: tls.h:1423
@ TLS_KEY_EXCH_ECDHE_PSK
Definition: tls.h:1239
Dtls13RetransmitState retransmitState
Retransmission state.
Definition: tls.h:2394
@ TLS_STATE_CLIENT_FINISHED_ACK
Definition: tls.h:1616
@ TLS_SIGN_SCHEME_RSA_PKCS1_SHA384
Definition: tls.h:1341
@ TLS_NAME_TYPE_HOSTNAME
Definition: tls.h:1458
TlsSocketSendCallback socketSendCallback
Socket send callback function.
Definition: tls.h:2425
@ TLS_ALERT_NO_APPLICATION_PROTOCOL
Definition: tls.h:1202
const PrngAlgo * prngAlgo
Pseudo-random number generator to be used.
Definition: tls.h:2428
@ TLS_CERT_RSA_FIXED_ECDH
Definition: tls.h:1283
TlsEncryptionEngine decryptionEngine[TLS_MAX_DECRYPTION_ENGINES]
Decryption engines.
Definition: tls.h:2515
TlsClientHello
Definition: tls.h:1943
#define TLS_MAX_HKDF_DIGEST_SIZE
Definition: tls.h:987
@ TLS_TYPE_HEARTBEAT
Definition: tls.h:1111
@ TLS_SIGN_SCHEME_ECDSA_SECP384R1_SHA384
Definition: tls.h:1354
systime_t clientHelloTimestamp
Time at which the ClientHello message was sent.
Definition: tls.h:2541
TlsSignatureAlgo
Signature algorithms.
Definition: tls.h:1320
uint8_t serverRandom[TLS_RANDOM_SIZE]
Server random value.
Definition: tls.h:2506
size_t certRequestContextLen
Length of the certificate request context.
Definition: tls.h:2544
Tls13PskKeModeList
Definition: tls13_misc.h:231
@ TLS_EXT_SRP
Definition: tls.h:1405
error_t tlsSetEcdsaVerifyCallback(TlsContext *context, TlsEcdsaVerifyCallback ecdsaVerifyCallback)
Register ECDSA signature verification callback function.
Definition: tls.c:826
@ TLS_CONNECTION_END_CLIENT
Definition: tls.h:1051
char_t * pskIdentityHint
PSK identity hint.
Definition: tls.h:2613
TlsCipherSuiteInfo cipherSuite
Negotiated cipher suite.
Definition: tls.h:2471
bool_t tlsIsRxReady(TlsContext *context)
Check whether some data is available in the receive buffer.
Definition: tls.c:2576
uint8_t clientAppTrafficSecret[TLS_MAX_HKDF_DIGEST_SIZE]
Definition: tls.h:2552
@ TLS_MAX_FRAGMENT_LENGTH_1024
Definition: tls.h:1469
TlsAlertLevel
Alert level.
Definition: tls.h:1155
@ TLS_EXT_CACHED_INFO
Definition: tls.h:1418
uint_t changeCipherSpecCount
Count of consecutive ChangeCipherSpec messages.
Definition: tls.h:2691
Common interface for encryption algorithms.
Definition: crypto.h:1285
@ TLS_TYPE_CERTIFICATE_REQUEST
Definition: tls.h:1135
uint8_t encKeyLen
Definition: tls.h:2231
@ TLS_EXT_PRE_SHARED_KEY
Definition: tls.h:1428
@ TLS_EC_POINT_FORMAT_ANSI_X962_COMPRESSED_PRIME
Definition: tls.h:1561
void tlsFree(TlsContext *context)
Release TLS context.
Definition: tls.c:2816
systime_t timestamp
Timestamp to manage lifetime.
Definition: tls.h:2364
@ TLS_GROUP_SECT571R1
Definition: tls.h:1508
error_t tlsRead(TlsContext *context, void *data, size_t size, size_t *received, uint_t flags)
Receive application data from a the remote host using TLS.
Definition: tls.c:2286
DtlsSequenceNumber
Definition: dtls_misc.h:148
@ TLS_GROUP_FFDHE_MAX
Definition: tls.h:1541
TlsCache * cache
TLS session cache.
Definition: tls.h:2452
TlsState state
TLS handshake finite state machine.
Definition: tls.h:2418
TlsContentType rxBufferType
Type of data that resides in the RX buffer.
Definition: tls.h:2499
char_t * serverName
Fully qualified DNS hostname of the server.
Definition: tls.h:2437
@ TLS_SIGN_ALGO_RSA
Definition: tls.h:1322
size_t rxRecordPos
Current position in the TLS record.
Definition: tls.h:2503
@ TLS_STATE_FINAL_ACK
Definition: tls.h:1614
char_t hostname[]
Definition: tls.h:1775
@ TLS_TYPE_TLS12_CID
Definition: tls.h:1112
error_t tlsSetPskIdentity(TlsContext *context, const char_t *pskIdentity)
Set the PSK identity to be used by the client.
Definition: tls.c:1069
uint16_t version
TLS protocol version.
Definition: tls.h:2245
@ TLS_TYPE_SUPPLEMENTAL_DATA
Definition: tls.h:1142
bool_t sessionTicketExtSent
The SessionTicket extension has been sent.
Definition: tls.h:2655
SHA-1 algorithm context.
Definition: sha1.h:62
bool_t etmExtReceived
The EncryptThenMac extension has been received.
Definition: tls.h:2637
TlsTrustedAuthorities
Definition: tls.h:1730
@ TLS_CERT_ECDSA_SIGN
Definition: tls.h:1282
@ TLS_ALERT_BAD_CERTIFICATE_STATUS_RESPONSE
Definition: tls.h:1197
const TlsExtension * recordSizeLimit
RecordSizeLimit extension.
Definition: tls.h:2316
@ TLS_GROUP_X25519
Definition: tls.h:1523
QUIC callback functions.
Definition: tls.h:2210
systime_t startTime
Definition: tls.h:2701
@ TLS_KEY_EXCH_DHE_DSS
Definition: tls.h:1229
error_t(* TlsSetQuicEncryptionKeyCallback)(TlsContext *context, TlsEncryptionLevel level, const uint8_t *txKey, const uint8_t *rxKey, size_t keyLen, void *param)
Encryption key update callback function.
Definition: tls.h:2184
bool_t clientCertRequested
This flag tells whether the client certificate is requested.
Definition: tls.h:2479
@ TLS_EXT_TLS_FLAG
Definition: tls.h:1447
@ TLS_TRANSPORT_PROTOCOL_STREAM
Definition: tls.h:1038
uint16_t version
Negotiated TLS version.
Definition: tls.h:2366
@ TLS_SIGN_SCHEME_GOSTR34102012_256D
Definition: tls.h:1365
uint_t newSessionTicketCount
Number of NewSessionTicket messages that have been sent.
Definition: tls.h:2557
EddsaPublicKey peerEddsaPublicKey
Peer's EdDSA public key.
Definition: tls.h:2601
error_t tlsSetTransportProtocol(TlsContext *context, TlsTransportProtocol transportProtocol)
Set the transport protocol to be used.
Definition: tls.c:340
TlsEcdhCallback ecdhCallback
Definition: tls.h:2440
bool_t earlyDataEnabled
EarlyData is enabled.
Definition: tls.h:2569
const char_t * certChain
End entity certificate chain (PEM format)
Definition: tls.h:2288
bool_t recordSizeLimitExtReceived
The RecordSizeLimit extension has been received.
Definition: tls.h:2626
RsaPublicKey peerRsaPublicKey
Peer's RSA public key.
Definition: tls.h:2589
bool_t unknownProtocolsAllowed
Unknown ALPN protocols allowed.
Definition: tls.h:2630
@ TLS_EXT_SIGNATURE_ALGORITHMS
Definition: tls.h:1406
uint32_t ticketLifetime
Lifetime of the ticket.
Definition: tls.h:2258
Common interface for hash algorithms.
Definition: crypto.h:1243
@ TLS_CERT_NONE
Definition: tls.h:1274
char_t * selectedProtocol
Selected ALPN protocol.
Definition: tls.h:2632
error_t(* TlsPskCallback)(TlsContext *context, const uint8_t *pskIdentity, size_t pskIdentityLen)
Pre-shared key callback function.
Definition: tls.h:2112
const TlsServerNameList * serverNameList
ServerName extension.
Definition: tls.h:2307
TlsEarlyDataStatus tlsGetEarlyDataStatus(TlsContext *context)
Check whether the server has accepted or rejected the early data.
Definition: tls.c:1853
@ TLS_GROUP_GC256A
Definition: tls.h:1528
size_t trustedCaListLen
Total length of the trusted CA list.
Definition: tls.h:2447
systime_t retransmitTimestamp
Time at which the datagram was sent.
Definition: tls.h:2708
const TlsExtension * selectedVersion
SupportedVersions extension (ServerHello)
Definition: tls.h:2306
@ TLS_EXT_POST_HANDSHAKE_AUTH
Definition: tls.h:1435
TlsSequenceNumber seqNum
TLS sequence number.
Definition: tls.h:2383
error_t tlsLoadCertificate(TlsContext *context, uint_t index, const char_t *certChain, size_t certChainLen, const char_t *privateKey, size_t privateKeyLen, const char_t *password)
Load entity's certificate.
Definition: tls.c:1256
uint8_t clientEarlyTrafficSecret[TLS_MAX_HKDF_DIGEST_SIZE]
Definition: tls.h:2549
@ TLS_SIGN_SCHEME_ECDSA_SECP256R1_SHA256
Definition: tls.h:1353
@ TLS_STATE_SERVER_CHANGE_CIPHER_SPEC_2
Definition: tls.h:1610
@ TLS_GROUP_SECT233R1
Definition: tls.h:1501
uint8_t flags
Definition: tcp.h:358
void * cipherContext
Cipher context.
Definition: tls.h:2376
@ TLS_TYPE_NEW_SESSION_TICKET
Definition: tls.h:1127
TlsEcdsaSignCallback ecdsaSignCallback
Definition: tls.h:2441
@ TLS_SIGN_SCHEME_MLDSA87_ECDSA_SECP384R1_SHA384
Definition: tls.h:1374
TlsNamedGroup
Named groups.
Definition: tls.h:1493
TlsSendQuicHandshakeMessageCallback sendHandshakeMessage
Definition: tls.h:2212
@ TLS_TYPE_HELLO_REQUEST
Definition: tls.h:1123
bool_t earlyDataRejected
The 0-RTT data have been rejected by the server.
Definition: tls.h:2570
uint16_t ticketLen
Definition: tls.h:2012
const char_t * privateKey
Private key (PEM format)
Definition: tls.h:2290
TlsSignatureScheme
Signature schemes.
Definition: tls.h:1337
error_t tlsSetPskIdentityHint(TlsContext *context, const char_t *pskIdentityHint)
Set the PSK identity hint to be used by the server.
Definition: tls.c:1118
@ TLS_EXT_STATUS_REQUEST
Definition: tls.h:1398
void(* TlsKeyLogCallback)(TlsContext *context, const char_t *key)
Key logging callback function (for debugging purpose only)
Definition: tls.h:2177
size_t macKeyLen
Length of the MAC key.
Definition: tls.h:2368
Tls13PskIdentityList
Definition: tls13_misc.h:253
@ TLS_TYPE_HELLO_RETRY_REQUEST
Definition: tls.h:1129
bool_t updatedClientHelloReceived
An updated ClientHello message has been received.
Definition: tls.h:2542
bool_t tlsIsTxReady(TlsContext *context)
Check whether some data is ready for transmission.
Definition: tls.c:2542
unsigned int uint_t
Definition: compiler_port.h:57
GcmContext * gcmContext
GCM context.
Definition: tls.h:2381
error_t tlsSetPreferredGroup(TlsContext *context, uint16_t group)
Specify the preferred ECDHE or FFDHE group.
Definition: tls.c:683
TlsFlags
Flags used by read and write functions.
Definition: tls.h:1084
@ TLS_GROUP_SECT163R1
Definition: tls.h:1496
@ TLS_ALERT_CERTIFICATE_REVOKED
Definition: tls.h:1177
error_t tlsEnableSecureRenegotiation(TlsContext *context, bool_t enabled)
Enable secure renegotiation.
Definition: tls.c:1503
size_t txBufferLen
Number of bytes that are pending to be sent.
Definition: tls.h:2491
@ TLS_GROUP_MLKEM768
Definition: tls.h:1543
TlsSupportedGroupList
Definition: tls.h:1820
uint_t retransmitCount
Retransmission counter.
Definition: tls.h:2707
uint16_t rxRecordVersion
Version of the incoming record.
Definition: tls.h:2718
@ TLS_STATE_SERVER_HELLO_DONE
Definition: tls.h:1599
size_t recordIvLen
Length of the IV.
Definition: tls.h:2373
@ TLS_STATE_SERVER_HELLO_2
Definition: tls.h:1591
@ TLS_EXT_USE_SRTP
Definition: tls.h:1407
@ TLS_ALERT_HANDSHAKE_FAILURE
Definition: tls.h:1173
@ TLS_SIGN_SCHEME_MLDSA65_RSA4096_PKCS1_SHA384
Definition: tls.h:1379
@ TLS_STATE_CLIENT_FINISHED
Definition: tls.h:1605
int_t selectedIdentity
Selected PSK identity.
Definition: tls.h:2545
uint8_t iv[48]
Initialization vector.
Definition: tls.h:2371
uint8_t macKeyLen
Definition: tls.h:2230
@ TLS_STATE_KEY_UPDATE_ACK
Definition: tls.h:1619
@ TLS_CERT_DSS_FIXED_DH
Definition: tls.h:1278
DtlsCookieVerifyCallback cookieVerifyCallback
Cookie verification callback function.
Definition: tls.h:2704
#define TLS_MAX_ENCRYPTION_ENGINES
Definition: tls.h:994
TlsSupportedVersionList
Definition: tls.h:1764
Legacy definitions.
@ TLS_ALERT_INTERNAL_ERROR
Definition: tls.h:1189
@ TLS_CERT_RSA_FIXED_DH
Definition: tls.h:1277
const uint16_t * supportedGroups
List of supported named groups.
Definition: tls.h:2434
error_t tlsEnableFallbackScsv(TlsContext *context, bool_t enabled)
Perform fallback retry (for clients only)
Definition: tls.c:1529
@ TLS_TYPE_KEY_UPDATE
Definition: tls.h:1143
@ TLS_SIGN_ALGO_ECDSA
Definition: tls.h:1324
const TlsExtension * encryptThenMac
EncryptThenMac extension.
Definition: tls.h:2328
TlsCertDesc certs[TLS_MAX_CERTIFICATES]
End entity certificates (PEM format)
Definition: tls.h:2445
error_t(* TlsTicketDecryptCallback)(TlsContext *context, const uint8_t *ciphertext, size_t ciphertextLen, uint8_t *plaintext, size_t *plaintextLen, void *param)
Ticket decryption callback function.
Definition: tls.h:2145
TlsNewSessionTicket
Definition: tls.h:2014
TlsSignatureScheme signScheme
Signature scheme to be used.
Definition: tls.h:2473
@ TLS_KEY_EXCH_DHE_RSA
Definition: tls.h:1227
bool_t trustedCaKeysEnabled
Support for TrustedCaKeys extension.
Definition: tls.h:2662
error_t tlsEnableSessionTickets(TlsContext *context, bool_t enabled)
Enable session ticket mechanism.
Definition: tls.c:1424
#define TlsEncryptionEngine
Definition: tls.h:40
uint16_t pskCipherSuite
Cipher suite associated with the PSK.
Definition: tls.h:2615
bool_t wrongKeyShare
Invalid key share.
Definition: tls.h:2475
bool_t extendedMasterSecret
Extended master secret computation.
Definition: tls.h:2252
@ TLS_SIGN_SCHEME_MLDSA65_ECDSA_SECP384R1_SHA384
Definition: tls.h:1373
error_t tlsSetTrustedCaList(TlsContext *context, const char_t *trustedCaList, size_t length)
Import a trusted CA list.
Definition: tls.c:1221
void TlsServerKeyExchange
ServerKeyExchange message.
Definition: tls.h:1970
bool_t earlyDataExtReceived
The EarlyData extension has been received.
Definition: tls.h:2571
const HashAlgo * prfHashAlgo
Definition: tls.h:2229
@ TLS_GROUP_FFDHE8192
Definition: tls.h:1540
TlsCertTypeList
Definition: tls.h:1842
uint8_t serverAppTrafficSecret[TLS_MAX_HKDF_DIGEST_SIZE]
Definition: tls.h:2553
const TlsSupportedGroupList * supportedGroupList
SupportedGroups extension.
Definition: tls.h:2308
TlsNamedGroup namedCurve
Named curve used to generate the EC public key.
Definition: tls.h:2295
ECDH context.
Definition: ecdh.h:60
systime_t timeout
Timeout for blocking calls.
Definition: tls.h:2700
TlsEcdsaVerifyCallback ecdsaVerifyCallback
Definition: tls.h:2442
const TlsExtension * serverCertType
Definition: tls.h:2325
TlsCertificateType peerCertType
Peer's certificate type.
Definition: tls.h:2477
@ TLS_EXT_RECORD_SIZE_LIMIT
Definition: tls.h:1420
TlsTrustedAuthority
Definition: tls.h:1719
HMAC (Keyed-Hashing for Message Authentication)
@ TLS_STATE_NEW_SESSION_TICKET_ACK
Definition: tls.h:1617
error_t tlsSetPskCallback(TlsContext *context, TlsPskCallback pskCallback)
Register PSK callback function.
Definition: tls.c:1167
bool_t sessionTicketExtReceived
The SessionTicket extension has been received.
Definition: tls.h:2654
@ TLS_KEY_EXCH_DH_RSA
Definition: tls.h:1226
@ TLS_CERT_FORMAT_X509
Definition: tls.h:1261
@ TLS_SIGN_SCHEME_GOSTR34102012_512A
Definition: tls.h:1366
TlsSequenceNumber
Definition: tls.h:1653
error_t tlsExportKeyingMaterial(TlsContext *context, const char_t *label, bool_t useContextValue, const uint8_t *contextValue, size_t contextValueLen, uint8_t *output, size_t outputLen)
Export keying material per RFC 5705 standard.
Definition: tls.c:1899
void * TlsSocketHandle
Socket handle.
Definition: tls.h:2074
TlsEarlyDataStatus
Early data status.
Definition: tls.h:1073
@ TLS_GROUP_BRAINPOOLP384R1
Definition: tls.h:1521
@ TLS_EXT_SIGNED_CERT_TIMESTAMP
Definition: tls.h:1411
char_t * ticketAlpn
ALPN protocol associated with the ticket.
Definition: tls.h:2261
@ TLS_MAX_FRAGMENT_LENGTH_512
Definition: tls.h:1468
error_t tlsSetKeyLogCallback(TlsContext *context, TlsKeyLogCallback keyLogCallback)
Register key logging callback function (for debugging purpose only)
Definition: tls.c:853
@ TLS_ALERT_CERTIFICATE_UNKNOWN
Definition: tls.h:1179
bool_t emsExtReceived
The ExtendedMasterSecret extension has been received.
Definition: tls.h:2641
void TlsCertificate
Certificate message.
Definition: tls.h:1963
@ TLS_ALERT_ECH_REQUIRED
Definition: tls.h:1203
@ TLS_EC_POINT_FORMAT_ANSI_X962_COMPRESSED_CHAR2
Definition: tls.h:1562
const TlsCertAuthorities * certAuthorities
CertificateAuthorities extension.
Definition: tls.h:2344
error_t tlsEnableCertAuthorities(TlsContext *context, bool_t enabled)
Enable CertificateAuthorities extension.
Definition: tls.c:1477
@ TLS_GROUP_SECP384R1_MLKEM1024
Definition: tls.h:1547
uint8_t description
Definition: tls.h:2041
const Tls13PskIdentityList * identityList
PreSharedKey extension (ClientHello)
Definition: tls.h:2349
TLS context.
Definition: tls.h:2417
char_t * protocolList
List of supported ALPN protocols.
Definition: tls.h:2631
@ TLS_TYPE_CERTIFICATE_URL
Definition: tls.h:1140
CipherMode
Cipher operation modes.
Definition: cipher_modes.h:78
void tlsFreeCache(TlsCache *cache)
Properly dispose a session cache.
Definition: tls_cache.c:319
uint8_t data[]
Definition: tls.h:1910
@ TLS_STATE_CLOSED
Definition: tls.h:1621