blob: 117af93400063e9ee98d01b070d511f4c244a895 [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/**
2 * \file dhm.h
Paul Bakkere0ccd0a2009-01-04 16:27:10 +00003 *
Darryl Green11999bb2018-03-13 15:22:58 +00004 * \brief This file contains Diffie-Hellman-Merkle (DHM) key exchange
Rose Zadikee963592018-04-18 09:46:12 +01005 * definitions and functions.
Rose Zadikf763f2b2018-04-17 11:00:40 +01006 *
7 * Diffie-Hellman-Merkle (DHM) key exchange is defined in
Darryl Green11999bb2018-03-13 15:22:58 +00008 * <em>RFC-2631: Diffie-Hellman Key Agreement Method</em> and
9 * <em>Public-Key Cryptography Standards (PKCS) #3: Diffie
Rose Zadikf763f2b2018-04-17 11:00:40 +010010 * Hellman Key Agreement Standard</em>.
Rose Zadik41ad0822018-01-26 10:54:57 +000011 *
12 * <em>RFC-3526: More Modular Exponential (MODP) Diffie-Hellman groups for
13 * Internet Key Exchange (IKE)</em> defines a number of standardized
14 * Diffie-Hellman groups for IKE.
15 *
16 * <em>RFC-5114: Additional Diffie-Hellman Groups for Use with IETF
17 * Standards</em> defines a number of standardized Diffie-Hellman
18 * groups that can be used.
Paul Bakker37ca75d2011-01-06 12:28:03 +000019 *
Jaeden Amero784de592018-01-26 17:52:01 +000020 * \warning The security of the DHM key exchange relies on the proper choice
21 * of prime modulus - optimally, it should be a safe prime. The usage
22 * of non-safe primes both decreases the difficulty of the underlying
23 * discrete logarithm problem and can lead to small subgroup attacks
24 * leaking private exponent bits when invalid public keys are used
25 * and not detected. This is especially relevant if the same DHM
26 * parameters are reused for multiple key exchanges as in static DHM,
27 * while the criticality of small-subgroup attacks is lower for
28 * ephemeral DHM.
29 *
30 * \warning For performance reasons, the code does neither perform primality
31 * nor safe primality tests, nor the expensive checks for invalid
32 * subgroups. Moreover, even if these were performed, non-standardized
33 * primes cannot be trusted because of the possibility of backdoors
34 * that can't be effectively checked for.
35 *
36 * \warning Diffie-Hellman-Merkle is therefore a security risk when not using
37 * standardized primes generated using a trustworthy ("nothing up
38 * my sleeve") method, such as the RFC 3526 / 7919 primes. In the TLS
39 * protocol, DH parameters need to be negotiated, so using the default
40 * primes systematically is not always an option. If possible, use
41 * Elliptic Curve Diffie-Hellman (ECDH), which has better performance,
42 * and for which the TLS protocol mandates the use of standard
43 * parameters.
44 *
Darryl Greena40a1012018-01-05 15:33:17 +000045 */
46/*
Bence Szépkúti1e148272020-08-07 13:07:28 +020047 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +020048 * SPDX-License-Identifier: Apache-2.0
49 *
50 * Licensed under the Apache License, Version 2.0 (the "License"); you may
51 * not use this file except in compliance with the License.
52 * You may obtain a copy of the License at
53 *
54 * http://www.apache.org/licenses/LICENSE-2.0
55 *
56 * Unless required by applicable law or agreed to in writing, software
57 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
58 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
59 * See the License for the specific language governing permissions and
60 * limitations under the License.
Paul Bakker5121ce52009-01-03 21:22:43 +000061 */
Rose Zadik41ad0822018-01-26 10:54:57 +000062
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020063#ifndef MBEDTLS_DHM_H
64#define MBEDTLS_DHM_H
Paul Bakker5121ce52009-01-03 21:22:43 +000065
Reuven Levin1f35ca92017-12-07 10:09:32 +000066#if !defined(MBEDTLS_CONFIG_FILE)
Jaeden Ameroc49fbbf2019-07-04 20:01:14 +010067#include "mbedtls/config.h"
Reuven Levin1f35ca92017-12-07 10:09:32 +000068#else
69#include MBEDTLS_CONFIG_FILE
70#endif
Jaeden Ameroc49fbbf2019-07-04 20:01:14 +010071#include "mbedtls/bignum.h"
Reuven Levin1f35ca92017-12-07 10:09:32 +000072
Paul Bakkerf3b86c12011-01-27 15:24:17 +000073/*
74 * DHM Error codes
75 */
Gilles Peskinea3974432021-07-26 18:48:10 +020076/** Bad input parameters. */
77#define MBEDTLS_ERR_DHM_BAD_INPUT_DATA -0x3080
78/** Reading of the DHM parameters failed. */
79#define MBEDTLS_ERR_DHM_READ_PARAMS_FAILED -0x3100
80/** Making of the DHM parameters failed. */
81#define MBEDTLS_ERR_DHM_MAKE_PARAMS_FAILED -0x3180
82/** Reading of the public values failed. */
83#define MBEDTLS_ERR_DHM_READ_PUBLIC_FAILED -0x3200
84/** Making of the public value failed. */
85#define MBEDTLS_ERR_DHM_MAKE_PUBLIC_FAILED -0x3280
86/** Calculation of the DHM secret failed. */
87#define MBEDTLS_ERR_DHM_CALC_SECRET_FAILED -0x3300
88/** The ASN.1 data is not formatted correctly. */
89#define MBEDTLS_ERR_DHM_INVALID_FORMAT -0x3380
90/** Allocation of memory failed. */
91#define MBEDTLS_ERR_DHM_ALLOC_FAILED -0x3400
92/** Read or write of file failed. */
93#define MBEDTLS_ERR_DHM_FILE_IO_ERROR -0x3480
Ron Eldor9924bdc2018-10-04 10:59:13 +030094
95/* MBEDTLS_ERR_DHM_HW_ACCEL_FAILED is deprecated and should not be used. */
Gilles Peskinea3974432021-07-26 18:48:10 +020096/** DHM hardware accelerator failed. */
97#define MBEDTLS_ERR_DHM_HW_ACCEL_FAILED -0x3500
Ron Eldor9924bdc2018-10-04 10:59:13 +030098
Gilles Peskinea3974432021-07-26 18:48:10 +020099/** Setting the modulus and generator failed. */
100#define MBEDTLS_ERR_DHM_SET_GROUP_FAILED -0x3580
Paul Bakker29b64762012-09-25 09:36:44 +0000101
Paul Bakker407a0da2013-06-27 14:29:21 +0200102#ifdef __cplusplus
103extern "C" {
104#endif
105
Ron Eldor4e6d55d2018-02-07 16:36:15 +0200106#if !defined(MBEDTLS_DHM_ALT)
107
Paul Bakker29b64762012-09-25 09:36:44 +0000108/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000109 * \brief The DHM context structure.
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000110 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100111typedef struct mbedtls_dhm_context {
Rose Zadik41ad0822018-01-26 10:54:57 +0000112 size_t len; /*!< The size of \p P in Bytes. */
113 mbedtls_mpi P; /*!< The prime modulus. */
114 mbedtls_mpi G; /*!< The generator. */
115 mbedtls_mpi X; /*!< Our secret value. */
116 mbedtls_mpi GX; /*!< Our public key = \c G^X mod \c P. */
117 mbedtls_mpi GY; /*!< The public key of the peer = \c G^Y mod \c P. */
118 mbedtls_mpi K; /*!< The shared secret = \c G^(XY) mod \c P. */
119 mbedtls_mpi RP; /*!< The cached value = \c R^2 mod \c P. */
120 mbedtls_mpi Vi; /*!< The blinding value. */
121 mbedtls_mpi Vf; /*!< The unblinding value. */
122 mbedtls_mpi pX; /*!< The previous \c X. */
Paul Bakker5121ce52009-01-03 21:22:43 +0000123}
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200124mbedtls_dhm_context;
Paul Bakker5121ce52009-01-03 21:22:43 +0000125
Ron Eldor4e6d55d2018-02-07 16:36:15 +0200126#else /* MBEDTLS_DHM_ALT */
127#include "dhm_alt.h"
128#endif /* MBEDTLS_DHM_ALT */
129
Paul Bakker5121ce52009-01-03 21:22:43 +0000130/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000131 * \brief This function initializes the DHM context.
Paul Bakker8f870b02014-06-20 13:32:38 +0200132 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000133 * \param ctx The DHM context to initialize.
Paul Bakker8f870b02014-06-20 13:32:38 +0200134 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100135void mbedtls_dhm_init(mbedtls_dhm_context *ctx);
Paul Bakker8f870b02014-06-20 13:32:38 +0200136
137/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500138 * \brief This function parses the DHM parameters in a
139 * TLS ServerKeyExchange handshake message
140 * (DHM modulus, generator, and public key).
Paul Bakker5121ce52009-01-03 21:22:43 +0000141 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500142 * \note In a TLS handshake, this is the how the client
143 * sets up its DHM context from the server's public
144 * DHM key material.
145 *
146 * \param ctx The DHM context to use. This must be initialized.
Hanno Beckerf240ea02017-10-02 15:09:14 +0100147 * \param p On input, *p must be the start of the input buffer.
148 * On output, *p is updated to point to the end of the data
149 * that has been read. On success, this is the first byte
150 * past the end of the ServerKeyExchange parameters.
151 * On error, this is the point at which an error has been
152 * detected, which is usually not useful except to debug
153 * failures.
Rose Zadik41ad0822018-01-26 10:54:57 +0000154 * \param end The end of the input buffer.
Paul Bakker5121ce52009-01-03 21:22:43 +0000155 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100156 * \return \c 0 on success.
157 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000158 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100159int mbedtls_dhm_read_params(mbedtls_dhm_context *ctx,
160 unsigned char **p,
161 const unsigned char *end);
Paul Bakker5121ce52009-01-03 21:22:43 +0000162
163/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500164 * \brief This function generates a DHM key pair and exports its
165 * public part together with the DHM parameters in the format
166 * used in a TLS ServerKeyExchange handshake message.
Paul Bakker5121ce52009-01-03 21:22:43 +0000167 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500168 * \note This function assumes that the DHM parameters \c ctx->P
169 * and \c ctx->G have already been properly set. For that, use
Jaeden Amero9564e972018-01-30 16:56:13 +0000170 * mbedtls_dhm_set_group() below in conjunction with
171 * mbedtls_mpi_read_binary() and mbedtls_mpi_read_string().
Paul Bakker5121ce52009-01-03 21:22:43 +0000172 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500173 * \note In a TLS handshake, this is the how the server generates
174 * and exports its DHM key material.
175 *
176 * \param ctx The DHM context to use. This must be initialized
177 * and have the DHM parameters set. It may or may not
178 * already have imported the peer's public key.
Rose Zadikf763f2b2018-04-17 11:00:40 +0100179 * \param x_size The private key size in Bytes.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500180 * \param olen The address at which to store the number of Bytes
181 * written on success. This must not be \c NULL.
182 * \param output The destination buffer. This must be a writable buffer of
183 * sufficient size to hold the reduced binary presentation of
184 * the modulus, the generator and the public key, each wrapped
185 * with a 2-byte length field. It is the responsibility of the
186 * caller to ensure that enough space is available. Refer to
187 * mbedtls_mpi_size() to computing the byte-size of an MPI.
188 * \param f_rng The RNG function. Must not be \c NULL.
189 * \param p_rng The RNG context to be passed to \p f_rng. This may be
190 * \c NULL if \p f_rng doesn't need a context parameter.
Rose Zadikf763f2b2018-04-17 11:00:40 +0100191 *
192 * \return \c 0 on success.
193 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000194 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100195int mbedtls_dhm_make_params(mbedtls_dhm_context *ctx, int x_size,
196 unsigned char *output, size_t *olen,
197 int (*f_rng)(void *, unsigned char *, size_t),
198 void *p_rng);
Paul Bakker5121ce52009-01-03 21:22:43 +0000199
200/**
Rose Zadikf763f2b2018-04-17 11:00:40 +0100201 * \brief This function sets the prime modulus and generator.
202 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500203 * \note This function can be used to set \c ctx->P, \c ctx->G
Rose Zadikf763f2b2018-04-17 11:00:40 +0100204 * in preparation for mbedtls_dhm_make_params().
Hanno Becker8880e752017-10-04 13:15:08 +0100205 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500206 * \param ctx The DHM context to configure. This must be initialized.
207 * \param P The MPI holding the DHM prime modulus. This must be
208 * an initialized MPI.
209 * \param G The MPI holding the DHM generator. This must be an
210 * initialized MPI.
Hanno Becker8880e752017-10-04 13:15:08 +0100211 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100212 * \return \c 0 if successful.
213 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Hanno Becker8880e752017-10-04 13:15:08 +0100214 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100215int mbedtls_dhm_set_group(mbedtls_dhm_context *ctx,
216 const mbedtls_mpi *P,
217 const mbedtls_mpi *G);
Hanno Becker8880e752017-10-04 13:15:08 +0100218
219/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500220 * \brief This function imports the raw public value of the peer.
Paul Bakker5121ce52009-01-03 21:22:43 +0000221 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500222 * \note In a TLS handshake, this is the how the server imports
223 * the Client's public DHM key.
224 *
225 * \param ctx The DHM context to use. This must be initialized and have
226 * its DHM parameters set, e.g. via mbedtls_dhm_set_group().
227 * It may or may not already have generated its own private key.
228 * \param input The input buffer containing the \c G^Y value of the peer.
229 * This must be a readable buffer of size \p ilen Bytes.
230 * \param ilen The size of the input buffer \p input in Bytes.
Paul Bakker5121ce52009-01-03 21:22:43 +0000231 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100232 * \return \c 0 on success.
233 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000234 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100235int mbedtls_dhm_read_public(mbedtls_dhm_context *ctx,
236 const unsigned char *input, size_t ilen);
Paul Bakker5121ce52009-01-03 21:22:43 +0000237
238/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500239 * \brief This function creates a DHM key pair and exports
240 * the raw public key in big-endian format.
Paul Bakker5121ce52009-01-03 21:22:43 +0000241 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100242 * \note The destination buffer is always fully written
243 * so as to contain a big-endian representation of G^X mod P.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500244 * If it is larger than \c ctx->len, it is padded accordingly
Rose Zadikf763f2b2018-04-17 11:00:40 +0100245 * with zero-bytes at the beginning.
246 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500247 * \param ctx The DHM context to use. This must be initialized and
248 * have the DHM parameters set. It may or may not already
249 * have imported the peer's public key.
Rose Zadikf763f2b2018-04-17 11:00:40 +0100250 * \param x_size The private key size in Bytes.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500251 * \param output The destination buffer. This must be a writable buffer of
252 * size \p olen Bytes.
253 * \param olen The length of the destination buffer. This must be at least
254 * equal to `ctx->len` (the size of \c P).
255 * \param f_rng The RNG function. This must not be \c NULL.
256 * \param p_rng The RNG context to be passed to \p f_rng. This may be \c NULL
257 * if \p f_rng doesn't need a context argument.
Paul Bakker5121ce52009-01-03 21:22:43 +0000258 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100259 * \return \c 0 on success.
260 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000261 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100262int mbedtls_dhm_make_public(mbedtls_dhm_context *ctx, int x_size,
263 unsigned char *output, size_t olen,
264 int (*f_rng)(void *, unsigned char *, size_t),
265 void *p_rng);
Paul Bakker5121ce52009-01-03 21:22:43 +0000266
267/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500268 * \brief This function derives and exports the shared secret
269 * \c (G^Y)^X mod \c P.
Paul Bakker5121ce52009-01-03 21:22:43 +0000270 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500271 * \note If \p f_rng is not \c NULL, it is used to blind the input as
272 * a countermeasure against timing attacks. Blinding is used
273 * only if our private key \c X is re-used, and not used
274 * otherwise. We recommend always passing a non-NULL
275 * \p f_rng argument.
Rose Zadikf763f2b2018-04-17 11:00:40 +0100276 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500277 * \param ctx The DHM context to use. This must be initialized
278 * and have its own private key generated and the peer's
279 * public key imported.
280 * \param output The buffer to write the generated shared key to. This
281 * must be a writable buffer of size \p output_size Bytes.
282 * \param output_size The size of the destination buffer. This must be at
283 * least the size of \c ctx->len (the size of \c P).
Rose Zadik41ad0822018-01-26 10:54:57 +0000284 * \param olen On exit, holds the actual number of Bytes written.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500285 * \param f_rng The RNG function, for blinding purposes. This may
286 * b \c NULL if blinding isn't needed.
287 * \param p_rng The RNG context. This may be \c NULL if \p f_rng
288 * doesn't need a context argument.
Paul Bakker5121ce52009-01-03 21:22:43 +0000289 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100290 * \return \c 0 on success.
291 * \return An \c MBEDTLS_ERR_DHM_XXX error code on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000292 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100293int mbedtls_dhm_calc_secret(mbedtls_dhm_context *ctx,
294 unsigned char *output, size_t output_size, size_t *olen,
295 int (*f_rng)(void *, unsigned char *, size_t),
296 void *p_rng);
Paul Bakker5121ce52009-01-03 21:22:43 +0000297
Paul Bakker9a736322012-11-14 12:39:52 +0000298/**
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500299 * \brief This function frees and clears the components
300 * of a DHM context.
Paul Bakker8f870b02014-06-20 13:32:38 +0200301 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500302 * \param ctx The DHM context to free and clear. This may be \c NULL,
303 * in which case this function is a no-op. If it is not \c NULL,
304 * it must point to an initialized DHM context.
Paul Bakker5121ce52009-01-03 21:22:43 +0000305 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100306void mbedtls_dhm_free(mbedtls_dhm_context *ctx);
Paul Bakker5121ce52009-01-03 21:22:43 +0000307
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200308#if defined(MBEDTLS_ASN1_PARSE_C)
Paul Bakker40ce79f2013-09-15 17:43:54 +0200309/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000310 * \brief This function parses DHM parameters in PEM or DER format.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200311 *
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500312 * \param dhm The DHM context to import the DHM parameters into.
313 * This must be initialized.
314 * \param dhmin The input buffer. This must be a readable buffer of
315 * length \p dhminlen Bytes.
316 * \param dhminlen The size of the input buffer \p dhmin, including the
317 * terminating \c NULL Byte for PEM data.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200318 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100319 * \return \c 0 on success.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500320 * \return An \c MBEDTLS_ERR_DHM_XXX or \c MBEDTLS_ERR_PEM_XXX error
321 * code on failure.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200322 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100323int mbedtls_dhm_parse_dhm(mbedtls_dhm_context *dhm, const unsigned char *dhmin,
324 size_t dhminlen);
Paul Bakker40ce79f2013-09-15 17:43:54 +0200325
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200326#if defined(MBEDTLS_FS_IO)
Paul Bakker40ce79f2013-09-15 17:43:54 +0200327/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000328 * \brief This function loads and parses DHM parameters from a file.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200329 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000330 * \param dhm The DHM context to load the parameters to.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500331 * This must be initialized.
Rose Zadik41ad0822018-01-26 10:54:57 +0000332 * \param path The filename to read the DHM parameters from.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500333 * This must not be \c NULL.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200334 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100335 * \return \c 0 on success.
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500336 * \return An \c MBEDTLS_ERR_DHM_XXX or \c MBEDTLS_ERR_PEM_XXX
337 * error code on failure.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200338 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100339int mbedtls_dhm_parse_dhmfile(mbedtls_dhm_context *dhm, const char *path);
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200340#endif /* MBEDTLS_FS_IO */
341#endif /* MBEDTLS_ASN1_PARSE_C */
nirekh01d569ecf2018-01-09 16:43:21 +0000342
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500343#if defined(MBEDTLS_SELF_TEST)
344
Paul Bakker5121ce52009-01-03 21:22:43 +0000345/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000346 * \brief The DMH checkup routine.
Paul Bakker5121ce52009-01-03 21:22:43 +0000347 *
Rose Zadikf763f2b2018-04-17 11:00:40 +0100348 * \return \c 0 on success.
349 * \return \c 1 on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000350 */
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100351int mbedtls_dhm_self_test(int verbose);
Paul Bakker5121ce52009-01-03 21:22:43 +0000352
Andrzej Kurekc470b6b2019-01-31 08:20:20 -0500353#endif /* MBEDTLS_SELF_TEST */
Paul Bakker5121ce52009-01-03 21:22:43 +0000354#ifdef __cplusplus
355}
356#endif
357
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100358/**
Gilles Peskined40f0072020-02-26 19:52:04 +0100359 * RFC 3526, RFC 5114 and RFC 7919 standardize a number of
360 * Diffie-Hellman groups, some of which are included here
361 * for use within the SSL/TLS module and the user's convenience
362 * when configuring the Diffie-Hellman parameters by hand
363 * through \c mbedtls_ssl_conf_dh_param.
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100364 *
Jaeden Amero9564e972018-01-30 16:56:13 +0000365 * The following lists the source of the above groups in the standards:
366 * - RFC 5114 section 2.2: 2048-bit MODP Group with 224-bit Prime Order Subgroup
367 * - RFC 3526 section 3: 2048-bit MODP Group
368 * - RFC 3526 section 4: 3072-bit MODP Group
369 * - RFC 3526 section 5: 4096-bit MODP Group
370 * - RFC 7919 section A.1: ffdhe2048
371 * - RFC 7919 section A.2: ffdhe3072
372 * - RFC 7919 section A.3: ffdhe4096
373 * - RFC 7919 section A.4: ffdhe6144
374 * - RFC 7919 section A.5: ffdhe8192
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100375 *
376 * The constants with suffix "_p" denote the chosen prime moduli, while
377 * the constants with suffix "_g" denote the chosen generator
378 * of the associated prime field.
379 *
380 * The constants further suffixed with "_bin" are provided in binary format,
381 * while all other constants represent null-terminated strings holding the
382 * hexadecimal presentation of the respective numbers.
383 *
384 * The primes from RFC 3526 and RFC 7919 have been generating by the following
385 * trust-worthy procedure:
386 * - Fix N in { 2048, 3072, 4096, 6144, 8192 } and consider the N-bit number
387 * the first and last 64 bits are all 1, and the remaining N - 128 bits of
388 * which are 0x7ff...ff.
389 * - Add the smallest multiple of the first N - 129 bits of the binary expansion
390 * of pi (for RFC 5236) or e (for RFC 7919) to this intermediate bit-string
391 * such that the resulting integer is a safe-prime.
392 * - The result is the respective RFC 3526 / 7919 prime, and the corresponding
393 * generator is always chosen to be 2 (which is a square for these prime,
394 * hence the corresponding subgroup has order (p-1)/2 and avoids leaking a
395 * bit in the private exponent).
396 *
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100397 */
398
399#if !defined(MBEDTLS_DEPRECATED_REMOVED)
400
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100401/**
402 * \warning The origin of the primes in RFC 5114 is not documented and
403 * their use therefore constitutes a security risk!
404 *
405 * \deprecated The hex-encoded primes from RFC 5114 are deprecated and are
406 * likely to be removed in a future version of the library without
407 * replacement.
408 */
409
Jaeden Amero9564e972018-01-30 16:56:13 +0000410/**
411 * The hexadecimal presentation of the prime underlying the
412 * 2048-bit MODP Group with 224-bit Prime Order Subgroup, as defined
413 * in <em>RFC-5114: Additional Diffie-Hellman Groups for Use with
414 * IETF Standards</em>.
415 */
Jaeden Amero129f5082018-02-08 14:25:36 +0000416#define MBEDTLS_DHM_RFC5114_MODP_2048_P \
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100417 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
418 "AD107E1E9123A9D0D660FAA79559C51FA20D64E5683B9FD1" \
419 "B54B1597B61D0A75E6FA141DF95A56DBAF9A3C407BA1DF15" \
420 "EB3D688A309C180E1DE6B85A1274A0A66D3F8152AD6AC212" \
421 "9037C9EDEFDA4DF8D91E8FEF55B7394B7AD5B7D0B6C12207" \
422 "C9F98D11ED34DBF6C6BA0B2C8BBC27BE6A00E0A0B9C49708" \
423 "B3BF8A317091883681286130BC8985DB1602E714415D9330" \
424 "278273C7DE31EFDC7310F7121FD5A07415987D9ADC0A486D" \
425 "CDF93ACC44328387315D75E198C641A480CD86A1B9E587E8" \
426 "BE60E69CC928B2B9C52172E413042E9B23F10B0E16E79763" \
427 "C9B53DCF4BA80A29E3FB73C16B8E75B97EF363E2FFA31F71" \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100428 "CF9DE5384E71B81C0AC4DFFE0C10E64F")
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100429
Jaeden Amero9564e972018-01-30 16:56:13 +0000430/**
431 * The hexadecimal presentation of the chosen generator of the 2048-bit MODP
432 * Group with 224-bit Prime Order Subgroup, as defined in <em>RFC-5114:
433 * Additional Diffie-Hellman Groups for Use with IETF Standards</em>.
434 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100435#define MBEDTLS_DHM_RFC5114_MODP_2048_G \
436 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
437 "AC4032EF4F2D9AE39DF30B5C8FFDAC506CDEBE7B89998CAF" \
438 "74866A08CFE4FFE3A6824A4E10B9A6F0DD921F01A70C4AFA" \
439 "AB739D7700C29F52C57DB17C620A8652BE5E9001A8D66AD7" \
440 "C17669101999024AF4D027275AC1348BB8A762D0521BC98A" \
441 "E247150422EA1ED409939D54DA7460CDB5F6C6B250717CBE" \
442 "F180EB34118E98D119529A45D6F834566E3025E316A330EF" \
443 "BB77A86F0C1AB15B051AE3D428C8F8ACB70A8137150B8EEB" \
444 "10E183EDD19963DDD9E263E4770589EF6AA21E7F5F2FF381" \
445 "B539CCE3409D13CD566AFBB48D6C019181E1BCFE94B30269" \
446 "EDFE72FE9B6AA4BD7B5A0F1C71CFFF4C19C418E1F6EC0179" \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100447 "81BC087F2A7065B384B890D3191F2BFA")
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100448
449/**
Jaeden Amero9564e972018-01-30 16:56:13 +0000450 * The hexadecimal presentation of the prime underlying the 2048-bit MODP
451 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
452 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
453 *
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100454 * \deprecated The hex-encoded primes from RFC 3625 are deprecated and
455 * superseded by the corresponding macros providing them as
456 * binary constants. Their hex-encoded constants are likely
457 * to be removed in a future version of the library.
458 *
459 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100460#define MBEDTLS_DHM_RFC3526_MODP_2048_P \
461 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
462 "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
463 "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
464 "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
465 "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
466 "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
467 "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
468 "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
469 "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
470 "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
471 "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100472 "15728E5A8AACAA68FFFFFFFFFFFFFFFF")
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100473
Jaeden Amero9564e972018-01-30 16:56:13 +0000474/**
475 * The hexadecimal presentation of the chosen generator of the 2048-bit MODP
476 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
477 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
478 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100479#define MBEDTLS_DHM_RFC3526_MODP_2048_G \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100480 MBEDTLS_DEPRECATED_STRING_CONSTANT("02")
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100481
Jaeden Amero9564e972018-01-30 16:56:13 +0000482/**
483 * The hexadecimal presentation of the prime underlying the 3072-bit MODP
484 * Group, as defined in <em>RFC-3072: More Modular Exponential (MODP)
485 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
486 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100487#define MBEDTLS_DHM_RFC3526_MODP_3072_P \
488 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
489 "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
490 "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
491 "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
492 "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
493 "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
494 "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
495 "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
496 "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
497 "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
498 "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
499 "15728E5A8AAAC42DAD33170D04507A33A85521ABDF1CBA64" \
500 "ECFB850458DBEF0A8AEA71575D060C7DB3970F85A6E1E4C7" \
501 "ABF5AE8CDB0933D71E8C94E04A25619DCEE3D2261AD2EE6B" \
502 "F12FFA06D98A0864D87602733EC86A64521F2B18177B200C" \
503 "BBE117577A615D6C770988C0BAD946E208E24FA074E5AB31" \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100504 "43DB5BFCE0FD108E4B82D120A93AD2CAFFFFFFFFFFFFFFFF")
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100505
Jaeden Amero9564e972018-01-30 16:56:13 +0000506/**
507 * The hexadecimal presentation of the chosen generator of the 3072-bit MODP
508 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
509 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
510 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100511#define MBEDTLS_DHM_RFC3526_MODP_3072_G \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100512 MBEDTLS_DEPRECATED_STRING_CONSTANT("02")
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100513
Jaeden Amero9564e972018-01-30 16:56:13 +0000514/**
515 * The hexadecimal presentation of the prime underlying the 4096-bit MODP
516 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
517 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
518 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100519#define MBEDTLS_DHM_RFC3526_MODP_4096_P \
520 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
521 "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
522 "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
523 "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
524 "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
525 "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
526 "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
527 "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
528 "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
529 "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
530 "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
531 "15728E5A8AAAC42DAD33170D04507A33A85521ABDF1CBA64" \
532 "ECFB850458DBEF0A8AEA71575D060C7DB3970F85A6E1E4C7" \
533 "ABF5AE8CDB0933D71E8C94E04A25619DCEE3D2261AD2EE6B" \
534 "F12FFA06D98A0864D87602733EC86A64521F2B18177B200C" \
535 "BBE117577A615D6C770988C0BAD946E208E24FA074E5AB31" \
536 "43DB5BFCE0FD108E4B82D120A92108011A723C12A787E6D7" \
537 "88719A10BDBA5B2699C327186AF4E23C1A946834B6150BDA" \
538 "2583E9CA2AD44CE8DBBBC2DB04DE8EF92E8EFC141FBECAA6" \
539 "287C59474E6BC05D99B2964FA090C3A2233BA186515BE7ED" \
540 "1F612970CEE2D7AFB81BDD762170481CD0069127D5B05AA9" \
541 "93B4EA988D8FDDC186FFB7DC90A6C08F4DF435C934063199" \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100542 "FFFFFFFFFFFFFFFF")
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100543
Jaeden Amero9564e972018-01-30 16:56:13 +0000544/**
545 * The hexadecimal presentation of the chosen generator of the 4096-bit MODP
546 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
547 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
548 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100549#define MBEDTLS_DHM_RFC3526_MODP_4096_G \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100550 MBEDTLS_DEPRECATED_STRING_CONSTANT("02")
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100551
552#endif /* MBEDTLS_DEPRECATED_REMOVED */
553
554/*
555 * Trustworthy DHM parameters in binary form
556 */
557
558#define MBEDTLS_DHM_RFC3526_MODP_2048_P_BIN { \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100559 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
560 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
561 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
562 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
563 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
564 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
565 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
566 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
567 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
568 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
569 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
570 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
571 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
572 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
573 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
574 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
575 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
576 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
577 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
578 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
579 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
580 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
581 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
582 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
583 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
584 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
585 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
586 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
587 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
588 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
589 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAC, 0xAA, 0x68, \
590 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100591
592#define MBEDTLS_DHM_RFC3526_MODP_2048_G_BIN { 0x02 }
593
594#define MBEDTLS_DHM_RFC3526_MODP_3072_P_BIN { \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100595 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
596 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
597 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
598 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
599 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
600 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
601 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
602 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
603 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
604 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
605 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
606 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
607 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
608 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
609 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
610 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
611 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
612 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
613 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
614 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
615 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
616 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
617 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
618 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
619 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
620 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
621 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
622 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
623 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
624 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
625 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAA, 0xC4, 0x2D, \
626 0xAD, 0x33, 0x17, 0x0D, 0x04, 0x50, 0x7A, 0x33, \
627 0xA8, 0x55, 0x21, 0xAB, 0xDF, 0x1C, 0xBA, 0x64, \
628 0xEC, 0xFB, 0x85, 0x04, 0x58, 0xDB, 0xEF, 0x0A, \
629 0x8A, 0xEA, 0x71, 0x57, 0x5D, 0x06, 0x0C, 0x7D, \
630 0xB3, 0x97, 0x0F, 0x85, 0xA6, 0xE1, 0xE4, 0xC7, \
631 0xAB, 0xF5, 0xAE, 0x8C, 0xDB, 0x09, 0x33, 0xD7, \
632 0x1E, 0x8C, 0x94, 0xE0, 0x4A, 0x25, 0x61, 0x9D, \
633 0xCE, 0xE3, 0xD2, 0x26, 0x1A, 0xD2, 0xEE, 0x6B, \
634 0xF1, 0x2F, 0xFA, 0x06, 0xD9, 0x8A, 0x08, 0x64, \
635 0xD8, 0x76, 0x02, 0x73, 0x3E, 0xC8, 0x6A, 0x64, \
636 0x52, 0x1F, 0x2B, 0x18, 0x17, 0x7B, 0x20, 0x0C, \
637 0xBB, 0xE1, 0x17, 0x57, 0x7A, 0x61, 0x5D, 0x6C, \
638 0x77, 0x09, 0x88, 0xC0, 0xBA, 0xD9, 0x46, 0xE2, \
639 0x08, 0xE2, 0x4F, 0xA0, 0x74, 0xE5, 0xAB, 0x31, \
640 0x43, 0xDB, 0x5B, 0xFC, 0xE0, 0xFD, 0x10, 0x8E, \
641 0x4B, 0x82, 0xD1, 0x20, 0xA9, 0x3A, 0xD2, 0xCA, \
642 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100643
644#define MBEDTLS_DHM_RFC3526_MODP_3072_G_BIN { 0x02 }
645
646#define MBEDTLS_DHM_RFC3526_MODP_4096_P_BIN { \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100647 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
648 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
649 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
650 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
651 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
652 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
653 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
654 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
655 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
656 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
657 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
658 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
659 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
660 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
661 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
662 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
663 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
664 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
665 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
666 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
667 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
668 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
669 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
670 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
671 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
672 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
673 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
674 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
675 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
676 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
677 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAA, 0xC4, 0x2D, \
678 0xAD, 0x33, 0x17, 0x0D, 0x04, 0x50, 0x7A, 0x33, \
679 0xA8, 0x55, 0x21, 0xAB, 0xDF, 0x1C, 0xBA, 0x64, \
680 0xEC, 0xFB, 0x85, 0x04, 0x58, 0xDB, 0xEF, 0x0A, \
681 0x8A, 0xEA, 0x71, 0x57, 0x5D, 0x06, 0x0C, 0x7D, \
682 0xB3, 0x97, 0x0F, 0x85, 0xA6, 0xE1, 0xE4, 0xC7, \
683 0xAB, 0xF5, 0xAE, 0x8C, 0xDB, 0x09, 0x33, 0xD7, \
684 0x1E, 0x8C, 0x94, 0xE0, 0x4A, 0x25, 0x61, 0x9D, \
685 0xCE, 0xE3, 0xD2, 0x26, 0x1A, 0xD2, 0xEE, 0x6B, \
686 0xF1, 0x2F, 0xFA, 0x06, 0xD9, 0x8A, 0x08, 0x64, \
687 0xD8, 0x76, 0x02, 0x73, 0x3E, 0xC8, 0x6A, 0x64, \
688 0x52, 0x1F, 0x2B, 0x18, 0x17, 0x7B, 0x20, 0x0C, \
689 0xBB, 0xE1, 0x17, 0x57, 0x7A, 0x61, 0x5D, 0x6C, \
690 0x77, 0x09, 0x88, 0xC0, 0xBA, 0xD9, 0x46, 0xE2, \
691 0x08, 0xE2, 0x4F, 0xA0, 0x74, 0xE5, 0xAB, 0x31, \
692 0x43, 0xDB, 0x5B, 0xFC, 0xE0, 0xFD, 0x10, 0x8E, \
693 0x4B, 0x82, 0xD1, 0x20, 0xA9, 0x21, 0x08, 0x01, \
694 0x1A, 0x72, 0x3C, 0x12, 0xA7, 0x87, 0xE6, 0xD7, \
695 0x88, 0x71, 0x9A, 0x10, 0xBD, 0xBA, 0x5B, 0x26, \
696 0x99, 0xC3, 0x27, 0x18, 0x6A, 0xF4, 0xE2, 0x3C, \
697 0x1A, 0x94, 0x68, 0x34, 0xB6, 0x15, 0x0B, 0xDA, \
698 0x25, 0x83, 0xE9, 0xCA, 0x2A, 0xD4, 0x4C, 0xE8, \
699 0xDB, 0xBB, 0xC2, 0xDB, 0x04, 0xDE, 0x8E, 0xF9, \
700 0x2E, 0x8E, 0xFC, 0x14, 0x1F, 0xBE, 0xCA, 0xA6, \
701 0x28, 0x7C, 0x59, 0x47, 0x4E, 0x6B, 0xC0, 0x5D, \
702 0x99, 0xB2, 0x96, 0x4F, 0xA0, 0x90, 0xC3, 0xA2, \
703 0x23, 0x3B, 0xA1, 0x86, 0x51, 0x5B, 0xE7, 0xED, \
704 0x1F, 0x61, 0x29, 0x70, 0xCE, 0xE2, 0xD7, 0xAF, \
705 0xB8, 0x1B, 0xDD, 0x76, 0x21, 0x70, 0x48, 0x1C, \
706 0xD0, 0x06, 0x91, 0x27, 0xD5, 0xB0, 0x5A, 0xA9, \
707 0x93, 0xB4, 0xEA, 0x98, 0x8D, 0x8F, 0xDD, 0xC1, \
708 0x86, 0xFF, 0xB7, 0xDC, 0x90, 0xA6, 0xC0, 0x8F, \
709 0x4D, 0xF4, 0x35, 0xC9, 0x34, 0x06, 0x31, 0x99, \
710 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100711
712#define MBEDTLS_DHM_RFC3526_MODP_4096_G_BIN { 0x02 }
713
714#define MBEDTLS_DHM_RFC7919_FFDHE2048_P_BIN { \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100715 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
716 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
717 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
718 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
719 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
720 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
721 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
722 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
723 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
724 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
725 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
726 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
727 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
728 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
729 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
730 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
731 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
732 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
733 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
734 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
735 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
736 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
737 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
738 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
739 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
740 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
741 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
742 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
743 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
744 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
745 0x88, 0x6B, 0x42, 0x38, 0x61, 0x28, 0x5C, 0x97, \
746 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100747
748#define MBEDTLS_DHM_RFC7919_FFDHE2048_G_BIN { 0x02 }
749
750#define MBEDTLS_DHM_RFC7919_FFDHE3072_P_BIN { \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100751 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
752 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
753 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
754 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
755 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
756 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
757 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
758 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
759 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
760 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
761 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
762 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
763 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
764 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
765 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
766 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
767 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
768 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
769 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
770 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
771 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
772 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
773 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
774 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
775 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
776 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
777 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
778 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
779 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
780 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
781 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
782 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
783 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
784 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
785 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
786 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
787 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
788 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
789 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
790 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
791 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
792 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
793 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
794 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
795 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
796 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
797 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0xC6, 0x2E, 0x37, \
798 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100799
800#define MBEDTLS_DHM_RFC7919_FFDHE3072_G_BIN { 0x02 }
801
802#define MBEDTLS_DHM_RFC7919_FFDHE4096_P_BIN { \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100803 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
804 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
805 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
806 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
807 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
808 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
809 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
810 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
811 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
812 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
813 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
814 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
815 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
816 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
817 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
818 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
819 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
820 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
821 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
822 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
823 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
824 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
825 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
826 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
827 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
828 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
829 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
830 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
831 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
832 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
833 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
834 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
835 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
836 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
837 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
838 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
839 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
840 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
841 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
842 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
843 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
844 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
845 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
846 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
847 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
848 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
849 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
850 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
851 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
852 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
853 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
854 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
855 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
856 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
857 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
858 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
859 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
860 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
861 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
862 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
863 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
864 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
865 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x65, 0x5F, 0x6A, \
866 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100867
868#define MBEDTLS_DHM_RFC7919_FFDHE4096_G_BIN { 0x02 }
869
870#define MBEDTLS_DHM_RFC7919_FFDHE6144_P_BIN { \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100871 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
872 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
873 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
874 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
875 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
876 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
877 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
878 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
879 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
880 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
881 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
882 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
883 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
884 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
885 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
886 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
887 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
888 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
889 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
890 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
891 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
892 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
893 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
894 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
895 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
896 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
897 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
898 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
899 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
900 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
901 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
902 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
903 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
904 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
905 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
906 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
907 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
908 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
909 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
910 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
911 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
912 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
913 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
914 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
915 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
916 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
917 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
918 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
919 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
920 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
921 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
922 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
923 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
924 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
925 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
926 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
927 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
928 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
929 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
930 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
931 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
932 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
933 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x0D, 0xD9, 0x02, \
934 0x0B, 0xFD, 0x64, 0xB6, 0x45, 0x03, 0x6C, 0x7A, \
935 0x4E, 0x67, 0x7D, 0x2C, 0x38, 0x53, 0x2A, 0x3A, \
936 0x23, 0xBA, 0x44, 0x42, 0xCA, 0xF5, 0x3E, 0xA6, \
937 0x3B, 0xB4, 0x54, 0x32, 0x9B, 0x76, 0x24, 0xC8, \
938 0x91, 0x7B, 0xDD, 0x64, 0xB1, 0xC0, 0xFD, 0x4C, \
939 0xB3, 0x8E, 0x8C, 0x33, 0x4C, 0x70, 0x1C, 0x3A, \
940 0xCD, 0xAD, 0x06, 0x57, 0xFC, 0xCF, 0xEC, 0x71, \
941 0x9B, 0x1F, 0x5C, 0x3E, 0x4E, 0x46, 0x04, 0x1F, \
942 0x38, 0x81, 0x47, 0xFB, 0x4C, 0xFD, 0xB4, 0x77, \
943 0xA5, 0x24, 0x71, 0xF7, 0xA9, 0xA9, 0x69, 0x10, \
944 0xB8, 0x55, 0x32, 0x2E, 0xDB, 0x63, 0x40, 0xD8, \
945 0xA0, 0x0E, 0xF0, 0x92, 0x35, 0x05, 0x11, 0xE3, \
946 0x0A, 0xBE, 0xC1, 0xFF, 0xF9, 0xE3, 0xA2, 0x6E, \
947 0x7F, 0xB2, 0x9F, 0x8C, 0x18, 0x30, 0x23, 0xC3, \
948 0x58, 0x7E, 0x38, 0xDA, 0x00, 0x77, 0xD9, 0xB4, \
949 0x76, 0x3E, 0x4E, 0x4B, 0x94, 0xB2, 0xBB, 0xC1, \
950 0x94, 0xC6, 0x65, 0x1E, 0x77, 0xCA, 0xF9, 0x92, \
951 0xEE, 0xAA, 0xC0, 0x23, 0x2A, 0x28, 0x1B, 0xF6, \
952 0xB3, 0xA7, 0x39, 0xC1, 0x22, 0x61, 0x16, 0x82, \
953 0x0A, 0xE8, 0xDB, 0x58, 0x47, 0xA6, 0x7C, 0xBE, \
954 0xF9, 0xC9, 0x09, 0x1B, 0x46, 0x2D, 0x53, 0x8C, \
955 0xD7, 0x2B, 0x03, 0x74, 0x6A, 0xE7, 0x7F, 0x5E, \
956 0x62, 0x29, 0x2C, 0x31, 0x15, 0x62, 0xA8, 0x46, \
957 0x50, 0x5D, 0xC8, 0x2D, 0xB8, 0x54, 0x33, 0x8A, \
958 0xE4, 0x9F, 0x52, 0x35, 0xC9, 0x5B, 0x91, 0x17, \
959 0x8C, 0xCF, 0x2D, 0xD5, 0xCA, 0xCE, 0xF4, 0x03, \
960 0xEC, 0x9D, 0x18, 0x10, 0xC6, 0x27, 0x2B, 0x04, \
961 0x5B, 0x3B, 0x71, 0xF9, 0xDC, 0x6B, 0x80, 0xD6, \
962 0x3F, 0xDD, 0x4A, 0x8E, 0x9A, 0xDB, 0x1E, 0x69, \
963 0x62, 0xA6, 0x95, 0x26, 0xD4, 0x31, 0x61, 0xC1, \
964 0xA4, 0x1D, 0x57, 0x0D, 0x79, 0x38, 0xDA, 0xD4, \
965 0xA4, 0x0E, 0x32, 0x9C, 0xD0, 0xE4, 0x0E, 0x65, \
966 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100967
968#define MBEDTLS_DHM_RFC7919_FFDHE6144_G_BIN { 0x02 }
969
970#define MBEDTLS_DHM_RFC7919_FFDHE8192_P_BIN { \
Gilles Peskine1b6c09a2023-01-11 14:52:35 +0100971 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
972 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
973 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
974 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
975 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
976 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
977 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
978 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
979 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
980 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
981 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
982 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
983 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
984 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
985 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
986 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
987 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
988 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
989 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
990 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
991 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
992 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
993 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
994 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
995 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
996 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
997 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
998 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
999 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
1000 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
1001 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
1002 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
1003 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
1004 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
1005 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
1006 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
1007 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
1008 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
1009 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
1010 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
1011 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
1012 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
1013 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
1014 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
1015 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
1016 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
1017 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
1018 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
1019 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
1020 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
1021 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
1022 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
1023 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
1024 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
1025 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
1026 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
1027 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
1028 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
1029 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
1030 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
1031 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
1032 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
1033 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x0D, 0xD9, 0x02, \
1034 0x0B, 0xFD, 0x64, 0xB6, 0x45, 0x03, 0x6C, 0x7A, \
1035 0x4E, 0x67, 0x7D, 0x2C, 0x38, 0x53, 0x2A, 0x3A, \
1036 0x23, 0xBA, 0x44, 0x42, 0xCA, 0xF5, 0x3E, 0xA6, \
1037 0x3B, 0xB4, 0x54, 0x32, 0x9B, 0x76, 0x24, 0xC8, \
1038 0x91, 0x7B, 0xDD, 0x64, 0xB1, 0xC0, 0xFD, 0x4C, \
1039 0xB3, 0x8E, 0x8C, 0x33, 0x4C, 0x70, 0x1C, 0x3A, \
1040 0xCD, 0xAD, 0x06, 0x57, 0xFC, 0xCF, 0xEC, 0x71, \
1041 0x9B, 0x1F, 0x5C, 0x3E, 0x4E, 0x46, 0x04, 0x1F, \
1042 0x38, 0x81, 0x47, 0xFB, 0x4C, 0xFD, 0xB4, 0x77, \
1043 0xA5, 0x24, 0x71, 0xF7, 0xA9, 0xA9, 0x69, 0x10, \
1044 0xB8, 0x55, 0x32, 0x2E, 0xDB, 0x63, 0x40, 0xD8, \
1045 0xA0, 0x0E, 0xF0, 0x92, 0x35, 0x05, 0x11, 0xE3, \
1046 0x0A, 0xBE, 0xC1, 0xFF, 0xF9, 0xE3, 0xA2, 0x6E, \
1047 0x7F, 0xB2, 0x9F, 0x8C, 0x18, 0x30, 0x23, 0xC3, \
1048 0x58, 0x7E, 0x38, 0xDA, 0x00, 0x77, 0xD9, 0xB4, \
1049 0x76, 0x3E, 0x4E, 0x4B, 0x94, 0xB2, 0xBB, 0xC1, \
1050 0x94, 0xC6, 0x65, 0x1E, 0x77, 0xCA, 0xF9, 0x92, \
1051 0xEE, 0xAA, 0xC0, 0x23, 0x2A, 0x28, 0x1B, 0xF6, \
1052 0xB3, 0xA7, 0x39, 0xC1, 0x22, 0x61, 0x16, 0x82, \
1053 0x0A, 0xE8, 0xDB, 0x58, 0x47, 0xA6, 0x7C, 0xBE, \
1054 0xF9, 0xC9, 0x09, 0x1B, 0x46, 0x2D, 0x53, 0x8C, \
1055 0xD7, 0x2B, 0x03, 0x74, 0x6A, 0xE7, 0x7F, 0x5E, \
1056 0x62, 0x29, 0x2C, 0x31, 0x15, 0x62, 0xA8, 0x46, \
1057 0x50, 0x5D, 0xC8, 0x2D, 0xB8, 0x54, 0x33, 0x8A, \
1058 0xE4, 0x9F, 0x52, 0x35, 0xC9, 0x5B, 0x91, 0x17, \
1059 0x8C, 0xCF, 0x2D, 0xD5, 0xCA, 0xCE, 0xF4, 0x03, \
1060 0xEC, 0x9D, 0x18, 0x10, 0xC6, 0x27, 0x2B, 0x04, \
1061 0x5B, 0x3B, 0x71, 0xF9, 0xDC, 0x6B, 0x80, 0xD6, \
1062 0x3F, 0xDD, 0x4A, 0x8E, 0x9A, 0xDB, 0x1E, 0x69, \
1063 0x62, 0xA6, 0x95, 0x26, 0xD4, 0x31, 0x61, 0xC1, \
1064 0xA4, 0x1D, 0x57, 0x0D, 0x79, 0x38, 0xDA, 0xD4, \
1065 0xA4, 0x0E, 0x32, 0x9C, 0xCF, 0xF4, 0x6A, 0xAA, \
1066 0x36, 0xAD, 0x00, 0x4C, 0xF6, 0x00, 0xC8, 0x38, \
1067 0x1E, 0x42, 0x5A, 0x31, 0xD9, 0x51, 0xAE, 0x64, \
1068 0xFD, 0xB2, 0x3F, 0xCE, 0xC9, 0x50, 0x9D, 0x43, \
1069 0x68, 0x7F, 0xEB, 0x69, 0xED, 0xD1, 0xCC, 0x5E, \
1070 0x0B, 0x8C, 0xC3, 0xBD, 0xF6, 0x4B, 0x10, 0xEF, \
1071 0x86, 0xB6, 0x31, 0x42, 0xA3, 0xAB, 0x88, 0x29, \
1072 0x55, 0x5B, 0x2F, 0x74, 0x7C, 0x93, 0x26, 0x65, \
1073 0xCB, 0x2C, 0x0F, 0x1C, 0xC0, 0x1B, 0xD7, 0x02, \
1074 0x29, 0x38, 0x88, 0x39, 0xD2, 0xAF, 0x05, 0xE4, \
1075 0x54, 0x50, 0x4A, 0xC7, 0x8B, 0x75, 0x82, 0x82, \
1076 0x28, 0x46, 0xC0, 0xBA, 0x35, 0xC3, 0x5F, 0x5C, \
1077 0x59, 0x16, 0x0C, 0xC0, 0x46, 0xFD, 0x82, 0x51, \
1078 0x54, 0x1F, 0xC6, 0x8C, 0x9C, 0x86, 0xB0, 0x22, \
1079 0xBB, 0x70, 0x99, 0x87, 0x6A, 0x46, 0x0E, 0x74, \
1080 0x51, 0xA8, 0xA9, 0x31, 0x09, 0x70, 0x3F, 0xEE, \
1081 0x1C, 0x21, 0x7E, 0x6C, 0x38, 0x26, 0xE5, 0x2C, \
1082 0x51, 0xAA, 0x69, 0x1E, 0x0E, 0x42, 0x3C, 0xFC, \
1083 0x99, 0xE9, 0xE3, 0x16, 0x50, 0xC1, 0x21, 0x7B, \
1084 0x62, 0x48, 0x16, 0xCD, 0xAD, 0x9A, 0x95, 0xF9, \
1085 0xD5, 0xB8, 0x01, 0x94, 0x88, 0xD9, 0xC0, 0xA0, \
1086 0xA1, 0xFE, 0x30, 0x75, 0xA5, 0x77, 0xE2, 0x31, \
1087 0x83, 0xF8, 0x1D, 0x4A, 0x3F, 0x2F, 0xA4, 0x57, \
1088 0x1E, 0xFC, 0x8C, 0xE0, 0xBA, 0x8A, 0x4F, 0xE8, \
1089 0xB6, 0x85, 0x5D, 0xFE, 0x72, 0xB0, 0xA6, 0x6E, \
1090 0xDE, 0xD2, 0xFB, 0xAB, 0xFB, 0xE5, 0x8A, 0x30, \
1091 0xFA, 0xFA, 0xBE, 0x1C, 0x5D, 0x71, 0xA8, 0x7E, \
1092 0x2F, 0x74, 0x1E, 0xF8, 0xC1, 0xFE, 0x86, 0xFE, \
1093 0xA6, 0xBB, 0xFD, 0xE5, 0x30, 0x67, 0x7F, 0x0D, \
1094 0x97, 0xD1, 0x1D, 0x49, 0xF7, 0xA8, 0x44, 0x3D, \
1095 0x08, 0x22, 0xE5, 0x06, 0xA9, 0xF4, 0x61, 0x4E, \
1096 0x01, 0x1E, 0x2A, 0x94, 0x83, 0x8F, 0xF8, 0x8C, \
1097 0xD6, 0x8C, 0x8B, 0xB7, 0xC5, 0xC6, 0x42, 0x4C, \
1098 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
Hanno Beckere2fcfa82017-10-04 13:12:15 +01001099
1100#define MBEDTLS_DHM_RFC7919_FFDHE8192_G_BIN { 0x02 }
1101
Paul Bakker9af723c2014-05-01 13:03:14 +02001102#endif /* dhm.h */