ssl_ciphersuites.c 80 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860
  1. /**
  2. * \file ssl_ciphersuites.c
  3. *
  4. * \brief SSL ciphersuites for mbed TLS
  5. *
  6. * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
  7. * SPDX-License-Identifier: GPL-2.0
  8. *
  9. * This program is free software; you can redistribute it and/or modify
  10. * it under the terms of the GNU General Public License as published by
  11. * the Free Software Foundation; either version 2 of the License, or
  12. * (at your option) any later version.
  13. *
  14. * This program is distributed in the hope that it will be useful,
  15. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  16. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  17. * GNU General Public License for more details.
  18. *
  19. * You should have received a copy of the GNU General Public License along
  20. * with this program; if not, write to the Free Software Foundation, Inc.,
  21. * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
  22. *
  23. * This file is part of mbed TLS (https://tls.mbed.org)
  24. */
  25. #if !defined(MBEDTLS_CONFIG_FILE)
  26. #include "mbedtls/config.h"
  27. #else
  28. #include MBEDTLS_CONFIG_FILE
  29. #endif
  30. #if defined(MBEDTLS_SSL_TLS_C)
  31. #if defined(MBEDTLS_PLATFORM_C)
  32. #include "mbedtls/platform.h"
  33. #else
  34. #include <stdlib.h>
  35. #endif
  36. #include "mbedtls/ssl_ciphersuites.h"
  37. #include "mbedtls/ssl.h"
  38. #include <string.h>
  39. /*
  40. * Ordered from most preferred to least preferred in terms of security.
  41. *
  42. * Current rule (except rc4, weak and null which come last):
  43. * 1. By key exchange:
  44. * Forward-secure non-PSK > forward-secure PSK > ECJPAKE > other non-PSK > other PSK
  45. * 2. By key length and cipher:
  46. * AES-256 > Camellia-256 > AES-128 > Camellia-128 > 3DES
  47. * 3. By cipher mode when relevant GCM > CCM > CBC > CCM_8
  48. * 4. By hash function used when relevant
  49. * 5. By key exchange/auth again: EC > non-EC
  50. */
  51. static const int ciphersuite_preference[] =
  52. {
  53. #if defined(MBEDTLS_SSL_CIPHERSUITES)
  54. MBEDTLS_SSL_CIPHERSUITES,
  55. #else
  56. /* All AES-256 ephemeral suites */
  57. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
  58. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
  59. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,
  60. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM,
  61. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM,
  62. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384,
  63. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,
  64. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256,
  65. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,
  66. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,
  67. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA,
  68. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8,
  69. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM_8,
  70. /* All CAMELLIA-256 ephemeral suites */
  71. MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384,
  72. MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384,
  73. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384,
  74. MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384,
  75. MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384,
  76. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256,
  77. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA,
  78. /* All AES-128 ephemeral suites */
  79. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
  80. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
  81. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,
  82. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM,
  83. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM,
  84. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,
  85. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
  86. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,
  87. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,
  88. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,
  89. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA,
  90. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8,
  91. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM_8,
  92. /* All CAMELLIA-128 ephemeral suites */
  93. MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256,
  94. MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256,
  95. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256,
  96. MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256,
  97. MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256,
  98. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256,
  99. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA,
  100. /* All remaining >= 128-bit ephemeral suites */
  101. MBEDTLS_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA,
  102. MBEDTLS_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA,
  103. MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA,
  104. /* The PSK ephemeral suites */
  105. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384,
  106. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM,
  107. MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384,
  108. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384,
  109. MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA,
  110. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA,
  111. MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384,
  112. MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384,
  113. MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384,
  114. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM_8,
  115. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256,
  116. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM,
  117. MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256,
  118. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256,
  119. MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA,
  120. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA,
  121. MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256,
  122. MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256,
  123. MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256,
  124. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM_8,
  125. MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA,
  126. MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA,
  127. /* The ECJPAKE suite */
  128. MBEDTLS_TLS_ECJPAKE_WITH_AES_128_CCM_8,
  129. /* All AES-256 suites */
  130. MBEDTLS_TLS_RSA_WITH_AES_256_GCM_SHA384,
  131. MBEDTLS_TLS_RSA_WITH_AES_256_CCM,
  132. MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA256,
  133. MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA,
  134. MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384,
  135. MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384,
  136. MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA,
  137. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384,
  138. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384,
  139. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA,
  140. MBEDTLS_TLS_RSA_WITH_AES_256_CCM_8,
  141. /* All CAMELLIA-256 suites */
  142. MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384,
  143. MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256,
  144. MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA,
  145. MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384,
  146. MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384,
  147. MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384,
  148. MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384,
  149. /* All AES-128 suites */
  150. MBEDTLS_TLS_RSA_WITH_AES_128_GCM_SHA256,
  151. MBEDTLS_TLS_RSA_WITH_AES_128_CCM,
  152. MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA256,
  153. MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA,
  154. MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256,
  155. MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256,
  156. MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA,
  157. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256,
  158. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256,
  159. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA,
  160. MBEDTLS_TLS_RSA_WITH_AES_128_CCM_8,
  161. /* All CAMELLIA-128 suites */
  162. MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256,
  163. MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256,
  164. MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA,
  165. MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256,
  166. MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256,
  167. MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256,
  168. MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256,
  169. /* All remaining >= 128-bit suites */
  170. MBEDTLS_TLS_RSA_WITH_3DES_EDE_CBC_SHA,
  171. MBEDTLS_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA,
  172. MBEDTLS_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA,
  173. /* The RSA PSK suites */
  174. MBEDTLS_TLS_RSA_PSK_WITH_AES_256_GCM_SHA384,
  175. MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA384,
  176. MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA,
  177. MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384,
  178. MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384,
  179. MBEDTLS_TLS_RSA_PSK_WITH_AES_128_GCM_SHA256,
  180. MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA256,
  181. MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA,
  182. MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256,
  183. MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256,
  184. MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA,
  185. /* The PSK suites */
  186. MBEDTLS_TLS_PSK_WITH_AES_256_GCM_SHA384,
  187. MBEDTLS_TLS_PSK_WITH_AES_256_CCM,
  188. MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA384,
  189. MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA,
  190. MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_GCM_SHA384,
  191. MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384,
  192. MBEDTLS_TLS_PSK_WITH_AES_256_CCM_8,
  193. MBEDTLS_TLS_PSK_WITH_AES_128_GCM_SHA256,
  194. MBEDTLS_TLS_PSK_WITH_AES_128_CCM,
  195. MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA256,
  196. MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA,
  197. MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256,
  198. MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256,
  199. MBEDTLS_TLS_PSK_WITH_AES_128_CCM_8,
  200. MBEDTLS_TLS_PSK_WITH_3DES_EDE_CBC_SHA,
  201. /* RC4 suites */
  202. MBEDTLS_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA,
  203. MBEDTLS_TLS_ECDHE_RSA_WITH_RC4_128_SHA,
  204. MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA,
  205. MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA,
  206. MBEDTLS_TLS_RSA_WITH_RC4_128_SHA,
  207. MBEDTLS_TLS_RSA_WITH_RC4_128_MD5,
  208. MBEDTLS_TLS_ECDH_RSA_WITH_RC4_128_SHA,
  209. MBEDTLS_TLS_ECDH_ECDSA_WITH_RC4_128_SHA,
  210. MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA,
  211. MBEDTLS_TLS_PSK_WITH_RC4_128_SHA,
  212. /* Weak suites */
  213. MBEDTLS_TLS_DHE_RSA_WITH_DES_CBC_SHA,
  214. MBEDTLS_TLS_RSA_WITH_DES_CBC_SHA,
  215. /* NULL suites */
  216. MBEDTLS_TLS_ECDHE_ECDSA_WITH_NULL_SHA,
  217. MBEDTLS_TLS_ECDHE_RSA_WITH_NULL_SHA,
  218. MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA384,
  219. MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA256,
  220. MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA,
  221. MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA384,
  222. MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA256,
  223. MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA,
  224. MBEDTLS_TLS_RSA_WITH_NULL_SHA256,
  225. MBEDTLS_TLS_RSA_WITH_NULL_SHA,
  226. MBEDTLS_TLS_RSA_WITH_NULL_MD5,
  227. MBEDTLS_TLS_ECDH_RSA_WITH_NULL_SHA,
  228. MBEDTLS_TLS_ECDH_ECDSA_WITH_NULL_SHA,
  229. MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA384,
  230. MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA256,
  231. MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA,
  232. MBEDTLS_TLS_PSK_WITH_NULL_SHA384,
  233. MBEDTLS_TLS_PSK_WITH_NULL_SHA256,
  234. MBEDTLS_TLS_PSK_WITH_NULL_SHA,
  235. #endif /* MBEDTLS_SSL_CIPHERSUITES */
  236. 0
  237. };
  238. static const mbedtls_ssl_ciphersuite_t ciphersuite_definitions[] =
  239. {
  240. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED)
  241. #if defined(MBEDTLS_AES_C)
  242. #if defined(MBEDTLS_SHA1_C)
  243. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  244. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, "TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA",
  245. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  246. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  247. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  248. 0 },
  249. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, "TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA",
  250. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  251. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  252. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  253. 0 },
  254. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  255. #endif /* MBEDTLS_SHA1_C */
  256. #if defined(MBEDTLS_SHA256_C)
  257. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  258. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, "TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256",
  259. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  260. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  261. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  262. 0 },
  263. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  264. #if defined(MBEDTLS_GCM_C)
  265. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, "TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256",
  266. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  267. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  268. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  269. 0 },
  270. #endif /* MBEDTLS_GCM_C */
  271. #endif /* MBEDTLS_SHA256_C */
  272. #if defined(MBEDTLS_SHA512_C)
  273. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  274. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, "TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384",
  275. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  276. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  277. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  278. 0 },
  279. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  280. #if defined(MBEDTLS_GCM_C)
  281. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, "TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384",
  282. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  283. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  284. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  285. 0 },
  286. #endif /* MBEDTLS_GCM_C */
  287. #endif /* MBEDTLS_SHA512_C */
  288. #if defined(MBEDTLS_CCM_C)
  289. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM, "TLS-ECDHE-ECDSA-WITH-AES-256-CCM",
  290. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  291. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  292. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  293. 0 },
  294. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8, "TLS-ECDHE-ECDSA-WITH-AES-256-CCM-8",
  295. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  296. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  297. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  298. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  299. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM, "TLS-ECDHE-ECDSA-WITH-AES-128-CCM",
  300. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  301. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  302. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  303. 0 },
  304. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8, "TLS-ECDHE-ECDSA-WITH-AES-128-CCM-8",
  305. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  306. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  307. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  308. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  309. #endif /* MBEDTLS_CCM_C */
  310. #endif /* MBEDTLS_AES_C */
  311. #if defined(MBEDTLS_CAMELLIA_C)
  312. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  313. #if defined(MBEDTLS_SHA256_C)
  314. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDHE-ECDSA-WITH-CAMELLIA-128-CBC-SHA256",
  315. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  316. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  317. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  318. 0 },
  319. #endif /* MBEDTLS_SHA256_C */
  320. #if defined(MBEDTLS_SHA512_C)
  321. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDHE-ECDSA-WITH-CAMELLIA-256-CBC-SHA384",
  322. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  323. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  324. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  325. 0 },
  326. #endif /* MBEDTLS_SHA512_C */
  327. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  328. #if defined(MBEDTLS_GCM_C)
  329. #if defined(MBEDTLS_SHA256_C)
  330. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-ECDHE-ECDSA-WITH-CAMELLIA-128-GCM-SHA256",
  331. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  332. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  333. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  334. 0 },
  335. #endif /* MBEDTLS_SHA256_C */
  336. #if defined(MBEDTLS_SHA512_C)
  337. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-ECDHE-ECDSA-WITH-CAMELLIA-256-GCM-SHA384",
  338. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  339. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  340. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  341. 0 },
  342. #endif /* MBEDTLS_SHA512_C */
  343. #endif /* MBEDTLS_GCM_C */
  344. #endif /* MBEDTLS_CAMELLIA_C */
  345. #if defined(MBEDTLS_DES_C)
  346. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  347. #if defined(MBEDTLS_SHA1_C)
  348. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA, "TLS-ECDHE-ECDSA-WITH-3DES-EDE-CBC-SHA",
  349. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  350. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  351. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  352. 0 },
  353. #endif /* MBEDTLS_SHA1_C */
  354. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  355. #endif /* MBEDTLS_DES_C */
  356. #if defined(MBEDTLS_ARC4_C)
  357. #if defined(MBEDTLS_SHA1_C)
  358. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, "TLS-ECDHE-ECDSA-WITH-RC4-128-SHA",
  359. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  360. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  361. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  362. MBEDTLS_CIPHERSUITE_NODTLS },
  363. #endif /* MBEDTLS_SHA1_C */
  364. #endif /* MBEDTLS_ARC4_C */
  365. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  366. #if defined(MBEDTLS_SHA1_C)
  367. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_NULL_SHA, "TLS-ECDHE-ECDSA-WITH-NULL-SHA",
  368. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  369. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  370. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  371. MBEDTLS_CIPHERSUITE_WEAK },
  372. #endif /* MBEDTLS_SHA1_C */
  373. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  374. #endif /* MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED */
  375. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED)
  376. #if defined(MBEDTLS_AES_C)
  377. #if defined(MBEDTLS_SHA1_C)
  378. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  379. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, "TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA",
  380. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  381. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  382. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  383. 0 },
  384. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, "TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA",
  385. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  386. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  387. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  388. 0 },
  389. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  390. #endif /* MBEDTLS_SHA1_C */
  391. #if defined(MBEDTLS_SHA256_C)
  392. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  393. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, "TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256",
  394. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  395. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  396. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  397. 0 },
  398. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  399. #if defined(MBEDTLS_GCM_C)
  400. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, "TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256",
  401. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  402. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  403. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  404. 0 },
  405. #endif /* MBEDTLS_GCM_C */
  406. #endif /* MBEDTLS_SHA256_C */
  407. #if defined(MBEDTLS_SHA512_C)
  408. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  409. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, "TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384",
  410. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  411. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  412. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  413. 0 },
  414. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  415. #if defined(MBEDTLS_GCM_C)
  416. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, "TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384",
  417. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  418. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  419. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  420. 0 },
  421. #endif /* MBEDTLS_GCM_C */
  422. #endif /* MBEDTLS_SHA512_C */
  423. #endif /* MBEDTLS_AES_C */
  424. #if defined(MBEDTLS_CAMELLIA_C)
  425. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  426. #if defined(MBEDTLS_SHA256_C)
  427. { MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDHE-RSA-WITH-CAMELLIA-128-CBC-SHA256",
  428. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  429. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  430. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  431. 0 },
  432. #endif /* MBEDTLS_SHA256_C */
  433. #if defined(MBEDTLS_SHA512_C)
  434. { MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDHE-RSA-WITH-CAMELLIA-256-CBC-SHA384",
  435. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  436. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  437. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  438. 0 },
  439. #endif /* MBEDTLS_SHA512_C */
  440. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  441. #if defined(MBEDTLS_GCM_C)
  442. #if defined(MBEDTLS_SHA256_C)
  443. { MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-ECDHE-RSA-WITH-CAMELLIA-128-GCM-SHA256",
  444. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  445. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  446. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  447. 0 },
  448. #endif /* MBEDTLS_SHA256_C */
  449. #if defined(MBEDTLS_SHA512_C)
  450. { MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-ECDHE-RSA-WITH-CAMELLIA-256-GCM-SHA384",
  451. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  452. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  453. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  454. 0 },
  455. #endif /* MBEDTLS_SHA512_C */
  456. #endif /* MBEDTLS_GCM_C */
  457. #endif /* MBEDTLS_CAMELLIA_C */
  458. #if defined(MBEDTLS_DES_C)
  459. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  460. #if defined(MBEDTLS_SHA1_C)
  461. { MBEDTLS_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, "TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA",
  462. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  463. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  464. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  465. 0 },
  466. #endif /* MBEDTLS_SHA1_C */
  467. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  468. #endif /* MBEDTLS_DES_C */
  469. #if defined(MBEDTLS_ARC4_C)
  470. #if defined(MBEDTLS_SHA1_C)
  471. { MBEDTLS_TLS_ECDHE_RSA_WITH_RC4_128_SHA, "TLS-ECDHE-RSA-WITH-RC4-128-SHA",
  472. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  473. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  474. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  475. MBEDTLS_CIPHERSUITE_NODTLS },
  476. #endif /* MBEDTLS_SHA1_C */
  477. #endif /* MBEDTLS_ARC4_C */
  478. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  479. #if defined(MBEDTLS_SHA1_C)
  480. { MBEDTLS_TLS_ECDHE_RSA_WITH_NULL_SHA, "TLS-ECDHE-RSA-WITH-NULL-SHA",
  481. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  482. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  483. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  484. MBEDTLS_CIPHERSUITE_WEAK },
  485. #endif /* MBEDTLS_SHA1_C */
  486. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  487. #endif /* MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED */
  488. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED)
  489. #if defined(MBEDTLS_AES_C)
  490. #if defined(MBEDTLS_SHA512_C) && defined(MBEDTLS_GCM_C)
  491. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, "TLS-DHE-RSA-WITH-AES-256-GCM-SHA384",
  492. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  493. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  494. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  495. 0 },
  496. #endif /* MBEDTLS_SHA512_C && MBEDTLS_GCM_C */
  497. #if defined(MBEDTLS_SHA256_C)
  498. #if defined(MBEDTLS_GCM_C)
  499. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, "TLS-DHE-RSA-WITH-AES-128-GCM-SHA256",
  500. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  501. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  502. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  503. 0 },
  504. #endif /* MBEDTLS_GCM_C */
  505. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  506. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256, "TLS-DHE-RSA-WITH-AES-128-CBC-SHA256",
  507. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  508. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  509. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  510. 0 },
  511. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256, "TLS-DHE-RSA-WITH-AES-256-CBC-SHA256",
  512. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  513. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  514. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  515. 0 },
  516. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  517. #endif /* MBEDTLS_SHA256_C */
  518. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  519. #if defined(MBEDTLS_SHA1_C)
  520. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA, "TLS-DHE-RSA-WITH-AES-128-CBC-SHA",
  521. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  522. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  523. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  524. 0 },
  525. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA, "TLS-DHE-RSA-WITH-AES-256-CBC-SHA",
  526. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  527. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  528. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  529. 0 },
  530. #endif /* MBEDTLS_SHA1_C */
  531. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  532. #if defined(MBEDTLS_CCM_C)
  533. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM, "TLS-DHE-RSA-WITH-AES-256-CCM",
  534. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  535. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  536. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  537. 0 },
  538. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM_8, "TLS-DHE-RSA-WITH-AES-256-CCM-8",
  539. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  540. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  541. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  542. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  543. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM, "TLS-DHE-RSA-WITH-AES-128-CCM",
  544. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  545. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  546. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  547. 0 },
  548. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM_8, "TLS-DHE-RSA-WITH-AES-128-CCM-8",
  549. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  550. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  551. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  552. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  553. #endif /* MBEDTLS_CCM_C */
  554. #endif /* MBEDTLS_AES_C */
  555. #if defined(MBEDTLS_CAMELLIA_C)
  556. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  557. #if defined(MBEDTLS_SHA256_C)
  558. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256",
  559. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  560. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  561. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  562. 0 },
  563. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256, "TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256",
  564. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  565. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  566. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  567. 0 },
  568. #endif /* MBEDTLS_SHA256_C */
  569. #if defined(MBEDTLS_SHA1_C)
  570. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA, "TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA",
  571. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  572. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  573. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  574. 0 },
  575. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA, "TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA",
  576. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  577. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  578. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  579. 0 },
  580. #endif /* MBEDTLS_SHA1_C */
  581. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  582. #if defined(MBEDTLS_GCM_C)
  583. #if defined(MBEDTLS_SHA256_C)
  584. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-DHE-RSA-WITH-CAMELLIA-128-GCM-SHA256",
  585. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  586. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  587. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  588. 0 },
  589. #endif /* MBEDTLS_SHA256_C */
  590. #if defined(MBEDTLS_SHA512_C)
  591. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-DHE-RSA-WITH-CAMELLIA-256-GCM-SHA384",
  592. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  593. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  594. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  595. 0 },
  596. #endif /* MBEDTLS_SHA512_C */
  597. #endif /* MBEDTLS_GCM_C */
  598. #endif /* MBEDTLS_CAMELLIA_C */
  599. #if defined(MBEDTLS_DES_C)
  600. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  601. #if defined(MBEDTLS_SHA1_C)
  602. { MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA, "TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA",
  603. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  604. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  605. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  606. 0 },
  607. #endif /* MBEDTLS_SHA1_C */
  608. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  609. #endif /* MBEDTLS_DES_C */
  610. #endif /* MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED */
  611. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED)
  612. #if defined(MBEDTLS_AES_C)
  613. #if defined(MBEDTLS_SHA512_C) && defined(MBEDTLS_GCM_C)
  614. { MBEDTLS_TLS_RSA_WITH_AES_256_GCM_SHA384, "TLS-RSA-WITH-AES-256-GCM-SHA384",
  615. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA,
  616. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  617. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  618. 0 },
  619. #endif /* MBEDTLS_SHA512_C && MBEDTLS_GCM_C */
  620. #if defined(MBEDTLS_SHA256_C)
  621. #if defined(MBEDTLS_GCM_C)
  622. { MBEDTLS_TLS_RSA_WITH_AES_128_GCM_SHA256, "TLS-RSA-WITH-AES-128-GCM-SHA256",
  623. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  624. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  625. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  626. 0 },
  627. #endif /* MBEDTLS_GCM_C */
  628. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  629. { MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA256, "TLS-RSA-WITH-AES-128-CBC-SHA256",
  630. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  631. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  632. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  633. 0 },
  634. { MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA256, "TLS-RSA-WITH-AES-256-CBC-SHA256",
  635. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  636. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  637. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  638. 0 },
  639. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  640. #endif /* MBEDTLS_SHA256_C */
  641. #if defined(MBEDTLS_SHA1_C)
  642. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  643. { MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA, "TLS-RSA-WITH-AES-128-CBC-SHA",
  644. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  645. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  646. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  647. 0 },
  648. { MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA, "TLS-RSA-WITH-AES-256-CBC-SHA",
  649. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  650. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  651. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  652. 0 },
  653. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  654. #endif /* MBEDTLS_SHA1_C */
  655. #if defined(MBEDTLS_CCM_C)
  656. { MBEDTLS_TLS_RSA_WITH_AES_256_CCM, "TLS-RSA-WITH-AES-256-CCM",
  657. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  658. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  659. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  660. 0 },
  661. { MBEDTLS_TLS_RSA_WITH_AES_256_CCM_8, "TLS-RSA-WITH-AES-256-CCM-8",
  662. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  663. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  664. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  665. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  666. { MBEDTLS_TLS_RSA_WITH_AES_128_CCM, "TLS-RSA-WITH-AES-128-CCM",
  667. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  668. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  669. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  670. 0 },
  671. { MBEDTLS_TLS_RSA_WITH_AES_128_CCM_8, "TLS-RSA-WITH-AES-128-CCM-8",
  672. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  673. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  674. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  675. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  676. #endif /* MBEDTLS_CCM_C */
  677. #endif /* MBEDTLS_AES_C */
  678. #if defined(MBEDTLS_CAMELLIA_C)
  679. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  680. #if defined(MBEDTLS_SHA256_C)
  681. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256",
  682. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  683. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  684. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  685. 0 },
  686. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256, "TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256",
  687. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  688. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  689. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  690. 0 },
  691. #endif /* MBEDTLS_SHA256_C */
  692. #if defined(MBEDTLS_SHA1_C)
  693. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA, "TLS-RSA-WITH-CAMELLIA-128-CBC-SHA",
  694. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  695. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  696. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  697. 0 },
  698. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA, "TLS-RSA-WITH-CAMELLIA-256-CBC-SHA",
  699. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  700. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  701. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  702. 0 },
  703. #endif /* MBEDTLS_SHA1_C */
  704. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  705. #if defined(MBEDTLS_GCM_C)
  706. #if defined(MBEDTLS_SHA256_C)
  707. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-RSA-WITH-CAMELLIA-128-GCM-SHA256",
  708. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  709. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  710. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  711. 0 },
  712. #endif /* MBEDTLS_SHA256_C */
  713. #if defined(MBEDTLS_SHA1_C)
  714. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-RSA-WITH-CAMELLIA-256-GCM-SHA384",
  715. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA,
  716. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  717. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  718. 0 },
  719. #endif /* MBEDTLS_SHA1_C */
  720. #endif /* MBEDTLS_GCM_C */
  721. #endif /* MBEDTLS_CAMELLIA_C */
  722. #if defined(MBEDTLS_DES_C)
  723. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  724. #if defined(MBEDTLS_SHA1_C)
  725. { MBEDTLS_TLS_RSA_WITH_3DES_EDE_CBC_SHA, "TLS-RSA-WITH-3DES-EDE-CBC-SHA",
  726. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  727. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  728. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  729. 0 },
  730. #endif /* MBEDTLS_SHA1_C */
  731. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  732. #endif /* MBEDTLS_DES_C */
  733. #if defined(MBEDTLS_ARC4_C)
  734. #if defined(MBEDTLS_MD5_C)
  735. { MBEDTLS_TLS_RSA_WITH_RC4_128_MD5, "TLS-RSA-WITH-RC4-128-MD5",
  736. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_MD5, MBEDTLS_KEY_EXCHANGE_RSA,
  737. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  738. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  739. MBEDTLS_CIPHERSUITE_NODTLS },
  740. #endif
  741. #if defined(MBEDTLS_SHA1_C)
  742. { MBEDTLS_TLS_RSA_WITH_RC4_128_SHA, "TLS-RSA-WITH-RC4-128-SHA",
  743. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  744. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  745. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  746. MBEDTLS_CIPHERSUITE_NODTLS },
  747. #endif
  748. #endif /* MBEDTLS_ARC4_C */
  749. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_ENABLED */
  750. #if defined(MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED)
  751. #if defined(MBEDTLS_AES_C)
  752. #if defined(MBEDTLS_SHA1_C)
  753. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  754. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA, "TLS-ECDH-RSA-WITH-AES-128-CBC-SHA",
  755. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  756. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  757. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  758. 0 },
  759. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA, "TLS-ECDH-RSA-WITH-AES-256-CBC-SHA",
  760. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  761. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  762. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  763. 0 },
  764. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  765. #endif /* MBEDTLS_SHA1_C */
  766. #if defined(MBEDTLS_SHA256_C)
  767. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  768. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256, "TLS-ECDH-RSA-WITH-AES-128-CBC-SHA256",
  769. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  770. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  771. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  772. 0 },
  773. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  774. #if defined(MBEDTLS_GCM_C)
  775. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256, "TLS-ECDH-RSA-WITH-AES-128-GCM-SHA256",
  776. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  777. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  778. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  779. 0 },
  780. #endif /* MBEDTLS_GCM_C */
  781. #endif /* MBEDTLS_SHA256_C */
  782. #if defined(MBEDTLS_SHA512_C)
  783. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  784. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384, "TLS-ECDH-RSA-WITH-AES-256-CBC-SHA384",
  785. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  786. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  787. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  788. 0 },
  789. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  790. #if defined(MBEDTLS_GCM_C)
  791. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384, "TLS-ECDH-RSA-WITH-AES-256-GCM-SHA384",
  792. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  793. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  794. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  795. 0 },
  796. #endif /* MBEDTLS_GCM_C */
  797. #endif /* MBEDTLS_SHA512_C */
  798. #endif /* MBEDTLS_AES_C */
  799. #if defined(MBEDTLS_CAMELLIA_C)
  800. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  801. #if defined(MBEDTLS_SHA256_C)
  802. { MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDH-RSA-WITH-CAMELLIA-128-CBC-SHA256",
  803. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  804. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  805. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  806. 0 },
  807. #endif /* MBEDTLS_SHA256_C */
  808. #if defined(MBEDTLS_SHA512_C)
  809. { MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDH-RSA-WITH-CAMELLIA-256-CBC-SHA384",
  810. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  811. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  812. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  813. 0 },
  814. #endif /* MBEDTLS_SHA512_C */
  815. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  816. #if defined(MBEDTLS_GCM_C)
  817. #if defined(MBEDTLS_SHA256_C)
  818. { MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-ECDH-RSA-WITH-CAMELLIA-128-GCM-SHA256",
  819. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  820. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  821. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  822. 0 },
  823. #endif /* MBEDTLS_SHA256_C */
  824. #if defined(MBEDTLS_SHA512_C)
  825. { MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-ECDH-RSA-WITH-CAMELLIA-256-GCM-SHA384",
  826. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  827. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  828. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  829. 0 },
  830. #endif /* MBEDTLS_SHA512_C */
  831. #endif /* MBEDTLS_GCM_C */
  832. #endif /* MBEDTLS_CAMELLIA_C */
  833. #if defined(MBEDTLS_DES_C)
  834. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  835. #if defined(MBEDTLS_SHA1_C)
  836. { MBEDTLS_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA, "TLS-ECDH-RSA-WITH-3DES-EDE-CBC-SHA",
  837. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  838. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  839. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  840. 0 },
  841. #endif /* MBEDTLS_SHA1_C */
  842. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  843. #endif /* MBEDTLS_DES_C */
  844. #if defined(MBEDTLS_ARC4_C)
  845. #if defined(MBEDTLS_SHA1_C)
  846. { MBEDTLS_TLS_ECDH_RSA_WITH_RC4_128_SHA, "TLS-ECDH-RSA-WITH-RC4-128-SHA",
  847. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  848. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  849. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  850. MBEDTLS_CIPHERSUITE_NODTLS },
  851. #endif /* MBEDTLS_SHA1_C */
  852. #endif /* MBEDTLS_ARC4_C */
  853. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  854. #if defined(MBEDTLS_SHA1_C)
  855. { MBEDTLS_TLS_ECDH_RSA_WITH_NULL_SHA, "TLS-ECDH-RSA-WITH-NULL-SHA",
  856. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  857. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  858. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  859. MBEDTLS_CIPHERSUITE_WEAK },
  860. #endif /* MBEDTLS_SHA1_C */
  861. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  862. #endif /* MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED */
  863. #if defined(MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED)
  864. #if defined(MBEDTLS_AES_C)
  865. #if defined(MBEDTLS_SHA1_C)
  866. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  867. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA, "TLS-ECDH-ECDSA-WITH-AES-128-CBC-SHA",
  868. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  869. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  870. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  871. 0 },
  872. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA, "TLS-ECDH-ECDSA-WITH-AES-256-CBC-SHA",
  873. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  874. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  875. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  876. 0 },
  877. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  878. #endif /* MBEDTLS_SHA1_C */
  879. #if defined(MBEDTLS_SHA256_C)
  880. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  881. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256, "TLS-ECDH-ECDSA-WITH-AES-128-CBC-SHA256",
  882. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  883. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  884. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  885. 0 },
  886. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  887. #if defined(MBEDTLS_GCM_C)
  888. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256, "TLS-ECDH-ECDSA-WITH-AES-128-GCM-SHA256",
  889. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  890. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  891. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  892. 0 },
  893. #endif /* MBEDTLS_GCM_C */
  894. #endif /* MBEDTLS_SHA256_C */
  895. #if defined(MBEDTLS_SHA512_C)
  896. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  897. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384, "TLS-ECDH-ECDSA-WITH-AES-256-CBC-SHA384",
  898. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  899. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  900. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  901. 0 },
  902. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  903. #if defined(MBEDTLS_GCM_C)
  904. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384, "TLS-ECDH-ECDSA-WITH-AES-256-GCM-SHA384",
  905. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  906. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  907. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  908. 0 },
  909. #endif /* MBEDTLS_GCM_C */
  910. #endif /* MBEDTLS_SHA512_C */
  911. #endif /* MBEDTLS_AES_C */
  912. #if defined(MBEDTLS_CAMELLIA_C)
  913. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  914. #if defined(MBEDTLS_SHA256_C)
  915. { MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDH-ECDSA-WITH-CAMELLIA-128-CBC-SHA256",
  916. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  917. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  918. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  919. 0 },
  920. #endif /* MBEDTLS_SHA256_C */
  921. #if defined(MBEDTLS_SHA512_C)
  922. { MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDH-ECDSA-WITH-CAMELLIA-256-CBC-SHA384",
  923. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  924. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  925. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  926. 0 },
  927. #endif /* MBEDTLS_SHA512_C */
  928. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  929. #if defined(MBEDTLS_GCM_C)
  930. #if defined(MBEDTLS_SHA256_C)
  931. { MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-ECDH-ECDSA-WITH-CAMELLIA-128-GCM-SHA256",
  932. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  933. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  934. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  935. 0 },
  936. #endif /* MBEDTLS_SHA256_C */
  937. #if defined(MBEDTLS_SHA512_C)
  938. { MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-ECDH-ECDSA-WITH-CAMELLIA-256-GCM-SHA384",
  939. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  940. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  941. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  942. 0 },
  943. #endif /* MBEDTLS_SHA512_C */
  944. #endif /* MBEDTLS_GCM_C */
  945. #endif /* MBEDTLS_CAMELLIA_C */
  946. #if defined(MBEDTLS_DES_C)
  947. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  948. #if defined(MBEDTLS_SHA1_C)
  949. { MBEDTLS_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA, "TLS-ECDH-ECDSA-WITH-3DES-EDE-CBC-SHA",
  950. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  951. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  952. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  953. 0 },
  954. #endif /* MBEDTLS_SHA1_C */
  955. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  956. #endif /* MBEDTLS_DES_C */
  957. #if defined(MBEDTLS_ARC4_C)
  958. #if defined(MBEDTLS_SHA1_C)
  959. { MBEDTLS_TLS_ECDH_ECDSA_WITH_RC4_128_SHA, "TLS-ECDH-ECDSA-WITH-RC4-128-SHA",
  960. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  961. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  962. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  963. MBEDTLS_CIPHERSUITE_NODTLS },
  964. #endif /* MBEDTLS_SHA1_C */
  965. #endif /* MBEDTLS_ARC4_C */
  966. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  967. #if defined(MBEDTLS_SHA1_C)
  968. { MBEDTLS_TLS_ECDH_ECDSA_WITH_NULL_SHA, "TLS-ECDH-ECDSA-WITH-NULL-SHA",
  969. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  970. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  971. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  972. MBEDTLS_CIPHERSUITE_WEAK },
  973. #endif /* MBEDTLS_SHA1_C */
  974. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  975. #endif /* MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED */
  976. #if defined(MBEDTLS_KEY_EXCHANGE_PSK_ENABLED)
  977. #if defined(MBEDTLS_AES_C)
  978. #if defined(MBEDTLS_GCM_C)
  979. #if defined(MBEDTLS_SHA256_C)
  980. { MBEDTLS_TLS_PSK_WITH_AES_128_GCM_SHA256, "TLS-PSK-WITH-AES-128-GCM-SHA256",
  981. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  982. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  983. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  984. 0 },
  985. #endif /* MBEDTLS_SHA256_C */
  986. #if defined(MBEDTLS_SHA512_C)
  987. { MBEDTLS_TLS_PSK_WITH_AES_256_GCM_SHA384, "TLS-PSK-WITH-AES-256-GCM-SHA384",
  988. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  989. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  990. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  991. 0 },
  992. #endif /* MBEDTLS_SHA512_C */
  993. #endif /* MBEDTLS_GCM_C */
  994. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  995. #if defined(MBEDTLS_SHA256_C)
  996. { MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA256, "TLS-PSK-WITH-AES-128-CBC-SHA256",
  997. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  998. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  999. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1000. 0 },
  1001. #endif /* MBEDTLS_SHA256_C */
  1002. #if defined(MBEDTLS_SHA512_C)
  1003. { MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA384, "TLS-PSK-WITH-AES-256-CBC-SHA384",
  1004. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  1005. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1006. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1007. 0 },
  1008. #endif /* MBEDTLS_SHA512_C */
  1009. #if defined(MBEDTLS_SHA1_C)
  1010. { MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA, "TLS-PSK-WITH-AES-128-CBC-SHA",
  1011. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1012. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1013. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1014. 0 },
  1015. { MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA, "TLS-PSK-WITH-AES-256-CBC-SHA",
  1016. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1017. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1018. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1019. 0 },
  1020. #endif /* MBEDTLS_SHA1_C */
  1021. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1022. #if defined(MBEDTLS_CCM_C)
  1023. { MBEDTLS_TLS_PSK_WITH_AES_256_CCM, "TLS-PSK-WITH-AES-256-CCM",
  1024. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1025. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1026. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1027. 0 },
  1028. { MBEDTLS_TLS_PSK_WITH_AES_256_CCM_8, "TLS-PSK-WITH-AES-256-CCM-8",
  1029. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1030. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1031. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1032. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1033. { MBEDTLS_TLS_PSK_WITH_AES_128_CCM, "TLS-PSK-WITH-AES-128-CCM",
  1034. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1035. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1036. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1037. 0 },
  1038. { MBEDTLS_TLS_PSK_WITH_AES_128_CCM_8, "TLS-PSK-WITH-AES-128-CCM-8",
  1039. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1040. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1041. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1042. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1043. #endif /* MBEDTLS_CCM_C */
  1044. #endif /* MBEDTLS_AES_C */
  1045. #if defined(MBEDTLS_CAMELLIA_C)
  1046. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1047. #if defined(MBEDTLS_SHA256_C)
  1048. { MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256, "TLS-PSK-WITH-CAMELLIA-128-CBC-SHA256",
  1049. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1050. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1051. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1052. 0 },
  1053. #endif /* MBEDTLS_SHA256_C */
  1054. #if defined(MBEDTLS_SHA512_C)
  1055. { MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384, "TLS-PSK-WITH-CAMELLIA-256-CBC-SHA384",
  1056. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  1057. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1058. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1059. 0 },
  1060. #endif /* MBEDTLS_SHA512_C */
  1061. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1062. #if defined(MBEDTLS_GCM_C)
  1063. #if defined(MBEDTLS_SHA256_C)
  1064. { MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256, "TLS-PSK-WITH-CAMELLIA-128-GCM-SHA256",
  1065. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1066. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1067. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1068. 0 },
  1069. #endif /* MBEDTLS_SHA256_C */
  1070. #if defined(MBEDTLS_SHA512_C)
  1071. { MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_GCM_SHA384, "TLS-PSK-WITH-CAMELLIA-256-GCM-SHA384",
  1072. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  1073. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1074. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1075. 0 },
  1076. #endif /* MBEDTLS_SHA512_C */
  1077. #endif /* MBEDTLS_GCM_C */
  1078. #endif /* MBEDTLS_CAMELLIA_C */
  1079. #if defined(MBEDTLS_DES_C)
  1080. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1081. #if defined(MBEDTLS_SHA1_C)
  1082. { MBEDTLS_TLS_PSK_WITH_3DES_EDE_CBC_SHA, "TLS-PSK-WITH-3DES-EDE-CBC-SHA",
  1083. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1084. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1085. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1086. 0 },
  1087. #endif /* MBEDTLS_SHA1_C */
  1088. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1089. #endif /* MBEDTLS_DES_C */
  1090. #if defined(MBEDTLS_ARC4_C)
  1091. #if defined(MBEDTLS_SHA1_C)
  1092. { MBEDTLS_TLS_PSK_WITH_RC4_128_SHA, "TLS-PSK-WITH-RC4-128-SHA",
  1093. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1094. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1095. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1096. MBEDTLS_CIPHERSUITE_NODTLS },
  1097. #endif /* MBEDTLS_SHA1_C */
  1098. #endif /* MBEDTLS_ARC4_C */
  1099. #endif /* MBEDTLS_KEY_EXCHANGE_PSK_ENABLED */
  1100. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED)
  1101. #if defined(MBEDTLS_AES_C)
  1102. #if defined(MBEDTLS_GCM_C)
  1103. #if defined(MBEDTLS_SHA256_C)
  1104. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256, "TLS-DHE-PSK-WITH-AES-128-GCM-SHA256",
  1105. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1106. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1107. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1108. 0 },
  1109. #endif /* MBEDTLS_SHA256_C */
  1110. #if defined(MBEDTLS_SHA512_C)
  1111. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384, "TLS-DHE-PSK-WITH-AES-256-GCM-SHA384",
  1112. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1113. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1114. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1115. 0 },
  1116. #endif /* MBEDTLS_SHA512_C */
  1117. #endif /* MBEDTLS_GCM_C */
  1118. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1119. #if defined(MBEDTLS_SHA256_C)
  1120. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256, "TLS-DHE-PSK-WITH-AES-128-CBC-SHA256",
  1121. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1122. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1123. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1124. 0 },
  1125. #endif /* MBEDTLS_SHA256_C */
  1126. #if defined(MBEDTLS_SHA512_C)
  1127. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384, "TLS-DHE-PSK-WITH-AES-256-CBC-SHA384",
  1128. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1129. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1130. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1131. 0 },
  1132. #endif /* MBEDTLS_SHA512_C */
  1133. #if defined(MBEDTLS_SHA1_C)
  1134. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA, "TLS-DHE-PSK-WITH-AES-128-CBC-SHA",
  1135. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1136. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1137. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1138. 0 },
  1139. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA, "TLS-DHE-PSK-WITH-AES-256-CBC-SHA",
  1140. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1141. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1142. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1143. 0 },
  1144. #endif /* MBEDTLS_SHA1_C */
  1145. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1146. #if defined(MBEDTLS_CCM_C)
  1147. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM, "TLS-DHE-PSK-WITH-AES-256-CCM",
  1148. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1149. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1150. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1151. 0 },
  1152. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM_8, "TLS-DHE-PSK-WITH-AES-256-CCM-8",
  1153. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1154. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1155. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1156. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1157. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM, "TLS-DHE-PSK-WITH-AES-128-CCM",
  1158. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1159. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1160. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1161. 0 },
  1162. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM_8, "TLS-DHE-PSK-WITH-AES-128-CCM-8",
  1163. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1164. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1165. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1166. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1167. #endif /* MBEDTLS_CCM_C */
  1168. #endif /* MBEDTLS_AES_C */
  1169. #if defined(MBEDTLS_CAMELLIA_C)
  1170. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1171. #if defined(MBEDTLS_SHA256_C)
  1172. { MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256, "TLS-DHE-PSK-WITH-CAMELLIA-128-CBC-SHA256",
  1173. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1174. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1175. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1176. 0 },
  1177. #endif /* MBEDTLS_SHA256_C */
  1178. #if defined(MBEDTLS_SHA512_C)
  1179. { MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384, "TLS-DHE-PSK-WITH-CAMELLIA-256-CBC-SHA384",
  1180. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1181. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1182. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1183. 0 },
  1184. #endif /* MBEDTLS_SHA512_C */
  1185. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1186. #if defined(MBEDTLS_GCM_C)
  1187. #if defined(MBEDTLS_SHA256_C)
  1188. { MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256, "TLS-DHE-PSK-WITH-CAMELLIA-128-GCM-SHA256",
  1189. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1190. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1191. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1192. 0 },
  1193. #endif /* MBEDTLS_SHA256_C */
  1194. #if defined(MBEDTLS_SHA512_C)
  1195. { MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384, "TLS-DHE-PSK-WITH-CAMELLIA-256-GCM-SHA384",
  1196. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1197. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1198. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1199. 0 },
  1200. #endif /* MBEDTLS_SHA512_C */
  1201. #endif /* MBEDTLS_GCM_C */
  1202. #endif /* MBEDTLS_CAMELLIA_C */
  1203. #if defined(MBEDTLS_DES_C)
  1204. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1205. #if defined(MBEDTLS_SHA1_C)
  1206. { MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA, "TLS-DHE-PSK-WITH-3DES-EDE-CBC-SHA",
  1207. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1208. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1209. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1210. 0 },
  1211. #endif /* MBEDTLS_SHA1_C */
  1212. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1213. #endif /* MBEDTLS_DES_C */
  1214. #if defined(MBEDTLS_ARC4_C)
  1215. #if defined(MBEDTLS_SHA1_C)
  1216. { MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA, "TLS-DHE-PSK-WITH-RC4-128-SHA",
  1217. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1218. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1219. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1220. MBEDTLS_CIPHERSUITE_NODTLS },
  1221. #endif /* MBEDTLS_SHA1_C */
  1222. #endif /* MBEDTLS_ARC4_C */
  1223. #endif /* MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED */
  1224. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED)
  1225. #if defined(MBEDTLS_AES_C)
  1226. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1227. #if defined(MBEDTLS_SHA256_C)
  1228. { MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256, "TLS-ECDHE-PSK-WITH-AES-128-CBC-SHA256",
  1229. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1230. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1231. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1232. 0 },
  1233. #endif /* MBEDTLS_SHA256_C */
  1234. #if defined(MBEDTLS_SHA512_C)
  1235. { MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384, "TLS-ECDHE-PSK-WITH-AES-256-CBC-SHA384",
  1236. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1237. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1238. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1239. 0 },
  1240. #endif /* MBEDTLS_SHA512_C */
  1241. #if defined(MBEDTLS_SHA1_C)
  1242. { MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA, "TLS-ECDHE-PSK-WITH-AES-128-CBC-SHA",
  1243. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1244. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1245. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1246. 0 },
  1247. { MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA, "TLS-ECDHE-PSK-WITH-AES-256-CBC-SHA",
  1248. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1249. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1250. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1251. 0 },
  1252. #endif /* MBEDTLS_SHA1_C */
  1253. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1254. #endif /* MBEDTLS_AES_C */
  1255. #if defined(MBEDTLS_CAMELLIA_C)
  1256. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1257. #if defined(MBEDTLS_SHA256_C)
  1258. { MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDHE-PSK-WITH-CAMELLIA-128-CBC-SHA256",
  1259. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1260. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1261. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1262. 0 },
  1263. #endif /* MBEDTLS_SHA256_C */
  1264. #if defined(MBEDTLS_SHA512_C)
  1265. { MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDHE-PSK-WITH-CAMELLIA-256-CBC-SHA384",
  1266. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1267. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1268. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1269. 0 },
  1270. #endif /* MBEDTLS_SHA512_C */
  1271. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1272. #endif /* MBEDTLS_CAMELLIA_C */
  1273. #if defined(MBEDTLS_DES_C)
  1274. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1275. #if defined(MBEDTLS_SHA1_C)
  1276. { MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA, "TLS-ECDHE-PSK-WITH-3DES-EDE-CBC-SHA",
  1277. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1278. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1279. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1280. 0 },
  1281. #endif /* MBEDTLS_SHA1_C */
  1282. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1283. #endif /* MBEDTLS_DES_C */
  1284. #if defined(MBEDTLS_ARC4_C)
  1285. #if defined(MBEDTLS_SHA1_C)
  1286. { MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA, "TLS-ECDHE-PSK-WITH-RC4-128-SHA",
  1287. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1288. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1289. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1290. MBEDTLS_CIPHERSUITE_NODTLS },
  1291. #endif /* MBEDTLS_SHA1_C */
  1292. #endif /* MBEDTLS_ARC4_C */
  1293. #endif /* MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED */
  1294. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED)
  1295. #if defined(MBEDTLS_AES_C)
  1296. #if defined(MBEDTLS_GCM_C)
  1297. #if defined(MBEDTLS_SHA256_C)
  1298. { MBEDTLS_TLS_RSA_PSK_WITH_AES_128_GCM_SHA256, "TLS-RSA-PSK-WITH-AES-128-GCM-SHA256",
  1299. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1300. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1301. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1302. 0 },
  1303. #endif /* MBEDTLS_SHA256_C */
  1304. #if defined(MBEDTLS_SHA512_C)
  1305. { MBEDTLS_TLS_RSA_PSK_WITH_AES_256_GCM_SHA384, "TLS-RSA-PSK-WITH-AES-256-GCM-SHA384",
  1306. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1307. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1308. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1309. 0 },
  1310. #endif /* MBEDTLS_SHA512_C */
  1311. #endif /* MBEDTLS_GCM_C */
  1312. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1313. #if defined(MBEDTLS_SHA256_C)
  1314. { MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA256, "TLS-RSA-PSK-WITH-AES-128-CBC-SHA256",
  1315. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1316. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1317. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1318. 0 },
  1319. #endif /* MBEDTLS_SHA256_C */
  1320. #if defined(MBEDTLS_SHA512_C)
  1321. { MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA384, "TLS-RSA-PSK-WITH-AES-256-CBC-SHA384",
  1322. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1323. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1324. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1325. 0 },
  1326. #endif /* MBEDTLS_SHA512_C */
  1327. #if defined(MBEDTLS_SHA1_C)
  1328. { MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA, "TLS-RSA-PSK-WITH-AES-128-CBC-SHA",
  1329. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1330. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1331. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1332. 0 },
  1333. { MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA, "TLS-RSA-PSK-WITH-AES-256-CBC-SHA",
  1334. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1335. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1336. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1337. 0 },
  1338. #endif /* MBEDTLS_SHA1_C */
  1339. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1340. #endif /* MBEDTLS_AES_C */
  1341. #if defined(MBEDTLS_CAMELLIA_C)
  1342. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1343. #if defined(MBEDTLS_SHA256_C)
  1344. { MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256, "TLS-RSA-PSK-WITH-CAMELLIA-128-CBC-SHA256",
  1345. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1346. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1347. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1348. 0 },
  1349. #endif /* MBEDTLS_SHA256_C */
  1350. #if defined(MBEDTLS_SHA512_C)
  1351. { MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384, "TLS-RSA-PSK-WITH-CAMELLIA-256-CBC-SHA384",
  1352. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1353. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1354. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1355. 0 },
  1356. #endif /* MBEDTLS_SHA512_C */
  1357. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1358. #if defined(MBEDTLS_GCM_C)
  1359. #if defined(MBEDTLS_SHA256_C)
  1360. { MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256, "TLS-RSA-PSK-WITH-CAMELLIA-128-GCM-SHA256",
  1361. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1362. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1363. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1364. 0 },
  1365. #endif /* MBEDTLS_SHA256_C */
  1366. #if defined(MBEDTLS_SHA512_C)
  1367. { MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384, "TLS-RSA-PSK-WITH-CAMELLIA-256-GCM-SHA384",
  1368. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1369. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1370. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1371. 0 },
  1372. #endif /* MBEDTLS_SHA512_C */
  1373. #endif /* MBEDTLS_GCM_C */
  1374. #endif /* MBEDTLS_CAMELLIA_C */
  1375. #if defined(MBEDTLS_DES_C)
  1376. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1377. #if defined(MBEDTLS_SHA1_C)
  1378. { MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA, "TLS-RSA-PSK-WITH-3DES-EDE-CBC-SHA",
  1379. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1380. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1381. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1382. 0 },
  1383. #endif /* MBEDTLS_SHA1_C */
  1384. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1385. #endif /* MBEDTLS_DES_C */
  1386. #if defined(MBEDTLS_ARC4_C)
  1387. #if defined(MBEDTLS_SHA1_C)
  1388. { MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA, "TLS-RSA-PSK-WITH-RC4-128-SHA",
  1389. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1390. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1391. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1392. MBEDTLS_CIPHERSUITE_NODTLS },
  1393. #endif /* MBEDTLS_SHA1_C */
  1394. #endif /* MBEDTLS_ARC4_C */
  1395. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED */
  1396. #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED)
  1397. #if defined(MBEDTLS_AES_C)
  1398. #if defined(MBEDTLS_CCM_C)
  1399. { MBEDTLS_TLS_ECJPAKE_WITH_AES_128_CCM_8, "TLS-ECJPAKE-WITH-AES-128-CCM-8",
  1400. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECJPAKE,
  1401. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1402. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1403. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1404. #endif /* MBEDTLS_CCM_C */
  1405. #endif /* MBEDTLS_AES_C */
  1406. #endif /* MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED */
  1407. #if defined(MBEDTLS_ENABLE_WEAK_CIPHERSUITES)
  1408. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  1409. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED)
  1410. #if defined(MBEDTLS_MD5_C)
  1411. { MBEDTLS_TLS_RSA_WITH_NULL_MD5, "TLS-RSA-WITH-NULL-MD5",
  1412. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_MD5, MBEDTLS_KEY_EXCHANGE_RSA,
  1413. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1414. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1415. MBEDTLS_CIPHERSUITE_WEAK },
  1416. #endif
  1417. #if defined(MBEDTLS_SHA1_C)
  1418. { MBEDTLS_TLS_RSA_WITH_NULL_SHA, "TLS-RSA-WITH-NULL-SHA",
  1419. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  1420. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1421. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1422. MBEDTLS_CIPHERSUITE_WEAK },
  1423. #endif
  1424. #if defined(MBEDTLS_SHA256_C)
  1425. { MBEDTLS_TLS_RSA_WITH_NULL_SHA256, "TLS-RSA-WITH-NULL-SHA256",
  1426. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  1427. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1428. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1429. MBEDTLS_CIPHERSUITE_WEAK },
  1430. #endif
  1431. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_ENABLED */
  1432. #if defined(MBEDTLS_KEY_EXCHANGE_PSK_ENABLED)
  1433. #if defined(MBEDTLS_SHA1_C)
  1434. { MBEDTLS_TLS_PSK_WITH_NULL_SHA, "TLS-PSK-WITH-NULL-SHA",
  1435. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1436. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1437. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1438. MBEDTLS_CIPHERSUITE_WEAK },
  1439. #endif /* MBEDTLS_SHA1_C */
  1440. #if defined(MBEDTLS_SHA256_C)
  1441. { MBEDTLS_TLS_PSK_WITH_NULL_SHA256, "TLS-PSK-WITH-NULL-SHA256",
  1442. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1443. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1444. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1445. MBEDTLS_CIPHERSUITE_WEAK },
  1446. #endif
  1447. #if defined(MBEDTLS_SHA512_C)
  1448. { MBEDTLS_TLS_PSK_WITH_NULL_SHA384, "TLS-PSK-WITH-NULL-SHA384",
  1449. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  1450. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1451. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1452. MBEDTLS_CIPHERSUITE_WEAK },
  1453. #endif
  1454. #endif /* MBEDTLS_KEY_EXCHANGE_PSK_ENABLED */
  1455. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED)
  1456. #if defined(MBEDTLS_SHA1_C)
  1457. { MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA, "TLS-DHE-PSK-WITH-NULL-SHA",
  1458. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1459. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1460. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1461. MBEDTLS_CIPHERSUITE_WEAK },
  1462. #endif /* MBEDTLS_SHA1_C */
  1463. #if defined(MBEDTLS_SHA256_C)
  1464. { MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA256, "TLS-DHE-PSK-WITH-NULL-SHA256",
  1465. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1466. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1467. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1468. MBEDTLS_CIPHERSUITE_WEAK },
  1469. #endif
  1470. #if defined(MBEDTLS_SHA512_C)
  1471. { MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA384, "TLS-DHE-PSK-WITH-NULL-SHA384",
  1472. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1473. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1474. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1475. MBEDTLS_CIPHERSUITE_WEAK },
  1476. #endif
  1477. #endif /* MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED */
  1478. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED)
  1479. #if defined(MBEDTLS_SHA1_C)
  1480. { MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA, "TLS-ECDHE-PSK-WITH-NULL-SHA",
  1481. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1482. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1483. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1484. MBEDTLS_CIPHERSUITE_WEAK },
  1485. #endif /* MBEDTLS_SHA1_C */
  1486. #if defined(MBEDTLS_SHA256_C)
  1487. { MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA256, "TLS-ECDHE-PSK-WITH-NULL-SHA256",
  1488. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1489. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1490. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1491. MBEDTLS_CIPHERSUITE_WEAK },
  1492. #endif
  1493. #if defined(MBEDTLS_SHA512_C)
  1494. { MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA384, "TLS-ECDHE-PSK-WITH-NULL-SHA384",
  1495. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1496. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1497. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1498. MBEDTLS_CIPHERSUITE_WEAK },
  1499. #endif
  1500. #endif /* MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED */
  1501. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED)
  1502. #if defined(MBEDTLS_SHA1_C)
  1503. { MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA, "TLS-RSA-PSK-WITH-NULL-SHA",
  1504. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1505. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1506. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1507. MBEDTLS_CIPHERSUITE_WEAK },
  1508. #endif /* MBEDTLS_SHA1_C */
  1509. #if defined(MBEDTLS_SHA256_C)
  1510. { MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA256, "TLS-RSA-PSK-WITH-NULL-SHA256",
  1511. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1512. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1513. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1514. MBEDTLS_CIPHERSUITE_WEAK },
  1515. #endif
  1516. #if defined(MBEDTLS_SHA512_C)
  1517. { MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA384, "TLS-RSA-PSK-WITH-NULL-SHA384",
  1518. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1519. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1520. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1521. MBEDTLS_CIPHERSUITE_WEAK },
  1522. #endif
  1523. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED */
  1524. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  1525. #if defined(MBEDTLS_DES_C)
  1526. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1527. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED)
  1528. #if defined(MBEDTLS_SHA1_C)
  1529. { MBEDTLS_TLS_DHE_RSA_WITH_DES_CBC_SHA, "TLS-DHE-RSA-WITH-DES-CBC-SHA",
  1530. MBEDTLS_CIPHER_DES_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  1531. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1532. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1533. MBEDTLS_CIPHERSUITE_WEAK },
  1534. #endif /* MBEDTLS_SHA1_C */
  1535. #endif /* MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED */
  1536. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED)
  1537. #if defined(MBEDTLS_SHA1_C)
  1538. { MBEDTLS_TLS_RSA_WITH_DES_CBC_SHA, "TLS-RSA-WITH-DES-CBC-SHA",
  1539. MBEDTLS_CIPHER_DES_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  1540. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1541. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1542. MBEDTLS_CIPHERSUITE_WEAK },
  1543. #endif /* MBEDTLS_SHA1_C */
  1544. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_ENABLED */
  1545. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1546. #endif /* MBEDTLS_DES_C */
  1547. #endif /* MBEDTLS_ENABLE_WEAK_CIPHERSUITES */
  1548. { 0, "",
  1549. MBEDTLS_CIPHER_NONE, MBEDTLS_MD_NONE, MBEDTLS_KEY_EXCHANGE_NONE,
  1550. 0, 0, 0, 0, 0 }
  1551. };
  1552. #if defined(MBEDTLS_SSL_CIPHERSUITES)
  1553. const int *mbedtls_ssl_list_ciphersuites( void )
  1554. {
  1555. return( ciphersuite_preference );
  1556. }
  1557. #else
  1558. #define MAX_CIPHERSUITES sizeof( ciphersuite_definitions ) / \
  1559. sizeof( ciphersuite_definitions[0] )
  1560. static int supported_ciphersuites[MAX_CIPHERSUITES];
  1561. static int supported_init = 0;
  1562. const int *mbedtls_ssl_list_ciphersuites( void )
  1563. {
  1564. /*
  1565. * On initial call filter out all ciphersuites not supported by current
  1566. * build based on presence in the ciphersuite_definitions.
  1567. */
  1568. if( supported_init == 0 )
  1569. {
  1570. const int *p;
  1571. int *q;
  1572. for( p = ciphersuite_preference, q = supported_ciphersuites;
  1573. *p != 0 && q < supported_ciphersuites + MAX_CIPHERSUITES - 1;
  1574. p++ )
  1575. {
  1576. #if defined(MBEDTLS_REMOVE_ARC4_CIPHERSUITES)
  1577. const mbedtls_ssl_ciphersuite_t *cs_info;
  1578. if( ( cs_info = mbedtls_ssl_ciphersuite_from_id( *p ) ) != NULL &&
  1579. cs_info->cipher != MBEDTLS_CIPHER_ARC4_128 )
  1580. #else
  1581. if( mbedtls_ssl_ciphersuite_from_id( *p ) != NULL )
  1582. #endif
  1583. *(q++) = *p;
  1584. }
  1585. *q = 0;
  1586. supported_init = 1;
  1587. }
  1588. return( supported_ciphersuites );
  1589. }
  1590. #endif /* MBEDTLS_SSL_CIPHERSUITES */
  1591. const mbedtls_ssl_ciphersuite_t *mbedtls_ssl_ciphersuite_from_string(
  1592. const char *ciphersuite_name )
  1593. {
  1594. const mbedtls_ssl_ciphersuite_t *cur = ciphersuite_definitions;
  1595. if( NULL == ciphersuite_name )
  1596. return( NULL );
  1597. while( cur->id != 0 )
  1598. {
  1599. if( 0 == strcmp( cur->name, ciphersuite_name ) )
  1600. return( cur );
  1601. cur++;
  1602. }
  1603. return( NULL );
  1604. }
  1605. const mbedtls_ssl_ciphersuite_t *mbedtls_ssl_ciphersuite_from_id( int ciphersuite )
  1606. {
  1607. const mbedtls_ssl_ciphersuite_t *cur = ciphersuite_definitions;
  1608. while( cur->id != 0 )
  1609. {
  1610. if( cur->id == ciphersuite )
  1611. return( cur );
  1612. cur++;
  1613. }
  1614. return( NULL );
  1615. }
  1616. const char *mbedtls_ssl_get_ciphersuite_name( const int ciphersuite_id )
  1617. {
  1618. const mbedtls_ssl_ciphersuite_t *cur;
  1619. cur = mbedtls_ssl_ciphersuite_from_id( ciphersuite_id );
  1620. if( cur == NULL )
  1621. return( "unknown" );
  1622. return( cur->name );
  1623. }
  1624. int mbedtls_ssl_get_ciphersuite_id( const char *ciphersuite_name )
  1625. {
  1626. const mbedtls_ssl_ciphersuite_t *cur;
  1627. cur = mbedtls_ssl_ciphersuite_from_string( ciphersuite_name );
  1628. if( cur == NULL )
  1629. return( 0 );
  1630. return( cur->id );
  1631. }
  1632. #if defined(MBEDTLS_PK_C)
  1633. mbedtls_pk_type_t mbedtls_ssl_get_ciphersuite_sig_pk_alg( const mbedtls_ssl_ciphersuite_t *info )
  1634. {
  1635. switch( info->key_exchange )
  1636. {
  1637. case MBEDTLS_KEY_EXCHANGE_RSA:
  1638. case MBEDTLS_KEY_EXCHANGE_DHE_RSA:
  1639. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  1640. case MBEDTLS_KEY_EXCHANGE_RSA_PSK:
  1641. return( MBEDTLS_PK_RSA );
  1642. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  1643. return( MBEDTLS_PK_ECDSA );
  1644. case MBEDTLS_KEY_EXCHANGE_ECDH_RSA:
  1645. case MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA:
  1646. return( MBEDTLS_PK_ECKEY );
  1647. default:
  1648. return( MBEDTLS_PK_NONE );
  1649. }
  1650. }
  1651. #endif /* MBEDTLS_PK_C */
  1652. #if defined(MBEDTLS_ECDH_C) || defined(MBEDTLS_ECDSA_C)
  1653. int mbedtls_ssl_ciphersuite_uses_ec( const mbedtls_ssl_ciphersuite_t *info )
  1654. {
  1655. switch( info->key_exchange )
  1656. {
  1657. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  1658. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  1659. case MBEDTLS_KEY_EXCHANGE_ECDHE_PSK:
  1660. case MBEDTLS_KEY_EXCHANGE_ECDH_RSA:
  1661. case MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA:
  1662. return( 1 );
  1663. default:
  1664. return( 0 );
  1665. }
  1666. }
  1667. #endif /* MBEDTLS_ECDH_C || MBEDTLS_ECDSA_C */
  1668. #if defined(MBEDTLS_KEY_EXCHANGE__SOME__PSK_ENABLED)
  1669. int mbedtls_ssl_ciphersuite_uses_psk( const mbedtls_ssl_ciphersuite_t *info )
  1670. {
  1671. switch( info->key_exchange )
  1672. {
  1673. case MBEDTLS_KEY_EXCHANGE_PSK:
  1674. case MBEDTLS_KEY_EXCHANGE_RSA_PSK:
  1675. case MBEDTLS_KEY_EXCHANGE_DHE_PSK:
  1676. case MBEDTLS_KEY_EXCHANGE_ECDHE_PSK:
  1677. return( 1 );
  1678. default:
  1679. return( 0 );
  1680. }
  1681. }
  1682. #endif /* MBEDTLS_KEY_EXCHANGE__SOME__PSK_ENABLED */
  1683. #endif /* MBEDTLS_SSL_TLS_C */