2015-01-22 11:40:55 +08:00
|
|
|
/*
|
2017-08-02 02:19:43 +08:00
|
|
|
* Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.
|
1999-12-22 09:39:23 +08:00
|
|
|
*
|
2018-12-06 20:54:02 +08:00
|
|
|
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
2016-05-18 02:51:34 +08:00
|
|
|
* this file except in compliance with the License. You can obtain a copy
|
|
|
|
* in the file LICENSE in the source distribution or at
|
|
|
|
* https://www.openssl.org/source/license.html
|
1999-12-22 09:39:23 +08:00
|
|
|
*/
|
|
|
|
|
2020-02-12 13:03:51 +08:00
|
|
|
/*
|
|
|
|
* RSA low level APIs are deprecated for public use, but still ok for
|
|
|
|
* internal use.
|
|
|
|
*/
|
|
|
|
#include "internal/deprecated.h"
|
|
|
|
|
1999-12-22 09:39:23 +08:00
|
|
|
#include <stdio.h>
|
2015-05-14 22:56:48 +08:00
|
|
|
#include "internal/cryptlib.h"
|
2000-12-09 03:09:35 +08:00
|
|
|
#include <openssl/bn.h>
|
2010-03-07 03:55:25 +08:00
|
|
|
#include <openssl/x509.h>
|
2000-12-09 03:09:35 +08:00
|
|
|
#include <openssl/asn1t.h>
|
2019-09-28 06:45:40 +08:00
|
|
|
#include "rsa_local.h"
|
1999-12-22 09:39:23 +08:00
|
|
|
|
2017-08-02 02:19:43 +08:00
|
|
|
/*
|
|
|
|
* Override the default free and new methods,
|
|
|
|
* and calculate helper products for multi-prime
|
|
|
|
* RSA keys.
|
|
|
|
*/
|
2005-09-02 04:42:52 +08:00
|
|
|
static int rsa_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it,
|
2015-01-22 11:40:55 +08:00
|
|
|
void *exarg)
|
2000-12-09 03:09:35 +08:00
|
|
|
{
|
2015-01-22 11:40:55 +08:00
|
|
|
if (operation == ASN1_OP_NEW_PRE) {
|
|
|
|
*pval = (ASN1_VALUE *)RSA_new();
|
2015-10-30 19:12:26 +08:00
|
|
|
if (*pval != NULL)
|
2015-01-22 11:40:55 +08:00
|
|
|
return 2;
|
|
|
|
return 0;
|
|
|
|
} else if (operation == ASN1_OP_FREE_PRE) {
|
|
|
|
RSA_free((RSA *)*pval);
|
|
|
|
*pval = NULL;
|
|
|
|
return 2;
|
2017-08-02 02:19:43 +08:00
|
|
|
} else if (operation == ASN1_OP_D2I_POST) {
|
|
|
|
if (((RSA *)*pval)->version != RSA_ASN1_VERSION_MULTI) {
|
|
|
|
/* not a multi-prime key, skip */
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
return (rsa_multip_calc_product((RSA *)*pval) == 1) ? 2 : 0;
|
2015-01-22 11:40:55 +08:00
|
|
|
}
|
|
|
|
return 1;
|
2000-12-09 03:09:35 +08:00
|
|
|
}
|
1999-12-22 09:39:23 +08:00
|
|
|
|
2017-08-02 02:19:43 +08:00
|
|
|
/* Based on definitions in RFC 8017 appendix A.1.2 */
|
|
|
|
ASN1_SEQUENCE(RSA_PRIME_INFO) = {
|
|
|
|
ASN1_SIMPLE(RSA_PRIME_INFO, r, CBIGNUM),
|
|
|
|
ASN1_SIMPLE(RSA_PRIME_INFO, d, CBIGNUM),
|
|
|
|
ASN1_SIMPLE(RSA_PRIME_INFO, t, CBIGNUM),
|
|
|
|
} ASN1_SEQUENCE_END(RSA_PRIME_INFO)
|
|
|
|
|
2000-12-09 03:09:35 +08:00
|
|
|
ASN1_SEQUENCE_cb(RSAPrivateKey, rsa_cb) = {
|
2017-04-12 17:52:52 +08:00
|
|
|
ASN1_EMBED(RSA, version, INT32),
|
2015-01-22 11:40:55 +08:00
|
|
|
ASN1_SIMPLE(RSA, n, BIGNUM),
|
|
|
|
ASN1_SIMPLE(RSA, e, BIGNUM),
|
2015-04-25 04:39:40 +08:00
|
|
|
ASN1_SIMPLE(RSA, d, CBIGNUM),
|
|
|
|
ASN1_SIMPLE(RSA, p, CBIGNUM),
|
|
|
|
ASN1_SIMPLE(RSA, q, CBIGNUM),
|
|
|
|
ASN1_SIMPLE(RSA, dmp1, CBIGNUM),
|
|
|
|
ASN1_SIMPLE(RSA, dmq1, CBIGNUM),
|
2017-08-02 02:19:43 +08:00
|
|
|
ASN1_SIMPLE(RSA, iqmp, CBIGNUM),
|
|
|
|
ASN1_SEQUENCE_OF_OPT(RSA, prime_infos, RSA_PRIME_INFO)
|
2001-02-23 20:47:06 +08:00
|
|
|
} ASN1_SEQUENCE_END_cb(RSA, RSAPrivateKey)
|
1999-12-22 09:39:23 +08:00
|
|
|
|
|
|
|
|
2000-12-09 03:09:35 +08:00
|
|
|
ASN1_SEQUENCE_cb(RSAPublicKey, rsa_cb) = {
|
2015-01-22 11:40:55 +08:00
|
|
|
ASN1_SIMPLE(RSA, n, BIGNUM),
|
|
|
|
ASN1_SIMPLE(RSA, e, BIGNUM),
|
2001-02-23 20:47:06 +08:00
|
|
|
} ASN1_SEQUENCE_END_cb(RSA, RSAPublicKey)
|
1999-12-22 09:39:23 +08:00
|
|
|
|
2016-11-25 02:51:54 +08:00
|
|
|
/* Free up maskHash */
|
|
|
|
static int rsa_pss_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it,
|
|
|
|
void *exarg)
|
|
|
|
{
|
|
|
|
if (operation == ASN1_OP_FREE_PRE) {
|
|
|
|
RSA_PSS_PARAMS *pss = (RSA_PSS_PARAMS *)*pval;
|
|
|
|
X509_ALGOR_free(pss->maskHash);
|
|
|
|
}
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
ASN1_SEQUENCE_cb(RSA_PSS_PARAMS, rsa_pss_cb) = {
|
2015-01-22 11:40:55 +08:00
|
|
|
ASN1_EXP_OPT(RSA_PSS_PARAMS, hashAlgorithm, X509_ALGOR,0),
|
|
|
|
ASN1_EXP_OPT(RSA_PSS_PARAMS, maskGenAlgorithm, X509_ALGOR,1),
|
|
|
|
ASN1_EXP_OPT(RSA_PSS_PARAMS, saltLength, ASN1_INTEGER,2),
|
|
|
|
ASN1_EXP_OPT(RSA_PSS_PARAMS, trailerField, ASN1_INTEGER,3)
|
2016-11-25 02:51:54 +08:00
|
|
|
} ASN1_SEQUENCE_END_cb(RSA_PSS_PARAMS, RSA_PSS_PARAMS)
|
2010-03-07 03:55:25 +08:00
|
|
|
|
2010-03-07 21:34:51 +08:00
|
|
|
IMPLEMENT_ASN1_FUNCTIONS(RSA_PSS_PARAMS)
|
2010-03-07 03:55:25 +08:00
|
|
|
|
2016-11-25 02:51:54 +08:00
|
|
|
/* Free up maskHash */
|
|
|
|
static int rsa_oaep_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it,
|
|
|
|
void *exarg)
|
|
|
|
{
|
|
|
|
if (operation == ASN1_OP_FREE_PRE) {
|
|
|
|
RSA_OAEP_PARAMS *oaep = (RSA_OAEP_PARAMS *)*pval;
|
|
|
|
X509_ALGOR_free(oaep->maskHash);
|
|
|
|
}
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
ASN1_SEQUENCE_cb(RSA_OAEP_PARAMS, rsa_oaep_cb) = {
|
2015-01-22 11:40:55 +08:00
|
|
|
ASN1_EXP_OPT(RSA_OAEP_PARAMS, hashFunc, X509_ALGOR, 0),
|
|
|
|
ASN1_EXP_OPT(RSA_OAEP_PARAMS, maskGenFunc, X509_ALGOR, 1),
|
|
|
|
ASN1_EXP_OPT(RSA_OAEP_PARAMS, pSourceFunc, X509_ALGOR, 2),
|
2016-11-25 02:51:54 +08:00
|
|
|
} ASN1_SEQUENCE_END_cb(RSA_OAEP_PARAMS, RSA_OAEP_PARAMS)
|
2013-06-20 01:21:37 +08:00
|
|
|
|
|
|
|
IMPLEMENT_ASN1_FUNCTIONS(RSA_OAEP_PARAMS)
|
|
|
|
|
2019-01-16 04:51:25 +08:00
|
|
|
IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(RSA, RSAPrivateKey, RSAPrivateKey)
|
1999-12-22 09:39:23 +08:00
|
|
|
|
2019-01-16 04:51:25 +08:00
|
|
|
IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(RSA, RSAPublicKey, RSAPublicKey)
|
2001-07-27 10:22:42 +08:00
|
|
|
|
2019-01-16 04:51:25 +08:00
|
|
|
RSA *RSAPublicKey_dup(const RSA *rsa)
|
2015-01-22 11:40:55 +08:00
|
|
|
{
|
|
|
|
return ASN1_item_dup(ASN1_ITEM_rptr(RSAPublicKey), rsa);
|
|
|
|
}
|
2001-07-27 10:22:42 +08:00
|
|
|
|
2019-01-16 04:51:25 +08:00
|
|
|
RSA *RSAPrivateKey_dup(const RSA *rsa)
|
2015-01-22 11:40:55 +08:00
|
|
|
{
|
|
|
|
return ASN1_item_dup(ASN1_ITEM_rptr(RSAPrivateKey), rsa);
|
|
|
|
}
|