]> git.proxmox.com Git - mirror_edk2.git/blame - MdePkg/Include/IndustryStandard/Tls1.h
UefiCpuPkg: Move AsmRelocateApLoopStart from Mpfuncs.nasm to AmdSev.nasm
[mirror_edk2.git] / MdePkg / Include / IndustryStandard / Tls1.h
CommitLineData
973f8862
HW
1/** @file\r
2 Transport Layer Security -- TLS 1.0/1.1/1.2 Standard definitions, from RFC 2246/4346/5246\r
3\r
4 This file contains common TLS 1.0/1.1/1.2 definitions from RFC 2246/4346/5246\r
5\r
0469ed69 6 Copyright (c) 2016 - 2018, Intel Corporation. All rights reserved.<BR>\r
9344f092 7 SPDX-License-Identifier: BSD-2-Clause-Patent\r
973f8862
HW
8**/\r
9\r
10#ifndef __TLS_1_H__\r
11#define __TLS_1_H__\r
12\r
13#pragma pack(1)\r
14\r
15///\r
cafc573a 16/// TLS Cipher Suite, refers to A.5 of rfc-2246, rfc-4346, rfc-5246, rfc-5288 and rfc-5289.\r
973f8862 17///\r
cafc573a
YL
18#define TLS_RSA_WITH_NULL_MD5 {0x00, 0x01}\r
19#define TLS_RSA_WITH_NULL_SHA {0x00, 0x02}\r
20#define TLS_RSA_WITH_RC4_128_MD5 {0x00, 0x04}\r
21#define TLS_RSA_WITH_RC4_128_SHA {0x00, 0x05}\r
22#define TLS_RSA_WITH_IDEA_CBC_SHA {0x00, 0x07}\r
23#define TLS_RSA_WITH_DES_CBC_SHA {0x00, 0x09}\r
24#define TLS_RSA_WITH_3DES_EDE_CBC_SHA {0x00, 0x0A}\r
25#define TLS_DH_DSS_WITH_DES_CBC_SHA {0x00, 0x0C}\r
26#define TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA {0x00, 0x0D}\r
27#define TLS_DH_RSA_WITH_DES_CBC_SHA {0x00, 0x0F}\r
28#define TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA {0x00, 0x10}\r
29#define TLS_DHE_DSS_WITH_DES_CBC_SHA {0x00, 0x12}\r
30#define TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA {0x00, 0x13}\r
31#define TLS_DHE_RSA_WITH_DES_CBC_SHA {0x00, 0x15}\r
32#define TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA {0x00, 0x16}\r
33#define TLS_RSA_WITH_AES_128_CBC_SHA {0x00, 0x2F}\r
34#define TLS_DH_DSS_WITH_AES_128_CBC_SHA {0x00, 0x30}\r
35#define TLS_DH_RSA_WITH_AES_128_CBC_SHA {0x00, 0x31}\r
36#define TLS_DHE_DSS_WITH_AES_128_CBC_SHA {0x00, 0x32}\r
37#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA {0x00, 0x33}\r
38#define TLS_RSA_WITH_AES_256_CBC_SHA {0x00, 0x35}\r
39#define TLS_DH_DSS_WITH_AES_256_CBC_SHA {0x00, 0x36}\r
40#define TLS_DH_RSA_WITH_AES_256_CBC_SHA {0x00, 0x37}\r
41#define TLS_DHE_DSS_WITH_AES_256_CBC_SHA {0x00, 0x38}\r
42#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA {0x00, 0x39}\r
43#define TLS_RSA_WITH_NULL_SHA256 {0x00, 0x3B}\r
44#define TLS_RSA_WITH_AES_128_CBC_SHA256 {0x00, 0x3C}\r
45#define TLS_RSA_WITH_AES_256_CBC_SHA256 {0x00, 0x3D}\r
46#define TLS_DH_DSS_WITH_AES_128_CBC_SHA256 {0x00, 0x3E}\r
47#define TLS_DH_RSA_WITH_AES_128_CBC_SHA256 {0x00, 0x3F}\r
48#define TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 {0x00, 0x40}\r
49#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 {0x00, 0x67}\r
50#define TLS_DH_DSS_WITH_AES_256_CBC_SHA256 {0x00, 0x68}\r
51#define TLS_DH_RSA_WITH_AES_256_CBC_SHA256 {0x00, 0x69}\r
52#define TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 {0x00, 0x6A}\r
53#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 {0x00, 0x6B}\r
54#define TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 {0x00, 0x9F}\r
55#define TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 {0xC0, 0x2B}\r
56#define TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 {0xC0, 0x2C}\r
57#define TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 {0xC0, 0x30}\r
973f8862
HW
58\r
59///\r
60/// TLS Version, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.\r
61///\r
62#define TLS10_PROTOCOL_VERSION_MAJOR 0x03\r
63#define TLS10_PROTOCOL_VERSION_MINOR 0x01\r
64#define TLS11_PROTOCOL_VERSION_MAJOR 0x03\r
65#define TLS11_PROTOCOL_VERSION_MINOR 0x02\r
66#define TLS12_PROTOCOL_VERSION_MAJOR 0x03\r
67#define TLS12_PROTOCOL_VERSION_MINOR 0x03\r
68\r
69///\r
70/// TLS Content Type, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.\r
71///\r
72typedef enum {\r
73 TlsContentTypeChangeCipherSpec = 20,\r
74 TlsContentTypeAlert = 21,\r
75 TlsContentTypeHandshake = 22,\r
76 TlsContentTypeApplicationData = 23,\r
77} TLS_CONTENT_TYPE;\r
78\r
79///\r
80/// TLS Record Header, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.\r
81///\r
82typedef struct {\r
2f88bd3a
MK
83 UINT8 ContentType;\r
84 EFI_TLS_VERSION Version;\r
85 UINT16 Length;\r
973f8862
HW
86} TLS_RECORD_HEADER;\r
87\r
2f88bd3a 88#define TLS_RECORD_HEADER_LENGTH 5\r
0469ed69
JW
89\r
90//\r
91// The length (in bytes) of the TLSPlaintext records payload MUST NOT exceed 2^14.\r
9095d37b 92// Refers to section 6.2 of RFC5246.\r
0469ed69 93//\r
2f88bd3a 94#define TLS_PLAINTEXT_RECORD_MAX_PAYLOAD_LENGTH 16384\r
0469ed69
JW
95\r
96//\r
97// The length (in bytes) of the TLSCiphertext records payload MUST NOT exceed 2^14 + 2048.\r
9095d37b 98// Refers to section 6.2 of RFC5246.\r
0469ed69 99//\r
2f88bd3a 100#define TLS_CIPHERTEXT_RECORD_MAX_PAYLOAD_LENGTH 18432\r
0469ed69 101\r
cafc573a
YL
102///\r
103/// TLS Hash algorithm, refers to section 7.4.1.4.1. of rfc-5246.\r
104///\r
105typedef enum {\r
106 TlsHashAlgoNone = 0,\r
107 TlsHashAlgoMd5 = 1,\r
108 TlsHashAlgoSha1 = 2,\r
109 TlsHashAlgoSha224 = 3,\r
110 TlsHashAlgoSha256 = 4,\r
111 TlsHashAlgoSha384 = 5,\r
112 TlsHashAlgoSha512 = 6,\r
113} TLS_HASH_ALGO;\r
114\r
115///\r
116/// TLS Signature algorithm, refers to section 7.4.1.4.1. of rfc-5246.\r
117///\r
118typedef enum {\r
119 TlsSignatureAlgoAnonymous = 0,\r
120 TlsSignatureAlgoRsa = 1,\r
121 TlsSignatureAlgoDsa = 2,\r
122 TlsSignatureAlgoEcdsa = 3,\r
123} TLS_SIGNATURE_ALGO;\r
124\r
125///\r
126/// TLS Supported Elliptic Curves Extensions, refers to section 5.1.1 of rfc-8422.\r
127///\r
128typedef enum {\r
129 TlsEcNamedCurveSecp256r1 = 23,\r
130 TlsEcNamedCurveSecp384r1 = 24,\r
131 TlsEcNamedCurveSecp521r1 = 25,\r
132 TlsEcNamedCurveX25519 = 29,\r
133 TlsEcNamedCurveX448 = 30,\r
134} TLS_EC_NAMED_CURVE;\r
135\r
973f8862
HW
136#pragma pack()\r
137\r
138#endif\r