summaryrefslogtreecommitdiffstats
path: root/src/include
diff options
context:
space:
mode:
authorMichael Brown2022-11-07 19:34:37 +0100
committerMichael Brown2022-11-08 14:48:45 +0100
commitb6eef1485808093f9dae4fe9d6b685e01a6d65a4 (patch)
tree412bf41dea752f04f3cca2cc658aedac5bebac9a /src/include
parent[tls] Ensure cipher alignment size is respected (diff)
downloadipxe-b6eef1485808093f9dae4fe9d6b685e01a6d65a4.tar.gz
ipxe-b6eef1485808093f9dae4fe9d6b685e01a6d65a4.tar.xz
ipxe-b6eef1485808093f9dae4fe9d6b685e01a6d65a4.zip
[tls] Abstract out concept of a TLS authentication header
All TLS cipher types use a common structure for the per-record data that is authenticated in addition to the plaintext itself. This data is used as a prefix in the HMAC calculation for stream and block ciphers, or as additional authenticated data for AEAD ciphers. Define a "TLS authentication header" structure to hold this data as a contiguous block, in order to meet the alignment requirement for AEAD ciphers such as GCM. Signed-off-by: Michael Brown <mcb30@ipxe.org>
Diffstat (limited to 'src/include')
-rw-r--r--src/include/ipxe/tls.h8
1 files changed, 8 insertions, 0 deletions
diff --git a/src/include/ipxe/tls.h b/src/include/ipxe/tls.h
index 8bb1ccceb..be192b7ef 100644
--- a/src/include/ipxe/tls.h
+++ b/src/include/ipxe/tls.h
@@ -122,6 +122,14 @@ struct tls_header {
/* TLS renegotiation information extension */
#define TLS_RENEGOTIATION_INFO 0xff01
+/** TLS authentication header */
+struct tls_auth_header {
+ /** Sequence number */
+ uint64_t seq;
+ /** TLS header */
+ struct tls_header header;
+} __attribute__ (( packed ));
+
/** TLS verification data */
struct tls_verify_data {
/** Client verification data */