]> git.proxmox.com Git - mirror_edk2.git/blob - MdePkg/Include/IndustryStandard/Tls1.h
MdePkg: Add Tls configuration related define
[mirror_edk2.git] / MdePkg / Include / IndustryStandard / Tls1.h
1 /** @file
2 Transport Layer Security -- TLS 1.0/1.1/1.2 Standard definitions, from RFC 2246/4346/5246
3
4 This file contains common TLS 1.0/1.1/1.2 definitions from RFC 2246/4346/5246
5
6 Copyright (c) 2016 - 2018, Intel Corporation. All rights reserved.<BR>
7 SPDX-License-Identifier: BSD-2-Clause-Patent
8 **/
9
10 #ifndef __TLS_1_H__
11 #define __TLS_1_H__
12
13 #pragma pack(1)
14
15 ///
16 /// TLS Cipher Suite, refers to A.5 of rfc-2246, rfc-4346, rfc-5246, rfc-5288 and rfc-5289.
17 ///
18 #define TLS_RSA_WITH_NULL_MD5 {0x00, 0x01}
19 #define TLS_RSA_WITH_NULL_SHA {0x00, 0x02}
20 #define TLS_RSA_WITH_RC4_128_MD5 {0x00, 0x04}
21 #define TLS_RSA_WITH_RC4_128_SHA {0x00, 0x05}
22 #define TLS_RSA_WITH_IDEA_CBC_SHA {0x00, 0x07}
23 #define TLS_RSA_WITH_DES_CBC_SHA {0x00, 0x09}
24 #define TLS_RSA_WITH_3DES_EDE_CBC_SHA {0x00, 0x0A}
25 #define TLS_DH_DSS_WITH_DES_CBC_SHA {0x00, 0x0C}
26 #define TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA {0x00, 0x0D}
27 #define TLS_DH_RSA_WITH_DES_CBC_SHA {0x00, 0x0F}
28 #define TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA {0x00, 0x10}
29 #define TLS_DHE_DSS_WITH_DES_CBC_SHA {0x00, 0x12}
30 #define TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA {0x00, 0x13}
31 #define TLS_DHE_RSA_WITH_DES_CBC_SHA {0x00, 0x15}
32 #define TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA {0x00, 0x16}
33 #define TLS_RSA_WITH_AES_128_CBC_SHA {0x00, 0x2F}
34 #define TLS_DH_DSS_WITH_AES_128_CBC_SHA {0x00, 0x30}
35 #define TLS_DH_RSA_WITH_AES_128_CBC_SHA {0x00, 0x31}
36 #define TLS_DHE_DSS_WITH_AES_128_CBC_SHA {0x00, 0x32}
37 #define TLS_DHE_RSA_WITH_AES_128_CBC_SHA {0x00, 0x33}
38 #define TLS_RSA_WITH_AES_256_CBC_SHA {0x00, 0x35}
39 #define TLS_DH_DSS_WITH_AES_256_CBC_SHA {0x00, 0x36}
40 #define TLS_DH_RSA_WITH_AES_256_CBC_SHA {0x00, 0x37}
41 #define TLS_DHE_DSS_WITH_AES_256_CBC_SHA {0x00, 0x38}
42 #define TLS_DHE_RSA_WITH_AES_256_CBC_SHA {0x00, 0x39}
43 #define TLS_RSA_WITH_NULL_SHA256 {0x00, 0x3B}
44 #define TLS_RSA_WITH_AES_128_CBC_SHA256 {0x00, 0x3C}
45 #define TLS_RSA_WITH_AES_256_CBC_SHA256 {0x00, 0x3D}
46 #define TLS_DH_DSS_WITH_AES_128_CBC_SHA256 {0x00, 0x3E}
47 #define TLS_DH_RSA_WITH_AES_128_CBC_SHA256 {0x00, 0x3F}
48 #define TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 {0x00, 0x40}
49 #define TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 {0x00, 0x67}
50 #define TLS_DH_DSS_WITH_AES_256_CBC_SHA256 {0x00, 0x68}
51 #define TLS_DH_RSA_WITH_AES_256_CBC_SHA256 {0x00, 0x69}
52 #define TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 {0x00, 0x6A}
53 #define TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 {0x00, 0x6B}
54 #define TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 {0x00, 0x9F}
55 #define TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 {0xC0, 0x2B}
56 #define TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 {0xC0, 0x2C}
57 #define TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 {0xC0, 0x30}
58
59 ///
60 /// TLS Version, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.
61 ///
62 #define TLS10_PROTOCOL_VERSION_MAJOR 0x03
63 #define TLS10_PROTOCOL_VERSION_MINOR 0x01
64 #define TLS11_PROTOCOL_VERSION_MAJOR 0x03
65 #define TLS11_PROTOCOL_VERSION_MINOR 0x02
66 #define TLS12_PROTOCOL_VERSION_MAJOR 0x03
67 #define TLS12_PROTOCOL_VERSION_MINOR 0x03
68
69 ///
70 /// TLS Content Type, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.
71 ///
72 typedef enum {
73 TlsContentTypeChangeCipherSpec = 20,
74 TlsContentTypeAlert = 21,
75 TlsContentTypeHandshake = 22,
76 TlsContentTypeApplicationData = 23,
77 } TLS_CONTENT_TYPE;
78
79 ///
80 /// TLS Record Header, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.
81 ///
82 typedef struct {
83 UINT8 ContentType;
84 EFI_TLS_VERSION Version;
85 UINT16 Length;
86 } TLS_RECORD_HEADER;
87
88 #define TLS_RECORD_HEADER_LENGTH 5
89
90 //
91 // The length (in bytes) of the TLSPlaintext records payload MUST NOT exceed 2^14.
92 // Refers to section 6.2 of RFC5246.
93 //
94 #define TLS_PLAINTEXT_RECORD_MAX_PAYLOAD_LENGTH 16384
95
96 //
97 // The length (in bytes) of the TLSCiphertext records payload MUST NOT exceed 2^14 + 2048.
98 // Refers to section 6.2 of RFC5246.
99 //
100 #define TLS_CIPHERTEXT_RECORD_MAX_PAYLOAD_LENGTH 18432
101
102 ///
103 /// TLS Hash algorithm, refers to section 7.4.1.4.1. of rfc-5246.
104 ///
105 typedef enum {
106 TlsHashAlgoNone = 0,
107 TlsHashAlgoMd5 = 1,
108 TlsHashAlgoSha1 = 2,
109 TlsHashAlgoSha224 = 3,
110 TlsHashAlgoSha256 = 4,
111 TlsHashAlgoSha384 = 5,
112 TlsHashAlgoSha512 = 6,
113 } TLS_HASH_ALGO;
114
115 ///
116 /// TLS Signature algorithm, refers to section 7.4.1.4.1. of rfc-5246.
117 ///
118 typedef enum {
119 TlsSignatureAlgoAnonymous = 0,
120 TlsSignatureAlgoRsa = 1,
121 TlsSignatureAlgoDsa = 2,
122 TlsSignatureAlgoEcdsa = 3,
123 } TLS_SIGNATURE_ALGO;
124
125 ///
126 /// TLS Supported Elliptic Curves Extensions, refers to section 5.1.1 of rfc-8422.
127 ///
128 typedef enum {
129 TlsEcNamedCurveSecp256r1 = 23,
130 TlsEcNamedCurveSecp384r1 = 24,
131 TlsEcNamedCurveSecp521r1 = 25,
132 TlsEcNamedCurveX25519 = 29,
133 TlsEcNamedCurveX448 = 30,
134 } TLS_EC_NAMED_CURVE;
135
136 #pragma pack()
137
138 #endif