mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-24 01:17:34 +09:00
Update NSS to 3.48 while keeping vc2013 hackfix and no-sslkeylogfile intact.
This commit is contained in:
parent
0b9855b841
commit
171849c8e5
351 changed files with 115185 additions and 57946 deletions
|
|
@ -9,9 +9,10 @@
|
|||
#ifndef __sslt_h_
|
||||
#define __sslt_h_
|
||||
|
||||
#include "certt.h"
|
||||
#include "keyhi.h"
|
||||
#include "prtypes.h"
|
||||
#include "secitem.h"
|
||||
#include "certt.h"
|
||||
|
||||
typedef enum {
|
||||
ssl_hs_hello_request = 0,
|
||||
|
|
@ -267,6 +268,26 @@ typedef struct SSLExtraServerCertDataStr {
|
|||
/* A serialized sign_certificate_timestamp extension, used to answer
|
||||
* requests from clients for this data. */
|
||||
const SECItem* signedCertTimestamps;
|
||||
|
||||
/* Delegated credentials.
|
||||
*
|
||||
* A serialized delegated credential (DC) to use for authentication to peers
|
||||
* who indicate support for this extension (ietf-drafts-tls-subcerts). DCs
|
||||
* are used opportunistically if (1) the client indicates support, (2) TLS
|
||||
* 1.3 or higher is negotiated, and (3) the selected certificate is
|
||||
* configured with a DC.
|
||||
*
|
||||
* Note that it's the caller's responsibility to ensure that the DC is
|
||||
* well-formed.
|
||||
*/
|
||||
const SECItem* delegCred;
|
||||
|
||||
/* The secret key corresponding to the |delegCred|.
|
||||
*
|
||||
* Note that it's the caller's responsibility to ensure that this matches
|
||||
* the DC public key.
|
||||
*/
|
||||
const SECKEYPrivateKey* delegCredPrivKey;
|
||||
} SSLExtraServerCertData;
|
||||
|
||||
typedef struct SSLChannelInfoStr {
|
||||
|
|
@ -278,7 +299,13 @@ typedef struct SSLChannelInfoStr {
|
|||
PRUint16 protocolVersion;
|
||||
PRUint16 cipherSuite;
|
||||
|
||||
/* server authentication info */
|
||||
/* The strength of the key used to authenticate the peer. Before
|
||||
* interpreting this value, check authType, signatureScheme, and
|
||||
* peerDelegCred, to determine the type of the key and how it was used.
|
||||
*
|
||||
* Typically, this is the length of the key from the peer's end-entity
|
||||
* certificate. If delegated credentials are used (i.e., peerDelegCred is
|
||||
* PR_TRUE), then this is the strength of the delegated credential key. */
|
||||
PRUint32 authKeyBits;
|
||||
|
||||
/* key exchange algorithm info */
|
||||
|
|
@ -326,6 +353,11 @@ typedef struct SSLChannelInfoStr {
|
|||
* otherwise. */
|
||||
PRBool resumed;
|
||||
|
||||
/* Indicates whether the peer used a delegated credential (DC) for
|
||||
* authentication.
|
||||
*/
|
||||
PRBool peerDelegCred;
|
||||
|
||||
/* When adding new fields to this structure, please document the
|
||||
* NSS version in which they were added. */
|
||||
} SSLChannelInfo;
|
||||
|
|
@ -334,6 +366,9 @@ typedef struct SSLChannelInfoStr {
|
|||
#define ssl_preinfo_version (1U << 0)
|
||||
#define ssl_preinfo_cipher_suite (1U << 1)
|
||||
#define ssl_preinfo_0rtt_cipher_suite (1U << 2)
|
||||
/* ssl_preinfo_peer_auth covers peerDelegCred, authKeyBits, and scheme. Not
|
||||
* included in ssl_preinfo_all as it is client-only. */
|
||||
#define ssl_preinfo_peer_auth (1U << 3)
|
||||
/* ssl_preinfo_all doesn't contain ssl_preinfo_0rtt_cipher_suite because that
|
||||
* field is only set if 0-RTT is sent (client) or accepted (server). */
|
||||
#define ssl_preinfo_all (ssl_preinfo_version | ssl_preinfo_cipher_suite)
|
||||
|
|
@ -367,13 +402,23 @@ typedef struct SSLPreliminaryChannelInfoStr {
|
|||
* resume this session. */
|
||||
PRUint32 maxEarlyDataSize;
|
||||
|
||||
/* The following fields were added in NSS 3.39. */
|
||||
/* The following fields were added in NSS 3.43. */
|
||||
/* This reports the cipher suite used for 0-RTT if it sent or accepted. For
|
||||
* a client, this is set earlier than |cipherSuite|, and will match that
|
||||
* value if 0-RTT is accepted by the server. The server only sets this
|
||||
* after accepting 0-RTT, so this will contain the same value. */
|
||||
PRUint16 zeroRttCipherSuite;
|
||||
|
||||
/* The following fields were added in NSS 3.48. */
|
||||
/* These fields contain information about the key that will be used in
|
||||
* the CertificateVerify message. If Delegated Credentials are being used,
|
||||
* this is the DC-contained SPKI, else the EE-cert SPKI. These fields are
|
||||
* valid only after the Certificate message is handled. This can be determined
|
||||
* by checking the valuesSet field against |ssl_preinfo_peer_auth|. */
|
||||
PRBool peerDelegCred;
|
||||
PRUint32 authKeyBits;
|
||||
SSLSignatureScheme signatureScheme;
|
||||
|
||||
/* When adding new fields to this structure, please document the
|
||||
* NSS version in which they were added. */
|
||||
} SSLPreliminaryChannelInfo;
|
||||
|
|
@ -422,7 +467,7 @@ typedef struct SSLCipherSuiteInfoStr {
|
|||
* this instead of |authAlgorithm|. */
|
||||
SSLAuthType authType;
|
||||
|
||||
/* The following fields were added in NSS 3.39. */
|
||||
/* The following fields were added in NSS 3.43. */
|
||||
/* This reports the hash function used in the TLS KDF, or HKDF for TLS 1.3.
|
||||
* For suites defined for versions of TLS earlier than TLS 1.2, this reports
|
||||
* ssl_hash_none. */
|
||||
|
|
@ -476,6 +521,7 @@ typedef enum {
|
|||
ssl_tls13_key_share_xtn = 51,
|
||||
ssl_next_proto_nego_xtn = 13172, /* Deprecated. */
|
||||
ssl_renegotiation_info_xtn = 0xff01,
|
||||
ssl_delegated_credentials_xtn = 0xff02,
|
||||
ssl_tls13_short_header_xtn = 0xff03, /* Deprecated. */
|
||||
ssl_tls13_encrypted_sni_xtn = 0xffce,
|
||||
} SSLExtensionType;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue