2 * Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
11 * DH low level APIs are deprecated for public use, but still ok for
14 #include "internal/deprecated.h"
16 #include <string.h> /* strcmp */
17 #include <openssl/core_dispatch.h>
18 #include <openssl/core_names.h>
19 #include <openssl/bn.h>
20 #include <openssl/err.h>
21 #include "prov/implementations.h"
22 #include "prov/providercommon.h"
23 #include "prov/provider_ctx.h"
24 #include "crypto/dh.h"
25 #include "internal/sizes.h"
27 static OSSL_FUNC_keymgmt_new_fn dh_newdata
;
28 static OSSL_FUNC_keymgmt_free_fn dh_freedata
;
29 static OSSL_FUNC_keymgmt_gen_init_fn dh_gen_init
;
30 static OSSL_FUNC_keymgmt_gen_init_fn dhx_gen_init
;
31 static OSSL_FUNC_keymgmt_gen_set_template_fn dh_gen_set_template
;
32 static OSSL_FUNC_keymgmt_gen_set_params_fn dh_gen_set_params
;
33 static OSSL_FUNC_keymgmt_gen_settable_params_fn dh_gen_settable_params
;
34 static OSSL_FUNC_keymgmt_gen_fn dh_gen
;
35 static OSSL_FUNC_keymgmt_gen_cleanup_fn dh_gen_cleanup
;
36 static OSSL_FUNC_keymgmt_load_fn dh_load
;
37 static OSSL_FUNC_keymgmt_get_params_fn dh_get_params
;
38 static OSSL_FUNC_keymgmt_gettable_params_fn dh_gettable_params
;
39 static OSSL_FUNC_keymgmt_set_params_fn dh_set_params
;
40 static OSSL_FUNC_keymgmt_settable_params_fn dh_settable_params
;
41 static OSSL_FUNC_keymgmt_has_fn dh_has
;
42 static OSSL_FUNC_keymgmt_match_fn dh_match
;
43 static OSSL_FUNC_keymgmt_validate_fn dh_validate
;
44 static OSSL_FUNC_keymgmt_import_fn dh_import
;
45 static OSSL_FUNC_keymgmt_import_types_fn dh_import_types
;
46 static OSSL_FUNC_keymgmt_export_fn dh_export
;
47 static OSSL_FUNC_keymgmt_export_types_fn dh_export_types
;
49 #define DH_POSSIBLE_SELECTIONS \
50 (OSSL_KEYMGMT_SELECT_KEYPAIR | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS)
55 FFC_PARAMS
*ffc_params
;
57 /* All these parameters are used for parameter generation only */
58 /* If there is a group name then the remaining parameters are not needed */
62 unsigned char *seed
; /* optional FIPS186-4 param for testing */
64 int gindex
; /* optional FIPS186-4 generator index (ignored if -1) */
65 int gen_type
; /* see dhtype2id */
66 int generator
; /* Used by DH_PARAMGEN_TYPE_GENERATOR in non fips mode only */
78 static int dh_gen_type_name2id_w_default(const char *name
, int type
)
80 if (strcmp(name
, "default") == 0) {
82 if (type
== DH_FLAG_TYPE_DHX
)
83 return DH_PARAMGEN_TYPE_FIPS_186_4
;
85 return DH_PARAMGEN_TYPE_GROUP
;
87 if (type
== DH_FLAG_TYPE_DHX
)
88 return DH_PARAMGEN_TYPE_FIPS_186_2
;
90 return DH_PARAMGEN_TYPE_GENERATOR
;
94 return dh_gen_type_name2id(name
);
97 static void *dh_newdata(void *provctx
)
101 if (ossl_prov_is_running()) {
102 dh
= dh_new_ex(PROV_LIBCTX_OF(provctx
));
104 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
105 DH_set_flags(dh
, DH_FLAG_TYPE_DH
);
111 static void *dhx_newdata(void *provctx
)
115 dh
= dh_new_ex(PROV_LIBCTX_OF(provctx
));
117 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
118 DH_set_flags(dh
, DH_FLAG_TYPE_DHX
);
123 static void dh_freedata(void *keydata
)
128 static int dh_has(const void *keydata
, int selection
)
130 const DH
*dh
= keydata
;
133 if (ossl_prov_is_running() && dh
!= NULL
) {
134 if ((selection
& DH_POSSIBLE_SELECTIONS
) != 0)
137 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
138 ok
= ok
&& (DH_get0_pub_key(dh
) != NULL
);
139 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
140 ok
= ok
&& (DH_get0_priv_key(dh
) != NULL
);
141 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0)
142 ok
= ok
&& (DH_get0_p(dh
) != NULL
&& DH_get0_g(dh
) != NULL
);
147 static int dh_match(const void *keydata1
, const void *keydata2
, int selection
)
149 const DH
*dh1
= keydata1
;
150 const DH
*dh2
= keydata2
;
153 if (!ossl_prov_is_running())
156 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
157 ok
= ok
&& BN_cmp(DH_get0_pub_key(dh1
), DH_get0_pub_key(dh2
)) == 0;
158 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
159 ok
= ok
&& BN_cmp(DH_get0_priv_key(dh1
), DH_get0_priv_key(dh2
)) == 0;
160 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0) {
161 FFC_PARAMS
*dhparams1
= dh_get0_params((DH
*)dh1
);
162 FFC_PARAMS
*dhparams2
= dh_get0_params((DH
*)dh2
);
164 ok
= ok
&& ossl_ffc_params_cmp(dhparams1
, dhparams2
, 1);
169 static int dh_import(void *keydata
, int selection
, const OSSL_PARAM params
[])
174 if (!ossl_prov_is_running() || dh
== NULL
)
177 if ((selection
& DH_POSSIBLE_SELECTIONS
) == 0)
180 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
181 ok
= ok
&& dh_params_fromdata(dh
, params
);
183 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
184 ok
= ok
&& dh_key_fromdata(dh
, params
);
189 static int dh_export(void *keydata
, int selection
, OSSL_CALLBACK
*param_cb
,
193 OSSL_PARAM_BLD
*tmpl
= NULL
;
194 OSSL_PARAM
*params
= NULL
;
197 if (!ossl_prov_is_running() || dh
== NULL
)
200 tmpl
= OSSL_PARAM_BLD_new();
204 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
205 ok
= ok
&& dh_params_todata(dh
, tmpl
, NULL
);
206 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
207 ok
= ok
&& dh_key_todata(dh
, tmpl
, NULL
);
210 || (params
= OSSL_PARAM_BLD_to_param(tmpl
)) == NULL
) {
214 ok
= param_cb(params
, cbarg
);
215 OSSL_PARAM_BLD_free_params(params
);
217 OSSL_PARAM_BLD_free(tmpl
);
221 /* IMEXPORT = IMPORT + EXPORT */
223 # define DH_IMEXPORTABLE_PARAMETERS \
224 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_P, NULL, 0), \
225 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_Q, NULL, 0), \
226 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_G, NULL, 0), \
227 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_COFACTOR, NULL, 0), \
228 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_GINDEX, NULL), \
229 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_PCOUNTER, NULL), \
230 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_H, NULL), \
231 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_FFC_SEED, NULL, 0), \
232 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME, NULL, 0), \
233 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_DH_PRIV_LEN, NULL, 0)
234 # define DH_IMEXPORTABLE_PUBLIC_KEY \
235 OSSL_PARAM_BN(OSSL_PKEY_PARAM_PUB_KEY, NULL, 0)
236 # define DH_IMEXPORTABLE_PRIVATE_KEY \
237 OSSL_PARAM_BN(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0)
238 static const OSSL_PARAM dh_all_types
[] = {
239 DH_IMEXPORTABLE_PARAMETERS
,
240 DH_IMEXPORTABLE_PUBLIC_KEY
,
241 DH_IMEXPORTABLE_PRIVATE_KEY
,
244 static const OSSL_PARAM dh_parameter_types
[] = {
245 DH_IMEXPORTABLE_PARAMETERS
,
248 static const OSSL_PARAM dh_key_types
[] = {
249 DH_IMEXPORTABLE_PUBLIC_KEY
,
250 DH_IMEXPORTABLE_PRIVATE_KEY
,
253 static const OSSL_PARAM
*dh_types
[] = {
254 NULL
, /* Index 0 = none of them */
255 dh_parameter_types
, /* Index 1 = parameter types */
256 dh_key_types
, /* Index 2 = key types */
257 dh_all_types
/* Index 3 = 1 + 2 */
260 static const OSSL_PARAM
*dh_imexport_types(int selection
)
264 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
266 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
268 return dh_types
[type_select
];
271 static const OSSL_PARAM
*dh_import_types(int selection
)
273 return dh_imexport_types(selection
);
276 static const OSSL_PARAM
*dh_export_types(int selection
)
278 return dh_imexport_types(selection
);
281 static ossl_inline
int dh_get_params(void *key
, OSSL_PARAM params
[])
286 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_BITS
)) != NULL
287 && !OSSL_PARAM_set_int(p
, DH_bits(dh
)))
289 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_SECURITY_BITS
)) != NULL
290 && !OSSL_PARAM_set_int(p
, DH_security_bits(dh
)))
292 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_MAX_SIZE
)) != NULL
293 && !OSSL_PARAM_set_int(p
, DH_size(dh
)))
295 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY
)) != NULL
) {
296 if (p
->data_type
!= OSSL_PARAM_OCTET_STRING
)
298 p
->return_size
= dh_key2buf(dh
, (unsigned char **)&p
->data
,
300 if (p
->return_size
== 0)
304 return dh_params_todata(dh
, NULL
, params
)
305 && dh_key_todata(dh
, NULL
, params
);
308 static const OSSL_PARAM dh_params
[] = {
309 OSSL_PARAM_int(OSSL_PKEY_PARAM_BITS
, NULL
),
310 OSSL_PARAM_int(OSSL_PKEY_PARAM_SECURITY_BITS
, NULL
),
311 OSSL_PARAM_int(OSSL_PKEY_PARAM_MAX_SIZE
, NULL
),
312 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY
, NULL
, 0),
313 DH_IMEXPORTABLE_PARAMETERS
,
314 DH_IMEXPORTABLE_PUBLIC_KEY
,
315 DH_IMEXPORTABLE_PRIVATE_KEY
,
319 static const OSSL_PARAM
*dh_gettable_params(void *provctx
)
324 static const OSSL_PARAM dh_known_settable_params
[] = {
325 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY
, NULL
, 0),
329 static const OSSL_PARAM
*dh_settable_params(void *provctx
)
331 return dh_known_settable_params
;
334 static int dh_set_params(void *key
, const OSSL_PARAM params
[])
339 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY
);
341 && (p
->data_type
!= OSSL_PARAM_OCTET_STRING
342 || !dh_buf2key(dh
, p
->data
, p
->data_size
)))
348 static int dh_validate_public(const DH
*dh
, int checktype
)
350 const BIGNUM
*pub_key
= NULL
;
353 DH_get0_key(dh
, &pub_key
, NULL
);
357 /* The partial test is only valid for named group's with q = (p - 1) / 2 */
358 if (checktype
== OSSL_KEYMGMT_VALIDATE_QUICK_CHECK
359 && ossl_dh_is_named_safe_prime_group(dh
))
360 return dh_check_pub_key_partial(dh
, pub_key
, &res
);
362 return DH_check_pub_key(dh
, pub_key
, &res
);
365 static int dh_validate_private(const DH
*dh
)
368 const BIGNUM
*priv_key
= NULL
;
370 DH_get0_key(dh
, NULL
, &priv_key
);
371 if (priv_key
== NULL
)
373 return dh_check_priv_key(dh
, priv_key
, &status
);;
376 static int dh_validate(const void *keydata
, int selection
, int checktype
)
378 const DH
*dh
= keydata
;
381 if (!ossl_prov_is_running())
384 if ((selection
& DH_POSSIBLE_SELECTIONS
) != 0)
387 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0) {
389 * Both of these functions check parameters. DH_check_params_ex()
390 * performs a lightweight check (e.g. it does not check that p is a
393 if (checktype
== OSSL_KEYMGMT_VALIDATE_QUICK_CHECK
)
394 ok
= ok
&& DH_check_params_ex(dh
);
396 ok
= ok
&& DH_check_ex(dh
);
399 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
400 ok
= ok
&& dh_validate_public(dh
, checktype
);
402 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
403 ok
= ok
&& dh_validate_private(dh
);
405 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
)
406 == OSSL_KEYMGMT_SELECT_KEYPAIR
)
407 ok
= ok
&& dh_check_pairwise(dh
);
411 static void *dh_gen_init_base(void *provctx
, int selection
, int type
)
413 OSSL_LIB_CTX
*libctx
= PROV_LIBCTX_OF(provctx
);
414 struct dh_gen_ctx
*gctx
= NULL
;
416 if (!ossl_prov_is_running())
419 if ((selection
& (OSSL_KEYMGMT_SELECT_KEYPAIR
420 | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
)) == 0)
423 if ((gctx
= OPENSSL_zalloc(sizeof(*gctx
))) != NULL
) {
424 gctx
->selection
= selection
;
425 gctx
->libctx
= libctx
;
430 gctx
->gen_type
= (type
== DH_FLAG_TYPE_DHX
)
431 ? DH_PARAMGEN_TYPE_FIPS_186_4
432 : DH_PARAMGEN_TYPE_GROUP
;
434 gctx
->gen_type
= (type
== DH_FLAG_TYPE_DHX
)
435 ? DH_PARAMGEN_TYPE_FIPS_186_2
436 : DH_PARAMGEN_TYPE_GENERATOR
;
441 gctx
->generator
= DH_GENERATOR_2
;
442 gctx
->dh_type
= type
;
447 static void *dh_gen_init(void *provctx
, int selection
)
449 return dh_gen_init_base(provctx
, selection
, DH_FLAG_TYPE_DH
);
452 static void *dhx_gen_init(void *provctx
, int selection
)
454 return dh_gen_init_base(provctx
, selection
, DH_FLAG_TYPE_DHX
);
457 static int dh_gen_set_template(void *genctx
, void *templ
)
459 struct dh_gen_ctx
*gctx
= genctx
;
462 if (!ossl_prov_is_running() || gctx
== NULL
|| dh
== NULL
)
464 gctx
->ffc_params
= dh_get0_params(dh
);
468 static int dh_set_gen_seed(struct dh_gen_ctx
*gctx
, unsigned char *seed
,
471 OPENSSL_clear_free(gctx
->seed
, gctx
->seedlen
);
474 if (seed
!= NULL
&& seedlen
> 0) {
475 gctx
->seed
= OPENSSL_memdup(seed
, seedlen
);
476 if (gctx
->seed
== NULL
)
478 gctx
->seedlen
= seedlen
;
483 static int dh_gen_set_params(void *genctx
, const OSSL_PARAM params
[])
485 struct dh_gen_ctx
*gctx
= genctx
;
491 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_TYPE
);
493 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
494 || ((gctx
->gen_type
=
495 dh_gen_type_name2id_w_default(p
->data
,
496 gctx
->dh_type
)) == -1)) {
497 ERR_raise(ERR_LIB_PROV
, ERR_R_PASSED_INVALID_ARGUMENT
);
501 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_GROUP_NAME
);
503 const DH_NAMED_GROUP
*group
= NULL
;
505 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
506 || (group
= ossl_ffc_name_to_dh_named_group(p
->data
)) == NULL
507 || ((gctx
->group_nid
=
508 ossl_ffc_named_group_get_uid(group
)) == NID_undef
)) {
509 ERR_raise(ERR_LIB_PROV
, ERR_R_PASSED_INVALID_ARGUMENT
);
512 gctx
->gen_type
= DH_PARAMGEN_TYPE_GROUP
;
514 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_DH_GENERATOR
);
515 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->generator
))
517 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_GINDEX
);
518 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->gindex
))
520 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_PCOUNTER
);
521 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->pcounter
))
523 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_H
);
524 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->hindex
))
526 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_SEED
);
528 && (p
->data_type
!= OSSL_PARAM_OCTET_STRING
529 || !dh_set_gen_seed(gctx
, p
->data
, p
->data_size
)))
532 if ((p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_PBITS
)) != NULL
533 && !OSSL_PARAM_get_size_t(p
, &gctx
->pbits
))
535 if ((p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_QBITS
)) != NULL
536 && !OSSL_PARAM_get_size_t(p
, &gctx
->qbits
))
538 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_DIGEST
);
540 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
)
542 OPENSSL_free(gctx
->mdname
);
543 gctx
->mdname
= OPENSSL_strdup(p
->data
);
544 if (gctx
->mdname
== NULL
)
547 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_DIGEST_PROPS
);
549 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
)
551 OPENSSL_free(gctx
->mdprops
);
552 gctx
->mdprops
= OPENSSL_strdup(p
->data
);
553 if (gctx
->mdprops
== NULL
)
556 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_DH_PRIV_LEN
);
557 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->priv_len
))
562 static const OSSL_PARAM
*dh_gen_settable_params(void *provctx
)
564 static OSSL_PARAM settable
[] = {
565 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME
, NULL
, 0),
566 OSSL_PARAM_int(OSSL_PKEY_PARAM_DH_PRIV_LEN
, NULL
),
567 OSSL_PARAM_int(OSSL_PKEY_PARAM_DH_GENERATOR
, NULL
),
568 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_TYPE
, NULL
, 0),
569 OSSL_PARAM_size_t(OSSL_PKEY_PARAM_FFC_PBITS
, NULL
),
570 OSSL_PARAM_size_t(OSSL_PKEY_PARAM_FFC_QBITS
, NULL
),
571 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_DIGEST
, NULL
, 0),
572 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_DIGEST_PROPS
, NULL
, 0),
573 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_GINDEX
, NULL
),
574 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_FFC_SEED
, NULL
, 0),
575 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_PCOUNTER
, NULL
),
576 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_H
, NULL
),
582 static int dh_gencb(int p
, int n
, BN_GENCB
*cb
)
584 struct dh_gen_ctx
*gctx
= BN_GENCB_get_arg(cb
);
585 OSSL_PARAM params
[] = { OSSL_PARAM_END
, OSSL_PARAM_END
, OSSL_PARAM_END
};
587 params
[0] = OSSL_PARAM_construct_int(OSSL_GEN_PARAM_POTENTIAL
, &p
);
588 params
[1] = OSSL_PARAM_construct_int(OSSL_GEN_PARAM_ITERATION
, &n
);
590 return gctx
->cb(params
, gctx
->cbarg
);
593 static void *dh_gen(void *genctx
, OSSL_CALLBACK
*osslcb
, void *cbarg
)
596 struct dh_gen_ctx
*gctx
= genctx
;
598 BN_GENCB
*gencb
= NULL
;
601 if (!ossl_prov_is_running() || gctx
== NULL
)
604 /* For parameter generation - If there is a group name just create it */
605 if (gctx
->gen_type
== DH_PARAMGEN_TYPE_GROUP
606 && gctx
->ffc_params
== NULL
) {
607 /* Select a named group if there is not one already */
608 if (gctx
->group_nid
== NID_undef
)
609 gctx
->group_nid
= dh_get_named_group_uid_from_size(gctx
->pbits
);
610 if (gctx
->group_nid
== NID_undef
)
612 dh
= dh_new_by_nid_ex(gctx
->libctx
, gctx
->group_nid
);
615 ffc
= dh_get0_params(dh
);
617 dh
= dh_new_ex(gctx
->libctx
);
620 ffc
= dh_get0_params(dh
);
622 /* Copy the template value if one was passed */
623 if (gctx
->ffc_params
!= NULL
624 && !ossl_ffc_params_copy(ffc
, gctx
->ffc_params
))
627 if (!ossl_ffc_params_set_seed(ffc
, gctx
->seed
, gctx
->seedlen
))
629 if (gctx
->gindex
!= -1) {
630 ossl_ffc_params_set_gindex(ffc
, gctx
->gindex
);
631 if (gctx
->pcounter
!= -1)
632 ossl_ffc_params_set_pcounter(ffc
, gctx
->pcounter
);
633 } else if (gctx
->hindex
!= 0) {
634 ossl_ffc_params_set_h(ffc
, gctx
->hindex
);
636 if (gctx
->mdname
!= NULL
) {
637 if (!ossl_ffc_set_digest(ffc
, gctx
->mdname
, gctx
->mdprops
))
642 gencb
= BN_GENCB_new();
644 BN_GENCB_set(gencb
, dh_gencb
, genctx
);
646 if ((gctx
->selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0) {
648 * NOTE: The old safe prime generator code is not used in fips mode,
649 * (i.e internally it ignores the generator and chooses a named
650 * group based on pbits.
652 if (gctx
->gen_type
== DH_PARAMGEN_TYPE_GENERATOR
)
653 ret
= DH_generate_parameters_ex(dh
, gctx
->pbits
,
654 gctx
->generator
, gencb
);
656 ret
= dh_generate_ffc_parameters(dh
, gctx
->gen_type
, gctx
->pbits
,
663 if ((gctx
->selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0) {
664 if (ffc
->p
== NULL
|| ffc
->g
== NULL
)
666 if (gctx
->priv_len
> 0)
667 DH_set_length(dh
, (long)gctx
->priv_len
);
668 ossl_ffc_params_enable_flags(ffc
, FFC_PARAM_FLAG_VALIDATE_LEGACY
,
669 gctx
->gen_type
== DH_PARAMGEN_TYPE_FIPS_186_2
);
670 if (DH_generate_key(dh
) <= 0)
673 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
674 DH_set_flags(dh
, gctx
->dh_type
);
682 BN_GENCB_free(gencb
);
686 static void dh_gen_cleanup(void *genctx
)
688 struct dh_gen_ctx
*gctx
= genctx
;
693 OPENSSL_free(gctx
->mdname
);
694 OPENSSL_free(gctx
->mdprops
);
695 OPENSSL_clear_free(gctx
->seed
, gctx
->seedlen
);
699 void *dh_load(const void *reference
, size_t reference_sz
)
703 if (ossl_prov_is_running() && reference_sz
== sizeof(dh
)) {
704 /* The contents of the reference is the address to our object */
705 dh
= *(DH
**)reference
;
706 /* We grabbed, so we detach it */
707 *(DH
**)reference
= NULL
;
713 const OSSL_DISPATCH ossl_dh_keymgmt_functions
[] = {
714 { OSSL_FUNC_KEYMGMT_NEW
, (void (*)(void))dh_newdata
},
715 { OSSL_FUNC_KEYMGMT_GEN_INIT
, (void (*)(void))dh_gen_init
},
716 { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE
, (void (*)(void))dh_gen_set_template
},
717 { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS
, (void (*)(void))dh_gen_set_params
},
718 { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS
,
719 (void (*)(void))dh_gen_settable_params
},
720 { OSSL_FUNC_KEYMGMT_GEN
, (void (*)(void))dh_gen
},
721 { OSSL_FUNC_KEYMGMT_GEN_CLEANUP
, (void (*)(void))dh_gen_cleanup
},
722 { OSSL_FUNC_KEYMGMT_LOAD
, (void (*)(void))dh_load
},
723 { OSSL_FUNC_KEYMGMT_FREE
, (void (*)(void))dh_freedata
},
724 { OSSL_FUNC_KEYMGMT_GET_PARAMS
, (void (*) (void))dh_get_params
},
725 { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS
, (void (*) (void))dh_gettable_params
},
726 { OSSL_FUNC_KEYMGMT_SET_PARAMS
, (void (*) (void))dh_set_params
},
727 { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS
, (void (*) (void))dh_settable_params
},
728 { OSSL_FUNC_KEYMGMT_HAS
, (void (*)(void))dh_has
},
729 { OSSL_FUNC_KEYMGMT_MATCH
, (void (*)(void))dh_match
},
730 { OSSL_FUNC_KEYMGMT_VALIDATE
, (void (*)(void))dh_validate
},
731 { OSSL_FUNC_KEYMGMT_IMPORT
, (void (*)(void))dh_import
},
732 { OSSL_FUNC_KEYMGMT_IMPORT_TYPES
, (void (*)(void))dh_import_types
},
733 { OSSL_FUNC_KEYMGMT_EXPORT
, (void (*)(void))dh_export
},
734 { OSSL_FUNC_KEYMGMT_EXPORT_TYPES
, (void (*)(void))dh_export_types
},
738 /* For any DH key, we use the "DH" algorithms regardless of sub-type. */
739 static const char *dhx_query_operation_name(int operation_id
)
744 const OSSL_DISPATCH ossl_dhx_keymgmt_functions
[] = {
745 { OSSL_FUNC_KEYMGMT_NEW
, (void (*)(void))dhx_newdata
},
746 { OSSL_FUNC_KEYMGMT_GEN_INIT
, (void (*)(void))dhx_gen_init
},
747 { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE
, (void (*)(void))dh_gen_set_template
},
748 { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS
, (void (*)(void))dh_gen_set_params
},
749 { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS
,
750 (void (*)(void))dh_gen_settable_params
},
751 { OSSL_FUNC_KEYMGMT_GEN
, (void (*)(void))dh_gen
},
752 { OSSL_FUNC_KEYMGMT_GEN_CLEANUP
, (void (*)(void))dh_gen_cleanup
},
753 { OSSL_FUNC_KEYMGMT_LOAD
, (void (*)(void))dh_load
},
754 { OSSL_FUNC_KEYMGMT_FREE
, (void (*)(void))dh_freedata
},
755 { OSSL_FUNC_KEYMGMT_GET_PARAMS
, (void (*) (void))dh_get_params
},
756 { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS
, (void (*) (void))dh_gettable_params
},
757 { OSSL_FUNC_KEYMGMT_SET_PARAMS
, (void (*) (void))dh_set_params
},
758 { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS
, (void (*) (void))dh_settable_params
},
759 { OSSL_FUNC_KEYMGMT_HAS
, (void (*)(void))dh_has
},
760 { OSSL_FUNC_KEYMGMT_MATCH
, (void (*)(void))dh_match
},
761 { OSSL_FUNC_KEYMGMT_VALIDATE
, (void (*)(void))dh_validate
},
762 { OSSL_FUNC_KEYMGMT_IMPORT
, (void (*)(void))dh_import
},
763 { OSSL_FUNC_KEYMGMT_IMPORT_TYPES
, (void (*)(void))dh_import_types
},
764 { OSSL_FUNC_KEYMGMT_EXPORT
, (void (*)(void))dh_export
},
765 { OSSL_FUNC_KEYMGMT_EXPORT_TYPES
, (void (*)(void))dh_export_types
},
766 { OSSL_FUNC_KEYMGMT_QUERY_OPERATION_NAME
,
767 (void (*)(void))dhx_query_operation_name
},