SharkSSL™ Embedded SSL/TLS Stack
SharkSSL.h
1/*
2 * ____ _________ __ _
3 * / __ \___ ____ _/ /_ __(_)___ ___ ___ / / ____ ____ _(_)____
4 * / /_/ / _ \/ __ `/ / / / / / __ `__ \/ _ \/ / / __ \/ __ `/ / ___/
5 * / _, _/ __/ /_/ / / / / / / / / / / / __/ /___/ /_/ / /_/ / / /__
6 * /_/ |_|\___/\__,_/_/ /_/ /_/_/ /_/ /_/\___/_____/\____/\__, /_/\___/
7 * /____/
8 *
9 * SharkSSL Embedded SSL/TLS Stack
10 ****************************************************************************
11 * PROGRAM MODULE
12 *
13 * $Id: SharkSSL.h 6034 2026-09-15 14:10:47Z gianluca $
14 *
15 * COPYRIGHT: Real Time Logic LLC, 2010 - 2026
16 *
17 * This software is copyrighted by and is the sole property of Real
18 * Time Logic LLC. All rights, title, ownership, or other interests in
19 * the software remain the property of Real Time Logic LLC. This
20 * software may only be used in accordance with the terms and
21 * conditions stipulated in the corresponding license agreement under
22 * which the software has been supplied. Any unauthorized use,
23 * duplication, transmission, distribution, or disclosure of this
24 * software is expressly forbidden.
25 *
26 * This Copyright notice may not be removed or modified without prior
27 * written consent of Real Time Logic LLC.
28 *
29 * Real Time Logic LLC. reserves the right to modify this software
30 * without notice.
31 *
32 * http://www.realtimelogic.com
33 * http://www.sharkssl.com
34 ****************************************************************************
35 *
36 */
37#ifndef _SharkSsl_h
38#define _SharkSsl_h
39
40#include "TargConfig.h" /* platform dependencies */
41
42#if defined(SHARKDBG_ENABLE) && SHARKDBG_ENABLE
43#define SHARKDBG_PRINTF(x) printf x
44#else
45#define SHARKDBG_PRINTF(x)
46#endif
47
48#ifndef SHARKSSL_API
49#define SHARKSSL_API
50#else /* Barracuda */
51#define SHARKSSL_BA 1
52#include <ThreadLib.h>
53#include <BaServerLib.h>
54#endif
55
56#include "SharkSSL_cfg.h" /* SharkSSL configuration */
57#include <stddef.h> /* size_t */
58
59#include "SharkSslCrypto.h" /* Crypto API */
60
61#ifndef sharkCertSerialNumber2NetworkEndian
66typedef U64 SharkCertSerialNumber;
67#ifdef B_BIG_ENDIAN
68#define sharkCertSerialNumber2NetworkEndian(n)
69#else
70#define sharkCertSerialNumber2NetworkEndian(n) \
71 do { \
72 U64 nn=0; \
73 register U8 *t=(U8*)&nn; \
74 register U8 *f=(U8*)&n; \
75 t[7]=f[0]; \
76 t[6]=f[1]; \
77 t[5]=f[2]; \
78 t[4]=f[3]; \
79 t[3]=f[4]; \
80 t[2]=f[5]; \
81 t[1]=f[6]; \
82 t[0]=f[7]; \
83 n=nn; \
84 } while(0)
85#endif
86#endif
87
88/* Forward decl. */
89struct SharkSslCertDN;
92
114#define SHARKSSL_ALERT_LEVEL_WARNING 1
115
117#define SHARKSSL_ALERT_LEVEL_FATAL 2
118
131#define SHARKSSL_ALERT_CLOSE_NOTIFY 0
133#define SHARKSSL_ALERT_UNEXPECTED_MESSAGE 10
135#define SHARKSSL_ALERT_BAD_RECORD_MAC 20
137#define SHARKSSL_ALERT_DECRYPTION_FAILED 21
139#define SHARKSSL_ALERT_RECORD_OVERFLOW 22
141#define SHARKSSL_ALERT_DECOMPRESSION_FAILURE 30
143#define SHARKSSL_ALERT_HANDSHAKE_FAILURE 40
145#define SHARKSSL_ALERT_BAD_CERTIFICATE 42
147#define SHARKSSL_ALERT_UNSUPPORTED_CERTIFICATE 43
149#define SHARKSSL_ALERT_CERTIFICATE_REVOKED 44
151#define SHARKSSL_ALERT_CERTIFICATE_EXPIRED 45
153#define SHARKSSL_ALERT_CERTIFICATE_UNKNOWN 46
155#define SHARKSSL_ALERT_ILLEGAL_PARAMETER 47
157#define SHARKSSL_ALERT_UNKNOWN_CA 48
159#define SHARKSSL_ALERT_ACCESS_DENIED 49
161#define SHARKSSL_ALERT_DECODE_ERROR 50
163#define SHARKSSL_ALERT_DECRYPT_ERROR 51
165#define SHARKSSL_ALERT_EXPORT_RESTRICTION 60
167#define SHARKSSL_ALERT_PROTOCOL_VERSION 70
169#define SHARKSSL_ALERT_INSUFFICIENT_SECURITY 71
171#define SHARKSSL_ALERT_INTERNAL_ERROR 80
173#define SHARKSSL_ALERT_USER_CANCELED 90
175#define SHARKSSL_ALERT_NO_RENEGOTIATION 100
177#define SHARKSSL_ALERT_MISSING_EXTENSION 109
179#define SHARKSSL_ALERT_UNSUPPORTED_EXTENSION 110
181#define SHARKSSL_ALERT_UNRECOGNIZED_NAME 112
183#define SHARKSSL_ALERT_NO_APPLICATION_PROTOCOL 120 /* RFC 7301 */
184 /* end group SharkSslAlertMsg */ /* end group SharkSslAlert */
187
188
197#if SHARKSSL_TLS_1_3
199#define TLS_AES_128_GCM_SHA256 0x1301
201#define TLS_AES_256_GCM_SHA384 0x1302
203#define TLS_CHACHA20_POLY1305_SHA256 0x1303
204#endif
205#if SHARKSSL_TLS_1_2
207#define TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 0x009E
209#define TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 0x009F
211#define TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 0xC02B
213#define TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 0xC02C
215#define TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 0xC02F
217#define TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 0xC030
219#define TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 0xCCA8
221#define TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 0xCCA9
223#define TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 0xCCAA
224#endif
225 /* end group SharkSslCiphers */
227
228
236#define SHARKSSL_PROTOCOL_UNKNOWN 0x00
238#define SHARKSSL_PROTOCOL_TLS_1_2 0x33
240#define SHARKSSL_PROTOCOL_TLS_1_3 0x34
241
242/* internal use, with SHARKSSL_PROTOCOL_TLS_1_x as parameter */
243#define SHARKSSL_PROTOCOL_MAJOR(p) (p >> 4)
244#define SHARKSSL_PROTOCOL_MINOR(p) (p & 0xF)
245 /* end group SharkSslProtocol */
247
248
249#if (SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA)
250#ifndef BA_API /* standalone SharkSSL */
251#define BA_API SHARKSSL_API
252#ifdef _SHARKSSL_C_
253#define SingleListCode 1
254#endif
255#endif
256#include "SingleList.h"
257#endif
258
259
260#if SHARKSSL_ENABLE_SESSION_CACHE || SHARKSSL_NOPACK
261
270 /* end group SharkSslSessionApi */
272
273#ifndef _DOXYGEN
274typedef struct SharkSslSessionCache
275{
276 SharkSslSession *cache;
277 ThreadMutexBase cacheMutex;
278 U16 cacheSize;
279} SharkSslSessionCache;
280#endif
281#endif
282
283
295typedef enum
296{
301 /* end group SharkSslInfoAndCodes */
303
304
305#if (SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA)
313typedef U8* SharkSslKey;
314
315
321typedef const U8 *SharkSslCert;
322
323#ifdef __cplusplus
324extern "C" {
325#endif
326
331SHARKSSL_API U16 SharkSslCert_len(SharkSslCert cert);
332
335#ifdef __DOXYGEN__
337#endif
338
339#if SHARKSSL_ENABLE_CSR_CREATION
401SHARKSSL_API int
403 SharkSslKey privKey,
404 U8 hashID,
405 struct SharkSslCertDN *certDN,
406 const char *SAN,
407 struct SharkSslBitExtReq *keyUsage,
408 struct SharkSslBitExtReq *nsCertType);
409#endif
410
411#if SHARKSSL_ENABLE_CSR_SIGNING
473SHARKSSL_API int
475 const U8 *csrData,
476 int csrDataLen,
477 const SharkSslCert caCert,
478 const SharkSslKey privKey,
479 const char *validFrom,
480 const char *validTo,
481 SharkCertSerialNumber serialNumber,
482 U8 hashID);
483#endif
484
485#if SHARKSSL_ENABLE_ASN1_KEY_CREATION
492SHARKSSL_API int
494#endif
495
496
497#ifdef __cplusplus
498}
499#endif
500
501
502#if SHARKSSL_ENABLE_CA_LIST
508typedef const U8 *SharkSslCAList;
509#endif
510 /* end group SharkSslInfoAndCodes */
512#endif
513
514#ifndef _DOXYGEN
515struct SharkSsl;
516#endif
517
518
519/* Non documented API used by SharkSslSCMgr when used indirectly by
520 Lua code in the Barracuda Application Server. The code manages
521 automatic destruction of SharkSslSCMgr.
522 */
523#ifndef _DOXYGEN
524struct SharkSslIntf;
525typedef void (*SharkSslIntf_Terminate)(struct SharkSslIntf *o,
526 struct SharkSsl *ssl);
527typedef struct SharkSslIntf
528{
529 SharkSslIntf_Terminate terminate;
530} SharkSslIntf;
531#define SharkSslIntf_constructor(o,terminateFunc) (o)->terminate=terminateFunc
532#endif
533
534
557
558
559#ifdef __cplusplus
560extern "C" {
561SHARKSSL_API void *sharkssl_mallocObject(size_t size);
562SHARKSSL_API void sharkssl_freeObject(void *object);
563}
564#endif
565
566
570typedef struct
572{
573#ifdef __cplusplus
574 void *operator new(size_t s) { return sharkssl_mallocObject(s); }
575 void operator delete(void *d) { sharkssl_freeObject(d); }
576 void *operator new(size_t, void *place) { return place; }
577 void operator delete(void*, void *) { }
578
579 SharkSsl() {};
580
582 U16 cacheSize = 0,
583 U16 inBufStartSize = 4096,
584 U16 outBufSize = 4096
585 );
586
587 ~SharkSsl();
588 SharkSslCon *createCon(void);
589 U8 setCAList(SharkSslCAList list);
590 U8 setCAListEx(SharkSslCAList list, U32 caListLen);
591 U8 addCertificate(SharkSslCert cert);
592 void terminateCon(SharkSslCon *sslCon);
593#endif
594 #if (SHARKSSL_SSL_SERVER_CODE && SHARKSSL_SSL_CLIENT_CODE) || SHARKSSL_NOPACK
595 SharkSsl_Role role;
596 #endif
597 U16 outBufSize;
598 U16 inBufStartSize;
599 U16 nCon;
600 #if (SHARKSSL_ENABLE_RSA || (SHARKSSL_ENABLE_ECDSA)) || SHARKSSL_NOPACK
601 SingleList certList;
602 #if SHARKSSL_ENABLE_CA_LIST || SHARKSSL_NOPACK
603 SharkSslCAList caList;
604 #endif
605 #endif
606 #if SHARKSSL_ENABLE_SESSION_CACHE || SHARKSSL_NOPACK
607 SharkSslSessionCache sessionCache;
608 /* Reserved for use with one SharkSslSCMgr object */
609 SharkSslIntf *intf;
610 #endif
612 /* end group SharkSslInfoAndCodes */
614
621typedef enum
622{
626
630
641
655
668
682
691
703
709
713
715 /* end group SharkSslCoreApi */
717
718#if (SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA)
719
731#if SHARKSSL_ENABLE_CERT_KEYUSAGE
732#define SHARKSSL_CERT_KEYUSAGE_DIGITALSIGNATURE 0x00000001
733#define SHARKSSL_CERT_KEYUSAGE_NONREPUDIATION 0x00000002
734#define SHARKSSL_CERT_KEYUSAGE_KEYENCIPHERMENT 0x00000004
735#define SHARKSSL_CERT_KEYUSAGE_DATAENCIPHERMENT 0x00000008
736#define SHARKSSL_CERT_KEYUSAGE_KEYAGREEMENT 0x00000010
737#define SHARKSSL_CERT_KEYUSAGE_KEYCERTSIGN 0x00000020
738#define SHARKSSL_CERT_KEYUSAGE_CRLSIGN 0x00000040
739#define SHARKSSL_CERT_KEYUSAGE_ENCIPHERONLY 0x00000080
740#define SHARKSSL_CERT_KEYUSAGE_DECIPHERONLY 0x00000100
741#define SHARKSSL_CERT_KEYUSAGE_PRESENT 0x00000200
742#define SHARKSSL_CERT_KEYUSAGE_CRITICAL 0x00000400
743
744#define SHARKSSL_CERT_KEYPURPOSE_SERVERAUTH 0x00010000
745#define SHARKSSL_CERT_KEYPURPOSE_CLIENTAUTH 0x00020000
746#define SHARKSSL_CERT_KEYPURPOSE_CODESIGNING 0x00040000
747#define SHARKSSL_CERT_KEYPURPOSE_EMAILPROTECTION 0x00080000
748#define SHARKSSL_CERT_KEYPURPOSE_TIMESTAMPING 0x00100000
749#define SHARKSSL_CERT_KEYPURPOSE_OCSPSIGNING 0x00200000
750
751#define SharkSslCertInfo_KeyFlagSet(o,f) ((o)->keyUsagePurposes & f)
752
756#define SharkSslCertInfo_isKeyUsagePresent(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_PRESENT)
757#define SharkSslCertInfo_isKeyUsageCritical(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_CRITICAL)
758#define SharkSslCertInfo_KU_digitalSignature(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_DIGITALSIGNATURE)
759#define SharkSslCertInfo_KU_nonRepudiation(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_NONREPUDIATION)
760#define SharkSslCertInfo_KU_keyEncipherment(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_KEYENCIPHERMENT)
761#define SharkSslCertInfo_KU_dataEncipherment(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_DATAENCIPHERMENT)
762#define SharkSslCertInfo_KU_keyAgreement(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_KEYAGREEMENT)
763#define SharkSslCertInfo_KU_keyCertSign(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_KEYCERTSIGN)
764#define SharkSslCertInfo_KU_cRLSign(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_CRLSIGN)
765#define SharkSslCertInfo_KU_encipherOnly(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_ENCIPHERONLY)
766#define SharkSslCertInfo_KU_decipherOnly(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYUSAGE_DECIPHERONLY)
767
768#define SharkSslCertInfo_kp_serverAuth(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYPURPOSE_SERVERAUTH)
769#define SharkSslCertInfo_kp_clientAuth(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYPURPOSE_CLIENTAUTH)
770#define SharkSslCertInfo_kp_codeSigning(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYPURPOSE_CODESIGNING)
771#define SharkSslCertInfo_kp_emailProtection(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYPURPOSE_EMAILPROTECTION)
772#define SharkSslCertInfo_kp_timeStamping(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYPURPOSE_TIMESTAMPING)
773#define SharkSslCertInfo_kp_OCSPSigning(o) SharkSslCertInfo_KeyFlagSet(o, SHARKSSL_CERT_KEYPURPOSE_OCSPSIGNING)
774#endif
775
776
788typedef struct SharkSslCertDN
789{
790 const U8 *countryName;
791 const U8 *province;
792 const U8 *locality;
793 const U8 *organization;
794 const U8 *unit;
798 const U8 *commonName;
799 const U8 *emailAddress;
800
801 U8 countryNameLen;
809
812#define SharkSslCertDN_constructor(o) memset(o,0,sizeof(SharkSslCertDN))
815#define SharkSslCertDN_setCountryName(o, countryNameMA) \
816 (o)->countryName=(const U8*)countryNameMA,(o)->countryNameLen=(U8)strlen(countryNameMA)
819#define SharkSslCertDN_setProvince(o, provinceMA) \
820 (o)->province=(const U8*)provinceMA,(o)->provinceLen=(U8)strlen(provinceMA)
823#define SharkSslCertDN_setLocality(o, localityMA) \
824 (o)->locality=(const U8*)localityMA,(o)->localityLen=(U8)strlen(localityMA)
827#define SharkSslCertDN_setOrganization(o, organizationMA) \
828 (o)->organization=(const U8*)organizationMA,(o)->organizationLen=(U8)strlen(organizationMA)
831#define SharkSslCertDN_setUnit(o, unitMA) \
832 (o)->unit=(const U8*)unitMA,(o)->unitLen=(U8)strlen(unitMA)
835#define SharkSslCertDN_setCommonName(o, commonNameMA) \
836 (o)->commonName=(const U8*)commonNameMA,(o)->commonNameLen=(U8)strlen(commonNameMA)
839#define SharkSslCertDN_setEmailAddress(o, emailAddressMA) \
840 (o)->emailAddress=(const U8*)emailAddressMA,(o)->emailAddressLen=(U8)strlen(emailAddressMA)
841
842
846typedef struct SharkSslCertInfo
847{
849 U16 snLen;
850
855
860
863 U8 *sn;
864
868 U8 *timeFrom; /* declaration of U8 timeFromLen below */
869
874 U8 *timeTo; /* declaration of U8 timeToLen below */
875
881
887
900 U16 subjectAltNamesLen;
901
904
907
908 #if SHARKSSL_ENABLE_CERT_KEYUSAGE
931 U32 keyUsagePurposes;
932 #endif
933
939 /* end group SharkSslCertInfo */
941#endif
942
948#ifdef __cplusplus
949extern "C" {
950#endif
951
997SHARKSSL_API void SharkSsl_constructor(
998 SharkSsl *o,
999 SharkSsl_Role role,
1000 U16 cacheSize,
1001 U16 inBufStartSize,
1002 U16 outBufSize
1003 );
1004
1012SHARKSSL_API void SharkSsl_destructor(SharkSsl *o);
1013
1014
1035
1036
1052
1053
1054#if SHARKSSL_ENABLE_SESSION_CACHE
1055
1060SHARKSSL_API U16 SharkSsl_getCacheSize(SharkSsl *o);
1061
1062#define SharkSsl_setIntf(o, sharkSslIntf) (o)->intf=sharkSslIntf
1063#define SharkSsl_getIntf(o) (o)->intf
1064
1065#endif
1066
1067
1074#define SharkSslCon_terminate(o) SharkSsl_terminateCon(0, o)
1075
1098
1099
1134
1135
1136#if (SHARKSSL_TLS_1_3 && SHARKSSL_ENABLE_KEY_UPDATE)
1143#define SHARKSSL_KEY_UPDATE_NOT_REQUESTED 0
1144
1150#define SHARKSSL_KEY_UPDATE_REQUESTED 1
1151
1180SHARKSSL_API U8 SharkSslCon_keyUpdate(SharkSslCon *o, U8 requestUpdate);
1181#endif
1182
1183
1193
1194
1212
1213
1224
1236
1237
1256
1287U16 SharkSslCon_copyDecData(SharkSslCon *o, U8 *buf, U16 maxLen);
1288
1289
1299SHARKSSL_API U16 SharkSslCon_getDecData(SharkSslCon *o, U8 **bufPtr);
1300
1301
1317
1318
1332
1333
1355
1356
1367
1368
1381
1382
1390
1391
1395
1396
1407
1408
1419
1420
1430#define SharkSslCon_getAlertData(o) SharkSslCon_getEncData(o)
1431
1432
1442#define SharkSslCon_getAlertDataLen(o) SharkSslCon_getEncDataLen(o)
1443 /* end group SharkSslCoreApi */
1445
1446
1447#if SHARKSSL_ENABLE_INFO_API
1448
1452
1455#if (SHARKSSL_TLS_1_3 && SHARKSSL_TLS_1_2)
1457#elif SHARKSSL_TLS_1_3
1458#define SharkSslCon_getProtocol(o) (SHARKSSL_PROTOCOL_TLS_1_3)
1459#elif SHARKSSL_TLS_1_2
1460#define SharkSslCon_getProtocol(o) (SHARKSSL_PROTOCOL_TLS_1_2)
1461#else
1462#error please enable at least one of SHARKSSL_TLS_1_3, SHARKSSL_TLS_1_2
1463#endif
1464
1465#endif
1466
1467
1468#if SHARKSSL_ENABLE_SNI
1469
1470#if SHARKSSL_SSL_CLIENT_CODE
1473SHARKSSL_API U8 SharkSslCon_setSNI(SharkSslCon *o, const char *name, U16 length);
1474#endif
1475
1476#endif
1477
1478
1479#if (SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA)
1480#if (SHARKSSL_SSL_CLIENT_CODE && SHARKSSL_ENABLE_CLIENT_AUTH)
1485#endif
1486
1491
1503
1504#if SHARKSSL_ENABLE_CA_LIST
1505
1534SHARKSSL_API U8 SharkSsl_setCAListEx(SharkSsl *o, SharkSslCAList caList, U32 caListLen);
1536#define SharkSsl_setCAList(o, caList) SharkSsl_setCAListEx((o), (caList), 0)
1537
1552
1553U8 SharkSslCon_isCAListEmpty(SharkSslCon *o);
1554#else
1555
1556#define SharkSslCon_trustedCA(o) 0
1557#endif /* SHARKSSL_ENABLE_CA_LIST */
1558
1559#if (SHARKSSL_SSL_SERVER_CODE && SHARKSSL_ENABLE_RSA)
1561#define SHARKSSL_SET_FAVOR_RSA 1
1563#define SHARKSSL_CLEAR_FAVOR_RSA 0
1564
1574#endif /* SHARKSSL_SSL_SERVER_CODE */
1575#endif /* SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA */
1576
1577U8 SharkSslCon_selectProtocol(SharkSslCon *o, U8 protocol);
1578
1583#if SHARKSSL_ENABLE_SESSION_CACHE
1584
1585#if SHARKSSL_ENABLE_INFO_API
1589#endif
1590
1594
1595#if SHARKSSL_SSL_SERVER_CODE
1599#endif
1600
1601#if SHARKSSL_SSL_CLIENT_CODE
1602
1611
1612
1620
1626#endif
1627#endif
1628 /* end group SharkSslSessionApi */
1630
1631#if (SHARKSSL_SSL_SERVER_CODE && SHARKSSL_ENABLE_CLIENT_AUTH && \
1632 (SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA))
1656SHARKSSL_API U8 SharkSslCon_requestClientCertEx(SharkSslCon *o, const void *caList, U32 caListLen);
1658#define SharkSslCon_requestClientCert(o, caList) SharkSslCon_requestClientCertEx((o), (caList), 0)
1659#endif
1660
1661#if (SHARKSSL_TLS_1_3 && SHARKSSL_SSL_CLIENT_CODE && SHARKSSL_ENABLE_CA_EXTENSION && \
1662 (SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA))
1682SHARKSSL_API U8 SharkSslCon_setCertificateAuthoritiesEx(SharkSslCon *o, const void *caList, U32 caListLen);
1684#define SharkSslCon_setCertificateAuthorities(o, caList) SharkSslCon_setCertificateAuthoritiesEx((o), (caList), 0)
1685#endif
1686
1687#if SHARKSSL_ENABLE_ALPN_EXTENSION
1688#if SHARKSSL_SSL_CLIENT_CODE
1708SHARKSSL_API U8 SharkSslCon_setALPNProtocols(SharkSslCon *o, const char *protList);
1709
1723SHARKSSL_API const char *SharkSslCon_getALPNProtocol(SharkSslCon *o);
1724#endif
1725#if SHARKSSL_SSL_SERVER_CODE
1726typedef int(*ALPNFunction)(SharkSslCon*, const char*, void*);
1727SHARKSSL_API U8 SharkSslCon_setALPNFunction(
1728 SharkSslCon *o, ALPNFunction func, void *pvoid);
1729#endif
1730#endif /* SHARKSSL_ENABLE_ALPN_EXTENSION */
1731
1732#if ((SHARKSSL_SSL_SERVER_CODE || SHARKSSL_SSL_CLIENT_CODE) && \
1733 SHARKSSL_ENABLE_SELECT_CIPHERSUITE)
1762SHARKSSL_API U8 SharkSslCon_selectCiphersuite(SharkSslCon *o, U16 cipherSuite);
1763
1767#endif
1768
1769#if (SHARKSSL_SSL_SERVER_CODE && SHARKSSL_ENABLE_SECURE_RENEGOTIATION)
1790#endif
1791 /* end group SharkSslApi */
1793
1794
1795#if SHARKSSL_ENABLE_PEM_API
1803typedef enum
1804{
1807
1810
1813
1816
1819
1822
1825
1828
1831
1834
1837
1840
1843
1846
1849
1852
1855
1858
1862
1863
1893 const char *certPEM, const char *keyPEM,
1894 const char *passphrase, SharkSslCert *sharkSslCert);
1895
1896#if SHARKSSL_ENABLE_ENCRYPTED_PKCS8_SUPPORT
1914SHARKSSL_API int sharkssl_PEM_PBKDF2(
1915 U8 *dk, const char *passphrase,
1916 const char *salt, U32 saltLen,
1917 U32 iterations, U16 dkLen, U8 hashID);
1918#endif
1919 /* end group RayCryptoApi */
1921#endif
1922
1923#if SHARKSSL_ENABLE_RSA
1924
1931#define SHARKSSL_RSA_NO_PADDING 0
1932
1933
1937#define SHARKSSL_RSA_PKCS1_PADDING 1
1938
1939
1945typedef enum
1946{
1949
1952
1955
1958
1961
1964
1967
1970
1973
1976
1979
1982
1986#endif
1987 /* end group SharkSslInfoAndCodes */
1989
1990#if SHARKSSL_ENABLE_RSA_API
1991
2002typedef U8* SharkSslRSAKey;
2003
2004#if SHARKSSL_ENABLE_PEM_API
2029 const char *PEMKey, const char *passphrase);
2030
2054SHARKSSL_API SharkSslKey
2056
2057SHARKSSL_API SharkSslKey
2058sharkssl_PEM_extractPublicKey_ext(const char *certPEM, U8 *keyType);
2059#endif /* SHARKSSL_ENABLE_PEM_API */
2060
2061#if (SHARKSSL_ENABLE_PEM_API || (SHARKSSL_ENABLE_RSA && SHARKSSL_ENABLE_RSAKEY_CREATE))
2066#define _SHARKSSLRSAKEY_FREE 1
2067#endif
2068
2069#if SHARKSSL_ENABLE_RSA
2070#if SHARKSSL_ENABLE_RSAKEY_CREATE
2091SHARKSSL_API int SharkSslRSAKey_create(SharkSslRSAKey *privKey, U16 keyLength);
2092
2106#endif
2107
2112
2136 SharkSslRSAKey pubkey, const U8 *in, int len, U8 *out, int padding);
2137
2138
2157 SharkSslRSAKey privkey, const U8 *in, int len, U8 *out, int padding);
2158
2159
2177 SharkSslRSAKey privkey, U8 *sig, U16 *siglen, const U8 *hash, U8 hashID);
2178
2179
2197 SharkSslRSAKey pubkey, U8 *sig, U16 siglen, const U8 *hash, U8 hashID);
2198
2199
2200#if SHARKSSL_ENABLE_RSA_OAEP
2225SHARKSSL_API sharkssl_RSA_RetVal sharkssl_RSA_private_decrypt_OAEP(
2226 SharkSslRSAKey privkey, U8 *in, int len, U8 hashID, U8 *out, const char *label, U16 labelLen);
2227
2228
2254SHARKSSL_API sharkssl_RSA_RetVal sharkssl_RSA_public_encrypt_OAEP(
2255 SharkSslRSAKey pubkey, const U8 *in, int len, U8 hashID, U8 *out, const char *label, U16 labelLen);
2256#endif
2257
2258
2280 SharkSslRSAKey privkey, const U8 *in, int len, U8 *out, int padding);
2281
2282
2304 SharkSslRSAKey pubkey, const U8 *in, int len, U8 *out, int padding);
2305
2306#endif
2307 /* end group RSA */
2309#endif
2310
2311
2324#if SHARKSSL_USE_ECC
2325/*
2326 * NamedCurve, use as curveID parameter
2327 * SECPxxxR1 - RFC 4492 section 5.1.1
2328 * BRAINPOOLPxxxR1 - RFC 7027 section 2
2329 * CURVE25519,448 - RFC 8446 section 4.2.7
2330 */
2331#define SHARKSSL_EC_CURVE_ID_SECP256R1 23
2332#define SHARKSSL_EC_CURVE_ID_SECP384R1 24
2333#define SHARKSSL_EC_CURVE_ID_SECP521R1 25
2334#define SHARKSSL_EC_CURVE_ID_BRAINPOOLP256R1 26
2335#define SHARKSSL_EC_CURVE_ID_BRAINPOOLP384R1 27
2336#define SHARKSSL_EC_CURVE_ID_BRAINPOOLP512R1 28
2337#define SHARKSSL_EC_CURVE_ID_CURVE25519 29
2338#define SHARKSSL_EC_CURVE_ID_CURVE448 30
2339
2340#define SHARKSSL_X25519_KEY_LEN 32
2341
2342
2343#if (SHARKSSL_ECC_USE_CURVE25519 && SHARKSSL_ENABLE_X25519_API)
2361 U8 privateKey[SHARKSSL_X25519_KEY_LEN],
2362 U8 publicKey[SHARKSSL_X25519_KEY_LEN]);
2363
2364
2378 const U8 privateKey[SHARKSSL_X25519_KEY_LEN],
2379 const U8 peerPublicKey[SHARKSSL_X25519_KEY_LEN],
2380 U8 sharedSecret[SHARKSSL_X25519_KEY_LEN]);
2381#endif
2382
2383
2390typedef U8* SharkSslECCKey;
2391
2392#if SHARKSSL_ENABLE_PEM_API
2418 const char *PEMKey, const char *passphrase);
2419
2420
2421#if (SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA)
2429SHARKSSL_API U16 SharkSslKey_vectSize(const SharkSslKey key);
2430#define SharkSslCert_vectSize(c) SharkSslKey_vectSize((const SharkSslCert)c)
2431#define SharkSslCert_vectSize_keyInfo(c, t, p, a, b, x, y) SharkSslKey_vectSize_keyInfo((const SharkSslKey)c, t, p, a, b, x, y)
2432#if SHARKSSL_ENABLE_RSA
2433#define SharkSslRSAKey_vectSize(k) SharkSslKey_vectSize(k)
2434#define SharkSslRSAKey_vectSize_keyInfo(k, t, p, a, b, x, y) SharkSslKey_vectSize_keyInfo((const SharkSslKey)k, t, p, a, b, x, y)
2435#endif
2436#if SHARKSSL_ENABLE_ECDSA
2437#define SharkSslECCKey_vectSize(k) SharkSslKey_vectSize(k)
2438#define SharkSslECCKey_vectSize_keyInfo(k, t, p, a, b, x, y) SharkSslKey_vectSize_keyInfo((const SharkSslKey)k, t, p, a, b, x, y)
2439#endif
2440
2441/* return values of function SharkSslKey_vectSize_keyInfo for the parameter keyType */
2442#define SHARKSSL_KEYTYPE_RSA 0x00
2443#define SHARKSSL_KEYTYPE_EC 0x02
2444
2460SHARKSSL_API U16 SharkSslKey_vectSize_keyInfo(const SharkSslKey key, U8 *keyType, U8 *isKeyPrivate, U8 **d1, U16 *d1Len, U8 **d2, U16 *d2Len);
2461#endif
2462#endif
2463
2464#if SHARKSSL_ENABLE_ECCKEY_CREATE
2465
2466typedef int (*sharkssl_rngfunc)(void *handle, U8 *ptr, U16 len);
2467
2468
2487#define SharkSslECCKey_create(privKey, curveID) SharkSslECCKey_createEx((privKey), (curveID), 0, 0)
2488
2489
2539SHARKSSL_API int SharkSslECCKey_createEx(SharkSslECCKey *privKey, U16 curveID, void *rngHandle, sharkssl_rngfunc rngFunc);
2540#endif
2541
2542
2543#if (SHARKSSL_ENABLE_PEM_API || SHARKSSL_ENABLE_ECCKEY_CREATE)
2549#define _SHARKSSLECCKEY_FREE 1
2550#endif
2551
2552
2553/*
2554 *-----------------------------------------------------------------------------
2555 * To free up the memory allocated by SharkSslECCKey_create and
2556 * SharkSslRSAKey_create, the following macro is provided
2557 * For instance, this function could be called after saving the key to a file
2558 *-----------------------------------------------------------------------------
2559 * key: input parameter, points to a buffer allocated by either
2560 * SharkSslECCKey_create or SharkSslRSAKey_create
2561 */
2562#if defined(_SHARKSSLRSAKEY_FREE)
2563#define SharkSslKey_free SharkSslRSAKey_free
2564#elif defined (_SHARKSSLECCKEY_FREE)
2565#define SharkSslKey_free SharkSslECCKey_free
2566#else
2567#define SharkSslKey_free
2568#endif
2569#undef _SHARKSSLRSAKEY_FREE
2570#undef _SHARKSSLECCKEY_FREE
2571
2572
2578#if SHARKSSL_ENABLE_ECDSA
2582/* ECDSA API and also internal sharkssl_ECDSA_signASN1 */
2583typedef enum
2584{
2587
2590
2593
2596
2599
2602
2605
2608
2611
2615 /* end group SharkSslInfoAndCodes */
2617
2623#if SHARKSSL_ENABLE_ECDSA_API
2624#if (!SHARKSSL_ECDSA_ONLY_VERIFY)
2633SHARKSSL_API U16 sharkssl_ECDSA_siglen(SharkSslECCKey privkey);
2634
2662 SharkSslECCKey privkey, U8 *sig, U16 *siglen, const U8 *hash, U8 hashID);
2663#endif
2664
2687 SharkSslECCKey pubkey, U8 *sig, U16 siglen, const U8 *hash, U8 hashID);
2688
2689#endif /* SHARKSSL_ENABLE_ECDSA_API */
2690#endif /* SHARKSSL_ENABLE_ECDSA */
2691 /* end group ECC */
2693#endif
2694
2695
2696#if (SHARKSSL_ENABLE_CA_LIST && SHARKSSL_ENABLE_CERTSTORE_API)
2697
2703#ifndef BA_API /* standalone SharkSSL */
2704#define BA_API SHARKSSL_API
2705typedef U8 BaBool;
2706#endif
2707#include "DoubleList.h"
2708
2728typedef struct SharkSslCertStore
2729{
2730 DoubleList certList;
2731 SharkSslCAList caList;
2732 U16 elements; /* number of elements in list */
2734
2744
2748
2750#define SharkSslCertStore_release(o) SharkSslCertStore_destructor(o)
2751
2767SHARKSSL_API U16 SharkSslCertStore_add(
2768 SharkSslCertStore *o, const char *cert, U32 certlen);
2769
2781 SharkSslCertStore *o, SharkSslCAList *outList);
2782 /* end group SharkSslCertApi */
2784#endif /* SHARKSSL_ENABLE_CA_LIST && SHARKSSL_ENABLE_CERTSTORE_API */
2785
2786#if ((SHARKSSL_ENABLE_PEM_API) || (SHARKSSL_ENABLE_CERTSTORE_API))
2787SHARKSSL_API U32 sharkssl_B64Decode(
2788 U8 *outStr, U32 outStrSize, const char *b64beg, const char *b64end);
2789#endif
2790
2791
2792
2793#ifdef __cplusplus
2794}
2795
2796inline SharkSsl::SharkSsl(
2797 SharkSsl_Role role, U16 cacheSize, U16 inBufStartSize, U16 outBufSize) {
2798 SharkSsl_constructor(this, role, cacheSize, inBufStartSize, outBufSize);
2799}
2800inline SharkSsl::~SharkSsl() {
2801 SharkSsl_destructor(this);
2802}
2803inline SharkSslCon *SharkSsl::createCon(void) {
2804 return SharkSsl_createCon(this);
2805}
2806inline void SharkSsl::terminateCon(SharkSslCon *sslCon) {
2807 SharkSsl_terminateCon(this, sslCon);
2808}
2809
2810#if (SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA)
2811inline U8 SharkSsl::addCertificate(SharkSslCert cert) {
2812 return SharkSsl_addCertificate(this, cert);
2813}
2814#if SHARKSSL_ENABLE_CA_LIST
2815inline U8 SharkSsl::setCAList(SharkSslCAList list) {
2816 return SharkSsl_setCAListEx(this, list, 0);
2817}
2818inline U8 SharkSsl::setCAListEx(SharkSslCAList list, U32 caListLen) {
2819 return SharkSsl_setCAListEx(this, list, caListLen);
2820}
2821#endif /* SHARKSSL_ENABLE_CA_LIST */
2822#endif /* SHARKSSL_ENABLE_RSA || SHARKSSL_ENABLE_ECDSA */
2823
2824#endif /* __cplusplus */
2825
2826
2827#endif
SHARKSSL_API SharkSslECCKey sharkssl_PEM_to_ECCKey(const char *PEMKey, const char *passphrase)
Convert an ECC private or public key in PEM format to the SharkSslECCKey format.
SHARKSSL_API sharkssl_ECDSA_RetVal sharkssl_ECDSA_verify_hash(SharkSslECCKey pubkey, U8 *sig, U16 siglen, const U8 *hash, U8 hashID)
Verify a message using the ECC public key and a hash algorithm.
SHARKSSL_API U16 sharkssl_ECDSA_siglen(SharkSslECCKey privkey)
Returns the maximum length (in bytes) of a DER-encoded ECDSA signature generated with the private key...
SHARKSSL_API sharkssl_ECDSA_RetVal sharkssl_ECDSA_sign_hash(SharkSslECCKey privkey, U8 *sig, U16 *siglen, const U8 *hash, U8 hashID)
Generate the signature using the ECC private key and a hash.
U8 * SharkSslECCKey
SharkSslECCKey is an alias for the SharkSslCert type and is a private/public key converted by sharkss...
Definition: SharkSSL.h:2390
SHARKSSL_API SharkSslRSAKey sharkssl_PEM_to_RSAKey(const char *PEMKey, const char *passphrase)
Convert an RSA private or public key in PEM format to the SharkSslRSAKey format.
SHARKSSL_API sharkssl_RSA_RetVal sharkssl_RSA_PKCS1V1_5_verify_hash(SharkSslRSAKey pubkey, U8 *sig, U16 siglen, const U8 *hash, U8 hashID)
Verify a signature hash using a public RSA key.
SHARKSSL_API SharkSslKey sharkssl_PEM_extractPublicKey(const char *certPEM)
Extract the public key form a certificate in PEM format.
SHARKSSL_API sharkssl_RSA_RetVal sharkssl_RSA_private_encrypt(SharkSslRSAKey privkey, const U8 *in, int len, U8 *out, int padding)
Sign a message digest using the private key.
SHARKSSL_API sharkssl_RSA_RetVal sharkssl_RSA_private_decrypt(SharkSslRSAKey privkey, const U8 *in, int len, U8 *out, int padding)
Decrypt ciphertext using the private key.
SHARKSSL_API sharkssl_RSA_RetVal sharkssl_RSA_public_encrypt(SharkSslRSAKey pubkey, const U8 *in, int len, U8 *out, int padding)
Encrypt data using the public key or private key.
SHARKSSL_API sharkssl_RSA_RetVal sharkssl_RSA_PKCS1V1_5_sign_hash(SharkSslRSAKey privkey, U8 *sig, U16 *siglen, const U8 *hash, U8 hashID)
Sign a hash using a private RSA key.
SHARKSSL_API void SharkSslRSAKey_free(SharkSslRSAKey key)
Release a SharkSslRSAKey allocated by functions sharkssl_PEM_to_RSAKey and sharkssl_PEM_extractPublic...
SHARKSSL_API sharkssl_RSA_RetVal sharkssl_RSA_public_decrypt(SharkSslRSAKey pubkey, const U8 *in, int len, U8 *out, int padding)
Bring back a message digest using the public key or private key.
U8 * SharkSslRSAKey
SharkSslRSAKey is an alias for the SharkSslCert type and is a private/public key converted by sharkss...
Definition: SharkSSL.h:2002
sharkssl_PEM_RetVal
Return values from function sharkssl_PEM.
Definition: SharkSSL.h:1804
SHARKSSL_API sharkssl_PEM_RetVal sharkssl_PEM(const char *certPEM, const char *keyPEM, const char *passphrase, SharkSslCert *sharkSslCert)
Create a SharkSslCert certificate by using a certificate and key in PEM format.
SHARKSSL_API int sharkssl_X25519_sharedSecret(const U8 privateKey[SHARKSSL_X25519_KEY_LEN], const U8 peerPublicKey[SHARKSSL_X25519_KEY_LEN], U8 sharedSecret[SHARKSSL_X25519_KEY_LEN])
Calculate an X25519 shared secret.
SHARKSSL_API int sharkssl_PEM_PBKDF2(U8 *dk, const char *passphrase, const char *salt, U32 saltLen, U32 iterations, U16 dkLen, U8 hashID)
sharkssl_PEM_PBKDF2 (output, passphrase, salt, salt_len, iterations, dkLen, hashID) Derives a key fro...
SHARKSSL_API int sharkssl_X25519_createKeyPair(U8 privateKey[SHARKSSL_X25519_KEY_LEN], U8 publicKey[SHARKSSL_X25519_KEY_LEN])
Create an X25519 private/public key pair.
@ SHARKSSL_PEM_CERT_UNSUPPORTED_TYPE
CERT_UNSUPPORTED_TYPE.
Definition: SharkSSL.h:1848
@ SHARKSSL_PEM_KEY_UNSUPPORTED_ENCRYPTION_TYPE
KEY_UNSUPPORTED_ENCRYPTION_TYPE.
Definition: SharkSSL.h:1839
@ SHARKSSL_PEM_OK
OK.
Definition: SharkSSL.h:1806
@ SHARKSSL_PEM_OK_PUBLIC
OK_PUBLIC.
Definition: SharkSSL.h:1809
@ SHARKSSL_PEM_KEY_PRIVATE_KEY_REQUIRED
A PRIVATE KEY IS REQUIRED.
Definition: SharkSSL.h:1857
@ SHARKSSL_PEM_KEY_UNSUPPORTED_EXPONENT_LENGTH
KEY_UNSUPPORTED_EXPONENT_LENGTH.
Definition: SharkSSL.h:1836
@ SHARKSSL_PEM_KEY_UNSUPPORTED_FORMAT
KEY_UNSUPPORTED_FORMAT.
Definition: SharkSSL.h:1830
@ SHARKSSL_PEM_KEY_UNRECOGNIZED_FORMAT
KEY_UNRECOGNIZED_FORMAT.
Definition: SharkSSL.h:1827
@ SHARKSSL_PEM_KEY_UNSUPPORTED_VERSION
KEY_UNSUPPORTED_VERSION.
Definition: SharkSSL.h:1851
@ SHARKSSL_PEM_KEY_PASSPHRASE_REQUIRED
KEY_PASSPHRASE_REQUIRED.
Definition: SharkSSL.h:1824
@ SHARKSSL_PEM_KEY_WRONG_LENGTH
KEY_WRONG_LENGTH.
Definition: SharkSSL.h:1821
@ SHARKSSL_PEM_KEY_PARSE_ERROR
KEY_PARSE_ERROR.
Definition: SharkSSL.h:1815
@ SHARKSSL_PEM_CERT_UNRECOGNIZED_FORMAT
CERT_UNRECOGNIZED_FORMAT.
Definition: SharkSSL.h:1845
@ SHARKSSL_PEM_KEY_REQUIRED
KEY_REQUIRED.
Definition: SharkSSL.h:1854
@ SHARKSSL_PEM_ALLOCATION_ERROR
ALLOCATION_ERROR.
Definition: SharkSSL.h:1812
@ SHARKSSL_PEM_KEY_WRONG_IV
KEY_WRONG_IV.
Definition: SharkSSL.h:1818
@ SHARKSSL_PEM_INTERNAL_ERROR
INTERNAL ERROR.
Definition: SharkSSL.h:1860
@ SHARKSSL_PEM_KEY_CERT_MISMATCH
KEY_CERT_MISMATCH.
Definition: SharkSSL.h:1842
@ SHARKSSL_PEM_KEY_UNSUPPORTED_MODULUS_LENGTH
KEY_UNSUPPORTED_MODULUS_LENGTH.
Definition: SharkSSL.h:1833
U8 SharkSslCon_favorRSA(SharkSslCon *o, U8 flag)
Configures TLS 1.2 cipher-suite selection to favor RSA-authenticated suites when both RSA and ECDSA c...
SHARKSSL_API U16 SharkSsl_getCacheSize(SharkSsl *o)
Returns the SharkSsl session cache size.
SharkSslCon * SharkSsl_createCon(SharkSsl *o)
Create a SharkSslCon object.
SHARKSSL_API U8 SharkSslCon_setSNI(SharkSslCon *o, const char *name, U16 length)
set Server Name Indication for TLS client connections
SHARKSSL_API U8 SharkSslCon_trustedCA(SharkSslCon *o)
Returns TRUE if the certificate is valid and is signed with a root certificate trusted by SharkSSL.
SHARKSSL_API U8 SharkSslCon_setCertificateAuthoritiesEx(SharkSslCon *o, const void *caList, U32 caListLen)
Configure the TLS 1.3 Certificate Authorities extension specified in RFC 9846, Section 4....
SHARKSSL_API void SharkSsl_destructor(SharkSsl *o)
Close the SharkSsl object.
SHARKSSL_API U8 SharkSslCon_clearCiphersuiteSelection(SharkSslCon *o)
Clears the selection, thus enabling all ciphers.
SHARKSSL_API U8 SharkSslCon_getProtocol(SharkSslCon *o)
Returns the active session's protocol version.
SHARKSSL_API U8 SharkSslCon_setALPNProtocols(SharkSslCon *o, const char *protList)
This function is used by client solutions to specify a list of application layer protocols according ...
U8 SharkSslCon_certificateRequested(SharkSslCon *o)
Returns TRUE if the server requested a certificate from the client to verify that the client's identi...
SHARKSSL_API U8 SharkSsl_addCertificate(SharkSsl *o, SharkSslCert cert)
Add a certificate to the SharkSsl object.
SHARKSSL_API U8 SharkSslCon_requestClientCertEx(SharkSslCon *o, const void *caList, U32 caListLen)
Request client-certificate authentication.
SHARKSSL_API U8 SharkSslCon_selectCiphersuite(SharkSslCon *o, U16 cipherSuite)
This function enables you to limit the number of ciphers at runtime.
void SharkSsl_terminateCon(const SharkSsl *o, SharkSslCon *con)
Terminate a SharkSslCon object created by function SharkSsl_createCon.
SHARKSSL_API SharkSslCertInfo * SharkSslCon_getCertInfo(SharkSslCon *o)
Returns the peer's certificate if the handshaking has completed.
SHARKSSL_API U8 SharkSsl_setCAListEx(SharkSsl *o, SharkSslCAList caList, U32 caListLen)
Set a Certificate Authority (CA) list so the SharkSSL object can perform certificate validation on th...
SHARKSSL_API U8 SharkSslCon_renegotiate(SharkSslCon *o)
This function enables you to renegotiate an already established SSL/TLS connection.
SHARKSSL_API U16 SharkSslCon_getCiphersuite(SharkSslCon *o)
Returns the active session's chiper suite.
SHARKSSL_API const char * SharkSslCon_getALPNProtocol(SharkSslCon *o)
This function is used by client solutions to return the application layer protocol selected by the se...
SHARKSSL_API void SharkSsl_constructor(SharkSsl *o, SharkSsl_Role role, U16 cacheSize, U16 inBufStartSize, U16 outBufSize)
A SharkSsl object is the coordinator for managing SharkSslCon objects.
SHARKSSL_API int SharkSslECCKey_createEx(SharkSslECCKey *privKey, U16 curveID, void *rngHandle, sharkssl_rngfunc rngFunc)
Creates an ECC key using the SharkSSL library.
SHARKSSL_API int SharkSslRSAKey_create(SharkSslRSAKey *privKey, U16 keyLength)
RSA key creation.
SHARKSSL_API U16 SharkSslKey_vectSize_keyInfo(const SharkSslKey key, U8 *keyType, U8 *isKeyPrivate, U8 **d1, U16 *d1Len, U8 **d2, U16 *d2Len)
Returns the private or public key's "vector size" in bytes.
SHARKSSL_API int SharkSslASN1Create_CSR(struct SharkSslASN1Create *o, SharkSslKey privKey, U8 hashID, struct SharkSslCertDN *certDN, const char *SAN, struct SharkSslBitExtReq *keyUsage, struct SharkSslBitExtReq *nsCertType)
CSR creation (all parameters are input parameters)
SHARKSSL_API void SharkSslCertStore_constructor(SharkSslCertStore *o)
Initialize a SharkSslCertStore object.
SHARKSSL_API int SharkSslCert_signCSR(SharkSslCert *signedCSR, const U8 *csrData, int csrDataLen, const SharkSslCert caCert, const SharkSslKey privKey, const char *validFrom, const char *validTo, SharkCertSerialNumber serialNumber, U8 hashID)
CSR signing (if not specified, parameters are input parameters)
SHARKSSL_API U16 SharkSslRSAKey_size(SharkSslRSAKey key)
Returns the private or public key's modulus size in bytes.
SHARKSSL_API void SharkSslECCKey_free(SharkSslECCKey key)
Release a SharkSslECCKey allocated by functions sharkssl_PEM_to_ECCKey or SharkSslECCKey_create.
SHARKSSL_API U16 SharkSslCertStore_add(SharkSslCertStore *o, const char *cert, U32 certlen)
Add one or more certificates to the CA store.
SHARKSSL_API U8 SharkSslCertStore_assemble(SharkSslCertStore *o, SharkSslCAList *outList)
Assemble all certificates added by calling SharkSslCertStore_add.
struct SharkSslCertStore SharkSslCertStore
SharkSslCertStore is a container object used when assembling a SharkSslCAList.
SHARKSSL_API void SharkSslCertStore_destructor(SharkSslCertStore *o)
Cleanup all memory used by the SharkSslCAList object.
SHARKSSL_API U16 SharkSslCert_len(SharkSslCert cert)
Get certificate length.
SHARKSSL_API U16 SharkSslKey_vectSize(const SharkSslKey key)
Returns the private or public key's "vector size" in bytes.
SHARKSSL_API U8 * SharkSslRSAKey_getPublic(SharkSslRSAKey privKey)
RSA public key extraction from a private key.
struct SharkSslCertInfo SharkSslCertInfo
The peer's certificate information returned by SharkSslCon_getCertInfo.
struct SharkSslCertDN SharkSslCertDN
Certificate KeyUsage and ExtendedKeyUsage flags and relative pseudofunctions.
U8 * SharkSslCon_getEncData(SharkSslCon *o)
This function is used in conjunction with state SharkSslCon_Encrypted returned by function SharkSslCo...
U16 SharkSslCon_getHandshakeDataLen(SharkSslCon *o)
This function is used in conjunction with state SharkSslCon_Handshake returned by function SharkSslCo...
U16 SharkSslCon_getEncDataLen(SharkSslCon *o)
This function is used in conjunction with state SharkSslCon_Encrypted returned by function SharkSslCo...
U16 SharkSslCon_getBufLen(SharkSslCon *o)
Returns the number of bytes currently available at the pointer returned by SharkSslCon_getBuf.
SHARKSSL_API U8 SharkSslCon_keyUpdate(SharkSslCon *o, U8 requestUpdate)
Creates a TLS 1.3 KeyUpdate message and advances the local write keys.
SharkSslCon_RetVal
The SharkSslCon_decrypt and SharkSslCon_encrypt return values.
Definition: SharkSSL.h:622
SharkSslCon_RetVal SharkSslCon_decrypt(SharkSslCon *o, U16 readLen)
Decrypt the received data copied into the SharkSslCon receive buffer (the buffer returned by SharkSsl...
U16 SharkSslCon_getEncBufSize(SharkSslCon *o)
Returns the length of the buffer returned by SharkSslCon_getEncBufPtr.
U8 SharkSslCon_encryptMore(SharkSslCon *o)
This function is used in conjunction with state SharkSslCon_Encrypted returned by function SharkSslCo...
U8 SharkSslCon_decryptMore(SharkSslCon *o)
This function is used in conjunction with state SharkSslCon_Decrypted returned by function SharkSslCo...
U8 * SharkSslCon_getBuf(SharkSslCon *o)
Returns a pointer to the SharkSslCon input/receive buffer.
SHARKSSL_API U16 SharkSslCon_getDecData(SharkSslCon *o, U8 **bufPtr)
Get a pointer to the decoded data.
U8 SharkSslCon_getAlertLevel(SharkSslCon *o)
This function is used in conjunction with state SharkSslCon_AlertSend returned by function SharkSslCo...
U16 SharkSslCon_copyDecData(SharkSslCon *o, U8 *buf, U16 maxLen)
Copy decoded data to 'buf'.
U8 * SharkSslCon_getEncBufPtr(SharkSslCon *o)
This function is used in conjunction with SharkSslCon_encrypt when using the zero copy send API.
U16 SharkSslCon_setHandshakeDataSent(SharkSslCon *o, U16 length)
This function is used in conjunction with SharkSslCon_getHandshakeData.
U8 SharkSslCon_getAlertDescription(SharkSslCon *o)
This function is used in conjunction with state SharkSslCon_AlertSend returned by function SharkSslCo...
U8 SharkSslCon_isHandshakeComplete(SharkSslCon *o)
Returns the following values:
U8 * SharkSslCon_getHandshakeData(SharkSslCon *o)
This function is used in conjunction with state SharkSslCon_Handshake returned by function SharkSslCo...
SharkSslCon_RetVal SharkSslCon_encrypt(SharkSslCon *o, U8 *buf, U16 maxLen)
Encrypt the data provided by parameter 'buf' or encrypt data in the SharkSslCon send buffer.
@ SharkSslCon_Encrypted
SharkSSL has successfully decrypted a chunk of data.
Definition: SharkSSL.h:702
@ SharkSslCon_Decrypted
Returned when a block of received data has been successfully decrypted.
Definition: SharkSSL.h:640
@ SharkSslCon_AlertSend
Returned when an SSL/TLS alert message must be sent to the peer side.
Definition: SharkSSL.h:681
@ SharkSslCon_AllocationError
The memory pool is too small.
Definition: SharkSSL.h:629
@ SharkSslCon_Error
Indicates general errors, including configuration errors.
Definition: SharkSSL.h:625
@ SharkSslCon_CertificateError
Unrecognized format of a provided certificate.
Definition: SharkSSL.h:712
@ SharkSslCon_AlertRecv
SharkSSL received an SSL/TLS alert message from the peer, which means that the peer either failed to ...
Definition: SharkSSL.h:690
@ SharkSslCon_HandshakeNotComplete
An error condition returned by function SharkSslCon_encrypt if the SSL handshake is not completed.
Definition: SharkSSL.h:708
@ SharkSslCon_Handshake
Returned when an SSL/TLS handshake message has been received or is to be sent.
Definition: SharkSSL.h:654
@ SharkSslCon_NeedMoreData
Returned when SharkSSL holds an incomplete SSL/TLS record or when the connection is initially establi...
Definition: SharkSSL.h:667
U32 baGetUnixTime(void)
Platform dependent function returning seconds since Jan 1 1970.
struct SharkSsl SharkSsl
A SharkSsl object is the coordinator for managing SharkSslCon objects (See SharkSsl_constructor for d...
const U8 * SharkSslCert
The SharkSSL Certificate is in a binary format optimized for speed and size.
Definition: SharkSSL.h:321
SHARKSSL_API int SharkSslASN1Create_key(struct SharkSslASN1Create *o, const SharkSslKey key)
Convert a SharkSslKey to ASN.1 representation.
const U8 * SharkSslCAList
The SharkSSL Certificate Authority (CA) List is in a binary format optimized for speed and size.
Definition: SharkSSL.h:508
struct SharkSslCon SharkSslCon
SharkSslCon is an opaque handle returned by function SharkSsl_createCon.
Definition: SharkSSL.h:556
SharkSsl_Role
Select one of client or server mode when creating a SharkSsl object.
Definition: SharkSSL.h:296
sharkssl_ECDSA_RetVal
Return values from functions sharkssl_ECDSA_sign_hash, sharkssl_ECDSA_verify_hash.
Definition: SharkSSL.h:2584
sharkssl_RSA_RetVal
Return values from functions sharkssl_RSA_public_encrypt, sharkssl_RSA_private_decrypt,...
Definition: SharkSSL.h:1946
U8 * SharkSslKey
The SharkSslKey type.
Definition: SharkSSL.h:313
@ SharkSsl_Unspecified
Definition: SharkSSL.h:297
@ SharkSsl_Client
Definition: SharkSSL.h:299
@ SharkSsl_Server
Definition: SharkSSL.h:298
@ SHARKSSL_ECDSA_ALLOCATION_ERROR
ALLOCATION_ERROR.
Definition: SharkSSL.h:2589
@ SHARKSSL_ECDSA_WRONG_KEY_FORMAT
WRONG_KEY_FORMAT.
Definition: SharkSSL.h:2598
@ SHARKSSL_ECDSA_WRONG_SIGNATURE
WRONG SIGNATURE.
Definition: SharkSSL.h:2613
@ SHARKSSL_ECDSA_WRONG_PARAMETERS
WRONG_PARAMETERS.
Definition: SharkSSL.h:2595
@ SHARKSSL_ECDSA_OK
OK.
Definition: SharkSSL.h:2586
@ SHARKSSL_ECDSA_VERIFICATION_FAIL
VERIFICATION_FAIL.
Definition: SharkSSL.h:2610
@ SHARKSSL_ECDSA_INTERNAL_ERROR
INTERNAL_ERROR.
Definition: SharkSSL.h:2592
@ SHARKSSL_ECDSA_KEY_NOT_PRIVATE
KEY_IS_NOT_PRIVATE.
Definition: SharkSSL.h:2601
@ SHARKSSL_ECDSA_KEY_NOT_PUBLIC
KEY_IS_NOT_PUBLIC.
Definition: SharkSSL.h:2604
@ SHARKSSL_ECDSA_SIGLEN_TOO_SMALL
SIGLEN_TOO_SMALL.
Definition: SharkSSL.h:2607
@ SHARKSSL_RSA_INPUT_DATA_LENGTH_TOO_BIG
INPUT_DATA_LENGTH_TOO_BIG.
Definition: SharkSSL.h:1966
@ SHARKSSL_RSA_WRONG_LABEL_LENGTH
WRONG_LABEL_LENGTH.
Definition: SharkSSL.h:1984
@ SHARKSSL_RSA_OK
OK.
Definition: SharkSSL.h:1948
@ SHARKSSL_RSA_INTERNAL_ERROR
INTERNAL_ERROR.
Definition: SharkSSL.h:1954
@ SHARKSSL_RSA_WRONG_PARAMETERS
WRONG_PARAMETERS.
Definition: SharkSSL.h:1957
@ SHARKSSL_RSA_WRONG_SIGNATURE
WRONG SIGNATURE.
Definition: SharkSSL.h:1981
@ SHARKSSL_RSA_ALLOCATION_ERROR
ALLOCATION_ERROR.
Definition: SharkSSL.h:1951
@ SHARKSSL_RSA_WRONG_KEY_FORMAT
WRONG_KEY_FORMAT.
Definition: SharkSSL.h:1960
@ SHARKSSL_RSA_PKCS1_PADDING_ERROR
PKCS1_PADDING_ERROR.
Definition: SharkSSL.h:1972
@ SHARKSSL_RSA_INPUT_DATA_LENGTH_AND_KEY_LENGTH_MISMATCH
INPUT_DATA_LENGTH_AND_KEY_LENGTH_MISMATCH.
Definition: SharkSSL.h:1969
@ SHARKSSL_RSA_WRONG_KEY_LENGTH
WRONG_KEY_LENGTH.
Definition: SharkSSL.h:1963
@ SHARKSSL_RSA_VERIFICATION_FAIL
VERIFICATION FAIL.
Definition: SharkSSL.h:1978
@ SHARKSSL_RSA_KEY_NOT_PRIVATE
KEY_IS_NOT_PRIVATE.
Definition: SharkSSL.h:1975
SHARKSSL_API SharkSslSession * SharkSslCon_acquireSession(SharkSslCon *o)
Request a SharkSslSession object from the client's session pool.
SHARKSSL_API U8 SharkSslCon_releaseSession(SharkSslCon *o)
experimental
struct SharkSslSession SharkSslSession
SharkSslSession is an opaque handle returned by function SharkSslCon_acquireSession.
Definition: SharkSSL.h:269
SHARKSSL_API U8 SharkSslCon_resumeSession(SharkSslCon *o, SharkSslSession *s)
Resume an existing session.
SHARKSSL_API U8 SharkSslCon_isResumed(SharkSslCon *o)
Returns 1 if the current session is a resumed one.
SHARKSSL_API U32 SharkSslSession_getLatestAccessTime(SharkSslSession *o)
Returns the last time the session was accessed.
SHARKSSL_API U8 SharkSslSession_release(SharkSslSession *o, SharkSsl *s)
Release a session created by function SharkSslCon_acquireSession.
Opaque object used when creating ASN.1 encoded data.
Definition: SharkSslASN1.h:233
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/nss_tech_notes/nss_tech_note3 http://to...
Definition: SharkSslASN1.h:244
Certificate KeyUsage and ExtendedKeyUsage flags and relative pseudofunctions.
Definition: SharkSSL.h:789
U8 unitLen
length in bytes of the field "organization"
Definition: SharkSSL.h:805
U8 provinceLen
length in bytes of the field "country"
Definition: SharkSSL.h:802
const U8 * province
State or Province.
Definition: SharkSSL.h:791
U8 localityLen
length in bytes of the field "province"
Definition: SharkSSL.h:803
const U8 * unit
Organizational Unit (OU: department or organization unit)
Definition: SharkSSL.h:794
const U8 * organization
Organization Name (company or department)
Definition: SharkSSL.h:793
const U8 * commonName
Common Name is the Host + Domain Name (example: www.mycompany.com, where www is host and mycompany....
Definition: SharkSSL.h:798
const U8 * countryName
ISO3166 country code.
Definition: SharkSSL.h:790
U8 organizationLen
length in bytes of the field "locality"
Definition: SharkSSL.h:804
U8 commonNameLen
length in bytes of the field "unit"
Definition: SharkSSL.h:806
const U8 * locality
The city or town name.
Definition: SharkSSL.h:792
U8 emailAddressLen
length in bytes of the field "common name"
Definition: SharkSSL.h:807
The peer's certificate information returned by SharkSslCon_getCertInfo.
Definition: SharkSSL.h:847
U8 timeFromLen
Length of 'timeFrom'.
Definition: SharkSSL.h:903
U8 timeToLen
Length of 'timeTo'.
Definition: SharkSSL.h:906
U16 snLen
Length of 'sn' (serial number)
Definition: SharkSSL.h:849
U8 * timeTo
Certificate expiration date (in Time format: [YY]YYMMDDHHMMSSZ) UTCTime: 2-digit year; GeneralizedTim...
Definition: SharkSSL.h:874
U8 CAflag
The Certificate Authority flag (CA) is set to one if the certificate is a CA i.e.
Definition: SharkSSL.h:859
SharkSslCertDN issuer
The entity who has signed and issued the certificate (RFC 2459 4.1.2.4)
Definition: SharkSSL.h:880
SharkSslCertDN subject
The entity associated with the public key (RFC 2459 4.1.2.6).
Definition: SharkSSL.h:886
U8 * sn
Binary serial number.
Definition: SharkSSL.h:863
U8 * timeFrom
Certificate is valid from date (in Time format: [YY]YYMMDDHHMMSSZ) UTCTime: 2-digit year; Generalized...
Definition: SharkSSL.h:868
U8 * subjectAltNamesPtr
Subject Alternative Names subjectAltNamesPtr is a pointer to an ASN1 sequence, whose length is subjec...
Definition: SharkSSL.h:899
struct SharkSslCertInfo * parent
Pointer to parent node when the SharkSslCertInfo object is part of a certificate chain.
Definition: SharkSSL.h:937
U8 version
Certificate version is offset at 0 so add +1 for actual version number.
Definition: SharkSSL.h:854
SharkSslCertStore is a container object used when assembling a SharkSslCAList.
Definition: SharkSSL.h:2729
A SharkSsl object is the coordinator for managing SharkSslCon objects (See SharkSsl_constructor for d...
Definition: SharkSSL.h:572