Skip to content
File

Blob: firmware/vendor/str0m-rust-crypto/provider.patch

5.2 KB
1--- a/Cargo.toml
2+++ b/Cargo.toml
3@@ -30,6 +30,10 @@
4 name = "str0m_rust_crypto"
5 path = "src/lib.rs"
6
7+[features]
8+default = ["generate-cert"]
9+generate-cert = ["dimpl/rcgen"]
10+
11 [dependencies.aes]
12 version = "0.8"
13
14@@ -43,7 +47,6 @@
15 version = "0.7.1"
16 features = [
17 "rust-crypto",
18- "rcgen",
19 ]
20 default-features = false
21
22--- a/src/lib.rs
23+++ b/src/lib.rs
24@@ -2,6 +2,8 @@
25 //! DTLS via dimpl with RustCrypto as crypto backend.
26
27 mod dtls;
28+
29+pub use dtls::with_crypto_provider as dtls_with_crypto_provider;
30 mod sha1;
31 mod sha256;
32 mod srtp;
33--- a/src/dtls.rs
34+++ b/src/dtls.rs
35@@ -17,13 +17,20 @@
36
37 impl DtlsProvider for RustCryptoDtlsProvider {
38 fn generate_certificate(&self) -> Option<DtlsCert> {
39- // Use dimpl's rcgen-based certificate generation (with RustCrypto backend)
40- dimpl::certificate::generate_self_signed_certificate()
41- .ok()
42- .map(|cert| DtlsCert {
43- certificate: cert.certificate,
44- private_key: cert.private_key,
45- })
46+ #[cfg(feature = "generate-cert")]
47+ {
48+ dimpl::certificate::generate_self_signed_certificate()
49+ .ok()
50+ .map(|cert| DtlsCert {
51+ certificate: cert.certificate,
52+ private_key: cert.private_key,
53+ })
54+ }
55+ #[cfg(not(feature = "generate-cert"))]
56+ {
57+ // The application supplies its certificate through RtcConfig.
58+ None
59+ }
60 }
61
62 fn new_dtls(
63@@ -33,40 +40,66 @@
64 dtls_version: DtlsVersion,
65 mtu: Option<usize>,
66 ) -> Result<Box<dyn DtlsInstance>, CryptoError> {
67- let dimpl_cert = dimpl::DtlsCertificate {
68- certificate: cert.certificate.clone(),
69- private_key: cert.private_key.clone(),
70- };
71+ let crypto = dimpl::crypto::rust_crypto::default_provider();
72+ create_instance(cert, now, dtls_version, mtu, crypto, self.is_test())
73+ }
74+}
75
76- // Create a default dimpl Config with RustCrypto crypto provider
77- // ICE verifies return routability before DTLS, making server cookies redundant.
78- let mut builder = dimpl::Config::builder().use_server_cookie(false);
79- if let Some(mtu) = mtu {
80- builder = builder.mtu(mtu);
81+/// Construct DTLS with an application-selected dimpl crypto provider.
82+/// Normal authentication, provider validation and OS randomness remain enabled.
83+pub fn with_crypto_provider(
84+ cert: &DtlsCert,
85+ now: Instant,
86+ dtls_version: DtlsVersion,
87+ mtu: Option<usize>,
88+ crypto: dimpl::crypto::CryptoProvider,
89+) -> Result<Box<dyn DtlsInstance>, CryptoError> {
90+ create_instance(cert, now, dtls_version, mtu, crypto, false)
91+}
92+
93+fn create_instance(
94+ cert: &DtlsCert,
95+ now: Instant,
96+ dtls_version: DtlsVersion,
97+ mtu: Option<usize>,
98+ crypto: dimpl::crypto::CryptoProvider,
99+ is_test: bool,
100+) -> Result<Box<dyn DtlsInstance>, CryptoError> {
101+ let dimpl_cert = dimpl::DtlsCertificate {
102+ certificate: cert.certificate.clone(),
103+ private_key: cert.private_key.clone(),
104+ };
105+
106+ // Create a dimpl Config with the explicitly selected crypto provider.
107+ // ICE verifies return routability before DTLS, making server cookies redundant.
108+ let mut builder = dimpl::Config::builder()
109+ .with_crypto_provider(crypto)
110+ .use_server_cookie(false);
111+ if let Some(mtu) = mtu {
112+ builder = builder.mtu(mtu);
113+ }
114+ if is_test {
115+ // We need the DTLS impl to be deterministic for the BWE tests.
116+ builder = builder.dangerously_set_rng_seed(42);
117+ }
118+
119+ let config = builder
120+ .build()
121+ .map_err(|e| CryptoError::Other(format!("dimpl config creation failed: {}", e)))?;
122+
123+ let config = Arc::new(config);
124+ let dtls = match dtls_version {
125+ DtlsVersion::Dtls12 => dimpl::Dtls::new_12(config, dimpl_cert, now),
126+ DtlsVersion::Dtls13 => dimpl::Dtls::new_13(config, dimpl_cert, now),
127+ DtlsVersion::Auto => dimpl::Dtls::new_auto(config, dimpl_cert, now),
128+ _ => {
129+ return Err(CryptoError::Other(format!(
130+ "Unsupported DTLS version: {dtls_version}"
131+ )));
132 }
133- if self.is_test() {
134- // We need the DTLS impl to be deterministic for the BWE tests.
135- builder = builder.dangerously_set_rng_seed(42);
136- }
137+ };
138
139- let config = builder
140- .build()
141- .map_err(|e| CryptoError::Other(format!("dimpl config creation failed: {}", e)))?;
142-
143- let config = Arc::new(config);
144- let dtls = match dtls_version {
145- DtlsVersion::Dtls12 => dimpl::Dtls::new_12(config, dimpl_cert, now),
146- DtlsVersion::Dtls13 => dimpl::Dtls::new_13(config, dimpl_cert, now),
147- DtlsVersion::Auto => dimpl::Dtls::new_auto(config, dimpl_cert, now),
148- _ => {
149- return Err(CryptoError::Other(format!(
150- "Unsupported DTLS version: {dtls_version}"
151- )));
152- }
153- };
154-
155- Ok(Box::new(RustCryptoDtlsInstance { dtls }))
156- }
157+ Ok(Box::new(RustCryptoDtlsInstance { dtls }))
158 }
159
160 // ============================================================================