|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
TLS version negotiation + pinned cipher-suite policy (PROTOCORE_ENABLE_TLS_POLICY). More...
#include "protocore_config.h"Go to the source code of this file.
TLS version negotiation + pinned cipher-suite policy (PROTOCORE_ENABLE_TLS_POLICY).
The transport TLS layer already runs the record and handshake and floors the version at TLS 1.2, so both TLS 1.2 (RFC 5246) and TLS 1.3 (RFC 8446) are negotiated. What this adds on top is a policy: pin the negotiated version to an audited [min,max] range and make the chosen version observable, and pin the cipher suites to an audited allowlist selected by server preference (AEAD-only for a hardened profile).
The pure policy core: TlsPolicyNs::negotiate picks the version the way a server does (the highest it supports not above the client's), TlsPolicyNs::name names it for a status endpoint, TlsPolicyNs::select picks a suite by server preference from the offered set, and TlsPolicyNs::is_aead classifies one. Host-testable; the app feeds the results to the TLS config. No heap, no stdlib.
Definition in file tls_policy.h.