Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 1 | /** |
| 2 | * \file baremetal.h |
| 3 | * |
| 4 | * \brief Test configuration for minimal baremetal Mbed TLS builds |
| 5 | * based on the following primitives: |
| 6 | * - ECDHE-ECDSA only |
| 7 | * - Elliptic curve SECP256R1 only |
| 8 | * - SHA-256 only |
| 9 | * - AES-CCM-8 only |
| 10 | * |
| 11 | * The library compiles in this configuration, but the example |
| 12 | * programs `ssl_client2` and `ssl_server2` require the |
| 13 | * modifications from `baremetal_test.h`. |
| 14 | */ |
| 15 | /* |
| 16 | * Copyright (C) 2006-2018, ARM Limited, All Rights Reserved |
| 17 | * SPDX-License-Identifier: Apache-2.0 |
| 18 | * |
| 19 | * Licensed under the Apache License, Version 2.0 (the "License"); you may |
| 20 | * not use this file except in compliance with the License. |
| 21 | * You may obtain a copy of the License at |
| 22 | * |
| 23 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 24 | * |
| 25 | * Unless required by applicable law or agreed to in writing, software |
| 26 | * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT |
| 27 | * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 28 | * See the License for the specific language governing permissions and |
| 29 | * limitations under the License. |
| 30 | * |
| 31 | * This file is part of mbed TLS (https://tls.mbed.org) |
| 32 | */ |
| 33 | |
| 34 | #ifndef MBEDTLS_BAREMETAL_CONFIG_H |
| 35 | #define MBEDTLS_BAREMETAL_CONFIG_H |
| 36 | |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 37 | /* Symmetric crypto: AES-CCM only */ |
| 38 | #define MBEDTLS_CIPHER_C |
| 39 | #define MBEDTLS_AES_C |
| 40 | #define MBEDTLS_AES_ROM_TABLES |
| 41 | #define MBEDTLS_AES_FEWER_TABLES |
Arto Kinnunen | 77b9cfc | 2019-08-30 11:43:21 +0300 | [diff] [blame] | 42 | #define MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH |
Arto Kinnunen | 1480444 | 2019-10-16 13:43:59 +0300 | [diff] [blame] | 43 | #define MBEDTLS_AES_ONLY_ENCRYPT |
Arto Kinnunen | be1bb06 | 2019-12-03 14:13:33 +0200 | [diff] [blame] | 44 | #define MBEDTLS_AES_SCA_COUNTERMEASURES |
Shelly Liberman | c907c81 | 2020-11-17 11:33:25 +0200 | [diff] [blame] | 45 | #define MBEDTLS_AES_128_BIT_MASKED |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 46 | #define MBEDTLS_CCM_C |
| 47 | |
| 48 | /* Asymmetric crypto: Single-curve ECC only. */ |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 49 | #define MBEDTLS_PK_C |
| 50 | #define MBEDTLS_PK_PARSE_C |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 51 | |
Hanno Becker | ead3aae | 2019-09-19 16:59:13 +0100 | [diff] [blame] | 52 | #define MBEDTLS_ENTROPY_MAX_SOURCES 1 |
| 53 | |
Hanno Becker | c1096e7 | 2019-06-19 12:30:41 +0100 | [diff] [blame] | 54 | #define MBEDTLS_SSL_CONF_SINGLE_EC |
Hanno Becker | a007e0d | 2019-09-02 16:24:00 +0100 | [diff] [blame] | 55 | #define MBEDTLS_SSL_CONF_SINGLE_UECC_GRP_ID MBEDTLS_UECC_DP_SECP256R1 |
Hanno Becker | c1096e7 | 2019-06-19 12:30:41 +0100 | [diff] [blame] | 56 | #define MBEDTLS_SSL_CONF_SINGLE_EC_TLS_ID 23 |
Hanno Becker | 56595f4 | 2019-06-19 16:31:38 +0100 | [diff] [blame] | 57 | #define MBEDTLS_SSL_CONF_SINGLE_SIG_HASH |
| 58 | #define MBEDTLS_SSL_CONF_SINGLE_SIG_HASH_MD_ID MBEDTLS_MD_SHA256 |
| 59 | #define MBEDTLS_SSL_CONF_SINGLE_SIG_HASH_TLS_ID MBEDTLS_SSL_HASH_SHA256 |
Hanno Becker | c1096e7 | 2019-06-19 12:30:41 +0100 | [diff] [blame] | 60 | |
Manuel Pégourié-Gonnard | 1c1cc0d | 2019-09-19 10:45:14 +0200 | [diff] [blame] | 61 | /* Harcoded options in abstraction layers */ |
Hanno Becker | d806d9d | 2019-08-13 16:09:10 +0100 | [diff] [blame] | 62 | #define MBEDTLS_MD_SINGLE_HASH MBEDTLS_MD_INFO_SHA256 |
Manuel Pégourié-Gonnard | 1c1cc0d | 2019-09-19 10:45:14 +0200 | [diff] [blame] | 63 | #define MBEDTLS_PK_SINGLE_TYPE MBEDTLS_PK_INFO_ECKEY |
Hanno Becker | d806d9d | 2019-08-13 16:09:10 +0100 | [diff] [blame] | 64 | |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 65 | /* Key exchanges */ |
| 66 | #define MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED |
Hanno Becker | 224eb0c | 2019-04-10 12:24:10 +0100 | [diff] [blame] | 67 | #define MBEDTLS_SSL_CIPHERSUITES MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 |
Hanno Becker | 73f4cb1 | 2019-06-27 13:51:07 +0100 | [diff] [blame] | 68 | #define MBEDTLS_SSL_CONF_SINGLE_CIPHERSUITE MBEDTLS_SUITE_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 69 | |
| 70 | /* Digests - just SHA-256 */ |
| 71 | #define MBEDTLS_MD_C |
| 72 | #define MBEDTLS_SHA256_C |
| 73 | #define MBEDTLS_SHA256_SMALLER |
Manuel Pégourié-Gonnard | e06cc31 | 2019-07-16 16:15:28 +0200 | [diff] [blame] | 74 | #define MBEDTLS_SHA256_NO_SHA224 |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 75 | |
| 76 | /* TLS options */ |
| 77 | #define MBEDTLS_SSL_CLI_C |
| 78 | #define MBEDTLS_SSL_TLS_C |
| 79 | #define MBEDTLS_SSL_PROTO_TLS1_2 |
| 80 | #define MBEDTLS_SSL_EXTENDED_MASTER_SECRET |
Jarno Lamsa | 29f2dd0 | 2019-06-20 15:31:52 +0300 | [diff] [blame] | 81 | #define MBEDTLS_SSL_NO_SESSION_CACHE |
| 82 | #define MBEDTLS_SSL_NO_SESSION_RESUMPTION |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 83 | #define MBEDTLS_SSL_COOKIE_C |
Hanno Becker | 275e5bf | 2019-04-03 13:39:31 +0100 | [diff] [blame] | 84 | #define MBEDTLS_SSL_PROTO_DTLS |
Manuel Pégourié-Gonnard | 19e8132 | 2019-06-18 10:54:25 +0200 | [diff] [blame] | 85 | #define MBEDTLS_SSL_PROTO_NO_TLS |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 86 | #define MBEDTLS_SSL_DTLS_ANTI_REPLAY |
| 87 | #define MBEDTLS_SSL_DTLS_HELLO_VERIFY |
| 88 | #define MBEDTLS_SSL_DTLS_BADMAC_LIMIT |
Hanno Becker | a5a2b08 | 2019-05-15 14:03:01 +0100 | [diff] [blame] | 89 | #define MBEDTLS_SSL_DTLS_CONNECTION_ID |
Andrzej Kurek | 1175044 | 2020-09-17 07:12:06 -0400 | [diff] [blame] | 90 | #define MBEDTLS_SSL_TRANSFORM_OPTIMIZE_CIPHERS |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 91 | |
Hanno Becker | aabbb58 | 2019-06-11 13:43:27 +0100 | [diff] [blame] | 92 | /* Compile-time fixed parts of the SSL configuration */ |
Kevin Bracey | 585e9e0 | 2020-11-03 12:22:27 +0200 | [diff] [blame] | 93 | #define MBEDTLS_SSL_CONF_TRANSPORT MBEDTLS_SSL_TRANSPORT_DATAGRAM |
Hanno Becker | f3400da | 2019-06-13 12:36:31 +0100 | [diff] [blame] | 94 | #define MBEDTLS_SSL_CONF_CERT_REQ_CA_LIST MBEDTLS_SSL_CERT_REQ_CA_LIST_DISABLED |
Hanno Becker | 1f835fa | 2019-06-13 10:14:59 +0100 | [diff] [blame] | 95 | #define MBEDTLS_SSL_CONF_READ_TIMEOUT 0 |
| 96 | #define MBEDTLS_SSL_CONF_HS_TIMEOUT_MIN 1000 |
| 97 | #define MBEDTLS_SSL_CONF_HS_TIMEOUT_MAX 16000 |
Hanno Becker | 3b876ac | 2019-06-21 15:51:19 +0100 | [diff] [blame] | 98 | #define MBEDTLS_SSL_CONF_CID_LEN 2 |
Hanno Becker | e0200da | 2019-06-13 09:23:43 +0100 | [diff] [blame] | 99 | #define MBEDTLS_SSL_CONF_IGNORE_UNEXPECTED_CID MBEDTLS_SSL_UNEXPECTED_CID_IGNORE |
Hanno Becker | b0b2b67 | 2019-06-12 16:58:10 +0100 | [diff] [blame] | 100 | #define MBEDTLS_SSL_CONF_ALLOW_LEGACY_RENEGOTIATION \ |
| 101 | MBEDTLS_SSL_SECURE_RENEGOTIATION |
Hanno Becker | acd4fc0 | 2019-06-12 16:40:50 +0100 | [diff] [blame] | 102 | #define MBEDTLS_SSL_CONF_AUTHMODE MBEDTLS_SSL_VERIFY_REQUIRED |
Hanno Becker | de67154 | 2019-06-12 16:30:46 +0100 | [diff] [blame] | 103 | #define MBEDTLS_SSL_CONF_BADMAC_LIMIT 0 |
Hanno Becker | 7f376f4 | 2019-06-12 16:20:48 +0100 | [diff] [blame] | 104 | #define MBEDTLS_SSL_CONF_ANTI_REPLAY MBEDTLS_SSL_ANTI_REPLAY_ENABLED |
Hanno Becker | 0ae6b24 | 2019-06-13 16:45:36 +0100 | [diff] [blame] | 105 | #define MBEDTLS_SSL_CONF_GET_TIMER mbedtls_timing_get_delay |
| 106 | #define MBEDTLS_SSL_CONF_SET_TIMER mbedtls_timing_set_delay |
Hanno Becker | a58a896 | 2019-06-13 16:11:15 +0100 | [diff] [blame] | 107 | #define MBEDTLS_SSL_CONF_RECV mbedtls_net_recv |
| 108 | #define MBEDTLS_SSL_CONF_SEND mbedtls_net_send |
| 109 | #define MBEDTLS_SSL_CONF_RECV_TIMEOUT mbedtls_net_recv_timeout |
Hanno Becker | 572d448 | 2019-07-23 13:47:53 +0100 | [diff] [blame] | 110 | #define MBEDTLS_SSL_CONF_RNG rng_wrap |
Hanno Becker | e965bd3 | 2019-06-12 14:04:34 +0100 | [diff] [blame] | 111 | #define MBEDTLS_SSL_CONF_MIN_MINOR_VER MBEDTLS_SSL_MINOR_VERSION_3 |
| 112 | #define MBEDTLS_SSL_CONF_MAX_MINOR_VER MBEDTLS_SSL_MINOR_VERSION_3 |
| 113 | #define MBEDTLS_SSL_CONF_MIN_MAJOR_VER MBEDTLS_SSL_MAJOR_VERSION_3 |
| 114 | #define MBEDTLS_SSL_CONF_MAX_MAJOR_VER MBEDTLS_SSL_MAJOR_VERSION_3 |
Hanno Becker | aabbb58 | 2019-06-11 13:43:27 +0100 | [diff] [blame] | 115 | #define MBEDTLS_SSL_CONF_EXTENDED_MASTER_SECRET \ |
| 116 | MBEDTLS_SSL_EXTENDED_MS_ENABLED |
| 117 | #define MBEDTLS_SSL_CONF_ENFORCE_EXTENDED_MASTER_SECRET \ |
| 118 | MBEDTLS_SSL_EXTENDED_MS_ENFORCE_ENABLED |
| 119 | |
Andrzej Kurek | f384495 | 2020-10-16 23:03:01 +0200 | [diff] [blame] | 120 | #define MBEDTLS_SSL_VARIABLE_BUFFER_LENGTH |
| 121 | #define MBEDTLS_SSL_MAX_FRAGMENT_LENGTH |
| 122 | |
Hanno Becker | c6c0fe6 | 2019-07-23 15:29:21 +0100 | [diff] [blame] | 123 | #define MBEDTLS_USE_TINYCRYPT |
Andrzej Kurek | db0e50e | 2020-10-14 12:24:20 +0200 | [diff] [blame] | 124 | #define MBEDTLS_HAVE_ASM |
Andrzej Kurek | b042081 | 2020-10-14 19:42:23 +0200 | [diff] [blame] | 125 | #if !( defined(__STRICT_ANSI__) && defined(__CC_ARM) ) |
| 126 | #define MBEDTLS_OPTIMIZE_TINYCRYPT_ASM |
| 127 | #endif |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 128 | /* X.509 CRT parsing */ |
| 129 | #define MBEDTLS_X509_USE_C |
| 130 | #define MBEDTLS_X509_CRT_PARSE_C |
| 131 | #define MBEDTLS_X509_CHECK_KEY_USAGE |
| 132 | #define MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE |
Hanno Becker | 02a2193 | 2019-06-10 15:08:43 +0100 | [diff] [blame] | 133 | #define MBEDTLS_X509_REMOVE_INFO |
Hanno Becker | 843b71a | 2019-06-25 09:39:21 +0100 | [diff] [blame] | 134 | #define MBEDTLS_X509_CRT_REMOVE_TIME |
Hanno Becker | d07614c | 2019-06-25 10:19:58 +0100 | [diff] [blame] | 135 | #define MBEDTLS_X509_CRT_REMOVE_SUBJECT_ISSUER_ID |
Hanno Becker | 938a805 | 2019-06-05 18:07:00 +0100 | [diff] [blame] | 136 | #define MBEDTLS_X509_ON_DEMAND_PARSING |
| 137 | #define MBEDTLS_X509_ALWAYS_FLUSH |
Hanno Becker | 9ec3fe0 | 2019-07-01 17:36:12 +0100 | [diff] [blame] | 138 | #define MBEDTLS_X509_REMOVE_VERIFY_CALLBACK |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 139 | #define MBEDTLS_ASN1_PARSE_C |
Teppo Järvelin | 4009d8f | 2019-08-19 14:48:09 +0300 | [diff] [blame] | 140 | #define MBEDTLS_X509_REMOVE_HOSTNAME_VERIFICATION |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 141 | |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 142 | /* RNG and PRNG */ |
| 143 | #define MBEDTLS_NO_PLATFORM_ENTROPY |
| 144 | #define MBEDTLS_ENTROPY_C |
| 145 | #define MBEDTLS_HMAC_DRBG_C |
| 146 | |
| 147 | #define MBEDTLS_OID_C |
| 148 | #define MBEDTLS_PLATFORM_C |
Andrzej Kurek | a793237 | 2020-09-19 07:56:06 +0200 | [diff] [blame] | 149 | #define MBEDTLS_VALIDATE_SSL_KEYS_INTEGRITY |
Andrzej Kurek | fba5921 | 2020-08-07 21:02:25 -0400 | [diff] [blame] | 150 | #define MBEDTLS_VALIDATE_AES_KEYS_INTEGRITY |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 151 | |
| 152 | /* I/O buffer configuration */ |
| 153 | #define MBEDTLS_SSL_MAX_CONTENT_LEN 2048 |
| 154 | |
| 155 | /* Server-side only */ |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 156 | #define MBEDTLS_SSL_SRV_C |
| 157 | |
Hanno Becker | d016e44 | 2019-09-05 13:35:57 +0100 | [diff] [blame] | 158 | #define MBEDTLS_DEPRECATED_REMOVED |
| 159 | |
Shelly Liberman | c6a7e6b | 2020-08-05 15:26:10 +0300 | [diff] [blame] | 160 | /* Fault Injection Countermeasures */ |
shelib01 | 4062d6c | 2020-07-21 11:54:52 +0300 | [diff] [blame] | 161 | #define MBEDTLS_FI_COUNTERMEASURES |
Andrzej Kurek | 7d0a686 | 2020-11-26 06:34:04 -0500 | [diff] [blame] | 162 | #define MBEDTLS_CCM_SHUFFLING_MASKING |
Andrzej Kurek | 9627202 | 2020-12-12 07:33:20 -0500 | [diff] [blame] | 163 | |
Andrzej Kurek | 1315124 | 2020-12-07 09:29:48 -0500 | [diff] [blame] | 164 | /* Further optimizations */ |
Andrzej Kurek | 9627202 | 2020-12-12 07:33:20 -0500 | [diff] [blame] | 165 | #define MBEDTLS_SSL_KEEP_PEER_CERTIFICATE |
Andrzej Kurek | ad3c4ff | 2020-12-21 08:11:36 -0500 | [diff] [blame] | 166 | #define MBEDTLS_SSL_DELAYED_SERVER_CERT_VERIFICATION |
Andrzej Kurek | 1315124 | 2020-12-07 09:29:48 -0500 | [diff] [blame] | 167 | #define MBEDTLS_SSL_FREE_SERVER_CERTIFICATE |
Andrzej Kurek | 4f5549f | 2020-12-21 07:56:57 -0500 | [diff] [blame] | 168 | #define MBEDTLS_SSL_IMMEDIATE_TRANSMISSION |
Andrzej Kurek | 6b5c9a3 | 2020-12-21 08:02:59 -0500 | [diff] [blame] | 169 | #define MBEDTLS_SSL_EARLY_KEY_COMPUTATION |
shelib01 | 4062d6c | 2020-07-21 11:54:52 +0300 | [diff] [blame] | 170 | |
Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 171 | #if defined(MBEDTLS_USER_CONFIG_FILE) |
| 172 | #include MBEDTLS_USER_CONFIG_FILE |
| 173 | #endif |
| 174 | |
| 175 | #include <mbedtls/check_config.h> |
| 176 | |
| 177 | #endif /* MBEDTLS_BAREMETAL_CONFIG_H */ |