【发布时间】:2015-11-17 01:23:01
【问题描述】:
在我研究此问题时遇到的许多示例中,都提到了长度 = 12。
但是:
根据 RFC,verify_data 长度在 older 版本中始终为 12。但是,在 TLS 1.2 中,长度可能会更长 - 取决于密码套件。
struct {
opaque verify_data[verify_data_length];
} Finished;
verify_data
PRF(master_secret, finished_label, Hash(handshake_messages))
[0..verify_data_length-1];
In previous versions of TLS, the verify_data was always 12 octets
long. In the current version of TLS, it depends on the cipher
suite. Any cipher suite which does not explicitly specify
verify_data_length has a verify_data_length equal to 12. This
includes all existing cipher suites. Note that this
representation has the same encoding as with previous versions.
Future cipher suites MAY specify other lengths but such length
MUST be at least 12 bytes.
verify_data 被定义为使用某种算法的 PRF。 AFAIK 并根据 rfc4868,使用 SHA384 时,PRF 输出长度将为 48 而不是 12。
PRF-HMAC-SHA-384 = afd03944d84895626b0825f4ab46907f
15f9dadbe4101ec682aa034c7cebc59c
faea9ea9076ede7f4af152e8b2fa9cb6
我还记录了一个使用SHA384的SSL流的PCAP,verify_data长度为12:
使用 SHA384 时,完成消息的结构和长度应该是什么?
谢谢!
【问题讨论】:
标签: ssl encryption pcap rfc