ssl_cookie.c 6.16 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35
/*
 *  DTLS cookie callbacks implementation
 *
 *  Copyright (C) 2014, Brainspark B.V.
 *
 *  This file is part of PolarSSL (http://www.polarssl.org)
 *  Lead Maintainer: Paul Bakker <polarssl_maintainer at polarssl.org>
 *
 *  All rights reserved.
 *
 *  This program is free software; you can redistribute it and/or modify
 *  it under the terms of the GNU General Public License as published by
 *  the Free Software Foundation; either version 2 of the License, or
 *  (at your option) any later version.
 *
 *  This program is distributed in the hope that it will be useful,
 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 *  GNU General Public License for more details.
 *
 *  You should have received a copy of the GNU General Public License along
 *  with this program; if not, write to the Free Software Foundation, Inc.,
 *  51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
 */
/*
 * These session callbacks use a simple chained list
 * to store and retrieve the session information.
 */

#if !defined(POLARSSL_CONFIG_FILE)
#include "polarssl/config.h"
#else
#include POLARSSL_CONFIG_FILE
#endif

36
#if defined(POLARSSL_SSL_COOKIE_C)
37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57

#include "polarssl/ssl_cookie.h"

#if defined(POLARSSL_PLATFORM_C)
#include "polarssl/platform.h"
#else
#define polarssl_malloc     malloc
#define polarssl_free       free
#endif

/* Implementation that should never be optimized out by the compiler */
static void polarssl_zeroize( void *v, size_t n ) {
    volatile unsigned char *p = v; while( n-- ) *p++ = 0;
}

/*
 * If DTLS is in use, then at least one of SHA-1, SHA-256, SHA-512 is
 * available. Try SHA-256 first, 512 wastes resources since we need to stay
 * with max 32 bytes of cookie for DTLS 1.0
 */
#if defined(POLARSSL_SHA256_C)
58 59 60
#define COOKIE_MD           POLARSSL_MD_SHA224
#define COOKIE_MD_OUTLEN    32
#define COOKIE_HMAC_LEN     28
61
#elif defined(POLARSSL_SHA512_C)
62 63 64
#define COOKIE_MD           POLARSSL_MD_SHA384
#define COOKIE_MD_OUTLEN    48
#define COOKIE_HMAC_LEN     28
65
#elif defined(POLARSSL_SHA1_C)
66 67 68
#define COOKIE_MD           POLARSSL_MD_SHA1
#define COOKIE_MD_OUTLEN    20
#define COOKIE_HMAC_LEN     20
69 70 71 72
#else
#error "DTLS hello verify needs SHA-1 or SHA-2"
#endif

73 74 75 76 77 78 79 80
/*
 * Cookies are formed of a 4-bytes timestamp (or serial number) and
 * an HMAC of timestemp and client ID.
 */
#define COOKIE_LEN      ( 4 + COOKIE_HMAC_LEN )

#define COOKIE_TIMEOUT  60

81 82 83
void ssl_cookie_init( ssl_cookie_ctx *ctx )
{
    md_init( &ctx->hmac_ctx );
84 85 86
#if !defined(POLARSSL_HAVE_TIME)
    ctx->serial = 0;
#endif
87 88 89 90 91 92 93 94 95 96 97 98
}

void ssl_cookie_free( ssl_cookie_ctx *ctx )
{
    md_free( &ctx->hmac_ctx );
}

int ssl_cookie_setup( ssl_cookie_ctx *ctx,
                      int (*f_rng)(void *, unsigned char *, size_t),
                      void *p_rng )
{
    int ret;
99
    unsigned char key[COOKIE_MD_OUTLEN];
100 101 102 103

    if( ( ret = f_rng( p_rng, key, sizeof( key ) ) ) != 0 )
        return( ret );

104
    ret = md_init_ctx( &ctx->hmac_ctx, md_info_from_type( COOKIE_MD ) );
105 106 107 108 109 110 111 112 113 114 115 116
    if( ret != 0 )
        return( ret );

    ret = md_hmac_starts( &ctx->hmac_ctx, key, sizeof( key ) );
    if( ret != 0 )
        return( ret );

    polarssl_zeroize( key, sizeof( key ) );

    return( 0 );
}

117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144
/*
 * Generate the HMAC part of a cookie
 */
static int ssl_cookie_hmac( md_context_t *hmac_ctx,
                            const unsigned char time[4],
                            unsigned char **p, unsigned char *end,
                            const unsigned char *cli_id, size_t cli_id_len )
{
    int ret;
    unsigned char hmac_out[COOKIE_MD_OUTLEN];

    if( (size_t)( end - *p ) < COOKIE_HMAC_LEN )
        return( POLARSSL_ERR_SSL_BAD_INPUT_DATA );

    if( ( ret = md_hmac_reset(  hmac_ctx ) ) != 0 ||
        ( ret = md_hmac_update( hmac_ctx, time, 4 ) ) != 0 ||
        ( ret = md_hmac_update( hmac_ctx, cli_id, cli_id_len ) ) != 0 ||
        ( ret = md_hmac_finish( hmac_ctx, hmac_out ) ) != 0 )
    {
        return( POLARSSL_ERR_SSL_INTERNAL_ERROR );
    }

    memcpy( *p, hmac_out, COOKIE_HMAC_LEN );
    *p += COOKIE_HMAC_LEN;

    return( 0 );
}

145 146 147
/*
 * Generate cookie for DTLS ClientHello verification
 */
148
int ssl_cookie_write( void *p_ctx,
149 150 151
                      unsigned char **p, unsigned char *end,
                      const unsigned char *cli_id, size_t cli_id_len )
{
152
    ssl_cookie_ctx *ctx = (ssl_cookie_ctx *) p_ctx;
153
    unsigned long t;
154

155
    if( ctx == NULL || cli_id == NULL )
156
        return( POLARSSL_ERR_SSL_BAD_INPUT_DATA );
157

158
    if( (size_t)( end - *p ) < COOKIE_LEN )
159 160
        return( POLARSSL_ERR_SSL_BAD_INPUT_DATA );

161 162 163 164 165
#if defined(POLARSSL_HAVE_TIME)
    t = (unsigned long) time( NULL );
#else
    t = ctx->serial++;
#endif
166

167 168 169 170 171
    (*p)[0] = (unsigned char)( t >> 24 );
    (*p)[1] = (unsigned char)( t >> 16 );
    (*p)[2] = (unsigned char)( t >>  8 );
    (*p)[3] = (unsigned char)( t       );
    *p += 4;
172

173 174
    return( ssl_cookie_hmac( &ctx->hmac_ctx, *p - 4,
                             p, end, cli_id, cli_id_len ) );
175 176 177 178 179
}

/*
 * Check a cookie
 */
180
int ssl_cookie_check( void *p_ctx,
181 182 183
                      const unsigned char *cookie, size_t cookie_len,
                      const unsigned char *cli_id, size_t cli_id_len )
{
184 185 186 187
    unsigned char ref_hmac[COOKIE_HMAC_LEN];
    unsigned char *p = ref_hmac;
    ssl_cookie_ctx *ctx = (ssl_cookie_ctx *) p_ctx;
    unsigned long cur_time, cookie_time;
188

189 190 191 192 193 194 195 196 197
    if( ctx == NULL || cli_id == NULL )
        return( POLARSSL_ERR_SSL_BAD_INPUT_DATA );

    if( cookie_len != COOKIE_LEN )
        return( -1 );

    if( ssl_cookie_hmac( &ctx->hmac_ctx, cookie,
                         &p, p + sizeof( ref_hmac ),
                         cli_id, cli_id_len ) != 0 )
198 199
        return( -1 );

200
    if( safer_memcmp( cookie + 4, ref_hmac, sizeof( ref_hmac ) ) != 0 )
201 202
        return( -1 );

203 204 205 206 207 208 209 210 211 212 213 214
#if defined(POLARSSL_HAVE_TIME)
    cur_time = (unsigned long) time( NULL );
#else
    cur_time = ctx->serial;
#endif

    cookie_time = ( (unsigned long) cookie[0] << 24 ) |
                  ( (unsigned long) cookie[1] << 16 ) |
                  ( (unsigned long) cookie[2] <<  8 ) |
                  ( (unsigned long) cookie[3]       );

    if( cur_time - cookie_time > COOKIE_TIMEOUT )
215 216 217 218 219
        return( -1 );

    return( 0 );
}
#endif /* POLARSSL_SSL_COOKIE_C */