1*48d99288Stb /* $OpenBSD: ssl_err.c,v 1.53 2024/10/09 08:00:29 tb Exp $ */ 2913ec974Sbeck /* ==================================================================== 317150393Sdjm * Copyright (c) 1999-2011 The OpenSSL Project. All rights reserved. 45b37fcf3Sryker * 55b37fcf3Sryker * Redistribution and use in source and binary forms, with or without 65b37fcf3Sryker * modification, are permitted provided that the following conditions 75b37fcf3Sryker * are met: 8913ec974Sbeck * 9913ec974Sbeck * 1. Redistributions of source code must retain the above copyright 105b37fcf3Sryker * notice, this list of conditions and the following disclaimer. 11913ec974Sbeck * 125b37fcf3Sryker * 2. Redistributions in binary form must reproduce the above copyright 13913ec974Sbeck * notice, this list of conditions and the following disclaimer in 14913ec974Sbeck * the documentation and/or other materials provided with the 15913ec974Sbeck * distribution. 165b37fcf3Sryker * 17913ec974Sbeck * 3. All advertising materials mentioning features or use of this 18913ec974Sbeck * software must display the following acknowledgment: 19913ec974Sbeck * "This product includes software developed by the OpenSSL Project 20913ec974Sbeck * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)" 215b37fcf3Sryker * 22913ec974Sbeck * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to 23913ec974Sbeck * endorse or promote products derived from this software without 24913ec974Sbeck * prior written permission. For written permission, please contact 25913ec974Sbeck * openssl-core@OpenSSL.org. 26913ec974Sbeck * 27913ec974Sbeck * 5. Products derived from this software may not be called "OpenSSL" 28913ec974Sbeck * nor may "OpenSSL" appear in their names without prior written 29913ec974Sbeck * permission of the OpenSSL Project. 30913ec974Sbeck * 31913ec974Sbeck * 6. Redistributions of any form whatsoever must retain the following 32913ec974Sbeck * acknowledgment: 33913ec974Sbeck * "This product includes software developed by the OpenSSL Project 34913ec974Sbeck * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)" 35913ec974Sbeck * 36913ec974Sbeck * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY 37913ec974Sbeck * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 38913ec974Sbeck * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 39913ec974Sbeck * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR 40913ec974Sbeck * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 41913ec974Sbeck * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 42913ec974Sbeck * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 43913ec974Sbeck * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 44913ec974Sbeck * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, 45913ec974Sbeck * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 46913ec974Sbeck * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED 47913ec974Sbeck * OF THE POSSIBILITY OF SUCH DAMAGE. 48913ec974Sbeck * ==================================================================== 49913ec974Sbeck * 50913ec974Sbeck * This product includes cryptographic software written by Eric Young 51913ec974Sbeck * (eay@cryptsoft.com). This product includes software written by Tim 52913ec974Sbeck * Hudson (tjh@cryptsoft.com). 53913ec974Sbeck * 545b37fcf3Sryker */ 55913ec974Sbeck 565b37fcf3Sryker #include <stdio.h> 57c5899dbcSjsing 58913ec974Sbeck #include <openssl/err.h> 59f4dd87b5Sjsing #include <openssl/opensslconf.h> 60913ec974Sbeck #include <openssl/ssl.h> 615b37fcf3Sryker 62c9675a23Stb #include "ssl_local.h" 63440bed4fSbeck 64da347917Sbeck #ifndef OPENSSL_NO_ERR 656d388760Sdjm 666d388760Sdjm #define ERR_FUNC(func) ERR_PACK(ERR_LIB_SSL,func,0) 676d388760Sdjm #define ERR_REASON(reason) ERR_PACK(ERR_LIB_SSL,0,reason) 686d388760Sdjm 69c9d7abb7Sbeck /* See SSL_state_func_code below */ 705f4c8480Stb static const ERR_STRING_DATA SSL_str_functs[] = { 71c9d7abb7Sbeck {ERR_FUNC(1), "CONNECT_CW_FLUSH"}, 72c9d7abb7Sbeck {ERR_FUNC(2), "CONNECT_CW_CLNT_HELLO"}, 73c9d7abb7Sbeck {ERR_FUNC(3), "CONNECT_CW_CLNT_HELLO"}, 74c9d7abb7Sbeck {ERR_FUNC(4), "CONNECT_CR_SRVR_HELLO"}, 75c9d7abb7Sbeck {ERR_FUNC(5), "CONNECT_CR_SRVR_HELLO"}, 76c9d7abb7Sbeck {ERR_FUNC(6), "CONNECT_CR_CERT"}, 77c9d7abb7Sbeck {ERR_FUNC(7), "CONNECT_CR_CERT"}, 78c9d7abb7Sbeck {ERR_FUNC(8), "CONNECT_CR_KEY_EXCH"}, 79c9d7abb7Sbeck {ERR_FUNC(9), "CONNECT_CR_KEY_EXCH"}, 80c9d7abb7Sbeck {ERR_FUNC(10), "CONNECT_CR_CERT_REQ"}, 81c9d7abb7Sbeck {ERR_FUNC(11), "CONNECT_CR_CERT_REQ"}, 82c9d7abb7Sbeck {ERR_FUNC(12), "CONNECT_CR_SRVR_DONE"}, 83c9d7abb7Sbeck {ERR_FUNC(13), "CONNECT_CR_SRVR_DONE"}, 84c9d7abb7Sbeck {ERR_FUNC(14), "CONNECT_CW_CERT"}, 85c9d7abb7Sbeck {ERR_FUNC(15), "CONNECT_CW_CERT"}, 86c9d7abb7Sbeck {ERR_FUNC(16), "CONNECT_CW_CERT_C"}, 87c9d7abb7Sbeck {ERR_FUNC(17), "CONNECT_CW_CERT_D"}, 88c9d7abb7Sbeck {ERR_FUNC(18), "CONNECT_CW_KEY_EXCH"}, 89c9d7abb7Sbeck {ERR_FUNC(19), "CONNECT_CW_KEY_EXCH"}, 90c9d7abb7Sbeck {ERR_FUNC(20), "CONNECT_CW_CERT_VRFY"}, 91c9d7abb7Sbeck {ERR_FUNC(21), "CONNECT_CW_CERT_VRFY"}, 92c9d7abb7Sbeck {ERR_FUNC(22), "CONNECT_CW_CHANGE"}, 93c9d7abb7Sbeck {ERR_FUNC(23), "CONNECT_CW_CHANGE"}, 94c9d7abb7Sbeck {ERR_FUNC(26), "CONNECT_CW_FINISHED"}, 95c9d7abb7Sbeck {ERR_FUNC(27), "CONNECT_CW_FINISHED"}, 96c9d7abb7Sbeck {ERR_FUNC(28), "CONNECT_CR_CHANGE"}, 97c9d7abb7Sbeck {ERR_FUNC(29), "CONNECT_CR_CHANGE"}, 98c9d7abb7Sbeck {ERR_FUNC(30), "CONNECT_CR_FINISHED"}, 99c9d7abb7Sbeck {ERR_FUNC(31), "CONNECT_CR_FINISHED"}, 100c9d7abb7Sbeck {ERR_FUNC(32), "CONNECT_CR_SESSION_TICKET"}, 101c9d7abb7Sbeck {ERR_FUNC(33), "CONNECT_CR_SESSION_TICKET"}, 102c9d7abb7Sbeck {ERR_FUNC(34), "CONNECT_CR_CERT_STATUS"}, 103c9d7abb7Sbeck {ERR_FUNC(35), "CONNECT_CR_CERT_STATUS"}, 104c9d7abb7Sbeck {ERR_FUNC(36), "ACCEPT_SW_FLUSH"}, 105c9d7abb7Sbeck {ERR_FUNC(37), "ACCEPT_SR_CLNT_HELLO"}, 106c9d7abb7Sbeck {ERR_FUNC(38), "ACCEPT_SR_CLNT_HELLO"}, 107c9d7abb7Sbeck {ERR_FUNC(39), "ACCEPT_SR_CLNT_HELLO_C"}, 108c9d7abb7Sbeck {ERR_FUNC(40), "ACCEPT_SW_HELLO_REQ"}, 109c9d7abb7Sbeck {ERR_FUNC(41), "ACCEPT_SW_HELLO_REQ"}, 110c9d7abb7Sbeck {ERR_FUNC(42), "ACCEPT_SW_HELLO_REQ_C"}, 111c9d7abb7Sbeck {ERR_FUNC(43), "ACCEPT_SW_SRVR_HELLO"}, 112c9d7abb7Sbeck {ERR_FUNC(44), "ACCEPT_SW_SRVR_HELLO"}, 113c9d7abb7Sbeck {ERR_FUNC(45), "ACCEPT_SW_CERT"}, 114c9d7abb7Sbeck {ERR_FUNC(46), "ACCEPT_SW_CERT"}, 115c9d7abb7Sbeck {ERR_FUNC(47), "ACCEPT_SW_KEY_EXCH"}, 116c9d7abb7Sbeck {ERR_FUNC(48), "ACCEPT_SW_KEY_EXCH"}, 117c9d7abb7Sbeck {ERR_FUNC(49), "ACCEPT_SW_CERT_REQ"}, 118c9d7abb7Sbeck {ERR_FUNC(50), "ACCEPT_SW_CERT_REQ"}, 119c9d7abb7Sbeck {ERR_FUNC(51), "ACCEPT_SW_SRVR_DONE"}, 120c9d7abb7Sbeck {ERR_FUNC(52), "ACCEPT_SW_SRVR_DONE"}, 121c9d7abb7Sbeck {ERR_FUNC(53), "ACCEPT_SR_CERT"}, 122c9d7abb7Sbeck {ERR_FUNC(54), "ACCEPT_SR_CERT"}, 123c9d7abb7Sbeck {ERR_FUNC(55), "ACCEPT_SR_KEY_EXCH"}, 124c9d7abb7Sbeck {ERR_FUNC(56), "ACCEPT_SR_KEY_EXCH"}, 125c9d7abb7Sbeck {ERR_FUNC(57), "ACCEPT_SR_CERT_VRFY"}, 126c9d7abb7Sbeck {ERR_FUNC(58), "ACCEPT_SR_CERT_VRFY"}, 127c9d7abb7Sbeck {ERR_FUNC(59), "ACCEPT_SR_CHANGE"}, 128c9d7abb7Sbeck {ERR_FUNC(60), "ACCEPT_SR_CHANGE"}, 129c9d7abb7Sbeck {ERR_FUNC(63), "ACCEPT_SR_FINISHED"}, 130c9d7abb7Sbeck {ERR_FUNC(64), "ACCEPT_SR_FINISHED"}, 131c9d7abb7Sbeck {ERR_FUNC(65), "ACCEPT_SW_CHANGE"}, 132c9d7abb7Sbeck {ERR_FUNC(66), "ACCEPT_SW_CHANGE"}, 133c9d7abb7Sbeck {ERR_FUNC(67), "ACCEPT_SW_FINISHED"}, 134c9d7abb7Sbeck {ERR_FUNC(68), "ACCEPT_SW_FINISHED"}, 135c9d7abb7Sbeck {ERR_FUNC(69), "ACCEPT_SW_SESSION_TICKET"}, 136c9d7abb7Sbeck {ERR_FUNC(70), "ACCEPT_SW_SESSION_TICKET"}, 137c9d7abb7Sbeck {ERR_FUNC(71), "ACCEPT_SW_CERT_STATUS"}, 138c9d7abb7Sbeck {ERR_FUNC(72), "ACCEPT_SW_CERT_STATUS"}, 139c9d7abb7Sbeck {ERR_FUNC(73), "ST_BEFORE"}, 140c9d7abb7Sbeck {ERR_FUNC(74), "ST_ACCEPT"}, 141c9d7abb7Sbeck {ERR_FUNC(75), "ST_CONNECT"}, 142c9d7abb7Sbeck {ERR_FUNC(76), "ST_OK"}, 143c9d7abb7Sbeck {ERR_FUNC(77), "ST_RENEGOTIATE"}, 144c9d7abb7Sbeck {ERR_FUNC(78), "ST_BEFORE_CONNECT"}, 145c9d7abb7Sbeck {ERR_FUNC(79), "ST_OK_CONNECT"}, 146c9d7abb7Sbeck {ERR_FUNC(80), "ST_BEFORE_ACCEPT"}, 147c9d7abb7Sbeck {ERR_FUNC(81), "ST_OK_ACCEPT"}, 148c9d7abb7Sbeck {ERR_FUNC(83), "DTLS1_ST_CR_HELLO_VERIFY_REQUEST"}, 149c9d7abb7Sbeck {ERR_FUNC(84), "DTLS1_ST_CR_HELLO_VERIFY_REQUEST"}, 150c9d7abb7Sbeck {ERR_FUNC(85), "DTLS1_ST_SW_HELLO_VERIFY_REQUEST"}, 151c9d7abb7Sbeck {ERR_FUNC(86), "DTLS1_ST_SW_HELLO_VERIFY_REQUEST"}, 152c9d7abb7Sbeck {ERR_FUNC(0xfff), "(UNKNOWN)SSL_internal"}, 153913ec974Sbeck {0, NULL} 1545b37fcf3Sryker }; 1555b37fcf3Sryker 1565f4c8480Stb static const ERR_STRING_DATA SSL_str_reasons[] = { 1576d388760Sdjm {ERR_REASON(SSL_R_APP_DATA_IN_HANDSHAKE) , "app data in handshake"}, 1586d388760Sdjm {ERR_REASON(SSL_R_ATTEMPT_TO_REUSE_SESSION_IN_DIFFERENT_CONTEXT), "attempt to reuse session in different context"}, 1596d388760Sdjm {ERR_REASON(SSL_R_BAD_ALERT_RECORD) , "bad alert record"}, 1606d388760Sdjm {ERR_REASON(SSL_R_BAD_AUTHENTICATION_TYPE), "bad authentication type"}, 1616d388760Sdjm {ERR_REASON(SSL_R_BAD_CHANGE_CIPHER_SPEC), "bad change cipher spec"}, 1626d388760Sdjm {ERR_REASON(SSL_R_BAD_CHECKSUM) , "bad checksum"}, 1636d388760Sdjm {ERR_REASON(SSL_R_BAD_DATA_RETURNED_BY_CALLBACK), "bad data returned by callback"}, 1646d388760Sdjm {ERR_REASON(SSL_R_BAD_DECOMPRESSION) , "bad decompression"}, 1656d388760Sdjm {ERR_REASON(SSL_R_BAD_DH_G_LENGTH) , "bad dh g length"}, 1666d388760Sdjm {ERR_REASON(SSL_R_BAD_DH_PUB_KEY_LENGTH) , "bad dh pub key length"}, 1676d388760Sdjm {ERR_REASON(SSL_R_BAD_DH_P_LENGTH) , "bad dh p length"}, 1686d388760Sdjm {ERR_REASON(SSL_R_BAD_DIGEST_LENGTH) , "bad digest length"}, 1696d388760Sdjm {ERR_REASON(SSL_R_BAD_DSA_SIGNATURE) , "bad dsa signature"}, 1704fcf65c5Sdjm {ERR_REASON(SSL_R_BAD_ECC_CERT) , "bad ecc cert"}, 1714fcf65c5Sdjm {ERR_REASON(SSL_R_BAD_ECDSA_SIGNATURE) , "bad ecdsa signature"}, 1724fcf65c5Sdjm {ERR_REASON(SSL_R_BAD_ECPOINT) , "bad ecpoint"}, 1730a5d6edeSdjm {ERR_REASON(SSL_R_BAD_HANDSHAKE_LENGTH) , "bad handshake length"}, 1746d388760Sdjm {ERR_REASON(SSL_R_BAD_HELLO_REQUEST) , "bad hello request"}, 1756d388760Sdjm {ERR_REASON(SSL_R_BAD_LENGTH) , "bad length"}, 1766d388760Sdjm {ERR_REASON(SSL_R_BAD_MAC_DECODE) , "bad mac decode"}, 1770a5d6edeSdjm {ERR_REASON(SSL_R_BAD_MAC_LENGTH) , "bad mac length"}, 1786d388760Sdjm {ERR_REASON(SSL_R_BAD_MESSAGE_TYPE) , "bad message type"}, 1796d388760Sdjm {ERR_REASON(SSL_R_BAD_PACKET_LENGTH) , "bad packet length"}, 1806d388760Sdjm {ERR_REASON(SSL_R_BAD_PROTOCOL_VERSION_NUMBER), "bad protocol version number"}, 1810a5d6edeSdjm {ERR_REASON(SSL_R_BAD_PSK_IDENTITY_HINT_LENGTH), "bad psk identity hint length"}, 1826d388760Sdjm {ERR_REASON(SSL_R_BAD_RESPONSE_ARGUMENT) , "bad response argument"}, 1836d388760Sdjm {ERR_REASON(SSL_R_BAD_RSA_DECRYPT) , "bad rsa decrypt"}, 1846d388760Sdjm {ERR_REASON(SSL_R_BAD_RSA_ENCRYPT) , "bad rsa encrypt"}, 1856d388760Sdjm {ERR_REASON(SSL_R_BAD_RSA_E_LENGTH) , "bad rsa e length"}, 1866d388760Sdjm {ERR_REASON(SSL_R_BAD_RSA_MODULUS_LENGTH), "bad rsa modulus length"}, 1876d388760Sdjm {ERR_REASON(SSL_R_BAD_RSA_SIGNATURE) , "bad rsa signature"}, 1886d388760Sdjm {ERR_REASON(SSL_R_BAD_SIGNATURE) , "bad signature"}, 1895cdd308eSdjm {ERR_REASON(SSL_R_BAD_SRP_A_LENGTH) , "bad srp a length"}, 1905cdd308eSdjm {ERR_REASON(SSL_R_BAD_SRP_B_LENGTH) , "bad srp b length"}, 1915cdd308eSdjm {ERR_REASON(SSL_R_BAD_SRP_G_LENGTH) , "bad srp g length"}, 1925cdd308eSdjm {ERR_REASON(SSL_R_BAD_SRP_N_LENGTH) , "bad srp n length"}, 1935cdd308eSdjm {ERR_REASON(SSL_R_BAD_SRP_S_LENGTH) , "bad srp s length"}, 1945cdd308eSdjm {ERR_REASON(SSL_R_BAD_SRTP_MKI_VALUE) , "bad srtp mki value"}, 1955cdd308eSdjm {ERR_REASON(SSL_R_BAD_SRTP_PROTECTION_PROFILE_LIST), "bad srtp protection profile list"}, 1966d388760Sdjm {ERR_REASON(SSL_R_BAD_SSL_FILETYPE) , "bad ssl filetype"}, 1976d388760Sdjm {ERR_REASON(SSL_R_BAD_SSL_SESSION_ID_LENGTH), "bad ssl session id length"}, 1986d388760Sdjm {ERR_REASON(SSL_R_BAD_STATE) , "bad state"}, 1996d388760Sdjm {ERR_REASON(SSL_R_BAD_WRITE_RETRY) , "bad write retry"}, 2006d388760Sdjm {ERR_REASON(SSL_R_BIO_NOT_SET) , "bio not set"}, 2016d388760Sdjm {ERR_REASON(SSL_R_BLOCK_CIPHER_PAD_IS_WRONG), "block cipher pad is wrong"}, 2026d388760Sdjm {ERR_REASON(SSL_R_BN_LIB) , "bn lib"}, 2036d388760Sdjm {ERR_REASON(SSL_R_CA_DN_LENGTH_MISMATCH) , "ca dn length mismatch"}, 2046d388760Sdjm {ERR_REASON(SSL_R_CA_DN_TOO_LONG) , "ca dn too long"}, 2059be8472bStb {ERR_REASON(SSL_R_CA_KEY_TOO_SMALL) , "ca key too small"}, 2069be8472bStb {ERR_REASON(SSL_R_CA_MD_TOO_WEAK) , "ca md too weak"}, 2076d388760Sdjm {ERR_REASON(SSL_R_CCS_RECEIVED_EARLY) , "ccs received early"}, 2086d388760Sdjm {ERR_REASON(SSL_R_CERTIFICATE_VERIFY_FAILED), "certificate verify failed"}, 2096d388760Sdjm {ERR_REASON(SSL_R_CERT_LENGTH_MISMATCH) , "cert length mismatch"}, 2106d388760Sdjm {ERR_REASON(SSL_R_CHALLENGE_IS_DIFFERENT), "challenge is different"}, 2116d388760Sdjm {ERR_REASON(SSL_R_CIPHER_CODE_WRONG_LENGTH), "cipher code wrong length"}, 2124c360d9eSjsing {ERR_REASON(SSL_R_CIPHER_COMPRESSION_UNAVAILABLE), "cipher compression unavailable"}, 2136d388760Sdjm {ERR_REASON(SSL_R_CIPHER_OR_HASH_UNAVAILABLE), "cipher or hash unavailable"}, 2146d388760Sdjm {ERR_REASON(SSL_R_CIPHER_TABLE_SRC_ERROR), "cipher table src error"}, 2154fcf65c5Sdjm {ERR_REASON(SSL_R_CLIENTHELLO_TLSEXT) , "clienthello tlsext"}, 2166d388760Sdjm {ERR_REASON(SSL_R_COMPRESSED_LENGTH_TOO_LONG), "compressed length too long"}, 2170a5d6edeSdjm {ERR_REASON(SSL_R_COMPRESSION_DISABLED) , "compression disabled"}, 2186d388760Sdjm {ERR_REASON(SSL_R_COMPRESSION_FAILURE) , "compression failure"}, 2194fcf65c5Sdjm {ERR_REASON(SSL_R_COMPRESSION_ID_NOT_WITHIN_PRIVATE_RANGE), "compression id not within private range"}, 2206d388760Sdjm {ERR_REASON(SSL_R_COMPRESSION_LIBRARY_ERROR), "compression library error"}, 2216d388760Sdjm {ERR_REASON(SSL_R_CONNECTION_ID_IS_DIFFERENT), "connection id is different"}, 2226d388760Sdjm {ERR_REASON(SSL_R_CONNECTION_TYPE_NOT_SET), "connection type not set"}, 2234fcf65c5Sdjm {ERR_REASON(SSL_R_COOKIE_MISMATCH) , "cookie mismatch"}, 2246d388760Sdjm {ERR_REASON(SSL_R_DATA_BETWEEN_CCS_AND_FINISHED), "data between ccs and finished"}, 2256d388760Sdjm {ERR_REASON(SSL_R_DATA_LENGTH_TOO_LONG) , "data length too long"}, 2266d388760Sdjm {ERR_REASON(SSL_R_DECRYPTION_FAILED) , "decryption failed"}, 2276d388760Sdjm {ERR_REASON(SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC), "decryption failed or bad record mac"}, 2289be8472bStb {ERR_REASON(SSL_R_DH_KEY_TOO_SMALL) , "dh key too small"}, 2296d388760Sdjm {ERR_REASON(SSL_R_DH_PUBLIC_VALUE_LENGTH_IS_WRONG), "dh public value length is wrong"}, 2306d388760Sdjm {ERR_REASON(SSL_R_DIGEST_CHECK_FAILED) , "digest check failed"}, 2310a5d6edeSdjm {ERR_REASON(SSL_R_DTLS_MESSAGE_TOO_BIG) , "dtls message too big"}, 2324fcf65c5Sdjm {ERR_REASON(SSL_R_DUPLICATE_COMPRESSION_ID), "duplicate compression id"}, 2330a5d6edeSdjm {ERR_REASON(SSL_R_ECC_CERT_NOT_FOR_KEY_AGREEMENT), "ecc cert not for key agreement"}, 2340a5d6edeSdjm {ERR_REASON(SSL_R_ECC_CERT_NOT_FOR_SIGNING), "ecc cert not for signing"}, 2350a5d6edeSdjm {ERR_REASON(SSL_R_ECC_CERT_SHOULD_HAVE_RSA_SIGNATURE), "ecc cert should have rsa signature"}, 2360a5d6edeSdjm {ERR_REASON(SSL_R_ECC_CERT_SHOULD_HAVE_SHA1_SIGNATURE), "ecc cert should have sha1 signature"}, 2374fcf65c5Sdjm {ERR_REASON(SSL_R_ECGROUP_TOO_LARGE_FOR_CIPHER), "ecgroup too large for cipher"}, 2389be8472bStb {ERR_REASON(SSL_R_EE_KEY_TOO_SMALL) , "ee key too small"}, 2395cdd308eSdjm {ERR_REASON(SSL_R_EMPTY_SRTP_PROTECTION_PROFILE_LIST), "empty srtp protection profile list"}, 2406d388760Sdjm {ERR_REASON(SSL_R_ENCRYPTED_LENGTH_TOO_LONG), "encrypted length too long"}, 2416d388760Sdjm {ERR_REASON(SSL_R_ERROR_GENERATING_TMP_RSA_KEY), "error generating tmp rsa key"}, 2426d388760Sdjm {ERR_REASON(SSL_R_ERROR_IN_RECEIVED_CIPHER_LIST), "error in received cipher list"}, 2436d388760Sdjm {ERR_REASON(SSL_R_EXCESSIVE_MESSAGE_SIZE), "excessive message size"}, 2446d388760Sdjm {ERR_REASON(SSL_R_EXTRA_DATA_IN_MESSAGE) , "extra data in message"}, 2456d388760Sdjm {ERR_REASON(SSL_R_GOT_A_FIN_BEFORE_A_CCS), "got a fin before a ccs"}, 2465cdd308eSdjm {ERR_REASON(SSL_R_GOT_NEXT_PROTO_BEFORE_A_CCS), "got next proto before a ccs"}, 2475cdd308eSdjm {ERR_REASON(SSL_R_GOT_NEXT_PROTO_WITHOUT_EXTENSION), "got next proto without seeing extension"}, 2486d388760Sdjm {ERR_REASON(SSL_R_HTTPS_PROXY_REQUEST) , "https proxy request"}, 2496d388760Sdjm {ERR_REASON(SSL_R_HTTP_REQUEST) , "http request"}, 2506d388760Sdjm {ERR_REASON(SSL_R_ILLEGAL_PADDING) , "illegal padding"}, 2516877ad7fSjsing {ERR_REASON(SSL_R_INAPPROPRIATE_FALLBACK), "inappropriate fallback"}, 2520a5d6edeSdjm {ERR_REASON(SSL_R_INCONSISTENT_COMPRESSION), "inconsistent compression"}, 2536d388760Sdjm {ERR_REASON(SSL_R_INVALID_CHALLENGE_LENGTH), "invalid challenge length"}, 2546d388760Sdjm {ERR_REASON(SSL_R_INVALID_COMMAND) , "invalid command"}, 2550a5d6edeSdjm {ERR_REASON(SSL_R_INVALID_COMPRESSION_ALGORITHM), "invalid compression algorithm"}, 2566d388760Sdjm {ERR_REASON(SSL_R_INVALID_PURPOSE) , "invalid purpose"}, 2575cdd308eSdjm {ERR_REASON(SSL_R_INVALID_SRP_USERNAME) , "invalid srp username"}, 2584fcf65c5Sdjm {ERR_REASON(SSL_R_INVALID_STATUS_RESPONSE), "invalid status response"}, 2594fcf65c5Sdjm {ERR_REASON(SSL_R_INVALID_TICKET_KEYS_LENGTH), "invalid ticket keys length"}, 2606d388760Sdjm {ERR_REASON(SSL_R_INVALID_TRUST) , "invalid trust"}, 2616d388760Sdjm {ERR_REASON(SSL_R_KEY_ARG_TOO_LONG) , "key arg too long"}, 2626d388760Sdjm {ERR_REASON(SSL_R_KRB5) , "krb5"}, 2636d388760Sdjm {ERR_REASON(SSL_R_KRB5_C_CC_PRINC) , "krb5 client cc principal (no tkt?)"}, 2646d388760Sdjm {ERR_REASON(SSL_R_KRB5_C_GET_CRED) , "krb5 client get cred"}, 2656d388760Sdjm {ERR_REASON(SSL_R_KRB5_C_INIT) , "krb5 client init"}, 2666d388760Sdjm {ERR_REASON(SSL_R_KRB5_C_MK_REQ) , "krb5 client mk_req (expired tkt?)"}, 2676d388760Sdjm {ERR_REASON(SSL_R_KRB5_S_BAD_TICKET) , "krb5 server bad ticket"}, 2686d388760Sdjm {ERR_REASON(SSL_R_KRB5_S_INIT) , "krb5 server init"}, 2696d388760Sdjm {ERR_REASON(SSL_R_KRB5_S_RD_REQ) , "krb5 server rd_req (keytab perms?)"}, 2706d388760Sdjm {ERR_REASON(SSL_R_KRB5_S_TKT_EXPIRED) , "krb5 server tkt expired"}, 2716d388760Sdjm {ERR_REASON(SSL_R_KRB5_S_TKT_NYV) , "krb5 server tkt not yet valid"}, 2726d388760Sdjm {ERR_REASON(SSL_R_KRB5_S_TKT_SKEW) , "krb5 server tkt skew"}, 2736d388760Sdjm {ERR_REASON(SSL_R_LENGTH_MISMATCH) , "length mismatch"}, 2746d388760Sdjm {ERR_REASON(SSL_R_LENGTH_TOO_SHORT) , "length too short"}, 2756d388760Sdjm {ERR_REASON(SSL_R_LIBRARY_BUG) , "library bug"}, 2766d388760Sdjm {ERR_REASON(SSL_R_LIBRARY_HAS_NO_CIPHERS), "library has no ciphers"}, 2776d388760Sdjm {ERR_REASON(SSL_R_MESSAGE_TOO_LONG) , "message too long"}, 2786d388760Sdjm {ERR_REASON(SSL_R_MISSING_DH_DSA_CERT) , "missing dh dsa cert"}, 2796d388760Sdjm {ERR_REASON(SSL_R_MISSING_DH_KEY) , "missing dh key"}, 2806d388760Sdjm {ERR_REASON(SSL_R_MISSING_DH_RSA_CERT) , "missing dh rsa cert"}, 2816d388760Sdjm {ERR_REASON(SSL_R_MISSING_DSA_SIGNING_CERT), "missing dsa signing cert"}, 2826d388760Sdjm {ERR_REASON(SSL_R_MISSING_EXPORT_TMP_DH_KEY), "missing export tmp dh key"}, 2836d388760Sdjm {ERR_REASON(SSL_R_MISSING_EXPORT_TMP_RSA_KEY), "missing export tmp rsa key"}, 2846d388760Sdjm {ERR_REASON(SSL_R_MISSING_RSA_CERTIFICATE), "missing rsa certificate"}, 2856d388760Sdjm {ERR_REASON(SSL_R_MISSING_RSA_ENCRYPTING_CERT), "missing rsa encrypting cert"}, 2866d388760Sdjm {ERR_REASON(SSL_R_MISSING_RSA_SIGNING_CERT), "missing rsa signing cert"}, 2875cdd308eSdjm {ERR_REASON(SSL_R_MISSING_SRP_PARAM) , "can't find SRP server param"}, 2886d388760Sdjm {ERR_REASON(SSL_R_MISSING_TMP_DH_KEY) , "missing tmp dh key"}, 2894fcf65c5Sdjm {ERR_REASON(SSL_R_MISSING_TMP_ECDH_KEY) , "missing tmp ecdh key"}, 2906d388760Sdjm {ERR_REASON(SSL_R_MISSING_TMP_RSA_KEY) , "missing tmp rsa key"}, 2916d388760Sdjm {ERR_REASON(SSL_R_MISSING_TMP_RSA_PKEY) , "missing tmp rsa pkey"}, 2926d388760Sdjm {ERR_REASON(SSL_R_MISSING_VERIFY_MESSAGE), "missing verify message"}, 29317150393Sdjm {ERR_REASON(SSL_R_MULTIPLE_SGC_RESTARTS) , "multiple sgc restarts"}, 2946d388760Sdjm {ERR_REASON(SSL_R_NON_SSLV2_INITIAL_PACKET), "non sslv2 initial packet"}, 295715d5aefStb {ERR_REASON(SSL_R_NO_APPLICATION_PROTOCOL), "no application protocol"}, 2966d388760Sdjm {ERR_REASON(SSL_R_NO_CERTIFICATES_RETURNED), "no certificates returned"}, 2976d388760Sdjm {ERR_REASON(SSL_R_NO_CERTIFICATE_ASSIGNED), "no certificate assigned"}, 2986d388760Sdjm {ERR_REASON(SSL_R_NO_CERTIFICATE_RETURNED), "no certificate returned"}, 2996d388760Sdjm {ERR_REASON(SSL_R_NO_CERTIFICATE_SET) , "no certificate set"}, 3006d388760Sdjm {ERR_REASON(SSL_R_NO_CERTIFICATE_SPECIFIED), "no certificate specified"}, 3016d388760Sdjm {ERR_REASON(SSL_R_NO_CIPHERS_AVAILABLE) , "no ciphers available"}, 3026d388760Sdjm {ERR_REASON(SSL_R_NO_CIPHERS_PASSED) , "no ciphers passed"}, 3036d388760Sdjm {ERR_REASON(SSL_R_NO_CIPHERS_SPECIFIED) , "no ciphers specified"}, 3046d388760Sdjm {ERR_REASON(SSL_R_NO_CIPHER_LIST) , "no cipher list"}, 3056d388760Sdjm {ERR_REASON(SSL_R_NO_CIPHER_MATCH) , "no cipher match"}, 3068214bb00Sdjm {ERR_REASON(SSL_R_NO_CLIENT_CERT_METHOD) , "no client cert method"}, 3076d388760Sdjm {ERR_REASON(SSL_R_NO_CLIENT_CERT_RECEIVED), "no client cert received"}, 3086d388760Sdjm {ERR_REASON(SSL_R_NO_COMPRESSION_SPECIFIED), "no compression specified"}, 3096d388760Sdjm {ERR_REASON(SSL_R_NO_METHOD_SPECIFIED) , "no method specified"}, 3106d388760Sdjm {ERR_REASON(SSL_R_NO_PRIVATEKEY) , "no privatekey"}, 3116d388760Sdjm {ERR_REASON(SSL_R_NO_PRIVATE_KEY_ASSIGNED), "no private key assigned"}, 3126d388760Sdjm {ERR_REASON(SSL_R_NO_PROTOCOLS_AVAILABLE), "no protocols available"}, 3136d388760Sdjm {ERR_REASON(SSL_R_NO_PUBLICKEY) , "no publickey"}, 3140a5d6edeSdjm {ERR_REASON(SSL_R_NO_RENEGOTIATION) , "no renegotiation"}, 3150a5d6edeSdjm {ERR_REASON(SSL_R_NO_REQUIRED_DIGEST) , "digest requred for handshake isn't computed"}, 3166d388760Sdjm {ERR_REASON(SSL_R_NO_SHARED_CIPHER) , "no shared cipher"}, 3175cdd308eSdjm {ERR_REASON(SSL_R_NO_SRTP_PROFILES) , "no srtp profiles"}, 3186d388760Sdjm {ERR_REASON(SSL_R_NO_VERIFY_CALLBACK) , "no verify callback"}, 3196d388760Sdjm {ERR_REASON(SSL_R_NULL_SSL_CTX) , "null ssl ctx"}, 3206d388760Sdjm {ERR_REASON(SSL_R_NULL_SSL_METHOD_PASSED), "null ssl method passed"}, 3216d388760Sdjm {ERR_REASON(SSL_R_OLD_SESSION_CIPHER_NOT_RETURNED), "old session cipher not returned"}, 3220a5d6edeSdjm {ERR_REASON(SSL_R_OLD_SESSION_COMPRESSION_ALGORITHM_NOT_RETURNED), "old session compression algorithm not returned"}, 3236d388760Sdjm {ERR_REASON(SSL_R_ONLY_TLS_ALLOWED_IN_FIPS_MODE), "only tls allowed in fips mode"}, 3246d388760Sdjm {ERR_REASON(SSL_R_PACKET_LENGTH_TOO_LONG), "packet length too long"}, 3254fcf65c5Sdjm {ERR_REASON(SSL_R_PARSE_TLSEXT) , "parse tlsext"}, 3266d388760Sdjm {ERR_REASON(SSL_R_PATH_TOO_LONG) , "path too long"}, 3276da04fa7Stb {ERR_REASON(SSL_R_PEER_BEHAVING_BADLY) , "peer is doing strange or hostile things"}, 3286d388760Sdjm {ERR_REASON(SSL_R_PEER_DID_NOT_RETURN_A_CERTIFICATE), "peer did not return a certificate"}, 3296d388760Sdjm {ERR_REASON(SSL_R_PEER_ERROR) , "peer error"}, 3306d388760Sdjm {ERR_REASON(SSL_R_PEER_ERROR_CERTIFICATE), "peer error certificate"}, 3316d388760Sdjm {ERR_REASON(SSL_R_PEER_ERROR_NO_CERTIFICATE), "peer error no certificate"}, 3326d388760Sdjm {ERR_REASON(SSL_R_PEER_ERROR_NO_CIPHER) , "peer error no cipher"}, 3336d388760Sdjm {ERR_REASON(SSL_R_PEER_ERROR_UNSUPPORTED_CERTIFICATE_TYPE), "peer error unsupported certificate type"}, 3346d388760Sdjm {ERR_REASON(SSL_R_PRE_MAC_LENGTH_TOO_LONG), "pre mac length too long"}, 3356d388760Sdjm {ERR_REASON(SSL_R_PROBLEMS_MAPPING_CIPHER_FUNCTIONS), "problems mapping cipher functions"}, 3366d388760Sdjm {ERR_REASON(SSL_R_PROTOCOL_IS_SHUTDOWN) , "protocol is shutdown"}, 3370a5d6edeSdjm {ERR_REASON(SSL_R_PSK_IDENTITY_NOT_FOUND), "psk identity not found"}, 3380a5d6edeSdjm {ERR_REASON(SSL_R_PSK_NO_CLIENT_CB) , "psk no client cb"}, 3390a5d6edeSdjm {ERR_REASON(SSL_R_PSK_NO_SERVER_CB) , "psk no server cb"}, 3406d388760Sdjm {ERR_REASON(SSL_R_PUBLIC_KEY_ENCRYPT_ERROR), "public key encrypt error"}, 3416d388760Sdjm {ERR_REASON(SSL_R_PUBLIC_KEY_IS_NOT_RSA) , "public key is not rsa"}, 3426d388760Sdjm {ERR_REASON(SSL_R_PUBLIC_KEY_NOT_RSA) , "public key not rsa"}, 343cfa19c4eSjsing {ERR_REASON(SSL_R_QUIC_INTERNAL_ERROR) , "QUIC: internal error"}, 3446d388760Sdjm {ERR_REASON(SSL_R_READ_BIO_NOT_SET) , "read bio not set"}, 3454fcf65c5Sdjm {ERR_REASON(SSL_R_READ_TIMEOUT_EXPIRED) , "read timeout expired"}, 3466d388760Sdjm {ERR_REASON(SSL_R_READ_WRONG_PACKET_TYPE), "read wrong packet type"}, 3476d388760Sdjm {ERR_REASON(SSL_R_RECORD_LENGTH_MISMATCH), "record length mismatch"}, 3486d388760Sdjm {ERR_REASON(SSL_R_RECORD_TOO_LARGE) , "record too large"}, 3496d388760Sdjm {ERR_REASON(SSL_R_RECORD_TOO_SMALL) , "record too small"}, 3500a5d6edeSdjm {ERR_REASON(SSL_R_RENEGOTIATE_EXT_TOO_LONG), "renegotiate ext too long"}, 3510a5d6edeSdjm {ERR_REASON(SSL_R_RENEGOTIATION_ENCODING_ERR), "renegotiation encoding err"}, 3520a5d6edeSdjm {ERR_REASON(SSL_R_RENEGOTIATION_MISMATCH), "renegotiation mismatch"}, 3536d388760Sdjm {ERR_REASON(SSL_R_REQUIRED_CIPHER_MISSING), "required cipher missing"}, 3540a5d6edeSdjm {ERR_REASON(SSL_R_REQUIRED_COMPRESSSION_ALGORITHM_MISSING), "required compresssion algorithm missing"}, 3556d388760Sdjm {ERR_REASON(SSL_R_REUSE_CERT_LENGTH_NOT_ZERO), "reuse cert length not zero"}, 3566d388760Sdjm {ERR_REASON(SSL_R_REUSE_CERT_TYPE_NOT_ZERO), "reuse cert type not zero"}, 3576d388760Sdjm {ERR_REASON(SSL_R_REUSE_CIPHER_LIST_NOT_ZERO), "reuse cipher list not zero"}, 3580a5d6edeSdjm {ERR_REASON(SSL_R_SCSV_RECEIVED_WHEN_RENEGOTIATING), "scsv received when renegotiating"}, 3594fcf65c5Sdjm {ERR_REASON(SSL_R_SERVERHELLO_TLSEXT) , "serverhello tlsext"}, 3606d388760Sdjm {ERR_REASON(SSL_R_SESSION_ID_CONTEXT_UNINITIALIZED), "session id context uninitialized"}, 3616d388760Sdjm {ERR_REASON(SSL_R_SHORT_READ) , "short read"}, 3625cdd308eSdjm {ERR_REASON(SSL_R_SIGNATURE_ALGORITHMS_ERROR), "signature algorithms error"}, 3636d388760Sdjm {ERR_REASON(SSL_R_SIGNATURE_FOR_NON_SIGNING_CERTIFICATE), "signature for non signing certificate"}, 3645cdd308eSdjm {ERR_REASON(SSL_R_SRP_A_CALC) , "error with the srp params"}, 3655cdd308eSdjm {ERR_REASON(SSL_R_SRTP_COULD_NOT_ALLOCATE_PROFILES), "srtp could not allocate profiles"}, 3665cdd308eSdjm {ERR_REASON(SSL_R_SRTP_PROTECTION_PROFILE_LIST_TOO_LONG), "srtp protection profile list too long"}, 3675cdd308eSdjm {ERR_REASON(SSL_R_SRTP_UNKNOWN_PROTECTION_PROFILE), "srtp unknown protection profile"}, 3686d388760Sdjm {ERR_REASON(SSL_R_SSL23_DOING_SESSION_ID_REUSE), "ssl23 doing session id reuse"}, 3696d388760Sdjm {ERR_REASON(SSL_R_SSL2_CONNECTION_ID_TOO_LONG), "ssl2 connection id too long"}, 3700a5d6edeSdjm {ERR_REASON(SSL_R_SSL3_EXT_INVALID_ECPOINTFORMAT), "ssl3 ext invalid ecpointformat"}, 3714fcf65c5Sdjm {ERR_REASON(SSL_R_SSL3_EXT_INVALID_SERVERNAME), "ssl3 ext invalid servername"}, 3724fcf65c5Sdjm {ERR_REASON(SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE), "ssl3 ext invalid servername type"}, 3736d388760Sdjm {ERR_REASON(SSL_R_SSL3_SESSION_ID_TOO_LONG), "ssl3 session id too long"}, 3746d388760Sdjm {ERR_REASON(SSL_R_SSL3_SESSION_ID_TOO_SHORT), "ssl3 session id too short"}, 3756d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_BAD_CERTIFICATE), "sslv3 alert bad certificate"}, 3766d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_BAD_RECORD_MAC), "sslv3 alert bad record mac"}, 3776d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED), "sslv3 alert certificate expired"}, 3786d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED), "sslv3 alert certificate revoked"}, 3796d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN), "sslv3 alert certificate unknown"}, 3806d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE), "sslv3 alert decompression failure"}, 3816d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE), "sslv3 alert handshake failure"}, 3826d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER), "sslv3 alert illegal parameter"}, 3836d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_NO_CERTIFICATE), "sslv3 alert no certificate"}, 3846d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE), "sslv3 alert unexpected message"}, 3856d388760Sdjm {ERR_REASON(SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE), "sslv3 alert unsupported certificate"}, 3866d388760Sdjm {ERR_REASON(SSL_R_SSL_CTX_HAS_NO_DEFAULT_SSL_VERSION), "ssl ctx has no default ssl version"}, 3876d388760Sdjm {ERR_REASON(SSL_R_SSL_HANDSHAKE_FAILURE) , "ssl handshake failure"}, 3886d388760Sdjm {ERR_REASON(SSL_R_SSL_LIBRARY_HAS_NO_CIPHERS), "ssl library has no ciphers"}, 3896d388760Sdjm {ERR_REASON(SSL_R_SSL_SESSION_ID_CALLBACK_FAILED), "ssl session id callback failed"}, 3906d388760Sdjm {ERR_REASON(SSL_R_SSL_SESSION_ID_CONFLICT), "ssl session id conflict"}, 3916d388760Sdjm {ERR_REASON(SSL_R_SSL_SESSION_ID_CONTEXT_TOO_LONG), "ssl session id context too long"}, 3926d388760Sdjm {ERR_REASON(SSL_R_SSL_SESSION_ID_HAS_BAD_LENGTH), "ssl session id has bad length"}, 3936d388760Sdjm {ERR_REASON(SSL_R_SSL_SESSION_ID_IS_DIFFERENT), "ssl session id is different"}, 39425ba64d1Stb {ERR_REASON(SSL_R_SSL_SESSION_ID_TOO_LONG), "ssl session id is too long"}, 395*48d99288Stb {ERR_REASON(SSL_R_TLSV13_ALERT_CERTIFICATE_REQUIRED), "tlsv13 alert certificate required"}, 396*48d99288Stb {ERR_REASON(SSL_R_TLSV13_ALERT_MISSING_EXTENSION), "tlsv13 alert missing extension"}, 3976d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_ACCESS_DENIED), "tlsv1 alert access denied"}, 3986d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_DECODE_ERROR), "tlsv1 alert decode error"}, 3996d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_DECRYPTION_FAILED), "tlsv1 alert decryption failed"}, 4006d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_DECRYPT_ERROR), "tlsv1 alert decrypt error"}, 4016d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_EXPORT_RESTRICTION), "tlsv1 alert export restriction"}, 4026877ad7fSjsing {ERR_REASON(SSL_R_TLSV1_ALERT_INAPPROPRIATE_FALLBACK), "tlsv1 alert inappropriate fallback"}, 4036d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_INSUFFICIENT_SECURITY), "tlsv1 alert insufficient security"}, 4046d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_INTERNAL_ERROR), "tlsv1 alert internal error"}, 405*48d99288Stb {ERR_REASON(SSL_R_TLSV1_ALERT_NO_APPLICATION_PROTOCOL), "tlsv1 alert no application protocol"}, 4066d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_NO_RENEGOTIATION), "tlsv1 alert no renegotiation"}, 4076d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_PROTOCOL_VERSION), "tlsv1 alert protocol version"}, 4086d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_RECORD_OVERFLOW), "tlsv1 alert record overflow"}, 4096d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_UNKNOWN_CA), "tlsv1 alert unknown ca"}, 410*48d99288Stb {ERR_REASON(SSL_R_TLSV1_ALERT_UNKNOWN_PSK_IDENTITY), "tlsv1 alert unknown psk_identity"}, 4116d388760Sdjm {ERR_REASON(SSL_R_TLSV1_ALERT_USER_CANCELLED), "tlsv1 alert user cancelled"}, 4120a5d6edeSdjm {ERR_REASON(SSL_R_TLSV1_BAD_CERTIFICATE_HASH_VALUE), "tlsv1 bad certificate hash value"}, 4130a5d6edeSdjm {ERR_REASON(SSL_R_TLSV1_BAD_CERTIFICATE_STATUS_RESPONSE), "tlsv1 bad certificate status response"}, 4140a5d6edeSdjm {ERR_REASON(SSL_R_TLSV1_CERTIFICATE_UNOBTAINABLE), "tlsv1 certificate unobtainable"}, 4150a5d6edeSdjm {ERR_REASON(SSL_R_TLSV1_UNRECOGNIZED_NAME), "tlsv1 unrecognized name"}, 4160a5d6edeSdjm {ERR_REASON(SSL_R_TLSV1_UNSUPPORTED_EXTENSION), "tlsv1 unsupported extension"}, 4176d388760Sdjm {ERR_REASON(SSL_R_TLS_CLIENT_CERT_REQ_WITH_ANON_CIPHER), "tls client cert req with anon cipher"}, 418c2072fd3Slogan {ERR_REASON(SSL_R_TLS_HEARTBEAT_PEER_DOESNT_ACCEPT), "peer does not accept heartbeats"}, 4195cdd308eSdjm {ERR_REASON(SSL_R_TLS_HEARTBEAT_PENDING) , "heartbeat request already pending"}, 4205cdd308eSdjm {ERR_REASON(SSL_R_TLS_ILLEGAL_EXPORTER_LABEL), "tls illegal exporter label"}, 4214fcf65c5Sdjm {ERR_REASON(SSL_R_TLS_INVALID_ECPOINTFORMAT_LIST), "tls invalid ecpointformat list"}, 4226d388760Sdjm {ERR_REASON(SSL_R_TLS_PEER_DID_NOT_RESPOND_WITH_CERTIFICATE_LIST), "tls peer did not respond with certificate list"}, 4236d388760Sdjm {ERR_REASON(SSL_R_TLS_RSA_ENCRYPTED_VALUE_LENGTH_IS_WRONG), "tls rsa encrypted value length is wrong"}, 4246d388760Sdjm {ERR_REASON(SSL_R_UNABLE_TO_DECODE_DH_CERTS), "unable to decode dh certs"}, 4254fcf65c5Sdjm {ERR_REASON(SSL_R_UNABLE_TO_DECODE_ECDH_CERTS), "unable to decode ecdh certs"}, 4266d388760Sdjm {ERR_REASON(SSL_R_UNABLE_TO_EXTRACT_PUBLIC_KEY), "unable to extract public key"}, 4276d388760Sdjm {ERR_REASON(SSL_R_UNABLE_TO_FIND_DH_PARAMETERS), "unable to find dh parameters"}, 4284fcf65c5Sdjm {ERR_REASON(SSL_R_UNABLE_TO_FIND_ECDH_PARAMETERS), "unable to find ecdh parameters"}, 4296d388760Sdjm {ERR_REASON(SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS), "unable to find public key parameters"}, 4306d388760Sdjm {ERR_REASON(SSL_R_UNABLE_TO_FIND_SSL_METHOD), "unable to find ssl method"}, 4316d388760Sdjm {ERR_REASON(SSL_R_UNABLE_TO_LOAD_SSL2_MD5_ROUTINES), "unable to load ssl2 md5 routines"}, 4326d388760Sdjm {ERR_REASON(SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES), "unable to load ssl3 md5 routines"}, 4336d388760Sdjm {ERR_REASON(SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES), "unable to load ssl3 sha1 routines"}, 4346d388760Sdjm {ERR_REASON(SSL_R_UNEXPECTED_MESSAGE) , "unexpected message"}, 4356d388760Sdjm {ERR_REASON(SSL_R_UNEXPECTED_RECORD) , "unexpected record"}, 4366d388760Sdjm {ERR_REASON(SSL_R_UNINITIALIZED) , "uninitialized"}, 4376da04fa7Stb {ERR_REASON(SSL_R_UNKNOWN), "unknown failure occurred"}, 4386d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_ALERT_TYPE) , "unknown alert type"}, 4396d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_CERTIFICATE_TYPE), "unknown certificate type"}, 4406d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_CIPHER_RETURNED), "unknown cipher returned"}, 4416d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_CIPHER_TYPE) , "unknown cipher type"}, 4425cdd308eSdjm {ERR_REASON(SSL_R_UNKNOWN_DIGEST) , "unknown digest"}, 4436d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_KEY_EXCHANGE_TYPE), "unknown key exchange type"}, 4446d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_PKEY_TYPE) , "unknown pkey type"}, 4456d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_PROTOCOL) , "unknown protocol"}, 4466d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_REMOTE_ERROR_TYPE), "unknown remote error type"}, 4476d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_SSL_VERSION) , "unknown ssl version"}, 4486d388760Sdjm {ERR_REASON(SSL_R_UNKNOWN_STATE) , "unknown state"}, 4490a5d6edeSdjm {ERR_REASON(SSL_R_UNSAFE_LEGACY_RENEGOTIATION_DISABLED), "unsafe legacy renegotiation disabled"}, 4506d388760Sdjm {ERR_REASON(SSL_R_UNSUPPORTED_CIPHER) , "unsupported cipher"}, 4516d388760Sdjm {ERR_REASON(SSL_R_UNSUPPORTED_COMPRESSION_ALGORITHM), "unsupported compression algorithm"}, 4520a5d6edeSdjm {ERR_REASON(SSL_R_UNSUPPORTED_DIGEST_TYPE), "unsupported digest type"}, 4534fcf65c5Sdjm {ERR_REASON(SSL_R_UNSUPPORTED_ELLIPTIC_CURVE), "unsupported elliptic curve"}, 4546d388760Sdjm {ERR_REASON(SSL_R_UNSUPPORTED_PROTOCOL) , "unsupported protocol"}, 4556d388760Sdjm {ERR_REASON(SSL_R_UNSUPPORTED_SSL_VERSION), "unsupported ssl version"}, 4564fcf65c5Sdjm {ERR_REASON(SSL_R_UNSUPPORTED_STATUS_TYPE), "unsupported status type"}, 4575cdd308eSdjm {ERR_REASON(SSL_R_USE_SRTP_NOT_NEGOTIATED), "use srtp not negotiated"}, 4589be8472bStb {ERR_REASON(SSL_R_VERSION_TOO_LOW) , "version too low"}, 4596d388760Sdjm {ERR_REASON(SSL_R_WRITE_BIO_NOT_SET) , "write bio not set"}, 4606d388760Sdjm {ERR_REASON(SSL_R_WRONG_CIPHER_RETURNED) , "wrong cipher returned"}, 46177897655Sjsing {ERR_REASON(SSL_R_WRONG_CURVE) , "wrong curve"}, 462cfa19c4eSjsing {ERR_REASON(SSL_R_WRONG_ENCRYPTION_LEVEL_RECEIVED), "QUIC: wrong encryption level received"}, 4636d388760Sdjm {ERR_REASON(SSL_R_WRONG_MESSAGE_TYPE) , "wrong message type"}, 4646d388760Sdjm {ERR_REASON(SSL_R_WRONG_NUMBER_OF_KEY_BITS), "wrong number of key bits"}, 4656d388760Sdjm {ERR_REASON(SSL_R_WRONG_SIGNATURE_LENGTH), "wrong signature length"}, 4666d388760Sdjm {ERR_REASON(SSL_R_WRONG_SIGNATURE_SIZE) , "wrong signature size"}, 4675cdd308eSdjm {ERR_REASON(SSL_R_WRONG_SIGNATURE_TYPE) , "wrong signature type"}, 4686d388760Sdjm {ERR_REASON(SSL_R_WRONG_SSL_VERSION) , "wrong ssl version"}, 4696d388760Sdjm {ERR_REASON(SSL_R_WRONG_VERSION_NUMBER) , "wrong version number"}, 4706d388760Sdjm {ERR_REASON(SSL_R_X509_LIB) , "x509 lib"}, 4716d388760Sdjm {ERR_REASON(SSL_R_X509_VERIFICATION_SETUP_PROBLEMS), "x509 verification setup problems"}, 472913ec974Sbeck {0, NULL} 4735b37fcf3Sryker }; 4745b37fcf3Sryker 4755b37fcf3Sryker #endif 4765b37fcf3Sryker 47735fb0677Sjsing void 47835fb0677Sjsing ERR_load_SSL_strings(void) 4795b37fcf3Sryker { 480da347917Sbeck #ifndef OPENSSL_NO_ERR 48135fb0677Sjsing if (ERR_func_error_string(SSL_str_functs[0].error) == NULL) { 4825dd6d43aStb /* TMP UGLY CASTS */ 4835f4c8480Stb ERR_load_strings(0, (ERR_STRING_DATA *)SSL_str_functs); 4845f4c8480Stb ERR_load_strings(0, (ERR_STRING_DATA *)SSL_str_reasons); 4855b37fcf3Sryker } 4864fcf65c5Sdjm #endif 4875b37fcf3Sryker } 48871e04849Sbeck LSSL_ALIAS(ERR_load_SSL_strings); 489ee426d13Sjsing 490ee426d13Sjsing void 491ee426d13Sjsing SSL_load_error_strings(void) 492ee426d13Sjsing { 493ee426d13Sjsing #ifndef OPENSSL_NO_ERR 494ee426d13Sjsing ERR_load_crypto_strings(); 495ee426d13Sjsing ERR_load_SSL_strings(); 496ee426d13Sjsing #endif 497ee426d13Sjsing } 49871e04849Sbeck LSSL_ALIAS(SSL_load_error_strings); 499c9d7abb7Sbeck 500c9d7abb7Sbeck int 501c9d7abb7Sbeck SSL_state_func_code(int state) { 502c9d7abb7Sbeck switch (state) { 503c9d7abb7Sbeck case SSL3_ST_CW_FLUSH: 504c9d7abb7Sbeck return 1; 505c9d7abb7Sbeck case SSL3_ST_CW_CLNT_HELLO_A: 506c9d7abb7Sbeck return 2; 507c9d7abb7Sbeck case SSL3_ST_CW_CLNT_HELLO_B: 508c9d7abb7Sbeck return 3; 509c9d7abb7Sbeck case SSL3_ST_CR_SRVR_HELLO_A: 510c9d7abb7Sbeck return 4; 511c9d7abb7Sbeck case SSL3_ST_CR_SRVR_HELLO_B: 512c9d7abb7Sbeck return 5; 513c9d7abb7Sbeck case SSL3_ST_CR_CERT_A: 514c9d7abb7Sbeck return 6; 515c9d7abb7Sbeck case SSL3_ST_CR_CERT_B: 516c9d7abb7Sbeck return 7; 517c9d7abb7Sbeck case SSL3_ST_CR_KEY_EXCH_A: 518c9d7abb7Sbeck return 8; 519c9d7abb7Sbeck case SSL3_ST_CR_KEY_EXCH_B: 520c9d7abb7Sbeck return 9; 521c9d7abb7Sbeck case SSL3_ST_CR_CERT_REQ_A: 522c9d7abb7Sbeck return 10; 523c9d7abb7Sbeck case SSL3_ST_CR_CERT_REQ_B: 524c9d7abb7Sbeck return 11; 525c9d7abb7Sbeck case SSL3_ST_CR_SRVR_DONE_A: 526c9d7abb7Sbeck return 12; 527c9d7abb7Sbeck case SSL3_ST_CR_SRVR_DONE_B: 528c9d7abb7Sbeck return 13; 529c9d7abb7Sbeck case SSL3_ST_CW_CERT_A: 530c9d7abb7Sbeck return 14; 531c9d7abb7Sbeck case SSL3_ST_CW_CERT_B: 532c9d7abb7Sbeck return 15; 533c9d7abb7Sbeck case SSL3_ST_CW_CERT_C: 534c9d7abb7Sbeck return 16; 535c9d7abb7Sbeck case SSL3_ST_CW_CERT_D: 536c9d7abb7Sbeck return 17; 537c9d7abb7Sbeck case SSL3_ST_CW_KEY_EXCH_A: 538c9d7abb7Sbeck return 18; 539c9d7abb7Sbeck case SSL3_ST_CW_KEY_EXCH_B: 540c9d7abb7Sbeck return 19; 541c9d7abb7Sbeck case SSL3_ST_CW_CERT_VRFY_A: 542c9d7abb7Sbeck return 20; 543c9d7abb7Sbeck case SSL3_ST_CW_CERT_VRFY_B: 544c9d7abb7Sbeck return 21; 545c9d7abb7Sbeck case SSL3_ST_CW_CHANGE_A: 546c9d7abb7Sbeck return 22; 547c9d7abb7Sbeck case SSL3_ST_CW_CHANGE_B: 548c9d7abb7Sbeck return 23; 549c9d7abb7Sbeck case SSL3_ST_CW_FINISHED_A: 550c9d7abb7Sbeck return 26; 551c9d7abb7Sbeck case SSL3_ST_CW_FINISHED_B: 552c9d7abb7Sbeck return 27; 553c9d7abb7Sbeck case SSL3_ST_CR_CHANGE_A: 554c9d7abb7Sbeck return 28; 555c9d7abb7Sbeck case SSL3_ST_CR_CHANGE_B: 556c9d7abb7Sbeck return 29; 557c9d7abb7Sbeck case SSL3_ST_CR_FINISHED_A: 558c9d7abb7Sbeck return 30; 559c9d7abb7Sbeck case SSL3_ST_CR_FINISHED_B: 560c9d7abb7Sbeck return 31; 561c9d7abb7Sbeck case SSL3_ST_CR_SESSION_TICKET_A: 562c9d7abb7Sbeck return 32; 563c9d7abb7Sbeck case SSL3_ST_CR_SESSION_TICKET_B: 564c9d7abb7Sbeck return 33; 565c9d7abb7Sbeck case SSL3_ST_CR_CERT_STATUS_A: 566c9d7abb7Sbeck return 34; 567c9d7abb7Sbeck case SSL3_ST_CR_CERT_STATUS_B: 568c9d7abb7Sbeck return 35; 569c9d7abb7Sbeck case SSL3_ST_SW_FLUSH: 570c9d7abb7Sbeck return 36; 571c9d7abb7Sbeck case SSL3_ST_SR_CLNT_HELLO_A: 572c9d7abb7Sbeck return 37; 573c9d7abb7Sbeck case SSL3_ST_SR_CLNT_HELLO_B: 574c9d7abb7Sbeck return 38; 575c9d7abb7Sbeck case SSL3_ST_SR_CLNT_HELLO_C: 576c9d7abb7Sbeck return 39; 577c9d7abb7Sbeck case SSL3_ST_SW_HELLO_REQ_A: 578c9d7abb7Sbeck return 40; 579c9d7abb7Sbeck case SSL3_ST_SW_HELLO_REQ_B: 580c9d7abb7Sbeck return 41; 581c9d7abb7Sbeck case SSL3_ST_SW_HELLO_REQ_C: 582c9d7abb7Sbeck return 42; 583c9d7abb7Sbeck case SSL3_ST_SW_SRVR_HELLO_A: 584c9d7abb7Sbeck return 43; 585c9d7abb7Sbeck case SSL3_ST_SW_SRVR_HELLO_B: 586c9d7abb7Sbeck return 44; 587c9d7abb7Sbeck case SSL3_ST_SW_CERT_A: 588c9d7abb7Sbeck return 45; 589c9d7abb7Sbeck case SSL3_ST_SW_CERT_B: 590c9d7abb7Sbeck return 46; 591c9d7abb7Sbeck case SSL3_ST_SW_KEY_EXCH_A: 592c9d7abb7Sbeck return 47; 593c9d7abb7Sbeck case SSL3_ST_SW_KEY_EXCH_B: 594c9d7abb7Sbeck return 48; 595c9d7abb7Sbeck case SSL3_ST_SW_CERT_REQ_A: 596c9d7abb7Sbeck return 49; 597c9d7abb7Sbeck case SSL3_ST_SW_CERT_REQ_B: 598c9d7abb7Sbeck return 50; 599c9d7abb7Sbeck case SSL3_ST_SW_SRVR_DONE_A: 600c9d7abb7Sbeck return 51; 601c9d7abb7Sbeck case SSL3_ST_SW_SRVR_DONE_B: 602c9d7abb7Sbeck return 52; 603c9d7abb7Sbeck case SSL3_ST_SR_CERT_A: 604c9d7abb7Sbeck return 53; 605c9d7abb7Sbeck case SSL3_ST_SR_CERT_B: 606c9d7abb7Sbeck return 54; 607c9d7abb7Sbeck case SSL3_ST_SR_KEY_EXCH_A: 608c9d7abb7Sbeck return 55; 609c9d7abb7Sbeck case SSL3_ST_SR_KEY_EXCH_B: 610c9d7abb7Sbeck return 56; 611c9d7abb7Sbeck case SSL3_ST_SR_CERT_VRFY_A: 612c9d7abb7Sbeck return 57; 613c9d7abb7Sbeck case SSL3_ST_SR_CERT_VRFY_B: 614c9d7abb7Sbeck return 58; 615c9d7abb7Sbeck case SSL3_ST_SR_CHANGE_A: 616c9d7abb7Sbeck return 59; 617c9d7abb7Sbeck case SSL3_ST_SR_CHANGE_B: 618c9d7abb7Sbeck return 60; 619c9d7abb7Sbeck case SSL3_ST_SR_FINISHED_A: 620c9d7abb7Sbeck return 63; 621c9d7abb7Sbeck case SSL3_ST_SR_FINISHED_B: 622c9d7abb7Sbeck return 64; 623c9d7abb7Sbeck case SSL3_ST_SW_CHANGE_A: 624c9d7abb7Sbeck return 65; 625c9d7abb7Sbeck case SSL3_ST_SW_CHANGE_B: 626c9d7abb7Sbeck return 66; 627c9d7abb7Sbeck case SSL3_ST_SW_FINISHED_A: 628c9d7abb7Sbeck return 67; 629c9d7abb7Sbeck case SSL3_ST_SW_FINISHED_B: 630c9d7abb7Sbeck return 68; 631c9d7abb7Sbeck case SSL3_ST_SW_SESSION_TICKET_A: 632c9d7abb7Sbeck return 69; 633c9d7abb7Sbeck case SSL3_ST_SW_SESSION_TICKET_B: 634c9d7abb7Sbeck return 70; 635c9d7abb7Sbeck case SSL3_ST_SW_CERT_STATUS_A: 636c9d7abb7Sbeck return 71; 637c9d7abb7Sbeck case SSL3_ST_SW_CERT_STATUS_B: 638c9d7abb7Sbeck return 72; 639c9d7abb7Sbeck case SSL_ST_BEFORE: 640c9d7abb7Sbeck return 73; 641c9d7abb7Sbeck case SSL_ST_ACCEPT: 642c9d7abb7Sbeck return 74; 643c9d7abb7Sbeck case SSL_ST_CONNECT: 644c9d7abb7Sbeck return 75; 645c9d7abb7Sbeck case SSL_ST_OK: 646c9d7abb7Sbeck return 76; 647c9d7abb7Sbeck case SSL_ST_RENEGOTIATE: 648c9d7abb7Sbeck return 77; 649c9d7abb7Sbeck case SSL_ST_BEFORE|SSL_ST_CONNECT: 650c9d7abb7Sbeck return 78; 651c9d7abb7Sbeck case SSL_ST_OK|SSL_ST_CONNECT: 652c9d7abb7Sbeck return 79; 653c9d7abb7Sbeck case SSL_ST_BEFORE|SSL_ST_ACCEPT: 654c9d7abb7Sbeck return 80; 655c9d7abb7Sbeck case SSL_ST_OK|SSL_ST_ACCEPT: 656c9d7abb7Sbeck return 81; 657c9d7abb7Sbeck case DTLS1_ST_CR_HELLO_VERIFY_REQUEST_A: 658c9d7abb7Sbeck return 83; 659c9d7abb7Sbeck case DTLS1_ST_CR_HELLO_VERIFY_REQUEST_B: 660c9d7abb7Sbeck return 84; 661c9d7abb7Sbeck case DTLS1_ST_SW_HELLO_VERIFY_REQUEST_A: 662c9d7abb7Sbeck return 85; 663c9d7abb7Sbeck case DTLS1_ST_SW_HELLO_VERIFY_REQUEST_B: 664c9d7abb7Sbeck return 86; 665c9d7abb7Sbeck default: 666c9d7abb7Sbeck break; 667c9d7abb7Sbeck } 668c9d7abb7Sbeck return 0xfff; 669c9d7abb7Sbeck } 670440bed4fSbeck 671440bed4fSbeck void 672440bed4fSbeck SSL_error_internal(const SSL *s, int r, char *f, int l) 673440bed4fSbeck { 674440bed4fSbeck ERR_PUT_error(ERR_LIB_SSL, 67502876cc3Sjsing (SSL_state_func_code(s->s3->hs.state)), r, f, l); 676440bed4fSbeck } 677