Compare commits
11 commits
master
...
feature/re
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c1a0d1e059 | ||
|
|
6b58200d56 | ||
|
|
1063038c39 | ||
|
|
b9f3d2977f | ||
|
|
0aff93a4df | ||
|
|
f0de14daa4 | ||
|
|
591e59ac5f | ||
|
|
67c33ab7cd | ||
|
|
40b454de54 | ||
|
|
0c38e433ed | ||
|
|
1977c6c9c7 |
78 changed files with 1701 additions and 11493 deletions
14
.github/workflows/ci.yml
vendored
14
.github/workflows/ci.yml
vendored
|
|
@ -144,7 +144,7 @@ jobs:
|
|||
with:
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config --strict-warnings enable-demos enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
run: ./config --strict-warnings enable-demos enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -178,7 +178,7 @@ jobs:
|
|||
- name: config
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace"
|
||||
"./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-trace"
|
||||
- name: config dump
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
|
|
@ -217,7 +217,7 @@ jobs:
|
|||
shutdown_vm: false
|
||||
run: |
|
||||
sudo pkg install -y gcc perl5
|
||||
./config --strict-warnings enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
./config --strict-warnings enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
- name: config dump
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
with:
|
||||
|
|
@ -418,7 +418,7 @@ jobs:
|
|||
sudo cat /proc/sys/vm/mmap_rnd_bits
|
||||
sudo sysctl -w vm.mmap_rnd_bits=28
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION enable-asan enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-weak-ssl-ciphers enable-ssl3 enable-ssl3-method enable-nextprotoneg && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured --debug -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION enable-asan enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-weak-ssl-ciphers enable-nextprotoneg && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -538,7 +538,7 @@ jobs:
|
|||
- name: install extra config support
|
||||
run: sudo apt-get -y install libsctp-dev abigail-tools libzstd-dev zstd
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ktls enable-fips enable-lms enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-trace enable-zlib enable-zstd && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ktls enable-fips enable-lms enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-weak-ssl-ciphers enable-trace enable-zlib enable-zstd && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -588,7 +588,7 @@ jobs:
|
|||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo no-shared enable-crypto-mdebug enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-fips && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo no-shared enable-crypto-mdebug enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -711,7 +711,7 @@ jobs:
|
|||
- name: setup hostname workaround
|
||||
run: sudo hostname localhost
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-external-tests no-fips && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-external-tests no-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- uses: dtolnay/rust-toolchain@0f44b27771c32bda9f458f75a1e241b09791b331
|
||||
|
|
|
|||
2
.github/workflows/coveralls.yml
vendored
2
.github/workflows/coveralls.yml
vendored
|
|
@ -107,7 +107,7 @@ jobs:
|
|||
- name: setup hostname workaround
|
||||
run: sudo hostname localhost
|
||||
- name: config
|
||||
run: CC=gcc ./config --debug --coverage ${{ matrix.branches.extra_config }} no-asm enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-buildtest-c++ enable-ssl-trace enable-trace
|
||||
run: CC=gcc ./config --debug --coverage ${{ matrix.branches.extra_config }} no-asm enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-buildtest-c++ enable-ssl-trace enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
|
|||
2
.github/workflows/fips-checksums.yml
vendored
2
.github/workflows/fips-checksums.yml
vendored
|
|
@ -79,7 +79,7 @@ jobs:
|
|||
compute-abidiff:
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
BUILD_OPTS: -g --strict-warnings enable-ktls enable-fips enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-ssl3 enable-ssl3-method enable-trace enable-zlib enable-zstd
|
||||
BUILD_OPTS: -g --strict-warnings enable-ktls enable-fips enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-trace enable-zlib enable-zstd
|
||||
steps:
|
||||
- name: create build dirs
|
||||
run: |
|
||||
|
|
|
|||
2
.github/workflows/fuzz-checker.yml
vendored
2
.github/workflows/fuzz-checker.yml
vendored
|
|
@ -35,7 +35,7 @@ jobs:
|
|||
name: libFuzzer+,
|
||||
config: enable-fuzz-libfuzzer enable-asan enable-ubsan -fno-sanitize=function -fsanitize-coverage=trace-cmp -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION,
|
||||
libs: --with-fuzzer-lib=/usr/lib/llvm-18/lib/libFuzzer.a --with-fuzzer-include=/usr/include/clang/18/include/fuzzer,
|
||||
extra: enable-fips enable-lms enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment enable-tls1_3 enable-weak-ssl-ciphers enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-nextprotoneg,
|
||||
extra: enable-fips enable-lms enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment enable-tls1_3 enable-weak-ssl-ciphers enable-rc5 enable-md2 enable-nextprotoneg,
|
||||
install: libfuzzer-18-dev,
|
||||
cc: clang-18,
|
||||
linker: clang++-18,
|
||||
|
|
|
|||
12
.github/workflows/os-zoo.yml
vendored
12
.github/workflows/os-zoo.yml
vendored
|
|
@ -192,7 +192,7 @@ jobs:
|
|||
with:
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -218,7 +218,7 @@ jobs:
|
|||
- name: config
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace"
|
||||
"./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-trace"
|
||||
- name: config dump
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
|
|
@ -251,7 +251,7 @@ jobs:
|
|||
with:
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -271,7 +271,7 @@ jobs:
|
|||
with:
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config --strict-warnings enable-fips enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
run: ./config --strict-warnings enable-fips enable-md2 enable-rc5 enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -291,7 +291,7 @@ jobs:
|
|||
with:
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
run: ./config enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -318,7 +318,7 @@ jobs:
|
|||
shutdown_vm: false
|
||||
run: |
|
||||
sudo pkg install -y gcc perl5
|
||||
./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
- name: config dump
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
with:
|
||||
|
|
|
|||
2
.github/workflows/prov-compat-label.yml
vendored
2
.github/workflows/prov-compat-label.yml
vendored
|
|
@ -16,7 +16,7 @@ permissions:
|
|||
contents: read
|
||||
|
||||
env:
|
||||
opts: enable-rc5 enable-md2 enable-ssl3 enable-weak-ssl-ciphers enable-zlib
|
||||
opts: enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib
|
||||
|
||||
jobs:
|
||||
fips-releases:
|
||||
|
|
|
|||
2
.github/workflows/provider-compatibility.yml
vendored
2
.github/workflows/provider-compatibility.yml
vendored
|
|
@ -24,7 +24,7 @@ permissions:
|
|||
contents: read
|
||||
|
||||
env:
|
||||
opts: enable-rc5 enable-md2 enable-ssl3 enable-weak-ssl-ciphers enable-zlib
|
||||
opts: enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib
|
||||
|
||||
jobs:
|
||||
fips-releases:
|
||||
|
|
|
|||
2
.github/workflows/run-checker-daily.yml
vendored
2
.github/workflows/run-checker-daily.yml
vendored
|
|
@ -104,8 +104,6 @@ jobs:
|
|||
no-sse2,
|
||||
no-ssl,
|
||||
no-ssl-trace,
|
||||
enable-ssl3,
|
||||
enable-ssl3-method,
|
||||
enable-sslkeylog,
|
||||
no-shared,
|
||||
no-tests,
|
||||
|
|
|
|||
|
|
@ -31,7 +31,7 @@ jobs:
|
|||
with:
|
||||
persist-credentials: false
|
||||
- name: Config
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC
|
||||
- name: Config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: Make
|
||||
|
|
|
|||
2
.github/workflows/static-analysis.yml
vendored
2
.github/workflows/static-analysis.yml
vendored
|
|
@ -30,7 +30,7 @@ jobs:
|
|||
--post-data "token=${{ secrets.COVERITY_TOKEN }}&project=openssl%2Fopenssl" \
|
||||
--progress=dot:giga -O coverity_tool.tgz
|
||||
- name: config
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: tool install
|
||||
|
|
|
|||
2
.github/workflows/windows.yml
vendored
2
.github/workflows/windows.yml
vendored
|
|
@ -115,7 +115,7 @@ jobs:
|
|||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
perl ..\Configure --banner=Configured --strict-warnings enable-demos no-makedepend no-shared no-fips enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-trace enable-crypto-mdebug -DOSSL_WINCTX=openssl VC-WIN64A-masm
|
||||
perl ..\Configure --banner=Configured --strict-warnings enable-demos no-makedepend no-shared no-fips enable-md2 enable-rc5 enable-weak-ssl-ciphers enable-trace enable-crypto-mdebug -DOSSL_WINCTX=openssl VC-WIN64A-masm
|
||||
perl configdata.pm --dump
|
||||
- name: build
|
||||
working-directory: _build
|
||||
|
|
|
|||
11
CHANGES.md
11
CHANGES.md
|
|
@ -32,6 +32,17 @@ OpenSSL 4.0
|
|||
|
||||
### Changes between 3.6 and 4.0 [xx XXX xxxx]
|
||||
|
||||
* Removed configure options can now only be disabled. You may continue to use
|
||||
`disable-<feature>`, which will remain supported. Using `enable-<feature>`
|
||||
for a removed feature is no longer permitted.
|
||||
|
||||
*Andrew Dinh*
|
||||
|
||||
* Support for SSLv3 was removed. SSLv3 has been deprecated since
|
||||
2015, and OpenSSL had it disabled by default since 1.1.0 (2016).
|
||||
|
||||
*Kurt Roeckx*
|
||||
|
||||
* The crypto-mdebug-backtrace configuration option has been entirely removed.
|
||||
The option has been a no-op since 1.0.2.
|
||||
|
||||
|
|
|
|||
25
Configure
25
Configure
|
|
@ -413,7 +413,7 @@ my $auto_threads=1; # enable threads automatically? true by default
|
|||
my $default_ranlib;
|
||||
|
||||
# Known TLS and DTLS protocols
|
||||
my @tls = qw(ssl3 tls1 tls1_1 tls1_2 tls1_3);
|
||||
my @tls = qw(tls1 tls1_1 tls1_2 tls1_3);
|
||||
my @dtls = qw(dtls1 dtls1_2);
|
||||
|
||||
# Explicitly known options that are possible to disable. They can
|
||||
|
|
@ -528,7 +528,6 @@ my @disablables = (
|
|||
"srp",
|
||||
"srtp",
|
||||
"sse2",
|
||||
"ssl",
|
||||
"ssl-trace",
|
||||
"stdio",
|
||||
"sslkeylog",
|
||||
|
|
@ -581,6 +580,9 @@ my %deprecated_disablables = (
|
|||
"ripemd" => "rmd160",
|
||||
"ui" => "ui-console",
|
||||
"heartbeats" => undef,
|
||||
"ssl" => undef,
|
||||
"ssl3" => undef,
|
||||
"ssl3-method" => undef,
|
||||
);
|
||||
|
||||
# All of the following are disabled by default:
|
||||
|
|
@ -611,8 +613,6 @@ our %disabled = ( # "what" => "comment"
|
|||
"msan" => "default",
|
||||
"rc5" => "default",
|
||||
"sctp" => "default",
|
||||
"ssl3" => "default",
|
||||
"ssl3-method" => "default",
|
||||
"sslkeylog" => "default",
|
||||
"tfo" => "default",
|
||||
"trace" => "default",
|
||||
|
|
@ -641,14 +641,12 @@ my @disable_cascades = (
|
|||
"rc2", "rc4", "rmd160",
|
||||
"scrypt", "seed", "siphash", "siv",
|
||||
"slh-dsa", "sm3", "sm4", "srp",
|
||||
"srtp", "ssl3-method", "ssl-trace",
|
||||
"srtp", "ssl-trace",
|
||||
"tfo",
|
||||
"ts", "ui-console", "whirlpool",
|
||||
"fips-securitychecks" ],
|
||||
sub { $config{processor} eq "386" }
|
||||
=> [ "sse2" ],
|
||||
"ssl" => [ "ssl3" ],
|
||||
"ssl3-method" => [ "ssl3" ],
|
||||
"zlib" => [ "zlib-dynamic" ],
|
||||
"brotli" => [ "brotli-dynamic" ],
|
||||
"zstd" => [ "zstd-dynamic" ],
|
||||
|
|
@ -882,6 +880,14 @@ while (@argvcopy)
|
|||
$unsupported_options{$_} = 1;
|
||||
next;
|
||||
}
|
||||
|
||||
# Do not allow users to enable removed features
|
||||
if (/^enable-(.+)$/ && exists $deprecated_disablables{$word}
|
||||
&& $deprecated_disablables{$word} eq undef)
|
||||
{
|
||||
$unsupported_options{$_} = 1;
|
||||
next;
|
||||
}
|
||||
}
|
||||
if (/^no-(.+)$/ || /^disable-(.+)$/)
|
||||
{
|
||||
|
|
@ -901,11 +907,6 @@ while (@argvcopy)
|
|||
}
|
||||
$disabled{"dtls"} = "option(dtls)";
|
||||
}
|
||||
elsif ($1 eq "ssl")
|
||||
{
|
||||
# Last one of its kind
|
||||
$disabled{"ssl3"} = "option(ssl)";
|
||||
}
|
||||
elsif ($1 eq "tls")
|
||||
{
|
||||
# XXX: Tests will fail if all SSL/TLS
|
||||
|
|
|
|||
|
|
@ -1161,8 +1161,8 @@ Don't build support for negotiating the specified SSL/TLS protocol.
|
|||
|
||||
If `no-tls` is selected then all of `tls1`, `tls1_1`, `tls1_2` and `tls1_3`
|
||||
are disabled.
|
||||
Similarly `no-dtls` will disable `dtls1` and `dtls1_2`. The `no-ssl` option is
|
||||
synonymous with `no-ssl3`. Note this only affects version negotiation.
|
||||
Similarly `no-dtls` will disable `dtls1` and `dtls1_2`.
|
||||
`no-ssl` and `no-ssl3` are deprecated and do nothing.
|
||||
OpenSSL will still provide the methods for applications to explicitly select
|
||||
the individual protocol versions.
|
||||
|
||||
|
|
@ -1178,6 +1178,7 @@ Analogous to `no-{protocol}` but in addition do not build the methods for
|
|||
applications to explicitly select individual protocol versions. Note that there
|
||||
is no `no-tls1_3-method` option because there is no application method for
|
||||
TLSv1.3.
|
||||
`no-ssl3` is deprecated and does nothing.
|
||||
|
||||
Using individual protocol methods directly is deprecated. Applications should
|
||||
use `TLS_method()` instead.
|
||||
|
|
|
|||
|
|
@ -187,7 +187,7 @@ the following variables. The following set of compiler defines are required:
|
|||
### Optional Build Variables
|
||||
|
||||
DBGFLAG="--debug"
|
||||
CIPHENABLES="enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-rc4"
|
||||
CIPHENABLES="enable-weak-ssl-ciphers enable-rc4"
|
||||
|
||||
### Internal Known TNS/X to TNS/E Cross Compile Variables
|
||||
|
||||
|
|
|
|||
|
|
@ -20,7 +20,6 @@ typedef enum OPTION_choice {
|
|||
OPT_COMMON,
|
||||
OPT_STDNAME,
|
||||
OPT_CONVERT,
|
||||
OPT_SSL3,
|
||||
OPT_TLS1,
|
||||
OPT_TLS1_1,
|
||||
OPT_TLS1_2,
|
||||
|
|
@ -48,9 +47,6 @@ const OPTIONS ciphers_options[] = {
|
|||
|
||||
OPT_SECTION("Cipher specification"),
|
||||
{ "s", OPT_S, '-', "Only supported ciphers" },
|
||||
#ifndef OPENSSL_NO_SSL3
|
||||
{ "ssl3", OPT_SSL3, '-', "Ciphers compatible with SSL3" },
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1
|
||||
{ "tls1", OPT_TLS1, '-', "Ciphers compatible with TLS1" },
|
||||
#endif
|
||||
|
|
@ -135,10 +131,6 @@ int ciphers_main(int argc, char **argv)
|
|||
case OPT_CONVERT:
|
||||
convert = opt_arg();
|
||||
break;
|
||||
case OPT_SSL3:
|
||||
min_version = SSL3_VERSION;
|
||||
max_version = SSL3_VERSION;
|
||||
break;
|
||||
case OPT_TLS1:
|
||||
min_version = TLS1_VERSION;
|
||||
max_version = TLS1_VERSION;
|
||||
|
|
|
|||
|
|
@ -583,7 +583,6 @@ void apps_ssl_info_callback(const SSL *s, int where, int ret)
|
|||
}
|
||||
|
||||
static STRINT_PAIR ssl_versions[] = {
|
||||
{ "SSL 3.0", SSL3_VERSION },
|
||||
{ "TLS 1.0", TLS1_VERSION },
|
||||
{ "TLS 1.1", TLS1_1_VERSION },
|
||||
{ "TLS 1.2", TLS1_2_VERSION },
|
||||
|
|
@ -666,7 +665,7 @@ void msg_cb(int write_p, int version, int content_type, const void *buf,
|
|||
const char *str_version, *str_content_type = "", *str_details1 = "", *str_details2 = "";
|
||||
const unsigned char *bp = buf;
|
||||
|
||||
if (version == SSL3_VERSION || version == TLS1_VERSION || version == TLS1_1_VERSION || version == TLS1_2_VERSION || version == TLS1_3_VERSION || version == DTLS1_VERSION || version == DTLS1_BAD_VER) {
|
||||
if (version == TLS1_VERSION || version == TLS1_1_VERSION || version == TLS1_2_VERSION || version == TLS1_3_VERSION || version == DTLS1_VERSION || version == DTLS1_BAD_VER) {
|
||||
str_version = lookup(version, ssl_versions, "???");
|
||||
switch (content_type) {
|
||||
case SSL3_RT_CHANGE_CIPHER_SPEC:
|
||||
|
|
|
|||
|
|
@ -1565,9 +1565,6 @@ static void list_disabled(void)
|
|||
#ifdef OPENSSL_NO_SRTP
|
||||
BIO_puts(bio_out, "SRTP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SSL3
|
||||
BIO_puts(bio_out, "SSL3\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1
|
||||
BIO_puts(bio_out, "TLS1\n");
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -530,7 +530,6 @@ typedef enum OPTION_choice {
|
|||
OPT_SRP_LATEUSER,
|
||||
OPT_SRP_MOREGROUPS,
|
||||
#endif
|
||||
OPT_SSL3,
|
||||
OPT_SSL_CONFIG,
|
||||
OPT_TLS1_3,
|
||||
OPT_TLS1_2,
|
||||
|
|
@ -760,9 +759,6 @@ const OPTIONS s_client_options[] = {
|
|||
{ "nbio", OPT_NBIO, '-', "Use non-blocking IO" },
|
||||
|
||||
OPT_SECTION("Protocol and version"),
|
||||
#ifndef OPENSSL_NO_SSL3
|
||||
{ "ssl3", OPT_SSL3, '-', "Just use SSLv3" },
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1
|
||||
{ "tls1", OPT_TLS1, '-', "Just use TLSv1" },
|
||||
#endif
|
||||
|
|
@ -888,7 +884,7 @@ static const OPT_PAIR services[] = {
|
|||
#define IS_UNIX_FLAG(o) (o == OPT_UNIX)
|
||||
|
||||
#define IS_PROT_FLAG(o) \
|
||||
(o == OPT_SSL3 || o == OPT_TLS1 || o == OPT_TLS1_1 || o == OPT_TLS1_2 \
|
||||
(o == OPT_TLS1 || o == OPT_TLS1_1 || o == OPT_TLS1_2 \
|
||||
|| o == OPT_TLS1_3 || o == OPT_DTLS || o == OPT_DTLS1 || o == OPT_DTLS1_2 \
|
||||
|| o == OPT_QUIC)
|
||||
|
||||
|
|
@ -1369,15 +1365,6 @@ int s_client_main(int argc, char **argv)
|
|||
case OPT_SSL_CONFIG:
|
||||
ssl_config = opt_arg();
|
||||
break;
|
||||
case OPT_SSL3:
|
||||
min_version = SSL3_VERSION;
|
||||
max_version = SSL3_VERSION;
|
||||
socket_type = SOCK_STREAM;
|
||||
#ifndef OPENSSL_NO_DTLS
|
||||
isdtls = 0;
|
||||
#endif
|
||||
isquic = 0;
|
||||
break;
|
||||
case OPT_TLS1_3:
|
||||
min_version = TLS1_3_VERSION;
|
||||
max_version = TLS1_3_VERSION;
|
||||
|
|
|
|||
|
|
@ -1025,7 +1025,6 @@ typedef enum OPTION_choice {
|
|||
OPT_SPLIT_SEND_FRAG,
|
||||
OPT_MAX_PIPELINES,
|
||||
OPT_READ_BUF,
|
||||
OPT_SSL3,
|
||||
OPT_TLS1_3,
|
||||
OPT_TLS1_2,
|
||||
OPT_TLS1_1,
|
||||
|
|
@ -1270,9 +1269,6 @@ const OPTIONS s_server_options[] = {
|
|||
{ "no_ca_names", OPT_NOCANAMES, '-',
|
||||
"Disable TLS Extension CA Names" },
|
||||
{ "stateless", OPT_STATELESS, '-', "Require TLSv1.3 cookies" },
|
||||
#ifndef OPENSSL_NO_SSL3
|
||||
{ "ssl3", OPT_SSL3, '-', "Just talk SSLv3" },
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1
|
||||
{ "tls1", OPT_TLS1, '-', "Just talk TLSv1" },
|
||||
#endif
|
||||
|
|
@ -1326,8 +1322,8 @@ const OPTIONS s_server_options[] = {
|
|||
{ NULL }
|
||||
};
|
||||
|
||||
#define IS_PROT_FLAG(o) \
|
||||
(o == OPT_SSL3 || o == OPT_TLS1 || o == OPT_TLS1_1 || o == OPT_TLS1_2 \
|
||||
#define IS_PROT_FLAG(o) \
|
||||
(o == OPT_TLS1 || o == OPT_TLS1_1 || o == OPT_TLS1_2 \
|
||||
|| o == OPT_TLS1_3 || o == OPT_DTLS || o == OPT_DTLS1 || o == OPT_DTLS1_2)
|
||||
|
||||
int s_server_main(int argc, char *argv[])
|
||||
|
|
@ -1856,10 +1852,6 @@ int s_server_main(int argc, char *argv[])
|
|||
case OPT_SSL_CONFIG:
|
||||
ssl_config = opt_arg();
|
||||
break;
|
||||
case OPT_SSL3:
|
||||
min_version = SSL3_VERSION;
|
||||
max_version = SSL3_VERSION;
|
||||
break;
|
||||
case OPT_TLS1_3:
|
||||
min_version = TLS1_3_VERSION;
|
||||
max_version = TLS1_3_VERSION;
|
||||
|
|
|
|||
|
|
@ -61,7 +61,6 @@ typedef enum OPTION_choice {
|
|||
OPT_BUGS,
|
||||
OPT_VERIFY,
|
||||
OPT_TIME,
|
||||
OPT_SSL3,
|
||||
OPT_WWW,
|
||||
OPT_TLS1,
|
||||
OPT_TLS1_1,
|
||||
|
|
@ -83,9 +82,6 @@ const OPTIONS s_time_options[] = {
|
|||
{ "cipher", OPT_CIPHER, 's', "TLSv1.2 and below cipher list to be used" },
|
||||
{ "ciphersuites", OPT_CIPHERSUITES, 's',
|
||||
"Specify TLSv1.3 ciphersuites to be used" },
|
||||
#ifndef OPENSSL_NO_SSL3
|
||||
{ "ssl3", OPT_SSL3, '-', "Just use SSLv3" },
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1
|
||||
{ "tls1", OPT_TLS1, '-', "Just use TLSv1.0" },
|
||||
#endif
|
||||
|
|
@ -226,10 +222,6 @@ int s_time_main(int argc, char **argv)
|
|||
goto end;
|
||||
}
|
||||
break;
|
||||
case OPT_SSL3:
|
||||
min_version = SSL3_VERSION;
|
||||
max_version = SSL3_VERSION;
|
||||
break;
|
||||
case OPT_TLS1:
|
||||
min_version = TLS1_VERSION;
|
||||
max_version = TLS1_VERSION;
|
||||
|
|
@ -326,8 +318,6 @@ int s_time_main(int argc, char **argv)
|
|||
ver = SSL_version(scon);
|
||||
if (ver == TLS1_VERSION)
|
||||
ver = 't';
|
||||
else if (ver == SSL3_VERSION)
|
||||
ver = '3';
|
||||
else
|
||||
ver = '*';
|
||||
}
|
||||
|
|
@ -408,8 +398,6 @@ next:
|
|||
ver = SSL_version(scon);
|
||||
if (ver == TLS1_VERSION)
|
||||
ver = 't';
|
||||
else if (ver == SSL3_VERSION)
|
||||
ver = '3';
|
||||
else
|
||||
ver = '*';
|
||||
}
|
||||
|
|
|
|||
|
|
@ -45,19 +45,19 @@ L OSSL_DECODER include/openssl/decodererr.h crypto/encode_decode/decoder_err
|
|||
L HTTP include/openssl/httperr.h crypto/http/http_err.c include/crypto/httperr.h
|
||||
|
||||
# SSL/TLS alerts
|
||||
R SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE 1010
|
||||
R SSL_R_SSLV3_ALERT_BAD_RECORD_MAC 1020
|
||||
R SSL_R_TLS_ALERT_UNEXPECTED_MESSAGE 1010
|
||||
R SSL_R_TLS_ALERT_BAD_RECORD_MAC 1020
|
||||
R SSL_R_TLSV1_ALERT_DECRYPTION_FAILED 1021
|
||||
R SSL_R_TLSV1_ALERT_RECORD_OVERFLOW 1022
|
||||
R SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE 1030
|
||||
R SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE 1040
|
||||
R SSL_R_SSLV3_ALERT_NO_CERTIFICATE 1041
|
||||
R SSL_R_SSLV3_ALERT_BAD_CERTIFICATE 1042
|
||||
R SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE 1043
|
||||
R SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED 1044
|
||||
R SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED 1045
|
||||
R SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN 1046
|
||||
R SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER 1047
|
||||
R SSL_R_TLS_ALERT_DECOMPRESSION_FAILURE 1030
|
||||
R SSL_R_TLS_ALERT_HANDSHAKE_FAILURE 1040
|
||||
R SSL_R_TLS_ALERT_NO_CERTIFICATE 1041
|
||||
R SSL_R_TLS_ALERT_BAD_CERTIFICATE 1042
|
||||
R SSL_R_TLS_ALERT_UNSUPPORTED_CERTIFICATE 1043
|
||||
R SSL_R_TLS_ALERT_CERTIFICATE_REVOKED 1044
|
||||
R SSL_R_TLS_ALERT_CERTIFICATE_EXPIRED 1045
|
||||
R SSL_R_TLS_ALERT_CERTIFICATE_UNKNOWN 1046
|
||||
R SSL_R_TLS_ALERT_ILLEGAL_PARAMETER 1047
|
||||
R SSL_R_TLSV1_ALERT_UNKNOWN_CA 1048
|
||||
R SSL_R_TLSV1_ALERT_ACCESS_DENIED 1049
|
||||
R SSL_R_TLSV1_ALERT_DECODE_ERROR 1050
|
||||
|
|
|
|||
|
|
@ -1296,7 +1296,6 @@ RSA_R_RANDOMNESS_SOURCE_STRENGTH_INSUFFICIENT:180:\
|
|||
RSA_R_RSA_OPERATIONS_NOT_SUPPORTED:130:rsa operations not supported
|
||||
RSA_R_SLEN_CHECK_FAILED:136:salt length check failed
|
||||
RSA_R_SLEN_RECOVERY_FAILED:135:salt length recovery failed
|
||||
RSA_R_SSLV3_ROLLBACK_ATTACK:115:sslv3 rollback attack
|
||||
RSA_R_THE_ASN1_OBJECT_IDENTIFIER_IS_NOT_KNOWN_FOR_THIS_MD:116:\
|
||||
the asn1 object identifier is not known for this md
|
||||
RSA_R_UNKNOWN_ALGORITHM_TYPE:117:unknown algorithm type
|
||||
|
|
@ -1585,22 +1584,22 @@ SSL_R_SRTP_COULD_NOT_ALLOCATE_PROFILES:362:srtp could not allocate profiles
|
|||
SSL_R_SRTP_PROTECTION_PROFILE_LIST_TOO_LONG:363:\
|
||||
srtp protection profile list too long
|
||||
SSL_R_SRTP_UNKNOWN_PROTECTION_PROFILE:364:srtp unknown protection profile
|
||||
SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH:232:\
|
||||
SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH:232:\
|
||||
ssl3 ext invalid max fragment length
|
||||
SSL_R_SSL3_EXT_INVALID_SERVERNAME:319:ssl3 ext invalid servername
|
||||
SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE:320:ssl3 ext invalid servername type
|
||||
SSL_R_SSL3_SESSION_ID_TOO_LONG:300:ssl3 session id too long
|
||||
SSL_R_SSLV3_ALERT_BAD_CERTIFICATE:1042:ssl/tls alert bad certificate
|
||||
SSL_R_SSLV3_ALERT_BAD_RECORD_MAC:1020:ssl/tls alert bad record mac
|
||||
SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED:1045:ssl/tls alert certificate expired
|
||||
SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED:1044:ssl/tls alert certificate revoked
|
||||
SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN:1046:ssl/tls alert certificate unknown
|
||||
SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE:1030:ssl/tls alert decompression failure
|
||||
SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE:1040:ssl/tls alert handshake failure
|
||||
SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER:1047:ssl/tls alert illegal parameter
|
||||
SSL_R_SSLV3_ALERT_NO_CERTIFICATE:1041:ssl/tls alert no certificate
|
||||
SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE:1010:ssl/tls alert unexpected message
|
||||
SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE:1043:\
|
||||
SSL_R_TLS_EXT_INVALID_SERVERNAME:319:ssl3 ext invalid servername
|
||||
SSL_R_TLS_EXT_INVALID_SERVERNAME_TYPE:320:ssl3 ext invalid servername type
|
||||
SSL_R_TLS_SESSION_ID_TOO_LONG:300:ssl3 session id too long
|
||||
SSL_R_TLS_ALERT_BAD_CERTIFICATE:1042:ssl/tls alert bad certificate
|
||||
SSL_R_TLS_ALERT_BAD_RECORD_MAC:1020:ssl/tls alert bad record mac
|
||||
SSL_R_TLS_ALERT_CERTIFICATE_EXPIRED:1045:ssl/tls alert certificate expired
|
||||
SSL_R_TLS_ALERT_CERTIFICATE_REVOKED:1044:ssl/tls alert certificate revoked
|
||||
SSL_R_TLS_ALERT_CERTIFICATE_UNKNOWN:1046:ssl/tls alert certificate unknown
|
||||
SSL_R_TLS_ALERT_DECOMPRESSION_FAILURE:1030:ssl/tls alert decompression failure
|
||||
SSL_R_TLS_ALERT_HANDSHAKE_FAILURE:1040:ssl/tls alert handshake failure
|
||||
SSL_R_TLS_ALERT_ILLEGAL_PARAMETER:1047:ssl/tls alert illegal parameter
|
||||
SSL_R_TLS_ALERT_NO_CERTIFICATE:1041:ssl/tls alert no certificate
|
||||
SSL_R_TLS_ALERT_UNEXPECTED_MESSAGE:1010:ssl/tls alert unexpected message
|
||||
SSL_R_TLS_ALERT_UNSUPPORTED_CERTIFICATE:1043:\
|
||||
ssl/tls alert unsupported certificate
|
||||
SSL_R_SSL_COMMAND_SECTION_EMPTY:117:ssl command section empty
|
||||
SSL_R_SSL_COMMAND_SECTION_NOT_FOUND:125:ssl command section not found
|
||||
|
|
@ -1654,8 +1653,6 @@ SSL_R_TOO_MUCH_EARLY_DATA:164:too much early data
|
|||
SSL_R_UNABLE_TO_FIND_ECDH_PARAMETERS:314:unable to find ecdh parameters
|
||||
SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS:239:\
|
||||
unable to find public key parameters
|
||||
SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES:242:unable to load ssl3 md5 routines
|
||||
SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES:243:unable to load ssl3 sha1 routines
|
||||
SSL_R_UNEXPECTED_CCS_MESSAGE:262:unexpected ccs message
|
||||
SSL_R_UNEXPECTED_END_OF_EARLY_DATA:178:unexpected end of early data
|
||||
SSL_R_UNEXPECTED_EOF_WHILE_READING:294:unexpected eof while reading
|
||||
|
|
|
|||
|
|
@ -127,8 +127,6 @@ static const ERR_STRING_DATA RSA_str_reasons[] = {
|
|||
"salt length check failed" },
|
||||
{ ERR_PACK(ERR_LIB_RSA, 0, RSA_R_SLEN_RECOVERY_FAILED),
|
||||
"salt length recovery failed" },
|
||||
{ ERR_PACK(ERR_LIB_RSA, 0, RSA_R_SSLV3_ROLLBACK_ATTACK),
|
||||
"sslv3 rollback attack" },
|
||||
{ ERR_PACK(ERR_LIB_RSA, 0, RSA_R_THE_ASN1_OBJECT_IDENTIFIER_IS_NOT_KNOWN_FOR_THIS_MD),
|
||||
"the asn1 object identifier is not known for this md" },
|
||||
{ ERR_PACK(ERR_LIB_RSA, 0, RSA_R_UNKNOWN_ALGORITHM_TYPE),
|
||||
|
|
|
|||
|
|
@ -422,36 +422,36 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
|||
"srtp protection profile list too long" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SRTP_UNKNOWN_PROTECTION_PROFILE),
|
||||
"srtp unknown protection profile" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH),
|
||||
"ssl3 ext invalid max fragment length" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL3_EXT_INVALID_SERVERNAME),
|
||||
"ssl3 ext invalid servername" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE),
|
||||
"ssl3 ext invalid servername type" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL3_SESSION_ID_TOO_LONG),
|
||||
"ssl3 session id too long" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_BAD_CERTIFICATE),
|
||||
"ssl/tls alert bad certificate" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_BAD_RECORD_MAC),
|
||||
"ssl/tls alert bad record mac" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED),
|
||||
"ssl/tls alert certificate expired" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED),
|
||||
"ssl/tls alert certificate revoked" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN),
|
||||
"ssl/tls alert certificate unknown" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE),
|
||||
"ssl/tls alert decompression failure" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE),
|
||||
"ssl/tls alert handshake failure" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER),
|
||||
"ssl/tls alert illegal parameter" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_NO_CERTIFICATE),
|
||||
"ssl/tls alert no certificate" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE),
|
||||
"ssl/tls alert unexpected message" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE),
|
||||
"ssl/tls alert unsupported certificate" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH),
|
||||
"tls ext invalid max fragment length" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_EXT_INVALID_SERVERNAME),
|
||||
"tls ext invalid servername" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_EXT_INVALID_SERVERNAME_TYPE),
|
||||
"tls ext invalid servername type" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_SESSION_ID_TOO_LONG),
|
||||
"tls session id too long" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_BAD_CERTIFICATE),
|
||||
"tls alert bad certificate" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_BAD_RECORD_MAC),
|
||||
"tls alert bad record mac" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_CERTIFICATE_EXPIRED),
|
||||
"tls alert certificate expired" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_CERTIFICATE_REVOKED),
|
||||
"tls alert certificate revoked" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_CERTIFICATE_UNKNOWN),
|
||||
"tls alert certificate unknown" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_DECOMPRESSION_FAILURE),
|
||||
"tls alert decompression failure" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_HANDSHAKE_FAILURE),
|
||||
"tls alert handshake failure" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_ILLEGAL_PARAMETER),
|
||||
"tls alert illegal parameter" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_NO_CERTIFICATE),
|
||||
"tls alert no certificate" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_UNEXPECTED_MESSAGE),
|
||||
"tls alert unexpected message" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_UNSUPPORTED_CERTIFICATE),
|
||||
"tls alert unsupported certificate" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL_COMMAND_SECTION_EMPTY),
|
||||
"ssl command section empty" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL_COMMAND_SECTION_NOT_FOUND),
|
||||
|
|
@ -544,10 +544,6 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
|
|||
"unable to find ecdh parameters" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS),
|
||||
"unable to find public key parameters" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES),
|
||||
"unable to load ssl3 md5 routines" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES),
|
||||
"unable to load ssl3 sha1 routines" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_CCS_MESSAGE),
|
||||
"unexpected ccs message" },
|
||||
{ ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_END_OF_EARLY_DATA),
|
||||
|
|
|
|||
|
|
@ -12,7 +12,6 @@ B<openssl> B<ciphers>
|
|||
[B<-s>]
|
||||
[B<-v>]
|
||||
[B<-V>]
|
||||
[B<-ssl3>]
|
||||
[B<-tls1>]
|
||||
[B<-tls1_1>]
|
||||
[B<-tls1_2>]
|
||||
|
|
@ -76,7 +75,7 @@ L<SSL_CIPHER_description(3)>.
|
|||
|
||||
Like B<-v>, but include the official cipher suite values in hex.
|
||||
|
||||
=item B<-tls1_3>, B<-tls1_2>, B<-tls1_1>, B<-tls1>, B<-ssl3>
|
||||
=item B<-tls1_3>, B<-tls1_2>, B<-tls1_1>, B<-tls1>
|
||||
|
||||
In combination with the B<-s> option, list the ciphers which could be used if
|
||||
the specified protocol were negotiated.
|
||||
|
|
|
|||
|
|
@ -912,7 +912,7 @@ then an HTTP command can be given such as "GET /" to retrieve a web page.
|
|||
|
||||
If the handshake fails then there are several possible causes, if it is
|
||||
nothing obvious like no client certificate then the B<-bugs>,
|
||||
B<-ssl3>, B<-tls1>, B<-no_ssl3>, B<-no_tls1> options can be tried
|
||||
B<-tls1>, B<-no_tls1> options can be tried
|
||||
in case it is a buggy server. In particular you should play with these
|
||||
options B<before> submitting a bug report to an OpenSSL mailing list.
|
||||
|
||||
|
|
|
|||
|
|
@ -17,7 +17,6 @@ B<openssl> B<s_time>
|
|||
[B<-new>]
|
||||
[B<-verify> I<depth>]
|
||||
[B<-time> I<seconds>]
|
||||
[B<-ssl3>]
|
||||
[B<-tls1>]
|
||||
[B<-tls1_1>]
|
||||
[B<-tls1_2>]
|
||||
|
|
@ -128,7 +127,7 @@ can establish.
|
|||
|
||||
This is an obsolete synonym for B<-CAfile>.
|
||||
|
||||
=item B<-ssl3>, B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>
|
||||
=item B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>
|
||||
|
||||
See L<openssl(1)/TLS Version Options>.
|
||||
|
||||
|
|
@ -151,7 +150,7 @@ by the client the same way the aforementioned option does.
|
|||
This command can be used to measure the performance of an SSL connection.
|
||||
To connect to an SSL HTTP server and get the default page the command
|
||||
|
||||
openssl s_time -connect servername:443 -www / -CApath yourdir -CAfile yourfile.pem -cipher commoncipher [-ssl3]
|
||||
openssl s_time -connect servername:443 -www / -CApath yourdir -CAfile yourfile.pem -cipher commoncipher
|
||||
|
||||
would typically be used (https uses port 443). I<commoncipher> is a cipher to
|
||||
which both client and server can agree, see the L<openssl-ciphers(1)> command
|
||||
|
|
@ -159,7 +158,7 @@ for details.
|
|||
|
||||
If the handshake fails then there are several possible causes, if it is
|
||||
nothing obvious like no client certificate then the B<-bugs> and
|
||||
B<-ssl3> options can be tried
|
||||
B<-tls1> options can be tried
|
||||
in case it is a buggy server. In particular you should play with these
|
||||
options B<before> submitting a bug report to an OpenSSL mailing list.
|
||||
|
||||
|
|
|
|||
|
|
@ -98,7 +98,7 @@ These are described below in more detail.
|
|||
|
||||
=item B<Protocol>
|
||||
|
||||
This is the protocol in use TLSv1.3, TLSv1.2, TLSv1.1, TLSv1 or SSLv3.
|
||||
This is the protocol in use TLSv1.3, TLSv1.2, TLSv1.1 or TLSv1.
|
||||
|
||||
=item B<Cipher>
|
||||
|
||||
|
|
|
|||
|
|
@ -597,7 +597,7 @@ OpenSSL was built.
|
|||
|
||||
=over 4
|
||||
|
||||
=item B<-ssl3>, B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>, B<-no_ssl3>, B<-no_tls1>, B<-no_tls1_1>, B<-no_tls1_2>, B<-no_tls1_3>
|
||||
=item B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>, B<-no_ssl3>, B<-no_tls1>, B<-no_tls1_1>, B<-no_tls1_2>, B<-no_tls1_3>
|
||||
|
||||
These options require or disable the use of the specified SSL or TLS protocols.
|
||||
When a specific TLS version is required, only that version will be offered or
|
||||
|
|
|
|||
|
|
@ -125,7 +125,7 @@ can be one of the following:
|
|||
These are the general-purpose I<version-flexible> SSL/TLS methods.
|
||||
The actual protocol version used will be negotiated to the highest version
|
||||
mutually supported by the client and the server.
|
||||
The supported protocols are SSLv3, TLSv1, TLSv1.1, TLSv1.2 and TLSv1.3.
|
||||
The supported protocols are TLSv1, TLSv1.1, TLSv1.2 and TLSv1.3.
|
||||
Applications should use these methods, and avoid the version-specific
|
||||
methods described below, which are deprecated.
|
||||
|
||||
|
|
@ -155,9 +155,7 @@ TLSv1 protocol. These methods are deprecated.
|
|||
|
||||
=item SSLv3_method(), SSLv3_server_method(), SSLv3_client_method()
|
||||
|
||||
A TLS/SSL connection established with these methods will only understand the
|
||||
SSLv3 protocol.
|
||||
The SSLv3 protocol is deprecated and should not be used.
|
||||
Starting in version 3.6 those functions always return NULL.
|
||||
|
||||
=item DTLS_method(), DTLS_server_method(), DTLS_client_method()
|
||||
|
||||
|
|
|
|||
|
|
@ -136,14 +136,13 @@ $OpenSSL::safe::opt_versiontls_synopsis = ""
|
|||
. "[B<-no_tls1_1>]\n"
|
||||
. "[B<-no_tls1_2>]\n"
|
||||
. "[B<-no_tls1_3>]\n"
|
||||
. "[B<-ssl3>]\n"
|
||||
. "[B<-tls1>]\n"
|
||||
. "[B<-tls1_1>]\n"
|
||||
. "[B<-tls1_2>]\n"
|
||||
. "[B<-tls1_3>]";
|
||||
$OpenSSL::safe::opt_versiontls_item = ""
|
||||
. "=item B<-no_ssl3>, B<-no_tls1>, B<-no_tls1_1>, B<-no_tls1_2>, B<-no_tls1_3>,\n"
|
||||
. "B<-ssl3>, B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>\n"
|
||||
. "B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>\n"
|
||||
. "\n"
|
||||
. "See L<openssl(1)/TLS Version Options>.";
|
||||
|
||||
|
|
|
|||
|
|
@ -29,7 +29,7 @@ to the `libFuzzer` library file while configuring; this is represented as
|
|||
-fsanitize=fuzzer-no-link \
|
||||
enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment \
|
||||
enable-weak-ssl-ciphers enable-rc5 enable-md2 \
|
||||
enable-ssl3 enable-ssl3-method enable-nextprotoneg \
|
||||
enable-nextprotoneg \
|
||||
--debug
|
||||
|
||||
Clang uses the gcc libstdc++ library so this must also be installed. You can
|
||||
|
|
@ -95,8 +95,7 @@ prebuilt fuzzer library. This is represented as `$PATH_TO_LIBFUZZER_DIR` below.
|
|||
-fsanitize=fuzzer-no-link \
|
||||
enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment \
|
||||
enable-weak-ssl-ciphers enable-rc5 enable-md2 \
|
||||
enable-ssl3 enable-ssl3-method enable-nextprotoneg \
|
||||
--debug
|
||||
enable-nextprotoneg --debug
|
||||
|
||||
AFL
|
||||
---
|
||||
|
|
@ -108,9 +107,8 @@ Configure for fuzzing:
|
|||
sudo apt-get install afl-clang
|
||||
CC=afl-clang-fast ./config enable-fuzz-afl no-shared no-module \
|
||||
-DPEDANTIC enable-tls1_3 enable-weak-ssl-ciphers enable-rc5 \
|
||||
enable-md2 enable-ssl3 enable-ssl3-method enable-nextprotoneg \
|
||||
enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment \
|
||||
--debug
|
||||
enable-md2 enable-nextprotoneg enable-ec_nistp_64_gcc_128 \
|
||||
-fno-sanitize=alignment --debug
|
||||
make clean
|
||||
make
|
||||
|
||||
|
|
|
|||
|
|
@ -88,7 +88,6 @@
|
|||
#define RSA_R_RSA_OPERATIONS_NOT_SUPPORTED 130
|
||||
#define RSA_R_SLEN_CHECK_FAILED 136
|
||||
#define RSA_R_SLEN_RECOVERY_FAILED 135
|
||||
#define RSA_R_SSLV3_ROLLBACK_ATTACK 115
|
||||
#define RSA_R_THE_ASN1_OBJECT_IDENTIFIER_IS_NOT_KNOWN_FOR_THIS_MD 116
|
||||
#define RSA_R_UNKNOWN_ALGORITHM_TYPE 117
|
||||
#define RSA_R_UNKNOWN_DIGEST 166
|
||||
|
|
|
|||
|
|
@ -163,7 +163,6 @@ extern "C" {
|
|||
#define SSL_TXT_SHA256 "SHA256"
|
||||
#define SSL_TXT_SHA384 "SHA384"
|
||||
|
||||
#define SSL_TXT_SSLV3 "SSLv3"
|
||||
#define SSL_TXT_TLSV1 "TLSv1"
|
||||
#define SSL_TXT_TLSV1_1 "TLSv1.1"
|
||||
#define SSL_TXT_TLSV1_2 "TLSv1.2"
|
||||
|
|
|
|||
|
|
@ -266,21 +266,21 @@
|
|||
#define SSL_R_SRTP_COULD_NOT_ALLOCATE_PROFILES 362
|
||||
#define SSL_R_SRTP_PROTECTION_PROFILE_LIST_TOO_LONG 363
|
||||
#define SSL_R_SRTP_UNKNOWN_PROTECTION_PROFILE 364
|
||||
#define SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH 232
|
||||
#define SSL_R_SSL3_EXT_INVALID_SERVERNAME 319
|
||||
#define SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE 320
|
||||
#define SSL_R_SSL3_SESSION_ID_TOO_LONG 300
|
||||
#define SSL_R_SSLV3_ALERT_BAD_CERTIFICATE 1042
|
||||
#define SSL_R_SSLV3_ALERT_BAD_RECORD_MAC 1020
|
||||
#define SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED 1045
|
||||
#define SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED 1044
|
||||
#define SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN 1046
|
||||
#define SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE 1030
|
||||
#define SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE 1040
|
||||
#define SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER 1047
|
||||
#define SSL_R_SSLV3_ALERT_NO_CERTIFICATE 1041
|
||||
#define SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE 1010
|
||||
#define SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE 1043
|
||||
#define SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH 232
|
||||
#define SSL_R_TLS_EXT_INVALID_SERVERNAME 319
|
||||
#define SSL_R_TLS_EXT_INVALID_SERVERNAME_TYPE 320
|
||||
#define SSL_R_TLS_SESSION_ID_TOO_LONG 300
|
||||
#define SSL_R_TLS_ALERT_BAD_CERTIFICATE 1042
|
||||
#define SSL_R_TLS_ALERT_BAD_RECORD_MAC 1020
|
||||
#define SSL_R_TLS_ALERT_CERTIFICATE_EXPIRED 1045
|
||||
#define SSL_R_TLS_ALERT_CERTIFICATE_REVOKED 1044
|
||||
#define SSL_R_TLS_ALERT_CERTIFICATE_UNKNOWN 1046
|
||||
#define SSL_R_TLS_ALERT_DECOMPRESSION_FAILURE 1030
|
||||
#define SSL_R_TLS_ALERT_HANDSHAKE_FAILURE 1040
|
||||
#define SSL_R_TLS_ALERT_ILLEGAL_PARAMETER 1047
|
||||
#define SSL_R_TLS_ALERT_NO_CERTIFICATE 1041
|
||||
#define SSL_R_TLS_ALERT_UNEXPECTED_MESSAGE 1010
|
||||
#define SSL_R_TLS_ALERT_UNSUPPORTED_CERTIFICATE 1043
|
||||
#define SSL_R_SSL_COMMAND_SECTION_EMPTY 117
|
||||
#define SSL_R_SSL_COMMAND_SECTION_NOT_FOUND 125
|
||||
#define SSL_R_SSL_CTX_HAS_NO_DEFAULT_SSL_VERSION 228
|
||||
|
|
@ -330,8 +330,6 @@
|
|||
#define SSL_R_TOO_MUCH_EARLY_DATA 164
|
||||
#define SSL_R_UNABLE_TO_FIND_ECDH_PARAMETERS 314
|
||||
#define SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS 239
|
||||
#define SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES 242
|
||||
#define SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES 243
|
||||
#define SSL_R_UNEXPECTED_CCS_MESSAGE 262
|
||||
#define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178
|
||||
#define SSL_R_UNEXPECTED_EOF_WHILE_READING 294
|
||||
|
|
|
|||
|
|
@ -461,6 +461,26 @@ OSSL_DEPRECATEDIN_3_0 int ERR_load_SSL_strings(void);
|
|||
#define SSL_F_WRITE_STATE_MACHINE 0
|
||||
#endif
|
||||
|
||||
#ifndef OPENSSL_NO_DEPRECATED_4_0
|
||||
|
||||
#define SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH 232
|
||||
#define SSL_R_SSL3_EXT_INVALID_SERVERNAME 319
|
||||
#define SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE 320
|
||||
#define SSL_R_SSL3_SESSION_ID_TOO_LONG 300
|
||||
#define SSL_R_SSLV3_ALERT_BAD_CERTIFICATE 1042
|
||||
#define SSL_R_SSLV3_ALERT_BAD_RECORD_MAC 1020
|
||||
#define SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED 1045
|
||||
#define SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED 1044
|
||||
#define SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN 1046
|
||||
#define SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE 1030
|
||||
#define SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE 1040
|
||||
#define SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER 1047
|
||||
#define SSL_R_SSLV3_ALERT_NO_CERTIFICATE 1041
|
||||
#define SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE 1010
|
||||
#define SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE 1043
|
||||
|
||||
#endif
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ LIBS=../libssl
|
|||
|
||||
SOURCE[../libssl]=\
|
||||
pqueue.c \
|
||||
statem/statem_srvr.c statem/statem_clnt.c s3_lib.c s3_enc.c \
|
||||
statem/statem_srvr.c statem/statem_clnt.c s3_lib.c s3_enc.c \
|
||||
statem/statem_lib.c statem/extensions.c statem/extensions_srvr.c \
|
||||
statem/extensions_clnt.c statem/extensions_cust.c s3_msg.c \
|
||||
methods.c t1_lib.c t1_enc.c tls13_enc.c \
|
||||
|
|
|
|||
|
|
@ -41,9 +41,6 @@ IMPLEMENT_tls_meth_func(TLS1_VERSION, SSL_METHOD_NO_SUITEB, SSL_OP_NO_TLSv1,
|
|||
tlsv1_method,
|
||||
ossl_statem_accept, ossl_statem_connect, TLSv1_enc_data)
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SSL3_METHOD
|
||||
IMPLEMENT_ssl3_meth_func(sslv3_method, ossl_statem_accept, ossl_statem_connect)
|
||||
#endif
|
||||
/*-
|
||||
* TLS/SSLv3 server methods
|
||||
*/
|
||||
|
|
@ -73,10 +70,6 @@ IMPLEMENT_tls_meth_func(TLS1_VERSION, SSL_METHOD_NO_SUITEB, SSL_OP_NO_TLSv1,
|
|||
ossl_statem_accept,
|
||||
ssl_undefined_function, TLSv1_enc_data)
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SSL3_METHOD
|
||||
IMPLEMENT_ssl3_meth_func(sslv3_server_method,
|
||||
ossl_statem_accept, ssl_undefined_function)
|
||||
#endif
|
||||
/*-
|
||||
* TLS/SSLv3 client methods
|
||||
*/
|
||||
|
|
@ -106,10 +99,6 @@ IMPLEMENT_tls_meth_func(TLS1_VERSION, SSL_METHOD_NO_SUITEB, SSL_OP_NO_TLSv1,
|
|||
ssl_undefined_function,
|
||||
ossl_statem_connect, TLSv1_enc_data)
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SSL3_METHOD
|
||||
IMPLEMENT_ssl3_meth_func(sslv3_client_method,
|
||||
ssl_undefined_function, ossl_statem_connect)
|
||||
#endif
|
||||
/*-
|
||||
* DTLS methods
|
||||
*/
|
||||
|
|
@ -228,17 +217,17 @@ const SSL_METHOD *TLSv1_client_method(void)
|
|||
#ifndef OPENSSL_NO_SSL3_METHOD
|
||||
const SSL_METHOD *SSLv3_method(void)
|
||||
{
|
||||
return sslv3_method();
|
||||
return NULL;
|
||||
}
|
||||
|
||||
const SSL_METHOD *SSLv3_server_method(void)
|
||||
{
|
||||
return sslv3_server_method();
|
||||
return NULL;
|
||||
}
|
||||
|
||||
const SSL_METHOD *SSLv3_client_method(void)
|
||||
{
|
||||
return sslv3_client_method();
|
||||
return NULL;
|
||||
}
|
||||
#endif
|
||||
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ IF[{- !$disabled{ktls} -}]
|
|||
ENDIF
|
||||
|
||||
SOURCE[../../../libssl]=\
|
||||
tls_common.c ssl3_meth.c tls1_meth.c tls13_meth.c tlsany_meth.c \
|
||||
tls_common.c tls1_meth.c tls13_meth.c tlsany_meth.c \
|
||||
dtls_meth.c tls_multib.c $KTLSSRC
|
||||
|
||||
# For shared builds we need to include the sources needed in providers
|
||||
|
|
|
|||
|
|
@ -378,7 +378,6 @@ typedef struct dtls_rlayer_record_data_st {
|
|||
TLS_RL_RECORD rrec;
|
||||
} DTLS_RLAYER_RECORD_DATA;
|
||||
|
||||
extern const struct record_functions_st ssl_3_0_funcs;
|
||||
extern const struct record_functions_st tls_1_funcs;
|
||||
extern const struct record_functions_st tls_1_3_funcs;
|
||||
extern const struct record_functions_st tls_any_funcs;
|
||||
|
|
|
|||
|
|
@ -1,331 +0,0 @@
|
|||
/*
|
||||
* Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/core_names.h>
|
||||
#include "internal/ssl3_cbc.h"
|
||||
#include "../../ssl_local.h"
|
||||
#include "../record_local.h"
|
||||
#include "recmethod_local.h"
|
||||
|
||||
static int ssl3_set_crypto_state(OSSL_RECORD_LAYER *rl, int level,
|
||||
unsigned char *key, size_t keylen,
|
||||
unsigned char *iv, size_t ivlen,
|
||||
unsigned char *mackey, size_t mackeylen,
|
||||
const EVP_CIPHER *ciph,
|
||||
size_t taglen,
|
||||
int mactype,
|
||||
const EVP_MD *md,
|
||||
COMP_METHOD *comp)
|
||||
{
|
||||
EVP_CIPHER_CTX *ciph_ctx;
|
||||
int enc = (rl->direction == OSSL_RECORD_DIRECTION_WRITE) ? 1 : 0;
|
||||
|
||||
if (md == NULL) {
|
||||
ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR);
|
||||
return OSSL_RECORD_RETURN_FATAL;
|
||||
}
|
||||
|
||||
if ((rl->enc_ctx = EVP_CIPHER_CTX_new()) == NULL) {
|
||||
ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR);
|
||||
return OSSL_RECORD_RETURN_FATAL;
|
||||
}
|
||||
ciph_ctx = rl->enc_ctx;
|
||||
|
||||
rl->md_ctx = EVP_MD_CTX_new();
|
||||
if (rl->md_ctx == NULL) {
|
||||
ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR);
|
||||
return OSSL_RECORD_RETURN_FATAL;
|
||||
}
|
||||
|
||||
if ((md != NULL && EVP_DigestInit_ex(rl->md_ctx, md, NULL) <= 0)) {
|
||||
ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR);
|
||||
return OSSL_RECORD_RETURN_FATAL;
|
||||
}
|
||||
|
||||
#ifndef OPENSSL_NO_COMP
|
||||
if (comp != NULL) {
|
||||
rl->compctx = COMP_CTX_new(comp);
|
||||
if (rl->compctx == NULL) {
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_COMPRESSION_LIBRARY_ERROR);
|
||||
return OSSL_RECORD_RETURN_FATAL;
|
||||
}
|
||||
}
|
||||
#endif
|
||||
|
||||
if (!EVP_CipherInit_ex(ciph_ctx, ciph, NULL, key, iv, enc)) {
|
||||
ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR);
|
||||
return OSSL_RECORD_RETURN_FATAL;
|
||||
}
|
||||
|
||||
if (EVP_CIPHER_get0_provider(EVP_CIPHER_CTX_get0_cipher(ciph_ctx)) != NULL
|
||||
&& !ossl_set_tls_provider_parameters(rl, ciph_ctx, ciph, md)) {
|
||||
/* ERR_raise already called */
|
||||
return OSSL_RECORD_RETURN_FATAL;
|
||||
}
|
||||
|
||||
if (mackeylen > sizeof(rl->mac_secret)) {
|
||||
ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR);
|
||||
return OSSL_RECORD_RETURN_FATAL;
|
||||
}
|
||||
memcpy(rl->mac_secret, mackey, mackeylen);
|
||||
|
||||
return OSSL_RECORD_RETURN_SUCCESS;
|
||||
}
|
||||
|
||||
/*
|
||||
* ssl3_cipher encrypts/decrypts |n_recs| records in |inrecs|. Calls RLAYERfatal
|
||||
* on internal error, but not otherwise. It is the responsibility of the caller
|
||||
* to report a bad_record_mac
|
||||
*
|
||||
* Returns:
|
||||
* 0: if the record is publicly invalid, or an internal error
|
||||
* 1: Success or Mac-then-encrypt decryption failed (MAC will be randomised)
|
||||
*/
|
||||
static int ssl3_cipher(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *inrecs,
|
||||
size_t n_recs, int sending, SSL_MAC_BUF *mac,
|
||||
size_t macsize)
|
||||
{
|
||||
TLS_RL_RECORD *rec;
|
||||
EVP_CIPHER_CTX *ds;
|
||||
size_t l, i;
|
||||
size_t bs;
|
||||
const EVP_CIPHER *enc;
|
||||
int provided;
|
||||
|
||||
rec = inrecs;
|
||||
/*
|
||||
* We shouldn't ever be called with more than one record in the SSLv3 case
|
||||
*/
|
||||
if (n_recs != 1)
|
||||
return 0;
|
||||
|
||||
ds = rl->enc_ctx;
|
||||
if (ds == NULL || (enc = EVP_CIPHER_CTX_get0_cipher(ds)) == NULL)
|
||||
return 0;
|
||||
|
||||
provided = (EVP_CIPHER_get0_provider(enc) != NULL);
|
||||
|
||||
l = rec->length;
|
||||
bs = EVP_CIPHER_CTX_get_block_size(ds);
|
||||
|
||||
if (bs == 0)
|
||||
return 0;
|
||||
|
||||
/* COMPRESS */
|
||||
|
||||
if ((bs != 1) && sending && !provided) {
|
||||
/*
|
||||
* We only do this for legacy ciphers. Provided ciphers add the
|
||||
* padding on the provider side.
|
||||
*/
|
||||
i = bs - (l % bs);
|
||||
|
||||
/* we need to add 'i-1' padding bytes */
|
||||
l += i;
|
||||
/*
|
||||
* the last of these zero bytes will be overwritten with the
|
||||
* padding length.
|
||||
*/
|
||||
memset(&rec->input[rec->length], 0, i);
|
||||
rec->length += i;
|
||||
rec->input[l - 1] = (unsigned char)(i - 1);
|
||||
}
|
||||
|
||||
if (!sending) {
|
||||
if (l == 0 || l % bs != 0) {
|
||||
/* Publicly invalid */
|
||||
return 0;
|
||||
}
|
||||
/* otherwise, rec->length >= bs */
|
||||
}
|
||||
|
||||
if (provided) {
|
||||
int outlen;
|
||||
|
||||
if (!EVP_CipherUpdate(ds, rec->data, &outlen, rec->input,
|
||||
(unsigned int)l))
|
||||
return 0;
|
||||
rec->length = outlen;
|
||||
|
||||
if (!sending && mac != NULL) {
|
||||
/* Now get a pointer to the MAC */
|
||||
OSSL_PARAM params[2], *p = params;
|
||||
|
||||
/* Get the MAC */
|
||||
mac->alloced = 0;
|
||||
|
||||
*p++ = OSSL_PARAM_construct_octet_ptr(OSSL_CIPHER_PARAM_TLS_MAC,
|
||||
(void **)&mac->mac,
|
||||
macsize);
|
||||
*p = OSSL_PARAM_construct_end();
|
||||
|
||||
if (!EVP_CIPHER_CTX_get_params(ds, params)) {
|
||||
/* Shouldn't normally happen */
|
||||
RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
} else {
|
||||
if (EVP_Cipher(ds, rec->data, rec->input, (unsigned int)l) < 1) {
|
||||
/* Shouldn't happen */
|
||||
RLAYERfatal(rl, SSL_AD_BAD_RECORD_MAC, ERR_R_INTERNAL_ERROR);
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (!sending)
|
||||
return ssl3_cbc_remove_padding_and_mac(&rec->length,
|
||||
rec->orig_len,
|
||||
rec->data,
|
||||
(mac != NULL) ? &mac->mac : NULL,
|
||||
(mac != NULL) ? &mac->alloced : NULL,
|
||||
bs,
|
||||
macsize,
|
||||
rl->libctx);
|
||||
}
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
static const unsigned char ssl3_pad_1[48] = {
|
||||
0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36,
|
||||
0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36,
|
||||
0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36,
|
||||
0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36,
|
||||
0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36,
|
||||
0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36
|
||||
};
|
||||
|
||||
static const unsigned char ssl3_pad_2[48] = {
|
||||
0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c,
|
||||
0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c,
|
||||
0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c,
|
||||
0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c,
|
||||
0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c,
|
||||
0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c
|
||||
};
|
||||
|
||||
static int ssl3_mac(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *rec, unsigned char *md,
|
||||
int sending)
|
||||
{
|
||||
unsigned char *mac_sec, *seq = rl->sequence;
|
||||
const EVP_MD_CTX *hash;
|
||||
unsigned char *p, rec_char;
|
||||
size_t md_size;
|
||||
size_t npad;
|
||||
int t;
|
||||
|
||||
mac_sec = &(rl->mac_secret[0]);
|
||||
hash = rl->md_ctx;
|
||||
|
||||
t = EVP_MD_CTX_get_size(hash);
|
||||
if (t <= 0)
|
||||
return 0;
|
||||
md_size = t;
|
||||
npad = (48 / md_size) * md_size;
|
||||
|
||||
if (!sending
|
||||
&& EVP_CIPHER_CTX_get_mode(rl->enc_ctx) == EVP_CIPH_CBC_MODE
|
||||
&& ssl3_cbc_record_digest_supported(hash)) {
|
||||
#ifdef OPENSSL_NO_DEPRECATED_3_0
|
||||
return 0;
|
||||
#else
|
||||
/*
|
||||
* This is a CBC-encrypted record. We must avoid leaking any
|
||||
* timing-side channel information about how many blocks of data we
|
||||
* are hashing because that gives an attacker a timing-oracle.
|
||||
*/
|
||||
|
||||
/*-
|
||||
* npad is, at most, 48 bytes and that's with MD5:
|
||||
* 16 + 48 + 8 (sequence bytes) + 1 + 2 = 75.
|
||||
*
|
||||
* With SHA-1 (the largest hash speced for SSLv3) the hash size
|
||||
* goes up 4, but npad goes down by 8, resulting in a smaller
|
||||
* total size.
|
||||
*/
|
||||
unsigned char header[75];
|
||||
size_t j = 0;
|
||||
memcpy(header + j, mac_sec, md_size);
|
||||
j += md_size;
|
||||
memcpy(header + j, ssl3_pad_1, npad);
|
||||
j += npad;
|
||||
memcpy(header + j, seq, 8);
|
||||
j += 8;
|
||||
header[j++] = rec->type;
|
||||
header[j++] = (unsigned char)(rec->length >> 8);
|
||||
header[j++] = (unsigned char)(rec->length & 0xff);
|
||||
|
||||
/* Final param == is SSLv3 */
|
||||
if (ssl3_cbc_digest_record(EVP_MD_CTX_get0_md(hash),
|
||||
md, &md_size,
|
||||
header, rec->input,
|
||||
rec->length, rec->orig_len,
|
||||
mac_sec, md_size, 1)
|
||||
<= 0)
|
||||
return 0;
|
||||
#endif
|
||||
} else {
|
||||
unsigned int md_size_u;
|
||||
/* Chop the digest off the end :-) */
|
||||
EVP_MD_CTX *md_ctx = EVP_MD_CTX_new();
|
||||
|
||||
if (md_ctx == NULL)
|
||||
return 0;
|
||||
|
||||
rec_char = rec->type;
|
||||
p = md;
|
||||
s2n(rec->length, p);
|
||||
if (EVP_MD_CTX_copy_ex(md_ctx, hash) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, mac_sec, md_size) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, ssl3_pad_1, npad) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, seq, 8) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, &rec_char, 1) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, md, 2) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, rec->input, rec->length) <= 0
|
||||
|| EVP_DigestFinal_ex(md_ctx, md, NULL) <= 0
|
||||
|| EVP_MD_CTX_copy_ex(md_ctx, hash) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, mac_sec, md_size) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, ssl3_pad_2, npad) <= 0
|
||||
|| EVP_DigestUpdate(md_ctx, md, md_size) <= 0
|
||||
|| EVP_DigestFinal_ex(md_ctx, md, &md_size_u) <= 0) {
|
||||
EVP_MD_CTX_free(md_ctx);
|
||||
return 0;
|
||||
}
|
||||
|
||||
EVP_MD_CTX_free(md_ctx);
|
||||
}
|
||||
|
||||
if (!tls_increment_sequence_ctr(rl))
|
||||
return 0;
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
const struct record_functions_st ssl_3_0_funcs = {
|
||||
ssl3_set_crypto_state,
|
||||
ssl3_cipher,
|
||||
ssl3_mac,
|
||||
tls_default_set_protocol_version,
|
||||
tls_default_read_n,
|
||||
tls_get_more_records,
|
||||
tls_default_validate_record_header,
|
||||
tls_default_post_process_record,
|
||||
tls_get_max_records_default,
|
||||
tls_write_records_default,
|
||||
/* These 2 functions are defined in tls1_meth.c */
|
||||
tls1_allocate_write_buffers,
|
||||
tls1_initialise_write_packets,
|
||||
NULL,
|
||||
tls_prepare_record_header_default,
|
||||
NULL,
|
||||
tls_prepare_for_encryption_default,
|
||||
tls_post_encryption_processing_default,
|
||||
NULL
|
||||
};
|
||||
|
|
@ -1425,9 +1425,6 @@ tls_new_record_layer(OSSL_LIB_CTX *libctx, const char *propq, int vers,
|
|||
case TLS1_VERSION:
|
||||
(*retrl)->funcs = &tls_1_funcs;
|
||||
break;
|
||||
case SSL3_VERSION:
|
||||
(*retrl)->funcs = &ssl_3_0_funcs;
|
||||
break;
|
||||
default:
|
||||
/* Should not happen */
|
||||
ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR);
|
||||
|
|
|
|||
391
ssl/s3_enc.c
391
ssl/s3_enc.c
|
|
@ -11,205 +11,10 @@
|
|||
#include <stdio.h>
|
||||
#include "ssl_local.h"
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/md5.h>
|
||||
#include <openssl/core_names.h>
|
||||
#include "internal/cryptlib.h"
|
||||
#include "internal/ssl_unwrap.h"
|
||||
|
||||
static int ssl3_generate_key_block(SSL_CONNECTION *s, unsigned char *km, int num)
|
||||
{
|
||||
const EVP_MD *md5 = NULL, *sha1 = NULL;
|
||||
EVP_MD_CTX *m5;
|
||||
EVP_MD_CTX *s1;
|
||||
unsigned char buf[16], smd[SHA_DIGEST_LENGTH];
|
||||
unsigned char c = 'A';
|
||||
unsigned int i, k;
|
||||
int ret = 0;
|
||||
SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s);
|
||||
|
||||
#ifdef CHARSET_EBCDIC
|
||||
c = os_toascii[c]; /* 'A' in ASCII */
|
||||
#endif
|
||||
k = 0;
|
||||
md5 = EVP_MD_fetch(sctx->libctx, "MD5", sctx->propq);
|
||||
sha1 = EVP_MD_fetch(sctx->libctx, "SHA1", sctx->propq);
|
||||
m5 = EVP_MD_CTX_new();
|
||||
s1 = EVP_MD_CTX_new();
|
||||
if (md5 == NULL || sha1 == NULL || m5 == NULL || s1 == NULL) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
goto err;
|
||||
}
|
||||
for (i = 0; (int)i < num; i += MD5_DIGEST_LENGTH) {
|
||||
k++;
|
||||
if (k > sizeof(buf)) {
|
||||
/* bug: 'buf' is too small for this ciphersuite */
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
|
||||
memset(buf, c, k);
|
||||
c++;
|
||||
if (!EVP_DigestInit_ex(s1, sha1, NULL)
|
||||
|| !EVP_DigestUpdate(s1, buf, k)
|
||||
|| !EVP_DigestUpdate(s1, s->session->master_key,
|
||||
s->session->master_key_length)
|
||||
|| !EVP_DigestUpdate(s1, s->s3.server_random, SSL3_RANDOM_SIZE)
|
||||
|| !EVP_DigestUpdate(s1, s->s3.client_random, SSL3_RANDOM_SIZE)
|
||||
|| !EVP_DigestFinal_ex(s1, smd, NULL)
|
||||
|| !EVP_DigestInit_ex(m5, md5, NULL)
|
||||
|| !EVP_DigestUpdate(m5, s->session->master_key,
|
||||
s->session->master_key_length)
|
||||
|| !EVP_DigestUpdate(m5, smd, SHA_DIGEST_LENGTH)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
if ((int)(i + MD5_DIGEST_LENGTH) > num) {
|
||||
if (!EVP_DigestFinal_ex(m5, smd, NULL)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
memcpy(km, smd, (num - i));
|
||||
} else {
|
||||
if (!EVP_DigestFinal_ex(m5, km, NULL)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
}
|
||||
|
||||
km += MD5_DIGEST_LENGTH;
|
||||
}
|
||||
OPENSSL_cleanse(smd, sizeof(smd));
|
||||
ret = 1;
|
||||
err:
|
||||
EVP_MD_CTX_free(m5);
|
||||
EVP_MD_CTX_free(s1);
|
||||
ssl_evp_md_free(md5);
|
||||
ssl_evp_md_free(sha1);
|
||||
return ret;
|
||||
}
|
||||
|
||||
int ssl3_change_cipher_state(SSL_CONNECTION *s, int which)
|
||||
{
|
||||
unsigned char *p, *mac_secret;
|
||||
size_t md_len;
|
||||
unsigned char *key, *iv;
|
||||
const EVP_CIPHER *ciph;
|
||||
const SSL_COMP *comp = NULL;
|
||||
const EVP_MD *md;
|
||||
int mdi;
|
||||
size_t n, iv_len, key_len;
|
||||
int direction = (which & SSL3_CC_READ) != 0 ? OSSL_RECORD_DIRECTION_READ
|
||||
: OSSL_RECORD_DIRECTION_WRITE;
|
||||
|
||||
ciph = s->s3.tmp.new_sym_enc;
|
||||
md = s->s3.tmp.new_hash;
|
||||
/* m == NULL will lead to a crash later */
|
||||
if (!ossl_assert(md != NULL)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
#ifndef OPENSSL_NO_COMP
|
||||
comp = s->s3.tmp.new_compression;
|
||||
#endif
|
||||
|
||||
p = s->s3.tmp.key_block;
|
||||
mdi = EVP_MD_get_size(md);
|
||||
if (mdi <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
md_len = (size_t)mdi;
|
||||
key_len = EVP_CIPHER_get_key_length(ciph);
|
||||
iv_len = EVP_CIPHER_get_iv_length(ciph);
|
||||
|
||||
if ((which == SSL3_CHANGE_CIPHER_CLIENT_WRITE) || (which == SSL3_CHANGE_CIPHER_SERVER_READ)) {
|
||||
mac_secret = &(p[0]);
|
||||
n = md_len + md_len;
|
||||
key = &(p[n]);
|
||||
n += key_len + key_len;
|
||||
iv = &(p[n]);
|
||||
n += iv_len + iv_len;
|
||||
} else {
|
||||
n = md_len;
|
||||
mac_secret = &(p[n]);
|
||||
n += md_len + key_len;
|
||||
key = &(p[n]);
|
||||
n += key_len + iv_len;
|
||||
iv = &(p[n]);
|
||||
n += iv_len;
|
||||
}
|
||||
|
||||
if (n > s->s3.tmp.key_block_length) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
|
||||
if (!ssl_set_new_record_layer(s, SSL3_VERSION,
|
||||
direction,
|
||||
OSSL_RECORD_PROTECTION_LEVEL_APPLICATION,
|
||||
NULL, 0, key, key_len, iv, iv_len, mac_secret,
|
||||
md_len, ciph, 0, NID_undef, md, comp, NULL)) {
|
||||
/* SSLfatal already called */
|
||||
goto err;
|
||||
}
|
||||
|
||||
return 1;
|
||||
err:
|
||||
return 0;
|
||||
}
|
||||
|
||||
int ssl3_setup_key_block(SSL_CONNECTION *s)
|
||||
{
|
||||
unsigned char *p;
|
||||
const EVP_CIPHER *c;
|
||||
const EVP_MD *hash;
|
||||
int num;
|
||||
int ret = 0;
|
||||
SSL_COMP *comp;
|
||||
|
||||
if (s->s3.tmp.key_block_length != 0)
|
||||
return 1;
|
||||
|
||||
if (!ssl_cipher_get_evp(SSL_CONNECTION_GET_CTX(s), s->session, &c, &hash,
|
||||
NULL, NULL, &comp, 0)) {
|
||||
/* Error is already recorded */
|
||||
SSLfatal_alert(s, SSL_AD_INTERNAL_ERROR);
|
||||
return 0;
|
||||
}
|
||||
|
||||
ssl_evp_cipher_free(s->s3.tmp.new_sym_enc);
|
||||
s->s3.tmp.new_sym_enc = c;
|
||||
ssl_evp_md_free(s->s3.tmp.new_hash);
|
||||
s->s3.tmp.new_hash = hash;
|
||||
#ifdef OPENSSL_NO_COMP
|
||||
s->s3.tmp.new_compression = NULL;
|
||||
#else
|
||||
s->s3.tmp.new_compression = comp;
|
||||
#endif
|
||||
|
||||
num = EVP_MD_get_size(hash);
|
||||
if (num <= 0)
|
||||
return 0;
|
||||
|
||||
num = EVP_CIPHER_get_key_length(c) + num + EVP_CIPHER_get_iv_length(c);
|
||||
num *= 2;
|
||||
|
||||
ssl3_cleanup_key_block(s);
|
||||
|
||||
if ((p = OPENSSL_malloc(num)) == NULL) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_CRYPTO_LIB);
|
||||
return 0;
|
||||
}
|
||||
|
||||
s->s3.tmp.key_block_length = num;
|
||||
s->s3.tmp.key_block = p;
|
||||
|
||||
/* Calls SSLfatal() as required */
|
||||
ret = ssl3_generate_key_block(s, p, num);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
void ssl3_cleanup_key_block(SSL_CONNECTION *s)
|
||||
{
|
||||
OPENSSL_clear_free(s->s3.tmp.key_block, s->s3.tmp.key_block_length);
|
||||
|
|
@ -307,199 +112,3 @@ int ssl3_digest_cached_records(SSL_CONNECTION *s, int keep)
|
|||
|
||||
return 1;
|
||||
}
|
||||
|
||||
void ssl3_digest_master_key_set_params(const SSL_SESSION *session,
|
||||
OSSL_PARAM params[])
|
||||
{
|
||||
int n = 0;
|
||||
params[n++] = OSSL_PARAM_construct_octet_string(OSSL_DIGEST_PARAM_SSL3_MS,
|
||||
(void *)session->master_key,
|
||||
session->master_key_length);
|
||||
params[n++] = OSSL_PARAM_construct_end();
|
||||
}
|
||||
|
||||
size_t ssl3_final_finish_mac(SSL_CONNECTION *s, const char *sender, size_t len,
|
||||
unsigned char *p)
|
||||
{
|
||||
int ret;
|
||||
EVP_MD_CTX *ctx = NULL;
|
||||
|
||||
if (!ssl3_digest_cached_records(s, 0)) {
|
||||
/* SSLfatal() already called */
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (EVP_MD_CTX_get_type(s->s3.handshake_dgst) != NID_md5_sha1) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_NO_REQUIRED_DIGEST);
|
||||
return 0;
|
||||
}
|
||||
|
||||
ctx = EVP_MD_CTX_new();
|
||||
if (ctx == NULL) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
return 0;
|
||||
}
|
||||
if (!EVP_MD_CTX_copy_ex(ctx, s->s3.handshake_dgst)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
ret = 0;
|
||||
goto err;
|
||||
}
|
||||
|
||||
ret = EVP_MD_CTX_get_size(ctx);
|
||||
if (ret < 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
ret = 0;
|
||||
goto err;
|
||||
}
|
||||
|
||||
if (sender != NULL) {
|
||||
OSSL_PARAM digest_cmd_params[3];
|
||||
|
||||
ssl3_digest_master_key_set_params(s->session, digest_cmd_params);
|
||||
|
||||
if (EVP_DigestUpdate(ctx, sender, len) <= 0
|
||||
|| EVP_MD_CTX_set_params(ctx, digest_cmd_params) <= 0
|
||||
|| EVP_DigestFinal_ex(ctx, p, NULL) <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
ret = 0;
|
||||
}
|
||||
}
|
||||
|
||||
err:
|
||||
EVP_MD_CTX_free(ctx);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
int ssl3_generate_master_secret(SSL_CONNECTION *s, unsigned char *out,
|
||||
unsigned char *p,
|
||||
size_t len, size_t *secret_size)
|
||||
{
|
||||
static const unsigned char *const salt[3] = {
|
||||
#ifndef CHARSET_EBCDIC
|
||||
(const unsigned char *)"A",
|
||||
(const unsigned char *)"BB",
|
||||
(const unsigned char *)"CCC",
|
||||
#else
|
||||
(const unsigned char *)"\x41",
|
||||
(const unsigned char *)"\x42\x42",
|
||||
(const unsigned char *)"\x43\x43\x43",
|
||||
#endif
|
||||
};
|
||||
unsigned char buf[EVP_MAX_MD_SIZE];
|
||||
EVP_MD_CTX *ctx = EVP_MD_CTX_new();
|
||||
int i, ret = 1;
|
||||
unsigned int n;
|
||||
size_t ret_secret_size = 0;
|
||||
|
||||
if (ctx == NULL) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
return 0;
|
||||
}
|
||||
for (i = 0; i < 3; i++) {
|
||||
if (EVP_DigestInit_ex(ctx, SSL_CONNECTION_GET_CTX(s)->sha1, NULL) <= 0
|
||||
|| EVP_DigestUpdate(ctx, salt[i],
|
||||
strlen((const char *)salt[i]))
|
||||
<= 0
|
||||
|| EVP_DigestUpdate(ctx, p, len) <= 0
|
||||
|| EVP_DigestUpdate(ctx, &(s->s3.client_random[0]),
|
||||
SSL3_RANDOM_SIZE)
|
||||
<= 0
|
||||
|| EVP_DigestUpdate(ctx, &(s->s3.server_random[0]),
|
||||
SSL3_RANDOM_SIZE)
|
||||
<= 0
|
||||
|| EVP_DigestFinal_ex(ctx, buf, &n) <= 0
|
||||
|| EVP_DigestInit_ex(ctx, SSL_CONNECTION_GET_CTX(s)->md5, NULL) <= 0
|
||||
|| EVP_DigestUpdate(ctx, p, len) <= 0
|
||||
|| EVP_DigestUpdate(ctx, buf, n) <= 0
|
||||
|| EVP_DigestFinal_ex(ctx, out, &n) <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
ret = 0;
|
||||
break;
|
||||
}
|
||||
out += n;
|
||||
ret_secret_size += n;
|
||||
}
|
||||
EVP_MD_CTX_free(ctx);
|
||||
|
||||
OPENSSL_cleanse(buf, sizeof(buf));
|
||||
if (ret)
|
||||
*secret_size = ret_secret_size;
|
||||
return ret;
|
||||
}
|
||||
|
||||
int ssl3_alert_code(int code)
|
||||
{
|
||||
switch (code) {
|
||||
case SSL_AD_CLOSE_NOTIFY:
|
||||
return SSL3_AD_CLOSE_NOTIFY;
|
||||
case SSL_AD_UNEXPECTED_MESSAGE:
|
||||
return SSL3_AD_UNEXPECTED_MESSAGE;
|
||||
case SSL_AD_BAD_RECORD_MAC:
|
||||
return SSL3_AD_BAD_RECORD_MAC;
|
||||
case SSL_AD_DECRYPTION_FAILED:
|
||||
return SSL3_AD_BAD_RECORD_MAC;
|
||||
case SSL_AD_RECORD_OVERFLOW:
|
||||
return SSL3_AD_BAD_RECORD_MAC;
|
||||
case SSL_AD_DECOMPRESSION_FAILURE:
|
||||
return SSL3_AD_DECOMPRESSION_FAILURE;
|
||||
case SSL_AD_HANDSHAKE_FAILURE:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_NO_CERTIFICATE:
|
||||
return SSL3_AD_NO_CERTIFICATE;
|
||||
case SSL_AD_BAD_CERTIFICATE:
|
||||
return SSL3_AD_BAD_CERTIFICATE;
|
||||
case SSL_AD_UNSUPPORTED_CERTIFICATE:
|
||||
return SSL3_AD_UNSUPPORTED_CERTIFICATE;
|
||||
case SSL_AD_CERTIFICATE_REVOKED:
|
||||
return SSL3_AD_CERTIFICATE_REVOKED;
|
||||
case SSL_AD_CERTIFICATE_EXPIRED:
|
||||
return SSL3_AD_CERTIFICATE_EXPIRED;
|
||||
case SSL_AD_CERTIFICATE_UNKNOWN:
|
||||
return SSL3_AD_CERTIFICATE_UNKNOWN;
|
||||
case SSL_AD_ILLEGAL_PARAMETER:
|
||||
return SSL3_AD_ILLEGAL_PARAMETER;
|
||||
case SSL_AD_UNKNOWN_CA:
|
||||
return SSL3_AD_BAD_CERTIFICATE;
|
||||
case SSL_AD_ACCESS_DENIED:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_DECODE_ERROR:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_DECRYPT_ERROR:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_EXPORT_RESTRICTION:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_PROTOCOL_VERSION:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_INSUFFICIENT_SECURITY:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_INTERNAL_ERROR:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_USER_CANCELLED:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_NO_RENEGOTIATION:
|
||||
return -1; /* Don't send it :-) */
|
||||
case SSL_AD_UNSUPPORTED_EXTENSION:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_CERTIFICATE_UNOBTAINABLE:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_UNRECOGNIZED_NAME:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_BAD_CERTIFICATE_STATUS_RESPONSE:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_BAD_CERTIFICATE_HASH_VALUE:
|
||||
return SSL3_AD_HANDSHAKE_FAILURE;
|
||||
case SSL_AD_UNKNOWN_PSK_IDENTITY:
|
||||
return TLS1_AD_UNKNOWN_PSK_IDENTITY;
|
||||
case SSL_AD_INAPPROPRIATE_FALLBACK:
|
||||
return TLS1_AD_INAPPROPRIATE_FALLBACK;
|
||||
case SSL_AD_NO_APPLICATION_PROTOCOL:
|
||||
return TLS1_AD_NO_APPLICATION_PROTOCOL;
|
||||
case SSL_AD_CERTIFICATE_REQUIRED:
|
||||
return SSL_AD_HANDSHAKE_FAILURE;
|
||||
case TLS13_AD_MISSING_EXTENSION:
|
||||
return SSL_AD_HANDSHAKE_FAILURE;
|
||||
default:
|
||||
return -1;
|
||||
}
|
||||
}
|
||||
|
|
|
|||
58
ssl/s3_lib.c
58
ssl/s3_lib.c
|
|
@ -3735,44 +3735,6 @@ void ssl_sort_cipher_list(void)
|
|||
qsort(ssl3_scsvs, SSL3_NUM_SCSVS, sizeof(ssl3_scsvs[0]), cipher_compare);
|
||||
}
|
||||
|
||||
static int sslcon_undefined_function_1(SSL_CONNECTION *sc, unsigned char *r,
|
||||
size_t s, const char *t, size_t u,
|
||||
const unsigned char *v, size_t w, int x)
|
||||
{
|
||||
(void)r;
|
||||
(void)s;
|
||||
(void)t;
|
||||
(void)u;
|
||||
(void)v;
|
||||
(void)w;
|
||||
(void)x;
|
||||
return ssl_undefined_function(SSL_CONNECTION_GET_SSL(sc));
|
||||
}
|
||||
|
||||
const SSL3_ENC_METHOD SSLv3_enc_data = {
|
||||
ssl3_setup_key_block,
|
||||
ssl3_generate_master_secret,
|
||||
ssl3_change_cipher_state,
|
||||
ssl3_final_finish_mac,
|
||||
SSL3_MD_CLIENT_FINISHED_CONST, 4,
|
||||
SSL3_MD_SERVER_FINISHED_CONST, 4,
|
||||
ssl3_alert_code,
|
||||
sslcon_undefined_function_1,
|
||||
0,
|
||||
ssl3_set_handshake_header,
|
||||
tls_close_construct_packet,
|
||||
ssl3_handshake_write
|
||||
};
|
||||
|
||||
OSSL_TIME ssl3_default_timeout(void)
|
||||
{
|
||||
/*
|
||||
* 2 hours, the 24 hours mentioned in the SSLv3 spec is way too long for
|
||||
* http, the cache would over fill
|
||||
*/
|
||||
return ossl_seconds2time(60 * 60 * 2);
|
||||
}
|
||||
|
||||
int ssl3_num_ciphers(void)
|
||||
{
|
||||
return SSL3_NUM_CIPHERS;
|
||||
|
|
@ -3927,7 +3889,7 @@ int ssl3_clear(SSL *s)
|
|||
if (!ssl_free_wbio_buffer(sc))
|
||||
return 0;
|
||||
|
||||
sc->version = SSL3_VERSION;
|
||||
sc->version = TLS1_VERSION;
|
||||
|
||||
#if !defined(OPENSSL_NO_NEXTPROTONEG)
|
||||
OPENSSL_free(sc->ext.npn);
|
||||
|
|
@ -4041,7 +4003,7 @@ long ssl3_ctrl(SSL *s, int cmd, long larg, void *parg)
|
|||
break;
|
||||
len = strlen((char *)parg);
|
||||
if (len == 0 || len > TLSEXT_MAXLEN_host_name) {
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_SSL3_EXT_INVALID_SERVERNAME);
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_TLS_EXT_INVALID_SERVERNAME);
|
||||
return 0;
|
||||
}
|
||||
if ((sc->ext.hostname = OPENSSL_strdup((char *)parg)) == NULL) {
|
||||
|
|
@ -4049,7 +4011,7 @@ long ssl3_ctrl(SSL *s, int cmd, long larg, void *parg)
|
|||
return 0;
|
||||
}
|
||||
} else {
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE);
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_TLS_EXT_INVALID_SERVERNAME_TYPE);
|
||||
return 0;
|
||||
}
|
||||
break;
|
||||
|
|
@ -4980,7 +4942,10 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL_CONNECTION *s, STACK_OF(SSL_CIPHER) *cl
|
|||
|
||||
int ssl3_get_req_cert_type(SSL_CONNECTION *s, WPACKET *pkt)
|
||||
{
|
||||
uint32_t alg_k, alg_a = 0;
|
||||
#ifndef OPENSSL_NO_GOST
|
||||
uint32_t alg_k;
|
||||
#endif
|
||||
uint32_t alg_a = 0;
|
||||
|
||||
/* If we have custom certificate types set, use them */
|
||||
if (s->cert->ctype)
|
||||
|
|
@ -4988,9 +4953,9 @@ int ssl3_get_req_cert_type(SSL_CONNECTION *s, WPACKET *pkt)
|
|||
/* Get mask of algorithms disabled by signature list */
|
||||
ssl_set_sig_mask(&alg_a, s, SSL_SECOP_SIGALG_MASK);
|
||||
|
||||
#ifndef OPENSSL_NO_GOST
|
||||
alg_k = s->s3.tmp.new_cipher->algorithm_mkey;
|
||||
|
||||
#ifndef OPENSSL_NO_GOST
|
||||
if (s->version >= TLS1_VERSION && (alg_k & SSL_kGOST))
|
||||
if (!WPACKET_put_bytes_u8(pkt, TLS_CT_GOST01_SIGN)
|
||||
|| !WPACKET_put_bytes_u8(pkt, TLS_CT_GOST12_IANA_SIGN)
|
||||
|
|
@ -5005,13 +4970,6 @@ int ssl3_get_req_cert_type(SSL_CONNECTION *s, WPACKET *pkt)
|
|||
return 0;
|
||||
#endif
|
||||
|
||||
if ((s->version == SSL3_VERSION) && (alg_k & SSL_kDHE)) {
|
||||
if (!WPACKET_put_bytes_u8(pkt, SSL3_CT_RSA_EPHEMERAL_DH))
|
||||
return 0;
|
||||
if (!(alg_a & SSL_aDSS)
|
||||
&& !WPACKET_put_bytes_u8(pkt, SSL3_CT_DSS_EPHEMERAL_DH))
|
||||
return 0;
|
||||
}
|
||||
if (!(alg_a & SSL_aRSA) && !WPACKET_put_bytes_u8(pkt, SSL3_CT_RSA_SIGN))
|
||||
return 0;
|
||||
if (!(alg_a & SSL_aDSS) && !WPACKET_put_bytes_u8(pkt, SSL3_CT_DSS_SIGN))
|
||||
|
|
|
|||
|
|
@ -51,9 +51,6 @@ int ssl3_send_alert(SSL_CONNECTION *s, int level, int desc)
|
|||
desc = tls13_alert_code(desc);
|
||||
else
|
||||
desc = ssl->method->ssl3_enc->alert_value(desc);
|
||||
if (s->version == SSL3_VERSION && desc == SSL_AD_PROTOCOL_VERSION)
|
||||
desc = SSL_AD_HANDSHAKE_FAILURE; /* SSL 3.0 does not have
|
||||
* protocol_version alerts */
|
||||
if (desc < 0)
|
||||
return -1;
|
||||
if (s->shutdown & SSL_SENT_SHUTDOWN && desc != SSL_AD_CLOSE_NOTIFY)
|
||||
|
|
|
|||
|
|
@ -254,7 +254,6 @@ static const SSL_CIPHER cipher_aliases[] = {
|
|||
{ 0, SSL_TXT_GOST12, NULL, 0, 0, 0, 0, SSL_GOST12_256 },
|
||||
|
||||
/* protocol version aliases */
|
||||
{ 0, SSL_TXT_SSLV3, NULL, 0, 0, 0, 0, 0, SSL3_VERSION },
|
||||
{ 0, SSL_TXT_TLSV1, NULL, 0, 0, 0, 0, 0, TLS1_VERSION },
|
||||
{ 0, "TLSv1.0", NULL, 0, 0, 0, 0, 0, TLS1_VERSION },
|
||||
{ 0, SSL_TXT_TLSV1_2, NULL, 0, 0, 0, 0, 0, TLS1_2_VERSION },
|
||||
|
|
|
|||
|
|
@ -494,7 +494,7 @@ static int ssl_check_allowed_versions(int min_version, int max_version)
|
|||
} else {
|
||||
/* Regular TLS version checks. */
|
||||
if (min_version == 0)
|
||||
min_version = SSL3_VERSION;
|
||||
min_version = TLS1_VERSION;
|
||||
if (max_version == 0)
|
||||
max_version = TLS1_3_VERSION;
|
||||
#ifdef OPENSSL_NO_TLS1_3
|
||||
|
|
@ -513,10 +513,6 @@ static int ssl_check_allowed_versions(int min_version, int max_version)
|
|||
if (max_version == TLS1_VERSION)
|
||||
max_version = SSL3_VERSION;
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SSL3
|
||||
if (min_version == SSL3_VERSION)
|
||||
min_version = TLS1_VERSION;
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1
|
||||
if (min_version == TLS1_VERSION)
|
||||
min_version = TLS1_1_VERSION;
|
||||
|
|
@ -531,9 +527,6 @@ static int ssl_check_allowed_versions(int min_version, int max_version)
|
|||
#endif
|
||||
/* Done massaging versions; do the check. */
|
||||
if (0
|
||||
#ifdef OPENSSL_NO_SSL3
|
||||
|| (min_version <= SSL3_VERSION && SSL3_VERSION <= max_version)
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1
|
||||
|| (min_version <= TLS1_VERSION && TLS1_VERSION <= max_version)
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -2297,9 +2297,6 @@ extern const unsigned char tls12downgrade[8];
|
|||
|
||||
extern const SSL3_ENC_METHOD ssl3_undef_enc_method;
|
||||
|
||||
__owur const SSL_METHOD *sslv3_method(void);
|
||||
__owur const SSL_METHOD *sslv3_server_method(void);
|
||||
__owur const SSL_METHOD *sslv3_client_method(void);
|
||||
__owur const SSL_METHOD *tlsv1_method(void);
|
||||
__owur const SSL_METHOD *tlsv1_server_method(void);
|
||||
__owur const SSL_METHOD *tlsv1_client_method(void);
|
||||
|
|
@ -2324,7 +2321,6 @@ extern const SSL3_ENC_METHOD TLSv1_enc_data;
|
|||
extern const SSL3_ENC_METHOD TLSv1_1_enc_data;
|
||||
extern const SSL3_ENC_METHOD TLSv1_2_enc_data;
|
||||
extern const SSL3_ENC_METHOD TLSv1_3_enc_data;
|
||||
extern const SSL3_ENC_METHOD SSLv3_enc_data;
|
||||
extern const SSL3_ENC_METHOD DTLSv1_enc_data;
|
||||
extern const SSL3_ENC_METHOD DTLSv1_2_enc_data;
|
||||
|
||||
|
|
@ -2375,46 +2371,6 @@ extern const SSL3_ENC_METHOD DTLSv1_2_enc_data;
|
|||
return &func_name##_data; \
|
||||
}
|
||||
|
||||
#define IMPLEMENT_ssl3_meth_func(func_name, s_accept, s_connect) \
|
||||
const SSL_METHOD *func_name(void) \
|
||||
{ \
|
||||
static const SSL_METHOD func_name##_data = { \
|
||||
SSL3_VERSION, \
|
||||
SSL_METHOD_NO_FIPS | SSL_METHOD_NO_SUITEB, \
|
||||
SSL_OP_NO_SSLv3, \
|
||||
ossl_ssl_connection_new, \
|
||||
ossl_ssl_connection_free, \
|
||||
ossl_ssl_connection_reset, \
|
||||
ssl3_new, \
|
||||
ssl3_clear, \
|
||||
ssl3_free, \
|
||||
s_accept, \
|
||||
s_connect, \
|
||||
ssl3_read, \
|
||||
ssl3_peek, \
|
||||
ssl3_write, \
|
||||
ssl3_shutdown, \
|
||||
ssl3_renegotiate, \
|
||||
ssl3_renegotiate_check, \
|
||||
ssl3_read_bytes, \
|
||||
ssl3_write_bytes, \
|
||||
ssl3_dispatch_alert, \
|
||||
ssl3_ctrl, \
|
||||
ssl3_ctx_ctrl, \
|
||||
ssl3_get_cipher_by_char, \
|
||||
ssl3_put_cipher_by_char, \
|
||||
ssl3_pending, \
|
||||
ssl3_num_ciphers, \
|
||||
ssl3_get_cipher, \
|
||||
ssl3_default_timeout, \
|
||||
&SSLv3_enc_data, \
|
||||
ssl_undefined_void_function, \
|
||||
ssl3_callback_ctrl, \
|
||||
ssl3_ctx_callback_ctrl, \
|
||||
}; \
|
||||
return &func_name##_data; \
|
||||
}
|
||||
|
||||
#define IMPLEMENT_dtls1_meth_func(version, flags, mask, func_name, s_accept, \
|
||||
s_connect, enc_data) \
|
||||
const SSL_METHOD *func_name(void) \
|
||||
|
|
@ -2645,24 +2601,15 @@ __owur const SSL_CIPHER *ssl3_get_cipher_by_char(const unsigned char *p);
|
|||
__owur int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt,
|
||||
size_t *len);
|
||||
int ssl3_init_finished_mac(SSL_CONNECTION *s);
|
||||
__owur int ssl3_setup_key_block(SSL_CONNECTION *s);
|
||||
__owur int ssl3_change_cipher_state(SSL_CONNECTION *s, int which);
|
||||
void ssl3_cleanup_key_block(SSL_CONNECTION *s);
|
||||
__owur int ssl3_do_write(SSL_CONNECTION *s, uint8_t type);
|
||||
int ssl3_send_alert(SSL_CONNECTION *s, int level, int desc);
|
||||
__owur int ssl3_generate_master_secret(SSL_CONNECTION *s, unsigned char *out,
|
||||
unsigned char *p, size_t len,
|
||||
size_t *secret_size);
|
||||
__owur int ssl3_get_req_cert_type(SSL_CONNECTION *s, WPACKET *pkt);
|
||||
__owur int ssl3_num_ciphers(void);
|
||||
__owur const SSL_CIPHER *ssl3_get_cipher(unsigned int u);
|
||||
int ssl3_renegotiate(SSL *ssl);
|
||||
int ssl3_renegotiate_check(SSL *ssl, int initok);
|
||||
void ssl3_digest_master_key_set_params(const SSL_SESSION *session,
|
||||
OSSL_PARAM params[]);
|
||||
__owur int ssl3_dispatch_alert(SSL *s);
|
||||
__owur size_t ssl3_final_finish_mac(SSL_CONNECTION *s, const char *sender,
|
||||
size_t slen, unsigned char *p);
|
||||
__owur int ssl3_finish_mac(SSL_CONNECTION *s, const unsigned char *buf,
|
||||
size_t len);
|
||||
void ssl3_free_digest_list(SSL_CONNECTION *s);
|
||||
|
|
@ -2685,7 +2632,6 @@ __owur long ssl3_callback_ctrl(SSL *s, int cmd, void (*fp)(void));
|
|||
__owur long ssl3_ctx_callback_ctrl(SSL_CTX *s, int cmd, void (*fp)(void));
|
||||
|
||||
__owur int ssl3_do_change_cipher_spec(SSL_CONNECTION *s);
|
||||
__owur OSSL_TIME ssl3_default_timeout(void);
|
||||
|
||||
__owur int ssl3_set_handshake_header(SSL_CONNECTION *s, WPACKET *pkt,
|
||||
int htype);
|
||||
|
|
@ -2823,7 +2769,6 @@ __owur int tls13_export_keying_material_early(SSL_CONNECTION *s,
|
|||
size_t contextlen);
|
||||
__owur int tls1_alert_code(int code);
|
||||
__owur int tls13_alert_code(int code);
|
||||
__owur int ssl3_alert_code(int code);
|
||||
|
||||
__owur int ssl_check_srvr_ecc_cert_and_alg(X509 *x, SSL_CONNECTION *s);
|
||||
|
||||
|
|
@ -3088,7 +3033,7 @@ long ossl_ctrl_internal(SSL *s, int cmd, long larg, void *parg, int no_quic);
|
|||
* allowed but ignored under QUIC.
|
||||
*/
|
||||
#define OSSL_TLS1_2_OPTIONS \
|
||||
(SSL_OP_CRYPTOPRO_TLSEXT_BUG | SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS | SSL_OP_ALLOW_CLIENT_RENEGOTIATION | SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION | SSL_OP_NO_COMPRESSION | SSL_OP_NO_SSLv3 | SSL_OP_NO_TLSv1 | SSL_OP_NO_TLSv1_1 | SSL_OP_NO_TLSv1_2 | SSL_OP_NO_DTLSv1 | SSL_OP_NO_DTLSv1_2 | SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION | SSL_OP_CISCO_ANYCONNECT | SSL_OP_NO_RENEGOTIATION | SSL_OP_NO_EXTENDED_MASTER_SECRET | SSL_OP_NO_ENCRYPT_THEN_MAC | SSL_OP_COOKIE_EXCHANGE | SSL_OP_LEGACY_SERVER_CONNECT | SSL_OP_IGNORE_UNEXPECTED_EOF)
|
||||
(SSL_OP_CRYPTOPRO_TLSEXT_BUG | SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS | SSL_OP_ALLOW_CLIENT_RENEGOTIATION | SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION | SSL_OP_NO_COMPRESSION | SSL_OP_NO_TLSv1 | SSL_OP_NO_TLSv1_1 | SSL_OP_NO_TLSv1_2 | SSL_OP_NO_DTLSv1 | SSL_OP_NO_DTLSv1_2 | SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION | SSL_OP_CISCO_ANYCONNECT | SSL_OP_NO_RENEGOTIATION | SSL_OP_NO_EXTENDED_MASTER_SECRET | SSL_OP_NO_ENCRYPT_THEN_MAC | SSL_OP_COOKIE_EXCHANGE | SSL_OP_LEGACY_SERVER_CONNECT | SSL_OP_IGNORE_UNEXPECTED_EOF)
|
||||
|
||||
/* Total mask of connection-level options permitted or ignored under QUIC. */
|
||||
#define OSSL_QUIC_PERMITTED_OPTIONS_CONN \
|
||||
|
|
|
|||
|
|
@ -351,7 +351,6 @@ int ssl_generate_session_id(SSL_CONNECTION *s, SSL_SESSION *ss)
|
|||
SSL *ssl = SSL_CONNECTION_GET_SSL(s);
|
||||
|
||||
switch (s->version) {
|
||||
case SSL3_VERSION:
|
||||
case TLS1_VERSION:
|
||||
case TLS1_1_VERSION:
|
||||
case TLS1_2_VERSION:
|
||||
|
|
|
|||
|
|
@ -144,7 +144,7 @@ typedef struct extensions_definition_st {
|
|||
static const EXTENSION_DEFINITION ext_defs[] = {
|
||||
{ TLSEXT_TYPE_renegotiate,
|
||||
SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO
|
||||
| SSL_EXT_SSL3_ALLOWED | SSL_EXT_TLS1_2_AND_BELOW_ONLY,
|
||||
| SSL_EXT_TLS1_2_AND_BELOW_ONLY,
|
||||
NULL, tls_parse_ctos_renegotiate, tls_parse_stoc_renegotiate,
|
||||
tls_construct_stoc_renegotiate, tls_construct_ctos_renegotiate,
|
||||
final_renegotiate },
|
||||
|
|
@ -522,8 +522,6 @@ int extension_is_relevant(SSL_CONNECTION *s, unsigned int extctx,
|
|||
|
||||
if ((SSL_CONNECTION_IS_DTLS(s)
|
||||
&& (extctx & SSL_EXT_TLS_IMPLEMENTATION_ONLY) != 0)
|
||||
|| (s->version == SSL3_VERSION
|
||||
&& (extctx & SSL_EXT_SSL3_ALLOWED) == 0)
|
||||
/*
|
||||
* Note that SSL_IS_TLS13() means "TLS 1.3 has been negotiated",
|
||||
* which is never true when generating the ClientHello.
|
||||
|
|
|
|||
|
|
@ -145,10 +145,6 @@ static int use_ecc(SSL_CONNECTION *s, int min_version, int max_version)
|
|||
size_t num_groups, j;
|
||||
SSL *ssl = SSL_CONNECTION_GET_SSL(s);
|
||||
|
||||
/* See if we support any ECC ciphersuites */
|
||||
if (s->version == SSL3_VERSION)
|
||||
return 0;
|
||||
|
||||
cipher_stack = SSL_get1_supported_ciphers(ssl);
|
||||
end = sk_SSL_CIPHER_num(cipher_stack);
|
||||
for (i = 0; i < end; i++) {
|
||||
|
|
@ -1369,7 +1365,7 @@ int tls_parse_stoc_maxfragmentlen(SSL_CONNECTION *s, PACKET *pkt,
|
|||
/* |value| should contains a valid max-fragment-length code. */
|
||||
if (!IS_MAX_FRAGMENT_LENGTH_EXT_VALID(value)) {
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER,
|
||||
SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
@ -1381,7 +1377,7 @@ int tls_parse_stoc_maxfragmentlen(SSL_CONNECTION *s, PACKET *pkt,
|
|||
*/
|
||||
if (value != s->ext.max_fragment_len_mode) {
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER,
|
||||
SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -188,7 +188,7 @@ int tls_parse_ctos_maxfragmentlen(SSL_CONNECTION *s, PACKET *pkt,
|
|||
/* Received |value| should be a valid max-fragment-length code. */
|
||||
if (!IS_MAX_FRAGMENT_LENGTH_EXT_VALID(value)) {
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER,
|
||||
SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -55,9 +55,8 @@ static ossl_inline int received_server_cert(SSL_CONNECTION *sc)
|
|||
static ossl_inline int cert_req_allowed(SSL_CONNECTION *s)
|
||||
{
|
||||
/* TLS does not like anon-DH with client cert */
|
||||
if ((s->version > SSL3_VERSION
|
||||
&& (s->s3.tmp.new_cipher->algorithm_auth & SSL_aNULL))
|
||||
|| (s->s3.tmp.new_cipher->algorithm_auth & (SSL_aSRP | SSL_aPSK)))
|
||||
if ((s->s3.tmp.new_cipher->algorithm_auth & SSL_aNULL) != 0
|
||||
|| (s->s3.tmp.new_cipher->algorithm_auth & (SSL_aSRP | SSL_aPSK)) != 0)
|
||||
return 0;
|
||||
|
||||
return 1;
|
||||
|
|
@ -1519,7 +1518,7 @@ MSG_PROCESS_RETURN tls_process_server_hello(SSL_CONNECTION *s, PACKET *pkt)
|
|||
session_id_len = PACKET_remaining(&session_id);
|
||||
if (session_id_len > sizeof(s->session->session_id)
|
||||
|| session_id_len > SSL3_SESSION_ID_SIZE) {
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_SSL3_SESSION_ID_TOO_LONG);
|
||||
SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_TLS_SESSION_ID_TOO_LONG);
|
||||
goto err;
|
||||
}
|
||||
|
||||
|
|
@ -3182,7 +3181,7 @@ static int tls_construct_cke_rsa(SSL_CONNECTION *s, WPACKET *pkt)
|
|||
}
|
||||
|
||||
/* Fix buf for TLS and beyond */
|
||||
if (s->version > SSL3_VERSION && !WPACKET_start_sub_packet_u16(pkt)) {
|
||||
if (!WPACKET_start_sub_packet_u16(pkt)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
|
|
@ -3202,7 +3201,7 @@ static int tls_construct_cke_rsa(SSL_CONNECTION *s, WPACKET *pkt)
|
|||
pctx = NULL;
|
||||
|
||||
/* Fix buf for TLS and beyond */
|
||||
if (s->version > SSL3_VERSION && !WPACKET_close(pkt)) {
|
||||
if (!WPACKET_close(pkt)) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR);
|
||||
goto err;
|
||||
}
|
||||
|
|
@ -3808,18 +3807,11 @@ WORK_STATE tls_prepare_client_certificate(SSL_CONNECTION *s, WORK_STATE wst)
|
|||
if (i && !ssl3_check_client_certificate(s))
|
||||
i = 0;
|
||||
if (i == 0) {
|
||||
if (s->version == SSL3_VERSION) {
|
||||
s->s3.tmp.cert_req = 0;
|
||||
ssl3_send_alert(s, SSL3_AL_WARNING, SSL_AD_NO_CERTIFICATE);
|
||||
return WORK_FINISHED_CONTINUE;
|
||||
} else {
|
||||
s->s3.tmp.cert_req = 2;
|
||||
s->ext.compress_certificate_from_peer[0] = TLSEXT_comp_cert_none;
|
||||
if (!ssl3_digest_cached_records(s, 0)) {
|
||||
/* SSLfatal() already called */
|
||||
return WORK_ERROR;
|
||||
}
|
||||
}
|
||||
s->s3.tmp.cert_req = 2;
|
||||
s->ext.compress_certificate_from_peer[0] = TLSEXT_comp_cert_none;
|
||||
if (!ssl3_digest_cached_records(s, 0))
|
||||
/* SSLfatal() already called */
|
||||
return WORK_ERROR;
|
||||
}
|
||||
|
||||
if (!SSL_CONNECTION_IS_TLS13(s)
|
||||
|
|
|
|||
|
|
@ -369,42 +369,20 @@ CON_FUNC_RETURN tls_construct_cert_verify(SSL_CONNECTION *s, WPACKET *pkt)
|
|||
goto err;
|
||||
}
|
||||
}
|
||||
if (s->version == SSL3_VERSION) {
|
||||
/*
|
||||
* Here we use EVP_DigestSignUpdate followed by EVP_DigestSignFinal
|
||||
* in order to add the EVP_CTRL_SSL3_MASTER_SECRET call between them.
|
||||
*/
|
||||
if (EVP_DigestSignUpdate(mctx, hdata, hdatalen) <= 0
|
||||
|| EVP_MD_CTX_ctrl(mctx, EVP_CTRL_SSL3_MASTER_SECRET,
|
||||
(int)s->session->master_key_length,
|
||||
s->session->master_key)
|
||||
<= 0
|
||||
|| EVP_DigestSignFinal(mctx, NULL, &siglen) <= 0) {
|
||||
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
goto err;
|
||||
}
|
||||
sig = OPENSSL_malloc(siglen);
|
||||
if (sig == NULL
|
||||
|| EVP_DigestSignFinal(mctx, sig, &siglen) <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
goto err;
|
||||
}
|
||||
} else {
|
||||
/*
|
||||
* Here we *must* use EVP_DigestSign() because Ed25519/Ed448 does not
|
||||
* support streaming via EVP_DigestSignUpdate/EVP_DigestSignFinal
|
||||
*/
|
||||
if (EVP_DigestSign(mctx, NULL, &siglen, hdata, hdatalen) <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
goto err;
|
||||
}
|
||||
sig = OPENSSL_malloc(siglen);
|
||||
if (sig == NULL
|
||||
|| EVP_DigestSign(mctx, sig, &siglen, hdata, hdatalen) <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
goto err;
|
||||
}
|
||||
/*
|
||||
* Here we *must* use EVP_DigestSign() because Ed25519/Ed448 does not
|
||||
* support streaming via EVP_DigestSignUpdate/EVP_DigestSignFinal
|
||||
*/
|
||||
if (EVP_DigestSign(mctx, NULL, &siglen, hdata, hdatalen) <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
goto err;
|
||||
}
|
||||
sig = OPENSSL_malloc(siglen);
|
||||
if (sig == NULL
|
||||
|| EVP_DigestSign(mctx, sig, &siglen, hdata, hdatalen) <= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
goto err;
|
||||
}
|
||||
|
||||
#ifndef OPENSSL_NO_GOST
|
||||
|
|
@ -567,30 +545,16 @@ MSG_PROCESS_RETURN tls_process_cert_verify(SSL_CONNECTION *s, PACKET *pkt)
|
|||
goto err;
|
||||
}
|
||||
}
|
||||
if (s->version == SSL3_VERSION) {
|
||||
if (EVP_DigestVerifyUpdate(mctx, hdata, hdatalen) <= 0
|
||||
|| EVP_MD_CTX_ctrl(mctx, EVP_CTRL_SSL3_MASTER_SECRET,
|
||||
(int)s->session->master_key_length,
|
||||
s->session->master_key)
|
||||
<= 0) {
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB);
|
||||
goto err;
|
||||
}
|
||||
if (EVP_DigestVerifyFinal(mctx, data, len) <= 0) {
|
||||
SSLfatal(s, SSL_AD_DECRYPT_ERROR, SSL_R_BAD_SIGNATURE);
|
||||
goto err;
|
||||
}
|
||||
} else {
|
||||
j = EVP_DigestVerify(mctx, data, len, hdata, hdatalen);
|
||||
|
||||
j = EVP_DigestVerify(mctx, data, len, hdata, hdatalen);
|
||||
#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
|
||||
/* Ignore bad signatures when fuzzing */
|
||||
if (SSL_IS_QUIC_HANDSHAKE(s))
|
||||
j = 1;
|
||||
/* Ignore bad signatures when fuzzing */
|
||||
if (SSL_IS_QUIC_HANDSHAKE(s))
|
||||
j = 1;
|
||||
#endif
|
||||
if (j <= 0) {
|
||||
SSLfatal(s, SSL_AD_DECRYPT_ERROR, SSL_R_BAD_SIGNATURE);
|
||||
goto err;
|
||||
}
|
||||
if (j <= 0) {
|
||||
SSLfatal(s, SSL_AD_DECRYPT_ERROR, SSL_R_BAD_SIGNATURE);
|
||||
goto err;
|
||||
}
|
||||
|
||||
/*
|
||||
|
|
@ -1859,11 +1823,6 @@ static const version_info tls_version_table[] = {
|
|||
{ TLS1_VERSION, tlsv1_client_method, tlsv1_server_method },
|
||||
#else
|
||||
{ TLS1_VERSION, NULL, NULL },
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SSL3
|
||||
{ SSL3_VERSION, sslv3_client_method, sslv3_server_method },
|
||||
#else
|
||||
{ SSL3_VERSION, NULL, NULL },
|
||||
#endif
|
||||
{ 0, NULL, NULL },
|
||||
};
|
||||
|
|
@ -2086,7 +2045,7 @@ int ssl_set_version_bound(int method_version, int version, int *bound)
|
|||
return 1;
|
||||
}
|
||||
|
||||
valid_tls = version >= SSL3_VERSION && version <= TLS_MAX_VERSION_INTERNAL;
|
||||
valid_tls = version > SSL3_VERSION && version <= TLS_MAX_VERSION_INTERNAL;
|
||||
valid_dtls =
|
||||
/* We support client side pre-standardisation version of DTLS */
|
||||
(version == DTLS1_BAD_VER)
|
||||
|
|
|
|||
|
|
@ -211,30 +211,10 @@ int ossl_statem_server_read_transition(SSL_CONNECTION *s, int mt)
|
|||
* If we get a CKE message after a ServerDone then either
|
||||
* 1) We didn't request a Certificate
|
||||
* OR
|
||||
* 2) If we did request one then
|
||||
* a) We allow no Certificate to be returned
|
||||
* AND
|
||||
* b) We are running SSL3 (in TLS1.0+ the client must return a 0
|
||||
* list if we requested a certificate)
|
||||
* 2) We did request one and we allow no Certificate to be returned
|
||||
*/
|
||||
if (mt == SSL3_MT_CLIENT_KEY_EXCHANGE) {
|
||||
if (s->s3.tmp.cert_request) {
|
||||
if (s->version == SSL3_VERSION) {
|
||||
if ((s->verify_mode & SSL_VERIFY_PEER)
|
||||
&& (s->verify_mode & SSL_VERIFY_FAIL_IF_NO_PEER_CERT)) {
|
||||
/*
|
||||
* This isn't an unexpected message as such - we're just
|
||||
* not going to accept it because we require a client
|
||||
* cert.
|
||||
*/
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_R_PEER_DID_NOT_RETURN_A_CERTIFICATE);
|
||||
return 0;
|
||||
}
|
||||
st->hand_state = TLS_ST_SR_KEY_EXCH;
|
||||
return 1;
|
||||
}
|
||||
} else {
|
||||
if (!s->s3.tmp.cert_request) {
|
||||
st->hand_state = TLS_ST_SR_KEY_EXCH;
|
||||
return 1;
|
||||
}
|
||||
|
|
@ -2685,7 +2665,7 @@ CON_FUNC_RETURN tls_construct_server_hello(SSL_CONNECTION *s, WPACKET *pkt)
|
|||
|
||||
CON_FUNC_RETURN tls_construct_server_done(SSL_CONNECTION *s, WPACKET *pkt)
|
||||
{
|
||||
if (!s->s3.tmp.cert_request) {
|
||||
if (s->s3.tmp.cert_request == 0) {
|
||||
if (!ssl3_digest_cached_records(s, 0)) {
|
||||
/* SSLfatal() already called */
|
||||
return CON_FUNC_ERROR;
|
||||
|
|
@ -3154,8 +3134,8 @@ static int tls_process_cke_rsa(SSL_CONNECTION *s, PACKET *pkt)
|
|||
return 0;
|
||||
}
|
||||
|
||||
/* SSLv3 and pre-standard DTLS omit the length bytes. */
|
||||
if (s->version == SSL3_VERSION || s->version == DTLS1_BAD_VER) {
|
||||
/* pre-standard DTLS omits the length bytes. */
|
||||
if (s->version == DTLS1_BAD_VER) {
|
||||
enc_premaster = *pkt;
|
||||
} else {
|
||||
if (!PACKET_get_length_prefixed_2(pkt, &enc_premaster)
|
||||
|
|
@ -3887,14 +3867,8 @@ MSG_PROCESS_RETURN tls_process_client_certificate(SSL_CONNECTION *s,
|
|||
}
|
||||
|
||||
if (sk_X509_num(sk) <= 0) {
|
||||
/* TLS does not mind 0 certs returned */
|
||||
if (s->version == SSL3_VERSION) {
|
||||
SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE,
|
||||
SSL_R_NO_CERTIFICATES_RETURNED);
|
||||
goto err;
|
||||
}
|
||||
/* Fail for TLS only if we required a certificate */
|
||||
else if ((s->verify_mode & SSL_VERIFY_PEER) && (s->verify_mode & SSL_VERIFY_FAIL_IF_NO_PEER_CERT)) {
|
||||
/* Fail only if we required a certificate */
|
||||
if ((s->verify_mode & SSL_VERIFY_PEER) && (s->verify_mode & SSL_VERIFY_FAIL_IF_NO_PEER_CERT)) {
|
||||
SSLfatal(s, SSL_AD_CERTIFICATE_REQUIRED,
|
||||
SSL_R_PEER_DID_NOT_RETURN_A_CERTIFICATE);
|
||||
goto err;
|
||||
|
|
|
|||
|
|
@ -4779,7 +4779,7 @@ int SSL_CTX_set_tlsext_max_fragment_length(SSL_CTX *ctx, uint8_t mode)
|
|||
{
|
||||
if (mode != TLSEXT_max_fragment_length_DISABLED
|
||||
&& !IS_MAX_FRAGMENT_LENGTH_EXT_VALID(mode)) {
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
@ -4797,7 +4797,7 @@ int SSL_set_tlsext_max_fragment_length(SSL *ssl, uint8_t mode)
|
|||
|
||||
if (mode != TLSEXT_max_fragment_length_DISABLED
|
||||
&& !IS_MAX_FRAGMENT_LENGTH_EXT_VALID(mode)) {
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
ERR_raise(ERR_LIB_SSL, SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH);
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -63,7 +63,6 @@ static int do_ssl_trace_list(BIO *bio, int indent,
|
|||
/* Version number */
|
||||
|
||||
static const ssl_trace_tbl ssl_version_tbl[] = {
|
||||
{ SSL3_VERSION, "SSL 3.0" },
|
||||
{ TLS1_VERSION, "TLS 1.0" },
|
||||
{ TLS1_1_VERSION, "TLS 1.1" },
|
||||
{ TLS1_2_VERSION, "TLS 1.2" },
|
||||
|
|
@ -1184,14 +1183,9 @@ static int ssl_print_client_keyex(BIO *bio, int indent, const SSL_CONNECTION *sc
|
|||
|
||||
case SSL_kRSA:
|
||||
case SSL_kRSAPSK:
|
||||
if (TLS1_get_version(SSL_CONNECTION_GET_SSL(sc)) == SSL3_VERSION) {
|
||||
ssl_print_hex(bio, indent + 2,
|
||||
"EncryptedPreMasterSecret", msg, msglen);
|
||||
} else {
|
||||
if (!ssl_print_hexbuf(bio, indent + 2,
|
||||
"EncryptedPreMasterSecret", 2, &msg, &msglen))
|
||||
return 0;
|
||||
}
|
||||
if (!ssl_print_hexbuf(bio, indent + 2,
|
||||
"EncryptedPreMasterSecret", 2, &msg, &msglen))
|
||||
return 0;
|
||||
break;
|
||||
|
||||
case SSL_kDHE:
|
||||
|
|
|
|||
|
|
@ -74,7 +74,7 @@ handshake.
|
|||
another alert.)
|
||||
|
||||
* ExpectedProtocol - expected negotiated protocol. One of
|
||||
SSLv3, TLSv1, TLSv1.1, TLSv1.2.
|
||||
TLSv1, TLSv1.1, TLSv1.2.
|
||||
|
||||
* SessionTicketExpected - whether or not a session ticket is expected
|
||||
- Ignore - do not check for a session ticket (default)
|
||||
|
|
@ -272,8 +272,8 @@ In the above examples, `default` is the provider to use.
|
|||
|
||||
Note that the test expectations sometimes depend on the Configure settings. For
|
||||
example, the negotiated protocol depends on the set of available (enabled)
|
||||
protocols: a build with `enable-ssl3` has different test expectations than a
|
||||
build with `no-ssl3`.
|
||||
protocols: a build with `enable-tls1_3` has different test expectations than a
|
||||
build with `no-tls1_3`.
|
||||
|
||||
The Perl test harness automatically generates expected outputs, so users who
|
||||
just run `make test` do not need any extra steps.
|
||||
|
|
|
|||
|
|
@ -155,7 +155,6 @@ static const test_enum ssl_protocols[] = {
|
|||
{ "TLSv1.2", TLS1_2_VERSION },
|
||||
{ "TLSv1.1", TLS1_1_VERSION },
|
||||
{ "TLSv1", TLS1_VERSION },
|
||||
{ "SSLv3", SSL3_VERSION },
|
||||
{ "DTLSv1", DTLS1_VERSION },
|
||||
{ "DTLSv1.2", DTLS1_2_VERSION },
|
||||
};
|
||||
|
|
|
|||
|
|
@ -13,7 +13,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/;
|
|||
setup("test_asyncio");
|
||||
|
||||
plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build"
|
||||
if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls"));
|
||||
if alldisabled(available_protocols("tls"));
|
||||
|
||||
plan tests => 1;
|
||||
|
||||
|
|
|
|||
|
|
@ -13,7 +13,7 @@ use OpenSSL::Test::Utils;
|
|||
setup("test_clienthello");
|
||||
|
||||
plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build"
|
||||
if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls"));
|
||||
if alldisabled(available_protocols("tls"));
|
||||
|
||||
#No EC with TLSv1.3 confuses the padding calculations in this test
|
||||
plan skip_all => "No EC with TLSv1.3 is not supported by this test"
|
||||
|
|
|
|||
|
|
@ -13,7 +13,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/;
|
|||
setup("test_recordlen");
|
||||
|
||||
plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build"
|
||||
if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls"));
|
||||
if alldisabled(available_protocols("tls"));
|
||||
|
||||
plan tests => 1;
|
||||
|
||||
|
|
|
|||
|
|
@ -28,7 +28,7 @@ plan skip_all => "$test_name needs the sock feature enabled"
|
|||
if disabled("sock");
|
||||
|
||||
plan skip_all => "$test_name needs TLS <= 1.2 enabled"
|
||||
if alldisabled(("ssl3", "tls1", "tls1_1", "tls1_2"));
|
||||
if alldisabled(("tls1", "tls1_1", "tls1_2"));
|
||||
|
||||
plan tests => 9;
|
||||
|
||||
|
|
|
|||
|
|
@ -17,7 +17,7 @@ use OpenSSL::Test::Utils qw(alldisabled available_protocols);
|
|||
setup("test_servername");
|
||||
|
||||
plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build"
|
||||
if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls"));
|
||||
if alldisabled(available_protocols("tls"));
|
||||
|
||||
plan tests => 1;
|
||||
|
||||
|
|
|
|||
|
|
@ -27,8 +27,8 @@ plan skip_all => "$test_name needs the module feature enabled"
|
|||
plan skip_all => "$test_name needs the sock feature enabled"
|
||||
if disabled("sock");
|
||||
|
||||
plan skip_all => "$test_name needs SSLv3, TLSv1, TLSv1.1 or TLSv1.2 enabled"
|
||||
if alldisabled(("ssl3", "tls1", "tls1_1", "tls1_2"));
|
||||
plan skip_all => "$test_name needs TLSv1, TLSv1.1 or TLSv1.2 enabled"
|
||||
if alldisabled(("tls1", "tls1_1", "tls1_2"));
|
||||
|
||||
sub checkmessages($$$$$$);
|
||||
sub clearclient();
|
||||
|
|
|
|||
|
|
@ -87,7 +87,7 @@ SKIP: {
|
|||
|
||||
SKIP: {
|
||||
skip "TLS <= 1.2 disabled", 2
|
||||
if alldisabled(("ssl3", "tls1", "tls1_1", "tls1_2"));
|
||||
if alldisabled(("tls1", "tls1_1", "tls1_2"));
|
||||
|
||||
#Test 3: Corrupting a CertVerify signature in <=TLSv1.2 should fail
|
||||
$proxy->clear();
|
||||
|
|
|
|||
|
|
@ -93,10 +93,10 @@ SKIP: {
|
|||
"Version tolerance test, max version but not TLS 1.3");
|
||||
}
|
||||
|
||||
#Test 3: Testing something below SSLv3 should fail. We must disable TLS 1.3
|
||||
#Test 3: Testing something below TLS1.0 should fail. We must disable TLS 1.3
|
||||
#to avoid having the 'supported_versions' extension kick in and override our
|
||||
#desires.
|
||||
$client_version = TLSProxy::Record::VERS_SSL_3_0 - 1;
|
||||
$client_version = TLSProxy::Record::VERS_TLS_1_0 - 1;
|
||||
$proxy->clear();
|
||||
$proxy->clientflags("-no_tls1_3");
|
||||
$proxy->start();
|
||||
|
|
@ -104,7 +104,7 @@ my $record = pop @{$proxy->record_list};
|
|||
ok((note("Record version received: ".
|
||||
(defined $record ? $record->version() : "none")),
|
||||
TLSProxy::Message->fail()),
|
||||
"Version tolerance test, SSL < 3.0");
|
||||
"Version tolerance test, TLS < 1.0");
|
||||
|
||||
sub vers_tolerance_filter
|
||||
{
|
||||
|
|
@ -119,7 +119,7 @@ sub vers_tolerance_filter
|
|||
if ($message->mt == TLSProxy::Message::MT_CLIENT_HELLO) {
|
||||
#Set the client version
|
||||
#Anything above the max supported version should succeed
|
||||
#Anything below SSLv3 should fail
|
||||
#Anything below TLS1.0 should fail
|
||||
$message->client_version($client_version);
|
||||
$message->repack();
|
||||
}
|
||||
|
|
|
|||
|
|
@ -50,13 +50,13 @@ map { s/\^// } @conf_files if $^O eq "VMS";
|
|||
|
||||
# Some test results depend on the configuration of enabled protocols. We only
|
||||
# verify generated sources in the default configuration.
|
||||
my $is_default_tls = (disabled("ssl3") && !disabled("tls1") &&
|
||||
!disabled("tls1_1") && !disabled("tls1_2") &&
|
||||
!disabled("tls1_3") && (!disabled("ec") || !disabled("dh")));
|
||||
my $is_default_tls = (!disabled("tls1") && !disabled("tls1_1") &&
|
||||
!disabled("tls1_2") && !disabled("tls1_3") &&
|
||||
(!disabled("ec") || !disabled("dh")));
|
||||
|
||||
my $is_default_dtls = (!disabled("dtls1") && !disabled("dtls1_2"));
|
||||
|
||||
my @all_pre_tls1_3 = ("ssl3", "tls1", "tls1_1", "tls1_2");
|
||||
my @all_pre_tls1_3 = ("tls1", "tls1_1", "tls1_2");
|
||||
my $no_tls = alldisabled(available_protocols("tls"));
|
||||
my $no_tls_below1_3 = $no_tls || (disabled("tls1_2") && !disabled("tls1_3"));
|
||||
if (!$no_tls && $no_tls_below1_3 && disabled("ec") && disabled("dh")) {
|
||||
|
|
|
|||
|
|
@ -25,10 +25,10 @@ use lib bldtop_dir('.');
|
|||
|
||||
my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0);
|
||||
my ($no_rsa, $no_dsa, $no_dh, $no_ec, $no_psk,
|
||||
$no_ssl3, $no_tls1, $no_tls1_1, $no_tls1_2, $no_tls1_3,
|
||||
$no_tls1, $no_tls1_1, $no_tls1_2, $no_tls1_3,
|
||||
$no_dtls, $no_dtls1, $no_dtls1_2, $no_ct) =
|
||||
anydisabled qw/rsa dsa dh ec psk
|
||||
ssl3 tls1 tls1_1 tls1_2 tls1_3
|
||||
tls1 tls1_1 tls1_2 tls1_3
|
||||
dtls dtls1 dtls1_2 ct/;
|
||||
#If ec and dh are disabled then don't use TLSv1.3
|
||||
$no_tls1_3 = 1 if (!$no_tls1_3 && $no_ec && $no_dh);
|
||||
|
|
@ -416,42 +416,25 @@ sub testssl {
|
|||
|
||||
subtest 'standard SSL tests' => sub {
|
||||
######################################################################
|
||||
plan tests => 19;
|
||||
plan tests => 15;
|
||||
|
||||
SKIP: {
|
||||
skip "SSLv3 is not supported by this OpenSSL build", 4
|
||||
if disabled("ssl3");
|
||||
|
||||
skip "SSLv3 is not supported by the FIPS provider", 4
|
||||
if $provider eq "fips";
|
||||
|
||||
ok(run(test([@ssltest, "-bio_pair", "-ssl3"])),
|
||||
'test sslv3 via BIO pair');
|
||||
ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-server_auth", @CA])),
|
||||
'test sslv3 with server authentication via BIO pair');
|
||||
ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-client_auth", @CA])),
|
||||
'test sslv3 with client authentication via BIO pair');
|
||||
ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-server_auth", "-client_auth", @CA])),
|
||||
'test sslv3 with both server and client authentication via BIO pair');
|
||||
}
|
||||
|
||||
SKIP: {
|
||||
skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", 1
|
||||
skip "No TLS versions are supported by this OpenSSL build", 1
|
||||
if $no_anytls;
|
||||
|
||||
ok(run(test([@ssltest, "-bio_pair"])),
|
||||
'test sslv2/sslv3 via BIO pair');
|
||||
'test via BIO pair');
|
||||
}
|
||||
|
||||
SKIP: {
|
||||
skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", 14
|
||||
skip "No TLS versions are supported by this OpenSSL build", 14
|
||||
if $no_anytls;
|
||||
|
||||
SKIP: {
|
||||
skip "skipping test of sslv2/sslv3 w/o (EC)DHE test", 1 if $dsa_cert;
|
||||
skip "skipping test w/o (EC)DHE test", 1 if $dsa_cert;
|
||||
|
||||
ok(run(test([@ssltest, "-bio_pair", "-no_dhe", "-no_ecdhe"])),
|
||||
'test sslv2/sslv3 w/o (EC)DHE via BIO pair');
|
||||
'test w/o (EC)DHE via BIO pair');
|
||||
}
|
||||
|
||||
SKIP: {
|
||||
|
|
@ -459,17 +442,17 @@ sub testssl {
|
|||
if ($no_dh);
|
||||
|
||||
ok(run(test([@ssltest, "-bio_pair", "-dhe1024dsa", "-v"])),
|
||||
'test sslv2/sslv3 with 1024bit DHE via BIO pair');
|
||||
'test with 1024bit DHE via BIO pair');
|
||||
}
|
||||
|
||||
ok(run(test([@ssltest, "-bio_pair", "-server_auth", @CA])),
|
||||
'test sslv2/sslv3 with server authentication');
|
||||
'test with server authentication');
|
||||
ok(run(test([@ssltest, "-bio_pair", "-client_auth", @CA])),
|
||||
'test sslv2/sslv3 with client authentication via BIO pair');
|
||||
'test with client authentication via BIO pair');
|
||||
ok(run(test([@ssltest, "-bio_pair", "-server_auth", "-client_auth", @CA])),
|
||||
'test sslv2/sslv3 with both client and server authentication via BIO pair');
|
||||
'test with both client and server authentication via BIO pair');
|
||||
ok(run(test([@ssltest, "-bio_pair", "-server_auth", "-client_auth", "-app_verify", @CA])),
|
||||
'test sslv2/sslv3 with both client and server authentication via BIO pair and app verify');
|
||||
'test with both client and server authentication via BIO pair and app verify');
|
||||
|
||||
SKIP: {
|
||||
skip "No IPv4 available on this machine", 4
|
||||
|
|
@ -517,7 +500,6 @@ sub testssl {
|
|||
push @protocols, "-tls1_3" unless $no_tls1_3;
|
||||
push @protocols, "-tls1_2" unless $no_tls1_2;
|
||||
push @protocols, "-tls1" unless $no_tls1 || $provider eq "fips";
|
||||
push @protocols, "-ssl3" unless $no_ssl3 || $provider eq "fips";
|
||||
my $protocolciphersuitecount = 0;
|
||||
my %ciphersuites = ();
|
||||
my %ciphersstatus = ();
|
||||
|
|
@ -566,9 +548,6 @@ sub testssl {
|
|||
# DSA is not allowed in FIPS 140-3
|
||||
note "*****SKIPPING $protocol $cipher";
|
||||
ok(1);
|
||||
} elsif ($protocol eq "-ssl3" && $cipher =~ /ECDH/ ) {
|
||||
note "*****SKIPPING $protocol $cipher";
|
||||
ok(1);
|
||||
} else {
|
||||
if ($protocol eq "-tls1_3") {
|
||||
$ciphersuites = $cipher;
|
||||
|
|
@ -601,18 +580,7 @@ sub testssl {
|
|||
|
||||
subtest 'SSL security level failure tests' => sub {
|
||||
######################################################################
|
||||
plan tests => 3;
|
||||
|
||||
SKIP: {
|
||||
skip "SSLv3 is not supported by this OpenSSL build", 1
|
||||
if disabled("ssl3");
|
||||
|
||||
skip "SSLv3 is not supported by the FIPS provider", 1
|
||||
if $provider eq "fips";
|
||||
|
||||
is(run(test([@ssltest, "-bio_pair", "-ssl3", "-cipher", '@SECLEVEL=1'])),
|
||||
0, "test sslv3 fails at security level 1, expecting failure");
|
||||
}
|
||||
plan tests => 2;
|
||||
|
||||
SKIP: {
|
||||
skip "TLSv1.0 is not supported by this OpenSSL build", 1
|
||||
|
|
|
|||
|
|
@ -13,7 +13,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/;
|
|||
setup("test_fatalerr");
|
||||
|
||||
plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build"
|
||||
if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls"));
|
||||
if alldisabled(available_protocols("tls"));
|
||||
|
||||
plan tests => 1;
|
||||
|
||||
|
|
|
|||
|
|
@ -32,7 +32,7 @@ my $fipsmodcfgtmp = result_file($fipsmodcfgtmp_filename);
|
|||
my $provconfnew = result_file("fips-and-base-temp.cnf");
|
||||
|
||||
plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build"
|
||||
if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls"));
|
||||
if alldisabled(available_protocols("tls"));
|
||||
|
||||
plan tests => 4;
|
||||
|
||||
|
|
|
|||
File diff suppressed because it is too large
Load diff
|
|
@ -21,8 +21,8 @@ if ($fips_mode) {
|
|||
@protocols = (undef, "TLSv1.2", "DTLSv1.2");
|
||||
push @is_disabled, anydisabled("tls1_2", "dtls1_2");
|
||||
} else {
|
||||
@protocols = (undef, "SSLv3", "TLSv1", "TLSv1.1", "TLSv1.2", "DTLSv1", "DTLSv1.2");
|
||||
push @is_disabled, anydisabled("ssl3", "tls1", "tls1_1", "tls1_2", "dtls1", "dtls1_2");
|
||||
@protocols = (undef, "TLSv1", "TLSv1.1", "TLSv1.2", "DTLSv1", "DTLSv1.2");
|
||||
push @is_disabled, anydisabled("tls1", "tls1_1", "tls1_2", "dtls1", "dtls1_2");
|
||||
}
|
||||
|
||||
our @tests = ();
|
||||
|
|
@ -47,11 +47,7 @@ sub generate_tests() {
|
|||
my $method;
|
||||
my $sctpenabled = 0;
|
||||
if (!$is_disabled[$_]) {
|
||||
if ($protocol_name eq "SSLv3") {
|
||||
$caalert = "BadCertificate";
|
||||
} else {
|
||||
$caalert = "UnknownCA";
|
||||
}
|
||||
$caalert = "UnknownCA";
|
||||
if ($protocol_name =~ m/^DTLS/) {
|
||||
$method = "DTLS";
|
||||
$sctpenabled = 1 if !disabled("sctp");
|
||||
|
|
|
|||
|
|
@ -20,15 +20,15 @@ use OpenSSL::Test;
|
|||
use OpenSSL::Test::Utils qw/anydisabled alldisabled disabled/;
|
||||
setup("no_test_here");
|
||||
|
||||
my @tls_protocols = ("SSLv3", "TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3");
|
||||
my @tls_protocols = ("TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3");
|
||||
my @tls_protocols_fips = ("TLSv1.2", "TLSv1.3");
|
||||
# undef stands for "no limit".
|
||||
my @min_tls_protocols = (undef, "SSLv3", "TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3");
|
||||
my @min_tls_protocols = (undef, "TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3");
|
||||
my @min_tls_protocols_fips = (undef, "TLSv1.2", "TLSv1.3");
|
||||
my @max_tls_protocols = ("SSLv3", "TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3", undef);
|
||||
my @max_tls_protocols = ("TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3", undef);
|
||||
my @max_tls_protocols_fips = ("TLSv1.2", "TLSv1.3", undef);
|
||||
|
||||
my @is_tls_disabled = anydisabled("ssl3", "tls1", "tls1_1", "tls1_2", "tls1_3");
|
||||
my @is_tls_disabled = anydisabled("tls1", "tls1_1", "tls1_2", "tls1_3");
|
||||
my @is_tls_disabled_fips = anydisabled("tls1_2", "tls1_3");
|
||||
|
||||
my $min_tls_enabled; my $max_tls_enabled;
|
||||
|
|
@ -107,7 +107,7 @@ sub no_tests {
|
|||
return disabled("dtls1_2");
|
||||
}
|
||||
return $dtls ? alldisabled("dtls1", "dtls1_2") :
|
||||
alldisabled("ssl3", "tls1", "tls1_1", "tls1_2", "tls1_3");
|
||||
alldisabled("tls1", "tls1_1", "tls1_2", "tls1_3");
|
||||
}
|
||||
|
||||
sub generate_version_tests {
|
||||
|
|
|
|||
|
|
@ -33,13 +33,12 @@ typedef struct {
|
|||
static const version_test version_testdata[] = {
|
||||
/* proto min max ok expected min expected max */
|
||||
{ PROTO_TLS, 0, 0, 1, 1, 0, 0 },
|
||||
{ PROTO_TLS, SSL3_VERSION, TLS1_3_VERSION, 1, 1, SSL3_VERSION, TLS1_3_VERSION },
|
||||
{ PROTO_TLS, TLS1_VERSION, TLS1_3_VERSION, 1, 1, TLS1_VERSION, TLS1_3_VERSION },
|
||||
{ PROTO_TLS, TLS1_VERSION, TLS1_2_VERSION, 1, 1, TLS1_VERSION, TLS1_2_VERSION },
|
||||
{ PROTO_TLS, TLS1_2_VERSION, TLS1_2_VERSION, 1, 1, TLS1_2_VERSION, TLS1_2_VERSION },
|
||||
{ PROTO_TLS, TLS1_2_VERSION, TLS1_1_VERSION, 1, 1, TLS1_2_VERSION, TLS1_1_VERSION },
|
||||
{ PROTO_TLS, SSL3_VERSION - 1, TLS1_3_VERSION, 0, 1, 0, TLS1_3_VERSION },
|
||||
{ PROTO_TLS, SSL3_VERSION, TLS1_3_VERSION + 1, 1, 0, SSL3_VERSION, 0 },
|
||||
{ PROTO_TLS, SSL3_VERSION, TLS1_3_VERSION, 0, 1, 0, TLS1_3_VERSION },
|
||||
{ PROTO_TLS, TLS1_VERSION, TLS1_3_VERSION + 1, 1, 0, TLS1_VERSION, 0 },
|
||||
#ifndef OPENSSL_NO_DTLS
|
||||
{ PROTO_TLS, DTLS1_VERSION, DTLS1_2_VERSION, 1, 1, 0, 0 },
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -655,9 +655,6 @@ static void sv_usage(void)
|
|||
#ifndef OPENSSL_NO_PSK
|
||||
fprintf(stderr, " -psk arg - PSK in hex (without 0x)\n");
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SSL3
|
||||
fprintf(stderr, " -ssl3 - use SSLv3\n");
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1
|
||||
fprintf(stderr, " -tls1 - use TLSv1\n");
|
||||
#endif
|
||||
|
|
@ -814,7 +811,6 @@ static int protocol_from_string(const char *value)
|
|||
int version;
|
||||
};
|
||||
static const struct protocol_versions versions[] = {
|
||||
{ "ssl3", SSL3_VERSION },
|
||||
{ "tls1", TLS1_VERSION },
|
||||
{ "tls1.1", TLS1_1_VERSION },
|
||||
{ "tls1.2", TLS1_2_VERSION },
|
||||
|
|
@ -898,7 +894,7 @@ int main(int argc, char *argv[])
|
|||
BIO_IPV6 } bio_type
|
||||
= BIO_MEM;
|
||||
int force = 0;
|
||||
int dtls1 = 0, dtls12 = 0, dtls = 0, tls1 = 0, tls1_1 = 0, tls1_2 = 0, ssl3 = 0;
|
||||
int dtls1 = 0, dtls12 = 0, dtls = 0, tls1 = 0, tls1_1 = 0, tls1_2 = 0;
|
||||
int ret = EXIT_FAILURE;
|
||||
int client_auth = 0;
|
||||
int server_auth = 0, i;
|
||||
|
|
@ -1028,8 +1024,6 @@ int main(int argc, char *argv[])
|
|||
tls1_1 = 1;
|
||||
} else if (strcmp(*argv, "-tls1") == 0) {
|
||||
tls1 = 1;
|
||||
} else if (strcmp(*argv, "-ssl3") == 0) {
|
||||
ssl3 = 1;
|
||||
} else if (strcmp(*argv, "-dtls1") == 0) {
|
||||
dtls1 = 1;
|
||||
} else if (strcmp(*argv, "-dtls12") == 0) {
|
||||
|
|
@ -1246,19 +1240,14 @@ int main(int argc, char *argv[])
|
|||
goto end;
|
||||
}
|
||||
|
||||
if (ssl3 + tls1 + tls1_1 + tls1_2 + dtls + dtls1 + dtls12 > 1) {
|
||||
fprintf(stderr, "At most one of -ssl3, -tls1, -tls1_1, -tls1_2, -dtls, -dtls1 or -dtls12 should "
|
||||
if (tls1 + tls1_1 + tls1_2 + dtls + dtls1 + dtls12 > 1) {
|
||||
fprintf(stderr, "At most one of -tls1, -tls1_1, -tls1_2, -dtls, -dtls1 or -dtls12 should "
|
||||
"be requested.\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
#ifdef OPENSSL_NO_SSL3
|
||||
if (ssl3)
|
||||
no_protocol = 1;
|
||||
else
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1
|
||||
if (tls1)
|
||||
if (tls1)
|
||||
no_protocol = 1;
|
||||
else
|
||||
#endif
|
||||
|
|
@ -1296,11 +1285,11 @@ int main(int argc, char *argv[])
|
|||
goto end;
|
||||
}
|
||||
|
||||
if (!ssl3 && !tls1 && !tls1_1 && !tls1_2 && !dtls && !dtls1 && !dtls12 && number > 1
|
||||
if (!tls1 && !tls1_1 && !tls1_2 && !dtls && !dtls1 && !dtls12 && number > 1
|
||||
&& !reuse && !force) {
|
||||
fprintf(stderr, "This case cannot work. Use -f to perform "
|
||||
"the test anyway (and\n-d to see what happens), "
|
||||
"or add one of -ssl3, -tls1, -tls1_1, -tls1_2, -dtls, -dtls1, -dtls12, -reuse\n"
|
||||
"or add one of -tls1, -tls1_1, -tls1_2, -dtls, -dtls1, -dtls12, -reuse\n"
|
||||
"to avoid protocol mismatch.\n");
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -1344,10 +1333,7 @@ int main(int argc, char *argv[])
|
|||
|
||||
#ifndef OPENSSL_NO_TLS
|
||||
meth = TLS_method();
|
||||
if (ssl3) {
|
||||
min_version = SSL3_VERSION;
|
||||
max_version = SSL3_VERSION;
|
||||
} else if (tls1) {
|
||||
if (tls1) {
|
||||
min_version = TLS1_VERSION;
|
||||
max_version = TLS1_VERSION;
|
||||
} else if (tls1_1) {
|
||||
|
|
|
|||
|
|
@ -1606,12 +1606,7 @@ static int test_large_app_data(int tst)
|
|||
#endif
|
||||
|
||||
case 4:
|
||||
#ifndef OPENSSL_NO_SSL3
|
||||
prot = SSL3_VERSION;
|
||||
break;
|
||||
#else
|
||||
return TEST_skip("SSL 3 not supported");
|
||||
#endif
|
||||
|
||||
case 5:
|
||||
#ifndef OPENSSL_NO_DTLS1_2
|
||||
|
|
@ -12050,9 +12045,6 @@ static int check_version_string(SSL *s, int version)
|
|||
const char *verstr = NULL;
|
||||
|
||||
switch (version) {
|
||||
case SSL3_VERSION:
|
||||
verstr = "SSLv3";
|
||||
break;
|
||||
case TLS1_VERSION:
|
||||
verstr = "TLSv1";
|
||||
break;
|
||||
|
|
@ -12090,11 +12082,6 @@ static int test_version(int idx)
|
|||
const SSL_METHOD *clientmeth = TLS_client_method();
|
||||
|
||||
switch (idx) {
|
||||
#if !defined(OPENSSL_NO_SSL3)
|
||||
case 0:
|
||||
version = SSL3_VERSION;
|
||||
break;
|
||||
#endif
|
||||
#if !defined(OPENSSL_NO_TLS1)
|
||||
case 1:
|
||||
version = TLS1_VERSION;
|
||||
|
|
@ -12131,8 +12118,7 @@ static int test_version(int idx)
|
|||
}
|
||||
|
||||
if (is_fips
|
||||
&& (version == SSL3_VERSION
|
||||
|| version == TLS1_VERSION
|
||||
&& (version == TLS1_VERSION
|
||||
|| version == DTLS1_VERSION)) {
|
||||
TEST_skip("Protocol version not supported with FIPS");
|
||||
return 1;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue