2 crypto.c -- Cryptographic miscellaneous functions and initialisation
3 Copyright (C) 2007-2021 Guus Sliepen <guus@tinc-vpn.org>
5 This program is free software; you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation; either version 2 of the License, or
8 (at your option) any later version.
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 GNU General Public License for more details.
15 You should have received a copy of the GNU General Public License along
16 with this program; if not, write to the Free Software Foundation, Inc.,
17 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
20 #include "../system.h"
22 #include <openssl/rand.h>
23 #include <openssl/evp.h>
24 #include <openssl/engine.h>
26 #include "../crypto.h"
30 static int random_fd = -1;
32 static void random_init(void) {
33 random_fd = open("/dev/urandom", O_RDONLY);
36 random_fd = open("/dev/random", O_RDONLY);
40 fprintf(stderr, "Could not open source of random numbers: %s\n", strerror(errno));
45 static void random_exit(void) {
49 void randomize(void *vout, size_t outlen) {
53 ssize_t len = read(random_fd, out, outlen);
56 if(len == -1 && (errno == EAGAIN || errno == EINTR)) {
60 fprintf(stderr, "Could not read random numbers: %s\n", strerror(errno));
74 void random_init(void) {
75 if(!CryptAcquireContext(&prov, NULL, NULL, PROV_RSA_FULL, CRYPT_VERIFYCONTEXT)) {
76 fprintf(stderr, "CryptAcquireContext() failed!\n");
81 void random_exit(void) {
82 CryptReleaseContext(prov, 0);
85 void randomize(void *out, size_t outlen) {
86 if(!CryptGenRandom(prov, outlen, out)) {
87 fprintf(stderr, "CryptGenRandom() failed\n");
94 void crypto_init(void) {
97 ENGINE_load_builtin_engines();
98 ENGINE_register_all_complete();
99 #if OPENSSL_API_COMPAT < 0x10100000L
100 ERR_load_crypto_strings();
101 OpenSSL_add_all_algorithms();
105 fprintf(stderr, "Not enough entropy for the PRNG!\n");
110 void crypto_exit(void) {
111 #if OPENSSL_API_COMPAT < 0x10100000L