ssl_stat.c 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336
  1. /*
  2. * Copyright 1995-2017 The OpenSSL Project Authors. All Rights Reserved.
  3. * Copyright 2005 Nokia. All rights reserved.
  4. *
  5. * Licensed under the OpenSSL license (the "License"). You may not use
  6. * this file except in compliance with the License. You can obtain a copy
  7. * in the file LICENSE in the source distribution or at
  8. * https://www.openssl.org/source/license.html
  9. */
  10. #include <stdio.h>
  11. #include "ssl_locl.h"
  12. const char *SSL_state_string_long(const SSL *s)
  13. {
  14. if (ossl_statem_in_error(s))
  15. return "error";
  16. switch (SSL_get_state(s)) {
  17. case TLS_ST_CR_CERT_STATUS:
  18. return "SSLv3/TLS read certificate status";
  19. case TLS_ST_CW_NEXT_PROTO:
  20. return "SSLv3/TLS write next proto";
  21. case TLS_ST_SR_NEXT_PROTO:
  22. return "SSLv3/TLS read next proto";
  23. case TLS_ST_SW_CERT_STATUS:
  24. return "SSLv3/TLS write certificate status";
  25. case TLS_ST_BEFORE:
  26. return "before SSL initialization";
  27. case TLS_ST_OK:
  28. return "SSL negotiation finished successfully";
  29. case TLS_ST_CW_CLNT_HELLO:
  30. return "SSLv3/TLS write client hello";
  31. case TLS_ST_CR_SRVR_HELLO:
  32. return "SSLv3/TLS read server hello";
  33. case TLS_ST_CR_CERT:
  34. return "SSLv3/TLS read server certificate";
  35. case TLS_ST_CR_KEY_EXCH:
  36. return "SSLv3/TLS read server key exchange";
  37. case TLS_ST_CR_CERT_REQ:
  38. return "SSLv3/TLS read server certificate request";
  39. case TLS_ST_CR_SESSION_TICKET:
  40. return "SSLv3/TLS read server session ticket";
  41. case TLS_ST_CR_SRVR_DONE:
  42. return "SSLv3/TLS read server done";
  43. case TLS_ST_CW_CERT:
  44. return "SSLv3/TLS write client certificate";
  45. case TLS_ST_CW_KEY_EXCH:
  46. return "SSLv3/TLS write client key exchange";
  47. case TLS_ST_CW_CERT_VRFY:
  48. return "SSLv3/TLS write certificate verify";
  49. case TLS_ST_CW_CHANGE:
  50. case TLS_ST_SW_CHANGE:
  51. return "SSLv3/TLS write change cipher spec";
  52. case TLS_ST_CW_FINISHED:
  53. case TLS_ST_SW_FINISHED:
  54. return "SSLv3/TLS write finished";
  55. case TLS_ST_CR_CHANGE:
  56. case TLS_ST_SR_CHANGE:
  57. return "SSLv3/TLS read change cipher spec";
  58. case TLS_ST_CR_FINISHED:
  59. case TLS_ST_SR_FINISHED:
  60. return "SSLv3/TLS read finished";
  61. case TLS_ST_SR_CLNT_HELLO:
  62. return "SSLv3/TLS read client hello";
  63. case TLS_ST_SW_HELLO_REQ:
  64. return "SSLv3/TLS write hello request";
  65. case TLS_ST_SW_SRVR_HELLO:
  66. return "SSLv3/TLS write server hello";
  67. case TLS_ST_SW_CERT:
  68. return "SSLv3/TLS write certificate";
  69. case TLS_ST_SW_KEY_EXCH:
  70. return "SSLv3/TLS write key exchange";
  71. case TLS_ST_SW_CERT_REQ:
  72. return "SSLv3/TLS write certificate request";
  73. case TLS_ST_SW_SESSION_TICKET:
  74. return "SSLv3/TLS write session ticket";
  75. case TLS_ST_SW_SRVR_DONE:
  76. return "SSLv3/TLS write server done";
  77. case TLS_ST_SR_CERT:
  78. return "SSLv3/TLS read client certificate";
  79. case TLS_ST_SR_KEY_EXCH:
  80. return "SSLv3/TLS read client key exchange";
  81. case TLS_ST_SR_CERT_VRFY:
  82. return "SSLv3/TLS read certificate verify";
  83. case DTLS_ST_CR_HELLO_VERIFY_REQUEST:
  84. return "DTLS1 read hello verify request";
  85. case DTLS_ST_SW_HELLO_VERIFY_REQUEST:
  86. return "DTLS1 write hello verify request";
  87. default:
  88. return "unknown state";
  89. }
  90. }
  91. const char *SSL_state_string(const SSL *s)
  92. {
  93. if (ossl_statem_in_error(s))
  94. return "SSLERR";
  95. switch (SSL_get_state(s)) {
  96. case TLS_ST_SR_NEXT_PROTO:
  97. return "TRNP";
  98. case TLS_ST_SW_SESSION_TICKET:
  99. return "TWST";
  100. case TLS_ST_SW_CERT_STATUS:
  101. return "TWCS";
  102. case TLS_ST_CR_CERT_STATUS:
  103. return "TRCS";
  104. case TLS_ST_CR_SESSION_TICKET:
  105. return "TRST";
  106. case TLS_ST_CW_NEXT_PROTO:
  107. return "TWNP";
  108. case TLS_ST_BEFORE:
  109. return "PINIT ";
  110. case TLS_ST_OK:
  111. return "SSLOK ";
  112. case TLS_ST_CW_CLNT_HELLO:
  113. return "TWCH";
  114. case TLS_ST_CR_SRVR_HELLO:
  115. return "TRSH";
  116. case TLS_ST_CR_CERT:
  117. return "TRSC";
  118. case TLS_ST_CR_KEY_EXCH:
  119. return "TRSKE";
  120. case TLS_ST_CR_CERT_REQ:
  121. return "TRCR";
  122. case TLS_ST_CR_SRVR_DONE:
  123. return "TRSD";
  124. case TLS_ST_CW_CERT:
  125. return "TWCC";
  126. case TLS_ST_CW_KEY_EXCH:
  127. return "TWCKE";
  128. case TLS_ST_CW_CERT_VRFY:
  129. return "TWCV";
  130. case TLS_ST_SW_CHANGE:
  131. case TLS_ST_CW_CHANGE:
  132. return "TWCCS";
  133. case TLS_ST_SW_FINISHED:
  134. case TLS_ST_CW_FINISHED:
  135. return "TWFIN";
  136. case TLS_ST_SR_CHANGE:
  137. case TLS_ST_CR_CHANGE:
  138. return "TRCCS";
  139. case TLS_ST_SR_FINISHED:
  140. case TLS_ST_CR_FINISHED:
  141. return "TRFIN";
  142. case TLS_ST_SW_HELLO_REQ:
  143. return "TWHR";
  144. case TLS_ST_SR_CLNT_HELLO:
  145. return "TRCH";
  146. case TLS_ST_SW_SRVR_HELLO:
  147. return "TWSH";
  148. case TLS_ST_SW_CERT:
  149. return "TWSC";
  150. case TLS_ST_SW_KEY_EXCH:
  151. return "TWSKE";
  152. case TLS_ST_SW_CERT_REQ:
  153. return "TWCR";
  154. case TLS_ST_SW_SRVR_DONE:
  155. return "TWSD";
  156. case TLS_ST_SR_CERT:
  157. return "TRCC";
  158. case TLS_ST_SR_KEY_EXCH:
  159. return "TRCKE";
  160. case TLS_ST_SR_CERT_VRFY:
  161. return "TRCV";
  162. case DTLS_ST_CR_HELLO_VERIFY_REQUEST:
  163. return "DRCHV";
  164. case DTLS_ST_SW_HELLO_VERIFY_REQUEST:
  165. return "DWCHV";
  166. default:
  167. return "UNKWN ";
  168. }
  169. }
  170. const char *SSL_alert_type_string_long(int value)
  171. {
  172. switch (value >> 8) {
  173. case SSL3_AL_WARNING:
  174. return "warning";
  175. case SSL3_AL_FATAL:
  176. return "fatal";
  177. default:
  178. return "unknown";
  179. }
  180. }
  181. const char *SSL_alert_type_string(int value)
  182. {
  183. switch (value >> 8) {
  184. case SSL3_AL_WARNING:
  185. return "W";
  186. case SSL3_AL_FATAL:
  187. return "F";
  188. default:
  189. return "U";
  190. }
  191. }
  192. const char *SSL_alert_desc_string(int value)
  193. {
  194. switch (value & 0xff) {
  195. case SSL3_AD_CLOSE_NOTIFY:
  196. return "CN";
  197. case SSL3_AD_UNEXPECTED_MESSAGE:
  198. return "UM";
  199. case SSL3_AD_BAD_RECORD_MAC:
  200. return "BM";
  201. case SSL3_AD_DECOMPRESSION_FAILURE:
  202. return "DF";
  203. case SSL3_AD_HANDSHAKE_FAILURE:
  204. return "HF";
  205. case SSL3_AD_NO_CERTIFICATE:
  206. return "NC";
  207. case SSL3_AD_BAD_CERTIFICATE:
  208. return "BC";
  209. case SSL3_AD_UNSUPPORTED_CERTIFICATE:
  210. return "UC";
  211. case SSL3_AD_CERTIFICATE_REVOKED:
  212. return "CR";
  213. case SSL3_AD_CERTIFICATE_EXPIRED:
  214. return "CE";
  215. case SSL3_AD_CERTIFICATE_UNKNOWN:
  216. return "CU";
  217. case SSL3_AD_ILLEGAL_PARAMETER:
  218. return "IP";
  219. case TLS1_AD_DECRYPTION_FAILED:
  220. return "DC";
  221. case TLS1_AD_RECORD_OVERFLOW:
  222. return "RO";
  223. case TLS1_AD_UNKNOWN_CA:
  224. return "CA";
  225. case TLS1_AD_ACCESS_DENIED:
  226. return "AD";
  227. case TLS1_AD_DECODE_ERROR:
  228. return "DE";
  229. case TLS1_AD_DECRYPT_ERROR:
  230. return "CY";
  231. case TLS1_AD_EXPORT_RESTRICTION:
  232. return "ER";
  233. case TLS1_AD_PROTOCOL_VERSION:
  234. return "PV";
  235. case TLS1_AD_INSUFFICIENT_SECURITY:
  236. return "IS";
  237. case TLS1_AD_INTERNAL_ERROR:
  238. return "IE";
  239. case TLS1_AD_USER_CANCELLED:
  240. return "US";
  241. case TLS1_AD_NO_RENEGOTIATION:
  242. return "NR";
  243. case TLS1_AD_UNSUPPORTED_EXTENSION:
  244. return "UE";
  245. case TLS1_AD_CERTIFICATE_UNOBTAINABLE:
  246. return "CO";
  247. case TLS1_AD_UNRECOGNIZED_NAME:
  248. return "UN";
  249. case TLS1_AD_BAD_CERTIFICATE_STATUS_RESPONSE:
  250. return "BR";
  251. case TLS1_AD_BAD_CERTIFICATE_HASH_VALUE:
  252. return "BH";
  253. case TLS1_AD_UNKNOWN_PSK_IDENTITY:
  254. return "UP";
  255. default:
  256. return "UK";
  257. }
  258. }
  259. const char *SSL_alert_desc_string_long(int value)
  260. {
  261. switch (value & 0xff) {
  262. case SSL3_AD_CLOSE_NOTIFY:
  263. return "close notify";
  264. case SSL3_AD_UNEXPECTED_MESSAGE:
  265. return "unexpected_message";
  266. case SSL3_AD_BAD_RECORD_MAC:
  267. return "bad record mac";
  268. case SSL3_AD_DECOMPRESSION_FAILURE:
  269. return "decompression failure";
  270. case SSL3_AD_HANDSHAKE_FAILURE:
  271. return "handshake failure";
  272. case SSL3_AD_NO_CERTIFICATE:
  273. return "no certificate";
  274. case SSL3_AD_BAD_CERTIFICATE:
  275. return "bad certificate";
  276. case SSL3_AD_UNSUPPORTED_CERTIFICATE:
  277. return "unsupported certificate";
  278. case SSL3_AD_CERTIFICATE_REVOKED:
  279. return "certificate revoked";
  280. case SSL3_AD_CERTIFICATE_EXPIRED:
  281. return "certificate expired";
  282. case SSL3_AD_CERTIFICATE_UNKNOWN:
  283. return "certificate unknown";
  284. case SSL3_AD_ILLEGAL_PARAMETER:
  285. return "illegal parameter";
  286. case TLS1_AD_DECRYPTION_FAILED:
  287. return "decryption failed";
  288. case TLS1_AD_RECORD_OVERFLOW:
  289. return "record overflow";
  290. case TLS1_AD_UNKNOWN_CA:
  291. return "unknown CA";
  292. case TLS1_AD_ACCESS_DENIED:
  293. return "access denied";
  294. case TLS1_AD_DECODE_ERROR:
  295. return "decode error";
  296. case TLS1_AD_DECRYPT_ERROR:
  297. return "decrypt error";
  298. case TLS1_AD_EXPORT_RESTRICTION:
  299. return "export restriction";
  300. case TLS1_AD_PROTOCOL_VERSION:
  301. return "protocol version";
  302. case TLS1_AD_INSUFFICIENT_SECURITY:
  303. return "insufficient security";
  304. case TLS1_AD_INTERNAL_ERROR:
  305. return "internal error";
  306. case TLS1_AD_USER_CANCELLED:
  307. return "user canceled";
  308. case TLS1_AD_NO_RENEGOTIATION:
  309. return "no renegotiation";
  310. case TLS1_AD_UNSUPPORTED_EXTENSION:
  311. return "unsupported extension";
  312. case TLS1_AD_CERTIFICATE_UNOBTAINABLE:
  313. return "certificate unobtainable";
  314. case TLS1_AD_UNRECOGNIZED_NAME:
  315. return "unrecognized name";
  316. case TLS1_AD_BAD_CERTIFICATE_STATUS_RESPONSE:
  317. return "bad certificate status response";
  318. case TLS1_AD_BAD_CERTIFICATE_HASH_VALUE:
  319. return "bad certificate hash value";
  320. case TLS1_AD_UNKNOWN_PSK_IDENTITY:
  321. return "unknown PSK identity";
  322. case TLS1_AD_NO_APPLICATION_PROTOCOL:
  323. return "no application protocol";
  324. default:
  325. return "unknown";
  326. }
  327. }