1use pki_types::PrivateKeyDer;
2pub(crate) use ring as ring_like;
3use webpki::ring as webpki_algs;
4use zeroize::Zeroizing;
5
6use crate::Error;
7use crate::crypto::{CryptoProvider, KeyProvider, SecureRandom, SupportedKxGroup};
8use crate::enums::SignatureScheme;
9use crate::rand::GetRandomFailed;
10use crate::sign::SigningKey;
11use crate::suites::SupportedCipherSuite;
12use crate::sync::Arc;
13use crate::webpki::WebPkiSupportedAlgorithms;
14
15pub mod sign;
17
18pub(crate) mod hash;
19#[cfg(any(test, feature = "tls12"))]
20pub(crate) mod hmac;
21pub(crate) mod kx;
22pub(crate) mod quic;
23#[cfg(feature = "std")]
24pub(crate) mod ticketer;
25#[cfg(feature = "tls12")]
26pub(crate) mod tls12;
27pub(crate) mod tls13;
28
29pub fn default_provider() -> CryptoProvider {
33 CryptoProvider {
34 cipher_suites: DEFAULT_CIPHER_SUITES.to_vec(),
35 kx_groups: DEFAULT_KX_GROUPS.to_vec(),
36 signature_verification_algorithms: SUPPORTED_SIG_ALGS,
37 secure_random: &Ring,
38 key_provider: &Ring,
39 }
40}
41
42#[derive(Debug)]
44struct Ring;
45
46impl SecureRandom for Ring {
47 fn fill(&self, buf: &mut [u8]) -> Result<(), GetRandomFailed> {
48 use ring_like::rand::SecureRandom;
49
50 ring_like::rand::SystemRandom::new()
51 .fill(buf)
52 .map_err(|_| GetRandomFailed)
53 }
54}
55
56impl KeyProvider for Ring {
57 fn load_private_key(
58 &self,
59 key_der: PrivateKeyDer<'static>,
60 ) -> Result<Arc<dyn SigningKey>, Error> {
61 sign::any_supported_type(&Zeroizing::new(key_der))
62 }
63}
64
65pub static DEFAULT_CIPHER_SUITES: &[SupportedCipherSuite] = ALL_CIPHER_SUITES;
70
71pub static ALL_CIPHER_SUITES: &[SupportedCipherSuite] = &[
73 tls13::TLS13_AES_256_GCM_SHA384,
75 tls13::TLS13_AES_128_GCM_SHA256,
76 tls13::TLS13_CHACHA20_POLY1305_SHA256,
77 #[cfg(feature = "tls12")]
79 tls12::TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
80 #[cfg(feature = "tls12")]
81 tls12::TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
82 #[cfg(feature = "tls12")]
83 tls12::TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256,
84 #[cfg(feature = "tls12")]
85 tls12::TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
86 #[cfg(feature = "tls12")]
87 tls12::TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
88 #[cfg(feature = "tls12")]
89 tls12::TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,
90];
91
92pub mod cipher_suite {
94 #[cfg(feature = "tls12")]
95 pub use super::tls12::{
96 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
97 TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
98 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,
99 };
100 pub use super::tls13::{
101 TLS13_AES_128_GCM_SHA256, TLS13_AES_256_GCM_SHA384, TLS13_CHACHA20_POLY1305_SHA256,
102 };
103}
104
105static SUPPORTED_SIG_ALGS: WebPkiSupportedAlgorithms = WebPkiSupportedAlgorithms {
108 all: &[
109 webpki_algs::ECDSA_P256_SHA256,
110 webpki_algs::ECDSA_P256_SHA384,
111 webpki_algs::ECDSA_P384_SHA256,
112 webpki_algs::ECDSA_P384_SHA384,
113 webpki_algs::ED25519,
114 webpki_algs::RSA_PSS_2048_8192_SHA256_LEGACY_KEY,
115 webpki_algs::RSA_PSS_2048_8192_SHA384_LEGACY_KEY,
116 webpki_algs::RSA_PSS_2048_8192_SHA512_LEGACY_KEY,
117 webpki_algs::RSA_PKCS1_2048_8192_SHA256,
118 webpki_algs::RSA_PKCS1_2048_8192_SHA384,
119 webpki_algs::RSA_PKCS1_2048_8192_SHA512,
120 webpki_algs::RSA_PKCS1_2048_8192_SHA256_ABSENT_PARAMS,
121 webpki_algs::RSA_PKCS1_2048_8192_SHA384_ABSENT_PARAMS,
122 webpki_algs::RSA_PKCS1_2048_8192_SHA512_ABSENT_PARAMS,
123 ],
124 mapping: &[
125 (
127 SignatureScheme::ECDSA_NISTP384_SHA384,
128 &[
129 webpki_algs::ECDSA_P384_SHA384,
130 webpki_algs::ECDSA_P256_SHA384,
131 ],
132 ),
133 (
134 SignatureScheme::ECDSA_NISTP256_SHA256,
135 &[
136 webpki_algs::ECDSA_P256_SHA256,
137 webpki_algs::ECDSA_P384_SHA256,
138 ],
139 ),
140 (SignatureScheme::ED25519, &[webpki_algs::ED25519]),
141 (
142 SignatureScheme::RSA_PSS_SHA512,
143 &[webpki_algs::RSA_PSS_2048_8192_SHA512_LEGACY_KEY],
144 ),
145 (
146 SignatureScheme::RSA_PSS_SHA384,
147 &[webpki_algs::RSA_PSS_2048_8192_SHA384_LEGACY_KEY],
148 ),
149 (
150 SignatureScheme::RSA_PSS_SHA256,
151 &[webpki_algs::RSA_PSS_2048_8192_SHA256_LEGACY_KEY],
152 ),
153 (
154 SignatureScheme::RSA_PKCS1_SHA512,
155 &[webpki_algs::RSA_PKCS1_2048_8192_SHA512],
156 ),
157 (
158 SignatureScheme::RSA_PKCS1_SHA384,
159 &[webpki_algs::RSA_PKCS1_2048_8192_SHA384],
160 ),
161 (
162 SignatureScheme::RSA_PKCS1_SHA256,
163 &[webpki_algs::RSA_PKCS1_2048_8192_SHA256],
164 ),
165 ],
166};
167
168pub mod kx_group {
173 pub use super::kx::{SECP256R1, SECP384R1, X25519};
174}
175
176pub static DEFAULT_KX_GROUPS: &[&dyn SupportedKxGroup] = ALL_KX_GROUPS;
178
179pub static ALL_KX_GROUPS: &[&dyn SupportedKxGroup] =
181 &[kx_group::X25519, kx_group::SECP256R1, kx_group::SECP384R1];
182
183#[cfg(feature = "std")]
184pub use ticketer::Ticketer;
185
186mod ring_shim {
188 use super::ring_like;
189 use crate::crypto::SharedSecret;
190
191 pub(super) fn agree_ephemeral(
192 priv_key: ring_like::agreement::EphemeralPrivateKey,
193 peer_key: &ring_like::agreement::UnparsedPublicKey<&[u8]>,
194 ) -> Result<SharedSecret, ()> {
195 ring_like::agreement::agree_ephemeral(priv_key, peer_key, |secret| {
196 SharedSecret::from(secret)
197 })
198 .map_err(|_| ())
199 }
200}
201
202pub(super) fn fips() -> bool {
203 false
204}