/*
digest.c -- Digest handling
- Copyright (C) 2007 Guus Sliepen <guus@tinc-vpn.org>
+ Copyright (C) 2007-2012 Guus Sliepen <guus@tinc-vpn.org>
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
static bool nametodigest(const char *name, int *algo) {
int i;
- for(i = 0; i < sizeof digesttable / sizeof *digesttable; i++) {
+ for(i = 0; i < sizeof(digesttable) / sizeof(*digesttable); i++) {
if(digesttable[i].name && !strcasecmp(name, digesttable[i].name)) {
*algo = digesttable[i].algo;
return true;
static bool nidtodigest(int nid, int *algo) {
int i;
- for(i = 0; i < sizeof digesttable / sizeof *digesttable; i++) {
+ for(i = 0; i < sizeof(digesttable) / sizeof(*digesttable); i++) {
if(nid == digesttable[i].nid) {
*algo = digesttable[i].algo;
return true;
static bool digesttonid(int algo, int *nid) {
int i;
- for(i = 0; i < sizeof digesttable / sizeof *digesttable; i++) {
+ for(i = 0; i < sizeof(digesttable) / sizeof(*digesttable); i++) {
if(algo == digesttable[i].algo) {
*nid = digesttable[i].nid;
return true;
static bool digest_open(digest_t *digest, int algo, int maclength) {
if(!digesttonid(algo, &digest->nid)) {
- logger(LOG_DEBUG, "Digest %d has no corresponding nid!", algo);
+ logger(DEBUG_ALWAYS, LOG_DEBUG, "Digest %d has no corresponding nid!", algo);
return false;
}
unsigned int len = gcry_md_get_algo_dlen(algo);
- if(maclength > len || maclength < 0)
+ if(maclength > len || maclength < 0) {
digest->maclength = len;
- else
+ } else {
digest->maclength = maclength;
-
+ }
+
digest->algo = algo;
+ digest->hmac = NULL;
return true;
}
int algo;
if(!nametodigest(name, &algo)) {
- logger(LOG_DEBUG, "Unknown digest name '%s'!", name);
+ logger(DEBUG_ALWAYS, LOG_DEBUG, "Unknown digest name '%s'!", name);
return false;
}
int algo;
if(!nidtodigest(nid, &algo)) {
- logger(LOG_DEBUG, "Unknown digest ID %d!", nid);
+ logger(DEBUG_ALWAYS, LOG_DEBUG, "Unknown digest ID %d!", nid);
return false;
}
}
void digest_close(digest_t *digest) {
+ if(digest->hmac) {
+ gcry_md_close(digest->hmac);
+ }
+
+ digest->hmac = NULL;
+}
+
+bool digest_set_key(digest_t *digest, const void *key, size_t len) {
+ if(!digest->hmac) {
+ gcry_md_open(&digest->hmac, digest->algo, GCRY_MD_FLAG_HMAC);
+ }
+
+ if(!digest->hmac) {
+ return false;
+ }
+
+ return !gcry_md_setkey(digest->hmac, key, len);
}
bool digest_create(digest_t *digest, const void *indata, size_t inlen, void *outdata) {
unsigned int len = gcry_md_get_algo_dlen(digest->algo);
- char tmpdata[len];
- gcry_md_hash_buffer(digest->algo, tmpdata, indata, inlen);
- memcpy(outdata, tmpdata, digest->maclength);
+ if(digest->hmac) {
+ char *tmpdata;
+ gcry_md_reset(digest->hmac);
+ gcry_md_write(digest->hmac, indata, inlen);
+ tmpdata = gcry_md_read(digest->hmac, digest->algo);
+
+ if(!tmpdata) {
+ return false;
+ }
+
+ memcpy(outdata, tmpdata, digest->maclength);
+ } else {
+ char tmpdata[len];
+ gcry_md_hash_buffer(digest->algo, tmpdata, indata, inlen);
+ memcpy(outdata, tmpdata, digest->maclength);
+ }
return true;
}
bool digest_verify(digest_t *digest, const void *indata, size_t inlen, const void *cmpdata) {
- unsigned int len = gcry_md_get_algo_dlen(digest->algo);
+ unsigned int len = digest->maclength;
char outdata[len];
- gcry_md_hash_buffer(digest->algo, outdata, indata, inlen);
- return !memcmp(cmpdata, outdata, digest->maclength);
+ return digest_create(digest, indata, inlen, outdata) && !memcmp(cmpdata, outdata, len);
}
int digest_get_nid(const digest_t *digest) {