2 * Copyright 2006-2018 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the OpenSSL license (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
12 #include "internal/cryptlib.h"
13 #include <openssl/engine.h>
14 #include <openssl/evp.h>
15 #include <openssl/x509v3.h>
16 #include "internal/asn1_int.h"
17 #include "internal/evp_int.h"
18 #include "internal/numbers.h"
20 typedef int sk_cmp_fn_type(const char *const *a, const char *const *b);
22 static STACK_OF(EVP_PKEY_METHOD) *app_pkey_methods = NULL;
24 /* This array needs to be in order of NIDs */
25 static const EVP_PKEY_METHOD *standard_methods[] = {
26 #ifndef OPENSSL_NO_RSA
32 #ifndef OPENSSL_NO_DSA
39 #ifndef OPENSSL_NO_CMAC
42 #ifndef OPENSSL_NO_RSA
48 #ifndef OPENSSL_NO_SCRYPT
57 #ifndef OPENSSL_NO_POLY1305
60 #ifndef OPENSSL_NO_SIPHASH
67 #ifndef OPENSSL_NO_SM2
72 DECLARE_OBJ_BSEARCH_CMP_FN(const EVP_PKEY_METHOD *, const EVP_PKEY_METHOD *,
75 static int pmeth_cmp(const EVP_PKEY_METHOD *const *a,
76 const EVP_PKEY_METHOD *const *b)
78 return ((*a)->pkey_id - (*b)->pkey_id);
81 IMPLEMENT_OBJ_BSEARCH_CMP_FN(const EVP_PKEY_METHOD *, const EVP_PKEY_METHOD *,
84 const EVP_PKEY_METHOD *EVP_PKEY_meth_find(int type)
87 const EVP_PKEY_METHOD *t = &tmp, **ret;
89 if (app_pkey_methods) {
91 idx = sk_EVP_PKEY_METHOD_find(app_pkey_methods, &tmp);
93 return sk_EVP_PKEY_METHOD_value(app_pkey_methods, idx);
95 ret = OBJ_bsearch_pmeth(&t, standard_methods,
96 sizeof(standard_methods) /
97 sizeof(EVP_PKEY_METHOD *));
103 static EVP_PKEY_CTX *int_ctx_new(EVP_PKEY *pkey, ENGINE *e, int id)
106 const EVP_PKEY_METHOD *pmeth;
113 #ifndef OPENSSL_NO_ENGINE
114 if (e == NULL && pkey != NULL)
115 e = pkey->pmeth_engine != NULL ? pkey->pmeth_engine : pkey->engine;
116 /* Try to find an ENGINE which implements this method */
118 if (!ENGINE_init(e)) {
119 EVPerr(EVP_F_INT_CTX_NEW, ERR_R_ENGINE_LIB);
123 e = ENGINE_get_pkey_meth_engine(id);
127 * If an ENGINE handled this method look it up. Otherwise use internal
131 pmeth = ENGINE_get_pkey_meth(e, id);
134 pmeth = EVP_PKEY_meth_find(id);
137 #ifndef OPENSSL_NO_ENGINE
140 EVPerr(EVP_F_INT_CTX_NEW, EVP_R_UNSUPPORTED_ALGORITHM);
144 ret = OPENSSL_zalloc(sizeof(*ret));
146 #ifndef OPENSSL_NO_ENGINE
149 EVPerr(EVP_F_INT_CTX_NEW, ERR_R_MALLOC_FAILURE);
154 ret->operation = EVP_PKEY_OP_UNDEFINED;
157 EVP_PKEY_up_ref(pkey);
160 if (pmeth->init(ret) <= 0) {
162 EVP_PKEY_CTX_free(ret);
170 EVP_PKEY_METHOD *EVP_PKEY_meth_new(int id, int flags)
172 EVP_PKEY_METHOD *pmeth;
174 pmeth = OPENSSL_zalloc(sizeof(*pmeth));
176 EVPerr(EVP_F_EVP_PKEY_METH_NEW, ERR_R_MALLOC_FAILURE);
181 pmeth->flags = flags | EVP_PKEY_FLAG_DYNAMIC;
185 void EVP_PKEY_meth_get0_info(int *ppkey_id, int *pflags,
186 const EVP_PKEY_METHOD *meth)
189 *ppkey_id = meth->pkey_id;
191 *pflags = meth->flags;
194 void EVP_PKEY_meth_copy(EVP_PKEY_METHOD *dst, const EVP_PKEY_METHOD *src)
197 dst->init = src->init;
198 dst->copy = src->copy;
199 dst->cleanup = src->cleanup;
201 dst->paramgen_init = src->paramgen_init;
202 dst->paramgen = src->paramgen;
204 dst->keygen_init = src->keygen_init;
205 dst->keygen = src->keygen;
207 dst->sign_init = src->sign_init;
208 dst->sign = src->sign;
210 dst->verify_init = src->verify_init;
211 dst->verify = src->verify;
213 dst->verify_recover_init = src->verify_recover_init;
214 dst->verify_recover = src->verify_recover;
216 dst->signctx_init = src->signctx_init;
217 dst->signctx = src->signctx;
219 dst->verifyctx_init = src->verifyctx_init;
220 dst->verifyctx = src->verifyctx;
222 dst->encrypt_init = src->encrypt_init;
223 dst->encrypt = src->encrypt;
225 dst->decrypt_init = src->decrypt_init;
226 dst->decrypt = src->decrypt;
228 dst->derive_init = src->derive_init;
229 dst->derive = src->derive;
231 dst->ctrl = src->ctrl;
232 dst->ctrl_str = src->ctrl_str;
234 dst->check = src->check;
237 void EVP_PKEY_meth_free(EVP_PKEY_METHOD *pmeth)
239 if (pmeth && (pmeth->flags & EVP_PKEY_FLAG_DYNAMIC))
243 EVP_PKEY_CTX *EVP_PKEY_CTX_new(EVP_PKEY *pkey, ENGINE *e)
245 return int_ctx_new(pkey, e, -1);
248 EVP_PKEY_CTX *EVP_PKEY_CTX_new_id(int id, ENGINE *e)
250 return int_ctx_new(NULL, e, id);
253 EVP_PKEY_CTX *EVP_PKEY_CTX_dup(EVP_PKEY_CTX *pctx)
256 if (!pctx->pmeth || !pctx->pmeth->copy)
258 #ifndef OPENSSL_NO_ENGINE
259 /* Make sure it's safe to copy a pkey context using an ENGINE */
260 if (pctx->engine && !ENGINE_init(pctx->engine)) {
261 EVPerr(EVP_F_EVP_PKEY_CTX_DUP, ERR_R_ENGINE_LIB);
265 rctx = OPENSSL_malloc(sizeof(*rctx));
267 EVPerr(EVP_F_EVP_PKEY_CTX_DUP, ERR_R_MALLOC_FAILURE);
271 rctx->pmeth = pctx->pmeth;
272 #ifndef OPENSSL_NO_ENGINE
273 rctx->engine = pctx->engine;
277 EVP_PKEY_up_ref(pctx->pkey);
279 rctx->pkey = pctx->pkey;
282 EVP_PKEY_up_ref(pctx->peerkey);
284 rctx->peerkey = pctx->peerkey;
287 rctx->app_data = NULL;
288 rctx->operation = pctx->operation;
290 if (pctx->pmeth->copy(rctx, pctx) > 0)
294 EVP_PKEY_CTX_free(rctx);
299 int EVP_PKEY_meth_add0(const EVP_PKEY_METHOD *pmeth)
301 if (app_pkey_methods == NULL) {
302 app_pkey_methods = sk_EVP_PKEY_METHOD_new(pmeth_cmp);
303 if (app_pkey_methods == NULL){
304 EVPerr(EVP_F_EVP_PKEY_METH_ADD0, ERR_R_MALLOC_FAILURE);
308 if (!sk_EVP_PKEY_METHOD_push(app_pkey_methods, pmeth)) {
309 EVPerr(EVP_F_EVP_PKEY_METH_ADD0, ERR_R_MALLOC_FAILURE);
312 sk_EVP_PKEY_METHOD_sort(app_pkey_methods);
316 void evp_app_cleanup_int(void)
318 if (app_pkey_methods != NULL)
319 sk_EVP_PKEY_METHOD_pop_free(app_pkey_methods, EVP_PKEY_meth_free);
322 int EVP_PKEY_meth_remove(const EVP_PKEY_METHOD *pmeth)
324 const EVP_PKEY_METHOD *ret;
326 ret = sk_EVP_PKEY_METHOD_delete_ptr(app_pkey_methods, pmeth);
328 return ret == NULL ? 0 : 1;
331 size_t EVP_PKEY_meth_get_count(void)
333 size_t rv = OSSL_NELEM(standard_methods);
335 if (app_pkey_methods)
336 rv += sk_EVP_PKEY_METHOD_num(app_pkey_methods);
340 const EVP_PKEY_METHOD *EVP_PKEY_meth_get0(size_t idx)
342 if (idx < OSSL_NELEM(standard_methods))
343 return standard_methods[idx];
344 if (app_pkey_methods == NULL)
346 idx -= OSSL_NELEM(standard_methods);
347 if (idx >= (size_t)sk_EVP_PKEY_METHOD_num(app_pkey_methods))
349 return sk_EVP_PKEY_METHOD_value(app_pkey_methods, idx);
352 void EVP_PKEY_CTX_free(EVP_PKEY_CTX *ctx)
356 if (ctx->pmeth && ctx->pmeth->cleanup)
357 ctx->pmeth->cleanup(ctx);
358 EVP_PKEY_free(ctx->pkey);
359 EVP_PKEY_free(ctx->peerkey);
360 #ifndef OPENSSL_NO_ENGINE
361 ENGINE_finish(ctx->engine);
366 int EVP_PKEY_CTX_ctrl(EVP_PKEY_CTX *ctx, int keytype, int optype,
367 int cmd, int p1, void *p2)
371 if (!ctx || !ctx->pmeth || !ctx->pmeth->ctrl) {
372 EVPerr(EVP_F_EVP_PKEY_CTX_CTRL, EVP_R_COMMAND_NOT_SUPPORTED);
375 if ((keytype != -1) && (ctx->pmeth->pkey_id != keytype))
378 /* Skip the operation checks since this is called in a very early stage */
379 if (ctx->pmeth->digest_custom != NULL)
382 if (ctx->operation == EVP_PKEY_OP_UNDEFINED) {
383 EVPerr(EVP_F_EVP_PKEY_CTX_CTRL, EVP_R_NO_OPERATION_SET);
387 if ((optype != -1) && !(ctx->operation & optype)) {
388 EVPerr(EVP_F_EVP_PKEY_CTX_CTRL, EVP_R_INVALID_OPERATION);
393 ret = ctx->pmeth->ctrl(ctx, cmd, p1, p2);
396 EVPerr(EVP_F_EVP_PKEY_CTX_CTRL, EVP_R_COMMAND_NOT_SUPPORTED);
401 int EVP_PKEY_CTX_ctrl_uint64(EVP_PKEY_CTX *ctx, int keytype, int optype,
402 int cmd, uint64_t value)
404 return EVP_PKEY_CTX_ctrl(ctx, keytype, optype, cmd, 0, &value);
407 int EVP_PKEY_CTX_ctrl_str(EVP_PKEY_CTX *ctx,
408 const char *name, const char *value)
410 if (!ctx || !ctx->pmeth || !ctx->pmeth->ctrl_str) {
411 EVPerr(EVP_F_EVP_PKEY_CTX_CTRL_STR, EVP_R_COMMAND_NOT_SUPPORTED);
414 if (strcmp(name, "digest") == 0)
415 return EVP_PKEY_CTX_md(ctx, EVP_PKEY_OP_TYPE_SIG, EVP_PKEY_CTRL_MD,
417 return ctx->pmeth->ctrl_str(ctx, name, value);
420 /* Utility functions to send a string of hex string to a ctrl */
422 int EVP_PKEY_CTX_str2ctrl(EVP_PKEY_CTX *ctx, int cmd, const char *str)
429 return ctx->pmeth->ctrl(ctx, cmd, len, (void *)str);
432 int EVP_PKEY_CTX_hex2ctrl(EVP_PKEY_CTX *ctx, int cmd, const char *hex)
438 bin = OPENSSL_hexstr2buf(hex, &binlen);
441 if (binlen <= INT_MAX)
442 rv = ctx->pmeth->ctrl(ctx, cmd, binlen, bin);
447 /* Pass a message digest to a ctrl */
448 int EVP_PKEY_CTX_md(EVP_PKEY_CTX *ctx, int optype, int cmd, const char *md)
452 if (md == NULL || (m = EVP_get_digestbyname(md)) == NULL) {
453 EVPerr(EVP_F_EVP_PKEY_CTX_MD, EVP_R_INVALID_DIGEST);
456 return EVP_PKEY_CTX_ctrl(ctx, -1, optype, cmd, 0, (void *)m);
459 int EVP_PKEY_CTX_get_operation(EVP_PKEY_CTX *ctx)
461 return ctx->operation;
464 void EVP_PKEY_CTX_set0_keygen_info(EVP_PKEY_CTX *ctx, int *dat, int datlen)
466 ctx->keygen_info = dat;
467 ctx->keygen_info_count = datlen;
470 void EVP_PKEY_CTX_set_data(EVP_PKEY_CTX *ctx, void *data)
475 void *EVP_PKEY_CTX_get_data(EVP_PKEY_CTX *ctx)
480 EVP_PKEY *EVP_PKEY_CTX_get0_pkey(EVP_PKEY_CTX *ctx)
485 EVP_PKEY *EVP_PKEY_CTX_get0_peerkey(EVP_PKEY_CTX *ctx)
490 void EVP_PKEY_CTX_set_app_data(EVP_PKEY_CTX *ctx, void *data)
492 ctx->app_data = data;
495 void *EVP_PKEY_CTX_get_app_data(EVP_PKEY_CTX *ctx)
497 return ctx->app_data;
500 void EVP_PKEY_meth_set_init(EVP_PKEY_METHOD *pmeth,
501 int (*init) (EVP_PKEY_CTX *ctx))
506 void EVP_PKEY_meth_set_copy(EVP_PKEY_METHOD *pmeth,
507 int (*copy) (EVP_PKEY_CTX *dst,
513 void EVP_PKEY_meth_set_cleanup(EVP_PKEY_METHOD *pmeth,
514 void (*cleanup) (EVP_PKEY_CTX *ctx))
516 pmeth->cleanup = cleanup;
519 void EVP_PKEY_meth_set_paramgen(EVP_PKEY_METHOD *pmeth,
520 int (*paramgen_init) (EVP_PKEY_CTX *ctx),
521 int (*paramgen) (EVP_PKEY_CTX *ctx,
524 pmeth->paramgen_init = paramgen_init;
525 pmeth->paramgen = paramgen;
528 void EVP_PKEY_meth_set_keygen(EVP_PKEY_METHOD *pmeth,
529 int (*keygen_init) (EVP_PKEY_CTX *ctx),
530 int (*keygen) (EVP_PKEY_CTX *ctx,
533 pmeth->keygen_init = keygen_init;
534 pmeth->keygen = keygen;
537 void EVP_PKEY_meth_set_sign(EVP_PKEY_METHOD *pmeth,
538 int (*sign_init) (EVP_PKEY_CTX *ctx),
539 int (*sign) (EVP_PKEY_CTX *ctx,
540 unsigned char *sig, size_t *siglen,
541 const unsigned char *tbs,
544 pmeth->sign_init = sign_init;
548 void EVP_PKEY_meth_set_verify(EVP_PKEY_METHOD *pmeth,
549 int (*verify_init) (EVP_PKEY_CTX *ctx),
550 int (*verify) (EVP_PKEY_CTX *ctx,
551 const unsigned char *sig,
553 const unsigned char *tbs,
556 pmeth->verify_init = verify_init;
557 pmeth->verify = verify;
560 void EVP_PKEY_meth_set_verify_recover(EVP_PKEY_METHOD *pmeth,
561 int (*verify_recover_init) (EVP_PKEY_CTX
563 int (*verify_recover) (EVP_PKEY_CTX
572 pmeth->verify_recover_init = verify_recover_init;
573 pmeth->verify_recover = verify_recover;
576 void EVP_PKEY_meth_set_signctx(EVP_PKEY_METHOD *pmeth,
577 int (*signctx_init) (EVP_PKEY_CTX *ctx,
579 int (*signctx) (EVP_PKEY_CTX *ctx,
584 pmeth->signctx_init = signctx_init;
585 pmeth->signctx = signctx;
588 void EVP_PKEY_meth_set_verifyctx(EVP_PKEY_METHOD *pmeth,
589 int (*verifyctx_init) (EVP_PKEY_CTX *ctx,
591 int (*verifyctx) (EVP_PKEY_CTX *ctx,
592 const unsigned char *sig,
596 pmeth->verifyctx_init = verifyctx_init;
597 pmeth->verifyctx = verifyctx;
600 void EVP_PKEY_meth_set_encrypt(EVP_PKEY_METHOD *pmeth,
601 int (*encrypt_init) (EVP_PKEY_CTX *ctx),
602 int (*encryptfn) (EVP_PKEY_CTX *ctx,
605 const unsigned char *in,
608 pmeth->encrypt_init = encrypt_init;
609 pmeth->encrypt = encryptfn;
612 void EVP_PKEY_meth_set_decrypt(EVP_PKEY_METHOD *pmeth,
613 int (*decrypt_init) (EVP_PKEY_CTX *ctx),
614 int (*decrypt) (EVP_PKEY_CTX *ctx,
617 const unsigned char *in,
620 pmeth->decrypt_init = decrypt_init;
621 pmeth->decrypt = decrypt;
624 void EVP_PKEY_meth_set_derive(EVP_PKEY_METHOD *pmeth,
625 int (*derive_init) (EVP_PKEY_CTX *ctx),
626 int (*derive) (EVP_PKEY_CTX *ctx,
630 pmeth->derive_init = derive_init;
631 pmeth->derive = derive;
634 void EVP_PKEY_meth_set_ctrl(EVP_PKEY_METHOD *pmeth,
635 int (*ctrl) (EVP_PKEY_CTX *ctx, int type, int p1,
637 int (*ctrl_str) (EVP_PKEY_CTX *ctx,
642 pmeth->ctrl_str = ctrl_str;
645 void EVP_PKEY_meth_set_check(EVP_PKEY_METHOD *pmeth,
646 int (*check) (EVP_PKEY *pkey))
648 pmeth->check = check;
651 void EVP_PKEY_meth_set_public_check(EVP_PKEY_METHOD *pmeth,
652 int (*check) (EVP_PKEY *pkey))
654 pmeth->public_check = check;
657 void EVP_PKEY_meth_set_param_check(EVP_PKEY_METHOD *pmeth,
658 int (*check) (EVP_PKEY *pkey))
660 pmeth->param_check = check;
663 void EVP_PKEY_meth_set_digest_custom(EVP_PKEY_METHOD *pmeth,
664 int (*digest_custom) (EVP_PKEY_CTX *ctx,
667 pmeth->digest_custom = digest_custom;
670 void EVP_PKEY_meth_get_init(const EVP_PKEY_METHOD *pmeth,
671 int (**pinit) (EVP_PKEY_CTX *ctx))
673 *pinit = pmeth->init;
676 void EVP_PKEY_meth_get_copy(const EVP_PKEY_METHOD *pmeth,
677 int (**pcopy) (EVP_PKEY_CTX *dst,
680 *pcopy = pmeth->copy;
683 void EVP_PKEY_meth_get_cleanup(const EVP_PKEY_METHOD *pmeth,
684 void (**pcleanup) (EVP_PKEY_CTX *ctx))
686 *pcleanup = pmeth->cleanup;
689 void EVP_PKEY_meth_get_paramgen(const EVP_PKEY_METHOD *pmeth,
690 int (**pparamgen_init) (EVP_PKEY_CTX *ctx),
691 int (**pparamgen) (EVP_PKEY_CTX *ctx,
695 *pparamgen_init = pmeth->paramgen_init;
697 *pparamgen = pmeth->paramgen;
700 void EVP_PKEY_meth_get_keygen(const EVP_PKEY_METHOD *pmeth,
701 int (**pkeygen_init) (EVP_PKEY_CTX *ctx),
702 int (**pkeygen) (EVP_PKEY_CTX *ctx,
706 *pkeygen_init = pmeth->keygen_init;
708 *pkeygen = pmeth->keygen;
711 void EVP_PKEY_meth_get_sign(const EVP_PKEY_METHOD *pmeth,
712 int (**psign_init) (EVP_PKEY_CTX *ctx),
713 int (**psign) (EVP_PKEY_CTX *ctx,
714 unsigned char *sig, size_t *siglen,
715 const unsigned char *tbs,
719 *psign_init = pmeth->sign_init;
721 *psign = pmeth->sign;
724 void EVP_PKEY_meth_get_verify(const EVP_PKEY_METHOD *pmeth,
725 int (**pverify_init) (EVP_PKEY_CTX *ctx),
726 int (**pverify) (EVP_PKEY_CTX *ctx,
727 const unsigned char *sig,
729 const unsigned char *tbs,
733 *pverify_init = pmeth->verify_init;
735 *pverify = pmeth->verify;
738 void EVP_PKEY_meth_get_verify_recover(const EVP_PKEY_METHOD *pmeth,
739 int (**pverify_recover_init) (EVP_PKEY_CTX
741 int (**pverify_recover) (EVP_PKEY_CTX
750 if (pverify_recover_init)
751 *pverify_recover_init = pmeth->verify_recover_init;
753 *pverify_recover = pmeth->verify_recover;
756 void EVP_PKEY_meth_get_signctx(const EVP_PKEY_METHOD *pmeth,
757 int (**psignctx_init) (EVP_PKEY_CTX *ctx,
759 int (**psignctx) (EVP_PKEY_CTX *ctx,
765 *psignctx_init = pmeth->signctx_init;
767 *psignctx = pmeth->signctx;
770 void EVP_PKEY_meth_get_verifyctx(const EVP_PKEY_METHOD *pmeth,
771 int (**pverifyctx_init) (EVP_PKEY_CTX *ctx,
773 int (**pverifyctx) (EVP_PKEY_CTX *ctx,
774 const unsigned char *sig,
779 *pverifyctx_init = pmeth->verifyctx_init;
781 *pverifyctx = pmeth->verifyctx;
784 void EVP_PKEY_meth_get_encrypt(const EVP_PKEY_METHOD *pmeth,
785 int (**pencrypt_init) (EVP_PKEY_CTX *ctx),
786 int (**pencryptfn) (EVP_PKEY_CTX *ctx,
789 const unsigned char *in,
793 *pencrypt_init = pmeth->encrypt_init;
795 *pencryptfn = pmeth->encrypt;
798 void EVP_PKEY_meth_get_decrypt(const EVP_PKEY_METHOD *pmeth,
799 int (**pdecrypt_init) (EVP_PKEY_CTX *ctx),
800 int (**pdecrypt) (EVP_PKEY_CTX *ctx,
803 const unsigned char *in,
807 *pdecrypt_init = pmeth->decrypt_init;
809 *pdecrypt = pmeth->decrypt;
812 void EVP_PKEY_meth_get_derive(const EVP_PKEY_METHOD *pmeth,
813 int (**pderive_init) (EVP_PKEY_CTX *ctx),
814 int (**pderive) (EVP_PKEY_CTX *ctx,
819 *pderive_init = pmeth->derive_init;
821 *pderive = pmeth->derive;
824 void EVP_PKEY_meth_get_ctrl(const EVP_PKEY_METHOD *pmeth,
825 int (**pctrl) (EVP_PKEY_CTX *ctx, int type, int p1,
827 int (**pctrl_str) (EVP_PKEY_CTX *ctx,
832 *pctrl = pmeth->ctrl;
834 *pctrl_str = pmeth->ctrl_str;
837 void EVP_PKEY_meth_get_check(const EVP_PKEY_METHOD *pmeth,
838 int (**pcheck) (EVP_PKEY *pkey))
841 *pcheck = pmeth->check;
844 void EVP_PKEY_meth_get_public_check(const EVP_PKEY_METHOD *pmeth,
845 int (**pcheck) (EVP_PKEY *pkey))
848 *pcheck = pmeth->public_check;
851 void EVP_PKEY_meth_get_param_check(const EVP_PKEY_METHOD *pmeth,
852 int (**pcheck) (EVP_PKEY *pkey))
855 *pcheck = pmeth->param_check;
858 void EVP_PKEY_meth_get_digest_custom(EVP_PKEY_METHOD *pmeth,
859 int (**pdigest_custom) (EVP_PKEY_CTX *ctx,
862 if (pdigest_custom != NULL)
863 *pdigest_custom = pmeth->digest_custom;