1 /**********************************************************************
3 * Copyright (c) 2005-2006 Cryptocom LTD *
4 * This file is distributed under the same license as OpenSSL *
6 * Implementation of RFC 4490/4491 ASN1 method *
8 * Requires OpenSSL 0.9.9 for compilation *
9 **********************************************************************/
11 #include <openssl/crypto.h>
12 #include <openssl/err.h>
13 #include <openssl/engine.h>
14 #include <openssl/evp.h>
15 #include <openssl/asn1.h>
16 #ifndef OPENSSL_NO_CMS
17 # include <openssl/cms.h>
19 #include "gost_params.h"
21 #include "e_gost_err.h"
23 int gost94_nid_by_params(DSA
*p
)
25 R3410_params
*gost_params
;
27 for (gost_params
= R3410_paramset
; gost_params
->q
!= NULL
; gost_params
++) {
28 BN_dec2bn(&q
, gost_params
->q
);
29 if (!BN_cmp(q
, p
->q
)) {
31 return gost_params
->nid
;
38 static ASN1_STRING
*encode_gost_algor_params(const EVP_PKEY
*key
)
40 ASN1_STRING
*params
= ASN1_STRING_new();
41 GOST_KEY_PARAMS
*gkp
= GOST_KEY_PARAMS_new();
42 int pkey_param_nid
= NID_undef
;
44 if (!params
|| !gkp
) {
45 GOSTerr(GOST_F_ENCODE_GOST_ALGOR_PARAMS
, ERR_R_MALLOC_FAILURE
);
46 ASN1_STRING_free(params
);
50 switch (EVP_PKEY_base_id(key
)) {
51 case NID_id_GostR3410_2001
:
53 EC_GROUP_get_curve_name(EC_KEY_get0_group
54 (EVP_PKEY_get0((EVP_PKEY
*)key
)));
56 case NID_id_GostR3410_94
:
58 (int)gost94_nid_by_params(EVP_PKEY_get0((EVP_PKEY
*)key
));
59 if (pkey_param_nid
== NID_undef
) {
60 GOSTerr(GOST_F_ENCODE_GOST_ALGOR_PARAMS
,
61 GOST_R_INVALID_GOST94_PARMSET
);
62 ASN1_STRING_free(params
);
68 gkp
->key_params
= OBJ_nid2obj(pkey_param_nid
);
69 gkp
->hash_params
= OBJ_nid2obj(NID_id_GostR3411_94_CryptoProParamSet
);
71 * gkp->cipher_params = OBJ_nid2obj(cipher_param_nid);
73 params
->length
= i2d_GOST_KEY_PARAMS(gkp
, ¶ms
->data
);
74 if (params
->length
<= 0) {
75 GOSTerr(GOST_F_ENCODE_GOST_ALGOR_PARAMS
, ERR_R_MALLOC_FAILURE
);
76 ASN1_STRING_free(params
);
80 params
->type
= V_ASN1_SEQUENCE
;
82 GOST_KEY_PARAMS_free(gkp
);
87 * Parses GOST algorithm parameters from X509_ALGOR and modifies pkey setting
90 static int decode_gost_algor_params(EVP_PKEY
*pkey
, X509_ALGOR
*palg
)
92 ASN1_OBJECT
*palg_obj
= NULL
;
93 int ptype
= V_ASN1_UNDEF
;
94 int pkey_nid
= NID_undef
, param_nid
= NID_undef
;
96 ASN1_STRING
*pval
= NULL
;
97 const unsigned char *p
;
98 GOST_KEY_PARAMS
*gkp
= NULL
;
100 X509_ALGOR_get0(&palg_obj
, &ptype
, &_pval
, palg
);
102 if (ptype
!= V_ASN1_SEQUENCE
) {
103 GOSTerr(GOST_F_DECODE_GOST_ALGOR_PARAMS
,
104 GOST_R_BAD_KEY_PARAMETERS_FORMAT
);
108 pkey_nid
= OBJ_obj2nid(palg_obj
);
110 gkp
= d2i_GOST_KEY_PARAMS(NULL
, &p
, pval
->length
);
112 GOSTerr(GOST_F_DECODE_GOST_ALGOR_PARAMS
,
113 GOST_R_BAD_PKEY_PARAMETERS_FORMAT
);
116 param_nid
= OBJ_obj2nid(gkp
->key_params
);
117 GOST_KEY_PARAMS_free(gkp
);
118 if (!EVP_PKEY_set_type(pkey
, pkey_nid
)) {
119 GOSTerr(GOST_F_DECODE_GOST_ALGOR_PARAMS
, ERR_R_INTERNAL_ERROR
);
123 case NID_id_GostR3410_94
:
125 DSA
*dsa
= EVP_PKEY_get0(pkey
);
128 if (!EVP_PKEY_assign(pkey
, pkey_nid
, dsa
))
131 if (!fill_GOST94_params(dsa
, param_nid
))
135 case NID_id_GostR3410_2001
:
137 EC_KEY
*ec
= EVP_PKEY_get0(pkey
);
140 if (!EVP_PKEY_assign(pkey
, pkey_nid
, ec
))
143 if (!fill_GOST2001_params(ec
, param_nid
))
151 static int gost_set_priv_key(EVP_PKEY
*pkey
, BIGNUM
*priv
)
153 switch (EVP_PKEY_base_id(pkey
)) {
154 case NID_id_GostR3410_94
:
156 DSA
*dsa
= EVP_PKEY_get0(pkey
);
159 EVP_PKEY_assign(pkey
, EVP_PKEY_base_id(pkey
), dsa
);
161 dsa
->priv_key
= BN_dup(priv
);
162 if (!EVP_PKEY_missing_parameters(pkey
))
163 gost94_compute_public(dsa
);
166 case NID_id_GostR3410_2001
:
168 EC_KEY
*ec
= EVP_PKEY_get0(pkey
);
171 EVP_PKEY_assign(pkey
, EVP_PKEY_base_id(pkey
), ec
);
173 if (!EC_KEY_set_private_key(ec
, priv
))
175 if (!EVP_PKEY_missing_parameters(pkey
))
176 gost2001_compute_public(ec
);
183 BIGNUM
*gost_get0_priv_key(const EVP_PKEY
*pkey
)
185 switch (EVP_PKEY_base_id(pkey
)) {
186 case NID_id_GostR3410_94
:
188 DSA
*dsa
= EVP_PKEY_get0((EVP_PKEY
*)pkey
);
194 return dsa
->priv_key
;
196 case NID_id_GostR3410_2001
:
198 EC_KEY
*ec
= EVP_PKEY_get0((EVP_PKEY
*)pkey
);
203 if (!(priv
= EC_KEY_get0_private_key(ec
)))
205 return (BIGNUM
*)priv
;
211 static int pkey_ctrl_gost(EVP_PKEY
*pkey
, int op
, long arg1
, void *arg2
)
214 case ASN1_PKEY_CTRL_PKCS7_SIGN
:
216 X509_ALGOR
*alg1
= NULL
, *alg2
= NULL
;
217 int nid
= EVP_PKEY_base_id(pkey
);
218 PKCS7_SIGNER_INFO_get0_algs((PKCS7_SIGNER_INFO
*)arg2
,
220 X509_ALGOR_set0(alg1
, OBJ_nid2obj(NID_id_GostR3411_94
),
222 if (nid
== NID_undef
) {
225 X509_ALGOR_set0(alg2
, OBJ_nid2obj(nid
), V_ASN1_NULL
, 0);
228 #ifndef OPENSSL_NO_CMS
229 case ASN1_PKEY_CTRL_CMS_SIGN
:
231 X509_ALGOR
*alg1
= NULL
, *alg2
= NULL
;
232 int nid
= EVP_PKEY_base_id(pkey
);
233 CMS_SignerInfo_get0_algs((CMS_SignerInfo
*)arg2
,
234 NULL
, NULL
, &alg1
, &alg2
);
235 X509_ALGOR_set0(alg1
, OBJ_nid2obj(NID_id_GostR3411_94
),
237 if (nid
== NID_undef
) {
240 X509_ALGOR_set0(alg2
, OBJ_nid2obj(nid
), V_ASN1_NULL
, 0);
244 case ASN1_PKEY_CTRL_PKCS7_ENCRYPT
:
247 ASN1_STRING
*params
= encode_gost_algor_params(pkey
);
251 PKCS7_RECIP_INFO_get0_alg((PKCS7_RECIP_INFO
*)arg2
, &alg
);
252 X509_ALGOR_set0(alg
, OBJ_nid2obj(pkey
->type
),
253 V_ASN1_SEQUENCE
, params
);
256 #ifndef OPENSSL_NO_CMS
257 case ASN1_PKEY_CTRL_CMS_ENVELOPE
:
259 X509_ALGOR
*alg
= NULL
;
260 ASN1_STRING
*params
= encode_gost_algor_params(pkey
);
264 CMS_RecipientInfo_ktri_get0_algs((CMS_RecipientInfo
*)arg2
, NULL
,
266 X509_ALGOR_set0(alg
, OBJ_nid2obj(pkey
->type
), V_ASN1_SEQUENCE
,
271 case ASN1_PKEY_CTRL_DEFAULT_MD_NID
:
272 *(int *)arg2
= NID_id_GostR3411_94
;
279 /* --------------------- free functions * ------------------------------*/
280 static void pkey_free_gost94(EVP_PKEY
*key
)
282 DSA_free(key
->pkey
.dsa
);
285 static void pkey_free_gost01(EVP_PKEY
*key
)
287 EC_KEY_free(key
->pkey
.ec
);
290 /* ------------------ private key functions -----------------------------*/
291 static int priv_decode_gost(EVP_PKEY
*pk
, PKCS8_PRIV_KEY_INFO
*p8inf
)
293 const unsigned char *pkey_buf
= NULL
, *p
= NULL
;
295 BIGNUM
*pk_num
= NULL
;
297 X509_ALGOR
*palg
= NULL
;
298 ASN1_OBJECT
*palg_obj
= NULL
;
299 ASN1_INTEGER
*priv_key
= NULL
;
301 if (!PKCS8_pkey_get0(&palg_obj
, &pkey_buf
, &priv_len
, &palg
, p8inf
))
304 if (!decode_gost_algor_params(pk
, palg
)) {
307 if (V_ASN1_OCTET_STRING
== *p
) {
308 /* New format - Little endian octet string */
309 unsigned char rev_buf
[32];
311 ASN1_OCTET_STRING
*s
= d2i_ASN1_OCTET_STRING(NULL
, &p
, priv_len
);
312 if (!s
|| s
->length
!= 32) {
313 GOSTerr(GOST_F_PRIV_DECODE_GOST
, EVP_R_DECODE_ERROR
);
316 for (i
= 0; i
< 32; i
++) {
317 rev_buf
[31 - i
] = s
->data
[i
];
320 pk_num
= getbnfrombuf(rev_buf
, 32);
322 priv_key
= d2i_ASN1_INTEGER(NULL
, &p
, priv_len
);
325 ret
= ((pk_num
= ASN1_INTEGER_to_BN(priv_key
, NULL
)) != NULL
);
326 ASN1_INTEGER_free(priv_key
);
328 GOSTerr(GOST_F_PRIV_DECODE_GOST
, EVP_R_DECODE_ERROR
);
333 ret
= gost_set_priv_key(pk
, pk_num
);
338 /* ----------------------------------------------------------------------*/
339 static int priv_encode_gost(PKCS8_PRIV_KEY_INFO
*p8
, const EVP_PKEY
*pk
)
341 ASN1_OBJECT
*algobj
= OBJ_nid2obj(EVP_PKEY_base_id(pk
));
342 ASN1_STRING
*params
= encode_gost_algor_params(pk
);
343 unsigned char *priv_buf
= NULL
;
346 ASN1_INTEGER
*asn1key
= NULL
;
350 asn1key
= BN_to_ASN1_INTEGER(gost_get0_priv_key(pk
), NULL
);
351 priv_len
= i2d_ASN1_INTEGER(asn1key
, &priv_buf
);
352 ASN1_INTEGER_free(asn1key
);
353 return PKCS8_pkey_set0(p8
, algobj
, 0, V_ASN1_SEQUENCE
, params
,
357 /* --------- printing keys --------------------------------*/
358 static int print_gost_94(BIO
*out
, const EVP_PKEY
*pkey
, int indent
,
359 ASN1_PCTX
*pctx
, int type
)
361 int param_nid
= NID_undef
;
366 if (!BIO_indent(out
, indent
, 128))
368 BIO_printf(out
, "Private key: ");
369 key
= gost_get0_priv_key(pkey
);
371 BIO_printf(out
, "<undefined>");
374 BIO_printf(out
, "\n");
379 pubkey
= ((DSA
*)EVP_PKEY_get0((EVP_PKEY
*)pkey
))->pub_key
;
380 BIO_indent(out
, indent
, 128);
381 BIO_printf(out
, "Public key: ");
382 BN_print(out
, pubkey
);
383 BIO_printf(out
, "\n");
386 param_nid
= gost94_nid_by_params(EVP_PKEY_get0((EVP_PKEY
*)pkey
));
387 BIO_indent(out
, indent
, 128);
388 BIO_printf(out
, "Parameter set: %s\n", OBJ_nid2ln(param_nid
));
392 static int param_print_gost94(BIO
*out
, const EVP_PKEY
*pkey
, int indent
,
395 return print_gost_94(out
, pkey
, indent
, pctx
, 0);
398 static int pub_print_gost94(BIO
*out
, const EVP_PKEY
*pkey
, int indent
,
401 return print_gost_94(out
, pkey
, indent
, pctx
, 1);
404 static int priv_print_gost94(BIO
*out
, const EVP_PKEY
*pkey
, int indent
,
407 return print_gost_94(out
, pkey
, indent
, pctx
, 2);
410 static int print_gost_01(BIO
*out
, const EVP_PKEY
*pkey
, int indent
,
411 ASN1_PCTX
*pctx
, int type
)
413 int param_nid
= NID_undef
;
417 if (!BIO_indent(out
, indent
, 128))
419 BIO_printf(out
, "Private key: ");
420 key
= gost_get0_priv_key(pkey
);
422 BIO_printf(out
, "<undefined)");
425 BIO_printf(out
, "\n");
428 BN_CTX
*ctx
= BN_CTX_new();
430 const EC_POINT
*pubkey
;
431 const EC_GROUP
*group
;
434 GOSTerr(GOST_F_PRINT_GOST_01
, ERR_R_MALLOC_FAILURE
);
441 EC_KEY_get0_public_key((EC_KEY
*)EVP_PKEY_get0((EVP_PKEY
*)pkey
));
442 group
= EC_KEY_get0_group((EC_KEY
*)EVP_PKEY_get0((EVP_PKEY
*)pkey
));
443 if (!EC_POINT_get_affine_coordinates_GFp(group
, pubkey
, X
, Y
, ctx
)) {
444 GOSTerr(GOST_F_PRINT_GOST_01
, ERR_R_EC_LIB
);
448 if (!BIO_indent(out
, indent
, 128))
450 BIO_printf(out
, "Public key:\n");
451 if (!BIO_indent(out
, indent
+ 3, 128))
453 BIO_printf(out
, "X:");
455 BIO_printf(out
, "\n");
456 BIO_indent(out
, indent
+ 3, 128);
457 BIO_printf(out
, "Y:");
459 BIO_printf(out
, "\n");
465 EC_GROUP_get_curve_name(EC_KEY_get0_group
466 (EVP_PKEY_get0((EVP_PKEY
*)pkey
)));
467 if (!BIO_indent(out
, indent
, 128))
469 BIO_printf(out
, "Parameter set: %s\n", OBJ_nid2ln(param_nid
));
473 static int param_print_gost01(BIO
*out
, const EVP_PKEY
*pkey
, int indent
,
476 return print_gost_01(out
, pkey
, indent
, pctx
, 0);
479 static int pub_print_gost01(BIO
*out
, const EVP_PKEY
*pkey
, int indent
,
482 return print_gost_01(out
, pkey
, indent
, pctx
, 1);
485 static int priv_print_gost01(BIO
*out
, const EVP_PKEY
*pkey
, int indent
,
488 return print_gost_01(out
, pkey
, indent
, pctx
, 2);
491 /* ---------------------------------------------------------------------*/
492 static int param_missing_gost94(const EVP_PKEY
*pk
)
494 const DSA
*dsa
= EVP_PKEY_get0((EVP_PKEY
*)pk
);
502 static int param_missing_gost01(const EVP_PKEY
*pk
)
504 const EC_KEY
*ec
= EVP_PKEY_get0((EVP_PKEY
*)pk
);
507 if (!EC_KEY_get0_group(ec
))
512 static int param_copy_gost94(EVP_PKEY
*to
, const EVP_PKEY
*from
)
514 const DSA
*dfrom
= EVP_PKEY_get0((EVP_PKEY
*)from
);
515 DSA
*dto
= EVP_PKEY_get0(to
);
516 if (EVP_PKEY_base_id(from
) != EVP_PKEY_base_id(to
)) {
517 GOSTerr(GOST_F_PARAM_COPY_GOST94
, GOST_R_INCOMPATIBLE_ALGORITHMS
);
521 GOSTerr(GOST_F_PARAM_COPY_GOST94
, GOST_R_KEY_PARAMETERS_MISSING
);
526 EVP_PKEY_assign(to
, EVP_PKEY_base_id(from
), dto
);
528 #define COPYBIGNUM(a,b,x) if (a->x) BN_free(a->x); a->x=BN_dup(b->x);
529 COPYBIGNUM(dto
, dfrom
, p
)
530 COPYBIGNUM(dto
, dfrom
, q
)
531 COPYBIGNUM(dto
, dfrom
, g
)
534 gost94_compute_public(dto
);
538 static int param_copy_gost01(EVP_PKEY
*to
, const EVP_PKEY
*from
)
540 EC_KEY
*eto
= EVP_PKEY_get0(to
);
541 const EC_KEY
*efrom
= EVP_PKEY_get0((EVP_PKEY
*)from
);
542 if (EVP_PKEY_base_id(from
) != EVP_PKEY_base_id(to
)) {
543 GOSTerr(GOST_F_PARAM_COPY_GOST01
, GOST_R_INCOMPATIBLE_ALGORITHMS
);
547 GOSTerr(GOST_F_PARAM_COPY_GOST01
, GOST_R_KEY_PARAMETERS_MISSING
);
553 GOSTerr(GOST_F_PARAM_COPY_GOST01
, ERR_R_MALLOC_FAILURE
);
556 if (!EVP_PKEY_assign(to
, EVP_PKEY_base_id(from
), eto
)) {
557 GOSTerr(GOST_F_PARAM_COPY_GOST01
, ERR_R_INTERNAL_ERROR
);
561 if (!EC_KEY_set_group(eto
, EC_KEY_get0_group(efrom
))) {
562 GOSTerr(GOST_F_PARAM_COPY_GOST01
, ERR_R_INTERNAL_ERROR
);
565 if (EC_KEY_get0_private_key(eto
)) {
566 gost2001_compute_public(eto
);
571 static int param_cmp_gost94(const EVP_PKEY
*a
, const EVP_PKEY
*b
)
573 const DSA
*da
= EVP_PKEY_get0((EVP_PKEY
*)a
);
574 const DSA
*db
= EVP_PKEY_get0((EVP_PKEY
*)b
);
575 if (!BN_cmp(da
->q
, db
->q
))
580 static int param_cmp_gost01(const EVP_PKEY
*a
, const EVP_PKEY
*b
)
582 if (EC_GROUP_get_curve_name
583 (EC_KEY_get0_group(EVP_PKEY_get0((EVP_PKEY
*)a
))) ==
584 EC_GROUP_get_curve_name(EC_KEY_get0_group
585 (EVP_PKEY_get0((EVP_PKEY
*)b
)))) {
592 /* ---------- Public key functions * --------------------------------------*/
593 static int pub_decode_gost94(EVP_PKEY
*pk
, X509_PUBKEY
*pub
)
595 X509_ALGOR
*palg
= NULL
;
596 const unsigned char *pubkey_buf
= NULL
;
597 unsigned char *databuf
;
598 ASN1_OBJECT
*palgobj
= NULL
;
601 ASN1_OCTET_STRING
*octet
= NULL
;
603 if (!X509_PUBKEY_get0_param(&palgobj
, &pubkey_buf
, &pub_len
, &palg
, pub
))
605 EVP_PKEY_assign(pk
, OBJ_obj2nid(palgobj
), NULL
);
606 if (!decode_gost_algor_params(pk
, palg
))
608 octet
= d2i_ASN1_OCTET_STRING(NULL
, &pubkey_buf
, pub_len
);
610 GOSTerr(GOST_F_PUB_DECODE_GOST94
, ERR_R_MALLOC_FAILURE
);
613 databuf
= OPENSSL_malloc(octet
->length
);
614 if (databuf
== NULL
) {
615 GOSTerr(GOST_F_PUB_DECODE_GOST94
, ERR_R_MALLOC_FAILURE
);
616 ASN1_OCTET_STRING_free(octet
);
619 for (i
= 0, j
= octet
->length
- 1; i
< octet
->length
; i
++, j
--) {
620 databuf
[j
] = octet
->data
[i
];
622 dsa
= EVP_PKEY_get0(pk
);
623 dsa
->pub_key
= BN_bin2bn(databuf
, octet
->length
, NULL
);
624 ASN1_OCTET_STRING_free(octet
);
625 OPENSSL_free(databuf
);
630 static int pub_encode_gost94(X509_PUBKEY
*pub
, const EVP_PKEY
*pk
)
632 ASN1_OBJECT
*algobj
= NULL
;
633 ASN1_OCTET_STRING
*octet
= NULL
;
635 unsigned char *buf
= NULL
, *databuf
, *sptr
;
636 int i
, j
, data_len
, ret
= 0;
638 int ptype
= V_ASN1_UNDEF
;
639 DSA
*dsa
= EVP_PKEY_get0((EVP_PKEY
*)pk
);
640 algobj
= OBJ_nid2obj(EVP_PKEY_base_id(pk
));
641 if (pk
->save_parameters
) {
642 ASN1_STRING
*params
= encode_gost_algor_params(pk
);
644 ptype
= V_ASN1_SEQUENCE
;
646 data_len
= BN_num_bytes(dsa
->pub_key
);
647 databuf
= OPENSSL_malloc(data_len
);
648 if (databuf
== NULL
) {
649 GOSTerr(GOST_F_PUB_ENCODE_GOST94
, ERR_R_MALLOC_FAILURE
);
652 BN_bn2bin(dsa
->pub_key
, databuf
);
653 octet
= ASN1_OCTET_STRING_new();
655 GOSTerr(GOST_F_PUB_ENCODE_GOST94
, ERR_R_MALLOC_FAILURE
);
656 OPENSSL_free(databuf
);
659 ASN1_STRING_set(octet
, NULL
, data_len
);
660 sptr
= ASN1_STRING_data(octet
);
661 for (i
= 0, j
= data_len
- 1; i
< data_len
; i
++, j
--) {
662 sptr
[i
] = databuf
[j
];
664 OPENSSL_free(databuf
);
665 ret
= i2d_ASN1_OCTET_STRING(octet
, &buf
);
666 ASN1_BIT_STRING_free(octet
);
669 return X509_PUBKEY_set0_param(pub
, algobj
, ptype
, pval
, buf
, ret
);
672 static int pub_decode_gost01(EVP_PKEY
*pk
, X509_PUBKEY
*pub
)
674 X509_ALGOR
*palg
= NULL
;
675 const unsigned char *pubkey_buf
= NULL
;
676 unsigned char *databuf
;
677 ASN1_OBJECT
*palgobj
= NULL
;
681 ASN1_OCTET_STRING
*octet
= NULL
;
683 const EC_GROUP
*group
;
685 if (!X509_PUBKEY_get0_param(&palgobj
, &pubkey_buf
, &pub_len
, &palg
, pub
))
687 EVP_PKEY_assign(pk
, OBJ_obj2nid(palgobj
), NULL
);
688 if (!decode_gost_algor_params(pk
, palg
))
690 group
= EC_KEY_get0_group(EVP_PKEY_get0(pk
));
691 octet
= d2i_ASN1_OCTET_STRING(NULL
, &pubkey_buf
, pub_len
);
693 GOSTerr(GOST_F_PUB_DECODE_GOST01
, ERR_R_MALLOC_FAILURE
);
696 databuf
= OPENSSL_malloc(octet
->length
);
697 if (databuf
== NULL
) {
698 GOSTerr(GOST_F_PUB_DECODE_GOST01
, ERR_R_MALLOC_FAILURE
);
699 ASN1_OCTET_STRING_free(octet
);
702 for (i
= 0, j
= octet
->length
- 1; i
< octet
->length
; i
++, j
--) {
703 databuf
[j
] = octet
->data
[i
];
705 len
= octet
->length
/ 2;
706 ASN1_OCTET_STRING_free(octet
);
708 Y
= getbnfrombuf(databuf
, len
);
709 X
= getbnfrombuf(databuf
+ len
, len
);
710 OPENSSL_free(databuf
);
711 pub_key
= EC_POINT_new(group
);
712 if (!EC_POINT_set_affine_coordinates_GFp(group
, pub_key
, X
, Y
, NULL
)) {
713 GOSTerr(GOST_F_PUB_DECODE_GOST01
, ERR_R_EC_LIB
);
714 EC_POINT_free(pub_key
);
721 if (!EC_KEY_set_public_key(EVP_PKEY_get0(pk
), pub_key
)) {
722 GOSTerr(GOST_F_PUB_DECODE_GOST01
, ERR_R_EC_LIB
);
723 EC_POINT_free(pub_key
);
726 EC_POINT_free(pub_key
);
731 static int pub_encode_gost01(X509_PUBKEY
*pub
, const EVP_PKEY
*pk
)
733 ASN1_OBJECT
*algobj
= NULL
;
734 ASN1_OCTET_STRING
*octet
= NULL
;
736 unsigned char *buf
= NULL
, *databuf
, *sptr
;
737 int i
, j
, data_len
, ret
= 0;
738 const EC_POINT
*pub_key
;
739 BIGNUM
*X
, *Y
, *order
;
740 const EC_KEY
*ec
= EVP_PKEY_get0((EVP_PKEY
*)pk
);
741 int ptype
= V_ASN1_UNDEF
;
743 algobj
= OBJ_nid2obj(EVP_PKEY_base_id(pk
));
744 if (pk
->save_parameters
) {
745 ASN1_STRING
*params
= encode_gost_algor_params(pk
);
747 ptype
= V_ASN1_SEQUENCE
;
750 EC_GROUP_get_order(EC_KEY_get0_group(ec
), order
, NULL
);
751 pub_key
= EC_KEY_get0_public_key(ec
);
753 GOSTerr(GOST_F_PUB_ENCODE_GOST01
, GOST_R_PUBLIC_KEY_UNDEFINED
);
760 GOSTerr(GOST_F_PUB_ENCODE_GOST01
, ERR_R_MALLOC_FAILURE
);
768 if (!EC_POINT_get_affine_coordinates_GFp(EC_KEY_get0_group(ec
),
769 pub_key
, X
, Y
, NULL
)) {
770 GOSTerr(GOST_F_PUB_ENCODE_GOST01
, ERR_R_INTERNAL_ERROR
);
776 data_len
= 2 * BN_num_bytes(order
);
778 databuf
= OPENSSL_malloc(data_len
);
779 if (databuf
== NULL
) {
780 GOSTerr(GOST_F_PUB_ENCODE_GOST01
, ERR_R_MALLOC_FAILURE
);
785 memset(databuf
, 0, data_len
);
787 store_bignum(X
, databuf
+ data_len
/ 2, data_len
/ 2);
788 store_bignum(Y
, databuf
, data_len
/ 2);
792 octet
= ASN1_OCTET_STRING_new();
794 GOSTerr(GOST_F_PUB_ENCODE_GOST01
, ERR_R_MALLOC_FAILURE
);
795 OPENSSL_free(databuf
);
798 ASN1_STRING_set(octet
, NULL
, data_len
);
799 sptr
= ASN1_STRING_data(octet
);
800 for (i
= 0, j
= data_len
- 1; i
< data_len
; i
++, j
--) {
801 sptr
[i
] = databuf
[j
];
803 OPENSSL_free(databuf
);
804 ret
= i2d_ASN1_OCTET_STRING(octet
, &buf
);
805 ASN1_BIT_STRING_free(octet
);
808 return X509_PUBKEY_set0_param(pub
, algobj
, ptype
, pval
, buf
, ret
);
811 static int pub_cmp_gost94(const EVP_PKEY
*a
, const EVP_PKEY
*b
)
813 const DSA
*da
= EVP_PKEY_get0((EVP_PKEY
*)a
);
814 const DSA
*db
= EVP_PKEY_get0((EVP_PKEY
*)b
);
815 if (da
&& db
&& da
->pub_key
&& db
->pub_key
816 && !BN_cmp(da
->pub_key
, db
->pub_key
)) {
822 static int pub_cmp_gost01(const EVP_PKEY
*a
, const EVP_PKEY
*b
)
824 const EC_KEY
*ea
= EVP_PKEY_get0((EVP_PKEY
*)a
);
825 const EC_KEY
*eb
= EVP_PKEY_get0((EVP_PKEY
*)b
);
826 const EC_POINT
*ka
, *kb
;
830 ka
= EC_KEY_get0_public_key(ea
);
831 kb
= EC_KEY_get0_public_key(eb
);
834 ret
= (0 == EC_POINT_cmp(EC_KEY_get0_group(ea
), ka
, kb
, NULL
));
838 static int pkey_size_gost(const EVP_PKEY
*pk
)
843 static int pkey_bits_gost(const EVP_PKEY
*pk
)
848 /* ---------------------- ASN1 METHOD for GOST MAC -------------------*/
849 static void mackey_free_gost(EVP_PKEY
*pk
)
852 OPENSSL_free(pk
->pkey
.ptr
);
856 static int mac_ctrl_gost(EVP_PKEY
*pkey
, int op
, long arg1
, void *arg2
)
859 case ASN1_PKEY_CTRL_DEFAULT_MD_NID
:
860 *(int *)arg2
= NID_id_Gost28147_89_MAC
;
866 static int gost94_param_encode(const EVP_PKEY
*pkey
, unsigned char **pder
)
868 int nid
= gost94_nid_by_params(EVP_PKEY_get0((EVP_PKEY
*)pkey
));
869 return i2d_ASN1_OBJECT(OBJ_nid2obj(nid
), pder
);
872 static int gost2001_param_encode(const EVP_PKEY
*pkey
, unsigned char **pder
)
875 EC_GROUP_get_curve_name(EC_KEY_get0_group
876 (EVP_PKEY_get0((EVP_PKEY
*)pkey
)));
877 return i2d_ASN1_OBJECT(OBJ_nid2obj(nid
), pder
);
880 static int gost94_param_decode(EVP_PKEY
*pkey
, const unsigned char **pder
,
883 ASN1_OBJECT
*obj
= NULL
;
884 DSA
*dsa
= EVP_PKEY_get0(pkey
);
886 if (d2i_ASN1_OBJECT(&obj
, pder
, derlen
) == NULL
) {
889 nid
= OBJ_obj2nid(obj
);
890 ASN1_OBJECT_free(obj
);
893 if (!EVP_PKEY_assign(pkey
, NID_id_GostR3410_94
, dsa
))
896 if (!fill_GOST94_params(dsa
, nid
))
901 static int gost2001_param_decode(EVP_PKEY
*pkey
, const unsigned char **pder
,
904 ASN1_OBJECT
*obj
= NULL
;
906 EC_KEY
*ec
= EVP_PKEY_get0(pkey
);
907 if (d2i_ASN1_OBJECT(&obj
, pder
, derlen
) == NULL
) {
910 nid
= OBJ_obj2nid(obj
);
911 ASN1_OBJECT_free(obj
);
914 if (!EVP_PKEY_assign(pkey
, NID_id_GostR3410_2001
, ec
))
917 if (!fill_GOST2001_params(ec
, nid
))
922 /* ----------------------------------------------------------------------*/
923 int register_ameth_gost(int nid
, EVP_PKEY_ASN1_METHOD
**ameth
,
924 const char *pemstr
, const char *info
)
926 *ameth
= EVP_PKEY_asn1_new(nid
, ASN1_PKEY_SIGPARAM_NULL
, pemstr
, info
);
930 case NID_id_GostR3410_94
:
931 EVP_PKEY_asn1_set_free(*ameth
, pkey_free_gost94
);
932 EVP_PKEY_asn1_set_private(*ameth
,
933 priv_decode_gost
, priv_encode_gost
,
936 EVP_PKEY_asn1_set_param(*ameth
,
937 gost94_param_decode
, gost94_param_encode
,
938 param_missing_gost94
, param_copy_gost94
,
939 param_cmp_gost94
, param_print_gost94
);
940 EVP_PKEY_asn1_set_public(*ameth
,
941 pub_decode_gost94
, pub_encode_gost94
,
942 pub_cmp_gost94
, pub_print_gost94
,
943 pkey_size_gost
, pkey_bits_gost
);
945 EVP_PKEY_asn1_set_ctrl(*ameth
, pkey_ctrl_gost
);
947 case NID_id_GostR3410_2001
:
948 EVP_PKEY_asn1_set_free(*ameth
, pkey_free_gost01
);
949 EVP_PKEY_asn1_set_private(*ameth
,
950 priv_decode_gost
, priv_encode_gost
,
953 EVP_PKEY_asn1_set_param(*ameth
,
954 gost2001_param_decode
, gost2001_param_encode
,
955 param_missing_gost01
, param_copy_gost01
,
956 param_cmp_gost01
, param_print_gost01
);
957 EVP_PKEY_asn1_set_public(*ameth
,
958 pub_decode_gost01
, pub_encode_gost01
,
959 pub_cmp_gost01
, pub_print_gost01
,
960 pkey_size_gost
, pkey_bits_gost
);
962 EVP_PKEY_asn1_set_ctrl(*ameth
, pkey_ctrl_gost
);
964 case NID_id_Gost28147_89_MAC
:
965 EVP_PKEY_asn1_set_free(*ameth
, mackey_free_gost
);
966 EVP_PKEY_asn1_set_ctrl(*ameth
, mac_ctrl_gost
);