blob: cf7f1f6b55c3d10c584f4d6f7f0a7887d42124b2 [file] [log] [blame]
Paul Bakkerb0c19a42013-06-24 19:26:38 +02001/**
Paul Bakkerdcbfdcc2013-09-10 16:16:50 +02002 * \file pkcs5.h
Paul Bakkerb0c19a42013-06-24 19:26:38 +02003 *
4 * \brief PKCS#5 functions
5 *
6 * \author Mathias Olsson <mathias@kompetensum.com>
7 *
Manuel Pégourié-Gonnarda658a402015-01-23 09:45:19 +00008 * Copyright (C) 2006-2013, ARM Limited, All Rights Reserved
Paul Bakkerb0c19a42013-06-24 19:26:38 +02009 *
Manuel Pégourié-Gonnard967a2a52015-01-22 14:28:16 +000010 * This file is part of mbed TLS (http://www.polarssl.org)
Paul Bakkerb0c19a42013-06-24 19:26:38 +020011 * Lead Maintainer: Paul Bakker <polarssl_maintainer at polarssl.org>
12 *
Paul Bakkerb0c19a42013-06-24 19:26:38 +020013 * This program is free software; you can redistribute it and/or modify
14 * it under the terms of the GNU General Public License as published by
15 * the Free Software Foundation; either version 2 of the License, or
16 * (at your option) any later version.
17 *
18 * This program is distributed in the hope that it will be useful,
19 * but WITHOUT ANY WARRANTY; without even the implied warranty of
20 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21 * GNU General Public License for more details.
22 *
23 * You should have received a copy of the GNU General Public License along
24 * with this program; if not, write to the Free Software Foundation, Inc.,
25 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
26 */
27#ifndef POLARSSL_PKCS5_H
28#define POLARSSL_PKCS5_H
29
30#include <string.h>
31
Paul Bakker28144de2013-06-24 19:28:55 +020032#include "asn1.h"
Paul Bakkerb0c19a42013-06-24 19:26:38 +020033#include "md.h"
34
Paul Bakkerfa6a6202013-10-28 18:48:30 +010035#if defined(_MSC_VER) && !defined(EFIX64) && !defined(EFI32)
Paul Bakkerb0c19a42013-06-24 19:26:38 +020036#include <basetsd.h>
37typedef UINT32 uint32_t;
38#else
39#include <inttypes.h>
40#endif
41
Paul Bakker28144de2013-06-24 19:28:55 +020042#define POLARSSL_ERR_PKCS5_BAD_INPUT_DATA -0x3f80 /**< Bad input parameters to function. */
43#define POLARSSL_ERR_PKCS5_INVALID_FORMAT -0x3f00 /**< Unexpected ASN.1 data. */
44#define POLARSSL_ERR_PKCS5_FEATURE_UNAVAILABLE -0x3e80 /**< Requested encryption or digest alg not available. */
45#define POLARSSL_ERR_PKCS5_PASSWORD_MISMATCH -0x3e00 /**< Given private key password does not allow for correct decryption. */
46
47#define PKCS5_DECRYPT 0
48#define PKCS5_ENCRYPT 1
49
Paul Bakkerb0c19a42013-06-24 19:26:38 +020050#ifdef __cplusplus
51extern "C" {
52#endif
53
54/**
Paul Bakker28144de2013-06-24 19:28:55 +020055 * \brief PKCS#5 PBES2 function
56 *
57 * \param pbe_params the ASN.1 algorithm parameters
58 * \param mode either PKCS5_DECRYPT or PKCS5_ENCRYPT
59 * \param pwd password to use when generating key
Paul Bakkerdcbfdcc2013-09-10 16:16:50 +020060 * \param pwdlen length of password
Paul Bakker28144de2013-06-24 19:28:55 +020061 * \param data data to process
62 * \param datalen length of data
63 * \param output output buffer
64 *
Manuel Pégourié-Gonnardb4fe3cb2015-01-22 16:11:05 +000065 * \returns 0 on success, or a POLARSSL_ERR_xxx code if verification fails.
Paul Bakker28144de2013-06-24 19:28:55 +020066 */
67int pkcs5_pbes2( asn1_buf *pbe_params, int mode,
68 const unsigned char *pwd, size_t pwdlen,
69 const unsigned char *data, size_t datalen,
70 unsigned char *output );
71
72/**
Paul Bakkerb0c19a42013-06-24 19:26:38 +020073 * \brief PKCS#5 PBKDF2 using HMAC
74 *
75 * \param ctx Generic HMAC context
76 * \param password Password to use when generating key
77 * \param plen Length of password
78 * \param salt Salt to use when generating key
79 * \param slen Length of salt
80 * \param iteration_count Iteration count
81 * \param key_length Length of generated key
82 * \param output Generated key. Must be at least as big as key_length
83 *
Manuel Pégourié-Gonnardb4fe3cb2015-01-22 16:11:05 +000084 * \returns 0 on success, or a POLARSSL_ERR_xxx code if verification fails.
Paul Bakkerb0c19a42013-06-24 19:26:38 +020085 */
86int pkcs5_pbkdf2_hmac( md_context_t *ctx, const unsigned char *password,
87 size_t plen, const unsigned char *salt, size_t slen,
88 unsigned int iteration_count,
89 uint32_t key_length, unsigned char *output );
90
91/**
92 * \brief Checkup routine
93 *
94 * \return 0 if successful, or 1 if the test failed
95 */
96int pkcs5_self_test( int verbose );
97
98#ifdef __cplusplus
99}
100#endif
101
102#endif /* pkcs5.h */