]> git.ipfire.org Git - thirdparty/openssl.git/blob - crypto/dh/dh_group_params.c
c71f4053da6c0c8683075ee2be6e6b4ceaa74701
[thirdparty/openssl.git] / crypto / dh / dh_group_params.c
1 /*
2 * Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.
3 *
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
8 */
9
10 /* DH parameters from RFC7919 and RFC3526 */
11
12 /*
13 * DH low level APIs are deprecated for public use, but still ok for
14 * internal use.
15 */
16 #include "internal/deprecated.h"
17
18 #include <stdio.h>
19 #include "internal/cryptlib.h"
20 #include "internal/ffc.h"
21 #include "dh_local.h"
22 #include <openssl/bn.h>
23 #include <openssl/objects.h>
24 #include "internal/nelem.h"
25 #include "crypto/dh.h"
26 #include "e_os.h" /* strcasecmp */
27
28 static DH *dh_param_init(OSSL_LIB_CTX *libctx, const DH_NAMED_GROUP *group)
29 {
30 DH *dh = ossl_dh_new_ex(libctx);
31
32 if (dh == NULL)
33 return NULL;
34
35 ossl_ffc_named_group_set_pqg(&dh->params, group);
36 dh->params.nid = ossl_ffc_named_group_get_uid(group);
37 dh->dirty_cnt++;
38 return dh;
39 }
40
41 DH *ossl_dh_new_by_nid_ex(OSSL_LIB_CTX *libctx, int nid)
42 {
43 const DH_NAMED_GROUP *group;
44
45 if ((group = ossl_ffc_uid_to_dh_named_group(nid)) != NULL)
46 return dh_param_init(libctx, group);
47
48 ERR_raise(ERR_LIB_DH, DH_R_INVALID_PARAMETER_NID);
49 return NULL;
50 }
51
52 DH *DH_new_by_nid(int nid)
53 {
54 return ossl_dh_new_by_nid_ex(NULL, nid);
55 }
56
57 void ossl_dh_cache_named_group(DH *dh)
58 {
59 const DH_NAMED_GROUP *group;
60
61 if (dh == NULL)
62 return;
63
64 dh->params.nid = NID_undef; /* flush cached value */
65
66 /* Exit if p or g is not set */
67 if (dh->params.p == NULL
68 || dh->params.g == NULL)
69 return;
70
71 if ((group = ossl_ffc_numbers_to_dh_named_group(dh->params.p,
72 dh->params.q,
73 dh->params.g)) != NULL) {
74 if (dh->params.q == NULL)
75 dh->params.q = (BIGNUM *)ossl_ffc_named_group_get_q(group);
76 /* cache the nid */
77 dh->params.nid = ossl_ffc_named_group_get_uid(group);
78 dh->dirty_cnt++;
79 }
80 }
81
82 int ossl_dh_is_named_safe_prime_group(const DH *dh)
83 {
84 int id = DH_get_nid(dh);
85
86 /*
87 * Exclude RFC5114 groups (id = 1..3) since they do not have
88 * q = (p - 1) / 2
89 */
90 return (id > 3);
91 }
92
93 int DH_get_nid(const DH *dh)
94 {
95 if (dh == NULL)
96 return NID_undef;
97
98 return dh->params.nid;
99 }