Fix bugs and typos.
[openssl.git] / crypto / ecdsa / ecs_asn1.c
1 /* crypto/ecdsa/ecs_asn1.c */
2 /* ====================================================================
3  * Copyright (c) 2000-2002 The OpenSSL Project.  All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer. 
11  *
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in
14  *    the documentation and/or other materials provided with the
15  *    distribution.
16  *
17  * 3. All advertising materials mentioning features or use of this
18  *    software must display the following acknowledgment:
19  *    "This product includes software developed by the OpenSSL Project
20  *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
21  *
22  * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
23  *    endorse or promote products derived from this software without
24  *    prior written permission. For written permission, please contact
25  *    licensing@OpenSSL.org.
26  *
27  * 5. Products derived from this software may not be called "OpenSSL"
28  *    nor may "OpenSSL" appear in their names without prior written
29  *    permission of the OpenSSL Project.
30  *
31  * 6. Redistributions of any form whatsoever must retain the following
32  *    acknowledgment:
33  *    "This product includes software developed by the OpenSSL Project
34  *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
35  *
36  * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
37  * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
38  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
39  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
40  * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
41  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
42  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
43  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
44  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
45  * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
46  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
47  * OF THE POSSIBILITY OF SUCH DAMAGE.
48  * ====================================================================
49  *
50  * This product includes cryptographic software written by Eric Young
51  * (eay@cryptsoft.com).  This product includes software written by Tim
52  * Hudson (tjh@cryptsoft.com).
53  *
54  */
55
56 #include "cryptlib.h"
57 #include "ecs_locl.h"
58 #include <openssl/asn1.h>
59 #include <openssl/asn1t.h>
60 #include <openssl/objects.h>
61
62 static point_conversion_form_t POINT_CONVERSION_FORM = POINT_CONVERSION_COMPRESSED;
63
64 ASN1_SEQUENCE(ECDSA_SIG) = {
65         ASN1_SIMPLE(ECDSA_SIG, r, CBIGNUM),
66         ASN1_SIMPLE(ECDSA_SIG, s, CBIGNUM)
67 } ASN1_SEQUENCE_END(ECDSA_SIG)
68
69 IMPLEMENT_ASN1_FUNCTIONS_const(ECDSA_SIG)
70
71 ASN1_SEQUENCE(X9_62_FIELDID) = {
72         ASN1_SIMPLE(X9_62_FIELDID, fieldType, ASN1_OBJECT),
73         ASN1_SIMPLE(X9_62_FIELDID, parameters, ASN1_ANY)
74 } ASN1_SEQUENCE_END(X9_62_FIELDID)
75
76 IMPLEMENT_ASN1_FUNCTIONS_const(X9_62_FIELDID)
77
78 ASN1_SEQUENCE(X9_62_CURVE) = {
79         ASN1_SIMPLE(X9_62_CURVE, a, ASN1_OCTET_STRING),
80         ASN1_SIMPLE(X9_62_CURVE, b, ASN1_OCTET_STRING),
81         ASN1_OPT(X9_62_CURVE, seed, ASN1_BIT_STRING)
82 } ASN1_SEQUENCE_END(X9_62_CURVE)
83
84 IMPLEMENT_ASN1_FUNCTIONS_const(X9_62_CURVE)
85
86 ASN1_SEQUENCE(X9_62_EC_PARAMETERS) = {
87         ASN1_OPT(X9_62_EC_PARAMETERS, version, ASN1_INTEGER),
88         ASN1_SIMPLE(X9_62_EC_PARAMETERS, fieldID, X9_62_FIELDID),
89         ASN1_SIMPLE(X9_62_EC_PARAMETERS, curve, X9_62_CURVE),
90         ASN1_SIMPLE(X9_62_EC_PARAMETERS, base, ASN1_OCTET_STRING),
91         ASN1_SIMPLE(X9_62_EC_PARAMETERS, order, ASN1_INTEGER),
92         ASN1_SIMPLE(X9_62_EC_PARAMETERS, cofactor, ASN1_INTEGER)
93 } ASN1_SEQUENCE_END(X9_62_EC_PARAMETERS)
94
95 IMPLEMENT_ASN1_FUNCTIONS_const(X9_62_EC_PARAMETERS)
96
97 ASN1_CHOICE(EC_PARAMETERS) = {
98         ASN1_SIMPLE(EC_PARAMETERS, value.named_curve, ASN1_OBJECT),
99         ASN1_SIMPLE(EC_PARAMETERS, value.parameters, X9_62_EC_PARAMETERS),
100         ASN1_SIMPLE(EC_PARAMETERS, value.implicitlyCA, ASN1_NULL)
101 } ASN1_CHOICE_END(EC_PARAMETERS)
102
103 IMPLEMENT_ASN1_FUNCTIONS_const(EC_PARAMETERS)
104              
105 ASN1_SEQUENCE(ECDSAPrivateKey) = {
106         ASN1_SIMPLE(ECDSAPrivateKey, version, LONG),
107         ASN1_SIMPLE(ECDSAPrivateKey, parameters, EC_PARAMETERS),
108         ASN1_SIMPLE(ECDSAPrivateKey, pub_key, ASN1_OCTET_STRING),
109         ASN1_SIMPLE(ECDSAPrivateKey, priv_key, BIGNUM)
110 } ASN1_SEQUENCE_END(ECDSAPrivateKey)
111
112 IMPLEMENT_ASN1_ALLOC_FUNCTIONS_fname(ECDSAPrivateKey, ECDSAPrivateKey, ECDSAPrivateKey)
113 IMPLEMENT_ASN1_ENCODE_FUNCTIONS_const_fname(ECDSAPrivateKey, ECDSAPrivateKey, ecdsaPrivateKey)
114
115 ASN1_SEQUENCE(ecdsa_pub_internal) = {
116         ASN1_SIMPLE(ECDSAPrivateKey, pub_key, ASN1_OCTET_STRING),
117         ASN1_SIMPLE(ECDSAPrivateKey, parameters, EC_PARAMETERS),
118 } ASN1_SEQUENCE_END_name(ECDSAPrivateKey, ecdsa_pub_internal)
119
120 ASN1_CHOICE(ECDSAPublicKey) = {
121         ASN1_SIMPLE(ECDSAPrivateKey, pub_key, ASN1_OCTET_STRING),
122         ASN1_EX_COMBINE(0, 0, ecdsa_pub_internal)
123 } ASN1_CHOICE_END_selector(ECDSAPrivateKey, ECDSAPublicKey, write_params)
124
125 IMPLEMENT_ASN1_ENCODE_FUNCTIONS_const_fname(ECDSAPrivateKey, ECDSAPublicKey, ecdsaPublicKey)
126
127
128 X9_62_FIELDID   *ECDSA_get_X9_62_FIELDID(const ECDSA *ecdsa, X9_62_FIELDID *field)
129 {
130         /* TODO : characteristic two */
131         int     ok=0, reason=ERR_R_ASN1_LIB;
132         X9_62_FIELDID *ret=NULL;
133         BIGNUM  *tmp=NULL;
134         
135         if (!ecdsa || !ecdsa->group)
136                 OPENSSL_ECDSA_ABORT(ECDSA_R_MISSING_PARAMETERS)
137         if (field == NULL)
138         {
139                 if ((ret = X9_62_FIELDID_new()) == NULL) return NULL;
140         }
141         else
142         {       
143                 ret = field;
144                 if (ret->fieldType != NULL)     ASN1_OBJECT_free(ret->fieldType);
145                 if (ret->parameters != NULL)    ASN1_TYPE_free(ret->parameters);
146         }
147         if ((tmp = BN_new()) == NULL) 
148                 OPENSSL_ECDSA_ABORT(ERR_R_BN_LIB)
149         if ((ret->fieldType = OBJ_nid2obj(NID_X9_62_prime_field)) == NULL)
150                 OPENSSL_ECDSA_ABORT(ERR_R_OBJ_LIB)
151         if ((ret->parameters = ASN1_TYPE_new()) == NULL) goto err;
152         ret->parameters->type = V_ASN1_INTEGER;
153         if (!EC_GROUP_get_curve_GFp(ecdsa->group, tmp, NULL, NULL, NULL))
154                 OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
155         if ((ret->parameters->value.integer = BN_to_ASN1_INTEGER(tmp, NULL)) == NULL) goto err;
156         ok = 1;
157 err :   if (!ok)
158         {
159                 if (ret && !field) X9_62_FIELDID_free(ret);
160                 ret = NULL;
161                 ECDSAerr(ECDSA_F_ECDSA_GET_X9_62_FIELDID, reason);
162         }
163         if (tmp) BN_free(tmp);
164         return(ret);
165 }
166
167 X9_62_CURVE   *ECDSA_get_X9_62_CURVE(const ECDSA *ecdsa, X9_62_CURVE *curve)
168 {
169         int     ok=0, reason=ERR_R_BN_LIB, len1=0, len2=0;
170         X9_62_CURVE *ret=NULL;
171         BIGNUM      *tmp1=NULL, *tmp2=NULL;
172         unsigned char *buffer=NULL;
173         unsigned char char_buf = 0;
174
175         if (!ecdsa || !ecdsa->group)
176                 OPENSSL_ECDSA_ABORT(ECDSA_R_MISSING_PARAMETERS)
177         if ((tmp1 = BN_new()) == NULL || (tmp2 = BN_new()) == NULL) goto err;
178         if (curve == NULL)
179         {
180                 if ((ret = X9_62_CURVE_new()) == NULL)
181                         OPENSSL_ECDSA_ABORT(ECDSA_R_X9_62_CURVE_NEW_FAILURE)
182         }
183         else
184         {
185                 ret = curve;
186                 if (ret->a)     ASN1_OCTET_STRING_free(ret->a);
187                 if (ret->b)     ASN1_OCTET_STRING_free(ret->b);
188                 if (ret->seed)  ASN1_BIT_STRING_free(ret->seed);
189         }
190         if (!EC_GROUP_get_curve_GFp(ecdsa->group, NULL, tmp1, tmp2, NULL))
191                 OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
192
193         if ((ret->a = M_ASN1_OCTET_STRING_new()) == NULL || 
194             (ret->b = M_ASN1_OCTET_STRING_new()) == NULL )
195                 OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
196
197         len1 = BN_num_bytes(tmp1);
198         len2 = BN_num_bytes(tmp2);
199
200         if ((buffer = OPENSSL_malloc(len1 > len2 ? len1 : len2)) == NULL)
201                 OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE)
202
203         if (len1 == 0) /* => a == 0 */
204         {
205                 if (!M_ASN1_OCTET_STRING_set(ret->a, char_buf, 1))
206                         OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
207         }
208         else
209         {
210                 if ((len1 = BN_bn2bin(tmp1, buffer)) == 0) goto err;
211                 if (!M_ASN1_OCTET_STRING_set(ret->a, buffer, len1))
212                         OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
213         }
214         if (len2 == 0) /* => b == 0 */
215         {
216                 if (!M_ASN1_OCTET_STRING_set(ret->a, char_buf, 1))
217                         OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
218         }
219         else
220         {
221                 if ((len2 = BN_bn2bin(tmp2, buffer)) == 0) goto err;
222                 if (!M_ASN1_OCTET_STRING_set(ret->b, buffer, len2))
223                         OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
224         }
225
226         if (ecdsa->seed)
227         {       
228                 if ((ret->seed = ASN1_BIT_STRING_new()) == NULL) goto err;
229                 if (!ASN1_BIT_STRING_set(ret->seed, ecdsa->seed, (int)ecdsa->seed_len))
230                         OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
231         }
232         else
233                 ret->seed = NULL;
234
235         ok = 1;
236 err :   if (!ok)
237         {
238                 if (ret && !curve) X9_62_CURVE_free(ret);
239                 ret = NULL;
240                 ECDSAerr(ECDSA_F_ECDSA_GET_X9_62_CURVE, reason);
241         }
242         if (buffer) OPENSSL_free(buffer);
243         if (tmp1)   BN_free(tmp1);
244         if (tmp2)   BN_free(tmp2);
245         return(ret);
246 }
247
248 X9_62_EC_PARAMETERS *ECDSA_get_X9_62_EC_PARAMETERS(const ECDSA *ecdsa, X9_62_EC_PARAMETERS *param)
249 {
250         int     ok=0, reason=ERR_R_ASN1_LIB;
251         size_t  len=0;
252         X9_62_EC_PARAMETERS *ret=NULL;
253         BIGNUM        *tmp=NULL;
254         unsigned char *buffer=NULL;
255         EC_POINT      *point=NULL;
256
257         if (!ecdsa || !ecdsa->group)
258                 OPENSSL_ECDSA_ABORT(ECDSA_R_MISSING_PARAMETERS)
259         if ((tmp = BN_new()) == NULL)
260                 OPENSSL_ECDSA_ABORT(ERR_R_BN_LIB)
261         if (param == NULL)
262         {
263                 if ((ret = X9_62_EC_PARAMETERS_new()) == NULL)
264                         OPENSSL_ECDSA_ABORT(ECDSA_R_X9_62_EC_PARAMETERS_NEW_FAILURE)
265         }
266         else
267                 ret = param;
268         if (ecdsa->version == 1)
269                 ret->version = NULL;
270         else
271         {
272                 if (ret->version == NULL && (ret->version = ASN1_INTEGER_new()) == NULL)
273                         OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE)
274                 if (!ASN1_INTEGER_set(ret->version, (long)ecdsa->version)) goto err;
275         }
276         if ((ret->fieldID = ECDSA_get_X9_62_FIELDID(ecdsa, ret->fieldID)) == NULL)
277                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSA_GET_X9_62_FIELDID_FAILURE)
278         if ((ret->curve = ECDSA_get_X9_62_CURVE(ecdsa, ret->curve)) == NULL)
279                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSA_GET_X9_62_CURVE_FAILURE)
280         if ((point = EC_GROUP_get0_generator(ecdsa->group)) == NULL)
281                 OPENSSL_ECDSA_ABORT(ECDSA_R_CAN_NOT_GET_GENERATOR)
282         if (!(len = EC_POINT_point2oct(ecdsa->group, point, POINT_CONVERSION_COMPRESSED, NULL, len, NULL)))
283                 OPENSSL_ECDSA_ABORT(ECDSA_R_UNEXPECTED_PARAMETER_LENGTH)
284         if ((buffer = OPENSSL_malloc(len)) == NULL)
285                 OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE)
286         if (!EC_POINT_point2oct(ecdsa->group, point, POINT_CONVERSION_COMPRESSED, buffer, len, NULL)) 
287                 OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
288         if (ret->base == NULL && (ret->base = ASN1_OCTET_STRING_new()) == NULL)
289                 OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE)
290         if (!ASN1_OCTET_STRING_set(ret->base, buffer, len)) goto err;
291         if (!EC_GROUP_get_order(ecdsa->group, tmp, NULL))
292                 OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
293         if ((ret->order = BN_to_ASN1_INTEGER(tmp, ret->order)) == NULL) goto err;
294         if (!EC_GROUP_get_cofactor(ecdsa->group, tmp, NULL))
295                 OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
296         if ((ret->cofactor = BN_to_ASN1_INTEGER(tmp, ret->cofactor)) == NULL) goto err;
297         ok = 1;
298
299 err :   if(!ok)
300         {
301                 ECDSAerr(ECDSA_F_ECDSA_GET_X9_62_EC_PARAMETERS, reason);
302                 if (ret && !param) X9_62_EC_PARAMETERS_free(ret);
303                 ret = NULL;
304         }
305         if (tmp)    BN_free(tmp);
306         if (buffer) OPENSSL_free(buffer);
307         return(ret);
308 }
309
310 EC_PARAMETERS *ECDSA_get_EC_PARAMETERS(const ECDSA *ecdsa, EC_PARAMETERS *params)
311 {
312         int ok = 1;
313         int tmp = 0;
314         EC_PARAMETERS *ret = params;
315         if (ret == NULL)
316                 if ((ret = EC_PARAMETERS_new()) == NULL)
317                 {
318                         ECDSAerr(ECDSA_F_ECDSA_GET_EC_PARAMETERS, ERR_R_MALLOC_FAILURE);
319                         return NULL;
320                 }
321         if (ecdsa == NULL)
322         {       /* missing parameter */
323                 ECDSAerr(ECDSA_F_ECDSA_GET_EC_PARAMETERS, ECDSA_R_MISSING_PARAMETERS);
324                 EC_PARAMETERS_free(params);
325                 return NULL;
326         }
327         if (ecdsa->parameter_flags & ECDSA_FLAG_NAMED_CURVE)
328         {       /* use a named curve */
329                 tmp = EC_GROUP_get_nid(ecdsa->group);
330                 if (tmp)
331                 {
332                         ret->type = 0;
333                         if ((ret->value.named_curve = OBJ_nid2obj(tmp)) == NULL)
334                                 ok = 0;
335                 }
336                 else
337                 {
338                         /* use the x9_64 ec_parameters structure */
339                         ret->type = 1;
340                         if ((ret->value.parameters = ECDSA_get_X9_62_EC_PARAMETERS(ecdsa, NULL)) == NULL)
341                                 ok = 0;
342                 }
343         }
344         else if (ecdsa->parameter_flags & ECDSA_FLAG_IMPLICITLYCA)
345         {       /* use implicitlyCA */
346                 ret->type = 2;
347                 if ((ret->value.implicitlyCA = ASN1_NULL_new()) == NULL)
348                         ok = 0;
349         }
350         else
351         {       /* use the x9_64 ec_parameters structure */
352                 ret->type = 1;
353                 if ((ret->value.parameters = ECDSA_get_X9_62_EC_PARAMETERS(ecdsa, NULL)) == NULL)
354                         ok = 0;
355         }
356         if (!ok)
357         {
358                 EC_PARAMETERS_free(ret);
359                 return NULL;
360         }
361                 return ret;
362 }
363
364 ECDSA         *ECDSA_x9_62parameters2ecdsa(const X9_62_EC_PARAMETERS *params, ECDSA *ecdsa)
365 {
366         int       ok=0, reason=ERR_R_EC_LIB, tmp;
367         ECDSA     *ret=NULL;
368         const EC_METHOD *meth=NULL;
369         BIGNUM    *tmp_1=NULL, *tmp_2=NULL, *tmp_3=NULL;
370         EC_POINT  *point=NULL;
371
372         if (!params) 
373                 OPENSSL_ECDSA_ABORT(ECDSA_R_MISSING_PARAMETERS)
374         if (ecdsa == NULL)
375         {
376                 if ((ret = ECDSA_new()) == NULL) 
377                         OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSA_NEW_FAILURE)
378         }
379         else
380         {
381                 if (ecdsa->group)       EC_GROUP_free(ecdsa->group);
382                 if (ecdsa->pub_key)     EC_POINT_free(ecdsa->pub_key);
383                 ecdsa->pub_key = NULL;
384                 if (ecdsa->priv_key)    BN_clear_free(ecdsa->priv_key);
385                 ecdsa->priv_key = NULL;
386                 if (ecdsa->seed)        OPENSSL_free(ecdsa->seed);
387                 ecdsa->seed = NULL;
388                 if (ecdsa->kinv)        
389                 {
390                         BN_clear_free(ecdsa->kinv);
391                         ecdsa->kinv = NULL;
392                 }
393                 if (ecdsa->r)
394                 {
395                         BN_clear_free(ecdsa->r);
396                         ecdsa->r = NULL;
397                 }
398                 ret = ecdsa;
399         }
400         /* TODO : characteristic two */
401         if (!params->fieldID || !params->fieldID->fieldType || !params->fieldID->parameters)
402                 OPENSSL_ECDSA_ABORT(ECDSA_R_NO_FIELD_SPECIFIED)
403         tmp = OBJ_obj2nid(params->fieldID->fieldType); 
404         if (tmp == NID_X9_62_characteristic_two_field)
405         {
406                 OPENSSL_ECDSA_ABORT(ECDSA_R_NOT_SUPPORTED)
407         }
408         else if (tmp == NID_X9_62_prime_field)
409         {
410                 /* TODO : optimal method for the curve */
411                 meth = EC_GFp_mont_method();
412                 if ((ret->group = EC_GROUP_new(meth)) == NULL) goto err;
413                 if (params->fieldID->parameters->type != V_ASN1_INTEGER)
414                         OPENSSL_ECDSA_ABORT(ECDSA_R_UNEXPECTED_ASN1_TYPE)
415                 if (!params->fieldID->parameters->value.integer)
416                         OPENSSL_ECDSA_ABORT(ECDSA_R_PRIME_MISSING)
417                 if ((tmp_1 = ASN1_INTEGER_to_BN(params->fieldID->parameters->value.integer, NULL)) == NULL)
418                         OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
419                 if (!params->curve)
420                         OPENSSL_ECDSA_ABORT(ECDSA_R_NO_CURVE_SPECIFIED)
421                 if (!params->curve->a || !params->curve->a->data)
422                         OPENSSL_ECDSA_ABORT(ECDSA_R_NO_CURVE_PARAMETER_A_SPECIFIED)
423                 if ((tmp_2 = BN_bin2bn(params->curve->a->data, params->curve->a->length, NULL)) == NULL)
424                         OPENSSL_ECDSA_ABORT(ERR_R_BN_LIB)
425                 if (!params->curve->b || !params->curve->b->data)
426                         OPENSSL_ECDSA_ABORT(ECDSA_R_NO_CURVE_PARAMETER_B_SPECIFIED)
427                 if ((tmp_3 = BN_bin2bn(params->curve->b->data, params->curve->b->length, NULL)) == NULL)
428                         OPENSSL_ECDSA_ABORT(ERR_R_BN_LIB)
429                 if (!EC_GROUP_set_curve_GFp(ret->group, tmp_1, tmp_2, tmp_3, NULL)) goto err;
430                 if ((point = EC_POINT_new(ret->group)) == NULL) goto err;
431         }
432         else OPENSSL_ECDSA_ABORT(ECDSA_R_WRONG_FIELD_IDENTIFIER)
433         if (params->curve->seed != NULL)
434         {
435                 if (ret->seed != NULL)
436                         OPENSSL_free(ret->seed);
437                 if ((ret->seed = OPENSSL_malloc(params->curve->seed->length)) == NULL)
438                         OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE)
439                 memcpy(ret->seed, params->curve->seed->data, params->curve->seed->length);
440                 ret->seed_len = params->curve->seed->length;
441         }
442         if (params->version)
443         {
444                 if ((ret->version = (int)ASN1_INTEGER_get(params->version)) < 0)
445                         OPENSSL_ECDSA_ABORT(ECDSA_R_UNEXPECTED_VERSION_NUMER)
446         }
447         else
448                 ret->version  = 1;
449         if (params->order && params->cofactor && params->base && params->base->data)
450         {
451                 if ((tmp_1 = ASN1_INTEGER_to_BN(params->order, tmp_1)) == NULL)
452                         OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
453                 if ((tmp_2 = ASN1_INTEGER_to_BN(params->cofactor, tmp_2)) == NULL)
454                         OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
455                 if (!EC_POINT_oct2point(ret->group, point, params->base->data, 
456                                 params->base->length, NULL)) goto err;
457                 if (!EC_GROUP_set_generator(ret->group, point, tmp_1, tmp_2)) goto err;
458         }
459         ok = 1;
460
461 err:    if (!ok)
462         {
463                 ECDSAerr(ECDSA_F_ECDSA_GET, reason);
464                 if (ret && !ecdsa) ECDSA_free(ret);
465                 ret = NULL;
466         }
467         if (tmp_1)      BN_free(tmp_1);
468         if (tmp_2)      BN_free(tmp_2);
469         if (tmp_3)      BN_free(tmp_3);
470         if (point)      EC_POINT_free(point);
471         return(ret);
472 }
473
474 ECDSA *ECDSA_ecparameters2ecdsa(const EC_PARAMETERS *params, ECDSA *ecdsa)
475 {
476         ECDSA *ret = ecdsa;
477         int tmp = 0;
478         if (ret == NULL)
479                 if ((ret = ECDSA_new()) == NULL)
480                 {
481                         ECDSAerr(ECDSA_F_ECDSA_GET_ECDSA, ERR_R_MALLOC_FAILURE);
482                         return NULL;
483                 }
484         if (params == NULL)
485         {
486                 ECDSAerr(ECDSA_F_ECDSA_GET_ECDSA, ECDSA_R_MISSING_PARAMETERS);
487                 ECDSA_free(ret);
488                 return NULL;
489         }
490         if (params->type == 0)
491         {
492                 if (ret->group)
493                         EC_GROUP_free(ret->group);
494                 tmp = OBJ_obj2nid(params->value.named_curve);
495                 ret->parameter_flags |= ECDSA_FLAG_NAMED_CURVE;
496                 if ((ret->group = EC_GROUP_new_by_name(tmp)) == NULL)
497                 {
498                         ECDSAerr(ECDSA_F_ECDSA_GET_ECDSA, ECDSA_R_EC_GROUP_NID2CURVE_FAILURE);
499                         ECDSA_free(ret);
500                         return NULL;
501                 }
502         }
503         else if (params->type == 1)
504         {
505                 ret = ECDSA_x9_62parameters2ecdsa(params->value.parameters, ret);
506         }
507         else if (params->type == 2)
508         {
509                 if (ret->group)
510                         EC_GROUP_free(ret->group);
511                 ret->group = NULL;
512                 ret->parameter_flags |= ECDSA_FLAG_IMPLICITLYCA;                
513         }
514         else
515         {
516                 ECDSAerr(ECDSA_F_ECDSA_GET_ECDSA, ECDSA_R_UNKNOWN_PARAMETERS_TYPE);
517                 ECDSA_free(ret);
518                 ret = NULL;
519         }
520         return ret;
521 }
522
523 ECDSA   *d2i_ECDSAParameters(ECDSA **a, const unsigned char **in, long len)
524 {
525         ECDSA           *ecdsa = (a && *a)? *a : NULL;
526         EC_PARAMETERS   *params = NULL;
527
528         if ((params = d2i_EC_PARAMETERS(NULL, in, len)) == NULL)
529         {
530                 ECDSAerr(ECDSA_F_D2I_ECDSAPARAMETERS, ECDSA_R_D2I_EC_PARAMETERS_FAILURE);
531                 EC_PARAMETERS_free(params);
532                 return NULL;
533         }
534         if ((ecdsa = ECDSA_ecparameters2ecdsa(params, ecdsa)) == NULL)
535         {
536                 ECDSAerr(ECDSA_F_D2I_ECDSAPARAMETERS, ECDSA_R_ECPARAMETERS2ECDSA_FAILURE);
537                 return NULL; 
538         }
539         EC_PARAMETERS_free(params);
540         return(ecdsa);  
541 }
542
543 int     i2d_ECDSAParameters(ECDSA *a, unsigned char **out)
544 {
545         int             ret=0;
546         EC_PARAMETERS   *tmp = ECDSA_get_EC_PARAMETERS(a, NULL);
547         if (tmp == NULL)
548         {
549                 ECDSAerr(ECDSA_F_I2D_ECDSAPARAMETERS, ECDSA_R_ECDSA_GET_EC_PARAMETERS_FAILURE);
550                 return 0;
551         }
552         if ((ret = i2d_EC_PARAMETERS(tmp, out)) == 0)
553         {
554                 ECDSAerr(ECDSA_F_I2D_ECDSAPARAMETERS, ECDSA_R_ECDSA_R_D2I_EC_PARAMETERS_FAILURE);
555                 EC_PARAMETERS_free(tmp);
556                 return 0;
557         }       
558         EC_PARAMETERS_free(tmp);
559         return(ret);
560 }
561
562 ECDSA   *d2i_ECDSAPrivateKey(ECDSA **a, const unsigned char **in, long len)
563 {
564         int reason=ERR_R_BN_LIB, ok=0;
565         ECDSA *ret=NULL;
566         ECDSAPrivateKey *priv_key=NULL;
567
568         if ((priv_key = ECDSAPrivateKey_new()) == NULL)
569                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSAPRIVATEKEY_NEW_FAILURE)
570         if ((priv_key = d2i_ecdsaPrivateKey(&priv_key, in, len)) == NULL)
571                 OPENSSL_ECDSA_ABORT(ECDSA_R_D2I_ECDSA_PRIVATEKEY_FAILURE)
572         if ((ret = ECDSA_ecparameters2ecdsa(priv_key->parameters, NULL)) == NULL)
573                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSA_GET_FAILURE)
574         ret->version = priv_key->version;
575         ret->write_params = priv_key->write_params;
576         if (priv_key->priv_key)
577         {
578                 if ((ret->priv_key = BN_dup(priv_key->priv_key)) == NULL)
579                         OPENSSL_ECDSA_ABORT(ERR_R_BN_LIB)
580         }
581         else
582                 OPENSSL_ECDSA_ABORT(ECDSA_R_D2I_ECDSAPRIVATEKEY_MISSING_PRIVATE_KEY)
583         if ((ret->pub_key = EC_POINT_new(ret->group)) == NULL)
584                 OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
585         if (!EC_POINT_oct2point(ret->group, ret->pub_key, priv_key->pub_key->data, priv_key->pub_key->length, NULL))
586                 OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
587         ok = 1;
588 err :   if (!ok)
589         {
590                 if (ret) ECDSA_free(ret);
591                 ret = NULL;
592                 ECDSAerr(ECDSA_F_D2I_ECDSAPRIVATEKEY, reason);
593         }
594         if (priv_key)   ECDSAPrivateKey_free(priv_key);
595         return(ret);
596 }
597
598 int     i2d_ECDSAPrivateKey(ECDSA *a, unsigned char **out)
599 {
600         int ret=0, ok=0, reason=ERR_R_EC_LIB;
601         unsigned char   *buffer=NULL;
602         size_t          buf_len=0;
603         ECDSAPrivateKey *priv_key=NULL;
604
605         if (a == NULL || a->group == NULL)
606                 OPENSSL_ECDSA_ABORT(ECDSA_R_MISSING_PARAMETERS)
607         if ((priv_key = ECDSAPrivateKey_new()) == NULL)
608                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSAPRIVATEKEY_NEW_FAILURE)
609         if ((priv_key->parameters = ECDSA_get_EC_PARAMETERS(a, priv_key->parameters)) == NULL)
610                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSA_GET_X9_62_EC_PARAMETERS_FAILURE)
611         priv_key->version      = a->version;
612         if (BN_copy(priv_key->priv_key, a->priv_key) == NULL)
613                 OPENSSL_ECDSA_ABORT(ERR_R_BN_LIB)
614         buf_len = EC_POINT_point2oct(a->group, a->pub_key, POINT_CONVERSION_COMPRESSED, NULL, 0, NULL);
615         if ((buffer = OPENSSL_malloc(buf_len)) == NULL)
616                 OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE)
617         if (!EC_POINT_point2oct(a->group, a->pub_key, POINT_CONVERSION_COMPRESSED,
618                                 buffer, buf_len, NULL)) goto err;
619         if (!M_ASN1_OCTET_STRING_set(priv_key->pub_key, buffer, buf_len))
620                 OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
621         if ((ret = i2d_ecdsaPrivateKey(priv_key, out)) == 0)
622                 OPENSSL_ECDSA_ABORT(ECDSA_R_I2D_ECDSA_PRIVATEKEY)
623         ok=1;
624         
625 err:    if (!ok)
626                 ECDSAerr(ECDSA_F_I2D_ECDSAPRIVATEKEY, reason);
627         if (buffer)   OPENSSL_free(buffer);
628         if (priv_key) ECDSAPrivateKey_free(priv_key);   
629         return(ok?ret:0);
630 }
631
632
633 ECDSA   *d2i_ECDSAPublicKey(ECDSA **a, const unsigned char **in, long len)
634 {
635         int reason=ERR_R_BN_LIB, ok=0, ecdsa_new=1;
636         ECDSA *ret=NULL;
637         ECDSAPrivateKey *priv_key=NULL;
638
639         if (a && *a)
640         {
641                 ecdsa_new = 0;
642                 ret = *a;
643         }
644         else if ((ret = ECDSA_new()) == NULL)
645                 OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE); 
646         if ((priv_key = ECDSAPrivateKey_new()) == NULL)
647                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSAPRIVATEKEY_NEW_FAILURE)
648         if ((priv_key = d2i_ecdsaPublicKey(&priv_key, in, len)) == NULL)
649                 OPENSSL_ECDSA_ABORT(ECDSA_R_D2I_ECDSA_PRIVATEKEY_FAILURE)
650         if (priv_key->write_params == 0)
651         {
652                 if (ecdsa_new || !ret->group)
653                         OPENSSL_ECDSA_ABORT(ECDSA_R_MISSING_PARAMETERS)
654                 if (ret->pub_key == NULL && (ret->pub_key = EC_POINT_new(ret->group)) == NULL)
655                         OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE)
656                 if (!EC_POINT_oct2point(ret->group, ret->pub_key, priv_key->pub_key->data,
657                                         priv_key->pub_key->length, NULL))
658                         OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
659         }
660         else if (priv_key->write_params == 1)
661         {
662                 if ((ret = ECDSA_ecparameters2ecdsa(priv_key->parameters, ret)) == NULL)
663                         OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSA_GET_FAILURE)
664                 if (ret->pub_key == NULL && (ret->pub_key = EC_POINT_new(ret->group)) == NULL)
665                         OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
666                 if (!EC_POINT_oct2point(ret->group, ret->pub_key, priv_key->pub_key->data, 
667                                 priv_key->pub_key->length, NULL))
668                         OPENSSL_ECDSA_ABORT(ERR_R_EC_LIB)
669         }
670         else    OPENSSL_ECDSA_ABORT(ECDSA_R_UNEXPECTED_PARAMETER)
671         ret->write_params = 1;
672         ok = 1;
673 err :   if (!ok)
674         {
675                 if (ret && ecdsa_new) ECDSA_free(ret);
676                 ret = NULL;
677                 ECDSAerr(ECDSA_F_D2I_ECDSAPRIVATEKEY, reason);
678         }
679         if (priv_key)   ECDSAPrivateKey_free(priv_key);
680         return(ret);
681 }
682
683 int     i2d_ECDSAPublicKey(ECDSA *a, unsigned char **out)
684 {
685         int     ret=0, reason=ERR_R_EC_LIB, ok=0;
686         unsigned char   *buffer=NULL;
687         size_t          buf_len=0;
688         ECDSAPrivateKey *priv_key=NULL;
689
690         if (a == NULL) 
691                 OPENSSL_ECDSA_ABORT(ECDSA_R_MISSING_PARAMETERS)
692         if ((priv_key = ECDSAPrivateKey_new()) == NULL) 
693                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSAPRIVATEKEY_NEW_FAILURE)
694         if ((priv_key->parameters = ECDSA_get_EC_PARAMETERS(a, priv_key->parameters)) == NULL)
695                 OPENSSL_ECDSA_ABORT(ECDSA_R_ECDSA_GET_X9_62_EC_PARAMETERS_FAILURE)
696         priv_key->version = a->version;
697         priv_key->write_params = a->write_params;
698         buf_len = EC_POINT_point2oct(a->group, a->pub_key, POINT_CONVERSION_FORM, NULL, 0, NULL);
699         if (!buf_len || (buffer = OPENSSL_malloc(buf_len)) == NULL)
700                 OPENSSL_ECDSA_ABORT(ERR_R_MALLOC_FAILURE)
701         if (!EC_POINT_point2oct(a->group, a->pub_key, POINT_CONVERSION_FORM,
702                                 buffer, buf_len, NULL)) goto err;
703         if (!M_ASN1_OCTET_STRING_set(priv_key->pub_key, buffer, buf_len))
704                 OPENSSL_ECDSA_ABORT(ERR_R_ASN1_LIB)
705         if ((ret = i2d_ecdsaPublicKey(priv_key, out)) == 0)
706                 OPENSSL_ECDSA_ABORT(ECDSA_R_I2D_ECDSA_PUBLICKEY)
707         ok = 1;
708
709 err:    if (!ok)
710                 ECDSAerr(ECDSA_F_I2D_ECDSAPUBLICKEY, reason);
711         if (buffer)   OPENSSL_free(buffer);
712         if (priv_key) ECDSAPrivateKey_free(priv_key);
713         return(ok?ret:0);
714 }