Botan 3.11.0
Crypto and TLS for C&
tls_client.cpp
Go to the documentation of this file.
1/*
2* TLS Client
3* (C) 2004-2011,2012,2015,2016 Jack Lloyd
4* 2016 Matthias Gierlings
5* 2017 Harry Reimann, Rohde & Schwarz Cybersecurity
6* 2021 Elektrobit Automotive GmbH
7*
8* Botan is released under the Simplified BSD License (see license.txt)
9*/
10
11#include <botan/tls_client.h>
12
13#include <botan/tls_policy.h>
14#include <botan/x509cert.h>
15#include <botan/internal/tls_channel_impl.h>
16
17#if defined(BOTAN_HAS_TLS_12)
18 #include <botan/internal/tls_client_impl_12.h>
19#endif
20
21#if defined(BOTAN_HAS_TLS_13)
22 #include <botan/internal/tls_client_impl_13.h>
23#endif
24
25namespace Botan::TLS {
26
27/*
28* TLS Client Constructor
29*/
30Client::Client(const std::shared_ptr<Callbacks>& callbacks,
31 const std::shared_ptr<Session_Manager>& session_manager,
32 const std::shared_ptr<Credentials_Manager>& creds,
33 const std::shared_ptr<const Policy>& policy,
34 const std::shared_ptr<RandomNumberGenerator>& rng,
36 Protocol_Version offer_version,
37 const std::vector<std::string>& next_protocols,
38 size_t io_buf_sz) {
39 BOTAN_ARG_CHECK(policy->acceptable_protocol_version(offer_version),
40 "Policy does not allow to offer requested protocol version");
41
42#if defined(BOTAN_HAS_TLS_13)
43 if(offer_version == Protocol_Version::TLS_V13) {
44 m_impl = std::make_unique<Client_Impl_13>(
45 callbacks, session_manager, creds, policy, rng, std::move(info), next_protocols);
46
47 if(m_impl->expects_downgrade()) {
48 m_impl->set_io_buffer_size(io_buf_sz);
49 }
50
51 if(m_impl->is_downgrading()) {
52 // TLS 1.3 implementation found a resumable TLS 1.2 session and
53 // requested a downgrade right away.
54 downgrade();
55 }
56
57 return;
58 }
59#endif
60
61#if defined(BOTAN_HAS_TLS_12)
62 if(offer_version.is_pre_tls_13()) {
63 m_impl = std::make_unique<Client_Impl_12>(callbacks,
64 session_manager,
65 creds,
66 policy,
67 rng,
68 std::move(info),
69 offer_version.is_datagram_protocol(),
70 next_protocols,
71 io_buf_sz);
72 return;
73 }
74#endif
75
76 BOTAN_UNUSED(callbacks, session_manager, creds, policy, rng, info, offer_version, next_protocols, io_buf_sz);
77 throw Not_Implemented("Requested TLS version to be offered is not available in this build");
78}
79
80Client::~Client() = default;
81
82size_t Client::downgrade() {
83 BOTAN_ASSERT_NOMSG(m_impl->is_downgrading());
84
85#if defined(BOTAN_HAS_TLS_12)
86 auto info = m_impl->extract_downgrade_info();
87 m_impl = std::make_unique<Client_Impl_12>(*info);
88
89 if(!info->peer_transcript.empty()) {
90 // replay peer data received so far
91 return m_impl->from_peer(info->peer_transcript);
92 } else {
93 // the downgrade happened due to a resumable TLS 1.2 session
94 // before any data was transferred
95 return 0;
96 }
97#else
98 // If TLS 1.2 is not available, we will never downgrade, the downgrade info
99 // won't even be created and `is_downgrading()` would always return false.
101#endif
102}
103
104size_t Client::from_peer(std::span<const uint8_t> data) {
105 auto read = m_impl->from_peer(data);
106
107 if(m_impl->is_downgrading()) {
108 read = downgrade();
109 }
110
111 return read;
112}
113
115 return m_impl->is_handshake_complete();
116}
117
118bool Client::is_active() const {
119 return m_impl->is_active();
120}
121
122bool Client::is_closed() const {
123 return m_impl->is_closed();
124}
125
127 return m_impl->is_closed_for_reading();
128}
129
131 return m_impl->is_closed_for_writing();
132}
133
134std::vector<X509_Certificate> Client::peer_cert_chain() const {
135 return m_impl->peer_cert_chain();
136}
137
138std::shared_ptr<const Public_Key> Client::peer_raw_public_key() const {
139 return m_impl->peer_raw_public_key();
140}
141
142std::optional<std::string> Client::external_psk_identity() const {
143 return m_impl->external_psk_identity();
144}
145
146SymmetricKey Client::key_material_export(std::string_view label, std::string_view context, size_t length) const {
147 return m_impl->key_material_export(label, context, length);
148}
149
150void Client::renegotiate(bool force_full_renegotiation) {
151 m_impl->renegotiate(force_full_renegotiation);
152}
153
154void Client::update_traffic_keys(bool request_peer_update) {
155 m_impl->update_traffic_keys(request_peer_update);
156}
157
159 return m_impl->secure_renegotiation_supported();
160}
161
162void Client::to_peer(std::span<const uint8_t> data) {
163 m_impl->to_peer(data);
164}
165
166void Client::send_alert(const Alert& alert) {
167 m_impl->send_alert(alert);
168}
169
171 m_impl->send_warning_alert(type);
172}
173
175 m_impl->send_fatal_alert(type);
176}
177
179 m_impl->close();
180}
181
183 return m_impl->timeout_check();
184}
185
186std::string Client::application_protocol() const {
187 return m_impl->application_protocol();
188}
189
190} // namespace Botan::TLS
#define BOTAN_UNUSED
Definition assert.h:144
#define BOTAN_ASSERT_NOMSG(expr)
Definition assert.h:75
#define BOTAN_ARG_CHECK(expr, msg)
Definition assert.h:33
#define BOTAN_ASSERT_UNREACHABLE()
Definition assert.h:163
AlertType Type
Definition tls_alert.h:72
bool is_closed_for_reading() const override
bool is_handshake_complete() const override
void renegotiate(bool force_full_renegotiation=false) override
void close() override
std::string application_protocol() const override
std::shared_ptr< const Public_Key > peer_raw_public_key() const override
Client(const std::shared_ptr< Callbacks > &callbacks, const std::shared_ptr< Session_Manager > &session_manager, const std::shared_ptr< Credentials_Manager > &creds, const std::shared_ptr< const Policy > &policy, const std::shared_ptr< RandomNumberGenerator > &rng, Server_Information server_info=Server_Information(), Protocol_Version offer_version=Protocol_Version::latest_tls_version(), const std::vector< std::string > &next_protocols={}, size_t reserved_io_buffer_size=TLS::Client::IO_BUF_DEFAULT_SIZE)
bool secure_renegotiation_supported() const override
bool is_active() const override
SymmetricKey key_material_export(std::string_view label, std::string_view context, size_t length) const override
bool is_closed_for_writing() const override
void send_fatal_alert(Alert::Type type) override
bool timeout_check() override
void send_warning_alert(Alert::Type type) override
void to_peer(std::span< const uint8_t > data) override
~Client() override
std::vector< X509_Certificate > peer_cert_chain() const override
bool is_closed() const override
void update_traffic_keys(bool request_peer_update=false) override
std::optional< std::string > external_psk_identity() const override
void send_alert(const Alert &alert) override
size_t from_peer(std::span< const uint8_t > data) override
OctetString SymmetricKey
Definition symkey.h:140