- unsigned char **ek, int *ekl, unsigned char *iv, EVP_PKEY **pubk,
- int npubk)
- {
- unsigned char key[EVP_MAX_KEY_LENGTH];
- int ret= -1;
- int i,j,max=0;
- char *s=NULL;
-
- for (i=0; i<npubk; i++)
- {
- if (pubk[i]->type != EVP_PKEY_RSA)
- {
- PEMerr(PEM_F_PEM_SEALINIT,PEM_R_PUBLIC_KEY_NO_RSA);
- goto err;
- }
- j=RSA_size(pubk[i]->pkey.rsa);
- if (j > max) max=j;
- }
- s=(char *)OPENSSL_malloc(max*2);
- if (s == NULL)
- {
- PEMerr(PEM_F_PEM_SEALINIT,ERR_R_MALLOC_FAILURE);
- goto err;
- }
-
- EVP_EncodeInit(&ctx->encode);
-
- EVP_MD_CTX_init(&ctx->md);
- EVP_SignInit(&ctx->md,md_type);
-
- EVP_CIPHER_CTX_init(&ctx->cipher);
- ret=EVP_SealInit(&ctx->cipher,type,ek,ekl,iv,pubk,npubk);
- if (!ret) goto err;
-
- /* base64 encode the keys */
- for (i=0; i<npubk; i++)
- {
- j=EVP_EncodeBlock((unsigned char *)s,ek[i],
- RSA_size(pubk[i]->pkey.rsa));
- ekl[i]=j;
- memcpy(ek[i],s,j+1);
- }
-
- ret=npubk;
-err:
- if (s != NULL) OPENSSL_free(s);
- OPENSSL_cleanse(key,EVP_MAX_KEY_LENGTH);
- return(ret);
- }
+ unsigned char **ek, int *ekl, unsigned char *iv,
+ EVP_PKEY **pubk, int npubk)
+{
+ unsigned char key[EVP_MAX_KEY_LENGTH];
+ int ret = -1;
+ int i, j, max = 0;
+ char *s = NULL;
+
+ for (i = 0; i < npubk; i++) {
+ if (pubk[i]->type != EVP_PKEY_RSA) {
+ PEMerr(PEM_F_PEM_SEALINIT, PEM_R_PUBLIC_KEY_NO_RSA);
+ goto err;
+ }
+ j = RSA_size(pubk[i]->pkey.rsa);
+ if (j > max)
+ max = j;
+ }
+ s = (char *)OPENSSL_malloc(max * 2);
+ if (s == NULL) {
+ PEMerr(PEM_F_PEM_SEALINIT, ERR_R_MALLOC_FAILURE);
+ goto err;
+ }
+
+ EVP_EncodeInit(&ctx->encode);
+
+ EVP_MD_CTX_init(&ctx->md);
+ if (!EVP_SignInit(&ctx->md, md_type))
+ goto err;
+
+ EVP_CIPHER_CTX_init(&ctx->cipher);
+ ret = EVP_SealInit(&ctx->cipher, type, ek, ekl, iv, pubk, npubk);
+ if (ret <= 0)
+ goto err;
+
+ /* base64 encode the keys */
+ for (i = 0; i < npubk; i++) {
+ j = EVP_EncodeBlock((unsigned char *)s, ek[i],
+ RSA_size(pubk[i]->pkey.rsa));
+ ekl[i] = j;
+ memcpy(ek[i], s, j + 1);
+ }
+
+ ret = npubk;
+ err:
+ if (s != NULL)
+ OPENSSL_free(s);
+ OPENSSL_cleanse(key, EVP_MAX_KEY_LENGTH);
+ return (ret);
+}