s3_lib.c

来自「一个用于点对点传输加密的工具包源码」· C语言 代码 · 共 1,340 行 · 第 1/2 页

C
1,340
字号
/* ssl/s3_lib.c *//* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * * This package is an SSL implementation written * by Eric Young (eay@cryptsoft.com). * The implementation was written so as to conform with Netscapes SSL. *  * This library is free for commercial and non-commercial use as long as * the following conditions are aheared to.  The following conditions * apply to all code found in this distribution, be it the RC4, RSA, * lhash, DES, etc., code; not just the SSL code.  The SSL documentation * included with this distribution is covered by the same copyright terms * except that the holder is Tim Hudson (tjh@cryptsoft.com). *  * Copyright remains Eric Young's, and as such any Copyright notices in * the code are not to be removed. * If this package is used in a product, Eric Young should be given attribution * as the author of the parts of the library used. * This can be in the form of a textual message at program startup or * in documentation (online or textual) provided with the package. *  * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * 1. Redistributions of source code must retain the copyright *    notice, this list of conditions and the following disclaimer. * 2. Redistributions in binary form must reproduce the above copyright *    notice, this list of conditions and the following disclaimer in the *    documentation and/or other materials provided with the distribution. * 3. All advertising materials mentioning features or use of this software *    must display the following acknowledgement: *    "This product includes cryptographic software written by *     Eric Young (eay@cryptsoft.com)" *    The word 'cryptographic' can be left out if the rouines from the library *    being used are not cryptographic related :-). * 4. If you include any Windows specific code (or a derivative thereof) from  *    the apps directory (application code) you must include an acknowledgement: *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" *  * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF * SUCH DAMAGE. *  * The licence and distribution terms for any publically available version or * derivative of this code cannot be changed.  i.e. this code cannot simply be * copied and put under another distribution licence * [including the GNU Public Licence.] */#include <stdio.h>#include <openssl/md5.h>#include <openssl/sha.h>#include <openssl/objects.h>#include "ssl_locl.h"const char *ssl3_version_str="SSLv3" OPENSSL_VERSION_PTEXT;#define SSL3_NUM_CIPHERS	(sizeof(ssl3_ciphers)/sizeof(SSL_CIPHER))static long ssl3_default_timeout(void );OPENSSL_GLOBAL SSL_CIPHER ssl3_ciphers[]={/* The RSA ciphers *//* Cipher 01 */	{	1,	SSL3_TXT_RSA_NULL_MD5,	SSL3_CK_RSA_NULL_MD5,	SSL_kRSA|SSL_aRSA|SSL_eNULL |SSL_MD5|SSL_SSLV3,	SSL_NOT_EXP,	0,	0,	0,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 02 */	{	1,	SSL3_TXT_RSA_NULL_SHA,	SSL3_CK_RSA_NULL_SHA,	SSL_kRSA|SSL_aRSA|SSL_eNULL |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP,	0,	0,	0,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* anon DH *//* Cipher 17 */	{	1,	SSL3_TXT_ADH_RC4_40_MD5,	SSL3_CK_ADH_RC4_40_MD5,	SSL_kEDH |SSL_aNULL|SSL_RC4  |SSL_MD5 |SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 18 */	{	1,	SSL3_TXT_ADH_RC4_128_MD5,	SSL3_CK_ADH_RC4_128_MD5,	SSL_kEDH |SSL_aNULL|SSL_RC4  |SSL_MD5 |SSL_SSLV3,	SSL_NOT_EXP,	0,	128,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 19 */	{	1,	SSL3_TXT_ADH_DES_40_CBC_SHA,	SSL3_CK_ADH_DES_40_CBC_SHA,	SSL_kEDH |SSL_aNULL|SSL_DES|SSL_SHA1|SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 1A */	{	1,	SSL3_TXT_ADH_DES_64_CBC_SHA,	SSL3_CK_ADH_DES_64_CBC_SHA,	SSL_kEDH |SSL_aNULL|SSL_DES  |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP,	0,	56,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 1B */	{	1,	SSL3_TXT_ADH_DES_192_CBC_SHA,	SSL3_CK_ADH_DES_192_CBC_SHA,	SSL_kEDH |SSL_aNULL|SSL_3DES |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP,	0,	168,	168,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* RSA again *//* Cipher 03 */	{	1,	SSL3_TXT_RSA_RC4_40_MD5,	SSL3_CK_RSA_RC4_40_MD5,	SSL_kRSA|SSL_aRSA|SSL_RC4  |SSL_MD5 |SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 04 */	{	1,	SSL3_TXT_RSA_RC4_128_MD5,	SSL3_CK_RSA_RC4_128_MD5,	SSL_kRSA|SSL_aRSA|SSL_RC4  |SSL_MD5|SSL_SSLV3,	SSL_NOT_EXP|SSL_MEDIUM,	0,	128,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 05 */	{	1,	SSL3_TXT_RSA_RC4_128_SHA,	SSL3_CK_RSA_RC4_128_SHA,	SSL_kRSA|SSL_aRSA|SSL_RC4  |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_MEDIUM,	0,	128,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 06 */	{	1,	SSL3_TXT_RSA_RC2_40_MD5,	SSL3_CK_RSA_RC2_40_MD5,	SSL_kRSA|SSL_aRSA|SSL_RC2  |SSL_MD5 |SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 07 */	{	1,	SSL3_TXT_RSA_IDEA_128_SHA,	SSL3_CK_RSA_IDEA_128_SHA,	SSL_kRSA|SSL_aRSA|SSL_IDEA |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_MEDIUM,	0,	128,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 08 */	{	1,	SSL3_TXT_RSA_DES_40_CBC_SHA,	SSL3_CK_RSA_DES_40_CBC_SHA,	SSL_kRSA|SSL_aRSA|SSL_DES|SSL_SHA1|SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 09 */	{	1,	SSL3_TXT_RSA_DES_64_CBC_SHA,	SSL3_CK_RSA_DES_64_CBC_SHA,	SSL_kRSA|SSL_aRSA|SSL_DES  |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_LOW,	0,	56,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 0A */	{	1,	SSL3_TXT_RSA_DES_192_CBC3_SHA,	SSL3_CK_RSA_DES_192_CBC3_SHA,	SSL_kRSA|SSL_aRSA|SSL_3DES |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_HIGH,	0,	168,	168,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/*  The DH ciphers *//* Cipher 0B */	{	0,	SSL3_TXT_DH_DSS_DES_40_CBC_SHA,	SSL3_CK_DH_DSS_DES_40_CBC_SHA,	SSL_kDHd |SSL_aDH|SSL_DES|SSL_SHA1|SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 0C */	{	0,	SSL3_TXT_DH_DSS_DES_64_CBC_SHA,	SSL3_CK_DH_DSS_DES_64_CBC_SHA,	SSL_kDHd |SSL_aDH|SSL_DES  |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_LOW,	0,	56,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 0D */	{	0,	SSL3_TXT_DH_DSS_DES_192_CBC3_SHA,	SSL3_CK_DH_DSS_DES_192_CBC3_SHA,	SSL_kDHd |SSL_aDH|SSL_3DES |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_HIGH,	0,	168,	168,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 0E */	{	0,	SSL3_TXT_DH_RSA_DES_40_CBC_SHA,	SSL3_CK_DH_RSA_DES_40_CBC_SHA,	SSL_kDHr |SSL_aDH|SSL_DES|SSL_SHA1|SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 0F */	{	0,	SSL3_TXT_DH_RSA_DES_64_CBC_SHA,	SSL3_CK_DH_RSA_DES_64_CBC_SHA,	SSL_kDHr |SSL_aDH|SSL_DES  |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_LOW,	0,	56,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 10 */	{	0,	SSL3_TXT_DH_RSA_DES_192_CBC3_SHA,	SSL3_CK_DH_RSA_DES_192_CBC3_SHA,	SSL_kDHr |SSL_aDH|SSL_3DES |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_HIGH,	0,	168,	168,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* The Ephemeral DH ciphers *//* Cipher 11 */	{	1,	SSL3_TXT_EDH_DSS_DES_40_CBC_SHA,	SSL3_CK_EDH_DSS_DES_40_CBC_SHA,	SSL_kEDH|SSL_aDSS|SSL_DES|SSL_SHA1|SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 12 */	{	1,	SSL3_TXT_EDH_DSS_DES_64_CBC_SHA,	SSL3_CK_EDH_DSS_DES_64_CBC_SHA,	SSL_kEDH|SSL_aDSS|SSL_DES  |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_LOW,	0,	56,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 13 */	{	1,	SSL3_TXT_EDH_DSS_DES_192_CBC3_SHA,	SSL3_CK_EDH_DSS_DES_192_CBC3_SHA,	SSL_kEDH|SSL_aDSS|SSL_3DES |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_HIGH,	0,	168,	168,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 14 */	{	1,	SSL3_TXT_EDH_RSA_DES_40_CBC_SHA,	SSL3_CK_EDH_RSA_DES_40_CBC_SHA,	SSL_kEDH|SSL_aRSA|SSL_DES|SSL_SHA1|SSL_SSLV3,	SSL_EXPORT|SSL_EXP40,	0,	40,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 15 */	{	1,	SSL3_TXT_EDH_RSA_DES_64_CBC_SHA,	SSL3_CK_EDH_RSA_DES_64_CBC_SHA,	SSL_kEDH|SSL_aRSA|SSL_DES  |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_LOW,	0,	56,	56,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 16 */	{	1,	SSL3_TXT_EDH_RSA_DES_192_CBC3_SHA,	SSL3_CK_EDH_RSA_DES_192_CBC3_SHA,	SSL_kEDH|SSL_aRSA|SSL_3DES |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP|SSL_HIGH,	0,	168,	168,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Fortezza *//* Cipher 1C */	{	0,	SSL3_TXT_FZA_DMS_NULL_SHA,	SSL3_CK_FZA_DMS_NULL_SHA,	SSL_kFZA|SSL_aFZA |SSL_eNULL |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP,	0,	0,	0,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 1D */	{	0,	SSL3_TXT_FZA_DMS_FZA_SHA,	SSL3_CK_FZA_DMS_FZA_SHA,	SSL_kFZA|SSL_aFZA |SSL_eFZA |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP,	0,	0,	0,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},/* Cipher 1E */	{	0,	SSL3_TXT_FZA_DMS_RC4_SHA,	SSL3_CK_FZA_DMS_RC4_SHA,	SSL_kFZA|SSL_aFZA |SSL_RC4  |SSL_SHA1|SSL_SSLV3,	SSL_NOT_EXP,	0,	128,	128,	SSL_ALL_CIPHERS,	SSL_ALL_STRENGTHS,	},#if TLS1_ALLOW_EXPERIMENTAL_CIPHERSUITES	/* New TLS Export CipherSuites */	/* Cipher 60 */	    {	    1,	    TLS1_TXT_RSA_EXPORT1024_WITH_RC4_56_MD5,	    TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_MD5,	    SSL_kRSA|SSL_aRSA|SSL_RC4|SSL_MD5|SSL_TLSV1,	    SSL_EXPORT|SSL_EXP56,	    0,	    56,	    128,	    SSL_ALL_CIPHERS,	    SSL_ALL_STRENGTHS,	    },	/* Cipher 61 */	    {	    1,	    TLS1_TXT_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5,	    TLS1_CK_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5,	    SSL_kRSA|SSL_aRSA|SSL_RC2|SSL_MD5|SSL_TLSV1,	    SSL_EXPORT|SSL_EXP56,	    0,	    56,	    128,	    SSL_ALL_CIPHERS,	    SSL_ALL_STRENGTHS,	    },	/* Cipher 62 */	    {	    1,	    TLS1_TXT_RSA_EXPORT1024_WITH_DES_CBC_SHA,	    TLS1_CK_RSA_EXPORT1024_WITH_DES_CBC_SHA,	    SSL_kRSA|SSL_aRSA|SSL_DES|SSL_SHA|SSL_TLSV1,	    SSL_EXPORT|SSL_EXP56,	    0,	    56,	    56,	    SSL_ALL_CIPHERS,	    SSL_ALL_STRENGTHS,	    },	/* Cipher 63 */	    {	    1,	    TLS1_TXT_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA,	    TLS1_CK_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA,	    SSL_kEDH|SSL_aDSS|SSL_DES|SSL_SHA|SSL_TLSV1,	    SSL_EXPORT|SSL_EXP56,	    0,	    56,	    56,	    SSL_ALL_CIPHERS,	    SSL_ALL_STRENGTHS,	    },	/* Cipher 64 */	    {	    1,	    TLS1_TXT_RSA_EXPORT1024_WITH_RC4_56_SHA,	    TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_SHA,	    SSL_kRSA|SSL_aRSA|SSL_RC4|SSL_SHA|SSL_TLSV1,	    SSL_EXPORT|SSL_EXP56,	    0,	    56,	    128,	    SSL_ALL_CIPHERS,	    SSL_ALL_STRENGTHS,	    },	/* Cipher 65 */	    {	    1,	    TLS1_TXT_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA,	    TLS1_CK_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA,	    SSL_kEDH|SSL_aDSS|SSL_RC4|SSL_SHA|SSL_TLSV1,	    SSL_EXPORT|SSL_EXP56,	    0,	    56,	    128,	    SSL_ALL_CIPHERS,	    SSL_ALL_STRENGTHS,	    },	/* Cipher 66 */	    {	    1,	    TLS1_TXT_DHE_DSS_WITH_RC4_128_SHA,	    TLS1_CK_DHE_DSS_WITH_RC4_128_SHA,	    SSL_kEDH|SSL_aDSS|SSL_RC4|SSL_SHA|SSL_TLSV1,	    SSL_NOT_EXP,	    0,	    128,	    128,	    SSL_ALL_CIPHERS,	    SSL_ALL_STRENGTHS	    },#endif/* end of list */	};static SSL3_ENC_METHOD SSLv3_enc_data={	ssl3_enc,	ssl3_mac,	ssl3_setup_key_block,	ssl3_generate_master_secret,	ssl3_change_cipher_state,	ssl3_final_finish_mac,	MD5_DIGEST_LENGTH+SHA_DIGEST_LENGTH,	ssl3_cert_verify_mac,	SSL3_MD_CLIENT_FINISHED_CONST,4,	SSL3_MD_SERVER_FINISHED_CONST,4,	ssl3_alert_code,	};static SSL_METHOD SSLv3_data= {	SSL3_VERSION,	ssl3_new,	ssl3_clear,	ssl3_free,	ssl_undefined_function,	ssl_undefined_function,	ssl3_read,	ssl3_peek,	ssl3_write,	ssl3_shutdown,	ssl3_renegotiate,	ssl3_renegotiate_check,	ssl3_ctrl,	ssl3_ctx_ctrl,	ssl3_get_cipher_by_char,	ssl3_put_cipher_by_char,	ssl3_pending,	ssl3_num_ciphers,	ssl3_get_cipher,	ssl_bad_method,	ssl3_default_timeout,	&SSLv3_enc_data,	ssl_undefined_function,	ssl3_callback_ctrl,	ssl3_ctx_callback_ctrl,	};static long ssl3_default_timeout(void)	{	/* 2 hours, the 24 hours mentioned in the SSLv3 spec	 * is way too long for http, the cache would over fill */	return(60*60*2);	}SSL_METHOD *sslv3_base_method(void)	{	return(&SSLv3_data);	}int ssl3_num_ciphers(void)	{	return(SSL3_NUM_CIPHERS);	}SSL_CIPHER *ssl3_get_cipher(unsigned int u)	{	if (u < SSL3_NUM_CIPHERS)		return(&(ssl3_ciphers[SSL3_NUM_CIPHERS-1-u]));	else		return(NULL);	}/* The problem is that it may not be the correct record type */int ssl3_pending(SSL *s)	{	return(s->s3->rrec.length);	}int ssl3_new(SSL *s)	{	SSL3_STATE *s3;	if ((s3=OPENSSL_malloc(sizeof *s3)) == NULL) goto err;	memset(s3,0,sizeof *s3);	s->s3=s3;	s->method->ssl_clear(s);	return(1);err:	return(0);	}void ssl3_free(SSL *s)	{	if(s == NULL)	    return;	ssl3_cleanup_key_block(s);	if (s->s3->rbuf.buf != NULL)		OPENSSL_free(s->s3->rbuf.buf);	if (s->s3->wbuf.buf != NULL)

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?