ssl_cookie.c 7.38 KB
Newer Older
1 2 3
/*
 *  DTLS cookie callbacks implementation
 *
4
 *  Copyright (C) 2014-2015, ARM Limited, All Rights Reserved
5
 *
6
 *  This file is part of mbed TLS (https://tls.mbed.org)
7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
 *
 *  This program is free software; you can redistribute it and/or modify
 *  it under the terms of the GNU General Public License as published by
 *  the Free Software Foundation; either version 2 of the License, or
 *  (at your option) any later version.
 *
 *  This program is distributed in the hope that it will be useful,
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 *  GNU General Public License for more details.
 *
 *  You should have received a copy of the GNU General Public License along
 *  with this program; if not, write to the Free Software Foundation, Inc.,
 *  51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
 */
/*
 * These session callbacks use a simple chained list
 * to store and retrieve the session information.
 */

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
27
#if !defined(MBEDTLS_CONFIG_FILE)
28
#include "mbedtls/config.h"
29
#else
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
30
#include MBEDTLS_CONFIG_FILE
31 32
#endif

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
33
#if defined(MBEDTLS_SSL_COOKIE_C)
34

35
#include "mbedtls/ssl_cookie.h"
36
#include "mbedtls/ssl_internal.h"
37

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
38
#if defined(MBEDTLS_PLATFORM_C)
39
#include "mbedtls/platform.h"
40
#else
41
#define mbedtls_calloc    calloc
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
42
#define mbedtls_free       free
43 44
#endif

45 46
#include <string.h>

47
/* Implementation that should never be optimized out by the compiler */
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
48
static void mbedtls_zeroize( void *v, size_t n ) {
49 50 51 52 53 54 55 56
    volatile unsigned char *p = v; while( n-- ) *p++ = 0;
}

/*
 * If DTLS is in use, then at least one of SHA-1, SHA-256, SHA-512 is
 * available. Try SHA-256 first, 512 wastes resources since we need to stay
 * with max 32 bytes of cookie for DTLS 1.0
 */
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
57 58
#if defined(MBEDTLS_SHA256_C)
#define COOKIE_MD           MBEDTLS_MD_SHA224
59 60
#define COOKIE_MD_OUTLEN    32
#define COOKIE_HMAC_LEN     28
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
61 62
#elif defined(MBEDTLS_SHA512_C)
#define COOKIE_MD           MBEDTLS_MD_SHA384
63 64
#define COOKIE_MD_OUTLEN    48
#define COOKIE_HMAC_LEN     28
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
65 66
#elif defined(MBEDTLS_SHA1_C)
#define COOKIE_MD           MBEDTLS_MD_SHA1
67 68
#define COOKIE_MD_OUTLEN    20
#define COOKIE_HMAC_LEN     20
69 70 71 72
#else
#error "DTLS hello verify needs SHA-1 or SHA-2"
#endif

73 74 75 76 77 78
/*
 * Cookies are formed of a 4-bytes timestamp (or serial number) and
 * an HMAC of timestemp and client ID.
 */
#define COOKIE_LEN      ( 4 + COOKIE_HMAC_LEN )

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
79
void mbedtls_ssl_cookie_init( mbedtls_ssl_cookie_ctx *ctx )
80
{
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
81 82
    mbedtls_md_init( &ctx->hmac_ctx );
#if !defined(MBEDTLS_HAVE_TIME)
83 84
    ctx->serial = 0;
#endif
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
85
    ctx->timeout = MBEDTLS_SSL_COOKIE_TIMEOUT;
86 87 88 89

#if defined(MBEDTLS_THREADING_C)
    mbedtls_mutex_init( &ctx->mutex );
#endif
90 91
}

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
92
void mbedtls_ssl_cookie_set_timeout( mbedtls_ssl_cookie_ctx *ctx, unsigned long delay )
93 94
{
    ctx->timeout = delay;
95 96
}

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
97
void mbedtls_ssl_cookie_free( mbedtls_ssl_cookie_ctx *ctx )
98
{
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
99
    mbedtls_md_free( &ctx->hmac_ctx );
100 101 102 103 104 105

#if defined(MBEDTLS_THREADING_C)
    mbedtls_mutex_init( &ctx->mutex );
#endif

    mbedtls_zeroize( ctx, sizeof( mbedtls_ssl_cookie_ctx ) );
106 107
}

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
108
int mbedtls_ssl_cookie_setup( mbedtls_ssl_cookie_ctx *ctx,
109 110 111 112
                      int (*f_rng)(void *, unsigned char *, size_t),
                      void *p_rng )
{
    int ret;
113
    unsigned char key[COOKIE_MD_OUTLEN];
114 115 116 117

    if( ( ret = f_rng( p_rng, key, sizeof( key ) ) ) != 0 )
        return( ret );

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
118
    ret = mbedtls_md_setup( &ctx->hmac_ctx, mbedtls_md_info_from_type( COOKIE_MD ), 1 );
119 120 121
    if( ret != 0 )
        return( ret );

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
122
    ret = mbedtls_md_hmac_starts( &ctx->hmac_ctx, key, sizeof( key ) );
123 124 125
    if( ret != 0 )
        return( ret );

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
126
    mbedtls_zeroize( key, sizeof( key ) );
127 128 129 130

    return( 0 );
}

131 132 133
/*
 * Generate the HMAC part of a cookie
 */
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
134
static int ssl_cookie_hmac( mbedtls_md_context_t *hmac_ctx,
135 136 137 138 139 140 141
                            const unsigned char time[4],
                            unsigned char **p, unsigned char *end,
                            const unsigned char *cli_id, size_t cli_id_len )
{
    unsigned char hmac_out[COOKIE_MD_OUTLEN];

    if( (size_t)( end - *p ) < COOKIE_HMAC_LEN )
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
142
        return( MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL );
143

144 145 146 147
    if( mbedtls_md_hmac_reset(  hmac_ctx ) != 0 ||
        mbedtls_md_hmac_update( hmac_ctx, time, 4 ) != 0 ||
        mbedtls_md_hmac_update( hmac_ctx, cli_id, cli_id_len ) != 0 ||
        mbedtls_md_hmac_finish( hmac_ctx, hmac_out ) != 0 )
148
    {
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
149
        return( MBEDTLS_ERR_SSL_INTERNAL_ERROR );
150 151 152 153 154 155 156 157
    }

    memcpy( *p, hmac_out, COOKIE_HMAC_LEN );
    *p += COOKIE_HMAC_LEN;

    return( 0 );
}

158 159 160
/*
 * Generate cookie for DTLS ClientHello verification
 */
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
161
int mbedtls_ssl_cookie_write( void *p_ctx,
162 163 164
                      unsigned char **p, unsigned char *end,
                      const unsigned char *cli_id, size_t cli_id_len )
{
165
    int ret;
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
166
    mbedtls_ssl_cookie_ctx *ctx = (mbedtls_ssl_cookie_ctx *) p_ctx;
167
    unsigned long t;
168

169
    if( ctx == NULL || cli_id == NULL )
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
170
        return( MBEDTLS_ERR_SSL_BAD_INPUT_DATA );
171

172
    if( (size_t)( end - *p ) < COOKIE_LEN )
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
173
        return( MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL );
174

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
175
#if defined(MBEDTLS_HAVE_TIME)
176 177 178 179
    t = (unsigned long) time( NULL );
#else
    t = ctx->serial++;
#endif
180

181 182 183 184 185
    (*p)[0] = (unsigned char)( t >> 24 );
    (*p)[1] = (unsigned char)( t >> 16 );
    (*p)[2] = (unsigned char)( t >>  8 );
    (*p)[3] = (unsigned char)( t       );
    *p += 4;
186

187 188 189 190 191 192 193 194 195 196 197 198 199 200 201
#if defined(MBEDTLS_THREADING_C)
    if( ( ret = mbedtls_mutex_lock( &ctx->mutex ) ) != 0 )
        return( MBEDTLS_ERR_SSL_INTERNAL_ERROR + ret );
#endif

    ret = ssl_cookie_hmac( &ctx->hmac_ctx, *p - 4,
                           p, end, cli_id, cli_id_len );

#if defined(MBEDTLS_THREADING_C)
    if( mbedtls_mutex_unlock( &ctx->mutex ) != 0 )
        return( MBEDTLS_ERR_SSL_INTERNAL_ERROR +
                MBEDTLS_ERR_THREADING_MUTEX_ERROR );
#endif

    return( ret );
202 203 204 205 206
}

/*
 * Check a cookie
 */
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
207
int mbedtls_ssl_cookie_check( void *p_ctx,
208 209 210
                      const unsigned char *cookie, size_t cookie_len,
                      const unsigned char *cli_id, size_t cli_id_len )
{
211
    unsigned char ref_hmac[COOKIE_HMAC_LEN];
212
    int ret = 0;
213
    unsigned char *p = ref_hmac;
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
214
    mbedtls_ssl_cookie_ctx *ctx = (mbedtls_ssl_cookie_ctx *) p_ctx;
215
    unsigned long cur_time, cookie_time;
216

217
    if( ctx == NULL || cli_id == NULL )
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
218
        return( MBEDTLS_ERR_SSL_BAD_INPUT_DATA );
219 220 221 222

    if( cookie_len != COOKIE_LEN )
        return( -1 );

223 224 225 226 227
#if defined(MBEDTLS_THREADING_C)
    if( ( ret = mbedtls_mutex_lock( &ctx->mutex ) ) != 0 )
        return( MBEDTLS_ERR_SSL_INTERNAL_ERROR + ret );
#endif

228 229 230
    if( ssl_cookie_hmac( &ctx->hmac_ctx, cookie,
                         &p, p + sizeof( ref_hmac ),
                         cli_id, cli_id_len ) != 0 )
231 232 233 234 235 236 237 238 239 240
        ret = -1;

#if defined(MBEDTLS_THREADING_C)
    if( mbedtls_mutex_unlock( &ctx->mutex ) != 0 )
        return( MBEDTLS_ERR_SSL_INTERNAL_ERROR +
                MBEDTLS_ERR_THREADING_MUTEX_ERROR );
#endif

    if( ret != 0 )
        return( ret );
241

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
242
    if( mbedtls_ssl_safer_memcmp( cookie + 4, ref_hmac, sizeof( ref_hmac ) ) != 0 )
243 244
        return( -1 );

Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
245
#if defined(MBEDTLS_HAVE_TIME)
246 247 248 249 250 251 252 253 254 255
    cur_time = (unsigned long) time( NULL );
#else
    cur_time = ctx->serial;
#endif

    cookie_time = ( (unsigned long) cookie[0] << 24 ) |
                  ( (unsigned long) cookie[1] << 16 ) |
                  ( (unsigned long) cookie[2] <<  8 ) |
                  ( (unsigned long) cookie[3]       );

256
    if( ctx->timeout != 0 && cur_time - cookie_time > ctx->timeout )
257 258 259 260
        return( -1 );

    return( 0 );
}
Manuel Pégourié-Gonnard's avatar
Manuel Pégourié-Gonnard committed
261
#endif /* MBEDTLS_SSL_COOKIE_C */