1*1c60b9acSAndroid Build Coastguard Worker /* 2*1c60b9acSAndroid Build Coastguard Worker * libwebsockets - small server side websockets and web server implementation 3*1c60b9acSAndroid Build Coastguard Worker * 4*1c60b9acSAndroid Build Coastguard Worker * Copyright (C) 2010 - 2019 Andy Green <[email protected]> 5*1c60b9acSAndroid Build Coastguard Worker * 6*1c60b9acSAndroid Build Coastguard Worker * Permission is hereby granted, free of charge, to any person obtaining a copy 7*1c60b9acSAndroid Build Coastguard Worker * of this software and associated documentation files (the "Software"), to 8*1c60b9acSAndroid Build Coastguard Worker * deal in the Software without restriction, including without limitation the 9*1c60b9acSAndroid Build Coastguard Worker * rights to use, copy, modify, merge, publish, distribute, sublicense, and/or 10*1c60b9acSAndroid Build Coastguard Worker * sell copies of the Software, and to permit persons to whom the Software is 11*1c60b9acSAndroid Build Coastguard Worker * furnished to do so, subject to the following conditions: 12*1c60b9acSAndroid Build Coastguard Worker * 13*1c60b9acSAndroid Build Coastguard Worker * The above copyright notice and this permission notice shall be included in 14*1c60b9acSAndroid Build Coastguard Worker * all copies or substantial portions of the Software. 15*1c60b9acSAndroid Build Coastguard Worker * 16*1c60b9acSAndroid Build Coastguard Worker * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR 17*1c60b9acSAndroid Build Coastguard Worker * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 18*1c60b9acSAndroid Build Coastguard Worker * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE 19*1c60b9acSAndroid Build Coastguard Worker * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER 20*1c60b9acSAndroid Build Coastguard Worker * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING 21*1c60b9acSAndroid Build Coastguard Worker * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS 22*1c60b9acSAndroid Build Coastguard Worker * IN THE SOFTWARE. 23*1c60b9acSAndroid Build Coastguard Worker * 24*1c60b9acSAndroid Build Coastguard Worker * This is included from private-lib-core.h if LWS_WITH_TLS 25*1c60b9acSAndroid Build Coastguard Worker */ 26*1c60b9acSAndroid Build Coastguard Worker 27*1c60b9acSAndroid Build Coastguard Worker #if !defined(__LWS_TLS_PRIVATE_H__) 28*1c60b9acSAndroid Build Coastguard Worker #define __LWS_TLS_PRIVATE_H__ 29*1c60b9acSAndroid Build Coastguard Worker 30*1c60b9acSAndroid Build Coastguard Worker 31*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_TLS) 32*1c60b9acSAndroid Build Coastguard Worker 33*1c60b9acSAndroid Build Coastguard Worker #include "private-jit-trust.h" 34*1c60b9acSAndroid Build Coastguard Worker 35*1c60b9acSAndroid Build Coastguard Worker #if defined(USE_WOLFSSL) 36*1c60b9acSAndroid Build Coastguard Worker #if defined(USE_OLD_CYASSL) 37*1c60b9acSAndroid Build Coastguard Worker #if defined(_WIN32) 38*1c60b9acSAndroid Build Coastguard Worker #include <IDE/WIN/user_settings.h> 39*1c60b9acSAndroid Build Coastguard Worker #include <cyassl/ctaocrypt/settings.h> 40*1c60b9acSAndroid Build Coastguard Worker #else 41*1c60b9acSAndroid Build Coastguard Worker #include <cyassl/options.h> 42*1c60b9acSAndroid Build Coastguard Worker #endif 43*1c60b9acSAndroid Build Coastguard Worker #include <cyassl/openssl/ssl.h> 44*1c60b9acSAndroid Build Coastguard Worker #include <cyassl/error-ssl.h> 45*1c60b9acSAndroid Build Coastguard Worker #else 46*1c60b9acSAndroid Build Coastguard Worker #if defined(_WIN32) 47*1c60b9acSAndroid Build Coastguard Worker #include <IDE/WIN/user_settings.h> 48*1c60b9acSAndroid Build Coastguard Worker #include <wolfssl/wolfcrypt/settings.h> 49*1c60b9acSAndroid Build Coastguard Worker #else 50*1c60b9acSAndroid Build Coastguard Worker #include <wolfssl/options.h> 51*1c60b9acSAndroid Build Coastguard Worker #endif 52*1c60b9acSAndroid Build Coastguard Worker #include <wolfssl/openssl/ssl.h> 53*1c60b9acSAndroid Build Coastguard Worker #include <wolfssl/error-ssl.h> 54*1c60b9acSAndroid Build Coastguard Worker #define OPENSSL_NO_TLSEXT 55*1c60b9acSAndroid Build Coastguard Worker #endif /* not USE_OLD_CYASSL */ 56*1c60b9acSAndroid Build Coastguard Worker #else /* WOLFSSL */ 57*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_PLAT_FREERTOS) 58*1c60b9acSAndroid Build Coastguard Worker #define OPENSSL_NO_TLSEXT 59*1c60b9acSAndroid Build Coastguard Worker #if !defined(LWS_AMAZON_RTOS) 60*1c60b9acSAndroid Build Coastguard Worker /* AMAZON RTOS has its own setting via MTK_MBEDTLS_CONFIG_FILE */ 61*1c60b9acSAndroid Build Coastguard Worker #undef MBEDTLS_CONFIG_FILE 62*1c60b9acSAndroid Build Coastguard Worker #define MBEDTLS_CONFIG_FILE <mbedtls/esp_config.h> 63*1c60b9acSAndroid Build Coastguard Worker #endif 64*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/ssl.h> 65*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/aes.h> 66*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/gcm.h> 67*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/x509_crt.h> 68*1c60b9acSAndroid Build Coastguard Worker #include "ssl.h" /* wrapper !!!! */ 69*1c60b9acSAndroid Build Coastguard Worker #else /* not esp32 */ 70*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_MBEDTLS) 71*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/ssl.h> 72*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/aes.h> 73*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/gcm.h> 74*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/x509_crt.h> 75*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/x509_csr.h> 76*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/ecp.h> 77*1c60b9acSAndroid Build Coastguard Worker #include <mbedtls/ecdsa.h> 78*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_AMAZON_LINUX) 79*1c60b9acSAndroid Build Coastguard Worker #include "ssl.h" /* wrapper !!!! */ 80*1c60b9acSAndroid Build Coastguard Worker #else 81*1c60b9acSAndroid Build Coastguard Worker #include "openssl/ssl.h" /* wrapper !!!! */ 82*1c60b9acSAndroid Build Coastguard Worker #endif 83*1c60b9acSAndroid Build Coastguard Worker #else 84*1c60b9acSAndroid Build Coastguard Worker #include <openssl/ssl.h> 85*1c60b9acSAndroid Build Coastguard Worker #include <openssl/evp.h> 86*1c60b9acSAndroid Build Coastguard Worker #include <openssl/err.h> 87*1c60b9acSAndroid Build Coastguard Worker #include <openssl/md5.h> 88*1c60b9acSAndroid Build Coastguard Worker #include <openssl/sha.h> 89*1c60b9acSAndroid Build Coastguard Worker #include <openssl/rsa.h> 90*1c60b9acSAndroid Build Coastguard Worker #include <openssl/bn.h> 91*1c60b9acSAndroid Build Coastguard Worker #include <openssl/aes.h> 92*1c60b9acSAndroid Build Coastguard Worker #ifdef LWS_HAVE_OPENSSL_ECDH_H 93*1c60b9acSAndroid Build Coastguard Worker #include <openssl/ecdh.h> 94*1c60b9acSAndroid Build Coastguard Worker #endif 95*1c60b9acSAndroid Build Coastguard Worker #if !defined(LWS_HAVE_EVP_MD_CTX_free) && !defined(USE_WOLFSSL) 96*1c60b9acSAndroid Build Coastguard Worker #define EVP_MD_CTX_free EVP_MD_CTX_destroy 97*1c60b9acSAndroid Build Coastguard Worker #endif 98*1c60b9acSAndroid Build Coastguard Worker #include <openssl/x509v3.h> 99*1c60b9acSAndroid Build Coastguard Worker #endif /* not mbedtls */ 100*1c60b9acSAndroid Build Coastguard Worker #if defined(OPENSSL_VERSION_NUMBER) 101*1c60b9acSAndroid Build Coastguard Worker #if (OPENSSL_VERSION_NUMBER < 0x0009080afL) 102*1c60b9acSAndroid Build Coastguard Worker /* 103*1c60b9acSAndroid Build Coastguard Worker * later openssl defines this to negate the presence of tlsext... but it was 104*1c60b9acSAndroid Build Coastguard Worker * only introduced at 0.9.8j. Earlier versions don't know it exists so don't 105*1c60b9acSAndroid Build Coastguard Worker * define it... making it look like the feature exists... 106*1c60b9acSAndroid Build Coastguard Worker */ 107*1c60b9acSAndroid Build Coastguard Worker #define OPENSSL_NO_TLSEXT 108*1c60b9acSAndroid Build Coastguard Worker #endif 109*1c60b9acSAndroid Build Coastguard Worker #endif 110*1c60b9acSAndroid Build Coastguard Worker #endif /* not ESP32 */ 111*1c60b9acSAndroid Build Coastguard Worker #endif /* not USE_WOLFSSL */ 112*1c60b9acSAndroid Build Coastguard Worker 113*1c60b9acSAndroid Build Coastguard Worker #endif /* LWS_WITH_TLS */ 114*1c60b9acSAndroid Build Coastguard Worker 115*1c60b9acSAndroid Build Coastguard Worker enum lws_tls_extant { 116*1c60b9acSAndroid Build Coastguard Worker LWS_TLS_EXTANT_NO, 117*1c60b9acSAndroid Build Coastguard Worker LWS_TLS_EXTANT_YES, 118*1c60b9acSAndroid Build Coastguard Worker LWS_TLS_EXTANT_ALTERNATIVE 119*1c60b9acSAndroid Build Coastguard Worker }; 120*1c60b9acSAndroid Build Coastguard Worker 121*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_TLS) 122*1c60b9acSAndroid Build Coastguard Worker 123*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_TLS_SESSIONS) && defined(LWS_WITH_CLIENT) && \ 124*1c60b9acSAndroid Build Coastguard Worker (defined(LWS_WITH_MBEDTLS) || defined(OPENSSL_IS_BORINGSSL)) 125*1c60b9acSAndroid Build Coastguard Worker #define LWS_TLS_SYNTHESIZE_CB 1 126*1c60b9acSAndroid Build Coastguard Worker #endif 127*1c60b9acSAndroid Build Coastguard Worker 128*1c60b9acSAndroid Build Coastguard Worker int 129*1c60b9acSAndroid Build Coastguard Worker lws_tls_restrict_borrow(struct lws *wsi); 130*1c60b9acSAndroid Build Coastguard Worker 131*1c60b9acSAndroid Build Coastguard Worker void 132*1c60b9acSAndroid Build Coastguard Worker lws_tls_restrict_return(struct lws *wsi); 133*1c60b9acSAndroid Build Coastguard Worker 134*1c60b9acSAndroid Build Coastguard Worker void 135*1c60b9acSAndroid Build Coastguard Worker lws_tls_restrict_return_handshake(struct lws *wsi); 136*1c60b9acSAndroid Build Coastguard Worker 137*1c60b9acSAndroid Build Coastguard Worker typedef SSL lws_tls_conn; 138*1c60b9acSAndroid Build Coastguard Worker typedef SSL_CTX lws_tls_ctx; 139*1c60b9acSAndroid Build Coastguard Worker typedef BIO lws_tls_bio; 140*1c60b9acSAndroid Build Coastguard Worker typedef X509 lws_tls_x509; 141*1c60b9acSAndroid Build Coastguard Worker 142*1c60b9acSAndroid Build Coastguard Worker #if defined(LWS_WITH_NETWORK) 143*1c60b9acSAndroid Build Coastguard Worker #include "private-network.h" 144*1c60b9acSAndroid Build Coastguard Worker #endif 145*1c60b9acSAndroid Build Coastguard Worker 146*1c60b9acSAndroid Build Coastguard Worker int 147*1c60b9acSAndroid Build Coastguard Worker lws_context_init_ssl_library(struct lws_context *cx, 148*1c60b9acSAndroid Build Coastguard Worker const struct lws_context_creation_info *info); 149*1c60b9acSAndroid Build Coastguard Worker void 150*1c60b9acSAndroid Build Coastguard Worker lws_context_deinit_ssl_library(struct lws_context *context); 151*1c60b9acSAndroid Build Coastguard Worker #define LWS_SSL_ENABLED(vh) (vh && vh->tls.use_ssl) 152*1c60b9acSAndroid Build Coastguard Worker 153*1c60b9acSAndroid Build Coastguard Worker extern const struct lws_tls_ops tls_ops_openssl, tls_ops_mbedtls; 154*1c60b9acSAndroid Build Coastguard Worker 155*1c60b9acSAndroid Build Coastguard Worker struct lws_ec_valid_curves { 156*1c60b9acSAndroid Build Coastguard Worker int id; 157*1c60b9acSAndroid Build Coastguard Worker const char *jwa_name; /* list terminates with NULL jwa_name */ 158*1c60b9acSAndroid Build Coastguard Worker }; 159*1c60b9acSAndroid Build Coastguard Worker 160*1c60b9acSAndroid Build Coastguard Worker enum lws_tls_extant 161*1c60b9acSAndroid Build Coastguard Worker lws_tls_use_any_upgrade_check_extant(const char *name); 162*1c60b9acSAndroid Build Coastguard Worker extern int openssl_websocket_private_data_index; 163*1c60b9acSAndroid Build Coastguard Worker 164*1c60b9acSAndroid Build Coastguard Worker void 165*1c60b9acSAndroid Build Coastguard Worker lws_tls_err_describe_clear(void); 166*1c60b9acSAndroid Build Coastguard Worker 167*1c60b9acSAndroid Build Coastguard Worker int 168*1c60b9acSAndroid Build Coastguard Worker lws_tls_openssl_cert_info(X509 *x509, enum lws_tls_cert_info type, 169*1c60b9acSAndroid Build Coastguard Worker union lws_tls_cert_info_results *buf, size_t len); 170*1c60b9acSAndroid Build Coastguard Worker int 171*1c60b9acSAndroid Build Coastguard Worker lws_tls_check_all_cert_lifetimes(struct lws_context *context); 172*1c60b9acSAndroid Build Coastguard Worker 173*1c60b9acSAndroid Build Coastguard Worker int 174*1c60b9acSAndroid Build Coastguard Worker lws_tls_alloc_pem_to_der_file(struct lws_context *context, const char *filename, 175*1c60b9acSAndroid Build Coastguard Worker const char *inbuf, lws_filepos_t inlen, 176*1c60b9acSAndroid Build Coastguard Worker uint8_t **buf, lws_filepos_t *amount); 177*1c60b9acSAndroid Build Coastguard Worker 178*1c60b9acSAndroid Build Coastguard Worker int 179*1c60b9acSAndroid Build Coastguard Worker lws_gencrypto_bits_to_bytes(int bits); 180*1c60b9acSAndroid Build Coastguard Worker 181*1c60b9acSAndroid Build Coastguard Worker void 182*1c60b9acSAndroid Build Coastguard Worker lws_gencrypto_destroy_elements(struct lws_gencrypto_keyelem *el, int m); 183*1c60b9acSAndroid Build Coastguard Worker 184*1c60b9acSAndroid Build Coastguard Worker /* genec */ 185*1c60b9acSAndroid Build Coastguard Worker 186*1c60b9acSAndroid Build Coastguard Worker struct lws_gencrypto_keyelem; 187*1c60b9acSAndroid Build Coastguard Worker struct lws_ec_curves; 188*1c60b9acSAndroid Build Coastguard Worker 189*1c60b9acSAndroid Build Coastguard Worker extern const struct lws_ec_curves lws_ec_curves[4]; 190*1c60b9acSAndroid Build Coastguard Worker const struct lws_ec_curves * 191*1c60b9acSAndroid Build Coastguard Worker lws_genec_curve(const struct lws_ec_curves *table, const char *name); 192*1c60b9acSAndroid Build Coastguard Worker LWS_VISIBLE void 193*1c60b9acSAndroid Build Coastguard Worker lws_genec_destroy_elements(struct lws_gencrypto_keyelem *el); 194*1c60b9acSAndroid Build Coastguard Worker int 195*1c60b9acSAndroid Build Coastguard Worker lws_gencrypto_mbedtls_rngf(void *context, unsigned char *buf, size_t len); 196*1c60b9acSAndroid Build Coastguard Worker 197*1c60b9acSAndroid Build Coastguard Worker int 198*1c60b9acSAndroid Build Coastguard Worker lws_genec_confirm_curve_allowed_by_tls_id(const char *allowed, int id, 199*1c60b9acSAndroid Build Coastguard Worker struct lws_jwk *jwk); 200*1c60b9acSAndroid Build Coastguard Worker 201*1c60b9acSAndroid Build Coastguard Worker void 202*1c60b9acSAndroid Build Coastguard Worker lws_tls_reuse_session(struct lws *wsi); 203*1c60b9acSAndroid Build Coastguard Worker 204*1c60b9acSAndroid Build Coastguard Worker void 205*1c60b9acSAndroid Build Coastguard Worker lws_tls_session_cache(struct lws_vhost *vh, uint32_t ttl); 206*1c60b9acSAndroid Build Coastguard Worker 207*1c60b9acSAndroid Build Coastguard Worker int 208*1c60b9acSAndroid Build Coastguard Worker lws_tls_session_name_from_wsi(struct lws *wsi, char *buf, size_t len); 209*1c60b9acSAndroid Build Coastguard Worker 210*1c60b9acSAndroid Build Coastguard Worker /** 211*1c60b9acSAndroid Build Coastguard Worker * lws_tls_session_name_discrete() - form an lws session tag name from pieces 212*1c60b9acSAndroid Build Coastguard Worker * 213*1c60b9acSAndroid Build Coastguard Worker * \param vhname: name of the vhost 214*1c60b9acSAndroid Build Coastguard Worker * \param host: name of the host we are connecting to, like warmcat.com 215*1c60b9acSAndroid Build Coastguard Worker * \param port: the port we connected to 216*1c60b9acSAndroid Build Coastguard Worker * \param buf: the destination buffer for the tag 217*1c60b9acSAndroid Build Coastguard Worker * \param len: the max available size of the destination buffer 218*1c60b9acSAndroid Build Coastguard Worker * 219*1c60b9acSAndroid Build Coastguard Worker * Creates a tag string representing a specific host, for use with serializing 220*1c60b9acSAndroid Build Coastguard Worker * sessions made with the host. 221*1c60b9acSAndroid Build Coastguard Worker */ 222*1c60b9acSAndroid Build Coastguard Worker void 223*1c60b9acSAndroid Build Coastguard Worker lws_tls_session_tag_discrete(const char *vhname, const char *host, 224*1c60b9acSAndroid Build Coastguard Worker uint16_t port, char *buf, size_t len); 225*1c60b9acSAndroid Build Coastguard Worker 226*1c60b9acSAndroid Build Coastguard Worker /** 227*1c60b9acSAndroid Build Coastguard Worker * lws_tls_session_name_from_wsi() - form an lws session tag name from a client wsi 228*1c60b9acSAndroid Build Coastguard Worker * 229*1c60b9acSAndroid Build Coastguard Worker * \param wsi: the wsi whose vhost, host and port we should use for the tag 230*1c60b9acSAndroid Build Coastguard Worker * \param buf: the destination buffer for the tag 231*1c60b9acSAndroid Build Coastguard Worker * \param len: the max available size of the destination buffer 232*1c60b9acSAndroid Build Coastguard Worker * 233*1c60b9acSAndroid Build Coastguard Worker * Creates a tag string representing a specific host, for use with serializing 234*1c60b9acSAndroid Build Coastguard Worker * sessions made with the host. 235*1c60b9acSAndroid Build Coastguard Worker */ 236*1c60b9acSAndroid Build Coastguard Worker int 237*1c60b9acSAndroid Build Coastguard Worker lws_tls_session_tag_from_wsi(struct lws *wsi, char *buf, size_t len); 238*1c60b9acSAndroid Build Coastguard Worker 239*1c60b9acSAndroid Build Coastguard Worker #else /* ! WITH_TLS */ 240*1c60b9acSAndroid Build Coastguard Worker 241*1c60b9acSAndroid Build Coastguard Worker #define lws_tls_restrict_borrow(xxx) (0) 242*1c60b9acSAndroid Build Coastguard Worker #define lws_tls_restrict_return(xxx) 243*1c60b9acSAndroid Build Coastguard Worker 244*1c60b9acSAndroid Build Coastguard Worker #endif 245*1c60b9acSAndroid Build Coastguard Worker #endif 246