mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-22 00:17:32 +09:00
Replace NSS with Pale Moon's
This commit is contained in:
parent
ff1e5e48bf
commit
8c2e376f94
2870 changed files with 1762232 additions and 1374220 deletions
|
|
@ -175,7 +175,7 @@ SSL_IMPORT PRFileDesc *DTLS_ImportFD(PRFileDesc *model, PRFileDesc *fd);
|
|||
|
||||
/* SSL_REUSE_SERVER_ECDHE_KEY controls whether the ECDHE server key is
|
||||
* reused for multiple handshakes or generated each time.
|
||||
* SSL_REUSE_SERVER_ECDHE_KEY is currently enabled by default.
|
||||
* SSL_REUSE_SERVER_ECDHE_KEY is currently disabled by default.
|
||||
* This socket option is for ECDHE, only. It is unrelated to DHE.
|
||||
*/
|
||||
#define SSL_REUSE_SERVER_ECDHE_KEY 27
|
||||
|
|
@ -312,7 +312,8 @@ SSL_IMPORT PRFileDesc *DTLS_ImportFD(PRFileDesc *model, PRFileDesc *fd);
|
|||
|
||||
/* Enables the delegated credentials extension (draft-ietf-tls-subcerts). When
|
||||
* enabled, a client that supports TLS 1.3 will indicate willingness to
|
||||
* negotiate a delegated credential (DC).
|
||||
* negotiate a delegated credential (DC). Note that client-delegated credentials
|
||||
* are not currently supported.
|
||||
*
|
||||
* If support is indicated, the peer may use a DC to authenticate itself. The DC
|
||||
* is sent as an extension to the peer's end-entity certificate; the end-entity
|
||||
|
|
@ -322,10 +323,63 @@ SSL_IMPORT PRFileDesc *DTLS_ImportFD(PRFileDesc *model, PRFileDesc *fd);
|
|||
* mitigate the damage in case the secret key is compromised, the DC is only
|
||||
* valid for a short time (days, hours, or even minutes).
|
||||
*
|
||||
* This library implements draft-03 of the protocol spec.
|
||||
* This library implements draft-07 of the protocol spec.
|
||||
*/
|
||||
#define SSL_ENABLE_DELEGATED_CREDENTIALS 40
|
||||
|
||||
/* Causes TLS (>=1.3) to suppress the EndOfEarlyData message in stream mode.
|
||||
*
|
||||
* This is not advisable in general, but the message only exists to delineate
|
||||
* early data in a streamed connection. DTLS does not use this message as a
|
||||
* result. The integration of TLS with QUIC, which uses a record/packet
|
||||
* protection layer that is unreliable, also does not use this message.
|
||||
*
|
||||
* On the server, this requires that SSL_RecordLayerData be used.
|
||||
* EndOfEarlyData is otherwise needed to drive key changes. Additionally,
|
||||
* servers that use this API must check that handshake messages (Certificate,
|
||||
* CertificateVerify, and Finished in particular) are only received in epoch 2
|
||||
* (Handshake). SSL_RecordLayerData will accept these handshake messages if
|
||||
* they are passed as epoch 1 (Early Data) in a single call.
|
||||
*
|
||||
* Using this option will cause connections to fail if early data is attempted
|
||||
* and the peer expects this message.
|
||||
*/
|
||||
#define SSL_SUPPRESS_END_OF_EARLY_DATA 41
|
||||
|
||||
/* Enables TLS GREASE (specified in RFC8701, following Chrome 55 implementation
|
||||
* decisions).
|
||||
*
|
||||
* If enabled and the client's ss->vrange.max >= SSL_LIBRARY_VERSION_TLS_1_3 or
|
||||
* the server's ss->version >= SSL_LIBRARY_VERSION_TLS_1_3, this adds random
|
||||
* GREASE values to:
|
||||
* - ClientHello (Client):
|
||||
* - A cipher_suite value to the cipher_suites field.
|
||||
* - An empty and a 1B zeroed payload extension.
|
||||
* - A named group value to the supported_groups extension and a
|
||||
* KeyShareEntry value for the added named group.
|
||||
* - A signature algorithm value to the signature_algorithms extension.
|
||||
* - A version value to the supported_versions extension.
|
||||
* - A PskKeyExchangeMode value to the psk_key_exchange_modes extension.
|
||||
* - A alpn value to the application_layer_protocol_negotiation extension.
|
||||
*
|
||||
* - CertificateRequest (Server):
|
||||
* - An empty extension.
|
||||
* - A signature algorithm value to the signature_algorithms extension.
|
||||
*
|
||||
* - NewSessionTicket (Server):
|
||||
* - An empty extension.
|
||||
*
|
||||
* GREASE values MUST nerver be negotiated but ignored.
|
||||
*/
|
||||
#define SSL_ENABLE_GREASE 42
|
||||
|
||||
/* Enables TLS ClientHello Extension Permutation.
|
||||
*
|
||||
* On a TLS ClientHello all extensions but the Psk extension
|
||||
* (which MUST be last) will be sent in randomly shuffeld order.
|
||||
*/
|
||||
#define SSL_ENABLE_CH_EXTENSION_PERMUTATION 43
|
||||
|
||||
#ifdef SSL_DEPRECATED_FUNCTION
|
||||
/* Old deprecated function names */
|
||||
SSL_IMPORT SECStatus SSL_Enable(PRFileDesc *fd, int option, PRIntn on);
|
||||
|
|
@ -383,7 +437,14 @@ SSL_IMPORT SECStatus SSL_SetNextProtoCallback(PRFileDesc *fd,
|
|||
* preferred. The other protocols should be in preference order.
|
||||
*
|
||||
* The supported protocols are specified in |data| in wire-format (8-bit
|
||||
* length-prefixed). For example: "\010http/1.1\006spdy/2". */
|
||||
* length-prefixed). For example: "\010http/1.1\006spdy/2".
|
||||
*
|
||||
* An empty value (i.e., where |length| is 0 and |data| is any value,
|
||||
* including NULL) forcibly disables ALPN. In this mode, the server will
|
||||
* reject any ClientHello that includes the ALPN extension.
|
||||
*
|
||||
* Calling this function overrides the callback previously set by
|
||||
* SSL_SetNextProtoCallback. */
|
||||
SSL_IMPORT SECStatus SSL_SetNextProtoNego(PRFileDesc *fd,
|
||||
const unsigned char *data,
|
||||
unsigned int length);
|
||||
|
|
@ -829,6 +890,20 @@ SSL_IMPORT SECStatus SSL_AuthCertificate(void *arg, PRFileDesc *fd,
|
|||
* caNames - pointer to distinguished names of CAs that the server likes
|
||||
* pRetCert - pointer to pointer to cert, for return of cert
|
||||
* pRetKey - pointer to key pointer, for return of key
|
||||
* Return value can be one of {SECSuccess, SECFailure, SECWouldBlock}
|
||||
*
|
||||
* If SECSuccess, pRetCert and pRetKey should be set to the selected
|
||||
* client cert and private key respectively. If SECFailure or SECWouldBlock
|
||||
* they should not be changed.
|
||||
*
|
||||
* Ownership of pRetCert and pRetKey passes to NSS. The application must not
|
||||
* mutate or free the structures after passing them to NSS.
|
||||
*
|
||||
* Returning SECWouldBlock will block the handshake until SSL_ClientCertCallbackComplete
|
||||
* is called. Note that references to *caNames should not be kept after SSLGetClientAuthData
|
||||
* returns. Instead, take a copy of the data.
|
||||
*
|
||||
* See also the comments for SSL_ClientCertCallbackComplete.
|
||||
*/
|
||||
typedef SECStatus(PR_CALLBACK *SSLGetClientAuthData)(void *arg,
|
||||
PRFileDesc *fd,
|
||||
|
|
@ -1478,6 +1553,50 @@ extern const char *NSSSSL_GetVersion(void);
|
|||
SSL_IMPORT SECStatus SSL_AuthCertificateComplete(PRFileDesc *fd,
|
||||
PRErrorCode error);
|
||||
|
||||
/* Restart an SSL connection which was paused to do asynchronous client
|
||||
* certificate selection (when the client certificate hook returned SECWouldBlock).
|
||||
*
|
||||
* This function only works for non-blocking sockets; Do not use it for
|
||||
* blocking sockets. This function works only for the client role of
|
||||
* a connection; it does not work for the server role.
|
||||
*
|
||||
* If a certificate has been sucessfully selected, the application must call
|
||||
* SSL_ClientCertCallbackComplete with:
|
||||
* - SECSuccess (0) as the value of outcome
|
||||
* - a valid SECKEYPrivateKey located at *clientPrivateKey
|
||||
* - a valid CERTCertificate located at *clientCertificate
|
||||
* The ownership of these latter structures will pass to NSS and the application
|
||||
* MUST not retain any references to them or invalidate them.
|
||||
*
|
||||
* If a certificate has not been selected, the application must call
|
||||
* SSL_ClientCertCallbackComplete with:
|
||||
* - SECFailure (-1) as the value of outcome
|
||||
* - *clientPrivateKey set to NULL.
|
||||
* - *clientCertificate set to NULL
|
||||
*
|
||||
* Once the application has returned SECWouldBlock to getClientAuthData
|
||||
* the handshake will not proceed until this function is called. It is an
|
||||
* error to call this function when the handshake is not waiting on client
|
||||
* certificate selection, or to call this function more than once.
|
||||
|
||||
* This function will not complete the entire handshake. The application must
|
||||
* call SSL_ForceHandshake, PR_Recv, PR_Send, etc. after calling this function
|
||||
* to force the handshake to complete.
|
||||
*
|
||||
* Be careful about converting an application from synchronous cert selection
|
||||
* to asynchronous certificate selection. A naive conversion is likely to
|
||||
* result in deadlocks; e.g. the application will wait in PR_Poll for network
|
||||
* I/O on the connection while all network I/O on the connection is blocked
|
||||
* waiting for this function to be called.
|
||||
*
|
||||
* Note that SSL_ClientCertCallbackComplete will (usually) return
|
||||
* SECSuccess; SECFailure indicates that the function was invoked incorrectly or
|
||||
* an error whilst processing the handshake. The return code does not indicate
|
||||
* whether or not the provided private key and certificate were sucessfully loaded
|
||||
* or accepted by the server.
|
||||
*/
|
||||
SSL_IMPORT SECStatus SSL_ClientCertCallbackComplete(PRFileDesc *fd, SECStatus outcome, SECKEYPrivateKey *clientPrivateKey, CERTCertificate *clientCertificate);
|
||||
|
||||
/*
|
||||
* This is used to access experimental APIs. Don't call this directly. This is
|
||||
* used to enable the experimental APIs that are defined in "sslexp.h".
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue