Add support for integrity-only cipher suites for TLS v1.3
authorRajeev Ranjan <ranjan.rajeev@siemens.com>
Fri, 1 Dec 2023 11:47:07 +0000 (12:47 +0100)
committerTomas Mraz <tomas@openssl.org>
Tue, 14 May 2024 13:39:15 +0000 (15:39 +0200)
commitb6a5e801679663c13875cf6e18f475f8700d72a9
tree437ddfdbc1fbcf49974cc2daa89bfeadd68876ae
parent61f32392dd67d47018ce46f427339e7191426e45
Add support for integrity-only cipher suites for TLS v1.3

- add test vectors for tls1_3 integrity-only ciphers
- recmethod_local.h: add new member for MAC
- tls13_meth.c: add MAC only to tls 1.3
- tls13_enc.c: extend function to add MAC only
- ssl_local.h: add ssl_cipher_get_evp_md_mac()
- s3_lib.c: add the new ciphers and add #ifndef OPENSSL_NO_INTEGRITY_ONLY_CIPHERS
- ssl_ciph.c : add ssl_cipher_get_evp_md_mac() and use it
- tls13secretstest.c: add dummy test function
- Configure: add integrity-only-ciphers option
- document the new ciphers

Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/22903)
22 files changed:
.github/workflows/run-checker-merge.yml
CHANGES.md
Configure
INSTALL.md
doc/man1/openssl-ciphers.pod.in
doc/man3/SSL_CTX_set_cipher_list.pod
include/openssl/tls1.h
ssl/record/methods/recmethod_local.h
ssl/record/methods/tls13_meth.c
ssl/record/methods/tls_common.c
ssl/s3_lib.c
ssl/ssl_ciph.c
ssl/ssl_local.h
ssl/t1_trce.c
ssl/tls13_enc.c
test/ciphername_test.c
test/evp_libctx_test.c
test/evp_test.c
test/helpers/ssltestlib.h
test/quicapitest.c
test/sslapitest.c
test/tls13secretstest.c