OpenVPN
ssl_mbedtls.c
Go to the documentation of this file.
1/*
2 * OpenVPN -- An application to securely tunnel IP networks
3 * over a single TCP/UDP port, with support for SSL/TLS-based
4 * session authentication and key exchange,
5 * packet encryption, packet authentication, and
6 * packet compression.
7 *
8 * Copyright (C) 2002-2026 OpenVPN Inc <sales@openvpn.net>
9 * Copyright (C) 2010-2026 Sentyron B.V. <openvpn@sentyron.com>
10 * Copyright (C) 2006-2010, Brainspark B.V.
11 *
12 * This program is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU General Public License version 2
14 * as published by the Free Software Foundation.
15 *
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 * GNU General Public License for more details.
20 *
21 * You should have received a copy of the GNU General Public License along
22 * with this program; if not, see <https://www.gnu.org/licenses/>.
23 */
24
30#ifdef HAVE_CONFIG_H
31#include "config.h"
32#endif
33
34#include "syshead.h"
35
36#if defined(ENABLE_CRYPTO_MBEDTLS)
37
38#include "errlevel.h"
39#include "ssl_backend.h"
40#include "base64.h"
41#include "buffer.h"
42#include "misc.h"
43#include "manage.h"
44#include "mbedtls_compat.h"
45#include "pkcs11_backend.h"
46#include "ssl_common.h"
47#include "ssl_util.h"
48
49#include "ssl_verify_mbedtls.h"
50#include <mbedtls/debug.h>
51#include <mbedtls/error.h>
52#include <mbedtls/net_sockets.h>
53#include <mbedtls/version.h>
54
55#include <mbedtls/oid.h>
56#include <mbedtls/pem.h>
57
58static const mbedtls_x509_crt_profile openvpn_x509_crt_profile_legacy = {
59 /* Hashes from SHA-1 and above */
60 MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA1) | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_RIPEMD160)
61 | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA224) | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA256)
62 | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA384) | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA512),
63 0xFFFFFFF, /* Any PK alg */
64 0xFFFFFFF, /* Any curve */
65 1024, /* RSA-1024 and larger */
66};
67
68static const mbedtls_x509_crt_profile openvpn_x509_crt_profile_preferred = {
69 /* SHA-2 and above */
70 MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA224) | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA256)
71 | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA384) | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA512),
72 0xFFFFFFF, /* Any PK alg */
73 0xFFFFFFF, /* Any curve */
74 2048, /* RSA-2048 and larger */
75};
76
77#define openvpn_x509_crt_profile_suiteb mbedtls_x509_crt_profile_suiteb;
78
79void
80tls_init_lib(void)
81{
83}
84
85void
86tls_free_lib(void)
87{
88}
89
90void
92{
93 ASSERT(NULL != ctx);
94 CLEAR(*ctx);
95
96#if MBEDTLS_VERSION_NUMBER < 0x04000000
97 ALLOC_OBJ_CLEAR(ctx->dhm_ctx, mbedtls_dhm_context);
98#endif
99
100 ALLOC_OBJ_CLEAR(ctx->ca_chain, mbedtls_x509_crt);
101
102 ctx->endpoint = MBEDTLS_SSL_IS_SERVER;
103 ctx->initialised = true;
104}
105
106void
108{
109 ASSERT(NULL != ctx);
110 CLEAR(*ctx);
111
112#if MBEDTLS_VERSION_NUMBER < 0x04000000
113 ALLOC_OBJ_CLEAR(ctx->dhm_ctx, mbedtls_dhm_context);
114#endif
115 ALLOC_OBJ_CLEAR(ctx->ca_chain, mbedtls_x509_crt);
116
117 ctx->endpoint = MBEDTLS_SSL_IS_CLIENT;
118 ctx->initialised = true;
119}
120
121void
122tls_ctx_free(struct tls_root_ctx *ctx)
123{
124 if (ctx)
125 {
126 mbedtls_pk_free(ctx->priv_key);
127 free(ctx->priv_key);
128
129 mbedtls_x509_crt_free(ctx->ca_chain);
130 free(ctx->ca_chain);
131
132 mbedtls_x509_crt_free(ctx->crt_chain);
133 free(ctx->crt_chain);
134
135#if MBEDTLS_VERSION_NUMBER < 0x04000000
136 mbedtls_dhm_free(ctx->dhm_ctx);
137 free(ctx->dhm_ctx);
138#endif
139
140 mbedtls_x509_crl_free(ctx->crl);
141 free(ctx->crl);
142
143#if defined(ENABLE_PKCS11)
144 /* ...freeCertificate() can handle NULL ptrs, but if pkcs11 helper
145 * has not been initialized, it will ASSERT() - so, do not pass NULL
146 */
147 if (ctx->pkcs11_cert)
148 {
149 pkcs11h_certificate_freeCertificate(ctx->pkcs11_cert);
150 }
151#endif
152
153 free(ctx->allowed_ciphers);
154
155 free(ctx->groups);
156
157 CLEAR(*ctx);
158
159 ctx->initialised = false;
160 }
161}
162
163bool
165{
166 /* either this should be NULL or should be non-null and then have a
167 * valid TLS ctx inside as well */
168 ASSERT(NULL == ctx || ctx->initialised);
169 return ctx != NULL;
170}
171#if !defined(MBEDTLS_SSL_KEYING_MATERIAL_EXPORT)
172/*
173 * If we don't have mbedtls_ssl_export_keying_material(), we use
174 * mbedtls_ssl_set_export_keys_cb() to obtain a copy of the TLS 1.2
175 * master secret and compute the TLS-Exporter function ourselves.
176 * Unfortunately, with TLS 1.3, there is no alternative to
177 * mbedtls_ssl_export_keying_material().
178 */
179void
180mbedtls_ssl_export_keys_cb(void *p_expkey, mbedtls_ssl_key_export_type type,
181 const unsigned char *secret, size_t secret_len,
182 const unsigned char client_random[32],
183 const unsigned char server_random[32],
184 mbedtls_tls_prf_types tls_prf_type)
185{
186 /* Since we can't get the TLS 1.3 exporter master secret, we ignore all key
187 * types except MBEDTLS_SSL_KEY_EXPORT_TLS12_MASTER_SECRET. */
188 if (type != MBEDTLS_SSL_KEY_EXPORT_TLS12_MASTER_SECRET)
189 {
190 return;
191 }
192
193 struct tls_session *session = p_expkey;
194 struct key_state_ssl *ks_ssl = &session->key[KS_PRIMARY].ks_ssl;
195 struct tls_key_cache *cache = &ks_ssl->tls_key_cache;
196
197 /* The TLS 1.2 master secret has a fixed size, so if secret_len has
198 * a different value, something is wrong with mbed TLS. */
199 if (secret_len != sizeof(cache->master_secret))
200 {
201 msg(M_FATAL, "ERROR: Incorrect TLS 1.2 master secret length: Got %zu, expected %zu",
202 secret_len, sizeof(cache->master_secret));
203 }
204
205 memcpy(cache->client_server_random, client_random, 32);
206 memcpy(cache->client_server_random + 32, server_random, 32);
207 memcpy(cache->master_secret, secret, sizeof(cache->master_secret));
208 cache->tls_prf_type = tls_prf_type;
209}
210#endif /* !defined(MBEDTLS_SSL_KEYING_MATERIAL_EXPORT) */
211
212
213bool
214key_state_export_keying_material(struct tls_session *session, const char *label, size_t label_size,
215 void *ekm, size_t ekm_size)
216{
217 ASSERT(strlen(label) == label_size);
218
219#if defined(MBEDTLS_SSL_KEYING_MATERIAL_EXPORT)
220 /* Our version of mbed TLS has a built-in TLS-Exporter. */
221
222 mbedtls_ssl_context *ctx = session->key[KS_PRIMARY].ks_ssl.ctx;
223 if (mbed_ok(
224 mbedtls_ssl_export_keying_material(ctx, ekm, ekm_size, label, label_size, NULL, 0, 0)))
225 {
226 return true;
227 }
228 else
229 {
230 return false;
231 }
232
233#else /* defined(MBEDTLS_SSL_KEYING_MATERIAL_EXPORT) */
234 struct tls_key_cache *cache = &session->key[KS_PRIMARY].ks_ssl.tls_key_cache;
235
236 /* If the type is NONE, we either have no cached secrets or
237 * there is no PRF, in both cases we cannot generate key material */
238 if (cache->tls_prf_type == MBEDTLS_SSL_TLS_PRF_NONE)
239 {
240 return false;
241 }
242
243 int ret = mbedtls_ssl_tls_prf(cache->tls_prf_type, cache->master_secret,
244 sizeof(cache->master_secret), label, cache->client_server_random,
245 sizeof(cache->client_server_random), ekm, ekm_size);
246
247 if (mbed_ok(ret))
248 {
249 return true;
250 }
251 else
252 {
253 secure_memzero(ekm, session->opt->ekm_size);
254 return false;
255 }
256#endif /* defined(MBEDTLS_SSL_KEYING_MATERIAL_EXPORT) */
257}
258
259bool
260tls_ctx_set_options(struct tls_root_ctx *ctx, unsigned int ssl_flags)
261{
262 return true;
263}
264
265static const char *
266tls_translate_cipher_name(const char *cipher_name)
267{
268 const tls_cipher_name_pair *pair = tls_get_cipher_name_pair(cipher_name, strlen(cipher_name));
269
270 if (NULL == pair)
271 {
272 /* No translation found, return original */
273 return cipher_name;
274 }
275
276 if (0 != strcmp(cipher_name, pair->iana_name))
277 {
278 /* Deprecated name found, notify user */
279 msg(M_WARN, "Deprecated cipher suite name '%s', please use IANA name '%s'",
280 pair->openssl_name, pair->iana_name);
281 }
282
283 return pair->iana_name;
284}
285
286void
287tls_ctx_restrict_ciphers_tls13(struct tls_root_ctx *ctx, const char *ciphers)
288{
289 if (ciphers == NULL)
290 {
291 /* Nothing to do, return without warning message */
292 return;
293 }
294
295 msg(M_WARN,
296 "mbed TLS does not support setting tls-ciphersuites. "
297 "Ignoring TLS 1.3 cipher list: %s",
298 ciphers);
299}
300
301void
302tls_ctx_restrict_ciphers(struct tls_root_ctx *ctx, const char *ciphers)
303{
304 char *tmp_ciphers, *tmp_ciphers_orig, *token;
305
306 if (NULL == ciphers)
307 {
308 return; /* Nothing to do */
309 }
310
311 ASSERT(NULL != ctx);
312
313 /* Get number of ciphers */
314 int cipher_count = get_num_elements(ciphers, ':');
315
316 /* Allocate an array for them */
317 ALLOC_ARRAY_CLEAR(ctx->allowed_ciphers, int, cipher_count + 1)
318
319 /* Parse allowed ciphers, getting IDs */
320 int i = 0;
321 tmp_ciphers_orig = tmp_ciphers = string_alloc(ciphers, NULL);
322
323 token = strtok(tmp_ciphers, ":");
324 while (token)
325 {
326 ctx->allowed_ciphers[i] = mbedtls_ssl_get_ciphersuite_id(tls_translate_cipher_name(token));
327 if (0 != ctx->allowed_ciphers[i])
328 {
329 i++;
330 }
331 token = strtok(NULL, ":");
332 }
333 free(tmp_ciphers_orig);
334}
335
336void
337tls_ctx_set_cert_profile(struct tls_root_ctx *ctx, const char *profile)
338{
339 if (!profile || 0 == strcmp(profile, "legacy") || 0 == strcmp(profile, "insecure"))
340 {
341 ctx->cert_profile = openvpn_x509_crt_profile_legacy;
342 }
343 else if (0 == strcmp(profile, "preferred"))
344 {
345 ctx->cert_profile = openvpn_x509_crt_profile_preferred;
346 }
347 else if (0 == strcmp(profile, "suiteb"))
348 {
349 ctx->cert_profile = openvpn_x509_crt_profile_suiteb;
350 }
351 else
352 {
353 msg(M_FATAL, "ERROR: Invalid cert profile: %s", profile);
354 }
355}
356
357#if MBEDTLS_VERSION_NUMBER >= 0x04000000
358static const mbedtls_ecp_curve_info ecp_curve_info_table[] = {
359/* secp curves. */
360#if defined(PSA_WANT_ECC_SECP_R1_256)
361 { "secp256r1", MBEDTLS_SSL_IANA_TLS_GROUP_SECP256R1 },
362#endif
363#if defined(PSA_WANT_ECC_SECP_R1_384)
364 { "secp384r1", MBEDTLS_SSL_IANA_TLS_GROUP_SECP384R1 },
365#endif
366#if defined(PSA_WANT_ECC_SECP_R1_521)
367 { "secp521r1", MBEDTLS_SSL_IANA_TLS_GROUP_SECP521R1 },
368#endif
369
370/* Curve25519. */
371#if defined(PSA_WANT_ECC_MONTGOMERY_255)
372 { "X25519", MBEDTLS_SSL_IANA_TLS_GROUP_X25519 },
373#endif
374
375/* Curve448. */
376#if defined(PSA_WANT_ECC_MONTGOMERY_448)
377 { "X448", MBEDTLS_SSL_IANA_TLS_GROUP_X448 },
378#endif
379
380/* Brainpool curves. */
381#if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_256)
382 { "brainpoolP256r1", MBEDTLS_SSL_IANA_TLS_GROUP_BP256R1 },
383#endif
384#if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_384)
385 { "brainpoolP384r1", MBEDTLS_SSL_IANA_TLS_GROUP_BP384R1 },
386#endif
387#if defined(PSA_WANT_ECC_BRAINPOOL_P_R1_512)
388 { "brainpoolP512r1", MBEDTLS_SSL_IANA_TLS_GROUP_BP512R1 },
389#endif
390
391/* Named Diffie-Hellman groups. */
392#if defined(PSA_WANT_DH_RFC7919_2048)
393 { "ffdhe2048", MBEDTLS_SSL_IANA_TLS_GROUP_FFDHE2048 },
394#endif
395#if defined(PSA_WANT_DH_RFC7919_3072)
396 { "ffdhe3072", MBEDTLS_SSL_IANA_TLS_GROUP_FFDHE3072 },
397#endif
398#if defined(PSA_WANT_DH_RFC7919_4096)
399 { "ffdhe4096", MBEDTLS_SSL_IANA_TLS_GROUP_FFDHE4096 },
400#endif
401#if defined(PSA_WANT_DH_RFC7919_6144)
402 { "ffdhe6144", MBEDTLS_SSL_IANA_TLS_GROUP_FFDHE6144 },
403#endif
404#if defined(PSA_WANT_DH_RFC7919_8192)
405 { "ffdhe8192", MBEDTLS_SSL_IANA_TLS_GROUP_FFDHE8192 },
406#endif
407};
408static const size_t ecp_curve_info_table_items = sizeof(ecp_curve_info_table) / sizeof(mbedtls_ecp_curve_info);
409
410static const mbedtls_ecp_curve_info *
411mbedtls_ecp_curve_info_from_name(const char *name)
412{
413 for (size_t i = 0; i < ecp_curve_info_table_items; i++)
414 {
415 if (strcmp(name, ecp_curve_info_table[i].name) == 0)
416 {
417 return &ecp_curve_info_table[i];
418 }
419 }
420 return NULL;
421}
422#endif /* MBEDTLS_VERSION_NUMBER >= 0x04000000 */
423
424void
425tls_ctx_set_tls_groups(struct tls_root_ctx *ctx, const char *groups)
426{
427 ASSERT(ctx);
428 struct gc_arena gc = gc_new();
429
430 /* Get number of groups and allocate an array in ctx */
431 int groups_count = get_num_elements(groups, ':');
432 ALLOC_ARRAY_CLEAR(ctx->groups, uint16_t, groups_count + 1)
433
434 /* Parse allowed ciphers, getting IDs */
435 int i = 0;
436 char *tmp_groups = string_alloc(groups, &gc);
437
438 const char *token;
439 while ((token = strsep(&tmp_groups, ":")))
440 {
441 const mbedtls_ecp_curve_info *ci = mbedtls_ecp_curve_info_from_name(token);
442 if (!ci)
443 {
444 msg(M_WARN, "Warning unknown curve/group specified: %s", token);
445 }
446 else
447 {
448 ctx->groups[i] = ci->tls_id;
449 i++;
450 }
451 }
452
453 /* Recent mbedtls versions state that the list of groups must be terminated
454 * with 0. Older versions state that it must be terminated with MBEDTLS_ECP_DP_NONE
455 * which is also 0, so this works either way. */
456 ctx->groups[i] = 0;
457
458 gc_free(&gc);
459}
460
461
462void
463tls_ctx_check_cert_time(const struct tls_root_ctx *ctx)
464{
465 ASSERT(ctx);
466 if (ctx->crt_chain == NULL)
467 {
468 return; /* Nothing to check if there is no certificate */
469 }
470
471 if (mbedtls_x509_time_is_future(&ctx->crt_chain->valid_from))
472 {
473 msg(M_WARN, "WARNING: Your certificate is not yet valid!");
474 }
475
476 if (mbedtls_x509_time_is_past(&ctx->crt_chain->valid_to))
477 {
478 msg(M_WARN, "WARNING: Your certificate has expired!");
479 }
480}
481
482void
483tls_ctx_load_dh_params(struct tls_root_ctx *ctx, const char *dh_file, bool dh_inline)
484{
485#if MBEDTLS_VERSION_NUMBER < 0x04000000
486 if (dh_inline)
487 {
488 if (!mbed_ok(mbedtls_dhm_parse_dhm(ctx->dhm_ctx, (const unsigned char *)dh_file,
489 strlen(dh_file) + 1)))
490 {
491 msg(M_FATAL, "Cannot read inline DH parameters");
492 }
493 }
494 else
495 {
496 if (!mbed_ok(mbedtls_dhm_parse_dhmfile(ctx->dhm_ctx, dh_file)))
497 {
498 msg(M_FATAL, "Cannot read DH parameters from file %s", dh_file);
499 }
500 }
501
502 msg(D_TLS_DEBUG_LOW, "Diffie-Hellman initialized with " counter_format " bit key",
503 (counter_type)mbedtls_dhm_get_bitlen(ctx->dhm_ctx));
504#else
505 if (strcmp(dh_file, "none") != 0)
506 {
507 msg(M_FATAL, "Mbed TLS 4 only supports pre-defined Diffie-Hellman groups.");
508 }
509#endif /* MBEDTLS_VERSION_NUMBER < 0x04000000 */
510}
511
512void
513tls_ctx_load_ecdh_params(struct tls_root_ctx *ctx, const char *curve_name)
514{
515 if (NULL != curve_name)
516 {
517 msg(M_WARN, "WARNING: mbed TLS builds do not support specifying an "
518 "ECDH curve with --ecdh-curve, using default curves. Use "
519 "--tls-groups to specify curves.");
520 }
521}
522
523int
524tls_ctx_load_pkcs12(struct tls_root_ctx *ctx, const char *pkcs12_file, bool pkcs12_file_inline,
525 bool load_ca_file)
526{
527 msg(M_FATAL, "PKCS #12 files not yet supported for mbed TLS.");
528 return 0;
529}
530
531#ifdef ENABLE_CRYPTOAPI
532void
533tls_ctx_load_cryptoapi(struct tls_root_ctx *ctx, const char *cryptoapi_cert)
534{
535 msg(M_FATAL, "Windows CryptoAPI not yet supported for mbed TLS.");
536}
537#endif /* _WIN32 */
538
539void
540tls_ctx_load_cert_file(struct tls_root_ctx *ctx, const char *cert_file, bool cert_inline)
541{
542 ASSERT(NULL != ctx);
543
544 if (!ctx->crt_chain)
545 {
546 ALLOC_OBJ_CLEAR(ctx->crt_chain, mbedtls_x509_crt);
547 }
548
549 if (cert_inline)
550 {
551 if (!cert_file)
552 {
553 msg(M_FATAL, "Cannot load inline certificate: NULL");
554 }
555 if (!mbed_ok(mbedtls_x509_crt_parse(ctx->crt_chain, (const unsigned char *)cert_file,
556 strlen(cert_file) + 1)))
557 {
558 msg(M_FATAL, "Cannot load inline certificate");
559 }
560 }
561 else
562 {
563 if (!mbed_ok(mbedtls_x509_crt_parse_file(ctx->crt_chain, cert_file)))
564 {
565 msg(M_FATAL, "Cannot load certificate file %s", cert_file);
566 }
567 }
568}
569
570int
571tls_ctx_load_priv_file(struct tls_root_ctx *ctx, const char *priv_key_file, bool priv_key_inline)
572{
573 int status;
574 ASSERT(NULL != ctx);
575
576 if (!ctx->priv_key)
577 {
578 ALLOC_OBJ_CLEAR(ctx->priv_key, mbedtls_pk_context);
579 }
580
581 if (priv_key_inline)
582 {
583 status = mbedtls_compat_pk_parse_key(ctx->priv_key, (const unsigned char *)priv_key_file,
584 strlen(priv_key_file) + 1, NULL, 0);
585
586 if (MBEDTLS_ERR_PK_PASSWORD_REQUIRED == status)
587 {
588 char passbuf[512] = { 0 };
589 pem_password_callback(passbuf, 512, 0, NULL);
591 ctx->priv_key, (const unsigned char *)priv_key_file, strlen(priv_key_file) + 1,
592 (unsigned char *)passbuf, strlen(passbuf));
593 }
594 }
595 else
596 {
597 status = mbedtls_compat_pk_parse_keyfile(ctx->priv_key, priv_key_file, NULL);
598 if (MBEDTLS_ERR_PK_PASSWORD_REQUIRED == status)
599 {
600 char passbuf[512] = { 0 };
601 pem_password_callback(passbuf, 512, 0, NULL);
603 }
604 }
605 if (!mbed_ok(status))
606 {
607#ifdef ENABLE_MANAGEMENT
608 if (management && (MBEDTLS_ERR_PK_PASSWORD_MISMATCH == status))
609 {
611 }
612#endif
613 msg(M_WARN, "Cannot load private key file %s",
614 print_key_filename(priv_key_file, priv_key_inline));
615 return 1;
616 }
617
619 {
620 msg(M_WARN, "Private key does not match the certificate");
621 return 1;
622 }
623
624 return 0;
625}
626
627#if defined(__GNUC__) || defined(__clang__)
628#pragma GCC diagnostic push
629#pragma GCC diagnostic ignored "-Wconversion"
630#pragma GCC diagnostic ignored "-Wsign-compare"
631#endif
632
633#if MBEDTLS_VERSION_NUMBER < 0x04000000
652static inline int
653external_pkcs1_sign(void *ctx_voidptr, int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
654 mbedtls_md_type_t md_alg, unsigned int hashlen, const unsigned char *hash,
655 unsigned char *sig)
656{
657 struct external_context *const ctx = ctx_voidptr;
658 int rv;
659 uint8_t *to_sign = NULL;
660 size_t asn_len = 0, oid_size = 0;
661 const char *oid = NULL;
662
663 if (NULL == ctx)
664 {
665 return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
666 }
667
668 /*
669 * Support a wide range of hashes. TLSv1.1 and before only need SIG_RSA_RAW,
670 * but TLSv1.2 needs the full suite of hashes.
671 *
672 * This code has been taken from mbed TLS pkcs11_sign(), under the GPLv2.0+.
673 */
674 if (md_alg != MBEDTLS_MD_NONE)
675 {
676 const mbedtls_md_info_t *md_info = mbedtls_md_info_from_type(md_alg);
677 if (md_info == NULL)
678 {
679 return (MBEDTLS_ERR_RSA_BAD_INPUT_DATA);
680 }
681
682 if (!mbed_ok(mbedtls_oid_get_oid_by_md(md_alg, &oid, &oid_size)))
683 {
684 return (MBEDTLS_ERR_RSA_BAD_INPUT_DATA);
685 }
686
687 hashlen = mbedtls_md_get_size(md_info);
688 asn_len = 10 + oid_size;
689 }
690
691 if ((SIZE_MAX - hashlen) < asn_len || ctx->signature_length < (asn_len + hashlen))
692 {
693 return MBEDTLS_ERR_RSA_BAD_INPUT_DATA;
694 }
695
696 ALLOC_ARRAY_CLEAR(to_sign, uint8_t, asn_len + hashlen);
697 uint8_t *p = to_sign;
698 if (md_alg != MBEDTLS_MD_NONE)
699 {
700 /*
701 * DigestInfo ::= SEQUENCE {
702 * digestAlgorithm DigestAlgorithmIdentifier,
703 * digest Digest }
704 *
705 * DigestAlgorithmIdentifier ::= AlgorithmIdentifier
706 *
707 * Digest ::= OCTET STRING
708 */
709 *p++ = MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED;
710 *p++ = (unsigned char)(0x08 + oid_size + hashlen);
711 *p++ = MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED;
712 *p++ = (unsigned char)(0x04 + oid_size);
713 *p++ = MBEDTLS_ASN1_OID;
714 *p++ = oid_size & 0xFF;
715 memcpy(p, oid, oid_size);
716 p += oid_size;
717 *p++ = MBEDTLS_ASN1_NULL;
718 *p++ = 0x00;
719 *p++ = MBEDTLS_ASN1_OCTET_STRING;
720 *p++ = hashlen;
721
722 /* Double-check ASN length */
723 ASSERT(asn_len == p - to_sign);
724 }
725
726 /* Copy the hash to be signed */
727 memcpy(p, hash, hashlen);
728
729 /* Call external signature function */
730 if (!ctx->sign(ctx->sign_ctx, to_sign, asn_len + hashlen, sig, ctx->signature_length))
731 {
732 rv = MBEDTLS_ERR_RSA_PRIVATE_FAILED;
733 goto done;
734 }
735
736 rv = 0;
737
738done:
739 free(to_sign);
740 return rv;
741}
742
743static inline size_t
744external_key_len(void *vctx)
745{
746 struct external_context *const ctx = vctx;
747
748 return ctx->signature_length;
749}
750#endif /* MBEDTLS_VERSION_NUMBER < 0x04000000 */
751
752int
754 void *sign_ctx)
755{
756#if MBEDTLS_VERSION_NUMBER >= 0x04000000
757 msg(M_WARN, "tls_ctx_use_external_signing_func is not implemented for Mbed TLS 4.");
758 return 1;
759#else
760 ASSERT(NULL != ctx);
761
762 if (ctx->crt_chain == NULL)
763 {
764 msg(M_WARN, "ERROR: external key requires a certificate.");
765 return 1;
766 }
767
768 if (mbedtls_pk_get_type(&ctx->crt_chain->pk) != MBEDTLS_PK_RSA)
769 {
770 msg(M_WARN, "ERROR: external key with mbed TLS requires a "
771 "certificate with an RSA key.");
772 return 1;
773 }
774
775 ctx->external_key.signature_length = mbedtls_pk_get_len(&ctx->crt_chain->pk);
776 ctx->external_key.sign = sign_func;
778
779 ALLOC_OBJ_CLEAR(ctx->priv_key, mbedtls_pk_context);
780 if (!mbed_ok(mbedtls_pk_setup_rsa_alt(ctx->priv_key, &ctx->external_key, NULL,
781 external_pkcs1_sign, external_key_len)))
782 {
783 return 1;
784 }
785
786 return 0;
787#endif /* MBEDTLS_VERSION_NUMBER >= 0x04000000 */
788}
789
790#ifdef ENABLE_MANAGEMENT
792static bool
793management_sign_func(void *sign_ctx, const void *src, size_t src_len, void *dst, size_t dst_len)
794{
795 bool ret = false;
796 char *src_b64 = NULL;
797 char *dst_b64 = NULL;
798
799 if (!management || (openvpn_base64_encode(src, (int)src_len, &src_b64) <= 0))
800 {
801 goto cleanup;
802 }
803
804 /*
805 * We only support RSA external keys and PKCS1 signatures at the moment
806 * in mbed TLS, so the signature parameter is hardcoded to this encoding
807 */
808 if (!(dst_b64 = management_query_pk_sig(management, src_b64, "RSA_PKCS1_PADDING")))
809 {
810 goto cleanup;
811 }
812
813 if (openvpn_base64_decode(dst_b64, dst, (int)dst_len) != dst_len)
814 {
815 goto cleanup;
816 }
817
818 ret = true;
819cleanup:
820 free(src_b64);
821 free(dst_b64);
822
823 return ret;
824}
825
826int
828{
829 return tls_ctx_use_external_signing_func(ctx, management_sign_func, NULL);
830}
831
832#endif /* ifdef ENABLE_MANAGEMENT */
833
834void
835tls_ctx_load_ca(struct tls_root_ctx *ctx, const char *ca_file, bool ca_inline, const char *ca_path,
836 bool tls_server)
837{
838 if (ca_path)
839 {
840 msg(M_FATAL, "ERROR: mbed TLS cannot handle the capath directive");
841 }
842
843 if (ca_file && ca_inline)
844 {
845 if (!mbed_ok(mbedtls_x509_crt_parse(ctx->ca_chain, (const unsigned char *)ca_file,
846 strlen(ca_file) + 1)))
847 {
848 msg(M_FATAL, "Cannot load inline CA certificates");
849 }
850 }
851 else
852 {
853 /* Load CA file for verifying peer supplied certificate */
854 if (!mbed_ok(mbedtls_x509_crt_parse_file(ctx->ca_chain, ca_file)))
855 {
856 msg(M_FATAL, "Cannot load CA certificate file %s", ca_file);
857 }
858 }
859}
860
861void
862tls_ctx_load_extra_certs(struct tls_root_ctx *ctx, const char *extra_certs_file,
863 bool extra_certs_inline)
864{
865 ASSERT(NULL != ctx);
866
867 if (!ctx->crt_chain)
868 {
869 ALLOC_OBJ_CLEAR(ctx->crt_chain, mbedtls_x509_crt);
870 }
871
872 if (extra_certs_inline)
873 {
874 if (!mbed_ok(mbedtls_x509_crt_parse(ctx->crt_chain, (const unsigned char *)extra_certs_file,
875 strlen(extra_certs_file) + 1)))
876 {
877 msg(M_FATAL, "Cannot load inline extra-certs file");
878 }
879 }
880 else
881 {
882 if (!mbed_ok(mbedtls_x509_crt_parse_file(ctx->crt_chain, extra_certs_file)))
883 {
884 msg(M_FATAL, "Cannot load extra-certs file: %s", extra_certs_file);
885 }
886 }
887}
888
889/* **************************************
890 *
891 * Key-state specific functions
892 *
893 ***************************************/
894
895/*
896 * "Endless buffer"
897 */
898
899static inline void
900buf_free_entry(buffer_entry *entry)
901{
902 if (NULL != entry)
903 {
904 free(entry->data);
905 free(entry);
906 }
907}
908
909static void
910buf_free_entries(endless_buffer *buf)
911{
912 while (buf->first_block)
913 {
914 buffer_entry *cur_block = buf->first_block;
915 buf->first_block = cur_block->next_block;
916 buf_free_entry(cur_block);
917 }
918 buf->last_block = NULL;
919}
920
921static int
922endless_buf_read(endless_buffer *in, unsigned char *out, size_t out_len)
923{
924 size_t read_len = 0;
925
926 if (in->first_block == NULL)
927 {
928 return MBEDTLS_ERR_SSL_WANT_READ;
929 }
930
931 while (in->first_block != NULL && read_len < out_len)
932 {
933 int block_len = in->first_block->length - in->data_start;
934 if (block_len <= out_len - read_len)
935 {
936 buffer_entry *cur_entry = in->first_block;
937 memcpy(out + read_len, cur_entry->data + in->data_start, block_len);
938
939 read_len += block_len;
940
941 in->first_block = cur_entry->next_block;
942 in->data_start = 0;
943
944 if (in->first_block == NULL)
945 {
946 in->last_block = NULL;
947 }
948
949 buf_free_entry(cur_entry);
950 }
951 else
952 {
953 memcpy(out + read_len, in->first_block->data + in->data_start, out_len - read_len);
954 in->data_start += out_len - read_len;
955 read_len = out_len;
956 }
957 }
958
959 return read_len;
960}
961
962static int
963endless_buf_write(endless_buffer *out, const unsigned char *in, size_t len)
964{
965 buffer_entry *new_block = malloc(sizeof(buffer_entry));
966 if (NULL == new_block)
967 {
968 return MBEDTLS_ERR_NET_SEND_FAILED;
969 }
970
971 new_block->data = malloc(len);
972 if (NULL == new_block->data)
973 {
974 free(new_block);
975 return MBEDTLS_ERR_NET_SEND_FAILED;
976 }
977
978 new_block->length = len;
979 new_block->next_block = NULL;
980
981 memcpy(new_block->data, in, len);
982
983 if (NULL == out->first_block)
984 {
985 out->first_block = new_block;
986 }
987
988 if (NULL != out->last_block)
989 {
990 out->last_block->next_block = new_block;
991 }
992
993 out->last_block = new_block;
994
995 return len;
996}
997
998static int
999ssl_bio_read(void *ctx, unsigned char *out, size_t out_len)
1000{
1001 bio_ctx *my_ctx = (bio_ctx *)ctx;
1002 return endless_buf_read(&my_ctx->in, out, out_len);
1003}
1004
1005static int
1006ssl_bio_write(void *ctx, const unsigned char *in, size_t in_len)
1007{
1008 bio_ctx *my_ctx = (bio_ctx *)ctx;
1009 return endless_buf_write(&my_ctx->out, in, in_len);
1010}
1011
1012static void
1013my_debug(void *ctx, int level, const char *file, int line, const char *str)
1014{
1015 int my_loglevel = (level < 3) ? D_TLS_DEBUG_MED : D_TLS_DEBUG;
1016 msg(my_loglevel, "mbed TLS msg (%s:%d): %s", file, line, str);
1017}
1018
1019/*
1020 * Further personalise the RNG using a hash of the public key
1021 */
1022void
1023tls_ctx_personalise_random(struct tls_root_ctx *ctx)
1024{
1025#if MBEDTLS_VERSION_NUMBER < 0x04000000
1026 static char old_sha256_hash[32] = { 0 };
1027 unsigned char sha256_hash[32] = { 0 };
1028 mbedtls_ctr_drbg_context *cd_ctx = rand_ctx_get();
1029
1030 if (NULL != ctx->crt_chain)
1031 {
1032 mbedtls_x509_crt *cert = ctx->crt_chain;
1033
1034 if (!md_full("SHA256", cert->tbs.p, cert->tbs.len, sha256_hash))
1035 {
1036 msg(M_WARN, "WARNING: failed to personalise random");
1037 }
1038
1039 if (0 != memcmp(old_sha256_hash, sha256_hash, sizeof(sha256_hash)))
1040 {
1041 if (!mbed_ok(mbedtls_ctr_drbg_update(cd_ctx, sha256_hash, 32)))
1042 {
1043 msg(M_WARN, "WARNING: failed to personalise random, could not update CTR_DRBG");
1044 }
1045 memcpy(old_sha256_hash, sha256_hash, sizeof(old_sha256_hash));
1046 }
1047 }
1048#endif /* MBEDTLS_VERSION_NUMBER < 0x040000 */
1049}
1050
1051#if defined(__GNUC__) || defined(__clang__)
1052#pragma GCC diagnostic pop
1053#endif
1054
1055int
1056tls_version_max(void)
1057{
1058 /* We need mbedtls_ssl_export_keying_material() to support TLS 1.3. */
1059#if defined(MBEDTLS_SSL_PROTO_TLS1_3) && defined(MBEDTLS_SSL_KEYING_MATERIAL_EXPORT)
1060 return TLS_VER_1_3;
1061#elif defined(MBEDTLS_SSL_PROTO_TLS1_2)
1062 return TLS_VER_1_2;
1063#else
1064#error mbedtls is compiled without support for TLS 1.2 or 1.3
1065#endif
1066}
1067
1075mbedtls_ssl_protocol_version
1076tls_version_to_ssl_version(int tls_ver)
1077{
1078 switch (tls_ver)
1079 {
1080#if defined(MBEDTLS_SSL_PROTO_TLS1_2)
1081 case TLS_VER_1_2:
1082 return MBEDTLS_SSL_VERSION_TLS1_2;
1083#endif
1084
1085#if defined(MBEDTLS_SSL_PROTO_TLS1_3)
1086 case TLS_VER_1_3:
1087 return MBEDTLS_SSL_VERSION_TLS1_3;
1088#endif
1089
1090 default:
1091 msg(M_FATAL, "%s: invalid or unsupported TLS version %d", __func__, tls_ver);
1092 return MBEDTLS_SSL_VERSION_UNKNOWN;
1093 }
1094}
1095
1096void
1097backend_tls_ctx_reload_crl(struct tls_root_ctx *ctx, const char *crl_file, bool crl_inline)
1098{
1099 ASSERT(crl_file);
1100
1101 if (ctx->crl == NULL)
1102 {
1103 ALLOC_OBJ_CLEAR(ctx->crl, mbedtls_x509_crl);
1104 }
1105 mbedtls_x509_crl_free(ctx->crl);
1106
1107 if (crl_inline)
1108 {
1109 if (!mbed_ok(mbedtls_x509_crl_parse(ctx->crl, (const unsigned char *)crl_file,
1110 strlen(crl_file) + 1)))
1111 {
1112 msg(M_WARN, "CRL: cannot parse inline CRL");
1113 goto err;
1114 }
1115 }
1116 else
1117 {
1118 if (!mbed_ok(mbedtls_x509_crl_parse_file(ctx->crl, crl_file)))
1119 {
1120 msg(M_WARN, "CRL: cannot read CRL from file %s", crl_file);
1121 goto err;
1122 }
1123 }
1124 return;
1125
1126err:
1127 mbedtls_x509_crl_free(ctx->crl);
1128}
1129
1130void
1131key_state_ssl_init(struct key_state_ssl *ks_ssl, const struct tls_root_ctx *ssl_ctx, bool is_server,
1132 struct tls_session *session)
1133{
1134 ASSERT(NULL != ssl_ctx);
1135 ASSERT(ks_ssl);
1136 CLEAR(*ks_ssl);
1137
1138 /* Initialise SSL config */
1139 ALLOC_OBJ_CLEAR(ks_ssl->ssl_config, mbedtls_ssl_config);
1140 mbedtls_ssl_config_init(ks_ssl->ssl_config);
1141 mbedtls_ssl_config_defaults(ks_ssl->ssl_config, ssl_ctx->endpoint, MBEDTLS_SSL_TRANSPORT_STREAM,
1142 MBEDTLS_SSL_PRESET_DEFAULT);
1143#ifdef MBEDTLS_DEBUG_C
1144 /* We only want to have mbed TLS generate debug level logging when we would
1145 * also display it.
1146 * In fact mbed TLS 2.25.0 crashes generating debug log if Curve25591 is
1147 * selected for DH (https://github.com/ARMmbed/mbedtls/issues/4208) */
1148 if (session->opt->ssl_flags & SSLF_TLS_DEBUG_ENABLED)
1149 {
1150 mbedtls_debug_set_threshold(3);
1151 }
1152 else
1153 {
1154 mbedtls_debug_set_threshold(2);
1155 }
1156#endif
1157 mbedtls_ssl_conf_dbg(ks_ssl->ssl_config, my_debug, NULL);
1158#if MBEDTLS_VERSION_NUMBER < 0x04000000
1159 mbedtls_ssl_conf_rng(ks_ssl->ssl_config, mbedtls_ctr_drbg_random, rand_ctx_get());
1160#endif /* MBEDTLS_VERSION_NUMBER < 0x04000000 */
1161
1162 mbedtls_ssl_conf_cert_profile(ks_ssl->ssl_config, &ssl_ctx->cert_profile);
1163
1164 if (ssl_ctx->allowed_ciphers)
1165 {
1166 mbedtls_ssl_conf_ciphersuites(ks_ssl->ssl_config, ssl_ctx->allowed_ciphers);
1167 }
1168
1169 if (ssl_ctx->groups)
1170 {
1171 mbedtls_ssl_conf_groups(ks_ssl->ssl_config, ssl_ctx->groups);
1172 }
1173
1174 /* Disable TLS renegotiations if the mbedtls library supports that feature.
1175 * OpenVPN's renegotiation creates new SSL sessions and does not depend on
1176 * this feature and TLS renegotiations have been problematic in the past. */
1177#if defined(MBEDTLS_SSL_RENEGOTIATION)
1178 mbedtls_ssl_conf_renegotiation(ks_ssl->ssl_config, MBEDTLS_SSL_RENEGOTIATION_DISABLED);
1179#endif /* MBEDTLS_SSL_RENEGOTIATION */
1180
1181 /* Disable record splitting (for now). OpenVPN assumes records are sent
1182 * unfragmented, and changing that will require thorough review and
1183 * testing. Since OpenVPN is not susceptible to BEAST, we can just
1184 * disable record splitting as a quick fix. */
1185#if defined(MBEDTLS_SSL_CBC_RECORD_SPLITTING)
1186 mbedtls_ssl_conf_cbc_record_splitting(ks_ssl->ssl_config,
1187 MBEDTLS_SSL_CBC_RECORD_SPLITTING_DISABLED);
1188#endif /* MBEDTLS_SSL_CBC_RECORD_SPLITTING */
1189
1190 /* Initialise authentication information */
1191#if MBEDTLS_VERSION_NUMBER < 0x04000000
1192 if (is_server)
1193 {
1194 mbed_ok(mbedtls_ssl_conf_dh_param_ctx(ks_ssl->ssl_config, ssl_ctx->dhm_ctx));
1195 }
1196#endif
1197
1198 (void)mbed_ok(mbedtls_ssl_conf_own_cert(ks_ssl->ssl_config, ssl_ctx->crt_chain, ssl_ctx->priv_key));
1199
1200 /* Initialise SSL verification */
1201 if (session->opt->ssl_flags & SSLF_CLIENT_CERT_OPTIONAL)
1202 {
1203 mbedtls_ssl_conf_authmode(ks_ssl->ssl_config, MBEDTLS_SSL_VERIFY_OPTIONAL);
1204 }
1205 else if (!(session->opt->ssl_flags & SSLF_CLIENT_CERT_NOT_REQUIRED))
1206 {
1207 mbedtls_ssl_conf_authmode(ks_ssl->ssl_config, MBEDTLS_SSL_VERIFY_REQUIRED);
1208 }
1209 mbedtls_ssl_conf_verify(ks_ssl->ssl_config, verify_callback, session);
1210
1211 /* TODO: mbed TLS does not currently support sending the CA chain to the client */
1212 mbedtls_ssl_conf_ca_chain(ks_ssl->ssl_config, ssl_ctx->ca_chain, ssl_ctx->crl);
1213
1214 /* Initialize minimum TLS version */
1215 {
1216 const int configured_tls_version_min =
1218
1219 /* default to TLS 1.2 */
1220 mbedtls_ssl_protocol_version version = MBEDTLS_SSL_VERSION_TLS1_2;
1221
1222 if (configured_tls_version_min > TLS_VER_UNSPEC)
1223 {
1224 version = tls_version_to_ssl_version(configured_tls_version_min);
1225 }
1226
1227 mbedtls_ssl_conf_min_tls_version(ks_ssl->ssl_config, version);
1228 }
1229
1230 /* Initialize maximum TLS version */
1231 {
1232 const int configured_tls_version_max =
1234
1235 mbedtls_ssl_protocol_version version = MBEDTLS_SSL_VERSION_UNKNOWN;
1236
1237 if (configured_tls_version_max > TLS_VER_UNSPEC)
1238 {
1239 version = tls_version_to_ssl_version(configured_tls_version_max);
1240 }
1241 else
1242 {
1243 /* Default to tls_version_max(). */
1244 version = tls_version_to_ssl_version(tls_version_max());
1245 }
1246
1247 mbedtls_ssl_conf_max_tls_version(ks_ssl->ssl_config, version);
1248 }
1249
1250 /* Initialise SSL context */
1251 ALLOC_OBJ_CLEAR(ks_ssl->ctx, mbedtls_ssl_context);
1252 mbedtls_ssl_init(ks_ssl->ctx);
1253 (void)mbed_ok(mbedtls_ssl_setup(ks_ssl->ctx, ks_ssl->ssl_config));
1254 /* We do verification in our own callback depending on the
1255 * exact configuration. We do not rely on the default hostname
1256 * verification. */
1257 ASSERT(mbed_ok(mbedtls_ssl_set_hostname(ks_ssl->ctx, NULL)));
1258
1259#if !defined(MBEDTLS_SSL_KEYING_MATERIAL_EXPORT)
1260 /* Initialize the keying material exporter callback. */
1261 mbedtls_ssl_set_export_keys_cb(ks_ssl->ctx, mbedtls_ssl_export_keys_cb, session);
1262#endif
1263
1264 /* Initialise BIOs */
1266 mbedtls_ssl_set_bio(ks_ssl->ctx, ks_ssl->bio_ctx, ssl_bio_write, ssl_bio_read, NULL);
1267}
1268
1269
1270void
1272{
1273 mbedtls_ssl_send_alert_message(ks_ssl->ctx, MBEDTLS_SSL_ALERT_LEVEL_FATAL,
1274 MBEDTLS_SSL_ALERT_MSG_CLOSE_NOTIFY);
1275}
1276
1277void
1278key_state_ssl_free(struct key_state_ssl *ks_ssl)
1279{
1280 if (ks_ssl)
1281 {
1282 CLEAR(ks_ssl->tls_key_cache);
1283
1284 if (ks_ssl->ctx)
1285 {
1286 mbedtls_ssl_free(ks_ssl->ctx);
1287 free(ks_ssl->ctx);
1288 }
1289 if (ks_ssl->ssl_config)
1290 {
1291 mbedtls_ssl_config_free(ks_ssl->ssl_config);
1292 free(ks_ssl->ssl_config);
1293 }
1294 if (ks_ssl->bio_ctx)
1295 {
1296 buf_free_entries(&ks_ssl->bio_ctx->in);
1297 buf_free_entries(&ks_ssl->bio_ctx->out);
1298 free(ks_ssl->bio_ctx);
1299 }
1300 CLEAR(*ks_ssl);
1301 }
1302}
1303
1304int
1305key_state_write_plaintext(struct key_state_ssl *ks, struct buffer *buf)
1306{
1307 int retval = 0;
1308
1309 ASSERT(buf);
1310
1311 retval = key_state_write_plaintext_const(ks, BPTR(buf), BLEN(buf));
1312
1313 if (1 == retval)
1314 {
1315 memset(BPTR(buf), 0, BLEN(buf)); /* erase data just written */
1316 buf->len = 0;
1317 }
1318
1319 return retval;
1320}
1321
1322int
1323key_state_write_plaintext_const(struct key_state_ssl *ks, const uint8_t *data, int len)
1324{
1325 int retval = 0;
1326
1327 ASSERT(NULL != ks);
1328 ASSERT(len >= 0);
1329
1330 if (0 == len)
1331 {
1332 return 0;
1333 }
1334
1335 ASSERT(data);
1336
1337 retval = mbedtls_ssl_write(ks->ctx, data, len);
1338
1339 if (retval < 0)
1340 {
1341 if (MBEDTLS_ERR_SSL_WANT_WRITE == retval || MBEDTLS_ERR_SSL_WANT_READ == retval)
1342 {
1343 return 0;
1344 }
1345 mbed_log_err(D_TLS_ERRORS, retval, "TLS ERROR: write tls_write_plaintext_const error");
1346 return -1;
1347 }
1348
1349 if (retval != len)
1350 {
1351 msg(D_TLS_ERRORS, "TLS ERROR: write tls_write_plaintext_const incomplete %d/%d", retval,
1352 len);
1353 return -1;
1354 }
1355
1356 /* successful write */
1357 dmsg(D_HANDSHAKE_VERBOSE, "write tls_write_plaintext_const %d bytes", retval);
1358
1359 return 1;
1360}
1361
1362int
1363key_state_read_ciphertext(struct key_state_ssl *ks, struct buffer *buf)
1364{
1365 int retval = 0;
1366 int len = 0;
1367
1368 ASSERT(NULL != ks);
1369 ASSERT(buf);
1370 ASSERT(buf->len >= 0);
1371
1372 if (buf->len)
1373 {
1374 return 0;
1375 }
1376
1377 len = buf_forward_capacity(buf);
1378
1379 retval = endless_buf_read(&ks->bio_ctx->out, BPTR(buf), len);
1380
1381 /* Error during read, check for retry error */
1382 if (retval < 0)
1383 {
1384 if (MBEDTLS_ERR_SSL_WANT_WRITE == retval || MBEDTLS_ERR_SSL_WANT_READ == retval)
1385 {
1386 return 0;
1387 }
1388 mbed_log_err(D_TLS_ERRORS, retval, "TLS_ERROR: read tls_read_ciphertext error");
1389 buf->len = 0;
1390 return -1;
1391 }
1392 /* Nothing read, try again */
1393 if (0 == retval)
1394 {
1395 buf->len = 0;
1396 return 0;
1397 }
1398
1399 /* successful read */
1400 dmsg(D_HANDSHAKE_VERBOSE, "read tls_read_ciphertext %d bytes", retval);
1401 buf->len = retval;
1402 return 1;
1403}
1404
1405int
1406key_state_write_ciphertext(struct key_state_ssl *ks, struct buffer *buf)
1407{
1408 int retval = 0;
1409
1410 ASSERT(NULL != ks);
1411 ASSERT(buf);
1412 ASSERT(buf->len >= 0);
1413
1414 if (0 == buf->len)
1415 {
1416 return 0;
1417 }
1418
1419 retval = endless_buf_write(&ks->bio_ctx->in, BPTR(buf), buf->len);
1420
1421 if (retval < 0)
1422 {
1423 if (MBEDTLS_ERR_SSL_WANT_WRITE == retval || MBEDTLS_ERR_SSL_WANT_READ == retval)
1424 {
1425 return 0;
1426 }
1427 mbed_log_err(D_TLS_ERRORS, retval, "TLS ERROR: write tls_write_ciphertext error");
1428 return -1;
1429 }
1430
1431 if (retval != buf->len)
1432 {
1433 msg(D_TLS_ERRORS, "TLS ERROR: write tls_write_ciphertext incomplete %d/%d", retval,
1434 buf->len);
1435 return -1;
1436 }
1437
1438 /* successful write */
1439 dmsg(D_HANDSHAKE_VERBOSE, "write tls_write_ciphertext %d bytes", retval);
1440
1441 memset(BPTR(buf), 0, BLEN(buf)); /* erase data just written */
1442 buf->len = 0;
1443
1444 return 1;
1445}
1446
1447int
1448key_state_read_plaintext(struct key_state_ssl *ks, struct buffer *buf)
1449{
1450 int retval = 0;
1451 int len = 0;
1452
1453 ASSERT(NULL != ks);
1454 ASSERT(buf);
1455 ASSERT(buf->len >= 0);
1456
1457 if (buf->len)
1458 {
1459 return 0;
1460 }
1461
1462 len = buf_forward_capacity(buf);
1463
1464 retval = mbedtls_ssl_read(ks->ctx, BPTR(buf), len);
1465
1466 /* Error during read, check for retry error */
1467 if (retval < 0)
1468 {
1469 if (MBEDTLS_ERR_SSL_WANT_WRITE == retval || MBEDTLS_ERR_SSL_WANT_READ == retval
1470 || MBEDTLS_ERR_SSL_RECEIVED_NEW_SESSION_TICKET == retval)
1471 {
1472 return 0;
1473 }
1474 mbed_log_err(D_TLS_ERRORS, retval, "TLS_ERROR: read tls_read_plaintext error");
1475 buf->len = 0;
1476 return -1;
1477 }
1478 /* Nothing read, try again */
1479 if (0 == retval)
1480 {
1481 buf->len = 0;
1482 return 0;
1483 }
1484
1485 /* successful read */
1486 dmsg(D_HANDSHAKE_VERBOSE, "read tls_read_plaintext %d bytes", retval);
1487 buf->len = retval;
1488
1489 return 1;
1490}
1491
1492/* **************************************
1493 *
1494 * Information functions
1495 *
1496 * Print information for the end user.
1497 *
1498 ***************************************/
1499void
1500print_details(struct key_state_ssl *ks_ssl, const char *prefix)
1501{
1502 const mbedtls_x509_crt *cert;
1503 char s1[256];
1504 char s2[256];
1505
1506 s1[0] = s2[0] = 0;
1507 snprintf(s1, sizeof(s1), "%s %s, cipher %s", prefix, mbedtls_ssl_get_version(ks_ssl->ctx),
1508 mbedtls_ssl_get_ciphersuite(ks_ssl->ctx));
1509
1510 cert = mbedtls_ssl_get_peer_cert(ks_ssl->ctx);
1511 if (cert != NULL)
1512 {
1513 snprintf(s2, sizeof(s2), ", %u bit key", (unsigned int)mbedtls_pk_get_bitlen(&cert->pk));
1514 }
1515
1516 msg(D_HANDSHAKE, "%s%s", s1, s2);
1517}
1518
1519void
1520show_available_tls_ciphers_list(const char *cipher_list, const char *tls_cert_profile, bool tls13)
1521{
1522 if (tls13)
1523 {
1524 /* mbed TLS has no TLS 1.3 support currently */
1525 return;
1526 }
1527 struct tls_root_ctx tls_ctx;
1528 const int *ciphers = mbedtls_ssl_list_ciphersuites();
1529
1530 tls_ctx_server_new(&tls_ctx);
1531 tls_ctx_set_cert_profile(&tls_ctx, tls_cert_profile);
1532 tls_ctx_restrict_ciphers(&tls_ctx, cipher_list);
1533
1534 if (tls_ctx.allowed_ciphers)
1535 {
1536 ciphers = tls_ctx.allowed_ciphers;
1537 }
1538
1539 while (*ciphers != 0)
1540 {
1541 printf("%s\n", mbedtls_ssl_get_ciphersuite_name(*ciphers));
1542 ciphers++;
1543 }
1544 tls_ctx_free(&tls_ctx);
1545}
1546
1547void
1549{
1550#if MBEDTLS_VERSION_NUMBER < 0x04000000
1551 const mbedtls_ecp_curve_info *pcurve = mbedtls_ecp_curve_list();
1552
1553 if (NULL == pcurve)
1554 {
1555 msg(M_FATAL, "Cannot retrieve curve list from mbed TLS");
1556 }
1557
1558 /* Print curve list */
1559 printf("Available Elliptic curves, listed in order of preference:\n\n");
1560 while (MBEDTLS_ECP_DP_NONE != pcurve->grp_id)
1561 {
1562 printf("%s\n", pcurve->name);
1563 pcurve++;
1564 }
1565#else
1566 printf("Available elliptic curves:\n\n");
1567 for (size_t i = 0; i < ecp_curve_info_table_items; i++)
1568 {
1569 printf("%s\n", ecp_curve_info_table[i].name);
1570 }
1571#endif /* MBEDTLS_VERSION_NUMBER < 0x04000000 */
1572}
1573
1574const char *
1576{
1577 static char mbedtls_version[30];
1578 unsigned int pv = mbedtls_version_get_number();
1579 snprintf(mbedtls_version, sizeof(mbedtls_version), "mbed TLS %d.%d.%d", (pv >> 24) & 0xff,
1580 (pv >> 16) & 0xff, (pv >> 8) & 0xff);
1581 return mbedtls_version;
1582}
1583
1584void
1586{
1587 return; /* no external key provider in mbedTLS build */
1588}
1589
1590#endif /* defined(ENABLE_CRYPTO_MBEDTLS) */
char * string_alloc(const char *str, struct gc_arena *gc)
Definition buffer.c:653
#define BPTR(buf)
Definition buffer.h:123
#define ALLOC_ARRAY_CLEAR(dptr, type, n)
Definition buffer.h:1104
static int buf_forward_capacity(const struct buffer *buf)
Definition buffer.h:540
static void secure_memzero(void *data, size_t len)
Securely zeroise memory.
Definition buffer.h:415
#define BLEN(buf)
Definition buffer.h:126
static void gc_free(struct gc_arena *a)
Definition buffer.h:1049
#define ALLOC_OBJ_CLEAR(dptr, type)
Definition buffer.h:1088
static struct gc_arena gc_new(void)
Definition buffer.h:1041
uint64_t counter_type
Definition common.h:31
#define counter_format
Definition common.h:32
char * strsep(char **stringp, const char *delim)
const char * print_key_filename(const char *str, bool is_inline)
To be used when printing a string that may contain inline data.
Definition crypto.c:1288
bool md_full(const char *mdname, const uint8_t *src, size_t src_len, uint8_t *dst)
Calculates the message digest for the given buffer.
#define mbed_ok(errval)
Check errval and log on error.
bool mbed_log_err(unsigned int flags, int errval, const char *prefix)
Log the supplied mbed TLS error, prefixed by supplied prefix.
mbedtls_ctr_drbg_context * rand_ctx_get(void)
Returns a singleton instance of the mbed TLS random number generator.
#define D_TLS_DEBUG_LOW
Definition errlevel.h:76
#define D_TLS_DEBUG_MED
Definition errlevel.h:156
#define D_HANDSHAKE_VERBOSE
Definition errlevel.h:155
#define D_HANDSHAKE
Definition errlevel.h:71
#define D_TLS_ERRORS
Definition errlevel.h:58
#define D_TLS_DEBUG
Definition errlevel.h:164
#define KS_PRIMARY
Primary key state index.
Definition ssl_common.h:464
int key_state_read_plaintext(struct key_state_ssl *ks_ssl, struct buffer *buf)
Extract plaintext data from the TLS module.
int key_state_write_ciphertext(struct key_state_ssl *ks_ssl, struct buffer *buf)
Insert a ciphertext buffer into the TLS module.
int key_state_read_ciphertext(struct key_state_ssl *ks_ssl, struct buffer *buf)
Extract ciphertext data from the TLS module.
int key_state_write_plaintext_const(struct key_state_ssl *ks_ssl, const uint8_t *data, int len)
Insert plaintext data into the TLS module.
int key_state_write_plaintext(struct key_state_ssl *ks_ssl, struct buffer *buf)
Insert a plaintext buffer into the TLS module.
int verify_callback(void *session_obj, mbedtls_x509_crt *cert, int cert_depth, uint32_t *flags)
Verify that the remote OpenVPN peer's certificate allows setting up a VPN tunnel.
static SERVICE_STATUS status
Definition interactive.c:51
void management_auth_failure(struct management *man, const char *type, const char *reason)
Definition manage.c:3123
char * management_query_pk_sig(struct management *man, const char *b64_data, const char *algorithm)
Definition manage.c:3784
mbedtls compatibility stub.
static int mbedtls_compat_pk_parse_key(mbedtls_pk_context *ctx, const unsigned char *key, size_t keylen, const unsigned char *pwd, size_t pwdlen)
static void mbedtls_compat_psa_crypto_init(void)
static int mbedtls_compat_pk_check_pair(const mbedtls_pk_context *pub, const mbedtls_pk_context *prv)
static int mbedtls_compat_pk_parse_keyfile(mbedtls_pk_context *ctx, const char *path, const char *password)
#define CLEAR(x)
Definition basic.h:32
#define M_FATAL
Definition error.h:90
#define dmsg(flags,...)
Definition error.h:172
#define msg(flags,...)
Definition error.h:152
#define ASSERT(x)
Definition error.h:219
#define M_WARN
Definition error.h:92
PKCS #11 SSL library-specific backend.
int openvpn_base64_decode(const char *str, void *data, int size)
Definition base64.c:160
int openvpn_base64_encode(const void *data, int size, char **str)
Definition base64.c:51
static struct user_pass passbuf
Definition ssl.c:245
int pem_password_callback(char *buf, int size, int rwflag, void *u)
Callback to retrieve the user's password.
Definition ssl.c:259
void load_xkey_provider(void)
Load ovpn.xkey provider used for external key signing.
Control Channel SSL library backend module.
void tls_ctx_set_tls_groups(struct tls_root_ctx *ctx, const char *groups)
Set the (elliptic curve) group allowed for signatures and key exchange.
void tls_ctx_free(struct tls_root_ctx *ctx)
Frees the library-specific TLSv1 context.
const char * get_ssl_library_version(void)
return a pointer to a static memory area containing the name and version number of the SSL library in...
bool key_state_export_keying_material(struct tls_session *session, const char *label, size_t label_size, void *ekm, size_t ekm_size)
Keying Material Exporters [RFC 5705] allows additional keying material to be derived from existing TL...
void show_available_tls_ciphers_list(const char *cipher_list, const char *tls_cert_profile, bool tls13)
Show the TLS ciphers that are available for us to use in the library depending on the TLS version.
void tls_ctx_server_new(struct tls_root_ctx *ctx)
Initialise a library-specific TLS context for a server.
void show_available_curves(void)
Show the available elliptic curves in the crypto library.
void key_state_ssl_free(struct key_state_ssl *ks_ssl)
Free the SSL channel part of the given key state.
#define TLS_VER_1_2
int tls_ctx_load_priv_file(struct tls_root_ctx *ctx, const char *priv_key_file, bool priv_key_file_inline)
Load private key file into the given TLS context.
void key_state_ssl_shutdown(struct key_state_ssl *ks_ssl)
Sets a TLS session to be shutdown state, so the TLS library will generate a shutdown alert.
void tls_ctx_load_extra_certs(struct tls_root_ctx *ctx, const char *extra_certs_file, bool extra_certs_file_inline)
Load extra certificate authority certificates from the given file or path.
void tls_ctx_check_cert_time(const struct tls_root_ctx *ctx)
Check our certificate notBefore and notAfter fields, and warn if the cert is either not yet valid or ...
void tls_ctx_restrict_ciphers_tls13(struct tls_root_ctx *ctx, const char *ciphers)
Restrict the list of ciphers that can be used within the TLS context for TLS 1.3 and higher.
int tls_ctx_load_pkcs12(struct tls_root_ctx *ctx, const char *pkcs12_file, bool pkcs12_file_inline, bool load_ca_file)
Load PKCS #12 file for key, cert and (optionally) CA certs, and add to library-specific TLS context.
bool tls_ctx_initialised(struct tls_root_ctx *ctx)
Checks whether the given TLS context is initialised.
void key_state_ssl_init(struct key_state_ssl *ks_ssl, const struct tls_root_ctx *ssl_ctx, bool is_server, struct tls_session *session)
Initialise the SSL channel part of the given key state.
void tls_free_lib(void)
Free any global SSL library-specific data structures.
Definition ssl_openssl.c:98
void tls_ctx_load_ecdh_params(struct tls_root_ctx *ctx, const char *curve_name)
Load Elliptic Curve Parameters, and load them into the library-specific TLS context.
#define TLS_VER_1_3
#define TLS_VER_UNSPEC
void tls_init_lib(void)
Perform any static initialisation necessary by the library.
Definition ssl_openssl.c:91
void print_details(struct key_state_ssl *ks_ssl, const char *prefix)
Print a one line summary of SSL/TLS session handshake.
int tls_version_max(void)
Return the maximum TLS version (as a TLS_VER_x constant) supported by current SSL implementation.
void backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, bool crl_inline)
Reload the Certificate Revocation List for the SSL channel.
void tls_ctx_restrict_ciphers(struct tls_root_ctx *ctx, const char *ciphers)
Restrict the list of ciphers that can be used within the TLS context for TLS 1.2 and below.
void tls_ctx_load_ca(struct tls_root_ctx *ctx, const char *ca_file, bool ca_file_inline, const char *ca_path, bool tls_server)
Load certificate authority certificates from the given file or path.
void tls_ctx_set_cert_profile(struct tls_root_ctx *ctx, const char *profile)
Set the TLS certificate profile.
int tls_ctx_use_management_external_key(struct tls_root_ctx *ctx)
Tell the management interface to load the given certificate and the external private key matching the...
void tls_ctx_load_cryptoapi(struct tls_root_ctx *ctx, const char *cryptoapi_cert)
Use Windows cryptoapi for key and cert, and add to library-specific TLS context.
bool tls_ctx_set_options(struct tls_root_ctx *ctx, unsigned int ssl_flags)
Set any library specific options.
void tls_ctx_load_dh_params(struct tls_root_ctx *ctx, const char *dh_file, bool dh_file_inline)
Load Diffie Hellman Parameters, and load them into the library-specific TLS context.
void tls_ctx_client_new(struct tls_root_ctx *ctx)
Initialises a library-specific TLS context for a client.
void tls_ctx_load_cert_file(struct tls_root_ctx *ctx, const char *cert_file, bool cert_file_inline)
Load certificate file into the given TLS context.
Control Channel Common Data Structures.
#define SSLF_TLS_VERSION_MAX_SHIFT
Definition ssl_common.h:431
#define UP_TYPE_PRIVATE_KEY
Definition ssl_common.h:42
#define SSLF_CLIENT_CERT_OPTIONAL
Definition ssl_common.h:424
#define SSLF_CLIENT_CERT_NOT_REQUIRED
Definition ssl_common.h:423
#define SSLF_TLS_DEBUG_ENABLED
Definition ssl_common.h:433
#define SSLF_TLS_VERSION_MAX_MASK
Definition ssl_common.h:432
#define SSLF_TLS_VERSION_MIN_SHIFT
Definition ssl_common.h:429
#define SSLF_TLS_VERSION_MIN_MASK
Definition ssl_common.h:430
int tls_ctx_use_external_signing_func(struct tls_root_ctx *ctx, external_sign_func sign_func, void *sign_ctx)
Call the supplied signing function to create a TLS signature during the TLS handshake.
bool(* external_sign_func)(void *sign_ctx, const void *src, size_t src_size, void *dst, size_t dst_size)
External signing function prototype.
Definition ssl_mbedtls.h:77
int get_num_elements(const char *string, char delimiter)
Returns the occurrences of 'delimiter' in a string +1 This is typically used to find out the number e...
Definition ssl_util.c:294
const tls_cipher_name_pair * tls_get_cipher_name_pair(const char *cipher_name, size_t len)
Definition ssl_util.c:275
SSL utility functions.
Control Channel Verification Module mbed TLS backend.
size_t length
Definition ssl_mbedtls.h:46
uint8_t * data
Definition ssl_mbedtls.h:47
buffer_entry * next_block
Definition ssl_mbedtls.h:48
endless_buffer out
Definition ssl_mbedtls.h:61
endless_buffer in
Definition ssl_mbedtls.h:60
Definition buffer.h:1143
Wrapper structure for dynamically allocated memory.
Definition buffer.h:60
int len
Length in bytes of the actual content within the allocated memory.
Definition buffer.h:65
size_t data_start
Definition ssl_mbedtls.h:53
buffer_entry * first_block
Definition ssl_mbedtls.h:54
buffer_entry * last_block
Definition ssl_mbedtls.h:55
Context used by external_pkcs1_sign()
Definition ssl_mbedtls.h:82
external_sign_func sign
Definition ssl_mbedtls.h:84
size_t signature_length
Definition ssl_mbedtls.h:83
Garbage collection arena used to keep track of dynamically allocated memory.
Definition buffer.h:116
Definition list.h:53
bio_ctx * bio_ctx
mbedtls_ssl_config * ssl_config
mbedTLS global ssl config
mbedtls_ssl_context * ctx
mbedTLS connection context
struct tls_key_cache tls_key_cache
Get a tls_cipher_name_pair containing OpenSSL and IANA names for supplied TLS cipher name.
Definition ssl_util.h:77
const char * iana_name
Definition ssl_util.h:79
const char * openssl_name
Definition ssl_util.h:78
struct to cache TLS secrets for keying material exporter (RFC 5705).
Definition ssl_mbedtls.h:96
unsigned char master_secret[48]
Definition ssl_mbedtls.h:99
mbedtls_tls_prf_types tls_prf_type
Definition ssl_mbedtls.h:98
unsigned char client_server_random[64]
Definition ssl_mbedtls.h:97
Structure that wraps the TLS context.
mbedtls_x509_crl * crl
Certificate Revocation List.
mbedtls_x509_crt * crt_chain
Local Certificate chain.
uint16_t * groups
List of allowed groups for this connection.
mbedtls_x509_crt * ca_chain
CA chain for remote verification.
int * allowed_ciphers
List of allowed ciphers for this connection.
mbedtls_dhm_context * dhm_ctx
Diffie-Helmann-Merkle context.
mbedtls_x509_crt_profile cert_profile
Allowed certificate types.
bool initialised
True if the context has been initialised.
int endpoint
Whether or not this is a server or a client.
struct external_context external_key
External key context.
mbedtls_pk_context * priv_key
Local private key.
Security parameter state of a single session within a VPN tunnel.
Definition ssl_common.h:489
static int cleanup(void **state)
struct gc_arena gc
Definition test_ssl.c:131