/* Sets |*certVerifyAlg| to the expected_cert_verify_algorithm field from the *serializedDC|in|.ReturnsSECSuccessuponsuccess;SECFailureindicatesa *decodingfailureortheinputwasn'tlongenough.
*/ static SECStatus
tls13_GetExpectedCertVerifyAlg(SECItem in, SSLSignatureScheme *certVerifyAlg)
{
SECStatus rv;
PRUint64 n;
sslReader rdr = SSL_READER(in.data, in.len);
if (in.len < 6) { /* Buffer too short to contain the first two params. */ return SECFailure;
}
/* Returns PR_TRUE if the host is verifying the handshake with a DC. */
PRBool
tls13_IsVerifyingWithDelegatedCredential(const sslSocket *ss)
{ /* We currently do not support client-delegated credentials. */ if (ss->sec.isServer ||
!ss->opt.enableDelegatedCredentials ||
!ss->xtnData.peerDelegCred) { return PR_FALSE;
}
return PR_TRUE;
}
/* Returns PR_TRUE if the host is signing the handshake with a DC. */
PRBool
tls13_IsSigningWithDelegatedCredential(const sslSocket *ss)
{ if (!ss->sec.isServer ||
!ss->xtnData.sendingDelegCredToPeer ||
!ss->xtnData.peerRequestedDelegCred) { return PR_FALSE;
}
return PR_TRUE;
}
/* Commits to authenticating with a DC if all of the following conditions hold: *-thenegotiatedprotocolisTLS1.3ornewer; *-theselectedcertificatehasaDCconfigured; *-thepeerhasindicatedsupportforthisextension; *-thepeerhasindicatedsupportfortheDCsignaturescheme;and *-thehostsupportstheDCsignaturescheme. * *It'sthecaller'sresponsibilitytoensurethattheversionhasbeen *negotiatedandthecertificatehasbeenselected.
*/
SECStatus
tls13_MaybeSetDelegatedCredential(sslSocket *ss)
{
SECStatus rv;
PRBool doesRsaPss;
SECKEYPrivateKey *priv;
SSLSignatureScheme scheme;
/* Assert that the host is the server (we do not currently support *client-delegatedcredentials),thecertificatehasbeen *chosen,TLS1.3orhigherhasbeennegotiated,andthatthesetof *signatureschemessupportedbytheclientisknown.
*/
PORT_Assert(ss->sec.isServer);
PORT_Assert(ss->sec.serverCert);
PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
PORT_Assert(ss->xtnData.peerRequestedDelegCred == !!ss->xtnData.delegCredSigSchemes);
/* Check that the peer has indicated support and that a DC has been *configuredfortheselectedcertificate.
*/ if (!ss->xtnData.peerRequestedDelegCred ||
!ss->xtnData.delegCredSigSchemes ||
!ss->sec.serverCert->delegCred.len ||
!ss->sec.serverCert->delegCredKeyPair) { return SECSuccess;
}
/* Check that the host and peer both support the signing algorithm used with *theDC.
*/
rv = tls13_GetExpectedCertVerifyAlg(ss->sec.serverCert->delegCred,
&scheme); if (rv != SECSuccess) { return SECFailure;
}
/* Commit to sending a DC and set the handshake signature scheme to the *indicatedalgorithm.
*/
ss->xtnData.sendingDelegCredToPeer = PR_TRUE;
ss->ssl3.hs.signatureScheme = scheme; return SECSuccess;
}
/* Serializes the DC up to the signature. */ static SECStatus
tls13_AppendCredentialParams(sslBuffer *buf, sslDelegatedCredential *dc)
{
SECStatus rv;
rv = sslBuffer_AppendNumber(buf, dc->validTime, 4); if (rv != SECSuccess) { return SECFailure; /* Error set by caller. */
}
/* The certificate must have the delegationUsage extension that authorizes *ittonegotiatedelegatedcredentials.
*/
found = PR_FALSE; for (i = 0; cert->extensions[i] != NULL; i++) {
ext = cert->extensions[i]; if (SECITEM_CompareItem(&ext->id, &delegUsageOid) == SECEqual) {
found = PR_TRUE; break;
}
}
/* The certificate must also have the digitalSignature keyUsage set. */ if (!found ||
!cert->keyUsagePresent ||
!(cert->keyUsage & KU_DIGITAL_SIGNATURE)) {
FATAL_ERROR(ss, SSL_ERROR_DC_INVALID_KEY_USAGE, illegal_parameter); return SECFailure;
}
end = start + ((PRTime)dc->validTime * PR_USEC_PER_SEC);
now = ssl_Time(ss); if (now > end || end < 0) {
FATAL_ERROR(ss, SSL_ERROR_DC_EXPIRED, illegal_parameter); return SECFailure;
}
/* Not more than 7 days remaining in the validity period. */ if (end - now > kMaxDcValidity) {
FATAL_ERROR(ss, SSL_ERROR_DC_INAPPROPRIATE_VALIDITY_PERIOD, illegal_parameter); return SECFailure;
}
return SECSuccess;
}
/* Returns SECSucces if |dc| is a DC for the current handshake; otherwise it *returnsSECFailure.AvalidDCmeetsthreerequirements:(1)thesignature *wasproducedbythepeer'send-entitycertificate,(2)theend-entity *certificatemusthavethecorrectkeyusage,and(3)theDCmustnotbe *expiredanditsremainingTTLmustbe<=themaximumvalidityperiod(fixed *as7days). * *ThisfunctioncallsFATAL_ERROR()whenanerroroccurs.
*/
SECStatus
tls13_VerifyDelegatedCredential(sslSocket *ss,
sslDelegatedCredential *dc)
{
SECStatus rv;
PRTime start;
PRExplodedTime end;
CERTCertificate *cert = ss->sec.peerCert; char endStr[256];
static CERTSubjectPublicKeyInfo *
tls13_MakeDcSpki(const SECKEYPublicKey *dcPub, SSLSignatureScheme dcCertVerifyAlg)
{ switch (SECKEY_GetPublicKeyType(dcPub)) { case rsaKey: {
SECOidTag hashOid; switch (dcCertVerifyAlg) { /* Note: RSAE schemes are NOT permitted within DC SPKIs. However, *supportfortheirissuanceremainssoastoenablenegative
* testing of client behavior. */ case ssl_sig_rsa_pss_rsae_sha256: case ssl_sig_rsa_pss_rsae_sha384: case ssl_sig_rsa_pss_rsae_sha512: return SECKEY_CreateSubjectPublicKeyInfo(dcPub); case ssl_sig_rsa_pss_pss_sha256:
hashOid = SEC_OID_SHA256; break; case ssl_sig_rsa_pss_pss_sha384:
hashOid = SEC_OID_SHA384; break; case ssl_sig_rsa_pss_pss_sha512:
hashOid = SEC_OID_SHA512; break;
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.