blob: 7a5b0dd39d001a41985d7dfefbb08d241d4b0bad [file] [log] [blame]
Paul Bakker17373852011-01-06 14:20:01 +00001/**
Gilles Peskine2091f3a2021-02-12 23:34:01 +01002 * \file md.c
Paul Bakker9af723c2014-05-01 13:03:14 +02003 *
Manuel Pégourié-Gonnardb4fe3cb2015-01-22 16:11:05 +00004 * \brief Generic message digest wrapper for mbed TLS
Paul Bakker17373852011-01-06 14:20:01 +00005 *
6 * \author Adriaan de Jong <dejong@fox-it.com>
7 *
Bence Szépkúti1e148272020-08-07 13:07:28 +02008 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02009 * SPDX-License-Identifier: Apache-2.0
10 *
11 * Licensed under the Apache License, Version 2.0 (the "License"); you may
12 * not use this file except in compliance with the License.
13 * You may obtain a copy of the License at
14 *
15 * http://www.apache.org/licenses/LICENSE-2.0
16 *
17 * Unless required by applicable law or agreed to in writing, software
18 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
19 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20 * See the License for the specific language governing permissions and
21 * limitations under the License.
Paul Bakker17373852011-01-06 14:20:01 +000022 */
23
Gilles Peskinedb09ef62020-06-03 01:43:33 +020024#include "common.h"
Paul Bakker17373852011-01-06 14:20:01 +000025
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020026#if defined(MBEDTLS_MD_C)
Paul Bakker17373852011-01-06 14:20:01 +000027
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020028# include "mbedtls/md.h"
29# include "md_wrap.h"
30# include "mbedtls/platform_util.h"
31# include "mbedtls/error.h"
Paul Bakker17373852011-01-06 14:20:01 +000032
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020033# include "mbedtls/md5.h"
34# include "mbedtls/ripemd160.h"
35# include "mbedtls/sha1.h"
36# include "mbedtls/sha256.h"
37# include "mbedtls/sha512.h"
Gilles Peskine84867cf2019-07-19 15:46:03 +020038
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020039# if defined(MBEDTLS_PLATFORM_C)
40# include "mbedtls/platform.h"
41# else
42# include <stdlib.h>
43# define mbedtls_calloc calloc
44# define mbedtls_free free
45# endif
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +010046
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020047# include <string.h>
Paul Bakker17373852011-01-06 14:20:01 +000048
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020049# if defined(MBEDTLS_FS_IO)
50# include <stdio.h>
51# endif
Paul Bakkeraf5c85f2011-04-18 03:47:52 +000052
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020053# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +020054const mbedtls_md_info_t mbedtls_md5_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020055 "MD5",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020056 MBEDTLS_MD_MD5,
Gilles Peskine84867cf2019-07-19 15:46:03 +020057 16,
58 64,
59};
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020060# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +020061
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020062# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +020063const mbedtls_md_info_t mbedtls_ripemd160_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020064 "RIPEMD160",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020065 MBEDTLS_MD_RIPEMD160,
Gilles Peskine84867cf2019-07-19 15:46:03 +020066 20,
67 64,
68};
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020069# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +020070
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020071# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +020072const mbedtls_md_info_t mbedtls_sha1_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020073 "SHA1",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020074 MBEDTLS_MD_SHA1,
Gilles Peskine84867cf2019-07-19 15:46:03 +020075 20,
76 64,
77};
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020078# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +020079
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020080# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +020081const mbedtls_md_info_t mbedtls_sha224_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020082 "SHA224",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020083 MBEDTLS_MD_SHA224,
Gilles Peskine84867cf2019-07-19 15:46:03 +020084 28,
85 64,
86};
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020087# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +020088
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020089# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +020090const mbedtls_md_info_t mbedtls_sha256_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +020091 "SHA256",
Gilles Peskine2838b7b2019-07-19 16:03:39 +020092 MBEDTLS_MD_SHA256,
Gilles Peskine84867cf2019-07-19 15:46:03 +020093 32,
94 64,
95};
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020096# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +020097
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +020098# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +020099const mbedtls_md_info_t mbedtls_sha384_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200100 "SHA384",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200101 MBEDTLS_MD_SHA384,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200102 48,
103 128,
104};
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200105# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200106
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200107# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200108const mbedtls_md_info_t mbedtls_sha512_info = {
Gilles Peskine84867cf2019-07-19 15:46:03 +0200109 "SHA512",
Gilles Peskine2838b7b2019-07-19 16:03:39 +0200110 MBEDTLS_MD_SHA512,
Gilles Peskine84867cf2019-07-19 15:46:03 +0200111 64,
112 128,
113};
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200114# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200115
Manuel Pégourié-Gonnard88db5da2015-06-15 14:34:59 +0200116/*
Gilles Peskine3a671502020-02-26 19:52:06 +0100117 * Reminder: update profiles in x509_crt.c when adding a new hash!
Manuel Pégourié-Gonnard88db5da2015-06-15 14:34:59 +0200118 */
Paul Bakker72f62662011-01-16 21:27:44 +0000119static const int supported_digests[] = {
120
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200121# if defined(MBEDTLS_SHA512_C)
122 MBEDTLS_MD_SHA512,
123# endif
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200124
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200125# if defined(MBEDTLS_SHA384_C)
126 MBEDTLS_MD_SHA384,
127# endif
Paul Bakker72f62662011-01-16 21:27:44 +0000128
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200129# if defined(MBEDTLS_SHA256_C)
130 MBEDTLS_MD_SHA256,
131# endif
132# if defined(MBEDTLS_SHA224_C)
133 MBEDTLS_MD_SHA224,
134# endif
Paul Bakker72f62662011-01-16 21:27:44 +0000135
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200136# if defined(MBEDTLS_SHA1_C)
137 MBEDTLS_MD_SHA1,
138# endif
Paul Bakker72f62662011-01-16 21:27:44 +0000139
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200140# if defined(MBEDTLS_RIPEMD160_C)
141 MBEDTLS_MD_RIPEMD160,
142# endif
Manuel Pégourié-Gonnardbd772542014-07-07 14:02:33 +0200143
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200144# if defined(MBEDTLS_MD5_C)
145 MBEDTLS_MD_MD5,
146# endif
Manuel Pégourié-Gonnardbd772542014-07-07 14:02:33 +0200147
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200148 MBEDTLS_MD_NONE
Paul Bakker72f62662011-01-16 21:27:44 +0000149};
150
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200151const int *mbedtls_md_list(void)
Paul Bakker72f62662011-01-16 21:27:44 +0000152{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200153 return supported_digests;
Paul Bakker72f62662011-01-16 21:27:44 +0000154}
155
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200156const mbedtls_md_info_t *mbedtls_md_info_from_string(const char *md_name)
Paul Bakker17373852011-01-06 14:20:01 +0000157{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200158 if (NULL == md_name)
159 return NULL;
Paul Bakker17373852011-01-06 14:20:01 +0000160
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200161 /* Get the appropriate digest information */
162# if defined(MBEDTLS_MD5_C)
163 if (!strcmp("MD5", md_name))
164 return mbedtls_md_info_from_type(MBEDTLS_MD_MD5);
165# endif
166# if defined(MBEDTLS_RIPEMD160_C)
167 if (!strcmp("RIPEMD160", md_name))
168 return mbedtls_md_info_from_type(MBEDTLS_MD_RIPEMD160);
169# endif
170# if defined(MBEDTLS_SHA1_C)
171 if (!strcmp("SHA1", md_name) || !strcmp("SHA", md_name))
172 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA1);
173# endif
174# if defined(MBEDTLS_SHA224_C)
175 if (!strcmp("SHA224", md_name))
176 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA224);
177# endif
178# if defined(MBEDTLS_SHA256_C)
179 if (!strcmp("SHA256", md_name))
180 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA256);
181# endif
182# if defined(MBEDTLS_SHA384_C)
183 if (!strcmp("SHA384", md_name))
184 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA384);
185# endif
186# if defined(MBEDTLS_SHA512_C)
187 if (!strcmp("SHA512", md_name))
188 return mbedtls_md_info_from_type(MBEDTLS_MD_SHA512);
189# endif
190 return NULL;
Paul Bakker17373852011-01-06 14:20:01 +0000191}
192
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200193const mbedtls_md_info_t *mbedtls_md_info_from_type(mbedtls_md_type_t md_type)
Paul Bakker17373852011-01-06 14:20:01 +0000194{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200195 switch (md_type) {
196# if defined(MBEDTLS_MD5_C)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200197 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200198 return &mbedtls_md5_info;
199# endif
200# if defined(MBEDTLS_RIPEMD160_C)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200201 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200202 return &mbedtls_ripemd160_info;
203# endif
204# if defined(MBEDTLS_SHA1_C)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200205 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200206 return &mbedtls_sha1_info;
207# endif
208# if defined(MBEDTLS_SHA224_C)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200209 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200210 return &mbedtls_sha224_info;
211# endif
212# if defined(MBEDTLS_SHA256_C)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200213 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200214 return &mbedtls_sha256_info;
215# endif
216# if defined(MBEDTLS_SHA384_C)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200217 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200218 return &mbedtls_sha384_info;
219# endif
220# if defined(MBEDTLS_SHA512_C)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200221 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200222 return &mbedtls_sha512_info;
223# endif
Paul Bakker17373852011-01-06 14:20:01 +0000224 default:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200225 return NULL;
Paul Bakker17373852011-01-06 14:20:01 +0000226 }
227}
228
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200229void mbedtls_md_init(mbedtls_md_context_t *ctx)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200230{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200231 memset(ctx, 0, sizeof(mbedtls_md_context_t));
Paul Bakker84bbeb52014-07-01 14:53:22 +0200232}
233
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200234void mbedtls_md_free(mbedtls_md_context_t *ctx)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200235{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200236 if (ctx == NULL || ctx->md_info == NULL)
Paul Bakker84bbeb52014-07-01 14:53:22 +0200237 return;
238
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200239 if (ctx->md_ctx != NULL) {
240 switch (ctx->md_info->type) {
241# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200242 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200243 mbedtls_md5_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200244 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200245# endif
246# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200247 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200248 mbedtls_ripemd160_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200249 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200250# endif
251# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200252 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200253 mbedtls_sha1_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200254 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200255# endif
256# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200257 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200258 mbedtls_sha256_free(ctx->md_ctx);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200259 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200260# endif
261# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200262 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200263 mbedtls_sha256_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200264 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200265# endif
266# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200267 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200268 mbedtls_sha512_free(ctx->md_ctx);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200269 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200270# endif
271# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200272 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200273 mbedtls_sha512_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200274 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200275# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200276 default:
277 /* Shouldn't happen */
278 break;
279 }
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200280 mbedtls_free(ctx->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200281 }
Paul Bakker84bbeb52014-07-01 14:53:22 +0200282
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200283 if (ctx->hmac_ctx != NULL) {
284 mbedtls_platform_zeroize(ctx->hmac_ctx, 2 * ctx->md_info->block_size);
285 mbedtls_free(ctx->hmac_ctx);
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100286 }
287
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200288 mbedtls_platform_zeroize(ctx, sizeof(mbedtls_md_context_t));
Paul Bakker84bbeb52014-07-01 14:53:22 +0200289}
290
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200291int mbedtls_md_clone(mbedtls_md_context_t *dst, const mbedtls_md_context_t *src)
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200292{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200293 if (dst == NULL || dst->md_info == NULL || src == NULL ||
294 src->md_info == NULL || dst->md_info != src->md_info) {
295 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200296 }
297
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200298 switch (src->md_info->type) {
299# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200300 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200301 mbedtls_md5_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200302 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200303# endif
304# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200305 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200306 mbedtls_ripemd160_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200307 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200308# endif
309# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200310 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200311 mbedtls_sha1_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200312 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200313# endif
314# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200315 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200316 mbedtls_sha256_clone(dst->md_ctx, src->md_ctx);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200317 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200318# endif
319# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200320 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200321 mbedtls_sha256_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200322 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200323# endif
324# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200325 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200326 mbedtls_sha512_clone(dst->md_ctx, src->md_ctx);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200327 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200328# endif
329# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200330 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200331 mbedtls_sha512_clone(dst->md_ctx, src->md_ctx);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200332 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200333# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200334 default:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200335 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200336 }
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200337
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200338 return 0;
Manuel Pégourié-Gonnard052a6c92015-07-06 16:06:02 +0200339}
340
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200341# define ALLOC(type) \
342 do { \
343 ctx->md_ctx = mbedtls_calloc(1, sizeof(mbedtls_##type##_context)); \
344 if (ctx->md_ctx == NULL) \
345 return MBEDTLS_ERR_MD_ALLOC_FAILED; \
346 mbedtls_##type##_init(ctx->md_ctx); \
347 } while (0)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200348
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200349int mbedtls_md_setup(mbedtls_md_context_t *ctx,
350 const mbedtls_md_info_t *md_info,
351 int hmac)
Paul Bakker17373852011-01-06 14:20:01 +0000352{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200353 if (md_info == NULL || ctx == NULL)
354 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000355
Gilles Peskined15c7402020-08-19 12:03:11 +0200356 ctx->md_info = md_info;
357 ctx->md_ctx = NULL;
358 ctx->hmac_ctx = NULL;
359
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200360 switch (md_info->type) {
361# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200362 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200363 ALLOC(md5);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200364 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200365# endif
366# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200367 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200368 ALLOC(ripemd160);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200369 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200370# endif
371# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200372 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200373 ALLOC(sha1);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200374 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200375# endif
376# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200377 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200378 ALLOC(sha256);
Mateusz Starzyke3c48b42021-04-19 16:46:28 +0200379 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200380# endif
381# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200382 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200383 ALLOC(sha256);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200384 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200385# endif
386# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200387 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200388 ALLOC(sha512);
Mateusz Starzyk3352a532021-04-06 14:28:22 +0200389 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200390# endif
391# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200392 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200393 ALLOC(sha512);
Gilles Peskine84867cf2019-07-19 15:46:03 +0200394 break;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200395# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200396 default:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200397 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200398 }
Paul Bakker17373852011-01-06 14:20:01 +0000399
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200400 if (hmac != 0) {
401 ctx->hmac_ctx = mbedtls_calloc(2, md_info->block_size);
402 if (ctx->hmac_ctx == NULL) {
403 mbedtls_md_free(ctx);
404 return MBEDTLS_ERR_MD_ALLOC_FAILED;
Manuel Pégourié-Gonnard4063ceb2015-03-25 16:08:53 +0100405 }
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100406 }
407
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200408 return 0;
Paul Bakker17373852011-01-06 14:20:01 +0000409}
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200410# undef ALLOC
Paul Bakker17373852011-01-06 14:20:01 +0000411
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200412int mbedtls_md_starts(mbedtls_md_context_t *ctx)
Paul Bakker562535d2011-01-20 16:42:01 +0000413{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200414 if (ctx == NULL || ctx->md_info == NULL)
415 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker562535d2011-01-20 16:42:01 +0000416
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200417 switch (ctx->md_info->type) {
418# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200419 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200420 return mbedtls_md5_starts(ctx->md_ctx);
421# endif
422# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200423 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200424 return mbedtls_ripemd160_starts(ctx->md_ctx);
425# endif
426# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200427 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200428 return mbedtls_sha1_starts(ctx->md_ctx);
429# endif
430# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200431 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200432 return mbedtls_sha256_starts(ctx->md_ctx, 1);
433# endif
434# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200435 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200436 return mbedtls_sha256_starts(ctx->md_ctx, 0);
437# endif
438# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200439 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200440 return mbedtls_sha512_starts(ctx->md_ctx, 1);
441# endif
442# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200443 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200444 return mbedtls_sha512_starts(ctx->md_ctx, 0);
445# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200446 default:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200447 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200448 }
Paul Bakker562535d2011-01-20 16:42:01 +0000449}
450
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200451int mbedtls_md_update(mbedtls_md_context_t *ctx,
452 const unsigned char *input,
453 size_t ilen)
Paul Bakker17373852011-01-06 14:20:01 +0000454{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200455 if (ctx == NULL || ctx->md_info == NULL)
456 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000457
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200458 switch (ctx->md_info->type) {
459# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200460 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200461 return mbedtls_md5_update(ctx->md_ctx, input, ilen);
462# endif
463# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200464 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200465 return mbedtls_ripemd160_update(ctx->md_ctx, input, ilen);
466# endif
467# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200468 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200469 return mbedtls_sha1_update(ctx->md_ctx, input, ilen);
470# endif
471# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200472 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200473 return mbedtls_sha256_update(ctx->md_ctx, input, ilen);
474# endif
475# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200476 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200477 return mbedtls_sha256_update(ctx->md_ctx, input, ilen);
478# endif
479# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200480 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200481 return mbedtls_sha512_update(ctx->md_ctx, input, ilen);
482# endif
483# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200484 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200485 return mbedtls_sha512_update(ctx->md_ctx, input, ilen);
486# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200487 default:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200488 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200489 }
Paul Bakker17373852011-01-06 14:20:01 +0000490}
491
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200492int mbedtls_md_finish(mbedtls_md_context_t *ctx, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000493{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200494 if (ctx == NULL || ctx->md_info == NULL)
495 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000496
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200497 switch (ctx->md_info->type) {
498# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200499 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200500 return mbedtls_md5_finish(ctx->md_ctx, output);
501# endif
502# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200503 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200504 return mbedtls_ripemd160_finish(ctx->md_ctx, output);
505# endif
506# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200507 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200508 return mbedtls_sha1_finish(ctx->md_ctx, output);
509# endif
510# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200511 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200512 return mbedtls_sha256_finish(ctx->md_ctx, output);
513# endif
514# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200515 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200516 return mbedtls_sha256_finish(ctx->md_ctx, output);
517# endif
518# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200519 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200520 return mbedtls_sha512_finish(ctx->md_ctx, output);
521# endif
522# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200523 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200524 return mbedtls_sha512_finish(ctx->md_ctx, output);
525# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200526 default:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200527 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200528 }
Paul Bakker17373852011-01-06 14:20:01 +0000529}
530
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200531int mbedtls_md(const mbedtls_md_info_t *md_info,
532 const unsigned char *input,
533 size_t ilen,
534 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000535{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200536 if (md_info == NULL)
537 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000538
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200539 switch (md_info->type) {
540# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200541 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200542 return mbedtls_md5(input, ilen, output);
543# endif
544# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200545 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200546 return mbedtls_ripemd160(input, ilen, output);
547# endif
548# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200549 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200550 return mbedtls_sha1(input, ilen, output);
551# endif
552# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200553 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200554 return mbedtls_sha256(input, ilen, output, 1);
555# endif
556# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200557 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200558 return mbedtls_sha256(input, ilen, output, 0);
559# endif
560# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200561 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200562 return mbedtls_sha512(input, ilen, output, 1);
563# endif
564# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200565 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200566 return mbedtls_sha512(input, ilen, output, 0);
567# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200568 default:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200569 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200570 }
Paul Bakker17373852011-01-06 14:20:01 +0000571}
572
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200573# if defined(MBEDTLS_FS_IO)
574int mbedtls_md_file(const mbedtls_md_info_t *md_info,
575 const char *path,
576 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000577{
Janos Follath24eed8d2019-11-22 13:21:35 +0000578 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200579 FILE *f;
580 size_t n;
581 mbedtls_md_context_t ctx;
582 unsigned char buf[1024];
Paul Bakker9c021ad2011-06-09 15:55:11 +0000583
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200584 if (md_info == NULL)
585 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000586
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200587 if ((f = fopen(path, "rb")) == NULL)
588 return MBEDTLS_ERR_MD_FILE_IO_ERROR;
Manuel Pégourié-Gonnardbcc03082015-06-24 00:09:29 +0200589
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200590 mbedtls_md_init(&ctx);
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200591
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200592 if ((ret = mbedtls_md_setup(&ctx, md_info, 0)) != 0)
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200593 goto cleanup;
594
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200595 if ((ret = mbedtls_md_starts(&ctx)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100596 goto cleanup;
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200597
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200598 while ((n = fread(buf, 1, sizeof(buf), f)) > 0)
599 if ((ret = mbedtls_md_update(&ctx, buf, n)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100600 goto cleanup;
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200601
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200602 if (ferror(f) != 0)
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200603 ret = MBEDTLS_ERR_MD_FILE_IO_ERROR;
Andres Amaya Garciaeb132b62017-06-23 16:30:31 +0100604 else
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200605 ret = mbedtls_md_finish(&ctx, output);
Manuel Pégourié-Gonnardbfffa902015-05-28 14:44:00 +0200606
607cleanup:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200608 mbedtls_platform_zeroize(buf, sizeof(buf));
609 fclose(f);
610 mbedtls_md_free(&ctx);
Paul Bakker9c021ad2011-06-09 15:55:11 +0000611
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200612 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000613}
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200614# endif /* MBEDTLS_FS_IO */
Paul Bakker17373852011-01-06 14:20:01 +0000615
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200616int mbedtls_md_hmac_starts(mbedtls_md_context_t *ctx,
617 const unsigned char *key,
618 size_t keylen)
Paul Bakker17373852011-01-06 14:20:01 +0000619{
Janos Follath24eed8d2019-11-22 13:21:35 +0000620 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200621 unsigned char sum[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100622 unsigned char *ipad, *opad;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100623 size_t i;
624
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200625 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL)
626 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000627
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200628 if (keylen > (size_t)ctx->md_info->block_size) {
629 if ((ret = mbedtls_md_starts(ctx)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100630 goto cleanup;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200631 if ((ret = mbedtls_md_update(ctx, key, keylen)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100632 goto cleanup;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200633 if ((ret = mbedtls_md_finish(ctx, sum)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100634 goto cleanup;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100635
636 keylen = ctx->md_info->size;
637 key = sum;
638 }
639
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200640 ipad = (unsigned char *)ctx->hmac_ctx;
641 opad = (unsigned char *)ctx->hmac_ctx + ctx->md_info->block_size;
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100642
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200643 memset(ipad, 0x36, ctx->md_info->block_size);
644 memset(opad, 0x5C, ctx->md_info->block_size);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100645
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200646 for (i = 0; i < keylen; i++) {
647 ipad[i] = (unsigned char)(ipad[i] ^ key[i]);
648 opad[i] = (unsigned char)(opad[i] ^ key[i]);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100649 }
650
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200651 if ((ret = mbedtls_md_starts(ctx)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100652 goto cleanup;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200653 if ((ret = mbedtls_md_update(ctx, ipad, ctx->md_info->block_size)) != 0)
Andres Amaya Garcia42e5e102017-07-20 16:27:03 +0100654 goto cleanup;
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100655
656cleanup:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200657 mbedtls_platform_zeroize(sum, sizeof(sum));
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100658
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200659 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000660}
661
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200662int mbedtls_md_hmac_update(mbedtls_md_context_t *ctx,
663 const unsigned char *input,
664 size_t ilen)
Paul Bakker17373852011-01-06 14:20:01 +0000665{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200666 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL)
667 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000668
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200669 return mbedtls_md_update(ctx, input, ilen);
Paul Bakker17373852011-01-06 14:20:01 +0000670}
671
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200672int mbedtls_md_hmac_finish(mbedtls_md_context_t *ctx, unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000673{
Janos Follath24eed8d2019-11-22 13:21:35 +0000674 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200675 unsigned char tmp[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100676 unsigned char *opad;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100677
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200678 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL)
679 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000680
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200681 opad = (unsigned char *)ctx->hmac_ctx + ctx->md_info->block_size;
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100682
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200683 if ((ret = mbedtls_md_finish(ctx, tmp)) != 0)
684 return ret;
685 if ((ret = mbedtls_md_starts(ctx)) != 0)
686 return ret;
687 if ((ret = mbedtls_md_update(ctx, opad, ctx->md_info->block_size)) != 0)
688 return ret;
689 if ((ret = mbedtls_md_update(ctx, tmp, ctx->md_info->size)) != 0)
690 return ret;
691 return mbedtls_md_finish(ctx, output);
Paul Bakker17373852011-01-06 14:20:01 +0000692}
693
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200694int mbedtls_md_hmac_reset(mbedtls_md_context_t *ctx)
Paul Bakker17373852011-01-06 14:20:01 +0000695{
Janos Follath24eed8d2019-11-22 13:21:35 +0000696 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100697 unsigned char *ipad;
698
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200699 if (ctx == NULL || ctx->md_info == NULL || ctx->hmac_ctx == NULL)
700 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000701
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200702 ipad = (unsigned char *)ctx->hmac_ctx;
Manuel Pégourié-Gonnarddfb3dc82015-03-25 11:49:07 +0100703
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200704 if ((ret = mbedtls_md_starts(ctx)) != 0)
705 return ret;
706 return mbedtls_md_update(ctx, ipad, ctx->md_info->block_size);
Paul Bakker17373852011-01-06 14:20:01 +0000707}
708
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200709int mbedtls_md_hmac(const mbedtls_md_info_t *md_info,
710 const unsigned char *key,
711 size_t keylen,
712 const unsigned char *input,
713 size_t ilen,
714 unsigned char *output)
Paul Bakker17373852011-01-06 14:20:01 +0000715{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200716 mbedtls_md_context_t ctx;
Janos Follath24eed8d2019-11-22 13:21:35 +0000717 int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100718
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200719 if (md_info == NULL)
720 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker17373852011-01-06 14:20:01 +0000721
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200722 mbedtls_md_init(&ctx);
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100723
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200724 if ((ret = mbedtls_md_setup(&ctx, md_info, 1)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100725 goto cleanup;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100726
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200727 if ((ret = mbedtls_md_hmac_starts(&ctx, key, keylen)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100728 goto cleanup;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200729 if ((ret = mbedtls_md_hmac_update(&ctx, input, ilen)) != 0)
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100730 goto cleanup;
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200731 if ((ret = mbedtls_md_hmac_finish(&ctx, output)) != 0)
Andres Amaya Garciaaa464ef2017-07-21 14:21:53 +0100732 goto cleanup;
Manuel Pégourié-Gonnard8379a822015-03-24 16:48:22 +0100733
Andres Amaya Garcia0dd4fa02017-06-28 14:16:07 +0100734cleanup:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200735 mbedtls_md_free(&ctx);
Paul Bakker17373852011-01-06 14:20:01 +0000736
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200737 return ret;
Paul Bakker17373852011-01-06 14:20:01 +0000738}
739
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200740int mbedtls_md_process(mbedtls_md_context_t *ctx, const unsigned char *data)
Paul Bakker1bd3ae82013-03-13 10:26:44 +0100741{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200742 if (ctx == NULL || ctx->md_info == NULL)
743 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Paul Bakker1bd3ae82013-03-13 10:26:44 +0100744
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200745 switch (ctx->md_info->type) {
746# if defined(MBEDTLS_MD5_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200747 case MBEDTLS_MD_MD5:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200748 return mbedtls_internal_md5_process(ctx->md_ctx, data);
749# endif
750# if defined(MBEDTLS_RIPEMD160_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200751 case MBEDTLS_MD_RIPEMD160:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200752 return mbedtls_internal_ripemd160_process(ctx->md_ctx, data);
753# endif
754# if defined(MBEDTLS_SHA1_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200755 case MBEDTLS_MD_SHA1:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200756 return mbedtls_internal_sha1_process(ctx->md_ctx, data);
757# endif
758# if defined(MBEDTLS_SHA224_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200759 case MBEDTLS_MD_SHA224:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200760 return mbedtls_internal_sha256_process(ctx->md_ctx, data);
761# endif
762# if defined(MBEDTLS_SHA256_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200763 case MBEDTLS_MD_SHA256:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200764 return mbedtls_internal_sha256_process(ctx->md_ctx, data);
765# endif
766# if defined(MBEDTLS_SHA384_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200767 case MBEDTLS_MD_SHA384:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200768 return mbedtls_internal_sha512_process(ctx->md_ctx, data);
769# endif
770# if defined(MBEDTLS_SHA512_C)
Gilles Peskine84867cf2019-07-19 15:46:03 +0200771 case MBEDTLS_MD_SHA512:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200772 return mbedtls_internal_sha512_process(ctx->md_ctx, data);
773# endif
Gilles Peskine84867cf2019-07-19 15:46:03 +0200774 default:
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200775 return MBEDTLS_ERR_MD_BAD_INPUT_DATA;
Gilles Peskine84867cf2019-07-19 15:46:03 +0200776 }
Paul Bakker1bd3ae82013-03-13 10:26:44 +0100777}
778
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200779unsigned char mbedtls_md_get_size(const mbedtls_md_info_t *md_info)
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100780{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200781 if (md_info == NULL)
782 return 0;
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100783
784 return md_info->size;
785}
786
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200787mbedtls_md_type_t mbedtls_md_get_type(const mbedtls_md_info_t *md_info)
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100788{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200789 if (md_info == NULL)
790 return MBEDTLS_MD_NONE;
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100791
792 return md_info->type;
793}
794
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200795const char *mbedtls_md_get_name(const mbedtls_md_info_t *md_info)
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100796{
Mateusz Starzykc0eabdc2021-08-03 14:09:02 +0200797 if (md_info == NULL)
798 return NULL;
Manuel Pégourié-Gonnardca878db2015-03-24 12:13:30 +0100799
800 return md_info->name;
801}
802
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200803#endif /* MBEDTLS_MD_C */