]>
git.proxmox.com Git - mirror_edk2.git/blob - CryptoPkg/Library/TlsLib/TlsProcess.c
2 SSL/TLS Process Library Wrapper Implementation over OpenSSL.
3 The process includes the TLS handshake and packet I/O.
5 Copyright (c) 2016 - 2017, Intel Corporation. All rights reserved.<BR>
6 (C) Copyright 2016 Hewlett Packard Enterprise Development LP<BR>
7 SPDX-License-Identifier: BSD-2-Clause-Patent
11 #include "InternalTlsLib.h"
13 #define MAX_BUFFER_SIZE 32768
16 Checks if the TLS handshake was done.
18 This function will check if the specified TLS handshake was done.
20 @param[in] Tls Pointer to the TLS object for handshake state checking.
22 @retval TRUE The TLS handshake was done.
23 @retval FALSE The TLS handshake was not done.
32 TLS_CONNECTION
*TlsConn
;
34 TlsConn
= (TLS_CONNECTION
*) Tls
;
35 if (TlsConn
== NULL
|| TlsConn
->Ssl
== NULL
) {
40 // Return the status which indicates if the TLS handshake was done.
42 return !SSL_is_init_finished (TlsConn
->Ssl
);
46 Perform a TLS/SSL handshake.
48 This function will perform a TLS/SSL handshake.
50 @param[in] Tls Pointer to the TLS object for handshake operation.
51 @param[in] BufferIn Pointer to the most recently received TLS Handshake packet.
52 @param[in] BufferInSize Packet size in bytes for the most recently received TLS
54 @param[out] BufferOut Pointer to the buffer to hold the built packet.
55 @param[in, out] BufferOutSize Pointer to the buffer size in bytes. On input, it is
56 the buffer size provided by the caller. On output, it
57 is the buffer size in fact needed to contain the
60 @retval EFI_SUCCESS The required TLS packet is built successfully.
61 @retval EFI_INVALID_PARAMETER One or more of the following conditions is TRUE:
63 BufferIn is NULL but BufferInSize is NOT 0.
64 BufferInSize is 0 but BufferIn is NOT NULL.
65 BufferOutSize is NULL.
66 BufferOut is NULL if *BufferOutSize is not zero.
67 @retval EFI_BUFFER_TOO_SMALL BufferOutSize is too small to hold the response packet.
68 @retval EFI_ABORTED Something wrong during handshake.
75 IN UINT8
*BufferIn
, OPTIONAL
76 IN UINTN BufferInSize
, OPTIONAL
77 OUT UINT8
*BufferOut
, OPTIONAL
78 IN OUT UINTN
*BufferOutSize
81 TLS_CONNECTION
*TlsConn
;
82 UINTN PendingBufferSize
;
86 TlsConn
= (TLS_CONNECTION
*) Tls
;
87 PendingBufferSize
= 0;
90 if (TlsConn
== NULL
|| \
91 TlsConn
->Ssl
== NULL
|| TlsConn
->InBio
== NULL
|| TlsConn
->OutBio
== NULL
|| \
92 BufferOutSize
== NULL
|| \
93 (BufferIn
== NULL
&& BufferInSize
!= 0) || \
94 (BufferIn
!= NULL
&& BufferInSize
== 0) || \
95 (BufferOut
== NULL
&& *BufferOutSize
!= 0)) {
96 return EFI_INVALID_PARAMETER
;
99 if(BufferIn
== NULL
&& BufferInSize
== 0) {
101 // If RequestBuffer is NULL and RequestSize is 0, and TLS session
102 // status is EfiTlsSessionNotStarted, the TLS session will be initiated
103 // and the response packet needs to be ClientHello.
105 PendingBufferSize
= (UINTN
) BIO_ctrl_pending (TlsConn
->OutBio
);
106 if (PendingBufferSize
== 0) {
107 SSL_set_connect_state (TlsConn
->Ssl
);
108 Ret
= SSL_do_handshake (TlsConn
->Ssl
);
109 PendingBufferSize
= (UINTN
) BIO_ctrl_pending (TlsConn
->OutBio
);
112 PendingBufferSize
= (UINTN
) BIO_ctrl_pending (TlsConn
->OutBio
);
113 if (PendingBufferSize
== 0) {
114 BIO_write (TlsConn
->InBio
, BufferIn
, (UINT32
) BufferInSize
);
115 Ret
= SSL_do_handshake (TlsConn
->Ssl
);
116 PendingBufferSize
= (UINTN
) BIO_ctrl_pending (TlsConn
->OutBio
);
121 Ret
= SSL_get_error (TlsConn
->Ssl
, (int) Ret
);
122 if (Ret
== SSL_ERROR_SSL
||
123 Ret
== SSL_ERROR_SYSCALL
||
124 Ret
== SSL_ERROR_ZERO_RETURN
) {
127 "%a SSL_HANDSHAKE_ERROR State=0x%x SSL_ERROR_%a\n",
129 SSL_get_state (TlsConn
->Ssl
),
130 Ret
== SSL_ERROR_SSL
? "SSL" : Ret
== SSL_ERROR_SYSCALL
? "SYSCALL" : "ZERO_RETURN"
134 ErrorCode
= ERR_get_error ();
135 if (ErrorCode
== 0) {
140 "%a ERROR 0x%x=L%x:F%x:R%x\n",
143 ERR_GET_LIB (ErrorCode
),
144 ERR_GET_FUNC (ErrorCode
),
145 ERR_GET_REASON (ErrorCode
)
153 if (PendingBufferSize
> *BufferOutSize
) {
154 *BufferOutSize
= PendingBufferSize
;
155 return EFI_BUFFER_TOO_SMALL
;
158 if (PendingBufferSize
> 0) {
159 *BufferOutSize
= BIO_read (TlsConn
->OutBio
, BufferOut
, (UINT32
) PendingBufferSize
);
168 Handle Alert message recorded in BufferIn. If BufferIn is NULL and BufferInSize is zero,
169 TLS session has errors and the response packet needs to be Alert message based on error type.
171 @param[in] Tls Pointer to the TLS object for state checking.
172 @param[in] BufferIn Pointer to the most recently received TLS Alert packet.
173 @param[in] BufferInSize Packet size in bytes for the most recently received TLS
175 @param[out] BufferOut Pointer to the buffer to hold the built packet.
176 @param[in, out] BufferOutSize Pointer to the buffer size in bytes. On input, it is
177 the buffer size provided by the caller. On output, it
178 is the buffer size in fact needed to contain the
181 @retval EFI_SUCCESS The required TLS packet is built successfully.
182 @retval EFI_INVALID_PARAMETER One or more of the following conditions is TRUE:
184 BufferIn is NULL but BufferInSize is NOT 0.
185 BufferInSize is 0 but BufferIn is NOT NULL.
186 BufferOutSize is NULL.
187 BufferOut is NULL if *BufferOutSize is not zero.
188 @retval EFI_ABORTED An error occurred.
189 @retval EFI_BUFFER_TOO_SMALL BufferOutSize is too small to hold the response packet.
196 IN UINT8
*BufferIn
, OPTIONAL
197 IN UINTN BufferInSize
, OPTIONAL
198 OUT UINT8
*BufferOut
, OPTIONAL
199 IN OUT UINTN
*BufferOutSize
202 TLS_CONNECTION
*TlsConn
;
203 UINTN PendingBufferSize
;
207 TlsConn
= (TLS_CONNECTION
*) Tls
;
208 PendingBufferSize
= 0;
212 if (TlsConn
== NULL
|| \
213 TlsConn
->Ssl
== NULL
|| TlsConn
->InBio
== NULL
|| TlsConn
->OutBio
== NULL
|| \
214 BufferOutSize
== NULL
|| \
215 (BufferIn
== NULL
&& BufferInSize
!= 0) || \
216 (BufferIn
!= NULL
&& BufferInSize
== 0) || \
217 (BufferOut
== NULL
&& *BufferOutSize
!= 0)) {
218 return EFI_INVALID_PARAMETER
;
221 PendingBufferSize
= (UINTN
) BIO_ctrl_pending (TlsConn
->OutBio
);
222 if (PendingBufferSize
== 0 && BufferIn
!= NULL
&& BufferInSize
!= 0) {
223 Ret
= BIO_write (TlsConn
->InBio
, BufferIn
, (UINT32
) BufferInSize
);
224 if (Ret
!= (INTN
) BufferInSize
) {
228 TempBuffer
= (UINT8
*) OPENSSL_malloc (MAX_BUFFER_SIZE
);
231 // ssl3_send_alert() will be called in ssl3_read_bytes() function.
232 // TempBuffer is invalid since it's a Alert message, so just ignore it.
234 SSL_read (TlsConn
->Ssl
, TempBuffer
, MAX_BUFFER_SIZE
);
236 OPENSSL_free (TempBuffer
);
238 PendingBufferSize
= (UINTN
) BIO_ctrl_pending (TlsConn
->OutBio
);
241 if (PendingBufferSize
> *BufferOutSize
) {
242 *BufferOutSize
= PendingBufferSize
;
243 return EFI_BUFFER_TOO_SMALL
;
246 if (PendingBufferSize
> 0) {
247 *BufferOutSize
= BIO_read (TlsConn
->OutBio
, BufferOut
, (UINT32
) PendingBufferSize
);
256 Build the CloseNotify packet.
258 @param[in] Tls Pointer to the TLS object for state checking.
259 @param[in, out] Buffer Pointer to the buffer to hold the built packet.
260 @param[in, out] BufferSize Pointer to the buffer size in bytes. On input, it is
261 the buffer size provided by the caller. On output, it
262 is the buffer size in fact needed to contain the
265 @retval EFI_SUCCESS The required TLS packet is built successfully.
266 @retval EFI_INVALID_PARAMETER One or more of the following conditions is TRUE:
269 Buffer is NULL if *BufferSize is not zero.
270 @retval EFI_BUFFER_TOO_SMALL BufferSize is too small to hold the response packet.
277 IN OUT UINT8
*Buffer
,
278 IN OUT UINTN
*BufferSize
281 TLS_CONNECTION
*TlsConn
;
282 UINTN PendingBufferSize
;
284 TlsConn
= (TLS_CONNECTION
*) Tls
;
285 PendingBufferSize
= 0;
287 if (TlsConn
== NULL
|| \
288 TlsConn
->Ssl
== NULL
|| TlsConn
->InBio
== NULL
|| TlsConn
->OutBio
== NULL
|| \
289 BufferSize
== NULL
|| \
290 (Buffer
== NULL
&& *BufferSize
!= 0)) {
291 return EFI_INVALID_PARAMETER
;
294 PendingBufferSize
= (UINTN
) BIO_ctrl_pending (TlsConn
->OutBio
);
295 if (PendingBufferSize
== 0) {
297 // ssl3_send_alert() and ssl3_dispatch_alert() function will be called.
299 SSL_shutdown (TlsConn
->Ssl
);
300 PendingBufferSize
= (UINTN
) BIO_ctrl_pending (TlsConn
->OutBio
);
303 if (PendingBufferSize
> *BufferSize
) {
304 *BufferSize
= PendingBufferSize
;
305 return EFI_BUFFER_TOO_SMALL
;
308 if (PendingBufferSize
> 0) {
309 *BufferSize
= BIO_read (TlsConn
->OutBio
, Buffer
, (UINT32
) PendingBufferSize
);
318 Attempts to read bytes from one TLS object and places the data in Buffer.
320 This function will attempt to read BufferSize bytes from the TLS object
321 and places the data in Buffer.
323 @param[in] Tls Pointer to the TLS object.
324 @param[in,out] Buffer Pointer to the buffer to store the data.
325 @param[in] BufferSize The size of Buffer in bytes.
327 @retval >0 The amount of data successfully read from the TLS object.
328 @retval <=0 No data was successfully read.
339 TLS_CONNECTION
*TlsConn
;
341 TlsConn
= (TLS_CONNECTION
*) Tls
;
342 if (TlsConn
== NULL
|| TlsConn
->OutBio
== 0) {
347 // Read and return the amount of data from the BIO.
349 return BIO_read (TlsConn
->OutBio
, Buffer
, (UINT32
) BufferSize
);
353 Attempts to write data from the buffer to TLS object.
355 This function will attempt to write BufferSize bytes data from the Buffer
358 @param[in] Tls Pointer to the TLS object.
359 @param[in] Buffer Pointer to the data buffer.
360 @param[in] BufferSize The size of Buffer in bytes.
362 @retval >0 The amount of data successfully written to the TLS object.
363 @retval <=0 No data was successfully written.
374 TLS_CONNECTION
*TlsConn
;
376 TlsConn
= (TLS_CONNECTION
*) Tls
;
377 if (TlsConn
== NULL
|| TlsConn
->InBio
== 0) {
382 // Write and return the amount of data to the BIO.
384 return BIO_write (TlsConn
->InBio
, Buffer
, (UINT32
) BufferSize
);
387 Attempts to read bytes from the specified TLS connection into the buffer.
389 This function tries to read BufferSize bytes data from the specified TLS
390 connection into the Buffer.
392 @param[in] Tls Pointer to the TLS connection for data reading.
393 @param[in,out] Buffer Pointer to the data buffer.
394 @param[in] BufferSize The size of Buffer in bytes.
396 @retval >0 The read operation was successful, and return value is the
397 number of bytes actually read from the TLS connection.
398 @retval <=0 The read operation was not successful.
409 TLS_CONNECTION
*TlsConn
;
411 TlsConn
= (TLS_CONNECTION
*) Tls
;
412 if (TlsConn
== NULL
|| TlsConn
->Ssl
== NULL
) {
417 // Read bytes from the specified TLS connection.
419 return SSL_read (TlsConn
->Ssl
, Buffer
, (UINT32
) BufferSize
);
423 Attempts to write data to a TLS connection.
425 This function tries to write BufferSize bytes data from the Buffer into the
426 specified TLS connection.
428 @param[in] Tls Pointer to the TLS connection for data writing.
429 @param[in] Buffer Pointer to the data buffer.
430 @param[in] BufferSize The size of Buffer in bytes.
432 @retval >0 The write operation was successful, and return value is the
433 number of bytes actually written to the TLS connection.
434 @retval <=0 The write operation was not successful.
445 TLS_CONNECTION
*TlsConn
;
447 TlsConn
= (TLS_CONNECTION
*) Tls
;
448 if (TlsConn
== NULL
|| TlsConn
->Ssl
== NULL
) {
453 // Write bytes to the specified TLS connection.
455 return SSL_write (TlsConn
->Ssl
, Buffer
, (UINT32
) BufferSize
);