Latest update.

This commit is contained in:
2020-02-17 23:45:59 +09:00
parent 9dfeec3942
commit f85de4da03
381 changed files with 7278 additions and 1826 deletions
+26
View File
@@ -21,6 +21,32 @@
options of the apps. options of the apps.
[Kurt Roeckx] [Kurt Roeckx]
*) The command line utilities dhparam, dsa, gendsa and dsaparam have been
deprecated. Instead use the pkeyparam, pkey, genpkey and pkeyparam
programs respectively.
[Paul Dale]
*) All of the low level DSA functions have been deprecated including:
DSA_do_sign, DSA_do_verify, DSA_OpenSSL, DSA_set_default_method,
DSA_get_default_method, DSA_set_method, DSA_get_method, DSA_new_method,
DSA_sign_setup, DSA_sign, DSA_verify, DSA_get_ex_new_index,
DSA_set_ex_data, DSA_get_ex_data, DSA_generate_parameters_ex,
DSA_generate_key, DSA_meth_new, DSA_get0_engine, DSA_meth_free,
DSA_meth_dup, DSA_meth_get0_name, DSA_meth_set1_name, DSA_meth_get_flags,
DSA_meth_set_flags, DSA_meth_get0_app_data, DSA_meth_set0_app_data,
DSA_meth_get_sign, DSA_meth_set_sign, DSA_meth_get_sign_setup,
DSA_meth_set_sign_setup, DSA_meth_get_verify, DSA_meth_set_verify,
DSA_meth_get_mod_exp, DSA_meth_set_mod_exp, DSA_meth_get_bn_mod_exp,
DSA_meth_set_bn_mod_exp, DSA_meth_get_init, DSA_meth_set_init,
DSA_meth_get_finish, DSA_meth_set_finish, DSA_meth_get_paramgen,
DSA_meth_set_paramgen, DSA_meth_get_keygen and DSA_meth_set_keygen.
Use of these low level functions has been informally discouraged for a long
time. Instead applications should use L<EVP_DigestSignInit_ex(3)>,
L<EVP_DigestSignUpdate(3)> and L<EVP_DigestSignFinal(3)>.
[Paul Dale]
*) Reworked the treatment of EC EVP_PKEYs with the SM2 curve to *) Reworked the treatment of EC EVP_PKEYs with the SM2 curve to
automatically become EVP_PKEY_SM2 rather than EVP_PKEY_EC. automatically become EVP_PKEY_SM2 rather than EVP_PKEY_EC.
This means that applications don't have to look at the curve NID and This means that applications don't have to look at the curve NID and
+10
View File
@@ -1483,6 +1483,16 @@ my %targets = (
lib_cppflags => "-DL_ENDIAN", lib_cppflags => "-DL_ENDIAN",
sys_id => "UEFI", sys_id => "UEFI",
}, },
"UEFI-x86" => {
inherit_from => [ "UEFI" ],
asm_arch => 'x86',
perlasm_scheme => "win32n",
},
"UEFI-x86_64" => {
inherit_from => [ "UEFI" ],
asm_arch => 'x86_64',
perlasm_scheme => "nasm",
},
#### UWIN #### UWIN
"UWIN" => { "UWIN" => {
+1
View File
@@ -412,6 +412,7 @@ my @disablables = (
"rmd160", "rmd160",
"scrypt", "scrypt",
"sctp", "sctp",
"secure-memory",
"seed", "seed",
"shared", "shared",
"siphash", "siphash",
+3
View File
@@ -7,6 +7,9 @@
Major changes between OpenSSL 1.1.1 and OpenSSL 3.0.0 [under development] Major changes between OpenSSL 1.1.1 and OpenSSL 3.0.0 [under development]
o The algorithm specific public key command line applications have
been deprecated. These include dhparam, gendsa and others. The pkey
alternatives should be used intead: pkey, pkeyparam and genpkey.
o X509 certificates signed using SHA1 are no longer allowed at security o X509 certificates signed using SHA1 are no longer allowed at security
level 1 or higher. The default security level for TLS is 1, so level 1 or higher. The default security level for TLS is 1, so
certificates signed using SHA1 are by default no longer trusted to certificates signed using SHA1 are by default no longer trusted to
+6 -2
View File
@@ -12,8 +12,8 @@ ENDIF
# Source for the 'openssl' program # Source for the 'openssl' program
$OPENSSLSRC=\ $OPENSSLSRC=\
openssl.c progs.c \ openssl.c progs.c \
asn1pars.c ca.c ciphers.c cms.c crl.c crl2p7.c dgst.c dhparam.c \ asn1pars.c ca.c ciphers.c cms.c crl.c crl2p7.c dgst.c \
dsa.c dsaparam.c ec.c ecparam.c enc.c engine.c errstr.c gendsa.c \ ec.c ecparam.c enc.c engine.c errstr.c \
genpkey.c genrsa.c kdf.c mac.c nseq.c ocsp.c passwd.c pkcs12.c pkcs7.c \ genpkey.c genrsa.c kdf.c mac.c nseq.c ocsp.c passwd.c pkcs12.c pkcs7.c \
pkcs8.c pkey.c pkeyparam.c pkeyutl.c prime.c rand.c req.c rsa.c \ pkcs8.c pkey.c pkeyparam.c pkeyutl.c prime.c rand.c req.c rsa.c \
rsautl.c s_client.c s_server.c s_time.c sess_id.c smime.c speed.c \ rsautl.c s_client.c s_server.c s_time.c sess_id.c smime.c speed.c \
@@ -31,6 +31,10 @@ IF[{- !$disabled{apps} -}]
SOURCE[openssl]=openssl.rc SOURCE[openssl]=openssl.rc
ENDIF ENDIF
IF[{- !$disabled{'deprecated-3.0'} -}]
SOURCE[openssl]=dhparam.c dsa.c dsaparam.c gendsa.c
ENDIF
SCRIPTS{misc}=CA.pl SCRIPTS{misc}=CA.pl
SOURCE[CA.pl]=CA.pl.in SOURCE[CA.pl]=CA.pl.in
# linkname tells build files that a symbolic link or copy of this script # linkname tells build files that a symbolic link or copy of this script
+3
View File
@@ -7,6 +7,9 @@
* https://www.openssl.org/source/license.html * https://www.openssl.org/source/license.html
*/ */
/* We need to use some deprecated APIs */
#define OPENSSL_SUPPRESS_DEPRECATED
#include <openssl/opensslconf.h> #include <openssl/opensslconf.h>
#ifdef OPENSSL_NO_DH #ifdef OPENSSL_NO_DH
NON_EMPTY_TRANSLATION_UNIT NON_EMPTY_TRANSLATION_UNIT
+4
View File
@@ -7,6 +7,9 @@
* https://www.openssl.org/source/license.html * https://www.openssl.org/source/license.html
*/ */
/* We need to use the deprecated DSA_print */
#define OPENSSL_SUPPRESS_DEPRECATED
#include <openssl/opensslconf.h> #include <openssl/opensslconf.h>
#ifdef OPENSSL_NO_DSA #ifdef OPENSSL_NO_DSA
NON_EMPTY_TRANSLATION_UNIT NON_EMPTY_TRANSLATION_UNIT
@@ -173,6 +176,7 @@ int dsa_main(int argc, char **argv)
EVP_PKEY_free(pkey); EVP_PKEY_free(pkey);
} }
} }
if (dsa == NULL) { if (dsa == NULL) {
BIO_printf(bio_err, "unable to load Key\n"); BIO_printf(bio_err, "unable to load Key\n");
ERR_print_errors(bio_err); ERR_print_errors(bio_err);
+3
View File
@@ -7,6 +7,9 @@
* https://www.openssl.org/source/license.html * https://www.openssl.org/source/license.html
*/ */
/* We need to use some deprecated APIs */
#define OPENSSL_SUPPRESS_DEPRECATED
#include <openssl/opensslconf.h> #include <openssl/opensslconf.h>
#ifdef OPENSSL_NO_DSA #ifdef OPENSSL_NO_DSA
NON_EMPTY_TRANSLATION_UNIT NON_EMPTY_TRANSLATION_UNIT
+3
View File
@@ -7,6 +7,9 @@
* https://www.openssl.org/source/license.html * https://www.openssl.org/source/license.html
*/ */
/* We need to use some deprecated APIs */
#define OPENSSL_SUPPRESS_DEPRECATED
#include <openssl/opensslconf.h> #include <openssl/opensslconf.h>
#ifdef OPENSSL_NO_DSA #ifdef OPENSSL_NO_DSA
NON_EMPTY_TRANSLATION_UNIT NON_EMPTY_TRANSLATION_UNIT
+3
View File
@@ -13,6 +13,8 @@
# include <openssl/lhash.h> # include <openssl/lhash.h>
# include "opt.h" # include "opt.h"
#define DEPRECATED_NO_ALTERNATIVE "unknown"
typedef enum FUNC_TYPE { typedef enum FUNC_TYPE {
FT_none, FT_general, FT_md, FT_cipher, FT_pkey, FT_none, FT_general, FT_md, FT_cipher, FT_pkey,
FT_md_alg, FT_cipher_alg FT_md_alg, FT_cipher_alg
@@ -23,6 +25,7 @@ typedef struct function_st {
const char *name; const char *name;
int (*func)(int argc, char *argv[]); int (*func)(int argc, char *argv[]);
const OPTIONS *help; const OPTIONS *help;
const char *deprecated_alternative;
} FUNCTION; } FUNCTION;
DEFINE_LHASH_OF(FUNCTION); DEFINE_LHASH_OF(FUNCTION);
+1
View File
@@ -190,6 +190,7 @@ static STRINT_PAIR cert_type_list[] = {
{"RSA fixed ECDH", TLS_CT_RSA_FIXED_ECDH}, {"RSA fixed ECDH", TLS_CT_RSA_FIXED_ECDH},
{"ECDSA fixed ECDH", TLS_CT_ECDSA_FIXED_ECDH}, {"ECDSA fixed ECDH", TLS_CT_ECDSA_FIXED_ECDH},
{"GOST01 Sign", TLS_CT_GOST01_SIGN}, {"GOST01 Sign", TLS_CT_GOST01_SIGN},
{"GOST12 Sign", TLS_CT_GOST12_SIGN},
{NULL} {NULL}
}; };
+13
View File
@@ -47,6 +47,15 @@ BIO *bio_in = NULL;
BIO *bio_out = NULL; BIO *bio_out = NULL;
BIO *bio_err = NULL; BIO *bio_err = NULL;
static void warn_deprecated(const char *pname,
const char *deprecated_alternative)
{
BIO_printf(bio_err, "The command %s is deprecated.", pname);
if (strcmp(deprecated_alternative, DEPRECATED_NO_ALTERNATIVE) != 0)
BIO_printf(bio_err, " Use '%s' instead.", deprecated_alternative);
BIO_printf(bio_err, "\n");
}
static int apps_startup(void) static int apps_startup(void)
{ {
#ifdef SIGPIPE #ifdef SIGPIPE
@@ -277,6 +286,8 @@ int main(int argc, char *argv[])
fp = lh_FUNCTION_retrieve(prog, &f); fp = lh_FUNCTION_retrieve(prog, &f);
if (fp != NULL) { if (fp != NULL) {
argv[0] = pname; argv[0] = pname;
if (fp->deprecated_alternative != NULL)
warn_deprecated(pname, fp->deprecated_alternative);
ret = fp->func(argc, argv); ret = fp->func(argc, argv);
goto end; goto end;
} }
@@ -470,6 +481,8 @@ static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
} }
} }
if (fp != NULL) { if (fp != NULL) {
if (fp->deprecated_alternative != NULL)
warn_deprecated(fp->name, fp->deprecated_alternative);
return fp->func(argc, argv); return fp->func(argc, argv);
} }
if ((strncmp(argv[0], "no-", 3)) == 0) { if ((strncmp(argv[0], "no-", 3)) == 0) {
+3 -2
View File
@@ -556,8 +556,9 @@ static EVP_PKEY_CTX *init_ctx(const char *kdfalg, int *pkeysize,
|| (group = EC_KEY_get0_group(eckey)) == NULL || (group = EC_KEY_get0_group(eckey)) == NULL
|| (nid = EC_GROUP_get_curve_name(group)) == 0) || (nid = EC_GROUP_get_curve_name(group)) == 0)
goto end; goto end;
if (nid == NID_sm2) if (nid == NID_sm2
EVP_PKEY_set_alias_type(pkey, EVP_PKEY_SM2); && !EVP_PKEY_set_alias_type(pkey, EVP_PKEY_SM2))
goto end;
} }
#endif #endif
*pkeysize = EVP_PKEY_size(pkey); *pkeysize = EVP_PKEY_size(pkey);
+170 -170
View File
@@ -13,388 +13,388 @@
#include "progs.h" #include "progs.h"
FUNCTION functions[] = { FUNCTION functions[] = {
{FT_general, "asn1parse", asn1parse_main, asn1parse_options}, {FT_general, "asn1parse", asn1parse_main, asn1parse_options, NULL},
{FT_general, "ca", ca_main, ca_options}, {FT_general, "ca", ca_main, ca_options, NULL},
#ifndef OPENSSL_NO_SOCK #ifndef OPENSSL_NO_SOCK
{FT_general, "ciphers", ciphers_main, ciphers_options}, {FT_general, "ciphers", ciphers_main, ciphers_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CMS #ifndef OPENSSL_NO_CMS
{FT_general, "cms", cms_main, cms_options}, {FT_general, "cms", cms_main, cms_options, NULL},
#endif #endif
{FT_general, "crl", crl_main, crl_options}, {FT_general, "crl", crl_main, crl_options, NULL},
{FT_general, "crl2pkcs7", crl2pkcs7_main, crl2pkcs7_options}, {FT_general, "crl2pkcs7", crl2pkcs7_main, crl2pkcs7_options, NULL},
{FT_general, "dgst", dgst_main, dgst_options}, {FT_general, "dgst", dgst_main, dgst_options, NULL},
#ifndef OPENSSL_NO_DH #if !defined(OPENSSL_NO_DH) && !defined(OPENSSL_NO_DEPRECATED_3_0)
{FT_general, "dhparam", dhparam_main, dhparam_options}, {FT_general, "dhparam", dhparam_main, dhparam_options, "pkeyparam"},
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
{FT_general, "dsa", dsa_main, dsa_options}, {FT_general, "dsa", dsa_main, dsa_options, "pkey"},
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
{FT_general, "dsaparam", dsaparam_main, dsaparam_options}, {FT_general, "dsaparam", dsaparam_main, dsaparam_options, "pkeyparam"},
#endif #endif
#ifndef OPENSSL_NO_EC #ifndef OPENSSL_NO_EC
{FT_general, "ec", ec_main, ec_options}, {FT_general, "ec", ec_main, ec_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_EC #ifndef OPENSSL_NO_EC
{FT_general, "ecparam", ecparam_main, ecparam_options}, {FT_general, "ecparam", ecparam_main, ecparam_options, NULL},
#endif #endif
{FT_general, "enc", enc_main, enc_options}, {FT_general, "enc", enc_main, enc_options, NULL},
#ifndef OPENSSL_NO_ENGINE #ifndef OPENSSL_NO_ENGINE
{FT_general, "engine", engine_main, engine_options}, {FT_general, "engine", engine_main, engine_options, NULL},
#endif #endif
{FT_general, "errstr", errstr_main, errstr_options}, {FT_general, "errstr", errstr_main, errstr_options, NULL},
{FT_general, "fipsinstall", fipsinstall_main, fipsinstall_options}, {FT_general, "fipsinstall", fipsinstall_main, fipsinstall_options, NULL},
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
{FT_general, "gendsa", gendsa_main, gendsa_options}, {FT_general, "gendsa", gendsa_main, gendsa_options, "genpkey"},
#endif #endif
{FT_general, "genpkey", genpkey_main, genpkey_options}, {FT_general, "genpkey", genpkey_main, genpkey_options, NULL},
#ifndef OPENSSL_NO_RSA #ifndef OPENSSL_NO_RSA
{FT_general, "genrsa", genrsa_main, genrsa_options}, {FT_general, "genrsa", genrsa_main, genrsa_options, NULL},
#endif #endif
{FT_general, "help", help_main, help_options}, {FT_general, "help", help_main, help_options, NULL},
{FT_general, "info", info_main, info_options}, {FT_general, "info", info_main, info_options, NULL},
{FT_general, "kdf", kdf_main, kdf_options}, {FT_general, "kdf", kdf_main, kdf_options, NULL},
{FT_general, "list", list_main, list_options}, {FT_general, "list", list_main, list_options, NULL},
{FT_general, "mac", mac_main, mac_options}, {FT_general, "mac", mac_main, mac_options, NULL},
{FT_general, "nseq", nseq_main, nseq_options}, {FT_general, "nseq", nseq_main, nseq_options, NULL},
#ifndef OPENSSL_NO_OCSP #ifndef OPENSSL_NO_OCSP
{FT_general, "ocsp", ocsp_main, ocsp_options}, {FT_general, "ocsp", ocsp_main, ocsp_options, NULL},
#endif #endif
{FT_general, "passwd", passwd_main, passwd_options}, {FT_general, "passwd", passwd_main, passwd_options, NULL},
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_general, "pkcs12", pkcs12_main, pkcs12_options}, {FT_general, "pkcs12", pkcs12_main, pkcs12_options, NULL},
#endif #endif
{FT_general, "pkcs7", pkcs7_main, pkcs7_options}, {FT_general, "pkcs7", pkcs7_main, pkcs7_options, NULL},
{FT_general, "pkcs8", pkcs8_main, pkcs8_options}, {FT_general, "pkcs8", pkcs8_main, pkcs8_options, NULL},
{FT_general, "pkey", pkey_main, pkey_options}, {FT_general, "pkey", pkey_main, pkey_options, NULL},
{FT_general, "pkeyparam", pkeyparam_main, pkeyparam_options}, {FT_general, "pkeyparam", pkeyparam_main, pkeyparam_options, NULL},
{FT_general, "pkeyutl", pkeyutl_main, pkeyutl_options}, {FT_general, "pkeyutl", pkeyutl_main, pkeyutl_options, NULL},
{FT_general, "prime", prime_main, prime_options}, {FT_general, "prime", prime_main, prime_options, NULL},
{FT_general, "provider", provider_main, provider_options}, {FT_general, "provider", provider_main, provider_options, NULL},
{FT_general, "rand", rand_main, rand_options}, {FT_general, "rand", rand_main, rand_options, NULL},
{FT_general, "rehash", rehash_main, rehash_options}, {FT_general, "rehash", rehash_main, rehash_options, NULL},
{FT_general, "req", req_main, req_options}, {FT_general, "req", req_main, req_options, NULL},
{FT_general, "rsa", rsa_main, rsa_options}, {FT_general, "rsa", rsa_main, rsa_options, NULL},
#ifndef OPENSSL_NO_RSA #ifndef OPENSSL_NO_RSA
{FT_general, "rsautl", rsautl_main, rsautl_options}, {FT_general, "rsautl", rsautl_main, rsautl_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SOCK #ifndef OPENSSL_NO_SOCK
{FT_general, "s_client", s_client_main, s_client_options}, {FT_general, "s_client", s_client_main, s_client_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SOCK #ifndef OPENSSL_NO_SOCK
{FT_general, "s_server", s_server_main, s_server_options}, {FT_general, "s_server", s_server_main, s_server_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SOCK #ifndef OPENSSL_NO_SOCK
{FT_general, "s_time", s_time_main, s_time_options}, {FT_general, "s_time", s_time_main, s_time_options, NULL},
#endif #endif
{FT_general, "sess_id", sess_id_main, sess_id_options}, {FT_general, "sess_id", sess_id_main, sess_id_options, NULL},
{FT_general, "smime", smime_main, smime_options}, {FT_general, "smime", smime_main, smime_options, NULL},
{FT_general, "speed", speed_main, speed_options}, {FT_general, "speed", speed_main, speed_options, NULL},
{FT_general, "spkac", spkac_main, spkac_options}, {FT_general, "spkac", spkac_main, spkac_options, NULL},
#ifndef OPENSSL_NO_SRP #ifndef OPENSSL_NO_SRP
{FT_general, "srp", srp_main, srp_options}, {FT_general, "srp", srp_main, srp_options, NULL},
#endif #endif
{FT_general, "storeutl", storeutl_main, storeutl_options}, {FT_general, "storeutl", storeutl_main, storeutl_options, NULL},
#ifndef OPENSSL_NO_TS #ifndef OPENSSL_NO_TS
{FT_general, "ts", ts_main, ts_options}, {FT_general, "ts", ts_main, ts_options, NULL},
#endif #endif
{FT_general, "verify", verify_main, verify_options}, {FT_general, "verify", verify_main, verify_options, NULL},
{FT_general, "version", version_main, version_options}, {FT_general, "version", version_main, version_options, NULL},
{FT_general, "x509", x509_main, x509_options}, {FT_general, "x509", x509_main, x509_options, NULL},
#ifndef OPENSSL_NO_MD2 #ifndef OPENSSL_NO_MD2
{FT_md, "md2", dgst_main}, {FT_md, "md2", dgst_main, NULL, NULL},
#endif #endif
#ifndef OPENSSL_NO_MD4 #ifndef OPENSSL_NO_MD4
{FT_md, "md4", dgst_main}, {FT_md, "md4", dgst_main, NULL, NULL},
#endif #endif
{FT_md, "md5", dgst_main}, {FT_md, "md5", dgst_main, NULL, NULL},
#ifndef OPENSSL_NO_GOST #ifndef OPENSSL_NO_GOST
{FT_md, "gost", dgst_main}, {FT_md, "gost", dgst_main, NULL, NULL},
#endif #endif
{FT_md, "sha1", dgst_main}, {FT_md, "sha1", dgst_main, NULL, NULL},
{FT_md, "sha224", dgst_main}, {FT_md, "sha224", dgst_main, NULL, NULL},
{FT_md, "sha256", dgst_main}, {FT_md, "sha256", dgst_main, NULL, NULL},
{FT_md, "sha384", dgst_main}, {FT_md, "sha384", dgst_main, NULL, NULL},
{FT_md, "sha512", dgst_main}, {FT_md, "sha512", dgst_main, NULL, NULL},
{FT_md, "sha512-224", dgst_main}, {FT_md, "sha512-224", dgst_main, NULL, NULL},
{FT_md, "sha512-256", dgst_main}, {FT_md, "sha512-256", dgst_main, NULL, NULL},
{FT_md, "sha3-224", dgst_main}, {FT_md, "sha3-224", dgst_main, NULL, NULL},
{FT_md, "sha3-256", dgst_main}, {FT_md, "sha3-256", dgst_main, NULL, NULL},
{FT_md, "sha3-384", dgst_main}, {FT_md, "sha3-384", dgst_main, NULL, NULL},
{FT_md, "sha3-512", dgst_main}, {FT_md, "sha3-512", dgst_main, NULL, NULL},
{FT_md, "shake128", dgst_main}, {FT_md, "shake128", dgst_main, NULL, NULL},
{FT_md, "shake256", dgst_main}, {FT_md, "shake256", dgst_main, NULL, NULL},
#ifndef OPENSSL_NO_MDC2 #ifndef OPENSSL_NO_MDC2
{FT_md, "mdc2", dgst_main}, {FT_md, "mdc2", dgst_main, NULL, NULL},
#endif #endif
#ifndef OPENSSL_NO_RMD160 #ifndef OPENSSL_NO_RMD160
{FT_md, "rmd160", dgst_main}, {FT_md, "rmd160", dgst_main, NULL, NULL},
#endif #endif
#ifndef OPENSSL_NO_BLAKE2 #ifndef OPENSSL_NO_BLAKE2
{FT_md, "blake2b512", dgst_main}, {FT_md, "blake2b512", dgst_main, NULL, NULL},
#endif #endif
#ifndef OPENSSL_NO_BLAKE2 #ifndef OPENSSL_NO_BLAKE2
{FT_md, "blake2s256", dgst_main}, {FT_md, "blake2s256", dgst_main, NULL, NULL},
#endif #endif
#ifndef OPENSSL_NO_SM3 #ifndef OPENSSL_NO_SM3
{FT_md, "sm3", dgst_main}, {FT_md, "sm3", dgst_main, NULL, NULL},
#endif #endif
{FT_cipher, "aes-128-cbc", enc_main, enc_options}, {FT_cipher, "aes-128-cbc", enc_main, enc_options, NULL},
{FT_cipher, "aes-128-ecb", enc_main, enc_options}, {FT_cipher, "aes-128-ecb", enc_main, enc_options, NULL},
{FT_cipher, "aes-192-cbc", enc_main, enc_options}, {FT_cipher, "aes-192-cbc", enc_main, enc_options, NULL},
{FT_cipher, "aes-192-ecb", enc_main, enc_options}, {FT_cipher, "aes-192-ecb", enc_main, enc_options, NULL},
{FT_cipher, "aes-256-cbc", enc_main, enc_options}, {FT_cipher, "aes-256-cbc", enc_main, enc_options, NULL},
{FT_cipher, "aes-256-ecb", enc_main, enc_options}, {FT_cipher, "aes-256-ecb", enc_main, enc_options, NULL},
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-128-cbc", enc_main, enc_options}, {FT_cipher, "aria-128-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-128-cfb", enc_main, enc_options}, {FT_cipher, "aria-128-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-128-ctr", enc_main, enc_options}, {FT_cipher, "aria-128-ctr", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-128-ecb", enc_main, enc_options}, {FT_cipher, "aria-128-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-128-ofb", enc_main, enc_options}, {FT_cipher, "aria-128-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-128-cfb1", enc_main, enc_options}, {FT_cipher, "aria-128-cfb1", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-128-cfb8", enc_main, enc_options}, {FT_cipher, "aria-128-cfb8", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-192-cbc", enc_main, enc_options}, {FT_cipher, "aria-192-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-192-cfb", enc_main, enc_options}, {FT_cipher, "aria-192-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-192-ctr", enc_main, enc_options}, {FT_cipher, "aria-192-ctr", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-192-ecb", enc_main, enc_options}, {FT_cipher, "aria-192-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-192-ofb", enc_main, enc_options}, {FT_cipher, "aria-192-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-192-cfb1", enc_main, enc_options}, {FT_cipher, "aria-192-cfb1", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-192-cfb8", enc_main, enc_options}, {FT_cipher, "aria-192-cfb8", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-256-cbc", enc_main, enc_options}, {FT_cipher, "aria-256-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-256-cfb", enc_main, enc_options}, {FT_cipher, "aria-256-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-256-ctr", enc_main, enc_options}, {FT_cipher, "aria-256-ctr", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-256-ecb", enc_main, enc_options}, {FT_cipher, "aria-256-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-256-ofb", enc_main, enc_options}, {FT_cipher, "aria-256-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-256-cfb1", enc_main, enc_options}, {FT_cipher, "aria-256-cfb1", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_ARIA #ifndef OPENSSL_NO_ARIA
{FT_cipher, "aria-256-cfb8", enc_main, enc_options}, {FT_cipher, "aria-256-cfb8", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAMELLIA #ifndef OPENSSL_NO_CAMELLIA
{FT_cipher, "camellia-128-cbc", enc_main, enc_options}, {FT_cipher, "camellia-128-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAMELLIA #ifndef OPENSSL_NO_CAMELLIA
{FT_cipher, "camellia-128-ecb", enc_main, enc_options}, {FT_cipher, "camellia-128-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAMELLIA #ifndef OPENSSL_NO_CAMELLIA
{FT_cipher, "camellia-192-cbc", enc_main, enc_options}, {FT_cipher, "camellia-192-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAMELLIA #ifndef OPENSSL_NO_CAMELLIA
{FT_cipher, "camellia-192-ecb", enc_main, enc_options}, {FT_cipher, "camellia-192-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAMELLIA #ifndef OPENSSL_NO_CAMELLIA
{FT_cipher, "camellia-256-cbc", enc_main, enc_options}, {FT_cipher, "camellia-256-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAMELLIA #ifndef OPENSSL_NO_CAMELLIA
{FT_cipher, "camellia-256-ecb", enc_main, enc_options}, {FT_cipher, "camellia-256-ecb", enc_main, enc_options, NULL},
#endif #endif
{FT_cipher, "base64", enc_main, enc_options}, {FT_cipher, "base64", enc_main, enc_options, NULL},
#ifdef ZLIB #ifdef ZLIB
{FT_cipher, "zlib", enc_main, enc_options}, {FT_cipher, "zlib", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des", enc_main, enc_options}, {FT_cipher, "des", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des3", enc_main, enc_options}, {FT_cipher, "des3", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "desx", enc_main, enc_options}, {FT_cipher, "desx", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_IDEA #ifndef OPENSSL_NO_IDEA
{FT_cipher, "idea", enc_main, enc_options}, {FT_cipher, "idea", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SEED #ifndef OPENSSL_NO_SEED
{FT_cipher, "seed", enc_main, enc_options}, {FT_cipher, "seed", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC4 #ifndef OPENSSL_NO_RC4
{FT_cipher, "rc4", enc_main, enc_options}, {FT_cipher, "rc4", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC4 #ifndef OPENSSL_NO_RC4
{FT_cipher, "rc4-40", enc_main, enc_options}, {FT_cipher, "rc4-40", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC2 #ifndef OPENSSL_NO_RC2
{FT_cipher, "rc2", enc_main, enc_options}, {FT_cipher, "rc2", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_BF #ifndef OPENSSL_NO_BF
{FT_cipher, "bf", enc_main, enc_options}, {FT_cipher, "bf", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAST #ifndef OPENSSL_NO_CAST
{FT_cipher, "cast", enc_main, enc_options}, {FT_cipher, "cast", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC5 #ifndef OPENSSL_NO_RC5
{FT_cipher, "rc5", enc_main, enc_options}, {FT_cipher, "rc5", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ecb", enc_main, enc_options}, {FT_cipher, "des-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ede", enc_main, enc_options}, {FT_cipher, "des-ede", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ede3", enc_main, enc_options}, {FT_cipher, "des-ede3", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-cbc", enc_main, enc_options}, {FT_cipher, "des-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ede-cbc", enc_main, enc_options}, {FT_cipher, "des-ede-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ede3-cbc", enc_main, enc_options}, {FT_cipher, "des-ede3-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-cfb", enc_main, enc_options}, {FT_cipher, "des-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ede-cfb", enc_main, enc_options}, {FT_cipher, "des-ede-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ede3-cfb", enc_main, enc_options}, {FT_cipher, "des-ede3-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ofb", enc_main, enc_options}, {FT_cipher, "des-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ede-ofb", enc_main, enc_options}, {FT_cipher, "des-ede-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_DES #ifndef OPENSSL_NO_DES
{FT_cipher, "des-ede3-ofb", enc_main, enc_options}, {FT_cipher, "des-ede3-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_IDEA #ifndef OPENSSL_NO_IDEA
{FT_cipher, "idea-cbc", enc_main, enc_options}, {FT_cipher, "idea-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_IDEA #ifndef OPENSSL_NO_IDEA
{FT_cipher, "idea-ecb", enc_main, enc_options}, {FT_cipher, "idea-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_IDEA #ifndef OPENSSL_NO_IDEA
{FT_cipher, "idea-cfb", enc_main, enc_options}, {FT_cipher, "idea-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_IDEA #ifndef OPENSSL_NO_IDEA
{FT_cipher, "idea-ofb", enc_main, enc_options}, {FT_cipher, "idea-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SEED #ifndef OPENSSL_NO_SEED
{FT_cipher, "seed-cbc", enc_main, enc_options}, {FT_cipher, "seed-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SEED #ifndef OPENSSL_NO_SEED
{FT_cipher, "seed-ecb", enc_main, enc_options}, {FT_cipher, "seed-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SEED #ifndef OPENSSL_NO_SEED
{FT_cipher, "seed-cfb", enc_main, enc_options}, {FT_cipher, "seed-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SEED #ifndef OPENSSL_NO_SEED
{FT_cipher, "seed-ofb", enc_main, enc_options}, {FT_cipher, "seed-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC2 #ifndef OPENSSL_NO_RC2
{FT_cipher, "rc2-cbc", enc_main, enc_options}, {FT_cipher, "rc2-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC2 #ifndef OPENSSL_NO_RC2
{FT_cipher, "rc2-ecb", enc_main, enc_options}, {FT_cipher, "rc2-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC2 #ifndef OPENSSL_NO_RC2
{FT_cipher, "rc2-cfb", enc_main, enc_options}, {FT_cipher, "rc2-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC2 #ifndef OPENSSL_NO_RC2
{FT_cipher, "rc2-ofb", enc_main, enc_options}, {FT_cipher, "rc2-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC2 #ifndef OPENSSL_NO_RC2
{FT_cipher, "rc2-64-cbc", enc_main, enc_options}, {FT_cipher, "rc2-64-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC2 #ifndef OPENSSL_NO_RC2
{FT_cipher, "rc2-40-cbc", enc_main, enc_options}, {FT_cipher, "rc2-40-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_BF #ifndef OPENSSL_NO_BF
{FT_cipher, "bf-cbc", enc_main, enc_options}, {FT_cipher, "bf-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_BF #ifndef OPENSSL_NO_BF
{FT_cipher, "bf-ecb", enc_main, enc_options}, {FT_cipher, "bf-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_BF #ifndef OPENSSL_NO_BF
{FT_cipher, "bf-cfb", enc_main, enc_options}, {FT_cipher, "bf-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_BF #ifndef OPENSSL_NO_BF
{FT_cipher, "bf-ofb", enc_main, enc_options}, {FT_cipher, "bf-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAST #ifndef OPENSSL_NO_CAST
{FT_cipher, "cast5-cbc", enc_main, enc_options}, {FT_cipher, "cast5-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAST #ifndef OPENSSL_NO_CAST
{FT_cipher, "cast5-ecb", enc_main, enc_options}, {FT_cipher, "cast5-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAST #ifndef OPENSSL_NO_CAST
{FT_cipher, "cast5-cfb", enc_main, enc_options}, {FT_cipher, "cast5-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAST #ifndef OPENSSL_NO_CAST
{FT_cipher, "cast5-ofb", enc_main, enc_options}, {FT_cipher, "cast5-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_CAST #ifndef OPENSSL_NO_CAST
{FT_cipher, "cast-cbc", enc_main, enc_options}, {FT_cipher, "cast-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC5 #ifndef OPENSSL_NO_RC5
{FT_cipher, "rc5-cbc", enc_main, enc_options}, {FT_cipher, "rc5-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC5 #ifndef OPENSSL_NO_RC5
{FT_cipher, "rc5-ecb", enc_main, enc_options}, {FT_cipher, "rc5-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC5 #ifndef OPENSSL_NO_RC5
{FT_cipher, "rc5-cfb", enc_main, enc_options}, {FT_cipher, "rc5-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_RC5 #ifndef OPENSSL_NO_RC5
{FT_cipher, "rc5-ofb", enc_main, enc_options}, {FT_cipher, "rc5-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SM4 #ifndef OPENSSL_NO_SM4
{FT_cipher, "sm4-cbc", enc_main, enc_options}, {FT_cipher, "sm4-cbc", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SM4 #ifndef OPENSSL_NO_SM4
{FT_cipher, "sm4-ecb", enc_main, enc_options}, {FT_cipher, "sm4-ecb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SM4 #ifndef OPENSSL_NO_SM4
{FT_cipher, "sm4-cfb", enc_main, enc_options}, {FT_cipher, "sm4-cfb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SM4 #ifndef OPENSSL_NO_SM4
{FT_cipher, "sm4-ofb", enc_main, enc_options}, {FT_cipher, "sm4-ofb", enc_main, enc_options, NULL},
#endif #endif
#ifndef OPENSSL_NO_SM4 #ifndef OPENSSL_NO_SM4
{FT_cipher, "sm4-ctr", enc_main, enc_options}, {FT_cipher, "sm4-ctr", enc_main, enc_options, NULL},
#endif #endif
{0, NULL, NULL} {0, NULL, NULL, NULL, NULL}
}; };
+20 -7
View File
@@ -94,20 +94,33 @@ EOF
ciphers => "sock", ciphers => "sock",
genrsa => "rsa", genrsa => "rsa",
rsautl => "rsa", rsautl => "rsa",
gendsa => "dsa",
dsaparam => "dsa",
gendh => "dh", gendh => "dh",
dhparam => "dh",
ecparam => "ec", ecparam => "ec",
pkcs12 => "des", pkcs12 => "des",
); );
my %cmd_deprecated = (
dhparam => [ "3_0", "pkeyparam", "dh" ],
dsaparam => [ "3_0", "pkeyparam", "dsa" ],
dsa => [ "3_0", "pkey", "dsa" ],
gendsa => [ "3_0", "genpkey", "dsa" ],
);
print "FUNCTION functions[] = {\n"; print "FUNCTION functions[] = {\n";
foreach my $cmd ( @ARGV ) { foreach my $cmd ( @ARGV ) {
my $str = my $str =
" {FT_general, \"$cmd\", ${cmd}_main, ${cmd}_options},\n"; " {FT_general, \"$cmd\", ${cmd}_main, ${cmd}_options, NULL},\n";
if ($cmd =~ /^s_/) { if ($cmd =~ /^s_/) {
print "#ifndef OPENSSL_NO_SOCK\n${str}#endif\n"; print "#ifndef OPENSSL_NO_SOCK\n${str}#endif\n";
} elsif (my $deprecated = $cmd_deprecated{$cmd}) {
my @dep = @{$deprecated};
print "#if ";
if ($dep[2]) {
print "!defined(OPENSSL_NO_" . uc($dep[2]) . ") && ";
}
print "!defined(OPENSSL_NO_DEPRECATED_" . $dep[0] . ")";
my $dalt = "\"" . $dep[1] . "\"";
$str =~ s/NULL/$dalt/;
print "\n${str}#endif\n";
} elsif (grep { $cmd eq $_ } @disablables) { } elsif (grep { $cmd eq $_ } @disablables) {
print "#ifndef OPENSSL_NO_" . uc($cmd) . "\n${str}#endif\n"; print "#ifndef OPENSSL_NO_" . uc($cmd) . "\n${str}#endif\n";
} elsif (my $disabler = $cmd_disabler{$cmd}) { } elsif (my $disabler = $cmd_disabler{$cmd}) {
@@ -131,7 +144,7 @@ EOF
"mdc2", "rmd160", "blake2b512", "blake2s256", "mdc2", "rmd160", "blake2b512", "blake2s256",
"sm3" "sm3"
) { ) {
my $str = " {FT_md, \"$cmd\", dgst_main},\n"; my $str = " {FT_md, \"$cmd\", dgst_main, NULL, NULL},\n";
if (grep { $cmd eq $_ } @disablables) { if (grep { $cmd eq $_ } @disablables) {
print "#ifndef OPENSSL_NO_" . uc($cmd) . "\n${str}#endif\n"; print "#ifndef OPENSSL_NO_" . uc($cmd) . "\n${str}#endif\n";
} elsif (my $disabler = $md_disabler{$cmd}) { } elsif (my $disabler = $md_disabler{$cmd}) {
@@ -177,7 +190,7 @@ EOF
"cast-cbc", "rc5-cbc", "rc5-ecb", "rc5-cfb", "rc5-ofb", "cast-cbc", "rc5-cbc", "rc5-ecb", "rc5-cfb", "rc5-ofb",
"sm4-cbc", "sm4-ecb", "sm4-cfb", "sm4-ofb", "sm4-ctr" "sm4-cbc", "sm4-ecb", "sm4-cfb", "sm4-ofb", "sm4-ctr"
) { ) {
my $str = " {FT_cipher, \"$cmd\", enc_main, enc_options},\n"; my $str = " {FT_cipher, \"$cmd\", enc_main, enc_options, NULL},\n";
(my $algo = $cmd) =~ s/-.*//g; (my $algo = $cmd) =~ s/-.*//g;
if ($cmd eq "zlib") { if ($cmd eq "zlib") {
print "#ifdef ZLIB\n${str}#endif\n"; print "#ifdef ZLIB\n${str}#endif\n";
@@ -190,5 +203,5 @@ EOF
} }
} }
print " {0, NULL, NULL}\n};\n"; print " {0, NULL, NULL, NULL, NULL}\n};\n";
} }
+13 -13
View File
@@ -99,7 +99,7 @@
# include "./testrsa.h" # include "./testrsa.h"
#endif #endif
#include <openssl/x509.h> #include <openssl/x509.h>
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
# include <openssl/dsa.h> # include <openssl/dsa.h>
# include "./testdsa.h" # include "./testdsa.h"
#endif #endif
@@ -406,7 +406,7 @@ static const OPT_PAIR doit_choices[] = {
static double results[ALGOR_NUM][SIZE_NUM]; static double results[ALGOR_NUM][SIZE_NUM];
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
enum { R_DSA_512, R_DSA_1024, R_DSA_2048, DSA_NUM }; enum { R_DSA_512, R_DSA_1024, R_DSA_2048, DSA_NUM };
static const OPT_PAIR dsa_choices[DSA_NUM] = { static const OPT_PAIR dsa_choices[DSA_NUM] = {
{"dsa512", R_DSA_512}, {"dsa512", R_DSA_512},
@@ -545,7 +545,7 @@ typedef struct loopargs_st {
#ifndef OPENSSL_NO_RSA #ifndef OPENSSL_NO_RSA
RSA *rsa_key[RSA_NUM]; RSA *rsa_key[RSA_NUM];
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
DSA *dsa_key[DSA_NUM]; DSA *dsa_key[DSA_NUM];
#endif #endif
#ifndef OPENSSL_NO_EC #ifndef OPENSSL_NO_EC
@@ -1066,7 +1066,7 @@ static int RSA_verify_loop(void *args)
} }
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
static long dsa_c[DSA_NUM][2]; static long dsa_c[DSA_NUM][2];
static int DSA_sign_loop(void *args) static int DSA_sign_loop(void *args)
{ {
@@ -1520,7 +1520,7 @@ int speed_main(int argc, char **argv)
uint8_t rsa_doit[RSA_NUM] = { 0 }; uint8_t rsa_doit[RSA_NUM] = { 0 };
int primes = RSA_DEFAULT_PRIME_NUM; int primes = RSA_DEFAULT_PRIME_NUM;
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
static const unsigned int dsa_bits[DSA_NUM] = { 512, 1024, 2048 }; static const unsigned int dsa_bits[DSA_NUM] = { 512, 1024, 2048 };
uint8_t dsa_doit[DSA_NUM] = { 0 }; uint8_t dsa_doit[DSA_NUM] = { 0 };
#endif #endif
@@ -1760,7 +1760,7 @@ int speed_main(int argc, char **argv)
} }
} }
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
if (strncmp(algo, "dsa", 3) == 0) { if (strncmp(algo, "dsa", 3) == 0) {
if (algo[3] == '\0') { if (algo[3] == '\0') {
memset(dsa_doit, 1, sizeof(dsa_doit)); memset(dsa_doit, 1, sizeof(dsa_doit));
@@ -1912,7 +1912,7 @@ int speed_main(int argc, char **argv)
#ifndef OPENSSL_NO_RSA #ifndef OPENSSL_NO_RSA
memset(rsa_doit, 1, sizeof(rsa_doit)); memset(rsa_doit, 1, sizeof(rsa_doit));
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
memset(dsa_doit, 1, sizeof(dsa_doit)); memset(dsa_doit, 1, sizeof(dsa_doit));
#endif #endif
#ifndef OPENSSL_NO_EC #ifndef OPENSSL_NO_EC
@@ -1952,7 +1952,7 @@ int speed_main(int argc, char **argv)
} }
} }
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
for (i = 0; i < loopargs_len; i++) { for (i = 0; i < loopargs_len; i++) {
loopargs[i].dsa_key[0] = get_dsa(512); loopargs[i].dsa_key[0] = get_dsa(512);
loopargs[i].dsa_key[1] = get_dsa(1024); loopargs[i].dsa_key[1] = get_dsa(1024);
@@ -2120,7 +2120,7 @@ int speed_main(int argc, char **argv)
} }
# endif # endif
# ifndef OPENSSL_NO_DSA # if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
dsa_c[R_DSA_512][0] = count / 1000; dsa_c[R_DSA_512][0] = count / 1000;
dsa_c[R_DSA_512][1] = count / 1000 / 2; dsa_c[R_DSA_512][1] = count / 1000 / 2;
for (i = 1; i < DSA_NUM; i++) { for (i = 1; i < DSA_NUM; i++) {
@@ -2955,7 +2955,7 @@ int speed_main(int argc, char **argv)
if (RAND_bytes(loopargs[i].buf, 36) <= 0) if (RAND_bytes(loopargs[i].buf, 36) <= 0)
goto end; goto end;
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
for (testnum = 0; testnum < DSA_NUM; testnum++) { for (testnum = 0; testnum < DSA_NUM; testnum++) {
int st = 0; int st = 0;
if (!dsa_doit[testnum]) if (!dsa_doit[testnum])
@@ -3582,7 +3582,7 @@ int speed_main(int argc, char **argv)
rsa_results[k][0], rsa_results[k][1]); rsa_results[k][0], rsa_results[k][1]);
} }
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
testnum = 1; testnum = 1;
for (k = 0; k < DSA_NUM; k++) { for (k = 0; k < DSA_NUM; k++) {
if (!dsa_doit[k]) if (!dsa_doit[k])
@@ -3695,7 +3695,7 @@ int speed_main(int argc, char **argv)
for (k = 0; k < RSA_NUM; k++) for (k = 0; k < RSA_NUM; k++)
RSA_free(loopargs[i].rsa_key[k]); RSA_free(loopargs[i].rsa_key[k]);
#endif #endif
#ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
for (k = 0; k < DSA_NUM; k++) for (k = 0; k < DSA_NUM; k++)
DSA_free(loopargs[i].dsa_key[k]); DSA_free(loopargs[i].dsa_key[k]);
#endif #endif
@@ -3901,7 +3901,7 @@ static int do_multi(int multi, int size_num)
d = atof(sstrsep(&p, sep)); d = atof(sstrsep(&p, sep));
rsa_results[k][1] += d; rsa_results[k][1] += d;
} }
# ifndef OPENSSL_NO_DSA #if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)
else if (strncmp(buf, "+F3:", 4) == 0) { else if (strncmp(buf, "+F3:", 4) == 0) {
int k; int k;
double d; double d;
+1 -1
View File
@@ -128,7 +128,7 @@ const OPTIONS x509_options[] = {
{"setalias", OPT_SETALIAS, 's', "Set certificate alias"}, {"setalias", OPT_SETALIAS, 's', "Set certificate alias"},
{"days", OPT_DAYS, 'n', {"days", OPT_DAYS, 'n',
"How long till expiry of a signed certificate - def 30 days"}, "How long till expiry of a signed certificate - def 30 days"},
{"signkey", OPT_SIGNKEY, '<', "Self sign cert with arg"}, {"signkey", OPT_SIGNKEY, 's', "Self sign cert with arg"},
{"set_serial", OPT_SET_SERIAL, 's', "Serial number to use"}, {"set_serial", OPT_SET_SERIAL, 's', "Serial number to use"},
{"extensions", OPT_EXTENSIONS, 's', "Section from config file to use"}, {"extensions", OPT_EXTENSIONS, 's', "Section from config file to use"},
{"certopt", OPT_CERTOPT, 's', "Various certificate text options"}, {"certopt", OPT_CERTOPT, 's', "Various certificate text options"},
+1 -1
View File
@@ -2995,4 +2995,4 @@ sub deckey()
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1245,4 +1245,4 @@ while(<SELF>) {
close SELF; close SELF;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; # enforce flush close STDOUT or die "error closing STDOUT: $!"; # enforce flush
+1 -1
View File
@@ -1378,4 +1378,4 @@ AES_Td4:
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -2203,4 +2203,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1038,4 +1038,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1460,4 +1460,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval $1/gem; $code =~ s/\`([^\`]*)\`/eval $1/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -2281,4 +2281,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval $1/gem; $code =~ s/\`([^\`]*)\`/eval $1/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; # force flush close STDOUT or die "error closing STDOUT: $!"; # force flush
+1 -1
View File
@@ -1188,4 +1188,4 @@ ___
$code =~ s/fmovs.*$//gm; $code =~ s/fmovs.*$//gm;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; # ensure flush close STDOUT or die "error closing STDOUT: $!"; # ensure flush
+6 -1
View File
@@ -606,6 +606,7 @@ $code.=<<___;
asm_AES_encrypt: asm_AES_encrypt:
AES_encrypt: AES_encrypt:
.cfi_startproc .cfi_startproc
endbranch
mov %rsp,%rax mov %rsp,%rax
.cfi_def_cfa_register %rax .cfi_def_cfa_register %rax
push %rbx push %rbx
@@ -1226,6 +1227,7 @@ $code.=<<___;
asm_AES_decrypt: asm_AES_decrypt:
AES_decrypt: AES_decrypt:
.cfi_startproc .cfi_startproc
endbranch
mov %rsp,%rax mov %rsp,%rax
.cfi_def_cfa_register %rax .cfi_def_cfa_register %rax
push %rbx push %rbx
@@ -1343,6 +1345,7 @@ $code.=<<___;
.align 16 .align 16
AES_set_encrypt_key: AES_set_encrypt_key:
.cfi_startproc .cfi_startproc
endbranch
push %rbx push %rbx
.cfi_push %rbx .cfi_push %rbx
push %rbp push %rbp
@@ -1623,6 +1626,7 @@ $code.=<<___;
.align 16 .align 16
AES_set_decrypt_key: AES_set_decrypt_key:
.cfi_startproc .cfi_startproc
endbranch
push %rbx push %rbx
.cfi_push %rbx .cfi_push %rbx
push %rbp push %rbp
@@ -1737,6 +1741,7 @@ $code.=<<___;
asm_AES_cbc_encrypt: asm_AES_cbc_encrypt:
AES_cbc_encrypt: AES_cbc_encrypt:
.cfi_startproc .cfi_startproc
endbranch
cmp \$0,%rdx # check length cmp \$0,%rdx # check length
je .Lcbc_epilogue je .Lcbc_epilogue
pushfq pushfq
@@ -2919,4 +2924,4 @@ $code =~ s/\`([^\`]*)\`/eval($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1266,4 +1266,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1473,4 +1473,4 @@ $code =~ s/\`([^\`]*)\`/eval($1)/gem;
$code =~ s/\b(aes.*%xmm[0-9]+).*$/aesni($1)/gem; $code =~ s/\b(aes.*%xmm[0-9]+).*$/aesni($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -2145,4 +2145,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1801,4 +1801,4 @@ sub rex {
$code =~ s/\`([^\`]*)\`/eval $1/gem; $code =~ s/\`([^\`]*)\`/eval $1/gem;
$code =~ s/\b(sha256[^\s]*)\s+(.*)/sha256op38($1,$2)/gem; $code =~ s/\b(sha256[^\s]*)\s+(.*)/sha256op38($1,$2)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -3410,4 +3410,4 @@ my ($l_,$block,$i1,$i3,$i5) = ($rounds_,$key_,$rounds,$len,$out);
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+12 -1
View File
@@ -277,6 +277,7 @@ $code.=<<___;
.align 16 .align 16
${PREFIX}_encrypt: ${PREFIX}_encrypt:
.cfi_startproc .cfi_startproc
endbranch
movups ($inp),$inout0 # load input movups ($inp),$inout0 # load input
mov 240($key),$rounds # key->rounds mov 240($key),$rounds # key->rounds
___ ___
@@ -295,6 +296,7 @@ $code.=<<___;
.align 16 .align 16
${PREFIX}_decrypt: ${PREFIX}_decrypt:
.cfi_startproc .cfi_startproc
endbranch
movups ($inp),$inout0 # load input movups ($inp),$inout0 # load input
mov 240($key),$rounds # key->rounds mov 240($key),$rounds # key->rounds
___ ___
@@ -615,6 +617,7 @@ $code.=<<___;
.align 16 .align 16
aesni_ecb_encrypt: aesni_ecb_encrypt:
.cfi_startproc .cfi_startproc
endbranch
___ ___
$code.=<<___ if ($win64); $code.=<<___ if ($win64);
lea -0x58(%rsp),%rsp lea -0x58(%rsp),%rsp
@@ -987,6 +990,7 @@ $code.=<<___;
.align 16 .align 16
aesni_ccm64_encrypt_blocks: aesni_ccm64_encrypt_blocks:
.cfi_startproc .cfi_startproc
endbranch
___ ___
$code.=<<___ if ($win64); $code.=<<___ if ($win64);
lea -0x58(%rsp),%rsp lea -0x58(%rsp),%rsp
@@ -1079,6 +1083,7 @@ $code.=<<___;
.align 16 .align 16
aesni_ccm64_decrypt_blocks: aesni_ccm64_decrypt_blocks:
.cfi_startproc .cfi_startproc
endbranch
___ ___
$code.=<<___ if ($win64); $code.=<<___ if ($win64);
lea -0x58(%rsp),%rsp lea -0x58(%rsp),%rsp
@@ -1205,6 +1210,7 @@ $code.=<<___;
.align 16 .align 16
aesni_ctr32_encrypt_blocks: aesni_ctr32_encrypt_blocks:
.cfi_startproc .cfi_startproc
endbranch
cmp \$1,$len cmp \$1,$len
jne .Lctr32_bulk jne .Lctr32_bulk
@@ -1777,6 +1783,7 @@ $code.=<<___;
.align 16 .align 16
aesni_xts_encrypt: aesni_xts_encrypt:
.cfi_startproc .cfi_startproc
endbranch
lea (%rsp),%r11 # frame pointer lea (%rsp),%r11 # frame pointer
.cfi_def_cfa_register %r11 .cfi_def_cfa_register %r11
push %rbp push %rbp
@@ -2260,6 +2267,7 @@ $code.=<<___;
.align 16 .align 16
aesni_xts_decrypt: aesni_xts_decrypt:
.cfi_startproc .cfi_startproc
endbranch
lea (%rsp),%r11 # frame pointer lea (%rsp),%r11 # frame pointer
.cfi_def_cfa_register %r11 .cfi_def_cfa_register %r11
push %rbp push %rbp
@@ -2785,6 +2793,7 @@ $code.=<<___;
.align 32 .align 32
aesni_ocb_encrypt: aesni_ocb_encrypt:
.cfi_startproc .cfi_startproc
endbranch
lea (%rsp),%rax lea (%rsp),%rax
push %rbx push %rbx
.cfi_push %rbx .cfi_push %rbx
@@ -3251,6 +3260,7 @@ __ocb_encrypt1:
.align 32 .align 32
aesni_ocb_decrypt: aesni_ocb_decrypt:
.cfi_startproc .cfi_startproc
endbranch
lea (%rsp),%rax lea (%rsp),%rax
push %rbx push %rbx
.cfi_push %rbx .cfi_push %rbx
@@ -3739,6 +3749,7 @@ $code.=<<___;
.align 16 .align 16
${PREFIX}_cbc_encrypt: ${PREFIX}_cbc_encrypt:
.cfi_startproc .cfi_startproc
endbranch
test $len,$len # check length test $len,$len # check length
jz .Lcbc_ret jz .Lcbc_ret
@@ -5156,4 +5167,4 @@ $code =~ s/\bmovbe\s+%eax,\s*([0-9]+)\(%rsp\)/movbe($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -3808,4 +3808,4 @@ foreach(split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -925,4 +925,4 @@ ___
&emit_assembler(); &emit_assembler();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+10 -2
View File
@@ -211,7 +211,12 @@ $code.=<<___;
.Loop192: .Loop192:
vtbl.8 $key,{$in1},$mask vtbl.8 $key,{$in1},$mask
vext.8 $tmp,$zero,$in0,#12 vext.8 $tmp,$zero,$in0,#12
#ifdef __ARMEB__
vst1.32 {$in1},[$out],#16
sub $out,$out,#8
#else
vst1.32 {$in1},[$out],#8 vst1.32 {$in1},[$out],#8
#endif
aese $key,$zero aese $key,$zero
subs $bits,$bits,#1 subs $bits,$bits,#1
@@ -1772,8 +1777,11 @@ $code.=<<___;
ldr $rounds,[$key,#240] ldr $rounds,[$key,#240]
ldr $ctr, [$ivp, #12] ldr $ctr, [$ivp, #12]
#ifdef __ARMEB__
vld1.8 {$dat0},[$ivp]
#else
vld1.32 {$dat0},[$ivp] vld1.32 {$dat0},[$ivp]
#endif
vld1.32 {q8-q9},[$key] // load key schedule... vld1.32 {q8-q9},[$key] // load key schedule...
sub $rounds,$rounds,#4 sub $rounds,$rounds,#4
mov $step,#16 mov $step,#16
@@ -2237,4 +2245,4 @@ if ($flavour =~ /64/) { ######## 64-bit code
} }
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -2491,4 +2491,4 @@ close SELF;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+3 -1
View File
@@ -1616,6 +1616,7 @@ $code.=<<___;
.align 16 .align 16
bsaes_cbc_encrypt: bsaes_cbc_encrypt:
.cfi_startproc .cfi_startproc
endbranch
___ ___
$code.=<<___ if ($win64); $code.=<<___ if ($win64);
mov 48(%rsp),$arg6 # pull direction flag mov 48(%rsp),$arg6 # pull direction flag
@@ -1921,6 +1922,7 @@ $code.=<<___;
.align 16 .align 16
bsaes_ctr32_encrypt_blocks: bsaes_ctr32_encrypt_blocks:
.cfi_startproc .cfi_startproc
endbranch
mov %rsp, %rax mov %rsp, %rax
.Lctr_enc_prologue: .Lctr_enc_prologue:
push %rbp push %rbp
@@ -3238,4 +3240,4 @@ $code =~ s/\`([^\`]*)\`/eval($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1278,4 +1278,4 @@ ___
} } } }
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1595,4 +1595,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -911,4 +911,4 @@ $k_dsbo=0x2c0; # decryption sbox final output
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+6 -1
View File
@@ -698,6 +698,7 @@ _vpaes_schedule_mangle:
.align 16 .align 16
${PREFIX}_set_encrypt_key: ${PREFIX}_set_encrypt_key:
.cfi_startproc .cfi_startproc
endbranch
___ ___
$code.=<<___ if ($win64); $code.=<<___ if ($win64);
lea -0xb8(%rsp),%rsp lea -0xb8(%rsp),%rsp
@@ -748,6 +749,7 @@ $code.=<<___;
.align 16 .align 16
${PREFIX}_set_decrypt_key: ${PREFIX}_set_decrypt_key:
.cfi_startproc .cfi_startproc
endbranch
___ ___
$code.=<<___ if ($win64); $code.=<<___ if ($win64);
lea -0xb8(%rsp),%rsp lea -0xb8(%rsp),%rsp
@@ -803,6 +805,7 @@ $code.=<<___;
.align 16 .align 16
${PREFIX}_encrypt: ${PREFIX}_encrypt:
.cfi_startproc .cfi_startproc
endbranch
___ ___
$code.=<<___ if ($win64); $code.=<<___ if ($win64);
lea -0xb8(%rsp),%rsp lea -0xb8(%rsp),%rsp
@@ -848,6 +851,7 @@ $code.=<<___;
.align 16 .align 16
${PREFIX}_decrypt: ${PREFIX}_decrypt:
.cfi_startproc .cfi_startproc
endbranch
___ ___
$code.=<<___ if ($win64); $code.=<<___ if ($win64);
lea -0xb8(%rsp),%rsp lea -0xb8(%rsp),%rsp
@@ -899,6 +903,7 @@ $code.=<<___;
.align 16 .align 16
${PREFIX}_cbc_encrypt: ${PREFIX}_cbc_encrypt:
.cfi_startproc .cfi_startproc
endbranch
xchg $key,$len xchg $key,$len
___ ___
($len,$key)=($key,$len); ($len,$key)=($key,$len);
@@ -1240,4 +1245,4 @@ $code =~ s/\`([^\`]*)\`/eval($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -253,4 +253,4 @@ OPENSSL_instrument_bus2:
___ ___
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -147,4 +147,4 @@ CRYPTO_memcmp:
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -297,4 +297,4 @@ atomic_add_spinlock:
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+8
View File
@@ -199,6 +199,14 @@ static int asn1_write_micalg(BIO *out, STACK_OF(X509_ALGOR) *mdalgs)
BIO_puts(out, "gostr3411-94"); BIO_puts(out, "gostr3411-94");
goto err; goto err;
case NID_id_GostR3411_2012_256:
BIO_puts(out, "gostr3411-2012-256");
goto err;
case NID_id_GostR3411_2012_512:
BIO_puts(out, "gostr3411-2012-512");
goto err;
default: default:
if (have_unknown) if (have_unknown)
write_comma = 0; write_comma = 0;
+6
View File
@@ -7,6 +7,12 @@
* https://www.openssl.org/source/license.html * https://www.openssl.org/source/license.html
*/ */
/*
* DSA low level APIs are deprecated for public use, but still ok for
* internal use.
*/
#include "internal/deprecated.h"
#include <stdio.h> #include <stdio.h>
#include "internal/cryptlib.h" #include "internal/cryptlib.h"
#include <openssl/bn.h> #include <openssl/bn.h>
+32
View File
@@ -10,6 +10,8 @@
#include <stdio.h> #include <stdio.h>
#include "internal/cryptlib.h" #include "internal/cryptlib.h"
#include <openssl/evp.h> #include <openssl/evp.h>
#include <openssl/serializer.h>
#include <openssl/buffer.h>
#include <openssl/x509.h> #include <openssl/x509.h>
#include "crypto/asn1.h" #include "crypto/asn1.h"
#include "crypto/evp.h" #include "crypto/evp.h"
@@ -28,6 +30,36 @@ int i2d_PrivateKey(const EVP_PKEY *a, unsigned char **pp)
} }
return ret; return ret;
} }
if (a->pkeys[0].keymgmt != NULL) {
const char *serprop = OSSL_SERIALIZER_PrivateKey_TO_DER_PQ;
OSSL_SERIALIZER_CTX *ctx =
OSSL_SERIALIZER_CTX_new_by_EVP_PKEY(a, serprop);
BIO *out = BIO_new(BIO_s_mem());
BUF_MEM *buf = NULL;
int ret = -1;
if (ctx != NULL
&& out != NULL
&& OSSL_SERIALIZER_CTX_get_serializer(ctx) != NULL
&& OSSL_SERIALIZER_to_bio(ctx, out)
&& BIO_get_mem_ptr(out, &buf) > 0) {
ret = buf->length;
if (pp != NULL) {
if (*pp == NULL) {
*pp = (unsigned char *)buf->data;
buf->length = 0;
buf->data = NULL;
} else {
memcpy(*pp, buf->data, ret);
*pp += ret;
}
}
}
BIO_free(out);
OSSL_SERIALIZER_CTX_free(ctx);
return ret;
}
ASN1err(ASN1_F_I2D_PRIVATEKEY, ASN1_R_UNSUPPORTED_PUBLIC_KEY_TYPE); ASN1err(ASN1_F_I2D_PRIVATEKEY, ASN1_R_UNSUPPORTED_PUBLIC_KEY_TYPE);
return -1; return -1;
} }
+6
View File
@@ -7,6 +7,12 @@
* https://www.openssl.org/source/license.html * https://www.openssl.org/source/license.html
*/ */
/*
* DSA low level APIs are deprecated for public use, but still ok for
* internal use.
*/
#include "internal/deprecated.h"
#include <stdio.h> #include <stdio.h>
#include "internal/cryptlib.h" #include "internal/cryptlib.h"
#include <openssl/bn.h> #include <openssl/bn.h>
+1 -1
View File
@@ -31,7 +31,7 @@ $tmp4="edx";
&cbc("BF_cbc_encrypt","BF_encrypt","BF_decrypt",1,4,5,3,-1,-1); &cbc("BF_cbc_encrypt","BF_encrypt","BF_decrypt",1,4,5,3,-1,-1);
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
sub BF_encrypt sub BF_encrypt
{ {
+1 -1
View File
@@ -324,4 +324,4 @@ bn_mul_mont:
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -338,4 +338,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; # enforce flush close STDOUT or die "error closing STDOUT: $!"; # enforce flush
+1 -1
View File
@@ -763,4 +763,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1514,4 +1514,4 @@ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -30,7 +30,7 @@ for (@ARGV) { $sse2=1 if (/-DOPENSSL_IA32_SSE2/); }
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
sub bn_mul_add_words sub bn_mul_add_words
{ {
+1 -1
View File
@@ -156,4 +156,4 @@ $code.=<<___;
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -21,7 +21,7 @@ $output = pop and open STDOUT,">$output";
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
sub mul_add_c sub mul_add_c
{ {
+1 -1
View File
@@ -858,4 +858,4 @@ ___
open STDOUT,">$output" if $output; open STDOUT,">$output" if $output;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -433,4 +433,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval $1/gem; $code =~ s/\`([^\`]*)\`/eval $1/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -2262,4 +2262,4 @@ $code.=<<___;
.end bn_sqr_comba4 .end bn_sqr_comba4
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1005,4 +1005,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1991,4 +1991,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval $1/gem; $code =~ s/\`([^\`]*)\`/eval $1/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -2013,4 +2013,4 @@ Lppcasm_maw_adios:
EOF EOF
$data =~ s/\`([^\`]*)\`/eval $1/gem; $data =~ s/\`([^\`]*)\`/eval $1/gem;
print $data; print $data;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1653,4 +1653,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval $1/gem; $code =~ s/\`([^\`]*)\`/eval $1/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1981,4 +1981,4 @@ rsaz_1024_gather5_avx2:
___ ___
}}} }}}
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -2430,4 +2430,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval $1/gem; $code =~ s/\`([^\`]*)\`/eval $1/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -227,4 +227,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval($1)/gem; $code =~ s/\`([^\`]*)\`/eval($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -283,4 +283,4 @@ foreach (split("\n",$code)) {
s/_dswap\s+(%r[0-9]+)/sprintf("rllg\t%s,%s,32",$1,$1) if($SIZE_T==4)/e; s/_dswap\s+(%r[0-9]+)/sprintf("rllg\t%s,%s,32",$1,$1) if($SIZE_T==4)/e;
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1224,4 +1224,4 @@ ___
&emit_assembler(); &emit_assembler();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -196,4 +196,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval($1)/gem; $code =~ s/\`([^\`]*)\`/eval($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -616,4 +616,4 @@ $code.=<<___;
___ ___
$code =~ s/\`([^\`]*)\`/eval($1)/gem; $code =~ s/\`([^\`]*)\`/eval($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -886,4 +886,4 @@ $code =~ s/fzeros\s+%f([0-9]+)/
print $code; print $code;
# flush # flush
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -247,4 +247,4 @@ $sp=&DWP(28,"esp");
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -380,4 +380,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -321,4 +321,4 @@ if ($sse2) {
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -627,4 +627,4 @@ $sbit=$num;
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -423,4 +423,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval($1)/gem; $code =~ s/\`([^\`]*)\`/eval($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1591,4 +1591,4 @@ ___
} }
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -3962,4 +3962,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval($1)/gem; $code =~ s/\`([^\`]*)\`/eval($1)/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1
View File
@@ -22,6 +22,7 @@
# endif # endif
# include "crypto/bn.h" # include "crypto/bn.h"
# include "internal/cryptlib.h"
/* /*
* These preprocessor symbols control various aspects of the bignum headers * These preprocessor symbols control various aspects of the bignum headers
+1 -1
View File
@@ -284,4 +284,4 @@ bus_loop2_done?:
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1146,4 +1146,4 @@ my ($s0,$s1,$s2,$s3) = @T;
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+2 -1
View File
@@ -687,6 +687,7 @@ $code.=<<___;
.align 16 .align 16
Camellia_cbc_encrypt: Camellia_cbc_encrypt:
.cfi_startproc .cfi_startproc
endbranch
cmp \$0,%rdx cmp \$0,%rdx
je .Lcbc_abort je .Lcbc_abort
push %rbx push %rbx
@@ -1152,4 +1153,4 @@ ___
$code =~ s/\`([^\`]*)\`/eval $1/gem; $code =~ s/\`([^\`]*)\`/eval $1/gem;
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -935,4 +935,4 @@ ___
&emit_assembler(); &emit_assembler();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -45,7 +45,7 @@ $S4="CAST_S_table3";
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
sub CAST_encrypt { sub CAST_encrypt {
local($name,$enc)=@_; local($name,$enc)=@_;
+1 -1
View File
@@ -1166,4 +1166,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1289,4 +1289,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; # flush close STDOUT or die "error closing STDOUT: $!"; # flush
+1 -1
View File
@@ -922,4 +922,4 @@ $code.=<<___;
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -288,4 +288,4 @@ stringz "ChaCha20 for IA64, CRYPTOGAMS by \@dot-asm"
___ ___
print $code; print $code;
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1349,4 +1349,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1151,4 +1151,4 @@ sub XOPROUND {
&asm_finish(); &asm_finish();
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -4004,4 +4004,4 @@ foreach (split("\n",$code)) {
print $_,"\n"; print $_,"\n";
} }
close STDOUT or die "error closing STDOUT"; close STDOUT or die "error closing STDOUT: $!";
+1 -1
View File
@@ -1,3 +1,3 @@
LIBS=../../libcrypto LIBS=../../libcrypto
SOURCE[../../libcrypto]= cmp_asn.c cmp_ctx.c cmp_err.c cmp_util.c \ SOURCE[../../libcrypto]= cmp_asn.c cmp_ctx.c cmp_err.c cmp_util.c \
cmp_status.c cmp_hdr.c cmp_protect.c cmp_msg.c cmp_status.c cmp_hdr.c cmp_protect.c cmp_msg.c cmp_vfy.c
+2 -1
View File
@@ -73,7 +73,8 @@ ASN1_SEQUENCE(OSSL_CMP_ERRORMSGCONTENT) = {
IMPLEMENT_ASN1_FUNCTIONS(OSSL_CMP_ERRORMSGCONTENT) IMPLEMENT_ASN1_FUNCTIONS(OSSL_CMP_ERRORMSGCONTENT)
ASN1_ADB_TEMPLATE(infotypeandvalue_default) = ASN1_OPT(OSSL_CMP_ITAV, ASN1_ADB_TEMPLATE(infotypeandvalue_default) = ASN1_OPT(OSSL_CMP_ITAV,
infoValue.other, ASN1_ANY); infoValue.other,
ASN1_ANY);
/* ITAV means InfoTypeAndValue */ /* ITAV means InfoTypeAndValue */
ASN1_ADB(OSSL_CMP_ITAV) = { ASN1_ADB(OSSL_CMP_ITAV) = {
/* OSSL_CMP_CMPCERTIFICATE is effectively X509 so it is used directly */ /* OSSL_CMP_CMPCERTIFICATE is effectively X509 so it is used directly */
+54 -3
View File
@@ -301,7 +301,7 @@ static size_t ossl_cmp_log_trace_cb(const char *buf, size_t cnt,
int category, int cmd, void *vdata) int category, int cmd, void *vdata)
{ {
OSSL_CMP_CTX *ctx = vdata; OSSL_CMP_CTX *ctx = vdata;
const char *prefix_msg; const char *msg;
OSSL_CMP_severity level = -1; OSSL_CMP_severity level = -1;
char *func = NULL; char *func = NULL;
char *file = NULL; char *file = NULL;
@@ -312,14 +312,14 @@ static size_t ossl_cmp_log_trace_cb(const char *buf, size_t cnt,
if (ctx->log_cb == NULL) if (ctx->log_cb == NULL)
return 1; /* silently drop message */ return 1; /* silently drop message */
prefix_msg = ossl_cmp_log_parse_metadata(buf, &level, &func, &file, &line); msg = ossl_cmp_log_parse_metadata(buf, &level, &func, &file, &line);
if (level > ctx->log_verbosity) /* excludes the case level is unknown */ if (level > ctx->log_verbosity) /* excludes the case level is unknown */
goto end; /* suppress output since severity is not sufficient */ goto end; /* suppress output since severity is not sufficient */
if (!ctx->log_cb(func != NULL ? func : "(no func)", if (!ctx->log_cb(func != NULL ? func : "(no func)",
file != NULL ? file : "(no file)", file != NULL ? file : "(no file)",
line, level, prefix_msg)) line, level, msg))
cnt = 0; cnt = 0;
end: end:
@@ -329,6 +329,57 @@ static size_t ossl_cmp_log_trace_cb(const char *buf, size_t cnt,
} }
#endif #endif
/* Print CMP log messages (i.e., diagnostic info) via the log cb of the ctx */
int ossl_cmp_print_log(OSSL_CMP_severity level, const OSSL_CMP_CTX *ctx,
const char *func, const char *file, int line,
const char *level_str, const char *format, ...)
{
va_list args;
char hugebuf[1024 * 2];
int res = 0;
if (ctx == NULL || ctx->log_cb == NULL)
return 1; /* silently drop message */
if (level > ctx->log_verbosity) /* excludes the case level is unknown */
return 1; /* suppress output since severity is not sufficient */
if (format == NULL)
return 0;
va_start(args, format);
if (func == NULL)
func = "(unset function name)";
if (file == NULL)
file = "(unset file name)";
if (level_str == NULL)
level_str = "(unset level string)";
#ifndef OPENSSL_NO_TRACE
if (OSSL_TRACE_ENABLED(CMP)) {
OSSL_TRACE_BEGIN(CMP) {
int printed =
BIO_snprintf(hugebuf, sizeof(hugebuf),
"%s:%s:%d:" OSSL_CMP_LOG_PREFIX "%s: ",
func, file, line, level_str);
if (printed > 0 && (size_t)printed < sizeof(hugebuf)) {
if (BIO_vsnprintf(hugebuf + printed,
sizeof(hugebuf) - printed, format, args) > 0)
res = BIO_puts(trc_out, hugebuf) > 0;
}
} OSSL_TRACE_END(CMP);
}
#else /* compensate for disabled trace API */
{
if (BIO_vsnprintf(hugebuf, sizeof(hugebuf), format, args) > 0)
res = ctx->log_cb(func, file, line, level, hugebuf);
}
#endif
va_end(args);
return res;
}
/* /*
* Set a callback function for error reporting and logging messages. * Set a callback function for error reporting and logging messages.
* Returns 1 on success, 0 on error * Returns 1 on success, 0 on error
+28
View File
@@ -14,6 +14,8 @@
#ifndef OPENSSL_NO_ERR #ifndef OPENSSL_NO_ERR
static const ERR_STRING_DATA CMP_str_reasons[] = { static const ERR_STRING_DATA CMP_str_reasons[] = {
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_ALGORITHM_NOT_SUPPORTED),
"algorithm not supported"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_BAD_REQUEST_ID), "bad request id"}, {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_BAD_REQUEST_ID), "bad request id"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_CERTID_NOT_FOUND), "certid not found"}, {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_CERTID_NOT_FOUND), "certid not found"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_CERTIFICATE_NOT_FOUND), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_CERTIFICATE_NOT_FOUND),
@@ -50,6 +52,10 @@ static const ERR_STRING_DATA CMP_str_reasons[] = {
"error protecting message"}, "error protecting message"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_ERROR_SETTING_CERTHASH), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_ERROR_SETTING_CERTHASH),
"error setting certhash"}, "error setting certhash"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_ERROR_VALIDATING_PROTECTION),
"error validating protection"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_FAILED_EXTRACTING_PUBKEY),
"failed extracting pubkey"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_FAILURE_OBTAINING_RANDOM), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_FAILURE_OBTAINING_RANDOM),
"failure obtaining random"}, "failure obtaining random"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_FAIL_INFO_OUT_OF_RANGE), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_FAIL_INFO_OUT_OF_RANGE),
@@ -57,19 +63,38 @@ static const ERR_STRING_DATA CMP_str_reasons[] = {
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_INVALID_ARGS), "invalid args"}, {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_INVALID_ARGS), "invalid args"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_KEY_INPUT_FOR_CREATING_PROTECTION), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_KEY_INPUT_FOR_CREATING_PROTECTION),
"missing key input for creating protection"}, "missing key input for creating protection"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_KEY_USAGE_DIGITALSIGNATURE),
"missing key usage digitalsignature"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_PRIVATE_KEY), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_PRIVATE_KEY),
"missing private key"}, "missing private key"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_PROTECTION), "missing protection"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_SENDER_IDENTIFICATION), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_SENDER_IDENTIFICATION),
"missing sender identification"}, "missing sender identification"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MISSING_TRUST_STORE),
"missing trust store"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MULTIPLE_SAN_SOURCES), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_MULTIPLE_SAN_SOURCES),
"multiple san sources"}, "multiple san sources"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_NO_STDIO), "no stdio"}, {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_NO_STDIO), "no stdio"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_NO_SUITABLE_SENDER_CERT),
"no suitable sender cert"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_NULL_ARGUMENT), "null argument"}, {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_NULL_ARGUMENT), "null argument"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_PKIBODY_ERROR), "pkibody error"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_PKISTATUSINFO_NOT_FOUND), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_PKISTATUSINFO_NOT_FOUND),
"pkistatusinfo not found"}, "pkistatusinfo not found"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_POTENTIALLY_INVALID_CERTIFICATE), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_POTENTIALLY_INVALID_CERTIFICATE),
"potentially invalid certificate"}, "potentially invalid certificate"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_RECIPNONCE_UNMATCHED),
"recipnonce unmatched"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_REQUEST_NOT_ACCEPTED),
"request not accepted"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_SENDER_GENERALNAME_TYPE_NOT_SUPPORTED),
"sender generalname type not supported"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_SRVCERT_DOES_NOT_VALIDATE_MSG),
"srvcert does not validate msg"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_TRANSACTIONID_UNMATCHED),
"transactionid unmatched"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNEXPECTED_PKIBODY), "unexpected pkibody"}, {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNEXPECTED_PKIBODY), "unexpected pkibody"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNEXPECTED_PVNO), "unexpected pvno"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNKNOWN_ALGORITHM_ID), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNKNOWN_ALGORITHM_ID),
"unknown algorithm id"}, "unknown algorithm id"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNKNOWN_CERT_TYPE), "unknown cert type"}, {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNKNOWN_CERT_TYPE), "unknown cert type"},
@@ -77,8 +102,11 @@ static const ERR_STRING_DATA CMP_str_reasons[] = {
"unsupported algorithm"}, "unsupported algorithm"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNSUPPORTED_KEY_TYPE), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNSUPPORTED_KEY_TYPE),
"unsupported key type"}, "unsupported key type"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_UNSUPPORTED_PROTECTION_ALG_DHBASEDMAC),
"unsupported protection alg dhbasedmac"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_WRONG_ALGORITHM_OID), {ERR_PACK(ERR_LIB_CMP, 0, CMP_R_WRONG_ALGORITHM_OID),
"wrong algorithm oid"}, "wrong algorithm oid"},
{ERR_PACK(ERR_LIB_CMP, 0, CMP_R_WRONG_PBM_VALUE), "wrong pbm value"},
{0, NULL} {0, NULL}
}; };
+123 -46
View File
@@ -48,16 +48,23 @@ struct ossl_cmp_ctx_st {
void *http_cb_arg; /* allows to store optional argument to cb */ void *http_cb_arg; /* allows to store optional argument to cb */
/* server authentication */ /* server authentication */
int unprotectedErrors; /* accept neg. response with no/invalid protection */ /*
/* to cope with broken server */ * unprotectedErrors may be set as workaround for broken server responses:
* accept missing or invalid protection of regular error messages, negative
* certificate responses (ip/cp/kup), revocation responses (rp), and PKIConf
*/
int unprotectedErrors;
X509 *srvCert; /* certificate used to identify the server */ X509 *srvCert; /* certificate used to identify the server */
X509 *validatedSrvCert; /* caches any already validated server cert */ X509 *validatedSrvCert; /* caches any already validated server cert */
X509_NAME *expected_sender; /* expected sender in pkiheader of response */ X509_NAME *expected_sender; /* expected sender in pkiheader of response */
X509_STORE *trusted; /* trust store maybe w CRLs and cert verify callback */ X509_STORE *trusted; /* trust store maybe w CRLs and cert verify callback */
STACK_OF(X509) *untrusted_certs; /* untrusted (intermediate) certs */ STACK_OF(X509) *untrusted_certs; /* untrusted (intermediate) certs */
int ignore_keyusage; /* ignore key usage entry when validating certs */ int ignore_keyusage; /* ignore key usage entry when validating certs */
int permitTAInExtraCertsForIR; /* allow use of root certs in extracerts */ /*
/* when validating message protection; used for 3GPP-style E.7 */ * permitTAInExtraCertsForIR allows use of root certs in extracerts
* when validating message protection; this is used for 3GPP-style E.7
*/
int permitTAInExtraCertsForIR;
/* client authentication */ /* client authentication */
int unprotectedSend; /* send unprotected PKI messages */ int unprotectedSend; /* send unprotected PKI messages */
@@ -536,68 +543,108 @@ typedef struct ossl_cmp_pkibody_st {
OSSL_CMP_CERTREPMESSAGE *ip; /* 1 */ OSSL_CMP_CERTREPMESSAGE *ip; /* 1 */
OSSL_CRMF_MSGS *cr; /* 2 */ OSSL_CRMF_MSGS *cr; /* 2 */
OSSL_CMP_CERTREPMESSAGE *cp; /* 3 */ OSSL_CMP_CERTREPMESSAGE *cp; /* 3 */
/* p10cr [4] CertificationRequest, --imported from [PKCS10] */ /*-
/* * p10cr [4] CertificationRequest, --imported from [PKCS10]
*
* PKCS10_CERTIFICATIONREQUEST is effectively X509_REQ * PKCS10_CERTIFICATIONREQUEST is effectively X509_REQ
* so it is used directly * so it is used directly
*/ */
X509_REQ *p10cr; /* 4 */ X509_REQ *p10cr; /* 4 */
/* popdecc [5] POPODecKeyChallContent, --pop Challenge */ /*-
/* POPODecKeyChallContent ::= SEQUENCE OF Challenge */ * popdecc [5] POPODecKeyChallContent, --pop Challenge
*
* POPODecKeyChallContent ::= SEQUENCE OF Challenge
*/
OSSL_CMP_POPODECKEYCHALLCONTENT *popdecc; /* 5 */ OSSL_CMP_POPODECKEYCHALLCONTENT *popdecc; /* 5 */
/* popdecr [6] POPODecKeyRespContent, --pop Response */ /*-
/* POPODecKeyRespContent ::= SEQUENCE OF INTEGER */ * popdecr [6] POPODecKeyRespContent, --pop Response
*
* POPODecKeyRespContent ::= SEQUENCE OF INTEGER
*/
OSSL_CMP_POPODECKEYRESPCONTENT *popdecr; /* 6 */ OSSL_CMP_POPODECKEYRESPCONTENT *popdecr; /* 6 */
OSSL_CRMF_MSGS *kur; /* 7 */ OSSL_CRMF_MSGS *kur; /* 7 */
OSSL_CMP_CERTREPMESSAGE *kup; /* 8 */ OSSL_CMP_CERTREPMESSAGE *kup; /* 8 */
OSSL_CRMF_MSGS *krr; /* 9 */ OSSL_CRMF_MSGS *krr; /* 9 */
/* krp [10] KeyRecRepContent, --Key Recovery Response */ /*-
* krp [10] KeyRecRepContent, --Key Recovery Response
*/
OSSL_CMP_KEYRECREPCONTENT *krp; /* 10 */ OSSL_CMP_KEYRECREPCONTENT *krp; /* 10 */
/* rr [11] RevReqContent, --Revocation Request */ /*-
* rr [11] RevReqContent, --Revocation Request
*/
OSSL_CMP_REVREQCONTENT *rr; /* 11 */ OSSL_CMP_REVREQCONTENT *rr; /* 11 */
/* rp [12] RevRepContent, --Revocation Response */ /*-
* rp [12] RevRepContent, --Revocation Response
*/
OSSL_CMP_REVREPCONTENT *rp; /* 12 */ OSSL_CMP_REVREPCONTENT *rp; /* 12 */
/* ccr [13] CertReqMessages, --Cross-Cert. Request */ /*-
* ccr [13] CertReqMessages, --Cross-Cert. Request
*/
OSSL_CRMF_MSGS *ccr; /* 13 */ OSSL_CRMF_MSGS *ccr; /* 13 */
/* ccp [14] CertRepMessage, --Cross-Cert. Response */ /*-
* ccp [14] CertRepMessage, --Cross-Cert. Response
*/
OSSL_CMP_CERTREPMESSAGE *ccp; /* 14 */ OSSL_CMP_CERTREPMESSAGE *ccp; /* 14 */
/* ckuann [15] CAKeyUpdAnnContent, --CA Key Update Ann. */ /*-
* ckuann [15] CAKeyUpdAnnContent, --CA Key Update Ann.
*/
OSSL_CMP_CAKEYUPDANNCONTENT *ckuann; /* 15 */ OSSL_CMP_CAKEYUPDANNCONTENT *ckuann; /* 15 */
/* cann [16] CertAnnContent, --Certificate Ann. */ /*-
/* OSSL_CMP_CMPCERTIFICATE is effectively X509 so it is used directly */ * cann [16] CertAnnContent, --Certificate Ann.
* OSSL_CMP_CMPCERTIFICATE is effectively X509 so it is used directly
*/
X509 *cann; /* 16 */ X509 *cann; /* 16 */
/* rann [17] RevAnnContent, --Revocation Ann. */ /*-
* rann [17] RevAnnContent, --Revocation Ann.
*/
OSSL_CMP_REVANNCONTENT *rann; /* 17 */ OSSL_CMP_REVANNCONTENT *rann; /* 17 */
/* crlann [18] CRLAnnContent, --CRL Announcement */ /*-
/* CRLAnnContent ::= SEQUENCE OF CertificateList */ * crlann [18] CRLAnnContent, --CRL Announcement
OSSL_CMP_CRLANNCONTENT *crlann; * CRLAnnContent ::= SEQUENCE OF CertificateList
/* PKIConfirmContent ::= NULL */ */
/* pkiconf [19] PKIConfirmContent, --Confirmation */ OSSL_CMP_CRLANNCONTENT *crlann; /* 18 */
/* OSSL_CMP_PKICONFIRMCONTENT would be only a typedef of ASN1_NULL */ /*-
/* OSSL_CMP_CONFIRMCONTENT *pkiconf; */ * PKIConfirmContent ::= NULL
/* * pkiconf [19] PKIConfirmContent, --Confirmation
* OSSL_CMP_PKICONFIRMCONTENT would be only a typedef of ASN1_NULL
* OSSL_CMP_CONFIRMCONTENT *pkiconf;
*
* NOTE: this should ASN1_NULL according to the RFC * NOTE: this should ASN1_NULL according to the RFC
* but there might be a struct in it when sent from faulty servers... * but there might be a struct in it when sent from faulty servers...
*/ */
ASN1_TYPE *pkiconf; /* 19 */ ASN1_TYPE *pkiconf; /* 19 */
/* nested [20] NestedMessageContent, --Nested Message */ /*-
/* NestedMessageContent ::= PKIMessages */ * nested [20] NestedMessageContent, --Nested Message
* NestedMessageContent ::= PKIMessages
*/
OSSL_CMP_MSGS *nested; /* 20 */ OSSL_CMP_MSGS *nested; /* 20 */
/* genm [21] GenMsgContent, --General Message */ /*-
/* GenMsgContent ::= SEQUENCE OF InfoTypeAndValue */ * genm [21] GenMsgContent, --General Message
* GenMsgContent ::= SEQUENCE OF InfoTypeAndValue
*/
OSSL_CMP_GENMSGCONTENT *genm; /* 21 */ OSSL_CMP_GENMSGCONTENT *genm; /* 21 */
/* genp [22] GenRepContent, --General Response */ /*-
/* GenRepContent ::= SEQUENCE OF InfoTypeAndValue */ * genp [22] GenRepContent, --General Response
* GenRepContent ::= SEQUENCE OF InfoTypeAndValue
*/
OSSL_CMP_GENREPCONTENT *genp; /* 22 */ OSSL_CMP_GENREPCONTENT *genp; /* 22 */
/* error [23] ErrorMsgContent, --Error Message */ /*-
* error [23] ErrorMsgContent, --Error Message
*/
OSSL_CMP_ERRORMSGCONTENT *error; /* 23 */ OSSL_CMP_ERRORMSGCONTENT *error; /* 23 */
/* certConf [24] CertConfirmContent, --Certificate confirm */ /*-
* certConf [24] CertConfirmContent, --Certificate confirm
*/
OSSL_CMP_CERTCONFIRMCONTENT *certConf; /* 24 */ OSSL_CMP_CERTCONFIRMCONTENT *certConf; /* 24 */
/* pollReq [25] PollReqContent, --Polling request */ /*-
OSSL_CMP_POLLREQCONTENT *pollReq; * pollReq [25] PollReqContent, --Polling request
/* pollRep [26] PollRepContent --Polling response */ */
OSSL_CMP_POLLREPCONTENT *pollRep; OSSL_CMP_POLLREQCONTENT *pollReq; /* 25 */
/*-
* pollRep [26] PollRepContent --Polling response
*/
OSSL_CMP_POLLREPCONTENT *pollRep; /* 26 */
} value; } value;
} OSSL_CMP_PKIBODY; } OSSL_CMP_PKIBODY;
DECLARE_ASN1_FUNCTIONS(OSSL_CMP_PKIBODY) DECLARE_ASN1_FUNCTIONS(OSSL_CMP_PKIBODY)
@@ -699,18 +746,15 @@ int ossl_cmp_asn1_get_int(const ASN1_INTEGER *a);
const char *ossl_cmp_log_parse_metadata(const char *buf, const char *ossl_cmp_log_parse_metadata(const char *buf,
OSSL_CMP_severity *level, char **func, OSSL_CMP_severity *level, char **func,
char **file, int *line); char **file, int *line);
/* workaround for 4096 bytes limitation of ERR_print_errors_cb() */ # define ossl_cmp_add_error_data(txt) ERR_add_error_txt(" : ", txt)
void ossl_cmp_add_error_txt(const char *separator, const char *txt); # define ossl_cmp_add_error_line(txt) ERR_add_error_txt("\n", txt)
# define ossl_cmp_add_error_data(txt) ossl_cmp_add_error_txt(" : ", txt)
# define ossl_cmp_add_error_line(txt) ossl_cmp_add_error_txt("\n", txt)
/* functions manipulating lists of certificates etc could be generally useful */ /* functions manipulating lists of certificates etc could be generally useful */
int ossl_cmp_sk_X509_add1_cert(STACK_OF(X509) *sk, X509 *cert, int ossl_cmp_sk_X509_add1_cert(STACK_OF(X509) *sk, X509 *cert,
int no_dup, int prepend); int no_dup, int prepend);
int ossl_cmp_sk_X509_add1_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs, int ossl_cmp_sk_X509_add1_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs,
int no_self_signed, int no_dups, int prepend); int no_self_issued, int no_dups, int prepend);
int ossl_cmp_X509_STORE_add1_certs(X509_STORE *store, STACK_OF(X509) *certs, int ossl_cmp_X509_STORE_add1_certs(X509_STORE *store, STACK_OF(X509) *certs,
int only_self_signed); int only_self_issued);
STACK_OF(X509) *ossl_cmp_X509_STORE_get1_certs(X509_STORE *store);
int ossl_cmp_asn1_octet_string_set1(ASN1_OCTET_STRING **tgt, int ossl_cmp_asn1_octet_string_set1(ASN1_OCTET_STRING **tgt,
const ASN1_OCTET_STRING *src); const ASN1_OCTET_STRING *src);
int ossl_cmp_asn1_octet_string_set1_bytes(ASN1_OCTET_STRING **tgt, int ossl_cmp_asn1_octet_string_set1_bytes(ASN1_OCTET_STRING **tgt,
@@ -718,6 +762,31 @@ int ossl_cmp_asn1_octet_string_set1_bytes(ASN1_OCTET_STRING **tgt,
STACK_OF(X509) *ossl_cmp_build_cert_chain(STACK_OF(X509) *certs, X509 *cert); STACK_OF(X509) *ossl_cmp_build_cert_chain(STACK_OF(X509) *certs, X509 *cert);
/* from cmp_ctx.c */ /* from cmp_ctx.c */
int ossl_cmp_print_log(OSSL_CMP_severity level, const OSSL_CMP_CTX *ctx,
const char *func, const char *file, int line,
const char *level_str, const char *format, ...);
# define ossl_cmp_log(level, ctx, msg) \
ossl_cmp_print_log(OSSL_CMP_LOG_##level, ctx, OPENSSL_FUNC, OPENSSL_FILE, \
OPENSSL_LINE, #level, "%s", msg)
# define ossl_cmp_log1(level, ctx, fmt, arg1) \
ossl_cmp_print_log(OSSL_CMP_LOG_##level, ctx, OPENSSL_FUNC, OPENSSL_FILE, \
OPENSSL_LINE, #level, fmt, arg1)
# define ossl_cmp_log2(level, ctx, fmt, arg1, arg2) \
ossl_cmp_print_log(OSSL_CMP_LOG_##level, ctx, OPENSSL_FUNC, OPENSSL_FILE, \
OPENSSL_LINE, #level, fmt, arg1, arg2)
# define ossl_cmp_log3(level, ctx, fmt, arg1, arg2, arg3) \
ossl_cmp_print_log(OSSL_CMP_LOG_##level, ctx, OPENSSL_FUNC, OPENSSL_FILE, \
OPENSSL_LINE, #level, fmt, arg1, arg2, arg3)
# define ossl_cmp_log4(level, ctx, fmt, arg1, arg2, arg3, arg4) \
ossl_cmp_print_log(OSSL_CMP_LOG_##level, ctx, OPENSSL_FUNC, OPENSSL_FILE, \
OPENSSL_LINE, #level, fmt, arg1, arg2, arg3, arg4)
# define OSSL_CMP_LOG_ERROR OSSL_CMP_LOG_ERR
# define OSSL_CMP_LOG_WARN OSSL_CMP_LOG_WARNING
# define ossl_cmp_alert(ctx, msg) ossl_cmp_log(ALERT, ctx, msg)
# define ossl_cmp_err(ctx, msg) ossl_cmp_log(ERROR, ctx, msg)
# define ossl_cmp_warn(ctx, msg) ossl_cmp_log(WARN, ctx, msg)
# define ossl_cmp_info(ctx, msg) ossl_cmp_log(INFO, ctx, msg)
# define ossl_cmp_debug(ctx, msg) ossl_cmp_log(DEBUG, ctx, msg)
int ossl_cmp_ctx_set0_validatedSrvCert(OSSL_CMP_CTX *ctx, X509 *cert); int ossl_cmp_ctx_set0_validatedSrvCert(OSSL_CMP_CTX *ctx, X509 *cert);
int ossl_cmp_ctx_set_status(OSSL_CMP_CTX *ctx, int status); int ossl_cmp_ctx_set_status(OSSL_CMP_CTX *ctx, int status);
int ossl_cmp_ctx_set0_statusString(OSSL_CMP_CTX *ctx, int ossl_cmp_ctx_set0_statusString(OSSL_CMP_CTX *ctx,
@@ -848,4 +917,12 @@ ASN1_BIT_STRING *ossl_cmp_calc_protection(const OSSL_CMP_MSG *msg,
int ossl_cmp_msg_add_extraCerts(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg); int ossl_cmp_msg_add_extraCerts(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg);
int ossl_cmp_msg_protect(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg); int ossl_cmp_msg_protect(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg);
/* from cmp_vfy.c */
typedef int (*ossl_cmp_allow_unprotected_cb_t)(const OSSL_CMP_CTX *ctx,
const OSSL_CMP_MSG *msg,
int invalid_protection, int arg);
int ossl_cmp_msg_check_received(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
ossl_cmp_allow_unprotected_cb_t cb, int cb_arg);
int ossl_cmp_verify_popo(const OSSL_CMP_MSG *msg, int accept_RAVerified);
#endif /* !defined OSSL_CRYPTO_CMP_LOCAL_H */ #endif /* !defined OSSL_CRYPTO_CMP_LOCAL_H */
+1 -1
View File
@@ -156,7 +156,7 @@ int ossl_cmp_msg_add_extraCerts(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg)
STACK_OF(X509) *chain = STACK_OF(X509) *chain =
ossl_cmp_build_cert_chain(ctx->untrusted_certs, ctx->clCert); ossl_cmp_build_cert_chain(ctx->untrusted_certs, ctx->clCert);
int res = ossl_cmp_sk_X509_add1_certs(msg->extraCerts, chain, int res = ossl_cmp_sk_X509_add1_certs(msg->extraCerts, chain,
1 /* no self-signed */, 1 /* no self-issued */,
1 /* no duplicates */, 0); 1 /* no duplicates */, 0);
sk_X509_pop_free(chain, X509_free); sk_X509_pop_free(chain, X509_free);
if (res == 0) if (res == 0)
+1 -1
View File
@@ -61,7 +61,7 @@ const char *ossl_cmp_PKIStatus_to_string(int status)
char buf[40]; char buf[40];
BIO_snprintf(buf, sizeof(buf), "PKIStatus: invalid=%d", status); BIO_snprintf(buf, sizeof(buf), "PKIStatus: invalid=%d", status);
CMPerr(0, CMP_R_ERROR_PARSING_PKISTATUS); CMPerr(0, CMP_R_ERROR_PARSING_PKISTATUS);
ossl_cmp_add_error_data(buf); ERR_add_error_data(1, buf);
return NULL; return NULL;
} }
} }
+54 -139
View File
@@ -69,7 +69,8 @@ static OSSL_CMP_severity parse_level(const char *level)
} }
const char *ossl_cmp_log_parse_metadata(const char *buf, const char *ossl_cmp_log_parse_metadata(const char *buf,
OSSL_CMP_severity *level, char **func, char **file, int *line) OSSL_CMP_severity *level,
char **func, char **file, int *line)
{ {
const char *p_func = buf; const char *p_func = buf;
const char *p_file = buf == NULL ? NULL : strchr(buf, ':'); const char *p_file = buf == NULL ? NULL : strchr(buf, ':');
@@ -106,131 +107,77 @@ const char *ossl_cmp_log_parse_metadata(const char *buf,
return msg; return msg;
} }
#define UNKNOWN_FUNC "(unknown function)" /* the default for OPENSSL_FUNC */
/* /*
* auxiliary function for incrementally reporting texts via the error queue * substitute fallback if component/function name is NULL or empty or contains
* just pseudo-information "(unknown function)" due to -pedantic and macros.h
*/ */
static void put_error(int lib, const char *func, int reason, static const char *improve_location_name(const char *func, const char *fallback)
const char *file, int line)
{ {
ERR_new(); if (!ossl_assert(fallback != NULL))
ERR_set_debug(file, line, func); return NULL;
ERR_set_error(lib, reason, NULL /* no data here, so fmt is NULL */); return func == NULL || *func == '\0' || strcmp(func, UNKNOWN_FUNC) == 0
? fallback : func;
} }
#define ERR_print_errors_cb_LIMIT 4096 /* size of char buf[] variable there */ int OSSL_CMP_print_to_bio(BIO *bio, const char *component, const char *file,
#define TYPICAL_MAX_OUTPUT_BEFORE_DATA 100 int line, OSSL_CMP_severity level, const char *msg)
#define MAX_DATA_LEN (ERR_print_errors_cb_LIMIT-TYPICAL_MAX_OUTPUT_BEFORE_DATA)
void ossl_cmp_add_error_txt(const char *separator, const char *txt)
{ {
const char *file = NULL; const char *level_string =
int line; level == OSSL_CMP_LOG_EMERG ? "EMERG" :
const char *func = NULL; level == OSSL_CMP_LOG_ALERT ? "ALERT" :
const char *data = NULL; level == OSSL_CMP_LOG_CRIT ? "CRIT" :
int flags; level == OSSL_CMP_LOG_ERR ? "error" :
unsigned long err = ERR_peek_last_error(); level == OSSL_CMP_LOG_WARNING ? "warning" :
level == OSSL_CMP_LOG_NOTICE ? "NOTE" :
level == OSSL_CMP_LOG_INFO ? "info" :
level == OSSL_CMP_LOG_DEBUG ? "DEBUG" : "(unknown level)";
if (separator == NULL) #ifndef NDEBUG
separator = ""; if (BIO_printf(bio, "%s:%s:%d:", improve_location_name(component, "CMP"),
if (err == 0) file, line) < 0)
put_error(ERR_LIB_CMP, NULL, 0, "", 0); return 0;
#endif
do { return BIO_printf(bio, OSSL_CMP_LOG_PREFIX"%s: %s\n",
size_t available_len, data_len; level_string, msg) >= 0;
const char *curr = txt, *next = txt;
char *tmp;
ERR_peek_last_error_all(&file, &line, &func, &data, &flags);
if ((flags & ERR_TXT_STRING) == 0) {
data = "";
separator = "";
}
data_len = strlen(data);
/* workaround for limit of ERR_print_errors_cb() */
if (data_len >= MAX_DATA_LEN
|| strlen(separator) >= (size_t)(MAX_DATA_LEN - data_len))
available_len = 0;
else
available_len = MAX_DATA_LEN - data_len - strlen(separator) - 1;
/* MAX_DATA_LEN > available_len >= 0 */
if (separator[0] == '\0') {
const size_t len_next = strlen(next);
if (len_next <= available_len) {
next += len_next;
curr = NULL; /* no need to split */
}
else {
next += available_len;
curr = next; /* will split at this point */
}
} else {
while (*next != '\0' && (size_t)(next - txt) <= available_len) {
curr = next;
next = strstr(curr, separator);
if (next != NULL)
next += strlen(separator);
else
next = curr + strlen(curr);
}
if ((size_t)(next - txt) <= available_len)
curr = NULL; /* the above loop implies *next == '\0' */
}
if (curr != NULL) {
/* split error msg at curr since error data would get too long */
if (curr != txt) {
tmp = OPENSSL_strndup(txt, curr - txt);
if (tmp == NULL)
return;
ERR_add_error_data(2, separator, tmp);
OPENSSL_free(tmp);
}
put_error(ERR_LIB_CMP, func, err, file, line);
txt = curr;
} else {
ERR_add_error_data(2, separator, txt);
txt = next; /* finished */
}
} while (*txt != '\0');
} }
#define ERR_PRINT_BUF_SIZE 4096
/* this is similar to ERR_print_errors_cb, but uses the CMP-specific cb type */ /* this is similar to ERR_print_errors_cb, but uses the CMP-specific cb type */
void OSSL_CMP_print_errors_cb(OSSL_cmp_log_cb_t log_fn) void OSSL_CMP_print_errors_cb(OSSL_cmp_log_cb_t log_fn)
{ {
unsigned long err; unsigned long err;
char msg[ERR_print_errors_cb_LIMIT]; char msg[ERR_PRINT_BUF_SIZE];
const char *file = NULL, *func = NULL, *data = NULL; const char *file = NULL, *func = NULL, *data = NULL;
int line, flags; int line, flags;
if (log_fn == NULL) {
#ifndef OPENSSL_NO_STDIO
ERR_print_errors_fp(stderr);
#else
/* CMPerr(0, CMP_R_NO_STDIO) makes no sense during error printing */
#endif
return;
}
while ((err = ERR_get_error_all(&file, &line, &func, &data, &flags)) != 0) { while ((err = ERR_get_error_all(&file, &line, &func, &data, &flags)) != 0) {
char component[128]; const char *component =
const char *func_ = func != NULL && *func != '\0' ? func : "<unknown>"; improve_location_name(func, ERR_lib_error_string(err));
if (!(flags & ERR_TXT_STRING)) if (!(flags & ERR_TXT_STRING))
data = NULL; data = NULL;
#ifdef OSSL_CMP_PRINT_LIBINFO
BIO_snprintf(component, sizeof(component), "OpenSSL:%s:%s",
ERR_lib_error_string(err), func_);
#else
BIO_snprintf(component, sizeof(component), "%s",func_);
#endif
BIO_snprintf(msg, sizeof(msg), "%s%s%s", ERR_reason_error_string(err), BIO_snprintf(msg, sizeof(msg), "%s%s%s", ERR_reason_error_string(err),
data == NULL ? "" : " : ", data == NULL ? "" : data); data == NULL || *data == '\0' ? "" : " : ",
data == NULL ? "" : data);
if (log_fn == NULL) {
#ifndef OPENSSL_NO_STDIO
BIO *bio = BIO_new_fp(stderr, BIO_NOCLOSE);
if (bio != NULL) {
OSSL_CMP_print_to_bio(bio, component, file, line,
OSSL_CMP_LOG_ERR, msg);
BIO_free(bio);
}
#else
/* CMPerr(0, CMP_R_NO_STDIO) makes no sense during error printing */
#endif
} else {
if (log_fn(component, file, line, OSSL_CMP_LOG_ERR, msg) <= 0) if (log_fn(component, file, line, OSSL_CMP_LOG_ERR, msg) <= 0)
break; /* abort outputting the error report */ break; /* abort outputting the error report */
} }
} }
}
/* /*
* functions manipulating lists of certificates etc. * functions manipulating lists of certificates etc.
@@ -266,7 +213,7 @@ int ossl_cmp_sk_X509_add1_cert(STACK_OF(X509) *sk, X509 *cert,
} }
int ossl_cmp_sk_X509_add1_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs, int ossl_cmp_sk_X509_add1_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs,
int no_self_signed, int no_dups, int prepend) int no_self_issued, int no_dups, int prepend)
/* compiler would allow 'const' for the list of certs, yet they are up-ref'ed */ /* compiler would allow 'const' for the list of certs, yet they are up-ref'ed */
{ {
int i; int i;
@@ -278,7 +225,7 @@ int ossl_cmp_sk_X509_add1_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs,
for (i = 0; i < sk_X509_num(certs); i++) { /* certs may be NULL */ for (i = 0; i < sk_X509_num(certs); i++) { /* certs may be NULL */
X509 *cert = sk_X509_value(certs, i); X509 *cert = sk_X509_value(certs, i);
if (!no_self_signed || X509_check_issued(cert, cert) != X509_V_OK) { if (!no_self_issued || X509_check_issued(cert, cert) != X509_V_OK) {
if (!ossl_cmp_sk_X509_add1_cert(sk, cert, no_dups, prepend)) if (!ossl_cmp_sk_X509_add1_cert(sk, cert, no_dups, prepend))
return 0; return 0;
} }
@@ -287,7 +234,7 @@ int ossl_cmp_sk_X509_add1_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs,
} }
int ossl_cmp_X509_STORE_add1_certs(X509_STORE *store, STACK_OF(X509) *certs, int ossl_cmp_X509_STORE_add1_certs(X509_STORE *store, STACK_OF(X509) *certs,
int only_self_signed) int only_self_issued)
{ {
int i; int i;
@@ -300,45 +247,13 @@ int ossl_cmp_X509_STORE_add1_certs(X509_STORE *store, STACK_OF(X509) *certs,
for (i = 0; i < sk_X509_num(certs); i++) { for (i = 0; i < sk_X509_num(certs); i++) {
X509 *cert = sk_X509_value(certs, i); X509 *cert = sk_X509_value(certs, i);
if (!only_self_signed || X509_check_issued(cert, cert) == X509_V_OK) if (!only_self_issued || X509_check_issued(cert, cert) == X509_V_OK)
if (!X509_STORE_add_cert(store, cert)) /* ups cert ref counter */ if (!X509_STORE_add_cert(store, cert)) /* ups cert ref counter */
return 0; return 0;
} }
return 1; return 1;
} }
STACK_OF(X509) *ossl_cmp_X509_STORE_get1_certs(X509_STORE *store)
{
int i;
STACK_OF(X509) *sk;
STACK_OF(X509_OBJECT) *objs;
if (store == NULL) {
CMPerr(0, CMP_R_NULL_ARGUMENT);
return 0;
}
if ((sk = sk_X509_new_null()) == NULL)
return NULL;
objs = X509_STORE_get0_objects(store);
for (i = 0; i < sk_X509_OBJECT_num(objs); i++) {
X509 *cert = X509_OBJECT_get0_X509(sk_X509_OBJECT_value(objs, i));
if (cert != NULL) {
if (!sk_X509_push(sk, cert))
goto err;
if (!X509_up_ref(cert)) {
(void)sk_X509_pop(sk);
goto err;
}
}
}
return sk;
err:
sk_X509_pop_free(sk, X509_free);
return NULL;
}
/*- /*-
* Builds up the certificate chain of certs as high up as possible using * Builds up the certificate chain of certs as high up as possible using
* the given list of certs containing all possible intermediate certificates and * the given list of certs containing all possible intermediate certificates and
@@ -390,10 +305,10 @@ STACK_OF(X509) *ossl_cmp_build_cert_chain(STACK_OF(X509) *certs, X509 *cert)
chain = X509_STORE_CTX_get0_chain(csc); chain = X509_STORE_CTX_get0_chain(csc);
/* result list to store the up_ref'ed not self-signed certificates */ /* result list to store the up_ref'ed not self-issued certificates */
if ((result = sk_X509_new_null()) == NULL) if ((result = sk_X509_new_null()) == NULL)
goto err; goto err;
if (!ossl_cmp_sk_X509_add1_certs(result, chain, 1 /* no self-signed */, if (!ossl_cmp_sk_X509_add1_certs(result, chain, 1 /* no self-issued */,
1 /* no duplicates */, 0)) { 1 /* no duplicates */, 0)) {
sk_X509_free(result); sk_X509_free(result);
result = NULL; result = NULL;
+754
View File
@@ -0,0 +1,754 @@
/*
* Copyright 2007-2020 The OpenSSL Project Authors. All Rights Reserved.
* Copyright Nokia 2007-2020
* Copyright Siemens AG 2015-2020
*
* Licensed under the Apache License 2.0 (the "License"). You may not use
* this file except in compliance with the License. You can obtain a copy
* in the file LICENSE in the source distribution or at
* https://www.openssl.org/source/license.html
*/
/* CMP functions for PKIMessage checking */
#include "cmp_local.h"
#include <openssl/cmp_util.h>
/* explicit #includes not strictly needed since implied by the above: */
#include <openssl/asn1t.h>
#include <openssl/cmp.h>
#include <openssl/crmf.h>
#include <openssl/err.h>
#include <openssl/x509.h>
#include "crypto/x509.h"
/*
* Verify a message protected by signature according to section 5.1.3.3
* (sha1+RSA/DSA or any other algorithm supported by OpenSSL).
*
* Returns 1 on successful validation and 0 otherwise.
*/
static int verify_signature(const OSSL_CMP_CTX *cmp_ctx,
const OSSL_CMP_MSG *msg, X509 *cert)
{
EVP_MD_CTX *ctx = NULL;
CMP_PROTECTEDPART prot_part;
int digest_nid, pk_nid;
const EVP_MD *digest = NULL;
EVP_PKEY *pubkey = NULL;
int len;
size_t prot_part_der_len = 0;
unsigned char *prot_part_der = NULL;
BIO *bio = BIO_new(BIO_s_mem()); /* may be NULL */
int res = 0;
if (!ossl_assert(cmp_ctx != NULL && msg != NULL && cert != NULL))
return 0;
/* verify that keyUsage, if present, contains digitalSignature */
if (!cmp_ctx->ignore_keyusage
&& (X509_get_key_usage(cert) & X509v3_KU_DIGITAL_SIGNATURE) == 0) {
CMPerr(0, CMP_R_MISSING_KEY_USAGE_DIGITALSIGNATURE);
goto sig_err;
}
pubkey = X509_get_pubkey(cert);
if (pubkey == NULL) {
CMPerr(0, CMP_R_FAILED_EXTRACTING_PUBKEY);
goto sig_err;
}
/* create the DER representation of protected part */
prot_part.header = msg->header;
prot_part.body = msg->body;
len = i2d_CMP_PROTECTEDPART(&prot_part, &prot_part_der);
if (len < 0 || prot_part_der == NULL)
goto end;
prot_part_der_len = (size_t) len;
/* verify signature of protected part */
if (!OBJ_find_sigid_algs(OBJ_obj2nid(msg->header->protectionAlg->algorithm),
&digest_nid, &pk_nid)
|| digest_nid == NID_undef || pk_nid == NID_undef
|| (digest = EVP_get_digestbynid(digest_nid)) == NULL) {
CMPerr(0, CMP_R_ALGORITHM_NOT_SUPPORTED);
goto sig_err;
}
/* check msg->header->protectionAlg is consistent with public key type */
if (EVP_PKEY_type(pk_nid) != EVP_PKEY_base_id(pubkey)) {
CMPerr(0, CMP_R_WRONG_ALGORITHM_OID);
goto sig_err;
}
if ((ctx = EVP_MD_CTX_new()) == NULL)
goto end;
if (EVP_DigestVerifyInit(ctx, NULL, digest, NULL, pubkey)
&& EVP_DigestVerify(ctx, msg->protection->data,
msg->protection->length,
prot_part_der, prot_part_der_len) == 1) {
res = 1;
goto end;
}
sig_err:
res = x509_print_ex_brief(bio, cert, X509_FLAG_NO_EXTENSIONS);
CMPerr(0, CMP_R_ERROR_VALIDATING_PROTECTION);
if (res)
ERR_add_error_mem_bio("\n", bio);
res = 0;
end:
EVP_MD_CTX_free(ctx);
OPENSSL_free(prot_part_der);
EVP_PKEY_free(pubkey);
BIO_free(bio);
return res;
}
/* Verify a message protected with PBMAC */
static int verify_PBMAC(const OSSL_CMP_MSG *msg,
const ASN1_OCTET_STRING *secret)
{
ASN1_BIT_STRING *protection = NULL;
int valid = 0;
/* generate expected protection for the message */
if ((protection = ossl_cmp_calc_protection(msg, secret, NULL)) == NULL)
return 0; /* failed to generate protection string! */
valid = msg->protection != NULL && msg->protection->length >= 0
&& msg->protection->type == protection->type
&& msg->protection->length == protection->length
&& CRYPTO_memcmp(msg->protection->data, protection->data,
protection->length) == 0;
ASN1_BIT_STRING_free(protection);
if (!valid)
CMPerr(0, CMP_R_WRONG_PBM_VALUE);
return valid;
}
/*
* Attempt to validate certificate and path using any given store with trusted
* certs (possibly including CRLs and a cert verification callback function)
* and non-trusted intermediate certs from the given ctx.
*
* Returns 1 on successful validation and 0 otherwise.
*/
int OSSL_CMP_validate_cert_path(OSSL_CMP_CTX *ctx, X509_STORE *trusted_store,
X509 *cert)
{
int valid = 0;
X509_STORE_CTX *csc = NULL;
int err;
if (ctx == NULL || cert == NULL) {
CMPerr(0, CMP_R_NULL_ARGUMENT);
return 0;
}
if (trusted_store == NULL) {
CMPerr(0, CMP_R_MISSING_TRUST_STORE);
return 0;
}
if ((csc = X509_STORE_CTX_new()) == NULL
|| !X509_STORE_CTX_init(csc, trusted_store,
cert, ctx->untrusted_certs))
goto err;
valid = X509_verify_cert(csc) > 0;
/* make sure suitable error is queued even if callback did not do */
err = ERR_peek_last_error();
if (!valid && ERR_GET_REASON(err) != CMP_R_POTENTIALLY_INVALID_CERTIFICATE)
CMPerr(0, CMP_R_POTENTIALLY_INVALID_CERTIFICATE);
err:
X509_STORE_CTX_free(csc);
return valid;
}
/* Return 0 if expect_name != NULL and there is no matching actual_name */
static int check_name(OSSL_CMP_CTX *ctx,
const char *actual_desc, const X509_NAME *actual_name,
const char *expect_desc, const X509_NAME *expect_name)
{
char *str;
if (expect_name == NULL)
return 1; /* no expectation, thus trivially fulfilled */
/* make sure that a matching name is there */
if (actual_name == NULL) {
ossl_cmp_log1(WARN, ctx, "missing %s", actual_desc);
return 0;
}
if (X509_NAME_cmp(actual_name, expect_name) == 0)
return 1;
if ((str = X509_NAME_oneline(actual_name, NULL, 0)) != NULL)
ossl_cmp_log2(INFO, ctx, " actual name in %s = %s", actual_desc, str);
OPENSSL_free(str);
if ((str = X509_NAME_oneline(expect_name, NULL, 0)) != NULL)
ossl_cmp_log2(INFO, ctx, " does not match %s = %s", expect_desc, str);
OPENSSL_free(str);
return 0;
}
/* Return 0 if skid != NULL and there is no matching subject key ID in cert */
static int check_kid(OSSL_CMP_CTX *ctx,
X509 *cert, const ASN1_OCTET_STRING *skid)
{
char *actual, *expect;
const ASN1_OCTET_STRING *ckid = X509_get0_subject_key_id(cert);
if (skid == NULL)
return 1; /* no expectation, thus trivially fulfilled */
/* make sure that the expected subject key identifier is there */
if (ckid == NULL) {
ossl_cmp_warn(ctx, "missing Subject Key Identifier in certificate");
return 0;
}
if (ASN1_OCTET_STRING_cmp(ckid, skid) == 0)
return 1;
if ((actual = OPENSSL_buf2hexstr(ckid->data, ckid->length)) != NULL)
ossl_cmp_log1(INFO, ctx, " cert Subject Key Identifier = %s", actual);
if ((expect = OPENSSL_buf2hexstr(skid->data, skid->length)) != NULL)
ossl_cmp_log1(INFO, ctx, " does not match senderKID = %s", expect);
OPENSSL_free(expect);
OPENSSL_free(actual);
return 0;
}
static int already_checked(X509 *cert, const STACK_OF(X509) *already_checked)
{
int i;
for (i = sk_X509_num(already_checked /* may be NULL */); i > 0; i--)
if (X509_cmp(sk_X509_value(already_checked, i - 1), cert) == 0)
return 1;
return 0;
}
/*
* Check if the given cert is acceptable as sender cert of the given message.
* The subject DN must match, the subject key ID as well if present in the msg,
* and the cert must be current (checked if ctx->trusted is not NULL).
* Note that cert revocation etc. is checked by OSSL_CMP_validate_cert_path().
*
* Returns 0 on error or not acceptable, else 1.
*/
static int cert_acceptable(OSSL_CMP_CTX *ctx,
const char *desc1, const char *desc2, X509 *cert,
const STACK_OF(X509) *already_checked1,
const STACK_OF(X509) *already_checked2,
const OSSL_CMP_MSG *msg)
{
X509_STORE *ts = ctx->trusted;
char *sub, *iss;
X509_VERIFY_PARAM *vpm = ts != NULL ? X509_STORE_get0_param(ts) : NULL;
int time_cmp;
ossl_cmp_log2(INFO, ctx, " considering %s %s with..", desc1, desc2);
if ((sub = X509_NAME_oneline(X509_get_subject_name(cert), NULL, 0)) != NULL)
ossl_cmp_log1(INFO, ctx, " subject = %s", sub);
if ((iss = X509_NAME_oneline(X509_get_issuer_name(cert), NULL, 0)) != NULL)
ossl_cmp_log1(INFO, ctx, " issuer = %s", iss);
OPENSSL_free(iss);
OPENSSL_free(sub);
if (already_checked(cert, already_checked1)
|| already_checked(cert, already_checked2)) {
ossl_cmp_info(ctx, " cert has already been checked");
return 0;
}
time_cmp = X509_cmp_timeframe(vpm, X509_get0_notBefore(cert),
X509_get0_notAfter(cert));
if (time_cmp != 0) {
ossl_cmp_warn(ctx, time_cmp > 0 ? "cert has expired"
: "cert is not yet valid");
return 0;
}
if (!check_name(ctx,
"cert subject", X509_get_subject_name(cert),
"sender field", msg->header->sender->d.directoryName))
return 0;
if (!check_kid(ctx, cert, msg->header->senderKID))
return 0;
/* acceptable also if there is no senderKID in msg header */
ossl_cmp_info(ctx, " cert is acceptable");
return 1;
}
static int check_msg_valid_cert(OSSL_CMP_CTX *ctx, X509_STORE *store,
X509 *scrt, const OSSL_CMP_MSG *msg)
{
if (!verify_signature(ctx, msg, scrt)) {
ossl_cmp_warn(ctx, "msg signature verification failed");
return 0;
}
if (!OSSL_CMP_validate_cert_path(ctx, store, scrt)) {
ossl_cmp_warn(ctx, "cert path validation failed");
return 0;
}
return 1;
}
/*
* Exceptional handling for 3GPP TS 33.310 [3G/LTE Network Domain Security
* (NDS); Authentication Framework (AF)], only to use for IP and if the ctx
* option is explicitly set: use self-issued certificates from extraCerts as
* trust anchor to validate sender cert and msg -
* provided it also can validate the newly enrolled certificate
*/
static int check_msg_valid_cert_3gpp(OSSL_CMP_CTX *ctx, X509 *scrt,
const OSSL_CMP_MSG *msg)
{
int valid = 0;
X509_STORE *store = X509_STORE_new();
if (store != NULL /* store does not include CRLs */
&& ossl_cmp_X509_STORE_add1_certs(store, msg->extraCerts,
1 /* self-issued only */))
valid = check_msg_valid_cert(ctx, store, scrt, msg);
if (valid) {
/*
* verify that the newly enrolled certificate (which is assumed to have
* rid == 0) can also be validated with the same trusted store
*/
EVP_PKEY *privkey = OSSL_CMP_CTX_get0_newPkey(ctx, 1);
OSSL_CMP_CERTRESPONSE *crep =
ossl_cmp_certrepmessage_get0_certresponse(msg->body->value.ip, 0);
X509 *newcrt = ossl_cmp_certresponse_get1_certificate(privkey, crep);
/*
* maybe better use get_cert_status() from cmp_client.c, which catches
* errors
*/
valid = OSSL_CMP_validate_cert_path(ctx, store, newcrt);
X509_free(newcrt);
}
X509_STORE_free(store);
return valid;
}
/*
* Try all certs in given list for verifying msg, normally or in 3GPP mode.
* If already_checked1 == NULL then certs are assumed to be the msg->extraCerts.
*/
static int check_msg_with_certs(OSSL_CMP_CTX *ctx, STACK_OF(X509) *certs,
const char *desc,
const STACK_OF(X509) *already_checked1,
const STACK_OF(X509) *already_checked2,
const OSSL_CMP_MSG *msg, int mode_3gpp)
{
int in_extraCerts = already_checked1 == NULL;
int n_acceptable_certs = 0;
int i;
if (sk_X509_num(certs) <= 0) {
ossl_cmp_log1(WARN, ctx, "no %s", desc);
return 0;
}
for (i = 0; i < sk_X509_num(certs); i++) { /* certs may be NULL */
X509 *cert = sk_X509_value(certs, i);
if (!ossl_assert(cert != NULL))
return 0;
if (!cert_acceptable(ctx, "cert from", desc, cert,
already_checked1, already_checked2, msg))
continue;
n_acceptable_certs++;
if (mode_3gpp ? check_msg_valid_cert_3gpp(ctx, cert, msg)
: check_msg_valid_cert(ctx, ctx->trusted, cert, msg)) {
/* store successful sender cert for further msgs in transaction */
if (!X509_up_ref(cert))
return 0;
if (!ossl_cmp_ctx_set0_validatedSrvCert(ctx, cert)) {
X509_free(cert);
return 0;
}
return 1;
}
}
if (in_extraCerts && n_acceptable_certs == 0)
ossl_cmp_warn(ctx, "no acceptable cert in extraCerts");
return 0;
}
/*
* Verify msg trying first ctx->untrusted_certs, which should include extraCerts
* at its front, then trying the trusted certs in truststore (if any) of ctx.
*/
static int check_msg_all_certs(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
int mode_3gpp)
{
int ret = 0;
ossl_cmp_info(ctx,
mode_3gpp ? "failed; trying now 3GPP mode trusting extraCerts"
: "trying first normal mode using trust store");
if (check_msg_with_certs(ctx, msg->extraCerts, "extraCerts",
NULL, NULL, msg, mode_3gpp))
return 1;
if (check_msg_with_certs(ctx, ctx->untrusted_certs, "untrusted certs",
msg->extraCerts, NULL, msg, mode_3gpp))
return 1;
if (ctx->trusted == NULL) {
ossl_cmp_warn(ctx, mode_3gpp ? "no self-issued extraCerts"
: "no trusted store");
} else {
STACK_OF(X509) *trusted = X509_STORE_get1_all_certs(ctx->trusted);
ret = check_msg_with_certs(ctx, trusted,
mode_3gpp ? "self-issued extraCerts"
: "certs in trusted store",
msg->extraCerts, ctx->untrusted_certs,
msg, mode_3gpp);
sk_X509_pop_free(trusted, X509_free);
}
return ret;
}
/* verify message signature with any acceptable and valid candidate cert */
static int check_msg_find_cert(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg)
{
X509 *scrt = ctx->validatedSrvCert; /* previous successful sender cert */
GENERAL_NAME *sender = msg->header->sender;
char *sname = NULL;
char *skid_str = NULL;
const ASN1_OCTET_STRING *skid = msg->header->senderKID;
OSSL_cmp_log_cb_t backup_log_cb = ctx->log_cb;
int res = 0;
if (sender == NULL || msg->body == NULL)
return 0; /* other NULL cases already have been checked */
if (sender->type != GEN_DIRNAME) {
CMPerr(0, CMP_R_SENDER_GENERALNAME_TYPE_NOT_SUPPORTED);
return 0;
}
/*
* try first cached scrt, used successfully earlier in same transaction,
* for validating this and any further msgs where extraCerts may be left out
*/
(void)ERR_set_mark();
if (scrt != NULL
&& cert_acceptable(ctx, "previously validated", "sender cert", scrt,
NULL, NULL, msg)
&& (check_msg_valid_cert(ctx, ctx->trusted, scrt, msg)
|| check_msg_valid_cert_3gpp(ctx, scrt, msg))) {
(void)ERR_pop_to_mark();
return 1;
}
(void)ERR_pop_to_mark();
/* release any cached sender cert that proved no more successfully usable */
(void)ossl_cmp_ctx_set0_validatedSrvCert(ctx, NULL);
/* enable clearing irrelevant errors in attempts to validate sender certs */
(void)ERR_set_mark();
ctx->log_cb = NULL; /* temporarily disable logging diagnostic info */
if (check_msg_all_certs(ctx, msg, 0 /* using ctx->trusted */)
|| check_msg_all_certs(ctx, msg, 1 /* 3gpp */)) {
/* discard any diagnostic info on trying to use certs */
ctx->log_cb = backup_log_cb; /* restore any logging */
(void)ERR_pop_to_mark();
res = 1;
goto end;
}
/* failed finding a sender cert that verifies the message signature */
ctx->log_cb = backup_log_cb; /* restore any logging */
(void)ERR_clear_last_mark();
sname = X509_NAME_oneline(sender->d.directoryName, NULL, 0);
skid_str = skid == NULL ? NULL
: OPENSSL_buf2hexstr(skid->data, skid->length);
if (ctx->log_cb != NULL) {
ossl_cmp_info(ctx, "verifying msg signature with valid cert that..");
if (sname != NULL)
ossl_cmp_log1(INFO, ctx, "matches msg sender name = %s", sname);
if (skid_str != NULL)
ossl_cmp_log1(INFO, ctx, "matches msg senderKID = %s", skid_str);
else
ossl_cmp_info(ctx, "while msg header does not contain senderKID");
/* re-do the above checks (just) for adding diagnostic information */
check_msg_all_certs(ctx, msg, 0 /* using ctx->trusted */);
check_msg_all_certs(ctx, msg, 1 /* 3gpp */);
}
CMPerr(0, CMP_R_NO_SUITABLE_SENDER_CERT);
if (sname != NULL) {
ERR_add_error_txt(NULL, "for msg sender name = ");
ERR_add_error_txt(NULL, sname);
}
if (skid_str != NULL) {
ERR_add_error_txt(" and ", "for msg senderKID = ");
ERR_add_error_txt(NULL, skid_str);
}
end:
OPENSSL_free(sname);
OPENSSL_free(skid_str);
return res;
}
/*
* Validate the protection of the given PKIMessage using either password-
* based mac (PBM) or a signature algorithm. In the case of signature algorithm,
* the sender certificate can have been pinned by providing it in ctx->srvCert,
* else it is searched in msg->extraCerts, ctx->untrusted_certs, in ctx->trusted
* (in this order) and is path is validated against ctx->trusted.
*
* If ctx->permitTAInExtraCertsForIR is true and when validating a CMP IP msg,
* the trust anchor for validating the IP msg may be taken from msg->extraCerts
* if a self-issued certificate is found there that can be used to
* validate the enrolled certificate returned in the IP.
* This is according to the need given in 3GPP TS 33.310.
*
* Returns 1 on success, 0 on error or validation failed.
*/
int OSSL_CMP_validate_msg(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg)
{
X509_ALGOR *alg;
int nid = NID_undef, pk_nid = NID_undef;
const ASN1_OBJECT *algorOID = NULL;
X509 *scrt;
if (ctx == NULL || msg == NULL
|| msg->header == NULL || msg->body == NULL) {
CMPerr(0, CMP_R_NULL_ARGUMENT);
return 0;
}
if ((alg = msg->header->protectionAlg) == NULL /* unprotected message */
|| msg->protection == NULL || msg->protection->data == NULL) {
CMPerr(0, CMP_R_MISSING_PROTECTION);
return 0;
}
/* determine the nid for the used protection algorithm */
X509_ALGOR_get0(&algorOID, NULL, NULL, alg);
nid = OBJ_obj2nid(algorOID);
switch (nid) {
/* 5.1.3.1. Shared Secret Information */
case NID_id_PasswordBasedMAC:
if (verify_PBMAC(msg, ctx->secretValue)) {
/*
* RFC 4210, 5.3.2: 'Note that if the PKI Message Protection is
* "shared secret information", then any certificate transported in
* the caPubs field may be directly trusted as a root CA
* certificate by the initiator.'
*/
switch (ossl_cmp_msg_get_bodytype(msg)) {
case -1:
return 0;
case OSSL_CMP_PKIBODY_IP:
case OSSL_CMP_PKIBODY_CP:
case OSSL_CMP_PKIBODY_KUP:
case OSSL_CMP_PKIBODY_CCP:
if (ctx->trusted != NULL) {
STACK_OF(X509) *certs = msg->body->value.ip->caPubs;
/* value.ip is same for cp, kup, and ccp */
if (!ossl_cmp_X509_STORE_add1_certs(ctx->trusted, certs, 0))
/* adds both self-issued and not self-issued certs */
return 0;
}
break;
default:
break;
}
return 1;
}
break;
/*
* 5.1.3.2 DH Key Pairs
* Not yet supported
*/
case NID_id_DHBasedMac:
CMPerr(0, CMP_R_UNSUPPORTED_PROTECTION_ALG_DHBASEDMAC);
break;
/*
* 5.1.3.3. Signature
*/
default:
if (!OBJ_find_sigid_algs(OBJ_obj2nid(alg->algorithm), NULL, &pk_nid)
|| pk_nid == NID_undef) {
CMPerr(0, CMP_R_UNKNOWN_ALGORITHM_ID);
break;
}
/* validate sender name of received msg */
if (msg->header->sender->type != GEN_DIRNAME) {
CMPerr(0, CMP_R_SENDER_GENERALNAME_TYPE_NOT_SUPPORTED);
break; /* FR#42: support for more than X509_NAME */
}
/*
* Compare actual sender name of response with expected sender name.
* Expected name can be set explicitly or the subject of ctx->srvCert.
* Mitigates risk to accept misused certificate of an unauthorized
* entity of a trusted hierarchy.
*/
if (!check_name(ctx, "sender DN field",
msg->header->sender->d.directoryName,
"expected sender", ctx->expected_sender))
break;
/* Note: if recipient was NULL-DN it could be learned here if needed */
scrt = ctx->srvCert;
if (scrt == NULL) {
if (check_msg_find_cert(ctx, msg))
return 1;
} else { /* use pinned sender cert */
/* use ctx->srvCert for signature check even if not acceptable */
if (verify_signature(ctx, msg, scrt))
return 1;
/* call cert_acceptable() for adding diagnostic information */
(void)cert_acceptable(ctx, "explicitly set", "sender cert", scrt,
NULL, NULL, msg);
ossl_cmp_warn(ctx, "msg signature verification failed");
CMPerr(0, CMP_R_SRVCERT_DOES_NOT_VALIDATE_MSG);
}
break;
}
return 0;
}
/*-
* Check received message (i.e., response by server or request from client)
* Any msg->extraCerts are prepended to ctx->untrusted_certs
*
* Ensures that:
* it has a valid body type
* its protection is valid or absent (allowed only if callback function is
* present and function yields non-zero result using also supplied argument)
* its transaction ID matches the previous transaction ID stored in ctx (if any)
* its recipNonce matches the previous senderNonce stored in the ctx (if any)
*
* If everything is fine:
* learns the senderNonce from the received message,
* learns the transaction ID if it is not yet in ctx.
*
* returns body type (which is >= 0) of the message on success, -1 on error
*/
int ossl_cmp_msg_check_received(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
ossl_cmp_allow_unprotected_cb_t cb, int cb_arg)
{
int rcvd_type;
if (!ossl_assert(ctx != NULL && msg != NULL))
return -1;
if (sk_X509_num(msg->extraCerts) > 10)
ossl_cmp_warn(ctx,
"received CMP message contains more than 10 extraCerts");
/* validate message protection */
if (msg->header->protectionAlg != 0) {
/* detect explicitly permitted exceptions for invalid protection */
if (!OSSL_CMP_validate_msg(ctx, msg)
&& (cb == NULL || !(*cb)(ctx, msg, 1, cb_arg))) {
CMPerr(0, CMP_R_ERROR_VALIDATING_PROTECTION);
return -1;
}
} else {
/* detect explicitly permitted exceptions for missing protection */
if (cb == NULL || !(*cb)(ctx, msg, 0, cb_arg)) {
CMPerr(0, CMP_R_MISSING_PROTECTION);
return -1;
}
}
/*
* Store any provided extraCerts in ctx for future use,
* such that they are available to ctx->certConf_cb and
* the peer does not need to send them again in the same transaction.
* For efficiency, the extraCerts are prepended so they get used first.
*/
if (!ossl_cmp_sk_X509_add1_certs(ctx->untrusted_certs, msg->extraCerts,
0 /* this allows self-issued certs */,
1 /* no_dups */, 1 /* prepend */))
return -1;
/* check CMP version number in header */
if (ossl_cmp_hdr_get_pvno(OSSL_CMP_MSG_get0_header(msg)) != OSSL_CMP_PVNO) {
CMPerr(0, CMP_R_UNEXPECTED_PVNO);
return -1;
}
/* compare received transactionID with the expected one in previous msg */
if (ctx->transactionID != NULL
&& (msg->header->transactionID == NULL
|| ASN1_OCTET_STRING_cmp(ctx->transactionID,
msg->header->transactionID) != 0)) {
CMPerr(0, CMP_R_TRANSACTIONID_UNMATCHED);
return -1;
}
/* compare received nonce with the one we sent */
if (ctx->senderNonce != NULL
&& (msg->header->recipNonce == NULL
|| ASN1_OCTET_STRING_cmp(ctx->senderNonce,
msg->header->recipNonce) != 0)) {
CMPerr(0, CMP_R_RECIPNONCE_UNMATCHED);
return -1;
}
/*
* RFC 4210 section 5.1.1 states: the recipNonce is copied from
* the senderNonce of the previous message in the transaction.
* --> Store for setting in next message
*/
if (!ossl_cmp_ctx_set1_recipNonce(ctx, msg->header->senderNonce))
return -1;
/* if not yet present, learn transactionID */
if (ctx->transactionID == NULL
&& !OSSL_CMP_CTX_set1_transactionID(ctx, msg->header->transactionID))
return -1;
if ((rcvd_type = ossl_cmp_msg_get_bodytype(msg)) < 0) {
CMPerr(0, CMP_R_PKIBODY_ERROR);
return -1;
}
return rcvd_type;
}
int ossl_cmp_verify_popo(const OSSL_CMP_MSG *msg, int accept_RAVerified)
{
if (!ossl_assert(msg != NULL && msg->body != NULL))
return 0;
switch (msg->body->type) {
case OSSL_CMP_PKIBODY_P10CR:
{
X509_REQ *req = msg->body->value.p10cr;
if (X509_REQ_verify(req, X509_REQ_get0_pubkey(req)) > 0)
return 1;
CMPerr(0, CMP_R_REQUEST_NOT_ACCEPTED);
return 0;
}
case OSSL_CMP_PKIBODY_IR:
case OSSL_CMP_PKIBODY_CR:
case OSSL_CMP_PKIBODY_KUR:
return OSSL_CRMF_MSGS_verify_popo(msg->body->value.ir,
OSSL_CMP_CERTREQID,
accept_RAVerified);
default:
CMPerr(0, CMP_R_PKIBODY_ERROR);
return 0;
}
}

Some files were not shown because too many files have changed in this diff Show More