2 * Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
11 * DH low level APIs are deprecated for public use, but still ok for
14 #include "internal/deprecated.h"
16 #include <string.h> /* strcmp */
17 #include <openssl/core_dispatch.h>
18 #include <openssl/core_names.h>
19 #include <openssl/bn.h>
20 #include <openssl/err.h>
21 #include "prov/implementations.h"
22 #include "prov/providercommon.h"
23 #include "prov/provider_ctx.h"
24 #include "crypto/dh.h"
25 #include "internal/sizes.h"
26 #include "internal/nelem.h"
27 #include "internal/param_build_set.h"
29 static OSSL_FUNC_keymgmt_new_fn dh_newdata
;
30 static OSSL_FUNC_keymgmt_free_fn dh_freedata
;
31 static OSSL_FUNC_keymgmt_gen_init_fn dh_gen_init
;
32 static OSSL_FUNC_keymgmt_gen_init_fn dhx_gen_init
;
33 static OSSL_FUNC_keymgmt_gen_set_template_fn dh_gen_set_template
;
34 static OSSL_FUNC_keymgmt_gen_set_params_fn dh_gen_set_params
;
35 static OSSL_FUNC_keymgmt_gen_settable_params_fn dh_gen_settable_params
;
36 static OSSL_FUNC_keymgmt_gen_fn dh_gen
;
37 static OSSL_FUNC_keymgmt_gen_cleanup_fn dh_gen_cleanup
;
38 static OSSL_FUNC_keymgmt_load_fn dh_load
;
39 static OSSL_FUNC_keymgmt_get_params_fn dh_get_params
;
40 static OSSL_FUNC_keymgmt_gettable_params_fn dh_gettable_params
;
41 static OSSL_FUNC_keymgmt_set_params_fn dh_set_params
;
42 static OSSL_FUNC_keymgmt_settable_params_fn dh_settable_params
;
43 static OSSL_FUNC_keymgmt_has_fn dh_has
;
44 static OSSL_FUNC_keymgmt_match_fn dh_match
;
45 static OSSL_FUNC_keymgmt_validate_fn dh_validate
;
46 static OSSL_FUNC_keymgmt_import_fn dh_import
;
47 static OSSL_FUNC_keymgmt_import_types_fn dh_import_types
;
48 static OSSL_FUNC_keymgmt_export_fn dh_export
;
49 static OSSL_FUNC_keymgmt_export_types_fn dh_export_types
;
51 #define DH_POSSIBLE_SELECTIONS \
52 (OSSL_KEYMGMT_SELECT_KEYPAIR | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS)
57 FFC_PARAMS
*ffc_params
;
59 /* All these parameters are used for parameter generation only */
60 /* If there is a group name then the remaining parameters are not needed */
64 unsigned char *seed
; /* optional FIPS186-4 param for testing */
66 int gindex
; /* optional FIPS186-4 generator index (ignored if -1) */
67 int gen_type
; /* see dhtype2id */
68 int generator
; /* Used by DH_PARAMGEN_TYPE_GENERATOR in non fips mode only */
80 typedef struct dh_name2id_st
{
85 static const DH_GENTYPE_NAME2ID dhtype2id
[]=
87 { "default", DH_PARAMGEN_TYPE_FIPS_186_4
},
88 { "fips186_4", DH_PARAMGEN_TYPE_FIPS_186_4
},
89 { "fips186_2", DH_PARAMGEN_TYPE_FIPS_186_2
},
90 { "group", DH_PARAMGEN_TYPE_GROUP
},
91 { "generator", DH_PARAMGEN_TYPE_GENERATOR
}
94 const char *dh_gen_type_id2name(int id
)
98 for (i
= 0; i
< OSSL_NELEM(dhtype2id
); ++i
) {
99 if (dhtype2id
[i
].id
== id
)
100 return dhtype2id
[i
].name
;
105 static int dh_gen_type_name2id(const char *name
)
109 for (i
= 0; i
< OSSL_NELEM(dhtype2id
); ++i
) {
110 if (strcmp(dhtype2id
[i
].name
, name
) == 0)
111 return dhtype2id
[i
].id
;
116 static int dh_key_todata(DH
*dh
, OSSL_PARAM_BLD
*bld
, OSSL_PARAM params
[])
118 const BIGNUM
*priv
= NULL
, *pub
= NULL
;
123 DH_get0_key(dh
, &pub
, &priv
);
125 && !ossl_param_build_set_bn(bld
, params
, OSSL_PKEY_PARAM_PRIV_KEY
, priv
))
128 && !ossl_param_build_set_bn(bld
, params
, OSSL_PKEY_PARAM_PUB_KEY
, pub
))
134 static void *dh_newdata(void *provctx
)
138 if (ossl_prov_is_running()) {
139 dh
= dh_new_with_libctx(PROV_LIBRARY_CONTEXT_OF(provctx
));
141 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
142 DH_set_flags(dh
, DH_FLAG_TYPE_DH
);
148 static void *dhx_newdata(void *provctx
)
152 dh
= dh_new_with_libctx(PROV_LIBRARY_CONTEXT_OF(provctx
));
154 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
155 DH_set_flags(dh
, DH_FLAG_TYPE_DHX
);
160 static void dh_freedata(void *keydata
)
165 static int dh_has(void *keydata
, int selection
)
170 if (ossl_prov_is_running() && dh
!= NULL
) {
171 if ((selection
& DH_POSSIBLE_SELECTIONS
) != 0)
174 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
175 ok
= ok
&& (DH_get0_pub_key(dh
) != NULL
);
176 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
177 ok
= ok
&& (DH_get0_priv_key(dh
) != NULL
);
178 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0)
179 ok
= ok
&& (DH_get0_p(dh
) != NULL
&& DH_get0_g(dh
) != NULL
);
184 static int dh_match(const void *keydata1
, const void *keydata2
, int selection
)
186 const DH
*dh1
= keydata1
;
187 const DH
*dh2
= keydata2
;
190 if (!ossl_prov_is_running())
193 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
194 ok
= ok
&& BN_cmp(DH_get0_pub_key(dh1
), DH_get0_pub_key(dh2
)) == 0;
195 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
196 ok
= ok
&& BN_cmp(DH_get0_priv_key(dh1
), DH_get0_priv_key(dh2
)) == 0;
197 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0) {
198 FFC_PARAMS
*dhparams1
= dh_get0_params((DH
*)dh1
);
199 FFC_PARAMS
*dhparams2
= dh_get0_params((DH
*)dh2
);
201 ok
= ok
&& ffc_params_cmp(dhparams1
, dhparams2
, 1);
206 static int dh_import(void *keydata
, int selection
, const OSSL_PARAM params
[])
211 if (!ossl_prov_is_running() || dh
== NULL
)
214 if ((selection
& DH_POSSIBLE_SELECTIONS
) == 0)
217 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
218 ok
= ok
&& dh_ffc_params_fromdata(dh
, params
);
220 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
221 ok
= ok
&& dh_key_fromdata(dh
, params
);
226 static int dh_export(void *keydata
, int selection
, OSSL_CALLBACK
*param_cb
,
230 OSSL_PARAM_BLD
*tmpl
= NULL
;
231 OSSL_PARAM
*params
= NULL
;
234 if (!ossl_prov_is_running() || dh
== NULL
)
237 tmpl
= OSSL_PARAM_BLD_new();
241 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
242 ok
= ok
&& ffc_params_todata(dh_get0_params(dh
), tmpl
, NULL
);
243 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
244 ok
= ok
&& dh_key_todata(dh
, tmpl
, NULL
);
247 || (params
= OSSL_PARAM_BLD_to_param(tmpl
)) == NULL
) {
251 ok
= param_cb(params
, cbarg
);
252 OSSL_PARAM_BLD_free_params(params
);
254 OSSL_PARAM_BLD_free(tmpl
);
258 /* IMEXPORT = IMPORT + EXPORT */
260 # define DH_IMEXPORTABLE_PARAMETERS \
261 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_P, NULL, 0), \
262 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_Q, NULL, 0), \
263 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_G, NULL, 0), \
264 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_COFACTOR, NULL, 0), \
265 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_GINDEX, NULL), \
266 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_PCOUNTER, NULL), \
267 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_H, NULL), \
268 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_FFC_SEED, NULL, 0), \
269 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME, NULL, 0)
270 # define DH_IMEXPORTABLE_PUBLIC_KEY \
271 OSSL_PARAM_BN(OSSL_PKEY_PARAM_PUB_KEY, NULL, 0)
272 # define DH_IMEXPORTABLE_PRIVATE_KEY \
273 OSSL_PARAM_BN(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0)
274 static const OSSL_PARAM dh_all_types
[] = {
275 DH_IMEXPORTABLE_PARAMETERS
,
276 DH_IMEXPORTABLE_PUBLIC_KEY
,
277 DH_IMEXPORTABLE_PRIVATE_KEY
,
280 static const OSSL_PARAM dh_parameter_types
[] = {
281 DH_IMEXPORTABLE_PARAMETERS
,
284 static const OSSL_PARAM dh_key_types
[] = {
285 DH_IMEXPORTABLE_PUBLIC_KEY
,
286 DH_IMEXPORTABLE_PRIVATE_KEY
,
289 static const OSSL_PARAM
*dh_types
[] = {
290 NULL
, /* Index 0 = none of them */
291 dh_parameter_types
, /* Index 1 = parameter types */
292 dh_key_types
, /* Index 2 = key types */
293 dh_all_types
/* Index 3 = 1 + 2 */
296 static const OSSL_PARAM
*dh_imexport_types(int selection
)
300 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
302 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
304 return dh_types
[type_select
];
307 static const OSSL_PARAM
*dh_import_types(int selection
)
309 return dh_imexport_types(selection
);
312 static const OSSL_PARAM
*dh_export_types(int selection
)
314 return dh_imexport_types(selection
);
317 static ossl_inline
int dh_get_params(void *key
, OSSL_PARAM params
[])
322 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_BITS
)) != NULL
323 && !OSSL_PARAM_set_int(p
, DH_bits(dh
)))
325 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_SECURITY_BITS
)) != NULL
326 && !OSSL_PARAM_set_int(p
, DH_security_bits(dh
)))
328 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_MAX_SIZE
)) != NULL
329 && !OSSL_PARAM_set_int(p
, DH_size(dh
)))
331 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_TLS_ENCODED_PT
)) != NULL
) {
332 if (p
->data_type
!= OSSL_PARAM_OCTET_STRING
)
334 p
->return_size
= dh_key2buf(dh
, (unsigned char **)&p
->data
,
336 if (p
->return_size
== 0)
340 return ffc_params_todata(dh_get0_params(dh
), NULL
, params
)
341 && dh_key_todata(dh
, NULL
, params
);
344 static const OSSL_PARAM dh_params
[] = {
345 OSSL_PARAM_int(OSSL_PKEY_PARAM_BITS
, NULL
),
346 OSSL_PARAM_int(OSSL_PKEY_PARAM_SECURITY_BITS
, NULL
),
347 OSSL_PARAM_int(OSSL_PKEY_PARAM_MAX_SIZE
, NULL
),
348 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_TLS_ENCODED_PT
, NULL
, 0),
349 DH_IMEXPORTABLE_PARAMETERS
,
350 DH_IMEXPORTABLE_PUBLIC_KEY
,
351 DH_IMEXPORTABLE_PRIVATE_KEY
,
355 static const OSSL_PARAM
*dh_gettable_params(void *provctx
)
360 static const OSSL_PARAM dh_known_settable_params
[] = {
361 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_TLS_ENCODED_PT
, NULL
, 0),
365 static const OSSL_PARAM
*dh_settable_params(void *provctx
)
367 return dh_known_settable_params
;
370 static int dh_set_params(void *key
, const OSSL_PARAM params
[])
375 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_TLS_ENCODED_PT
);
377 && (p
->data_type
!= OSSL_PARAM_OCTET_STRING
378 || !dh_buf2key(dh
, p
->data
, p
->data_size
)))
384 static int dh_validate_public(DH
*dh
)
386 const BIGNUM
*pub_key
= NULL
;
388 DH_get0_key(dh
, &pub_key
, NULL
);
391 return DH_check_pub_key_ex(dh
, pub_key
);
394 static int dh_validate_private(DH
*dh
)
397 const BIGNUM
*priv_key
= NULL
;
399 DH_get0_key(dh
, NULL
, &priv_key
);
400 if (priv_key
== NULL
)
402 return dh_check_priv_key(dh
, priv_key
, &status
);;
405 static int dh_validate(void *keydata
, int selection
)
410 if (!ossl_prov_is_running())
413 if ((selection
& DH_POSSIBLE_SELECTIONS
) != 0)
416 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0)
417 ok
= ok
&& DH_check_params_ex(dh
);
419 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
420 ok
= ok
&& dh_validate_public(dh
);
422 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
423 ok
= ok
&& dh_validate_private(dh
);
425 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
)
426 == OSSL_KEYMGMT_SELECT_KEYPAIR
)
427 ok
= ok
&& dh_check_pairwise(dh
);
431 static void *dh_gen_init_base(void *provctx
, int selection
, int type
)
433 OPENSSL_CTX
*libctx
= PROV_LIBRARY_CONTEXT_OF(provctx
);
434 struct dh_gen_ctx
*gctx
= NULL
;
436 if (!ossl_prov_is_running())
439 if ((selection
& (OSSL_KEYMGMT_SELECT_KEYPAIR
440 | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
)) == 0)
443 if ((gctx
= OPENSSL_zalloc(sizeof(*gctx
))) != NULL
) {
444 gctx
->selection
= selection
;
445 gctx
->libctx
= libctx
;
449 gctx
->gen_type
= DH_PARAMGEN_TYPE_FIPS_186_4
;
453 gctx
->generator
= DH_GENERATOR_2
;
454 gctx
->dh_type
= type
;
459 static void *dh_gen_init(void *provctx
, int selection
)
461 return dh_gen_init_base(provctx
, selection
, DH_FLAG_TYPE_DH
);
464 static void *dhx_gen_init(void *provctx
, int selection
)
466 return dh_gen_init_base(provctx
, selection
, DH_FLAG_TYPE_DHX
);
469 static int dh_gen_set_template(void *genctx
, void *templ
)
471 struct dh_gen_ctx
*gctx
= genctx
;
474 if (!ossl_prov_is_running() || gctx
== NULL
|| dh
== NULL
)
476 gctx
->ffc_params
= dh_get0_params(dh
);
480 static int dh_set_gen_seed(struct dh_gen_ctx
*gctx
, unsigned char *seed
,
483 OPENSSL_clear_free(gctx
->seed
, gctx
->seedlen
);
486 if (seed
!= NULL
&& seedlen
> 0) {
487 gctx
->seed
= OPENSSL_memdup(seed
, seedlen
);
488 if (gctx
->seed
== NULL
)
490 gctx
->seedlen
= seedlen
;
495 static int dh_gen_set_params(void *genctx
, const OSSL_PARAM params
[])
497 struct dh_gen_ctx
*gctx
= genctx
;
503 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_TYPE
);
505 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
506 || ((gctx
->gen_type
= dh_gen_type_name2id(p
->data
)) == -1)) {
507 ERR_raise(ERR_LIB_PROV
, ERR_R_PASSED_INVALID_ARGUMENT
);
511 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_GROUP_NAME
);
513 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
514 || ((gctx
->group_nid
= ffc_named_group_to_uid(p
->data
)) == NID_undef
)) {
515 ERR_raise(ERR_LIB_PROV
, ERR_R_PASSED_INVALID_ARGUMENT
);
518 gctx
->gen_type
= DH_PARAMGEN_TYPE_GROUP
;
520 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_DH_GENERATOR
);
521 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->generator
))
523 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_GINDEX
);
524 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->gindex
))
526 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_PCOUNTER
);
527 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->pcounter
))
529 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_H
);
530 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->hindex
))
532 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_SEED
);
534 && (p
->data_type
!= OSSL_PARAM_OCTET_STRING
535 || !dh_set_gen_seed(gctx
, p
->data
, p
->data_size
)))
538 if ((p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_PBITS
)) != NULL
539 && !OSSL_PARAM_get_size_t(p
, &gctx
->pbits
))
541 if ((p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_QBITS
)) != NULL
542 && !OSSL_PARAM_get_size_t(p
, &gctx
->qbits
))
544 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_DIGEST
);
546 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
)
548 gctx
->mdname
= p
->data
;
550 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_DIGEST_PROPS
);
552 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
)
554 gctx
->mdprops
= p
->data
;
556 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_DH_PRIV_LEN
);
557 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->priv_len
))
562 static const OSSL_PARAM
*dh_gen_settable_params(void *provctx
)
564 static OSSL_PARAM settable
[] = {
565 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME
, NULL
, 0),
566 OSSL_PARAM_int(OSSL_PKEY_PARAM_DH_PRIV_LEN
, NULL
),
567 OSSL_PARAM_int(OSSL_PKEY_PARAM_DH_GENERATOR
, NULL
),
568 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_TYPE
, NULL
, 0),
569 OSSL_PARAM_size_t(OSSL_PKEY_PARAM_FFC_PBITS
, NULL
),
570 OSSL_PARAM_size_t(OSSL_PKEY_PARAM_FFC_QBITS
, NULL
),
571 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_DIGEST
, NULL
, 0),
572 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_DIGEST_PROPS
, NULL
, 0),
573 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_GINDEX
, NULL
),
574 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_FFC_SEED
, NULL
, 0),
575 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_PCOUNTER
, NULL
),
576 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_H
, NULL
),
582 static int dh_gencb(int p
, int n
, BN_GENCB
*cb
)
584 struct dh_gen_ctx
*gctx
= BN_GENCB_get_arg(cb
);
585 OSSL_PARAM params
[] = { OSSL_PARAM_END
, OSSL_PARAM_END
, OSSL_PARAM_END
};
587 params
[0] = OSSL_PARAM_construct_int(OSSL_GEN_PARAM_POTENTIAL
, &p
);
588 params
[1] = OSSL_PARAM_construct_int(OSSL_GEN_PARAM_ITERATION
, &n
);
590 return gctx
->cb(params
, gctx
->cbarg
);
593 static void *dh_gen(void *genctx
, OSSL_CALLBACK
*osslcb
, void *cbarg
)
596 struct dh_gen_ctx
*gctx
= genctx
;
598 BN_GENCB
*gencb
= NULL
;
601 if (!ossl_prov_is_running() || gctx
== NULL
)
604 /* For parameter generation - If there is a group name just create it */
605 if (gctx
->gen_type
== DH_PARAMGEN_TYPE_GROUP
) {
606 /* Select a named group if there is not one already */
607 if (gctx
->group_nid
== NID_undef
)
608 gctx
->group_nid
= dh_get_named_group_uid_from_size(gctx
->pbits
);
609 if (gctx
->group_nid
== NID_undef
)
611 dh
= dh_new_by_nid_with_libctx(gctx
->libctx
, gctx
->group_nid
);
614 ffc
= dh_get0_params(dh
);
616 dh
= dh_new_with_libctx(gctx
->libctx
);
619 ffc
= dh_get0_params(dh
);
621 /* Copy the template value if one was passed */
622 if (gctx
->ffc_params
!= NULL
623 && !ffc_params_copy(ffc
, gctx
->ffc_params
))
626 if (!ffc_params_set_seed(ffc
, gctx
->seed
, gctx
->seedlen
))
628 if (gctx
->gindex
!= -1) {
629 ffc_params_set_gindex(ffc
, gctx
->gindex
);
630 if (gctx
->pcounter
!= -1)
631 ffc_params_set_pcounter(ffc
, gctx
->pcounter
);
632 } else if (gctx
->hindex
!= 0) {
633 ffc_params_set_h(ffc
, gctx
->hindex
);
635 if (gctx
->mdname
!= NULL
) {
636 if (!ffc_set_digest(ffc
, gctx
->mdname
, gctx
->mdprops
))
641 gencb
= BN_GENCB_new();
643 BN_GENCB_set(gencb
, dh_gencb
, genctx
);
645 if ((gctx
->selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0) {
647 * NOTE: The old safe prime generator code is not used in fips mode,
648 * (i.e internally it ignores the generator and chooses a named
649 * group based on pbits.
651 if (gctx
->gen_type
== DH_PARAMGEN_TYPE_GENERATOR
)
652 ret
= DH_generate_parameters_ex(dh
, gctx
->pbits
,
653 gctx
->generator
, gencb
);
655 ret
= dh_generate_ffc_parameters(dh
, gctx
->gen_type
, gctx
->pbits
,
662 if ((gctx
->selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0) {
663 if (ffc
->p
== NULL
|| ffc
->g
== NULL
)
665 if (gctx
->priv_len
> 0)
666 DH_set_length(dh
, (long)gctx
->priv_len
);
667 ffc_params_enable_flags(ffc
, FFC_PARAM_FLAG_VALIDATE_LEGACY
,
668 gctx
->gen_type
== DH_PARAMGEN_TYPE_FIPS_186_2
);
669 if (DH_generate_key(dh
) <= 0)
672 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
673 DH_set_flags(dh
, gctx
->dh_type
);
681 BN_GENCB_free(gencb
);
685 static void dh_gen_cleanup(void *genctx
)
687 struct dh_gen_ctx
*gctx
= genctx
;
692 OPENSSL_clear_free(gctx
->seed
, gctx
->seedlen
);
696 void *dh_load(const void *reference
, size_t reference_sz
)
700 if (ossl_prov_is_running() && reference_sz
== sizeof(dh
)) {
701 /* The contents of the reference is the address to our object */
702 dh
= *(DH
**)reference
;
703 /* We grabbed, so we detach it */
704 *(DH
**)reference
= NULL
;
710 const OSSL_DISPATCH dh_keymgmt_functions
[] = {
711 { OSSL_FUNC_KEYMGMT_NEW
, (void (*)(void))dh_newdata
},
712 { OSSL_FUNC_KEYMGMT_GEN_INIT
, (void (*)(void))dh_gen_init
},
713 { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE
, (void (*)(void))dh_gen_set_template
},
714 { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS
, (void (*)(void))dh_gen_set_params
},
715 { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS
,
716 (void (*)(void))dh_gen_settable_params
},
717 { OSSL_FUNC_KEYMGMT_GEN
, (void (*)(void))dh_gen
},
718 { OSSL_FUNC_KEYMGMT_GEN_CLEANUP
, (void (*)(void))dh_gen_cleanup
},
719 { OSSL_FUNC_KEYMGMT_LOAD
, (void (*)(void))dh_load
},
720 { OSSL_FUNC_KEYMGMT_FREE
, (void (*)(void))dh_freedata
},
721 { OSSL_FUNC_KEYMGMT_GET_PARAMS
, (void (*) (void))dh_get_params
},
722 { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS
, (void (*) (void))dh_gettable_params
},
723 { OSSL_FUNC_KEYMGMT_SET_PARAMS
, (void (*) (void))dh_set_params
},
724 { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS
, (void (*) (void))dh_settable_params
},
725 { OSSL_FUNC_KEYMGMT_HAS
, (void (*)(void))dh_has
},
726 { OSSL_FUNC_KEYMGMT_MATCH
, (void (*)(void))dh_match
},
727 { OSSL_FUNC_KEYMGMT_VALIDATE
, (void (*)(void))dh_validate
},
728 { OSSL_FUNC_KEYMGMT_IMPORT
, (void (*)(void))dh_import
},
729 { OSSL_FUNC_KEYMGMT_IMPORT_TYPES
, (void (*)(void))dh_import_types
},
730 { OSSL_FUNC_KEYMGMT_EXPORT
, (void (*)(void))dh_export
},
731 { OSSL_FUNC_KEYMGMT_EXPORT_TYPES
, (void (*)(void))dh_export_types
},
735 /* For any DH key, we use the "DH" algorithms regardless of sub-type. */
736 static const char *dhx_query_operation_name(int operation_id
)
741 const OSSL_DISPATCH dhx_keymgmt_functions
[] = {
742 { OSSL_FUNC_KEYMGMT_NEW
, (void (*)(void))dhx_newdata
},
743 { OSSL_FUNC_KEYMGMT_GEN_INIT
, (void (*)(void))dhx_gen_init
},
744 { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE
, (void (*)(void))dh_gen_set_template
},
745 { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS
, (void (*)(void))dh_gen_set_params
},
746 { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS
,
747 (void (*)(void))dh_gen_settable_params
},
748 { OSSL_FUNC_KEYMGMT_GEN
, (void (*)(void))dh_gen
},
749 { OSSL_FUNC_KEYMGMT_GEN_CLEANUP
, (void (*)(void))dh_gen_cleanup
},
750 { OSSL_FUNC_KEYMGMT_LOAD
, (void (*)(void))dh_load
},
751 { OSSL_FUNC_KEYMGMT_FREE
, (void (*)(void))dh_freedata
},
752 { OSSL_FUNC_KEYMGMT_GET_PARAMS
, (void (*) (void))dh_get_params
},
753 { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS
, (void (*) (void))dh_gettable_params
},
754 { OSSL_FUNC_KEYMGMT_SET_PARAMS
, (void (*) (void))dh_set_params
},
755 { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS
, (void (*) (void))dh_settable_params
},
756 { OSSL_FUNC_KEYMGMT_HAS
, (void (*)(void))dh_has
},
757 { OSSL_FUNC_KEYMGMT_MATCH
, (void (*)(void))dh_match
},
758 { OSSL_FUNC_KEYMGMT_VALIDATE
, (void (*)(void))dh_validate
},
759 { OSSL_FUNC_KEYMGMT_IMPORT
, (void (*)(void))dh_import
},
760 { OSSL_FUNC_KEYMGMT_IMPORT_TYPES
, (void (*)(void))dh_import_types
},
761 { OSSL_FUNC_KEYMGMT_EXPORT
, (void (*)(void))dh_export
},
762 { OSSL_FUNC_KEYMGMT_EXPORT_TYPES
, (void (*)(void))dh_export_types
},
763 { OSSL_FUNC_KEYMGMT_QUERY_OPERATION_NAME
,
764 (void (*)(void))dhx_query_operation_name
},