summaryrefslogtreecommitdiff
path: root/src/lib/libc/stdlib/random.c (unfollow)
Commit message (Collapse)AuthorFilesLines
2020-01-23When certificate validation fails, we must send a DECRYPT_ERROR alertbeck1-3/+6
according to RFC8446. ok jsing@
2020-01-23Remove the ssl_get_message function pointer from SSL_METHOD_INTERNAL.jsing6-47/+27
ssl_get_message is essentially a switch between ssl3_get_message and dtls1_get_message, both only used by the legacy stack. Instead, use SSL_IS_DTLS() in ssl3_get_message to call the DTLS function when necessary. ok beck@ inoguchi@ tb@
2020-01-23Implement sending client certificate requests for 1.3 serverbeck1-1/+13
ok jsing@
2020-01-23Correctly handle TLSv1.3 ciphers suites in ssl3_choose_cipher().jsing4-5/+30
Currently, TLSv1.3 cipher suites are filtered out by the fact that they have authentication and key exchange algorithms that are not being set in ssl_set_cert_masks(). Fix this so that ssl3_choose_cipher() works for TLSv1.3, however we also now need to ensure that we filter out TLSv1.3 for non-TLSv1.3 and only select TLSv1.3 for TLSv1.3. ok beck@ tb@
2020-01-23Build the encrypted extensions for the 1.3 serverbeck1-2/+8
ok jsing@
2020-01-23If we are building a legacy server hello, check to see if we arebeck1-1/+20
downgrading from TLS 1.3. If we are, set the last 8 bytes of the server_random value to the required values as per RFC 8446 section 4.1.3 indicating that we deliberately meant to downgrade. ok jsing@
2020-01-23Add checking int the client to check the magic values which arebeck3-3/+30
set by a 1.3 server when it downgrades to tls 1.2 or 1.1 as per RFC 8446 section 4.1.3 ok jsing@
2020-01-23Add code to build and send a server hello for tls 1.3beck1-3/+40
ok jsing@
2020-01-23Save the legacy session id in the client, and enforce that it is returnedbeck2-7/+18
the same from the server. ok jsing@ tb@
2020-01-23Implement pending for TLSv1.3.jsing4-6/+42
Makes `openssl s_client -peekaboo` work with TLSv1.3. ok beck@ tb@
2020-01-23The X509_LOOKUP code tries to grope around in /etc/ssl/cert/ to findtb1-30/+67
CA certs it couldn't find otherwise. This may lead to a pledge rpath violation reported by Kor, son of Rynar. Unfortunately, providing certs inside a directory is common in linuxes, so we need to keep this functionality for portable. Check if /etc/ssl/cert.pem and /etc/ssl/cert exist and pledge accordingly. Add unveils to restrict this program further on a default OpenBSD install. Fix -C to look only inside the provided root bundle. Input from jsing and sthen, tests by sthen and Kor ok beck, jsing, sthen (after much back and forth)
2020-01-23Remove lies from the SSL_pending man page, Our implementation neverbeck1-22/+3
advances the record layer, it only reports internal state. ok jsing@ tb@
2020-01-23Make -peekaboo mode also use SSL_pending after peeking, to ensurebeck1-2/+9
SSL_pending implementation is correct. annoying jsing@
2020-01-23Switch back to a function pointer for ssl_pending.jsing3-14/+24
This will allow the TLSv1.3 stack to provide its own implementation. Nuke a completely bogus comment from SSL_pending() whilst here. ok beck@
2020-01-23Add a TLS13_IO_ALERT return value so that we can explicitly signal whenjsing3-11/+22
we sent or received a fatal alert. Pull the fatal_alert check up into tls13_legacy_error(). Also, if sending an alert resulted in EOF, do not propagate this back since we do not want to signal EOF to the caller (rather we want to indicate failure). ok beck@ tb@
2020-01-23Pass a CBB to TLSv1.3 send handlers.jsing4-50/+44
This avoids the need for each send handler to call tls13_handshake_msg_start() and tls13_handshake_msg_finish(). ok beck@ tb@
2020-01-22The length of the IV of EVP_chacha20 is currently 64 bits, not 96.tb1-3/+3
ok beck
2020-01-22Wire up the TLSv1.3 server.jsing3-6/+182
This currently only has enough code to handle fallback to the legacy TLS stack for TLSv1.2 or earlier, however allows for further development and testing. ok beck@
2020-01-22Pass a handshake message content CBS to TLSv1.3 receive handlers.jsing5-85/+70
This avoids every receive handler from having to get the handshake message content itself. Additionally, pull the trailing data check up so that each receive handler does not have to implement it. This makes the code more readable and reduces duplication. ok beck@ tb@
2020-01-22Fix things so that `make -DTLS1_3` works again.jsing1-1/+3
2020-01-22Send alerts on certificate verification failures of server certsbeck1-2/+2
ok tb@
2020-01-22Rename failure into alert_desc in tlsext_ocsp_server_parse().tb1-5/+5
2020-01-22fix previous: alert_desc needs to be an int.tb1-2/+2
2020-01-22Avoid modifying alert in the success path.tb1-11/+17
ok beck jsing
2020-01-22Enable the TLSv1.3 client in libssl.jsing1-2/+3
This also makes it available to clients that use libtls, including ftp(1) and nc(1). Note that this does not expose additional defines via public headers, which means that any code conditioning on defines like TLS1_3_VERSION or SSL_OP_NO_TLSv1_3 will not enable or use TLSv1.3. This approach is necessary since too many pieces of software assume that if TLS1_3_VERSION is available, other OpenSSL 1.1 API will also be available, which is not necessarily the case. ok beck@ tb@
2020-01-22Correct includes check for libtls.jsing1-2/+2
2020-01-22Add checks to ensure that lib{crypto,ssl,tls} public headers have actuallyjsing3-3/+33
been installed prior to building. Requested by and ok tb@
2020-01-22delete wasteful ;;deraadt1-2/+2
ok tedu
2020-01-22Move guards from public to internal headers, and fix not use values.beck2-8/+7
reverts previous attempt which would have broken ports ok jsing@
2020-01-22Simplify header installation by combining the HDRS and HDRS_GEN loops.jsing1-9/+2
ok beck@
2020-01-22Note in the man page that the default protocols list includes 1.3beck1-4/+4
ok jsing@
2020-01-22Enable TLS version 1.3 in the default protocols for libtls.beck1-2/+2
This will as yet not do anything, until we turn it on in the lower level libraries. ok jsing@
2020-01-22Simplify the peekaboo code.jsing1-35/+6
ok beck@
2020-01-22Implement support for SSL_peek() in the TLSv1.3 record layer.jsing3-14/+39
ok beck@ tb@
2020-01-22After the ClientHello has been sent or received and before the peer'stb4-8/+22
Finished message has been received, a change cipher spec may be received and must be ignored. Add a flag to the record layer struct and set it at the appropriate moments during the handshake so that we will ignore it. ok jsing
2020-01-22Add -peekaboo option to s_client, to test SSL_peekbeck1-4/+66
peeks data before reading, compares to subsequent read. ok jsing@
2020-01-22Correctly set the legacy version when TLSv1.3 is building a client hello.jsing1-4/+11
The legacy version field is capped at TLSv1.2, however it may be lower than this if we are only choosing to use TLSv1.0 or TLSv1.1. ok beck@ tb@
2020-01-22Don't add an extra unknown error if we got a fatal alertbeck1-2/+3
ok jsing@
2020-01-22The legacy_record_version must be set to TLS1_2_VERSION excepttb4-9/+30
in the ClientHello where it may be set to TLS1_VERSION. Use the minimal supported version to decide whether we choose to do so or not. Use a sent hook to set it back TLS1_2_VERSION right after the ClientHello message is on the wire. ok beck jsing
2020-01-22Hook up the TLSv1.3 legacy shutdown code.jsing1-2/+2
Missed in an earlier commit.
2020-01-22Add minimal support for hello retry request for RFC conformance.beck4-11/+71
We currently don't support sending a modified clienthello ok jsing@ tb@
2020-01-22Split the TLSv1.3 guards into separate client and server guards.jsing3-6/+13
ok beck@ tb@
2020-01-22Implement close-notify and SSL_shutdown() handling for the TLSv1.3 client.jsing3-9/+76
ok beck@ inoguchi@ tb@
2020-01-21Correct legacy fallback for TLSv1.3 client.jsing3-9/+30
When falling back to the legacy TLS client, in the case where a server has sent a TLS record that contains more than one handshake message, we also need to stash the unprocessed record data for later processing. Otherwise we end up with missing handshake data. ok beck@ tb@
2020-01-21Remove redundant ASN1_INTEGER_set call in PKCS7_set_typeinoguchi1-2/+1
ok bcook@
2020-01-21Provide SSL_R_UNKNOWN.jsing3-5/+7
This allows us to indicate that the cause of the failure is unknown, rather than implying that it was an internal error when it was not. ok beck@
2020-01-21Clear and free the tls13_ctx that hangs off an SSL *s fromtb2-2/+8
SSL_{clear,free}(3). Make sure the handshake context is cleaned up completely: the hs_tls13 reacharound is taken care of by ssl3_{clear,free}(3). Add a missing tls13_handshake_msg_free() call to tls13_ctx_free(). ok beck jsing
2020-01-21Add alert processing in tls client code, by adding alert to thebeck3-19/+30
tls13 context, and emiting the alert at the upper layers when the lower level code fails ok jsing@, tb@
2020-01-20Add alerts to the tls 1.3 record layer and handshake layerbeck2-49/+29
ok jsing@, inoguchi@, tb@
2020-01-20Provide an error framework for use with the TLSv1.3 code.jsing5-7/+151
This is based on the libtls error handling code, but adds machine readable codes and subcodes. We then map these codes back to libssl error codes. ok beck@ inoguchi@