Skip to main content

cturtle/bttls

include "cturtle/bttls";

Types​

BttlsClientHello​

Object

FieldTypeWritableDescription
handshakebufferyes
randombufferyes

BttlsServerHello​

Object

FieldTypeWritableDescription
hello_retry_requestboolyes
randombufferyes
peer_key_sharebufferyes
cookiebufferyes

BttlsHandshakeSecrets​

Object

FieldTypeWritableDescription
client_secretbufferyes
server_secretbufferyes
master_secretbufferyes

BttlsTrafficKeys​

Object

FieldTypeWritableDescription
traffic_secretbufferyes
keybufferyes
ivbufferyes
recordsTlsRecordSequenceyes
wipedboolyes

TlsHandshakeMessage​

Object

FieldTypeWritableDescription
message_typeintyes
bodybufferyes
encodedbufferyes

TlsHandshakeParser​

Object

FieldTypeWritableDescription
pendingbufferyes
maximum_messageintyes

TlsClientHandshakeState​

Object

FieldTypeWritableDescription
phaseintyes
retry_countintyes
certificate_chain_validatedboolyes
certificate_verify_validatedboolyes
server_finished_validatedboolyes
ignored_ticketsintyes
received_key_updatesintyes
receive_key_update_pendingboolyes
key_update_response_requiredboolyes
send_key_update_pendingboolyes
send_epochintyes

TlsRecord​

Object

FieldTypeWritableDescription
content_typeintyes
legacy_versionintyes
headerbufferyes
fragmentbufferyes
protected_recordboolyes

TlsRecordParse​

Object

FieldTypeWritableDescription
recordTlsRecordyes
nextintyes

TlsInnerPlaintext​

Object

FieldTypeWritableDescription
content_typeintyes
contentbufferyes

TlsRecordSequence​

Object

FieldTypeWritableDescription
sequenceintyes
epochintyes
records_with_keyintyes
record_limitintyes
sendingboolyes

BtTlsClientConfig​

Object

FieldTypeWritableDescription
server_namestringyes
trust_anchorsarray<BttlsX509Certificate>yes
allow_wildcardsboolyes
maximum_handshake_messageintyes
maximum_certificate_bytesintyes
record_limitintyes

BtTlsConnection​

Object

FieldTypeWritableDescription
protocol_versionstringyes
cipher_suitestringyes
named_groupstringyes
signature_schemestringyes
verified_server_namestringyes

send​

fn send(buffer source, int offset, int count) -> int

receive​

fn receive(buffer output, int offset, int count) -> int

close infallible​

infallible fn close()

BttlsX509Algorithm​

Object

FieldTypeWritableDescription
oidstringyes
encodedbufferyes
has_parametersboolyes
parametersbufferyes

BttlsX509Time​

Object

FieldTypeWritableDescription
encodedstringyes
unix_secondsintyes

BttlsX509Certificate​

Object

FieldTypeWritableDescription
versionintyes
derbufferyes
tbs_certificatebufferyes
serial_numberbufferyes
signature_algorithmBttlsX509Algorithmyes
tbs_signature_algorithmBttlsX509Algorithmyes
signaturebufferyes
issuerbufferyes
subjectbufferyes
not_beforeBttlsX509Timeyes
not_afterBttlsX509Timeyes
subject_public_key_infobufferyes
public_key_algorithmBttlsX509Algorithmyes
subject_public_keybufferyes
subject_alt_name_presentboolyes
subject_alt_name_criticalboolyes
san_dns_namesarray<string>yes
san_ip_addressesarray<buffer>yes
basic_constraints_presentboolyes
basic_constraints_criticalboolyes
is_caboolyes
path_lengthintyes
key_usage_presentboolyes
key_usageintyes
extended_key_usage_presentboolyes
extended_key_usagearray<string>yes
subject_key_identifierbufferyes
authority_key_identifierbufferyes

BttlsX509VerifyLimits​

Object

FieldTypeWritableDescription
max_peer_certificatesintyes
max_trust_anchorsintyes
max_depthintyes
max_path_candidatesintyes

BttlsX509VerifiedServer​

Object

FieldTypeWritableDescription
leafBttlsX509Certificateyes
p256_public_keybufferyes
path_certificatesintyes
trust_anchor_indexintyes
dns_identityboolyes
reference_dns_namestringyes
reference_ip_addressbufferyes

Interfaces​

BtTlsKeyAgreement​

Interface

public_key​

fn public_key(buffer output)

shared_secret​

fn shared_secret(buffer peer_public_key, buffer shared_secret)

close infallible​

infallible fn close()

BtTlsCryptoProvider​

Interface

random​

fn random(buffer output)

utc_seconds​

fn utc_seconds() -> int

sha256​

fn sha256(buffer message, buffer digest)

hmac_sha256​

fn hmac_sha256(buffer key, buffer message, buffer tag)

pbkdf2_sha256​

fn pbkdf2_sha256(
buffer password,
buffer salt,
int iterations,
buffer output)

hkdf_extract_sha256​

fn hkdf_extract_sha256(buffer salt, buffer ikm, buffer prk)

hkdf_expand_sha256​

fn hkdf_expand_sha256(buffer prk, buffer info, buffer output)

equal​

fn equal(buffer left, buffer right) -> bool

wipe​

fn wipe(buffer secret)

xor_bytes​

fn xor_bytes(buffer left, buffer right, buffer output)

record_nonce​

fn record_nonce(buffer iv, int sequence, buffer nonce)

aes128_gcm_seal​

fn aes128_gcm_seal(
buffer key,
buffer nonce,
buffer additional_data,
buffer plaintext,
buffer ciphertext_and_tag)

aes128_gcm_open​

fn aes128_gcm_open(
buffer key,
buffer nonce,
buffer additional_data,
buffer ciphertext_and_tag,
buffer plaintext)

p256_generate​

fn p256_generate() -> BtTlsKeyAgreement

x25519_generate​

fn x25519_generate() -> BtTlsKeyAgreement

rsa_pss_sha256_verify​

fn rsa_pss_sha256_verify(
buffer modulus,
int exponent,
buffer message,
buffer signature) -> bool

rsa_pkcs1_sha256_verify​

fn rsa_pkcs1_sha256_verify(
buffer modulus,
int exponent,
buffer message,
buffer signature) -> bool

ecdsa_p256_sha256_verify​

fn ecdsa_p256_sha256_verify(
buffer public_key,
buffer message,
buffer signature) -> bool

Functions​

bttls_reference_sha256​

fn bttls_reference_sha256(buffer message) -> buffer

bttls_reference_hmac_sha256​

fn bttls_reference_hmac_sha256(buffer key, buffer message) -> buffer

bttls_reference_hkdf_extract_sha256​

fn bttls_reference_hkdf_extract_sha256(buffer salt, buffer ikm) -> buffer

bttls_reference_hkdf_expand_sha256​

fn bttls_reference_hkdf_expand_sha256(
buffer pseudorandom_key,
buffer info,
int length) -> buffer

bttls_hkdf_expand_label_sha256​

fn bttls_hkdf_expand_label_sha256(
BtTlsCryptoProvider provider,
buffer secret,
string label,
buffer context,
buffer output)

bttls_reference_hkdf_expand_label_sha256​

fn bttls_reference_hkdf_expand_label_sha256(
buffer secret,
string label,
buffer context,
int length) -> buffer

bttls_crypto_equal_reference​

fn bttls_crypto_equal_reference(buffer left, buffer right) -> bool

bttls_der_buffers_equal​

fn bttls_der_buffers_equal(buffer left, buffer right) -> bool

bttls_der_validate​

fn bttls_der_validate(buffer bytes, int max_depth, int max_elements)

bttls_identity_dns_matches​

fn bttls_identity_dns_matches(
string presented,
string reference,
bool allow_wildcards) -> bool

bttls_identity_verify_dns​

fn bttls_identity_verify_dns(
BttlsX509Certificate certificate,
string reference_dns_name,
bool allow_wildcards)

bttls_identity_verify_ip​

fn bttls_identity_verify_ip(
BttlsX509Certificate certificate,
buffer reference_address)

bttls_x509_verify_validity​

fn bttls_x509_verify_validity(
BttlsX509Certificate certificate,
int trusted_unix_seconds)

bttls_x509_verify_tls_server_leaf_profile​

fn bttls_x509_verify_tls_server_leaf_profile(
BttlsX509Certificate certificate)

bttls_pem_decode_certificates​

fn bttls_pem_decode_certificates(
string text,
int max_input_bytes,
int max_certificates,
int max_der_bytes) -> array<buffer>

bttls_cipher_aes_128_gcm_sha256 infallible​

infallible fn bttls_cipher_aes_128_gcm_sha256() -> int

bttls_group_secp256r1 infallible​

infallible fn bttls_group_secp256r1() -> int

bttls_extension_supported_versions infallible​

infallible fn bttls_extension_supported_versions() -> int

infallible fn bttls_extension_cookie() -> int

bttls_extension_key_share infallible​

infallible fn bttls_extension_key_share() -> int

bttls_public_equal​

fn bttls_public_equal(buffer left, buffer right) -> bool

bttls_push_u16​

fn bttls_push_u16(buffer output, int value)

bttls_append​

fn bttls_append(buffer output, buffer value)

bttls_push_extension​

fn bttls_push_extension(buffer extensions, int extension_type, buffer data)

bttls_build_client_hello​

fn bttls_build_client_hello(
buffer client_random,
buffer public_key,
string server_name,
buffer cookie) -> BttlsClientHello

bttls_hrr_random_bytes infallible​

infallible fn bttls_hrr_random_bytes() -> array<int>

bttls_parse_server_hello​

fn bttls_parse_server_hello(
TlsHandshakeMessage message,
bool already_retried) -> BttlsServerHello

bttls_parse_encrypted_extensions​

fn bttls_parse_encrypted_extensions(TlsHandshakeMessage message)

bttls_parse_certificate_chain​

fn bttls_parse_certificate_chain(
TlsHandshakeMessage message,
int maximum_certificates,
int maximum_certificate_bytes) -> array<buffer>

bttls_handshake_secrets​

fn bttls_handshake_secrets(
BtTlsCryptoProvider provider,
buffer shared_secret,
buffer transcript) -> BttlsHandshakeSecrets

bttls_traffic_keys​

fn bttls_traffic_keys(
BtTlsCryptoProvider provider,
buffer traffic_secret,
int record_limit,
bool sending) -> BttlsTrafficKeys

bttls_traffic_keys_update​

fn bttls_traffic_keys_update(
BtTlsCryptoProvider provider,
BttlsTrafficKeys keys)

bttls_traffic_keys_wipe​

fn bttls_traffic_keys_wipe(
BtTlsCryptoProvider provider,
BttlsTrafficKeys keys)

bttls_finished_verify_data​

fn bttls_finished_verify_data(
BtTlsCryptoProvider provider,
buffer base_key,
buffer transcript) -> buffer

bttls_verify_server_finished​

fn bttls_verify_server_finished(
BtTlsCryptoProvider provider,
buffer server_handshake_secret,
buffer transcript,
TlsHandshakeMessage message)

tls_handshake_client_hello infallible​

infallible fn tls_handshake_client_hello() -> int

tls_handshake_server_hello infallible​

infallible fn tls_handshake_server_hello() -> int

tls_handshake_new_session_ticket infallible​

infallible fn tls_handshake_new_session_ticket() -> int

tls_handshake_end_of_early_data infallible​

infallible fn tls_handshake_end_of_early_data() -> int

tls_handshake_encrypted_extensions infallible​

infallible fn tls_handshake_encrypted_extensions() -> int

tls_handshake_certificate infallible​

infallible fn tls_handshake_certificate() -> int

tls_handshake_certificate_request infallible​

infallible fn tls_handshake_certificate_request() -> int

tls_handshake_certificate_verify infallible​

infallible fn tls_handshake_certificate_verify() -> int

tls_handshake_finished infallible​

infallible fn tls_handshake_finished() -> int

tls_handshake_key_update infallible​

infallible fn tls_handshake_key_update() -> int

tls_handshake_message_hash infallible​

infallible fn tls_handshake_message_hash() -> int

tls_client_phase_new infallible​

infallible fn tls_client_phase_new() -> int

tls_client_phase_client_hello_sent infallible​

infallible fn tls_client_phase_client_hello_sent() -> int

tls_client_phase_hello_retry_received infallible​

infallible fn tls_client_phase_hello_retry_received() -> int

tls_client_phase_server_hello_received infallible​

infallible fn tls_client_phase_server_hello_received() -> int

tls_client_phase_encrypted_extensions_received infallible​

infallible fn tls_client_phase_encrypted_extensions_received() -> int

tls_client_phase_certificate_received infallible​

infallible fn tls_client_phase_certificate_received() -> int

tls_client_phase_certificate_verify_received infallible​

infallible fn tls_client_phase_certificate_verify_received() -> int

tls_client_phase_certificate_verify_validated infallible​

infallible fn tls_client_phase_certificate_verify_validated() -> int

tls_client_phase_server_finished_received infallible​

infallible fn tls_client_phase_server_finished_received() -> int

tls_client_phase_server_finished_validated infallible​

infallible fn tls_client_phase_server_finished_validated() -> int

tls_client_phase_connected infallible​

infallible fn tls_client_phase_connected() -> int

tls_client_phase_closed infallible​

infallible fn tls_client_phase_closed() -> int

tls_handshake_frame​

fn tls_handshake_frame(int message_type, buffer body) -> buffer

tls_handshake_message_hash_frame​

fn tls_handshake_message_hash_frame(buffer client_hello_hash) -> buffer

tls_handshake_parser​

fn tls_handshake_parser(int maximum_message) -> TlsHandshakeParser

tls_handshake_require_boundary​

fn tls_handshake_require_boundary(TlsHandshakeParser parser)

tls_handshake_feed​

fn tls_handshake_feed(
TlsHandshakeParser parser,
buffer fragment) -> array<TlsHandshakeMessage>

tls_handshake_finish​

fn tls_handshake_finish(TlsHandshakeParser parser)

tls_client_handshake_state infallible​

infallible fn tls_client_handshake_state() -> TlsClientHandshakeState

tls_client_mark_client_hello_sent​

fn tls_client_mark_client_hello_sent(TlsClientHandshakeState state)

tls_client_receive_server_hello​

fn tls_client_receive_server_hello(
TlsClientHandshakeState state,
bool hello_retry_request)

tls_client_mark_certificate_chain_validated​

fn tls_client_mark_certificate_chain_validated(
TlsClientHandshakeState state)

tls_client_mark_certificate_verify_validated​

fn tls_client_mark_certificate_verify_validated(
TlsClientHandshakeState state)

tls_client_mark_server_finished_validated​

fn tls_client_mark_server_finished_validated(TlsClientHandshakeState state)

tls_client_mark_client_finished_sent​

fn tls_client_mark_client_finished_sent(TlsClientHandshakeState state)

tls_client_accept_key_update​

fn tls_client_accept_key_update(
TlsClientHandshakeState state,
TlsHandshakeMessage message)

tls_client_mark_receive_keys_updated​

fn tls_client_mark_receive_keys_updated(TlsClientHandshakeState state)

tls_client_mark_key_update_response_sent​

fn tls_client_mark_key_update_response_sent(TlsClientHandshakeState state)

tls_client_mark_key_update_sent​

fn tls_client_mark_key_update_sent(TlsClientHandshakeState state)

tls_client_mark_send_keys_updated​

fn tls_client_mark_send_keys_updated(TlsClientHandshakeState state)

tls_client_receive_handshake​

fn tls_client_receive_handshake(
TlsClientHandshakeState state,
TlsHandshakeMessage message,
bool hello_retry_request)

tls_client_accept_compatibility_ccs​

fn tls_client_accept_compatibility_ccs(
TlsClientHandshakeState state,
TlsRecord record)

tls_client_can_receive_application_data infallible​

infallible fn tls_client_can_receive_application_data(
TlsClientHandshakeState state) -> bool

tls_client_can_send_application_data infallible​

infallible fn tls_client_can_send_application_data(
TlsClientHandshakeState state) -> bool

tls_client_close infallible​

infallible fn tls_client_close(TlsClientHandshakeState state)

tls_content_change_cipher_spec infallible​

infallible fn tls_content_change_cipher_spec() -> int

tls_content_alert infallible​

infallible fn tls_content_alert() -> int

tls_content_handshake infallible​

infallible fn tls_content_handshake() -> int

tls_content_application_data infallible​

infallible fn tls_content_application_data() -> int

tls_version_1_0 infallible​

infallible fn tls_version_1_0() -> int

tls_version_1_2 infallible​

infallible fn tls_version_1_2() -> int

tls_version_1_3 infallible​

infallible fn tls_version_1_3() -> int

tls_plaintext_limit infallible​

infallible fn tls_plaintext_limit() -> int

tls_inner_plaintext_limit infallible​

infallible fn tls_inner_plaintext_limit() -> int

tls_ciphertext_limit infallible​

infallible fn tls_ciphertext_limit() -> int

tls_aes_gcm_record_limit infallible​

infallible fn tls_aes_gcm_record_limit() -> int

tls_record_copy_range​

fn tls_record_copy_range(
buffer source,
int offset,
int count,
buffer destination)

tls_record_peek_size​

fn tls_record_peek_size(buffer bytes, int offset, bool protected_record) -> int

tls_record_parse​

fn tls_record_parse(
buffer bytes,
int offset,
bool protected_record) -> TlsRecordParse

tls_record_parse_exact​

fn tls_record_parse_exact(buffer bytes, bool protected_record) -> TlsRecord

tls_record_header​

fn tls_record_header(int content_type, int legacy_version, int length) -> buffer

tls_record_encode_plaintext​

fn tls_record_encode_plaintext(
int content_type,
buffer fragment,
bool initial_client_hello) -> buffer

tls_record_encode_ciphertext​

fn tls_record_encode_ciphertext(buffer encrypted_record) -> buffer

tls_inner_plaintext_encode​

fn tls_inner_plaintext_encode(
int content_type,
buffer content,
int padding_length) -> buffer

tls_inner_plaintext_parse​

fn tls_inner_plaintext_parse(buffer plaintext) -> TlsInnerPlaintext

tls_record_sequence​

fn tls_record_sequence(int record_limit, bool sending) -> TlsRecordSequence

tls_record_sequence_take​

fn tls_record_sequence_take(TlsRecordSequence state) -> int

tls_record_sequence_rekey​

fn tls_record_sequence_rekey(TlsRecordSequence state)

bttls_seal_record​

fn bttls_seal_record(
BtTlsCryptoProvider provider,
BttlsTrafficKeys keys,
int content_type,
buffer content) -> buffer

bttls_open_record​

fn bttls_open_record(
BtTlsCryptoProvider provider,
BttlsTrafficKeys keys,
TlsRecord record) -> TlsInnerPlaintext

bttls_client_config​

fn bttls_client_config(
string server_name,
array<BttlsX509Certificate> trust_anchors) -> BtTlsClientConfig

bttls_client_on_socket​

fn bttls_client_on_socket(
socket peer,
BtTlsCryptoProvider provider,
BtTlsClientConfig config) -> BtTlsConnection

bttls_client_connect_tcp​

fn bttls_client_connect_tcp(
string host,
string service,
int family,
BtTlsCryptoProvider provider,
BtTlsClientConfig config) -> BtTlsConnection

bttls_x509_parse_certificate​

fn bttls_x509_parse_certificate(
buffer der,
int max_certificate_bytes) -> BttlsX509Certificate

bttls_x509_key_usage_digital_signature infallible​

infallible fn bttls_x509_key_usage_digital_signature() -> int

bttls_x509_key_usage_key_cert_sign infallible​

infallible fn bttls_x509_key_usage_key_cert_sign() -> int

bttls_x509_key_usage_crl_sign infallible​

infallible fn bttls_x509_key_usage_crl_sign() -> int

bttls_x509_eku_server_auth infallible​

infallible fn bttls_x509_eku_server_auth() -> string

bttls_x509_default_verify_limits infallible​

infallible fn bttls_x509_default_verify_limits() -> BttlsX509VerifyLimits

bttls_x509_parse_pem_bundle​

fn bttls_x509_parse_pem_bundle(
string pem,
int max_input_bytes,
int max_certificates,
int max_certificate_bytes) -> array<BttlsX509Certificate>

bttls_x509_parse_der_chain​

fn bttls_x509_parse_der_chain(
array<buffer> encoded,
int max_certificates,
int max_certificate_bytes) -> array<BttlsX509Certificate>

bttls_x509_validate_ecdsa_signature_shape​

fn bttls_x509_validate_ecdsa_signature_shape(buffer signature)

bttls_x509_verify_certificate_signature​

fn bttls_x509_verify_certificate_signature(
BttlsX509Certificate certificate,
BttlsX509Certificate issuer,
BtTlsCryptoProvider provider)

bttls_x509_verify_server_dns​

fn bttls_x509_verify_server_dns(
array<BttlsX509Certificate> peers,
array<BttlsX509Certificate> trust_anchors,
BtTlsCryptoProvider provider,
string reference_dns_name,
bool allow_wildcards,
BttlsX509VerifyLimits limits) -> BttlsX509VerifiedServer

bttls_x509_verify_server_ip​

fn bttls_x509_verify_server_ip(
array<BttlsX509Certificate> peers,
array<BttlsX509Certificate> trust_anchors,
BtTlsCryptoProvider provider,
buffer reference_address,
BttlsX509VerifyLimits limits) -> BttlsX509VerifiedServer

x509_path_test_ca_pem infallible​

infallible fn x509_path_test_ca_pem() -> string

x509_path_test_leaf_pem infallible​

infallible fn x509_path_test_leaf_pem() -> string