libidav/crypto.c

11 days ago

author
Olaf Wintermann <olaf.wintermann@gmail.com>
date
Tue, 01 Apr 2025 21:48:14 +0200 (11 days ago)
changeset 857
03982275f29b
parent 816
839fefbdedc7
permissions
-rw-r--r--

use newer openssl hashing functions to fix warnings

40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
1 /*
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
2 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
3 *
404
5c08b8e14df8 updates copyright notice
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 367
diff changeset
4 * Copyright 2018 Olaf Wintermann. All rights reserved.
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
5 *
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
6 * Redistribution and use in source and binary forms, with or without
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
7 * modification, are permitted provided that the following conditions are met:
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
8 *
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
9 * 1. Redistributions of source code must retain the above copyright
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
10 * notice, this list of conditions and the following disclaimer.
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
11 *
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
12 * 2. Redistributions in binary form must reproduce the above copyright
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
13 * notice, this list of conditions and the following disclaimer in the
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
14 * documentation and/or other materials provided with the distribution.
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
15 *
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
16 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
17 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
19 * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
20 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
21 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
22 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
23 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
24 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
25 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
26 * POSSIBILITY OF SUCH DAMAGE.
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
27 */
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
28
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
29 #include <stdio.h>
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
30 #include <stdlib.h>
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
31 #include <string.h>
789
378b5ab86f77 add new build system for windows
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 747
diff changeset
32 #include <fcntl.h>
378b5ab86f77 add new build system for windows
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 747
diff changeset
33
378b5ab86f77 add new build system for windows
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 747
diff changeset
34 #ifndef _WIN32
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
35 #include <unistd.h>
789
378b5ab86f77 add new build system for windows
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 747
diff changeset
36 #endif
378b5ab86f77 add new build system for windows
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 747
diff changeset
37
506
ceed7714846a fixes crash in dav-sync archive command when trying to remove resources from the db
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 505
diff changeset
38 #include "utils.h"
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
39
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
40 #include "crypto.h"
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
41
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
42 /* -------------------- OpenSSL Crypto Functions -------------------- */
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
43 #ifdef DAV_USE_OPENSSL
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
44
625
e1a85fbf68f9 add more dav-sync pull tests
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 624
diff changeset
45 #if OPENSSL_VERSION_NUMBER < 0x10000000L
261
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
46
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
47 static EVP_CIPHER_CTX* create_evp_cipher_ctx() {
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
48 EVP_CIPHER_CTX *ctx = malloc(sizeof(EVP_CIPHER_CTX));
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
49 EVP_CIPHER_CTX_init(ctx);
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
50 return ctx;
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
51 }
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
52
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
53 static void free_evp_cipher_ctx(EVP_CIPHER_CTX *ctx) {
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
54 EVP_CIPHER_CTX_cleanup(ctx);
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
55 free(ctx);
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
56 }
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
57
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
58 #define EVP_CIPHER_CTX_new() create_evp_cipher_ctx()
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
59 #define EVP_CIPHER_CTX_free(ctx) free_evp_cipher_ctx(ctx)
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
60
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
61 #endif
f60d742a62a0 fixes build with ancient openssl
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 260
diff changeset
62
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
63 int dav_rand_bytes(unsigned char *buf, size_t len) {
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
64 return !RAND_bytes(buf, len);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
65 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
66
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
67 AESDecrypter* aes_decrypter_new(DavKey *key, void *stream, dav_write_func write_func) {
207
de23f8881e9f fixed hash verification and head requests
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 185
diff changeset
68 AESDecrypter *dec = calloc(1, sizeof(AESDecrypter));
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
69 dav_sha256_init(&dec->sha256);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
70 dec->stream = stream;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
71 dec->write = write_func;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
72 dec->key = key;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
73 dec->init = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
74 dec->ivpos = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
75
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
76 return dec;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
77 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
78
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
79 void aes_decrypter_init(AESDecrypter *dec) {
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
80 //EVP_CIPHER_CTX_init(&dec->ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
81 dec->ctx = EVP_CIPHER_CTX_new();
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
82 dec->init = 1;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
83 if(dec->key->type == DAV_KEY_AES128) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
84 EVP_DecryptInit_ex(
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
85 dec->ctx,
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
86 EVP_aes_128_cbc(),
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
87 NULL,
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
88 dec->key->data,
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
89 dec->ivtmp);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
90 } else if(dec->key->type == DAV_KEY_AES256) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
91 EVP_DecryptInit_ex(
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
92 dec->ctx,
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
93 EVP_aes_256_cbc(),
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
94 NULL,
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
95 dec->key->data,
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
96 dec->ivtmp);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
97 } else {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
98 fprintf(stderr, "unknown key type\n");
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
99 exit(-1);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
100 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
101 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
102
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
103 size_t aes_write(const void *buf, size_t s, size_t n, AESDecrypter *dec) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
104 int len = s*n;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
105 if(!dec->init) {
816
839fefbdedc7 compatibility with UCX 3.1 plus several minor code fixes
Mike Becker <universe@uap-core.de>
parents: 791
diff changeset
106 size_t m = 16 - dec->ivpos;
839fefbdedc7 compatibility with UCX 3.1 plus several minor code fixes
Mike Becker <universe@uap-core.de>
parents: 791
diff changeset
107 size_t cp = m > len ? len : m;
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
108 memcpy(dec->ivtmp + dec->ivpos, buf, cp);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
109 dec->ivpos += cp;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
110 if(dec->ivpos >= 16) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
111 aes_decrypter_init(dec);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
112 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
113 if(len == cp) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
114 return len;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
115 } else {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
116 buf = (char*)buf + cp;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
117 len -= cp;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
118 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
119 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
120
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
121 int outlen = len + 16;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
122 unsigned char *out = malloc(outlen);
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
123 EVP_DecryptUpdate(dec->ctx, out, &outlen, buf, len);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
124 ssize_t wlen = dec->write(out, 1, outlen, dec->stream);
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
125 dav_sha256_update(&dec->sha256, out, wlen);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
126 free(out);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
127 return (s*n) / s;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
128 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
129
207
de23f8881e9f fixed hash verification and head requests
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 185
diff changeset
130 void aes_decrypter_shutdown(AESDecrypter *dec) {
237
fd9135bc7580 fixed crash when encrypted streams are empty
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 207
diff changeset
131 if(dec->init) {
fd9135bc7580 fixed crash when encrypted streams are empty
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 207
diff changeset
132 void *out = malloc(128);
fd9135bc7580 fixed crash when encrypted streams are empty
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 207
diff changeset
133 int len = 0;
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
134 EVP_DecryptFinal_ex(dec->ctx, out, &len);
237
fd9135bc7580 fixed crash when encrypted streams are empty
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 207
diff changeset
135 dec->write(out, 1, len, dec->stream);
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
136 dav_sha256_update(&dec->sha256, out, len);
237
fd9135bc7580 fixed crash when encrypted streams are empty
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 207
diff changeset
137 free(out);
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
138 //EVP_CIPHER_CTX_cleanup(&dec->ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
139 EVP_CIPHER_CTX_free(dec->ctx);
237
fd9135bc7580 fixed crash when encrypted streams are empty
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 207
diff changeset
140 }
207
de23f8881e9f fixed hash verification and head requests
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 185
diff changeset
141 }
de23f8881e9f fixed hash verification and head requests
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 185
diff changeset
142
de23f8881e9f fixed hash verification and head requests
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 185
diff changeset
143 void aes_decrypter_close(AESDecrypter *dec) {
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
144 free(dec);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
145 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
146
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
147
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
148 AESEncrypter* aes_encrypter_new(DavKey *key, void *stream, dav_read_func read_func, dav_seek_func seek_func) {
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
149 unsigned char *iv = malloc(16);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
150 if(!RAND_bytes(iv, 16)) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
151 free(iv);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
152 return NULL;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
153 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
154
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
155 AESEncrypter *enc = malloc(sizeof(AESEncrypter));
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
156 dav_sha256_init(&enc->sha256);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
157 enc->stream = stream;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
158 enc->read = read_func;
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
159 enc->seek = seek_func;
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
160 enc->tmp = NULL;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
161 enc->tmplen = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
162 enc->tmpoff = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
163 enc->end = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
164 enc->iv = iv;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
165 enc->ivlen = 16;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
166
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
167 //EVP_CIPHER_CTX_init(&enc->ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
168 enc->ctx = EVP_CIPHER_CTX_new();
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
169 if(key->type == DAV_KEY_AES128) {
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
170 EVP_EncryptInit_ex(enc->ctx, EVP_aes_128_cbc(), NULL, key->data, enc->iv);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
171 } else if(key->type == DAV_KEY_AES256) {
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
172 EVP_EncryptInit_ex(enc->ctx, EVP_aes_256_cbc(), NULL, key->data, enc->iv);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
173 } else {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
174 fprintf(stderr, "unknown key type\n");
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
175 exit(-1);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
176 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
177 return enc;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
178 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
179
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
180 size_t aes_read(void *buf, size_t s, size_t n, AESEncrypter *enc) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
181 size_t len = s*n;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
182 if(enc->tmp) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
183 size_t tmp_diff = enc->tmplen - enc->tmpoff;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
184 size_t cp_len = tmp_diff > len ? len : tmp_diff;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
185 memcpy(buf, enc->tmp + enc->tmpoff, cp_len);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
186 enc->tmpoff += cp_len;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
187 if(enc->tmpoff >= enc->tmplen) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
188 free(enc->tmp);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
189 enc->tmp = NULL;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
190 enc->tmplen = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
191 enc->tmpoff = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
192 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
193 return cp_len / s;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
194 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
195
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
196 if(enc->end) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
197 return 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
198 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
199
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
200 void *in = malloc(len);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
201 size_t in_len = enc->read(in, 1, len, enc->stream);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
202
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
203 dav_sha256_update(&enc->sha256, in, in_len);
150
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
204
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
205 unsigned char *out = NULL;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
206 int outlen = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
207 size_t ivl = enc->ivlen;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
208 if(in_len != 0) {
459
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
209 outlen = len + 32;
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
210 out = malloc(outlen + ivl);
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
211 if(ivl > 0) {
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
212 memcpy(out, enc->iv, ivl);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
213 }
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
214 EVP_EncryptUpdate(enc->ctx, out + ivl, &outlen, in, in_len);
728
35a421f441d5 add stream API
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 692
diff changeset
215 // I think we don't need this
35a421f441d5 add stream API
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 692
diff changeset
216 /*
459
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
217 if(in_len != len) {
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
218 int newoutlen = 16;
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
219 EVP_EncryptFinal_ex(enc->ctx, out + ivl + outlen, &newoutlen);
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
220 outlen += newoutlen;
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
221 enc->end = 1;
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
222 }
728
35a421f441d5 add stream API
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 692
diff changeset
223 */
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
224 } else {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
225 out = malloc(16);
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
226 EVP_EncryptFinal_ex(enc->ctx, out, &outlen);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
227 enc->end = 1;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
228 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
229 enc->tmp = (char*)out;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
230 enc->tmplen = outlen + ivl;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
231 enc->tmpoff = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
232
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
233 if(enc->ivlen > 0) {
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
234 enc->ivlen = 0;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
235 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
236
459
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
237 free(in);
2c112cbaa08e aes encrypter: fixes case where EVP_EncryptFinal_ex was not called at the stream end
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 404
diff changeset
238
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
239 return aes_read(buf, s, n, enc);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
240 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
241
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
242 void aes_encrypter_close(AESEncrypter *enc) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
243 if(enc->tmp) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
244 free(enc->tmp);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
245 }
150
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
246 if(enc->iv) {
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
247 free(enc->iv);
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
248 }
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
249 //EVP_CIPHER_CTX_cleanup(&enc->ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
250 EVP_CIPHER_CTX_free(enc->ctx);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
251 free(enc);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
252 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
253
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
254 int aes_encrypter_reset(AESEncrypter *enc, curl_off_t offset, int origin) {
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
255 if(origin != SEEK_SET || offset != 0 || !enc->seek) {
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
256 return CURL_SEEKFUNC_CANTSEEK;
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
257 }
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
258
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
259 enc->ivlen = 16;
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
260 if(enc->seek(enc->stream, 0, SEEK_SET) != 0) {
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
261 return CURL_SEEKFUNC_FAIL;
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
262 }
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
263 return CURL_SEEKFUNC_OK;
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
264 }
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
265
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
266
505
481802342fdf ucx update
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 488
diff changeset
267 char* aes_encrypt(const char *in, size_t len, DavKey *key) {
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
268 unsigned char iv[16];
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
269 if(!RAND_bytes(iv, 16)) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
270 return NULL;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
271 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
272
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
273 //EVP_CIPHER_CTX ctx;
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
274 //EVP_CIPHER_CTX_init(&ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
275 EVP_CIPHER_CTX *ctx = EVP_CIPHER_CTX_new();
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
276 if(key->type == DAV_KEY_AES128) {
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
277 EVP_EncryptInit_ex(
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
278 ctx,
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
279 EVP_aes_128_cbc(),
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
280 NULL,
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
281 (unsigned char*)key->data,
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
282 iv);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
283 } else if(key->type == DAV_KEY_AES256) {
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
284 EVP_EncryptInit_ex(
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
285 ctx,
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
286 EVP_aes_256_cbc(),
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
287 NULL,
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
288 (unsigned char*)key->data,
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
289 iv);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
290 } else {
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
291 //EVP_CIPHER_CTX_cleanup(&ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
292 EVP_CIPHER_CTX_free(ctx);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
293 return NULL;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
294 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
295
150
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
296 //int len = strlen(in);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
297 int buflen = len + 64;
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
298 unsigned char *buf = calloc(1, buflen);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
299 memcpy(buf, iv, 16);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
300
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
301 int l = buflen - 16;
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
302 EVP_EncryptUpdate(ctx, buf + 16, &l, (unsigned char*)in, len);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
303
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
304 int f = 0;
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
305 EVP_EncryptFinal_ex(ctx, buf + 16 + l, &f);
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
306 char *out = util_base64encode((char*)buf, 16 + l + f);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
307 free(buf);
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
308 EVP_CIPHER_CTX_free(ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
309 //EVP_CIPHER_CTX_cleanup(&ctx);
150
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
310
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
311 return out;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
312 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
313
505
481802342fdf ucx update
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 488
diff changeset
314 char* aes_decrypt(const char *in, size_t *length, DavKey *key) {
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
315 int len;
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
316 unsigned char *buf = (unsigned char*)util_base64decode_len(in, &len);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
317
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
318 //EVP_CIPHER_CTX ctx;
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
319 //EVP_CIPHER_CTX_init(&ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
320 EVP_CIPHER_CTX *ctx = EVP_CIPHER_CTX_new();
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
321 if(key->type == DAV_KEY_AES128) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
322 EVP_DecryptInit_ex(
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
323 ctx,
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
324 EVP_aes_128_cbc(),
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
325 NULL,
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
326 key->data,
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
327 buf);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
328 } else if(key->type == DAV_KEY_AES256) {
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
329 EVP_DecryptInit_ex(
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
330 ctx,
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
331 EVP_aes_256_cbc(),
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
332 NULL,
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
333 key->data,
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
334 buf);
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
335 } else {
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
336 //EVP_CIPHER_CTX_cleanup(&ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
337 EVP_CIPHER_CTX_free(ctx);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
338 return NULL;
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
339 }
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
340
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
341 unsigned char *out = malloc(len + 1);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
342 int outlen = len;
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
343 unsigned char *in_buf = buf + 16;
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
344 int inlen = len - 16;
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
345 int f = 0;
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
346
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
347 EVP_DecryptUpdate(ctx, out, &outlen, in_buf, inlen);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
348 EVP_DecryptFinal_ex(ctx, out + outlen, &f);
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
349 out[outlen + f] = '\0';
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
350 free(buf);
260
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
351 //EVP_CIPHER_CTX_cleanup(&ctx);
26f5f817429e fixes build with openssl 1.1
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 237
diff changeset
352 EVP_CIPHER_CTX_free(ctx);
150
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
353
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
354 *length = outlen + f;
43
03076907b58a added file name encryption
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 40
diff changeset
355 return (char*)out;
40
a95ee94b9204 supports whitespace in paths
Olaf Wintermann <olaf.wintermann@gmail.com>
parents:
diff changeset
356 }
150
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
357
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
358
354
067ea2315a8a moves auth prompt functionality to libidav
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 349
diff changeset
359 void dav_get_hash(DAV_SHA_CTX *sha256, unsigned char *buf){
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
360 dav_sha256_final(sha256, (unsigned char*)buf);
150
37fb12574acd added checksums for encrypted resources
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 75
diff changeset
361 }
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
362
367
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
363 char* dav_create_hash(const char *data, size_t len) {
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
364 unsigned char hash[DAV_SHA256_DIGEST_LENGTH];
624
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
365 DAV_SHA_CTX ctx;
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
366 dav_sha256_init(&ctx);
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
367 dav_sha256_update(&ctx, data, len);
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
368 dav_sha256_final(&ctx, hash);
367
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
369 return util_hexstr(hash, DAV_SHA256_DIGEST_LENGTH);
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
370 }
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
371
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
372 DAV_SHA_CTX* dav_sha256_create(void) {
520
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
373 DAV_SHA_CTX *ctx = malloc(sizeof(DAV_SHA_CTX));
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
374 dav_sha256_init(ctx);
520
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
375 return ctx;
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
376 }
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
377
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
378 #if OPENSSL_VERSION_NUMBER < 0x30000000L
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
379
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
380 void dav_sha256_init(DAV_SHA_CTX *ctx) {
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
381 SHA256_Init(ctx);
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
382 }
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
383
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
384 void dav_sha256_update(DAV_SHA_CTX *ctx, const void *data, size_t length) {
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
385 SHA256_Update(ctx, data, length);
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
386 }
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
387
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
388 void dav_sha256_final(char *md, DAV_SHA_CTX *ctx) {
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
389 SHA256_Final(md, ctx);
520
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
390 }
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
391
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
392 #else
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
393
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
394 void dav_sha256_init(DAV_SHA_CTX *ctx) {
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
395 EVP_MD_CTX *mdctx = EVP_MD_CTX_new();
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
396 EVP_DigestInit_ex(mdctx, EVP_sha256(), NULL);
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
397 *ctx = mdctx;
520
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
398 }
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
399
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
400 void dav_sha256_update(DAV_SHA_CTX *ctx, const char *data, size_t length) {
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
401 EVP_DigestUpdate(*ctx, data, length);
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
402 }
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
403
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
404 void dav_sha256_final(DAV_SHA_CTX *ctx, unsigned char *md) {
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
405 EVP_DigestFinal(*ctx, md, NULL);
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
406 }
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
407
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
408 #endif
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
409
624
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
410 #if OPENSSL_VERSION_NUMBER < 0x10100000L
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
411 static int crypto_pw2key_error = 0;
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
412 DavKey* dav_pw2key(const char *password, const unsigned char *salt, int saltlen, int pwfunc, int enc) {
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
413 if(!crypto_pw2key_error) {
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
414 fprintf(stderr, "Error: password key derivation not supported on this platform: openssl to old\n");
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
415 crypto_pw2key_error = 1;
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
416 }
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
417 return 0;
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
418 }
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
419
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
420 #else
515
2465dd550bb5 fixes signedness of salt in dav_pw2key()
Mike Becker <universe@uap-core.de>
parents: 506
diff changeset
421 DavKey* dav_pw2key(const char *password, const unsigned char *salt, int saltlen, int pwfunc, int enc) {
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
422 if(!password) {
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
423 return NULL;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
424 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
425 size_t len = strlen(password);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
426 if(len == 0) {
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
427 return NULL;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
428 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
429
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
430 // setup key data and length
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
431 unsigned char keydata[32];
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
432 int keylen = 32;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
433 switch(enc) {
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
434 case DAV_KEY_AES128: keylen = 16; break;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
435 case DAV_KEY_AES256: keylen = 32; break;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
436 default: return NULL;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
437 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
438
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
439 // generate key
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
440 switch(pwfunc) {
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
441 case DAV_PWFUNC_PBKDF2_SHA256: {
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
442 PKCS5_PBKDF2_HMAC(
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
443 password,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
444 len,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
445 salt,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
446 saltlen,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
447 DAV_CRYPTO_ITERATION_COUNT,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
448 EVP_sha256(),
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
449 keylen,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
450 keydata);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
451 break;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
452 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
453 case DAV_PWFUNC_PBKDF2_SHA512: {
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
454 PKCS5_PBKDF2_HMAC(
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
455 password,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
456 len,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
457 salt,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
458 saltlen,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
459 DAV_CRYPTO_ITERATION_COUNT,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
460 EVP_sha512(),
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
461 keylen,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
462 keydata);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
463 break;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
464 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
465 default: return NULL;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
466 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
467
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
468 // create DavKey with generated data
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
469 DavKey *key = malloc(sizeof(DavKey));
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
470 key->data = malloc(keylen);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
471 key->length = keylen;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
472 key->name = NULL;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
473 key->type = enc;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
474 memcpy(key->data, keydata, keylen);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
475 return key;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
476 }
624
27985062cd2c fix build on Solaris 10
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 520
diff changeset
477 #endif
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
478
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
479 #endif
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
480
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
481
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
482 /* -------------------- Apple Crypto Functions -------------------- */
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
483 #ifdef DAV_CRYPTO_COMMON_CRYPTO
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
484
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
485 #define RANDOM_BUFFER_LENGTH 256
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
486 static char randbuf[RANDOM_BUFFER_LENGTH];
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
487 static int rbufpos = RANDOM_BUFFER_LENGTH;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
488
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
489 int dav_rand_bytes(unsigned char *buf, size_t len) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
490 if(len + rbufpos > RANDOM_BUFFER_LENGTH) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
491 int devr = open("/dev/urandom", O_RDONLY);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
492 if(devr == -1) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
493 return 1;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
494 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
495
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
496 if(read(devr, randbuf, RANDOM_BUFFER_LENGTH) < RANDOM_BUFFER_LENGTH) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
497 close(devr);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
498 return 1;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
499 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
500
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
501 rbufpos = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
502 if(len > RANDOM_BUFFER_LENGTH) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
503 int err = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
504 if(read(devr, buf, len) < len) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
505 err = 1;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
506 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
507 close(devr);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
508 return err;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
509 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
510
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
511 close(devr);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
512 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
513
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
514 char *r = randbuf;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
515 memcpy(buf, r + rbufpos, len);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
516 rbufpos += len;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
517
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
518 return 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
519 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
520
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
521 AESDecrypter* aes_decrypter_new(DavKey *key, void *stream, dav_write_func write_func) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
522 AESDecrypter *dec = calloc(1, sizeof(AESDecrypter));
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
523 CC_SHA256_Init(&dec->sha256);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
524 dec->stream = stream;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
525 dec->write = write_func;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
526 dec->key = key;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
527 dec->init = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
528 dec->ivpos = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
529
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
530 return dec;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
531 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
532
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
533
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
534 void aes_decrypter_init(AESDecrypter *dec) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
535 //EVP_CIPHER_CTX_init(&dec->ctx);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
536 dec->init = 1;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
537
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
538 CCCryptorRef cryptor;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
539 CCCryptorStatus status;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
540 if(dec->key->type == DAV_KEY_AES128) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
541 status = CCCryptorCreate(kCCDecrypt, kCCAlgorithmAES128, kCCOptionPKCS7Padding, dec->key->data, dec->key->length, dec->ivtmp, &cryptor);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
542 } else if(dec->key->type == DAV_KEY_AES256) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
543 status = CCCryptorCreate(kCCDecrypt, kCCAlgorithmAES, kCCOptionPKCS7Padding, dec->key->data, dec->key->length, dec->ivtmp, &cryptor);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
544 } else {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
545 fprintf(stderr, "unknown key type\n");
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
546 exit(-1);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
547 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
548 dec->ctx = cryptor;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
549 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
550
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
551 size_t aes_write(const void *buf, size_t s, size_t n, AESDecrypter *dec) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
552 int len = s*n;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
553 if(!dec->init) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
554 size_t n = 16 - dec->ivpos;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
555 size_t cp = n > len ? len : n;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
556 memcpy(dec->ivtmp + dec->ivpos, buf, cp);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
557 dec->ivpos += cp;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
558 if(dec->ivpos >= 16) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
559 aes_decrypter_init(dec);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
560 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
561 if(len == cp) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
562 return len;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
563 } else {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
564 buf = (char*)buf + cp;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
565 len -= cp;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
566 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
567 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
568
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
569 int outlen = len + 16;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
570 unsigned char *out = malloc(outlen);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
571
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
572 CCCryptorStatus status;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
573 size_t avail = outlen;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
574 size_t moved = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
575 status = CCCryptorUpdate(dec->ctx, buf, len, out, avail, &moved);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
576
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
577 ssize_t wlen = dec->write(out, 1, moved, dec->stream);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
578 CC_SHA256_Update(&dec->sha256, out, wlen);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
579 free(out);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
580 return (s*n) / s;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
581 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
582
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
583 void aes_decrypter_shutdown(AESDecrypter *dec) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
584 if(dec->init) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
585 void *out = malloc(128);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
586 size_t len = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
587 //EVP_DecryptFinal_ex(dec->ctx, out, &len);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
588 CCCryptorFinal(dec->ctx, out, 128, &len);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
589
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
590
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
591 dec->write(out, 1, len, dec->stream);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
592 CC_SHA256_Update(&dec->sha256, out, len);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
593 free(out);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
594 //EVP_CIPHER_CTX_cleanup(&dec->ctx);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
595 //EVP_CIPHER_CTX_free(dec->ctx);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
596 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
597 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
598
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
599 void aes_decrypter_close(AESDecrypter *dec) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
600
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
601 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
602
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
603 AESEncrypter* aes_encrypter_new(DavKey *key, void *stream, dav_read_func read_func, dav_seek_func seek_func) {
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
604 unsigned char *iv = malloc(16);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
605 if(dav_rand_bytes(iv, 16)) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
606 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
607 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
608
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
609 CCCryptorRef cryptor;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
610 CCCryptorStatus status;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
611 if(key->type == DAV_KEY_AES128) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
612 status = CCCryptorCreate(kCCEncrypt, kCCAlgorithmAES128, kCCOptionPKCS7Padding, key->data, key->length, iv, &cryptor);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
613 } else if(key->type == DAV_KEY_AES256) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
614 status = CCCryptorCreate(kCCEncrypt, kCCAlgorithmAES, kCCOptionPKCS7Padding, key->data, key->length, iv, &cryptor);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
615 } else {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
616 free(iv);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
617 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
618 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
619
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
620 AESEncrypter *enc = malloc(sizeof(AESEncrypter));
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
621 enc->ctx = cryptor;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
622 CC_SHA256_Init(&enc->sha256);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
623 enc->stream = stream;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
624 enc->read = read_func;
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
625 enc->seek = seek_func;
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
626 enc->tmp = NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
627 enc->tmplen = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
628 enc->tmpoff = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
629 enc->end = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
630 enc->iv = iv;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
631 enc->ivlen = 16;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
632
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
633 return enc;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
634 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
635
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
636 size_t aes_read(void *buf, size_t s, size_t n, AESEncrypter *enc) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
637 size_t len = s*n;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
638 if(enc->tmp) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
639 size_t tmp_diff = enc->tmplen - enc->tmpoff;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
640 size_t cp_len = tmp_diff > len ? len : tmp_diff;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
641 memcpy(buf, enc->tmp + enc->tmpoff, cp_len);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
642 enc->tmpoff += cp_len;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
643 if(enc->tmpoff >= enc->tmplen) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
644 free(enc->tmp);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
645 enc->tmp = NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
646 enc->tmplen = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
647 enc->tmpoff = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
648 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
649 return cp_len / s;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
650 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
651
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
652 if(enc->end) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
653 return 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
654 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
655
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
656 void *in = malloc(len);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
657 size_t in_len = enc->read(in, 1, len, enc->stream);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
658
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
659 CC_SHA256_Update(&enc->sha256, in, in_len);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
660
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
661 unsigned char *out = NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
662 size_t outlen = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
663 size_t ivl = enc->ivlen;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
664 if(in_len != 0) {
462
efda9aa1bbad applies aes stream fix to macos implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 459
diff changeset
665 outlen = len + 32;
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
666 out = malloc(outlen + ivl);
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
667 if(ivl > 0) {
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
668 memcpy(out, enc->iv, ivl);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
669 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
670
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
671 CCCryptorStatus status;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
672 size_t avail = outlen;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
673 status = CCCryptorUpdate(enc->ctx, in, in_len, out + ivl, avail, &outlen);
728
35a421f441d5 add stream API
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 692
diff changeset
674 // TODO: check if this still works
35a421f441d5 add stream API
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 692
diff changeset
675 /*
462
efda9aa1bbad applies aes stream fix to macos implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 459
diff changeset
676 if(in_len != len) {
488
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
677 size_t newoutlen = 16;
462
efda9aa1bbad applies aes stream fix to macos implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 459
diff changeset
678 status = CCCryptorFinal(enc->ctx, out + ivl + outlen, 16, &newoutlen);
efda9aa1bbad applies aes stream fix to macos implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 459
diff changeset
679 outlen += newoutlen;
efda9aa1bbad applies aes stream fix to macos implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 459
diff changeset
680 enc->end = 1;
efda9aa1bbad applies aes stream fix to macos implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 459
diff changeset
681 }
728
35a421f441d5 add stream API
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 692
diff changeset
682 */
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
683 } else {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
684 out = malloc(32);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
685 CCCryptorStatus status;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
686 size_t avail = outlen;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
687 status = CCCryptorFinal(enc->ctx, out, 32, &outlen);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
688 enc->end = 1;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
689 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
690 enc->tmp = (char*)out;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
691 enc->tmplen = outlen + ivl;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
692 enc->tmpoff = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
693
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
694 if(enc->ivlen > 0) {
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
695 enc->ivlen = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
696 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
697
462
efda9aa1bbad applies aes stream fix to macos implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 459
diff changeset
698 free(in);
efda9aa1bbad applies aes stream fix to macos implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 459
diff changeset
699
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
700 return aes_read(buf, s, n, enc);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
701 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
702
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
703 int aes_encrypter_reset(AESEncrypter *enc, curl_off_t offset, int origin) {
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
704 if(origin != SEEK_SET || offset != 0 || !enc->seek) {
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
705 return CURL_SEEKFUNC_CANTSEEK;
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
706 }
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
707
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
708 enc->ivlen = 16;
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
709 if(enc->seek(enc->stream, 0, SEEK_SET) != 0) {
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
710 return CURL_SEEKFUNC_FAIL;
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
711 }
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
712 return CURL_SEEKFUNC_OK;
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
713 }
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
714
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
715 void aes_encrypter_close(AESEncrypter *enc) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
716 if(enc->tmp) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
717 free(enc->tmp);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
718 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
719 if(enc->iv) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
720 free(enc->iv);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
721 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
722 // TODO: cleanup cryptor
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
723 free(enc);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
724 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
725
505
481802342fdf ucx update
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 488
diff changeset
726 char* aes_encrypt(const char *in, size_t len, DavKey *key) {
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
727 unsigned char iv[16];
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
728 if(dav_rand_bytes(iv, 16)) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
729 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
730 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
731
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
732 CCCryptorRef cryptor;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
733 CCCryptorStatus status;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
734 if(key->type == DAV_KEY_AES128) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
735 status = CCCryptorCreate(kCCEncrypt, kCCAlgorithmAES128, kCCOptionPKCS7Padding, key->data, key->length, iv, &cryptor);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
736 } else if(key->type == DAV_KEY_AES256) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
737 status = CCCryptorCreate(kCCEncrypt, kCCAlgorithmAES, kCCOptionPKCS7Padding, key->data, key->length, iv, &cryptor);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
738 } else {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
739 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
740 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
741
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
742 if(status != kCCSuccess) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
743 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
744 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
745
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
746 int buflen = len + 64;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
747 char *buf = calloc(1, buflen);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
748 memcpy(buf, iv, 16);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
749
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
750 int pos = 16;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
751 size_t avail = buflen - 16;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
752 size_t moved;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
753 char *out = buf + 16;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
754
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
755 status = CCCryptorUpdate(cryptor, in,
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
756 len, out, avail,
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
757 &moved);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
758 if(status != kCCSuccess) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
759 free(buf);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
760 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
761 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
762
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
763 pos += moved;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
764 avail -= moved;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
765 out += moved;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
766
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
767 status = CCCryptorFinal(cryptor, out, avail, &moved);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
768 if(status != kCCSuccess) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
769 free(buf);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
770 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
771 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
772
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
773 pos += moved;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
774
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
775 char *b64enc = util_base64encode(buf, pos);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
776 free(buf);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
777
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
778 return b64enc;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
779 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
780
505
481802342fdf ucx update
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 488
diff changeset
781 char* aes_decrypt(const char *in, size_t *len, DavKey *key) {
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
782 int inlen;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
783 unsigned char *buf = (unsigned char*)util_base64decode_len(in, &inlen);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
784
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
785 CCCryptorRef cryptor;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
786 CCCryptorStatus status;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
787 if(key->type == DAV_KEY_AES128) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
788 status = CCCryptorCreate(kCCDecrypt, kCCAlgorithmAES128, kCCOptionPKCS7Padding, key->data, key->length, buf, &cryptor);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
789 } else if(key->type == DAV_KEY_AES256) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
790 status = CCCryptorCreate(kCCDecrypt, kCCAlgorithmAES, kCCOptionPKCS7Padding, key->data, key->length, buf, &cryptor);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
791 } else {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
792 free(buf);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
793 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
794 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
795
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
796 if(status != kCCSuccess) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
797 free(buf);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
798 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
799 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
800
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
801 char *out = malloc(inlen + 1);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
802 size_t outavail = inlen;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
803 size_t outlen = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
804
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
805 unsigned char *inbuf = buf + 16;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
806 inlen -= 16;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
807
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
808 size_t moved = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
809 status = CCCryptorUpdate(cryptor, inbuf, inlen, out, outavail, &moved);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
810 if(status != kCCSuccess) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
811 free(buf);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
812 free(out);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
813 // TODO cryptor
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
814 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
815 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
816
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
817 outlen += moved;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
818 outavail -= moved;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
819
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
820 status = CCCryptorFinal(cryptor, out + outlen, outavail, &moved);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
821 if(status != kCCSuccess) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
822 free(buf);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
823 free(out);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
824 // TODO cryptor
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
825 return NULL;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
826 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
827
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
828 outlen += moved;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
829 out[outlen] = 0;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
830
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
831 *len = outlen;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
832 return out;
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
833 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
834
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
835 void dav_get_hash(DAV_SHA_CTX *sha256, unsigned char *buf) {
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
836 CC_SHA256_Final(buf, sha256);
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
837 }
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
838
367
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
839 char* dav_create_hash(const char *data, size_t len) {
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
840 unsigned char hash[DAV_SHA256_DIGEST_LENGTH];
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
841 CC_SHA256((const unsigned char*)data, len, hash);
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
842 return util_hexstr(hash, DAV_SHA256_DIGEST_LENGTH);
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
843 }
4a6a59f89f9f adds dav-sync config for autodetecting tag changes
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 354
diff changeset
844
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
845 DAV_SHA_CTX* dav_sha256_create(void) {
520
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
846 DAV_SHA_CTX *ctx = malloc(sizeof(DAV_SHA_CTX));
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
847 CC_SHA256_Init(ctx);
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
848 return ctx;
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
849 }
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
850
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
851 void dav_sha256_update(DAV_SHA_CTX *ctx, const char *data, size_t len) {
520
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
852 CC_SHA256_Update(ctx, data, len);
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
853 }
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
854
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
855 void dav_sha256_final(DAV_SHA_CTX *ctx, unsigned char *buf) {
520
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
856 CC_SHA256_Final(buf, ctx);
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
857 free(ctx);
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
858 }
da2b0cc44e4f adds xml attribute support and xattr property
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 515
diff changeset
859
515
2465dd550bb5 fixes signedness of salt in dav_pw2key()
Mike Becker <universe@uap-core.de>
parents: 506
diff changeset
860 DavKey* dav_pw2key(const char *password, const unsigned char *salt, int saltlen, int pwfunc, int enc) {
488
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
861 if(!password) {
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
862 return NULL;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
863 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
864 size_t len = strlen(password);
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
865 if(len == 0) {
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
866 return NULL;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
867 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
868
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
869 // setup key data and length
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
870 unsigned char keydata[32];
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
871 int keylen = 32;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
872 switch(enc) {
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
873 case DAV_KEY_AES128: keylen = 16; break;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
874 case DAV_KEY_AES256: keylen = 32; break;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
875 default: return NULL;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
876 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
877
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
878 // generate key
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
879 switch(pwfunc) {
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
880 case DAV_PWFUNC_PBKDF2_SHA256: {
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
881 int result = CCKeyDerivationPBKDF(
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
882 kCCPBKDF2,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
883 password,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
884 len,
515
2465dd550bb5 fixes signedness of salt in dav_pw2key()
Mike Becker <universe@uap-core.de>
parents: 506
diff changeset
885 salt,
488
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
886 saltlen,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
887 kCCPRFHmacAlgSHA256,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
888 DAV_CRYPTO_ITERATION_COUNT,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
889 keydata,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
890 keylen);
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
891 if(result) {
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
892 return NULL;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
893 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
894 break;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
895 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
896 case DAV_PWFUNC_PBKDF2_SHA512: {
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
897 int result = CCKeyDerivationPBKDF(
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
898 kCCPBKDF2,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
899 password,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
900 len,
515
2465dd550bb5 fixes signedness of salt in dav_pw2key()
Mike Becker <universe@uap-core.de>
parents: 506
diff changeset
901 salt,
488
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
902 saltlen,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
903 kCCPRFHmacAlgSHA512,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
904 DAV_CRYPTO_ITERATION_COUNT,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
905 keydata,
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
906 keylen);
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
907 if(result) {
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
908 return NULL;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
909 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
910 break;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
911 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
912 default: return NULL;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
913 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
914
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
915 // create DavKey with generated data
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
916 DavKey *key = malloc(sizeof(DavKey));
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
917 key->data = malloc(keylen);
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
918 key->length = keylen;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
919 key->name = NULL;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
920 key->type = enc;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
921 memcpy(key->data, keydata, keylen);
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
922 return key;
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
923 }
29b979ca8750 adds dav_pw2key commoncrypto implementation
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 478
diff changeset
924
349
0b4ecadaf3f9 ports openssl code to commoncrypto (macos)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 267
diff changeset
925 #endif
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
926
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
927 /* -------------------- Windows Crypto Functions -------------------- */
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
928 #ifdef DAV_CRYPTO_CNG
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
929
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
930 static void cng_cleanup(BCRYPT_ALG_HANDLE hAesAlg, BCRYPT_KEY_HANDLE hKey, BCRYPT_HASH_HANDLE hHash, void *pbObject) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
931 if(hAesAlg) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
932 BCryptCloseAlgorithmProvider(hAesAlg,0);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
933 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
934 if(hKey) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
935 BCryptDestroyKey(hKey);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
936 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
937 if(hHash) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
938 BCryptDestroyHash(hHash);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
939 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
940 if(pbObject) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
941 free(pbObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
942 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
943 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
944
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
945 static int cng_init_key(BCRYPT_ALG_HANDLE *alg, BCRYPT_KEY_HANDLE *key, void **keyobj, DavKey *aesKey) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
946 BCRYPT_ALG_HANDLE hAesAlg = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
947 BCRYPT_KEY_HANDLE hKey = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
948
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
949 void *pbKeyObject = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
950 ULONG keyObjectLength = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
951
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
952 ULONG result = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
953
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
954 // check DavKey and get AES key length
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
955 if(!aesKey) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
956 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
957 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
958
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
959 ULONG aesKeyLength = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
960 if(aesKey->type == DAV_KEY_AES128) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
961 aesKeyLength = 16;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
962 } else if(aesKey->type == DAV_KEY_AES256) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
963 aesKeyLength = 32;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
964 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
965 if(aesKeyLength > aesKey->length || !aesKey->data) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
966 // invalid DavKey
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
967 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
968 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
969
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
970 // initialize BCrypt stuff
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
971 if(BCryptOpenAlgorithmProvider(&hAesAlg, BCRYPT_AES_ALGORITHM, NULL, 0)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
972 fprintf(stderr, "Error: BCryptOpenAlgorithmProvider failed\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
973 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
974 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
975
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
976 if(BCryptGetProperty(hAesAlg, BCRYPT_OBJECT_LENGTH, (PUCHAR)&keyObjectLength, sizeof(DWORD), &result, 0)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
977 fprintf(stderr, "Error: BCrypt: Cannot get BCRYPT_OBJECT_LENGTH\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
978 cng_cleanup(hAesAlg, hKey, NULL, pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
979 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
980 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
981
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
982 if(BCryptSetProperty(hAesAlg, BCRYPT_CHAINING_MODE, (PBYTE)BCRYPT_CHAIN_MODE_CBC, sizeof(BCRYPT_CHAIN_MODE_CBC), 0)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
983 fprintf(stderr, "Error: BCrypt: Cannot set CBC mode\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
984 cng_cleanup(hAesAlg, hKey, NULL, pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
985 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
986 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
987
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
988 pbKeyObject = calloc(1, keyObjectLength);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
989 if(!pbKeyObject) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
990 cng_cleanup(hAesAlg, hKey, NULL, pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
991 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
992 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
993
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
994 // init key
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
995 if(BCryptGenerateSymmetricKey(hAesAlg, &hKey, pbKeyObject, keyObjectLength, aesKey->data, aesKeyLength, 0)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
996 fprintf(stderr, "Error: BCrypt: Cannot set key\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
997 cng_cleanup(hAesAlg, hKey, NULL, pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
998 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
999 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1000
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1001 *alg = hAesAlg;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1002 *key = hKey;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1003 *keyobj = pbKeyObject;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1004
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1005 return 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1006 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1007
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1008 static int cng_hash_init(WinBCryptSHACTX *ctx) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1009 if(BCryptOpenAlgorithmProvider(&ctx->hAlg, BCRYPT_SHA256_ALGORITHM, NULL, 0)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1010 fprintf(stderr, "Error: BCryptOpenAlgorithmProvider failed\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1011 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1012 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1013
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1014 ULONG hashObjectLen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1015 ULONG result;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1016 if(BCryptGetProperty(ctx->hAlg, BCRYPT_OBJECT_LENGTH, (PBYTE)&hashObjectLen, sizeof(DWORD), &result, 0)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1017 cng_cleanup(ctx->hAlg, NULL, NULL, NULL);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1018 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1019 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1020
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1021 ctx->pbHashObject = calloc(1, hashObjectLen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1022
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1023 if(BCryptCreateHash(ctx->hAlg, &ctx->hHash, ctx->pbHashObject, hashObjectLen, NULL, 0, 0)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1024 cng_cleanup(ctx->hAlg, NULL, ctx->hHash, ctx->pbHashObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1025 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1026 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1027
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1028 return 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1029 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1030
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1031
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1032 int dav_rand_bytes(unsigned char *buf, size_t len) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1033 if(BCryptGenRandom(NULL, (unsigned char*)buf, (ULONG)len, BCRYPT_USE_SYSTEM_PREFERRED_RNG)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1034 return 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1035 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1036 return 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1037 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1038
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1039 AESDecrypter* aes_decrypter_new(DavKey *key, void *stream, dav_write_func write_func) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1040 AESDecrypter *dec = calloc(1, sizeof(AESDecrypter));
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1041 if(!dec) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1042 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1043 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1044 if(cng_hash_init(&dec->sha256)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1045 free(dec);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1046 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1047 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1048
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1049 dec->stream = stream;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1050 dec->write = write_func;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1051 dec->key = key;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1052 dec->init = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1053 dec->ivpos = 0;
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1054
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1055 return dec;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1056 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1057
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1058 static void aes_decrypter_init(AESDecrypter *dec) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1059 if(cng_init_key(&dec->ctx.hAlg, &dec->ctx.hKey, &dec->ctx.pbKeyObject, dec->key)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1060 fprintf(stderr, "Error: cng_init_key failed\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1061 exit(-1);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1062 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1063 // copy iv
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1064 memcpy(dec->ctx.pbIV, dec->ivtmp, 16);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1065 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1066
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1067 size_t aes_write(const void *buf, size_t s, size_t n, AESDecrypter *dec) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1068 int len = s*n;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1069 if(!dec->init) {
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1070 dec->init = 1;
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1071
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1072 size_t n = 16 - dec->ivpos;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1073 size_t cp = n > len ? len : n;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1074 memcpy(dec->ivtmp + dec->ivpos, buf, cp);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1075 dec->ivpos += cp;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1076 if(dec->ivpos >= 16) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1077 aes_decrypter_init(dec);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1078 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1079 if(len == cp) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1080 return len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1081 } else {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1082 buf = (char*)buf + cp;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1083 len -= cp;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1084 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1085 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1086
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1087 // the cipher text must be a multiply of 16
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1088 // remaining bytes are stored in ctx.buf and must be added to cibuf
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1089 // the next time
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1090 size_t cbufalloc = len + 64;
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1091 ULONG clen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1092 char *cbuf = malloc(cbufalloc);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1093
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1094 // add previous remaining bytes
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1095 if(dec->ctx.buflen > 0) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1096 memcpy(cbuf, dec->ctx.buf, dec->ctx.buflen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1097 clen = dec->ctx.buflen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1098 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1099 // add current bytes
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1100 memcpy(cbuf + clen, buf, len);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1101 clen += len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1102
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1103 // check if the message fits the blocksize
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1104 int remaining = clen % 16;
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1105 if(remaining == 0) {
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1106 // decrypt last block next time, or in aes_decrypter_shutdown
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1107 // this makes sure, that shutdown always decrypts the last block
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1108 // with BCRYPT_BLOCK_PADDING flag
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1109 remaining = 16;
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1110 }
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1111
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1112 // add remaining bytes to ctx.buf for the next aes_write run
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1113 clen -= remaining;
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1114 memcpy(dec->ctx.buf, cbuf + clen, remaining);
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1115 dec->ctx.buflen = remaining;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1116
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1117 // ready to decrypt the message
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1118 ULONG outlen = clen + 32;
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1119
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1120 // decrypt
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1121 if(clen > 0) {
791
38796c7e32b6 fix aes_write on windows could write non-decrypted bytes to output buffer
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 789
diff changeset
1122 unsigned char* out = malloc(outlen);
38796c7e32b6 fix aes_write on windows could write non-decrypted bytes to output buffer
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 789
diff changeset
1123
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1124 ULONG enc_len = 0;
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1125 ULONG status = BCryptDecrypt(dec->ctx.hKey, cbuf, clen, NULL, dec->ctx.pbIV, 16, out, outlen, &enc_len, 0);
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1126 if(status > 0) {
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1127 fprintf(stderr, "Error: BCryptDecrypt failed: 0x%X\n", status);
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1128 free(out);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1129 free(cbuf);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1130 return 0;
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1131 }
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1132 outlen = enc_len;
791
38796c7e32b6 fix aes_write on windows could write non-decrypted bytes to output buffer
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 789
diff changeset
1133
38796c7e32b6 fix aes_write on windows could write non-decrypted bytes to output buffer
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 789
diff changeset
1134 // write decrypted data to the output stream and update the hash
38796c7e32b6 fix aes_write on windows could write non-decrypted bytes to output buffer
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 789
diff changeset
1135 dec->write(out, 1, outlen, dec->stream);
38796c7e32b6 fix aes_write on windows could write non-decrypted bytes to output buffer
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 789
diff changeset
1136 BCryptHashData(dec->sha256.hHash, out, outlen, 0);
38796c7e32b6 fix aes_write on windows could write non-decrypted bytes to output buffer
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 789
diff changeset
1137
38796c7e32b6 fix aes_write on windows could write non-decrypted bytes to output buffer
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 789
diff changeset
1138 free(out);
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1139 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1140
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1141 free(cbuf);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1142
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1143 return (s*n) / s;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1144 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1145
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1146 void aes_decrypter_shutdown(AESDecrypter *dec) {
689
b1f7d83f6e69 fix aes decrypter stream
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 688
diff changeset
1147 if(dec->init && dec->ctx.buflen > 0) {
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1148 ULONG outlen = 64;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1149 char out[64];
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1150 if(BCryptDecrypt(dec->ctx.hKey, dec->ctx.buf, dec->ctx.buflen, NULL, dec->ctx.pbIV, 16, out, outlen, &outlen, BCRYPT_BLOCK_PADDING)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1151 fprintf(stderr, "Error: BCryptDecrypt failed\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1152 return;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1153 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1154 dec->write(out, 1, outlen, dec->stream);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1155 BCryptHashData(dec->sha256.hHash, out, outlen, 0);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1156 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1157 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1158
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1159 void aes_decrypter_close(AESDecrypter *dec) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1160 cng_cleanup(dec->ctx.hAlg, dec->ctx.hKey, NULL, dec->ctx.pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1161 cng_cleanup(dec->sha256.hAlg, NULL, dec->sha256.hHash, dec->sha256.pbHashObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1162 free(dec);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1163 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1164
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1165 AESEncrypter* aes_encrypter_new(DavKey *key, void *stream, dav_read_func read_func, dav_seek_func seek_func) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1166 unsigned char *iv = malloc(16);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1167 if(dav_rand_bytes(iv, 16)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1168 free(iv);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1169 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1170 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1171
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1172 AESEncrypter *enc = calloc(1, sizeof(AESEncrypter));
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1173 if(cng_hash_init(&enc->sha256)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1174 free(iv);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1175 free(enc);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1176 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1177 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1178
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1179 enc->stream = stream;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1180 enc->read = read_func;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1181 enc->seek = seek_func;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1182 enc->tmp = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1183 enc->tmplen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1184 enc->tmpoff = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1185 enc->end = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1186 enc->iv = iv;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1187 enc->ivlen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1188
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1189 if(cng_init_key(&enc->ctx.hAlg, &enc->ctx.hKey, &enc->ctx.pbKeyObject, key)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1190 fprintf(stderr, "Error: cng_init_key failed\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1191 exit(-1);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1192 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1193
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1194 enc->ctx.buflen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1195 memcpy(enc->ctx.pbIV, iv, 16);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1196
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1197 return enc;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1198 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1199
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1200 size_t aes_read(void *buf, size_t s, size_t n, AESEncrypter *enc) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1201 size_t len = s*n;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1202 size_t nread = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1203
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1204 if(enc->tmp) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1205 // the temp buffer contains bytes that are already encrypted, but
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1206 // the last aes_read had not enough read buffer space
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1207
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1208 // in case we have a tmp buf, we just return this
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1209 size_t tmp_diff = enc->tmplen - enc->tmpoff;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1210 size_t cp_len = tmp_diff > len ? len : tmp_diff;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1211 memcpy(buf, enc->tmp + enc->tmpoff, cp_len);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1212 enc->tmpoff += cp_len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1213 if(enc->tmpoff >= enc->tmplen) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1214 free(enc->tmp);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1215 enc->tmp = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1216 enc->tmplen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1217 enc->tmpoff = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1218 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1219 return cp_len / s;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1220 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1221
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1222 if(enc->ivlen < 16) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1223 size_t copy_iv_len = 16 - enc->ivlen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1224 copy_iv_len = len > copy_iv_len ? copy_iv_len : len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1225
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1226 memcpy(buf, enc->iv, copy_iv_len);
789
378b5ab86f77 add new build system for windows
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 747
diff changeset
1227 (char*)buf += copy_iv_len;
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1228 len -= copy_iv_len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1229 nread = copy_iv_len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1230
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1231 enc->ivlen += copy_iv_len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1232
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1233 if(len == 0) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1234 return copy_iv_len / s;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1235 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1236 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1237
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1238 if(enc->end) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1239 return 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1240 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1241
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1242 size_t remaining = len % 16;
690
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1243 len -= remaining;
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1244
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1245 if(len > 256) {
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1246 len -= 16; // optimization for avoiding tmp buffer usage
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1247 }
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1248
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1249 size_t inalloc = len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1250 ULONG inlen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1251 unsigned char *in = malloc(inalloc);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1252
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1253 // fill the input buffer
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1254 while(inlen < inalloc) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1255 size_t r = enc->read(in + inlen, 1, inalloc - inlen, enc->stream);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1256 if(r == 0) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1257 enc->end = 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1258 break;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1259 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1260 inlen += r;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1261 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1262
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1263 if(inlen == 0) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1264 return nread / s;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1265 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1266
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1267 // hash read data
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1268 BCryptHashData(enc->sha256.hHash, in, inlen, 0);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1269
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1270 // create output buffer
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1271 ULONG outalloc = inlen + 16;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1272 ULONG outlen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1273 char *out = malloc(outalloc);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1274
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1275 // encrypt
690
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1276 int flags = 0;
692
56b66fe2b4f5 fix dav-sync deltav versioning
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 691
diff changeset
1277 if(inlen % 16 != 0) {
691
48ec0ab17011 fix encryption of files with specific length
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 690
diff changeset
1278 enc->end = 1;
48ec0ab17011 fix encryption of files with specific length
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 690
diff changeset
1279 }
48ec0ab17011 fix encryption of files with specific length
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 690
diff changeset
1280 if(enc->end) {
690
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1281 flags = BCRYPT_BLOCK_PADDING;
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1282 }
ce253cfb9127 fix aes encrypter stream (cng)
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 689
diff changeset
1283 if(BCryptEncrypt(enc->ctx.hKey, in, inlen, NULL, enc->ctx.pbIV, 16, out, outalloc, &outlen, flags)) {
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1284 fprintf(stderr, "Error: BCryptEncrypt failed\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1285 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1286
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1287 // check if the output fits in buf, if not, save the remaining bytes in tmp
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1288 if(outlen > len) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1289 size_t tmplen = outlen - len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1290 char *tmp = malloc(tmplen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1291 memcpy(tmp, out+len, tmplen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1292
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1293 enc->tmp = tmp;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1294 enc->tmplen = tmplen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1295 enc->tmpoff = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1296
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1297 outlen = len;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1298 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1299
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1300 // fill read buffer and return
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1301 memcpy(buf, out, outlen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1302 nread += outlen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1303
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1304 free(in);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1305 free(out);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1306
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1307 return nread / s;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1308 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1309
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1310 void aes_encrypter_close(AESEncrypter *enc) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1311 enc->end = 1;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1312 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1313
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1314 int aes_encrypter_reset(AESEncrypter *enc, curl_off_t offset, int origin) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1315 if(origin != SEEK_SET || offset != 0 || !enc->seek) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1316 return CURL_SEEKFUNC_CANTSEEK;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1317 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1318
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1319 enc->ivlen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1320 memcpy(enc->ctx.pbIV, enc->iv, 16);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1321 if(enc->seek(enc->stream, 0, SEEK_SET) != 0) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1322 return CURL_SEEKFUNC_FAIL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1323 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1324 return CURL_SEEKFUNC_OK;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1325 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1326
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1327 char* aes_encrypt(const char *in, size_t len, DavKey *key) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1328 // create random IV
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1329 char iv[16];
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1330 if(dav_rand_bytes(iv, 16)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1331 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1332 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1333
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1334 // initialize bcrypt stuff
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1335 BCRYPT_ALG_HANDLE hAlg = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1336 BCRYPT_KEY_HANDLE hKey = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1337 void *pbKeyObject = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1338 if(cng_init_key(&hAlg, &hKey, &pbKeyObject, key)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1339 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1340 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1341
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1342 // create output buffer
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1343 ULONG outlen = len + 128;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1344 char *out = malloc(outlen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1345
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1346 // the output must start with the IV
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1347 memcpy(out, iv, 16);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1348 char *encbuf = out + 16;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1349 ULONG enclen = outlen - 16;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1350 ULONG encoutlen = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1351
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1352 // encrypt
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1353 if(BCryptEncrypt(hKey, (PUCHAR)in, len, NULL, (PUCHAR)iv, 16, encbuf, enclen, &encoutlen, BCRYPT_BLOCK_PADDING)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1354 fprintf(stderr, "Error: BCryptEncrypt failed\n");
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1355 cng_cleanup(hAlg, hKey, NULL, pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1356 free(out);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1357 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1358 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1359
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1360 outlen = encoutlen + 16; // length of encrypted data + 16 bytes IV
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1361
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1362 // base64 encode
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1363 char *outstr = util_base64encode(out, outlen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1364
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1365 cng_cleanup(hAlg, hKey, NULL, pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1366 free(out);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1367
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1368 return outstr;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1369 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1370
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1371 char* aes_decrypt(const char *in, size_t *len, DavKey *key) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1372 BCRYPT_ALG_HANDLE hAlg = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1373 BCRYPT_KEY_HANDLE hKey = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1374 void *pbKeyObject = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1375 if(cng_init_key(&hAlg, &hKey, &pbKeyObject, key)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1376 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1377 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1378
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1379 int inlen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1380 unsigned char *buf = (unsigned char*)util_base64decode_len(in, &inlen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1381 if(inlen < 16 || !buf) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1382 cng_cleanup(hAlg, hKey, NULL, pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1383 if(buf) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1384 free(buf);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1385 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1386 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1387 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1388
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1389 // encrypted data starts with IV
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1390 char iv[16];
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1391 memcpy(iv, buf, 16);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1392
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1393 // decrypt data
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1394 char *data = buf + 16; // encrypted data starts after IV
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1395 size_t datalen = inlen - 16;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1396
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1397 // create output buffer
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1398 ULONG outlen = inlen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1399 char *out = malloc(outlen + 1);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1400
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1401 // decrypt
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1402 if(BCryptDecrypt(hKey, data, datalen, NULL, iv, 16, out, outlen, &outlen, BCRYPT_BLOCK_PADDING)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1403 cng_cleanup(hAlg, hKey, NULL, pbKeyObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1404 free(out);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1405 free(buf);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1406 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1407 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1408
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1409 // decrypt finished, return
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1410 out[outlen] = 0;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1411 *len = (size_t)outlen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1412 return out;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1413 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1414
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1415 void dav_get_hash(DAV_SHA_CTX *sha256, unsigned char *buf) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1416 BCryptFinishHash(sha256->hHash, buf, DAV_SHA256_DIGEST_LENGTH, 0);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1417 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1418
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1419
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1420 char* dav_create_hash(const char *data, size_t len) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1421 unsigned char hash[DAV_SHA256_DIGEST_LENGTH];
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
1422 DAV_SHA_CTX *ctx = dav_sha256_create();
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1423 if(ctx) {
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
1424 dav_sha256_update(ctx, data, len);
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
1425 dav_sha256_final(ctx, hash);
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1426 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1427 return util_hexstr(hash, DAV_SHA256_DIGEST_LENGTH);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1428 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1429
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
1430 DAV_SHA_CTX* dav_sha256_create(void) {
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1431 DAV_SHA_CTX *ctx = malloc(sizeof(DAV_SHA_CTX));
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1432 if(!ctx) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1433 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1434 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1435 if(cng_hash_init(ctx)) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1436 free(ctx);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1437 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1438 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1439 return ctx;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1440 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1441
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
1442 void dav_sha256_update(DAV_SHA_CTX *ctx, const char *data, size_t len) {
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1443 BCryptHashData(ctx->hHash, (PUCHAR)data, len, 0);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1444 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1445
857
03982275f29b use newer openssl hashing functions to fix warnings
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 816
diff changeset
1446 void dav_sha256_final(DAV_SHA_CTX *ctx, unsigned char *buf) {
688
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1447 BCryptFinishHash(ctx->hHash, (PUCHAR)buf, DAV_SHA256_DIGEST_LENGTH, 0);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1448
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1449 // cleanup
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1450 cng_cleanup(ctx->hAlg, NULL, ctx->hHash, ctx->pbHashObject);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1451 free(ctx);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1452 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1453
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1454 DavKey* dav_pw2key(const char *password, const unsigned char *salt, int saltlen, int pwfunc, int enc) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1455 if(!password) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1456 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1457 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1458 size_t len = strlen(password);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1459 if(len == 0) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1460 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1461 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1462
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1463 // setup key data and length
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1464 unsigned char keydata[128];
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1465 int keylen = 32;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1466 switch(enc) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1467 case DAV_KEY_AES128: keylen = 16; break;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1468 case DAV_KEY_AES256: keylen = 32; break;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1469 default: return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1470 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1471
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1472 LPCWSTR algid;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1473 switch(pwfunc) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1474 case DAV_PWFUNC_PBKDF2_SHA256: algid = BCRYPT_SHA256_ALGORITHM; break;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1475 case DAV_PWFUNC_PBKDF2_SHA512: algid = BCRYPT_SHA512_ALGORITHM; break;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1476 default: return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1477 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1478
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1479 // open algorithm provider
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1480 BCRYPT_ALG_HANDLE hAlg;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1481 ULONG status = BCryptOpenAlgorithmProvider(&hAlg, algid, NULL, BCRYPT_ALG_HANDLE_HMAC_FLAG);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1482 if(status > 0) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1483 fprintf(stderr, "Error: dav_pw2key: BCryptOpenAlgorithmProvider failed: 0x%X\n", (unsigned int)status);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1484 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1485 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1486
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1487 // derive key
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1488 status = BCryptDeriveKeyPBKDF2(
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1489 hAlg,
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1490 (PUCHAR)password,
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1491 len,
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1492 (PUCHAR)salt,
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1493 saltlen,
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1494 DAV_CRYPTO_ITERATION_COUNT,
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1495 keydata,
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1496 128,
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1497 0);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1498
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1499 BCryptCloseAlgorithmProvider(hAlg,0);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1500
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1501 if(status) {
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1502 fprintf(stderr, "Error: dav_pw2key: BCryptDeriveKeyPBKDF2 failed: 0x%X\n", (unsigned int)status);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1503 return NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1504 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1505
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1506 // create DavKey with generated data
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1507 DavKey *key = malloc(sizeof(DavKey));
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1508 key->data = malloc(keylen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1509 key->length = keylen;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1510 key->name = NULL;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1511 key->type = enc;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1512 memcpy(key->data, keydata, keylen);
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1513 return key;
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1514 }
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1515 #endif
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1516
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1517
d405d2ac78e6 replace openssl on windows with cng/bcrypt
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 625
diff changeset
1518
747
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1519 CxBuffer* aes_encrypt_buffer(CxBuffer *in, DavKey *key) {
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1520 CxBuffer *encbuf = cxBufferCreate(NULL, in->size, cxDefaultAllocator, CX_BUFFER_FREE_CONTENTS|CX_BUFFER_AUTO_EXTEND);
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1521 if(!encbuf) {
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1522 return NULL;
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1523 }
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1524
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1525 AESEncrypter *enc = aes_encrypter_new(
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1526 key,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1527 in,
747
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1528 (dav_read_func)cxBufferRead,
478
baa63fef5c5c fixes redirects
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 470
diff changeset
1529 NULL);
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1530 if(!enc) {
747
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1531 cxBufferFree(encbuf);
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1532 return NULL;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1533 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1534
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1535 char buf[1024];
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1536 size_t r;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1537 while((r = aes_read(buf, 1, 1024, enc)) > 0) {
747
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1538 cxBufferWrite(buf, 1, r, encbuf);
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1539 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1540 aes_encrypter_close(enc);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1541
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1542 encbuf->pos = 0;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1543 return encbuf;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1544 }
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1545
747
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1546 CxBuffer* aes_decrypt_buffer(CxBuffer *in, DavKey *key) {
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1547 CxBuffer *decbuf = cxBufferCreate(NULL, in->size, cxDefaultAllocator, CX_BUFFER_FREE_CONTENTS|CX_BUFFER_AUTO_EXTEND);
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1548 if(!decbuf) {
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1549 return NULL;
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1550 }
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1551 AESDecrypter *dec = aes_decrypter_new(
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1552 key,
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1553 decbuf,
747
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1554 (dav_write_func)cxBufferWrite);
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1555 if(!dec) {
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1556 cxBufferFree(decbuf);
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1557 return NULL;
efbd59642577 ucx 3 update, basic dav commands work, most stuff is still broken
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 728
diff changeset
1558 }
470
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1559
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1560 aes_write(in->space, 1, in->size, dec);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1561 aes_decrypter_shutdown(dec);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1562 aes_decrypter_close(dec);
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1563 decbuf->pos = 0;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1564 return decbuf;
6bf798ad3aec adds encrypted password store
Olaf Wintermann <olaf.wintermann@gmail.com>
parents: 462
diff changeset
1565 }

mercurial