1 /** @file
2   Transport Layer Security  -- TLS 1.0/1.1/1.2 Standard definitions, from RFC 2246/4346/5246
3 
4   This file contains common TLS 1.0/1.1/1.2 definitions from RFC 2246/4346/5246
5 
6   Copyright (c) 2016 - 2018, Intel Corporation. All rights reserved.<BR>
7   SPDX-License-Identifier: BSD-2-Clause-Patent
8 **/
9 
10 #ifndef __TLS_1_H__
11 #define __TLS_1_H__
12 
13 #pragma pack(1)
14 
15 ///
16 /// TLS Cipher Suite, refers to A.5 of rfc-2246, rfc-4346 and rfc-5246.
17 ///
18 #define TLS_RSA_WITH_NULL_MD5                    {0x00, 0x01}
19 #define TLS_RSA_WITH_NULL_SHA                    {0x00, 0x02}
20 #define TLS_RSA_WITH_RC4_128_MD5                 {0x00, 0x04}
21 #define TLS_RSA_WITH_RC4_128_SHA                 {0x00, 0x05}
22 #define TLS_RSA_WITH_IDEA_CBC_SHA                {0x00, 0x07}
23 #define TLS_RSA_WITH_DES_CBC_SHA                 {0x00, 0x09}
24 #define TLS_RSA_WITH_3DES_EDE_CBC_SHA            {0x00, 0x0A}
25 #define TLS_DH_DSS_WITH_DES_CBC_SHA              {0x00, 0x0C}
26 #define TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA         {0x00, 0x0D}
27 #define TLS_DH_RSA_WITH_DES_CBC_SHA              {0x00, 0x0F}
28 #define TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA         {0x00, 0x10}
29 #define TLS_DHE_DSS_WITH_DES_CBC_SHA             {0x00, 0x12}
30 #define TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA        {0x00, 0x13}
31 #define TLS_DHE_RSA_WITH_DES_CBC_SHA             {0x00, 0x15}
32 #define TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA        {0x00, 0x16}
33 #define TLS_RSA_WITH_AES_128_CBC_SHA             {0x00, 0x2F}
34 #define TLS_DH_DSS_WITH_AES_128_CBC_SHA          {0x00, 0x30}
35 #define TLS_DH_RSA_WITH_AES_128_CBC_SHA          {0x00, 0x31}
36 #define TLS_DHE_DSS_WITH_AES_128_CBC_SHA         {0x00, 0x32}
37 #define TLS_DHE_RSA_WITH_AES_128_CBC_SHA         {0x00, 0x33}
38 #define TLS_RSA_WITH_AES_256_CBC_SHA             {0x00, 0x35}
39 #define TLS_DH_DSS_WITH_AES_256_CBC_SHA          {0x00, 0x36}
40 #define TLS_DH_RSA_WITH_AES_256_CBC_SHA          {0x00, 0x37}
41 #define TLS_DHE_DSS_WITH_AES_256_CBC_SHA         {0x00, 0x38}
42 #define TLS_DHE_RSA_WITH_AES_256_CBC_SHA         {0x00, 0x39}
43 #define TLS_RSA_WITH_NULL_SHA256                 {0x00, 0x3B}
44 #define TLS_RSA_WITH_AES_128_CBC_SHA256          {0x00, 0x3C}
45 #define TLS_RSA_WITH_AES_256_CBC_SHA256          {0x00, 0x3D}
46 #define TLS_DH_DSS_WITH_AES_128_CBC_SHA256       {0x00, 0x3E}
47 #define TLS_DH_RSA_WITH_AES_128_CBC_SHA256       {0x00, 0x3F}
48 #define TLS_DHE_DSS_WITH_AES_128_CBC_SHA256      {0x00, 0x40}
49 #define TLS_DHE_RSA_WITH_AES_128_CBC_SHA256      {0x00, 0x67}
50 #define TLS_DH_DSS_WITH_AES_256_CBC_SHA256       {0x00, 0x68}
51 #define TLS_DH_RSA_WITH_AES_256_CBC_SHA256       {0x00, 0x69}
52 #define TLS_DHE_DSS_WITH_AES_256_CBC_SHA256      {0x00, 0x6A}
53 #define TLS_DHE_RSA_WITH_AES_256_CBC_SHA256      {0x00, 0x6B}
54 
55 ///
56 /// TLS Version, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.
57 ///
58 #define TLS10_PROTOCOL_VERSION_MAJOR  0x03
59 #define TLS10_PROTOCOL_VERSION_MINOR  0x01
60 #define TLS11_PROTOCOL_VERSION_MAJOR  0x03
61 #define TLS11_PROTOCOL_VERSION_MINOR  0x02
62 #define TLS12_PROTOCOL_VERSION_MAJOR  0x03
63 #define TLS12_PROTOCOL_VERSION_MINOR  0x03
64 
65 ///
66 /// TLS Content Type, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.
67 ///
68 typedef enum {
69   TlsContentTypeChangeCipherSpec = 20,
70   TlsContentTypeAlert            = 21,
71   TlsContentTypeHandshake        = 22,
72   TlsContentTypeApplicationData  = 23,
73 } TLS_CONTENT_TYPE;
74 
75 ///
76 /// TLS Record Header, refers to A.1 of rfc-2246, rfc-4346 and rfc-5246.
77 ///
78 typedef struct {
79   UINT8                   ContentType;
80   EFI_TLS_VERSION         Version;
81   UINT16                  Length;
82 } TLS_RECORD_HEADER;
83 
84 #define TLS_RECORD_HEADER_LENGTH   5
85 
86 //
87 // The length (in bytes) of the TLSPlaintext records payload MUST NOT exceed 2^14.
88 // Refers to section 6.2 of RFC5246.
89 //
90 #define TLS_PLAINTEXT_RECORD_MAX_PAYLOAD_LENGTH   16384
91 
92 //
93 // The length (in bytes) of the TLSCiphertext records payload MUST NOT exceed 2^14 + 2048.
94 // Refers to section 6.2 of RFC5246.
95 //
96 #define TLS_CIPHERTEXT_RECORD_MAX_PAYLOAD_LENGTH   18432
97 
98 #pragma pack()
99 
100 #endif
101 
102