]> git.ipfire.org Git - thirdparty/openssl.git/blame - ssl/ssl_txt.c
Update SSL_SESSION_print for TLSv1.3
[thirdparty/openssl.git] / ssl / ssl_txt.c
CommitLineData
846e33c7 1/*
83cf7abf 2 * Copyright 1995-2018 The OpenSSL Project Authors. All Rights Reserved.
c80149d9 3 * Copyright 2005 Nokia. All rights reserved.
d02b48c6 4 *
846e33c7
RS
5 * Licensed under the OpenSSL license (the "License"). You may not use
6 * this file except in compliance with the License. You can obtain a copy
7 * in the file LICENSE in the source distribution or at
8 * https://www.openssl.org/source/license.html
d02b48c6 9 */
846e33c7 10
d02b48c6 11#include <stdio.h>
ec577822 12#include <openssl/buffer.h>
d02b48c6
RE
13#include "ssl_locl.h"
14
4b618848 15#ifndef OPENSSL_NO_STDIO
0821bcd4 16int SSL_SESSION_print_fp(FILE *fp, const SSL_SESSION *x)
0f113f3e
MC
17{
18 BIO *b;
19 int ret;
d02b48c6 20
9982cbbb 21 if ((b = BIO_new(BIO_s_file())) == NULL) {
0f113f3e 22 SSLerr(SSL_F_SSL_SESSION_PRINT_FP, ERR_R_BUF_LIB);
26a7d938 23 return 0;
0f113f3e
MC
24 }
25 BIO_set_fp(b, fp, BIO_NOCLOSE);
26 ret = SSL_SESSION_print(b, x);
27 BIO_free(b);
26a7d938 28 return ret;
0f113f3e 29}
d02b48c6
RE
30#endif
31
0821bcd4 32int SSL_SESSION_print(BIO *bp, const SSL_SESSION *x)
0f113f3e 33{
ec60ccc1 34 size_t i;
0f113f3e 35 const char *s;
32f803d8 36 int istls13 = (x->ssl_version == TLS1_3_VERSION);
d02b48c6 37
0f113f3e
MC
38 if (x == NULL)
39 goto err;
40 if (BIO_puts(bp, "SSL-Session:\n") <= 0)
41 goto err;
3eb2aff4 42 s = ssl_protocol_to_string(x->ssl_version);
0f113f3e
MC
43 if (BIO_printf(bp, " Protocol : %s\n", s) <= 0)
44 goto err;
58964a49 45
0f113f3e
MC
46 if (x->cipher == NULL) {
47 if (((x->cipher_id) & 0xff000000) == 0x02000000) {
d61e6040
TK
48 if (BIO_printf(bp, " Cipher : %06lX\n",
49 x->cipher_id & 0xffffff) <= 0)
0f113f3e
MC
50 goto err;
51 } else {
d61e6040
TK
52 if (BIO_printf(bp, " Cipher : %04lX\n",
53 x->cipher_id & 0xffff) <= 0)
0f113f3e
MC
54 goto err;
55 }
56 } else {
d61e6040
TK
57 if (BIO_printf(bp, " Cipher : %s\n",
58 ((x->cipher->name == NULL) ? "unknown"
59 : x->cipher->name)) <= 0)
0f113f3e
MC
60 goto err;
61 }
62 if (BIO_puts(bp, " Session-ID: ") <= 0)
63 goto err;
64 for (i = 0; i < x->session_id_length; i++) {
65 if (BIO_printf(bp, "%02X", x->session_id[i]) <= 0)
66 goto err;
67 }
68 if (BIO_puts(bp, "\n Session-ID-ctx: ") <= 0)
69 goto err;
70 for (i = 0; i < x->sid_ctx_length; i++) {
71 if (BIO_printf(bp, "%02X", x->sid_ctx[i]) <= 0)
72 goto err;
73 }
32f803d8
MC
74 if (istls13) {
75 if (BIO_puts(bp, "\n Resumption PSK: ") <= 0)
76 goto err;
77 } else if (BIO_puts(bp, "\n Master-Key: ") <= 0)
0f113f3e 78 goto err;
ec60ccc1 79 for (i = 0; i < x->master_key_length; i++) {
0f113f3e
MC
80 if (BIO_printf(bp, "%02X", x->master_key[i]) <= 0)
81 goto err;
82 }
ddac1974 83#ifndef OPENSSL_NO_PSK
0f113f3e
MC
84 if (BIO_puts(bp, "\n PSK identity: ") <= 0)
85 goto err;
86 if (BIO_printf(bp, "%s", x->psk_identity ? x->psk_identity : "None") <= 0)
87 goto err;
88 if (BIO_puts(bp, "\n PSK identity hint: ") <= 0)
89 goto err;
90 if (BIO_printf
91 (bp, "%s", x->psk_identity_hint ? x->psk_identity_hint : "None") <= 0)
92 goto err;
ddac1974 93#endif
edc032b5 94#ifndef OPENSSL_NO_SRP
0f113f3e
MC
95 if (BIO_puts(bp, "\n SRP username: ") <= 0)
96 goto err;
97 if (BIO_printf(bp, "%s", x->srp_username ? x->srp_username : "None") <= 0)
98 goto err;
edc032b5 99#endif
aff8c126 100 if (x->ext.tick_lifetime_hint) {
0f113f3e
MC
101 if (BIO_printf(bp,
102 "\n TLS session ticket lifetime hint: %ld (seconds)",
aff8c126 103 x->ext.tick_lifetime_hint) <= 0)
0f113f3e
MC
104 goto err;
105 }
aff8c126 106 if (x->ext.tick) {
0f113f3e
MC
107 if (BIO_puts(bp, "\n TLS session ticket:\n") <= 0)
108 goto err;
348240c6 109 /* TODO(size_t): Convert this call */
a230b26e 110 if (BIO_dump_indent
aff8c126 111 (bp, (const char *)x->ext.tick, (int)x->ext.ticklen, 4)
0f113f3e
MC
112 <= 0)
113 goto err;
114 }
09b6c2ef 115#ifndef OPENSSL_NO_COMP
0f113f3e
MC
116 if (x->compress_meth != 0) {
117 SSL_COMP *comp = NULL;
413c4f45 118
61986d32 119 if (!ssl_cipher_get_evp(x, NULL, NULL, NULL, NULL, &comp, 0))
69f68237 120 goto err;
0f113f3e 121 if (comp == NULL) {
a230b26e 122 if (BIO_printf(bp, "\n Compression: %d", x->compress_meth) <= 0)
0f113f3e
MC
123 goto err;
124 } else {
9a555706 125 if (BIO_printf(bp, "\n Compression: %d (%s)", comp->id,
a230b26e 126 comp->name) <= 0)
0f113f3e
MC
127 goto err;
128 }
129 }
09b6c2ef 130#endif
0f113f3e
MC
131 if (x->time != 0L) {
132 if (BIO_printf(bp, "\n Start Time: %ld", x->time) <= 0)
133 goto err;
134 }
135 if (x->timeout != 0L) {
136 if (BIO_printf(bp, "\n Timeout : %ld (sec)", x->timeout) <= 0)
137 goto err;
138 }
139 if (BIO_puts(bp, "\n") <= 0)
140 goto err;
141
142 if (BIO_puts(bp, " Verify return code: ") <= 0)
143 goto err;
144 if (BIO_printf(bp, "%ld (%s)\n", x->verify_result,
145 X509_verify_cert_error_string(x->verify_result)) <= 0)
146 goto err;
25f923dd 147
ddc06b35
DSH
148 if (BIO_printf(bp, " Extended master secret: %s\n",
149 x->flags & SSL_SESS_FLAG_EXTMS ? "yes" : "no") <= 0)
150 goto err;
151
32f803d8
MC
152 if (istls13) {
153 if (BIO_printf(bp, " Max Early Data: %u\n",
154 x->ext.max_early_data) <= 0)
155 goto err;
156 }
157
208fb891 158 return 1;
0f113f3e 159 err:
26a7d938 160 return 0;
0f113f3e 161}
d02b48c6 162
0f113f3e
MC
163/*
164 * print session id and master key in NSS keylog format (RSA
165 * Session-ID:<session id> Master-Key:<master key>)
166 */
189ae368 167int SSL_SESSION_print_keylog(BIO *bp, const SSL_SESSION *x)
0f113f3e 168{
ec60ccc1 169 size_t i;
189ae368 170
0f113f3e
MC
171 if (x == NULL)
172 goto err;
173 if (x->session_id_length == 0 || x->master_key_length == 0)
174 goto err;
189ae368 175
0f113f3e
MC
176 /*
177 * the RSA prefix is required by the format's definition although there's
8483a003 178 * nothing RSA-specific in the output, therefore, we don't have to check if
0f113f3e
MC
179 * the cipher suite is based on RSA
180 */
181 if (BIO_puts(bp, "RSA ") <= 0)
182 goto err;
189ae368 183
0f113f3e
MC
184 if (BIO_puts(bp, "Session-ID:") <= 0)
185 goto err;
186 for (i = 0; i < x->session_id_length; i++) {
187 if (BIO_printf(bp, "%02X", x->session_id[i]) <= 0)
188 goto err;
189 }
190 if (BIO_puts(bp, " Master-Key:") <= 0)
191 goto err;
ec60ccc1 192 for (i = 0; i < x->master_key_length; i++) {
0f113f3e
MC
193 if (BIO_printf(bp, "%02X", x->master_key[i]) <= 0)
194 goto err;
195 }
196 if (BIO_puts(bp, "\n") <= 0)
197 goto err;
189ae368 198
208fb891 199 return 1;
0f113f3e 200 err:
26a7d938 201 return 0;
0f113f3e 202}