1*72c33676SMaxim Ag /* $OpenBSD: pmeth_fn.c,v 1.6 2017/01/29 17:49:23 beck Exp $ */
2f5b1c8a1SJohn Marino /* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
3f5b1c8a1SJohn Marino * project 2006.
4f5b1c8a1SJohn Marino */
5f5b1c8a1SJohn Marino /* ====================================================================
6f5b1c8a1SJohn Marino * Copyright (c) 2006 The OpenSSL Project. All rights reserved.
7f5b1c8a1SJohn Marino *
8f5b1c8a1SJohn Marino * Redistribution and use in source and binary forms, with or without
9f5b1c8a1SJohn Marino * modification, are permitted provided that the following conditions
10f5b1c8a1SJohn Marino * are met:
11f5b1c8a1SJohn Marino *
12f5b1c8a1SJohn Marino * 1. Redistributions of source code must retain the above copyright
13f5b1c8a1SJohn Marino * notice, this list of conditions and the following disclaimer.
14f5b1c8a1SJohn Marino *
15f5b1c8a1SJohn Marino * 2. Redistributions in binary form must reproduce the above copyright
16f5b1c8a1SJohn Marino * notice, this list of conditions and the following disclaimer in
17f5b1c8a1SJohn Marino * the documentation and/or other materials provided with the
18f5b1c8a1SJohn Marino * distribution.
19f5b1c8a1SJohn Marino *
20f5b1c8a1SJohn Marino * 3. All advertising materials mentioning features or use of this
21f5b1c8a1SJohn Marino * software must display the following acknowledgment:
22f5b1c8a1SJohn Marino * "This product includes software developed by the OpenSSL Project
23f5b1c8a1SJohn Marino * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
24f5b1c8a1SJohn Marino *
25f5b1c8a1SJohn Marino * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
26f5b1c8a1SJohn Marino * endorse or promote products derived from this software without
27f5b1c8a1SJohn Marino * prior written permission. For written permission, please contact
28f5b1c8a1SJohn Marino * licensing@OpenSSL.org.
29f5b1c8a1SJohn Marino *
30f5b1c8a1SJohn Marino * 5. Products derived from this software may not be called "OpenSSL"
31f5b1c8a1SJohn Marino * nor may "OpenSSL" appear in their names without prior written
32f5b1c8a1SJohn Marino * permission of the OpenSSL Project.
33f5b1c8a1SJohn Marino *
34f5b1c8a1SJohn Marino * 6. Redistributions of any form whatsoever must retain the following
35f5b1c8a1SJohn Marino * acknowledgment:
36f5b1c8a1SJohn Marino * "This product includes software developed by the OpenSSL Project
37f5b1c8a1SJohn Marino * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
38f5b1c8a1SJohn Marino *
39f5b1c8a1SJohn Marino * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
40f5b1c8a1SJohn Marino * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
41f5b1c8a1SJohn Marino * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
42f5b1c8a1SJohn Marino * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
43f5b1c8a1SJohn Marino * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
44f5b1c8a1SJohn Marino * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
45f5b1c8a1SJohn Marino * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
46f5b1c8a1SJohn Marino * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
47f5b1c8a1SJohn Marino * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
48f5b1c8a1SJohn Marino * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
49f5b1c8a1SJohn Marino * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
50f5b1c8a1SJohn Marino * OF THE POSSIBILITY OF SUCH DAMAGE.
51f5b1c8a1SJohn Marino * ====================================================================
52f5b1c8a1SJohn Marino *
53f5b1c8a1SJohn Marino * This product includes cryptographic software written by Eric Young
54f5b1c8a1SJohn Marino * (eay@cryptsoft.com). This product includes software written by Tim
55f5b1c8a1SJohn Marino * Hudson (tjh@cryptsoft.com).
56f5b1c8a1SJohn Marino *
57f5b1c8a1SJohn Marino */
58f5b1c8a1SJohn Marino
59f5b1c8a1SJohn Marino #include <stdio.h>
60f5b1c8a1SJohn Marino #include <stdlib.h>
61f5b1c8a1SJohn Marino
62f5b1c8a1SJohn Marino #include <openssl/err.h>
63f5b1c8a1SJohn Marino #include <openssl/evp.h>
64f5b1c8a1SJohn Marino #include <openssl/objects.h>
65f5b1c8a1SJohn Marino
66f5b1c8a1SJohn Marino #include "evp_locl.h"
67f5b1c8a1SJohn Marino
68f5b1c8a1SJohn Marino #define M_check_autoarg(ctx, arg, arglen, err) \
69f5b1c8a1SJohn Marino if (ctx->pmeth->flags & EVP_PKEY_FLAG_AUTOARGLEN) \
70f5b1c8a1SJohn Marino { \
71f5b1c8a1SJohn Marino size_t pksize = (size_t)EVP_PKEY_size(ctx->pkey); \
72f5b1c8a1SJohn Marino if (!arg) \
73f5b1c8a1SJohn Marino { \
74f5b1c8a1SJohn Marino *arglen = pksize; \
75f5b1c8a1SJohn Marino return 1; \
76f5b1c8a1SJohn Marino } \
77f5b1c8a1SJohn Marino else if (*arglen < pksize) \
78f5b1c8a1SJohn Marino { \
79*72c33676SMaxim Ag EVPerror(EVP_R_BUFFER_TOO_SMALL); /*ckerr_ignore*/\
80f5b1c8a1SJohn Marino return 0; \
81f5b1c8a1SJohn Marino } \
82f5b1c8a1SJohn Marino }
83f5b1c8a1SJohn Marino
84f5b1c8a1SJohn Marino int
EVP_PKEY_sign_init(EVP_PKEY_CTX * ctx)85f5b1c8a1SJohn Marino EVP_PKEY_sign_init(EVP_PKEY_CTX *ctx)
86f5b1c8a1SJohn Marino {
87f5b1c8a1SJohn Marino int ret;
88f5b1c8a1SJohn Marino
89f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->sign) {
90*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
91f5b1c8a1SJohn Marino return -2;
92f5b1c8a1SJohn Marino }
93f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_SIGN;
94f5b1c8a1SJohn Marino if (!ctx->pmeth->sign_init)
95f5b1c8a1SJohn Marino return 1;
96f5b1c8a1SJohn Marino ret = ctx->pmeth->sign_init(ctx);
97f5b1c8a1SJohn Marino if (ret <= 0)
98f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_UNDEFINED;
99f5b1c8a1SJohn Marino return ret;
100f5b1c8a1SJohn Marino }
101f5b1c8a1SJohn Marino
102f5b1c8a1SJohn Marino int
EVP_PKEY_sign(EVP_PKEY_CTX * ctx,unsigned char * sig,size_t * siglen,const unsigned char * tbs,size_t tbslen)103f5b1c8a1SJohn Marino EVP_PKEY_sign(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen,
104f5b1c8a1SJohn Marino const unsigned char *tbs, size_t tbslen)
105f5b1c8a1SJohn Marino {
106f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->sign) {
107*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
108f5b1c8a1SJohn Marino return -2;
109f5b1c8a1SJohn Marino }
110f5b1c8a1SJohn Marino if (ctx->operation != EVP_PKEY_OP_SIGN) {
111*72c33676SMaxim Ag EVPerror(EVP_R_OPERATON_NOT_INITIALIZED);
112f5b1c8a1SJohn Marino return -1;
113f5b1c8a1SJohn Marino }
114f5b1c8a1SJohn Marino M_check_autoarg(ctx, sig, siglen, EVP_F_EVP_PKEY_SIGN)
115f5b1c8a1SJohn Marino return ctx->pmeth->sign(ctx, sig, siglen, tbs, tbslen);
116f5b1c8a1SJohn Marino }
117f5b1c8a1SJohn Marino
118f5b1c8a1SJohn Marino int
EVP_PKEY_verify_init(EVP_PKEY_CTX * ctx)119f5b1c8a1SJohn Marino EVP_PKEY_verify_init(EVP_PKEY_CTX *ctx)
120f5b1c8a1SJohn Marino {
121f5b1c8a1SJohn Marino int ret;
122f5b1c8a1SJohn Marino
123f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->verify) {
124*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
125f5b1c8a1SJohn Marino return -2;
126f5b1c8a1SJohn Marino }
127f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_VERIFY;
128f5b1c8a1SJohn Marino if (!ctx->pmeth->verify_init)
129f5b1c8a1SJohn Marino return 1;
130f5b1c8a1SJohn Marino ret = ctx->pmeth->verify_init(ctx);
131f5b1c8a1SJohn Marino if (ret <= 0)
132f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_UNDEFINED;
133f5b1c8a1SJohn Marino return ret;
134f5b1c8a1SJohn Marino }
135f5b1c8a1SJohn Marino
136f5b1c8a1SJohn Marino int
EVP_PKEY_verify(EVP_PKEY_CTX * ctx,const unsigned char * sig,size_t siglen,const unsigned char * tbs,size_t tbslen)137f5b1c8a1SJohn Marino EVP_PKEY_verify(EVP_PKEY_CTX *ctx, const unsigned char *sig, size_t siglen,
138f5b1c8a1SJohn Marino const unsigned char *tbs, size_t tbslen)
139f5b1c8a1SJohn Marino {
140f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->verify) {
141*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
142f5b1c8a1SJohn Marino return -2;
143f5b1c8a1SJohn Marino }
144f5b1c8a1SJohn Marino if (ctx->operation != EVP_PKEY_OP_VERIFY) {
145*72c33676SMaxim Ag EVPerror(EVP_R_OPERATON_NOT_INITIALIZED);
146f5b1c8a1SJohn Marino return -1;
147f5b1c8a1SJohn Marino }
148f5b1c8a1SJohn Marino return ctx->pmeth->verify(ctx, sig, siglen, tbs, tbslen);
149f5b1c8a1SJohn Marino }
150f5b1c8a1SJohn Marino
151f5b1c8a1SJohn Marino int
EVP_PKEY_verify_recover_init(EVP_PKEY_CTX * ctx)152f5b1c8a1SJohn Marino EVP_PKEY_verify_recover_init(EVP_PKEY_CTX *ctx)
153f5b1c8a1SJohn Marino {
154f5b1c8a1SJohn Marino int ret;
155f5b1c8a1SJohn Marino
156f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->verify_recover) {
157*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
158f5b1c8a1SJohn Marino return -2;
159f5b1c8a1SJohn Marino }
160f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_VERIFYRECOVER;
161f5b1c8a1SJohn Marino if (!ctx->pmeth->verify_recover_init)
162f5b1c8a1SJohn Marino return 1;
163f5b1c8a1SJohn Marino ret = ctx->pmeth->verify_recover_init(ctx);
164f5b1c8a1SJohn Marino if (ret <= 0)
165f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_UNDEFINED;
166f5b1c8a1SJohn Marino return ret;
167f5b1c8a1SJohn Marino }
168f5b1c8a1SJohn Marino
169f5b1c8a1SJohn Marino int
EVP_PKEY_verify_recover(EVP_PKEY_CTX * ctx,unsigned char * rout,size_t * routlen,const unsigned char * sig,size_t siglen)170f5b1c8a1SJohn Marino EVP_PKEY_verify_recover(EVP_PKEY_CTX *ctx, unsigned char *rout, size_t *routlen,
171f5b1c8a1SJohn Marino const unsigned char *sig, size_t siglen)
172f5b1c8a1SJohn Marino {
173f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->verify_recover) {
174*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
175f5b1c8a1SJohn Marino return -2;
176f5b1c8a1SJohn Marino }
177f5b1c8a1SJohn Marino if (ctx->operation != EVP_PKEY_OP_VERIFYRECOVER) {
178*72c33676SMaxim Ag EVPerror(EVP_R_OPERATON_NOT_INITIALIZED);
179f5b1c8a1SJohn Marino return -1;
180f5b1c8a1SJohn Marino }
181f5b1c8a1SJohn Marino M_check_autoarg(ctx, rout, routlen, EVP_F_EVP_PKEY_VERIFY_RECOVER)
182f5b1c8a1SJohn Marino return ctx->pmeth->verify_recover(ctx, rout, routlen, sig, siglen);
183f5b1c8a1SJohn Marino }
184f5b1c8a1SJohn Marino
185f5b1c8a1SJohn Marino int
EVP_PKEY_encrypt_init(EVP_PKEY_CTX * ctx)186f5b1c8a1SJohn Marino EVP_PKEY_encrypt_init(EVP_PKEY_CTX *ctx)
187f5b1c8a1SJohn Marino {
188f5b1c8a1SJohn Marino int ret;
189f5b1c8a1SJohn Marino
190f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->encrypt) {
191*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
192f5b1c8a1SJohn Marino return -2;
193f5b1c8a1SJohn Marino }
194f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_ENCRYPT;
195f5b1c8a1SJohn Marino if (!ctx->pmeth->encrypt_init)
196f5b1c8a1SJohn Marino return 1;
197f5b1c8a1SJohn Marino ret = ctx->pmeth->encrypt_init(ctx);
198f5b1c8a1SJohn Marino if (ret <= 0)
199f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_UNDEFINED;
200f5b1c8a1SJohn Marino return ret;
201f5b1c8a1SJohn Marino }
202f5b1c8a1SJohn Marino
203f5b1c8a1SJohn Marino int
EVP_PKEY_encrypt(EVP_PKEY_CTX * ctx,unsigned char * out,size_t * outlen,const unsigned char * in,size_t inlen)204f5b1c8a1SJohn Marino EVP_PKEY_encrypt(EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen,
205f5b1c8a1SJohn Marino const unsigned char *in, size_t inlen)
206f5b1c8a1SJohn Marino {
207f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->encrypt) {
208*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
209f5b1c8a1SJohn Marino return -2;
210f5b1c8a1SJohn Marino }
211f5b1c8a1SJohn Marino if (ctx->operation != EVP_PKEY_OP_ENCRYPT) {
212*72c33676SMaxim Ag EVPerror(EVP_R_OPERATON_NOT_INITIALIZED);
213f5b1c8a1SJohn Marino return -1;
214f5b1c8a1SJohn Marino }
215f5b1c8a1SJohn Marino M_check_autoarg(ctx, out, outlen, EVP_F_EVP_PKEY_ENCRYPT)
216f5b1c8a1SJohn Marino return ctx->pmeth->encrypt(ctx, out, outlen, in, inlen);
217f5b1c8a1SJohn Marino }
218f5b1c8a1SJohn Marino
219f5b1c8a1SJohn Marino int
EVP_PKEY_decrypt_init(EVP_PKEY_CTX * ctx)220f5b1c8a1SJohn Marino EVP_PKEY_decrypt_init(EVP_PKEY_CTX *ctx)
221f5b1c8a1SJohn Marino {
222f5b1c8a1SJohn Marino int ret;
223f5b1c8a1SJohn Marino
224f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->decrypt) {
225*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
226f5b1c8a1SJohn Marino return -2;
227f5b1c8a1SJohn Marino }
228f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_DECRYPT;
229f5b1c8a1SJohn Marino if (!ctx->pmeth->decrypt_init)
230f5b1c8a1SJohn Marino return 1;
231f5b1c8a1SJohn Marino ret = ctx->pmeth->decrypt_init(ctx);
232f5b1c8a1SJohn Marino if (ret <= 0)
233f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_UNDEFINED;
234f5b1c8a1SJohn Marino return ret;
235f5b1c8a1SJohn Marino }
236f5b1c8a1SJohn Marino
237f5b1c8a1SJohn Marino int
EVP_PKEY_decrypt(EVP_PKEY_CTX * ctx,unsigned char * out,size_t * outlen,const unsigned char * in,size_t inlen)238f5b1c8a1SJohn Marino EVP_PKEY_decrypt(EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen,
239f5b1c8a1SJohn Marino const unsigned char *in, size_t inlen)
240f5b1c8a1SJohn Marino {
241f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->decrypt) {
242*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
243f5b1c8a1SJohn Marino return -2;
244f5b1c8a1SJohn Marino }
245f5b1c8a1SJohn Marino if (ctx->operation != EVP_PKEY_OP_DECRYPT) {
246*72c33676SMaxim Ag EVPerror(EVP_R_OPERATON_NOT_INITIALIZED);
247f5b1c8a1SJohn Marino return -1;
248f5b1c8a1SJohn Marino }
249f5b1c8a1SJohn Marino M_check_autoarg(ctx, out, outlen, EVP_F_EVP_PKEY_DECRYPT)
250f5b1c8a1SJohn Marino return ctx->pmeth->decrypt(ctx, out, outlen, in, inlen);
251f5b1c8a1SJohn Marino }
252f5b1c8a1SJohn Marino
253f5b1c8a1SJohn Marino int
EVP_PKEY_derive_init(EVP_PKEY_CTX * ctx)254f5b1c8a1SJohn Marino EVP_PKEY_derive_init(EVP_PKEY_CTX *ctx)
255f5b1c8a1SJohn Marino {
256f5b1c8a1SJohn Marino int ret;
257f5b1c8a1SJohn Marino
258f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->derive) {
259*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
260f5b1c8a1SJohn Marino return -2;
261f5b1c8a1SJohn Marino }
262f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_DERIVE;
263f5b1c8a1SJohn Marino if (!ctx->pmeth->derive_init)
264f5b1c8a1SJohn Marino return 1;
265f5b1c8a1SJohn Marino ret = ctx->pmeth->derive_init(ctx);
266f5b1c8a1SJohn Marino if (ret <= 0)
267f5b1c8a1SJohn Marino ctx->operation = EVP_PKEY_OP_UNDEFINED;
268f5b1c8a1SJohn Marino return ret;
269f5b1c8a1SJohn Marino }
270f5b1c8a1SJohn Marino
271f5b1c8a1SJohn Marino int
EVP_PKEY_derive_set_peer(EVP_PKEY_CTX * ctx,EVP_PKEY * peer)272f5b1c8a1SJohn Marino EVP_PKEY_derive_set_peer(EVP_PKEY_CTX *ctx, EVP_PKEY *peer)
273f5b1c8a1SJohn Marino {
274f5b1c8a1SJohn Marino int ret;
275f5b1c8a1SJohn Marino
276f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !(ctx->pmeth->derive ||
277f5b1c8a1SJohn Marino ctx->pmeth->encrypt || ctx->pmeth->decrypt) ||
278f5b1c8a1SJohn Marino !ctx->pmeth->ctrl) {
279*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
280f5b1c8a1SJohn Marino return -2;
281f5b1c8a1SJohn Marino }
282f5b1c8a1SJohn Marino if (ctx->operation != EVP_PKEY_OP_DERIVE &&
283f5b1c8a1SJohn Marino ctx->operation != EVP_PKEY_OP_ENCRYPT &&
284f5b1c8a1SJohn Marino ctx->operation != EVP_PKEY_OP_DECRYPT) {
285*72c33676SMaxim Ag EVPerror(EVP_R_OPERATON_NOT_INITIALIZED);
286f5b1c8a1SJohn Marino return -1;
287f5b1c8a1SJohn Marino }
288f5b1c8a1SJohn Marino
289f5b1c8a1SJohn Marino ret = ctx->pmeth->ctrl(ctx, EVP_PKEY_CTRL_PEER_KEY, 0, peer);
290f5b1c8a1SJohn Marino
291f5b1c8a1SJohn Marino if (ret <= 0)
292f5b1c8a1SJohn Marino return ret;
293f5b1c8a1SJohn Marino
294f5b1c8a1SJohn Marino if (ret == 2)
295f5b1c8a1SJohn Marino return 1;
296f5b1c8a1SJohn Marino
297f5b1c8a1SJohn Marino if (!ctx->pkey) {
298*72c33676SMaxim Ag EVPerror(EVP_R_NO_KEY_SET);
299f5b1c8a1SJohn Marino return -1;
300f5b1c8a1SJohn Marino }
301f5b1c8a1SJohn Marino
302f5b1c8a1SJohn Marino if (ctx->pkey->type != peer->type) {
303*72c33676SMaxim Ag EVPerror(EVP_R_DIFFERENT_KEY_TYPES);
304f5b1c8a1SJohn Marino return -1;
305f5b1c8a1SJohn Marino }
306f5b1c8a1SJohn Marino
307f5b1c8a1SJohn Marino /* ran@cryptocom.ru: For clarity. The error is if parameters in peer are
308f5b1c8a1SJohn Marino * present (!missing) but don't match. EVP_PKEY_cmp_parameters may return
309f5b1c8a1SJohn Marino * 1 (match), 0 (don't match) and -2 (comparison is not defined). -1
310f5b1c8a1SJohn Marino * (different key types) is impossible here because it is checked earlier.
311f5b1c8a1SJohn Marino * -2 is OK for us here, as well as 1, so we can check for 0 only. */
312f5b1c8a1SJohn Marino if (!EVP_PKEY_missing_parameters(peer) &&
313f5b1c8a1SJohn Marino !EVP_PKEY_cmp_parameters(ctx->pkey, peer)) {
314*72c33676SMaxim Ag EVPerror(EVP_R_DIFFERENT_PARAMETERS);
315f5b1c8a1SJohn Marino return -1;
316f5b1c8a1SJohn Marino }
317f5b1c8a1SJohn Marino
318f5b1c8a1SJohn Marino EVP_PKEY_free(ctx->peerkey);
319f5b1c8a1SJohn Marino ctx->peerkey = peer;
320f5b1c8a1SJohn Marino
321f5b1c8a1SJohn Marino ret = ctx->pmeth->ctrl(ctx, EVP_PKEY_CTRL_PEER_KEY, 1, peer);
322f5b1c8a1SJohn Marino
323f5b1c8a1SJohn Marino if (ret <= 0) {
324f5b1c8a1SJohn Marino ctx->peerkey = NULL;
325f5b1c8a1SJohn Marino return ret;
326f5b1c8a1SJohn Marino }
327f5b1c8a1SJohn Marino
328f5b1c8a1SJohn Marino CRYPTO_add(&peer->references, 1, CRYPTO_LOCK_EVP_PKEY);
329f5b1c8a1SJohn Marino return 1;
330f5b1c8a1SJohn Marino }
331f5b1c8a1SJohn Marino
332f5b1c8a1SJohn Marino int
EVP_PKEY_derive(EVP_PKEY_CTX * ctx,unsigned char * key,size_t * pkeylen)333f5b1c8a1SJohn Marino EVP_PKEY_derive(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *pkeylen)
334f5b1c8a1SJohn Marino {
335f5b1c8a1SJohn Marino if (!ctx || !ctx->pmeth || !ctx->pmeth->derive) {
336*72c33676SMaxim Ag EVPerror(EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
337f5b1c8a1SJohn Marino return -2;
338f5b1c8a1SJohn Marino }
339f5b1c8a1SJohn Marino if (ctx->operation != EVP_PKEY_OP_DERIVE) {
340*72c33676SMaxim Ag EVPerror(EVP_R_OPERATON_NOT_INITIALIZED);
341f5b1c8a1SJohn Marino return -1;
342f5b1c8a1SJohn Marino }
343f5b1c8a1SJohn Marino M_check_autoarg(ctx, key, pkeylen, EVP_F_EVP_PKEY_DERIVE)
344f5b1c8a1SJohn Marino return ctx->pmeth->derive(ctx, key, pkeylen);
345f5b1c8a1SJohn Marino }
346