|
| 1 | +***************************** |
| 2 | +mbedtls Network Stream Driver |
| 3 | +***************************** |
| 4 | + |
| 5 | +=========================== =========================================================================== |
| 6 | +**Driver Name:** **mbedtls** |
| 7 | +** Author:** Stéphane Adenot < [email protected]> |
| 8 | +**Available since:** |
| 9 | +=========================== =========================================================================== |
| 10 | + |
| 11 | + |
| 12 | +Purpose |
| 13 | +======= |
| 14 | + |
| 15 | +This network stream driver implements a TLS protected transport |
| 16 | +via the `MbedTLS library <https://www.trustedfirmware.org/projects/mbed-tls/>`_. |
| 17 | + |
| 18 | + |
| 19 | +Supported Driver Modes |
| 20 | +====================== |
| 21 | + |
| 22 | +- **0** - unencrypted transmission (just like `ptcp <ns_ptcp.html>`_ driver) |
| 23 | +- **1** - TLS-protected operation |
| 24 | + |
| 25 | +.. note:: |
| 26 | + |
| 27 | + Mode 0 does not provide any benefit over the ptcp driver. This |
| 28 | + mode exists for technical reasons, but should not be used. It may be |
| 29 | + removed in the future. |
| 30 | + |
| 31 | + |
| 32 | +Supported Authentication Modes |
| 33 | +============================== |
| 34 | + |
| 35 | +- **anon** - anonymous authentication as described in IETF's |
| 36 | + draft-ietf-syslog-transport-tls-12 Internet draft |
| 37 | + |
| 38 | +- **x509/certvalid** - certificate validation only. x509/certvalid is |
| 39 | + a nonstandard mode. It validates the remote peers certificate, but |
| 40 | + does not check the subject name. This is weak authentication that may |
| 41 | + be useful in scenarios where multiple devices are deployed and it is |
| 42 | + sufficient proof of authenticity when their certificates are signed by |
| 43 | + the CA the server trusts. This is better than anon authentication, but |
| 44 | + still not recommended. **Known Problems** |
| 45 | + |
| 46 | +- **x509/name** - certificate validation and subject name authentication as |
| 47 | + described in IETF's draft-ietf-syslog-transport-tls-12 Internet draft |
| 48 | + |
| 49 | +.. note:: |
| 50 | + |
| 51 | + "anon" does not permit to authenticate the remote peer. As such, |
| 52 | + this mode is vulnerable to man in the middle attacks as well as |
| 53 | + unauthorized access. It is recommended NOT to use this mode. |
| 54 | + A certificate / key does not need to be configured in this authmode. |
0 commit comments