s3_lib.c 25.2 KB
Newer Older
1
/* ssl/s3_lib.c */
2
/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59
 * All rights reserved.
 *
 * This package is an SSL implementation written
 * by Eric Young (eay@cryptsoft.com).
 * The implementation was written so as to conform with Netscapes SSL.
 * 
 * This library is free for commercial and non-commercial use as long as
 * the following conditions are aheared to.  The following conditions
 * apply to all code found in this distribution, be it the RC4, RSA,
 * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
 * included with this distribution is covered by the same copyright terms
 * except that the holder is Tim Hudson (tjh@cryptsoft.com).
 * 
 * Copyright remains Eric Young's, and as such any Copyright notices in
 * the code are not to be removed.
 * If this package is used in a product, Eric Young should be given attribution
 * as the author of the parts of the library used.
 * This can be in the form of a textual message at program startup or
 * in documentation (online or textual) provided with the package.
 * 
 * Redistribution and use in source and binary forms, with or without
 * modification, are permitted provided that the following conditions
 * are met:
 * 1. Redistributions of source code must retain the copyright
 *    notice, this list of conditions and the following disclaimer.
 * 2. Redistributions in binary form must reproduce the above copyright
 *    notice, this list of conditions and the following disclaimer in the
 *    documentation and/or other materials provided with the distribution.
 * 3. All advertising materials mentioning features or use of this software
 *    must display the following acknowledgement:
 *    "This product includes cryptographic software written by
 *     Eric Young (eay@cryptsoft.com)"
 *    The word 'cryptographic' can be left out if the rouines from the library
 *    being used are not cryptographic related :-).
 * 4. If you include any Windows specific code (or a derivative thereof) from 
 *    the apps directory (application code) you must include an acknowledgement:
 *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
 * 
 * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 * SUCH DAMAGE.
 * 
 * The licence and distribution terms for any publically available version or
 * derivative of this code cannot be changed.  i.e. this code cannot simply be
 * copied and put under another distribution licence
 * [including the GNU Public Licence.]
 */

#include <stdio.h>
U
Ulf Möller 已提交
60 61
#include <openssl/md5.h>
#include <openssl/sha.h>
62
#include <openssl/objects.h>
63 64
#include "ssl_locl.h"

B
Ben Laurie 已提交
65
const char *ssl3_version_str="SSLv3" OPENSSL_VERSION_PTEXT;
66 67 68 69

#define SSL3_NUM_CIPHERS	(sizeof(ssl3_ciphers)/sizeof(SSL_CIPHER))

static long ssl3_default_timeout(void );
U
Ulf Möller 已提交
70

B
Bodo Möller 已提交
71
OPENSSL_GLOBAL SSL_CIPHER ssl3_ciphers[]={
72 73 74 75 76 77
/* The RSA ciphers */
/* Cipher 01 */
	{
	1,
	SSL3_TXT_RSA_NULL_MD5,
	SSL3_CK_RSA_NULL_MD5,
78 79 80 81
	SSL_kRSA|SSL_aRSA|SSL_eNULL |SSL_MD5|SSL_SSLV3,
	SSL_NOT_EXP,
	0,
	0,
82 83
	0,
	SSL_ALL_CIPHERS,
84
	SSL_ALL_STRENGTHS,
85 86 87 88 89 90
	},
/* Cipher 02 */
	{
	1,
	SSL3_TXT_RSA_NULL_SHA,
	SSL3_CK_RSA_NULL_SHA,
91 92 93 94
	SSL_kRSA|SSL_aRSA|SSL_eNULL |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP,
	0,
	0,
95 96
	0,
	SSL_ALL_CIPHERS,
97
	SSL_ALL_STRENGTHS,
98 99 100 101 102 103 104 105
	},

/* anon DH */
/* Cipher 17 */
	{
	1,
	SSL3_TXT_ADH_RC4_40_MD5,
	SSL3_CK_ADH_RC4_40_MD5,
106 107
	SSL_kEDH |SSL_aNULL|SSL_RC4  |SSL_MD5 |SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
108
	0,
109 110
	40,
	128,
111
	SSL_ALL_CIPHERS,
112
	SSL_ALL_STRENGTHS,
113 114 115 116 117 118
	},
/* Cipher 18 */
	{
	1,
	SSL3_TXT_ADH_RC4_128_MD5,
	SSL3_CK_ADH_RC4_128_MD5,
119 120
	SSL_kEDH |SSL_aNULL|SSL_RC4  |SSL_MD5 |SSL_SSLV3,
	SSL_NOT_EXP,
121
	0,
122 123
	128,
	128,
124
	SSL_ALL_CIPHERS,
125
	SSL_ALL_STRENGTHS,
126 127 128 129 130 131
	},
/* Cipher 19 */
	{
	1,
	SSL3_TXT_ADH_DES_40_CBC_SHA,
	SSL3_CK_ADH_DES_40_CBC_SHA,
132 133
	SSL_kEDH |SSL_aNULL|SSL_DES|SSL_SHA1|SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
134
	0,
135 136
	40,
	128,
137
	SSL_ALL_CIPHERS,
138
	SSL_ALL_STRENGTHS,
139 140 141 142 143 144
	},
/* Cipher 1A */
	{
	1,
	SSL3_TXT_ADH_DES_64_CBC_SHA,
	SSL3_CK_ADH_DES_64_CBC_SHA,
145 146
	SSL_kEDH |SSL_aNULL|SSL_DES  |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP,
147
	0,
148 149
	56,
	56,
150
	SSL_ALL_CIPHERS,
151
	SSL_ALL_STRENGTHS,
152 153 154 155
	},
/* Cipher 1B */
	{
	1,
156 157
	SSL3_TXT_ADH_DES_192_CBC_SHA,
	SSL3_CK_ADH_DES_192_CBC_SHA,
158 159
	SSL_kEDH |SSL_aNULL|SSL_3DES |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP,
160
	0,
161 162
	168,
	168,
163
	SSL_ALL_CIPHERS,
164
	SSL_ALL_STRENGTHS,
165 166 167 168 169 170 171 172
	},

/* RSA again */
/* Cipher 03 */
	{
	1,
	SSL3_TXT_RSA_RC4_40_MD5,
	SSL3_CK_RSA_RC4_40_MD5,
173 174
	SSL_kRSA|SSL_aRSA|SSL_RC4  |SSL_MD5 |SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
175
	0,
176 177
	40,
	128,
178
	SSL_ALL_CIPHERS,
179
	SSL_ALL_STRENGTHS,
180 181 182 183 184 185
	},
/* Cipher 04 */
	{
	1,
	SSL3_TXT_RSA_RC4_128_MD5,
	SSL3_CK_RSA_RC4_128_MD5,
186 187
	SSL_kRSA|SSL_aRSA|SSL_RC4  |SSL_MD5|SSL_SSLV3,
	SSL_NOT_EXP|SSL_MEDIUM,
188
	0,
189 190
	128,
	128,
191
	SSL_ALL_CIPHERS,
192
	SSL_ALL_STRENGTHS,
193 194 195 196 197 198
	},
/* Cipher 05 */
	{
	1,
	SSL3_TXT_RSA_RC4_128_SHA,
	SSL3_CK_RSA_RC4_128_SHA,
199 200
	SSL_kRSA|SSL_aRSA|SSL_RC4  |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_MEDIUM,
201
	0,
202 203
	128,
	128,
204
	SSL_ALL_CIPHERS,
205
	SSL_ALL_STRENGTHS,
206 207 208 209 210 211
	},
/* Cipher 06 */
	{
	1,
	SSL3_TXT_RSA_RC2_40_MD5,
	SSL3_CK_RSA_RC2_40_MD5,
212 213
	SSL_kRSA|SSL_aRSA|SSL_RC2  |SSL_MD5 |SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
214
	0,
215 216
	40,
	128,
217
	SSL_ALL_CIPHERS,
218
	SSL_ALL_STRENGTHS,
219 220 221 222 223 224
	},
/* Cipher 07 */
	{
	1,
	SSL3_TXT_RSA_IDEA_128_SHA,
	SSL3_CK_RSA_IDEA_128_SHA,
225 226
	SSL_kRSA|SSL_aRSA|SSL_IDEA |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_MEDIUM,
227
	0,
228 229
	128,
	128,
230
	SSL_ALL_CIPHERS,
231
	SSL_ALL_STRENGTHS,
232 233 234 235 236 237
	},
/* Cipher 08 */
	{
	1,
	SSL3_TXT_RSA_DES_40_CBC_SHA,
	SSL3_CK_RSA_DES_40_CBC_SHA,
238 239
	SSL_kRSA|SSL_aRSA|SSL_DES|SSL_SHA1|SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
240
	0,
241 242
	40,
	56,
243
	SSL_ALL_CIPHERS,
244
	SSL_ALL_STRENGTHS,
245 246 247 248 249 250
	},
/* Cipher 09 */
	{
	1,
	SSL3_TXT_RSA_DES_64_CBC_SHA,
	SSL3_CK_RSA_DES_64_CBC_SHA,
251 252
	SSL_kRSA|SSL_aRSA|SSL_DES  |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_LOW,
253
	0,
254 255
	56,
	56,
256
	SSL_ALL_CIPHERS,
257
	SSL_ALL_STRENGTHS,
258 259 260 261 262 263
	},
/* Cipher 0A */
	{
	1,
	SSL3_TXT_RSA_DES_192_CBC3_SHA,
	SSL3_CK_RSA_DES_192_CBC3_SHA,
264 265
	SSL_kRSA|SSL_aRSA|SSL_3DES |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_HIGH,
266
	0,
267 268
	168,
	168,
269
	SSL_ALL_CIPHERS,
270
	SSL_ALL_STRENGTHS,
271 272 273 274 275 276 277 278
	},

/*  The DH ciphers */
/* Cipher 0B */
	{
	0,
	SSL3_TXT_DH_DSS_DES_40_CBC_SHA,
	SSL3_CK_DH_DSS_DES_40_CBC_SHA,
279 280
	SSL_kDHd |SSL_aDH|SSL_DES|SSL_SHA1|SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
281
	0,
282 283
	40,
	56,
284
	SSL_ALL_CIPHERS,
285
	SSL_ALL_STRENGTHS,
286 287 288 289 290 291
	},
/* Cipher 0C */
	{
	0,
	SSL3_TXT_DH_DSS_DES_64_CBC_SHA,
	SSL3_CK_DH_DSS_DES_64_CBC_SHA,
292 293
	SSL_kDHd |SSL_aDH|SSL_DES  |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_LOW,
294
	0,
295 296
	56,
	56,
297
	SSL_ALL_CIPHERS,
298
	SSL_ALL_STRENGTHS,
299 300 301 302 303 304
	},
/* Cipher 0D */
	{
	0,
	SSL3_TXT_DH_DSS_DES_192_CBC3_SHA,
	SSL3_CK_DH_DSS_DES_192_CBC3_SHA,
305 306
	SSL_kDHd |SSL_aDH|SSL_3DES |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_HIGH,
307
	0,
308 309
	168,
	168,
310
	SSL_ALL_CIPHERS,
311
	SSL_ALL_STRENGTHS,
312 313 314 315 316 317
	},
/* Cipher 0E */
	{
	0,
	SSL3_TXT_DH_RSA_DES_40_CBC_SHA,
	SSL3_CK_DH_RSA_DES_40_CBC_SHA,
318 319
	SSL_kDHr |SSL_aDH|SSL_DES|SSL_SHA1|SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
320
	0,
321 322
	40,
	56,
323
	SSL_ALL_CIPHERS,
324
	SSL_ALL_STRENGTHS,
325 326 327 328 329 330
	},
/* Cipher 0F */
	{
	0,
	SSL3_TXT_DH_RSA_DES_64_CBC_SHA,
	SSL3_CK_DH_RSA_DES_64_CBC_SHA,
331 332
	SSL_kDHr |SSL_aDH|SSL_DES  |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_LOW,
333
	0,
334 335
	56,
	56,
336
	SSL_ALL_CIPHERS,
337
	SSL_ALL_STRENGTHS,
338 339 340 341 342 343
	},
/* Cipher 10 */
	{
	0,
	SSL3_TXT_DH_RSA_DES_192_CBC3_SHA,
	SSL3_CK_DH_RSA_DES_192_CBC3_SHA,
344 345
	SSL_kDHr |SSL_aDH|SSL_3DES |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_HIGH,
346
	0,
347 348
	168,
	168,
349
	SSL_ALL_CIPHERS,
350
	SSL_ALL_STRENGTHS,
351 352 353 354 355 356 357 358
	},

/* The Ephemeral DH ciphers */
/* Cipher 11 */
	{
	1,
	SSL3_TXT_EDH_DSS_DES_40_CBC_SHA,
	SSL3_CK_EDH_DSS_DES_40_CBC_SHA,
359 360
	SSL_kEDH|SSL_aDSS|SSL_DES|SSL_SHA1|SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
361
	0,
362 363
	40,
	56,
364
	SSL_ALL_CIPHERS,
365
	SSL_ALL_STRENGTHS,
366 367 368 369 370 371
	},
/* Cipher 12 */
	{
	1,
	SSL3_TXT_EDH_DSS_DES_64_CBC_SHA,
	SSL3_CK_EDH_DSS_DES_64_CBC_SHA,
372 373
	SSL_kEDH|SSL_aDSS|SSL_DES  |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_LOW,
374
	0,
375 376
	56,
	56,
377
	SSL_ALL_CIPHERS,
378
	SSL_ALL_STRENGTHS,
379 380 381 382 383 384
	},
/* Cipher 13 */
	{
	1,
	SSL3_TXT_EDH_DSS_DES_192_CBC3_SHA,
	SSL3_CK_EDH_DSS_DES_192_CBC3_SHA,
385 386
	SSL_kEDH|SSL_aDSS|SSL_3DES |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_HIGH,
387
	0,
388 389
	168,
	168,
390
	SSL_ALL_CIPHERS,
391
	SSL_ALL_STRENGTHS,
392 393 394 395 396 397
	},
/* Cipher 14 */
	{
	1,
	SSL3_TXT_EDH_RSA_DES_40_CBC_SHA,
	SSL3_CK_EDH_RSA_DES_40_CBC_SHA,
398 399
	SSL_kEDH|SSL_aRSA|SSL_DES|SSL_SHA1|SSL_SSLV3,
	SSL_EXPORT|SSL_EXP40,
400
	0,
401 402
	40,
	56,
403
	SSL_ALL_CIPHERS,
404
	SSL_ALL_STRENGTHS,
405 406 407 408 409 410
	},
/* Cipher 15 */
	{
	1,
	SSL3_TXT_EDH_RSA_DES_64_CBC_SHA,
	SSL3_CK_EDH_RSA_DES_64_CBC_SHA,
411 412
	SSL_kEDH|SSL_aRSA|SSL_DES  |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_LOW,
413
	0,
414 415
	56,
	56,
416
	SSL_ALL_CIPHERS,
417
	SSL_ALL_STRENGTHS,
418 419 420 421 422 423
	},
/* Cipher 16 */
	{
	1,
	SSL3_TXT_EDH_RSA_DES_192_CBC3_SHA,
	SSL3_CK_EDH_RSA_DES_192_CBC3_SHA,
424 425
	SSL_kEDH|SSL_aRSA|SSL_3DES |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP|SSL_HIGH,
426
	0,
427 428
	168,
	168,
429
	SSL_ALL_CIPHERS,
430
	SSL_ALL_STRENGTHS,
431 432 433 434 435 436 437 438
	},

/* Fortezza */
/* Cipher 1C */
	{
	0,
	SSL3_TXT_FZA_DMS_NULL_SHA,
	SSL3_CK_FZA_DMS_NULL_SHA,
439 440 441 442
	SSL_kFZA|SSL_aFZA |SSL_eNULL |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP,
	0,
	0,
443 444
	0,
	SSL_ALL_CIPHERS,
445
	SSL_ALL_STRENGTHS,
446 447 448 449 450 451 452
	},

/* Cipher 1D */
	{
	0,
	SSL3_TXT_FZA_DMS_FZA_SHA,
	SSL3_CK_FZA_DMS_FZA_SHA,
453 454 455 456
	SSL_kFZA|SSL_aFZA |SSL_eFZA |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP,
	0,
	0,
457 458
	0,
	SSL_ALL_CIPHERS,
459
	SSL_ALL_STRENGTHS,
460 461 462 463 464 465 466
	},

/* Cipher 1E */
	{
	0,
	SSL3_TXT_FZA_DMS_RC4_SHA,
	SSL3_CK_FZA_DMS_RC4_SHA,
467 468
	SSL_kFZA|SSL_aFZA |SSL_RC4  |SSL_SHA1|SSL_SSLV3,
	SSL_NOT_EXP,
469
	0,
470 471
	128,
	128,
472
	SSL_ALL_CIPHERS,
473
	SSL_ALL_STRENGTHS,
474 475
	},

B
Ben Laurie 已提交
476
#if TLS1_ALLOW_EXPERIMENTAL_CIPHERSUITES
477 478 479 480
	/* New TLS Export CipherSuites */
	/* Cipher 60 */
	    {
	    1,
481 482
	    TLS1_TXT_RSA_EXPORT1024_WITH_RC4_56_MD5,
	    TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_MD5,
483 484
	    SSL_kRSA|SSL_aRSA|SSL_RC4|SSL_MD5|SSL_TLSV1,
	    SSL_EXPORT|SSL_EXP56,
485
	    0,
486 487 488 489
	    56,
	    128,
	    SSL_ALL_CIPHERS,
	    SSL_ALL_STRENGTHS,
490 491 492 493
	    },
	/* Cipher 61 */
	    {
	    1,
494 495
	    TLS1_TXT_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5,
	    TLS1_CK_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5,
496 497
	    SSL_kRSA|SSL_aRSA|SSL_RC2|SSL_MD5|SSL_TLSV1,
	    SSL_EXPORT|SSL_EXP56,
498
	    0,
499 500 501 502
	    56,
	    128,
	    SSL_ALL_CIPHERS,
	    SSL_ALL_STRENGTHS,
503 504 505 506
	    },
	/* Cipher 62 */
	    {
	    1,
507 508
	    TLS1_TXT_RSA_EXPORT1024_WITH_DES_CBC_SHA,
	    TLS1_CK_RSA_EXPORT1024_WITH_DES_CBC_SHA,
509 510
	    SSL_kRSA|SSL_aRSA|SSL_DES|SSL_SHA|SSL_TLSV1,
	    SSL_EXPORT|SSL_EXP56,
511
	    0,
512 513 514 515
	    56,
	    56,
	    SSL_ALL_CIPHERS,
	    SSL_ALL_STRENGTHS,
516
	    },
517 518 519 520 521
	/* Cipher 63 */
	    {
	    1,
	    TLS1_TXT_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA,
	    TLS1_CK_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA,
522 523
	    SSL_kEDH|SSL_aDSS|SSL_DES|SSL_SHA|SSL_TLSV1,
	    SSL_EXPORT|SSL_EXP56,
524
	    0,
525 526 527 528
	    56,
	    56,
	    SSL_ALL_CIPHERS,
	    SSL_ALL_STRENGTHS,
529 530 531 532 533 534
	    },
	/* Cipher 64 */
	    {
	    1,
	    TLS1_TXT_RSA_EXPORT1024_WITH_RC4_56_SHA,
	    TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_SHA,
535 536
	    SSL_kRSA|SSL_aRSA|SSL_RC4|SSL_SHA|SSL_TLSV1,
	    SSL_EXPORT|SSL_EXP56,
537
	    0,
538 539 540 541
	    56,
	    128,
	    SSL_ALL_CIPHERS,
	    SSL_ALL_STRENGTHS,
542 543 544 545 546 547
	    },
	/* Cipher 65 */
	    {
	    1,
	    TLS1_TXT_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA,
	    TLS1_CK_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA,
548 549
	    SSL_kEDH|SSL_aDSS|SSL_RC4|SSL_SHA|SSL_TLSV1,
	    SSL_EXPORT|SSL_EXP56,
550
	    0,
551 552 553 554
	    56,
	    128,
	    SSL_ALL_CIPHERS,
	    SSL_ALL_STRENGTHS,
555 556 557 558 559 560 561
	    },
	/* Cipher 66 */
	    {
	    1,
	    TLS1_TXT_DHE_DSS_WITH_RC4_128_SHA,
	    TLS1_CK_DHE_DSS_WITH_RC4_128_SHA,
	    SSL_kEDH|SSL_aDSS|SSL_RC4|SSL_SHA|SSL_TLSV1,
562
	    SSL_NOT_EXP,
563
	    0,
564 565 566 567
	    128,
	    128,
	    SSL_ALL_CIPHERS,
	    SSL_ALL_STRENGTHS
568
	    },
B
Ben Laurie 已提交
569
#endif
570

571 572 573
/* end of list */
	};

574 575 576 577 578 579 580 581 582 583 584 585 586 587
static SSL3_ENC_METHOD SSLv3_enc_data={
	ssl3_enc,
	ssl3_mac,
	ssl3_setup_key_block,
	ssl3_generate_master_secret,
	ssl3_change_cipher_state,
	ssl3_final_finish_mac,
	MD5_DIGEST_LENGTH+SHA_DIGEST_LENGTH,
	ssl3_cert_verify_mac,
	SSL3_MD_CLIENT_FINISHED_CONST,4,
	SSL3_MD_SERVER_FINISHED_CONST,4,
	ssl3_alert_code,
	};

588
static SSL_METHOD SSLv3_data= {
589
	SSL3_VERSION,
590 591 592 593 594 595 596 597 598 599
	ssl3_new,
	ssl3_clear,
	ssl3_free,
	ssl_undefined_function,
	ssl_undefined_function,
	ssl3_read,
	ssl3_peek,
	ssl3_write,
	ssl3_shutdown,
	ssl3_renegotiate,
600
	ssl3_renegotiate_check,
601 602 603 604 605 606 607 608 609
	ssl3_ctrl,
	ssl3_ctx_ctrl,
	ssl3_get_cipher_by_char,
	ssl3_put_cipher_by_char,
	ssl3_pending,
	ssl3_num_ciphers,
	ssl3_get_cipher,
	ssl_bad_method,
	ssl3_default_timeout,
610
	&SSLv3_enc_data,
611 612
	};

613 614 615 616 617 618 619 620 621 622 623 624
union rsa_fn_to_char_u
	{
	char *char_p;
	RSA *(*fn_p)(SSL *, int, int);
	};

union dh_fn_to_char_u
	{
	char *char_p;
	DH *(*fn_p)(SSL *, int, int);
	};

U
Ulf Möller 已提交
625
static long ssl3_default_timeout(void)
626 627 628 629 630 631
	{
	/* 2 hours, the 24 hours mentioned in the SSLv3 spec
	 * is way too long for http, the cache would over fill */
	return(60*60*2);
	}

U
Ulf Möller 已提交
632
SSL_METHOD *sslv3_base_method(void)
633 634 635 636
	{
	return(&SSLv3_data);
	}

U
Ulf Möller 已提交
637
int ssl3_num_ciphers(void)
638 639 640 641
	{
	return(SSL3_NUM_CIPHERS);
	}

U
Ulf Möller 已提交
642
SSL_CIPHER *ssl3_get_cipher(unsigned int u)
643 644 645 646 647 648 649 650
	{
	if (u < SSL3_NUM_CIPHERS)
		return(&(ssl3_ciphers[SSL3_NUM_CIPHERS-1-u]));
	else
		return(NULL);
	}

/* The problem is that it may not be the correct record type */
U
Ulf Möller 已提交
651
int ssl3_pending(SSL *s)
652 653 654 655
	{
	return(s->s3->rrec.length);
	}

U
Ulf Möller 已提交
656
int ssl3_new(SSL *s)
657 658 659 660
	{
	SSL3_CTX *s3;

	if ((s3=(SSL3_CTX *)Malloc(sizeof(SSL3_CTX))) == NULL) goto err;
661
	memset(s3,0,sizeof(SSL3_CTX));
662 663

	s->s3=s3;
664
	/*
665 666
	s->s3->tmp.ca_names=NULL;
	s->s3->tmp.key_block=NULL;
667
	s->s3->tmp.key_block_length=0;
668 669
	s->s3->rbuf.buf=NULL;
	s->s3->wbuf.buf=NULL;
670
	*/
671

672
	s->method->ssl_clear(s);
673 674 675 676 677
	return(1);
err:
	return(0);
	}

U
Ulf Möller 已提交
678
void ssl3_free(SSL *s)
679
	{
B
Ben Laurie 已提交
680 681 682
	if(s == NULL)
	    return;

683 684 685 686 687
	ssl3_cleanup_key_block(s);
	if (s->s3->rbuf.buf != NULL)
		Free(s->s3->rbuf.buf);
	if (s->s3->wbuf.buf != NULL)
		Free(s->s3->wbuf.buf);
688 689
	if (s->s3->rrec.comp != NULL)
		Free(s->s3->rrec.comp);
690 691 692 693 694
#ifndef NO_DH
	if (s->s3->tmp.dh != NULL)
		DH_free(s->s3->tmp.dh);
#endif
	if (s->s3->tmp.ca_names != NULL)
B
Ben Laurie 已提交
695
		sk_X509_NAME_pop_free(s->s3->tmp.ca_names,X509_NAME_free);
696 697 698 699 700
	memset(s->s3,0,sizeof(SSL3_CTX));
	Free(s->s3);
	s->s3=NULL;
	}

U
Ulf Möller 已提交
701
void ssl3_clear(SSL *s)
702 703 704 705 706
	{
	unsigned char *rp,*wp;

	ssl3_cleanup_key_block(s);
	if (s->s3->tmp.ca_names != NULL)
B
Ben Laurie 已提交
707
		sk_X509_NAME_pop_free(s->s3->tmp.ca_names,X509_NAME_free);
708

709 710 711 712 713 714
	if (s->s3->rrec.comp != NULL)
		{
		Free(s->s3->rrec.comp);
		s->s3->rrec.comp=NULL;
		}

715 716 717 718
	rp=s->s3->rbuf.buf;
	wp=s->s3->wbuf.buf;

	memset(s->s3,0,sizeof(SSL3_CTX));
719 720
	if (rp != NULL) s->s3->rbuf.buf=rp;
	if (wp != NULL) s->s3->wbuf.buf=wp;
721

722
	ssl_free_wbio_buffer(s);
723

724
	s->packet_length=0;
725 726 727 728 729
	s->s3->renegotiate=0;
	s->s3->total_renegotiations=0;
	s->s3->num_renegotiations=0;
	s->s3->in_read_app_data=0;
	s->version=SSL3_VERSION;
730 731
	}

U
Ulf Möller 已提交
732
long ssl3_ctrl(SSL *s, int cmd, long larg, char *parg)
733
	{
734 735
	int ret=0;

736 737 738 739 740 741 742 743 744 745 746 747
#if !defined(NO_DSA) || !defined(NO_RSA)
	if (
#ifndef NO_RSA
	    cmd == SSL_CTRL_SET_TMP_RSA ||
	    cmd == SSL_CTRL_SET_TMP_RSA_CB ||
#endif
#ifndef NO_DSA
	    cmd == SSL_CTRL_SET_TMP_DH ||
	    cmd == SSL_CTRL_SET_TMP_DH_CB ||
#endif
		0)
		{
748
		if (!ssl_cert_inst(&s->cert))
749 750 751 752 753 754 755
		    	{
			SSLerr(SSL_F_SSL3_CTRL, ERR_R_MALLOC_FAILURE);
			return(0);
			}
		}
#endif

756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772
	switch (cmd)
		{
	case SSL_CTRL_GET_SESSION_REUSED:
		ret=s->hit;
		break;
	case SSL_CTRL_GET_CLIENT_CERT_REQUEST:
		break;
	case SSL_CTRL_GET_NUM_RENEGOTIATIONS:
		ret=s->s3->num_renegotiations;
		break;
	case SSL_CTRL_CLEAR_NUM_RENEGOTIATIONS:
		ret=s->s3->num_renegotiations;
		s->s3->num_renegotiations=0;
		break;
	case SSL_CTRL_GET_TOTAL_RENEGOTIATIONS:
		ret=s->s3->total_renegotiations;
		break;
773
	case SSL_CTRL_GET_FLAGS:
774
		ret=(int)(s->s3->flags);
775
		break;
776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800
#ifndef NO_RSA
	case SSL_CTRL_NEED_TMP_RSA:
		if ((s->cert != NULL) && (s->cert->rsa_tmp == NULL) &&
		    ((s->cert->pkeys[SSL_PKEY_RSA_ENC].privatekey == NULL) ||
		     (EVP_PKEY_size(s->cert->pkeys[SSL_PKEY_RSA_ENC].privatekey) > (512/8))))
			ret = 1;
		break;
	case SSL_CTRL_SET_TMP_RSA:
		{
			RSA *rsa = (RSA *)parg;
			if (rsa == NULL) {
				SSLerr(SSL_F_SSL3_CTRL, ERR_R_PASSED_NULL_PARAMETER);
				return(ret);
			}
			if ((rsa = RSAPrivateKey_dup(rsa)) == NULL) {
				SSLerr(SSL_F_SSL3_CTRL, ERR_R_RSA_LIB);
				return(ret);
			}
			if (s->cert->rsa_tmp != NULL)
				RSA_free(s->cert->rsa_tmp);
			s->cert->rsa_tmp = rsa;
			ret = 1;
		}
		break;
	case SSL_CTRL_SET_TMP_RSA_CB:
801 802 803 804 805 806
		{
		union rsa_fn_to_char_u rsa_tmp_cb;

		rsa_tmp_cb.char_p = parg;
		s->cert->rsa_tmp_cb = rsa_tmp_cb.fn_p;
		}
807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832
		break;
#endif
#ifndef NO_DH
	case SSL_CTRL_SET_TMP_DH:
		{
			DH *dh = (DH *)parg;
			if (dh == NULL) {
				SSLerr(SSL_F_SSL3_CTRL, ERR_R_PASSED_NULL_PARAMETER);
				return(ret);
			}
			if ((dh = DHparams_dup(dh)) == NULL) {
				SSLerr(SSL_F_SSL3_CTRL, ERR_R_DH_LIB);
				return(ret);
			}
			if (!DH_generate_key(dh)) {
				DH_free(dh);
				SSLerr(SSL_F_SSL3_CTRL, ERR_R_DH_LIB);
				return(ret);
			}
			if (s->cert->dh_tmp != NULL)
				DH_free(s->cert->dh_tmp);
			s->cert->dh_tmp = dh;
			ret = 1;
		}
		break;
	case SSL_CTRL_SET_TMP_DH_CB:
833 834 835 836 837 838
		{
		union dh_fn_to_char_u dh_tmp_cb;

		dh_tmp_cb.char_p = parg;
		s->cert->dh_tmp_cb = dh_tmp_cb.fn_p;
		}
839 840
		break;
#endif
841 842 843 844
	default:
		break;
		}
	return(ret);
845 846
	}

U
Ulf Möller 已提交
847
long ssl3_ctx_ctrl(SSL_CTX *ctx, int cmd, long larg, char *parg)
848 849 850
	{
	CERT *cert;

851
	cert=ctx->cert;
852 853 854 855 856 857 858 859 860 861 862 863

	switch (cmd)
		{
#ifndef NO_RSA
	case SSL_CTRL_NEED_TMP_RSA:
		if (	(cert->rsa_tmp == NULL) &&
			((cert->pkeys[SSL_PKEY_RSA_ENC].privatekey == NULL) ||
			 (EVP_PKEY_size(cert->pkeys[SSL_PKEY_RSA_ENC].privatekey) > (512/8)))
			)
			return(1);
		else
			return(0);
864
		/* break; */
865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891
	case SSL_CTRL_SET_TMP_RSA:
		{
		RSA *rsa;
		int i;

		rsa=(RSA *)parg;
		i=1;
		if (rsa == NULL)
			i=0;
		else
			{
			if ((rsa=RSAPrivateKey_dup(rsa)) == NULL)
				i=0;
			}
		if (!i)
			{
			SSLerr(SSL_F_SSL3_CTX_CTRL,ERR_R_RSA_LIB);
			return(0);
			}
		else
			{
			if (cert->rsa_tmp != NULL)
				RSA_free(cert->rsa_tmp);
			cert->rsa_tmp=rsa;
			return(1);
			}
		}
892
		/* break; */
893
	case SSL_CTRL_SET_TMP_RSA_CB:
894 895 896 897 898 899
		{
		union rsa_fn_to_char_u rsa_tmp_cb;

		rsa_tmp_cb.char_p = parg;
		cert->rsa_tmp_cb = rsa_tmp_cb.fn_p;
		}
900 901 902 903 904 905
		break;
#endif
#ifndef NO_DH
	case SSL_CTRL_SET_TMP_DH:
		{
		DH *new=NULL,*dh;
906
		int rret=0;
907 908 909 910 911 912 913 914 915 916 917 918 919

		dh=(DH *)parg;
		if (	((new=DHparams_dup(dh)) == NULL) ||
			(!DH_generate_key(new)))
			{
			SSLerr(SSL_F_SSL3_CTX_CTRL,ERR_R_DH_LIB);
			if (new != NULL) DH_free(new);
			}
		else
			{
			if (cert->dh_tmp != NULL)
				DH_free(cert->dh_tmp);
			cert->dh_tmp=new;
920
			rret=1;
921
			}
922
		return(rret);
923
		}
924
		/*break; */
925
	case SSL_CTRL_SET_TMP_DH_CB:
926 927 928 929 930 931
		{
		union dh_fn_to_char_u dh_tmp_cb;

		dh_tmp_cb.char_p = parg;
		cert->dh_tmp_cb = dh_tmp_cb.fn_p;
		}
932 933
		break;
#endif
934
	/* A Thawte special :-) */
935 936 937
	case SSL_CTRL_EXTRA_CHAIN_CERT:
		if (ctx->extra_certs == NULL)
			{
B
Ben Laurie 已提交
938
			if ((ctx->extra_certs=sk_X509_new_null()) == NULL)
939 940
				return(0);
			}
B
Ben Laurie 已提交
941
		sk_X509_push(ctx->extra_certs,(X509 *)parg);
942 943
		break;

944 945 946 947 948 949 950 951
	default:
		return(0);
		}
	return(1);
	}

/* This function needs to check if the ciphers required are actually
 * available */
U
Ulf Möller 已提交
952
SSL_CIPHER *ssl3_get_cipher_by_char(const unsigned char *p)
953 954 955 956 957 958 959 960 961
	{
	static int init=1;
	static SSL_CIPHER *sorted[SSL3_NUM_CIPHERS];
	SSL_CIPHER c,*cp= &c,**cpp;
	unsigned long id;
	int i;

	if (init)
		{
B
Bodo Möller 已提交
962
		CRYPTO_w_lock(CRYPTO_LOCK_SSL);
963 964 965 966 967 968 969

		for (i=0; i<SSL3_NUM_CIPHERS; i++)
			sorted[i]= &(ssl3_ciphers[i]);

		qsort(	(char *)sorted,
			SSL3_NUM_CIPHERS,sizeof(SSL_CIPHER *),
			FP_ICC ssl_cipher_ptr_id_cmp);
B
Bodo Möller 已提交
970 971 972 973

		CRYPTO_w_unlock(CRYPTO_LOCK_SSL);

		init=0;
974 975 976 977 978 979 980 981 982 983 984 985 986 987
		}

	id=0x03000000L|((unsigned long)p[0]<<8L)|(unsigned long)p[1];
	c.id=id;
	cpp=(SSL_CIPHER **)OBJ_bsearch((char *)&cp,
		(char *)sorted,
		SSL3_NUM_CIPHERS,sizeof(SSL_CIPHER *),
		(int (*)())ssl_cipher_ptr_id_cmp);
	if ((cpp == NULL) || !(*cpp)->valid)
		return(NULL);
	else
		return(*cpp);
	}

U
Ulf Möller 已提交
988
int ssl3_put_cipher_by_char(const SSL_CIPHER *c, unsigned char *p)
989 990 991 992 993 994 995 996 997 998 999 1000 1001
	{
	long l;

	if (p != NULL)
		{
		l=c->id;
		if ((l & 0xff000000) != 0x03000000) return(0);
		p[0]=((unsigned char)(l>> 8L))&0xFF;
		p[1]=((unsigned char)(l     ))&0xFF;
		}
	return(2);
	}

U
Ulf Möller 已提交
1002
int ssl3_part_read(SSL *s, int i)
1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016
	{
	s->rwstate=SSL_READING;

	if (i < 0)
		{
		return(i);
		}
	else
		{
		s->init_num+=i;
		return(0);
		}
	}

U
Ulf Möller 已提交
1017 1018
SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *have,
	     STACK_OF(SSL_CIPHER) *pref)
1019 1020 1021 1022 1023 1024
	{
	SSL_CIPHER *c,*ret=NULL;
	int i,j,ok;
	CERT *cert;
	unsigned long alg,mask,emask;

1025 1026
	/* Let's see which ciphers we can support */
	cert=s->cert;
1027

B
Ben Laurie 已提交
1028
	sk_SSL_CIPHER_set_cmp_func(pref,ssl_cipher_ptr_id_cmp);
1029

B
Ben Laurie 已提交
1030 1031 1032 1033 1034 1035 1036 1037 1038
#ifdef CIPHER_DEBUG
	printf("Have:\n");
	for(i=0 ; i < sk_num(pref) ; ++i)
	    {
	    c=(SSL_CIPHER *)sk_value(pref,i);
	    printf("%p:%s\n",c,c->name);
	    }
#endif

B
Ben Laurie 已提交
1039
	for (i=0; i<sk_SSL_CIPHER_num(have); i++)
1040
		{
B
Ben Laurie 已提交
1041
		c=sk_SSL_CIPHER_value(have,i);
1042

1043
		ssl_set_cert_masks(cert,c);
1044 1045 1046
		mask=cert->mask;
		emask=cert->export_mask;
			
1047
		alg=c->algorithms&(SSL_MKEY_MASK|SSL_AUTH_MASK);
1048
		if (SSL_C_IS_EXPORT(c))
1049 1050 1051
			{
			ok=((alg & emask) == alg)?1:0;
#ifdef CIPHER_DEBUG
B
Ben Laurie 已提交
1052 1053
			printf("%d:[%08lX:%08lX]%p:%s (export)\n",ok,alg,emask,
			       c,c->name);
1054 1055 1056 1057 1058 1059
#endif
			}
		else
			{
			ok=((alg & mask) == alg)?1:0;
#ifdef CIPHER_DEBUG
B
Ben Laurie 已提交
1060 1061
			printf("%d:[%08lX:%08lX]%p:%s\n",ok,alg,mask,c,
			       c->name);
1062 1063 1064 1065 1066
#endif
			}

		if (!ok) continue;
	
B
Ben Laurie 已提交
1067
		j=sk_SSL_CIPHER_find(pref,c);
1068 1069
		if (j >= 0)
			{
B
Ben Laurie 已提交
1070
			ret=sk_SSL_CIPHER_value(pref,j);
1071 1072 1073 1074 1075 1076
			break;
			}
		}
	return(ret);
	}

U
Ulf Möller 已提交
1077
int ssl3_get_req_cert_type(SSL *s, unsigned char *p)
1078 1079 1080 1081 1082 1083 1084 1085 1086
	{
	int ret=0;
	unsigned long alg;

	alg=s->s3->tmp.new_cipher->algorithms;

#ifndef NO_DH
	if (alg & (SSL_kDHr|SSL_kEDH))
		{
1087
#  ifndef NO_RSA
1088
		p[ret++]=SSL3_CT_RSA_FIXED_DH;
1089 1090
#  endif
#  ifndef NO_DSA
1091
		p[ret++]=SSL3_CT_DSS_FIXED_DH;
1092
#  endif
1093
		}
1094 1095
	if ((s->version == SSL3_VERSION) &&
		(alg & (SSL_kEDH|SSL_kDHd|SSL_kDHr)))
1096
		{
1097
#  ifndef NO_RSA
1098
		p[ret++]=SSL3_CT_RSA_EPHEMERAL_DH;
1099 1100
#  endif
#  ifndef NO_DSA
1101
		p[ret++]=SSL3_CT_DSS_EPHEMERAL_DH;
1102
#  endif
1103 1104 1105 1106 1107
		}
#endif /* !NO_DH */
#ifndef NO_RSA
	p[ret++]=SSL3_CT_RSA_SIGN;
#endif
1108
#ifndef NO_DSA
1109
	p[ret++]=SSL3_CT_DSS_SIGN;
1110
#endif
1111 1112 1113
	return(ret);
	}

U
Ulf Möller 已提交
1114
int ssl3_shutdown(SSL *s)
1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128
	{

	/* Don't do anything much if we have not done the handshake or
	 * we don't want to send messages :-) */
	if ((s->quiet_shutdown) || (s->state == SSL_ST_BEFORE))
		{
		s->shutdown=(SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN);
		return(1);
		}

	if (!(s->shutdown & SSL_SENT_SHUTDOWN))
		{
		s->shutdown|=SSL_SENT_SHUTDOWN;
#if 1
1129
		ssl3_send_alert(s,SSL3_AL_WARNING,SSL_AD_CLOSE_NOTIFY);
1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149 1150 1151 1152 1153
#endif
		/* our shutdown alert has been sent now, and if it still needs
	 	 * to be written, s->s3->alert_dispatch will be true */
		}
	else if (s->s3->alert_dispatch)
		{
		/* resend it if not sent */
#if 1
		ssl3_dispatch_alert(s);
#endif
		}
	else if (!(s->shutdown & SSL_RECEIVED_SHUTDOWN))
		{
		/* If we are waiting for a close from our peer, we are closed */
		ssl3_read_bytes(s,0,NULL,0);
		}

	if ((s->shutdown == (SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN)) &&
		!s->s3->alert_dispatch)
		return(1);
	else
		return(0);
	}

B
Ben Laurie 已提交
1154
int ssl3_write(SSL *s, const void *buf, int len)
1155 1156 1157 1158 1159 1160 1161 1162 1163 1164
	{
	int ret,n;

#if 0
	if (s->shutdown & SSL_SEND_SHUTDOWN)
		{
		s->rwstate=SSL_NOTHING;
		return(0);
		}
#endif
1165 1166
	clear_sys_error();
	if (s->s3->renegotiate) ssl3_renegotiate_check(s);
1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178

	/* This is an experimental flag that sends the
	 * last handshake message in the same packet as the first
	 * use data - used to see if it helps the TCP protocol during
	 * session-id reuse */
	/* The second test is because the buffer may have been removed */
	if ((s->s3->flags & SSL3_FLAGS_POP_BUFFER) && (s->wbio == s->bbio))
		{
		/* First time through, we write into the buffer */
		if (s->s3->delay_buf_pop_ret == 0)
			{
			ret=ssl3_write_bytes(s,SSL3_RT_APPLICATION_DATA,
B
Ben Laurie 已提交
1179
					     buf,len);
1180 1181 1182 1183 1184 1185 1186 1187 1188 1189
			if (ret <= 0) return(ret);

			s->s3->delay_buf_pop_ret=ret;
			}

		s->rwstate=SSL_WRITING;
		n=BIO_flush(s->wbio);
		if (n <= 0) return(n);
		s->rwstate=SSL_NOTHING;

1190 1191 1192 1193
		/* We have flushed the buffer, so remove it */
		ssl_free_wbio_buffer(s);
		s->s3->flags&= ~SSL3_FLAGS_POP_BUFFER;

1194 1195 1196 1197 1198 1199
		ret=s->s3->delay_buf_pop_ret;
		s->s3->delay_buf_pop_ret=0;
		}
	else
		{
		ret=ssl3_write_bytes(s,SSL3_RT_APPLICATION_DATA,
B
Ben Laurie 已提交
1200
				     buf,len);
1201 1202
		if (ret <= 0) return(ret);
		}
1203

1204 1205 1206
	return(ret);
	}

B
Ben Laurie 已提交
1207
int ssl3_read(SSL *s, void *buf, int len)
1208
	{
1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226
	int ret;
	
	clear_sys_error();
	if (s->s3->renegotiate) ssl3_renegotiate_check(s);
	s->s3->in_read_app_data=1;
	ret=ssl3_read_bytes(s,SSL3_RT_APPLICATION_DATA,buf,len);
	if ((ret == -1) && (s->s3->in_read_app_data == 0))
		{
		ERR_get_error(); /* clear the error */
		s->s3->in_read_app_data=0;
		s->in_handshake++;
		ret=ssl3_read_bytes(s,SSL3_RT_APPLICATION_DATA,buf,len);
		s->in_handshake--;
		}
	else
		s->s3->in_read_app_data=0;

	return(ret);
1227 1228
	}

U
Ulf Möller 已提交
1229
int ssl3_peek(SSL *s, char *buf, int len)
1230 1231 1232 1233 1234 1235
	{
	SSL3_RECORD *rr;
	int n;

	rr= &(s->s3->rrec);
	if ((rr->length == 0) || (rr->type != SSL3_RT_APPLICATION_DATA))
1236 1237 1238 1239 1240 1241
		{
		n=ssl3_read(s,buf,1);
		if (n <= 0) return(n);
		rr->length++;
		rr->off--;
		}
1242 1243 1244 1245 1246 1247 1248 1249 1250

	if ((unsigned int)len > rr->length)
		n=rr->length;
	else
		n=len;
	memcpy(buf,&(rr->data[rr->off]),(unsigned int)n);
	return(n);
	}

U
Ulf Möller 已提交
1251
int ssl3_renegotiate(SSL *s)
1252 1253 1254 1255 1256 1257 1258
	{
	if (s->handshake_func == NULL)
		return(1);

	if (s->s3->flags & SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS)
		return(0);

1259
	s->s3->renegotiate=1;
1260 1261 1262
	return(1);
	}

U
Ulf Möller 已提交
1263
int ssl3_renegotiate_check(SSL *s)
1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274
	{
	int ret=0;

	if (s->s3->renegotiate)
		{
		if (	(s->s3->rbuf.left == 0) &&
			(s->s3->wbuf.left == 0) &&
			!SSL_in_init(s))
			{
/*
if we are the server, and we have sent a 'RENEGOTIATE' message, we
U
Ulf Möller 已提交
1275
need to go to SSL_ST_ACCEPT.
1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287
*/
			/* SSL_ST_ACCEPT */
			s->state=SSL_ST_RENEGOTIATE;
			s->s3->renegotiate=0;
			s->s3->num_renegotiations++;
			s->s3->total_renegotiations++;
			ret=1;
			}
		}
	return(ret);
	}