+/* Written by Ben Laurie, 2001 */
/*
- * Copyright (c) 1998-2001 The OpenSSL Project. All rights reserved.
+ * Copyright (c) 2001 The OpenSSL Project. All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
#include "evp_locl.h"
#include <assert.h>
-// longest key supported in hardware
+/* longest key supported in hardware */
#define MAX_HW_KEY 24
+#define MAX_HW_IV 8
static int fd;
static int dev_failed;
+typedef struct session_op session_op;
+
+#define data(ctx) EVP_C_DATA(session_op,ctx)
+
static void err(const char *str)
{
fprintf(stderr,"%s: errno %d\n",str,errno);
}
close(cryptodev_fd);
}
- if(!ctx->c.dev_crypto)
- {
- ctx->c.dev_crypto=OPENSSL_malloc(sizeof *ctx->c.dev_crypto);
- memset(ctx->c.dev_crypto,'\0',sizeof *ctx->c.dev_crypto);
- ctx->c.dev_crypto->key=OPENSSL_malloc(MAX_HW_KEY);
- }
-
+ assert(data(ctx));
+ memset(data(ctx),'\0',sizeof *data(ctx));
+ data(ctx)->key=OPENSSL_malloc(MAX_HW_KEY);
+
return 1;
}
static int dev_crypto_cleanup(EVP_CIPHER_CTX *ctx)
{
- if(ioctl(fd,CIOCFSESSION,ctx->c.dev_crypto->ses) == -1)
+ printf("Cleanup %d\n",data(ctx)->ses);
+ if(ioctl(fd,CIOCFSESSION,&data(ctx)->ses) == -1)
err("CIOCFSESSION failed");
- OPENSSL_free(ctx->c.dev_crypto->key);
- OPENSSL_free(ctx->c.dev_crypto);
- ctx->c.dev_crypto=NULL;
+ OPENSSL_free(data(ctx)->key);
return 1;
}
-// FIXME: there should be some non-fatal way to report we fell back to s/w?
-static int dev_crypto_des_ede3_init_key(EVP_CIPHER_CTX *ctx,
- const unsigned char *key,
- const unsigned char *iv, int enc)
+/* FIXME: there should be some non-fatal way to report we fell back to s/w? */
+static int dev_crypto_init_key(EVP_CIPHER_CTX *ctx,int cipher,
+ const unsigned char *key,int klen)
{
if(!dev_crypto_init(ctx))
- {
- // fall back to using software...
- ctx->cipher=EVP_des_ede3_cbc();
- return ctx->cipher->init(ctx,key,iv,enc);
- }
- memcpy(ctx->c.dev_crypto->key,key,24);
+ return 0;
+
+ assert(ctx->cipher->iv_len <= MAX_HW_IV);
+
+ memcpy(data(ctx)->key,key,klen);
- ctx->c.dev_crypto->cipher=CRYPTO_3DES_CBC;
- ctx->c.dev_crypto->mac=0;
- ctx->c.dev_crypto->keylen=24;
+ data(ctx)->cipher=cipher;
+ data(ctx)->mac=0;
+ data(ctx)->keylen=klen;
- if (ioctl(fd,CIOCGSESSION,ctx->c.dev_crypto) == -1)
+ if (ioctl(fd,CIOCGSESSION,data(ctx)) == -1)
{
err("CIOCGSESSION failed");
- // fall back to using software...
- dev_crypto_cleanup(ctx);
- ctx->cipher=EVP_des_ede3_cbc();
- return ctx->cipher->init(ctx,key,iv,enc);
+ return 0;
}
+ printf("Init %d\n",data(ctx)->ses);
return 1;
}
-static int dev_crypto_des_ede3_cbc_cipher(EVP_CIPHER_CTX *ctx,
- unsigned char *out,
- const unsigned char *in,
- unsigned int inl)
+static int dev_crypto_cipher(EVP_CIPHER_CTX *ctx,unsigned char *out,
+ const unsigned char *in,unsigned int inl)
{
struct crypt_op cryp;
- unsigned char lb[8];
+ unsigned char lb[MAX_HW_IV];
- assert(ctx->c.dev_crypto);
+ assert(data(ctx));
assert(!dev_failed);
memset(&cryp,'\0',sizeof cryp);
- cryp.ses=ctx->c.dev_crypto->ses;
+ cryp.ses=data(ctx)->ses;
cryp.op=ctx->encrypt ? COP_ENCRYPT : COP_DECRYPT;
cryp.flags=0;
- // cryp.len=((inl+7)/8)*8;
cryp.len=inl;
- assert((inl&7) == 0);
+ assert((inl&ctx->cipher->block_size) == 0);
cryp.src=(caddr_t)in;
cryp.dst=(caddr_t)out;
cryp.mac=0;
- cryp.iv=(caddr_t)ctx->iv;
+ if(ctx->cipher->iv_len)
+ cryp.iv=(caddr_t)ctx->iv;
if(!ctx->encrypt)
- memcpy(lb,&in[cryp.len-8],8);
+ memcpy(lb,&in[cryp.len-ctx->cipher->iv_len],ctx->cipher->iv_len);
if (ioctl(fd, CIOCCRYPT, &cryp) == -1)
{
}
if(ctx->encrypt)
- memcpy(ctx->iv,&out[cryp.len-8],8);
+ memcpy(ctx->iv,&out[cryp.len-ctx->cipher->iv_len],ctx->cipher->iv_len);
else
- memcpy(ctx->iv,lb,8);
+ memcpy(ctx->iv,lb,ctx->cipher->iv_len);
return 1;
}
-BLOCK_CIPHER_def_cbc(dev_crypto_des_ede3, des_ede,NID_des_ede3, 8, 24, 8,
+static int dev_crypto_des_ede3_init_key(EVP_CIPHER_CTX *ctx,
+ const unsigned char *key,
+ const unsigned char *iv, int enc)
+ { return dev_crypto_init_key(ctx,CRYPTO_3DES_CBC,key,24); }
+
+#define dev_crypto_des_ede3_cbc_cipher dev_crypto_cipher
+
+BLOCK_CIPHER_def_cbc(dev_crypto_des_ede3, session_op, NID_des_ede3, 8, 24, 8,
0, dev_crypto_des_ede3_init_key,
dev_crypto_cleanup,
EVP_CIPHER_set_asn1_iv,
EVP_CIPHER_get_asn1_iv,
NULL)
+static int dev_crypto_rc4_init_key(EVP_CIPHER_CTX *ctx,
+ const unsigned char *key,
+ const unsigned char *iv, int enc)
+ { return dev_crypto_init_key(ctx,CRYPTO_ARC4,key,16); }
+
+static const EVP_CIPHER r4_cipher=
+ {
+ NID_rc4,
+ 1,16,0, /* FIXME: key should be up to 256 bytes */
+ EVP_CIPH_VARIABLE_LENGTH,
+ dev_crypto_rc4_init_key,
+ dev_crypto_cipher,
+ dev_crypto_cleanup,
+ sizeof(session_op),
+ NULL,
+ NULL,
+ NULL
+ };
+
+const EVP_CIPHER *EVP_dev_crypto_rc4(void)
+ { return &r4_cipher; }
+
+#else
+static void *dummy=&dummy;
#endif