ssl_stat.c 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409
  1. /*
  2. * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  3. * Copyright 2005 Nokia. All rights reserved.
  4. *
  5. * Licensed under the Apache License 2.0 (the "License"). You may not use
  6. * this file except in compliance with the License. You can obtain a copy
  7. * in the file LICENSE in the source distribution or at
  8. * https://www.openssl.org/source/license.html
  9. */
  10. #include <stdio.h>
  11. #include "ssl_local.h"
  12. #include "internal/ssl_unwrap.h"
  13. const char *SSL_state_string_long(const SSL *s)
  14. {
  15. const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(s);
  16. if (sc == NULL || ossl_statem_in_error(sc))
  17. return "error";
  18. switch (SSL_get_state(s)) {
  19. case TLS_ST_CR_CERT_STATUS:
  20. return "SSLv3/TLS read certificate status";
  21. case TLS_ST_CW_NEXT_PROTO:
  22. return "SSLv3/TLS write next proto";
  23. case TLS_ST_SR_NEXT_PROTO:
  24. return "SSLv3/TLS read next proto";
  25. case TLS_ST_SW_CERT_STATUS:
  26. return "SSLv3/TLS write certificate status";
  27. case TLS_ST_BEFORE:
  28. return "before SSL initialization";
  29. case TLS_ST_OK:
  30. return "SSL negotiation finished successfully";
  31. case TLS_ST_CW_CLNT_HELLO:
  32. return "SSLv3/TLS write client hello";
  33. case TLS_ST_CR_SRVR_HELLO:
  34. return "SSLv3/TLS read server hello";
  35. case TLS_ST_CR_CERT:
  36. return "SSLv3/TLS read server certificate";
  37. case TLS_ST_CR_COMP_CERT:
  38. return "TLSv1.3 read server compressed certificate";
  39. case TLS_ST_CR_KEY_EXCH:
  40. return "SSLv3/TLS read server key exchange";
  41. case TLS_ST_CR_CERT_REQ:
  42. return "SSLv3/TLS read server certificate request";
  43. case TLS_ST_CR_SESSION_TICKET:
  44. return "SSLv3/TLS read server session ticket";
  45. case TLS_ST_CR_SRVR_DONE:
  46. return "SSLv3/TLS read server done";
  47. case TLS_ST_CW_CERT:
  48. return "SSLv3/TLS write client certificate";
  49. case TLS_ST_CW_COMP_CERT:
  50. return "TLSv1.3 write client compressed certificate";
  51. case TLS_ST_CW_KEY_EXCH:
  52. return "SSLv3/TLS write client key exchange";
  53. case TLS_ST_CW_CERT_VRFY:
  54. return "SSLv3/TLS write certificate verify";
  55. case TLS_ST_CW_CHANGE:
  56. case TLS_ST_SW_CHANGE:
  57. return "SSLv3/TLS write change cipher spec";
  58. case TLS_ST_CW_FINISHED:
  59. case TLS_ST_SW_FINISHED:
  60. return "SSLv3/TLS write finished";
  61. case TLS_ST_CR_CHANGE:
  62. case TLS_ST_SR_CHANGE:
  63. return "SSLv3/TLS read change cipher spec";
  64. case TLS_ST_CR_FINISHED:
  65. case TLS_ST_SR_FINISHED:
  66. return "SSLv3/TLS read finished";
  67. case TLS_ST_SR_CLNT_HELLO:
  68. return "SSLv3/TLS read client hello";
  69. case TLS_ST_SW_HELLO_REQ:
  70. return "SSLv3/TLS write hello request";
  71. case TLS_ST_SW_SRVR_HELLO:
  72. return "SSLv3/TLS write server hello";
  73. case TLS_ST_SW_CERT:
  74. return "SSLv3/TLS write certificate";
  75. case TLS_ST_SW_COMP_CERT:
  76. return "TLSv1.3 write server compressed certificate";
  77. case TLS_ST_SW_KEY_EXCH:
  78. return "SSLv3/TLS write key exchange";
  79. case TLS_ST_SW_CERT_REQ:
  80. return "SSLv3/TLS write certificate request";
  81. case TLS_ST_SW_SESSION_TICKET:
  82. return "SSLv3/TLS write session ticket";
  83. case TLS_ST_SW_SRVR_DONE:
  84. return "SSLv3/TLS write server done";
  85. case TLS_ST_SR_CERT:
  86. return "SSLv3/TLS read client certificate";
  87. case TLS_ST_SR_COMP_CERT:
  88. return "TLSv1.3 read client compressed certificate";
  89. case TLS_ST_SR_KEY_EXCH:
  90. return "SSLv3/TLS read client key exchange";
  91. case TLS_ST_SR_CERT_VRFY:
  92. return "SSLv3/TLS read certificate verify";
  93. case DTLS_ST_CR_HELLO_VERIFY_REQUEST:
  94. return "DTLS1 read hello verify request";
  95. case DTLS_ST_SW_HELLO_VERIFY_REQUEST:
  96. return "DTLS1 write hello verify request";
  97. case TLS_ST_SW_ENCRYPTED_EXTENSIONS:
  98. return "TLSv1.3 write encrypted extensions";
  99. case TLS_ST_CR_ENCRYPTED_EXTENSIONS:
  100. return "TLSv1.3 read encrypted extensions";
  101. case TLS_ST_CR_CERT_VRFY:
  102. return "TLSv1.3 read server certificate verify";
  103. case TLS_ST_SW_CERT_VRFY:
  104. return "TLSv1.3 write server certificate verify";
  105. case TLS_ST_CR_HELLO_REQ:
  106. return "SSLv3/TLS read hello request";
  107. case TLS_ST_SW_KEY_UPDATE:
  108. return "TLSv1.3 write server key update";
  109. case TLS_ST_CW_KEY_UPDATE:
  110. return "TLSv1.3 write client key update";
  111. case TLS_ST_SR_KEY_UPDATE:
  112. return "TLSv1.3 read client key update";
  113. case TLS_ST_CR_KEY_UPDATE:
  114. return "TLSv1.3 read server key update";
  115. case TLS_ST_EARLY_DATA:
  116. return "TLSv1.3 early data";
  117. case TLS_ST_PENDING_EARLY_DATA_END:
  118. return "TLSv1.3 pending early data end";
  119. case TLS_ST_CW_END_OF_EARLY_DATA:
  120. return "TLSv1.3 write end of early data";
  121. case TLS_ST_SR_END_OF_EARLY_DATA:
  122. return "TLSv1.3 read end of early data";
  123. default:
  124. return "unknown state";
  125. }
  126. }
  127. const char *SSL_state_string(const SSL *s)
  128. {
  129. const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(s);
  130. if (sc == NULL || ossl_statem_in_error(sc))
  131. return "SSLERR";
  132. switch (SSL_get_state(s)) {
  133. case TLS_ST_SR_NEXT_PROTO:
  134. return "TRNP";
  135. case TLS_ST_SW_SESSION_TICKET:
  136. return "TWST";
  137. case TLS_ST_SW_CERT_STATUS:
  138. return "TWCS";
  139. case TLS_ST_CR_CERT_STATUS:
  140. return "TRCS";
  141. case TLS_ST_CR_SESSION_TICKET:
  142. return "TRST";
  143. case TLS_ST_CW_NEXT_PROTO:
  144. return "TWNP";
  145. case TLS_ST_BEFORE:
  146. return "PINIT";
  147. case TLS_ST_OK:
  148. return "SSLOK";
  149. case TLS_ST_CW_CLNT_HELLO:
  150. return "TWCH";
  151. case TLS_ST_CR_SRVR_HELLO:
  152. return "TRSH";
  153. case TLS_ST_CR_CERT:
  154. return "TRSC";
  155. case TLS_ST_CR_COMP_CERT:
  156. return "TRSCC";
  157. case TLS_ST_CR_KEY_EXCH:
  158. return "TRSKE";
  159. case TLS_ST_CR_CERT_REQ:
  160. return "TRCR";
  161. case TLS_ST_CR_SRVR_DONE:
  162. return "TRSD";
  163. case TLS_ST_CW_CERT:
  164. return "TWCC";
  165. case TLS_ST_CW_COMP_CERT:
  166. return "TWCCC";
  167. case TLS_ST_CW_KEY_EXCH:
  168. return "TWCKE";
  169. case TLS_ST_CW_CERT_VRFY:
  170. return "TWCV";
  171. case TLS_ST_SW_CHANGE:
  172. case TLS_ST_CW_CHANGE:
  173. return "TWCCS";
  174. case TLS_ST_SW_FINISHED:
  175. case TLS_ST_CW_FINISHED:
  176. return "TWFIN";
  177. case TLS_ST_SR_CHANGE:
  178. case TLS_ST_CR_CHANGE:
  179. return "TRCCS";
  180. case TLS_ST_SR_FINISHED:
  181. case TLS_ST_CR_FINISHED:
  182. return "TRFIN";
  183. case TLS_ST_SW_HELLO_REQ:
  184. return "TWHR";
  185. case TLS_ST_SR_CLNT_HELLO:
  186. return "TRCH";
  187. case TLS_ST_SW_SRVR_HELLO:
  188. return "TWSH";
  189. case TLS_ST_SW_CERT:
  190. return "TWSC";
  191. case TLS_ST_SW_COMP_CERT:
  192. return "TWSCC";
  193. case TLS_ST_SW_KEY_EXCH:
  194. return "TWSKE";
  195. case TLS_ST_SW_CERT_REQ:
  196. return "TWCR";
  197. case TLS_ST_SW_SRVR_DONE:
  198. return "TWSD";
  199. case TLS_ST_SR_CERT:
  200. return "TRCC";
  201. case TLS_ST_SR_COMP_CERT:
  202. return "TRCCC";
  203. case TLS_ST_SR_KEY_EXCH:
  204. return "TRCKE";
  205. case TLS_ST_SR_CERT_VRFY:
  206. return "TRCV";
  207. case DTLS_ST_CR_HELLO_VERIFY_REQUEST:
  208. return "DRCHV";
  209. case DTLS_ST_SW_HELLO_VERIFY_REQUEST:
  210. return "DWCHV";
  211. case TLS_ST_SW_ENCRYPTED_EXTENSIONS:
  212. return "TWEE";
  213. case TLS_ST_CR_ENCRYPTED_EXTENSIONS:
  214. return "TREE";
  215. case TLS_ST_CR_CERT_VRFY:
  216. return "TRSCV";
  217. case TLS_ST_SW_CERT_VRFY:
  218. return "TWSCV";
  219. case TLS_ST_CR_HELLO_REQ:
  220. return "TRHR";
  221. case TLS_ST_SW_KEY_UPDATE:
  222. return "TWSKU";
  223. case TLS_ST_CW_KEY_UPDATE:
  224. return "TWCKU";
  225. case TLS_ST_SR_KEY_UPDATE:
  226. return "TRCKU";
  227. case TLS_ST_CR_KEY_UPDATE:
  228. return "TRSKU";
  229. case TLS_ST_EARLY_DATA:
  230. return "TED";
  231. case TLS_ST_PENDING_EARLY_DATA_END:
  232. return "TPEDE";
  233. case TLS_ST_CW_END_OF_EARLY_DATA:
  234. return "TWEOED";
  235. case TLS_ST_SR_END_OF_EARLY_DATA:
  236. return "TWEOED";
  237. default:
  238. return "UNKWN";
  239. }
  240. }
  241. const char *SSL_alert_type_string_long(int value)
  242. {
  243. switch (value >> 8) {
  244. case SSL3_AL_WARNING:
  245. return "warning";
  246. case SSL3_AL_FATAL:
  247. return "fatal";
  248. default:
  249. return "unknown";
  250. }
  251. }
  252. const char *SSL_alert_type_string(int value)
  253. {
  254. switch (value >> 8) {
  255. case SSL3_AL_WARNING:
  256. return "W";
  257. case SSL3_AL_FATAL:
  258. return "F";
  259. default:
  260. return "U";
  261. }
  262. }
  263. const char *SSL_alert_desc_string(int value)
  264. {
  265. switch (value & 0xff) {
  266. case SSL3_AD_CLOSE_NOTIFY:
  267. return "CN";
  268. case SSL3_AD_UNEXPECTED_MESSAGE:
  269. return "UM";
  270. case SSL3_AD_BAD_RECORD_MAC:
  271. return "BM";
  272. case SSL3_AD_DECOMPRESSION_FAILURE:
  273. return "DF";
  274. case SSL3_AD_HANDSHAKE_FAILURE:
  275. return "HF";
  276. case SSL3_AD_NO_CERTIFICATE:
  277. return "NC";
  278. case SSL3_AD_BAD_CERTIFICATE:
  279. return "BC";
  280. case SSL3_AD_UNSUPPORTED_CERTIFICATE:
  281. return "UC";
  282. case SSL3_AD_CERTIFICATE_REVOKED:
  283. return "CR";
  284. case SSL3_AD_CERTIFICATE_EXPIRED:
  285. return "CE";
  286. case SSL3_AD_CERTIFICATE_UNKNOWN:
  287. return "CU";
  288. case SSL3_AD_ILLEGAL_PARAMETER:
  289. return "IP";
  290. case TLS1_AD_DECRYPTION_FAILED:
  291. return "DC";
  292. case TLS1_AD_RECORD_OVERFLOW:
  293. return "RO";
  294. case TLS1_AD_UNKNOWN_CA:
  295. return "CA";
  296. case TLS1_AD_ACCESS_DENIED:
  297. return "AD";
  298. case TLS1_AD_DECODE_ERROR:
  299. return "DE";
  300. case TLS1_AD_DECRYPT_ERROR:
  301. return "CY";
  302. case TLS1_AD_EXPORT_RESTRICTION:
  303. return "ER";
  304. case TLS1_AD_PROTOCOL_VERSION:
  305. return "PV";
  306. case TLS1_AD_INSUFFICIENT_SECURITY:
  307. return "IS";
  308. case TLS1_AD_INTERNAL_ERROR:
  309. return "IE";
  310. case TLS1_AD_USER_CANCELLED:
  311. return "US";
  312. case TLS1_AD_NO_RENEGOTIATION:
  313. return "NR";
  314. case TLS1_AD_UNSUPPORTED_EXTENSION:
  315. return "UE";
  316. case TLS1_AD_CERTIFICATE_UNOBTAINABLE:
  317. return "CO";
  318. case TLS1_AD_UNRECOGNIZED_NAME:
  319. return "UN";
  320. case TLS1_AD_BAD_CERTIFICATE_STATUS_RESPONSE:
  321. return "BR";
  322. case TLS1_AD_BAD_CERTIFICATE_HASH_VALUE:
  323. return "BH";
  324. case TLS1_AD_UNKNOWN_PSK_IDENTITY:
  325. return "UP";
  326. default:
  327. return "UK";
  328. }
  329. }
  330. const char *SSL_alert_desc_string_long(int value)
  331. {
  332. switch (value & 0xff) {
  333. case SSL3_AD_CLOSE_NOTIFY:
  334. return "close notify";
  335. case SSL3_AD_UNEXPECTED_MESSAGE:
  336. return "unexpected message";
  337. case SSL3_AD_BAD_RECORD_MAC:
  338. return "bad record mac";
  339. case SSL3_AD_DECOMPRESSION_FAILURE:
  340. return "decompression failure";
  341. case SSL3_AD_HANDSHAKE_FAILURE:
  342. return "handshake failure";
  343. case SSL3_AD_NO_CERTIFICATE:
  344. return "no certificate";
  345. case SSL3_AD_BAD_CERTIFICATE:
  346. return "bad certificate";
  347. case SSL3_AD_UNSUPPORTED_CERTIFICATE:
  348. return "unsupported certificate";
  349. case SSL3_AD_CERTIFICATE_REVOKED:
  350. return "certificate revoked";
  351. case SSL3_AD_CERTIFICATE_EXPIRED:
  352. return "certificate expired";
  353. case SSL3_AD_CERTIFICATE_UNKNOWN:
  354. return "certificate unknown";
  355. case SSL3_AD_ILLEGAL_PARAMETER:
  356. return "illegal parameter";
  357. case TLS1_AD_DECRYPTION_FAILED:
  358. return "decryption failed";
  359. case TLS1_AD_RECORD_OVERFLOW:
  360. return "record overflow";
  361. case TLS1_AD_UNKNOWN_CA:
  362. return "unknown CA";
  363. case TLS1_AD_ACCESS_DENIED:
  364. return "access denied";
  365. case TLS1_AD_DECODE_ERROR:
  366. return "decode error";
  367. case TLS1_AD_DECRYPT_ERROR:
  368. return "decrypt error";
  369. case TLS1_AD_EXPORT_RESTRICTION:
  370. return "export restriction";
  371. case TLS1_AD_PROTOCOL_VERSION:
  372. return "protocol version";
  373. case TLS1_AD_INSUFFICIENT_SECURITY:
  374. return "insufficient security";
  375. case TLS1_AD_INTERNAL_ERROR:
  376. return "internal error";
  377. case TLS1_AD_USER_CANCELLED:
  378. return "user canceled";
  379. case TLS1_AD_NO_RENEGOTIATION:
  380. return "no renegotiation";
  381. case TLS1_AD_UNSUPPORTED_EXTENSION:
  382. return "unsupported extension";
  383. case TLS1_AD_CERTIFICATE_UNOBTAINABLE:
  384. return "certificate unobtainable";
  385. case TLS1_AD_UNRECOGNIZED_NAME:
  386. return "unrecognized name";
  387. case TLS1_AD_BAD_CERTIFICATE_STATUS_RESPONSE:
  388. return "bad certificate status response";
  389. case TLS1_AD_BAD_CERTIFICATE_HASH_VALUE:
  390. return "bad certificate hash value";
  391. case TLS1_AD_UNKNOWN_PSK_IDENTITY:
  392. return "unknown PSK identity";
  393. case TLS1_AD_NO_APPLICATION_PROTOCOL:
  394. return "no application protocol";
  395. default:
  396. return "unknown";
  397. }
  398. }