xref: /aosp_15_r20/external/libwebsockets/lib/tls/private-lib-tls.h (revision 1c60b9aca93fdbc9b5f19b2d2194c91294b22281)
1*1c60b9acSAndroid Build Coastguard Worker  /*
2*1c60b9acSAndroid Build Coastguard Worker  * libwebsockets - small server side websockets and web server implementation
3*1c60b9acSAndroid Build Coastguard Worker  *
4*1c60b9acSAndroid Build Coastguard Worker  * Copyright (C) 2010 - 2019 Andy Green <[email protected]>
5*1c60b9acSAndroid Build Coastguard Worker  *
6*1c60b9acSAndroid Build Coastguard Worker  * Permission is hereby granted, free of charge, to any person obtaining a copy
7*1c60b9acSAndroid Build Coastguard Worker  * of this software and associated documentation files (the "Software"), to
8*1c60b9acSAndroid Build Coastguard Worker  * deal in the Software without restriction, including without limitation the
9*1c60b9acSAndroid Build Coastguard Worker  * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or
10*1c60b9acSAndroid Build Coastguard Worker  * sell copies of the Software, and to permit persons to whom the Software is
11*1c60b9acSAndroid Build Coastguard Worker  * furnished to do so, subject to the following conditions:
12*1c60b9acSAndroid Build Coastguard Worker  *
13*1c60b9acSAndroid Build Coastguard Worker  * The above copyright notice and this permission notice shall be included in
14*1c60b9acSAndroid Build Coastguard Worker  * all copies or substantial portions of the Software.
15*1c60b9acSAndroid Build Coastguard Worker  *
16*1c60b9acSAndroid Build Coastguard Worker  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
17*1c60b9acSAndroid Build Coastguard Worker  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
18*1c60b9acSAndroid Build Coastguard Worker  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
19*1c60b9acSAndroid Build Coastguard Worker  * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
20*1c60b9acSAndroid Build Coastguard Worker  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
21*1c60b9acSAndroid Build Coastguard Worker  * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
22*1c60b9acSAndroid Build Coastguard Worker  * IN THE SOFTWARE.
23*1c60b9acSAndroid Build Coastguard Worker  *
24*1c60b9acSAndroid Build Coastguard Worker  *  This is included from private-lib-core.h if LWS_WITH_TLS
25*1c60b9acSAndroid Build Coastguard Worker  */
26*1c60b9acSAndroid Build Coastguard Worker 
27*1c60b9acSAndroid Build Coastguard Worker #if !defined(__LWS_TLS_PRIVATE_H__)
28*1c60b9acSAndroid Build Coastguard Worker #define __LWS_TLS_PRIVATE_H__
29*1c60b9acSAndroid Build Coastguard Worker 
30*1c60b9acSAndroid Build Coastguard Worker 
31*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_TLS)
32*1c60b9acSAndroid Build Coastguard Worker 
33*1c60b9acSAndroid Build Coastguard Worker #include "private-jit-trust.h"
34*1c60b9acSAndroid Build Coastguard Worker 
35*1c60b9acSAndroid Build Coastguard Worker #if defined(USE_WOLFSSL)
36*1c60b9acSAndroid Build Coastguard Worker  #if defined(USE_OLD_CYASSL)
37*1c60b9acSAndroid Build Coastguard Worker   #if defined(_WIN32)
38*1c60b9acSAndroid Build Coastguard Worker    #include <IDE/WIN/user_settings.h>
39*1c60b9acSAndroid Build Coastguard Worker    #include <cyassl/ctaocrypt/settings.h>
40*1c60b9acSAndroid Build Coastguard Worker   #else
41*1c60b9acSAndroid Build Coastguard Worker    #include <cyassl/options.h>
42*1c60b9acSAndroid Build Coastguard Worker   #endif
43*1c60b9acSAndroid Build Coastguard Worker   #include <cyassl/openssl/ssl.h>
44*1c60b9acSAndroid Build Coastguard Worker   #include <cyassl/error-ssl.h>
45*1c60b9acSAndroid Build Coastguard Worker  #else
46*1c60b9acSAndroid Build Coastguard Worker   #if defined(_WIN32)
47*1c60b9acSAndroid Build Coastguard Worker    #include <IDE/WIN/user_settings.h>
48*1c60b9acSAndroid Build Coastguard Worker    #include <wolfssl/wolfcrypt/settings.h>
49*1c60b9acSAndroid Build Coastguard Worker   #else
50*1c60b9acSAndroid Build Coastguard Worker    #include <wolfssl/options.h>
51*1c60b9acSAndroid Build Coastguard Worker   #endif
52*1c60b9acSAndroid Build Coastguard Worker   #include <wolfssl/openssl/ssl.h>
53*1c60b9acSAndroid Build Coastguard Worker   #include <wolfssl/error-ssl.h>
54*1c60b9acSAndroid Build Coastguard Worker   #define OPENSSL_NO_TLSEXT
55*1c60b9acSAndroid Build Coastguard Worker  #endif /* not USE_OLD_CYASSL */
56*1c60b9acSAndroid Build Coastguard Worker #else /* WOLFSSL */
57*1c60b9acSAndroid Build Coastguard Worker  #if defined(LWS_PLAT_FREERTOS)
58*1c60b9acSAndroid Build Coastguard Worker   #define OPENSSL_NO_TLSEXT
59*1c60b9acSAndroid Build Coastguard Worker   #if !defined(LWS_AMAZON_RTOS)
60*1c60b9acSAndroid Build Coastguard Worker    /* AMAZON RTOS has its own setting via MTK_MBEDTLS_CONFIG_FILE */
61*1c60b9acSAndroid Build Coastguard Worker    #undef MBEDTLS_CONFIG_FILE
62*1c60b9acSAndroid Build Coastguard Worker    #define MBEDTLS_CONFIG_FILE <mbedtls/esp_config.h>
63*1c60b9acSAndroid Build Coastguard Worker   #endif
64*1c60b9acSAndroid Build Coastguard Worker   #include <mbedtls/ssl.h>
65*1c60b9acSAndroid Build Coastguard Worker   #include <mbedtls/aes.h>
66*1c60b9acSAndroid Build Coastguard Worker   #include <mbedtls/gcm.h>
67*1c60b9acSAndroid Build Coastguard Worker   #include <mbedtls/x509_crt.h>
68*1c60b9acSAndroid Build Coastguard Worker   #include "ssl.h" /* wrapper !!!! */
69*1c60b9acSAndroid Build Coastguard Worker  #else /* not esp32 */
70*1c60b9acSAndroid Build Coastguard Worker   #if defined(LWS_WITH_MBEDTLS)
71*1c60b9acSAndroid Build Coastguard Worker    #include <mbedtls/ssl.h>
72*1c60b9acSAndroid Build Coastguard Worker    #include <mbedtls/aes.h>
73*1c60b9acSAndroid Build Coastguard Worker    #include <mbedtls/gcm.h>
74*1c60b9acSAndroid Build Coastguard Worker    #include <mbedtls/x509_crt.h>
75*1c60b9acSAndroid Build Coastguard Worker    #include <mbedtls/x509_csr.h>
76*1c60b9acSAndroid Build Coastguard Worker    #include <mbedtls/ecp.h>
77*1c60b9acSAndroid Build Coastguard Worker    #include <mbedtls/ecdsa.h>
78*1c60b9acSAndroid Build Coastguard Worker   #if defined(LWS_AMAZON_LINUX)
79*1c60b9acSAndroid Build Coastguard Worker    #include "ssl.h" /* wrapper !!!! */
80*1c60b9acSAndroid Build Coastguard Worker   #else
81*1c60b9acSAndroid Build Coastguard Worker    #include "openssl/ssl.h" /* wrapper !!!! */
82*1c60b9acSAndroid Build Coastguard Worker   #endif
83*1c60b9acSAndroid Build Coastguard Worker   #else
84*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/ssl.h>
85*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/evp.h>
86*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/err.h>
87*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/md5.h>
88*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/sha.h>
89*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/rsa.h>
90*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/bn.h>
91*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/aes.h>
92*1c60b9acSAndroid Build Coastguard Worker    #ifdef LWS_HAVE_OPENSSL_ECDH_H
93*1c60b9acSAndroid Build Coastguard Worker     #include <openssl/ecdh.h>
94*1c60b9acSAndroid Build Coastguard Worker    #endif
95*1c60b9acSAndroid Build Coastguard Worker    #if !defined(LWS_HAVE_EVP_MD_CTX_free) && !defined(USE_WOLFSSL)
96*1c60b9acSAndroid Build Coastguard Worker     #define EVP_MD_CTX_free EVP_MD_CTX_destroy
97*1c60b9acSAndroid Build Coastguard Worker    #endif
98*1c60b9acSAndroid Build Coastguard Worker    #include <openssl/x509v3.h>
99*1c60b9acSAndroid Build Coastguard Worker   #endif /* not mbedtls */
100*1c60b9acSAndroid Build Coastguard Worker   #if defined(OPENSSL_VERSION_NUMBER)
101*1c60b9acSAndroid Build Coastguard Worker    #if (OPENSSL_VERSION_NUMBER < 0x0009080afL)
102*1c60b9acSAndroid Build Coastguard Worker /*
103*1c60b9acSAndroid Build Coastguard Worker  * later openssl defines this to negate the presence of tlsext... but it was
104*1c60b9acSAndroid Build Coastguard Worker  * only introduced at 0.9.8j.  Earlier versions don't know it exists so don't
105*1c60b9acSAndroid Build Coastguard Worker  * define it... making it look like the feature exists...
106*1c60b9acSAndroid Build Coastguard Worker  */
107*1c60b9acSAndroid Build Coastguard Worker     #define OPENSSL_NO_TLSEXT
108*1c60b9acSAndroid Build Coastguard Worker    #endif
109*1c60b9acSAndroid Build Coastguard Worker   #endif
110*1c60b9acSAndroid Build Coastguard Worker  #endif /* not ESP32 */
111*1c60b9acSAndroid Build Coastguard Worker #endif /* not USE_WOLFSSL */
112*1c60b9acSAndroid Build Coastguard Worker 
113*1c60b9acSAndroid Build Coastguard Worker #endif /* LWS_WITH_TLS */
114*1c60b9acSAndroid Build Coastguard Worker 
115*1c60b9acSAndroid Build Coastguard Worker enum lws_tls_extant {
116*1c60b9acSAndroid Build Coastguard Worker 	LWS_TLS_EXTANT_NO,
117*1c60b9acSAndroid Build Coastguard Worker 	LWS_TLS_EXTANT_YES,
118*1c60b9acSAndroid Build Coastguard Worker 	LWS_TLS_EXTANT_ALTERNATIVE
119*1c60b9acSAndroid Build Coastguard Worker };
120*1c60b9acSAndroid Build Coastguard Worker 
121*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_TLS)
122*1c60b9acSAndroid Build Coastguard Worker 
123*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_TLS_SESSIONS) && defined(LWS_WITH_CLIENT) && \
124*1c60b9acSAndroid Build Coastguard Worker 	(defined(LWS_WITH_MBEDTLS) || defined(OPENSSL_IS_BORINGSSL))
125*1c60b9acSAndroid Build Coastguard Worker #define LWS_TLS_SYNTHESIZE_CB 1
126*1c60b9acSAndroid Build Coastguard Worker #endif
127*1c60b9acSAndroid Build Coastguard Worker 
128*1c60b9acSAndroid Build Coastguard Worker int
129*1c60b9acSAndroid Build Coastguard Worker lws_tls_restrict_borrow(struct lws *wsi);
130*1c60b9acSAndroid Build Coastguard Worker 
131*1c60b9acSAndroid Build Coastguard Worker void
132*1c60b9acSAndroid Build Coastguard Worker lws_tls_restrict_return(struct lws *wsi);
133*1c60b9acSAndroid Build Coastguard Worker 
134*1c60b9acSAndroid Build Coastguard Worker void
135*1c60b9acSAndroid Build Coastguard Worker lws_tls_restrict_return_handshake(struct lws *wsi);
136*1c60b9acSAndroid Build Coastguard Worker 
137*1c60b9acSAndroid Build Coastguard Worker typedef SSL lws_tls_conn;
138*1c60b9acSAndroid Build Coastguard Worker typedef SSL_CTX lws_tls_ctx;
139*1c60b9acSAndroid Build Coastguard Worker typedef BIO lws_tls_bio;
140*1c60b9acSAndroid Build Coastguard Worker typedef X509 lws_tls_x509;
141*1c60b9acSAndroid Build Coastguard Worker 
142*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_NETWORK)
143*1c60b9acSAndroid Build Coastguard Worker #include "private-network.h"
144*1c60b9acSAndroid Build Coastguard Worker #endif
145*1c60b9acSAndroid Build Coastguard Worker 
146*1c60b9acSAndroid Build Coastguard Worker int
147*1c60b9acSAndroid Build Coastguard Worker lws_context_init_ssl_library(struct lws_context *cx,
148*1c60b9acSAndroid Build Coastguard Worker 			     const struct lws_context_creation_info *info);
149*1c60b9acSAndroid Build Coastguard Worker void
150*1c60b9acSAndroid Build Coastguard Worker lws_context_deinit_ssl_library(struct lws_context *context);
151*1c60b9acSAndroid Build Coastguard Worker #define LWS_SSL_ENABLED(vh) (vh && vh->tls.use_ssl)
152*1c60b9acSAndroid Build Coastguard Worker 
153*1c60b9acSAndroid Build Coastguard Worker extern const struct lws_tls_ops tls_ops_openssl, tls_ops_mbedtls;
154*1c60b9acSAndroid Build Coastguard Worker 
155*1c60b9acSAndroid Build Coastguard Worker struct lws_ec_valid_curves {
156*1c60b9acSAndroid Build Coastguard Worker 	int id;
157*1c60b9acSAndroid Build Coastguard Worker 	const char *jwa_name; /* list terminates with NULL jwa_name */
158*1c60b9acSAndroid Build Coastguard Worker };
159*1c60b9acSAndroid Build Coastguard Worker 
160*1c60b9acSAndroid Build Coastguard Worker enum lws_tls_extant
161*1c60b9acSAndroid Build Coastguard Worker lws_tls_use_any_upgrade_check_extant(const char *name);
162*1c60b9acSAndroid Build Coastguard Worker extern int openssl_websocket_private_data_index;
163*1c60b9acSAndroid Build Coastguard Worker 
164*1c60b9acSAndroid Build Coastguard Worker void
165*1c60b9acSAndroid Build Coastguard Worker lws_tls_err_describe_clear(void);
166*1c60b9acSAndroid Build Coastguard Worker 
167*1c60b9acSAndroid Build Coastguard Worker int
168*1c60b9acSAndroid Build Coastguard Worker lws_tls_openssl_cert_info(X509 *x509, enum lws_tls_cert_info type,
169*1c60b9acSAndroid Build Coastguard Worker 			  union lws_tls_cert_info_results *buf, size_t len);
170*1c60b9acSAndroid Build Coastguard Worker int
171*1c60b9acSAndroid Build Coastguard Worker lws_tls_check_all_cert_lifetimes(struct lws_context *context);
172*1c60b9acSAndroid Build Coastguard Worker 
173*1c60b9acSAndroid Build Coastguard Worker int
174*1c60b9acSAndroid Build Coastguard Worker lws_tls_alloc_pem_to_der_file(struct lws_context *context, const char *filename,
175*1c60b9acSAndroid Build Coastguard Worker 			      const char *inbuf, lws_filepos_t inlen,
176*1c60b9acSAndroid Build Coastguard Worker 			      uint8_t **buf, lws_filepos_t *amount);
177*1c60b9acSAndroid Build Coastguard Worker 
178*1c60b9acSAndroid Build Coastguard Worker int
179*1c60b9acSAndroid Build Coastguard Worker lws_gencrypto_bits_to_bytes(int bits);
180*1c60b9acSAndroid Build Coastguard Worker 
181*1c60b9acSAndroid Build Coastguard Worker void
182*1c60b9acSAndroid Build Coastguard Worker lws_gencrypto_destroy_elements(struct lws_gencrypto_keyelem *el, int m);
183*1c60b9acSAndroid Build Coastguard Worker 
184*1c60b9acSAndroid Build Coastguard Worker /* genec */
185*1c60b9acSAndroid Build Coastguard Worker 
186*1c60b9acSAndroid Build Coastguard Worker struct lws_gencrypto_keyelem;
187*1c60b9acSAndroid Build Coastguard Worker struct lws_ec_curves;
188*1c60b9acSAndroid Build Coastguard Worker 
189*1c60b9acSAndroid Build Coastguard Worker extern const struct lws_ec_curves lws_ec_curves[4];
190*1c60b9acSAndroid Build Coastguard Worker const struct lws_ec_curves *
191*1c60b9acSAndroid Build Coastguard Worker lws_genec_curve(const struct lws_ec_curves *table, const char *name);
192*1c60b9acSAndroid Build Coastguard Worker LWS_VISIBLE void
193*1c60b9acSAndroid Build Coastguard Worker lws_genec_destroy_elements(struct lws_gencrypto_keyelem *el);
194*1c60b9acSAndroid Build Coastguard Worker int
195*1c60b9acSAndroid Build Coastguard Worker lws_gencrypto_mbedtls_rngf(void *context, unsigned char *buf, size_t len);
196*1c60b9acSAndroid Build Coastguard Worker 
197*1c60b9acSAndroid Build Coastguard Worker int
198*1c60b9acSAndroid Build Coastguard Worker lws_genec_confirm_curve_allowed_by_tls_id(const char *allowed, int id,
199*1c60b9acSAndroid Build Coastguard Worker 					  struct lws_jwk *jwk);
200*1c60b9acSAndroid Build Coastguard Worker 
201*1c60b9acSAndroid Build Coastguard Worker void
202*1c60b9acSAndroid Build Coastguard Worker lws_tls_reuse_session(struct lws *wsi);
203*1c60b9acSAndroid Build Coastguard Worker 
204*1c60b9acSAndroid Build Coastguard Worker void
205*1c60b9acSAndroid Build Coastguard Worker lws_tls_session_cache(struct lws_vhost *vh, uint32_t ttl);
206*1c60b9acSAndroid Build Coastguard Worker 
207*1c60b9acSAndroid Build Coastguard Worker int
208*1c60b9acSAndroid Build Coastguard Worker lws_tls_session_name_from_wsi(struct lws *wsi, char *buf, size_t len);
209*1c60b9acSAndroid Build Coastguard Worker 
210*1c60b9acSAndroid Build Coastguard Worker /**
211*1c60b9acSAndroid Build Coastguard Worker  * lws_tls_session_name_discrete() - form an lws session tag name from pieces
212*1c60b9acSAndroid Build Coastguard Worker  *
213*1c60b9acSAndroid Build Coastguard Worker  * \param vhname: name of the vhost
214*1c60b9acSAndroid Build Coastguard Worker  * \param host: name of the host we are connecting to, like warmcat.com
215*1c60b9acSAndroid Build Coastguard Worker  * \param port: the port we connected to
216*1c60b9acSAndroid Build Coastguard Worker  * \param buf: the destination buffer for the tag
217*1c60b9acSAndroid Build Coastguard Worker  * \param len: the max available size of the destination buffer
218*1c60b9acSAndroid Build Coastguard Worker  *
219*1c60b9acSAndroid Build Coastguard Worker  * Creates a tag string representing a specific host, for use with serializing
220*1c60b9acSAndroid Build Coastguard Worker  * sessions made with the host.
221*1c60b9acSAndroid Build Coastguard Worker  */
222*1c60b9acSAndroid Build Coastguard Worker void
223*1c60b9acSAndroid Build Coastguard Worker lws_tls_session_tag_discrete(const char *vhname, const char *host,
224*1c60b9acSAndroid Build Coastguard Worker 			     uint16_t port, char *buf, size_t len);
225*1c60b9acSAndroid Build Coastguard Worker 
226*1c60b9acSAndroid Build Coastguard Worker /**
227*1c60b9acSAndroid Build Coastguard Worker  * lws_tls_session_name_from_wsi() - form an lws session tag name from a client wsi
228*1c60b9acSAndroid Build Coastguard Worker  *
229*1c60b9acSAndroid Build Coastguard Worker  * \param wsi: the wsi whose vhost, host and port we should use for the tag
230*1c60b9acSAndroid Build Coastguard Worker  * \param buf: the destination buffer for the tag
231*1c60b9acSAndroid Build Coastguard Worker  * \param len: the max available size of the destination buffer
232*1c60b9acSAndroid Build Coastguard Worker  *
233*1c60b9acSAndroid Build Coastguard Worker  * Creates a tag string representing a specific host, for use with serializing
234*1c60b9acSAndroid Build Coastguard Worker  * sessions made with the host.
235*1c60b9acSAndroid Build Coastguard Worker  */
236*1c60b9acSAndroid Build Coastguard Worker int
237*1c60b9acSAndroid Build Coastguard Worker lws_tls_session_tag_from_wsi(struct lws *wsi, char *buf, size_t len);
238*1c60b9acSAndroid Build Coastguard Worker 
239*1c60b9acSAndroid Build Coastguard Worker #else /* ! WITH_TLS */
240*1c60b9acSAndroid Build Coastguard Worker 
241*1c60b9acSAndroid Build Coastguard Worker #define lws_tls_restrict_borrow(xxx) (0)
242*1c60b9acSAndroid Build Coastguard Worker #define lws_tls_restrict_return(xxx)
243*1c60b9acSAndroid Build Coastguard Worker 
244*1c60b9acSAndroid Build Coastguard Worker #endif
245*1c60b9acSAndroid Build Coastguard Worker #endif
246