|
Packit Service |
e737ee |
/* -*- mode: c; c-basic-offset: 4; indent-tabs-mode: nil -*- */
|
|
Packit Service |
e737ee |
/* lib/crypto/openssl/enc_provider/des3.c */
|
|
Packit Service |
e737ee |
/*
|
|
Packit Service |
e737ee |
* Copyright (C) 2009 by the Massachusetts Institute of Technology.
|
|
Packit Service |
e737ee |
* All rights reserved.
|
|
Packit Service |
e737ee |
*
|
|
Packit Service |
e737ee |
* Export of this software from the United States of America may
|
|
Packit Service |
e737ee |
* require a specific license from the United States Government.
|
|
Packit Service |
e737ee |
* It is the responsibility of any person or organization contemplating
|
|
Packit Service |
e737ee |
* export to obtain such a license before exporting.
|
|
Packit Service |
e737ee |
*
|
|
Packit Service |
e737ee |
* WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
|
|
Packit Service |
e737ee |
* distribute this software and its documentation for any purpose and
|
|
Packit Service |
e737ee |
* without fee is hereby granted, provided that the above copyright
|
|
Packit Service |
e737ee |
* notice appear in all copies and that both that copyright notice and
|
|
Packit Service |
e737ee |
* this permission notice appear in supporting documentation, and that
|
|
Packit Service |
e737ee |
* the name of M.I.T. not be used in advertising or publicity pertaining
|
|
Packit Service |
e737ee |
* to distribution of the software without specific, written prior
|
|
Packit Service |
e737ee |
* permission. Furthermore if you modify this software you must label
|
|
Packit Service |
e737ee |
* your software as modified software and not distribute it in such a
|
|
Packit Service |
e737ee |
* fashion that it might be confused with the original M.I.T. software.
|
|
Packit Service |
e737ee |
* M.I.T. makes no representations about the suitability of
|
|
Packit Service |
e737ee |
* this software for any purpose. It is provided "as is" without express
|
|
Packit Service |
e737ee |
* or implied warranty.
|
|
Packit Service |
e737ee |
*/
|
|
Packit Service |
e737ee |
/*
|
|
Packit Service |
e737ee |
* Copyright (C) 1998 by the FundsXpress, INC.
|
|
Packit Service |
e737ee |
*
|
|
Packit Service |
e737ee |
* All rights reserved.
|
|
Packit Service |
e737ee |
*
|
|
Packit Service |
e737ee |
* Export of this software from the United States of America may require
|
|
Packit Service |
e737ee |
* a specific license from the United States Government. It is the
|
|
Packit Service |
e737ee |
* responsibility of any person or organization contemplating export to
|
|
Packit Service |
e737ee |
* obtain such a license before exporting.
|
|
Packit Service |
e737ee |
*
|
|
Packit Service |
e737ee |
* WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
|
|
Packit Service |
e737ee |
* distribute this software and its documentation for any purpose and
|
|
Packit Service |
e737ee |
* without fee is hereby granted, provided that the above copyright
|
|
Packit Service |
e737ee |
* notice appear in all copies and that both that copyright notice and
|
|
Packit Service |
e737ee |
* this permission notice appear in supporting documentation, and that
|
|
Packit Service |
e737ee |
* the name of FundsXpress. not be used in advertising or publicity pertaining
|
|
Packit Service |
e737ee |
* to distribution of the software without specific, written prior
|
|
Packit Service |
e737ee |
* permission. FundsXpress makes no representations about the suitability of
|
|
Packit Service |
e737ee |
* this software for any purpose. It is provided "as is" without express
|
|
Packit Service |
e737ee |
* or implied warranty.
|
|
Packit Service |
e737ee |
*
|
|
Packit Service |
e737ee |
* THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR
|
|
Packit Service |
e737ee |
* IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
|
|
Packit Service |
e737ee |
* WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
|
|
Packit Service |
e737ee |
*/
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
#include "crypto_int.h"
|
|
Packit Service |
e737ee |
#include <openssl/evp.h>
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
#define DES3_BLOCK_SIZE 8
|
|
Packit Service |
e737ee |
#define DES3_KEY_SIZE 24
|
|
Packit Service |
e737ee |
#define DES3_KEY_BYTES 21
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
static krb5_error_code
|
|
Packit Service |
e737ee |
validate(krb5_key key, const krb5_data *ivec, const krb5_crypto_iov *data,
|
|
Packit Service |
e737ee |
size_t num_data, krb5_boolean *empty)
|
|
Packit Service |
e737ee |
{
|
|
Packit Service |
e737ee |
size_t input_length = iov_total_length(data, num_data, FALSE);
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
if (key->keyblock.length != DES3_KEY_SIZE)
|
|
Packit Service |
e737ee |
return(KRB5_BAD_KEYSIZE);
|
|
Packit Service |
e737ee |
if ((input_length%DES3_BLOCK_SIZE) != 0)
|
|
Packit Service |
e737ee |
return(KRB5_BAD_MSIZE);
|
|
Packit Service |
e737ee |
if (ivec && (ivec->length != 8))
|
|
Packit Service |
e737ee |
return(KRB5_BAD_MSIZE);
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
*empty = (input_length == 0);
|
|
Packit Service |
e737ee |
return 0;
|
|
Packit Service |
e737ee |
}
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
static krb5_error_code
|
|
Packit Service |
e737ee |
k5_des3_encrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data,
|
|
Packit Service |
e737ee |
size_t num_data)
|
|
Packit Service |
e737ee |
{
|
|
Packit Service |
e737ee |
int ret, olen = DES3_BLOCK_SIZE;
|
|
Packit Service |
e737ee |
unsigned char iblock[DES3_BLOCK_SIZE], oblock[DES3_BLOCK_SIZE];
|
|
Packit Service |
e737ee |
struct iov_cursor cursor;
|
|
Packit Service |
e737ee |
EVP_CIPHER_CTX *ctx;
|
|
Packit Service |
e737ee |
krb5_boolean empty;
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
ret = validate(key, ivec, data, num_data, &empty);
|
|
Packit Service |
e737ee |
if (ret != 0 || empty)
|
|
Packit Service |
e737ee |
return ret;
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
ctx = EVP_CIPHER_CTX_new();
|
|
Packit Service |
e737ee |
if (ctx == NULL)
|
|
Packit Service |
e737ee |
return ENOMEM;
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
ret = EVP_EncryptInit_ex(ctx, EVP_des_ede3_cbc(), NULL,
|
|
Packit Service |
e737ee |
key->keyblock.contents,
|
|
Packit Service |
e737ee |
(ivec) ? (unsigned char*)ivec->data : NULL);
|
|
Packit Service |
e737ee |
if (!ret) {
|
|
Packit Service |
e737ee |
EVP_CIPHER_CTX_free(ctx);
|
|
Packit Service |
e737ee |
return KRB5_CRYPTO_INTERNAL;
|
|
Packit Service |
e737ee |
}
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
EVP_CIPHER_CTX_set_padding(ctx,0);
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
k5_iov_cursor_init(&cursor, data, num_data, DES3_BLOCK_SIZE, FALSE);
|
|
Packit Service |
e737ee |
while (k5_iov_cursor_get(&cursor, iblock)) {
|
|
Packit Service |
e737ee |
ret = EVP_EncryptUpdate(ctx, oblock, &olen, iblock, DES3_BLOCK_SIZE);
|
|
Packit Service |
e737ee |
if (!ret)
|
|
Packit Service |
e737ee |
break;
|
|
Packit Service |
e737ee |
k5_iov_cursor_put(&cursor, oblock);
|
|
Packit Service |
e737ee |
}
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
if (ivec != NULL)
|
|
Packit Service |
e737ee |
memcpy(ivec->data, oblock, DES3_BLOCK_SIZE);
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
EVP_CIPHER_CTX_free(ctx);
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
zap(iblock, sizeof(iblock));
|
|
Packit Service |
e737ee |
zap(oblock, sizeof(oblock));
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
if (ret != 1)
|
|
Packit Service |
e737ee |
return KRB5_CRYPTO_INTERNAL;
|
|
Packit Service |
e737ee |
return 0;
|
|
Packit Service |
e737ee |
}
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
static krb5_error_code
|
|
Packit Service |
e737ee |
k5_des3_decrypt(krb5_key key, const krb5_data *ivec, krb5_crypto_iov *data,
|
|
Packit Service |
e737ee |
size_t num_data)
|
|
Packit Service |
e737ee |
{
|
|
Packit Service |
e737ee |
int ret, olen = DES3_BLOCK_SIZE;
|
|
Packit Service |
e737ee |
unsigned char iblock[DES3_BLOCK_SIZE], oblock[DES3_BLOCK_SIZE];
|
|
Packit Service |
e737ee |
struct iov_cursor cursor;
|
|
Packit Service |
e737ee |
EVP_CIPHER_CTX *ctx;
|
|
Packit Service |
e737ee |
krb5_boolean empty;
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
ret = validate(key, ivec, data, num_data, &empty);
|
|
Packit Service |
e737ee |
if (ret != 0 || empty)
|
|
Packit Service |
e737ee |
return ret;
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
ctx = EVP_CIPHER_CTX_new();
|
|
Packit Service |
e737ee |
if (ctx == NULL)
|
|
Packit Service |
e737ee |
return ENOMEM;
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
ret = EVP_DecryptInit_ex(ctx, EVP_des_ede3_cbc(), NULL,
|
|
Packit Service |
e737ee |
key->keyblock.contents,
|
|
Packit Service |
e737ee |
(ivec) ? (unsigned char*)ivec->data : NULL);
|
|
Packit Service |
e737ee |
if (!ret) {
|
|
Packit Service |
e737ee |
EVP_CIPHER_CTX_free(ctx);
|
|
Packit Service |
e737ee |
return KRB5_CRYPTO_INTERNAL;
|
|
Packit Service |
e737ee |
}
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
EVP_CIPHER_CTX_set_padding(ctx,0);
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
k5_iov_cursor_init(&cursor, data, num_data, DES3_BLOCK_SIZE, FALSE);
|
|
Packit Service |
e737ee |
while (k5_iov_cursor_get(&cursor, iblock)) {
|
|
Packit Service |
e737ee |
ret = EVP_DecryptUpdate(ctx, oblock, &olen,
|
|
Packit Service |
e737ee |
(unsigned char *)iblock, DES3_BLOCK_SIZE);
|
|
Packit Service |
e737ee |
if (!ret)
|
|
Packit Service |
e737ee |
break;
|
|
Packit Service |
e737ee |
k5_iov_cursor_put(&cursor, oblock);
|
|
Packit Service |
e737ee |
}
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
if (ivec != NULL)
|
|
Packit Service |
e737ee |
memcpy(ivec->data, iblock, DES3_BLOCK_SIZE);
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
EVP_CIPHER_CTX_free(ctx);
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
zap(iblock, sizeof(iblock));
|
|
Packit Service |
e737ee |
zap(oblock, sizeof(oblock));
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
if (ret != 1)
|
|
Packit Service |
e737ee |
return KRB5_CRYPTO_INTERNAL;
|
|
Packit Service |
e737ee |
return 0;
|
|
Packit Service |
e737ee |
}
|
|
Packit Service |
e737ee |
|
|
Packit Service |
e737ee |
const struct krb5_enc_provider krb5int_enc_des3 = {
|
|
Packit Service |
e737ee |
DES3_BLOCK_SIZE,
|
|
Packit Service |
e737ee |
DES3_KEY_BYTES, DES3_KEY_SIZE,
|
|
Packit Service |
e737ee |
k5_des3_encrypt,
|
|
Packit Service |
e737ee |
k5_des3_decrypt,
|
|
Packit Service |
e737ee |
NULL,
|
|
Packit Service |
e737ee |
krb5int_des_init_state,
|
|
Packit Service |
e737ee |
krb5int_default_free_state
|
|
Packit Service |
e737ee |
};
|