[dtls] explicitly configure ECJPAKE parameters (#5192)

This commit:

- Uses the mbedtls API to explicitly fix the number of used curves to
  one when using ECJPAKE, as required by Section 3 of
  draft-cragie-tls-ecjpake-01.

- Uses the mbedtls API to explicitly remove the Signature Hash
  Algorithms when using ECJPAKE.
This commit is contained in:
Eduardo Montoya
2020-07-07 19:05:19 -07:00
committed by GitHub
parent eee173af0b
commit 396d23cd06
2 changed files with 17 additions and 0 deletions
+12
View File
@@ -56,6 +56,11 @@
namespace ot {
namespace MeshCoP {
const mbedtls_ecp_group_id Dtls::sCurves[] = {MBEDTLS_ECP_DP_SECP256R1, MBEDTLS_ECP_DP_NONE};
#ifdef MBEDTLS_KEY_EXCHANGE__WITH_CERT__ENABLED
const int Dtls::sHashes[] = {MBEDTLS_MD_NONE};
#endif
Dtls::Dtls(Instance &aInstance, bool aLayerTwoSecurity)
: InstanceLocator(aInstance)
, mState(kStateClosed)
@@ -286,6 +291,13 @@ otError Dtls::Setup(bool aClient)
OT_ASSERT(mCipherSuites[1] == 0);
mbedtls_ssl_conf_ciphersuites(&mConf, mCipherSuites);
if (mCipherSuites[0] == MBEDTLS_TLS_ECJPAKE_WITH_AES_128_CCM_8)
{
mbedtls_ssl_conf_curves(&mConf, sCurves);
#ifdef MBEDTLS_KEY_EXCHANGE__WITH_CERT__ENABLED
mbedtls_ssl_conf_sig_hashes(&mConf, sHashes);
#endif
}
mbedtls_ssl_conf_export_keys_cb(&mConf, HandleMbedtlsExportKeys, this);
mbedtls_ssl_conf_handshake_timeout(&mConf, 8000, 60000);
mbedtls_ssl_conf_dbg(&mConf, HandleMbedtlsDebug, this);
+5
View File
@@ -413,6 +413,11 @@ private:
uint8_t mPsk[kPskMaxLength];
uint8_t mPskLength;
static const mbedtls_ecp_group_id sCurves[];
#ifdef MBEDTLS_KEY_EXCHANGE__WITH_CERT__ENABLED
static const int sHashes[];
#endif
#if OPENTHREAD_CONFIG_COAP_SECURE_API_ENABLE
#ifdef MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
const uint8_t * mCaChainSrc;