blob: d26349d0f13b98052ae9e19cfa9fb5792bdd1a3d [file] [log] [blame] [view]
Gilles Peskineceb7b122018-01-18 23:27:47 +01001Mbed TLS sample programs
2========================
3
4This subdirectory mostly contains sample programs that illustrate specific features of the library, as well as a few test and support programs.
5
6## Symmetric cryptography (AES) examples
7
Gilles Peskinec2e5cdd2018-07-30 20:11:05 +02008* [`aes/aescrypt2.c`](aes/aescrypt2.c): file encryption and authentication with a key derived from a low-entropy secret, demonstrating the low-level AES interface, the digest interface and HMAC.
9 Warning: this program illustrates how to use low-level functions in the library. It should not be taken as an example of how to build a secure encryption mechanism. To derive a key from a low-entropy secret such as a password, use a standard key stretching mechanism such as PBKDF2 (provided by the `pkcs5` module). To encrypt and authenticate data, use a standard mode such as GCM or CCM (both available as library module).
Gilles Peskineceb7b122018-01-18 23:27:47 +010010
11* [`aes/crypt_and_hash.c`](aes/crypt_and_hash.c): file encryption and authentication, demonstrating the generic cipher interface and the generic hash interface.
12
13## Hash (digest) examples
14
15* [`hash/generic_sum.c`](hash/generic_sum.c): file hash calculator and verifier, demonstrating the message digest (`md`) interface.
16
17* [`hash/hello.c`](hash/hello.c): hello-world program for MD5.
18
19## Public-key cryptography examples
20
21### Generic public-key cryptography (`pk`) examples
22
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020023* [`pkey/gen_key.c`](pkey/gen_key.c): generates a key for any of the supported public-key algorithms (RSA or ECC) and writes it to a file that can be used by the other pk sample programs.
Gilles Peskineceb7b122018-01-18 23:27:47 +010024
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020025* [`pkey/key_app.c`](pkey/key_app.c): loads a PEM or DER public key or private key file and dumps its content.
Gilles Peskineceb7b122018-01-18 23:27:47 +010026
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020027* [`pkey/key_app_writer.c`](pkey/key_app_writer.c): loads a PEM or DER public key or private key file and writes it to a new PEM or DER file.
Gilles Peskineceb7b122018-01-18 23:27:47 +010028
Gilles Peskine27a04602018-08-06 20:09:16 +020029* [`pkey/pk_encrypt.c`](pkey/pk_encrypt.c), [`pkey/pk_decrypt.c`](pkey/pk_decrypt.c): loads a PEM or DER public/private key file and uses the key to encrypt/decrypt a short string through the generic public-key interface.
Gilles Peskineceb7b122018-01-18 23:27:47 +010030
Gilles Peskine27a04602018-08-06 20:09:16 +020031* [`pkey/pk_sign.c`](pkey/pk_sign.c), [`pkey/pk_verify.c`](pkey/pk_verify.c): loads a PEM or DER private/public key file and uses the key to sign/verify a short string.
Gilles Peskineceb7b122018-01-18 23:27:47 +010032
33### ECDSA and RSA signature examples
34
Gilles Peskine0b544192018-08-10 11:32:11 +020035* [`pkey/ecdsa.c`](pkey/ecdsa.c): generates an ECDSA key, signs a fixed message and verifies the signature.
Gilles Peskineceb7b122018-01-18 23:27:47 +010036
Gilles Peskine27a04602018-08-06 20:09:16 +020037* [`pkey/rsa_encrypt.c`](pkey/rsa_encrypt.c), [`pkey/rsa_decrypt.c`](pkey/rsa_decrypt.c): loads an RSA public/private key and uses it to encrypt/decrypt a short string through the low-level RSA interface.
Gilles Peskineceb7b122018-01-18 23:27:47 +010038
Gilles Peskine27a04602018-08-06 20:09:16 +020039* [`pkey/rsa_genkey.c`](pkey/rsa_genkey.c): generates an RSA key and writes it to a file that can be used with the other RSA sample programs.
Gilles Peskineceb7b122018-01-18 23:27:47 +010040
Gilles Peskine27a04602018-08-06 20:09:16 +020041* [`pkey/rsa_sign.c`](pkey/rsa_sign.c), [`pkey/rsa_verify.c`](pkey/rsa_verify.c): loads an RSA private/public key and uses it to sign/verify a short string with the RSA PKCS#1 v1.5 algorithm.
Gilles Peskineceb7b122018-01-18 23:27:47 +010042
Gilles Peskine0b544192018-08-10 11:32:11 +020043* [`pkey/rsa_sign_pss.c`](pkey/rsa_sign_pss.c), [`pkey/rsa_verify_pss.c`](pkey/rsa_verify_pss.c): loads an RSA private/public key and uses it to sign/verify a short string with the RSASSA-PSS algorithm.
Gilles Peskineceb7b122018-01-18 23:27:47 +010044
45### Diffie-Hellman key exchange examples
46
Gilles Peskine27a04602018-08-06 20:09:16 +020047* [`pkey/dh_client.c`](pkey/dh_client.c), [`pkey/dh_server.c`](pkey/dh_server.c): secure channel demonstrators (client, server). This pair of programs illustrates how to set up a secure channel using RSA for authentication and Diffie-Hellman to generate a shared AES session key.
Gilles Peskineceb7b122018-01-18 23:27:47 +010048
49* [`pkey/ecdh_curve25519.c`](pkey/ecdh_curve25519.c): demonstration of a elliptic curve Diffie-Hellman (ECDH) key agreement.
50
51### Bignum (`mpi`) usage examples
52
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020053* [`pkey/dh_genprime.c`](pkey/dh_genprime.c): shows how to use the bignum (`mpi`) interface to generate Diffie-Hellman parameters.
Gilles Peskineceb7b122018-01-18 23:27:47 +010054
55* [`pkey/mpi_demo.c`](pkey/mpi_demo.c): demonstrates operations on big integers.
56
57## Random number generator (RNG) examples
58
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020059* [`random/gen_entropy.c`](random/gen_entropy.c): shows how to use the default entropy sources to generate random data.
60 Note: most applications should only use the entropy generator to seed a cryptographic pseudorandom generator, as illustrated by `random/gen_random_ctr_drbg.c`.
Gilles Peskineceb7b122018-01-18 23:27:47 +010061
Gilles Peskineaa220302018-08-06 20:19:50 +020062* [`random/gen_random_ctr_drbg.c`](random/gen_random_ctr_drbg.c): shows how to use the default entropy sources to seed a pseudorandom generator, and how to use the resulting random generator to generate random data.
Gilles Peskineceb7b122018-01-18 23:27:47 +010063
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020064* [`random/gen_random_havege.c`](random/gen_random_havege.c): demonstrates the HAVEGE entropy collector.
Gilles Peskineceb7b122018-01-18 23:27:47 +010065
66## SSL/TLS examples
67
68### SSL/TLS sample applications
69
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020070* [`ssl/dtls_client.c`](ssl/dtls_client.c): a simple DTLS client program, which sends one datagram to the server and reads one datagram in response.
Gilles Peskineceb7b122018-01-18 23:27:47 +010071
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020072* [`ssl/dtls_server.c`](ssl/dtls_server.c): a simple DTLS server program, which expects one datagram from the client and writes one datagram in response. This program supports DTLS cookies for hello verification.
Gilles Peskineceb7b122018-01-18 23:27:47 +010073
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020074* [`ssl/mini_client.c`](ssl/mini_client.c): a minimalistic SSL client, which sends a short string and disconnects. This is primarily intended as a benchmark; for a better example of a typical TLS client, see `ssl/ssl_client1.c`.
Gilles Peskineceb7b122018-01-18 23:27:47 +010075
76* [`ssl/ssl_client1.c`](ssl/ssl_client1.c): a simple HTTPS client that sends a fixed request and displays the response.
77
78* [`ssl/ssl_fork_server.c`](ssl/ssl_fork_server.c): a simple HTTPS server using one process per client to send a fixed response. This program requires a Unix/POSIX environment implementing the `fork` system call.
79
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020080* [`ssl/ssl_mail_client.c`](ssl/ssl_mail_client.c): a simple SMTP-over-TLS or SMTP-STARTTLS client. This client sends an email with fixed content.
Gilles Peskineceb7b122018-01-18 23:27:47 +010081
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020082* [`ssl/ssl_pthread_server.c`](ssl/ssl_pthread_server.c): a simple HTTPS server using one thread per client to send a fixed response. This program requires the pthread library.
Gilles Peskineceb7b122018-01-18 23:27:47 +010083
Gilles Peskineaa220302018-08-06 20:19:50 +020084* [`ssl/ssl_server.c`](ssl/ssl_server.c): a simple HTTPS server that sends a fixed response. It serves a single client at a time.
Gilles Peskineceb7b122018-01-18 23:27:47 +010085
86### SSL/TLS feature demonstrators
87
Gilles Peskine6b9cbb82018-07-30 20:06:19 +020088Note: unlike most of the other programs under the `programs/` directory, these two programs are not intended as a basis for writing an application. They combine most of the features supported by the library, and most applications require only a few features. To write a new application, we recommended that you start with `ssl_client1.c` or `ssl_server.c`, and then look inside `ssl/ssl_client2.c` or `ssl/ssl_server2.c` to see how to use the specific features that your application needs.
Gilles Peskineceb7b122018-01-18 23:27:47 +010089
90* [`ssl/ssl_client2.c`](ssl/ssl_client2.c): an HTTPS client that sends a fixed request and displays the response, with options to select TLS protocol features and Mbed TLS library features.
91
92* [`ssl/ssl_server2.c`](ssl/ssl_server2.c): an HTTPS server that sends a fixed response, with options to select TLS protocol features and Mbed TLS library features.
93
Gilles Peskineaa220302018-08-06 20:19:50 +020094In addition to providing options for testing client-side features, the `ssl_client2` program has options that allow you to trigger certain behaviors in the server. For example, there are options to select ciphersuites, or to force a renegotiation. These options are useful for testing the corresponding features in a TLS server. Likewise, `ssl_server2` has options to activate certain behaviors that are useful for testing a TLS client.
Gilles Peskineceb7b122018-01-18 23:27:47 +010095
96## Test utilities
97
98* [`test/benchmark.c`](test/benchmark.c): benchmark for cryptographic algorithms.
99
Gilles Peskine6b9cbb82018-07-30 20:06:19 +0200100* [`test/selftest.c`](test/selftest.c): runs the self-test function in each library module.
Gilles Peskineceb7b122018-01-18 23:27:47 +0100101
Gilles Peskine6b9cbb82018-07-30 20:06:19 +0200102* [`test/udp_proxy.c`](test/udp_proxy.c): a UDP proxy that can inject certain failures (delay, duplicate, drop). Useful for testing DTLS.
Gilles Peskineceb7b122018-01-18 23:27:47 +0100103
Gilles Peskineffbdc612018-08-10 11:48:52 +0200104* [`test/zeroize.c`](test/zeroize.c): a test program for `mbedtls_platform_zeroize`, used by [`tests/scripts/test_zeroize.gdb`](tests/scripts/test_zeroize.gdb).
105
Gilles Peskineceb7b122018-01-18 23:27:47 +0100106## Development utilities
107
Gilles Peskine6b9cbb82018-07-30 20:06:19 +0200108* [`util/pem2der.c`](util/pem2der.c): a PEM to DER converter. Mbed TLS can read PEM files directly, but this utility can be useful for interacting with other tools or with minimal Mbed TLS builds that lack PEM support.
Gilles Peskineceb7b122018-01-18 23:27:47 +0100109
Gilles Peskine6b9cbb82018-07-30 20:06:19 +0200110* [`util/strerror.c`](util/strerror.c): prints the error description corresponding to an integer status returned by an Mbed TLS function.
Gilles Peskineceb7b122018-01-18 23:27:47 +0100111
112## X.509 certificate examples
113
Gilles Peskine6b9cbb82018-07-30 20:06:19 +0200114* [`x509/cert_app.c`](x509/cert_app.c): connects to a TLS server and verifies its certificate chain.
Gilles Peskineceb7b122018-01-18 23:27:47 +0100115
Gilles Peskine6b9cbb82018-07-30 20:06:19 +0200116* [`x509/cert_req.c`](x509/cert_req.c): generates a certificate signing request (CSR) for a private key.
Gilles Peskineceb7b122018-01-18 23:27:47 +0100117
Gilles Peskine27a04602018-08-06 20:09:16 +0200118* [`x509/cert_write.c`](x509/cert_write.c): signs a certificate signing request, or self-signs a certificate.
Gilles Peskineceb7b122018-01-18 23:27:47 +0100119
Gilles Peskine6b9cbb82018-07-30 20:06:19 +0200120* [`x509/crl_app.c`](x509/crl_app.c): loads and dumps a certificate revocation list (CRL).
Gilles Peskineceb7b122018-01-18 23:27:47 +0100121
Gilles Peskine6b9cbb82018-07-30 20:06:19 +0200122* [`x509/req_app.c`](x509/req_app.c): loads and dumps a certificate signing request (CSR).
Gilles Peskineceb7b122018-01-18 23:27:47 +0100123