📄 tls1.h
字号:
/* ssl/tls1.h *//* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * * This package is an SSL implementation written * by Eric Young (eay@cryptsoft.com). * The implementation was written so as to conform with Netscapes SSL. * * This library is free for commercial and non-commercial use as long as * the following conditions are aheared to. The following conditions * apply to all code found in this distribution, be it the RC4, RSA, * lhash, DES, etc., code; not just the SSL code. The SSL documentation * included with this distribution is covered by the same copyright terms * except that the holder is Tim Hudson (tjh@cryptsoft.com). * * Copyright remains Eric Young's, and as such any Copyright notices in * the code are not to be removed. * If this package is used in a product, Eric Young should be given attribution * as the author of the parts of the library used. * This can be in the form of a textual message at program startup or * in documentation (online or textual) provided with the package. * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * 1. Redistributions of source code must retain the copyright * notice, this list of conditions and the following disclaimer. * 2. Redistributions in binary form must reproduce the above copyright * notice, this list of conditions and the following disclaimer in the * documentation and/or other materials provided with the distribution. * 3. All advertising materials mentioning features or use of this software * must display the following acknowledgement: * "This product includes cryptographic software written by * Eric Young (eay@cryptsoft.com)" * The word 'cryptographic' can be left out if the rouines from the library * being used are not cryptographic related :-). * 4. If you include any Windows specific code (or a derivative thereof) from * the apps directory (application code) you must include an acknowledgement: * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" * * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF * SUCH DAMAGE. * * The licence and distribution terms for any publically available version or * derivative of this code cannot be changed. i.e. this code cannot simply be * copied and put under another distribution licence * [including the GNU Public Licence.] *//* ==================================================================== * Copyright 2002 Sun Microsystems, Inc. ALL RIGHTS RESERVED. * * Portions of the attached software ("Contribution") are developed by * SUN MICROSYSTEMS, INC., and are contributed to the OpenSSL project. * * The Contribution is licensed pursuant to the OpenSSL open source * license provided above. * * ECC cipher suite support in OpenSSL originally written by * Vipul Gupta and Sumit Gupta of Sun Microsystems Laboratories. * */#ifndef HEADER_TLS1_H #define HEADER_TLS1_H #include <openssl/buffer.h>#ifdef __cplusplusextern "C" {#endif#define TLS1_ALLOW_EXPERIMENTAL_CIPHERSUITES 0#define TLS1_VERSION 0x0301#define TLS1_VERSION_MAJOR 0x03#define TLS1_VERSION_MINOR 0x01#define TLS1_AD_DECRYPTION_FAILED 21#define TLS1_AD_RECORD_OVERFLOW 22#define TLS1_AD_UNKNOWN_CA 48 /* fatal */#define TLS1_AD_ACCESS_DENIED 49 /* fatal */#define TLS1_AD_DECODE_ERROR 50 /* fatal */#define TLS1_AD_DECRYPT_ERROR 51#define TLS1_AD_EXPORT_RESTRICTION 60 /* fatal */#define TLS1_AD_PROTOCOL_VERSION 70 /* fatal */#define TLS1_AD_INSUFFICIENT_SECURITY 71 /* fatal */#define TLS1_AD_INTERNAL_ERROR 80 /* fatal */#define TLS1_AD_USER_CANCELLED 90#define TLS1_AD_NO_RENEGOTIATION 100/* codes 110-114 are from RFC3546 */#define TLS1_AD_UNSUPPORTED_EXTENSION 110#define TLS1_AD_CERTIFICATE_UNOBTAINABLE 111#define TLS1_AD_UNRECOGNIZED_NAME 112#define TLS1_AD_BAD_CERTIFICATE_STATUS_RESPONSE 113#define TLS1_AD_BAD_CERTIFICATE_HASH_VALUE 114#define TLS1_AD_UNKNOWN_PSK_IDENTITY 115 /* fatal *//* ExtensionType values from RFC 3546 */#define TLSEXT_TYPE_server_name 0#define TLSEXT_TYPE_max_fragment_length 1#define TLSEXT_TYPE_client_certificate_url 2#define TLSEXT_TYPE_trusted_ca_keys 3#define TLSEXT_TYPE_truncated_hmac 4#define TLSEXT_TYPE_status_request 5#define TLSEXT_TYPE_elliptic_curves 10#define TLSEXT_TYPE_ec_point_formats 11#define TLSEXT_TYPE_session_ticket 35/* NameType value from RFC 3546 */#define TLSEXT_NAMETYPE_host_name 0/* status request value from RFC 3546 */#define TLSEXT_STATUSTYPE_ocsp 1#ifndef OPENSSL_NO_TLSEXT#define TLSEXT_MAXLEN_host_name 255const char *SSL_get_servername(const SSL *s, const int type) ;int SSL_get_servername_type(const SSL *s) ;#define SSL_set_tlsext_host_name(s,name) \SSL_ctrl(s,SSL_CTRL_SET_TLSEXT_HOSTNAME,TLSEXT_NAMETYPE_host_name,(char *)name)#define SSL_set_tlsext_debug_callback(ssl, cb) \SSL_callback_ctrl(ssl,SSL_CTRL_SET_TLSEXT_DEBUG_CB,(void (*)(void))cb)#define SSL_set_tlsext_debug_arg(ssl, arg) \SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_DEBUG_ARG,0, (void *)arg)#define SSL_set_tlsext_status_type(ssl, type) \SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_TYPE,type, NULL)#define SSL_get_tlsext_status_exts(ssl, arg) \SSL_ctrl(ssl,SSL_CTRL_GET_TLSEXT_STATUS_REQ_EXTS,0, (void *)arg)#define SSL_set_tlsext_status_exts(ssl, arg) \SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_EXTS,0, (void *)arg)#define SSL_get_tlsext_status_ids(ssl, arg) \SSL_ctrl(ssl,SSL_CTRL_GET_TLSEXT_STATUS_REQ_IDS,0, (void *)arg)#define SSL_set_tlsext_status_ids(ssl, arg) \SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_IDS,0, (void *)arg)#define SSL_get_tlsext_status_ocsp_resp(ssl, arg) \SSL_ctrl(ssl,SSL_CTRL_GET_TLSEXT_STATUS_REQ_OCSP_RESP,0, (void *)arg)#define SSL_set_tlsext_status_ocsp_resp(ssl, arg, arglen) \SSL_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_OCSP_RESP,arglen, (void *)arg)#define SSL_CTX_set_tlsext_servername_callback(ctx, cb) \SSL_CTX_callback_ctrl(ctx,SSL_CTRL_SET_TLSEXT_SERVERNAME_CB,(void (*)(void))cb)#define SSL_TLSEXT_ERR_OK 0#define SSL_TLSEXT_ERR_ALERT_WARNING 1#define SSL_TLSEXT_ERR_ALERT_FATAL 2#define SSL_TLSEXT_ERR_NOACK 3#define SSL_CTX_set_tlsext_servername_arg(ctx, arg) \SSL_CTX_ctrl(ctx,SSL_CTRL_SET_TLSEXT_SERVERNAME_ARG,0, (void *)arg)#define SSL_CTX_get_tlsext_ticket_keys(ctx, keys, keylen) \ SSL_CTX_ctrl((ctx),SSL_CTRL_GET_TLXEXT_TICKET_KEYS,(keylen),(keys))#define SSL_CTX_set_tlsext_ticket_keys(ctx, keys, keylen) \ SSL_CTX_ctrl((ctx),SSL_CTRL_SET_TLXEXT_TICKET_KEYS,(keylen),(keys))#define SSL_CTX_set_tlsext_status_cb(ssl, cb) \SSL_CTX_callback_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB,(void (*)(void))cb)#define SSL_CTX_set_tlsext_status_arg(ssl, arg) \SSL_CTX_ctrl(ssl,SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB_ARG,0, (void *)arg)#define SSL_CTX_set_tlsext_ticket_key_cb(ssl, cb) \SSL_CTX_callback_ctrl(ssl,SSL_CTRL_SET_TLSEXT_TICKET_KEY_CB,(void (*)(void))cb)#endif/* Additional TLS ciphersuites from draft-ietf-tls-56-bit-ciphersuites-00.txt * (available if TLS1_ALLOW_EXPERIMENTAL_CIPHERSUITES is defined, see * s3_lib.c). We actually treat them like SSL 3.0 ciphers, which we probably * shouldn't. */#define TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_MD5 0x03000060#define TLS1_CK_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5 0x03000061#define TLS1_CK_RSA_EXPORT1024_WITH_DES_CBC_SHA 0x03000062#define TLS1_CK_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA 0x03000063#define TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_SHA 0x03000064#define TLS1_CK_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA 0x03000065#define TLS1_CK_DHE_DSS_WITH_RC4_128_SHA 0x03000066/* AES ciphersuites from RFC3268 */#define TLS1_CK_RSA_WITH_AES_128_SHA 0x0300002F#define TLS1_CK_DH_DSS_WITH_AES_128_SHA 0x03000030#define TLS1_CK_DH_RSA_WITH_AES_128_SHA 0x03000031#define TLS1_CK_DHE_DSS_WITH_AES_128_SHA 0x03000032
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -