|
Packit |
c4476c |
/*
|
|
Packit |
c4476c |
* Copyright 2018 The OpenSSL Project Authors. All Rights Reserved.
|
|
Packit |
c4476c |
* Copyright (c) 2018, Oracle and/or its affiliates. All rights reserved.
|
|
Packit |
c4476c |
*
|
|
Packit |
c4476c |
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
|
Packit |
c4476c |
* this file except in compliance with the License. You can obtain a copy
|
|
Packit |
c4476c |
* in the file LICENSE in the source distribution or at
|
|
Packit |
c4476c |
* https://www.openssl.org/source/license.html
|
|
Packit |
c4476c |
*/
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
#include <stdio.h>
|
|
Packit |
c4476c |
#include <stdlib.h>
|
|
Packit |
c4476c |
#include "internal/cryptlib.h"
|
|
Packit |
c4476c |
#include <openssl/engine.h>
|
|
Packit |
c4476c |
#include <openssl/evp.h>
|
|
Packit |
c4476c |
#include <openssl/x509v3.h>
|
|
Packit |
c4476c |
#include <openssl/kdf.h>
|
|
Packit |
c4476c |
#include "crypto/asn1.h"
|
|
Packit |
c4476c |
#include "crypto/evp.h"
|
|
Packit |
c4476c |
#include "internal/numbers.h"
|
|
Packit |
c4476c |
#include "evp_local.h"
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
typedef int sk_cmp_fn_type(const char *const *a, const char *const *b);
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
/* This array needs to be in order of NIDs */
|
|
Packit |
c4476c |
static const EVP_KDF_METHOD *standard_methods[] = {
|
|
Packit |
c4476c |
&pbkdf2_kdf_meth,
|
|
Packit |
c4476c |
#ifndef OPENSSL_NO_SCRYPT
|
|
Packit |
c4476c |
&scrypt_kdf_meth,
|
|
Packit |
c4476c |
#endif
|
|
Packit |
c4476c |
&tls1_prf_kdf_meth,
|
|
Packit |
c4476c |
&hkdf_kdf_meth,
|
|
Packit |
c4476c |
&sshkdf_kdf_meth,
|
|
Packit |
c4476c |
&kb_kdf_meth,
|
|
Packit |
c4476c |
&krb5kdf_kdf_meth,
|
|
Packit |
c4476c |
&ss_kdf_meth
|
|
Packit |
c4476c |
};
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
DECLARE_OBJ_BSEARCH_CMP_FN(const EVP_KDF_METHOD *, const EVP_KDF_METHOD *,
|
|
Packit |
c4476c |
kmeth);
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
static int kmeth_cmp(const EVP_KDF_METHOD *const *a,
|
|
Packit |
c4476c |
const EVP_KDF_METHOD *const *b)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
return ((*a)->type - (*b)->type);
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
IMPLEMENT_OBJ_BSEARCH_CMP_FN(const EVP_KDF_METHOD *, const EVP_KDF_METHOD *,
|
|
Packit |
c4476c |
kmeth);
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
static const EVP_KDF_METHOD *kdf_meth_find(int type)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
EVP_KDF_METHOD tmp;
|
|
Packit |
c4476c |
const EVP_KDF_METHOD *t = &tmp, **ret;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
tmp.type = type;
|
|
Packit |
c4476c |
ret = OBJ_bsearch_kmeth(&t, standard_methods,
|
|
Packit |
c4476c |
OSSL_NELEM(standard_methods));
|
|
Packit |
c4476c |
if (ret == NULL || *ret == NULL)
|
|
Packit |
c4476c |
return NULL;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
return *ret;
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
EVP_KDF_CTX *EVP_KDF_CTX_new_id(int id)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
EVP_KDF_CTX *ret;
|
|
Packit |
c4476c |
const EVP_KDF_METHOD *kmeth;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
kmeth = kdf_meth_find(id);
|
|
Packit |
c4476c |
if (kmeth == NULL) {
|
|
Packit |
c4476c |
EVPerr(EVP_F_EVP_KDF_CTX_NEW_ID, EVP_R_UNSUPPORTED_ALGORITHM);
|
|
Packit |
c4476c |
return NULL;
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
ret = OPENSSL_zalloc(sizeof(*ret));
|
|
Packit |
c4476c |
if (ret == NULL) {
|
|
Packit |
c4476c |
EVPerr(EVP_F_EVP_KDF_CTX_NEW_ID, ERR_R_MALLOC_FAILURE);
|
|
Packit |
c4476c |
return NULL;
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
if (kmeth->new != NULL && (ret->impl = kmeth->new()) == NULL) {
|
|
Packit |
c4476c |
EVP_KDF_CTX_free(ret);
|
|
Packit |
c4476c |
return NULL;
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
ret->kmeth = kmeth;
|
|
Packit |
c4476c |
return ret;
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
void EVP_KDF_CTX_free(EVP_KDF_CTX *ctx)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
if (ctx == NULL)
|
|
Packit |
c4476c |
return;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
ctx->kmeth->free(ctx->impl);
|
|
Packit |
c4476c |
OPENSSL_free(ctx);
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
void EVP_KDF_reset(EVP_KDF_CTX *ctx)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
if (ctx == NULL)
|
|
Packit |
c4476c |
return;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
if (ctx->kmeth->reset != NULL)
|
|
Packit |
c4476c |
ctx->kmeth->reset(ctx->impl);
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
int EVP_KDF_ctrl(EVP_KDF_CTX *ctx, int cmd, ...)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
int ret;
|
|
Packit |
c4476c |
va_list args;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
va_start(args, cmd);
|
|
Packit |
c4476c |
ret = EVP_KDF_vctrl(ctx, cmd, args);
|
|
Packit |
c4476c |
va_end(args);
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
if (ret == -2)
|
|
Packit |
c4476c |
EVPerr(EVP_F_EVP_KDF_CTRL, EVP_R_COMMAND_NOT_SUPPORTED);
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
return ret;
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
int EVP_KDF_vctrl(EVP_KDF_CTX *ctx, int cmd, va_list args)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
if (ctx == NULL)
|
|
Packit |
c4476c |
return 0;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
return ctx->kmeth->ctrl(ctx->impl, cmd, args);
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
int EVP_KDF_ctrl_str(EVP_KDF_CTX *ctx, const char *type, const char *value)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
int ret;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
if (ctx == NULL)
|
|
Packit |
c4476c |
return 0;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
if (ctx->kmeth->ctrl_str == NULL) {
|
|
Packit |
c4476c |
EVPerr(EVP_F_EVP_KDF_CTRL_STR, EVP_R_COMMAND_NOT_SUPPORTED);
|
|
Packit |
c4476c |
return -2;
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
ret = ctx->kmeth->ctrl_str(ctx->impl, type, value);
|
|
Packit |
c4476c |
if (ret == -2)
|
|
Packit |
c4476c |
EVPerr(EVP_F_EVP_KDF_CTRL_STR, EVP_R_COMMAND_NOT_SUPPORTED);
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
return ret;
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
size_t EVP_KDF_size(EVP_KDF_CTX *ctx)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
if (ctx == NULL)
|
|
Packit |
c4476c |
return 0;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
if (ctx->kmeth->size == NULL)
|
|
Packit |
c4476c |
return SIZE_MAX;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
return ctx->kmeth->size(ctx->impl);
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
int EVP_KDF_derive(EVP_KDF_CTX *ctx, unsigned char *key, size_t keylen)
|
|
Packit |
c4476c |
{
|
|
Packit |
c4476c |
if (ctx == NULL)
|
|
Packit |
c4476c |
return 0;
|
|
Packit |
c4476c |
|
|
Packit |
c4476c |
return ctx->kmeth->derive(ctx->impl, key, keylen);
|
|
Packit |
c4476c |
}
|
|
Packit |
c4476c |
|