dsa_asn1.c 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203
  1. /* dsa_asn1.c */
  2. /*
  3. * Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL project
  4. * 2000.
  5. */
  6. /* ====================================================================
  7. * Copyright (c) 2000-2005 The OpenSSL Project. All rights reserved.
  8. *
  9. * Redistribution and use in source and binary forms, with or without
  10. * modification, are permitted provided that the following conditions
  11. * are met:
  12. *
  13. * 1. Redistributions of source code must retain the above copyright
  14. * notice, this list of conditions and the following disclaimer.
  15. *
  16. * 2. Redistributions in binary form must reproduce the above copyright
  17. * notice, this list of conditions and the following disclaimer in
  18. * the documentation and/or other materials provided with the
  19. * distribution.
  20. *
  21. * 3. All advertising materials mentioning features or use of this
  22. * software must display the following acknowledgment:
  23. * "This product includes software developed by the OpenSSL Project
  24. * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
  25. *
  26. * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
  27. * endorse or promote products derived from this software without
  28. * prior written permission. For written permission, please contact
  29. * licensing@OpenSSL.org.
  30. *
  31. * 5. Products derived from this software may not be called "OpenSSL"
  32. * nor may "OpenSSL" appear in their names without prior written
  33. * permission of the OpenSSL Project.
  34. *
  35. * 6. Redistributions of any form whatsoever must retain the following
  36. * acknowledgment:
  37. * "This product includes software developed by the OpenSSL Project
  38. * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
  39. *
  40. * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
  41. * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  42. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
  43. * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
  44. * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  45. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  46. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  47. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
  48. * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  49. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  50. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
  51. * OF THE POSSIBILITY OF SUCH DAMAGE.
  52. * ====================================================================
  53. *
  54. * This product includes cryptographic software written by Eric Young
  55. * (eay@cryptsoft.com). This product includes software written by Tim
  56. * Hudson (tjh@cryptsoft.com).
  57. *
  58. */
  59. #include <stdio.h>
  60. #include "cryptlib.h"
  61. #include <openssl/dsa.h>
  62. #include <openssl/asn1.h>
  63. #include <openssl/asn1t.h>
  64. #include <openssl/rand.h>
  65. /* Override the default new methods */
  66. static int sig_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it,
  67. void *exarg)
  68. {
  69. if (operation == ASN1_OP_NEW_PRE) {
  70. DSA_SIG *sig;
  71. sig = OPENSSL_malloc(sizeof(DSA_SIG));
  72. if (!sig) {
  73. DSAerr(DSA_F_SIG_CB, ERR_R_MALLOC_FAILURE);
  74. return 0;
  75. }
  76. sig->r = NULL;
  77. sig->s = NULL;
  78. *pval = (ASN1_VALUE *)sig;
  79. return 2;
  80. }
  81. return 1;
  82. }
  83. ASN1_SEQUENCE_cb(DSA_SIG, sig_cb) = {
  84. ASN1_SIMPLE(DSA_SIG, r, CBIGNUM),
  85. ASN1_SIMPLE(DSA_SIG, s, CBIGNUM)
  86. } ASN1_SEQUENCE_END_cb(DSA_SIG, DSA_SIG)
  87. IMPLEMENT_ASN1_ENCODE_FUNCTIONS_const_fname(DSA_SIG, DSA_SIG, DSA_SIG)
  88. /* Override the default free and new methods */
  89. static int dsa_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it,
  90. void *exarg)
  91. {
  92. if (operation == ASN1_OP_NEW_PRE) {
  93. *pval = (ASN1_VALUE *)DSA_new();
  94. if (*pval)
  95. return 2;
  96. return 0;
  97. } else if (operation == ASN1_OP_FREE_PRE) {
  98. DSA_free((DSA *)*pval);
  99. *pval = NULL;
  100. return 2;
  101. }
  102. return 1;
  103. }
  104. ASN1_SEQUENCE_cb(DSAPrivateKey, dsa_cb) = {
  105. ASN1_SIMPLE(DSA, version, LONG),
  106. ASN1_SIMPLE(DSA, p, BIGNUM),
  107. ASN1_SIMPLE(DSA, q, BIGNUM),
  108. ASN1_SIMPLE(DSA, g, BIGNUM),
  109. ASN1_SIMPLE(DSA, pub_key, BIGNUM),
  110. ASN1_SIMPLE(DSA, priv_key, BIGNUM)
  111. } ASN1_SEQUENCE_END_cb(DSA, DSAPrivateKey)
  112. IMPLEMENT_ASN1_ENCODE_FUNCTIONS_const_fname(DSA, DSAPrivateKey, DSAPrivateKey)
  113. ASN1_SEQUENCE_cb(DSAparams, dsa_cb) = {
  114. ASN1_SIMPLE(DSA, p, BIGNUM),
  115. ASN1_SIMPLE(DSA, q, BIGNUM),
  116. ASN1_SIMPLE(DSA, g, BIGNUM),
  117. } ASN1_SEQUENCE_END_cb(DSA, DSAparams)
  118. IMPLEMENT_ASN1_ENCODE_FUNCTIONS_const_fname(DSA, DSAparams, DSAparams)
  119. /*
  120. * DSA public key is a bit trickier... its effectively a CHOICE type decided
  121. * by a field called write_params which can either write out just the public
  122. * key as an INTEGER or the parameters and public key in a SEQUENCE
  123. */
  124. ASN1_SEQUENCE(dsa_pub_internal) = {
  125. ASN1_SIMPLE(DSA, pub_key, BIGNUM),
  126. ASN1_SIMPLE(DSA, p, BIGNUM),
  127. ASN1_SIMPLE(DSA, q, BIGNUM),
  128. ASN1_SIMPLE(DSA, g, BIGNUM)
  129. } ASN1_SEQUENCE_END_name(DSA, dsa_pub_internal)
  130. ASN1_CHOICE_cb(DSAPublicKey, dsa_cb) = {
  131. ASN1_SIMPLE(DSA, pub_key, BIGNUM),
  132. ASN1_EX_COMBINE(0, 0, dsa_pub_internal)
  133. } ASN1_CHOICE_END_cb(DSA, DSAPublicKey, write_params)
  134. IMPLEMENT_ASN1_ENCODE_FUNCTIONS_const_fname(DSA, DSAPublicKey, DSAPublicKey)
  135. DSA *DSAparams_dup(DSA *dsa)
  136. {
  137. return ASN1_item_dup(ASN1_ITEM_rptr(DSAparams), dsa);
  138. }
  139. int DSA_sign(int type, const unsigned char *dgst, int dlen,
  140. unsigned char *sig, unsigned int *siglen, DSA *dsa)
  141. {
  142. DSA_SIG *s;
  143. RAND_seed(dgst, dlen);
  144. s = DSA_do_sign(dgst, dlen, dsa);
  145. if (s == NULL) {
  146. *siglen = 0;
  147. return (0);
  148. }
  149. *siglen = i2d_DSA_SIG(s, &sig);
  150. DSA_SIG_free(s);
  151. return (1);
  152. }
  153. /* data has already been hashed (probably with SHA or SHA-1). */
  154. /*-
  155. * returns
  156. * 1: correct signature
  157. * 0: incorrect signature
  158. * -1: error
  159. */
  160. int DSA_verify(int type, const unsigned char *dgst, int dgst_len,
  161. const unsigned char *sigbuf, int siglen, DSA *dsa)
  162. {
  163. DSA_SIG *s;
  164. const unsigned char *p = sigbuf;
  165. unsigned char *der = NULL;
  166. int derlen = -1;
  167. int ret = -1;
  168. s = DSA_SIG_new();
  169. if (s == NULL)
  170. return (ret);
  171. if (d2i_DSA_SIG(&s, &p, siglen) == NULL)
  172. goto err;
  173. /* Ensure signature uses DER and doesn't have trailing garbage */
  174. derlen = i2d_DSA_SIG(s, &der);
  175. if (derlen != siglen || memcmp(sigbuf, der, derlen))
  176. goto err;
  177. ret = DSA_do_verify(dgst, dgst_len, s, dsa);
  178. err:
  179. if (derlen > 0) {
  180. OPENSSL_cleanse(der, derlen);
  181. OPENSSL_free(der);
  182. }
  183. DSA_SIG_free(s);
  184. return (ret);
  185. }