35#if defined(ENABLE_CRYPTO_OPENSSL)
48#ifdef ENABLE_CRYPTOAPI
55#include <openssl/bn.h>
56#include <openssl/crypto.h>
57#include <openssl/dh.h>
58#include <openssl/dsa.h>
59#include <openssl/err.h>
60#include <openssl/pkcs12.h>
61#include <openssl/rsa.h>
62#include <openssl/x509.h>
63#include <openssl/ssl.h>
65#include <openssl/ec.h>
68#if OPENSSL_VERSION_NUMBER >= 0x30000000L
69#define HAVE_OPENSSL_STORE_API
70#include <openssl/ui.h>
71#include <openssl/store.h>
74#if defined(_MSC_VER) && !defined(_M_ARM64)
75#include <openssl/applink.c>
93 mydata_index = SSL_get_ex_new_index(0,
"struct session *", NULL, NULL, NULL);
109 if (ctx->
ctx == NULL)
113 if (ERR_peek_error() != 0)
124 SSL_CTX_free(ctx->
ctx);
126 sk_X509_CRL_pop_free(ctx->crls, X509_CRL_free);
142 void *ekm,
size_t ekm_size)
147 if (SSL_export_keying_material(ssl, ekm, ekm_size, label, label_size, NULL, 0, 0) == 1)
162#ifndef INFO_CALLBACK_SSL_CONST
163#define INFO_CALLBACK_SSL_CONST const
168 if (where & SSL_CB_LOOP)
171 where & SSL_ST_CONNECT ?
"connect"
172 : where & SSL_ST_ACCEPT ?
"accept"
174 SSL_state_string_long(s));
176 else if (where & SSL_CB_ALERT)
179 SSL_alert_type_string_long(ret), SSL_alert_desc_string_long(ret));
203 return TLS1_1_VERSION;
207 return TLS1_2_VERSION;
211 return TLS1_3_VERSION;
219 uint16_t tls_ver_min =
221 uint16_t tls_ver_max =
227 uint16_t cur_min = (uint16_t)SSL_CTX_get_min_proto_version(ctx->
ctx);
228 tls_ver_min = cur_min < TLS1_VERSION ? TLS1_VERSION : cur_min;
231 if (!SSL_CTX_set_min_proto_version(ctx->
ctx, tls_ver_min))
237 if (tls_ver_max && !SSL_CTX_set_max_proto_version(ctx->
ctx, tls_ver_max))
252 ssl = X509_STORE_CTX_get_ex_data(ctx, SSL_get_ex_data_X509_STORE_CTX_idx());
258 X509_STORE_CTX_set0_crls(ctx,
session->opt->ssl_ctx->crls);
259 return X509_verify_cert(ctx);
268 openssl_opt_t sslopt = SSL_OP_SINGLE_DH_USE | SSL_OP_NO_TICKET;
269#ifdef SSL_OP_CIPHER_SERVER_PREFERENCE
270 sslopt |= SSL_OP_CIPHER_SERVER_PREFERENCE;
272 sslopt |= SSL_OP_NO_COMPRESSION;
276#ifdef SSL_OP_NO_RENEGOTIATION
277 sslopt |= SSL_OP_NO_RENEGOTIATION;
280 SSL_CTX_set_options(ctx->
ctx, sslopt);
287#ifdef SSL_MODE_RELEASE_BUFFERS
288 SSL_CTX_set_mode(ctx->
ctx, SSL_MODE_RELEASE_BUFFERS);
290 SSL_CTX_set_session_cache_mode(ctx->
ctx, SSL_SESS_CACHE_OFF);
294 int verify_flags = SSL_VERIFY_PEER | SSL_VERIFY_FAIL_IF_NO_PEER_CERT;
301 verify_flags = SSL_VERIFY_PEER;
315 size_t begin_of_cipher, end_of_cipher;
317 const char *current_cipher;
318 size_t current_cipher_len;
322 size_t openssl_ciphers_len = 0;
323 openssl_ciphers[0] =
'\0';
326 begin_of_cipher = end_of_cipher = 0;
327 for (; begin_of_cipher < strlen(ciphers); begin_of_cipher = end_of_cipher)
329 end_of_cipher += strcspn(&ciphers[begin_of_cipher],
":");
333 if (NULL == cipher_pair)
336 current_cipher = &ciphers[begin_of_cipher];
337 current_cipher_len = end_of_cipher - begin_of_cipher;
342 msg(
D_LOW,
"No valid translation found for TLS cipher '%.*s'",
343 constrain_int((
int)current_cipher_len, 0, 256), current_cipher);
349 current_cipher_len = strlen(current_cipher);
351 if (end_of_cipher - begin_of_cipher == current_cipher_len
353 != memcmp(&ciphers[begin_of_cipher], cipher_pair->
iana_name,
354 end_of_cipher - begin_of_cipher))
357 msg(
M_WARN,
"Deprecated TLS cipher name '%s', please use IANA name '%s'",
363 if ((SIZE_MAX - openssl_ciphers_len) < current_cipher_len
364 || (len - 1) < (openssl_ciphers_len + current_cipher_len))
366 msg(
M_FATAL,
"Failed to set restricted TLS cipher list, too long (>%d).",
371 memcpy(&openssl_ciphers[openssl_ciphers_len], current_cipher, current_cipher_len);
372 openssl_ciphers_len += current_cipher_len;
373 openssl_ciphers[openssl_ciphers_len] =
':';
374 openssl_ciphers_len++;
379 if (openssl_ciphers_len > 0)
381 openssl_ciphers[openssl_ciphers_len - 1] =
'\0';
391 if (!SSL_CTX_set_cipher_list(
409 char openssl_ciphers[4096];
415 if (!SSL_CTX_set_cipher_list(ctx->
ctx, openssl_ciphers))
417 crypto_msg(
M_FATAL,
"Failed to set restricted TLS cipher list: %s", openssl_ciphers);
423convert_tls13_list_to_openssl(
char *openssl_ciphers,
size_t len,
const char *ciphers)
430 if (strlen(ciphers) >= (len - 1))
432 msg(
M_FATAL,
"Failed to set restricted TLS 1.3 cipher list, too long (>%zd).",
436 strncpy(openssl_ciphers, ciphers, len);
438 for (
size_t i = 0; i < strlen(openssl_ciphers); i++)
440 if (openssl_ciphers[i] ==
'-')
442 openssl_ciphers[i] =
'_';
460 char openssl_ciphers[4096];
461 convert_tls13_list_to_openssl(openssl_ciphers,
sizeof(openssl_ciphers), ciphers);
463 if (!SSL_CTX_set_ciphersuites(ctx->
ctx, openssl_ciphers))
465 crypto_msg(
M_FATAL,
"Failed to set restricted TLS 1.3 cipher list: %s", openssl_ciphers);
472#if (!defined(LIBRESSL_VERSION_NUMBER) || LIBRESSL_VERSION_NUMBER > 0x3060000fL) \
473 && !defined(OPENSSL_IS_AWSLC)
478 if (!profile || 0 == strcmp(profile,
"legacy"))
480 SSL_CTX_set_security_level(ctx->
ctx, 1);
482 else if (0 == strcmp(profile,
"insecure"))
484 SSL_CTX_set_security_level(ctx->
ctx, 0);
486 else if (0 == strcmp(profile,
"preferred"))
488 SSL_CTX_set_security_level(ctx->
ctx, 2);
490 else if (0 == strcmp(profile,
"suiteb"))
492 SSL_CTX_set_security_level(ctx->
ctx, 3);
493 SSL_CTX_set_cipher_list(ctx->
ctx,
"SUITEB128");
497 msg(
M_FATAL,
"ERROR: Invalid cert profile: %s", profile);
503 "WARNING: OpenSSL 1.1.0, AWS-LC and LibreSSL < 3.6.0 do not "
504 "support --tls-cert-profile, ignoring user-set profile: '%s'",
514#if OPENSSL_VERSION_NUMBER < 0x30000000L && !defined(ENABLE_CRYPTO_WOLFSSL)
536 while ((token =
strsep(&tmp_groups,
":")))
538 if (
streq(token,
"secp256r1"))
540 token =
"prime256v1";
542 int nid = OBJ_sn2nid(token);
546 msg(
M_WARN,
"Warning unknown curve/group specified: %s", token);
550 glist[glistlen] = nid;
555 if (!SSL_CTX_set1_groups(ctx->
ctx, glist, glistlen))
561 if (!SSL_CTX_set1_groups_list(ctx->
ctx, groups))
568#if OPENSSL_VERSION_NUMBER < 0x40000000L
577 cert = SSL_CTX_get0_certificate(ctx->
ctx);
584 ret = X509_cmp_time(X509_get0_notBefore(cert), NULL);
591 msg(
M_WARN,
"WARNING: Your certificate is not yet valid!");
594 ret = X509_cmp_time(X509_get0_notAfter(cert), NULL);
601 msg(
M_WARN,
"WARNING: Your certificate has expired!");
611 cert = SSL_CTX_get0_certificate(ctx->
ctx);
618 X509_VERIFY_PARAM *vpm = X509_VERIFY_PARAM_new();
626 X509_VERIFY_PARAM_set_flags(vpm, X509_V_FLAG_USE_CHECK_TIME);
627 X509_VERIFY_PARAM_set_time(vpm,
now);
630 int ret = X509_check_certificate_times(vpm, cert, &error);
631 X509_VERIFY_PARAM_free(vpm);
640 case X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD:
644 case X509_V_ERR_CERT_NOT_YET_VALID:
645 msg(
M_WARN,
"WARNING: Your certificate is not yet valid!");
648 case X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD:
652 case X509_V_ERR_CERT_HAS_EXPIRED:
653 msg(
M_WARN,
"WARNING: Your certificate has expired!");
668 if (!(bio = BIO_new_mem_buf((
char *)dh_file, -1)))
676 if (!(bio = BIO_new_file(dh_file,
"r")))
682#if OPENSSL_VERSION_NUMBER >= 0x30000000L
683 EVP_PKEY *dh = PEM_read_bio_Parameters(bio, NULL);
691 if (!SSL_CTX_set0_tmp_dh_pkey(ctx->
ctx, dh))
696 msg(
D_TLS_DEBUG_LOW,
"Diffie-Hellman initialized with %d bit key", 8 * EVP_PKEY_get_size(dh));
698 DH *dh = PEM_read_bio_DHparams(bio, NULL, NULL, NULL);
706 if (!SSL_CTX_set_tmp_dh(ctx->
ctx, dh))
720#if OPENSSL_VERSION_NUMBER >= 0x30000000L
721 if (curve_name != NULL)
723 msg(
M_WARN,
"WARNING: OpenSSL 3.0+ builds do not support specifying an "
724 "ECDH curve with --ecdh-curve, using default curves. Use "
725 "--tls-groups to specify groups.");
727#elif !defined(OPENSSL_NO_EC)
730 const char *sname = NULL;
733 SSL_CTX_set_options(ctx->
ctx, SSL_OP_SINGLE_ECDH_USE);
735 if (curve_name != NULL)
738 msg(
D_TLS_DEBUG,
"Using user specified ECDH curve (%s)", curve_name);
739 nid = OBJ_sn2nid(curve_name);
747 sname = OBJ_nid2sn(nid);
754 if (NID_undef == nid || NULL == (ecdh = EC_KEY_new_by_curve_name(nid)))
757 ecdh = EC_KEY_new_by_curve_name(NID_secp384r1);
759 (NULL == curve_name) ?
"extract curve from certificate" :
"use supplied curve";
761 sname = OBJ_nid2sn(NID_secp384r1);
764 if (!SSL_CTX_set_tmp_ecdh(ctx->
ctx, ecdh))
773 msg(
D_LOW,
"Your OpenSSL library was built without elliptic curve support."
774 " Skipping ECDH parameter loading.");
778#if defined(HAVE_OPENSSL_STORE_API)
785ui_reader(UI *ui, UI_STRING *uis)
787 SSL_CTX *ctx = UI_get0_user_data(ui);
789 if (UI_get_string_type(uis) == UIT_PROMPT)
791 const char *prompt = UI_get0_output_string(uis);
794 if (strstr(prompt,
"PKCS#11"))
800 UI_set_result(ui, uis, up.password);
806 pem_password_cb *cb = SSL_CTX_get_default_passwd_cb(ctx);
807 void *d = SSL_CTX_get_default_passwd_cb_userdata(ctx);
820clear_ossl_store_error(OSSL_STORE_CTX *store_ctx)
822 if (OSSL_STORE_error(store_ctx))
840 EVP_PKEY *pkey = NULL;
842#if !defined(HAVE_OPENSSL_STORE_API)
845 BIO *in = BIO_new_file(uri,
"r");
850 pkey = PEM_read_bio_PrivateKey(in, NULL, SSL_CTX_get_default_passwd_cb(ssl_ctx),
851 SSL_CTX_get_default_passwd_cb_userdata(ssl_ctx));
856 OSSL_STORE_CTX *store_ctx = NULL;
857 OSSL_STORE_INFO *info = NULL;
859 UI_METHOD *ui_method = UI_create_method(
"openvpn");
862 msg(
M_WARN,
"OpenSSL UI creation failed");
865 UI_method_set_reader(ui_method, ui_reader);
867 store_ctx = OSSL_STORE_open_ex(uri,
tls_libctx, NULL, ui_method, ssl_ctx, NULL, NULL, NULL);
872 if (OSSL_STORE_expect(store_ctx, OSSL_STORE_INFO_PKEY) != 1)
878 info = OSSL_STORE_load(store_ctx);
879 if (info || OSSL_STORE_eof(store_ctx))
887 clear_ossl_store_error(store_ctx);
893 pkey = OSSL_STORE_INFO_get1_PKEY(info);
894 OSSL_STORE_INFO_free(info);
898 OSSL_STORE_close(store_ctx);
899 UI_destroy_method(ui_method);
913 STACK_OF(X509) *ca = NULL;
919 if (pkcs12_file_inline)
921 BIO *b64 = BIO_new(BIO_f_base64());
922 BIO *bio = BIO_new_mem_buf((
void *)pkcs12_file, (
int)strlen(pkcs12_file));
925 p12 = d2i_PKCS12_bio(b64, NULL);
940 p12 = d2i_PKCS12_fp(fp, NULL);
949 if (!PKCS12_parse(p12,
"", &pkey, &cert, &ca))
954 if (!PKCS12_parse(p12,
password, &pkey, &cert, &ca))
957 "or unsupported/legacy encryption");
958#ifdef ENABLE_MANAGEMENT
959 if (
management && (ERR_GET_REASON(ERR_peek_error()) == PKCS12_R_MAC_VERIFY_FAILURE))
971 if (!SSL_CTX_use_certificate(ctx->
ctx, cert))
978 if (!SSL_CTX_use_PrivateKey(ctx->
ctx, pkey))
984 if (!SSL_CTX_check_private_key(ctx->
ctx))
996 if (ca && sk_X509_num(ca))
1000 X509_STORE *cert_store = SSL_CTX_get_cert_store(ctx->
ctx);
1001 if (!X509_STORE_add_cert(cert_store, sk_X509_value(ca, i)))
1004 "Cannot add certificate to certificate chain (X509_STORE_add_cert)");
1006 if (!SSL_CTX_add_client_CA(ctx->
ctx, sk_X509_value(ca, i)))
1009 "Cannot add certificate to client CA list (SSL_CTX_add_client_CA)");
1021 if (ca && sk_X509_num(ca))
1025 if (!SSL_CTX_add_extra_chain_cert(ctx->
ctx, sk_X509_value(ca, i)))
1029 "Cannot add extra certificate to chain (SSL_CTX_add_extra_chain_cert)");
1037#ifdef ENABLE_CRYPTOAPI
1046 crypto_msg(
M_FATAL,
"Cannot load certificate \"%s\" from Microsoft Certificate Store",
1059 if (!PEM_read_bio_X509(bio, &cert, NULL, NULL))
1065 if (optional && ERR_GET_REASON(ERR_peek_error()) == PEM_R_NO_START_LINE)
1068 (void)ERR_get_error();
1076 if (SSL_CTX_add_extra_chain_cert(ctx->
ctx, cert) != 1)
1088#if defined(HAVE_OPENSSL_STORE_API)
1098#if defined(HAVE_OPENSSL_STORE_API)
1101 OSSL_STORE_CTX *store_ctx = NULL;
1102 OSSL_STORE_INFO *info = NULL;
1106 UI_METHOD *ui_method = UI_create_method(
"openvpn");
1109 msg(
M_WARN,
"OpenSSL UI method creation failed");
1112 UI_method_set_reader(ui_method, ui_reader);
1115 OSSL_STORE_open_ex(uri,
tls_libctx, NULL, ui_method, tls_ctx->
ctx, NULL, NULL, NULL);
1120 if (OSSL_STORE_expect(store_ctx, OSSL_STORE_INFO_CERT) != 1)
1127 info = OSSL_STORE_load(store_ctx);
1128 if (info || OSSL_STORE_eof(store_ctx))
1136 clear_ossl_store_error(store_ctx);
1143 x = OSSL_STORE_INFO_get0_CERT(info);
1150 ret = SSL_CTX_use_certificate(tls_ctx->
ctx, x);
1155 OSSL_STORE_INFO_free(info);
1159 while (!OSSL_STORE_eof(store_ctx))
1161 info = OSSL_STORE_load(store_ctx);
1164 clear_ossl_store_error(store_ctx);
1167 x = OSSL_STORE_INFO_get1_CERT(info);
1168 if (x && SSL_CTX_add_extra_chain_cert(tls_ctx->
ctx, x) != 1)
1174 OSSL_STORE_INFO_free(info);
1189 UI_destroy_method(ui_method);
1190 OSSL_STORE_INFO_free(info);
1191 OSSL_STORE_close(store_ctx);
1206 if (cert_file_inline)
1208 in = BIO_new_mem_buf((
char *)cert_file, -1);
1212 in = BIO_new_file((
char *)cert_file,
"r");
1217 SSLerr(SSL_F_SSL_CTX_USE_CERTIFICATE_FILE, ERR_R_SYS_LIB);
1221 x = PEM_read_bio_X509(in, NULL, SSL_CTX_get_default_passwd_cb(ctx->
ctx),
1222 SSL_CTX_get_default_passwd_cb_userdata(ctx->
ctx));
1225 SSLerr(SSL_F_SSL_CTX_USE_CERTIFICATE_FILE, ERR_R_PEM_LIB);
1229 ret = SSL_CTX_use_certificate(ctx->
ctx, x);
1239 if (cert_file_inline)
1272 bool priv_key_file_inline)
1274 SSL_CTX *ssl_ctx = NULL;
1276 EVP_PKEY *pkey = NULL;
1283 if (priv_key_file_inline)
1285 in = BIO_new_mem_buf((
char *)priv_key_file, -1);
1290 pkey = PEM_read_bio_PrivateKey(in, NULL, SSL_CTX_get_default_passwd_cb(ctx->
ctx),
1291 SSL_CTX_get_default_passwd_cb_userdata(ctx->
ctx));
1298 if (!pkey || !SSL_CTX_use_PrivateKey(ssl_ctx, pkey))
1300#ifdef ENABLE_MANAGEMENT
1301 if (
management && (ERR_GET_REASON(ERR_peek_error()) == EVP_R_BAD_DECRYPT))
1312 if (!SSL_CTX_check_private_key(ssl_ctx))
1319 EVP_PKEY_free(pkey);
1328 STACK_OF(X509_CRL) *crls = NULL;
1330 X509_STORE *store = SSL_CTX_get_cert_store(ssl_ctx->
ctx);
1336 sk_X509_CRL_pop_free(ssl_ctx->crls, X509_CRL_free);
1337 ssl_ctx->crls = NULL;
1339 X509_STORE_set_flags(store, X509_V_FLAG_CRL_CHECK | X509_V_FLAG_CRL_CHECK_ALL);
1343 in = BIO_new_mem_buf((
char *)crl_file, -1);
1347 in = BIO_new_file(crl_file,
"r");
1356 crls = sk_X509_CRL_new_null();
1362 int num_crls_loaded = 0;
1365 X509_CRL *crl = PEM_read_bio_X509_CRL(in, NULL, NULL, NULL);
1371 bool eof = ERR_GET_REASON(ERR_peek_error()) == PEM_R_NO_START_LINE;
1373 if (num_crls_loaded > 0 && eof)
1376 (void)ERR_get_error();
1385 if (!sk_X509_CRL_push(crls, crl))
1391 msg(
M_INFO,
"CRL: loaded %d CRLs from file %s", num_crls_loaded, crl_file);
1392 ssl_ctx->crls = crls;
1397#if defined(ENABLE_MANAGEMENT) && !defined(HAVE_XKEY_PROVIDER)
1401rsa_pub_enc(
int flen,
const unsigned char *from,
unsigned char *to, RSA *rsa,
int padding)
1409rsa_pub_dec(
int flen,
const unsigned char *from,
unsigned char *to, RSA *rsa,
int padding)
1417rsa_priv_dec(
int flen,
const unsigned char *from,
unsigned char *to, RSA *rsa,
int padding)
1430 const RSA_METHOD *meth = RSA_get_method(rsa);
1431 RSA_meth_free((RSA_METHOD *)meth);
1444 case RSA_PKCS1_PADDING:
1445 return "RSA_PKCS1_PADDING";
1447 case RSA_NO_PADDING:
1448 return "RSA_NO_PADDING";
1468 unsigned int siglen,
const char *algorithm)
1470 char *in_b64 = NULL;
1471 char *out_b64 = NULL;
1492rsa_priv_enc(
int flen,
const unsigned char *from,
unsigned char *to, RSA *rsa,
int padding)
1494 int len = RSA_size(rsa);
1496 if (padding != RSA_PKCS1_PADDING && padding != RSA_NO_PADDING)
1498 RSAerr(RSA_F_RSA_OSSL_PRIVATE_ENCRYPT, RSA_R_UNKNOWN_PADDING_TYPE);
1504 return (ret == len) ? ret : -1;
1511 RSA_METHOD *rsa_meth;
1515 const RSA *pub_rsa = EVP_PKEY_get0_RSA(pkey);
1519 rsa_meth = RSA_meth_new(
"OpenVPN external private key RSA Method", RSA_METHOD_FLAG_NO_CHECK);
1525 RSA_meth_set_init(rsa_meth, NULL);
1527 RSA_meth_set0_app_data(rsa_meth, NULL);
1533 SSLerr(SSL_F_SSL_USE_PRIVATEKEY, ERR_R_MALLOC_FAILURE);
1538 const BIGNUM *n = NULL;
1539 const BIGNUM *e = NULL;
1540 RSA_get0_key(pub_rsa, &n, &e, NULL);
1541 RSA_set0_key(rsa, BN_dup(n), BN_dup(e), NULL);
1542 RSA_set_flags(rsa, RSA_flags(rsa) | RSA_FLAG_EXT_PKEY);
1543 if (!RSA_set_method(rsa, rsa_meth))
1545 RSA_meth_free(rsa_meth);
1551 if (!SSL_CTX_use_RSAPrivateKey(ctx->
ctx, rsa))
1566 RSA_meth_free(rsa_meth);
1571#if !defined(OPENSSL_NO_EC)
1578 const EC_KEY_METHOD *ec_meth = EC_KEY_get_method(ec);
1579 EC_KEY_METHOD_free((EC_KEY_METHOD *)ec_meth);
1587ecdsa_sign(
int type,
const unsigned char *dgst,
int dgstlen,
unsigned char *sig,
1588 unsigned int *siglen,
const BIGNUM *kinv,
const BIGNUM *r, EC_KEY *ec)
1590 int capacity = (int)ECDSA_size(ec);
1606#ifndef OPENSSL_IS_AWSLC
1620ecdsa_sign_sig(
const unsigned char *dgst,
int dgstlen,
const BIGNUM *in_kinv,
const BIGNUM *in_r,
1623 ECDSA_SIG *ecsig = NULL;
1624 unsigned int len = (
unsigned int)ECDSA_size(ec);
1628 if (
ecdsa_sign(0, dgst, dgstlen, buf, &len, NULL, NULL, ec) != 1)
1633 ecsig = d2i_ECDSA_SIG(NULL, (
const unsigned char **)&buf, len);
1644 EVP_PKEY *privkey = NULL;
1645 EC_KEY_METHOD *ec_method;
1649 ec_method = EC_KEY_METHOD_new(EC_KEY_OpenSSL());
1657#ifdef OPENSSL_IS_AWSLC
1663 ec = EC_KEY_dup(EVP_PKEY_get0_EC_KEY(pkey));
1666 EC_KEY_METHOD_free(ec_method);
1669 if (!EC_KEY_set_method(ec, ec_method))
1671 EC_KEY_METHOD_free(ec_method);
1676 privkey = EVP_PKEY_new();
1677 if (!EVP_PKEY_assign_EC_KEY(privkey, ec))
1683 if (!SSL_CTX_use_PrivateKey(ctx->
ctx, privkey))
1689 EVP_PKEY_free(privkey);
1694 EVP_PKEY_free(privkey);
1701#ifdef ENABLE_MANAGEMENT
1709 X509 *cert = SSL_CTX_get0_certificate(ctx->
ctx);
1714 EVP_PKEY *pkey = X509_get0_pubkey(cert);
1717#ifdef HAVE_XKEY_PROVIDER
1718 EVP_PKEY *privkey = xkey_load_management_key(
tls_libctx, pkey);
1719 if (!privkey || !SSL_CTX_use_PrivateKey(ctx->
ctx, privkey))
1721 EVP_PKEY_free(privkey);
1724 EVP_PKEY_free(privkey);
1726#if OPENSSL_VERSION_NUMBER < 0x30000000L
1727 if (EVP_PKEY_id(pkey) == EVP_PKEY_RSA)
1729 if (EVP_PKEY_is_a(pkey,
"RSA"))
1737#if !defined(OPENSSL_NO_EC)
1738#if OPENSSL_VERSION_NUMBER < 0x30000000L
1739 else if (EVP_PKEY_id(pkey) == EVP_PKEY_EC)
1741 else if (EVP_PKEY_is_a(pkey,
"EC"))
1751 crypto_msg(
M_WARN,
"management-external-key requires an RSA or EC certificate");
1778 return X509_NAME_cmp(*a, *b);
1783 const char *ca_path,
bool tls_server)
1785 STACK_OF(X509_INFO) *info_stack = NULL;
1786 STACK_OF(X509_NAME) *cert_names = NULL;
1787 X509_LOOKUP *lookup = NULL;
1788 X509_STORE *store = NULL;
1794 store = SSL_CTX_get_cert_store(ctx->
ctx);
1805 in = BIO_new_mem_buf((
char *)ca_file, -1);
1809 in = BIO_new_file(ca_file,
"r");
1814 info_stack = PEM_X509_INFO_read_bio(in, NULL, NULL, NULL);
1821 X509_INFO *info = sk_X509_INFO_value(info_stack, i);
1824 X509_STORE_add_crl(store, info->crl);
1827 if (tls_server && !info->x509)
1834 X509_STORE_add_cert(store, info->x509);
1843 if (cert_names == NULL)
1856 X509_NAME *xn = (X509_NAME *)X509_get_subject_name(info->x509);
1864 if (sk_X509_NAME_find(cert_names, (X509_NAME *)xn) == -1)
1866 X509_NAME *xn_dup = X509_NAME_dup(xn);
1871 sk_X509_NAME_push(cert_names, xn_dup);
1878 if (cnum != (prev + 1))
1881 "Cannot load CA certificate file %s (entry %" PRI_OPENSSL_STACK " did not validate)",
1887 sk_X509_INFO_pop_free(info_stack, X509_INFO_free);
1892 cnum = sk_X509_NAME_num(cert_names);
1893 SSL_CTX_set_client_CA_list(ctx->
ctx, cert_names);
1898 crypto_msg(
M_FATAL,
"Cannot load CA certificate file %s (no entries were read)",
1919 lookup = X509_STORE_add_lookup(store, X509_LOOKUP_hash_dir());
1920 if (lookup && X509_LOOKUP_add_dir(lookup, ca_path, X509_FILETYPE_PEM))
1922 msg(
M_WARN,
"WARNING: experimental option --capath %s", ca_path);
1928 X509_STORE_set_flags(store, X509_V_FLAG_CRL_CHECK | X509_V_FLAG_CRL_CHECK_ALL);
1934 bool extra_certs_file_inline)
1937 if (extra_certs_file_inline)
1939 in = BIO_new_mem_buf((
char *)extra_certs_file, -1);
1943 in = BIO_new_file(extra_certs_file,
"r");
1972#warning BIO_DEBUG defined
1975static bool biofp_toggle;
1976static time_t biofp_last_open;
1977static const int biofp_reopen_interval = 600;
1992 const time_t current = time(NULL);
1993 const pid_t pid = getpid();
1995 if (biofp_last_open + biofp_reopen_interval < current)
2002 snprintf(fn,
sizeof(fn),
"bio/%d-%d.log", pid, biofp_toggle);
2003 biofp = fopen(fn,
"w");
2005 biofp_last_open = time(NULL);
2011bio_debug_data(
const char *mode, BIO *bio,
const uint8_t *buf,
int len,
const char *desc)
2017 fprintf(biofp,
"BIO_%s %s time=%" PRIi64
" bio=" ptr_format " len=%d data=%s\n", mode, desc,
2025bio_debug_oc(
const char *mode, BIO *bio)
2028 fprintf(biofp,
"BIO %s time=%" PRIi64
" bio=" ptr_format "\n", mode, (int64_t)time(NULL),
2039bio_write(BIO *bio,
const uint8_t *data,
int size,
const char *desc)
2053 bio_debug_data(
"write", bio, data, size, desc);
2055 i = BIO_write(bio, data, size);
2059 if (!BIO_should_retry(bio))
2116 int i = BIO_read(bio,
BPTR(buf), len);
2121 bio_debug_data(
"read", bio,
BPTR(buf), i, desc);
2127 if (!BIO_should_retry(bio))
2157 ks_ssl->
ssl = SSL_new(ssl_ctx->
ctx);
2172 bio_debug_oc(
"open ssl_bio", ks_ssl->
ssl_bio);
2173 bio_debug_oc(
"open ct_in", ks_ssl->
ct_in);
2174 bio_debug_oc(
"open ct_out", ks_ssl->
ct_out);
2179 SSL_set_accept_state(ks_ssl->
ssl);
2183 SSL_set_connect_state(ks_ssl->
ssl);
2187 BIO_set_ssl(ks_ssl->
ssl_bio, ks_ssl->
ssl, BIO_NOCLOSE);
2193 SSL_set_shutdown(ks_ssl->
ssl, SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN);
2202 bio_debug_oc(
"close ssl_bio", ks_ssl->
ssl_bio);
2203 bio_debug_oc(
"close ct_in", ks_ssl->
ct_in);
2204 bio_debug_oc(
"close ct_out", ks_ssl->
ct_out);
2206 BIO_free_all(ks_ssl->
ssl_bio);
2207 SSL_free(ks_ssl->
ssl);
2276 const char *curve =
"";
2277 const char *type =
"(error getting type)";
2285 int typeid = EVP_PKEY_id(pkey);
2286#if OPENSSL_VERSION_NUMBER < 0x30000000L
2287 bool is_ec =
typeid == EVP_PKEY_EC;
2289 bool is_ec = EVP_PKEY_is_a(pkey,
"EC");
2292#ifndef OPENSSL_NO_EC
2303 curve =
"(error getting curve name)";
2309#if OPENSSL_VERSION_NUMBER < 0x30000000L
2310 type = OBJ_nid2sn(
typeid);
2314 if (
typeid == EVP_PKEY_RSA)
2318 else if (
typeid == EVP_PKEY_DSA)
2322 else if (
typeid == EVP_PKEY_EC)
2325 type =
"EC, curve ";
2327 else if (type == NULL)
2329 type =
"unknown type";
2332 type = EVP_PKEY_get0_type_name(pkey);
2335 type =
"(error getting public key type)";
2340 snprintf(buf, buflen,
"%d bits %s%s", EVP_PKEY_bits(pkey), type, curve);
2352 EVP_PKEY *pkey = X509_get_pubkey(cert);
2353 char pkeybuf[64] = { 0 };
2356 char sig[128] = { 0 };
2357 int signature_nid = X509_get_signature_nid(cert);
2358 if (signature_nid != 0)
2360 snprintf(sig,
sizeof(sig),
", signature: %s", OBJ_nid2sn(signature_nid));
2363 snprintf(buf, buflen,
", peer certificate: %s%s", pkeybuf, sig);
2365 EVP_PKEY_free(pkey);
2371 EVP_PKEY *pkey = NULL;
2372 SSL_get_peer_tmp_key(ssl, &pkey);
2378 char pkeybuf[128] = { 0 };
2381 snprintf(buf, buflen,
", peer temporary key: %s", pkeybuf);
2383 EVP_PKEY_free(pkey);
2386#if !defined(LIBRESSL_VERSION_NUMBER) \
2387 || (defined(LIBRESSL_VERSION_NUMBER) && LIBRESSL_VERSION_NUMBER >= 0x3090000fL)
2412 return "(error getting name)";
2416 const char *type = OBJ_nid2sn(nid);
2422 type =
"(error getting name, OBJ_nid2sn failed)";
2437 int peer_sig_type_nid = NID_undef;
2438 const char *peer_sig_unknown =
"unknown";
2439 const char *peer_sig = peer_sig_unknown;
2440 const char *peer_sig_type =
"unknown type";
2449#if !defined(LIBRESSL_VERSION_NUMBER) \
2450 || (defined(LIBRESSL_VERSION_NUMBER) && LIBRESSL_VERSION_NUMBER >= 0x3090000fL)
2453 if (SSL_get_peer_signature_type_nid(ssl, &peer_sig_type_nid) && peer_sig_type_nid != NID_undef)
2459 if (peer_sig == peer_sig_unknown && peer_sig_type_nid == NID_undef)
2464 snprintf(buf, buflen,
", peer signing digest/type: %s %s", peer_sig, peer_sig_type);
2467#if OPENSSL_VERSION_NUMBER >= 0x30000000L
2469print_tls_key_agreement_group(SSL *ssl,
char *buf,
size_t buflen)
2471 const char *groupname = SSL_get0_group_name(ssl);
2474 snprintf(buf, buflen,
", key agreement: (error fetching group)");
2478 snprintf(buf, buflen,
", key agreement: %s", groupname);
2493 const SSL_CIPHER *ciph;
2500 s1[0] = s2[0] = s3[0] = s4[0] = s5[0] = 0;
2501 ciph = SSL_get_current_cipher(ks_ssl->
ssl);
2502 snprintf(s1,
sizeof(s1),
"%s %s, cipher %s %s", prefix, SSL_get_version(ks_ssl->
ssl),
2503 SSL_CIPHER_get_version(ciph), SSL_CIPHER_get_name(ciph));
2504 X509 *cert = SSL_get_peer_certificate(ks_ssl->
ssl);
2513#if OPENSSL_VERSION_NUMBER >= 0x30000000L
2514 print_tls_key_agreement_group(ks_ssl->
ssl, s5,
sizeof(s5));
2525 tls_ctx.
ctx = SSL_CTX_new(SSLv23_method());
2533 SSL_CTX_set_min_proto_version(tls_ctx.
ctx, TLS1_3_VERSION);
2538 SSL_CTX_set_max_proto_version(tls_ctx.
ctx, TLS1_2_VERSION);
2544 SSL *ssl = SSL_new(tls_ctx.
ctx);
2550#if defined(OPENSSL_IS_AWSLC) || defined(ENABLE_CRYPTO_WOLFSSL)
2551 STACK_OF(SSL_CIPHER) *sk = SSL_get_ciphers(ssl);
2553 STACK_OF(SSL_CIPHER) *sk = SSL_get1_supported_ciphers(ssl);
2557 const SSL_CIPHER *c = sk_SSL_CIPHER_value(sk, i);
2559 const char *cipher_name = SSL_CIPHER_get_name(c);
2566 printf(
"%s\n", cipher_name);
2568 else if (NULL == pair)
2571 printf(
"%s (No IANA name known to OpenVPN, use OpenSSL name.)\n", cipher_name);
2578 sk_SSL_CIPHER_free(sk);
2580 SSL_CTX_free(tls_ctx.
ctx);
2590 printf(
"Consider using 'openssl ecparam -list_curves' as alternative to running\n"
2592 "Note this output does only list curves/groups that OpenSSL considers as\n"
2593 "builtin EC curves. It does not list additional curves nor X448 or X25519\n");
2594#ifndef OPENSSL_NO_EC
2595 EC_builtin_curve *curves = NULL;
2599 crv_len = EC_get_builtin_curves(NULL, 0);
2601 if (EC_get_builtin_curves(curves, crv_len))
2603 printf(
"\nAvailable Elliptic curves/groups:\n");
2604 for (n = 0; n < crv_len; n++)
2607 sname = OBJ_nid2sn(curves[n].nid);
2613 printf(
"%s\n", sname);
2622 msg(
M_WARN,
"Your OpenSSL library was built without elliptic curve support. "
2623 "No curves available.");
2630 return OpenSSL_version(OPENSSL_VERSION);
2635#ifdef HAVE_XKEY_PROVIDER
2639 const char *name = OSSL_PROVIDER_get0_name(prov);
2640 OSSL_PROVIDER_load(dest_libctx, name);
2648 OSSL_PROVIDER_unload(prov);
2663#ifdef HAVE_XKEY_PROVIDER
2676 OSSL_PROVIDER_do_all(NULL, provider_load,
tls_libctx);
2679 if (!OSSL_PROVIDER_available(
tls_libctx,
"ovpn.xkey"))
2681 OSSL_PROVIDER_add_builtin(
tls_libctx,
"ovpn.xkey", xkey_provider_init);
2682 if (!OSSL_PROVIDER_load(
tls_libctx,
"ovpn.xkey"))
2684 msg(
M_NONFATAL,
"ERROR: failed loading external key provider: "
2685 "Signing with external keys will not work.");
2695 EVP_set_default_properties(
tls_libctx,
"?provider!=ovpn.xkey");
2706#ifdef HAVE_XKEY_PROVIDER
2709 OSSL_PROVIDER_do_all(
tls_libctx, provider_unload, NULL);
void * gc_malloc(size_t size, bool clear, struct gc_arena *a)
Allocate memory and, optionally, zero it.
char * string_alloc(const char *str, struct gc_arena *gc)
Duplicate a string, allocating memory under garbage collection.
Buffer management functions and garbage collection.
#define BPTR(buf)
Return a pointer to the start of the buffer content.
#define ALLOC_ARRAY_CLEAR_GC(dptr, type, n, gc)
Allocate and zero-initialise a garbage-collected array of n elements.
static int buf_forward_capacity(const struct buffer *buf)
Return the number of bytes that can still be appended to the buffer.
static void secure_memzero(void *data, size_t len)
Securely zeroise memory.
#define BLEN(buf)
Return the length of the buffer content in bytes.
static char * format_hex(const uint8_t *data, size_t size, size_t maxoutput, struct gc_arena *gc)
Format a binary buffer as a hex string with spaces every 4 bytes.
#define BLENZ(buf)
Return the length of the buffer content as a size_t.
static void check_malloc_return(void *p)
Abort if a memory allocation returned NULL.
static void gc_free(struct gc_arena *a)
Free all allocations in a garbage collection arena.
#define ALLOC_ARRAY(dptr, type, n)
Allocate memory for an array of n elements of the given type.
static struct gc_arena gc_new(void)
Allocate and return a new, empty garbage collection arena.
char * strsep(char **stringp, const char *delim)
const char * print_key_filename(const char *str, bool is_inline)
To be used when printing a string that may contain inline data.
void crypto_print_openssl_errors(const unsigned int flags)
Retrieve any occurred OpenSSL errors and print those errors.
#define crypto_msg(flags,...)
Retrieve any OpenSSL errors, then print the supplied error message.
int SSL_CTX_use_CryptoAPI_certificate(SSL_CTX *ssl_ctx, const char *cert_prop)
#define D_HANDSHAKE_VERBOSE
#define KS_PRIMARY
Primary key state index.
int key_state_read_plaintext(struct key_state_ssl *ks_ssl, struct buffer *buf)
Extract plaintext data from the TLS module.
int key_state_write_ciphertext(struct key_state_ssl *ks_ssl, struct buffer *buf)
Insert a ciphertext buffer into the TLS module.
int key_state_read_ciphertext(struct key_state_ssl *ks_ssl, struct buffer *buf)
Extract ciphertext data from the TLS module.
int key_state_write_plaintext_const(struct key_state_ssl *ks_ssl, const uint8_t *data, int len)
Insert plaintext data into the TLS module.
int key_state_write_plaintext(struct key_state_ssl *ks_ssl, struct buffer *buf)
Insert a plaintext buffer into the TLS module.
int verify_callback(void *session_obj, mbedtls_x509_crt *cert, int cert_depth, uint32_t *flags)
Verify that the remote OpenVPN peer's certificate allows setting up a VPN tunnel.
static int constrain_int(int x, int min, int max)
static SERVICE_STATUS status
void management_auth_failure(struct management *man, const char *type, const char *reason)
char * management_query_pk_sig(struct management *man, const char *b64_data, const char *algorithm)
#define VALGRIND_MAKE_READABLE(addr, len)
void purge_user_pass(struct user_pass *up, const bool force)
#define GET_USER_PASS_MANAGEMENT
#define GET_USER_PASS_PASSWORD_ONLY
static bool get_user_pass(struct user_pass *up, const char *auth_file, const char *prefix, const unsigned int flags)
Retrieves the user credentials from various sources depending on the flags.
OpenSSL compatibility stub.
static int SSL_get0_peer_signature_name(SSL *ssl, const char **sigalg)
static int EVP_PKEY_get_group_name(EVP_PKEY *pkey, char *gname, size_t gname_sz, size_t *gname_len)
#define PRI_OPENSSL_STACK
#define SSL_CTX_new_ex(libctx, propq, method)
Reduce SSL_CTX_new_ex() to SSL_CTX_new() for OpenSSL < 3.
int openvpn_base64_decode(const char *str, void *data, int size)
int openvpn_base64_encode(const void *data, int size, char **str)
int pem_password_callback(char *buf, int size, int rwflag, void *u)
Callback to retrieve the user's password.
Control Channel SSL library backend module.
Control Channel Common Data Structures.
#define SSLF_TLS_VERSION_MAX_SHIFT
#define UP_TYPE_PRIVATE_KEY
#define SSLF_CLIENT_CERT_OPTIONAL
#define SSLF_CLIENT_CERT_NOT_REQUIRED
#define SSLF_TLS_VERSION_MAX_MASK
#define SSLF_TLS_VERSION_MIN_SHIFT
#define SSLF_TLS_VERSION_MIN_MASK
void tls_ctx_set_tls_groups(struct tls_root_ctx *ctx, const char *groups)
Set the (elliptic curve) group allowed for signatures and key exchange.
void tls_ctx_free(struct tls_root_ctx *ctx)
Frees the library-specific TLSv1 context.
static int bio_read(BIO *bio, struct buffer *buf, const char *desc)
const char * get_ssl_library_version(void)
return a pointer to a static memory area containing the name and version number of the SSL library in...
static void openvpn_extkey_ec_finish(EC_KEY *ec)
static bool tls_ctx_set_tls_versions(struct tls_root_ctx *ctx, unsigned int ssl_flags)
static int bio_write(BIO *bio, const uint8_t *data, int size, const char *desc)
static int openvpn_extkey_rsa_finish(RSA *rsa)
static int tls_ctx_use_external_ec_key(struct tls_root_ctx *ctx, EVP_PKEY *pkey)
bool key_state_export_keying_material(struct tls_session *session, const char *label, size_t label_size, void *ekm, size_t ekm_size)
Keying Material Exporters [RFC 5705] allows additional keying material to be derived from existing TL...
void load_xkey_provider(void)
Some helper routines for provider load/unload.
static void print_pkey_details(EVP_PKEY *pkey, char *buf, size_t buflen)
static void print_server_tempkey(SSL *ssl, char *buf, size_t buflen)
static int rsa_pub_enc(int flen, const unsigned char *from, unsigned char *to, RSA *rsa, int padding)
static void tls_ctx_add_extra_certs(struct tls_root_ctx *ctx, BIO *bio, bool optional)
void show_available_tls_ciphers_list(const char *cipher_list, const char *tls_cert_profile, bool tls13)
Show the TLS ciphers that are available for us to use in the library depending on the TLS version.
static void * load_pkey_from_uri(const char *uri, SSL_CTX *ssl_ctx)
Load private key from OSSL_STORE URI or file uri : URI of object or filename ssl_ctx : SSL_CTX for UI...
void show_available_curves(void)
Show the available elliptic curves in the crypto library.
static uint16_t openssl_tls_version(unsigned int ver)
Convert internal version number to openssl version number.
void key_state_ssl_free(struct key_state_ssl *ks_ssl)
Free the SSL channel part of the given key state.
static int ecdsa_sign(int type, const unsigned char *dgst, int dgstlen, unsigned char *sig, unsigned int *siglen, const BIGNUM *kinv, const BIGNUM *r, EC_KEY *ec)
int tls_ctx_load_priv_file(struct tls_root_ctx *ctx, const char *priv_key_file, bool priv_key_file_inline)
Load private key file into the given TLS context.
static int cert_verify_callback(X509_STORE_CTX *ctx, void *arg)
void key_state_ssl_shutdown(struct key_state_ssl *ks_ssl)
Sets a TLS session to be shutdown state, so the TLS library will generate a shutdown alert.
void tls_ctx_load_extra_certs(struct tls_root_ctx *ctx, const char *extra_certs_file, bool extra_certs_file_inline)
Load extra certificate authority certificates from the given file or path.
static void print_peer_signature(SSL *ssl, char *buf, size_t buflen)
Get the type of the signature that is used by the peer during the TLS handshake.
OSSL_LIB_CTX * tls_libctx
static const char * get_sigtype(int nid)
Translate an OpenSSL NID into a more human readable name.
int mydata_index
Allocate space in SSL objects in which to store a struct tls_session pointer back to parent.
static void print_cert_details(X509 *cert, char *buf, size_t buflen)
Print human readable information about the certificate into buf.
static int ecdsa_sign_setup(EC_KEY *ec, BN_CTX *ctx_in, BIGNUM **kinvp, BIGNUM **rp)
void tls_ctx_check_cert_time(const struct tls_root_ctx *ctx)
Check our certificate notBefore and notAfter fields, and warn if the cert is either not yet valid or ...
void tls_ctx_restrict_ciphers_tls13(struct tls_root_ctx *ctx, const char *ciphers)
Restrict the list of ciphers that can be used within the TLS context for TLS 1.3 and higher.
static bool cert_uri_supported(void)
static int rsa_priv_dec(int flen, const unsigned char *from, unsigned char *to, RSA *rsa, int padding)
#define INFO_CALLBACK_SSL_CONST
static int rsa_pub_dec(int flen, const unsigned char *from, unsigned char *to, RSA *rsa, int padding)
static void bio_write_post(const int status, struct buffer *buf)
int tls_ctx_load_pkcs12(struct tls_root_ctx *ctx, const char *pkcs12_file, bool pkcs12_file_inline, bool load_ca_file)
Load PKCS #12 file for key, cert and (optionally) CA certs, and add to library-specific TLS context.
bool tls_ctx_initialised(struct tls_root_ctx *ctx)
Checks whether the given TLS context is initialised.
void key_state_ssl_init(struct key_state_ssl *ks_ssl, const struct tls_root_ctx *ssl_ctx, bool is_server, struct tls_session *session)
Initialise the SSL channel part of the given key state.
void tls_free_lib(void)
Free any global SSL library-specific data structures.
static void unload_xkey_provider(void)
Undo steps in load_xkey_provider.
const char * get_rsa_padding_name(const int padding)
void tls_ctx_load_ecdh_params(struct tls_root_ctx *ctx, const char *curve_name)
Load Elliptic Curve Parameters, and load them into the library-specific TLS context.
static int get_sig_from_man(const unsigned char *dgst, unsigned int dgstlen, unsigned char *sig, unsigned int siglen, const char *algorithm)
Pass the input hash in 'dgst' to management and get the signature back.
static void tls_ctx_load_cert_uri(struct tls_root_ctx *tls_ctx, const char *uri)
static int rsa_priv_enc(int flen, const unsigned char *from, unsigned char *to, RSA *rsa, int padding)
static void convert_tls_list_to_openssl(char *openssl_ciphers, size_t len, const char *ciphers)
static void tls_ctx_load_cert_pem_file(struct tls_root_ctx *ctx, const char *cert_file, bool cert_file_inline)
void tls_init_lib(void)
Perform any static initialisation necessary by the library.
void print_details(struct key_state_ssl *ks_ssl, const char *prefix)
Print a one line summary of SSL/TLS session handshake.
static void info_callback(INFO_CALLBACK_SSL_CONST SSL *s, int where, int ret)
int tls_version_max(void)
Return the maximum TLS version (as a TLS_VER_x constant) supported by current SSL implementation.
void backend_tls_ctx_reload_crl(struct tls_root_ctx *ssl_ctx, const char *crl_file, bool crl_inline)
Reload the Certificate Revocation List for the SSL channel.
void tls_ctx_restrict_ciphers(struct tls_root_ctx *ctx, const char *ciphers)
Restrict the list of ciphers that can be used within the TLS context for TLS 1.2 and below.
void tls_ctx_load_ca(struct tls_root_ctx *ctx, const char *ca_file, bool ca_file_inline, const char *ca_path, bool tls_server)
Load certificate authority certificates from the given file or path.
void tls_ctx_set_cert_profile(struct tls_root_ctx *ctx, const char *profile)
Set the TLS certificate profile.
int tls_ctx_use_management_external_key(struct tls_root_ctx *ctx)
Tell the management interface to load the given certificate and the external private key matching the...
static int tls_ctx_use_external_rsa_key(struct tls_root_ctx *ctx, EVP_PKEY *pkey)
static ECDSA_SIG * ecdsa_sign_sig(const unsigned char *dgst, int dgstlen, const BIGNUM *in_kinv, const BIGNUM *in_r, EC_KEY *ec)
void tls_ctx_load_cryptoapi(struct tls_root_ctx *ctx, const char *cryptoapi_cert)
Use Windows cryptoapi for key and cert, and add to library-specific TLS context.
bool tls_ctx_set_options(struct tls_root_ctx *ctx, unsigned int ssl_flags)
Set any library specific options.
void tls_ctx_load_dh_params(struct tls_root_ctx *ctx, const char *dh_file, bool dh_file_inline)
Load Diffie Hellman Parameters, and load them into the library-specific TLS context.
void tls_ctx_new(struct tls_root_ctx *ctx)
Initialise a library-specific TLS context.
static int sk_x509_name_cmp(const X509_NAME *const *a, const X509_NAME *const *b)
void tls_ctx_load_cert_file(struct tls_root_ctx *ctx, const char *cert_file, bool cert_file_inline)
Load certificate file into the given TLS context.
int get_num_elements(const char *string, char delimiter)
Returns the occurrences of 'delimiter' in a string +1 This is typically used to find out the number e...
const tls_cipher_name_pair * tls_get_cipher_name_pair(const char *cipher_name, size_t len)
Control Channel Verification Module OpenSSL backend.
Wrapper structure for dynamically allocated memory.
int len
Length in bytes of the actual content within the allocated memory.
Garbage collection arena used to keep track of dynamically allocated memory.
Get a tls_cipher_name_pair containing OpenSSL and IANA names for supplied TLS cipher name.
const char * openssl_name
Structure that wraps the TLS context.
Security parameter state of a single session within a VPN tunnel.
char password[USER_PASS_LEN]
static int cleanup(void **state)