X-Git-Url: https://www.tinc-vpn.org/git/browse?a=blobdiff_plain;f=src%2Fsptps.h;h=1fead07a0a4391a8a36916cddd1fa2bce3a30410;hb=cc3c69c892b0dad9a6ece0a0f4ccd429a22fcbff;hp=b1026d535e5fb97f4371865663c856e6f8016fe5;hpb=3d75dbc0880484ff6d2f689a9b981def3cd75b5e;p=tinc diff --git a/src/sptps.h b/src/sptps.h index b1026d53..1fead07a 100644 --- a/src/sptps.h +++ b/src/sptps.h @@ -1,6 +1,6 @@ /* sptps.h -- Simple Peer-to-Peer Security - Copyright (C) 2011 Guus Sliepen , + Copyright (C) 2011-2013 Guus Sliepen , This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by @@ -17,6 +17,9 @@ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. */ +#ifndef __SPTPS_H__ +#define __SPTPS_H__ + #include "system.h" #include "cipher.h" @@ -24,25 +27,41 @@ #include "ecdh.h" #include "ecdsa.h" -#define STATE_FIRST_KEX 0 // Waiting for peer's ECDHE pubkey -#define STATE_NORMAL 1 -#define STATE_WAIT_KEX 2 // Waiting for peer's ECDHE pubkey -#define STATE_WAIT_ACK 3 // Waiting for peer's acknowledgement of pubkey reception +#define SPTPS_VERSION 0 + +// Record types +#define SPTPS_HANDSHAKE 128 // Key exchange and authentication +#define SPTPS_ALERT 129 // Warning or error messages +#define SPTPS_CLOSE 130 // Application closed the connection -typedef bool (*send_data_t)(void *handle, const char *data, size_t len); +// Key exchange states +#define SPTPS_KEX 0 // Waiting for the first Key EXchange record +#define SPTPS_SECONDARY_KEX 1 // Ready to receive a secondary Key EXchange record +#define SPTPS_SIG 2 // Waiting for a SIGnature record +#define SPTPS_ACK 3 // Waiting for an ACKnowledgement record + +typedef bool (*send_data_t)(void *handle, uint8_t type, const char *data, size_t len); typedef bool (*receive_record_t)(void *handle, uint8_t type, const char *data, uint16_t len); typedef struct sptps { bool initiator; + bool datagram; int state; char *inbuf; size_t buflen; + uint16_t reclen; + bool instate; cipher_t incipher; digest_t indigest; uint32_t inseqno; + uint32_t received; + unsigned int replaywin; + unsigned int farfuture; + char *late; + bool outstate; cipher_t outcipher; digest_t outdigest; uint32_t outseqno; @@ -51,7 +70,8 @@ typedef struct sptps { ecdsa_t hiskey; ecdh_t ecdh; - char *myrandom; + char *mykex; + char *hiskex; char *key; char *label; size_t labellen; @@ -61,7 +81,15 @@ typedef struct sptps { receive_record_t receive_record; } sptps_t; -extern bool start_sptps(sptps_t *s, void *handle, bool initiator, ecdsa_t mykey, ecdsa_t hiskey, const char *label, size_t labellen, send_data_t send_data, receive_record_t receive_record); -extern bool stop_sptps(sptps_t *s); -extern bool send_record(sptps_t *s, uint8_t type, const char *data, uint16_t len); -extern bool receive_data(sptps_t *s, const char *data, size_t len); +extern unsigned int sptps_replaywin; +extern void sptps_log_quiet(sptps_t *s, int s_errno, const char *format, va_list ap); +extern void sptps_log_stderr(sptps_t *s, int s_errno, const char *format, va_list ap); +extern void (*sptps_log)(sptps_t *s, int s_errno, const char *format, va_list ap); +extern bool sptps_start(sptps_t *s, void *handle, bool initiator, bool datagram, ecdsa_t mykey, ecdsa_t hiskey, const char *label, size_t labellen, send_data_t send_data, receive_record_t receive_record); +extern bool sptps_stop(sptps_t *s); +extern bool sptps_send_record(sptps_t *s, uint8_t type, const char *data, uint16_t len); +extern bool sptps_receive_data(sptps_t *s, const char *data, size_t len); +extern bool sptps_force_kex(sptps_t *s); +extern bool sptps_verify_datagram(sptps_t *s, const char *data, size_t len); + +#endif