blob: 7171057a990deb6633ac44bf3c49dfb7157a35bc [file] [log] [blame]
Paul Bakker17373852011-01-06 14:20:01 +00001/**
Gilles Peskine2091f3a2021-02-12 23:34:01 +01002 * \file md.c
Paul Bakker9af723c2014-05-01 13:03:14 +02003 *
Manuel Pégourié-Gonnardb4fe3cb2015-01-22 16:11:05 +00004 * \brief Generic message digest wrapper for mbed TLS
Paul Bakker17373852011-01-06 14:20:01 +00005 *
6 * \author Adriaan de Jong <dejong@fox-it.com>
7 *
Bence Szépkúti1e148272020-08-07 13:07:28 +02008 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02009 * SPDX-License-Identifier: Apache-2.0
10 *
11 * Licensed under the Apache License, Version 2.0 (the "License"); you may
12 * not use this file except in compliance with the License.
13 * You may obtain a copy of the License at
14 *
15 * http://www.apache.org/licenses/LICENSE-2.0
16 *
17 * Unless required by applicable law or agreed to in writing, software
18 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
19 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20 * See the License for the specific language governing permissions and
21 * limitations under the License.
Paul Bakker17373852011-01-06 14:20:01 +000022 */
23
Gilles Peskinedb09ef62020-06-03 01:43:33 +020024#include "common.h"
Paul Bakker17373852011-01-06 14:20:01 +000025
Manuel Pégourié-Gonnard0d415212023-02-23 13:02:13 +010026/*
27 * Availability of functions in this module is controlled by two
28 * feature macros:
29 * - MBEDTLS_MD_C enables the whole module;
30 * - MBEDTLS_MD_LIGHT enables only functions for hashing and accessing
31 * most hash metadata (everything except string names); is it
32 * automatically set whenever MBEDTLS_MD_C is defined.
33 *
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +010034 * In this file, functions from MD_LIGHT are at the top, MD_C at the end.
35 *
Manuel Pégourié-Gonnard0d415212023-02-23 13:02:13 +010036 * In the future we may want to change the contract of some functions
37 * (behaviour with NULL arguments) depending on whether MD_C is defined or
38 * only MD_LIGHT. Also, the exact scope of MD_LIGHT might vary.
39 *
40 * For these reasons, we're keeping MD_LIGHT internal for now.
41 */
Manuel Pégourié-Gonnardb9b630d2023-02-16 19:07:31 +010042#if defined(MBEDTLS_MD_LIGHT)
Paul Bakker17373852011-01-06 14:20:01 +000043
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +000044#include "mbedtls/md.h"
Chris Jonesdaacb592021-03-09 17:03:29 +000045#include "md_wrap.h"
Andres Amaya Garcia1f6301b2018-04-17 09:51:09 -050046#include "mbedtls/platform_util.h"
Janos Follath24eed8d2019-11-22 13:21:35 +000047#include "mbedtls/error.h"
Paul Bakker17373852011-01-06 14:20:01 +000048
Gilles Peskine84867cf2019-07-19 15:46:03 +020049#include "mbedtls/md5.h"
50#include "mbedtls/ripemd160.h"
51#include "mbedtls/sha1.h"
52#include "mbedtls/sha256.h"
53#include "mbedtls/sha512.h"
54
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +010055#include "mbedtls/platform.h"
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +010056
Rich Evans00ab4702015-02-06 13:43:58 +000057#include <string.h>
Paul Bakker17373852011-01-06 14:20:01 +000058
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +020059#if defined(MBEDTLS_FS_IO)
60#include <stdio.h>
Paul Bakkeraf5c85f2011-04-18 03:47:52 +000061#endif
62
Gilles Peskine83d9e092022-10-22 18:32:43 +020063#if defined(MBEDTLS_MD_CAN_MD5)
Gilles Peskine84867cf2019-07-19 15:46:03 +020064const mbedtls_md_info_t mbedtls_md5_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020065 "MD5",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020066 MBEDTLS_MD_MD5,
Gilles Peskine84867cf2019-07-19 15:46:03 +020067 16,
68 64,
69};
70#endif
71
Gilles Peskine83d9e092022-10-22 18:32:43 +020072#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Gilles Peskine84867cf2019-07-19 15:46:03 +020073const mbedtls_md_info_t mbedtls_ripemd160_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020074 "RIPEMD160",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020075 MBEDTLS_MD_RIPEMD160,
Gilles Peskine84867cf2019-07-19 15:46:03 +020076 20,
77 64,
78};
79#endif
80
Gilles Peskine83d9e092022-10-22 18:32:43 +020081#if defined(MBEDTLS_MD_CAN_SHA1)
Gilles Peskine84867cf2019-07-19 15:46:03 +020082const mbedtls_md_info_t mbedtls_sha1_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020083 "SHA1",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020084 MBEDTLS_MD_SHA1,
Gilles Peskine84867cf2019-07-19 15:46:03 +020085 20,
86 64,
87};
88#endif
89
Gilles Peskine83d9e092022-10-22 18:32:43 +020090#if defined(MBEDTLS_MD_CAN_SHA224)
Gilles Peskine84867cf2019-07-19 15:46:03 +020091const mbedtls_md_info_t mbedtls_sha224_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020092 "SHA224",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020093 MBEDTLS_MD_SHA224,
Gilles Peskine84867cf2019-07-19 15:46:03 +020094 28,
95 64,
96};
Mateusz Starzyke3c48b42021-04-19 16:46:28 +020097#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +020098
Gilles Peskine83d9e092022-10-22 18:32:43 +020099#if defined(MBEDTLS_MD_CAN_SHA256)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200100const mbedtls_md_info_t mbedtls_sha256_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200101 "SHA256",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200102 MBEDTLS_MD_SHA256,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200103 32,
104 64,
105};
106#endif
107
Gilles Peskine83d9e092022-10-22 18:32:43 +0200108#if defined(MBEDTLS_MD_CAN_SHA384)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200109const mbedtls_md_info_t mbedtls_sha384_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200110 "SHA384",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200111 MBEDTLS_MD_SHA384,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200112 48,
113 128,
114};
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200115#endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200116
Gilles Peskine83d9e092022-10-22 18:32:43 +0200117#if defined(MBEDTLS_MD_CAN_SHA512)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200118const mbedtls_md_info_t mbedtls_sha512_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200119 "SHA512",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200120 MBEDTLS_MD_SHA512,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200121 64,
122 128,
123};
124#endif
125
Gilles Peskine449bd832023-01-11 14:50:10 +0100126const mbedtls_md_info_t *mbedtls_md_info_from_type(mbedtls_md_type_t md_type)
Paul Bakker17373852011-01-06 14:20:01 +0000127{
Gilles Peskine449bd832023-01-11 14:50:10 +0100128 switch (md_type) {
Gilles Peskine83d9e092022-10-22 18:32:43 +0200129#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200130 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100131 return &mbedtls_md5_info;
Paul Bakker17373852011-01-06 14:20:01 +0000132#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200133#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200134 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100135 return &mbedtls_ripemd160_info;
Manuel Pégourié-Gonnarde4d47a62014-01-17 20:41:32 +0100136#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200137#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200138 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100139 return &mbedtls_sha1_info;
Paul Bakker17373852011-01-06 14:20:01 +0000140#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200141#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200142 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100143 return &mbedtls_sha224_info;
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200144#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200145#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200146 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100147 return &mbedtls_sha256_info;
Paul Bakker17373852011-01-06 14:20:01 +0000148#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200149#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200150 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100151 return &mbedtls_sha384_info;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200152#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200153#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200154 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100155 return &mbedtls_sha512_info;
Paul Bakker17373852011-01-06 14:20:01 +0000156#endif
157 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100158 return NULL;
Paul Bakker17373852011-01-06 14:20:01 +0000159 }
160}
161
Gilles Peskine449bd832023-01-11 14:50:10 +0100162void mbedtls_md_init(mbedtls_md_context_t *ctx)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200163{
Gilles Peskine449bd832023-01-11 14:50:10 +0100164 memset(ctx, 0, sizeof(mbedtls_md_context_t));
Paul Bakker84bbeb52014-07-01 14:53:22 +0200165}
166
Gilles Peskine449bd832023-01-11 14:50:10 +0100167void mbedtls_md_free(mbedtls_md_context_t *ctx)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200168{
Gilles Peskine449bd832023-01-11 14:50:10 +0100169 if (ctx == NULL || ctx->md_info == NULL) {
Paul Bakker84bbeb52014-07-01 14:53:22 +0200170 return;
Gilles Peskine449bd832023-01-11 14:50:10 +0100171 }
Paul Bakker84bbeb52014-07-01 14:53:22 +0200172
Gilles Peskine449bd832023-01-11 14:50:10 +0100173 if (ctx->md_ctx != NULL) {
174 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200175#if defined(MBEDTLS_MD5_C)
176 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100177 mbedtls_md5_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200178 break;
179#endif
180#if defined(MBEDTLS_RIPEMD160_C)
181 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100182 mbedtls_ripemd160_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200183 break;
184#endif
185#if defined(MBEDTLS_SHA1_C)
186 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100187 mbedtls_sha1_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200188 break;
189#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200190#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200191 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100192 mbedtls_sha256_free(ctx->md_ctx);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200193 break;
194#endif
195#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200196 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100197 mbedtls_sha256_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200198 break;
199#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200200#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200201 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100202 mbedtls_sha512_free(ctx->md_ctx);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200203 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200204#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200205#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200206 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100207 mbedtls_sha512_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200208 break;
209#endif
210 default:
211 /* Shouldn't happen */
212 break;
213 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100214 mbedtls_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200215 }
Paul Bakker84bbeb52014-07-01 14:53:22 +0200216
Gilles Peskine449bd832023-01-11 14:50:10 +0100217 if (ctx->hmac_ctx != NULL) {
218 mbedtls_platform_zeroize(ctx->hmac_ctx,
219 2 * ctx->md_info->block_size);
220 mbedtls_free(ctx->hmac_ctx);
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100221 }
222
Gilles Peskine449bd832023-01-11 14:50:10 +0100223 mbedtls_platform_zeroize(ctx, sizeof(mbedtls_md_context_t));
Paul Bakker84bbeb52014-07-01 14:53:22 +0200224}
225
Gilles Peskine449bd832023-01-11 14:50:10 +0100226int mbedtls_md_clone(mbedtls_md_context_t *dst,
227 const mbedtls_md_context_t *src)
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200228{
Gilles Peskine449bd832023-01-11 14:50:10 +0100229 if (dst == NULL || dst->md_info == NULL ||
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200230 src == NULL || src->md_info == NULL ||
Gilles Peskine449bd832023-01-11 14:50:10 +0100231 dst->md_info != src->md_info) {
232 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200233 }
234
Gilles Peskine449bd832023-01-11 14:50:10 +0100235 switch (src->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200236#if defined(MBEDTLS_MD5_C)
237 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100238 mbedtls_md5_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200239 break;
240#endif
241#if defined(MBEDTLS_RIPEMD160_C)
242 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100243 mbedtls_ripemd160_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200244 break;
245#endif
246#if defined(MBEDTLS_SHA1_C)
247 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100248 mbedtls_sha1_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200249 break;
250#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200251#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200252 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100253 mbedtls_sha256_clone(dst->md_ctx, src->md_ctx);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200254 break;
255#endif
256#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200257 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100258 mbedtls_sha256_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200259 break;
260#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200261#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200262 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100263 mbedtls_sha512_clone(dst->md_ctx, src->md_ctx);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200264 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200265#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200266#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200267 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100268 mbedtls_sha512_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200269 break;
270#endif
271 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100272 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200273 }
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200274
Gilles Peskine449bd832023-01-11 14:50:10 +0100275 return 0;
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200276}
277
Gilles Peskine449bd832023-01-11 14:50:10 +0100278#define ALLOC(type) \
Gilles Peskine84867cf2019-07-19 15:46:03 +0200279 do { \
Gilles Peskine449bd832023-01-11 14:50:10 +0100280 ctx->md_ctx = mbedtls_calloc(1, sizeof(mbedtls_##type##_context)); \
281 if (ctx->md_ctx == NULL) \
282 return MBEDTLS_ERR_MD_ALLOC_FAILED; \
283 mbedtls_##type##_init(ctx->md_ctx); \
Gilles Peskine84867cf2019-07-19 15:46:03 +0200284 } \
Gilles Peskine449bd832023-01-11 14:50:10 +0100285 while (0)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200286
Gilles Peskine449bd832023-01-11 14:50:10 +0100287int mbedtls_md_setup(mbedtls_md_context_t *ctx, const mbedtls_md_info_t *md_info, int hmac)
Paul Bakker17373852011-01-06 14:20:01 +0000288{
Gilles Peskine449bd832023-01-11 14:50:10 +0100289 if (md_info == NULL || ctx == NULL) {
290 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
291 }
Paul Bakker17373852011-01-06 14:20:01 +0000292
Gilles Peskined15c7402020-08-19 12:03:11 +0200293 ctx->md_info = md_info;
294 ctx->md_ctx = NULL;
295 ctx->hmac_ctx = NULL;
296
Gilles Peskine449bd832023-01-11 14:50:10 +0100297 switch (md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200298#if defined(MBEDTLS_MD5_C)
299 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100300 ALLOC(md5);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200301 break;
302#endif
303#if defined(MBEDTLS_RIPEMD160_C)
304 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100305 ALLOC(ripemd160);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200306 break;
307#endif
308#if defined(MBEDTLS_SHA1_C)
309 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100310 ALLOC(sha1);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200311 break;
312#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200313#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200314 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100315 ALLOC(sha256);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200316 break;
317#endif
318#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200319 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100320 ALLOC(sha256);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200321 break;
322#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200323#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200324 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100325 ALLOC(sha512);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200326 break;
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200327#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200328#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200329 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100330 ALLOC(sha512);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200331 break;
332#endif
333 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100334 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200335 }
Paul Bakker17373852011-01-06 14:20:01 +0000336
Gilles Peskine449bd832023-01-11 14:50:10 +0100337 if (hmac != 0) {
338 ctx->hmac_ctx = mbedtls_calloc(2, md_info->block_size);
339 if (ctx->hmac_ctx == NULL) {
340 mbedtls_md_free(ctx);
341 return MBEDTLS_ERR_MD_ALLOC_FAILED;
Manuel Pégourié-Gonnard4063ceb2015-03-25 16:08:53 +0100342 }
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100343 }
344
Gilles Peskine449bd832023-01-11 14:50:10 +0100345 return 0;
Paul Bakker17373852011-01-06 14:20:01 +0000346}
Gilles Peskine84867cf2019-07-19 15:46:03 +0200347#undef ALLOC
Paul Bakker17373852011-01-06 14:20:01 +0000348
Gilles Peskine449bd832023-01-11 14:50:10 +0100349int mbedtls_md_starts(mbedtls_md_context_t *ctx)
Paul Bakker562535d2011-01-20 16:42:01 +0000350{
Gilles Peskine449bd832023-01-11 14:50:10 +0100351 if (ctx == NULL || ctx->md_info == NULL) {
352 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
353 }
Paul Bakker562535d2011-01-20 16:42:01 +0000354
Gilles Peskine449bd832023-01-11 14:50:10 +0100355 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200356#if defined(MBEDTLS_MD5_C)
357 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100358 return mbedtls_md5_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200359#endif
360#if defined(MBEDTLS_RIPEMD160_C)
361 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100362 return mbedtls_ripemd160_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200363#endif
364#if defined(MBEDTLS_SHA1_C)
365 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100366 return mbedtls_sha1_starts(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200367#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200368#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200369 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100370 return mbedtls_sha256_starts(ctx->md_ctx, 1);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200371#endif
372#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200373 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100374 return mbedtls_sha256_starts(ctx->md_ctx, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200375#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200376#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200377 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100378 return mbedtls_sha512_starts(ctx->md_ctx, 1);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200379#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200380#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200381 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100382 return mbedtls_sha512_starts(ctx->md_ctx, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200383#endif
384 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100385 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200386 }
Paul Bakker562535d2011-01-20 16:42:01 +0000387}
388
Gilles Peskine449bd832023-01-11 14:50:10 +0100389int mbedtls_md_update(mbedtls_md_context_t *ctx, const unsigned char *input, size_t ilen)
Paul Bakker17373852011-01-06 14:20:01 +0000390{
Gilles Peskine449bd832023-01-11 14:50:10 +0100391 if (ctx == NULL || ctx->md_info == NULL) {
392 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
393 }
Paul Bakker17373852011-01-06 14:20:01 +0000394
Gilles Peskine449bd832023-01-11 14:50:10 +0100395 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200396#if defined(MBEDTLS_MD5_C)
397 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100398 return mbedtls_md5_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200399#endif
400#if defined(MBEDTLS_RIPEMD160_C)
401 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100402 return mbedtls_ripemd160_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200403#endif
404#if defined(MBEDTLS_SHA1_C)
405 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100406 return mbedtls_sha1_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200407#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200408#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200409 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100410 return mbedtls_sha256_update(ctx->md_ctx, input, ilen);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200411#endif
412#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200413 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100414 return mbedtls_sha256_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200415#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200416#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200417 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100418 return mbedtls_sha512_update(ctx->md_ctx, input, ilen);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200419#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200420#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200421 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100422 return mbedtls_sha512_update(ctx->md_ctx, input, ilen);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200423#endif
424 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100425 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200426 }
Paul Bakker17373852011-01-06 14:20:01 +0000427}
428
Gilles Peskine449bd832023-01-11 14:50:10 +0100429int mbedtls_md_finish(mbedtls_md_context_t *ctx, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000430{
Gilles Peskine449bd832023-01-11 14:50:10 +0100431 if (ctx == NULL || ctx->md_info == NULL) {
432 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
433 }
Paul Bakker17373852011-01-06 14:20:01 +0000434
Gilles Peskine449bd832023-01-11 14:50:10 +0100435 switch (ctx->md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200436#if defined(MBEDTLS_MD5_C)
437 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100438 return mbedtls_md5_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200439#endif
440#if defined(MBEDTLS_RIPEMD160_C)
441 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100442 return mbedtls_ripemd160_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200443#endif
444#if defined(MBEDTLS_SHA1_C)
445 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100446 return mbedtls_sha1_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200447#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200448#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200449 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100450 return mbedtls_sha256_finish(ctx->md_ctx, output);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200451#endif
452#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200453 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100454 return mbedtls_sha256_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200455#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200456#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200457 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100458 return mbedtls_sha512_finish(ctx->md_ctx, output);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200459#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200460#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200461 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100462 return mbedtls_sha512_finish(ctx->md_ctx, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200463#endif
464 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100465 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200466 }
Paul Bakker17373852011-01-06 14:20:01 +0000467}
468
Gilles Peskine449bd832023-01-11 14:50:10 +0100469int mbedtls_md(const mbedtls_md_info_t *md_info, const unsigned char *input, size_t ilen,
470 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000471{
Gilles Peskine449bd832023-01-11 14:50:10 +0100472 if (md_info == NULL) {
473 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
474 }
Paul Bakker17373852011-01-06 14:20:01 +0000475
Gilles Peskine449bd832023-01-11 14:50:10 +0100476 switch (md_info->type) {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200477#if defined(MBEDTLS_MD5_C)
478 case MBEDTLS_MD_MD5:
Gilles Peskine449bd832023-01-11 14:50:10 +0100479 return mbedtls_md5(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200480#endif
481#if defined(MBEDTLS_RIPEMD160_C)
482 case MBEDTLS_MD_RIPEMD160:
Gilles Peskine449bd832023-01-11 14:50:10 +0100483 return mbedtls_ripemd160(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200484#endif
485#if defined(MBEDTLS_SHA1_C)
486 case MBEDTLS_MD_SHA1:
Gilles Peskine449bd832023-01-11 14:50:10 +0100487 return mbedtls_sha1(input, ilen, output);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200488#endif
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200489#if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200490 case MBEDTLS_MD_SHA224:
Gilles Peskine449bd832023-01-11 14:50:10 +0100491 return mbedtls_sha256(input, ilen, output, 1);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200492#endif
493#if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200494 case MBEDTLS_MD_SHA256:
Gilles Peskine449bd832023-01-11 14:50:10 +0100495 return mbedtls_sha256(input, ilen, output, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200496#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200497#if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200498 case MBEDTLS_MD_SHA384:
Gilles Peskine449bd832023-01-11 14:50:10 +0100499 return mbedtls_sha512(input, ilen, output, 1);
Manuel Pégourié-Gonnardd6020842019-07-17 16:28:21 +0200500#endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200501#if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200502 case MBEDTLS_MD_SHA512:
Gilles Peskine449bd832023-01-11 14:50:10 +0100503 return mbedtls_sha512(input, ilen, output, 0);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200504#endif
505 default:
Gilles Peskine449bd832023-01-11 14:50:10 +0100506 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200507 }
Paul Bakker17373852011-01-06 14:20:01 +0000508}
509
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100510unsigned char mbedtls_md_get_size(const mbedtls_md_info_t *md_info)
511{
512 if (md_info == NULL) {
513 return 0;
514 }
515
516 return md_info->size;
517}
518
519mbedtls_md_type_t mbedtls_md_get_type(const mbedtls_md_info_t *md_info)
520{
521 if (md_info == NULL) {
522 return MBEDTLS_MD_NONE;
523 }
524
525 return md_info->type;
526}
527
528/************************************************************************
529 * Functions above this separator are part of MBEDTLS_MD_LIGHT, *
530 * functions below are only available when MBEDTLS_MD_C is set. *
531 ************************************************************************/
532#if defined(MBEDTLS_MD_C)
533
534/*
535 * Reminder: update profiles in x509_crt.c when adding a new hash!
536 */
537static const int supported_digests[] = {
538
Gilles Peskine83d9e092022-10-22 18:32:43 +0200539#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100540 MBEDTLS_MD_SHA512,
541#endif
542
Gilles Peskine83d9e092022-10-22 18:32:43 +0200543#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100544 MBEDTLS_MD_SHA384,
545#endif
546
Gilles Peskine83d9e092022-10-22 18:32:43 +0200547#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100548 MBEDTLS_MD_SHA256,
549#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200550#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100551 MBEDTLS_MD_SHA224,
552#endif
553
Gilles Peskine83d9e092022-10-22 18:32:43 +0200554#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100555 MBEDTLS_MD_SHA1,
556#endif
557
Gilles Peskine83d9e092022-10-22 18:32:43 +0200558#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100559 MBEDTLS_MD_RIPEMD160,
560#endif
561
Gilles Peskine83d9e092022-10-22 18:32:43 +0200562#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100563 MBEDTLS_MD_MD5,
564#endif
565
566 MBEDTLS_MD_NONE
567};
568
569const int *mbedtls_md_list(void)
570{
571 return supported_digests;
572}
573
574const mbedtls_md_info_t *mbedtls_md_info_from_string(const char *md_name)
575{
576 if (NULL == md_name) {
577 return NULL;
578 }
579
580 /* Get the appropriate digest information */
Gilles Peskine83d9e092022-10-22 18:32:43 +0200581#if defined(MBEDTLS_MD_CAN_MD5)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100582 if (!strcmp("MD5", md_name)) {
583 return mbedtls_md_info_from_type(MBEDTLS_MD_MD5);
584 }
585#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200586#if defined(MBEDTLS_MD_CAN_RIPEMD160)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100587 if (!strcmp("RIPEMD160", md_name)) {
588 return mbedtls_md_info_from_type(MBEDTLS_MD_RIPEMD160);
589 }
590#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200591#if defined(MBEDTLS_MD_CAN_SHA1)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100592 if (!strcmp("SHA1", md_name) || !strcmp("SHA", md_name)) {
593 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA1);
594 }
595#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200596#if defined(MBEDTLS_MD_CAN_SHA224)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100597 if (!strcmp("SHA224", md_name)) {
598 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA224);
599 }
600#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200601#if defined(MBEDTLS_MD_CAN_SHA256)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100602 if (!strcmp("SHA256", md_name)) {
603 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA256);
604 }
605#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200606#if defined(MBEDTLS_MD_CAN_SHA384)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100607 if (!strcmp("SHA384", md_name)) {
608 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA384);
609 }
610#endif
Gilles Peskine83d9e092022-10-22 18:32:43 +0200611#if defined(MBEDTLS_MD_CAN_SHA512)
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100612 if (!strcmp("SHA512", md_name)) {
613 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA512);
614 }
615#endif
616 return NULL;
617}
618
619const mbedtls_md_info_t *mbedtls_md_info_from_ctx(
620 const mbedtls_md_context_t *ctx)
621{
622 if (ctx == NULL) {
623 return NULL;
624 }
625
626 return ctx->MBEDTLS_PRIVATE(md_info);
627}
628
629#if defined(MBEDTLS_FS_IO)
Gilles Peskine449bd832023-01-11 14:50:10 +0100630int mbedtls_md_file(const mbedtls_md_info_t *md_info, const char *path, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000631{
Janos Follath24eed8d2019-11-22 13:21:35 +0000632 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200633 FILE *f;
634 size_t n;
635 mbedtls_md_context_t ctx;
636 unsigned char buf[1024];
Paul Bakker9c021ad2011-06-09 15:55:11 +0000637
Gilles Peskine449bd832023-01-11 14:50:10 +0100638 if (md_info == NULL) {
639 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
640 }
Paul Bakker17373852011-01-06 14:20:01 +0000641
Gilles Peskine449bd832023-01-11 14:50:10 +0100642 if ((f = fopen(path, "rb")) == NULL) {
643 return MBEDTLS_ERR_MD_FILE_IO_ERROR;
644 }
Manuel Pégourié-Gonnardbcc03082015-06-24 00:09:29 +0200645
Gilles Peskineda0913b2022-06-30 17:03:40 +0200646 /* Ensure no stdio buffering of secrets, as such buffers cannot be wiped. */
Gilles Peskine449bd832023-01-11 14:50:10 +0100647 mbedtls_setbuf(f, NULL);
Gilles Peskineda0913b2022-06-30 17:03:40 +0200648
Gilles Peskine449bd832023-01-11 14:50:10 +0100649 mbedtls_md_init(&ctx);
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200650
Gilles Peskine449bd832023-01-11 14:50:10 +0100651 if ((ret = mbedtls_md_setup(&ctx, md_info, 0)) != 0) {
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200652 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100653 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200654
Gilles Peskine449bd832023-01-11 14:50:10 +0100655 if ((ret = mbedtls_md_starts(&ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100656 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100657 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200658
Gilles Peskine449bd832023-01-11 14:50:10 +0100659 while ((n = fread(buf, 1, sizeof(buf), f)) > 0) {
660 if ((ret = mbedtls_md_update(&ctx, buf, n)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100661 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100662 }
663 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200664
Gilles Peskine449bd832023-01-11 14:50:10 +0100665 if (ferror(f) != 0) {
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200666 ret = MBEDTLS_ERR_MD_FILE_IO_ERROR;
Gilles Peskine449bd832023-01-11 14:50:10 +0100667 } else {
668 ret = mbedtls_md_finish(&ctx, output);
669 }
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200670
671cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +0100672 mbedtls_platform_zeroize(buf, sizeof(buf));
673 fclose(f);
674 mbedtls_md_free(&ctx);
Paul Bakker9c021ad2011-06-09 15:55:11 +0000675
Gilles Peskine449bd832023-01-11 14:50:10 +0100676 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000677}
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100678#endif /* MBEDTLS_FS_IO */
Paul Bakker17373852011-01-06 14:20:01 +0000679
Gilles Peskine449bd832023-01-11 14:50:10 +0100680int mbedtls_md_hmac_starts(mbedtls_md_context_t *ctx, const unsigned char *key, size_t keylen)
Paul Bakker17373852011-01-06 14:20:01 +0000681{
Janos Follath24eed8d2019-11-22 13:21:35 +0000682 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200683 unsigned char sum[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100684 unsigned char *ipad, *opad;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100685
Gilles Peskine449bd832023-01-11 14:50:10 +0100686 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
687 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
688 }
Paul Bakker17373852011-01-06 14:20:01 +0000689
Gilles Peskine449bd832023-01-11 14:50:10 +0100690 if (keylen > (size_t) ctx->md_info->block_size) {
691 if ((ret = mbedtls_md_starts(ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100692 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100693 }
694 if ((ret = mbedtls_md_update(ctx, key, keylen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100695 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100696 }
697 if ((ret = mbedtls_md_finish(ctx, sum)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100698 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100699 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100700
701 keylen = ctx->md_info->size;
702 key = sum;
703 }
704
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100705 ipad = (unsigned char *) ctx->hmac_ctx;
706 opad = (unsigned char *) ctx->hmac_ctx + ctx->md_info->block_size;
707
Gilles Peskine449bd832023-01-11 14:50:10 +0100708 memset(ipad, 0x36, ctx->md_info->block_size);
709 memset(opad, 0x5C, ctx->md_info->block_size);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100710
Gilles Peskine449bd832023-01-11 14:50:10 +0100711 mbedtls_xor(ipad, ipad, key, keylen);
712 mbedtls_xor(opad, opad, key, keylen);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100713
Gilles Peskine449bd832023-01-11 14:50:10 +0100714 if ((ret = mbedtls_md_starts(ctx)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100715 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100716 }
717 if ((ret = mbedtls_md_update(ctx, ipad,
718 ctx->md_info->block_size)) != 0) {
Andres Amaya Garcia42e5e102017-07-20 16:27:03 +0100719 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100720 }
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100721
722cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +0100723 mbedtls_platform_zeroize(sum, sizeof(sum));
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100724
Gilles Peskine449bd832023-01-11 14:50:10 +0100725 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000726}
727
Gilles Peskine449bd832023-01-11 14:50:10 +0100728int mbedtls_md_hmac_update(mbedtls_md_context_t *ctx, const unsigned char *input, size_t ilen)
Paul Bakker17373852011-01-06 14:20:01 +0000729{
Gilles Peskine449bd832023-01-11 14:50:10 +0100730 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
731 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
732 }
Paul Bakker17373852011-01-06 14:20:01 +0000733
Gilles Peskine449bd832023-01-11 14:50:10 +0100734 return mbedtls_md_update(ctx, input, ilen);
Paul Bakker17373852011-01-06 14:20:01 +0000735}
736
Gilles Peskine449bd832023-01-11 14:50:10 +0100737int mbedtls_md_hmac_finish(mbedtls_md_context_t *ctx, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000738{
Janos Follath24eed8d2019-11-22 13:21:35 +0000739 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200740 unsigned char tmp[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100741 unsigned char *opad;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100742
Gilles Peskine449bd832023-01-11 14:50:10 +0100743 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
744 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
745 }
Paul Bakker17373852011-01-06 14:20:01 +0000746
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100747 opad = (unsigned char *) ctx->hmac_ctx + ctx->md_info->block_size;
748
Gilles Peskine449bd832023-01-11 14:50:10 +0100749 if ((ret = mbedtls_md_finish(ctx, tmp)) != 0) {
750 return ret;
751 }
752 if ((ret = mbedtls_md_starts(ctx)) != 0) {
753 return ret;
754 }
755 if ((ret = mbedtls_md_update(ctx, opad,
756 ctx->md_info->block_size)) != 0) {
757 return ret;
758 }
759 if ((ret = mbedtls_md_update(ctx, tmp,
760 ctx->md_info->size)) != 0) {
761 return ret;
762 }
763 return mbedtls_md_finish(ctx, output);
Paul Bakker17373852011-01-06 14:20:01 +0000764}
765
Gilles Peskine449bd832023-01-11 14:50:10 +0100766int mbedtls_md_hmac_reset(mbedtls_md_context_t *ctx)
Paul Bakker17373852011-01-06 14:20:01 +0000767{
Janos Follath24eed8d2019-11-22 13:21:35 +0000768 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100769 unsigned char *ipad;
770
Gilles Peskine449bd832023-01-11 14:50:10 +0100771 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL) {
772 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
773 }
Paul Bakker17373852011-01-06 14:20:01 +0000774
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100775 ipad = (unsigned char *) ctx->hmac_ctx;
776
Gilles Peskine449bd832023-01-11 14:50:10 +0100777 if ((ret = mbedtls_md_starts(ctx)) != 0) {
778 return ret;
779 }
780 return mbedtls_md_update(ctx, ipad, ctx->md_info->block_size);
Paul Bakker17373852011-01-06 14:20:01 +0000781}
782
Gilles Peskine449bd832023-01-11 14:50:10 +0100783int mbedtls_md_hmac(const mbedtls_md_info_t *md_info,
784 const unsigned char *key, size_t keylen,
785 const unsigned char *input, size_t ilen,
786 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000787{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200788 mbedtls_md_context_t ctx;
Janos Follath24eed8d2019-11-22 13:21:35 +0000789 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100790
Gilles Peskine449bd832023-01-11 14:50:10 +0100791 if (md_info == NULL) {
792 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
793 }
Paul Bakker17373852011-01-06 14:20:01 +0000794
Gilles Peskine449bd832023-01-11 14:50:10 +0100795 mbedtls_md_init(&ctx);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100796
Gilles Peskine449bd832023-01-11 14:50:10 +0100797 if ((ret = mbedtls_md_setup(&ctx, md_info, 1)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100798 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100799 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100800
Gilles Peskine449bd832023-01-11 14:50:10 +0100801 if ((ret = mbedtls_md_hmac_starts(&ctx, key, keylen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100802 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100803 }
804 if ((ret = mbedtls_md_hmac_update(&ctx, input, ilen)) != 0) {
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100805 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100806 }
807 if ((ret = mbedtls_md_hmac_finish(&ctx, output)) != 0) {
Andres Amaya Garciaaa464ef2017-07-21 14:21:53 +0100808 goto cleanup;
Gilles Peskine449bd832023-01-11 14:50:10 +0100809 }
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100810
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100811cleanup:
Gilles Peskine449bd832023-01-11 14:50:10 +0100812 mbedtls_md_free(&ctx);
Paul Bakker17373852011-01-06 14:20:01 +0000813
Gilles Peskine449bd832023-01-11 14:50:10 +0100814 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000815}
816
Gilles Peskine449bd832023-01-11 14:50:10 +0100817const char *mbedtls_md_get_name(const mbedtls_md_info_t *md_info)
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100818{
Gilles Peskine449bd832023-01-11 14:50:10 +0100819 if (md_info == NULL) {
820 return NULL;
821 }
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100822
823 return md_info->name;
824}
Manuel Pégourié-Gonnard1e57abd2023-02-23 20:45:26 +0100825
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200826#endif /* MBEDTLS_MD_C */
Manuel Pégourié-Gonnardb9b630d2023-02-16 19:07:31 +0100827
828#endif /* MBEDTLS_MD_LIGHT */