Latest update
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
LIBS=../../libcrypto
|
||||
SOURCE[../../libcrypto]=\
|
||||
randfile.c rand_lib.c rand_err.c rand_crng_test.c rand_egd.c \
|
||||
rand_win.c rand_unix.c rand_vms.c drbg_lib.c drbg_ctr.c rand_vxworks.c \
|
||||
drbg_hash.c drbg_hmac.c
|
||||
|
||||
$COMMON=rand_lib.c rand_crng_test.c rand_win.c rand_unix.c rand_vms.c \
|
||||
drbg_lib.c drbg_ctr.c rand_vxworks.c drbg_hash.c drbg_hmac.c
|
||||
|
||||
SOURCE[../../libcrypto]=$COMMON randfile.c rand_err.c rand_egd.c
|
||||
SOURCE[../../providers/fips]=$COMMON
|
||||
+10
-3
@@ -354,6 +354,7 @@ static int drbg_ctr_uninstantiate(RAND_DRBG *drbg)
|
||||
{
|
||||
EVP_CIPHER_CTX_free(drbg->data.ctr.ctx);
|
||||
EVP_CIPHER_CTX_free(drbg->data.ctr.ctx_df);
|
||||
EVP_CIPHER_meth_free(drbg->data.ctr.cipher);
|
||||
OPENSSL_cleanse(&drbg->data.ctr, sizeof(drbg->data.ctr));
|
||||
return 1;
|
||||
}
|
||||
@@ -369,6 +370,7 @@ int drbg_ctr_init(RAND_DRBG *drbg)
|
||||
{
|
||||
RAND_DRBG_CTR *ctr = &drbg->data.ctr;
|
||||
size_t keylen;
|
||||
EVP_CIPHER *cipher = NULL;
|
||||
|
||||
switch (drbg->type) {
|
||||
default:
|
||||
@@ -376,17 +378,22 @@ int drbg_ctr_init(RAND_DRBG *drbg)
|
||||
return 0;
|
||||
case NID_aes_128_ctr:
|
||||
keylen = 16;
|
||||
ctr->cipher = EVP_aes_128_ecb();
|
||||
cipher = EVP_CIPHER_fetch(drbg->libctx, "AES-128-ECB", "");
|
||||
break;
|
||||
case NID_aes_192_ctr:
|
||||
keylen = 24;
|
||||
ctr->cipher = EVP_aes_192_ecb();
|
||||
cipher = EVP_CIPHER_fetch(drbg->libctx, "AES-192-ECB", "");
|
||||
break;
|
||||
case NID_aes_256_ctr:
|
||||
keylen = 32;
|
||||
ctr->cipher = EVP_aes_256_ecb();
|
||||
cipher = EVP_CIPHER_fetch(drbg->libctx, "AES-256-ECB", "");
|
||||
break;
|
||||
}
|
||||
if (cipher == NULL)
|
||||
return 0;
|
||||
|
||||
EVP_CIPHER_meth_free(ctr->cipher);
|
||||
ctr->cipher = cipher;
|
||||
|
||||
drbg->meth = &drbg_ctr_meth;
|
||||
|
||||
|
||||
+39
-5
@@ -14,6 +14,7 @@
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/rand.h>
|
||||
#include "internal/thread_once.h"
|
||||
#include "internal/providercommon.h"
|
||||
#include "rand_lcl.h"
|
||||
|
||||
/* 440 bits from SP800-90Ar1 10.1 table 2 */
|
||||
@@ -289,6 +290,7 @@ static int drbg_hash_generate(RAND_DRBG *drbg,
|
||||
|
||||
static int drbg_hash_uninstantiate(RAND_DRBG *drbg)
|
||||
{
|
||||
EVP_MD_meth_free(drbg->data.hash.md);
|
||||
EVP_MD_CTX_free(drbg->data.hash.ctx);
|
||||
OPENSSL_cleanse(&drbg->data.hash, sizeof(drbg->data.hash));
|
||||
return 1;
|
||||
@@ -303,23 +305,55 @@ static RAND_DRBG_METHOD drbg_hash_meth = {
|
||||
|
||||
int drbg_hash_init(RAND_DRBG *drbg)
|
||||
{
|
||||
const EVP_MD *md;
|
||||
EVP_MD *md;
|
||||
RAND_DRBG_HASH *hash = &drbg->data.hash;
|
||||
|
||||
/* Any approved digest is allowed */
|
||||
md = EVP_get_digestbynid(drbg->type);
|
||||
/*
|
||||
* Confirm digest is allowed. Outside FIPS_MODE we allow all non-legacy
|
||||
* digests. Inside FIPS_MODE we only allow approved digests. Also no XOF
|
||||
* digests (such as SHAKE).
|
||||
*/
|
||||
switch (drbg->type) {
|
||||
default:
|
||||
return 0;
|
||||
|
||||
case NID_sha1:
|
||||
case NID_sha224:
|
||||
case NID_sha256:
|
||||
case NID_sha384:
|
||||
case NID_sha512:
|
||||
case NID_sha512_224:
|
||||
case NID_sha512_256:
|
||||
case NID_sha3_224:
|
||||
case NID_sha3_256:
|
||||
case NID_sha3_384:
|
||||
case NID_sha3_512:
|
||||
#ifndef FIPS_MODE
|
||||
case NID_blake2b512:
|
||||
case NID_blake2s256:
|
||||
case NID_sm3:
|
||||
#endif
|
||||
break;
|
||||
}
|
||||
|
||||
md = EVP_MD_fetch(drbg->libctx, ossl_prov_util_nid_to_name(drbg->type), "");
|
||||
if (md == NULL)
|
||||
return 0;
|
||||
|
||||
|
||||
drbg->meth = &drbg_hash_meth;
|
||||
hash->md = md;
|
||||
|
||||
if (hash->ctx == NULL) {
|
||||
hash->ctx = EVP_MD_CTX_new();
|
||||
if (hash->ctx == NULL)
|
||||
if (hash->ctx == NULL) {
|
||||
EVP_MD_meth_free(md);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
|
||||
EVP_MD_meth_free(hash->md);
|
||||
hash->md = md;
|
||||
|
||||
/* These are taken from SP 800-90 10.1 Table 2 */
|
||||
hash->blocklen = EVP_MD_size(md);
|
||||
/* See SP800-57 Part1 Rev4 5.6.1 Table 3 */
|
||||
|
||||
+36
-4
@@ -13,6 +13,7 @@
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/rand.h>
|
||||
#include "internal/thread_once.h"
|
||||
#include "internal/providercommon.h"
|
||||
#include "rand_lcl.h"
|
||||
|
||||
/*
|
||||
@@ -183,6 +184,7 @@ static int drbg_hmac_generate(RAND_DRBG *drbg,
|
||||
|
||||
static int drbg_hmac_uninstantiate(RAND_DRBG *drbg)
|
||||
{
|
||||
EVP_MD_meth_free(drbg->data.hmac.md);
|
||||
HMAC_CTX_free(drbg->data.hmac.ctx);
|
||||
OPENSSL_cleanse(&drbg->data.hmac, sizeof(drbg->data.hmac));
|
||||
return 1;
|
||||
@@ -197,11 +199,38 @@ static RAND_DRBG_METHOD drbg_hmac_meth = {
|
||||
|
||||
int drbg_hmac_init(RAND_DRBG *drbg)
|
||||
{
|
||||
const EVP_MD *md = NULL;
|
||||
EVP_MD *md = NULL;
|
||||
RAND_DRBG_HMAC *hmac = &drbg->data.hmac;
|
||||
|
||||
/* Any approved digest is allowed - assume we pass digest (not NID_hmac*) */
|
||||
md = EVP_get_digestbynid(drbg->type);
|
||||
/*
|
||||
* Confirm digest is allowed. Outside FIPS_MODE we allow all non-legacy
|
||||
* digests. Inside FIPS_MODE we only allow approved digests. Also no XOF
|
||||
* digests (such as SHAKE).
|
||||
*/
|
||||
switch (drbg->type) {
|
||||
default:
|
||||
return 0;
|
||||
|
||||
case NID_sha1:
|
||||
case NID_sha224:
|
||||
case NID_sha256:
|
||||
case NID_sha384:
|
||||
case NID_sha512:
|
||||
case NID_sha512_224:
|
||||
case NID_sha512_256:
|
||||
case NID_sha3_224:
|
||||
case NID_sha3_256:
|
||||
case NID_sha3_384:
|
||||
case NID_sha3_512:
|
||||
#ifndef FIPS_MODE
|
||||
case NID_blake2b512:
|
||||
case NID_blake2s256:
|
||||
case NID_sm3:
|
||||
#endif
|
||||
break;
|
||||
}
|
||||
|
||||
md = EVP_MD_fetch(drbg->libctx, ossl_prov_util_nid_to_name(drbg->type), "");
|
||||
if (md == NULL)
|
||||
return 0;
|
||||
|
||||
@@ -209,11 +238,14 @@ int drbg_hmac_init(RAND_DRBG *drbg)
|
||||
|
||||
if (hmac->ctx == NULL) {
|
||||
hmac->ctx = HMAC_CTX_new();
|
||||
if (hmac->ctx == NULL)
|
||||
if (hmac->ctx == NULL) {
|
||||
EVP_MD_meth_free(md);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
|
||||
/* These are taken from SP 800-90 10.1 Table 2 */
|
||||
EVP_MD_meth_free(hmac->md);
|
||||
hmac->md = md;
|
||||
hmac->blocklen = EVP_MD_size(md);
|
||||
/* See SP800-57 Part1 Rev4 5.6.1 Table 3 */
|
||||
|
||||
+265
-110
@@ -29,49 +29,54 @@
|
||||
* a much bigger deal than just re-setting an allocated resource.)
|
||||
*/
|
||||
|
||||
/*
|
||||
* The three shared DRBG instances
|
||||
*
|
||||
* There are three shared DRBG instances: <master>, <public>, and <private>.
|
||||
*/
|
||||
|
||||
/*
|
||||
* The <master> DRBG
|
||||
*
|
||||
* Not used directly by the application, only for reseeding the two other
|
||||
* DRBGs. It reseeds itself by pulling either randomness from os entropy
|
||||
* sources or by consuming randomness which was added by RAND_add().
|
||||
*
|
||||
* The <master> DRBG is a global instance which is accessed concurrently by
|
||||
* all threads. The necessary locking is managed automatically by its child
|
||||
* DRBG instances during reseeding.
|
||||
*/
|
||||
static RAND_DRBG *master_drbg;
|
||||
/*
|
||||
* The <public> DRBG
|
||||
*
|
||||
* Used by default for generating random bytes using RAND_bytes().
|
||||
*
|
||||
* The <public> DRBG is thread-local, i.e., there is one instance per thread.
|
||||
*/
|
||||
static CRYPTO_THREAD_LOCAL public_drbg;
|
||||
/*
|
||||
* The <private> DRBG
|
||||
*
|
||||
* Used by default for generating private keys using RAND_priv_bytes()
|
||||
*
|
||||
* The <private> DRBG is thread-local, i.e., there is one instance per thread.
|
||||
*/
|
||||
static CRYPTO_THREAD_LOCAL private_drbg;
|
||||
typedef struct drbg_global_st {
|
||||
/*
|
||||
* The three shared DRBG instances
|
||||
*
|
||||
* There are three shared DRBG instances: <master>, <public>, and <private>.
|
||||
*/
|
||||
|
||||
/*
|
||||
* The <master> DRBG
|
||||
*
|
||||
* Not used directly by the application, only for reseeding the two other
|
||||
* DRBGs. It reseeds itself by pulling either randomness from os entropy
|
||||
* sources or by consuming randomness which was added by RAND_add().
|
||||
*
|
||||
* The <master> DRBG is a global instance which is accessed concurrently by
|
||||
* all threads. The necessary locking is managed automatically by its child
|
||||
* DRBG instances during reseeding.
|
||||
*/
|
||||
RAND_DRBG *master_drbg;
|
||||
/*
|
||||
* The <public> DRBG
|
||||
*
|
||||
* Used by default for generating random bytes using RAND_bytes().
|
||||
*
|
||||
* The <public> DRBG is thread-local, i.e., there is one instance per
|
||||
* thread.
|
||||
*/
|
||||
CRYPTO_THREAD_LOCAL public_drbg;
|
||||
/*
|
||||
* The <private> DRBG
|
||||
*
|
||||
* Used by default for generating private keys using RAND_priv_bytes()
|
||||
*
|
||||
* The <private> DRBG is thread-local, i.e., there is one instance per
|
||||
* thread.
|
||||
*/
|
||||
CRYPTO_THREAD_LOCAL private_drbg;
|
||||
} DRBG_GLOBAL;
|
||||
|
||||
typedef struct drbg_nonce_global_st {
|
||||
CRYPTO_RWLOCK *rand_nonce_lock;
|
||||
int rand_nonce_count;
|
||||
} DRBG_NONCE_GLOBAL;
|
||||
|
||||
/* NIST SP 800-90A DRBG recommends the use of a personalization string. */
|
||||
static const char ossl_pers_string[] = DRBG_DEFAULT_PERS_STRING;
|
||||
|
||||
static CRYPTO_ONCE rand_drbg_init = CRYPTO_ONCE_STATIC_INIT;
|
||||
|
||||
|
||||
#define RAND_DRBG_TYPE_FLAGS ( \
|
||||
RAND_DRBG_FLAG_MASTER | RAND_DRBG_FLAG_PUBLIC | RAND_DRBG_FLAG_PRIVATE )
|
||||
|
||||
@@ -102,9 +107,10 @@ static const unsigned int rand_drbg_used_flags =
|
||||
RAND_DRBG_FLAG_CTR_NO_DF | RAND_DRBG_FLAG_HMAC | RAND_DRBG_TYPE_FLAGS;
|
||||
|
||||
|
||||
static RAND_DRBG *drbg_setup(RAND_DRBG *parent, int drbg_type);
|
||||
static RAND_DRBG *drbg_setup(OPENSSL_CTX *ctx, RAND_DRBG *parent, int drbg_type);
|
||||
|
||||
static RAND_DRBG *rand_drbg_new(int secure,
|
||||
static RAND_DRBG *rand_drbg_new(OPENSSL_CTX *ctx,
|
||||
int secure,
|
||||
int type,
|
||||
unsigned int flags,
|
||||
RAND_DRBG *parent);
|
||||
@@ -141,6 +147,157 @@ static int is_digest(int type)
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Initialize the OPENSSL_CTX global DRBGs on first use.
|
||||
* Returns the allocated global data on success or NULL on failure.
|
||||
*/
|
||||
static void *drbg_ossl_ctx_new(OPENSSL_CTX *libctx)
|
||||
{
|
||||
DRBG_GLOBAL *dgbl = OPENSSL_zalloc(sizeof(*dgbl));
|
||||
|
||||
if (dgbl == NULL)
|
||||
return NULL;
|
||||
|
||||
#ifndef FIPS_MODE
|
||||
/*
|
||||
* We need to ensure that base libcrypto thread handling has been
|
||||
* initialised.
|
||||
*/
|
||||
OPENSSL_init_crypto(0, NULL);
|
||||
#endif
|
||||
|
||||
if (!CRYPTO_THREAD_init_local(&dgbl->private_drbg, NULL))
|
||||
goto err1;
|
||||
|
||||
if (!CRYPTO_THREAD_init_local(&dgbl->public_drbg, NULL))
|
||||
goto err2;
|
||||
|
||||
dgbl->master_drbg = drbg_setup(libctx, NULL, RAND_DRBG_TYPE_MASTER);
|
||||
if (dgbl->master_drbg == NULL)
|
||||
goto err3;
|
||||
|
||||
return dgbl;
|
||||
|
||||
err3:
|
||||
CRYPTO_THREAD_cleanup_local(&dgbl->public_drbg);
|
||||
err2:
|
||||
CRYPTO_THREAD_cleanup_local(&dgbl->private_drbg);
|
||||
err1:
|
||||
OPENSSL_free(dgbl);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static void drbg_ossl_ctx_free(void *vdgbl)
|
||||
{
|
||||
DRBG_GLOBAL *dgbl = vdgbl;
|
||||
|
||||
RAND_DRBG_free(dgbl->master_drbg);
|
||||
CRYPTO_THREAD_cleanup_local(&dgbl->private_drbg);
|
||||
CRYPTO_THREAD_cleanup_local(&dgbl->public_drbg);
|
||||
|
||||
OPENSSL_free(dgbl);
|
||||
}
|
||||
|
||||
static const OPENSSL_CTX_METHOD drbg_ossl_ctx_method = {
|
||||
drbg_ossl_ctx_new,
|
||||
drbg_ossl_ctx_free,
|
||||
};
|
||||
|
||||
/*
|
||||
* drbg_ossl_ctx_new() calls drgb_setup() which calls rand_drbg_get_nonce()
|
||||
* which needs to get the rand_nonce_lock out of the OPENSSL_CTX...but since
|
||||
* drbg_ossl_ctx_new() hasn't finished running yet we need the rand_nonce_lock
|
||||
* to be in a different global data object. Otherwise we will go into an
|
||||
* infinite recursion loop.
|
||||
*/
|
||||
static void *drbg_nonce_ossl_ctx_new(OPENSSL_CTX *libctx)
|
||||
{
|
||||
DRBG_NONCE_GLOBAL *dngbl = OPENSSL_zalloc(sizeof(*dngbl));
|
||||
|
||||
if (dngbl == NULL)
|
||||
return NULL;
|
||||
|
||||
dngbl->rand_nonce_lock = CRYPTO_THREAD_lock_new();
|
||||
if (dngbl->rand_nonce_lock == NULL) {
|
||||
OPENSSL_free(dngbl);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
return dngbl;
|
||||
}
|
||||
|
||||
static void drbg_nonce_ossl_ctx_free(void *vdngbl)
|
||||
{
|
||||
DRBG_NONCE_GLOBAL *dngbl = vdngbl;
|
||||
|
||||
CRYPTO_THREAD_lock_free(dngbl->rand_nonce_lock);
|
||||
|
||||
OPENSSL_free(dngbl);
|
||||
}
|
||||
|
||||
static const OPENSSL_CTX_METHOD drbg_nonce_ossl_ctx_method = {
|
||||
drbg_nonce_ossl_ctx_new,
|
||||
drbg_nonce_ossl_ctx_free,
|
||||
};
|
||||
|
||||
static DRBG_GLOBAL *drbg_get_global(OPENSSL_CTX *libctx)
|
||||
{
|
||||
return openssl_ctx_get_data(libctx, OPENSSL_CTX_DRBG_INDEX,
|
||||
&drbg_ossl_ctx_method);
|
||||
}
|
||||
|
||||
/* Implements the get_nonce() callback (see RAND_DRBG_set_callbacks()) */
|
||||
size_t rand_drbg_get_nonce(RAND_DRBG *drbg,
|
||||
unsigned char **pout,
|
||||
int entropy, size_t min_len, size_t max_len)
|
||||
{
|
||||
size_t ret = 0;
|
||||
RAND_POOL *pool;
|
||||
DRBG_NONCE_GLOBAL *dngbl
|
||||
= openssl_ctx_get_data(drbg->libctx, OPENSSL_CTX_DRBG_NONCE_INDEX,
|
||||
&drbg_nonce_ossl_ctx_method);
|
||||
struct {
|
||||
void *instance;
|
||||
int count;
|
||||
} data;
|
||||
|
||||
if (dngbl == NULL)
|
||||
return 0;
|
||||
|
||||
memset(&data, 0, sizeof(data));
|
||||
pool = rand_pool_new(0, min_len, max_len);
|
||||
if (pool == NULL)
|
||||
return 0;
|
||||
|
||||
if (rand_pool_add_nonce_data(pool) == 0)
|
||||
goto err;
|
||||
|
||||
data.instance = drbg;
|
||||
CRYPTO_atomic_add(&dngbl->rand_nonce_count, 1, &data.count,
|
||||
dngbl->rand_nonce_lock);
|
||||
|
||||
if (rand_pool_add(pool, (unsigned char *)&data, sizeof(data), 0) == 0)
|
||||
goto err;
|
||||
|
||||
ret = rand_pool_length(pool);
|
||||
*pout = rand_pool_detach(pool);
|
||||
|
||||
err:
|
||||
rand_pool_free(pool);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/*
|
||||
* Implements the cleanup_nonce() callback (see RAND_DRBG_set_callbacks())
|
||||
*
|
||||
*/
|
||||
void rand_drbg_cleanup_nonce(RAND_DRBG *drbg,
|
||||
unsigned char *out, size_t outlen)
|
||||
{
|
||||
OPENSSL_secure_clear_free(out, outlen);
|
||||
}
|
||||
|
||||
/*
|
||||
* Set/initialize |drbg| to be of type |type|, with optional |flags|.
|
||||
*
|
||||
@@ -236,7 +393,8 @@ int RAND_DRBG_set_defaults(int type, unsigned int flags)
|
||||
*
|
||||
* Returns a pointer to the new DRBG instance on success, NULL on failure.
|
||||
*/
|
||||
static RAND_DRBG *rand_drbg_new(int secure,
|
||||
static RAND_DRBG *rand_drbg_new(OPENSSL_CTX *ctx,
|
||||
int secure,
|
||||
int type,
|
||||
unsigned int flags,
|
||||
RAND_DRBG *parent)
|
||||
@@ -249,6 +407,7 @@ static RAND_DRBG *rand_drbg_new(int secure,
|
||||
return NULL;
|
||||
}
|
||||
|
||||
drbg->libctx = ctx;
|
||||
drbg->secure = secure && CRYPTO_secure_allocated(drbg);
|
||||
drbg->fork_count = rand_fork_count;
|
||||
drbg->parent = parent;
|
||||
@@ -305,16 +464,27 @@ static RAND_DRBG *rand_drbg_new(int secure,
|
||||
return NULL;
|
||||
}
|
||||
|
||||
RAND_DRBG *RAND_DRBG_new_ex(OPENSSL_CTX *ctx, int type, unsigned int flags,
|
||||
RAND_DRBG *parent)
|
||||
{
|
||||
return rand_drbg_new(ctx, 0, type, flags, parent);
|
||||
}
|
||||
|
||||
RAND_DRBG *RAND_DRBG_new(int type, unsigned int flags, RAND_DRBG *parent)
|
||||
{
|
||||
return rand_drbg_new(0, type, flags, parent);
|
||||
return RAND_DRBG_new_ex(NULL, type, flags, parent);
|
||||
}
|
||||
|
||||
RAND_DRBG *RAND_DRBG_secure_new_ex(OPENSSL_CTX *ctx, int type,
|
||||
unsigned int flags, RAND_DRBG *parent)
|
||||
{
|
||||
return rand_drbg_new(ctx, 1, type, flags, parent);
|
||||
}
|
||||
|
||||
RAND_DRBG *RAND_DRBG_secure_new(int type, unsigned int flags, RAND_DRBG *parent)
|
||||
{
|
||||
return rand_drbg_new(1, type, flags, parent);
|
||||
return RAND_DRBG_secure_new_ex(NULL, type, flags, parent);
|
||||
}
|
||||
|
||||
/*
|
||||
* Uninstantiate |drbg| and free all memory.
|
||||
*/
|
||||
@@ -376,7 +546,7 @@ int RAND_DRBG_instantiate(RAND_DRBG *drbg,
|
||||
/*
|
||||
* NIST SP800-90Ar1 section 9.1 says you can combine getting the entropy
|
||||
* and nonce in 1 call by increasing the entropy with 50% and increasing
|
||||
* the minimum length to accomadate the length of the nonce.
|
||||
* the minimum length to accommodate the length of the nonce.
|
||||
* We do this in case a nonce is require and get_nonce is NULL.
|
||||
*/
|
||||
if (drbg->min_noncelen > 0 && drbg->get_nonce == NULL) {
|
||||
@@ -943,12 +1113,12 @@ void *RAND_DRBG_get_ex_data(const RAND_DRBG *drbg, int idx)
|
||||
*
|
||||
* Returns a pointer to the new DRBG instance on success, NULL on failure.
|
||||
*/
|
||||
static RAND_DRBG *drbg_setup(RAND_DRBG *parent, int drbg_type)
|
||||
static RAND_DRBG *drbg_setup(OPENSSL_CTX *ctx, RAND_DRBG *parent, int drbg_type)
|
||||
{
|
||||
RAND_DRBG *drbg;
|
||||
|
||||
drbg = RAND_DRBG_secure_new(rand_drbg_type[drbg_type],
|
||||
rand_drbg_flags[drbg_type], parent);
|
||||
drbg = RAND_DRBG_secure_new_ex(ctx, rand_drbg_type[drbg_type],
|
||||
rand_drbg_flags[drbg_type], parent);
|
||||
if (drbg == NULL)
|
||||
return NULL;
|
||||
|
||||
@@ -975,60 +1145,20 @@ err:
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/*
|
||||
* Initialize the global DRBGs on first use.
|
||||
* Returns 1 on success, 0 on failure.
|
||||
*/
|
||||
DEFINE_RUN_ONCE_STATIC(do_rand_drbg_init)
|
||||
{
|
||||
/*
|
||||
* ensure that libcrypto is initialized, otherwise the
|
||||
* DRBG locks are not cleaned up properly
|
||||
*/
|
||||
if (!OPENSSL_init_crypto(0, NULL))
|
||||
return 0;
|
||||
|
||||
if (!CRYPTO_THREAD_init_local(&private_drbg, NULL))
|
||||
return 0;
|
||||
|
||||
if (!CRYPTO_THREAD_init_local(&public_drbg, NULL))
|
||||
goto err1;
|
||||
|
||||
master_drbg = drbg_setup(NULL, RAND_DRBG_TYPE_MASTER);
|
||||
if (master_drbg == NULL)
|
||||
goto err2;
|
||||
|
||||
return 1;
|
||||
|
||||
err2:
|
||||
CRYPTO_THREAD_cleanup_local(&public_drbg);
|
||||
err1:
|
||||
CRYPTO_THREAD_cleanup_local(&private_drbg);
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Clean up the global DRBGs before exit */
|
||||
void rand_drbg_cleanup_int(void)
|
||||
{
|
||||
if (master_drbg != NULL) {
|
||||
RAND_DRBG_free(master_drbg);
|
||||
master_drbg = NULL;
|
||||
|
||||
CRYPTO_THREAD_cleanup_local(&private_drbg);
|
||||
CRYPTO_THREAD_cleanup_local(&public_drbg);
|
||||
}
|
||||
}
|
||||
|
||||
void drbg_delete_thread_state(void)
|
||||
static void drbg_delete_thread_state(void *arg)
|
||||
{
|
||||
OPENSSL_CTX *ctx = arg;
|
||||
DRBG_GLOBAL *dgbl = drbg_get_global(ctx);
|
||||
RAND_DRBG *drbg;
|
||||
|
||||
drbg = CRYPTO_THREAD_get_local(&public_drbg);
|
||||
CRYPTO_THREAD_set_local(&public_drbg, NULL);
|
||||
if (dgbl == NULL)
|
||||
return;
|
||||
drbg = CRYPTO_THREAD_get_local(&dgbl->public_drbg);
|
||||
CRYPTO_THREAD_set_local(&dgbl->public_drbg, NULL);
|
||||
RAND_DRBG_free(drbg);
|
||||
|
||||
drbg = CRYPTO_THREAD_get_local(&private_drbg);
|
||||
CRYPTO_THREAD_set_local(&private_drbg, NULL);
|
||||
drbg = CRYPTO_THREAD_get_local(&dgbl->private_drbg);
|
||||
CRYPTO_THREAD_set_local(&dgbl->private_drbg, NULL);
|
||||
RAND_DRBG_free(drbg);
|
||||
}
|
||||
|
||||
@@ -1180,56 +1310,77 @@ static int drbg_status(void)
|
||||
* Returns pointer to the DRBG on success, NULL on failure.
|
||||
*
|
||||
*/
|
||||
RAND_DRBG *RAND_DRBG_get0_master(void)
|
||||
RAND_DRBG *OPENSSL_CTX_get0_master_drbg(OPENSSL_CTX *ctx)
|
||||
{
|
||||
if (!RUN_ONCE(&rand_drbg_init, do_rand_drbg_init))
|
||||
DRBG_GLOBAL *dgbl = drbg_get_global(ctx);
|
||||
|
||||
if (dgbl == NULL)
|
||||
return NULL;
|
||||
|
||||
return master_drbg;
|
||||
return dgbl->master_drbg;
|
||||
}
|
||||
|
||||
RAND_DRBG *RAND_DRBG_get0_master(void)
|
||||
{
|
||||
return OPENSSL_CTX_get0_master_drbg(NULL);
|
||||
}
|
||||
|
||||
/*
|
||||
* Get the public DRBG.
|
||||
* Returns pointer to the DRBG on success, NULL on failure.
|
||||
*/
|
||||
RAND_DRBG *RAND_DRBG_get0_public(void)
|
||||
RAND_DRBG *OPENSSL_CTX_get0_public_drbg(OPENSSL_CTX *ctx)
|
||||
{
|
||||
DRBG_GLOBAL *dgbl = drbg_get_global(ctx);
|
||||
RAND_DRBG *drbg;
|
||||
|
||||
if (!RUN_ONCE(&rand_drbg_init, do_rand_drbg_init))
|
||||
if (dgbl == NULL)
|
||||
return NULL;
|
||||
|
||||
drbg = CRYPTO_THREAD_get_local(&public_drbg);
|
||||
drbg = CRYPTO_THREAD_get_local(&dgbl->public_drbg);
|
||||
if (drbg == NULL) {
|
||||
if (!ossl_init_thread_start(OPENSSL_INIT_THREAD_RAND))
|
||||
ctx = openssl_ctx_get_concrete(ctx);
|
||||
if (!ossl_init_thread_start(NULL, ctx, drbg_delete_thread_state))
|
||||
return NULL;
|
||||
drbg = drbg_setup(master_drbg, RAND_DRBG_TYPE_PUBLIC);
|
||||
CRYPTO_THREAD_set_local(&public_drbg, drbg);
|
||||
drbg = drbg_setup(ctx, dgbl->master_drbg, RAND_DRBG_TYPE_PUBLIC);
|
||||
CRYPTO_THREAD_set_local(&dgbl->public_drbg, drbg);
|
||||
}
|
||||
return drbg;
|
||||
}
|
||||
|
||||
RAND_DRBG *RAND_DRBG_get0_public(void)
|
||||
{
|
||||
return OPENSSL_CTX_get0_public_drbg(NULL);
|
||||
}
|
||||
|
||||
/*
|
||||
* Get the private DRBG.
|
||||
* Returns pointer to the DRBG on success, NULL on failure.
|
||||
*/
|
||||
RAND_DRBG *RAND_DRBG_get0_private(void)
|
||||
RAND_DRBG *OPENSSL_CTX_get0_private_drbg(OPENSSL_CTX *ctx)
|
||||
{
|
||||
DRBG_GLOBAL *dgbl = drbg_get_global(ctx);
|
||||
RAND_DRBG *drbg;
|
||||
|
||||
if (!RUN_ONCE(&rand_drbg_init, do_rand_drbg_init))
|
||||
if (dgbl == NULL)
|
||||
return NULL;
|
||||
|
||||
drbg = CRYPTO_THREAD_get_local(&private_drbg);
|
||||
drbg = CRYPTO_THREAD_get_local(&dgbl->private_drbg);
|
||||
if (drbg == NULL) {
|
||||
if (!ossl_init_thread_start(OPENSSL_INIT_THREAD_RAND))
|
||||
ctx = openssl_ctx_get_concrete(ctx);
|
||||
if (!ossl_init_thread_start(NULL, ctx, drbg_delete_thread_state))
|
||||
return NULL;
|
||||
drbg = drbg_setup(master_drbg, RAND_DRBG_TYPE_PRIVATE);
|
||||
CRYPTO_THREAD_set_local(&private_drbg, drbg);
|
||||
drbg = drbg_setup(ctx, dgbl->master_drbg, RAND_DRBG_TYPE_PRIVATE);
|
||||
CRYPTO_THREAD_set_local(&dgbl->private_drbg, drbg);
|
||||
}
|
||||
return drbg;
|
||||
}
|
||||
|
||||
RAND_DRBG *RAND_DRBG_get0_private(void)
|
||||
{
|
||||
return OPENSSL_CTX_get0_private_drbg(NULL);
|
||||
}
|
||||
|
||||
RAND_METHOD rand_meth = {
|
||||
drbg_seed,
|
||||
drbg_bytes,
|
||||
@@ -1241,5 +1392,9 @@ RAND_METHOD rand_meth = {
|
||||
|
||||
RAND_METHOD *RAND_OpenSSL(void)
|
||||
{
|
||||
#ifndef FIPS_MODE
|
||||
return &rand_meth;
|
||||
#else
|
||||
return NULL;
|
||||
#endif
|
||||
}
|
||||
@@ -16,66 +16,83 @@
|
||||
#include <openssl/evp.h>
|
||||
#include "internal/rand_int.h"
|
||||
#include "internal/thread_once.h"
|
||||
#include "internal/cryptlib.h"
|
||||
#include "rand_lcl.h"
|
||||
|
||||
static RAND_POOL *crngt_pool;
|
||||
static unsigned char crngt_prev[EVP_MAX_MD_SIZE];
|
||||
typedef struct crng_test_global_st {
|
||||
unsigned char crngt_prev[EVP_MAX_MD_SIZE];
|
||||
RAND_POOL *crngt_pool;
|
||||
} CRNG_TEST_GLOBAL;
|
||||
|
||||
int (*crngt_get_entropy)(unsigned char *, unsigned char *, unsigned int *)
|
||||
int (*crngt_get_entropy)(OPENSSL_CTX *, RAND_POOL *, unsigned char *,
|
||||
unsigned char *, unsigned int *)
|
||||
= &rand_crngt_get_entropy_cb;
|
||||
|
||||
int rand_crngt_get_entropy_cb(unsigned char *buf, unsigned char *md,
|
||||
static void rand_crng_ossl_ctx_free(void *vcrngt_glob)
|
||||
{
|
||||
CRNG_TEST_GLOBAL *crngt_glob = vcrngt_glob;
|
||||
|
||||
rand_pool_free(crngt_glob->crngt_pool);
|
||||
OPENSSL_free(crngt_glob);
|
||||
}
|
||||
|
||||
static void *rand_crng_ossl_ctx_new(OPENSSL_CTX *ctx)
|
||||
{
|
||||
unsigned char buf[CRNGT_BUFSIZ];
|
||||
CRNG_TEST_GLOBAL *crngt_glob = OPENSSL_zalloc(sizeof(*crngt_glob));
|
||||
|
||||
if (crngt_glob == NULL)
|
||||
return NULL;
|
||||
|
||||
if ((crngt_glob->crngt_pool
|
||||
= rand_pool_new(0, CRNGT_BUFSIZ, CRNGT_BUFSIZ)) == NULL) {
|
||||
OPENSSL_free(crngt_glob);
|
||||
return NULL;
|
||||
}
|
||||
if (crngt_get_entropy(ctx, crngt_glob->crngt_pool, buf,
|
||||
crngt_glob->crngt_prev, NULL)) {
|
||||
OPENSSL_cleanse(buf, sizeof(buf));
|
||||
return crngt_glob;
|
||||
}
|
||||
rand_pool_free(crngt_glob->crngt_pool);
|
||||
OPENSSL_free(crngt_glob);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static const OPENSSL_CTX_METHOD rand_crng_ossl_ctx_method = {
|
||||
rand_crng_ossl_ctx_new,
|
||||
rand_crng_ossl_ctx_free,
|
||||
};
|
||||
|
||||
int rand_crngt_get_entropy_cb(OPENSSL_CTX *ctx,
|
||||
RAND_POOL *pool,
|
||||
unsigned char *buf,
|
||||
unsigned char *md,
|
||||
unsigned int *md_size)
|
||||
{
|
||||
int r;
|
||||
size_t n;
|
||||
unsigned char *p;
|
||||
|
||||
n = rand_pool_acquire_entropy(crngt_pool);
|
||||
if (pool == NULL)
|
||||
return 0;
|
||||
|
||||
n = rand_pool_acquire_entropy(pool);
|
||||
if (n >= CRNGT_BUFSIZ) {
|
||||
p = rand_pool_detach(crngt_pool);
|
||||
r = EVP_Digest(p, CRNGT_BUFSIZ, md, md_size, EVP_sha256(), NULL);
|
||||
EVP_MD *fmd = EVP_MD_fetch(ctx, "SHA256", "");
|
||||
if (fmd == NULL)
|
||||
return 0;
|
||||
p = rand_pool_detach(pool);
|
||||
r = EVP_Digest(p, CRNGT_BUFSIZ, md, md_size, fmd, NULL);
|
||||
if (r != 0)
|
||||
memcpy(buf, p, CRNGT_BUFSIZ);
|
||||
rand_pool_reattach(crngt_pool, p);
|
||||
rand_pool_reattach(pool, p);
|
||||
EVP_MD_meth_free(fmd);
|
||||
return r;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
void rand_crngt_cleanup(void)
|
||||
{
|
||||
rand_pool_free(crngt_pool);
|
||||
crngt_pool = NULL;
|
||||
}
|
||||
|
||||
int rand_crngt_init(void)
|
||||
{
|
||||
unsigned char buf[CRNGT_BUFSIZ];
|
||||
|
||||
if ((crngt_pool = rand_pool_new(0, CRNGT_BUFSIZ, CRNGT_BUFSIZ)) == NULL)
|
||||
return 0;
|
||||
if (crngt_get_entropy(buf, crngt_prev, NULL)) {
|
||||
OPENSSL_cleanse(buf, sizeof(buf));
|
||||
return 1;
|
||||
}
|
||||
rand_crngt_cleanup();
|
||||
return 0;
|
||||
}
|
||||
|
||||
static CRYPTO_ONCE rand_crngt_init_flag = CRYPTO_ONCE_STATIC_INIT;
|
||||
DEFINE_RUN_ONCE_STATIC(do_rand_crngt_init)
|
||||
{
|
||||
return OPENSSL_init_crypto(0, NULL)
|
||||
&& rand_crngt_init()
|
||||
&& OPENSSL_atexit(&rand_crngt_cleanup);
|
||||
}
|
||||
|
||||
int rand_crngt_single_init(void)
|
||||
{
|
||||
return RUN_ONCE(&rand_crngt_init_flag, do_rand_crngt_init);
|
||||
}
|
||||
|
||||
size_t rand_crngt_get_entropy(RAND_DRBG *drbg,
|
||||
unsigned char **pout,
|
||||
int entropy, size_t min_len, size_t max_len,
|
||||
@@ -86,8 +103,11 @@ size_t rand_crngt_get_entropy(RAND_DRBG *drbg,
|
||||
RAND_POOL *pool;
|
||||
size_t q, r = 0, s, t = 0;
|
||||
int attempts = 3;
|
||||
CRNG_TEST_GLOBAL *crngt_glob
|
||||
= openssl_ctx_get_data(drbg->libctx, OPENSSL_CTX_RAND_CRNGT_INDEX,
|
||||
&rand_crng_ossl_ctx_method);
|
||||
|
||||
if (!RUN_ONCE(&rand_crngt_init_flag, do_rand_crngt_init))
|
||||
if (crngt_glob == NULL)
|
||||
return 0;
|
||||
|
||||
if ((pool = rand_pool_new(entropy, min_len, max_len)) == NULL)
|
||||
@@ -95,11 +115,12 @@ size_t rand_crngt_get_entropy(RAND_DRBG *drbg,
|
||||
|
||||
while ((q = rand_pool_bytes_needed(pool, 1)) > 0 && attempts-- > 0) {
|
||||
s = q > sizeof(buf) ? sizeof(buf) : q;
|
||||
if (!crngt_get_entropy(buf, md, &sz)
|
||||
|| memcmp(crngt_prev, md, sz) == 0
|
||||
if (!crngt_get_entropy(drbg->libctx, crngt_glob->crngt_pool, buf, md,
|
||||
&sz)
|
||||
|| memcmp(crngt_glob->crngt_prev, md, sz) == 0
|
||||
|| !rand_pool_add(pool, buf, s, s * 8))
|
||||
goto err;
|
||||
memcpy(crngt_prev, md, sz);
|
||||
memcpy(crngt_glob->crngt_prev, md, sz);
|
||||
t += s;
|
||||
attempts++;
|
||||
}
|
||||
|
||||
@@ -38,7 +38,7 @@ int RAND_egd_bytes(const char *path, int bytes)
|
||||
|
||||
# else
|
||||
|
||||
# include OPENSSL_UNISTD
|
||||
# include <unistd.h>
|
||||
# include <stddef.h>
|
||||
# include <sys/types.h>
|
||||
# include <sys/socket.h>
|
||||
|
||||
@@ -20,6 +20,7 @@ static const ERR_STRING_DATA RAND_str_functs[] = {
|
||||
{ERR_PACK(ERR_LIB_RAND, RAND_F_DRBG_SETUP, 0), "drbg_setup"},
|
||||
{ERR_PACK(ERR_LIB_RAND, RAND_F_GET_ENTROPY, 0), "get_entropy"},
|
||||
{ERR_PACK(ERR_LIB_RAND, RAND_F_RAND_BYTES, 0), "RAND_bytes"},
|
||||
{ERR_PACK(ERR_LIB_RAND, RAND_F_RAND_BYTES_EX, 0), "rand_bytes_ex"},
|
||||
{ERR_PACK(ERR_LIB_RAND, RAND_F_RAND_DRBG_ENABLE_LOCKING, 0),
|
||||
"rand_drbg_enable_locking"},
|
||||
{ERR_PACK(ERR_LIB_RAND, RAND_F_RAND_DRBG_GENERATE, 0),
|
||||
|
||||
+10
-14
@@ -17,6 +17,7 @@
|
||||
# include <openssl/ec.h>
|
||||
# include <openssl/rand_drbg.h>
|
||||
# include "internal/tsan_assist.h"
|
||||
# include "internal/rand_int.h"
|
||||
|
||||
# include "internal/numbers.h"
|
||||
|
||||
@@ -129,7 +130,7 @@ typedef struct rand_drbg_method_st {
|
||||
#define HASH_PRNG_MAX_SEEDLEN (888/8)
|
||||
|
||||
typedef struct rand_drbg_hash_st {
|
||||
const EVP_MD *md;
|
||||
EVP_MD *md;
|
||||
EVP_MD_CTX *ctx;
|
||||
size_t blocklen;
|
||||
unsigned char V[HASH_PRNG_MAX_SEEDLEN];
|
||||
@@ -139,7 +140,7 @@ typedef struct rand_drbg_hash_st {
|
||||
} RAND_DRBG_HASH;
|
||||
|
||||
typedef struct rand_drbg_hmac_st {
|
||||
const EVP_MD *md;
|
||||
EVP_MD *md;
|
||||
HMAC_CTX *ctx;
|
||||
size_t blocklen;
|
||||
unsigned char K[EVP_MAX_MD_SIZE];
|
||||
@@ -152,7 +153,7 @@ typedef struct rand_drbg_hmac_st {
|
||||
typedef struct rand_drbg_ctr_st {
|
||||
EVP_CIPHER_CTX *ctx;
|
||||
EVP_CIPHER_CTX *ctx_df;
|
||||
const EVP_CIPHER *cipher;
|
||||
EVP_CIPHER *cipher;
|
||||
size_t keylen;
|
||||
unsigned char K[32];
|
||||
unsigned char V[16];
|
||||
@@ -192,6 +193,8 @@ struct rand_pool_st {
|
||||
*/
|
||||
struct rand_drbg_st {
|
||||
CRYPTO_RWLOCK *lock;
|
||||
/* The library context this DRBG is associated with, if any */
|
||||
OPENSSL_CTX *libctx;
|
||||
RAND_DRBG *parent;
|
||||
int secure; /* 1: allocated on the secure heap, 0: otherwise */
|
||||
int type; /* the nid of the underlying algorithm */
|
||||
@@ -334,18 +337,11 @@ int drbg_hmac_init(RAND_DRBG *drbg);
|
||||
* Entropy call back for the FIPS 140-2 section 4.9.2 Conditional Tests.
|
||||
* These need to be exposed for the unit tests.
|
||||
*/
|
||||
int rand_crngt_get_entropy_cb(unsigned char *buf, unsigned char *md,
|
||||
int rand_crngt_get_entropy_cb(OPENSSL_CTX *ctx, RAND_POOL *pool,
|
||||
unsigned char *buf, unsigned char *md,
|
||||
unsigned int *md_size);
|
||||
extern int (*crngt_get_entropy)(unsigned char *buf, unsigned char *md,
|
||||
extern int (*crngt_get_entropy)(OPENSSL_CTX *ctx, RAND_POOL *pool,
|
||||
unsigned char *buf, unsigned char *md,
|
||||
unsigned int *md_size);
|
||||
int rand_crngt_init(void);
|
||||
void rand_crngt_cleanup(void);
|
||||
|
||||
/*
|
||||
* Expose the run once initialisation function for the unit tests because.
|
||||
* they need to restart from scratch to validate the first block is skipped
|
||||
* properly.
|
||||
*/
|
||||
int rand_crngt_single_init(void);
|
||||
|
||||
#endif
|
||||
+68
-98
@@ -17,21 +17,20 @@
|
||||
#include "rand_lcl.h"
|
||||
#include "e_os.h"
|
||||
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
#ifndef FIPS_MODE
|
||||
# ifndef OPENSSL_NO_ENGINE
|
||||
/* non-NULL if default_RAND_meth is ENGINE-provided */
|
||||
static ENGINE *funct_ref;
|
||||
static CRYPTO_RWLOCK *rand_engine_lock;
|
||||
#endif
|
||||
# endif
|
||||
static CRYPTO_RWLOCK *rand_meth_lock;
|
||||
static const RAND_METHOD *default_RAND_meth;
|
||||
static CRYPTO_ONCE rand_init = CRYPTO_ONCE_STATIC_INIT;
|
||||
|
||||
int rand_fork_count;
|
||||
|
||||
static CRYPTO_RWLOCK *rand_nonce_lock;
|
||||
static int rand_nonce_count;
|
||||
|
||||
static int rand_inited = 0;
|
||||
#endif /* FIPS_MODE */
|
||||
|
||||
int rand_fork_count;
|
||||
|
||||
#ifdef OPENSSL_RAND_SEED_RDTSC
|
||||
/*
|
||||
@@ -208,56 +207,6 @@ void rand_drbg_cleanup_entropy(RAND_DRBG *drbg,
|
||||
OPENSSL_secure_clear_free(out, outlen);
|
||||
}
|
||||
|
||||
|
||||
/*
|
||||
* Implements the get_nonce() callback (see RAND_DRBG_set_callbacks())
|
||||
*
|
||||
*/
|
||||
size_t rand_drbg_get_nonce(RAND_DRBG *drbg,
|
||||
unsigned char **pout,
|
||||
int entropy, size_t min_len, size_t max_len)
|
||||
{
|
||||
size_t ret = 0;
|
||||
RAND_POOL *pool;
|
||||
|
||||
struct {
|
||||
void * instance;
|
||||
int count;
|
||||
} data;
|
||||
|
||||
memset(&data, 0, sizeof(data));
|
||||
pool = rand_pool_new(0, min_len, max_len);
|
||||
if (pool == NULL)
|
||||
return 0;
|
||||
|
||||
if (rand_pool_add_nonce_data(pool) == 0)
|
||||
goto err;
|
||||
|
||||
data.instance = drbg;
|
||||
CRYPTO_atomic_add(&rand_nonce_count, 1, &data.count, rand_nonce_lock);
|
||||
|
||||
if (rand_pool_add(pool, (unsigned char *)&data, sizeof(data), 0) == 0)
|
||||
goto err;
|
||||
|
||||
ret = rand_pool_length(pool);
|
||||
*pout = rand_pool_detach(pool);
|
||||
|
||||
err:
|
||||
rand_pool_free(pool);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/*
|
||||
* Implements the cleanup_nonce() callback (see RAND_DRBG_set_callbacks())
|
||||
*
|
||||
*/
|
||||
void rand_drbg_cleanup_nonce(RAND_DRBG *drbg,
|
||||
unsigned char *out, size_t outlen)
|
||||
{
|
||||
OPENSSL_secure_clear_free(out, outlen);
|
||||
}
|
||||
|
||||
/*
|
||||
* Generate additional data that can be used for the drbg. The data does
|
||||
* not need to contain entropy, but it's useful if it contains at least
|
||||
@@ -292,39 +241,32 @@ void rand_fork(void)
|
||||
rand_fork_count++;
|
||||
}
|
||||
|
||||
#ifndef FIPS_MODE
|
||||
DEFINE_RUN_ONCE_STATIC(do_rand_init)
|
||||
{
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
# ifndef OPENSSL_NO_ENGINE
|
||||
rand_engine_lock = CRYPTO_THREAD_lock_new();
|
||||
if (rand_engine_lock == NULL)
|
||||
return 0;
|
||||
#endif
|
||||
# endif
|
||||
|
||||
rand_meth_lock = CRYPTO_THREAD_lock_new();
|
||||
if (rand_meth_lock == NULL)
|
||||
goto err1;
|
||||
|
||||
rand_nonce_lock = CRYPTO_THREAD_lock_new();
|
||||
if (rand_nonce_lock == NULL)
|
||||
goto err2;
|
||||
goto err;
|
||||
|
||||
if (!rand_pool_init())
|
||||
goto err3;
|
||||
goto err;
|
||||
|
||||
rand_inited = 1;
|
||||
return 1;
|
||||
|
||||
err3:
|
||||
CRYPTO_THREAD_lock_free(rand_nonce_lock);
|
||||
rand_nonce_lock = NULL;
|
||||
err2:
|
||||
err:
|
||||
CRYPTO_THREAD_lock_free(rand_meth_lock);
|
||||
rand_meth_lock = NULL;
|
||||
err1:
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
# ifndef OPENSSL_NO_ENGINE
|
||||
CRYPTO_THREAD_lock_free(rand_engine_lock);
|
||||
rand_engine_lock = NULL;
|
||||
#endif
|
||||
# endif
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -339,19 +281,18 @@ void rand_cleanup_int(void)
|
||||
meth->cleanup();
|
||||
RAND_set_rand_method(NULL);
|
||||
rand_pool_cleanup();
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
# ifndef OPENSSL_NO_ENGINE
|
||||
CRYPTO_THREAD_lock_free(rand_engine_lock);
|
||||
rand_engine_lock = NULL;
|
||||
#endif
|
||||
# endif
|
||||
CRYPTO_THREAD_lock_free(rand_meth_lock);
|
||||
rand_meth_lock = NULL;
|
||||
CRYPTO_THREAD_lock_free(rand_nonce_lock);
|
||||
rand_nonce_lock = NULL;
|
||||
rand_inited = 0;
|
||||
}
|
||||
|
||||
/* TODO(3.0): Do we need to handle this somehow in the FIPS module? */
|
||||
/*
|
||||
* RAND_close_seed_files() ensures that any seed file decriptors are
|
||||
* RAND_close_seed_files() ensures that any seed file descriptors are
|
||||
* closed after use.
|
||||
*/
|
||||
void RAND_keep_random_devices_open(int keep)
|
||||
@@ -371,8 +312,6 @@ int RAND_poll(void)
|
||||
{
|
||||
int ret = 0;
|
||||
|
||||
RAND_POOL *pool = NULL;
|
||||
|
||||
const RAND_METHOD *meth = RAND_get_rand_method();
|
||||
|
||||
if (meth == RAND_OpenSSL()) {
|
||||
@@ -389,6 +328,8 @@ int RAND_poll(void)
|
||||
return ret;
|
||||
|
||||
} else {
|
||||
RAND_POOL *pool = NULL;
|
||||
|
||||
/* fill random pool and seed the current legacy RNG */
|
||||
pool = rand_pool_new(RAND_DRBG_STRENGTH,
|
||||
(RAND_DRBG_STRENGTH + 7) / 8,
|
||||
@@ -406,12 +347,14 @@ int RAND_poll(void)
|
||||
goto err;
|
||||
|
||||
ret = 1;
|
||||
|
||||
err:
|
||||
rand_pool_free(pool);
|
||||
}
|
||||
|
||||
err:
|
||||
rand_pool_free(pool);
|
||||
return ret;
|
||||
}
|
||||
#endif /* FIPS_MODE */
|
||||
|
||||
/*
|
||||
* Allocate memory and initialize a new random pool
|
||||
@@ -708,23 +651,28 @@ int rand_pool_add_end(RAND_POOL *pool, size_t len, size_t entropy)
|
||||
return 1;
|
||||
}
|
||||
|
||||
#ifndef FIPS_MODE
|
||||
int RAND_set_rand_method(const RAND_METHOD *meth)
|
||||
{
|
||||
if (!RUN_ONCE(&rand_init, do_rand_init))
|
||||
return 0;
|
||||
|
||||
CRYPTO_THREAD_write_lock(rand_meth_lock);
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
# ifndef OPENSSL_NO_ENGINE
|
||||
ENGINE_finish(funct_ref);
|
||||
funct_ref = NULL;
|
||||
#endif
|
||||
# endif
|
||||
default_RAND_meth = meth;
|
||||
CRYPTO_THREAD_unlock(rand_meth_lock);
|
||||
return 1;
|
||||
}
|
||||
#endif
|
||||
|
||||
const RAND_METHOD *RAND_get_rand_method(void)
|
||||
{
|
||||
#ifdef FIPS_MODE
|
||||
return NULL;
|
||||
#else
|
||||
const RAND_METHOD *tmp_meth = NULL;
|
||||
|
||||
if (!RUN_ONCE(&rand_init, do_rand_init))
|
||||
@@ -732,7 +680,7 @@ const RAND_METHOD *RAND_get_rand_method(void)
|
||||
|
||||
CRYPTO_THREAD_write_lock(rand_meth_lock);
|
||||
if (default_RAND_meth == NULL) {
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
# ifndef OPENSSL_NO_ENGINE
|
||||
ENGINE *e;
|
||||
|
||||
/* If we have an engine that can do RAND, use it. */
|
||||
@@ -744,16 +692,17 @@ const RAND_METHOD *RAND_get_rand_method(void)
|
||||
ENGINE_finish(e);
|
||||
default_RAND_meth = &rand_meth;
|
||||
}
|
||||
#else
|
||||
# else
|
||||
default_RAND_meth = &rand_meth;
|
||||
#endif
|
||||
# endif
|
||||
}
|
||||
tmp_meth = default_RAND_meth;
|
||||
CRYPTO_THREAD_unlock(rand_meth_lock);
|
||||
return tmp_meth;
|
||||
#endif
|
||||
}
|
||||
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
#if !defined(OPENSSL_NO_ENGINE) && !defined(FIPS_MODE)
|
||||
int RAND_set_rand_engine(ENGINE *engine)
|
||||
{
|
||||
const RAND_METHOD *tmp_meth = NULL;
|
||||
@@ -800,16 +749,42 @@ void RAND_add(const void *buf, int num, double randomness)
|
||||
* the default method, then just call RAND_bytes(). Otherwise make
|
||||
* sure we're instantiated and use the private DRBG.
|
||||
*/
|
||||
int RAND_priv_bytes(unsigned char *buf, int num)
|
||||
int rand_priv_bytes_ex(OPENSSL_CTX *ctx, unsigned char *buf, int num)
|
||||
{
|
||||
const RAND_METHOD *meth = RAND_get_rand_method();
|
||||
RAND_DRBG *drbg;
|
||||
int ret;
|
||||
const RAND_METHOD *meth = RAND_get_rand_method();
|
||||
|
||||
if (meth != RAND_OpenSSL())
|
||||
return RAND_bytes(buf, num);
|
||||
return meth->bytes(buf, num);
|
||||
|
||||
drbg = RAND_DRBG_get0_private();
|
||||
drbg = OPENSSL_CTX_get0_private_drbg(ctx);
|
||||
if (drbg == NULL)
|
||||
return 0;
|
||||
|
||||
ret = RAND_DRBG_bytes(drbg, buf, num);
|
||||
return ret;
|
||||
}
|
||||
|
||||
int RAND_priv_bytes(unsigned char *buf, int num)
|
||||
{
|
||||
return rand_priv_bytes_ex(NULL, buf, num);
|
||||
}
|
||||
|
||||
int rand_bytes_ex(OPENSSL_CTX *ctx, unsigned char *buf, int num)
|
||||
{
|
||||
RAND_DRBG *drbg;
|
||||
int ret;
|
||||
const RAND_METHOD *meth = RAND_get_rand_method();
|
||||
|
||||
if (meth != RAND_OpenSSL()) {
|
||||
if (meth->bytes != NULL)
|
||||
return meth->bytes(buf, num);
|
||||
RANDerr(RAND_F_RAND_BYTES_EX, RAND_R_FUNC_NOT_IMPLEMENTED);
|
||||
return -1;
|
||||
}
|
||||
|
||||
drbg = OPENSSL_CTX_get0_public_drbg(ctx);
|
||||
if (drbg == NULL)
|
||||
return 0;
|
||||
|
||||
@@ -819,15 +794,10 @@ int RAND_priv_bytes(unsigned char *buf, int num)
|
||||
|
||||
int RAND_bytes(unsigned char *buf, int num)
|
||||
{
|
||||
const RAND_METHOD *meth = RAND_get_rand_method();
|
||||
|
||||
if (meth->bytes != NULL)
|
||||
return meth->bytes(buf, num);
|
||||
RANDerr(RAND_F_RAND_BYTES, RAND_R_FUNC_NOT_IMPLEMENTED);
|
||||
return -1;
|
||||
return rand_bytes_ex(NULL, buf, num);
|
||||
}
|
||||
|
||||
#if !OPENSSL_API_1_1_0
|
||||
#if !OPENSSL_API_1_1_0 && !defined(FIPS_MODE)
|
||||
int RAND_pseudo_bytes(unsigned char *buf, int num)
|
||||
{
|
||||
const RAND_METHOD *meth = RAND_get_rand_method();
|
||||
|
||||
+2
-25
@@ -21,7 +21,7 @@
|
||||
#if defined(__linux)
|
||||
# include <asm/unistd.h>
|
||||
#endif
|
||||
#if defined(__FreeBSD__)
|
||||
#if defined(__FreeBSD__) && !defined(OPENSSL_SYS_UEFI)
|
||||
# include <sys/types.h>
|
||||
# include <sys/sysctl.h>
|
||||
# include <sys/param.h>
|
||||
@@ -285,7 +285,7 @@ static ssize_t syscall_random(void *buf, size_t buflen)
|
||||
|
||||
if (getentropy != NULL)
|
||||
return getentropy(buf, buflen) == 0 ? (ssize_t)buflen : -1;
|
||||
# else
|
||||
# elif !defined(FIPS_MODE)
|
||||
union {
|
||||
void *p;
|
||||
int (*f)(void *buffer, size_t length);
|
||||
@@ -489,29 +489,6 @@ size_t rand_pool_acquire_entropy(RAND_POOL *pool)
|
||||
bytes_needed = rand_pool_bytes_needed(pool, 1 /*entropy_factor*/);
|
||||
{
|
||||
size_t i;
|
||||
#ifdef DEVRANDOM_WAIT
|
||||
static int wait_done = 0;
|
||||
|
||||
/*
|
||||
* On some implementations reading from /dev/urandom is possible
|
||||
* before it is initialized. Therefore we wait for /dev/random
|
||||
* to be readable to make sure /dev/urandom is initialized.
|
||||
*/
|
||||
if (!wait_done && bytes_needed > 0) {
|
||||
int f = open(DEVRANDOM_WAIT, O_RDONLY);
|
||||
|
||||
if (f >= 0) {
|
||||
fd_set fds;
|
||||
|
||||
FD_ZERO(&fds);
|
||||
FD_SET(f, &fds);
|
||||
while (select(f+1, &fds, NULL, NULL, NULL) < 0
|
||||
&& errno == EINTR);
|
||||
close(f);
|
||||
}
|
||||
wait_done = 1;
|
||||
}
|
||||
#endif
|
||||
|
||||
for (i = 0; bytes_needed > 0 && i < OSSL_NELEM(random_device_paths); i++) {
|
||||
ssize_t bytes = 0;
|
||||
|
||||
@@ -162,7 +162,7 @@ int rand_pool_add_additional_data(RAND_POOL *pool)
|
||||
return rand_pool_add(pool, (unsigned char *)&data, sizeof(data), 0);
|
||||
}
|
||||
|
||||
# if !OPENSSL_API_1_1_0
|
||||
# if !OPENSSL_API_1_1_0 && !defined(FIPS_MODE)
|
||||
int RAND_event(UINT iMsg, WPARAM wParam, LPARAM lParam)
|
||||
{
|
||||
RAND_poll();
|
||||
|
||||
Reference in New Issue
Block a user