xref: /freebsd-src/crypto/openssl/providers/implementations/keymgmt/mac_legacy_kmgmt.c (revision 6f1af0d7d2af54b339b5212434cd6d4fda628d80)
1b077aed3SPierre Pronchery /*
2*6f1af0d7SPierre Pronchery  * Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.
3b077aed3SPierre Pronchery  *
4b077aed3SPierre Pronchery  * Licensed under the Apache License 2.0 (the "License").  You may not use
5b077aed3SPierre Pronchery  * this file except in compliance with the License.  You can obtain a copy
6b077aed3SPierre Pronchery  * in the file LICENSE in the source distribution or at
7b077aed3SPierre Pronchery  * https://www.openssl.org/source/license.html
8b077aed3SPierre Pronchery  */
9b077aed3SPierre Pronchery 
10b077aed3SPierre Pronchery /* We need to use some engine deprecated APIs */
11b077aed3SPierre Pronchery #define OPENSSL_SUPPRESS_DEPRECATED
12b077aed3SPierre Pronchery 
13b077aed3SPierre Pronchery #include <string.h>
14b077aed3SPierre Pronchery #include <openssl/core_dispatch.h>
15b077aed3SPierre Pronchery #include <openssl/core_names.h>
16b077aed3SPierre Pronchery #include <openssl/params.h>
17b077aed3SPierre Pronchery #include <openssl/err.h>
18b077aed3SPierre Pronchery #include <openssl/evp.h>
19b077aed3SPierre Pronchery #include <openssl/proverr.h>
20b077aed3SPierre Pronchery #include <openssl/param_build.h>
21b077aed3SPierre Pronchery #ifndef FIPS_MODULE
22b077aed3SPierre Pronchery # include <openssl/engine.h>
23b077aed3SPierre Pronchery #endif
24b077aed3SPierre Pronchery #include "internal/param_build_set.h"
25b077aed3SPierre Pronchery #include "prov/implementations.h"
26b077aed3SPierre Pronchery #include "prov/providercommon.h"
27b077aed3SPierre Pronchery #include "prov/provider_ctx.h"
28b077aed3SPierre Pronchery #include "prov/macsignature.h"
29b077aed3SPierre Pronchery 
30b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_new_fn mac_new;
31b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_free_fn mac_free;
32b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gen_init_fn mac_gen_init;
33b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gen_fn mac_gen;
34b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gen_cleanup_fn mac_gen_cleanup;
35b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gen_set_params_fn mac_gen_set_params;
36b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gen_settable_params_fn mac_gen_settable_params;
37b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_get_params_fn mac_get_params;
38b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gettable_params_fn mac_gettable_params;
39b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_set_params_fn mac_set_params;
40b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_settable_params_fn mac_settable_params;
41b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_has_fn mac_has;
42b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_match_fn mac_match;
43b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_import_fn mac_import;
44b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_import_types_fn mac_imexport_types;
45b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_export_fn mac_export;
46b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_export_types_fn mac_imexport_types;
47b077aed3SPierre Pronchery 
48b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_new_fn mac_new_cmac;
49b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gettable_params_fn cmac_gettable_params;
50b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_import_types_fn cmac_imexport_types;
51b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_export_types_fn cmac_imexport_types;
52b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gen_init_fn cmac_gen_init;
53b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gen_set_params_fn cmac_gen_set_params;
54b077aed3SPierre Pronchery static OSSL_FUNC_keymgmt_gen_settable_params_fn cmac_gen_settable_params;
55b077aed3SPierre Pronchery 
56b077aed3SPierre Pronchery struct mac_gen_ctx {
57b077aed3SPierre Pronchery     OSSL_LIB_CTX *libctx;
58b077aed3SPierre Pronchery     int selection;
59b077aed3SPierre Pronchery     unsigned char *priv_key;
60b077aed3SPierre Pronchery     size_t priv_key_len;
61b077aed3SPierre Pronchery     PROV_CIPHER cipher;
62b077aed3SPierre Pronchery };
63b077aed3SPierre Pronchery 
ossl_mac_key_new(OSSL_LIB_CTX * libctx,int cmac)64b077aed3SPierre Pronchery MAC_KEY *ossl_mac_key_new(OSSL_LIB_CTX *libctx, int cmac)
65b077aed3SPierre Pronchery {
66b077aed3SPierre Pronchery     MAC_KEY *mackey;
67b077aed3SPierre Pronchery 
68b077aed3SPierre Pronchery     if (!ossl_prov_is_running())
69b077aed3SPierre Pronchery         return NULL;
70b077aed3SPierre Pronchery 
71b077aed3SPierre Pronchery     mackey = OPENSSL_zalloc(sizeof(*mackey));
72b077aed3SPierre Pronchery     if (mackey == NULL)
73b077aed3SPierre Pronchery         return NULL;
74b077aed3SPierre Pronchery 
75b077aed3SPierre Pronchery     mackey->lock = CRYPTO_THREAD_lock_new();
76b077aed3SPierre Pronchery     if (mackey->lock == NULL) {
77b077aed3SPierre Pronchery         OPENSSL_free(mackey);
78b077aed3SPierre Pronchery         return NULL;
79b077aed3SPierre Pronchery     }
80b077aed3SPierre Pronchery     mackey->libctx = libctx;
81b077aed3SPierre Pronchery     mackey->refcnt = 1;
82b077aed3SPierre Pronchery     mackey->cmac = cmac;
83b077aed3SPierre Pronchery 
84b077aed3SPierre Pronchery     return mackey;
85b077aed3SPierre Pronchery }
86b077aed3SPierre Pronchery 
ossl_mac_key_free(MAC_KEY * mackey)87b077aed3SPierre Pronchery void ossl_mac_key_free(MAC_KEY *mackey)
88b077aed3SPierre Pronchery {
89b077aed3SPierre Pronchery     int ref = 0;
90b077aed3SPierre Pronchery 
91b077aed3SPierre Pronchery     if (mackey == NULL)
92b077aed3SPierre Pronchery         return;
93b077aed3SPierre Pronchery 
94b077aed3SPierre Pronchery     CRYPTO_DOWN_REF(&mackey->refcnt, &ref, mackey->lock);
95b077aed3SPierre Pronchery     if (ref > 0)
96b077aed3SPierre Pronchery         return;
97b077aed3SPierre Pronchery 
98b077aed3SPierre Pronchery     OPENSSL_secure_clear_free(mackey->priv_key, mackey->priv_key_len);
99b077aed3SPierre Pronchery     OPENSSL_free(mackey->properties);
100b077aed3SPierre Pronchery     ossl_prov_cipher_reset(&mackey->cipher);
101b077aed3SPierre Pronchery     CRYPTO_THREAD_lock_free(mackey->lock);
102b077aed3SPierre Pronchery     OPENSSL_free(mackey);
103b077aed3SPierre Pronchery }
104b077aed3SPierre Pronchery 
ossl_mac_key_up_ref(MAC_KEY * mackey)105b077aed3SPierre Pronchery int ossl_mac_key_up_ref(MAC_KEY *mackey)
106b077aed3SPierre Pronchery {
107b077aed3SPierre Pronchery     int ref = 0;
108b077aed3SPierre Pronchery 
109b077aed3SPierre Pronchery     /* This is effectively doing a new operation on the MAC_KEY and should be
110b077aed3SPierre Pronchery      * adequately guarded again modules' error states.  However, both current
111b077aed3SPierre Pronchery      * calls here are guarded propery in signature/mac_legacy.c.  Thus, it
112b077aed3SPierre Pronchery      * could be removed here.  The concern is that something in the future
113b077aed3SPierre Pronchery      * might call this function without adequate guards.  It's a cheap call,
114b077aed3SPierre Pronchery      * it seems best to leave it even though it is currently redundant.
115b077aed3SPierre Pronchery      */
116b077aed3SPierre Pronchery     if (!ossl_prov_is_running())
117b077aed3SPierre Pronchery         return 0;
118b077aed3SPierre Pronchery 
119b077aed3SPierre Pronchery     CRYPTO_UP_REF(&mackey->refcnt, &ref, mackey->lock);
120b077aed3SPierre Pronchery     return 1;
121b077aed3SPierre Pronchery }
122b077aed3SPierre Pronchery 
mac_new(void * provctx)123b077aed3SPierre Pronchery static void *mac_new(void *provctx)
124b077aed3SPierre Pronchery {
125b077aed3SPierre Pronchery     return ossl_mac_key_new(PROV_LIBCTX_OF(provctx), 0);
126b077aed3SPierre Pronchery }
127b077aed3SPierre Pronchery 
mac_new_cmac(void * provctx)128b077aed3SPierre Pronchery static void *mac_new_cmac(void *provctx)
129b077aed3SPierre Pronchery {
130b077aed3SPierre Pronchery     return ossl_mac_key_new(PROV_LIBCTX_OF(provctx), 1);
131b077aed3SPierre Pronchery }
132b077aed3SPierre Pronchery 
mac_free(void * mackey)133b077aed3SPierre Pronchery static void mac_free(void *mackey)
134b077aed3SPierre Pronchery {
135b077aed3SPierre Pronchery     ossl_mac_key_free(mackey);
136b077aed3SPierre Pronchery }
137b077aed3SPierre Pronchery 
mac_has(const void * keydata,int selection)138b077aed3SPierre Pronchery static int mac_has(const void *keydata, int selection)
139b077aed3SPierre Pronchery {
140b077aed3SPierre Pronchery     const MAC_KEY *key = keydata;
141b077aed3SPierre Pronchery     int ok = 0;
142b077aed3SPierre Pronchery 
143b077aed3SPierre Pronchery     if (ossl_prov_is_running() && key != NULL) {
144b077aed3SPierre Pronchery         /*
145b077aed3SPierre Pronchery          * MAC keys always have all the parameters they need (i.e. none).
146b077aed3SPierre Pronchery          * Therefore we always return with 1, if asked about parameters.
147b077aed3SPierre Pronchery          * Similarly for public keys.
148b077aed3SPierre Pronchery          */
149b077aed3SPierre Pronchery         ok = 1;
150b077aed3SPierre Pronchery 
151b077aed3SPierre Pronchery         if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0)
152b077aed3SPierre Pronchery             ok = key->priv_key != NULL;
153b077aed3SPierre Pronchery     }
154b077aed3SPierre Pronchery     return ok;
155b077aed3SPierre Pronchery }
156b077aed3SPierre Pronchery 
mac_match(const void * keydata1,const void * keydata2,int selection)157b077aed3SPierre Pronchery static int mac_match(const void *keydata1, const void *keydata2, int selection)
158b077aed3SPierre Pronchery {
159b077aed3SPierre Pronchery     const MAC_KEY *key1 = keydata1;
160b077aed3SPierre Pronchery     const MAC_KEY *key2 = keydata2;
161b077aed3SPierre Pronchery     int ok = 1;
162b077aed3SPierre Pronchery 
163b077aed3SPierre Pronchery     if (!ossl_prov_is_running())
164b077aed3SPierre Pronchery         return 0;
165b077aed3SPierre Pronchery 
166b077aed3SPierre Pronchery     if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0) {
167b077aed3SPierre Pronchery         if ((key1->priv_key == NULL && key2->priv_key != NULL)
168b077aed3SPierre Pronchery                 || (key1->priv_key != NULL && key2->priv_key == NULL)
169b077aed3SPierre Pronchery                 || key1->priv_key_len != key2->priv_key_len
170b077aed3SPierre Pronchery                 || (key1->cipher.cipher == NULL && key2->cipher.cipher != NULL)
171b077aed3SPierre Pronchery                 || (key1->cipher.cipher != NULL && key2->cipher.cipher == NULL))
172b077aed3SPierre Pronchery             ok = 0;
173b077aed3SPierre Pronchery         else
174b077aed3SPierre Pronchery             ok = ok && (key1->priv_key == NULL /* implies key2->privkey == NULL */
175b077aed3SPierre Pronchery                         || CRYPTO_memcmp(key1->priv_key, key2->priv_key,
176b077aed3SPierre Pronchery                                          key1->priv_key_len) == 0);
177b077aed3SPierre Pronchery         if (key1->cipher.cipher != NULL)
178b077aed3SPierre Pronchery             ok = ok && EVP_CIPHER_is_a(key1->cipher.cipher,
179b077aed3SPierre Pronchery                                        EVP_CIPHER_get0_name(key2->cipher.cipher));
180b077aed3SPierre Pronchery     }
181b077aed3SPierre Pronchery     return ok;
182b077aed3SPierre Pronchery }
183b077aed3SPierre Pronchery 
mac_key_fromdata(MAC_KEY * key,const OSSL_PARAM params[])184b077aed3SPierre Pronchery static int mac_key_fromdata(MAC_KEY *key, const OSSL_PARAM params[])
185b077aed3SPierre Pronchery {
186b077aed3SPierre Pronchery     const OSSL_PARAM *p;
187b077aed3SPierre Pronchery 
188b077aed3SPierre Pronchery     p = OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_PRIV_KEY);
189b077aed3SPierre Pronchery     if (p != NULL) {
190b077aed3SPierre Pronchery         if (p->data_type != OSSL_PARAM_OCTET_STRING) {
191b077aed3SPierre Pronchery             ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_INVALID_ARGUMENT);
192b077aed3SPierre Pronchery             return 0;
193b077aed3SPierre Pronchery         }
194b077aed3SPierre Pronchery         OPENSSL_secure_clear_free(key->priv_key, key->priv_key_len);
195b077aed3SPierre Pronchery         /* allocate at least one byte to distinguish empty key from no key set */
196b077aed3SPierre Pronchery         key->priv_key = OPENSSL_secure_malloc(p->data_size > 0 ? p->data_size : 1);
197b077aed3SPierre Pronchery         if (key->priv_key == NULL) {
198b077aed3SPierre Pronchery             ERR_raise(ERR_LIB_PROV, ERR_R_MALLOC_FAILURE);
199b077aed3SPierre Pronchery             return 0;
200b077aed3SPierre Pronchery         }
201b077aed3SPierre Pronchery         memcpy(key->priv_key, p->data, p->data_size);
202b077aed3SPierre Pronchery         key->priv_key_len = p->data_size;
203b077aed3SPierre Pronchery     }
204b077aed3SPierre Pronchery 
205b077aed3SPierre Pronchery     p = OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_PROPERTIES);
206b077aed3SPierre Pronchery     if (p != NULL) {
207b077aed3SPierre Pronchery         if (p->data_type != OSSL_PARAM_UTF8_STRING) {
208b077aed3SPierre Pronchery             ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_INVALID_ARGUMENT);
209b077aed3SPierre Pronchery             return 0;
210b077aed3SPierre Pronchery         }
211b077aed3SPierre Pronchery         OPENSSL_free(key->properties);
212b077aed3SPierre Pronchery         key->properties = OPENSSL_strdup(p->data);
213b077aed3SPierre Pronchery         if (key->properties == NULL) {
214b077aed3SPierre Pronchery             ERR_raise(ERR_LIB_PROV, ERR_R_MALLOC_FAILURE);
215b077aed3SPierre Pronchery             return 0;
216b077aed3SPierre Pronchery         }
217b077aed3SPierre Pronchery     }
218b077aed3SPierre Pronchery 
219b077aed3SPierre Pronchery     if (key->cmac && !ossl_prov_cipher_load_from_params(&key->cipher, params,
220b077aed3SPierre Pronchery                                                         key->libctx)) {
221b077aed3SPierre Pronchery         ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_INVALID_ARGUMENT);
222b077aed3SPierre Pronchery         return 0;
223b077aed3SPierre Pronchery     }
224b077aed3SPierre Pronchery 
225b077aed3SPierre Pronchery     if (key->priv_key != NULL)
226b077aed3SPierre Pronchery         return 1;
227b077aed3SPierre Pronchery 
228b077aed3SPierre Pronchery     return 0;
229b077aed3SPierre Pronchery }
230b077aed3SPierre Pronchery 
mac_import(void * keydata,int selection,const OSSL_PARAM params[])231b077aed3SPierre Pronchery static int mac_import(void *keydata, int selection, const OSSL_PARAM params[])
232b077aed3SPierre Pronchery {
233b077aed3SPierre Pronchery     MAC_KEY *key = keydata;
234b077aed3SPierre Pronchery 
235b077aed3SPierre Pronchery     if (!ossl_prov_is_running() || key == NULL)
236b077aed3SPierre Pronchery         return 0;
237b077aed3SPierre Pronchery 
238b077aed3SPierre Pronchery     if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) == 0)
239b077aed3SPierre Pronchery         return 0;
240b077aed3SPierre Pronchery 
241b077aed3SPierre Pronchery     return mac_key_fromdata(key, params);
242b077aed3SPierre Pronchery }
243b077aed3SPierre Pronchery 
key_to_params(MAC_KEY * key,OSSL_PARAM_BLD * tmpl,OSSL_PARAM params[])244b077aed3SPierre Pronchery static int key_to_params(MAC_KEY *key, OSSL_PARAM_BLD *tmpl,
245b077aed3SPierre Pronchery                          OSSL_PARAM params[])
246b077aed3SPierre Pronchery {
247b077aed3SPierre Pronchery     if (key == NULL)
248b077aed3SPierre Pronchery         return 0;
249b077aed3SPierre Pronchery 
250b077aed3SPierre Pronchery     if (key->priv_key != NULL
251b077aed3SPierre Pronchery         && !ossl_param_build_set_octet_string(tmpl, params,
252b077aed3SPierre Pronchery                                               OSSL_PKEY_PARAM_PRIV_KEY,
253b077aed3SPierre Pronchery                                               key->priv_key, key->priv_key_len))
254b077aed3SPierre Pronchery         return 0;
255b077aed3SPierre Pronchery 
256b077aed3SPierre Pronchery     if (key->cipher.cipher != NULL
257b077aed3SPierre Pronchery         && !ossl_param_build_set_utf8_string(tmpl, params,
258b077aed3SPierre Pronchery                                              OSSL_PKEY_PARAM_CIPHER,
259b077aed3SPierre Pronchery                                              EVP_CIPHER_get0_name(key->cipher.cipher)))
260b077aed3SPierre Pronchery         return 0;
261b077aed3SPierre Pronchery 
262b077aed3SPierre Pronchery #if !defined(OPENSSL_NO_ENGINE) && !defined(FIPS_MODULE)
263b077aed3SPierre Pronchery     if (key->cipher.engine != NULL
264b077aed3SPierre Pronchery         && !ossl_param_build_set_utf8_string(tmpl, params,
265b077aed3SPierre Pronchery                                              OSSL_PKEY_PARAM_ENGINE,
266b077aed3SPierre Pronchery                                              ENGINE_get_id(key->cipher.engine)))
267b077aed3SPierre Pronchery         return 0;
268b077aed3SPierre Pronchery #endif
269b077aed3SPierre Pronchery 
270b077aed3SPierre Pronchery     return 1;
271b077aed3SPierre Pronchery }
272b077aed3SPierre Pronchery 
mac_export(void * keydata,int selection,OSSL_CALLBACK * param_cb,void * cbarg)273b077aed3SPierre Pronchery static int mac_export(void *keydata, int selection, OSSL_CALLBACK *param_cb,
274b077aed3SPierre Pronchery                       void *cbarg)
275b077aed3SPierre Pronchery {
276b077aed3SPierre Pronchery     MAC_KEY *key = keydata;
277b077aed3SPierre Pronchery     OSSL_PARAM_BLD *tmpl;
278b077aed3SPierre Pronchery     OSSL_PARAM *params = NULL;
279b077aed3SPierre Pronchery     int ret = 0;
280b077aed3SPierre Pronchery 
281b077aed3SPierre Pronchery     if (!ossl_prov_is_running() || key == NULL)
282b077aed3SPierre Pronchery         return 0;
283b077aed3SPierre Pronchery 
284*6f1af0d7SPierre Pronchery     if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) == 0)
285*6f1af0d7SPierre Pronchery         return 0;
286*6f1af0d7SPierre Pronchery 
287b077aed3SPierre Pronchery     tmpl = OSSL_PARAM_BLD_new();
288b077aed3SPierre Pronchery     if (tmpl == NULL)
289b077aed3SPierre Pronchery         return 0;
290b077aed3SPierre Pronchery 
291b077aed3SPierre Pronchery     if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0
292b077aed3SPierre Pronchery          && !key_to_params(key, tmpl, NULL))
293b077aed3SPierre Pronchery         goto err;
294b077aed3SPierre Pronchery 
295b077aed3SPierre Pronchery     params = OSSL_PARAM_BLD_to_param(tmpl);
296b077aed3SPierre Pronchery     if (params == NULL)
297b077aed3SPierre Pronchery         goto err;
298b077aed3SPierre Pronchery 
299b077aed3SPierre Pronchery     ret = param_cb(params, cbarg);
300b077aed3SPierre Pronchery     OSSL_PARAM_free(params);
301b077aed3SPierre Pronchery err:
302b077aed3SPierre Pronchery     OSSL_PARAM_BLD_free(tmpl);
303b077aed3SPierre Pronchery     return ret;
304b077aed3SPierre Pronchery }
305b077aed3SPierre Pronchery 
306b077aed3SPierre Pronchery static const OSSL_PARAM mac_key_types[] = {
307b077aed3SPierre Pronchery     OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0),
308b077aed3SPierre Pronchery     OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_PROPERTIES, NULL, 0),
309b077aed3SPierre Pronchery     OSSL_PARAM_END
310b077aed3SPierre Pronchery };
mac_imexport_types(int selection)311b077aed3SPierre Pronchery static const OSSL_PARAM *mac_imexport_types(int selection)
312b077aed3SPierre Pronchery {
313b077aed3SPierre Pronchery     if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0)
314b077aed3SPierre Pronchery         return mac_key_types;
315b077aed3SPierre Pronchery     return NULL;
316b077aed3SPierre Pronchery }
317b077aed3SPierre Pronchery 
318b077aed3SPierre Pronchery static const OSSL_PARAM cmac_key_types[] = {
319b077aed3SPierre Pronchery     OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0),
320b077aed3SPierre Pronchery     OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_CIPHER, NULL, 0),
321b077aed3SPierre Pronchery     OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_ENGINE, NULL, 0),
322b077aed3SPierre Pronchery     OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_PROPERTIES, NULL, 0),
323b077aed3SPierre Pronchery     OSSL_PARAM_END
324b077aed3SPierre Pronchery };
cmac_imexport_types(int selection)325b077aed3SPierre Pronchery static const OSSL_PARAM *cmac_imexport_types(int selection)
326b077aed3SPierre Pronchery {
327b077aed3SPierre Pronchery     if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0)
328b077aed3SPierre Pronchery         return cmac_key_types;
329b077aed3SPierre Pronchery     return NULL;
330b077aed3SPierre Pronchery }
331b077aed3SPierre Pronchery 
mac_get_params(void * key,OSSL_PARAM params[])332b077aed3SPierre Pronchery static int mac_get_params(void *key, OSSL_PARAM params[])
333b077aed3SPierre Pronchery {
334b077aed3SPierre Pronchery     return key_to_params(key, NULL, params);
335b077aed3SPierre Pronchery }
336b077aed3SPierre Pronchery 
mac_gettable_params(void * provctx)337b077aed3SPierre Pronchery static const OSSL_PARAM *mac_gettable_params(void *provctx)
338b077aed3SPierre Pronchery {
339b077aed3SPierre Pronchery     static const OSSL_PARAM gettable_params[] = {
340b077aed3SPierre Pronchery         OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0),
341b077aed3SPierre Pronchery         OSSL_PARAM_END
342b077aed3SPierre Pronchery     };
343b077aed3SPierre Pronchery     return gettable_params;
344b077aed3SPierre Pronchery }
345b077aed3SPierre Pronchery 
cmac_gettable_params(void * provctx)346b077aed3SPierre Pronchery static const OSSL_PARAM *cmac_gettable_params(void *provctx)
347b077aed3SPierre Pronchery {
348b077aed3SPierre Pronchery     static const OSSL_PARAM gettable_params[] = {
349b077aed3SPierre Pronchery         OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0),
350b077aed3SPierre Pronchery         OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_CIPHER, NULL, 0),
351b077aed3SPierre Pronchery         OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_ENGINE, NULL, 0),
352b077aed3SPierre Pronchery         OSSL_PARAM_END
353b077aed3SPierre Pronchery     };
354b077aed3SPierre Pronchery     return gettable_params;
355b077aed3SPierre Pronchery }
356b077aed3SPierre Pronchery 
mac_set_params(void * keydata,const OSSL_PARAM params[])357b077aed3SPierre Pronchery static int mac_set_params(void *keydata, const OSSL_PARAM params[])
358b077aed3SPierre Pronchery {
359b077aed3SPierre Pronchery     MAC_KEY *key = keydata;
360b077aed3SPierre Pronchery     const OSSL_PARAM *p;
361b077aed3SPierre Pronchery 
362b077aed3SPierre Pronchery     if (key == NULL)
363b077aed3SPierre Pronchery         return 0;
364b077aed3SPierre Pronchery 
365b077aed3SPierre Pronchery     p = OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_PRIV_KEY);
366b077aed3SPierre Pronchery     if (p != NULL)
367b077aed3SPierre Pronchery         return mac_key_fromdata(key, params);
368b077aed3SPierre Pronchery 
369b077aed3SPierre Pronchery     return 1;
370b077aed3SPierre Pronchery }
371b077aed3SPierre Pronchery 
mac_settable_params(void * provctx)372b077aed3SPierre Pronchery static const OSSL_PARAM *mac_settable_params(void *provctx)
373b077aed3SPierre Pronchery {
374b077aed3SPierre Pronchery     static const OSSL_PARAM settable_params[] = {
375b077aed3SPierre Pronchery         OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0),
376b077aed3SPierre Pronchery         OSSL_PARAM_END
377b077aed3SPierre Pronchery     };
378b077aed3SPierre Pronchery     return settable_params;
379b077aed3SPierre Pronchery }
380b077aed3SPierre Pronchery 
mac_gen_init_common(void * provctx,int selection)381b077aed3SPierre Pronchery static void *mac_gen_init_common(void *provctx, int selection)
382b077aed3SPierre Pronchery {
383b077aed3SPierre Pronchery     OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(provctx);
384b077aed3SPierre Pronchery     struct mac_gen_ctx *gctx = NULL;
385b077aed3SPierre Pronchery 
386b077aed3SPierre Pronchery     if (!ossl_prov_is_running())
387b077aed3SPierre Pronchery         return NULL;
388b077aed3SPierre Pronchery 
389b077aed3SPierre Pronchery     if ((gctx = OPENSSL_zalloc(sizeof(*gctx))) != NULL) {
390b077aed3SPierre Pronchery         gctx->libctx = libctx;
391b077aed3SPierre Pronchery         gctx->selection = selection;
392b077aed3SPierre Pronchery     }
393b077aed3SPierre Pronchery     return gctx;
394b077aed3SPierre Pronchery }
395b077aed3SPierre Pronchery 
mac_gen_init(void * provctx,int selection,const OSSL_PARAM params[])396b077aed3SPierre Pronchery static void *mac_gen_init(void *provctx, int selection,
397b077aed3SPierre Pronchery                           const OSSL_PARAM params[])
398b077aed3SPierre Pronchery {
399b077aed3SPierre Pronchery     struct mac_gen_ctx *gctx = mac_gen_init_common(provctx, selection);
400b077aed3SPierre Pronchery 
401b077aed3SPierre Pronchery     if (gctx != NULL && !mac_gen_set_params(gctx, params)) {
402b077aed3SPierre Pronchery         OPENSSL_free(gctx);
403b077aed3SPierre Pronchery         gctx = NULL;
404b077aed3SPierre Pronchery     }
405b077aed3SPierre Pronchery     return gctx;
406b077aed3SPierre Pronchery }
407b077aed3SPierre Pronchery 
cmac_gen_init(void * provctx,int selection,const OSSL_PARAM params[])408b077aed3SPierre Pronchery static void *cmac_gen_init(void *provctx, int selection,
409b077aed3SPierre Pronchery                            const OSSL_PARAM params[])
410b077aed3SPierre Pronchery {
411b077aed3SPierre Pronchery     struct mac_gen_ctx *gctx = mac_gen_init_common(provctx, selection);
412b077aed3SPierre Pronchery 
413b077aed3SPierre Pronchery     if (gctx != NULL && !cmac_gen_set_params(gctx, params)) {
414b077aed3SPierre Pronchery         OPENSSL_free(gctx);
415b077aed3SPierre Pronchery         gctx = NULL;
416b077aed3SPierre Pronchery     }
417b077aed3SPierre Pronchery     return gctx;
418b077aed3SPierre Pronchery }
419b077aed3SPierre Pronchery 
mac_gen_set_params(void * genctx,const OSSL_PARAM params[])420b077aed3SPierre Pronchery static int mac_gen_set_params(void *genctx, const OSSL_PARAM params[])
421b077aed3SPierre Pronchery {
422b077aed3SPierre Pronchery     struct mac_gen_ctx *gctx = genctx;
423b077aed3SPierre Pronchery     const OSSL_PARAM *p;
424b077aed3SPierre Pronchery 
425b077aed3SPierre Pronchery     if (gctx == NULL)
426b077aed3SPierre Pronchery         return 0;
427b077aed3SPierre Pronchery 
428b077aed3SPierre Pronchery     p = OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_PRIV_KEY);
429b077aed3SPierre Pronchery     if (p != NULL) {
430b077aed3SPierre Pronchery         if (p->data_type != OSSL_PARAM_OCTET_STRING) {
431b077aed3SPierre Pronchery             ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_INVALID_ARGUMENT);
432b077aed3SPierre Pronchery             return 0;
433b077aed3SPierre Pronchery         }
434b077aed3SPierre Pronchery         gctx->priv_key = OPENSSL_secure_malloc(p->data_size);
435b077aed3SPierre Pronchery         if (gctx->priv_key == NULL) {
436b077aed3SPierre Pronchery             ERR_raise(ERR_LIB_PROV, ERR_R_MALLOC_FAILURE);
437b077aed3SPierre Pronchery             return 0;
438b077aed3SPierre Pronchery         }
439b077aed3SPierre Pronchery         memcpy(gctx->priv_key, p->data, p->data_size);
440b077aed3SPierre Pronchery         gctx->priv_key_len = p->data_size;
441b077aed3SPierre Pronchery     }
442b077aed3SPierre Pronchery 
443b077aed3SPierre Pronchery     return 1;
444b077aed3SPierre Pronchery }
445b077aed3SPierre Pronchery 
cmac_gen_set_params(void * genctx,const OSSL_PARAM params[])446b077aed3SPierre Pronchery static int cmac_gen_set_params(void *genctx, const OSSL_PARAM params[])
447b077aed3SPierre Pronchery {
448b077aed3SPierre Pronchery     struct mac_gen_ctx *gctx = genctx;
449b077aed3SPierre Pronchery 
450b077aed3SPierre Pronchery     if (!mac_gen_set_params(genctx, params))
451b077aed3SPierre Pronchery         return 0;
452b077aed3SPierre Pronchery 
453b077aed3SPierre Pronchery     if (!ossl_prov_cipher_load_from_params(&gctx->cipher, params,
454b077aed3SPierre Pronchery                                            gctx->libctx)) {
455b077aed3SPierre Pronchery         ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_INVALID_ARGUMENT);
456b077aed3SPierre Pronchery         return 0;
457b077aed3SPierre Pronchery     }
458b077aed3SPierre Pronchery 
459b077aed3SPierre Pronchery     return 1;
460b077aed3SPierre Pronchery }
461b077aed3SPierre Pronchery 
mac_gen_settable_params(ossl_unused void * genctx,ossl_unused void * provctx)462b077aed3SPierre Pronchery static const OSSL_PARAM *mac_gen_settable_params(ossl_unused void *genctx,
463b077aed3SPierre Pronchery                                                  ossl_unused void *provctx)
464b077aed3SPierre Pronchery {
465b077aed3SPierre Pronchery     static OSSL_PARAM settable[] = {
466b077aed3SPierre Pronchery         OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0),
467b077aed3SPierre Pronchery         OSSL_PARAM_END
468b077aed3SPierre Pronchery     };
469b077aed3SPierre Pronchery     return settable;
470b077aed3SPierre Pronchery }
471b077aed3SPierre Pronchery 
cmac_gen_settable_params(ossl_unused void * genctx,ossl_unused void * provctx)472b077aed3SPierre Pronchery static const OSSL_PARAM *cmac_gen_settable_params(ossl_unused void *genctx,
473b077aed3SPierre Pronchery                                                   ossl_unused void *provctx)
474b077aed3SPierre Pronchery {
475b077aed3SPierre Pronchery     static OSSL_PARAM settable[] = {
476b077aed3SPierre Pronchery         OSSL_PARAM_octet_string(OSSL_PKEY_PARAM_PRIV_KEY, NULL, 0),
477b077aed3SPierre Pronchery         OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_CIPHER, NULL, 0),
478b077aed3SPierre Pronchery         OSSL_PARAM_END
479b077aed3SPierre Pronchery     };
480b077aed3SPierre Pronchery     return settable;
481b077aed3SPierre Pronchery }
482b077aed3SPierre Pronchery 
mac_gen(void * genctx,OSSL_CALLBACK * cb,void * cbarg)483b077aed3SPierre Pronchery static void *mac_gen(void *genctx, OSSL_CALLBACK *cb, void *cbarg)
484b077aed3SPierre Pronchery {
485b077aed3SPierre Pronchery     struct mac_gen_ctx *gctx = genctx;
486b077aed3SPierre Pronchery     MAC_KEY *key;
487b077aed3SPierre Pronchery 
488b077aed3SPierre Pronchery     if (!ossl_prov_is_running() || gctx == NULL)
489b077aed3SPierre Pronchery         return NULL;
490b077aed3SPierre Pronchery 
491b077aed3SPierre Pronchery     if ((key = ossl_mac_key_new(gctx->libctx, 0)) == NULL) {
492b077aed3SPierre Pronchery         ERR_raise(ERR_LIB_PROV, ERR_R_MALLOC_FAILURE);
493b077aed3SPierre Pronchery         return NULL;
494b077aed3SPierre Pronchery     }
495b077aed3SPierre Pronchery 
496b077aed3SPierre Pronchery     /* If we're doing parameter generation then we just return a blank key */
497b077aed3SPierre Pronchery     if ((gctx->selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0)
498b077aed3SPierre Pronchery         return key;
499b077aed3SPierre Pronchery 
500b077aed3SPierre Pronchery     if (gctx->priv_key == NULL) {
501b077aed3SPierre Pronchery         ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY);
502b077aed3SPierre Pronchery         ossl_mac_key_free(key);
503b077aed3SPierre Pronchery         return NULL;
504b077aed3SPierre Pronchery     }
505b077aed3SPierre Pronchery 
506b077aed3SPierre Pronchery     /*
507b077aed3SPierre Pronchery      * This is horrible but required for backwards compatibility. We don't
508b077aed3SPierre Pronchery      * actually do real key generation at all. We simply copy the key that was
509b077aed3SPierre Pronchery      * previously set in the gctx. Hopefully at some point in the future all
510b077aed3SPierre Pronchery      * of this can be removed and we will only support the EVP_KDF APIs.
511b077aed3SPierre Pronchery      */
512b077aed3SPierre Pronchery     if (!ossl_prov_cipher_copy(&key->cipher, &gctx->cipher)) {
513b077aed3SPierre Pronchery         ossl_mac_key_free(key);
514b077aed3SPierre Pronchery         ERR_raise(ERR_LIB_PROV, ERR_R_INTERNAL_ERROR);
515b077aed3SPierre Pronchery         return NULL;
516b077aed3SPierre Pronchery     }
517b077aed3SPierre Pronchery     ossl_prov_cipher_reset(&gctx->cipher);
518b077aed3SPierre Pronchery     key->priv_key = gctx->priv_key;
519b077aed3SPierre Pronchery     key->priv_key_len = gctx->priv_key_len;
520b077aed3SPierre Pronchery     gctx->priv_key_len = 0;
521b077aed3SPierre Pronchery     gctx->priv_key = NULL;
522b077aed3SPierre Pronchery 
523b077aed3SPierre Pronchery     return key;
524b077aed3SPierre Pronchery }
525b077aed3SPierre Pronchery 
mac_gen_cleanup(void * genctx)526b077aed3SPierre Pronchery static void mac_gen_cleanup(void *genctx)
527b077aed3SPierre Pronchery {
528b077aed3SPierre Pronchery     struct mac_gen_ctx *gctx = genctx;
529b077aed3SPierre Pronchery 
530b077aed3SPierre Pronchery     OPENSSL_secure_clear_free(gctx->priv_key, gctx->priv_key_len);
531b077aed3SPierre Pronchery     ossl_prov_cipher_reset(&gctx->cipher);
532b077aed3SPierre Pronchery     OPENSSL_free(gctx);
533b077aed3SPierre Pronchery }
534b077aed3SPierre Pronchery 
535b077aed3SPierre Pronchery const OSSL_DISPATCH ossl_mac_legacy_keymgmt_functions[] = {
536b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))mac_new },
537b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_FREE, (void (*)(void))mac_free },
538b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GET_PARAMS, (void (*) (void))mac_get_params },
539b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS, (void (*) (void))mac_gettable_params },
540b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_SET_PARAMS, (void (*) (void))mac_set_params },
541b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS, (void (*) (void))mac_settable_params },
542b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_HAS, (void (*)(void))mac_has },
543b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_MATCH, (void (*)(void))mac_match },
544b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_IMPORT, (void (*)(void))mac_import },
545b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_IMPORT_TYPES, (void (*)(void))mac_imexport_types },
546b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_EXPORT, (void (*)(void))mac_export },
547b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (void (*)(void))mac_imexport_types },
548b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))mac_gen_init },
549b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))mac_gen_set_params },
550b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS,
551b077aed3SPierre Pronchery         (void (*)(void))mac_gen_settable_params },
552b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN, (void (*)(void))mac_gen },
553b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN_CLEANUP, (void (*)(void))mac_gen_cleanup },
554b077aed3SPierre Pronchery     { 0, NULL }
555b077aed3SPierre Pronchery };
556b077aed3SPierre Pronchery 
557b077aed3SPierre Pronchery const OSSL_DISPATCH ossl_cmac_legacy_keymgmt_functions[] = {
558b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))mac_new_cmac },
559b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_FREE, (void (*)(void))mac_free },
560b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GET_PARAMS, (void (*) (void))mac_get_params },
561b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS, (void (*) (void))cmac_gettable_params },
562b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_SET_PARAMS, (void (*) (void))mac_set_params },
563b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS, (void (*) (void))mac_settable_params },
564b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_HAS, (void (*)(void))mac_has },
565b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_MATCH, (void (*)(void))mac_match },
566b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_IMPORT, (void (*)(void))mac_import },
567b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_IMPORT_TYPES, (void (*)(void))cmac_imexport_types },
568b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_EXPORT, (void (*)(void))mac_export },
569b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (void (*)(void))cmac_imexport_types },
570b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))cmac_gen_init },
571b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))cmac_gen_set_params },
572b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS,
573b077aed3SPierre Pronchery         (void (*)(void))cmac_gen_settable_params },
574b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN, (void (*)(void))mac_gen },
575b077aed3SPierre Pronchery     { OSSL_FUNC_KEYMGMT_GEN_CLEANUP, (void (*)(void))mac_gen_cleanup },
576b077aed3SPierre Pronchery     { 0, NULL }
577b077aed3SPierre Pronchery };
578b077aed3SPierre Pronchery 
579