/**********************************************************************
* gost_eng.c *
+ * Main file of GOST engine *
+ * *
* Copyright (c) 2005-2006 Cryptocom LTD *
- * This file is distributed under the same license as OpenSSL *
+ * Copyright (c) 2020 Chikunov Vitaly <vt@altlinux.org> *
+ * *
+ * This file is distributed under the same license as OpenSSL *
* *
- * Main file of GOST engine *
- * for OpenSSL *
- * Requires OpenSSL 0.9.9 for compilation *
**********************************************************************/
#include <string.h>
#include <openssl/crypto.h>
#include <openssl/obj_mac.h>
#include "e_gost_err.h"
#include "gost_lcl.h"
-static const char *engine_gost_id = "gost";
-static const char *engine_gost_name =
- "Reference implementation of GOST engine";
-/* Symmetric cipher and digest function registrar */
-
-static int gost_ciphers(ENGINE *e, const EVP_CIPHER **cipher,
- const int **nids, int nid);
+#include "gost_grasshopper_cipher.h"
-static int gost_digests(ENGINE *e, const EVP_MD **digest,
- const int **nids, int ind);
+static const char* engine_gost_id = "gost";
-static int gost_pkey_meths(ENGINE *e, EVP_PKEY_METHOD **pmeth,
- const int **nids, int nid);
+static const char* engine_gost_name =
+ "Reference implementation of GOST engine";
-static int gost_pkey_asn1_meths(ENGINE *e, EVP_PKEY_ASN1_METHOD **ameth,
- const int **nids, int nid);
+/* Symmetric cipher and digest function registrar */
-static int gost_cipher_nids[] = {
- NID_id_Gost28147_89,
- NID_gost89_cnt,
- NID_gost89_cnt_12,
- 0
+static int gost_ciphers(ENGINE* e, const EVP_CIPHER** cipher,
+ const int** nids, int nid);
+
+static int gost_digests(ENGINE* e, const EVP_MD** digest,
+ const int** nids, int nid);
+
+static int gost_pkey_meths(ENGINE* e, EVP_PKEY_METHOD** pmeth,
+ const int** nids, int nid);
+
+static int gost_pkey_asn1_meths(ENGINE* e, EVP_PKEY_ASN1_METHOD** ameth,
+ const int** nids, int nid);
+
+static EVP_PKEY_METHOD* pmeth_GostR3410_2001 = NULL,
+ * pmeth_GostR3410_2012_256 = NULL,
+ * pmeth_GostR3410_2012_512 = NULL,
+ * pmeth_Gost28147_MAC = NULL, * pmeth_Gost28147_MAC_12 = NULL,
+ * pmeth_magma_mac = NULL, * pmeth_grasshopper_mac = NULL,
+ * pmeth_magma_mac_acpkm = NULL, * pmeth_grasshopper_mac_acpkm = NULL;
+
+static EVP_PKEY_ASN1_METHOD* ameth_GostR3410_2001 = NULL,
+ * ameth_GostR3410_2012_256 = NULL,
+ * ameth_GostR3410_2012_512 = NULL,
+ * ameth_Gost28147_MAC = NULL, * ameth_Gost28147_MAC_12 = NULL,
+ * ameth_magma_mac = NULL, * ameth_grasshopper_mac = NULL,
+ * ameth_magma_mac_acpkm = NULL, * ameth_grasshopper_mac_acpkm = NULL;
+
+static struct gost_digest_minfo {
+ int nid;
+ EVP_MD *(*digest)(void);
+ void (*destroy)(void);
+ const char *sn;
+ const char *alias;
+} gost_digest_array[] = {
+ {
+ NID_id_GostR3411_94,
+ digest_gost,
+ digest_gost_destroy,
+ },
+ {
+ NID_id_Gost28147_89_MAC,
+ imit_gost_cpa,
+ imit_gost_cpa_destroy,
+ },
+ {
+ NID_id_GostR3411_2012_256,
+ digest_gost2012_256,
+ digest_gost2012_256_destroy,
+ SN_id_GostR3411_2012_256,
+ "streebog256",
+ },
+ {
+ NID_id_GostR3411_2012_512,
+ digest_gost2012_512,
+ digest_gost2012_512_destroy,
+ SN_id_GostR3411_2012_512,
+ "streebog512",
+ },
+ {
+ NID_gost_mac_12,
+ imit_gost_cp_12,
+ imit_gost_cp_12_destroy,
+ },
+ {
+ NID_magma_mac,
+ magma_omac,
+ magma_omac_destroy,
+ },
+ {
+ NID_grasshopper_mac,
+ grasshopper_omac,
+ grasshopper_omac_destroy,
+ },
+ {
+ NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm_omac,
+ grasshopper_omac_acpkm,
+ grasshopper_omac_acpkm_destroy,
+ },
+ { 0 },
};
-static int gost_digest_nids[] = {
- NID_id_GostR3411_94,
- NID_id_Gost28147_89_MAC,
- NID_id_GostR3411_2012_256,
- NID_id_GostR3411_2012_512,
- NID_gost_mac_12,
- 0
+static struct gost_cipher_minfo {
+ int nid;
+ const EVP_CIPHER *(*cipher)(void);
+} gost_cipher_array[] = {
+ {
+ NID_id_Gost28147_89,
+ cipher_gost,
+ },
+ {
+ NID_gost89_cnt,
+ cipher_gost_cpacnt,
+ },
+ {
+ NID_gost89_cnt_12,
+ cipher_gost_cpcnt_12,
+ },
+ {
+ NID_gost89_cbc,
+ cipher_gost_cbc,
+ },
+ {
+ NID_grasshopper_ecb,
+ cipher_gost_grasshopper_ecb,
+ },
+ {
+ NID_grasshopper_cbc,
+ cipher_gost_grasshopper_cbc,
+ },
+ {
+ NID_grasshopper_cfb,
+ cipher_gost_grasshopper_cfb,
+ },
+ {
+ NID_grasshopper_ofb,
+ cipher_gost_grasshopper_ofb,
+ },
+ {
+ NID_grasshopper_ctr,
+ cipher_gost_grasshopper_ctr,
+ },
+ {
+ NID_magma_cbc,
+ cipher_magma_cbc,
+ },
+ {
+ NID_magma_ctr,
+ cipher_magma_ctr,
+ },
+ {
+ NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm,
+ cipher_gost_grasshopper_ctracpkm,
+ },
+ { 0 },
};
-static int gost_pkey_meth_nids[] = {
- NID_id_GostR3410_94,
- NID_id_GostR3410_2001,
- NID_id_Gost28147_89_MAC,
- NID_id_GostR3410_2012_256,
- NID_id_GostR3410_2012_512,
- NID_gost_mac_12,
- 0
+static struct gost_meth_minfo {
+ int nid;
+ EVP_PKEY_METHOD **pmeth;
+ EVP_PKEY_ASN1_METHOD **ameth;
+ const char *pemstr;
+ const char *info;
+} gost_meth_array[] = {
+ {
+ NID_id_GostR3410_2001,
+ &pmeth_GostR3410_2001,
+ &ameth_GostR3410_2001,
+ "GOST2001",
+ "GOST R 34.10-2001",
+ },
+ {
+ NID_id_Gost28147_89_MAC,
+ &pmeth_Gost28147_MAC,
+ &ameth_Gost28147_MAC,
+ "GOST-MAC",
+ "GOST 28147-89 MAC",
+ },
+ {
+ NID_id_GostR3410_2012_256,
+ &pmeth_GostR3410_2012_256,
+ &ameth_GostR3410_2012_256,
+ "GOST2012_256",
+ "GOST R 34.10-2012 with 256 bit key",
+ },
+ {
+ NID_id_GostR3410_2012_512,
+ &pmeth_GostR3410_2012_512,
+ &ameth_GostR3410_2012_512,
+ "GOST2012_512",
+ "GOST R 34.10-2012 with 512 bit key",
+ },
+ {
+ NID_gost_mac_12,
+ &pmeth_Gost28147_MAC_12,
+ &ameth_Gost28147_MAC_12,
+ "GOST-MAC-12",
+ "GOST 28147-89 MAC with 2012 params",
+ },
+ {
+ NID_magma_mac,
+ &pmeth_magma_mac,
+ &ameth_magma_mac,
+ "MAGMA-MAC",
+ "GOST R 34.13-2015 Magma MAC",
+ },
+ {
+ NID_grasshopper_mac,
+ &pmeth_grasshopper_mac,
+ &ameth_grasshopper_mac,
+ "GRASSHOPPER-MAC",
+ "GOST R 34.13-2015 Grasshopper MAC",
+ },
+ {
+ NID_id_tc26_cipher_gostr3412_2015_magma_ctracpkm_omac,
+ &pmeth_magma_mac_acpkm,
+ &ameth_magma_mac_acpkm,
+ "ID-TC26-CIPHER-GOSTR3412-2015-MAGMA-CTRACPKM-OMAC",
+ "GOST R 34.13-2015 Magma MAC ACPKM",
+ },
+ {
+ NID_id_tc26_cipher_gostr3412_2015_kuznyechik_ctracpkm_omac,
+ &pmeth_grasshopper_mac_acpkm,
+ &ameth_grasshopper_mac_acpkm,
+ "ID-TC26-CIPHER-GOSTR3412-2015-KUZNYECHIK-CTRACPKM-OMAC",
+ "GOST R 34.13-2015 Grasshopper MAC ACPKM",
+ },
+ { 0 },
};
-static EVP_PKEY_METHOD *pmeth_GostR3410_94 = NULL,
- *pmeth_GostR3410_2001 = NULL,
- *pmeth_GostR3410_2012_256 = NULL,
- *pmeth_GostR3410_2012_512 = NULL,
- *pmeth_Gost28147_MAC = NULL,
- *pmeth_Gost28147_MAC_12 = NULL;
-
-static EVP_PKEY_ASN1_METHOD *ameth_GostR3410_94 = NULL,
- *ameth_GostR3410_2001 = NULL,
- *ameth_GostR3410_2012_256 = NULL,
- *ameth_GostR3410_2012_512 = NULL,
- *ameth_Gost28147_MAC = NULL,
- *ameth_Gost28147_MAC_12 = NULL;
-
-static int gost_engine_init(ENGINE *e)
-{
+#ifndef OSSL_NELEM
+# define OSSL_NELEM(x) (sizeof(x)/sizeof((x)[0]))
+#endif
+
+/* `- 1' because of terminating zero element */
+static int known_digest_nids[OSSL_NELEM(gost_digest_array) - 1];
+static int known_cipher_nids[OSSL_NELEM(gost_cipher_array) - 1];
+static int known_meths_nids[OSSL_NELEM(gost_meth_array) - 1];
+
+static int gost_engine_init(ENGINE* e) {
return 1;
}
-static int gost_engine_finish(ENGINE *e)
-{
+static int gost_engine_finish(ENGINE* e) {
return 1;
}
-static int gost_engine_destroy(ENGINE *e)
-{
+static int gost_engine_destroy(ENGINE* e) {
+ struct gost_digest_minfo *dinfo = gost_digest_array;
+ for (; dinfo->nid; dinfo++) {
+ if (dinfo->alias)
+ EVP_delete_digest_alias(dinfo->alias);
+ dinfo->destroy();
+ }
+
+ cipher_gost_destroy();
+ cipher_gost_grasshopper_destroy();
+
gost_param_free();
- pmeth_GostR3410_94 = NULL;
- pmeth_GostR3410_2001 = NULL;
- pmeth_Gost28147_MAC = NULL;
- pmeth_GostR3410_2012_256 = NULL;
- pmeth_GostR3410_2012_512 = NULL;
- pmeth_Gost28147_MAC_12 = NULL;
+ struct gost_meth_minfo *minfo = gost_meth_array;
+ for (; minfo->nid; minfo++) {
+ *minfo->pmeth = NULL;
+ *minfo->ameth = NULL;
+ }
- ameth_GostR3410_94 = NULL;
- ameth_GostR3410_2001 = NULL;
- ameth_Gost28147_MAC = NULL;
- ameth_GostR3410_2012_256 = NULL;
- ameth_GostR3410_2012_512 = NULL;
- ameth_Gost28147_MAC_12 = NULL;
+ ERR_unload_GOST_strings();
return 1;
}
-static int bind_gost(ENGINE *e, const char *id)
-{
+static int bind_gost(ENGINE* e, const char* id) {
int ret = 0;
- if (id && strcmp(id, engine_gost_id))
+ if (id != NULL && strcmp(id, engine_gost_id) != 0)
return 0;
-
- if (ameth_GostR3410_94) {
+ if (ameth_GostR3410_2001) {
printf("GOST engine already loaded\n");
goto end;
}
goto end;
}
- if (!register_ameth_gost
- (NID_id_GostR3410_94, &ameth_GostR3410_94, "GOST94",
- "GOST R 34.10-94"))
- goto end;
- if (!register_ameth_gost
- (NID_id_GostR3410_2001, &ameth_GostR3410_2001, "GOST2001",
- "GOST R 34.10-2001"))
- goto end;
- if (!register_ameth_gost
- (NID_id_GostR3410_2012_256, &ameth_GostR3410_2012_256, "GOST2012_256",
- "GOST R 34.10-2012 with 256 bit key"))
- goto end;
- if (!register_ameth_gost
- (NID_id_GostR3410_2012_512, &ameth_GostR3410_2012_512, "GOST2012_512",
- "GOST R 34.10-2012 with 512 bit key"))
- goto end;
- if (!register_ameth_gost(NID_id_Gost28147_89_MAC, &ameth_Gost28147_MAC,
- "GOST-MAC", "GOST 28147-89 MAC"))
- goto end;
- if (!register_ameth_gost(NID_gost_mac_12, &ameth_Gost28147_MAC_12,
- "GOST-MAC-12",
- "GOST 28147-89 MAC with 2012 params"))
- goto end;
+ struct gost_meth_minfo *minfo = gost_meth_array;
+ for (; minfo->nid; minfo++) {
+
+ /* This skip looks temporary. */
+ if (minfo->nid == NID_id_tc26_cipher_gostr3412_2015_magma_ctracpkm_omac)
+ continue;
+
+ if (!register_ameth_gost(minfo->nid, minfo->ameth, minfo->pemstr,
+ minfo->info))
+ goto end;
+ if (!register_pmeth_gost(minfo->nid, minfo->pmeth, 0))
+ goto end;
+ }
- if (!register_pmeth_gost(NID_id_GostR3410_94, &pmeth_GostR3410_94, 0))
- goto end;
- if (!register_pmeth_gost(NID_id_GostR3410_2001, &pmeth_GostR3410_2001, 0))
- goto end;
- if (!register_pmeth_gost
- (NID_id_GostR3410_2012_256, &pmeth_GostR3410_2012_256, 0))
- goto end;
- if (!register_pmeth_gost
- (NID_id_GostR3410_2012_512, &pmeth_GostR3410_2012_512, 0))
- goto end;
- if (!register_pmeth_gost
- (NID_id_Gost28147_89_MAC, &pmeth_Gost28147_MAC, 0))
- goto end;
- if (!register_pmeth_gost(NID_gost_mac_12, &pmeth_Gost28147_MAC_12, 0))
- goto end;
if (!ENGINE_register_ciphers(e)
|| !ENGINE_register_digests(e)
- || !ENGINE_register_pkey_meths(e)
- /* These two actually should go in LIST_ADD command */
- || !EVP_add_cipher(&cipher_gost)
- || !EVP_add_cipher(&cipher_gost_cpacnt)
- || !EVP_add_cipher(&cipher_gost_cpcnt_12)
- || !EVP_add_digest(&digest_gost)
- || !EVP_add_digest(&digest_gost2012_512)
- || !EVP_add_digest(&digest_gost2012_256)
- || !EVP_add_digest(&imit_gost_cpa)
- || !EVP_add_digest(&imit_gost_cp_12)
- ) {
+ || !ENGINE_register_pkey_meths(e))
goto end;
+
+ struct gost_cipher_minfo *cinfo = gost_cipher_array;
+ for (; cinfo->nid; cinfo++)
+ if (!EVP_add_cipher(cinfo->cipher()))
+ goto end;
+
+ struct gost_digest_minfo *dinfo = gost_digest_array;
+ for (; dinfo->nid; dinfo++) {
+ if (!EVP_add_digest(dinfo->digest()))
+ goto end;
+ if (dinfo->alias &&
+ !EVP_add_digest_alias(dinfo->sn, dinfo->alias))
+ goto end;
}
+ ENGINE_register_all_complete();
+
ERR_load_GOST_strings();
ret = 1;
- end:
+ end:
return ret;
}
IMPLEMENT_DYNAMIC_BIND_FN(bind_gost)
IMPLEMENT_DYNAMIC_CHECK_FN()
#endif /* ndef OPENSSL_NO_DYNAMIC_ENGINE */
+
+/* ENGINE_DIGESTS_PTR callback installed by ENGINE_set_digests */
static int gost_digests(ENGINE *e, const EVP_MD **digest,
const int **nids, int nid)
{
- int ok = 1;
+ struct gost_digest_minfo *info = gost_digest_array;
+
if (!digest) {
- *nids = gost_digest_nids;
- return 5;
- }
- if (nid == NID_id_GostR3411_94) {
- *digest = &digest_gost;
- } else if (nid == NID_id_GostR3411_2012_256) {
- *digest = &digest_gost2012_256;
- } else if (nid == NID_id_GostR3411_2012_512) {
- *digest = &digest_gost2012_512;
- } else if (nid == NID_id_Gost28147_89_MAC) {
- *digest = &imit_gost_cpa;
- } else if (nid == NID_gost_mac_12) {
- *digest = &imit_gost_cp_12;
- } else {
- ok = 0;
- *digest = NULL;
+ int *n = known_digest_nids;
+
+ *nids = n;
+ for (; info->nid; info++)
+ *n++ = info->nid;
+ return OSSL_NELEM(known_digest_nids);
}
- return ok;
+
+ for (; info->nid; info++)
+ if (nid == info->nid) {
+ *digest = info->digest();
+ return 1;
+ }
+ *digest = NULL;
+ return 0;
}
+/* ENGINE_CIPHERS_PTR callback installed by ENGINE_set_ciphers */
static int gost_ciphers(ENGINE *e, const EVP_CIPHER **cipher,
const int **nids, int nid)
{
- int ok = 1;
+ struct gost_cipher_minfo *info = gost_cipher_array;
+
if (!cipher) {
- *nids = gost_cipher_nids;
- return 3; /* three ciphers are supported */
- }
+ int *n = known_cipher_nids;
- if (nid == NID_id_Gost28147_89) {
- *cipher = &cipher_gost;
- } else if (nid == NID_gost89_cnt) {
- *cipher = &cipher_gost_cpacnt;
- } else if (nid == NID_gost89_cnt_12) {
- *cipher = &cipher_gost_cpcnt_12;
- } else {
- ok = 0;
- *cipher = NULL;
+ *nids = n;
+ for (; info->nid; info++)
+ *n++ = info->nid;
+ return OSSL_NELEM(known_cipher_nids);
}
- return ok;
+
+ for (; info->nid; info++)
+ if (nid == info->nid) {
+ *cipher = info->cipher();
+ return 1;
+ }
+ *cipher = NULL;
+ return 0;
+}
+
+static int gost_meth_nids(const int **nids)
+{
+ struct gost_meth_minfo *info = gost_meth_array;
+ int *n = known_meths_nids;
+
+ *nids = n;
+ for (; info->nid; info++)
+ *n++ = info->nid;
+ return OSSL_NELEM(known_meths_nids);
}
+/* ENGINE_PKEY_METHS_PTR installed by ENGINE_set_pkey_meths */
static int gost_pkey_meths(ENGINE *e, EVP_PKEY_METHOD **pmeth,
const int **nids, int nid)
{
- if (!pmeth) {
- *nids = gost_pkey_meth_nids;
- return 6;
- }
+ struct gost_meth_minfo *info;
- switch (nid) {
- case NID_id_GostR3410_94:
- *pmeth = pmeth_GostR3410_94;
- return 1;
- case NID_id_GostR3410_2001:
- *pmeth = pmeth_GostR3410_2001;
- return 1;
- case NID_id_GostR3410_2012_256:
- *pmeth = pmeth_GostR3410_2012_256;
- return 1;
- case NID_id_GostR3410_2012_512:
- *pmeth = pmeth_GostR3410_2012_512;
- return 1;
- case NID_id_Gost28147_89_MAC:
- *pmeth = pmeth_Gost28147_MAC;
- return 1;
- case NID_gost_mac_12:
- *pmeth = pmeth_Gost28147_MAC_12;
- return 1;
-
- default:;
- }
+ if (!pmeth)
+ return gost_meth_nids(nids);
+ for (info = gost_meth_array; info->nid; info++)
+ if (nid == info->nid) {
+ *pmeth = *info->pmeth;
+ return 1;
+ }
*pmeth = NULL;
return 0;
}
+/* ENGINE_PKEY_ASN1_METHS_PTR installed by ENGINE_set_pkey_asn1_meths */
static int gost_pkey_asn1_meths(ENGINE *e, EVP_PKEY_ASN1_METHOD **ameth,
const int **nids, int nid)
{
- if (!ameth) {
- *nids = gost_pkey_meth_nids;
- return 6;
- }
- switch (nid) {
- case NID_id_GostR3410_94:
- *ameth = ameth_GostR3410_94;
- return 1;
- case NID_id_GostR3410_2001:
- *ameth = ameth_GostR3410_2001;
- return 1;
- case NID_id_GostR3410_2012_256:
- *ameth = ameth_GostR3410_2012_256;
- return 1;
- case NID_id_GostR3410_2012_512:
- *ameth = ameth_GostR3410_2012_512;
- return 1;
- case NID_id_Gost28147_89_MAC:
- *ameth = ameth_Gost28147_MAC;
- return 1;
- case NID_gost_mac_12:
- *ameth = ameth_Gost28147_MAC_12;
- return 1;
-
- default:;
- }
+ struct gost_meth_minfo *info;
+ if (!ameth)
+ return gost_meth_nids(nids);
+
+ for (info = gost_meth_array; info->nid; info++)
+ if (nid == info->nid) {
+ *ameth = *info->ameth;
+ return 1;
+ }
*ameth = NULL;
return 0;
}
#ifdef OPENSSL_NO_DYNAMIC_ENGINE
-static ENGINE *engine_gost(void)
-{
- ENGINE *ret = ENGINE_new();
+
+static ENGINE* engine_gost(void) {
+ ENGINE* ret = ENGINE_new();
if (!ret)
return NULL;
if (!bind_gost(ret, engine_gost_id)) {
return ret;
}
-void ENGINE_load_gost(void)
-{
- ENGINE *toadd;
- if (pmeth_GostR3410_94)
+void ENGINE_load_gost(void) {
+ ENGINE* toadd;
+ if (pmeth_GostR3410_2001)
return;
toadd = engine_gost();
if (!toadd)
ENGINE_free(toadd);
ERR_clear_error();
}
+
#endif