| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent 33a0e08 commit 2fde794
2 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -94,7 +94,19 @@ const EVP_MD* GetDigestCtxMd(const EVP_MD_CTX* ctx) { | |||
| 94 | 94 | ||
| 95 | 95 | #if NCRYPTO_USE_OPENSSL3_PROVIDER | |
| 96 | 96 | using OSSLParamBldPointer = DeleteFnPtr<OSSL_PARAM_BLD, OSSL_PARAM_BLD_free>; | |
| 97 | - using OSSLParamPointer = DeleteFnPtr<OSSL_PARAM, OSSL_PARAM_free>; | ||
| 97 | + struct OSSLParamDeleter { | ||
| 98 | + void operator()(OSSL_PARAM* params) const { | ||
| 99 | + if (params == nullptr) return; | ||
| 100 | + for (OSSL_PARAM* param = params; param->key != nullptr; param++) { | ||
| 101 | + if (param->data != nullptr && param->data_type != OSSL_PARAM_UTF8_PTR && | ||
| 102 | + param->data_type != OSSL_PARAM_OCTET_PTR) { | ||
| 103 | + OPENSSL_cleanse(param->data, param->data_size); | ||
| 104 | + } | ||
| 105 | + } | ||
| 106 | + OSSL_PARAM_free(params); | ||
| 107 | + } | ||
| 108 | + }; | ||
| 109 | + using OSSLParamPointer = std::unique_ptr<OSSL_PARAM, OSSLParamDeleter>; | ||
| 98 | 110 | struct OpenSSLBufferDeleter { | |
| 99 | 111 | void operator()(unsigned char* pointer) const { OPENSSL_free(pointer); } | |
| 100 | 112 | }; | |
@@ -106,9 +118,8 @@ static constexpr int kX509NameFlagsRFC2253WithinUtf8JSON = | |||
| 106 | 118 | XN_FLAG_RFC2253 & ~ASN1_STRFLGS_ESC_MSB & ~ASN1_STRFLGS_ESC_CTRL; | |
| 107 | 119 | ||
| 108 | 120 | #if NCRYPTO_USE_OPENSSL3_PROVIDER | |
| 109 | - bool GetPKeyBnParam(const EVP_PKEY* pkey, | ||
| 110 | - const char* name, | ||
| 111 | - DeleteFnPtr<BIGNUM, BN_free>* out) { | ||
| 121 | + template <typename Pointer> | ||
| 122 | + bool GetPKeyBnParam(const EVP_PKEY* pkey, const char* name, Pointer* out) { | ||
| 112 | 123 | BIGNUM* bn = nullptr; | |
| 113 | 124 | if (pkey == nullptr) return false; | |
| 114 | 125 | if (EVP_PKEY_get_bn_param(pkey, name, &bn) == 1) { | |
@@ -135,9 +146,10 @@ bool GetPKeyBnParam(const EVP_PKEY* pkey, | |||
| 135 | 146 | return true; | |
| 136 | 147 | } | |
| 137 | 148 | ||
| 149 | + template <typename Pointer> | ||
| 138 | 150 | bool GetOptionalPKeyBnParam(const EVP_PKEY* pkey, | |
| 139 | 151 | const char* name, | |
| 140 | - DeleteFnPtr<BIGNUM, BN_free>* out) { | ||
| 152 | + Pointer* out) { | ||
| 141 | 153 | BIGNUM* bn = nullptr; | |
| 142 | 154 | if (pkey == nullptr) { | |
| 143 | 155 | out->reset(); | |
@@ -273,9 +285,11 @@ bool GetDhParams(const EVP_PKEY* pkey, | |||
| 273 | 285 | ||
| 274 | 286 | bool GetDhKeys(const EVP_PKEY* pkey, | |
| 275 | 287 | DeleteFnPtr<BIGNUM, BN_free>* pub, | |
| 276 | - DeleteFnPtr<BIGNUM, BN_free>* priv) { | ||
| 277 | - return GetOptionalPKeyBnParam(pkey, OSSL_PKEY_PARAM_PUB_KEY, pub) && | ||
| 278 | - GetOptionalPKeyBnParam(pkey, OSSL_PKEY_PARAM_PRIV_KEY, priv); | ||
| 288 | + DeleteFnPtr<BIGNUM, BN_clear_free>* priv) { | ||
| 289 | + return (pub == nullptr || | ||
| 290 | + GetOptionalPKeyBnParam(pkey, OSSL_PKEY_PARAM_PUB_KEY, pub)) && | ||
| 291 | + (priv == nullptr || | ||
| 292 | + GetOptionalPKeyBnParam(pkey, OSSL_PKEY_PARAM_PRIV_KEY, priv)); | ||
| 279 | 293 | } | |
| 280 | 294 | #endif | |
| 281 | 295 | ||
@@ -2287,8 +2301,7 @@ DataPointer DHPointer::getPublicKey() const { | |||
| 2287 | 2301 | if (!dh_) return {}; | |
| 2288 | 2302 | ||
| 2289 | 2303 | DeleteFnPtr<BIGNUM, BN_free> pub_key; | |
| 2290 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2291 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) return {}; | ||
| 2304 | + if (!GetDhKeys(dh_.get(), &pub_key, nullptr)) return {}; | ||
| 2292 | 2305 | return BignumPointer::Encode(pub_key.get()); | |
| 2293 | 2306 | #else | |
| 2294 | 2307 | const BIGNUM* pub_key; | |
@@ -2303,9 +2316,8 @@ DataPointer DHPointer::getPrivateKey() const { | |||
| 2303 | 2316 | if (pvt_key_) return pvt_key_.encode(); | |
| 2304 | 2317 | if (!dh_) return {}; | |
| 2305 | 2318 | ||
| 2306 | - DeleteFnPtr<BIGNUM, BN_free> pub_key; | ||
| 2307 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2308 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) return {}; | ||
| 2319 | + DeleteFnPtr<BIGNUM, BN_clear_free> pvt_key; | ||
| 2320 | + if (!GetDhKeys(dh_.get(), nullptr, &pvt_key)) return {}; | ||
| 2309 | 2321 | return BignumPointer::Encode(pvt_key.get()); | |
| 2310 | 2322 | #else | |
| 2311 | 2323 | const BIGNUM* pvt_key; | |
@@ -2320,9 +2332,8 @@ bool DHPointer::hasPrivateKey() const { | |||
| 2320 | 2332 | if (pvt_key_) return true; | |
| 2321 | 2333 | if (!dh_) return false; | |
| 2322 | 2334 | ||
| 2323 | - DeleteFnPtr<BIGNUM, BN_free> pub_key; | ||
| 2324 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2325 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) return false; | ||
| 2335 | + DeleteFnPtr<BIGNUM, BN_clear_free> pvt_key; | ||
| 2336 | + if (!GetDhKeys(dh_.get(), nullptr, &pvt_key)) return false; | ||
| 2326 | 2337 | return pvt_key != nullptr; | |
| 2327 | 2338 | #else | |
| 2328 | 2339 | const BIGNUM* pvt_key = nullptr; | |
@@ -2358,7 +2369,7 @@ DataPointer DHPointer::generateKeys() { | |||
| 2358 | 2369 | DeleteFnPtr<BIGNUM, BN_free> p; | |
| 2359 | 2370 | DeleteFnPtr<BIGNUM, BN_free> g; | |
| 2360 | 2371 | DeleteFnPtr<BIGNUM, BN_free> pub_key; | |
| 2361 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2372 | + DeleteFnPtr<BIGNUM, BN_clear_free> pvt_key; | ||
| 2362 | 2373 | if (!GetDhParams(dh_.get(), &p, &g) || | |
| 2363 | 2374 | !GetDhKeys(dh_.get(), &pub_key, &pvt_key)) { | |
| 2364 | 2375 | return {}; | |
@@ -2493,9 +2504,8 @@ bool DHPointer::setPublicKey(BignumPointer&& key) { | |||
| 2493 | 2504 | return true; | |
| 2494 | 2505 | } | |
| 2495 | 2506 | ||
| 2496 | - DeleteFnPtr<BIGNUM, BN_free> pub_key; | ||
| 2497 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2498 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) { | ||
| 2507 | + DeleteFnPtr<BIGNUM, BN_clear_free> pvt_key; | ||
| 2508 | + if (!GetDhKeys(dh_.get(), nullptr, &pvt_key)) { | ||
| 2499 | 2509 | return false; | |
| 2500 | 2510 | } | |
| 2501 | 2511 | EVPKeyPointer pkey; | |
@@ -2532,8 +2542,7 @@ bool DHPointer::setPrivateKey(BignumPointer&& key) { | |||
| 2532 | 2542 | } | |
| 2533 | 2543 | ||
| 2534 | 2544 | DeleteFnPtr<BIGNUM, BN_free> pub_key; | |
| 2535 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2536 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) { | ||
| 2545 | + if (!GetDhKeys(dh_.get(), &pub_key, nullptr)) { | ||
| 2537 | 2546 | return false; | |
| 2538 | 2547 | } | |
| 2539 | 2548 | EVPKeyPointer pkey; | |
@@ -3525,12 +3534,13 @@ bool WriteEncryptedTraditionalPEM(BIO* bio, | |||
| 3525 | 3534 | size_t der_len = 0; | |
| 3526 | 3535 | OSSLEncoderCtxPointer ctx(OSSL_ENCODER_CTX_new_for_pkey( | |
| 3527 | 3536 | pkey, OSSL_KEYMGMT_SELECT_KEYPAIR, "DER", "pkcs1", nullptr)); | |
| 3528 | - if (!ctx || OSSL_ENCODER_to_data(ctx.get(), &der, &der_len) != 1) { | ||
| 3529 | - return false; | ||
| 3530 | - } | ||
| 3537 | + if (!ctx) return false; | ||
| 3538 | + | ||
| 3539 | + const int result = OSSL_ENCODER_to_data(ctx.get(), &der, &der_len); | ||
| 3540 | + DataPointer der_storage(der, der_len); | ||
| 3541 | + if (result != 1) return false; | ||
| 3531 | 3542 | ||
| 3532 | - OpenSSLBufferPointer der_storage(der); | ||
| 3533 | - DERView der_view{der_storage.get(), der_len}; | ||
| 3543 | + DERView der_view{der_storage.get<const unsigned char>(), der_len}; | ||
| 3534 | 3544 | return PEM_ASN1_write_bio( | |
| 3535 | 3545 | WriteDERView, | |
| 3536 | 3546 | PEM_STRING_RSA, | |
@@ -4959,7 +4969,7 @@ bool ECKeyPointer::generate() { | |||
| 4959 | 4969 | if (EVP_PKEY_keygen(ctx.get(), &raw) != 1) return false; | |
| 4960 | 4970 | EVPKeyPointer pkey(raw); | |
| 4961 | 4971 | ||
| 4962 | - DeleteFnPtr<BIGNUM, BN_free> priv; | ||
| 4972 | + DeleteFnPtr<BIGNUM, BN_clear_free> priv; | ||
| 4963 | 4973 | if (!GetPKeyBnParam(pkey.get(), OSSL_PKEY_PARAM_PRIV_KEY, &priv)) { | |
| 4964 | 4974 | return false; | |
| 4965 | 4975 | } | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -641,12 +641,12 @@ class Rsa final { | |||
| 641 | 641 | bool rsa_ = false; | |
| 642 | 642 | DeleteFnPtr<BIGNUM, BN_free> n_; | |
| 643 | 643 | DeleteFnPtr<BIGNUM, BN_free> e_; | |
| 644 | - DeleteFnPtr<BIGNUM, BN_free> d_; | ||
| 645 | - DeleteFnPtr<BIGNUM, BN_free> p_; | ||
| 646 | - DeleteFnPtr<BIGNUM, BN_free> q_; | ||
| 647 | - DeleteFnPtr<BIGNUM, BN_free> dp_; | ||
| 648 | - DeleteFnPtr<BIGNUM, BN_free> dq_; | ||
| 649 | - DeleteFnPtr<BIGNUM, BN_free> qi_; | ||
| 644 | + DeleteFnPtr<BIGNUM, BN_clear_free> d_; | ||
| 645 | + DeleteFnPtr<BIGNUM, BN_clear_free> p_; | ||
| 646 | + DeleteFnPtr<BIGNUM, BN_clear_free> q_; | ||
| 647 | + DeleteFnPtr<BIGNUM, BN_clear_free> dp_; | ||
| 648 | + DeleteFnPtr<BIGNUM, BN_clear_free> dq_; | ||
| 649 | + DeleteFnPtr<BIGNUM, BN_clear_free> qi_; | ||
| 650 | 650 | std::optional<PssParams> pss_params_; | |
| 651 | 651 | #else | |
| 652 | 652 | OSSL3_CONST RSA* rsa_; | |
@@ -1634,7 +1634,7 @@ class ECKeyPointer final { | |||
| 1634 | 1634 | #if NCRYPTO_USE_OPENSSL3_PROVIDER | |
| 1635 | 1635 | DeleteFnPtr<EC_GROUP, EC_GROUP_free> group_; | |
| 1636 | 1636 | DeleteFnPtr<EC_POINT, EC_POINT_free> pub_; | |
| 1637 | - DeleteFnPtr<BIGNUM, BN_free> priv_; | ||
| 1637 | + DeleteFnPtr<BIGNUM, BN_clear_free> priv_; | ||
| 1638 | 1638 | #else | |
| 1639 | 1639 | DeleteFnPtr<EC_KEY, EC_KEY_free> key_; | |
| 1640 | 1640 | #endif | |
| Back | FazBrowse Home | New Git URL |
0 commit comments