Branch data Line data Source code
1 : : /*
2 : : * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
3 : : *
4 : : * Licensed under the Apache License, Version 2.0 (the "License").
5 : : * You may not use this file except in compliance with the License.
6 : : * A copy of the License is located at
7 : : *
8 : : * http://aws.amazon.com/apache2.0
9 : : *
10 : : * or in the "license" file accompanying this file. This file is distributed
11 : : * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either
12 : : * express or implied. See the License for the specific language governing
13 : : * permissions and limitations under the License.
14 : : */
15 : :
16 : : #include <time.h>
17 : :
18 : : #include "api/s2n.h"
19 : : #include "error/s2n_errno.h"
20 : : #include "stuffer/s2n_stuffer.h"
21 : : #include "tls/s2n_alerts.h"
22 : : #include "tls/s2n_connection.h"
23 : : #include "tls/s2n_record.h"
24 : : #include "tls/s2n_resume.h"
25 : : #include "tls/s2n_tls.h"
26 : : #include "tls/s2n_tls13_handshake.h"
27 : : #include "utils/s2n_random.h"
28 : : #include "utils/s2n_safety.h"
29 : :
30 : : /*
31 : : * The maximum size of the NewSessionTicket message, not taking into account the
32 : : * ticket itself.
33 : : *
34 : : * To get the actual maximum size required for the NewSessionTicket message, we'll need
35 : : * to add the size of the ticket, which is much less predictable.
36 : : *
37 : : * This constant is enforced via unit tests.
38 : : */
39 : 300 : #define S2N_TLS13_MAX_FIXED_NEW_SESSION_TICKET_SIZE 112
40 : :
41 : : int s2n_server_nst_recv(struct s2n_connection *conn)
42 : 20 : {
43 [ - + ]: 20 : POSIX_GUARD(s2n_stuffer_read_uint32(&conn->handshake.io, &conn->ticket_lifetime_hint));
44 : :
45 : 20 : uint16_t session_ticket_len = 0;
46 [ - + ]: 20 : POSIX_GUARD(s2n_stuffer_read_uint16(&conn->handshake.io, &session_ticket_len));
47 : :
48 [ + + ]: 20 : if (session_ticket_len > 0) {
49 [ - + ]: 19 : POSIX_GUARD(s2n_realloc(&conn->client_ticket, session_ticket_len));
50 : :
51 [ - + ]: 19 : POSIX_GUARD(s2n_stuffer_read(&conn->handshake.io, &conn->client_ticket));
52 : :
53 [ + + ]: 19 : if (conn->config->session_ticket_cb != NULL) {
54 : 7 : size_t session_len = s2n_connection_get_session_length(conn);
55 : :
56 : : /* Alloc some memory for the serialized session ticket */
57 : 7 : DEFER_CLEANUP(struct s2n_blob mem = { 0 }, s2n_free);
58 [ - + ]: 7 : POSIX_GUARD(s2n_alloc(&mem,
59 : 7 : S2N_STATE_FORMAT_LEN + S2N_SESSION_TICKET_SIZE_LEN + conn->client_ticket.size + S2N_TLS12_STATE_SIZE_IN_BYTES));
60 : :
61 [ - + ]: 7 : POSIX_GUARD(s2n_connection_get_session(conn, mem.data, session_len));
62 : 7 : uint32_t session_lifetime = s2n_connection_get_session_ticket_lifetime_hint(conn);
63 : :
64 : 7 : struct s2n_session_ticket ticket = { .ticket_data = mem, .session_lifetime = session_lifetime };
65 : :
66 [ - + ][ # # ]: 7 : POSIX_ENSURE(conn->config->session_ticket_cb(conn, conn->config->session_ticket_ctx, &ticket) >= S2N_SUCCESS,
67 : 7 : S2N_ERR_CANCELLED);
68 : 7 : }
69 : 19 : }
70 : :
71 : 20 : return S2N_SUCCESS;
72 : 20 : }
73 : :
74 : : static S2N_RESULT s2n_generate_ticket_lifetime(struct s2n_connection *conn, uint64_t key_intro_time,
75 : : uint32_t *ticket_lifetime)
76 : 407 : {
77 [ # # ][ - + ]: 407 : RESULT_ENSURE_REF(conn);
78 [ - + ][ # # ]: 407 : RESULT_ENSURE_REF(conn->config);
79 [ - + ][ # # ]: 407 : RESULT_ENSURE_MUT(ticket_lifetime);
80 : :
81 : 407 : uint64_t now = 0;
82 [ - + ]: 407 : RESULT_GUARD(s2n_config_wall_clock(conn->config, &now));
83 : :
84 : : /* Calculate ticket key age */
85 [ # # ][ - + ]: 407 : RESULT_ENSURE_GTE(now, key_intro_time);
86 : 407 : uint64_t ticket_key_age_in_nanos = now - key_intro_time;
87 : :
88 : : /* Calculate remaining key lifetime */
89 : 407 : uint64_t key_lifetime_in_nanos = conn->config->encrypt_decrypt_key_lifetime_in_nanos + conn->config->decrypt_key_lifetime_in_nanos;
90 [ - + ][ # # ]: 407 : RESULT_ENSURE_GTE(key_lifetime_in_nanos, ticket_key_age_in_nanos);
91 : 407 : uint32_t remaining_key_lifetime = (key_lifetime_in_nanos - ticket_key_age_in_nanos) / ONE_SEC_IN_NANOS;
92 : :
93 : 407 : uint32_t session_lifetime = conn->config->session_state_lifetime_in_nanos / ONE_SEC_IN_NANOS;
94 : :
95 : : /* Min of remaining key lifetime and session */
96 [ + + ]: 407 : uint32_t min_lifetime = S2N_MIN(remaining_key_lifetime, session_lifetime);
97 : :
98 : : /* In TLS1.3 we take into account keying material lifetime */
99 [ + + ]: 407 : if (conn->actual_protocol_version == S2N_TLS13) {
100 : 388 : uint32_t key_material_lifetime = conn->server_keying_material_lifetime;
101 : 388 : struct s2n_psk *chosen_psk = conn->psk_params.chosen_psk;
102 [ + + ]: 388 : if (chosen_psk) {
103 [ - + ][ # # ]: 186 : RESULT_ENSURE_GTE(chosen_psk->keying_material_expiration, now);
104 : 186 : uint32_t psk_key_material_lifetime = (chosen_psk->keying_material_expiration - now) / ONE_SEC_IN_NANOS;
105 [ - + ]: 186 : key_material_lifetime = S2N_MIN(key_material_lifetime, psk_key_material_lifetime);
106 : 186 : }
107 [ + - ]: 388 : min_lifetime = S2N_MIN(min_lifetime, key_material_lifetime);
108 : 388 : }
109 : :
110 : : /**
111 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
112 : : *# Servers MUST NOT use any value greater than
113 : : *# 604800 seconds (7 days).
114 : : **/
115 [ + - ]: 407 : *ticket_lifetime = S2N_MIN(min_lifetime, ONE_WEEK_IN_SEC);
116 : :
117 : 407 : return S2N_RESULT_OK;
118 : 407 : }
119 : :
120 : : int s2n_server_nst_send(struct s2n_connection *conn)
121 : 23 : {
122 [ - + ][ # # ]: 23 : POSIX_ENSURE_REF(conn);
123 : :
124 : 23 : uint8_t data[S2N_TLS12_TICKET_SIZE_IN_BYTES] = { 0 };
125 : 23 : struct s2n_blob session_ticket = { 0 };
126 [ - + ]: 23 : POSIX_GUARD(s2n_blob_init(&session_ticket, data, sizeof(data)));
127 : :
128 : 23 : uint32_t lifetime_hint_in_secs = 0;
129 : :
130 : : /* Send a zero-length ticket in the NewSessionTicket message if the server changes
131 : : * its mind mid-handshake or if there are no valid encrypt keys currently available.
132 : : *
133 : : *= https://www.rfc-editor.org/rfc/rfc5077#section-3.3
134 : : *# If the server determines that it does not want to include a
135 : : *# ticket after it has included the SessionTicket extension in the
136 : : *# ServerHello, then it sends a zero-length ticket in the
137 : : *# NewSessionTicket handshake message.
138 : : **/
139 [ + + ]: 23 : if (s2n_result_is_error(s2n_server_nst_write(conn, &lifetime_hint_in_secs, &session_ticket))) {
140 [ - + ]: 3 : POSIX_GUARD(s2n_stuffer_write_uint32(&conn->handshake.io, 0));
141 [ - + ]: 3 : POSIX_GUARD(s2n_stuffer_write_uint16(&conn->handshake.io, 0));
142 : 3 : return S2N_SUCCESS;
143 : 3 : }
144 : :
145 [ - + ]: 20 : POSIX_GUARD(s2n_stuffer_write_uint32(&conn->handshake.io, lifetime_hint_in_secs));
146 [ - + ]: 20 : POSIX_GUARD(s2n_stuffer_write_uint16(&conn->handshake.io, session_ticket.size));
147 [ - + ]: 20 : POSIX_GUARD(s2n_stuffer_write(&conn->handshake.io, &session_ticket));
148 : :
149 : : /* For parity with TLS1.3, track the single ticket sent.
150 : : * This simplifies s2n_connection_get_tickets_sent.
151 : : */
152 : 20 : conn->tickets_sent++;
153 : 20 : return S2N_SUCCESS;
154 : 20 : }
155 : :
156 : : S2N_RESULT s2n_server_nst_write(struct s2n_connection *conn, uint32_t *lifetime_hint_in_secs,
157 : : struct s2n_blob *session_ticket)
158 : 23 : {
159 [ # # ][ - + ]: 23 : RESULT_ENSURE_REF(conn);
160 [ + - ][ + + ]: 23 : RESULT_ENSURE(s2n_server_sending_nst(conn), S2N_ERR_SENDING_NST);
[ + - ]
161 : :
162 : 21 : struct s2n_stuffer output = { 0 };
163 [ - + ]: 21 : RESULT_GUARD_POSIX(s2n_stuffer_init(&output, session_ticket));
164 : :
165 : 21 : struct s2n_ticket_key *key = s2n_get_ticket_encrypt_decrypt_key(conn->config);
166 [ + - ][ + + ]: 21 : RESULT_ENSURE(key != NULL, S2N_ERR_NO_TICKET_ENCRYPT_DECRYPT_KEY);
167 : :
168 [ - + ]: 20 : RESULT_GUARD(s2n_generate_ticket_lifetime(conn, key->intro_timestamp, lifetime_hint_in_secs));
169 [ - + ]: 20 : RESULT_GUARD(s2n_resume_encrypt_session_ticket(conn, key, &output));
170 : :
171 : 20 : return S2N_RESULT_OK;
172 : 20 : }
173 : :
174 : : S2N_RESULT s2n_tls13_server_nst_send(struct s2n_connection *conn, s2n_blocked_status *blocked)
175 : 51445 : {
176 [ # # ][ - + ]: 51445 : RESULT_ENSURE_REF(conn);
177 [ + + ][ + - ]: 51445 : RESULT_ENSURE_GTE(conn->actual_protocol_version, S2N_TLS13);
178 : :
179 : : /* Usually tickets are sent immediately after the handshake.
180 : : * If possible, reuse the handshake IO stuffer before it's wiped.
181 : : *
182 : : * Note: handshake.io isn't explicitly dedicated to only reading or only writing,
183 : : * so we have to be careful using it outside of s2n_negotiate.
184 : : * If we use it for writing here, we CAN'T use it for reading any post-handshake messages.
185 : : */
186 : 51444 : struct s2n_stuffer *nst_stuffer = &conn->handshake.io;
187 : :
188 [ + + ][ + + ]: 51444 : if (conn->mode != S2N_SERVER || !conn->config->use_tickets) {
189 : 50978 : return S2N_RESULT_OK;
190 : 50978 : }
191 : :
192 : : /* Don't issue tickets under client auth: resumption is not supported in that
193 : : * case (see s2n_select_resumption_psk), so the ticket could never be used.
194 : : */
195 [ + + ]: 466 : if (s2n_connection_is_client_auth_enabled(conn)) {
196 : 2 : return S2N_RESULT_OK;
197 : 2 : }
198 : :
199 : : /* Legacy behavior is that the s2n server sends a NST even if the client did not indicate support
200 : : * for resumption or does not support the psk_dhe_ke mode. This is potentially wasteful so we
201 : : * choose to not extend this behavior to QUIC.
202 : : */
203 [ + + ][ + + ]: 464 : if (conn->quic_enabled && conn->psk_params.psk_ke_mode != S2N_PSK_DHE_KE) {
204 : 3 : return S2N_RESULT_OK;
205 : 3 : }
206 : :
207 : : /* No-op if all tickets already sent.
208 : : * Clean up the stuffer used for the ticket to conserve memory. */
209 [ + + ]: 461 : if (conn->tickets_to_send == conn->tickets_sent) {
210 [ - + ]: 160 : RESULT_GUARD_POSIX(s2n_stuffer_resize(nst_stuffer, 0));
211 : 160 : return S2N_RESULT_OK;
212 : 160 : }
213 : :
214 : : /**
215 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
216 : : *# Note that in principle it is possible to continue issuing new tickets
217 : : *# which indefinitely extend the lifetime of the keying material
218 : : *# originally derived from an initial non-PSK handshake (which was most
219 : : *# likely tied to the peer's certificate). It is RECOMMENDED that
220 : : *# implementations place limits on the total lifetime of such keying
221 : : *# material; these limits should take into account the lifetime of the
222 : : *# peer's certificate, the likelihood of intervening revocation, and the
223 : : *# time since the peer's online CertificateVerify signature.
224 : : */
225 [ + + ]: 301 : if (s2n_result_is_error(s2n_psk_validate_keying_material(conn))) {
226 : 1 : conn->tickets_to_send = conn->tickets_sent;
227 : 1 : return S2N_RESULT_OK;
228 : 1 : }
229 : :
230 [ # # ][ - + ]: 300 : RESULT_ENSURE(conn->tickets_sent <= conn->tickets_to_send, S2N_ERR_INTEGER_OVERFLOW);
231 : :
232 : 300 : size_t session_state_size = 0;
233 [ - + ]: 300 : RESULT_GUARD(s2n_connection_get_session_state_size(conn, &session_state_size));
234 : 300 : const size_t maximum_nst_size = session_state_size + S2N_TLS13_MAX_FIXED_NEW_SESSION_TICKET_SIZE;
235 [ + + ]: 300 : if (s2n_stuffer_space_remaining(nst_stuffer) < maximum_nst_size) {
236 [ - + ]: 129 : RESULT_GUARD_POSIX(s2n_stuffer_resize(nst_stuffer, maximum_nst_size));
237 : 129 : }
238 : :
239 [ + + ]: 599 : while (conn->tickets_to_send - conn->tickets_sent > 0) {
240 [ + + ]: 325 : if (s2n_result_is_error(s2n_tls13_server_nst_write(conn, nst_stuffer))) {
241 : 5 : return S2N_RESULT_OK;
242 : 5 : }
243 : :
244 [ + + ]: 320 : RESULT_GUARD(s2n_post_handshake_write_records(conn, blocked));
245 : 320 : }
246 : :
247 : 274 : return S2N_RESULT_OK;
248 : 300 : }
249 : :
250 : : /**
251 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
252 : : *# A per-ticket value that is unique across all tickets
253 : : *# issued on this connection.
254 : : **/
255 : : static S2N_RESULT s2n_generate_ticket_nonce(uint16_t value, struct s2n_blob *output)
256 : 387 : {
257 [ # # ][ - + ]: 387 : RESULT_ENSURE_MUT(output);
258 : :
259 : 387 : struct s2n_stuffer stuffer = { 0 };
260 [ - + ]: 387 : RESULT_GUARD_POSIX(s2n_stuffer_init(&stuffer, output));
261 [ - + ]: 387 : RESULT_GUARD_POSIX(s2n_stuffer_write_uint16(&stuffer, value));
262 : :
263 : 387 : return S2N_RESULT_OK;
264 : 387 : }
265 : :
266 : : /**
267 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
268 : : *# A securely generated, random 32-bit value that is
269 : : *# used to obscure the age of the ticket that the client includes in
270 : : *# the "pre_shared_key" extension.
271 : : **/
272 : : static S2N_RESULT s2n_generate_ticket_age_add(struct s2n_blob *random_data, uint32_t *ticket_age_add)
273 : 387 : {
274 [ - + ][ # # ]: 387 : RESULT_ENSURE_REF(random_data);
275 [ - + ][ # # ]: 387 : RESULT_ENSURE_REF(ticket_age_add);
276 : :
277 : 387 : struct s2n_stuffer stuffer = { 0 };
278 [ - + ]: 387 : RESULT_GUARD_POSIX(s2n_stuffer_init(&stuffer, random_data));
279 [ - + ]: 387 : RESULT_GUARD_POSIX(s2n_stuffer_skip_write(&stuffer, random_data->size));
280 [ - + ]: 387 : RESULT_GUARD_POSIX(s2n_stuffer_read_uint32(&stuffer, ticket_age_add));
281 : :
282 : 387 : return S2N_RESULT_OK;
283 : 387 : }
284 : :
285 : : /**
286 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
287 : : *# The PSK associated with the ticket is computed as:
288 : : *#
289 : : *# HKDF-Expand-Label(resumption_master_secret,
290 : : *# "resumption", ticket_nonce, Hash.length)
291 : : **/
292 : : static int s2n_generate_session_secret(struct s2n_connection *conn, struct s2n_blob *nonce, struct s2n_blob *output)
293 : 855 : {
294 [ - + ][ # # ]: 855 : POSIX_ENSURE_REF(conn);
295 [ - + ][ # # ]: 855 : POSIX_ENSURE_REF(nonce);
296 [ - + ][ # # ]: 855 : POSIX_ENSURE_REF(output);
297 : :
298 [ - + ]: 855 : s2n_tls13_connection_keys(secrets, conn);
299 : 855 : struct s2n_blob master_secret = { 0 };
300 [ - + ]: 855 : POSIX_GUARD(s2n_blob_init(&master_secret, conn->secrets.version.tls13.resumption_master_secret, secrets.size));
301 [ - + ]: 855 : POSIX_GUARD(s2n_realloc(output, secrets.size));
302 [ - + ]: 855 : POSIX_GUARD_RESULT(s2n_tls13_derive_session_ticket_secret(&secrets, &master_secret, nonce, output));
303 : :
304 : 855 : return S2N_SUCCESS;
305 : 855 : }
306 : :
307 : : S2N_RESULT s2n_tls13_server_nst_write(struct s2n_connection *conn, struct s2n_stuffer *output)
308 : 429 : {
309 [ - + ][ # # ]: 429 : RESULT_ENSURE_REF(conn);
310 [ - + ][ # # ]: 429 : RESULT_ENSURE_REF(output);
311 : :
312 : 429 : struct s2n_ticket_key *key = s2n_get_ticket_encrypt_decrypt_key(conn->config);
313 [ + + ][ + - ]: 429 : RESULT_ENSURE(key != NULL, S2N_ERR_NO_TICKET_ENCRYPT_DECRYPT_KEY);
314 : :
315 : 424 : struct s2n_ticket_fields *ticket_fields = &conn->tls13_ticket_fields;
316 : :
317 : : /* Write message type because session resumption in TLS13 is a post-handshake message */
318 [ - + ]: 424 : RESULT_GUARD_POSIX(s2n_stuffer_write_uint8(output, TLS_SERVER_NEW_SESSION_TICKET));
319 : :
320 : 424 : struct s2n_stuffer_reservation message_size = { 0 };
321 [ - + ]: 424 : RESULT_GUARD_POSIX(s2n_stuffer_reserve_uint24(output, &message_size));
322 : :
323 : 424 : uint32_t ticket_lifetime_in_secs = 0;
324 [ - + ]: 424 : RESULT_GUARD(s2n_generate_ticket_lifetime(conn, key->intro_timestamp, &ticket_lifetime_in_secs));
325 : :
326 [ + + ][ + - ]: 424 : RESULT_ENSURE(ticket_lifetime_in_secs > 0, S2N_ERR_ZERO_LIFETIME_TICKET);
327 [ - + ]: 422 : RESULT_GUARD_POSIX(s2n_stuffer_write_uint32(output, ticket_lifetime_in_secs));
328 : :
329 : : /* Get random data to use as ticket_age_add value */
330 : 422 : uint8_t data[sizeof(uint32_t)] = { 0 };
331 : 422 : struct s2n_blob random_data = { 0 };
332 [ - + ]: 422 : RESULT_GUARD_POSIX(s2n_blob_init(&random_data, data, sizeof(data)));
333 : : /**
334 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
335 : : *# The server MUST generate a fresh value
336 : : *# for each ticket it sends.
337 : : **/
338 [ - + ]: 422 : RESULT_GUARD(s2n_get_private_random_data(&random_data));
339 [ - + ]: 422 : RESULT_GUARD(s2n_generate_ticket_age_add(&random_data, &ticket_fields->ticket_age_add));
340 [ - + ]: 422 : RESULT_GUARD_POSIX(s2n_stuffer_write_uint32(output, ticket_fields->ticket_age_add));
341 : :
342 : : /* Write ticket nonce */
343 : 422 : uint8_t nonce_data[sizeof(uint16_t)] = { 0 };
344 : 422 : struct s2n_blob nonce = { 0 };
345 [ - + ]: 422 : RESULT_GUARD_POSIX(s2n_blob_init(&nonce, nonce_data, sizeof(nonce_data)));
346 [ - + ]: 422 : RESULT_GUARD(s2n_generate_ticket_nonce(conn->tickets_sent, &nonce));
347 [ - + ]: 422 : RESULT_GUARD_POSIX(s2n_stuffer_write_uint8(output, nonce.size));
348 [ - + ]: 422 : RESULT_GUARD_POSIX(s2n_stuffer_write_bytes(output, nonce.data, nonce.size));
349 : :
350 : : /* Derive individual session ticket secret */
351 [ - + ]: 422 : RESULT_GUARD_POSIX(s2n_generate_session_secret(conn, &nonce, &ticket_fields->session_secret));
352 : :
353 : : /* Write ticket */
354 : 422 : struct s2n_stuffer_reservation ticket_size = { 0 };
355 [ - + ]: 422 : RESULT_GUARD_POSIX(s2n_stuffer_reserve_uint16(output, &ticket_size));
356 [ - + ]: 422 : RESULT_GUARD(s2n_resume_encrypt_session_ticket(conn, key, output));
357 [ + + ]: 422 : RESULT_GUARD_POSIX(s2n_stuffer_write_vector_size(&ticket_size));
358 : :
359 [ - + ]: 421 : RESULT_GUARD_POSIX(s2n_extension_list_send(S2N_EXTENSION_LIST_NST, conn, output));
360 : :
361 [ - + ]: 421 : RESULT_GUARD_POSIX(s2n_stuffer_write_vector_size(&message_size));
362 : :
363 [ + - ][ + + ]: 421 : RESULT_ENSURE(conn->tickets_sent < UINT16_MAX, S2N_ERR_INTEGER_OVERFLOW);
364 : 420 : conn->tickets_sent++;
365 : :
366 : 420 : return S2N_RESULT_OK;
367 : 421 : }
368 : :
369 : : /**
370 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
371 : : *# struct {
372 : : *# uint32 ticket_lifetime;
373 : : *# uint32 ticket_age_add;
374 : : *# opaque ticket_nonce<0..255>;
375 : : *# opaque ticket<1..2^16-1>;
376 : : *# Extension extensions<0..2^16-2>;
377 : : *# } NewSessionTicket;
378 : : **/
379 : : S2N_RESULT s2n_tls13_server_nst_recv(struct s2n_connection *conn, struct s2n_stuffer *input)
380 : 487 : {
381 [ # # ][ - + ]: 487 : RESULT_ENSURE_REF(conn);
382 [ - + ][ # # ]: 487 : RESULT_ENSURE_REF(input);
383 [ - + ][ # # ]: 487 : RESULT_ENSURE_REF(conn->config);
384 : :
385 [ + + ][ + - ]: 487 : RESULT_ENSURE(conn->actual_protocol_version >= S2N_TLS13, S2N_ERR_BAD_MESSAGE);
386 [ + + ][ + - ]: 486 : RESULT_ENSURE(conn->mode == S2N_CLIENT, S2N_ERR_BAD_MESSAGE);
387 : :
388 [ + + ]: 483 : if (!conn->config->use_tickets) {
389 : 1 : return S2N_RESULT_OK;
390 : 1 : }
391 : 482 : struct s2n_ticket_fields *ticket_fields = &conn->tls13_ticket_fields;
392 : :
393 : : /* Handle `ticket_lifetime` field */
394 : 482 : uint32_t ticket_lifetime = 0;
395 [ - + ]: 482 : RESULT_GUARD_POSIX(s2n_stuffer_read_uint32(input, &ticket_lifetime));
396 : : /**
397 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
398 : : *# Servers MUST NOT use any value greater than
399 : : *# 604800 seconds (7 days).
400 : : */
401 [ + + ][ + - ]: 482 : RESULT_ENSURE(ticket_lifetime <= ONE_WEEK_IN_SEC, S2N_ERR_BAD_MESSAGE);
402 : : /**
403 : : *= https://www.rfc-editor.org/rfc/rfc8446#section-4.6.1
404 : : *# The value of zero indicates that the
405 : : *# ticket should be discarded immediately.
406 : : */
407 [ + + ]: 481 : if (ticket_lifetime == 0) {
408 : 1 : return S2N_RESULT_OK;
409 : 1 : }
410 : 480 : conn->ticket_lifetime_hint = ticket_lifetime;
411 : :
412 : : /* Handle `ticket_age_add` field */
413 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_stuffer_read_uint32(input, &ticket_fields->ticket_age_add));
414 : :
415 : : /* Handle `ticket_nonce` field */
416 : 480 : uint8_t ticket_nonce_len = 0;
417 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_stuffer_read_uint8(input, &ticket_nonce_len));
418 : 480 : uint8_t nonce_data[UINT8_MAX] = { 0 };
419 : 480 : struct s2n_blob nonce = { 0 };
420 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_blob_init(&nonce, nonce_data, ticket_nonce_len));
421 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_stuffer_read_bytes(input, nonce.data, ticket_nonce_len));
422 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_generate_session_secret(conn, &nonce, &ticket_fields->session_secret));
423 : :
424 : : /* Handle `ticket` field */
425 : 480 : uint16_t session_ticket_len = 0;
426 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_stuffer_read_uint16(input, &session_ticket_len));
427 [ - + ][ # # ]: 480 : RESULT_ENSURE(session_ticket_len > 0, S2N_ERR_SAFETY);
428 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_realloc(&conn->client_ticket, session_ticket_len));
429 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_stuffer_read(input, &conn->client_ticket));
430 : :
431 : : /* Handle `extensions` field */
432 [ - + ]: 480 : RESULT_GUARD_POSIX(s2n_extension_list_recv(S2N_EXTENSION_LIST_NST, conn, input));
433 : :
434 [ + + ]: 480 : if (conn->config->session_ticket_cb != NULL) {
435 : : /* Retrieve serialized session data */
436 : 433 : const uint16_t session_state_size = s2n_connection_get_session_length(conn);
437 : 433 : DEFER_CLEANUP(struct s2n_blob session_state = { 0 }, s2n_free);
438 [ - + ]: 433 : RESULT_GUARD_POSIX(s2n_realloc(&session_state, session_state_size));
439 [ - + ]: 433 : RESULT_GUARD_POSIX(s2n_connection_get_session(conn, session_state.data, session_state.size));
440 : :
441 : 433 : struct s2n_session_ticket ticket = {
442 : 433 : .ticket_data = session_state,
443 : 433 : .session_lifetime = ticket_lifetime
444 : 433 : };
445 [ - + ][ # # ]: 433 : RESULT_ENSURE(conn->config->session_ticket_cb(conn, conn->config->session_ticket_ctx, &ticket) >= S2N_SUCCESS,
446 : 433 : S2N_ERR_CANCELLED);
447 : 433 : }
448 : :
449 : 480 : return S2N_RESULT_OK;
450 : 480 : }
|