mirror of
https://github.com/curl/curl.git
synced 2024-12-15 06:40:09 +08:00
76172511e7
- Use the Windows API to seed the fallback random generator. This ensures to always have a random seed, even when libcurl is built with a vtls backend lacking a random generator API, such as rustls (experimental), GSKit and certain mbedTLS builds, or, when libcurl is built without a TLS backend. We reuse the Windows-specific random function from the Schannel backend. - Implement support for `BCryptGenRandom()` [1] on Windows, as a replacement for the deprecated `CryptGenRandom()` [2] function. It is used as the secure random generator for Schannel, and also to provide entropy for libcurl's fallback random generator. The new function is supported on Vista and newer via its `bcrypt.dll`. It is used automatically when building for supported versions. It also works in UWP apps (the old function did not). - Clear entropy buffer before calling the Windows random generator. This avoids using arbitrary application memory as entropy (with `CryptGenRandom()`) and makes sure to return in a predictable state when an API call fails. [1] https://docs.microsoft.com/windows/win32/api/bcrypt/nf-bcrypt-bcryptgenrandom [2] https://docs.microsoft.com/windows/win32/api/wincrypt/nf-wincrypt-cryptgenrandom Closes #9027
58 lines
2.1 KiB
C
58 lines
2.1 KiB
C
#ifndef HEADER_CURL_RAND_H
|
|
#define HEADER_CURL_RAND_H
|
|
/***************************************************************************
|
|
* _ _ ____ _
|
|
* Project ___| | | | _ \| |
|
|
* / __| | | | |_) | |
|
|
* | (__| |_| | _ <| |___
|
|
* \___|\___/|_| \_\_____|
|
|
*
|
|
* Copyright (C) 1998 - 2022, Daniel Stenberg, <daniel@haxx.se>, et al.
|
|
*
|
|
* This software is licensed as described in the file COPYING, which
|
|
* you should have received as part of this distribution. The terms
|
|
* are also available at https://curl.se/docs/copyright.html.
|
|
*
|
|
* You may opt to use, copy, modify, merge, publish, distribute and/or sell
|
|
* copies of the Software, and permit persons to whom the Software is
|
|
* furnished to do so, under the terms of the COPYING file.
|
|
*
|
|
* This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
|
|
* KIND, either express or implied.
|
|
*
|
|
* SPDX-License-Identifier: curl
|
|
*
|
|
***************************************************************************/
|
|
|
|
/*
|
|
* Curl_rand() stores 'num' number of random unsigned characters in the buffer
|
|
* 'rnd' points to.
|
|
*
|
|
* If libcurl is built without TLS support or with a TLS backend that lacks a
|
|
* proper random API (Gskit or mbedTLS), this function will use "weak" random.
|
|
*
|
|
* When built *with* TLS support and a backend that offers strong random, it
|
|
* will return error if it cannot provide strong random values.
|
|
*
|
|
* NOTE: 'data' may be passed in as NULL when coming from external API without
|
|
* easy handle!
|
|
*
|
|
*/
|
|
CURLcode Curl_rand(struct Curl_easy *data, unsigned char *rnd, size_t num);
|
|
|
|
/*
|
|
* Curl_rand_hex() fills the 'rnd' buffer with a given 'num' size with random
|
|
* hexadecimal digits PLUS a zero terminating byte. It must be an odd number
|
|
* size.
|
|
*/
|
|
CURLcode Curl_rand_hex(struct Curl_easy *data, unsigned char *rnd,
|
|
size_t num);
|
|
|
|
#ifdef WIN32
|
|
/* Random generator shared between the Schannel vtls and Curl_rand*()
|
|
functions */
|
|
CURLcode Curl_win32_random(unsigned char *entropy, size_t length);
|
|
#endif
|
|
|
|
#endif /* HEADER_CURL_RAND_H */
|