| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 1 | /** |
| 2 | * \file baremetal.h |
| 3 | * |
| 4 | * \brief Test configuration for minimal baremetal Mbed TLS builds |
| 5 | * based on the following primitives: |
| 6 | * - ECDHE-ECDSA only |
| 7 | * - Elliptic curve SECP256R1 only |
| 8 | * - SHA-256 only |
| 9 | * - AES-CCM-8 only |
| 10 | * |
| 11 | * The library compiles in this configuration, but the example |
| 12 | * programs `ssl_client2` and `ssl_server2` require the |
| 13 | * modifications from `baremetal_test.h`. |
| 14 | */ |
| 15 | /* |
| 16 | * Copyright (C) 2006-2018, ARM Limited, All Rights Reserved |
| 17 | * SPDX-License-Identifier: Apache-2.0 |
| 18 | * |
| 19 | * Licensed under the Apache License, Version 2.0 (the "License"); you may |
| 20 | * not use this file except in compliance with the License. |
| 21 | * You may obtain a copy of the License at |
| 22 | * |
| 23 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 24 | * |
| 25 | * Unless required by applicable law or agreed to in writing, software |
| 26 | * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT |
| 27 | * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 28 | * See the License for the specific language governing permissions and |
| 29 | * limitations under the License. |
| 30 | * |
| 31 | * This file is part of mbed TLS (https://tls.mbed.org) |
| 32 | */ |
| 33 | |
| 34 | #ifndef MBEDTLS_BAREMETAL_CONFIG_H |
| 35 | #define MBEDTLS_BAREMETAL_CONFIG_H |
| 36 | |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 37 | /* Symmetric crypto: AES-CCM only */ |
| 38 | #define MBEDTLS_CIPHER_C |
| 39 | #define MBEDTLS_AES_C |
| 40 | #define MBEDTLS_AES_ROM_TABLES |
| 41 | #define MBEDTLS_AES_FEWER_TABLES |
| Arto Kinnunen | 77b9cfc | 2019-08-30 11:43:21 +0300 | [diff] [blame] | 42 | #define MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH |
| Arto Kinnunen | 1480444 | 2019-10-16 13:43:59 +0300 | [diff] [blame^] | 43 | #define MBEDTLS_AES_ONLY_ENCRYPT |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 44 | #define MBEDTLS_CCM_C |
| 45 | |
| 46 | /* Asymmetric crypto: Single-curve ECC only. */ |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 47 | #define MBEDTLS_PK_C |
| 48 | #define MBEDTLS_PK_PARSE_C |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 49 | |
| Hanno Becker | c1096e7 | 2019-06-19 12:30:41 +0100 | [diff] [blame] | 50 | #define MBEDTLS_SSL_CONF_SINGLE_EC |
| Hanno Becker | a007e0d | 2019-09-02 16:24:00 +0100 | [diff] [blame] | 51 | #define MBEDTLS_SSL_CONF_SINGLE_UECC_GRP_ID MBEDTLS_UECC_DP_SECP256R1 |
| Hanno Becker | c1096e7 | 2019-06-19 12:30:41 +0100 | [diff] [blame] | 52 | #define MBEDTLS_SSL_CONF_SINGLE_EC_TLS_ID 23 |
| Hanno Becker | 56595f4 | 2019-06-19 16:31:38 +0100 | [diff] [blame] | 53 | #define MBEDTLS_SSL_CONF_SINGLE_SIG_HASH |
| 54 | #define MBEDTLS_SSL_CONF_SINGLE_SIG_HASH_MD_ID MBEDTLS_MD_SHA256 |
| 55 | #define MBEDTLS_SSL_CONF_SINGLE_SIG_HASH_TLS_ID MBEDTLS_SSL_HASH_SHA256 |
| Hanno Becker | c1096e7 | 2019-06-19 12:30:41 +0100 | [diff] [blame] | 56 | |
| Manuel Pégourié-Gonnard | 1c1cc0d | 2019-09-19 10:45:14 +0200 | [diff] [blame] | 57 | /* Harcoded options in abstraction layers */ |
| Hanno Becker | d806d9d | 2019-08-13 16:09:10 +0100 | [diff] [blame] | 58 | #define MBEDTLS_MD_SINGLE_HASH MBEDTLS_MD_INFO_SHA256 |
| Manuel Pégourié-Gonnard | 1c1cc0d | 2019-09-19 10:45:14 +0200 | [diff] [blame] | 59 | #define MBEDTLS_PK_SINGLE_TYPE MBEDTLS_PK_INFO_ECKEY |
| Hanno Becker | d806d9d | 2019-08-13 16:09:10 +0100 | [diff] [blame] | 60 | |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 61 | /* Key exchanges */ |
| 62 | #define MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED |
| Hanno Becker | 224eb0c | 2019-04-10 12:24:10 +0100 | [diff] [blame] | 63 | #define MBEDTLS_SSL_CIPHERSUITES MBEDTLS_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 |
| Hanno Becker | 73f4cb1 | 2019-06-27 13:51:07 +0100 | [diff] [blame] | 64 | #define MBEDTLS_SSL_CONF_SINGLE_CIPHERSUITE MBEDTLS_SUITE_TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 65 | |
| 66 | /* Digests - just SHA-256 */ |
| 67 | #define MBEDTLS_MD_C |
| 68 | #define MBEDTLS_SHA256_C |
| 69 | #define MBEDTLS_SHA256_SMALLER |
| Manuel Pégourié-Gonnard | e06cc31 | 2019-07-16 16:15:28 +0200 | [diff] [blame] | 70 | #define MBEDTLS_SHA256_NO_SHA224 |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 71 | |
| 72 | /* TLS options */ |
| 73 | #define MBEDTLS_SSL_CLI_C |
| 74 | #define MBEDTLS_SSL_TLS_C |
| 75 | #define MBEDTLS_SSL_PROTO_TLS1_2 |
| 76 | #define MBEDTLS_SSL_EXTENDED_MASTER_SECRET |
| Jarno Lamsa | 29f2dd0 | 2019-06-20 15:31:52 +0300 | [diff] [blame] | 77 | #define MBEDTLS_SSL_NO_SESSION_CACHE |
| 78 | #define MBEDTLS_SSL_NO_SESSION_RESUMPTION |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 79 | #define MBEDTLS_SSL_COOKIE_C |
| Hanno Becker | 275e5bf | 2019-04-03 13:39:31 +0100 | [diff] [blame] | 80 | #define MBEDTLS_SSL_PROTO_DTLS |
| Manuel Pégourié-Gonnard | 19e8132 | 2019-06-18 10:54:25 +0200 | [diff] [blame] | 81 | #define MBEDTLS_SSL_PROTO_NO_TLS |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 82 | #define MBEDTLS_SSL_DTLS_ANTI_REPLAY |
| 83 | #define MBEDTLS_SSL_DTLS_HELLO_VERIFY |
| 84 | #define MBEDTLS_SSL_DTLS_BADMAC_LIMIT |
| Hanno Becker | a5a2b08 | 2019-05-15 14:03:01 +0100 | [diff] [blame] | 85 | #define MBEDTLS_SSL_DTLS_CONNECTION_ID |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 86 | |
| Hanno Becker | aabbb58 | 2019-06-11 13:43:27 +0100 | [diff] [blame] | 87 | /* Compile-time fixed parts of the SSL configuration */ |
| Hanno Becker | f3400da | 2019-06-13 12:36:31 +0100 | [diff] [blame] | 88 | #define MBEDTLS_SSL_CONF_CERT_REQ_CA_LIST MBEDTLS_SSL_CERT_REQ_CA_LIST_DISABLED |
| Hanno Becker | 1f835fa | 2019-06-13 10:14:59 +0100 | [diff] [blame] | 89 | #define MBEDTLS_SSL_CONF_READ_TIMEOUT 0 |
| 90 | #define MBEDTLS_SSL_CONF_HS_TIMEOUT_MIN 1000 |
| 91 | #define MBEDTLS_SSL_CONF_HS_TIMEOUT_MAX 16000 |
| Hanno Becker | 3b876ac | 2019-06-21 15:51:19 +0100 | [diff] [blame] | 92 | #define MBEDTLS_SSL_CONF_CID_LEN 2 |
| Hanno Becker | e0200da | 2019-06-13 09:23:43 +0100 | [diff] [blame] | 93 | #define MBEDTLS_SSL_CONF_IGNORE_UNEXPECTED_CID MBEDTLS_SSL_UNEXPECTED_CID_IGNORE |
| Hanno Becker | b0b2b67 | 2019-06-12 16:58:10 +0100 | [diff] [blame] | 94 | #define MBEDTLS_SSL_CONF_ALLOW_LEGACY_RENEGOTIATION \ |
| 95 | MBEDTLS_SSL_SECURE_RENEGOTIATION |
| Hanno Becker | acd4fc0 | 2019-06-12 16:40:50 +0100 | [diff] [blame] | 96 | #define MBEDTLS_SSL_CONF_AUTHMODE MBEDTLS_SSL_VERIFY_REQUIRED |
| Hanno Becker | de67154 | 2019-06-12 16:30:46 +0100 | [diff] [blame] | 97 | #define MBEDTLS_SSL_CONF_BADMAC_LIMIT 0 |
| Hanno Becker | 7f376f4 | 2019-06-12 16:20:48 +0100 | [diff] [blame] | 98 | #define MBEDTLS_SSL_CONF_ANTI_REPLAY MBEDTLS_SSL_ANTI_REPLAY_ENABLED |
| Hanno Becker | 0ae6b24 | 2019-06-13 16:45:36 +0100 | [diff] [blame] | 99 | #define MBEDTLS_SSL_CONF_GET_TIMER mbedtls_timing_get_delay |
| 100 | #define MBEDTLS_SSL_CONF_SET_TIMER mbedtls_timing_set_delay |
| Hanno Becker | a58a896 | 2019-06-13 16:11:15 +0100 | [diff] [blame] | 101 | #define MBEDTLS_SSL_CONF_RECV mbedtls_net_recv |
| 102 | #define MBEDTLS_SSL_CONF_SEND mbedtls_net_send |
| 103 | #define MBEDTLS_SSL_CONF_RECV_TIMEOUT mbedtls_net_recv_timeout |
| Hanno Becker | 572d448 | 2019-07-23 13:47:53 +0100 | [diff] [blame] | 104 | #define MBEDTLS_SSL_CONF_RNG rng_wrap |
| Hanno Becker | e965bd3 | 2019-06-12 14:04:34 +0100 | [diff] [blame] | 105 | #define MBEDTLS_SSL_CONF_MIN_MINOR_VER MBEDTLS_SSL_MINOR_VERSION_3 |
| 106 | #define MBEDTLS_SSL_CONF_MAX_MINOR_VER MBEDTLS_SSL_MINOR_VERSION_3 |
| 107 | #define MBEDTLS_SSL_CONF_MIN_MAJOR_VER MBEDTLS_SSL_MAJOR_VERSION_3 |
| 108 | #define MBEDTLS_SSL_CONF_MAX_MAJOR_VER MBEDTLS_SSL_MAJOR_VERSION_3 |
| Hanno Becker | aabbb58 | 2019-06-11 13:43:27 +0100 | [diff] [blame] | 109 | #define MBEDTLS_SSL_CONF_EXTENDED_MASTER_SECRET \ |
| 110 | MBEDTLS_SSL_EXTENDED_MS_ENABLED |
| 111 | #define MBEDTLS_SSL_CONF_ENFORCE_EXTENDED_MASTER_SECRET \ |
| 112 | MBEDTLS_SSL_EXTENDED_MS_ENFORCE_ENABLED |
| 113 | |
| Hanno Becker | c6c0fe6 | 2019-07-23 15:29:21 +0100 | [diff] [blame] | 114 | #define MBEDTLS_USE_TINYCRYPT |
| 115 | |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 116 | /* X.509 CRT parsing */ |
| 117 | #define MBEDTLS_X509_USE_C |
| 118 | #define MBEDTLS_X509_CRT_PARSE_C |
| 119 | #define MBEDTLS_X509_CHECK_KEY_USAGE |
| 120 | #define MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE |
| Hanno Becker | 02a2193 | 2019-06-10 15:08:43 +0100 | [diff] [blame] | 121 | #define MBEDTLS_X509_REMOVE_INFO |
| Hanno Becker | 843b71a | 2019-06-25 09:39:21 +0100 | [diff] [blame] | 122 | #define MBEDTLS_X509_CRT_REMOVE_TIME |
| Hanno Becker | d07614c | 2019-06-25 10:19:58 +0100 | [diff] [blame] | 123 | #define MBEDTLS_X509_CRT_REMOVE_SUBJECT_ISSUER_ID |
| Hanno Becker | 938a805 | 2019-06-05 18:07:00 +0100 | [diff] [blame] | 124 | #define MBEDTLS_X509_ON_DEMAND_PARSING |
| 125 | #define MBEDTLS_X509_ALWAYS_FLUSH |
| Hanno Becker | 9ec3fe0 | 2019-07-01 17:36:12 +0100 | [diff] [blame] | 126 | #define MBEDTLS_X509_REMOVE_VERIFY_CALLBACK |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 127 | #define MBEDTLS_ASN1_PARSE_C |
| Teppo Järvelin | 4009d8f | 2019-08-19 14:48:09 +0300 | [diff] [blame] | 128 | #define MBEDTLS_X509_REMOVE_HOSTNAME_VERIFICATION |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 129 | |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 130 | /* RNG and PRNG */ |
| 131 | #define MBEDTLS_NO_PLATFORM_ENTROPY |
| 132 | #define MBEDTLS_ENTROPY_C |
| 133 | #define MBEDTLS_HMAC_DRBG_C |
| 134 | |
| 135 | #define MBEDTLS_OID_C |
| 136 | #define MBEDTLS_PLATFORM_C |
| 137 | |
| 138 | /* I/O buffer configuration */ |
| 139 | #define MBEDTLS_SSL_MAX_CONTENT_LEN 2048 |
| 140 | |
| 141 | /* Server-side only */ |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 142 | #define MBEDTLS_SSL_SRV_C |
| 143 | |
| Hanno Becker | d016e44 | 2019-09-05 13:35:57 +0100 | [diff] [blame] | 144 | #define MBEDTLS_DEPRECATED_REMOVED |
| 145 | |
| Hanno Becker | abc22b7 | 2019-03-18 12:39:49 +0000 | [diff] [blame] | 146 | #if defined(MBEDTLS_USER_CONFIG_FILE) |
| 147 | #include MBEDTLS_USER_CONFIG_FILE |
| 148 | #endif |
| 149 | |
| 150 | #include <mbedtls/check_config.h> |
| 151 | |
| 152 | #endif /* MBEDTLS_BAREMETAL_CONFIG_H */ |