projects
/
tinc
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
Have tincctl act as a shell when no command is given.
[tinc]
/
src
/
openssl
/
ecdh.c
diff --git
a/src/openssl/ecdh.c
b/src/openssl/ecdh.c
index
7640674
..
871f9fb
100644
(file)
--- a/
src/openssl/ecdh.c
+++ b/
src/openssl/ecdh.c
@@
-28,30
+28,34
@@
#include "ecdh.h"
#include "logger.h"
#include "ecdh.h"
#include "logger.h"
-// TODO: proper KDF
-static void *kdf(const void *in, size_t inlen, void *out, size_t *outlen) {
- memcpy(out, in, inlen);
- *outlen = inlen;
- return out;
-}
-
bool ecdh_generate_public(ecdh_t *ecdh, void *pubkey) {
*ecdh = EC_KEY_new_by_curve_name(NID_secp521r1);
bool ecdh_generate_public(ecdh_t *ecdh, void *pubkey) {
*ecdh = EC_KEY_new_by_curve_name(NID_secp521r1);
+ if(!*ecdh) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Generating EC key_by_curve_name failed: %s", ERR_error_string(ERR_get_error(), NULL));
+ return false;
+ }
+
if(!EC_KEY_generate_key(*ecdh)) {
if(!EC_KEY_generate_key(*ecdh)) {
- logger(LOG_ERR, "Generating EC key failed: %s", ERR_error_string(ERR_get_error(), NULL));
- abort();
+ EC_KEY_free(*ecdh);
+ *ecdh = NULL;
+ logger(DEBUG_ALWAYS, LOG_ERR, "Generating EC key failed: %s", ERR_error_string(ERR_get_error(), NULL));
+ return false;
}
const EC_POINT *point = EC_KEY_get0_public_key(*ecdh);
if(!point) {
}
const EC_POINT *point = EC_KEY_get0_public_key(*ecdh);
if(!point) {
- logger(LOG_ERR, "Getting public key failed: %s", ERR_error_string(ERR_get_error(), NULL));
- abort();
+ EC_KEY_free(*ecdh);
+ *ecdh = NULL;
+ logger(DEBUG_ALWAYS, LOG_ERR, "Getting public key failed: %s", ERR_error_string(ERR_get_error(), NULL));
+ return false;
}
size_t result = EC_POINT_point2oct(EC_KEY_get0_group(*ecdh), point, POINT_CONVERSION_COMPRESSED, pubkey, ECDH_SIZE, NULL);
if(!result) {
}
size_t result = EC_POINT_point2oct(EC_KEY_get0_group(*ecdh), point, POINT_CONVERSION_COMPRESSED, pubkey, ECDH_SIZE, NULL);
if(!result) {
- logger(LOG_ERR, "Converting EC_POINT to binary failed: %s", ERR_error_string(ERR_get_error(), NULL));
- abort();
+ EC_KEY_free(*ecdh);
+ *ecdh = NULL;
+ logger(DEBUG_ALWAYS, LOG_ERR, "Converting EC_POINT to binary failed: %s", ERR_error_string(ERR_get_error(), NULL));
+ return false;
}
return true;
}
return true;
@@
-59,22
+63,34
@@
bool ecdh_generate_public(ecdh_t *ecdh, void *pubkey) {
bool ecdh_compute_shared(ecdh_t *ecdh, const void *pubkey, void *shared) {
EC_POINT *point = EC_POINT_new(EC_KEY_get0_group(*ecdh));
bool ecdh_compute_shared(ecdh_t *ecdh, const void *pubkey, void *shared) {
EC_POINT *point = EC_POINT_new(EC_KEY_get0_group(*ecdh));
+ if(!point) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "EC_POINT_new() failed: %s", ERR_error_string(ERR_get_error(), NULL));
+ return false;
+ }
int result = EC_POINT_oct2point(EC_KEY_get0_group(*ecdh), point, pubkey, ECDH_SIZE, NULL);
int result = EC_POINT_oct2point(EC_KEY_get0_group(*ecdh), point, pubkey, ECDH_SIZE, NULL);
- if(!point) {
- logger(LOG_ERR, "Converting binary to EC_POINT failed: %s", ERR_error_string(ERR_get_error(), NULL));
- abort();
+ if(!result) {
+ EC_POINT_free(point);
+ logger(DEBUG_ALWAYS, LOG_ERR, "Converting binary to EC_POINT failed: %s", ERR_error_string(ERR_get_error(), NULL));
+ return false;
}
}
- result = ECDH_compute_key(shared, ECDH_SIZE, point, *ecdh,
kdf
);
+ result = ECDH_compute_key(shared, ECDH_SIZE, point, *ecdh,
NULL
);
EC_POINT_free(point);
EC_KEY_free(*ecdh);
*ecdh = NULL;
if(!result) {
EC_POINT_free(point);
EC_KEY_free(*ecdh);
*ecdh = NULL;
if(!result) {
- logger(LOG_ERR, "Computing Elliptic Curve Diffie-Hellman shared key failed: %s", ERR_error_string(ERR_get_error(), NULL));
+ logger(
DEBUG_ALWAYS,
LOG_ERR, "Computing Elliptic Curve Diffie-Hellman shared key failed: %s", ERR_error_string(ERR_get_error(), NULL));
return false;
}
return true;
}
return false;
}
return true;
}
+
+void ecdh_free(ecdh_t *ecdh) {
+ if(*ecdh) {
+ EC_KEY_free(*ecdh);
+ *ecdh = NULL;
+ }
+}