1 /**********************************************************************
3 * Copyright (c) 2005-2006 Cryptocom LTD *
4 * This file is distributed under the same license as OpenSSL *
6 * Main file of GOST engine *
8 * Requires OpenSSL 0.9.9 for compilation *
9 **********************************************************************/
11 #include <openssl/crypto.h>
12 #include <openssl/err.h>
13 #include <openssl/evp.h>
14 #include <openssl/engine.h>
15 #include <openssl/obj_mac.h>
16 #include "e_gost_err.h"
18 static const char *engine_gost_id = "gost";
19 static const char *engine_gost_name =
20 "Reference implementation of GOST engine";
22 /* Symmetric cipher and digest function registrar */
24 static int gost_ciphers(ENGINE *e, const EVP_CIPHER **cipher,
25 const int **nids, int nid);
27 static int gost_digests(ENGINE *e, const EVP_MD **digest,
28 const int **nids, int ind);
30 static int gost_pkey_meths(ENGINE *e, EVP_PKEY_METHOD **pmeth,
31 const int **nids, int nid);
33 static int gost_pkey_asn1_meths(ENGINE *e, EVP_PKEY_ASN1_METHOD **ameth,
34 const int **nids, int nid);
36 static int gost_cipher_nids[] = {
44 static int gost_digest_nids(const int **nids)
46 static int digest_nids[6] = { 0, 0, 0, 0, 0, 0 };
52 if ((md = digest_gost()) != NULL)
53 digest_nids[pos++] = EVP_MD_type(md);
54 if ((md = imit_gost_cpa()) != NULL)
55 digest_nids[pos++] = EVP_MD_type(md);
56 if ((md = digest_gost2012_256()) != NULL)
57 digest_nids[pos++] = EVP_MD_type(md);
58 if ((md = digest_gost2012_512()) != NULL)
59 digest_nids[pos++] = EVP_MD_type(md);
60 if ((md = imit_gost_cp_12()) != NULL)
61 digest_nids[pos++] = EVP_MD_type(md);
69 static int gost_pkey_meth_nids[] = {
70 NID_id_GostR3410_2001,
71 NID_id_Gost28147_89_MAC,
72 NID_id_GostR3410_2012_256,
73 NID_id_GostR3410_2012_512,
78 static EVP_PKEY_METHOD *pmeth_GostR3410_2001 = NULL,
79 *pmeth_GostR3410_2012_256 = NULL,
80 *pmeth_GostR3410_2012_512 = NULL,
81 *pmeth_Gost28147_MAC = NULL, *pmeth_Gost28147_MAC_12 = NULL;
83 static EVP_PKEY_ASN1_METHOD *ameth_GostR3410_2001 = NULL,
84 *ameth_GostR3410_2012_256 = NULL,
85 *ameth_GostR3410_2012_512 = NULL,
86 *ameth_Gost28147_MAC = NULL, *ameth_Gost28147_MAC_12 = NULL;
88 static int gost_engine_init(ENGINE *e)
93 static int gost_engine_finish(ENGINE *e)
98 static int gost_engine_destroy(ENGINE *e)
100 digest_gost_destroy();
101 digest_gost2012_256_destroy();
102 digest_gost2012_512_destroy();
103 imit_gost_cpa_destroy();
104 imit_gost_cp_12_destroy();
108 pmeth_GostR3410_2001 = NULL;
109 pmeth_Gost28147_MAC = NULL;
110 pmeth_GostR3410_2012_256 = NULL;
111 pmeth_GostR3410_2012_512 = NULL;
112 pmeth_Gost28147_MAC_12 = NULL;
114 ameth_GostR3410_2001 = NULL;
115 ameth_Gost28147_MAC = NULL;
116 ameth_GostR3410_2012_256 = NULL;
117 ameth_GostR3410_2012_512 = NULL;
118 ameth_Gost28147_MAC_12 = NULL;
123 static int bind_gost(ENGINE *e, const char *id)
126 if (id && strcmp(id, engine_gost_id))
128 if (ameth_GostR3410_2001) {
129 printf("GOST engine already loaded\n");
132 if (!ENGINE_set_id(e, engine_gost_id)) {
133 printf("ENGINE_set_id failed\n");
136 if (!ENGINE_set_name(e, engine_gost_name)) {
137 printf("ENGINE_set_name failed\n");
140 if (!ENGINE_set_digests(e, gost_digests)) {
141 printf("ENGINE_set_digests failed\n");
144 if (!ENGINE_set_ciphers(e, gost_ciphers)) {
145 printf("ENGINE_set_ciphers failed\n");
148 if (!ENGINE_set_pkey_meths(e, gost_pkey_meths)) {
149 printf("ENGINE_set_pkey_meths failed\n");
152 if (!ENGINE_set_pkey_asn1_meths(e, gost_pkey_asn1_meths)) {
153 printf("ENGINE_set_pkey_asn1_meths failed\n");
156 /* Control function and commands */
157 if (!ENGINE_set_cmd_defns(e, gost_cmds)) {
158 fprintf(stderr, "ENGINE_set_cmd_defns failed\n");
161 if (!ENGINE_set_ctrl_function(e, gost_control_func)) {
162 fprintf(stderr, "ENGINE_set_ctrl_func failed\n");
165 if (!ENGINE_set_destroy_function(e, gost_engine_destroy)
166 || !ENGINE_set_init_function(e, gost_engine_init)
167 || !ENGINE_set_finish_function(e, gost_engine_finish)) {
171 if (!register_ameth_gost
172 (NID_id_GostR3410_2001, &ameth_GostR3410_2001, "GOST2001",
173 "GOST R 34.10-2001"))
175 if (!register_ameth_gost
176 (NID_id_GostR3410_2012_256, &ameth_GostR3410_2012_256, "GOST2012_256",
177 "GOST R 34.10-2012 with 256 bit key"))
179 if (!register_ameth_gost
180 (NID_id_GostR3410_2012_512, &ameth_GostR3410_2012_512, "GOST2012_512",
181 "GOST R 34.10-2012 with 512 bit key"))
183 if (!register_ameth_gost(NID_id_Gost28147_89_MAC, &ameth_Gost28147_MAC,
184 "GOST-MAC", "GOST 28147-89 MAC"))
186 if (!register_ameth_gost(NID_gost_mac_12, &ameth_Gost28147_MAC_12,
188 "GOST 28147-89 MAC with 2012 params"))
191 if (!register_pmeth_gost(NID_id_GostR3410_2001, &pmeth_GostR3410_2001, 0))
194 if (!register_pmeth_gost
195 (NID_id_GostR3410_2012_256, &pmeth_GostR3410_2012_256, 0))
197 if (!register_pmeth_gost
198 (NID_id_GostR3410_2012_512, &pmeth_GostR3410_2012_512, 0))
200 if (!register_pmeth_gost
201 (NID_id_Gost28147_89_MAC, &pmeth_Gost28147_MAC, 0))
203 if (!register_pmeth_gost(NID_gost_mac_12, &pmeth_Gost28147_MAC_12, 0))
205 if (!ENGINE_register_ciphers(e)
206 || !ENGINE_register_digests(e)
207 || !ENGINE_register_pkey_meths(e)
208 /* These two actually should go in LIST_ADD command */
209 || !EVP_add_cipher(&cipher_gost)
210 || !EVP_add_cipher(&cipher_gost_cbc)
211 || !EVP_add_cipher(&cipher_gost_cpacnt)
212 || !EVP_add_cipher(&cipher_gost_cpcnt_12)
213 || !EVP_add_digest(digest_gost())
214 || !EVP_add_digest(digest_gost2012_512())
215 || !EVP_add_digest(digest_gost2012_256())
216 || !EVP_add_digest(imit_gost_cpa())
217 || !EVP_add_digest(imit_gost_cp_12())
222 ERR_load_GOST_strings();
228 #ifndef OPENSSL_NO_DYNAMIC_ENGINE
229 IMPLEMENT_DYNAMIC_BIND_FN(bind_gost)
230 IMPLEMENT_DYNAMIC_CHECK_FN()
231 #endif /* ndef OPENSSL_NO_DYNAMIC_ENGINE */
232 static int gost_digests(ENGINE *e, const EVP_MD **digest,
233 const int **nids, int nid)
237 return gost_digest_nids(nids);
239 if (nid == NID_id_GostR3411_94) {
240 *digest = digest_gost();
241 } else if (nid == NID_id_Gost28147_89_MAC) {
242 *digest = imit_gost_cpa();
243 } else if (nid == NID_id_GostR3411_2012_256) {
244 *digest = digest_gost2012_256();
245 } else if (nid == NID_id_GostR3411_2012_512) {
246 *digest = digest_gost2012_512();
247 } else if (nid == NID_gost_mac_12) {
248 *digest = imit_gost_cp_12();
256 static int gost_ciphers(ENGINE *e, const EVP_CIPHER **cipher,
257 const int **nids, int nid)
261 *nids = gost_cipher_nids;
262 return sizeof(gost_cipher_nids) / sizeof(gost_cipher_nids[0]) - 1;
265 if (nid == NID_id_Gost28147_89) {
266 *cipher = &cipher_gost;
267 } else if (nid == NID_gost89_cnt) {
268 *cipher = &cipher_gost_cpacnt;
269 } else if (nid == NID_gost89_cnt_12) {
270 *cipher = &cipher_gost_cpcnt_12;
271 } else if (nid == NID_gost89_cbc) {
272 *cipher = &cipher_gost_cbc;
280 static int gost_pkey_meths(ENGINE *e, EVP_PKEY_METHOD **pmeth,
281 const int **nids, int nid)
284 *nids = gost_pkey_meth_nids;
285 return sizeof(gost_pkey_meth_nids) / sizeof(gost_pkey_meth_nids[0]) -
290 case NID_id_GostR3410_2001:
291 *pmeth = pmeth_GostR3410_2001;
293 case NID_id_GostR3410_2012_256:
294 *pmeth = pmeth_GostR3410_2012_256;
296 case NID_id_GostR3410_2012_512:
297 *pmeth = pmeth_GostR3410_2012_512;
299 case NID_id_Gost28147_89_MAC:
300 *pmeth = pmeth_Gost28147_MAC;
302 case NID_gost_mac_12:
303 *pmeth = pmeth_Gost28147_MAC_12;
313 static int gost_pkey_asn1_meths(ENGINE *e, EVP_PKEY_ASN1_METHOD **ameth,
314 const int **nids, int nid)
317 *nids = gost_pkey_meth_nids;
318 return sizeof(gost_pkey_meth_nids) / sizeof(gost_pkey_meth_nids[0]) -
322 case NID_id_GostR3410_2001:
323 *ameth = ameth_GostR3410_2001;
325 case NID_id_GostR3410_2012_256:
326 *ameth = ameth_GostR3410_2012_256;
328 case NID_id_GostR3410_2012_512:
329 *ameth = ameth_GostR3410_2012_512;
331 case NID_id_Gost28147_89_MAC:
332 *ameth = ameth_Gost28147_MAC;
334 case NID_gost_mac_12:
335 *ameth = ameth_Gost28147_MAC_12;
345 #ifdef OPENSSL_NO_DYNAMIC_ENGINE
346 static ENGINE *engine_gost(void)
348 ENGINE *ret = ENGINE_new();
351 if (!bind_gost(ret, engine_gost_id)) {
358 void ENGINE_load_gost(void)
361 if (pmeth_GostR3410_2001)
363 toadd = engine_gost();