Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
728 changes: 400 additions & 328 deletions src/lib/tls/tls13/tls_cipher_state.cpp

Large diffs are not rendered by default.

263 changes: 185 additions & 78 deletions src/lib/tls/tls13/tls_cipher_state.h

Large diffs are not rendered by default.

8 changes: 6 additions & 2 deletions src/lib/tls/tls13/tls_client_impl_13.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -366,8 +366,12 @@ void Client_Impl_13::handle(const Server_Hello_13& sh) {
return new_cipher_state;
} else {
m_handshake->resumed_session.reset(); // might have been set if we attempted a resumption
return Cipher_State::init_with_server_hello(
m_side, std::move(shared_secret), cipher.value(), m_transcript_hash->current(), secret_logger());
return Cipher_State::init_with_server_hello(m_side,
TLS_Flavor::TLS,
std::move(shared_secret),
cipher.value(),
m_transcript_hash->current(),
secret_logger());
}
}());

Expand Down
4 changes: 2 additions & 2 deletions src/lib/tls/tls13/tls_extensions_psk.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -76,8 +76,8 @@ class Client_PSK {
// transcript hash that underpins the PSK binders. S.a. `calculate_binders()`
m_binder(HashFunction::create_or_throw(prf_algo)->output_length()),
m_is_resumption(psk_type == Cipher_State::PSK_Type::Resumption),
m_cipher_state(
Cipher_State::init_with_psk(Connection_Side::Client, psk_type, std::move(master_secret), prf_algo)) {}
m_cipher_state(Cipher_State::init_with_psk(
Connection_Side::Client, TLS_Flavor::TLS, psk_type, std::move(master_secret), prf_algo)) {}

const PskIdentity& identity() const { return m_identity; }

Expand Down
7 changes: 4 additions & 3 deletions src/lib/tls/tls13/tls_record_layer_13.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -170,8 +170,8 @@ std::vector<uint8_t> Record_Layer::prepare_records(const Record_Type type,

const auto pt_fragment = data.subspan(pt_offset, pt_size);
if(protect) {
const auto record =
cipher_state->protect_record(type, pt_fragment, pt_size_with_type_and_padding - pt_size_with_type);
const auto record = as_tls_cipher_state(cipher_state)
->protect_record(type, pt_fragment, pt_size_with_type_and_padding - pt_size_with_type);
BOTAN_ASSERT_NOMSG(record.size() == ct_size + TLS_HEADER_SIZE);

// TODO: avoid this copy
Expand Down Expand Up @@ -270,7 +270,8 @@ Record_Layer::ReadResult Record_Layer::next_record(Cipher_State* cipher_state) {
throw TLS_Exception(Alert::UnexpectedMessage, "premature Application Data received");
}

return generalize_to<ReadResult>(cipher_state->deprotect_record(std::move(record), m_incoming_record_size_limit));
return generalize_to<ReadResult>(
as_tls_cipher_state(cipher_state)->deprotect_record(std::move(record), m_incoming_record_size_limit));
}
}

Expand Down
39 changes: 23 additions & 16 deletions src/lib/tls/tls13/tls_server_impl_13.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -272,20 +272,23 @@ void Server_Impl_13::handle_reply_to_client_hello(Server_Hello_13 server_hello)
auto* psk_extension = server_hello.extensions().get<PSK>();

psk_cipher_state = std::visit(
overloaded{[&, this](Session session) {
m_handshake->resumed_session = std::move(session);
return Cipher_State::init_with_psk(Connection_Side::Server,
Cipher_State::PSK_Type::Resumption,
m_handshake->resumed_session->extract_master_secret(),
cipher.prf_algo());
},
[&, this](ExternalPSK psk) {
m_handshake->psk_identity = psk.identity();
const auto psk_type =
psk.is_imported() ? Cipher_State::PSK_Type::Imported : Cipher_State::PSK_Type::External;
return Cipher_State::init_with_psk(
Connection_Side::Server, psk_type, psk.extract_master_secret(), cipher.prf_algo());
}},
overloaded{
[&, this](Session session) {
m_handshake->resumed_session = std::move(session);
return Cipher_State::init_with_psk(Connection_Side::Server,
TLS_Flavor::TLS,
Cipher_State::PSK_Type::Resumption,
m_handshake->resumed_session->extract_master_secret(),
cipher.prf_algo());
},
[&, this](ExternalPSK psk) {
m_handshake->psk_identity = psk.identity();
const auto psk_type =
psk.is_imported() ? Cipher_State::PSK_Type::Imported : Cipher_State::PSK_Type::External;
return Cipher_State::init_with_psk(
Connection_Side::Server, TLS_Flavor::TLS, psk_type, psk.extract_master_secret(), cipher.prf_algo());
},
},
psk_extension->take_session_to_resume_or_psk());
psk_cipher_state->set_secret_logger(secret_logger());

Expand Down Expand Up @@ -349,8 +352,12 @@ void Server_Impl_13::handle_reply_to_client_hello(Server_Hello_13 server_hello)

return std::move(psk_cipher_state);
} else {
return Cipher_State::init_with_server_hello(
m_side, my_keyshare->take_shared_secret(), cipher, m_transcript_hash->current(), secret_logger());
return Cipher_State::init_with_server_hello(m_side,
TLS_Flavor::TLS,
my_keyshare->take_shared_secret(),
cipher,
m_transcript_hash->current(),
secret_logger());
}
}());

Expand Down
Loading
Loading