2 * Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
11 * DH low level APIs are deprecated for public use, but still ok for
14 #include "internal/deprecated.h"
16 #include <string.h> /* strcmp */
17 #include <openssl/core_dispatch.h>
18 #include <openssl/core_names.h>
19 #include <openssl/bn.h>
20 #include <openssl/err.h>
21 #include "prov/implementations.h"
22 #include "prov/providercommon.h"
23 #include "prov/provider_ctx.h"
24 #include "crypto/dh.h"
25 #include "internal/sizes.h"
26 #include "internal/nelem.h"
28 static OSSL_FUNC_keymgmt_new_fn dh_newdata
;
29 static OSSL_FUNC_keymgmt_free_fn dh_freedata
;
30 static OSSL_FUNC_keymgmt_gen_init_fn dh_gen_init
;
31 static OSSL_FUNC_keymgmt_gen_init_fn dhx_gen_init
;
32 static OSSL_FUNC_keymgmt_gen_set_template_fn dh_gen_set_template
;
33 static OSSL_FUNC_keymgmt_gen_set_params_fn dh_gen_set_params
;
34 static OSSL_FUNC_keymgmt_gen_settable_params_fn dh_gen_settable_params
;
35 static OSSL_FUNC_keymgmt_gen_fn dh_gen
;
36 static OSSL_FUNC_keymgmt_gen_cleanup_fn dh_gen_cleanup
;
37 static OSSL_FUNC_keymgmt_load_fn dh_load
;
38 static OSSL_FUNC_keymgmt_get_params_fn dh_get_params
;
39 static OSSL_FUNC_keymgmt_gettable_params_fn dh_gettable_params
;
40 static OSSL_FUNC_keymgmt_set_params_fn dh_set_params
;
41 static OSSL_FUNC_keymgmt_settable_params_fn dh_settable_params
;
42 static OSSL_FUNC_keymgmt_has_fn dh_has
;
43 static OSSL_FUNC_keymgmt_match_fn dh_match
;
44 static OSSL_FUNC_keymgmt_validate_fn dh_validate
;
45 static OSSL_FUNC_keymgmt_import_fn dh_import
;
46 static OSSL_FUNC_keymgmt_import_types_fn dh_import_types
;
47 static OSSL_FUNC_keymgmt_export_fn dh_export
;
48 static OSSL_FUNC_keymgmt_export_types_fn dh_export_types
;
50 #define DH_POSSIBLE_SELECTIONS \
51 (OSSL_KEYMGMT_SELECT_KEYPAIR | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS)
56 FFC_PARAMS
*ffc_params
;
58 /* All these parameters are used for parameter generation only */
59 /* If there is a group name then the remaining parameters are not needed */
63 unsigned char *seed
; /* optional FIPS186-4 param for testing */
65 int gindex
; /* optional FIPS186-4 generator index (ignored if -1) */
66 int gen_type
; /* see dhtype2id */
67 int generator
; /* Used by DH_PARAMGEN_TYPE_GENERATOR in non fips mode only */
79 typedef struct dh_name2id_st
{
84 static const DH_GENTYPE_NAME2ID dhtype2id
[]=
86 { "default", DH_PARAMGEN_TYPE_FIPS_186_4
},
87 { "fips186_4", DH_PARAMGEN_TYPE_FIPS_186_4
},
88 { "fips186_2", DH_PARAMGEN_TYPE_FIPS_186_2
},
89 { "group", DH_PARAMGEN_TYPE_GROUP
},
90 { "generator", DH_PARAMGEN_TYPE_GENERATOR
}
93 const char *dh_gen_type_id2name(int id
)
97 for (i
= 0; i
< OSSL_NELEM(dhtype2id
); ++i
) {
98 if (dhtype2id
[i
].id
== id
)
99 return dhtype2id
[i
].name
;
104 static int dh_gen_type_name2id(const char *name
)
108 for (i
= 0; i
< OSSL_NELEM(dhtype2id
); ++i
) {
109 if (strcmp(dhtype2id
[i
].name
, name
) == 0)
110 return dhtype2id
[i
].id
;
115 static void *dh_newdata(void *provctx
)
119 if (ossl_prov_is_running()) {
120 dh
= dh_new_ex(PROV_LIBCTX_OF(provctx
));
122 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
123 DH_set_flags(dh
, DH_FLAG_TYPE_DH
);
129 static void *dhx_newdata(void *provctx
)
133 dh
= dh_new_ex(PROV_LIBCTX_OF(provctx
));
135 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
136 DH_set_flags(dh
, DH_FLAG_TYPE_DHX
);
141 static void dh_freedata(void *keydata
)
146 static int dh_has(const void *keydata
, int selection
)
148 const DH
*dh
= keydata
;
151 if (ossl_prov_is_running() && dh
!= NULL
) {
152 if ((selection
& DH_POSSIBLE_SELECTIONS
) != 0)
155 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
156 ok
= ok
&& (DH_get0_pub_key(dh
) != NULL
);
157 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
158 ok
= ok
&& (DH_get0_priv_key(dh
) != NULL
);
159 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0)
160 ok
= ok
&& (DH_get0_p(dh
) != NULL
&& DH_get0_g(dh
) != NULL
);
165 static int dh_match(const void *keydata1
, const void *keydata2
, int selection
)
167 const DH
*dh1
= keydata1
;
168 const DH
*dh2
= keydata2
;
171 if (!ossl_prov_is_running())
174 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
175 ok
= ok
&& BN_cmp(DH_get0_pub_key(dh1
), DH_get0_pub_key(dh2
)) == 0;
176 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
177 ok
= ok
&& BN_cmp(DH_get0_priv_key(dh1
), DH_get0_priv_key(dh2
)) == 0;
178 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0) {
179 FFC_PARAMS
*dhparams1
= dh_get0_params((DH
*)dh1
);
180 FFC_PARAMS
*dhparams2
= dh_get0_params((DH
*)dh2
);
182 ok
= ok
&& ossl_ffc_params_cmp(dhparams1
, dhparams2
, 1);
187 static int dh_import(void *keydata
, int selection
, const OSSL_PARAM params
[])
192 if (!ossl_prov_is_running() || dh
== NULL
)
195 if ((selection
& DH_POSSIBLE_SELECTIONS
) == 0)
198 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
199 ok
= ok
&& dh_params_fromdata(dh
, params
);
201 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
202 ok
= ok
&& dh_key_fromdata(dh
, params
);
207 static int dh_export(void *keydata
, int selection
, OSSL_CALLBACK
*param_cb
,
211 OSSL_PARAM_BLD
*tmpl
= NULL
;
212 OSSL_PARAM
*params
= NULL
;
215 if (!ossl_prov_is_running() || dh
== NULL
)
218 tmpl
= OSSL_PARAM_BLD_new();
222 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
223 ok
= ok
&& dh_params_todata(dh
, tmpl
, NULL
);
224 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
225 ok
= ok
&& dh_key_todata(dh
, tmpl
, NULL
);
228 || (params
= OSSL_PARAM_BLD_to_param(tmpl
)) == NULL
) {
232 ok
= param_cb(params
, cbarg
);
233 OSSL_PARAM_BLD_free_params(params
);
235 OSSL_PARAM_BLD_free(tmpl
);
239 /* IMEXPORT = IMPORT + EXPORT */
241 # define DH_IMEXPORTABLE_PARAMETERS \
242 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_P, NULL, 0), \
243 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_Q, NULL, 0), \
244 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_G, NULL, 0), \
245 OSSL_PARAM_BN(OSSL_PKEY_PARAM_FFC_COFACTOR, NULL, 0), \
246 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_GINDEX, NULL), \
247 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_PCOUNTER, NULL), \
248 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_H, NULL), \
249 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_FFC_SEED, NULL, 0), \
250 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME, NULL, 0), \
251 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_DH_PRIV_LEN, NULL, 0)
252 # define DH_IMEXPORTABLE_PUBLIC_KEY \
253 OSSL_PARAM_BN(OSSL_PKEY_PARAM_PUB_KEY, NULL, 0)
254 # define DH_IMEXPORTABLE_PRIVATE_KEY \
255 OSSL_PARAM_BN(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0)
256 static const OSSL_PARAM dh_all_types
[] = {
257 DH_IMEXPORTABLE_PARAMETERS
,
258 DH_IMEXPORTABLE_PUBLIC_KEY
,
259 DH_IMEXPORTABLE_PRIVATE_KEY
,
262 static const OSSL_PARAM dh_parameter_types
[] = {
263 DH_IMEXPORTABLE_PARAMETERS
,
266 static const OSSL_PARAM dh_key_types
[] = {
267 DH_IMEXPORTABLE_PUBLIC_KEY
,
268 DH_IMEXPORTABLE_PRIVATE_KEY
,
271 static const OSSL_PARAM
*dh_types
[] = {
272 NULL
, /* Index 0 = none of them */
273 dh_parameter_types
, /* Index 1 = parameter types */
274 dh_key_types
, /* Index 2 = key types */
275 dh_all_types
/* Index 3 = 1 + 2 */
278 static const OSSL_PARAM
*dh_imexport_types(int selection
)
282 if ((selection
& OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
) != 0)
284 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0)
286 return dh_types
[type_select
];
289 static const OSSL_PARAM
*dh_import_types(int selection
)
291 return dh_imexport_types(selection
);
294 static const OSSL_PARAM
*dh_export_types(int selection
)
296 return dh_imexport_types(selection
);
299 static ossl_inline
int dh_get_params(void *key
, OSSL_PARAM params
[])
304 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_BITS
)) != NULL
305 && !OSSL_PARAM_set_int(p
, DH_bits(dh
)))
307 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_SECURITY_BITS
)) != NULL
308 && !OSSL_PARAM_set_int(p
, DH_security_bits(dh
)))
310 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_MAX_SIZE
)) != NULL
311 && !OSSL_PARAM_set_int(p
, DH_size(dh
)))
313 if ((p
= OSSL_PARAM_locate(params
, OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY
)) != NULL
) {
314 if (p
->data_type
!= OSSL_PARAM_OCTET_STRING
)
316 p
->return_size
= dh_key2buf(dh
, (unsigned char **)&p
->data
,
318 if (p
->return_size
== 0)
322 return dh_params_todata(dh
, NULL
, params
)
323 && dh_key_todata(dh
, NULL
, params
);
326 static const OSSL_PARAM dh_params
[] = {
327 OSSL_PARAM_int(OSSL_PKEY_PARAM_BITS
, NULL
),
328 OSSL_PARAM_int(OSSL_PKEY_PARAM_SECURITY_BITS
, NULL
),
329 OSSL_PARAM_int(OSSL_PKEY_PARAM_MAX_SIZE
, NULL
),
330 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY
, NULL
, 0),
331 DH_IMEXPORTABLE_PARAMETERS
,
332 DH_IMEXPORTABLE_PUBLIC_KEY
,
333 DH_IMEXPORTABLE_PRIVATE_KEY
,
337 static const OSSL_PARAM
*dh_gettable_params(void *provctx
)
342 static const OSSL_PARAM dh_known_settable_params
[] = {
343 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY
, NULL
, 0),
347 static const OSSL_PARAM
*dh_settable_params(void *provctx
)
349 return dh_known_settable_params
;
352 static int dh_set_params(void *key
, const OSSL_PARAM params
[])
357 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY
);
359 && (p
->data_type
!= OSSL_PARAM_OCTET_STRING
360 || !dh_buf2key(dh
, p
->data
, p
->data_size
)))
366 static int dh_validate_public(DH
*dh
)
368 const BIGNUM
*pub_key
= NULL
;
370 DH_get0_key(dh
, &pub_key
, NULL
);
373 return DH_check_pub_key_ex(dh
, pub_key
);
376 static int dh_validate_private(DH
*dh
)
379 const BIGNUM
*priv_key
= NULL
;
381 DH_get0_key(dh
, NULL
, &priv_key
);
382 if (priv_key
== NULL
)
384 return dh_check_priv_key(dh
, priv_key
, &status
);;
387 static int dh_validate(void *keydata
, int selection
)
392 if (!ossl_prov_is_running())
395 if ((selection
& DH_POSSIBLE_SELECTIONS
) != 0)
398 if ((selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0)
399 ok
= ok
&& DH_check_params_ex(dh
);
401 if ((selection
& OSSL_KEYMGMT_SELECT_PUBLIC_KEY
) != 0)
402 ok
= ok
&& dh_validate_public(dh
);
404 if ((selection
& OSSL_KEYMGMT_SELECT_PRIVATE_KEY
) != 0)
405 ok
= ok
&& dh_validate_private(dh
);
407 if ((selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
)
408 == OSSL_KEYMGMT_SELECT_KEYPAIR
)
409 ok
= ok
&& dh_check_pairwise(dh
);
413 static void *dh_gen_init_base(void *provctx
, int selection
, int type
)
415 OSSL_LIB_CTX
*libctx
= PROV_LIBCTX_OF(provctx
);
416 struct dh_gen_ctx
*gctx
= NULL
;
418 if (!ossl_prov_is_running())
421 if ((selection
& (OSSL_KEYMGMT_SELECT_KEYPAIR
422 | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
)) == 0)
425 if ((gctx
= OPENSSL_zalloc(sizeof(*gctx
))) != NULL
) {
426 gctx
->selection
= selection
;
427 gctx
->libctx
= libctx
;
431 gctx
->gen_type
= DH_PARAMGEN_TYPE_FIPS_186_4
;
435 gctx
->generator
= DH_GENERATOR_2
;
436 gctx
->dh_type
= type
;
441 static void *dh_gen_init(void *provctx
, int selection
)
443 return dh_gen_init_base(provctx
, selection
, DH_FLAG_TYPE_DH
);
446 static void *dhx_gen_init(void *provctx
, int selection
)
448 return dh_gen_init_base(provctx
, selection
, DH_FLAG_TYPE_DHX
);
451 static int dh_gen_set_template(void *genctx
, void *templ
)
453 struct dh_gen_ctx
*gctx
= genctx
;
456 if (!ossl_prov_is_running() || gctx
== NULL
|| dh
== NULL
)
458 gctx
->ffc_params
= dh_get0_params(dh
);
462 static int dh_set_gen_seed(struct dh_gen_ctx
*gctx
, unsigned char *seed
,
465 OPENSSL_clear_free(gctx
->seed
, gctx
->seedlen
);
468 if (seed
!= NULL
&& seedlen
> 0) {
469 gctx
->seed
= OPENSSL_memdup(seed
, seedlen
);
470 if (gctx
->seed
== NULL
)
472 gctx
->seedlen
= seedlen
;
477 static int dh_gen_set_params(void *genctx
, const OSSL_PARAM params
[])
479 struct dh_gen_ctx
*gctx
= genctx
;
485 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_TYPE
);
487 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
488 || ((gctx
->gen_type
= dh_gen_type_name2id(p
->data
)) == -1)) {
489 ERR_raise(ERR_LIB_PROV
, ERR_R_PASSED_INVALID_ARGUMENT
);
493 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_GROUP_NAME
);
495 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
496 || ((gctx
->group_nid
= ossl_ffc_named_group_to_uid(p
->data
)) == NID_undef
)) {
497 ERR_raise(ERR_LIB_PROV
, ERR_R_PASSED_INVALID_ARGUMENT
);
500 gctx
->gen_type
= DH_PARAMGEN_TYPE_GROUP
;
502 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_DH_GENERATOR
);
503 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->generator
))
505 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_GINDEX
);
506 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->gindex
))
508 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_PCOUNTER
);
509 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->pcounter
))
511 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_H
);
512 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->hindex
))
514 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_SEED
);
516 && (p
->data_type
!= OSSL_PARAM_OCTET_STRING
517 || !dh_set_gen_seed(gctx
, p
->data
, p
->data_size
)))
520 if ((p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_PBITS
)) != NULL
521 && !OSSL_PARAM_get_size_t(p
, &gctx
->pbits
))
523 if ((p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_QBITS
)) != NULL
524 && !OSSL_PARAM_get_size_t(p
, &gctx
->qbits
))
526 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_DIGEST
);
528 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
)
530 gctx
->mdname
= p
->data
;
532 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_FFC_DIGEST_PROPS
);
534 if (p
->data_type
!= OSSL_PARAM_UTF8_STRING
)
536 gctx
->mdprops
= p
->data
;
538 p
= OSSL_PARAM_locate_const(params
, OSSL_PKEY_PARAM_DH_PRIV_LEN
);
539 if (p
!= NULL
&& !OSSL_PARAM_get_int(p
, &gctx
->priv_len
))
544 static const OSSL_PARAM
*dh_gen_settable_params(void *provctx
)
546 static OSSL_PARAM settable
[] = {
547 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME
, NULL
, 0),
548 OSSL_PARAM_int(OSSL_PKEY_PARAM_DH_PRIV_LEN
, NULL
),
549 OSSL_PARAM_int(OSSL_PKEY_PARAM_DH_GENERATOR
, NULL
),
550 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_TYPE
, NULL
, 0),
551 OSSL_PARAM_size_t(OSSL_PKEY_PARAM_FFC_PBITS
, NULL
),
552 OSSL_PARAM_size_t(OSSL_PKEY_PARAM_FFC_QBITS
, NULL
),
553 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_DIGEST
, NULL
, 0),
554 OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_FFC_DIGEST_PROPS
, NULL
, 0),
555 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_GINDEX
, NULL
),
556 OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_FFC_SEED
, NULL
, 0),
557 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_PCOUNTER
, NULL
),
558 OSSL_PARAM_int(OSSL_PKEY_PARAM_FFC_H
, NULL
),
564 static int dh_gencb(int p
, int n
, BN_GENCB
*cb
)
566 struct dh_gen_ctx
*gctx
= BN_GENCB_get_arg(cb
);
567 OSSL_PARAM params
[] = { OSSL_PARAM_END
, OSSL_PARAM_END
, OSSL_PARAM_END
};
569 params
[0] = OSSL_PARAM_construct_int(OSSL_GEN_PARAM_POTENTIAL
, &p
);
570 params
[1] = OSSL_PARAM_construct_int(OSSL_GEN_PARAM_ITERATION
, &n
);
572 return gctx
->cb(params
, gctx
->cbarg
);
575 static void *dh_gen(void *genctx
, OSSL_CALLBACK
*osslcb
, void *cbarg
)
578 struct dh_gen_ctx
*gctx
= genctx
;
580 BN_GENCB
*gencb
= NULL
;
583 if (!ossl_prov_is_running() || gctx
== NULL
)
586 /* For parameter generation - If there is a group name just create it */
587 if (gctx
->gen_type
== DH_PARAMGEN_TYPE_GROUP
) {
588 /* Select a named group if there is not one already */
589 if (gctx
->group_nid
== NID_undef
)
590 gctx
->group_nid
= dh_get_named_group_uid_from_size(gctx
->pbits
);
591 if (gctx
->group_nid
== NID_undef
)
593 dh
= dh_new_by_nid_ex(gctx
->libctx
, gctx
->group_nid
);
596 ffc
= dh_get0_params(dh
);
598 dh
= dh_new_ex(gctx
->libctx
);
601 ffc
= dh_get0_params(dh
);
603 /* Copy the template value if one was passed */
604 if (gctx
->ffc_params
!= NULL
605 && !ossl_ffc_params_copy(ffc
, gctx
->ffc_params
))
608 if (!ossl_ffc_params_set_seed(ffc
, gctx
->seed
, gctx
->seedlen
))
610 if (gctx
->gindex
!= -1) {
611 ossl_ffc_params_set_gindex(ffc
, gctx
->gindex
);
612 if (gctx
->pcounter
!= -1)
613 ossl_ffc_params_set_pcounter(ffc
, gctx
->pcounter
);
614 } else if (gctx
->hindex
!= 0) {
615 ossl_ffc_params_set_h(ffc
, gctx
->hindex
);
617 if (gctx
->mdname
!= NULL
) {
618 if (!ossl_ffc_set_digest(ffc
, gctx
->mdname
, gctx
->mdprops
))
623 gencb
= BN_GENCB_new();
625 BN_GENCB_set(gencb
, dh_gencb
, genctx
);
627 if ((gctx
->selection
& OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
) != 0) {
629 * NOTE: The old safe prime generator code is not used in fips mode,
630 * (i.e internally it ignores the generator and chooses a named
631 * group based on pbits.
633 if (gctx
->gen_type
== DH_PARAMGEN_TYPE_GENERATOR
)
634 ret
= DH_generate_parameters_ex(dh
, gctx
->pbits
,
635 gctx
->generator
, gencb
);
637 ret
= dh_generate_ffc_parameters(dh
, gctx
->gen_type
, gctx
->pbits
,
644 if ((gctx
->selection
& OSSL_KEYMGMT_SELECT_KEYPAIR
) != 0) {
645 if (ffc
->p
== NULL
|| ffc
->g
== NULL
)
647 if (gctx
->priv_len
> 0)
648 DH_set_length(dh
, (long)gctx
->priv_len
);
649 ossl_ffc_params_enable_flags(ffc
, FFC_PARAM_FLAG_VALIDATE_LEGACY
,
650 gctx
->gen_type
== DH_PARAMGEN_TYPE_FIPS_186_2
);
651 if (DH_generate_key(dh
) <= 0)
654 DH_clear_flags(dh
, DH_FLAG_TYPE_MASK
);
655 DH_set_flags(dh
, gctx
->dh_type
);
663 BN_GENCB_free(gencb
);
667 static void dh_gen_cleanup(void *genctx
)
669 struct dh_gen_ctx
*gctx
= genctx
;
674 OPENSSL_clear_free(gctx
->seed
, gctx
->seedlen
);
678 void *dh_load(const void *reference
, size_t reference_sz
)
682 if (ossl_prov_is_running() && reference_sz
== sizeof(dh
)) {
683 /* The contents of the reference is the address to our object */
684 dh
= *(DH
**)reference
;
685 /* We grabbed, so we detach it */
686 *(DH
**)reference
= NULL
;
692 const OSSL_DISPATCH ossl_dh_keymgmt_functions
[] = {
693 { OSSL_FUNC_KEYMGMT_NEW
, (void (*)(void))dh_newdata
},
694 { OSSL_FUNC_KEYMGMT_GEN_INIT
, (void (*)(void))dh_gen_init
},
695 { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE
, (void (*)(void))dh_gen_set_template
},
696 { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS
, (void (*)(void))dh_gen_set_params
},
697 { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS
,
698 (void (*)(void))dh_gen_settable_params
},
699 { OSSL_FUNC_KEYMGMT_GEN
, (void (*)(void))dh_gen
},
700 { OSSL_FUNC_KEYMGMT_GEN_CLEANUP
, (void (*)(void))dh_gen_cleanup
},
701 { OSSL_FUNC_KEYMGMT_LOAD
, (void (*)(void))dh_load
},
702 { OSSL_FUNC_KEYMGMT_FREE
, (void (*)(void))dh_freedata
},
703 { OSSL_FUNC_KEYMGMT_GET_PARAMS
, (void (*) (void))dh_get_params
},
704 { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS
, (void (*) (void))dh_gettable_params
},
705 { OSSL_FUNC_KEYMGMT_SET_PARAMS
, (void (*) (void))dh_set_params
},
706 { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS
, (void (*) (void))dh_settable_params
},
707 { OSSL_FUNC_KEYMGMT_HAS
, (void (*)(void))dh_has
},
708 { OSSL_FUNC_KEYMGMT_MATCH
, (void (*)(void))dh_match
},
709 { OSSL_FUNC_KEYMGMT_VALIDATE
, (void (*)(void))dh_validate
},
710 { OSSL_FUNC_KEYMGMT_IMPORT
, (void (*)(void))dh_import
},
711 { OSSL_FUNC_KEYMGMT_IMPORT_TYPES
, (void (*)(void))dh_import_types
},
712 { OSSL_FUNC_KEYMGMT_EXPORT
, (void (*)(void))dh_export
},
713 { OSSL_FUNC_KEYMGMT_EXPORT_TYPES
, (void (*)(void))dh_export_types
},
717 /* For any DH key, we use the "DH" algorithms regardless of sub-type. */
718 static const char *dhx_query_operation_name(int operation_id
)
723 const OSSL_DISPATCH ossl_dhx_keymgmt_functions
[] = {
724 { OSSL_FUNC_KEYMGMT_NEW
, (void (*)(void))dhx_newdata
},
725 { OSSL_FUNC_KEYMGMT_GEN_INIT
, (void (*)(void))dhx_gen_init
},
726 { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE
, (void (*)(void))dh_gen_set_template
},
727 { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS
, (void (*)(void))dh_gen_set_params
},
728 { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS
,
729 (void (*)(void))dh_gen_settable_params
},
730 { OSSL_FUNC_KEYMGMT_GEN
, (void (*)(void))dh_gen
},
731 { OSSL_FUNC_KEYMGMT_GEN_CLEANUP
, (void (*)(void))dh_gen_cleanup
},
732 { OSSL_FUNC_KEYMGMT_LOAD
, (void (*)(void))dh_load
},
733 { OSSL_FUNC_KEYMGMT_FREE
, (void (*)(void))dh_freedata
},
734 { OSSL_FUNC_KEYMGMT_GET_PARAMS
, (void (*) (void))dh_get_params
},
735 { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS
, (void (*) (void))dh_gettable_params
},
736 { OSSL_FUNC_KEYMGMT_SET_PARAMS
, (void (*) (void))dh_set_params
},
737 { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS
, (void (*) (void))dh_settable_params
},
738 { OSSL_FUNC_KEYMGMT_HAS
, (void (*)(void))dh_has
},
739 { OSSL_FUNC_KEYMGMT_MATCH
, (void (*)(void))dh_match
},
740 { OSSL_FUNC_KEYMGMT_VALIDATE
, (void (*)(void))dh_validate
},
741 { OSSL_FUNC_KEYMGMT_IMPORT
, (void (*)(void))dh_import
},
742 { OSSL_FUNC_KEYMGMT_IMPORT_TYPES
, (void (*)(void))dh_import_types
},
743 { OSSL_FUNC_KEYMGMT_EXPORT
, (void (*)(void))dh_export
},
744 { OSSL_FUNC_KEYMGMT_EXPORT_TYPES
, (void (*)(void))dh_export_types
},
745 { OSSL_FUNC_KEYMGMT_QUERY_OPERATION_NAME
,
746 (void (*)(void))dhx_query_operation_name
},