Skip to main content

rustls/crypto/ring/
mod.rs

1use pki_types::PrivateKeyDer;
2pub(crate) use ring as ring_like;
3use webpki::ring as webpki_algs;
4use zeroize::Zeroizing;
5
6use crate::Error;
7use crate::crypto::{CryptoProvider, KeyProvider, SecureRandom, SupportedKxGroup};
8use crate::enums::SignatureScheme;
9use crate::rand::GetRandomFailed;
10use crate::sign::SigningKey;
11use crate::suites::SupportedCipherSuite;
12use crate::sync::Arc;
13use crate::webpki::WebPkiSupportedAlgorithms;
14
15/// Using software keys for authentication.
16pub mod sign;
17
18pub(crate) mod hash;
19#[cfg(any(test, feature = "tls12"))]
20pub(crate) mod hmac;
21pub(crate) mod kx;
22pub(crate) mod quic;
23#[cfg(feature = "std")]
24pub(crate) mod ticketer;
25#[cfg(feature = "tls12")]
26pub(crate) mod tls12;
27pub(crate) mod tls13;
28
29/// A `CryptoProvider` backed by the [*ring*] crate.
30///
31/// [*ring*]: https://github.com/briansmith/ring
32pub fn default_provider() -> CryptoProvider {
33    CryptoProvider {
34        cipher_suites: DEFAULT_CIPHER_SUITES.to_vec(),
35        kx_groups: DEFAULT_KX_GROUPS.to_vec(),
36        signature_verification_algorithms: SUPPORTED_SIG_ALGS,
37        secure_random: &Ring,
38        key_provider: &Ring,
39    }
40}
41
42/// Default crypto provider.
43#[derive(Debug)]
44struct Ring;
45
46impl SecureRandom for Ring {
47    fn fill(&self, buf: &mut [u8]) -> Result<(), GetRandomFailed> {
48        use ring_like::rand::SecureRandom;
49
50        ring_like::rand::SystemRandom::new()
51            .fill(buf)
52            .map_err(|_| GetRandomFailed)
53    }
54}
55
56impl KeyProvider for Ring {
57    fn load_private_key(
58        &self,
59        key_der: PrivateKeyDer<'static>,
60    ) -> Result<Arc<dyn SigningKey>, Error> {
61        sign::any_supported_type(&Zeroizing::new(key_der))
62    }
63}
64
65/// The cipher suite configuration that an application should use by default.
66///
67/// This will be [`ALL_CIPHER_SUITES`] sans any supported cipher suites that
68/// shouldn't be enabled by most applications.
69pub static DEFAULT_CIPHER_SUITES: &[SupportedCipherSuite] = ALL_CIPHER_SUITES;
70
71/// A list of all the cipher suites supported by the rustls *ring* provider.
72pub static ALL_CIPHER_SUITES: &[SupportedCipherSuite] = &[
73    // TLS1.3 suites
74    tls13::TLS13_AES_256_GCM_SHA384,
75    tls13::TLS13_AES_128_GCM_SHA256,
76    tls13::TLS13_CHACHA20_POLY1305_SHA256,
77    // TLS1.2 suites
78    #[cfg(feature = "tls12")]
79    tls12::TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
80    #[cfg(feature = "tls12")]
81    tls12::TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
82    #[cfg(feature = "tls12")]
83    tls12::TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256,
84    #[cfg(feature = "tls12")]
85    tls12::TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
86    #[cfg(feature = "tls12")]
87    tls12::TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
88    #[cfg(feature = "tls12")]
89    tls12::TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,
90];
91
92/// All defined cipher suites supported by *ring* appear in this module.
93pub mod cipher_suite {
94    #[cfg(feature = "tls12")]
95    pub use super::tls12::{
96        TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
97        TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
98        TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,
99    };
100    pub use super::tls13::{
101        TLS13_AES_128_GCM_SHA256, TLS13_AES_256_GCM_SHA384, TLS13_CHACHA20_POLY1305_SHA256,
102    };
103}
104
105/// A `WebPkiSupportedAlgorithms` value that reflects webpki's capabilities when
106/// compiled against *ring*.
107static SUPPORTED_SIG_ALGS: WebPkiSupportedAlgorithms = WebPkiSupportedAlgorithms {
108    all: &[
109        webpki_algs::ECDSA_P256_SHA256,
110        webpki_algs::ECDSA_P256_SHA384,
111        webpki_algs::ECDSA_P384_SHA256,
112        webpki_algs::ECDSA_P384_SHA384,
113        webpki_algs::ED25519,
114        webpki_algs::RSA_PSS_2048_8192_SHA256_LEGACY_KEY,
115        webpki_algs::RSA_PSS_2048_8192_SHA384_LEGACY_KEY,
116        webpki_algs::RSA_PSS_2048_8192_SHA512_LEGACY_KEY,
117        webpki_algs::RSA_PKCS1_2048_8192_SHA256,
118        webpki_algs::RSA_PKCS1_2048_8192_SHA384,
119        webpki_algs::RSA_PKCS1_2048_8192_SHA512,
120        webpki_algs::RSA_PKCS1_2048_8192_SHA256_ABSENT_PARAMS,
121        webpki_algs::RSA_PKCS1_2048_8192_SHA384_ABSENT_PARAMS,
122        webpki_algs::RSA_PKCS1_2048_8192_SHA512_ABSENT_PARAMS,
123    ],
124    mapping: &[
125        // Note: for TLS1.2 the curve is not fixed by SignatureScheme. For TLS1.3 it is.
126        (
127            SignatureScheme::ECDSA_NISTP384_SHA384,
128            &[
129                webpki_algs::ECDSA_P384_SHA384,
130                webpki_algs::ECDSA_P256_SHA384,
131            ],
132        ),
133        (
134            SignatureScheme::ECDSA_NISTP256_SHA256,
135            &[
136                webpki_algs::ECDSA_P256_SHA256,
137                webpki_algs::ECDSA_P384_SHA256,
138            ],
139        ),
140        (SignatureScheme::ED25519, &[webpki_algs::ED25519]),
141        (
142            SignatureScheme::RSA_PSS_SHA512,
143            &[webpki_algs::RSA_PSS_2048_8192_SHA512_LEGACY_KEY],
144        ),
145        (
146            SignatureScheme::RSA_PSS_SHA384,
147            &[webpki_algs::RSA_PSS_2048_8192_SHA384_LEGACY_KEY],
148        ),
149        (
150            SignatureScheme::RSA_PSS_SHA256,
151            &[webpki_algs::RSA_PSS_2048_8192_SHA256_LEGACY_KEY],
152        ),
153        (
154            SignatureScheme::RSA_PKCS1_SHA512,
155            &[webpki_algs::RSA_PKCS1_2048_8192_SHA512],
156        ),
157        (
158            SignatureScheme::RSA_PKCS1_SHA384,
159            &[webpki_algs::RSA_PKCS1_2048_8192_SHA384],
160        ),
161        (
162            SignatureScheme::RSA_PKCS1_SHA256,
163            &[webpki_algs::RSA_PKCS1_2048_8192_SHA256],
164        ),
165    ],
166};
167
168/// All defined key exchange groups supported by *ring* appear in this module.
169///
170/// [`ALL_KX_GROUPS`] is provided as an array of all of these values.
171/// [`DEFAULT_KX_GROUPS`] is provided as an array of this provider's defaults.
172pub mod kx_group {
173    pub use super::kx::{SECP256R1, SECP384R1, X25519};
174}
175
176/// A list of the default key exchange groups supported by this provider.
177pub static DEFAULT_KX_GROUPS: &[&dyn SupportedKxGroup] = ALL_KX_GROUPS;
178
179/// A list of all the key exchange groups supported by this provider.
180pub static ALL_KX_GROUPS: &[&dyn SupportedKxGroup] =
181    &[kx_group::X25519, kx_group::SECP256R1, kx_group::SECP384R1];
182
183#[cfg(feature = "std")]
184pub use ticketer::Ticketer;
185
186/// Compatibility shims between ring 0.16.x and 0.17.x API
187mod ring_shim {
188    use super::ring_like;
189    use crate::crypto::SharedSecret;
190
191    pub(super) fn agree_ephemeral(
192        priv_key: ring_like::agreement::EphemeralPrivateKey,
193        peer_key: &ring_like::agreement::UnparsedPublicKey<&[u8]>,
194    ) -> Result<SharedSecret, ()> {
195        ring_like::agreement::agree_ephemeral(priv_key, peer_key, |secret| {
196            SharedSecret::from(secret)
197        })
198        .map_err(|_| ())
199    }
200}
201
202pub(super) fn fips() -> bool {
203    false
204}