pem_lib.c

来自「openssl是ssl的开源项目」· C语言 代码 · 共 763 行 · 第 1/2 页

C
763
字号
/* crypto/pem/pem_lib.c *//* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * * This package is an SSL implementation written * by Eric Young (eay@cryptsoft.com). * The implementation was written so as to conform with Netscapes SSL. *  * This library is free for commercial and non-commercial use as long as * the following conditions are aheared to.  The following conditions * apply to all code found in this distribution, be it the RC4, RSA, * lhash, DES, etc., code; not just the SSL code.  The SSL documentation * included with this distribution is covered by the same copyright terms * except that the holder is Tim Hudson (tjh@cryptsoft.com). *  * Copyright remains Eric Young's, and as such any Copyright notices in * the code are not to be removed. * If this package is used in a product, Eric Young should be given attribution * as the author of the parts of the library used. * This can be in the form of a textual message at program startup or * in documentation (online or textual) provided with the package. *  * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * 1. Redistributions of source code must retain the copyright *    notice, this list of conditions and the following disclaimer. * 2. Redistributions in binary form must reproduce the above copyright *    notice, this list of conditions and the following disclaimer in the *    documentation and/or other materials provided with the distribution. * 3. All advertising materials mentioning features or use of this software *    must display the following acknowledgement: *    "This product includes cryptographic software written by *     Eric Young (eay@cryptsoft.com)" *    The word 'cryptographic' can be left out if the rouines from the library *    being used are not cryptographic related :-). * 4. If you include any Windows specific code (or a derivative thereof) from  *    the apps directory (application code) you must include an acknowledgement: *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" *  * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF * SUCH DAMAGE. *  * The licence and distribution terms for any publically available version or * derivative of this code cannot be changed.  i.e. this code cannot simply be * copied and put under another distribution licence * [including the GNU Public Licence.] */#include <stdio.h>#include "cryptlib.h"#include "buffer.h"#include "objects.h"#include "evp.h"#include "rand.h"#include "x509.h"#include "pem.h"#ifndef NO_DES#include "des.h"#endifchar *PEM_version="PEM part of OpenSSL 0.9.1c 23-Dec-1998";#define MIN_LENGTH	4/* PEMerr(PEM_F_PEM_WRITE_BIO,ERR_R_MALLOC_FAILURE); * PEMerr(PEM_F_PEM_READ_BIO,ERR_R_MALLOC_FAILURE); */#ifndef NOPROTOstatic int def_callback(char *buf, int num, int w);static int load_iv(unsigned char **fromp,unsigned char *to, int num);#elsestatic int def_callback();static int load_iv();#endifstatic int def_callback(buf, num, w)char *buf;int num;int w;	{#ifdef NO_FP_API	/* We should not ever call the default callback routine from	 * windows. */	PEMerr(PEM_F_DEF_CALLBACK,ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);	return(-1);#else	int i,j;	char *prompt;	prompt=EVP_get_pw_prompt();	if (prompt == NULL)		prompt="Enter PEM pass phrase:";	for (;;)		{		i=EVP_read_pw_string(buf,num,prompt,w);		if (i != 0)			{			PEMerr(PEM_F_DEF_CALLBACK,PEM_R_PROBLEMS_GETTING_PASSWORD);			memset(buf,0,(unsigned int)num);			return(-1);			}		j=strlen(buf);		if (j < MIN_LENGTH)			{			fprintf(stderr,"phrase is too short, needs to be at least %d chars\n",MIN_LENGTH);			}		else			break;		}	return(j);#endif	}void PEM_proc_type(buf, type)char *buf;int type;	{	char *str;	if (type == PEM_TYPE_ENCRYPTED)		str="ENCRYPTED";	else if (type == PEM_TYPE_MIC_CLEAR)		str="MIC-CLEAR";	else if (type == PEM_TYPE_MIC_ONLY)		str="MIC-ONLY";	else		str="BAD-TYPE";			strcat(buf,"Proc-Type: 4,");	strcat(buf,str);	strcat(buf,"\n");	}void PEM_dek_info(buf, type, len, str)char *buf;char *type;int len;char *str;	{	static unsigned char map[17]="0123456789ABCDEF";	long i;	int j;	strcat(buf,"DEK-Info: ");	strcat(buf,type);	strcat(buf,",");	j=strlen(buf);	for (i=0; i<len; i++)		{		buf[j+i*2]  =map[(str[i]>>4)&0x0f];		buf[j+i*2+1]=map[(str[i]   )&0x0f];		}	buf[j+i*2]='\n';	buf[j+i*2+1]='\0';	}#ifndef NO_FP_APIchar *PEM_ASN1_read(d2i,name,fp, x, cb)char *(*d2i)();char *name;FILE *fp;char **x;int (*cb)();	{        BIO *b;        char *ret;        if ((b=BIO_new(BIO_s_file())) == NULL)		{		PEMerr(PEM_F_PEM_ASN1_READ,ERR_R_BUF_LIB);                return(0);		}        BIO_set_fp(b,fp,BIO_NOCLOSE);        ret=PEM_ASN1_read_bio(d2i,name,b,x,cb);        BIO_free(b);        return(ret);	}#endifchar *PEM_ASN1_read_bio(d2i,name,bp, x, cb)char *(*d2i)();char *name;BIO *bp;char **x;int (*cb)();	{	EVP_CIPHER_INFO cipher;	char *nm=NULL,*header=NULL;	unsigned char *p=NULL,*data=NULL;	long len;	char *ret=NULL;	for (;;)		{		if (!PEM_read_bio(bp,&nm,&header,&data,&len)) return(NULL);		if (	(strcmp(nm,name) == 0) ||			((strcmp(nm,PEM_STRING_RSA) == 0) &&			 (strcmp(name,PEM_STRING_EVP_PKEY) == 0)) ||			((strcmp(nm,PEM_STRING_DSA) == 0) &&			 (strcmp(name,PEM_STRING_EVP_PKEY) == 0)) ||			((strcmp(nm,PEM_STRING_X509_OLD) == 0) &&			 (strcmp(name,PEM_STRING_X509) == 0)) ||			((strcmp(nm,PEM_STRING_X509_REQ_OLD) == 0) &&			 (strcmp(name,PEM_STRING_X509_REQ) == 0))			)			break;		Free(nm);		Free(header);		Free(data);		}	if (!PEM_get_EVP_CIPHER_INFO(header,&cipher)) goto err;	if (!PEM_do_header(&cipher,data,&len,cb)) goto err;	p=data;	if (strcmp(name,PEM_STRING_EVP_PKEY) == 0)		{		if (strcmp(nm,PEM_STRING_RSA) == 0)			ret=d2i(EVP_PKEY_RSA,x,&p,len);		else if (strcmp(nm,PEM_STRING_DSA) == 0)			ret=d2i(EVP_PKEY_DSA,x,&p,len);		}	else			ret=d2i(x,&p,len);	if (ret == NULL)		PEMerr(PEM_F_PEM_ASN1_READ_BIO,ERR_R_ASN1_LIB);err:	Free(nm);	Free(header);	Free(data);	return(ret);	}#ifndef NO_FP_APIint PEM_ASN1_write(i2d,name,fp, x, enc, kstr, klen, callback)int (*i2d)();char *name;FILE *fp;char *x;EVP_CIPHER *enc;unsigned char *kstr;int klen;int (*callback)();        {        BIO *b;        int ret;        if ((b=BIO_new(BIO_s_file())) == NULL)		{		PEMerr(PEM_F_PEM_ASN1_WRITE,ERR_R_BUF_LIB);                return(0);		}        BIO_set_fp(b,fp,BIO_NOCLOSE);        ret=PEM_ASN1_write_bio(i2d,name,b,x,enc,kstr,klen,callback);        BIO_free(b);        return(ret);        }#endifint PEM_ASN1_write_bio(i2d,name,bp, x, enc, kstr, klen, callback)int (*i2d)();char *name;BIO *bp;char *x;EVP_CIPHER *enc;unsigned char *kstr;int klen;int (*callback)();	{	EVP_CIPHER_CTX ctx;	int dsize=0,i,j,ret=0;	unsigned char *p,*data=NULL;	char *objstr=NULL;#define PEM_BUFSIZE	1024	char buf[PEM_BUFSIZE];	unsigned char key[EVP_MAX_KEY_LENGTH];	unsigned char iv[EVP_MAX_IV_LENGTH];		if (enc != NULL)		{		objstr=OBJ_nid2sn(EVP_CIPHER_nid(enc));		if (objstr == NULL)			{			PEMerr(PEM_F_PEM_ASN1_WRITE_BIO,PEM_R_UNSUPPORTED_CIPHER);			goto err;			}		}	if ((dsize=i2d(x,NULL)) < 0)		{		PEMerr(PEM_F_PEM_ASN1_WRITE_BIO,ERR_R_MALLOC_FAILURE);		dsize=0;		goto err;		}	/* dzise + 8 bytes are needed */	data=(unsigned char *)Malloc((unsigned int)dsize+20);	if (data == NULL)		{		PEMerr(PEM_F_PEM_ASN1_WRITE_BIO,ERR_R_MALLOC_FAILURE);		goto err;		}	p=data;	i=i2d(x,&p);	if (enc != NULL)		{		if (kstr == NULL)			{			if (callback == NULL)				klen=def_callback(buf,PEM_BUFSIZE,1);			else				klen=(*callback)(buf,PEM_BUFSIZE,1);			if (klen <= 0)				{				PEMerr(PEM_F_PEM_ASN1_WRITE_BIO,PEM_R_READ_KEY);				goto err;				}			kstr=(unsigned char *)buf;			}		RAND_seed(data,i);/* put in the RSA key. */		RAND_bytes(iv,8);	/* Generate a salt */		/* The 'iv' is used as the iv and as a salt.  It is		 * NOT taken from the BytesToKey function */		EVP_BytesToKey(enc,EVP_md5(),iv,kstr,klen,1,key,NULL);		if (kstr == (unsigned char *)buf) memset(buf,0,PEM_BUFSIZE);		buf[0]='\0';		PEM_proc_type(buf,PEM_TYPE_ENCRYPTED);		PEM_dek_info(buf,objstr,8,(char *)iv);		/* k=strlen(buf); */			EVP_EncryptInit(&ctx,enc,key,iv);		EVP_EncryptUpdate(&ctx,data,&j,data,i);		EVP_EncryptFinal(&ctx,&(data[j]),&i);		i+=j;		ret=1;		}	else		{		ret=1;		buf[0]='\0';		}	i=PEM_write_bio(bp,name,buf,data,i);	if (i <= 0) ret=0;err:	memset(key,0,sizeof(key));	memset(iv,0,sizeof(iv));	memset((char *)&ctx,0,sizeof(ctx));	memset(buf,0,PEM_BUFSIZE);	memset(data,0,(unsigned int)dsize);	Free(data);	return(ret);	}int PEM_do_header(cipher, data, plen, callback)EVP_CIPHER_INFO *cipher;unsigned char *data;long *plen;int (*callback)();	{	int i,j,o,klen;	long len;	EVP_CIPHER_CTX ctx;	unsigned char key[EVP_MAX_KEY_LENGTH];	char buf[PEM_BUFSIZE];	len= *plen;	if (cipher->cipher == NULL) return(1);	if (callback == NULL)		klen=def_callback(buf,PEM_BUFSIZE,0);

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?