1b077aed3SPierre Pronchery /*
2b077aed3SPierre Pronchery * Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.
3b077aed3SPierre Pronchery *
4b077aed3SPierre Pronchery * Licensed under the Apache License 2.0 (the "License"). You may not use
5b077aed3SPierre Pronchery * this file except in compliance with the License. You can obtain a copy
6b077aed3SPierre Pronchery * in the file LICENSE in the source distribution or at
7b077aed3SPierre Pronchery * https://www.openssl.org/source/license.html
8b077aed3SPierre Pronchery */
9b077aed3SPierre Pronchery
10b077aed3SPierre Pronchery /*
11b077aed3SPierre Pronchery * DES low level APIs are deprecated for public use, but still ok for internal
12b077aed3SPierre Pronchery * use.
13b077aed3SPierre Pronchery */
14b077aed3SPierre Pronchery #include "internal/deprecated.h"
15b077aed3SPierre Pronchery
16b077aed3SPierre Pronchery #include <openssl/rand.h>
17b077aed3SPierre Pronchery #include <openssl/proverr.h>
18b077aed3SPierre Pronchery #include "prov/ciphercommon.h"
19b077aed3SPierre Pronchery #include "cipher_tdes.h"
20b077aed3SPierre Pronchery #include "prov/implementations.h"
21b077aed3SPierre Pronchery #include "prov/providercommon.h"
22b077aed3SPierre Pronchery
ossl_tdes_newctx(void * provctx,int mode,size_t kbits,size_t blkbits,size_t ivbits,uint64_t flags,const PROV_CIPHER_HW * hw)23b077aed3SPierre Pronchery void *ossl_tdes_newctx(void *provctx, int mode, size_t kbits, size_t blkbits,
24b077aed3SPierre Pronchery size_t ivbits, uint64_t flags, const PROV_CIPHER_HW *hw)
25b077aed3SPierre Pronchery {
26b077aed3SPierre Pronchery PROV_TDES_CTX *tctx;
27b077aed3SPierre Pronchery
28b077aed3SPierre Pronchery if (!ossl_prov_is_running())
29b077aed3SPierre Pronchery return NULL;
30b077aed3SPierre Pronchery
31b077aed3SPierre Pronchery tctx = OPENSSL_zalloc(sizeof(*tctx));
32b077aed3SPierre Pronchery if (tctx != NULL)
33b077aed3SPierre Pronchery ossl_cipher_generic_initkey(tctx, kbits, blkbits, ivbits, mode, flags,
34b077aed3SPierre Pronchery hw, provctx);
35b077aed3SPierre Pronchery return tctx;
36b077aed3SPierre Pronchery }
37b077aed3SPierre Pronchery
ossl_tdes_dupctx(void * ctx)38b077aed3SPierre Pronchery void *ossl_tdes_dupctx(void *ctx)
39b077aed3SPierre Pronchery {
40b077aed3SPierre Pronchery PROV_TDES_CTX *in = (PROV_TDES_CTX *)ctx;
41b077aed3SPierre Pronchery PROV_TDES_CTX *ret;
42b077aed3SPierre Pronchery
43b077aed3SPierre Pronchery if (!ossl_prov_is_running())
44b077aed3SPierre Pronchery return NULL;
45b077aed3SPierre Pronchery
46b077aed3SPierre Pronchery ret = OPENSSL_malloc(sizeof(*ret));
47b077aed3SPierre Pronchery if (ret == NULL) {
48b077aed3SPierre Pronchery ERR_raise(ERR_LIB_PROV, ERR_R_MALLOC_FAILURE);
49b077aed3SPierre Pronchery return NULL;
50b077aed3SPierre Pronchery }
51b077aed3SPierre Pronchery in->base.hw->copyctx(&ret->base, &in->base);
52b077aed3SPierre Pronchery
53b077aed3SPierre Pronchery return ret;
54b077aed3SPierre Pronchery }
55b077aed3SPierre Pronchery
ossl_tdes_freectx(void * vctx)56b077aed3SPierre Pronchery void ossl_tdes_freectx(void *vctx)
57b077aed3SPierre Pronchery {
58b077aed3SPierre Pronchery PROV_TDES_CTX *ctx = (PROV_TDES_CTX *)vctx;
59b077aed3SPierre Pronchery
60b077aed3SPierre Pronchery ossl_cipher_generic_reset_ctx((PROV_CIPHER_CTX *)vctx);
61b077aed3SPierre Pronchery OPENSSL_clear_free(ctx, sizeof(*ctx));
62b077aed3SPierre Pronchery }
63b077aed3SPierre Pronchery
tdes_init(void * vctx,const unsigned char * key,size_t keylen,const unsigned char * iv,size_t ivlen,const OSSL_PARAM params[],int enc)64b077aed3SPierre Pronchery static int tdes_init(void *vctx, const unsigned char *key, size_t keylen,
65b077aed3SPierre Pronchery const unsigned char *iv, size_t ivlen,
66b077aed3SPierre Pronchery const OSSL_PARAM params[], int enc)
67b077aed3SPierre Pronchery {
68b077aed3SPierre Pronchery PROV_CIPHER_CTX *ctx = (PROV_CIPHER_CTX *)vctx;
69b077aed3SPierre Pronchery
70b077aed3SPierre Pronchery if (!ossl_prov_is_running())
71b077aed3SPierre Pronchery return 0;
72b077aed3SPierre Pronchery
73b077aed3SPierre Pronchery ctx->num = 0;
74b077aed3SPierre Pronchery ctx->bufsz = 0;
75b077aed3SPierre Pronchery ctx->enc = enc;
76b077aed3SPierre Pronchery
77b077aed3SPierre Pronchery if (iv != NULL) {
78b077aed3SPierre Pronchery if (!ossl_cipher_generic_initiv(ctx, iv, ivlen))
79b077aed3SPierre Pronchery return 0;
80b077aed3SPierre Pronchery } else if (ctx->iv_set
81b077aed3SPierre Pronchery && (ctx->mode == EVP_CIPH_CBC_MODE
82b077aed3SPierre Pronchery || ctx->mode == EVP_CIPH_CFB_MODE
83b077aed3SPierre Pronchery || ctx->mode == EVP_CIPH_OFB_MODE)) {
84b077aed3SPierre Pronchery /* reset IV to keep compatibility with 1.1.1 */
85b077aed3SPierre Pronchery memcpy(ctx->iv, ctx->oiv, ctx->ivlen);
86b077aed3SPierre Pronchery }
87b077aed3SPierre Pronchery
88b077aed3SPierre Pronchery if (key != NULL) {
89b077aed3SPierre Pronchery if (keylen != ctx->keylen) {
90b077aed3SPierre Pronchery ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH);
91b077aed3SPierre Pronchery return 0;
92b077aed3SPierre Pronchery }
93b077aed3SPierre Pronchery if (!ctx->hw->init(ctx, key, ctx->keylen))
94b077aed3SPierre Pronchery return 0;
95*e0c4386eSCy Schubert ctx->key_set = 1;
96b077aed3SPierre Pronchery }
97b077aed3SPierre Pronchery return ossl_cipher_generic_set_ctx_params(ctx, params);
98b077aed3SPierre Pronchery }
99b077aed3SPierre Pronchery
ossl_tdes_einit(void * vctx,const unsigned char * key,size_t keylen,const unsigned char * iv,size_t ivlen,const OSSL_PARAM params[])100b077aed3SPierre Pronchery int ossl_tdes_einit(void *vctx, const unsigned char *key, size_t keylen,
101b077aed3SPierre Pronchery const unsigned char *iv, size_t ivlen,
102b077aed3SPierre Pronchery const OSSL_PARAM params[])
103b077aed3SPierre Pronchery {
104b077aed3SPierre Pronchery return tdes_init(vctx, key, keylen, iv, ivlen, params, 1);
105b077aed3SPierre Pronchery }
106b077aed3SPierre Pronchery
ossl_tdes_dinit(void * vctx,const unsigned char * key,size_t keylen,const unsigned char * iv,size_t ivlen,const OSSL_PARAM params[])107b077aed3SPierre Pronchery int ossl_tdes_dinit(void *vctx, const unsigned char *key, size_t keylen,
108b077aed3SPierre Pronchery const unsigned char *iv, size_t ivlen,
109b077aed3SPierre Pronchery const OSSL_PARAM params[])
110b077aed3SPierre Pronchery {
111b077aed3SPierre Pronchery return tdes_init(vctx, key, keylen, iv, ivlen, params, 0);
112b077aed3SPierre Pronchery }
113b077aed3SPierre Pronchery
114b077aed3SPierre Pronchery CIPHER_DEFAULT_GETTABLE_CTX_PARAMS_START(ossl_tdes)
115b077aed3SPierre Pronchery OSSL_PARAM_octet_string(OSSL_CIPHER_PARAM_RANDOM_KEY, NULL, 0),
116b077aed3SPierre Pronchery CIPHER_DEFAULT_GETTABLE_CTX_PARAMS_END(ossl_tdes)
117b077aed3SPierre Pronchery
118b077aed3SPierre Pronchery static int tdes_generatekey(PROV_CIPHER_CTX *ctx, void *ptr)
119b077aed3SPierre Pronchery {
120b077aed3SPierre Pronchery
121b077aed3SPierre Pronchery DES_cblock *deskey = ptr;
122b077aed3SPierre Pronchery size_t kl = ctx->keylen;
123b077aed3SPierre Pronchery
124b077aed3SPierre Pronchery if (kl == 0 || RAND_priv_bytes_ex(ctx->libctx, ptr, kl, 0) <= 0)
125b077aed3SPierre Pronchery return 0;
126b077aed3SPierre Pronchery DES_set_odd_parity(deskey);
127b077aed3SPierre Pronchery if (kl >= 16) {
128b077aed3SPierre Pronchery DES_set_odd_parity(deskey + 1);
129b077aed3SPierre Pronchery if (kl >= 24)
130b077aed3SPierre Pronchery DES_set_odd_parity(deskey + 2);
131b077aed3SPierre Pronchery }
132b077aed3SPierre Pronchery return 1;
133b077aed3SPierre Pronchery }
134b077aed3SPierre Pronchery
ossl_tdes_get_ctx_params(void * vctx,OSSL_PARAM params[])135b077aed3SPierre Pronchery int ossl_tdes_get_ctx_params(void *vctx, OSSL_PARAM params[])
136b077aed3SPierre Pronchery {
137b077aed3SPierre Pronchery PROV_CIPHER_CTX *ctx = (PROV_CIPHER_CTX *)vctx;
138b077aed3SPierre Pronchery OSSL_PARAM *p;
139b077aed3SPierre Pronchery
140b077aed3SPierre Pronchery if (!ossl_cipher_generic_get_ctx_params(vctx, params))
141b077aed3SPierre Pronchery return 0;
142b077aed3SPierre Pronchery
143b077aed3SPierre Pronchery p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_RANDOM_KEY);
144b077aed3SPierre Pronchery if (p != NULL && !tdes_generatekey(ctx, p->data)) {
145b077aed3SPierre Pronchery ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GENERATE_KEY);
146b077aed3SPierre Pronchery return 0;
147b077aed3SPierre Pronchery }
148b077aed3SPierre Pronchery return 1;
149b077aed3SPierre Pronchery }
150