blob: b7c3256fb92c5f7a709a0d780d870c5d63281a00 [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/**
2 * \file dhm.h
Paul Bakkere0ccd0a2009-01-04 16:27:10 +00003 *
Darryl Green11999bb2018-03-13 15:22:58 +00004 * \brief This file contains Diffie-Hellman-Merkle (DHM) key exchange
Rose Zadikee963592018-04-18 09:46:12 +01005 * definitions and functions.
Rose Zadikf763f2b2018-04-17 11:00:40 +01006 *
7 * Diffie-Hellman-Merkle (DHM) key exchange is defined in
Darryl Green11999bb2018-03-13 15:22:58 +00008 * <em>RFC-2631: Diffie-Hellman Key Agreement Method</em> and
9 * <em>Public-Key Cryptography Standards (PKCS) #3: Diffie
Rose Zadikf763f2b2018-04-17 11:00:40 +010010 * Hellman Key Agreement Standard</em>.
Rose Zadik41ad0822018-01-26 10:54:57 +000011 *
12 * <em>RFC-3526: More Modular Exponential (MODP) Diffie-Hellman groups for
13 * Internet Key Exchange (IKE)</em> defines a number of standardized
14 * Diffie-Hellman groups for IKE.
15 *
16 * <em>RFC-5114: Additional Diffie-Hellman Groups for Use with IETF
17 * Standards</em> defines a number of standardized Diffie-Hellman
18 * groups that can be used.
Paul Bakker37ca75d2011-01-06 12:28:03 +000019 *
Jaeden Amero784de592018-01-26 17:52:01 +000020 * \warning The security of the DHM key exchange relies on the proper choice
21 * of prime modulus - optimally, it should be a safe prime. The usage
22 * of non-safe primes both decreases the difficulty of the underlying
23 * discrete logarithm problem and can lead to small subgroup attacks
24 * leaking private exponent bits when invalid public keys are used
25 * and not detected. This is especially relevant if the same DHM
26 * parameters are reused for multiple key exchanges as in static DHM,
27 * while the criticality of small-subgroup attacks is lower for
28 * ephemeral DHM.
29 *
30 * \warning For performance reasons, the code does neither perform primality
31 * nor safe primality tests, nor the expensive checks for invalid
32 * subgroups. Moreover, even if these were performed, non-standardized
33 * primes cannot be trusted because of the possibility of backdoors
34 * that can't be effectively checked for.
35 *
36 * \warning Diffie-Hellman-Merkle is therefore a security risk when not using
37 * standardized primes generated using a trustworthy ("nothing up
38 * my sleeve") method, such as the RFC 3526 / 7919 primes. In the TLS
39 * protocol, DH parameters need to be negotiated, so using the default
40 * primes systematically is not always an option. If possible, use
41 * Elliptic Curve Diffie-Hellman (ECDH), which has better performance,
42 * and for which the TLS protocol mandates the use of standard
43 * parameters.
44 *
Darryl Greena40a1012018-01-05 15:33:17 +000045 */
46/*
Bence Szépkúti1e148272020-08-07 13:07:28 +020047 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +020048 * SPDX-License-Identifier: Apache-2.0
49 *
50 * Licensed under the Apache License, Version 2.0 (the "License"); you may
51 * not use this file except in compliance with the License.
52 * You may obtain a copy of the License at
53 *
54 * http://www.apache.org/licenses/LICENSE-2.0
55 *
56 * Unless required by applicable law or agreed to in writing, software
57 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
58 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
59 * See the License for the specific language governing permissions and
60 * limitations under the License.
Paul Bakker5121ce52009-01-03 21:22:43 +000061 */
Rose Zadik41ad0822018-01-26 10:54:57 +000062
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020063#ifndef MBEDTLS_DHM_H
64#define MBEDTLS_DHM_H
Mateusz Starzyk846f0212021-05-19 19:44:07 +020065#include "mbedtls/private_access.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000066
Bence Szépkútic662b362021-05-27 11:25:03 +020067#include "mbedtls/build_info.h"
Jaeden Ameroc49fbbf2019-07-04 20:01:14 +010068#include "mbedtls/bignum.h"
Przemek Stekielcceb9332023-05-18 14:31:10 +020069#include <string.h>
Reuven Levin1f35ca92017-12-07 10:09:32 +000070
Paul Bakkerf3b86c12011-01-27 15:24:17 +000071/*
72 * DHM Error codes
73 */
Gilles Peskined2971572021-07-26 18:48:10 +020074/** Bad input parameters. */
75#define MBEDTLS_ERR_DHM_BAD_INPUT_DATA -0x3080
76/** Reading of the DHM parameters failed. */
77#define MBEDTLS_ERR_DHM_READ_PARAMS_FAILED -0x3100
78/** Making of the DHM parameters failed. */
79#define MBEDTLS_ERR_DHM_MAKE_PARAMS_FAILED -0x3180
80/** Reading of the public values failed. */
81#define MBEDTLS_ERR_DHM_READ_PUBLIC_FAILED -0x3200
82/** Making of the public value failed. */
83#define MBEDTLS_ERR_DHM_MAKE_PUBLIC_FAILED -0x3280
84/** Calculation of the DHM secret failed. */
85#define MBEDTLS_ERR_DHM_CALC_SECRET_FAILED -0x3300
86/** The ASN.1 data is not formatted correctly. */
87#define MBEDTLS_ERR_DHM_INVALID_FORMAT -0x3380
88/** Allocation of memory failed. */
89#define MBEDTLS_ERR_DHM_ALLOC_FAILED -0x3400
90/** Read or write of file failed. */
91#define MBEDTLS_ERR_DHM_FILE_IO_ERROR -0x3480
92/** Setting the modulus and generator failed. */
93#define MBEDTLS_ERR_DHM_SET_GROUP_FAILED -0x3580
Paul Bakker29b64762012-09-25 09:36:44 +000094
Przemek Stekielcceb9332023-05-18 14:31:10 +020095/* Finite Field Groups (DHE) */
96#define MBEDTLS_DHM_GROUP_FFDHE2048 0x0100
97#define MBEDTLS_DHM_GROUP_FFDHE3072 0x0101
98#define MBEDTLS_DHM_GROUP_FFDHE4096 0x0102
99#define MBEDTLS_DHM_GROUP_FFDHE6144 0x0103
100#define MBEDTLS_DHM_GROUP_FFDHE8192 0x0104
101
102/* Finite Field Group Names (DHE) */
103#define MBEDTLS_DHM_GROUP_NAME_FFDHE2048 "ffdhe2048"
104#define MBEDTLS_DHM_GROUP_NAME_FFDHE3072 "ffdhe3072"
105#define MBEDTLS_DHM_GROUP_NAME_FFDHE4096 "ffdhe4096"
106#define MBEDTLS_DHM_GROUP_NAME_FFDHE6144 "ffdhe6144"
107#define MBEDTLS_DHM_GROUP_NAME_FFDHE8192 "ffdhe8192"
108
Gilles Peskine71acc6e2021-05-27 22:50:53 +0200109/** Which parameter to access in mbedtls_dhm_get_value(). */
Gilles Peskine449bd832023-01-11 14:50:10 +0100110typedef enum {
Gilles Peskine71acc6e2021-05-27 22:50:53 +0200111 MBEDTLS_DHM_PARAM_P, /*!< The prime modulus. */
112 MBEDTLS_DHM_PARAM_G, /*!< The generator. */
113 MBEDTLS_DHM_PARAM_X, /*!< Our secret value. */
114 MBEDTLS_DHM_PARAM_GX, /*!< Our public key = \c G^X mod \c P. */
115 MBEDTLS_DHM_PARAM_GY, /*!< The public key of the peer = \c G^Y mod \c P. */
116 MBEDTLS_DHM_PARAM_K, /*!< The shared secret = \c G^(XY) mod \c P. */
117} mbedtls_dhm_parameter;
118
Paul Bakker407a0da2013-06-27 14:29:21 +0200119#ifdef __cplusplus
120extern "C" {
121#endif
122
Ron Eldor4e6d55d2018-02-07 16:36:15 +0200123#if !defined(MBEDTLS_DHM_ALT)
124
Paul Bakker29b64762012-09-25 09:36:44 +0000125/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000126 * \brief The DHM context structure.
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000127 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100128typedef struct mbedtls_dhm_context {
Mateusz Starzyk846f0212021-05-19 19:44:07 +0200129 mbedtls_mpi MBEDTLS_PRIVATE(P); /*!< The prime modulus. */
130 mbedtls_mpi MBEDTLS_PRIVATE(G); /*!< The generator. */
131 mbedtls_mpi MBEDTLS_PRIVATE(X); /*!< Our secret value. */
132 mbedtls_mpi MBEDTLS_PRIVATE(GX); /*!< Our public key = \c G^X mod \c P. */
133 mbedtls_mpi MBEDTLS_PRIVATE(GY); /*!< The public key of the peer = \c G^Y mod \c P. */
134 mbedtls_mpi MBEDTLS_PRIVATE(K); /*!< The shared secret = \c G^(XY) mod \c P. */
135 mbedtls_mpi MBEDTLS_PRIVATE(RP); /*!< The cached value = \c R^2 mod \c P. */
136 mbedtls_mpi MBEDTLS_PRIVATE(Vi); /*!< The blinding value. */
137 mbedtls_mpi MBEDTLS_PRIVATE(Vf); /*!< The unblinding value. */
138 mbedtls_mpi MBEDTLS_PRIVATE(pX); /*!< The previous \c X. */
Paul Bakker5121ce52009-01-03 21:22:43 +0000139}
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200140mbedtls_dhm_context;
Paul Bakker5121ce52009-01-03 21:22:43 +0000141
Ron Eldor4e6d55d2018-02-07 16:36:15 +0200142#else /* MBEDTLS_DHM_ALT */
143#include "dhm_alt.h"
144#endif /* MBEDTLS_DHM_ALT */
145
Paul Bakker5121ce52009-01-03 21:22:43 +0000146/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000147 * \brief This function initializes the DHM context.
Paul Bakker8f870b02014-06-20 13:32:38 +0200148 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000149 * \param ctx The DHM context to initialize.
Paul Bakker8f870b02014-06-20 13:32:38 +0200150 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100151void mbedtls_dhm_init(mbedtls_dhm_context *ctx);
Paul Bakker8f870b02014-06-20 13:32:38 +0200152
153/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500154 * \brief This function parses the DHM parameters in a
155 * TLS ServerKeyExchange handshake message
156 * (DHM modulus, generator, and public key).
Paul Bakker5121ce52009-01-03 21:22:43 +0000157 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500158 * \note In a TLS handshake, this is the how the client
159 * sets up its DHM context from the server's public
160 * DHM key material.
161 *
162 * \param ctx The DHM context to use. This must be initialized.
Hanno Beckerf240ea02017-10-02 15:09:14 +0100163 * \param p On input, *p must be the start of the input buffer.
164 * On output, *p is updated to point to the end of the data
165 * that has been read. On success, this is the first byte
166 * past the end of the ServerKeyExchange parameters.
167 * On error, this is the point at which an error has been
168 * detected, which is usually not useful except to debug
169 * failures.
Rose Zadik41ad0822018-01-26 10:54:57 +0000170 * \param end The end of the input buffer.
Paul Bakker5121ce52009-01-03 21:22:43 +0000171 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100172 * \return \c 0 on success.
173 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000174 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100175int mbedtls_dhm_read_params(mbedtls_dhm_context *ctx,
176 unsigned char **p,
177 const unsigned char *end);
Paul Bakker5121ce52009-01-03 21:22:43 +0000178
179/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500180 * \brief This function generates a DHM key pair and exports its
181 * public part together with the DHM parameters in the format
182 * used in a TLS ServerKeyExchange handshake message.
Paul Bakker5121ce52009-01-03 21:22:43 +0000183 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500184 * \note This function assumes that the DHM parameters \c ctx->P
185 * and \c ctx->G have already been properly set. For that, use
Jaeden Amero9564e972018-01-30 16:56:13 +0000186 * mbedtls_dhm_set_group() below in conjunction with
187 * mbedtls_mpi_read_binary() and mbedtls_mpi_read_string().
Paul Bakker5121ce52009-01-03 21:22:43 +0000188 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500189 * \note In a TLS handshake, this is the how the server generates
190 * and exports its DHM key material.
191 *
192 * \param ctx The DHM context to use. This must be initialized
193 * and have the DHM parameters set. It may or may not
194 * already have imported the peer's public key.
Rose Zadikf763f2b2018-04-17 11:00:40 +0100195 * \param x_size The private key size in Bytes.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500196 * \param olen The address at which to store the number of Bytes
197 * written on success. This must not be \c NULL.
198 * \param output The destination buffer. This must be a writable buffer of
199 * sufficient size to hold the reduced binary presentation of
200 * the modulus, the generator and the public key, each wrapped
201 * with a 2-byte length field. It is the responsibility of the
202 * caller to ensure that enough space is available. Refer to
203 * mbedtls_mpi_size() to computing the byte-size of an MPI.
204 * \param f_rng The RNG function. Must not be \c NULL.
205 * \param p_rng The RNG context to be passed to \p f_rng. This may be
206 * \c NULL if \p f_rng doesn't need a context parameter.
Rose Zadikf763f2b2018-04-17 11:00:40 +0100207 *
208 * \return \c 0 on success.
209 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000210 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100211int mbedtls_dhm_make_params(mbedtls_dhm_context *ctx, int x_size,
212 unsigned char *output, size_t *olen,
213 int (*f_rng)(void *, unsigned char *, size_t),
214 void *p_rng);
Paul Bakker5121ce52009-01-03 21:22:43 +0000215
216/**
Rose Zadikf763f2b2018-04-17 11:00:40 +0100217 * \brief This function sets the prime modulus and generator.
218 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500219 * \note This function can be used to set \c ctx->P, \c ctx->G
Rose Zadikf763f2b2018-04-17 11:00:40 +0100220 * in preparation for mbedtls_dhm_make_params().
Hanno Becker8880e752017-10-04 13:15:08 +0100221 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500222 * \param ctx The DHM context to configure. This must be initialized.
223 * \param P The MPI holding the DHM prime modulus. This must be
224 * an initialized MPI.
225 * \param G The MPI holding the DHM generator. This must be an
226 * initialized MPI.
Hanno Becker8880e752017-10-04 13:15:08 +0100227 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100228 * \return \c 0 if successful.
229 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Hanno Becker8880e752017-10-04 13:15:08 +0100230 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100231int mbedtls_dhm_set_group(mbedtls_dhm_context *ctx,
232 const mbedtls_mpi *P,
233 const mbedtls_mpi *G);
Hanno Becker8880e752017-10-04 13:15:08 +0100234
235/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500236 * \brief This function imports the raw public value of the peer.
Paul Bakker5121ce52009-01-03 21:22:43 +0000237 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500238 * \note In a TLS handshake, this is the how the server imports
239 * the Client's public DHM key.
240 *
241 * \param ctx The DHM context to use. This must be initialized and have
242 * its DHM parameters set, e.g. via mbedtls_dhm_set_group().
243 * It may or may not already have generated its own private key.
244 * \param input The input buffer containing the \c G^Y value of the peer.
245 * This must be a readable buffer of size \p ilen Bytes.
246 * \param ilen The size of the input buffer \p input in Bytes.
Paul Bakker5121ce52009-01-03 21:22:43 +0000247 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100248 * \return \c 0 on success.
249 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000250 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100251int mbedtls_dhm_read_public(mbedtls_dhm_context *ctx,
252 const unsigned char *input, size_t ilen);
Paul Bakker5121ce52009-01-03 21:22:43 +0000253
254/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500255 * \brief This function creates a DHM key pair and exports
256 * the raw public key in big-endian format.
Paul Bakker5121ce52009-01-03 21:22:43 +0000257 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100258 * \note The destination buffer is always fully written
259 * so as to contain a big-endian representation of G^X mod P.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500260 * If it is larger than \c ctx->len, it is padded accordingly
Rose Zadikf763f2b2018-04-17 11:00:40 +0100261 * with zero-bytes at the beginning.
262 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500263 * \param ctx The DHM context to use. This must be initialized and
264 * have the DHM parameters set. It may or may not already
265 * have imported the peer's public key.
Rose Zadikf763f2b2018-04-17 11:00:40 +0100266 * \param x_size The private key size in Bytes.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500267 * \param output The destination buffer. This must be a writable buffer of
268 * size \p olen Bytes.
269 * \param olen The length of the destination buffer. This must be at least
270 * equal to `ctx->len` (the size of \c P).
271 * \param f_rng The RNG function. This must not be \c NULL.
272 * \param p_rng The RNG context to be passed to \p f_rng. This may be \c NULL
273 * if \p f_rng doesn't need a context argument.
Paul Bakker5121ce52009-01-03 21:22:43 +0000274 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100275 * \return \c 0 on success.
276 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000277 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100278int mbedtls_dhm_make_public(mbedtls_dhm_context *ctx, int x_size,
279 unsigned char *output, size_t olen,
280 int (*f_rng)(void *, unsigned char *, size_t),
281 void *p_rng);
Paul Bakker5121ce52009-01-03 21:22:43 +0000282
283/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500284 * \brief This function derives and exports the shared secret
285 * \c (G^Y)^X mod \c P.
Paul Bakker5121ce52009-01-03 21:22:43 +0000286 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500287 * \note If \p f_rng is not \c NULL, it is used to blind the input as
288 * a countermeasure against timing attacks. Blinding is used
289 * only if our private key \c X is re-used, and not used
290 * otherwise. We recommend always passing a non-NULL
291 * \p f_rng argument.
Rose Zadikf763f2b2018-04-17 11:00:40 +0100292 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500293 * \param ctx The DHM context to use. This must be initialized
294 * and have its own private key generated and the peer's
295 * public key imported.
296 * \param output The buffer to write the generated shared key to. This
297 * must be a writable buffer of size \p output_size Bytes.
298 * \param output_size The size of the destination buffer. This must be at
299 * least the size of \c ctx->len (the size of \c P).
Rose Zadik41ad0822018-01-26 10:54:57 +0000300 * \param olen On exit, holds the actual number of Bytes written.
Manuel Pégourié-Gonnard1a877222021-06-15 11:29:26 +0200301 * \param f_rng The RNG function. Must not be \c NULL. Used for
302 * blinding.
303 * \param p_rng The RNG context to be passed to \p f_rng. This may be
304 * \c NULL if \p f_rng doesn't need a context parameter.
Paul Bakker5121ce52009-01-03 21:22:43 +0000305 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100306 * \return \c 0 on success.
307 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000308 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100309int mbedtls_dhm_calc_secret(mbedtls_dhm_context *ctx,
310 unsigned char *output, size_t output_size, size_t *olen,
311 int (*f_rng)(void *, unsigned char *, size_t),
312 void *p_rng);
Paul Bakker5121ce52009-01-03 21:22:43 +0000313
Paul Bakker9a736322012-11-14 12:39:52 +0000314/**
Gilles Peskine487bbf62021-05-27 22:17:07 +0200315 * \brief This function returns the size of the prime modulus in bits.
316 *
317 * \param ctx The DHM context to query.
318 *
319 * \return The size of the prime modulus in bits,
320 * i.e. the number n such that 2^(n-1) <= P < 2^n.
321 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100322size_t mbedtls_dhm_get_bitlen(const mbedtls_dhm_context *ctx);
Gilles Peskine487bbf62021-05-27 22:17:07 +0200323
324/**
325 * \brief This function returns the size of the prime modulus in bytes.
326 *
327 * \param ctx The DHM context to query.
328 *
329 * \return The size of the prime modulus in bytes,
330 * i.e. the number n such that 2^(8*(n-1)) <= P < 2^(8*n).
331 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100332size_t mbedtls_dhm_get_len(const mbedtls_dhm_context *ctx);
Gilles Peskine487bbf62021-05-27 22:17:07 +0200333
334/**
Gilles Peskine71acc6e2021-05-27 22:50:53 +0200335 * \brief This function copies a parameter of a DHM key.
336 *
Gilles Peskine71acc6e2021-05-27 22:50:53 +0200337 * \param ctx The DHM context to query.
338 * \param param The parameter to copy.
Gilles Peskinee5702482021-06-11 21:59:08 +0200339 * \param dest The MPI object to copy the value into. It must be
340 * initialized.
Gilles Peskine71acc6e2021-05-27 22:50:53 +0200341 *
342 * \return \c 0 on success.
343 * \return #MBEDTLS_ERR_DHM_BAD_INPUT_DATA if \p field is invalid.
344 * \return An \c MBEDTLS_ERR_MPI_XXX error code if the copy fails.
345 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100346int mbedtls_dhm_get_value(const mbedtls_dhm_context *ctx,
347 mbedtls_dhm_parameter param,
348 mbedtls_mpi *dest);
Gilles Peskine71acc6e2021-05-27 22:50:53 +0200349
350/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500351 * \brief This function frees and clears the components
352 * of a DHM context.
Paul Bakker8f870b02014-06-20 13:32:38 +0200353 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500354 * \param ctx The DHM context to free and clear. This may be \c NULL,
355 * in which case this function is a no-op. If it is not \c NULL,
356 * it must point to an initialized DHM context.
Paul Bakker5121ce52009-01-03 21:22:43 +0000357 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100358void mbedtls_dhm_free(mbedtls_dhm_context *ctx);
Paul Bakker5121ce52009-01-03 21:22:43 +0000359
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200360#if defined(MBEDTLS_ASN1_PARSE_C)
Paul Bakker40ce79f2013-09-15 17:43:54 +0200361/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000362 * \brief This function parses DHM parameters in PEM or DER format.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200363 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500364 * \param dhm The DHM context to import the DHM parameters into.
365 * This must be initialized.
366 * \param dhmin The input buffer. This must be a readable buffer of
367 * length \p dhminlen Bytes.
368 * \param dhminlen The size of the input buffer \p dhmin, including the
369 * terminating \c NULL Byte for PEM data.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200370 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100371 * \return \c 0 on success.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500372 * \return An \c MBEDTLS_ERR_DHM_XXX or \c MBEDTLS_ERR_PEM_XXX error
373 * code on failure.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200374 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100375int mbedtls_dhm_parse_dhm(mbedtls_dhm_context *dhm, const unsigned char *dhmin,
376 size_t dhminlen);
Paul Bakker40ce79f2013-09-15 17:43:54 +0200377
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200378#if defined(MBEDTLS_FS_IO)
Paul Bakker40ce79f2013-09-15 17:43:54 +0200379/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000380 * \brief This function loads and parses DHM parameters from a file.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200381 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000382 * \param dhm The DHM context to load the parameters to.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500383 * This must be initialized.
Rose Zadik41ad0822018-01-26 10:54:57 +0000384 * \param path The filename to read the DHM parameters from.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500385 * This must not be \c NULL.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200386 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100387 * \return \c 0 on success.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500388 * \return An \c MBEDTLS_ERR_DHM_XXX or \c MBEDTLS_ERR_PEM_XXX
389 * error code on failure.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200390 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100391int mbedtls_dhm_parse_dhmfile(mbedtls_dhm_context *dhm, const char *path);
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200392#endif /* MBEDTLS_FS_IO */
393#endif /* MBEDTLS_ASN1_PARSE_C */
nirekh01d569ecf2018-01-09 16:43:21 +0000394
Przemek Stekielcceb9332023-05-18 14:31:10 +0200395static inline uint16_t mbedtls_ssl_ffdh_group_from_name(const char *name)
396{
397 if (strcmp(name, MBEDTLS_DHM_GROUP_NAME_FFDHE2048) == 0) {
398 return MBEDTLS_DHM_GROUP_FFDHE2048;
399 } else if (strcmp(name, MBEDTLS_DHM_GROUP_NAME_FFDHE3072) == 0) {
400 return MBEDTLS_DHM_GROUP_FFDHE3072;
401 } else if (strcmp(name, MBEDTLS_DHM_GROUP_NAME_FFDHE4096) == 0) {
402 return MBEDTLS_DHM_GROUP_FFDHE4096;
403 } else if (strcmp(name, MBEDTLS_DHM_GROUP_NAME_FFDHE6144) == 0) {
404 return MBEDTLS_DHM_GROUP_FFDHE6144;
405 } else if (strcmp(name, MBEDTLS_DHM_GROUP_NAME_FFDHE8192) == 0) {
406 return MBEDTLS_DHM_GROUP_FFDHE8192;
407 }
408 return 0;
409}
410
411static inline const char *mbedtls_ssl_ffdh_name_from_group(uint16_t group)
412{
413 switch (group) {
414 case MBEDTLS_DHM_GROUP_FFDHE2048:
415 return MBEDTLS_DHM_GROUP_NAME_FFDHE2048;
416 case MBEDTLS_DHM_GROUP_FFDHE3072:
417 return MBEDTLS_DHM_GROUP_NAME_FFDHE3072;
418 case MBEDTLS_DHM_GROUP_FFDHE4096:
419 return MBEDTLS_DHM_GROUP_NAME_FFDHE4096;
420 case MBEDTLS_DHM_GROUP_FFDHE6144:
421 return MBEDTLS_DHM_GROUP_NAME_FFDHE6144;
422 case MBEDTLS_DHM_GROUP_FFDHE8192:
423 return MBEDTLS_DHM_GROUP_NAME_FFDHE8192;
424 default:
425 return NULL;
426 }
427 return NULL;
428}
429
430static inline uint16_t *mbedtls_ssl_ffdh_supported_groups(void)
431{
432 static uint16_t ffdh_groups[] = {
433 MBEDTLS_DHM_GROUP_FFDHE2048,
434 MBEDTLS_DHM_GROUP_FFDHE3072,
435 MBEDTLS_DHM_GROUP_FFDHE4096,
436 MBEDTLS_DHM_GROUP_FFDHE6144,
437 MBEDTLS_DHM_GROUP_FFDHE8192,
438 0
439 };
440
441 return ffdh_groups;
442}
443
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500444#if defined(MBEDTLS_SELF_TEST)
445
Paul Bakker5121ce52009-01-03 21:22:43 +0000446/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000447 * \brief The DMH checkup routine.
Paul Bakker5121ce52009-01-03 21:22:43 +0000448 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100449 * \return \c 0 on success.
450 * \return \c 1 on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000451 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100452int mbedtls_dhm_self_test(int verbose);
Paul Bakker5121ce52009-01-03 21:22:43 +0000453
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500454#endif /* MBEDTLS_SELF_TEST */
Paul Bakker5121ce52009-01-03 21:22:43 +0000455#ifdef __cplusplus
456}
457#endif
458
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100459/**
Gilles Peskined40f0072020-02-26 19:52:04 +0100460 * RFC 3526, RFC 5114 and RFC 7919 standardize a number of
461 * Diffie-Hellman groups, some of which are included here
462 * for use within the SSL/TLS module and the user's convenience
463 * when configuring the Diffie-Hellman parameters by hand
464 * through \c mbedtls_ssl_conf_dh_param.
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100465 *
Jaeden Amero9564e972018-01-30 16:56:13 +0000466 * The following lists the source of the above groups in the standards:
467 * - RFC 5114 section 2.2: 2048-bit MODP Group with 224-bit Prime Order Subgroup
468 * - RFC 3526 section 3: 2048-bit MODP Group
469 * - RFC 3526 section 4: 3072-bit MODP Group
470 * - RFC 3526 section 5: 4096-bit MODP Group
471 * - RFC 7919 section A.1: ffdhe2048
472 * - RFC 7919 section A.2: ffdhe3072
473 * - RFC 7919 section A.3: ffdhe4096
474 * - RFC 7919 section A.4: ffdhe6144
475 * - RFC 7919 section A.5: ffdhe8192
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100476 *
477 * The constants with suffix "_p" denote the chosen prime moduli, while
478 * the constants with suffix "_g" denote the chosen generator
479 * of the associated prime field.
480 *
481 * The constants further suffixed with "_bin" are provided in binary format,
482 * while all other constants represent null-terminated strings holding the
483 * hexadecimal presentation of the respective numbers.
484 *
485 * The primes from RFC 3526 and RFC 7919 have been generating by the following
486 * trust-worthy procedure:
487 * - Fix N in { 2048, 3072, 4096, 6144, 8192 } and consider the N-bit number
488 * the first and last 64 bits are all 1, and the remaining N - 128 bits of
489 * which are 0x7ff...ff.
490 * - Add the smallest multiple of the first N - 129 bits of the binary expansion
491 * of pi (for RFC 5236) or e (for RFC 7919) to this intermediate bit-string
492 * such that the resulting integer is a safe-prime.
493 * - The result is the respective RFC 3526 / 7919 prime, and the corresponding
494 * generator is always chosen to be 2 (which is a square for these prime,
495 * hence the corresponding subgroup has order (p-1)/2 and avoids leaking a
496 * bit in the private exponent).
497 *
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100498 */
499
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100500/*
501 * Trustworthy DHM parameters in binary form
502 */
503
504#define MBEDTLS_DHM_RFC3526_MODP_2048_P_BIN { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100505 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
506 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
507 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
508 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
509 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
510 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
511 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
512 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
513 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
514 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
515 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
516 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
517 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
518 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
519 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
520 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
521 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
522 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
523 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
524 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
525 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
526 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
527 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
528 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
529 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
530 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
531 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
532 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
533 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
534 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
535 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAC, 0xAA, 0x68, \
536 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100537
538#define MBEDTLS_DHM_RFC3526_MODP_2048_G_BIN { 0x02 }
539
540#define MBEDTLS_DHM_RFC3526_MODP_3072_P_BIN { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100541 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
542 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
543 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
544 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
545 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
546 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
547 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
548 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
549 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
550 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
551 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
552 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
553 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
554 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
555 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
556 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
557 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
558 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
559 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
560 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
561 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
562 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
563 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
564 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
565 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
566 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
567 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
568 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
569 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
570 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
571 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAA, 0xC4, 0x2D, \
572 0xAD, 0x33, 0x17, 0x0D, 0x04, 0x50, 0x7A, 0x33, \
573 0xA8, 0x55, 0x21, 0xAB, 0xDF, 0x1C, 0xBA, 0x64, \
574 0xEC, 0xFB, 0x85, 0x04, 0x58, 0xDB, 0xEF, 0x0A, \
575 0x8A, 0xEA, 0x71, 0x57, 0x5D, 0x06, 0x0C, 0x7D, \
576 0xB3, 0x97, 0x0F, 0x85, 0xA6, 0xE1, 0xE4, 0xC7, \
577 0xAB, 0xF5, 0xAE, 0x8C, 0xDB, 0x09, 0x33, 0xD7, \
578 0x1E, 0x8C, 0x94, 0xE0, 0x4A, 0x25, 0x61, 0x9D, \
579 0xCE, 0xE3, 0xD2, 0x26, 0x1A, 0xD2, 0xEE, 0x6B, \
580 0xF1, 0x2F, 0xFA, 0x06, 0xD9, 0x8A, 0x08, 0x64, \
581 0xD8, 0x76, 0x02, 0x73, 0x3E, 0xC8, 0x6A, 0x64, \
582 0x52, 0x1F, 0x2B, 0x18, 0x17, 0x7B, 0x20, 0x0C, \
583 0xBB, 0xE1, 0x17, 0x57, 0x7A, 0x61, 0x5D, 0x6C, \
584 0x77, 0x09, 0x88, 0xC0, 0xBA, 0xD9, 0x46, 0xE2, \
585 0x08, 0xE2, 0x4F, 0xA0, 0x74, 0xE5, 0xAB, 0x31, \
586 0x43, 0xDB, 0x5B, 0xFC, 0xE0, 0xFD, 0x10, 0x8E, \
587 0x4B, 0x82, 0xD1, 0x20, 0xA9, 0x3A, 0xD2, 0xCA, \
588 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100589
590#define MBEDTLS_DHM_RFC3526_MODP_3072_G_BIN { 0x02 }
591
592#define MBEDTLS_DHM_RFC3526_MODP_4096_P_BIN { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100593 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
594 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
595 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
596 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
597 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
598 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
599 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
600 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
601 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
602 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
603 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
604 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
605 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
606 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
607 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
608 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
609 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
610 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
611 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
612 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
613 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
614 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
615 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
616 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
617 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
618 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
619 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
620 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
621 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
622 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
623 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAA, 0xC4, 0x2D, \
624 0xAD, 0x33, 0x17, 0x0D, 0x04, 0x50, 0x7A, 0x33, \
625 0xA8, 0x55, 0x21, 0xAB, 0xDF, 0x1C, 0xBA, 0x64, \
626 0xEC, 0xFB, 0x85, 0x04, 0x58, 0xDB, 0xEF, 0x0A, \
627 0x8A, 0xEA, 0x71, 0x57, 0x5D, 0x06, 0x0C, 0x7D, \
628 0xB3, 0x97, 0x0F, 0x85, 0xA6, 0xE1, 0xE4, 0xC7, \
629 0xAB, 0xF5, 0xAE, 0x8C, 0xDB, 0x09, 0x33, 0xD7, \
630 0x1E, 0x8C, 0x94, 0xE0, 0x4A, 0x25, 0x61, 0x9D, \
631 0xCE, 0xE3, 0xD2, 0x26, 0x1A, 0xD2, 0xEE, 0x6B, \
632 0xF1, 0x2F, 0xFA, 0x06, 0xD9, 0x8A, 0x08, 0x64, \
633 0xD8, 0x76, 0x02, 0x73, 0x3E, 0xC8, 0x6A, 0x64, \
634 0x52, 0x1F, 0x2B, 0x18, 0x17, 0x7B, 0x20, 0x0C, \
635 0xBB, 0xE1, 0x17, 0x57, 0x7A, 0x61, 0x5D, 0x6C, \
636 0x77, 0x09, 0x88, 0xC0, 0xBA, 0xD9, 0x46, 0xE2, \
637 0x08, 0xE2, 0x4F, 0xA0, 0x74, 0xE5, 0xAB, 0x31, \
638 0x43, 0xDB, 0x5B, 0xFC, 0xE0, 0xFD, 0x10, 0x8E, \
639 0x4B, 0x82, 0xD1, 0x20, 0xA9, 0x21, 0x08, 0x01, \
640 0x1A, 0x72, 0x3C, 0x12, 0xA7, 0x87, 0xE6, 0xD7, \
641 0x88, 0x71, 0x9A, 0x10, 0xBD, 0xBA, 0x5B, 0x26, \
642 0x99, 0xC3, 0x27, 0x18, 0x6A, 0xF4, 0xE2, 0x3C, \
643 0x1A, 0x94, 0x68, 0x34, 0xB6, 0x15, 0x0B, 0xDA, \
644 0x25, 0x83, 0xE9, 0xCA, 0x2A, 0xD4, 0x4C, 0xE8, \
645 0xDB, 0xBB, 0xC2, 0xDB, 0x04, 0xDE, 0x8E, 0xF9, \
646 0x2E, 0x8E, 0xFC, 0x14, 0x1F, 0xBE, 0xCA, 0xA6, \
647 0x28, 0x7C, 0x59, 0x47, 0x4E, 0x6B, 0xC0, 0x5D, \
648 0x99, 0xB2, 0x96, 0x4F, 0xA0, 0x90, 0xC3, 0xA2, \
649 0x23, 0x3B, 0xA1, 0x86, 0x51, 0x5B, 0xE7, 0xED, \
650 0x1F, 0x61, 0x29, 0x70, 0xCE, 0xE2, 0xD7, 0xAF, \
651 0xB8, 0x1B, 0xDD, 0x76, 0x21, 0x70, 0x48, 0x1C, \
652 0xD0, 0x06, 0x91, 0x27, 0xD5, 0xB0, 0x5A, 0xA9, \
653 0x93, 0xB4, 0xEA, 0x98, 0x8D, 0x8F, 0xDD, 0xC1, \
654 0x86, 0xFF, 0xB7, 0xDC, 0x90, 0xA6, 0xC0, 0x8F, \
655 0x4D, 0xF4, 0x35, 0xC9, 0x34, 0x06, 0x31, 0x99, \
656 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100657
658#define MBEDTLS_DHM_RFC3526_MODP_4096_G_BIN { 0x02 }
659
660#define MBEDTLS_DHM_RFC7919_FFDHE2048_P_BIN { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100661 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
662 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
663 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
664 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
665 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
666 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
667 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
668 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
669 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
670 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
671 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
672 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
673 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
674 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
675 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
676 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
677 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
678 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
679 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
680 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
681 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
682 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
683 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
684 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
685 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
686 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
687 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
688 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
689 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
690 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
691 0x88, 0x6B, 0x42, 0x38, 0x61, 0x28, 0x5C, 0x97, \
692 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100693
694#define MBEDTLS_DHM_RFC7919_FFDHE2048_G_BIN { 0x02 }
695
696#define MBEDTLS_DHM_RFC7919_FFDHE3072_P_BIN { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100697 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
698 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
699 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
700 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
701 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
702 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
703 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
704 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
705 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
706 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
707 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
708 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
709 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
710 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
711 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
712 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
713 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
714 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
715 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
716 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
717 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
718 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
719 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
720 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
721 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
722 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
723 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
724 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
725 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
726 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
727 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
728 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
729 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
730 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
731 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
732 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
733 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
734 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
735 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
736 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
737 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
738 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
739 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
740 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
741 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
742 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
743 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0xC6, 0x2E, 0x37, \
744 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100745
746#define MBEDTLS_DHM_RFC7919_FFDHE3072_G_BIN { 0x02 }
747
748#define MBEDTLS_DHM_RFC7919_FFDHE4096_P_BIN { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100749 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
750 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
751 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
752 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
753 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
754 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
755 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
756 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
757 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
758 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
759 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
760 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
761 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
762 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
763 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
764 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
765 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
766 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
767 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
768 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
769 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
770 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
771 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
772 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
773 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
774 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
775 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
776 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
777 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
778 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
779 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
780 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
781 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
782 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
783 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
784 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
785 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
786 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
787 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
788 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
789 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
790 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
791 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
792 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
793 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
794 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
795 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
796 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
797 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
798 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
799 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
800 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
801 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
802 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
803 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
804 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
805 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
806 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
807 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
808 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
809 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
810 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
811 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x65, 0x5F, 0x6A, \
812 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100813
814#define MBEDTLS_DHM_RFC7919_FFDHE4096_G_BIN { 0x02 }
815
816#define MBEDTLS_DHM_RFC7919_FFDHE6144_P_BIN { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100817 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
818 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
819 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
820 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
821 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
822 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
823 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
824 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
825 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
826 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
827 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
828 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
829 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
830 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
831 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
832 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
833 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
834 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
835 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
836 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
837 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
838 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
839 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
840 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
841 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
842 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
843 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
844 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
845 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
846 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
847 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
848 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
849 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
850 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
851 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
852 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
853 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
854 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
855 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
856 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
857 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
858 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
859 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
860 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
861 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
862 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
863 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
864 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
865 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
866 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
867 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
868 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
869 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
870 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
871 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
872 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
873 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
874 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
875 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
876 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
877 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
878 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
879 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x0D, 0xD9, 0x02, \
880 0x0B, 0xFD, 0x64, 0xB6, 0x45, 0x03, 0x6C, 0x7A, \
881 0x4E, 0x67, 0x7D, 0x2C, 0x38, 0x53, 0x2A, 0x3A, \
882 0x23, 0xBA, 0x44, 0x42, 0xCA, 0xF5, 0x3E, 0xA6, \
883 0x3B, 0xB4, 0x54, 0x32, 0x9B, 0x76, 0x24, 0xC8, \
884 0x91, 0x7B, 0xDD, 0x64, 0xB1, 0xC0, 0xFD, 0x4C, \
885 0xB3, 0x8E, 0x8C, 0x33, 0x4C, 0x70, 0x1C, 0x3A, \
886 0xCD, 0xAD, 0x06, 0x57, 0xFC, 0xCF, 0xEC, 0x71, \
887 0x9B, 0x1F, 0x5C, 0x3E, 0x4E, 0x46, 0x04, 0x1F, \
888 0x38, 0x81, 0x47, 0xFB, 0x4C, 0xFD, 0xB4, 0x77, \
889 0xA5, 0x24, 0x71, 0xF7, 0xA9, 0xA9, 0x69, 0x10, \
890 0xB8, 0x55, 0x32, 0x2E, 0xDB, 0x63, 0x40, 0xD8, \
891 0xA0, 0x0E, 0xF0, 0x92, 0x35, 0x05, 0x11, 0xE3, \
892 0x0A, 0xBE, 0xC1, 0xFF, 0xF9, 0xE3, 0xA2, 0x6E, \
893 0x7F, 0xB2, 0x9F, 0x8C, 0x18, 0x30, 0x23, 0xC3, \
894 0x58, 0x7E, 0x38, 0xDA, 0x00, 0x77, 0xD9, 0xB4, \
895 0x76, 0x3E, 0x4E, 0x4B, 0x94, 0xB2, 0xBB, 0xC1, \
896 0x94, 0xC6, 0x65, 0x1E, 0x77, 0xCA, 0xF9, 0x92, \
897 0xEE, 0xAA, 0xC0, 0x23, 0x2A, 0x28, 0x1B, 0xF6, \
898 0xB3, 0xA7, 0x39, 0xC1, 0x22, 0x61, 0x16, 0x82, \
899 0x0A, 0xE8, 0xDB, 0x58, 0x47, 0xA6, 0x7C, 0xBE, \
900 0xF9, 0xC9, 0x09, 0x1B, 0x46, 0x2D, 0x53, 0x8C, \
901 0xD7, 0x2B, 0x03, 0x74, 0x6A, 0xE7, 0x7F, 0x5E, \
902 0x62, 0x29, 0x2C, 0x31, 0x15, 0x62, 0xA8, 0x46, \
903 0x50, 0x5D, 0xC8, 0x2D, 0xB8, 0x54, 0x33, 0x8A, \
904 0xE4, 0x9F, 0x52, 0x35, 0xC9, 0x5B, 0x91, 0x17, \
905 0x8C, 0xCF, 0x2D, 0xD5, 0xCA, 0xCE, 0xF4, 0x03, \
906 0xEC, 0x9D, 0x18, 0x10, 0xC6, 0x27, 0x2B, 0x04, \
907 0x5B, 0x3B, 0x71, 0xF9, 0xDC, 0x6B, 0x80, 0xD6, \
908 0x3F, 0xDD, 0x4A, 0x8E, 0x9A, 0xDB, 0x1E, 0x69, \
909 0x62, 0xA6, 0x95, 0x26, 0xD4, 0x31, 0x61, 0xC1, \
910 0xA4, 0x1D, 0x57, 0x0D, 0x79, 0x38, 0xDA, 0xD4, \
911 0xA4, 0x0E, 0x32, 0x9C, 0xD0, 0xE4, 0x0E, 0x65, \
912 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100913
914#define MBEDTLS_DHM_RFC7919_FFDHE6144_G_BIN { 0x02 }
915
916#define MBEDTLS_DHM_RFC7919_FFDHE8192_P_BIN { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100917 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
918 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
919 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
920 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
921 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
922 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
923 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
924 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
925 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
926 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
927 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
928 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
929 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
930 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
931 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
932 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
933 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
934 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
935 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
936 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
937 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
938 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
939 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
940 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
941 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
942 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
943 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
944 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
945 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
946 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
947 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
948 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
949 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
950 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
951 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
952 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
953 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
954 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
955 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
956 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
957 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
958 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
959 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
960 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
961 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
962 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
963 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
964 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
965 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
966 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
967 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
968 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
969 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
970 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
971 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
972 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
973 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
974 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
975 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
976 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
977 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
978 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
979 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x0D, 0xD9, 0x02, \
980 0x0B, 0xFD, 0x64, 0xB6, 0x45, 0x03, 0x6C, 0x7A, \
981 0x4E, 0x67, 0x7D, 0x2C, 0x38, 0x53, 0x2A, 0x3A, \
982 0x23, 0xBA, 0x44, 0x42, 0xCA, 0xF5, 0x3E, 0xA6, \
983 0x3B, 0xB4, 0x54, 0x32, 0x9B, 0x76, 0x24, 0xC8, \
984 0x91, 0x7B, 0xDD, 0x64, 0xB1, 0xC0, 0xFD, 0x4C, \
985 0xB3, 0x8E, 0x8C, 0x33, 0x4C, 0x70, 0x1C, 0x3A, \
986 0xCD, 0xAD, 0x06, 0x57, 0xFC, 0xCF, 0xEC, 0x71, \
987 0x9B, 0x1F, 0x5C, 0x3E, 0x4E, 0x46, 0x04, 0x1F, \
988 0x38, 0x81, 0x47, 0xFB, 0x4C, 0xFD, 0xB4, 0x77, \
989 0xA5, 0x24, 0x71, 0xF7, 0xA9, 0xA9, 0x69, 0x10, \
990 0xB8, 0x55, 0x32, 0x2E, 0xDB, 0x63, 0x40, 0xD8, \
991 0xA0, 0x0E, 0xF0, 0x92, 0x35, 0x05, 0x11, 0xE3, \
992 0x0A, 0xBE, 0xC1, 0xFF, 0xF9, 0xE3, 0xA2, 0x6E, \
993 0x7F, 0xB2, 0x9F, 0x8C, 0x18, 0x30, 0x23, 0xC3, \
994 0x58, 0x7E, 0x38, 0xDA, 0x00, 0x77, 0xD9, 0xB4, \
995 0x76, 0x3E, 0x4E, 0x4B, 0x94, 0xB2, 0xBB, 0xC1, \
996 0x94, 0xC6, 0x65, 0x1E, 0x77, 0xCA, 0xF9, 0x92, \
997 0xEE, 0xAA, 0xC0, 0x23, 0x2A, 0x28, 0x1B, 0xF6, \
998 0xB3, 0xA7, 0x39, 0xC1, 0x22, 0x61, 0x16, 0x82, \
999 0x0A, 0xE8, 0xDB, 0x58, 0x47, 0xA6, 0x7C, 0xBE, \
1000 0xF9, 0xC9, 0x09, 0x1B, 0x46, 0x2D, 0x53, 0x8C, \
1001 0xD7, 0x2B, 0x03, 0x74, 0x6A, 0xE7, 0x7F, 0x5E, \
1002 0x62, 0x29, 0x2C, 0x31, 0x15, 0x62, 0xA8, 0x46, \
1003 0x50, 0x5D, 0xC8, 0x2D, 0xB8, 0x54, 0x33, 0x8A, \
1004 0xE4, 0x9F, 0x52, 0x35, 0xC9, 0x5B, 0x91, 0x17, \
1005 0x8C, 0xCF, 0x2D, 0xD5, 0xCA, 0xCE, 0xF4, 0x03, \
1006 0xEC, 0x9D, 0x18, 0x10, 0xC6, 0x27, 0x2B, 0x04, \
1007 0x5B, 0x3B, 0x71, 0xF9, 0xDC, 0x6B, 0x80, 0xD6, \
1008 0x3F, 0xDD, 0x4A, 0x8E, 0x9A, 0xDB, 0x1E, 0x69, \
1009 0x62, 0xA6, 0x95, 0x26, 0xD4, 0x31, 0x61, 0xC1, \
1010 0xA4, 0x1D, 0x57, 0x0D, 0x79, 0x38, 0xDA, 0xD4, \
1011 0xA4, 0x0E, 0x32, 0x9C, 0xCF, 0xF4, 0x6A, 0xAA, \
1012 0x36, 0xAD, 0x00, 0x4C, 0xF6, 0x00, 0xC8, 0x38, \
1013 0x1E, 0x42, 0x5A, 0x31, 0xD9, 0x51, 0xAE, 0x64, \
1014 0xFD, 0xB2, 0x3F, 0xCE, 0xC9, 0x50, 0x9D, 0x43, \
1015 0x68, 0x7F, 0xEB, 0x69, 0xED, 0xD1, 0xCC, 0x5E, \
1016 0x0B, 0x8C, 0xC3, 0xBD, 0xF6, 0x4B, 0x10, 0xEF, \
1017 0x86, 0xB6, 0x31, 0x42, 0xA3, 0xAB, 0x88, 0x29, \
1018 0x55, 0x5B, 0x2F, 0x74, 0x7C, 0x93, 0x26, 0x65, \
1019 0xCB, 0x2C, 0x0F, 0x1C, 0xC0, 0x1B, 0xD7, 0x02, \
1020 0x29, 0x38, 0x88, 0x39, 0xD2, 0xAF, 0x05, 0xE4, \
1021 0x54, 0x50, 0x4A, 0xC7, 0x8B, 0x75, 0x82, 0x82, \
1022 0x28, 0x46, 0xC0, 0xBA, 0x35, 0xC3, 0x5F, 0x5C, \
1023 0x59, 0x16, 0x0C, 0xC0, 0x46, 0xFD, 0x82, 0x51, \
1024 0x54, 0x1F, 0xC6, 0x8C, 0x9C, 0x86, 0xB0, 0x22, \
1025 0xBB, 0x70, 0x99, 0x87, 0x6A, 0x46, 0x0E, 0x74, \
1026 0x51, 0xA8, 0xA9, 0x31, 0x09, 0x70, 0x3F, 0xEE, \
1027 0x1C, 0x21, 0x7E, 0x6C, 0x38, 0x26, 0xE5, 0x2C, \
1028 0x51, 0xAA, 0x69, 0x1E, 0x0E, 0x42, 0x3C, 0xFC, \
1029 0x99, 0xE9, 0xE3, 0x16, 0x50, 0xC1, 0x21, 0x7B, \
1030 0x62, 0x48, 0x16, 0xCD, 0xAD, 0x9A, 0x95, 0xF9, \
1031 0xD5, 0xB8, 0x01, 0x94, 0x88, 0xD9, 0xC0, 0xA0, \
1032 0xA1, 0xFE, 0x30, 0x75, 0xA5, 0x77, 0xE2, 0x31, \
1033 0x83, 0xF8, 0x1D, 0x4A, 0x3F, 0x2F, 0xA4, 0x57, \
1034 0x1E, 0xFC, 0x8C, 0xE0, 0xBA, 0x8A, 0x4F, 0xE8, \
1035 0xB6, 0x85, 0x5D, 0xFE, 0x72, 0xB0, 0xA6, 0x6E, \
1036 0xDE, 0xD2, 0xFB, 0xAB, 0xFB, 0xE5, 0x8A, 0x30, \
1037 0xFA, 0xFA, 0xBE, 0x1C, 0x5D, 0x71, 0xA8, 0x7E, \
1038 0x2F, 0x74, 0x1E, 0xF8, 0xC1, 0xFE, 0x86, 0xFE, \
1039 0xA6, 0xBB, 0xFD, 0xE5, 0x30, 0x67, 0x7F, 0x0D, \
1040 0x97, 0xD1, 0x1D, 0x49, 0xF7, 0xA8, 0x44, 0x3D, \
1041 0x08, 0x22, 0xE5, 0x06, 0xA9, 0xF4, 0x61, 0x4E, \
1042 0x01, 0x1E, 0x2A, 0x94, 0x83, 0x8F, 0xF8, 0x8C, \
1043 0xD6, 0x8C, 0x8B, 0xB7, 0xC5, 0xC6, 0x42, 0x4C, \
1044 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +01001045
1046#define MBEDTLS_DHM_RFC7919_FFDHE8192_G_BIN { 0x02 }
1047
Paul Bakker9af723c2014-05-01 13:03:14 +02001048#endif /* dhm.h */