File ssl_ticket.h
TLS server ticket callbacks implementation.
Typedefs
-
typedef struct mbedtls_ssl_ticket_key mbedtls_ssl_ticket_key
Information for session ticket protection.
-
typedef struct mbedtls_ssl_ticket_context mbedtls_ssl_ticket_context
Context for session ticket handling functions.
Functions
-
void mbedtls_ssl_ticket_init(mbedtls_ssl_ticket_context *ctx)
Initialize a ticket context. (Just make it ready for mbedtls_ssl_ticket_setup() or mbedtls_ssl_ticket_free().)
- Parameters
ctx – Context to be initialized
-
int mbedtls_ssl_ticket_setup(mbedtls_ssl_ticket_context *ctx, int (*f_rng)(void*, unsigned char*, size_t), void *p_rng, mbedtls_cipher_type_t cipher, uint32_t lifetime)
Prepare context to be actually used.
Note
It is highly recommended to select a cipher that is at least as strong as the strongest ciphersuite supported. Usually that means a 256-bit key.
Note
The lifetime of the keys is twice the lifetime of tickets. It is recommended to pick a reasonable lifetime so as not to negate the benefits of forward secrecy.
- Parameters
ctx – Context to be set up
f_rng – RNG callback function
p_rng – RNG callback context
cipher – AEAD cipher to use for ticket protection. Recommended value: MBEDTLS_CIPHER_AES_256_GCM.
lifetime – Tickets lifetime in seconds Recommended value: 86400 (one day).
- Returns
0 if successful, or a specific MBEDTLS_ERR_XXX error code
-
void mbedtls_ssl_ticket_free(mbedtls_ssl_ticket_context *ctx)
Free a context’s content and zeroize it.
- Parameters
ctx – Context to be cleaned up
Variables
-
mbedtls_ssl_ticket_write_t mbedtls_ssl_ticket_write
Implementation of the ticket write callback.
Note
See
mbedtls_ssl_ticket_write_tfor description
-
mbedtls_ssl_ticket_parse_t mbedtls_ssl_ticket_parse
Implementation of the ticket parse callback.
Note
See
mbedtls_ssl_ticket_parse_tfor description
-
struct mbedtls_ssl_ticket_key
- #include <ssl_ticket.h>
Information for session ticket protection.
Public Members
-
unsigned char name[4]
random key identifier
-
uint32_t generation_time
key generation timestamp (seconds)
-
mbedtls_cipher_context_t ctx
context for auth enc/decryption
-
unsigned char name[4]
-
struct mbedtls_ssl_ticket_context
- #include <ssl_ticket.h>
Context for session ticket handling functions.
Public Members
-
mbedtls_ssl_ticket_key keys[2]
ticket protection keys
-
unsigned char active
index of the currently active key
-
uint32_t ticket_lifetime
lifetime of tickets in seconds
-
int (*f_rng)(void*, unsigned char*, size_t)
Callback for getting (pseudo-)random numbers
-
void *p_rng
context for the RNG function
-
mbedtls_ssl_ticket_key keys[2]