Coverage Report

Created: 2026-09-28 07:30

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/gnutls/lib/nettle/pk.c
Line
Count
Source
1
/*
2
 * Copyright (C) 2010-2012 Free Software Foundation, Inc.
3
 * Copyright (C) 2013-2017 Nikos Mavrogiannopoulos
4
 * Copyright (C) 2016-2017 Red Hat, Inc.
5
 *
6
 * Author: Nikos Mavrogiannopoulos
7
 *
8
 * This file is part of GNUTLS.
9
 *
10
 * The GNUTLS library is free software; you can redistribute it and/or
11
 * modify it under the terms of the GNU Lesser General Public License
12
 * as published by the Free Software Foundation; either version 2.1 of
13
 * the License, or (at your option) any later version.
14
 *
15
 * This library is distributed in the hope that it will be useful, but
16
 * WITHOUT ANY WARRANTY; without even the implied warranty of
17
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
18
 * Lesser General Public License for more details.
19
 *
20
 * You should have received a copy of the GNU Lesser General Public License
21
 * along with this program.  If not, see <https://www.gnu.org/licenses/>
22
 *
23
 */
24
25
/* This file contains the functions needed for RSA/DSA public key
26
 * encryption and signatures.
27
 */
28
29
#include "gnutls_int.h"
30
#include "mpi.h"
31
#include "pk.h"
32
#include "errors.h"
33
#include "datum.h"
34
#include "global.h"
35
#include "tls-sig.h"
36
#include "num.h"
37
#include "x509/x509_int.h"
38
#include "x509/common.h"
39
#include "random.h"
40
#include "pk.h"
41
#include <nettle/dsa.h>
42
#include "dsa-fips.h"
43
#include "rsa-fips.h"
44
#include <nettle/rsa.h>
45
#include <gnutls/crypto.h>
46
#include <nettle/bignum.h>
47
#include <nettle/ecc.h>
48
#include <nettle/ecdsa.h>
49
#include <nettle/ecc-curve.h>
50
#include <nettle/curve25519.h>
51
#include <nettle/curve448.h>
52
#include <nettle/eddsa.h>
53
#include <nettle/version.h>
54
#if ENABLE_GOST
55
#if NEED_INT_ECC
56
#include "ecc/gostdsa.h"
57
#include "ecc-gost-curve.h"
58
#else
59
#include <nettle/gostdsa.h>
60
0
#define gost_point_mul_g ecc_point_mul_g
61
0
#define gost_point_set ecc_point_set
62
#endif
63
#include "gost/gostdsa2.h"
64
#endif
65
#include "int/ecdsa-compute-k.h"
66
#include "int/dsa-compute-k.h"
67
#include "gnettle.h"
68
#include "fips.h"
69
#include "dh.h"
70
#include "audit.h"
71
#ifdef HAVE_LEANCRYPTO
72
#include <leancrypto.h>
73
#endif
74
#include "attribute.h"
75
76
#define MAX_PRIME_CURVE_COORD_SIZE 66
77
78
static inline const struct ecc_curve *get_supported_nist_curve(int curve);
79
static inline const struct ecc_curve *get_supported_gost_curve(int curve);
80
81
static inline const char *get_supported_nist_curve_order(int curve);
82
static inline const char *get_supported_nist_curve_modulus(int curve);
83
84
/* When these callbacks are used for a nettle operation, the
85
 * caller must check the macro HAVE_LIB_ERROR() after the operation
86
 * is complete. If the macro is true, the operation is to be considered
87
 * failed (meaning the random generation failed).
88
 */
89
static void rnd_key_func(void *_ctx, size_t length, uint8_t *data)
90
0
{
91
0
  if (gnutls_rnd(GNUTLS_RND_KEY, data, length) < 0) {
92
0
    _gnutls_switch_lib_state(LIB_STATE_ERROR);
93
0
  }
94
0
}
95
96
static void rnd_tmpkey_func(void *_ctx, size_t length, uint8_t *data)
97
0
{
98
0
  if (gnutls_rnd(GNUTLS_RND_RANDOM, data, length) < 0) {
99
0
    _gnutls_switch_lib_state(LIB_STATE_ERROR);
100
0
  }
101
0
}
102
103
static void rnd_nonce_func(void *_ctx, size_t length, uint8_t *data)
104
0
{
105
0
  if (gnutls_rnd(GNUTLS_RND_NONCE, data, length) < 0) {
106
0
    _gnutls_switch_lib_state(LIB_STATE_ERROR);
107
0
  }
108
0
}
109
110
static void rnd_datum_func(void *ctx, size_t length, uint8_t *data)
111
0
{
112
0
  gnutls_datum_t *d = ctx;
113
114
0
  if (length > d->size) {
115
0
    memset(data, 0, length - d->size);
116
0
    memcpy(data + (length - d->size), d->data, d->size);
117
0
  } else {
118
0
    memcpy(data, d->data, length);
119
0
  }
120
0
}
121
122
static void rnd_nonce_func_fallback(void *_ctx, size_t length, uint8_t *data)
123
0
{
124
0
  if (unlikely(_gnutls_get_lib_state() != LIB_STATE_SELFTEST)) {
125
0
    _gnutls_switch_lib_state(LIB_STATE_ERROR);
126
0
  }
127
128
0
  memset(data, 0xAA, length);
129
0
}
130
131
static void ecc_scalar_zclear(struct ecc_scalar *s)
132
0
{
133
0
  zeroize_key(s->p, ecc_size(s->ecc) * sizeof(mp_limb_t));
134
0
  ecc_scalar_clear(s);
135
0
}
136
137
static void ecc_point_zclear(struct ecc_point *p)
138
0
{
139
0
  zeroize_key(p->p, ecc_size_a(p->ecc) * sizeof(mp_limb_t));
140
0
  ecc_point_clear(p);
141
0
}
142
143
static void _dsa_params_get(const gnutls_pk_params_st *pk_params,
144
          struct dsa_params *pub)
145
0
{
146
0
  memcpy(pub->p, pk_params->params[DSA_P], SIZEOF_MPZT);
147
148
0
  if (pk_params->params[DSA_Q])
149
0
    memcpy(&pub->q, pk_params->params[DSA_Q], SIZEOF_MPZT);
150
0
  memcpy(pub->g, pk_params->params[DSA_G], SIZEOF_MPZT);
151
0
}
152
153
static void _rsa_params_to_privkey(const gnutls_pk_params_st *pk_params,
154
           struct rsa_private_key *priv)
155
0
{
156
0
  memcpy(priv->d, pk_params->params[RSA_PRIV], SIZEOF_MPZT);
157
0
  memcpy(priv->p, pk_params->params[RSA_PRIME1], SIZEOF_MPZT);
158
0
  memcpy(priv->q, pk_params->params[RSA_PRIME2], SIZEOF_MPZT);
159
0
  memcpy(priv->c, pk_params->params[RSA_COEF], SIZEOF_MPZT);
160
0
  memcpy(priv->a, pk_params->params[RSA_E1], SIZEOF_MPZT);
161
0
  memcpy(priv->b, pk_params->params[RSA_E2], SIZEOF_MPZT);
162
  /* we do not rsa_private_key_prepare() because it involves a multiplication.
163
   * we call it once when we import the parameters */
164
0
  priv->size = nettle_mpz_sizeinbase_256_u(
165
0
    TOMPZ(pk_params->params[RSA_MODULUS]));
166
0
}
167
168
/* returns a negative value on invalid pubkey */
169
static int _rsa_params_to_pubkey(const gnutls_pk_params_st *pk_params,
170
         struct rsa_public_key *pub)
171
0
{
172
0
  memcpy(pub->n, pk_params->params[RSA_MODULUS], SIZEOF_MPZT);
173
0
  memcpy(pub->e, pk_params->params[RSA_PUB], SIZEOF_MPZT);
174
0
  if (rsa_public_key_prepare(pub) == 0)
175
0
    return gnutls_assert_val(GNUTLS_E_PK_INVALID_PUBKEY);
176
177
0
  return 0;
178
0
}
179
180
static int _ecc_params_to_privkey(const gnutls_pk_params_st *pk_params,
181
          struct ecc_scalar *priv,
182
          const struct ecc_curve *curve)
183
0
{
184
0
  ecc_scalar_init(priv, curve);
185
0
  if (ecc_scalar_set(priv, pk_params->params[ECC_K]) == 0) {
186
0
    ecc_scalar_clear(priv);
187
0
    return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
188
0
  }
189
190
0
  return 0;
191
0
}
192
193
static int _ecc_params_to_pubkey(const gnutls_pk_params_st *pk_params,
194
         struct ecc_point *pub,
195
         const struct ecc_curve *curve)
196
0
{
197
0
  ecc_point_init(pub, curve);
198
0
  if (ecc_point_set(pub, pk_params->params[ECC_X],
199
0
        pk_params->params[ECC_Y]) == 0) {
200
0
    ecc_point_clear(pub);
201
0
    return gnutls_assert_val(GNUTLS_E_PK_INVALID_PUBKEY);
202
0
  }
203
204
0
  return 0;
205
0
}
206
207
#if ENABLE_GOST
208
static int _gost_params_to_privkey(const gnutls_pk_params_st *pk_params,
209
           struct ecc_scalar *priv,
210
           const struct ecc_curve *curve)
211
0
{
212
0
  ecc_scalar_init(priv, curve);
213
0
  if (ecc_scalar_set(priv, pk_params->params[GOST_K]) == 0) {
214
0
    ecc_scalar_clear(priv);
215
0
    return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
216
0
  }
217
218
0
  return 0;
219
0
}
220
221
static int _gost_params_to_pubkey(const gnutls_pk_params_st *pk_params,
222
          struct ecc_point *pub,
223
          const struct ecc_curve *curve)
224
0
{
225
0
  ecc_point_init(pub, curve);
226
0
  if (gost_point_set(pub, pk_params->params[GOST_X],
227
0
         pk_params->params[GOST_Y]) == 0) {
228
0
    ecc_point_clear(pub);
229
0
    return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
230
0
  }
231
232
0
  return 0;
233
0
}
234
#endif
235
236
static int ecc_shared_secret(struct ecc_scalar *private_key,
237
           struct ecc_point *public_key, void *out,
238
           unsigned size)
239
0
{
240
0
  struct ecc_point r;
241
0
  mpz_t x, y;
242
0
  int ret = 0;
243
244
0
  mpz_init(x);
245
0
  mpz_init(y);
246
0
  ecc_point_init(&r, public_key->ecc);
247
248
0
  ecc_point_mul(&r, private_key, public_key);
249
250
0
  ecc_point_get(&r, x, y);
251
252
  /* Check if the point is not an identity element.  Note that this cannot
253
   * happen in nettle implementation, because it cannot represent an
254
   * infinity point. */
255
0
  if (mpz_cmp_ui(x, 0) == 0 && mpz_cmp_ui(y, 0) == 0) {
256
0
    ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
257
0
    goto cleanup;
258
0
  }
259
260
0
  nettle_mpz_get_str_256(size, out, x);
261
262
0
cleanup:
263
0
  mpz_clear(x);
264
0
  mpz_clear(y);
265
0
  ecc_point_clear(&r);
266
267
0
  return ret;
268
0
}
269
270
0
#define MAX_DH_BITS DEFAULT_MAX_VERIFY_BITS
271
/* This is used when we have no idea on the structure
272
 * of p-1 used by the peer. It is still a conservative
273
 * choice, but small than what we've been using before.
274
 */
275
#define DH_EXPONENT_SIZE(p_size) (2 * _gnutls_pk_bits_to_subgroup_bits(p_size))
276
277
static inline int edwards_curve_mul(gnutls_pk_algorithm_t algo, uint8_t *q,
278
            const uint8_t *n, const uint8_t *p)
279
0
{
280
0
  switch (algo) {
281
0
  case GNUTLS_PK_ECDH_X25519:
282
0
    curve25519_mul(q, n, p);
283
0
    return 0;
284
0
  case GNUTLS_PK_ECDH_X448:
285
0
    curve448_mul(q, n, p);
286
0
    return 0;
287
0
  default:
288
0
    return gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
289
0
  }
290
0
}
291
292
/* This is used for DH or ECDH key derivation. In DH for example
293
 * it is given the peers Y and our x, and calculates Y^x
294
 */
295
static int _wrap_nettle_pk_derive(gnutls_pk_algorithm_t algo,
296
          gnutls_datum_t *out,
297
          const gnutls_pk_params_st *priv,
298
          const gnutls_pk_params_st *pub,
299
          const gnutls_datum_t *nonce,
300
          unsigned int flags)
301
0
{
302
0
  int ret;
303
0
  bool not_approved = false;
304
305
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING, "pk::derive",
306
0
              "pk::algorithm", CRAU_STRING,
307
0
              gnutls_pk_get_name(algo), NULL);
308
309
0
  switch (algo) {
310
0
  case GNUTLS_PK_DH: {
311
0
    bigint_t f, x, q, prime;
312
0
    bigint_t k = NULL, primesub1 = NULL, r = NULL;
313
0
    unsigned int bits;
314
315
0
    if (nonce != NULL) {
316
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
317
0
      goto cleanup;
318
0
    }
319
320
0
    f = pub->params[DH_Y];
321
0
    x = priv->params[DH_X];
322
0
    q = priv->params[DH_Q];
323
0
    prime = priv->params[DH_P];
324
325
0
    ret = _gnutls_mpi_init_multi(&k, &primesub1, &r, NULL);
326
0
    if (ret < 0) {
327
0
      gnutls_assert();
328
0
      goto cleanup;
329
0
    }
330
331
0
    ret = _gnutls_mpi_sub_ui(primesub1, prime, 1);
332
0
    if (ret < 0) {
333
0
      gnutls_assert();
334
0
      goto dh_cleanup;
335
0
    }
336
337
    /* check if f==0,1, or f >= p-1 */
338
0
    if ((_gnutls_mpi_cmp_ui(f, 1) == 0) ||
339
0
        (_gnutls_mpi_cmp_ui(f, 0) == 0) ||
340
0
        (_gnutls_mpi_cmp(f, primesub1) >= 0)) {
341
0
      gnutls_assert();
342
0
      ret = GNUTLS_E_RECEIVED_ILLEGAL_PARAMETER;
343
0
      goto dh_cleanup;
344
0
    }
345
346
    /* if we have Q check that y ^ q mod p == 1 */
347
0
    if (q != NULL) {
348
0
      ret = _gnutls_mpi_powm(r, f, q, prime);
349
0
      if (ret < 0) {
350
0
        gnutls_assert();
351
0
        goto dh_cleanup;
352
0
      }
353
0
      ret = _gnutls_mpi_cmp_ui(r, 1);
354
0
      if (ret != 0) {
355
0
        gnutls_assert();
356
0
        ret = GNUTLS_E_RECEIVED_ILLEGAL_PARAMETER;
357
0
        goto dh_cleanup;
358
0
      }
359
0
    } else if ((flags & PK_DERIVE_TLS13) &&
360
0
         _gnutls_fips_mode_enabled()) {
361
      /* Mandatory in FIPS mode for TLS 1.3 */
362
0
      ret = gnutls_assert_val(
363
0
        GNUTLS_E_RECEIVED_ILLEGAL_PARAMETER);
364
0
      goto dh_cleanup;
365
0
    }
366
367
    /* prevent denial of service */
368
0
    bits = _gnutls_mpi_get_nbits(prime);
369
0
    if (bits == 0 || bits > MAX_DH_BITS) {
370
0
      gnutls_assert();
371
0
      ret = GNUTLS_E_RECEIVED_ILLEGAL_PARAMETER;
372
0
      goto dh_cleanup;
373
0
    }
374
375
0
    _gnutls_audit_data("pk::bits", CRAU_WORD, bits, NULL);
376
377
0
    if (bits < 2048) {
378
0
      not_approved = true;
379
0
    }
380
381
0
    ret = _gnutls_mpi_powm(k, f, x, prime);
382
0
    if (ret < 0) {
383
0
      gnutls_assert();
384
0
      goto dh_cleanup;
385
0
    }
386
387
    /* check if k==0,1, or k = p-1 */
388
0
    if ((_gnutls_mpi_cmp_ui(k, 1) == 0) ||
389
0
        (_gnutls_mpi_cmp_ui(k, 0) == 0) ||
390
0
        (_gnutls_mpi_cmp(k, primesub1) == 0)) {
391
0
      ret = gnutls_assert_val(
392
0
        GNUTLS_E_RECEIVED_ILLEGAL_PARAMETER);
393
0
      goto dh_cleanup;
394
0
    }
395
396
0
    if (flags & PK_DERIVE_TLS13) {
397
0
      ret = _gnutls_mpi_dprint_size(k, out, (bits + 7) / 8);
398
0
    } else {
399
0
      ret = _gnutls_mpi_dprint(k, out);
400
0
    }
401
402
0
    if (ret < 0) {
403
0
      gnutls_assert();
404
0
      goto dh_cleanup;
405
0
    }
406
407
0
    ret = 0;
408
0
  dh_cleanup:
409
0
    _gnutls_mpi_release(&r);
410
0
    _gnutls_mpi_release(&primesub1);
411
0
    zrelease_mpi_key(&k);
412
0
    if (ret < 0)
413
0
      goto cleanup;
414
415
0
    break;
416
0
  }
417
0
  case GNUTLS_PK_EC: {
418
0
    struct ecc_scalar ecc_priv;
419
0
    struct ecc_point ecc_pub;
420
0
    const struct ecc_curve *curve;
421
0
    struct ecc_scalar n;
422
0
    struct ecc_scalar m;
423
0
    struct ecc_point r;
424
0
    mpz_t x, y, xx, yy, nn, mm;
425
426
0
    out->data = NULL;
427
428
0
    if (nonce != NULL) {
429
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
430
0
      goto cleanup;
431
0
    }
432
433
0
    curve = get_supported_nist_curve(priv->curve);
434
0
    if (curve == NULL) {
435
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
436
0
      goto cleanup;
437
0
    }
438
439
0
    _gnutls_audit_data("pk::curve", CRAU_STRING,
440
0
           gnutls_ecc_curve_get_name(priv->curve),
441
0
           NULL);
442
443
    /* P-192 is not supported in FIPS 140-3 */
444
0
    if (priv->curve == GNUTLS_ECC_CURVE_SECP192R1) {
445
0
      not_approved = true;
446
0
    }
447
448
0
    mpz_init(x);
449
0
    mpz_init(y);
450
0
    mpz_init(xx);
451
0
    mpz_init(yy);
452
0
    mpz_init(nn);
453
0
    mpz_init(mm);
454
455
0
    ecc_scalar_init(&n, curve);
456
0
    ecc_scalar_init(&m, curve);
457
0
    ecc_point_init(&r, curve);
458
459
0
    ret = _ecc_params_to_pubkey(pub, &ecc_pub, curve);
460
0
    if (ret < 0) {
461
0
      gnutls_assert();
462
0
      goto ecc_fail_cleanup;
463
0
    }
464
465
0
    ret = _ecc_params_to_privkey(priv, &ecc_priv, curve);
466
0
    if (ret < 0) {
467
0
      ecc_point_clear(&ecc_pub);
468
0
      gnutls_assert();
469
0
      goto ecc_fail_cleanup;
470
0
    }
471
472
0
    out->size = gnutls_ecc_curve_get_size(priv->curve);
473
    /*ecc_size(curve)*sizeof(mp_limb_t); */
474
0
    out->data = gnutls_malloc(out->size);
475
0
    if (out->data == NULL) {
476
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
477
0
      goto ecc_cleanup;
478
0
    }
479
480
    /* Perform ECC Full Public-Key Validation Routine
481
     * according to SP800-56A (revision 3), 5.6.2.3.3.
482
     */
483
484
    /* Step 1: verify that Q is not an identity
485
     * element (an infinity point). Note that this
486
     * cannot happen in the nettle implementation,
487
     * because it cannot represent an infinity point
488
     * on curves. */
489
0
    ret = ecc_shared_secret(&ecc_priv, &ecc_pub, out->data,
490
0
          out->size);
491
0
    if (ret < 0) {
492
0
      gnutls_free(out->data);
493
0
      goto ecc_cleanup;
494
0
    }
495
#ifdef ENABLE_FIPS140
496
    if (_gnutls_fips_mode_enabled()) {
497
      const char *order, *modulus;
498
499
      ecc_point_mul(&r, &ecc_priv, &ecc_pub);
500
      ecc_point_get(&r, x, y);
501
502
      /* Step 2: verify that both coordinates of Q are
503
       * in the range [0, p - 1].
504
       *
505
       * Step 3: verify that Q lie on the curve
506
       *
507
       * Both checks are performed in nettle.  */
508
      if (!ecc_point_set(&r, x, y)) {
509
        ret = gnutls_assert_val(
510
          GNUTLS_E_ILLEGAL_PARAMETER);
511
        goto ecc_cleanup;
512
      }
513
514
      /* Step 4: verify that n * Q, where n is the
515
       * curve order, result in an identity element
516
       *
517
       * Since nettle internally cannot represent an
518
       * identity element on curves, we validate this
519
       * instead:
520
       *
521
       *   (n - 1) * Q = -Q
522
       *
523
       * That effectively means: n * Q = -Q + Q = O
524
       */
525
      order = get_supported_nist_curve_order(priv->curve);
526
      if (unlikely(order == NULL)) {
527
        ret = gnutls_assert_val(
528
          GNUTLS_E_INTERNAL_ERROR);
529
        goto ecc_cleanup;
530
      }
531
532
      ret = mpz_set_str(nn, order, 16);
533
      if (unlikely(ret < 0)) {
534
        ret = gnutls_assert_val(
535
          GNUTLS_E_MPI_SCAN_FAILED);
536
        goto ecc_cleanup;
537
      }
538
539
      modulus = get_supported_nist_curve_modulus(priv->curve);
540
      if (unlikely(modulus == NULL)) {
541
        ret = gnutls_assert_val(
542
          GNUTLS_E_INTERNAL_ERROR);
543
        goto ecc_cleanup;
544
      }
545
546
      ret = mpz_set_str(mm, modulus, 16);
547
      if (unlikely(ret < 0)) {
548
        ret = gnutls_assert_val(
549
          GNUTLS_E_MPI_SCAN_FAILED);
550
        goto ecc_cleanup;
551
      }
552
553
      /* (n - 1) * Q = -Q */
554
      mpz_sub_ui(nn, nn, 1);
555
      ecc_scalar_set(&n, nn);
556
      ecc_point_mul(&r, &n, &r);
557
      ecc_point_get(&r, xx, yy);
558
      mpz_sub(mm, mm, y);
559
560
      if (mpz_cmp(xx, x) != 0 || mpz_cmp(yy, mm) != 0) {
561
        ret = gnutls_assert_val(
562
          GNUTLS_E_ILLEGAL_PARAMETER);
563
        goto ecc_cleanup;
564
      }
565
    } else {
566
      not_approved = true;
567
    }
568
#endif
569
570
0
  ecc_cleanup:
571
0
    ecc_point_clear(&ecc_pub);
572
0
    ecc_scalar_zclear(&ecc_priv);
573
0
  ecc_fail_cleanup:
574
0
    mpz_clear(x);
575
0
    mpz_clear(y);
576
0
    mpz_clear(xx);
577
0
    mpz_clear(yy);
578
0
    mpz_clear(nn);
579
0
    mpz_clear(mm);
580
0
    ecc_point_clear(&r);
581
0
    ecc_scalar_clear(&n);
582
0
    ecc_scalar_clear(&m);
583
0
    if (ret < 0)
584
0
      goto cleanup;
585
0
    break;
586
0
  }
587
0
  case GNUTLS_PK_ECDH_X25519:
588
0
  case GNUTLS_PK_ECDH_X448: {
589
0
    unsigned size = gnutls_ecc_curve_get_size(priv->curve);
590
591
    /* Edwards curves are not approved */
592
0
    not_approved = true;
593
594
0
    if (nonce != NULL) {
595
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
596
0
      goto cleanup;
597
0
    }
598
599
    /* The point is in pub, while the private part (scalar) in priv. */
600
601
0
    if (size == 0 || priv->raw_priv.size != size) {
602
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
603
0
      goto cleanup;
604
0
    }
605
606
0
    out->data = gnutls_malloc(size);
607
0
    if (out->data == NULL) {
608
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
609
0
      goto cleanup;
610
0
    }
611
612
0
    out->size = size;
613
614
0
    ret = edwards_curve_mul(algo, out->data, priv->raw_priv.data,
615
0
          pub->raw_pub.data);
616
0
    if (ret < 0)
617
0
      goto cleanup;
618
619
0
    if (_gnutls_mem_is_zero(out->data, out->size)) {
620
0
      gnutls_free(out->data);
621
0
      gnutls_assert();
622
0
      ret = GNUTLS_E_RECEIVED_ILLEGAL_PARAMETER;
623
0
      goto cleanup;
624
0
    }
625
0
    break;
626
0
  }
627
0
#if ENABLE_GOST
628
0
  case GNUTLS_PK_GOST_01:
629
0
  case GNUTLS_PK_GOST_12_256:
630
0
  case GNUTLS_PK_GOST_12_512: {
631
0
    struct ecc_scalar ecc_priv;
632
0
    struct ecc_point ecc_pub;
633
0
    const struct ecc_curve *curve;
634
635
    /* GOST curves are not approved */
636
0
    not_approved = true;
637
638
0
    out->data = NULL;
639
640
0
    curve = get_supported_gost_curve(priv->curve);
641
0
    if (curve == NULL) {
642
0
      gnutls_assert();
643
0
      ret = GNUTLS_E_ECC_UNSUPPORTED_CURVE;
644
0
      goto cleanup;
645
0
    }
646
647
0
    _gnutls_audit_data("pk::curve", CRAU_STRING,
648
0
           gnutls_ecc_curve_get_name(priv->curve),
649
0
           NULL);
650
651
0
    if (nonce == NULL) {
652
0
      gnutls_assert();
653
0
      ret = GNUTLS_E_INVALID_REQUEST;
654
0
      goto cleanup;
655
0
    }
656
657
0
    ret = _gost_params_to_pubkey(pub, &ecc_pub, curve);
658
0
    if (ret < 0) {
659
0
      gnutls_assert();
660
0
      goto cleanup;
661
0
    }
662
663
0
    ret = _gost_params_to_privkey(priv, &ecc_priv, curve);
664
0
    if (ret < 0) {
665
0
      ecc_point_clear(&ecc_pub);
666
0
      gnutls_assert();
667
0
      goto cleanup;
668
0
    }
669
670
0
    out->size = 2 * gnutls_ecc_curve_get_size(priv->curve);
671
0
    out->data = gnutls_malloc(out->size);
672
0
    if (out->data == NULL) {
673
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
674
0
      goto gost_cleanup;
675
0
    }
676
677
0
    gostdsa_vko(&ecc_priv, &ecc_pub, nonce->size, nonce->data,
678
0
          out->data);
679
680
0
  gost_cleanup:
681
0
    ecc_point_clear(&ecc_pub);
682
0
    ecc_scalar_zclear(&ecc_priv);
683
0
    if (ret < 0)
684
0
      goto cleanup;
685
0
    break;
686
0
  }
687
0
#endif
688
0
  default:
689
0
    gnutls_assert();
690
0
    ret = GNUTLS_E_INTERNAL_ERROR;
691
0
    goto cleanup;
692
0
  }
693
694
0
  ret = 0;
695
696
0
cleanup:
697
0
  if (ret < 0) {
698
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
699
0
  } else if (not_approved) {
700
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_NOT_APPROVED);
701
0
  } else {
702
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_APPROVED);
703
0
  }
704
705
0
  gnutls_audit_pop_context();
706
707
0
  return ret;
708
0
}
709
710
#ifdef HAVE_LEANCRYPTO
711
static enum lc_kyber_type ml_kem_pk_to_lc_kyber_type(gnutls_pk_algorithm_t algo)
712
{
713
  switch (algo) {
714
#ifdef LC_KYBER_768_ENABLED
715
  case GNUTLS_PK_MLKEM768:
716
    return LC_KYBER_768;
717
#endif
718
#ifdef LC_KYBER_1024_ENABLED
719
  case GNUTLS_PK_MLKEM1024:
720
    return LC_KYBER_1024;
721
#endif
722
  default:
723
    return gnutls_assert_val(LC_KYBER_UNKNOWN);
724
  }
725
}
726
727
static int ml_kem_exists(gnutls_pk_algorithm_t algo)
728
{
729
  return ml_kem_pk_to_lc_kyber_type(algo) != LC_KYBER_UNKNOWN;
730
}
731
732
static int ml_kem_encaps(gnutls_pk_algorithm_t algo, gnutls_datum_t *ciphertext,
733
       gnutls_datum_t *shared_secret,
734
       const gnutls_datum_t *pub)
735
{
736
  enum lc_kyber_type type;
737
  struct lc_kyber_ct ct;
738
  struct lc_kyber_ss ss;
739
  struct lc_kyber_pk pk;
740
  gnutls_datum_t tmp_ciphertext = { NULL, 0 };
741
  gnutls_datum_t tmp_shared_secret = { NULL, 0 };
742
  uint8_t *ptr;
743
  size_t len;
744
  int ret;
745
746
  type = ml_kem_pk_to_lc_kyber_type(algo);
747
  if (type == LC_KYBER_UNKNOWN)
748
    return gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
749
750
  ret = lc_kyber_pk_load(&pk, pub->data, pub->size);
751
  if (ret < 0 || lc_kyber_pk_type(&pk) != type) {
752
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
753
    goto cleanup;
754
  }
755
756
  ret = lc_kyber_enc(&ct, &ss, &pk);
757
  if (ret < 0) {
758
    ret = gnutls_assert_val(GNUTLS_E_PK_ENCRYPTION_FAILED);
759
    goto cleanup;
760
  }
761
762
  ret = lc_kyber_ct_ptr(&ptr, &len, &ct);
763
  if (ret < 0) {
764
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
765
    goto cleanup;
766
  }
767
  ret = _gnutls_set_datum(&tmp_ciphertext, ptr, len);
768
  if (ret < 0) {
769
    gnutls_assert();
770
    goto cleanup;
771
  }
772
773
  ret = lc_kyber_ss_ptr(&ptr, &len, &ss);
774
  if (ret < 0) {
775
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
776
    goto cleanup;
777
  }
778
  ret = _gnutls_set_datum(&tmp_shared_secret, ptr, len);
779
  if (ret < 0) {
780
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
781
    goto cleanup;
782
  }
783
784
  *ciphertext = _gnutls_take_datum(&tmp_ciphertext);
785
  *shared_secret = _gnutls_take_datum(&tmp_shared_secret);
786
787
  ret = 0;
788
789
cleanup:
790
  _gnutls_free_datum(&tmp_ciphertext);
791
  _gnutls_free_key_datum(&tmp_shared_secret);
792
  zeroize_key(&pk, sizeof(pk));
793
  return ret;
794
}
795
796
static int ml_kem_decaps(gnutls_pk_algorithm_t algo,
797
       gnutls_datum_t *shared_secret,
798
       const gnutls_datum_t *ciphertext,
799
       const gnutls_datum_t *priv)
800
{
801
  int ret;
802
  enum lc_kyber_type type;
803
  struct lc_kyber_ss ss;
804
  struct lc_kyber_ct ct;
805
  struct lc_kyber_sk sk;
806
  gnutls_datum_t tmp_shared_secret = { NULL, 0 };
807
  uint8_t *ptr;
808
  size_t len;
809
810
  type = ml_kem_pk_to_lc_kyber_type(algo);
811
  if (type == LC_KYBER_UNKNOWN)
812
    return gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
813
814
  ret = lc_kyber_sk_load(&sk, priv->data, priv->size);
815
  if (ret < 0 || lc_kyber_sk_type(&sk) != type) {
816
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
817
    goto cleanup;
818
  }
819
820
  ret = lc_kyber_ct_load(&ct, ciphertext->data, ciphertext->size);
821
  if (ret < 0 || lc_kyber_ct_type(&ct) != type) {
822
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
823
    goto cleanup;
824
  }
825
826
  ret = lc_kyber_dec(&ss, &ct, &sk);
827
  if (ret < 0) {
828
    ret = gnutls_assert_val(GNUTLS_E_PK_DECRYPTION_FAILED);
829
    goto cleanup;
830
  }
831
832
  ret = lc_kyber_ss_ptr(&ptr, &len, &ss);
833
  if (ret < 0) {
834
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
835
    goto cleanup;
836
  }
837
838
  ret = _gnutls_set_datum(&tmp_shared_secret, ptr, len);
839
  if (ret < 0) {
840
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
841
    goto cleanup;
842
  }
843
844
  *shared_secret = _gnutls_take_datum(&tmp_shared_secret);
845
846
  ret = 0;
847
848
cleanup:
849
  _gnutls_free_key_datum(&tmp_shared_secret);
850
  zeroize_key(&ss, sizeof(ss));
851
  zeroize_key(&sk, sizeof(sk));
852
  return ret;
853
}
854
855
static int ml_kem_generate_keypair(gnutls_pk_algorithm_t algo,
856
           gnutls_datum_t *raw_priv,
857
           gnutls_datum_t *raw_pub)
858
{
859
  int ret;
860
  enum lc_kyber_type type;
861
  struct lc_kyber_sk sk;
862
  struct lc_kyber_pk pk;
863
  gnutls_datum_t tmp_raw_priv = { NULL, 0 };
864
  gnutls_datum_t tmp_raw_pub = { NULL, 0 };
865
  uint8_t *ptr;
866
  size_t len;
867
868
  type = ml_kem_pk_to_lc_kyber_type(algo);
869
  if (type == LC_KYBER_UNKNOWN)
870
    return gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
871
872
  ret = lc_kyber_keypair(&pk, &sk, lc_seeded_rng, type);
873
  if (ret < 0) {
874
    ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
875
    goto cleanup;
876
  }
877
878
  ret = lc_kyber_sk_ptr(&ptr, &len, &sk);
879
  if (ret < 0) {
880
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
881
    goto cleanup;
882
  }
883
884
  ret = _gnutls_set_datum(&tmp_raw_priv, ptr, len);
885
  if (ret < 0) {
886
    gnutls_assert();
887
    goto cleanup;
888
  }
889
890
  ret = lc_kyber_pk_ptr(&ptr, &len, &pk);
891
  if (ret < 0) {
892
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
893
    goto cleanup;
894
  }
895
896
  ret = _gnutls_set_datum(&tmp_raw_pub, ptr, len);
897
  if (ret < 0) {
898
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
899
    goto cleanup;
900
  }
901
902
  *raw_priv = _gnutls_take_datum(&tmp_raw_priv);
903
  *raw_pub = _gnutls_take_datum(&tmp_raw_pub);
904
905
  ret = 0;
906
907
cleanup:
908
  _gnutls_free_key_datum(&tmp_raw_priv);
909
  _gnutls_free_key_datum(&tmp_raw_pub);
910
  zeroize_key(&pk, sizeof(pk));
911
  zeroize_key(&sk, sizeof(sk));
912
  return ret;
913
}
914
#else
915
static int ml_kem_exists(gnutls_pk_algorithm_t algo MAYBE_UNUSED)
916
0
{
917
0
  return 0;
918
0
}
919
920
static int ml_kem_encaps(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
921
       gnutls_datum_t *ciphertext MAYBE_UNUSED,
922
       gnutls_datum_t *shared_secret MAYBE_UNUSED,
923
       const gnutls_datum_t *pub MAYBE_UNUSED)
924
0
{
925
0
  return gnutls_assert_val(GNUTLS_E_UNKNOWN_ALGORITHM);
926
0
}
927
928
static int ml_kem_decaps(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
929
       gnutls_datum_t *shared_secret MAYBE_UNUSED,
930
       const gnutls_datum_t *ciphertext MAYBE_UNUSED,
931
       const gnutls_datum_t *priv MAYBE_UNUSED)
932
0
{
933
0
  return gnutls_assert_val(GNUTLS_E_UNKNOWN_ALGORITHM);
934
0
}
935
936
static int ml_kem_generate_keypair(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
937
           gnutls_datum_t *raw_priv MAYBE_UNUSED,
938
           gnutls_datum_t *raw_pub MAYBE_UNUSED)
939
0
{
940
0
  return gnutls_assert_val(GNUTLS_E_UNKNOWN_ALGORITHM);
941
0
}
942
#endif
943
944
static int _wrap_nettle_pk_encaps(gnutls_pk_algorithm_t algo,
945
          gnutls_datum_t *ciphertext,
946
          gnutls_datum_t *shared_secret,
947
          const gnutls_datum_t *pub)
948
0
{
949
0
  int ret;
950
0
  bool not_approved = false;
951
952
0
  switch (algo) {
953
0
  case GNUTLS_PK_MLKEM768:
954
0
  case GNUTLS_PK_MLKEM1024:
955
    /* unapproved until we implement a CAST per IG 10.3.A(14). */
956
0
    not_approved = true;
957
0
    break;
958
0
  default:
959
0
    return gnutls_assert_val(GNUTLS_E_UNKNOWN_ALGORITHM);
960
0
  }
961
962
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING,
963
0
              "pk::encapsulate", "pk::algorithm",
964
0
              CRAU_STRING,
965
0
              gnutls_pk_get_name(algo), NULL);
966
967
0
  ret = ml_kem_encaps(algo, ciphertext, shared_secret, pub);
968
969
0
  if (ret < 0) {
970
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
971
0
  } else if (not_approved) {
972
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_NOT_APPROVED);
973
0
  } else {
974
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_APPROVED);
975
0
  }
976
977
0
  gnutls_audit_pop_context();
978
979
0
  return ret;
980
0
}
981
982
static int _wrap_nettle_pk_decaps(gnutls_pk_algorithm_t algo,
983
          gnutls_datum_t *shared_secret,
984
          const gnutls_datum_t *ciphertext,
985
          const gnutls_datum_t *priv)
986
0
{
987
0
  int ret;
988
0
  bool not_approved = false;
989
990
0
  switch (algo) {
991
0
  case GNUTLS_PK_MLKEM768:
992
0
  case GNUTLS_PK_MLKEM1024:
993
    /* unapproved until we implement a CAST per IG 10.3.A(14). */
994
0
    not_approved = true;
995
0
    break;
996
0
  default:
997
0
    return gnutls_assert_val(GNUTLS_E_UNKNOWN_ALGORITHM);
998
0
  }
999
1000
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING,
1001
0
              "pk::decapsulate", "pk::algorithm",
1002
0
              CRAU_STRING,
1003
0
              gnutls_pk_get_name(algo), NULL);
1004
1005
0
  ret = ml_kem_decaps(algo, shared_secret, ciphertext, priv);
1006
1007
0
  if (ret < 0) {
1008
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
1009
0
  } else if (not_approved) {
1010
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_NOT_APPROVED);
1011
0
  } else {
1012
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_APPROVED);
1013
0
  }
1014
1015
0
  gnutls_audit_pop_context();
1016
1017
0
  return ret;
1018
0
}
1019
1020
/* This wraps nettle_rsa_encrypt so it returns ciphertext as a byte
1021
 * array instead of a mpz_t value.  Returns 1 on success; 0 otherwise.
1022
 */
1023
static inline int _rsa_encrypt(const struct rsa_public_key *key, void *rnd_ctx,
1024
             nettle_random_func *rnd_func, size_t length,
1025
             const uint8_t *message, uint8_t *ciphertext)
1026
0
{
1027
0
  mpz_t p;
1028
0
  int ret;
1029
1030
0
  mpz_init(p);
1031
1032
0
  ret = rsa_encrypt(key, rnd_ctx, rnd_func, length, message, p);
1033
1034
0
  if (ret == 0) {
1035
0
    gnutls_assert();
1036
0
    goto cleanup;
1037
0
  }
1038
1039
0
  if (_gnutls_mpi_bprint_size(p, ciphertext, key->size) < 0) {
1040
0
    gnutls_assert();
1041
0
    goto cleanup;
1042
0
  }
1043
1044
0
cleanup:
1045
0
  mpz_clear(p);
1046
0
  return ret;
1047
0
}
1048
1049
/* This wraps nettle_rsa_oaep_sha*_encrypt to parametrize the function
1050
 * calls with a DIG argument.  Returns 1 on success; 0 otherwise.
1051
 */
1052
static inline int _rsa_oaep_encrypt(gnutls_digest_algorithm_t dig,
1053
            const struct rsa_public_key *pub,
1054
            void *rnd_ctx, nettle_random_func *rnd_func,
1055
            size_t label_length, const uint8_t *label,
1056
            size_t length, const uint8_t *message,
1057
            uint8_t *ciphertext)
1058
0
{
1059
0
  int (*encrypt_func)(const struct rsa_public_key *, void *,
1060
0
          nettle_random_func *, size_t, const uint8_t *,
1061
0
          size_t, const uint8_t *, uint8_t *);
1062
1063
0
  switch (dig) {
1064
0
  case GNUTLS_DIG_SHA256:
1065
0
    encrypt_func = rsa_oaep_sha256_encrypt;
1066
0
    break;
1067
0
  case GNUTLS_DIG_SHA384:
1068
0
    encrypt_func = rsa_oaep_sha384_encrypt;
1069
0
    break;
1070
0
  case GNUTLS_DIG_SHA512:
1071
0
    encrypt_func = rsa_oaep_sha512_encrypt;
1072
0
    break;
1073
0
  default:
1074
0
    gnutls_assert();
1075
0
    return 0;
1076
0
  }
1077
1078
0
  return encrypt_func(pub, rnd_ctx, rnd_func, label_length, label, length,
1079
0
          message, ciphertext);
1080
0
}
1081
1082
static int _wrap_nettle_pk_encrypt(gnutls_pk_algorithm_t algo,
1083
           gnutls_datum_t *ciphertext,
1084
           const gnutls_datum_t *plaintext,
1085
           const gnutls_pk_params_st *pk_params,
1086
           const gnutls_x509_spki_st *encrypt_params)
1087
0
{
1088
0
  int ret;
1089
0
  bool not_approved = false;
1090
0
  uint8_t *buf = NULL;
1091
1092
0
  FAIL_IF_LIB_ERROR;
1093
1094
0
  if (algo == GNUTLS_PK_RSA && pk_params->spki.pk == GNUTLS_PK_RSA_OAEP) {
1095
0
    algo = GNUTLS_PK_RSA_OAEP;
1096
0
  }
1097
1098
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING, "pk::encrypt",
1099
0
              "pk::algorithm", CRAU_STRING,
1100
0
              gnutls_pk_get_name(algo), NULL);
1101
1102
0
  switch (algo) {
1103
0
  case GNUTLS_PK_RSA: {
1104
0
    struct rsa_public_key pub;
1105
0
    nettle_random_func *random_func;
1106
0
    size_t bits;
1107
1108
0
    if (!_gnutls_config_is_rsa_pkcs1_encrypt_allowed()) {
1109
0
      ret = gnutls_assert_val(
1110
0
        GNUTLS_E_UNSUPPORTED_ENCRYPTION_ALGORITHM);
1111
0
      goto cleanup;
1112
0
    }
1113
1114
    /* RSA encryption with PKCS#1 v1.5 padding is not approved */
1115
0
    not_approved = true;
1116
1117
0
    ret = _rsa_params_to_pubkey(pk_params, &pub);
1118
0
    if (ret < 0) {
1119
0
      gnutls_assert();
1120
0
      goto cleanup;
1121
0
    }
1122
1123
0
    bits = mpz_sizeinbase(pub.n, 2);
1124
1125
0
    _gnutls_audit_data("pk::bits", CRAU_WORD, bits, NULL);
1126
1127
0
    if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST)
1128
0
      random_func = rnd_nonce_func_fallback;
1129
0
    else
1130
0
      random_func = rnd_nonce_func;
1131
1132
0
    buf = gnutls_malloc(pub.size);
1133
0
    if (!buf) {
1134
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
1135
0
      goto cleanup;
1136
0
    }
1137
1138
0
    ret = _rsa_encrypt(&pub, NULL, random_func, plaintext->size,
1139
0
           plaintext->data, buf);
1140
0
    if (ret == 0 || HAVE_LIB_ERROR()) {
1141
0
      ret = gnutls_assert_val(GNUTLS_E_ENCRYPTION_FAILED);
1142
0
      goto cleanup;
1143
0
    }
1144
1145
0
    ciphertext->data = buf;
1146
0
    buf = NULL;
1147
0
    ciphertext->size = pub.size;
1148
0
    break;
1149
0
  }
1150
0
  case GNUTLS_PK_RSA_OAEP: {
1151
0
    struct rsa_public_key pub;
1152
0
    nettle_random_func *random_func;
1153
0
    size_t bits;
1154
1155
0
    ret = _rsa_params_to_pubkey(pk_params, &pub);
1156
0
    if (ret < 0) {
1157
0
      gnutls_assert();
1158
0
      goto cleanup;
1159
0
    }
1160
1161
0
    bits = mpz_sizeinbase(pub.n, 2);
1162
1163
0
    _gnutls_audit_data(
1164
0
      "pk::bits", CRAU_WORD, bits, "pk::hash", CRAU_STRING,
1165
0
      gnutls_digest_get_name(encrypt_params->rsa_oaep_dig),
1166
0
      NULL);
1167
1168
0
    if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST)
1169
0
      random_func = rnd_nonce_func_fallback;
1170
0
    else
1171
0
      random_func = rnd_nonce_func;
1172
1173
0
    buf = gnutls_malloc(pub.size);
1174
0
    if (!buf) {
1175
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
1176
0
      goto cleanup;
1177
0
    }
1178
1179
0
    ret = _rsa_oaep_encrypt(encrypt_params->rsa_oaep_dig, &pub,
1180
0
          NULL, random_func,
1181
0
          encrypt_params->rsa_oaep_label.size,
1182
0
          encrypt_params->rsa_oaep_label.data,
1183
0
          plaintext->size, plaintext->data, buf);
1184
0
    if (ret == 0 || HAVE_LIB_ERROR()) {
1185
0
      ret = gnutls_assert_val(GNUTLS_E_ENCRYPTION_FAILED);
1186
0
      goto cleanup;
1187
0
    }
1188
0
    ciphertext->data = buf;
1189
0
    buf = NULL;
1190
0
    ciphertext->size = pub.size;
1191
0
    break;
1192
0
  }
1193
0
  default:
1194
0
    gnutls_assert();
1195
0
    ret = GNUTLS_E_INVALID_REQUEST;
1196
0
    goto cleanup;
1197
0
  }
1198
1199
0
  ret = 0;
1200
1201
0
cleanup:
1202
0
  gnutls_free(buf);
1203
0
  if (ret < 0) {
1204
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
1205
0
  } else if (not_approved) {
1206
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_NOT_APPROVED);
1207
0
  } else {
1208
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_APPROVED);
1209
0
  }
1210
1211
0
  gnutls_audit_pop_context();
1212
1213
0
  FAIL_IF_LIB_ERROR;
1214
0
  return ret;
1215
0
}
1216
1217
/* This wraps nettle_rsa_decrypt_tr so it takes ciphertext as a byte
1218
 * array instead of a mpz_t value.  Returns 1 on success; 0 otherwise.
1219
 */
1220
static inline int _rsa_decrypt_tr(const struct rsa_public_key *pub,
1221
          const struct rsa_private_key *key,
1222
          void *rnd_ctx, nettle_random_func *rnd_func,
1223
          size_t *length, uint8_t *message,
1224
          const uint8_t *ciphertext)
1225
0
{
1226
0
  bigint_t c;
1227
0
  int ret;
1228
1229
0
  if (_gnutls_mpi_init_scan_nz(&c, ciphertext, pub->size) < 0) {
1230
0
    gnutls_assert();
1231
0
    return 0;
1232
0
  }
1233
1234
0
  ret = rsa_decrypt_tr(pub, key, rnd_ctx, rnd_func, length, message, c);
1235
1236
0
  _gnutls_mpi_release(&c);
1237
1238
0
  return ret;
1239
0
}
1240
1241
/* This wraps nettle_rsa_oaep_sha*_decrypt to parametrize the function
1242
 * calls with a DIG argument.  Returns 1 on success; 0 otherwise.
1243
 */
1244
static inline int _rsa_oaep_decrypt(gnutls_digest_algorithm_t dig,
1245
            const struct rsa_public_key *pub,
1246
            const struct rsa_private_key *key,
1247
            void *rnd_ctx, nettle_random_func *rnd_func,
1248
            size_t label_length, const uint8_t *label,
1249
            size_t *length, uint8_t *message,
1250
            const uint8_t *ciphertext)
1251
0
{
1252
0
  int (*decrypt_func)(const struct rsa_public_key *,
1253
0
          const struct rsa_private_key *, void *,
1254
0
          nettle_random_func *, size_t, const uint8_t *,
1255
0
          size_t *, uint8_t *, const uint8_t *);
1256
1257
0
  switch (dig) {
1258
0
  case GNUTLS_DIG_SHA256:
1259
0
    decrypt_func = rsa_oaep_sha256_decrypt;
1260
0
    break;
1261
0
  case GNUTLS_DIG_SHA384:
1262
0
    decrypt_func = rsa_oaep_sha384_decrypt;
1263
0
    break;
1264
0
  case GNUTLS_DIG_SHA512:
1265
0
    decrypt_func = rsa_oaep_sha512_decrypt;
1266
0
    break;
1267
0
  default:
1268
0
    gnutls_assert();
1269
0
    return 0;
1270
0
  }
1271
1272
0
  return decrypt_func(pub, key, rnd_ctx, rnd_func, label_length, label,
1273
0
          length, message, ciphertext);
1274
0
}
1275
1276
static int _wrap_nettle_pk_decrypt(gnutls_pk_algorithm_t algo,
1277
           gnutls_datum_t *plaintext,
1278
           const gnutls_datum_t *ciphertext,
1279
           const gnutls_pk_params_st *pk_params,
1280
           const gnutls_x509_spki_st *encrypt_params)
1281
0
{
1282
0
  int ret;
1283
0
  bool not_approved = false;
1284
0
  uint8_t *buf = NULL;
1285
1286
0
  FAIL_IF_LIB_ERROR;
1287
1288
0
  if (algo == GNUTLS_PK_RSA && encrypt_params->pk == GNUTLS_PK_RSA_OAEP) {
1289
0
    algo = GNUTLS_PK_RSA_OAEP;
1290
0
  }
1291
1292
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING, "pk::decrypt",
1293
0
              "pk::algorithm", CRAU_STRING,
1294
0
              gnutls_pk_get_name(algo), NULL);
1295
1296
0
  switch (algo) {
1297
0
  case GNUTLS_PK_RSA: {
1298
0
    struct rsa_private_key priv;
1299
0
    struct rsa_public_key pub;
1300
0
    size_t length;
1301
0
    nettle_random_func *random_func;
1302
0
    size_t bits;
1303
1304
0
    if (!_gnutls_config_is_rsa_pkcs1_encrypt_allowed()) {
1305
0
      ret = gnutls_assert_val(
1306
0
        GNUTLS_E_UNSUPPORTED_ENCRYPTION_ALGORITHM);
1307
0
      goto cleanup;
1308
0
    }
1309
1310
    /* RSA decryption with PKCS#1 v1.5 padding is not approved */
1311
0
    not_approved = true;
1312
1313
0
    _rsa_params_to_privkey(pk_params, &priv);
1314
0
    ret = _rsa_params_to_pubkey(pk_params, &pub);
1315
0
    if (ret < 0) {
1316
0
      gnutls_assert();
1317
0
      goto cleanup;
1318
0
    }
1319
1320
0
    bits = mpz_sizeinbase(pub.n, 2);
1321
1322
0
    _gnutls_audit_data("pk::bits", CRAU_WORD, bits, NULL);
1323
1324
0
    if (ciphertext->size != pub.size) {
1325
0
      ret = gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED);
1326
0
      goto cleanup;
1327
0
    }
1328
1329
0
    length = pub.size;
1330
0
    buf = gnutls_malloc(length);
1331
0
    if (!buf) {
1332
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
1333
0
      goto cleanup;
1334
0
    }
1335
1336
0
    if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST)
1337
0
      random_func = rnd_nonce_func_fallback;
1338
0
    else
1339
0
      random_func = rnd_nonce_func;
1340
0
    ret = _rsa_decrypt_tr(&pub, &priv, NULL, random_func, &length,
1341
0
              buf, ciphertext->data);
1342
1343
0
    if (ret == 0 || HAVE_LIB_ERROR()) {
1344
0
      ret = gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED);
1345
0
      goto cleanup;
1346
0
    }
1347
1348
0
    plaintext->data = buf;
1349
0
    buf = NULL;
1350
0
    plaintext->size = length;
1351
0
    break;
1352
0
  }
1353
0
  case GNUTLS_PK_RSA_OAEP: {
1354
0
    struct rsa_private_key priv;
1355
0
    struct rsa_public_key pub;
1356
0
    size_t length;
1357
0
    nettle_random_func *random_func;
1358
0
    size_t bits;
1359
1360
0
    _rsa_params_to_privkey(pk_params, &priv);
1361
0
    ret = _rsa_params_to_pubkey(pk_params, &pub);
1362
0
    if (ret < 0) {
1363
0
      gnutls_assert();
1364
0
      goto cleanup;
1365
0
    }
1366
1367
0
    bits = mpz_sizeinbase(pub.n, 2);
1368
1369
0
    _gnutls_audit_data(
1370
0
      "pk::bits", CRAU_WORD, bits, "pk::hash", CRAU_STRING,
1371
0
      gnutls_digest_get_name(encrypt_params->rsa_oaep_dig),
1372
0
      NULL);
1373
1374
0
    if (ciphertext->size != pub.size) {
1375
0
      ret = gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED);
1376
0
      goto cleanup;
1377
0
    }
1378
1379
0
    length = pub.size;
1380
0
    buf = gnutls_malloc(length);
1381
0
    if (!buf) {
1382
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
1383
0
      goto cleanup;
1384
0
    }
1385
1386
0
    if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST)
1387
0
      random_func = rnd_nonce_func_fallback;
1388
0
    else
1389
0
      random_func = rnd_nonce_func;
1390
0
    ret = _rsa_oaep_decrypt(encrypt_params->rsa_oaep_dig, &pub,
1391
0
          &priv, NULL, random_func,
1392
0
          encrypt_params->rsa_oaep_label.size,
1393
0
          encrypt_params->rsa_oaep_label.data,
1394
0
          &length, buf, ciphertext->data);
1395
1396
0
    if (ret == 0 || HAVE_LIB_ERROR()) {
1397
0
      ret = gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED);
1398
0
      goto cleanup;
1399
0
    }
1400
1401
0
    plaintext->data = buf;
1402
0
    buf = NULL;
1403
0
    plaintext->size = length;
1404
0
    break;
1405
0
  }
1406
0
  default:
1407
0
    gnutls_assert();
1408
0
    ret = GNUTLS_E_INTERNAL_ERROR;
1409
0
    goto cleanup;
1410
0
  }
1411
1412
0
  ret = 0;
1413
1414
0
cleanup:
1415
0
  gnutls_free(buf);
1416
0
  if (ret < 0) {
1417
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
1418
0
  } else if (not_approved) {
1419
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_NOT_APPROVED);
1420
0
  } else {
1421
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_APPROVED);
1422
0
  }
1423
1424
0
  gnutls_audit_pop_context();
1425
1426
0
  FAIL_IF_LIB_ERROR;
1427
0
  return ret;
1428
0
}
1429
1430
/* This wraps nettle_rsa_sec_decrypt so it takes ciphertext as a byte
1431
 * array instead of a mpz_t value.  Returns 1 on success; 0 otherwise.
1432
 */
1433
static inline int _rsa_sec_decrypt(const struct rsa_public_key *pub,
1434
           const struct rsa_private_key *key,
1435
           void *rnd_ctx, nettle_random_func *rnd_func,
1436
           size_t length, uint8_t *message,
1437
           const uint8_t *ciphertext)
1438
0
{
1439
0
  bigint_t c;
1440
0
  int ret;
1441
1442
0
  if (_gnutls_mpi_init_scan_nz(&c, ciphertext, pub->size) < 0) {
1443
0
    gnutls_assert();
1444
0
    return 0;
1445
0
  }
1446
1447
0
  ret = rsa_sec_decrypt(pub, key, rnd_ctx, rnd_func, length, message, c);
1448
1449
0
  _gnutls_mpi_release(&c);
1450
1451
0
  return ret;
1452
0
}
1453
1454
/* Note: we do not allocate in this function to avoid asymettric
1455
 * unallocation (which creates a side channel) in case of failure
1456
 * */
1457
static int _wrap_nettle_pk_decrypt2(gnutls_pk_algorithm_t algo,
1458
            const gnutls_datum_t *ciphertext,
1459
            unsigned char *plaintext,
1460
            size_t plaintext_size,
1461
            const gnutls_pk_params_st *pk_params,
1462
            const gnutls_x509_spki_st *encrypt_params)
1463
0
{
1464
0
  struct rsa_private_key priv;
1465
0
  struct rsa_public_key pub;
1466
0
  uint32_t is_err;
1467
0
  int ret;
1468
0
  nettle_random_func *random_func;
1469
0
  bool not_approved = false;
1470
0
  size_t bits;
1471
1472
0
  FAIL_IF_LIB_ERROR;
1473
1474
0
  if ((algo != GNUTLS_PK_RSA && algo != GNUTLS_PK_RSA_OAEP) ||
1475
0
      plaintext == NULL) {
1476
0
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
1477
0
    goto fail;
1478
0
  }
1479
1480
0
  if (encrypt_params->pk == GNUTLS_PK_RSA_OAEP) {
1481
0
    algo = GNUTLS_PK_RSA_OAEP;
1482
0
  }
1483
1484
0
  _rsa_params_to_privkey(pk_params, &priv);
1485
0
  ret = _rsa_params_to_pubkey(pk_params, &pub);
1486
0
  if (ret < 0) {
1487
0
    gnutls_assert();
1488
0
    goto fail;
1489
0
  }
1490
1491
0
  bits = mpz_sizeinbase(pub.n, 2);
1492
1493
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING, "pk::decrypt",
1494
0
              "pk::algorithm", CRAU_STRING,
1495
0
              gnutls_pk_get_name(algo),
1496
0
              "pk::bits", CRAU_WORD, bits, NULL);
1497
1498
0
  if (ciphertext->size != pub.size) {
1499
0
    ret = gnutls_assert_val(GNUTLS_E_DECRYPTION_FAILED);
1500
0
    goto fail;
1501
0
  }
1502
1503
0
  if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST)
1504
0
    random_func = rnd_nonce_func_fallback;
1505
0
  else
1506
0
    random_func = rnd_nonce_func;
1507
1508
0
  switch (algo) {
1509
0
  case GNUTLS_PK_RSA:
1510
0
    if (!_gnutls_config_is_rsa_pkcs1_encrypt_allowed()) {
1511
0
      ret = gnutls_assert_val(
1512
0
        GNUTLS_E_UNSUPPORTED_ENCRYPTION_ALGORITHM);
1513
0
      goto fail;
1514
0
    }
1515
1516
    /* RSA decryption with PKCS#1 v1.5 padding is not approved */
1517
0
    not_approved = true;
1518
1519
0
    ret = _rsa_sec_decrypt(&pub, &priv, NULL, random_func,
1520
0
               plaintext_size, plaintext,
1521
0
               ciphertext->data);
1522
0
    break;
1523
0
  case GNUTLS_PK_RSA_OAEP:
1524
0
    _gnutls_audit_data(
1525
0
      "pk::hash", CRAU_STRING,
1526
0
      gnutls_digest_get_name(encrypt_params->rsa_oaep_dig),
1527
0
      NULL);
1528
1529
0
    ret = _rsa_oaep_decrypt(encrypt_params->rsa_oaep_dig, &pub,
1530
0
          &priv, NULL, random_func,
1531
0
          encrypt_params->rsa_oaep_label.size,
1532
0
          encrypt_params->rsa_oaep_label.data,
1533
0
          &plaintext_size, plaintext,
1534
0
          ciphertext->data);
1535
0
    break;
1536
0
  default:
1537
0
    gnutls_assert();
1538
0
    ret = GNUTLS_E_INTERNAL_ERROR;
1539
0
    goto fail;
1540
0
  }
1541
1542
  /* The decrypt operation is infallible; treat the approved
1543
   * operation as complete at this point, regardless of any
1544
   * decryption failure detected below.
1545
   */
1546
0
  _gnutls_switch_fips_state(not_approved ?
1547
0
            GNUTLS_FIPS140_OP_NOT_APPROVED :
1548
0
            GNUTLS_FIPS140_OP_APPROVED);
1549
1550
  /* after this point, any conditional on failure that cause differences
1551
   * in execution may create a timing or cache access pattern side
1552
   * channel that can be used as an oracle, so thread very carefully */
1553
1554
  /* Here HAVE_LIB_ERROR() should be fine as it doesn't have
1555
   * branches in it and returns a bool */
1556
0
  is_err = HAVE_LIB_ERROR();
1557
  /* if is_err != 0 */
1558
0
  is_err = CONSTCHECK_NOT_EQUAL(is_err, 0);
1559
  /* or ret == 0 */
1560
0
  is_err |= CONSTCHECK_EQUAL(ret, 0);
1561
  /* then return GNUTLS_E_DECRYPTION_FAILED */
1562
0
  return (int)((is_err * UINT_MAX) & GNUTLS_E_DECRYPTION_FAILED);
1563
1564
0
fail:
1565
0
  _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
1566
1567
0
  gnutls_audit_pop_context();
1568
1569
0
  return ret;
1570
0
}
1571
1572
#define CHECK_INVALID_RSA_PSS_PARAMS(dig_size, salt_size, pub_size, err) \
1573
0
  if (unlikely(dig_size + salt_size + 2 > pub_size))               \
1574
0
  return gnutls_assert_val(err)
1575
1576
static int _rsa_pss_sign_digest_tr(gnutls_digest_algorithm_t dig,
1577
           const struct rsa_public_key *pub,
1578
           const struct rsa_private_key *priv,
1579
           void *rnd_ctx, nettle_random_func *rnd_func,
1580
           size_t salt_size, const uint8_t *digest,
1581
           mpz_t s)
1582
0
{
1583
0
  int (*sign_func)(const struct rsa_public_key *,
1584
0
       const struct rsa_private_key *, void *,
1585
0
       nettle_random_func *, size_t, const uint8_t *,
1586
0
       const uint8_t *, mpz_t);
1587
0
  uint8_t *salt = NULL;
1588
0
  size_t hash_size;
1589
0
  int ret;
1590
1591
0
  switch (dig) {
1592
0
  case GNUTLS_DIG_SHA256:
1593
0
    sign_func = rsa_pss_sha256_sign_digest_tr;
1594
0
    hash_size = 32;
1595
0
    break;
1596
0
  case GNUTLS_DIG_SHA384:
1597
0
    sign_func = rsa_pss_sha384_sign_digest_tr;
1598
0
    hash_size = 48;
1599
0
    break;
1600
0
  case GNUTLS_DIG_SHA512:
1601
0
    sign_func = rsa_pss_sha512_sign_digest_tr;
1602
0
    hash_size = 64;
1603
0
    break;
1604
0
  default:
1605
0
    gnutls_assert();
1606
0
    return GNUTLS_E_UNKNOWN_ALGORITHM;
1607
0
  }
1608
1609
  /* This is also checked in pss_encode_mgf1, but error out earlier.  */
1610
0
  CHECK_INVALID_RSA_PSS_PARAMS(hash_size, salt_size, pub->size,
1611
0
             GNUTLS_E_PK_INVALID_PUBKEY_PARAMS);
1612
1613
0
  if (salt_size > 0) {
1614
0
    salt = gnutls_malloc(salt_size);
1615
0
    if (salt == NULL)
1616
0
      return gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
1617
1618
0
    rnd_func(NULL, salt_size, salt);
1619
0
  }
1620
1621
0
  ret = sign_func(pub, priv, rnd_ctx, rnd_func, salt_size, salt, digest,
1622
0
      s);
1623
0
  if (ret == 0) {
1624
0
    gnutls_assert();
1625
0
    ret = GNUTLS_E_PK_SIGN_FAILED;
1626
0
  } else
1627
0
    ret = 0;
1628
1629
0
  gnutls_free(salt);
1630
0
  return ret;
1631
0
}
1632
1633
static inline gnutls_ecc_curve_t get_eddsa_curve(gnutls_pk_algorithm_t algo)
1634
0
{
1635
0
  switch (algo) {
1636
0
  case GNUTLS_PK_EDDSA_ED25519:
1637
0
    return GNUTLS_ECC_CURVE_ED25519;
1638
0
  case GNUTLS_PK_EDDSA_ED448:
1639
0
    return GNUTLS_ECC_CURVE_ED448;
1640
0
  default:
1641
0
    return gnutls_assert_val(GNUTLS_ECC_CURVE_INVALID);
1642
0
  }
1643
0
}
1644
1645
static inline gnutls_ecc_curve_t get_ecdh_curve(gnutls_pk_algorithm_t algo)
1646
0
{
1647
0
  switch (algo) {
1648
0
  case GNUTLS_PK_ECDH_X25519:
1649
0
    return GNUTLS_ECC_CURVE_X25519;
1650
0
  case GNUTLS_PK_ECDH_X448:
1651
0
    return GNUTLS_ECC_CURVE_X448;
1652
0
  default:
1653
0
    return gnutls_assert_val(GNUTLS_ECC_CURVE_INVALID);
1654
0
  }
1655
0
}
1656
1657
static inline int eddsa_sign(gnutls_pk_algorithm_t algo, const uint8_t *pub,
1658
           const uint8_t *priv, size_t length,
1659
           const uint8_t *msg, uint8_t *signature)
1660
0
{
1661
0
  switch (algo) {
1662
0
  case GNUTLS_PK_EDDSA_ED25519:
1663
0
    ed25519_sha512_sign(pub, priv, length, msg, signature);
1664
0
    return 0;
1665
0
  case GNUTLS_PK_EDDSA_ED448:
1666
0
    ed448_shake256_sign(pub, priv, length, msg, signature);
1667
0
    return 0;
1668
0
  default:
1669
0
    return gnutls_assert_val(
1670
0
      GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
1671
0
  }
1672
0
}
1673
1674
#ifdef HAVE_LEANCRYPTO
1675
static enum lc_dilithium_type
1676
ml_dsa_pk_to_lc_dilithium_type(gnutls_pk_algorithm_t algo)
1677
{
1678
  switch (algo) {
1679
#ifdef LC_DILITHIUM_44_ENABLED
1680
  case GNUTLS_PK_MLDSA44:
1681
    return LC_DILITHIUM_44;
1682
#endif
1683
#ifdef LC_DILITHIUM_65_ENABLED
1684
  case GNUTLS_PK_MLDSA65:
1685
    return LC_DILITHIUM_65;
1686
#endif
1687
#ifdef LC_DILITHIUM_87_ENABLED
1688
  case GNUTLS_PK_MLDSA87:
1689
    return LC_DILITHIUM_87;
1690
#endif
1691
  default:
1692
    return gnutls_assert_val(LC_DILITHIUM_UNKNOWN);
1693
  }
1694
}
1695
1696
static int ml_dsa_exists(gnutls_pk_algorithm_t algo)
1697
{
1698
  return ml_dsa_pk_to_lc_dilithium_type(algo) != LC_DILITHIUM_UNKNOWN;
1699
}
1700
1701
static int ml_dsa_sign(gnutls_pk_algorithm_t algo, gnutls_datum_t *signature,
1702
           const gnutls_datum_t *message,
1703
           const gnutls_datum_t *raw_priv)
1704
{
1705
  int ret;
1706
  enum lc_dilithium_type type;
1707
  struct lc_dilithium_sk sk;
1708
  struct lc_dilithium_sig sig;
1709
  gnutls_datum_t tmp_signature = { NULL, 0 };
1710
  uint8_t *ptr;
1711
  size_t len;
1712
1713
  type = ml_dsa_pk_to_lc_dilithium_type(algo);
1714
  if (type == LC_DILITHIUM_UNKNOWN)
1715
    return gnutls_assert_val(
1716
      GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
1717
1718
  ret = lc_dilithium_sk_load(&sk, raw_priv->data, raw_priv->size);
1719
  if (ret < 0 || lc_dilithium_sk_type(&sk) != type) {
1720
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
1721
    goto cleanup;
1722
  }
1723
1724
  ret = lc_dilithium_sign(&sig, message->data, message->size, &sk,
1725
        lc_seeded_rng);
1726
  if (ret < 0) {
1727
    ret = gnutls_assert_val(GNUTLS_E_PK_SIGN_FAILED);
1728
    goto cleanup;
1729
  }
1730
1731
  ret = lc_dilithium_sig_ptr(&ptr, &len, &sig);
1732
  if (ret < 0) {
1733
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
1734
    goto cleanup;
1735
  }
1736
  ret = _gnutls_set_datum(&tmp_signature, ptr, len);
1737
  if (ret < 0)
1738
    goto cleanup;
1739
1740
  *signature = _gnutls_take_datum(&tmp_signature);
1741
1742
  ret = 0;
1743
1744
cleanup:
1745
  _gnutls_free_datum(&tmp_signature);
1746
  zeroize_key(&sk, sizeof(sk));
1747
  return ret;
1748
}
1749
1750
static int ml_dsa_verify(gnutls_pk_algorithm_t algo,
1751
       const gnutls_datum_t *signature,
1752
       const gnutls_datum_t *message,
1753
       const gnutls_datum_t *raw_pub)
1754
{
1755
  int ret;
1756
  enum lc_dilithium_type type;
1757
  struct lc_dilithium_sig sig;
1758
  struct lc_dilithium_pk pk;
1759
1760
  type = ml_dsa_pk_to_lc_dilithium_type(algo);
1761
  if (type == LC_DILITHIUM_UNKNOWN)
1762
    return gnutls_assert_val(
1763
      GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
1764
1765
  ret = lc_dilithium_pk_load(&pk, raw_pub->data, raw_pub->size);
1766
  if (ret < 0 || lc_dilithium_pk_type(&pk) != type) {
1767
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
1768
    goto cleanup;
1769
  }
1770
1771
  ret = lc_dilithium_sig_load(&sig, signature->data, signature->size);
1772
  if (ret < 0 || lc_dilithium_sig_type(&sig) != type) {
1773
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
1774
    goto cleanup;
1775
  }
1776
1777
  ret = lc_dilithium_verify(&sig, message->data, message->size, &pk);
1778
  if (ret < 0) {
1779
    ret = gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
1780
    goto cleanup;
1781
  }
1782
1783
  ret = 0;
1784
1785
cleanup:
1786
  zeroize_key(&pk, sizeof(pk));
1787
  return ret;
1788
}
1789
1790
static int ml_dsa_generate_keypair(gnutls_pk_algorithm_t algo,
1791
           gnutls_datum_t *raw_priv,
1792
           gnutls_datum_t *raw_pub,
1793
           const gnutls_datum_t *raw_seed)
1794
{
1795
  int ret;
1796
  enum lc_dilithium_type type;
1797
  struct lc_dilithium_sk sk;
1798
  struct lc_dilithium_pk pk;
1799
  gnutls_datum_t tmp_raw_priv = { NULL, 0 };
1800
  gnutls_datum_t tmp_raw_pub = { NULL, 0 };
1801
  uint8_t *ptr;
1802
  size_t len;
1803
1804
  type = ml_dsa_pk_to_lc_dilithium_type(algo);
1805
  if (type == LC_DILITHIUM_UNKNOWN)
1806
    return gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
1807
1808
  ret = lc_dilithium_keypair_from_seed(&pk, &sk, raw_seed->data,
1809
               raw_seed->size, type);
1810
  if (ret < 0) {
1811
    ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
1812
    goto cleanup;
1813
  }
1814
1815
  ret = lc_dilithium_sk_ptr(&ptr, &len, &sk);
1816
  if (ret < 0) {
1817
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
1818
    goto cleanup;
1819
  }
1820
1821
  ret = _gnutls_set_datum(&tmp_raw_priv, ptr, len);
1822
  if (ret < 0) {
1823
    gnutls_assert();
1824
    goto cleanup;
1825
  }
1826
1827
  ret = lc_dilithium_pk_ptr(&ptr, &len, &pk);
1828
  if (ret < 0) {
1829
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
1830
    goto cleanup;
1831
  }
1832
1833
  ret = _gnutls_set_datum(&tmp_raw_pub, ptr, len);
1834
  if (ret < 0) {
1835
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
1836
    goto cleanup;
1837
  }
1838
1839
  *raw_priv = _gnutls_take_datum(&tmp_raw_priv);
1840
  *raw_pub = _gnutls_take_datum(&tmp_raw_pub);
1841
1842
  ret = 0;
1843
1844
cleanup:
1845
  _gnutls_free_key_datum(&tmp_raw_priv);
1846
  _gnutls_free_key_datum(&tmp_raw_pub);
1847
  zeroize_key(&pk, sizeof(pk));
1848
  zeroize_key(&sk, sizeof(sk));
1849
  return ret;
1850
}
1851
1852
#ifdef HAVE_LC_DILITHIUM_PK_FROM_SK
1853
static int ml_dsa_privkey_to_pubkey(gnutls_pk_algorithm_t algo,
1854
            const gnutls_datum_t *raw_priv,
1855
            gnutls_datum_t *raw_pub)
1856
{
1857
  int ret;
1858
  enum lc_dilithium_type type;
1859
  struct lc_dilithium_sk sk;
1860
  struct lc_dilithium_pk pk;
1861
  gnutls_datum_t tmp_raw_pub = { NULL, 0 };
1862
  uint8_t *ptr;
1863
  size_t len;
1864
1865
  type = ml_dsa_pk_to_lc_dilithium_type(algo);
1866
  if (type == LC_DILITHIUM_UNKNOWN)
1867
    return gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
1868
1869
  ret = lc_dilithium_sk_load(&sk, raw_priv->data, raw_priv->size);
1870
  if (ret < 0 || lc_dilithium_sk_type(&sk) != type) {
1871
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
1872
    goto cleanup;
1873
  }
1874
1875
  ret = lc_dilithium_pk_from_sk(&pk, &sk);
1876
  if (ret < 0) {
1877
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
1878
    goto cleanup;
1879
  }
1880
1881
  ret = lc_dilithium_pk_ptr(&ptr, &len, &pk);
1882
  if (ret < 0) {
1883
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
1884
    goto cleanup;
1885
  }
1886
1887
  ret = _gnutls_set_datum(&tmp_raw_pub, ptr, len);
1888
  if (ret < 0) {
1889
    ret = gnutls_assert_val(GNUTLS_E_INTERNAL_ERROR);
1890
    goto cleanup;
1891
  }
1892
1893
  *raw_pub = _gnutls_take_datum(&tmp_raw_pub);
1894
1895
  ret = 0;
1896
1897
cleanup:
1898
  _gnutls_free_key_datum(&tmp_raw_pub);
1899
  zeroize_key(&pk, sizeof(pk));
1900
  zeroize_key(&sk, sizeof(sk));
1901
  return ret;
1902
}
1903
#else /* !HAVE_LC_DILITHIUM_PK_FROM_SK */
1904
static int ml_dsa_privkey_to_pubkey(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
1905
            const gnutls_datum_t *raw_priv MAYBE_UNUSED,
1906
            gnutls_datum_t *raw_pub MAYBE_UNUSED)
1907
{
1908
  return gnutls_assert_val(GNUTLS_E_UNIMPLEMENTED_FEATURE);
1909
}
1910
#endif
1911
#else /* !HAVE_LEANCRYPTO */
1912
static int ml_dsa_exists(gnutls_pk_algorithm_t algo MAYBE_UNUSED)
1913
0
{
1914
0
  return 0;
1915
0
}
1916
1917
static int ml_dsa_sign(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
1918
           gnutls_datum_t *signature MAYBE_UNUSED,
1919
           const gnutls_datum_t *message MAYBE_UNUSED,
1920
           const gnutls_datum_t *raw_priv MAYBE_UNUSED)
1921
0
{
1922
0
  return gnutls_assert_val(GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
1923
0
}
1924
1925
static int ml_dsa_verify(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
1926
       const gnutls_datum_t *signature MAYBE_UNUSED,
1927
       const gnutls_datum_t *message MAYBE_UNUSED,
1928
       const gnutls_datum_t *raw_pub MAYBE_UNUSED)
1929
0
{
1930
0
  return gnutls_assert_val(GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
1931
0
}
1932
1933
static int ml_dsa_generate_keypair(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
1934
           gnutls_datum_t *raw_priv MAYBE_UNUSED,
1935
           gnutls_datum_t *raw_pub MAYBE_UNUSED,
1936
           const gnutls_datum_t *raw_seed MAYBE_UNUSED)
1937
0
{
1938
0
  return gnutls_assert_val(GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
1939
0
}
1940
1941
static int ml_dsa_privkey_to_pubkey(gnutls_pk_algorithm_t algo MAYBE_UNUSED,
1942
            const gnutls_datum_t *raw_priv MAYBE_UNUSED,
1943
            gnutls_datum_t *raw_pub MAYBE_UNUSED)
1944
0
{
1945
0
  return gnutls_assert_val(GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
1946
0
}
1947
#endif
1948
1949
/* This is the lower-level part of privkey_sign_raw_data().
1950
 *
1951
 * It accepts data in the appropriate hash form, i.e., DigestInfo
1952
 * for PK_RSA, hash for PK_ECDSA, PK_DSA, PK_RSA_PSS, and raw data
1953
 * for Ed25519 and Ed448.
1954
 *
1955
 * in case of EC/DSA, signed data are encoded into r,s values
1956
 */
1957
static int _wrap_nettle_pk_sign(gnutls_pk_algorithm_t algo,
1958
        gnutls_datum_t *signature,
1959
        const gnutls_datum_t *vdata,
1960
        const gnutls_pk_params_st *pk_params,
1961
        const gnutls_x509_spki_st *sign_params)
1962
0
{
1963
0
  int ret;
1964
0
  unsigned int hash_len;
1965
0
  const mac_entry_st *me;
1966
0
  bool not_approved = false;
1967
1968
0
  FAIL_IF_LIB_ERROR;
1969
1970
  /* check if the curve relates to the algorithm used */
1971
0
  if (IS_EC(algo) && gnutls_ecc_curve_get_pk(pk_params->curve) != algo) {
1972
0
    ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
1973
0
    goto cleanup;
1974
0
  }
1975
1976
  /* deterministic ECDSA/DSA is prohibited under FIPS except in
1977
   * the selftests */
1978
0
  if ((algo == GNUTLS_PK_DSA || algo == GNUTLS_PK_ECDSA) &&
1979
0
      (sign_params->flags & GNUTLS_PK_FLAG_REPRODUCIBLE) &&
1980
0
      _gnutls_fips_mode_enabled() &&
1981
0
      _gnutls_get_lib_state() != LIB_STATE_SELFTEST) {
1982
0
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
1983
0
    goto cleanup;
1984
0
  }
1985
1986
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING, "pk::sign",
1987
0
              "pk::algorithm", CRAU_STRING,
1988
0
              gnutls_pk_get_name(algo), NULL);
1989
1990
0
  switch (algo) {
1991
0
  case GNUTLS_PK_EDDSA_ED25519: /* we do EdDSA */
1992
0
  case GNUTLS_PK_EDDSA_ED448: {
1993
0
    const gnutls_ecc_curve_entry_st *e;
1994
1995
0
    if (unlikely(get_eddsa_curve(algo) != pk_params->curve)) {
1996
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
1997
0
      goto cleanup;
1998
0
    }
1999
2000
0
    e = _gnutls_ecc_curve_get_params(pk_params->curve);
2001
0
    if (e == NULL) {
2002
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
2003
0
      goto cleanup;
2004
0
    }
2005
2006
0
    signature->data = gnutls_malloc(e->sig_size);
2007
0
    if (signature->data == NULL) {
2008
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
2009
0
      goto cleanup;
2010
0
    }
2011
2012
0
    signature->size = e->sig_size;
2013
2014
0
    if (pk_params->raw_pub.size != e->size ||
2015
0
        pk_params->raw_priv.size != e->size) {
2016
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIGN_FAILED);
2017
0
      goto cleanup;
2018
0
    }
2019
2020
0
    ret = eddsa_sign(algo, pk_params->raw_pub.data,
2021
0
         pk_params->raw_priv.data, vdata->size,
2022
0
         vdata->data, signature->data);
2023
0
    if (ret < 0)
2024
0
      goto cleanup;
2025
2026
0
    break;
2027
0
  }
2028
0
#if ENABLE_GOST
2029
0
  case GNUTLS_PK_GOST_01:
2030
0
  case GNUTLS_PK_GOST_12_256:
2031
0
  case GNUTLS_PK_GOST_12_512: {
2032
0
    struct ecc_scalar priv;
2033
0
    struct dsa_signature sig;
2034
0
    const struct ecc_curve *curve;
2035
2036
    /* GOSTDSA is not approved */
2037
0
    not_approved = true;
2038
2039
0
    curve = get_supported_gost_curve(pk_params->curve);
2040
0
    if (curve == NULL) {
2041
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
2042
0
      goto cleanup;
2043
0
    }
2044
2045
0
    _gnutls_audit_data("pk::curve", CRAU_STRING,
2046
0
           gnutls_ecc_curve_get_name(pk_params->curve),
2047
0
           NULL);
2048
2049
0
    ret = _ecc_params_to_privkey(pk_params, &priv, curve);
2050
0
    if (ret < 0) {
2051
0
      gnutls_assert();
2052
0
      goto cleanup;
2053
0
    }
2054
2055
    /* This call will return a valid MAC entry and
2056
     * getters will check that is not null anyway. */
2057
0
    me = hash_to_entry(_gnutls_gost_digest(pk_params->algo));
2058
0
    if (_gnutls_mac_get_algo_len(me) != vdata->size) {
2059
0
      _gnutls_debug_log(
2060
0
        "Security level of algorithm requires hash %s(%zd)\n",
2061
0
        _gnutls_mac_get_name(me),
2062
0
        _gnutls_mac_get_algo_len(me));
2063
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
2064
0
      goto cleanup;
2065
0
    }
2066
2067
0
    dsa_signature_init(&sig);
2068
2069
0
    gostdsa_sign(&priv, NULL, rnd_tmpkey_func, vdata->size,
2070
0
           vdata->data, &sig);
2071
2072
0
    ret = _gnutls_encode_gost_rs(signature, &sig.r, &sig.s,
2073
0
               (ecc_bit_size(curve) + 7) / 8);
2074
2075
0
    dsa_signature_clear(&sig);
2076
0
    ecc_scalar_zclear(&priv);
2077
2078
0
    if (ret < 0) {
2079
0
      gnutls_assert();
2080
0
      goto cleanup;
2081
0
    }
2082
0
    break;
2083
0
  }
2084
0
#endif
2085
0
  case GNUTLS_PK_ECDSA: /* we do ECDSA */
2086
0
  {
2087
0
    struct ecc_scalar priv;
2088
0
    struct dsa_signature sig;
2089
0
    int curve_id = pk_params->curve;
2090
0
    const struct ecc_curve *curve;
2091
0
    mpz_t q;
2092
    /* 521-bit elliptic curve generator at maximum */
2093
0
    uint8_t buf[(521 + 7) / 8];
2094
0
    gnutls_datum_t k = { NULL, 0 };
2095
0
    void *random_ctx;
2096
0
    nettle_random_func *random_func;
2097
2098
0
    curve = get_supported_nist_curve(curve_id);
2099
0
    if (curve == NULL) {
2100
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
2101
0
      goto cleanup;
2102
0
    }
2103
2104
    /* P-192 is not supported in FIPS 140-3 */
2105
0
    if (curve_id == GNUTLS_ECC_CURVE_SECP192R1) {
2106
0
      not_approved = true;
2107
0
    }
2108
2109
0
    ret = _ecc_params_to_privkey(pk_params, &priv, curve);
2110
0
    if (ret < 0) {
2111
0
      gnutls_assert();
2112
0
      goto cleanup;
2113
0
    }
2114
2115
0
    dsa_signature_init(&sig);
2116
2117
0
    me = _gnutls_dsa_q_to_hash(pk_params, &hash_len);
2118
2119
0
    if (hash_len > vdata->size) {
2120
0
      gnutls_assert();
2121
0
      _gnutls_debug_log(
2122
0
        "Security level of algorithm requires hash %s(%d) or better\n",
2123
0
        _gnutls_mac_get_name(me), hash_len);
2124
0
      hash_len = vdata->size;
2125
0
    }
2126
2127
    /* Only SHA-2 is allowed in FIPS 140-3 */
2128
0
    switch (DIG_TO_MAC(sign_params->dsa_dig)) {
2129
0
    case GNUTLS_MAC_SHA256:
2130
0
    case GNUTLS_MAC_SHA384:
2131
0
    case GNUTLS_MAC_SHA512:
2132
0
    case GNUTLS_MAC_SHA224:
2133
0
      break;
2134
0
    default:
2135
0
      not_approved = true;
2136
0
    }
2137
2138
0
    _gnutls_audit_data("pk::curve", CRAU_STRING,
2139
0
           gnutls_ecc_curve_get_name(curve_id),
2140
0
           "pk::hash", CRAU_STRING,
2141
0
           _gnutls_mac_get_name(me), NULL);
2142
2143
0
    mpz_init(q);
2144
2145
0
    if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST ||
2146
0
        (sign_params->flags & GNUTLS_PK_FLAG_REPRODUCIBLE)) {
2147
0
      mp_limb_t h[DSA_COMPUTE_K_ITCH];
2148
2149
0
      ret = _gnutls_ecc_curve_to_dsa_q(q, curve_id);
2150
0
      if (ret < 0)
2151
0
        goto ecdsa_cleanup;
2152
2153
0
      ret = _gnutls_dsa_compute_k(
2154
0
        h, mpz_limbs_read(q), priv.p,
2155
0
        ecc_size(priv.ecc), ecc_bit_size(priv.ecc),
2156
0
        DIG_TO_MAC(sign_params->dsa_dig), vdata->data,
2157
0
        vdata->size);
2158
0
      if (ret < 0)
2159
0
        goto ecdsa_cleanup;
2160
2161
0
      k.data = buf;
2162
0
      k.size = (ecc_bit_size(priv.ecc) + 7) / 8;
2163
2164
0
      _gnutls_ecdsa_compute_k_finish(k.data, k.size, h,
2165
0
                   ecc_size(priv.ecc));
2166
2167
0
      random_ctx = &k;
2168
0
      random_func = rnd_datum_func;
2169
0
    } else {
2170
0
      random_ctx = NULL;
2171
0
      random_func = rnd_nonce_func;
2172
0
    }
2173
0
    ecdsa_sign(&priv, random_ctx, random_func, hash_len,
2174
0
         vdata->data, &sig);
2175
2176
    /* prevent memory leaks */
2177
0
    if (HAVE_LIB_ERROR()) {
2178
0
      ret = GNUTLS_E_LIB_IN_ERROR_STATE;
2179
0
      goto ecdsa_cleanup;
2180
0
    }
2181
2182
0
    ret = _gnutls_encode_ber_rs(signature, &sig.r, &sig.s);
2183
2184
0
  ecdsa_cleanup:
2185
0
    dsa_signature_clear(&sig);
2186
0
    ecc_scalar_zclear(&priv);
2187
0
    mpz_clear(q);
2188
2189
0
    if (ret < 0) {
2190
0
      gnutls_assert();
2191
0
      goto cleanup;
2192
0
    }
2193
0
    break;
2194
0
  }
2195
0
#ifdef ENABLE_DSA
2196
0
  case GNUTLS_PK_DSA: {
2197
0
    struct dsa_params pub;
2198
0
    bigint_t priv;
2199
0
    struct dsa_signature sig;
2200
    /* 512-bit DSA subgroup at maximum */
2201
0
    uint8_t buf[(512 + 7) / 8];
2202
0
    gnutls_datum_t k = { NULL, 0 };
2203
0
    void *random_ctx;
2204
0
    nettle_random_func *random_func;
2205
0
    size_t bits;
2206
2207
    /* DSA is currently being defined as sunset with the
2208
     * current draft of FIPS 186-5 */
2209
0
    not_approved = true;
2210
2211
0
    memset(&priv, 0, sizeof(priv));
2212
0
    memset(&pub, 0, sizeof(pub));
2213
0
    _dsa_params_get(pk_params, &pub);
2214
2215
0
    priv = pk_params->params[DSA_X];
2216
2217
0
    dsa_signature_init(&sig);
2218
2219
0
    me = _gnutls_dsa_q_to_hash(pk_params, &hash_len);
2220
2221
0
    if (hash_len > vdata->size) {
2222
0
      gnutls_assert();
2223
0
      _gnutls_debug_log(
2224
0
        "Security level of algorithm requires hash %s(%d) or better (have: %d)\n",
2225
0
        _gnutls_mac_get_name(me), hash_len,
2226
0
        (int)vdata->size);
2227
0
      hash_len = vdata->size;
2228
0
    }
2229
2230
0
    bits = mpz_sizeinbase(pub.p, 2);
2231
0
    _gnutls_audit_data("pk::bits", CRAU_WORD, bits, NULL);
2232
2233
0
    if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST ||
2234
0
        (sign_params->flags & GNUTLS_PK_FLAG_REPRODUCIBLE)) {
2235
0
      mp_limb_t h[DSA_COMPUTE_K_ITCH];
2236
2237
0
      ret = _gnutls_dsa_compute_k(
2238
0
        h, mpz_limbs_read(pub.q),
2239
0
        mpz_limbs_read(TOMPZ(priv)), mpz_size(pub.q),
2240
0
        mpz_sizeinbase(pub.q, 2),
2241
0
        DIG_TO_MAC(sign_params->dsa_dig), vdata->data,
2242
0
        vdata->size);
2243
0
      if (ret < 0)
2244
0
        goto dsa_fail;
2245
2246
0
      k.data = buf;
2247
0
      k.size = (mpz_sizeinbase(pub.q, 2) + 7) / 8;
2248
2249
0
      _gnutls_dsa_compute_k_finish(k.data, k.size, h,
2250
0
                 mpz_size(pub.q));
2251
2252
0
      random_ctx = &k;
2253
0
      random_func = rnd_datum_func;
2254
0
    } else {
2255
0
      random_ctx = NULL;
2256
0
      random_func = rnd_nonce_func;
2257
0
    }
2258
0
    ret = dsa_sign(&pub, TOMPZ(priv), random_ctx, random_func,
2259
0
             hash_len, vdata->data, &sig);
2260
0
    if (ret == 0 || HAVE_LIB_ERROR()) {
2261
0
      gnutls_assert();
2262
0
      ret = GNUTLS_E_PK_SIGN_FAILED;
2263
0
      goto dsa_fail;
2264
0
    }
2265
2266
0
    ret = _gnutls_encode_ber_rs(signature, &sig.r, &sig.s);
2267
2268
0
  dsa_fail:
2269
0
    dsa_signature_clear(&sig);
2270
2271
0
    if (ret < 0) {
2272
0
      gnutls_assert();
2273
0
      goto cleanup;
2274
0
    }
2275
0
    break;
2276
0
  }
2277
0
#endif
2278
0
  case GNUTLS_PK_RSA: {
2279
0
    struct rsa_private_key priv;
2280
0
    struct rsa_public_key pub;
2281
0
    nettle_random_func *random_func;
2282
0
    mpz_t s;
2283
0
    size_t bits;
2284
2285
0
    _rsa_params_to_privkey(pk_params, &priv);
2286
2287
0
    ret = _rsa_params_to_pubkey(pk_params, &pub);
2288
0
    if (ret < 0) {
2289
0
      gnutls_assert();
2290
0
      goto cleanup;
2291
0
    }
2292
2293
0
    bits = mpz_sizeinbase(pub.n, 2);
2294
2295
    /* RSA modulus size should be 2048-bit or larger in FIPS
2296
     * 140-3.  In addition to this, only SHA-2 is allowed
2297
     * for SigGen; it is checked in pk_prepare_hash lib/pk.c
2298
     */
2299
0
    if (unlikely(bits < 2048)) {
2300
0
      not_approved = true;
2301
0
    }
2302
2303
0
    _gnutls_audit_data("pk::bits", CRAU_WORD, bits, NULL);
2304
2305
0
    mpz_init(s);
2306
2307
0
    if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST)
2308
0
      random_func = rnd_nonce_func_fallback;
2309
0
    else
2310
0
      random_func = rnd_nonce_func;
2311
0
    ret = rsa_pkcs1_sign_tr(&pub, &priv, NULL, random_func,
2312
0
          vdata->size, vdata->data, s);
2313
0
    if (ret == 0 || HAVE_LIB_ERROR()) {
2314
0
      gnutls_assert();
2315
0
      ret = GNUTLS_E_PK_SIGN_FAILED;
2316
0
      goto rsa_fail;
2317
0
    }
2318
2319
0
    ret = _gnutls_mpi_dprint_size(s, signature, pub.size);
2320
2321
0
  rsa_fail:
2322
0
    mpz_clear(s);
2323
2324
0
    if (ret < 0) {
2325
0
      gnutls_assert();
2326
0
      goto cleanup;
2327
0
    }
2328
2329
0
    break;
2330
0
  }
2331
0
  case GNUTLS_PK_RSA_PSS: {
2332
0
    struct rsa_private_key priv;
2333
0
    struct rsa_public_key pub;
2334
0
    nettle_random_func *random_func;
2335
0
    mpz_t s;
2336
0
    size_t bits;
2337
2338
0
    _rsa_params_to_privkey(pk_params, &priv);
2339
2340
0
    ret = _rsa_params_to_pubkey(pk_params, &pub);
2341
0
    if (ret < 0) {
2342
0
      gnutls_assert();
2343
0
      goto cleanup;
2344
0
    }
2345
2346
0
    bits = mpz_sizeinbase(pub.n, 2);
2347
2348
    /* RSA modulus size should be 2048-bit or larger in FIPS
2349
     * 140-3.  In addition to this, only SHA-2 is allowed
2350
     * for SigGen; however, Nettle only support SHA256,
2351
     * SHA384, and SHA512 for RSA-PSS (see
2352
     * _rsa_pss_sign_digest_tr in this file for details).
2353
     */
2354
0
    if (unlikely(bits < 2048)) {
2355
0
      not_approved = true;
2356
0
    }
2357
2358
0
    mpz_init(s);
2359
2360
0
    me = hash_to_entry(sign_params->rsa_pss_dig);
2361
2362
0
    _gnutls_audit_data("pk::bits", CRAU_WORD, bits, "pk::hash",
2363
0
           CRAU_STRING, _gnutls_mac_get_name(me), NULL);
2364
2365
    /* According to FIPS 186-5 5.4, the salt length must be
2366
     * in the range between 0 and the hash length inclusive.
2367
     */
2368
0
    if (sign_params->salt_size > _gnutls_mac_get_algo_len(me)) {
2369
0
      not_approved = true;
2370
0
    }
2371
2372
0
    if (_gnutls_get_lib_state() == LIB_STATE_SELFTEST)
2373
0
      random_func = rnd_nonce_func_fallback;
2374
0
    else
2375
0
      random_func = rnd_nonce_func;
2376
0
    ret = _rsa_pss_sign_digest_tr(sign_params->rsa_pss_dig, &pub,
2377
0
                &priv, NULL, random_func,
2378
0
                sign_params->salt_size,
2379
0
                vdata->data, s);
2380
0
    if (ret < 0) {
2381
0
      gnutls_assert();
2382
0
      ret = GNUTLS_E_PK_SIGN_FAILED;
2383
0
      goto rsa_pss_fail;
2384
0
    }
2385
2386
0
    ret = _gnutls_mpi_dprint_size(s, signature, pub.size);
2387
2388
0
  rsa_pss_fail:
2389
0
    mpz_clear(s);
2390
2391
0
    if (ret < 0) {
2392
0
      gnutls_assert();
2393
0
      goto cleanup;
2394
0
    }
2395
2396
0
    break;
2397
0
  }
2398
0
  case GNUTLS_PK_MLDSA44:
2399
0
  case GNUTLS_PK_MLDSA65:
2400
0
  case GNUTLS_PK_MLDSA87:
2401
0
    not_approved = true;
2402
0
    ret = ml_dsa_sign(algo, signature, vdata, &pk_params->raw_priv);
2403
0
    if (ret < 0)
2404
0
      goto cleanup;
2405
0
    break;
2406
0
  default:
2407
0
    gnutls_assert();
2408
0
    ret = GNUTLS_E_INTERNAL_ERROR;
2409
0
    goto cleanup;
2410
0
  }
2411
2412
0
  ret = 0;
2413
2414
0
cleanup:
2415
0
  if (ret < 0) {
2416
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
2417
0
  } else if (not_approved) {
2418
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_NOT_APPROVED);
2419
0
  } else {
2420
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_APPROVED);
2421
0
  }
2422
2423
0
  gnutls_audit_pop_context();
2424
2425
0
  FAIL_IF_LIB_ERROR;
2426
0
  return ret;
2427
0
}
2428
2429
static int _rsa_pss_verify_digest(gnutls_digest_algorithm_t dig,
2430
          const struct rsa_public_key *pub,
2431
          size_t salt_size, const uint8_t *digest,
2432
          size_t digest_size, const mpz_t s)
2433
0
{
2434
0
  int (*verify_func)(const struct rsa_public_key *, size_t,
2435
0
         const uint8_t *, const mpz_t);
2436
0
  size_t hash_size;
2437
2438
0
  switch (dig) {
2439
0
  case GNUTLS_DIG_SHA256:
2440
0
    verify_func = rsa_pss_sha256_verify_digest;
2441
0
    hash_size = 32;
2442
0
    break;
2443
0
  case GNUTLS_DIG_SHA384:
2444
0
    verify_func = rsa_pss_sha384_verify_digest;
2445
0
    hash_size = 48;
2446
0
    break;
2447
0
  case GNUTLS_DIG_SHA512:
2448
0
    verify_func = rsa_pss_sha512_verify_digest;
2449
0
    hash_size = 64;
2450
0
    break;
2451
0
  default:
2452
0
    gnutls_assert();
2453
0
    return 0;
2454
0
  }
2455
2456
0
  if (digest_size != hash_size)
2457
0
    return gnutls_assert_val(0);
2458
2459
0
  CHECK_INVALID_RSA_PSS_PARAMS(hash_size, salt_size, pub->size, 0);
2460
2461
0
  return verify_func(pub, salt_size, digest, s);
2462
0
}
2463
2464
static inline int eddsa_verify(gnutls_pk_algorithm_t algo, const uint8_t *pub,
2465
             size_t length, const uint8_t *msg,
2466
             const uint8_t *signature)
2467
0
{
2468
0
  int ret;
2469
2470
0
  switch (algo) {
2471
0
  case GNUTLS_PK_EDDSA_ED25519:
2472
0
    ret = ed25519_sha512_verify(pub, length, msg, signature);
2473
0
    if (ret == 0)
2474
0
      return gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2475
0
    return 0;
2476
0
  case GNUTLS_PK_EDDSA_ED448:
2477
0
    ret = ed448_shake256_verify(pub, length, msg, signature);
2478
0
    if (ret == 0)
2479
0
      return gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2480
0
    return 0;
2481
0
  default:
2482
0
    return gnutls_assert_val(
2483
0
      GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
2484
0
  }
2485
0
}
2486
2487
static int _wrap_nettle_pk_verify(gnutls_pk_algorithm_t algo,
2488
          const gnutls_datum_t *vdata,
2489
          const gnutls_datum_t *signature,
2490
          const gnutls_pk_params_st *pk_params,
2491
          const gnutls_x509_spki_st *sign_params)
2492
0
{
2493
0
  int ret;
2494
0
  unsigned int hash_len;
2495
0
  bigint_t tmp[2] = { NULL, NULL };
2496
0
  bool not_approved = false;
2497
2498
0
  FAIL_IF_LIB_ERROR;
2499
2500
  /* check if the curve relates to the algorithm used */
2501
0
  if (IS_EC(algo) && gnutls_ecc_curve_get_pk(pk_params->curve) != algo) {
2502
0
    ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
2503
0
    goto cleanup;
2504
0
  }
2505
2506
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING, "pk::verify",
2507
0
              "pk::algorithm", CRAU_STRING,
2508
0
              gnutls_pk_get_name(algo), NULL);
2509
2510
0
  switch (algo) {
2511
0
  case GNUTLS_PK_EDDSA_ED25519: /* we do EdDSA */
2512
0
  case GNUTLS_PK_EDDSA_ED448: {
2513
0
    const gnutls_ecc_curve_entry_st *e;
2514
2515
0
    if (unlikely(get_eddsa_curve(algo) != pk_params->curve)) {
2516
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
2517
0
      goto cleanup;
2518
0
    }
2519
2520
0
    e = _gnutls_ecc_curve_get_params(pk_params->curve);
2521
0
    if (e == NULL) {
2522
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
2523
0
      goto cleanup;
2524
0
    }
2525
2526
0
    if (signature->size != e->sig_size) {
2527
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2528
0
      goto cleanup;
2529
0
    }
2530
2531
0
    if (pk_params->raw_pub.size != e->size) {
2532
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIGN_FAILED);
2533
0
      goto cleanup;
2534
0
    }
2535
2536
0
    ret = eddsa_verify(algo, pk_params->raw_pub.data, vdata->size,
2537
0
           vdata->data, signature->data);
2538
0
    break;
2539
0
  }
2540
0
#if ENABLE_GOST
2541
0
  case GNUTLS_PK_GOST_01:
2542
0
  case GNUTLS_PK_GOST_12_256:
2543
0
  case GNUTLS_PK_GOST_12_512: {
2544
0
    struct ecc_point pub;
2545
0
    struct dsa_signature sig;
2546
0
    const struct ecc_curve *curve;
2547
0
    const mac_entry_st *me;
2548
2549
    /* GOSTDSA is not approved */
2550
0
    not_approved = true;
2551
2552
0
    curve = get_supported_gost_curve(pk_params->curve);
2553
0
    if (curve == NULL) {
2554
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
2555
0
      goto cleanup;
2556
0
    }
2557
2558
0
    _gnutls_audit_data("pk::curve", CRAU_STRING,
2559
0
           gnutls_ecc_curve_get_name(pk_params->curve),
2560
0
           NULL);
2561
2562
    /* This call will return a valid MAC entry and
2563
     * getters will check that is not null anyway. */
2564
0
    me = hash_to_entry(_gnutls_gost_digest(pk_params->algo));
2565
0
    if (_gnutls_mac_get_algo_len(me) != vdata->size) {
2566
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2567
0
      goto cleanup;
2568
0
    }
2569
2570
0
    ret = _gnutls_decode_gost_rs(signature, &tmp[0], &tmp[1]);
2571
0
    if (ret < 0) {
2572
0
      gnutls_assert();
2573
0
      goto cleanup;
2574
0
    }
2575
2576
0
    ret = _gost_params_to_pubkey(pk_params, &pub, curve);
2577
0
    if (ret < 0) {
2578
0
      gnutls_assert();
2579
0
      goto cleanup;
2580
0
    }
2581
2582
0
    memcpy(sig.r, tmp[0], SIZEOF_MPZT);
2583
0
    memcpy(sig.s, tmp[1], SIZEOF_MPZT);
2584
2585
0
    ret = gostdsa_verify(&pub, vdata->size, vdata->data, &sig);
2586
0
    if (ret == 0) {
2587
0
      gnutls_assert();
2588
0
      ret = GNUTLS_E_PK_SIG_VERIFY_FAILED;
2589
0
    } else
2590
0
      ret = 0;
2591
2592
0
    ecc_point_clear(&pub);
2593
0
    break;
2594
0
  }
2595
0
#endif
2596
0
  case GNUTLS_PK_ECDSA: /* ECDSA */
2597
0
  {
2598
0
    struct ecc_point pub;
2599
0
    struct dsa_signature sig;
2600
0
    int curve_id = pk_params->curve;
2601
0
    const struct ecc_curve *curve;
2602
0
    const mac_entry_st *me;
2603
2604
0
    curve = get_supported_nist_curve(curve_id);
2605
0
    if (curve == NULL) {
2606
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
2607
0
      goto cleanup;
2608
0
    }
2609
2610
    /* P-192 is not supported in FIPS 140-3 */
2611
0
    if (curve_id == GNUTLS_ECC_CURVE_SECP192R1) {
2612
0
      not_approved = true;
2613
0
    }
2614
2615
0
    ret = _gnutls_decode_ber_rs(signature, &tmp[0], &tmp[1]);
2616
0
    if (ret < 0) {
2617
0
      gnutls_assert();
2618
0
      goto cleanup;
2619
0
    }
2620
2621
0
    ret = _ecc_params_to_pubkey(pk_params, &pub, curve);
2622
0
    if (ret < 0) {
2623
0
      gnutls_assert();
2624
0
      goto cleanup;
2625
0
    }
2626
2627
0
    memcpy(sig.r, tmp[0], SIZEOF_MPZT);
2628
0
    memcpy(sig.s, tmp[1], SIZEOF_MPZT);
2629
2630
0
    (void)_gnutls_dsa_q_to_hash(pk_params, &hash_len);
2631
2632
0
    if (hash_len > vdata->size)
2633
0
      hash_len = vdata->size;
2634
2635
0
    switch (DIG_TO_MAC(sign_params->dsa_dig)) {
2636
0
    case GNUTLS_MAC_SHA256:
2637
0
    case GNUTLS_MAC_SHA384:
2638
0
    case GNUTLS_MAC_SHA512:
2639
0
    case GNUTLS_MAC_SHA224:
2640
0
      break;
2641
0
    default:
2642
0
      not_approved = true;
2643
0
    }
2644
2645
0
    me = hash_to_entry(sign_params->dsa_dig);
2646
2647
0
    _gnutls_audit_data("pk::curve", CRAU_STRING,
2648
0
           gnutls_ecc_curve_get_name(curve_id),
2649
0
           "pk::hash", CRAU_STRING,
2650
0
           _gnutls_mac_get_name(me), NULL);
2651
2652
0
    ret = ecdsa_verify(&pub, hash_len, vdata->data, &sig);
2653
0
    if (ret == 0) {
2654
0
      gnutls_assert();
2655
0
      ret = GNUTLS_E_PK_SIG_VERIFY_FAILED;
2656
0
    } else
2657
0
      ret = 0;
2658
2659
0
    ecc_point_clear(&pub);
2660
0
    break;
2661
0
  }
2662
0
#ifdef ENABLE_DSA
2663
0
  case GNUTLS_PK_DSA: {
2664
0
    struct dsa_params pub;
2665
0
    struct dsa_signature sig;
2666
0
    bigint_t y;
2667
0
    size_t bits;
2668
2669
    /* DSA is currently being defined as sunset with the
2670
     * current draft of FIPS 186-5 */
2671
0
    not_approved = true;
2672
2673
0
    ret = _gnutls_decode_ber_rs(signature, &tmp[0], &tmp[1]);
2674
0
    if (ret < 0) {
2675
0
      gnutls_assert();
2676
0
      goto cleanup;
2677
0
    }
2678
0
    memset(&pub, 0, sizeof(pub));
2679
0
    _dsa_params_get(pk_params, &pub);
2680
0
    y = pk_params->params[DSA_Y];
2681
2682
0
    memcpy(sig.r, tmp[0], SIZEOF_MPZT);
2683
0
    memcpy(sig.s, tmp[1], SIZEOF_MPZT);
2684
2685
0
    _gnutls_dsa_q_to_hash(pk_params, &hash_len);
2686
2687
0
    if (hash_len > vdata->size)
2688
0
      hash_len = vdata->size;
2689
2690
0
    bits = mpz_sizeinbase(pub.p, 2);
2691
0
    _gnutls_audit_data("pk::bits", CRAU_WORD, bits, NULL);
2692
2693
0
    ret = dsa_verify(&pub, TOMPZ(y), hash_len, vdata->data, &sig);
2694
0
    if (ret == 0) {
2695
0
      gnutls_assert();
2696
0
      ret = GNUTLS_E_PK_SIG_VERIFY_FAILED;
2697
0
    } else
2698
0
      ret = 0;
2699
2700
0
    break;
2701
0
  }
2702
0
#endif
2703
0
  case GNUTLS_PK_RSA: {
2704
0
    struct rsa_public_key pub;
2705
0
    size_t bits;
2706
2707
0
    ret = _rsa_params_to_pubkey(pk_params, &pub);
2708
0
    if (ret < 0) {
2709
0
      gnutls_assert();
2710
0
      goto cleanup;
2711
0
    }
2712
2713
0
    bits = mpz_sizeinbase(pub.n, 2);
2714
2715
0
    _gnutls_audit_data("pk::bits", CRAU_WORD, bits, NULL);
2716
2717
    /* In FIPS 140-3, RSA key size should be larger than 2048-bit.
2718
     * In addition to this, only SHA-2 is allowed
2719
     * for SigVer; it is checked in _pkcs1_rsa_verify_sig in
2720
     * lib/pubkey.c.
2721
     */
2722
0
    if (unlikely(bits < 2048)) {
2723
0
      not_approved = true;
2724
0
    }
2725
2726
0
    if (signature->size != pub.size) {
2727
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2728
0
      goto cleanup;
2729
0
    }
2730
2731
0
    ret = _gnutls_mpi_init_scan_nz(&tmp[0], signature->data,
2732
0
                 signature->size);
2733
0
    if (ret < 0) {
2734
0
      gnutls_assert();
2735
0
      goto cleanup;
2736
0
    }
2737
2738
0
    ret = rsa_pkcs1_verify(&pub, vdata->size, vdata->data,
2739
0
               TOMPZ(tmp[0]));
2740
0
    if (ret == 0)
2741
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2742
0
    else
2743
0
      ret = 0;
2744
2745
0
    break;
2746
0
  }
2747
0
  case GNUTLS_PK_RSA_PSS: {
2748
0
    struct rsa_public_key pub;
2749
0
    size_t bits;
2750
2751
0
    if ((sign_params->flags &
2752
0
         GNUTLS_PK_FLAG_RSA_PSS_FIXED_SALT_LENGTH) &&
2753
0
        sign_params->salt_size != vdata->size) {
2754
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2755
0
      goto cleanup;
2756
0
    }
2757
2758
0
    ret = _rsa_params_to_pubkey(pk_params, &pub);
2759
0
    if (ret < 0) {
2760
0
      gnutls_assert();
2761
0
      goto cleanup;
2762
0
    }
2763
2764
0
    bits = mpz_sizeinbase(pub.n, 2);
2765
2766
    /* RSA modulus size should be 2048-bit or larger in FIPS
2767
     * 140-3.  In addition to this, only SHA-2 are
2768
     * allowed for SigVer, while Nettle only supports
2769
     * SHA256, SHA384, and SHA512 for RSA-PSS (see
2770
     * _rsa_pss_verify_digest in this file for the details).
2771
     */
2772
0
    if (unlikely(bits < 2048)) {
2773
0
      not_approved = true;
2774
0
    }
2775
2776
0
    if (signature->size != pub.size) {
2777
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2778
0
      goto cleanup;
2779
0
    }
2780
2781
0
    ret = _gnutls_mpi_init_scan_nz(&tmp[0], signature->data,
2782
0
                 signature->size);
2783
0
    if (ret < 0) {
2784
0
      gnutls_assert();
2785
0
      goto cleanup;
2786
0
    }
2787
2788
0
    _gnutls_audit_data(
2789
0
      "pk::bits", CRAU_WORD, bits, "pk::hash", CRAU_STRING,
2790
0
      gnutls_digest_get_name(sign_params->rsa_pss_dig), NULL);
2791
2792
0
    ret = _rsa_pss_verify_digest(sign_params->rsa_pss_dig, &pub,
2793
0
               sign_params->salt_size,
2794
0
               vdata->data, vdata->size,
2795
0
               TOMPZ(tmp[0]));
2796
0
    if (ret == 0)
2797
0
      ret = gnutls_assert_val(GNUTLS_E_PK_SIG_VERIFY_FAILED);
2798
0
    else
2799
0
      ret = 0;
2800
2801
0
    break;
2802
0
  }
2803
0
  case GNUTLS_PK_MLDSA44:
2804
0
  case GNUTLS_PK_MLDSA65:
2805
0
  case GNUTLS_PK_MLDSA87:
2806
0
    not_approved = true;
2807
0
    ret = ml_dsa_verify(algo, signature, vdata,
2808
0
            &pk_params->raw_pub);
2809
0
    if (ret < 0)
2810
0
      goto cleanup;
2811
0
    break;
2812
0
  default:
2813
0
    gnutls_assert();
2814
0
    ret = GNUTLS_E_INTERNAL_ERROR;
2815
0
    goto cleanup;
2816
0
  }
2817
2818
0
cleanup:
2819
0
  if (ret < 0) {
2820
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
2821
0
  } else if (not_approved) {
2822
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_NOT_APPROVED);
2823
0
  } else {
2824
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_APPROVED);
2825
0
  }
2826
2827
0
  _gnutls_mpi_release(&tmp[0]);
2828
0
  _gnutls_mpi_release(&tmp[1]);
2829
2830
0
  gnutls_audit_pop_context();
2831
2832
0
  FAIL_IF_LIB_ERROR;
2833
0
  return ret;
2834
0
}
2835
2836
static inline const struct ecc_curve *get_supported_nist_curve(int curve)
2837
0
{
2838
0
  switch (curve) {
2839
0
#ifdef ENABLE_NON_SUITEB_CURVES
2840
0
  case GNUTLS_ECC_CURVE_SECP192R1:
2841
0
    return nettle_get_secp_192r1();
2842
0
  case GNUTLS_ECC_CURVE_SECP224R1:
2843
0
    return nettle_get_secp_224r1();
2844
0
#endif
2845
0
  case GNUTLS_ECC_CURVE_SECP256R1:
2846
0
    return nettle_get_secp_256r1();
2847
0
  case GNUTLS_ECC_CURVE_SECP384R1:
2848
0
    return nettle_get_secp_384r1();
2849
0
  case GNUTLS_ECC_CURVE_SECP521R1:
2850
0
    return nettle_get_secp_521r1();
2851
0
  default:
2852
0
    return NULL;
2853
0
  }
2854
0
}
2855
2856
static inline const char *get_supported_nist_curve_order(int curve)
2857
0
{
2858
0
  static const struct {
2859
0
    int curve;
2860
0
    const char *order;
2861
0
  } orders[] = {
2862
0
#ifdef ENABLE_NON_SUITEB_CURVES
2863
0
    { GNUTLS_ECC_CURVE_SECP192R1, "ffffffffffffffffffffffff99def836"
2864
0
                "146bc9b1b4d22831" },
2865
0
    { GNUTLS_ECC_CURVE_SECP224R1, "ffffffffffffffffffffffffffff16a2"
2866
0
                "e0b8f03e13dd29455c5c2a3d" },
2867
0
#endif
2868
0
    { GNUTLS_ECC_CURVE_SECP256R1,
2869
0
      "ffffffff00000000ffffffffffffffff"
2870
0
      "bce6faada7179e84f3b9cac2fc632551" },
2871
0
    { GNUTLS_ECC_CURVE_SECP384R1,
2872
0
      "ffffffffffffffffffffffffffffffff"
2873
0
      "ffffffffffffffffc7634d81f4372ddf"
2874
0
      "581a0db248b0a77aecec196accc52973" },
2875
0
    { GNUTLS_ECC_CURVE_SECP521R1, "1fffffffffffffffffffffffffffffff"
2876
0
                "ffffffffffffffffffffffffffffffff"
2877
0
                "ffa51868783bf2f966b7fcc0148f709a"
2878
0
                "5d03bb5c9b8899c47aebb6fb71e91386"
2879
0
                "409" },
2880
0
  };
2881
0
  size_t i;
2882
0
2883
0
  for (i = 0; i < sizeof(orders) / sizeof(orders[0]); i++) {
2884
0
    if (orders[i].curve == curve)
2885
0
      return orders[i].order;
2886
0
  }
2887
0
  return NULL;
2888
0
}
2889
2890
static inline const char *get_supported_nist_curve_modulus(int curve)
2891
0
{
2892
0
  static const struct {
2893
0
    int curve;
2894
0
    const char *order;
2895
0
  } orders[] = {
2896
0
#ifdef ENABLE_NON_SUITEB_CURVES
2897
0
    { GNUTLS_ECC_CURVE_SECP192R1, "fffffffffffffffffffffffffffffffe"
2898
0
                "ffffffffffffffff" },
2899
0
    { GNUTLS_ECC_CURVE_SECP224R1, "ffffffffffffffffffffffffffffffff"
2900
0
                "000000000000000000000001" },
2901
0
#endif
2902
0
    { GNUTLS_ECC_CURVE_SECP256R1,
2903
0
      "ffffffff000000010000000000000000"
2904
0
      "00000000ffffffffffffffffffffffff" },
2905
0
    { GNUTLS_ECC_CURVE_SECP384R1,
2906
0
      "ffffffffffffffffffffffffffffffff"
2907
0
      "fffffffffffffffffffffffffffffffe"
2908
0
      "ffffffff0000000000000000ffffffff" },
2909
0
    { GNUTLS_ECC_CURVE_SECP521R1,
2910
0
      "1ff"
2911
0
      "ffffffffffffffffffffffffffffffff"
2912
0
      "ffffffffffffffffffffffffffffffff"
2913
0
      "ffffffffffffffffffffffffffffffff"
2914
0
      "ffffffffffffffffffffffffffffffff" },
2915
0
  };
2916
0
  size_t i;
2917
0
2918
0
  for (i = 0; i < sizeof(orders) / sizeof(orders[0]); i++) {
2919
0
    if (orders[i].curve == curve)
2920
0
      return orders[i].order;
2921
0
  }
2922
0
  return NULL;
2923
0
}
2924
2925
static inline const struct ecc_curve *get_supported_gost_curve(int curve)
2926
0
{
2927
0
  switch (curve) {
2928
0
#if ENABLE_GOST
2929
0
  case GNUTLS_ECC_CURVE_GOST256CPA:
2930
0
  case GNUTLS_ECC_CURVE_GOST256CPXA:
2931
0
  case GNUTLS_ECC_CURVE_GOST256B:
2932
0
    return nettle_get_gost_gc256b();
2933
0
  case GNUTLS_ECC_CURVE_GOST512A:
2934
0
    return nettle_get_gost_gc512a();
2935
0
#endif
2936
0
  default:
2937
0
    return NULL;
2938
0
  }
2939
0
}
2940
2941
static int _wrap_nettle_pk_curve_exists(gnutls_ecc_curve_t curve)
2942
0
{
2943
0
  switch (curve) {
2944
0
  case GNUTLS_ECC_CURVE_ED25519:
2945
0
  case GNUTLS_ECC_CURVE_X25519:
2946
0
  case GNUTLS_ECC_CURVE_ED448:
2947
0
  case GNUTLS_ECC_CURVE_X448:
2948
0
    return 1;
2949
0
  default:
2950
0
    return ((get_supported_nist_curve(curve) != NULL ||
2951
0
       get_supported_gost_curve(curve) != NULL) ?
2952
0
        1 :
2953
0
        0);
2954
0
  }
2955
0
}
2956
2957
static int _wrap_nettle_pk_exists(gnutls_pk_algorithm_t pk)
2958
0
{
2959
0
  switch (pk) {
2960
0
  case GNUTLS_PK_RSA:
2961
0
#ifdef ENABLE_DSA
2962
0
  case GNUTLS_PK_DSA:
2963
0
#endif
2964
0
  case GNUTLS_PK_DH:
2965
0
  case GNUTLS_PK_ECDSA:
2966
0
  case GNUTLS_PK_ECDH_X25519:
2967
0
  case GNUTLS_PK_RSA_PSS:
2968
0
  case GNUTLS_PK_RSA_OAEP:
2969
0
  case GNUTLS_PK_EDDSA_ED25519:
2970
0
#if ENABLE_GOST
2971
0
  case GNUTLS_PK_GOST_01:
2972
0
  case GNUTLS_PK_GOST_12_256:
2973
0
  case GNUTLS_PK_GOST_12_512:
2974
0
#endif
2975
0
  case GNUTLS_PK_ECDH_X448:
2976
0
  case GNUTLS_PK_EDDSA_ED448:
2977
0
    return 1;
2978
0
  case GNUTLS_PK_MLKEM768:
2979
0
  case GNUTLS_PK_MLKEM1024:
2980
0
    return ml_kem_exists(pk);
2981
0
  case GNUTLS_PK_MLDSA44:
2982
0
  case GNUTLS_PK_MLDSA65:
2983
0
  case GNUTLS_PK_MLDSA87:
2984
0
    return ml_dsa_exists(pk);
2985
0
  default:
2986
0
    return 0;
2987
0
  }
2988
0
}
2989
2990
static int _wrap_nettle_pk_sign_exists(gnutls_sign_algorithm_t sign)
2991
0
{
2992
0
  switch (sign) {
2993
0
  case GNUTLS_SIGN_RSA_SHA1:
2994
0
#ifdef ENABLE_DSA
2995
0
  case GNUTLS_SIGN_DSA_SHA1:
2996
0
#endif
2997
0
  case GNUTLS_SIGN_RSA_MD5:
2998
0
  case GNUTLS_SIGN_RSA_MD2:
2999
0
  case GNUTLS_SIGN_RSA_RMD160:
3000
0
  case GNUTLS_SIGN_RSA_SHA256:
3001
0
  case GNUTLS_SIGN_RSA_SHA384:
3002
0
  case GNUTLS_SIGN_RSA_SHA512:
3003
0
  case GNUTLS_SIGN_RSA_SHA224:
3004
0
#ifdef ENABLE_DSA
3005
0
  case GNUTLS_SIGN_DSA_SHA224:
3006
0
  case GNUTLS_SIGN_DSA_SHA256:
3007
0
#endif
3008
0
  case GNUTLS_SIGN_ECDSA_SHA1:
3009
0
  case GNUTLS_SIGN_ECDSA_SHA224:
3010
0
  case GNUTLS_SIGN_ECDSA_SHA256:
3011
0
  case GNUTLS_SIGN_ECDSA_SHA384:
3012
0
  case GNUTLS_SIGN_ECDSA_SHA512:
3013
0
#ifdef ENABLE_DSA
3014
0
  case GNUTLS_SIGN_DSA_SHA384:
3015
0
  case GNUTLS_SIGN_DSA_SHA512:
3016
0
#endif
3017
0
  case GNUTLS_SIGN_ECDSA_SHA3_224:
3018
0
  case GNUTLS_SIGN_ECDSA_SHA3_256:
3019
0
  case GNUTLS_SIGN_ECDSA_SHA3_384:
3020
0
  case GNUTLS_SIGN_ECDSA_SHA3_512:
3021
3022
0
#ifdef ENABLE_DSA
3023
0
  case GNUTLS_SIGN_DSA_SHA3_224:
3024
0
  case GNUTLS_SIGN_DSA_SHA3_256:
3025
0
  case GNUTLS_SIGN_DSA_SHA3_384:
3026
0
  case GNUTLS_SIGN_DSA_SHA3_512:
3027
0
#endif
3028
0
  case GNUTLS_SIGN_RSA_SHA3_224:
3029
0
  case GNUTLS_SIGN_RSA_SHA3_256:
3030
0
  case GNUTLS_SIGN_RSA_SHA3_384:
3031
0
  case GNUTLS_SIGN_RSA_SHA3_512:
3032
3033
0
  case GNUTLS_SIGN_RSA_PSS_SHA256:
3034
0
  case GNUTLS_SIGN_RSA_PSS_SHA384:
3035
0
  case GNUTLS_SIGN_RSA_PSS_SHA512:
3036
0
  case GNUTLS_SIGN_EDDSA_ED25519:
3037
0
  case GNUTLS_SIGN_RSA_RAW:
3038
3039
0
  case GNUTLS_SIGN_ECDSA_SECP256R1_SHA256:
3040
0
  case GNUTLS_SIGN_ECDSA_SECP384R1_SHA384:
3041
0
  case GNUTLS_SIGN_ECDSA_SECP521R1_SHA512:
3042
3043
0
  case GNUTLS_SIGN_RSA_PSS_RSAE_SHA256:
3044
0
  case GNUTLS_SIGN_RSA_PSS_RSAE_SHA384:
3045
0
  case GNUTLS_SIGN_RSA_PSS_RSAE_SHA512:
3046
3047
0
#if ENABLE_GOST
3048
0
  case GNUTLS_SIGN_GOST_94:
3049
0
  case GNUTLS_SIGN_GOST_256:
3050
0
  case GNUTLS_SIGN_GOST_512:
3051
0
#endif
3052
0
  case GNUTLS_SIGN_EDDSA_ED448:
3053
0
    return 1;
3054
0
  default:
3055
0
    return 0;
3056
0
  }
3057
0
}
3058
3059
/* Generates algorithm's parameters. That is:
3060
 *  For DSA: p, q, and g are generated.
3061
 *  For RSA: nothing
3062
 *  For ECDSA/EDDSA: nothing
3063
 */
3064
static int wrap_nettle_pk_generate_params(gnutls_pk_algorithm_t algo,
3065
            unsigned int level /*bits or curve */,
3066
            gnutls_pk_params_st *params)
3067
0
{
3068
0
  int ret;
3069
0
  unsigned int i, q_bits;
3070
3071
0
  FAIL_IF_LIB_ERROR;
3072
3073
0
  params->algo = algo;
3074
3075
0
  switch (algo) {
3076
0
#ifdef ENABLE_DSA
3077
0
  case GNUTLS_PK_DSA:
3078
0
#endif
3079
0
  case GNUTLS_PK_DH: {
3080
0
    struct dsa_params pub;
3081
0
    struct dss_params_validation_seeds cert;
3082
0
    unsigned index;
3083
3084
0
    dsa_params_init(&pub);
3085
3086
0
    if (GNUTLS_BITS_HAVE_SUBGROUP(level)) {
3087
0
      q_bits = GNUTLS_BITS_TO_SUBGROUP(level);
3088
0
      level = GNUTLS_BITS_TO_GROUP(level);
3089
0
    } else {
3090
0
      q_bits = _gnutls_pk_bits_to_subgroup_bits(level);
3091
0
    }
3092
3093
0
    if (q_bits == 0)
3094
0
      return gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
3095
3096
0
    if (_gnutls_fips_mode_enabled() != 0 ||
3097
0
        params->pkflags & GNUTLS_PK_FLAG_PROVABLE) {
3098
0
      if (algo == GNUTLS_PK_DSA)
3099
0
        index = 1;
3100
0
      else
3101
0
        index = 2;
3102
3103
0
      if (params->palgo != 0 &&
3104
0
          params->palgo != GNUTLS_DIG_SHA384) {
3105
0
        ret = GNUTLS_E_INVALID_REQUEST;
3106
0
        goto dsa_fail;
3107
0
      }
3108
3109
0
      params->palgo = GNUTLS_DIG_SHA384;
3110
3111
0
      if (params->seed_size) {
3112
0
        ret = _dsa_generate_dss_pqg(&pub, &cert, index,
3113
0
                  params->seed_size,
3114
0
                  params->seed, NULL,
3115
0
                  NULL, level,
3116
0
                  q_bits);
3117
0
      } else {
3118
0
        ret = dsa_generate_dss_pqg(&pub, &cert, index,
3119
0
                 NULL,
3120
0
                 rnd_tmpkey_func,
3121
0
                 NULL, NULL, level,
3122
0
                 q_bits);
3123
0
      }
3124
0
      if (ret != 1 || HAVE_LIB_ERROR()) {
3125
0
        gnutls_assert();
3126
0
        ret = GNUTLS_E_PK_GENERATION_ERROR;
3127
0
        goto dsa_fail;
3128
0
      }
3129
3130
0
      if (cert.seed_length &&
3131
0
          cert.seed_length < sizeof(params->seed)) {
3132
0
        params->seed_size = cert.seed_length;
3133
0
        memcpy(params->seed, cert.seed,
3134
0
               cert.seed_length);
3135
0
      }
3136
3137
      /* verify the generated parameters */
3138
0
      ret = dsa_validate_dss_pqg(&pub, &cert, index);
3139
0
      if (ret != 1) {
3140
0
        gnutls_assert();
3141
0
        ret = GNUTLS_E_PK_GENERATION_ERROR;
3142
0
        goto dsa_fail;
3143
0
      }
3144
0
    } else {
3145
0
      if (q_bits < 160)
3146
0
        q_bits = 160;
3147
3148
0
      ret = dsa_generate_params(&pub, NULL, rnd_tmpkey_func,
3149
0
              NULL, NULL, level, q_bits);
3150
0
      if (ret != 1 || HAVE_LIB_ERROR()) {
3151
0
        gnutls_assert();
3152
0
        ret = GNUTLS_E_PK_GENERATION_ERROR;
3153
0
        goto dsa_fail;
3154
0
      }
3155
0
    }
3156
3157
0
    params->params_nr = 0;
3158
3159
0
    ret = _gnutls_mpi_init_multi(&params->params[DSA_P],
3160
0
               &params->params[DSA_Q],
3161
0
               &params->params[DSA_G], NULL);
3162
0
    if (ret < 0) {
3163
0
      gnutls_assert();
3164
0
      goto dsa_fail;
3165
0
    }
3166
0
    params->params_nr = 3;
3167
3168
0
    mpz_set(TOMPZ(params->params[DSA_P]), pub.p);
3169
0
    mpz_set(TOMPZ(params->params[DSA_Q]), pub.q);
3170
0
    mpz_set(TOMPZ(params->params[DSA_G]), pub.g);
3171
3172
0
    ret = 0;
3173
3174
0
  dsa_fail:
3175
0
    dsa_params_clear(&pub);
3176
3177
0
    if (ret < 0)
3178
0
      goto fail;
3179
3180
0
    break;
3181
0
  }
3182
0
  case GNUTLS_PK_RSA_PSS:
3183
0
  case GNUTLS_PK_RSA_OAEP:
3184
0
  case GNUTLS_PK_RSA:
3185
0
  case GNUTLS_PK_ECDSA:
3186
0
  case GNUTLS_PK_EDDSA_ED25519:
3187
0
  case GNUTLS_PK_EDDSA_ED448:
3188
0
  case GNUTLS_PK_ECDH_X25519:
3189
0
  case GNUTLS_PK_ECDH_X448:
3190
0
#if ENABLE_GOST
3191
0
  case GNUTLS_PK_GOST_01:
3192
0
  case GNUTLS_PK_GOST_12_256:
3193
0
  case GNUTLS_PK_GOST_12_512:
3194
0
#endif
3195
0
  case GNUTLS_PK_MLKEM768:
3196
0
  case GNUTLS_PK_MLDSA44:
3197
0
  case GNUTLS_PK_MLDSA65:
3198
0
  case GNUTLS_PK_MLDSA87:
3199
0
    break;
3200
0
  default:
3201
0
    gnutls_assert();
3202
0
    return GNUTLS_E_INVALID_REQUEST;
3203
0
  }
3204
3205
0
  FAIL_IF_LIB_ERROR;
3206
0
  return 0;
3207
3208
0
fail:
3209
3210
0
  for (i = 0; i < params->params_nr; i++) {
3211
0
    _gnutls_mpi_release(&params->params[i]);
3212
0
  }
3213
0
  params->params_nr = 0;
3214
3215
0
  FAIL_IF_LIB_ERROR;
3216
0
  return ret;
3217
0
}
3218
3219
#ifdef ENABLE_FIPS140
3220
int _gnutls_dh_generate_key(gnutls_dh_params_t dh_params,
3221
          gnutls_datum_t *priv_key, gnutls_datum_t *pub_key);
3222
3223
int _gnutls_dh_compute_key(gnutls_dh_params_t dh_params,
3224
         const gnutls_datum_t *priv_key,
3225
         const gnutls_datum_t *pub_key,
3226
         const gnutls_datum_t *peer_key, gnutls_datum_t *Z);
3227
3228
int _gnutls_ecdh_compute_key(gnutls_ecc_curve_t curve, const gnutls_datum_t *x,
3229
           const gnutls_datum_t *y, const gnutls_datum_t *k,
3230
           const gnutls_datum_t *peer_x,
3231
           const gnutls_datum_t *peer_y, gnutls_datum_t *Z);
3232
3233
int _gnutls_ecdh_generate_key(gnutls_ecc_curve_t curve, gnutls_datum_t *x,
3234
            gnutls_datum_t *y, gnutls_datum_t *k);
3235
3236
int _gnutls_dh_generate_key(gnutls_dh_params_t dh_params,
3237
          gnutls_datum_t *priv_key, gnutls_datum_t *pub_key)
3238
{
3239
  gnutls_pk_params_st params;
3240
  int ret;
3241
3242
  gnutls_pk_params_init(&params);
3243
  params.params[DH_P] = _gnutls_mpi_copy(dh_params->params[0]);
3244
  params.params[DH_G] = _gnutls_mpi_copy(dh_params->params[1]);
3245
3246
  params.params_nr = 5;
3247
  params.algo = GNUTLS_PK_DH;
3248
3249
  priv_key->data = NULL;
3250
  pub_key->data = NULL;
3251
3252
  ret = _gnutls_pk_generate_keys(GNUTLS_PK_DH, dh_params->q_bits, &params,
3253
               0);
3254
  if (ret < 0) {
3255
    return gnutls_assert_val(ret);
3256
  }
3257
3258
  ret = _gnutls_mpi_dprint_lz(params.params[DH_X], priv_key);
3259
  if (ret < 0) {
3260
    gnutls_assert();
3261
    goto fail;
3262
  }
3263
3264
  ret = _gnutls_mpi_dprint_lz(params.params[DH_Y], pub_key);
3265
  if (ret < 0) {
3266
    gnutls_assert();
3267
    goto fail;
3268
  }
3269
3270
  ret = 0;
3271
  goto cleanup;
3272
fail:
3273
  gnutls_free(pub_key->data);
3274
  gnutls_free(priv_key->data);
3275
cleanup:
3276
  gnutls_pk_params_clear(&params);
3277
  gnutls_pk_params_release(&params);
3278
  return ret;
3279
}
3280
3281
/* Note that the value of Z will have the leading bytes stripped if they are zero -
3282
 * which follows the TLS approach. */
3283
int _gnutls_dh_compute_key(gnutls_dh_params_t dh_params,
3284
         const gnutls_datum_t *priv_key,
3285
         const gnutls_datum_t *pub_key,
3286
         const gnutls_datum_t *peer_key, gnutls_datum_t *Z)
3287
{
3288
  gnutls_pk_params_st pub, priv;
3289
  int ret;
3290
3291
  gnutls_pk_params_init(&pub);
3292
  pub.params_nr = 5;
3293
  pub.algo = GNUTLS_PK_DH;
3294
3295
  gnutls_pk_params_init(&priv);
3296
  priv.params_nr = 5;
3297
  priv.algo = GNUTLS_PK_DH;
3298
3299
  if (_gnutls_mpi_init_scan_nz(&pub.params[DH_Y], peer_key->data,
3300
             peer_key->size) != 0) {
3301
    ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
3302
    goto cleanup;
3303
  }
3304
3305
  priv.params[DH_P] = _gnutls_mpi_copy(dh_params->params[0]);
3306
  priv.params[DH_G] = _gnutls_mpi_copy(dh_params->params[1]);
3307
  if (dh_params->params[2])
3308
    priv.params[DH_Q] = _gnutls_mpi_copy(dh_params->params[2]);
3309
3310
  if (_gnutls_mpi_init_scan_nz(&priv.params[DH_X], priv_key->data,
3311
             priv_key->size) != 0) {
3312
    ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
3313
    goto cleanup;
3314
  }
3315
3316
  Z->data = NULL;
3317
3318
  ret = _gnutls_pk_derive(GNUTLS_PK_DH, Z, &priv, &pub);
3319
  if (ret < 0) {
3320
    gnutls_assert();
3321
    goto cleanup;
3322
  }
3323
3324
  ret = 0;
3325
cleanup:
3326
  gnutls_pk_params_clear(&pub);
3327
  gnutls_pk_params_release(&pub);
3328
  gnutls_pk_params_clear(&priv);
3329
  gnutls_pk_params_release(&priv);
3330
  return ret;
3331
}
3332
3333
int _gnutls_ecdh_generate_key(gnutls_ecc_curve_t curve, gnutls_datum_t *x,
3334
            gnutls_datum_t *y, gnutls_datum_t *k)
3335
{
3336
  gnutls_pk_params_st params;
3337
  int ret;
3338
3339
  gnutls_pk_params_init(&params);
3340
  params.params_nr = 3;
3341
  params.curve = curve;
3342
  params.algo = GNUTLS_PK_ECDSA;
3343
3344
  x->data = NULL;
3345
  y->data = NULL;
3346
  k->data = NULL;
3347
3348
  ret = _gnutls_pk_generate_keys(GNUTLS_PK_ECDSA, curve, &params, 0);
3349
  if (ret < 0) {
3350
    return gnutls_assert_val(ret);
3351
  }
3352
3353
  ret = _gnutls_mpi_dprint_lz(params.params[ECC_X], x);
3354
  if (ret < 0) {
3355
    gnutls_assert();
3356
    goto fail;
3357
  }
3358
3359
  ret = _gnutls_mpi_dprint_lz(params.params[ECC_Y], y);
3360
  if (ret < 0) {
3361
    gnutls_assert();
3362
    goto fail;
3363
  }
3364
3365
  ret = _gnutls_mpi_dprint_lz(params.params[ECC_K], k);
3366
  if (ret < 0) {
3367
    gnutls_assert();
3368
    goto fail;
3369
  }
3370
3371
  ret = 0;
3372
  goto cleanup;
3373
fail:
3374
  gnutls_free(y->data);
3375
  gnutls_free(x->data);
3376
  gnutls_free(k->data);
3377
cleanup:
3378
  gnutls_pk_params_clear(&params);
3379
  gnutls_pk_params_release(&params);
3380
  return ret;
3381
}
3382
3383
int _gnutls_ecdh_compute_key(gnutls_ecc_curve_t curve, const gnutls_datum_t *x,
3384
           const gnutls_datum_t *y, const gnutls_datum_t *k,
3385
           const gnutls_datum_t *peer_x,
3386
           const gnutls_datum_t *peer_y, gnutls_datum_t *Z)
3387
{
3388
  gnutls_pk_params_st pub, priv;
3389
  int ret;
3390
3391
  gnutls_pk_params_init(&pub);
3392
  pub.params_nr = 3;
3393
  pub.algo = GNUTLS_PK_ECDSA;
3394
  pub.curve = curve;
3395
3396
  gnutls_pk_params_init(&priv);
3397
  priv.params_nr = 3;
3398
  priv.algo = GNUTLS_PK_ECDSA;
3399
  priv.curve = curve;
3400
3401
  if (_gnutls_mpi_init_scan_nz(&pub.params[ECC_Y], peer_y->data,
3402
             peer_y->size) != 0) {
3403
    ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
3404
    goto cleanup;
3405
  }
3406
3407
  if (_gnutls_mpi_init_scan_nz(&pub.params[ECC_X], peer_x->data,
3408
             peer_x->size) != 0) {
3409
    ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
3410
    goto cleanup;
3411
  }
3412
3413
  if (_gnutls_mpi_init_scan_nz(&priv.params[ECC_Y], y->data, y->size) !=
3414
      0) {
3415
    ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
3416
    goto cleanup;
3417
  }
3418
3419
  if (_gnutls_mpi_init_scan_nz(&priv.params[ECC_X], x->data, x->size) !=
3420
      0) {
3421
    ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
3422
    goto cleanup;
3423
  }
3424
3425
  if (_gnutls_mpi_init_scan_nz(&priv.params[ECC_K], k->data, k->size) !=
3426
      0) {
3427
    ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
3428
    goto cleanup;
3429
  }
3430
3431
  Z->data = NULL;
3432
3433
  ret = _gnutls_pk_derive(GNUTLS_PK_ECDSA, Z, &priv, &pub);
3434
  if (ret < 0) {
3435
    gnutls_assert();
3436
    goto cleanup;
3437
  }
3438
3439
  ret = 0;
3440
cleanup:
3441
  gnutls_pk_params_clear(&pub);
3442
  gnutls_pk_params_release(&pub);
3443
  gnutls_pk_params_clear(&priv);
3444
  gnutls_pk_params_release(&priv);
3445
  return ret;
3446
}
3447
3448
static gnutls_sign_algorithm_t pct_pk_to_sign(gnutls_pk_algorithm_t algo,
3449
                const gnutls_x509_spki_st *spki)
3450
{
3451
  switch (algo) {
3452
  case GNUTLS_PK_RSA_PSS:
3453
    return gnutls_pk_to_sign(algo, spki->rsa_pss_dig);
3454
#ifdef ENABLE_DSA
3455
  case GNUTLS_PK_DSA:
3456
#endif
3457
  case GNUTLS_PK_ECDSA:
3458
    return gnutls_pk_to_sign(algo, spki->dsa_dig);
3459
  case GNUTLS_PK_EDDSA_ED25519:
3460
    return GNUTLS_SIGN_EDDSA_ED25519;
3461
  case GNUTLS_PK_EDDSA_ED448:
3462
    return GNUTLS_SIGN_EDDSA_ED448;
3463
#if ENABLE_GOST
3464
  case GNUTLS_PK_GOST_01:
3465
    return GNUTLS_SIGN_GOST_94;
3466
  case GNUTLS_PK_GOST_12_256:
3467
    return GNUTLS_SIGN_GOST_256;
3468
  case GNUTLS_PK_GOST_12_512:
3469
    return GNUTLS_SIGN_GOST_512;
3470
#endif
3471
  case GNUTLS_PK_MLDSA44:
3472
    return GNUTLS_SIGN_MLDSA44;
3473
  case GNUTLS_PK_MLDSA65:
3474
    return GNUTLS_SIGN_MLDSA65;
3475
  case GNUTLS_PK_MLDSA87:
3476
    return GNUTLS_SIGN_MLDSA87;
3477
  default:
3478
    return GNUTLS_SIGN_UNKNOWN;
3479
  }
3480
}
3481
3482
static int pct_hash_sign_test(gnutls_pk_algorithm_t algo,
3483
            const gnutls_pk_params_st *params,
3484
            const gnutls_x509_spki_st *spki,
3485
            const gnutls_datum_t *data)
3486
{
3487
  gnutls_privkey_t privkey = NULL;
3488
  gnutls_pubkey_t pubkey = NULL;
3489
  gnutls_x509_privkey_t xprivkey = NULL;
3490
  gnutls_datum_t sig = { NULL, 0 };
3491
  gnutls_sign_algorithm_t sign_algo;
3492
  int ret;
3493
3494
  sign_algo = pct_pk_to_sign(algo, spki);
3495
  if (sign_algo == GNUTLS_SIGN_UNKNOWN)
3496
    return gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3497
3498
  ret = gnutls_x509_privkey_init(&xprivkey);
3499
  if (ret < 0) {
3500
    gnutls_assert();
3501
    goto cleanup;
3502
  }
3503
3504
  ret = _gnutls_pk_params_copy(&xprivkey->params, params);
3505
  if (ret < 0) {
3506
    gnutls_assert();
3507
    goto cleanup;
3508
  }
3509
3510
  ret = gnutls_privkey_init(&privkey);
3511
  if (ret < 0) {
3512
    gnutls_assert();
3513
    goto cleanup;
3514
  }
3515
3516
  ret = gnutls_privkey_import_x509(privkey, xprivkey,
3517
           GNUTLS_PRIVKEY_IMPORT_AUTO_RELEASE);
3518
  if (ret < 0) {
3519
    gnutls_assert();
3520
    goto cleanup;
3521
  }
3522
  xprivkey = NULL;
3523
3524
  ret = gnutls_pubkey_init(&pubkey);
3525
  if (ret < 0) {
3526
    gnutls_assert();
3527
    goto cleanup;
3528
  }
3529
3530
  ret = gnutls_pubkey_import_privkey(pubkey, privkey, 0, 0);
3531
  if (ret < 0) {
3532
    gnutls_assert();
3533
    goto cleanup;
3534
  }
3535
3536
  ret = gnutls_privkey_sign_data2(privkey, sign_algo, 0, data, &sig);
3537
  if (ret < 0) {
3538
    gnutls_assert();
3539
    goto cleanup;
3540
  }
3541
3542
  /* Ignore algorithm disablement through configuration during PCT.  */
3543
  ret = gnutls_pubkey_verify_data2(
3544
    pubkey, sign_algo, GNUTLS_VERIFY_ALLOW_BROKEN, data, &sig);
3545
  if (ret < 0) {
3546
    gnutls_assert();
3547
    goto cleanup;
3548
  }
3549
3550
cleanup:
3551
  if (ret < 0) {
3552
    _gnutls_debug_log("PCT: %s hash+sign self-test failed: %s\n",
3553
          gnutls_sign_get_name(sign_algo),
3554
          gnutls_strerror(ret));
3555
  } else {
3556
    _gnutls_debug_log("PCT: %s hash+sign self-test succeeded\n",
3557
          gnutls_sign_get_name(sign_algo));
3558
  }
3559
3560
  gnutls_x509_privkey_deinit(xprivkey);
3561
  gnutls_privkey_deinit(privkey);
3562
  gnutls_pubkey_deinit(pubkey);
3563
  _gnutls_free_datum(&sig);
3564
3565
  return ret;
3566
}
3567
3568
static int pct_test(gnutls_pk_algorithm_t algo,
3569
        const gnutls_pk_params_st *params)
3570
{
3571
  int ret;
3572
  gnutls_datum_t sig = { NULL, 0 };
3573
  const char const_data[20] = "onetwothreefourfive";
3574
  const char const_data_sha256[32] = "onetwothreefourfivesixseveneigh";
3575
  const char const_data_sha384[48] =
3576
    "onetwothreefourfivesixseveneightnineteneleventw";
3577
  const char const_data_sha512[64] =
3578
    "onetwothreefourfivesixseveneightnineteneleventwelvethirteenfour";
3579
  gnutls_datum_t ddata, tmp = { NULL, 0 };
3580
  char gen_data[MAX_HASH_SIZE];
3581
  gnutls_x509_spki_st spki;
3582
3583
  ret = _gnutls_x509_spki_copy(&spki, &params->spki);
3584
  if (ret < 0) {
3585
    gnutls_assert();
3586
    goto cleanup;
3587
  }
3588
3589
  if (algo == GNUTLS_PK_DSA || algo == GNUTLS_PK_EC) {
3590
    unsigned hash_len;
3591
    const mac_entry_st *me;
3592
3593
    me = _gnutls_dsa_q_to_hash(params, &hash_len);
3594
    spki.dsa_dig = MAC_TO_DIG(me->id);
3595
    gnutls_rnd(GNUTLS_RND_NONCE, gen_data, hash_len);
3596
3597
    ddata.data = (void *)gen_data;
3598
    ddata.size = hash_len;
3599
  } else if (algo == GNUTLS_PK_GOST_01 || algo == GNUTLS_PK_GOST_12_256) {
3600
    ddata.data = (void *)const_data_sha256;
3601
    ddata.size = sizeof(const_data_sha256);
3602
  } else if (algo == GNUTLS_PK_GOST_12_512) {
3603
    ddata.data = (void *)const_data_sha512;
3604
    ddata.size = sizeof(const_data_sha512);
3605
  } else if (algo == GNUTLS_PK_RSA_PSS) {
3606
    if (spki.rsa_pss_dig == GNUTLS_DIG_UNKNOWN)
3607
      spki.rsa_pss_dig = GNUTLS_DIG_SHA256;
3608
3609
    switch (spki.rsa_pss_dig) {
3610
    case GNUTLS_DIG_SHA256:
3611
      ddata.data = (void *)const_data_sha256;
3612
      ddata.size = sizeof(const_data_sha256);
3613
      break;
3614
    case GNUTLS_DIG_SHA384:
3615
      ddata.data = (void *)const_data_sha384;
3616
      ddata.size = sizeof(const_data_sha384);
3617
      break;
3618
    case GNUTLS_DIG_SHA512:
3619
      ddata.data = (void *)const_data_sha512;
3620
      ddata.size = sizeof(const_data_sha512);
3621
      break;
3622
    default:
3623
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3624
      goto cleanup;
3625
    }
3626
  } else if (algo == GNUTLS_PK_RSA_OAEP) {
3627
    if (spki.rsa_oaep_dig == GNUTLS_DIG_UNKNOWN)
3628
      spki.rsa_oaep_dig = GNUTLS_DIG_SHA256;
3629
    ddata.data = (void *)const_data;
3630
    ddata.size = sizeof(const_data);
3631
  } else {
3632
    ddata.data = (void *)const_data;
3633
    ddata.size = sizeof(const_data);
3634
  }
3635
3636
  switch (algo) {
3637
  case GNUTLS_PK_RSA:
3638
    /* To comply with FIPS 140-3 IG 10.3.A, additional comment 1,
3639
     * Perform both key transport and signature PCTs for
3640
     * unrestricted RSA key.  */
3641
    ret = pct_test(GNUTLS_PK_RSA_OAEP, params);
3642
    if (ret < 0) {
3643
      gnutls_assert();
3644
      break;
3645
    }
3646
    ret = pct_test(GNUTLS_PK_RSA_PSS, params);
3647
    if (ret < 0) {
3648
      gnutls_assert();
3649
      break;
3650
    }
3651
    break;
3652
  case GNUTLS_PK_RSA_OAEP:
3653
    ret = _gnutls_pk_encrypt(GNUTLS_PK_RSA_OAEP, &sig, &ddata,
3654
           params, &spki);
3655
    if (ret < 0) {
3656
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3657
    }
3658
    if (ret == 0 && ddata.size == sig.size &&
3659
        memeq(ddata.data, sig.data, sig.size)) {
3660
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3661
    }
3662
    if (ret == 0 &&
3663
        _gnutls_pk_decrypt(algo, &tmp, &sig, params, &spki) < 0) {
3664
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3665
    }
3666
    if (ret == 0 && !(tmp.size == ddata.size &&
3667
          memeq(tmp.data, ddata.data, tmp.size))) {
3668
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3669
    }
3670
    if (ret == 0 &&
3671
        _gnutls_pk_decrypt2(algo, &sig, tmp.data, tmp.size, params,
3672
          &spki) < 0) {
3673
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3674
    }
3675
    if (ret == 0 && !(tmp.size == ddata.size &&
3676
          memeq(tmp.data, ddata.data, tmp.size))) {
3677
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3678
    }
3679
3680
    if (ret < 0) {
3681
      goto cleanup;
3682
    }
3683
3684
    free(sig.data);
3685
    sig.data = NULL;
3686
3687
    break;
3688
  case GNUTLS_PK_EC: /* we only do keys for ECDSA */
3689
  case GNUTLS_PK_EDDSA_ED25519:
3690
  case GNUTLS_PK_EDDSA_ED448:
3691
#ifdef ENABLE_DSA
3692
  case GNUTLS_PK_DSA:
3693
#endif
3694
  case GNUTLS_PK_RSA_PSS:
3695
  case GNUTLS_PK_GOST_01:
3696
  case GNUTLS_PK_GOST_12_256:
3697
  case GNUTLS_PK_GOST_12_512:
3698
  case GNUTLS_PK_MLDSA44:
3699
  case GNUTLS_PK_MLDSA65:
3700
  case GNUTLS_PK_MLDSA87:
3701
    ret = _gnutls_pk_sign(algo, &sig, &ddata, params, &spki);
3702
    if (ret < 0) {
3703
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3704
      goto cleanup;
3705
    }
3706
3707
    ret = _gnutls_pk_verify(algo, &ddata, &sig, params, &spki);
3708
    if (ret < 0) {
3709
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3710
      goto cleanup;
3711
    }
3712
3713
    /* Exercise the combined hash+sign operation, using
3714
     * the abstract key interface.
3715
     *
3716
     * FIXME: rework this once the crypto-backend
3717
     * interface natively supports hash+sign operation, see:
3718
     * https://gitlab.com/gnutls/gnutls/-/merge_requests/2066
3719
     */
3720
    ret = pct_hash_sign_test(algo, params, &spki, &ddata);
3721
    if (ret < 0) {
3722
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3723
      goto cleanup;
3724
    }
3725
    break;
3726
  case GNUTLS_PK_DH: {
3727
    mpz_t y;
3728
3729
    /* Perform SP800 56A (rev 3) 5.6.2.1.4 Owner Assurance
3730
     * of Pair-wise Consistency check, even if we only
3731
     * support ephemeral DH, as it is required by FIPS
3732
     * 140-3 IG 10.3.A.
3733
     *
3734
     * Use the private key, x, along with the generator g
3735
     * and prime modulus p included in the domain
3736
     * parameters associated with the key pair to compute
3737
     * g^x mod p. Compare the result to the public key, y.
3738
     */
3739
    mpz_init(y);
3740
    mpz_powm(y, TOMPZ(params->params[DSA_G]),
3741
       TOMPZ(params->params[DSA_X]),
3742
       TOMPZ(params->params[DSA_P]));
3743
    if (unlikely(mpz_cmp(y, TOMPZ(params->params[DSA_Y])) != 0)) {
3744
      ret = gnutls_assert_val(GNUTLS_E_PK_GENERATION_ERROR);
3745
      mpz_clear(y);
3746
      goto cleanup;
3747
    }
3748
    mpz_clear(y);
3749
    break;
3750
  }
3751
  case GNUTLS_PK_ECDH_X25519:
3752
  case GNUTLS_PK_ECDH_X448:
3753
    break;
3754
  case GNUTLS_PK_MLKEM768:
3755
  case GNUTLS_PK_MLKEM1024:
3756
    if (!ml_kem_exists(algo)) {
3757
      ret = gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
3758
      goto cleanup;
3759
    }
3760
    break;
3761
  default:
3762
    ret = gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
3763
    goto cleanup;
3764
  }
3765
3766
  ret = 0;
3767
cleanup:
3768
  if (ret == GNUTLS_E_PK_GENERATION_ERROR) {
3769
    _gnutls_switch_lib_state(LIB_STATE_ERROR);
3770
  }
3771
  _gnutls_x509_spki_clear(&spki);
3772
  gnutls_free(sig.data);
3773
  gnutls_free(tmp.data);
3774
  return ret;
3775
}
3776
#endif
3777
3778
static inline int eddsa_public_key(gnutls_pk_algorithm_t algo, uint8_t *pub,
3779
           const uint8_t *priv)
3780
0
{
3781
0
  switch (algo) {
3782
0
  case GNUTLS_PK_EDDSA_ED25519:
3783
0
    ed25519_sha512_public_key(pub, priv);
3784
0
    return 0;
3785
0
  case GNUTLS_PK_EDDSA_ED448:
3786
0
    ed448_shake256_public_key(pub, priv);
3787
0
    return 0;
3788
0
  default:
3789
0
    return gnutls_assert_val(
3790
0
      GNUTLS_E_UNSUPPORTED_SIGNATURE_ALGORITHM);
3791
0
  }
3792
0
}
3793
3794
static inline int edwards_curve_mul_g(gnutls_pk_algorithm_t algo, uint8_t *q,
3795
              const uint8_t *n)
3796
0
{
3797
0
  switch (algo) {
3798
0
  case GNUTLS_PK_ECDH_X25519:
3799
0
    curve25519_mul_g(q, n);
3800
0
    return 0;
3801
0
  case GNUTLS_PK_ECDH_X448:
3802
0
    curve448_mul_g(q, n);
3803
0
    return 0;
3804
0
  default:
3805
0
    return gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
3806
0
  }
3807
0
}
3808
3809
static inline int dh_find_q(const gnutls_pk_params_st *pk_params, mpz_t q)
3810
0
{
3811
0
  gnutls_datum_t prime = { NULL, 0 };
3812
0
  gnutls_datum_t generator = { NULL, 0 };
3813
0
  uint8_t *data_q;
3814
0
  size_t n_q;
3815
0
  bigint_t _q;
3816
0
  int ret = 0;
3817
0
3818
0
  ret = _gnutls_mpi_dprint(pk_params->params[DSA_P], &prime);
3819
0
  if (ret < 0) {
3820
0
    gnutls_assert();
3821
0
    goto cleanup;
3822
0
  }
3823
0
3824
0
  ret = _gnutls_mpi_dprint(pk_params->params[DSA_G], &generator);
3825
0
  if (ret < 0) {
3826
0
    gnutls_assert();
3827
0
    goto cleanup;
3828
0
  }
3829
0
3830
0
  if (!_gnutls_dh_prime_match_fips_approved(
3831
0
        prime.data, prime.size, generator.data, generator.size,
3832
0
        &data_q, &n_q)) {
3833
0
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
3834
0
    goto cleanup;
3835
0
  }
3836
0
3837
0
  if (_gnutls_mpi_init_scan_nz(&_q, data_q, n_q) != 0) {
3838
0
    ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
3839
0
    goto cleanup;
3840
0
  }
3841
0
3842
0
  mpz_set(q, TOMPZ(_q));
3843
0
  _gnutls_mpi_release(&_q);
3844
0
3845
0
cleanup:
3846
0
  gnutls_free(prime.data);
3847
0
  gnutls_free(generator.data);
3848
0
3849
0
  return ret;
3850
0
}
3851
3852
/* To generate a DH key either q must be set in the params or
3853
 * level should be set to the number of required bits.
3854
 */
3855
static int
3856
wrap_nettle_pk_generate_keys(gnutls_pk_algorithm_t algo,
3857
           unsigned int level /*bits or curve */,
3858
           gnutls_pk_params_st *params, unsigned ephemeral
3859
           /*non-zero if they are ephemeral keys */)
3860
0
{
3861
0
  int ret;
3862
0
  unsigned int i;
3863
0
  unsigned rnd_level;
3864
0
  nettle_random_func *rnd_func;
3865
0
  bool not_approved = false;
3866
3867
0
  FAIL_IF_LIB_ERROR;
3868
3869
  /* check if the curve relates to the algorithm used */
3870
0
  if (IS_EC(algo) && gnutls_ecc_curve_get_pk(level) != algo) {
3871
0
    ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
3872
0
    goto cleanup;
3873
0
  }
3874
3875
0
  if (ephemeral) {
3876
0
    rnd_level = GNUTLS_RND_RANDOM;
3877
0
    rnd_func = rnd_tmpkey_func;
3878
0
  } else {
3879
0
    rnd_func = rnd_key_func;
3880
0
    rnd_level = GNUTLS_RND_KEY;
3881
0
  }
3882
3883
0
  _gnutls_audit_new_context_with_data("name", CRAU_STRING, "pk::generate",
3884
0
              "pk::algorithm", CRAU_STRING,
3885
0
              gnutls_pk_get_name(algo), NULL);
3886
3887
0
  switch (algo) {
3888
0
#ifdef ENABLE_DSA
3889
0
  case GNUTLS_PK_DSA:
3890
#ifdef ENABLE_FIPS140
3891
    if (_gnutls_fips_mode_enabled() != 0) {
3892
      struct dsa_params pub;
3893
      mpz_t x, y;
3894
3895
      /* DSA is currently being defined as sunset with the
3896
       * current draft of FIPS 186-5 */
3897
      not_approved = true;
3898
3899
      if (params->params[DSA_Q] == NULL) {
3900
        ret = gnutls_assert_val(
3901
          GNUTLS_E_INVALID_REQUEST);
3902
        goto cleanup;
3903
      }
3904
3905
      _dsa_params_get(params, &pub);
3906
3907
      mpz_init(x);
3908
      mpz_init(y);
3909
3910
      ret = dsa_generate_dss_keypair(&pub, y, x, NULL,
3911
                   rnd_func, NULL, NULL);
3912
      if (ret != 1 || HAVE_LIB_ERROR()) {
3913
        gnutls_assert();
3914
        ret = GNUTLS_E_PK_GENERATION_ERROR;
3915
        goto dsa_fail;
3916
      }
3917
3918
      ret = _gnutls_mpi_init_multi(&params->params[DSA_Y],
3919
                 &params->params[DSA_X],
3920
                 NULL);
3921
      if (ret < 0) {
3922
        gnutls_assert();
3923
        goto dsa_fail;
3924
      }
3925
3926
      mpz_set(TOMPZ(params->params[DSA_Y]), y);
3927
      mpz_set(TOMPZ(params->params[DSA_X]), x);
3928
      params->params_nr += 2;
3929
3930
    dsa_fail:
3931
      mpz_clear(x);
3932
      mpz_clear(y);
3933
3934
      if (ret < 0)
3935
        goto cleanup;
3936
3937
      break;
3938
    }
3939
#endif
3940
0
    FALLTHROUGH;
3941
0
#endif
3942
0
  case GNUTLS_PK_DH: {
3943
0
    struct dsa_params pub;
3944
0
    mpz_t r;
3945
0
    mpz_t x, y;
3946
0
    int max_tries;
3947
0
    unsigned have_q = 0;
3948
0
    mpz_t q;
3949
0
    mpz_t primesub1;
3950
0
    mpz_t ypowq;
3951
3952
0
    if (algo != params->algo) {
3953
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
3954
0
      goto cleanup;
3955
0
    }
3956
3957
0
    _dsa_params_get(params, &pub);
3958
3959
0
    if (params->params[DSA_Q] != NULL)
3960
0
      have_q = 1;
3961
3962
    /* This check is for the case !ENABLE_FIPS140 */
3963
0
    if (algo == GNUTLS_PK_DSA && have_q == 0) {
3964
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
3965
0
      goto cleanup;
3966
0
    }
3967
3968
0
    mpz_init(r);
3969
0
    mpz_init(x);
3970
0
    mpz_init(y);
3971
3972
0
    mpz_init(q);
3973
0
    mpz_init(primesub1);
3974
0
    mpz_init(ypowq);
3975
3976
0
    max_tries = 3;
3977
0
    do {
3978
0
      if (have_q) {
3979
0
        mpz_set(r, pub.q);
3980
0
        mpz_sub_ui(r, r, 2);
3981
0
        nettle_mpz_random(x, NULL, rnd_func, r);
3982
0
        mpz_add_ui(x, x, 1);
3983
0
      } else {
3984
0
        unsigned size = mpz_sizeinbase(pub.p, 2);
3985
0
        if (level == 0)
3986
0
          level = MIN(size,
3987
0
                DH_EXPONENT_SIZE(size));
3988
0
        nettle_mpz_random_size(x, NULL, rnd_func,
3989
0
                   level);
3990
3991
0
        if (level >= size)
3992
0
          mpz_mod(x, x, pub.p);
3993
0
      }
3994
3995
0
      mpz_powm(y, pub.g, x, pub.p);
3996
3997
0
      max_tries--;
3998
0
      if (max_tries <= 0) {
3999
0
        gnutls_assert();
4000
0
        ret = GNUTLS_E_RANDOM_FAILED;
4001
0
        goto dh_fail;
4002
0
      }
4003
4004
0
      if (HAVE_LIB_ERROR()) {
4005
0
        gnutls_assert();
4006
0
        ret = GNUTLS_E_LIB_IN_ERROR_STATE;
4007
0
        goto dh_fail;
4008
0
      }
4009
4010
0
    } while (mpz_cmp_ui(y, 1) == 0);
4011
4012
#ifdef ENABLE_FIPS140
4013
    if (_gnutls_fips_mode_enabled()) {
4014
      /* Perform FFC full public key validation checks
4015
       * according to SP800-56A (revision 3), 5.6.2.3.1.
4016
       */
4017
4018
      /* Step 1: 2 <= y <= p - 2 */
4019
      mpz_sub_ui(primesub1, pub.p, 1);
4020
4021
      if (mpz_cmp_ui(y, 2) < 0 ||
4022
          mpz_cmp(y, primesub1) >= 0) {
4023
        ret = gnutls_assert_val(GNUTLS_E_RANDOM_FAILED);
4024
        goto dh_fail;
4025
      }
4026
4027
      /* Step 2: 1 = y^q mod p */
4028
      if (have_q)
4029
        mpz_set(q, pub.q);
4030
      else {
4031
        ret = dh_find_q(params, q);
4032
        if (ret < 0)
4033
          goto dh_fail;
4034
      }
4035
4036
      mpz_powm(ypowq, y, q, pub.p);
4037
      if (mpz_cmp_ui(ypowq, 1) != 0) {
4038
        ret = gnutls_assert_val(GNUTLS_E_RANDOM_FAILED);
4039
        goto dh_fail;
4040
      }
4041
    }
4042
#endif
4043
4044
0
    ret = _gnutls_mpi_init_multi(&params->params[DSA_Y],
4045
0
               &params->params[DSA_X], NULL);
4046
0
    if (ret < 0) {
4047
0
      gnutls_assert();
4048
0
      goto dh_fail;
4049
0
    }
4050
4051
0
    mpz_set(TOMPZ(params->params[DSA_Y]), y);
4052
0
    mpz_set(TOMPZ(params->params[DSA_X]), x);
4053
0
    params->params_nr += 2;
4054
4055
0
    ret = 0;
4056
4057
0
  dh_fail:
4058
0
    mpz_clear(r);
4059
0
    mpz_clear(x);
4060
0
    mpz_clear(y);
4061
0
    mpz_clear(q);
4062
0
    mpz_clear(primesub1);
4063
0
    mpz_clear(ypowq);
4064
4065
0
    if (ret < 0)
4066
0
      goto cleanup;
4067
4068
0
    break;
4069
0
  }
4070
0
  case GNUTLS_PK_RSA_PSS:
4071
0
  case GNUTLS_PK_RSA_OAEP:
4072
0
  case GNUTLS_PK_RSA: {
4073
0
    struct rsa_public_key pub;
4074
0
    struct rsa_private_key priv;
4075
4076
0
    rsa_public_key_init(&pub);
4077
0
    rsa_private_key_init(&priv);
4078
4079
0
    mpz_set_ui(pub.e, 65537);
4080
4081
0
    if ((params->pkflags & GNUTLS_PK_FLAG_PROVABLE) ||
4082
0
        _gnutls_fips_mode_enabled() != 0) {
4083
0
      params->pkflags |= GNUTLS_PK_FLAG_PROVABLE;
4084
0
      if (params->palgo != 0 &&
4085
0
          params->palgo != GNUTLS_DIG_SHA384) {
4086
0
        ret = GNUTLS_E_INVALID_REQUEST;
4087
0
        goto rsa_fail;
4088
0
      }
4089
4090
0
      params->palgo = GNUTLS_DIG_SHA384;
4091
4092
0
      if (params->seed_size) {
4093
0
        ret = _rsa_generate_fips186_4_keypair(
4094
0
          &pub, &priv, params->seed_size,
4095
0
          params->seed, NULL, NULL, level);
4096
0
      } else {
4097
0
        unsigned retries = 0;
4098
        /* The provable RSA key generation process is deterministic
4099
         * but has an internal maximum iteration counter and when
4100
         * exceed will fail for certain random seeds. This is a very
4101
         * rare condition, but it nevertheless happens and even CI builds fail
4102
         * occasionally. When we generate the random seed internally, remediate
4103
         * by retrying a different seed on failure. */
4104
0
        do {
4105
0
          params->seed_size =
4106
0
            sizeof(params->seed);
4107
0
          ret = rsa_generate_fips186_4_keypair(
4108
0
            &pub, &priv, NULL, rnd_func,
4109
0
            NULL, NULL, &params->seed_size,
4110
0
            params->seed, level);
4111
0
        } while (ret != 1 && ++retries < 3);
4112
0
      }
4113
0
    } else {
4114
0
      not_approved = true;
4115
4116
0
      ret = rsa_generate_keypair(&pub, &priv, NULL, rnd_func,
4117
0
               NULL, NULL, level, 0);
4118
0
    }
4119
0
    if (ret != 1 || HAVE_LIB_ERROR()) {
4120
0
      gnutls_assert();
4121
0
      ret = GNUTLS_E_PK_GENERATION_ERROR;
4122
0
      goto rsa_fail;
4123
0
    }
4124
4125
0
    params->params_nr = 0;
4126
0
    for (i = 0; i < RSA_PRIVATE_PARAMS; i++) {
4127
0
      ret = _gnutls_mpi_init(&params->params[i]);
4128
0
      if (ret < 0) {
4129
0
        gnutls_assert();
4130
0
        goto rsa_fail;
4131
0
      }
4132
0
      params->params_nr++;
4133
0
    }
4134
4135
    /* In FIPS 140-3, pub.n should be 2048-bit or larger; it
4136
     * is assured in rsa_generate_fips186_4_keypair in
4137
     * lib/nettle/int/rsa-keygen-fips186.c. */
4138
4139
0
    mpz_set(TOMPZ(params->params[RSA_MODULUS]), pub.n);
4140
0
    mpz_set(TOMPZ(params->params[RSA_PUB]), pub.e);
4141
0
    mpz_set(TOMPZ(params->params[RSA_PRIV]), priv.d);
4142
0
    mpz_set(TOMPZ(params->params[RSA_PRIME1]), priv.p);
4143
0
    mpz_set(TOMPZ(params->params[RSA_PRIME2]), priv.q);
4144
0
    mpz_set(TOMPZ(params->params[RSA_COEF]), priv.c);
4145
0
    mpz_set(TOMPZ(params->params[RSA_E1]), priv.a);
4146
0
    mpz_set(TOMPZ(params->params[RSA_E2]), priv.b);
4147
4148
0
    ret = 0;
4149
4150
0
  rsa_fail:
4151
0
    rsa_private_key_clear(&priv);
4152
0
    rsa_public_key_clear(&pub);
4153
4154
0
    if (ret < 0)
4155
0
      goto cleanup;
4156
4157
0
    break;
4158
0
  }
4159
0
  case GNUTLS_PK_EDDSA_ED25519:
4160
0
  case GNUTLS_PK_EDDSA_ED448: {
4161
0
    unsigned size = gnutls_ecc_curve_get_size(level);
4162
4163
0
    if (params->pkflags & GNUTLS_PK_FLAG_PROVABLE) {
4164
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4165
0
      goto cleanup;
4166
0
    }
4167
4168
0
    if (unlikely(get_eddsa_curve(algo) != level)) {
4169
0
      ret = gnutls_assert_val(GNUTLS_E_ECC_UNSUPPORTED_CURVE);
4170
0
      goto cleanup;
4171
0
    }
4172
4173
0
    if (size == 0) {
4174
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4175
0
      goto cleanup;
4176
0
    }
4177
4178
0
    params->curve = level;
4179
4180
0
    params->raw_priv.data = gnutls_malloc(size);
4181
0
    if (params->raw_priv.data == NULL) {
4182
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
4183
0
      goto cleanup;
4184
0
    }
4185
4186
0
    params->raw_pub.data = gnutls_malloc(size);
4187
0
    if (params->raw_pub.data == NULL) {
4188
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
4189
0
      goto cleanup;
4190
0
    }
4191
4192
0
    ret = gnutls_rnd(rnd_level, params->raw_priv.data, size);
4193
0
    if (ret < 0) {
4194
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
4195
0
      goto cleanup;
4196
0
    }
4197
0
    params->raw_pub.size = size;
4198
0
    params->raw_priv.size = size;
4199
4200
0
    ret = eddsa_public_key(algo, params->raw_pub.data,
4201
0
               params->raw_priv.data);
4202
0
    if (ret < 0)
4203
0
      goto cleanup;
4204
4205
0
    break;
4206
0
  }
4207
0
  case GNUTLS_PK_ECDSA:
4208
0
    if (params->pkflags & GNUTLS_PK_FLAG_PROVABLE)
4209
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4210
4211
0
    {
4212
0
      struct ecc_scalar key;
4213
0
      struct ecc_point pub;
4214
0
      const struct ecc_curve *curve;
4215
0
      struct ecc_scalar n;
4216
0
      struct ecc_scalar m;
4217
0
      struct ecc_point r;
4218
0
      mpz_t x, y, xx, yy, nn, mm;
4219
4220
0
      curve = get_supported_nist_curve(level);
4221
0
      if (curve == NULL) {
4222
0
        ret = gnutls_assert_val(
4223
0
          GNUTLS_E_ECC_UNSUPPORTED_CURVE);
4224
0
        goto cleanup;
4225
0
      }
4226
4227
0
      _gnutls_audit_data("pk::curve", CRAU_STRING,
4228
0
             gnutls_ecc_curve_get_name(level),
4229
0
             NULL);
4230
4231
      /* P-192 is not supported in FIPS 140-3 */
4232
0
      if (level == GNUTLS_ECC_CURVE_SECP192R1) {
4233
0
        not_approved = true;
4234
0
      }
4235
4236
0
      mpz_init(x);
4237
0
      mpz_init(y);
4238
0
      mpz_init(xx);
4239
0
      mpz_init(yy);
4240
0
      mpz_init(nn);
4241
0
      mpz_init(mm);
4242
4243
0
      ecc_scalar_init(&key, curve);
4244
0
      ecc_point_init(&pub, curve);
4245
0
      ecc_scalar_init(&n, curve);
4246
0
      ecc_scalar_init(&m, curve);
4247
0
      ecc_point_init(&r, curve);
4248
4249
0
      ecdsa_generate_keypair(&pub, &key, NULL, rnd_func);
4250
0
      if (HAVE_LIB_ERROR()) {
4251
0
        ret = gnutls_assert_val(
4252
0
          GNUTLS_E_LIB_IN_ERROR_STATE);
4253
0
        goto ecc_fail;
4254
0
      }
4255
4256
0
      ret = _gnutls_mpi_init_multi(&params->params[ECC_X],
4257
0
                 &params->params[ECC_Y],
4258
0
                 &params->params[ECC_K],
4259
0
                 NULL);
4260
0
      if (ret < 0) {
4261
0
        gnutls_assert();
4262
0
        goto ecc_fail;
4263
0
      }
4264
4265
0
      params->curve = level;
4266
0
      params->params_nr = ECC_PRIVATE_PARAMS;
4267
4268
0
      ecc_point_get(&pub, x, y);
4269
4270
#ifdef ENABLE_FIPS140
4271
      if (_gnutls_fips_mode_enabled()) {
4272
        /* Perform ECC full public key validation checks
4273
         * according to SP800-56A (revision 3), 5.6.2.3.3.
4274
         */
4275
4276
        const char *order, *modulus;
4277
4278
        /* Step 1: verify that Q is not an identity
4279
         * element (an infinity point).  Note that this
4280
         * cannot happen in the nettle implementation,
4281
         * because it cannot represent an infinity point
4282
         * on curves. */
4283
        if (mpz_cmp_ui(x, 0) == 0 &&
4284
            mpz_cmp_ui(y, 0) == 0) {
4285
          ret = gnutls_assert_val(
4286
            GNUTLS_E_ILLEGAL_PARAMETER);
4287
          goto ecc_fail;
4288
        }
4289
4290
        /* Step 2: verify that both coordinates of Q are
4291
         * in the range [0, p - 1].
4292
         *
4293
         * Step 3: verify that Q lie on the curve
4294
         *
4295
         * Both checks are performed in nettle.  */
4296
        if (!ecc_point_set(&r, x, y)) {
4297
          ret = gnutls_assert_val(
4298
            GNUTLS_E_ILLEGAL_PARAMETER);
4299
          goto ecc_fail;
4300
        }
4301
4302
        /* Step 4: verify that n * Q, where n is the
4303
         * curve order, result in an identity element
4304
         *
4305
         * Since nettle internally cannot represent an
4306
         * identity element on curves, we validate this
4307
         * instead:
4308
         *
4309
         *   (n - 1) * Q = -Q
4310
         *
4311
         * That effectively means: n * Q = -Q + Q = O
4312
         */
4313
        order = get_supported_nist_curve_order(level);
4314
        if (unlikely(order == NULL)) {
4315
          ret = gnutls_assert_val(
4316
            GNUTLS_E_INTERNAL_ERROR);
4317
          goto ecc_fail;
4318
        }
4319
4320
        ret = mpz_set_str(nn, order, 16);
4321
        if (unlikely(ret < 0)) {
4322
          ret = gnutls_assert_val(
4323
            GNUTLS_E_MPI_SCAN_FAILED);
4324
          goto ecc_fail;
4325
        }
4326
4327
        modulus =
4328
          get_supported_nist_curve_modulus(level);
4329
        if (unlikely(modulus == NULL)) {
4330
          ret = gnutls_assert_val(
4331
            GNUTLS_E_INTERNAL_ERROR);
4332
          goto ecc_fail;
4333
        }
4334
4335
        ret = mpz_set_str(mm, modulus, 16);
4336
        if (unlikely(ret < 0)) {
4337
          ret = gnutls_assert_val(
4338
            GNUTLS_E_MPI_SCAN_FAILED);
4339
          goto ecc_fail;
4340
        }
4341
4342
        /* (n - 1) * Q = -Q */
4343
        mpz_sub_ui(nn, nn, 1);
4344
        ecc_scalar_set(&n, nn);
4345
        ecc_point_mul(&r, &n, &r);
4346
        ecc_point_get(&r, xx, yy);
4347
        mpz_sub(mm, mm, y);
4348
4349
        if (mpz_cmp(xx, x) != 0 ||
4350
            mpz_cmp(yy, mm) != 0) {
4351
          ret = gnutls_assert_val(
4352
            GNUTLS_E_ILLEGAL_PARAMETER);
4353
          goto ecc_fail;
4354
        }
4355
      } else {
4356
        not_approved = true;
4357
      }
4358
#endif
4359
4360
0
      mpz_set(TOMPZ(params->params[ECC_X]), x);
4361
0
      mpz_set(TOMPZ(params->params[ECC_Y]), y);
4362
4363
0
      ecc_scalar_get(&key, TOMPZ(params->params[ECC_K]));
4364
4365
0
      ret = 0;
4366
4367
0
    ecc_fail:
4368
0
      mpz_clear(x);
4369
0
      mpz_clear(y);
4370
0
      mpz_clear(xx);
4371
0
      mpz_clear(yy);
4372
0
      mpz_clear(nn);
4373
0
      mpz_clear(mm);
4374
0
      ecc_point_clear(&pub);
4375
0
      ecc_scalar_clear(&key);
4376
0
      ecc_point_clear(&r);
4377
0
      ecc_scalar_clear(&n);
4378
0
      ecc_scalar_clear(&m);
4379
4380
0
      if (ret < 0)
4381
0
        goto cleanup;
4382
4383
0
      break;
4384
0
    }
4385
0
#if ENABLE_GOST
4386
0
  case GNUTLS_PK_GOST_01:
4387
0
  case GNUTLS_PK_GOST_12_256:
4388
0
  case GNUTLS_PK_GOST_12_512:
4389
0
    if (params->pkflags & GNUTLS_PK_FLAG_PROVABLE)
4390
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4391
4392
0
    {
4393
0
      struct ecc_scalar key;
4394
0
      struct ecc_point pub;
4395
0
      const struct ecc_curve *curve;
4396
0
      const mac_entry_st *me;
4397
4398
      /* GOST curves are not approved */
4399
0
      not_approved = true;
4400
4401
0
      curve = get_supported_gost_curve(level);
4402
0
      if (curve == NULL) {
4403
0
        ret = gnutls_assert_val(
4404
0
          GNUTLS_E_ECC_UNSUPPORTED_CURVE);
4405
0
        goto cleanup;
4406
0
      }
4407
4408
0
      me = hash_to_entry(_gnutls_gost_digest(algo));
4409
0
      if (!me || me->output_size * 8 != ecc_bit_size(curve)) {
4410
0
        ret = gnutls_assert_val(
4411
0
          GNUTLS_E_INVALID_REQUEST);
4412
0
        goto cleanup;
4413
0
      }
4414
4415
0
      ecc_scalar_init(&key, curve);
4416
0
      ecc_point_init(&pub, curve);
4417
4418
0
      gostdsa_generate_keypair(&pub, &key, NULL,
4419
0
             rnd_key_func);
4420
0
      if (HAVE_LIB_ERROR()) {
4421
0
        ret = gnutls_assert_val(
4422
0
          GNUTLS_E_LIB_IN_ERROR_STATE);
4423
0
        goto ecc_fail;
4424
0
      }
4425
4426
0
      ret = _gnutls_mpi_init_multi(&params->params[GOST_X],
4427
0
                 &params->params[GOST_Y],
4428
0
                 &params->params[GOST_K],
4429
0
                 NULL);
4430
0
      if (ret < 0) {
4431
0
        gnutls_assert();
4432
0
        goto gost_fail;
4433
0
      }
4434
4435
0
      params->curve = level;
4436
0
      params->params_nr = GOST_PRIVATE_PARAMS;
4437
4438
0
      ecc_point_get(&pub, TOMPZ(params->params[GOST_X]),
4439
0
              TOMPZ(params->params[GOST_Y]));
4440
0
      ecc_scalar_get(&key, TOMPZ(params->params[GOST_K]));
4441
4442
0
      ret = 0;
4443
4444
0
    gost_fail:
4445
0
      ecc_point_clear(&pub);
4446
0
      ecc_scalar_clear(&key);
4447
4448
0
      if (ret < 0)
4449
0
        goto cleanup;
4450
4451
0
      break;
4452
0
    }
4453
0
#endif
4454
0
  case GNUTLS_PK_ECDH_X25519:
4455
0
  case GNUTLS_PK_ECDH_X448: {
4456
0
    unsigned size = gnutls_ecc_curve_get_size(level);
4457
4458
0
    not_approved = true;
4459
4460
0
    if (size == 0) {
4461
0
      ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4462
0
      goto cleanup;
4463
0
    }
4464
4465
0
    params->curve = level;
4466
4467
0
    params->raw_priv.data = gnutls_malloc(size);
4468
0
    if (params->raw_priv.data == NULL) {
4469
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
4470
0
      goto cleanup;
4471
0
    }
4472
4473
0
    params->raw_pub.data = gnutls_malloc(size);
4474
0
    if (params->raw_pub.data == NULL) {
4475
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
4476
0
      goto cleanup;
4477
0
    }
4478
4479
0
    ret = gnutls_rnd(rnd_level, params->raw_priv.data, size);
4480
0
    if (ret < 0) {
4481
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
4482
0
      goto cleanup;
4483
0
    }
4484
0
    params->raw_pub.size = size;
4485
0
    params->raw_priv.size = size;
4486
4487
0
    ret = edwards_curve_mul_g(algo, params->raw_pub.data,
4488
0
            params->raw_priv.data);
4489
0
    if (ret < 0)
4490
0
      goto cleanup;
4491
0
    break;
4492
0
  }
4493
0
  case GNUTLS_PK_MLKEM768:
4494
0
  case GNUTLS_PK_MLKEM1024:
4495
    /* unapproved until we implement CAST/PCT per IG 10.3.A(14). */
4496
0
    not_approved = true;
4497
0
    ret = ml_kem_generate_keypair(algo, &params->raw_priv,
4498
0
                &params->raw_pub);
4499
0
    if (ret < 0)
4500
0
      goto cleanup;
4501
0
    break;
4502
0
  case GNUTLS_PK_MLDSA44:
4503
0
  case GNUTLS_PK_MLDSA65:
4504
0
  case GNUTLS_PK_MLDSA87:
4505
0
    if (params->pkflags & GNUTLS_PK_FLAG_PROVABLE)
4506
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4507
4508
0
    not_approved = true;
4509
4510
0
    if (!(params->pkflags & GNUTLS_PK_FLAG_EXPAND_KEYS_FROM_SEED)) {
4511
0
      _gnutls_free_key_datum(&params->raw_seed);
4512
0
      params->raw_seed.data = gnutls_malloc(32);
4513
0
      params->raw_seed.size = 32;
4514
0
      ret = gnutls_rnd(GNUTLS_RND_KEY, params->raw_seed.data,
4515
0
           params->raw_seed.size);
4516
0
      if (ret < 0)
4517
0
        goto cleanup;
4518
0
    }
4519
4520
0
    ret = ml_dsa_generate_keypair(algo, &params->raw_priv,
4521
0
                &params->raw_pub,
4522
0
                &params->raw_seed);
4523
0
    if (ret < 0)
4524
0
      goto cleanup;
4525
0
    break;
4526
0
  default:
4527
0
    gnutls_assert();
4528
0
    return GNUTLS_E_INVALID_REQUEST;
4529
0
  }
4530
4531
0
  params->algo = algo;
4532
4533
#ifdef ENABLE_FIPS140
4534
  if (_gnutls_fips_mode_enabled()) {
4535
    ret = pct_test(algo, params);
4536
    if (ret < 0) {
4537
      gnutls_assert();
4538
      goto cleanup;
4539
    }
4540
  }
4541
#endif
4542
4543
0
cleanup:
4544
0
  if (ret < 0) {
4545
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_ERROR);
4546
0
    for (i = 0; i < params->params_nr; i++) {
4547
0
      _gnutls_mpi_release(&params->params[i]);
4548
0
    }
4549
0
    params->params_nr = 0;
4550
0
    gnutls_free(params->raw_priv.data);
4551
0
    gnutls_free(params->raw_pub.data);
4552
0
  } else if (not_approved) {
4553
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_NOT_APPROVED);
4554
0
  } else {
4555
0
    _gnutls_switch_fips_state(GNUTLS_FIPS140_OP_APPROVED);
4556
0
  }
4557
4558
0
  gnutls_audit_pop_context();
4559
4560
0
  FAIL_IF_LIB_ERROR;
4561
0
  return ret;
4562
0
}
4563
4564
static int wrap_nettle_pk_verify_priv_params(gnutls_pk_algorithm_t algo,
4565
               const gnutls_pk_params_st *params)
4566
0
{
4567
0
  int ret;
4568
4569
0
  switch (algo) {
4570
0
  case GNUTLS_PK_RSA:
4571
0
  case GNUTLS_PK_RSA_PSS:
4572
0
  case GNUTLS_PK_RSA_OAEP: {
4573
0
    bigint_t t1 = NULL, t2 = NULL;
4574
4575
0
    if (params->params_nr != RSA_PRIVATE_PARAMS)
4576
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4577
4578
0
    ret = _gnutls_mpi_init_multi(&t1, &t2, NULL);
4579
0
    if (ret < 0)
4580
0
      return gnutls_assert_val(ret);
4581
4582
0
    _gnutls_mpi_mulm(t1, params->params[RSA_PRIME1],
4583
0
         params->params[RSA_PRIME2],
4584
0
         params->params[RSA_MODULUS]);
4585
0
    if (_gnutls_mpi_cmp_ui(t1, 0) != 0) {
4586
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4587
0
      goto rsa_cleanup;
4588
0
    }
4589
4590
0
    if (!mpz_invert(TOMPZ(t1), TOMPZ(params->params[RSA_PRIME2]),
4591
0
        TOMPZ(params->params[RSA_PRIME1]))) {
4592
0
      ret = gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
4593
0
      goto rsa_cleanup;
4594
0
    }
4595
0
    if (_gnutls_mpi_cmp(t1, params->params[RSA_COEF]) != 0) {
4596
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4597
0
      goto rsa_cleanup;
4598
0
    }
4599
4600
    /* [RSA_PRIME1] = d % p-1, [RSA_PRIME2] = d % q-1 */
4601
0
    _gnutls_mpi_sub_ui(t1, params->params[RSA_PRIME1], 1);
4602
0
    ret = _gnutls_mpi_modm(t2, params->params[RSA_PRIV], t1);
4603
0
    if (ret < 0) {
4604
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
4605
0
      goto rsa_cleanup;
4606
0
    }
4607
4608
0
    if (_gnutls_mpi_cmp(params->params[RSA_E1], t2) != 0) {
4609
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4610
0
      goto rsa_cleanup;
4611
0
    }
4612
4613
0
    _gnutls_mpi_sub_ui(t1, params->params[RSA_PRIME2], 1);
4614
4615
0
    ret = _gnutls_mpi_modm(t2, params->params[RSA_PRIV], t1);
4616
0
    if (ret < 0) {
4617
0
      ret = gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
4618
0
      goto rsa_cleanup;
4619
0
    }
4620
4621
0
    if (_gnutls_mpi_cmp(params->params[RSA_E2], t2) != 0) {
4622
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4623
0
      goto rsa_cleanup;
4624
0
    }
4625
4626
0
    ret = 0;
4627
4628
0
  rsa_cleanup:
4629
0
    zrelease_mpi_key(&t1);
4630
0
    zrelease_mpi_key(&t2);
4631
0
  }
4632
4633
0
  break;
4634
0
#ifdef ENABLE_DSA
4635
0
  case GNUTLS_PK_DSA:
4636
0
#endif
4637
0
  case GNUTLS_PK_DH: {
4638
0
    bigint_t t1 = NULL;
4639
4640
0
    if (params->params_nr != DSA_PRIVATE_PARAMS)
4641
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4642
4643
0
    ret = _gnutls_mpi_init(&t1);
4644
0
    if (ret < 0)
4645
0
      return gnutls_assert_val(ret);
4646
4647
0
    ret = _gnutls_mpi_powm(t1, params->params[DSA_G],
4648
0
               params->params[DSA_X],
4649
0
               params->params[DSA_P]);
4650
0
    if (ret < 0) {
4651
0
      gnutls_assert();
4652
0
      goto dsa_cleanup;
4653
0
    }
4654
4655
0
    if (_gnutls_mpi_cmp(t1, params->params[DSA_Y]) != 0) {
4656
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4657
0
      goto dsa_cleanup;
4658
0
    }
4659
4660
0
    ret = 0;
4661
4662
0
  dsa_cleanup:
4663
0
    zrelease_mpi_key(&t1);
4664
0
  }
4665
4666
0
  break;
4667
0
  case GNUTLS_PK_ECDSA: {
4668
0
    struct ecc_point r, pub;
4669
0
    struct ecc_scalar priv;
4670
0
    mpz_t x1, y1, x2, y2;
4671
0
    const struct ecc_curve *curve;
4672
4673
0
    if (params->params_nr != ECC_PRIVATE_PARAMS)
4674
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4675
4676
0
    curve = get_supported_nist_curve(params->curve);
4677
0
    if (curve == NULL)
4678
0
      return gnutls_assert_val(
4679
0
        GNUTLS_E_ECC_UNSUPPORTED_CURVE);
4680
4681
0
    ret = _ecc_params_to_pubkey(params, &pub, curve);
4682
0
    if (ret < 0)
4683
0
      return gnutls_assert_val(ret);
4684
4685
0
    ret = _ecc_params_to_privkey(params, &priv, curve);
4686
0
    if (ret < 0) {
4687
0
      ecc_point_clear(&pub);
4688
0
      return gnutls_assert_val(ret);
4689
0
    }
4690
4691
0
    ecc_point_init(&r, curve);
4692
    /* verify that x,y lie on the curve */
4693
0
    ret = ecc_point_set(&r, TOMPZ(params->params[ECC_X]),
4694
0
            TOMPZ(params->params[ECC_Y]));
4695
0
    if (ret == 0) {
4696
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4697
0
      goto ecc_cleanup;
4698
0
    }
4699
0
    ecc_point_clear(&r);
4700
4701
0
    ecc_point_init(&r, curve);
4702
0
    ecc_point_mul_g(&r, &priv);
4703
4704
0
    mpz_init(x1);
4705
0
    mpz_init(y1);
4706
0
    ecc_point_get(&r, x1, y1);
4707
0
    ecc_point_zclear(&r);
4708
4709
0
    mpz_init(x2);
4710
0
    mpz_init(y2);
4711
0
    ecc_point_get(&pub, x2, y2);
4712
4713
    /* verify that k*(Gx,Gy)=(x,y) */
4714
0
    if (mpz_cmp(x1, x2) != 0 || mpz_cmp(y1, y2) != 0) {
4715
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4716
0
      goto ecc_cleanup;
4717
0
    }
4718
4719
0
    ret = 0;
4720
4721
0
  ecc_cleanup:
4722
0
    ecc_scalar_zclear(&priv);
4723
0
    ecc_point_clear(&pub);
4724
4725
0
    mpz_clear(x1);
4726
0
    mpz_clear(y1);
4727
0
    mpz_clear(x2);
4728
0
    mpz_clear(y2);
4729
0
  } break;
4730
0
  case GNUTLS_PK_EDDSA_ED25519:
4731
0
  case GNUTLS_PK_EDDSA_ED448: {
4732
0
    gnutls_ecc_curve_t curve;
4733
0
    const gnutls_ecc_curve_entry_st *e;
4734
0
    uint8_t pub[57]; /* can accommodate both curves */
4735
4736
0
    curve = get_eddsa_curve(algo);
4737
0
    e = _gnutls_ecc_curve_get_params(curve);
4738
0
    if (e == NULL)
4739
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4740
4741
0
    if (params->raw_pub.data == NULL) {
4742
0
      return 0; /* nothing to verify */
4743
0
    }
4744
4745
0
    if (params->raw_pub.size != e->size)
4746
0
      return gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4747
4748
0
    ret = eddsa_public_key(algo, pub, params->raw_priv.data);
4749
0
    if (ret < 0)
4750
0
      return ret;
4751
4752
0
    if (!memeq(params->raw_pub.data, pub, e->size))
4753
0
      return gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4754
4755
0
    ret = 0;
4756
0
    break;
4757
0
  }
4758
0
  case GNUTLS_PK_ECDH_X25519:
4759
0
  case GNUTLS_PK_ECDH_X448: {
4760
0
    gnutls_ecc_curve_t curve;
4761
0
    const gnutls_ecc_curve_entry_st *e;
4762
0
    uint8_t pub[57]; /* can accommodate both curves */
4763
4764
0
    curve = get_ecdh_curve(algo);
4765
0
    e = _gnutls_ecc_curve_get_params(curve);
4766
0
    if (e == NULL)
4767
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4768
4769
0
    if (params->raw_pub.data == NULL) {
4770
0
      return 0; /* nothing to verify */
4771
0
    }
4772
4773
0
    if (params->raw_pub.size != e->size)
4774
0
      return gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4775
4776
0
    ret = edwards_curve_mul_g(algo, pub, params->raw_priv.data);
4777
0
    if (ret < 0)
4778
0
      return ret;
4779
4780
0
    if (!memeq(params->raw_pub.data, pub, e->size))
4781
0
      return gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4782
4783
0
    ret = 0;
4784
0
    break;
4785
0
  }
4786
0
  case GNUTLS_PK_MLKEM768:
4787
0
  case GNUTLS_PK_MLKEM1024:
4788
0
    if (!ml_kem_exists(algo))
4789
0
      return gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
4790
4791
0
    ret = 0;
4792
0
    break;
4793
0
  case GNUTLS_PK_MLDSA44:
4794
0
  case GNUTLS_PK_MLDSA65:
4795
0
  case GNUTLS_PK_MLDSA87: {
4796
0
    if (!ml_dsa_exists(algo))
4797
0
      return gnutls_assert_val(GNUTLS_E_UNKNOWN_PK_ALGORITHM);
4798
4799
0
    ret = 0;
4800
0
    break;
4801
0
  }
4802
0
#if ENABLE_GOST
4803
0
  case GNUTLS_PK_GOST_01:
4804
0
  case GNUTLS_PK_GOST_12_256:
4805
0
  case GNUTLS_PK_GOST_12_512: {
4806
0
    struct ecc_point r, pub;
4807
0
    struct ecc_scalar priv;
4808
0
    mpz_t x1, y1, x2, y2;
4809
0
    const struct ecc_curve *curve;
4810
4811
0
    if (params->params_nr != GOST_PRIVATE_PARAMS)
4812
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4813
4814
0
    curve = get_supported_gost_curve(params->curve);
4815
0
    if (curve == NULL)
4816
0
      return gnutls_assert_val(
4817
0
        GNUTLS_E_ECC_UNSUPPORTED_CURVE);
4818
4819
0
    ret = _gost_params_to_pubkey(params, &pub, curve);
4820
0
    if (ret < 0)
4821
0
      return gnutls_assert_val(ret);
4822
4823
0
    ret = _gost_params_to_privkey(params, &priv, curve);
4824
0
    if (ret < 0) {
4825
0
      ecc_point_clear(&pub);
4826
0
      return gnutls_assert_val(ret);
4827
0
    }
4828
4829
0
    ecc_point_init(&r, curve);
4830
    /* verify that x,y lie on the curve */
4831
0
    ret = gost_point_set(&r, TOMPZ(params->params[GOST_X]),
4832
0
             TOMPZ(params->params[GOST_Y]));
4833
0
    if (ret == 0) {
4834
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4835
0
      goto gost_cleanup;
4836
0
    }
4837
0
    ecc_point_clear(&r);
4838
4839
0
    ecc_point_init(&r, curve);
4840
0
    gost_point_mul_g(&r, &priv);
4841
4842
0
    mpz_init(x1);
4843
0
    mpz_init(y1);
4844
0
    ecc_point_get(&r, x1, y1);
4845
0
    ecc_point_zclear(&r);
4846
4847
0
    mpz_init(x2);
4848
0
    mpz_init(y2);
4849
0
    ecc_point_get(&pub, x2, y2);
4850
4851
    /* verify that k*(Gx,Gy)=(x,y) */
4852
0
    if (mpz_cmp(x1, x2) != 0 || mpz_cmp(y1, y2) != 0) {
4853
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4854
0
      goto gost_cleanup;
4855
0
    }
4856
4857
0
    ret = 0;
4858
4859
0
  gost_cleanup:
4860
0
    ecc_scalar_zclear(&priv);
4861
0
    ecc_point_clear(&pub);
4862
4863
0
    mpz_clear(x1);
4864
0
    mpz_clear(y1);
4865
0
    mpz_clear(x2);
4866
0
    mpz_clear(y2);
4867
0
  } break;
4868
0
#endif
4869
0
  default:
4870
0
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4871
0
  }
4872
4873
0
  return ret;
4874
0
}
4875
4876
static int wrap_nettle_pk_verify_pub_params(gnutls_pk_algorithm_t algo,
4877
              const gnutls_pk_params_st *params)
4878
0
{
4879
0
  int ret;
4880
4881
0
  switch (algo) {
4882
0
  case GNUTLS_PK_RSA:
4883
0
  case GNUTLS_PK_RSA_PSS:
4884
0
  case GNUTLS_PK_RSA_OAEP:
4885
0
#ifdef ENABLE_DSA
4886
0
  case GNUTLS_PK_DSA:
4887
0
#endif
4888
0
  case GNUTLS_PK_EDDSA_ED25519:
4889
0
  case GNUTLS_PK_EDDSA_ED448:
4890
0
    return 0;
4891
0
  case GNUTLS_PK_ECDSA: {
4892
    /* just verify that x and y lie on the curve */
4893
0
    struct ecc_point r, pub;
4894
0
    const struct ecc_curve *curve;
4895
4896
0
    if (params->params_nr != ECC_PUBLIC_PARAMS)
4897
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4898
4899
0
    curve = get_supported_nist_curve(params->curve);
4900
0
    if (curve == NULL)
4901
0
      return gnutls_assert_val(
4902
0
        GNUTLS_E_ECC_UNSUPPORTED_CURVE);
4903
4904
0
    ret = _ecc_params_to_pubkey(params, &pub, curve);
4905
0
    if (ret < 0)
4906
0
      return gnutls_assert_val(ret);
4907
4908
0
    ecc_point_init(&r, curve);
4909
    /* verify that x,y lie on the curve */
4910
0
    ret = ecc_point_set(&r, TOMPZ(params->params[ECC_X]),
4911
0
            TOMPZ(params->params[ECC_Y]));
4912
0
    if (ret == 0) {
4913
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4914
0
      goto ecc_cleanup;
4915
0
    }
4916
0
    ecc_point_clear(&r);
4917
4918
0
    ret = 0;
4919
4920
0
  ecc_cleanup:
4921
0
    ecc_point_clear(&pub);
4922
0
  } break;
4923
0
#if ENABLE_GOST
4924
0
  case GNUTLS_PK_GOST_01:
4925
0
  case GNUTLS_PK_GOST_12_256:
4926
0
  case GNUTLS_PK_GOST_12_512: {
4927
    /* just verify that x and y lie on the curve */
4928
0
    struct ecc_point r, pub;
4929
0
    const struct ecc_curve *curve;
4930
4931
0
    if (params->params_nr != GOST_PUBLIC_PARAMS)
4932
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4933
4934
0
    curve = get_supported_gost_curve(params->curve);
4935
0
    if (curve == NULL)
4936
0
      return gnutls_assert_val(
4937
0
        GNUTLS_E_ECC_UNSUPPORTED_CURVE);
4938
4939
0
    ret = _gost_params_to_pubkey(params, &pub, curve);
4940
0
    if (ret < 0)
4941
0
      return gnutls_assert_val(ret);
4942
4943
0
    ecc_point_init(&r, curve);
4944
    /* verify that x,y lie on the curve */
4945
0
    ret = ecc_point_set(&r, TOMPZ(params->params[GOST_X]),
4946
0
            TOMPZ(params->params[GOST_Y]));
4947
0
    if (ret == 0) {
4948
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
4949
0
      goto gost_cleanup;
4950
0
    }
4951
0
    ecc_point_clear(&r);
4952
4953
0
    ret = 0;
4954
4955
0
  gost_cleanup:
4956
0
    ecc_point_clear(&pub);
4957
0
  } break;
4958
0
#endif
4959
0
  default:
4960
0
    ret = gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
4961
0
  }
4962
4963
0
  return ret;
4964
0
}
4965
4966
static int calc_rsa_exp(gnutls_pk_params_st *params)
4967
0
{
4968
0
  bigint_t tmp;
4969
0
  int ret;
4970
4971
0
  if (params->params_nr < RSA_PRIVATE_PARAMS - 2) {
4972
0
    gnutls_assert();
4973
0
    return GNUTLS_E_INTERNAL_ERROR;
4974
0
  }
4975
4976
0
  params->params[RSA_E1] = params->params[RSA_E2] = NULL;
4977
4978
0
  ret = _gnutls_mpi_init_multi(&tmp, &params->params[RSA_E1],
4979
0
             &params->params[RSA_E2], NULL);
4980
0
  if (ret < 0)
4981
0
    return gnutls_assert_val(ret);
4982
4983
  /* [6] = d % p-1, [7] = d % q-1 */
4984
0
  _gnutls_mpi_sub_ui(tmp, params->params[RSA_PRIME1], 1);
4985
0
  ret = _gnutls_mpi_modm(params->params[RSA_E1],
4986
0
             params->params[RSA_PRIV] /*d */, tmp);
4987
0
  if (ret < 0)
4988
0
    goto fail;
4989
4990
0
  _gnutls_mpi_sub_ui(tmp, params->params[RSA_PRIME2], 1);
4991
0
  ret = _gnutls_mpi_modm(params->params[RSA_E2],
4992
0
             params->params[RSA_PRIV] /*d */, tmp);
4993
0
  if (ret < 0)
4994
0
    goto fail;
4995
4996
0
  zrelease_mpi_key(&tmp);
4997
4998
0
  return 0;
4999
5000
0
fail:
5001
0
  zrelease_mpi_key(&tmp);
5002
0
  zrelease_mpi_key(&params->params[RSA_E1]);
5003
0
  zrelease_mpi_key(&params->params[RSA_E2]);
5004
5005
0
  return ret;
5006
0
}
5007
5008
static int calc_rsa_priv(gnutls_pk_params_st *params)
5009
0
{
5010
0
  bigint_t lcm, p1, q1;
5011
0
  int ret;
5012
5013
0
  params->params[RSA_PRIV] = NULL;
5014
5015
0
  ret = _gnutls_mpi_init_multi(&params->params[RSA_PRIV], &lcm, &p1, &q1,
5016
0
             NULL);
5017
0
  if (ret < 0)
5018
0
    return gnutls_assert_val(ret);
5019
5020
  /* lcm(p - 1, q - 1) */
5021
0
  mpz_sub_ui(p1, params->params[RSA_PRIME1], 1);
5022
0
  mpz_sub_ui(q1, params->params[RSA_PRIME2], 1);
5023
0
  mpz_lcm(lcm, p1, q1);
5024
5025
0
  zrelease_mpi_key(&p1);
5026
0
  zrelease_mpi_key(&q1);
5027
5028
  /* d = e^{-1} (mod lcm) */
5029
0
  ret = mpz_invert(params->params[RSA_PRIV], params->params[RSA_PUB],
5030
0
       lcm);
5031
5032
0
  zrelease_mpi_key(&lcm);
5033
5034
0
  if (ret == 0) {
5035
0
    zrelease_mpi_key(&params->params[RSA_PRIV]);
5036
0
    return GNUTLS_E_INVALID_REQUEST;
5037
0
  }
5038
5039
0
  return 0;
5040
0
}
5041
5042
#ifdef ENABLE_DSA
5043
static int calc_dsa_pub(gnutls_pk_params_st *params)
5044
0
{
5045
0
  int ret;
5046
5047
0
  params->params[DSA_Y] = NULL;
5048
5049
0
  ret = _gnutls_mpi_init(&params->params[DSA_Y]);
5050
0
  if (ret < 0)
5051
0
    return gnutls_assert_val(ret);
5052
5053
  /* y = g^x mod p */
5054
0
  ret = _gnutls_mpi_powm(params->params[DSA_Y], params->params[DSA_G],
5055
0
             params->params[DSA_X], params->params[DSA_P]);
5056
0
  if (ret < 0) {
5057
0
    zrelease_mpi_key(&params->params[DSA_Y]);
5058
0
    return gnutls_assert_val(ret);
5059
0
  }
5060
5061
0
  return 0;
5062
0
}
5063
#endif
5064
5065
static int wrap_nettle_pk_fixup(gnutls_pk_algorithm_t algo,
5066
        gnutls_direction_t direction,
5067
        gnutls_pk_params_st *params)
5068
0
{
5069
0
  int ret = 0;
5070
5071
0
  if (direction != GNUTLS_IMPORT)
5072
0
    return 0;
5073
5074
0
  switch (algo) {
5075
0
  case GNUTLS_PK_RSA: {
5076
0
    struct rsa_private_key priv;
5077
5078
0
    if (params->params[RSA_PRIV] == NULL) {
5079
0
      ret = calc_rsa_priv(params);
5080
0
      if (ret < 0)
5081
0
        return gnutls_assert_val(ret);
5082
0
      params->params_nr++;
5083
0
    }
5084
5085
    /* do not trust the generated values. Some old private keys
5086
     * generated by us have mess on the values. Those were very
5087
     * old but it seemed some of the shipped example private
5088
     * keys were as old.
5089
     */
5090
0
    if (params->params_nr < RSA_PRIVATE_PARAMS - 3)
5091
0
      return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
5092
5093
0
    if (params->params[RSA_COEF] == NULL) {
5094
0
      ret = _gnutls_mpi_init(&params->params[RSA_COEF]);
5095
0
      if (ret < 0)
5096
0
        return gnutls_assert_val(ret);
5097
0
    }
5098
5099
0
    if (mpz_cmp_ui(TOMPZ(params->params[RSA_PRIME1]), 0) == 0)
5100
0
      return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
5101
5102
0
    if (mpz_invert(TOMPZ(params->params[RSA_COEF]),
5103
0
             TOMPZ(params->params[RSA_PRIME2]),
5104
0
             TOMPZ(params->params[RSA_PRIME1])) == 0)
5105
0
      return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
5106
5107
    /* calculate exp1 [6] and exp2 [7] */
5108
0
    zrelease_mpi_key(&params->params[RSA_E1]);
5109
0
    zrelease_mpi_key(&params->params[RSA_E2]);
5110
5111
    /* marks RSA_COEF as present */
5112
0
    params->params_nr = RSA_PRIVATE_PARAMS - 2;
5113
0
    ret = calc_rsa_exp(params);
5114
0
    if (ret < 0)
5115
0
      return gnutls_assert_val(ret);
5116
5117
0
    params->params_nr = RSA_PRIVATE_PARAMS;
5118
5119
    /* perform nettle's internal checks */
5120
0
    _rsa_params_to_privkey(params, &priv);
5121
0
    ret = rsa_private_key_prepare(&priv);
5122
0
    if (ret == 0) {
5123
0
      return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
5124
0
    }
5125
0
    ret = 0;
5126
0
  } break;
5127
0
  case GNUTLS_PK_EDDSA_ED25519:
5128
0
  case GNUTLS_PK_EDDSA_ED448:
5129
0
    if (unlikely(get_eddsa_curve(algo) != params->curve))
5130
0
      return gnutls_assert_val(
5131
0
        GNUTLS_E_ECC_UNSUPPORTED_CURVE);
5132
5133
0
    if (params->raw_priv.data == NULL)
5134
0
      return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
5135
5136
0
    if (params->raw_pub.data == NULL) {
5137
0
      params->raw_pub.data =
5138
0
        gnutls_malloc(params->raw_priv.size);
5139
0
    }
5140
5141
0
    if (params->raw_pub.data == NULL)
5142
0
      return gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
5143
5144
0
    ret = eddsa_public_key(algo, params->raw_pub.data,
5145
0
               params->raw_priv.data);
5146
0
    if (ret < 0) {
5147
0
      gnutls_free(params->raw_pub.data);
5148
0
      return ret;
5149
0
    }
5150
5151
0
    params->raw_pub.size = params->raw_priv.size;
5152
0
    break;
5153
5154
0
  case GNUTLS_PK_ECDH_X25519:
5155
0
  case GNUTLS_PK_ECDH_X448:
5156
0
    if (unlikely(get_ecdh_curve(algo) != params->curve))
5157
0
      return gnutls_assert_val(
5158
0
        GNUTLS_E_ECC_UNSUPPORTED_CURVE);
5159
5160
0
    if (params->raw_priv.data == NULL)
5161
0
      return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
5162
5163
0
    if (params->raw_pub.data == NULL) {
5164
0
      params->raw_pub.data =
5165
0
        gnutls_malloc(params->raw_priv.size);
5166
0
    }
5167
5168
0
    if (params->raw_pub.data == NULL)
5169
0
      return gnutls_assert_val(GNUTLS_E_MEMORY_ERROR);
5170
5171
0
    ret = edwards_curve_mul_g(algo, params->raw_pub.data,
5172
0
            params->raw_priv.data);
5173
0
    if (ret < 0) {
5174
0
      gnutls_free(params->raw_pub.data);
5175
0
      return ret;
5176
0
    }
5177
5178
0
    params->raw_pub.size = params->raw_priv.size;
5179
0
    break;
5180
5181
0
  case GNUTLS_PK_RSA_PSS:
5182
0
    if (params->params_nr < RSA_PRIVATE_PARAMS - 3)
5183
0
      return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
5184
5185
0
    if (params->spki.rsa_pss_dig != 0) {
5186
0
      unsigned pub_size = nettle_mpz_sizeinbase_256_u(
5187
0
        TOMPZ(params->params[RSA_MODULUS]));
5188
      /* sanity check for private key */
5189
0
      CHECK_INVALID_RSA_PSS_PARAMS(
5190
0
        gnutls_hash_get_len(params->spki.rsa_pss_dig),
5191
0
        params->spki.salt_size, pub_size,
5192
0
        GNUTLS_E_PK_INVALID_PUBKEY_PARAMS);
5193
0
    }
5194
0
    break;
5195
5196
0
  case GNUTLS_PK_MLDSA44:
5197
0
  case GNUTLS_PK_MLDSA65:
5198
0
  case GNUTLS_PK_MLDSA87:
5199
0
    if (params->raw_priv.data == NULL)
5200
0
      return gnutls_assert_val(GNUTLS_E_PK_INVALID_PRIVKEY);
5201
5202
0
    if (params->raw_pub.data == NULL) {
5203
0
      ret = ml_dsa_privkey_to_pubkey(algo, &params->raw_priv,
5204
0
                   &params->raw_pub);
5205
0
      if (ret < 0) {
5206
0
        if (ret == GNUTLS_E_UNIMPLEMENTED_FEATURE) {
5207
0
          _gnutls_debug_log(
5208
0
            "Deriving public key from an ML-DSA private key is not implemented; ignoring the request\n");
5209
0
          return 0;
5210
0
        }
5211
0
        return gnutls_assert_val(ret);
5212
0
      }
5213
0
    }
5214
0
    break;
5215
5216
0
#ifdef ENABLE_DSA
5217
0
  case GNUTLS_PK_DSA:
5218
0
    if (params->params[DSA_Y] == NULL) {
5219
0
      ret = calc_dsa_pub(params);
5220
0
      if (ret < 0)
5221
0
        return gnutls_assert_val(ret);
5222
0
      params->params_nr++;
5223
0
    }
5224
0
    break;
5225
0
#endif
5226
0
#if ENABLE_GOST
5227
0
  case GNUTLS_PK_GOST_01:
5228
0
  case GNUTLS_PK_GOST_12_256:
5229
0
  case GNUTLS_PK_GOST_12_512: {
5230
0
    struct ecc_point r;
5231
0
    struct ecc_scalar priv;
5232
0
    const struct ecc_curve *curve;
5233
5234
0
    if (params->params_nr != GOST_PRIVATE_PARAMS)
5235
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
5236
5237
0
    curve = get_supported_gost_curve(params->curve);
5238
0
    if (curve == NULL)
5239
0
      return gnutls_assert_val(
5240
0
        GNUTLS_E_ECC_UNSUPPORTED_CURVE);
5241
5242
0
    if (ecc_bit_size(curve) <
5243
0
        _gnutls_mpi_get_nbits(params->params[GOST_K]))
5244
0
      gostdsa_unmask_key(curve,
5245
0
             TOMPZ(params->params[GOST_K]));
5246
5247
0
    ret = _gost_params_to_privkey(params, &priv, curve);
5248
0
    if (ret < 0) {
5249
0
      return gnutls_assert_val(ret);
5250
0
    }
5251
5252
0
    ecc_point_init(&r, curve);
5253
0
    gost_point_mul_g(&r, &priv);
5254
5255
0
    ecc_point_get(&r, params->params[GOST_X],
5256
0
            params->params[GOST_Y]);
5257
5258
0
    ecc_point_clear(&r);
5259
0
    ecc_scalar_clear(&priv);
5260
0
  } break;
5261
0
#endif
5262
0
  case GNUTLS_PK_EC:
5263
0
    if (params->params_nr == ECC_PRIVATE_PARAMS) {
5264
0
      return 0;
5265
0
    }
5266
0
    struct ecc_scalar s;
5267
0
    struct ecc_point p;
5268
0
    mpz_t pk, px, py;
5269
0
    gnutls_datum_t k = { NULL, 0 };
5270
0
    unsigned char exported_mpz_buf[MAX_PRIME_CURVE_COORD_SIZE] = {
5271
0
      0
5272
0
    };
5273
0
    uint8_t x_buf[MAX_PRIME_CURVE_COORD_SIZE] = { 0 };
5274
0
    uint8_t y_buf[MAX_PRIME_CURVE_COORD_SIZE] = { 0 };
5275
0
    size_t count = 0;
5276
5277
0
    const struct ecc_curve *ecc =
5278
0
      get_supported_nist_curve(params->curve);
5279
5280
0
    if (ecc == NULL) {
5281
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
5282
0
    }
5283
5284
0
    size_t coord_size = gnutls_ecc_curve_get_size(params->curve);
5285
0
    if (coord_size == 0) {
5286
0
      return gnutls_assert_val(GNUTLS_E_INVALID_REQUEST);
5287
0
    }
5288
5289
0
    mpz_init(pk);
5290
0
    mpz_init(px);
5291
0
    mpz_init(py);
5292
5293
0
    ret = _gnutls_mpi_dprint(params->params[ECC_K], &k);
5294
0
    if (ret != 0) {
5295
0
      ret = gnutls_assert_val(ret);
5296
0
      goto cleanup;
5297
0
    }
5298
5299
0
    mpz_import(pk, k.size, 1, 1, 1, 0, k.data);
5300
5301
0
    ecc_scalar_init(&s, ecc);
5302
5303
0
    if (!ecc_scalar_set(&s, pk)) {
5304
0
      ret = gnutls_assert_val(GNUTLS_E_ILLEGAL_PARAMETER);
5305
0
      goto cleanup;
5306
0
    }
5307
5308
0
    ecc_point_init(&p, ecc);
5309
0
    ecc_point_mul_g(&p, &s);
5310
0
    ecc_point_get(&p, px, py);
5311
5312
0
    mpz_export(exported_mpz_buf, &count, 1, 1, 1, 0, px);
5313
0
    memcpy(x_buf + (coord_size - count), exported_mpz_buf, count);
5314
5315
0
    zeroize_key(exported_mpz_buf, MAX_PRIME_CURVE_COORD_SIZE);
5316
0
    mpz_export(exported_mpz_buf, &count, 1, 1, 1, 0, py);
5317
0
    memcpy(y_buf + (coord_size - count), exported_mpz_buf, count);
5318
5319
0
    ret = _gnutls_mpi_init_scan(&params->params[ECC_X], x_buf,
5320
0
              coord_size);
5321
0
    if (ret != 0) {
5322
0
      ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
5323
0
      goto cleanup;
5324
0
    }
5325
0
    params->params_nr++;
5326
5327
0
    ret = _gnutls_mpi_init_scan(&params->params[ECC_Y], y_buf,
5328
0
              coord_size);
5329
0
    if (ret != 0) {
5330
0
      ret = gnutls_assert_val(GNUTLS_E_MPI_SCAN_FAILED);
5331
0
      goto cleanup;
5332
0
    }
5333
0
    params->params_nr++;
5334
5335
0
  cleanup:
5336
0
    ecc_point_clear(&p);
5337
0
    ecc_scalar_clear(&s);
5338
0
    mpz_clear(pk);
5339
0
    mpz_clear(px);
5340
0
    mpz_clear(py);
5341
5342
0
    _gnutls_free_key_datum(&k);
5343
0
    break;
5344
0
  default:
5345
0
    break;
5346
0
  }
5347
5348
0
  return ret;
5349
0
}
5350
5351
int crypto_pk_prio = INT_MAX;
5352
5353
gnutls_crypto_pk_st _gnutls_pk_ops = {
5354
  .encrypt = _wrap_nettle_pk_encrypt,
5355
  .decrypt = _wrap_nettle_pk_decrypt,
5356
  .decrypt2 = _wrap_nettle_pk_decrypt2,
5357
  .sign = _wrap_nettle_pk_sign,
5358
  .verify = _wrap_nettle_pk_verify,
5359
  .verify_priv_params = wrap_nettle_pk_verify_priv_params,
5360
  .verify_pub_params = wrap_nettle_pk_verify_pub_params,
5361
  .generate_params = wrap_nettle_pk_generate_params,
5362
  .generate_keys = wrap_nettle_pk_generate_keys,
5363
  .pk_fixup_private_params = wrap_nettle_pk_fixup,
5364
  .derive = _wrap_nettle_pk_derive,
5365
  .encaps = _wrap_nettle_pk_encaps,
5366
  .decaps = _wrap_nettle_pk_decaps,
5367
  .curve_exists = _wrap_nettle_pk_curve_exists,
5368
  .pk_exists = _wrap_nettle_pk_exists,
5369
  .sign_exists = _wrap_nettle_pk_sign_exists
5370
};