Blame include/libssh/crypto.h

Packit Service 31306d
/*
Packit Service 31306d
 * This file is part of the SSH Library
Packit Service 31306d
 *
Packit Service 31306d
 * Copyright (c) 2003-2009 by Aris Adamantiadis
Packit Service 31306d
 *
Packit Service 31306d
 * This library is free software; you can redistribute it and/or
Packit Service 31306d
 * modify it under the terms of the GNU Lesser General Public
Packit Service 31306d
 * License as published by the Free Software Foundation; either
Packit Service 31306d
 * version 2.1 of the License, or (at your option) any later version.
Packit Service 31306d
 *
Packit Service 31306d
 * This library is distributed in the hope that it will be useful,
Packit Service 31306d
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit Service 31306d
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Packit Service 31306d
 * Lesser General Public License for more details.
Packit Service 31306d
 *
Packit Service 31306d
 * You should have received a copy of the GNU Lesser General Public
Packit Service 31306d
 * License along with this library; if not, write to the Free Software
Packit Service 31306d
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
Packit Service 31306d
 */
Packit Service 31306d
Packit Service 31306d
/*
Packit Service 31306d
 * crypto.h is an include file for internal cryptographic structures of libssh
Packit Service 31306d
 */
Packit Service 31306d
Packit Service 31306d
#ifndef _CRYPTO_H_
Packit Service 31306d
#define _CRYPTO_H_
Packit Service 31306d
Packit Service 31306d
#include <stdbool.h>
Packit Service 31306d
#include "config.h"
Packit Service 31306d
Packit Service 31306d
#ifdef HAVE_LIBGCRYPT
Packit Service 31306d
#include <gcrypt.h>
Packit Service 31306d
#elif defined(HAVE_LIBMBEDCRYPTO)
Packit Service 31306d
#include <mbedtls/gcm.h>
Packit Service 31306d
#endif
Packit Service 31306d
#include "libssh/wrapper.h"
Packit Service 31306d
Packit Service 31306d
#ifdef cbc_encrypt
Packit Service 31306d
#undef cbc_encrypt
Packit Service 31306d
#endif
Packit Service 31306d
#ifdef cbc_decrypt
Packit Service 31306d
#undef cbc_decrypt
Packit Service 31306d
#endif
Packit Service 31306d
Packit Service 31306d
#ifdef HAVE_OPENSSL_ECDH_H
Packit Service 31306d
#include <openssl/ecdh.h>
Packit Service 31306d
#endif
Packit Service 31306d
#include "libssh/dh.h"
Packit Service 31306d
#include "libssh/ecdh.h"
Packit Service 31306d
#include "libssh/kex.h"
Packit Service 31306d
#include "libssh/curve25519.h"
Packit Service 31306d
Packit Service 31306d
#define DIGEST_MAX_LEN 64
Packit Service 31306d
Packit Service 31306d
#define AES_GCM_TAGLEN 16
Packit Service 31306d
#define AES_GCM_IVLEN  12
Packit Service 31306d
Packit Service 31306d
enum ssh_key_exchange_e {
Packit Service 31306d
  /* diffie-hellman-group1-sha1 */
Packit Service 31306d
  SSH_KEX_DH_GROUP1_SHA1=1,
Packit Service 31306d
  /* diffie-hellman-group14-sha1 */
Packit Service 31306d
  SSH_KEX_DH_GROUP14_SHA1,
Packit Service 31306d
#ifdef WITH_GEX
Packit Service 31306d
  /* diffie-hellman-group-exchange-sha1 */
Packit Service 31306d
  SSH_KEX_DH_GEX_SHA1,
Packit Service 31306d
  /* diffie-hellman-group-exchange-sha256 */
Packit Service 31306d
  SSH_KEX_DH_GEX_SHA256,
Packit Service 31306d
#endif /* WITH_GEX */
Packit Service 31306d
  /* ecdh-sha2-nistp256 */
Packit Service 31306d
  SSH_KEX_ECDH_SHA2_NISTP256,
Packit Service 31306d
  /* ecdh-sha2-nistp384 */
Packit Service 31306d
  SSH_KEX_ECDH_SHA2_NISTP384,
Packit Service 31306d
  /* ecdh-sha2-nistp521 */
Packit Service 31306d
  SSH_KEX_ECDH_SHA2_NISTP521,
Packit Service 31306d
  /* curve25519-sha256@libssh.org */
Packit Service 31306d
  SSH_KEX_CURVE25519_SHA256_LIBSSH_ORG,
Packit Service 31306d
  /* curve25519-sha256 */
Packit Service 31306d
  SSH_KEX_CURVE25519_SHA256,
Packit Service 31306d
  /* diffie-hellman-group16-sha512 */
Packit Service 31306d
  SSH_KEX_DH_GROUP16_SHA512,
Packit Service 31306d
  /* diffie-hellman-group18-sha512 */
Packit Service 31306d
  SSH_KEX_DH_GROUP18_SHA512,
Packit Service 31306d
  /* diffie-hellman-group14-sha256 */
Packit Service 31306d
  SSH_KEX_DH_GROUP14_SHA256,
Packit Service 31306d
};
Packit Service 31306d
Packit Service 31306d
enum ssh_cipher_e {
Packit Service 31306d
    SSH_NO_CIPHER=0,
Packit Service 31306d
#ifdef WITH_BLOWFISH_CIPHER
Packit Service 31306d
    SSH_BLOWFISH_CBC,
Packit Service 31306d
#endif /* WITH_BLOWFISH_CIPHER */
Packit Service 31306d
    SSH_3DES_CBC,
Packit Service 31306d
    SSH_AES128_CBC,
Packit Service 31306d
    SSH_AES192_CBC,
Packit Service 31306d
    SSH_AES256_CBC,
Packit Service 31306d
    SSH_AES128_CTR,
Packit Service 31306d
    SSH_AES192_CTR,
Packit Service 31306d
    SSH_AES256_CTR,
Packit Service 31306d
    SSH_AEAD_AES128_GCM,
Packit Service 31306d
    SSH_AEAD_AES256_GCM,
Packit Service 31306d
    SSH_AEAD_CHACHA20_POLY1305
Packit Service 31306d
};
Packit Service 31306d
Packit Service 31306d
struct dh_ctx;
Packit Service 31306d
Packit Service 31306d
struct ssh_crypto_struct {
Packit Service 31306d
    bignum shared_secret;
Packit Service 31306d
    struct dh_ctx *dh_ctx;
Packit Service 31306d
#ifdef WITH_GEX
Packit Service 31306d
    size_t dh_pmin; size_t dh_pn; size_t dh_pmax; /* preferred group parameters */
Packit Service 31306d
#endif /* WITH_GEX */
Packit Service 31306d
#ifdef HAVE_ECDH
Packit Service 31306d
#ifdef HAVE_OPENSSL_ECC
Packit Service 31306d
    EC_KEY *ecdh_privkey;
Packit Service 31306d
#elif defined HAVE_GCRYPT_ECC
Packit Service 31306d
    gcry_sexp_t ecdh_privkey;
Packit Service 31306d
#elif defined HAVE_LIBMBEDCRYPTO
Packit Service 31306d
    mbedtls_ecp_keypair *ecdh_privkey;
Packit Service 31306d
#endif
Packit Service 31306d
    ssh_string ecdh_client_pubkey;
Packit Service 31306d
    ssh_string ecdh_server_pubkey;
Packit Service 31306d
#endif
Packit Service 31306d
#ifdef HAVE_CURVE25519
Packit Service 31306d
    ssh_curve25519_privkey curve25519_privkey;
Packit Service 31306d
    ssh_curve25519_pubkey curve25519_client_pubkey;
Packit Service 31306d
    ssh_curve25519_pubkey curve25519_server_pubkey;
Packit Service 31306d
#endif
Packit Service 31306d
    ssh_string dh_server_signature; /* information used by dh_handshake. */
Packit Service 31306d
    size_t digest_len; /* len of the two fields below */
Packit Service 31306d
    unsigned char *session_id;
Packit Service 31306d
    unsigned char *secret_hash; /* Secret hash is same as session id until re-kex */
Packit Service 31306d
    unsigned char *encryptIV;
Packit Service 31306d
    unsigned char *decryptIV;
Packit Service 31306d
    unsigned char *decryptkey;
Packit Service 31306d
    unsigned char *encryptkey;
Packit Service 31306d
    unsigned char *encryptMAC;
Packit Service 31306d
    unsigned char *decryptMAC;
Packit Service 31306d
    unsigned char hmacbuf[DIGEST_MAX_LEN];
Packit Service 31306d
    struct ssh_cipher_struct *in_cipher, *out_cipher; /* the cipher structures/objects */
Packit Service 31306d
    enum ssh_hmac_e in_hmac, out_hmac; /* the MAC algorithms used */
Packit Service 31306d
    bool in_hmac_etm, out_hmac_etm; /* Whether EtM mode is used or not */
Packit Service 31306d
Packit Service 31306d
    ssh_key server_pubkey;
Packit Service 31306d
    int do_compress_out; /* idem */
Packit Service 31306d
    int do_compress_in; /* don't set them, set the option instead */
Packit Service 31306d
    int delayed_compress_in; /* Use of zlib@openssh.org */
Packit Service 31306d
    int delayed_compress_out;
Packit Service 31306d
    void *compress_out_ctx; /* don't touch it */
Packit Service 31306d
    void *compress_in_ctx; /* really, don't */
Packit Service 31306d
    /* kex sent by server, client, and mutually elected methods */
Packit Service 31306d
    struct ssh_kex_struct server_kex;
Packit Service 31306d
    struct ssh_kex_struct client_kex;
Packit Service 31306d
    char *kex_methods[SSH_KEX_METHODS];
Packit Service 31306d
    enum ssh_key_exchange_e kex_type;
Packit Service 31306d
    enum ssh_kdf_digest digest_type; /* Digest type for session keys derivation */
Packit Service 31306d
    enum ssh_crypto_direction_e used; /* Is this crypto still used for either of directions? */
Packit Service 31306d
};
Packit Service 31306d
Packit Service 31306d
struct ssh_cipher_struct {
Packit Service 31306d
    const char *name; /* ssh name of the algorithm */
Packit Service 31306d
    unsigned int blocksize; /* blocksize of the algo */
Packit Service 31306d
    enum ssh_cipher_e ciphertype;
Packit Service 31306d
    uint32_t lenfield_blocksize; /* blocksize of the packet length field */
Packit Service 31306d
    size_t keylen; /* length of the key structure */
Packit Service 31306d
#ifdef HAVE_LIBGCRYPT
Packit Service 31306d
    gcry_cipher_hd_t *key;
Packit Service 31306d
    unsigned char last_iv[AES_GCM_IVLEN];
Packit Service 31306d
#elif defined HAVE_LIBCRYPTO
Packit Service 31306d
    struct ssh_3des_key_schedule *des3_key;
Packit Service 31306d
    struct ssh_aes_key_schedule *aes_key;
Packit Service 31306d
    const EVP_CIPHER *cipher;
Packit Service 31306d
    EVP_CIPHER_CTX *ctx;
Packit Service 31306d
#elif defined HAVE_LIBMBEDCRYPTO
Packit Service 31306d
    mbedtls_cipher_context_t encrypt_ctx;
Packit Service 31306d
    mbedtls_cipher_context_t decrypt_ctx;
Packit Service 31306d
    mbedtls_cipher_type_t type;
Packit Service 31306d
#ifdef MBEDTLS_GCM_C
Packit Service 31306d
    mbedtls_gcm_context gcm_ctx;
Packit Service 31306d
    unsigned char last_iv[AES_GCM_IVLEN];
Packit Service 31306d
#endif /* MBEDTLS_GCM_C */
Packit Service 31306d
#endif
Packit Service 31306d
    struct chacha20_poly1305_keysched *chacha20_schedule;
Packit Service 31306d
    unsigned int keysize; /* bytes of key used. != keylen */
Packit Service 31306d
    size_t tag_size; /* overhead required for tag */
Packit Service 31306d
    /* Counters for rekeying initialization */
Packit Service 31306d
    uint32_t packets;
Packit Service 31306d
    uint64_t blocks;
Packit Service 31306d
    /* Rekeying limit for the cipher or manually enforced */
Packit Service 31306d
    uint64_t max_blocks;
Packit Service 31306d
    /* sets the new key for immediate use */
Packit Service 31306d
    int (*set_encrypt_key)(struct ssh_cipher_struct *cipher, void *key, void *IV);
Packit Service 31306d
    int (*set_decrypt_key)(struct ssh_cipher_struct *cipher, void *key, void *IV);
Packit Service 31306d
    void (*encrypt)(struct ssh_cipher_struct *cipher,
Packit Service 31306d
                    void *in,
Packit Service 31306d
                    void *out,
Packit Service 31306d
                    size_t len);
Packit Service 31306d
    void (*decrypt)(struct ssh_cipher_struct *cipher,
Packit Service 31306d
                    void *in,
Packit Service 31306d
                    void *out,
Packit Service 31306d
                    size_t len);
Packit Service 31306d
    void (*aead_encrypt)(struct ssh_cipher_struct *cipher, void *in, void *out,
Packit Service 31306d
        size_t len, uint8_t *mac, uint64_t seq);
Packit Service 31306d
    int (*aead_decrypt_length)(struct ssh_cipher_struct *cipher, void *in,
Packit Service 31306d
        uint8_t *out, size_t len, uint64_t seq);
Packit Service 31306d
    int (*aead_decrypt)(struct ssh_cipher_struct *cipher, void *complete_packet, uint8_t *out,
Packit Service 31306d
        size_t encrypted_size, uint64_t seq);
Packit Service 31306d
    void (*cleanup)(struct ssh_cipher_struct *cipher);
Packit Service 31306d
};
Packit Service 31306d
Packit Service 31306d
const struct ssh_cipher_struct *ssh_get_chacha20poly1305_cipher(void);
Packit Service 31306d
int sshkdf_derive_key(struct ssh_crypto_struct *crypto,
Packit Service 31306d
                      unsigned char *key, size_t key_len,
Packit Service 31306d
                      int key_type, unsigned char *output,
Packit Service 31306d
                      size_t requested_len);
Packit Service 31306d
Packit Service 31306d
#endif /* _CRYPTO_H_ */