diff --git a/pkcs1-rsa-md5.c b/pkcs1-rsa-md5.c new file mode 100644 index 0000000000000000000000000000000000000000..5273ee8ed84113f465c3a901d56b9719085e3e74 --- /dev/null +++ b/pkcs1-rsa-md5.c @@ -0,0 +1,92 @@ +/* pkcs1-rsa-md5.c + * + * PKCS stuff for rsa-md5. + */ + +/* nettle, low-level cryptographics library + * + * Copyright (C) 2001, 2003 Niels Möller + * + * The nettle library is free software; you can redistribute it and/or modify + * it under the terms of the GNU Lesser General Public License as published by + * the Free Software Foundation; either version 2.1 of the License, or (at your + * option) any later version. + * + * The nettle library is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY + * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public + * License for more details. + * + * You should have received a copy of the GNU Lesser General Public License + * along with the nettle library; see the file COPYING.LIB. If not, write to + * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, + * MA 02111-1307, USA. + */ + +#if HAVE_CONFIG_H +#include "config.h" +#endif + +#if WITH_PUBLIC_KEY + +#include "rsa.h" + +#include "bignum.h" +#include "pkcs1.h" + +#include <assert.h> +#include <stdlib.h> +#include <string.h> + +/* From pkcs-1v2 + * + * md5 OBJECT IDENTIFIER ::= + * {iso(1) member-body(2) US(840) rsadsi(113549) digestAlgorithm(2) 5} + * + * The parameters part of the algorithm identifier is NULL: + * + * md5Identifier ::= AlgorithmIdentifier {md5, NULL} + */ + +static const uint8_t +md5_prefix[] = +{ + /* 18 octets prefix, 16 octets hash, 34 total. */ + 0x30, 32, /* SEQUENCE */ + 0x30, 12, /* SEQUENCE */ + 0x06, 8, /* OBJECT IDENTIFIER */ + 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x02, 0x05, + 0x05, 0, /* NULL */ + 0x04, 16 /* OCTET STRING */ + /* Here comes the raw hash value */ +}; + +void +pkcs1_rsa_md5_encode(mpz_t m, unsigned length, struct md5_ctx *hash) +{ + uint8_t *em = alloca(length); + + assert(length >= MD5_DIGEST_SIZE); + pkcs1_signature_prefix(length - MD5_DIGEST_SIZE, em, + sizeof(md5_prefix), + md5_prefix); + + md5_digest(hash, MD5_DIGEST_SIZE, em + length - MD5_DIGEST_SIZE); + nettle_mpz_set_str_256_u(m, length, em); +} + +void +pkcs1_rsa_md5_encode_digest(mpz_t m, unsigned length, const uint8_t *digest) +{ + uint8_t *em = alloca(length); + + assert(length >= MD5_DIGEST_SIZE); + pkcs1_signature_prefix(length - MD5_DIGEST_SIZE, em, + sizeof(md5_prefix), + md5_prefix); + + memcpy(em + length - MD5_DIGEST_SIZE, digest, MD5_DIGEST_SIZE); + nettle_mpz_set_str_256_u(m, length, em); +} + +#endif /* WITH_PUBLIC_KEY */ diff --git a/pkcs1-rsa-sha1.c b/pkcs1-rsa-sha1.c new file mode 100644 index 0000000000000000000000000000000000000000..9517411945e06f9a81ef95d1b3ad3fea3b0ce983 --- /dev/null +++ b/pkcs1-rsa-sha1.c @@ -0,0 +1,92 @@ +/* pkcs1-rsa-md5.c + * + * PKCS stuff for rsa-md5. + */ + +/* nettle, low-level cryptographics library + * + * Copyright (C) 2001, 2003 Niels Möller + * + * The nettle library is free software; you can redistribute it and/or modify + * it under the terms of the GNU Lesser General Public License as published by + * the Free Software Foundation; either version 2.1 of the License, or (at your + * option) any later version. + * + * The nettle library is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY + * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public + * License for more details. + * + * You should have received a copy of the GNU Lesser General Public License + * along with the nettle library; see the file COPYING.LIB. If not, write to + * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, + * MA 02111-1307, USA. + */ + +#if HAVE_CONFIG_H +#include "config.h" +#endif + +#if WITH_PUBLIC_KEY + +#include "rsa.h" + +#include "bignum.h" +#include "pkcs1.h" + +#include <assert.h> +#include <stdlib.h> +#include <string.h> + +/* From pkcs-1v2 + * + * id-sha1 OBJECT IDENTIFIER ::= + * {iso(1) identified-organization(3) oiw(14) secsig(3) + * algorithms(2) 26} + * + * The default hash function is SHA-1: + * sha1Identifier ::= AlgorithmIdentifier {id-sha1, NULL} + */ + +static const uint8_t +sha1_prefix[] = +{ + /* 15 octets prefix, 20 octets hash, total 35 */ + 0x30, 33, /* SEQUENCE */ + 0x30, 9, /* SEQUENCE */ + 0x06, 5, /* OBJECT IDENTIFIER */ + 0x2b, 0x0e, 0x03, 0x02, 0x1a, + 0x05, 0, /* NULL */ + 0x04, 20 /* OCTET STRING */ + /* Here comes the raw hash value */ +}; + +void +pkcs1_rsa_sha1_encode(mpz_t m, unsigned length, struct sha1_ctx *hash) +{ + uint8_t *em = alloca(length); + + assert(length >= SHA1_DIGEST_SIZE); + pkcs1_signature_prefix(length - SHA1_DIGEST_SIZE, em, + sizeof(sha1_prefix), + sha1_prefix); + + sha1_digest(hash, SHA1_DIGEST_SIZE, em + length - SHA1_DIGEST_SIZE); + nettle_mpz_set_str_256_u(m, length, em); +} + +void +pkcs1_rsa_sha1_encode_digest(mpz_t m, unsigned length, const uint8_t *digest) +{ + uint8_t *em = alloca(length); + + assert(length >= SHA1_DIGEST_SIZE); + pkcs1_signature_prefix(length - SHA1_DIGEST_SIZE, em, + sizeof(sha1_prefix), + sha1_prefix); + + memcpy(em + length - SHA1_DIGEST_SIZE, digest, SHA1_DIGEST_SIZE); + nettle_mpz_set_str_256_u(m, length, em); +} + +#endif /* WITH_PUBLIC_KEY */ diff --git a/pkcs1.c b/pkcs1.c new file mode 100644 index 0000000000000000000000000000000000000000..104af2acb158e5bde4f21dc8411fe3ab1ade4b14 --- /dev/null +++ b/pkcs1.c @@ -0,0 +1,55 @@ +/* pkcs1.c + * + * PKCS1 embedding. + */ + +/* nettle, low-level cryptographics library + * + * Copyright (C) 2003 Niels Möller + * + * The nettle library is free software; you can redistribute it and/or modify + * it under the terms of the GNU Lesser General Public License as published by + * the Free Software Foundation; either version 2.1 of the License, or (at your + * option) any later version. + * + * The nettle library is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY + * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public + * License for more details. + * + * You should have received a copy of the GNU Lesser General Public License + * along with the nettle library; see the file COPYING.LIB. If not, write to + * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, + * MA 02111-1307, USA. + */ + +#if HAVE_CONFIG_H +#include "config.h" +#endif + +#if WITH_PUBLIC_KEY + +#include "pkcs1.h" + +#include <assert.h> +#include <string.h> + +void +pkcs1_signature_prefix(unsigned length, + uint8_t *buffer, + unsigned id_length, + const uint8_t *id) +{ + assert(length >= id_length); + length -= id_length; + memcpy(buffer + length, id, id_length); + + assert(length); + buffer[--length] = 0; + + assert(length >= 9); + memset(buffer + 1, 0xff, length - 1); + buffer[0] = 1; +} + +#endif /* WITH_PUBLIC_KEY */ diff --git a/pkcs1.h b/pkcs1.h new file mode 100644 index 0000000000000000000000000000000000000000..3671f8018c3ea259beb51dbb3efab55c6f3d0403 --- /dev/null +++ b/pkcs1.h @@ -0,0 +1,53 @@ +/* pkcs1.h + * + * PKCS1 embedding. + */ + +/* nettle, low-level cryptographics library + * + * Copyright (C) 2003 Niels Möller + * + * The nettle library is free software; you can redistribute it and/or modify + * it under the terms of the GNU Lesser General Public License as published by + * the Free Software Foundation; either version 2.1 of the License, or (at your + * option) any later version. + * + * The nettle library is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY + * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public + * License for more details. + * + * You should have received a copy of the GNU Lesser General Public License + * along with the nettle library; see the file COPYING.LIB. If not, write to + * the Free Software Foundation, Inc., 59 Temple Place - Suite 330, Boston, + * MA 02111-1307, USA. + */ + +#ifndef NETTLE_PKCS1_H_INCLUDED +#define NETTLE_PKCS1_H_INCLUDED + +#include <inttypes.h> +#include <gmp.h> + +struct md5_ctx; +struct sha1_ctx; + +void +pkcs1_signature_prefix(unsigned length, + uint8_t *buffer, + unsigned id_length, + const uint8_t *id); + +void +pkcs1_rsa_md5_encode(mpz_t m, unsigned length, struct md5_ctx *hash); + +void +pkcs1_rsa_md5_encode_digest(mpz_t m, unsigned length, const uint8_t *digest); + +void +pkcs1_rsa_sha1_encode(mpz_t m, unsigned length, struct sha1_ctx *hash); + +void +pkcs1_rsa_sha1_encode_digest(mpz_t m, unsigned length, const uint8_t *digest); + +#endif /* NETTLE_PKCS1_H_INCLUDED */