/*************************************************************************** * Copyright (c) 2024 Microsoft Corporation * Copyright (c) 2025-present Eclipse ThreadX Contributors * * This program and the accompanying materials are made available under the * terms of the MIT License which is available at * https://opensource.org/licenses/MIT. * * SPDX-License-Identifier: MIT **************************************************************************/ /**************************************************************************/ /**************************************************************************/ /** */ /** NetX Secure Component */ /** */ /** Transport Layer Security (TLS) */ /** */ /**************************************************************************/ /**************************************************************************/ #define NX_SECURE_SOURCE_CODE #include "nx_secure_tls.h" /**************************************************************************/ /* */ /* FUNCTION RELEASE */ /* */ /* _nx_secure_tls_send_alert PORTABLE C */ /* 6.4.3 */ /* AUTHOR */ /* */ /* Timothy Stapko, Microsoft Corporation */ /* */ /* DESCRIPTION */ /* */ /* This function populates an NX_PACKET with a TLS Alert message, */ /* which indicates an error (and possible security breach) has been */ /* detected. The alert notifies the remote host of the error. */ /* */ /* INPUT */ /* */ /* tls_session TLS control block */ /* send_packet Packet to be filled */ /* alert_number TLS alert number */ /* alert_level TLS alert severity */ /* */ /* OUTPUT */ /* */ /* None */ /* */ /* CALLS */ /* */ /* None */ /* */ /* CALLED BY */ /* */ /* _nx_secure_dtls_client_handshake DTLS client state machine */ /* _nx_secure_dtls_server_handshake DTLS server state machine */ /* _nx_secure_dtls_session_end End of a session */ /* _nx_secure_dtls_session_receive Receive DTLS data */ /* _nx_secure_tls_client_handshake TLS client state machine */ /* _nx_secure_tls_server_handshake TLS server state machine */ /* _nx_secure_tls_session_end End of a session */ /* _nx_secure_tls_session_receive_records */ /* Receive TLS records */ /* */ /**************************************************************************/ VOID _nx_secure_tls_send_alert(NX_SECURE_TLS_SESSION *tls_session, NX_PACKET *send_packet, UCHAR alert_number, UCHAR alert_level) { #ifndef NX_SECURE_TLS_CLIENT_DISABLED if (tls_session -> nx_secure_tls_socket_type == NX_SECURE_TLS_SESSION_TYPE_CLIENT) { tls_session -> nx_secure_tls_client_state = NX_SECURE_TLS_CLIENT_STATE_ALERT_SENT; } #endif #ifndef NX_SECURE_TLS_SERVER_DISABLED if (tls_session -> nx_secure_tls_socket_type == NX_SECURE_TLS_SESSION_TYPE_SERVER) { tls_session -> nx_secure_tls_server_state = NX_SECURE_TLS_SERVER_STATE_ALERT_SENT; } #endif /* Populate the buffer with the alert level and alert number to send to the remote host. */ send_packet -> nx_packet_append_ptr[0] = alert_level; send_packet -> nx_packet_append_ptr[1] = alert_number; /* Make sure the caller has the right length of data to send. */ send_packet -> nx_packet_append_ptr = send_packet -> nx_packet_append_ptr + 2; send_packet -> nx_packet_length = 2; }