2 * Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
10 #ifndef OPENSSL_CORE_NAMES_H
11 # define OPENSSL_CORE_NAMES_H
17 /* Well known parameter names that Providers can define */
18 #define OSSL_PROV_PARAM_NAME "name" /* utf8_string */
19 #define OSSL_PROV_PARAM_VERSION "version" /* utf8_string */
20 #define OSSL_PROV_PARAM_BUILDINFO "buildinfo" /* utf8_string */
21 #define OSSL_PROV_PARAM_MODULE_FILENAME "module-filename" /* octet_string */
23 /* Self test callback parameters */
24 #define OSSL_PROV_PARAM_SELF_TEST_PHASE "st-phase" /* utf8_string */
25 #define OSSL_PROV_PARAM_SELF_TEST_TYPE "st-type" /* utf8_string */
26 #define OSSL_PROV_PARAM_SELF_TEST_DESC "st-desc" /* utf8_string */
29 * Algorithm parameters
30 * If "engine" or "properties" are specified, they should always be paired
31 * with the algorithm type.
33 #define OSSL_ALG_PARAM_DIGEST "digest" /* utf8_string */
34 #define OSSL_ALG_PARAM_CIPHER "cipher" /* utf8_string */
35 #define OSSL_ALG_PARAM_MAC "mac" /* utf8_string */
36 #define OSSL_ALG_PARAM_PROPERTIES "properties"/* utf8_string */
38 /* cipher parameters */
39 #define OSSL_CIPHER_PARAM_PADDING "padding" /* uint */
40 #define OSSL_CIPHER_PARAM_MODE "mode" /* uint */
41 #define OSSL_CIPHER_PARAM_BLOCK_SIZE "blocksize" /* size_t */
42 #define OSSL_CIPHER_PARAM_FLAGS "flags" /* ulong */
43 #define OSSL_CIPHER_PARAM_KEYLEN "keylen" /* size_t */
44 #define OSSL_CIPHER_PARAM_IVLEN "ivlen" /* size_t */
45 #define OSSL_CIPHER_PARAM_IV "iv" /* octet_string OR octet_ptr */
46 #define OSSL_CIPHER_PARAM_NUM "num" /* uint */
47 #define OSSL_CIPHER_PARAM_ROUNDS "rounds" /* uint */
48 #define OSSL_CIPHER_PARAM_AEAD_TAG "tag" /* octet_string */
49 #define OSSL_CIPHER_PARAM_AEAD_TLS1_AAD "tlsaad" /* octet_string */
50 #define OSSL_CIPHER_PARAM_AEAD_TLS1_AAD_PAD "tlsaadpad" /* size_t */
51 #define OSSL_CIPHER_PARAM_AEAD_TLS1_IV_FIXED "tlsivfixed" /* octet_string */
52 #define OSSL_CIPHER_PARAM_AEAD_TLS1_GET_IV_GEN "tlsivgen" /* octet_string */
53 #define OSSL_CIPHER_PARAM_AEAD_TLS1_SET_IV_INV "tlsivinv" /* octet_string */
54 #define OSSL_CIPHER_PARAM_AEAD_IVLEN OSSL_CIPHER_PARAM_IVLEN
55 #define OSSL_CIPHER_PARAM_AEAD_TAGLEN "taglen" /* size_t */
56 #define OSSL_CIPHER_PARAM_AEAD_MAC_KEY "mackey" /* octet_string */
57 #define OSSL_CIPHER_PARAM_RANDOM_KEY "randkey" /* octet_string */
58 #define OSSL_CIPHER_PARAM_RC2_KEYBITS "keybits" /* size_t */
59 #define OSSL_CIPHER_PARAM_SPEED "speed" /* uint */
60 /* For passing the AlgorithmIdentifier parameter in DER form */
61 #define OSSL_CIPHER_PARAM_ALG_ID "alg_id_param" /* octet_string */
63 #define OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_SEND_FRAGMENT \
64 "tls1multi_maxsndfrag" /* uint */
65 #define OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_BUFSIZE \
66 "tls1multi_maxbufsz" /* size_t */
67 #define OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE \
68 "tls1multi_interleave" /* uint */
69 #define OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD \
70 "tls1multi_aad" /* octet_string */
71 #define OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD_PACKLEN \
72 "tls1multi_aadpacklen" /* uint */
73 #define OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC \
74 "tls1multi_enc" /* octet_string */
75 #define OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_IN \
76 "tls1multi_encin" /* octet_string */
77 #define OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_LEN \
78 "tls1multi_enclen" /* size_t */
80 /* digest parameters */
81 #define OSSL_DIGEST_PARAM_XOFLEN "xoflen" /* size_t */
82 #define OSSL_DIGEST_PARAM_SSL3_MS "ssl3-ms" /* octet string */
83 #define OSSL_DIGEST_PARAM_PAD_TYPE "pad_type" /* uint */
84 #define OSSL_DIGEST_PARAM_MICALG "micalg" /* utf8 string */
85 #define OSSL_DIGEST_PARAM_BLOCK_SIZE "blocksize" /* size_t */
86 #define OSSL_DIGEST_PARAM_SIZE "size" /* size_t */
87 #define OSSL_DIGEST_PARAM_FLAGS "flags" /* ulong */
89 /* Known DIGEST names (not a complete list) */
90 #define OSSL_DIGEST_NAME_MD5 "MD5"
91 #define OSSL_DIGEST_NAME_SHA1 "SHA1"
92 #define OSSL_DIGEST_NAME_SHA2_224 "SHA2-224"
93 #define OSSL_DIGEST_NAME_SHA2_256 "SHA2-256"
94 #define OSSL_DIGEST_NAME_SHA2_384 "SHA2-384"
95 #define OSSL_DIGEST_NAME_SHA2_512 "SHA2-512"
96 #define OSSL_DIGEST_NAME_SHA3_224 "SHA3-224"
97 #define OSSL_DIGEST_NAME_SHA3_256 "SHA3-256"
98 #define OSSL_DIGEST_NAME_SHA3_384 "SHA3-384"
99 #define OSSL_DIGEST_NAME_SHA3_512 "SHA3-512"
100 #define OSSL_DIGEST_NAME_KECCAK_KMAC128 "KECCAK-KMAC-128"
101 #define OSSL_DIGEST_NAME_KECCAK_KMAC256 "KECCAK-KMAC-256"
104 #define OSSL_MAC_PARAM_KEY "key" /* octet string */
105 #define OSSL_MAC_PARAM_IV "iv" /* octet string */
106 #define OSSL_MAC_PARAM_CUSTOM "custom" /* utf8 string */
107 #define OSSL_MAC_PARAM_SALT "salt" /* octet string */
108 #define OSSL_MAC_PARAM_XOF "xof" /* int, 0 or 1 */
109 #define OSSL_MAC_PARAM_FLAGS "flags" /* int */
111 * If "engine" or "properties" are specified, they should always be paired
112 * with "cipher" or "digest".
114 #define OSSL_MAC_PARAM_CIPHER OSSL_ALG_PARAM_CIPHER /* utf8 string */
115 #define OSSL_MAC_PARAM_DIGEST OSSL_ALG_PARAM_DIGEST /* utf8 string */
116 #define OSSL_MAC_PARAM_PROPERTIES OSSL_ALG_PARAM_PROPERTIES /* utf8 string */
117 #define OSSL_MAC_PARAM_SIZE "size" /* size_t */
119 /* Known MAC names (not a complete list) */
120 #define OSSL_MAC_NAME_CMAC "CMAC"
121 #define OSSL_MAC_NAME_HMAC "HMAC"
122 #define OSSL_MAC_NAME_KMAC128 "KMAC128"
123 #define OSSL_MAC_NAME_KMAC256 "KMAC256"
125 /* KDF / PRF parameters */
126 #define OSSL_KDF_PARAM_SECRET "secret" /* octet string */
127 #define OSSL_KDF_PARAM_KEY "key" /* octet string */
128 #define OSSL_KDF_PARAM_SALT "salt" /* octet string */
129 #define OSSL_KDF_PARAM_PASSWORD "pass" /* octet string */
130 #define OSSL_KDF_PARAM_DIGEST OSSL_ALG_PARAM_DIGEST /* utf8 string */
131 #define OSSL_KDF_PARAM_CIPHER OSSL_ALG_PARAM_CIPHER /* utf8 string */
132 #define OSSL_KDF_PARAM_MAC OSSL_ALG_PARAM_MAC /* utf8 string */
133 #define OSSL_KDF_PARAM_MAC_SIZE "maclen" /* size_t */
134 #define OSSL_KDF_PARAM_PROPERTIES OSSL_ALG_PARAM_PROPERTIES /* utf8 string */
135 #define OSSL_KDF_PARAM_ITER "iter" /* unsigned int */
136 #define OSSL_KDF_PARAM_MODE "mode" /* utf8 string or int */
137 #define OSSL_KDF_PARAM_PKCS5 "pkcs5" /* int */
138 #define OSSL_KDF_PARAM_UKM "ukm" /* octet string */
139 #define OSSL_KDF_PARAM_CEK_ALG "cekalg" /* utf8 string */
140 #define OSSL_KDF_PARAM_SCRYPT_N "n" /* uint64_t */
141 #define OSSL_KDF_PARAM_SCRYPT_R "r" /* uint32_t */
142 #define OSSL_KDF_PARAM_SCRYPT_P "p" /* uint32_t */
143 #define OSSL_KDF_PARAM_SCRYPT_MAXMEM "maxmem_bytes" /* uint64_t */
144 #define OSSL_KDF_PARAM_INFO "info" /* octet string */
145 #define OSSL_KDF_PARAM_SEED "seed" /* octet string */
146 #define OSSL_KDF_PARAM_SSHKDF_XCGHASH "xcghash" /* octet string */
147 #define OSSL_KDF_PARAM_SSHKDF_SESSION_ID "session_id" /* octet string */
148 #define OSSL_KDF_PARAM_SSHKDF_TYPE "type" /* int */
149 #define OSSL_KDF_PARAM_SIZE "size" /* size_t */
150 #define OSSL_KDF_PARAM_CIPHER OSSL_ALG_PARAM_CIPHER /* utf8 string */
151 #define OSSL_KDF_PARAM_CONSTANT "constant" /* octet string */
153 /* Known KDF names */
154 #define OSSL_KDF_NAME_HKDF "HKDF"
155 #define OSSL_KDF_NAME_PBKDF2 "PBKDF2"
156 #define OSSL_KDF_NAME_SCRYPT "SCRYPT"
157 #define OSSL_KDF_NAME_SSHKDF "SSHKDF"
158 #define OSSL_KDF_NAME_SSKDF "SSKDF"
159 #define OSSL_KDF_NAME_TLS1_PRF "TLS1-PRF"
160 #define OSSL_KDF_NAME_X942KDF "X942KDF"
161 #define OSSL_KDF_NAME_X963KDF "X963KDF"
162 #define OSSL_KDF_NAME_KBKDF "KBKDF"
163 #define OSSL_KDF_NAME_KRB5KDF "KRB5KDF"
165 /* PKEY parameters */
166 /* Common PKEY parameters */
167 #define OSSL_PKEY_PARAM_BITS "bits" /* integer */
168 #define OSSL_PKEY_PARAM_MAX_SIZE "max-size" /* integer */
169 #define OSSL_PKEY_PARAM_SECURITY_BITS "security-bits" /* integer */
170 #define OSSL_PKEY_PARAM_DIGEST OSSL_ALG_PARAM_DIGEST
171 #define OSSL_PKEY_PARAM_PROPERTIES OSSL_ALG_PARAM_PROPERTIES
172 #define OSSL_PKEY_PARAM_DEFAULT_DIGEST "default-digest" /* utf8 string */
173 #define OSSL_PKEY_PARAM_MANDATORY_DIGEST "mandatory-digest" /* utf8 string */
174 #define OSSL_PKEY_PARAM_PUB_KEY "pub"
175 #define OSSL_PKEY_PARAM_PRIV_KEY "priv"
177 /* Diffie-Hellman/DSA Parameters */
178 #define OSSL_PKEY_PARAM_FFC_P "p"
179 #define OSSL_PKEY_PARAM_FFC_G "g"
180 #define OSSL_PKEY_PARAM_FFC_Q "q"
182 /* Elliptic Curve Domain Parameters */
183 #define OSSL_PKEY_PARAM_EC_NAME "curve-name"
185 /* Elliptic Curve Key Parameters */
186 #define OSSL_PKEY_PARAM_USE_COFACTOR_FLAG "use-cofactor-flag"
187 #define OSSL_PKEY_PARAM_USE_COFACTOR_ECDH \
188 OSSL_PKEY_PARAM_USE_COFACTOR_FLAG
192 * n, e, d are the usual public and private key components
194 * rsa-num is the number of factors, including p and q
195 * rsa-factor is used for each factor: p, q, r_i (i = 3, ...)
196 * rsa-exponent is used for each exponent: dP, dQ, d_i (i = 3, ...)
197 * rsa-coefficient is used for each coefficient: qInv, t_i (i = 3, ...)
199 * The number of rsa-factor items must be equal to the number of rsa-exponent
200 * items, and the number of rsa-coefficients must be one less.
201 * (the base i for the coefficients is 2, not 1, at least as implied by
204 #define OSSL_PKEY_PARAM_RSA_N "n"
205 #define OSSL_PKEY_PARAM_RSA_E "e"
206 #define OSSL_PKEY_PARAM_RSA_D "d"
207 #define OSSL_PKEY_PARAM_RSA_FACTOR "rsa-factor"
208 #define OSSL_PKEY_PARAM_RSA_EXPONENT "rsa-exponent"
209 #define OSSL_PKEY_PARAM_RSA_COEFFICIENT "rsa-coefficient"
211 /* Key Exchange parameters */
213 #define OSSL_EXCHANGE_PARAM_PAD "pad" /* uint */
214 #define OSSL_EXCHANGE_PARAM_EC_ECDH_COFACTOR_MODE "ecdh-cofactor-mode" /* int */
215 #define OSSL_EXCHANGE_PARAM_KDF_TYPE "kdf-type" /* utf8_string */
216 #define OSSL_EXCHANGE_PARAM_KDF_DIGEST "kdf-digest" /* utf8_string */
217 #define OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS "kdf-digest-props" /* utf8_string */
218 #define OSSL_EXCHANGE_PARAM_KDF_OUTLEN "kdf-outlen" /* size_t */
221 * TODO(3.0): improve this pattern
223 * Currently the sole internal user of OSSL_EXCHANGE_PARAM_KDF_UKM is
224 * EVP_PKEY_CTX_{set0,get0}_ecdh_kdf_ukm():
225 * OSSL_EXCHANGE_PARAM_KDF_UKM is handled as a octet_string on set0,
226 * and as an octet_ptr on get0.
228 * This pattern is borrowed from the handling of
229 * OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL in
230 * EVP_PKEY_CTX_{set0,get0}_rsa_oaep_label().
232 #define OSSL_EXCHANGE_PARAM_KDF_UKM "kdf-ukm" /* see note above */
233 #define OSSL_EXCHANGE_PARAM_KDF_UKM_LEN "kdf-ukm-len" /* size_t */
235 /* Signature parameters */
236 #define OSSL_SIGNATURE_PARAM_ALGORITHM_ID "algorithm-id"
237 #define OSSL_SIGNATURE_PARAM_DIGEST OSSL_PKEY_PARAM_DIGEST
238 #define OSSL_SIGNATURE_PARAM_PROPERTIES OSSL_PKEY_PARAM_PROPERTIES
240 /* Asym cipher parameters */
241 #define OSSL_ASYM_CIPHER_PARAM_PAD_MODE "pad-mode"
242 #define OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST OSSL_ALG_PARAM_DIGEST
243 #define OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS "digest-props"
244 #define OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST "mgf1-digest"
245 #define OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS "mgf1-digest-props"
246 #define OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL "oaep-label"
247 #define OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL_LEN "oaep-label-len"
248 #define OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION "tls-client-version"
249 #define OSSL_ASYM_CIPHER_PARAM_TLS_NEGOTIATED_VERSION "tls-negotiated-version"
252 * Serializer parameters
254 /* The passphrase may be passed as a utf8 string or an octet string */
255 #define OSSL_SERIALIZER_PARAM_CIPHER OSSL_ALG_PARAM_CIPHER
256 #define OSSL_SERIALIZER_PARAM_PROPERTIES OSSL_ALG_PARAM_PROPERTIES
257 #define OSSL_SERIALIZER_PARAM_PASS "passphrase"
259 /* Passphrase callback parameters */
260 #define OSSL_PASSPHRASE_PARAM_INFO "info"