]>
Commit | Line | Data |
---|---|---|
58964a49 RE |
1 | /* ssl/tls1.h */ |
2 | /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) | |
3 | * All rights reserved. | |
4 | * | |
5 | * This package is an SSL implementation written | |
6 | * by Eric Young (eay@cryptsoft.com). | |
7 | * The implementation was written so as to conform with Netscapes SSL. | |
8 | * | |
9 | * This library is free for commercial and non-commercial use as long as | |
10 | * the following conditions are aheared to. The following conditions | |
11 | * apply to all code found in this distribution, be it the RC4, RSA, | |
12 | * lhash, DES, etc., code; not just the SSL code. The SSL documentation | |
13 | * included with this distribution is covered by the same copyright terms | |
14 | * except that the holder is Tim Hudson (tjh@cryptsoft.com). | |
15 | * | |
16 | * Copyright remains Eric Young's, and as such any Copyright notices in | |
17 | * the code are not to be removed. | |
18 | * If this package is used in a product, Eric Young should be given attribution | |
19 | * as the author of the parts of the library used. | |
20 | * This can be in the form of a textual message at program startup or | |
21 | * in documentation (online or textual) provided with the package. | |
22 | * | |
23 | * Redistribution and use in source and binary forms, with or without | |
24 | * modification, are permitted provided that the following conditions | |
25 | * are met: | |
26 | * 1. Redistributions of source code must retain the copyright | |
27 | * notice, this list of conditions and the following disclaimer. | |
28 | * 2. Redistributions in binary form must reproduce the above copyright | |
29 | * notice, this list of conditions and the following disclaimer in the | |
30 | * documentation and/or other materials provided with the distribution. | |
31 | * 3. All advertising materials mentioning features or use of this software | |
32 | * must display the following acknowledgement: | |
33 | * "This product includes cryptographic software written by | |
34 | * Eric Young (eay@cryptsoft.com)" | |
35 | * The word 'cryptographic' can be left out if the rouines from the library | |
36 | * being used are not cryptographic related :-). | |
37 | * 4. If you include any Windows specific code (or a derivative thereof) from | |
38 | * the apps directory (application code) you must include an acknowledgement: | |
39 | * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" | |
40 | * | |
41 | * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND | |
42 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | |
43 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE | |
44 | * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE | |
45 | * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL | |
46 | * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS | |
47 | * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) | |
48 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT | |
49 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY | |
50 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF | |
51 | * SUCH DAMAGE. | |
52 | * | |
53 | * The licence and distribution terms for any publically available version or | |
54 | * derivative of this code cannot be changed. i.e. this code cannot simply be | |
55 | * copied and put under another distribution licence | |
56 | * [including the GNU Public Licence.] | |
57 | */ | |
ea262260 BM |
58 | /* ==================================================================== |
59 | * Copyright 2002 Sun Microsystems, Inc. ALL RIGHTS RESERVED. | |
60 | * | |
61 | * Portions of the attached software ("Contribution") are developed by | |
62 | * SUN MICROSYSTEMS, INC., and are contributed to the OpenSSL project. | |
63 | * | |
64 | * The Contribution is licensed pursuant to the OpenSSL open source | |
65 | * license provided above. | |
66 | * | |
ea262260 BM |
67 | * ECC cipher suite support in OpenSSL originally written by |
68 | * Vipul Gupta and Sumit Gupta of Sun Microsystems Laboratories. | |
69 | * | |
70 | */ | |
58964a49 RE |
71 | |
72 | #ifndef HEADER_TLS1_H | |
73 | #define HEADER_TLS1_H | |
74 | ||
ec577822 | 75 | #include <openssl/buffer.h> |
58964a49 RE |
76 | |
77 | #ifdef __cplusplus | |
78 | extern "C" { | |
79 | #endif | |
80 | ||
0e73294e | 81 | #define TLS1_ALLOW_EXPERIMENTAL_CIPHERSUITES 0 |
bc348244 | 82 | |
c6a87647 BM |
83 | #define TLS1_VERSION 0x0301 |
84 | #define TLS1_1_VERSION 0x0302 | |
020a4782 | 85 | #define TLS1_2_VERSION 0x0303 |
dc5dfe43 | 86 | /* TLS 1.1 and 1.2 are not supported by this version of OpenSSL, so |
c6a87647 BM |
87 | * TLS_MAX_VERSION indicates TLS 1.0 regardless of the above |
88 | * definitions. (s23_clnt.c and s23_srvr.c have an OPENSSL_assert() | |
89 | * check that would catch the error if TLS_MAX_VERSION was too low.) | |
90 | */ | |
91 | #define TLS_MAX_VERSION TLS1_VERSION | |
92 | ||
93 | #define TLS1_VERSION_MAJOR 0x03 | |
94 | #define TLS1_VERSION_MINOR 0x01 | |
020a4782 | 95 | |
020a4782 RS |
96 | #define TLS1_1_VERSION_MAJOR 0x03 |
97 | #define TLS1_1_VERSION_MINOR 0x02 | |
98 | ||
c6a87647 BM |
99 | #define TLS1_2_VERSION_MAJOR 0x03 |
100 | #define TLS1_2_VERSION_MINOR 0x03 | |
58964a49 | 101 | |
020a4782 RS |
102 | #define TLS1_get_version(s) \ |
103 | ((s->version >> 8) == TLS1_VERSION_MAJOR ? s->version : 0) | |
104 | ||
105 | #define TLS1_get_client_version(s) \ | |
106 | ((s->client_version >> 8) == TLS1_VERSION_MAJOR ? s->client_version : 0) | |
107 | ||
58964a49 RE |
108 | #define TLS1_AD_DECRYPTION_FAILED 21 |
109 | #define TLS1_AD_RECORD_OVERFLOW 22 | |
110 | #define TLS1_AD_UNKNOWN_CA 48 /* fatal */ | |
111 | #define TLS1_AD_ACCESS_DENIED 49 /* fatal */ | |
112 | #define TLS1_AD_DECODE_ERROR 50 /* fatal */ | |
113 | #define TLS1_AD_DECRYPT_ERROR 51 | |
657e60fa | 114 | #define TLS1_AD_EXPORT_RESTRICTION 60 /* fatal */ |
58964a49 RE |
115 | #define TLS1_AD_PROTOCOL_VERSION 70 /* fatal */ |
116 | #define TLS1_AD_INSUFFICIENT_SECURITY 71 /* fatal */ | |
117 | #define TLS1_AD_INTERNAL_ERROR 80 /* fatal */ | |
c6a87647 | 118 | #define TLS1_AD_INAPPROPRIATE_FALLBACK 86 /* fatal */ |
657e60fa | 119 | #define TLS1_AD_USER_CANCELLED 90 |
58964a49 | 120 | #define TLS1_AD_NO_RENEGOTIATION 100 |
865a90eb DSH |
121 | /* codes 110-114 are from RFC3546 */ |
122 | #define TLS1_AD_UNSUPPORTED_EXTENSION 110 | |
123 | #define TLS1_AD_CERTIFICATE_UNOBTAINABLE 111 | |
124 | #define TLS1_AD_UNRECOGNIZED_NAME 112 | |
125 | #define TLS1_AD_BAD_CERTIFICATE_STATUS_RESPONSE 113 | |
126 | #define TLS1_AD_BAD_CERTIFICATE_HASH_VALUE 114 | |
127 | #define TLS1_AD_UNKNOWN_PSK_IDENTITY 115 /* fatal */ | |
128 | ||
129 | /* ExtensionType values from RFC 3546 */ | |
130 | #define TLSEXT_TYPE_server_name 0 | |
131 | #define TLSEXT_TYPE_max_fragment_length 1 | |
132 | #define TLSEXT_TYPE_client_certificate_url 2 | |
133 | #define TLSEXT_TYPE_trusted_ca_keys 3 | |
134 | #define TLSEXT_TYPE_truncated_hmac 4 | |
135 | #define TLSEXT_TYPE_status_request 5 | |
136 | #define TLSEXT_TYPE_elliptic_curves 10 | |
137 | #define TLSEXT_TYPE_ec_point_formats 11 | |
138 | #define TLSEXT_TYPE_session_ticket 35 | |
139 | ||
c2b78c31 BL |
140 | /* Temporary extension type */ |
141 | #define TLSEXT_TYPE_renegotiate 0xff01 | |
142 | ||
865a90eb DSH |
143 | /* NameType value from RFC 3546 */ |
144 | #define TLSEXT_NAMETYPE_host_name 0 | |
a5232767 DSH |
145 | /* status request value from RFC 3546 */ |
146 | #define TLSEXT_STATUSTYPE_ocsp 1 | |
865a90eb DSH |
147 | |
148 | #ifndef OPENSSL_NO_TLSEXT | |
149 | ||
150 | #define TLSEXT_MAXLEN_host_name 255 | |
151 | ||
152 | const char *SSL_get_servername(const SSL *s, const int type) ; | |
153 | int SSL_get_servername_type(const SSL *s) ; | |
154 | ||
155 | #define SSL_set_tlsext_host_name(s,name) \ | |
156 | SSL_ctrl(s,SSL_CTRL_SET_TLSEXT_HOSTNAME,TLSEXT_NAMETYPE_host_name,(char *)name) | |
157 | ||
158 | #define SSL_set_tlsext_debug_callback(ssl, cb) \ | |
159 | SSL_callback_ctrl(ssl,SSL_CTRL_SET_TLSEXT_DEBUG_CB,(void (*)(void))cb) | |
160 | ||
161 | #define SSL_set_tlsext_debug_arg(ssl, arg) \ | |
162 | SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_DEBUG_ARG,0, (void *)arg) | |
163 | ||
a5232767 DSH |
164 | #define SSL_set_tlsext_status_type(ssl, type) \ |
165 | SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_TYPE,type, NULL) | |
166 | ||
167 | #define SSL_get_tlsext_status_exts(ssl, arg) \ | |
168 | SSL_ctrl(ssl,SSL_CTRL_GET_TLSEXT_STATUS_REQ_EXTS,0, (void *)arg) | |
169 | ||
170 | #define SSL_set_tlsext_status_exts(ssl, arg) \ | |
171 | SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_EXTS,0, (void *)arg) | |
172 | ||
173 | #define SSL_get_tlsext_status_ids(ssl, arg) \ | |
174 | SSL_ctrl(ssl,SSL_CTRL_GET_TLSEXT_STATUS_REQ_IDS,0, (void *)arg) | |
175 | ||
176 | #define SSL_set_tlsext_status_ids(ssl, arg) \ | |
177 | SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_IDS,0, (void *)arg) | |
178 | ||
179 | #define SSL_get_tlsext_status_ocsp_resp(ssl, arg) \ | |
180 | SSL_ctrl(ssl,SSL_CTRL_GET_TLSEXT_STATUS_REQ_OCSP_RESP,0, (void *)arg) | |
181 | ||
182 | #define SSL_set_tlsext_status_ocsp_resp(ssl, arg, arglen) \ | |
183 | SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_OCSP_RESP,arglen, (void *)arg) | |
184 | ||
865a90eb DSH |
185 | #define SSL_CTX_set_tlsext_servername_callback(ctx, cb) \ |
186 | SSL_CTX_callback_ctrl(ctx,SSL_CTRL_SET_TLSEXT_SERVERNAME_CB,(void (*)(void))cb) | |
187 | ||
a5232767 DSH |
188 | #define SSL_TLSEXT_ERR_OK 0 |
189 | #define SSL_TLSEXT_ERR_ALERT_WARNING 1 | |
190 | #define SSL_TLSEXT_ERR_ALERT_FATAL 2 | |
865a90eb DSH |
191 | #define SSL_TLSEXT_ERR_NOACK 3 |
192 | ||
193 | #define SSL_CTX_set_tlsext_servername_arg(ctx, arg) \ | |
194 | SSL_CTX_ctrl(ctx,SSL_CTRL_SET_TLSEXT_SERVERNAME_ARG,0, (void *)arg) | |
c2079de8 DSH |
195 | |
196 | #define SSL_CTX_get_tlsext_ticket_keys(ctx, keys, keylen) \ | |
3dfa7416 | 197 | SSL_CTX_ctrl((ctx),SSL_CTRL_GET_TLSEXT_TICKET_KEYS,(keylen),(keys)) |
c2079de8 | 198 | #define SSL_CTX_set_tlsext_ticket_keys(ctx, keys, keylen) \ |
3dfa7416 | 199 | SSL_CTX_ctrl((ctx),SSL_CTRL_SET_TLSEXT_TICKET_KEYS,(keylen),(keys)) |
a5232767 DSH |
200 | |
201 | #define SSL_CTX_set_tlsext_status_cb(ssl, cb) \ | |
202 | SSL_CTX_callback_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB,(void (*)(void))cb) | |
203 | ||
204 | #define SSL_CTX_set_tlsext_status_arg(ssl, arg) \ | |
205 | SSL_CTX_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB_ARG,0, (void *)arg) | |
206 | ||
db533c96 DSH |
207 | #define SSL_CTX_set_tlsext_ticket_key_cb(ssl, cb) \ |
208 | SSL_CTX_callback_ctrl(ssl,SSL_CTRL_SET_TLSEXT_TICKET_KEY_CB,(void (*)(void))cb) | |
209 | ||
865a90eb | 210 | #endif |
58964a49 | 211 | |
1d90f280 BM |
212 | /* Additional TLS ciphersuites from draft-ietf-tls-56-bit-ciphersuites-00.txt |
213 | * (available if TLS1_ALLOW_EXPERIMENTAL_CIPHERSUITES is defined, see | |
214 | * s3_lib.c). We actually treat them like SSL 3.0 ciphers, which we probably | |
215 | * shouldn't. */ | |
abed0b8a BL |
216 | #define TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_MD5 0x03000060 |
217 | #define TLS1_CK_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5 0x03000061 | |
218 | #define TLS1_CK_RSA_EXPORT1024_WITH_DES_CBC_SHA 0x03000062 | |
219 | #define TLS1_CK_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA 0x03000063 | |
220 | #define TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_SHA 0x03000064 | |
221 | #define TLS1_CK_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA 0x03000065 | |
222 | #define TLS1_CK_DHE_DSS_WITH_RC4_128_SHA 0x03000066 | |
deb2c1a1 | 223 | |
ea4f109c | 224 | /* AES ciphersuites from RFC3268 */ |
deb2c1a1 DSH |
225 | |
226 | #define TLS1_CK_RSA_WITH_AES_128_SHA 0x0300002F | |
227 | #define TLS1_CK_DH_DSS_WITH_AES_128_SHA 0x03000030 | |
228 | #define TLS1_CK_DH_RSA_WITH_AES_128_SHA 0x03000031 | |
229 | #define TLS1_CK_DHE_DSS_WITH_AES_128_SHA 0x03000032 | |
230 | #define TLS1_CK_DHE_RSA_WITH_AES_128_SHA 0x03000033 | |
231 | #define TLS1_CK_ADH_WITH_AES_128_SHA 0x03000034 | |
232 | ||
233 | #define TLS1_CK_RSA_WITH_AES_256_SHA 0x03000035 | |
234 | #define TLS1_CK_DH_DSS_WITH_AES_256_SHA 0x03000036 | |
235 | #define TLS1_CK_DH_RSA_WITH_AES_256_SHA 0x03000037 | |
236 | #define TLS1_CK_DHE_DSS_WITH_AES_256_SHA 0x03000038 | |
237 | #define TLS1_CK_DHE_RSA_WITH_AES_256_SHA 0x03000039 | |
238 | #define TLS1_CK_ADH_WITH_AES_256_SHA 0x0300003A | |
abed0b8a | 239 | |
e18eef3d BM |
240 | /* Camellia ciphersuites from RFC4132 */ |
241 | #define TLS1_CK_RSA_WITH_CAMELLIA_128_CBC_SHA 0x03000041 | |
242 | #define TLS1_CK_DH_DSS_WITH_CAMELLIA_128_CBC_SHA 0x03000042 | |
243 | #define TLS1_CK_DH_RSA_WITH_CAMELLIA_128_CBC_SHA 0x03000043 | |
244 | #define TLS1_CK_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA 0x03000044 | |
245 | #define TLS1_CK_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 0x03000045 | |
246 | #define TLS1_CK_ADH_WITH_CAMELLIA_128_CBC_SHA 0x03000046 | |
247 | ||
248 | #define TLS1_CK_RSA_WITH_CAMELLIA_256_CBC_SHA 0x03000084 | |
249 | #define TLS1_CK_DH_DSS_WITH_CAMELLIA_256_CBC_SHA 0x03000085 | |
250 | #define TLS1_CK_DH_RSA_WITH_CAMELLIA_256_CBC_SHA 0x03000086 | |
251 | #define TLS1_CK_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA 0x03000087 | |
252 | #define TLS1_CK_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 0x03000088 | |
253 | #define TLS1_CK_ADH_WITH_CAMELLIA_256_CBC_SHA 0x03000089 | |
254 | ||
c3cc4662 BM |
255 | /* SEED ciphersuites from RFC4162 */ |
256 | #define TLS1_CK_RSA_WITH_SEED_SHA 0x03000096 | |
257 | #define TLS1_CK_DH_DSS_WITH_SEED_SHA 0x03000097 | |
258 | #define TLS1_CK_DH_RSA_WITH_SEED_SHA 0x03000098 | |
259 | #define TLS1_CK_DHE_DSS_WITH_SEED_SHA 0x03000099 | |
260 | #define TLS1_CK_DHE_RSA_WITH_SEED_SHA 0x0300009A | |
261 | #define TLS1_CK_ADH_WITH_SEED_SHA 0x0300009B | |
262 | ||
bc932045 BM |
263 | /* ECC ciphersuites from draft-ietf-tls-ecc-12.txt with changes soon to be in draft 13 */ |
264 | #define TLS1_CK_ECDH_ECDSA_WITH_NULL_SHA 0x0300C001 | |
265 | #define TLS1_CK_ECDH_ECDSA_WITH_RC4_128_SHA 0x0300C002 | |
266 | #define TLS1_CK_ECDH_ECDSA_WITH_DES_192_CBC3_SHA 0x0300C003 | |
267 | #define TLS1_CK_ECDH_ECDSA_WITH_AES_128_CBC_SHA 0x0300C004 | |
268 | #define TLS1_CK_ECDH_ECDSA_WITH_AES_256_CBC_SHA 0x0300C005 | |
269 | ||
270 | #define TLS1_CK_ECDHE_ECDSA_WITH_NULL_SHA 0x0300C006 | |
271 | #define TLS1_CK_ECDHE_ECDSA_WITH_RC4_128_SHA 0x0300C007 | |
272 | #define TLS1_CK_ECDHE_ECDSA_WITH_DES_192_CBC3_SHA 0x0300C008 | |
273 | #define TLS1_CK_ECDHE_ECDSA_WITH_AES_128_CBC_SHA 0x0300C009 | |
274 | #define TLS1_CK_ECDHE_ECDSA_WITH_AES_256_CBC_SHA 0x0300C00A | |
275 | ||
276 | #define TLS1_CK_ECDH_RSA_WITH_NULL_SHA 0x0300C00B | |
277 | #define TLS1_CK_ECDH_RSA_WITH_RC4_128_SHA 0x0300C00C | |
278 | #define TLS1_CK_ECDH_RSA_WITH_DES_192_CBC3_SHA 0x0300C00D | |
279 | #define TLS1_CK_ECDH_RSA_WITH_AES_128_CBC_SHA 0x0300C00E | |
280 | #define TLS1_CK_ECDH_RSA_WITH_AES_256_CBC_SHA 0x0300C00F | |
281 | ||
282 | #define TLS1_CK_ECDHE_RSA_WITH_NULL_SHA 0x0300C010 | |
283 | #define TLS1_CK_ECDHE_RSA_WITH_RC4_128_SHA 0x0300C011 | |
284 | #define TLS1_CK_ECDHE_RSA_WITH_DES_192_CBC3_SHA 0x0300C012 | |
285 | #define TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA 0x0300C013 | |
286 | #define TLS1_CK_ECDHE_RSA_WITH_AES_256_CBC_SHA 0x0300C014 | |
287 | ||
288 | #define TLS1_CK_ECDH_anon_WITH_NULL_SHA 0x0300C015 | |
289 | #define TLS1_CK_ECDH_anon_WITH_RC4_128_SHA 0x0300C016 | |
290 | #define TLS1_CK_ECDH_anon_WITH_DES_192_CBC3_SHA 0x0300C017 | |
291 | #define TLS1_CK_ECDH_anon_WITH_AES_128_CBC_SHA 0x0300C018 | |
292 | #define TLS1_CK_ECDH_anon_WITH_AES_256_CBC_SHA 0x0300C019 | |
ea262260 | 293 | |
1d90f280 BM |
294 | /* XXX |
295 | * Inconsistency alert: | |
296 | * The OpenSSL names of ciphers with ephemeral DH here include the string | |
297 | * "DHE", while elsewhere it has always been "EDH". | |
298 | * (The alias for the list of all such ciphers also is "EDH".) | |
299 | * The specifications speak of "EDH"; maybe we should allow both forms | |
300 | * for everything. */ | |
abed0b8a BL |
301 | #define TLS1_TXT_RSA_EXPORT1024_WITH_RC4_56_MD5 "EXP1024-RC4-MD5" |
302 | #define TLS1_TXT_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5 "EXP1024-RC2-CBC-MD5" | |
303 | #define TLS1_TXT_RSA_EXPORT1024_WITH_DES_CBC_SHA "EXP1024-DES-CBC-SHA" | |
304 | #define TLS1_TXT_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA "EXP1024-DHE-DSS-DES-CBC-SHA" | |
305 | #define TLS1_TXT_RSA_EXPORT1024_WITH_RC4_56_SHA "EXP1024-RC4-SHA" | |
306 | #define TLS1_TXT_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA "EXP1024-DHE-DSS-RC4-SHA" | |
307 | #define TLS1_TXT_DHE_DSS_WITH_RC4_128_SHA "DHE-DSS-RC4-SHA" | |
ea4f109c BM |
308 | |
309 | /* AES ciphersuites from RFC3268 */ | |
310 | #define TLS1_TXT_RSA_WITH_AES_128_SHA "AES128-SHA" | |
311 | #define TLS1_TXT_DH_DSS_WITH_AES_128_SHA "DH-DSS-AES128-SHA" | |
312 | #define TLS1_TXT_DH_RSA_WITH_AES_128_SHA "DH-RSA-AES128-SHA" | |
313 | #define TLS1_TXT_DHE_DSS_WITH_AES_128_SHA "DHE-DSS-AES128-SHA" | |
314 | #define TLS1_TXT_DHE_RSA_WITH_AES_128_SHA "DHE-RSA-AES128-SHA" | |
315 | #define TLS1_TXT_ADH_WITH_AES_128_SHA "ADH-AES128-SHA" | |
316 | ||
317 | #define TLS1_TXT_RSA_WITH_AES_256_SHA "AES256-SHA" | |
318 | #define TLS1_TXT_DH_DSS_WITH_AES_256_SHA "DH-DSS-AES256-SHA" | |
319 | #define TLS1_TXT_DH_RSA_WITH_AES_256_SHA "DH-RSA-AES256-SHA" | |
320 | #define TLS1_TXT_DHE_DSS_WITH_AES_256_SHA "DHE-DSS-AES256-SHA" | |
321 | #define TLS1_TXT_DHE_RSA_WITH_AES_256_SHA "DHE-RSA-AES256-SHA" | |
322 | #define TLS1_TXT_ADH_WITH_AES_256_SHA "ADH-AES256-SHA" | |
06ab81f9 | 323 | |
ea262260 BM |
324 | /* ECC ciphersuites from draft-ietf-tls-ecc-01.txt (Mar 15, 2001) */ |
325 | #define TLS1_TXT_ECDH_ECDSA_WITH_NULL_SHA "ECDH-ECDSA-NULL-SHA" | |
326 | #define TLS1_TXT_ECDH_ECDSA_WITH_RC4_128_SHA "ECDH-ECDSA-RC4-SHA" | |
ea262260 BM |
327 | #define TLS1_TXT_ECDH_ECDSA_WITH_DES_192_CBC3_SHA "ECDH-ECDSA-DES-CBC3-SHA" |
328 | #define TLS1_TXT_ECDH_ECDSA_WITH_AES_128_CBC_SHA "ECDH-ECDSA-AES128-SHA" | |
329 | #define TLS1_TXT_ECDH_ECDSA_WITH_AES_256_CBC_SHA "ECDH-ECDSA-AES256-SHA" | |
bc932045 BM |
330 | |
331 | #define TLS1_TXT_ECDHE_ECDSA_WITH_NULL_SHA "ECDHE-ECDSA-NULL-SHA" | |
332 | #define TLS1_TXT_ECDHE_ECDSA_WITH_RC4_128_SHA "ECDHE-ECDSA-RC4-SHA" | |
333 | #define TLS1_TXT_ECDHE_ECDSA_WITH_DES_192_CBC3_SHA "ECDHE-ECDSA-DES-CBC3-SHA" | |
334 | #define TLS1_TXT_ECDHE_ECDSA_WITH_AES_128_CBC_SHA "ECDHE-ECDSA-AES128-SHA" | |
335 | #define TLS1_TXT_ECDHE_ECDSA_WITH_AES_256_CBC_SHA "ECDHE-ECDSA-AES256-SHA" | |
ea262260 BM |
336 | |
337 | #define TLS1_TXT_ECDH_RSA_WITH_NULL_SHA "ECDH-RSA-NULL-SHA" | |
338 | #define TLS1_TXT_ECDH_RSA_WITH_RC4_128_SHA "ECDH-RSA-RC4-SHA" | |
ea262260 BM |
339 | #define TLS1_TXT_ECDH_RSA_WITH_DES_192_CBC3_SHA "ECDH-RSA-DES-CBC3-SHA" |
340 | #define TLS1_TXT_ECDH_RSA_WITH_AES_128_CBC_SHA "ECDH-RSA-AES128-SHA" | |
341 | #define TLS1_TXT_ECDH_RSA_WITH_AES_256_CBC_SHA "ECDH-RSA-AES256-SHA" | |
bc932045 BM |
342 | |
343 | #define TLS1_TXT_ECDHE_RSA_WITH_NULL_SHA "ECDHE-RSA-NULL-SHA" | |
344 | #define TLS1_TXT_ECDHE_RSA_WITH_RC4_128_SHA "ECDHE-RSA-RC4-SHA" | |
345 | #define TLS1_TXT_ECDHE_RSA_WITH_DES_192_CBC3_SHA "ECDHE-RSA-DES-CBC3-SHA" | |
346 | #define TLS1_TXT_ECDHE_RSA_WITH_AES_128_CBC_SHA "ECDHE-RSA-AES128-SHA" | |
347 | #define TLS1_TXT_ECDHE_RSA_WITH_AES_256_CBC_SHA "ECDHE-RSA-AES256-SHA" | |
ea262260 BM |
348 | |
349 | #define TLS1_TXT_ECDH_anon_WITH_NULL_SHA "AECDH-NULL-SHA" | |
350 | #define TLS1_TXT_ECDH_anon_WITH_RC4_128_SHA "AECDH-RC4-SHA" | |
ea262260 | 351 | #define TLS1_TXT_ECDH_anon_WITH_DES_192_CBC3_SHA "AECDH-DES-CBC3-SHA" |
bc932045 BM |
352 | #define TLS1_TXT_ECDH_anon_WITH_AES_128_CBC_SHA "AECDH-AES128-SHA" |
353 | #define TLS1_TXT_ECDH_anon_WITH_AES_256_CBC_SHA "AECDH-AES256-SHA" | |
06ab81f9 | 354 | |
c3cc4662 | 355 | /* Camellia ciphersuites from RFC4132 */ |
e18eef3d BM |
356 | #define TLS1_TXT_RSA_WITH_CAMELLIA_128_CBC_SHA "CAMELLIA128-SHA" |
357 | #define TLS1_TXT_DH_DSS_WITH_CAMELLIA_128_CBC_SHA "DH-DSS-CAMELLIA128-SHA" | |
358 | #define TLS1_TXT_DH_RSA_WITH_CAMELLIA_128_CBC_SHA "DH-RSA-CAMELLIA128-SHA" | |
359 | #define TLS1_TXT_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA "DHE-DSS-CAMELLIA128-SHA" | |
360 | #define TLS1_TXT_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA "DHE-RSA-CAMELLIA128-SHA" | |
361 | #define TLS1_TXT_ADH_WITH_CAMELLIA_128_CBC_SHA "ADH-CAMELLIA128-SHA" | |
362 | ||
363 | #define TLS1_TXT_RSA_WITH_CAMELLIA_256_CBC_SHA "CAMELLIA256-SHA" | |
364 | #define TLS1_TXT_DH_DSS_WITH_CAMELLIA_256_CBC_SHA "DH-DSS-CAMELLIA256-SHA" | |
365 | #define TLS1_TXT_DH_RSA_WITH_CAMELLIA_256_CBC_SHA "DH-RSA-CAMELLIA256-SHA" | |
366 | #define TLS1_TXT_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA "DHE-DSS-CAMELLIA256-SHA" | |
367 | #define TLS1_TXT_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA "DHE-RSA-CAMELLIA256-SHA" | |
368 | #define TLS1_TXT_ADH_WITH_CAMELLIA_256_CBC_SHA "ADH-CAMELLIA256-SHA" | |
369 | ||
c3cc4662 BM |
370 | /* SEED ciphersuites from RFC4162 */ |
371 | #define TLS1_TXT_RSA_WITH_SEED_SHA "SEED-SHA" | |
372 | #define TLS1_TXT_DH_DSS_WITH_SEED_SHA "DH-DSS-SEED-SHA" | |
373 | #define TLS1_TXT_DH_RSA_WITH_SEED_SHA "DH-RSA-SEED-SHA" | |
374 | #define TLS1_TXT_DHE_DSS_WITH_SEED_SHA "DHE-DSS-SEED-SHA" | |
375 | #define TLS1_TXT_DHE_RSA_WITH_SEED_SHA "DHE-RSA-SEED-SHA" | |
376 | #define TLS1_TXT_ADH_WITH_SEED_SHA "ADH-SEED-SHA" | |
e18eef3d | 377 | |
58964a49 RE |
378 | #define TLS_CT_RSA_SIGN 1 |
379 | #define TLS_CT_DSS_SIGN 2 | |
380 | #define TLS_CT_RSA_FIXED_DH 3 | |
381 | #define TLS_CT_DSS_FIXED_DH 4 | |
bc932045 BM |
382 | #define TLS_CT_ECDSA_SIGN 64 |
383 | #define TLS_CT_RSA_FIXED_ECDH 65 | |
384 | #define TLS_CT_ECDSA_FIXED_ECDH 66 | |
ea262260 | 385 | #define TLS_CT_NUMBER 7 |
58964a49 RE |
386 | |
387 | #define TLS1_FINISH_MAC_LENGTH 12 | |
388 | ||
389 | #define TLS_MD_MAX_CONST_SIZE 20 | |
390 | #define TLS_MD_CLIENT_FINISH_CONST "client finished" | |
391 | #define TLS_MD_CLIENT_FINISH_CONST_SIZE 15 | |
392 | #define TLS_MD_SERVER_FINISH_CONST "server finished" | |
393 | #define TLS_MD_SERVER_FINISH_CONST_SIZE 15 | |
394 | #define TLS_MD_SERVER_WRITE_KEY_CONST "server write key" | |
395 | #define TLS_MD_SERVER_WRITE_KEY_CONST_SIZE 16 | |
396 | #define TLS_MD_KEY_EXPANSION_CONST "key expansion" | |
397 | #define TLS_MD_KEY_EXPANSION_CONST_SIZE 13 | |
398 | #define TLS_MD_CLIENT_WRITE_KEY_CONST "client write key" | |
399 | #define TLS_MD_CLIENT_WRITE_KEY_CONST_SIZE 16 | |
400 | #define TLS_MD_SERVER_WRITE_KEY_CONST "server write key" | |
401 | #define TLS_MD_SERVER_WRITE_KEY_CONST_SIZE 16 | |
402 | #define TLS_MD_IV_BLOCK_CONST "IV block" | |
403 | #define TLS_MD_IV_BLOCK_CONST_SIZE 8 | |
404 | #define TLS_MD_MASTER_SECRET_CONST "master secret" | |
405 | #define TLS_MD_MASTER_SECRET_CONST_SIZE 13 | |
406 | ||
ca570cfd UM |
407 | #ifdef CHARSET_EBCDIC |
408 | #undef TLS_MD_CLIENT_FINISH_CONST | |
409 | #define TLS_MD_CLIENT_FINISH_CONST "\x63\x6c\x69\x65\x6e\x74\x20\x66\x69\x6e\x69\x73\x68\x65\x64" /*client finished*/ | |
410 | #undef TLS_MD_SERVER_FINISH_CONST | |
411 | #define TLS_MD_SERVER_FINISH_CONST "\x73\x65\x72\x76\x65\x72\x20\x66\x69\x6e\x69\x73\x68\x65\x64" /*server finished*/ | |
412 | #undef TLS_MD_SERVER_WRITE_KEY_CONST | |
413 | #define TLS_MD_SERVER_WRITE_KEY_CONST "\x73\x65\x72\x76\x65\x72\x20\x77\x72\x69\x74\x65\x20\x6b\x65\x79" /*server write key*/ | |
414 | #undef TLS_MD_KEY_EXPANSION_CONST | |
415 | #define TLS_MD_KEY_EXPANSION_CONST "\x6b\x65\x79\x20\x65\x78\x70\x61\x6e\x73\x69\x6f\x6e" /*key expansion*/ | |
416 | #undef TLS_MD_CLIENT_WRITE_KEY_CONST | |
417 | #define TLS_MD_CLIENT_WRITE_KEY_CONST "\x63\x6c\x69\x65\x6e\x74\x20\x77\x72\x69\x74\x65\x20\x6b\x65\x79" /*client write key*/ | |
418 | #undef TLS_MD_SERVER_WRITE_KEY_CONST | |
419 | #define TLS_MD_SERVER_WRITE_KEY_CONST "\x73\x65\x72\x76\x65\x72\x20\x77\x72\x69\x74\x65\x20\x6b\x65\x79" /*server write key*/ | |
420 | #undef TLS_MD_IV_BLOCK_CONST | |
421 | #define TLS_MD_IV_BLOCK_CONST "\x49\x56\x20\x62\x6c\x6f\x63\x6b" /*IV block*/ | |
422 | #undef TLS_MD_MASTER_SECRET_CONST | |
423 | #define TLS_MD_MASTER_SECRET_CONST "\x6d\x61\x73\x74\x65\x72\x20\x73\x65\x63\x72\x65\x74" /*master secret*/ | |
424 | #endif | |
425 | ||
58964a49 RE |
426 | #ifdef __cplusplus |
427 | } | |
428 | #endif | |
429 | #endif |