suricata
app-layer-ssl.c
Go to the documentation of this file.
1 /* Copyright (C) 2007-2024 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 /**
19  * \file
20  *
21  * \author Anoop Saldanha <anoopsaldanha@gmail.com>
22  * \author Pierre Chifflier <pierre.chifflier@ssi.gouv.fr>
23  * \author Mats Klepsland <mats.klepsland@gmail.com>
24  *
25  */
26 
27 #include "suricata-common.h"
28 #include "decode.h"
29 
30 #include "app-layer.h"
31 #include "app-layer-detect-proto.h"
32 #include "app-layer-protos.h"
33 #include "app-layer-parser.h"
34 #include "app-layer-frames.h"
35 #include "app-layer-events.h"
36 #include "app-layer-ssl.h"
37 
38 #include "conf.h"
39 
40 #include "feature.h"
41 
42 #include "util-debug.h"
43 #include "util-ja3.h"
44 #include "util-enum.h"
45 #include "util-validate.h"
46 
47 static SCEnumCharMap tls_state_client_table[] = {
48  {
49  "client_in_progress",
51  },
52  {
53  "client_hello_done",
55  },
56  {
57  "client_cert_done",
59  },
60  {
61  "client_handshake_done",
63  },
64  {
65  "client_finished",
67  },
68  { NULL, -1 },
69 };
70 
71 static SCEnumCharMap tls_state_server_table[] = {
72  {
73  "server_in_progress",
75  },
76  {
77  "server_hello",
79  },
80  {
81  "server_cert_done",
83  },
84  {
85  "server_hello_done",
87  },
88  {
89  "server_handshake_done",
91  },
92  {
93  "server_finished",
95  },
96  { NULL, -1 },
97 };
98 
100  {
101  "pdu",
103  },
104  {
105  "hdr",
107  },
108  {
109  "data",
111  },
112  {
113  "alert",
115  },
116  {
117  "heartbeat",
119  },
120  {
121  "ssl2.hdr",
123  },
124  {
125  "ssl2.pdu",
127  },
128  { NULL, -1 },
129 };
130 
132  /* TLS protocol messages */
133  { "INVALID_SSLV2_HEADER", TLS_DECODER_EVENT_INVALID_SSLV2_HEADER },
134  { "INVALID_TLS_HEADER", TLS_DECODER_EVENT_INVALID_TLS_HEADER },
135  { "INVALID_RECORD_VERSION", TLS_DECODER_EVENT_INVALID_RECORD_VERSION },
136  { "INVALID_RECORD_TYPE", TLS_DECODER_EVENT_INVALID_RECORD_TYPE },
137  { "INVALID_RECORD_LENGTH", TLS_DECODER_EVENT_INVALID_RECORD_LENGTH },
138  { "INVALID_HANDSHAKE_MESSAGE", TLS_DECODER_EVENT_INVALID_HANDSHAKE_MESSAGE },
139  { "HEARTBEAT_MESSAGE", TLS_DECODER_EVENT_HEARTBEAT },
140  { "INVALID_HEARTBEAT_MESSAGE", TLS_DECODER_EVENT_INVALID_HEARTBEAT },
141  { "OVERFLOW_HEARTBEAT_MESSAGE", TLS_DECODER_EVENT_OVERFLOW_HEARTBEAT },
142  { "DATALEAK_HEARTBEAT_MISMATCH", TLS_DECODER_EVENT_DATALEAK_HEARTBEAT_MISMATCH },
143  { "HANDSHAKE_INVALID_LENGTH", TLS_DECODER_EVENT_HANDSHAKE_INVALID_LENGTH },
144  { "MULTIPLE_SNI_EXTENSIONS", TLS_DECODER_EVENT_MULTIPLE_SNI_EXTENSIONS },
145  { "INVALID_SNI_TYPE", TLS_DECODER_EVENT_INVALID_SNI_TYPE },
146  { "INVALID_SNI_LENGTH", TLS_DECODER_EVENT_INVALID_SNI_LENGTH },
147  { "TOO_MANY_RECORDS_IN_PACKET", TLS_DECODER_EVENT_TOO_MANY_RECORDS_IN_PACKET },
148  { "INVALID_ALERT_MESSAGE", TLS_DECODER_EVENT_INVALID_ALERT },
149  /* certificate decoding messages */
150  { "INVALID_CERTIFICATE", TLS_DECODER_EVENT_INVALID_CERTIFICATE },
151  { "CERTIFICATE_INVALID_LENGTH", TLS_DECODER_EVENT_CERTIFICATE_INVALID_LENGTH },
152  { "CERTIFICATE_INVALID_VERSION", TLS_DECODER_EVENT_CERTIFICATE_INVALID_VERSION },
153  { "CERTIFICATE_INVALID_SERIAL", TLS_DECODER_EVENT_CERTIFICATE_INVALID_SERIAL },
154  { "CERTIFICATE_INVALID_ALGORITHMIDENTIFIER",
156  { "CERTIFICATE_INVALID_X509NAME", TLS_DECODER_EVENT_CERTIFICATE_INVALID_X509NAME },
157  { "CERTIFICATE_INVALID_DATE", TLS_DECODER_EVENT_CERTIFICATE_INVALID_DATE },
158  { "CERTIFICATE_INVALID_EXTENSIONS", TLS_DECODER_EVENT_CERTIFICATE_INVALID_EXTENSIONS },
159  { "CERTIFICATE_INVALID_DER", TLS_DECODER_EVENT_CERTIFICATE_INVALID_DER },
160  { "CERTIFICATE_INVALID_SUBJECT", TLS_DECODER_EVENT_CERTIFICATE_INVALID_SUBJECT },
161  { "CERTIFICATE_INVALID_ISSUER", TLS_DECODER_EVENT_CERTIFICATE_INVALID_ISSUER },
162  { "CERTIFICATE_INVALID_VALIDITY", TLS_DECODER_EVENT_CERTIFICATE_INVALID_VALIDITY },
163  { "ERROR_MESSAGE_ENCOUNTERED", TLS_DECODER_EVENT_ERROR_MSG_ENCOUNTERED },
164  { "TOO_MANY_SUBJECT_ALTERNATIVE_NAMES", TLS_DECODER_EVENT_TOO_MANY_SUBJECT_ALTERNATIVE_NAMES },
165  /* used as a generic error event */
166  { "INVALID_SSL_RECORD", TLS_DECODER_EVENT_INVALID_SSL_RECORD },
167  { NULL, -1 },
168 };
169 
170 enum {
171  /* X.509 error codes, returned by decoder
172  * THESE CONSTANTS MUST MATCH rust/src/x509/mod.rs ! */
182 
183  /* error getting data */
187 };
188 
189 /* JA3 and JA4 fingerprints are disabled by default */
190 #define SSL_CONFIG_DEFAULT_JA3 0
191 #ifdef HAVE_JA4
192 #define SSL_CONFIG_DEFAULT_JA4 0
193 #endif
194 
196  SSL_CNF_ENC_HANDLE_TRACK_ONLY = 0, /**< disable raw content, continue tracking */
197  SSL_CNF_ENC_HANDLE_BYPASS = 1, /**< skip processing of flow, bypass if possible */
198  SSL_CNF_ENC_HANDLE_FULL = 2, /**< handle fully like any other proto */
199 };
200 
201 typedef struct SslConfig_ {
203  /** dynamic setting for ja3 and ja4: can be enabled on demand if not
204  * explicitly disabled. */
205  SC_ATOMIC_DECLARE(int, enable_ja3);
206  bool disable_ja3; /**< ja3 explicitly disabled. Don't enable on demand. */
207  SC_ATOMIC_DECLARE(int, enable_ja4);
208  bool disable_ja4; /**< ja4 explicitly disabled. Don't enable on demand. */
210 
212 
213 /* SSLv3 record types */
214 #define SSLV3_CHANGE_CIPHER_SPEC 20
215 #define SSLV3_ALERT_PROTOCOL 21
216 #define SSLV3_HANDSHAKE_PROTOCOL 22
217 #define SSLV3_APPLICATION_PROTOCOL 23
218 #define SSLV3_HEARTBEAT_PROTOCOL 24
219 
220 /* SSLv3 handshake protocol types */
221 #define SSLV3_HS_HELLO_REQUEST 0
222 #define SSLV3_HS_CLIENT_HELLO 1
223 #define SSLV3_HS_SERVER_HELLO 2
224 #define SSLV3_HS_NEW_SESSION_TICKET 4
225 #define SSLV3_HS_CERTIFICATE 11
226 #define SSLV3_HS_SERVER_KEY_EXCHANGE 12
227 #define SSLV3_HS_CERTIFICATE_REQUEST 13
228 #define SSLV3_HS_SERVER_HELLO_DONE 14
229 #define SSLV3_HS_CERTIFICATE_VERIFY 15
230 #define SSLV3_HS_CLIENT_KEY_EXCHANGE 16
231 #define SSLV3_HS_FINISHED 20
232 #define SSLV3_HS_CERTIFICATE_URL 21
233 #define SSLV3_HS_CERTIFICATE_STATUS 22
234 
235 /* SSLv2 protocol message types */
236 #define SSLV2_MT_ERROR 0
237 #define SSLV2_MT_CLIENT_HELLO 1
238 #define SSLV2_MT_CLIENT_MASTER_KEY 2
239 #define SSLV2_MT_CLIENT_FINISHED 3
240 #define SSLV2_MT_SERVER_HELLO 4
241 #define SSLV2_MT_SERVER_VERIFY 5
242 #define SSLV2_MT_SERVER_FINISHED 6
243 #define SSLV2_MT_REQUEST_CERTIFICATE 7
244 #define SSLV2_MT_CLIENT_CERTIFICATE 8
245 
246 #define SSLV3_RECORD_HDR_LEN 5
247 /** max length according to RFC 5246 6.2.2 is 2^14 + 1024 */
248 #define SSLV3_RECORD_MAX_LEN ((1 << 14) + 1024)
249 
250 #define SSLV3_CLIENT_HELLO_VERSION_LEN 2
251 #define SSLV3_CLIENT_HELLO_RANDOM_LEN 32
252 
253 /* TLS heartbeat protocol types */
254 #define TLS_HB_REQUEST 1
255 #define TLS_HB_RESPONSE 2
256 
257 #define SSL_RECORD_MINIMUM_LENGTH 6
258 
259 #define SHA1_STRING_LENGTH 60
260 
261 #define HAS_SPACE(n) ((uint64_t)(input - initial_input) + (uint64_t)(n) <= (uint64_t)(input_len))
262 
264  int retval; // nr bytes consumed from input, or < 0 on error
265  uint32_t needed; // more bytes needed
266 };
267 #define SSL_DECODER_ERROR(e) \
268  (struct SSLDecoderResult) \
269  { \
270  (e), 0 \
271  }
272 #define SSL_DECODER_OK(c) \
273  (struct SSLDecoderResult) \
274  { \
275  (uint32_t)(c), 0 \
276  }
277 #define SSL_DECODER_INCOMPLETE(c, n) \
278  (struct SSLDecoderResult) \
279  { \
280  (uint32_t)(c), (n) \
281  }
282 
283 static inline int SafeMemcpy(void *dst, size_t dst_offset, size_t dst_size,
284  const void *src, size_t src_offset, size_t src_size, size_t src_tocopy) WARN_UNUSED;
285 
286 static inline int SafeMemcpy(void *dst, size_t dst_offset, size_t dst_size,
287  const void *src, size_t src_offset, size_t src_size, size_t src_tocopy)
288 {
289  DEBUG_VALIDATE_BUG_ON(dst_offset >= dst_size);
290  DEBUG_VALIDATE_BUG_ON(src_offset >= src_size);
291  DEBUG_VALIDATE_BUG_ON(src_tocopy > (src_size - src_offset));
292  DEBUG_VALIDATE_BUG_ON(src_tocopy > (dst_size - dst_offset));
293 
294  if (dst_offset < dst_size && src_offset < src_size &&
295  src_tocopy <= (src_size - src_offset) &&
296  src_tocopy <= (dst_size - dst_offset)) {
297  memcpy(dst + dst_offset, src + src_offset, src_tocopy);
298  return 0;
299  }
300  return -1;
301 }
302 
303 #ifdef DEBUG_VALIDATION
304 #define ValidateRecordState(connp) \
305  do { \
306  DEBUG_VALIDATE_BUG_ON(((connp)->record_length + SSLV3_RECORD_HDR_LEN) < \
307  (connp)->bytes_processed); \
308  } while(0);
309 #else
310 #define ValidateRecordState(...)
311 #endif
312 
313 #define SSLParserHSReset(connp) \
314  do { \
315  (connp)->handshake_type = 0; \
316  (connp)->message_length = 0; \
317  } while (0)
318 
319 #define SSLParserReset(state) \
320  do { \
321  SCLogDebug("resetting state"); \
322  (state)->curr_connp->bytes_processed = 0; \
323  SSLParserHSReset((state)->curr_connp); \
324  } while(0)
325 
326 #define SSLSetEvent(ssl_state, event) \
327  do { \
328  SCLogDebug("setting event %u", (event)); \
329  if ((ssl_state) == NULL) { \
330  SCLogDebug("could not set decoder event %u", event); \
331  } else { \
332  SCAppLayerDecoderEventsSetEventRaw(&(ssl_state)->tx_data.events, (event)); \
333  (ssl_state)->events++; \
334  } \
335  } while (0)
336 
337 static void *SSLGetTx(void *state, uint64_t tx_id)
338 {
339  SSLState *ssl_state = (SSLState *)state;
340  return ssl_state;
341 }
342 
343 static uint64_t SSLGetTxCnt(void *state)
344 {
345  /* single tx */
346  return 1;
347 }
348 
349 static void UpdateClientState(SSLState *ssl_state, enum TlsStateClient s)
350 {
351 #ifdef DEBUG
352  enum TlsStateClient old = ssl_state->client_state;
353 #endif
354  ssl_state->client_state = s;
355 #ifdef DEBUG
356  SCLogDebug("toserver: state updated to %u from %u", s, old);
357 #endif
358 }
359 
360 static void UpdateServerState(SSLState *ssl_state, enum TlsStateServer s)
361 {
362 #ifdef DEBUG
363  enum TlsStateServer old = ssl_state->server_state;
364 #endif
365  ssl_state->server_state = s;
366 #ifdef DEBUG
367  SCLogDebug("toclient: state updated to %u from %u", s, old);
368 #endif
369 }
370 
371 static int SSLGetAlstateProgress(void *tx, uint8_t direction)
372 {
373  SSLState *ssl_state = (SSLState *)tx;
374  if (direction & STREAM_TOCLIENT) {
375  return ssl_state->server_state;
376  } else {
377  return ssl_state->client_state;
378  }
379 }
380 
381 static AppLayerTxData *SSLGetTxData(void *vtx)
382 {
383  SSLState *ssl_state = (SSLState *)vtx;
384  return &ssl_state->tx_data;
385 }
386 
387 static AppLayerStateData *SSLGetStateData(void *vstate)
388 {
389  SSLState *ssl_state = (SSLState *)vstate;
390  return &ssl_state->state_data;
391 }
392 
393 static void TlsDecodeHSCertificateErrSetEvent(SSLState *ssl_state, uint32_t err)
394 {
395  switch(err) {
398  break;
399  case ERR_EXTRACT_ISSUER:
401  break;
402  case ERR_EXTRACT_SUBJECT:
404  break;
405  case ERR_INVALID_DER:
407  break;
410  break;
411  case ERR_INVALID_DATE:
413  break;
416  break;
419  break;
420  case ERR_INVALID_SERIAL:
422  break;
423  case ERR_INVALID_VERSION:
425  break;
426  case ERR_INVALID_LENGTH:
428  break;
430  default:
432  break;
433  }
434 }
435 
436 static inline int TlsDecodeHSCertificateFingerprint(
437  SSLStateConnp *connp, const uint8_t *input, uint32_t cert_len)
438 {
439  if (unlikely(connp->cert0_fingerprint != NULL))
440  return 0;
441 
443  if (connp->cert0_fingerprint == NULL)
444  return -1;
445 
446  uint8_t hash[SC_SHA1_LEN];
447  if (SCSha1HashBuffer(input, cert_len, hash, sizeof(hash)) == 1) {
448  SCToHex_sep(
449  (uint8_t *)connp->cert0_fingerprint, SHA1_STRING_LENGTH, ':', hash, SC_SHA1_LEN);
450  }
451  return 0;
452 }
453 
454 static inline int TlsDecodeHSCertificateAddCertToChain(
455  SSLStateConnp *connp, const uint8_t *input, uint32_t cert_len)
456 {
457  SSLCertsChain *cert = SCCalloc(1, sizeof(SSLCertsChain));
458  if (cert == NULL)
459  return -1;
460 
461  cert->cert_data = (uint8_t *)input;
462  cert->cert_len = cert_len;
463  TAILQ_INSERT_TAIL(&connp->certs, cert, next);
464 
465  return 0;
466 }
467 
468 static int TlsDecodeHSCertificate(SSLState *ssl_state, SSLStateConnp *connp,
469  const uint8_t *const initial_input, const uint32_t input_len, const int certn)
470 {
471  const uint8_t *input = (uint8_t *)initial_input;
472  uint32_t err_code = 0;
473  X509 *x509 = NULL;
474  int rc = 0;
475 
476  if (!(HAS_SPACE(3)))
477  goto invalid_cert;
478 
479  uint32_t cert_len = *input << 16 | *(input + 1) << 8 | *(input + 2);
480  input += 3;
481 
482  if (!(HAS_SPACE(cert_len)))
483  goto invalid_cert;
484 
485  /* only store fields from the first certificate in the chain */
486  if (certn == 0 && connp->cert0_subject == NULL && connp->cert0_issuerdn == NULL &&
487  connp->cert0_serial == NULL) {
488  x509 = SCX509Decode(input, cert_len, &err_code);
489  if (x509 == NULL) {
490  TlsDecodeHSCertificateErrSetEvent(ssl_state, err_code);
491  goto next;
492  }
493 
494  SCX509GetSubject(x509, &connp->cert0_subject, &connp->cert0_subject_len);
495  if (connp->cert0_subject == NULL) {
496  err_code = ERR_EXTRACT_SUBJECT;
497  goto error;
498  }
499 
500  SCX509GetIssuer(x509, &connp->cert0_issuerdn, &connp->cert0_issuerdn_len);
501  if (connp->cert0_issuerdn == NULL) {
502  err_code = ERR_EXTRACT_ISSUER;
503  goto error;
504  }
505 
506  connp->cert0_sans_num = SCX509GetSubjectAltNameLen(x509);
507  if (connp->cert0_sans_num == TLS_MAX_SAN) {
509  }
510  connp->cert0_sans = SCCalloc(connp->cert0_sans_num, sizeof(SSLSubjectAltName));
511  if (connp->cert0_sans == NULL) {
512  connp->cert0_sans_num = 0;
513  goto error;
514  }
515  for (uint16_t i = 0; i < connp->cert0_sans_num; i++) {
516  SCX509GetSubjectAltNameAt(
517  x509, i, &connp->cert0_sans[i].san, &connp->cert0_sans[i].san_len);
518  }
519 
520  SCX509GetSerial(x509, &connp->cert0_serial, &connp->cert0_serial_len);
521  if (connp->cert0_serial == NULL) {
522  err_code = ERR_INVALID_SERIAL;
523  goto error;
524  }
525 
526  rc = SCX509GetValidity(x509, &connp->cert0_not_before, &connp->cert0_not_after);
527  if (rc != 0) {
528  err_code = ERR_EXTRACT_VALIDITY;
529  goto error;
530  }
531 
532  SCX509Free(x509);
533  x509 = NULL;
534 
535  rc = TlsDecodeHSCertificateFingerprint(connp, input, cert_len);
536  if (rc != 0) {
537  SCLogDebug("TlsDecodeHSCertificateFingerprint failed with %d", rc);
538  goto error;
539  }
540  }
541 
542  rc = TlsDecodeHSCertificateAddCertToChain(connp, input, cert_len);
543  if (rc != 0) {
544  SCLogDebug("TlsDecodeHSCertificateAddCertToChain failed with %d", rc);
545  goto error;
546  }
547 
548 next:
549  input += cert_len;
550  return (int)(input - initial_input);
551 
552 error:
553  if (err_code != 0)
554  TlsDecodeHSCertificateErrSetEvent(ssl_state, err_code);
555  if (x509 != NULL)
556  SCX509Free(x509);
557 
558  return -1;
559 
560 invalid_cert:
561  SCLogDebug("TLS invalid certificate");
563  return -1;
564 }
565 
566 /** \internal
567  * \brief parse cert data in a certificate handshake message
568  * will be called with all data.
569  * \retval consumed bytes consumed or -1 on error
570  */
571 static int TlsDecodeHSCertificates(SSLState *ssl_state, SSLStateConnp *connp,
572  const uint8_t *const initial_input, const uint32_t input_len)
573 {
574  const uint8_t *input = (uint8_t *)initial_input;
575 
576  if (!(HAS_SPACE(3)))
577  return -1;
578 
579  const uint32_t cert_chain_len = *input << 16 | *(input + 1) << 8 | *(input + 2);
580  input += 3;
581 
582  if (!(HAS_SPACE(cert_chain_len)))
583  return -1;
584 
585  if (connp->certs_buffer != NULL) {
586  // TODO should we set an event here?
587  return -1;
588  }
589 
590  connp->certs_buffer = SCCalloc(1, cert_chain_len);
591  if (connp->certs_buffer == NULL) {
592  return -1;
593  }
594  connp->certs_buffer_size = cert_chain_len;
595  memcpy(connp->certs_buffer, input, cert_chain_len);
596 
597  int cert_cnt = 0;
598  uint32_t processed_len = 0;
599  /* coverity[tainted_data] */
600  while (processed_len < cert_chain_len) {
601  int rc = TlsDecodeHSCertificate(ssl_state, connp, connp->certs_buffer + processed_len,
602  connp->certs_buffer_size - processed_len, cert_cnt);
603  if (rc <= 0) { // 0 should be impossible, but lets be defensive
604  return -1;
605  }
606  DEBUG_VALIDATE_BUG_ON(processed_len + (uint32_t)rc > cert_chain_len);
607  if (processed_len + (uint32_t)rc > cert_chain_len) {
608  return -1;
609  }
610 
611  processed_len += (uint32_t)rc;
612  }
613 
614  return processed_len + 3;
615 }
616 
617 /**
618  * \inline
619  * \brief Check if value is GREASE.
620  *
621  * http://tools.ietf.org/html/draft-davidben-tls-grease-00
622  *
623  * \param value Value to check.
624  *
625  * \retval 1 if is GREASE.
626  * \retval 0 if not is GREASE.
627  */
628 static inline int TLSDecodeValueIsGREASE(const uint16_t value)
629 {
630  switch (value)
631  {
632  case 0x0a0a:
633  case 0x1a1a:
634  case 0x2a2a:
635  case 0x3a3a:
636  case 0x4a4a:
637  case 0x5a5a:
638  case 0x6a6a:
639  case 0x7a7a:
640  case 0x8a8a:
641  case 0x9a9a:
642  case 0xaaaa:
643  case 0xbaba:
644  case 0xcaca:
645  case 0xdada:
646  case 0xeaea:
647  case 0xfafa:
648  return 1;
649  default:
650  return 0;
651  }
652 }
653 
654 static inline int TLSDecodeHSHelloVersion(SSLState *ssl_state,
655  const uint8_t * const initial_input,
656  const uint32_t input_len)
657 {
658  uint8_t *input = (uint8_t *)initial_input;
659 
661  SCLogDebug("TLS handshake invalid length");
662  SSLSetEvent(ssl_state,
664  return -1;
665  }
666 
667  uint16_t version = (uint16_t)(*input << 8) | *(input + 1);
668  ssl_state->curr_connp->version = version;
669 
670  if (ssl_state->current_flags &
672  SCTLSHandshakeSetTLSVersion(ssl_state->curr_connp->hs, version);
673  }
674 
675  /* TLSv1.3 draft1 to draft21 use the version field as earlier TLS
676  versions, instead of using the supported versions extension. */
677  if ((ssl_state->current_flags & SSL_AL_FLAG_STATE_SERVER_HELLO) &&
678  ((ssl_state->curr_connp->version == TLS_VERSION_13) ||
679  (((ssl_state->curr_connp->version >> 8) & 0xff) == 0x7f))) {
680  ssl_state->flags |= SSL_AL_FLAG_LOG_WITHOUT_CERT;
681  }
682 
683  /* Catch some early TLSv1.3 draft implementations that does not conform
684  to the draft version. */
685  if ((ssl_state->curr_connp->version >= 0x7f01) &&
686  (ssl_state->curr_connp->version < 0x7f10)) {
687  ssl_state->curr_connp->version = TLS_VERSION_13_PRE_DRAFT16;
688  }
689 
690  /* TLSv1.3 drafts from draft1 to draft15 use 0x0304 (TLSv1.3) as the
691  version number, which makes it hard to accurately pinpoint the
692  exact draft version. */
693  else if (ssl_state->curr_connp->version == TLS_VERSION_13) {
694  ssl_state->curr_connp->version = TLS_VERSION_13_PRE_DRAFT16;
695  }
696 
697  if (SC_ATOMIC_GET(ssl_config.enable_ja3) && ssl_state->curr_connp->ja3_str == NULL) {
698  ssl_state->curr_connp->ja3_str = Ja3BufferInit();
699  if (ssl_state->curr_connp->ja3_str == NULL)
700  return -1;
701 
702  int rc = Ja3BufferAddValue(&ssl_state->curr_connp->ja3_str, version);
703  if (rc != 0)
704  return -1;
705  }
706 
708 
709  return (int)(input - initial_input);
710 }
711 
712 static inline int TLSDecodeHSHelloRandom(SSLState *ssl_state,
713  const uint8_t * const initial_input,
714  const uint32_t input_len)
715 {
716  uint8_t *input = (uint8_t *)initial_input;
717 
719  SCLogDebug("TLS handshake invalid length");
720  SSLSetEvent(ssl_state,
722  return -1;
723  }
724 
726  memcpy(ssl_state->server_connp.random, input, TLS_RANDOM_LEN);
727  ssl_state->flags |= TLS_TS_RANDOM_SET;
728  } else if (ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) {
729  memcpy(ssl_state->client_connp.random, input, TLS_RANDOM_LEN);
730  ssl_state->flags |= TLS_TC_RANDOM_SET;
731  }
732 
733  /* Skip random */
735 
736  return (int)(input - initial_input);
737 }
738 
739 static inline int TLSDecodeHSHelloSessionID(SSLState *ssl_state,
740  const uint8_t * const initial_input,
741  const uint32_t input_len)
742 {
743  uint8_t *input = (uint8_t *)initial_input;
744 
745  if (!(HAS_SPACE(1)))
746  goto invalid_length;
747 
748  uint8_t session_id_length = *input;
749  input += 1;
750 
751  if (!(HAS_SPACE(session_id_length)))
752  goto invalid_length;
753 
754  if (session_id_length != 0 && ssl_state->curr_connp->session_id == NULL) {
755  ssl_state->curr_connp->session_id = SCMalloc(session_id_length);
756 
757  if (unlikely(ssl_state->curr_connp->session_id == NULL)) {
758  return -1;
759  }
760 
761  if (SafeMemcpy(ssl_state->curr_connp->session_id, 0, session_id_length,
762  input, 0, input_len, session_id_length) != 0) {
763  return -1;
764  }
765  ssl_state->curr_connp->session_id_length = session_id_length;
766 
767  if ((ssl_state->current_flags & SSL_AL_FLAG_STATE_SERVER_HELLO) &&
768  ssl_state->client_connp.session_id != NULL &&
769  ssl_state->server_connp.session_id != NULL) {
770  if ((ssl_state->client_connp.session_id_length ==
771  ssl_state->server_connp.session_id_length) &&
772  (memcmp(ssl_state->server_connp.session_id,
773  ssl_state->client_connp.session_id, session_id_length) == 0)) {
774  ssl_state->flags |= SSL_AL_FLAG_SESSION_RESUMED;
775  }
776  }
777  }
778 
779  input += session_id_length;
780 
781  return (int)(input - initial_input);
782 
783 invalid_length:
784  SCLogDebug("TLS handshake invalid length");
785  SSLSetEvent(ssl_state,
787  return -1;
788 }
789 
790 static inline int TLSDecodeHSHelloCipherSuites(SSLState *ssl_state,
791  const uint8_t * const initial_input,
792  const uint32_t input_len)
793 {
794  const uint8_t *input = initial_input;
795 
796  if (!(HAS_SPACE(2)))
797  goto invalid_length;
798 
799  uint16_t cipher_suites_length;
800 
802  cipher_suites_length = 2;
803  } else if (ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) {
804  cipher_suites_length = (uint16_t)(*input << 8) | *(input + 1);
805  input += 2;
806  } else {
807  return -1;
808  }
809 
810  if (!(HAS_SPACE(cipher_suites_length)))
811  goto invalid_length;
812 
813  /* Cipher suites length should always be divisible by 2 */
814  if ((cipher_suites_length % 2) != 0) {
815  goto invalid_length;
816  }
817 
818  const bool enable_ja3 =
819  SC_ATOMIC_GET(ssl_config.enable_ja3) && ssl_state->curr_connp->ja3_hash == NULL;
820 
821  JA3Buffer *ja3_cipher_suites = NULL;
822 
823  if (enable_ja3) {
824  ja3_cipher_suites = Ja3BufferInit();
825  if (ja3_cipher_suites == NULL)
826  return -1;
827  }
828 
829  uint16_t processed_len = 0;
830  /* coverity[tainted_data] */
831  while (processed_len < cipher_suites_length) {
832  if (!(HAS_SPACE(2))) {
833  if (enable_ja3) {
834  Ja3BufferFree(&ja3_cipher_suites);
835  }
836  goto invalid_length;
837  }
838 
839  uint16_t cipher_suite = (uint16_t)(*input << 8) | *(input + 1);
840  input += 2;
841 
842  if (TLSDecodeValueIsGREASE(cipher_suite) != 1) {
843  if (ssl_state->current_flags &
845  SCTLSHandshakeAddCipher(ssl_state->curr_connp->hs, cipher_suite);
846  }
847  if (enable_ja3) {
848  int rc = Ja3BufferAddValue(&ja3_cipher_suites, cipher_suite);
849  if (rc != 0) {
850  return -1;
851  }
852  }
853  }
854  processed_len += 2;
855  }
856 
857  if (enable_ja3) {
858  int rc = Ja3BufferAppendBuffer(&ssl_state->curr_connp->ja3_str, &ja3_cipher_suites);
859  if (rc == -1) {
860  return -1;
861  }
862  }
863 
864  return (int)(input - initial_input);
865 
866 invalid_length:
867  SCLogDebug("TLS handshake invalid length");
868  SSLSetEvent(ssl_state,
870  return -1;
871 }
872 
873 static inline int TLSDecodeHSHelloCompressionMethods(SSLState *ssl_state,
874  const uint8_t * const initial_input,
875  const uint32_t input_len)
876 {
877  const uint8_t *input = initial_input;
878 
879  if (!(HAS_SPACE(1)))
880  goto invalid_length;
881 
882  /* Skip compression methods */
884  input += 1;
885  } else {
886  uint8_t compression_methods_length = *input;
887  input += 1;
888 
889  if (!(HAS_SPACE(compression_methods_length)))
890  goto invalid_length;
891 
892  input += compression_methods_length;
893  }
894 
895  return (int)(input - initial_input);
896 
897 invalid_length:
898  SCLogDebug("TLS handshake invalid_length");
899  SSLSetEvent(ssl_state,
901  return -1;
902 }
903 
904 static inline int TLSDecodeHSHelloExtensionSni(SSLState *ssl_state,
905  const uint8_t * const initial_input,
906  const uint32_t input_len)
907 {
908  uint8_t *input = (uint8_t *)initial_input;
909 
910  /* Empty extension */
911  if (input_len == 0)
912  return 0;
913 
914  if (!(HAS_SPACE(2)))
915  goto invalid_length;
916 
917  /* Skip sni_list_length */
918  input += 2;
919 
920  if (!(HAS_SPACE(1)))
921  goto invalid_length;
922 
923  uint8_t sni_type = *input;
924  input += 1;
925 
926  /* Currently the only type allowed is host_name
927  (RFC6066 section 3). */
928  if (sni_type != SSL_SNI_TYPE_HOST_NAME) {
929  SCLogDebug("Unknown SNI type");
930  SSLSetEvent(ssl_state,
932  return -1;
933  }
934 
935  if (!(HAS_SPACE(2)))
936  goto invalid_length;
937 
938  uint16_t sni_len = (uint16_t)(*input << 8) | *(input + 1);
939  input += 2;
940 
941  /* host_name contains the fully qualified domain name,
942  and should therefore be limited by the maximum domain
943  name length. */
944  if (!(HAS_SPACE(sni_len)) || sni_len > 255 || sni_len == 0) {
945  SSLSetEvent(ssl_state,
947  return -1;
948  }
949 
950  /* There must not be more than one extension of the same
951  type (RFC5246 section 7.4.1.4). */
952  if (ssl_state->curr_connp->sni) {
953  SCLogDebug("Multiple SNI extensions");
954  SSLSetEvent(ssl_state,
956  input += sni_len;
957  return (int)(input - initial_input);
958  }
959 
960  ssl_state->curr_connp->sni_len = sni_len;
961  ssl_state->curr_connp->sni = SCMalloc(sni_len);
962  if (unlikely(ssl_state->curr_connp->sni == NULL))
963  return -1;
964 
965  const size_t consumed = input - initial_input;
966  if (SafeMemcpy(ssl_state->curr_connp->sni, 0, sni_len, initial_input, consumed, input_len,
967  sni_len) != 0) {
968  SCFree(ssl_state->curr_connp->sni);
969  ssl_state->curr_connp->sni = NULL;
970  return -1;
971  }
972  input += sni_len;
973 
974  return (int)(input - initial_input);
975 
976 invalid_length:
977  SCLogDebug("TLS handshake invalid length");
978  SSLSetEvent(ssl_state,
980 
981 
982  return -1;
983 }
984 
985 static inline int TLSDecodeHSHelloExtensionSupportedVersions(SSLState *ssl_state,
986  const uint8_t * const initial_input,
987  const uint32_t input_len)
988 {
989  const uint8_t *input = initial_input;
990 
991  /* Empty extension */
992  if (input_len == 0)
993  return 0;
994 
996  if (!(HAS_SPACE(1)))
997  goto invalid_length;
998 
999  uint8_t supported_ver_len = *input;
1000  input += 1;
1001 
1002  if (supported_ver_len < 2)
1003  goto invalid_length;
1004 
1005  if (!(HAS_SPACE(supported_ver_len)))
1006  goto invalid_length;
1007 
1008  /* Use the first (and preferred) valid version as client version,
1009  * skip over GREASE and other possible noise. */
1010  uint16_t i = 0;
1011  while (i + 1 < (uint16_t)supported_ver_len) {
1012  uint16_t ver = (uint16_t)(input[i] << 8) | input[i + 1];
1013  if (TLSVersionValid(ver)) {
1014  ssl_state->curr_connp->version = ver;
1015  SCTLSHandshakeSetTLSVersion(ssl_state->curr_connp->hs, ver);
1016  break;
1017  }
1018  i += 2;
1019  }
1020 
1021  /* Set a flag to indicate that we have seen this extension */
1023 
1024  input += supported_ver_len;
1025  }
1026  else if (ssl_state->current_flags & SSL_AL_FLAG_STATE_SERVER_HELLO) {
1027  if (!(HAS_SPACE(2)))
1028  goto invalid_length;
1029 
1030  uint16_t ver = (uint16_t)(*input << 8) | *(input + 1);
1031 
1032  if ((ssl_state->flags & SSL_AL_FLAG_CH_VERSION_EXTENSION) &&
1033  (ver > TLS_VERSION_12)) {
1034  ssl_state->flags |= SSL_AL_FLAG_LOG_WITHOUT_CERT;
1035  }
1036 
1037  ssl_state->curr_connp->version = ver;
1038  input += 2;
1039  }
1040 
1041  return (int)(input - initial_input);
1042 
1043 invalid_length:
1044  SCLogDebug("TLS handshake invalid length");
1045  SSLSetEvent(ssl_state,
1047 
1048  return -1;
1049 }
1050 
1051 static inline int TLSDecodeHSHelloExtensionEllipticCurves(SSLState *ssl_state,
1052  const uint8_t *const initial_input, const uint32_t input_len,
1053  JA3Buffer **ja3_elliptic_curves)
1054 {
1055  const uint8_t *input = initial_input;
1056 
1057  /* Empty extension */
1058  if (input_len == 0)
1059  return 0;
1060 
1061  if (!(HAS_SPACE(2)))
1062  goto invalid_length;
1063 
1064  uint16_t elliptic_curves_len = (uint16_t)(*input << 8) | *(input + 1);
1065  input += 2;
1066 
1067  if (!(HAS_SPACE(elliptic_curves_len)))
1068  goto invalid_length;
1069 
1070  if ((ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) &&
1071  *ja3_elliptic_curves != NULL) {
1072  uint16_t ec_processed_len = 0;
1073  /* coverity[tainted_data] */
1074  while (ec_processed_len < elliptic_curves_len)
1075  {
1076  if (!(HAS_SPACE(2)))
1077  goto invalid_length;
1078 
1079  uint16_t elliptic_curve = (uint16_t)(*input << 8) | *(input + 1);
1080  input += 2;
1081 
1082  if (TLSDecodeValueIsGREASE(elliptic_curve) != 1) {
1083  int rc = Ja3BufferAddValue(ja3_elliptic_curves, elliptic_curve);
1084  if (rc != 0)
1085  return -1;
1086  }
1087 
1088  ec_processed_len += 2;
1089  }
1090 
1091  } else {
1092  /* Skip elliptic curves */
1093  input += elliptic_curves_len;
1094  }
1095 
1096  return (int)(input - initial_input);
1097 
1098 invalid_length:
1099  SCLogDebug("TLS handshake invalid length");
1100  SSLSetEvent(ssl_state,
1102 
1103  return -1;
1104 }
1105 
1106 static inline int TLSDecodeHSHelloExtensionEllipticCurvePF(SSLState *ssl_state,
1107  const uint8_t *const initial_input, const uint32_t input_len,
1108  JA3Buffer **ja3_elliptic_curves_pf)
1109 {
1110  const uint8_t *input = initial_input;
1111 
1112  /* Empty extension */
1113  if (input_len == 0)
1114  return 0;
1115 
1116  if (!(HAS_SPACE(1)))
1117  goto invalid_length;
1118 
1119  uint8_t ec_pf_len = *input;
1120  input += 1;
1121 
1122  if (!(HAS_SPACE(ec_pf_len)))
1123  goto invalid_length;
1124 
1125  if ((ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) &&
1126  *ja3_elliptic_curves_pf != NULL) {
1127  uint8_t ec_pf_processed_len = 0;
1128  /* coverity[tainted_data] */
1129  while (ec_pf_processed_len < ec_pf_len)
1130  {
1131  uint8_t elliptic_curve_pf = *input;
1132  input += 1;
1133 
1134  if (TLSDecodeValueIsGREASE(elliptic_curve_pf) != 1) {
1135  int rc = Ja3BufferAddValue(ja3_elliptic_curves_pf, elliptic_curve_pf);
1136  if (rc != 0)
1137  return -1;
1138  }
1139 
1140  ec_pf_processed_len += 1;
1141  }
1142 
1143  } else {
1144  /* Skip elliptic curve point formats */
1145  input += ec_pf_len;
1146  }
1147 
1148  return (int)(input - initial_input);
1149 
1150 invalid_length:
1151  SCLogDebug("TLS handshake invalid length");
1152  SSLSetEvent(ssl_state,
1154 
1155  return -1;
1156 }
1157 
1158 static inline int TLSDecodeHSHelloExtensionSigAlgorithms(
1159  SSLState *ssl_state, const uint8_t *const initial_input, const uint32_t input_len)
1160 {
1161  const uint8_t *input = initial_input;
1162 
1163  /* Empty extension */
1164  if (input_len == 0)
1165  return 0;
1166 
1167  if (!(HAS_SPACE(2)))
1168  goto invalid_length;
1169 
1170  uint16_t sigalgo_len = (uint16_t)(*input << 8) | *(input + 1);
1171  input += 2;
1172 
1173  /* Signature algorithms length should always be divisible by 2 */
1174  if ((sigalgo_len % 2) != 0) {
1175  goto invalid_length;
1176  }
1177 
1178  if (!(HAS_SPACE(sigalgo_len)))
1179  goto invalid_length;
1180 
1181  if (ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) {
1182  uint16_t sigalgo_processed_len = 0;
1183  while (sigalgo_processed_len < sigalgo_len) {
1184  uint16_t sigalgo = (uint16_t)(*input << 8) | *(input + 1);
1185  input += 2;
1186  sigalgo_processed_len += 2;
1187 
1188  SCTLSHandshakeAddSigAlgo(ssl_state->curr_connp->hs, sigalgo);
1189  }
1190  } else {
1191  /* Skip signature algorithms */
1192  input += sigalgo_len;
1193  }
1194 
1195  return (int)(input - initial_input);
1196 
1197 invalid_length:
1198  SCLogDebug("Signature algorithm list invalid length");
1200 
1201  return -1;
1202 }
1203 
1204 static inline int TLSDecodeHSHelloExtensionALPN(
1205  SSLState *ssl_state, const uint8_t *const initial_input, const uint32_t input_len)
1206 {
1207  const uint8_t *input = initial_input;
1208 
1209  /* Empty extension */
1210  if (input_len == 0)
1211  return 0;
1212 
1213  if (!(HAS_SPACE(2)))
1214  goto invalid_length;
1215 
1216  uint16_t alpn_len = (uint16_t)(*input << 8) | *(input + 1);
1217  input += 2;
1218 
1219  if (!(HAS_SPACE(alpn_len)))
1220  goto invalid_length;
1221 
1222  /* We use 32 bits here to avoid potentially overflowing a value that
1223  needs to be compared to an unsigned 16-bit value. */
1224  uint32_t alpn_processed_len = 0;
1225  while (alpn_processed_len < alpn_len) {
1226  uint8_t protolen = *input;
1227  input += 1;
1228  alpn_processed_len += 1;
1229 
1230  if (!(HAS_SPACE(protolen)))
1231  goto invalid_length;
1232 
1233  /* Check if reading another protolen bytes would exceed the
1234  overall ALPN length; if so, skip and continue */
1235  if (alpn_processed_len + protolen > ((uint32_t)alpn_len)) {
1236  input += alpn_len - alpn_processed_len;
1237  break;
1238  }
1239  SCTLSHandshakeAddALPN(ssl_state->curr_connp->hs, (const char *)input, protolen);
1240 
1241  alpn_processed_len += protolen;
1242  input += protolen;
1243  }
1244 
1245  return (int)(input - initial_input);
1246 
1247 invalid_length:
1248  SCLogDebug("ALPN list invalid length");
1250 
1251  return -1;
1252 }
1253 
1254 static inline int TLSDecodeHSHelloExtensions(SSLState *ssl_state,
1255  const uint8_t * const initial_input,
1256  const uint32_t input_len)
1257 {
1258  const uint8_t *input = initial_input;
1259 
1260  int ret;
1261  int rc;
1262  // if ja3_hash is already computed, do not use new hello to augment ja3_str
1263  const bool ja3 =
1264  (SC_ATOMIC_GET(ssl_config.enable_ja3) == 1) && ssl_state->curr_connp->ja3_hash == NULL;
1265 
1266  JA3Buffer *ja3_extensions = NULL;
1267  JA3Buffer *ja3_elliptic_curves = NULL;
1268  JA3Buffer *ja3_elliptic_curves_pf = NULL;
1269 
1270  if (ja3) {
1271  ja3_extensions = Ja3BufferInit();
1272  if (ja3_extensions == NULL)
1273  goto error;
1274 
1275  if (ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) {
1276  ja3_elliptic_curves = Ja3BufferInit();
1277  if (ja3_elliptic_curves == NULL)
1278  goto error;
1279 
1280  ja3_elliptic_curves_pf = Ja3BufferInit();
1281  if (ja3_elliptic_curves_pf == NULL)
1282  goto error;
1283  }
1284  }
1285 
1286  /* Extensions are optional (RFC5246 section 7.4.1.2) */
1287  if (!(HAS_SPACE(2)))
1288  goto end;
1289 
1290  uint16_t extensions_len = (uint16_t)(*input << 8) | *(input + 1);
1291  input += 2;
1292 
1293  if (!(HAS_SPACE(extensions_len)))
1294  goto invalid_length;
1295 
1296  uint32_t processed_len = 0;
1297  /* coverity[tainted_data] */
1298  while (processed_len < (uint32_t)extensions_len) {
1299  if (!(HAS_SPACE(2)))
1300  goto invalid_length;
1301 
1302  uint16_t ext_type = (uint16_t)(*input << 8) | *(input + 1);
1303  input += 2;
1304 
1305  if (!(HAS_SPACE(2)))
1306  goto invalid_length;
1307 
1308  uint16_t ext_len = (uint16_t)(*input << 8) | *(input + 1);
1309  input += 2;
1310 
1311  if (!(HAS_SPACE(ext_len)))
1312  goto invalid_length;
1313 
1314  if (processed_len + 4UL + (uint32_t)ext_len > (uint32_t)extensions_len)
1315  goto invalid_length;
1316 
1317  switch (ext_type) {
1318  case SSL_EXTENSION_SNI:
1319  {
1320  /* coverity[tainted_data] */
1321  ret = TLSDecodeHSHelloExtensionSni(ssl_state, input,
1322  ext_len);
1323  if (ret < 0)
1324  goto end;
1325 
1326  input += ext_len;
1327 
1328  break;
1329  }
1330 
1332  {
1333  /* coverity[tainted_data] */
1334  ret = TLSDecodeHSHelloExtensionEllipticCurves(
1335  ssl_state, input, ext_len, &ja3_elliptic_curves);
1336  if (ret < 0)
1337  goto error;
1338 
1339  input += ext_len;
1340 
1341  break;
1342  }
1343 
1345  {
1346  /* coverity[tainted_data] */
1347  ret = TLSDecodeHSHelloExtensionEllipticCurvePF(
1348  ssl_state, input, ext_len, &ja3_elliptic_curves_pf);
1349  if (ret < 0)
1350  goto error;
1351 
1352  input += ext_len;
1353 
1354  break;
1355  }
1356 
1358  /* coverity[tainted_data] */
1359  ret = TLSDecodeHSHelloExtensionSigAlgorithms(ssl_state, input, ext_len);
1360  if (ret < 0)
1361  goto end;
1362 
1363  input += ext_len;
1364 
1365  break;
1366  }
1367 
1368  case SSL_EXTENSION_ALPN: {
1369  /* coverity[tainted_data] */
1370  ret = TLSDecodeHSHelloExtensionALPN(ssl_state, input, ext_len);
1371  if (ret < 0)
1372  goto end;
1373 
1374  input += ext_len;
1375 
1376  break;
1377  }
1378 
1380  {
1381  if (ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) {
1382  /* Used by 0-RTT to indicate that encrypted data will
1383  be sent right after the ClientHello record. */
1384  ssl_state->flags |= SSL_AL_FLAG_EARLY_DATA;
1385  }
1386 
1387  input += ext_len;
1388 
1389  break;
1390  }
1391 
1393  {
1394  ret = TLSDecodeHSHelloExtensionSupportedVersions(ssl_state, input,
1395  ext_len);
1396  if (ret < 0)
1397  goto end;
1398 
1399  input += ext_len;
1400 
1401  break;
1402  }
1403 
1405  {
1406  if (ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) {
1407  /* This has to be verified later on by checking if a
1408  certificate record has been sent by the server. */
1409  ssl_state->flags |= SSL_AL_FLAG_SESSION_RESUMED;
1410  }
1411 
1412  input += ext_len;
1413 
1414  break;
1415  }
1416 
1417  default:
1418  {
1419  input += ext_len;
1420  break;
1421  }
1422  }
1423 
1424  if (ja3) {
1425  if (TLSDecodeValueIsGREASE(ext_type) != 1) {
1426  rc = Ja3BufferAddValue(&ja3_extensions, ext_type);
1427  if (rc != 0)
1428  goto error;
1429  }
1430  }
1431 
1432  if (ssl_state->current_flags &
1434  if (TLSDecodeValueIsGREASE(ext_type) != 1) {
1435  SCTLSHandshakeAddExtension(ssl_state->curr_connp->hs, ext_type);
1436  }
1437  }
1438 
1439  processed_len += (uint32_t)ext_len + 4UL;
1440  }
1441 
1442 end:
1443  if (ja3) {
1444  rc = Ja3BufferAppendBuffer(&ssl_state->curr_connp->ja3_str,
1445  &ja3_extensions);
1446  if (rc == -1)
1447  goto error;
1448 
1449  if (ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) {
1450  rc = Ja3BufferAppendBuffer(&ssl_state->curr_connp->ja3_str,
1451  &ja3_elliptic_curves);
1452  if (rc == -1)
1453  goto error;
1454 
1455  rc = Ja3BufferAppendBuffer(&ssl_state->curr_connp->ja3_str,
1456  &ja3_elliptic_curves_pf);
1457  if (rc == -1)
1458  goto error;
1459  }
1460  }
1461 
1462  return (int)(input - initial_input);
1463 
1464 invalid_length:
1465  SCLogDebug("TLS handshake invalid length");
1466  SSLSetEvent(ssl_state,
1468 
1469 error:
1470  if (ja3_extensions != NULL)
1471  Ja3BufferFree(&ja3_extensions);
1472  if (ja3_elliptic_curves != NULL)
1473  Ja3BufferFree(&ja3_elliptic_curves);
1474  if (ja3_elliptic_curves_pf != NULL)
1475  Ja3BufferFree(&ja3_elliptic_curves_pf);
1476 
1477  return -1;
1478 }
1479 
1480 static int TLSDecodeHandshakeHello(SSLState *ssl_state,
1481  const uint8_t * const input,
1482  const uint32_t input_len)
1483 {
1484  int ret;
1485  uint32_t parsed = 0;
1486 
1487  ret = TLSDecodeHSHelloVersion(ssl_state, input, input_len);
1488  if (ret < 0)
1489  goto end;
1490 
1491  parsed += ret;
1492 
1493  ret = TLSDecodeHSHelloRandom(ssl_state, input + parsed, input_len - parsed);
1494  if (ret < 0)
1495  goto end;
1496 
1497  parsed += ret;
1498 
1499  /* The session id field in the server hello record was removed in
1500  TLSv1.3 draft1, but was readded in draft22. */
1501  if ((ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) ||
1503  ((ssl_state->flags & SSL_AL_FLAG_LOG_WITHOUT_CERT) == 0))) {
1504  ret = TLSDecodeHSHelloSessionID(ssl_state, input + parsed,
1505  input_len - parsed);
1506  if (ret < 0)
1507  goto end;
1508 
1509  parsed += ret;
1510  }
1511 
1512  ret = TLSDecodeHSHelloCipherSuites(ssl_state, input + parsed,
1513  input_len - parsed);
1514  if (ret < 0)
1515  goto end;
1516 
1517  parsed += ret;
1518 
1519  /* The compression methods field in the server hello record was
1520  removed in TLSv1.3 draft1, but was readded in draft22. */
1521  if ((ssl_state->current_flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) ||
1523  ((ssl_state->flags & SSL_AL_FLAG_LOG_WITHOUT_CERT) == 0))) {
1524  ret = TLSDecodeHSHelloCompressionMethods(ssl_state, input + parsed,
1525  input_len - parsed);
1526  if (ret < 0)
1527  goto end;
1528 
1529  parsed += ret;
1530  }
1531 
1532  ret = TLSDecodeHSHelloExtensions(ssl_state, input + parsed,
1533  input_len - parsed);
1534  if (ret < 0)
1535  goto end;
1536 
1537  if (SC_ATOMIC_GET(ssl_config.enable_ja3) && ssl_state->curr_connp->ja3_hash == NULL) {
1538  ssl_state->curr_connp->ja3_hash = Ja3GenerateHash(ssl_state->curr_connp->ja3_str);
1539  }
1540 
1541  if (ssl_state->curr_connp == &ssl_state->client_connp) {
1542  UpdateClientState(ssl_state, TLS_STATE_CLIENT_HELLO_DONE);
1543  } else {
1544  UpdateServerState(ssl_state, TLS_STATE_SERVER_HELLO);
1545  }
1546 end:
1547  return 0;
1548 }
1549 
1550 #ifdef DEBUG_VALIDATION
1551 static inline bool
1552 RecordAlreadyProcessed(const SSLStateConnp *curr_connp)
1553 {
1554  return ((curr_connp->record_length + SSLV3_RECORD_HDR_LEN) <
1555  curr_connp->bytes_processed);
1556 }
1557 #endif
1558 
1559 static inline int SSLv3ParseHandshakeTypeCertificate(SSLState *ssl_state, SSLStateConnp *connp,
1560  const uint8_t *const initial_input, const uint32_t input_len)
1561 {
1562  int rc = TlsDecodeHSCertificates(ssl_state, connp, initial_input, input_len);
1563  SCLogDebug("rc %d", rc);
1564  if (rc > 0) {
1565  DEBUG_VALIDATE_BUG_ON(rc > (int)input_len);
1566  SSLParserHSReset(connp);
1567  } else if (rc < 0) {
1568  SCLogDebug("error parsing cert, reset state");
1569  SSLParserHSReset(connp);
1570  /* fall through to still consume the cert bytes */
1571  }
1572  if (connp == &ssl_state->client_connp) {
1573  UpdateClientState(ssl_state, TLS_STATE_CLIENT_CERT_DONE);
1574  } else {
1575  UpdateServerState(ssl_state, TLS_STATE_SERVER_CERT_DONE);
1576  }
1577  return input_len;
1578 }
1579 
1580 static int SupportedHandshakeType(const uint8_t type)
1581 {
1582  switch (type) {
1583  case SSLV3_HS_CLIENT_HELLO:
1584  case SSLV3_HS_SERVER_HELLO:
1587  case SSLV3_HS_CERTIFICATE:
1591  case SSLV3_HS_FINISHED:
1596  return true;
1597  break;
1598 
1599  default:
1600  return false;
1601  break;
1602  }
1603 }
1604 
1605 /**
1606  * \param input_len length of bytes after record header. Can be 0 (e.g. for server hello done).
1607  * \retval parsed number of consumed bytes
1608  * \retval < 0 error
1609  */
1610 static int SSLv3ParseHandshakeType(SSLState *ssl_state, const uint8_t *input,
1611  uint32_t input_len, uint8_t direction)
1612 {
1613  const uint8_t *initial_input = input;
1614  int rc;
1615 
1616  DEBUG_VALIDATE_BUG_ON(RecordAlreadyProcessed(ssl_state->curr_connp));
1617 
1618  switch (ssl_state->curr_connp->handshake_type) {
1619  case SSLV3_HS_CLIENT_HELLO:
1621 
1622  if (ssl_state->curr_connp->hs == NULL)
1623  ssl_state->curr_connp->hs = SCTLSHandshakeNew();
1624 
1625  rc = TLSDecodeHandshakeHello(ssl_state, input, input_len);
1626  if (rc < 0)
1627  return rc;
1628  break;
1629 
1630  case SSLV3_HS_SERVER_HELLO:
1632 
1633  DEBUG_VALIDATE_BUG_ON(ssl_state->curr_connp->message_length != input_len);
1634  if (ssl_state->curr_connp->hs == NULL)
1635  ssl_state->curr_connp->hs = SCTLSHandshakeNew();
1636 
1637  rc = TLSDecodeHandshakeHello(ssl_state, input, input_len);
1638  if (rc < 0)
1639  return rc;
1640  break;
1641 
1644  break;
1645 
1648  break;
1649 
1650  case SSLV3_HS_CERTIFICATE:
1651  rc = SSLv3ParseHandshakeTypeCertificate(ssl_state,
1652  direction ? &ssl_state->server_connp : &ssl_state->client_connp, initial_input,
1653  input_len);
1654  if (rc < 0)
1655  return rc;
1656  break;
1657 
1659  break;
1661  if (direction) {
1663  }
1664  break;
1666  case SSLV3_HS_FINISHED:
1669  break;
1671  SCLogDebug("new session ticket");
1672  break;
1674  if (direction) {
1675  UpdateServerState(ssl_state, TLS_STATE_SERVER_HELLO_DONE);
1676  }
1677  break;
1678  default:
1680  return -1;
1681  }
1682 
1683  ssl_state->flags |= ssl_state->current_flags;
1684 
1685  SCLogDebug("message: length %u", ssl_state->curr_connp->message_length);
1686  SCLogDebug("input_len %u ssl_state->curr_connp->bytes_processed %u", input_len, ssl_state->curr_connp->bytes_processed);
1687 
1688  return input_len;
1689 }
1690 
1691 static int SSLv3ParseHandshakeProtocol(SSLState *ssl_state, const uint8_t *input,
1692  uint32_t input_len, uint8_t direction)
1693 {
1694  const uint8_t *initial_input = input;
1695 
1696  if (input_len == 0 || ssl_state->curr_connp->bytes_processed ==
1697  (ssl_state->curr_connp->record_length + SSLV3_RECORD_HDR_LEN)) {
1698  SCReturnInt(0);
1699  }
1700 
1701  while (input_len) {
1702  SCLogDebug("input_len %u", input_len);
1703 
1704  if (ssl_state->curr_connp->hs_buffer != NULL) {
1705  SCLogDebug("partial handshake record in place");
1706  const uint32_t need = ssl_state->curr_connp->hs_buffer_message_size -
1707  ssl_state->curr_connp->hs_buffer_offset;
1708  const uint32_t add = MIN(need, input_len);
1709 
1710  /* grow buffer to next multiple of 4k that fits all data we have */
1711  if (ssl_state->curr_connp->hs_buffer_offset + add >
1712  ssl_state->curr_connp->hs_buffer_size) {
1713  const uint32_t avail = ssl_state->curr_connp->hs_buffer_offset + add;
1714  const uint32_t new_size = avail + (4096 - (avail % 4096));
1715  SCLogDebug("new_size %u, avail %u", new_size, avail);
1716  void *ptr = SCRealloc(ssl_state->curr_connp->hs_buffer, new_size);
1717  if (ptr == NULL)
1718  return -1;
1719  ssl_state->curr_connp->hs_buffer = ptr;
1720  ssl_state->curr_connp->hs_buffer_size = new_size;
1721  }
1722 
1723  SCLogDebug("ssl_state->curr_connp->hs_buffer_offset %u "
1724  "ssl_state->curr_connp->hs_buffer_size %u",
1725  ssl_state->curr_connp->hs_buffer_offset, ssl_state->curr_connp->hs_buffer_size);
1726  SCLogDebug("to add %u total %u", add, ssl_state->curr_connp->hs_buffer_offset + add);
1727 
1728  if (SafeMemcpy(ssl_state->curr_connp->hs_buffer,
1729  ssl_state->curr_connp->hs_buffer_offset,
1730  ssl_state->curr_connp->hs_buffer_size, input, 0, add, add) != 0) {
1731  SCLogDebug("copy failed");
1732  return -1;
1733  }
1734  ssl_state->curr_connp->hs_buffer_offset += add;
1735 
1736  if (ssl_state->curr_connp->hs_buffer_message_size <=
1737  ssl_state->curr_connp->hs_buffer_offset) {
1739  ssl_state->curr_connp->hs_buffer_offset);
1740 
1741  ssl_state->curr_connp->handshake_type =
1742  ssl_state->curr_connp->hs_buffer_message_type;
1743  ssl_state->curr_connp->message_length =
1744  ssl_state->curr_connp->hs_buffer_message_size;
1745 
1746  SCLogDebug("got all data now: handshake_type %u message_length %u",
1747  ssl_state->curr_connp->handshake_type,
1748  ssl_state->curr_connp->message_length);
1749 
1750  int retval = SSLv3ParseHandshakeType(ssl_state, ssl_state->curr_connp->hs_buffer,
1751  ssl_state->curr_connp->hs_buffer_offset, direction);
1752  if (retval < 0) {
1753  SSLParserHSReset(ssl_state->curr_connp);
1754  return (retval);
1755  }
1756  SCLogDebug("retval %d", retval);
1757 
1758  /* data processed, reset buffer */
1759  SCFree(ssl_state->curr_connp->hs_buffer);
1760  ssl_state->curr_connp->hs_buffer = NULL;
1761  ssl_state->curr_connp->hs_buffer_size = 0;
1762  ssl_state->curr_connp->hs_buffer_message_size = 0;
1763  ssl_state->curr_connp->hs_buffer_message_type = 0;
1764  ssl_state->curr_connp->hs_buffer_offset = 0;
1765  } else {
1766  SCLogDebug("partial data");
1767  }
1768 
1769  input += add;
1770  input_len -= add;
1771  SCLogDebug("input_len %u", input_len);
1772  SSLParserHSReset(ssl_state->curr_connp);
1773  continue;
1774  }
1775 
1776  SCLogDebug("bytes_processed %u", ssl_state->curr_connp->bytes_processed);
1777  SCLogDebug("input %p input_len %u", input, input_len);
1778 
1779  if (input_len < 4) {
1781  SCReturnInt(-1);
1782  }
1783 
1784  ssl_state->curr_connp->handshake_type = input[0];
1785  ssl_state->curr_connp->message_length = input[1] << 16 | input[2] << 8 | input[3];
1786  SCLogDebug("handshake_type %u message len %u input %p input_len %u",
1787  ssl_state->curr_connp->handshake_type, ssl_state->curr_connp->message_length, input,
1788  input_len);
1789  input += 4;
1790  input_len -= 4;
1791 
1792  const uint32_t record_len = ssl_state->curr_connp->message_length;
1793  /* see if we support this type. We check here to not use the fragment
1794  * handling on things we don't support. */
1795  const bool supported_type = SupportedHandshakeType(ssl_state->curr_connp->handshake_type);
1796  SCLogDebug("supported_type %s handshake_type %u/%02x", supported_type ? "true" : "false",
1797  ssl_state->curr_connp->handshake_type, ssl_state->curr_connp->handshake_type);
1798  if (!supported_type) {
1799  uint32_t avail_record_len = MIN(input_len, record_len);
1800  input += avail_record_len;
1801  input_len -= avail_record_len;
1802 
1803  SSLParserHSReset(ssl_state->curr_connp);
1804 
1805  if ((direction && (ssl_state->flags & SSL_AL_FLAG_SERVER_CHANGE_CIPHER_SPEC)) ||
1806  (!direction && (ssl_state->flags & SSL_AL_FLAG_CLIENT_CHANGE_CIPHER_SPEC))) {
1807  // after Change Cipher Spec we get Encrypted Handshake Messages
1808  } else {
1810  }
1811  continue;
1812  }
1813 
1814  /* if the message length exceeds our input_len, we have a tls fragment. */
1815  if (record_len > input_len) {
1816  const uint32_t avail = input_len;
1817  const uint32_t size = avail + (4096 - (avail % 4096));
1818  SCLogDebug("initial buffer size %u, based on input %u", size, avail);
1819  ssl_state->curr_connp->hs_buffer = SCCalloc(1, size);
1820  if (ssl_state->curr_connp->hs_buffer == NULL) {
1821  return -1;
1822  }
1823  ssl_state->curr_connp->hs_buffer_size = size;
1824  ssl_state->curr_connp->hs_buffer_message_size = record_len;
1825  ssl_state->curr_connp->hs_buffer_message_type = ssl_state->curr_connp->handshake_type;
1826 
1827  if (input_len > 0) {
1828  if (SafeMemcpy(ssl_state->curr_connp->hs_buffer, 0,
1829  ssl_state->curr_connp->hs_buffer_size, input, 0, input_len,
1830  input_len) != 0) {
1831  return -1;
1832  }
1833  ssl_state->curr_connp->hs_buffer_offset = input_len;
1834  }
1835  SCLogDebug("opened record buffer %p size %u offset %u type %u msg_size %u",
1836  ssl_state->curr_connp->hs_buffer, ssl_state->curr_connp->hs_buffer_size,
1837  ssl_state->curr_connp->hs_buffer_offset,
1838  ssl_state->curr_connp->hs_buffer_message_type,
1839  ssl_state->curr_connp->hs_buffer_message_size);
1840  input += input_len;
1841  SSLParserHSReset(ssl_state->curr_connp);
1842  return (int)(input - initial_input);
1843 
1844  } else {
1845  /* full record, parse it now */
1846  int retval = SSLv3ParseHandshakeType(
1847  ssl_state, input, ssl_state->curr_connp->message_length, direction);
1848  if (retval < 0 || retval > (int)input_len) {
1849  DEBUG_VALIDATE_BUG_ON(retval > (int)input_len);
1850  return (retval);
1851  }
1852  SCLogDebug("retval %d input_len %u", retval, input_len);
1853  input += retval;
1854  input_len -= retval;
1855 
1856  SSLParserHSReset(ssl_state->curr_connp);
1857  }
1858  SCLogDebug("input_len left %u", input_len);
1859  }
1860  return (int)(input - initial_input);
1861 }
1862 
1863 /**
1864  * \internal
1865  * \brief TLS Alert parser
1866  *
1867  * \param sslstate Pointer to the SSL state.
1868  * \param input Pointer to the received input data.
1869  * \param input_len Length in bytes of the received data.
1870  * \param direction 1 toclient, 0 toserver
1871  *
1872  * \retval The number of bytes parsed on success, 0 if nothing parsed, -1 on failure.
1873  */
1874 static int SSLv3ParseAlertProtocol(
1875  SSLState *ssl_state, const uint8_t *input, uint32_t input_len, uint8_t direction)
1876 {
1877  if (input_len < 2) {
1879  return -1;
1880  }
1881 
1882  /* assume a record > 2 to be an encrypted alert record */
1883  if (input_len == 2) {
1884  uint8_t level = input[0];
1885  // uint8_t desc = input[1];
1886 
1887  /* if level Fatal, we consider the tx finished */
1888  if (level == 2) {
1889  UpdateClientState(ssl_state, TLS_STATE_CLIENT_FINISHED);
1890  UpdateServerState(ssl_state, TLS_STATE_SERVER_FINISHED);
1891  }
1892  }
1893  return 0;
1894 }
1895 
1896 /**
1897  * \internal
1898  * \brief TLS Heartbeat parser (see RFC 6520)
1899  *
1900  * \param sslstate Pointer to the SSL state.
1901  * \param input Pointer to the received input data.
1902  * \param input_len Length in bytes of the received data.
1903  * \param direction 1 toclient, 0 toserver
1904  *
1905  * \retval The number of bytes parsed on success, 0 if nothing parsed, -1 on failure.
1906  */
1907 static int SSLv3ParseHeartbeatProtocol(SSLState *ssl_state, const uint8_t *input,
1908  uint32_t input_len, uint8_t direction)
1909 {
1910  uint8_t hb_type;
1911  uint16_t payload_len;
1912  uint32_t padding_len;
1913 
1914  /* expect at least 3 bytes: heartbeat type (1) + length (2) */
1915  if (input_len < 3) {
1916  return 0;
1917  }
1918 
1919  hb_type = *input++;
1920 
1921  if (!(ssl_state->flags & SSL_AL_FLAG_CHANGE_CIPHER_SPEC)) {
1922  if (!(hb_type == TLS_HB_REQUEST || hb_type == TLS_HB_RESPONSE)) {
1924  return -1;
1925  }
1926  }
1927 
1928  if ((ssl_state->flags & SSL_AL_FLAG_HB_INFLIGHT) == 0) {
1929  ssl_state->flags |= SSL_AL_FLAG_HB_INFLIGHT;
1930 
1931  if (direction) {
1932  SCLogDebug("HeartBeat Record type sent in the toclient direction!");
1933  ssl_state->flags |= SSL_AL_FLAG_HB_SERVER_INIT;
1934  } else {
1935  SCLogDebug("HeartBeat Record type sent in the toserver direction!");
1936  ssl_state->flags |= SSL_AL_FLAG_HB_CLIENT_INIT;
1937  }
1938 
1939  /* if we reach this point, then we can assume that the HB request
1940  is encrypted. If so, let's set the HB record length */
1941  if (ssl_state->flags & SSL_AL_FLAG_CHANGE_CIPHER_SPEC) {
1942  ssl_state->hb_record_len = ssl_state->curr_connp->record_length;
1943  SCLogDebug("Encrypted HeartBeat Request In-flight. Storing len %u",
1944  ssl_state->hb_record_len);
1945  return (ssl_state->curr_connp->record_length - 3);
1946  }
1947 
1948  payload_len = (uint16_t)(*input << 8) | *(input + 1);
1949 
1950  /* check that the requested payload length is really present in
1951  the record (CVE-2014-0160) */
1952  if ((uint32_t)(payload_len+3) > ssl_state->curr_connp->record_length) {
1953  SCLogDebug("We have a short record in HeartBeat Request");
1955  return -1;
1956  }
1957 
1958  /* check the padding length. It must be at least 16 bytes
1959  (RFC 6520, section 4) */
1960  padding_len = ssl_state->curr_connp->record_length - payload_len - 3;
1961  if (padding_len < 16) {
1962  SCLogDebug("We have a short record in HeartBeat Request");
1964  return -1;
1965  }
1966 
1967  /* we don't have the payload */
1968  if (input_len < payload_len + padding_len) {
1969  return 0;
1970  }
1971 
1972  /* OpenSSL still seems to discard multiple in-flight
1973  heartbeats although some tools send multiple at once */
1974  } else if (direction == 1 && (ssl_state->flags & SSL_AL_FLAG_HB_INFLIGHT) &&
1975  (ssl_state->flags & SSL_AL_FLAG_HB_SERVER_INIT)) {
1976  SCLogDebug("Multiple in-flight server initiated HeartBeats");
1978  return -1;
1979 
1980  } else if (direction == 0 && (ssl_state->flags & SSL_AL_FLAG_HB_INFLIGHT) &&
1981  (ssl_state->flags & SSL_AL_FLAG_HB_CLIENT_INIT)) {
1982  SCLogDebug("Multiple in-flight client initiated HeartBeats");
1984  return -1;
1985 
1986  } else {
1987  /* we have a HB record in the opposite direction of the request,
1988  let's reset our flags */
1989  ssl_state->flags &= ~SSL_AL_FLAG_HB_INFLIGHT;
1990  ssl_state->flags &= ~SSL_AL_FLAG_HB_SERVER_INIT;
1991  ssl_state->flags &= ~SSL_AL_FLAG_HB_CLIENT_INIT;
1992 
1993  /* if we reach this point, then we can assume that the HB request
1994  is encrypted. If so, let's set the HB record length */
1995  if (ssl_state->flags & SSL_AL_FLAG_CHANGE_CIPHER_SPEC) {
1996  /* check to see if the encrypted response is longer than the
1997  encrypted request */
1998  if (ssl_state->hb_record_len > 0 && ssl_state->hb_record_len <
1999  ssl_state->curr_connp->record_length) {
2000  SCLogDebug("My heart is bleeding.. OpenSSL HeartBleed response (%u)",
2001  ssl_state->hb_record_len);
2002  SSLSetEvent(ssl_state,
2004  ssl_state->hb_record_len = 0;
2005  return -1;
2006  }
2007  }
2008 
2009  /* reset the HB record length in case we have a legit HB followed
2010  by a bad one */
2011  ssl_state->hb_record_len = 0;
2012  }
2013 
2014  /* skip the HeartBeat, 3 bytes were already parsed,
2015  e.g |18 03 02| for TLS 1.2 */
2016  return (ssl_state->curr_connp->record_length - 3);
2017 }
2018 
2019 static int SSLv3ParseRecord(uint8_t direction, SSLState *ssl_state,
2020  const uint8_t *input, uint32_t input_len)
2021 {
2022  const uint8_t *initial_input = input;
2023 
2024  if (input_len == 0) {
2025  return 0;
2026  }
2027 
2028  uint8_t skip_version = 0;
2029 
2030  /* Only set SSL/TLS version here if it has not already been set in
2031  client/server hello. */
2032  if (direction == 0) {
2033  if ((ssl_state->flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) &&
2034  (ssl_state->client_connp.version != TLS_VERSION_UNKNOWN)) {
2035  skip_version = 1;
2036  }
2037  } else {
2038  if ((ssl_state->flags & SSL_AL_FLAG_STATE_SERVER_HELLO) &&
2039  (ssl_state->server_connp.version != TLS_VERSION_UNKNOWN)) {
2040  skip_version = 1;
2041  }
2042  }
2043 
2044  switch (ssl_state->curr_connp->bytes_processed) {
2045  case 0:
2046  if (input_len >= 5) {
2047  ssl_state->curr_connp->content_type = input[0];
2048  if (!skip_version) {
2049  ssl_state->curr_connp->version = (uint16_t)(input[1] << 8) | input[2];
2050  }
2051  ssl_state->curr_connp->record_length = input[3] << 8;
2052  ssl_state->curr_connp->record_length |= input[4];
2054  return SSLV3_RECORD_HDR_LEN;
2055  } else {
2056  ssl_state->curr_connp->content_type = *(input++);
2057  if (--input_len == 0)
2058  break;
2059  }
2060 
2061  /* fall through */
2062  case 1:
2063  if (!skip_version) {
2064  ssl_state->curr_connp->version = (uint16_t)(*(input++) << 8);
2065  } else {
2066  input++;
2067  }
2068  if (--input_len == 0)
2069  break;
2070 
2071  /* fall through */
2072  case 2:
2073  if (!skip_version) {
2074  ssl_state->curr_connp->version |= *(input++);
2075  } else {
2076  input++;
2077  }
2078  if (--input_len == 0)
2079  break;
2080 
2081  /* fall through */
2082  case 3:
2083  ssl_state->curr_connp->record_length = *(input++) << 8;
2084  if (--input_len == 0)
2085  break;
2086 
2087  /* fall through */
2088  case 4:
2089  ssl_state->curr_connp->record_length |= *(input++);
2090  if (--input_len == 0)
2091  break;
2092 
2093  /* fall through */
2094  }
2095 
2096  ssl_state->curr_connp->bytes_processed += (input - initial_input);
2097 
2098  return (int)(input - initial_input);
2099 }
2100 
2101 static int SSLv2ParseRecord(uint8_t direction, SSLState *ssl_state,
2102  const uint8_t *input, uint32_t input_len)
2103 {
2104  const uint8_t *initial_input = input;
2105 
2106  if (input_len == 0) {
2107  return 0;
2108  }
2109 
2110  if (ssl_state->curr_connp->record_lengths_length == 2) {
2111  switch (ssl_state->curr_connp->bytes_processed) {
2112  case 0:
2113  if (input_len >= ssl_state->curr_connp->record_lengths_length + 1) {
2114  ssl_state->curr_connp->record_length = (0x7f & input[0]) << 8 | input[1];
2115  ssl_state->curr_connp->content_type = input[2];
2116  ssl_state->curr_connp->version = SSL_VERSION_2;
2117  ssl_state->curr_connp->bytes_processed += 3;
2118  return 3;
2119  } else {
2120  ssl_state->curr_connp->record_length = (0x7f & *(input++)) << 8;
2121  if (--input_len == 0)
2122  break;
2123  }
2124 
2125  /* fall through */
2126  case 1:
2127  ssl_state->curr_connp->record_length |= *(input++);
2128  if (--input_len == 0)
2129  break;
2130 
2131  /* fall through */
2132  case 2:
2133  ssl_state->curr_connp->content_type = *(input++);
2134  ssl_state->curr_connp->version = SSL_VERSION_2;
2135  if (--input_len == 0)
2136  break;
2137 
2138  /* fall through */
2139  }
2140 
2141  } else {
2142  switch (ssl_state->curr_connp->bytes_processed) {
2143  case 0:
2144  if (input_len >= ssl_state->curr_connp->record_lengths_length + 1) {
2145  ssl_state->curr_connp->record_length = (0x3f & input[0]) << 8 | input[1];
2146  ssl_state->curr_connp->content_type = input[3];
2147  ssl_state->curr_connp->version = SSL_VERSION_2;
2148  ssl_state->curr_connp->bytes_processed += 4;
2149  return 4;
2150  } else {
2151  ssl_state->curr_connp->record_length = (0x3f & *(input++)) << 8;
2152  if (--input_len == 0)
2153  break;
2154  }
2155 
2156  /* fall through */
2157  case 1:
2158  ssl_state->curr_connp->record_length |= *(input++);
2159  if (--input_len == 0)
2160  break;
2161 
2162  /* fall through */
2163  case 2:
2164  /* padding */
2165  input++;
2166  if (--input_len == 0)
2167  break;
2168 
2169  /* fall through */
2170  case 3:
2171  ssl_state->curr_connp->content_type = *(input++);
2172  ssl_state->curr_connp->version = SSL_VERSION_2;
2173  if (--input_len == 0)
2174  break;
2175 
2176  /* fall through */
2177  }
2178  }
2179 
2180  ssl_state->curr_connp->bytes_processed += (input - initial_input);
2181 
2182  return (int)(input - initial_input);
2183 }
2184 
2185 static struct SSLDecoderResult SSLv2Decode(uint8_t direction, SSLState *ssl_state,
2186  AppLayerParserState *pstate, const uint8_t *input, uint32_t input_len,
2187  const StreamSlice stream_slice)
2188 {
2189  const uint8_t *initial_input = input;
2190 
2191  if (ssl_state->curr_connp->bytes_processed == 0) {
2192  if (input[0] & 0x80) {
2193  ssl_state->curr_connp->record_lengths_length = 2;
2194  } else {
2195  ssl_state->curr_connp->record_lengths_length = 3;
2196  }
2197 
2198  SCLogDebug("record start: ssl2.hdr frame");
2199  AppLayerFrameNewByPointer(ssl_state->f, &stream_slice, input,
2200  ssl_state->curr_connp->record_lengths_length + 1, direction, TLS_FRAME_SSLV2_HDR);
2201  }
2202 
2203  SCLogDebug("direction %u ssl_state->curr_connp->record_lengths_length + 1 %u, "
2204  "ssl_state->curr_connp->bytes_processed %u",
2205  direction, ssl_state->curr_connp->record_lengths_length + 1,
2206  ssl_state->curr_connp->bytes_processed);
2207  /* the +1 is because we read one extra byte inside SSLv2ParseRecord
2208  to read the msg_type */
2209  if (ssl_state->curr_connp->bytes_processed <
2210  (ssl_state->curr_connp->record_lengths_length + 1)) {
2211  const int retval = SSLv2ParseRecord(direction, ssl_state, input, input_len);
2212  SCLogDebug("retval %d ssl_state->curr_connp->record_length %u", retval,
2213  ssl_state->curr_connp->record_length);
2214  if (retval < 0 || retval > (int)input_len) {
2215  DEBUG_VALIDATE_BUG_ON(retval > (int)input_len);
2217  return SSL_DECODER_ERROR(-1);
2218  }
2219 
2220  AppLayerFrameNewByPointer(ssl_state->f, &stream_slice, input,
2221  ssl_state->curr_connp->record_lengths_length + ssl_state->curr_connp->record_length,
2222  direction, TLS_FRAME_SSLV2_PDU);
2223  SCLogDebug("record start: ssl2.pdu frame");
2224 
2225  input += retval;
2226  input_len -= retval;
2227  }
2228 
2229  /* if we don't have the full record, we return incomplete */
2230  if (ssl_state->curr_connp->record_lengths_length + ssl_state->curr_connp->record_length >
2231  input_len + ssl_state->curr_connp->bytes_processed) {
2232  uint32_t needed = ssl_state->curr_connp->record_length;
2233  SCLogDebug("record len %u input_len %u parsed %u: need %u bytes more data",
2234  ssl_state->curr_connp->record_length, input_len, (uint32_t)(input - initial_input),
2235  needed);
2236  return SSL_DECODER_INCOMPLETE((input - initial_input), needed);
2237  }
2238 
2239  if (input_len == 0) {
2240  return SSL_DECODER_OK((input - initial_input));
2241  }
2242 
2243  /* record_length should never be zero */
2244  if (ssl_state->curr_connp->record_length == 0) {
2245  SCLogDebug("SSLv2 record length is zero");
2247  return SSL_DECODER_ERROR(-1);
2248  }
2249 
2250  /* record_lengths_length should never be zero */
2251  if (ssl_state->curr_connp->record_lengths_length == 0) {
2252  SCLogDebug("SSLv2 record lengths length is zero");
2254  return SSL_DECODER_ERROR(-1);
2255  }
2256 
2257  switch (ssl_state->curr_connp->content_type) {
2258  case SSLV2_MT_ERROR:
2259  SCLogDebug("SSLV2_MT_ERROR msg_type received. Error encountered "
2260  "in establishing the sslv2 session, may be version");
2262 
2263  break;
2264 
2265  case SSLV2_MT_CLIENT_HELLO:
2266  /* record_length does not count the msg_type byte. CLIENT_HELLO
2267  * body starts with 3 fixed fields: client_version (2) +
2268  * cipher_spec_length (2) + session_id_length (2). We need at
2269  * least those 6 bytes after the msg_type, so record_length
2270  * must be >= 7. */
2271  if (input_len < 6 || ssl_state->curr_connp->record_length < 7) {
2273  return SSL_DECODER_ERROR(-1);
2274  }
2275 
2276  ssl_state->current_flags = SSL_AL_FLAG_STATE_CLIENT_HELLO;
2277  ssl_state->current_flags |= SSL_AL_FLAG_SSL_CLIENT_HS;
2278  UpdateClientState(ssl_state, TLS_STATE_CLIENT_HELLO_DONE);
2279 
2280  const uint16_t version = (uint16_t)(input[0] << 8) | input[1];
2281  SCLogDebug("SSLv2: version %04x", version);
2282  ssl_state->curr_connp->version = version;
2283  uint16_t session_id_length = (input[5]) | (uint16_t)(input[4] << 8);
2284  input += 6;
2285  input_len -= 6;
2286  ssl_state->curr_connp->bytes_processed += 6;
2287  if (session_id_length == 0) {
2288  ssl_state->current_flags |= SSL_AL_FLAG_SSL_NO_SESSION_ID;
2289  }
2290  break;
2291 
2293  if (!(ssl_state->flags & SSL_AL_FLAG_SSL_CLIENT_HS)) {
2294  SCLogDebug("Client hello is not seen before master key "
2295  "message!");
2296  }
2297  ssl_state->current_flags = SSL_AL_FLAG_SSL_CLIENT_MASTER_KEY;
2298 
2299  break;
2300 
2302  if (direction == 1) {
2303  SCLogDebug("Incorrect SSL Record type sent in the toclient "
2304  "direction!");
2305  } else {
2306  ssl_state->current_flags = SSL_AL_FLAG_STATE_CLIENT_KEYX;
2307  }
2308  UpdateServerState(ssl_state, TLS_STATE_SERVER_CERT_DONE);
2309 
2310  /* fall through */
2313  if (direction == 0 &&
2314  !(ssl_state->curr_connp->content_type &
2316  SCLogDebug("Incorrect SSL Record type sent in the toserver "
2317  "direction!");
2318  }
2319 
2320  /* fall through */
2323  /* both client hello and server hello must be seen */
2324  if ((ssl_state->flags & SSL_AL_FLAG_SSL_CLIENT_HS) &&
2325  (ssl_state->flags & SSL_AL_FLAG_SSL_SERVER_HS)) {
2326 
2327  if (direction == 0) {
2328  if (ssl_state->flags & SSL_AL_FLAG_SSL_NO_SESSION_ID) {
2329  ssl_state->current_flags |= SSL_AL_FLAG_SSL_CLIENT_SSN_ENCRYPTED;
2330  SCLogDebug("SSLv2 client side has started the encryption");
2331  } else if (ssl_state->flags & SSL_AL_FLAG_SSL_CLIENT_MASTER_KEY) {
2332  ssl_state->current_flags = SSL_AL_FLAG_SSL_CLIENT_SSN_ENCRYPTED;
2333  SCLogDebug("SSLv2 client side has started the encryption");
2334  }
2335  } else {
2336  ssl_state->current_flags = SSL_AL_FLAG_SSL_SERVER_SSN_ENCRYPTED;
2337  SCLogDebug("SSLv2 Server side has started the encryption");
2338  }
2339 
2340  if ((ssl_state->flags & SSL_AL_FLAG_SSL_CLIENT_SSN_ENCRYPTED) &&
2341  (ssl_state->flags & SSL_AL_FLAG_SSL_SERVER_SSN_ENCRYPTED))
2342  {
2344  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_NO_INSPECTION);
2345  }
2346 
2348  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_NO_REASSEMBLY);
2349  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_BYPASS_READY);
2350  }
2351  SCLogDebug("SSLv2 No reassembly & inspection has been set");
2352  }
2353  }
2354 
2355  break;
2356 
2357  case SSLV2_MT_SERVER_HELLO:
2358  ssl_state->current_flags = SSL_AL_FLAG_STATE_SERVER_HELLO;
2359  ssl_state->current_flags |= SSL_AL_FLAG_SSL_SERVER_HS;
2360  UpdateServerState(ssl_state, TLS_STATE_SERVER_HELLO);
2361 
2362  break;
2363  }
2364 
2365  ssl_state->flags |= ssl_state->current_flags;
2366 
2367  if (ssl_state->curr_connp->bytes_processed >
2368  ssl_state->curr_connp->record_length + ssl_state->curr_connp->record_lengths_length) {
2369  SCLogDebug("SSLv2 bytes_processed (%u) exceeds record+hdr "
2370  "len (record_length=%u, lengths_length=%u)",
2371  ssl_state->curr_connp->bytes_processed, ssl_state->curr_connp->record_length,
2372  ssl_state->curr_connp->record_lengths_length);
2374  return SSL_DECODER_ERROR(-1);
2375  }
2376 
2377  if (input_len + ssl_state->curr_connp->bytes_processed >=
2378  (ssl_state->curr_connp->record_length +
2379  ssl_state->curr_connp->record_lengths_length)) {
2380 
2381  /* looks like we have another record after this */
2382  uint32_t diff = ssl_state->curr_connp->record_length +
2383  ssl_state->curr_connp->record_lengths_length + -
2384  ssl_state->curr_connp->bytes_processed;
2385  input += diff;
2386  SSLParserReset(ssl_state);
2387 
2388  /* we still don't have the entire record for the one we are
2389  currently parsing */
2390  } else {
2391  input += input_len;
2392  ssl_state->curr_connp->bytes_processed += input_len;
2393  }
2394  return SSL_DECODER_OK((input - initial_input));
2395 }
2396 
2397 static struct SSLDecoderResult SSLv3Decode(uint8_t direction, SSLState *ssl_state,
2398  AppLayerParserState *pstate, const uint8_t *input, const uint32_t input_len,
2399  const StreamSlice stream_slice)
2400 {
2401  uint32_t parsed = 0;
2402  uint32_t record_len; /* slice of input_len for the current record */
2403  const bool first_call = (ssl_state->curr_connp->bytes_processed == 0);
2404 
2405  if (ssl_state->curr_connp->bytes_processed < SSLV3_RECORD_HDR_LEN) {
2406  const uint16_t prev_version = ssl_state->curr_connp->version;
2407 
2408  int retval = SSLv3ParseRecord(direction, ssl_state, input, input_len);
2409  if (retval < 0 || retval > (int)input_len) {
2410  DEBUG_VALIDATE_BUG_ON(retval > (int)input_len);
2411  SCLogDebug("SSLv3ParseRecord returned %d", retval);
2413  return SSL_DECODER_ERROR(-1);
2414  }
2415  parsed = retval;
2416 
2417  SCLogDebug("%s input %p record_length %u", (direction == 0) ? "toserver" : "toclient",
2418  input, ssl_state->curr_connp->record_length);
2419 
2420  /* first the hdr frame at our first chance */
2421  if (first_call) {
2422  AppLayerFrameNewByPointer(ssl_state->f, &stream_slice, input, SSLV3_RECORD_HDR_LEN,
2423  direction, TLS_FRAME_HDR);
2424  }
2425 
2426  /* parser is streaming for the initial header, then switches to incomplete
2427  * API: so if we don't have the hdr yet, return consumed bytes and wait
2428  * until we are called again with new data. */
2429  if (ssl_state->curr_connp->bytes_processed < SSLV3_RECORD_HDR_LEN) {
2430  SCLogDebug(
2431  "incomplete header, return %u bytes consumed and wait for more data", parsed);
2432  return SSL_DECODER_OK(parsed);
2433  }
2434 
2435  /* pdu frame needs record length, so only create it when hdr fully parsed. */
2436  AppLayerFrameNewByPointer(ssl_state->f, &stream_slice, input,
2437  ssl_state->curr_connp->record_length + retval, direction, TLS_FRAME_PDU);
2438  record_len = MIN(input_len - parsed, ssl_state->curr_connp->record_length);
2439  SCLogDebug(
2440  "record_len %u (input_len %u, parsed %u, ssl_state->curr_connp->record_length %u)",
2441  record_len, input_len, parsed, ssl_state->curr_connp->record_length);
2442 
2443  bool unknown_record = false;
2444  switch (ssl_state->curr_connp->content_type) {
2446  case SSLV3_ALERT_PROTOCOL:
2450  break;
2451  default:
2452  unknown_record = true;
2453  break;
2454  }
2455 
2456  /* unknown record type. For TLS 1.0, 1.1 and 1.2 this is ok. For the rest it is fatal. Based
2457  * on Wireshark logic. */
2458  if (prev_version == TLS_VERSION_10 || prev_version == TLS_VERSION_11) {
2459  if (unknown_record) {
2460  SCLogDebug("unknown record, ignore it");
2462 
2463  ssl_state->curr_connp->bytes_processed = 0; // TODO review this reset logic
2464  ssl_state->curr_connp->content_type = 0;
2465  ssl_state->curr_connp->record_length = 0;
2466  // restore last good version
2467  ssl_state->curr_connp->version = prev_version;
2468  return SSL_DECODER_OK(input_len); // consume everything
2469  }
2470  } else {
2471  if (unknown_record) {
2472  SCLogDebug("unknown record, fatal");
2474  return SSL_DECODER_ERROR(-1);
2475  }
2476  }
2477 
2478  /* record_length should never be zero */
2479  if (ssl_state->curr_connp->record_length == 0) {
2480  SCLogDebug("SSLv3 Record length is 0");
2482  return SSL_DECODER_ERROR(-1);
2483  }
2484 
2485  if (!TLSVersionValid(ssl_state->curr_connp->version)) {
2486  SCLogDebug("ssl_state->curr_connp->version %04x", ssl_state->curr_connp->version);
2488  return SSL_DECODER_ERROR(-1);
2489  }
2490 
2491  if (ssl_state->curr_connp->bytes_processed == SSLV3_RECORD_HDR_LEN &&
2492  ssl_state->curr_connp->record_length > SSLV3_RECORD_MAX_LEN) {
2494  return SSL_DECODER_ERROR(-1);
2495  }
2496  DEBUG_VALIDATE_BUG_ON(ssl_state->curr_connp->bytes_processed > SSLV3_RECORD_HDR_LEN);
2497  } else {
2498  ValidateRecordState(ssl_state->curr_connp);
2499 
2500  record_len = (ssl_state->curr_connp->record_length + SSLV3_RECORD_HDR_LEN)- ssl_state->curr_connp->bytes_processed;
2501  record_len = MIN(input_len, record_len);
2502  }
2503  SCLogDebug("record length %u processed %u got %u",
2504  ssl_state->curr_connp->record_length, ssl_state->curr_connp->bytes_processed, record_len);
2505 
2506  /* if we don't have the full record, we return incomplete */
2507  if (ssl_state->curr_connp->record_length > input_len - parsed) {
2508  /* no need to use incomplete api buffering for application
2509  * records that we'll not use anyway. */
2510  if (ssl_state->curr_connp->content_type == SSLV3_APPLICATION_PROTOCOL) {
2511  SCLogDebug("application record");
2512  } else {
2513  uint32_t needed = ssl_state->curr_connp->record_length;
2514  SCLogDebug("record len %u input_len %u parsed %u: need %u bytes more data",
2515  ssl_state->curr_connp->record_length, input_len, parsed, needed);
2517  return SSL_DECODER_INCOMPLETE(parsed, needed);
2518  }
2519  }
2520 
2521  if (record_len == 0) {
2522  return SSL_DECODER_OK(parsed);
2523  }
2524 
2525  AppLayerFrameNewByPointer(ssl_state->f, &stream_slice, input + parsed,
2526  ssl_state->curr_connp->record_length, direction, TLS_FRAME_DATA);
2527 
2528  switch (ssl_state->curr_connp->content_type) {
2529  /* we don't need any data from these types */
2531  ssl_state->flags |= SSL_AL_FLAG_CHANGE_CIPHER_SPEC;
2532 
2533  if (direction) {
2534  ssl_state->flags |= SSL_AL_FLAG_SERVER_CHANGE_CIPHER_SPEC;
2535  } else {
2536  ssl_state->flags |= SSL_AL_FLAG_CLIENT_CHANGE_CIPHER_SPEC;
2537 
2538  // TODO TLS 1.3
2539  UpdateClientState(ssl_state, TLS_STATE_CLIENT_HANDSHAKE_DONE);
2540  }
2541  break;
2542 
2543  case SSLV3_ALERT_PROTOCOL: {
2544  AppLayerFrameNewByPointer(ssl_state->f, &stream_slice, input + parsed,
2545  ssl_state->curr_connp->record_length, direction, TLS_FRAME_ALERT_DATA);
2546 
2547  int retval = SSLv3ParseAlertProtocol(ssl_state, input + parsed, record_len, direction);
2548  if (retval < 0) {
2549  SCLogDebug("SSLv3ParseAlertProtocol returned %d", retval);
2550  return SSL_DECODER_ERROR(-1);
2551  }
2552  break;
2553  }
2555  /* In TLSv1.3 early data (0-RTT) could be sent before the
2556  handshake is complete (rfc8446, section 2.3). We should
2557  therefore not mark the handshake as done before we have
2558  seen the ServerHello record. */
2559  if ((ssl_state->flags & SSL_AL_FLAG_EARLY_DATA) &&
2560  ((ssl_state->flags & SSL_AL_FLAG_STATE_SERVER_HELLO) == 0))
2561  break;
2562 
2563  /* if we see (encrypted) application data, then this means the
2564  handshake must be done */
2565  if (ssl_state->curr_connp == &ssl_state->client_connp) {
2566  UpdateClientState(ssl_state, TLS_STATE_CLIENT_HANDSHAKE_DONE);
2567  } else {
2568  UpdateServerState(ssl_state, TLS_STATE_SERVER_HANDSHAKE_DONE);
2569  }
2570 
2572  SCLogDebug("setting APP_LAYER_PARSER_NO_INSPECTION_PAYLOAD");
2573  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_NO_INSPECTION_PAYLOAD);
2574  }
2575 
2576  /* Encrypted data, reassembly not asked, bypass asked, let's sacrifice
2577  * heartbeat lke inspection to be able to be able to bypass the flow */
2579  SCLogDebug("setting APP_LAYER_PARSER_NO_REASSEMBLY");
2580  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_NO_REASSEMBLY);
2581  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_NO_INSPECTION);
2582  SCAppLayerParserStateSetFlag(pstate, APP_LAYER_PARSER_BYPASS_READY);
2583  }
2584  break;
2585 
2586  case SSLV3_HANDSHAKE_PROTOCOL: {
2587  if (ssl_state->flags & SSL_AL_FLAG_CHANGE_CIPHER_SPEC) {
2588  /* In TLSv1.3, ChangeCipherSpec is only used for middlebox
2589  compatibility (rfc8446, appendix D.4). */
2590  // Client hello flags is needed to have a valid version
2591  if ((ssl_state->flags & SSL_AL_FLAG_STATE_CLIENT_HELLO) &&
2592  (ssl_state->client_connp.version > TLS_VERSION_12) &&
2593  ((ssl_state->flags & SSL_AL_FLAG_STATE_SERVER_HELLO) == 0)) {
2594  /* do nothing */
2595  } else {
2596  // if we started parsing this, we must stop
2597  break;
2598  }
2599  }
2600 
2601  if (ssl_state->curr_connp->record_length < 4) {
2602  SSLParserReset(ssl_state);
2604  SCLogDebug("record len < 4 => %u", ssl_state->curr_connp->record_length);
2605  return SSL_DECODER_ERROR(-1);
2606  }
2607 
2608  int retval = SSLv3ParseHandshakeProtocol(ssl_state, input + parsed,
2609  record_len, direction);
2610  SCLogDebug("retval %d", retval);
2611  if (retval < 0 || retval > (int)record_len) {
2612  DEBUG_VALIDATE_BUG_ON(retval > (int)record_len);
2614  SCLogDebug("SSLv3ParseHandshakeProtocol returned %d", retval);
2615  return SSL_DECODER_ERROR(-1);
2616  }
2617  ValidateRecordState(ssl_state->curr_connp);
2618  break;
2619  }
2620  case SSLV3_HEARTBEAT_PROTOCOL: {
2621  AppLayerFrameNewByPointer(ssl_state->f, &stream_slice, input + parsed,
2622  ssl_state->curr_connp->record_length, direction, TLS_FRAME_HB_DATA);
2623  int retval = SSLv3ParseHeartbeatProtocol(ssl_state, input + parsed,
2624  record_len, direction);
2625  if (retval < 0) {
2626  SCLogDebug("SSLv3ParseHeartbeatProtocol returned %d", retval);
2627  return SSL_DECODER_ERROR(-1);
2628  }
2629  break;
2630  }
2631  default:
2632  // should be unreachable now that we check after header parsing
2634  SCLogDebug("unsupported record type");
2635  return SSL_DECODER_ERROR(-1);
2636  }
2637 
2638  parsed += record_len;
2639  ssl_state->curr_connp->bytes_processed += record_len;
2640 
2641  if (ssl_state->curr_connp->bytes_processed >=
2642  ssl_state->curr_connp->record_length + SSLV3_RECORD_HDR_LEN) {
2643  SCLogDebug("record complete, trigger RAW");
2645  ssl_state->f, direction == 0 ? STREAM_TOSERVER : STREAM_TOCLIENT);
2646  SSLParserReset(ssl_state);
2647  ValidateRecordState(ssl_state->curr_connp);
2648  return SSL_DECODER_OK(parsed);
2649 
2650  } else {
2651  /* we still don't have the entire record for the one we are
2652  currently parsing */
2653  ValidateRecordState(ssl_state->curr_connp);
2654  return SSL_DECODER_OK(parsed);
2655  }
2656 }
2657 
2658 /**
2659  * \internal
2660  * \brief SSLv2, SSLv23, SSLv3, TLSv1.1, TLSv1.2, TLSv1.3 parser.
2661  *
2662  * On parsing error, this should be the only function that should reset
2663  * the parser state, to avoid multiple functions in the chain resetting
2664  * the parser state.
2665  *
2666  * \param direction 0 for toserver, 1 for toclient.
2667  * \param alstate Pointer to the state.
2668  * \param pstate Application layer parser state for this session.
2669  * \param output Pointer to the list of parsed output elements.
2670  *
2671  * \todo On reaching an inconsistent state, check if the input has
2672  * another new record, instead of just returning after the reset
2673  *
2674  * \retval >=0 On success.
2675  */
2676 static AppLayerResult SSLDecode(Flow *f, uint8_t direction, void *alstate,
2677  AppLayerParserState *pstate, StreamSlice stream_slice)
2678 {
2679  SSLState *ssl_state = (SSLState *)alstate;
2680  ssl_state->tx_data.updated_tc = true;
2681  ssl_state->tx_data.updated_ts = true;
2682  uint32_t counter = 0;
2683  ssl_state->f = f;
2684  const uint8_t *input = StreamSliceGetData(&stream_slice);
2685  const uint8_t *init_input = input;
2686  int32_t input_len = (int32_t)StreamSliceGetDataLen(&stream_slice);
2687 
2688  if ((input == NULL || input_len == 0) &&
2689  ((direction == 0 && SCAppLayerParserStateIssetFlag(pstate, APP_LAYER_PARSER_EOF_TS)) ||
2690  (direction == 1 &&
2691  SCAppLayerParserStateIssetFlag(pstate, APP_LAYER_PARSER_EOF_TC)))) {
2692  /* flag session as finished if APP_LAYER_PARSER_EOF is set */
2693  if (direction == 0)
2694  UpdateClientState(ssl_state, TLS_STATE_CLIENT_FINISHED);
2695  else
2696  UpdateServerState(ssl_state, TLS_STATE_SERVER_FINISHED);
2698  } else if (input == NULL || input_len == 0) {
2700  }
2701 
2702  if (direction == 0)
2703  ssl_state->curr_connp = &ssl_state->client_connp;
2704  else
2705  ssl_state->curr_connp = &ssl_state->server_connp;
2706 
2707  /* If entering on a new record, reset the current flags. */
2708  if (ssl_state->curr_connp->bytes_processed == 0) {
2709  ssl_state->current_flags = 0;
2710  }
2711 
2712  /* if we have more than one record */
2713  uint32_t max_records = MAX((input_len / SSL_RECORD_MINIMUM_LENGTH),1);
2714  while (input_len > 0) {
2715  if (counter > max_records) {
2716  SCLogDebug("Looks like we have looped quite a bit. Reset state "
2717  "and get out of here");
2718  SSLParserReset(ssl_state);
2719  SSLSetEvent(ssl_state,
2721  return APP_LAYER_ERROR;
2722  }
2723 
2724  /* ssl_state->bytes_processed is zero for a fresh record or
2725  positive to indicate a record currently being parsed */
2726 
2727  if (ssl_state->curr_connp->bytes_processed == 0) {
2728  if ((input[0] & 0x80) || (input[0] & 0x40)) {
2729  /* only SSLv2, has one of the top 2 bits set */
2730  ssl_state->curr_connp->version = SSL_VERSION_2;
2731  SCLogDebug("SSLv2 detected");
2732  } else if (ssl_state->curr_connp->version == SSL_VERSION_2) {
2733  ssl_state->curr_connp->version = TLS_VERSION_UNKNOWN;
2734  SCLogDebug("SSL/TLS version reset");
2735  }
2736  }
2737  SCLogDebug("record %u: bytes_processed %u, version %02X, input_len %u", counter,
2738  ssl_state->curr_connp->bytes_processed, ssl_state->curr_connp->version, input_len);
2739 
2740  if (ssl_state->curr_connp->version == SSL_VERSION_2) {
2741  if (ssl_state->curr_connp->bytes_processed == 0) {
2742  SCLogDebug("New SSLv2 record parsing");
2743  } else {
2744  SCLogDebug("Continuing parsing SSLv2 record");
2745  }
2746  struct SSLDecoderResult r =
2747  SSLv2Decode(direction, ssl_state, pstate, input, input_len, stream_slice);
2748  if (r.retval < 0 || r.retval > input_len) {
2749  DEBUG_VALIDATE_BUG_ON(r.retval > input_len);
2750  SCLogDebug("Error parsing SSLv2. Resetting parser "
2751  "state. Let's get outta here");
2752  SSLParserReset(ssl_state);
2753  SSLSetEvent(ssl_state,
2755  return APP_LAYER_ERROR;
2756  } else if (r.needed) {
2757  input += r.retval;
2758  SCLogDebug("returning consumed %" PRIuMAX " needed %u",
2759  (uintmax_t)(input - init_input), r.needed);
2760  SCReturnStruct(APP_LAYER_INCOMPLETE((uint32_t)(input - init_input), r.needed));
2761  }
2762  input_len -= r.retval;
2763  input += r.retval;
2764  SCLogDebug("SSLv2 decoder consumed %d bytes: %u left", r.retval, input_len);
2765  } else {
2766  if (ssl_state->curr_connp->bytes_processed == 0) {
2767  SCLogDebug("New TLS record: record_length %u",
2768  ssl_state->curr_connp->record_length);
2769  } else {
2770  SCLogDebug("Continuing parsing TLS record: record_length %u, bytes_processed %u",
2771  ssl_state->curr_connp->record_length, ssl_state->curr_connp->bytes_processed);
2772  }
2773  struct SSLDecoderResult r =
2774  SSLv3Decode(direction, ssl_state, pstate, input, input_len, stream_slice);
2775  if (r.retval < 0 || r.retval > input_len) {
2776  DEBUG_VALIDATE_BUG_ON(r.retval > input_len);
2777  SCLogDebug("Error parsing TLS. Resetting parser "
2778  "state. Let's get outta here");
2779  SSLParserReset(ssl_state);
2780  return APP_LAYER_ERROR;
2781  } else if (r.needed) {
2782  input += r.retval;
2783  SCLogDebug("returning consumed %" PRIuMAX " needed %u",
2784  (uintmax_t)(input - init_input), r.needed);
2785  SCReturnStruct(APP_LAYER_INCOMPLETE((uint32_t)(input - init_input), r.needed));
2786  }
2787  input_len -= r.retval;
2788  input += r.retval;
2789  SCLogDebug("TLS decoder consumed %d bytes: %u left", r.retval, input_len);
2790 
2792  && ssl_state->curr_connp->record_length == 0) {
2793  SCLogDebug("TLS empty record");
2794  /* empty record */
2795  SSLParserReset(ssl_state);
2796  }
2797  }
2798  counter++;
2799  } /* while (input_len) */
2800 
2801  /* mark handshake as done if we have subject and issuer */
2802  if ((ssl_state->flags & SSL_AL_FLAG_NEED_CLIENT_CERT) &&
2803  ssl_state->client_connp.cert0_subject && ssl_state->client_connp.cert0_issuerdn) {
2804  /* update both sides to keep existing behavior */
2805  UpdateClientState(ssl_state, TLS_STATE_CLIENT_HANDSHAKE_DONE);
2806  UpdateServerState(ssl_state, TLS_STATE_SERVER_HANDSHAKE_DONE);
2807  } else if ((ssl_state->flags & SSL_AL_FLAG_NEED_CLIENT_CERT) == 0 &&
2808  ssl_state->server_connp.cert0_subject && ssl_state->server_connp.cert0_issuerdn) {
2809  /* update both sides to keep existing behavior */
2810  UpdateClientState(ssl_state, TLS_STATE_CLIENT_HANDSHAKE_DONE);
2811  UpdateServerState(ssl_state, TLS_STATE_SERVER_HANDSHAKE_DONE);
2812  }
2813 
2814  /* flag session as finished if APP_LAYER_PARSER_EOF is set */
2815  if (SCAppLayerParserStateIssetFlag(pstate, APP_LAYER_PARSER_EOF_TS) &&
2816  SCAppLayerParserStateIssetFlag(pstate, APP_LAYER_PARSER_EOF_TC)) {
2817  /* update both sides to keep existing behavior */
2818  UpdateClientState(ssl_state, TLS_STATE_CLIENT_FINISHED);
2819  UpdateServerState(ssl_state, TLS_STATE_SERVER_FINISHED);
2820  }
2821 
2822  return APP_LAYER_OK;
2823 }
2824 
2825 static AppLayerResult SSLParseClientRecord(Flow *f, void *alstate, AppLayerParserState *pstate,
2826  StreamSlice stream_slice, void *local_data)
2827 {
2828  return SSLDecode(f, 0 /* toserver */, alstate, pstate, stream_slice);
2829 }
2830 
2831 static AppLayerResult SSLParseServerRecord(Flow *f, void *alstate, AppLayerParserState *pstate,
2832  StreamSlice stream_slice, void *local_data)
2833 {
2834  return SSLDecode(f, 1 /* toclient */, alstate, pstate, stream_slice);
2835 }
2836 
2837 /**
2838  * \internal
2839  * \brief Function to allocate the SSL state memory.
2840  */
2841 static void *SSLStateAlloc(void *orig_state, AppProto proto_orig)
2842 {
2843  SSLState *ssl_state = SCCalloc(1, sizeof(SSLState));
2844  if (unlikely(ssl_state == NULL))
2845  return NULL;
2846  TAILQ_INIT(&ssl_state->server_connp.certs);
2847  TAILQ_INIT(&ssl_state->client_connp.certs);
2848 
2849  return (void *)ssl_state;
2850 }
2851 
2852 static void SSLStateCertSANFree(SSLStateConnp *connp)
2853 {
2854  if (connp->cert0_sans) {
2855  for (uint16_t i = 0; i < connp->cert0_sans_num; i++) {
2856  SCX509ArrayFree(connp->cert0_sans[i].san, connp->cert0_sans[i].san_len);
2857  }
2858  SCFree(connp->cert0_sans);
2859  }
2860 }
2861 
2862 /**
2863  * \internal
2864  * \brief Function to free the SSL state memory.
2865  */
2866 static void SSLStateFree(void *p)
2867 {
2868  SSLState *ssl_state = (SSLState *)p;
2869  SSLCertsChain *item;
2870 
2871  if (ssl_state->client_connp.cert0_subject)
2872  SCX509ArrayFree(
2873  ssl_state->client_connp.cert0_subject, ssl_state->client_connp.cert0_subject_len);
2874  if (ssl_state->client_connp.cert0_issuerdn)
2875  SCX509ArrayFree(
2877  if (ssl_state->client_connp.cert0_serial)
2878  SCX509ArrayFree(
2879  ssl_state->client_connp.cert0_serial, ssl_state->client_connp.cert0_serial_len);
2880  if (ssl_state->client_connp.cert0_fingerprint)
2882  if (ssl_state->client_connp.sni)
2883  SCFree(ssl_state->client_connp.sni);
2884  if (ssl_state->client_connp.session_id)
2885  SCFree(ssl_state->client_connp.session_id);
2886  if (ssl_state->client_connp.hs_buffer)
2887  SCFree(ssl_state->client_connp.hs_buffer);
2888 
2889  if (ssl_state->server_connp.cert0_subject)
2890  SCX509ArrayFree(
2891  ssl_state->server_connp.cert0_subject, ssl_state->server_connp.cert0_subject_len);
2892  if (ssl_state->server_connp.cert0_issuerdn)
2893  SCX509ArrayFree(
2895  if (ssl_state->server_connp.cert0_serial)
2896  SCX509ArrayFree(
2897  ssl_state->server_connp.cert0_serial, ssl_state->server_connp.cert0_serial_len);
2898  if (ssl_state->server_connp.cert0_fingerprint)
2900  if (ssl_state->server_connp.sni)
2901  SCFree(ssl_state->server_connp.sni);
2902  if (ssl_state->server_connp.session_id)
2903  SCFree(ssl_state->server_connp.session_id);
2904 
2905  if (ssl_state->client_connp.hs)
2906  SCTLSHandshakeFree(ssl_state->client_connp.hs);
2907  if (ssl_state->client_connp.ja3_str)
2908  Ja3BufferFree(&ssl_state->client_connp.ja3_str);
2909  if (ssl_state->client_connp.ja3_hash)
2910  SCFree(ssl_state->client_connp.ja3_hash);
2911  if (ssl_state->server_connp.hs)
2912  SCTLSHandshakeFree(ssl_state->server_connp.hs);
2913  if (ssl_state->server_connp.ja3_str)
2914  Ja3BufferFree(&ssl_state->server_connp.ja3_str);
2915  if (ssl_state->server_connp.ja3_hash)
2916  SCFree(ssl_state->server_connp.ja3_hash);
2917  if (ssl_state->server_connp.hs_buffer)
2918  SCFree(ssl_state->server_connp.hs_buffer);
2919 
2920  SSLStateCertSANFree(&ssl_state->server_connp);
2921  SSLStateCertSANFree(&ssl_state->client_connp);
2922 
2923  SCAppLayerTxDataCleanup(&ssl_state->tx_data);
2924 
2925  /* Free certificate chain */
2926  if (ssl_state->server_connp.certs_buffer)
2927  SCFree(ssl_state->server_connp.certs_buffer);
2928  while ((item = TAILQ_FIRST(&ssl_state->server_connp.certs))) {
2929  TAILQ_REMOVE(&ssl_state->server_connp.certs, item, next);
2930  SCFree(item);
2931  }
2932  TAILQ_INIT(&ssl_state->server_connp.certs);
2933  /* Free certificate chain */
2934  if (ssl_state->client_connp.certs_buffer)
2935  SCFree(ssl_state->client_connp.certs_buffer);
2936  while ((item = TAILQ_FIRST(&ssl_state->client_connp.certs))) {
2937  TAILQ_REMOVE(&ssl_state->client_connp.certs, item, next);
2938  SCFree(item);
2939  }
2940  TAILQ_INIT(&ssl_state->client_connp.certs);
2941 
2942  SCFree(ssl_state);
2943 }
2944 
2945 static void SSLStateTransactionFree(void *state, uint64_t tx_id)
2946 {
2947  /* do nothing */
2948 }
2949 
2950 static AppProto SSLProbingParser(
2951  const Flow *f, uint8_t direction, const uint8_t *input, uint32_t ilen, uint8_t *rdir)
2952 {
2953  /* probably a rst/fin sending an eof */
2954  if (ilen < 3)
2955  return ALPROTO_UNKNOWN;
2956 
2957  /* for now just the 3 byte header ones */
2958  /* \todo Detect the 2 byte ones */
2959  if ((input[0] & 0x80) && (input[2] == 0x01)) {
2960  return ALPROTO_TLS;
2961  }
2962 
2963  return ALPROTO_FAILED;
2964 }
2965 
2966 static int SSLStateGetStateIdByName(const char *name, const uint8_t direction)
2967 {
2968  SCEnumCharMap *map =
2969  direction == STREAM_TOSERVER ? tls_state_client_table : tls_state_server_table;
2970 
2971  int id = SCMapEnumNameToValue(name, map);
2972  if (id < 0) {
2973  return -1;
2974  }
2975  return id;
2976 }
2977 
2978 static const char *SSLStateGetStateNameById(const int id, const uint8_t direction)
2979 {
2980  SCEnumCharMap *map =
2981  direction == STREAM_TOSERVER ? tls_state_client_table : tls_state_server_table;
2982  const char *name = SCMapEnumValueToName(id, map);
2983  return name;
2984 }
2985 
2986 static int SSLStateGetFrameIdByName(const char *frame_name)
2987 {
2988  int id = SCMapEnumNameToValue(frame_name, tls_frame_table);
2989  if (id < 0) {
2990  return -1;
2991  }
2992  return id;
2993 }
2994 
2995 static const char *SSLStateGetFrameNameById(const uint8_t frame_id)
2996 {
2997  const char *name = SCMapEnumValueToName(frame_id, tls_frame_table);
2998  return name;
2999 }
3000 
3001 static int SSLStateGetEventInfo(
3002  const char *event_name, uint8_t *event_id, AppLayerEventType *event_type)
3003 {
3004  if (SCAppLayerGetEventIdByName(event_name, tls_decoder_event_table, event_id) == 0) {
3005  *event_type = APP_LAYER_EVENT_TYPE_TRANSACTION;
3006  return 0;
3007  }
3008  return -1;
3009 }
3010 
3011 static int SSLStateGetEventInfoById(
3012  uint8_t event_id, const char **event_name, AppLayerEventType *event_type)
3013 {
3014  *event_name = SCMapEnumValueToName(event_id, tls_decoder_event_table);
3015  if (*event_name == NULL) {
3016  SCLogError("event \"%d\" not present in "
3017  "ssl's enum map table.",
3018  event_id);
3019  /* yes this is fatal */
3020  return -1;
3021  }
3022 
3023  *event_type = APP_LAYER_EVENT_TYPE_TRANSACTION;
3024 
3025  return 0;
3026 }
3027 
3028 static int SSLRegisterPatternsForProtocolDetection(void)
3029 {
3030  if (SCAppLayerProtoDetectPMRegisterPatternCSwPP(IPPROTO_TCP, ALPROTO_TLS, "|01 00 02|", 5, 2,
3031  STREAM_TOSERVER, SSLProbingParser, 0, 3) < 0) {
3032  return -1;
3033  }
3034 
3035  /** SSLv3 */
3037  IPPROTO_TCP, ALPROTO_TLS, "|01 03 00|", 3, 0, STREAM_TOSERVER) < 0) {
3038  return -1;
3039  }
3041  IPPROTO_TCP, ALPROTO_TLS, "|16 03 00|", 3, 0, STREAM_TOSERVER) < 0) {
3042  return -1;
3043  }
3044 
3045  /** TLSv1 */
3047  IPPROTO_TCP, ALPROTO_TLS, "|01 03 01|", 3, 0, STREAM_TOSERVER) < 0) {
3048  return -1;
3049  }
3051  IPPROTO_TCP, ALPROTO_TLS, "|16 03 01|", 3, 0, STREAM_TOSERVER) < 0) {
3052  return -1;
3053  }
3054 
3055  /** TLSv1.1 */
3057  IPPROTO_TCP, ALPROTO_TLS, "|01 03 02|", 3, 0, STREAM_TOSERVER) < 0) {
3058  return -1;
3059  }
3061  IPPROTO_TCP, ALPROTO_TLS, "|16 03 02|", 3, 0, STREAM_TOSERVER) < 0) {
3062  return -1;
3063  }
3064 
3065  /** TLSv1.2 */
3067  IPPROTO_TCP, ALPROTO_TLS, "|01 03 03|", 3, 0, STREAM_TOSERVER) < 0) {
3068  return -1;
3069  }
3071  IPPROTO_TCP, ALPROTO_TLS, "|16 03 03|", 3, 0, STREAM_TOSERVER) < 0) {
3072  return -1;
3073  }
3074 
3075  /***** toclient direction *****/
3076 
3078  IPPROTO_TCP, ALPROTO_TLS, "|15 03 00|", 3, 0, STREAM_TOCLIENT) < 0) {
3079  return -1;
3080  }
3082  IPPROTO_TCP, ALPROTO_TLS, "|16 03 00|", 3, 0, STREAM_TOCLIENT) < 0) {
3083  return -1;
3084  }
3086  IPPROTO_TCP, ALPROTO_TLS, "|17 03 00|", 3, 0, STREAM_TOCLIENT) < 0) {
3087  return -1;
3088  }
3089 
3090  /** TLSv1 */
3092  IPPROTO_TCP, ALPROTO_TLS, "|15 03 01|", 3, 0, STREAM_TOCLIENT) < 0) {
3093  return -1;
3094  }
3096  IPPROTO_TCP, ALPROTO_TLS, "|16 03 01|", 3, 0, STREAM_TOCLIENT) < 0) {
3097  return -1;
3098  }
3100  IPPROTO_TCP, ALPROTO_TLS, "|17 03 01|", 3, 0, STREAM_TOCLIENT) < 0) {
3101  return -1;
3102  }
3103 
3104  /** TLSv1.1 */
3106  IPPROTO_TCP, ALPROTO_TLS, "|15 03 02|", 3, 0, STREAM_TOCLIENT) < 0) {
3107  return -1;
3108  }
3110  IPPROTO_TCP, ALPROTO_TLS, "|16 03 02|", 3, 0, STREAM_TOCLIENT) < 0) {
3111  return -1;
3112  }
3114  IPPROTO_TCP, ALPROTO_TLS, "|17 03 02|", 3, 0, STREAM_TOCLIENT) < 0) {
3115  return -1;
3116  }
3117 
3118  /** TLSv1.2 */
3120  IPPROTO_TCP, ALPROTO_TLS, "|15 03 03|", 3, 0, STREAM_TOCLIENT) < 0) {
3121  return -1;
3122  }
3124  IPPROTO_TCP, ALPROTO_TLS, "|16 03 03|", 3, 0, STREAM_TOCLIENT) < 0) {
3125  return -1;
3126  }
3128  IPPROTO_TCP, ALPROTO_TLS, "|17 03 03|", 3, 0, STREAM_TOCLIENT) < 0) {
3129  return -1;
3130  }
3131 
3132  /* Subsection - SSLv2 style record by client, but informing the server
3133  * the max version it supports.
3134  * Updated by Anoop Saldanha. Disabled it for now. We'll get back to
3135  * it after some tests */
3136 #if 0
3138  "|01 03 00|", 5, 2, STREAM_TOSERVER) < 0)
3139  {
3140  return -1;
3141  }
3143  "|00 02|", 7, 5, STREAM_TOCLIENT) < 0)
3144  {
3145  return -1;
3146  }
3147 #endif
3148 
3149  return 0;
3150 }
3151 
3152 #ifdef HAVE_JA3
3153 static void CheckJA3Enabled(void)
3154 {
3155  const char *strval = NULL;
3156  /* Check if we should generate JA3 fingerprints */
3157  int enable_ja3 = SSL_CONFIG_DEFAULT_JA3;
3158  if (SCConfGetNonNull("app-layer.protocols.tls.ja3-fingerprints", &strval) != 1) {
3159  enable_ja3 = SSL_CONFIG_DEFAULT_JA3;
3160  } else if (strcmp(strval, "auto") == 0) {
3161  enable_ja3 = SSL_CONFIG_DEFAULT_JA3;
3162  } else if (SCConfValIsFalse(strval)) {
3163  enable_ja3 = 0;
3164  ssl_config.disable_ja3 = true;
3165  } else if (SCConfValIsTrue(strval)) {
3166  enable_ja3 = true;
3167  }
3168  SC_ATOMIC_SET(ssl_config.enable_ja3, enable_ja3);
3170  /* The feature is available, i.e. _could_ be activated by a rule or
3171  even is enabled in the configuration. */
3173  }
3174 }
3175 #endif /* HAVE_JA3 */
3176 
3177 #ifdef HAVE_JA4
3178 static void CheckJA4Enabled(void)
3179 {
3180  const char *strval = NULL;
3181  /* Check if we should generate JA4 fingerprints */
3182  int enable_ja4 = SSL_CONFIG_DEFAULT_JA4;
3183  if (SCConfGetNonNull("app-layer.protocols.tls.ja4-fingerprints", &strval) != 1) {
3184  enable_ja4 = SSL_CONFIG_DEFAULT_JA4;
3185  } else if (strcmp(strval, "auto") == 0) {
3186  enable_ja4 = SSL_CONFIG_DEFAULT_JA4;
3187  } else if (SCConfValIsFalse(strval)) {
3188  enable_ja4 = 0;
3189  ssl_config.disable_ja4 = true;
3190  } else if (SCConfValIsTrue(strval)) {
3191  enable_ja4 = true;
3192  }
3193  SC_ATOMIC_SET(ssl_config.enable_ja4, enable_ja4);
3195  /* The feature is available, i.e. _could_ be activated by a rule or
3196  even is enabled in the configuration. */
3198  }
3199 }
3200 #endif /* HAVE_JA4 */
3201 
3202 /**
3203  * \brief Function to register the SSL protocol parser and other functions
3204  */
3206 {
3207  const char *proto_name = "tls";
3208 
3209  SC_ATOMIC_INIT(ssl_config.enable_ja3);
3210 
3211  /** SSLv2 and SSLv23*/
3212  if (SCAppLayerProtoDetectConfProtoDetectionEnabled("tcp", proto_name)) {
3214 
3215  if (SSLRegisterPatternsForProtocolDetection() < 0)
3216  return;
3217 
3218  if (RunmodeIsUnittests()) {
3220  IPPROTO_TCP, "443", ALPROTO_TLS, 0, 3, STREAM_TOSERVER, SSLProbingParser, NULL);
3221  } else {
3222  if (SCAppLayerProtoDetectPPParseConfPorts("tcp", IPPROTO_TCP, proto_name, ALPROTO_TLS,
3223  0, 3, SSLProbingParser, NULL) == 0) {
3224  SCLogConfig("no TLS config found, "
3225  "enabling TLS detection on port 443.");
3226  SCAppLayerProtoDetectPPRegister(IPPROTO_TCP, "443", ALPROTO_TLS, 0, 3,
3227  STREAM_TOSERVER, SSLProbingParser, NULL);
3228  }
3229  }
3230  } else {
3231  SCLogConfig("Protocol detection and parser disabled for %s protocol",
3232  proto_name);
3233  return;
3234  }
3235 
3236  if (SCAppLayerParserConfParserEnabled("tcp", proto_name)) {
3237  AppLayerParserRegisterParser(IPPROTO_TCP, ALPROTO_TLS, STREAM_TOSERVER,
3238  SSLParseClientRecord);
3239 
3240  AppLayerParserRegisterParser(IPPROTO_TCP, ALPROTO_TLS, STREAM_TOCLIENT,
3241  SSLParseServerRecord);
3243  IPPROTO_TCP, ALPROTO_TLS, SSLStateGetStateIdByName, SSLStateGetStateNameById);
3245  IPPROTO_TCP, ALPROTO_TLS, SSLStateGetFrameIdByName, SSLStateGetFrameNameById);
3246  AppLayerParserRegisterGetEventInfo(IPPROTO_TCP, ALPROTO_TLS, SSLStateGetEventInfo);
3247  AppLayerParserRegisterGetEventInfoById(IPPROTO_TCP, ALPROTO_TLS, SSLStateGetEventInfoById);
3248 
3249  AppLayerParserRegisterStateFuncs(IPPROTO_TCP, ALPROTO_TLS, SSLStateAlloc, SSLStateFree);
3250 
3252  IPPROTO_TCP, ALPROTO_TLS, STREAM_TOSERVER);
3253 
3254  AppLayerParserRegisterTxFreeFunc(IPPROTO_TCP, ALPROTO_TLS, SSLStateTransactionFree);
3255 
3256  AppLayerParserRegisterGetTx(IPPROTO_TCP, ALPROTO_TLS, SSLGetTx);
3257  AppLayerParserRegisterTxDataFunc(IPPROTO_TCP, ALPROTO_TLS, SSLGetTxData);
3258  AppLayerParserRegisterStateDataFunc(IPPROTO_TCP, ALPROTO_TLS, SSLGetStateData);
3259 
3260  AppLayerParserRegisterGetTxCnt(IPPROTO_TCP, ALPROTO_TLS, SSLGetTxCnt);
3261 
3262  AppLayerParserRegisterGetStateProgressFunc(IPPROTO_TCP, ALPROTO_TLS, SSLGetAlstateProgress);
3263 
3266 
3267  SCConfNode *enc_handle = SCConfGetNode("app-layer.protocols.tls.encryption-handling");
3268  if (enc_handle != NULL && enc_handle->val != NULL) {
3269  SCLogDebug("have app-layer.protocols.tls.encryption-handling = %s", enc_handle->val);
3270  if (strcmp(enc_handle->val, "full") == 0) {
3272  } else if (strcmp(enc_handle->val, "bypass") == 0) {
3274  } else if (strcmp(enc_handle->val, "track-only") == 0) {
3276  } else if (strcmp(enc_handle->val, "default") == 0) {
3277  SCLogWarning("app-layer.protocols.tls.encryption-handling = default is deprecated "
3278  "and will be removed in Suricata 9, use \"track-only\" instead, "
3279  "(see ticket #7642)");
3281  } else {
3283  }
3284  } else {
3285  /* Get the value of no reassembly option from the config file */
3286  if (SCConfGetNode("app-layer.protocols.tls.no-reassemble") == NULL) {
3287  int value = 0;
3288  if (SCConfGetBool("tls.no-reassemble", &value) == 1 && value == 1)
3290  } else {
3291  int value = 0;
3292  if (SCConfGetBool("app-layer.protocols.tls.no-reassemble", &value) == 1 &&
3293  value == 1)
3295  }
3296  }
3297  SCLogDebug("ssl_config.encrypt_mode %u", ssl_config.encrypt_mode);
3298 
3299 #ifdef HAVE_JA3
3300  CheckJA3Enabled();
3301 #endif /* HAVE_JA3 */
3302 #ifdef HAVE_JA4
3303  CheckJA4Enabled();
3304 #endif /* HAVE_JA4 */
3305 
3306  if (g_disable_hashing) {
3307  if (SC_ATOMIC_GET(ssl_config.enable_ja3)) {
3308  SCLogWarning("MD5 calculation has been disabled, disabling JA3");
3309  SC_ATOMIC_SET(ssl_config.enable_ja3, 0);
3310  }
3311  if (SC_ATOMIC_GET(ssl_config.enable_ja4)) {
3312  SCLogWarning("Hashing has been disabled, disabling JA4");
3313  SC_ATOMIC_SET(ssl_config.enable_ja4, 0);
3314  }
3315  } else {
3316  if (RunmodeIsUnittests()) {
3317 #ifdef HAVE_JA3
3318  SC_ATOMIC_SET(ssl_config.enable_ja3, 1);
3319 #endif /* HAVE_JA3 */
3320 #ifdef HAVE_JA4
3321  SC_ATOMIC_SET(ssl_config.enable_ja4, 1);
3322 #endif /* HAVE_JA4 */
3323  }
3324  }
3325  } else {
3326  SCLogConfig("Parser disabled for %s protocol. Protocol detection still on.", proto_name);
3327  }
3328 }
3329 
3330 /**
3331  * \brief if not explicitly disabled in config, enable ja3 support
3332  *
3333  * Implemented using atomic to allow rule reloads to do this at
3334  * runtime.
3335  */
3336 void SSLEnableJA3(void)
3337 {
3339  return;
3340  }
3341  if (SC_ATOMIC_GET(ssl_config.enable_ja3)) {
3342  return;
3343  }
3344  SC_ATOMIC_SET(ssl_config.enable_ja3, 1);
3345 }
3346 
3347 /**
3348  * \brief if not explicitly disabled in config, enable ja4 support
3349  *
3350  * Implemented using atomic to allow rule reloads to do this at
3351  * runtime.
3352  */
3353 void SSLEnableJA4(void)
3354 {
3355  // only caller has #ifdef HAVE_JA4
3357  return;
3358  }
3359  if (SC_ATOMIC_GET(ssl_config.enable_ja4)) {
3360  return;
3361  }
3362  SC_ATOMIC_SET(ssl_config.enable_ja4, 1);
3363 }
3364 
3365 /**
3366  * \brief return whether ja3 is effectively enabled
3367  *
3368  * This means that it either has been enabled explicitly or has been
3369  * enabled by having loaded a rule while not being explicitly disabled.
3370  *
3371  * \retval true if enabled, false otherwise
3372  */
3374 {
3375  return SC_ATOMIC_GET(ssl_config.enable_ja3);
3376 }
3377 
3378 /**
3379  * \brief return whether ja4 is effectively enabled
3380  *
3381  * This means that it either has been enabled explicitly or has been
3382  * enabled by having loaded a rule while not being explicitly disabled.
3383  *
3384  * \retval true if enabled, false otherwise
3385  */
3387 {
3388  return SC_ATOMIC_GET(ssl_config.enable_ja4);
3389 }
SSLV3_CHANGE_CIPHER_SPEC
#define SSLV3_CHANGE_CIPHER_SPEC
Definition: app-layer-ssl.c:214
ERR_INVALID_SERIAL
@ ERR_INVALID_SERIAL
Definition: app-layer-ssl.c:176
tls_frame_table
SCEnumCharMap tls_frame_table[]
Definition: app-layer-ssl.c:99
StreamSlice
Definition: app-layer-parser.h:120
TLS_DECODER_EVENT_CERTIFICATE_INVALID_ISSUER
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_ISSUER
Definition: app-layer-ssl.h:72
AppLayerParserRegisterGetStateProgressFunc
void AppLayerParserRegisterGetStateProgressFunc(uint8_t ipproto, AppProto alproto, int(*StateGetProgress)(void *alstate, uint8_t direction))
Definition: app-layer-parser.c:536
SSLState_
SSLv[2.0|3.[0|1|2|3]] state structure.
Definition: app-layer-ssl.h:238
SslConfig_::disable_ja3
bool disable_ja3
Definition: app-layer-ssl.c:206
SSL_EXTENSION_EC_POINT_FORMATS
#define SSL_EXTENSION_EC_POINT_FORMATS
Definition: app-layer-ssl.h:150
SSLSubjectAltName_::san_len
uint32_t san_len
Definition: app-layer-ssl.h:171
SCConfValIsTrue
int SCConfValIsTrue(const char *val)
Check if a value is true.
Definition: conf.c:578
SCAppLayerParserStateIssetFlag
uint16_t SCAppLayerParserStateIssetFlag(AppLayerParserState *pstate, uint16_t flag)
Definition: app-layer-parser.c:2105
JA3Buffer_
Definition: util-ja3.h:31
TLS_DECODER_EVENT_DATALEAK_HEARTBEAT_MISMATCH
@ TLS_DECODER_EVENT_DATALEAK_HEARTBEAT_MISMATCH
Definition: app-layer-ssl.h:54
SSLCertsChain_::cert_len
uint32_t cert_len
Definition: app-layer-ssl.h:165
TLS_DECODER_EVENT_HEARTBEAT
@ TLS_DECODER_EVENT_HEARTBEAT
Definition: app-layer-ssl.h:51
TLS_HB_RESPONSE
#define TLS_HB_RESPONSE
Definition: app-layer-ssl.c:255
SHA1_STRING_LENGTH
#define SHA1_STRING_LENGTH
Definition: app-layer-ssl.c:259
TAILQ_INIT
#define TAILQ_INIT(head)
Definition: queue.h:262
TLS_DECODER_EVENT_OVERFLOW_HEARTBEAT
@ TLS_DECODER_EVENT_OVERFLOW_HEARTBEAT
Definition: app-layer-ssl.h:53
SC_ATOMIC_INIT
#define SC_ATOMIC_INIT(name)
wrapper for initializing an atomic variable.
Definition: util-atomic.h:314
TLS_DECODER_EVENT_TOO_MANY_SUBJECT_ALTERNATIVE_NAMES
@ TLS_DECODER_EVENT_TOO_MANY_SUBJECT_ALTERNATIVE_NAMES
Definition: app-layer-ssl.h:75
TLS_DECODER_EVENT_ERROR_MSG_ENCOUNTERED
@ TLS_DECODER_EVENT_ERROR_MSG_ENCOUNTERED
Definition: app-layer-ssl.h:74
ERR_EXTRACT_SUBJECT
@ ERR_EXTRACT_SUBJECT
Definition: app-layer-ssl.c:184
SSLV3_HS_FINISHED
#define SSLV3_HS_FINISHED
Definition: app-layer-ssl.c:231
SSLState_::hb_record_len
uint32_t hb_record_len
Definition: app-layer-ssl.h:248
unlikely
#define unlikely(expr)
Definition: util-optimize.h:35
SSL_EXTENSION_ELLIPTIC_CURVES
#define SSL_EXTENSION_ELLIPTIC_CURVES
Definition: app-layer-ssl.h:149
SC_ATOMIC_SET
#define SC_ATOMIC_SET(name, val)
Set the value for the atomic variable.
Definition: util-atomic.h:386
SSLStateConnp_::message_length
uint32_t message_length
Definition: app-layer-ssl.h:181
SSLState_::client_connp
SSLStateConnp client_connp
Definition: app-layer-ssl.h:259
TLS_DECODER_EVENT_INVALID_HANDSHAKE_MESSAGE
@ TLS_DECODER_EVENT_INVALID_HANDSHAKE_MESSAGE
Definition: app-layer-ssl.h:50
TLS_FRAME_DATA
@ TLS_FRAME_DATA
Definition: app-layer-ssl.h:36
ALPROTO_TLS
@ ALPROTO_TLS
Definition: app-layer-protos.h:39
SSLEnableJA4
void SSLEnableJA4(void)
if not explicitly disabled in config, enable ja4 support
Definition: app-layer-ssl.c:3353
SCLogDebug
#define SCLogDebug(...)
Definition: util-debug.h:282
SSL_AL_FLAG_EARLY_DATA
#define SSL_AL_FLAG_EARLY_DATA
Definition: app-layer-ssl.h:134
SSLStateConnp_::bytes_processed
uint32_t bytes_processed
Definition: app-layer-ssl.h:189
SCAppLayerTxDataCleanup
void SCAppLayerTxDataCleanup(AppLayerTxData *txd)
Definition: app-layer-parser.c:823
next
struct HtpBodyChunk_ * next
Definition: app-layer-htp.h:0
SSLV2_MT_SERVER_FINISHED
#define SSLV2_MT_SERVER_FINISHED
Definition: app-layer-ssl.c:242
SSLState_::server_connp
SSLStateConnp server_connp
Definition: app-layer-ssl.h:260
SSLStateConnp_::cert0_not_before
int64_t cert0_not_before
Definition: app-layer-ssl.h:200
name
const char * name
Definition: detect-engine-proto.c:48
SSL_AL_FLAG_SESSION_RESUMED
#define SSL_AL_FLAG_SESSION_RESUMED
Definition: app-layer-ssl.h:123
AppProto
uint16_t AppProto
Definition: app-layer-protos.h:87
ValidateRecordState
#define ValidateRecordState(...)
Definition: app-layer-ssl.c:310
SSLStateConnp_
Definition: app-layer-ssl.h:174
SSLStateConnp_::ja3_hash
char * ja3_hash
Definition: app-layer-ssl.h:220
SSL_CONFIG_DEFAULT_JA3
#define SSL_CONFIG_DEFAULT_JA3
Definition: app-layer-ssl.c:190
type
uint8_t type
Definition: decode-sctp.h:0
SCAppLayerParserStateSetFlag
void SCAppLayerParserStateSetFlag(AppLayerParserState *pstate, uint16_t flag)
Definition: app-layer-parser.c:2097
SSLStateConnp_::session_id_length
uint16_t session_id_length
Definition: app-layer-ssl.h:191
AppLayerStateData
Definition: app-layer-parser.h:149
tls_decoder_event_table
SCEnumCharMap tls_decoder_event_table[]
Definition: app-layer-ssl.c:131
Flow_
Flow data structure.
Definition: flow.h:355
SSL_EXTENSION_SUPPORTED_VERSIONS
#define SSL_EXTENSION_SUPPORTED_VERSIONS
Definition: app-layer-ssl.h:155
SSLState_::f
Flow * f
Definition: app-layer-ssl.h:239
SSL_AL_FLAG_STATE_SERVER_HELLO
#define SSL_AL_FLAG_STATE_SERVER_HELLO
Definition: app-layer-ssl.h:112
SC_SHA1_LEN
#define SC_SHA1_LEN
Definition: util-file.h:107
SSLV3_HS_SERVER_HELLO
#define SSLV3_HS_SERVER_HELLO
Definition: app-layer-ssl.c:223
AppLayerParserRegisterStateProgressCompletionStatus
void AppLayerParserRegisterStateProgressCompletionStatus(AppProto alproto, const int ts, const int tc)
Definition: app-layer-parser.c:584
SSLState_::tx_data
AppLayerTxData tx_data
Definition: app-layer-ssl.h:242
SSLParserHSReset
#define SSLParserHSReset(connp)
Definition: app-layer-ssl.c:313
SSLV3_HS_CERTIFICATE
#define SSLV3_HS_CERTIFICATE
Definition: app-layer-ssl.c:225
ERR_INVALID_X509NAME
@ ERR_INVALID_X509NAME
Definition: app-layer-ssl.c:178
AppLayerParserRegisterTxFreeFunc
void AppLayerParserRegisterTxFreeFunc(uint8_t ipproto, AppProto alproto, void(*StateTransactionFree)(void *, uint64_t))
Definition: app-layer-parser.c:546
SSLV3_HEARTBEAT_PROTOCOL
#define SSLV3_HEARTBEAT_PROTOCOL
Definition: app-layer-ssl.c:218
SSLV2_MT_SERVER_HELLO
#define SSLV2_MT_SERVER_HELLO
Definition: app-layer-ssl.c:240
SSLState_::curr_connp
SSLStateConnp * curr_connp
Definition: app-layer-ssl.h:254
Ja3BufferAddValue
int Ja3BufferAddValue(JA3Buffer **buffer, uint32_t value)
Definition: util-ja3.c:314
SSLV3_HS_CERTIFICATE_URL
#define SSLV3_HS_CERTIFICATE_URL
Definition: app-layer-ssl.c:232
TLS_STATE_SERVER_HELLO_DONE
@ TLS_STATE_SERVER_HELLO_DONE
Definition: app-layer-ssl.h:91
MIN
#define MIN(x, y)
Definition: suricata-common.h:416
SCConfGetBool
int SCConfGetBool(const char *name, int *val)
Retrieve a configuration value as a boolean.
Definition: conf.c:524
AppLayerParserRegisterGetStateFuncs
void AppLayerParserRegisterGetStateFuncs(uint8_t ipproto, AppProto alproto, AppLayerParserGetStateIdByNameFn GetIdByNameFunc, AppLayerParserGetStateNameByIdFn GetNameByIdFunc)
Definition: app-layer-parser.c:643
util-ja3.h
SCConfValIsFalse
int SCConfValIsFalse(const char *val)
Check if a value is false.
Definition: conf.c:603
ERR_INVALID_ALGORITHMIDENTIFIER
@ ERR_INVALID_ALGORITHMIDENTIFIER
Definition: app-layer-ssl.c:177
SSL_AL_FLAG_STATE_SERVER_KEYX
#define SSL_AL_FLAG_STATE_SERVER_KEYX
Definition: app-layer-ssl.h:114
SSLState_::state_data
AppLayerStateData state_data
Definition: app-layer-ssl.h:241
TAILQ_INSERT_TAIL
#define TAILQ_INSERT_TAIL(head, elm, field)
Definition: queue.h:294
p
Packet * p
Definition: fuzz_iprep.c:21
SSLV3_HS_CERTIFICATE_VERIFY
#define SSLV3_HS_CERTIFICATE_VERIFY
Definition: app-layer-ssl.c:229
TLS_DECODER_EVENT_INVALID_TLS_HEADER
@ TLS_DECODER_EVENT_INVALID_TLS_HEADER
Definition: app-layer-ssl.h:46
SSL_CNF_ENC_HANDLE_TRACK_ONLY
@ SSL_CNF_ENC_HANDLE_TRACK_ONLY
Definition: app-layer-ssl.c:196
MAX
#define MAX(x, y)
Definition: suricata-common.h:420
SSLStateConnp_::hs_buffer_message_type
uint8_t hs_buffer_message_type
Definition: app-layer-ssl.h:227
TLS_DECODER_EVENT_INVALID_SSL_RECORD
@ TLS_DECODER_EVENT_INVALID_SSL_RECORD
Definition: app-layer-ssl.h:76
TLS_DECODER_EVENT_TOO_MANY_RECORDS_IN_PACKET
@ TLS_DECODER_EVENT_TOO_MANY_RECORDS_IN_PACKET
Definition: app-layer-ssl.h:59
TLS_DECODER_EVENT_MULTIPLE_SNI_EXTENSIONS
@ TLS_DECODER_EVENT_MULTIPLE_SNI_EXTENSIONS
Definition: app-layer-ssl.h:56
SSLStateConnp_::record_lengths_length
uint32_t record_lengths_length
Definition: app-layer-ssl.h:178
SSLSubjectAltName_::san
uint8_t * san
Definition: app-layer-ssl.h:170
TLS_FRAME_SSLV2_HDR
@ TLS_FRAME_SSLV2_HDR
Definition: app-layer-ssl.h:39
SSL_AL_FLAG_CHANGE_CIPHER_SPEC
#define SSL_AL_FLAG_CHANGE_CIPHER_SPEC
Definition: app-layer-ssl.h:100
SCAppLayerProtoDetectPMRegisterPatternCSwPP
int SCAppLayerProtoDetectPMRegisterPatternCSwPP(uint8_t ipproto, AppProto alproto, const char *pattern, uint16_t depth, uint16_t offset, uint8_t direction, ProbingParserFPtr PPFunc, uint16_t pp_min_depth, uint16_t pp_max_depth)
Definition: app-layer-detect-proto.c:1651
ERR_INVALID_DATE
@ ERR_INVALID_DATE
Definition: app-layer-ssl.c:179
SSLStateConnp_::hs_buffer_size
uint32_t hs_buffer_size
Definition: app-layer-ssl.h:229
TLS_DECODER_EVENT_CERTIFICATE_INVALID_DER
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_DER
Definition: app-layer-ssl.h:70
TLS_DECODER_EVENT_CERTIFICATE_INVALID_LENGTH
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_LENGTH
Definition: app-layer-ssl.h:63
TLS_FRAME_HB_DATA
@ TLS_FRAME_HB_DATA
Definition: app-layer-ssl.h:38
SSL_AL_FLAG_SSL_CLIENT_MASTER_KEY
#define SSL_AL_FLAG_SSL_CLIENT_MASTER_KEY
Definition: app-layer-ssl.h:105
SSL_AL_FLAG_SSL_CLIENT_SSN_ENCRYPTED
#define SSL_AL_FLAG_SSL_CLIENT_SSN_ENCRYPTED
Definition: app-layer-ssl.h:106
SSLStateConnp_::cert0_not_after
int64_t cert0_not_after
Definition: app-layer-ssl.h:201
SCAppLayerProtoDetectConfProtoDetectionEnabled
int SCAppLayerProtoDetectConfProtoDetectionEnabled(const char *ipproto, const char *alproto)
Given a protocol name, checks if proto detection is enabled in the conf file.
Definition: app-layer-detect-proto.c:2002
ERR_INVALID_LENGTH
@ ERR_INVALID_LENGTH
Definition: app-layer-ssl.c:174
SSLState_::current_flags
uint32_t current_flags
Definition: app-layer-ssl.h:252
SSLStateConnp_::cert0_sans
SSLSubjectAltName * cert0_sans
Definition: app-layer-ssl.h:204
AppLayerResult
Definition: app-layer-parser.h:114
SSL_AL_FLAG_HB_SERVER_INIT
#define SSL_AL_FLAG_HB_SERVER_INIT
Definition: app-layer-ssl.h:120
SCAppLayerParserTriggerRawStreamInspection
void SCAppLayerParserTriggerRawStreamInspection(Flow *f, int direction)
Definition: app-layer-parser.c:1813
TLS_DECODER_EVENT_CERTIFICATE_INVALID_VALIDITY
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_VALIDITY
Definition: app-layer-ssl.h:73
SSLV2_MT_SERVER_VERIFY
#define SSLV2_MT_SERVER_VERIFY
Definition: app-layer-ssl.c:241
app-layer-detect-proto.h
SSLDecoderResult::needed
uint32_t needed
Definition: app-layer-ssl.c:265
Ja3BufferInit
JA3Buffer * Ja3BufferInit(void)
Allocate new buffer.
Definition: util-ja3.c:39
APP_LAYER_INCOMPLETE
#define APP_LAYER_INCOMPLETE(c, n)
Definition: app-layer-parser.h:70
Ja3BufferFree
void Ja3BufferFree(JA3Buffer **buffer)
Free allocated buffer.
Definition: util-ja3.c:54
TAILQ_REMOVE
#define TAILQ_REMOVE(head, elm, field)
Definition: queue.h:312
feature.h
decode.h
util-debug.h
TLS_STATE_CLIENT_HANDSHAKE_DONE
@ TLS_STATE_CLIENT_HANDSHAKE_DONE
Definition: app-layer-ssl.h:83
TAILQ_FIRST
#define TAILQ_FIRST(head)
Definition: queue.h:250
AppLayerParserState_
Definition: app-layer-parser.c:148
TLS_HB_REQUEST
#define TLS_HB_REQUEST
Definition: app-layer-ssl.c:254
SSLJA3IsEnabled
bool SSLJA3IsEnabled(void)
return whether ja3 is effectively enabled
Definition: app-layer-ssl.c:3373
TLS_TC_RANDOM_SET
#define TLS_TC_RANDOM_SET
Definition: app-layer-ssl.h:140
AppLayerTxData
Definition: app-layer-parser.h:166
SCAppLayerParserConfParserEnabled
int SCAppLayerParserConfParserEnabled(const char *ipproto, const char *alproto_name)
check if a parser is enabled in the config Returns enabled always if: were running unittests
Definition: app-layer-parser.c:377
TLS_DECODER_EVENT_INVALID_RECORD_TYPE
@ TLS_DECODER_EVENT_INVALID_RECORD_TYPE
Definition: app-layer-ssl.h:48
ERR_INVALID_CERTIFICATE
@ ERR_INVALID_CERTIFICATE
Definition: app-layer-ssl.c:173
SSLState_::client_state
enum TlsStateClient client_state
Definition: app-layer-ssl.h:256
APP_LAYER_EVENT_TYPE_TRANSACTION
@ APP_LAYER_EVENT_TYPE_TRANSACTION
Definition: app-layer-events.h:55
AppLayerEventType
AppLayerEventType
Definition: app-layer-events.h:54
Ja3BufferAppendBuffer
int Ja3BufferAppendBuffer(JA3Buffer **buffer1, JA3Buffer **buffer2)
Definition: util-ja3.c:309
SSLStateConnp_::handshake_type
uint8_t handshake_type
Definition: app-layer-ssl.h:186
SSLV2_MT_REQUEST_CERTIFICATE
#define SSLV2_MT_REQUEST_CERTIFICATE
Definition: app-layer-ssl.c:243
SSLDecoderResult::retval
int retval
Definition: app-layer-ssl.c:264
SSLStateConnp_::hs_buffer_offset
uint32_t hs_buffer_offset
Definition: app-layer-ssl.h:230
SSLStateConnp_::certs_buffer
uint8_t * certs_buffer
Definition: app-layer-ssl.h:214
TLS_STATE_CLIENT_HELLO_DONE
@ TLS_STATE_CLIENT_HELLO_DONE
Definition: app-layer-ssl.h:81
TLS_DECODER_EVENT_INVALID_RECORD_VERSION
@ TLS_DECODER_EVENT_INVALID_RECORD_VERSION
Definition: app-layer-ssl.h:47
TlsStateServer
TlsStateServer
Definition: app-layer-ssl.h:87
TLS_DECODER_EVENT_CERTIFICATE_INVALID_DATE
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_DATE
Definition: app-layer-ssl.h:68
SSLCertsChain_
Definition: app-layer-ssl.h:163
SSLStateConnp_::cert0_serial_len
uint32_t cert0_serial_len
Definition: app-layer-ssl.h:199
AppLayerParserRegisterGetFrameFuncs
void AppLayerParserRegisterGetFrameFuncs(uint8_t ipproto, AppProto alproto, AppLayerParserGetFrameIdByNameFn GetIdByNameFunc, AppLayerParserGetFrameNameByIdFn GetNameByIdFunc)
Definition: app-layer-parser.c:653
TLS_DECODER_EVENT_CERTIFICATE_INVALID_SERIAL
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_SERIAL
Definition: app-layer-ssl.h:65
SSLParserReset
#define SSLParserReset(state)
Definition: app-layer-ssl.c:319
SCConfGetNonNull
int SCConfGetNonNull(const char *name, const char **vptr)
Retrieve the non-null value of a configuration node.
Definition: conf.c:381
TlsStateClient
TlsStateClient
Definition: app-layer-ssl.h:79
TLS_DECODER_EVENT_CERTIFICATE_INVALID_SUBJECT
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_SUBJECT
Definition: app-layer-ssl.h:71
TLS_TS_RANDOM_SET
#define TLS_TS_RANDOM_SET
Definition: app-layer-ssl.h:137
AppLayerParserRegisterStateFuncs
void AppLayerParserRegisterStateFuncs(uint8_t ipproto, AppProto alproto, void *(*StateAlloc)(void *, AppProto), void(*StateFree)(void *))
Definition: app-layer-parser.c:485
SSL_AL_FLAG_STATE_CLIENT_HELLO
#define SSL_AL_FLAG_STATE_CLIENT_HELLO
Definition: app-layer-ssl.h:111
TLS_STATE_SERVER_FINISHED
@ TLS_STATE_SERVER_FINISHED
Definition: app-layer-ssl.h:93
SCLogWarning
#define SCLogWarning(...)
Macro used to log WARNING messages.
Definition: util-debug.h:262
TLS_RANDOM_LEN
#define TLS_RANDOM_LEN
Definition: app-layer-ssl.h:161
SSLStateConnp_::cert0_serial
uint8_t * cert0_serial
Definition: app-layer-ssl.h:198
SslConfig_::SC_ATOMIC_DECLARE
SC_ATOMIC_DECLARE(int, enable_ja3)
app-layer-parser.h
TLS_STATE_CLIENT_IN_PROGRESS
@ TLS_STATE_CLIENT_IN_PROGRESS
Definition: app-layer-ssl.h:80
TLS_FRAME_SSLV2_PDU
@ TLS_FRAME_SSLV2_PDU
Definition: app-layer-ssl.h:40
AppLayerParserRegisterGetEventInfo
void AppLayerParserRegisterGetEventInfo(uint8_t ipproto, AppProto alproto, int(*StateGetEventInfo)(const char *event_name, uint8_t *event_id, AppLayerEventType *event_type))
Definition: app-layer-parser.c:663
SslConfigEncryptHandling
SslConfigEncryptHandling
Definition: app-layer-ssl.c:195
SSL_AL_FLAG_HB_CLIENT_INIT
#define SSL_AL_FLAG_HB_CLIENT_INIT
Definition: app-layer-ssl.h:119
SSL_AL_FLAG_STATE_CLIENT_KEYX
#define SSL_AL_FLAG_STATE_CLIENT_KEYX
Definition: app-layer-ssl.h:113
SSLV3_RECORD_HDR_LEN
#define SSLV3_RECORD_HDR_LEN
Definition: app-layer-ssl.c:246
SSLV2_MT_CLIENT_MASTER_KEY
#define SSLV2_MT_CLIENT_MASTER_KEY
Definition: app-layer-ssl.c:238
SSL_EXTENSION_ALPN
#define SSL_EXTENSION_ALPN
Definition: app-layer-ssl.h:152
TLS_DECODER_EVENT_INVALID_SSLV2_HEADER
@ TLS_DECODER_EVENT_INVALID_SSLV2_HEADER
Definition: app-layer-ssl.h:45
TLS_DECODER_EVENT_INVALID_RECORD_LENGTH
@ TLS_DECODER_EVENT_INVALID_RECORD_LENGTH
Definition: app-layer-ssl.h:49
conf.h
ERR_EXTRACT_ISSUER
@ ERR_EXTRACT_ISSUER
Definition: app-layer-ssl.c:185
SSL_AL_FLAG_CH_VERSION_EXTENSION
#define SSL_AL_FLAG_CH_VERSION_EXTENSION
Definition: app-layer-ssl.h:126
SSLStateConnp_::cert0_issuerdn
uint8_t * cert0_issuerdn
Definition: app-layer-ssl.h:196
SSLState_::server_state
enum TlsStateServer server_state
Definition: app-layer-ssl.h:257
SSLEnableJA3
void SSLEnableJA3(void)
if not explicitly disabled in config, enable ja3 support
Definition: app-layer-ssl.c:3336
SSLStateConnp_::record_length
uint32_t record_length
Definition: app-layer-ssl.h:176
SslConfig_
Definition: app-layer-ssl.c:201
SSLV2_MT_CLIENT_HELLO
#define SSLV2_MT_CLIENT_HELLO
Definition: app-layer-ssl.c:237
AppLayerProtoDetectRegisterProtocol
void AppLayerProtoDetectRegisterProtocol(AppProto alproto, const char *alproto_name)
Registers a protocol for protocol detection phase.
Definition: app-layer-detect-proto.c:1782
TLS_STATE_SERVER_CERT_DONE
@ TLS_STATE_SERVER_CERT_DONE
Definition: app-layer-ssl.h:90
SSLV3_APPLICATION_PROTOCOL
#define SSLV3_APPLICATION_PROTOCOL
Definition: app-layer-ssl.c:217
SSLV3_ALERT_PROTOCOL
#define SSLV3_ALERT_PROTOCOL
Definition: app-layer-ssl.c:215
SSLV2_MT_CLIENT_CERTIFICATE
#define SSLV2_MT_CLIENT_CERTIFICATE
Definition: app-layer-ssl.c:244
SSLStateConnp_::sni
uint8_t * sni
Definition: app-layer-ssl.h:207
SSLCertsChain_::cert_data
uint8_t * cert_data
Definition: app-layer-ssl.h:164
SSLStateConnp_::cert0_sans_num
uint16_t cert0_sans_num
Definition: app-layer-ssl.h:205
RunmodeIsUnittests
int RunmodeIsUnittests(void)
Definition: suricata.c:292
SSLStateConnp_::certs_buffer_size
uint32_t certs_buffer_size
Definition: app-layer-ssl.h:215
AppLayerParserRegisterParser
int AppLayerParserRegisterParser(uint8_t ipproto, AppProto alproto, uint8_t direction, AppLayerParserFPtr Parser)
Register app layer parser for the protocol.
Definition: app-layer-parser.c:452
TLS_DECODER_EVENT_INVALID_HEARTBEAT
@ TLS_DECODER_EVENT_INVALID_HEARTBEAT
Definition: app-layer-ssl.h:52
SSL_AL_FLAG_NEED_CLIENT_CERT
#define SSL_AL_FLAG_NEED_CLIENT_CERT
Definition: app-layer-ssl.h:142
SSLV3_HS_CLIENT_KEY_EXCHANGE
#define SSLV3_HS_CLIENT_KEY_EXCHANGE
Definition: app-layer-ssl.c:230
SSL_AL_FLAG_SERVER_CHANGE_CIPHER_SPEC
#define SSL_AL_FLAG_SERVER_CHANGE_CIPHER_SPEC
Definition: app-layer-ssl.h:97
SCRealloc
#define SCRealloc(ptr, sz)
Definition: util-mem.h:50
HAS_SPACE
#define HAS_SPACE(n)
Definition: app-layer-ssl.c:261
SCAppLayerProtoDetectPPRegister
void SCAppLayerProtoDetectPPRegister(uint8_t ipproto, const char *portstr, AppProto alproto, uint16_t min_depth, uint16_t max_depth, uint8_t direction, ProbingParserFPtr ProbingParser1, ProbingParserFPtr ProbingParser2)
register parser at a port
Definition: app-layer-detect-proto.c:1541
AppLayerParserRegisterGetTx
void AppLayerParserRegisterGetTx(uint8_t ipproto, AppProto alproto, void *(StateGetTx)(void *alstate, uint64_t tx_id))
Definition: app-layer-parser.c:566
TLS_DECODER_EVENT_HANDSHAKE_INVALID_LENGTH
@ TLS_DECODER_EVENT_HANDSHAKE_INVALID_LENGTH
Definition: app-layer-ssl.h:55
SSLDecoderResult
Definition: app-layer-ssl.c:263
APP_LAYER_OK
#define APP_LAYER_OK
Definition: app-layer-parser.h:58
TLS_DECODER_EVENT_CERTIFICATE_INVALID_VERSION
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_VERSION
Definition: app-layer-ssl.h:64
SSLStateConnp_::random
uint8_t random[TLS_RANDOM_LEN]
Definition: app-layer-ssl.h:193
SSLV3_RECORD_MAX_LEN
#define SSLV3_RECORD_MAX_LEN
Definition: app-layer-ssl.c:248
app-layer-frames.h
SSL_DECODER_ERROR
#define SSL_DECODER_ERROR(e)
Definition: app-layer-ssl.c:267
SSL_AL_FLAG_SSL_CLIENT_HS
#define SSL_AL_FLAG_SSL_CLIENT_HS
Definition: app-layer-ssl.h:103
SCMapEnumValueToName
const char * SCMapEnumValueToName(int enum_value, SCEnumCharMap *table)
Maps an enum value to a string name, from the supplied table.
Definition: util-enum.c:68
SCReturnStruct
#define SCReturnStruct(x)
Definition: util-debug.h:304
ERR_EXTRACT_VALIDITY
@ ERR_EXTRACT_VALIDITY
Definition: app-layer-ssl.c:186
TLS_DECODER_EVENT_INVALID_CERTIFICATE
@ TLS_DECODER_EVENT_INVALID_CERTIFICATE
Definition: app-layer-ssl.h:62
RegisterSSLParsers
void RegisterSSLParsers(void)
Function to register the SSL protocol parser and other functions.
Definition: app-layer-ssl.c:3205
SSLStateConnp_::cert0_subject_len
uint32_t cert0_subject_len
Definition: app-layer-ssl.h:195
SSLV3_CLIENT_HELLO_VERSION_LEN
#define SSLV3_CLIENT_HELLO_VERSION_LEN
Definition: app-layer-ssl.c:250
SCMapEnumNameToValue
int SCMapEnumNameToValue(const char *enum_name, SCEnumCharMap *table)
Maps a string name to an enum value from the supplied table. Please specify the last element of any m...
Definition: util-enum.c:40
SSL_DECODER_OK
#define SSL_DECODER_OK(c)
Definition: app-layer-ssl.c:272
suricata-common.h
TLS_FRAME_PDU
@ TLS_FRAME_PDU
Definition: app-layer-ssl.h:34
SSL_EXTENSION_SESSION_TICKET
#define SSL_EXTENSION_SESSION_TICKET
Definition: app-layer-ssl.h:153
SSL_EXTENSION_SIGNATURE_ALGORITHMS
#define SSL_EXTENSION_SIGNATURE_ALGORITHMS
Definition: app-layer-ssl.h:151
AppLayerTxData::updated_tc
bool updated_tc
Definition: app-layer-parser.h:173
Ja3GenerateHash
char * Ja3GenerateHash(JA3Buffer *buffer)
Definition: util-ja3.c:319
SSL_EXTENSION_EARLY_DATA
#define SSL_EXTENSION_EARLY_DATA
Definition: app-layer-ssl.h:154
SCEnumCharMap_
Definition: util-enum.h:27
SCAppLayerParserRegisterParserAcceptableDataDirection
void SCAppLayerParserRegisterParserAcceptableDataDirection(uint8_t ipproto, AppProto alproto, uint8_t direction)
Definition: app-layer-parser.c:464
version
uint8_t version
Definition: decode-gre.h:1
SSLStateConnp_::content_type
uint8_t content_type
Definition: app-layer-ssl.h:184
SSLSetEvent
#define SSLSetEvent(ssl_state, event)
Definition: app-layer-ssl.c:326
AppLayerParserRegisterStateDataFunc
void AppLayerParserRegisterStateDataFunc(uint8_t ipproto, AppProto alproto, AppLayerStateData *(*GetStateData)(void *state))
Definition: app-layer-parser.c:684
SSLStateConnp_::hs_buffer_message_size
uint32_t hs_buffer_message_size
Definition: app-layer-ssl.h:228
TLS_DECODER_EVENT_CERTIFICATE_INVALID_ALGORITHMIDENTIFIER
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_ALGORITHMIDENTIFIER
Definition: app-layer-ssl.h:66
SSL_DECODER_INCOMPLETE
#define SSL_DECODER_INCOMPLETE(c, n)
Definition: app-layer-ssl.c:277
AppLayerParserRegisterTxDataFunc
void AppLayerParserRegisterTxDataFunc(uint8_t ipproto, AppProto alproto, AppLayerTxData *(*GetTxData)(void *tx))
Definition: app-layer-parser.c:674
TLS_DECODER_EVENT_INVALID_SNI_TYPE
@ TLS_DECODER_EVENT_INVALID_SNI_TYPE
Definition: app-layer-ssl.h:57
AppLayerFrameNewByPointer
Frame * AppLayerFrameNewByPointer(Flow *f, const StreamSlice *stream_slice, const uint8_t *frame_start, const int64_t len, int dir, uint8_t frame_type)
create new frame using a pointer to start of the frame
Definition: app-layer-frames.c:465
FEATURE_JA4
#define FEATURE_JA4
Definition: feature.h:30
SslConfig_::encrypt_mode
enum SslConfigEncryptHandling encrypt_mode
Definition: app-layer-ssl.c:202
TLS_STATE_CLIENT_CERT_DONE
@ TLS_STATE_CLIENT_CERT_DONE
Definition: app-layer-ssl.h:82
SSLV3_HS_HELLO_REQUEST
#define SSLV3_HS_HELLO_REQUEST
Definition: app-layer-ssl.c:221
app-layer-events.h
SSL_AL_FLAG_CLIENT_CHANGE_CIPHER_SPEC
#define SSL_AL_FLAG_CLIENT_CHANGE_CIPHER_SPEC
Definition: app-layer-ssl.h:99
SSLV3_HS_CERTIFICATE_REQUEST
#define SSLV3_HS_CERTIFICATE_REQUEST
Definition: app-layer-ssl.c:227
util-validate.h
SSL_SNI_TYPE_HOST_NAME
#define SSL_SNI_TYPE_HOST_NAME
Definition: app-layer-ssl.h:158
SCMalloc
#define SCMalloc(sz)
Definition: util-mem.h:47
SCLogConfig
struct SCLogConfig_ SCLogConfig
Holds the config state used by the logging api.
SSLV2_MT_CLIENT_FINISHED
#define SSLV2_MT_CLIENT_FINISHED
Definition: app-layer-ssl.c:239
ssl_config
SslConfig ssl_config
Definition: app-layer-ssl.c:211
SCAppLayerProtoDetectPMRegisterPatternCS
int SCAppLayerProtoDetectPMRegisterPatternCS(uint8_t ipproto, AppProto alproto, const char *pattern, uint16_t depth, uint16_t offset, uint8_t direction)
Registers a case-sensitive pattern for protocol detection.
Definition: app-layer-detect-proto.c:1640
SCConfGetNode
SCConfNode * SCConfGetNode(const char *name)
Get a SCConfNode by name.
Definition: conf.c:184
SCLogError
#define SCLogError(...)
Macro used to log ERROR messages.
Definition: util-debug.h:274
SCFree
#define SCFree(p)
Definition: util-mem.h:61
SCAppLayerProtoDetectPPParseConfPorts
int SCAppLayerProtoDetectPPParseConfPorts(const char *ipproto_name, uint8_t ipproto, const char *alproto_name, AppProto alproto, uint16_t min_depth, uint16_t max_depth, ProbingParserFPtr ProbingParserTs, ProbingParserFPtr ProbingParserTc)
Definition: app-layer-detect-proto.c:1577
SSLSubjectAltName_
Definition: app-layer-ssl.h:169
TLS_STATE_SERVER_IN_PROGRESS
@ TLS_STATE_SERVER_IN_PROGRESS
Definition: app-layer-ssl.h:88
TLS_DECODER_EVENT_CERTIFICATE_INVALID_X509NAME
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_X509NAME
Definition: app-layer-ssl.h:67
src
uint16_t src
Definition: app-layer-dnp3.h:5
payload_len
uint16_t payload_len
Definition: stream-tcp-private.h:1
SSLV2_MT_ERROR
#define SSLV2_MT_ERROR
Definition: app-layer-ssl.c:236
SSL_AL_FLAG_SSL_SERVER_SSN_ENCRYPTED
#define SSL_AL_FLAG_SSL_SERVER_SSN_ENCRYPTED
Definition: app-layer-ssl.h:107
SSLV3_HANDSHAKE_PROTOCOL
#define SSLV3_HANDSHAKE_PROTOCOL
Definition: app-layer-ssl.c:216
SSLJA4IsEnabled
bool SSLJA4IsEnabled(void)
return whether ja4 is effectively enabled
Definition: app-layer-ssl.c:3386
WARN_UNUSED
#define WARN_UNUSED
Definition: bindgen.h:33
SslConfig_::disable_ja4
bool disable_ja4
Definition: app-layer-ssl.c:208
ALPROTO_UNKNOWN
@ ALPROTO_UNKNOWN
Definition: app-layer-protos.h:29
ALPROTO_FAILED
@ ALPROTO_FAILED
Definition: app-layer-protos.h:33
SSLV3_HS_CLIENT_HELLO
#define SSLV3_HS_CLIENT_HELLO
Definition: app-layer-ssl.c:222
TLS_DECODER_EVENT_CERTIFICATE_INVALID_EXTENSIONS
@ TLS_DECODER_EVENT_CERTIFICATE_INVALID_EXTENSIONS
Definition: app-layer-ssl.h:69
SSLV3_CLIENT_HELLO_RANDOM_LEN
#define SSLV3_CLIENT_HELLO_RANDOM_LEN
Definition: app-layer-ssl.c:251
ProvidesFeature
void ProvidesFeature(const char *feature_name)
Definition: feature.c:106
SslConfig_::SC_ATOMIC_DECLARE
SC_ATOMIC_DECLARE(int, enable_ja4)
app-layer-protos.h
TLS_DECODER_EVENT_INVALID_SNI_LENGTH
@ TLS_DECODER_EVENT_INVALID_SNI_LENGTH
Definition: app-layer-ssl.h:58
ERR_INVALID_DER
@ ERR_INVALID_DER
Definition: app-layer-ssl.c:181
AppLayerParserRegisterGetTxCnt
void AppLayerParserRegisterGetTxCnt(uint8_t ipproto, AppProto alproto, uint64_t(*StateGetTxCnt)(void *alstate))
Definition: app-layer-parser.c:556
SSL_CNF_ENC_HANDLE_BYPASS
@ SSL_CNF_ENC_HANDLE_BYPASS
Definition: app-layer-ssl.c:197
APP_LAYER_ERROR
#define APP_LAYER_ERROR
Definition: app-layer-parser.h:62
SslConfig
struct SslConfig_ SslConfig
SSLStateConnp_::hs
HandshakeParams * hs
Definition: app-layer-ssl.h:222
FEATURE_JA3
#define FEATURE_JA3
Definition: feature.h:29
SSLStateConnp_::cert0_issuerdn_len
uint32_t cert0_issuerdn_len
Definition: app-layer-ssl.h:197
AppLayerParserRegisterGetEventInfoById
void AppLayerParserRegisterGetEventInfoById(uint8_t ipproto, AppProto alproto, int(*StateGetEventInfoById)(uint8_t event_id, const char **event_name, AppLayerEventType *event_type))
Definition: app-layer-parser.c:599
TLS_FRAME_ALERT_DATA
@ TLS_FRAME_ALERT_DATA
Definition: app-layer-ssl.h:37
SSL_AL_FLAG_SSL_NO_SESSION_ID
#define SSL_AL_FLAG_SSL_NO_SESSION_ID
Definition: app-layer-ssl.h:108
TLS_STATE_SERVER_HELLO
@ TLS_STATE_SERVER_HELLO
Definition: app-layer-ssl.h:89
SSLStateConnp_::session_id
char * session_id
Definition: app-layer-ssl.h:210
TLS_FRAME_HDR
@ TLS_FRAME_HDR
Definition: app-layer-ssl.h:35
SC_ATOMIC_GET
#define SC_ATOMIC_GET(name)
Get the value from the atomic variable.
Definition: util-atomic.h:375
dst
uint16_t dst
Definition: app-layer-dnp3.h:4
TLS_DECODER_EVENT_INVALID_ALERT
@ TLS_DECODER_EVENT_INVALID_ALERT
Definition: app-layer-ssl.h:60
SSL_EXTENSION_SNI
#define SSL_EXTENSION_SNI
Definition: app-layer-ssl.h:148
SSLStateConnp_::cert0_fingerprint
char * cert0_fingerprint
Definition: app-layer-ssl.h:202
SSL_RECORD_MINIMUM_LENGTH
#define SSL_RECORD_MINIMUM_LENGTH
Definition: app-layer-ssl.c:257
SSLStateConnp_::sni_len
uint16_t sni_len
Definition: app-layer-ssl.h:208
SSLStateConnp_::ja3_str
JA3Buffer * ja3_str
Definition: app-layer-ssl.h:219
TLS_STATE_SERVER_HANDSHAKE_DONE
@ TLS_STATE_SERVER_HANDSHAKE_DONE
Definition: app-layer-ssl.h:92
SCCalloc
#define SCCalloc(nm, sz)
Definition: util-mem.h:53
ERR_INVALID_EXTENSIONS
@ ERR_INVALID_EXTENSIONS
Definition: app-layer-ssl.c:180
SSLV3_HS_SERVER_HELLO_DONE
#define SSLV3_HS_SERVER_HELLO_DONE
Definition: app-layer-ssl.c:228
util-enum.h
SCReturnInt
#define SCReturnInt(x)
Definition: util-debug.h:288
SCConfNode_
Definition: conf.h:37
SSLStateConnp_::hs_buffer
uint8_t * hs_buffer
Definition: app-layer-ssl.h:226
SCConfNode_::val
char * val
Definition: conf.h:39
ERR_INVALID_VERSION
@ ERR_INVALID_VERSION
Definition: app-layer-ssl.c:175
TLS_STATE_CLIENT_FINISHED
@ TLS_STATE_CLIENT_FINISHED
Definition: app-layer-ssl.h:84
DEBUG_VALIDATE_BUG_ON
#define DEBUG_VALIDATE_BUG_ON(exp)
Definition: util-validate.h:109
app-layer-ssl.h
SSLV3_HS_NEW_SESSION_TICKET
#define SSLV3_HS_NEW_SESSION_TICKET
Definition: app-layer-ssl.c:224
SCAppLayerGetEventIdByName
int SCAppLayerGetEventIdByName(const char *event_name, SCEnumCharMap *table, uint8_t *event_id)
Definition: app-layer-events.c:30
SSL_AL_FLAG_LOG_WITHOUT_CERT
#define SSL_AL_FLAG_LOG_WITHOUT_CERT
Definition: app-layer-ssl.h:130
SSLV3_HS_CERTIFICATE_STATUS
#define SSLV3_HS_CERTIFICATE_STATUS
Definition: app-layer-ssl.c:233
SSL_AL_FLAG_HB_INFLIGHT
#define SSL_AL_FLAG_HB_INFLIGHT
Definition: app-layer-ssl.h:118
SSL_AL_FLAG_SSL_SERVER_HS
#define SSL_AL_FLAG_SSL_SERVER_HS
Definition: app-layer-ssl.h:104
AppLayerTxData::updated_ts
bool updated_ts
Definition: app-layer-parser.h:174
app-layer.h
SSL_CNF_ENC_HANDLE_FULL
@ SSL_CNF_ENC_HANDLE_FULL
Definition: app-layer-ssl.c:198
SSLStateConnp_::cert0_subject
uint8_t * cert0_subject
Definition: app-layer-ssl.h:194
SSLState_::flags
uint32_t flags
Definition: app-layer-ssl.h:245
SSLStateConnp_::version
uint16_t version
Definition: app-layer-ssl.h:183
SSLV3_HS_SERVER_KEY_EXCHANGE
#define SSLV3_HS_SERVER_KEY_EXCHANGE
Definition: app-layer-ssl.c:226
g_disable_hashing
bool g_disable_hashing
Definition: suricata.c:218