ssl_ciphersuites.c 79 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858
  1. /**
  2. * \file ssl_ciphersuites.c
  3. *
  4. * \brief SSL ciphersuites for mbed TLS
  5. *
  6. * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
  7. * SPDX-License-Identifier: Apache-2.0
  8. *
  9. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  10. * not use this file except in compliance with the License.
  11. * You may obtain a copy of the License at
  12. *
  13. * http://www.apache.org/licenses/LICENSE-2.0
  14. *
  15. * Unless required by applicable law or agreed to in writing, software
  16. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  17. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  18. * See the License for the specific language governing permissions and
  19. * limitations under the License.
  20. *
  21. * This file is part of mbed TLS (https://tls.mbed.org)
  22. */
  23. #if !defined(MBEDTLS_CONFIG_FILE)
  24. #include "mbedtls/config.h"
  25. #else
  26. #include MBEDTLS_CONFIG_FILE
  27. #endif
  28. #if defined(MBEDTLS_SSL_TLS_C)
  29. #if defined(MBEDTLS_PLATFORM_C)
  30. #include "mbedtls/platform.h"
  31. #else
  32. #include <stdlib.h>
  33. #define mbedtls_time_t time_t
  34. #endif
  35. #include "mbedtls/ssl_ciphersuites.h"
  36. #include "mbedtls/ssl.h"
  37. #include <string.h>
  38. /*
  39. * Ordered from most preferred to least preferred in terms of security.
  40. *
  41. * Current rule (except rc4, weak and null which come last):
  42. * 1. By key exchange:
  43. * Forward-secure non-PSK > forward-secure PSK > ECJPAKE > other non-PSK > other PSK
  44. * 2. By key length and cipher:
  45. * AES-256 > Camellia-256 > AES-128 > Camellia-128 > 3DES
  46. * 3. By cipher mode when relevant GCM > CCM > CBC > CCM_8
  47. * 4. By hash function used when relevant
  48. * 5. By key exchange/auth again: EC > non-EC
  49. */
  50. static const int ciphersuite_preference[] =
  51. {
  52. #if defined(MBEDTLS_SSL_CIPHERSUITES)
  53. MBEDTLS_SSL_CIPHERSUITES,
  54. #else
  55. /* All AES-256 ephemeral suites */
  56. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
  57. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
  58. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,
  59. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM,
  60. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM,
  61. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384,
  62. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,
  63. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256,
  64. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,
  65. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,
  66. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA,
  67. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8,
  68. MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM_8,
  69. /* All CAMELLIA-256 ephemeral suites */
  70. MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384,
  71. MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384,
  72. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384,
  73. MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384,
  74. MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384,
  75. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256,
  76. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA,
  77. /* All AES-128 ephemeral suites */
  78. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
  79. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
  80. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,
  81. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM,
  82. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM,
  83. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,
  84. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
  85. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,
  86. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,
  87. MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,
  88. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA,
  89. MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8,
  90. MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM_8,
  91. /* All CAMELLIA-128 ephemeral suites */
  92. MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256,
  93. MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256,
  94. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256,
  95. MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256,
  96. MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256,
  97. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256,
  98. MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA,
  99. /* All remaining >= 128-bit ephemeral suites */
  100. MBEDTLS_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA,
  101. MBEDTLS_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA,
  102. MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA,
  103. /* The PSK ephemeral suites */
  104. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384,
  105. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM,
  106. MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384,
  107. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384,
  108. MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA,
  109. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA,
  110. MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384,
  111. MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384,
  112. MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384,
  113. MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM_8,
  114. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256,
  115. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM,
  116. MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256,
  117. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256,
  118. MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA,
  119. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA,
  120. MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256,
  121. MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256,
  122. MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256,
  123. MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM_8,
  124. MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA,
  125. MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA,
  126. /* The ECJPAKE suite */
  127. MBEDTLS_TLS_ECJPAKE_WITH_AES_128_CCM_8,
  128. /* All AES-256 suites */
  129. MBEDTLS_TLS_RSA_WITH_AES_256_GCM_SHA384,
  130. MBEDTLS_TLS_RSA_WITH_AES_256_CCM,
  131. MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA256,
  132. MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA,
  133. MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384,
  134. MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384,
  135. MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA,
  136. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384,
  137. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384,
  138. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA,
  139. MBEDTLS_TLS_RSA_WITH_AES_256_CCM_8,
  140. /* All CAMELLIA-256 suites */
  141. MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384,
  142. MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256,
  143. MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA,
  144. MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384,
  145. MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384,
  146. MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384,
  147. MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384,
  148. /* All AES-128 suites */
  149. MBEDTLS_TLS_RSA_WITH_AES_128_GCM_SHA256,
  150. MBEDTLS_TLS_RSA_WITH_AES_128_CCM,
  151. MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA256,
  152. MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA,
  153. MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256,
  154. MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256,
  155. MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA,
  156. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256,
  157. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256,
  158. MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA,
  159. MBEDTLS_TLS_RSA_WITH_AES_128_CCM_8,
  160. /* All CAMELLIA-128 suites */
  161. MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256,
  162. MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256,
  163. MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA,
  164. MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256,
  165. MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256,
  166. MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256,
  167. MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256,
  168. /* All remaining >= 128-bit suites */
  169. MBEDTLS_TLS_RSA_WITH_3DES_EDE_CBC_SHA,
  170. MBEDTLS_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA,
  171. MBEDTLS_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA,
  172. /* The RSA PSK suites */
  173. MBEDTLS_TLS_RSA_PSK_WITH_AES_256_GCM_SHA384,
  174. MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA384,
  175. MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA,
  176. MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384,
  177. MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384,
  178. MBEDTLS_TLS_RSA_PSK_WITH_AES_128_GCM_SHA256,
  179. MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA256,
  180. MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA,
  181. MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256,
  182. MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256,
  183. MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA,
  184. /* The PSK suites */
  185. MBEDTLS_TLS_PSK_WITH_AES_256_GCM_SHA384,
  186. MBEDTLS_TLS_PSK_WITH_AES_256_CCM,
  187. MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA384,
  188. MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA,
  189. MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_GCM_SHA384,
  190. MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384,
  191. MBEDTLS_TLS_PSK_WITH_AES_256_CCM_8,
  192. MBEDTLS_TLS_PSK_WITH_AES_128_GCM_SHA256,
  193. MBEDTLS_TLS_PSK_WITH_AES_128_CCM,
  194. MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA256,
  195. MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA,
  196. MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256,
  197. MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256,
  198. MBEDTLS_TLS_PSK_WITH_AES_128_CCM_8,
  199. MBEDTLS_TLS_PSK_WITH_3DES_EDE_CBC_SHA,
  200. /* RC4 suites */
  201. MBEDTLS_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA,
  202. MBEDTLS_TLS_ECDHE_RSA_WITH_RC4_128_SHA,
  203. MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA,
  204. MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA,
  205. MBEDTLS_TLS_RSA_WITH_RC4_128_SHA,
  206. MBEDTLS_TLS_RSA_WITH_RC4_128_MD5,
  207. MBEDTLS_TLS_ECDH_RSA_WITH_RC4_128_SHA,
  208. MBEDTLS_TLS_ECDH_ECDSA_WITH_RC4_128_SHA,
  209. MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA,
  210. MBEDTLS_TLS_PSK_WITH_RC4_128_SHA,
  211. /* Weak suites */
  212. MBEDTLS_TLS_DHE_RSA_WITH_DES_CBC_SHA,
  213. MBEDTLS_TLS_RSA_WITH_DES_CBC_SHA,
  214. /* NULL suites */
  215. MBEDTLS_TLS_ECDHE_ECDSA_WITH_NULL_SHA,
  216. MBEDTLS_TLS_ECDHE_RSA_WITH_NULL_SHA,
  217. MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA384,
  218. MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA256,
  219. MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA,
  220. MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA384,
  221. MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA256,
  222. MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA,
  223. MBEDTLS_TLS_RSA_WITH_NULL_SHA256,
  224. MBEDTLS_TLS_RSA_WITH_NULL_SHA,
  225. MBEDTLS_TLS_RSA_WITH_NULL_MD5,
  226. MBEDTLS_TLS_ECDH_RSA_WITH_NULL_SHA,
  227. MBEDTLS_TLS_ECDH_ECDSA_WITH_NULL_SHA,
  228. MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA384,
  229. MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA256,
  230. MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA,
  231. MBEDTLS_TLS_PSK_WITH_NULL_SHA384,
  232. MBEDTLS_TLS_PSK_WITH_NULL_SHA256,
  233. MBEDTLS_TLS_PSK_WITH_NULL_SHA,
  234. #endif /* MBEDTLS_SSL_CIPHERSUITES */
  235. 0
  236. };
  237. static const mbedtls_ssl_ciphersuite_t ciphersuite_definitions[] =
  238. {
  239. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED)
  240. #if defined(MBEDTLS_AES_C)
  241. #if defined(MBEDTLS_SHA1_C)
  242. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  243. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, "TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA",
  244. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  245. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  246. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  247. 0 },
  248. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, "TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA",
  249. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  250. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  251. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  252. 0 },
  253. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  254. #endif /* MBEDTLS_SHA1_C */
  255. #if defined(MBEDTLS_SHA256_C)
  256. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  257. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, "TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256",
  258. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  259. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  260. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  261. 0 },
  262. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  263. #if defined(MBEDTLS_GCM_C)
  264. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, "TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256",
  265. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  266. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  267. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  268. 0 },
  269. #endif /* MBEDTLS_GCM_C */
  270. #endif /* MBEDTLS_SHA256_C */
  271. #if defined(MBEDTLS_SHA512_C)
  272. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  273. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, "TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384",
  274. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  275. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  276. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  277. 0 },
  278. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  279. #if defined(MBEDTLS_GCM_C)
  280. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, "TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384",
  281. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  282. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  283. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  284. 0 },
  285. #endif /* MBEDTLS_GCM_C */
  286. #endif /* MBEDTLS_SHA512_C */
  287. #if defined(MBEDTLS_CCM_C)
  288. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM, "TLS-ECDHE-ECDSA-WITH-AES-256-CCM",
  289. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  290. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  291. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  292. 0 },
  293. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8, "TLS-ECDHE-ECDSA-WITH-AES-256-CCM-8",
  294. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  295. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  296. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  297. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  298. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM, "TLS-ECDHE-ECDSA-WITH-AES-128-CCM",
  299. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  300. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  301. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  302. 0 },
  303. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8, "TLS-ECDHE-ECDSA-WITH-AES-128-CCM-8",
  304. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  305. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  306. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  307. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  308. #endif /* MBEDTLS_CCM_C */
  309. #endif /* MBEDTLS_AES_C */
  310. #if defined(MBEDTLS_CAMELLIA_C)
  311. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  312. #if defined(MBEDTLS_SHA256_C)
  313. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDHE-ECDSA-WITH-CAMELLIA-128-CBC-SHA256",
  314. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  315. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  316. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  317. 0 },
  318. #endif /* MBEDTLS_SHA256_C */
  319. #if defined(MBEDTLS_SHA512_C)
  320. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDHE-ECDSA-WITH-CAMELLIA-256-CBC-SHA384",
  321. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  322. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  323. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  324. 0 },
  325. #endif /* MBEDTLS_SHA512_C */
  326. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  327. #if defined(MBEDTLS_GCM_C)
  328. #if defined(MBEDTLS_SHA256_C)
  329. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-ECDHE-ECDSA-WITH-CAMELLIA-128-GCM-SHA256",
  330. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  331. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  332. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  333. 0 },
  334. #endif /* MBEDTLS_SHA256_C */
  335. #if defined(MBEDTLS_SHA512_C)
  336. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-ECDHE-ECDSA-WITH-CAMELLIA-256-GCM-SHA384",
  337. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  338. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  339. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  340. 0 },
  341. #endif /* MBEDTLS_SHA512_C */
  342. #endif /* MBEDTLS_GCM_C */
  343. #endif /* MBEDTLS_CAMELLIA_C */
  344. #if defined(MBEDTLS_DES_C)
  345. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  346. #if defined(MBEDTLS_SHA1_C)
  347. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA, "TLS-ECDHE-ECDSA-WITH-3DES-EDE-CBC-SHA",
  348. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  349. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  350. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  351. 0 },
  352. #endif /* MBEDTLS_SHA1_C */
  353. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  354. #endif /* MBEDTLS_DES_C */
  355. #if defined(MBEDTLS_ARC4_C)
  356. #if defined(MBEDTLS_SHA1_C)
  357. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, "TLS-ECDHE-ECDSA-WITH-RC4-128-SHA",
  358. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  359. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  360. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  361. MBEDTLS_CIPHERSUITE_NODTLS },
  362. #endif /* MBEDTLS_SHA1_C */
  363. #endif /* MBEDTLS_ARC4_C */
  364. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  365. #if defined(MBEDTLS_SHA1_C)
  366. { MBEDTLS_TLS_ECDHE_ECDSA_WITH_NULL_SHA, "TLS-ECDHE-ECDSA-WITH-NULL-SHA",
  367. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA,
  368. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  369. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  370. MBEDTLS_CIPHERSUITE_WEAK },
  371. #endif /* MBEDTLS_SHA1_C */
  372. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  373. #endif /* MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED */
  374. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED)
  375. #if defined(MBEDTLS_AES_C)
  376. #if defined(MBEDTLS_SHA1_C)
  377. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  378. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, "TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA",
  379. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  380. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  381. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  382. 0 },
  383. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, "TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA",
  384. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  385. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  386. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  387. 0 },
  388. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  389. #endif /* MBEDTLS_SHA1_C */
  390. #if defined(MBEDTLS_SHA256_C)
  391. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  392. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, "TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256",
  393. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  394. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  395. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  396. 0 },
  397. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  398. #if defined(MBEDTLS_GCM_C)
  399. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, "TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256",
  400. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  401. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  402. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  403. 0 },
  404. #endif /* MBEDTLS_GCM_C */
  405. #endif /* MBEDTLS_SHA256_C */
  406. #if defined(MBEDTLS_SHA512_C)
  407. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  408. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, "TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384",
  409. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  410. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  411. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  412. 0 },
  413. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  414. #if defined(MBEDTLS_GCM_C)
  415. { MBEDTLS_TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, "TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384",
  416. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  417. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  418. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  419. 0 },
  420. #endif /* MBEDTLS_GCM_C */
  421. #endif /* MBEDTLS_SHA512_C */
  422. #endif /* MBEDTLS_AES_C */
  423. #if defined(MBEDTLS_CAMELLIA_C)
  424. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  425. #if defined(MBEDTLS_SHA256_C)
  426. { MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDHE-RSA-WITH-CAMELLIA-128-CBC-SHA256",
  427. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  428. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  429. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  430. 0 },
  431. #endif /* MBEDTLS_SHA256_C */
  432. #if defined(MBEDTLS_SHA512_C)
  433. { MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDHE-RSA-WITH-CAMELLIA-256-CBC-SHA384",
  434. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  435. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  436. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  437. 0 },
  438. #endif /* MBEDTLS_SHA512_C */
  439. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  440. #if defined(MBEDTLS_GCM_C)
  441. #if defined(MBEDTLS_SHA256_C)
  442. { MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-ECDHE-RSA-WITH-CAMELLIA-128-GCM-SHA256",
  443. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  444. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  445. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  446. 0 },
  447. #endif /* MBEDTLS_SHA256_C */
  448. #if defined(MBEDTLS_SHA512_C)
  449. { MBEDTLS_TLS_ECDHE_RSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-ECDHE-RSA-WITH-CAMELLIA-256-GCM-SHA384",
  450. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  451. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  452. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  453. 0 },
  454. #endif /* MBEDTLS_SHA512_C */
  455. #endif /* MBEDTLS_GCM_C */
  456. #endif /* MBEDTLS_CAMELLIA_C */
  457. #if defined(MBEDTLS_DES_C)
  458. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  459. #if defined(MBEDTLS_SHA1_C)
  460. { MBEDTLS_TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, "TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA",
  461. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  462. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  463. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  464. 0 },
  465. #endif /* MBEDTLS_SHA1_C */
  466. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  467. #endif /* MBEDTLS_DES_C */
  468. #if defined(MBEDTLS_ARC4_C)
  469. #if defined(MBEDTLS_SHA1_C)
  470. { MBEDTLS_TLS_ECDHE_RSA_WITH_RC4_128_SHA, "TLS-ECDHE-RSA-WITH-RC4-128-SHA",
  471. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  472. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  473. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  474. MBEDTLS_CIPHERSUITE_NODTLS },
  475. #endif /* MBEDTLS_SHA1_C */
  476. #endif /* MBEDTLS_ARC4_C */
  477. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  478. #if defined(MBEDTLS_SHA1_C)
  479. { MBEDTLS_TLS_ECDHE_RSA_WITH_NULL_SHA, "TLS-ECDHE-RSA-WITH-NULL-SHA",
  480. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_RSA,
  481. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  482. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  483. MBEDTLS_CIPHERSUITE_WEAK },
  484. #endif /* MBEDTLS_SHA1_C */
  485. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  486. #endif /* MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED */
  487. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED)
  488. #if defined(MBEDTLS_AES_C)
  489. #if defined(MBEDTLS_SHA512_C) && defined(MBEDTLS_GCM_C)
  490. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, "TLS-DHE-RSA-WITH-AES-256-GCM-SHA384",
  491. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  492. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  493. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  494. 0 },
  495. #endif /* MBEDTLS_SHA512_C && MBEDTLS_GCM_C */
  496. #if defined(MBEDTLS_SHA256_C)
  497. #if defined(MBEDTLS_GCM_C)
  498. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, "TLS-DHE-RSA-WITH-AES-128-GCM-SHA256",
  499. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  500. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  501. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  502. 0 },
  503. #endif /* MBEDTLS_GCM_C */
  504. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  505. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA256, "TLS-DHE-RSA-WITH-AES-128-CBC-SHA256",
  506. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  507. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  508. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  509. 0 },
  510. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA256, "TLS-DHE-RSA-WITH-AES-256-CBC-SHA256",
  511. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  512. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  513. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  514. 0 },
  515. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  516. #endif /* MBEDTLS_SHA256_C */
  517. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  518. #if defined(MBEDTLS_SHA1_C)
  519. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CBC_SHA, "TLS-DHE-RSA-WITH-AES-128-CBC-SHA",
  520. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  521. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  522. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  523. 0 },
  524. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CBC_SHA, "TLS-DHE-RSA-WITH-AES-256-CBC-SHA",
  525. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  526. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  527. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  528. 0 },
  529. #endif /* MBEDTLS_SHA1_C */
  530. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  531. #if defined(MBEDTLS_CCM_C)
  532. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM, "TLS-DHE-RSA-WITH-AES-256-CCM",
  533. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  534. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  535. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  536. 0 },
  537. { MBEDTLS_TLS_DHE_RSA_WITH_AES_256_CCM_8, "TLS-DHE-RSA-WITH-AES-256-CCM-8",
  538. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  539. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  540. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  541. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  542. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM, "TLS-DHE-RSA-WITH-AES-128-CCM",
  543. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  544. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  545. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  546. 0 },
  547. { MBEDTLS_TLS_DHE_RSA_WITH_AES_128_CCM_8, "TLS-DHE-RSA-WITH-AES-128-CCM-8",
  548. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  549. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  550. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  551. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  552. #endif /* MBEDTLS_CCM_C */
  553. #endif /* MBEDTLS_AES_C */
  554. #if defined(MBEDTLS_CAMELLIA_C)
  555. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  556. #if defined(MBEDTLS_SHA256_C)
  557. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256",
  558. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  559. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  560. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  561. 0 },
  562. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256, "TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256",
  563. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  564. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  565. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  566. 0 },
  567. #endif /* MBEDTLS_SHA256_C */
  568. #if defined(MBEDTLS_SHA1_C)
  569. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA, "TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA",
  570. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  571. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  572. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  573. 0 },
  574. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA, "TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA",
  575. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  576. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  577. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  578. 0 },
  579. #endif /* MBEDTLS_SHA1_C */
  580. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  581. #if defined(MBEDTLS_GCM_C)
  582. #if defined(MBEDTLS_SHA256_C)
  583. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-DHE-RSA-WITH-CAMELLIA-128-GCM-SHA256",
  584. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  585. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  586. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  587. 0 },
  588. #endif /* MBEDTLS_SHA256_C */
  589. #if defined(MBEDTLS_SHA512_C)
  590. { MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-DHE-RSA-WITH-CAMELLIA-256-GCM-SHA384",
  591. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  592. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  593. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  594. 0 },
  595. #endif /* MBEDTLS_SHA512_C */
  596. #endif /* MBEDTLS_GCM_C */
  597. #endif /* MBEDTLS_CAMELLIA_C */
  598. #if defined(MBEDTLS_DES_C)
  599. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  600. #if defined(MBEDTLS_SHA1_C)
  601. { MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA, "TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA",
  602. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  603. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  604. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  605. 0 },
  606. #endif /* MBEDTLS_SHA1_C */
  607. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  608. #endif /* MBEDTLS_DES_C */
  609. #endif /* MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED */
  610. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED)
  611. #if defined(MBEDTLS_AES_C)
  612. #if defined(MBEDTLS_SHA512_C) && defined(MBEDTLS_GCM_C)
  613. { MBEDTLS_TLS_RSA_WITH_AES_256_GCM_SHA384, "TLS-RSA-WITH-AES-256-GCM-SHA384",
  614. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA,
  615. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  616. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  617. 0 },
  618. #endif /* MBEDTLS_SHA512_C && MBEDTLS_GCM_C */
  619. #if defined(MBEDTLS_SHA256_C)
  620. #if defined(MBEDTLS_GCM_C)
  621. { MBEDTLS_TLS_RSA_WITH_AES_128_GCM_SHA256, "TLS-RSA-WITH-AES-128-GCM-SHA256",
  622. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  623. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  624. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  625. 0 },
  626. #endif /* MBEDTLS_GCM_C */
  627. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  628. { MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA256, "TLS-RSA-WITH-AES-128-CBC-SHA256",
  629. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  630. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  631. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  632. 0 },
  633. { MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA256, "TLS-RSA-WITH-AES-256-CBC-SHA256",
  634. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  635. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  636. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  637. 0 },
  638. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  639. #endif /* MBEDTLS_SHA256_C */
  640. #if defined(MBEDTLS_SHA1_C)
  641. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  642. { MBEDTLS_TLS_RSA_WITH_AES_128_CBC_SHA, "TLS-RSA-WITH-AES-128-CBC-SHA",
  643. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  644. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  645. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  646. 0 },
  647. { MBEDTLS_TLS_RSA_WITH_AES_256_CBC_SHA, "TLS-RSA-WITH-AES-256-CBC-SHA",
  648. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  649. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  650. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  651. 0 },
  652. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  653. #endif /* MBEDTLS_SHA1_C */
  654. #if defined(MBEDTLS_CCM_C)
  655. { MBEDTLS_TLS_RSA_WITH_AES_256_CCM, "TLS-RSA-WITH-AES-256-CCM",
  656. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  657. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  658. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  659. 0 },
  660. { MBEDTLS_TLS_RSA_WITH_AES_256_CCM_8, "TLS-RSA-WITH-AES-256-CCM-8",
  661. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  662. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  663. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  664. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  665. { MBEDTLS_TLS_RSA_WITH_AES_128_CCM, "TLS-RSA-WITH-AES-128-CCM",
  666. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  667. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  668. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  669. 0 },
  670. { MBEDTLS_TLS_RSA_WITH_AES_128_CCM_8, "TLS-RSA-WITH-AES-128-CCM-8",
  671. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  672. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  673. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  674. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  675. #endif /* MBEDTLS_CCM_C */
  676. #endif /* MBEDTLS_AES_C */
  677. #if defined(MBEDTLS_CAMELLIA_C)
  678. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  679. #if defined(MBEDTLS_SHA256_C)
  680. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256",
  681. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  682. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  683. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  684. 0 },
  685. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256, "TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256",
  686. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  687. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  688. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  689. 0 },
  690. #endif /* MBEDTLS_SHA256_C */
  691. #if defined(MBEDTLS_SHA1_C)
  692. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_CBC_SHA, "TLS-RSA-WITH-CAMELLIA-128-CBC-SHA",
  693. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  694. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  695. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  696. 0 },
  697. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_CBC_SHA, "TLS-RSA-WITH-CAMELLIA-256-CBC-SHA",
  698. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  699. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  700. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  701. 0 },
  702. #endif /* MBEDTLS_SHA1_C */
  703. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  704. #if defined(MBEDTLS_GCM_C)
  705. #if defined(MBEDTLS_SHA256_C)
  706. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-RSA-WITH-CAMELLIA-128-GCM-SHA256",
  707. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  708. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  709. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  710. 0 },
  711. #endif /* MBEDTLS_SHA256_C */
  712. #if defined(MBEDTLS_SHA1_C)
  713. { MBEDTLS_TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-RSA-WITH-CAMELLIA-256-GCM-SHA384",
  714. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA,
  715. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  716. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  717. 0 },
  718. #endif /* MBEDTLS_SHA1_C */
  719. #endif /* MBEDTLS_GCM_C */
  720. #endif /* MBEDTLS_CAMELLIA_C */
  721. #if defined(MBEDTLS_DES_C)
  722. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  723. #if defined(MBEDTLS_SHA1_C)
  724. { MBEDTLS_TLS_RSA_WITH_3DES_EDE_CBC_SHA, "TLS-RSA-WITH-3DES-EDE-CBC-SHA",
  725. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  726. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  727. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  728. 0 },
  729. #endif /* MBEDTLS_SHA1_C */
  730. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  731. #endif /* MBEDTLS_DES_C */
  732. #if defined(MBEDTLS_ARC4_C)
  733. #if defined(MBEDTLS_MD5_C)
  734. { MBEDTLS_TLS_RSA_WITH_RC4_128_MD5, "TLS-RSA-WITH-RC4-128-MD5",
  735. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_MD5, MBEDTLS_KEY_EXCHANGE_RSA,
  736. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  737. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  738. MBEDTLS_CIPHERSUITE_NODTLS },
  739. #endif
  740. #if defined(MBEDTLS_SHA1_C)
  741. { MBEDTLS_TLS_RSA_WITH_RC4_128_SHA, "TLS-RSA-WITH-RC4-128-SHA",
  742. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  743. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  744. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  745. MBEDTLS_CIPHERSUITE_NODTLS },
  746. #endif
  747. #endif /* MBEDTLS_ARC4_C */
  748. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_ENABLED */
  749. #if defined(MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED)
  750. #if defined(MBEDTLS_AES_C)
  751. #if defined(MBEDTLS_SHA1_C)
  752. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  753. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA, "TLS-ECDH-RSA-WITH-AES-128-CBC-SHA",
  754. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  755. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  756. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  757. 0 },
  758. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA, "TLS-ECDH-RSA-WITH-AES-256-CBC-SHA",
  759. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  760. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  761. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  762. 0 },
  763. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  764. #endif /* MBEDTLS_SHA1_C */
  765. #if defined(MBEDTLS_SHA256_C)
  766. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  767. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256, "TLS-ECDH-RSA-WITH-AES-128-CBC-SHA256",
  768. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  769. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  770. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  771. 0 },
  772. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  773. #if defined(MBEDTLS_GCM_C)
  774. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256, "TLS-ECDH-RSA-WITH-AES-128-GCM-SHA256",
  775. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  776. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  777. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  778. 0 },
  779. #endif /* MBEDTLS_GCM_C */
  780. #endif /* MBEDTLS_SHA256_C */
  781. #if defined(MBEDTLS_SHA512_C)
  782. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  783. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384, "TLS-ECDH-RSA-WITH-AES-256-CBC-SHA384",
  784. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  785. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  786. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  787. 0 },
  788. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  789. #if defined(MBEDTLS_GCM_C)
  790. { MBEDTLS_TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384, "TLS-ECDH-RSA-WITH-AES-256-GCM-SHA384",
  791. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  792. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  793. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  794. 0 },
  795. #endif /* MBEDTLS_GCM_C */
  796. #endif /* MBEDTLS_SHA512_C */
  797. #endif /* MBEDTLS_AES_C */
  798. #if defined(MBEDTLS_CAMELLIA_C)
  799. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  800. #if defined(MBEDTLS_SHA256_C)
  801. { MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDH-RSA-WITH-CAMELLIA-128-CBC-SHA256",
  802. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  803. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  804. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  805. 0 },
  806. #endif /* MBEDTLS_SHA256_C */
  807. #if defined(MBEDTLS_SHA512_C)
  808. { MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDH-RSA-WITH-CAMELLIA-256-CBC-SHA384",
  809. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  810. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  811. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  812. 0 },
  813. #endif /* MBEDTLS_SHA512_C */
  814. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  815. #if defined(MBEDTLS_GCM_C)
  816. #if defined(MBEDTLS_SHA256_C)
  817. { MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-ECDH-RSA-WITH-CAMELLIA-128-GCM-SHA256",
  818. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  819. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  820. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  821. 0 },
  822. #endif /* MBEDTLS_SHA256_C */
  823. #if defined(MBEDTLS_SHA512_C)
  824. { MBEDTLS_TLS_ECDH_RSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-ECDH-RSA-WITH-CAMELLIA-256-GCM-SHA384",
  825. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  826. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  827. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  828. 0 },
  829. #endif /* MBEDTLS_SHA512_C */
  830. #endif /* MBEDTLS_GCM_C */
  831. #endif /* MBEDTLS_CAMELLIA_C */
  832. #if defined(MBEDTLS_DES_C)
  833. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  834. #if defined(MBEDTLS_SHA1_C)
  835. { MBEDTLS_TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA, "TLS-ECDH-RSA-WITH-3DES-EDE-CBC-SHA",
  836. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  837. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  838. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  839. 0 },
  840. #endif /* MBEDTLS_SHA1_C */
  841. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  842. #endif /* MBEDTLS_DES_C */
  843. #if defined(MBEDTLS_ARC4_C)
  844. #if defined(MBEDTLS_SHA1_C)
  845. { MBEDTLS_TLS_ECDH_RSA_WITH_RC4_128_SHA, "TLS-ECDH-RSA-WITH-RC4-128-SHA",
  846. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  847. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  848. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  849. MBEDTLS_CIPHERSUITE_NODTLS },
  850. #endif /* MBEDTLS_SHA1_C */
  851. #endif /* MBEDTLS_ARC4_C */
  852. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  853. #if defined(MBEDTLS_SHA1_C)
  854. { MBEDTLS_TLS_ECDH_RSA_WITH_NULL_SHA, "TLS-ECDH-RSA-WITH-NULL-SHA",
  855. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_RSA,
  856. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  857. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  858. MBEDTLS_CIPHERSUITE_WEAK },
  859. #endif /* MBEDTLS_SHA1_C */
  860. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  861. #endif /* MBEDTLS_KEY_EXCHANGE_ECDH_RSA_ENABLED */
  862. #if defined(MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED)
  863. #if defined(MBEDTLS_AES_C)
  864. #if defined(MBEDTLS_SHA1_C)
  865. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  866. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA, "TLS-ECDH-ECDSA-WITH-AES-128-CBC-SHA",
  867. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  868. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  869. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  870. 0 },
  871. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA, "TLS-ECDH-ECDSA-WITH-AES-256-CBC-SHA",
  872. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  873. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  874. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  875. 0 },
  876. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  877. #endif /* MBEDTLS_SHA1_C */
  878. #if defined(MBEDTLS_SHA256_C)
  879. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  880. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256, "TLS-ECDH-ECDSA-WITH-AES-128-CBC-SHA256",
  881. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  882. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  883. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  884. 0 },
  885. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  886. #if defined(MBEDTLS_GCM_C)
  887. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256, "TLS-ECDH-ECDSA-WITH-AES-128-GCM-SHA256",
  888. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  889. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  890. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  891. 0 },
  892. #endif /* MBEDTLS_GCM_C */
  893. #endif /* MBEDTLS_SHA256_C */
  894. #if defined(MBEDTLS_SHA512_C)
  895. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  896. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384, "TLS-ECDH-ECDSA-WITH-AES-256-CBC-SHA384",
  897. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  898. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  899. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  900. 0 },
  901. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  902. #if defined(MBEDTLS_GCM_C)
  903. { MBEDTLS_TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384, "TLS-ECDH-ECDSA-WITH-AES-256-GCM-SHA384",
  904. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  905. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  906. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  907. 0 },
  908. #endif /* MBEDTLS_GCM_C */
  909. #endif /* MBEDTLS_SHA512_C */
  910. #endif /* MBEDTLS_AES_C */
  911. #if defined(MBEDTLS_CAMELLIA_C)
  912. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  913. #if defined(MBEDTLS_SHA256_C)
  914. { MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDH-ECDSA-WITH-CAMELLIA-128-CBC-SHA256",
  915. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  916. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  917. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  918. 0 },
  919. #endif /* MBEDTLS_SHA256_C */
  920. #if defined(MBEDTLS_SHA512_C)
  921. { MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDH-ECDSA-WITH-CAMELLIA-256-CBC-SHA384",
  922. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  923. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  924. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  925. 0 },
  926. #endif /* MBEDTLS_SHA512_C */
  927. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  928. #if defined(MBEDTLS_GCM_C)
  929. #if defined(MBEDTLS_SHA256_C)
  930. { MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256, "TLS-ECDH-ECDSA-WITH-CAMELLIA-128-GCM-SHA256",
  931. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  932. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  933. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  934. 0 },
  935. #endif /* MBEDTLS_SHA256_C */
  936. #if defined(MBEDTLS_SHA512_C)
  937. { MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384, "TLS-ECDH-ECDSA-WITH-CAMELLIA-256-GCM-SHA384",
  938. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  939. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  940. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  941. 0 },
  942. #endif /* MBEDTLS_SHA512_C */
  943. #endif /* MBEDTLS_GCM_C */
  944. #endif /* MBEDTLS_CAMELLIA_C */
  945. #if defined(MBEDTLS_DES_C)
  946. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  947. #if defined(MBEDTLS_SHA1_C)
  948. { MBEDTLS_TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA, "TLS-ECDH-ECDSA-WITH-3DES-EDE-CBC-SHA",
  949. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  950. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  951. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  952. 0 },
  953. #endif /* MBEDTLS_SHA1_C */
  954. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  955. #endif /* MBEDTLS_DES_C */
  956. #if defined(MBEDTLS_ARC4_C)
  957. #if defined(MBEDTLS_SHA1_C)
  958. { MBEDTLS_TLS_ECDH_ECDSA_WITH_RC4_128_SHA, "TLS-ECDH-ECDSA-WITH-RC4-128-SHA",
  959. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  960. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  961. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  962. MBEDTLS_CIPHERSUITE_NODTLS },
  963. #endif /* MBEDTLS_SHA1_C */
  964. #endif /* MBEDTLS_ARC4_C */
  965. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  966. #if defined(MBEDTLS_SHA1_C)
  967. { MBEDTLS_TLS_ECDH_ECDSA_WITH_NULL_SHA, "TLS-ECDH-ECDSA-WITH-NULL-SHA",
  968. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA,
  969. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  970. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  971. MBEDTLS_CIPHERSUITE_WEAK },
  972. #endif /* MBEDTLS_SHA1_C */
  973. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  974. #endif /* MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA_ENABLED */
  975. #if defined(MBEDTLS_KEY_EXCHANGE_PSK_ENABLED)
  976. #if defined(MBEDTLS_AES_C)
  977. #if defined(MBEDTLS_GCM_C)
  978. #if defined(MBEDTLS_SHA256_C)
  979. { MBEDTLS_TLS_PSK_WITH_AES_128_GCM_SHA256, "TLS-PSK-WITH-AES-128-GCM-SHA256",
  980. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  981. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  982. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  983. 0 },
  984. #endif /* MBEDTLS_SHA256_C */
  985. #if defined(MBEDTLS_SHA512_C)
  986. { MBEDTLS_TLS_PSK_WITH_AES_256_GCM_SHA384, "TLS-PSK-WITH-AES-256-GCM-SHA384",
  987. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  988. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  989. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  990. 0 },
  991. #endif /* MBEDTLS_SHA512_C */
  992. #endif /* MBEDTLS_GCM_C */
  993. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  994. #if defined(MBEDTLS_SHA256_C)
  995. { MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA256, "TLS-PSK-WITH-AES-128-CBC-SHA256",
  996. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  997. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  998. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  999. 0 },
  1000. #endif /* MBEDTLS_SHA256_C */
  1001. #if defined(MBEDTLS_SHA512_C)
  1002. { MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA384, "TLS-PSK-WITH-AES-256-CBC-SHA384",
  1003. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  1004. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1005. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1006. 0 },
  1007. #endif /* MBEDTLS_SHA512_C */
  1008. #if defined(MBEDTLS_SHA1_C)
  1009. { MBEDTLS_TLS_PSK_WITH_AES_128_CBC_SHA, "TLS-PSK-WITH-AES-128-CBC-SHA",
  1010. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1011. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1012. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1013. 0 },
  1014. { MBEDTLS_TLS_PSK_WITH_AES_256_CBC_SHA, "TLS-PSK-WITH-AES-256-CBC-SHA",
  1015. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1016. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1017. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1018. 0 },
  1019. #endif /* MBEDTLS_SHA1_C */
  1020. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1021. #if defined(MBEDTLS_CCM_C)
  1022. { MBEDTLS_TLS_PSK_WITH_AES_256_CCM, "TLS-PSK-WITH-AES-256-CCM",
  1023. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1024. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1025. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1026. 0 },
  1027. { MBEDTLS_TLS_PSK_WITH_AES_256_CCM_8, "TLS-PSK-WITH-AES-256-CCM-8",
  1028. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1029. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1030. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1031. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1032. { MBEDTLS_TLS_PSK_WITH_AES_128_CCM, "TLS-PSK-WITH-AES-128-CCM",
  1033. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1034. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1035. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1036. 0 },
  1037. { MBEDTLS_TLS_PSK_WITH_AES_128_CCM_8, "TLS-PSK-WITH-AES-128-CCM-8",
  1038. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1039. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1040. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1041. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1042. #endif /* MBEDTLS_CCM_C */
  1043. #endif /* MBEDTLS_AES_C */
  1044. #if defined(MBEDTLS_CAMELLIA_C)
  1045. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1046. #if defined(MBEDTLS_SHA256_C)
  1047. { MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256, "TLS-PSK-WITH-CAMELLIA-128-CBC-SHA256",
  1048. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1049. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1050. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1051. 0 },
  1052. #endif /* MBEDTLS_SHA256_C */
  1053. #if defined(MBEDTLS_SHA512_C)
  1054. { MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384, "TLS-PSK-WITH-CAMELLIA-256-CBC-SHA384",
  1055. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  1056. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1057. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1058. 0 },
  1059. #endif /* MBEDTLS_SHA512_C */
  1060. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1061. #if defined(MBEDTLS_GCM_C)
  1062. #if defined(MBEDTLS_SHA256_C)
  1063. { MBEDTLS_TLS_PSK_WITH_CAMELLIA_128_GCM_SHA256, "TLS-PSK-WITH-CAMELLIA-128-GCM-SHA256",
  1064. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1065. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1066. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1067. 0 },
  1068. #endif /* MBEDTLS_SHA256_C */
  1069. #if defined(MBEDTLS_SHA512_C)
  1070. { MBEDTLS_TLS_PSK_WITH_CAMELLIA_256_GCM_SHA384, "TLS-PSK-WITH-CAMELLIA-256-GCM-SHA384",
  1071. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  1072. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1073. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1074. 0 },
  1075. #endif /* MBEDTLS_SHA512_C */
  1076. #endif /* MBEDTLS_GCM_C */
  1077. #endif /* MBEDTLS_CAMELLIA_C */
  1078. #if defined(MBEDTLS_DES_C)
  1079. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1080. #if defined(MBEDTLS_SHA1_C)
  1081. { MBEDTLS_TLS_PSK_WITH_3DES_EDE_CBC_SHA, "TLS-PSK-WITH-3DES-EDE-CBC-SHA",
  1082. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1083. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1084. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1085. 0 },
  1086. #endif /* MBEDTLS_SHA1_C */
  1087. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1088. #endif /* MBEDTLS_DES_C */
  1089. #if defined(MBEDTLS_ARC4_C)
  1090. #if defined(MBEDTLS_SHA1_C)
  1091. { MBEDTLS_TLS_PSK_WITH_RC4_128_SHA, "TLS-PSK-WITH-RC4-128-SHA",
  1092. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1093. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1094. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1095. MBEDTLS_CIPHERSUITE_NODTLS },
  1096. #endif /* MBEDTLS_SHA1_C */
  1097. #endif /* MBEDTLS_ARC4_C */
  1098. #endif /* MBEDTLS_KEY_EXCHANGE_PSK_ENABLED */
  1099. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED)
  1100. #if defined(MBEDTLS_AES_C)
  1101. #if defined(MBEDTLS_GCM_C)
  1102. #if defined(MBEDTLS_SHA256_C)
  1103. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_GCM_SHA256, "TLS-DHE-PSK-WITH-AES-128-GCM-SHA256",
  1104. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1105. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1106. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1107. 0 },
  1108. #endif /* MBEDTLS_SHA256_C */
  1109. #if defined(MBEDTLS_SHA512_C)
  1110. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_GCM_SHA384, "TLS-DHE-PSK-WITH-AES-256-GCM-SHA384",
  1111. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1112. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1113. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1114. 0 },
  1115. #endif /* MBEDTLS_SHA512_C */
  1116. #endif /* MBEDTLS_GCM_C */
  1117. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1118. #if defined(MBEDTLS_SHA256_C)
  1119. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA256, "TLS-DHE-PSK-WITH-AES-128-CBC-SHA256",
  1120. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1121. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1122. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1123. 0 },
  1124. #endif /* MBEDTLS_SHA256_C */
  1125. #if defined(MBEDTLS_SHA512_C)
  1126. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA384, "TLS-DHE-PSK-WITH-AES-256-CBC-SHA384",
  1127. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1128. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1129. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1130. 0 },
  1131. #endif /* MBEDTLS_SHA512_C */
  1132. #if defined(MBEDTLS_SHA1_C)
  1133. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CBC_SHA, "TLS-DHE-PSK-WITH-AES-128-CBC-SHA",
  1134. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1135. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1136. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1137. 0 },
  1138. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CBC_SHA, "TLS-DHE-PSK-WITH-AES-256-CBC-SHA",
  1139. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1140. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1141. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1142. 0 },
  1143. #endif /* MBEDTLS_SHA1_C */
  1144. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1145. #if defined(MBEDTLS_CCM_C)
  1146. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM, "TLS-DHE-PSK-WITH-AES-256-CCM",
  1147. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1148. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1149. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1150. 0 },
  1151. { MBEDTLS_TLS_DHE_PSK_WITH_AES_256_CCM_8, "TLS-DHE-PSK-WITH-AES-256-CCM-8",
  1152. MBEDTLS_CIPHER_AES_256_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1153. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1154. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1155. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1156. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM, "TLS-DHE-PSK-WITH-AES-128-CCM",
  1157. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1158. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1159. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1160. 0 },
  1161. { MBEDTLS_TLS_DHE_PSK_WITH_AES_128_CCM_8, "TLS-DHE-PSK-WITH-AES-128-CCM-8",
  1162. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1163. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1164. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1165. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1166. #endif /* MBEDTLS_CCM_C */
  1167. #endif /* MBEDTLS_AES_C */
  1168. #if defined(MBEDTLS_CAMELLIA_C)
  1169. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1170. #if defined(MBEDTLS_SHA256_C)
  1171. { MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256, "TLS-DHE-PSK-WITH-CAMELLIA-128-CBC-SHA256",
  1172. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1173. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1174. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1175. 0 },
  1176. #endif /* MBEDTLS_SHA256_C */
  1177. #if defined(MBEDTLS_SHA512_C)
  1178. { MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384, "TLS-DHE-PSK-WITH-CAMELLIA-256-CBC-SHA384",
  1179. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1180. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1181. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1182. 0 },
  1183. #endif /* MBEDTLS_SHA512_C */
  1184. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1185. #if defined(MBEDTLS_GCM_C)
  1186. #if defined(MBEDTLS_SHA256_C)
  1187. { MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_128_GCM_SHA256, "TLS-DHE-PSK-WITH-CAMELLIA-128-GCM-SHA256",
  1188. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1189. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1190. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1191. 0 },
  1192. #endif /* MBEDTLS_SHA256_C */
  1193. #if defined(MBEDTLS_SHA512_C)
  1194. { MBEDTLS_TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384, "TLS-DHE-PSK-WITH-CAMELLIA-256-GCM-SHA384",
  1195. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1196. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1197. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1198. 0 },
  1199. #endif /* MBEDTLS_SHA512_C */
  1200. #endif /* MBEDTLS_GCM_C */
  1201. #endif /* MBEDTLS_CAMELLIA_C */
  1202. #if defined(MBEDTLS_DES_C)
  1203. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1204. #if defined(MBEDTLS_SHA1_C)
  1205. { MBEDTLS_TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA, "TLS-DHE-PSK-WITH-3DES-EDE-CBC-SHA",
  1206. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1207. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1208. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1209. 0 },
  1210. #endif /* MBEDTLS_SHA1_C */
  1211. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1212. #endif /* MBEDTLS_DES_C */
  1213. #if defined(MBEDTLS_ARC4_C)
  1214. #if defined(MBEDTLS_SHA1_C)
  1215. { MBEDTLS_TLS_DHE_PSK_WITH_RC4_128_SHA, "TLS-DHE-PSK-WITH-RC4-128-SHA",
  1216. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1217. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1218. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1219. MBEDTLS_CIPHERSUITE_NODTLS },
  1220. #endif /* MBEDTLS_SHA1_C */
  1221. #endif /* MBEDTLS_ARC4_C */
  1222. #endif /* MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED */
  1223. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED)
  1224. #if defined(MBEDTLS_AES_C)
  1225. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1226. #if defined(MBEDTLS_SHA256_C)
  1227. { MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256, "TLS-ECDHE-PSK-WITH-AES-128-CBC-SHA256",
  1228. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1229. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1230. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1231. 0 },
  1232. #endif /* MBEDTLS_SHA256_C */
  1233. #if defined(MBEDTLS_SHA512_C)
  1234. { MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384, "TLS-ECDHE-PSK-WITH-AES-256-CBC-SHA384",
  1235. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1236. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1237. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1238. 0 },
  1239. #endif /* MBEDTLS_SHA512_C */
  1240. #if defined(MBEDTLS_SHA1_C)
  1241. { MBEDTLS_TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA, "TLS-ECDHE-PSK-WITH-AES-128-CBC-SHA",
  1242. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1243. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1244. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1245. 0 },
  1246. { MBEDTLS_TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA, "TLS-ECDHE-PSK-WITH-AES-256-CBC-SHA",
  1247. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1248. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1249. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1250. 0 },
  1251. #endif /* MBEDTLS_SHA1_C */
  1252. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1253. #endif /* MBEDTLS_AES_C */
  1254. #if defined(MBEDTLS_CAMELLIA_C)
  1255. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1256. #if defined(MBEDTLS_SHA256_C)
  1257. { MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256, "TLS-ECDHE-PSK-WITH-CAMELLIA-128-CBC-SHA256",
  1258. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1259. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1260. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1261. 0 },
  1262. #endif /* MBEDTLS_SHA256_C */
  1263. #if defined(MBEDTLS_SHA512_C)
  1264. { MBEDTLS_TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384, "TLS-ECDHE-PSK-WITH-CAMELLIA-256-CBC-SHA384",
  1265. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1266. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1267. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1268. 0 },
  1269. #endif /* MBEDTLS_SHA512_C */
  1270. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1271. #endif /* MBEDTLS_CAMELLIA_C */
  1272. #if defined(MBEDTLS_DES_C)
  1273. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1274. #if defined(MBEDTLS_SHA1_C)
  1275. { MBEDTLS_TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA, "TLS-ECDHE-PSK-WITH-3DES-EDE-CBC-SHA",
  1276. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1277. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1278. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1279. 0 },
  1280. #endif /* MBEDTLS_SHA1_C */
  1281. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1282. #endif /* MBEDTLS_DES_C */
  1283. #if defined(MBEDTLS_ARC4_C)
  1284. #if defined(MBEDTLS_SHA1_C)
  1285. { MBEDTLS_TLS_ECDHE_PSK_WITH_RC4_128_SHA, "TLS-ECDHE-PSK-WITH-RC4-128-SHA",
  1286. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1287. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1288. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1289. MBEDTLS_CIPHERSUITE_NODTLS },
  1290. #endif /* MBEDTLS_SHA1_C */
  1291. #endif /* MBEDTLS_ARC4_C */
  1292. #endif /* MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED */
  1293. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED)
  1294. #if defined(MBEDTLS_AES_C)
  1295. #if defined(MBEDTLS_GCM_C)
  1296. #if defined(MBEDTLS_SHA256_C)
  1297. { MBEDTLS_TLS_RSA_PSK_WITH_AES_128_GCM_SHA256, "TLS-RSA-PSK-WITH-AES-128-GCM-SHA256",
  1298. MBEDTLS_CIPHER_AES_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1299. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1300. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1301. 0 },
  1302. #endif /* MBEDTLS_SHA256_C */
  1303. #if defined(MBEDTLS_SHA512_C)
  1304. { MBEDTLS_TLS_RSA_PSK_WITH_AES_256_GCM_SHA384, "TLS-RSA-PSK-WITH-AES-256-GCM-SHA384",
  1305. MBEDTLS_CIPHER_AES_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1306. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1307. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1308. 0 },
  1309. #endif /* MBEDTLS_SHA512_C */
  1310. #endif /* MBEDTLS_GCM_C */
  1311. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1312. #if defined(MBEDTLS_SHA256_C)
  1313. { MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA256, "TLS-RSA-PSK-WITH-AES-128-CBC-SHA256",
  1314. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1315. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1316. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1317. 0 },
  1318. #endif /* MBEDTLS_SHA256_C */
  1319. #if defined(MBEDTLS_SHA512_C)
  1320. { MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA384, "TLS-RSA-PSK-WITH-AES-256-CBC-SHA384",
  1321. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1322. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1323. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1324. 0 },
  1325. #endif /* MBEDTLS_SHA512_C */
  1326. #if defined(MBEDTLS_SHA1_C)
  1327. { MBEDTLS_TLS_RSA_PSK_WITH_AES_128_CBC_SHA, "TLS-RSA-PSK-WITH-AES-128-CBC-SHA",
  1328. MBEDTLS_CIPHER_AES_128_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1329. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1330. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1331. 0 },
  1332. { MBEDTLS_TLS_RSA_PSK_WITH_AES_256_CBC_SHA, "TLS-RSA-PSK-WITH-AES-256-CBC-SHA",
  1333. MBEDTLS_CIPHER_AES_256_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1334. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1335. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1336. 0 },
  1337. #endif /* MBEDTLS_SHA1_C */
  1338. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1339. #endif /* MBEDTLS_AES_C */
  1340. #if defined(MBEDTLS_CAMELLIA_C)
  1341. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1342. #if defined(MBEDTLS_SHA256_C)
  1343. { MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256, "TLS-RSA-PSK-WITH-CAMELLIA-128-CBC-SHA256",
  1344. MBEDTLS_CIPHER_CAMELLIA_128_CBC, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1345. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1346. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1347. 0 },
  1348. #endif /* MBEDTLS_SHA256_C */
  1349. #if defined(MBEDTLS_SHA512_C)
  1350. { MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384, "TLS-RSA-PSK-WITH-CAMELLIA-256-CBC-SHA384",
  1351. MBEDTLS_CIPHER_CAMELLIA_256_CBC, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1352. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1353. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1354. 0 },
  1355. #endif /* MBEDTLS_SHA512_C */
  1356. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1357. #if defined(MBEDTLS_GCM_C)
  1358. #if defined(MBEDTLS_SHA256_C)
  1359. { MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256, "TLS-RSA-PSK-WITH-CAMELLIA-128-GCM-SHA256",
  1360. MBEDTLS_CIPHER_CAMELLIA_128_GCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1361. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1362. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1363. 0 },
  1364. #endif /* MBEDTLS_SHA256_C */
  1365. #if defined(MBEDTLS_SHA512_C)
  1366. { MBEDTLS_TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384, "TLS-RSA-PSK-WITH-CAMELLIA-256-GCM-SHA384",
  1367. MBEDTLS_CIPHER_CAMELLIA_256_GCM, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1368. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1369. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1370. 0 },
  1371. #endif /* MBEDTLS_SHA512_C */
  1372. #endif /* MBEDTLS_GCM_C */
  1373. #endif /* MBEDTLS_CAMELLIA_C */
  1374. #if defined(MBEDTLS_DES_C)
  1375. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1376. #if defined(MBEDTLS_SHA1_C)
  1377. { MBEDTLS_TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA, "TLS-RSA-PSK-WITH-3DES-EDE-CBC-SHA",
  1378. MBEDTLS_CIPHER_DES_EDE3_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1379. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1380. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1381. 0 },
  1382. #endif /* MBEDTLS_SHA1_C */
  1383. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1384. #endif /* MBEDTLS_DES_C */
  1385. #if defined(MBEDTLS_ARC4_C)
  1386. #if defined(MBEDTLS_SHA1_C)
  1387. { MBEDTLS_TLS_RSA_PSK_WITH_RC4_128_SHA, "TLS-RSA-PSK-WITH-RC4-128-SHA",
  1388. MBEDTLS_CIPHER_ARC4_128, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1389. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1390. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1391. MBEDTLS_CIPHERSUITE_NODTLS },
  1392. #endif /* MBEDTLS_SHA1_C */
  1393. #endif /* MBEDTLS_ARC4_C */
  1394. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED */
  1395. #if defined(MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED)
  1396. #if defined(MBEDTLS_AES_C)
  1397. #if defined(MBEDTLS_CCM_C)
  1398. { MBEDTLS_TLS_ECJPAKE_WITH_AES_128_CCM_8, "TLS-ECJPAKE-WITH-AES-128-CCM-8",
  1399. MBEDTLS_CIPHER_AES_128_CCM, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECJPAKE,
  1400. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1401. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1402. MBEDTLS_CIPHERSUITE_SHORT_TAG },
  1403. #endif /* MBEDTLS_CCM_C */
  1404. #endif /* MBEDTLS_AES_C */
  1405. #endif /* MBEDTLS_KEY_EXCHANGE_ECJPAKE_ENABLED */
  1406. #if defined(MBEDTLS_ENABLE_WEAK_CIPHERSUITES)
  1407. #if defined(MBEDTLS_CIPHER_NULL_CIPHER)
  1408. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED)
  1409. #if defined(MBEDTLS_MD5_C)
  1410. { MBEDTLS_TLS_RSA_WITH_NULL_MD5, "TLS-RSA-WITH-NULL-MD5",
  1411. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_MD5, MBEDTLS_KEY_EXCHANGE_RSA,
  1412. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1413. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1414. MBEDTLS_CIPHERSUITE_WEAK },
  1415. #endif
  1416. #if defined(MBEDTLS_SHA1_C)
  1417. { MBEDTLS_TLS_RSA_WITH_NULL_SHA, "TLS-RSA-WITH-NULL-SHA",
  1418. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  1419. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1420. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1421. MBEDTLS_CIPHERSUITE_WEAK },
  1422. #endif
  1423. #if defined(MBEDTLS_SHA256_C)
  1424. { MBEDTLS_TLS_RSA_WITH_NULL_SHA256, "TLS-RSA-WITH-NULL-SHA256",
  1425. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA,
  1426. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1427. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1428. MBEDTLS_CIPHERSUITE_WEAK },
  1429. #endif
  1430. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_ENABLED */
  1431. #if defined(MBEDTLS_KEY_EXCHANGE_PSK_ENABLED)
  1432. #if defined(MBEDTLS_SHA1_C)
  1433. { MBEDTLS_TLS_PSK_WITH_NULL_SHA, "TLS-PSK-WITH-NULL-SHA",
  1434. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_PSK,
  1435. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1436. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1437. MBEDTLS_CIPHERSUITE_WEAK },
  1438. #endif /* MBEDTLS_SHA1_C */
  1439. #if defined(MBEDTLS_SHA256_C)
  1440. { MBEDTLS_TLS_PSK_WITH_NULL_SHA256, "TLS-PSK-WITH-NULL-SHA256",
  1441. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_PSK,
  1442. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1443. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1444. MBEDTLS_CIPHERSUITE_WEAK },
  1445. #endif
  1446. #if defined(MBEDTLS_SHA512_C)
  1447. { MBEDTLS_TLS_PSK_WITH_NULL_SHA384, "TLS-PSK-WITH-NULL-SHA384",
  1448. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_PSK,
  1449. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1450. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1451. MBEDTLS_CIPHERSUITE_WEAK },
  1452. #endif
  1453. #endif /* MBEDTLS_KEY_EXCHANGE_PSK_ENABLED */
  1454. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED)
  1455. #if defined(MBEDTLS_SHA1_C)
  1456. { MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA, "TLS-DHE-PSK-WITH-NULL-SHA",
  1457. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1458. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1459. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1460. MBEDTLS_CIPHERSUITE_WEAK },
  1461. #endif /* MBEDTLS_SHA1_C */
  1462. #if defined(MBEDTLS_SHA256_C)
  1463. { MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA256, "TLS-DHE-PSK-WITH-NULL-SHA256",
  1464. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1465. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1466. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1467. MBEDTLS_CIPHERSUITE_WEAK },
  1468. #endif
  1469. #if defined(MBEDTLS_SHA512_C)
  1470. { MBEDTLS_TLS_DHE_PSK_WITH_NULL_SHA384, "TLS-DHE-PSK-WITH-NULL-SHA384",
  1471. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_DHE_PSK,
  1472. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1473. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1474. MBEDTLS_CIPHERSUITE_WEAK },
  1475. #endif
  1476. #endif /* MBEDTLS_KEY_EXCHANGE_DHE_PSK_ENABLED */
  1477. #if defined(MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED)
  1478. #if defined(MBEDTLS_SHA1_C)
  1479. { MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA, "TLS-ECDHE-PSK-WITH-NULL-SHA",
  1480. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1481. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1482. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1483. MBEDTLS_CIPHERSUITE_WEAK },
  1484. #endif /* MBEDTLS_SHA1_C */
  1485. #if defined(MBEDTLS_SHA256_C)
  1486. { MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA256, "TLS-ECDHE-PSK-WITH-NULL-SHA256",
  1487. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1488. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1489. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1490. MBEDTLS_CIPHERSUITE_WEAK },
  1491. #endif
  1492. #if defined(MBEDTLS_SHA512_C)
  1493. { MBEDTLS_TLS_ECDHE_PSK_WITH_NULL_SHA384, "TLS-ECDHE-PSK-WITH-NULL-SHA384",
  1494. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_ECDHE_PSK,
  1495. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1496. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1497. MBEDTLS_CIPHERSUITE_WEAK },
  1498. #endif
  1499. #endif /* MBEDTLS_KEY_EXCHANGE_ECDHE_PSK_ENABLED */
  1500. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED)
  1501. #if defined(MBEDTLS_SHA1_C)
  1502. { MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA, "TLS-RSA-PSK-WITH-NULL-SHA",
  1503. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1504. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1505. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1506. MBEDTLS_CIPHERSUITE_WEAK },
  1507. #endif /* MBEDTLS_SHA1_C */
  1508. #if defined(MBEDTLS_SHA256_C)
  1509. { MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA256, "TLS-RSA-PSK-WITH-NULL-SHA256",
  1510. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA256, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1511. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1512. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1513. MBEDTLS_CIPHERSUITE_WEAK },
  1514. #endif
  1515. #if defined(MBEDTLS_SHA512_C)
  1516. { MBEDTLS_TLS_RSA_PSK_WITH_NULL_SHA384, "TLS-RSA-PSK-WITH-NULL-SHA384",
  1517. MBEDTLS_CIPHER_NULL, MBEDTLS_MD_SHA384, MBEDTLS_KEY_EXCHANGE_RSA_PSK,
  1518. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_1,
  1519. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1520. MBEDTLS_CIPHERSUITE_WEAK },
  1521. #endif
  1522. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_PSK_ENABLED */
  1523. #endif /* MBEDTLS_CIPHER_NULL_CIPHER */
  1524. #if defined(MBEDTLS_DES_C)
  1525. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  1526. #if defined(MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED)
  1527. #if defined(MBEDTLS_SHA1_C)
  1528. { MBEDTLS_TLS_DHE_RSA_WITH_DES_CBC_SHA, "TLS-DHE-RSA-WITH-DES-CBC-SHA",
  1529. MBEDTLS_CIPHER_DES_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_DHE_RSA,
  1530. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1531. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1532. MBEDTLS_CIPHERSUITE_WEAK },
  1533. #endif /* MBEDTLS_SHA1_C */
  1534. #endif /* MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED */
  1535. #if defined(MBEDTLS_KEY_EXCHANGE_RSA_ENABLED)
  1536. #if defined(MBEDTLS_SHA1_C)
  1537. { MBEDTLS_TLS_RSA_WITH_DES_CBC_SHA, "TLS-RSA-WITH-DES-CBC-SHA",
  1538. MBEDTLS_CIPHER_DES_CBC, MBEDTLS_MD_SHA1, MBEDTLS_KEY_EXCHANGE_RSA,
  1539. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_0,
  1540. MBEDTLS_SSL_MAJOR_VERSION_3, MBEDTLS_SSL_MINOR_VERSION_3,
  1541. MBEDTLS_CIPHERSUITE_WEAK },
  1542. #endif /* MBEDTLS_SHA1_C */
  1543. #endif /* MBEDTLS_KEY_EXCHANGE_RSA_ENABLED */
  1544. #endif /* MBEDTLS_CIPHER_MODE_CBC */
  1545. #endif /* MBEDTLS_DES_C */
  1546. #endif /* MBEDTLS_ENABLE_WEAK_CIPHERSUITES */
  1547. { 0, "",
  1548. MBEDTLS_CIPHER_NONE, MBEDTLS_MD_NONE, MBEDTLS_KEY_EXCHANGE_NONE,
  1549. 0, 0, 0, 0, 0 }
  1550. };
  1551. #if defined(MBEDTLS_SSL_CIPHERSUITES)
  1552. const int *mbedtls_ssl_list_ciphersuites( void )
  1553. {
  1554. return( ciphersuite_preference );
  1555. }
  1556. #else
  1557. #define MAX_CIPHERSUITES sizeof( ciphersuite_definitions ) / \
  1558. sizeof( ciphersuite_definitions[0] )
  1559. static int supported_ciphersuites[MAX_CIPHERSUITES];
  1560. static int supported_init = 0;
  1561. const int *mbedtls_ssl_list_ciphersuites( void )
  1562. {
  1563. /*
  1564. * On initial call filter out all ciphersuites not supported by current
  1565. * build based on presence in the ciphersuite_definitions.
  1566. */
  1567. if( supported_init == 0 )
  1568. {
  1569. const int *p;
  1570. int *q;
  1571. for( p = ciphersuite_preference, q = supported_ciphersuites;
  1572. *p != 0 && q < supported_ciphersuites + MAX_CIPHERSUITES - 1;
  1573. p++ )
  1574. {
  1575. #if defined(MBEDTLS_REMOVE_ARC4_CIPHERSUITES)
  1576. const mbedtls_ssl_ciphersuite_t *cs_info;
  1577. if( ( cs_info = mbedtls_ssl_ciphersuite_from_id( *p ) ) != NULL &&
  1578. cs_info->cipher != MBEDTLS_CIPHER_ARC4_128 )
  1579. #else
  1580. if( mbedtls_ssl_ciphersuite_from_id( *p ) != NULL )
  1581. #endif
  1582. *(q++) = *p;
  1583. }
  1584. *q = 0;
  1585. supported_init = 1;
  1586. }
  1587. return( supported_ciphersuites );
  1588. }
  1589. #endif /* MBEDTLS_SSL_CIPHERSUITES */
  1590. const mbedtls_ssl_ciphersuite_t *mbedtls_ssl_ciphersuite_from_string(
  1591. const char *ciphersuite_name )
  1592. {
  1593. const mbedtls_ssl_ciphersuite_t *cur = ciphersuite_definitions;
  1594. if( NULL == ciphersuite_name )
  1595. return( NULL );
  1596. while( cur->id != 0 )
  1597. {
  1598. if( 0 == strcmp( cur->name, ciphersuite_name ) )
  1599. return( cur );
  1600. cur++;
  1601. }
  1602. return( NULL );
  1603. }
  1604. const mbedtls_ssl_ciphersuite_t *mbedtls_ssl_ciphersuite_from_id( int ciphersuite )
  1605. {
  1606. const mbedtls_ssl_ciphersuite_t *cur = ciphersuite_definitions;
  1607. while( cur->id != 0 )
  1608. {
  1609. if( cur->id == ciphersuite )
  1610. return( cur );
  1611. cur++;
  1612. }
  1613. return( NULL );
  1614. }
  1615. const char *mbedtls_ssl_get_ciphersuite_name( const int ciphersuite_id )
  1616. {
  1617. const mbedtls_ssl_ciphersuite_t *cur;
  1618. cur = mbedtls_ssl_ciphersuite_from_id( ciphersuite_id );
  1619. if( cur == NULL )
  1620. return( "unknown" );
  1621. return( cur->name );
  1622. }
  1623. int mbedtls_ssl_get_ciphersuite_id( const char *ciphersuite_name )
  1624. {
  1625. const mbedtls_ssl_ciphersuite_t *cur;
  1626. cur = mbedtls_ssl_ciphersuite_from_string( ciphersuite_name );
  1627. if( cur == NULL )
  1628. return( 0 );
  1629. return( cur->id );
  1630. }
  1631. #if defined(MBEDTLS_PK_C)
  1632. mbedtls_pk_type_t mbedtls_ssl_get_ciphersuite_sig_pk_alg( const mbedtls_ssl_ciphersuite_t *info )
  1633. {
  1634. switch( info->key_exchange )
  1635. {
  1636. case MBEDTLS_KEY_EXCHANGE_RSA:
  1637. case MBEDTLS_KEY_EXCHANGE_DHE_RSA:
  1638. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  1639. case MBEDTLS_KEY_EXCHANGE_RSA_PSK:
  1640. return( MBEDTLS_PK_RSA );
  1641. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  1642. return( MBEDTLS_PK_ECDSA );
  1643. case MBEDTLS_KEY_EXCHANGE_ECDH_RSA:
  1644. case MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA:
  1645. return( MBEDTLS_PK_ECKEY );
  1646. default:
  1647. return( MBEDTLS_PK_NONE );
  1648. }
  1649. }
  1650. #endif /* MBEDTLS_PK_C */
  1651. #if defined(MBEDTLS_ECDH_C) || defined(MBEDTLS_ECDSA_C)
  1652. int mbedtls_ssl_ciphersuite_uses_ec( const mbedtls_ssl_ciphersuite_t *info )
  1653. {
  1654. switch( info->key_exchange )
  1655. {
  1656. case MBEDTLS_KEY_EXCHANGE_ECDHE_RSA:
  1657. case MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA:
  1658. case MBEDTLS_KEY_EXCHANGE_ECDHE_PSK:
  1659. case MBEDTLS_KEY_EXCHANGE_ECDH_RSA:
  1660. case MBEDTLS_KEY_EXCHANGE_ECDH_ECDSA:
  1661. return( 1 );
  1662. default:
  1663. return( 0 );
  1664. }
  1665. }
  1666. #endif /* MBEDTLS_ECDH_C || MBEDTLS_ECDSA_C */
  1667. #if defined(MBEDTLS_KEY_EXCHANGE__SOME__PSK_ENABLED)
  1668. int mbedtls_ssl_ciphersuite_uses_psk( const mbedtls_ssl_ciphersuite_t *info )
  1669. {
  1670. switch( info->key_exchange )
  1671. {
  1672. case MBEDTLS_KEY_EXCHANGE_PSK:
  1673. case MBEDTLS_KEY_EXCHANGE_RSA_PSK:
  1674. case MBEDTLS_KEY_EXCHANGE_DHE_PSK:
  1675. case MBEDTLS_KEY_EXCHANGE_ECDHE_PSK:
  1676. return( 1 );
  1677. default:
  1678. return( 0 );
  1679. }
  1680. }
  1681. #endif /* MBEDTLS_KEY_EXCHANGE__SOME__PSK_ENABLED */
  1682. #endif /* MBEDTLS_SSL_TLS_C */