handshake_messages.go 47 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892
  1. // Copyright 2009 The Go Authors. All rights reserved.
  2. // Use of this source code is governed by a BSD-style
  3. // license that can be found in the LICENSE file.
  4. package tls
  5. import (
  6. "fmt"
  7. "golang.org/x/crypto/cryptobyte"
  8. "strings"
  9. )
  10. // The marshalingFunction type is an adapter to allow the use of ordinary
  11. // functions as cryptobyte.MarshalingValue.
  12. type marshalingFunction func(b *cryptobyte.Builder) error
  13. func (f marshalingFunction) Marshal(b *cryptobyte.Builder) error {
  14. return f(b)
  15. }
  16. // addBytesWithLength appends a sequence of bytes to the cryptobyte.Builder. If
  17. // the length of the sequence is not the value specified, it produces an error.
  18. func addBytesWithLength(b *cryptobyte.Builder, v []byte, n int) {
  19. b.AddValue(marshalingFunction(func(b *cryptobyte.Builder) error {
  20. if len(v) != n {
  21. return fmt.Errorf("invalid value length: expected %d, got %d", n, len(v))
  22. }
  23. b.AddBytes(v)
  24. return nil
  25. }))
  26. }
  27. // addUint64 appends a big-endian, 64-bit value to the cryptobyte.Builder.
  28. func addUint64(b *cryptobyte.Builder, v uint64) {
  29. b.AddUint32(uint32(v >> 32))
  30. b.AddUint32(uint32(v))
  31. }
  32. // readUint64 decodes a big-endian, 64-bit value into out and advances over it.
  33. // It reports whether the read was successful.
  34. func readUint64(s *cryptobyte.String, out *uint64) bool {
  35. var hi, lo uint32
  36. if !s.ReadUint32(&hi) || !s.ReadUint32(&lo) {
  37. return false
  38. }
  39. *out = uint64(hi)<<32 | uint64(lo)
  40. return true
  41. }
  42. // readUint8LengthPrefixed acts like s.ReadUint8LengthPrefixed, but targets a
  43. // []byte instead of a cryptobyte.String.
  44. func readUint8LengthPrefixed(s *cryptobyte.String, out *[]byte) bool {
  45. return s.ReadUint8LengthPrefixed((*cryptobyte.String)(out))
  46. }
  47. // readUint16LengthPrefixed acts like s.ReadUint16LengthPrefixed, but targets a
  48. // []byte instead of a cryptobyte.String.
  49. func readUint16LengthPrefixed(s *cryptobyte.String, out *[]byte) bool {
  50. return s.ReadUint16LengthPrefixed((*cryptobyte.String)(out))
  51. }
  52. // readUint24LengthPrefixed acts like s.ReadUint24LengthPrefixed, but targets a
  53. // []byte instead of a cryptobyte.String.
  54. func readUint24LengthPrefixed(s *cryptobyte.String, out *[]byte) bool {
  55. return s.ReadUint24LengthPrefixed((*cryptobyte.String)(out))
  56. }
  57. type clientHelloMsg struct {
  58. raw []byte
  59. vers uint16
  60. random []byte
  61. sessionId []byte
  62. cipherSuites []uint16
  63. compressionMethods []uint8
  64. nextProtoNeg bool
  65. serverName string
  66. ocspStapling bool
  67. supportedCurves []CurveID
  68. supportedPoints []uint8
  69. ticketSupported bool
  70. sessionTicket []uint8
  71. supportedSignatureAlgorithms []SignatureScheme
  72. supportedSignatureAlgorithmsCert []SignatureScheme
  73. secureRenegotiationSupported bool
  74. secureRenegotiation []byte
  75. alpnProtocols []string
  76. scts bool
  77. ems bool // [UTLS] actually implemented due to its prevalence
  78. supportedVersions []uint16
  79. cookie []byte
  80. keyShares []keyShare
  81. earlyData bool
  82. pskModes []uint8
  83. pskIdentities []pskIdentity
  84. pskBinders [][]byte
  85. }
  86. func (m *clientHelloMsg) marshal() []byte {
  87. if m.raw != nil {
  88. return m.raw
  89. }
  90. var b cryptobyte.Builder
  91. b.AddUint8(typeClientHello)
  92. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  93. b.AddUint16(m.vers)
  94. addBytesWithLength(b, m.random, 32)
  95. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  96. b.AddBytes(m.sessionId)
  97. })
  98. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  99. for _, suite := range m.cipherSuites {
  100. b.AddUint16(suite)
  101. }
  102. })
  103. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  104. b.AddBytes(m.compressionMethods)
  105. })
  106. // If extensions aren't present, omit them.
  107. var extensionsPresent bool
  108. bWithoutExtensions := *b
  109. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  110. if m.nextProtoNeg {
  111. // draft-agl-tls-nextprotoneg-04
  112. b.AddUint16(extensionNextProtoNeg)
  113. b.AddUint16(0) // empty extension_data
  114. }
  115. if len(m.serverName) > 0 {
  116. // RFC 6066, Section 3
  117. b.AddUint16(extensionServerName)
  118. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  119. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  120. b.AddUint8(0) // name_type = host_name
  121. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  122. b.AddBytes([]byte(m.serverName))
  123. })
  124. })
  125. })
  126. }
  127. if m.ocspStapling {
  128. // RFC 4366, Section 3.6
  129. b.AddUint16(extensionStatusRequest)
  130. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  131. b.AddUint8(1) // status_type = ocsp
  132. b.AddUint16(0) // empty responder_id_list
  133. b.AddUint16(0) // empty request_extensions
  134. })
  135. }
  136. if len(m.supportedCurves) > 0 {
  137. // RFC 4492, sections 5.1.1 and RFC 8446, Section 4.2.7
  138. b.AddUint16(extensionSupportedCurves)
  139. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  140. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  141. for _, curve := range m.supportedCurves {
  142. b.AddUint16(uint16(curve))
  143. }
  144. })
  145. })
  146. }
  147. if len(m.supportedPoints) > 0 {
  148. // RFC 4492, Section 5.1.2
  149. b.AddUint16(extensionSupportedPoints)
  150. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  151. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  152. b.AddBytes(m.supportedPoints)
  153. })
  154. })
  155. }
  156. if m.ticketSupported {
  157. // RFC 5077, Section 3.2
  158. b.AddUint16(extensionSessionTicket)
  159. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  160. b.AddBytes(m.sessionTicket)
  161. })
  162. }
  163. if len(m.supportedSignatureAlgorithms) > 0 {
  164. // RFC 5246, Section 7.4.1.4.1
  165. b.AddUint16(extensionSignatureAlgorithms)
  166. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  167. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  168. for _, sigAlgo := range m.supportedSignatureAlgorithms {
  169. b.AddUint16(uint16(sigAlgo))
  170. }
  171. })
  172. })
  173. }
  174. if len(m.supportedSignatureAlgorithmsCert) > 0 {
  175. // RFC 8446, Section 4.2.3
  176. b.AddUint16(extensionSignatureAlgorithmsCert)
  177. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  178. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  179. for _, sigAlgo := range m.supportedSignatureAlgorithmsCert {
  180. b.AddUint16(uint16(sigAlgo))
  181. }
  182. })
  183. })
  184. }
  185. if m.secureRenegotiationSupported {
  186. // RFC 5746, Section 3.2
  187. b.AddUint16(extensionRenegotiationInfo)
  188. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  189. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  190. b.AddBytes(m.secureRenegotiation)
  191. })
  192. })
  193. }
  194. if len(m.alpnProtocols) > 0 {
  195. // RFC 7301, Section 3.1
  196. b.AddUint16(extensionALPN)
  197. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  198. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  199. for _, proto := range m.alpnProtocols {
  200. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  201. b.AddBytes([]byte(proto))
  202. })
  203. }
  204. })
  205. })
  206. }
  207. if m.scts {
  208. // RFC 6962, Section 3.3.1
  209. b.AddUint16(extensionSCT)
  210. b.AddUint16(0) // empty extension_data
  211. }
  212. if len(m.supportedVersions) > 0 {
  213. // RFC 8446, Section 4.2.1
  214. b.AddUint16(extensionSupportedVersions)
  215. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  216. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  217. for _, vers := range m.supportedVersions {
  218. b.AddUint16(vers)
  219. }
  220. })
  221. })
  222. }
  223. if len(m.cookie) > 0 {
  224. // RFC 8446, Section 4.2.2
  225. b.AddUint16(extensionCookie)
  226. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  227. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  228. b.AddBytes(m.cookie)
  229. })
  230. })
  231. }
  232. if len(m.keyShares) > 0 {
  233. // RFC 8446, Section 4.2.8
  234. b.AddUint16(extensionKeyShare)
  235. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  236. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  237. for _, ks := range m.keyShares {
  238. b.AddUint16(uint16(ks.group))
  239. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  240. b.AddBytes(ks.data)
  241. })
  242. }
  243. })
  244. })
  245. }
  246. if m.earlyData {
  247. // RFC 8446, Section 4.2.10
  248. b.AddUint16(extensionEarlyData)
  249. b.AddUint16(0) // empty extension_data
  250. }
  251. if len(m.pskModes) > 0 {
  252. // RFC 8446, Section 4.2.9
  253. b.AddUint16(extensionPSKModes)
  254. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  255. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  256. b.AddBytes(m.pskModes)
  257. })
  258. })
  259. }
  260. if len(m.pskIdentities) > 0 { // pre_shared_key must be the last extension
  261. // RFC 8446, Section 4.2.11
  262. b.AddUint16(extensionPreSharedKey)
  263. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  264. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  265. for _, psk := range m.pskIdentities {
  266. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  267. b.AddBytes(psk.label)
  268. })
  269. b.AddUint32(psk.obfuscatedTicketAge)
  270. }
  271. })
  272. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  273. for _, binder := range m.pskBinders {
  274. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  275. b.AddBytes(binder)
  276. })
  277. }
  278. })
  279. })
  280. }
  281. extensionsPresent = len(b.BytesOrPanic()) > 2
  282. })
  283. if !extensionsPresent {
  284. *b = bWithoutExtensions
  285. }
  286. })
  287. m.raw = b.BytesOrPanic()
  288. return m.raw
  289. }
  290. // marshalWithoutBinders returns the ClientHello through the
  291. // PreSharedKeyExtension.identities field, according to RFC 8446, Section
  292. // 4.2.11.2. Note that m.pskBinders must be set to slices of the correct length.
  293. func (m *clientHelloMsg) marshalWithoutBinders() []byte {
  294. bindersLen := 2 // uint16 length prefix
  295. for _, binder := range m.pskBinders {
  296. bindersLen += 1 // uint8 length prefix
  297. bindersLen += len(binder)
  298. }
  299. fullMessage := m.marshal()
  300. return fullMessage[:len(fullMessage)-bindersLen]
  301. }
  302. // updateBinders updates the m.pskBinders field, if necessary updating the
  303. // cached marshaled representation. The supplied binders must have the same
  304. // length as the current m.pskBinders.
  305. func (m *clientHelloMsg) updateBinders(pskBinders [][]byte) {
  306. if len(pskBinders) != len(m.pskBinders) {
  307. panic("tls: internal error: pskBinders length mismatch")
  308. }
  309. for i := range m.pskBinders {
  310. if len(pskBinders[i]) != len(m.pskBinders[i]) {
  311. panic("tls: internal error: pskBinders length mismatch")
  312. }
  313. }
  314. m.pskBinders = pskBinders
  315. if m.raw != nil {
  316. lenWithoutBinders := len(m.marshalWithoutBinders())
  317. // TODO(filippo): replace with NewFixedBuilder once CL 148882 is imported.
  318. b := cryptobyte.NewBuilder(m.raw[:lenWithoutBinders])
  319. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  320. for _, binder := range m.pskBinders {
  321. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  322. b.AddBytes(binder)
  323. })
  324. }
  325. })
  326. if len(b.BytesOrPanic()) != len(m.raw) {
  327. panic("tls: internal error: failed to update binders")
  328. }
  329. }
  330. }
  331. func (m *clientHelloMsg) unmarshal(data []byte) bool {
  332. *m = clientHelloMsg{raw: data}
  333. s := cryptobyte.String(data)
  334. if !s.Skip(4) || // message type and uint24 length field
  335. !s.ReadUint16(&m.vers) || !s.ReadBytes(&m.random, 32) ||
  336. !readUint8LengthPrefixed(&s, &m.sessionId) {
  337. return false
  338. }
  339. var cipherSuites cryptobyte.String
  340. if !s.ReadUint16LengthPrefixed(&cipherSuites) {
  341. return false
  342. }
  343. m.cipherSuites = []uint16{}
  344. m.secureRenegotiationSupported = false
  345. for !cipherSuites.Empty() {
  346. var suite uint16
  347. if !cipherSuites.ReadUint16(&suite) {
  348. return false
  349. }
  350. if suite == scsvRenegotiation {
  351. m.secureRenegotiationSupported = true
  352. }
  353. m.cipherSuites = append(m.cipherSuites, suite)
  354. }
  355. if !readUint8LengthPrefixed(&s, &m.compressionMethods) {
  356. return false
  357. }
  358. if s.Empty() {
  359. // ClientHello is optionally followed by extension data
  360. return true
  361. }
  362. var extensions cryptobyte.String
  363. if !s.ReadUint16LengthPrefixed(&extensions) || !s.Empty() {
  364. return false
  365. }
  366. for !extensions.Empty() {
  367. var extension uint16
  368. var extData cryptobyte.String
  369. if !extensions.ReadUint16(&extension) ||
  370. !extensions.ReadUint16LengthPrefixed(&extData) {
  371. return false
  372. }
  373. switch extension {
  374. case extensionServerName:
  375. // RFC 6066, Section 3
  376. var nameList cryptobyte.String
  377. if !extData.ReadUint16LengthPrefixed(&nameList) || nameList.Empty() {
  378. return false
  379. }
  380. for !nameList.Empty() {
  381. var nameType uint8
  382. var serverName cryptobyte.String
  383. if !nameList.ReadUint8(&nameType) ||
  384. !nameList.ReadUint16LengthPrefixed(&serverName) ||
  385. serverName.Empty() {
  386. return false
  387. }
  388. if nameType != 0 {
  389. continue
  390. }
  391. if len(m.serverName) != 0 {
  392. // Multiple names of the same name_type are prohibited.
  393. return false
  394. }
  395. m.serverName = string(serverName)
  396. // An SNI value may not include a trailing dot.
  397. if strings.HasSuffix(m.serverName, ".") {
  398. return false
  399. }
  400. }
  401. case extensionNextProtoNeg:
  402. // draft-agl-tls-nextprotoneg-04
  403. m.nextProtoNeg = true
  404. case extensionStatusRequest:
  405. // RFC 4366, Section 3.6
  406. var statusType uint8
  407. var ignored cryptobyte.String
  408. if !extData.ReadUint8(&statusType) ||
  409. !extData.ReadUint16LengthPrefixed(&ignored) ||
  410. !extData.ReadUint16LengthPrefixed(&ignored) {
  411. return false
  412. }
  413. m.ocspStapling = statusType == statusTypeOCSP
  414. case extensionSupportedCurves:
  415. // RFC 4492, sections 5.1.1 and RFC 8446, Section 4.2.7
  416. var curves cryptobyte.String
  417. if !extData.ReadUint16LengthPrefixed(&curves) || curves.Empty() {
  418. return false
  419. }
  420. for !curves.Empty() {
  421. var curve uint16
  422. if !curves.ReadUint16(&curve) {
  423. return false
  424. }
  425. m.supportedCurves = append(m.supportedCurves, CurveID(curve))
  426. }
  427. case extensionSupportedPoints:
  428. // RFC 4492, Section 5.1.2
  429. if !readUint8LengthPrefixed(&extData, &m.supportedPoints) ||
  430. len(m.supportedPoints) == 0 {
  431. return false
  432. }
  433. case extensionSessionTicket:
  434. // RFC 5077, Section 3.2
  435. m.ticketSupported = true
  436. extData.ReadBytes(&m.sessionTicket, len(extData))
  437. case extensionSignatureAlgorithms:
  438. // RFC 5246, Section 7.4.1.4.1
  439. var sigAndAlgs cryptobyte.String
  440. if !extData.ReadUint16LengthPrefixed(&sigAndAlgs) || sigAndAlgs.Empty() {
  441. return false
  442. }
  443. for !sigAndAlgs.Empty() {
  444. var sigAndAlg uint16
  445. if !sigAndAlgs.ReadUint16(&sigAndAlg) {
  446. return false
  447. }
  448. m.supportedSignatureAlgorithms = append(
  449. m.supportedSignatureAlgorithms, SignatureScheme(sigAndAlg))
  450. }
  451. case extensionSignatureAlgorithmsCert:
  452. // RFC 8446, Section 4.2.3
  453. var sigAndAlgs cryptobyte.String
  454. if !extData.ReadUint16LengthPrefixed(&sigAndAlgs) || sigAndAlgs.Empty() {
  455. return false
  456. }
  457. for !sigAndAlgs.Empty() {
  458. var sigAndAlg uint16
  459. if !sigAndAlgs.ReadUint16(&sigAndAlg) {
  460. return false
  461. }
  462. m.supportedSignatureAlgorithmsCert = append(
  463. m.supportedSignatureAlgorithmsCert, SignatureScheme(sigAndAlg))
  464. }
  465. case extensionRenegotiationInfo:
  466. // RFC 5746, Section 3.2
  467. if !readUint8LengthPrefixed(&extData, &m.secureRenegotiation) {
  468. return false
  469. }
  470. m.secureRenegotiationSupported = true
  471. case extensionALPN:
  472. // RFC 7301, Section 3.1
  473. var protoList cryptobyte.String
  474. if !extData.ReadUint16LengthPrefixed(&protoList) || protoList.Empty() {
  475. return false
  476. }
  477. for !protoList.Empty() {
  478. var proto cryptobyte.String
  479. if !protoList.ReadUint8LengthPrefixed(&proto) || proto.Empty() {
  480. return false
  481. }
  482. m.alpnProtocols = append(m.alpnProtocols, string(proto))
  483. }
  484. case extensionSCT:
  485. // RFC 6962, Section 3.3.1
  486. m.scts = true
  487. case extensionSupportedVersions:
  488. // RFC 8446, Section 4.2.1
  489. var versList cryptobyte.String
  490. if !extData.ReadUint8LengthPrefixed(&versList) || versList.Empty() {
  491. return false
  492. }
  493. for !versList.Empty() {
  494. var vers uint16
  495. if !versList.ReadUint16(&vers) {
  496. return false
  497. }
  498. m.supportedVersions = append(m.supportedVersions, vers)
  499. }
  500. case extensionCookie:
  501. // RFC 8446, Section 4.2.2
  502. if !readUint16LengthPrefixed(&extData, &m.cookie) ||
  503. len(m.cookie) == 0 {
  504. return false
  505. }
  506. case extensionKeyShare:
  507. // RFC 8446, Section 4.2.8
  508. var clientShares cryptobyte.String
  509. if !extData.ReadUint16LengthPrefixed(&clientShares) {
  510. return false
  511. }
  512. for !clientShares.Empty() {
  513. var ks keyShare
  514. if !clientShares.ReadUint16((*uint16)(&ks.group)) ||
  515. !readUint16LengthPrefixed(&clientShares, &ks.data) ||
  516. len(ks.data) == 0 {
  517. return false
  518. }
  519. m.keyShares = append(m.keyShares, ks)
  520. }
  521. case extensionEarlyData:
  522. // RFC 8446, Section 4.2.10
  523. m.earlyData = true
  524. case extensionPSKModes:
  525. // RFC 8446, Section 4.2.9
  526. if !readUint8LengthPrefixed(&extData, &m.pskModes) {
  527. return false
  528. }
  529. case extensionPreSharedKey:
  530. // RFC 8446, Section 4.2.11
  531. if !extensions.Empty() {
  532. return false // pre_shared_key must be the last extension
  533. }
  534. var identities cryptobyte.String
  535. if !extData.ReadUint16LengthPrefixed(&identities) || identities.Empty() {
  536. return false
  537. }
  538. for !identities.Empty() {
  539. var psk pskIdentity
  540. if !readUint16LengthPrefixed(&identities, &psk.label) ||
  541. !identities.ReadUint32(&psk.obfuscatedTicketAge) ||
  542. len(psk.label) == 0 {
  543. return false
  544. }
  545. m.pskIdentities = append(m.pskIdentities, psk)
  546. }
  547. var binders cryptobyte.String
  548. if !extData.ReadUint16LengthPrefixed(&binders) || binders.Empty() {
  549. return false
  550. }
  551. for !binders.Empty() {
  552. var binder []byte
  553. if !readUint8LengthPrefixed(&binders, &binder) ||
  554. len(binder) == 0 {
  555. return false
  556. }
  557. m.pskBinders = append(m.pskBinders, binder)
  558. }
  559. default:
  560. // Ignore unknown extensions.
  561. continue
  562. }
  563. if !extData.Empty() {
  564. return false
  565. }
  566. }
  567. return true
  568. }
  569. type serverHelloMsg struct {
  570. raw []byte
  571. vers uint16
  572. random []byte
  573. sessionId []byte
  574. cipherSuite uint16
  575. compressionMethod uint8
  576. nextProtoNeg bool
  577. nextProtos []string
  578. ocspStapling bool
  579. ticketSupported bool
  580. secureRenegotiationSupported bool
  581. secureRenegotiation []byte
  582. alpnProtocol string
  583. ems bool
  584. scts [][]byte
  585. supportedVersion uint16
  586. serverShare keyShare
  587. selectedIdentityPresent bool
  588. selectedIdentity uint16
  589. // HelloRetryRequest extensions
  590. cookie []byte
  591. selectedGroup CurveID
  592. }
  593. func (m *serverHelloMsg) marshal() []byte {
  594. if m.raw != nil {
  595. return m.raw
  596. }
  597. var b cryptobyte.Builder
  598. b.AddUint8(typeServerHello)
  599. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  600. b.AddUint16(m.vers)
  601. addBytesWithLength(b, m.random, 32)
  602. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  603. b.AddBytes(m.sessionId)
  604. })
  605. b.AddUint16(m.cipherSuite)
  606. b.AddUint8(m.compressionMethod)
  607. // If extensions aren't present, omit them.
  608. var extensionsPresent bool
  609. bWithoutExtensions := *b
  610. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  611. if m.nextProtoNeg {
  612. b.AddUint16(extensionNextProtoNeg)
  613. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  614. for _, proto := range m.nextProtos {
  615. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  616. b.AddBytes([]byte(proto))
  617. })
  618. }
  619. })
  620. }
  621. if m.ocspStapling {
  622. b.AddUint16(extensionStatusRequest)
  623. b.AddUint16(0) // empty extension_data
  624. }
  625. if m.ticketSupported {
  626. b.AddUint16(extensionSessionTicket)
  627. b.AddUint16(0) // empty extension_data
  628. }
  629. if m.secureRenegotiationSupported {
  630. b.AddUint16(extensionRenegotiationInfo)
  631. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  632. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  633. b.AddBytes(m.secureRenegotiation)
  634. })
  635. })
  636. }
  637. if len(m.alpnProtocol) > 0 {
  638. b.AddUint16(extensionALPN)
  639. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  640. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  641. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  642. b.AddBytes([]byte(m.alpnProtocol))
  643. })
  644. })
  645. })
  646. }
  647. if len(m.scts) > 0 {
  648. b.AddUint16(extensionSCT)
  649. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  650. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  651. for _, sct := range m.scts {
  652. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  653. b.AddBytes(sct)
  654. })
  655. }
  656. })
  657. })
  658. }
  659. if m.supportedVersion != 0 {
  660. b.AddUint16(extensionSupportedVersions)
  661. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  662. b.AddUint16(m.supportedVersion)
  663. })
  664. }
  665. if m.serverShare.group != 0 {
  666. b.AddUint16(extensionKeyShare)
  667. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  668. b.AddUint16(uint16(m.serverShare.group))
  669. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  670. b.AddBytes(m.serverShare.data)
  671. })
  672. })
  673. }
  674. if m.selectedIdentityPresent {
  675. b.AddUint16(extensionPreSharedKey)
  676. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  677. b.AddUint16(m.selectedIdentity)
  678. })
  679. }
  680. if len(m.cookie) > 0 {
  681. b.AddUint16(extensionCookie)
  682. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  683. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  684. b.AddBytes(m.cookie)
  685. })
  686. })
  687. }
  688. if m.selectedGroup != 0 {
  689. b.AddUint16(extensionKeyShare)
  690. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  691. b.AddUint16(uint16(m.selectedGroup))
  692. })
  693. }
  694. extensionsPresent = len(b.BytesOrPanic()) > 2
  695. })
  696. if !extensionsPresent {
  697. *b = bWithoutExtensions
  698. }
  699. })
  700. m.raw = b.BytesOrPanic()
  701. return m.raw
  702. }
  703. func (m *serverHelloMsg) unmarshal(data []byte) bool {
  704. *m = serverHelloMsg{raw: data}
  705. s := cryptobyte.String(data)
  706. if !s.Skip(4) || // message type and uint24 length field
  707. !s.ReadUint16(&m.vers) || !s.ReadBytes(&m.random, 32) ||
  708. !readUint8LengthPrefixed(&s, &m.sessionId) ||
  709. !s.ReadUint16(&m.cipherSuite) ||
  710. !s.ReadUint8(&m.compressionMethod) {
  711. return false
  712. }
  713. if s.Empty() {
  714. // ServerHello is optionally followed by extension data
  715. return true
  716. }
  717. var extensions cryptobyte.String
  718. if !s.ReadUint16LengthPrefixed(&extensions) || !s.Empty() {
  719. return false
  720. }
  721. for !extensions.Empty() {
  722. var extension uint16
  723. var extData cryptobyte.String
  724. if !extensions.ReadUint16(&extension) ||
  725. !extensions.ReadUint16LengthPrefixed(&extData) {
  726. return false
  727. }
  728. switch extension {
  729. case extensionNextProtoNeg:
  730. m.nextProtoNeg = true
  731. for !extData.Empty() {
  732. var proto cryptobyte.String
  733. if !extData.ReadUint8LengthPrefixed(&proto) ||
  734. proto.Empty() {
  735. return false
  736. }
  737. m.nextProtos = append(m.nextProtos, string(proto))
  738. }
  739. case extensionStatusRequest:
  740. m.ocspStapling = true
  741. case extensionSessionTicket:
  742. m.ticketSupported = true
  743. case utlsExtensionExtendedMasterSecret:
  744. // No sanity check for this extension: pretending not to know it.
  745. // if length > 0 {
  746. // return false
  747. // }
  748. m.ems = true
  749. case extensionRenegotiationInfo:
  750. if !readUint8LengthPrefixed(&extData, &m.secureRenegotiation) {
  751. return false
  752. }
  753. m.secureRenegotiationSupported = true
  754. case extensionALPN:
  755. var protoList cryptobyte.String
  756. if !extData.ReadUint16LengthPrefixed(&protoList) || protoList.Empty() {
  757. return false
  758. }
  759. var proto cryptobyte.String
  760. if !protoList.ReadUint8LengthPrefixed(&proto) ||
  761. proto.Empty() || !protoList.Empty() {
  762. return false
  763. }
  764. m.alpnProtocol = string(proto)
  765. case extensionSCT:
  766. var sctList cryptobyte.String
  767. if !extData.ReadUint16LengthPrefixed(&sctList) || sctList.Empty() {
  768. return false
  769. }
  770. for !sctList.Empty() {
  771. var sct []byte
  772. if !readUint16LengthPrefixed(&sctList, &sct) ||
  773. len(sct) == 0 {
  774. return false
  775. }
  776. m.scts = append(m.scts, sct)
  777. }
  778. case extensionSupportedVersions:
  779. if !extData.ReadUint16(&m.supportedVersion) {
  780. return false
  781. }
  782. case extensionCookie:
  783. if !readUint16LengthPrefixed(&extData, &m.cookie) ||
  784. len(m.cookie) == 0 {
  785. return false
  786. }
  787. case extensionKeyShare:
  788. // This extension has different formats in SH and HRR, accept either
  789. // and let the handshake logic decide. See RFC 8446, Section 4.2.8.
  790. if len(extData) == 2 {
  791. if !extData.ReadUint16((*uint16)(&m.selectedGroup)) {
  792. return false
  793. }
  794. } else {
  795. if !extData.ReadUint16((*uint16)(&m.serverShare.group)) ||
  796. !readUint16LengthPrefixed(&extData, &m.serverShare.data) {
  797. return false
  798. }
  799. }
  800. case extensionPreSharedKey:
  801. m.selectedIdentityPresent = true
  802. if !extData.ReadUint16(&m.selectedIdentity) {
  803. return false
  804. }
  805. default:
  806. // Ignore unknown extensions.
  807. continue
  808. }
  809. if !extData.Empty() {
  810. return false
  811. }
  812. }
  813. return true
  814. }
  815. type encryptedExtensionsMsg struct {
  816. raw []byte
  817. alpnProtocol string
  818. }
  819. func (m *encryptedExtensionsMsg) marshal() []byte {
  820. if m.raw != nil {
  821. return m.raw
  822. }
  823. var b cryptobyte.Builder
  824. b.AddUint8(typeEncryptedExtensions)
  825. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  826. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  827. if len(m.alpnProtocol) > 0 {
  828. b.AddUint16(extensionALPN)
  829. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  830. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  831. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  832. b.AddBytes([]byte(m.alpnProtocol))
  833. })
  834. })
  835. })
  836. }
  837. })
  838. })
  839. m.raw = b.BytesOrPanic()
  840. return m.raw
  841. }
  842. func (m *encryptedExtensionsMsg) unmarshal(data []byte) bool {
  843. *m = encryptedExtensionsMsg{raw: data}
  844. s := cryptobyte.String(data)
  845. var extensions cryptobyte.String
  846. if !s.Skip(4) || // message type and uint24 length field
  847. !s.ReadUint16LengthPrefixed(&extensions) || !s.Empty() {
  848. return false
  849. }
  850. for !extensions.Empty() {
  851. var extension uint16
  852. var extData cryptobyte.String
  853. if !extensions.ReadUint16(&extension) ||
  854. !extensions.ReadUint16LengthPrefixed(&extData) {
  855. return false
  856. }
  857. switch extension {
  858. case extensionALPN:
  859. var protoList cryptobyte.String
  860. if !extData.ReadUint16LengthPrefixed(&protoList) || protoList.Empty() {
  861. return false
  862. }
  863. var proto cryptobyte.String
  864. if !protoList.ReadUint8LengthPrefixed(&proto) ||
  865. proto.Empty() || !protoList.Empty() {
  866. return false
  867. }
  868. m.alpnProtocol = string(proto)
  869. default:
  870. // Ignore unknown extensions.
  871. continue
  872. }
  873. if !extData.Empty() {
  874. return false
  875. }
  876. }
  877. return true
  878. }
  879. type endOfEarlyDataMsg struct{}
  880. func (m *endOfEarlyDataMsg) marshal() []byte {
  881. x := make([]byte, 4)
  882. x[0] = typeEndOfEarlyData
  883. return x
  884. }
  885. func (m *endOfEarlyDataMsg) unmarshal(data []byte) bool {
  886. return len(data) == 4
  887. }
  888. type keyUpdateMsg struct {
  889. raw []byte
  890. updateRequested bool
  891. }
  892. func (m *keyUpdateMsg) marshal() []byte {
  893. if m.raw != nil {
  894. return m.raw
  895. }
  896. var b cryptobyte.Builder
  897. b.AddUint8(typeKeyUpdate)
  898. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  899. if m.updateRequested {
  900. b.AddUint8(1)
  901. } else {
  902. b.AddUint8(0)
  903. }
  904. })
  905. m.raw = b.BytesOrPanic()
  906. return m.raw
  907. }
  908. func (m *keyUpdateMsg) unmarshal(data []byte) bool {
  909. m.raw = data
  910. s := cryptobyte.String(data)
  911. var updateRequested uint8
  912. if !s.Skip(4) || // message type and uint24 length field
  913. !s.ReadUint8(&updateRequested) || !s.Empty() {
  914. return false
  915. }
  916. switch updateRequested {
  917. case 0:
  918. m.updateRequested = false
  919. case 1:
  920. m.updateRequested = true
  921. default:
  922. return false
  923. }
  924. return true
  925. }
  926. type newSessionTicketMsgTLS13 struct {
  927. raw []byte
  928. lifetime uint32
  929. ageAdd uint32
  930. nonce []byte
  931. label []byte
  932. maxEarlyData uint32
  933. }
  934. func (m *newSessionTicketMsgTLS13) marshal() []byte {
  935. if m.raw != nil {
  936. return m.raw
  937. }
  938. var b cryptobyte.Builder
  939. b.AddUint8(typeNewSessionTicket)
  940. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  941. b.AddUint32(m.lifetime)
  942. b.AddUint32(m.ageAdd)
  943. b.AddUint8LengthPrefixed(func(b *cryptobyte.Builder) {
  944. b.AddBytes(m.nonce)
  945. })
  946. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  947. b.AddBytes(m.label)
  948. })
  949. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  950. if m.maxEarlyData > 0 {
  951. b.AddUint16(extensionEarlyData)
  952. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  953. b.AddUint32(m.maxEarlyData)
  954. })
  955. }
  956. })
  957. })
  958. m.raw = b.BytesOrPanic()
  959. return m.raw
  960. }
  961. func (m *newSessionTicketMsgTLS13) unmarshal(data []byte) bool {
  962. *m = newSessionTicketMsgTLS13{raw: data}
  963. s := cryptobyte.String(data)
  964. var extensions cryptobyte.String
  965. if !s.Skip(4) || // message type and uint24 length field
  966. !s.ReadUint32(&m.lifetime) ||
  967. !s.ReadUint32(&m.ageAdd) ||
  968. !readUint8LengthPrefixed(&s, &m.nonce) ||
  969. !readUint16LengthPrefixed(&s, &m.label) ||
  970. !s.ReadUint16LengthPrefixed(&extensions) ||
  971. !s.Empty() {
  972. return false
  973. }
  974. for !extensions.Empty() {
  975. var extension uint16
  976. var extData cryptobyte.String
  977. if !extensions.ReadUint16(&extension) ||
  978. !extensions.ReadUint16LengthPrefixed(&extData) {
  979. return false
  980. }
  981. switch extension {
  982. case extensionEarlyData:
  983. if !extData.ReadUint32(&m.maxEarlyData) {
  984. return false
  985. }
  986. default:
  987. // Ignore unknown extensions.
  988. continue
  989. }
  990. if !extData.Empty() {
  991. return false
  992. }
  993. }
  994. return true
  995. }
  996. type certificateRequestMsgTLS13 struct {
  997. raw []byte
  998. ocspStapling bool
  999. scts bool
  1000. supportedSignatureAlgorithms []SignatureScheme
  1001. supportedSignatureAlgorithmsCert []SignatureScheme
  1002. certificateAuthorities [][]byte
  1003. }
  1004. func (m *certificateRequestMsgTLS13) marshal() []byte {
  1005. if m.raw != nil {
  1006. return m.raw
  1007. }
  1008. var b cryptobyte.Builder
  1009. b.AddUint8(typeCertificateRequest)
  1010. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1011. // certificate_request_context (SHALL be zero length unless used for
  1012. // post-handshake authentication)
  1013. b.AddUint8(0)
  1014. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1015. if m.ocspStapling {
  1016. b.AddUint16(extensionStatusRequest)
  1017. b.AddUint16(0) // empty extension_data
  1018. }
  1019. if m.scts {
  1020. // RFC 8446, Section 4.4.2.1 makes no mention of
  1021. // signed_certificate_timestamp in CertificateRequest, but
  1022. // "Extensions in the Certificate message from the client MUST
  1023. // correspond to extensions in the CertificateRequest message
  1024. // from the server." and it appears in the table in Section 4.2.
  1025. b.AddUint16(extensionSCT)
  1026. b.AddUint16(0) // empty extension_data
  1027. }
  1028. if len(m.supportedSignatureAlgorithms) > 0 {
  1029. b.AddUint16(extensionSignatureAlgorithms)
  1030. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1031. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1032. for _, sigAlgo := range m.supportedSignatureAlgorithms {
  1033. b.AddUint16(uint16(sigAlgo))
  1034. }
  1035. })
  1036. })
  1037. }
  1038. if len(m.supportedSignatureAlgorithmsCert) > 0 {
  1039. b.AddUint16(extensionSignatureAlgorithmsCert)
  1040. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1041. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1042. for _, sigAlgo := range m.supportedSignatureAlgorithmsCert {
  1043. b.AddUint16(uint16(sigAlgo))
  1044. }
  1045. })
  1046. })
  1047. }
  1048. if len(m.certificateAuthorities) > 0 {
  1049. b.AddUint16(extensionCertificateAuthorities)
  1050. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1051. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1052. for _, ca := range m.certificateAuthorities {
  1053. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1054. b.AddBytes(ca)
  1055. })
  1056. }
  1057. })
  1058. })
  1059. }
  1060. })
  1061. })
  1062. m.raw = b.BytesOrPanic()
  1063. return m.raw
  1064. }
  1065. func (m *certificateRequestMsgTLS13) unmarshal(data []byte) bool {
  1066. *m = certificateRequestMsgTLS13{raw: data}
  1067. s := cryptobyte.String(data)
  1068. var context, extensions cryptobyte.String
  1069. if !s.Skip(4) || // message type and uint24 length field
  1070. !s.ReadUint8LengthPrefixed(&context) || !context.Empty() ||
  1071. !s.ReadUint16LengthPrefixed(&extensions) ||
  1072. !s.Empty() {
  1073. return false
  1074. }
  1075. for !extensions.Empty() {
  1076. var extension uint16
  1077. var extData cryptobyte.String
  1078. if !extensions.ReadUint16(&extension) ||
  1079. !extensions.ReadUint16LengthPrefixed(&extData) {
  1080. return false
  1081. }
  1082. switch extension {
  1083. case extensionStatusRequest:
  1084. m.ocspStapling = true
  1085. case extensionSCT:
  1086. m.scts = true
  1087. case extensionSignatureAlgorithms:
  1088. var sigAndAlgs cryptobyte.String
  1089. if !extData.ReadUint16LengthPrefixed(&sigAndAlgs) || sigAndAlgs.Empty() {
  1090. return false
  1091. }
  1092. for !sigAndAlgs.Empty() {
  1093. var sigAndAlg uint16
  1094. if !sigAndAlgs.ReadUint16(&sigAndAlg) {
  1095. return false
  1096. }
  1097. m.supportedSignatureAlgorithms = append(
  1098. m.supportedSignatureAlgorithms, SignatureScheme(sigAndAlg))
  1099. }
  1100. case extensionSignatureAlgorithmsCert:
  1101. var sigAndAlgs cryptobyte.String
  1102. if !extData.ReadUint16LengthPrefixed(&sigAndAlgs) || sigAndAlgs.Empty() {
  1103. return false
  1104. }
  1105. for !sigAndAlgs.Empty() {
  1106. var sigAndAlg uint16
  1107. if !sigAndAlgs.ReadUint16(&sigAndAlg) {
  1108. return false
  1109. }
  1110. m.supportedSignatureAlgorithmsCert = append(
  1111. m.supportedSignatureAlgorithmsCert, SignatureScheme(sigAndAlg))
  1112. }
  1113. case extensionCertificateAuthorities:
  1114. var auths cryptobyte.String
  1115. if !extData.ReadUint16LengthPrefixed(&auths) || auths.Empty() {
  1116. return false
  1117. }
  1118. for !auths.Empty() {
  1119. var ca []byte
  1120. if !readUint16LengthPrefixed(&auths, &ca) || len(ca) == 0 {
  1121. return false
  1122. }
  1123. m.certificateAuthorities = append(m.certificateAuthorities, ca)
  1124. }
  1125. default:
  1126. // Ignore unknown extensions.
  1127. continue
  1128. }
  1129. if !extData.Empty() {
  1130. return false
  1131. }
  1132. }
  1133. return true
  1134. }
  1135. type certificateMsg struct {
  1136. raw []byte
  1137. certificates [][]byte
  1138. }
  1139. func (m *certificateMsg) marshal() (x []byte) {
  1140. if m.raw != nil {
  1141. return m.raw
  1142. }
  1143. var i int
  1144. for _, slice := range m.certificates {
  1145. i += len(slice)
  1146. }
  1147. length := 3 + 3*len(m.certificates) + i
  1148. x = make([]byte, 4+length)
  1149. x[0] = typeCertificate
  1150. x[1] = uint8(length >> 16)
  1151. x[2] = uint8(length >> 8)
  1152. x[3] = uint8(length)
  1153. certificateOctets := length - 3
  1154. x[4] = uint8(certificateOctets >> 16)
  1155. x[5] = uint8(certificateOctets >> 8)
  1156. x[6] = uint8(certificateOctets)
  1157. y := x[7:]
  1158. for _, slice := range m.certificates {
  1159. y[0] = uint8(len(slice) >> 16)
  1160. y[1] = uint8(len(slice) >> 8)
  1161. y[2] = uint8(len(slice))
  1162. copy(y[3:], slice)
  1163. y = y[3+len(slice):]
  1164. }
  1165. m.raw = x
  1166. return
  1167. }
  1168. func (m *certificateMsg) unmarshal(data []byte) bool {
  1169. if len(data) < 7 {
  1170. return false
  1171. }
  1172. m.raw = data
  1173. certsLen := uint32(data[4])<<16 | uint32(data[5])<<8 | uint32(data[6])
  1174. if uint32(len(data)) != certsLen+7 {
  1175. return false
  1176. }
  1177. numCerts := 0
  1178. d := data[7:]
  1179. for certsLen > 0 {
  1180. if len(d) < 4 {
  1181. return false
  1182. }
  1183. certLen := uint32(d[0])<<16 | uint32(d[1])<<8 | uint32(d[2])
  1184. if uint32(len(d)) < 3+certLen {
  1185. return false
  1186. }
  1187. d = d[3+certLen:]
  1188. certsLen -= 3 + certLen
  1189. numCerts++
  1190. }
  1191. m.certificates = make([][]byte, numCerts)
  1192. d = data[7:]
  1193. for i := 0; i < numCerts; i++ {
  1194. certLen := uint32(d[0])<<16 | uint32(d[1])<<8 | uint32(d[2])
  1195. m.certificates[i] = d[3 : 3+certLen]
  1196. d = d[3+certLen:]
  1197. }
  1198. return true
  1199. }
  1200. type certificateMsgTLS13 struct {
  1201. raw []byte
  1202. certificate Certificate
  1203. ocspStapling bool
  1204. scts bool
  1205. }
  1206. func (m *certificateMsgTLS13) marshal() []byte {
  1207. if m.raw != nil {
  1208. return m.raw
  1209. }
  1210. var b cryptobyte.Builder
  1211. b.AddUint8(typeCertificate)
  1212. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1213. b.AddUint8(0) // certificate_request_context
  1214. certificate := m.certificate
  1215. if !m.ocspStapling {
  1216. certificate.OCSPStaple = nil
  1217. }
  1218. if !m.scts {
  1219. certificate.SignedCertificateTimestamps = nil
  1220. }
  1221. marshalCertificate(b, certificate)
  1222. })
  1223. m.raw = b.BytesOrPanic()
  1224. return m.raw
  1225. }
  1226. func marshalCertificate(b *cryptobyte.Builder, certificate Certificate) {
  1227. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1228. for i, cert := range certificate.Certificate {
  1229. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1230. b.AddBytes(cert)
  1231. })
  1232. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1233. if i > 0 {
  1234. // This library only supports OCSP and SCT for leaf certificates.
  1235. return
  1236. }
  1237. if certificate.OCSPStaple != nil {
  1238. b.AddUint16(extensionStatusRequest)
  1239. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1240. b.AddUint8(statusTypeOCSP)
  1241. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1242. b.AddBytes(certificate.OCSPStaple)
  1243. })
  1244. })
  1245. }
  1246. if certificate.SignedCertificateTimestamps != nil {
  1247. b.AddUint16(extensionSCT)
  1248. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1249. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1250. for _, sct := range certificate.SignedCertificateTimestamps {
  1251. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1252. b.AddBytes(sct)
  1253. })
  1254. }
  1255. })
  1256. })
  1257. }
  1258. })
  1259. }
  1260. })
  1261. }
  1262. func (m *certificateMsgTLS13) unmarshal(data []byte) bool {
  1263. *m = certificateMsgTLS13{raw: data}
  1264. s := cryptobyte.String(data)
  1265. var context cryptobyte.String
  1266. if !s.Skip(4) || // message type and uint24 length field
  1267. !s.ReadUint8LengthPrefixed(&context) || !context.Empty() ||
  1268. !unmarshalCertificate(&s, &m.certificate) ||
  1269. !s.Empty() {
  1270. return false
  1271. }
  1272. m.scts = m.certificate.SignedCertificateTimestamps != nil
  1273. m.ocspStapling = m.certificate.OCSPStaple != nil
  1274. return true
  1275. }
  1276. func unmarshalCertificate(s *cryptobyte.String, certificate *Certificate) bool {
  1277. var certList cryptobyte.String
  1278. if !s.ReadUint24LengthPrefixed(&certList) {
  1279. return false
  1280. }
  1281. for !certList.Empty() {
  1282. var cert []byte
  1283. var extensions cryptobyte.String
  1284. if !readUint24LengthPrefixed(&certList, &cert) ||
  1285. !certList.ReadUint16LengthPrefixed(&extensions) {
  1286. return false
  1287. }
  1288. certificate.Certificate = append(certificate.Certificate, cert)
  1289. for !extensions.Empty() {
  1290. var extension uint16
  1291. var extData cryptobyte.String
  1292. if !extensions.ReadUint16(&extension) ||
  1293. !extensions.ReadUint16LengthPrefixed(&extData) {
  1294. return false
  1295. }
  1296. if len(certificate.Certificate) > 1 {
  1297. // This library only supports OCSP and SCT for leaf certificates.
  1298. continue
  1299. }
  1300. switch extension {
  1301. case extensionStatusRequest:
  1302. var statusType uint8
  1303. if !extData.ReadUint8(&statusType) || statusType != statusTypeOCSP ||
  1304. !readUint24LengthPrefixed(&extData, &certificate.OCSPStaple) ||
  1305. len(certificate.OCSPStaple) == 0 {
  1306. return false
  1307. }
  1308. case extensionSCT:
  1309. var sctList cryptobyte.String
  1310. if !extData.ReadUint16LengthPrefixed(&sctList) || sctList.Empty() {
  1311. return false
  1312. }
  1313. for !sctList.Empty() {
  1314. var sct []byte
  1315. if !readUint16LengthPrefixed(&sctList, &sct) ||
  1316. len(sct) == 0 {
  1317. return false
  1318. }
  1319. certificate.SignedCertificateTimestamps = append(
  1320. certificate.SignedCertificateTimestamps, sct)
  1321. }
  1322. default:
  1323. // Ignore unknown extensions.
  1324. continue
  1325. }
  1326. if !extData.Empty() {
  1327. return false
  1328. }
  1329. }
  1330. }
  1331. return true
  1332. }
  1333. type serverKeyExchangeMsg struct {
  1334. raw []byte
  1335. key []byte
  1336. }
  1337. func (m *serverKeyExchangeMsg) marshal() []byte {
  1338. if m.raw != nil {
  1339. return m.raw
  1340. }
  1341. length := len(m.key)
  1342. x := make([]byte, length+4)
  1343. x[0] = typeServerKeyExchange
  1344. x[1] = uint8(length >> 16)
  1345. x[2] = uint8(length >> 8)
  1346. x[3] = uint8(length)
  1347. copy(x[4:], m.key)
  1348. m.raw = x
  1349. return x
  1350. }
  1351. func (m *serverKeyExchangeMsg) unmarshal(data []byte) bool {
  1352. m.raw = data
  1353. if len(data) < 4 {
  1354. return false
  1355. }
  1356. m.key = data[4:]
  1357. return true
  1358. }
  1359. type certificateStatusMsg struct {
  1360. raw []byte
  1361. response []byte
  1362. }
  1363. func (m *certificateStatusMsg) marshal() []byte {
  1364. if m.raw != nil {
  1365. return m.raw
  1366. }
  1367. var b cryptobyte.Builder
  1368. b.AddUint8(typeCertificateStatus)
  1369. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1370. b.AddUint8(statusTypeOCSP)
  1371. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1372. b.AddBytes(m.response)
  1373. })
  1374. })
  1375. m.raw = b.BytesOrPanic()
  1376. return m.raw
  1377. }
  1378. func (m *certificateStatusMsg) unmarshal(data []byte) bool {
  1379. m.raw = data
  1380. s := cryptobyte.String(data)
  1381. var statusType uint8
  1382. if !s.Skip(4) || // message type and uint24 length field
  1383. !s.ReadUint8(&statusType) || statusType != statusTypeOCSP ||
  1384. !readUint24LengthPrefixed(&s, &m.response) ||
  1385. len(m.response) == 0 || !s.Empty() {
  1386. return false
  1387. }
  1388. return true
  1389. }
  1390. type serverHelloDoneMsg struct{}
  1391. func (m *serverHelloDoneMsg) marshal() []byte {
  1392. x := make([]byte, 4)
  1393. x[0] = typeServerHelloDone
  1394. return x
  1395. }
  1396. func (m *serverHelloDoneMsg) unmarshal(data []byte) bool {
  1397. return len(data) == 4
  1398. }
  1399. type clientKeyExchangeMsg struct {
  1400. raw []byte
  1401. ciphertext []byte
  1402. }
  1403. func (m *clientKeyExchangeMsg) marshal() []byte {
  1404. if m.raw != nil {
  1405. return m.raw
  1406. }
  1407. length := len(m.ciphertext)
  1408. x := make([]byte, length+4)
  1409. x[0] = typeClientKeyExchange
  1410. x[1] = uint8(length >> 16)
  1411. x[2] = uint8(length >> 8)
  1412. x[3] = uint8(length)
  1413. copy(x[4:], m.ciphertext)
  1414. m.raw = x
  1415. return x
  1416. }
  1417. func (m *clientKeyExchangeMsg) unmarshal(data []byte) bool {
  1418. m.raw = data
  1419. if len(data) < 4 {
  1420. return false
  1421. }
  1422. l := int(data[1])<<16 | int(data[2])<<8 | int(data[3])
  1423. if l != len(data)-4 {
  1424. return false
  1425. }
  1426. m.ciphertext = data[4:]
  1427. return true
  1428. }
  1429. type finishedMsg struct {
  1430. raw []byte
  1431. verifyData []byte
  1432. }
  1433. func (m *finishedMsg) marshal() []byte {
  1434. if m.raw != nil {
  1435. return m.raw
  1436. }
  1437. var b cryptobyte.Builder
  1438. b.AddUint8(typeFinished)
  1439. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1440. b.AddBytes(m.verifyData)
  1441. })
  1442. m.raw = b.BytesOrPanic()
  1443. return m.raw
  1444. }
  1445. func (m *finishedMsg) unmarshal(data []byte) bool {
  1446. m.raw = data
  1447. s := cryptobyte.String(data)
  1448. return s.Skip(1) &&
  1449. readUint24LengthPrefixed(&s, &m.verifyData) &&
  1450. s.Empty()
  1451. }
  1452. type nextProtoMsg struct {
  1453. raw []byte
  1454. proto string
  1455. }
  1456. func (m *nextProtoMsg) marshal() []byte {
  1457. if m.raw != nil {
  1458. return m.raw
  1459. }
  1460. l := len(m.proto)
  1461. if l > 255 {
  1462. l = 255
  1463. }
  1464. padding := 32 - (l+2)%32
  1465. length := l + padding + 2
  1466. x := make([]byte, length+4)
  1467. x[0] = typeNextProtocol
  1468. x[1] = uint8(length >> 16)
  1469. x[2] = uint8(length >> 8)
  1470. x[3] = uint8(length)
  1471. y := x[4:]
  1472. y[0] = byte(l)
  1473. copy(y[1:], []byte(m.proto[0:l]))
  1474. y = y[1+l:]
  1475. y[0] = byte(padding)
  1476. m.raw = x
  1477. return x
  1478. }
  1479. func (m *nextProtoMsg) unmarshal(data []byte) bool {
  1480. m.raw = data
  1481. if len(data) < 5 {
  1482. return false
  1483. }
  1484. data = data[4:]
  1485. protoLen := int(data[0])
  1486. data = data[1:]
  1487. if len(data) < protoLen {
  1488. return false
  1489. }
  1490. m.proto = string(data[0:protoLen])
  1491. data = data[protoLen:]
  1492. if len(data) < 1 {
  1493. return false
  1494. }
  1495. paddingLen := int(data[0])
  1496. data = data[1:]
  1497. if len(data) != paddingLen {
  1498. return false
  1499. }
  1500. return true
  1501. }
  1502. type certificateRequestMsg struct {
  1503. raw []byte
  1504. // hasSignatureAlgorithm indicates whether this message includes a list of
  1505. // supported signature algorithms. This change was introduced with TLS 1.2.
  1506. hasSignatureAlgorithm bool
  1507. certificateTypes []byte
  1508. supportedSignatureAlgorithms []SignatureScheme
  1509. certificateAuthorities [][]byte
  1510. }
  1511. func (m *certificateRequestMsg) marshal() (x []byte) {
  1512. if m.raw != nil {
  1513. return m.raw
  1514. }
  1515. // See RFC 4346, Section 7.4.4.
  1516. length := 1 + len(m.certificateTypes) + 2
  1517. casLength := 0
  1518. for _, ca := range m.certificateAuthorities {
  1519. casLength += 2 + len(ca)
  1520. }
  1521. length += casLength
  1522. if m.hasSignatureAlgorithm {
  1523. length += 2 + 2*len(m.supportedSignatureAlgorithms)
  1524. }
  1525. x = make([]byte, 4+length)
  1526. x[0] = typeCertificateRequest
  1527. x[1] = uint8(length >> 16)
  1528. x[2] = uint8(length >> 8)
  1529. x[3] = uint8(length)
  1530. x[4] = uint8(len(m.certificateTypes))
  1531. copy(x[5:], m.certificateTypes)
  1532. y := x[5+len(m.certificateTypes):]
  1533. if m.hasSignatureAlgorithm {
  1534. n := len(m.supportedSignatureAlgorithms) * 2
  1535. y[0] = uint8(n >> 8)
  1536. y[1] = uint8(n)
  1537. y = y[2:]
  1538. for _, sigAlgo := range m.supportedSignatureAlgorithms {
  1539. y[0] = uint8(sigAlgo >> 8)
  1540. y[1] = uint8(sigAlgo)
  1541. y = y[2:]
  1542. }
  1543. }
  1544. y[0] = uint8(casLength >> 8)
  1545. y[1] = uint8(casLength)
  1546. y = y[2:]
  1547. for _, ca := range m.certificateAuthorities {
  1548. y[0] = uint8(len(ca) >> 8)
  1549. y[1] = uint8(len(ca))
  1550. y = y[2:]
  1551. copy(y, ca)
  1552. y = y[len(ca):]
  1553. }
  1554. m.raw = x
  1555. return
  1556. }
  1557. func (m *certificateRequestMsg) unmarshal(data []byte) bool {
  1558. m.raw = data
  1559. if len(data) < 5 {
  1560. return false
  1561. }
  1562. length := uint32(data[1])<<16 | uint32(data[2])<<8 | uint32(data[3])
  1563. if uint32(len(data))-4 != length {
  1564. return false
  1565. }
  1566. numCertTypes := int(data[4])
  1567. data = data[5:]
  1568. if numCertTypes == 0 || len(data) <= numCertTypes {
  1569. return false
  1570. }
  1571. m.certificateTypes = make([]byte, numCertTypes)
  1572. if copy(m.certificateTypes, data) != numCertTypes {
  1573. return false
  1574. }
  1575. data = data[numCertTypes:]
  1576. if m.hasSignatureAlgorithm {
  1577. if len(data) < 2 {
  1578. return false
  1579. }
  1580. sigAndHashLen := uint16(data[0])<<8 | uint16(data[1])
  1581. data = data[2:]
  1582. if sigAndHashLen&1 != 0 {
  1583. return false
  1584. }
  1585. if len(data) < int(sigAndHashLen) {
  1586. return false
  1587. }
  1588. numSigAlgos := sigAndHashLen / 2
  1589. m.supportedSignatureAlgorithms = make([]SignatureScheme, numSigAlgos)
  1590. for i := range m.supportedSignatureAlgorithms {
  1591. m.supportedSignatureAlgorithms[i] = SignatureScheme(data[0])<<8 | SignatureScheme(data[1])
  1592. data = data[2:]
  1593. }
  1594. }
  1595. if len(data) < 2 {
  1596. return false
  1597. }
  1598. casLength := uint16(data[0])<<8 | uint16(data[1])
  1599. data = data[2:]
  1600. if len(data) < int(casLength) {
  1601. return false
  1602. }
  1603. cas := make([]byte, casLength)
  1604. copy(cas, data)
  1605. data = data[casLength:]
  1606. m.certificateAuthorities = nil
  1607. for len(cas) > 0 {
  1608. if len(cas) < 2 {
  1609. return false
  1610. }
  1611. caLen := uint16(cas[0])<<8 | uint16(cas[1])
  1612. cas = cas[2:]
  1613. if len(cas) < int(caLen) {
  1614. return false
  1615. }
  1616. m.certificateAuthorities = append(m.certificateAuthorities, cas[:caLen])
  1617. cas = cas[caLen:]
  1618. }
  1619. return len(data) == 0
  1620. }
  1621. type certificateVerifyMsg struct {
  1622. raw []byte
  1623. hasSignatureAlgorithm bool // format change introduced in TLS 1.2
  1624. signatureAlgorithm SignatureScheme
  1625. signature []byte
  1626. }
  1627. func (m *certificateVerifyMsg) marshal() (x []byte) {
  1628. if m.raw != nil {
  1629. return m.raw
  1630. }
  1631. var b cryptobyte.Builder
  1632. b.AddUint8(typeCertificateVerify)
  1633. b.AddUint24LengthPrefixed(func(b *cryptobyte.Builder) {
  1634. if m.hasSignatureAlgorithm {
  1635. b.AddUint16(uint16(m.signatureAlgorithm))
  1636. }
  1637. b.AddUint16LengthPrefixed(func(b *cryptobyte.Builder) {
  1638. b.AddBytes(m.signature)
  1639. })
  1640. })
  1641. m.raw = b.BytesOrPanic()
  1642. return m.raw
  1643. }
  1644. func (m *certificateVerifyMsg) unmarshal(data []byte) bool {
  1645. m.raw = data
  1646. s := cryptobyte.String(data)
  1647. if !s.Skip(4) { // message type and uint24 length field
  1648. return false
  1649. }
  1650. if m.hasSignatureAlgorithm {
  1651. if !s.ReadUint16((*uint16)(&m.signatureAlgorithm)) {
  1652. return false
  1653. }
  1654. }
  1655. return readUint16LengthPrefixed(&s, &m.signature) && s.Empty()
  1656. }
  1657. type newSessionTicketMsg struct {
  1658. raw []byte
  1659. ticket []byte
  1660. }
  1661. func (m *newSessionTicketMsg) marshal() (x []byte) {
  1662. if m.raw != nil {
  1663. return m.raw
  1664. }
  1665. // See RFC 5077, Section 3.3.
  1666. ticketLen := len(m.ticket)
  1667. length := 2 + 4 + ticketLen
  1668. x = make([]byte, 4+length)
  1669. x[0] = typeNewSessionTicket
  1670. x[1] = uint8(length >> 16)
  1671. x[2] = uint8(length >> 8)
  1672. x[3] = uint8(length)
  1673. x[8] = uint8(ticketLen >> 8)
  1674. x[9] = uint8(ticketLen)
  1675. copy(x[10:], m.ticket)
  1676. m.raw = x
  1677. return
  1678. }
  1679. func (m *newSessionTicketMsg) unmarshal(data []byte) bool {
  1680. m.raw = data
  1681. if len(data) < 10 {
  1682. return false
  1683. }
  1684. length := uint32(data[1])<<16 | uint32(data[2])<<8 | uint32(data[3])
  1685. if uint32(len(data))-4 != length {
  1686. return false
  1687. }
  1688. ticketLen := int(data[8])<<8 + int(data[9])
  1689. if len(data)-10 != ticketLen {
  1690. return false
  1691. }
  1692. m.ticket = data[10:]
  1693. return true
  1694. }
  1695. type helloRequestMsg struct {
  1696. }
  1697. func (*helloRequestMsg) marshal() []byte {
  1698. return []byte{typeHelloRequest, 0, 0, 0}
  1699. }
  1700. func (*helloRequestMsg) unmarshal(data []byte) bool {
  1701. return len(data) == 4
  1702. }