| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent a5d4ac8 commit 49f2ae2
2 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -94,7 +94,19 @@ const EVP_MD* GetDigestCtxMd(const EVP_MD_CTX* ctx) { | |||
| 94 | 94 | ||
| 95 | 95 | #if NCRYPTO_USE_OPENSSL3_PROVIDER | |
| 96 | 96 | using OSSLParamBldPointer = DeleteFnPtr<OSSL_PARAM_BLD, OSSL_PARAM_BLD_free>; | |
| 97 | - using OSSLParamPointer = DeleteFnPtr<OSSL_PARAM, OSSL_PARAM_free>; | ||
| 97 | + struct OSSLParamDeleter { | ||
| 98 | + void operator()(OSSL_PARAM* params) const { | ||
| 99 | + if (params == nullptr) return; | ||
| 100 | + for (OSSL_PARAM* param = params; param->key != nullptr; param++) { | ||
| 101 | + if (param->data != nullptr && param->data_type != OSSL_PARAM_UTF8_PTR && | ||
| 102 | + param->data_type != OSSL_PARAM_OCTET_PTR) { | ||
| 103 | + OPENSSL_cleanse(param->data, param->data_size); | ||
| 104 | + } | ||
| 105 | + } | ||
| 106 | + OSSL_PARAM_free(params); | ||
| 107 | + } | ||
| 108 | + }; | ||
| 109 | + using OSSLParamPointer = std::unique_ptr<OSSL_PARAM, OSSLParamDeleter>; | ||
| 98 | 110 | struct OpenSSLBufferDeleter { | |
| 99 | 111 | void operator()(unsigned char* pointer) const { OPENSSL_free(pointer); } | |
| 100 | 112 | }; | |
@@ -106,9 +118,8 @@ static constexpr int kX509NameFlagsRFC2253WithinUtf8JSON = | |||
| 106 | 118 | XN_FLAG_RFC2253 & ~ASN1_STRFLGS_ESC_MSB & ~ASN1_STRFLGS_ESC_CTRL; | |
| 107 | 119 | ||
| 108 | 120 | #if NCRYPTO_USE_OPENSSL3_PROVIDER | |
| 109 | - bool GetPKeyBnParam(const EVP_PKEY* pkey, | ||
| 110 | - const char* name, | ||
| 111 | - DeleteFnPtr<BIGNUM, BN_free>* out) { | ||
| 121 | + template <typename Pointer> | ||
| 122 | + bool GetPKeyBnParam(const EVP_PKEY* pkey, const char* name, Pointer* out) { | ||
| 112 | 123 | BIGNUM* bn = nullptr; | |
| 113 | 124 | if (pkey == nullptr) return false; | |
| 114 | 125 | if (EVP_PKEY_get_bn_param(pkey, name, &bn) == 1) { | |
@@ -135,9 +146,10 @@ bool GetPKeyBnParam(const EVP_PKEY* pkey, | |||
| 135 | 146 | return true; | |
| 136 | 147 | } | |
| 137 | 148 | ||
| 149 | + template <typename Pointer> | ||
| 138 | 150 | bool GetOptionalPKeyBnParam(const EVP_PKEY* pkey, | |
| 139 | 151 | const char* name, | |
| 140 | - DeleteFnPtr<BIGNUM, BN_free>* out) { | ||
| 152 | + Pointer* out) { | ||
| 141 | 153 | BIGNUM* bn = nullptr; | |
| 142 | 154 | if (pkey == nullptr) { | |
| 143 | 155 | out->reset(); | |
@@ -273,9 +285,11 @@ bool GetDhParams(const EVP_PKEY* pkey, | |||
| 273 | 285 | ||
| 274 | 286 | bool GetDhKeys(const EVP_PKEY* pkey, | |
| 275 | 287 | DeleteFnPtr<BIGNUM, BN_free>* pub, | |
| 276 | - DeleteFnPtr<BIGNUM, BN_free>* priv) { | ||
| 277 | - return GetOptionalPKeyBnParam(pkey, OSSL_PKEY_PARAM_PUB_KEY, pub) && | ||
| 278 | - GetOptionalPKeyBnParam(pkey, OSSL_PKEY_PARAM_PRIV_KEY, priv); | ||
| 288 | + DeleteFnPtr<BIGNUM, BN_clear_free>* priv) { | ||
| 289 | + return (pub == nullptr || | ||
| 290 | + GetOptionalPKeyBnParam(pkey, OSSL_PKEY_PARAM_PUB_KEY, pub)) && | ||
| 291 | + (priv == nullptr || | ||
| 292 | + GetOptionalPKeyBnParam(pkey, OSSL_PKEY_PARAM_PRIV_KEY, priv)); | ||
| 279 | 293 | } | |
| 280 | 294 | #endif | |
| 281 | 295 | ||
@@ -2290,8 +2304,7 @@ DataPointer DHPointer::getPublicKey() const { | |||
| 2290 | 2304 | if (!dh_) return {}; | |
| 2291 | 2305 | ||
| 2292 | 2306 | DeleteFnPtr<BIGNUM, BN_free> pub_key; | |
| 2293 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2294 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) return {}; | ||
| 2307 | + if (!GetDhKeys(dh_.get(), &pub_key, nullptr)) return {}; | ||
| 2295 | 2308 | return BignumPointer::Encode(pub_key.get()); | |
| 2296 | 2309 | #else | |
| 2297 | 2310 | const BIGNUM* pub_key; | |
@@ -2306,9 +2319,8 @@ DataPointer DHPointer::getPrivateKey() const { | |||
| 2306 | 2319 | if (pvt_key_) return pvt_key_.encode(); | |
| 2307 | 2320 | if (!dh_) return {}; | |
| 2308 | 2321 | ||
| 2309 | - DeleteFnPtr<BIGNUM, BN_free> pub_key; | ||
| 2310 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2311 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) return {}; | ||
| 2322 | + DeleteFnPtr<BIGNUM, BN_clear_free> pvt_key; | ||
| 2323 | + if (!GetDhKeys(dh_.get(), nullptr, &pvt_key)) return {}; | ||
| 2312 | 2324 | return BignumPointer::Encode(pvt_key.get()); | |
| 2313 | 2325 | #else | |
| 2314 | 2326 | const BIGNUM* pvt_key; | |
@@ -2323,9 +2335,8 @@ bool DHPointer::hasPrivateKey() const { | |||
| 2323 | 2335 | if (pvt_key_) return true; | |
| 2324 | 2336 | if (!dh_) return false; | |
| 2325 | 2337 | ||
| 2326 | - DeleteFnPtr<BIGNUM, BN_free> pub_key; | ||
| 2327 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2328 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) return false; | ||
| 2338 | + DeleteFnPtr<BIGNUM, BN_clear_free> pvt_key; | ||
| 2339 | + if (!GetDhKeys(dh_.get(), nullptr, &pvt_key)) return false; | ||
| 2329 | 2340 | return pvt_key != nullptr; | |
| 2330 | 2341 | #else | |
| 2331 | 2342 | const BIGNUM* pvt_key = nullptr; | |
@@ -2361,7 +2372,7 @@ DataPointer DHPointer::generateKeys() { | |||
| 2361 | 2372 | DeleteFnPtr<BIGNUM, BN_free> p; | |
| 2362 | 2373 | DeleteFnPtr<BIGNUM, BN_free> g; | |
| 2363 | 2374 | DeleteFnPtr<BIGNUM, BN_free> pub_key; | |
| 2364 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2375 | + DeleteFnPtr<BIGNUM, BN_clear_free> pvt_key; | ||
| 2365 | 2376 | if (!GetDhParams(dh_.get(), &p, &g) || | |
| 2366 | 2377 | !GetDhKeys(dh_.get(), &pub_key, &pvt_key)) { | |
| 2367 | 2378 | return {}; | |
@@ -2496,9 +2507,8 @@ bool DHPointer::setPublicKey(BignumPointer&& key) { | |||
| 2496 | 2507 | return true; | |
| 2497 | 2508 | } | |
| 2498 | 2509 | ||
| 2499 | - DeleteFnPtr<BIGNUM, BN_free> pub_key; | ||
| 2500 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2501 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) { | ||
| 2510 | + DeleteFnPtr<BIGNUM, BN_clear_free> pvt_key; | ||
| 2511 | + if (!GetDhKeys(dh_.get(), nullptr, &pvt_key)) { | ||
| 2502 | 2512 | return false; | |
| 2503 | 2513 | } | |
| 2504 | 2514 | EVPKeyPointer pkey; | |
@@ -2535,8 +2545,7 @@ bool DHPointer::setPrivateKey(BignumPointer&& key) { | |||
| 2535 | 2545 | } | |
| 2536 | 2546 | ||
| 2537 | 2547 | DeleteFnPtr<BIGNUM, BN_free> pub_key; | |
| 2538 | - DeleteFnPtr<BIGNUM, BN_free> pvt_key; | ||
| 2539 | - if (!GetDhKeys(dh_.get(), &pub_key, &pvt_key)) { | ||
| 2548 | + if (!GetDhKeys(dh_.get(), &pub_key, nullptr)) { | ||
| 2540 | 2549 | return false; | |
| 2541 | 2550 | } | |
| 2542 | 2551 | EVPKeyPointer pkey; | |
@@ -3537,12 +3546,13 @@ bool WriteEncryptedTraditionalPEM(BIO* bio, | |||
| 3537 | 3546 | size_t der_len = 0; | |
| 3538 | 3547 | OSSLEncoderCtxPointer ctx(OSSL_ENCODER_CTX_new_for_pkey( | |
| 3539 | 3548 | pkey, OSSL_KEYMGMT_SELECT_KEYPAIR, "DER", "pkcs1", nullptr)); | |
| 3540 | - if (!ctx || OSSL_ENCODER_to_data(ctx.get(), &der, &der_len) != 1) { | ||
| 3541 | - return false; | ||
| 3542 | - } | ||
| 3549 | + if (!ctx) return false; | ||
| 3550 | + | ||
| 3551 | + const int result = OSSL_ENCODER_to_data(ctx.get(), &der, &der_len); | ||
| 3552 | + DataPointer der_storage(der, der_len); | ||
| 3553 | + if (result != 1) return false; | ||
| 3543 | 3554 | ||
| 3544 | - OpenSSLBufferPointer der_storage(der); | ||
| 3545 | - DERView der_view{der_storage.get(), der_len}; | ||
| 3555 | + DERView der_view{der_storage.get<const unsigned char>(), der_len}; | ||
| 3546 | 3556 | return PEM_ASN1_write_bio( | |
| 3547 | 3557 | WriteDERView, | |
| 3548 | 3558 | PEM_STRING_RSA, | |
@@ -4977,7 +4987,7 @@ bool ECKeyPointer::generate() { | |||
| 4977 | 4987 | if (EVP_PKEY_keygen(ctx.get(), &raw) != 1) return false; | |
| 4978 | 4988 | EVPKeyPointer pkey(raw); | |
| 4979 | 4989 | ||
| 4980 | - DeleteFnPtr<BIGNUM, BN_free> priv; | ||
| 4990 | + DeleteFnPtr<BIGNUM, BN_clear_free> priv; | ||
| 4981 | 4991 | if (!GetPKeyBnParam(pkey.get(), OSSL_PKEY_PARAM_PRIV_KEY, &priv)) { | |
| 4982 | 4992 | return false; | |
| 4983 | 4993 | } | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -641,12 +641,12 @@ class Rsa final { | |||
| 641 | 641 | bool rsa_ = false; | |
| 642 | 642 | DeleteFnPtr<BIGNUM, BN_free> n_; | |
| 643 | 643 | DeleteFnPtr<BIGNUM, BN_free> e_; | |
| 644 | - DeleteFnPtr<BIGNUM, BN_free> d_; | ||
| 645 | - DeleteFnPtr<BIGNUM, BN_free> p_; | ||
| 646 | - DeleteFnPtr<BIGNUM, BN_free> q_; | ||
| 647 | - DeleteFnPtr<BIGNUM, BN_free> dp_; | ||
| 648 | - DeleteFnPtr<BIGNUM, BN_free> dq_; | ||
| 649 | - DeleteFnPtr<BIGNUM, BN_free> qi_; | ||
| 644 | + DeleteFnPtr<BIGNUM, BN_clear_free> d_; | ||
| 645 | + DeleteFnPtr<BIGNUM, BN_clear_free> p_; | ||
| 646 | + DeleteFnPtr<BIGNUM, BN_clear_free> q_; | ||
| 647 | + DeleteFnPtr<BIGNUM, BN_clear_free> dp_; | ||
| 648 | + DeleteFnPtr<BIGNUM, BN_clear_free> dq_; | ||
| 649 | + DeleteFnPtr<BIGNUM, BN_clear_free> qi_; | ||
| 650 | 650 | std::optional<PssParams> pss_params_; | |
| 651 | 651 | #else | |
| 652 | 652 | OSSL3_CONST RSA* rsa_; | |
@@ -1634,7 +1634,7 @@ class ECKeyPointer final { | |||
| 1634 | 1634 | #if NCRYPTO_USE_OPENSSL3_PROVIDER | |
| 1635 | 1635 | DeleteFnPtr<EC_GROUP, EC_GROUP_free> group_; | |
| 1636 | 1636 | DeleteFnPtr<EC_POINT, EC_POINT_free> pub_; | |
| 1637 | - DeleteFnPtr<BIGNUM, BN_free> priv_; | ||
| 1637 | + DeleteFnPtr<BIGNUM, BN_clear_free> priv_; | ||
| 1638 | 1638 | #else | |
| 1639 | 1639 | DeleteFnPtr<EC_KEY, EC_KEY_free> key_; | |
| 1640 | 1640 | #endif | |
| Back | FazBrowse Home | New Git URL |
0 commit comments