mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
[tls] Add ClientHello to transcript before selecting named group
The TLS version 1.3 ClientHello includes a key_share extension whose value will depend upon the selected key exchange named group. The incorporation of the initial ClientHello into the selected handshake digest must therefore be done before the named group is potentially modified. Move responsibility for adding the initial ClientHello to the transcript digest from tls_new_server_hello() to tls_select_cipher(), so that this can be done before updating the selected named group. Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
+34
-30
@@ -218,6 +218,10 @@ static int tls_send_plaintext ( struct tls_connection *tls, unsigned int type,
|
||||
static void tls_clear_digest ( struct tls_connection *tls );
|
||||
static void tls_clear_cipher ( struct tls_connection *tls,
|
||||
struct tls_cipherspec *cipherspec );
|
||||
static int tls_client_hello ( struct tls_connection *tls,
|
||||
int ( * action ) ( struct tls_connection *tls,
|
||||
const void *data,
|
||||
size_t len ) );
|
||||
|
||||
/******************************************************************************
|
||||
*
|
||||
@@ -512,6 +516,23 @@ static int tls_set_digest ( struct tls_connection *tls,
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* Add handshake record to verification hash
|
||||
*
|
||||
* @v tls TLS connection
|
||||
* @v data Handshake record
|
||||
* @v len Length of handshake record
|
||||
* @ret rc Return status code
|
||||
*/
|
||||
static int tls_add_handshake ( struct tls_connection *tls,
|
||||
const void *data, size_t len ) {
|
||||
|
||||
/* Record in transcript digest */
|
||||
tlskey_digest ( &tls->key, data, len );
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/******************************************************************************
|
||||
*
|
||||
* Cipher suite management
|
||||
@@ -666,15 +687,25 @@ static int tls_select_cipher ( struct tls_connection *tls,
|
||||
return -ENOTSUP_CIPHER;
|
||||
}
|
||||
|
||||
/* Set default named group */
|
||||
tls->group = suite->exchange->group;
|
||||
|
||||
/* Set key schedule digest algorithm */
|
||||
digest = ( tls_version ( tls, TLS_VERSION_TLS_1_2 ) ?
|
||||
suite->handshake : &md5_sha1_algorithm );
|
||||
if ( ( rc = tls_set_digest ( tls, digest ) ) != 0 )
|
||||
return rc;
|
||||
|
||||
/* Add initial Client Hello to handshake digest
|
||||
*
|
||||
* When the Client Hello was originally sent, the digest
|
||||
* algorithm selected by the server's choice of cipher suite
|
||||
* was not yet known. This is the earliest point at which it
|
||||
* can be incorporated into the handshake transcript digest.
|
||||
*/
|
||||
if ( ( rc = tls_client_hello ( tls, tls_add_handshake ) ) != 0 )
|
||||
return rc;
|
||||
|
||||
/* Set default named group */
|
||||
tls->group = suite->exchange->group;
|
||||
|
||||
/* Set ciphers */
|
||||
if ( ( rc = tls_set_cipher ( tls, &tls->tx.cipherspec.pending,
|
||||
suite ) ) != 0 )
|
||||
@@ -1543,23 +1574,6 @@ static int tls_resume ( struct tls_connection *tls ) {
|
||||
******************************************************************************
|
||||
*/
|
||||
|
||||
/**
|
||||
* Add handshake record to verification hash
|
||||
*
|
||||
* @v tls TLS connection
|
||||
* @v data Handshake record
|
||||
* @v len Length of handshake record
|
||||
* @ret rc Return status code
|
||||
*/
|
||||
static int tls_add_handshake ( struct tls_connection *tls,
|
||||
const void *data, size_t len ) {
|
||||
|
||||
/* Record in transcript digest */
|
||||
tlskey_digest ( &tls->key, data, len );
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* Resume TX state machine
|
||||
*
|
||||
@@ -2474,16 +2488,6 @@ static int tls_new_server_hello ( struct tls_connection *tls,
|
||||
if ( ( rc = tls_select_cipher ( tls, hello_b->cipher_suite ) ) != 0 )
|
||||
return rc;
|
||||
|
||||
/* Add preceding Client Hello to handshake digest
|
||||
*
|
||||
* When the Client Hello was originally sent, the digest
|
||||
* algorithm selected by the server's choice of cipher suite
|
||||
* was not yet known. This is the earliest point at which it
|
||||
* can be incorporated into the handshake transcript digest.
|
||||
*/
|
||||
if ( ( rc = tls_client_hello ( tls, tls_add_handshake ) ) != 0 )
|
||||
return rc;
|
||||
|
||||
/* Handle extended master secret */
|
||||
tls->extended_master_secret = ( !! ems );
|
||||
|
||||
|
||||
Reference in New Issue
Block a user