File ssl_ticket.h

TLS server ticket callbacks implementation.

Typedefs

typedef struct mbedtls_ssl_ticket_key mbedtls_ssl_ticket_key

Information for session ticket protection.

typedef struct mbedtls_ssl_ticket_context mbedtls_ssl_ticket_context

Context for session ticket handling functions.

Functions

void mbedtls_ssl_ticket_init(mbedtls_ssl_ticket_context *ctx)

Initialize a ticket context. (Just make it ready for mbedtls_ssl_ticket_setup() or mbedtls_ssl_ticket_free().)

Parameters

ctx – Context to be initialized

int mbedtls_ssl_ticket_setup(mbedtls_ssl_ticket_context *ctx, int (*f_rng)(void*, unsigned char*, size_t), void *p_rng, mbedtls_cipher_type_t cipher, uint32_t lifetime)

Prepare context to be actually used.

Note

It is highly recommended to select a cipher that is at least as strong as the strongest ciphersuite supported. Usually that means a 256-bit key.

Note

The lifetime of the keys is twice the lifetime of tickets. It is recommended to pick a reasonable lifetime so as not to negate the benefits of forward secrecy.

Parameters
  • ctx – Context to be set up

  • f_rng – RNG callback function

  • p_rng – RNG callback context

  • cipher – AEAD cipher to use for ticket protection. Recommended value: MBEDTLS_CIPHER_AES_256_GCM.

  • lifetime – Tickets lifetime in seconds Recommended value: 86400 (one day).

Returns

0 if successful, or a specific MBEDTLS_ERR_XXX error code

void mbedtls_ssl_ticket_free(mbedtls_ssl_ticket_context *ctx)

Free a context’s content and zeroize it.

Parameters

ctx – Context to be cleaned up

Variables

mbedtls_ssl_ticket_write_t mbedtls_ssl_ticket_write

Implementation of the ticket write callback.

Note

See mbedtls_ssl_ticket_write_t for description

mbedtls_ssl_ticket_parse_t mbedtls_ssl_ticket_parse

Implementation of the ticket parse callback.

Note

See mbedtls_ssl_ticket_parse_t for description

struct mbedtls_ssl_ticket_key
#include <ssl_ticket.h>

Information for session ticket protection.

Public Members

unsigned char name[4]

random key identifier

uint32_t generation_time

key generation timestamp (seconds)

mbedtls_cipher_context_t ctx

context for auth enc/decryption

struct mbedtls_ssl_ticket_context
#include <ssl_ticket.h>

Context for session ticket handling functions.

Public Members

mbedtls_ssl_ticket_key keys[2]

ticket protection keys

unsigned char active

index of the currently active key

uint32_t ticket_lifetime

lifetime of tickets in seconds

int (*f_rng)(void*, unsigned char*, size_t)

Callback for getting (pseudo-)random numbers

void *p_rng

context for the RNG function

mbedtls_threading_mutex_t mutex