- wo_tls_server: the mirror of the client driver. parse ClientHello (pick
suite, extract x25519 share, echo session id; reject no-x25519/no-1.3),
build ServerHello, derive the role-symmetric keys, emit the encrypted
flight (EncryptedExtensions + Certificate + a signed CertificateVerify +
Finished), verify the client Finished, switch to application keys
- server_sign_cv signs the CertificateVerify with the phase-G1 primitives
(RSA-PSS or ECDSA-P256 + a minimal DER SEQ{r,s} encoder); parse_client_hello
+ build helpers reuse the file's wire reader/writer
- wo_tls_server_start builds the Certificate message from a cert chain +
private key (RSA n/d or EC scalar) + ephemeral; encrypt/decrypt over the
application keys
- KAT: loopback — our client driver against our server driver, EC then RSA
server identity, reaching ESTABLISHED with an app round-trip both ways.
test_tls 123, ASan/UBSan clean
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 34d2b8f87cebe536cd2b1b33e6948251ec11684f)