projects
/
tinc
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
Wipe (some) secrets from memory after use
[tinc]
/
src
/
gcrypt
/
digest.c
diff --git
a/src/gcrypt/digest.c
b/src/gcrypt/digest.c
index
066600f
..
cfea1f0
100644
(file)
--- a/
src/gcrypt/digest.c
+++ b/
src/gcrypt/digest.c
@@
-1,6
+1,6
@@
/*
digest.c -- Digest handling
/*
digest.c -- Digest handling
- Copyright (C) 2007 Guus Sliepen <guus@tinc-vpn.org>
+ Copyright (C) 2007
-2022
Guus Sliepen <guus@tinc-vpn.org>
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
@@
-17,27
+17,26
@@
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
*/
51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
*/
-#include "system.h"
+#include "
../
system.h"
#include "digest.h"
#include "digest.h"
-#include "logger.h"
+#include "../digest.h"
+#include "../logger.h"
static struct {
const char *name;
static struct {
const char *name;
-
in
t algo;
-
in
t nid;
+
md_algo_
t algo;
+
nid_
t nid;
} digesttable[] = {
} digesttable[] = {
- {"none",
GCRY_MD_NONE,
0},
- {"sha1",
GCRY_MD_SHA1,
64},
+ {"none",
GCRY_MD_NONE,
0},
+ {"sha1",
GCRY_MD_SHA1,
64},
{"sha256", GCRY_MD_SHA256, 672},
{"sha384", GCRY_MD_SHA384, 673},
{"sha512", GCRY_MD_SHA512, 674},
};
{"sha256", GCRY_MD_SHA256, 672},
{"sha384", GCRY_MD_SHA384, 673},
{"sha512", GCRY_MD_SHA512, 674},
};
-static bool nametodigest(const char *name, int *algo) {
- int i;
-
- for(i = 0; i < sizeof digesttable / sizeof *digesttable; i++) {
+static bool nametodigest(md_algo_t *algo, const char *name) {
+ for(size_t i = 0; i < sizeof(digesttable) / sizeof(*digesttable); i++) {
if(digesttable[i].name && !strcasecmp(name, digesttable[i].name)) {
*algo = digesttable[i].algo;
return true;
if(digesttable[i].name && !strcasecmp(name, digesttable[i].name)) {
*algo = digesttable[i].algo;
return true;
@@
-47,10
+46,8
@@
static bool nametodigest(const char *name, int *algo) {
return false;
}
return false;
}
-static bool nidtodigest(int nid, int *algo) {
- int i;
-
- for(i = 0; i < sizeof digesttable / sizeof *digesttable; i++) {
+static bool nidtodigest(md_algo_t *algo, nid_t nid) {
+ for(size_t i = 0; i < sizeof(digesttable) / sizeof(*digesttable); i++) {
if(nid == digesttable[i].nid) {
*algo = digesttable[i].algo;
return true;
if(nid == digesttable[i].nid) {
*algo = digesttable[i].algo;
return true;
@@
-60,10
+57,8
@@
static bool nidtodigest(int nid, int *algo) {
return false;
}
return false;
}
-static bool digesttonid(int algo, int *nid) {
- int i;
-
- for(i = 0; i < sizeof digesttable / sizeof *digesttable; i++) {
+static bool digesttonid(nid_t *nid, md_algo_t algo) {
+ for(size_t i = 0; i < sizeof(digesttable) / sizeof(*digesttable); i++) {
if(algo == digesttable[i].algo) {
*nid = digesttable[i].nid;
return true;
if(algo == digesttable[i].algo) {
*nid = digesttable[i].nid;
return true;
@@
-73,62
+68,68
@@
static bool digesttonid(int algo, int *nid) {
return false;
}
return false;
}
-static bool digest_open(digest_t *digest,
int algo, in
t maclength) {
- if(!digesttonid(
algo, &digest->nid
)) {
- logger(LOG_DEBUG, "Digest %d has no corresponding nid!", algo);
+static bool digest_open(digest_t *digest,
md_algo_t algo, size_
t maclength) {
+ if(!digesttonid(
&digest->nid, algo
)) {
+ logger(
DEBUG_ALWAYS,
LOG_DEBUG, "Digest %d has no corresponding nid!", algo);
return false;
}
unsigned int len = gcry_md_get_algo_dlen(algo);
return false;
}
unsigned int len = gcry_md_get_algo_dlen(algo);
- if(maclength > len
|| maclength < 0)
+ if(maclength > len
) {
digest->maclength = len;
digest->maclength = len;
- else
+ } else {
digest->maclength = maclength;
digest->maclength = maclength;
-
+ }
+
digest->algo = algo;
digest->hmac = NULL;
return true;
}
digest->algo = algo;
digest->hmac = NULL;
return true;
}
-bool digest_open_by_name(digest_t *digest, const char *name,
in
t maclength) {
-
in
t algo;
+bool digest_open_by_name(digest_t *digest, const char *name,
size_
t maclength) {
+
md_algo_
t algo;
- if(!nametodigest(
name, &algo
)) {
- logger(LOG_DEBUG, "Unknown digest name '%s'!", name);
+ if(!nametodigest(
&algo, name
)) {
+ logger(
DEBUG_ALWAYS,
LOG_DEBUG, "Unknown digest name '%s'!", name);
return false;
}
return digest_open(digest, algo, maclength);
}
return false;
}
return digest_open(digest, algo, maclength);
}
-bool digest_open_by_nid(digest_t *digest,
int nid, in
t maclength) {
-
in
t algo;
+bool digest_open_by_nid(digest_t *digest,
nid_t nid, size_
t maclength) {
+
md_algo_
t algo;
- if(!nidtodigest(
nid, &algo
)) {
- logger(LOG_DEBUG, "Unknown digest ID %d!", nid);
+ if(!nidtodigest(
&algo, nid
)) {
+ logger(
DEBUG_ALWAYS,
LOG_DEBUG, "Unknown digest ID %d!", nid);
return false;
}
return digest_open(digest, algo, maclength);
}
return false;
}
return digest_open(digest, algo, maclength);
}
-bool digest_open_sha1(digest_t *digest, int maclength) {
- return digest_open(digest, GCRY_MD_SHA1, maclength);
-}
-
void digest_close(digest_t *digest) {
void digest_close(digest_t *digest) {
- if(digest->hmac)
+ if(!digest) {
+ return;
+ }
+
+ if(digest->hmac) {
gcry_md_close(digest->hmac);
gcry_md_close(digest->hmac);
- digest->hmac = NULL;
+ }
+
+ memset(digest, 0, sizeof(*digest));
}
bool digest_set_key(digest_t *digest, const void *key, size_t len) {
}
bool digest_set_key(digest_t *digest, const void *key, size_t len) {
- if(!digest->hmac)
+ if(!digest->hmac)
{
gcry_md_open(&digest->hmac, digest->algo, GCRY_MD_FLAG_HMAC);
gcry_md_open(&digest->hmac, digest->algo, GCRY_MD_FLAG_HMAC);
- if(!digest->hmac)
+ }
+
+ if(!digest->hmac) {
return false;
return false;
+ }
return !gcry_md_setkey(digest->hmac, key, len);
}
return !gcry_md_setkey(digest->hmac, key, len);
}
@@
-137,12
+138,15
@@
bool digest_create(digest_t *digest, const void *indata, size_t inlen, void *out
unsigned int len = gcry_md_get_algo_dlen(digest->algo);
if(digest->hmac) {
unsigned int len = gcry_md_get_algo_dlen(digest->algo);
if(digest->hmac) {
-
char
*tmpdata;
+
uint8_t
*tmpdata;
gcry_md_reset(digest->hmac);
gcry_md_write(digest->hmac, indata, inlen);
tmpdata = gcry_md_read(digest->hmac, digest->algo);
gcry_md_reset(digest->hmac);
gcry_md_write(digest->hmac, indata, inlen);
tmpdata = gcry_md_read(digest->hmac, digest->algo);
- if(!tmpdata)
+
+ if(!tmpdata) {
return false;
return false;
+ }
+
memcpy(outdata, tmpdata, digest->maclength);
} else {
char tmpdata[len];
memcpy(outdata, tmpdata, digest->maclength);
} else {
char tmpdata[len];
@@
-154,20
+158,28
@@
bool digest_create(digest_t *digest, const void *indata, size_t inlen, void *out
}
bool digest_verify(digest_t *digest, const void *indata, size_t inlen, const void *cmpdata) {
}
bool digest_verify(digest_t *digest, const void *indata, size_t inlen, const void *cmpdata) {
-
unsigned in
t len = digest->maclength;
-
char
outdata[len];
+
size_
t len = digest->maclength;
+
uint8_t
outdata[len];
return digest_create(digest, indata, inlen, outdata) && !memcmp(cmpdata, outdata, len);
}
return digest_create(digest, indata, inlen, outdata) && !memcmp(cmpdata, outdata, len);
}
-int digest_get_nid(const digest_t *digest) {
+nid_t digest_get_nid(const digest_t *digest) {
+ if(!digest || !digest->nid) {
+ return 0;
+ }
+
return digest->nid;
}
size_t digest_length(const digest_t *digest) {
return digest->nid;
}
size_t digest_length(const digest_t *digest) {
+ if(!digest) {
+ return 0;
+ }
+
return digest->maclength;
}
bool digest_active(const digest_t *digest) {
return digest->maclength;
}
bool digest_active(const digest_t *digest) {
- return digest->algo != GCRY_MD_NONE;
+ return digest
&& digest
->algo != GCRY_MD_NONE;
}
}