diff --git a/BRANCHES.md b/BRANCHES.md index 8abb39cefb..cce737cd25 100644 --- a/BRANCHES.md +++ b/BRANCHES.md @@ -88,9 +88,9 @@ The following branches are currently maintained: - [`development`](https://github.com/Mbed-TLS/mbedtls/) - [`mbedtls-3.6`](https://github.com/Mbed-TLS/mbedtls/tree/mbedtls-3.6) maintained until March 2027, see - . + . - [`mbedtls-4.1`](https://github.com/Mbed-TLS/mbedtls/tree/mbedtls-4.1) maintained until March 2029, see - . + . Users are urged to always use the latest version of a maintained branch. diff --git a/CMakeLists.txt b/CMakeLists.txt index c6d076346c..1c9b2c4b55 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -37,7 +37,7 @@ cmake_policy(SET CMP0011 NEW) # is deprecated and will be removed in future versions. cmake_policy(SET CMP0012 NEW) -set(MBEDTLS_VERSION 4.1.0) +set(MBEDTLS_VERSION 4.1.1) set(MBEDTLS_CRYPTO_SOVERSION 18) set(MBEDTLS_X509_SOVERSION 9) set(MBEDTLS_TLS_SOVERSION 23) diff --git a/ChangeLog b/ChangeLog index b7a79ce348..4212640731 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,5 +1,107 @@ Mbed TLS ChangeLog (Sorted per branch, date) += Mbed TLS 4.1.1 branch released 2026-07-07 + +Features + * Restore DESTDIR support for CMake installs of compatibility + libmbedcrypto symlinks. Fixes #10627. + * SHA3-256, SHA3-384 and SHA3-512 are now accepted in the default X.509 + certificate profile. + +Security + * Added advice about compiler options in SECURITY.md. + * Fix a bug where transcript-hash computation errors during TLS 1.2 + extended master secret calculation could be ignored instead of causing the + handshake to fail. This could allow a handshake to continue with a master + secret that was not correctly bound to the handshake transcript, + undermining the security guarantees of the extended master secret + extension. Report by Mathew Gretton-Dann. CVE-2026-50581 + * Fix a TLS 1.3 server-side error-handling bug affecting session ticket + generation. Under rare conditions, such as memory allocation failures + while computing the resumption master secret, the server could issue + invalid session tickets instead of failing the handshake. Clients + presented with such tickets would fail session resumption and fall back to + a full handshake. In deployments relying on session resumption, repeated + occurrences could increase the frequency of full handshakes and amplify + resource consumption during periods of resource exhaustion or other + transient failures. Reported by jjfz123. + CVE-2026-50640 + * Fixed a TLS 1.3 record-boundary validation issue that could allow + unauthenticated plaintext data to be processed across a key change. In + servers with MBEDTLS_SSL_EARLY_DATA enabled, this could be exploited by a + man-in-the-middle attacker to cause loss of 0-RTT early data. + Reported by Ben Smyth. + * Fix a remote buffer overflow in (D)TLS with ECDHE-PSK cipher suites when + CBC is disabled. Reported by Karnakar Reddy. CVE-ID-50580 + * Fix a potential information disclosure in TLS 1.2 servers using session + tickets. If the session ticket write callback failed without setting the + lifetime output parameter, Mbed TLS could send 4 bytes of uninitialized + stack memory to the peer in the NewSessionTicket message. Fixes #1570. + Reported by James Love. CVE-2026-50586. + * Fix an out-of-bounds read when parsing TLS 1.2 ECJPAKE ServerKeyExchange + messages. Reported-by Biniam Demissie. + CVE-2026-50588 + * Fix a use-after-free/double-free risk in mbedtls_pkcs7_free() when reusing + an mbedtls_pkcs7 context across parse -> free -> parse -> free cycles. The + function now resets the context after freeing it, ensuring stale + signed_data.signers.next pointers cannot be walked by a later free + operation. CVE-2026-50579 + * PKCS7 now rejects weak hash algorithms (RIPEMD160, MD5, SHA-1, SHA-224, + SHA3-224) on signature verification. The new configuration option + MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES allows to keep using weak hash + algorithms in PKCS7 for backward compatibility purposes. + * Improved documentation of mbedtls_ssl_conf_sig_algs() to emphasize that + this function only sets signature algorithms that are enforced during + TLS key exchange and not on certificate verification. Reported by + Xiangdong Li, Beijing University of Posts and Telecommunications (BUPT). + CVE-2026-54441 + * Ensure 'badmac_seen' and 'dtls_srtp_info' fields from 'mbedtls_ssl_context' + are properly zeroized when mbedtls_ssl_session_reset() is called. This + could cause premature DTLS connection failure or incorrect DTLS-SRTP + parameter inheritance for applications reusing an SSL context. + Reported by jjfz123. CVE-2026-50585. + * Fix a bug where mbedtls_ssl_read() and mbedtls_ssl_write() could return + 1 instead of an error code if the random generator failed when a server + called these functions before the end of a TLS 1.3 handshake. + Reported by Mohammad Seet (mhdsait101). + * Fix TLS 1.3 clients to reject a HelloRetryRequest whose selected group was + not advertised in the original ClientHello. Reported independently by + Din Asotić / Xiangdong Li, Beijing University of Posts and + Telecommunications (BUPT), and NVIDIA Project Vanessa. + CVE-2026-25832. + * Fix two bugs in the X.509 certificate parser that caused some inputs + with a malformed basicConstraints extension to be accepted. This + could have dangerous results, in particular causing some certificates + to be parsed as CA certificates when other X.509 implementations would + parse them as end-entity certificates. Reported by Mohammad Seet + (mhdsait101), Pablo Ruiz García and NVIDIA Project Vanessa. CVE-2026-49300 + +Bugfix + * Fix a TLS 1.2 regression that caused clients to reject valid + ServerKeyExchange signatures using RSA-PSS signature algorithms. + Fixes #10668. + * Fix a build error using the LLVM based MinGW toolchain. + Bug reported and fix contributed by valord577. + * Fixed a bug which prevented the inclusion of standard C library header + files from the user provided configuration file. Fixes #10740. + * Reject malformed TLS 1.3 serialized sessions instead of accepting + unterminated strings or extra trailing data. + * Reject serialized SSL contexts whose DTLS Connection ID length exceeds + the maximum supported size, instead of overflowing the internal buffer. + * Fixed documentation of mbedtls_ssl_set_cid(): the set CID configuration + is applied to all subsequent handshakes, not just to the next one. + * Reject malformed X.509 CSRs where the extensionRequest attribute + wrappers do not exactly contain the requested extensions. + +Changes + * Upgraded TF-PSA-Crypto from 1.1.0 to 1.1.1. See tf-psa-crypto/ChangeLog. + * X.509 certificates with a basicConstraints extension starting with an + INTEGER field are no longer accepted. According to RFC 5280, such + certificates are syntactically valid and the first field is the + pathLenConstraint value, but certificate authorities must not emit such + certificates. Mbed TLS interpreted it as a cA value, which was nonstandard + and dangerous. + = Mbed TLS 4.1.0 branch released 2026-03-31 API changes diff --git a/ChangeLog.d/cmake-destdir-instal.txt b/ChangeLog.d/cmake-destdir-instal.txt deleted file mode 100644 index 1638a4bea9..0000000000 --- a/ChangeLog.d/cmake-destdir-instal.txt +++ /dev/null @@ -1,3 +0,0 @@ -Features - * Restore DESTDIR support for CMake installs of compatibility - libmbedcrypto symlinks. Fixes #10627. diff --git a/ChangeLog.d/fix-tls12-rsa-pss-sigalgs.txt b/ChangeLog.d/fix-tls12-rsa-pss-sigalgs.txt deleted file mode 100644 index 34296b602e..0000000000 --- a/ChangeLog.d/fix-tls12-rsa-pss-sigalgs.txt +++ /dev/null @@ -1,4 +0,0 @@ -Bugfix - * Fix a TLS 1.2 regression that caused clients to reject valid - ServerKeyExchange signatures using RSA-PSS signature algorithms. - Fixes #10668. diff --git a/ChangeLog.d/issue10740.txt b/ChangeLog.d/issue10740.txt deleted file mode 100644 index eb7a36c063..0000000000 --- a/ChangeLog.d/issue10740.txt +++ /dev/null @@ -1,3 +0,0 @@ -Bugfix - * Fixed a bug which prevented the inclusion of standard C library header - files from the user provided configuration file. Fixes #10740. diff --git a/ChangeLog.d/pr_10695__fix_build_llvm_mingw.txt b/ChangeLog.d/pr_10695__fix_build_llvm_mingw.txt deleted file mode 100644 index 3fed87143f..0000000000 --- a/ChangeLog.d/pr_10695__fix_build_llvm_mingw.txt +++ /dev/null @@ -1,3 +0,0 @@ -Bugfix - * Fix a build error using the LLVM based MinGW toolchain. - Bug reported and fix contributed by valord577. diff --git a/ChangeLog.d/security-advice.txt b/ChangeLog.d/security-advice.txt deleted file mode 100644 index 1f7677a882..0000000000 --- a/ChangeLog.d/security-advice.txt +++ /dev/null @@ -1,2 +0,0 @@ -Security - * Added advice about compiler options in SECURITY.md. diff --git a/ChangeLog.d/serialized-data-load-hardening.txt b/ChangeLog.d/serialized-data-load-hardening.txt deleted file mode 100644 index e068988dac..0000000000 --- a/ChangeLog.d/serialized-data-load-hardening.txt +++ /dev/null @@ -1,5 +0,0 @@ -Bugfix - * Reject malformed TLS 1.3 serialized sessions instead of accepting - unterminated strings or extra trailing data. - * Reject serialized SSL contexts whose DTLS Connection ID length exceeds - the maximum supported size, instead of overflowing the internal buffer. diff --git a/doxygen/input/doc_mainpage.h b/doxygen/input/doc_mainpage.h index b28b82b851..74799cf81e 100644 --- a/doxygen/input/doc_mainpage.h +++ b/doxygen/input/doc_mainpage.h @@ -10,7 +10,7 @@ */ /** - * @mainpage Mbed TLS v4.1.0 API Documentation + * @mainpage Mbed TLS v4.1.1 API Documentation * * This documentation describes the application programming interface (API) * of Mbed TLS. diff --git a/doxygen/mbedtls.doxyfile b/doxygen/mbedtls.doxyfile index c6a5e4f4fd..f2d5f2f83b 100644 --- a/doxygen/mbedtls.doxyfile +++ b/doxygen/mbedtls.doxyfile @@ -1,4 +1,4 @@ -PROJECT_NAME = "Mbed TLS v4.1.0" +PROJECT_NAME = "Mbed TLS v4.1.1" OUTPUT_DIRECTORY = ../apidoc/ FULL_PATH_NAMES = NO OPTIMIZE_OUTPUT_FOR_C = YES diff --git a/framework b/framework index e79f4fdd48..a307955223 160000 --- a/framework +++ b/framework @@ -1 +1 @@ -Subproject commit e79f4fdd4877e79a92e6b1e5965132ff0c5cc729 +Subproject commit a3079552234917a9831dd70693983af5e62c70de diff --git a/include/mbedtls/build_info.h b/include/mbedtls/build_info.h index e077bbce40..e83b7e99e2 100644 --- a/include/mbedtls/build_info.h +++ b/include/mbedtls/build_info.h @@ -28,16 +28,16 @@ */ #define MBEDTLS_VERSION_MAJOR 4 #define MBEDTLS_VERSION_MINOR 1 -#define MBEDTLS_VERSION_PATCH 0 +#define MBEDTLS_VERSION_PATCH 1 /** * The single version number has the following structure: * MMNNPP00 * Major version | Minor version | Patch version */ -#define MBEDTLS_VERSION_NUMBER 0x04010000 -#define MBEDTLS_VERSION_STRING "4.1.0" -#define MBEDTLS_VERSION_STRING_FULL "Mbed TLS 4.1.0" +#define MBEDTLS_VERSION_NUMBER 0x04010100 +#define MBEDTLS_VERSION_STRING "4.1.1" +#define MBEDTLS_VERSION_STRING_FULL "Mbed TLS 4.1.1" #if defined(MBEDTLS_CONFIG_FILES_READ) #error "Something went wrong: MBEDTLS_CONFIG_FILES_READ defined before reading the config files!" diff --git a/include/mbedtls/mbedtls_config.h b/include/mbedtls/mbedtls_config.h index a38b61c147..038a483de3 100644 --- a/include/mbedtls/mbedtls_config.h +++ b/include/mbedtls/mbedtls_config.h @@ -1036,6 +1036,15 @@ */ #define MBEDTLS_PKCS7_C +/** + * \def MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES + * + * Allow weak signature algorithms (RIPEMD160, MD5, SHA-1) in PKCS#7. + * + * Requires: MBEDTLS_PKCS7_C + */ +// #define MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES + /** * \def MBEDTLS_X509_CREATE_C * diff --git a/include/mbedtls/pkcs7.h b/include/mbedtls/pkcs7.h index 957ca53d71..f2da99021c 100644 --- a/include/mbedtls/pkcs7.h +++ b/include/mbedtls/pkcs7.h @@ -31,6 +31,12 @@ * assumed these fields are empty. * - The RFC allows for the signed Data type to contain contentInfo. This * implementation assumes the type is DATA and the content is empty. + * - The RFC doesn't put any constrain on the hash algorithm to be used, but + * this implementation by default rejects weak hash algorithms (i.e. RIPEMD160, + * MD5, SHA-1, SHA-224, SHA3-224). In general accepted hash algorithms + * are the ones belonging to ::mbedtls_x509_crt_profile_default. + * #MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES can be enabled to accept all + * supported hash algorithms. */ #ifndef MBEDTLS_PKCS7_H @@ -190,6 +196,9 @@ int mbedtls_pkcs7_parse_der(mbedtls_pkcs7 *pkcs7, const unsigned char *buf, * \note This function internally calculates the hash on the supplied * plain data for signature verification. * + * \note For limitation on the supported hash algorithms, please refer + * to the note at the top of this document. + * * \return 0 if the signature verifies, or a negative error code on failure. */ int mbedtls_pkcs7_signed_data_verify(mbedtls_pkcs7 *pkcs7, @@ -219,6 +228,9 @@ int mbedtls_pkcs7_signed_data_verify(mbedtls_pkcs7 *pkcs7, * \note This function is different from mbedtls_pkcs7_signed_data_verify() * in that it is directly passed the hash of the data. * + * \note For limitation on the supported hash algorithms, please refer + * to the note at the top of this document. + * * \return 0 if the signature verifies, or a negative error code on failure. */ int mbedtls_pkcs7_signed_hash_verify(mbedtls_pkcs7 *pkcs7, diff --git a/include/mbedtls/ssl.h b/include/mbedtls/ssl.h index 3a69df5466..00e28442d6 100644 --- a/include/mbedtls/ssl.h +++ b/include/mbedtls/ssl.h @@ -1324,6 +1324,15 @@ typedef union { void *p; /* typically a pointer to extra data */ } mbedtls_ssl_user_data_t; +/** + * Added at the end of "struct mbedtls_ssl_config" and "struct mbedtls_ssl_context" + * to reserve a field for future use. + */ +typedef union { + size_t number; + void *ptr; +} mbedtls_ssl_unused_data_t; + /** * SSL/TLS configuration to be shared between mbedtls_ssl_context structures. */ @@ -1572,13 +1581,20 @@ struct mbedtls_ssl_config { const mbedtls_x509_crt *MBEDTLS_PRIVATE(dn_hints);/*!< acceptable client cert issuers */ #endif - /* Unused field reserved for future use */ - union { - size_t number; - void *ptr; - } MBEDTLS_PRIVATE(unused); + mbedtls_ssl_unused_data_t MBEDTLS_PRIVATE(unused); }; +/* + * Warning: whenever a change is applied to "mbedtls_ssl_context" please re-run + * the script "tests/scripts/generate_ssl_session_reset_check.py". + * Please note that this script has some limitation that should be considered + * when modifing "mbedtls_ssl_context": + * - Parsed structure must start with struct "mbedtls_ssl_context {" + * (not "typedef struct {"). + * - It must end with "}}" in column 0. + * - Must not contain "#else" or "#elif" conditionals. + * - Must not contain nested struct/union/enum definitions. + */ struct mbedtls_ssl_context { const mbedtls_ssl_config *MBEDTLS_PRIVATE(conf); /*!< configuration information */ @@ -1861,11 +1877,7 @@ struct mbedtls_ssl_context { */ mbedtls_ssl_user_data_t MBEDTLS_PRIVATE(user_data); - /* Unused field reserved for future use */ - union { - size_t number; - void *ptr; - } MBEDTLS_PRIVATE(unused); + mbedtls_ssl_unused_data_t MBEDTLS_PRIVATE(unused); }; /** @@ -2169,7 +2181,7 @@ void mbedtls_ssl_set_bio(mbedtls_ssl_context *ssl, /** * \brief Configure the use of the Connection ID (CID) - * extension in the next handshake. + * extension in subsequent handshakes. * * Reference: RFC 9146 (or draft-ietf-tls-dtls-connection-id-05 * https://tools.ietf.org/html/draft-ietf-tls-dtls-connection-id-05 @@ -2190,7 +2202,7 @@ void mbedtls_ssl_set_bio(mbedtls_ssl_context *ssl, * headers of outgoing messages. * * This API enables or disables the use of the CID extension - * in the next handshake and sets the value of the CID to + * in subsequent handshakes and sets the value of the CID to * be used for incoming messages. * * \param ssl The SSL context to configure. This must be initialized. @@ -2221,11 +2233,11 @@ void mbedtls_ssl_set_bio(mbedtls_ssl_context *ssl, * successful call to this function to run the handshake. * * \note This call cannot guarantee that the use of the CID - * will be successfully negotiated in the next handshake, + * will be successfully negotiated in subsequent handshakes, * because the peer might not support it. Specifically: * - On the Client, enabling the use of the CID through - * this call implies that the `ClientHello` in the next - * handshake will include the CID extension, thereby + * this call implies that the `ClientHello` in subsequent + * handshakes will include the CID extension, thereby * offering the use of the CID to the server. Only if * the `ServerHello` contains the CID extension, too, * the CID extension will actually be put to use. @@ -2248,7 +2260,7 @@ void mbedtls_ssl_set_bio(mbedtls_ssl_context *ssl, * Mbed TLS. * * \return \c 0 on success. In this case, the CID configuration - * applies to the next handshake. + * applies to subsequent handshakes. * \return A negative error code on failure. */ int mbedtls_ssl_set_cid(mbedtls_ssl_context *ssl, @@ -3411,7 +3423,7 @@ int mbedtls_ssl_conf_cid(mbedtls_ssl_config *conf, size_t len, * * \note The restrictions are enforced for all certificates in the * chain. However, signatures in the handshake are not covered - * by this setting but by \b mbedtls_ssl_conf_sig_algs(). + * by this setting but by \c mbedtls_ssl_conf_sig_algs(). * * \param conf SSL configuration * \param profile Profile to use @@ -3899,7 +3911,12 @@ void mbedtls_ssl_conf_groups(mbedtls_ssl_config *conf, #if defined(MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED) /** - * \brief Configure allowed signature algorithms for use in TLS + * \brief Configure allowed signature algorithms for use in TLS key + * exchange. + * + * \note This only covers signature algorithms used in the key + * exchange. To also enforce restrictions in certificate verification + * refer to \c mbedtls_ssl_conf_cert_profile(). * * \param conf The SSL configuration to use. * \param sig_algs List of allowed IANA values for TLS 1.3 signature algorithms, diff --git a/library/pkcs7.c b/library/pkcs7.c index 2cc7812bf0..6346cdc6b0 100644 --- a/library/pkcs7.c +++ b/library/pkcs7.c @@ -665,6 +665,20 @@ static int mbedtls_pkcs7_data_or_hash_verify(mbedtls_pkcs7 *pkcs7, return ret; } +#if !defined(MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES) + /* Ensure the MD alg from the PKCS#7 context and signature algorithm from + * the certificate belong to the list of secure algorithms + * (i.e. mbedtls_x509_crt_profile_default). */ + ret = mbedtls_x509_profile_check_md_alg(&mbedtls_x509_crt_profile_default, md_alg); + if (ret != 0) { + return MBEDTLS_ERR_PKCS7_INVALID_ALG; + } + ret = mbedtls_x509_profile_check_pk_alg(&mbedtls_x509_crt_profile_default, cert->sig_pk); + if (ret != 0) { + return MBEDTLS_ERR_PKCS7_INVALID_ALG; + } +#endif /* MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES */ + md_info = mbedtls_md_info_from_type(md_alg); if (md_info == NULL) { return MBEDTLS_ERR_PKCS7_VERIFY_FAIL; @@ -766,7 +780,7 @@ void mbedtls_pkcs7_free(mbedtls_pkcs7 *pkcs7) mbedtls_free(signer_prev); } - pkcs7->raw.p = NULL; + mbedtls_platform_zeroize(pkcs7, sizeof(*pkcs7)); } #endif diff --git a/library/ssl_client.c b/library/ssl_client.c index 6fe6dd8fe6..354fe9b72b 100644 --- a/library/ssl_client.c +++ b/library/ssl_client.c @@ -208,6 +208,10 @@ static int ssl_write_alpn_ext(mbedtls_ssl_context *ssl, * generalization of the TLS 1.2 supported elliptic curves extension. They both * share the same extension identifier. * + * If the TLS 1.3 logic for selecting proposed groups changes, the TLS 1.3 + * group filtering in the function `ssl_tls13_parse_hrr_key_share_ext()` must + * be updated accordingly. + * */ #define SSL_WRITE_SUPPORTED_GROUPS_EXT_TLS1_2_FLAG 1 #define SSL_WRITE_SUPPORTED_GROUPS_EXT_TLS1_3_FLAG 2 @@ -251,8 +255,8 @@ static int ssl_write_supported_groups_ext(mbedtls_ssl_context *ssl, if (flags & SSL_WRITE_SUPPORTED_GROUPS_EXT_TLS1_3_FLAG) { #if defined(PSA_WANT_ALG_ECDH) if (mbedtls_ssl_tls13_named_group_is_ecdhe(*group_list) && - (mbedtls_ssl_get_ecp_group_id_from_tls_id(*group_list) != - MBEDTLS_ECP_DP_NONE)) { + mbedtls_ssl_get_psa_curve_info_from_tls_id( + *group_list, NULL, NULL) == PSA_SUCCESS) { propose_group = 1; } #endif diff --git a/library/ssl_tls.c b/library/ssl_tls.c index cb14275d1e..0195576213 100644 --- a/library/ssl_tls.c +++ b/library/ssl_tls.c @@ -29,7 +29,6 @@ #include #include "mbedtls/psa_util.h" -#include "md_psa.h" // for mbedtls_md_error_from_psa() #include "psa/crypto.h" #if defined(MBEDTLS_X509_CRT_PARSE_C) @@ -846,21 +845,21 @@ int mbedtls_ssl_reset_checksum(mbedtls_ssl_context *ssl) #if defined(PSA_WANT_ALG_SHA_256) status = psa_hash_abort(&ssl->handshake->fin_sha256_psa); if (status != PSA_SUCCESS) { - return mbedtls_md_error_from_psa(status); + return PSA_TO_MBEDTLS_ERR(status); } status = psa_hash_setup(&ssl->handshake->fin_sha256_psa, PSA_ALG_SHA_256); if (status != PSA_SUCCESS) { - return mbedtls_md_error_from_psa(status); + return PSA_TO_MBEDTLS_ERR(status); } #endif #if defined(PSA_WANT_ALG_SHA_384) status = psa_hash_abort(&ssl->handshake->fin_sha384_psa); if (status != PSA_SUCCESS) { - return mbedtls_md_error_from_psa(status); + return PSA_TO_MBEDTLS_ERR(status); } status = psa_hash_setup(&ssl->handshake->fin_sha384_psa, PSA_ALG_SHA_384); if (status != PSA_SUCCESS) { - return mbedtls_md_error_from_psa(status); + return PSA_TO_MBEDTLS_ERR(status); } #endif return 0; @@ -880,13 +879,13 @@ static int ssl_update_checksum_start(mbedtls_ssl_context *ssl, #if defined(PSA_WANT_ALG_SHA_256) status = psa_hash_update(&ssl->handshake->fin_sha256_psa, buf, len); if (status != PSA_SUCCESS) { - return mbedtls_md_error_from_psa(status); + return PSA_TO_MBEDTLS_ERR(status); } #endif #if defined(PSA_WANT_ALG_SHA_384) status = psa_hash_update(&ssl->handshake->fin_sha384_psa, buf, len); if (status != PSA_SUCCESS) { - return mbedtls_md_error_from_psa(status); + return PSA_TO_MBEDTLS_ERR(status); } #endif return 0; @@ -896,8 +895,8 @@ static int ssl_update_checksum_start(mbedtls_ssl_context *ssl, static int ssl_update_checksum_sha256(mbedtls_ssl_context *ssl, const unsigned char *buf, size_t len) { - return mbedtls_md_error_from_psa(psa_hash_update( - &ssl->handshake->fin_sha256_psa, buf, len)); + return PSA_TO_MBEDTLS_ERR(psa_hash_update( + &ssl->handshake->fin_sha256_psa, buf, len)); } #endif @@ -905,8 +904,8 @@ static int ssl_update_checksum_sha256(mbedtls_ssl_context *ssl, static int ssl_update_checksum_sha384(mbedtls_ssl_context *ssl, const unsigned char *buf, size_t len) { - return mbedtls_md_error_from_psa(psa_hash_update( - &ssl->handshake->fin_sha384_psa, buf, len)); + return PSA_TO_MBEDTLS_ERR(psa_hash_update( + &ssl->handshake->fin_sha384_psa, buf, len)); } #endif @@ -1309,6 +1308,8 @@ void mbedtls_ssl_session_reset_msg_layer(mbedtls_ssl_context *ssl, ssl->in_fatal_alert_recv = 0; ssl->in_fatal_alert_type = 0; ssl->send_alert = 0; + ssl->alert_reason = 0; + ssl->alert_type = 0; /* Reset outgoing message writing */ ssl->out_msgtype = 0; @@ -1358,6 +1359,8 @@ int mbedtls_ssl_session_reset_int(mbedtls_ssl_context *ssl, int partial) ssl->flags &= MBEDTLS_SSL_CONTEXT_FLAGS_KEEP_AT_SESSION; ssl->tls_version = ssl->conf->max_tls_version; + ssl->badmac_seen = 0; + mbedtls_ssl_session_reset_msg_layer(ssl, partial); /* Reset renegotiation state */ @@ -1383,6 +1386,10 @@ int mbedtls_ssl_session_reset_int(mbedtls_ssl_context *ssl, int partial) ssl->alpn_chosen = NULL; #endif +#if defined(MBEDTLS_SSL_DTLS_SRTP) + memset(&ssl->dtls_srtp_info, 0, sizeof(ssl->dtls_srtp_info)); +#endif /* MBEDTLS_SSL_DTLS_SRTP */ + #if defined(MBEDTLS_SSL_DTLS_HELLO_VERIFY) && defined(MBEDTLS_SSL_SRV_C) int free_cli_id = 1; #if defined(MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE) @@ -6316,11 +6323,16 @@ static int ssl_compute_master(mbedtls_ssl_handshake_params *handshake, #if defined(MBEDTLS_SSL_EXTENDED_MASTER_SECRET) if (handshake->extended_ms == MBEDTLS_SSL_EXTENDED_MS_ENABLED) { lbl = "extended master secret"; - seed = session_hash; ret = handshake->calc_verify(ssl, session_hash, &seed_len); if (ret != 0) { MBEDTLS_SSL_DEBUG_RET(1, "calc_verify", ret); + return ret; } + if (seed_len > sizeof(session_hash)) { + MBEDTLS_SSL_DEBUG_MSG(1, ("bad session hash length")); + return MBEDTLS_ERR_SSL_INTERNAL_ERROR; + } + seed = session_hash; MBEDTLS_SSL_DEBUG_BUF(3, "session hash for extended master secret", session_hash, seed_len); @@ -6587,7 +6599,7 @@ static int ssl_calc_verify_tls_psa(const mbedtls_ssl_context *ssl, exit: psa_hash_abort(&cloned_op); - return mbedtls_md_error_from_psa(status); + return PSA_TO_MBEDTLS_ERR(status); } #if defined(PSA_WANT_ALG_SHA_256) @@ -7280,7 +7292,7 @@ static int ssl_calc_finished_tls_generic(mbedtls_ssl_context *ssl, void *ctx, exit: psa_hash_abort(&cloned_op); - return mbedtls_md_error_from_psa(status); + return PSA_TO_MBEDTLS_ERR(status); } #if defined(PSA_WANT_ALG_SHA_256) diff --git a/library/ssl_tls12_client.c b/library/ssl_tls12_client.c index c101ccd91e..8799287a09 100644 --- a/library/ssl_tls12_client.c +++ b/library/ssl_tls12_client.c @@ -1931,6 +1931,8 @@ start_processing: * However since we only support secp256r1 for now, we check only * that TLS ID here */ + MBEDTLS_SSL_CHK_BUF_READ_PTR(p, end, 3); + uint16_t read_tls_id = MBEDTLS_GET_UINT16_BE(p, 1); uint16_t exp_tls_id = mbedtls_ssl_get_tls_id_from_ecp_group_id( MBEDTLS_ECP_DP_SECP256R1); @@ -2470,11 +2472,16 @@ static int ssl_write_client_key_exchange(mbedtls_ssl_context *ssl) /* uint16 to store content length */ const size_t content_len_size = 2; + const size_t ecpoint_len_size = 1; + const size_t ecpoint_max_len = + PSA_EXPORT_PUBLIC_KEY_OUTPUT_SIZE(handshake->xxdh_psa_type, + handshake->xxdh_psa_bits); header_len = 4; - if (header_len + content_len_size + ssl->conf->psk_identity_len - > MBEDTLS_SSL_OUT_CONTENT_LEN) { + if (ecpoint_max_len > MBEDTLS_SSL_OUT_CONTENT_LEN - ecpoint_len_size || + header_len + content_len_size + ssl->conf->psk_identity_len + > MBEDTLS_SSL_OUT_CONTENT_LEN - ecpoint_len_size - ecpoint_max_len) { MBEDTLS_SSL_DEBUG_MSG(1, ("psk identity too long or SSL buffer too short")); return MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL; diff --git a/library/ssl_tls12_server.c b/library/ssl_tls12_server.c index 884c8fd4a4..2a825e07b1 100644 --- a/library/ssl_tls12_server.c +++ b/library/ssl_tls12_server.c @@ -1746,9 +1746,9 @@ static void ssl_write_supported_point_formats_ext(mbedtls_ssl_context *ssl, MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED */ #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED) -static void ssl_write_ecjpake_kkpp_ext(mbedtls_ssl_context *ssl, - unsigned char *buf, - size_t *olen) +static int ssl_write_ecjpake_kkpp_ext(mbedtls_ssl_context *ssl, + unsigned char *buf, + size_t *olen) { int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED; unsigned char *p = buf; @@ -1760,14 +1760,14 @@ static void ssl_write_ecjpake_kkpp_ext(mbedtls_ssl_context *ssl, /* Skip costly computation if not needed */ if (ssl->handshake->ciphersuite_info->key_exchange != MBEDTLS_KEY_EXCHANGE_ECJPAKE) { - return; + return 0; } MBEDTLS_SSL_DEBUG_MSG(3, ("server hello, ecjpake kkpp extension")); if (end - p < 4) { MBEDTLS_SSL_DEBUG_MSG(1, ("buffer too small")); - return; + return MBEDTLS_ERR_SSL_BUFFER_TOO_SMALL; } MBEDTLS_PUT_UINT16_BE(MBEDTLS_TLS_EXT_ECJPAKE_KKPP, p, 0); @@ -1780,13 +1780,14 @@ static void ssl_write_ecjpake_kkpp_ext(mbedtls_ssl_context *ssl, psa_destroy_key(ssl->handshake->psa_pake_password); psa_pake_abort(&ssl->handshake->psa_pake_ctx); MBEDTLS_SSL_DEBUG_RET(1, "psa_pake_output", ret); - return; + return ret; } MBEDTLS_PUT_UINT16_BE(kkpp_len, p, 0); p += 2; *olen = kkpp_len + 4; + return 0; } #endif /* MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED */ @@ -2169,7 +2170,11 @@ static int ssl_write_server_hello(mbedtls_ssl_context *ssl) #endif #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED) - ssl_write_ecjpake_kkpp_ext(ssl, p + 2 + ext_len, &olen); + ret = ssl_write_ecjpake_kkpp_ext(ssl, p + 2 + ext_len, &olen); + if (ret != 0) { + MBEDTLS_SSL_DEBUG_RET(1, "ssl_write_ecjpake_kkpp_ext", ret); + return ret; + } ext_len += olen; #endif @@ -3367,8 +3372,8 @@ MBEDTLS_CHECK_RETURN_CRITICAL static int ssl_write_new_session_ticket(mbedtls_ssl_context *ssl) { int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED; - size_t tlen; - uint32_t lifetime; + size_t tlen = 0; + uint32_t lifetime = 0; MBEDTLS_SSL_DEBUG_MSG(2, ("=> write new session ticket")); @@ -3395,7 +3400,6 @@ static int ssl_write_new_session_ticket(mbedtls_ssl_context *ssl) ssl->out_msg + MBEDTLS_SSL_OUT_CONTENT_LEN, &tlen, &lifetime)) != 0) { MBEDTLS_SSL_DEBUG_RET(1, "mbedtls_ssl_ticket_write", ret); - tlen = 0; } MBEDTLS_PUT_UINT32_BE(lifetime, ssl->out_msg, 4); diff --git a/library/ssl_tls13_client.c b/library/ssl_tls13_client.c index 9b7ca82f91..e8b6063f32 100644 --- a/library/ssl_tls13_client.c +++ b/library/ssl_tls13_client.c @@ -404,14 +404,18 @@ static int ssl_tls13_parse_hrr_key_share_ext(mbedtls_ssl_context *ssl, * then the client MUST abort the handshake with an "illegal_parameter" alert. */ for (; *group_list != 0; group_list++) { + if (*group_list != selected_group) { + continue; + } #if defined(PSA_WANT_ALG_ECDH) if (mbedtls_ssl_tls13_named_group_is_ecdhe(*group_list)) { - if ((mbedtls_ssl_get_psa_curve_info_from_tls_id( - *group_list, NULL, NULL) == PSA_ERROR_NOT_SUPPORTED) || - *group_list != selected_group) { - found = 1; - break; + if (mbedtls_ssl_get_psa_curve_info_from_tls_id( + *group_list, NULL, NULL) == PSA_ERROR_NOT_SUPPORTED) { + continue; } + /* Found only if psa_curve is supported and group_list == selected_group */ + found = 1; + break; } #endif /* PSA_WANT_ALG_ECDH */ #if defined(PSA_WANT_ALG_FFDH) @@ -2012,6 +2016,19 @@ static int ssl_tls13_process_server_hello(mbedtls_ssl_context *ssl) goto cleanup; } + /* + * TLS 1.3 is negotiated. Check that ServerHello/HRR ends at a record + * boundary. For HRR, which does not trigger a key update, this checks + * that HRR terminates the server flight. + */ + if (ssl->in_hslen != ssl->in_msglen) { + MBEDTLS_SSL_DEBUG_MSG(1, ("ServerHello end not aligned with a record boundary")); + ret = MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE; + MBEDTLS_SSL_PEND_FATAL_ALERT(MBEDTLS_SSL_ALERT_MSG_UNEXPECTED_MESSAGE, + MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE); + goto cleanup; + } + MBEDTLS_SSL_PROC_CHK(ssl_tls13_parse_server_hello(ssl, buf, buf + buf_len, is_hrr)); @@ -2800,6 +2817,7 @@ static int ssl_tls13_parse_new_session_ticket_exts(mbedtls_ssl_context *ssl, MBEDTLS_SSL_DEBUG_RET( 1, "ssl_tls13_parse_new_session_ticket_early_data_ext", ret); + return ret; } break; #endif /* MBEDTLS_SSL_EARLY_DATA */ diff --git a/library/ssl_tls13_generic.c b/library/ssl_tls13_generic.c index 7cb8bbd8c1..60c0f2348c 100644 --- a/library/ssl_tls13_generic.c +++ b/library/ssl_tls13_generic.c @@ -50,20 +50,55 @@ int mbedtls_ssl_tls13_fetch_handshake_msg(mbedtls_ssl_context *ssl, unsigned char **buf, size_t *buf_len) { - int ret; + int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED; + int require_record_boundary; - if ((ret = mbedtls_ssl_read_record(ssl, 0)) != 0) { - MBEDTLS_SSL_DEBUG_RET(1, "mbedtls_ssl_read_record", ret); - goto cleanup; + /* Require record-boundary alignment by default. The exceptions below are + * handshake messages that may legitimately be followed by additional + * handshake messages in the same record. Using the default behaviour for a + * message that should be exempt is an interoperability bug; exempting a + * message that should not be exempt may have security implications. + */ + switch (hs_type) { + case MBEDTLS_SSL_HS_NEW_SESSION_TICKET: + case MBEDTLS_SSL_HS_ENCRYPTED_EXTENSIONS: + case MBEDTLS_SSL_HS_CERTIFICATE: + case MBEDTLS_SSL_HS_CERTIFICATE_REQUEST: + case MBEDTLS_SSL_HS_CERTIFICATE_VERIFY: + /* + * For TLS 1.3, ServerHello (including HelloRetryRequest) must end at a + * record boundary, but not for TLS 1.2. At this point the ServerHello + * has not yet been processed, so we do not know whether it negotiates + * TLS 1.3 or TLS 1.2. Defer the boundary check until the protocol + * version is known to be TLS 1.3. + */ + case MBEDTLS_SSL_HS_SERVER_HELLO: + require_record_boundary = 0; + break; + + default: + /* ClientHello, EndOfEarlyData, Finished, and KeyUpdate. + */ + require_record_boundary = 1; } + ret = mbedtls_ssl_read_record(ssl, 0); + if (ret != 0) { + MBEDTLS_SSL_DEBUG_RET(1, "mbedtls_ssl_read_record", ret); + goto error; + } + + ret = MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE; if (ssl->in_msgtype != MBEDTLS_SSL_MSG_HANDSHAKE || ssl->in_msg[0] != hs_type) { MBEDTLS_SSL_DEBUG_MSG(1, ("Receive unexpected handshake message.")); - MBEDTLS_SSL_PEND_FATAL_ALERT(MBEDTLS_SSL_ALERT_MSG_UNEXPECTED_MESSAGE, - MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE); - ret = MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE; - goto cleanup; + goto error; + } + + if (require_record_boundary && (ssl->in_hslen != ssl->in_msglen)) { + MBEDTLS_SSL_DEBUG_MSG(1, ("Handshake message %s end not aligned with a record boundary", + mbedtls_ssl_get_hs_msg_name(hs_type))); + goto error; } /* @@ -73,11 +108,15 @@ int mbedtls_ssl_tls13_fetch_handshake_msg(mbedtls_ssl_context *ssl, * uint24 length; * ... */ - *buf = ssl->in_msg + 4; + *buf = ssl->in_msg + 4; *buf_len = ssl->in_hslen - 4; + return 0; -cleanup: - +error: + if (ret == MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE) { + MBEDTLS_SSL_PEND_FATAL_ALERT(MBEDTLS_SSL_ALERT_MSG_UNEXPECTED_MESSAGE, + MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE); + } return ret; } diff --git a/library/ssl_tls13_server.c b/library/ssl_tls13_server.c index dc7c776830..38f2fe9370 100644 --- a/library/ssl_tls13_server.c +++ b/library/ssl_tls13_server.c @@ -3077,6 +3077,7 @@ static int ssl_tls13_process_client_finished(mbedtls_ssl_context *ssl) if (ret != 0) { MBEDTLS_SSL_DEBUG_RET( 1, "mbedtls_ssl_tls13_compute_resumption_master_secret", ret); + return ret; } mbedtls_ssl_handshake_set_state(ssl, MBEDTLS_SSL_HANDSHAKE_WRAPUP); @@ -3183,8 +3184,9 @@ static int ssl_tls13_prepare_new_session_ticket(mbedtls_ssl_context *ssl, #endif /* Generate ticket_age_add */ - if ((ret = psa_generate_random((unsigned char *) &session->ticket_age_add, - sizeof(session->ticket_age_add)) != 0)) { + ret = psa_generate_random((unsigned char *) &session->ticket_age_add, + sizeof(session->ticket_age_add)); + if (ret != 0) { MBEDTLS_SSL_DEBUG_RET(1, "generate_ticket_age_add", ret); return ret; } diff --git a/library/x509_crt.c b/library/x509_crt.c index 3232760ea2..a6fcd1b4e6 100644 --- a/library/x509_crt.c +++ b/library/x509_crt.c @@ -87,11 +87,13 @@ typedef struct { * concerns. */ const mbedtls_x509_crt_profile mbedtls_x509_crt_profile_default = { - /* Hashes from SHA-256 and above. Note that this selection - * should be aligned with ssl_preset_default_hashes in ssl_tls.c. */ + /* Hashes from SHA-256 and above. */ MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA256) | MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA384) | - MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA512), + MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA512) | + MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA3_256) | + MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA3_384) | + MBEDTLS_X509_ID_FLAG(MBEDTLS_MD_SHA3_512), 0xFFFFFFF, /* Any PK alg */ #if defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) /* Curves at or above 128-bit security level. Note that this selection @@ -165,12 +167,8 @@ const mbedtls_x509_crt_profile mbedtls_x509_crt_profile_none = (uint32_t) -1, }; -/* - * Check md_alg against profile - * Return 0 if md_alg is acceptable for this profile, -1 otherwise - */ -static int x509_profile_check_md_alg(const mbedtls_x509_crt_profile *profile, - mbedtls_md_type_t md_alg) +int mbedtls_x509_profile_check_md_alg(const mbedtls_x509_crt_profile *profile, + mbedtls_md_type_t md_alg) { if (md_alg == MBEDTLS_MD_NONE) { return -1; @@ -183,12 +181,8 @@ static int x509_profile_check_md_alg(const mbedtls_x509_crt_profile *profile, return -1; } -/* - * Check pk_alg against profile - * Return 0 if pk_alg is acceptable for this profile, -1 otherwise - */ -static int x509_profile_check_pk_alg(const mbedtls_x509_crt_profile *profile, - mbedtls_pk_sigalg_t pk_alg) +int mbedtls_x509_profile_check_pk_alg(const mbedtls_x509_crt_profile *profile, + mbedtls_pk_sigalg_t pk_alg) { if (pk_alg == MBEDTLS_PK_SIGALG_NONE) { return -1; @@ -512,23 +506,34 @@ static int x509_get_basic_constraints(unsigned char **p, } if (*p == end) { + /* Empty basicConstraints: valid, not a CA. */ return 0; } - if ((ret = mbedtls_asn1_get_bool(p, end, ca_istrue)) != 0) { - if (ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG) { - ret = mbedtls_asn1_get_int(p, end, ca_istrue); - } - - if (ret != 0) { - return MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, ret); - } - - if (*ca_istrue != 0) { - *ca_istrue = 1; - } + if ((size_t) (end - *p) != len) { + /* Reject junk after the SEQUENCE inside the extension (which is + * probably benign), and reject a SEQUENCE that extends beyond + * the extension (could be very dangerous). */ + return MBEDTLS_ERR_X509_INVALID_EXTENSIONS; } + if ((ret = mbedtls_asn1_get_bool(p, end, ca_istrue)) != 0) { + /* If the SEQUENCE starts with an INTEGER and not a BOOLEAN, + * according to RFC 5280, it's syntactically valid, but it's + * something that a CA MUST NOT produce. So we reject it. + * + * Note: historically, from XySSL 0.9 to Mbed TLS 3.6.6/4.1.0, + * `SEQUENCE { INTEGER n }` was interpreted as cA=FALSE if n == 0 + * and cA=TRUE if n != 0. This was dangerous since + * `SEQUENCE { INTEGER n }` should be parsed as cA=FALSE + * according to RFC 5280, so we stopped doing it. + */ + return MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, ret); + } + /* `SEQUENCE { BOOLEAN FALSE }` is not DER since default-value fields + * must be omitted in DER. But it seems harmless, and Mbed TLS has + * always accepted it, so we continue to accept it. */ + if (*p == end) { return 0; } @@ -2037,11 +2042,11 @@ static int x509_crt_verifycrl(mbedtls_x509_crt *crt, mbedtls_x509_crt *ca, /* * Check if CRL is correctly signed by the trusted CA */ - if (x509_profile_check_md_alg(profile, crl_list->sig_md) != 0) { + if (mbedtls_x509_profile_check_md_alg(profile, crl_list->sig_md) != 0) { flags |= MBEDTLS_X509_BADCRL_BAD_MD; } - if (x509_profile_check_pk_alg(profile, crl_list->sig_pk) != 0) { + if (mbedtls_x509_profile_check_pk_alg(profile, crl_list->sig_pk) != 0) { flags |= MBEDTLS_X509_BADCRL_BAD_PK; } @@ -2550,11 +2555,11 @@ static int x509_crt_verify_chain( } /* Check signature algorithm: MD & PK algs */ - if (x509_profile_check_md_alg(profile, child->sig_md) != 0) { + if (mbedtls_x509_profile_check_md_alg(profile, child->sig_md) != 0) { *flags |= MBEDTLS_X509_BADCERT_BAD_MD; } - if (x509_profile_check_pk_alg(profile, child->sig_pk) != 0) { + if (mbedtls_x509_profile_check_pk_alg(profile, child->sig_pk) != 0) { *flags |= MBEDTLS_X509_BADCERT_BAD_PK; } @@ -3062,7 +3067,7 @@ static int x509_crt_verify_restartable_ca_cb(mbedtls_x509_crt *crt, /* Check the type and size of the key */ pk_type = mbedtls_pk_get_type(&crt->pk); - if (x509_profile_check_pk_alg(profile, (mbedtls_pk_sigalg_t) pk_type) != 0) { + if (mbedtls_x509_profile_check_pk_alg(profile, (mbedtls_pk_sigalg_t) pk_type) != 0) { ee_flags |= MBEDTLS_X509_BADCERT_BAD_PK; } diff --git a/library/x509_csr.c b/library/x509_csr.c index 3e8e407b26..28a4560c43 100644 --- a/library/x509_csr.c +++ b/library/x509_csr.c @@ -227,25 +227,34 @@ static int x509_csr_parse_attributes(mbedtls_x509_csr *csr, /* Check that this is an extension-request attribute */ if (MBEDTLS_OID_CMP(MBEDTLS_OID_PKCS9_CSR_EXT_REQ, &attr_oid) == 0) { - if ((ret = mbedtls_asn1_get_tag(p, end, &len, + if ((ret = mbedtls_asn1_get_tag(p, end_attr_data, &len, MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SET)) != 0) { return MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, ret); } - if ((ret = mbedtls_asn1_get_tag(p, end, &len, + const unsigned char *end_set = *p + len; + if (end_set != end_attr_data) { + return MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, + MBEDTLS_ERR_ASN1_LENGTH_MISMATCH); + } + + if ((ret = mbedtls_asn1_get_tag(p, end_set, &len, MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE)) != 0) { return MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, ret); } - if ((ret = x509_csr_parse_extensions(csr, p, *p + len, cb, p_ctx)) != 0) { - return ret; - } - - if (*p != end_attr_data) { + const unsigned char *end_exts = *p + len; + if (end_exts != end_set) { return MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_LENGTH_MISMATCH); } + + if ((ret = x509_csr_parse_extensions(csr, p, end_exts, cb, p_ctx)) != 0) { + return ret; + } + /* x509_csr_parse_extensions() guarantees *p == end_exts + * on success */ } *p = end_attr_data; diff --git a/library/x509_internal.h b/library/x509_internal.h index fcb996b19d..f68b6593bd 100644 --- a/library/x509_internal.h +++ b/library/x509_internal.h @@ -15,6 +15,7 @@ #include "mbedtls/private_access.h" #include "mbedtls/x509.h" +#include "mbedtls/x509_crt.h" #include "mbedtls/asn1.h" #include "pk_internal.h" // for a lot of things, including in SSL @@ -79,4 +80,18 @@ int mbedtls_x509_info_key_usage(char **buf, size_t *size, int mbedtls_x509_write_set_san_common(mbedtls_asn1_named_data **extensions, const mbedtls_x509_san_list *san_list); +/* + * Check md_alg against profile + * Return 0 if md_alg is acceptable for this profile, -1 otherwise + */ +int mbedtls_x509_profile_check_md_alg(const mbedtls_x509_crt_profile *profile, + mbedtls_md_type_t md_alg); + +/* + * Check pk_alg against profile + * Return 0 if pk_alg is acceptable for this profile, -1 otherwise + */ +int mbedtls_x509_profile_check_pk_alg(const mbedtls_x509_crt_profile *profile, + mbedtls_pk_sigalg_t pk_alg); + #endif /* MBEDTLS_X509_INTERNAL_H */ diff --git a/programs/ssl/ssl_client2.c b/programs/ssl/ssl_client2.c index fc00473cfc..ad87e225da 100644 --- a/programs/ssl/ssl_client2.c +++ b/programs/ssl/ssl_client2.c @@ -22,6 +22,7 @@ int main(void) #else /* !MBEDTLS_SSL_TEST_IMPOSSIBLE && MBEDTLS_SSL_CLI_C */ #include "test/psa_crypto_helpers.h" +#include "test/ssl_helpers.h" /* Size of memory to be allocated for the heap, when using the library's memory * management and MBEDTLS_MEMORY_BUFFER_ALLOC_C is enabled. */ @@ -86,6 +87,7 @@ int main(void) #define DFL_HS_TO_MIN 0 #define DFL_HS_TO_MAX 0 #define DFL_DTLS_MTU -1 +#define DFL_BADMAC_LIMIT -1 #define DFL_DGRAM_PACKING 1 #define DFL_FALLBACK -1 #define DFL_EXTENDED_MS -1 @@ -269,7 +271,8 @@ int main(void) " mtu=%%d default: (library default: unlimited)\n" \ " dgram_packing=%%d default: 1 (allowed)\n" \ " allow or forbid packing of multiple\n" \ - " records within a single datgram.\n" + " records within a single datagram.\n" \ + " badmac_limit=%%d default: (library default: disabled)\n" #else #define USAGE_DTLS "" #endif @@ -294,7 +297,7 @@ int main(void) #if defined(MBEDTLS_SSL_RENEGOTIATION) #define USAGE_RENEGO \ " renegotiation=%%d default: 0 (disabled)\n" \ - " renegotiate=%%d default: 0 (disabled)\n" \ + " renegotiate=%%d default: 0 (disabled), 1 immediately, 2 after first exchange\n" \ " renego_delay=%%d default: -2 (library default)\n" #else #define USAGE_RENEGO "" @@ -491,7 +494,7 @@ struct options { #endif /* MBEDTLS_SSL_PROTO_TLS1_3 */ int renegotiation; /* enable / disable renegotiation */ int allow_legacy; /* allow legacy renegotiation */ - int renegotiate; /* attempt renegotiation? */ + int renegotiate; /* attempt renegotiation? 1: before data, 2: after first exchange */ int renego_delay; /* delay before enforcing renegotiation */ int exchanges; /* number of data exchanges */ int min_version; /* minimum protocol version accepted */ @@ -518,6 +521,7 @@ struct options { int dtls_mtu; /* UDP Maximum transport unit for DTLS */ int fallback; /* is this a fallback connection? */ int dgram_packing; /* allow/forbid datagram packing */ + int badmac_limit; /* Limit of records with bad MAC */ int extended_ms; /* negotiate extended master secret? */ int etm; /* negotiate encrypt then mac? */ int context_crt_cb; /* use context-specific CRT verify callback */ @@ -959,6 +963,7 @@ int main(int argc, char *argv[]) opt.extended_ms = DFL_EXTENDED_MS; opt.etm = DFL_ETM; opt.dgram_packing = DFL_DGRAM_PACKING; + opt.badmac_limit = DFL_BADMAC_LIMIT; opt.serialize = DFL_SERIALIZE; opt.context_file = DFL_CONTEXT_FILE; opt.eap_tls = DFL_EAP_TLS; @@ -1164,7 +1169,7 @@ usage: opt.renego_delay = (atoi(q)); } else if (strcmp(p, "renegotiate") == 0) { opt.renegotiate = atoi(q); - if (opt.renegotiate < 0 || opt.renegotiate > 1) { + if (opt.renegotiate < 0 || opt.renegotiate > 2) { goto usage; } } else if (strcmp(p, "exchanges") == 0) { @@ -1372,6 +1377,11 @@ usage: opt.dgram_packing != 1) { goto usage; } + } else if (strcmp(p, "badmac_limit") == 0) { + opt.badmac_limit = atoi(q); + if (opt.badmac_limit < 0) { + goto usage; + } } else if (strcmp(p, "recsplit") == 0) { opt.recsplit = atoi(q); if (opt.recsplit < 0 || opt.recsplit > 1) { @@ -1835,6 +1845,10 @@ usage: if (opt.dgram_packing != DFL_DGRAM_PACKING) { mbedtls_ssl_set_datagram_packing(&ssl, opt.dgram_packing); } + + if (opt.badmac_limit != DFL_BADMAC_LIMIT) { + mbedtls_ssl_conf_dtls_badmac_limit(&conf, opt.badmac_limit); + } #endif /* MBEDTLS_SSL_PROTO_DTLS */ #if defined(MBEDTLS_SSL_MAX_FRAGMENT_LENGTH) @@ -2442,7 +2456,7 @@ usage: #endif /* MBEDTLS_SSL_DTLS_CONNECTION_ID */ #if defined(MBEDTLS_SSL_RENEGOTIATION) - if (opt.renegotiate) { + if (opt.renegotiate == 1) { /* * Perform renegotiation (this must be done when the server is waiting * for input from our side). @@ -2787,12 +2801,21 @@ send_request: memset(peer_crt_info, 0, sizeof(peer_crt_info)); #endif /* MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED */ + /* Dump the SSL context before resetting it. This will be used below + * to check if the reset function worked properly. */ + mbedtls_ssl_context ssl_before = ssl; if ((ret = mbedtls_ssl_session_reset(&ssl)) != 0) { mbedtls_printf(" failed\n ! mbedtls_ssl_session_reset returned -0x%x\n\n", (unsigned int) -ret); goto exit; } + if (mbedtls_test_ssl_check_context_after_session_reset(&ssl_before, &ssl) != 0) { + mbedtls_printf( + " failed\n ! mbedtls_ssl_session_reset didn't properly reset ssl context\n\n"); + goto exit; + } + while ((ret = mbedtls_ssl_handshake(&ssl)) != 0) { if (ret != MBEDTLS_ERR_SSL_WANT_READ && ret != MBEDTLS_ERR_SSL_WANT_WRITE && @@ -2817,6 +2840,44 @@ send_request: goto send_request; } +#if defined(MBEDTLS_SSL_RENEGOTIATION) + if (opt.renegotiate == 2) { + /* Perform renegotiation after the first data exchange. + * This is a one-time thing, we won't renegotiate even if there are + * more data exchanges that cause a `goto send_request` later. + */ + opt.renegotiate = 0; + + mbedtls_printf(" . Performing renegotiation..."); + fflush(stdout); + while ((ret = mbedtls_ssl_renegotiate(&ssl)) != 0) { + if (ret != MBEDTLS_ERR_SSL_WANT_READ && + ret != MBEDTLS_ERR_SSL_WANT_WRITE && + ret != MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS) { + mbedtls_printf(" failed\n ! mbedtls_ssl_renegotiate returned %d\n\n", + ret); + goto exit; + } + +#if defined(MBEDTLS_ECP_RESTARTABLE) + if (ret == MBEDTLS_ERR_SSL_CRYPTO_IN_PROGRESS) { + continue; + } +#endif + + /* For event-driven IO, wait for socket to become available */ + if (opt.event == 1 /* level triggered IO */) { +#if defined(MBEDTLS_TIMING_C) + idle(&server_fd, &timer, ret); +#else + idle(&server_fd, ret); +#endif + } + } + mbedtls_printf(" ok\n"); + } +#endif /* MBEDTLS_SSL_RENEGOTIATION */ + /* * 7c. Simulate serialize/deserialize and go back to data exchange */ diff --git a/programs/ssl/ssl_server2.c b/programs/ssl/ssl_server2.c index 79cbad877d..b5cdc817b8 100644 --- a/programs/ssl/ssl_server2.c +++ b/programs/ssl/ssl_server2.c @@ -52,6 +52,7 @@ int main(void) #endif #include "test/psa_crypto_helpers.h" +#include "test/ssl_helpers.h" #include "mbedtls/pk.h" #if defined(MBEDTLS_PK_HAVE_PRIVATE_HEADER) @@ -367,9 +368,6 @@ int main(void) #define USAGE_ANTI_REPLAY "" #endif -#define USAGE_BADMAC_LIMIT \ - " badmac_limit=%%d default: (library default: disabled)\n" - #if defined(MBEDTLS_SSL_PROTO_DTLS) #define USAGE_DTLS \ " dtls=%%d default: 0 (TLS)\n" \ @@ -378,7 +376,8 @@ int main(void) " mtu=%%d default: (library default: unlimited)\n" \ " dgram_packing=%%d default: 1 (allowed)\n" \ " allow or forbid packing of multiple\n" \ - " records within a single datgram.\n" + " records within a single datagram.\n" \ + " badmac_limit=%%d default: (library default: disabled)\n" #else #define USAGE_DTLS "" #endif @@ -524,7 +523,6 @@ int main(void) USAGE_SRTP \ USAGE_COOKIES \ USAGE_ANTI_REPLAY \ - USAGE_BADMAC_LIMIT \ "\n" #define USAGE2 \ " auth_mode=%%s default: (library default: none)\n" \ @@ -3274,7 +3272,15 @@ reset: mbedtls_net_free(&client_fd); + /* Dump the SSL context before resetting it. This will be used below + * to check if the reset function worked properly. */ + mbedtls_ssl_context ssl_before = ssl; mbedtls_ssl_session_reset(&ssl); + if (mbedtls_test_ssl_check_context_after_session_reset(&ssl_before, &ssl) != 0) { + mbedtls_printf( + " failed\n ! mbedtls_ssl_session_reset didn't properly reset ssl context\n\n"); + goto exit; + } /* * 3. Wait until a client connects diff --git a/programs/test/udp_proxy.c b/programs/test/udp_proxy.c index eab15feb38..04c2e3a7e7 100644 --- a/programs/test/udp_proxy.c +++ b/programs/test/udp_proxy.c @@ -103,6 +103,12 @@ int main(void) " May be used multiple times, even for the same\n" \ " message, in which case the respective message\n" \ " gets delayed multiple times.\n" \ + " delay_encrypted_hs_cli=%%d default: 0 (don't delay)\n" \ + " delay the Nth encrypted handshake message from\n" \ + " client to server.\n" \ + " delay_encrypted_hs_srv=%%d default: 0 (don't delay)\n" \ + " delay the Nth encrypted handshake message from\n" \ + " server to client.\n" \ " delay_srv=%%s Handshake message from server that should be\n" \ " delayed. Possible values are 'HelloRequest',\n" \ " 'ServerHello', 'ServerHelloDone', 'Certificate'\n" \ @@ -116,6 +122,12 @@ int main(void) " mtu=%%d default: 0 (unlimited)\n" \ " drop packets larger than N bytes\n" \ " bad_ad=0/1 default: 0 (don't add bad ApplicationData)\n" \ + " bad_ad_cli_once=%%d default: 0 (don't add bad ApplicationData)\n" \ + " add bad ApplicationData before the Nth\n" \ + " ApplicationData from client to server.\n" \ + " bad_ad_srv_once=%%d default: 0 (don't add bad ApplicationData)\n" \ + " add bad ApplicationData before the Nth\n" \ + " ApplicationData from server to client.\n" \ " bad_cid=%%d default: 0 (don't corrupt Connection IDs)\n" \ " duplicate 1:N packets containing a CID,\n" \ " modifying CID in first instance of the packet.\n" \ @@ -148,9 +160,13 @@ static struct options { char *delay_srv[MAX_DELAYED_HS]; /* handshake types of messages from * server that should be delayed. */ uint8_t delay_srv_cnt; /* Number of entries in delay_srv. */ + int delay_encrypted_hs_cli; /* Delay Nth encrypted HS from client. */ + int delay_encrypted_hs_srv; /* Delay Nth encrypted HS from server. */ int drop; /* drop 1 packet in N (none if 0) */ int mtu; /* drop packets larger than this */ int bad_ad; /* inject corrupted ApplicationData record */ + int bad_ad_cli_once; /* Inject corrupted Nth AD from client. */ + int bad_ad_srv_once; /* Inject corrupted Nth AD from server. */ unsigned bad_cid; /* inject corrupted CID record */ int protect_hvr; /* never drop or delay HelloVerifyRequest */ int protect_len; /* never drop/delay packet of the given size*/ @@ -219,6 +235,16 @@ static void get_options(int argc, char *argv[]) if (opt.delay_ccs < 0 || opt.delay_ccs > 1) { exit_usage(p, q); } + } else if (strcmp(p, "delay_encrypted_hs_cli") == 0) { + opt.delay_encrypted_hs_cli = atoi(q); + if (opt.delay_encrypted_hs_cli < 0) { + exit_usage(p, q); + } + } else if (strcmp(p, "delay_encrypted_hs_srv") == 0) { + opt.delay_encrypted_hs_srv = atoi(q); + if (opt.delay_encrypted_hs_srv < 0) { + exit_usage(p, q); + } } else if (strcmp(p, "delay_cli") == 0 || strcmp(p, "delay_srv") == 0) { uint8_t *delay_cnt; @@ -271,6 +297,16 @@ static void get_options(int argc, char *argv[]) if (opt.bad_ad < 0 || opt.bad_ad > 1) { exit_usage(p, q); } + } else if (strcmp(p, "bad_ad_cli_once") == 0) { + opt.bad_ad_cli_once = atoi(q); + if (opt.bad_ad_cli_once < 0) { + exit_usage(p, q); + } + } else if (strcmp(p, "bad_ad_srv_once") == 0) { + opt.bad_ad_srv_once = atoi(q); + if (opt.bad_ad_srv_once < 0) { + exit_usage(p, q); + } } #if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) else if (strcmp(p, "bad_cid") == 0) { @@ -528,6 +564,35 @@ typedef enum { static inject_clihlo_state_t inject_clihlo_state; static packet initial_clihlo; +static unsigned bad_ad_cli_seen; +static unsigned bad_ad_srv_seen; + +static int bad_ad_once(const packet *p) +{ + unsigned *seen; + int bad_ad_at; + + if (strcmp(p->type, "ApplicationData") != 0) { + return 0; + } + + if (strcmp(p->way, "S <- C") == 0) { + seen = &bad_ad_cli_seen; + bad_ad_at = opt.bad_ad_cli_once; + } else { + seen = &bad_ad_srv_seen; + bad_ad_at = opt.bad_ad_srv_once; + } + + if (bad_ad_at <= 0) { + return 0; + } + + ++*seen; + + return *seen == (unsigned) bad_ad_at; +} + static int send_packet(const packet *p, const char *why) { int ret; @@ -559,7 +624,7 @@ static int send_packet(const packet *p, const char *why) } /* insert corrupted ApplicationData record? */ - if (opt.bad_ad && + if ((bad_ad_once(p) || opt.bad_ad) && strcmp(p->type, "ApplicationData") == 0) { unsigned char buf[MAX_MSG_SIZE]; memcpy(buf, p->buf, p->len); @@ -664,6 +729,31 @@ static int send_delayed(void) static unsigned char held[2048] = { 0 }; #define HOLD_MAX 2 +static unsigned encrypted_hs_cli_seen; +static unsigned encrypted_hs_srv_seen; + +static int delay_encrypted_hs(const packet *p) +{ + unsigned *seen; + int delay_at; + + if (strcmp(p->type, "Encrypted handshake") != 0) { + return 0; + } + + if (strcmp(p->way, "S <- C") == 0) { + seen = &encrypted_hs_cli_seen; + delay_at = opt.delay_encrypted_hs_cli; + } else { + seen = &encrypted_hs_srv_seen; + delay_at = opt.delay_encrypted_hs_srv; + } + + ++*seen; + + return delay_at > 0 && *seen == (unsigned) delay_at; +} + static int handle_message(const char *way, mbedtls_net_context *dst, mbedtls_net_context *src) @@ -717,6 +807,11 @@ static int handle_message(const char *way, } } + if (delay_encrypted_hs(&cur)) { + delay_packet(&cur); + return 0; + } + /* do we want to drop, delay, or forward it? */ if ((opt.mtu != 0 && cur.len > (unsigned) opt.mtu) || @@ -851,6 +946,10 @@ accept: */ clear_pending(); memset(held, 0, sizeof(held)); + encrypted_hs_cli_seen = 0; + encrypted_hs_srv_seen = 0; + bad_ad_cli_seen = 0; + bad_ad_srv_seen = 0; nb_fds = client_fd.fd; if (nb_fds < server_fd.fd) { diff --git a/scripts/data_files/config-options-current.txt b/scripts/data_files/config-options-current.txt index 81b233804c..bd18a1cc76 100644 --- a/scripts/data_files/config-options-current.txt +++ b/scripts/data_files/config-options-current.txt @@ -9,6 +9,7 @@ MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED MBEDTLS_KEY_EXCHANGE_PSK_ENABLED MBEDTLS_NET_C +MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES MBEDTLS_PKCS7_C MBEDTLS_PSK_MAX_LEN MBEDTLS_SSL_ALL_ALERT_MESSAGES diff --git a/tests/include/test/ssl_helpers.h b/tests/include/test/ssl_helpers.h index a653c9643e..21965b0c9a 100644 --- a/tests/include/test/ssl_helpers.h +++ b/tests/include/test/ssl_helpers.h @@ -16,12 +16,10 @@ #include #include -#include #include #include #if defined(MBEDTLS_SSL_TLS_C) -#include #include #include @@ -31,10 +29,6 @@ #include "mbedtls/ssl_cache.h" #endif -#define PSA_TO_MBEDTLS_ERR(status) PSA_TO_MBEDTLS_ERR_LIST(status, \ - psa_to_ssl_errors, \ - psa_generic_status_to_mbedtls) - #if defined(MBEDTLS_SSL_PROTO_TLS1_3) #if defined(PSA_WANT_KEY_TYPE_AES) #if defined(PSA_WANT_ALG_GCM) @@ -106,17 +100,13 @@ #define MBEDTLS_TEST_HAS_ADDITIONAL_HASH #endif -enum { -#define MBEDTLS_SSL_TLS1_3_LABEL(name, string) \ - tls13_label_ ## name, - MBEDTLS_SSL_TLS1_3_LABEL_LIST -#undef MBEDTLS_SSL_TLS1_3_LABEL -}; - #if defined(MBEDTLS_SSL_ALPN) #define MBEDTLS_TEST_MAX_ALPN_LIST_SIZE 10 #endif +/* Forward declaration. Defined below. */ +struct mbedtls_test_ssl_endpoint; + typedef struct mbedtls_test_ssl_log_pattern { const char *pattern; size_t counter; @@ -147,6 +137,35 @@ typedef struct mbedtls_test_handshake_test_options { int expected_srv_fragments; int renegotiate; int legacy_renegotiation; + /** Hook that mbedtls_test_ssl_perform_handshake() runs just before + * the initial handshake. */ + void (*pre_handshake_fun)(struct mbedtls_test_ssl_endpoint *client, + struct mbedtls_test_ssl_endpoint *server, + void *param); + /** Value passed to ::pre_handshake_fun. */ + void *pre_handshake_param; + /** Hook that mbedtls_test_ssl_perform_handshake() runs after + * the initial handshake succeeds. */ + void (*post_handshake_fun)(struct mbedtls_test_ssl_endpoint *client, + struct mbedtls_test_ssl_endpoint *server, + void *param); + /** Value passed to ::post_handshake_fun. */ + void *post_handshake_param; + /** Hook that mbedtls_test_ssl_perform_handshake() runs after + * exchanging some data, before testing additional features such as + * serialization and renegotiation. */ + void (*post_data_fun)(struct mbedtls_test_ssl_endpoint *client, + struct mbedtls_test_ssl_endpoint *server, + void *param); + /** Value passed to ::post_data_fun. */ + void *post_data_param; + /** Hook that mbedtls_test_ssl_perform_handshake() runs after a successful + * connection, just before closing down. */ + void (*pre_shutdown_fun)(struct mbedtls_test_ssl_endpoint *client, + struct mbedtls_test_ssl_endpoint *server, + void *param); + /** Value passed to ::pre_shutdown_fun. */ + void *pre_shutdown_param; void *srv_log_obj; void *cli_log_obj; void (*srv_log_fun)(void *, int, const char *, int, const char *); @@ -582,68 +601,6 @@ int mbedtls_test_move_handshake_to_state(mbedtls_ssl_context *ssl, #endif /* MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED */ -/* - * Helper function setting up inverse record transformations - * using given cipher, hash, EtM mode, authentication tag length, - * and version. - */ -#define CHK(x) \ - do \ - { \ - if (!(x)) \ - { \ - ret = -1; \ - goto cleanup; \ - } \ - } while (0) - -#if MBEDTLS_SSL_CID_OUT_LEN_MAX > MBEDTLS_SSL_CID_IN_LEN_MAX -#define SSL_CID_LEN_MIN MBEDTLS_SSL_CID_IN_LEN_MAX -#else -#define SSL_CID_LEN_MIN MBEDTLS_SSL_CID_OUT_LEN_MAX -#endif - -#if defined(MBEDTLS_SSL_PROTO_TLS1_2) && \ - defined(PSA_WANT_ALG_CBC_NO_PADDING) && defined(PSA_WANT_KEY_TYPE_AES) -int mbedtls_test_psa_cipher_encrypt_helper(mbedtls_ssl_transform *transform, - const unsigned char *iv, - size_t iv_len, - const unsigned char *input, - size_t ilen, - unsigned char *output, - size_t *olen); -#endif /* MBEDTLS_SSL_PROTO_TLS1_2 && PSA_WANT_ALG_CBC_NO_PADDING && - PSA_WANT_KEY_TYPE_AES */ - -int mbedtls_test_ssl_build_transforms(mbedtls_ssl_transform *t_in, - mbedtls_ssl_transform *t_out, - int cipher_type, int hash_id, - int etm, int tag_mode, - mbedtls_ssl_protocol_version tls_version, - size_t cid0_len, - size_t cid1_len); - -#if defined(MBEDTLS_SSL_SOME_SUITES_USE_MAC) -/** - * \param[in,out] record The record to prepare. - * It must contain the data to MAC at offset - * `record->data_offset`, of length - * `record->data_length`. - * On success, write the MAC immediately - * after the data and increment - * `record->data_length` accordingly. - * \param[in,out] transform_out The out transform, typically prepared by - * mbedtls_test_ssl_build_transforms(). - * Its HMAC context may be used. Other than that - * it is treated as an input parameter. - * - * \return 0 on success, an `MBEDTLS_ERR_xxx` error code - * or -1 on error. - */ -int mbedtls_test_ssl_prepare_record_mac(mbedtls_record *record, - mbedtls_ssl_transform *transform_out); -#endif /* MBEDTLS_SSL_SOME_SUITES_USE_MAC */ - /* * Populate a session structure for serialization tests. * Choose dummy values, mostly non-0 to distinguish from the init default. @@ -743,23 +700,6 @@ void mbedtls_test_ssl_perform_handshake( const mbedtls_test_handshake_test_options *options); #endif /* MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED */ -#if defined(MBEDTLS_TEST_HOOKS) -/* - * Tweak vector lengths in a TLS 1.3 Certificate message - * - * \param[in] buf Buffer containing the Certificate message to tweak - * \param[in]]out] end End of the buffer to parse - * \param tweak Tweak identifier (from 1 to the number of tweaks). - * \param[out] expected_result Error code expected from the parsing function - * \param[out] args Arguments of the MBEDTLS_SSL_CHK_BUF_READ_PTR call that - * is expected to fail. All zeroes if no - * MBEDTLS_SSL_CHK_BUF_READ_PTR failure is expected. - */ -int mbedtls_test_tweak_tls13_certificate_msg_vector_len( - unsigned char *buf, unsigned char **end, int tweak, - int *expected_result, mbedtls_ssl_chk_buf_ptr_args *args); -#endif /* MBEDTLS_TEST_HOOKS */ - #if defined(MBEDTLS_SSL_SESSION_TICKETS) int mbedtls_test_ticket_write( void *p_ticket, const mbedtls_ssl_session *session, @@ -806,6 +746,23 @@ int mbedtls_test_get_tls13_ticket( &psa_type, &psa_bits), \ PSA_ERROR_NOT_SUPPORTED); +/** + * Verify that mbedtls_ssl_session_reset() properly managed fields of the + * mbedtls_ssl_context structure. The expected action on reset depends on the + * specific field. + * + * Note: the code is automatically generated from the python script + * "tests/scripts/generate_ssl_session_reset_check.py". + * + * \param[in] before The SSL context before mbedtls_ssl_session_reset() + * is called on it. This is used for fields that + * should be kept untouched during the reset. + * \param[in] after The SSL context after mbedtls_ssl_session_reset() + * has been called on it. + */ +int mbedtls_test_ssl_check_context_after_session_reset(const mbedtls_ssl_context *before, + const mbedtls_ssl_context *after); + #endif /* MBEDTLS_SSL_TLS_C */ #endif /* SSL_HELPERS_H */ diff --git a/tests/include/test/ssl_helpers_internal.h b/tests/include/test/ssl_helpers_internal.h new file mode 100644 index 0000000000..7180534f79 --- /dev/null +++ b/tests/include/test/ssl_helpers_internal.h @@ -0,0 +1,110 @@ +/** \file ssl_helpers.h + * + * \brief This file contains helper functions for TLS that rely on private + * headers. + */ + +/* + * Copyright The Mbed TLS Contributors + * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later + */ + +#ifndef SSL_HELPERS_INTERNAL_H +#define SSL_HELPERS_INTERNAL_H + +#if defined(MBEDTLS_SSL_TLS_C) +#include + +#define PSA_TO_MBEDTLS_ERR(status) PSA_TO_MBEDTLS_ERR_LIST(status, \ + psa_to_ssl_errors, \ + psa_generic_status_to_mbedtls) + +enum { +#define MBEDTLS_SSL_TLS1_3_LABEL(name, string) \ + tls13_label_ ## name, + MBEDTLS_SSL_TLS1_3_LABEL_LIST +#undef MBEDTLS_SSL_TLS1_3_LABEL +}; + +/* + * Helper function setting up inverse record transformations + * using given cipher, hash, EtM mode, authentication tag length, + * and version. + */ +#define CHK(x) \ + do \ + { \ + if (!(x)) \ + { \ + ret = -1; \ + goto cleanup; \ + } \ + } while (0) + +#if MBEDTLS_SSL_CID_OUT_LEN_MAX > MBEDTLS_SSL_CID_IN_LEN_MAX +#define SSL_CID_LEN_MIN MBEDTLS_SSL_CID_IN_LEN_MAX +#else +#define SSL_CID_LEN_MIN MBEDTLS_SSL_CID_OUT_LEN_MAX +#endif + +#if defined(MBEDTLS_SSL_PROTO_TLS1_2) && \ + defined(PSA_WANT_ALG_CBC_NO_PADDING) && defined(PSA_WANT_KEY_TYPE_AES) +int mbedtls_test_psa_cipher_encrypt_helper(mbedtls_ssl_transform *transform, + const unsigned char *iv, + size_t iv_len, + const unsigned char *input, + size_t ilen, + unsigned char *output, + size_t *olen); +#endif /* MBEDTLS_SSL_PROTO_TLS1_2 && PSA_WANT_ALG_CBC_NO_PADDING && + PSA_WANT_KEY_TYPE_AES */ + +int mbedtls_test_ssl_build_transforms(mbedtls_ssl_transform *t_in, + mbedtls_ssl_transform *t_out, + int cipher_type, int hash_id, + int etm, int tag_mode, + mbedtls_ssl_protocol_version tls_version, + size_t cid0_len, + size_t cid1_len); + +#if defined(MBEDTLS_SSL_SOME_SUITES_USE_MAC) +/** + * \param[in,out] record The record to prepare. + * It must contain the data to MAC at offset + * `record->data_offset`, of length + * `record->data_length`. + * On success, write the MAC immediately + * after the data and increment + * `record->data_length` accordingly. + * \param[in,out] transform_out The out transform, typically prepared by + * mbedtls_test_ssl_build_transforms(). + * Its HMAC context may be used. Other than that + * it is treated as an input parameter. + * + * \return 0 on success, an `MBEDTLS_ERR_xxx` error code + * or -1 on error. + */ +int mbedtls_test_ssl_prepare_record_mac(mbedtls_record *record, + mbedtls_ssl_transform *transform_out); +#endif /* MBEDTLS_SSL_SOME_SUITES_USE_MAC */ + +#if defined(MBEDTLS_TEST_HOOKS) +/* + * Tweak vector lengths in a TLS 1.3 Certificate message + * + * \param[in] buf Buffer containing the Certificate message to tweak + * \param[in]]out] end End of the buffer to parse + * \param tweak Tweak identifier (from 1 to the number of tweaks). + * \param[out] expected_result Error code expected from the parsing function + * \param[out] args Arguments of the MBEDTLS_SSL_CHK_BUF_READ_PTR call that + * is expected to fail. All zeroes if no + * MBEDTLS_SSL_CHK_BUF_READ_PTR failure is expected. + */ +int mbedtls_test_tweak_tls13_certificate_msg_vector_len( + unsigned char *buf, unsigned char **end, int tweak, + int *expected_result, mbedtls_ssl_chk_buf_ptr_args *args); +#endif /* MBEDTLS_TEST_HOOKS */ + +#endif /* MBEDTLS_SSL_TLS_C */ + +#endif /* SSL_HELPERS_INTERNAL_H */ diff --git a/tests/scripts/generate_ssl_session_reset_check.py b/tests/scripts/generate_ssl_session_reset_check.py new file mode 100755 index 0000000000..8e26d9ee1a --- /dev/null +++ b/tests/scripts/generate_ssl_session_reset_check.py @@ -0,0 +1,118 @@ +#!/usr/bin/env python3 +"""Generate test code to validate mbedtls_ssl_session_reset(). +""" + +# Copyright The Mbed TLS Contributors +# SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later + +import scripts_path # pylint: disable=unused-import +from mbedtls_framework import ssl_session_reset_check + +RULES = { + 'conf': ssl_session_reset_check.ResetBehavior.KEEP, + 'state': ssl_session_reset_check.ResetBehavior.RESET, + 'flags': ssl_session_reset_check.ResetBehavior.SPECIAL, + 'renego_status': ssl_session_reset_check.ResetBehavior.RESET, + 'renego_records_seen': ssl_session_reset_check.ResetBehavior.RESET, + 'tls_version': ssl_session_reset_check.ResetBehavior.SPECIAL, + 'early_data_state': ssl_session_reset_check.ResetBehavior.RESET, + 'badmac_seen': ssl_session_reset_check.ResetBehavior.RESET, + 'f_vrfy': ssl_session_reset_check.ResetBehavior.KEEP, + 'p_vrfy': ssl_session_reset_check.ResetBehavior.KEEP, + 'f_send': ssl_session_reset_check.ResetBehavior.KEEP, + 'f_recv': ssl_session_reset_check.ResetBehavior.KEEP, + 'f_recv_timeout': ssl_session_reset_check.ResetBehavior.KEEP, + 'p_bio': ssl_session_reset_check.ResetBehavior.KEEP, + 'session_in': ssl_session_reset_check.ResetBehavior.RESET, + 'session_out': ssl_session_reset_check.ResetBehavior.RESET, + 'session': ssl_session_reset_check.ResetBehavior.RESET, + 'session_negotiate': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'handshake': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'transform_in': ssl_session_reset_check.ResetBehavior.RESET, + 'transform_out': ssl_session_reset_check.ResetBehavior.RESET, + 'transform': ssl_session_reset_check.ResetBehavior.RESET, + 'transform_negotiate': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'transform_application': ssl_session_reset_check.ResetBehavior.RESET, + 'p_timer': ssl_session_reset_check.ResetBehavior.KEEP, + 'f_set_timer': ssl_session_reset_check.ResetBehavior.KEEP, + 'f_get_timer': ssl_session_reset_check.ResetBehavior.KEEP, + 'in_buf': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'in_ctr': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'in_hdr': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'in_cid': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'in_len': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'in_iv': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'in_msg': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'in_offt': ssl_session_reset_check.ResetBehavior.RESET, + 'in_msgtype': ssl_session_reset_check.ResetBehavior.RESET, + 'in_msglen': ssl_session_reset_check.ResetBehavior.RESET, + 'in_left': ssl_session_reset_check.ResetBehavior.RESET, + 'in_buf_len': ssl_session_reset_check.ResetBehavior.SPECIAL, + 'in_epoch': ssl_session_reset_check.ResetBehavior.RESET, + 'next_record_offset': ssl_session_reset_check.ResetBehavior.RESET, + 'in_window_top': ssl_session_reset_check.ResetBehavior.RESET, + 'in_window': ssl_session_reset_check.ResetBehavior.RESET, + 'in_hslen': ssl_session_reset_check.ResetBehavior.RESET, + 'in_hsfraglen': ssl_session_reset_check.ResetBehavior.RESET, + 'nb_zero': ssl_session_reset_check.ResetBehavior.RESET, + 'keep_current_message': ssl_session_reset_check.ResetBehavior.RESET, + 'in_fatal_alert_recv': ssl_session_reset_check.ResetBehavior.RESET, + 'in_fatal_alert_type': ssl_session_reset_check.ResetBehavior.RESET, + 'send_alert': ssl_session_reset_check.ResetBehavior.RESET, + 'alert_type': ssl_session_reset_check.ResetBehavior.RESET, + 'alert_reason': ssl_session_reset_check.ResetBehavior.RESET, + 'disable_datagram_packing': ssl_session_reset_check.ResetBehavior.KEEP, + 'discard_early_data_record': ssl_session_reset_check.ResetBehavior.RESET, + 'total_early_data_size': ssl_session_reset_check.ResetBehavior.RESET, + 'out_buf': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'out_ctr': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'out_hdr': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'out_cid': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'out_len': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'out_iv': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'out_msg': ssl_session_reset_check.ResetBehavior.REALLOCATE, + 'out_msgtype': ssl_session_reset_check.ResetBehavior.RESET, + 'out_msglen': ssl_session_reset_check.ResetBehavior.RESET, + 'out_left': ssl_session_reset_check.ResetBehavior.RESET, + 'out_buf_len': ssl_session_reset_check.ResetBehavior.SPECIAL, + 'cur_out_ctr': ssl_session_reset_check.ResetBehavior.RESET, + 'mtu': ssl_session_reset_check.ResetBehavior.KEEP, + 'hostname': ssl_session_reset_check.ResetBehavior.KEEP, + 'alpn_chosen': ssl_session_reset_check.ResetBehavior.RESET, + 'dtls_srtp_info': ssl_session_reset_check.ResetBehavior.RESET, + 'cli_id': ssl_session_reset_check.ResetBehavior.RESET, + 'cli_id_len': ssl_session_reset_check.ResetBehavior.RESET, + 'secure_renegotiation': ssl_session_reset_check.ResetBehavior.RESET, + 'verify_data_len': ssl_session_reset_check.ResetBehavior.RESET, + 'own_verify_data': ssl_session_reset_check.ResetBehavior.RESET, + 'peer_verify_data': ssl_session_reset_check.ResetBehavior.RESET, + 'own_cid': ssl_session_reset_check.ResetBehavior.KEEP, + 'own_cid_len': ssl_session_reset_check.ResetBehavior.KEEP, + 'negotiate_cid': ssl_session_reset_check.ResetBehavior.KEEP, + 'f_export_keys': ssl_session_reset_check.ResetBehavior.KEEP, + 'p_export_keys': ssl_session_reset_check.ResetBehavior.KEEP, + 'user_data': ssl_session_reset_check.ResetBehavior.SPECIAL, + 'unused': ssl_session_reset_check.ResetBehavior.IGNORE, +} + +SPECIAL_BEHAVIORS = { + 'flags': ['TEST_EQUAL((after->flags & ~(MBEDTLS_SSL_CONTEXT_FLAGS_KEEP_AT_SESSION)), ' + + 'initial.flags);', + 'TEST_EQUAL((before->flags & MBEDTLS_SSL_CONTEXT_FLAGS_KEEP_AT_SESSION), ' + + '(after->flags & MBEDTLS_SSL_CONTEXT_FLAGS_KEEP_AT_SESSION));'], + 'tls_version': ['TEST_ASSERT(after->tls_version == after->conf->max_tls_version);'], + 'user_data': ['TEST_ASSERT(before->user_data.n == after->user_data.n);'], + 'in_buf_len': ['TEST_ASSERT(after->in_buf_len == MBEDTLS_SSL_IN_BUFFER_LEN);'], + 'out_buf_len': ['TEST_ASSERT(after->out_buf_len == MBEDTLS_SSL_OUT_BUFFER_LEN);'], +} + +NAMED_STRUCTURES = frozenset([ + 'dtls_srtp_info', +]) + +FIELDS_INFO = ssl_session_reset_check.FieldsInfo(RULES, + SPECIAL_BEHAVIORS, + NAMED_STRUCTURES) + +if __name__ == '__main__': + ssl_session_reset_check.main(FIELDS_INFO) diff --git a/tests/src/ssl_context_reset_verifier.c b/tests/src/ssl_context_reset_verifier.c new file mode 100644 index 0000000000..a0fda308ec --- /dev/null +++ b/tests/src/ssl_context_reset_verifier.c @@ -0,0 +1,190 @@ +/* + * Copyright The Mbed TLS Contributors + * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later + */ + +/* + * The following function was automatically generated through the script + * ./tests/scripts/generate_ssl_session_reset_check.py. + */ + +#include +#include +#include "mbedtls/psa_util.h" +#include + +#include + +#if defined(MBEDTLS_SSL_TLS_C) + +int mbedtls_test_ssl_check_context_after_session_reset(const mbedtls_ssl_context *before, + const mbedtls_ssl_context *after) +{ + mbedtls_ssl_context initial; + int ret = -1; + + /* Create a freshly initialized SSL context*/ + memset(&initial, 0, sizeof(initial)); + mbedtls_ssl_init(&initial); + TEST_EQUAL(mbedtls_ssl_setup(&initial, after->conf), 0); + + /* *INDENT-OFF* */ + TEST_ASSERT(before->conf == after->conf); + TEST_ASSERT(after->state == initial.state); + TEST_EQUAL((after->flags & ~(MBEDTLS_SSL_CONTEXT_FLAGS_KEEP_AT_SESSION)), initial.flags); + TEST_EQUAL((before->flags & MBEDTLS_SSL_CONTEXT_FLAGS_KEEP_AT_SESSION), (after->flags & MBEDTLS_SSL_CONTEXT_FLAGS_KEEP_AT_SESSION)); +#if defined(MBEDTLS_SSL_RENEGOTIATION) + TEST_ASSERT(after->renego_status == initial.renego_status); +#endif +#if defined(MBEDTLS_SSL_RENEGOTIATION) + TEST_ASSERT(after->renego_records_seen == initial.renego_records_seen); +#endif + TEST_ASSERT(after->tls_version == after->conf->max_tls_version); +#if defined(MBEDTLS_SSL_EARLY_DATA) && defined(MBEDTLS_SSL_CLI_C) + TEST_ASSERT(after->early_data_state == initial.early_data_state); +#endif + TEST_ASSERT(after->badmac_seen == initial.badmac_seen); +#if defined(MBEDTLS_X509_CRT_PARSE_C) + TEST_ASSERT(before->f_vrfy == after->f_vrfy); +#endif +#if defined(MBEDTLS_X509_CRT_PARSE_C) + TEST_ASSERT(before->p_vrfy == after->p_vrfy); +#endif + TEST_ASSERT(before->f_send == after->f_send); + TEST_ASSERT(before->f_recv == after->f_recv); + TEST_ASSERT(before->f_recv_timeout == after->f_recv_timeout); + TEST_ASSERT(before->p_bio == after->p_bio); + TEST_ASSERT(after->session_in == initial.session_in); + TEST_ASSERT(after->session_out == initial.session_out); + TEST_ASSERT(after->session == initial.session); + TEST_ASSERT(after->session_negotiate != NULL); + TEST_ASSERT(after->handshake != NULL); + TEST_ASSERT(after->transform_in == initial.transform_in); + TEST_ASSERT(after->transform_out == initial.transform_out); + TEST_ASSERT(after->transform == initial.transform); +#if defined(MBEDTLS_SSL_PROTO_TLS1_2) + TEST_ASSERT(after->transform_negotiate != NULL); +#endif +#if defined(MBEDTLS_SSL_PROTO_TLS1_3) + TEST_ASSERT(after->transform_application == initial.transform_application); +#endif + TEST_ASSERT(before->p_timer == after->p_timer); + TEST_ASSERT(before->f_set_timer == after->f_set_timer); + TEST_ASSERT(before->f_get_timer == after->f_get_timer); + TEST_ASSERT(after->in_buf != NULL); + TEST_ASSERT(after->in_ctr != NULL); + TEST_ASSERT(after->in_hdr != NULL); +#if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) + TEST_ASSERT(after->in_cid != NULL); +#endif + TEST_ASSERT(after->in_len != NULL); + TEST_ASSERT(after->in_iv != NULL); + TEST_ASSERT(after->in_msg != NULL); + TEST_ASSERT(after->in_offt == initial.in_offt); + TEST_ASSERT(after->in_msgtype == initial.in_msgtype); + TEST_ASSERT(after->in_msglen == initial.in_msglen); + TEST_ASSERT(after->in_left == initial.in_left); +#if defined(MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH) + TEST_ASSERT(after->in_buf_len == MBEDTLS_SSL_IN_BUFFER_LEN); +#endif +#if defined(MBEDTLS_SSL_PROTO_DTLS) + TEST_ASSERT(after->in_epoch == initial.in_epoch); +#endif +#if defined(MBEDTLS_SSL_PROTO_DTLS) + TEST_ASSERT(after->next_record_offset == initial.next_record_offset); +#endif +#if defined(MBEDTLS_SSL_DTLS_ANTI_REPLAY) + TEST_ASSERT(after->in_window_top == initial.in_window_top); +#endif +#if defined(MBEDTLS_SSL_DTLS_ANTI_REPLAY) + TEST_ASSERT(after->in_window == initial.in_window); +#endif + TEST_ASSERT(after->in_hslen == initial.in_hslen); + TEST_ASSERT(after->in_hsfraglen == initial.in_hsfraglen); + TEST_ASSERT(after->nb_zero == initial.nb_zero); + TEST_ASSERT(after->keep_current_message == initial.keep_current_message); + TEST_ASSERT(after->in_fatal_alert_recv == initial.in_fatal_alert_recv); + TEST_ASSERT(after->in_fatal_alert_type == initial.in_fatal_alert_type); + TEST_ASSERT(after->send_alert == initial.send_alert); + TEST_ASSERT(after->alert_type == initial.alert_type); + TEST_ASSERT(after->alert_reason == initial.alert_reason); +#if defined(MBEDTLS_SSL_PROTO_DTLS) + TEST_EQUAL(before->disable_datagram_packing, after->disable_datagram_packing); +#endif +#if defined(MBEDTLS_SSL_EARLY_DATA) + +#if defined(MBEDTLS_SSL_SRV_C) + TEST_ASSERT(after->discard_early_data_record == initial.discard_early_data_record); +#endif +#endif +#if defined(MBEDTLS_SSL_EARLY_DATA) + TEST_ASSERT(after->total_early_data_size == initial.total_early_data_size); +#endif + TEST_ASSERT(after->out_buf != NULL); + TEST_ASSERT(after->out_ctr != NULL); + TEST_ASSERT(after->out_hdr != NULL); +#if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) + TEST_ASSERT(after->out_cid != NULL); +#endif + TEST_ASSERT(after->out_len != NULL); + TEST_ASSERT(after->out_iv != NULL); + TEST_ASSERT(after->out_msg != NULL); + TEST_ASSERT(after->out_msgtype == initial.out_msgtype); + TEST_ASSERT(after->out_msglen == initial.out_msglen); + TEST_ASSERT(after->out_left == initial.out_left); +#if defined(MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH) + TEST_ASSERT(after->out_buf_len == MBEDTLS_SSL_OUT_BUFFER_LEN); +#endif + TEST_MEMORY_COMPARE(after->cur_out_ctr, sizeof(after->cur_out_ctr), initial.cur_out_ctr, sizeof(initial.cur_out_ctr)); +#if defined(MBEDTLS_SSL_PROTO_DTLS) + TEST_EQUAL(before->mtu, after->mtu); +#endif +#if defined(MBEDTLS_X509_CRT_PARSE_C) + TEST_ASSERT(before->hostname == after->hostname); +#endif +#if defined(MBEDTLS_SSL_ALPN) + TEST_ASSERT(after->alpn_chosen == initial.alpn_chosen); +#endif +#if defined(MBEDTLS_SSL_DTLS_SRTP) + TEST_MEMORY_COMPARE(&(after->dtls_srtp_info), sizeof(after->dtls_srtp_info), &(initial.dtls_srtp_info), sizeof(initial.dtls_srtp_info)); +#endif +#if defined(MBEDTLS_SSL_DTLS_HELLO_VERIFY) && defined(MBEDTLS_SSL_SRV_C) + TEST_ASSERT(after->cli_id == initial.cli_id); +#endif +#if defined(MBEDTLS_SSL_DTLS_HELLO_VERIFY) && defined(MBEDTLS_SSL_SRV_C) + TEST_ASSERT(after->cli_id_len == initial.cli_id_len); +#endif + TEST_ASSERT(after->secure_renegotiation == initial.secure_renegotiation); +#if defined(MBEDTLS_SSL_RENEGOTIATION) + TEST_ASSERT(after->verify_data_len == initial.verify_data_len); +#endif +#if defined(MBEDTLS_SSL_RENEGOTIATION) + TEST_MEMORY_COMPARE(after->own_verify_data, sizeof(after->own_verify_data), initial.own_verify_data, sizeof(initial.own_verify_data)); +#endif +#if defined(MBEDTLS_SSL_RENEGOTIATION) + TEST_MEMORY_COMPARE(after->peer_verify_data, sizeof(after->peer_verify_data), initial.peer_verify_data, sizeof(initial.peer_verify_data)); +#endif +#if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) + TEST_MEMORY_COMPARE(before->own_cid, sizeof(before->own_cid), after->own_cid, sizeof(after->own_cid)); +#endif +#if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) + TEST_EQUAL(before->own_cid_len, after->own_cid_len); +#endif +#if defined(MBEDTLS_SSL_DTLS_CONNECTION_ID) + TEST_EQUAL(before->negotiate_cid, after->negotiate_cid); +#endif + TEST_ASSERT(before->f_export_keys == after->f_export_keys); + TEST_ASSERT(before->p_export_keys == after->p_export_keys); + TEST_ASSERT(before->user_data.n == after->user_data.n); + /* unused is ignored */ + /* *INDENT-ON* */ + + ret = 0; + +exit: + mbedtls_ssl_free(&initial); + + return ret; +} + +#endif /* MBEDTLS_SSL_TLS_C */ diff --git a/tests/src/test_helpers/ssl_helpers.c b/tests/src/test_helpers/ssl_helpers.c index db29413de6..ebb9103de9 100644 --- a/tests/src/test_helpers/ssl_helpers.c +++ b/tests/src/test_helpers/ssl_helpers.c @@ -9,6 +9,8 @@ */ #include +#include +#include #include "mbedtls/psa_util.h" #include @@ -1033,6 +1035,17 @@ int mbedtls_test_ssl_endpoint_init( void mbedtls_test_ssl_endpoint_free( mbedtls_test_ssl_endpoint *ep) { + // mbedtls_ssl_session_reset() requires the SSL to be setup. + if (ep->ssl.conf != NULL) { + mbedtls_ssl_context ssl_before; + + /* Dump the SSL context before resetting it */ + memcpy(&ssl_before, &(ep->ssl), sizeof(mbedtls_ssl_context)); + + mbedtls_ssl_session_reset(&(ep->ssl)); + /* Check that required fields were properly reset */ + mbedtls_test_ssl_check_context_after_session_reset(&ssl_before, &(ep->ssl)); + } mbedtls_ssl_free(&(ep->ssl)); mbedtls_ssl_config_free(&(ep->conf)); @@ -2282,6 +2295,10 @@ int mbedtls_test_ssl_perform_connection( expected_handshake_result = MBEDTLS_ERR_SSL_BAD_PROTOCOL_VERSION; } + if (options->pre_handshake_fun != NULL) { + options->pre_handshake_fun(client, server, options->pre_handshake_param); + } + TEST_EQUAL(mbedtls_test_move_handshake_to_state(&(client->ssl), &(server->ssl), MBEDTLS_SSL_HANDSHAKE_OVER), @@ -2313,6 +2330,10 @@ int mbedtls_test_ssl_perform_connection( options->expected_ciphersuite); } + if (options->post_handshake_fun != NULL) { + options->post_handshake_fun(client, server, options->post_handshake_param); + } + #if defined(MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH) if (options->resize_buffers != 0) { /* A server, when using DTLS, might delay a buffer resize to happen @@ -2339,6 +2360,11 @@ int mbedtls_test_ssl_perform_connection( options->expected_srv_fragments), 0); } + + if (options->post_data_fun != NULL) { + options->post_data_fun(client, server, options->post_data_param); + } + #if defined(MBEDTLS_SSL_CONTEXT_SERIALIZATION) if (options->serialize == 1) { TEST_ASSERT(test_serialization(options, client, server)); @@ -2396,6 +2422,10 @@ void mbedtls_test_ssl_perform_handshake( TEST_ASSERT(mbedtls_ssl_conf_get_user_data_p(&server->conf) == server); TEST_ASSERT(mbedtls_ssl_get_user_data_p(&server->ssl) == server); + if (options->pre_shutdown_fun != NULL) { + options->pre_shutdown_fun(client, server, options->pre_shutdown_param); + } + exit: mbedtls_test_ssl_endpoint_free(client); mbedtls_test_ssl_endpoint_free(server); diff --git a/tests/ssl-opt.sh b/tests/ssl-opt.sh index 6fa14924b3..9d9209dc1e 100755 --- a/tests/ssl-opt.sh +++ b/tests/ssl-opt.sh @@ -5269,6 +5269,7 @@ run_test "Renegotiation: client-initiated, server-rejected" \ -c "=> renegotiate" \ -S "=> renegotiate" \ -S "write hello request" \ + -s "refusing renegotiation" \ -c "SSL - Unexpected message at ServerHello in renegotiation" \ -c "failed" @@ -5285,6 +5286,7 @@ run_test "Renegotiation: server-initiated, client-rejected, default" \ -C "=> renegotiate" \ -S "=> renegotiate" \ -s "write hello request" \ + -c "refusing renegotiation" \ -S "SSL - An unexpected message was received from our peer" \ -S "failed" @@ -5302,6 +5304,7 @@ run_test "Renegotiation: server-initiated, client-rejected, not enforced" \ -C "=> renegotiate" \ -S "=> renegotiate" \ -s "write hello request" \ + -c "refusing renegotiation" \ -S "SSL - An unexpected message was received from our peer" \ -S "failed" @@ -5320,6 +5323,7 @@ run_test "Renegotiation: server-initiated, client-rejected, delay 2" \ -C "=> renegotiate" \ -S "=> renegotiate" \ -s "write hello request" \ + -c "refusing renegotiation" \ -S "SSL - An unexpected message was received from our peer" \ -S "failed" @@ -5337,6 +5341,7 @@ run_test "Renegotiation: server-initiated, client-rejected, delay 0" \ -C "=> renegotiate" \ -S "=> renegotiate" \ -s "write hello request" \ + -c "refusing renegotiation" \ -s "SSL - An unexpected message was received from our peer" requires_config_enabled MBEDTLS_SSL_RENEGOTIATION @@ -5353,6 +5358,7 @@ run_test "Renegotiation: server-initiated, client-accepted, delay 0" \ -c "=> renegotiate" \ -s "=> renegotiate" \ -s "write hello request" \ + -C "refusing renegotiation" \ -S "SSL - An unexpected message was received from our peer" \ -S "failed" @@ -8382,6 +8388,37 @@ run_test "extKeyUsage cli-auth 1.3: codeSign -> fail (hard)" \ -s "Processing of the Certificate handshake message failed" # MBEDTLS_X509_BADCERT_EXT_KEY_USAGE -> MBEDTLS_SSL_ALERT_MSG_UNSUPPORTED_CERT +# Miscellaneous PSK-related tests + +psk_identity_max_minus_10=a$(printf "%$((MAX_OUT_LEN - 11))s" z | tr ' ' .) + +run_test "Large PSK identity (MBEDTLS_SSL_OUT_CONTENT_LEN - 7)" \ + "$P_SRV debug_level=3 \ + psk_identity=${psk_identity_max_minus_10}987 psk=73776f726466697368" \ + "$P_CLI force_ciphersuite=TLS-ECDHE-PSK-WITH-AES-128-CBC-SHA256 debug_level=3 \ + psk_identity=${psk_identity_max_minus_10}987 psk=73776f726466697368" \ + 1 \ + -s "! mbedtls_ssl_handshake returned" \ + -c "! mbedtls_ssl_handshake returned" + +run_test "Large PSK identity (MBEDTLS_SSL_OUT_CONTENT_LEN - 6)" \ + "$P_SRV debug_level=3 \ + psk_identity=${psk_identity_max_minus_10}9876 psk=73776f726466697368" \ + "$P_CLI force_ciphersuite=TLS-ECDHE-PSK-WITH-AES-128-CBC-SHA256 debug_level=3 \ + psk_identity=${psk_identity_max_minus_10}9876 psk=73776f726466697368" \ + 1 \ + -s "! mbedtls_ssl_handshake returned" \ + -c "! mbedtls_ssl_handshake returned" + +run_test "Large PSK identity (MBEDTLS_SSL_OUT_CONTENT_LEN - 5)" \ + "$P_SRV debug_level=3 \ + psk_identity=${psk_identity_max_minus_10}98765 psk=73776f726466697368" \ + "$P_CLI force_ciphersuite=TLS-ECDHE-PSK-WITH-AES-128-CBC-SHA256 debug_level=3 \ + psk_identity=${psk_identity_max_minus_10}98765 psk=73776f726466697368" \ + 1 \ + -s "! mbedtls_ssl_handshake returned" \ + -c "! mbedtls_ssl_handshake returned" + # Tests for PSK callback run_test "PSK callback: psk, no callback" \ @@ -11769,6 +11806,147 @@ run_test "DTLS proxy: inject invalid AD record, badmac_limit 2, exchanges 2"\ -s "too many records with bad MAC" \ -s "Verification of the message MAC failed" +# The next few tests exercise renegotiation in DTLS when `ssl->badmac_seen != 0`. +# +# This seems unrelated, but was the location of a bug in Mbed TLS 3.6.3 to +# 3.6.6 (CVE-2026-50713) due to `ssl->badmac_seen` being unified with +# `ssl->in_hsfraglen` (to preserve the ABI when adding support for handshake +# defragmentation in TLS in 3.6.3), with some mistakes in using the unified +# field that were fixed in 3.6.7. + +requires_config_enabled MBEDTLS_SSL_RENEGOTIATION +run_test "DTLS proxy: client: get invalid AD record then reject renego" \ + -p "$P_PXY bad_ad_srv_once=1" \ + "$P_SRV dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiate=1 renegotiation=1 exchanges=4 \ + debug_level=3" \ + "$P_CLI dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + exchanges=4 badmac_limit=99 debug_level=3" \ + 0 \ + -s "write hello request" \ + -c "refusing renegotiation" \ + -S "=> renegotiate" \ + -C "=> renegotiate" \ + -s "Extra-header:" \ + -c "HTTP/1.0 200 OK" \ + -c "discarding invalid record (mac)" \ + -C "too many records with bad MAC" \ + -C "Verification of the message MAC failed" \ + -C "Consume: waiting for more handshake fragments" + +requires_config_enabled MBEDTLS_SSL_RENEGOTIATION +run_test "DTLS proxy: server: get invalid AD record then reject renego" \ + -p "$P_PXY bad_ad_cli_once=1" \ + "$P_SRV dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiation=0 exchanges=4 \ + badmac_limit=99 debug_level=3" \ + "$P_CLI dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiation=1 renegotiate=2 exchanges=4 debug_level=3" \ + 1 \ + -s "discarding invalid record (mac)" \ + -c "=> renegotiate" \ + -S "=> renegotiate" \ + -s "refusing renegotiation" \ + -s "Extra-header:" \ + -c "HTTP/1.0 200 OK" \ + -S "too many records with bad MAC" \ + -S "Verification of the message MAC failed" \ + -S "Consume: waiting for more handshake fragments" + +requires_config_enabled MBEDTLS_SSL_RENEGOTIATION +run_test "DTLS proxy: client: get invalid AD record then accept renego" \ + -p "$P_PXY bad_ad_srv_once=1" \ + "$P_SRV dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiate=1 renegotiation=1 exchanges=4 \ + debug_level=3" \ + "$P_CLI dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiation=1 exchanges=4 badmac_limit=99 debug_level=3" \ + 0 \ + -s "=> renegotiate" \ + -c "=> renegotiate" \ + -s "Extra-header:" \ + -c "HTTP/1.0 200 OK" \ + -c "discarding invalid record (mac)" \ + -C "too many records with bad MAC" \ + -C "Verification of the message MAC failed" \ + -C "Consume: waiting for more handshake fragments" + +requires_config_enabled MBEDTLS_SSL_RENEGOTIATION +run_test "DTLS proxy: server: get invalid AD record then accept renego" \ + -p "$P_PXY bad_ad_cli_once=1" \ + "$P_SRV dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiation=1 exchanges=4 \ + badmac_limit=99 debug_level=3" \ + "$P_CLI dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiation=1 renegotiate=2 exchanges=4 debug_level=3" \ + 0 \ + -s "discarding invalid record (mac)" \ + -c "=> renegotiate" \ + -s "=> renegotiate" \ + -s "Extra-header:" \ + -c "HTTP/1.0 200 OK" \ + -S "too many records with bad MAC" \ + -S "Verification of the message MAC failed" \ + -S "Consume: waiting for more handshake fragments" + +# The next few tests have "early renego". A DTLS handshake message is delayed +# past another handshake message. From the perspective of the recipient, +# this means that a DTLS handshake arrives early (its epoch number is still +# in the future) and needs to be queued. +# +# In Mbed TLS 3.6.3 through 3.6.6, due to the fields `ssl->badmac_seen` +# and `ssl->in_hsfraglen` being unified, the early message was parsed +# incorrectly, leading to heap corruption. + +requires_config_enabled MBEDTLS_SSL_RENEGOTIATION +run_test "DTLS proxy: client: get invalid AD record then reject early renego" \ + -p "$P_PXY bad_ad_srv_once=1 delay_encrypted_hs_srv=3" \ + "$P_SRV dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiate=1 renegotiation=1 exchanges=4 \ + debug_level=3" \ + "$P_CLI dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + exchanges=4 badmac_limit=99 debug_level=3" \ + 0 \ + -S "=> renegotiate" \ + -C "=> renegotiate" \ + -s "write hello request" \ + -c "refusing renegotiation" \ + -C "=> ssl_buffer_message" \ + -C "initialize reassembly, total length = 0" \ + -s "Extra-header:" \ + -c "HTTP/1.0 200 OK" \ + -c "discarding invalid record (mac)" \ + -C "too many records with bad MAC" \ + -C "Verification of the message MAC failed" \ + -C "Consume: waiting for more handshake fragments" + +# Delay the third encrypted handshake message from the server: +# 1. Finished message of the initial handshake. +# 2. HelloRequest to request renegotiation. +# 3. ServerHello of renegotiation, delayed. +# 4. Subsequent handshake message, which the client receives and enqueues. +# +# In Mbed TLS 3.6.3 though 3.6.6, the processing of (4) caused heap corruption. +requires_config_enabled MBEDTLS_SSL_RENEGOTIATION +run_test "DTLS proxy: client: get invalid AD record then accept early renego" \ + -p "$P_PXY bad_ad_srv_once=1 delay_encrypted_hs_srv=3" \ + "$P_SRV dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiate=1 renegotiation=1 exchanges=4 \ + debug_level=3" \ + "$P_CLI dtls=1 dgram_packing=0 hs_timeout=500-10000 \ + renegotiation=1 exchanges=4 badmac_limit=99 debug_level=3" \ + 0 \ + -s "=> renegotiate" \ + -c "=> renegotiate" \ + -c "=> ssl_buffer_message" \ + -C "initialize reassembly, total length = 0" \ + -s "Extra-header:" \ + -c "HTTP/1.0 200 OK" \ + -c "discarding invalid record (mac)" \ + -C "too many records with bad MAC" \ + -C "Verification of the message MAC failed" \ + -C "Consume: waiting for more handshake fragments" + requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2 run_test "DTLS proxy: delay ChangeCipherSpec" \ -p "$P_PXY delay_ccs=1" \ diff --git a/tests/suites/test_suite_pkcs7.data b/tests/suites/test_suite_pkcs7.data index 3e3f7f1d7d..71a6b03fc3 100644 --- a/tests/suites/test_suite_pkcs7.data +++ b/tests/suites/test_suite_pkcs7.data @@ -14,6 +14,14 @@ PKCS7 Signed Data Parse with zero signers depends_on:PSA_WANT_ALG_SHA_256 pkcs7_parse:"../framework/data_files/pkcs7_data_no_signers.der":MBEDTLS_PKCS7_SIGNED_DATA +PKCS7 Signed Data Parse reused object after multiple signers +depends_on:PSA_WANT_ALG_SHA_256:PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY +pkcs7_parse_reuse:"../framework/data_files/pkcs7_data_multiple_signed.der":"../framework/data_files/pkcs7_data_no_signers.der":MBEDTLS_PKCS7_SIGNED_DATA + +PKCS7 Signed Data Parse reused object from multiple signers to one signer +depends_on:PSA_WANT_ALG_SHA_256:PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY +pkcs7_parse_reuse:"../framework/data_files/pkcs7_data_multiple_signed.der":"../framework/data_files/pkcs7_data_cert_signed_sha256.der":MBEDTLS_PKCS7_SIGNED_DATA + PKCS7 Signed Data Parse Fail with multiple certs #4 depends_on:PSA_WANT_ALG_SHA_256:PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY pkcs7_parse:"../framework/data_files/pkcs7_data_multiple_certs_signed.der":MBEDTLS_ERR_PKCS7_FEATURE_UNAVAILABLE @@ -86,10 +94,30 @@ PKCS7 Signed Data Verification Pass SHA256 #9.1 depends_on:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY pkcs7_verify:"../framework/data_files/pkcs7_data_cert_signed_sha256.der":"../framework/data_files/pkcs7-rsa-sha256-1.der":"../framework/data_files/pkcs7_data.bin":MBEDTLS_MD_SHA256:0 +PKCS7 Signed Data Verification Fail SHA1 #10 +depends_on:PSA_WANT_ALG_SHA_1:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY:!MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES +pkcs7_verify:"../framework/data_files/pkcs7_data_cert_signed_sha1.der":"../framework/data_files/pkcs7-rsa-sha256-1.der":"../framework/data_files/pkcs7_data.bin":0:MBEDTLS_ERR_PKCS7_INVALID_ALG + PKCS7 Signed Data Verification Pass SHA1 #10 -depends_on:PSA_WANT_ALG_SHA_1:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY +depends_on:PSA_WANT_ALG_SHA_1:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY:MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES pkcs7_verify:"../framework/data_files/pkcs7_data_cert_signed_sha1.der":"../framework/data_files/pkcs7-rsa-sha256-1.der":"../framework/data_files/pkcs7_data.bin":0:0 +PKCS7 Signed Data Verification Fail MD5 #10.1 +depends_on:PSA_WANT_ALG_MD5:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY:!MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES +pkcs7_verify:"../framework/data_files/pkcs7_data_cert_signed_md5.der":"../framework/data_files/pkcs7-rsa-sha256-1.der":"../framework/data_files/pkcs7_data.bin":0:MBEDTLS_ERR_PKCS7_INVALID_ALG + +PKCS7 Signed Data Verification Pass MD5 #10.1 +depends_on:PSA_WANT_ALG_MD5:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY:MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES +pkcs7_verify:"../framework/data_files/pkcs7_data_cert_signed_md5.der":"../framework/data_files/pkcs7-rsa-sha256-1.der":"../framework/data_files/pkcs7_data.bin":0:0 + +PKCS7 Signed Data Verification Fail RIPEMD160 #10.2 +depends_on:PSA_WANT_ALG_RIPEMD160:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY:!MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES +pkcs7_verify:"../framework/data_files/pkcs7_data_cert_signed_ripemd160.der":"../framework/data_files/pkcs7-rsa-sha256-1.der":"../framework/data_files/pkcs7_data.bin":0:MBEDTLS_ERR_PKCS7_INVALID_ALG + +PKCS7 Signed Data Verification Pass RIPEMD160 #10.2 +depends_on:PSA_WANT_ALG_RIPEMD160:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY:MBEDTLS_PKCS7_ALLOW_WEAK_SIGNATURES +pkcs7_verify:"../framework/data_files/pkcs7_data_cert_signed_ripemd160.der":"../framework/data_files/pkcs7-rsa-sha256-1.der":"../framework/data_files/pkcs7_data.bin":0:0 + PKCS7 Signed Data Verification Pass SHA512 #11 depends_on:PSA_WANT_ALG_SHA_512:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_RSA_PKCS1V15_VERIFY pkcs7_verify:"../framework/data_files/pkcs7_data_cert_signed_sha512.der":"../framework/data_files/pkcs7-rsa-sha256-1.der":"../framework/data_files/pkcs7_data.bin":0:0 diff --git a/tests/suites/test_suite_pkcs7.function b/tests/suites/test_suite_pkcs7.function index 9eccabab22..3bd7595b96 100644 --- a/tests/suites/test_suite_pkcs7.function +++ b/tests/suites/test_suite_pkcs7.function @@ -25,8 +25,10 @@ static int pkcs7_parse_buffer(unsigned char *pkcs7_buf, int buflen) mbedtls_pkcs7_init(&pkcs7); res = mbedtls_pkcs7_parse_der(&pkcs7, pkcs7_buf, buflen); mbedtls_pkcs7_free(&pkcs7); + return res; } + /* END_SUITE_HELPERS */ /* BEGIN_CASE */ @@ -71,6 +73,48 @@ exit: } /* END_CASE */ +/* BEGIN_CASE depends_on:MBEDTLS_FS_IO */ +void pkcs7_parse_reuse(char *first_pkcs7_file, char *second_pkcs7_file, + int res_expect) +{ + unsigned char *first_pkcs7_buf = NULL; + unsigned char *second_pkcs7_buf = NULL; + mbedtls_pkcs7 pkcs7; + size_t first_buflen; + size_t second_buflen; + + mbedtls_pkcs7_init(&pkcs7); + + /* PKCS7 uses X509 which itself relies on PK under the hood and the latter + * can use PSA to store keys and perform operations so psa_crypto_init() + * must be called before. */ + USE_PSA_INIT(); + + TEST_EQUAL(mbedtls_pk_load_file(first_pkcs7_file, &first_pkcs7_buf, + &first_buflen), 0); + + TEST_EQUAL(mbedtls_pk_load_file(second_pkcs7_file, &second_pkcs7_buf, + &second_buflen), 0); + + TEST_EQUAL(mbedtls_pkcs7_parse_der(&pkcs7, first_pkcs7_buf, + first_buflen), + MBEDTLS_PKCS7_SIGNED_DATA); + + mbedtls_pkcs7_free(&pkcs7); + TEST_ASSERT(pkcs7.raw.p == NULL); + TEST_ASSERT(pkcs7.signed_data.signers.next == NULL); + TEST_EQUAL(mbedtls_pkcs7_parse_der(&pkcs7, second_pkcs7_buf, + second_buflen), + res_expect); + +exit: + mbedtls_free(first_pkcs7_buf); + mbedtls_free(second_pkcs7_buf); + mbedtls_pkcs7_free(&pkcs7); + USE_PSA_DONE(); +} +/* END_CASE */ + /* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:PSA_HAVE_ALG_SOME_RSA_VERIFY */ void pkcs7_verify(char *pkcs7_file, char *crt_files, diff --git a/tests/suites/test_suite_ssl.data b/tests/suites/test_suite_ssl.data index aba17ff145..f7876d993e 100644 --- a/tests/suites/test_suite_ssl.data +++ b/tests/suites/test_suite_ssl.data @@ -471,6 +471,14 @@ Handshake, select ECDHE-ECDSA-WITH-AES-256-CCM, opaque, bad usage depends_on:PSA_WANT_ALG_SHA_256:PSA_WANT_KEY_TYPE_AES:PSA_WANT_ALG_CCM:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ECC_SECP_R1_384:MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED:!MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH handshake_ciphersuite_select:"TLS-ECDHE-ECDSA-WITH-AES-256-CCM":MBEDTLS_PK_ECDSA:"":PSA_ALG_ECDSA(PSA_ALG_ANY_HASH):PSA_ALG_NONE:PSA_KEY_USAGE_DERIVE:MBEDTLS_ERR_SSL_HANDSHAKE_FAILURE:0 +Handshake: DTLS 1.2, badmac_seen on client +depends_on:MBEDTLS_SSL_PROTO_DTLS:MBEDTLS_SSL_PROTO_TLS1_2 +handshake_with_forced_context:1:MBEDTLS_SSL_VERSION_TLS1_2:PRE_HANDSHAKE_BADMAC_SEEN:0 + +Handshake: DTLS 1.2, badmac_seen on server +depends_on:MBEDTLS_SSL_PROTO_DTLS:MBEDTLS_SSL_PROTO_TLS1_2 +handshake_with_forced_context:1:MBEDTLS_SSL_VERSION_TLS1_2:0:PRE_HANDSHAKE_BADMAC_SEEN + Sending app data via TLS, MFL=512 without fragmentation depends_on:MBEDTLS_SSL_MAX_FRAGMENT_LENGTH app_data_tls:MBEDTLS_SSL_MAX_FRAG_LEN_512:400:512:1:1 @@ -548,13 +556,19 @@ Sending app data via DTLS, without MFL and with fragmentation app_data_dtls:MBEDTLS_SSL_MAX_FRAG_LEN_NONE:16385:100000:0:0 DTLS renegotiation: no legacy renegotiation -renegotiation:MBEDTLS_SSL_LEGACY_NO_RENEGOTIATION +renegotiation:MBEDTLS_SSL_LEGACY_NO_RENEGOTIATION:-1 DTLS renegotiation: legacy renegotiation -renegotiation:MBEDTLS_SSL_LEGACY_ALLOW_RENEGOTIATION +renegotiation:MBEDTLS_SSL_LEGACY_ALLOW_RENEGOTIATION:-1 DTLS renegotiation: legacy break handshake -renegotiation:MBEDTLS_SSL_LEGACY_BREAK_HANDSHAKE +renegotiation:MBEDTLS_SSL_LEGACY_BREAK_HANDSHAKE:-1 + +DTLS renegotiation: after bad MAC on client +renegotiation:MBEDTLS_SSL_LEGACY_NO_RENEGOTIATION:MBEDTLS_SSL_IS_CLIENT + +DTLS renegotiation: after bad MAC on server +renegotiation:MBEDTLS_SSL_LEGACY_NO_RENEGOTIATION:MBEDTLS_SSL_IS_SERVER DTLS serialization with MFL=512 resize_buffers_serialize_mfl:MBEDTLS_SSL_MAX_FRAG_LEN_512 @@ -3363,6 +3377,9 @@ cookie_parsing:"16fefd0000000000000000002F010000de000000000000011efefd7b72727272 TLS 1.3 srv Certificate msg - wrong vector lengths tls13_server_certificate_msg_invalid_vector_len +TLS 1.3 cli rejects HRR selecting an un-offered group +reject_hrr_selecting_unoffered_group + EC-JPAKE set password depends_on:MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED ssl_ecjpake_set_password:0 @@ -3377,6 +3394,22 @@ elliptic_curve_get_properties TLS 1.3 resume session with ticket tls13_resume_session_with_ticket +TLS 1.3 server propagates RMS computation error +depends_on:MBEDTLS_SSL_PROTO_TLS1_3:MBEDTLS_TEST_AT_LEAST_ONE_TLS1_3_CIPHERSUITE:MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED:MBEDTLS_X509_RSASSA_PSS_SUPPORT:PSA_WANT_ALG_RSA_PKCS1V15_SIGN +tls_transcript_error_propagation:MBEDTLS_SSL_IS_SERVER:MBEDTLS_SSL_VERSION_TLS1_3:"<= parse finished message":MBEDTLS_SSL_CLIENT_FINISHED:MBEDTLS_SSL_FLUSH_BUFFERS:MBEDTLS_ERR_SSL_INTERNAL_ERROR + +TLS 1.3 client propagates RMS computation error +depends_on:MBEDTLS_SSL_PROTO_TLS1_3:MBEDTLS_TEST_AT_LEAST_ONE_TLS1_3_CIPHERSUITE:MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED:MBEDTLS_X509_RSASSA_PSS_SUPPORT:PSA_WANT_ALG_RSA_PKCS1V15_SIGN +tls_transcript_error_propagation:MBEDTLS_SSL_IS_CLIENT:MBEDTLS_SSL_VERSION_TLS1_3:"<= write finished message":MBEDTLS_SSL_CLIENT_FINISHED:-1:MBEDTLS_ERR_SSL_INTERNAL_ERROR + +TLS 1.2 server propagates EMS computation error +depends_on:MBEDTLS_SSL_PROTO_TLS1_2:MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED +tls_transcript_error_propagation:MBEDTLS_SSL_IS_SERVER:MBEDTLS_SSL_VERSION_TLS1_2:"=> derive keys":MBEDTLS_SSL_CLIENT_KEY_EXCHANGE:MBEDTLS_SSL_CERTIFICATE_VERIFY:MBEDTLS_ERR_SSL_INTERNAL_ERROR + +TLS 1.2 client propagates EMS computation error +depends_on:MBEDTLS_SSL_PROTO_TLS1_2:MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED +tls_transcript_error_propagation:MBEDTLS_SSL_IS_CLIENT:MBEDTLS_SSL_VERSION_TLS1_2:"=> derive keys":MBEDTLS_SSL_CERTIFICATE_VERIFY:-1:MBEDTLS_ERR_SSL_INTERNAL_ERROR + TLS 1.3 read early data, early data accepted tls13_read_early_data:TEST_EARLY_DATA_ACCEPTED @@ -3565,3 +3598,29 @@ send_invalid_sig_alg:MBEDTLS_SSL_SIG_ECDSA:MBEDTLS_SSL_HASH_SHA512:0 Negative Test: Server using sig_alg not offered by the client - ECDSA with SHA512 depends_on:MBEDTLS_CAN_HANDLE_ECDSA_TEST_KEY:MBEDTLS_CAN_HANDLE_ECDSA_CLIENT_TEST_KEY:PSA_WANT_ALG_SHA_512 send_invalid_sig_alg:MBEDTLS_SSL_SIG_ECDSA:MBEDTLS_SSL_HASH_SHA512:MBEDTLS_ERR_SSL_ILLEGAL_PARAMETER + +TLS 1.2 NewSessionTicket: failing ticket callback leaves lifetime unset +depends_on:MBEDTLS_SSL_PROTO_TLS1_2:MBEDTLS_SSL_SESSION_TICKETS:MBEDTLS_SSL_CLI_C:MBEDTLS_SSL_SRV_C:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:PSA_WANT_ALG_SHA_256:PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY:MBEDTLS_CAN_HANDLE_RSA_TEST_KEY +write_new_session_ticket_mem + +TLS 1.3 drop early data +tls13_drop_early_data:0 + +TLS 1.3 drop early data and insert an EndOfEarlyData +tls13_drop_early_data:1 + +TLS 1.3 ClientHello record boundary alignment enforcement +tls13_record_boundary_alignment:MBEDTLS_SSL_IS_SERVER:MBEDTLS_SSL_HS_CLIENT_HELLO + +TLS 1.3 ServerHello record boundary alignment enforcement +tls13_record_boundary_alignment:MBEDTLS_SSL_IS_CLIENT:MBEDTLS_SSL_HS_SERVER_HELLO + +TLS 1.3 server Finished record boundary alignment enforcement +tls13_record_boundary_alignment:MBEDTLS_SSL_IS_CLIENT:MBEDTLS_SSL_HS_FINISHED + +TLS 1.3 client Finished record boundary alignment enforcement +tls13_record_boundary_alignment:MBEDTLS_SSL_IS_SERVER:MBEDTLS_SSL_HS_FINISHED + +TLS 1.3 EndOfEarlyData record boundary alignment enforcement +depends_on:MBEDTLS_SSL_EARLY_DATA:MBEDTLS_SSL_SESSION_TICKETS +tls13_record_boundary_alignment:MBEDTLS_SSL_IS_SERVER:MBEDTLS_SSL_HS_END_OF_EARLY_DATA diff --git a/tests/suites/test_suite_ssl.function b/tests/suites/test_suite_ssl.function index 2000eddc3c..c1cf9bab86 100644 --- a/tests/suites/test_suite_ssl.function +++ b/tests/suites/test_suite_ssl.function @@ -9,6 +9,7 @@ #include #include #include +#include #include #include @@ -30,6 +31,83 @@ #define TEST_TLS13_SESSION_LOAD_HOSTNAME_NO_NUL 1 #define TEST_TLS13_SESSION_LOAD_ALPN_NO_NUL 2 +#if defined(MBEDTLS_SSL_PROTO_TLS1_2) && \ + defined(MBEDTLS_SSL_SESSION_TICKETS) && \ + defined(MBEDTLS_SSL_CLI_C) && defined(MBEDTLS_SSL_SRV_C) && \ + defined(MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED) && \ + defined(PSA_HAVE_ALG_SOME_RSA_SIGN) && \ + defined(PSA_WANT_ECC_SECP_R1_384) && \ + defined(PSA_WANT_ALG_SHA_256) && \ + defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) && \ + defined(MBEDTLS_CAN_HANDLE_RSA_TEST_KEY) +static int failing_ticket_write_unset_lifetime( + void *p_ticket, const mbedtls_ssl_session *session, + unsigned char *start, const unsigned char *end, + size_t *tlen, uint32_t *lifetime) +{ + ((void) p_ticket); + ((void) session); + ((void) start); + ((void) end); + ((void) tlen); + ((void) lifetime); + + return MBEDTLS_ERR_SSL_INTERNAL_ERROR; +} +#endif /* MBEDTLS_SSL_PROTO_TLS1_2 && MBEDTLS_SSL_SESSION_TICKETS && + MBEDTLS_SSL_CLI_C && MBEDTLS_SSL_SRV_C && + MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED && + PSA_HAVE_ALG_SOME_RSA_SIGN && PSA_WANT_ECC_SECP_R1_384 && + PSA_WANT_ALG_SHA_256 && PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY && + MBEDTLS_CAN_HANDLE_RSA_TEST_KEY */ + +#if defined(MBEDTLS_SSL_TLS_C) && defined(MBEDTLS_DEBUG_C) && \ + defined(MBEDTLS_SSL_CLI_C) && defined(MBEDTLS_SSL_SRV_C) && \ + defined(MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED) && \ + defined(MBEDTLS_TEST_HAS_DEFAULT_EC_GROUP) && \ + defined(PSA_WANT_ALG_SHA_256) +typedef struct { + /* Context for tls_abort_transcript(). The debug callback watches for + * trigger in the SSL debug trace, then aborts this connection's transcript + * hash operation exactly once so the test can check error propagation. */ + mbedtls_ssl_context *ssl; + const char *trigger; + int triggered; +} tls_abort_transcript_context; + +static void tls_abort_transcript(void *ctx, int level, + const char *file, int line, + const char *str) +{ + tls_abort_transcript_context *abort_ctx = ctx; + + (void) level; + (void) file; + (void) line; + + if (abort_ctx->triggered) { + return; + } + if (abort_ctx->ssl == NULL) { + return; + } + if (abort_ctx->ssl->handshake == NULL) { + return; + } + if (strstr(str, abort_ctx->trigger) == NULL) { + return; + } + + abort_ctx->triggered = 1; +#if defined(PSA_WANT_ALG_SHA_256) + psa_hash_abort(&abort_ctx->ssl->handshake->fin_sha256_psa); +#endif +#if defined(PSA_WANT_ALG_SHA_384) + psa_hash_abort(&abort_ctx->ssl->handshake->fin_sha384_psa); +#endif +} +#endif + #if (!defined(MBEDTLS_SSL_PROTO_TLS1_2)) && \ defined(MBEDTLS_SSL_EARLY_DATA) && defined(MBEDTLS_SSL_CLI_C) && \ defined(MBEDTLS_SSL_SRV_C) && defined(MBEDTLS_DEBUG_C) && \ @@ -71,6 +149,39 @@ exit: } #endif +typedef enum { + PRE_HANDSHAKE_BADMAC_SEEN = 1u << 0, +} pre_handshake_tweaks_t; + +#if defined(MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED) && \ + defined(PSA_HAVE_ALG_SOME_RSA_SIGN) && \ + defined(PSA_WANT_ECC_SECP_R1_384) && \ + defined(PSA_WANT_ALG_SHA_256) && \ + defined(PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY) && \ + defined(MBEDTLS_CAN_HANDLE_RSA_TEST_KEY) +typedef struct { + uint32_t client; + uint32_t server; +} pre_handshake_tweak_spec_t; + +static void pre_handshake_tweak_context(mbedtls_ssl_context *ssl, + int tweaks) +{ + if (tweaks & PRE_HANDSHAKE_BADMAC_SEEN) { + ssl->badmac_seen = 1; + } +} + +static void pre_handshake_tweak_contexts(mbedtls_test_ssl_endpoint *client, + mbedtls_test_ssl_endpoint *server, + void *param) +{ + const pre_handshake_tweak_spec_t *tweaks = param; + pre_handshake_tweak_context(&client->ssl, tweaks->client); + pre_handshake_tweak_context(&server->ssl, tweaks->server); +} +#endif + #if defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED) && \ defined(MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH) && \ defined(MBEDTLS_SSL_PROTO_TLS1_2) && \ @@ -114,6 +225,30 @@ static void resize_buffers(int mfl, int renegotiation, int legacy_renegotiation, #define TEST_GCM_OR_CHACHAPOLY_ENABLED #endif +#if defined(MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED) && \ + defined(MBEDTLS_SSL_PROTO_TLS1_2) && \ + defined(PSA_HAVE_ALG_SOME_RSA_SIGN) && \ + defined(PSA_WANT_ECC_SECP_R1_384) && \ + defined(MBEDTLS_SSL_PROTO_DTLS) && \ + defined(MBEDTLS_SSL_RENEGOTIATION) && \ + defined(PSA_WANT_ALG_SHA_256) && \ + defined(MBEDTLS_CAN_HANDLE_RSA_TEST_KEY) +static void simulate_badmac_seen_on(mbedtls_test_ssl_endpoint *client, + mbedtls_test_ssl_endpoint *server, + void *param) +{ + int on = *(int *) param; + switch (on) { + case MBEDTLS_SSL_IS_CLIENT: + client->ssl.badmac_seen = 1; + break; + case MBEDTLS_SSL_IS_SERVER: + server->ssl.badmac_seen = 1; + break; + } +} +#endif + typedef enum { RECOMBINE_NOMINAL, /* param: ignored */ RECOMBINE_SPLIT_FIRST, /* param: offset of split (<=0 means from end) */ @@ -423,6 +558,51 @@ exit: #endif /* MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED etc */ +#if defined(MBEDTLS_SSL_PROTO_TLS1_3) && defined(MBEDTLS_DEBUG_C) && \ + defined(MBEDTLS_SSL_CLI_C) && defined(MBEDTLS_SSL_SRV_C) && \ + defined(MBEDTLS_TEST_AT_LEAST_ONE_TLS1_3_CIPHERSUITE) && \ + defined(MBEDTLS_TEST_HAS_DEFAULT_EC_GROUP) && \ + defined(MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED) && \ + defined(PSA_WANT_ALG_SHA_256) && \ + defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT) && \ + defined(PSA_WANT_ALG_RSA_PKCS1V15_SIGN) +typedef struct { + /* Context for `tls_tweak_in_msglen()`. The debug callback + * watches for "<= read record" in the SSL debug trace. When the pattern is + * detected, it increases by `nb_bytes` the 'in_msglen' field of the + * associated SSL context. + */ + mbedtls_ssl_context *ssl; + int armed; + int nb_bytes; + int triggered; +} tls_tweak_in_msglen_context; + +static void tls_tweak_in_msglen(void *ctx, int level, + const char *file, int line, + const char *str) +{ + tls_tweak_in_msglen_context *tweak_in_msglen_ctx = ctx; + + (void) level; + (void) file; + (void) line; + + if (!tweak_in_msglen_ctx->armed) { + return; + } + if (strstr(str, "<= read record") == NULL) { + return; + } + + tweak_in_msglen_ctx->ssl->in_msglen += tweak_in_msglen_ctx->nb_bytes; + tweak_in_msglen_ctx->armed = 0; + tweak_in_msglen_ctx->triggered++; +} +#endif + + + /* END_HEADER */ /* BEGIN_DEPENDENCIES @@ -3039,7 +3219,7 @@ exit: } /* END_CASE */ -/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:!MBEDTLS_SSL_PROTO_TLS1_3:PSA_WANT_ALG_SHA_256 */ +/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:PSA_WANT_ALG_SHA_256 */ void mbedtls_endpoint_sanity(int endpoint_type) { enum { BUFFSIZE = 1024 }; @@ -3234,6 +3414,40 @@ exit: } /* END_CASE */ +/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:PSA_WANT_ALG_SHA_256:PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY:MBEDTLS_CAN_HANDLE_RSA_TEST_KEY */ +/* Test a handshake in forced conditions. + * + * This can be used for defense in depths for scenarios that we think + * can't happen, but might actually happen due to a bug, or due to + * a new feature that is insufficiently tested. + * + * This can also be a proxy for testing aspects of renegotiation or + * session resumption in circumstances that are hard to arrange. + */ +void handshake_with_forced_context(int dtls, int version, + int client_tweaks, int server_tweaks) +{ + pre_handshake_tweak_spec_t tweaks = { client_tweaks, server_tweaks }; + + mbedtls_test_handshake_test_options options; + mbedtls_test_init_handshake_options(&options); + options.dtls = dtls; + options.client_min_version = version; + options.client_max_version = version; + options.expected_negotiated_version = version; + options.pre_handshake_fun = &pre_handshake_tweak_contexts; + options.pre_handshake_param = &tweaks; + + mbedtls_test_ssl_perform_handshake(&options); + + /* The goto below is used to avoid an "unused label" warning.*/ + goto exit; + +exit: + mbedtls_test_free_handshake_options(&options); +} +/* END_CASE */ + /* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:PSA_WANT_ALG_SHA_256 */ void app_data(int mfl, int cli_msg_len, int srv_msg_len, int expected_cli_fragments, @@ -3275,7 +3489,7 @@ void app_data_tls(int mfl, int cli_msg_len, int srv_msg_len, } /* END_CASE */ -/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:!MBEDTLS_SSL_PROTO_TLS1_3:MBEDTLS_SSL_PROTO_TLS1_2:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:MBEDTLS_SSL_PROTO_DTLS:PSA_WANT_ALG_SHA_256:MBEDTLS_CAN_HANDLE_RSA_TEST_KEY */ +/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:MBEDTLS_SSL_PROTO_TLS1_2:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:MBEDTLS_SSL_PROTO_DTLS:PSA_WANT_ALG_SHA_256:MBEDTLS_CAN_HANDLE_RSA_TEST_KEY */ void app_data_dtls(int mfl, int cli_msg_len, int srv_msg_len, int expected_cli_fragments, int expected_srv_fragments) @@ -3304,7 +3518,7 @@ exit: } /* END_CASE */ -/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:!MBEDTLS_SSL_PROTO_TLS1_3:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_KEY_TYPE_AES:PSA_WANT_ECC_SECP_R1_384:MBEDTLS_DEBUG_C:MBEDTLS_SSL_MAX_FRAGMENT_LENGTH:PSA_WANT_ALG_CBC_NO_PADDING:PSA_WANT_ALG_SHA_384:MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED */ +/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_KEY_TYPE_AES:PSA_WANT_ECC_SECP_R1_384:MBEDTLS_DEBUG_C:MBEDTLS_SSL_MAX_FRAGMENT_LENGTH:PSA_WANT_ALG_CBC_NO_PADDING:PSA_WANT_ALG_SHA_256:PSA_WANT_ALG_SHA_384:MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED */ void handshake_fragmentation(int mfl, int expected_srv_hs_fragmentation, int expected_cli_hs_fragmentation) @@ -3501,8 +3715,8 @@ exit: } /* END_CASE */ -/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:!MBEDTLS_SSL_PROTO_TLS1_3:MBEDTLS_SSL_PROTO_TLS1_2:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:MBEDTLS_SSL_PROTO_DTLS:MBEDTLS_SSL_RENEGOTIATION:PSA_WANT_ALG_SHA_256:MBEDTLS_CAN_HANDLE_RSA_TEST_KEY */ -void renegotiation(int legacy_renegotiation) +/* BEGIN_CASE depends_on:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:MBEDTLS_SSL_PROTO_TLS1_2:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:MBEDTLS_SSL_PROTO_DTLS:MBEDTLS_SSL_RENEGOTIATION:PSA_WANT_ALG_SHA_256:MBEDTLS_CAN_HANDLE_RSA_TEST_KEY */ +void renegotiation(int legacy_renegotiation, int badmac_seen_on) { mbedtls_test_handshake_test_options options; mbedtls_test_init_handshake_options(&options); @@ -3511,6 +3725,8 @@ void renegotiation(int legacy_renegotiation) options.legacy_renegotiation = legacy_renegotiation; options.dtls = 1; options.expected_negotiated_version = MBEDTLS_SSL_VERSION_TLS1_2; + options.post_data_fun = &simulate_badmac_seen_on; + options.post_data_param = &badmac_seen_on; mbedtls_test_ssl_perform_handshake(&options); @@ -4164,6 +4380,116 @@ exit: } /* END_CASE */ +/* BEGIN_CASE depends_on:MBEDTLS_SSL_PROTO_TLS1_3:MBEDTLS_SSL_CLI_C:MBEDTLS_SSL_SRV_C:MBEDTLS_TEST_AT_LEAST_ONE_TLS1_3_CIPHERSUITE:MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED:PSA_WANT_ALG_SHA_256:PSA_WANT_ALG_ECDH:PSA_WANT_ALG_ECDSA_ANY:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ECC_SECP_R1_384 */ +void reject_hrr_selecting_unoffered_group(void) +{ + int ret = -1; + + mbedtls_test_ssl_endpoint client_ep, server_ep; + mbedtls_test_handshake_test_options client_options, server_options; +#if defined(MBEDTLS_DEBUG_C) + mbedtls_test_ssl_log_pattern cli_pattern = { .pattern = "Invalid key share in HRR" }; +#endif /* MBEDTLS_DEBUG_C */ + + /* Group order is intentional: client offers secp256r1 first, while server only + * accepts secp384r1. This prevents immediate group agreement and forces HRR. */ + uint16_t client_group_list[] = { + MBEDTLS_SSL_IANA_TLS_GROUP_SECP256R1, + MBEDTLS_SSL_IANA_TLS_GROUP_SECP384R1, + MBEDTLS_SSL_IANA_TLS_GROUP_NONE + }; + uint16_t server_group_list[] = { MBEDTLS_SSL_IANA_TLS_GROUP_SECP384R1, + MBEDTLS_SSL_IANA_TLS_GROUP_NONE }; + + memset(&client_ep, 0, sizeof(client_ep)); + memset(&server_ep, 0, sizeof(server_ep)); + + mbedtls_test_init_handshake_options(&client_options); + mbedtls_test_init_handshake_options(&server_options); + MD_OR_USE_PSA_INIT(); + + client_options.pk_alg = MBEDTLS_PK_ECDSA; + client_options.client_min_version = MBEDTLS_SSL_VERSION_TLS1_3; + client_options.client_max_version = MBEDTLS_SSL_VERSION_TLS1_3; + client_options.group_list = client_group_list; +#if defined(MBEDTLS_DEBUG_C) + client_options.cli_log_obj = &cli_pattern; + client_options.cli_log_fun = mbedtls_test_ssl_log_analyzer; + mbedtls_debug_set_threshold(1); +#endif /* MBEDTLS_DEBUG_C */ + + server_options.pk_alg = MBEDTLS_PK_ECDSA; + server_options.server_min_version = MBEDTLS_SSL_VERSION_TLS1_3; + server_options.server_max_version = MBEDTLS_SSL_VERSION_TLS1_3; + server_options.group_list = server_group_list; + + for (int round = 0; round < 2; round++) { + int select_unoffered_group = (round != 0); + TEST_EQUAL(mbedtls_test_ssl_endpoint_init(&client_ep, + MBEDTLS_SSL_IS_CLIENT, + &client_options), 0); + + TEST_EQUAL(mbedtls_test_ssl_endpoint_init(&server_ep, + MBEDTLS_SSL_IS_SERVER, + &server_options), 0); + + TEST_EQUAL(mbedtls_test_mock_socket_connect(&(client_ep.socket), + &(server_ep.socket), 4096), 0); + + ret = mbedtls_test_move_handshake_to_state( + &(server_ep.ssl), &(client_ep.ssl), + MBEDTLS_SSL_HELLO_RETRY_REQUEST); + TEST_EQUAL(ret, 0); + TEST_EQUAL(client_ep.ssl.handshake->offered_group_id, + MBEDTLS_SSL_IANA_TLS_GROUP_SECP256R1); + + if (!select_unoffered_group) { + TEST_EQUAL(server_ep.ssl.handshake->hrr_selected_group, + MBEDTLS_SSL_IANA_TLS_GROUP_SECP384R1); + } else { + server_ep.ssl.handshake->hrr_selected_group = MBEDTLS_SSL_IANA_TLS_GROUP_X25519; + } + + /* Write and send the HRR */ + TEST_EQUAL(mbedtls_ssl_handshake_step(&(server_ep.ssl)), 0); + TEST_EQUAL(mbedtls_ssl_flush_output(&(server_ep.ssl)), 0); + + if (!select_unoffered_group) { + /* Valid HRR, the client accepts the group MBEDTLS_SSL_IANA_TLS_GROUP_SECP384R1 + * and goes ahead with the handshake. + */ + TEST_EQUAL(mbedtls_ssl_handshake_step(&(client_ep.ssl)), 0); + TEST_ASSERT(client_ep.ssl.state != MBEDTLS_SSL_SERVER_HELLO); +#if defined(MBEDTLS_DEBUG_C) + TEST_EQUAL(cli_pattern.counter, 0); +#endif /* MBEDTLS_DEBUG_C */ + } else { + /* Invalid HRR selecting MBEDTLS_SSL_IANA_TLS_GROUP_X25519 group. + * The client rejects it and aborts the handshake. + */ + TEST_EQUAL(mbedtls_ssl_handshake_step(&(client_ep.ssl)), + MBEDTLS_ERR_SSL_ILLEGAL_PARAMETER); + TEST_EQUAL(client_ep.ssl.state, MBEDTLS_SSL_SERVER_HELLO); +#if defined(MBEDTLS_DEBUG_C) + TEST_EQUAL(cli_pattern.counter, 1); +#endif /* MBEDTLS_DEBUG_C */ + } + mbedtls_test_ssl_endpoint_free(&client_ep); + mbedtls_test_ssl_endpoint_free(&server_ep); + } + +exit: + mbedtls_test_ssl_endpoint_free(&client_ep); + mbedtls_test_ssl_endpoint_free(&server_ep); + mbedtls_test_free_handshake_options(&client_options); + mbedtls_test_free_handshake_options(&server_options); +#if defined(MBEDTLS_DEBUG_C) + mbedtls_debug_set_threshold(0); +#endif /* MBEDTLS_DEBUG_C */ + MD_OR_USE_PSA_DONE(); +} +/* END_CASE */ + /* BEGIN_CASE depends_on:MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED */ void ssl_ecjpake_set_password(int use_opaque_arg) { @@ -4294,6 +4620,92 @@ exit: } /* END_CASE */ +/* BEGIN_CASE depends_on:MBEDTLS_SSL_TLS_C:MBEDTLS_DEBUG_C:MBEDTLS_SSL_CLI_C:MBEDTLS_SSL_SRV_C:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:MBEDTLS_TEST_HAS_DEFAULT_EC_GROUP:PSA_WANT_ALG_SHA_256 */ +void tls_transcript_error_propagation(int endpoint, + int tls_version, + const char *trigger, + int target_state, + int peer_target_state, + int expected_ret) +{ + int ret = -1; + mbedtls_test_ssl_endpoint client_ep, server_ep; + mbedtls_test_handshake_test_options client_options; + mbedtls_test_init_handshake_options(&client_options); + mbedtls_test_handshake_test_options server_options; + mbedtls_test_init_handshake_options(&server_options); + tls_abort_transcript_context abort_ctx; + memset(&abort_ctx, 0, sizeof(abort_ctx)); + mbedtls_ssl_context *peer_ssl_context = NULL; + + PSA_INIT(); + + client_options.client_min_version = tls_version; + client_options.client_max_version = tls_version; + server_options.server_min_version = tls_version; + server_options.server_max_version = tls_version; + + abort_ctx.trigger = trigger; + TEST_ASSERT(abort_ctx.trigger != NULL); + + if (endpoint == MBEDTLS_SSL_IS_CLIENT) { + client_options.cli_log_obj = &abort_ctx; + client_options.cli_log_fun = tls_abort_transcript; + abort_ctx.ssl = &client_ep.ssl; + peer_ssl_context = &server_ep.ssl; + } else { + server_options.srv_log_obj = &abort_ctx; + server_options.srv_log_fun = tls_abort_transcript; + abort_ctx.ssl = &server_ep.ssl; + peer_ssl_context = &client_ep.ssl; + } + + mbedtls_debug_set_threshold(4); + + TEST_EQUAL(mbedtls_test_ssl_endpoint_init(&client_ep, MBEDTLS_SSL_IS_CLIENT, + &client_options), 0); + TEST_EQUAL(mbedtls_test_ssl_endpoint_init(&server_ep, MBEDTLS_SSL_IS_SERVER, + &server_options), 0); + + /* Keep enough socket capacity for setup traffic so the final step below + * exercises the target state instead of only flushing previous messages. */ + TEST_EQUAL(mbedtls_test_mock_socket_connect(&(client_ep.socket), + &(server_ep.socket), 4096), 0); + + TEST_EQUAL(mbedtls_test_move_handshake_to_state( + abort_ctx.ssl, peer_ssl_context, + target_state), 0); + /* + * Advance the peer further through the handshake so that it emits the + * messages needed by the endpoint under test to proceed through its next + * step. + */ + if (peer_target_state != -1) { + TEST_EQUAL(mbedtls_test_move_handshake_to_state( + peer_ssl_context, abort_ctx.ssl, + peer_target_state), 0); + TEST_EQUAL(mbedtls_ssl_flush_output(peer_ssl_context), 0); + } + + TEST_EQUAL(mbedtls_ssl_flush_output(abort_ctx.ssl), 0); + TEST_EQUAL(abort_ctx.ssl->state, target_state); + TEST_EQUAL(abort_ctx.triggered, 0); + + ret = mbedtls_ssl_handshake_step(abort_ctx.ssl); + TEST_ASSERT(abort_ctx.triggered); + TEST_ASSERT(ret != 0); + TEST_EQUAL(ret, expected_ret); + +exit: + mbedtls_test_ssl_endpoint_free(&client_ep); + mbedtls_test_ssl_endpoint_free(&server_ep); + mbedtls_test_free_handshake_options(&client_options); + mbedtls_test_free_handshake_options(&server_options); + mbedtls_debug_set_threshold(0); + PSA_DONE(); +} +/* END_CASE */ + /* BEGIN_CASE depends_on:MBEDTLS_SSL_PROTO_TLS1_3:MBEDTLS_SSL_CLI_C:MBEDTLS_SSL_SRV_C:MBEDTLS_TEST_AT_LEAST_ONE_TLS1_3_CIPHERSUITE:MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED:MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_PSK_EPHEMERAL_ENABLED:PSA_WANT_ALG_SHA_256:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ECC_SECP_R1_384:PSA_HAVE_ALG_ECDSA_VERIFY:MBEDTLS_SSL_SESSION_TICKETS */ void tls13_resume_session_with_ticket() { @@ -6519,3 +6931,377 @@ exit: PSA_DONE(); } /* END_CASE */ + +/* BEGIN_CASE depends_on:MBEDTLS_SSL_PROTO_TLS1_2:MBEDTLS_SSL_SESSION_TICKETS:MBEDTLS_SSL_CLI_C:MBEDTLS_SSL_SRV_C:MBEDTLS_SSL_HANDSHAKE_WITH_CERT_ENABLED:PSA_HAVE_ALG_SOME_RSA_SIGN:PSA_WANT_ECC_SECP_R1_384:PSA_WANT_ALG_SHA_256:PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY:MBEDTLS_CAN_HANDLE_RSA_TEST_KEY */ +void write_new_session_ticket_mem() +{ + enum { BUFFSIZE = 1024 }; + mbedtls_test_ssl_endpoint server_ep, client_ep; + mbedtls_test_handshake_test_options options; + int ret = -1; + + memset(&server_ep, 0, sizeof(server_ep)); + memset(&client_ep, 0, sizeof(client_ep)); + mbedtls_test_init_handshake_options(&options); + + options.pk_alg = MBEDTLS_PK_RSA; + options.client_min_version = MBEDTLS_SSL_VERSION_TLS1_2; + options.client_max_version = MBEDTLS_SSL_VERSION_TLS1_2; + options.server_min_version = MBEDTLS_SSL_VERSION_TLS1_2; + options.server_max_version = MBEDTLS_SSL_VERSION_TLS1_2; + + MD_OR_USE_PSA_INIT(); + + ret = mbedtls_test_ssl_endpoint_init(&server_ep, MBEDTLS_SSL_IS_SERVER, + &options); + TEST_EQUAL(ret, 0); + + mbedtls_ssl_conf_session_tickets_cb(&server_ep.conf, + failing_ticket_write_unset_lifetime, + mbedtls_test_ticket_parse, + NULL); + + ret = mbedtls_test_ssl_endpoint_init(&client_ep, MBEDTLS_SSL_IS_CLIENT, + &options); + TEST_EQUAL(ret, 0); + + ret = mbedtls_test_mock_socket_connect(&(server_ep.socket), + &(client_ep.socket), + BUFFSIZE); + TEST_EQUAL(ret, 0); + + ret = mbedtls_test_move_handshake_to_state(&(server_ep.ssl), + &(client_ep.ssl), + MBEDTLS_SSL_SERVER_CHANGE_CIPHER_SPEC); + TEST_EQUAL(ret, 0); + + ret = mbedtls_ssl_handshake_step(&(server_ep.ssl)); + TEST_EQUAL(ret, 0); + + /* Force a read of the lifetime value from the outgoing message. + * This is a non-regression test for a bug where the lifetime was set from + * uninitialized memory. + * The read here causes MSan and Valgrind to complain if the bug isn't fixed. + */ + volatile uint32_t lifetime = MBEDTLS_GET_UINT32_BE(server_ep.ssl.out_msg, 4); + (void) lifetime; + +exit: + mbedtls_test_ssl_endpoint_free(&client_ep); + mbedtls_test_ssl_endpoint_free(&server_ep); + mbedtls_test_free_handshake_options(&options); + MD_OR_USE_PSA_DONE(); +} +/* END_CASE */ + +/* BEGIN_CASE depends_on:MBEDTLS_SSL_EARLY_DATA:MBEDTLS_SSL_CLI_C:MBEDTLS_SSL_SRV_C:MBEDTLS_TEST_AT_LEAST_ONE_TLS1_3_CIPHERSUITE:MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED:MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_PSK_EPHEMERAL_ENABLED:MBEDTLS_TEST_HAS_DEFAULT_EC_GROUP:PSA_WANT_ALG_SHA_256:MBEDTLS_X509_RSASSA_PSS_SUPPORT:PSA_WANT_ALG_RSA_PKCS1V15_SIGN:MBEDTLS_SSL_SESSION_TICKETS */ +void tls13_drop_early_data(int insert_end_of_early_data) +{ + int ret = -1; + mbedtls_test_ssl_endpoint client_ep, server_ep; + memset(&client_ep, 0, sizeof(client_ep)); + memset(&server_ep, 0, sizeof(server_ep)); + + mbedtls_test_handshake_test_options client_options, server_options; + mbedtls_test_init_handshake_options(&client_options); + mbedtls_test_init_handshake_options(&server_options); + + mbedtls_ssl_session saved_session; + mbedtls_ssl_session_init(&saved_session); + + const char *early_data = "This is early data."; + size_t early_data_len = strlen(early_data); + unsigned char buf[256]; + + PSA_INIT(); + + /* + * Run first handshake to get a ticket from the server. + */ + + client_options.early_data = MBEDTLS_SSL_EARLY_DATA_ENABLED; + server_options.early_data = MBEDTLS_SSL_EARLY_DATA_ENABLED; + ret = mbedtls_test_get_tls13_ticket(&client_options, &server_options, + &saved_session); + TEST_EQUAL(ret, 0); + + /* + * Prepare for handshake with the ticket. + */ + ret = mbedtls_test_ssl_endpoint_init(&client_ep, MBEDTLS_SSL_IS_CLIENT, + &client_options); + TEST_EQUAL(ret, 0); + + ret = mbedtls_test_ssl_endpoint_init(&server_ep, MBEDTLS_SSL_IS_SERVER, + &server_options); + TEST_EQUAL(ret, 0); + + mbedtls_ssl_conf_session_tickets_cb(&server_ep.conf, + mbedtls_test_ticket_write, + mbedtls_test_ticket_parse, + NULL); + + ret = mbedtls_test_mock_socket_connect(&(client_ep.socket), + &(server_ep.socket), 1024); + TEST_EQUAL(ret, 0); + + ret = mbedtls_ssl_set_session(&(client_ep.ssl), &saved_session); + TEST_EQUAL(ret, 0); + + /* + * Initiate handshake with ticket, up to the point where the client has + * written the ClientHello and only the ClientHello in its output socket + * buffer. + */ +#if defined(MBEDTLS_SSL_TLS1_3_COMPATIBILITY_MODE) + TEST_EQUAL(mbedtls_test_move_handshake_to_state( + &(client_ep.ssl), &(server_ep.ssl), + MBEDTLS_SSL_CLIENT_CCS_AFTER_CLIENT_HELLO), 0); +#else + TEST_EQUAL(mbedtls_test_move_handshake_to_state( + &(client_ep.ssl), &(server_ep.ssl), + MBEDTLS_SSL_SERVER_HELLO), 0); +#endif + TEST_EQUAL(mbedtls_ssl_flush_output(&client_ep.ssl), 0); + + if (insert_end_of_early_data) { + /* + * Append an EndOfEarlyData message at the end of the record, just + * after the ClientHello message. + */ + unsigned char *client_output_buffer = client_ep.socket.output->buffer; + size_t record_size = MBEDTLS_GET_UINT16_BE(client_output_buffer, 3); + + MBEDTLS_PUT_UINT16_BE(record_size + 4, client_output_buffer, 3); + unsigned char end_of_early_data[] = { 0x05, 0x00, 0x00, 0x00 }; + ret = mbedtls_test_ssl_buffer_put(client_ep.socket.output, + end_of_early_data, + sizeof(end_of_early_data)); + TEST_EQUAL(ret, (int) sizeof(end_of_early_data)); + } + + /* The server read the record containing the ClientHello. */ + ret = mbedtls_test_move_handshake_to_state(&(server_ep.ssl), + &(client_ep.ssl), + MBEDTLS_SSL_SERVER_HELLO); + if (insert_end_of_early_data) { + /* + * If an EndOfEarlyData message was appended to the record containing + * the ClientHello then the end of the ClientHello does not align with + * the record boundary and the handshake fails. + */ + TEST_EQUAL(ret, MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE); + goto exit; + } + + TEST_EQUAL(ret, 0); + /* The client application writes early data */ + ret = mbedtls_ssl_write_early_data(&(client_ep.ssl), + (unsigned char *) early_data, + early_data_len); + TEST_EQUAL(ret, early_data_len); + + /* Drop early data */ + TEST_ASSERT(client_ep.socket.output->content_length <= sizeof(buf)); + mbedtls_test_ssl_buffer_get(client_ep.socket.output, buf, sizeof(buf)); + TEST_EQUAL(server_ep.socket.input->content_length, 0); + + /* Resume the handshake */ + ret = mbedtls_test_move_handshake_to_state(&(server_ep.ssl), + &(client_ep.ssl), + MBEDTLS_SSL_HANDSHAKE_OVER); + /* + * The early data were dropped. The EndOfEarlyData message is encrypted + * with the record number 1, but the server expects it to be encrypted + * with record number 0. Thus the handshake fails with + * MBEDTLS_ERR_SSL_INVALID_MAC. + */ + TEST_EQUAL(ret, MBEDTLS_ERR_SSL_INVALID_MAC); + +exit: + mbedtls_test_ssl_endpoint_free(&client_ep); + mbedtls_test_ssl_endpoint_free(&server_ep); + mbedtls_test_free_handshake_options(&client_options); + mbedtls_test_free_handshake_options(&server_options); + mbedtls_ssl_session_free(&saved_session); + PSA_DONE(); +} +/* END_CASE */ + +/* BEGIN_CASE depends_on:MBEDTLS_SSL_PROTO_TLS1_3:MBEDTLS_DEBUG_C:MBEDTLS_SSL_CLI_C:MBEDTLS_SSL_SRV_C:MBEDTLS_TEST_AT_LEAST_ONE_TLS1_3_CIPHERSUITE:MBEDTLS_TEST_HAS_DEFAULT_EC_GROUP:MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED:PSA_WANT_ALG_SHA_256:MBEDTLS_X509_RSASSA_PSS_SUPPORT:PSA_WANT_ALG_RSA_PKCS1V15_SIGN */ +void tls13_record_boundary_alignment(int endpoint, int handshake_message) +{ + int ret = -1; + int target_state, peer_target_state, encrypted; + mbedtls_test_ssl_endpoint client_ep, server_ep; + memset(&client_ep, 0, sizeof(client_ep)); + memset(&server_ep, 0, sizeof(server_ep)); + + mbedtls_test_handshake_test_options client_options, server_options; + mbedtls_test_init_handshake_options(&client_options); + mbedtls_test_init_handshake_options(&server_options); + + mbedtls_ssl_session saved_session; + mbedtls_ssl_session_init(&saved_session); + + tls_tweak_in_msglen_context tweak_in_msglen_ctx; + memset(&tweak_in_msglen_ctx, 0, sizeof(tweak_in_msglen_ctx)); + + mbedtls_test_mock_socket *socket = NULL; + mbedtls_ssl_context *ssl_ctx = NULL; + mbedtls_ssl_context *peer_ssl_ctx = NULL; + unsigned char additional_empty_hs_msg[4] = { 0, 0, 0, 0 }; + + PSA_INIT(); + + switch (handshake_message) { + case MBEDTLS_SSL_HS_CLIENT_HELLO: + TEST_EQUAL(endpoint, MBEDTLS_SSL_IS_SERVER); + target_state = MBEDTLS_SSL_CLIENT_HELLO; + peer_target_state = MBEDTLS_SSL_SERVER_HELLO; + additional_empty_hs_msg[0] = MBEDTLS_SSL_HS_CERTIFICATE; + encrypted = 0; + break; + + case MBEDTLS_SSL_HS_SERVER_HELLO: + TEST_EQUAL(endpoint, MBEDTLS_SSL_IS_CLIENT); + target_state = MBEDTLS_SSL_SERVER_HELLO; + peer_target_state = MBEDTLS_SSL_ENCRYPTED_EXTENSIONS; + additional_empty_hs_msg[0] = MBEDTLS_SSL_HS_ENCRYPTED_EXTENSIONS; + encrypted = 0; + break; + + case MBEDTLS_SSL_HS_FINISHED: + if (endpoint == MBEDTLS_SSL_IS_CLIENT) { + target_state = MBEDTLS_SSL_SERVER_FINISHED; + peer_target_state = MBEDTLS_SSL_CLIENT_CERTIFICATE; + } else { + target_state = MBEDTLS_SSL_CLIENT_FINISHED; + peer_target_state = MBEDTLS_SSL_FLUSH_BUFFERS; + } + /* Finished messages are not followed by any handshake message, + * insert an empty Finished message at the end of the record. + */ + additional_empty_hs_msg[0] = MBEDTLS_SSL_HS_FINISHED; + encrypted = 1; + break; + + +#if defined(MBEDTLS_SSL_EARLY_DATA) && defined(MBEDTLS_SSL_SESSION_TICKETS) + case MBEDTLS_SSL_HS_END_OF_EARLY_DATA: + TEST_EQUAL(endpoint, MBEDTLS_SSL_IS_SERVER); + target_state = MBEDTLS_SSL_END_OF_EARLY_DATA; + peer_target_state = MBEDTLS_SSL_CLIENT_CERTIFICATE; + additional_empty_hs_msg[0] = MBEDTLS_SSL_HS_FINISHED; + encrypted = 1; + client_options.early_data = MBEDTLS_SSL_EARLY_DATA_ENABLED; + server_options.early_data = MBEDTLS_SSL_EARLY_DATA_ENABLED; + ret = mbedtls_test_get_tls13_ticket(&client_options, &server_options, + &saved_session); + TEST_EQUAL(ret, 0); + break; +#endif + + default: + TEST_FAIL("Handshake message type not supported"); + } + + if (endpoint == MBEDTLS_SSL_IS_CLIENT) { + ssl_ctx = &client_ep.ssl; + peer_ssl_ctx = &server_ep.ssl; + socket = &client_ep.socket; + client_options.cli_log_obj = &tweak_in_msglen_ctx; + client_options.cli_log_fun = tls_tweak_in_msglen; + } else { + ssl_ctx = &server_ep.ssl; + peer_ssl_ctx = &client_ep.ssl; + socket = &server_ep.socket; + server_options.srv_log_obj = &tweak_in_msglen_ctx; + server_options.srv_log_fun = tls_tweak_in_msglen; + } + + mbedtls_debug_set_threshold(2); + tweak_in_msglen_ctx.ssl = ssl_ctx; + + TEST_EQUAL(mbedtls_test_ssl_endpoint_init(&client_ep, MBEDTLS_SSL_IS_CLIENT, + &client_options), 0); + TEST_EQUAL(mbedtls_test_ssl_endpoint_init(&server_ep, MBEDTLS_SSL_IS_SERVER, + &server_options), 0); + +#if defined(MBEDTLS_SSL_EARLY_DATA) && defined(MBEDTLS_SSL_SESSION_TICKETS) + if (handshake_message == MBEDTLS_SSL_HS_END_OF_EARLY_DATA) { + mbedtls_ssl_conf_session_tickets_cb(&server_ep.conf, + mbedtls_test_ticket_write, + mbedtls_test_ticket_parse, + NULL); + + ret = mbedtls_ssl_set_session(&(client_ep.ssl), &saved_session); + TEST_EQUAL(ret, 0); + } +#endif + + TEST_EQUAL(mbedtls_test_mock_socket_connect(&(client_ep.socket), + &(server_ep.socket), 1024), 0); + + TEST_EQUAL(mbedtls_test_move_handshake_to_state( + ssl_ctx, peer_ssl_ctx, target_state), 0); + TEST_EQUAL(mbedtls_ssl_flush_output(ssl_ctx), 0); + /* + * Advance the peer further through the handshake so that it emits the + * messages needed by the endpoint under test to proceed through its next + * step. + */ + TEST_ASSERT(peer_target_state != -1); + TEST_EQUAL(mbedtls_test_move_handshake_to_state( + peer_ssl_ctx, ssl_ctx, peer_target_state), 0); + TEST_EQUAL(mbedtls_ssl_flush_output(peer_ssl_ctx), 0); + TEST_EQUAL(ssl_ctx->state, target_state); + + if (encrypted) { + /* + * If the message we want to test the record boundary enforcement is + * encrypted, we cannot manipulate easily the record that contains it. + * In that case, we tamper with the record size after the record has been + * fetched from the socket buffer and decrypted by + * `mbedtls_ssl_read_record()`. + */ + tweak_in_msglen_ctx.armed = 1; + tweak_in_msglen_ctx.nb_bytes = sizeof(additional_empty_hs_msg); + } else { + /* + * In case of the unencrypted ClientHello or ServerHello, add an + * additional byte to the record that contains the handshake message. + * The byte is added in the socket buffer, before to be fetched by + * `mbedtls_ssl_read_record()`, simulating a man-in-the-middle tampering + * with the record. + */ + unsigned char *input_buffer = socket->input->buffer; + size_t record_size = MBEDTLS_GET_UINT16_BE(input_buffer, 3); + ret = mbedtls_test_ssl_buffer_put(socket->input, additional_empty_hs_msg, + sizeof(additional_empty_hs_msg)); + TEST_EQUAL(ret, (int) sizeof(additional_empty_hs_msg)); + MBEDTLS_PUT_UINT16_BE(record_size + sizeof(additional_empty_hs_msg), + input_buffer, 3); + } + + ret = mbedtls_ssl_handshake_step(ssl_ctx); + TEST_EQUAL(ret, MBEDTLS_ERR_SSL_UNEXPECTED_MESSAGE); + TEST_EQUAL(ssl_ctx->in_msglen, + ssl_ctx->in_hslen + sizeof(additional_empty_hs_msg)); + TEST_EQUAL(ssl_ctx->in_msgtype, MBEDTLS_SSL_MSG_HANDSHAKE); + TEST_EQUAL(ssl_ctx->in_msg[0], handshake_message); + + if (encrypted) { + TEST_EQUAL(tweak_in_msglen_ctx.triggered, 1); + } + +exit: + mbedtls_test_ssl_endpoint_free(&client_ep); + mbedtls_test_ssl_endpoint_free(&server_ep); + mbedtls_test_free_handshake_options(&client_options); + mbedtls_test_free_handshake_options(&server_options); + mbedtls_debug_set_threshold(0); + mbedtls_ssl_session_free(&saved_session); + PSA_DONE(); +} +/* END_CASE */ diff --git a/tests/suites/test_suite_ssl_decrypt.function b/tests/suites/test_suite_ssl_decrypt.function index 7a22939eb4..dd26537127 100644 --- a/tests/suites/test_suite_ssl_decrypt.function +++ b/tests/suites/test_suite_ssl_decrypt.function @@ -5,6 +5,7 @@ #include #include #include +#include /* END_HEADER */ diff --git a/tests/suites/test_suite_version.data b/tests/suites/test_suite_version.data index 5ffdfe71f9..1d2c3f9b96 100644 --- a/tests/suites/test_suite_version.data +++ b/tests/suites/test_suite_version.data @@ -1,8 +1,8 @@ Check compile time library version -check_compiletime_version:"4.1.0" +check_compiletime_version:"4.1.1" Check runtime library version -check_runtime_version:"4.1.0" +check_runtime_version:"4.1.1" Check for MBEDTLS_VERSION_C check_feature:"MBEDTLS_VERSION_C":0 diff --git a/tests/suites/test_suite_x509parse.data b/tests/suites/test_suite_x509parse.data index 5e91df9107..63f4c0daa9 100644 --- a/tests/suites/test_suite_x509parse.data +++ b/tests/suites/test_suite_x509parse.data @@ -2052,9 +2052,25 @@ X509 CRT ASN1 (TBSCertificate v3, inv CertificatePolicies, policy qualifier leng depends_on:PSA_HAVE_ALG_SOME_RSA_VERIFY:PSA_WANT_ALG_SHA_256 x509parse_crt:"3081b030819aa0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092a864886f70d01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a314301230100603551d200409300730050601003001300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) +X509 CRT ASN1: basicConstraints overflow would make CA=1 (bad signature) +depends_on:PSA_HAVE_ALG_ECDSA_VERIFY:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ALG_SHA_256 +mbedtls_x509_crt_parse_file:"../framework/data_files/parse_input/server5.basic-constraints-sequence-overflow.badsign.crt":MBEDTLS_ERR_X509_INVALID_EXTENSIONS:0 + +X509 CRT ASN1: basicConstraints overflow would make CA=1 (good self signature) +depends_on:PSA_HAVE_ALG_ECDSA_VERIFY:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ALG_SHA_256 +mbedtls_x509_crt_parse_file:"../framework/data_files/parse_input/server5.basic-constraints-sequence-overflow.selfsigned.crt":MBEDTLS_ERR_X509_INVALID_EXTENSIONS:0 + +X509 CRT ASN1: basicConstraints: no cA but pathLenConstraint (bad signature) +depends_on:PSA_HAVE_ALG_ECDSA_VERIFY:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ALG_SHA_256 +mbedtls_x509_crt_parse_file:"../framework/data_files/parse_input/server5.basic-constraints-integer-first.badsign.crt":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_UNEXPECTED_TAG):0 + +X509 CRT ASN1: basicConstraints: no cA but pathLenConstraint (good self signature) +depends_on:PSA_HAVE_ALG_ECDSA_VERIFY:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ALG_SHA_256 +mbedtls_x509_crt_parse_file:"../framework/data_files/parse_input/server5.basic-constraints-integer-first.selfsigned.crt":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_UNEXPECTED_TAG):0 + X509 CRT ASN1 (TBS, inv extBasicConstraint, no pathlen length) depends_on:PSA_HAVE_ALG_SOME_RSA_VERIFY:PSA_WANT_ALG_SHA_256 -x509parse_crt:"3081b030819aa0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a314301230100603551d130101010406300402010102300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) +x509parse_crt:"3081b030819aa0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a314301230100603551d13010101040630040101ff02300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) X509 CRT ASN1 (inv extBasicConstraint, pathlen is INT_MAX) depends_on:PSA_HAVE_ALG_SOME_RSA_VERIFY:PSA_WANT_ALG_SHA_256:PSA_WANT_ALG_SHA_1 @@ -2066,19 +2082,19 @@ mbedtls_x509_crt_parse_file:"../framework/data_files/parse_input/server1_pathlen X509 CRT ASN1 (TBS, inv extBasicConstraint, pathlen inv length encoding) depends_on:PSA_HAVE_ALG_SOME_RSA_VERIFY:PSA_WANT_ALG_SHA_256 -x509parse_crt:"3081b130819ba0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a315301330110603551d13010101040730050201010285300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_INVALID_LENGTH) +x509parse_crt:"3081b130819ba0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a315301330110603551d13010101040730050101ff0285300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_INVALID_LENGTH) X509 CRT ASN1 (TBS, inv extBasicConstraint, pathlen length out of bounds) depends_on:PSA_HAVE_ALG_SOME_RSA_VERIFY:PSA_WANT_ALG_SHA_256 -x509parse_crt:"3081b130819ba0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a315301330110603551d13010101040730050201010201300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) +x509parse_crt:"3081b130819ba0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a315301330110603551d13010101040730050101ff0201300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) X509 CRT ASN1 (TBS, inv extBasicConstraint, pathlen empty) depends_on:PSA_HAVE_ALG_SOME_RSA_VERIFY:PSA_WANT_ALG_SHA_256 -x509parse_crt:"3081b130819ba0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a315301330110603551d13010101040730050201010200300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_INVALID_LENGTH) +x509parse_crt:"3081b130819ba0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a315301330110603551d13010101040730050101ff0200300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_INVALID_LENGTH) X509 CRT ASN1 (TBS, inv extBasicConstraint, pathlen length mismatch) depends_on:PSA_HAVE_ALG_SOME_RSA_VERIFY:PSA_WANT_ALG_SHA_256 -x509parse_crt:"3081b430819ea0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a318301630140603551d13010101040a30080201010201010500300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_LENGTH_MISMATCH) +x509parse_crt:"3081b430819ea0030201028204deadbeef300d06092a864886f70d01010b0500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D01010105000319003016021100ffffffffffffffffffffffffffffffff020103a100a200a318301630140603551d13010101040a30080101ff0201010500300d06092a864886f70d01010b0500030200ff":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_LENGTH_MISMATCH) X509 CRT ASN1 (TBS, inv v3Ext, ExtKeyUsage bad second tag) depends_on:PSA_HAVE_ALG_SOME_RSA_VERIFY:PSA_WANT_ALG_SHA_256 @@ -2947,6 +2963,10 @@ X509 CSR ASN.1 (OK) depends_on:PSA_HAVE_ALG_SOME_ECDSA:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ALG_SHA_1:!MBEDTLS_X509_REMOVE_INFO mbedtls_x509_csr_parse:"308201183081bf0201003034310b3009060355040613024e4c3111300f060355040a1308506f6c617253534c31123010060355040313096c6f63616c686f73743059301306072a8648ce3d020106082a8648ce3d0301070342000437cc56d976091e5a723ec7592dff206eee7cf9069174d0ad14b5f768225962924ee500d82311ffea2fd2345d5d16bd8a88c26b770d55cd8a2a0efa01c8b4edffa029302706092a864886f70d01090e311a301830090603551d1304023000300b0603551d0f0404030205e0300906072a8648ce3d04010349003046022100b49fd8c8f77abfa871908dfbe684a08a793d0f490a43d86fcf2086e4f24bb0c2022100f829d5ccd3742369299e6294394717c4b723a0f68b44e831b6e6c3bcabf97243":"CSR version \: 1\nsubject name \: C=NL, O=PolarSSL, CN=localhost\nsigned using \: ECDSA with SHA1\nEC key size \: 256 bits\n\nkey usage \: Digital Signature, Non Repudiation, Key Encipherment\n":0 +X509 CSR ASN.1 (extensionRequest SET length too short) +depends_on:PSA_HAVE_ALG_ECDSA_VERIFY:PSA_WANT_ECC_SECP_R1_256 +mbedtls_x509_csr_parse:"308201183081bf0201003034310b3009060355040613024e4c3111300f060355040a1308506f6c617253534c31123010060355040313096c6f63616c686f73743059301306072a8648ce3d020106082a8648ce3d0301070342000437cc56d976091e5a723ec7592dff206eee7cf9069174d0ad14b5f768225962924ee500d82311ffea2fd2345d5d16bd8a88c26b770d55cd8a2a0efa01c8b4edffa029302706092a864886f70d01090e3119301830090603551d1304023000300b0603551d0f0404030205e0300906072a8648ce3d04010349003046022100b49fd8c8f77abfa871908dfbe684a08a793d0f490a43d86fcf2086e4f24bb0c2022100f829d5ccd3742369299e6294394717c4b723a0f68b44e831b6e6c3bcabf97243":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_LENGTH_MISMATCH) + X509 CSR ASN.1 (Unsupported critical extension, critical=true) depends_on:PSA_HAVE_ALG_SOME_ECDSA:PSA_WANT_ECC_SECP_R1_256:PSA_WANT_ALG_SHA_256:!MBEDTLS_X509_REMOVE_INFO mbedtls_x509_csr_parse:"308201233081cb02010030413119301706035504030c1053656c66207369676e65642074657374310b300906035504061302444531173015060355040a0c0e41757468437274444220546573743059301306072a8648ce3d020106082a8648ce3d03010703420004c11ebb9951848a436ca2c8a73382f24bbb6c28a92e401d4889b0c361f377b92a8b0497ff2f5a5f6057ae85f704ab1850bef075914f68ed3aeb15a1ff1ebc0dc6a028302606092a864886f70d01090e311930173015060b2b0601040183890c8622020101ff0403010101300a06082a8648ce3d040302034700304402200c4108fd098525993d3fd5b113f0a1ead8750852baf55a2f8e670a22cabc0ba1022034db93a0fcb993912adcf2ea8cb4b66389af30e264d43c0daea03255e45d2ccc":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_UNEXPECTED_TAG) @@ -3082,17 +3102,17 @@ X509 CSR ASN.1 (attributes: invalid len (len > data)) depends_on:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_SOME_RSA_VERIFY mbedtls_x509_csr_parse_file:"../framework/data_files/parse_input/test_csr_v3_all_malformed_attributes_len1.csr.der":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) -X509 CSR ASN.1 (attributes: invalid len (len < data)) +X509 CSR ASN.1 (attributes: extensionRequest SET extends past attribute) depends_on:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_SOME_RSA_VERIFY -mbedtls_x509_csr_parse_file:"../framework/data_files/parse_input/test_csr_v3_all_malformed_attributes_len2.csr.der":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_LENGTH_MISMATCH) +mbedtls_x509_csr_parse_file:"../framework/data_files/parse_input/test_csr_v3_all_malformed_attributes_len2.csr.der":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) X509 CSR ASN.1 (attributes: extension request invalid len (len > data)) depends_on:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_SOME_RSA_VERIFY mbedtls_x509_csr_parse_file:"../framework/data_files/parse_input/test_csr_v3_all_malformed_attributes_extension_request_sequence_len1.csr.der":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) -X509 CSR ASN.1 (attributes: extension request invalid len (len < data)) +X509 CSR ASN.1 (attributes: extensionRequest sequence shorter than SET) depends_on:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_SOME_RSA_VERIFY -mbedtls_x509_csr_parse_file:"../framework/data_files/parse_input/test_csr_v3_all_malformed_attributes_extension_request_sequence_len2.csr.der":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_OUT_OF_DATA) +mbedtls_x509_csr_parse_file:"../framework/data_files/parse_input/test_csr_v3_all_malformed_attributes_extension_request_sequence_len2.csr.der":"":MBEDTLS_ERROR_ADD(MBEDTLS_ERR_X509_INVALID_EXTENSIONS, MBEDTLS_ERR_ASN1_LENGTH_MISMATCH) X509 CSR ASN.1 (extensions: invalid sequence tag) depends_on:PSA_WANT_ALG_SHA_256:PSA_HAVE_ALG_SOME_RSA_VERIFY diff --git a/tf-psa-crypto b/tf-psa-crypto index e0e92d56c7..07e5c26e5b 160000 --- a/tf-psa-crypto +++ b/tf-psa-crypto @@ -1 +1 @@ -Subproject commit e0e92d56c73bf2fee0cdc92e67bd35c90015d301 +Subproject commit 07e5c26e5b9be0d04596174763ee8b982bf16a10