Blame src/lib/crypto/openssl/enc_provider/des3.c

Packit Service e737ee
/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
Packit Service e737ee
/* lib/crypto/openssl/enc_provider/des3.c */
Packit Service e737ee
/*
Packit Service e737ee
 * Copyright (C) 2009 by the Massachusetts Institute of Technology.
Packit Service e737ee
 * All rights reserved.
Packit Service e737ee
 *
Packit Service e737ee
 * Export of this software from the United States of America may
Packit Service e737ee
 *   require a specific license from the United States Government.
Packit Service e737ee
 *   It is the responsibility of any person or organization contemplating
Packit Service e737ee
 *   export to obtain such a license before exporting.
Packit Service e737ee
 *
Packit Service e737ee
 * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
Packit Service e737ee
 * distribute this software and its documentation for any purpose and
Packit Service e737ee
 * without fee is hereby granted, provided that the above copyright
Packit Service e737ee
 * notice appear in all copies and that both that copyright notice and
Packit Service e737ee
 * this permission notice appear in supporting documentation, and that
Packit Service e737ee
 * the name of M.I.T. not be used in advertising or publicity pertaining
Packit Service e737ee
 * to distribution of the software without specific, written prior
Packit Service e737ee
 * permission.  Furthermore if you modify this software you must label
Packit Service e737ee
 * your software as modified software and not distribute it in such a
Packit Service e737ee
 * fashion that it might be confused with the original M.I.T. software.
Packit Service e737ee
 * M.I.T. makes no representations about the suitability of
Packit Service e737ee
 * this software for any purpose.  It is provided "as is" without express
Packit Service e737ee
 * or implied warranty.
Packit Service e737ee
 */
Packit Service e737ee
/*
Packit Service e737ee
 * Copyright (C) 1998 by the FundsXpress, INC.
Packit Service e737ee
 *
Packit Service e737ee
 * All rights reserved.
Packit Service e737ee
 *
Packit Service e737ee
 * Export of this software from the United States of America may require
Packit Service e737ee
 * a specific license from the United States Government.  It is the
Packit Service e737ee
 * responsibility of any person or organization contemplating export to
Packit Service e737ee
 * obtain such a license before exporting.
Packit Service e737ee
 *
Packit Service e737ee
 * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
Packit Service e737ee
 * distribute this software and its documentation for any purpose and
Packit Service e737ee
 * without fee is hereby granted, provided that the above copyright
Packit Service e737ee
 * notice appear in all copies and that both that copyright notice and
Packit Service e737ee
 * this permission notice appear in supporting documentation, and that
Packit Service e737ee
 * the name of FundsXpress. not be used in advertising or publicity pertaining
Packit Service e737ee
 * to distribution of the software without specific, written prior
Packit Service e737ee
 * permission.  FundsXpress makes no representations about the suitability of
Packit Service e737ee
 * this software for any purpose.  It is provided "as is" without express
Packit Service e737ee
 * or implied warranty.
Packit Service e737ee
 *
Packit Service e737ee
 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR
Packit Service e737ee
 * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
Packit Service e737ee
 * WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
Packit Service e737ee
 */
Packit Service e737ee
Packit Service e737ee
#include "crypto_int.h"
Packit Service e737ee
#include <openssl/evp.h>
Packit Service e737ee
Packit Service e737ee
Packit Service e737ee
#define DES3_BLOCK_SIZE 8
Packit Service e737ee
#define DES3_KEY_SIZE 24
Packit Service e737ee
#define DES3_KEY_BYTES 21
Packit Service e737ee
Packit Service e737ee
static krb5_error_code
Packit Service e737ee
validate(krb5_key key, const krb5_data *ivec, const krb5_crypto_iov *data,
Packit Service e737ee
         size_t num_data, krb5_boolean *empty)
Packit Service e737ee
{
Packit Service e737ee
    size_t input_length = iov_total_length(data, num_data, FALSE);
Packit Service e737ee
Packit Service e737ee
    if (key->keyblock.length != DES3_KEY_SIZE)
Packit Service e737ee
        return(KRB5_BAD_KEYSIZE);
Packit Service e737ee
    if ((input_length%DES3_BLOCK_SIZE) != 0)
Packit Service e737ee
        return(KRB5_BAD_MSIZE);
Packit Service e737ee
    if (ivec && (ivec->length != 8))
Packit Service e737ee
        return(KRB5_BAD_MSIZE);
Packit Service e737ee
Packit Service e737ee
    *empty = (input_length == 0);
Packit Service e737ee
    return 0;
Packit Service e737ee
}
Packit Service e737ee
Packit Service e737ee
static krb5_error_code
Packit Service e737ee
k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data,
Packit Service e737ee
                size_t num_data)
Packit Service e737ee
{
Packit Service e737ee
    int ret, olen = DES3_BLOCK_SIZE;
Packit Service e737ee
    unsigned char iblock[DES3_BLOCK_SIZE], oblock[DES3_BLOCK_SIZE];
Packit Service e737ee
    struct iov_cursor cursor;
Packit Service e737ee
    EVP_CIPHER_CTX *ctx;
Packit Service e737ee
    krb5_boolean empty;
Packit Service e737ee
Packit Service e737ee
    ret = validate(key, ivec, data, num_data, &empty);
Packit Service e737ee
    if (ret != 0 || empty)
Packit Service e737ee
        return ret;
Packit Service e737ee
Packit Service e737ee
    ctx = EVP_CIPHER_CTX_new();
Packit Service e737ee
    if (ctx == NULL)
Packit Service e737ee
        return ENOMEM;
Packit Service e737ee
Packit Service e737ee
    ret = EVP_EncryptInit_ex(ctx, EVP_des_ede3_cbc(), NULL,
Packit Service e737ee
                             key->keyblock.contents,
Packit Service e737ee
                             (ivec) ? (unsigned char*)ivec->data : NULL);
Packit Service e737ee
    if (!ret) {
Packit Service e737ee
        EVP_CIPHER_CTX_free(ctx);
Packit Service e737ee
        return KRB5_CRYPTO_INTERNAL;
Packit Service e737ee
    }
Packit Service e737ee
Packit Service e737ee
    EVP_CIPHER_CTX_set_padding(ctx,0);
Packit Service e737ee
Packit Service e737ee
    k5_iov_cursor_init(&cursor, data, num_data, DES3_BLOCK_SIZE, FALSE);
Packit Service e737ee
    while (k5_iov_cursor_get(&cursor, iblock)) {
Packit Service e737ee
        ret = EVP_EncryptUpdate(ctx, oblock, &olen, iblock, DES3_BLOCK_SIZE);
Packit Service e737ee
        if (!ret)
Packit Service e737ee
            break;
Packit Service e737ee
        k5_iov_cursor_put(&cursor, oblock);
Packit Service e737ee
    }
Packit Service e737ee
Packit Service e737ee
    if (ivec != NULL)
Packit Service e737ee
        memcpy(ivec->data, oblock, DES3_BLOCK_SIZE);
Packit Service e737ee
Packit Service e737ee
    EVP_CIPHER_CTX_free(ctx);
Packit Service e737ee
Packit Service e737ee
    zap(iblock, sizeof(iblock));
Packit Service e737ee
    zap(oblock, sizeof(oblock));
Packit Service e737ee
Packit Service e737ee
    if (ret != 1)
Packit Service e737ee
        return KRB5_CRYPTO_INTERNAL;
Packit Service e737ee
    return 0;
Packit Service e737ee
}
Packit Service e737ee
Packit Service e737ee
static krb5_error_code
Packit Service e737ee
k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data,
Packit Service e737ee
                size_t num_data)
Packit Service e737ee
{
Packit Service e737ee
    int ret, olen = DES3_BLOCK_SIZE;
Packit Service e737ee
    unsigned char iblock[DES3_BLOCK_SIZE], oblock[DES3_BLOCK_SIZE];
Packit Service e737ee
    struct iov_cursor cursor;
Packit Service e737ee
    EVP_CIPHER_CTX *ctx;
Packit Service e737ee
    krb5_boolean empty;
Packit Service e737ee
Packit Service e737ee
    ret = validate(key, ivec, data, num_data, &empty);
Packit Service e737ee
    if (ret != 0 || empty)
Packit Service e737ee
        return ret;
Packit Service e737ee
Packit Service e737ee
    ctx = EVP_CIPHER_CTX_new();
Packit Service e737ee
    if (ctx == NULL)
Packit Service e737ee
        return ENOMEM;
Packit Service e737ee
Packit Service e737ee
    ret = EVP_DecryptInit_ex(ctx, EVP_des_ede3_cbc(), NULL,
Packit Service e737ee
                             key->keyblock.contents,
Packit Service e737ee
                             (ivec) ? (unsigned char*)ivec->data : NULL);
Packit Service e737ee
    if (!ret) {
Packit Service e737ee
        EVP_CIPHER_CTX_free(ctx);
Packit Service e737ee
        return KRB5_CRYPTO_INTERNAL;
Packit Service e737ee
    }
Packit Service e737ee
Packit Service e737ee
    EVP_CIPHER_CTX_set_padding(ctx,0);
Packit Service e737ee
Packit Service e737ee
    k5_iov_cursor_init(&cursor, data, num_data, DES3_BLOCK_SIZE, FALSE);
Packit Service e737ee
    while (k5_iov_cursor_get(&cursor, iblock)) {
Packit Service e737ee
        ret = EVP_DecryptUpdate(ctx, oblock, &olen,
Packit Service e737ee
                                (unsigned char *)iblock, DES3_BLOCK_SIZE);
Packit Service e737ee
        if (!ret)
Packit Service e737ee
            break;
Packit Service e737ee
        k5_iov_cursor_put(&cursor, oblock);
Packit Service e737ee
    }
Packit Service e737ee
Packit Service e737ee
    if (ivec != NULL)
Packit Service e737ee
        memcpy(ivec->data, iblock, DES3_BLOCK_SIZE);
Packit Service e737ee
Packit Service e737ee
    EVP_CIPHER_CTX_free(ctx);
Packit Service e737ee
Packit Service e737ee
    zap(iblock, sizeof(iblock));
Packit Service e737ee
    zap(oblock, sizeof(oblock));
Packit Service e737ee
Packit Service e737ee
    if (ret != 1)
Packit Service e737ee
        return KRB5_CRYPTO_INTERNAL;
Packit Service e737ee
    return 0;
Packit Service e737ee
}
Packit Service e737ee
Packit Service e737ee
const struct krb5_enc_provider krb5int_enc_des3 = {
Packit Service e737ee
    DES3_BLOCK_SIZE,
Packit Service e737ee
    DES3_KEY_BYTES, DES3_KEY_SIZE,
Packit Service e737ee
    k5_des3_encrypt,
Packit Service e737ee
    k5_des3_decrypt,
Packit Service e737ee
    NULL,
Packit Service e737ee
    krb5int_des_init_state,
Packit Service e737ee
    krb5int_default_free_state
Packit Service e737ee
};