File: TlsClientKeyExchange.cs

package info (click to toggle)
mono 1.2.2.1-1etch1
  • links: PTS
  • area: main
  • in suites: etch
  • size: 142,720 kB
  • ctags: 256,408
  • sloc: cs: 1,495,736; ansic: 249,442; sh: 18,327; xml: 12,463; makefile: 5,046; perl: 1,248; asm: 635; yacc: 285; sql: 7
file content (116 lines) | stat: -rw-r--r-- 4,252 bytes parent folder | download | duplicates (16)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
// Transport Security Layer (TLS)
// Copyright (c) 2003-2004 Carlos Guzman Alvarez
// Copyright (C) 2006 Novell, Inc (http://www.novell.com)
//
// Permission is hereby granted, free of charge, to any person obtaining
// a copy of this software and associated documentation files (the
// "Software"), to deal in the Software without restriction, including
// without limitation the rights to use, copy, modify, merge, publish,
// distribute, sublicense, and/or sell copies of the Software, and to
// permit persons to whom the Software is furnished to do so, subject to
// the following conditions:
// 
// The above copyright notice and this permission notice shall be
// included in all copies or substantial portions of the Software.
// 
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
// EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
// NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
// LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
// OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
// WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
//

using System;
using System.IO;
using System.Security.Cryptography;
using System.Security.Cryptography.X509Certificates;

namespace Mono.Security.Protocol.Tls.Handshake.Server
{
    internal class TlsClientKeyExchange : HandshakeMessage
    {
        #region Constructors

        public TlsClientKeyExchange(Context context, byte[] buffer) : 
			base(context,
				HandshakeType.ClientKeyExchange, 
				buffer)
        {
        }

        #endregion

        #region Protected Methods

        protected override void ProcessAsSsl3()
        {
            AsymmetricAlgorithm privKey = null;
            ServerContext context = (ServerContext)this.Context;

            // Select the private key information
            privKey = context.SslStream.RaisePrivateKeySelection(
                new X509Certificate(context.ServerSettings.Certificates[0].RawData),
                null);

            if (privKey == null)
            {
                throw new TlsException(AlertDescription.UserCancelled, "Server certificate Private Key unavailable.");
            }

            // Read client premaster secret
            byte[] clientSecret = this.ReadBytes((int)this.Length);

            // Decrypt premaster secret
            RSAPKCS1KeyExchangeDeformatter deformatter = new RSAPKCS1KeyExchangeDeformatter(privKey);

            byte[] preMasterSecret = deformatter.DecryptKeyExchange(clientSecret);

            // Create master secret
            this.Context.Negotiating.Cipher.ComputeMasterSecret(preMasterSecret);

            // Create keys
	    this.Context.Negotiating.Cipher.ComputeKeys ();

            // Initialize Cipher Suite
	    this.Context.Negotiating.Cipher.InitializeCipher ();
        }

        protected override void ProcessAsTls1()
        {
            AsymmetricAlgorithm privKey = null;
            ServerContext context = (ServerContext)this.Context;

            // Select the private key information
            // Select the private key information
            privKey = context.SslStream.RaisePrivateKeySelection(
                new X509Certificate(context.ServerSettings.Certificates[0].RawData),
                null);

            if (privKey == null)
            {
                throw new TlsException(AlertDescription.UserCancelled, "Server certificate Private Key unavailable.");
            }

            // Read client premaster secret
            byte[] clientSecret = this.ReadBytes(this.ReadInt16());

            // Decrypt premaster secret
            RSAPKCS1KeyExchangeDeformatter deformatter = new RSAPKCS1KeyExchangeDeformatter(privKey);

            byte[] preMasterSecret = deformatter.DecryptKeyExchange(clientSecret);

            // Create master secret
            this.Context.Negotiating.Cipher.ComputeMasterSecret(preMasterSecret);

            // Create keys
            this.Context.Negotiating.Cipher.ComputeKeys();

            // Initialize Cipher Suite
            this.Context.Negotiating.Cipher.InitializeCipher();
        }

        #endregion
    }
}