3 ms·
I implemented TLS without any external deps by supporting only mandatory stuff from the RFC specifications. DER parsing here: https://github.com/mateuszb/tls1.
by mrcode007 3y ago
I implemented TLS without any external deps by supporting only mandatory stuff from the RFC specifications.
DER parsing here: https://github.com/mateuszb/tls1.3/blob/master/der.lisp https://github.com/mateuszb/tls1.3/blob/master/der.lisp
Elliptic curves here: https://github.com/mateuszb/tls1.3/blob/master/elliptic-curves.lisp https://github.com/mateuszb/tls1.3/blob/master/elliptic-curv...
Protocol records: https://github.com/mateuszb/tls1.3/blob/master/record.lisp https://github.com/mateuszb/tls1.3/blob/master/record.lisp
At the time I implemented TLS1.3 there was very little support for it and it seemed like a fun project. The parsing wasn’t the difficult part
- wahern 3y agoder.lisp is only loading a PKCS1/DER-encoded private RSA key, which is a far cry from certificate parsing. (And certificate.lisp just loads a blob.) Granted, for a server which doesn't support mTLS you don't need to parse certificates, or any other complex DER-encoded structures.
- Timon3 3y agoI don't know much Lisp, but your code is wonderfully readable! Great job!
- mrcode007 3y agoThanks. It was a really fun project. There were a lot of things to keep track of so readability of the code was a big help to not lose the big picture.
- yjftsjthsd-h 3y agoDoes supporting only the mandatory stuff give you acceptable compatibility in the real world, or do too many people rely on things that were supposed to be optional?
- mrcode007 3y agoIt works most of the time unless the "endpoint" employs an engineer who is prone to customizing things too much :) In TLS 1.3 "mandatory" really means it.