/*************************************************************************** * Copyright (c) 2024 Microsoft Corporation * Copyright (c) 2025-present Eclipse ThreadX Contributors * * This program and the accompanying materials are made available under the * terms of the MIT License which is available at * https://opensource.org/licenses/MIT. * * SPDX-License-Identifier: MIT **************************************************************************/ /**************************************************************************/ /**************************************************************************/ /** */ /** NetX Secure Component */ /** */ /** Transport Layer Security (TLS) */ /** */ /**************************************************************************/ /**************************************************************************/ #define NX_SECURE_SOURCE_CODE #include "nx_secure_tls.h" /**************************************************************************/ /* */ /* FUNCTION RELEASE */ /* */ /* _nx_secure_tls_generate_premaster_secret PORTABLE C */ /* 6.4.3 */ /* AUTHOR */ /* */ /* Timothy Stapko, Microsoft Corporation */ /* */ /* DESCRIPTION */ /* */ /* This function generates the Pre-Master Secret for TLS Client */ /* instances. It is sent to the remote host and used as the seed for */ /* session key generation. */ /* */ /* INPUT */ /* */ /* tls_session TLS control block */ /* id TLS or DTLS */ /* */ /* OUTPUT */ /* */ /* status Completion status */ /* */ /* CALLS */ /* */ /* _nx_secure_tls_protocol_version_get Get current TLS version to use*/ /* [nx_secure_generate_premaster_secret] Generate pre-master secret */ /* */ /* CALLED BY */ /* */ /* _nx_secure_dtls_client_handshake DTLS client state machine */ /* _nx_secure_tls_client_handshake TLS client state machine */ /* _nx_secure_tls_process_client_key_exchange */ /* Process ClientKeyExchange */ /* */ /**************************************************************************/ UINT _nx_secure_tls_generate_premaster_secret(NX_SECURE_TLS_SESSION *tls_session, UINT id) { UINT status; USHORT protocol_version; if (tls_session -> nx_secure_tls_session_ciphersuite == NX_NULL) { /* Likely internal error since at this point ciphersuite negotiation was theoretically completed. */ return(NX_SECURE_TLS_UNKNOWN_CIPHERSUITE); } _nx_secure_tls_protocol_version_get(tls_session, &protocol_version, id); #ifdef NX_SECURE_ENABLE_ECC_CIPHERSUITE status = tls_session -> nx_secure_generate_premaster_secret(tls_session -> nx_secure_tls_session_ciphersuite, protocol_version, &tls_session -> nx_secure_tls_key_material, &tls_session -> nx_secure_tls_credentials, tls_session -> nx_secure_tls_socket_type, &tls_session -> nx_secure_tls_received_remote_credentials, tls_session -> nx_secure_public_cipher_metadata_area, tls_session -> nx_secure_public_cipher_metadata_size, &tls_session -> nx_secure_tls_ecc); #else status = tls_session -> nx_secure_generate_premaster_secret(tls_session -> nx_secure_tls_session_ciphersuite, protocol_version, &tls_session -> nx_secure_tls_key_material, &tls_session -> nx_secure_tls_credentials, tls_session -> nx_secure_tls_socket_type, &tls_session -> nx_secure_tls_received_remote_credentials, tls_session -> nx_secure_public_cipher_metadata_area, tls_session -> nx_secure_public_cipher_metadata_size, NX_NULL); #endif return(status); }