Branch data Line data Source code
1 : : /*
2 : : * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
3 : : *
4 : : * Licensed under the Apache License, Version 2.0 (the "License").
5 : : * You may not use this file except in compliance with the License.
6 : : * A copy of the License is located at
7 : : *
8 : : * http://aws.amazon.com/apache2.0
9 : : *
10 : : * or in the "license" file accompanying this file. This file is distributed
11 : : * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either
12 : : * express or implied. See the License for the specific language governing
13 : : * permissions and limitations under the License.
14 : : */
15 : :
16 : : #include "tls/s2n_security_policies.h"
17 : :
18 : : #include "api/s2n.h"
19 : : #include "crypto/s2n_pq.h"
20 : : #include "tls/s2n_certificate_keys.h"
21 : : #include "tls/s2n_connection.h"
22 : : #include "tls/s2n_supported_group_preferences.h"
23 : : #include "utils/s2n_safety.h"
24 : :
25 : : /* Default as of 10/13 */
26 : : const struct s2n_security_policy security_policy_20251014 = {
27 : : .minimum_protocol_version = S2N_TLS12,
28 : : .cipher_preferences = &cipher_preferences_20251014,
29 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
30 : : .signature_preferences = &s2n_signature_preferences_20240501,
31 : : .ecc_preferences = &s2n_ecc_preferences_20240501,
32 : : .rules = {
33 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
34 : : },
35 : : };
36 : :
37 : : /* FIPS default as of 10/13 */
38 : : const struct s2n_security_policy security_policy_20251015 = {
39 : : .minimum_protocol_version = S2N_TLS12,
40 : : .cipher_preferences = &cipher_preferences_20251015,
41 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
42 : : .signature_preferences = &s2n_signature_preferences_20240501,
43 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
44 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
45 : : .rules = {
46 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
47 : : [S2N_FIPS_140_3] = true,
48 : : },
49 : : };
50 : :
51 : : const struct s2n_security_policy security_policy_20240501 = {
52 : : .minimum_protocol_version = S2N_TLS12,
53 : : .cipher_preferences = &cipher_preferences_20240331,
54 : : .kem_preferences = &kem_preferences_null,
55 : : .signature_preferences = &s2n_signature_preferences_20240501,
56 : : .ecc_preferences = &s2n_ecc_preferences_20240501,
57 : : .rules = {
58 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
59 : : },
60 : : };
61 : :
62 : : const struct s2n_security_policy security_policy_20240502 = {
63 : : .minimum_protocol_version = S2N_TLS12,
64 : : .cipher_preferences = &cipher_preferences_20240331,
65 : : .kem_preferences = &kem_preferences_null,
66 : : .signature_preferences = &s2n_signature_preferences_20240501,
67 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
68 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
69 : : .rules = {
70 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
71 : : [S2N_FIPS_140_3] = true,
72 : : },
73 : : };
74 : :
75 : : /* TLS1.3 default as of 05/24 */
76 : : const struct s2n_security_policy security_policy_20240503 = {
77 : : .minimum_protocol_version = S2N_TLS12,
78 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019,
79 : : .kem_preferences = &kem_preferences_null,
80 : : .signature_preferences = &s2n_signature_preferences_20240501,
81 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
82 : : .ecc_preferences = &s2n_ecc_preferences_20240501,
83 : : .rules = {
84 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
85 : : },
86 : : };
87 : :
88 : : const struct s2n_security_policy security_policy_20241001 = {
89 : : .minimum_protocol_version = S2N_TLS12,
90 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019,
91 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
92 : : .signature_preferences = &s2n_signature_preferences_20240501,
93 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
94 : : .ecc_preferences = &s2n_ecc_preferences_20240501,
95 : : .rules = {
96 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
97 : : },
98 : : };
99 : :
100 : : /* 20241001, but with ML-DSA added */
101 : : const struct s2n_security_policy security_policy_20250512 = {
102 : : .minimum_protocol_version = S2N_TLS12,
103 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019,
104 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
105 : : .signature_preferences = &s2n_signature_preferences_20250512,
106 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250512,
107 : : .ecc_preferences = &s2n_ecc_preferences_20240501,
108 : : .rules = {
109 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
110 : : },
111 : : };
112 : :
113 : : const struct s2n_security_policy security_policy_20250721 = {
114 : : .minimum_protocol_version = S2N_TLS12,
115 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019,
116 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
117 : : .signature_preferences = &s2n_signature_preferences_20250512,
118 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250512,
119 : : .ecc_preferences = &s2n_ecc_preferences_20240501,
120 : : .rules = {
121 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
122 : : },
123 : : };
124 : :
125 : : const struct s2n_security_policy security_policy_20241001_pq_mixed = {
126 : : .minimum_protocol_version = S2N_TLS12,
127 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019,
128 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
129 : : .signature_preferences = &s2n_signature_preferences_20240501,
130 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
131 : : .ecc_preferences = &s2n_ecc_preferences_20240501,
132 : : .rules = {
133 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
134 : : },
135 : : };
136 : :
137 : : const struct s2n_security_policy security_policy_20240603 = {
138 : : .minimum_protocol_version = S2N_TLS12,
139 : : .cipher_preferences = &cipher_preferences_20240603,
140 : : .kem_preferences = &kem_preferences_null,
141 : : .signature_preferences = &s2n_signature_preferences_20240501,
142 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
143 : : .ecc_preferences = &s2n_ecc_preferences_20240603,
144 : : };
145 : :
146 : : const struct s2n_security_policy security_policy_20170210 = {
147 : : .minimum_protocol_version = S2N_TLS10,
148 : : .cipher_preferences = &cipher_preferences_20170210,
149 : : .kem_preferences = &kem_preferences_null,
150 : : .signature_preferences = &s2n_signature_preferences_20140601,
151 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
152 : : };
153 : :
154 : : const struct s2n_security_policy security_policy_20240417 = {
155 : : .minimum_protocol_version = S2N_TLS10,
156 : : .cipher_preferences = &cipher_preferences_20210831,
157 : : .kem_preferences = &kem_preferences_null,
158 : : .signature_preferences = &s2n_signature_preferences_20200207,
159 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
160 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
161 : : };
162 : :
163 : : /*
164 : : * This security policy is derived from the following specification:
165 : : * https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf
166 : : *
167 : : * Supports TLS1.2
168 : : */
169 : : const struct s2n_security_policy security_policy_20240416 = {
170 : : .minimum_protocol_version = S2N_TLS12,
171 : : .cipher_preferences = &cipher_preferences_default_fips,
172 : : .kem_preferences = &kem_preferences_null,
173 : : .signature_preferences = &s2n_signature_preferences_default_fips,
174 : : .certificate_signature_preferences = &s2n_signature_preferences_default_fips,
175 : : .ecc_preferences = &s2n_ecc_preferences_default_fips,
176 : : .rules = {
177 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
178 : : [S2N_FIPS_140_3] = true,
179 : : },
180 : : };
181 : :
182 : : const struct s2n_security_policy security_policy_20230317 = {
183 : : .minimum_protocol_version = S2N_TLS12,
184 : : .cipher_preferences = &cipher_preferences_20230317,
185 : : .kem_preferences = &kem_preferences_null,
186 : : .signature_preferences = &s2n_signature_preferences_20230317,
187 : : .certificate_signature_preferences = &s2n_signature_preferences_20230317,
188 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
189 : : .rules = {
190 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
191 : : [S2N_FIPS_140_3] = true,
192 : : },
193 : : };
194 : :
195 : : const struct s2n_security_policy security_policy_20230317_pq = {
196 : : .minimum_protocol_version = S2N_TLS12,
197 : : .cipher_preferences = &cipher_preferences_20230317,
198 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
199 : : .signature_preferences = &s2n_signature_preferences_20230317,
200 : : .certificate_signature_preferences = &s2n_signature_preferences_20230317,
201 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
202 : : .rules = {
203 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
204 : : [S2N_FIPS_140_3] = true,
205 : : },
206 : : };
207 : :
208 : : const struct s2n_security_policy security_policy_20240331 = {
209 : : .minimum_protocol_version = S2N_TLS12,
210 : : .cipher_preferences = &cipher_preferences_20240331,
211 : : .kem_preferences = &kem_preferences_null,
212 : : .signature_preferences = &s2n_signature_preferences_20230317,
213 : : .certificate_signature_preferences = &s2n_signature_preferences_20230317,
214 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
215 : : .rules = {
216 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
217 : : [S2N_FIPS_140_3] = true,
218 : : },
219 : : };
220 : :
221 : : const struct s2n_security_policy security_policy_20190801 = {
222 : : .minimum_protocol_version = S2N_TLS10,
223 : : .cipher_preferences = &cipher_preferences_20190801,
224 : : .kem_preferences = &kem_preferences_null,
225 : : /* The discrepancy in the date exists because the signature preferences
226 : : * were named when cipher preferences and signature preferences were
227 : : * tracked separately, and we chose to keep the cipher preference
228 : : * name because customers use it.
229 : : */
230 : : .signature_preferences = &s2n_signature_preferences_20200207,
231 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
232 : : };
233 : :
234 : : const struct s2n_security_policy security_policy_20190802 = {
235 : : .minimum_protocol_version = S2N_TLS10,
236 : : .cipher_preferences = &cipher_preferences_20190801,
237 : : .kem_preferences = &kem_preferences_null,
238 : : /* The discrepancy in the date exists because the signature preferences
239 : : * were named when cipher preferences and signature preferences were
240 : : * tracked separately, and we chose to keep the cipher preference
241 : : * name because customers use it.
242 : : */
243 : : .signature_preferences = &s2n_signature_preferences_20200207,
244 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
245 : : };
246 : :
247 : : const struct s2n_security_policy security_policy_20170405 = {
248 : : .minimum_protocol_version = S2N_TLS10,
249 : : .cipher_preferences = &cipher_preferences_20170405,
250 : : .kem_preferences = &kem_preferences_null,
251 : : .signature_preferences = &s2n_signature_preferences_20140601,
252 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
253 : : };
254 : :
255 : : const struct s2n_security_policy security_policy_20170405_gcm = {
256 : : .minimum_protocol_version = S2N_TLS10,
257 : : .cipher_preferences = &cipher_preferences_20170405_gcm,
258 : : .kem_preferences = &kem_preferences_null,
259 : : .signature_preferences = &s2n_signature_preferences_20140601,
260 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
261 : : };
262 : :
263 : : const struct s2n_security_policy security_policy_elb_2015_04 = {
264 : : .minimum_protocol_version = S2N_TLS10,
265 : : .cipher_preferences = &elb_security_policy_2015_04,
266 : : .kem_preferences = &kem_preferences_null,
267 : : .signature_preferences = &s2n_signature_preferences_20140601,
268 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
269 : : };
270 : :
271 : : const struct s2n_security_policy security_policy_elb_2016_08 = {
272 : : .minimum_protocol_version = S2N_TLS10,
273 : : .cipher_preferences = &elb_security_policy_2016_08,
274 : : .kem_preferences = &kem_preferences_null,
275 : : .signature_preferences = &s2n_signature_preferences_20140601,
276 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
277 : : };
278 : :
279 : : const struct s2n_security_policy security_policy_elb_tls_1_1_2017_01 = {
280 : : .minimum_protocol_version = S2N_TLS11,
281 : : .cipher_preferences = &elb_security_policy_tls_1_1_2017_01,
282 : : .kem_preferences = &kem_preferences_null,
283 : : .signature_preferences = &s2n_signature_preferences_20140601,
284 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
285 : : };
286 : :
287 : : const struct s2n_security_policy security_policy_elb_tls_1_2_2017_01 = {
288 : : .minimum_protocol_version = S2N_TLS12,
289 : : .cipher_preferences = &elb_security_policy_tls_1_2_2017_01,
290 : : .kem_preferences = &kem_preferences_null,
291 : : .signature_preferences = &s2n_signature_preferences_20140601,
292 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
293 : : };
294 : :
295 : : const struct s2n_security_policy security_policy_elb_tls_1_2_ext_2018_06 = {
296 : : .minimum_protocol_version = S2N_TLS12,
297 : : .cipher_preferences = &elb_security_policy_tls_1_2_ext_2018_06,
298 : : .kem_preferences = &kem_preferences_null,
299 : : .signature_preferences = &s2n_signature_preferences_20140601,
300 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
301 : : };
302 : :
303 : : const struct s2n_security_policy security_policy_elb_fs_2018_06 = {
304 : : .minimum_protocol_version = S2N_TLS10,
305 : : .cipher_preferences = &elb_security_policy_fs_2018_06,
306 : : .kem_preferences = &kem_preferences_null,
307 : : .signature_preferences = &s2n_signature_preferences_20140601,
308 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
309 : : .rules = {
310 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
311 : : },
312 : : };
313 : :
314 : : const struct s2n_security_policy security_policy_elb_fs_1_2_2019_08 = {
315 : : .minimum_protocol_version = S2N_TLS12,
316 : : .cipher_preferences = &elb_security_policy_fs_1_2_2019_08,
317 : : .kem_preferences = &kem_preferences_null,
318 : : .signature_preferences = &s2n_signature_preferences_20140601,
319 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
320 : : .rules = {
321 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
322 : : },
323 : : };
324 : :
325 : : const struct s2n_security_policy security_policy_elb_fs_1_1_2019_08 = {
326 : : .minimum_protocol_version = S2N_TLS11,
327 : : .cipher_preferences = &elb_security_policy_fs_1_1_2019_08,
328 : : .kem_preferences = &kem_preferences_null,
329 : : .signature_preferences = &s2n_signature_preferences_20140601,
330 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
331 : : .rules = {
332 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
333 : : },
334 : : };
335 : :
336 : : const struct s2n_security_policy security_policy_elb_fs_1_2_Res_2019_08 = {
337 : : .minimum_protocol_version = S2N_TLS12,
338 : : .cipher_preferences = &elb_security_policy_fs_1_2_Res_2019_08,
339 : : .kem_preferences = &kem_preferences_null,
340 : : .signature_preferences = &s2n_signature_preferences_20140601,
341 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
342 : : .rules = {
343 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
344 : : },
345 : : };
346 : :
347 : : /* CloudFront upstream */
348 : : const struct s2n_security_policy security_policy_cloudfront_upstream = {
349 : : .minimum_protocol_version = S2N_SSLv3,
350 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream,
351 : : .kem_preferences = &kem_preferences_null,
352 : : .signature_preferences = &s2n_signature_preferences_20140601,
353 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
354 : : };
355 : :
356 : : const struct s2n_security_policy security_policy_cloudfront_upstream_tls10 = {
357 : : .minimum_protocol_version = S2N_TLS10,
358 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_tls10,
359 : : .kem_preferences = &kem_preferences_null,
360 : : .signature_preferences = &s2n_signature_preferences_20140601,
361 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
362 : : };
363 : :
364 : : const struct s2n_security_policy security_policy_cloudfront_upstream_tls11 = {
365 : : .minimum_protocol_version = S2N_TLS11,
366 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_tls11,
367 : : .kem_preferences = &kem_preferences_null,
368 : : .signature_preferences = &s2n_signature_preferences_20140601,
369 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
370 : : };
371 : :
372 : : const struct s2n_security_policy security_policy_cloudfront_upstream_tls12 = {
373 : : .minimum_protocol_version = S2N_TLS12,
374 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_tls12,
375 : : .kem_preferences = &kem_preferences_null,
376 : : .signature_preferences = &s2n_signature_preferences_20140601,
377 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
378 : : };
379 : :
380 : : /* CloudFront upstream 2025 -- same as original upstream above, but with:
381 : : * 1. TLSv1.3 enabled and
382 : : * 2. signature preferences updated to 2020-10-21, expanding support for RSA
383 : : * PSS while preserving support for legacy signature algorithms
384 : : */
385 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08 = {
386 : : .minimum_protocol_version = S2N_SSLv3,
387 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08,
388 : : .kem_preferences = &kem_preferences_null,
389 : : .signature_preferences = &s2n_signature_preferences_20250820,
390 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
391 : : };
392 : :
393 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_tls10 = {
394 : : .minimum_protocol_version = S2N_TLS10,
395 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08,
396 : : .kem_preferences = &kem_preferences_null,
397 : : .signature_preferences = &s2n_signature_preferences_20250820,
398 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
399 : : };
400 : :
401 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_tls11 = {
402 : : .minimum_protocol_version = S2N_TLS11,
403 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08,
404 : : .kem_preferences = &kem_preferences_null,
405 : : .signature_preferences = &s2n_signature_preferences_20250820,
406 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
407 : : };
408 : :
409 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_tls12 = {
410 : : .minimum_protocol_version = S2N_TLS12,
411 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08,
412 : : .kem_preferences = &kem_preferences_null,
413 : : .signature_preferences = &s2n_signature_preferences_20250820,
414 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
415 : : };
416 : :
417 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_tls13 = {
418 : : .minimum_protocol_version = S2N_TLS13,
419 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08_tls13,
420 : : .kem_preferences = &kem_preferences_null,
421 : : .signature_preferences = &s2n_signature_preferences_20250820,
422 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
423 : : };
424 : :
425 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_pq = {
426 : : .minimum_protocol_version = S2N_SSLv3,
427 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08,
428 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
429 : : .signature_preferences = &s2n_signature_preferences_20250821,
430 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
431 : : };
432 : :
433 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_tls10_pq = {
434 : : .minimum_protocol_version = S2N_TLS10,
435 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08,
436 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
437 : : .signature_preferences = &s2n_signature_preferences_20250821,
438 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
439 : : };
440 : :
441 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_tls11_pq = {
442 : : .minimum_protocol_version = S2N_TLS11,
443 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08,
444 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
445 : : .signature_preferences = &s2n_signature_preferences_20250821,
446 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
447 : : };
448 : :
449 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_tls12_pq = {
450 : : .minimum_protocol_version = S2N_TLS12,
451 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08,
452 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
453 : : .signature_preferences = &s2n_signature_preferences_20250821,
454 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
455 : : };
456 : :
457 : : const struct s2n_security_policy security_policy_cloudfront_upstream_2025_08_08_tls13_pq = {
458 : : .minimum_protocol_version = S2N_TLS13,
459 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08_tls13,
460 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
461 : : .signature_preferences = &s2n_signature_preferences_20250821,
462 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
463 : : };
464 : :
465 : : /* CloudFront viewer facing */
466 : : const struct s2n_security_policy security_policy_cloudfront_ssl_v_3 = {
467 : : .minimum_protocol_version = S2N_SSLv3,
468 : : .cipher_preferences = &cipher_preferences_cloudfront_ssl_v_3,
469 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
470 : : .signature_preferences = &s2n_signature_preferences_20200207,
471 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
472 : : };
473 : :
474 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2014 = {
475 : : .minimum_protocol_version = S2N_TLS10,
476 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2014,
477 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
478 : : .signature_preferences = &s2n_signature_preferences_20200207,
479 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
480 : : };
481 : :
482 : : /* Same as security_policy_cloudfront_tls_1_0_2014, but with IETF standard KEM Groups */
483 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2014_pq_beta = {
484 : : .minimum_protocol_version = S2N_TLS10,
485 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2014,
486 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
487 : : .signature_preferences = &s2n_signature_preferences_20200207,
488 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
489 : : };
490 : :
491 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2014_sha256 = {
492 : : .minimum_protocol_version = S2N_TLS10,
493 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2014_sha256,
494 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
495 : : .signature_preferences = &s2n_signature_preferences_20200207,
496 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
497 : : };
498 : :
499 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2016 = {
500 : : .minimum_protocol_version = S2N_TLS10,
501 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2016,
502 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
503 : : .signature_preferences = &s2n_signature_preferences_20200207,
504 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
505 : : };
506 : :
507 : : /* Same as security_policy_cloudfront_tls_1_0_2016, but with TLS 1.2 as minimum */
508 : : const struct s2n_security_policy security_policy_20241106 = {
509 : : .minimum_protocol_version = S2N_TLS12,
510 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2016,
511 : : .kem_preferences = &kem_preferences_null,
512 : : .signature_preferences = &s2n_signature_preferences_20200207,
513 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
514 : : };
515 : :
516 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_1_2016 = {
517 : : .minimum_protocol_version = S2N_TLS11,
518 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_1_2016,
519 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
520 : : .signature_preferences = &s2n_signature_preferences_20200207,
521 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
522 : : };
523 : :
524 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2017 = {
525 : : .minimum_protocol_version = S2N_TLS12,
526 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2017,
527 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
528 : : .signature_preferences = &s2n_signature_preferences_20200207,
529 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
530 : : };
531 : :
532 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2018_no_sha1 = {
533 : : .minimum_protocol_version = S2N_TLS12,
534 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2018,
535 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
536 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
537 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
538 : : };
539 : :
540 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2018_beta = {
541 : : .minimum_protocol_version = S2N_TLS12,
542 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2018_beta,
543 : : .kem_preferences = &kem_preferences_null,
544 : : .signature_preferences = &s2n_signature_preferences_20200207,
545 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
546 : : };
547 : :
548 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2019_no_sha1 = {
549 : : .minimum_protocol_version = S2N_TLS12,
550 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019,
551 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
552 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
553 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
554 : : .rules = {
555 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
556 : : },
557 : : };
558 : :
559 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2021_no_sha1 = {
560 : : .minimum_protocol_version = S2N_TLS12,
561 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2021,
562 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
563 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
564 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
565 : : .rules = {
566 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
567 : : },
568 : : };
569 : :
570 : : /* Same as security_policy_cloudfront_tls_1_2_2021_no_sha1, but with IETF standard KEM Groups */
571 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2021_no_sha1_pq_beta = {
572 : : .minimum_protocol_version = S2N_TLS12,
573 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2021,
574 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
575 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
576 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
577 : : .rules = {
578 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
579 : : },
580 : : };
581 : :
582 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2021_chacha20_boosted = {
583 : : .minimum_protocol_version = S2N_TLS12,
584 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2021_chacha20_boosted,
585 : : .kem_preferences = &kem_preferences_null,
586 : : .signature_preferences = &s2n_signature_preferences_20200207,
587 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
588 : : .rules = {
589 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
590 : : },
591 : : };
592 : :
593 : : /* FIPS 140-3 compliant version of security_policy_cloudfront_tls_1_2_2021 */
594 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2025 = {
595 : : .minimum_protocol_version = S2N_TLS12,
596 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2025,
597 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
598 : : .signature_preferences = &s2n_signature_preferences_20250813,
599 : : .ecc_preferences = &s2n_ecc_preferences_default_fips,
600 : : .rules = {
601 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
602 : : [S2N_FIPS_140_3] = true,
603 : : },
604 : : };
605 : :
606 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_3_2025 = {
607 : : .minimum_protocol_version = S2N_TLS13,
608 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_3_2025,
609 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
610 : : .signature_preferences = &s2n_signature_preferences_20250813,
611 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
612 : : .rules = {
613 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
614 : : },
615 : : };
616 : :
617 : : /* CloudFront non-pq viewer facing policies */
618 : : const struct s2n_security_policy security_policy_cloudfront_ssl_v_3_no_pq = {
619 : : .minimum_protocol_version = S2N_SSLv3,
620 : : .cipher_preferences = &cipher_preferences_cloudfront_ssl_v_3,
621 : : .kem_preferences = &kem_preferences_null,
622 : : .signature_preferences = &s2n_signature_preferences_20200207,
623 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
624 : : };
625 : :
626 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2014_no_pq = {
627 : : .minimum_protocol_version = S2N_TLS10,
628 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2014,
629 : : .kem_preferences = &kem_preferences_null,
630 : : .signature_preferences = &s2n_signature_preferences_20200207,
631 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
632 : : };
633 : :
634 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2014_sha256_no_pq = {
635 : : .minimum_protocol_version = S2N_TLS10,
636 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2014_sha256,
637 : : .kem_preferences = &kem_preferences_null,
638 : : .signature_preferences = &s2n_signature_preferences_20200207,
639 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
640 : : };
641 : :
642 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2016_no_pq = {
643 : : .minimum_protocol_version = S2N_TLS10,
644 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2016,
645 : : .kem_preferences = &kem_preferences_null,
646 : : .signature_preferences = &s2n_signature_preferences_20200207,
647 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
648 : : };
649 : :
650 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_1_2016_no_pq = {
651 : : .minimum_protocol_version = S2N_TLS11,
652 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_1_2016,
653 : : .kem_preferences = &kem_preferences_null,
654 : : .signature_preferences = &s2n_signature_preferences_20200207,
655 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
656 : : };
657 : :
658 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2017_no_pq = {
659 : : .minimum_protocol_version = S2N_TLS12,
660 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2017,
661 : : .kem_preferences = &kem_preferences_null,
662 : : .signature_preferences = &s2n_signature_preferences_20200207,
663 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
664 : : };
665 : :
666 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2018_no_sha1_no_pq = {
667 : : .minimum_protocol_version = S2N_TLS12,
668 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2018,
669 : : .kem_preferences = &kem_preferences_null,
670 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
671 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
672 : : };
673 : :
674 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2019_no_sha1_no_pq = {
675 : : .minimum_protocol_version = S2N_TLS12,
676 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019,
677 : : .kem_preferences = &kem_preferences_null,
678 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
679 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
680 : : .rules = {
681 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
682 : : },
683 : : };
684 : :
685 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2021_no_sha1_no_pq = {
686 : : .minimum_protocol_version = S2N_TLS12,
687 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2021,
688 : : .kem_preferences = &kem_preferences_null,
689 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
690 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
691 : : .rules = {
692 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
693 : : },
694 : : };
695 : :
696 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2025_no_pq = {
697 : : .minimum_protocol_version = S2N_TLS12,
698 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2025,
699 : : .kem_preferences = &kem_preferences_null,
700 : : .signature_preferences = &s2n_signature_preferences_20250813,
701 : : .ecc_preferences = &s2n_ecc_preferences_default_fips,
702 : : .rules = {
703 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
704 : : [S2N_FIPS_140_3] = true,
705 : : },
706 : : };
707 : :
708 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_3_2025_no_pq = {
709 : : .minimum_protocol_version = S2N_TLS13,
710 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_3_2025,
711 : : .kem_preferences = &kem_preferences_null,
712 : : .signature_preferences = &s2n_signature_preferences_20250813,
713 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
714 : : .rules = {
715 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
716 : : },
717 : : };
718 : :
719 : : /* CloudFront viewer facing legacy policies */
720 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2018 = {
721 : : .minimum_protocol_version = S2N_TLS12,
722 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2018,
723 : : .kem_preferences = &kem_preferences_null,
724 : : .signature_preferences = &s2n_signature_preferences_20200207,
725 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
726 : : };
727 : :
728 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2019 = {
729 : : .minimum_protocol_version = S2N_TLS12,
730 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019,
731 : : .kem_preferences = &kem_preferences_null,
732 : : .signature_preferences = &s2n_signature_preferences_20200207,
733 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
734 : : .rules = {
735 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
736 : : },
737 : : };
738 : :
739 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2021 = {
740 : : .minimum_protocol_version = S2N_TLS12,
741 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2021,
742 : : .kem_preferences = &kem_preferences_null,
743 : : .signature_preferences = &s2n_signature_preferences_20200207,
744 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
745 : : .rules = {
746 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
747 : : },
748 : : };
749 : :
750 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2021_pq = {
751 : : .minimum_protocol_version = S2N_TLS12,
752 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2021,
753 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
754 : : .signature_preferences = &s2n_signature_preferences_20200207,
755 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
756 : : .rules = {
757 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
758 : : },
759 : : };
760 : :
761 : : const struct s2n_security_policy security_policy_cloudfront_ssl_v_3_legacy = {
762 : : .minimum_protocol_version = S2N_SSLv3,
763 : : .cipher_preferences = &cipher_preferences_cloudfront_ssl_v_3_legacy,
764 : : .kem_preferences = &kem_preferences_null,
765 : : .signature_preferences = &s2n_signature_preferences_20140601,
766 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
767 : : };
768 : :
769 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2014_legacy = {
770 : : .minimum_protocol_version = S2N_TLS10,
771 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2014_legacy,
772 : : .kem_preferences = &kem_preferences_null,
773 : : .signature_preferences = &s2n_signature_preferences_20140601,
774 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
775 : : };
776 : :
777 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_0_2016_legacy = {
778 : : .minimum_protocol_version = S2N_TLS10,
779 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_0_2016_legacy,
780 : : .kem_preferences = &kem_preferences_null,
781 : : .signature_preferences = &s2n_signature_preferences_20140601,
782 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
783 : : };
784 : :
785 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_1_2016_legacy = {
786 : : .minimum_protocol_version = S2N_TLS11,
787 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_1_2016_legacy,
788 : : .kem_preferences = &kem_preferences_null,
789 : : .signature_preferences = &s2n_signature_preferences_20140601,
790 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
791 : : };
792 : :
793 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2018_legacy = {
794 : : .minimum_protocol_version = S2N_TLS12,
795 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2018_legacy,
796 : : .kem_preferences = &kem_preferences_null,
797 : : .signature_preferences = &s2n_signature_preferences_20140601,
798 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
799 : : };
800 : :
801 : : const struct s2n_security_policy security_policy_cloudfront_tls_1_2_2019_legacy = {
802 : : .minimum_protocol_version = S2N_TLS12,
803 : : .cipher_preferences = &cipher_preferences_cloudfront_tls_1_2_2019_legacy,
804 : : .kem_preferences = &kem_preferences_null,
805 : : .signature_preferences = &s2n_signature_preferences_20140601,
806 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
807 : : .rules = {
808 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
809 : : },
810 : : };
811 : :
812 : : const struct s2n_security_policy security_policy_aws_crt_sdk_ssl_v3 = {
813 : : .minimum_protocol_version = S2N_SSLv3,
814 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_ssl_v3,
815 : : .kem_preferences = &kem_preferences_null,
816 : : .signature_preferences = &s2n_signature_preferences_20200207,
817 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
818 : : };
819 : :
820 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_10 = {
821 : : .minimum_protocol_version = S2N_TLS10,
822 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
823 : : .kem_preferences = &kem_preferences_null,
824 : : .signature_preferences = &s2n_signature_preferences_20200207,
825 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
826 : : };
827 : :
828 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_11 = {
829 : : .minimum_protocol_version = S2N_TLS11,
830 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
831 : : .kem_preferences = &kem_preferences_null,
832 : : .signature_preferences = &s2n_signature_preferences_20200207,
833 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
834 : : };
835 : :
836 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_12 = {
837 : : .minimum_protocol_version = S2N_TLS12,
838 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
839 : : .kem_preferences = &kem_preferences_null,
840 : : .signature_preferences = &s2n_signature_preferences_20200207,
841 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
842 : : };
843 : :
844 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_13 = {
845 : : .minimum_protocol_version = S2N_TLS13,
846 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_tls_13,
847 : : .kem_preferences = &kem_preferences_null,
848 : : .signature_preferences = &s2n_signature_preferences_20200207,
849 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
850 : : .rules = {
851 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
852 : : },
853 : : };
854 : :
855 : : const struct s2n_security_policy security_policy_aws_crt_sdk_ssl_v3_06_23 = {
856 : : .minimum_protocol_version = S2N_SSLv3,
857 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_ssl_v3,
858 : : .kem_preferences = &kem_preferences_null,
859 : : .signature_preferences = &s2n_signature_preferences_20200207,
860 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
861 : : };
862 : :
863 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_10_06_23 = {
864 : : .minimum_protocol_version = S2N_TLS10,
865 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
866 : : .kem_preferences = &kem_preferences_null,
867 : : .signature_preferences = &s2n_signature_preferences_20200207,
868 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
869 : : };
870 : :
871 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_11_06_23 = {
872 : : .minimum_protocol_version = S2N_TLS11,
873 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
874 : : .kem_preferences = &kem_preferences_null,
875 : : .signature_preferences = &s2n_signature_preferences_20200207,
876 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
877 : : };
878 : :
879 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_12_06_23 = {
880 : : .minimum_protocol_version = S2N_TLS12,
881 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
882 : : .kem_preferences = &kem_preferences_null,
883 : : .signature_preferences = &s2n_signature_preferences_20200207,
884 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
885 : : };
886 : :
887 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_30_06_25 = {
888 : : .minimum_protocol_version = S2N_TLS12,
889 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_2025,
890 : : .kem_preferences = &kem_preferences_null,
891 : : .signature_preferences = &s2n_signature_preferences_20240501,
892 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
893 : : .rules = {
894 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
895 : : [S2N_FIPS_140_3] = true,
896 : : },
897 : : };
898 : :
899 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_13_06_23 = {
900 : : .minimum_protocol_version = S2N_TLS13,
901 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_tls_13,
902 : : .kem_preferences = &kem_preferences_null,
903 : : .signature_preferences = &s2n_signature_preferences_20200207,
904 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
905 : : .rules = {
906 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
907 : : },
908 : : };
909 : :
910 : : const struct s2n_security_policy security_policy_kms_tls_1_0_2018_10 = {
911 : : .minimum_protocol_version = S2N_TLS10,
912 : : .cipher_preferences = &cipher_preferences_kms_tls_1_0_2018_10,
913 : : .kem_preferences = &kem_preferences_null,
914 : : .signature_preferences = &s2n_signature_preferences_20140601,
915 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
916 : : .rules = {
917 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
918 : : },
919 : : };
920 : :
921 : : const struct s2n_security_policy security_policy_kms_tls_1_0_2021_08 = {
922 : : .minimum_protocol_version = S2N_TLS10,
923 : : .cipher_preferences = &cipher_preferences_kms_tls_1_0_2021_08,
924 : : .kem_preferences = &kem_preferences_null,
925 : : .signature_preferences = &s2n_signature_preferences_20200207,
926 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
927 : : .rules = {
928 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
929 : : },
930 : : };
931 : :
932 : : const struct s2n_security_policy security_policy_kms_tls_1_2_2023_06 = {
933 : : .minimum_protocol_version = S2N_TLS12,
934 : : .cipher_preferences = &cipher_preferences_kms_tls_1_0_2021_08,
935 : : .kem_preferences = &kem_preferences_null,
936 : : .signature_preferences = &s2n_signature_preferences_20200207,
937 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
938 : : .rules = {
939 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
940 : : },
941 : : };
942 : :
943 : : /* Same as security_policy_aws_crt_sdk_tls_10_06_23 but with (IETF-standardized) ML-KEM Support */
944 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_10_07_25_pq = {
945 : : .minimum_protocol_version = S2N_TLS10,
946 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
947 : : .kem_preferences = &kem_preferences_all,
948 : : .signature_preferences = &s2n_signature_preferences_20200207,
949 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
950 : : };
951 : :
952 : : /* Same as security_policy_aws_crt_sdk_tls_12_06_23 but with (IETF-standardized) ML-KEM Support */
953 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_12_07_25_pq = {
954 : : .minimum_protocol_version = S2N_TLS12,
955 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
956 : : .kem_preferences = &kem_preferences_all,
957 : : .signature_preferences = &s2n_signature_preferences_20200207,
958 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
959 : : };
960 : :
961 : : /* Same as security_policy_aws_crt_sdk_tls_13_06_23 but with (IETF-standardized) ML-KEM Support */
962 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_13_07_25_pq = {
963 : : .minimum_protocol_version = S2N_TLS13,
964 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_tls_13,
965 : : .kem_preferences = &kem_preferences_all,
966 : : .signature_preferences = &s2n_signature_preferences_20200207,
967 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
968 : : };
969 : :
970 : : /* Same as security_policy_aws_crt_sdk_tls_12_06_23 but with ML-KEM Support */
971 : : const struct s2n_security_policy security_policy_aws_crt_sdk_tls_12_06_23_pq = {
972 : : .minimum_protocol_version = S2N_TLS12,
973 : : .cipher_preferences = &cipher_preferences_aws_crt_sdk_default,
974 : : .kem_preferences = &kem_preferences_all,
975 : : .signature_preferences = &s2n_signature_preferences_20200207,
976 : : .ecc_preferences = &s2n_ecc_preferences_20230623,
977 : : };
978 : :
979 : : /* Same as security_policy_pq_tls_1_2_2023_10_07, but with ML-KEM support */
980 : : const struct s2n_security_policy security_policy_pq_tls_1_2_2024_10_07 = {
981 : : .minimum_protocol_version = S2N_TLS12,
982 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext2_2021_06,
983 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
984 : : .signature_preferences = &s2n_signature_preferences_20200207,
985 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
986 : : };
987 : :
988 : : /* Same as security_policy_pq_tls_1_2_2023_10_08, but with 3DES removed, and added ML-KEM support */
989 : : const struct s2n_security_policy security_policy_pq_tls_1_2_2024_10_08 = {
990 : : .minimum_protocol_version = S2N_TLS12,
991 : : .cipher_preferences = &cipher_preferences_20241008,
992 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
993 : : .signature_preferences = &s2n_signature_preferences_20200207,
994 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
995 : : };
996 : :
997 : : /* Same as security_policy_pq_tls_1_2_2023_10_10, but with 3DES removed, and added ML-KEM support */
998 : : const struct s2n_security_policy security_policy_pq_tls_1_2_2024_10_08_gcm = {
999 : : .minimum_protocol_version = S2N_TLS12,
1000 : : .cipher_preferences = &cipher_preferences_20241008_gcm,
1001 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1002 : : .signature_preferences = &s2n_signature_preferences_20200207,
1003 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
1004 : : };
1005 : :
1006 : : /* Same as security_policy_pq_tls_1_2_2023_10_09 but with 3DES removed, and added ML-KEM support */
1007 : : const struct s2n_security_policy security_policy_pq_tls_1_2_2024_10_09 = {
1008 : : .minimum_protocol_version = S2N_TLS12,
1009 : : .cipher_preferences = &cipher_preferences_20241009,
1010 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1011 : : .signature_preferences = &s2n_signature_preferences_20200207,
1012 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
1013 : : .rules = {
1014 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1015 : : },
1016 : : };
1017 : : const struct s2n_security_policy security_policy_kms_fips_tls_1_2_2018_10 = {
1018 : : .minimum_protocol_version = S2N_TLS12,
1019 : : .cipher_preferences = &cipher_preferences_kms_fips_tls_1_2_2018_10,
1020 : : .kem_preferences = &kem_preferences_null,
1021 : : .signature_preferences = &s2n_signature_preferences_20140601,
1022 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1023 : : .rules = {
1024 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1025 : : },
1026 : : };
1027 : :
1028 : : const struct s2n_security_policy security_policy_kms_fips_tls_1_2_2021_08 = {
1029 : : .minimum_protocol_version = S2N_TLS12,
1030 : : .cipher_preferences = &cipher_preferences_kms_fips_tls_1_2_2021_08,
1031 : : .kem_preferences = &kem_preferences_null,
1032 : : .signature_preferences = &s2n_signature_preferences_20200207,
1033 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1034 : : .rules = {
1035 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1036 : : },
1037 : : };
1038 : :
1039 : : /* Same as security_policy_pq_20231215, but with only ML-KEM Support */
1040 : : const struct s2n_security_policy security_policy_kms_fips_tls_1_2_2024_10 = {
1041 : : .minimum_protocol_version = S2N_TLS12,
1042 : : .cipher_preferences = &cipher_preferences_kms_fips_tls_1_2_2021_08,
1043 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1044 : : .signature_preferences = &s2n_signature_preferences_20230317,
1045 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1046 : : .rules = {
1047 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1048 : : [S2N_FIPS_140_3] = true,
1049 : : },
1050 : : };
1051 : :
1052 : : const struct s2n_security_policy security_policy_20140601 = {
1053 : : .minimum_protocol_version = S2N_SSLv3,
1054 : : .cipher_preferences = &cipher_preferences_20140601,
1055 : : .kem_preferences = &kem_preferences_null,
1056 : : .signature_preferences = &s2n_signature_preferences_20140601,
1057 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1058 : : };
1059 : :
1060 : : const struct s2n_security_policy security_policy_20141001 = {
1061 : : .minimum_protocol_version = S2N_TLS10,
1062 : : .cipher_preferences = &cipher_preferences_20141001,
1063 : : .kem_preferences = &kem_preferences_null,
1064 : : .signature_preferences = &s2n_signature_preferences_20140601,
1065 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1066 : : };
1067 : :
1068 : : const struct s2n_security_policy security_policy_20150202 = {
1069 : : .minimum_protocol_version = S2N_TLS10,
1070 : : .cipher_preferences = &cipher_preferences_20150202,
1071 : : .kem_preferences = &kem_preferences_null,
1072 : : .signature_preferences = &s2n_signature_preferences_20140601,
1073 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1074 : : };
1075 : :
1076 : : const struct s2n_security_policy security_policy_20150214 = {
1077 : : .minimum_protocol_version = S2N_TLS10,
1078 : : .cipher_preferences = &cipher_preferences_20150214,
1079 : : .kem_preferences = &kem_preferences_null,
1080 : : .signature_preferences = &s2n_signature_preferences_20140601,
1081 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1082 : : };
1083 : :
1084 : : const struct s2n_security_policy security_policy_20160411 = {
1085 : : .minimum_protocol_version = S2N_TLS10,
1086 : : .cipher_preferences = &cipher_preferences_20160411,
1087 : : .kem_preferences = &kem_preferences_null,
1088 : : .signature_preferences = &s2n_signature_preferences_20140601,
1089 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1090 : : };
1091 : :
1092 : : const struct s2n_security_policy security_policy_20150306 = {
1093 : : .minimum_protocol_version = S2N_TLS10,
1094 : : .cipher_preferences = &cipher_preferences_20150306,
1095 : : .kem_preferences = &kem_preferences_null,
1096 : : .signature_preferences = &s2n_signature_preferences_20140601,
1097 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1098 : : };
1099 : :
1100 : : const struct s2n_security_policy security_policy_20160804 = {
1101 : : .minimum_protocol_version = S2N_TLS10,
1102 : : .cipher_preferences = &cipher_preferences_20160804,
1103 : : .kem_preferences = &kem_preferences_null,
1104 : : .signature_preferences = &s2n_signature_preferences_20140601,
1105 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1106 : : };
1107 : :
1108 : : const struct s2n_security_policy security_policy_20160824 = {
1109 : : .minimum_protocol_version = S2N_TLS10,
1110 : : .cipher_preferences = &cipher_preferences_20160824,
1111 : : .kem_preferences = &kem_preferences_null,
1112 : : .signature_preferences = &s2n_signature_preferences_20140601,
1113 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1114 : : };
1115 : :
1116 : : const struct s2n_security_policy security_policy_20190122 = {
1117 : : .minimum_protocol_version = S2N_TLS10,
1118 : : .cipher_preferences = &cipher_preferences_20190122,
1119 : : .kem_preferences = &kem_preferences_null,
1120 : : .signature_preferences = &s2n_signature_preferences_20140601,
1121 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1122 : : };
1123 : :
1124 : : const struct s2n_security_policy security_policy_20190121 = {
1125 : : .minimum_protocol_version = S2N_TLS10,
1126 : : .cipher_preferences = &cipher_preferences_20190121,
1127 : : .kem_preferences = &kem_preferences_null,
1128 : : .signature_preferences = &s2n_signature_preferences_20140601,
1129 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1130 : : };
1131 : :
1132 : : const struct s2n_security_policy security_policy_20190120 = {
1133 : : .minimum_protocol_version = S2N_TLS10,
1134 : : .cipher_preferences = &cipher_preferences_20190120,
1135 : : .kem_preferences = &kem_preferences_null,
1136 : : .signature_preferences = &s2n_signature_preferences_20140601,
1137 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1138 : : };
1139 : :
1140 : : const struct s2n_security_policy security_policy_20190214 = {
1141 : : .minimum_protocol_version = S2N_TLS10,
1142 : : .cipher_preferences = &cipher_preferences_20190214,
1143 : : .kem_preferences = &kem_preferences_null,
1144 : : .signature_preferences = &s2n_signature_preferences_20140601,
1145 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1146 : : };
1147 : :
1148 : : const struct s2n_security_policy security_policy_20190214_gcm = {
1149 : : .minimum_protocol_version = S2N_TLS10,
1150 : : .cipher_preferences = &cipher_preferences_20190214_gcm,
1151 : : .kem_preferences = &kem_preferences_null,
1152 : : .signature_preferences = &s2n_signature_preferences_20140601,
1153 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1154 : : };
1155 : :
1156 : : const struct s2n_security_policy security_policy_20210825 = {
1157 : : .minimum_protocol_version = S2N_TLS10,
1158 : : .cipher_preferences = &cipher_preferences_20210825,
1159 : : .kem_preferences = &kem_preferences_null,
1160 : : .signature_preferences = &s2n_signature_preferences_20200207,
1161 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
1162 : : };
1163 : :
1164 : : const struct s2n_security_policy security_policy_20210825_gcm = {
1165 : : .minimum_protocol_version = S2N_TLS10,
1166 : : .cipher_preferences = &cipher_preferences_20210825_gcm,
1167 : : .kem_preferences = &kem_preferences_null,
1168 : : .signature_preferences = &s2n_signature_preferences_20200207,
1169 : : .ecc_preferences = &s2n_ecc_preferences_20200310,
1170 : : };
1171 : :
1172 : : const struct s2n_security_policy security_policy_20170328 = {
1173 : : .minimum_protocol_version = S2N_TLS10,
1174 : : .cipher_preferences = &cipher_preferences_20170328,
1175 : : .kem_preferences = &kem_preferences_null,
1176 : : .signature_preferences = &s2n_signature_preferences_20140601,
1177 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1178 : : };
1179 : :
1180 : : const struct s2n_security_policy security_policy_20170328_gcm = {
1181 : : .minimum_protocol_version = S2N_TLS10,
1182 : : .cipher_preferences = &cipher_preferences_20170328_gcm,
1183 : : .kem_preferences = &kem_preferences_null,
1184 : : .signature_preferences = &s2n_signature_preferences_20140601,
1185 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1186 : : };
1187 : :
1188 : : const struct s2n_security_policy security_policy_20170718 = {
1189 : : .minimum_protocol_version = S2N_TLS10,
1190 : : .cipher_preferences = &cipher_preferences_20170718,
1191 : : .kem_preferences = &kem_preferences_null,
1192 : : .signature_preferences = &s2n_signature_preferences_20140601,
1193 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1194 : : };
1195 : :
1196 : : const struct s2n_security_policy security_policy_20170718_gcm = {
1197 : : .minimum_protocol_version = S2N_TLS10,
1198 : : .cipher_preferences = &cipher_preferences_20170718_gcm,
1199 : : .kem_preferences = &kem_preferences_null,
1200 : : .signature_preferences = &s2n_signature_preferences_20140601,
1201 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1202 : : };
1203 : :
1204 : : const struct s2n_security_policy security_policy_20201021 = {
1205 : : .minimum_protocol_version = S2N_TLS10,
1206 : : .cipher_preferences = &cipher_preferences_20190122,
1207 : : .kem_preferences = &kem_preferences_null,
1208 : : .signature_preferences = &s2n_signature_preferences_20201021,
1209 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1210 : : };
1211 : :
1212 : : const struct s2n_security_policy security_policy_20210816 = {
1213 : : .minimum_protocol_version = S2N_TLS12,
1214 : : .cipher_preferences = &cipher_preferences_20210816,
1215 : : .kem_preferences = &kem_preferences_null,
1216 : : .signature_preferences = &s2n_signature_preferences_20210816,
1217 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1218 : : .rules = {
1219 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1220 : : [S2N_FIPS_140_3] = true,
1221 : : },
1222 : : };
1223 : :
1224 : : const struct s2n_security_policy security_policy_20210816_gcm = {
1225 : : .minimum_protocol_version = S2N_TLS12,
1226 : : .cipher_preferences = &cipher_preferences_20210816_gcm,
1227 : : .kem_preferences = &kem_preferences_null,
1228 : : .signature_preferences = &s2n_signature_preferences_20210816,
1229 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1230 : : .rules = {
1231 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1232 : : [S2N_FIPS_140_3] = true,
1233 : : },
1234 : : };
1235 : :
1236 : : /*
1237 : : * This security policy is derived from the following specification:
1238 : : * https://datatracker.ietf.org/doc/html/rfc9151
1239 : : */
1240 : : const struct s2n_security_policy security_policy_20250429 = {
1241 : : .minimum_protocol_version = S2N_TLS12,
1242 : : .cipher_preferences = &cipher_preferences_20250429,
1243 : : .kem_preferences = &kem_preferences_null,
1244 : : .signature_preferences = &s2n_signature_preferences_20250429,
1245 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250429,
1246 : : .certificate_key_preferences = &s2n_certificate_key_preferences_20250429,
1247 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1248 : : .certificate_preferences_apply_locally = true,
1249 : : };
1250 : :
1251 : : /*
1252 : : * This security policy is derived from the following specification:
1253 : : * https://datatracker.ietf.org/doc/html/rfc9151
1254 : : *
1255 : : * The following exceptions to this specification are made:
1256 : : * - RSA cipher suites are not supported to allow for perfect forward secrecy.
1257 : : * - DHE cipher suites are not supported to remove the possibility of improper Diffie-Hellman
1258 : : * parameter configuration.
1259 : : */
1260 : : const struct s2n_security_policy security_policy_20251013 = {
1261 : : .minimum_protocol_version = S2N_TLS12,
1262 : : .cipher_preferences = &cipher_preferences_20251013,
1263 : : .kem_preferences = &kem_preferences_null,
1264 : : .signature_preferences = &s2n_signature_preferences_20250429,
1265 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250429,
1266 : : .certificate_key_preferences = &s2n_certificate_key_preferences_20250429,
1267 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1268 : : .certificate_preferences_apply_locally = true,
1269 : : .rules = {
1270 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1271 : : [S2N_FIPS_140_3] = true,
1272 : : },
1273 : : };
1274 : :
1275 : : /*
1276 : : * This security policy is a mix of default_tls13 (20240503) and rfc9151, with
1277 : : * a primary requirement that AES-256 is the ciphersuite chosen. Other
1278 : : * requirements are generally picked to raise minimum thresholds (e.g.,
1279 : : * requiring TLS 1.3) where possible without losing compatibility with modern
1280 : : * default_tls13 clients or servers.
1281 : : */
1282 : : const struct s2n_security_policy security_policy_20250211 = {
1283 : : .minimum_protocol_version = S2N_TLS13,
1284 : : .cipher_preferences = &cipher_preferences_20250211,
1285 : : .kem_preferences = &kem_preferences_null,
1286 : : .signature_preferences = &s2n_signature_preferences_20250429,
1287 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
1288 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1289 : : .rules = {
1290 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1291 : : },
1292 : : };
1293 : :
1294 : : /*
1295 : : * This is essentially identical to 20250211, but fixes a bug which required
1296 : : * P-384 keys on certificates, which invalidated the compatibility promise for
1297 : : * that policy.
1298 : : */
1299 : : const struct s2n_security_policy security_policy_20250414 = {
1300 : : .minimum_protocol_version = S2N_TLS13,
1301 : : .cipher_preferences = &cipher_preferences_20250211,
1302 : : .kem_preferences = &kem_preferences_null,
1303 : : .signature_preferences = &s2n_signature_preferences_20240501,
1304 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20201110,
1305 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1306 : : .rules = {
1307 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1308 : : [S2N_FIPS_140_3] = true,
1309 : : },
1310 : : };
1311 : :
1312 : : const struct s2n_security_policy security_policy_20251113 = {
1313 : : .minimum_protocol_version = S2N_TLS12,
1314 : : .cipher_preferences = &cipher_preferences_20251113,
1315 : : .kem_preferences = &kem_preferences_null,
1316 : : .signature_preferences = &s2n_signature_preferences_20251113,
1317 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20251113,
1318 : : .ecc_preferences = &s2n_ecc_preferences_20251113,
1319 : : .strongly_preferred_groups = &cnsa_1_strong_preference,
1320 : : };
1321 : :
1322 : : const struct s2n_security_policy security_policy_20251114 = {
1323 : : .minimum_protocol_version = S2N_TLS12,
1324 : : .cipher_preferences = &cipher_preferences_20251114,
1325 : : .kem_preferences = &kem_preferences_null,
1326 : : .signature_preferences = &s2n_signature_preferences_20251113,
1327 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20251113,
1328 : : .ecc_preferences = &s2n_ecc_preferences_20251113,
1329 : : .strongly_preferred_groups = &cnsa_1_strong_preference,
1330 : : };
1331 : :
1332 : : const struct s2n_security_policy security_policy_20251115 = {
1333 : : .minimum_protocol_version = S2N_TLS12,
1334 : : .cipher_preferences = &cipher_preferences_20251115,
1335 : : .kem_preferences = &kem_preferences_null,
1336 : : .signature_preferences = &s2n_signature_preferences_20251113,
1337 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20251113,
1338 : : .ecc_preferences = &s2n_ecc_preferences_20251113,
1339 : : .strongly_preferred_groups = &cnsa_1_strong_preference,
1340 : : };
1341 : :
1342 : : const struct s2n_security_policy security_policy_20251116 = {
1343 : : .minimum_protocol_version = S2N_TLS10,
1344 : : .cipher_preferences = &cipher_preferences_20251116,
1345 : : .kem_preferences = &kem_preferences_null,
1346 : : .signature_preferences = &s2n_signature_preferences_20251113,
1347 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20251113,
1348 : : .ecc_preferences = &s2n_ecc_preferences_20251113,
1349 : : .strongly_preferred_groups = &cnsa_1_strong_preference,
1350 : : };
1351 : :
1352 : : const struct s2n_security_policy security_policy_20251117 = {
1353 : : .minimum_protocol_version = S2N_TLS12,
1354 : : .cipher_preferences = &cipher_preferences_20251117,
1355 : : .kem_preferences = &kem_preferences_null,
1356 : : .signature_preferences = &s2n_signature_preferences_20251113,
1357 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20251113,
1358 : : .ecc_preferences = &s2n_ecc_preferences_20251113,
1359 : : .strongly_preferred_groups = &cnsa_1_strong_preference,
1360 : : };
1361 : :
1362 : : /* strict CNSA 2.0 policy */
1363 : : const struct s2n_security_policy security_policy_20260219 = {
1364 : : .minimum_protocol_version = S2N_TLS13,
1365 : : .cipher_preferences = &cipher_preferences_20250211,
1366 : : .kem_preferences = &kem_preferences_pq_tls_1_3_cnsa2_2026_02,
1367 : : .signature_preferences = &s2n_signature_preferences_20260219,
1368 : : .certificate_signature_preferences = &s2n_signature_preferences_20260219,
1369 : : .certificate_key_preferences = &s2n_certificate_key_preferences_20260219,
1370 : : .ecc_preferences = &s2n_ecc_preferences_null,
1371 : : .certificate_preferences_apply_locally = true,
1372 : : .rules = {
1373 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1374 : : [S2N_FIPS_140_3] = true,
1375 : : },
1376 : : };
1377 : :
1378 : : /* CNSA 1.0 - 2.0 interop policy */
1379 : : const struct s2n_security_policy security_policy_20260220 = {
1380 : : .minimum_protocol_version = S2N_TLS12,
1381 : : .cipher_preferences = &cipher_preferences_20260220,
1382 : : .kem_preferences = &kem_preferences_pq_tls_1_3_cnsa2_2026_02,
1383 : : .signature_preferences = &s2n_signature_preferences_20260220,
1384 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20260220,
1385 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1386 : : .rules = {
1387 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1388 : : [S2N_FIPS_140_3] = true,
1389 : : },
1390 : : };
1391 : :
1392 : : /* TLS 1.3 only CNSA2 interop policy: remove TLS 1.2 ciphers from 20260220 */
1393 : : const struct s2n_security_policy security_policy_20260720 = {
1394 : : .minimum_protocol_version = S2N_TLS13,
1395 : : .cipher_preferences = &cipher_preferences_20250211,
1396 : : .kem_preferences = &kem_preferences_pq_tls_1_3_cnsa2_2026_02,
1397 : : .signature_preferences = &s2n_signature_preferences_20260220,
1398 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20260220,
1399 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1400 : : .rules = {
1401 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1402 : : [S2N_FIPS_140_3] = true,
1403 : : },
1404 : : };
1405 : :
1406 : : /* CNSA2 interop: add MLKEM1024 and ML-DSA-87 to 20251115 */
1407 : : const struct s2n_security_policy security_policy_20260722 = {
1408 : : .minimum_protocol_version = S2N_TLS12,
1409 : : .cipher_preferences = &cipher_preferences_20251115,
1410 : : .kem_preferences = &kem_preferences_pq_tls_1_3_cnsa2_2026_02,
1411 : : .signature_preferences = &s2n_signature_preferences_20260722,
1412 : : .certificate_signature_preferences = &s2n_signature_preferences_20260722,
1413 : : .ecc_preferences = &s2n_ecc_preferences_20251113,
1414 : : .strongly_preferred_groups = &cnsa_1_strong_preference,
1415 : : };
1416 : :
1417 : : /* 20250414 with pure MLKEM1024 and ML-DSA-87 added, interoperable with CNSA 2.0 */
1418 : : const struct s2n_security_policy security_policy_20260513 = {
1419 : : .minimum_protocol_version = S2N_TLS13,
1420 : : .cipher_preferences = &cipher_preferences_20250211,
1421 : : .kem_preferences = &kem_preferences_pq_tls_1_3_cnsa2_2026_02,
1422 : : .signature_preferences = &s2n_signature_preferences_20260513,
1423 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20260514,
1424 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1425 : : .rules = {
1426 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1427 : : [S2N_FIPS_140_3] = true,
1428 : : },
1429 : : };
1430 : :
1431 : : const struct s2n_security_policy security_policy_20260520 = {
1432 : : .minimum_protocol_version = S2N_TLS10,
1433 : : .cipher_preferences = &cipher_preferences_20260520,
1434 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1435 : : .signature_preferences = &s2n_signature_preferences_20201021,
1436 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1437 : : };
1438 : :
1439 : : const struct s2n_security_policy security_policy_20260520_gcm = {
1440 : : .minimum_protocol_version = S2N_TLS10,
1441 : : .cipher_preferences = &cipher_preferences_20260520_gcm,
1442 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1443 : : .signature_preferences = &s2n_signature_preferences_20201021,
1444 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1445 : : };
1446 : :
1447 : : const struct s2n_security_policy security_policy_20260521 = {
1448 : : .minimum_protocol_version = S2N_TLS12,
1449 : : .cipher_preferences = &cipher_preferences_20260521,
1450 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1451 : : .signature_preferences = &s2n_signature_preferences_20201021,
1452 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1453 : : };
1454 : :
1455 : : const struct s2n_security_policy security_policy_20260521_gcm = {
1456 : : .minimum_protocol_version = S2N_TLS12,
1457 : : .cipher_preferences = &cipher_preferences_20260521_gcm,
1458 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1459 : : .signature_preferences = &s2n_signature_preferences_20201021,
1460 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1461 : : };
1462 : :
1463 : : const struct s2n_security_policy security_policy_20260522 = {
1464 : : .minimum_protocol_version = S2N_TLS12,
1465 : : .cipher_preferences = &cipher_preferences_20260522,
1466 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1467 : : .signature_preferences = &s2n_signature_preferences_20201021,
1468 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1469 : : };
1470 : :
1471 : : const struct s2n_security_policy security_policy_20260522_gcm = {
1472 : : .minimum_protocol_version = S2N_TLS12,
1473 : : .cipher_preferences = &cipher_preferences_20260522_gcm,
1474 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1475 : : .signature_preferences = &s2n_signature_preferences_20201021,
1476 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1477 : : };
1478 : :
1479 : : const struct s2n_security_policy security_policy_20260523 = {
1480 : : .minimum_protocol_version = S2N_TLS12,
1481 : : .cipher_preferences = &cipher_preferences_20260523,
1482 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1483 : : .signature_preferences = &s2n_signature_preferences_20240521,
1484 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1485 : : };
1486 : :
1487 : : const struct s2n_security_policy security_policy_20260523_gcm = {
1488 : : .minimum_protocol_version = S2N_TLS12,
1489 : : .cipher_preferences = &cipher_preferences_20260523_gcm,
1490 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2024_10,
1491 : : .signature_preferences = &s2n_signature_preferences_20240521,
1492 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1493 : : };
1494 : :
1495 : : const struct s2n_security_policy security_policy_test_all = {
1496 : : .minimum_protocol_version = S2N_SSLv3,
1497 : : .cipher_preferences = &cipher_preferences_test_all,
1498 : : .kem_preferences = &kem_preferences_all,
1499 : : .signature_preferences = &s2n_signature_preferences_all,
1500 : : .ecc_preferences = &s2n_ecc_preferences_test_all,
1501 : : };
1502 : :
1503 : : const struct s2n_security_policy security_policy_test_all_tls12 = {
1504 : : .minimum_protocol_version = S2N_SSLv3,
1505 : : .cipher_preferences = &cipher_preferences_test_all_tls12,
1506 : : .kem_preferences = &kem_preferences_null,
1507 : : .signature_preferences = &s2n_signature_preferences_20201021,
1508 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1509 : : };
1510 : :
1511 : : const struct s2n_security_policy security_policy_test_all_fips = {
1512 : : .minimum_protocol_version = S2N_TLS12,
1513 : : .cipher_preferences = &cipher_preferences_test_all_fips,
1514 : : .kem_preferences = &kem_preferences_all,
1515 : : .signature_preferences = &s2n_signature_preferences_test_all_fips,
1516 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1517 : : .rules = {
1518 : : [S2N_FIPS_140_3] = true,
1519 : : },
1520 : : };
1521 : :
1522 : : const struct s2n_security_policy security_policy_test_all_ecdsa = {
1523 : : .minimum_protocol_version = S2N_TLS10,
1524 : : .cipher_preferences = &cipher_preferences_test_all_ecdsa,
1525 : : .kem_preferences = &kem_preferences_null,
1526 : : .signature_preferences = &s2n_signature_preferences_20201021,
1527 : : .ecc_preferences = &s2n_ecc_preferences_test_all,
1528 : : .rules = {
1529 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1530 : : },
1531 : : };
1532 : :
1533 : : const struct s2n_security_policy security_policy_test_all_rsa_kex = {
1534 : : .minimum_protocol_version = S2N_TLS10,
1535 : : .cipher_preferences = &cipher_preferences_test_all_rsa_kex,
1536 : : .kem_preferences = &kem_preferences_null,
1537 : : .signature_preferences = &s2n_signature_preferences_20140601,
1538 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1539 : : };
1540 : :
1541 : : const struct s2n_security_policy security_policy_test_all_tls13 = {
1542 : : .minimum_protocol_version = S2N_SSLv3,
1543 : : .cipher_preferences = &cipher_preferences_test_all_tls13,
1544 : : .kem_preferences = &kem_preferences_null,
1545 : : .signature_preferences = &s2n_signature_preferences_all,
1546 : : .ecc_preferences = &s2n_ecc_preferences_test_all,
1547 : : .rules = {
1548 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1549 : : },
1550 : : };
1551 : :
1552 : : const struct s2n_security_policy security_policy_test_pq_only = {
1553 : : .minimum_protocol_version = S2N_TLS13,
1554 : : .cipher_preferences = &cipher_preferences_cloudfront_upstream_2025_08_08_tls13,
1555 : : .kem_preferences = &kem_preferences_all,
1556 : : .signature_preferences = &s2n_signature_preferences_20240501,
1557 : : .certificate_signature_preferences = &s2n_signature_preferences_20240501,
1558 : : .ecc_preferences = &s2n_ecc_preferences_null,
1559 : : .rules = {
1560 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1561 : : },
1562 : : };
1563 : :
1564 : : const struct s2n_security_policy security_policy_20200207 = {
1565 : : .minimum_protocol_version = S2N_SSLv3,
1566 : : .cipher_preferences = &cipher_preferences_test_all_tls13,
1567 : : .kem_preferences = &kem_preferences_null,
1568 : : .signature_preferences = &s2n_signature_preferences_20201021,
1569 : : .ecc_preferences = &s2n_ecc_preferences_test_all,
1570 : : .rules = {
1571 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1572 : : },
1573 : : };
1574 : :
1575 : : const struct s2n_security_policy security_policy_20200207_pq = {
1576 : : .minimum_protocol_version = S2N_SSLv3,
1577 : : .cipher_preferences = &cipher_preferences_test_all_tls13,
1578 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1579 : : .signature_preferences = &s2n_signature_preferences_20201021,
1580 : : .ecc_preferences = &s2n_ecc_preferences_test_all,
1581 : : .rules = {
1582 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1583 : : },
1584 : : };
1585 : :
1586 : : const struct s2n_security_policy security_policy_test_ecdsa_priority = {
1587 : : .minimum_protocol_version = S2N_SSLv3,
1588 : : .cipher_preferences = &cipher_preferences_test_ecdsa_priority,
1589 : : .kem_preferences = &kem_preferences_null,
1590 : : .signature_preferences = &s2n_signature_preferences_20201021,
1591 : : .ecc_preferences = &s2n_ecc_preferences_test_all,
1592 : : };
1593 : :
1594 : : const struct s2n_security_policy security_policy_null = {
1595 : : .minimum_protocol_version = S2N_TLS10,
1596 : : .cipher_preferences = &cipher_preferences_null,
1597 : : .kem_preferences = &kem_preferences_null,
1598 : : .signature_preferences = &s2n_signature_preferences_null,
1599 : : .ecc_preferences = &s2n_ecc_preferences_null,
1600 : : };
1601 : :
1602 : : const struct s2n_security_policy security_policy_elb_backend_2016_08 = {
1603 : : .minimum_protocol_version = S2N_TLS10,
1604 : : .cipher_preferences = &elb_security_policy_backend_2016_08,
1605 : : .kem_preferences = &kem_preferences_null,
1606 : : .signature_preferences = &s2n_signature_preferences_20140601,
1607 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1608 : : };
1609 : :
1610 : : const struct s2n_security_policy security_policy_elb_sslv3_2013_12 = {
1611 : : .minimum_protocol_version = S2N_SSLv3,
1612 : : .cipher_preferences = &elb_security_policy_sslv3_2013_12,
1613 : : .kem_preferences = &kem_preferences_null,
1614 : : .signature_preferences = &s2n_signature_preferences_20140601,
1615 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1616 : : };
1617 : :
1618 : : const struct s2n_security_policy security_policy_elb_tls_1_1_Res_2017_01 = {
1619 : : .minimum_protocol_version = S2N_TLS11,
1620 : : .cipher_preferences = &elb_security_policy_tls_1_1_Res_2017_01,
1621 : : .kem_preferences = &kem_preferences_null,
1622 : : .signature_preferences = &s2n_signature_preferences_20140601,
1623 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1624 : : };
1625 : :
1626 : : const struct s2n_security_policy security_policy_elb_fs_1_2_Res_2020_10 = {
1627 : : .minimum_protocol_version = S2N_TLS12,
1628 : : .cipher_preferences = &elb_security_policy_fs_1_2_Res_2020_10,
1629 : : .kem_preferences = &kem_preferences_null,
1630 : : .signature_preferences = &s2n_signature_preferences_20140601,
1631 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1632 : : .rules = {
1633 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1634 : : },
1635 : : };
1636 : :
1637 : : const struct s2n_security_policy security_policy_intb_2021_04 = {
1638 : : .minimum_protocol_version = S2N_TLS12,
1639 : : .cipher_preferences = &cipher_preferences_intb_2021_04,
1640 : : .kem_preferences = &kem_preferences_null,
1641 : : .signature_preferences = &s2n_signature_preferences_20210816,
1642 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1643 : : };
1644 : :
1645 : : const struct s2n_security_policy security_policy_intb_2021_04_gcm = {
1646 : : .minimum_protocol_version = S2N_TLS12,
1647 : : .cipher_preferences = &cipher_preferences_intb_2021_04_gcm,
1648 : : .kem_preferences = &kem_preferences_null,
1649 : : .signature_preferences = &s2n_signature_preferences_20210816,
1650 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1651 : : .rules = {
1652 : : [S2N_PERFECT_FORWARD_SECRECY] = true,
1653 : : },
1654 : : };
1655 : :
1656 : : const struct s2n_security_policy security_policy_elb_tls13_1_0_FIPS_2023_04 = {
1657 : : .minimum_protocol_version = S2N_TLS10,
1658 : : .cipher_preferences = &elb_security_policy_tls13_1_0_FIPS_2023_04,
1659 : : .kem_preferences = &kem_preferences_null,
1660 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1661 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1662 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1663 : : };
1664 : :
1665 : : const struct s2n_security_policy security_policy_elb_tls13_1_1_FIPS_2023_04 = {
1666 : : .minimum_protocol_version = S2N_TLS11,
1667 : : .cipher_preferences = &elb_security_policy_tls13_1_1_FIPS_2023_04,
1668 : : .kem_preferences = &kem_preferences_null,
1669 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1670 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1671 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1672 : : };
1673 : :
1674 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_FIPS_2023_04 = {
1675 : : .minimum_protocol_version = S2N_TLS12,
1676 : : .cipher_preferences = &elb_security_policy_tls13_1_2_FIPS_2023_04,
1677 : : .kem_preferences = &kem_preferences_null,
1678 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1679 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1680 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1681 : : };
1682 : :
1683 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext0_FIPS_2023_04 = {
1684 : : .minimum_protocol_version = S2N_TLS12,
1685 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext0_FIPS_2023_04,
1686 : : .kem_preferences = &kem_preferences_null,
1687 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1688 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1689 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1690 : : };
1691 : :
1692 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext1_FIPS_2023_04 = {
1693 : : .minimum_protocol_version = S2N_TLS12,
1694 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext1_FIPS_2023_04,
1695 : : .kem_preferences = &kem_preferences_null,
1696 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1697 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1698 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1699 : : };
1700 : :
1701 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext2_FIPS_2023_04 = {
1702 : : .minimum_protocol_version = S2N_TLS12,
1703 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext2_FIPS_2023_04,
1704 : : .kem_preferences = &kem_preferences_null,
1705 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1706 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1707 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1708 : : };
1709 : :
1710 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Res_FIPS_2023_04 = {
1711 : : .minimum_protocol_version = S2N_TLS12,
1712 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Res_FIPS_2023_04,
1713 : : .kem_preferences = &kem_preferences_null,
1714 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1715 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1716 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1717 : : };
1718 : :
1719 : : const struct s2n_security_policy security_policy_elb_tls13_1_3_FIPS_2023_04 = {
1720 : : .minimum_protocol_version = S2N_TLS13,
1721 : : .cipher_preferences = &elb_security_policy_tls13_1_3_FIPS_2023_04,
1722 : : .kem_preferences = &kem_preferences_null,
1723 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1724 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1725 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1726 : : };
1727 : :
1728 : : const struct s2n_security_policy security_policy_elb_tls13_1_0_PQ_2025_09 = {
1729 : : .minimum_protocol_version = S2N_TLS10,
1730 : : .cipher_preferences = &elb_security_policy_tls13_1_0_2021_06,
1731 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1732 : : .signature_preferences = &s2n_signature_preferences_20201021,
1733 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1734 : : .ecc_preferences = &s2n_ecc_preferences_20240603,
1735 : : };
1736 : :
1737 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_PQ_2025_09 = {
1738 : : .minimum_protocol_version = S2N_TLS12,
1739 : : .cipher_preferences = &elb_security_policy_tls13_1_2_2021_06,
1740 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1741 : : .signature_preferences = &s2n_signature_preferences_20250813,
1742 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1743 : : .ecc_preferences = &s2n_ecc_preferences_20240603,
1744 : : };
1745 : :
1746 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Res_PQ_2025_09 = {
1747 : : .minimum_protocol_version = S2N_TLS12,
1748 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Res_2021_06,
1749 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1750 : : .signature_preferences = &s2n_signature_preferences_20250813,
1751 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1752 : : .ecc_preferences = &s2n_ecc_preferences_20240603,
1753 : : };
1754 : :
1755 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext1_PQ_2025_09 = {
1756 : : .minimum_protocol_version = S2N_TLS12,
1757 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext1_2021_06,
1758 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1759 : : .signature_preferences = &s2n_signature_preferences_20250813,
1760 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1761 : : .ecc_preferences = &s2n_ecc_preferences_20240603,
1762 : : };
1763 : :
1764 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext2_PQ_2025_09 = {
1765 : : .minimum_protocol_version = S2N_TLS12,
1766 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext2_2021_06,
1767 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1768 : : .signature_preferences = &s2n_signature_preferences_20201021,
1769 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1770 : : .ecc_preferences = &s2n_ecc_preferences_20240603,
1771 : : };
1772 : :
1773 : : const struct s2n_security_policy security_policy_elb_tls13_1_3_PQ_2025_09 = {
1774 : : .minimum_protocol_version = S2N_TLS13,
1775 : : .cipher_preferences = &elb_security_policy_tls13_1_3_2021_06,
1776 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1777 : : .signature_preferences = &s2n_signature_preferences_20250813,
1778 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1779 : : .ecc_preferences = &s2n_ecc_preferences_20240603,
1780 : : };
1781 : :
1782 : : const struct s2n_security_policy security_policy_elb_tls13_1_0_FIPS_PQ_2025_09 = {
1783 : : .minimum_protocol_version = S2N_TLS10,
1784 : : .cipher_preferences = &elb_security_policy_tls13_1_0_FIPS_2023_04,
1785 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1786 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1787 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1788 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1789 : : };
1790 : :
1791 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_FIPS_PQ_2025_09 = {
1792 : : .minimum_protocol_version = S2N_TLS12,
1793 : : .cipher_preferences = &elb_security_policy_tls13_1_2_FIPS_2023_04,
1794 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1795 : : .signature_preferences = &s2n_signature_preferences_20250813,
1796 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1797 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1798 : : };
1799 : :
1800 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext0_FIPS_PQ_2025_09 = {
1801 : : .minimum_protocol_version = S2N_TLS12,
1802 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext0_FIPS_2023_04,
1803 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1804 : : .signature_preferences = &s2n_signature_preferences_20250813,
1805 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1806 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1807 : : };
1808 : :
1809 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext1_FIPS_PQ_2025_09 = {
1810 : : .minimum_protocol_version = S2N_TLS12,
1811 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext1_FIPS_2023_04,
1812 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1813 : : .signature_preferences = &s2n_signature_preferences_20250813,
1814 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1815 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1816 : : };
1817 : :
1818 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext2_FIPS_PQ_2025_09 = {
1819 : : .minimum_protocol_version = S2N_TLS12,
1820 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext2_FIPS_2023_04,
1821 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1822 : : .signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1823 : : .certificate_signature_preferences = &s2n_signature_preferences_20200207_no_sha1,
1824 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1825 : : };
1826 : :
1827 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Res_FIPS_PQ_2025_09 = {
1828 : : .minimum_protocol_version = S2N_TLS12,
1829 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Res_FIPS_2023_04,
1830 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1831 : : .signature_preferences = &s2n_signature_preferences_20250813,
1832 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1833 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1834 : : };
1835 : :
1836 : : const struct s2n_security_policy security_policy_elb_tls13_1_3_FIPS_PQ_2025_09 = {
1837 : : .minimum_protocol_version = S2N_TLS13,
1838 : : .cipher_preferences = &elb_security_policy_tls13_1_3_FIPS_2023_04,
1839 : : .kem_preferences = &kem_preferences_pq_tls_1_3_ietf_2025_07,
1840 : : .signature_preferences = &s2n_signature_preferences_20250813,
1841 : : .certificate_signature_preferences = &s2n_signature_preferences_20250813,
1842 : : .ecc_preferences = &s2n_ecc_preferences_20201021,
1843 : : };
1844 : :
1845 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_RFC9151_FIPS_2023_07 = {
1846 : : .minimum_protocol_version = S2N_TLS12,
1847 : : .cipher_preferences = &elb_security_policy_tls13_1_2_RFC9151_FIPS_2023_07,
1848 : : .kem_preferences = &kem_preferences_null,
1849 : : .signature_preferences = &s2n_signature_preferences_20250429,
1850 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250429,
1851 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1852 : : };
1853 : :
1854 : : const struct s2n_security_policy security_policy_elb_tls13_1_2_Ext0_RFC9151_FIPS_2023_07 = {
1855 : : .minimum_protocol_version = S2N_TLS12,
1856 : : .cipher_preferences = &elb_security_policy_tls13_1_2_Ext0_RFC9151_FIPS_2023_07,
1857 : : .kem_preferences = &kem_preferences_null,
1858 : : .signature_preferences = &s2n_signature_preferences_20250429,
1859 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250429,
1860 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1861 : : };
1862 : :
1863 : : const struct s2n_security_policy security_policy_elb_tls13_1_3_RFC9151_FIPS_2023_07 = {
1864 : : .minimum_protocol_version = S2N_TLS13,
1865 : : .cipher_preferences = &elb_security_policy_tls13_1_3_RFC9151_FIPS_2023_07,
1866 : : .kem_preferences = &kem_preferences_null,
1867 : : .signature_preferences = &s2n_signature_preferences_20250429,
1868 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250429,
1869 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1870 : : };
1871 : :
1872 : : const struct s2n_security_policy security_policy_elb_tls12_1_2_RFC9151_2024_01 = {
1873 : : .minimum_protocol_version = S2N_TLS12,
1874 : : .cipher_preferences = &elb_security_policy_tls12_1_2_RFC9151_2024_01,
1875 : : .kem_preferences = &kem_preferences_null,
1876 : : /* Not s2n_signature_preferences_20250429, which also offers rsa_pss. This TLS1.2
1877 : : * policy offers only ecdsa_sha384 and rsa_pkcs1_sha384. */
1878 : : .signature_preferences = &s2n_certificate_signature_preferences_20250429,
1879 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250429,
1880 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1881 : : };
1882 : :
1883 : : const struct s2n_security_policy security_policy_elb_tls12_1_2_Ext0_RFC9151_2024_01 = {
1884 : : .minimum_protocol_version = S2N_TLS12,
1885 : : .cipher_preferences = &elb_security_policy_tls12_1_2_Ext0_RFC9151_2024_01,
1886 : : .kem_preferences = &kem_preferences_null,
1887 : : /* Not s2n_signature_preferences_20250429, which also offers rsa_pss. This TLS1.2
1888 : : * policy offers only ecdsa_sha384 and rsa_pkcs1_sha384. */
1889 : : .signature_preferences = &s2n_certificate_signature_preferences_20250429,
1890 : : .certificate_signature_preferences = &s2n_certificate_signature_preferences_20250429,
1891 : : .ecc_preferences = &s2n_ecc_preferences_20210816,
1892 : : };
1893 : :
1894 : : const struct s2n_security_policy security_policy_20170816_healthcheck = {
1895 : : .minimum_protocol_version = S2N_TLS10,
1896 : : .cipher_preferences = &cipher_preferences_20170816_healthcheck,
1897 : : .kem_preferences = &kem_preferences_null,
1898 : : .signature_preferences = &s2n_signature_preferences_20140601,
1899 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1900 : : };
1901 : :
1902 : : const struct s2n_security_policy security_policy_kms_tls_1_2_2023_07 = {
1903 : : .minimum_protocol_version = S2N_TLS12,
1904 : : .cipher_preferences = &cipher_preferences_kms_tls_1_2_2023_07,
1905 : : .kem_preferences = &kem_preferences_null,
1906 : : .signature_preferences = &s2n_signature_preferences_20200207,
1907 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1908 : : };
1909 : :
1910 : : const struct s2n_security_policy security_policy_kms_fips_tls_1_2_2023_09 = {
1911 : : .minimum_protocol_version = S2N_TLS12,
1912 : : .cipher_preferences = &cipher_preferences_kms_fips_tls_1_2_2021_08,
1913 : : .kem_preferences = &kem_preferences_null,
1914 : : .signature_preferences = &s2n_certificate_signature_preferences_20201110,
1915 : : .ecc_preferences = &s2n_ecc_preferences_20140601,
1916 : : };
1917 : : struct s2n_security_policy_selection security_policy_selection[] = {
1918 : : /* If changing named policies, please update the usage guide's docs on the corresponding policy.
1919 : : * You likely also want to update the compatibility unit tests in (tests/unit/s2n_security_rules_test.c).
1920 : : */
1921 : : { .version = "default", .security_policy = &security_policy_20251014, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1922 : : { .version = "default_tls13", .security_policy = &security_policy_20240503, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1923 : : { .version = "default_fips", .security_policy = &security_policy_20251015, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1924 : : { .version = "default_pq", .security_policy = &security_policy_20250721, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1925 : : { .version = "20241106", .security_policy = &security_policy_20241106, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1926 : : { .version = "20240501", .security_policy = &security_policy_20240501, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1927 : : { .version = "20240502", .security_policy = &security_policy_20240502, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1928 : : { .version = "20240503", .security_policy = &security_policy_20240503, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1929 : : { .version = "20230317", .security_policy = &security_policy_20230317, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1930 : : { .version = "20230317_pq", .security_policy = &security_policy_20230317_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1931 : : { .version = "20240331", .security_policy = &security_policy_20240331, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1932 : : { .version = "20240417", .security_policy = &security_policy_20240417, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1933 : : { .version = "20240416", .security_policy = &security_policy_20240416, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1934 : : { .version = "20241001", .security_policy = &security_policy_20241001, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1935 : : { .version = "20250512", .security_policy = &security_policy_20250512, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1936 : : { .version = "20250721", .security_policy = &security_policy_20250721, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1937 : : { .version = "20251014", .security_policy = &security_policy_20251014, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1938 : : { .version = "20251015", .security_policy = &security_policy_20251015, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1939 : : { .version = "20241001_pq_mixed", .security_policy = &security_policy_20241001_pq_mixed, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1940 : : { .version = "ELBSecurityPolicy-TLS-1-0-2015-04", .security_policy = &security_policy_elb_2015_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1941 : : /* Not a mistake. TLS-1-0-2015-05 and 2016-08 are equivalent */
1942 : : { .version = "ELBSecurityPolicy-TLS-1-0-2015-05", .security_policy = &security_policy_elb_2016_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1943 : : { .version = "ELBSecurityPolicy-2016-08", .security_policy = &security_policy_elb_2016_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1944 : : { .version = "ELBSecurityPolicy-TLS-1-1-2017-01", .security_policy = &security_policy_elb_tls_1_1_2017_01, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1945 : : { .version = "ELBSecurityPolicy-TLS-1-2-2017-01", .security_policy = &security_policy_elb_tls_1_2_2017_01, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1946 : : { .version = "ELBSecurityPolicy-TLS-1-2-Ext-2018-06", .security_policy = &security_policy_elb_tls_1_2_ext_2018_06, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1947 : : { .version = "ELBSecurityPolicy-FS-2018-06", .security_policy = &security_policy_elb_fs_2018_06, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1948 : : { .version = "ELBSecurityPolicy-FS-1-2-2019-08", .security_policy = &security_policy_elb_fs_1_2_2019_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1949 : : { .version = "ELBSecurityPolicy-FS-1-1-2019-08", .security_policy = &security_policy_elb_fs_1_1_2019_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1950 : : { .version = "ELBSecurityPolicy-FS-1-2-Res-2019-08", .security_policy = &security_policy_elb_fs_1_2_Res_2019_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1951 : : { .version = "ELBSecurityPolicy-TLS13-1-3-CNSA2-INTEROP1-FIPS-PQ-2026-07", .security_policy = &security_policy_20260720, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1952 : : { .version = "ELBSecurityPolicy-TLS13-1-2-CNSA2-INTEROP2-FIPS-PQ-2026-07", .security_policy = &security_policy_20260220, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1953 : : { .version = "ELBSecurityPolicy-TLS13-1-2-CNSA2-INTEROP3-FIPS-PQ-2026-07", .security_policy = &security_policy_20260722, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1954 : : { .version = "ELBSecurityPolicy-FS-1-2-Res-2020-10", .security_policy = &security_policy_elb_fs_1_2_Res_2020_10, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1955 : : { .version = "ELBSecurityPolicy-Backend-2016-08", .security_policy = &security_policy_elb_backend_2016_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1956 : : { .version = "ELBSecurityPolicy-SSLv3-2013-12", .security_policy = &security_policy_elb_sslv3_2013_12, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1957 : : { .version = "ELBSecurityPolicy-TLS-1-1-Res-2017-01", .security_policy = &security_policy_elb_tls_1_1_Res_2017_01, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1958 : : { .version = "ELBSecurityPolicy-TLS13-1-0-FIPS-2023-04", .security_policy = &security_policy_elb_tls13_1_0_FIPS_2023_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1959 : : { .version = "ELBSecurityPolicy-TLS13-1-1-FIPS-2023-04", .security_policy = &security_policy_elb_tls13_1_1_FIPS_2023_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1960 : : { .version = "ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04", .security_policy = &security_policy_elb_tls13_1_2_FIPS_2023_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1961 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext0-FIPS-2023-04", .security_policy = &security_policy_elb_tls13_1_2_Ext0_FIPS_2023_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1962 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext1-FIPS-2023-04", .security_policy = &security_policy_elb_tls13_1_2_Ext1_FIPS_2023_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1963 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext2-FIPS-2023-04", .security_policy = &security_policy_elb_tls13_1_2_Ext2_FIPS_2023_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1964 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Res-FIPS-2023-04", .security_policy = &security_policy_elb_tls13_1_2_Res_FIPS_2023_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1965 : : { .version = "ELBSecurityPolicy-TLS13-1-3-FIPS-2023-04", .security_policy = &security_policy_elb_tls13_1_3_FIPS_2023_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1966 : : { .version = "ELBSecurityPolicy-TLS13-1-2-RFC9151-FIPS-2023-07", .security_policy = &security_policy_elb_tls13_1_2_RFC9151_FIPS_2023_07, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1967 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext0-RFC9151-FIPS-2023-07", .security_policy = &security_policy_elb_tls13_1_2_Ext0_RFC9151_FIPS_2023_07, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1968 : : { .version = "ELBSecurityPolicy-TLS13-1-3-RFC9151-FIPS-2023-07", .security_policy = &security_policy_elb_tls13_1_3_RFC9151_FIPS_2023_07, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1969 : : { .version = "ELBSecurityPolicy-TLS13-1-2-RFC9151-INTEROP1-FIPS-2023-07", .security_policy = &security_policy_20251113, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1970 : : { .version = "ELBSecurityPolicy-TLS13-1-2-RFC9151-INTEROP2-FIPS-2023-07", .security_policy = &security_policy_20251117, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1971 : : { .version = "ELBSecurityPolicy-TLS13-1-2-RFC9151-INTEROP3-FIPS-2023-07", .security_policy = &security_policy_20251114, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1972 : : { .version = "ELBSecurityPolicy-TLS13-1-2-RFC9151-INTEROP4-FIPS-2023-07", .security_policy = &security_policy_20251115, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1973 : : { .version = "ELBSecurityPolicy-TLS12-1-2-RFC9151-2024-01", .security_policy = &security_policy_elb_tls12_1_2_RFC9151_2024_01, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1974 : : { .version = "ELBSecurityPolicy-TLS12-1-2-Ext0-RFC9151-2024-01", .security_policy = &security_policy_elb_tls12_1_2_Ext0_RFC9151_2024_01, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1975 : : { .version = "ELBSecurityPolicy-TLS13-1-0-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_0_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1976 : : { .version = "ELBSecurityPolicy-TLS13-1-2-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1977 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Res-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_Res_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1978 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext1-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_Ext1_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1979 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext2-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_Ext2_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1980 : : { .version = "ELBSecurityPolicy-TLS13-1-3-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_3_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1981 : : { .version = "ELBSecurityPolicy-TLS13-1-0-FIPS-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_0_FIPS_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1982 : : { .version = "ELBSecurityPolicy-TLS13-1-2-FIPS-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_FIPS_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1983 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext0-FIPS-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_Ext0_FIPS_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1984 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext1-FIPS-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_Ext1_FIPS_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1985 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Ext2-FIPS-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_Ext2_FIPS_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1986 : : { .version = "ELBSecurityPolicy-TLS13-1-2-Res-FIPS-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_2_Res_FIPS_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1987 : : { .version = "ELBSecurityPolicy-TLS13-1-3-FIPS-PQ-2025-09", .security_policy = &security_policy_elb_tls13_1_3_FIPS_PQ_2025_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1988 : : { .version = "CloudFront-Upstream", .security_policy = &security_policy_cloudfront_upstream, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1989 : : { .version = "CloudFront-Upstream-TLS-1-0", .security_policy = &security_policy_cloudfront_upstream_tls10, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1990 : : { .version = "CloudFront-Upstream-TLS-1-1", .security_policy = &security_policy_cloudfront_upstream_tls11, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1991 : : { .version = "CloudFront-Upstream-TLS-1-2", .security_policy = &security_policy_cloudfront_upstream_tls12, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1992 : : { .version = "CloudFront-Upstream-2025", .security_policy = &security_policy_cloudfront_upstream_2025_08_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1993 : : { .version = "CloudFront-Upstream-TLS-1-0-2025", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_tls10, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1994 : : { .version = "CloudFront-Upstream-TLS-1-1-2025", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_tls11, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1995 : : { .version = "CloudFront-Upstream-TLS-1-2-2025", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_tls12, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1996 : : { .version = "CloudFront-Upstream-TLS-1-3-2025", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_tls13, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1997 : : { .version = "CloudFront-Upstream-2025-PQ", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1998 : : { .version = "CloudFront-Upstream-TLS-1-0-2025-PQ", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_tls10_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
1999 : : { .version = "CloudFront-Upstream-TLS-1-1-2025-PQ", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_tls11_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2000 : : { .version = "CloudFront-Upstream-TLS-1-2-2025-PQ", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_tls12_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2001 : : { .version = "CloudFront-Upstream-TLS-1-3-2025-PQ", .security_policy = &security_policy_cloudfront_upstream_2025_08_08_tls13_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2002 : : /* CloudFront Viewer Facing */
2003 : : { .version = "CloudFront-SSL-v-3", .security_policy = &security_policy_cloudfront_ssl_v_3, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2004 : : { .version = "CloudFront-TLS-1-0-2014", .security_policy = &security_policy_cloudfront_tls_1_0_2014, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2005 : : { .version = "CloudFront-TLS-1-0-2014-sha256", .security_policy = &security_policy_cloudfront_tls_1_0_2014_sha256, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2006 : : { .version = "CloudFront-TLS-1-0-2016", .security_policy = &security_policy_cloudfront_tls_1_0_2016, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2007 : : { .version = "CloudFront-TLS-1-1-2016", .security_policy = &security_policy_cloudfront_tls_1_1_2016, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2008 : : { .version = "CloudFront-TLS-1-2-2017", .security_policy = &security_policy_cloudfront_tls_1_2_2017, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2009 : : { .version = "CloudFront-TLS-1-2-2018-no-sha1", .security_policy = &security_policy_cloudfront_tls_1_2_2018_no_sha1, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2010 : : { .version = "CloudFront-TLS-1-2-2019-no-sha1", .security_policy = &security_policy_cloudfront_tls_1_2_2019_no_sha1, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2011 : : { .version = "CloudFront-TLS-1-2-2021-no-sha1", .security_policy = &security_policy_cloudfront_tls_1_2_2021_no_sha1, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2012 : : { .version = "CloudFront-TLS-1-2-2025", .security_policy = &security_policy_cloudfront_tls_1_2_2025, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2013 : : { .version = "CloudFront-TLS-1-3-2025", .security_policy = &security_policy_cloudfront_tls_1_3_2025, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2014 : : /* CloudFront Non-PQ Viewer Facing */
2015 : : { .version = "CloudFront-SSL-v-3-no-pq", .security_policy = &security_policy_cloudfront_ssl_v_3_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2016 : : { .version = "CloudFront-TLS-1-0-2014-no-pq", .security_policy = &security_policy_cloudfront_tls_1_0_2014_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2017 : : { .version = "CloudFront-TLS-1-0-2014-sha256-no-pq", .security_policy = &security_policy_cloudfront_tls_1_0_2014_sha256_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2018 : : { .version = "CloudFront-TLS-1-0-2016-no-pq", .security_policy = &security_policy_cloudfront_tls_1_0_2016_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2019 : : { .version = "CloudFront-TLS-1-1-2016-no-pq", .security_policy = &security_policy_cloudfront_tls_1_1_2016_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2020 : : { .version = "CloudFront-TLS-1-2-2017-no-pq", .security_policy = &security_policy_cloudfront_tls_1_2_2017_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2021 : : { .version = "CloudFront-TLS-1-2-2018-no-sha1-no-pq", .security_policy = &security_policy_cloudfront_tls_1_2_2018_no_sha1_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2022 : : { .version = "CloudFront-TLS-1-2-2019-no-sha1-no-pq", .security_policy = &security_policy_cloudfront_tls_1_2_2019_no_sha1_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2023 : : { .version = "CloudFront-TLS-1-2-2021-no-sha1-no-pq", .security_policy = &security_policy_cloudfront_tls_1_2_2021_no_sha1_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2024 : : { .version = "CloudFront-TLS-1-2-2025-no-pq", .security_policy = &security_policy_cloudfront_tls_1_2_2025_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2025 : : { .version = "CloudFront-TLS-1-3-2025-no-pq", .security_policy = &security_policy_cloudfront_tls_1_3_2025_no_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2026 : : /* CloudFront Unofficial Viewer Facing */
2027 : : { .version = "CloudFront-TLS-1-0-2014-PQ-Beta", .security_policy = &security_policy_cloudfront_tls_1_0_2014_pq_beta, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2028 : : { .version = "CloudFront-TLS-1-2-2021-no-sha1-PQ-Beta", .security_policy = &security_policy_cloudfront_tls_1_2_2021_no_sha1_pq_beta, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2029 : : { .version = "CloudFront-TLS-1-2-2018-Beta", .security_policy = &security_policy_cloudfront_tls_1_2_2018_beta, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2030 : : { .version = "CloudFront-TLS-1-2-2021-Chacha20-Boosted", .security_policy = &security_policy_cloudfront_tls_1_2_2021_chacha20_boosted, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2031 : : /* CloudFront Legacy policies */
2032 : : { .version = "CloudFront-SSL-v-3-Legacy", .security_policy = &security_policy_cloudfront_ssl_v_3_legacy, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2033 : : { .version = "CloudFront-TLS-1-0-2014-Legacy", .security_policy = &security_policy_cloudfront_tls_1_0_2014_legacy, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2034 : : { .version = "CloudFront-TLS-1-0-2016-Legacy", .security_policy = &security_policy_cloudfront_tls_1_0_2016_legacy, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2035 : : { .version = "CloudFront-TLS-1-1-2016-Legacy", .security_policy = &security_policy_cloudfront_tls_1_1_2016_legacy, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2036 : : { .version = "CloudFront-TLS-1-2-2018-Legacy", .security_policy = &security_policy_cloudfront_tls_1_2_2018_legacy, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2037 : : { .version = "CloudFront-TLS-1-2-2019-Legacy", .security_policy = &security_policy_cloudfront_tls_1_2_2019_legacy, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2038 : : { .version = "CloudFront-TLS-1-2-2018", .security_policy = &security_policy_cloudfront_tls_1_2_2018, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2039 : : { .version = "CloudFront-TLS-1-2-2019", .security_policy = &security_policy_cloudfront_tls_1_2_2019, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2040 : : { .version = "CloudFront-TLS-1-2-2021", .security_policy = &security_policy_cloudfront_tls_1_2_2021, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2041 : : { .version = "CloudFront-TLS-1-2-2021-PQ", .security_policy = &security_policy_cloudfront_tls_1_2_2021_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2042 : : /* CRT allows users to choose the minimal TLS protocol they want to negotiate with. This translates to 5 different security policies in s2n */
2043 : : { .version = "AWS-CRT-SDK-SSLv3.0", .security_policy = &security_policy_aws_crt_sdk_ssl_v3, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2044 : : { .version = "AWS-CRT-SDK-TLSv1.0", .security_policy = &security_policy_aws_crt_sdk_tls_10, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2045 : : { .version = "AWS-CRT-SDK-TLSv1.1", .security_policy = &security_policy_aws_crt_sdk_tls_11, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2046 : : { .version = "AWS-CRT-SDK-TLSv1.2", .security_policy = &security_policy_aws_crt_sdk_tls_12, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2047 : : { .version = "AWS-CRT-SDK-TLSv1.3", .security_policy = &security_policy_aws_crt_sdk_tls_13, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2048 : : { .version = "AWS-CRT-SDK-SSLv3.0-2023", .security_policy = &security_policy_aws_crt_sdk_ssl_v3_06_23, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2049 : : { .version = "AWS-CRT-SDK-TLSv1.0-2023", .security_policy = &security_policy_aws_crt_sdk_tls_10_06_23, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2050 : : { .version = "AWS-CRT-SDK-TLSv1.0-2025-PQ", .security_policy = &security_policy_aws_crt_sdk_tls_10_07_25_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2051 : : { .version = "AWS-CRT-SDK-TLSv1.1-2023", .security_policy = &security_policy_aws_crt_sdk_tls_11_06_23, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2052 : : { .version = "AWS-CRT-SDK-TLSv1.2-2023", .security_policy = &security_policy_aws_crt_sdk_tls_12_06_23, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2053 : : { .version = "AWS-CRT-SDK-TLSv1.2-2023-PQ", .security_policy = &security_policy_aws_crt_sdk_tls_12_06_23_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2054 : : { .version = "AWS-CRT-SDK-TLSv1.2-2025", .security_policy = &security_policy_aws_crt_sdk_tls_30_06_25, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2055 : : { .version = "AWS-CRT-SDK-TLSv1.2-2025-PQ", .security_policy = &security_policy_aws_crt_sdk_tls_12_07_25_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2056 : : { .version = "AWS-CRT-SDK-TLSv1.3-2023", .security_policy = &security_policy_aws_crt_sdk_tls_13_06_23, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2057 : : { .version = "AWS-CRT-SDK-TLSv1.3-2025-PQ", .security_policy = &security_policy_aws_crt_sdk_tls_13_07_25_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2058 : : /* KMS TLS Policies*/
2059 : : { .version = "KMS-TLS-1-0-2018-10", .security_policy = &security_policy_kms_tls_1_0_2018_10, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2060 : : { .version = "KMS-TLS-1-0-2021-08", .security_policy = &security_policy_kms_tls_1_0_2021_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2061 : : { .version = "KMS-TLS-1-2-2023-06", .security_policy = &security_policy_kms_tls_1_2_2023_06, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2062 : : { .version = "KMS-FIPS-TLS-1-2-2018-10", .security_policy = &security_policy_kms_fips_tls_1_2_2018_10, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2063 : : { .version = "KMS-FIPS-TLS-1-2-2021-08", .security_policy = &security_policy_kms_fips_tls_1_2_2021_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2064 : : { .version = "KMS-FIPS-TLS-1-2-2024-10", .security_policy = &security_policy_kms_fips_tls_1_2_2024_10, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2065 : : { .version = "20170816_healthcheck", .security_policy = &security_policy_20170816_healthcheck, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2066 : : { .version = "KMS-TLS-1-2-2023-07", .security_policy = &security_policy_kms_tls_1_2_2023_07, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2067 : : { .version = "KMS-FIPS-TLS-1-2-2023-09", .security_policy = &security_policy_kms_fips_tls_1_2_2023_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2068 : : { .version = "PQ-TLS-1-2-2024-10-07", .security_policy = &security_policy_pq_tls_1_2_2024_10_07, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2069 : : { .version = "PQ-TLS-1-2-2024-10-08", .security_policy = &security_policy_pq_tls_1_2_2024_10_08, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2070 : : { .version = "PQ-TLS-1-2-2024-10-08_gcm", .security_policy = &security_policy_pq_tls_1_2_2024_10_08_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2071 : : { .version = "PQ-TLS-1-2-2024-10-09", .security_policy = &security_policy_pq_tls_1_2_2024_10_09, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2072 : : { .version = "20140601", .security_policy = &security_policy_20140601, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2073 : : { .version = "20141001", .security_policy = &security_policy_20141001, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2074 : : { .version = "20150202", .security_policy = &security_policy_20150202, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2075 : : { .version = "20150214", .security_policy = &security_policy_20150214, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2076 : : { .version = "20150306", .security_policy = &security_policy_20150306, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2077 : : { .version = "20160411", .security_policy = &security_policy_20160411, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2078 : : { .version = "20160804", .security_policy = &security_policy_20160804, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2079 : : { .version = "20160824", .security_policy = &security_policy_20160824, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2080 : : { .version = "20170210", .security_policy = &security_policy_20170210, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2081 : : { .version = "20170328", .security_policy = &security_policy_20170328, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2082 : : { .version = "20170328_gcm", .security_policy = &security_policy_20170328_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2083 : : { .version = "20190214", .security_policy = &security_policy_20190214, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2084 : : { .version = "20190214_gcm", .security_policy = &security_policy_20190214_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2085 : : { .version = "20210825", .security_policy = &security_policy_20210825, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2086 : : { .version = "20210825_gcm", .security_policy = &security_policy_20210825_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2087 : : { .version = "20170405", .security_policy = &security_policy_20170405, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2088 : : { .version = "20170405_gcm", .security_policy = &security_policy_20170405_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2089 : : { .version = "20170718", .security_policy = &security_policy_20170718, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2090 : : { .version = "20170718_gcm", .security_policy = &security_policy_20170718_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2091 : : { .version = "20190120", .security_policy = &security_policy_20190120, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2092 : : { .version = "20190121", .security_policy = &security_policy_20190121, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2093 : : { .version = "20190122", .security_policy = &security_policy_20190122, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2094 : : { .version = "20190801", .security_policy = &security_policy_20190801, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2095 : : { .version = "20190802", .security_policy = &security_policy_20190802, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2096 : : { .version = "20200207", .security_policy = &security_policy_20200207, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2097 : : { .version = "20200207_pq", .security_policy = &security_policy_20200207_pq, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2098 : : { .version = "20201021", .security_policy = &security_policy_20201021, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2099 : : { .version = "20210816", .security_policy = &security_policy_20210816, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2100 : : { .version = "20210422_INTB", .security_policy = &security_policy_intb_2021_04, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2101 : : { .version = "20210422_INTB_gcm", .security_policy = &security_policy_intb_2021_04_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2102 : : { .version = "20210816_GCM", .security_policy = &security_policy_20210816_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2103 : : { .version = "20240603", .security_policy = &security_policy_20240603, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2104 : : { .version = "20250211", .security_policy = &security_policy_20250211, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2105 : : { .version = "20250414", .security_policy = &security_policy_20250414, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2106 : : { .version = "20250429", .security_policy = &security_policy_20250429, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2107 : : { .version = "20251013", .security_policy = &security_policy_20251013, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2108 : : { .version = "20251113", .security_policy = &security_policy_20251113, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2109 : : { .version = "20251114", .security_policy = &security_policy_20251114, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2110 : : { .version = "20251115", .security_policy = &security_policy_20251115, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2111 : : { .version = "20251116", .security_policy = &security_policy_20251116, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2112 : : /* the same as 20251114, but without any SHA1 HMAC ciphers */
2113 : : { .version = "20251117", .security_policy = &security_policy_20251117, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2114 : : { .version = "20260219", .security_policy = &security_policy_20260219, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2115 : : { .version = "20260220", .security_policy = &security_policy_20260220, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2116 : : { .version = "20260513", .security_policy = &security_policy_20260513, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2117 : : { .version = "20260520", .security_policy = &security_policy_20260520, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2118 : : { .version = "20260520_gcm", .security_policy = &security_policy_20260520_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2119 : : { .version = "20260521", .security_policy = &security_policy_20260521, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2120 : : { .version = "20260521_gcm", .security_policy = &security_policy_20260521_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2121 : : { .version = "20260522", .security_policy = &security_policy_20260522, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2122 : : { .version = "20260522_gcm", .security_policy = &security_policy_20260522_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2123 : : { .version = "20260523", .security_policy = &security_policy_20260523, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2124 : : { .version = "20260523_gcm", .security_policy = &security_policy_20260523_gcm, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2125 : : { .version = "20260720", .security_policy = &security_policy_20260720, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2126 : : { .version = "20260722", .security_policy = &security_policy_20260722, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2127 : : /* If changing this, please update the usage guide's docs on the corresponding policy. */
2128 : : { .version = "rfc9151", .security_policy = &security_policy_20251013, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2129 : : { .version = "cnsa_1", .security_policy = &security_policy_20251013, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2130 : : { .version = "cnsa_2", .security_policy = &security_policy_20260219, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2131 : : { .version = "cnsa_1_2_interop", .security_policy = &security_policy_20260220, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2132 : : { .version = "test_all", .security_policy = &security_policy_test_all, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2133 : : { .version = "test_all_fips", .security_policy = &security_policy_test_all_fips, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2134 : : { .version = "test_all_ecdsa", .security_policy = &security_policy_test_all_ecdsa, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2135 : : { .version = "test_all_rsa_kex", .security_policy = &security_policy_test_all_rsa_kex, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2136 : : { .version = "test_ecdsa_priority", .security_policy = &security_policy_test_ecdsa_priority, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2137 : : { .version = "test_all_tls12", .security_policy = &security_policy_test_all_tls12, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2138 : : { .version = "test_all_tls13", .security_policy = &security_policy_test_all_tls13, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2139 : : { .version = "test_pq_only", .security_policy = &security_policy_test_pq_only, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2140 : : { .version = "null", .security_policy = &security_policy_null, .ecc_extension_required = 0, .pq_kem_extension_required = 0 },
2141 : : { .version = NULL, .security_policy = NULL, .ecc_extension_required = 0, .pq_kem_extension_required = 0 }
2142 : : };
2143 : :
2144 : : const char *deprecated_security_policies[] = {
2145 : : "KMS-PQ-TLS-1-0-2019-06",
2146 : : "KMS-PQ-TLS-1-0-2020-02",
2147 : : "KMS-PQ-TLS-1-0-2020-07",
2148 : : "PQ-TLS-1-0-2020-12",
2149 : : "PQ-TLS-1-1-2021-05-17",
2150 : : "PQ-TLS-1-0-2021-05-18",
2151 : : "PQ-TLS-1-0-2021-05-19",
2152 : : "PQ-TLS-1-0-2021-05-20",
2153 : : "PQ-TLS-1-1-2021-05-21",
2154 : : "PQ-TLS-1-0-2021-05-22",
2155 : : "PQ-TLS-1-0-2021-05-23",
2156 : : "PQ-TLS-1-0-2021-05-24",
2157 : : "PQ-TLS-1-0-2021-05-25",
2158 : : "PQ-TLS-1-0-2021-05-26",
2159 : : "PQ-TLS-1-0-2023-01-24",
2160 : : "PQ-TLS-1-2-2023-04-07",
2161 : : "PQ-TLS-1-2-2023-04-08",
2162 : : "PQ-TLS-1-2-2023-04-09",
2163 : : "PQ-TLS-1-2-2023-04-10",
2164 : : "PQ-TLS-1-3-2023-06-01",
2165 : : "PQ-TLS-1-2-2023-10-07",
2166 : : "PQ-TLS-1-2-2023-10-08",
2167 : : "PQ-TLS-1-2-2023-10-09",
2168 : : "PQ-TLS-1-2-2023-10-10",
2169 : : "PQ-TLS-1-2-2023-12-13",
2170 : : "PQ-TLS-1-2-2023-12-14",
2171 : : "PQ-TLS-1-2-2023-12-15",
2172 : : "PQ-SIKE-TEST-TLS-1-0-2019-11",
2173 : : "PQ-SIKE-TEST-TLS-1-0-2020-02",
2174 : : "20240730",
2175 : : };
2176 : : const size_t deprecated_security_policies_len = s2n_array_len(deprecated_security_policies);
2177 : :
2178 : : int s2n_find_security_policy_from_version(const char *version, const struct s2n_security_policy **security_policy)
2179 : 6056 : {
2180 [ + + ][ + - ]: 6056 : POSIX_ENSURE_REF(version);
2181 [ - + ][ # # ]: 6054 : POSIX_ENSURE_REF(security_policy);
2182 : :
2183 [ + + ]: 119042 : for (int i = 0; security_policy_selection[i].version != NULL; i++) {
2184 [ + + ]: 119007 : if (!strcasecmp(version, security_policy_selection[i].version)) {
2185 : 6019 : *security_policy = security_policy_selection[i].security_policy;
2186 : 6019 : return 0;
2187 : 6019 : }
2188 : 119007 : }
2189 : :
2190 [ + + ]: 615 : for (size_t i = 0; i < deprecated_security_policies_len; i++) {
2191 [ + + ]: 612 : if (!strcasecmp(version, deprecated_security_policies[i])) {
2192 [ + - ]: 32 : POSIX_BAIL(S2N_ERR_DEPRECATED_SECURITY_POLICY);
2193 : 32 : }
2194 : 612 : }
2195 : :
2196 [ + - ]: 3 : POSIX_BAIL(S2N_ERR_INVALID_SECURITY_POLICY);
2197 : 3 : }
2198 : :
2199 : : /* Find the label e.g. "20190422" for a given security policy
2200 : : *
2201 : : * This relies on the exact security policy pointer being available in the security
2202 : : * policy table. If no match is found in the security policy table then "unknown"
2203 : : * will be returned.
2204 : : *
2205 : : * Note that a given security policy may appear in the security policy table multiple
2206 : : * times under different names. This is the case for our default policy, which
2207 : : * has both a `default` and numbered label. This function will return the label
2208 : : * of the first matching entry.
2209 : : *
2210 : : * The returned `char *` is static memory and must not be freed by the application.
2211 : : */
2212 : : const char *s2n_find_version_from_security_policy(const struct s2n_security_policy *security_policy)
2213 : 20806 : {
2214 [ + + ]: 1296980 : for (int i = 0; security_policy_selection[i].version != NULL; i++) {
2215 [ + + ]: 1292360 : if (security_policy_selection[i].security_policy == security_policy) {
2216 : 16186 : return security_policy_selection[i].version;
2217 : 16186 : }
2218 : 1292360 : }
2219 : :
2220 : 4620 : return "unknown";
2221 : 20806 : }
2222 : :
2223 : : static int s2n_config_validate_security_policy(struct s2n_config *config, const struct s2n_security_policy *security_policy)
2224 : 6134 : {
2225 [ - + ][ # # ]: 6134 : POSIX_ENSURE_REF(config);
2226 [ - + ][ # # ]: 6134 : POSIX_ENSURE_REF(security_policy);
2227 [ - + ][ # # ]: 6134 : POSIX_ENSURE_REF(security_policy->cipher_preferences);
2228 [ - + ][ # # ]: 6134 : POSIX_ENSURE_REF(security_policy->kem_preferences);
2229 [ - + ][ # # ]: 6134 : POSIX_ENSURE_REF(security_policy->signature_preferences);
2230 [ - + ][ # # ]: 6134 : POSIX_ENSURE_REF(security_policy->ecc_preferences);
2231 : :
2232 : : /* If the security policy's minimum version is higher than what libcrypto supports, return an error. */
2233 [ - + ][ # # ]: 6134 : POSIX_ENSURE((security_policy->minimum_protocol_version <= s2n_get_highest_fully_supported_tls_version()), S2N_ERR_PROTOCOL_VERSION_UNSUPPORTED);
2234 : :
2235 [ + + ]: 6134 : if (security_policy == &security_policy_null) {
2236 : 4 : return S2N_SUCCESS;
2237 : 4 : }
2238 : :
2239 : : /* Ensure that all strongly preferred groups are supported by our libcrypto. */
2240 [ - + ][ # # ]: 6130 : for (size_t i = 0; security_policy->strongly_preferred_groups != NULL && i < security_policy->strongly_preferred_groups->count; i++) {
2241 : 0 : const struct s2n_kem_group *strongly_preferred_kem_group = NULL;
2242 : 0 : bool found_kem_group_from_iana = false;
2243 [ # # ]: 0 : POSIX_GUARD(s2n_find_kem_group_from_iana_id(security_policy->strongly_preferred_groups->iana_ids[i], &strongly_preferred_kem_group, &found_kem_group_from_iana));
2244 : :
2245 [ # # ]: 0 : if (found_kem_group_from_iana) {
2246 [ # # ][ # # ]: 0 : POSIX_ENSURE(s2n_kem_group_is_available(strongly_preferred_kem_group), S2N_ERR_INVALID_SECURITY_POLICY);
2247 : 0 : }
2248 : 0 : }
2249 : :
2250 : : /* Ensure that an ECC or PQ key exchange can occur. */
2251 : 6130 : uint32_t ecc_available = security_policy->ecc_preferences->count;
2252 : 6130 : uint32_t kem_groups_available = 0;
2253 [ - + ]: 6130 : POSIX_GUARD_RESULT(s2n_kem_preferences_groups_available(security_policy->kem_preferences, &kem_groups_available));
2254 [ + - ][ + + ]: 6130 : POSIX_ENSURE(ecc_available + kem_groups_available > 0, S2N_ERR_INVALID_SECURITY_POLICY);
2255 : :
2256 : : /* If the config contains certificates violating the security policy cert preferences, return an error. */
2257 [ + + ]: 6128 : POSIX_GUARD_RESULT(s2n_config_validate_loaded_certificates(config, security_policy));
2258 : 6126 : return S2N_SUCCESS;
2259 : 6128 : }
2260 : :
2261 : : int s2n_config_set_security_policy(struct s2n_config *config, const struct s2n_security_policy *security_policy)
2262 : 4483 : {
2263 [ - + ][ # # ]: 4483 : POSIX_ENSURE_REF(config);
2264 [ + + ]: 4483 : POSIX_GUARD(s2n_config_validate_security_policy(config, security_policy));
2265 : 4480 : config->security_policy = security_policy;
2266 : 4480 : return 0;
2267 : 4483 : }
2268 : :
2269 : : int s2n_config_set_cipher_preferences(struct s2n_config *config, const char *version)
2270 : 4485 : {
2271 : 4485 : const struct s2n_security_policy *security_policy = NULL;
2272 [ + + ]: 4485 : POSIX_GUARD(s2n_find_security_policy_from_version(version, &security_policy));
2273 [ + + ]: 4483 : POSIX_GUARD(s2n_config_set_security_policy(config, security_policy));
2274 : 4480 : return S2N_SUCCESS;
2275 : 4483 : }
2276 : :
2277 : : int s2n_connection_set_security_policy(struct s2n_connection *conn, const struct s2n_security_policy *security_policy)
2278 : 1651 : {
2279 [ - + ][ # # ]: 1651 : POSIX_ENSURE_REF(conn);
2280 [ + + ]: 1651 : POSIX_GUARD(s2n_config_validate_security_policy(conn->config, security_policy));
2281 : 1650 : conn->security_policy_override = security_policy;
2282 : 1650 : return 0;
2283 : 1651 : }
2284 : :
2285 : : int s2n_connection_set_cipher_preferences(struct s2n_connection *conn, const char *version)
2286 : 1263 : {
2287 : 1263 : const struct s2n_security_policy *security_policy = NULL;
2288 [ + + ]: 1263 : POSIX_GUARD(s2n_find_security_policy_from_version(version, &security_policy));
2289 [ + + ]: 1261 : POSIX_GUARD(s2n_connection_set_security_policy(conn, security_policy));
2290 : 1260 : return S2N_SUCCESS;
2291 : 1261 : }
2292 : :
2293 : : int s2n_security_policies_init()
2294 : 350 : {
2295 [ + + ]: 74200 : for (int i = 0; security_policy_selection[i].version != NULL; i++) {
2296 : 73850 : const struct s2n_security_policy *security_policy = security_policy_selection[i].security_policy;
2297 [ # # ][ - + ]: 73850 : POSIX_ENSURE_REF(security_policy);
2298 : 73850 : const struct s2n_cipher_preferences *cipher_preference = security_policy->cipher_preferences;
2299 [ # # ][ - + ]: 73850 : POSIX_ENSURE_REF(cipher_preference);
2300 : 73850 : const struct s2n_kem_preferences *kem_preference = security_policy->kem_preferences;
2301 [ # # ][ - + ]: 73850 : POSIX_ENSURE_REF(kem_preference);
2302 : 73850 : const struct s2n_ecc_preferences *ecc_preference = security_policy->ecc_preferences;
2303 [ # # ][ - + ]: 73850 : POSIX_ENSURE_REF(ecc_preference);
2304 [ - + ]: 73850 : POSIX_GUARD(s2n_check_ecc_preferences_curves_list(ecc_preference));
2305 : :
2306 : 73850 : const struct s2n_signature_preferences *certificate_signature_preference = security_policy->certificate_signature_preferences;
2307 [ + + ]: 73850 : if (certificate_signature_preference != NULL) {
2308 [ - + ]: 23800 : POSIX_GUARD_RESULT(s2n_validate_certificate_signature_preferences(certificate_signature_preference));
2309 : 23800 : }
2310 : :
2311 [ + + ]: 73850 : if (security_policy != &security_policy_null) {
2312 : : /* All policies must have at least one ecc curve or PQ kem group configured. */
2313 : 73500 : bool ecc_kx_supported = ecc_preference->count > 0;
2314 : 73500 : bool pq_kx_supported = kem_preference->tls13_kem_group_count > 0;
2315 [ # # ][ + - ]: 73500 : POSIX_ENSURE(ecc_kx_supported || pq_kx_supported, S2N_ERR_INVALID_SECURITY_POLICY);
[ + + ]
2316 : :
2317 : : /* A PQ key exchange is only supported in TLS 1.3, so PQ-only policies must require TLS 1.3.*/
2318 [ + + ]: 73500 : if (!ecc_kx_supported) {
2319 [ # # ][ - + ]: 1050 : POSIX_ENSURE(security_policy->minimum_protocol_version >= S2N_TLS13, S2N_ERR_INVALID_SECURITY_POLICY);
2320 : 1050 : }
2321 : 73500 : }
2322 : :
2323 [ + + ]: 1076250 : for (int j = 0; j < cipher_preference->count; j++) {
2324 : 1002400 : struct s2n_cipher_suite *cipher = cipher_preference->suites[j];
2325 [ - + ][ # # ]: 1002400 : POSIX_ENSURE_REF(cipher);
2326 : :
2327 : 1002400 : const uint8_t *iana = cipher->iana_value;
2328 : :
2329 [ + + ]: 1002400 : if (cipher->minimum_required_tls_version >= S2N_TLS13) {
2330 : 127750 : security_policy_selection[i].supports_tls13 = 1;
2331 : 127750 : }
2332 : :
2333 : : /* Sanity check that valid tls13 has minimum tls version set correctly */
2334 [ - + ][ # # ]: 1002400 : S2N_ERROR_IF(s2n_is_valid_tls13_cipher(iana) ^ (cipher->minimum_required_tls_version >= S2N_TLS13),
2335 : 1002400 : S2N_ERR_INVALID_SECURITY_POLICY);
2336 : :
2337 [ + + ]: 1002400 : if (s2n_cipher_suite_requires_ecc_extension(cipher)) {
2338 : 714000 : security_policy_selection[i].ecc_extension_required = 1;
2339 : 714000 : }
2340 : :
2341 [ - + ][ # # ]: 1002400 : if (s2n_cipher_suite_requires_pq_extension(cipher) && kem_preference->kem_count > 0) {
2342 : 0 : security_policy_selection[i].pq_kem_extension_required = 1;
2343 : 0 : }
2344 : 1002400 : }
2345 : :
2346 [ - + ]: 73850 : POSIX_GUARD(s2n_validate_kem_preferences(kem_preference, security_policy_selection[i].pq_kem_extension_required));
2347 : :
2348 : : /* Validate that security rules are correctly applied.
2349 : : * This should be checked by a unit test, but outside of unit tests we
2350 : : * check again here to cover the case where the unit tests are not run.
2351 : : */
2352 [ - + ]: 73850 : if (!s2n_in_unit_test()) {
2353 : 0 : struct s2n_security_rule_result result = { 0 };
2354 [ # # ]: 0 : POSIX_GUARD_RESULT(s2n_security_policy_validate_security_rules(security_policy, &result));
2355 [ # # ][ # # ]: 0 : POSIX_ENSURE(!result.found_error, S2N_ERR_INVALID_SECURITY_POLICY);
2356 : 0 : }
2357 : 73850 : }
2358 : 350 : return 0;
2359 : 350 : }
2360 : :
2361 : : bool s2n_ecc_is_extension_required(const struct s2n_security_policy *security_policy)
2362 : 15787 : {
2363 [ + + ]: 15787 : if (security_policy == NULL) {
2364 : 1 : return false;
2365 : 1 : }
2366 : :
2367 [ + + ]: 1511023 : for (int i = 0; security_policy_selection[i].version != NULL; i++) {
2368 [ + + ]: 1505646 : if (security_policy_selection[i].security_policy == security_policy) {
2369 : 10409 : return 1 == security_policy_selection[i].ecc_extension_required;
2370 : 10409 : }
2371 : 1505646 : }
2372 : :
2373 : : /* If cipher preference is not in the official list, compute the result */
2374 : 5377 : const struct s2n_cipher_preferences *cipher_preferences = security_policy->cipher_preferences;
2375 [ - + ]: 5377 : if (cipher_preferences == NULL) {
2376 : 0 : return false;
2377 : 0 : }
2378 [ + + ]: 138607 : for (size_t i = 0; i < cipher_preferences->count; i++) {
2379 [ + + ]: 136141 : if (s2n_cipher_suite_requires_ecc_extension(cipher_preferences->suites[i])) {
2380 : 2911 : return true;
2381 : 2911 : }
2382 : 136141 : }
2383 : :
2384 : 2466 : return false;
2385 : 5377 : }
2386 : :
2387 : : bool s2n_pq_kem_is_extension_required(const struct s2n_security_policy *security_policy)
2388 : 7899 : {
2389 [ + + ]: 7899 : if (security_policy == NULL) {
2390 : 1 : return false;
2391 : 1 : }
2392 : :
2393 [ + + ]: 756136 : for (int i = 0; security_policy_selection[i].version != NULL; i++) {
2394 [ + + ]: 753447 : if (security_policy_selection[i].security_policy == security_policy) {
2395 : 5209 : return 1 == security_policy_selection[i].pq_kem_extension_required;
2396 : 5209 : }
2397 : 753447 : }
2398 : :
2399 : : /* Preferences with no KEMs for the TLS 1.2 PQ KEM extension do not require that extension. */
2400 [ + - ][ + + ]: 2689 : if (security_policy->kem_preferences && security_policy->kem_preferences->kem_count == 0) {
2401 : 2688 : return false;
2402 : 2688 : }
2403 : :
2404 : : /* If cipher preference is not in the official list, compute the result */
2405 : 1 : const struct s2n_cipher_preferences *cipher_preferences = security_policy->cipher_preferences;
2406 [ - + ]: 1 : if (cipher_preferences == NULL) {
2407 : 0 : return false;
2408 : 0 : }
2409 [ + + ]: 2 : for (size_t i = 0; i < cipher_preferences->count; i++) {
2410 [ - + ]: 1 : if (s2n_cipher_suite_requires_pq_extension(cipher_preferences->suites[i])) {
2411 : 0 : return true;
2412 : 0 : }
2413 : 1 : }
2414 : 1 : return false;
2415 : 1 : }
2416 : :
2417 : : /* Checks whether cipher preference supports TLS 1.3 based on whether it is configured
2418 : : * with TLS 1.3 ciphers. Returns true or false.
2419 : : */
2420 : : bool s2n_security_policy_supports_tls13(const struct s2n_security_policy *security_policy)
2421 : 15943 : {
2422 [ + + ]: 15943 : if (security_policy == NULL) {
2423 : 1 : return false;
2424 : 1 : }
2425 : :
2426 [ + + ]: 1283690 : for (size_t i = 0; security_policy_selection[i].version != NULL; i++) {
2427 [ + + ]: 1278987 : if (security_policy_selection[i].security_policy == security_policy) {
2428 : 11239 : return security_policy_selection[i].supports_tls13 == 1;
2429 : 11239 : }
2430 : 1278987 : }
2431 : :
2432 : : /* if cipher preference is not in the official list, compute the result */
2433 : 4703 : const struct s2n_cipher_preferences *cipher_preferences = security_policy->cipher_preferences;
2434 [ - + ]: 4703 : if (cipher_preferences == NULL) {
2435 : 0 : return false;
2436 : 0 : }
2437 : :
2438 [ + + ]: 106625 : for (size_t i = 0; i < cipher_preferences->count; i++) {
2439 [ + + ]: 103276 : if (cipher_preferences->suites[i]->minimum_required_tls_version >= S2N_TLS13) {
2440 : 1354 : return true;
2441 : 1354 : }
2442 : 103276 : }
2443 : :
2444 : 3349 : return false;
2445 : 4703 : }
2446 : :
2447 : : int s2n_connection_is_valid_for_cipher_preferences(struct s2n_connection *conn, const char *version)
2448 : 7 : {
2449 [ - + ][ # # ]: 7 : POSIX_ENSURE_REF(conn);
2450 [ - + ][ # # ]: 7 : POSIX_ENSURE_REF(version);
2451 [ - + ][ # # ]: 7 : POSIX_ENSURE_REF(conn->secure);
2452 [ - + ][ # # ]: 7 : POSIX_ENSURE_REF(conn->secure->cipher_suite);
2453 : :
2454 : 7 : const struct s2n_security_policy *security_policy = NULL;
2455 [ + + ]: 7 : POSIX_GUARD(s2n_find_security_policy_from_version(version, &security_policy));
2456 [ - + ][ # # ]: 6 : POSIX_ENSURE_REF(security_policy);
2457 : :
2458 : : /* make sure we don't use a tls version lower than that configured by the version */
2459 [ + + ]: 6 : if (s2n_connection_get_actual_protocol_version(conn) < security_policy->minimum_protocol_version) {
2460 : 2 : return 0;
2461 : 2 : }
2462 : :
2463 : 4 : struct s2n_cipher_suite *cipher = conn->secure->cipher_suite;
2464 [ - + ][ # # ]: 4 : POSIX_ENSURE_REF(cipher);
2465 [ + + ]: 9 : for (int i = 0; i < security_policy->cipher_preferences->count; ++i) {
2466 [ + + ]: 8 : if (s2n_constant_time_equals(security_policy->cipher_preferences->suites[i]->iana_value, cipher->iana_value, S2N_TLS_CIPHER_SUITE_LEN)) {
2467 : 3 : return 1;
2468 : 3 : }
2469 : 8 : }
2470 : :
2471 : 1 : return 0;
2472 : 4 : }
2473 : :
2474 : : int s2n_validate_kem_preferences(const struct s2n_kem_preferences *kem_preferences, bool pq_kem_extension_required)
2475 : 73857 : {
2476 [ + + ][ + - ]: 73857 : POSIX_ENSURE_REF(kem_preferences);
2477 : :
2478 : : /* Basic sanity checks to assert that the count is 0 if and only if the associated list is NULL */
2479 [ + + ][ + - ]: 73856 : POSIX_ENSURE(S2N_IFF(kem_preferences->tls13_kem_group_count == 0, kem_preferences->tls13_kem_groups == NULL),
2480 : 73854 : S2N_ERR_INVALID_SECURITY_POLICY);
2481 [ + - ][ + + ]: 73854 : POSIX_ENSURE(S2N_IFF(kem_preferences->kem_count == 0, kem_preferences->kems == NULL),
2482 : 73853 : S2N_ERR_INVALID_SECURITY_POLICY);
2483 [ # # ][ - + ]: 73853 : POSIX_ENSURE(kem_preferences->tls13_kem_group_count <= S2N_KEM_GROUPS_COUNT, S2N_ERR_ARRAY_INDEX_OOB);
2484 : :
2485 : : /* The PQ KEM extension is applicable only to TLS 1.2 */
2486 [ + + ]: 73853 : if (pq_kem_extension_required) {
2487 [ + - ][ + - ]: 1 : POSIX_ENSURE(kem_preferences->kem_count > 0, S2N_ERR_INVALID_SECURITY_POLICY);
2488 [ # # ][ # # ]: 0 : POSIX_ENSURE(kem_preferences->kems != NULL, S2N_ERR_INVALID_SECURITY_POLICY);
2489 : 73852 : } else {
2490 [ - + ][ # # ]: 73852 : POSIX_ENSURE(kem_preferences->kem_count == 0, S2N_ERR_INVALID_SECURITY_POLICY);
2491 [ - + ][ # # ]: 73852 : POSIX_ENSURE(kem_preferences->kems == NULL, S2N_ERR_INVALID_SECURITY_POLICY);
2492 : 73852 : }
2493 : :
2494 : 73852 : return S2N_SUCCESS;
2495 : 73853 : }
2496 : :
2497 : : S2N_RESULT s2n_validate_certificate_signature_preferences(const struct s2n_signature_preferences *certificate_signature_preferences)
2498 : 23803 : {
2499 [ - + ][ # # ]: 23803 : RESULT_ENSURE_REF(certificate_signature_preferences);
2500 : :
2501 : 23803 : size_t rsa_pss_scheme_count = 0;
2502 : :
2503 [ + + ]: 275812 : for (size_t i = 0; i < certificate_signature_preferences->count; i++) {
2504 [ + + ]: 252009 : if (certificate_signature_preferences->signature_schemes[i]->libcrypto_nid == NID_rsassaPss) {
2505 : 107108 : rsa_pss_scheme_count++;
2506 : 107108 : }
2507 : 252009 : }
2508 : :
2509 : : /*
2510 : : * https://github.com/aws/s2n-tls/issues/3435
2511 : : *
2512 : : * The Openssl function used to parse signatures off certificates does not differentiate between any rsa pss
2513 : : * signature schemes. Therefore a security policy with a certificate signatures preference list must include
2514 : : * all rsa_pss signature schemes. */
2515 [ + - ][ + + ]: 23803 : RESULT_ENSURE(rsa_pss_scheme_count == NUM_RSA_PSS_SCHEMES || rsa_pss_scheme_count == 0, S2N_ERR_INVALID_SECURITY_POLICY);
[ + + ]
2516 : 23802 : return S2N_RESULT_OK;
2517 : 23803 : }
2518 : :
2519 : : S2N_RESULT s2n_security_policy_get_version(const struct s2n_security_policy *security_policy, const char **version)
2520 : 109 : {
2521 [ # # ][ - + ]: 109 : RESULT_ENSURE_REF(version);
2522 : 109 : *version = NULL;
2523 [ + + ]: 11993 : for (size_t i = 0; security_policy_selection[i].version != NULL; i++) {
2524 [ + + ]: 11978 : if (security_policy_selection[i].security_policy == security_policy) {
2525 : 94 : *version = security_policy_selection[i].version;
2526 : 94 : return S2N_RESULT_OK;
2527 : 94 : }
2528 : 11978 : }
2529 [ + - ]: 15 : RESULT_BAIL(S2N_ERR_INVALID_SECURITY_POLICY);
2530 : 15 : }
2531 : :
2532 : : S2N_RESULT s2n_security_policy_validate_cert_signature(const struct s2n_security_policy *security_policy,
2533 : : const struct s2n_cert_info *info, s2n_error error)
2534 : 745 : {
2535 [ # # ][ - + ]: 745 : RESULT_ENSURE_REF(info);
2536 [ # # ][ - + ]: 745 : RESULT_ENSURE_REF(security_policy);
2537 : 745 : const struct s2n_signature_preferences *sig_preferences = security_policy->certificate_signature_preferences;
2538 : :
2539 [ + + ]: 745 : if (sig_preferences != NULL) {
2540 [ + + ]: 1707 : for (size_t i = 0; i < sig_preferences->count; i++) {
2541 [ + + ]: 1696 : if (sig_preferences->signature_schemes[i]->libcrypto_nid == info->signature_nid) {
2542 : 297 : return S2N_RESULT_OK;
2543 : 297 : }
2544 : 1696 : }
2545 : :
2546 [ + - ]: 11 : RESULT_BAIL(error);
2547 : 11 : }
2548 : 437 : return S2N_RESULT_OK;
2549 : 745 : }
2550 : :
2551 : : S2N_RESULT s2n_security_policy_validate_cert_key(const struct s2n_security_policy *security_policy,
2552 : : const struct s2n_cert_info *info, s2n_error error)
2553 : 1364 : {
2554 [ - + ][ # # ]: 1364 : RESULT_ENSURE_REF(info);
2555 [ # # ][ - + ]: 1364 : RESULT_ENSURE_REF(security_policy);
2556 : 1364 : const struct s2n_certificate_key_preferences *key_preferences = security_policy->certificate_key_preferences;
2557 : :
2558 [ + + ]: 1364 : if (key_preferences != NULL) {
2559 [ + + ]: 120 : for (size_t i = 0; i < key_preferences->count; i++) {
2560 [ + + ]: 111 : if (key_preferences->certificate_keys[i]->public_key_libcrypto_nid == info->public_key_nid
2561 [ + + ]: 111 : && key_preferences->certificate_keys[i]->bits == info->public_key_bits) {
2562 : 83 : return S2N_RESULT_OK;
2563 : 83 : }
2564 : 111 : }
2565 [ + - ]: 9 : RESULT_BAIL(error);
2566 : 9 : }
2567 : 1272 : return S2N_RESULT_OK;
2568 : 1364 : }
2569 : :
2570 : : S2N_RESULT s2n_security_policy_validate_certificate_chain(
2571 : : const struct s2n_security_policy *security_policy,
2572 : : const struct s2n_cert_chain_and_key *cert_key_pair)
2573 : 1276 : {
2574 [ # # ][ - + ]: 1276 : RESULT_ENSURE_REF(security_policy);
2575 [ - + ][ # # ]: 1276 : RESULT_ENSURE_REF(cert_key_pair);
2576 [ - + ][ # # ]: 1276 : RESULT_ENSURE_REF(cert_key_pair->cert_chain);
2577 : :
2578 [ + + ]: 1276 : if (!security_policy->certificate_preferences_apply_locally) {
2579 : 1241 : return S2N_RESULT_OK;
2580 : 1241 : }
2581 : :
2582 : 35 : struct s2n_cert *current = cert_key_pair->cert_chain->head;
2583 [ + + ]: 104 : while (current != NULL) {
2584 [ + + ]: 84 : RESULT_GUARD(s2n_security_policy_validate_cert_key(security_policy, ¤t->info,
2585 : 78 : S2N_ERR_SECURITY_POLICY_INCOMPATIBLE_CERT));
2586 [ + + ]: 78 : RESULT_GUARD(s2n_security_policy_validate_cert_signature(security_policy, ¤t->info,
2587 : 69 : S2N_ERR_SECURITY_POLICY_INCOMPATIBLE_CERT));
2588 : 69 : current = current->next;
2589 : 69 : }
2590 : 20 : return S2N_RESULT_OK;
2591 : 35 : }
2592 : :
2593 : : /* The preference-list comparisons below all treat two NULL lists as equal and a
2594 : : * NULL list as unequal to a non-NULL one, because optional policy fields are left
2595 : : * NULL by the designated initializers used to define each security policy.
2596 : : *
2597 : : * List elements are compared by pointer. Every cipher suite, signature scheme,
2598 : : * curve, KEM, and certificate key is a singleton, so pointer identity is
2599 : : * equivalent to identity of the underlying algorithm.
2600 : : */
2601 : :
2602 : : static bool s2n_cipher_preferences_equals(const struct s2n_cipher_preferences *a,
2603 : : const struct s2n_cipher_preferences *b)
2604 : 3914 : {
2605 [ + + ]: 3914 : if (a == b) {
2606 : 322 : return true;
2607 : 322 : }
2608 [ - + ][ - + ]: 3592 : if (a == NULL || b == NULL) {
2609 : 0 : return false;
2610 : 0 : }
2611 [ + + ]: 3592 : if (a->count != b->count) {
2612 : 3412 : return false;
2613 : 3412 : }
2614 [ + + ]: 180 : if (a->allow_chacha20_boosting != b->allow_chacha20_boosting) {
2615 : 5 : return false;
2616 : 5 : }
2617 [ + + ]: 532 : for (size_t i = 0; i < a->count; i++) {
2618 [ + + ]: 515 : if (a->suites[i] != b->suites[i]) {
2619 : 158 : return false;
2620 : 158 : }
2621 : 515 : }
2622 : 17 : return true;
2623 : 175 : }
2624 : :
2625 : : static bool s2n_signature_preferences_equals(const struct s2n_signature_preferences *a,
2626 : : const struct s2n_signature_preferences *b)
2627 : 475 : {
2628 [ + + ]: 475 : if (a == b) {
2629 : 454 : return true;
2630 : 454 : }
2631 [ - + ][ - + ]: 21 : if (a == NULL || b == NULL) {
2632 : 0 : return false;
2633 : 0 : }
2634 [ + + ]: 21 : if (a->count != b->count) {
2635 : 19 : return false;
2636 : 19 : }
2637 [ + - ]: 2 : for (size_t i = 0; i < a->count; i++) {
2638 [ + - ]: 2 : if (a->signature_schemes[i] != b->signature_schemes[i]) {
2639 : 2 : return false;
2640 : 2 : }
2641 : 2 : }
2642 : 0 : return true;
2643 : 2 : }
2644 : :
2645 : : static bool s2n_ecc_preferences_equals(const struct s2n_ecc_preferences *a,
2646 : : const struct s2n_ecc_preferences *b)
2647 : 227 : {
2648 [ + + ]: 227 : if (a == b) {
2649 : 219 : return true;
2650 : 219 : }
2651 [ - + ][ - + ]: 8 : if (a == NULL || b == NULL) {
2652 : 0 : return false;
2653 : 0 : }
2654 [ + + ]: 8 : if (a->count != b->count) {
2655 : 3 : return false;
2656 : 3 : }
2657 [ + - ]: 5 : for (size_t i = 0; i < a->count; i++) {
2658 [ + - ]: 5 : if (a->ecc_curves[i] != b->ecc_curves[i]) {
2659 : 5 : return false;
2660 : 5 : }
2661 : 5 : }
2662 : 0 : return true;
2663 : 5 : }
2664 : :
2665 : : static bool s2n_kem_preferences_equals(const struct s2n_kem_preferences *a,
2666 : : const struct s2n_kem_preferences *b)
2667 : 339 : {
2668 [ + + ]: 339 : if (a == b) {
2669 : 248 : return true;
2670 : 248 : }
2671 [ - + ][ - + ]: 91 : if (a == NULL || b == NULL) {
2672 : 0 : return false;
2673 : 0 : }
2674 [ - + ]: 91 : if (a->kem_count != b->kem_count) {
2675 : 0 : return false;
2676 : 0 : }
2677 [ + - ]: 91 : if (a->tls13_kem_group_count != b->tls13_kem_group_count) {
2678 : 91 : return false;
2679 : 91 : }
2680 [ # # ]: 0 : for (size_t i = 0; i < a->kem_count; i++) {
2681 [ # # ]: 0 : if (a->kems[i] != b->kems[i]) {
2682 : 0 : return false;
2683 : 0 : }
2684 : 0 : }
2685 [ # # ]: 0 : for (size_t i = 0; i < a->tls13_kem_group_count; i++) {
2686 [ # # ]: 0 : if (a->tls13_kem_groups[i] != b->tls13_kem_groups[i]) {
2687 : 0 : return false;
2688 : 0 : }
2689 : 0 : }
2690 : 0 : return true;
2691 : 0 : }
2692 : :
2693 : : static bool s2n_supported_group_preferences_equals(const struct s2n_supported_group_preferences *a,
2694 : : const struct s2n_supported_group_preferences *b)
2695 : 219 : {
2696 [ + - ]: 219 : if (a == b) {
2697 : 219 : return true;
2698 : 219 : }
2699 [ # # ][ # # ]: 0 : if (a == NULL || b == NULL) {
2700 : 0 : return false;
2701 : 0 : }
2702 [ # # ]: 0 : if (a->count != b->count) {
2703 : 0 : return false;
2704 : 0 : }
2705 : : /* iana_ids holds IANA identifiers by value, not pointers to shared singletons. */
2706 [ # # ]: 0 : for (size_t i = 0; i < a->count; i++) {
2707 [ # # ]: 0 : if (a->iana_ids[i] != b->iana_ids[i]) {
2708 : 0 : return false;
2709 : 0 : }
2710 : 0 : }
2711 : 0 : return true;
2712 : 0 : }
2713 : :
2714 : : static bool s2n_certificate_key_preferences_equals(const struct s2n_certificate_key_preferences *a,
2715 : : const struct s2n_certificate_key_preferences *b)
2716 : 219 : {
2717 [ + - ]: 219 : if (a == b) {
2718 : 219 : return true;
2719 : 219 : }
2720 [ # # ][ # # ]: 0 : if (a == NULL || b == NULL) {
2721 : 0 : return false;
2722 : 0 : }
2723 [ # # ]: 0 : if (a->count != b->count) {
2724 : 0 : return false;
2725 : 0 : }
2726 [ # # ]: 0 : for (size_t i = 0; i < a->count; i++) {
2727 [ # # ]: 0 : if (a->certificate_keys[i] != b->certificate_keys[i]) {
2728 : 0 : return false;
2729 : 0 : }
2730 : 0 : }
2731 : 0 : return true;
2732 : 0 : }
2733 : :
2734 : : S2N_RESULT s2n_security_policy_equals(const struct s2n_security_policy *a,
2735 : : const struct s2n_security_policy *b, bool *equal)
2736 : 22355 : {
2737 [ + - ][ + + ]: 22355 : RESULT_ENSURE_REF(a);
2738 [ + - ][ + + ]: 22354 : RESULT_ENSURE_REF(b);
2739 [ + + ][ + - ]: 22353 : RESULT_ENSURE_MUT(equal);
2740 : :
2741 : : /* Set false up front so that any early return reports "not equal". Only the
2742 : : * fallthrough at the end, after every field has been compared, reports equal. */
2743 : 22352 : *equal = false;
2744 : :
2745 [ + + ]: 22352 : if (a->minimum_protocol_version != b->minimum_protocol_version) {
2746 : 14531 : return S2N_RESULT_OK;
2747 : 14531 : }
2748 [ + + ]: 7821 : if (a->certificate_preferences_apply_locally != b->certificate_preferences_apply_locally) {
2749 : 446 : return S2N_RESULT_OK;
2750 : 446 : }
2751 [ + + ]: 15733 : for (size_t i = 0; i < S2N_SECURITY_RULES_COUNT; i++) {
2752 [ + + ]: 11819 : if (a->rules[i] != b->rules[i]) {
2753 : 3461 : return S2N_RESULT_OK;
2754 : 3461 : }
2755 : 11819 : }
2756 [ + + ]: 3914 : if (!s2n_cipher_preferences_equals(a->cipher_preferences, b->cipher_preferences)) {
2757 : 3575 : return S2N_RESULT_OK;
2758 : 3575 : }
2759 [ + + ]: 339 : if (!s2n_kem_preferences_equals(a->kem_preferences, b->kem_preferences)) {
2760 : 91 : return S2N_RESULT_OK;
2761 : 91 : }
2762 [ + + ]: 248 : if (!s2n_signature_preferences_equals(a->signature_preferences, b->signature_preferences)) {
2763 : 21 : return S2N_RESULT_OK;
2764 : 21 : }
2765 [ - + ]: 227 : if (!s2n_signature_preferences_equals(a->certificate_signature_preferences,
2766 : 227 : b->certificate_signature_preferences)) {
2767 : 0 : return S2N_RESULT_OK;
2768 : 0 : }
2769 [ + + ]: 227 : if (!s2n_ecc_preferences_equals(a->ecc_preferences, b->ecc_preferences)) {
2770 : 8 : return S2N_RESULT_OK;
2771 : 8 : }
2772 [ - + ]: 219 : if (!s2n_supported_group_preferences_equals(a->strongly_preferred_groups, b->strongly_preferred_groups)) {
2773 : 0 : return S2N_RESULT_OK;
2774 : 0 : }
2775 [ - + ]: 219 : if (!s2n_certificate_key_preferences_equals(a->certificate_key_preferences, b->certificate_key_preferences)) {
2776 : 0 : return S2N_RESULT_OK;
2777 : 0 : }
2778 : :
2779 : 219 : *equal = true;
2780 : 219 : return S2N_RESULT_OK;
2781 : 219 : }
|