1 /* SPDX-License-Identifier: ((GPL-2.0 WITH Linux-syscall-note) OR Linux-OpenIB) */ 2 /* 3 * Copyright (c) 2016-2017, Mellanox Technologies. All rights reserved. 4 * 5 * This software is available to you under a choice of one of two 6 * licenses. You may choose to be licensed under the terms of the GNU 7 * General Public License (GPL) Version 2, available from the file 8 * COPYING in the main directory of this source tree, or the 9 * OpenIB.org BSD license below: 10 * 11 * Redistribution and use in source and binary forms, with or 12 * without modification, are permitted provided that the following 13 * conditions are met: 14 * 15 * - Redistributions of source code must retain the above 16 * copyright notice, this list of conditions and the following 17 * disclaimer. 18 * 19 * - Redistributions in binary form must reproduce the above 20 * copyright notice, this list of conditions and the following 21 * disclaimer in the documentation and/or other materials 22 * provided with the distribution. 23 * 24 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, 25 * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF 26 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND 27 * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS 28 * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN 29 * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN 30 * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE 31 * SOFTWARE. 32 */ 33 34 #ifndef _UAPI_LINUX_TLS_H 35 #define _UAPI_LINUX_TLS_H 36 37 #include <linux/types.h> 38 39 /* TLS socket options */ 40 #define TLS_TX 1 /* Set transmit parameters */ 41 #define TLS_RX 2 /* Set receive parameters */ 42 43 /* Supported versions */ 44 #define TLS_VERSION_MINOR(ver) ((ver) & 0xFF) 45 #define TLS_VERSION_MAJOR(ver) (((ver) >> 8) & 0xFF) 46 47 #define TLS_VERSION_NUMBER(id) ((((id##_VERSION_MAJOR) & 0xFF) << 8) | \ 48 ((id##_VERSION_MINOR) & 0xFF)) 49 50 #define TLS_1_2_VERSION_MAJOR 0x3 51 #define TLS_1_2_VERSION_MINOR 0x3 52 #define TLS_1_2_VERSION TLS_VERSION_NUMBER(TLS_1_2) 53 54 #define TLS_1_3_VERSION_MAJOR 0x3 55 #define TLS_1_3_VERSION_MINOR 0x4 56 #define TLS_1_3_VERSION TLS_VERSION_NUMBER(TLS_1_3) 57 58 /* Supported ciphers */ 59 #define TLS_CIPHER_AES_GCM_128 51 60 #define TLS_CIPHER_AES_GCM_128_IV_SIZE 8 61 #define TLS_CIPHER_AES_GCM_128_KEY_SIZE 16 62 #define TLS_CIPHER_AES_GCM_128_SALT_SIZE 4 63 #define TLS_CIPHER_AES_GCM_128_TAG_SIZE 16 64 #define TLS_CIPHER_AES_GCM_128_REC_SEQ_SIZE 8 65 66 #define TLS_CIPHER_AES_GCM_256 52 67 #define TLS_CIPHER_AES_GCM_256_IV_SIZE 8 68 #define TLS_CIPHER_AES_GCM_256_KEY_SIZE 32 69 #define TLS_CIPHER_AES_GCM_256_SALT_SIZE 4 70 #define TLS_CIPHER_AES_GCM_256_TAG_SIZE 16 71 #define TLS_CIPHER_AES_GCM_256_REC_SEQ_SIZE 8 72 73 #define TLS_CIPHER_AES_CCM_128 53 74 #define TLS_CIPHER_AES_CCM_128_IV_SIZE 8 75 #define TLS_CIPHER_AES_CCM_128_KEY_SIZE 16 76 #define TLS_CIPHER_AES_CCM_128_SALT_SIZE 4 77 #define TLS_CIPHER_AES_CCM_128_TAG_SIZE 16 78 #define TLS_CIPHER_AES_CCM_128_REC_SEQ_SIZE 8 79 80 #define TLS_CIPHER_CHACHA20_POLY1305 54 81 #define TLS_CIPHER_CHACHA20_POLY1305_IV_SIZE 12 82 #define TLS_CIPHER_CHACHA20_POLY1305_KEY_SIZE 32 83 #define TLS_CIPHER_CHACHA20_POLY1305_SALT_SIZE 0 84 #define TLS_CIPHER_CHACHA20_POLY1305_TAG_SIZE 16 85 #define TLS_CIPHER_CHACHA20_POLY1305_REC_SEQ_SIZE 8 86 87 #define TLS_SET_RECORD_TYPE 1 88 #define TLS_GET_RECORD_TYPE 2 89 90 struct tls_crypto_info { 91 __u16 version; 92 __u16 cipher_type; 93 }; 94 95 struct tls12_crypto_info_aes_gcm_128 { 96 struct tls_crypto_info info; 97 unsigned char iv[TLS_CIPHER_AES_GCM_128_IV_SIZE]; 98 unsigned char key[TLS_CIPHER_AES_GCM_128_KEY_SIZE]; 99 unsigned char salt[TLS_CIPHER_AES_GCM_128_SALT_SIZE]; 100 unsigned char rec_seq[TLS_CIPHER_AES_GCM_128_REC_SEQ_SIZE]; 101 }; 102 103 struct tls12_crypto_info_aes_gcm_256 { 104 struct tls_crypto_info info; 105 unsigned char iv[TLS_CIPHER_AES_GCM_256_IV_SIZE]; 106 unsigned char key[TLS_CIPHER_AES_GCM_256_KEY_SIZE]; 107 unsigned char salt[TLS_CIPHER_AES_GCM_256_SALT_SIZE]; 108 unsigned char rec_seq[TLS_CIPHER_AES_GCM_256_REC_SEQ_SIZE]; 109 }; 110 111 struct tls12_crypto_info_aes_ccm_128 { 112 struct tls_crypto_info info; 113 unsigned char iv[TLS_CIPHER_AES_CCM_128_IV_SIZE]; 114 unsigned char key[TLS_CIPHER_AES_CCM_128_KEY_SIZE]; 115 unsigned char salt[TLS_CIPHER_AES_CCM_128_SALT_SIZE]; 116 unsigned char rec_seq[TLS_CIPHER_AES_CCM_128_REC_SEQ_SIZE]; 117 }; 118 119 struct tls12_crypto_info_chacha20_poly1305 { 120 struct tls_crypto_info info; 121 unsigned char iv[TLS_CIPHER_CHACHA20_POLY1305_IV_SIZE]; 122 unsigned char key[TLS_CIPHER_CHACHA20_POLY1305_KEY_SIZE]; 123 unsigned char salt[TLS_CIPHER_CHACHA20_POLY1305_SALT_SIZE]; 124 unsigned char rec_seq[TLS_CIPHER_CHACHA20_POLY1305_REC_SEQ_SIZE]; 125 }; 126 127 enum { 128 TLS_INFO_UNSPEC, 129 TLS_INFO_VERSION, 130 TLS_INFO_CIPHER, 131 TLS_INFO_TXCONF, 132 TLS_INFO_RXCONF, 133 __TLS_INFO_MAX, 134 }; 135 #define TLS_INFO_MAX (__TLS_INFO_MAX - 1) 136 137 #define TLS_CONF_BASE 1 138 #define TLS_CONF_SW 2 139 #define TLS_CONF_HW 3 140 #define TLS_CONF_HW_RECORD 4 141 142 #endif /* _UAPI_LINUX_TLS_H */ 143