Move openssl evp digest functions to a separate file

P4:8088064,8088066
This commit is contained in:
Fletcher Dunn
2023-05-27 18:37:08 -07:00
parent bfd3d6e95b
commit 83ee762a7e
4 changed files with 96 additions and 92 deletions
+1
View File
@@ -70,6 +70,7 @@ if(USE_CRYPTO STREQUAL "OpenSSL")
set(GNS_CRYPTO_SRCS ${GNS_CRYPTO_SRCS}
"common/crypto_openssl.cpp"
"common/crypto_25519_openssl.cpp"
"common/crypto_digest_opensslevp.cpp"
"common/crypto_symmetric_opensslevp.cpp"
"common/opensslwrapper.cpp"
)
+4 -1
View File
@@ -7,6 +7,8 @@
#include "crypto_constants.h"
#include "keypair.h"
constexpr int k_cb25519KeySize = 32;
class CEC25519KeyBase : public CCryptoKeyBase_RawBuffer
{
public:
@@ -53,6 +55,7 @@ public:
bool MatchesPublicKey( const CEC25519PublicKeyBase &pPublicKey ) const;
const uint8 *GetPublicKeyRawData() const { return m_publicKey; }
inline static constexpr int GetPublicKeyRawDataSize() { return k_cb25519KeySize; }
protected:
CEC25519PrivateKeyBase( ECryptoKeyType eType ) : CEC25519KeyBase( eType ) { }
@@ -60,7 +63,7 @@ protected:
// We keep a copy of the public key cached.
// It is not considered part of the raw key data,
// as was previously the case.)
uint8 m_publicKey[32];
uint8 m_publicKey[k_cb25519KeySize];
bool CachePublicKey();
virtual bool SetRawData( const void *pData, size_t cbData ) override;
+91
View File
@@ -0,0 +1,91 @@
//========= Copyright Valve LLC, All rights reserved. ========================
#include "crypto.h"
#ifdef VALVE_CRYPTO_OPENSSL
#include <tier0/dbg.h>
#include <tier0/vprof.h>
#include "tier0/memdbgoff.h"
#include <openssl/evp.h>
#include <openssl/hmac.h>
#include "tier0/memdbgon.h"
#if OPENSSL_VERSION_NUMBER < 0x10100000
inline void EVP_MD_CTX_free( EVP_MD_CTX *ctx )
{
EVP_MD_CTX_destroy( ctx );
}
#endif
template < typename CTXType, void(*CleanupFunc)(CTXType)>
class EVPCTXPointer
{
public:
CTXType ctx;
EVPCTXPointer() { this->ctx = NULL; }
EVPCTXPointer(CTXType ctx) { this->ctx = ctx; }
~EVPCTXPointer() { CleanupFunc(ctx); }
};
//-----------------------------------------------------------------------------
// Generate a SHA256 hash
//-----------------------------------------------------------------------------
void CCrypto::GenerateSHA256Digest( const void *pInput, size_t cbInput, SHA256Digest_t *pOutDigest )
{
VPROF_BUDGET( "CCrypto::GenerateSHA256Digest", VPROF_BUDGETGROUP_ENCRYPTION );
//Assert( pubInput );
Assert( pOutDigest );
EVPCTXPointer<EVP_MD_CTX *, EVP_MD_CTX_free> ctx(EVP_MD_CTX_create());
unsigned int digest_len = sizeof(SHA256Digest_t);
VerifyFatal(ctx.ctx != NULL);
VerifyFatal(EVP_DigestInit_ex(ctx.ctx, EVP_sha256(), NULL) == 1);
VerifyFatal(EVP_DigestUpdate(ctx.ctx, pInput, cbInput) == 1);
VerifyFatal(EVP_DigestFinal(ctx.ctx, *pOutDigest, &digest_len) == 1);
}
//-----------------------------------------------------------------------------
// Purpose: Generate a keyed-hash MAC using SHA-256
//-----------------------------------------------------------------------------
void CCrypto::GenerateHMAC256( const uint8 *pubData, uint32 cubData, const uint8 *pubKey, uint32 cubKey, SHA256Digest_t *pOutputDigest )
{
VPROF_BUDGET( "CCrypto::GenerateHMAC256", VPROF_BUDGETGROUP_ENCRYPTION );
Assert( pubData );
Assert( cubData > 0 );
Assert( pubKey );
Assert( cubKey > 0 );
Assert( pOutputDigest );
EVPCTXPointer<EVP_MD_CTX *, EVP_MD_CTX_free> mdctx(EVP_MD_CTX_create());
EVPCTXPointer<EVP_PKEY *, EVP_PKEY_free> pkey(EVP_PKEY_new_mac_key(EVP_PKEY_HMAC, NULL, pubKey, cubKey));
const EVP_MD *digest = EVP_sha256();
VerifyFatal(mdctx.ctx != NULL && pkey.ctx != NULL);
VerifyFatal(EVP_DigestInit_ex(mdctx.ctx, digest, NULL) == 1);
VerifyFatal(EVP_DigestSignInit(mdctx.ctx, NULL, digest, NULL, pkey.ctx) == 1);
VerifyFatal(EVP_DigestSignUpdate(mdctx.ctx, pubData, cubData) == 1);
size_t needed = sizeof(SHA256Digest_t);
VerifyFatal(EVP_DigestSignFinal(mdctx.ctx, *pOutputDigest, &needed) == 1);
}
//-----------------------------------------------------------------------------
// Purpose: Generate a keyed-hash MAC using SHA1
//-----------------------------------------------------------------------------
void CCrypto::GenerateHMAC( const uint8 *pubData, uint32 cubData, const uint8 *pubKey, uint32 cubKey, SHADigest_t *pOutputDigest )
{
VPROF_BUDGET( "CCrypto::GenerateHMAC", VPROF_BUDGETGROUP_ENCRYPTION );
Assert( pubData );
Assert( cubData > 0 );
Assert( pubKey );
Assert( cubKey > 0 );
Assert( pOutputDigest );
unsigned int needed = (unsigned int)sizeof(SHADigest_t);
HMAC( EVP_sha1(), pubKey, cubKey, pubData, cubData, (unsigned char*)pOutputDigest, &needed );
}
#endif // VALVE_CRYPTO_OPENSSL
-91
View File
@@ -19,23 +19,9 @@
#include <tier0/vprof.h>
#include <tier1/utlmemory.h>
#include "crypto.h"
#include "tier0/memdbgoff.h"
#include <openssl/evp.h>
#include <openssl/pem.h>
#include <openssl/hmac.h>
#include "tier0/memdbgon.h"
#include "opensslwrapper.h"
#if OPENSSL_VERSION_NUMBER < 0x10100000
inline void EVP_MD_CTX_free( EVP_MD_CTX *ctx )
{
EVP_MD_CTX_destroy( ctx );
}
#endif
void OneTimeCryptoInitOpenSSL()
{
static bool once;
@@ -52,36 +38,6 @@ void CCrypto::Init()
OneTimeCryptoInitOpenSSL();
}
template < typename CTXType, void(*CleanupFunc)(CTXType)>
class EVPCTXPointer
{
public:
CTXType ctx;
EVPCTXPointer() { this->ctx = NULL; }
EVPCTXPointer(CTXType ctx) { this->ctx = ctx; }
~EVPCTXPointer() { CleanupFunc(ctx); }
};
//-----------------------------------------------------------------------------
// Purpose: Generate a SHA256 hash
// Input: pchInput - Plaintext string of item to hash (null terminated)
// pOutDigest - Pointer to receive hashed digest output
//-----------------------------------------------------------------------------
void CCrypto::GenerateSHA256Digest( const void *pInput, size_t cbInput, SHA256Digest_t *pOutDigest )
{
VPROF_BUDGET( "CCrypto::GenerateSHA256Digest", VPROF_BUDGETGROUP_ENCRYPTION );
//Assert( pubInput );
Assert( pOutDigest );
EVPCTXPointer<EVP_MD_CTX *, EVP_MD_CTX_free> ctx(EVP_MD_CTX_create());
unsigned int digest_len = sizeof(SHA256Digest_t);
VerifyFatal(ctx.ctx != NULL);
VerifyFatal(EVP_DigestInit_ex(ctx.ctx, EVP_sha256(), NULL) == 1);
VerifyFatal(EVP_DigestUpdate(ctx.ctx, pInput, cbInput) == 1);
VerifyFatal(EVP_DigestFinal(ctx.ctx, *pOutDigest, &digest_len) == 1);
}
//-----------------------------------------------------------------------------
// Purpose: Generates a cryptographiacally random block of data fit for any use.
@@ -139,51 +95,4 @@ void CCrypto::GenerateRandomBlock( void *pvDest, int cubDest )
#endif
}
//-----------------------------------------------------------------------------
// Purpose: Generate a keyed-hash MAC using SHA-256
//-----------------------------------------------------------------------------
void CCrypto::GenerateHMAC256( const uint8 *pubData, uint32 cubData, const uint8 *pubKey, uint32 cubKey, SHA256Digest_t *pOutputDigest )
{
VPROF_BUDGET( "CCrypto::GenerateHMAC256", VPROF_BUDGETGROUP_ENCRYPTION );
Assert( pubData );
Assert( cubData > 0 );
Assert( pubKey );
Assert( cubKey > 0 );
Assert( pOutputDigest );
EVPCTXPointer<EVP_MD_CTX *, EVP_MD_CTX_free> mdctx(EVP_MD_CTX_create());
EVPCTXPointer<EVP_PKEY *, EVP_PKEY_free> pkey(EVP_PKEY_new_mac_key(EVP_PKEY_HMAC, NULL, pubKey, cubKey));
const EVP_MD *digest = EVP_sha256();
VerifyFatal(mdctx.ctx != NULL && pkey.ctx != NULL);
VerifyFatal(EVP_DigestInit_ex(mdctx.ctx, digest, NULL) == 1);
VerifyFatal(EVP_DigestSignInit(mdctx.ctx, NULL, digest, NULL, pkey.ctx) == 1);
VerifyFatal(EVP_DigestSignUpdate(mdctx.ctx, pubData, cubData) == 1);
size_t needed = sizeof(SHA256Digest_t);
VerifyFatal(EVP_DigestSignFinal(mdctx.ctx, *pOutputDigest, &needed) == 1);
}
//-----------------------------------------------------------------------------
// Purpose: Generate a keyed-hash MAC using SHA1
// Input: pubData - Plaintext data to digest
// cubData - length of data
// pubKey - key to use in HMAC
// cubKey - length of key
// pOutDigest - Pointer to receive hashed digest output
//-----------------------------------------------------------------------------
void CCrypto::GenerateHMAC( const uint8 *pubData, uint32 cubData, const uint8 *pubKey, uint32 cubKey, SHADigest_t *pOutputDigest )
{
VPROF_BUDGET( "CCrypto::GenerateHMAC", VPROF_BUDGETGROUP_ENCRYPTION );
Assert( pubData );
Assert( cubData > 0 );
Assert( pubKey );
Assert( cubKey > 0 );
Assert( pOutputDigest );
unsigned int needed = (unsigned int)sizeof(SHADigest_t);
HMAC( EVP_sha1(), pubKey, cubKey, pubData, cubData, (unsigned char*)pOutputDigest, &needed );
}
#endif // VALVE_CRYPTO_OPENSSL