xref: /curl/lib/vtls/cipher_suite.c (revision 6e4b7abf)
1 /***************************************************************************
2  *                                  _   _ ____  _
3  *  Project                     ___| | | |  _ \| |
4  *                             / __| | | | |_) | |
5  *                            | (__| |_| |  _ <| |___
6  *                             \___|\___/|_| \_\_____|
7  *
8  * Copyright (C) Jan Venekamp, <jan@venekamp.net>
9  *
10  * This software is licensed as described in the file COPYING, which
11  * you should have received as part of this distribution. The terms
12  * are also available at https://curl.se/docs/copyright.html.
13  *
14  * You may opt to use, copy, modify, merge, publish, distribute and/or sell
15  * copies of the Software, and permit persons to whom the Software is
16  * furnished to do so, under the terms of the COPYING file.
17  *
18  * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
19  * KIND, either express or implied.
20  *
21  * SPDX-License-Identifier: curl
22  *
23  ***************************************************************************/
24 #include "curl_setup.h"
25 
26 #if defined(USE_MBEDTLS) || defined(USE_BEARSSL)
27 #include "cipher_suite.h"
28 #include "curl_printf.h"
29 #include "strcase.h"
30 #include <string.h>
31 
32 /*
33  * To support the CURLOPT_SSL_CIPHER_LIST option on SSL backends
34  * that do not support it natively, but do support setting a list of
35  * IANA ids, we need a list of all supported cipher suite names
36  * (openssl and IANA) to be able to look up the IANA ids.
37  *
38  * To keep the binary size of this list down we compress each entry
39  * down to 2 + 6 bytes using the C preprocessor.
40  */
41 
42 /*
43  * mbedTLS NOTE: mbedTLS has mbedtls_ssl_get_ciphersuite_id() to
44  * convert a string representation to an IANA id, we do not use that
45  * because it does not support "standard" openssl cipher suite
46  * names, nor IANA names.
47  */
48 
49 /* NOTE: also see tests/unit/unit3205.c */
50 
51 /* Text for cipher suite parts (max 64 entries),
52    keep indexes below in sync with this! */
53 static const char *cs_txt =
54   "\0"
55   "TLS" "\0"
56   "WITH" "\0"
57   "128" "\0"
58   "256" "\0"
59   "3DES" "\0"
60   "8" "\0"
61   "AES" "\0"
62   "AES128" "\0"
63   "AES256" "\0"
64   "CBC" "\0"
65   "CBC3" "\0"
66   "CCM" "\0"
67   "CCM8" "\0"
68   "CHACHA20" "\0"
69   "DES" "\0"
70   "DHE" "\0"
71   "ECDH" "\0"
72   "ECDHE" "\0"
73   "ECDSA" "\0"
74   "EDE" "\0"
75   "GCM" "\0"
76   "MD5" "\0"
77   "NULL" "\0"
78   "POLY1305" "\0"
79   "PSK" "\0"
80   "RSA" "\0"
81   "SHA" "\0"
82   "SHA256" "\0"
83   "SHA384" "\0"
84 #if defined(USE_MBEDTLS)
85   "ARIA" "\0"
86   "ARIA128" "\0"
87   "ARIA256" "\0"
88   "CAMELLIA" "\0"
89   "CAMELLIA128" "\0"
90   "CAMELLIA256" "\0"
91 #endif
92 ;
93 /* Indexes of above cs_txt */
94 enum {
95   CS_TXT_IDX_,
96   CS_TXT_IDX_TLS,
97   CS_TXT_IDX_WITH,
98   CS_TXT_IDX_128,
99   CS_TXT_IDX_256,
100   CS_TXT_IDX_3DES,
101   CS_TXT_IDX_8,
102   CS_TXT_IDX_AES,
103   CS_TXT_IDX_AES128,
104   CS_TXT_IDX_AES256,
105   CS_TXT_IDX_CBC,
106   CS_TXT_IDX_CBC3,
107   CS_TXT_IDX_CCM,
108   CS_TXT_IDX_CCM8,
109   CS_TXT_IDX_CHACHA20,
110   CS_TXT_IDX_DES,
111   CS_TXT_IDX_DHE,
112   CS_TXT_IDX_ECDH,
113   CS_TXT_IDX_ECDHE,
114   CS_TXT_IDX_ECDSA,
115   CS_TXT_IDX_EDE,
116   CS_TXT_IDX_GCM,
117   CS_TXT_IDX_MD5,
118   CS_TXT_IDX_NULL,
119   CS_TXT_IDX_POLY1305,
120   CS_TXT_IDX_PSK,
121   CS_TXT_IDX_RSA,
122   CS_TXT_IDX_SHA,
123   CS_TXT_IDX_SHA256,
124   CS_TXT_IDX_SHA384,
125 #if defined(USE_MBEDTLS)
126   CS_TXT_IDX_ARIA,
127   CS_TXT_IDX_ARIA128,
128   CS_TXT_IDX_ARIA256,
129   CS_TXT_IDX_CAMELLIA,
130   CS_TXT_IDX_CAMELLIA128,
131   CS_TXT_IDX_CAMELLIA256,
132 #endif
133   CS_TXT_LEN,
134 };
135 
136 #define CS_ZIP_IDX(a, b, c, d, e, f, g, h)    \
137 {                                             \
138   (uint8_t) ((a) << 2 | ((b) & 0x3F) >> 4),   \
139   (uint8_t) ((b) << 4 | ((c) & 0x3F) >> 2),   \
140   (uint8_t) ((c) << 6 | ((d) & 0x3F)),        \
141   (uint8_t) ((e) << 2 | ((f) & 0x3F) >> 4),   \
142   (uint8_t) ((f) << 4 | ((g) & 0x3F) >> 2),   \
143   (uint8_t) ((g) << 6 | ((h) & 0x3F))         \
144 }
145 #define CS_ENTRY(id, a, b, c, d, e, f, g, h)  \
146 {                                             \
147   id,                                         \
148   CS_ZIP_IDX(                                 \
149     CS_TXT_IDX_ ## a, CS_TXT_IDX_ ## b,       \
150     CS_TXT_IDX_ ## c, CS_TXT_IDX_ ## d,       \
151     CS_TXT_IDX_ ## e, CS_TXT_IDX_ ## f,       \
152     CS_TXT_IDX_ ## g, CS_TXT_IDX_ ## h        \
153   )                                           \
154 }
155 
156 struct cs_entry {
157   uint16_t id;
158   uint8_t zip[6];
159 };
160 
161 /* !checksrc! disable COMMANOSPACE all */
162 static const struct cs_entry cs_list [] = {
163   CS_ENTRY(0x002F, TLS,RSA,WITH,AES,128,CBC,SHA,),
164   CS_ENTRY(0x002F, AES128,SHA,,,,,,),
165   CS_ENTRY(0x0035, TLS,RSA,WITH,AES,256,CBC,SHA,),
166   CS_ENTRY(0x0035, AES256,SHA,,,,,,),
167   CS_ENTRY(0x003C, TLS,RSA,WITH,AES,128,CBC,SHA256,),
168   CS_ENTRY(0x003C, AES128,SHA256,,,,,,),
169   CS_ENTRY(0x003D, TLS,RSA,WITH,AES,256,CBC,SHA256,),
170   CS_ENTRY(0x003D, AES256,SHA256,,,,,,),
171   CS_ENTRY(0x009C, TLS,RSA,WITH,AES,128,GCM,SHA256,),
172   CS_ENTRY(0x009C, AES128,GCM,SHA256,,,,,),
173   CS_ENTRY(0x009D, TLS,RSA,WITH,AES,256,GCM,SHA384,),
174   CS_ENTRY(0x009D, AES256,GCM,SHA384,,,,,),
175   CS_ENTRY(0xC004, TLS,ECDH,ECDSA,WITH,AES,128,CBC,SHA),
176   CS_ENTRY(0xC004, ECDH,ECDSA,AES128,SHA,,,,),
177   CS_ENTRY(0xC005, TLS,ECDH,ECDSA,WITH,AES,256,CBC,SHA),
178   CS_ENTRY(0xC005, ECDH,ECDSA,AES256,SHA,,,,),
179   CS_ENTRY(0xC009, TLS,ECDHE,ECDSA,WITH,AES,128,CBC,SHA),
180   CS_ENTRY(0xC009, ECDHE,ECDSA,AES128,SHA,,,,),
181   CS_ENTRY(0xC00A, TLS,ECDHE,ECDSA,WITH,AES,256,CBC,SHA),
182   CS_ENTRY(0xC00A, ECDHE,ECDSA,AES256,SHA,,,,),
183   CS_ENTRY(0xC00E, TLS,ECDH,RSA,WITH,AES,128,CBC,SHA),
184   CS_ENTRY(0xC00E, ECDH,RSA,AES128,SHA,,,,),
185   CS_ENTRY(0xC00F, TLS,ECDH,RSA,WITH,AES,256,CBC,SHA),
186   CS_ENTRY(0xC00F, ECDH,RSA,AES256,SHA,,,,),
187   CS_ENTRY(0xC013, TLS,ECDHE,RSA,WITH,AES,128,CBC,SHA),
188   CS_ENTRY(0xC013, ECDHE,RSA,AES128,SHA,,,,),
189   CS_ENTRY(0xC014, TLS,ECDHE,RSA,WITH,AES,256,CBC,SHA),
190   CS_ENTRY(0xC014, ECDHE,RSA,AES256,SHA,,,,),
191   CS_ENTRY(0xC023, TLS,ECDHE,ECDSA,WITH,AES,128,CBC,SHA256),
192   CS_ENTRY(0xC023, ECDHE,ECDSA,AES128,SHA256,,,,),
193   CS_ENTRY(0xC024, TLS,ECDHE,ECDSA,WITH,AES,256,CBC,SHA384),
194   CS_ENTRY(0xC024, ECDHE,ECDSA,AES256,SHA384,,,,),
195   CS_ENTRY(0xC025, TLS,ECDH,ECDSA,WITH,AES,128,CBC,SHA256),
196   CS_ENTRY(0xC025, ECDH,ECDSA,AES128,SHA256,,,,),
197   CS_ENTRY(0xC026, TLS,ECDH,ECDSA,WITH,AES,256,CBC,SHA384),
198   CS_ENTRY(0xC026, ECDH,ECDSA,AES256,SHA384,,,,),
199   CS_ENTRY(0xC027, TLS,ECDHE,RSA,WITH,AES,128,CBC,SHA256),
200   CS_ENTRY(0xC027, ECDHE,RSA,AES128,SHA256,,,,),
201   CS_ENTRY(0xC028, TLS,ECDHE,RSA,WITH,AES,256,CBC,SHA384),
202   CS_ENTRY(0xC028, ECDHE,RSA,AES256,SHA384,,,,),
203   CS_ENTRY(0xC029, TLS,ECDH,RSA,WITH,AES,128,CBC,SHA256),
204   CS_ENTRY(0xC029, ECDH,RSA,AES128,SHA256,,,,),
205   CS_ENTRY(0xC02A, TLS,ECDH,RSA,WITH,AES,256,CBC,SHA384),
206   CS_ENTRY(0xC02A, ECDH,RSA,AES256,SHA384,,,,),
207   CS_ENTRY(0xC02B, TLS,ECDHE,ECDSA,WITH,AES,128,GCM,SHA256),
208   CS_ENTRY(0xC02B, ECDHE,ECDSA,AES128,GCM,SHA256,,,),
209   CS_ENTRY(0xC02C, TLS,ECDHE,ECDSA,WITH,AES,256,GCM,SHA384),
210   CS_ENTRY(0xC02C, ECDHE,ECDSA,AES256,GCM,SHA384,,,),
211   CS_ENTRY(0xC02D, TLS,ECDH,ECDSA,WITH,AES,128,GCM,SHA256),
212   CS_ENTRY(0xC02D, ECDH,ECDSA,AES128,GCM,SHA256,,,),
213   CS_ENTRY(0xC02E, TLS,ECDH,ECDSA,WITH,AES,256,GCM,SHA384),
214   CS_ENTRY(0xC02E, ECDH,ECDSA,AES256,GCM,SHA384,,,),
215   CS_ENTRY(0xC02F, TLS,ECDHE,RSA,WITH,AES,128,GCM,SHA256),
216   CS_ENTRY(0xC02F, ECDHE,RSA,AES128,GCM,SHA256,,,),
217   CS_ENTRY(0xC030, TLS,ECDHE,RSA,WITH,AES,256,GCM,SHA384),
218   CS_ENTRY(0xC030, ECDHE,RSA,AES256,GCM,SHA384,,,),
219   CS_ENTRY(0xC031, TLS,ECDH,RSA,WITH,AES,128,GCM,SHA256),
220   CS_ENTRY(0xC031, ECDH,RSA,AES128,GCM,SHA256,,,),
221   CS_ENTRY(0xC032, TLS,ECDH,RSA,WITH,AES,256,GCM,SHA384),
222   CS_ENTRY(0xC032, ECDH,RSA,AES256,GCM,SHA384,,,),
223   CS_ENTRY(0xCCA8, TLS,ECDHE,RSA,WITH,CHACHA20,POLY1305,SHA256,),
224   CS_ENTRY(0xCCA8, ECDHE,RSA,CHACHA20,POLY1305,,,,),
225   CS_ENTRY(0xCCA9, TLS,ECDHE,ECDSA,WITH,CHACHA20,POLY1305,SHA256,),
226   CS_ENTRY(0xCCA9, ECDHE,ECDSA,CHACHA20,POLY1305,,,,),
227 #if defined(USE_MBEDTLS)
228   CS_ENTRY(0x0001, TLS,RSA,WITH,NULL,MD5,,,),
229   CS_ENTRY(0x0001, NULL,MD5,,,,,,),
230   CS_ENTRY(0x0002, TLS,RSA,WITH,NULL,SHA,,,),
231   CS_ENTRY(0x0002, NULL,SHA,,,,,,),
232   CS_ENTRY(0x002C, TLS,PSK,WITH,NULL,SHA,,,),
233   CS_ENTRY(0x002C, PSK,NULL,SHA,,,,,),
234   CS_ENTRY(0x002D, TLS,DHE,PSK,WITH,NULL,SHA,,),
235   CS_ENTRY(0x002D, DHE,PSK,NULL,SHA,,,,),
236   CS_ENTRY(0x002E, TLS,RSA,PSK,WITH,NULL,SHA,,),
237   CS_ENTRY(0x002E, RSA,PSK,NULL,SHA,,,,),
238   CS_ENTRY(0x0033, TLS,DHE,RSA,WITH,AES,128,CBC,SHA),
239   CS_ENTRY(0x0033, DHE,RSA,AES128,SHA,,,,),
240   CS_ENTRY(0x0039, TLS,DHE,RSA,WITH,AES,256,CBC,SHA),
241   CS_ENTRY(0x0039, DHE,RSA,AES256,SHA,,,,),
242   CS_ENTRY(0x003B, TLS,RSA,WITH,NULL,SHA256,,,),
243   CS_ENTRY(0x003B, NULL,SHA256,,,,,,),
244   CS_ENTRY(0x0067, TLS,DHE,RSA,WITH,AES,128,CBC,SHA256),
245   CS_ENTRY(0x0067, DHE,RSA,AES128,SHA256,,,,),
246   CS_ENTRY(0x006B, TLS,DHE,RSA,WITH,AES,256,CBC,SHA256),
247   CS_ENTRY(0x006B, DHE,RSA,AES256,SHA256,,,,),
248   CS_ENTRY(0x008C, TLS,PSK,WITH,AES,128,CBC,SHA,),
249   CS_ENTRY(0x008C, PSK,AES128,CBC,SHA,,,,),
250   CS_ENTRY(0x008D, TLS,PSK,WITH,AES,256,CBC,SHA,),
251   CS_ENTRY(0x008D, PSK,AES256,CBC,SHA,,,,),
252   CS_ENTRY(0x0090, TLS,DHE,PSK,WITH,AES,128,CBC,SHA),
253   CS_ENTRY(0x0090, DHE,PSK,AES128,CBC,SHA,,,),
254   CS_ENTRY(0x0091, TLS,DHE,PSK,WITH,AES,256,CBC,SHA),
255   CS_ENTRY(0x0091, DHE,PSK,AES256,CBC,SHA,,,),
256   CS_ENTRY(0x0094, TLS,RSA,PSK,WITH,AES,128,CBC,SHA),
257   CS_ENTRY(0x0094, RSA,PSK,AES128,CBC,SHA,,,),
258   CS_ENTRY(0x0095, TLS,RSA,PSK,WITH,AES,256,CBC,SHA),
259   CS_ENTRY(0x0095, RSA,PSK,AES256,CBC,SHA,,,),
260   CS_ENTRY(0x009E, TLS,DHE,RSA,WITH,AES,128,GCM,SHA256),
261   CS_ENTRY(0x009E, DHE,RSA,AES128,GCM,SHA256,,,),
262   CS_ENTRY(0x009F, TLS,DHE,RSA,WITH,AES,256,GCM,SHA384),
263   CS_ENTRY(0x009F, DHE,RSA,AES256,GCM,SHA384,,,),
264   CS_ENTRY(0x00A8, TLS,PSK,WITH,AES,128,GCM,SHA256,),
265   CS_ENTRY(0x00A8, PSK,AES128,GCM,SHA256,,,,),
266   CS_ENTRY(0x00A9, TLS,PSK,WITH,AES,256,GCM,SHA384,),
267   CS_ENTRY(0x00A9, PSK,AES256,GCM,SHA384,,,,),
268   CS_ENTRY(0x00AA, TLS,DHE,PSK,WITH,AES,128,GCM,SHA256),
269   CS_ENTRY(0x00AA, DHE,PSK,AES128,GCM,SHA256,,,),
270   CS_ENTRY(0x00AB, TLS,DHE,PSK,WITH,AES,256,GCM,SHA384),
271   CS_ENTRY(0x00AB, DHE,PSK,AES256,GCM,SHA384,,,),
272   CS_ENTRY(0x00AC, TLS,RSA,PSK,WITH,AES,128,GCM,SHA256),
273   CS_ENTRY(0x00AC, RSA,PSK,AES128,GCM,SHA256,,,),
274   CS_ENTRY(0x00AD, TLS,RSA,PSK,WITH,AES,256,GCM,SHA384),
275   CS_ENTRY(0x00AD, RSA,PSK,AES256,GCM,SHA384,,,),
276   CS_ENTRY(0x00AE, TLS,PSK,WITH,AES,128,CBC,SHA256,),
277   CS_ENTRY(0x00AE, PSK,AES128,CBC,SHA256,,,,),
278   CS_ENTRY(0x00AF, TLS,PSK,WITH,AES,256,CBC,SHA384,),
279   CS_ENTRY(0x00AF, PSK,AES256,CBC,SHA384,,,,),
280   CS_ENTRY(0x00B0, TLS,PSK,WITH,NULL,SHA256,,,),
281   CS_ENTRY(0x00B0, PSK,NULL,SHA256,,,,,),
282   CS_ENTRY(0x00B1, TLS,PSK,WITH,NULL,SHA384,,,),
283   CS_ENTRY(0x00B1, PSK,NULL,SHA384,,,,,),
284   CS_ENTRY(0x00B2, TLS,DHE,PSK,WITH,AES,128,CBC,SHA256),
285   CS_ENTRY(0x00B2, DHE,PSK,AES128,CBC,SHA256,,,),
286   CS_ENTRY(0x00B3, TLS,DHE,PSK,WITH,AES,256,CBC,SHA384),
287   CS_ENTRY(0x00B3, DHE,PSK,AES256,CBC,SHA384,,,),
288   CS_ENTRY(0x00B4, TLS,DHE,PSK,WITH,NULL,SHA256,,),
289   CS_ENTRY(0x00B4, DHE,PSK,NULL,SHA256,,,,),
290   CS_ENTRY(0x00B5, TLS,DHE,PSK,WITH,NULL,SHA384,,),
291   CS_ENTRY(0x00B5, DHE,PSK,NULL,SHA384,,,,),
292   CS_ENTRY(0x00B6, TLS,RSA,PSK,WITH,AES,128,CBC,SHA256),
293   CS_ENTRY(0x00B6, RSA,PSK,AES128,CBC,SHA256,,,),
294   CS_ENTRY(0x00B7, TLS,RSA,PSK,WITH,AES,256,CBC,SHA384),
295   CS_ENTRY(0x00B7, RSA,PSK,AES256,CBC,SHA384,,,),
296   CS_ENTRY(0x00B8, TLS,RSA,PSK,WITH,NULL,SHA256,,),
297   CS_ENTRY(0x00B8, RSA,PSK,NULL,SHA256,,,,),
298   CS_ENTRY(0x00B9, TLS,RSA,PSK,WITH,NULL,SHA384,,),
299   CS_ENTRY(0x00B9, RSA,PSK,NULL,SHA384,,,,),
300   CS_ENTRY(0x1301, TLS,AES,128,GCM,SHA256,,,),
301   CS_ENTRY(0x1302, TLS,AES,256,GCM,SHA384,,,),
302   CS_ENTRY(0x1303, TLS,CHACHA20,POLY1305,SHA256,,,,),
303   CS_ENTRY(0x1304, TLS,AES,128,CCM,SHA256,,,),
304   CS_ENTRY(0x1305, TLS,AES,128,CCM,8,SHA256,,),
305   CS_ENTRY(0xC001, TLS,ECDH,ECDSA,WITH,NULL,SHA,,),
306   CS_ENTRY(0xC001, ECDH,ECDSA,NULL,SHA,,,,),
307   CS_ENTRY(0xC006, TLS,ECDHE,ECDSA,WITH,NULL,SHA,,),
308   CS_ENTRY(0xC006, ECDHE,ECDSA,NULL,SHA,,,,),
309   CS_ENTRY(0xC00B, TLS,ECDH,RSA,WITH,NULL,SHA,,),
310   CS_ENTRY(0xC00B, ECDH,RSA,NULL,SHA,,,,),
311   CS_ENTRY(0xC010, TLS,ECDHE,RSA,WITH,NULL,SHA,,),
312   CS_ENTRY(0xC010, ECDHE,RSA,NULL,SHA,,,,),
313   CS_ENTRY(0xC035, TLS,ECDHE,PSK,WITH,AES,128,CBC,SHA),
314   CS_ENTRY(0xC035, ECDHE,PSK,AES128,CBC,SHA,,,),
315   CS_ENTRY(0xC036, TLS,ECDHE,PSK,WITH,AES,256,CBC,SHA),
316   CS_ENTRY(0xC036, ECDHE,PSK,AES256,CBC,SHA,,,),
317   CS_ENTRY(0xCCAB, TLS,PSK,WITH,CHACHA20,POLY1305,SHA256,,),
318   CS_ENTRY(0xCCAB, PSK,CHACHA20,POLY1305,,,,,),
319 #endif
320 #if defined(USE_BEARSSL)
321   CS_ENTRY(0x000A, TLS,RSA,WITH,3DES,EDE,CBC,SHA,),
322   CS_ENTRY(0x000A, DES,CBC3,SHA,,,,,),
323   CS_ENTRY(0xC003, TLS,ECDH,ECDSA,WITH,3DES,EDE,CBC,SHA),
324   CS_ENTRY(0xC003, ECDH,ECDSA,DES,CBC3,SHA,,,),
325   CS_ENTRY(0xC008, TLS,ECDHE,ECDSA,WITH,3DES,EDE,CBC,SHA),
326   CS_ENTRY(0xC008, ECDHE,ECDSA,DES,CBC3,SHA,,,),
327   CS_ENTRY(0xC00D, TLS,ECDH,RSA,WITH,3DES,EDE,CBC,SHA),
328   CS_ENTRY(0xC00D, ECDH,RSA,DES,CBC3,SHA,,,),
329   CS_ENTRY(0xC012, TLS,ECDHE,RSA,WITH,3DES,EDE,CBC,SHA),
330   CS_ENTRY(0xC012, ECDHE,RSA,DES,CBC3,SHA,,,),
331 #endif
332   CS_ENTRY(0xC09C, TLS,RSA,WITH,AES,128,CCM,,),
333   CS_ENTRY(0xC09C, AES128,CCM,,,,,,),
334   CS_ENTRY(0xC09D, TLS,RSA,WITH,AES,256,CCM,,),
335   CS_ENTRY(0xC09D, AES256,CCM,,,,,,),
336   CS_ENTRY(0xC0A0, TLS,RSA,WITH,AES,128,CCM,8,),
337   CS_ENTRY(0xC0A0, AES128,CCM8,,,,,,),
338   CS_ENTRY(0xC0A1, TLS,RSA,WITH,AES,256,CCM,8,),
339   CS_ENTRY(0xC0A1, AES256,CCM8,,,,,,),
340   CS_ENTRY(0xC0AC, TLS,ECDHE,ECDSA,WITH,AES,128,CCM,),
341   CS_ENTRY(0xC0AC, ECDHE,ECDSA,AES128,CCM,,,,),
342   CS_ENTRY(0xC0AD, TLS,ECDHE,ECDSA,WITH,AES,256,CCM,),
343   CS_ENTRY(0xC0AD, ECDHE,ECDSA,AES256,CCM,,,,),
344   CS_ENTRY(0xC0AE, TLS,ECDHE,ECDSA,WITH,AES,128,CCM,8),
345   CS_ENTRY(0xC0AE, ECDHE,ECDSA,AES128,CCM8,,,,),
346   CS_ENTRY(0xC0AF, TLS,ECDHE,ECDSA,WITH,AES,256,CCM,8),
347   CS_ENTRY(0xC0AF, ECDHE,ECDSA,AES256,CCM8,,,,),
348 #if defined(USE_MBEDTLS)
349   /* entries marked ns are "non-standard", they are not in openssl */
350   CS_ENTRY(0x0041, TLS,RSA,WITH,CAMELLIA,128,CBC,SHA,),
351   CS_ENTRY(0x0041, CAMELLIA128,SHA,,,,,,),
352   CS_ENTRY(0x0045, TLS,DHE,RSA,WITH,CAMELLIA,128,CBC,SHA),
353   CS_ENTRY(0x0045, DHE,RSA,CAMELLIA128,SHA,,,,),
354   CS_ENTRY(0x0084, TLS,RSA,WITH,CAMELLIA,256,CBC,SHA,),
355   CS_ENTRY(0x0084, CAMELLIA256,SHA,,,,,,),
356   CS_ENTRY(0x0088, TLS,DHE,RSA,WITH,CAMELLIA,256,CBC,SHA),
357   CS_ENTRY(0x0088, DHE,RSA,CAMELLIA256,SHA,,,,),
358   CS_ENTRY(0x00BA, TLS,RSA,WITH,CAMELLIA,128,CBC,SHA256,),
359   CS_ENTRY(0x00BA, CAMELLIA128,SHA256,,,,,,),
360   CS_ENTRY(0x00BE, TLS,DHE,RSA,WITH,CAMELLIA,128,CBC,SHA256),
361   CS_ENTRY(0x00BE, DHE,RSA,CAMELLIA128,SHA256,,,,),
362   CS_ENTRY(0x00C0, TLS,RSA,WITH,CAMELLIA,256,CBC,SHA256,),
363   CS_ENTRY(0x00C0, CAMELLIA256,SHA256,,,,,,),
364   CS_ENTRY(0x00C4, TLS,DHE,RSA,WITH,CAMELLIA,256,CBC,SHA256),
365   CS_ENTRY(0x00C4, DHE,RSA,CAMELLIA256,SHA256,,,,),
366   CS_ENTRY(0xC037, TLS,ECDHE,PSK,WITH,AES,128,CBC,SHA256),
367   CS_ENTRY(0xC037, ECDHE,PSK,AES128,CBC,SHA256,,,),
368   CS_ENTRY(0xC038, TLS,ECDHE,PSK,WITH,AES,256,CBC,SHA384),
369   CS_ENTRY(0xC038, ECDHE,PSK,AES256,CBC,SHA384,,,),
370   CS_ENTRY(0xC039, TLS,ECDHE,PSK,WITH,NULL,SHA,,),
371   CS_ENTRY(0xC039, ECDHE,PSK,NULL,SHA,,,,),
372   CS_ENTRY(0xC03A, TLS,ECDHE,PSK,WITH,NULL,SHA256,,),
373   CS_ENTRY(0xC03A, ECDHE,PSK,NULL,SHA256,,,,),
374   CS_ENTRY(0xC03B, TLS,ECDHE,PSK,WITH,NULL,SHA384,,),
375   CS_ENTRY(0xC03B, ECDHE,PSK,NULL,SHA384,,,,),
376   CS_ENTRY(0xC03C, TLS,RSA,WITH,ARIA,128,CBC,SHA256,),
377   CS_ENTRY(0xC03C, ARIA128,SHA256,,,,,,), /* ns */
378   CS_ENTRY(0xC03D, TLS,RSA,WITH,ARIA,256,CBC,SHA384,),
379   CS_ENTRY(0xC03D, ARIA256,SHA384,,,,,,), /* ns */
380   CS_ENTRY(0xC044, TLS,DHE,RSA,WITH,ARIA,128,CBC,SHA256),
381   CS_ENTRY(0xC044, DHE,RSA,ARIA128,SHA256,,,,), /* ns */
382   CS_ENTRY(0xC045, TLS,DHE,RSA,WITH,ARIA,256,CBC,SHA384),
383   CS_ENTRY(0xC045, DHE,RSA,ARIA256,SHA384,,,,), /* ns */
384   CS_ENTRY(0xC048, TLS,ECDHE,ECDSA,WITH,ARIA,128,CBC,SHA256),
385   CS_ENTRY(0xC048, ECDHE,ECDSA,ARIA128,SHA256,,,,), /* ns */
386   CS_ENTRY(0xC049, TLS,ECDHE,ECDSA,WITH,ARIA,256,CBC,SHA384),
387   CS_ENTRY(0xC049, ECDHE,ECDSA,ARIA256,SHA384,,,,), /* ns */
388   CS_ENTRY(0xC04A, TLS,ECDH,ECDSA,WITH,ARIA,128,CBC,SHA256),
389   CS_ENTRY(0xC04A, ECDH,ECDSA,ARIA128,SHA256,,,,), /* ns */
390   CS_ENTRY(0xC04B, TLS,ECDH,ECDSA,WITH,ARIA,256,CBC,SHA384),
391   CS_ENTRY(0xC04B, ECDH,ECDSA,ARIA256,SHA384,,,,), /* ns */
392   CS_ENTRY(0xC04C, TLS,ECDHE,RSA,WITH,ARIA,128,CBC,SHA256),
393   CS_ENTRY(0xC04C, ECDHE,ARIA128,SHA256,,,,,), /* ns */
394   CS_ENTRY(0xC04D, TLS,ECDHE,RSA,WITH,ARIA,256,CBC,SHA384),
395   CS_ENTRY(0xC04D, ECDHE,ARIA256,SHA384,,,,,), /* ns */
396   CS_ENTRY(0xC04E, TLS,ECDH,RSA,WITH,ARIA,128,CBC,SHA256),
397   CS_ENTRY(0xC04E, ECDH,ARIA128,SHA256,,,,,), /* ns */
398   CS_ENTRY(0xC04F, TLS,ECDH,RSA,WITH,ARIA,256,CBC,SHA384),
399   CS_ENTRY(0xC04F, ECDH,ARIA256,SHA384,,,,,), /* ns */
400   CS_ENTRY(0xC050, TLS,RSA,WITH,ARIA,128,GCM,SHA256,),
401   CS_ENTRY(0xC050, ARIA128,GCM,SHA256,,,,,),
402   CS_ENTRY(0xC051, TLS,RSA,WITH,ARIA,256,GCM,SHA384,),
403   CS_ENTRY(0xC051, ARIA256,GCM,SHA384,,,,,),
404   CS_ENTRY(0xC052, TLS,DHE,RSA,WITH,ARIA,128,GCM,SHA256),
405   CS_ENTRY(0xC052, DHE,RSA,ARIA128,GCM,SHA256,,,),
406   CS_ENTRY(0xC053, TLS,DHE,RSA,WITH,ARIA,256,GCM,SHA384),
407   CS_ENTRY(0xC053, DHE,RSA,ARIA256,GCM,SHA384,,,),
408   CS_ENTRY(0xC05C, TLS,ECDHE,ECDSA,WITH,ARIA,128,GCM,SHA256),
409   CS_ENTRY(0xC05C, ECDHE,ECDSA,ARIA128,GCM,SHA256,,,),
410   CS_ENTRY(0xC05D, TLS,ECDHE,ECDSA,WITH,ARIA,256,GCM,SHA384),
411   CS_ENTRY(0xC05D, ECDHE,ECDSA,ARIA256,GCM,SHA384,,,),
412   CS_ENTRY(0xC05E, TLS,ECDH,ECDSA,WITH,ARIA,128,GCM,SHA256),
413   CS_ENTRY(0xC05E, ECDH,ECDSA,ARIA128,GCM,SHA256,,,), /* ns */
414   CS_ENTRY(0xC05F, TLS,ECDH,ECDSA,WITH,ARIA,256,GCM,SHA384),
415   CS_ENTRY(0xC05F, ECDH,ECDSA,ARIA256,GCM,SHA384,,,), /* ns */
416   CS_ENTRY(0xC060, TLS,ECDHE,RSA,WITH,ARIA,128,GCM,SHA256),
417   CS_ENTRY(0xC060, ECDHE,ARIA128,GCM,SHA256,,,,),
418   CS_ENTRY(0xC061, TLS,ECDHE,RSA,WITH,ARIA,256,GCM,SHA384),
419   CS_ENTRY(0xC061, ECDHE,ARIA256,GCM,SHA384,,,,),
420   CS_ENTRY(0xC062, TLS,ECDH,RSA,WITH,ARIA,128,GCM,SHA256),
421   CS_ENTRY(0xC062, ECDH,ARIA128,GCM,SHA256,,,,), /* ns */
422   CS_ENTRY(0xC063, TLS,ECDH,RSA,WITH,ARIA,256,GCM,SHA384),
423   CS_ENTRY(0xC063, ECDH,ARIA256,GCM,SHA384,,,,), /* ns */
424   CS_ENTRY(0xC064, TLS,PSK,WITH,ARIA,128,CBC,SHA256,),
425   CS_ENTRY(0xC064, PSK,ARIA128,SHA256,,,,,), /* ns */
426   CS_ENTRY(0xC065, TLS,PSK,WITH,ARIA,256,CBC,SHA384,),
427   CS_ENTRY(0xC065, PSK,ARIA256,SHA384,,,,,), /* ns */
428   CS_ENTRY(0xC066, TLS,DHE,PSK,WITH,ARIA,128,CBC,SHA256),
429   CS_ENTRY(0xC066, DHE,PSK,ARIA128,SHA256,,,,), /* ns */
430   CS_ENTRY(0xC067, TLS,DHE,PSK,WITH,ARIA,256,CBC,SHA384),
431   CS_ENTRY(0xC067, DHE,PSK,ARIA256,SHA384,,,,), /* ns */
432   CS_ENTRY(0xC068, TLS,RSA,PSK,WITH,ARIA,128,CBC,SHA256),
433   CS_ENTRY(0xC068, RSA,PSK,ARIA128,SHA256,,,,), /* ns */
434   CS_ENTRY(0xC069, TLS,RSA,PSK,WITH,ARIA,256,CBC,SHA384),
435   CS_ENTRY(0xC069, RSA,PSK,ARIA256,SHA384,,,,), /* ns */
436   CS_ENTRY(0xC06A, TLS,PSK,WITH,ARIA,128,GCM,SHA256,),
437   CS_ENTRY(0xC06A, PSK,ARIA128,GCM,SHA256,,,,),
438   CS_ENTRY(0xC06B, TLS,PSK,WITH,ARIA,256,GCM,SHA384,),
439   CS_ENTRY(0xC06B, PSK,ARIA256,GCM,SHA384,,,,),
440   CS_ENTRY(0xC06C, TLS,DHE,PSK,WITH,ARIA,128,GCM,SHA256),
441   CS_ENTRY(0xC06C, DHE,PSK,ARIA128,GCM,SHA256,,,),
442   CS_ENTRY(0xC06D, TLS,DHE,PSK,WITH,ARIA,256,GCM,SHA384),
443   CS_ENTRY(0xC06D, DHE,PSK,ARIA256,GCM,SHA384,,,),
444   CS_ENTRY(0xC06E, TLS,RSA,PSK,WITH,ARIA,128,GCM,SHA256),
445   CS_ENTRY(0xC06E, RSA,PSK,ARIA128,GCM,SHA256,,,),
446   CS_ENTRY(0xC06F, TLS,RSA,PSK,WITH,ARIA,256,GCM,SHA384),
447   CS_ENTRY(0xC06F, RSA,PSK,ARIA256,GCM,SHA384,,,),
448   CS_ENTRY(0xC070, TLS,ECDHE,PSK,WITH,ARIA,128,CBC,SHA256),
449   CS_ENTRY(0xC070, ECDHE,PSK,ARIA128,SHA256,,,,), /* ns */
450   CS_ENTRY(0xC071, TLS,ECDHE,PSK,WITH,ARIA,256,CBC,SHA384),
451   CS_ENTRY(0xC071, ECDHE,PSK,ARIA256,SHA384,,,,), /* ns */
452   CS_ENTRY(0xC072, TLS,ECDHE,ECDSA,WITH,CAMELLIA,128,CBC,SHA256),
453   CS_ENTRY(0xC072, ECDHE,ECDSA,CAMELLIA128,SHA256,,,,),
454   CS_ENTRY(0xC073, TLS,ECDHE,ECDSA,WITH,CAMELLIA,256,CBC,SHA384),
455   CS_ENTRY(0xC073, ECDHE,ECDSA,CAMELLIA256,SHA384,,,,),
456   CS_ENTRY(0xC074, TLS,ECDH,ECDSA,WITH,CAMELLIA,128,CBC,SHA256),
457   CS_ENTRY(0xC074, ECDH,ECDSA,CAMELLIA128,SHA256,,,,), /* ns */
458   CS_ENTRY(0xC075, TLS,ECDH,ECDSA,WITH,CAMELLIA,256,CBC,SHA384),
459   CS_ENTRY(0xC075, ECDH,ECDSA,CAMELLIA256,SHA384,,,,), /* ns */
460   CS_ENTRY(0xC076, TLS,ECDHE,RSA,WITH,CAMELLIA,128,CBC,SHA256),
461   CS_ENTRY(0xC076, ECDHE,RSA,CAMELLIA128,SHA256,,,,),
462   CS_ENTRY(0xC077, TLS,ECDHE,RSA,WITH,CAMELLIA,256,CBC,SHA384),
463   CS_ENTRY(0xC077, ECDHE,RSA,CAMELLIA256,SHA384,,,,),
464   CS_ENTRY(0xC078, TLS,ECDH,RSA,WITH,CAMELLIA,128,CBC,SHA256),
465   CS_ENTRY(0xC078, ECDH,CAMELLIA128,SHA256,,,,,), /* ns */
466   CS_ENTRY(0xC079, TLS,ECDH,RSA,WITH,CAMELLIA,256,CBC,SHA384),
467   CS_ENTRY(0xC079, ECDH,CAMELLIA256,SHA384,,,,,), /* ns */
468   CS_ENTRY(0xC07A, TLS,RSA,WITH,CAMELLIA,128,GCM,SHA256,),
469   CS_ENTRY(0xC07A, CAMELLIA128,GCM,SHA256,,,,,), /* ns */
470   CS_ENTRY(0xC07B, TLS,RSA,WITH,CAMELLIA,256,GCM,SHA384,),
471   CS_ENTRY(0xC07B, CAMELLIA256,GCM,SHA384,,,,,), /* ns */
472   CS_ENTRY(0xC07C, TLS,DHE,RSA,WITH,CAMELLIA,128,GCM,SHA256),
473   CS_ENTRY(0xC07C, DHE,RSA,CAMELLIA128,GCM,SHA256,,,), /* ns */
474   CS_ENTRY(0xC07D, TLS,DHE,RSA,WITH,CAMELLIA,256,GCM,SHA384),
475   CS_ENTRY(0xC07D, DHE,RSA,CAMELLIA256,GCM,SHA384,,,), /* ns */
476   CS_ENTRY(0xC086, TLS,ECDHE,ECDSA,WITH,CAMELLIA,128,GCM,SHA256),
477   CS_ENTRY(0xC086, ECDHE,ECDSA,CAMELLIA128,GCM,SHA256,,,), /* ns */
478   CS_ENTRY(0xC087, TLS,ECDHE,ECDSA,WITH,CAMELLIA,256,GCM,SHA384),
479   CS_ENTRY(0xC087, ECDHE,ECDSA,CAMELLIA256,GCM,SHA384,,,), /* ns */
480   CS_ENTRY(0xC088, TLS,ECDH,ECDSA,WITH,CAMELLIA,128,GCM,SHA256),
481   CS_ENTRY(0xC088, ECDH,ECDSA,CAMELLIA128,GCM,SHA256,,,), /* ns */
482   CS_ENTRY(0xC089, TLS,ECDH,ECDSA,WITH,CAMELLIA,256,GCM,SHA384),
483   CS_ENTRY(0xC089, ECDH,ECDSA,CAMELLIA256,GCM,SHA384,,,), /* ns */
484   CS_ENTRY(0xC08A, TLS,ECDHE,RSA,WITH,CAMELLIA,128,GCM,SHA256),
485   CS_ENTRY(0xC08A, ECDHE,CAMELLIA128,GCM,SHA256,,,,), /* ns */
486   CS_ENTRY(0xC08B, TLS,ECDHE,RSA,WITH,CAMELLIA,256,GCM,SHA384),
487   CS_ENTRY(0xC08B, ECDHE,CAMELLIA256,GCM,SHA384,,,,), /* ns */
488   CS_ENTRY(0xC08C, TLS,ECDH,RSA,WITH,CAMELLIA,128,GCM,SHA256),
489   CS_ENTRY(0xC08C, ECDH,CAMELLIA128,GCM,SHA256,,,,), /* ns */
490   CS_ENTRY(0xC08D, TLS,ECDH,RSA,WITH,CAMELLIA,256,GCM,SHA384),
491   CS_ENTRY(0xC08D, ECDH,CAMELLIA256,GCM,SHA384,,,,), /* ns */
492   CS_ENTRY(0xC08E, TLS,PSK,WITH,CAMELLIA,128,GCM,SHA256,),
493   CS_ENTRY(0xC08E, PSK,CAMELLIA128,GCM,SHA256,,,,), /* ns */
494   CS_ENTRY(0xC08F, TLS,PSK,WITH,CAMELLIA,256,GCM,SHA384,),
495   CS_ENTRY(0xC08F, PSK,CAMELLIA256,GCM,SHA384,,,,), /* ns */
496   CS_ENTRY(0xC090, TLS,DHE,PSK,WITH,CAMELLIA,128,GCM,SHA256),
497   CS_ENTRY(0xC090, DHE,PSK,CAMELLIA128,GCM,SHA256,,,), /* ns */
498   CS_ENTRY(0xC091, TLS,DHE,PSK,WITH,CAMELLIA,256,GCM,SHA384),
499   CS_ENTRY(0xC091, DHE,PSK,CAMELLIA256,GCM,SHA384,,,), /* ns */
500   CS_ENTRY(0xC092, TLS,RSA,PSK,WITH,CAMELLIA,128,GCM,SHA256),
501   CS_ENTRY(0xC092, RSA,PSK,CAMELLIA128,GCM,SHA256,,,), /* ns */
502   CS_ENTRY(0xC093, TLS,RSA,PSK,WITH,CAMELLIA,256,GCM,SHA384),
503   CS_ENTRY(0xC093, RSA,PSK,CAMELLIA256,GCM,SHA384,,,), /* ns */
504   CS_ENTRY(0xC094, TLS,PSK,WITH,CAMELLIA,128,CBC,SHA256,),
505   CS_ENTRY(0xC094, PSK,CAMELLIA128,SHA256,,,,,),
506   CS_ENTRY(0xC095, TLS,PSK,WITH,CAMELLIA,256,CBC,SHA384,),
507   CS_ENTRY(0xC095, PSK,CAMELLIA256,SHA384,,,,,),
508   CS_ENTRY(0xC096, TLS,DHE,PSK,WITH,CAMELLIA,128,CBC,SHA256),
509   CS_ENTRY(0xC096, DHE,PSK,CAMELLIA128,SHA256,,,,),
510   CS_ENTRY(0xC097, TLS,DHE,PSK,WITH,CAMELLIA,256,CBC,SHA384),
511   CS_ENTRY(0xC097, DHE,PSK,CAMELLIA256,SHA384,,,,),
512   CS_ENTRY(0xC098, TLS,RSA,PSK,WITH,CAMELLIA,128,CBC,SHA256),
513   CS_ENTRY(0xC098, RSA,PSK,CAMELLIA128,SHA256,,,,),
514   CS_ENTRY(0xC099, TLS,RSA,PSK,WITH,CAMELLIA,256,CBC,SHA384),
515   CS_ENTRY(0xC099, RSA,PSK,CAMELLIA256,SHA384,,,,),
516   CS_ENTRY(0xC09A, TLS,ECDHE,PSK,WITH,CAMELLIA,128,CBC,SHA256),
517   CS_ENTRY(0xC09A, ECDHE,PSK,CAMELLIA128,SHA256,,,,),
518   CS_ENTRY(0xC09B, TLS,ECDHE,PSK,WITH,CAMELLIA,256,CBC,SHA384),
519   CS_ENTRY(0xC09B, ECDHE,PSK,CAMELLIA256,SHA384,,,,),
520   CS_ENTRY(0xC09E, TLS,DHE,RSA,WITH,AES,128,CCM,),
521   CS_ENTRY(0xC09E, DHE,RSA,AES128,CCM,,,,),
522   CS_ENTRY(0xC09F, TLS,DHE,RSA,WITH,AES,256,CCM,),
523   CS_ENTRY(0xC09F, DHE,RSA,AES256,CCM,,,,),
524   CS_ENTRY(0xC0A2, TLS,DHE,RSA,WITH,AES,128,CCM,8),
525   CS_ENTRY(0xC0A2, DHE,RSA,AES128,CCM8,,,,),
526   CS_ENTRY(0xC0A3, TLS,DHE,RSA,WITH,AES,256,CCM,8),
527   CS_ENTRY(0xC0A3, DHE,RSA,AES256,CCM8,,,,),
528   CS_ENTRY(0xC0A4, TLS,PSK,WITH,AES,128,CCM,,),
529   CS_ENTRY(0xC0A4, PSK,AES128,CCM,,,,,),
530   CS_ENTRY(0xC0A5, TLS,PSK,WITH,AES,256,CCM,,),
531   CS_ENTRY(0xC0A5, PSK,AES256,CCM,,,,,),
532   CS_ENTRY(0xC0A6, TLS,DHE,PSK,WITH,AES,128,CCM,),
533   CS_ENTRY(0xC0A6, DHE,PSK,AES128,CCM,,,,),
534   CS_ENTRY(0xC0A7, TLS,DHE,PSK,WITH,AES,256,CCM,),
535   CS_ENTRY(0xC0A7, DHE,PSK,AES256,CCM,,,,),
536   CS_ENTRY(0xC0A8, TLS,PSK,WITH,AES,128,CCM,8,),
537   CS_ENTRY(0xC0A8, PSK,AES128,CCM8,,,,,),
538   CS_ENTRY(0xC0A9, TLS,PSK,WITH,AES,256,CCM,8,),
539   CS_ENTRY(0xC0A9, PSK,AES256,CCM8,,,,,),
540   CS_ENTRY(0xC0AA, TLS,PSK,DHE,WITH,AES,128,CCM,8),
541   CS_ENTRY(0xC0AA, DHE,PSK,AES128,CCM8,,,,),
542   CS_ENTRY(0xC0AB, TLS,PSK,DHE,WITH,AES,256,CCM,8),
543   CS_ENTRY(0xC0AB, DHE,PSK,AES256,CCM8,,,,),
544   CS_ENTRY(0xCCAA, TLS,DHE,RSA,WITH,CHACHA20,POLY1305,SHA256,),
545   CS_ENTRY(0xCCAA, DHE,RSA,CHACHA20,POLY1305,,,,),
546   CS_ENTRY(0xCCAC, TLS,ECDHE,PSK,WITH,CHACHA20,POLY1305,SHA256,),
547   CS_ENTRY(0xCCAC, ECDHE,PSK,CHACHA20,POLY1305,,,,),
548   CS_ENTRY(0xCCAD, TLS,DHE,PSK,WITH,CHACHA20,POLY1305,SHA256,),
549   CS_ENTRY(0xCCAD, DHE,PSK,CHACHA20,POLY1305,,,,),
550   CS_ENTRY(0xCCAE, TLS,RSA,PSK,WITH,CHACHA20,POLY1305,SHA256,),
551   CS_ENTRY(0xCCAE, RSA,PSK,CHACHA20,POLY1305,,,,),
552 #endif
553 };
554 #define CS_LIST_LEN (sizeof(cs_list) / sizeof(cs_list[0]))
555 
cs_str_to_zip(const char * cs_str,size_t cs_len,uint8_t zip[6])556 static int cs_str_to_zip(const char *cs_str, size_t cs_len,
557                          uint8_t zip[6])
558 {
559   uint8_t indexes[8] = {0};
560   const char *entry, *cur;
561   const char *nxt = cs_str;
562   const char *end = cs_str + cs_len;
563   char separator = '-';
564   int idx, i = 0;
565   size_t len;
566 
567   /* split the cipher string by '-' or '_' */
568   if(strncasecompare(cs_str, "TLS", 3))
569     separator = '_';
570 
571   do {
572     if(i == 8)
573       return -1;
574 
575     /* determine the length of the part */
576     cur = nxt;
577     for(; nxt < end && *nxt != '\0' && *nxt != separator; nxt++);
578     len = nxt - cur;
579 
580     /* lookup index for the part (skip empty string at 0) */
581     for(idx = 1, entry = cs_txt + 1; idx < CS_TXT_LEN; idx++) {
582       size_t elen = strlen(entry);
583       if(elen == len && strncasecompare(entry, cur, len))
584         break;
585       entry += elen + 1;
586     }
587     if(idx == CS_TXT_LEN)
588       return -1;
589 
590     indexes[i++] = (uint8_t) idx;
591   } while(nxt < end && *(nxt++) != '\0');
592 
593   /* zip the 8 indexes into 48 bits */
594   zip[0] = (uint8_t) (indexes[0] << 2 | (indexes[1] & 0x3F) >> 4);
595   zip[1] = (uint8_t) (indexes[1] << 4 | (indexes[2] & 0x3F) >> 2);
596   zip[2] = (uint8_t) (indexes[2] << 6 | (indexes[3] & 0x3F));
597   zip[3] = (uint8_t) (indexes[4] << 2 | (indexes[5] & 0x3F) >> 4);
598   zip[4] = (uint8_t) (indexes[5] << 4 | (indexes[6] & 0x3F) >> 2);
599   zip[5] = (uint8_t) (indexes[6] << 6 | (indexes[7] & 0x3F));
600 
601   return 0;
602 }
603 
cs_zip_to_str(const uint8_t zip[6],char * buf,size_t buf_size)604 static int cs_zip_to_str(const uint8_t zip[6],
605                          char *buf, size_t buf_size)
606 {
607   uint8_t indexes[8] = {0};
608   const char *entry;
609   char separator = '-';
610   int idx, i, r;
611   size_t len = 0;
612 
613   /* unzip the 8 indexes */
614   indexes[0] = zip[0] >> 2;
615   indexes[1] = ((zip[0] << 4) & 0x3F) | zip[1] >> 4;
616   indexes[2] = ((zip[1] << 2) & 0x3F) | zip[2] >> 6;
617   indexes[3] = ((zip[2] << 0) & 0x3F);
618   indexes[4] = zip[3] >> 2;
619   indexes[5] = ((zip[3] << 4) & 0x3F) | zip[4] >> 4;
620   indexes[6] = ((zip[4] << 2) & 0x3F) | zip[5] >> 6;
621   indexes[7] = ((zip[5] << 0) & 0x3F);
622 
623   if(indexes[0] == CS_TXT_IDX_TLS)
624     separator = '_';
625 
626   for(i = 0; i < 8 && indexes[i] != 0 && len < buf_size; i++) {
627     if(indexes[i] >= CS_TXT_LEN)
628       return -1;
629 
630     /* lookup the part string for the index (skip empty string at 0) */
631     for(idx = 1, entry = cs_txt + 1; idx < indexes[i]; idx++) {
632       size_t elen = strlen(entry);
633       entry += elen + 1;
634     }
635 
636     /* append the part string to the buffer */
637     if(i > 0)
638       r = msnprintf(&buf[len], buf_size - len, "%c%s", separator, entry);
639     else
640       r = msnprintf(&buf[len], buf_size - len, "%s", entry);
641 
642     if(r < 0)
643       return -1;
644     len += r;
645   }
646 
647   return 0;
648 }
649 
Curl_cipher_suite_lookup_id(const char * cs_str,size_t cs_len)650 uint16_t Curl_cipher_suite_lookup_id(const char *cs_str, size_t cs_len)
651 {
652   size_t i;
653   uint8_t zip[6];
654 
655   if(cs_len > 0 && cs_str_to_zip(cs_str, cs_len, zip) == 0) {
656     for(i = 0; i < CS_LIST_LEN; i++) {
657       if(memcmp(cs_list[i].zip, zip, sizeof(zip)) == 0)
658         return cs_list[i].id;
659     }
660   }
661 
662   return 0;
663 }
664 
cs_is_separator(char c)665 static bool cs_is_separator(char c)
666 {
667   switch(c) {
668     case ' ':
669     case '\t':
670     case ':':
671     case ',':
672     case ';':
673       return true;
674     default:;
675   }
676   return false;
677 }
678 
Curl_cipher_suite_walk_str(const char ** str,const char ** end)679 uint16_t Curl_cipher_suite_walk_str(const char **str, const char **end)
680 {
681   /* move string pointer to first non-separator or end of string */
682   for(; cs_is_separator(*str[0]); (*str)++);
683 
684   /* move end pointer to next separator or end of string */
685   for(*end = *str; *end[0] != '\0' && !cs_is_separator(*end[0]); (*end)++);
686 
687   return Curl_cipher_suite_lookup_id(*str, *end - *str);
688 }
689 
Curl_cipher_suite_get_str(uint16_t id,char * buf,size_t buf_size,bool prefer_rfc)690 int Curl_cipher_suite_get_str(uint16_t id, char *buf, size_t buf_size,
691                               bool prefer_rfc)
692 {
693   size_t i, j = CS_LIST_LEN;
694   int r = -1;
695 
696   for(i = 0; i < CS_LIST_LEN; i++) {
697     if(cs_list[i].id != id)
698       continue;
699     if((cs_list[i].zip[0] >> 2 != CS_TXT_IDX_TLS) == !prefer_rfc) {
700       j = i;
701       break;
702     }
703     if(j == CS_LIST_LEN)
704       j = i;
705   }
706 
707   if(j < CS_LIST_LEN)
708     r = cs_zip_to_str(cs_list[j].zip, buf, buf_size);
709 
710   if(r < 0)
711     msnprintf(buf, buf_size, "TLS_UNKNOWN_0x%04x", id);
712 
713   return r;
714 }
715 
716 #endif /* defined(USE_MBEDTLS) || defined(USE_BEARSSL) */
717