Loading ssl/t1_enc.c +18 −12 Original line number Diff line number Diff line Loading @@ -31,7 +31,7 @@ static int tls1_PRF(SSL *s, unsigned char *out, size_t olen, int fatal) { const EVP_MD *md = ssl_prf_md(s); EVP_PKEY_CTX *pctx = NULL; EVP_KDF_CTX *kctx = NULL; int ret = 0; if (md == NULL) { Loading @@ -43,16 +43,22 @@ static int tls1_PRF(SSL *s, SSLerr(SSL_F_TLS1_PRF, ERR_R_INTERNAL_ERROR); return 0; } pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_TLS1_PRF, NULL); if (pctx == NULL || EVP_PKEY_derive_init(pctx) <= 0 || EVP_PKEY_CTX_set_tls1_prf_md(pctx, md) <= 0 || EVP_PKEY_CTX_set1_tls1_prf_secret(pctx, sec, (int)slen) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed1, (int)seed1_len) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed2, (int)seed2_len) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed3, (int)seed3_len) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed4, (int)seed4_len) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed5, (int)seed5_len) <= 0 || EVP_PKEY_derive(pctx, out, &olen) <= 0) { kctx = EVP_KDF_CTX_new_id(EVP_PKEY_TLS1_PRF); if (kctx == NULL || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_MD, md) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_TLS_SECRET, sec, (size_t)slen) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed1, (size_t)seed1_len) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed2, (size_t)seed2_len) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed3, (size_t)seed3_len) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed4, (size_t)seed4_len) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed5, (size_t)seed5_len) <= 0 || EVP_KDF_derive(kctx, out, olen) <= 0) { if (fatal) SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS1_PRF, ERR_R_INTERNAL_ERROR); Loading @@ -64,7 +70,7 @@ static int tls1_PRF(SSL *s, ret = 1; err: EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); return ret; } Loading ssl/tls13_enc.c +24 −26 Original line number Diff line number Diff line Loading @@ -31,7 +31,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, unsigned char *out, size_t outlen, int fatal) { static const unsigned char label_prefix[] = "tls13 "; EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL); EVP_KDF_CTX *kctx = EVP_KDF_CTX_new_id(EVP_PKEY_HKDF); int ret; size_t hkdflabellen; size_t hashlen; Loading @@ -45,7 +45,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, + 1 + EVP_MAX_MD_SIZE]; WPACKET pkt; if (pctx == NULL) if (kctx == NULL) return 0; if (labellen > TLS13_MAX_LABEL_LEN) { Loading @@ -59,7 +59,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, */ SSLerr(SSL_F_TLS13_HKDF_EXPAND, SSL_R_TLS_ILLEGAL_EXPORTER_LABEL); } EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); return 0; } Loading @@ -74,7 +74,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, || !WPACKET_sub_memcpy_u8(&pkt, data, (data == NULL) ? 0 : datalen) || !WPACKET_get_total_written(&pkt, &hkdflabellen) || !WPACKET_finish(&pkt)) { EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); WPACKET_cleanup(&pkt); if (fatal) SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_HKDF_EXPAND, Loading @@ -84,15 +84,15 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, return 0; } ret = EVP_PKEY_derive_init(pctx) <= 0 || EVP_PKEY_CTX_hkdf_mode(pctx, EVP_PKEY_HKDEF_MODE_EXPAND_ONLY) <= 0 || EVP_PKEY_CTX_set_hkdf_md(pctx, md) <= 0 || EVP_PKEY_CTX_set1_hkdf_key(pctx, secret, hashlen) <= 0 || EVP_PKEY_CTX_add1_hkdf_info(pctx, hkdflabel, hkdflabellen) <= 0 || EVP_PKEY_derive(pctx, out, &outlen) <= 0; ret = EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_HKDF_MODE, EVP_PKEY_HKDEF_MODE_EXPAND_ONLY) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_MD, md) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_KEY, secret, hashlen) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_HKDF_INFO, hkdflabel, hkdflabellen) <= 0 || EVP_KDF_derive(kctx, out, outlen) <= 0; EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); if (ret != 0) { if (fatal) Loading Loading @@ -155,11 +155,11 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md, size_t mdlen, prevsecretlen; int mdleni; int ret; EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL); EVP_KDF_CTX *kctx = EVP_KDF_CTX_new_id(EVP_PKEY_HKDF); static const char derived_secret_label[] = "derived"; unsigned char preextractsec[EVP_MAX_MD_SIZE]; if (pctx == NULL) { if (kctx == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_GENERATE_SECRET, ERR_R_INTERNAL_ERROR); return 0; Loading Loading @@ -192,7 +192,7 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md, SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_GENERATE_SECRET, ERR_R_INTERNAL_ERROR); EVP_MD_CTX_free(mctx); EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); return 0; } EVP_MD_CTX_free(mctx); Loading @@ -203,7 +203,7 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md, sizeof(derived_secret_label) - 1, hash, mdlen, preextractsec, mdlen, 1)) { /* SSLfatal() already called */ EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); return 0; } Loading @@ -211,21 +211,19 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md, prevsecretlen = mdlen; } ret = EVP_PKEY_derive_init(pctx) <= 0 || EVP_PKEY_CTX_hkdf_mode(pctx, EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY) <= 0 || EVP_PKEY_CTX_set_hkdf_md(pctx, md) <= 0 || EVP_PKEY_CTX_set1_hkdf_key(pctx, insecret, insecretlen) <= 0 || EVP_PKEY_CTX_set1_hkdf_salt(pctx, prevsecret, prevsecretlen) <= 0 || EVP_PKEY_derive(pctx, outsecret, &mdlen) <= 0; ret = EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_HKDF_MODE, EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_MD, md) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_KEY, insecret, insecretlen) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_SALT, prevsecret, prevsecretlen) <= 0 || EVP_KDF_derive(kctx, outsecret, mdlen) <= 0; if (ret != 0) SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_GENERATE_SECRET, ERR_R_INTERNAL_ERROR); EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); if (prevsecret == preextractsec) OPENSSL_cleanse(preextractsec, mdlen); return ret == 0; Loading Loading
ssl/t1_enc.c +18 −12 Original line number Diff line number Diff line Loading @@ -31,7 +31,7 @@ static int tls1_PRF(SSL *s, unsigned char *out, size_t olen, int fatal) { const EVP_MD *md = ssl_prf_md(s); EVP_PKEY_CTX *pctx = NULL; EVP_KDF_CTX *kctx = NULL; int ret = 0; if (md == NULL) { Loading @@ -43,16 +43,22 @@ static int tls1_PRF(SSL *s, SSLerr(SSL_F_TLS1_PRF, ERR_R_INTERNAL_ERROR); return 0; } pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_TLS1_PRF, NULL); if (pctx == NULL || EVP_PKEY_derive_init(pctx) <= 0 || EVP_PKEY_CTX_set_tls1_prf_md(pctx, md) <= 0 || EVP_PKEY_CTX_set1_tls1_prf_secret(pctx, sec, (int)slen) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed1, (int)seed1_len) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed2, (int)seed2_len) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed3, (int)seed3_len) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed4, (int)seed4_len) <= 0 || EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed5, (int)seed5_len) <= 0 || EVP_PKEY_derive(pctx, out, &olen) <= 0) { kctx = EVP_KDF_CTX_new_id(EVP_PKEY_TLS1_PRF); if (kctx == NULL || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_MD, md) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_TLS_SECRET, sec, (size_t)slen) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed1, (size_t)seed1_len) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed2, (size_t)seed2_len) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed3, (size_t)seed3_len) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed4, (size_t)seed4_len) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_TLS_SEED, seed5, (size_t)seed5_len) <= 0 || EVP_KDF_derive(kctx, out, olen) <= 0) { if (fatal) SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS1_PRF, ERR_R_INTERNAL_ERROR); Loading @@ -64,7 +70,7 @@ static int tls1_PRF(SSL *s, ret = 1; err: EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); return ret; } Loading
ssl/tls13_enc.c +24 −26 Original line number Diff line number Diff line Loading @@ -31,7 +31,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, unsigned char *out, size_t outlen, int fatal) { static const unsigned char label_prefix[] = "tls13 "; EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL); EVP_KDF_CTX *kctx = EVP_KDF_CTX_new_id(EVP_PKEY_HKDF); int ret; size_t hkdflabellen; size_t hashlen; Loading @@ -45,7 +45,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, + 1 + EVP_MAX_MD_SIZE]; WPACKET pkt; if (pctx == NULL) if (kctx == NULL) return 0; if (labellen > TLS13_MAX_LABEL_LEN) { Loading @@ -59,7 +59,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, */ SSLerr(SSL_F_TLS13_HKDF_EXPAND, SSL_R_TLS_ILLEGAL_EXPORTER_LABEL); } EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); return 0; } Loading @@ -74,7 +74,7 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, || !WPACKET_sub_memcpy_u8(&pkt, data, (data == NULL) ? 0 : datalen) || !WPACKET_get_total_written(&pkt, &hkdflabellen) || !WPACKET_finish(&pkt)) { EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); WPACKET_cleanup(&pkt); if (fatal) SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_HKDF_EXPAND, Loading @@ -84,15 +84,15 @@ int tls13_hkdf_expand(SSL *s, const EVP_MD *md, const unsigned char *secret, return 0; } ret = EVP_PKEY_derive_init(pctx) <= 0 || EVP_PKEY_CTX_hkdf_mode(pctx, EVP_PKEY_HKDEF_MODE_EXPAND_ONLY) <= 0 || EVP_PKEY_CTX_set_hkdf_md(pctx, md) <= 0 || EVP_PKEY_CTX_set1_hkdf_key(pctx, secret, hashlen) <= 0 || EVP_PKEY_CTX_add1_hkdf_info(pctx, hkdflabel, hkdflabellen) <= 0 || EVP_PKEY_derive(pctx, out, &outlen) <= 0; ret = EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_HKDF_MODE, EVP_PKEY_HKDEF_MODE_EXPAND_ONLY) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_MD, md) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_KEY, secret, hashlen) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_ADD_HKDF_INFO, hkdflabel, hkdflabellen) <= 0 || EVP_KDF_derive(kctx, out, outlen) <= 0; EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); if (ret != 0) { if (fatal) Loading Loading @@ -155,11 +155,11 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md, size_t mdlen, prevsecretlen; int mdleni; int ret; EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL); EVP_KDF_CTX *kctx = EVP_KDF_CTX_new_id(EVP_PKEY_HKDF); static const char derived_secret_label[] = "derived"; unsigned char preextractsec[EVP_MAX_MD_SIZE]; if (pctx == NULL) { if (kctx == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_GENERATE_SECRET, ERR_R_INTERNAL_ERROR); return 0; Loading Loading @@ -192,7 +192,7 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md, SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_GENERATE_SECRET, ERR_R_INTERNAL_ERROR); EVP_MD_CTX_free(mctx); EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); return 0; } EVP_MD_CTX_free(mctx); Loading @@ -203,7 +203,7 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md, sizeof(derived_secret_label) - 1, hash, mdlen, preextractsec, mdlen, 1)) { /* SSLfatal() already called */ EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); return 0; } Loading @@ -211,21 +211,19 @@ int tls13_generate_secret(SSL *s, const EVP_MD *md, prevsecretlen = mdlen; } ret = EVP_PKEY_derive_init(pctx) <= 0 || EVP_PKEY_CTX_hkdf_mode(pctx, EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY) <= 0 || EVP_PKEY_CTX_set_hkdf_md(pctx, md) <= 0 || EVP_PKEY_CTX_set1_hkdf_key(pctx, insecret, insecretlen) <= 0 || EVP_PKEY_CTX_set1_hkdf_salt(pctx, prevsecret, prevsecretlen) <= 0 || EVP_PKEY_derive(pctx, outsecret, &mdlen) <= 0; ret = EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_HKDF_MODE, EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_MD, md) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_KEY, insecret, insecretlen) <= 0 || EVP_KDF_ctrl(kctx, EVP_KDF_CTRL_SET_SALT, prevsecret, prevsecretlen) <= 0 || EVP_KDF_derive(kctx, outsecret, mdlen) <= 0; if (ret != 0) SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_F_TLS13_GENERATE_SECRET, ERR_R_INTERNAL_ERROR); EVP_PKEY_CTX_free(pctx); EVP_KDF_CTX_free(kctx); if (prevsecret == preextractsec) OPENSSL_cleanse(preextractsec, mdlen); return ret == 0; Loading