/src/openssl/crypto/ecdh/ech_lib.c
Line | Count | Source (jump to first uncovered line) |
1 | | /* crypto/ecdh/ech_lib.c */ |
2 | | /* ==================================================================== |
3 | | * Copyright 2002 Sun Microsystems, Inc. ALL RIGHTS RESERVED. |
4 | | * |
5 | | * The Elliptic Curve Public-Key Crypto Library (ECC Code) included |
6 | | * herein is developed by SUN MICROSYSTEMS, INC., and is contributed |
7 | | * to the OpenSSL project. |
8 | | * |
9 | | * The ECC Code is licensed pursuant to the OpenSSL open source |
10 | | * license provided below. |
11 | | * |
12 | | * The ECDH software is originally written by Douglas Stebila of |
13 | | * Sun Microsystems Laboratories. |
14 | | * |
15 | | */ |
16 | | /* ==================================================================== |
17 | | * Copyright (c) 1998-2003 The OpenSSL Project. All rights reserved. |
18 | | * |
19 | | * Redistribution and use in source and binary forms, with or without |
20 | | * modification, are permitted provided that the following conditions |
21 | | * are met: |
22 | | * |
23 | | * 1. Redistributions of source code must retain the above copyright |
24 | | * notice, this list of conditions and the following disclaimer. |
25 | | * |
26 | | * 2. Redistributions in binary form must reproduce the above copyright |
27 | | * notice, this list of conditions and the following disclaimer in |
28 | | * the documentation and/or other materials provided with the |
29 | | * distribution. |
30 | | * |
31 | | * 3. All advertising materials mentioning features or use of this |
32 | | * software must display the following acknowledgment: |
33 | | * "This product includes software developed by the OpenSSL Project |
34 | | * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)" |
35 | | * |
36 | | * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to |
37 | | * endorse or promote products derived from this software without |
38 | | * prior written permission. For written permission, please contact |
39 | | * openssl-core@OpenSSL.org. |
40 | | * |
41 | | * 5. Products derived from this software may not be called "OpenSSL" |
42 | | * nor may "OpenSSL" appear in their names without prior written |
43 | | * permission of the OpenSSL Project. |
44 | | * |
45 | | * 6. Redistributions of any form whatsoever must retain the following |
46 | | * acknowledgment: |
47 | | * "This product includes software developed by the OpenSSL Project |
48 | | * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)" |
49 | | * |
50 | | * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY |
51 | | * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
52 | | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR |
53 | | * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR |
54 | | * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
55 | | * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT |
56 | | * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; |
57 | | * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) |
58 | | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, |
59 | | * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) |
60 | | * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED |
61 | | * OF THE POSSIBILITY OF SUCH DAMAGE. |
62 | | * ==================================================================== |
63 | | * |
64 | | * This product includes cryptographic software written by Eric Young |
65 | | * (eay@cryptsoft.com). This product includes software written by Tim |
66 | | * Hudson (tjh@cryptsoft.com). |
67 | | * |
68 | | */ |
69 | | |
70 | | #include "ech_locl.h" |
71 | | #include <string.h> |
72 | | #ifndef OPENSSL_NO_ENGINE |
73 | | # include <openssl/engine.h> |
74 | | #endif |
75 | | #include <openssl/err.h> |
76 | | #ifdef OPENSSL_FIPS |
77 | | # include <openssl/fips.h> |
78 | | #endif |
79 | | |
80 | | const char ECDH_version[] = "ECDH" OPENSSL_VERSION_PTEXT; |
81 | | |
82 | | static const ECDH_METHOD *default_ECDH_method = NULL; |
83 | | |
84 | | static void *ecdh_data_new(void); |
85 | | static void *ecdh_data_dup(void *); |
86 | | static void ecdh_data_free(void *); |
87 | | |
88 | | void ECDH_set_default_method(const ECDH_METHOD *meth) |
89 | 0 | { |
90 | 0 | default_ECDH_method = meth; |
91 | 0 | } |
92 | | |
93 | | const ECDH_METHOD *ECDH_get_default_method(void) |
94 | 0 | { |
95 | 0 | if (!default_ECDH_method) { |
96 | | #ifdef OPENSSL_FIPS |
97 | | if (FIPS_mode()) |
98 | | return FIPS_ecdh_openssl(); |
99 | | else |
100 | | return ECDH_OpenSSL(); |
101 | | #else |
102 | 0 | default_ECDH_method = ECDH_OpenSSL(); |
103 | 0 | #endif |
104 | 0 | } |
105 | 0 | return default_ECDH_method; |
106 | 0 | } |
107 | | |
108 | | int ECDH_set_method(EC_KEY *eckey, const ECDH_METHOD *meth) |
109 | 0 | { |
110 | 0 | ECDH_DATA *ecdh; |
111 | |
|
112 | 0 | ecdh = ecdh_check(eckey); |
113 | |
|
114 | 0 | if (ecdh == NULL) |
115 | 0 | return 0; |
116 | | |
117 | | #if 0 |
118 | | mtmp = ecdh->meth; |
119 | | if (mtmp->finish) |
120 | | mtmp->finish(eckey); |
121 | | #endif |
122 | 0 | #ifndef OPENSSL_NO_ENGINE |
123 | 0 | if (ecdh->engine) { |
124 | 0 | ENGINE_finish(ecdh->engine); |
125 | 0 | ecdh->engine = NULL; |
126 | 0 | } |
127 | 0 | #endif |
128 | 0 | ecdh->meth = meth; |
129 | | #if 0 |
130 | | if (meth->init) |
131 | | meth->init(eckey); |
132 | | #endif |
133 | 0 | return 1; |
134 | 0 | } |
135 | | |
136 | | static ECDH_DATA *ECDH_DATA_new_method(ENGINE *engine) |
137 | 0 | { |
138 | 0 | ECDH_DATA *ret; |
139 | |
|
140 | 0 | ret = (ECDH_DATA *)OPENSSL_malloc(sizeof(ECDH_DATA)); |
141 | 0 | if (ret == NULL) { |
142 | 0 | ECDHerr(ECDH_F_ECDH_DATA_NEW_METHOD, ERR_R_MALLOC_FAILURE); |
143 | 0 | return (NULL); |
144 | 0 | } |
145 | | |
146 | 0 | ret->init = NULL; |
147 | |
|
148 | 0 | ret->meth = ECDH_get_default_method(); |
149 | 0 | ret->engine = engine; |
150 | 0 | #ifndef OPENSSL_NO_ENGINE |
151 | 0 | if (!ret->engine) |
152 | 0 | ret->engine = ENGINE_get_default_ECDH(); |
153 | 0 | if (ret->engine) { |
154 | 0 | ret->meth = ENGINE_get_ECDH(ret->engine); |
155 | 0 | if (!ret->meth) { |
156 | 0 | ECDHerr(ECDH_F_ECDH_DATA_NEW_METHOD, ERR_R_ENGINE_LIB); |
157 | 0 | ENGINE_finish(ret->engine); |
158 | 0 | OPENSSL_free(ret); |
159 | 0 | return NULL; |
160 | 0 | } |
161 | 0 | } |
162 | 0 | #endif |
163 | | |
164 | 0 | ret->flags = ret->meth->flags; |
165 | 0 | CRYPTO_new_ex_data(CRYPTO_EX_INDEX_ECDH, ret, &ret->ex_data); |
166 | | #if 0 |
167 | | if ((ret->meth->init != NULL) && !ret->meth->init(ret)) { |
168 | | CRYPTO_free_ex_data(CRYPTO_EX_INDEX_ECDH, ret, &ret->ex_data); |
169 | | OPENSSL_free(ret); |
170 | | ret = NULL; |
171 | | } |
172 | | #endif |
173 | 0 | return (ret); |
174 | 0 | } |
175 | | |
176 | | static void *ecdh_data_new(void) |
177 | 0 | { |
178 | 0 | return (void *)ECDH_DATA_new_method(NULL); |
179 | 0 | } |
180 | | |
181 | | static void *ecdh_data_dup(void *data) |
182 | 0 | { |
183 | 0 | ECDH_DATA *r = (ECDH_DATA *)data; |
184 | | |
185 | | /* XXX: dummy operation */ |
186 | 0 | if (r == NULL) |
187 | 0 | return NULL; |
188 | | |
189 | 0 | return (void *)ecdh_data_new(); |
190 | 0 | } |
191 | | |
192 | | void ecdh_data_free(void *data) |
193 | 0 | { |
194 | 0 | ECDH_DATA *r = (ECDH_DATA *)data; |
195 | |
|
196 | 0 | #ifndef OPENSSL_NO_ENGINE |
197 | 0 | if (r->engine) |
198 | 0 | ENGINE_finish(r->engine); |
199 | 0 | #endif |
200 | |
|
201 | 0 | CRYPTO_free_ex_data(CRYPTO_EX_INDEX_ECDH, r, &r->ex_data); |
202 | |
|
203 | 0 | OPENSSL_cleanse((void *)r, sizeof(ECDH_DATA)); |
204 | |
|
205 | 0 | OPENSSL_free(r); |
206 | 0 | } |
207 | | |
208 | | ECDH_DATA *ecdh_check(EC_KEY *key) |
209 | 0 | { |
210 | 0 | ECDH_DATA *ecdh_data; |
211 | |
|
212 | 0 | void *data = EC_KEY_get_key_method_data(key, ecdh_data_dup, |
213 | 0 | ecdh_data_free, ecdh_data_free); |
214 | 0 | if (data == NULL) { |
215 | 0 | ecdh_data = (ECDH_DATA *)ecdh_data_new(); |
216 | 0 | if (ecdh_data == NULL) |
217 | 0 | return NULL; |
218 | 0 | data = EC_KEY_insert_key_method_data(key, (void *)ecdh_data, |
219 | 0 | ecdh_data_dup, ecdh_data_free, |
220 | 0 | ecdh_data_free); |
221 | 0 | if (data != NULL) { |
222 | | /* |
223 | | * Another thread raced us to install the key_method data and |
224 | | * won. |
225 | | */ |
226 | 0 | ecdh_data_free(ecdh_data); |
227 | 0 | ecdh_data = (ECDH_DATA *)data; |
228 | 0 | } else if (EC_KEY_get_key_method_data(key, ecdh_data_dup, |
229 | 0 | ecdh_data_free, |
230 | 0 | ecdh_data_free) != ecdh_data) { |
231 | | /* Or an out of memory error in EC_KEY_insert_key_method_data. */ |
232 | 0 | ecdh_data_free(ecdh_data); |
233 | 0 | return NULL; |
234 | 0 | } |
235 | 0 | } else { |
236 | 0 | ecdh_data = (ECDH_DATA *)data; |
237 | 0 | } |
238 | | #ifdef OPENSSL_FIPS |
239 | | if (FIPS_mode() && !(ecdh_data->flags & ECDH_FLAG_FIPS_METHOD) |
240 | | && !(EC_KEY_get_flags(key) & EC_FLAG_NON_FIPS_ALLOW)) { |
241 | | ECDHerr(ECDH_F_ECDH_CHECK, ECDH_R_NON_FIPS_METHOD); |
242 | | return NULL; |
243 | | } |
244 | | #endif |
245 | | |
246 | 0 | return ecdh_data; |
247 | 0 | } |
248 | | |
249 | | int ECDH_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func, |
250 | | CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func) |
251 | 0 | { |
252 | 0 | return CRYPTO_get_ex_new_index(CRYPTO_EX_INDEX_ECDH, argl, argp, |
253 | 0 | new_func, dup_func, free_func); |
254 | 0 | } |
255 | | |
256 | | int ECDH_set_ex_data(EC_KEY *d, int idx, void *arg) |
257 | 0 | { |
258 | 0 | ECDH_DATA *ecdh; |
259 | 0 | ecdh = ecdh_check(d); |
260 | 0 | if (ecdh == NULL) |
261 | 0 | return 0; |
262 | 0 | return (CRYPTO_set_ex_data(&ecdh->ex_data, idx, arg)); |
263 | 0 | } |
264 | | |
265 | | void *ECDH_get_ex_data(EC_KEY *d, int idx) |
266 | 0 | { |
267 | 0 | ECDH_DATA *ecdh; |
268 | 0 | ecdh = ecdh_check(d); |
269 | 0 | if (ecdh == NULL) |
270 | 0 | return NULL; |
271 | 0 | return (CRYPTO_get_ex_data(&ecdh->ex_data, idx)); |
272 | 0 | } |