24#ifndef LIBMBEDCRYPTO_H_
25#define LIBMBEDCRYPTO_H_
29#ifdef HAVE_LIBMBEDCRYPTO
31#include <mbedtls/md.h>
32#include <mbedtls/bignum.h>
33#include <mbedtls/pk.h>
34#include <mbedtls/cipher.h>
35#include <mbedtls/entropy.h>
36#include <mbedtls/ctr_drbg.h>
38typedef mbedtls_md_context_t *SHACTX;
39typedef mbedtls_md_context_t *SHA256CTX;
40typedef mbedtls_md_context_t *SHA384CTX;
41typedef mbedtls_md_context_t *SHA512CTX;
42typedef mbedtls_md_context_t *MD5CTX;
43typedef mbedtls_md_context_t *HMACCTX;
45#define SHA_DIGEST_LENGTH 20
46#define SHA_DIGEST_LEN SHA_DIGEST_LENGTH
47#define MD5_DIGEST_LEN 16
48#define SHA256_DIGEST_LENGTH 32
49#define SHA256_DIGEST_LEN SHA256_DIGEST_LENGTH
50#define SHA384_DIGEST_LENGTH 48
51#define SHA384_DIGEST_LEN SHA384_DIGEST_LENGTH
52#define SHA512_DIGEST_LENGTH 64
53#define SHA512_DIGEST_LEN SHA512_DIGEST_LENGTH
55#ifndef EVP_MAX_MD_SIZE
56#define EVP_MAX_MD_SIZE 64
59#define EVP_DIGEST_LEN EVP_MAX_MD_SIZE
61typedef mbedtls_mpi *bignum;
62typedef const mbedtls_mpi *const_bignum;
63typedef void* bignum_CTX;
66#define NID_mbedtls_nistp256 0
67#define NID_mbedtls_nistp384 1
68#define NID_mbedtls_nistp521 2
70struct mbedtls_ecdsa_sig {
75bignum ssh_mbedcry_bn_new(
void);
76void ssh_mbedcry_bn_free(bignum num);
77unsigned char *ssh_mbedcry_bn2num(const_bignum num,
int radix);
78int ssh_mbedcry_rand(bignum rnd,
int bits,
int top,
int bottom);
79int ssh_mbedcry_is_bit_set(bignum num,
size_t pos);
80int ssh_mbedcry_rand_range(bignum dest, bignum max);
81int ssh_mbedcry_hex2bn(bignum *dest,
char *data);
83#define bignum_new() ssh_mbedcry_bn_new()
84#define bignum_safe_free(num) do { \
85 if ((num) != NULL) { \
86 ssh_mbedcry_bn_free(num); \
90#define bignum_ctx_new() NULL
91#define bignum_ctx_free(num) do {(num) = NULL;} while(0)
92#define bignum_ctx_invalid(ctx) (ctx == NULL?0:1)
93#define bignum_set_word(bn, n) (mbedtls_mpi_lset(bn, n)==0?1:0)
95#define bignum_bin2bn(data, datalen, bn) do { \
96 *(bn) = bignum_new(); \
97 if (*(bn) != NULL) { \
98 mbedtls_mpi_read_binary(*(bn), data, datalen); \
101#define bignum_bn2dec(num) ssh_mbedcry_bn2num(num, 10)
102#define bignum_dec2bn(data, bn) mbedtls_mpi_read_string(bn, 10, data)
103#define bignum_bn2hex(num, dest) (*dest)=ssh_mbedcry_bn2num(num, 16)
104#define bignum_hex2bn(data, dest) ssh_mbedcry_hex2bn(dest, data)
105#define bignum_rand(rnd, bits) ssh_mbedcry_rand((rnd), (bits), 0, 1)
106#define bignum_rand_range(rnd, max) ssh_mbedcry_rand_range(rnd, max)
107#define bignum_mod_exp(dest, generator, exp, modulo, ctx) \
108 (mbedtls_mpi_exp_mod(dest, generator, exp, modulo, NULL)==0?1:0)
109#define bignum_add(dest, a, b) mbedtls_mpi_add_mpi(dest, a, b)
110#define bignum_sub(dest, a, b) mbedtls_mpi_sub_mpi(dest, a, b)
111#define bignum_mod(dest, a, b, ctx) \
112 (mbedtls_mpi_mod_mpi(dest, a, b) == 0 ? 1 : 0)
113#define bignum_num_bytes(num) mbedtls_mpi_size(num)
114#define bignum_num_bits(num) mbedtls_mpi_bitlen(num)
115#define bignum_is_bit_set(num, bit) ssh_mbedcry_is_bit_set(num, bit)
116#define bignum_bn2bin(num, len, ptr) mbedtls_mpi_write_binary(num, ptr, \
117 mbedtls_mpi_size(num))
118#define bignum_cmp(num1, num2) mbedtls_mpi_cmp_mpi(num1, num2)
119#define bignum_rshift1(dest, src) mbedtls_mpi_copy(dest, src), mbedtls_mpi_shift_r(dest, 1)
120#define bignum_dup(orig, dest) do { \
121 if (*(dest) == NULL) { \
122 *(dest) = bignum_new(); \
124 if (*(dest) != NULL) { \
125 mbedtls_mpi_copy(orig, *(dest)); \
129mbedtls_ctr_drbg_context *ssh_get_mbedtls_ctr_drbg_context(
void);
131int ssh_mbedtls_random(
void *where,
int len,
int strong);
133ssh_string make_ecpoint_string(
const mbedtls_ecp_group *g,
const
134 mbedtls_ecp_point *p);
136#define ssh_fips_mode() false