/src/nss-nspr/dist/public/nss/eccutil.h
Line | Count | Source |
1 | | /* This Source Code Form is subject to the terms of the Mozilla Public |
2 | | * License, v. 2.0. If a copy of the MPL was not distributed with this |
3 | | * file, You can obtain one at http://mozilla.org/MPL/2.0/. */ |
4 | | |
5 | | #ifndef _FREEBL_H_ |
6 | | #define _FREEBL_H_ |
7 | | |
8 | | #include "seccomon.h" |
9 | | |
10 | | #define X25519_PUBLIC_KEY_BYTES 32U |
11 | | #define SECP256_PUBLIC_KEY_BYTES 65U |
12 | | #define SECP384_PUBLIC_KEY_BYTES 97U |
13 | | |
14 | | /* deprecated */ |
15 | | typedef enum { |
16 | | ECPoint_Uncompressed, |
17 | | ECPoint_XOnly, |
18 | | ECPoint_Undefined |
19 | | } ECPointEncoding; |
20 | | |
21 | | /* EC point compression format. blapit.h includes this header, so freebl and |
22 | | * its callers get these from here too. */ |
23 | | #define EC_POINT_FORM_COMPRESSED_Y0 0x02 |
24 | | #define EC_POINT_FORM_COMPRESSED_Y1 0x03 |
25 | | #define EC_POINT_FORM_UNCOMPRESSED 0x04 |
26 | | #define EC_POINT_FORM_HYBRID_Y0 0x06 |
27 | | #define EC_POINT_FORM_HYBRID_Y1 0x07 |
28 | | |
29 | | /* |
30 | | * Is this ECPoint the bare point, rather than the DER encoding of one? |
31 | | * |
32 | | * CKA_EC_POINT and the ECPoint in an ECPrivateKey are defined as the DER |
33 | | * encoding of an OCTET STRING, but plenty of tokens hand back the bare point |
34 | | * instead, so readers have to take either. The first byte doesn't tell them |
35 | | * apart: EC_POINT_FORM_UNCOMPRESSED and the OCTET STRING tag are both 0x04, |
36 | | * and a bare uncompressed point is itself a well formed OCTET STRING whenever |
37 | | * X's first byte happens to equal the point's length - 2 (63 for P-256, 95 |
38 | | * for P-384). The lengths do tell them apart, so check those first. |
39 | | * |
40 | | * fieldLen is the size of one coordinate in bytes. Pass 0 if the curve isn't |
41 | | * known: the point is then reported as not bare, so a caller deciding whether |
42 | | * to unwrap falls back on trying the decode. |
43 | | */ |
44 | | static inline PRBool |
45 | | ECPoint_IsBare(const SECItem *point, unsigned int fieldLen) |
46 | 0 | { |
47 | 0 | if (fieldLen == 0 || point == NULL || point->data == NULL) { |
48 | 0 | return PR_FALSE; |
49 | 0 | } |
50 | 0 | /* EC_POINT_FORM_UNCOMPRESSED || X || Y */ |
51 | 0 | if (point->len == 2 * fieldLen + 1 && |
52 | 0 | point->data[0] == EC_POINT_FORM_UNCOMPRESSED) { |
53 | 0 | return PR_TRUE; |
54 | 0 | } |
55 | 0 | /* EC_POINT_FORM_COMPRESSED_Y0/Y1 || X */ |
56 | 0 | if (point->len == fieldLen + 1 && |
57 | 0 | (point->data[0] == EC_POINT_FORM_COMPRESSED_Y0 || |
58 | 0 | point->data[0] == EC_POINT_FORM_COMPRESSED_Y1)) { |
59 | 0 | return PR_TRUE; |
60 | 0 | } |
61 | 0 | return PR_FALSE; |
62 | 0 | } |
63 | | |
64 | | #endif /* _FREEBL_H_ */ |