Compare commits

...

2675 commits

Author SHA1 Message Date
Steffen Jaeckel
a10cad624d Update makefiles
Some checks failed
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-24.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-24.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-22.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-22.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-24.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-24.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-22.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-22.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-24.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-24.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-22.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-22.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-24.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, clang, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-24.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-22.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-22.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-24.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-24.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-22.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-22.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-24.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, , map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-24.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-22.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-22.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-24.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=Off], ubuntu-24.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-22.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-22.04-arm) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-24.04) (push) Has been cancelled
CI / CMake (-DCMAKE_BUILD_TYPE=Release, gcc, -DLTC_CFLAGS="-DLTC_NO_ASM", map[CMAKEOPTIONS:-DBUILD_SHARED_LIBS=On], ubuntu-24.04-arm) (push) Has been cancelled
2026-08-07 08:33:48 +02:00
Karel Miko
0a0969b3d2 private - ltc_algname_match (relaxed alg name matching) 2026-08-04 12:40:06 +02:00
Karel Miko
a3ecbbc800 DER - fail cleanly when no math provider is registered 2026-08-04 12:40:06 +02:00
Steffen Jaeckel
223ecd23b8
Merge pull request #730 from libtom/pr/blake3
BLAKE3
2026-08-04 11:29:14 +02:00
Karel Miko
075342e984 Update makefiles 2026-08-04 11:26:06 +02:00
Karel Miko
5b05baaf36 BLAKE3 2026-08-04 11:26:06 +02:00
Karel Miko
4d5140219b typo LTC_BLAKE2S / LTC_BLAKE2B 2026-08-03 11:39:44 +02:00
Steffen Jaeckel
dc77d926dc
Merge pull request #790 from libtom/fix-latex-tables
Fix latex tables
2026-08-03 11:38:00 +02:00
Steffen Jaeckel
82b193d7c6 Add ARIA to latex-tabels tool & PEM docs.
Fixes: 05ad38ab66 ("With ARIA added, we can now decrypt ARIA encrypted PEM files.")
Fixes: libtom/libtomcrypt#760
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-08-03 11:33:39 +02:00
Steffen Jaeckel
885578932a Ensure that latex-tables tool succeeds
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-08-03 11:12:19 +02:00
Steffen Jaeckel
014cc99c75
Merge pull request #789 from libtom/pr/zero-stat
verify functions always set stat=0 before any other return
2026-08-03 10:53:27 +02:00
Karel Miko
47479c474f verify functions always set stat=0 before any other return 2026-08-03 00:16:20 +02:00
karel-m
02788482af
Merge pull request #788 from libtom/pr/pbes-fix-stack-over-read
PBES - fix stack over-read with malformed PBES2 parameters
2026-08-01 18:37:52 +02:00
karel-m
59767256e6
Merge pull request #787 from libtom/pr/sha512-x86-alt
SHA-512 accelerated by x86 (alternative)
2026-08-01 18:37:40 +02:00
Karel Miko
b50ffea546 PBES - fix stack over-read with malformed PBES2 parameters 2026-08-01 15:44:26 +02:00
Karel Miko
22bc6b68e0 MSVC & SHA512 extension support 2026-08-01 14:13:43 +02:00
Karel Miko
51511d1cd0 Update makefiles 2026-08-01 11:17:41 +02:00
Karel Miko
9e2984aa7e SHA-512 accelerated by x86 (alternative) 2026-08-01 11:17:36 +02:00
karel-m
4d9e2a1a57
Merge pull request #758 from libtom/more-fixes-and-improvements
More fixes and improvements
2026-08-01 10:20:27 +02:00
Karel Miko
bfc516d246 fix typo sha256_x86_compress/sha256_compress (LTC_CLEAN_STACK only) 2026-08-01 09:26:29 +02:00
Steffen Jaeckel
97f5d72457 Ensure the table sizes are OK.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 23:57:51 +02:00
Steffen Jaeckel
5a2bc6b131 Fix importing certificate with Ed448 key.
While running the tests in verbose mode I saw that
`tests/pem/openssl_ed448_x509.pem` is skipped instead of processed.

Fixes: 076a11037a ("Ed448 + X448")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 23:57:51 +02:00
Steffen Jaeckel
2320e44205 Allow processing of empty files.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 23:57:51 +02:00
Steffen Jaeckel
b0894f683f Add pem tests with empty files.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 23:57:51 +02:00
Steffen Jaeckel
7978822b69 Add help to test binary.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 23:57:51 +02:00
Steffen Jaeckel
429d07e388 Some minor SHA1/256 improvements&fixes.
* Use a shared init function.
* Fix some functions used in descriptors and implementation.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 23:57:51 +02:00
Steffen Jaeckel
fb857d83ed Auto-generate table of hashes.
Fixes: 6c885c7732 ("SM3 hash function")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 23:57:51 +02:00
Steffen Jaeckel
54f5803ad8 Rename keccac hash descriptors.
They're the only ones which don't follow the same pattern.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 23:57:51 +02:00
Steffen Jaeckel
459bd79006
Merge pull request #786 from libtom/pr/appveyor-clang-cl
appveyor + clang-cl
2026-07-31 23:50:20 +02:00
Karel Miko
a58d4b5278 clang-cl fix related to intrin.h 2026-07-31 23:48:18 +02:00
Karel Miko
3acb5aed64 appveyor + clang-cl 2026-07-31 23:48:18 +02:00
Steffen Jaeckel
2d16cc7f76
Merge pull request #756 from libtom/fast-type
Fix LTC_FAST_TYPE
2026-07-31 23:48:02 +02:00
Steffen Jaeckel
4a964ea017 Align macro based and inline LTC_FAST functions. 2026-07-31 20:27:50 +02:00
Karel Miko
6bc4dd9b7b fix UBSanitizer issue: load of misaligned address for type LTC_FAST_TYPE (replacing LTC_FAST_TYPE_PTR_CAST approach) 2026-07-31 20:16:48 +02:00
Steffen Jaeckel
88f95afc5c Rename according to PR #756
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-07-31 20:16:48 +02:00
karel-m
a467ea586b
Merge pull request #785 from libtom/pr/hash-memcpyable
Another attempt to make sha1/sha256 states memcpyable
2026-07-31 11:10:10 +02:00
Steffen Jaeckel
927191b193
Merge pull request #763 from MarekKnapek/ubsan
ubsan
2026-07-31 10:54:12 +02:00
Marek Knápek
c727c4032a Get rid of LTC_FAST_TYPE_PTR_CAST entirely.
As it might be dangerous to use it.

This introduces `LTC_FAST_TYPE_{ASSIGN,MASK,XOR{2,3}}()` in order to
replace the potential unaligned loads.

This fixes the following UBSAN errors:

src/modes/ctr/ctr_encrypt.c:56:66: runtime error: load of misaligned address 0x7ffea07ee82f for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/modes/ctr/ctr_encrypt.c:56:64: runtime error: store to misaligned address 0x7ffea07ee82f for type 'LTC_FAST_TYPE', which requires 8 byte alignment
tests/store_test.c:66:91: runtime error: load of misaligned address 0x7ffdd32f0d9f for type 'LTC_FAST_TYPE', which requires 8 byte alignment
tests/store_test.c:66:52: runtime error: load of misaligned address 0x7ffdd32f0d71 for type 'LTC_FAST_TYPE', which requires 8 byte alignment
tests/store_test.c:66:50: runtime error: store to misaligned address 0x7ffdd32f0dc1 for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/mac/pmac/pmac_process.c:40:50: runtime error: load of misaligned address 0x57c89c4329ec for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/mac/xcbc/xcbc_process.c:35:60: runtime error: load of misaligned address 0x57c89c432ccc for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/mac/f9/f9_process.c:39:58: runtime error: load of misaligned address 0x5c2b1a1d2c14 for type 'LTC_FAST_TYPE', which requires 8 byte alignment
src/encauth/gcm/gcm_process.c:82:58: runtime error: load of misaligned address 0x596b3e6aa354 for type 'LTC_FAST_TYPE', which requires 8 byte alignment
2026-07-31 10:45:09 +02:00
Marek Knápek
471f143078 Fix UBSAN errors
src/encauth/siv/siv.c:164:19: runtime error: null pointer passed as argument 2, which is declared to never be null
/usr/include/string.h:44:28: note: nonnull attribute specified here
src/misc/compare_testvector.c:63:25: runtime error: null pointer passed as argument 2, which is declared to never be null
/usr/include/string.h:65:33: note: nonnull attribute specified here
2026-07-31 10:44:16 +02:00
Karel Miko
a1a631efe4 make sha1/sha states clonable via memcpy 2026-07-30 20:17:44 +02:00
karel-m
c5607aff6b
Merge pull request #784 from libtom/pr/msvc-fallthrough
Fix LTC_FALLTHROUGH related error reported by MSVC compiler
2026-07-30 16:48:17 +02:00
Karel Miko
23fca6ed39 Fix LTC_FALLTHROUGH related error reported by MSVC compiler 2026-07-30 16:01:06 +02:00
Steffen Jaeckel
79f2b5762d
Merge pull request #777 from libtom/pr/siv-zero-ad
SIV properly handle zero AD components
2026-07-30 15:42:03 +02:00
Karel Miko
511252c49e update SIV doc - fix adnum; explain no associated data vs. empty associated data 2026-07-30 15:39:27 +02:00
Karel Miko
cff7442824 SIV properly handle zero AD components 2026-07-30 15:39:27 +02:00
Steffen Jaeckel
f5fe918ab8
Merge pull request #755 from libtom/fix-warnings
Fix warnings
2026-07-30 15:37:58 +02:00
Karel Miko
074a354151 fix build failures with -std=c99 2026-07-30 15:22:33 +02:00
Karel Miko
0b6f0e1232 fix clang warnings -Wimplicit-fallthrough (while keeping /* FALLTHROUGH */ for some code review tools) 2026-07-30 15:22:33 +02:00
Karel Miko
26605163a4 fix clang warnings -Wmissing-variable-declarations 2026-07-30 15:22:33 +02:00
Karel Miko
317994fb1b fix clang warnings -Wstrict-prototypes -Wmissing-prototypes in tests+demos 2026-07-30 15:22:33 +02:00
Karel Miko
661fcd6486 fix UBSanitizer issue: applying non-zero offset to null pointer 2026-07-30 15:22:33 +02:00
Karel Miko
5c8ac18bd1 fix UBSanitizer issue: memcpy/memcmp require non-null pointers even when the length is zero 2026-07-30 15:22:33 +02:00
Karel Miko
76a9ece653 fix UBSanitizer issue: left-shifting negative integer is undefined behavior 2026-07-30 15:22:33 +02:00
Karel Miko
509da35eee fix clang warning: 'err' may be used uninitialized 2026-07-30 15:22:33 +02:00
karel-m
612f211bbc
Merge pull request #783 from libtom/pr/der-misc-issues
various DER related fixes/improvements
2026-07-29 23:50:05 +02:00
Karel Miko
209df8ae1a hardening pkcs8_get_children against uninitialized output pointers 2026-07-28 16:33:09 +02:00
Karel Miko
5c7757d0a5 various DER related fixes/improvements 2026-07-28 00:10:29 +02:00
Steffen Jaeckel
a8ed78c2ca
Merge pull request #780 from libtom/pr/argon2-parallelism-overflow
Argon2 enforce parallelism max 2^24-1
2026-07-21 11:07:46 +02:00
Karel Miko
fcadf67bbb Argon2 enforce parallelism max 2^24-1 2026-07-21 11:02:31 +02:00
Steffen Jaeckel
b7b04ffd37
Merge pull request #778 from libtom/pr/eax-taglen
EAX properly handle taglen boundaries
2026-07-21 10:59:19 +02:00
Karel Miko
39f5e1fae8 EAX properly handle taglen boundaries 2026-07-21 10:56:44 +02:00
Steffen Jaeckel
84aec00adc
Merge pull request #776 from libtom/pr/ccm-nonce
Fix issue #775 - CCM nonce is 7..13 bytes
2026-07-21 10:56:27 +02:00
Karel Miko
e00b22d939 CCM nonce is 7..13 bytes 2026-07-21 10:53:25 +02:00
Steffen Jaeckel
1027dcfaf6
Merge pull request #765 from libtom/pr/fix-issue764
Fix issue #764 - small-subgroup attack
2026-07-21 10:53:14 +02:00
Karel Miko
bc95a1fd2d hardening ecc_shared_secret against small-subgroup attacks 2026-05-25 16:18:14 +02:00
Karel Miko
ec7c05f94e fix issue #764 as suggested by @yaotushaozhu 2026-05-25 14:11:27 +02:00
Karel Miko
afb09869f7 failing test for issue #764 - small-subgroup attack regression test 2026-05-25 13:56:48 +02:00
Steffen Jaeckel
a68fa19bc2
Merge pull request #732 from libtom/pr/sm3-hash
SM3 hash function
2026-05-19 13:31:48 +02:00
Steffen Jaeckel
c17e5ed051 Update makefiles 2026-05-19 13:29:49 +02:00
Karel Miko
6c885c7732 SM3 hash function 2026-05-19 13:29:36 +02:00
Steffen Jaeckel
291d847c10
Merge pull request #752 from libtom/pr/AES-GCM-SIV
RFC 8452 - AES-GCM-SIV
2026-05-19 13:14:53 +02:00
Karel Miko
96d2d09d7a Update makefiles 2026-05-19 13:12:32 +02:00
Karel Miko
37a2e345a4 AES-GCM-SIV 2026-05-19 13:12:32 +02:00
Steffen Jaeckel
8512e3e891
Merge pull request #759 from libtom/pr/KMAC128-256
KMAC as defined in NIST SP 800-185
2026-05-19 13:05:06 +02:00
Karel Miko
7bcdb63950 Update makefiles 2026-05-19 13:03:25 +02:00
Karel Miko
9b268d6258 KMAC - NIST SP 800-185 2026-05-19 13:03:25 +02:00
Steffen Jaeckel
6e4dcfcc11
Merge pull request #760 from libtom/pr/ARIA
ARIA block cipher (RFC 5794)
2026-05-19 10:22:37 +02:00
Steffen Jaeckel
05ad38ab66 With ARIA added, we can now decrypt ARIA encrypted PEM files.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-17 13:49:10 +02:00
Karel Miko
2f6b257def Update makefiles 2026-05-16 11:38:42 +02:00
Karel Miko
4d513a02fc ARIA block cipher (RFC 5794) 2026-05-16 11:38:38 +02:00
Steffen Jaeckel
8b5af49b94
Merge pull request #754 from libtom/pr/shake128-256
RFC 8702: RSA-PSS-SHAKE128/256 and ECDSA-SHAKE128/256
2026-05-06 09:48:25 +02:00
Karel Miko
1e4d471a9f RFC 8702: RSA-PSS-SHAKE128/256 and ECDSA-SHAKE128/256 2026-05-06 09:23:52 +02:00
Steffen Jaeckel
efd7f24f1a
Merge pull request #753 from libtom/pr/wycheproof-pk-stricter-checks
Stricter checks (RSA OAEP, X25519, X448) - based on wycheproof results
2026-05-05 07:42:48 +02:00
Karel Miko
2c375b3a3c RSA OAEP - reject ciphertext values 0 and 1 2026-05-05 07:42:20 +02:00
Karel Miko
71f45fedbc x25519/x448 - reject all-zero shared secrets 2026-05-05 07:40:06 +02:00
Steffen Jaeckel
efad039f19
Merge pull request #751 from libtom/more-fixes-and-improvements
More fixes and improvements
2026-05-04 15:32:59 +02:00
Steffen Jaeckel
a724483a0b Add gcm_hw_pmul_is_supported()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:47:11 +02:00
Steffen Jaeckel
c05b3088b4 Use __has_attribute() for target attribute.
... and bring aarch64/PMULL in similar shape as x86/PCLMUL.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:47:05 +02:00
Karel Miko
42489a16cb fix basename(..) in demos 2026-05-04 10:44:57 +02:00
Steffen Jaeckel
9e446e665f Better position to print this info.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
fdf0b60170 Replace some CI builds with a single build_options.sh run.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
078fd15f69 Apply V option to make clean
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
f940880a67 Create ENCRYPT_ONLY descriptors in amalgamated build.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
3520a0fcf5 Fix maybe-unitialized warnings.
Fixes: e20fff1f3d ("Add more TurboSHAKE unit tests.")
Fixes: 6832f3c106 ("Add KangarooTwelve XOF functions.")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
011d427196 Remove dirty hacks in SHA3.
Fixes: 6832f3c106 ("Add KangarooTwelve XOF functions.")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
001fa107d1 Some minor fixes detected in AMALGAMATED builds.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Marek Knápek
580be51806 Use LTC_UNUSED_PARAM().
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
07cab77569 Test aesgcm demo.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
7fb003f1a2 Slightly improve timing demo.
* Use faster sober128 if available.
* Use stable PRNG state for ECC operations, so we get comparable results.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-04 10:08:07 +02:00
Steffen Jaeckel
ccbbb797f0 Fix indentation.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-03 11:11:39 +02:00
Steffen Jaeckel
229f540c48 Don't print warning in case LTC_NO_TEST is defined.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-03 11:11:39 +02:00
Steffen Jaeckel
0834f876cd Split up ec25519/448 tests.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-03 11:11:39 +02:00
Steffen Jaeckel
811b1a6c14 Introduce LTC_NOP_TEST()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-05-03 11:11:39 +02:00
Steffen Jaeckel
45f95768da
Merge pull request #747 from libtom/pr/wycheproof-padding_depad
padding_depad - reject zero-length input (except for LTC_PAD_ZERO)
2026-04-30 11:42:08 +02:00
Steffen Jaeckel
180ffcdd65
Merge pull request #748 from libtom/pr/wycheproof-ecdh
ECC failing wycheproof tests
2026-04-30 11:41:18 +02:00
Karel Miko
e312fffaf2 fix ECC failing wycheproof tests 2026-04-30 11:41:04 +02:00
Karel Miko
7c0e52114e ecc - failing wycheproof tests 2026-04-30 11:41:04 +02:00
Steffen Jaeckel
2317c13d62
Merge pull request #749 from libtom/pr/wycheproof-ed448
Ed448/X448 failing wycheproof tests
2026-04-30 08:46:24 +02:00
Karel Miko
176c4827fc fix Ed448/X448 failing wycheproof tests 2026-04-30 08:46:13 +02:00
Karel Miko
8dd6ecfd20 ed448/x448 - failing wycheproof tests 2026-04-30 08:46:13 +02:00
Steffen Jaeckel
284129706a
Merge pull request #746 from libtom/pr/wycheproof-frp256v1
add FRP256v1 - French governmental ECC curve
2026-04-30 08:45:07 +02:00
Karel Miko
8a1b70a040 add FRP256v1 (French governmental ECC curve referenced in wycheproof test suite) 2026-04-30 08:44:46 +02:00
Steffen Jaeckel
888307876a
Merge pull request #750 from libtom/pr/wycheproof-decode_bit_string
wycheproof - fix failing ASN.1 BIT STRING related test
2026-04-30 08:43:45 +02:00
Karel Miko
577f2bc155 fix failing wycheproof test (ecdh_brainpoolP224r1_test.json tcId=787) ASN.1 BIT STRING related 2026-04-29 20:07:43 +02:00
Karel Miko
8ea53b4eaf padding_depad - reject zero-length input (except for LTC_PAD_ZERO) 2026-04-29 14:33:20 +02:00
Steffen Jaeckel
6e699f964d
Merge pull request #410 from libtom/pr/fix-LTC_MECC_FP
fix LTC_MECC_FP
2026-04-29 10:56:18 +02:00
Steffen Jaeckel
9e1c6174fc Add CI jobs with ECC FP enabled.
We replace the PTHREAD job with `ECC_FP+PTHREAD` since PTHREAD is only
relevant for ECC_FP and the PRNG's.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-29 10:53:40 +02:00
Steffen Jaeckel
576258b5fc Fix ECC FP API.
We have to return an error code when working with the mutex API.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-29 10:53:40 +02:00
Steffen Jaeckel
1f28017b10 Fix typo
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-29 10:53:40 +02:00
Steffen Jaeckel
22586373c3 Fix potential unsigned underflow.
Running the `timing` demo with `LTC_MECC_FP` enabled gave a segfault,
which Valgrind narrowed down to

```
==135594== Invalid read of size 1
==135594==    at 0x49298C: ss_accel_fp_mul2add (ltc_ecc_fp_mulmod.c:1007)
==135594==    by 0x4931C1: ltc_ecc_fp_mul2add (ltc_ecc_fp_mulmod.c:1192)
==135594==    by 0x41C1B2: ecc_verify_hash_internal (ecc_verify_hash_internal.c:114)
==135594==    by 0x41C830: ecc_verify_hash_rfc7518_internal (ecc_verify_hash_rfc7518.c:35)
==135594==    by 0x40340F: time_ecc (timing.c:1031)
==135594==    by 0x402894: main (timing.c:1621)
==135594==  Address 0x20feffeb2f is not stack'd, malloc'd or (recently) free'd
```

The origin being `ltc_mp_unsigned_bin_size(tkb)` returning 0, so y is -1,
but as an unsigned type that's no fun.

Fixed by making y a signed type.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-29 10:53:40 +02:00
Karel Miko
6affa8b99f fix LTC_MECC_FP 2026-04-29 10:53:40 +02:00
Steffen Jaeckel
0a46eb2e5c
Merge pull request #740 from MarekKnapek/738
Fix for issue #738.
2026-04-27 23:26:19 +02:00
Marek Knápek
44d111e755 Fix for issue #738.
Closes: libtom/libtomcrypt#738
2026-04-27 23:25:14 +02:00
Steffen Jaeckel
d062d0e31f
Merge pull request #446 from libtom/pr/wycheproof-fail-changed-seq-tag
Wycheproof failing ECC tests
2026-04-27 14:23:07 +02:00
Karel Miko
66a2e73eb8 fix for issue #116 2026-04-27 14:19:59 +02:00
Karel Miko
8e9b1983af fix ecc_projective_add_point + ecc_projective_dbl_point 2026-04-27 14:19:59 +02:00
Steffen Jaeckel
689b57755b Fix cases where the points are equal.
In the case where `(P.x,P.y) == (Q.x,Q.y)` in affine coordinates, which
shows itself as either of the two being 0 after the add, we have
to double instead of add.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-27 14:19:59 +02:00
Steffen Jaeckel
b67f4397f4 Ensure that stat is initialized.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-27 14:19:59 +02:00
Steffen Jaeckel
9fa2f16ddc Fix length-related wycheproof testcases
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-27 14:19:59 +02:00
Karel Miko
1d55aca785 failing wycheproof tests 2026-04-27 14:19:59 +02:00
Steffen Jaeckel
7d0d0799ce
Merge pull request #744 from libtom/fix-743
Fix 743
2026-04-27 14:16:54 +02:00
tynus3
1bb1e6172c Fix off-by-one heap BOF.
Fixes: 1b3a757345 ("add ASN.1-identifier functions")
Closes: libtom/libtomcrypt#743
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-27 12:56:58 +02:00
Steffen Jaeckel
876460e7b6 Add testcases.
Link: libtom/libtomcrypt#743
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-27 12:56:58 +02:00
Steffen Jaeckel
143679efce
Merge pull request #741 from libtom/pr/rsa-import-failure
fix RSA import
2026-04-24 18:34:59 +02:00
Steffen Jaeckel
55bf39c50e Also add the failing key to the test corpus.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-24 18:32:50 +02:00
Karel Miko
9f56c5803e fix RSA import 2026-04-24 16:49:08 +02:00
Steffen Jaeckel
0971e458ba
Merge pull request #722 from libtom/pr/ed448-x448-attempt3
Ed448 + X448
2026-04-24 13:14:56 +02:00
Karel Miko
e0599e2b3a Update makefiles 2026-04-24 11:50:39 +02:00
Karel Miko
076a11037a Ed448 + X448 2026-04-24 11:49:23 +02:00
Steffen Jaeckel
c80285ba04
Merge pull request #725 from libtom/remove-ocb-v1
Remove OCB v1
2026-04-24 10:49:18 +02:00
Steffen Jaeckel
b6d4e6384e Update makefiles 2026-04-24 10:45:27 +02:00
Steffen Jaeckel
800e5ce319 Remove OCB v1.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-24 10:45:24 +02:00
Steffen Jaeckel
f5438b298d Deprecate OCB v1.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-24 09:45:26 +02:00
Steffen Jaeckel
8c82c8786b Update OCB docs regarding patents.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-24 09:45:26 +02:00
Steffen Jaeckel
2be5cceb84
Merge pull request #729 from libtom/pr/xchacha20-xchacha20poly130
XChaCha20 / XChaCha20-Poly1305
2026-04-24 09:44:28 +02:00
Karel Miko
b0a1804d50 Update makefiles 2026-04-24 09:41:08 +02:00
Karel Miko
0e4c5aff7e XChaCha20 / XChaCha20-Poly1305 2026-04-24 09:41:08 +02:00
Steffen Jaeckel
c53dfcc6df
Merge pull request #739 from libtom/pr/wycheproof-ed25519
Wycheproof Ed25519 test vectors + fix
2026-04-24 09:36:21 +02:00
Karel Miko
0f37c60fd7 Wycheproof Ed25519 test vectors + fix 2026-04-24 09:36:09 +02:00
Steffen Jaeckel
14d9bd0f82
Merge pull request #736 from libtom/pr/gcm-freebsd
GCM + FreeBSD + HWCAP_PMULL
2026-04-24 09:35:00 +02:00
Karel Miko
e63dca1277 GCM + FreeBSD + HWCAP_PMULL 2026-04-24 09:34:50 +02:00
Steffen Jaeckel
cfb3ba8339
Merge pull request #726 from libtom/cleanup-and-fixes
Cleanup and fixes
2026-04-23 12:27:16 +02:00
Steffen Jaeckel
760d09031e Add Project Wycheproof testvectors for SIV.
Gemini proposed this to convert
```
import json
import requests

def to_c_hex(hex_str):
    if not hex_str: return "NULL"
    bytes_list = [f"0x{hex_str[i:i+2]}" for i in range(0, len(hex_str), 2)]
    return "{" + ",".join(bytes_list) + "}"

url = "https://raw.githubusercontent.com/C2SP/wycheproof/main/testvectors_v1/aes_siv_cmac_test.json"
data = requests.get(url).json()

print("#include <stdint.h>\n#include <stddef.h>\n")
print("typedef struct { int tcId; const char* comment; uint8_t key[64]; size_t keyLen; const uint8_t* aad; size_t aadLen; const uint8_t* msg; size_t msgLen; const uint8_t* ct; size_t ctLen; const char* result; } aes_siv_test_case;\n")

for group in data['testGroups']:
    for test in group['tests']:
        tid = test['tcId']
        if test['aad']: print(f"static const uint8_t aad_{tid}[] = {to_c_hex(test['aad'])};")
        if test['msg']: print(f"static const uint8_t msg_{tid}[] = {to_c_hex(test['msg'])};")
        if test['ct']:  print(f"static const uint8_t ct_{tid}[]  = {to_c_hex(test['ct'])};")

print("\nstatic const aes_siv_test_case aes_siv_tests[] = {")
for group in data['testGroups']:
    for test in group['tests']:
        tid = test['tcId']
        key_hex = to_c_hex(test['key'])
        aad_ptr = f"aad_{tid}" if test['aad'] else "NULL"
        msg_ptr = f"msg_{tid}" if test['msg'] else "NULL"
        ct_ptr  = f"ct_{tid}"  if test['ct']  else "NULL"

        print(f"    {{ {tid}, \"{test['comment']}\", {key_hex}, {len(test['key'])//2}, {aad_ptr}, {len(test['aad'])//2}, {msg_ptr}, {len(test['msg'])//2}, {ct_ptr}, {len(test['ct'])//2}, \"{test['result']}\" }},")
print("};")
```

I manually modified the result type to be an enum.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 10:30:32 +02:00
Steffen Jaeckel
098e0e3030 Explicitly use padding type.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 10:30:32 +02:00
Steffen Jaeckel
72642a7e8c Make depadding better against timing attacks.
Fixes: 82482119df ("add padding module")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 10:30:27 +02:00
Steffen Jaeckel
f700888231 Accept zero-length data in CTR mode.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 10:30:27 +02:00
Steffen Jaeckel
b8c5ea8f18 Accept zero-length data in OMAC.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 10:30:27 +02:00
Steffen Jaeckel
5f4287aced Fix SIV.
This also changes the API, since we need to know how many ADs are passed
and can't rely on a NULL element, as an empty element also changes the
tag.

Fixes: faa8cd71e5 ("add SIV")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 10:29:48 +02:00
Steffen Jaeckel
5c7e0e9fb1 Allow pt as NULL if there's nothing to encrypt.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
57b92e7351 Add a sentence about the origins of the CHC hash.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
d7c650d398 Update PR template.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
18cfd0f87a Suppress warnings emitted by Clang.
Fixes: 874e095a19 ("SHA-256 & SHA-224 x86")
Fixes: 7ac05df902 ("Add x86-optimized SHA1.")
Fixes: 46e0137e55 ("Optimize gcm_gf_mult using PCLMULQDQ and PMULL")
Fixes: 31c7f891aa ("add support for AES-NI instructions")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
fe7bfb053a Branch once, not on each iteration.
Even though the branch predictor should get this, it's unnecessary.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
6be6de1ffa Replace int* recid hack in ECC.
Link: libtom/libtomcrypt#724
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
233f226108 Fix some ifdefs, include guards and a function call.
Fixes: 7ac05df902 ("Add x86-optimized SHA1.")
Fixes: 874e095a19 ("SHA-256 & SHA-224 x86")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
e5df4f7ce8 Fix build with -DLTC_MINIMAL.
Fixes: 661109f660 ("re-factor modes to use internal ECB implementation")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
e2544d4071 Further improve timing demo.
Filtering is now possible for all classes besides public key crypto.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
661dad10c7 Make HW-accel checkers always available.
Since the SHA-NI checker does the same for all three versions, we only have
to make one version public. This also now enables explicit testing of the
SHA-NI blocks.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
ec3804c452 Use s_x86_cpuid() in s_{aesni,pclmul}_is_supported().
Hopefully at one point we can get rid of its duplication. Why again don't
we use inline functions as they should be used?

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
e3bf539e5d Clean-up some defines.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
4bdd0480f7 Introduce LTC_NO_ACCEL.
Related-to: libtom/libtomcrypt#727
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-23 09:13:02 +02:00
Steffen Jaeckel
a8236250a9
Merge pull request #737 from libtom/pr/sha3-missing-ltc_test
couple of missing: if defined(LTC_TEST)
2026-04-23 08:55:41 +02:00
Karel Miko
854749e2f4 couple of missing: if defined(LTC_TEST) 2026-04-23 08:16:12 +02:00
Steffen Jaeckel
ff52a70038
Merge pull request #734 from libtom/pr/fix-unused-parameter
fix unused-parameter warning
2026-04-22 14:41:44 +02:00
Karel Miko
a29e328b07 fix unused-parameter warning 2026-04-22 14:41:34 +02:00
Steffen Jaeckel
463431edc2
Merge pull request #735 from libtom/pr/hmac-zero-key
patch HMAC to accept zero-length keys and remove the scrypt workaround
2026-04-22 14:40:45 +02:00
Karel Miko
557e9e2678 patch HMAC to accept zero-length keys and remove the scrypt workaround 2026-04-21 23:35:10 +02:00
Steffen Jaeckel
2e441a17df
Merge pull request #717 from MarekKnapek/SHA-1x86
SHA-1, SHA-224 & SHA-256 with x86 instructions
2026-04-15 17:27:26 +02:00
Steffen Jaeckel
070d613d26 Update makefiles 2026-04-15 15:22:32 +02:00
Marek Knápek
874e095a19 SHA-256 & SHA-224 x86 2026-04-15 15:22:25 +02:00
Marek Knápek
7ac05df902 Add x86-optimized SHA1. 2026-04-15 15:20:28 +02:00
Steffen Jaeckel
68aae28a9d
Merge pull request #706 from libtom/new-rsa-api
New RSA API
2026-04-15 12:27:08 +02:00
Karel Miko
fa26d13016 RSA: update documentation (crypt.tex) to reflect the latest changes 2026-04-15 11:12:30 +02:00
Karel Miko
7ab625c090 RSA: fix demos/timing.c 2026-04-15 11:12:30 +02:00
Karel Miko
21d100d862 RSA: make rsa_decode_parameters work with rsa_key instead of ltc_rsa_parameters 2026-04-15 11:12:30 +02:00
Karel Miko
80de9b088b RSA: cosmetics - consistency tomcrypt_pk.h vs implementation files 2026-04-15 11:12:30 +02:00
Karel Miko
32ab39fb42 RSA: comment typo 2026-04-15 11:12:30 +02:00
Karel Miko
e4d3bd2fa5 RSA: replace hash_alg + mgf1_hash_alg with hash_idx + mgf1_hash_idx 2026-04-15 11:12:30 +02:00
Karel Miko
7fa7c2ad51 RSA: remove unnecessary #define LTC_DEPRECATED(x) 2026-04-15 11:12:30 +02:00
Karel Miko
557cb62b06 RSA: use consistently ltc_rsa_op_checked (+ cosmetic renaming op_check >> op_checked) 2026-04-15 11:12:30 +02:00
Karel Miko
c1b3281433 RSA: no more dual semantics of pss_oaep (removed from ltc_rsa_parameters; now lives on rsa_key where it belongs) 2026-04-15 11:12:30 +02:00
Karel Miko
d2829aa10f RSA: PSS + all encryption needs a PRNG 2026-04-15 11:12:30 +02:00
Steffen Jaeckel
66e677aedd Introduce new RSA API.
This also:
a) deprecates the old RSA and PKCS#1 API.
b) reverts the changes done to them in order to make the now deprecated API
   compatible again with the last release.

The fixes commit mentioned below is the testcase for the Bleichenbacher
attack, which works now again as expected.

Fixes: 9d03c38e ("add flags to `der_decode_sequence()`")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-15 11:12:30 +02:00
Steffen Jaeckel
208ee2be4e Refactor SubjectPublicKeyInfo import
Slightly minimize both space and time when importing a
SubjectPublicKeyInfo. Time for ECC keys stays the same.

Those tests were done with X.509 support already available, but later these
commits were split up to be independent of the X.509 feature.

Running the entire set of pem files through `x509_verify` via [0]
resp. the timing app via [1] resulted in the following data:

Before this patch:

[0]
```
==1031519== HEAP SUMMARY:
==1031519==     in use at exit: 0 bytes in 0 blocks
==1031519==   total heap usage: 424,057 allocs, 424,057 frees, 73,527,730 bytes allocated
```

[1]
```
x509 cert-rsa-pss.pem    :     50021 cycles
x509 LTC_CA.pem          :     10335 cycles
x509 LTC_S0.pem          :     47284 cycles
x509 LTC_SS0.pem         :     36687 cycles
x509 secp384r1.pem       :   1985416 cycles
x509 secp521r1.pem       :   3287773 cycles
x509 LTC_SSS0.pem        :     25086 cycles
x509 secp224r1.pem       :    775807 cycles
```

After this patch:

[0]
```
==1043548== HEAP SUMMARY:
==1043548==     in use at exit: 0 bytes in 0 blocks
==1043548==   total heap usage: 337,244 allocs, 337,244 frees, 65,047,463 bytes allocated
```

[1]
```
x509 cert-rsa-pss.pem    :     32568 cycles
x509 LTC_CA.pem          :      5478 cycles
x509 LTC_S0.pem          :     36093 cycles
x509 LTC_SS0.pem         :     23351 cycles
x509 secp384r1.pem       :   1984030 cycles
x509 secp521r1.pem       :   3303396 cycles
x509 LTC_SSS0.pem        :     13220 cycles
x509 secp224r1.pem       :    781534 cycles
```

[0] find tests/x509 -name '*.pem' -exec valgrind --leak-check=full --show-leak-kinds=all './x509_verify' {} \+
[1] ./timing x509

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-15 11:12:30 +02:00
Steffen Jaeckel
d1ab64ec25 Add support for RSA-PSS keys
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-15 11:12:30 +02:00
Steffen Jaeckel
56f0e118dd Add support for separate MGF1 hashes
Update PKCS#1-PSS and RSA APIs that allow passing a separate hash index for
the MGF1 hash.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-15 11:12:30 +02:00
Steffen Jaeckel
33d8f8464d
Merge pull request #723 from cyanogilvie/fix/ocb-decrypt-aliasing
Fix s_ocb_done aliasing bug in decrypt path
2026-04-15 11:10:32 +02:00
Cyan Ogilvie
8c68d99221 Fix s_ocb_done aliasing bug in decrypt path
In decrypt mode (mode==1), s_ocb_done was XORing `ct[x]` into the
checksum before writing the output.  The function's parameter names are
misleading (the header comment notes pt/ct really mean in/out), so in
decrypt mode `ct` is the not-yet-written *output* buffer and `pt` is
the *input* ciphertext.  Reading from `ct` only worked when callers
aliased the input and output buffers (in-place decryption), as the
self-test does.  Callers passing distinct buffers got CRYPT_OK with
stat=0 -- correct plaintext but failed tag verification.

Fix by reading from `pt[x]` (the input).  Add a separate-buffer
regression case to ocb_test that runs against every existing test
vector and was confirmed to fail without the fix.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 19:32:17 -03:00
Steffen Jaeckel
e5bfb94f63
Merge pull request #719 from libtom/pr/scrypt-rfc7914
The scrypt Password-Based Key Derivation Function (RFC 7914)
2026-04-14 16:17:28 +02:00
Karel Miko
3aed12c410 The scrypt Password-Based Key Derivation Function (RFC 7914) 2026-04-14 13:59:38 +02:00
Steffen Jaeckel
94287f0480
Merge pull request #721 from cyanogilvie/fix/pclmul-cache-init-msvc
Fix s_pclmul_is_supported() cache flag on MSVC
2026-04-14 13:36:27 +02:00
Cyan Ogilvie
baac704391 Fix s_pclmul_is_supported() cache flag on MSVC
Move initialized=1 out of the #else branch so that on MSVC it doesn't
call __cpuid every time.
2026-04-14 07:45:41 -03:00
Steffen Jaeckel
cf29490bfc Introduce LTC_ALIGNED_BUF_SIZE(). [skip ci]
Since there's absolutely no way to ensure that a struct is somehow
aligned -- all those compile-time mechanism are best-effort and no
guarantee -- we align the necessary buffers at run-time.

AES-NI already introduced that, let's improve a bit upon its usage.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-14 09:55:43 +02:00
Steffen Jaeckel
14352f5036 Improve timing demo a bit. [skip ci]
Allow more classes to be filtered.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-14 09:17:11 +02:00
Karel Miko
66925c259c Fix helper.pl. [skip ci]
Fix matching of other uses of a descriptor type, besides their declaration.
2026-04-13 19:48:05 +02:00
Steffen Jaeckel
25e93e39cf Add uninstall_hooks make command. [skip ci]
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-13 14:45:12 +02:00
Steffen Jaeckel
5abd33ea32
Merge pull request #718 from libtom/pr/argon2-rfc9106
Argon2 password hashing function (RFC 9106)
2026-04-13 10:47:50 +02:00
Steffen Jaeckel
c68b9c0b3f Minor changes of argon2 implementation.
* We continue using `LTC_ARGCHK()` until we've decided on something else.
* Call the enum/struct the same as the typedef.
* Some other small adjustments/fixes.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-12 16:06:53 +02:00
Karel Miko
458b392d01 Argon2 password hashing function (RFC 9106) 2026-04-12 14:48:32 +02:00
Steffen Jaeckel
3223b87588
Merge pull request #709 from MarekKnapek/sha-stack
Smaller stack usage for SHA-1, SHA-256 and SHA-512.
2026-04-09 17:04:26 +02:00
Steffen Jaeckel
cc53195945 Update docs.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-09 15:40:07 +02:00
Steffen Jaeckel
11929885a4 Basic algo self-tests should be run before the ones using them.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-09 15:40:07 +02:00
Steffen Jaeckel
77afa82d14 Add option LTC_SMALL_STACK.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-09 15:40:07 +02:00
Steffen Jaeckel
a9cd3cd0ff Slightly improve timing demo.
* Add the option to only run for a subset of algos.
* Improve `hash` to show something meaningful.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-09 08:29:50 +02:00
Marek Knápek
17cbd2be0a Smaller stack usage for SHA-1, SHA-256 and SHA-512. 2026-04-09 08:29:50 +02:00
Steffen Jaeckel
d0e09092f9 Re-format gitignore. [skip ci]
I wasn't aware that the gitignore file had DOS line endings. Changed that
to UNIX line endings.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-09 08:29:38 +02:00
Steffen Jaeckel
ecc36868a9
Merge pull request #714 from sjlombardo/develop
Optimize gcm_gf_mult using PCLMULQDQ and PMULL
2026-04-07 18:31:43 +02:00
Steffen Jaeckel
93eed8d3fa Add CMake CI testrun w/o ASM
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-07 16:51:37 +02:00
Stephen Lombardo
46e0137e55 Optimize gcm_gf_mult using PCLMULQDQ and PMULL
GCM table setup disproportionately hurts LTC performance
with small messages. Disabling LTC_GCM_TABLES helps for
small payloads but hurts large ones.

This implements hardware carry-less multiplication for GCM that
performs well for both cases using PCLMULQDQ on x86/x86_64 and
PMULL on AArch64.

There are no public API changes.

These features can be disabled with LTC_NO_GCM_PCLMUL,
LTC_NO_GCM_PMULL, or LTC_NO_ASM. LTC_GCM_TABLES is disabled
automatically when no opt-out macro is set.
2026-04-07 16:51:37 +02:00
Steffen Jaeckel
6ad2ce97a4
Merge pull request #715 from libtom/add-cmake-tests
Add CMake & arm64 tests to CI
2026-04-07 15:45:09 +02:00
Steffen Jaeckel
0572f9564f Update nick-fields/retry GH action
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-07 12:40:22 +02:00
Steffen Jaeckel
97be312324 Add CMake tests to CI
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-04-07 12:19:33 +02:00
Steffen Jaeckel
63af5f6dc1 Update docs of ecc_free().
This fixes #710

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2026-02-04 11:30:24 +01:00
Steffen Jaeckel
9a13375d47
Merge pull request #708 from MarekKnapek/KangarooTwelve
KangarooTwelve
2025-11-28 22:27:59 +01:00
Marek Knápek
6832f3c106 Add KangarooTwelve XOF functions.
KangarooTwelve 128bits and KangarooTwelve 256 bits.

https://keccak.team/files/TurboSHAKE.pdf
https://www.rfc-editor.org/rfc/rfc9861.txt
https://datatracker.ietf.org/doc/html/rfc9861
2025-11-28 19:05:31 +01:00
Marek Knápek
189f9ccdf0 LTC_TURBO_SHAKE requires LTC_SHA3 2025-11-28 19:05:31 +01:00
Marek Knápek
e20fff1f3d Add more TurboSHAKE unit tests. 2025-11-28 19:05:31 +01:00
Marek Knápek
d31ca86251 Introduce the concept of "domain" for SHAKE XOF. 2025-11-27 14:28:00 +01:00
Steffen Jaeckel
4db24a7d08
Merge pull request #692 from MarekKnapek/turboshake
Add TurboSHAKE XOF functions.
2025-11-26 11:08:29 +01:00
Steffen Jaeckel
2c487a2e4b Update docs.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-25 10:09:14 +01:00
Steffen Jaeckel
e33128e18c Fix LTC_COMPARE_TESTVECTOR()
Fixes: 6daff83d ("Deprecate `compare_testvector()`.")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-25 09:28:20 +01:00
Marek Knápek
709572e22e Add TurboSHAKE XOF functions.
TurboSHAKE128 and TurboSHAKE256.
https://datatracker.ietf.org/doc/html/rfc9861
https://www.rfc-editor.org/rfc/rfc9861.txt
https://keccak.team/files/TurboSHAKE.pdf
https://github.com/libtom/libtomcrypt/issues/691
2025-11-25 09:22:35 +01:00
Steffen Jaeckel
34b6ad9a2e
Merge pull request #707 from libtom/improve-tests
Improve tests
2025-11-24 16:15:18 +01:00
Steffen Jaeckel
dda1c7eedf Re-factor modes_test().
... also funny that no static analyzer complained about `ret` being
assigned, but never read ...

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-24 14:58:13 +01:00
Steffen Jaeckel
6daff83d82 Deprecate compare_testvector().
This should never have been public API.
Also introduce a `LTC_COMPARE_TESTVECTOR()` macro to be used within the
library, which doesn't exit, but only returns an error.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-24 14:58:13 +01:00
Steffen Jaeckel
03881e4abc
Merge pull request #699 from libtom/some-improvements
Some improvements
2025-11-19 00:22:08 +01:00
Steffen Jaeckel
369650ccd3 Update makefiles 2025-11-18 23:20:01 +01:00
Steffen Jaeckel
e2918971fa Re-order PEM headers to prepare for X.509 APIs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 23:20:01 +01:00
Steffen Jaeckel
ea672df7a3 Put realloc logic into pem_read()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 23:20:01 +01:00
Steffen Jaeckel
9abf12305a Add SubjectPublicKeyInfo support to dsa_import()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 23:20:01 +01:00
Steffen Jaeckel
d77afd6a68 Use rsa_init() to initialize an rsa_key
(and you should do that too)

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 23:03:42 +01:00
Steffen Jaeckel
c9b609a0b7 Extend der_flexi_sequence_cmp()
To be able to do a bit more, add an optional handler callback function.
Additional to that, also make it possible to mark elements as optional.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 23:03:42 +01:00
Steffen Jaeckel
7e78899af6 Re-factor s_import_pkcs8()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 23:03:42 +01:00
Steffen Jaeckel
002a6c8330 Export static function as x509_import_spki()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 23:03:42 +01:00
Steffen Jaeckel
06b7a7e416 Extract static function as x509_get_pka()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 23:03:41 +01:00
Steffen Jaeckel
eda303df0f
Merge pull request #705 from libtom/new-ecc-api
New ECC API
2025-11-18 21:41:41 +01:00
Steffen Jaeckel
7f73f83853 Update docs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 18:53:26 +01:00
Steffen Jaeckel
a642e69afb Update makefiles 2025-11-18 18:53:26 +01:00
Steffen Jaeckel
b46c695505 Add tests for deprecated APIs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 18:53:26 +01:00
Steffen Jaeckel
35a4a5fc1b Move RFC6979 hash alg to a new ecc signature options struct
Fixes #700

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-18 18:53:26 +01:00
Steffen Jaeckel
c421e570c6
Merge pull request #704 from libtom/minor-improvements
Minor improvements
2025-11-11 09:04:01 +01:00
Steffen Jaeckel
91757cf54d Bump required CMake version & DRY
* The oldest supported Ubuntu Version is 22.04 which comes with CMake 3.22.
* Refactor demos/CMakeLists.txt to set the list of binaries only once.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:57:15 +01:00
Steffen Jaeckel
d8a62f3367 Create table of supported ECC curves programmatically
Related to #349

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:56:58 +01:00
Steffen Jaeckel
47162b9609 Add demos/der_print_flexi.c
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:56:42 +01:00
Steffen Jaeckel
e2d0935792 Add SHA3-HMAC support to PKCS#8
This also enables testing of PKCS#8 keys using modern hash algos with
LTC_EASY.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:38 +01:00
Steffen Jaeckel
934bd7e0fe Remove init_{GMP,LTM,TFM}()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:34 +01:00
Steffen Jaeckel
e0f49a924f Use LTC_TMPVAR() in more Macros.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:32 +01:00
Steffen Jaeckel
78e2675bfe Make store_test() a bit more aggressive.
With `LTC_FAST` enabled test to read from different offsets.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:29 +01:00
Steffen Jaeckel
6f085d349e Allow disabling of CLZL and CTZL builtins.
Fixes: fe8e4bf5 ("Use more builtin functions if available")
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:26 +01:00
Steffen Jaeckel
3c906ab3da Enable AES-NI per default on x86_64.
This can be disabled by defining `LTC_NO_AES_NI`.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:24 +01:00
Steffen Jaeckel
1924f43503 Fix warning uncovered by scan-build.
```
src/ciphers/aes/aesni.c:150:7: warning: Value stored to 'temp' is never read [deadcode.DeadStores]
  150 |       temp = temp_invert(rk);
      |       ^      ~~~~~~~~~~~~~~~
1 warning generated.
```

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:20 +01:00
Steffen Jaeckel
5dbdaff16b Minor fixes
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:16 +01:00
Steffen Jaeckel
ac291e8bdd Fix hmac_memory_multi() invocation
It expects a pair of type `(unsigned char*,unsigned long)` and not
`(unsigned char*,unsigned int)`.

Fixes: 46fa363f ("Finish up RFC6979 ECDSA keygen")
Reported-via: https://github.com/libtom/libtomcrypt/pull/699#issuecomment-3414862539 ff.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:52:06 +01:00
Steffen Jaeckel
c9259ffa31 Allow deprecation warnings to be disabled
One can now define them on a per-case basis to disable them.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:51:58 +01:00
Nicolas Mora
95a492a184 Make build of docs reproducible 2025-11-03 13:51:48 +01:00
Steffen Jaeckel
0c15edb22c Don't abort() in "release" builds
Change the default behavior of `LTC_ARGCHK()` for Release, resp.
Release+Shared Library builds to be non-fatal.

This closes #458

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:51:45 +01:00
Steffen Jaeckel
5e0d801c1d Clarify MPI providers a bit further
This closes #354

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:51:37 +01:00
Steffen Jaeckel
52b93bf3d1 Revert "cmake: add ccache support"
This reverts commit 93f5348c47.

You should use the CMake flag `-DCMAKE_CXX_COMPILER_LAUNCHER=ccache`
instead.

Sibling-to: https://github.com/libtom/libtommath/pull/577
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:51:29 +01:00
Steffen Jaeckel
c895dd990c Improve readability of script and the logs it creates
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:50:16 +01:00
Steffen Jaeckel
dd6ef9cdc7 Correctly treat NULL in the parameters of a SubjectPublicKeyInfo
The NULL is optional.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:50:11 +01:00
Steffen Jaeckel
eb807b84d0 Don't use written parameter of macro directly
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:50:06 +01:00
Steffen Jaeckel
2d64fc45e0 Fix curve25519 in case sha512 is not available
Before this patch it silently didn't work, now it errors out.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:49:58 +01:00
Steffen Jaeckel
8001748cd1 Improve register_{cipher,hash,prng}()
Only go once through `X_descriptor[]` when calling `register_X()`

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:49:53 +01:00
Steffen Jaeckel
4c03415dea Re-order hash registrations
... in order of likelihood of usage and/or strength.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:49:47 +01:00
Steffen Jaeckel
fc3af1e0ec A BitString of length 0 can be only 3bytes long
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-11-03 13:49:30 +01:00
Steffen Jaeckel
a3cc5bf623 Update issue template according to the new way how GH wants it.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-10-31 09:49:37 +01:00
Steffen Jaeckel
b1fa61d594
Merge pull request #698 from enginelesscc/develop
Fix build of aesni on msvc
2025-10-06 10:23:13 +02:00
Steffen Jaeckel
4d84f53ee7 Let's see if AESNI makes a difference
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-10-04 16:19:15 +02:00
Steffen Jaeckel
0aef68af83 Lets try to build with AESNI support on MSVC
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-10-04 12:12:49 +02:00
Vivyy
89b37c3606
Fix build of aesni on msvc 2025-09-20 23:43:10 +02:00
Steffen Jaeckel
5edb54e522
Merge pull request #696 from libtom/some-improvements
Some improvements
2025-09-15 15:35:47 +02:00
Steffen Jaeckel
ae50082c0f Only compute length of OID data once.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-13 12:04:42 +02:00
Steffen Jaeckel
ef1453d5ba It should be static inline
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-13 12:04:38 +02:00
Steffen Jaeckel
a58de2e03d Fix some scan-build warnings
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-13 12:04:38 +02:00
Steffen Jaeckel
f8c319ee6e Update crypt_build_settings
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-13 12:04:38 +02:00
Steffen Jaeckel
fe8e4bf547 Use more builtin functions if available
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-13 12:04:38 +02:00
Steffen Jaeckel
1978245572 Update makefiles 2025-09-13 12:04:38 +02:00
Steffen Jaeckel
bb389e2c99 Make some DER helpers private
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-13 12:04:38 +02:00
Steffen Jaeckel
18b4e3f2ef Handle long OID nodes.
This will behave differently on 32bit architectures, but since 32bit
is mostly dead and I don't see a way how to handle this w/o breaking
ABI&API, I guess we have to live with it.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-13 12:04:38 +02:00
Steffen Jaeckel
c00b006174 Make pem_read() ignore all junk before a real PEM header is found
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-12 18:25:09 +02:00
Steffen Jaeckel
78bb06c8d6 Minor cleanup
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-12 18:25:09 +02:00
Steffen Jaeckel
07d544c5d9 Add tests for & fix pk_oid API
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-12 18:25:09 +02:00
Steffen Jaeckel
fe32e7ea9d Add LTC_ARRAY_SIZE() macro
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-06 15:00:00 +02:00
Steffen Jaeckel
8d44e48d46 Be less strict in register_all_hashes()
Allow using all hashes in case we didn't register our ciphers.
Nobody should really use CHC, so we shouldn't make it mandatory.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-06 15:00:00 +02:00
Steffen Jaeckel
19a5520936 Allow base16_encode() to re-use the input buffer as output
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-06 15:00:00 +02:00
Steffen Jaeckel
72b353f3dd Workflow trigger filtering changed
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-06 15:00:00 +02:00
Steffen Jaeckel
6155a33e5f Use COMPARE_TESTVECTOR() consistently
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-06 15:00:00 +02:00
Steffen Jaeckel
cb12f2e7d0 Clarify some test descriptions
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-06 15:00:00 +02:00
Steffen Jaeckel
6fe391956d Fix/improve some install/uninstall make targets
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-06 15:00:00 +02:00
Steffen Jaeckel
87d51de391 Improve variable naming
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-06 14:59:59 +02:00
Steffen Jaeckel
563f0fb4f2
Merge pull request #524 from libtom/modes-use-ecb
Make all modes use the ECB mode API
2025-09-06 14:58:49 +02:00
Steffen Jaeckel
cd18fed7ba fix scan-build warnings 2025-09-05 18:23:26 +02:00
Steffen Jaeckel
3c42b6a668 fix timing demo 2025-09-05 17:38:30 +02:00
Steffen Jaeckel
06adf5269f refactor AEAD's and MAC's to use ECB API 2025-09-05 17:37:02 +02:00
Steffen Jaeckel
661109f660 re-factor modes to use internal ECB implementation 2025-09-05 17:37:02 +02:00
Steffen Jaeckel
23803626b6
Merge pull request #594 from orbea/shared
makefile.shared: Don't use libtool
2025-09-05 10:56:13 +02:00
orbea
d2f50cc16d makefile.shared: Don't use libtool
Gentoo Bug: https://bugs.gentoo.org/777084
2025-09-04 20:59:48 +02:00
Steffen Jaeckel
60566ebe0e
Merge pull request #477 from rmw42/feature/rfc6979
Deterministic EcDSA according to RFC6979
2025-09-04 20:59:17 +02:00
Steffen Jaeckel
46fa363f2c Finish up RFC6979 ECDSA keygen
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-04 17:36:30 +02:00
Steffen Jaeckel
d05119491b Update makefiles 2025-09-04 17:36:30 +02:00
Russ Williams
d376af52ca RFC6979: implementation, tests, docs 2025-09-04 17:36:30 +02:00
Steffen Jaeckel
f5a626f15f Let's wait a bit longer before bailing out
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-09-04 17:36:11 +02:00
Steffen Jaeckel
d448df1938
Merge pull request #689 from momo5502/develop
Fix CMake configure on Windows
2025-05-06 08:19:25 +02:00
Steffen Jaeckel
aeccd41afc Also run CMake build in Appveyor
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-05-05 21:17:57 +02:00
Maurice Heumann
5b93429053
Fix CMake configure on Windows 2025-05-03 10:10:40 +02:00
Steffen Jaeckel
3905c28913
Merge pull request #687 from UnknownDK/fix-flag-scopes
Fix PBES and OMAC flag scopes
2025-04-23 18:10:45 +02:00
Bjørn Højmose Grevenkop-Castenskiold
0672c6182f Fix PBES and OMAC flag scopes
pbes_properties and omac_state are gatekept by LTC_PBES and LTC_OMAC
respectively. Therefore they should only be used within those scopes.
2025-04-11 20:01:28 +02:00
Steffen Jaeckel
a6b9aff7aa
Merge pull request #450 from libtom/pr/ecdsa-der-attempt1
Fix #449 (ECDSA forcing DER/ASN.1)
2025-03-02 12:31:08 +01:00
Steffen Jaeckel
46f33c6b5d Update ecc_recover_key() docs.
This also adds a note about the potential limitation of the signature
formats, depending on the tailoring.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-03-02 12:09:24 +01:00
Steffen Jaeckel
3b7ad1b5d1 Improve ecc_recover_key()
It is already nearly independent of `LTC_DER`, so simply `#ifdef` that
code path instead of multiplying the APIs by the number of signature
formats.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-03-02 12:09:24 +01:00
Steffen Jaeckel
ecb5fdd997 Add testcase for Ethereum signatures.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-03-02 12:09:24 +01:00
Steffen Jaeckel
bdffc3d53e Update docs.
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-03-02 12:09:24 +01:00
Steffen Jaeckel
47c721c164 Update doc formatting
* make PDF content copy&paste-able
* add new `\code{}` command

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-03-02 12:09:24 +01:00
Steffen Jaeckel
2e09d68712 Update makefiles 2025-03-02 12:09:24 +01:00
Steffen Jaeckel
161b3be130 There is also no private PEM API if it's disabled
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-03-02 12:09:24 +01:00
Steffen Jaeckel
77bc1a7737 allow compilation of ECC w/o DER
via e.g.

```
make -j9 EXTRALIBS="../libtommath/libtommath.a " \
	CFLAGS="-DLTC_NOTHING -DLTC_MINIMAL -DLTC_MECC -DUSE_LTM \
	-DLTM_DESC -I../libtommath"
```
2025-03-02 12:09:24 +01:00
Karel Miko
6561b37bac refactor ecc_verify_hash_ex 2025-03-02 12:09:24 +01:00
Karel Miko
0ee3bb5786 refactor ecc_sign_hash_ex 2025-03-02 12:09:24 +01:00
Steffen Jaeckel
c996610ca6
Merge pull request #685 from paperchalice/quote
Quote header list when finding bcrypt
2025-03-02 11:42:59 +01:00
paperchalice
b508028b14 Quote header list when finding bcrypt
Found try compile source is incorrect, add quote to generate correct  source file.
2025-03-01 19:49:54 +01:00
Steffen Jaeckel
5c73ba894e
Merge pull request #686 from libtom/retry-dependencies-install
Try to work around build failures
2025-03-01 19:49:39 +01:00
Steffen Jaeckel
e609a505ca Try to work around build failures
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-03-01 11:52:51 +01:00
Steffen Jaeckel
d032686639
Merge pull request #596 from libtom/amalgamation
Amalgamation
2025-02-21 12:08:14 +01:00
Steffen Jaeckel
92aef0ade1 Include the tables into the amalgamation
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-20 14:43:07 +01:00
Steffen Jaeckel
22e71d755b Fix return value.
Instead of wrongfully always returning OK, return the real error code.

This was uncovered by the amalgamation via the warning:

```
pre_gen/tomcrypt_amalgam.c: In function ‘der_decode_custom_type_ex’:
pre_gen/tomcrypt_amalgam.c:49820:10: warning: ‘*(unsigned int *)((char *)&ident + offsetof(ltc_asn1_list, type))’ may be used uninitialized [-Wmaybe-uninitialized]
49820 |       if ((ident.type != root->type) ||
      |          ^
pre_gen/tomcrypt_amalgam.c:49780:18: note: ‘*(unsigned int *)((char *)&ident + offsetof(ltc_asn1_list, type))’ was declared here
49780 |    ltc_asn1_list ident;
      |                  ^~~~~
```

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-20 14:43:07 +01:00
Steffen Jaeckel
00f662da80 Fix compiler warning
```
pre_gen/tomcrypt_amalgam.c: In function ‘pkcs_1_oaep_encode’:
pre_gen/tomcrypt_amalgam.c:64485:18: warning: ‘DB’ may be used uninitialized [-Wmaybe-uninitialized]
64485 |       if ((err = hash_memory(lparam_hash_used, DB, 0, DB, &x)) != CRYPT_OK) {
      |                  ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
pre_gen/tomcrypt_amalgam.c:22613:5: note: by argument 2 of type ‘const unsigned char *’ to ‘hash_memory’ declared here
22613 | int hash_memory(int hash, const unsigned char *in, unsigned long inlen, unsigned char *out, unsigned long *outlen)
      |     ^~~~~~~~~~~
```

Use `out` instead of `DB`, since `out` is `LTC_ARGCHK`'ed.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-20 14:43:07 +01:00
Steffen Jaeckel
647b340ec3 Use LTC_NULL with ssh_decode_sequence_multi()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-20 14:43:07 +01:00
Steffen Jaeckel
08b69be797 minor changes for amalgamation
* de-duplicate `struct oid_to_pbes`
* add makefile target
* add amalgamation to release
* fix `small` demo
* add header guards for `tomcrypt_private.h`
* update docs
* add CI job with amalgamated library

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-20 14:43:06 +01:00
Steffen Jaeckel
236477823a prefix the MPI related macros with ltc_
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-20 14:41:50 +01:00
Steffen Jaeckel
3cc754610d undef Macros after usage & rename duplicate symbols
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-20 14:41:50 +01:00
Steffen Jaeckel
ac2c11aa17
Merge pull request #683 from libtom/some-improvements
Some improvements
2025-02-20 14:41:11 +01:00
Richard Levitte
894f33b81c Add contrib/libtomcrypt.cmake, and write about it in doc/crypt.tex
contrib/libtomcrypt.cmake is a snippet that can be used by any CMake
based project that wants to link with libtomcrypt, no matter if it
was installed with libtomcrypt-config.cmake or libtomcrypt.pc.

Fixes #681
2025-02-18 21:27:38 +01:00
Steffen Jaeckel
cda7d42647 Improve ILP32 detection
This should fix https://github.com/DCIT/perl-CryptX/issues/117

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-17 15:12:53 +01:00
Steffen Jaeckel
b4d41d53bb Ubuntu-20.04 is no longer
https://github.com/actions/runner-images/issues/11101

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-17 15:08:44 +01:00
Steffen Jaeckel
c93cc120f0 LTC_SOURCE ceased to exist
f55039bfeb removed all usage of
`LTC_SOURCE`, but I missed to remove it from the makefiles etc.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-02-17 15:05:01 +01:00
Steffen Jaeckel
54f0456559
Merge pull request #682 from paperchalice/cmake
Check BCryptGenRandom correctly
2025-01-29 17:13:55 +01:00
paperchalice
ae7f26ed44 Check BCryptGenRandom correctly 2025-01-29 19:05:43 +08:00
Steffen Jaeckel
427e0551c0
Merge pull request #680 from levitte/tomcrypt_private-stdarg 2025-01-21 09:35:06 +01:00
Richard Levitte
2fd160eae9 Have src/headers/tomcrypt_private.h include stdarg.h
This ensures that va_list, which is used in that file, gets properly
declared.

As a consequence, the following pattern in other files can be reduced:

    #include "tomcrypt_private.h"
    #include <stdarg.h>

Fixes #679
2025-01-21 07:18:45 +01:00
Steffen Jaeckel
2e9f2b5e44
Merge pull request #319 from libtom/add/SIV
Add SIV
2025-01-09 13:36:02 +01:00
Steffen Jaeckel
ad2696f24f Update SIV a bit
* Rename `siv_{en,de}crypt()` to `siv_{en,de}crypt_memory()`.
* The number of AAD components per SIV operation must not exceed 126.
* Init OMAC only once per SIV operation.
  All OMAC operations start off with the same key. Instead of
  re-initializing the OMAC context for each operation, init once and
  store the context.
* Add SIV to timing demo.
* Add 1000-times-encrypt-then-decrypt test for SIV.
* Update docs.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2025-01-01 17:05:36 +01:00
Steffen Jaeckel
8bdc093fae Add omac_vprocess()
As a new private API.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-28 19:11:32 +01:00
Steffen Jaeckel
197be81918 Re-factor SIV and add siv_memory()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-19 16:17:34 +01:00
Steffen Jaeckel
f4df47b59b Update makefiles
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-17 18:24:26 +01:00
Steffen Jaeckel
faa8cd71e5 add SIV
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-17 18:24:26 +01:00
Steffen Jaeckel
c900951dab Fix c&p error [skip-ci]
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-17 18:24:16 +01:00
Steffen Jaeckel
a81dab9970
Merge pull request #678 from libtom/some-improvements 2024-12-11 18:24:46 +01:00
Steffen Jaeckel
f6e71dfced Remove even more footers
Fixes 2400883060

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-11 12:10:02 +01:00
Steffen Jaeckel
87ff205c8b Handle potential pkg-config failures
There are cases where we want to use an MPI provider, but the package is
not installed in the system, so `pkg-config` can't find it.
To solve this simply ignore the errors created and only print something
if the user asks us to by passing `V=1`.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-11 11:57:08 +01:00
Steffen Jaeckel
54a16fb672 There are no broken demos anymore
... at least at compile time.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-11 11:09:58 +01:00
Steffen Jaeckel
795e8e8cfe Re-work some of the demos
* Add at least a `-h` option, sometimes more.
* Fix the exit codes of some of them.
* Make them all compile with `LTC_EASY`.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-11 11:09:58 +01:00
Steffen Jaeckel
d96605b4b9 Fix build on x32
* `CONSTPTR()` must be 32bit.
* `CRYPT_HASH_OVERFLOW` test operates on `unsigned long`, which is only
  32bit wide on x32.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-11 11:09:58 +01:00
Steffen Jaeckel
e487f8400e Introduce CRYPT_ERR_NUM and build-time check err_2_str[] size
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-11 11:09:58 +01:00
Steffen Jaeckel
507c66827f
Merge pull request #677 from libtom/some-improvements
Some improvements
2024-12-05 18:34:05 +01:00
Steffen Jaeckel
88dcebdbf5 Rework demos building and installation
* add `ltc` wrapper script for installed demos
* rework demos/CMakeLists.txt and add some more bells and whistles
* prefix installed demos with `ltc-`

Currently this makes the standard makefiles and CMake results diverge, but
we can fix that later if required.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-05 17:23:12 +01:00
Steffen Jaeckel
a9bb1c1525 Use cmake-format to format CMake files
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-03 19:51:26 +01:00
Steffen Jaeckel
98415b8a38 Change ltcrypt back to crypt
This reverts 85dc39483f

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-03 19:51:22 +01:00
Steffen Jaeckel
9eef89c5a4 Cancel running GH action on update of PR branch
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-12-03 19:48:18 +01:00
Steffen Jaeckel
dc945f9697 Add LTC_PTHREAD to pkg-config file if enabled at build time
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-11-20 13:11:59 +01:00
Steffen Jaeckel
2400883060 Remove remaining footers
Fixes 24765c30c5

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-11-20 12:59:49 +01:00
Richard Levitte
6659f36ad6 Align demo/CMakeLists.txt a bit more with with makefile_include.mk
Now, they build the same executables.
2024-11-20 12:59:45 +01:00
Steffen Jaeckel
17642547e4
Merge pull request #676 from hughsie/hughsie/sbom
Add a SBOM file in CycloneDX format
2024-11-19 14:39:57 +01:00
Richard Hughes
55441f12d2
Add a SBOM file in CycloneDX format
Improve supply chain security by including a SBOM file with substituted values.

This will be used to construct a composite platform SBOM.

Signed-off-by: Richard Hughes <richard@hughsie.com>
2024-11-19 12:28:13 +00:00
Steffen Jaeckel
5d2b15472f
Merge pull request #667 from levitte/constify-math
Constify math descriptors
2024-11-09 09:56:08 +01:00
Steffen Jaeckel
1d07689581 Remove unnecessary casts in the tests
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-11-08 17:15:39 +01:00
Richard Levitte
1e31c38e61 Remove unnecessary casts in the demos 2024-11-08 17:15:39 +01:00
Richard Levitte
4b3c98a4e6 Remove unnecessary casts in the misc implementations 2024-11-08 17:15:39 +01:00
Richard Levitte
b98ef26112 Remove unnecessary casts in the Sober128 implementation 2024-11-08 17:15:39 +01:00
Richard Levitte
fc32d77845 Remove unnecessary casts in the ECC implementation 2024-11-08 17:15:39 +01:00
Richard Levitte
477d09fd01 Remove unnecessary casts in the DSA implementation 2024-11-08 17:15:39 +01:00
Richard Levitte
7d3e6b7066 Remove unnecessary casts in the RSA implementation 2024-11-08 17:15:39 +01:00
Richard Levitte
e95069924a src/math/tfm_desc.c: Compensate for TFM before 0.14.0 (yet to be released)
TFM is notorious for not having a properly constified API.  This is to appear
in its next release, which is tentatively set to 0.14.0.
2024-11-08 17:15:39 +01:00
Richard Levitte
88315ff8df Constify all the functions in ltc_math_descriptor appropriately
This includes amending the documentation in doc/crypt.tex
This also includes removing unnecessary casts in src/math/*.c
2024-11-08 17:15:39 +01:00
Steffen Jaeckel
2dd6690edf
Merge pull request #674 from cmorty/pem_decode_filehandle
Add missing ifndef LTC_NO_FILE
2024-11-07 10:46:30 +01:00
Moritz Strübe
89d73ac405 Add missing ifndef LTC_NO_FILE
pem_decode_filehandle is deactiveted in the header, but not the module.
2024-11-06 15:35:29 +00:00
Steffen Jaeckel
d34f2130a6
Merge pull request #673 from cmorty/ltc_lrw_mode-macro
Add missing LTC_ prefix to LTC_LRW_MODE macro
2024-11-06 00:07:28 +01:00
Moritz Strübe
8daa79f85b Add missing LTC_ prefix to LTC_LRW_MODE macro
This also fixes the implicit declaration of function ‘gcm_gf_mult’
warning in lrw_start.c.
2024-11-04 14:36:19 +00:00
Steffen Jaeckel
cbb01b3708
Merge pull request #672 from libtom/some-fixes
Some fixes
2024-10-14 19:30:11 +02:00
Steffen Jaeckel
5a1545a8ae Ensure test buffers are always '\0' terminated
This caused spurious test failures.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-10-12 14:04:49 +02:00
Steffen Jaeckel
ebfcff3027 Fix handling of trailing spaces when decoding PEM files
Reported via [0].

[0] https://github.com/DCIT/perl-CryptX/issues/110#issuecomment-2407279713

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-10-12 14:04:49 +02:00
Steffen Jaeckel
31a48d06bf Const arrays should be const
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-10-12 14:04:49 +02:00
Steffen Jaeckel
c1437deec2 Fix hang when decoding PEM
Reported via [0]

[0] https://github.com/DCIT/perl-CryptX/issues/110#issue-2533207989

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-10-12 14:04:33 +02:00
Steffen Jaeckel
29af8922b6
Merge pull request #670 from libtom/fix-669
Fix type in PEM+SSH decoder
2024-10-07 12:42:12 +02:00
Steffen Jaeckel
3df7a96258 Fix type in PEM+SSH decoder
9b6bf32f88 changed the type of the length
argument of a `LTC_SSHDATA_STRING` from `ulong32` to `unsigned long` and
usage of this wrong type survived multiple re-factors and code moves.

This fixes #669

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-10-07 12:10:40 +02:00
Steffen Jaeckel
24fc92b857
Merge pull request #668 from levitte/pem-doc-fixes
Fix PEM documentation
2024-10-06 14:41:34 +02:00
Richard Levitte
2026e2865d Fix demos/pem-info.c to properly display different CFB modes
Also, make CMake build it.
2024-09-20 13:38:26 +02:00
Richard Levitte
dd3b9e59e1 Fix PEM documentation 2024-09-20 11:24:19 +02:00
Steffen Jaeckel
e0d90c58da
Merge pull request #646 from Xartrick/patch-1
Allow 72 bytes (576 bits) keys for Blowfish
2024-09-14 11:28:07 +02:00
Steffen Jaeckel
5f4ddc8d13 Update notes/cipher_tv.txt
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-09-14 10:33:04 +02:00
Xartrick
556c3222f2 Allow 72 bytes (576 bits) keys for Blowfish 2024-09-14 10:20:54 +02:00
Steffen Jaeckel
6865b9fc81
Merge pull request #666 from libtom/fix-aesni-in-ci
Fix AESNI build job
2024-09-03 13:03:29 +02:00
Steffen Jaeckel
dd98fcc461 Fix AESNI build job
Fixes: 33d1c814 ("Improve SSE4.1/AES-NI support")

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-09-03 12:35:12 +02:00
Steffen Jaeckel
ce904c86ef
Merge pull request #644 from tbvdm/aesni
Improve SSE4.1/AES-NI support
2024-09-02 14:26:39 +02:00
Tim van der Molen
33d1c81485 Improve SSE4.1/AES-NI support 2024-09-02 13:54:35 +02:00
Steffen Jaeckel
e8eb4a0312
Merge pull request #664 from libtom/pr/fix-sm4-on-cygwin
Cygwin fix for SM4 (issue #663)
2024-09-02 08:54:16 +02:00
Karel Miko
24e31ef373 Cygwin fix for SM4 (issue #663) 2024-09-01 18:59:41 +02:00
Steffen Jaeckel
fc6b42025b
Merge pull request #665 from libtom/pr/fix-anon-union
avoid using anonymous union (issue #662)
2024-09-01 17:28:56 +02:00
Karel Miko
d85a4e05e7 avoid using anonymous union (issue #662) 2024-09-01 12:59:32 +02:00
Steffen Jaeckel
ab16280bf1
Merge pull request #657 from levitte/ChaoWeiAtGit/develop
Add SM4 block cipher [reboot]
2024-08-31 15:13:06 +02:00
Chao Wei
6f15a45adc Add SM4 block cipher
SM4 (formerly SMS4)[1] is a block cipher used in the Chinese
National Standard for Wireless LAN WAPI (Wired Authentication
and Privacy Infrastructure).
--from wikipedia
2024-08-30 05:30:48 +02:00
Steffen Jaeckel
12bf723b74
Merge pull request #661 from libtom/fix-ccm
Fix compiler warning
2024-08-29 22:37:17 +02:00
Steffen Jaeckel
349d56e38c Fix compiler warning
Repeated from 97edea362a

```
src/encauth/ccm/ccm_add_nonce.c: In function ‘ccm_add_nonce’:
src/encauth/ccm/ccm_add_nonce.c:61:21: warning: writing 1 byte into a region of size 0 [-Wstringop-overflow=]
   61 |       ccm->PAD[x++] = (unsigned char)((len >> 24) & 255);
      |       ~~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
In file included from ./src/headers/tomcrypt.h:82,
                 from ./src/headers/tomcrypt_private.h:4,
                 from src/encauth/ccm/ccm_add_nonce.c:3:
./src/headers/tomcrypt_mac.h:410:24: note: at offset 16 into destination object ‘PAD’ of size 16
  410 |    unsigned char       PAD[16],              /* flags | Nonce N | l(m) */
```

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-28 08:47:34 +02:00
Steffen Jaeckel
c4b423f809
Merge pull request #660 from levitte/no-BCryptGenRandom
Make the definition of LTC_WIN32_BCRYPT private
2024-08-26 14:49:35 +02:00
Richard Levitte
00708c8837 Make the definition of LTC_WIN32_BCRYPT private
1. It's internal anyway, so doesn't quite need to be reflected in a
   public header file.
2. This makes it easy for someone build this library to choose not
   to use BCryptGenRandom() by simply definining LTC_NO_WIN32_BCRYPT,
   which was hard to reflect in an unmodified public header file.

Alternative to #653
2024-08-22 09:36:38 +02:00
Steffen Jaeckel
427ce3315e
Merge pull request #659 from levitte/cmake-build-tv_gen
With CMake, build demos/tv_gen as well
2024-08-20 14:36:09 +02:00
Richard Levitte
ba132eb4a7 With CMake, build demos/tv_gen as well 2024-08-20 14:35:58 +02:00
Steffen Jaeckel
e75c563d1d
Merge pull request #658 from levitte/fix-cipher_hash_test.c
fix: tests/cipher_hash_test.c failed to use aes_enc_test
2024-08-20 14:35:34 +02:00
Richard Levitte
6170ba5205 fix: tests/cipher_hash_test.c failed to use aes_enc_test
Depending on build circumstances, the AES test function is either
aes_test() or aes_enc_test().
2024-08-20 14:35:16 +02:00
Steffen Jaeckel
668bd74b93
Merge pull request #587 from libtom/add-pem-support
Add PEM support
2024-08-20 14:34:57 +02:00
Steffen Jaeckel
2594f3a7d2 Update docs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
2613264cef We can now also decrypt PEM files encrypted in CFB1 and CFB8 mode
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
cf79facfb9 Add support for CFB1 and CFB8
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
5dec1ee02d Fix make tvs, add make pr-check
Fixup of 5ad1681ccb

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
ec8ffbb5bd Update makefiles 2024-08-20 13:29:27 +02:00
Steffen Jaeckel
478f43fc56 Add support for reading authorized_keys files
This also changes the requirements when calling `ecc_find_curve()` that
the `cu` argument can be NULL.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
c0be0aa0bf Add support for more types of encrypted PEM files
1. ChaCha20, two-key 3DES and DES-X encrypted OpenSSL PEM files

2. AES-GCM and Chacha20+Poly1305 encrypted SSH keys

* OpenSSH uses a slightly different algorithm for its
  `chacha20-poly1305@openssh.com` than defined in the RFC.
  Therefore add an `openssh_compat` flag to
  `chacha20poly1305_state`.
* Add the option to give a 16byte IV and no counter, when calling
  `chacha20poly1305_memory()`
* Add support for DES-X

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
65e05bfa56 Update docs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
95790221fb Add free() function to password_ctx
The user can now pass a `free()` function pointer that will be used to
free the memory that has been allocated by the `callback()`.
If `free()` is NULL, the library will still call `XFREE()`.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
02cb0c4957 Revert "Move password buffer into the library"
This reverts commit d840323bc1d3bc35bc72271e55ffa644f02b4582
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
9db30dfdc5 Make everything compile on MSVC
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
03515d5611 Move password buffer into the library
The design before was not completely fine. The user had to allocate the
buffer and passed ownership to the library.
As of [0] this seems to be a problem in some environments.

[0] https://github.com/libtom/libtomcrypt/pull/587#issuecomment-1765324724

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
fe3b3e627b Add generic PEM decode APIs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
8d19047336 Add support for more PEM file types + some fixes
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
7b5d85d735 Calm old Valgrind ...
Valgrind 3.15.0 on Ubuntu 20.04 reports a false positive [0]

```
==7922== Conditional jump or move depends on uninitialised value(s)
==7922==    at 0x461F0C: s_decode_header (pem_ssh.c:316)
[...]
```

Simply suppress this false positive.

[0] https://github.com/libtom/libtomcrypt/actions/runs/6507805191/job/17676616149?pr=587

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
ca7b4ee354 Add more SSH key tests
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
928c476734 Per default support PEM line lengths up to 80 chars
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
23eb8f97bc Add support for importing PEM public keys
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Karel Miko
cda6211712 pem: support for RC5-CBC, RC5-CFB, RC5-OFB 2024-08-20 13:29:27 +02:00
Steffen Jaeckel
f6497d22ce Add support for more algos of encrypted PEM files
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
5d8658946b Refactor some of the ECC import internals
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
934abdd82f Add "Enter passphrase" support to openssh-privkey
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
9333d5c8a1 Use the public key contained within the ssh key
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
6c24c5c06d Add support for aes256-ctr encrypted SSH keys
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
661f5845fe distinguish between Ed25519 and X25519
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
39d4b089ac Update docs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
651582254b introduce pka_key_free()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
4e46f823df clean-up a bit
* more `const` correctness
* take `LTC_NO_FILE` into account
* only declare `extern` variables where they're required
* ensure keys don't contain stale data
* ensure input arguments are valid
* add `CRYPT_PW_CTX_MISSING` error code
* fix documentation

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
5523eadc13 disable PEM support on MSVC
If someone wants to fix builds on MSVC, please step forward. Until then
the library can still be used on Windows via `mingw-gcc`.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
26fbebb9d0 add support for DH keys
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>

# Conflicts:
#	src/pk/dh/dh_import.c
#	src/pk/dh/dh_set.c
#	src/pk/dh/dh_set_pg_dhparam.c
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
87a1758f2f split-up into multiple C files
... and slightly optimize multiple things, e.g. `DEK-Info` decoding

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
3e981af4c4 also test FILE-based PEM API's
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
a76447f7aa add file-iterator to test_process_dir()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
d1e48df763 Verify that the imported keys match
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
22a952b813 add DSA support to PEM decoder
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
464c9b1986 add dsa_import_pkcs8()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
370457f405 add PEM tests
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
f036a471bd add support for regular PEM files
This adds support to decode plain and encrypted PEM files.

Either in OpenSSL specific format or PKCS#8

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
3f6f885852 re-factor PKCS#8 API a bit
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
e9f1db1742 add pkcs8_get_children()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
b8cb13f998 add LTC_OID_MAX_STRLEN
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
18baa1476c add der_flexi_sequence_cmp()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
35c306feae add pk_get_oid_from_asn1()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
69c93a82a5 rename file
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
cf71fffbd9 re-factor openssh-privkey demo into library functions
This adds two new API functions
* `pem_decode_openssh()`
* `pem_decode_openssh_filehandle()`

It also introduces the following two new types:
* a new union type `ltc_pka_key` which can hold any PKA key type.
* a `password_ctx` type with a callback to retrieve a password
  if necessary.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
a301ea1419 use updated API
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
350fbc6546 refactor & clean-up
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
e0046fbd7e add ssh private testkeys
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
2ff20d7966 add ecdsa key support
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
fec3d45adc add rsa-support
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
bee3ad2a2a add OpenSSH Private Key decryption demo
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-20 13:29:27 +02:00
Steffen Jaeckel
f27a312a6c
Merge pull request #655 from levitte/upgrade-workflows
In workflows, modernise the actions that are used
2024-08-20 08:50:38 +02:00
Richard Levitte
3cea832f5e In workflows, modernise the actions that are used
actions/checkout@v2 → actions/checkout@v4
actions/upload-artifact@v3 → actions/upload-artifact@v4

This will reduce the amount of warnings in the workflow summary.
2024-08-20 06:53:53 +02:00
Steffen Jaeckel
cacfc2dc04
Merge pull request #651 from libtom/pr/fix-warning-unusedvar-tiger
fix unused variable warning in hashes/tiger
2024-08-18 16:14:45 +02:00
Steffen Jaeckel
1405c732ee
Merge pull request #652 from libtom/pr/fix-asm-volatile
Use standard __asm__ blocks instead of asm (from CryptX PR)
2024-08-18 13:22:44 +02:00
Karel Miko
e78a7b65eb Use standard __asm__ blocks instead of asm (from CryptX PR) 2024-08-18 13:21:37 +02:00
Steffen Jaeckel
90529a2d0c Fix missing static
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-08-18 12:57:04 +02:00
Karel Miko
9bdf5794d3 fix unused variable warning in hashes/tiger 2024-08-18 12:57:04 +02:00
Steffen Jaeckel
7d4a646f50 Merge branch 'fix-b64-zero-length-array' into develop
Closes #538
2024-08-18 12:56:05 +02:00
Steffen Jaeckel
9183396b85 Avoid zero length array with LTC_BASE64_URL unset 2024-08-18 12:53:47 +02:00
Steffen Jaeckel
2302a3a897
Merge pull request #647 from etienne-lms/xcalloc
fix XCALLOC() against GCC 14 -Wcalloc-transposed-args
2024-06-26 19:59:31 +02:00
Etienne Carriere
9c1e83b51b fix XCALLOC() against GCC 14 -Wcalloc-transposed-args
Fix use of XCALLOC() macro against GCC 14 directive
-Wcalloc-transposed-args that makes GCC to complain with an warning/error
trace message like the below when 1st argument is given by sizeof().

warning: 'calloc' sizes specified with 'sizeof' in the earlier argument and not in the later argument [-Wcalloc-transposed-args]

No functional changes.

Signed-off-by: Etienne Carriere <etienne.carriere@foss.st.com>
2024-06-25 17:28:16 +02:00
Steffen Jaeckel
f7e6519fae
Merge pull request #636 from libtom/update-fortuna
Update fortuna
2024-02-26 17:02:46 +01:00
Steffen Jaeckel
0e12dbd964 Update AES integration of fortuna
* Use `aes_` based API instead of `rijndael_`, so we can profit from
  a potential hardware accelerated version of AES.
* Add option to use 'encrypt_only' variant of AES inside fortuna

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-02-26 16:25:17 +01:00
Steffen Jaeckel
090f52755c Add aes_enc_test()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-02-26 16:25:17 +01:00
Steffen Jaeckel
86fe3b91f1
Merge pull request #640 from libtom/extend-tiger
Extend tiger
2024-02-26 16:22:59 +01:00
Steffen Jaeckel
5ad1681ccb Add new make target tvs
To simplify generating the necessary testvectors when adding a new
algorithm.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-02-26 15:53:17 +01:00
Steffen Jaeckel
8be96ac2f6 Update docs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-02-26 15:51:54 +01:00
Steffen Jaeckel
d11758e700 Add support for Tiger2
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-02-26 15:51:54 +01:00
Steffen Jaeckel
c272d2264c Add support for Tiger with more than 3 passes
This fixes #632

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-02-26 10:16:49 +01:00
Steffen Jaeckel
1777e6d5c3 Fix potential memory leak
Fixup of 97edea362a

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2024-02-25 23:55:53 +01:00
Steffen Jaeckel
7e863d2142
Merge pull request #612 from libtom/rsaaes_oaep_hashes
add possibility to use different hash algorithms in RSAES-OAEP
2023-10-09 14:38:14 +02:00
Steffen Jaeckel
63091c9e5c Add possibility to use different hash algorithms in RSAES-OAEP
The hash algorithms used in the MGF and to create the hash of the Label
must not forcibly be the same. This change allows to use different
algorithms.

Unfortunately this breaks the API if you use one of:
* `rsa_decrypt_key_ex()`
* `rsa_encrypt_key_ex()`
* `pkcs_1_oaep_decode()`
* `pkcs_1_oaep_encode()`

The `rsa_decrypt_key()` and `rsa_encrypt_key()` macros are still the same.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-09 12:26:21 +02:00
Steffen Jaeckel
91b7bbe4c1
Merge pull request #633 from libtom/some-fixes
Fix AES-NI and other minor stuff
2023-10-08 23:04:26 +02:00
Steffen Jaeckel
e4adaafd90 Fix make incompatibility
Since make version 4.3 [0] the `#` sign inside a string is handled
differently. Fix that.

[0] https://lists.gnu.org/archive/html/info-gnu/2020-01/msg00004.html

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 12:34:33 +02:00
Steffen Jaeckel
124e020437 Add missing package name suffix to CMake/CPack
Fixes e98e0a64e6

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 11:14:46 +02:00
Steffen Jaeckel
d9b25936fb Fix CMake with MSVC
Reported by @pineappleiceberg in [0]

[0] https://github.com/libtom/libtomcrypt/issues/577#issuecomment-1722545061

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 11:14:46 +02:00
Steffen Jaeckel
97edea362a Fix compiler warning
```
src/encauth/ccm/ccm_memory.c: In function ‘ccm_memory’:
src/encauth/ccm/ccm_memory.c:164:17: warning: writing 1 byte into a region of size 0 [-Wstringop-overflow=]
  164 |        PAD[x++] = (unsigned char)((len >> 24) & 255);
      |        ~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
src/encauth/ccm/ccm_memory.c:43:19: note: at offset 16 into destination object ‘PAD’ of size 16
   43 |    unsigned char  PAD[16], ctr[16], CTRPAD[16], ptTag[16], b, *pt_real;
      |                   ^~~
```

Multiple reviews and tests determined that this can't happen, but most
likely computers are better in finding out such stuff (or it was a false
positive).

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 11:14:46 +02:00
Steffen Jaeckel
7aaa8ebe19 Re-order struct members
In order to memory-align the used buffers for keys, IVs etc. we re-order
the struct members of ciphers, modes and encauth.

There's no guarantee that this works, but it improves the chances.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 11:14:46 +02:00
Steffen Jaeckel
c48673234c Always determine manually whether CC is clang
This is required
1. when cross-compiling
2. to enable/disable the specific compiler warnings

Tested on `bash`, `dash`, `zsh` and FreeBSD `sh`.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 11:14:46 +02:00
Steffen Jaeckel
d3a297c341 Add option to disable AES-NI at compile time
One can now define `LTC_NO_AES_NI` to disable AES-NI.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 11:14:46 +02:00
Steffen Jaeckel
1c36997bd0 Ensure that AES key is always correctly aligned
Aligning a `struct` member via `attribute(align(<n>))` is not guaranteed
to work.
Change the approach to use an opaque buffer and always manually align
the start pointers of the keys.

c.f. https://github.com/DCIT/perl-CryptX/issues/95

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 11:14:46 +02:00
Steffen Jaeckel
024d8a1340 Add LTC_ALIGN_BUF()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-10-05 11:14:46 +02:00
Steffen Jaeckel
b96e96cf8b
Merge pull request #626 from libtom/some-fixes
Some fixes
2023-08-23 14:37:18 +02:00
Steffen Jaeckel
c4fd304ff4 Fix #627
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 13:06:53 +02:00
Steffen Jaeckel
dc883ea0ea Add Testcase for #627
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 13:06:53 +02:00
Steffen Jaeckel
c4d22b9046 Fix build for Windows ARM (UWP)
This fixes #576

Patch inspired by the same, but modified.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 13:06:53 +02:00
Steffen Jaeckel
bc59fb82b8 Add support for reading random data from "bcrypt" on Windows
This fixes #577

Patch inspired by the same, but simplified after reading the docs.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 13:06:53 +02:00
Steffen Jaeckel
e591a35c6a Port WinCSP usage from libtommath
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 11:37:19 +02:00
Steffen Jaeckel
5fa7837f3a Add empty stub for s_der_tests_print_flexi()
So we don't have to `#ifdef` whether it's available or not.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 11:37:19 +02:00
Steffen Jaeckel
18863a8ade Fix DER decoding of UTF-8 Strings
Don't read more than the length indicated by the length field.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 11:37:19 +02:00
Steffen Jaeckel
c939720699 Add Testcase that UTF-8 decoding respects the ASN.1 length
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 11:37:19 +02:00
Steffen Jaeckel
7a38fca62a Fix some pkg-config related things
* use a separate `libtomcrypt` folder to install the headers to
* use `INCPATH` and `LIBPATH` when installing `libtomcrypt.pc`
* fix `libtomcrypt.pc` generation for `makefile.unix`

This fixes #625

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 11:37:19 +02:00
Steffen Jaeckel
e98e0a64e6 Port CMake changes from libtommath for Debian packaging
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 11:37:19 +02:00
ycaibb
ee24a31ae1 fix missing mutex unlock
Fixes a missing mutex unlock on an out of memory error
in ltc_ecc_fp_save_state().

Originates from: 4af447d408

Fixes #571

Comment by sj:
This patch version slightly deviates from the original patch to OP-TEE
since we don't call `XFREE(NULL)` as there exist implementations of
`free()` that don't support it.

Signed-off-by: Ryan Cai <ycaibb@gmail.com>
Reviewed-by: Jens Wiklander <jens.wiklander@linaro.org>
Modified-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 11:37:19 +02:00
Steffen Jaeckel
2cb51b656c
Merge pull request #631 from ulikos/fix-630
Fixed size check in ecc_get_key, Fixes #630
2023-08-07 11:36:53 +02:00
Ulrich Koschella
48462aab40 Fixed size check in ecc_get_key, Fixes #630 2023-08-07 11:05:09 +02:00
Steffen Jaeckel
6120c82618 Add Testcase for #630
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-08-07 11:05:09 +02:00
Steffen Jaeckel
06b0f7711b
Merge pull request #629 from ulikos/fix-628
Fixed wrong sign in docu of ECC Extended Key Generation, Fixes #628
2023-08-07 07:49:23 +02:00
Ulrich Koschella
7ddd4f7de2 Fixed wrong sign in docu of ECC Extended Key Generation, Fixes #628 2023-08-03 13:03:25 +02:00
Steffen Jaeckel
1e629e6f64
Merge pull request #557 from libtom/add-aesni
Add AES-NI
2023-06-22 19:15:27 +02:00
Steffen Jaeckel
d026c63075 Update makefiles
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-22 18:37:25 +02:00
Steffen Jaeckel
9e0a131b2c introduce separate aes_desc
`aes_desc` and `aes_enc_desc` now do auto-detection of the best suitable
AES implementation for the platform.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-22 18:37:25 +02:00
Steffen Jaeckel
2314444cb0 Disable warnings from clang
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-22 18:37:25 +02:00
Steffen Jaeckel
37a8d7ec77 add CI testrun with AESNI
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-22 18:37:25 +02:00
Steffen Jaeckel
31c7f891aa add support for AES-NI instructions
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-22 18:37:25 +02:00
Steffen Jaeckel
0173cac3be Add LTC_TMPVAR() macro
Use unique names for variables declared in macros.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-21 13:23:52 +02:00
Steffen Jaeckel
93f5348c47 cmake: add ccache support
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 21:14:38 +02:00
Steffen Jaeckel
a2245e8696
Merge pull request #611 from libtom/fix-mpi-pkgconfig
update `Libs` part of pkg-config file with configured MPI providers
2023-06-19 20:56:48 +02:00
Steffen Jaeckel
4767558fd0 Add correct MPI provider defines to pkg-config cflags
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 20:24:03 +02:00
Steffen Jaeckel
3f33ccf181 cmake: Add TomsFastMath support
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 20:23:23 +02:00
Steffen Jaeckel
5330cd1d9b also update pkg-config file generated by cmake
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 19:18:28 +02:00
Steffen Jaeckel
2c3a5fd0ac update Libs part of pkg-config file with configured MPI providers
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 19:18:28 +02:00
Steffen Jaeckel
93dc29ab9a
Merge pull request #623 from libtom/update-ci
Update base OS version of CI
2023-06-19 19:17:15 +02:00
Steffen Jaeckel
90359498e1 Remove pre-installed libtommath
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 17:16:23 +02:00
Steffen Jaeckel
acec8a5c3e More error logs on CI failure
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 17:15:59 +02:00
Steffen Jaeckel
8076d86366 Fix missing include paths of ltm and tfm
Default include paths of ltm and tfm have changed.
Try to get include paths from pkg-config.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 16:44:40 +02:00
Steffen Jaeckel
e1a52a5b94 Fix Valgrind CI run when building with Clang
Clang creates now DWARFv5 debug infos which isn't supported in old Valgrind
versions. Instruct Clang to create DWARFv4 debug infos, so we can run our
tests in Valgrind.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 16:34:07 +02:00
Steffen Jaeckel
87665fb276 Calm scan-build static analyser
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 16:34:07 +02:00
Steffen Jaeckel
f0328b02c2 Update base OS version of CI
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-06-19 16:34:07 +02:00
Steffen Jaeckel
fae62af0ab
Merge pull request #613 from SOuajih/pkcs_fix
fix pkcs_1_v1_5_decode() when empty message
2023-03-31 20:55:08 +02:00
Steffen Jaeckel
6164cc1cb6 ensure that input-data pointer is non-NULL
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-03-31 14:42:50 +02:00
Steffen Jaeckel
f9c0c63433 allow input-data pointer to be NULL
If we allow the length to be 0, we should also prepare for the case where
the user doesn't want to provide a valid input-data pointer.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-03-31 14:42:50 +02:00
Safae Ouajih
caf3500288 fix pkcs_1_v1_5_decode() when empty message
In case of EME-PKCS1-v1_5 decoding, the encoded message
format is as follow : EM = 0x00 || 0x02 || PS || 0x00 || M.
When using an empty message, the 0x00 octet that separates
the padding string and message is located at the end. Thus,
update the condition to pass the check in case of empty message.

This fixes the following AOSP cts test:
Module: CtsKeystoreTestCases
Test: testEmptyPlaintextEncryptsAndDecrypts
Link: https://android.googlesource.com/platform/cts/+/refs/tags/android-cts-12.0_r6/tests/tests/keystore/src/android/keystore/cts/CipherTest.java

Signed-off-by: Safae Ouajih <souajih@baylibre.com>
2023-03-31 14:21:01 +02:00
Steffen Jaeckel
05f94077cc fix help message of aesgcm demo
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2023-03-31 14:17:51 +02:00
Steffen Jaeckel
2a1b284677
Merge pull request #609 from atomicmooseca/fix-cmake
Update CMakeLists.txt
2023-01-18 19:33:50 +01:00
Steve Manley
2e24591795 Fix CMakeLists.txt which still used variables from the ltm port
It still used `LTM_{C,LD}_FLAGS` instead of `LTC_{C,LD}_FLAGS`.
2023-01-18 19:02:36 +01:00
Steffen Jaeckel
29986d04f2
Merge pull request #607 from Jinbosh8/reset-gcm-memory 2022-11-15 16:23:23 +01:00
Jin
b207b63bb3 Added gcm_reset() to gcm_memory() to avoid key leakage 2022-11-14 23:45:09 -08:00
Steffen Jaeckel
3474ca3712
Merge pull request #606 from libtom/docs-in-ci
Docs in ci
2022-10-14 12:47:50 +02:00
Steffen Jaeckel
06f22b61b5 create developer manual in CI
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-10-14 11:06:10 +02:00
Steffen Jaeckel
b073ee0c62 use correct Build Status badge in README
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-10-14 10:37:19 +02:00
Steffen Jaeckel
e8e678e101 improve MPI providers section in documentation
.. also add a checkbox regarding MPI providers to the issue template

This closes #605

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-10-12 12:06:59 +02:00
Steffen Jaeckel
e10c62ec18
Merge pull request #586 from libtom/feature/cmake-support
Feature/cmake support
2022-10-05 15:23:59 +02:00
Steffen Jaeckel
cdc1dbe6f5 port cmake integration changes from libtommath
... also enable building of tests.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-10-05 14:49:54 +02:00
Adrian Antonana
a9a010d5fc introduce initial cmake support 2022-09-13 12:29:55 +02:00
Steffen Jaeckel
e6be20bfc7
Merge pull request #601 from libtom/fix-600
remove camellia tests if `LTC_TEST` is not defined
2022-09-13 12:29:16 +02:00
Steffen Jaeckel
2fe75d31cb remove camellia tests if LTC_TEST is not defined
Fixes #600

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-09-13 11:55:20 +02:00
Steffen Jaeckel
fde3e8c10a
Merge pull request #599 from libtom/rereview-curve25519-ctx-and-ph
Re-review curve25519 ctx and ph
2022-09-13 11:50:57 +02:00
Steffen Jaeckel
1873838e96 fix incompatibility issues with LLP64 data models
This is also a fixup of a921112fe3

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-09-12 11:34:27 +02:00
Steffen Jaeckel
ca92434d9d don't overwrite arguments
There's no need to store those values first somewhere else.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-09-12 11:34:27 +02:00
Steffen Jaeckel
24275fee7e optimize stack arrays
* minimize stack usage
* no need to zero-initialize the arrays

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-09-12 11:34:27 +02:00
Steffen Jaeckel
97f78901e9 ensure that ctx is non-NULL
The code-path via the `ed25519ph_*()` APIs would have allowed to get here
and de-reference `ctx` even if it is `NULL`.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-09-12 11:34:27 +02:00
Steffen Jaeckel
e836af56c2 re-factor tweetnacl_crypto_hash[_ctx]()
@etienne-lms remarked in [0] that the stack usage could be minimized
by using `hash_memory_multi()` instead of copying the data, so let's do
that.

[0] https://github.com/OP-TEE/optee_os/pull/5486#discussion_r955095821

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-09-12 11:34:27 +02:00
Steffen Jaeckel
288088ce3f
Merge pull request #598 from libtom/improve-vararg-apis
Improve vararg apis
2022-09-12 11:34:01 +02:00
Steffen Jaeckel
1ee85a8f25 Update makefiles 2022-09-02 11:30:45 +02:00
Steffen Jaeckel
13dc1f4fa2 add test-case that uses LTC_NO_NULL_TERMINATION_CHECK
It's a compile-only test, but we run it anyways so we can finally get
`crypt_fsa()` included in the coverage report. It's not really useful but
also doesn't hurt.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-09-02 11:30:45 +02:00
Steffen Jaeckel
6ab01a8e8f fix possible UB
A user isn't guaranteed to use the `der_..._multi()` in a correct fashion.
Therefor change the pattern in the library and terminate further vararg
processing immediately after the `EOL` marker is hit.

The previous changes introducing the function-`attribute(sentinel)` would
allow detecting this, but not all compilers have support for the attribute.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-08-31 13:05:00 +02:00
Steffen Jaeckel
1c805e1c66 use LTC_NULL in the library code
`NULL` as defined by the standard is not guaranteed to be of a pointer
type. In order to make sure that in vararg API's a pointer type is used,
define our own version and use that one internally.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-08-31 13:05:00 +02:00
Steffen Jaeckel
0ad23e1b4c introduce LTC_NULL_TERMINATED function attribute
In order to be able to check at compile time whether a vararg function
is correctly NULL-terminated.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-08-31 13:05:00 +02:00
Steffen Jaeckel
ddfe2e8aa7
Merge pull request #597 from sa-kib/ed25519ctx
contextualized extension of the Ed25519 scheme
2022-08-21 11:34:22 +02:00
Steffen Jaeckel
23d7091b9f Update makefiles 2022-08-20 14:38:43 +02:00
Steffen Jaeckel
9dec999564 re-factor some parts of the Ed25519ctx and Ed25519ph implementation
* The RFC doesn't limit the context to be a string.
  It talks about `octets` which means it could be any binary data.
* Move the context-preprocessing function out of tweetnacl.c
* Fix potential segfaults when Ed25519 signature verification fails and
  `LTC_CLEAN_STACK` is enabled.
* Fix all the warnings.
* Update documentation.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-08-20 14:38:43 +02:00
Valerii Chubar
b761cc0f67 Add ed25519ctx and ed25519ph support
Signed-off-by: Valerii Chubar <valerii_chubar@epam.com>
Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@epam.com>
2022-08-20 14:38:43 +02:00
Valerii Chubar
a6c6492139 ed25519: Add testcase for segfault on verify
In case when the signature is not verified the "mlen" variable
is equal to ULONG_MAX. When LTC_CLEAN_STACK has been defined
this results in a segmentation fault.

Signed-off-by: Valerii Chubar <valerii_chubar@epam.com>
Signed-off-by: Sergiy Kibrik <Sergiy_Kibrik@epam.com>
2022-08-20 14:38:43 +02:00
Steffen Jaeckel
8fd5dad96b
Merge pull request #593 from libtom/cleanup
Cleanup
2022-07-18 10:55:46 +02:00
Steffen Jaeckel
a921112fe3 Ensure that hash overflow is detected
Previously it was not detected if `inlen` itself was too big and would
overflow the multiplication by 8.

Related to #592

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-07-16 15:09:48 +02:00
Steffen Jaeckel
bb09c272bb also build with MSVC 2019 & 2022
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-07-16 15:07:09 +02:00
Oliver Schneider
0219ace105 Spelling fix in tomcrypt_cfg.h 2022-03-18 10:43:09 +01:00
Steffen Jaeckel
038db7e03e fix sporadically failing tests when built with pthreads support
... I hope ... :)

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-03-17 15:08:39 +01:00
Steffen Jaeckel
2c51ae81ac make sure to check yarrow_read() return values
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-03-17 15:08:37 +01:00
Steffen Jaeckel
69843a4807 pack up failed build to be able to investigate
Sometimes it's hard to reproduce an issue as they happen on CI, so let's
pack-up what we can on failure and upload it as artifact.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-03-17 15:08:32 +01:00
Steffen Jaeckel
6552fbcfe2 add hash Id to docs 2022-03-17 14:26:44 +01:00
Steffen Jaeckel
06a81aeb22
Merge pull request #584 from libtom/cleanup
Clean-up & minor improvements
2022-03-16 20:52:33 +01:00
Steffen Jaeckel
c8e49539e6 add cipher Id to docs
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
31ab638fb6 silence valgrind
When compiling with clang (9-12) and then running the tests in
valgrind (I tested 3.13.0 and 3.15.0) the following error was created:

```
Conditional jump or move depends on uninitialised value(s)
   at 0x47761F: ecc_ssh_ecdsa_encode_name (ecc_ssh_ecdsa_encode_name.c:38)
   ...
Uninitialised value was created by a stack allocation
   at 0x477570: ecc_ssh_ecdsa_encode_name (ecc_ssh_ecdsa_encode_name.c:21)
```

This silences this error by initialising the stack-array on creation.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
7a8496df5c better debug output
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
cf58641c99 migrate from travis CI to GitHub actions
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
5c30a53074 improve pk_oid_num_to_str()
* allow `OID` to be `NULL` until you want to write it ...
* make sure we don't overflow the `int i`

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
1052703116 fix/improve DER tests
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
c2f6c403fe prevent UB
This prevents incrementing `adata`, which can be a NULL pointer at this
point.

Fixes #583

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
4a1477e289 add (private) rsa_import_pkcs1()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
3bf3dffabc signal a potential overflow when decoding a LTC_ASN1_SHORT_INTEGER
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
8899c81601 continue looping on NOP
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
ec27d57548 slightly improve base64 encoding
* ensure base64 encode in&out buffers aren't the same
* allow calling any of the encode functions with `out` being a
  NULL-pointer, to be able to determine the size for storing
  the output.

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
a24af5f7e1 correctly prefix enum ltc_oid_id members
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-11 16:12:27 +01:00
Steffen Jaeckel
0bfa7d0e1e add base64_encode_pem()
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-10 16:15:14 +01:00
Steffen Jaeckel
1aac5b322a fix typo
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-10 16:15:14 +01:00
Steffen Jaeckel
b39c46f817 re-order code a bit
... so only relevant parts are executed

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-10 16:15:14 +01:00
Steffen Jaeckel
11590de241 add SSH-style padding
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-10 16:15:14 +01:00
Steffen Jaeckel
cee9569fdd annotate some and fix un-aligned #endif
This fixes #572

Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2022-02-10 16:15:14 +01:00
Steffen Jaeckel
673f5ce290
Merge pull request #569 from cneveux/rsa_public_exponent
rsa: add rsa key generate with bignumber public exponent
2021-06-04 18:51:41 +02:00
Cedric Neveux
75cfdaa490 documentation: add new rsa generate key API
Add rsa_make_key_ubin_e api documentation.

Signed-off-by: Cedric Neveux <cedric.neveux@nxp.com>
2021-06-04 08:05:58 +02:00
Cedric Neveux
d6bc30e8b8 test: add test rsa key generate with public exponent upto 256 bits
Add a RSA test generating a RSA key with a 256 bits public exponent.

Signed-off-by: Cedric Neveux <cedric.neveux@nxp.com>
2021-06-04 08:05:58 +02:00
Cedric Neveux
49556a8e60 rsa: add rsa key generate with public exponent upto 256 bits
Function rsa_make_key() limits the RSA key generates to a public
exponent of type long (32 bits or 64 bits).
RSA standard specify that public exponent e can be between 65537 (included)
and 2^256 (excluded).

Add function rsa_make_key_ubin_e to use a hexadecimal public exponent.
Add function rsa_make_key_bn_e to use a bignumber public exponent
(op-tee).

Signed-off-by: Cedric Neveux <cedric.neveux@nxp.com>
2021-06-04 08:05:58 +02:00
Steffen Jaeckel
165c795b65
Merge pull request #546 from libtom/fix-dsa-sha-dependency
fix DSA dependency to SHA2
2021-04-14 15:52:41 +02:00
Karel Miko
9a07c425bd DSA gen params: fixed check group_size vs LTC_MDSA_MAX_GROUP, updated LTC_MDSA_DELTA, new LTC_MDSA_MAX_MODULUS 2021-04-14 12:10:45 +02:00
Steffen Jaeckel
4bcb2c1873 don't undermine hash-registry concept
This allows registering an own implementation with a different
descriptor name.
2021-04-14 12:07:03 +02:00
Steffen Jaeckel
32d650807c use sha3 if available 2021-04-14 12:07:03 +02:00
Steffen Jaeckel
96c72ec31e fix dependency to sha2
DSA had a hard dependency to the basic sha2 operations.
In case one wanted to compile e.g. only with sha256 this lead to a
compilation error.
2021-04-14 12:07:03 +02:00
Steffen Jaeckel
077f4d6367
Merge pull request #567 from dcantrell/develop
m68k platforms are big endian
2021-04-11 21:01:42 +02:00
David Cantrell
112c32d756 m68k platforms are big endian
The endianness fallback in tomcrypt_cfg.h lacked a check for the gcc
define for m68k.  I discovered this while building dropbear on A/UX
3.1.1 on a Macintosh Quadra 700 (yes, in 2021).  Adding the check for
the gcc __m68k__ define gets everything building.

Signed-off-by: David Cantrell <david.l.cantrell@gmail.com>
2021-04-11 12:21:42 -04:00
Steffen Jaeckel
d34c440421
Merge pull request #560 from libtom/cleanup-and-fixes
Cleanup and fixes
2021-04-10 15:16:55 +02:00
Steffen Jaeckel
c117cd8a85 add comment indicating supported platforms of makefile.shared 2021-04-10 13:02:39 +02:00
Karel Miko
5329bdc5fb missing endif 2021-04-10 13:02:39 +02:00
Steffen Jaeckel
2a6e57fc2f fix unbalanced #ifdef for MIPS R5900
This fixes #562

[skip ci]
2021-04-10 13:02:39 +02:00
Steffen Jaeckel
2bee98076f cast away cast-align warnings 2021-04-10 13:02:39 +02:00
Steffen Jaeckel
9616356abe review CCM
* improve some comments
* harden some arguments
* fix the overflow warning

fixes #555, fixes #544
2021-04-10 13:02:39 +02:00
Steffen Jaeckel
ea7d8eb541 make sure that CTR->pad[] is aligned to 16 bytes
Fixes #549
2021-04-10 13:02:39 +02:00
Steffen Jaeckel
8f36c37acb clarify LTC_PAD_PKCS7 2021-04-10 13:02:39 +02:00
Steffen Jaeckel
748994c55f add LTC_ALIGN() macro 2021-04-10 13:02:39 +02:00
Steffen Jaeckel
5bc034ff55 re-factor some tests 2021-04-10 13:02:39 +02:00
Steffen Jaeckel
ddf1b63ac2
Merge pull request #565 from libtom/fix-cryptx69
make sure basic types are marked as UNIVERSAL&PRIMITIVE
2021-04-10 13:02:19 +02:00
Steffen Jaeckel
df6e14a9cb make sure basic types are marked as UNIVERSAL&PRIMITIVE
This fixes DCIT/perl-CryptX#69
2021-04-09 12:48:17 +02:00
Steffen Jaeckel
ae87fca70a
Merge pull request #564 from Biswa96/develop
Makefile: Fix shared library build in MinGW.
2021-04-09 12:30:37 +02:00
Biswapriyo Nath
e86dbc4591
Makefile: Fix shared library build in MinGW.
This enables -no-undefined linker flag in mingw toolchain.
Previous related commit 9c2c9f8af4
2021-03-28 22:06:52 +05:30
Steffen Jaeckel
910d625277
Merge pull request #558 from jamuir/develop
Add new utf8 test-vector, update comments explaining utf8 decoding
2021-01-19 13:51:22 +01:00
James Muir
2092250088 Add new utf8 test-vector, update comments explaining utf8 decoding
Description:
Minor changes to help test and clarify the way utf8 strings are
decoded.  This originated from my misunderstanding of the fix for
issue #507.  The new test-vector uses two bytes to encode each
wide-char.

The utf8 format is described here:

  https://tools.ietf.org/html/rfc3629#section-3

Testing:

  $ make clean
  $ make CFLAGS="-DUSE_LTM -DLTM_DESC -I../libtommath" EXTRALIBS="../libtommath/libtommath.a" test
  $ ./test

You can confirm that the new utf8 test data is correct using python:

  >>> s="\xD7\xA9\xD7\x9C\xD7\x95\xD7\x9D"
  >>> s.decode("utf-8")
  u'\u05e9\u05dc\u05d5\u05dd'
2021-01-15 20:55:09 -05:00
Steffen Jaeckel
954ab9bcfc
Merge pull request #550 from libtom/clean-up-stuff
Patch & clean up
2020-12-21 19:34:39 +01:00
Steffen Jaeckel
6b12bc5bd8 don't allow LTC_CLEAN_STACK to be enabled until fixed
As discussed in issue #486 [1] the current behavior shouldn't be used
anymore.

[1] https://github.com/libtom/libtomcrypt/issues/486
2020-12-21 13:53:36 +01:00
Steffen Jaeckel
53b0f1e30f update TEA testvectors 2020-12-21 13:53:36 +01:00
Steffen Jaeckel
3ec7f71f4f fix tea_ecb_encrypt()
This fixes #553
2020-12-21 13:53:36 +01:00
Steffen Jaeckel
77a932cb07 fix tea_test() 2020-12-21 13:53:36 +01:00
Steffen Jaeckel
11978c16d7 make sure PKCS#5 iteration count is a "positive integer"
This fixes #552
2020-12-21 13:53:36 +01:00
Steffen Jaeckel
c549f0fb3b add check maketarget 2020-12-21 13:53:36 +01:00
Steffen Jaeckel
f8393fd7c2 Exclude tests/test.key from potential crlf conversion
This closes #521
2020-12-21 13:53:36 +01:00
Steffen Jaeckel
8f12addd0f add comment about padding types 2020-12-21 13:53:36 +01:00
Steffen Jaeckel
7d57bae82c read system timer on AARCH64 2020-12-21 13:53:36 +01:00
Steffen Jaeckel
98dd1df545 recent aesgcm versions have shorter iv/key strings 2020-12-21 13:53:36 +01:00
Steffen Jaeckel
696e781d41 Fix returning too many or too few bits
original patch by @friedrichsenm

This closes #543
2020-12-21 13:53:36 +01:00
Steffen Jaeckel
b3305b05e7
Merge pull request #556 from timgates42/bugfix_typo_success
docs: fix simple typo, succes -> success
2020-12-21 11:16:09 +01:00
Tim Gates
59d8741d65
docs: fix simple typo, succes -> success
There is a small typo in src/mac/f9/f9_test.c, src/mac/xcbc/xcbc_test.c.

Should read `success` rather than `succes`.
2020-12-08 21:44:22 +11:00
Steffen Jaeckel
cfbd7f8d36
Merge pull request #545 from libtom/pattop/fixes
Minor fix & cleanup
2020-08-29 11:30:23 +02:00
Patrick Oppenlander
d63d6faf22 sha256: minor undef cleanup
RND is #defined in both the #if and #else case, so move the #undef after
the #endif.
2020-08-17 09:54:14 +10:00
Patrick Oppenlander
40b9560521 HASH_PROCESS: fix overflow test
state_var.length counts bits, inlen is in bytes.
2020-08-17 09:44:21 +10:00
Steffen Jaeckel
3f1b6877c0
Merge pull request #541 from pattop/fixes
Minor dependency cleanups
2020-08-16 15:13:27 +02:00
Steffen Jaeckel
93ae347132 prevent usage of ifdef in code 2020-08-14 00:49:44 +02:00
Patrick Oppenlander
78f94225c8 error on missing dependencies for LTC_PBES and LTC_PKCS_5 2020-08-13 23:37:16 +02:00
Patrick Oppenlander
3a775da837 support compilation of x509 without LTC_MECC 2020-08-13 23:37:16 +02:00
Patrick Oppenlander
a5765d2b61 make ecc_ssh_ecdsa_encode_name conditional on LTC_SSH
This fixes build breakage when LTC_MECC is not defined:

src/pk/ecc/ecc_ssh_ecdsa_encode_name.c:20:74: error: unknown type name 'ecc_key'
   20 | int ecc_ssh_ecdsa_encode_name(char *buffer, unsigned long *buflen, const ecc_key *key)
2020-08-13 23:37:16 +02:00
Steffen Jaeckel
40eea675cd
Merge pull request #534 from libtom/pr/macro-names-cleanup
Clean up macro names and static functions
2020-08-03 14:01:42 +02:00
Steffen Jaeckel
469eeaf632 prefix static function in multi2 with s_
This fixes #540
2020-07-16 11:03:40 +02:00
Steffen Jaeckel
c5d7bfb2cc manually fix the remaining leading _'s 2020-07-16 10:38:33 +02:00
Steffen Jaeckel
373974edee Revert "rename according to currently still valid rules"
This reverts commit 561d4ab8e8.
2020-07-16 10:38:33 +02:00
Steffen Jaeckel
3447eaff53 also prefix static hash functions by s_ 2020-07-16 10:38:33 +02:00
Steffen Jaeckel
4fd7b5002d prefix static functions with s_ 2020-07-14 18:44:40 +02:00
Karel Miko
cb63d3c074 Fix macro names - related to #448 2020-07-14 18:44:38 +02:00
Karel Miko
89d991e946 add macro name check to helper.pl 2020-07-14 18:44:23 +02:00
Steffen Jaeckel
d8d7a83b34
Merge pull request #539 from libtom/relicense
Relicense
2020-07-14 18:42:24 +02:00
Steffen Jaeckel
3630bee6fc update LICENSE file 2020-07-14 18:41:30 +02:00
Steffen Jaeckel
9824af8e3b update header 2020-07-14 18:41:30 +02:00
Steffen Jaeckel
24765c30c5 remove footer 2020-07-14 18:41:29 +02:00
Steffen Jaeckel
6b85be4095
Merge pull request #533 from libtom/fix-373
really implement DER decoding resursion limit
2020-07-14 18:40:46 +02:00
Steffen Jaeckel
561d4ab8e8 rename according to currently still valid rules 2020-06-20 12:43:08 +02:00
Steffen Jaeckel
cac400cf79 really implement DER decoding resursion limit
PR #373 did not really fix the issue of preventing a potential stack
overflow in case a lot of nested sequences have to be decoded.
Instead it only threw an error after successfully decoding all the nested
sequences.
This change fixes this and prevents the decoding.
2020-06-20 12:28:22 +02:00
Steffen Jaeckel
14ed10c11f
Merge pull request #535 from libtom/fix-532
Add "memory" to clobber list of `STORE/LOAD32`
2020-05-08 14:01:59 +02:00
Frédéric Recoules
19c6e7942d Add "memory" to clobber list of STORE/LOAD32
c.f. cefff85550
2020-05-07 13:00:21 +02:00
Steffen Jaeckel
1937f41260
Merge pull request #523 from libtom/cleanup-hmac-state
remove unused `hashstate` from `hmac_state`
2019-11-22 12:03:27 +01:00
Steffen Jaeckel
c713e9536f remove unused hashstate from hmac_state 2019-11-22 12:02:52 +01:00
Steffen Jaeckel
193086d6eb
Merge pull request #526 from libtom/latest-ltm
allow building against latest ltm
2019-11-22 11:43:15 +01:00
Steffen Jaeckel
8842720236 allow building against latest ltm 2019-11-21 08:53:30 +01:00
Steffen Jaeckel
0c30412a66
Merge pull request #503 from libtom/fix-502
Replace (ed|x)25519_set_key by (ed|x)25519_import_raw
2019-10-21 11:44:04 +02:00
Steffen Jaeckel
354c90517e
Merge pull request #514 from libtom/pr/fix-for-513
Avoid 64-bit rotation for i386 targets
2019-10-20 12:45:51 +02:00
Karel Miko
23a7ba244c Avoid 64-bit rotation for i386 targets 2019-10-20 10:06:51 +02:00
Steffen Jaeckel
2d930616e0 Update docs
[skip ci]
2019-10-19 16:30:18 +02:00
Steffen Jaeckel
461a047afd Update makefiles 2019-10-19 16:30:18 +02:00
Steffen Jaeckel
334876db78 rename x25519_set_key to x25519_import_raw 2019-10-19 16:30:18 +02:00
Steffen Jaeckel
44a18342ba rename ed25519_set_key to ed25519_import_raw 2019-10-19 16:30:18 +02:00
Steffen Jaeckel
3540fd713c fixup x25519_import()
bring x25519_import() in line with its ed25519 counterpart
2019-10-19 16:30:05 +02:00
Steffen Jaeckel
25410c7524
Merge pull request #505 from libtom/rsa-improvements
Add rsa_init() and rsa_shrink_key()
2019-10-17 22:28:18 +02:00
Steffen Jaeckel
5c6212af75 make rsa_shrink_key() private for now 2019-10-17 22:27:54 +02:00
Steffen Jaeckel
08abc93c40 Update makefiles 2019-10-17 22:27:54 +02:00
Steffen Jaeckel
4e28b922a9 add rsa_shrink_key() 2019-10-17 22:27:54 +02:00
Steffen Jaeckel
6fa98beb8a fix comment 2019-10-17 22:27:54 +02:00
Steffen Jaeckel
b9a75829a6 add rsa_init() 2019-10-17 22:27:54 +02:00
Steffen Jaeckel
50584ac7ec do timing on actual RSA key sizes 2019-10-17 22:27:54 +02:00
Steffen Jaeckel
49bb37dff1
Merge pull request #512 from fperrad/20191017_indent
fix indentation
2019-10-17 22:27:32 +02:00
Francois Perrad
38c144870b fix indentation 2019-10-17 17:17:38 +02:00
Steffen Jaeckel
9682df98e4
Merge pull request #511 from libtom/more-fixes
More fixes
2019-10-17 14:50:11 +02:00
Steffen Jaeckel
68cc580602 use macros in more tests 2019-10-17 12:49:20 +02:00
Steffen Jaeckel
a3310959d0 fix changed ltm API 2019-10-17 12:49:20 +02:00
Steffen Jaeckel
a68b703e22 use zeromem in stream-cipher done() functions 2019-10-17 10:29:27 +02:00
Steffen Jaeckel
ef55d1335e fix some MSVC compiler warnings 2019-10-17 10:29:27 +02:00
Steffen Jaeckel
2a63adc1ab add XSTRLEN 2019-10-17 10:29:27 +02:00
Steffen Jaeckel
fcdb14ede1
Merge pull request #500 from libtom/fix-ssh-api
Fix SSH API
2019-10-16 23:16:46 +02:00
Steffen Jaeckel
9b6bf32f88 use unsigned long for the length of a string 2019-10-13 14:05:41 +02:00
Steffen Jaeckel
27ec31d4f3 improve SSH decoding & doc 2019-10-13 14:05:41 +02:00
Steffen Jaeckel
c13dc105f3 verify pointer to be non-NULL before dereferencing 2019-10-13 14:05:41 +02:00
Steffen Jaeckel
58254f76e8 fix SSH string implementation 2019-10-13 14:05:41 +02:00
Steffen Jaeckel
f89909bd6c use macros in ssh_test() 2019-10-13 14:05:41 +02:00
Steffen Jaeckel
8b5ce8ba7e add ENSURE() macro 2019-10-13 14:05:41 +02:00
Steffen Jaeckel
26dc2766bd move LTC_SSHDATA_EOL to the beginning of the enum
If there's an EOL at the end of the enum I'm tempted to add new entries
before that one and then this will break the ABI which I don't like.
2019-10-13 14:05:41 +02:00
Steffen Jaeckel
5ded083bb0
Merge pull request #497 from libtom/bcrypt
Bcrypt
2019-10-13 14:05:13 +02:00
Steffen Jaeckel
36260aea85 Update makefiles 2019-10-12 14:31:38 +02:00
Steffen Jaeckel
d4233e9156 rename arguments 2019-10-12 14:31:38 +02:00
Steffen Jaeckel
e9ff57d5d7 fix varargs error
When compiling with "-g -O0" valgrind complained about "Conditional jump
or move depends on uninitialised value(s)", c.f. e.g. [1]

[1] https://travis-ci.org/libtom/libtomcrypt/jobs/588690930
2019-10-12 14:31:38 +02:00
Steffen Jaeckel
9423f3b26d add bcrypt 2019-10-12 14:31:38 +02:00
Steffen Jaeckel
5e30d3512f add required private API 2019-10-12 13:13:49 +02:00
Steffen Jaeckel
e69579cac2 start re-factor 2019-10-12 13:13:49 +02:00
Steffen Jaeckel
238eb7339a
Merge pull request #504 from libtom/minor-fixes
Minor fixes and improvements
2019-10-12 13:11:20 +02:00
Steffen Jaeckel
c0d1cbdf1d fix #469
[skip ci]
2019-10-11 14:32:22 +02:00
Steffen Jaeckel
4fd4e86ce0 re-order examples 2019-10-11 14:32:22 +02:00
Steffen Jaeckel
d2027d60eb add testcase for issue #507 2019-10-11 14:32:22 +02:00
Steffen Jaeckel
197621d867 re-order vars of travis.yml
the travis UI shows them right besides the build and the name says more
than the script on what is done
2019-10-11 14:32:22 +02:00
Steffen Jaeckel
8d22018065 don't produce any console-output on make V=0 2019-10-11 14:32:22 +02:00
Steffen Jaeckel
5e41924d85 use mp_init_copy() instead of init()+copy() 2019-10-11 14:32:22 +02:00
Steffen Jaeckel
34d865488b update LTC_DEPRECATED macro from ltm 2019-10-11 14:32:22 +02:00
Steffen Jaeckel
3e11e86f3e further updated ltm API 2019-10-11 14:32:22 +02:00
Steffen Jaeckel
c113c03c13 run {A,UB}SAN again with GMP
Fixup of 798d7dc61f
2019-10-11 14:32:22 +02:00
Steffen Jaeckel
9c67f8ac3c Fix includes
Headers which are included with '< >' can only be found if the folder where
the files are located is given as include path.
To be able to install the files to a separate folder, include them instead
with '" "'.
2019-10-11 14:32:22 +02:00
Steffen Jaeckel
0ca8a31cd3 clean-up define 2019-10-11 14:32:22 +02:00
Steffen Jaeckel
f9ab401098 check ranges of more ciphers
Inspired by #493 of @jbech-linaro I reviewed all blockciphers
for similar patterns.

Reviewed-by: Joakim Bech <joakim.bech@linaro.org>
2019-10-11 14:32:22 +02:00
Steffen Jaeckel
659540393e
Merge pull request #506 from libtom/add-tea
Add TEA blockcipher
2019-10-11 14:30:21 +02:00
Steffen Jaeckel
79f812c9f4 update TV's 2019-10-11 14:20:43 +02:00
Steffen Jaeckel
06a58ab519 update doc 2019-10-11 14:20:43 +02:00
Steffen Jaeckel
74197c81c5 Update makefiles 2019-10-11 14:20:43 +02:00
Steffen Jaeckel
0f2c415e7a add TEA 2019-10-11 14:20:43 +02:00
Steffen Jaeckel
8e044b8bf6
Merge pull request #509 from armcc/improve-des-tests
fix and cleanup des and 3des test cases
2019-10-11 09:39:13 +02:00
Andre McCurdy
d85045e18a fix and cleanup des and 3des test cases
- Drop unused 'num' field from struct des_test_case.
 - Fix the order of arguments passed to compare_testvector() (actual
   and expected buffers were swapped, leading to misleading error
   messages for failing tests).
 - Enable all DES test vectors by default and use them for both
   encrypt and decrypt. That allows the struct des_test_case 'mode'
   field (which was previously incorrect for the LTC_TEST_EXT tests)
   to be dropped.
 - Run the "encrypt / decrypt all zero's" tests once, instead of
   running repeatedly from within the test vectors loop.
 - Add minimal set of 128bit key 3DES test vectors.
 - Try to more closely align the des_test() and des3_test() functions
   (common flow, common variable names, etc).
 - Minor indent fixes.

Signed-off-by: Andre McCurdy <armccurdy@gmail.com>
2019-10-10 00:58:55 -07:00
Steffen Jaeckel
64d1153e5a
Merge pull request #508 from werew/develop
Fixes #507
2019-10-08 09:07:43 +02:00
werew
25c26a3b7a Fixes #507 2019-10-03 19:57:10 +02:00
Steffen Jaeckel
734ba7ec50
Merge pull request #499 from libtom/minor-improvements
Minor improvements
2019-09-30 15:00:05 +02:00
Steffen Jaeckel
da9f55231f don't exclude other settings when giving make options
Now `make LTC_DEBUG=1` builds a full-speed library but with debug infos.

One has to do `make LTC_DEBUG=1 IGNORE_SPEED=1` now to have the same
results as before.

This was done since
1. it makes sense to enable optimization also when adding debug infos
2. clang+valgrind creates errors if there's no optimization enabled
   (c.f. #497)
2019-09-30 11:55:51 +02:00
Steffen Jaeckel
d4b8d9b507 fix scan-build error 2019-09-30 11:55:51 +02:00
Steffen Jaeckel
9416a88468 install libtool-bin 2019-09-30 11:55:49 +02:00
Steffen Jaeckel
e4dd30af54 run tests on bionic 2019-09-30 11:54:07 +02:00
Steffen Jaeckel
4458e91151 be more strict when searching scan-build-*
clang-9 brings `scan-build-py-9` which matched the old pattern
2019-09-30 11:54:03 +02:00
Steffen Jaeckel
62bbdecaff use rotate intrinsics if available 2019-09-30 11:35:49 +02:00
Steffen Jaeckel
33dabf9693 only run the standard build in travis PR's
all the other builds are only get built, the testrun is skipped
2019-09-30 11:35:49 +02:00
Steffen Jaeckel
e2f5d17dcc test default-build as first 2019-09-30 09:59:59 +02:00
Steffen Jaeckel
6f3a7c9e3e improve GNU Makefiles a bit
* unignore type-limits warning
* add the possibility to do `make V=0 >/dev/null` and still get the
  CFLAGS and LDFLAGS that are used while compilation
2019-09-30 09:59:59 +02:00
Steffen Jaeckel
1e67d81f7b
Merge pull request #498 from libtom/appveyor
Add AppVeyor MSVC builds
2019-09-29 17:33:24 +02:00
Steffen Jaeckel
eaf2c7b6b9 fix build for msvc 2019-09-24 14:09:35 +02:00
Steffen Jaeckel
d25c52b546 add AppVeyor to README 2019-09-24 14:09:35 +02:00
Steffen Jaeckel
b4c6c4c45f also build on appveyor 2019-09-24 13:24:09 +02:00
Steffen Jaeckel
a1f6312416
Merge pull request #493 from jbech-linaro/rijndael_range
check range in _rijndael_ecb_ functions
2019-09-04 13:44:47 +02:00
Joakim Bech
7b4a5c1dcf check range in _rijndael_ecb_ functions
There is no check that the 'skey' structure has been properly
initialized. For example, the skey->rijndael.Nr is assumed to contain a
positive number corresponding to the number of AES rounds to perform. In
_rijndael_ecb_encrypt the skey->rijndael.Nr is subtracted by two, which
can result in an integer underflow if the structure hasn't been
initialized correctly.

By clamping the value for skey->rijndael.Nr into the valid rounds for
AES we can return an error instead of ending up reading outside the
boundaries (of skey->rijndael.eK).

Signed-off-by: Joakim Bech <joakim.bech@linaro.org>
Reported-by: Martijn Bogaard <bogaard@riscure.com>
2019-08-02 10:39:08 +02:00
Steffen Jaeckel
e01e4c5c97
Merge pull request #491 from fperrad/20190610_lint
some linting
2019-06-11 07:55:21 +02:00
Francois Perrad
75d53696c2 remove useless initialization 2019-06-10 23:56:27 +02:00
Steffen Jaeckel
c23f4699fb
Merge pull request #490 from libtom/improve/curve25519
Improve curve25519
2019-06-10 21:53:51 +02:00
Steffen Jaeckel
c971205404 fix clang-tidy warnings: do not use else after return 2019-06-10 12:48:16 +02:00
Steffen Jaeckel
e673906026 fix differing parameter names 2019-06-10 12:48:16 +02:00
Steffen Jaeckel
0b06979b10 prefix tweetnacl crypto_ API 2019-06-10 12:48:16 +02:00
Karel Miko
10056ed540 make crypto_verify_32 static 2019-06-10 12:32:28 +02:00
Karel Miko
1301cc5d2f fix clang-tidy warnings: do not use else after return 2019-06-10 12:31:56 +02:00
Steffen Jaeckel
3da27d71a0 Improve comments&doc
[skip ci]
2019-06-10 03:28:42 +02:00
Steffen Jaeckel
55d6661d48 Update makefiles 2019-06-09 23:20:45 +02:00
Steffen Jaeckel
fef07fd843 add documentation of Curve25519 API 2019-06-09 23:20:45 +02:00
Steffen Jaeckel
e0a9114129 move setting of sig-verification result to crypto_sign_open() 2019-06-09 23:20:45 +02:00
Steffen Jaeckel
0392867678 use shared {ed,x}25519_export() implementation 2019-06-09 23:20:45 +02:00
Steffen Jaeckel
3957c22e28 remove unused code from tweetnacl 2019-06-09 23:20:45 +02:00
Steffen Jaeckel
819656a12f add ed25519_make_key() testcase 2019-06-09 23:20:45 +02:00
Steffen Jaeckel
41731855c9 fix comment 2019-06-09 23:20:45 +02:00
Steffen Jaeckel
e3766e16ca add real pkcs#8 import of Curve25519 private keys 2019-06-09 22:46:57 +02:00
Steffen Jaeckel
8ea0fb1195 rename x25519_set_ku() to x25519_set_key() 2019-06-09 22:46:57 +02:00
Steffen Jaeckel
5d87aa21a5
Merge pull request #364 from libtom/feature/curve25519
Add curve25519
2019-06-09 22:22:39 +02:00
Steffen Jaeckel
47c34b37ef Update makefiles 2019-06-09 20:41:04 +02:00
Steffen Jaeckel
94b894fda9 update tests 2019-06-09 20:41:04 +02:00
Steffen Jaeckel
34196b90b9 add {ed,x}25519_import_x509() 2019-06-09 20:41:04 +02:00
Steffen Jaeckel
54d7c6782b clean-up macros
no need to enable them separately now
2019-06-09 20:41:04 +02:00
Steffen Jaeckel
233f8af490 draft-ietf-curdle-pkix is meanwhile rfc8410 2019-06-09 20:41:02 +02:00
Steffen Jaeckel
fe00be4abc Fix removed oid_st 2019-06-09 20:40:42 +02:00
Steffen Jaeckel
52a24ca3a3 add Curve25519 API 2019-06-09 20:40:40 +02:00
Steffen Jaeckel
59190c4f3c fix warnings & apply required changes 2019-06-09 11:43:54 +02:00
Steffen Jaeckel
a5072b17d5 add new signed datatype 2019-06-09 11:43:54 +02:00
Steffen Jaeckel
5698e0592c remove not required stuff & re-implement crypto_hash() 2019-06-09 11:43:54 +02:00
Steffen Jaeckel
ee11f2d500 add headers & footers 2019-06-09 11:43:54 +02:00
Steffen Jaeckel
85e902bcc0 add tweetnacl.c Version 20140427 2019-06-09 11:43:54 +02:00
Steffen Jaeckel
c600d81e31
Merge pull request #489 from libtom/pr/fix-stringop-truncation
Fix gcc 8.3 warning (stringop-truncation)
2019-06-09 11:40:51 +02:00
Karel Miko
5f09c2c584 Fix gcc 8.3 warning (stringop-truncation) 2019-06-09 11:40:27 +02:00
Steffen Jaeckel
65282c17b5
Merge pull request #488 from libtom/update/ltm
Update ltm
2019-06-09 11:39:19 +02:00
Steffen Jaeckel
7c56243a0f use replacement functions if they're available
we use the fact that in the same move of deprecating those functions,
tommath_class.h also isn't included anymore in tommath.h so those defines
are gone as well and can be used as an indication if the new functions are
available
2019-06-06 15:06:20 +02:00
Steffen Jaeckel
c11287a0ad latest version of ltm deprecated DIGIT_BIT 2019-06-06 15:06:20 +02:00
Steffen Jaeckel
4ed50d8da1
Merge pull request #485 from libtom/minor-fixes
Minor fixes
2019-06-05 09:24:19 +02:00
Steffen Jaeckel
b0bb7c830a fix missing dependencies 2019-06-04 08:50:27 +02:00
Steffen Jaeckel
4b3ef78901 TGTLIBTOOL wasn't always defined 2019-06-04 08:50:27 +02:00
Steffen Jaeckel
061237e6b1
Merge pull request #484 from fperrad/20190603_indent
fix indentation
2019-06-03 09:31:01 +02:00
Francois Perrad
b40cc35c2d fix indentation 2019-06-03 04:18:53 +02:00
Steffen Jaeckel
e9b2277a49
Merge pull request #483 from libtom/improve/x509
Improve/x509
2019-06-02 22:19:43 +02:00
Steffen Jaeckel
f6299995f8 update ecc_import_x509() 2019-05-27 10:05:11 +02:00
Steffen Jaeckel
21fa9cd92e Update makefiles 2019-05-27 10:05:11 +02:00
Steffen Jaeckel
dfa5258db5 update rsa_import_x509() 2019-05-27 10:05:11 +02:00
Steffen Jaeckel
5119e71023 add x509_decode_public_key_from_certificate() 2019-05-27 10:05:11 +02:00
Steffen Jaeckel
c28a8495d2
Merge pull request #481 from RektInator/develop
fixed compile issue on msvc++
2019-05-08 17:19:56 +02:00
Micky Langeveld
596e9a65e6 fixed compile issue on msvc++ 2019-04-18 09:22:38 +02:00
Steffen Jaeckel
e8afa13d5c
Merge pull request #476 from libtom/fix/474
Fix issue #474
2019-04-10 17:05:59 +02:00
Steffen Jaeckel
19e7f73948 fix scan-build warnings 2019-04-10 11:26:33 +02:00
Steffen Jaeckel
99fcbea2a2 don't error-out if no MPI is available 2019-04-10 11:26:33 +02:00
Steffen Jaeckel
a72aa2fc14 try to make travis job error-out if first build fails 2019-04-10 11:26:33 +02:00
Steffen Jaeckel
a76c823992 fix unused-function _sha256() in xsalsa20_test.c 2019-04-10 11:26:32 +02:00
Steffen Jaeckel
5f7feeab59 fix build
* LDFLAGS were missing when building the demo's
* change how CFLAGS and EXTRALIBS are passed
* also use EXTRALIBS when running testbuild.sh
2019-04-10 11:26:32 +02:00
Steffen Jaeckel
1bfde18513 FIPS 186.4 compliant usage of ltm mp_prime_is_prime() 2019-04-10 11:26:32 +02:00
Steffen Jaeckel
5ed32b73e6 improve ecc_test() output 2019-04-10 11:26:32 +02:00
Steffen Jaeckel
27d09b6104 also provide LTC_NORETURN for msvc 2019-04-10 09:17:50 +02:00
Steffen Jaeckel
a9ff2d0dac fixup meta_builds.sh after 798d7dc61f 2019-01-02 23:30:00 +01:00
Steffen Jaeckel
d58103d54f oops, NORETURN isn't only used in crypt_argchk() 2019-01-02 22:22:34 +01:00
Steffen Jaeckel
ee13f6ffec let ssh_test() NOP silently 2018-12-31 17:22:28 +01:00
Steffen Jaeckel
912f6da757 add some more builds to travis 2018-12-29 22:37:50 +01:00
Steffen Jaeckel
b7874c5864 fix warnings when using other ARGTYPE's 2018-12-29 22:37:09 +01:00
Steffen Jaeckel
798d7dc61f turn around static and dynamic build-options in travis recipe 2018-12-29 18:09:33 +01:00
Steffen Jaeckel
252a172c08 SSH requires MPI funtionality 2018-12-29 18:08:46 +01:00
Steffen Jaeckel
f95be00582 unconditonally create ssh_test() 2018-12-29 18:08:31 +01:00
Steffen Jaeckel
f6f70aa2ec fix ssh tests when compiled w/o MPI provider 2018-12-29 18:08:07 +01:00
Steffen Jaeckel
4b448d29a2 fix warnings on ARGTYPE=3 2018-12-29 18:02:42 +01:00
Steffen Jaeckel
01c455c3d5
Merge pull request #473 from libtom/fixup/padding_pad
fix compilation of padding_pad
2018-12-17 15:44:02 +01:00
Jordan Hrycaj
11ee9683e7 fix compilation of padding_pad
... in cases where rng_get_bytes() isn't available
2018-12-17 13:28:47 +01:00
karel-m
d432b13139
Merge pull request #465 from libtom/pr/ecc-test-cleanup
ecc_test cleanup
2018-11-07 13:35:57 +01:00
Karel Miko
ae2ab2083b ecc_test cleanup 2018-11-07 09:25:08 +01:00
Karel Miko
0de6fa3084 Update makefiles 2018-11-07 09:15:34 +01:00
karel-m
3fa462a7f0
Merge pull request #464 from fperrad/20181029_indent
fix indentation
2018-10-29 20:33:05 +01:00
Francois Perrad
acf3fcda84 fix indentation 2018-10-29 18:56:02 +01:00
karel-m
f413335b2a
Merge pull request #463 from libtom/pr/ssh-decode-encode-fix
Avoid using LOAD32H/STORE32H with unsigned long
2018-10-29 13:04:52 +01:00
Karel Miko
09d116da87 avoid using LOAD32H/STORE32H with unsigned long 2018-10-29 11:28:07 +01:00
karel-m
62cd87342e
Merge pull request #451 from libtom/pr/wycheproof-gcm
Wycheproof failing GCM test - invalid/modified tag
2018-10-29 07:28:56 +01:00
Karel Miko
7d8567695b update doc - chacha20poly1305_memory + gcm_memory 2018-10-29 07:28:18 +01:00
Karel Miko
9a1131da14 add tag validation to chacha20poly1305_memory in decrypt mode 2018-10-29 07:28:18 +01:00
Karel Miko
fd4d8fbc05 add tag validation to gcm_memory in decrypt mode 2018-10-29 07:28:18 +01:00
Karel Miko
27c472654c fix chacha20poly1305 encrypt/decrypt empty pt/ct 2018-10-29 07:28:18 +01:00
Karel Miko
2599618ca6 wycheproof failing test - invalid/modified tag 2018-10-29 07:28:18 +01:00
karel-m
60eb5d0591
Merge pull request #454 from libtom/pr/wycheproof-padding
Wycheproof failing PKCS7 depadding test
2018-10-29 07:27:26 +01:00
Karel Miko
dee704d063 padding_depad + PKCS7 - reject invalid pad 0 2018-10-29 07:26:40 +01:00
Karel Miko
2adc261612 wycheproof failing PKCS7 depadding test 2018-10-29 07:26:40 +01:00
karel-m
332f66dfbe
Merge pull request #452 from libtom/pr/wycheproof-ccm
Wycheproof failing CCM test - invalid tag len
2018-10-29 07:25:55 +01:00
Steffen Jaeckel
9a0df8d936 fix scan-build 2018-10-27 10:50:27 +02:00
Steffen Jaeckel
ac5192cf56 update CCM tv's and tv generation 2018-10-27 10:50:27 +02:00
Karel Miko
890c1a8dad fix - CCM invalid tag len 2018-10-27 10:50:27 +02:00
Karel Miko
93c676ccd8 wycheproof failing CCM test - invalid tag len 2018-10-27 10:50:27 +02:00
karel-m
983fd25e40
Merge pull request #459 from libtom/pr/copy_or_zeromem
Avoid LTC_ARGCHK in void functions
2018-10-27 10:46:53 +02:00
Karel Miko
058a7e2c4e properly use LTC_ARGCHKVD in void function 2018-10-26 19:35:06 +02:00
Steffen Jaeckel
99f9181f67
Merge pull request #456 from dinamicoplus/patch-1
Fix RSA Encryption Example
2018-10-25 16:42:54 +02:00
Marcos Brito
be29591812
Fix RSA Encryption Example
RSA Encryption Example is missing a closing comment bracket */
2018-10-25 16:34:45 +02:00
Karel Miko
9c0d708523 fix typo pkcs7_depad > padding_depad [skip-ci] 2018-10-15 10:51:17 +02:00
karel-m
fba6ae3ed7
Merge pull request #447 from libtom/pr/ecc-LTC_ECCSIG_RFC7518_RELAXED
Make LTC_ECCSIG_RFC7518 strict (again)
2018-10-13 18:50:48 +02:00
Karel Miko
c2cdaaab4d make LTC_ECCSIG_RFC7518 strict (again) 2018-10-13 18:48:49 +02:00
karel-m
dec99ed99c
Merge pull request #438 from rmw42/feature/ssh-ecdsa
LTC_ECCSIG_RFC5656 SSH+ECDSA signature format
2018-10-13 17:51:29 +02:00
Russ Williams
4ee5bfc013 GCC 4.8 -Wmaybe-uninitialized is *really* dumb 2018-10-12 10:22:10 +01:00
Russ Williams
7c4d7cb610 Fixes suggested by Matt Johnston 2018-10-12 10:22:10 +01:00
Russ Williams
9706aa62a7 Update makefiles 2018-10-12 10:22:10 +01:00
Russ Williams
b4b50cc0c6 Initial commit of SSH+ECDSA signature format
Wrap signature format in #ifdef LTC_SSH
Update docs
Code review fixes
Replace strcmp/memcmp with XSTRCMP/XMEMCMP for check-source
Fix for check-defines
XSTRCMP/XMEMCMP != 0
GCC7.3 wants only literal strings for sprintf format
Code review changes
Rework SSH decoding and tests
Fix encoding and tests
COMPARE_TESTVECTOR macro
Single return point in ssh_decode_sequence_multi
Actually use XSTRNCPY rather than just defining it
More code review fixes
Code review tweaks
Ensure it's not possible to read past buffer end
Keep track of size remaining, not end pointer
2018-10-12 10:22:10 +01:00
Steffen Jaeckel
2e7c194322
Merge pull request #445 from fperrad/20181007_lint
pbes: some linting
2018-10-08 15:34:49 +02:00
Francois Perrad
a381957846 more const 2018-10-07 14:52:43 +02:00
Francois Perrad
bd767a3116 fix condition 2018-10-07 14:52:36 +02:00
Francois Perrad
46bb470aaa remove useless initialization 2018-10-07 14:52:16 +02:00
Steffen Jaeckel
838feac7c6
Merge pull request #404 from libtom/pr/pkcs8-improved
Improved pkcs8 support
2018-10-07 11:40:30 +02:00
Steffen Jaeckel
a55e7caa48 fix missing handling of optional keyLength in PBKDF2-params 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
f81bdc46e7 add more rsa-pkcs8 PBES2-RC2 test-files 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
c96639bef6 add rsa-pkcs8 PBES2 AES and SHA512-224/256 test-files 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
cbe65fe59a add rsa-pkcs8 PBE-SHA1-3DES test-file 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
8fabca6171 merge duplicated tables into separate chapter
[skip ci]
2018-10-06 23:04:51 +02:00
Karel Miko
14b09138a9 doc update
[skip ci]
2018-10-06 23:04:51 +02:00
Karel Miko
8349eda5a5 fix LTC_EASY test failure 2018-10-06 23:04:51 +02:00
Karel Miko
e5a2683f5b RSA - pkcs8 test keys 2018-10-06 23:04:51 +02:00
Karel Miko
2dd8bcdfe9 rsa_import_pkcs8 tests 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
7af942a66b use pkcs8_decode_flexi() in rsa_import_pkcs8() 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
52c5473a13 use pkcs8_decode_flexi() in ecc_import_pkcs8() 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
bc673c2853 implement pkcs8_decode_flexi() 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
a2ec37b93c refactor PBES into separate modules 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
aac1e592b4 Update makefiles 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
0af0033390 add empty der_decode_pkcs8_flexi.c 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
362e0c9284 add pk_oid_cmp_with_ulong() 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
4abd84b7c3 Update makefiles 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
3d6a49a64b rename pk_oid_asn1.c to pk_oid_cmp.c 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
498a534b9c Update makefiles 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
97d1c17c8d add empty pbes files 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
6bdfa7c428 add _der_flexi_sequence_cmp() 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
c56053870a pkcs#8 support for aes and reduced sha512 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
36d603e3d2 re-factor ecc_import_pkcs8() 2018-10-06 23:04:51 +02:00
Karel Miko
3c9d2ebc5e clang-tidy fix misc-suspicious-string-compare 2018-10-06 23:04:51 +02:00
Karel Miko
e29fecde12 use ecc_find_curve + ecc_set_curve 2018-10-06 23:04:51 +02:00
Karel Miko
8207a6a1c4 use pkcs12_kdf + pkcs12_utf8_to_utf16 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
c4642bacf0 mark fall-through in switch-case to calm linter 2018-10-06 23:04:51 +02:00
Steffen Jaeckel
93e758a82e introduce LTC_ASN1_IS_TYPE() 2018-10-06 23:04:51 +02:00
Karel Miko
bf04bf18a4 add ecc_import_pkcs8 2018-10-06 23:04:51 +02:00
Karel Miko
7529e02b96 Update makefiles 2018-10-06 23:04:51 +02:00
karel-m
223ece7f6d
Merge pull request #443 from libtom/pr/ecc-verify-was-too-strict
Less strict ecc_verify_hash_ex (as it was before ecc_recover_key)
2018-10-05 12:32:49 +02:00
Karel Miko
59bc3b5885 make ecc_verify_hash_ex less strict (as it was before ecc_recover_key addition) 2018-10-05 07:44:15 +02:00
karel-m
4d6f973b2d
Merge pull request #444 from libtom/pr/fix-unused-macros
Remove unused macros
2018-10-05 07:05:29 +02:00
Karel Miko
ef20f2e656 remove unused macros 2018-10-04 23:29:12 +02:00
karel-m
0157bef943
Merge pull request #442 from libtom/pr/ltc-byte
Rename macro 'byte' to 'LTC_BYTE'
2018-10-04 19:52:34 +02:00
Karel Miko
bb5ea12d0b move LTC_BYTE macro from tomcrypt_macros.h to tomcrypt_private.h 2018-10-04 17:21:58 +02:00
Karel Miko
1bbbc60d06 rename macro byte >> LTC_BYTE - related to #439 2018-10-04 17:20:47 +02:00
Steffen Jaeckel
c5e4679b7a
Merge pull request #436 from rmw42/feature/ecrecover
Implement ecc_recover_key to recover public key from hash+signature
2018-09-30 16:28:22 +02:00
Russ Williams
88d9b6db26 Make ECC signature format explicit
Optionally return recovery ID from ecc_sign_hash()

Update documentation

Update tests for ECC recovery

Fix (v,r,s) signature format, regenerate recovery test

Fix over-freeing of private key

Code review fixes to docs

Rename LTC_ECCSIG_BLOCKCHAIN to LTC_ECCSIG_ETH to reflect original definition

Rename to LTC_ECCSIG_ETH27 to make clear it's using the Ethereum +27 convention

Code review changes - calculate recovery ID only if needed, type safety on signature format enum

Use enum for sigformat in docs, and add explanatory note for recid<0

Range checks on v, check RFC7518 signatures' length based on size of key. Fix for when order>prime.

Limit LET_ECCSIG_ETH27 to secp256k1 curve only
2018-09-29 21:07:41 +01:00
Russ Williams
57781c7acd Update makefiles 2018-09-23 09:03:30 +01:00
Russ Williams
76190521e3 Implementation of ecc_recover_key to obtain public key from hash+signature
Workaround for TFM missing sqrtmod_prime

Fix unused variable warnings with USE_TFM, make TomsFastMath a runtime check

Disable ecc_recover_key if no ecc_mul2add available

Wrap ecc_recover_key and its test in #ifdef LTC_ECC_SHAMIR

Fix unused variables when built without LTC_ECC_SHAMIR

Code review tweaks

Code review tweaks - remove sigformat, tidy up (de)allocation

Code review tweaks
2018-09-23 09:03:30 +01:00
Larry Bugbee
b44155fdb0
Merge pull request #431 from libtom/streams-add-single-call-crypt-functions
Streams - add single call crypt functions
2018-09-21 12:03:36 -07:00
buggywhip
a2b343b2d0 streams-add-single-call-crypt-functions
fix mixed declarations and code

add _memory chacha_ivctr32() test
2018-09-10 02:21:09 -07:00
buggywhip
305a589d64 update makefiles 2018-09-10 02:21:09 -07:00
Steffen Jaeckel
e77ad636e7
Merge pull request #435 from fperrad/20180907_lint
some lintings
2018-09-08 17:00:54 +02:00
Francois Perrad
9d9718e56b remove useless initialization 2018-09-08 11:49:36 +02:00
Francois Perrad
698790fdeb explicit condition 2018-09-07 17:06:09 +02:00
Steffen Jaeckel
e5f56d4617
Merge pull request #429 from libtom/rework/oid
Remove oid_st
2018-09-07 16:49:25 +02:00
Steffen Jaeckel
fb7b8799cd rename enum public_key_algorithms to something more generic 2018-09-07 11:58:54 +02:00
Steffen Jaeckel
4cf2e80346 remove oid_st 2018-09-07 11:58:54 +02:00
Steffen Jaeckel
af23fdd1c2 Update makefiles 2018-09-07 11:58:54 +02:00
Steffen Jaeckel
645460a5d5 add pk_oid_cmp_with_asn1() 2018-09-07 11:58:54 +02:00
Steffen Jaeckel
e318f6f1e3 re-work pk_oid_str functions a bit 2018-09-07 11:58:54 +02:00
Steffen Jaeckel
1a90da844c only print der flexi-test on higher debug level
it's smashing the stack for some inputs :>
2018-09-07 11:58:54 +02:00
Steffen Jaeckel
caff4cea40 change pk_get_oid() to return a string 2018-09-07 11:58:54 +02:00
Steffen Jaeckel
41599db904 Update makefiles 2018-09-07 11:58:54 +02:00
Steffen Jaeckel
fdc97f8648 move oid functions to own folder 2018-09-07 11:58:54 +02:00
Steffen Jaeckel
86ff14100f
Merge pull request #430 from libtom/fix/oid-decode
Fix OID issues
2018-09-07 11:57:38 +02:00
Steffen Jaeckel
2e9c80cbc1 fix der_length_object_identifier()
... there are only three root nodes

As of X6.90 Ch. 8.19.4: "NOTE – This packing of the first two
object identifier components recognizes that only three values
are allocated from the root node..."
2018-09-07 08:24:25 +02:00
Steffen Jaeckel
6584569872 add another OID testcase for root-node 3 2018-09-07 08:24:25 +02:00
Steffen Jaeckel
4ffdb915f0 fix der_decode_object_identifier() 2018-09-07 08:24:25 +02:00
Steffen Jaeckel
079ed04b17 add OID testcase from x.690 2018-09-07 08:24:25 +02:00
Steffen Jaeckel
bd542c6c30
Merge pull request #433 from orbea/rlibtool
makefile.shared: Support rlibtool.
2018-09-07 08:24:03 +02:00
orbea
ccc18b9eda makefile.shared: Support rlibtool.
When building libtomcrypt with rlibtool instead of libtool it will fail
when rlibtool fails to parse the generated libtool which does not exist.

Since rlibtool should be the default choice for most slibtool users in
the future this patch will use slibtool-shared instead which will
correctly build the shared library.

This could also help build the shared library on additional targets and
hosts where the stock libtool does not have shared libraries enabled.
2018-09-06 18:19:10 +02:00
Steffen Jaeckel
c9c3c42739 Merge branch 'streams-make_state_names_consistent' into develop
This fixes #427
2018-07-10 07:11:39 +02:00
buggywhip
380d1d2452 streams-make_state_names_consistent 2018-07-09 17:31:24 -07:00
karel-m
c9376c29ba
Merge pull request #428 from libtom/pr/fix-gcc-warnings1
fix -Wmissing-declarations -Wmissing-prototypes -Wmissing-noreturn
2018-07-09 11:32:35 +02:00
Karel Miko
ba8fa04f9a reorganize ifdefs in tv_gen 2018-07-08 21:59:06 +02:00
Karel Miko
4fb0562a3b fix -Wmissing-declarations -Wmissing-prototypes -Wmissing-noreturn 2018-07-07 19:54:08 +02:00
Steffen Jaeckel
b5009d704c
Merge pull request #426 from libtom/feature/pkcs12
Feature/pkcs12
2018-07-06 18:37:54 +02:00
Steffen Jaeckel
53fc5694c9 re-work pkcs12 a bit 2018-07-06 18:26:43 +02:00
Steffen Jaeckel
6fe1b5b765 Update makefiles 2018-07-06 18:26:43 +02:00
Karel Miko
a96997dd29 add pkcs12_utf8_to_utf16() 2018-07-06 18:26:43 +02:00
Karel Miko
b3f483a204 add pkcs12_kdf() 2018-07-06 18:26:43 +02:00
karel-m
98ad88b3ee
Merge pull request #422 from libtom/pr/clang-tidy-google-readability-braces-around-statements
fix clang-tidy warning: google-readability-braces-around-statements
2018-07-06 17:53:12 +02:00
Karel Miko
a3dab04074 fix clang-tidy warning: google-readability-braces-around-statements 2018-07-06 13:58:15 +02:00
karel-m
e02694cfc2
Merge pull request #393 from libtom/pr/ecc-doc-update
ECC doc update
2018-07-06 13:44:17 +02:00
Karel Miko
4f3bce103f move ecc_make_key_ex to Legacy Key Generation
[skip ci]
2018-07-06 13:42:54 +02:00
Karel Miko
b30c27066d new names: ecc_find_curve, ecc_set_curve 2018-07-06 13:42:38 +02:00
Steffen Jaeckel
415c19b8df re-work ECC docs a bit
[skip ci]
2018-07-06 13:42:38 +02:00
Karel Miko
57c884d50d ECC doc update
[skip ci]
2018-07-06 13:42:38 +02:00
karel-m
d3c5890a1b
Merge pull request #423 from libtom/pr/ecc_set_dp--ecc_set_curve
rename ecc_set_dp >> ecc_set_curve + ecc_get_curve >> ecc_find_curve
2018-07-06 13:39:51 +02:00
Karel Miko
4bec98f88c rename ecc_get_curve to ecc_find_curve 2018-07-04 10:43:15 +02:00
Karel Miko
611ca6bf14 rename ecc_set_dp (+related) to ecc_set_curve 2018-07-04 10:41:10 +02:00
Karel Miko
091d52828c Update makefiles 2018-07-04 10:41:02 +02:00
karel-m
4473953742
Merge pull request #415 from libtom/pr/clang-tidy-else-after-return
fix clang-tidy warning: readability-else-after-return
2018-07-03 22:45:28 +02:00
Karel Miko
ed2ec2e3ed add script .ci/clang-tidy.sh 2018-07-03 22:43:26 +02:00
Karel Miko
22b764ec85 fix clang-tidy warning: readability-else-after-return 2018-07-03 22:42:15 +02:00
karel-m
6ac6d36bf4
Merge pull request #416 from libtom/pr/clang-tidy-readability-non-const-parameter
fix clang-tidy warning: readability-non-const-parameter
2018-07-03 22:37:34 +02:00
Karel Miko
ae6aa3dd86 fix clang-tidy warning: readability-non-const-parameter 2018-07-03 22:37:05 +02:00
karel-m
48ad48f900
Merge pull request #417 from libtom/pr/clang-tidy-readability-inconsistent-declaration-parameter-name
fix clang-tidy warning: inconsistent-declaration-parameter-name
2018-07-03 22:35:56 +02:00
Karel Miko
12c3091077 fix clang-tidy warning: readability-inconsistent-declaration-parameter-name - issue #376 2018-07-03 22:33:48 +02:00
karel-m
168f3bd1db
Merge pull request #421 from libtom/pr/tests-cosmetics
fix "make test" built with no math provider or multiple providers
2018-07-03 22:30:41 +02:00
Karel Miko
fc056a645d fix "make test" built with no math provider or multiple providers 2018-07-03 00:12:08 +02:00
Steffen Jaeckel
3fb0eea01b show in SCRYPT etc. that we're on develop 2018-07-02 23:25:20 +02:00
Steffen Jaeckel
215ec5f69d Merge tag 'v1.18.2' into develop
libtomcrypt v1.18.2
2018-07-02 23:23:47 +02:00
Steffen Jaeckel
7e7eb695d5 Merge branch 'release/1.18.2' 2018-07-01 22:49:01 +02:00
Steffen Jaeckel
a015a8f05f don't install test in target install_all
This fixes #396
2018-07-01 22:47:05 +02:00
Steffen Jaeckel
54e6db588a Bump version 2018-07-01 12:51:54 +02:00
Steffen Jaeckel
788a0463b9 Update changes
[skip ci]
2018-06-22 14:25:34 +02:00
Steffen Jaeckel
bf5ad76c28 Merge pull request #414 from libtom/fix/411
Fix/411
(cherry picked from commit 8972027b46)
2018-06-22 11:33:54 +02:00
Steffen Jaeckel
8972027b46
Merge pull request #414 from libtom/fix/411
Fix/411
2018-06-22 11:33:14 +02:00
Steffen Jaeckel
73426f4b26 fix constants and sizes demos 2018-06-22 10:10:23 +02:00
Steffen Jaeckel
ecfe5882ac re-factor crypt_list_all_sizes() 2018-06-22 10:10:23 +02:00
Steffen Jaeckel
8bc889cd64 re-factor crypt_list_all_constants() 2018-06-22 10:10:23 +02:00
Steffen Jaeckel
07b626d7a1 fix-up 250eced904 2018-06-22 02:05:03 +02:00
Steffen Jaeckel
11bdffcf05 fix-up 719d297e9f 2018-06-22 00:31:44 +02:00
karel-m
250eced904 Merge pull request #408 from libtom/pr/fix-cve-2018-12437
ecc_sign_hash blinding CVE-2018-12437
(cherry picked from commit 6aef5e3765)
2018-06-22 00:17:24 +02:00
Steffen Jaeckel
927b196210
Merge pull request #406 from libtom/remove-sosemanuk_setup()-"NOP"
Sosemanuk - remove what is effectively a NOP
2018-06-19 11:45:38 +02:00
Steffen Jaeckel
fd6535c74b remove lying comment 2018-06-19 11:45:13 +02:00
Larry Bugbee
6cfa1fcad7 remove what is effectively a NOP
prior return stmt was a failed attempt to initialize the remaining bytes of the state which is also negated by the policy of enforcing a call to sosemanuk_setiv() before calling sosemanuk_crypt().
2018-06-19 11:44:04 +02:00
karel-m
6aef5e3765
Merge pull request #408 from libtom/pr/fix-cve-2018-12437
ecc_sign_hash blinding CVE-2018-12437
2018-06-19 09:30:51 +02:00
Karel Miko
f0a51bbdbd ecc_sign_hash blinding CVE-2018-12437 2018-06-17 12:54:01 +02:00
Steffen Jaeckel
b7873025b7
Merge pull request #405 from libtom/pr/fix-ecc_import_openssl
fix ecc_import_openssl - bin_seed size
2018-06-12 08:17:48 +02:00
Karel Miko
5efbddc3f4 fix ecc_import_openssl - bin_seed size 2018-06-12 00:00:11 +02:00
Steffen Jaeckel
6238b6381f
Merge pull request #187 from libtom/pr/ecc-asn1-part
ECC-step3: extra import/export (ASN.1 related)
2018-06-11 19:13:21 +02:00
Steffen Jaeckel
4f36e03970 re-factor ecc_import_openssl()
... into several smaller functions
2018-06-11 10:00:37 +02:00
Karel Miko
05d397d634 ECC improved import/export 2018-06-11 10:00:37 +02:00
Karel Miko
abedfa17eb Update makefiles 2018-06-11 10:00:37 +02:00
karel-m
d11a1a7f06
Merge pull request #402 from libtom/pr/fix-ecc_set_key
fix ecc_set_key - no check of private key input buffer size
2018-06-10 19:06:24 +02:00
Karel Miko
70d800f6b3 fix ecc_set_key - no check of private key input buffer size 2018-06-10 17:30:00 +02:00
karel-m
504396764e
Merge pull request #401 from libtom/pr/fix-der_length_custom_type
fix der_length_custom_type - incorrect length of length
2018-06-10 17:27:54 +02:00
Karel Miko
ac1622e042 fix der_length_custom_type - incorrect length of length 2018-06-05 16:39:38 +02:00
karel-m
a8d0442bd3
Merge pull request #400 from libtom/pr/avoid-anonymous-union
avoid anonymous union
2018-06-04 11:49:23 +02:00
Karel Miko
5834223db5 avoid anonymous union (which is not supported by some compilers) 2018-06-04 08:56:29 +02:00
karel-m
10355675a9
Merge pull request #398 from libtom/improve/base16_api
Improve base16 api
2018-06-04 08:55:07 +02:00
Steffen Jaeckel
06c0606da2 generalize caps argument of base16_encode()
probably we want to add more options in the future

I could think of support for some options of `xxd` resp. `hexdump`
2018-06-03 20:50:06 +02:00
Steffen Jaeckel
a1341e028e fix doxygen warning 2018-06-03 20:50:06 +02:00
Steffen Jaeckel
c315b1c3b7
Merge pull request #399 from libtom/remove/katja
Remove katja
2018-06-03 20:49:48 +02:00
Steffen Jaeckel
f8ed30bc22 Update makefiles 2018-06-03 19:19:58 +02:00
Steffen Jaeckel
d9215be060 Remove katja 2018-06-03 19:19:58 +02:00
Steffen Jaeckel
e31e757a86 fix build of crypt.pdf 2018-06-03 17:48:48 +02:00
Steffen Jaeckel
55fbe256ad
Merge pull request #395 from libtom/feature/private_header
Add a new header file for private functions
2018-06-03 17:48:30 +02:00
Steffen Jaeckel
c725be276a add blake2-hash API documentation 2018-06-03 15:07:28 +02:00
Steffen Jaeckel
d752f90d18 fix Doxygen docs 2018-06-03 15:07:28 +02:00
Steffen Jaeckel
7cfc0c93e6 use tomcrypt_private.h 2018-06-03 15:07:28 +02:00
Steffen Jaeckel
2cb77edf4c update makefiles etc. for tomcrypt_private.h 2018-06-03 15:07:27 +02:00
Steffen Jaeckel
f55039bfeb add tomcrypt_private.h 2018-06-03 15:07:27 +02:00
Steffen Jaeckel
5d8f35e5ed
Merge pull request #397 from fperrad/20180601_lint
xsalsa20: some linting
2018-06-02 12:16:01 +02:00
Francois Perrad
57bffbaa82 remove useless initialization 2018-06-01 21:05:49 +02:00
Francois Perrad
772a9e68cf make _sha256 a static function 2018-06-01 21:05:47 +02:00
Steffen Jaeckel
b7493253ea fix misplaced #endif 2018-06-01 14:47:19 +02:00
Karel Miko
7f6a4e1ff1 fix chmod 2018-06-01 10:07:17 +02:00
Larry Bugbee
82ac9a2275
Merge pull request #387 from libtom/add_xsalsa20
Add XSalsa20
2018-05-31 16:42:08 -07:00
buggywhip
8144209695 add XSalsa20 2018-05-31 11:58:21 -07:00
buggywhip
2ffcd1706e update makefiles 2018-05-31 11:58:08 -07:00
Steffen Jaeckel
94132324a9 fix testvectors for two-key 3des
(cherry picked from commit e4a03ca72a)
2018-05-31 14:18:44 +02:00
Steffen Jaeckel
4c2ae4758e fix "two-key 3des"-related things
(cherry picked from commit 715103a203)
2018-05-31 14:18:44 +02:00
Steffen Jaeckel
615b361673 no need to include wchar.h in all cases
(cherry picked from commit a32d1afd10)
2018-05-31 14:18:44 +02:00
Steffen Jaeckel
4c2bb90dec Merge pull request #382 from ararslan/aa/freebsd
Make the build logic more robust for BSD systems
(cherry picked from commit 5ab8dcf04d)
2018-05-31 14:18:13 +02:00
Steffen Jaeckel
e7f4c6e47f Merge pull request #392 from orbea/libtool
makefile.shared: Respect LIBTOOL.
(cherry picked from commit a528528a2b)
2018-05-31 14:18:01 +02:00
Steffen Jaeckel
3d6181d0a7 there should be no need to pass CFLAGS when linking
(cherry picked from commit 196f25e32f)
2018-05-31 14:16:54 +02:00
Steffen Jaeckel
5ab8dcf04d
Merge pull request #382 from ararslan/aa/freebsd
Make the build logic more robust for BSD systems
2018-05-31 13:51:54 +02:00
Alex Arslan
f5c665b9f6
Make the build logic more robust for BSD systems
This properly sets MAKE (when undefined) on BSDs to gmake rather than
make, which refers to the incompatible BSD Make. Further, it betters
detection of Clang as the default compiler, which is the case on FreeBSD
11.0+ and OpenBSD 6.0+.
2018-05-29 14:05:41 -07:00
karel-m
a94b02be94
Merge pull request #390 from libtom/fixes/and/improvements
Fixes and improvements
2018-05-24 17:08:28 +02:00
Steffen Jaeckel
e4a03ca72a fix testvectors for two-key 3des 2018-05-23 10:33:47 +02:00
Steffen Jaeckel
0011f7f927 add generic test_process_dir() 2018-05-23 10:33:47 +02:00
Steffen Jaeckel
715103a203 fix "two-key 3des"-related things 2018-05-23 10:33:47 +02:00
Steffen Jaeckel
a32d1afd10 no need to include wchar.h in all cases 2018-05-23 10:33:47 +02:00
karel-m
fe665c5246
Merge pull request #236 from libtom/pr/ecc-non-asn1-part
ECC curves y^2 = x^3 + ax + b
2018-05-23 09:30:39 +02:00
Karel Miko
24c0eb84f9 ECC curves y^2 = x^3 + ax + b 2018-05-22 23:02:44 +02:00
Karel Miko
ea32b2b194 Update makefiles 2018-05-22 23:02:44 +02:00
Steffen Jaeckel
a528528a2b
Merge pull request #392 from orbea/libtool
makefile.shared: Respect LIBTOOL.
2018-05-20 10:29:56 +02:00
orbea
f2918866bc makefile.shared: Respect LIBTOOL. 2018-05-19 08:36:41 -07:00
karel-m
b0c098e9c0
Merge pull request #389 from libtom/pr/avoid-exit
avoid calling exit() in sosemanuk_setup
2018-05-07 08:18:32 +02:00
Karel Miko
cdc256258a avoid calling exit() in sosemanuk_setup 2018-05-06 22:47:06 +02:00
karel-m
49001f01b3
Merge pull request #383 from libtom/pr/fortuna-fix
new fortuna: fix getting current time
2018-05-05 17:59:26 +02:00
Karel Miko
29af2d95cc fix getting current time on MS Windows + improve gettimeofday/clock_gettime usage on UNIX 2018-05-04 16:42:47 +02:00
Karel Miko
a8aa207381 change fortuna_prng.wd to ulong64 2018-05-04 16:42:47 +02:00
Karel Miko
d2ba3c93f6 introducing LTC_CLOCK_GETTIME macro 2018-05-04 16:42:47 +02:00
karel-m
73465cfb95
Merge pull request #388 from libtom/pr/check-all
do --check-all in check_source.sh
2018-05-04 16:42:02 +02:00
Karel Miko
41341195c5 do --check-all in check_source.sh 2018-05-04 12:48:42 +02:00
karel-m
c2548bf190
Merge pull request #386 from libtom/pr/fix-issue-384
fix #384 "const" related warnings
2018-05-04 07:17:52 +02:00
Karel Miko
11e15eaaa7 fix #384 "const" related warnings 2018-05-03 12:32:32 +02:00
karel-m
d16e5b0b05 Merge pull request #379 from libtom/pr/clang-tidy-misc-misplaced-widening-cast
clang-tidy: misc-misplaced-widening-cast
(cherry picked from commit 248352c36f)

With back-ported patch from src/misc/copy_or_zeromem.c back to
src/encauth/ccm/ccm_memory.c
2018-04-13 09:56:43 +02:00
karel-m
00dfe66081 Merge pull request #378 from libtom/pr/clang-tidy-misc-suspicious-string-compare
clang-tidy: misc-suspicious-string-compare
(cherry picked from commit 24f933d22a)
2018-04-13 09:54:03 +02:00
karel-m
1783100e7b Merge pull request #377 from libtom/pr/clang-tidy-void-return
clang-tidy: readability-redundant-control-flow
(cherry picked from commit 4cc8d08e50)
2018-04-13 09:53:59 +02:00
karel-m
92c5082a25 Merge pull request #375 from libtom/pr/fix-unused-const-variable
Fix -Wunused-const-variable in aes_tab.c
(cherry picked from commit 5c31c3d016)
2018-04-13 09:53:59 +02:00
Steffen Jaeckel
719d297e9f Merge pull request #373 from libtom/fix/der-recursion-limit
implement DER recursion limit
(cherry picked from commit af67321bf3)
2018-04-13 09:52:11 +02:00
Steffen Jaeckel
af67321bf3
Merge pull request #373 from libtom/fix/der-recursion-limit
implement DER recursion limit
2018-04-13 09:42:47 +02:00
Steffen Jaeckel
62c2124b82 implement DER resursion limit 2018-04-11 11:15:21 +02:00
Steffen Jaeckel
2e8371ce0b
Merge pull request #381 from felixdoerre/const_hash
add const to the hashes' compress functions
2018-04-11 11:14:49 +02:00
Felix Dörre
332ae41a2b add const to the hashes' compress functions 2018-04-10 13:30:12 +02:00
Steffen Jaeckel
8236ade38e
Merge pull request #363 from libtom/improve/fortuna
Improve Fortuna PRNG
2018-04-10 04:23:19 +02:00
Steffen Jaeckel
c7a880f222 update docs 2018-04-09 23:30:27 +02:00
Steffen Jaeckel
2dfc2d87da make fortuna_update_seed() public
In order to be able to implement UpdateSeedFile from the original paper
this is required to be available on the public API.
2018-04-09 23:30:27 +02:00
Steffen Jaeckel
7b97911cc6 add build with LTC_FORTUNA_RESEED_RATELIMIT_STATIC to travis 2018-04-09 23:30:27 +02:00
Steffen Jaeckel
ca91ae5a1f add fortuna_add_random_event() 2018-04-09 23:30:27 +02:00
Steffen Jaeckel
75dad9473d implement FORTUNA's reseed rate limit based on time 2018-04-09 23:30:27 +02:00
Steffen Jaeckel
1fb478ea31
Merge pull request #324 from TrinityCoder/fix-missing-const-params
Added missing 'const' qualifier to many functions' parameters
2018-04-09 11:58:37 +02:00
Steffen Jaeckel
1c3629fc06 add more missing const 2018-04-09 10:29:29 +02:00
Miroslav Mareš
228d29d1e7 Added missing 'const' qualifier to many functions' parameters 2018-04-09 10:29:29 +02:00
karel-m
248352c36f
Merge pull request #379 from libtom/pr/clang-tidy-misc-misplaced-widening-cast
clang-tidy: misc-misplaced-widening-cast
2018-04-09 08:56:53 +02:00
Karel Miko
7465d0bac3 fix clang-tidy misc-misplaced-widening-cast 2018-04-09 08:56:41 +02:00
karel-m
24f933d22a
Merge pull request #378 from libtom/pr/clang-tidy-misc-suspicious-string-compare
clang-tidy: misc-suspicious-string-compare
2018-04-09 08:55:32 +02:00
Karel Miko
fa01052b32 fix memcmp is called without explicitly comparing result 2018-04-09 08:55:13 +02:00
karel-m
4cc8d08e50
Merge pull request #377 from libtom/pr/clang-tidy-void-return
clang-tidy: readability-redundant-control-flow
2018-04-09 08:53:20 +02:00
Karel Miko
061fe36114 fix redundant return statement at the end of a function with a void return type 2018-04-08 18:04:34 +02:00
karel-m
5c31c3d016
Merge pull request #375 from libtom/pr/fix-unused-const-variable
Fix -Wunused-const-variable in aes_tab.c
2018-04-08 16:22:05 +02:00
Karel Miko
318451ce66 Fix -Wunused-const-variable in aes_tab.c 2018-04-08 14:28:57 +02:00
Steffen Jaeckel
49b3425de7
Merge pull request #374 from libtom/fix/cygwin
fix aesgcm on cygwin
2018-04-08 02:56:20 +02:00
Steffen Jaeckel
3249dcb963 allow TAB_SIZE to be defined at compile-time 2018-04-06 10:27:12 +02:00
Steffen Jaeckel
ba54b891b9 fix aesgcm on cygwin
This fixes #372
2018-04-06 10:19:53 +02:00
Steffen Jaeckel
70ec9b3b35 back-port of the bugfix done in #363 2018-04-04 19:31:36 +02:00
Steffen Jaeckel
24aab18d5b Merge pull request #359 from vchong/ltc_ctr
ltc: ctr: improve performance
(cherry picked from commit 9b80d07487)
2018-04-04 19:27:40 +02:00
Steffen Jaeckel
affb3d70cb improve fortuna_import()
This makes fortuna_import() kinda compliant to the "Update seed file"
behavior of the original paper.
It differs from the original behavior in that it allows to import
seed files which are larger	than 64 bytes.

(cherry picked from commit 39d4a14c29)
2018-04-04 19:25:31 +02:00
Steffen Jaeckel
89dffe6c7e add comment to Fortuna docs
(cherry picked from commit cccd1e3053)
2018-04-04 19:25:31 +02:00
Steffen Jaeckel
415c57f3af don't ignore additional data on SOBER128-PRNG import
(cherry picked from commit d502869728)
2018-04-04 19:25:31 +02:00
Steffen Jaeckel
b9fa4c063a fortuna_import() shouldn't ignore additional input
(cherry picked from commit 0c05e5386f)
2018-04-04 19:25:31 +02:00
Steffen Jaeckel
67d8ca19f5 ensure that fortuna has been seeded properly
(cherry picked from commit 04ce8cf613)
2018-04-04 19:25:31 +02:00
karel-m
243898972c Merge pull request #351 from libtom/pr/fix-time_cipher_lrw
LTC_EASY & time_cipher_lrw
(cherry picked from commit ea5b6cdce9)
2018-04-04 19:19:52 +02:00
Steffen Jaeckel
873240e7a0 Merge pull request #350 from libtom/fix/no-file-warnings
Fix warnings in `XMAC_file()` functions when compiling with `LTC_NO_FILE`.
(cherry picked from commit 11cda2e274)
2018-04-04 19:19:19 +02:00
karel-m
fa759d8ee9
Merge pull request #371 from libtom/pr/baseNN-consistent-nul
consistent NUL byte handling in baseNN_encode
2018-03-28 09:30:56 +02:00
Karel Miko
6d33ecdbf9 consistent NUL byte handling in baseNN_encode 2018-03-28 07:46:31 +02:00
karel-m
ef1fba20b7
Merge pull request #365 from libtom/pr/base64-decode-less-relaxed
Make base64_decode relaxed mode less relaxed
2018-03-27 23:18:15 +02:00
Karel Miko
f0f1283dbb doc - add indexes for base64url_* 2018-03-27 21:06:31 +02:00
Karel Miko
798f257059 fix base64_decode comments 2018-03-27 21:06:31 +02:00
Karel Miko
229aec965c enhanced base64 related tests 2018-03-27 21:06:30 +02:00
Karel Miko
ad8067eaf7 doc for base64_sane_decode 2018-03-27 21:06:30 +02:00
Karel Miko
964f61709f introducing base64_sane_decode 2018-03-27 21:06:30 +02:00
Karel Miko
b10bf8fa0d make base64_decode relaxed mode less relaxed 2018-03-27 21:06:30 +02:00
Steffen Jaeckel
8b6d9dba76
Merge pull request #369 from libtom/demo/aesgcm
Add aesgcm demo
2018-03-27 19:39:13 +02:00
Steffen Jaeckel
e040ef1a59 add aesgcm demo
yeah I know, it's GNU specific, therefore it's also only added to the
GNU makefiles
2018-03-27 14:26:16 +02:00
Steffen Jaeckel
31088c0e9e add gcm_file() and gcm_filehandle() 2018-03-27 14:26:16 +02:00
Steffen Jaeckel
f4afa5d5bb
Merge pull request #368 from libtom/fix/base16-api
Improve base16
2018-03-27 12:58:18 +02:00
Steffen Jaeckel
ed5025398b check input of base16_decode() 2018-03-27 10:08:29 +02:00
Steffen Jaeckel
efbf38adce update docs 2018-03-27 10:08:29 +02:00
Steffen Jaeckel
73e5330c47 add inlen parameter to base16_decode() 2018-03-27 10:08:29 +02:00
Steffen Jaeckel
9b80d07487
Merge pull request #359 from vchong/ltc_ctr
ltc: ctr: improve performance
2018-03-27 02:25:25 +02:00
Steffen Jaeckel
bed9811d74 fix-up ctr_encrypt.c 2018-03-26 23:34:15 +02:00
Tetsuya Yoshizaki
431319f30b ltc: ctr: improve performance
When accel_ctr_encrypt() is not used, accel_ecb_encrypt() is used via
ecb_encrypt() instead. The accel_ecb_encrypt() is frequently called at
every single block process. VFP assembly code called from the
accel_ecb_encrypt() is protected by
tomcrypt_arm_neon_enable()/disable(). FIQ enable/disable and VFP
register save/restore (64bitx32 registers!) to/from memory are done in
the tomcrypt_arm_neon_enable()/disable(). These overhead exist in each
single block process cause the degradation of system performance
eventually. Cases where h/w accelerated AES-CTR did not show any effects
or showed less performance than pure software processing have been
observed.

This patch resolves the issue by increasing utilization rate of
accel_ctr_encrypt().

Signed-off-by: Tetsuya Yoshizaki <yoshizaki.tetsuya@socionext.com>
Signed-off-by: Victor Chong <victor.chong@linaro.org>
2018-03-26 23:29:07 +02:00
karel-m
f240aeadc2
Merge pull request #366 from libtom/pr/base64-char
base64 - use `char *` for Base64 strings
2018-03-26 21:06:43 +02:00
Karel Miko
e73bb36f3f update doc - base64 & char* 2018-03-26 16:42:19 +02:00
Karel Miko
065c89108e base64_* use char * for Base64 strings 2018-03-26 16:42:19 +02:00
karel-m
f72621e276
Merge pull request #367 from libtom/pr/base32-nul
base32_encode - make the output NUL-terminated
2018-03-26 16:41:25 +02:00
Karel Miko
981f3ef844 base32_encode - make the output NUL-terminated 2018-03-25 22:17:46 +02:00
Karel Miko
7a7b773b3c Revert "make base64_decode relaxed mode less relaxed"
This reverts commit e7117ea9df.
2018-03-25 19:41:43 +02:00
Karel Miko
e7117ea9df make base64_decode relaxed mode less relaxed 2018-03-25 15:46:49 +02:00
Steffen Jaeckel
e299431be8
Merge pull request #343 from libtom/feature/pkcs7
Add padding/depadding support
2018-03-25 14:12:35 +02:00
Steffen Jaeckel
bc2739347d Update makefiles 2018-03-23 22:01:41 +01:00
Steffen Jaeckel
daed6fe91e add padding documentation 2018-03-23 22:01:41 +01:00
Steffen Jaeckel
6a48f7d184 add padding tests 2018-03-23 22:01:41 +01:00
Steffen Jaeckel
ea79c5f8b1 use new padding functions in openssl-enc 2018-03-23 22:01:41 +01:00
Steffen Jaeckel
82482119df add padding module 2018-03-23 22:01:41 +01:00
Steffen Jaeckel
8a6ee82e17
Merge pull request #341 from libtom/review/prngs
Review of prngs
2018-03-23 22:00:56 +01:00
Steffen Jaeckel
39d4a14c29 improve fortuna_import()
This makes fortuna_import() kinda compliant to the "Update seed file"
behavior of the original paper.
It differs from the original behavior in that it allows to import
seed files which are larger	than 64 bytes.
2018-03-23 15:16:13 +01:00
Steffen Jaeckel
4fb3a6468e unify the prng's export() functions
This also makes fortuna_export() compliant to the "Write seed file"
behavior of the original paper.
2018-03-23 15:16:13 +01:00
Steffen Jaeckel
979a36b9bb add possibility to seed PRNG as if it's imported 2018-03-23 15:16:13 +01:00
Steffen Jaeckel
cccd1e3053 add comment to Fortuna docs 2018-03-23 15:16:13 +01:00
Steffen Jaeckel
d502869728 don't ignore additional data on SOBER128-PRNG import 2018-03-23 15:16:13 +01:00
Steffen Jaeckel
0c05e5386f fortuna_import() shouldn't ignore additional input 2018-03-23 15:16:13 +01:00
Steffen Jaeckel
04ce8cf613 ensure that fortuna has been seeded properly 2018-03-23 15:16:13 +01:00
Steffen Jaeckel
70fd5dd83d
Merge pull request #353 from libtom/minor/improvements
Minor improvements
2018-03-23 15:15:30 +01:00
Steffen Jaeckel
0dc3ab00d9 update/improve docs 2018-03-22 16:12:56 +01:00
Steffen Jaeckel
9d72e81ce8 use 'char*' in base32
... instead of 'unsigned char*'
2018-03-22 16:12:56 +01:00
Steffen Jaeckel
6f20738057 Update makefiles 2018-03-22 16:12:56 +01:00
Steffen Jaeckel
3d99d9b443 add base16_{de,en}code() 2018-03-22 16:12:56 +01:00
Steffen Jaeckel
b026c23b0a use do_compare_testvector() where possible 2018-03-22 16:12:56 +01:00
Steffen Jaeckel
e1cba4da7d fix der_test and rsa_test when compiling for msvc 2018-03-22 16:12:56 +01:00
Steffen Jaeckel
e36e512459 use DO() macro in file_test 2018-03-22 16:12:56 +01:00
Steffen Jaeckel
ffd4dd9e6a give a name to the public-key-type enum
... and add PK_STD to it
2018-03-22 16:12:56 +01:00
Steffen Jaeckel
ccc7cf4af2 improve/fix x509_decode_subject_public_key_info()
1. only pass in as many alg_id sequence elements as used
2. we weren't able to import into exactly sized public_key buffers
3. fix types in API signature
4. make `public_key` arg a `const*`
2018-03-22 14:39:16 +01:00
Steffen Jaeckel
ecd3fb714d add do_compare_testvector() 2018-03-22 14:39:16 +01:00
Steffen Jaeckel
4d17d1328d
Merge pull request #358 from libtom/travis/build-debug
Travis/build debug
2018-03-10 22:42:35 +01:00
Steffen Jaeckel
7fb108d884 add full-debug build to ci-tests 2018-03-10 17:37:54 +01:00
Steffen Jaeckel
3cfdd4bfdb fix compilation with debug output enabled 2018-03-10 11:34:05 +01:00
Steffen Jaeckel
2c07ff6fbe
Merge pull request #355 from MilkywayPwns/develop
renamed class -> klass
2018-03-10 10:43:14 +01:00
RektInator
b477e2c221 Renamed class->klass 2018-03-09 16:37:18 +01:00
karel-m
249d4694da
Merge pull request #356 from libtom/pr/keccak
Keccak
2018-03-08 09:58:46 +01:00
Karel Miko
e1ffc82bfb add keccak_NNN_init + keccak_process defines 2018-03-08 07:18:33 +01:00
Karel Miko
3cd8044290 Keccak 2018-03-08 07:18:33 +01:00
karel-m
2731b9a873
Merge pull request #357 from libtom/pr/357-msvc-warning
MSVC fix warning: signed/unsigned mismatch
2018-03-08 07:10:52 +01:00
Karel Miko
1871c5dff4 fix warning: signed/unsigned mismatch 2018-03-07 23:39:43 +01:00
Steffen Jaeckel
0a4f36d45d
Merge pull request #352 from fperrad/20180226_lint
some linting after ecc-asn1-minimal-part merge
2018-03-01 08:47:59 +01:00
Francois Perrad
1662910b40 refactor der_encode_asn1_length
in order to avoid comparison : len <= 0xffffffffffffffffULL
2018-02-28 16:19:15 +01:00
Francois Perrad
995e575521 variable 'len' must be initialized in all case 2018-02-27 22:16:57 +01:00
Francois Perrad
525b129466 fix indentation 2018-02-26 21:11:44 +01:00
karel-m
ea5b6cdce9
Merge pull request #351 from libtom/pr/fix-time_cipher_lrw
LTC_EASY & time_cipher_lrw
2018-02-26 12:55:41 +01:00
Karel Miko
733d3e5d7d fix: return with a value, in function returning void (LTC_EASY) 2018-02-26 09:52:57 +01:00
Steffen Jaeckel
64298c1819
Merge pull request #309 from libtom/pr/ecc-asn1-part-minimal
ECC-step1: ASN.1 changes required for future ECC enhancements
2018-02-25 23:34:09 +01:00
Steffen Jaeckel
d89326bbea update doc 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
e4efd70382 add der_decode_custom_type_ex()
This merges der_decode_sequence_ex() into a new der_decode_custom_type_ex()
which can decode SEQUENCEs, SETs and custom types.
2018-02-25 20:42:26 +01:00
Steffen Jaeckel
9d03c38ea4 add flags to der_decode_sequence() 2018-02-25 20:42:26 +01:00
Karel Miko
3044b227f8 improve style of length-checks
As `der_decode_asn1_length()` will now also decode a uint64 with all 0xff
the old style would overflow in that check which "wouldn't be good"^TM.

The old way the length-checks were written were kind of fine when building
on 64bit architectures, but have the same problem on 32bit.
2018-02-25 20:42:26 +01:00
Steffen Jaeckel
7e2d163d1d add testvectors from [1]
[1] https://misc.daniel-marschall.de/asn.1/oid_facts.html
2018-02-25 20:42:26 +01:00
Steffen Jaeckel
756bc7fa21 use new ASN.1 functionality 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
3431763275 update/add more DER tests 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
b75c3ce9db remove LTC_ASN1_CONSTRUCTED and LTC_ASN1_CONTEXT_SPECIFIC 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
799e147254 Update makefiles 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
5230977219 implement the Custom-type de-/encoders 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
0d02137a8e add required ASN.1 custom-types functions 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
1b3a757345 add ASN.1-identifier functions 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
509ad5222f add maps for ASN.1 en-/decoding 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
64875d3a8f add ASN.1-length functions 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
2a78ed31bf add CRYPT_PK_ASN1_ERROR 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
54dd6ce840 fix naming of SubjectPublicKeyInfo de-&encoder 2018-02-25 20:42:26 +01:00
Karel Miko
fd7c2b8c1f no need for der_decode_subject_public_key_info_ex 2018-02-25 20:42:26 +01:00
Karel Miko
f155d3c530 ASN.1 changes required fo future ECC enhancements 2018-02-25 20:42:26 +01:00
Steffen Jaeckel
11cda2e274
Merge pull request #350 from libtom/fix/no-file-warnings
Fix warnings in `XMAC_file()` functions when compiling with `LTC_NO_FILE`.
2018-02-25 20:35:49 +01:00
Steffen Jaeckel
b1b40d48fa silencio por favor
Fix warnings in `XMAC_file()` functions when compiling with `LTC_NO_FILE`.
2018-02-25 17:17:04 +01:00
Steffen Jaeckel
5a3a12c9b3 don't export .travis.yml in future releases 2018-01-22 11:09:38 +01:00
Steffen Jaeckel
fa96614366 Update makefiles 2018-01-22 11:05:22 +01:00
Steffen Jaeckel
d68de4d26d show in SCRYPT etc. that we're on develop 2018-01-22 11:05:20 +01:00
Steffen Jaeckel
7de2d910fe libtomcrypt v1.18.1
-----BEGIN PGP SIGNATURE-----
 Version: GnuPG v1
 Comment: Gnu Privacy Tools
 
 iF4EABEIAAYFAlpltt4ACgkQrwyxdiHtrXIaugD+PZ1lGJ3Hhm5nQzVycQqp5ryc
 BbfeJhhrRVr1art3ftMA/2AOFXS0SEKtkgALCh1qJkK9YwZIZcDGPqSl/6uTEbKq
 =1DpZ
 -----END PGP SIGNATURE-----

Merge tag 'v1.18.1' into develop

libtomcrypt v1.18.1
2018-01-22 11:04:49 +01:00
Steffen Jaeckel
e08fd8630f Merge branch 'release/1.18.1' 2018-01-22 11:02:57 +01:00
Steffen Jaeckel
60df7d360a Fix 'fixme check'
The error produced by `make zipup` - but ignored by make - was:

```
...
fixme check
makefile_include.mk:448: recipe for target 'zipup' failed
make: [zipup] Error 123 (ignored)
mkdir -p libtomcrypt-...
```
2018-01-22 11:01:34 +01:00
Steffen Jaeckel
c7ff3bb86e Bump revision 2018-01-22 10:45:28 +01:00
Steffen Jaeckel
08e0424d52 Update changes 2018-01-22 10:06:54 +01:00
Steffen Jaeckel
4800543664 add -p switch to install commands in GNU makefiles
This fixes #340

[skip ci]

(cherry picked from commit fc6eb3ecf0)
2018-01-22 10:05:03 +01:00
Steffen Jaeckel
fc6eb3ecf0 add -p switch to install commands in GNU makefiles
This fixes #340

[skip ci]
2018-01-21 13:23:14 +01:00
Steffen Jaeckel
da7054820c Fix some latex formatting errors
[skip ci]
2018-01-20 15:31:00 +01:00
Tetsuya Yoshizaki
144839a8db ltc: ctr: update pt and ct after acceleration
Problem occurs in the condition of the following case:

1st decryption:
Decrypt a ciphertext whose length is a multiple of the block size (16B)
(len = n * block_size)
2nd decryption:
Decrypt the continuing ciphertext whose length is not a multiple of the
block size
(len = m * block_size + l)

In this case accel_ctr_encrypt() is firstly used at the 2nd decryption.
If pt and ct are not updated, the top (l = len % block_size) bytes of
decryption result are sometimes destroyed.

From: Tetsuya Yoshizaki <yoshizaki.tetsuya@socionext.com>
Signed-off-by: Tetsuya Yoshizaki <yoshizaki.tetsuya@socionext.com>
Signed-off-by: Victor Chong <victor.chong@linaro.org>
(cherry picked from commit d1d3ae2d1e)
2018-01-19 10:01:03 +01:00
Tetsuya Yoshizaki
d1d3ae2d1e ltc: ctr: update pt and ct after acceleration
Problem occurs in the condition of the following case:

1st decryption:
Decrypt a ciphertext whose length is a multiple of the block size (16B)
(len = n * block_size)
2nd decryption:
Decrypt the continuing ciphertext whose length is not a multiple of the
block size
(len = m * block_size + l)

In this case accel_ctr_encrypt() is firstly used at the 2nd decryption.
If pt and ct are not updated, the top (l = len % block_size) bytes of
decryption result are sometimes destroyed.

From: Tetsuya Yoshizaki <yoshizaki.tetsuya@socionext.com>
Signed-off-by: Tetsuya Yoshizaki <yoshizaki.tetsuya@socionext.com>
Signed-off-by: Victor Chong <victor.chong@linaro.org>
2018-01-19 09:39:25 +01:00
Steffen Jaeckel
5501572b35 Merge pull request #339 from libtom/minor_improvements
Minor improvements
(cherry picked from commit df8ed5c76b)
2018-01-15 00:39:26 +01:00
Steffen Jaeckel
df8ed5c76b
Merge pull request #339 from libtom/minor_improvements
Minor improvements
2018-01-14 22:31:24 +01:00
Steffen Jaeckel
aa8441409e fix some DER bugs
1. the "ask for required memory size" pattern wasn't implemented for
`der_decode_object_identifier()`
2. fix wrong "required memory size" returned by UTF-8 de- & encoder
2018-01-11 18:06:23 +01:00
Steffen Jaeckel
a898fde5b7 better debug output 2018-01-11 18:06:23 +01:00
Larry Bugbee
48a798261d
Merge pull request #334 from libtom/add-rabbit
Add Rabbit stream cipher
2017-12-18 04:16:32 -08:00
Larry Bugbee
8ef60f7b47 add rabbit 2017-12-17 08:05:41 -08:00
Larry Bugbee
784fc5313c makefile updates 2017-12-17 08:05:41 -08:00
Steffen Jaeckel
f4d2b37cf4 Merge pull request #337 from libtom/fix/prng_pthread
prevent undefined behavior with LTC_PTHREAD
(cherry picked from commit 45db2a9d9a)
2017-12-17 01:20:32 +01:00
Karel Miko
dd868600b3 fix staticfunc_name detection
(cherry picked from commit 6d71d657ef)
2017-12-17 01:05:53 +01:00
Steffen Jaeckel
10ad3b5b41 fixup type of type in ltc_asn1_list doc
(cherry picked from commit 5e3e7e5304)
2017-12-17 01:05:43 +01:00
Steffen Jaeckel
8ef3b9dffd
Merge pull request #335 from libtom/minor_cleanup
Minor cleanup
2017-12-17 00:43:35 +01:00
Steffen Jaeckel
35c4d157d0 as of POSIX.1-2008 gettimeofday() is obsolete 2017-12-16 16:02:00 +01:00
Steffen Jaeckel
b84bea8e78 easier calculation 2017-12-16 16:02:00 +01:00
Steffen Jaeckel
38143771d7 Update makefiles 2017-12-16 16:02:00 +01:00
Steffen Jaeckel
fd46a74331 re-order tomcrypt_mac.h 2017-12-16 16:02:00 +01:00
Steffen Jaeckel
8fffebc395 fix .travis.yml 2017-12-16 16:02:00 +01:00
Steffen Jaeckel
5c0b1b4bf6 add copy_or_zeromem() 2017-12-16 16:02:00 +01:00
Steffen Jaeckel
c0b7c8dd67 more output in debug build
make compare_testvector() a bit more verbose in debug build
2017-12-10 12:35:59 +01:00
Steffen Jaeckel
5546e85218 introduce LTC_EXTRALIBS
it's used for libraries added in the makefile
2017-12-10 12:35:59 +01:00
Karel Miko
6d71d657ef fix staticfunc_name detection 2017-12-10 12:35:59 +01:00
Steffen Jaeckel
5e3e7e5304 fixup type of type in ltc_asn1_list doc 2017-12-10 12:35:59 +01:00
Steffen Jaeckel
ea43e5dd68 suppress 'missing-braces' warnings 2017-12-10 12:35:59 +01:00
Steffen Jaeckel
196f25e32f there should be no need to pass CFLAGS when linking 2017-12-10 12:35:59 +01:00
Steffen Jaeckel
45db2a9d9a
Merge pull request #337 from libtom/fix/prng_pthread
prevent undefined behavior with LTC_PTHREAD
2017-12-10 12:35:01 +01:00
Steffen Jaeckel
c0eefc2b20 prevent undefined behavior with LTC_PTHREAD
as of `man pthread_mutex_init`:

"Attempting to initialize an already initialized mutex
results in undefined behavior."
2017-12-07 14:56:44 +01:00
Larry Bugbee
479cce29ab
Merge pull request #332 from libtom/sosemanuk--cleanup-comments-and-doc
sosemanuk updated comments and doc
2017-12-05 12:20:06 -08:00
Larry Bugbee
b6ae9ab000
grammatical change 2017-12-05 09:53:15 -08:00
Steffen Jaeckel
cec171c17e Update changes 2017-12-05 18:41:11 +01:00
Steffen Jaeckel
c7bdb247bf Update makefiles 2017-12-05 18:40:57 +01:00
Steffen Jaeckel
cfaf964284 Bump version 2017-12-05 18:40:49 +01:00
Steffen Jaeckel
ce93eaa577 add fixme-check to zipup make-target
(cherry picked from commit 6c83a2f363)
2017-12-05 18:39:46 +01:00
Steffen Jaeckel
f9e90f5b1c revert the change of MAXBLOCKSIZE
Currently this only plays a role in HMAC which still uses dynamic
allocation depending on the real blocksize defined by the hash
algorithm.
2017-12-05 17:46:08 +01:00
Steffen Jaeckel
f122e9b887 Merge pull request #329 from libtom/pr/sha3-blocksize
Correct SHA3 block sizes
(cherry picked from commit 64d028832b)
2017-12-05 17:43:46 +01:00
Steffen Jaeckel
64d028832b
Merge pull request #329 from libtom/pr/sha3-blocksize
Correct SHA3 block sizes
2017-12-05 17:41:44 +01:00
Karel Miko
8fdc46cc4b updated tv_gen outputs 2017-12-05 13:00:13 +01:00
Karel Miko
e89a1f2ae6 correct SHA3 block sizes 2017-12-05 13:00:13 +01:00
Larry Bugbee
83ee79ac56
change crypt() length data name to match doc 2017-12-05 01:02:10 -08:00
Larry Bugbee
c4fdf5c1fc
rephrase one sentence 2017-12-05 00:55:07 -08:00
Steffen Jaeckel
13d91e7c8b Merge pull request #327 from libtom/fix/ccm_segfault
Fix ccm_memory() cleaning user-supplied key
(cherry picked from commit 85ac227862)
2017-12-05 09:23:06 +01:00
Steffen Jaeckel
368dc60ff3 Merge pull request #326 from libtom/pr/ccm_process
fixes #323 ccm_process fails to process input buffer longer than 256
(cherry picked from commit 7c4c61d7ef)
2017-12-05 09:21:52 +01:00
Karel Miko
153b897984 helper.pl - detect sizeof without brackets
(cherry picked from commit b7e35e9f57)
2017-12-05 09:21:27 +01:00
Karel Miko
f10c2055dc helper.pl - improved detection of static functions without _
(cherry picked from commit 5c34fb2bad)
2017-12-05 09:21:17 +01:00
Karel Miko
a674de7408 Merge branch 'diamondo25-patch-2' into develop
Fix not defined warnings (-Wundef)

(cherry picked from commit 617698e544)
2017-12-05 09:20:41 +01:00
karel-m
7f6af93798 Merge pull request #320 from diamondo25/patch-1
Remove duplicate prototypes
(cherry picked from commit b4eae5231d)
2017-12-05 09:20:15 +01:00
karel-m
00ca140c57 Merge pull request #316 from libtom/pr/register-all
register_all_* should return CRYPT_OK on success
(cherry picked from commit e4763d940a)
2017-12-05 09:19:40 +01:00
Steffen Jaeckel
521d0737ea fix typo
(cherry picked from commit 442bb90a51)
2017-12-05 09:17:30 +01:00
Steffen Jaeckel
035e958edd Merge pull request #310 from libtom/pr/fix-changes
proper 1.18.0 date in changes
(cherry picked from commit a6c8be292e)
2017-12-05 09:16:30 +01:00
Larry Bugbee
f42bf2f942 updated comments and doc 2017-12-04 22:15:18 -08:00
Steffen Jaeckel
c6cccf9120
Merge pull request #330 from J08nY/fix/sosemanuk-doc
Fix docs build in Sosemanuk section.
2017-11-29 09:52:39 +01:00
J08nY
684c0890e7 Fix docs build in Sosemanuk section. 2017-11-28 17:13:09 +01:00
karel-m
af10ad084d
Merge pull request #328 from fperrad/20171122_lint
sosemanuk: some linting
2017-11-22 18:00:51 +01:00
Francois Perrad
77b0aff4e6 remove always true condition
ivlen is unsigned, so always >= 0
2017-11-22 10:34:45 +01:00
Francois Perrad
e985a9c111 add const 2017-11-22 10:34:42 +01:00
Karel Miko
2dec37044c chmod sosemanuk.c 2017-11-21 08:55:01 +01:00
Larry Bugbee
174f0aaf33
Merge pull request #322 from libtom/add-sosemanuk
add Sosemanuk
2017-11-20 14:35:56 -08:00
Steffen Jaeckel
85ac227862
Merge pull request #327 from libtom/fix/ccm_segfault
Fix ccm_memory() cleaning user-supplied key
2017-11-20 14:25:45 +01:00
Steffen Jaeckel
2a5f5cff16 test that ccm_memory() doesn't touch user-supplied key 2017-11-20 12:11:12 +01:00
Steffen Jaeckel
e05097e413 fix segfault in ccm_memory() with LTC_CLEAN_STACK
we shouldn't clean user-supplied variables
2017-11-20 12:11:12 +01:00
Larry Bugbee
108ddf5b50 add Sosemanuk 2017-11-20 02:41:30 -08:00
Larry Bugbee
807ae09916 Update makefiles 2017-11-20 02:40:45 -08:00
Steffen Jaeckel
7c4c61d7ef
Merge pull request #326 from libtom/pr/ccm_process
fixes #323 ccm_process fails to process input buffer longer than 256
2017-11-10 00:41:50 +01:00
Karel Miko
08dee27359 fixes #323 ccm_process fails to process input buffer longer than 256 bytes 2017-11-09 19:47:51 +01:00
Steffen Jaeckel
28d44b35f3
Merge pull request #325 from libtom/pr/new_63
Statically allocated key in hmac_state

This fixes #63 and closes #64
2017-11-09 19:44:28 +01:00
Pascal Brand
c2ce5a18e7 Statically allocated key in hmac_state
Signed-off-by: Pascal Brand <pascal.brand@st.com>
2017-11-09 15:32:01 +01:00
Steffen Jaeckel
b159ca0d12 add missing file footers
[skip ci]
2017-11-09 15:31:51 +01:00
Steffen Jaeckel
f5e5c6eed7 simplify calculation 2017-11-06 12:13:16 +01:00
Karel Miko
b7e35e9f57 helper.pl - detect sizeof without brackets 2017-11-05 17:08:02 +01:00
Karel Miko
5c34fb2bad helper.pl - improved detection of static functions without _ 2017-11-05 11:40:01 +01:00
Karel Miko
617698e544 Merge branch 'diamondo25-patch-2' into develop
Fix not defined warnings (-Wundef)
2017-11-03 17:06:23 +01:00
Karel Miko
053996dc5e Fix _POSIX_C_SOURCE not defined warning (-Wundef) 2017-11-03 17:05:56 +01:00
Erwin Oegema
5a6c258679 Fix LTC_TEST_DBG not defined warning (-Wundef) 2017-11-03 17:04:32 +01:00
karel-m
b4eae5231d
Merge pull request #320 from diamondo25/patch-1
Remove duplicate prototypes
2017-11-03 17:01:51 +01:00
Erwin Oegema
b1115b4e8f
Remove duplicate prototypes 2017-11-01 15:30:36 +01:00
Larry Bugbee
9b65d46584 Merge pull request #318 from libtom/add-salsa20
Add salsa20
2017-10-24 13:28:55 -07:00
Larry Bugbee
f1da5783eb fixed C90 warning: value after decl
warning: ISO C90 forbids mixed declarations and code
2017-10-23 22:40:21 -07:00
Larry Bugbee
74dcbc810f fixed C90 warning: value after decl
warning: ISO C90 forbids mixed declarations and code
2017-10-23 22:00:45 -07:00
Larry Bugbee
6ada199d7d added keystream regression test 2017-10-23 21:43:17 -07:00
Larry Bugbee
4341424ce9 Add Salsa20 2017-10-23 15:45:02 -07:00
Larry Bugbee
aa5a2e5a26 Update makefiles 2017-10-23 15:41:04 -07:00
Karel Miko
6c5dea3e61 __declspec(deprecated) is supported since Visual Studio 2008 2017-10-23 20:18:59 +02:00
Steffen Jaeckel
80665ac576 Merge pull request #317 from libtom/pr/base32
Base32
2017-10-22 11:04:40 +02:00
Karel Miko
854a145c92 Base32: alpha_id >> id 2017-10-20 20:00:46 +02:00
Karel Miko
3fc98adaf5 tuning base32 stuff 2017-10-20 19:51:40 +02:00
Karel Miko
8674eb3097 base32_decode + base32_encode 2017-10-20 19:51:40 +02:00
Karel Miko
035205af85 update makefiles 2017-10-20 19:51:40 +02:00
Steffen Jaeckel
c8edd3c2e9 Merge pull request #315 from libtom/improve/travis_build
Improve/travis build
2017-10-20 15:44:41 +02:00
Steffen Jaeckel
1fc46a0f15 fix travis detection in coverage.sh 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
742a6c7a33 fix paths 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
b070672f59 move ci scripts to .ci/ 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
c5caac505b print stderr on the fly also to console 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
29c640f7e1 enable parallel builds 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
30948fc0e9 move valgrind build to own travis instance
testing under valgrind takes forever, so we start a separate build-job
2017-10-19 09:54:47 +02:00
Steffen Jaeckel
384f82d0a9 also create coverage for gmp_desc 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
91e1d04831 incorporate scan_build.sh in meta_builds.sh 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
65e1eb68e9 fix missing valgrind & don't be that noisy 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
ce3da7c06f use correct set of parameters 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
2dad6d30bf add meta_builds.sh
This fixes #267 #268 #269
2017-10-19 09:54:47 +02:00
Steffen Jaeckel
18ba0cbda9 fix tv_gen.c for scan-build run 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
3f024c0685 only run scan_build for clang 2017-10-19 09:54:47 +02:00
Steffen Jaeckel
315d03ccd5 use parameters instead of pre-defined values 2017-10-19 09:54:47 +02:00
karel-m
e4763d940a Merge pull request #316 from libtom/pr/register-all
register_all_* should return CRYPT_OK on success
2017-10-19 07:29:05 +02:00
Karel Miko
152513477b fix return value of register_all_*() 2017-10-18 22:35:16 +02:00
karel-m
d470f8a7ab Merge pull request #314 from libtom/pr/serpent-cipher
Serpent cipher
2017-10-18 17:24:18 +02:00
Karel Miko
aa3e5a43bb fix warning: Value stored to 'e' is never read 2017-10-18 17:21:46 +02:00
Karel Miko
a37a93aecc doc update 2017-10-18 17:21:46 +02:00
Karel Miko
c5735be01e update makefiles 2017-10-18 17:21:46 +02:00
Karel Miko
5a63e7ef7d Serpent cipher 2017-10-18 17:21:46 +02:00
Steffen Jaeckel
49f732101c Merge pull request #297 from libtom/improve/mpi_selection
Improve MPI provider selection
2017-10-18 08:47:10 +02:00
Steffen Jaeckel
d709e3d9a3 Update doc
[skip ci]
2017-10-18 08:46:17 +02:00
Steffen Jaeckel
1a892960fe don't be that strict 2017-10-18 08:46:17 +02:00
Steffen Jaeckel
bfef6350a2 deprecate init_{LTM,TFM,GMP} 2017-10-18 08:46:17 +02:00
Steffen Jaeckel
beb1e279ec add LTC_DEPRECATED 2017-10-18 08:46:17 +02:00
Steffen Jaeckel
735566993b add crypt_mp_init() 2017-10-18 08:46:17 +02:00
Steffen Jaeckel
fdc6cd2013 improve tests and timing in regards to MPI provider selection 2017-10-18 08:46:17 +02:00
Steffen Jaeckel
442bb90a51 fix typo 2017-10-18 08:45:56 +02:00
Steffen Jaeckel
6c83a2f363 add fixme-check to zipup make-target 2017-10-18 08:45:56 +02:00
karel-m
dd95518db4 Merge pull request #312 from libtom/pr/idea-cipher
IDEA cipher
2017-10-18 07:08:04 +02:00
Karel Miko
ee484a0bc0 burn_stack 2017-10-16 23:15:54 +02:00
Karel Miko
a2dd766ed5 IDEA cipher 2017-10-16 21:20:33 +02:00
Karel Miko
295bde14c1 update makefiles 2017-10-16 21:19:54 +02:00
Steffen Jaeckel
a6c8be292e Merge pull request #310 from libtom/pr/fix-changes
proper 1.18.0 date in changes
2017-10-12 19:41:52 +02:00
karel-m
437cb0207a proper 1.18.0 date in changes 2017-10-12 17:19:38 +02:00
Steffen Jaeckel
44b15a76aa add issue and PR templates 2017-10-10 18:08:35 +02:00
Steffen Jaeckel
976e7c4e31 Merge tag 'v1.18.0' into develop
libtomcrypt v1.18.0
2017-10-10 15:52:19 +02:00
Steffen Jaeckel
0676c9aec7 Merge branch 'release/1.18.0' 2017-10-10 15:51:36 +02:00
Steffen Jaeckel
c165f3a23a Update makefiles 2017-10-10 15:48:35 +02:00
Steffen Jaeckel
a7d0008f52 bump version 2017-10-10 15:48:35 +02:00
Steffen Jaeckel
b3c9f586dc also patch doc/Doxyfile automatically 2017-10-10 15:48:35 +02:00
Steffen Jaeckel
62143d96bd fix doxygen warning 2017-10-10 15:43:26 +02:00
Steffen Jaeckel
58b5e5c7ca improve README
[skip ci]
2017-10-10 15:19:23 +02:00
Steffen Jaeckel
ea5cb8bff6 make it possible to use LTC_NOTHING with a math provider 2017-10-10 15:19:01 +02:00
Steffen Jaeckel
233ef83530 suppress some warnings when compiling with mingw-gcc
[skip ci]
2017-10-10 14:29:34 +02:00
Steffen Jaeckel
e40482f82a review README.md and changes 2017-10-09 18:26:38 +02:00
Steffen Jaeckel
dd0bbdeac0 increase default value of Miller-Rabin rounds to 40 2017-10-09 17:58:47 +02:00
Steffen Jaeckel
4503ddcfb0 improve wording
[skip ci]
2017-10-08 01:05:12 +02:00
Steffen Jaeckel
6493f0fe94 Merge pull request #308 from libtom/pr/avoid-dulplicit-manes
Aviod duplicit rc4.c sober128.c
2017-10-08 00:57:47 +02:00
Steffen Jaeckel
bab6af73e5 fix check_source() 2017-10-07 18:09:13 +02:00
Karel Miko
2041f9528e update makefiles 2017-10-07 11:35:27 +02:00
Karel Miko
959121253d rename duplicit rc4.c sober128.c 2017-10-07 11:35:10 +02:00
Steffen Jaeckel
adcd6ee9fd only try to print the version from git if there's git installed 2017-10-03 19:54:27 +02:00
Steffen Jaeckel
58b71292c3 fixup caed025f8a
Simply always use an unsigned long long for ltc_mp_digit on 64-bit besides
when using MSVC.
2017-10-03 19:20:33 +02:00
Steffen Jaeckel
e438dbc3bf add ltc_mp_digit to sizes and tests 2017-10-03 18:43:32 +02:00
Steffen Jaeckel
caed025f8a define ltc_mp_digit as 'unsigned long' resp 'unsigned long long' for x32
This fixes #306
2017-10-03 18:42:26 +02:00
Steffen Jaeckel
cb34ef8626 fix-up LTC_FAST related defines/typedefs 2017-10-03 13:32:17 +02:00
Steffen Jaeckel
bb291cbbeb init_GMP() works perfectly fine 2017-10-02 14:06:42 +02:00
Steffen Jaeckel
01a61e64ef Merge pull request #302 from libtom/fix/pr/301
re-work PK crypto im- & export
2017-10-02 14:05:58 +02:00
Steffen Jaeckel
7f302dab54 make sure size is valid 2017-10-02 01:18:36 +02:00
Steffen Jaeckel
c702ac6f1c improve rsa_test a bit 2017-10-02 01:18:19 +02:00
Karel Miko
67f9064b71 missing rsa_free in _rsa_issue_301 test 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
ce7ae84d0d correctly fix decoding of SubjectPublicKeyInfo 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
db7d7a866e Revert "fix bit-length check in der_decode_raw_bit_string()"
This reverts commit 2b8d83ff93da0764f19f494de0a8211515428cef.
2017-10-01 22:56:47 +02:00
Steffen Jaeckel
e5de0a0004 Revert "catch case where blen%8 != 0"
This reverts commit 548ee347c0d3366a41e5fa28ac3c0b44b362fdb5.
2017-10-01 22:56:47 +02:00
Steffen Jaeckel
d1d9566250 format code 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
30b3a9a986 remove {MIN,MAX}_RSA_SIZE 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
40e4a66693 catch case where blen%8 != 0 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
3fef07c03e also clear bits in der_decode_raw_bit_string() 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
1d20c32a45 update README
[skip ci]
2017-10-01 22:56:47 +02:00
Steffen Jaeckel
9cfbaa83a3 mostly remove MAX_RSA_SIZE 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
ab02d2e450 fix rsa_import() of MAX_RSA_SIZE'ed keys
The ASN1 encoded RSA key contains two MPI's therefore MAX_RSA_SIZE / 8
isn't enough.
2017-10-01 22:56:47 +02:00
Steffen Jaeckel
0500aaec45 add tests for MAX_RSA_SIZE sized openssl-standard RSA keys 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
efa089e211 fixup #290 2017-10-01 22:56:47 +02:00
Steffen Jaeckel
15eab9702b don't over-allocate that much in der_decode_subject_public_key_info() 2017-10-01 22:56:46 +02:00
Steffen Jaeckel
0b04279890 fix bit-length check in der_decode_raw_bit_string() 2017-10-01 22:56:46 +02:00
Steffen Jaeckel
062fc3ffe3 print info when doing a debug build 2017-10-01 22:56:46 +02:00
Rob Swindell
6da2211ee9 Update rsa_import.c
Bug-fix: MAX_RSA_SIZE is the maximum RSA key size in *bits* (as commented in tomcrypt_custom.h), so the proper conversion to bytes (as the argument value to XCALLOC) would be to divide by 8 (bits per byte), not multiply by 8. This excessive allocation (32 Kbytes instead of 512 bytes) is readily apparent in memory-constrained environments.
2017-10-01 22:56:46 +02:00
karel-m
c2f0675ede Merge pull request #304 from libtom/pr/fix-303
missing dsa_free
2017-10-01 17:24:08 +02:00
Karel Miko
98536fa5bf add missing dsa_free to _dsa_wycheproof_test - fixes #303 2017-10-01 15:40:19 +02:00
Steffen Jaeckel
f4802ef40a add ltc_math_descriptor to crypt_sizes 2017-09-30 13:01:08 +02:00
Steffen Jaeckel
9ff889b330 Update makefiles 2017-09-27 21:37:23 +02:00
Steffen Jaeckel
07c5e6b0a4 bump version 2017-09-27 21:37:21 +02:00
Steffen Jaeckel
5f89a5ce2c Merge pull request #298 from libtom/strict_der_decoding
initialize 'flags' etc. to invalid values before trying to decode
2017-09-27 21:34:30 +02:00
Steffen Jaeckel
4a8bfc0a21 introduce CRYPT_INPUT_TOO_LONG 2017-09-27 21:34:11 +02:00
Steffen Jaeckel
13cb43ad4c initialize 'flags' etc. to invalid values before trying to decode 2017-09-27 21:34:11 +02:00
Steffen Jaeckel
8935cd9a8a Merge pull request #299 from libtom/pr/libtool-cygwin
libtool + cygwin
2017-09-27 21:33:29 +02:00
Karel Miko
9c2c9f8af4 libtool on cygwin needs -no-undefined 2017-09-27 21:25:19 +02:00
Steffen Jaeckel
5049463774 bump the libtool version
yeah, helper.pl doesn't update it anymore automagically...
we'll probably find a new way to do that in the future...
or we keep on updating it manually...

This fixes #300
2017-09-27 21:19:33 +02:00
Steffen Jaeckel
f868a16a44 Update makefiles 2017-09-25 16:56:59 +02:00
Steffen Jaeckel
20c6bf812b bump version 2017-09-25 16:56:57 +02:00
Karel Miko
83e7f4a1c7 keep dh_key.x instead of free'ing it
the approach before probably saves some bytes on the heap, but it's
inconsistent in regards to what we normally do
2017-09-25 15:35:29 +02:00
Steffen Jaeckel
f7c0b25146 add missing math constants 2017-09-23 11:42:05 +02:00
Steffen Jaeckel
91a10318f1 Merge pull request #296 from libtom/cleanup/3
General clean-up 3
2017-09-21 20:46:41 +02:00
Karel Miko
ea43d9a1d2 Fix openssl-enc compilation 2017-09-21 18:37:37 +02:00
Steffen Jaeckel
8f7986bbb2 fix coverage_more.sh after updating hashsum 2017-09-21 18:37:37 +02:00
Steffen Jaeckel
5bb63f1bca hashsum: improve help 2017-09-21 18:37:37 +02:00
Steffen Jaeckel
eb75c894db hashsum: cleanup at exit 2017-09-21 18:37:37 +02:00
Steffen Jaeckel
312247fa0b better comments for PKCS#5 2017-09-21 18:37:37 +02:00
Steffen Jaeckel
da4f854329 make sure chacha_crypt() can only be called after setting the IV 2017-09-21 18:37:37 +02:00
Steffen Jaeckel
342a10cc14 make PK_MAX_RETRIES a config option 2017-09-21 18:37:37 +02:00
Steffen Jaeckel
a278f72659 skip comment lines when checking hashes
[skip ci]
2017-09-20 17:43:07 +02:00
Steffen Jaeckel
9a83397376 catch case where we could BOF should_buffer[]
[skip ci]
2017-09-20 17:29:05 +02:00
Steffen Jaeckel
b6213309ca Merge pull request #197 from libtom/update/doc
Update documentation
2017-09-20 15:14:54 +02:00
Steffen Jaeckel
f8d132ea03 update changes
[skip ci]
2017-09-20 15:14:10 +02:00
Steffen Jaeckel
7cc9aad5cc remove TODO 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
9fb08af23d fix location of some of the tables
this fixes the last open issue of #54
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
2d3a921de4 align code
[skip-ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
4f7747eaec DSA not DH 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
c210f24853 IV is short for 'initialization vector' 2017-09-20 15:06:40 +02:00
Karel Miko
fff9fee129 DSA new functions - doc 2017-09-20 15:06:40 +02:00
Karel Miko
f3f839ec6c BLAKE2s + BLAKE2b MAC doc 2017-09-20 15:06:40 +02:00
Karel Miko
50e52d0b4c poly1305 doc 2017-09-20 15:06:40 +02:00
Karel Miko
11827feef3 ChaCha20-Poly1305 doc 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
35d920a688 moar doc
[skip ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
8b3af12d70 add radix_to_bin() docs
[skip ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
78e9601eb6 review "Configuring and Building the Library"
[skip ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
13b484f8a5 moar doc
[skip ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
0742a99fb5 update README
[skip ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
fc65352261 moar doc
[skip ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
dd01232bcb review stream ciphers
[skip ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
2ccb3fb53d update OCB3 doc
[skip ci]
2017-09-20 15:06:40 +02:00
Steffen Jaeckel
56d17c8e55 some more doc updates 2017-09-20 15:06:40 +02:00
Karel Miko
5d74fee9dc doc tuning 2017-09-20 15:06:40 +02:00
Karel Miko
468245ce56 doc: stream ciphers 2017-09-20 15:06:40 +02:00
Karel Miko
9584975a6d some crypt.tex hacking 2017-09-20 15:06:40 +02:00
Karel Miko
7edc41162d fix crypt.pdf building 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
39650b4a08 add doc of new RSA API functions 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
583b2b3938 document PKCS#1 v1.5 signatures w/o ASN.1 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
09c3196930 use v1.18.0 instead of v1.18 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
9a0e208f5e add 'ltc_mp_digit' docs 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
728bc4a6a4 update "Primality Testing" 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
ce68fa34ee add rand_bn_X() doc 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
a0a7daea6f add termdoc option to view documentation on the terminal 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
01cb819c48 trim trailing spaces 2017-09-20 15:06:40 +02:00
Steffen Jaeckel
a9d9466694 beautify some strings
[skip-ci]
2017-09-20 15:06:28 +02:00
karel-m
632d2b757b Merge pull request #291 from libtom/pr/dsa-test-wycheproof
dsa_verify_hash fix + dsa_wycheproof_test
2017-09-20 13:23:51 +02:00
Karel Miko
66abefc54b add dsa_wycheproof_test + fix old dsa tests 2017-09-20 11:59:03 +02:00
Karel Miko
155e29dd68 dsa_verify_hash must set stat=0 on any error 2017-09-20 11:58:32 +02:00
Steffen Jaeckel
4b36f0654f Add 'Installation' section
This closes #293

[skip-ci]
2017-09-19 14:19:43 +02:00
Steffen Jaeckel
d169aa2af2 Merge pull request #290 from libtom/pr/write-strings
Add -Wwrite-strings (char* vs. const char*)
2017-09-19 13:24:13 +02:00
Karel Miko
b2813480bf LTC_CFLAGS += -Wwrite-strings 2017-09-18 12:35:03 +02:00
Karel Miko
5057af3ef1 fix char* vs. const char* 2017-09-18 12:35:03 +02:00
karel-m
565be29bb0 Merge pull request #292 from libtom/pr/write-strings-test-part
Partial changes from #290 (char* vs. const char* - tests related part)
2017-09-18 12:34:14 +02:00
Karel Miko
3b663a199f fix char* vs. const char* (tests related part) 2017-09-18 09:24:19 +02:00
karel-m
0ceb1c1213 Merge pull request #289 from libtom/pr/scan-build-status-bugs
scan-build --status-bugs, related to #287
2017-09-15 06:47:08 +02:00
Karel Miko
84fcd4aec7 scan_build --status-bugs - related to #287 2017-09-14 23:07:18 +02:00
karel-m
04cc6cc652 Merge pull request #288 from libtom/pr/fix-tv_gen-scan-build
Fix scan-build bug/warning in tv_gen - related to #287
2017-09-14 23:05:10 +02:00
Karel Miko
3ddb45a6b7 fix scan-build bug/warning in tv_gen 2017-09-14 20:32:47 +02:00
Karel Miko
5e71849942 properly exit dsa_int_validate_pqg 2017-09-14 20:07:32 +02:00
karel-m
5934eb3b7c Merge pull request #280 from libtom/pr/fix-dsa-cdf
fixes necessary to pass DSA cdf tests
2017-09-14 19:10:13 +02:00
Karel Miko
bb6a7e1c6c if dsa_int_validate_* fails return consistently CRYPT_INVALID_PACKET 2017-09-14 18:53:09 +02:00
Karel Miko
a990a8252e mp_clear_multi - reverse the order 2017-09-14 18:51:02 +02:00
Karel Miko
6200f301a5 add comment #ifdef LTC_SOURCE + internal helper functions 2017-09-14 18:49:42 +02:00
Karel Miko
d91d59421f fix de-referencing stat before checking for NULL 2017-09-14 18:48:04 +02:00
Karel Miko
444d9f3fb7 do dsa_int_validate_* in dsa_import 2017-09-14 17:38:12 +02:00
Karel Miko
fd94e9540f move qord trest to dsa_int_validate_pqg 2017-09-14 17:37:39 +02:00
Karel Miko
9765befd6b do dsa_int_validate_pqg in dsa_set_pqg_dsaparam 2017-09-14 17:29:59 +02:00
Karel Miko
45b6b947da dsa_int_validate_primes & LTC_MILLER_RABIN_REPS 2017-09-14 17:21:48 +02:00
Karel Miko
c806ea17f9 fix dsa_int_validate_xy 2017-09-14 17:21:48 +02:00
Karel Miko
1ea4fecc81 FIPS 186-4 DSA validity tests 2017-09-14 17:21:48 +02:00
Karel Miko
5fb4c9f89b another approach for dsa_int_validate_* 2017-09-14 17:21:48 +02:00
Karel Miko
aa5b9dafc4 fix dsa_int_validate_key related compiler warnings 2017-09-14 17:21:48 +02:00
Steffen Jaeckel
1625ce4001 re-factor & re-name internal dsa key validation 2017-09-14 17:21:48 +02:00
Karel Miko
053ba6d600 introducing dsa_verify_key_ex 2017-09-14 17:21:48 +02:00
Karel Miko
2505e3b609 add basic validity tests to dsa_set 2017-09-14 17:21:48 +02:00
Karel Miko
c908eb16bb Merge pull request #283 from apjanke-build-on-mac-darnit 2017-09-14 17:15:53 +02:00
Steffen Jaeckel
2dd446dbdb clang and -Wno-missing-field-initializers 2017-09-14 17:11:06 +02:00
Andrew Janke
cfce691a50 initialize ltc_mp to force allocation under all compilers, including clang on macOS 2017-09-14 17:07:49 +02:00
karel-m
32d60ac134 Merge pull request #278 from libtom/pr/fix-dsa-wycheproof
DSA wycheproof tests
2017-09-10 14:00:54 +02:00
Karel Miko
c927e4315a dsa_verify_hash: fix wycheproof - appending unused 0's 2017-09-02 14:16:52 +02:00
Karel Miko
7e4bd971de dsa_verify_hash: properly handle (=reject) negative r, s 2017-09-02 14:16:52 +02:00
karel-m
aade47c62c Merge pull request #286 from libtom/pr/fix-dsa-rsa-trouble
Fix DSA dependency on RSA
2017-09-01 20:15:52 +02:00
Karel Miko
59857ba5e0 fix DSA dependency on RSA #285 2017-09-01 18:24:15 +02:00
Karel Miko
87f94e1f0d Merge branch 'apjanke-add-sizes-and-constants-demo-targets' into release/1.18.0
PR #282
2017-08-31 19:08:00 +02:00
Andrew Janke
f5353a613d makefile.msvc: add targets for sizes and constants demos 2017-08-31 18:55:31 +02:00
Andrew Janke
d7461a91bc makefile.mingw: add targets for sizes and constants demos 2017-08-31 18:55:31 +02:00
Andrew Janke
509086253e makefile.unix: add targets for sizes and constants demos 2017-08-31 18:55:31 +02:00
Karel Miko
c04e8a397f Merge branch 'apjanke-fix-typos-in-makefile.shared-help' into release/1.18.0
PR #284
2017-08-31 18:52:53 +02:00
Andrew Janke
39c721c8da makefile.shared: protect commas in function calls through variable substitution 2017-08-31 05:51:37 -04:00
Karel Miko
9ea6247da1 Revert "add basic validity tests to dsa_set"
This reverts commit 9003e87e5a.
2017-08-30 00:03:04 +02:00
Karel Miko
9003e87e5a add basic validity tests to dsa_set 2017-08-30 00:01:00 +02:00
karel-m
a86287b698 Merge pull request #277 from libtom/pr/fix-rsa-wycheproof
RSA wycheproof tests
2017-08-29 22:13:35 +02:00
Steffen Jaeckel
43e6860925 fix RSA - wycheproof "wrong length" 2017-08-29 17:26:14 +02:00
Karel Miko
fe9af6cfbd RSA: handle wycheproof test vectors - Legacy:missing NULL 2017-08-29 17:26:14 +02:00
Steffen Jaeckel
a22140f94c oops, fix .common_uninstall make-target
[skip-ci]
2017-08-28 17:31:44 +02:00
Steffen Jaeckel
e6d23834ae Merge pull request #276 from libtom/pr/fix-gcm-iv
GCM zero size IV
2017-08-28 17:28:30 +02:00
Karel Miko
105abdd8cd GCM: 0 size IV is not valid #273 2017-08-28 16:10:30 +02:00
Steffen Jaeckel
042df8ca20 Merge pull request #279 from libtom/cleanup/2
Yet another clean-up and bugfix PR
2017-08-28 09:14:25 +02:00
Steffen Jaeckel
bb42345234 fix missing registration of PRNG's in ltcrypt 2017-08-26 12:07:24 +02:00
Steffen Jaeckel
b49ce35b2c fix DH timing when compiling with TFM support 2017-08-26 12:05:53 +02:00
Steffen Jaeckel
33e70b427a CRYPT_INVALID_KEYSIZE isn't only used for block ciphers 2017-08-26 12:03:35 +02:00
Steffen Jaeckel
041b7aa5c0 Update makefiles 2017-08-23 22:35:35 +02:00
Steffen Jaeckel
0afbefc549 bump version 2017-08-23 22:35:32 +02:00
Larry Bugbee
725532c6b6 Merge pull request #272 from libtom/update-demos-demo_dynamic.py
Update demos demo dynamic.py - everything is green
2017-08-19 18:19:00 -07:00
Larry Bugbee
de6ac748c7 refine comments 2017-08-19 16:29:48 -07:00
Larry Bugbee
3794ecaf94 Update demo_dynamic.py
removed trailing spaces
2017-08-18 20:34:03 -07:00
Larry Bugbee
631de35ee3 Update and rename demo_dynamic.py3 to demo_dynamic.py
this version runs under python2 and python3 so only one version need be distributed
2017-08-17 21:11:59 -07:00
Larry Bugbee
ae16210939 Delete demo_dynamic.py 2017-08-17 21:06:50 -07:00
Steffen Jaeckel
d502c247db Merge pull request #271 from libtom/rel-1.18-sm-demo-cleanup
Rel 1.18 sm demo cleanup
2017-08-17 10:11:30 +02:00
Larry Bugbee
147a406243 Update demo_dynamic.py3
clean comments
2017-08-16 23:50:23 -07:00
Larry Bugbee
5d3e2d1e90 Update demo_dynamic.py
clean comments
2017-08-16 23:49:39 -07:00
Steffen Jaeckel
7a64e13845 Merge pull request #270 from libtom/minor_changes
Minor changes
2017-08-16 13:42:22 +02:00
Steffen Jaeckel
1fa8caff6c fix call to gettimeofday()
as of `man gettimeofday`
"The use of the timezone structure is obsolete;
the tz argument should normally be specified as NULL."
2017-08-16 11:52:40 +02:00
Steffen Jaeckel
bb9d397975 default ChaCha to ChaCha20 2017-08-16 11:49:25 +02:00
karel-m
385bae81a1 Merge pull request #266 from libtom/pr/fix-lint-issues
Fix lint issues
2017-08-13 18:16:55 +02:00
Karel Miko
de8a53a2e5 ocb3_test cosmetics
[skip ci]
2017-08-13 18:15:44 +02:00
Karel Miko
2a52c68f2e fix lint issues from #199 2017-08-13 14:54:39 +02:00
Steffen Jaeckel
daaab843f3 Merge pull request #263 from libtom/pr/crypt_sizes
missing items in crypt sizes
2017-08-11 13:27:23 +02:00
Larry Bugbee
6bbb450d40 remove trailing space 2017-08-11 02:17:31 -07:00
Larry Bugbee
8b703c1505 remove traling space for Travis 2017-08-11 02:16:26 -07:00
Larry Bugbee
bab115c631 converted demo_dynamic.py to Python3 2017-08-11 01:27:21 -07:00
Larry Bugbee
ee55c4e51c minor cleanup and formatting changes 2017-08-11 01:21:59 -07:00
Larry Bugbee
695c3b235d Update demo_dynamic.py
added error strings (with function returning a string type) and a decryption to ChCha.
2017-08-10 16:40:28 -07:00
Steffen Jaeckel
87d876f6ac add comment about usage to demo_dynamic
[skip ci]
2017-08-09 16:06:11 +02:00
Steffen Jaeckel
35925eada5 improve constants demo 2017-08-09 16:06:11 +02:00
Steffen Jaeckel
d5d4cadbde PKA_{D,R}SA shouldn't be public 2017-08-09 16:06:11 +02:00
Steffen Jaeckel
a247583e63 add error-codes to crypt_constants 2017-08-09 16:06:11 +02:00
Larry Bugbee
9f548c9928 update demo_dynamic.py 2017-08-09 16:06:11 +02:00
Steffen Jaeckel
91e5e8350b ltc_dh_set_type can be hidden as well 2017-08-09 16:06:11 +02:00
Steffen Jaeckel
d22b20833e we don't expose internal structs 2017-08-09 16:06:11 +02:00
Steffen Jaeckel
22822417c9 really define LTC_{DE,EN}CRYPT 2017-08-09 16:06:11 +02:00
Larry Bugbee
a3a199e14b update crypt_sizes.c 2017-08-09 16:06:11 +02:00
Larry Bugbee
7a2aabf47e update crypt_constants.c 2017-08-09 16:06:11 +02:00
Steffen Jaeckel
9f02fde06e improve sizes demo a bit 2017-08-09 16:06:11 +02:00
Karel Miko
b79ae63408 add missing items to crypt_sizes 2017-08-09 16:06:11 +02:00
Steffen Jaeckel
b5ab8ec811 update README.md a bit
[skip ci]
2017-08-09 15:55:15 +02:00
karel-m
231af66e03 Merge pull request #264 from libtom/pr/doxygen-warnings
fix doxygen warnings (as mentioned in #228)
2017-08-09 09:53:19 +02:00
Karel Miko
0286b36ad6 fix doxygen warnings (as mentioned in #228)
[skip ci]
2017-08-09 09:44:12 +02:00
Steffen Jaeckel
65dc00e23a align HASH_PROCESS() macro 2017-08-08 19:05:59 +02:00
Steffen Jaeckel
c29c9f140d disable DSA4096 timing tests when building for TFM
this fixes #260
2017-08-08 08:47:58 +02:00
Steffen Jaeckel
227838bb09 Merge pull request #261 from libtom/improve/test_without_mpi
make it possible to 'make all' w/o an MPI provider
2017-08-08 08:46:31 +02:00
Steffen Jaeckel
a65cfb8dbe make it possible to 'make all' w/o an MPI provider 2017-08-07 21:11:42 +02:00
Steffen Jaeckel
7993ce8e10 Merge pull request #262 from libtom/pr/ocb3-done-taglen-fix
ocb3_done taglen fix
2017-08-07 21:07:25 +02:00
Steffen Jaeckel
9139b59699 OCBv3: fix testvector generation 2017-08-07 19:43:09 +02:00
Steffen Jaeckel
9952fac68e tv.txt contains errors from tv_gen 2017-08-07 19:37:53 +02:00
Karel Miko
f647baa778 OCBv3: ocb3_init taglen check 2017-08-07 18:24:59 +02:00
Karel Miko
af63d0a55f OCBv3: improved handling of taglen in ocb3_done 2017-08-07 18:24:59 +02:00
Steffen Jaeckel
41130900d0 fix 1. help-line of openssl-enc
[skip ci]
2017-08-07 17:28:49 +02:00
Steffen Jaeckel
28ecdd5d12 minor improvements
[skip ci]
2017-08-07 16:33:38 +02:00
Steffen Jaeckel
ac4687d88d also put LTC_TEST_DBG in crypt_build_settings 2017-08-07 16:18:15 +02:00
Steffen Jaeckel
44076e3815 Merge branch 'fix/254' into release/1.18.0
This fixes #254
2017-08-07 16:05:38 +02:00
Steffen Jaeckel
7a59f71af8 fix warning
warning: 'ltc_asn1_type {aka enum ltc_asn1_type_}' is promoted to 'int' when passed through '...'
        type = va_arg(args, ltc_asn1_type);
note: (so you should pass 'int' not 'ltc_asn1_type {aka enum ltc_asn1_type_}' to 'va_arg')
note: if this code is reached, the program will abort
2017-08-07 16:04:57 +02:00
Steffen Jaeckel
32355d04bb fix endianness detection for some versions of gcc
This fixes #254
2017-08-07 16:04:57 +02:00
Steffen Jaeckel
9f020b17df limit malloc'ed data in eax_decrypt_verify_memory() 2017-08-07 16:04:36 +02:00
Steffen Jaeckel
05f7393067 Merge pull request #256 from libtom/fix/256
OCB3 is not according to RFC7253
2017-08-07 16:03:39 +02:00
Karel Miko
6ac1c5fa34 OCBv3: fix demos/timing failures 2017-08-07 07:48:21 +02:00
Steffen Jaeckel
3ecd18763b OCBv3: better taglen limitation 2017-08-03 13:40:57 +02:00
Steffen Jaeckel
3b4d39ea45 OCBv3: improve a bit when ARGCHK'ing pointers
* it didn't really make sense to check that the _in_ pointer is NULL
* instead we should check that _in_ and _out_ are not NULL when there's
  something to process
2017-08-03 13:40:26 +02:00
Steffen Jaeckel
868c5a82c3 OCBv3: fix handling of empty plaintext 2017-08-03 13:19:12 +02:00
Steffen Jaeckel
bc0c18f347 Update makefiles 2017-08-02 18:55:42 +02:00
Steffen Jaeckel
0c2ff4a1b0 OCBv3: small review
* better LTC_ARGCHK()
* move unnecessary functions from API to be static
* limit malloc'ed data in ocb3_decrypt_verify_memory()
2017-08-02 18:55:34 +02:00
Steffen Jaeckel
d77cf0e248 OCBv3: implement RFC7253 compliance
This fixes #256
2017-08-02 17:45:59 +02:00
Steffen Jaeckel
1aaa5abb33 ocb3: check the length of the nonce 2017-08-02 14:41:46 +02:00
Steffen Jaeckel
b2448c593a ocb3: properly handle empty AAD
* allow passing "no additional data" to ocb3_decrypt_verify_memory() and
  ocb3_encrypt_authenticate_memory()
* ensure that the caller didn't want to add AAD
2017-08-01 14:44:37 +02:00
Steffen Jaeckel
4805c89adb add ARGTYPE to crypt_build_settings 2017-08-01 14:21:11 +02:00
Michael Stapelberg
541ab1c16c Fix crypt.tex with newer TeXLive (thanks Norbert Preining)
See https://lists.debian.org/debian-tex-maint/2017/08/msg00000.html for details
2017-08-01 12:04:01 +02:00
Steffen Jaeckel
129bc7175f beautify dh & rsa 2017-07-21 10:16:19 +02:00
Steffen Jaeckel
6b925485a8 make sure to request an element which is always available 2017-07-20 13:34:16 +02:00
Steffen Jaeckel
ab8c5b8b49 fix help of {un,}install targets 2017-07-20 12:58:28 +02:00
Steffen Jaeckel
61eb98b76e add compile-time check for sprng requirements 2017-07-20 12:47:19 +02:00
Steffen Jaeckel
a46d6eb819 remove define of LTC_NO_FILE when defining LTC_NOTHING
it doesn't make sense to define this opt-out option especially
since there's no way to undefine it again.
2017-07-19 16:44:37 +02:00
Steffen Jaeckel
83407feaa6 Merge pull request #250 from libtom/pr/readme-building
README building instructions
2017-07-17 18:34:52 +02:00
Steffen Jaeckel
1e1170df29 move timing to BROKEN_DEMOS 2017-07-17 13:36:34 +02:00
Steffen Jaeckel
24c5b74193 introduce 'make help' 2017-07-17 13:36:34 +02:00
Steffen Jaeckel
bffaab4eed re-group demos and really build everything in 'all' target 2017-07-17 13:36:34 +02:00
Steffen Jaeckel
22c13b49d8 oops, refman.pdf can't be built with DOT 2017-07-17 13:36:34 +02:00
Steffen Jaeckel
0e081d666a improve error message when using makefile on Mac OSX
[skip ci]
2017-07-17 13:36:34 +02:00
Steffen Jaeckel
4cb8936a31 update readme
[skip ci]
2017-07-17 13:36:34 +02:00
Karel Miko
bfe6c4d35c improved README - building instructions
[skip ci]
2017-07-17 13:36:34 +02:00
karel-m
ff54ec2f0d Merge pull request #253 from libtom/pr/rc2-fix-win64
Fix MS Windows/64bit related warnings
2017-07-14 20:41:10 +02:00
Karel Miko
909b4954a9 fix MS Windows/64bit related warnings 2017-07-14 19:59:03 +02:00
Steffen Jaeckel
aa0f396c0c Update makefiles 2017-07-13 14:58:01 +02:00
Steffen Jaeckel
535358ec28 bump version 2017-07-13 14:57:45 +02:00
Steffen Jaeckel
89d0c64335 Merge pull request #247 from libtom/pr/custom_compile_flags
introduce LTC_CFLAGS and LTC_LDFLAGS
2017-07-13 14:34:05 +02:00
Steffen Jaeckel
a2f48578e9 also pre-pend -Itests 2017-07-12 22:48:46 +02:00
Steffen Jaeckel
a949ef5a89 append instead of prepend CFLAGS for the other makefiles 2017-07-11 15:37:31 +02:00
Steffen Jaeckel
b1c0227d54 introduce LTC_CFLAGS and LTC_LDFLAGS 2017-07-11 15:33:33 +02:00
Steffen Jaeckel
24e69b2956 more printf() clean-up
* remove last occurences in non-test code
* minimize in tests
2017-07-11 15:29:45 +02:00
Steffen Jaeckel
8b7edf5478 update DOT max values 2017-07-11 15:29:45 +02:00
Steffen Jaeckel
c6b93ae72e Merge branch 'pr/245' into release/1.18.0
This closes #245
2017-07-11 15:29:45 +02:00
Francois Perrad
37de73db01 add static _chc_process like in its prototype 2017-07-11 15:29:45 +02:00
Francois Perrad
53c62b3670 remove redundant prototypes
already declared in src/headers/tomcrypt_hash.h
2017-07-11 15:29:45 +02:00
Steffen Jaeckel
70f8a57f01 Merge pull request #249 from libtom/pr/dh-dsa-api
dh_set_key + dsa_set_key
2017-07-11 10:36:09 +02:00
Steffen Jaeckel
1819a02d5a update comments
[skip ci]
2017-07-11 10:32:53 +02:00
Karel Miko
e20e204b8c dh_set_key + dsa_set_key API change described in #248 2017-07-11 00:13:26 +02:00
karel-m
fa4713b68e Merge pull request #246 from libtom/pr/gcm-corner-cases
GCM allow skipping gcm_add_aad and gcm_process
2017-07-10 23:26:13 +02:00
Karel Miko
0792e3701e GCM allow skipping gcm_add_aad and gcm_process 2017-07-10 22:35:42 +02:00
Steffen Jaeckel
dd5996dd1f don't find the lo's to link, but use the list of objects 2017-07-10 10:20:36 +02:00
Steffen Jaeckel
221f7f223d add 'uninstall' make target
[skip ci]
2017-07-10 10:16:35 +02:00
Steffen Jaeckel
3806629e9e fix default make target 2017-07-09 17:34:45 +02:00
Steffen Jaeckel
4d897a36a3 Merge pull request #243 from libtom/pr/fix-chmod
Fix: chmod -x
2017-07-09 17:34:04 +02:00
Karel Miko
b89f3d8b5a fix: chmod -x notes/rsa-testvectors/*.txt 2017-07-09 16:22:28 +02:00
Karel Miko
2aa42f002f fix: chmod -x 2017-07-09 16:22:28 +02:00
Steffen Jaeckel
68bf547f9c use rsa_free() on error in rsa_make_key() 2017-07-09 16:02:11 +02:00
Steffen Jaeckel
749873c306 fix docs generation with TeX Live 2017
[skip ci]
2017-07-06 10:19:38 +02:00
Steffen Jaeckel
f15e0172ca Travis: also build master and 'release/*' branches 2017-07-05 14:43:21 +02:00
Steffen Jaeckel
e53858c740 update VERSION variables in makefiles
VERSION is now VERSION_PC
the new VERSION contains the entire string of SCRYPT
2017-07-05 14:30:17 +02:00
Steffen Jaeckel
a8965f048a Update makefiles 2017-07-05 14:30:17 +02:00
Steffen Jaeckel
fa5acee802 bump version 2017-07-05 14:30:17 +02:00
Steffen Jaeckel
d03635acab support patch-releases in helper.pl 2017-07-05 14:30:17 +02:00
Steffen Jaeckel
ac6f62badc update changes 2017-07-05 14:30:16 +02:00
Steffen Jaeckel
b59f066de3 update prng section in doc 2017-07-05 14:27:05 +02:00
Steffen Jaeckel
ac6fb72ef1 fix some doxygen headers 2017-07-05 14:27:05 +02:00
Steffen Jaeckel
6598dc0c3f update Doxyfile 2017-07-05 14:27:05 +02:00
Steffen Jaeckel
e1fcd3ab04 add hashsum multi-hash option 2017-07-05 14:26:53 +02:00
Steffen Jaeckel
ebc9d2943b Merge pull request #239 from libtom/pr/asn1-small-fixes
ASN.1 changes extracted from ECC stuff
2017-07-05 12:46:59 +02:00
Steffen Jaeckel
7d60fd2bfe don't expose der_length_sequence_ex() 2017-07-05 11:52:46 +02:00
Karel Miko
4bc1489584 small ASN.1 changes extracted from ECC stuff 2017-07-05 11:34:27 +02:00
Steffen Jaeckel
ce1ba58f00 Merge pull request #238 from libtom/proposal/ltc_pk_part
Re-factor X_import_radix() etc. API's
2017-07-05 11:33:17 +02:00
Steffen Jaeckel
c2f50459e2 better doc of radix_to_bin() 2017-07-05 10:25:01 +02:00
Steffen Jaeckel
4221c44fbc rename rand_bn_range() to rand_bn_upto() 2017-07-05 10:03:56 +02:00
Steffen Jaeckel
22919cd4f2 rand_bn_range(): count bits once 2017-07-04 10:58:10 +02:00
Steffen Jaeckel
8167b4d1cc Update makefiles 2017-07-04 10:30:50 +02:00
Steffen Jaeckel
a6aef23438 dh_make_key() is now dh_generate_key() 2017-07-04 10:30:39 +02:00
Steffen Jaeckel
e647f9a0e4 not good to check that prng is non-NULL
e.g. sprng() lives w/o context
2017-07-04 10:25:38 +02:00
Steffen Jaeckel
a0f2abc5b5 re-format 2017-07-04 10:25:38 +02:00
Steffen Jaeckel
a80abb1222 put dh_set_pg_dhparam() in own c file 2017-07-04 10:25:38 +02:00
Steffen Jaeckel
5640f8afc7 put dsa_set_pqg_dsaparam() in own c file 2017-07-04 10:25:38 +02:00
Steffen Jaeckel
3c2e0d6686 dsa_make_key_ex() is now dsa_generate_key() 2017-07-04 10:25:38 +02:00
Steffen Jaeckel
dbeaefd65b remove LTC_{DH,DSA}_KEY_INITIALIZER 2017-07-04 10:25:38 +02:00
Steffen Jaeckel
d1ecd82a42 use rand_bn_range() where possible 2017-06-28 20:50:21 +02:00
Steffen Jaeckel
bdfecc5f3c more doc updates 2017-06-28 16:45:29 +02:00
Steffen Jaeckel
d64880eeb1 add dsa_set_pqg_dsaparam() 2017-06-28 16:07:54 +02:00
Steffen Jaeckel
35e0c5fc71 clean-up a bit around DSA
* comments
* dsa_test()
* order of alloc/free of key parts
2017-06-28 16:07:32 +02:00
Steffen Jaeckel
1cce065676 Update makefiles 2017-06-28 14:44:17 +02:00
Steffen Jaeckel
0aad68c20d clean-up some PK tests
no need to test the same functionality multiple times
these tests were multiplied for the XX_import_radix() functions which
are gone now.
2017-06-28 14:44:06 +02:00
Steffen Jaeckel
cfff656e25 re-factor dsa_make_key() etc. 2017-06-28 14:40:30 +02:00
Steffen Jaeckel
24946d08b7 use mp_cleanup_multi() 2017-06-28 14:40:30 +02:00
Steffen Jaeckel
ed149c9396 add tests for radix_to_bin() 2017-06-28 14:40:30 +02:00
Steffen Jaeckel
76b9bba857 introduce mp_cleanup_multi() 2017-06-28 14:40:30 +02:00
Steffen Jaeckel
292f42d3c0 Merge pull request #227 from libtom/pr/dh_make_key_ex
DH facelift part 2 (dh_make_key_ex & co.)
2017-06-27 22:25:00 +02:00
Steffen Jaeckel
37ce78fdc8 Update makefiles 2017-06-27 22:10:10 +02:00
Steffen Jaeckel
f2f113880b also rename file 2017-06-27 22:10:07 +02:00
Steffen Jaeckel
c493a2a0a3 re-factor dh_export_radix() to dh_export_key() 2017-06-27 22:09:21 +02:00
Steffen Jaeckel
f226efc9a9 Update makefiles 2017-06-27 22:00:13 +02:00
Steffen Jaeckel
9d6689fc08 re-factor dh_make_key() and variants 2017-06-27 22:00:13 +02:00
Steffen Jaeckel
fbc54756c1 replace dh_import_radix() by dh_set_{pg,key} 2017-06-27 21:53:02 +02:00
Karel Miko
b3e535f933 update makefiles 2017-06-27 20:11:52 +02:00
Karel Miko
f60e2902ed dh_make_key_ex dh_export_radix dh_import_radix 2017-06-27 20:11:52 +02:00
Steffen Jaeckel
a42f467ff1 Update makefiles 2017-06-27 20:05:36 +02:00
Steffen Jaeckel
ae7d4d2947 re-factor rsa_test() to new rsa_set_X() API 2017-06-27 20:05:36 +02:00
Steffen Jaeckel
627f6696cb add radix_to_bin() 2017-06-27 20:05:36 +02:00
Steffen Jaeckel
6b798ca6a6 replace rsa_import_radix() by rsa_set_{key,factors,crt_params}() 2017-06-27 20:05:36 +02:00
Steffen Jaeckel
05e9f0ee79 Revert "use ltc_pk_part in rsa_import_radix()"
This reverts commit 023e4a2c23641d852cf47000948fa29a53249457.
2017-06-27 20:05:36 +02:00
Steffen Jaeckel
083e8af78b Revert "also test binary import"
This reverts commit 8b6f8c8cce325fa1ce3b61805aa80cdabc1826b4.
2017-06-27 20:05:36 +02:00
Steffen Jaeckel
4afc024f6a also test binary import 2017-06-27 20:05:36 +02:00
Steffen Jaeckel
bfae92e4ab use compare_testvector() in rsa_test() 2017-06-27 20:05:36 +02:00
Steffen Jaeckel
00a5212d99 use ltc_pk_part in rsa_import_radix() 2017-06-27 20:05:36 +02:00
Steffen Jaeckel
51ac4da8fc Merge pull request #241 from libtom/cleanup/4
Fourth general clean-up
2017-06-27 20:04:59 +02:00
Steffen Jaeckel
0a6af8d333 rsa_exptmod(): verify that p and q are valid before going the CRT path 2017-06-27 19:01:56 +02:00
Steffen Jaeckel
f5b8cc9dae this should really implement a patch for the illegal access 2017-06-27 12:35:39 +02:00
Steffen Jaeckel
1a3880fda5 Revert "re-factor size checks in blake2 implementations"
This reverts commit af38b1830e.
2017-06-27 12:33:40 +02:00
Steffen Jaeckel
af38b1830e re-factor size checks in blake2 implementations 2017-06-26 14:02:52 +02:00
Steffen Jaeckel
907d5301ee update coverity build script to use makefile.unix
it seems like the regular makefile is somehow broken...
2017-06-23 16:46:31 +02:00
Steffen Jaeckel
3cfb2a5e2e hide some of the 'new since 1.17' internal functions 2017-06-23 14:14:05 +02:00
Steffen Jaeckel
a80d3c00a8 no need for DH_BUF_SIZE 2017-06-23 14:05:57 +02:00
Steffen Jaeckel
c15d656a23 crypt{,.exe} is now ltcrypt{,.exe} 2017-06-23 14:05:57 +02:00
Steffen Jaeckel
e68d846429 hopefully finally fix usage of $(DESTDIR)
This closes #232
2017-06-23 14:05:57 +02:00
Steffen Jaeckel
cd6e602b48 Merge pull request #240 from fperrad/20170622_lint
more linting
2017-06-23 10:06:13 +02:00
Francois Perrad
446fec1bc4 refactor switch with default 2017-06-22 17:13:40 +02:00
Steffen Jaeckel
1725b87098 Merge pull request #234 from libtom/cleanup/3
Third general clean-up
2017-06-22 16:01:14 +02:00
Steffen Jaeckel
5ce602558f Revert "also use DESTDIR in makefile.m{ingw,svc}"
This reverts commit 1655e63c49.

As of @karel-m [1]

"I am not sure whether DESTDIR concept make sense for MS Windows
paths. For example: `make -f makefile.mingw DESTDIR=c:\builddir\
PREFIX=c:\installdir` means that `"$(DESTDIR)$(PREFIX)\bin"` will
expand to `"c:\builddir\c:\installdir\bin"` which is obviously
invalid.
I propose reverting `also use DESTDIR in makefile.m{ingw,svc}`."

[1] https://github.com/libtom/libtomcrypt/pull/234#issuecomment-310366602
2017-06-22 14:41:37 +02:00
Steffen Jaeckel
09c4d4c93b proper use of $(DESTDIR)
@rofl0r @ [1]

"...still it's unusual/unexpected to embed DESTDIR in LIBPATH
etc. where this could hickup is when for example hardcoded paths need
to be embedded into the resulting binary. for example, in the
netbsd-curses makefile i linked earlier, such a case would be reference
to the terminfo DB location, which is derived from PREFIX.
other possible cases might be stuff that dlopen()s its own libs using an
absolute path, or uses other data files. for such a case a contributor
would typically re-use DATAPATH oslt and put it into CPPFLAGS or write
it into a header, to find the required files. when now these paths have
DESTDIR in them too, this will not work. thus it is good practice to use
$(DESTDIR) only in install targets, and keep it out of other vars."


[1] 8e29a6061f (commitcomment-22678488)

This closes #232
2017-06-22 14:21:14 +02:00
Steffen Jaeckel
e3937a2906 fix compile warning when building w/o tests 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
11338d2496 introduce XMEMMOVE and check for its usage 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
e9c90e7f63 no need to use XMEM_NEQ() in PK crypto 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
ae698927ff improve mem_neq() documentation 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
1655e63c49 also use DESTDIR in makefile.m{ingw,svc} 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
af984dc33e exclude more sources from "static function check" 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
1bf42ea99a update some of the static functions 2017-06-22 14:21:14 +02:00
Karel Miko
8f433f1a36 add check for static function names 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
27b3ffc627 use compare_testvector() instead of XMEMCMP() in tests 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
05e28d6cfa fix potential timing attacks in rsa, eax, ocb and ocb3 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
b03b93099d allow to give only a part as parameter to ./test 2017-06-22 14:21:14 +02:00
Steffen Jaeckel
36132b016f update title page of pdf doc 2017-06-22 14:21:14 +02:00
karel-m
316450c20e Merge pull request #237 from libtom/pr/dh-facelift-part1
DH facelift part 1
2017-06-22 14:16:36 +02:00
Karel Miko
243a1dc33e drop _dh_make_key_ex 2017-06-22 13:19:48 +02:00
Karel Miko
cba1569c82 fix tomcrypt_pk.h 2017-06-22 13:19:48 +02:00
Karel Miko
a0257df999 update makefiles 2017-06-22 13:19:47 +02:00
Karel Miko
5eaff56d90 remove dh_export_radix.c dh_import_radix.c 2017-06-22 13:19:47 +02:00
Karel Miko
f4ce5a21c8 helper.pl - enable check_comments for --check-all 2017-06-22 13:19:47 +02:00
Karel Miko
f9802359c9 update makefiles 2017-06-22 13:19:47 +02:00
Karel Miko
771d67e102 DH facelift part1 2017-06-22 13:19:47 +02:00
Steffen Jaeckel
5e71ac27e2 Merge pull request #230 from libtom/math/miller-rabin
Fix number of Miller-Rabin rounds
2017-06-22 12:44:33 +02:00
Steffen Jaeckel
26b57032e7 use correct amount of M-R tests in dsa_make_params() 2017-06-22 11:55:08 +02:00
Steffen Jaeckel
7453eddae9 improve ltc_math_descriptor a bit
* introduce LTC_MILLER_RABIN_REPS which is used as default value
  in the isprime() implementations
2017-06-22 11:55:08 +02:00
karel-m
6f85293672 Merge pull request #235 from libtom/pr/ecc_sign+verify_hash_rfc7518
ECC ecc_sign+verify_hash_raw > ecc_sign+verify_hash_rfc7518
2017-06-21 14:33:37 +02:00
Karel Miko
ac02f7422b ecc_sign+verify_hash_rfc7518 tests 2017-06-21 13:43:25 +02:00
Karel Miko
b8f22157b3 PK_MAX_RETRIES 2017-06-21 13:38:39 +02:00
Karel Miko
0c115a162d whitespace 2017-06-21 13:26:52 +02:00
Karel Miko
fff832091f ecc_sign_hash max_iterations 2017-06-21 13:25:06 +02:00
Karel Miko
cdf04b6140 fix mp_montgomery_setup 2017-06-21 13:01:22 +02:00
Karel Miko
a937f23821 static functions name fix 2017-06-21 12:49:19 +02:00
Karel Miko
67200b641d ecc_sign+verify_hash_raw > ecc_sign+verify_hash_rfc7518 2017-06-21 12:11:35 +02:00
Steffen Jaeckel
c14bcf4d30 Merge pull request #233 from libtom/cleanup/2
Second general clean-up
2017-06-20 17:51:16 +02:00
Steffen Jaeckel
18c00ddcd6 better usage of find() 2017-06-20 15:16:11 +02:00
Steffen Jaeckel
5246c7de64 fix links in pdf doc 2017-06-20 15:16:11 +02:00
Steffen Jaeckel
8e29a6061f use {BIN,DATA,INC,LIB}PATH in makefile.unix 2017-06-20 15:16:11 +02:00
Steffen Jaeckel
6fc0a90a1e fix headers & footers in demos & tests 2017-06-20 15:16:11 +02:00
Steffen Jaeckel
4cd1355b8f more clean-up of headers/footers 2017-06-20 15:16:11 +02:00
Steffen Jaeckel
fe19dad623 replace SVN tags 2017-06-20 15:16:11 +02:00
Steffen Jaeckel
8c11490e2d fix usage of PREFIX vs. DESTDIR
This closes #232
2017-06-20 15:16:11 +02:00
Steffen Jaeckel
7597d20c78 use CROSS_COMPILE instead of PREFIX to indicate toolchain prefix 2017-06-20 15:16:11 +02:00
Steffen Jaeckel
b16066cbfc Add possibility to change install options
This closes #231
2017-06-20 15:16:11 +02:00
Steffen Jaeckel
66527b3e5e include "tomcrypt.h", not <tomcrypt.h>
we want to include the local version of the header, not the system-version
2017-06-20 15:16:11 +02:00
Steffen Jaeckel
fb35d5be54 more clean-up of headers 2017-06-20 15:16:11 +02:00
Steffen Jaeckel
4dc211e19d clean-up headers 2017-06-20 15:16:11 +02:00
Karel Miko
2fd5808897 timing - silence valgrind warning (memleak) 2017-06-20 01:33:23 +02:00
Karel Miko
e5f25b6553 tests+timing - silence valgrind warning (memleak) 2017-06-19 20:34:08 +02:00
Karel Miko
03437a1bdd timing - silence valgrind warning 2017-06-19 18:51:04 +02:00
Karel Miko
8dec4d9ac4 prng_test - silence valgrind warning 2017-06-19 12:28:22 +02:00
Steffen Jaeckel
cbc4260314 Merge pull request #229 from libtom/cleanup/1
First general clean-up
2017-06-15 10:31:14 +02:00
Steffen Jaeckel
f2076f0700 use zeromem() where appropriate 2017-06-15 01:07:44 +02:00
Steffen Jaeckel
258de3cecc use ltc_mp_digit instead of unsigned long 2017-06-15 01:07:44 +02:00
Steffen Jaeckel
d6e2a585d0 sync doc from ltc_math_descriptor 2017-06-15 01:07:44 +02:00
Steffen Jaeckel
98b500e873 update crypt_build_settings et al. 2017-06-15 01:07:44 +02:00
Steffen Jaeckel
0cf7c49045 sync ltc_math_descriptor from doc 2017-06-15 00:46:50 +02:00
Steffen Jaeckel
a0e5c2e4ff add some makefile docs 2017-06-15 00:46:50 +02:00
Steffen Jaeckel
3995f971d7 make sure to use makefile.shared on Mac 2017-06-15 00:46:50 +02:00
Steffen Jaeckel
048cbc55b0 disable yet another warning 2017-06-15 00:46:50 +02:00
Karel Miko
2cd69fb541 improved helper.pl (check mandatory comments - not included in "--check-all" yet) 2017-06-14 17:16:26 +02:00
Steffen Jaeckel
23d5a02ecd Merge pull request #217 from libtom/scan-build
Travis-CI: clang static analyzer
2017-06-14 09:19:19 +02:00
Steffen Jaeckel
31ddf7c894 ...
https://www.youtube.com/watch?v=6bbIBs0P2t0
2017-06-13 18:41:09 +02:00
Steffen Jaeckel
ac41d07247 try libtommath from ubuntu 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
ea08fbb777 use libtommath from debian sid 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
ba94b536be this is a horrible PR 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
1ee2662ab5 only run scan_build.sh once 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
52672bc358 m( 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
9baba0a83a fix usage of makefile.unix 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
ebfd164246 alright, let's also use ltm from packagecloud 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
3bb9193d6f alright, let's try if upgrading to trusty helps... 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
75e00e097c well, then install a new clang version and see... 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
ff2de0b07a looks like precise doesn't have scan-build under that name
...but we should be able to find it somewhere in /usr/bin/
2017-06-13 18:41:09 +02:00
Steffen Jaeckel
742b4cee78 add clang scan-build 2017-06-13 18:41:09 +02:00
Steffen Jaeckel
bda493d770 Merge pull request #226 from fperrad/20170609_lint
some linting

[skip ci]
2017-06-13 12:17:16 +02:00
Steffen Jaeckel
caa05540b7 Merge pull request #172 from libtom/test_tfm
Run tests for tomsfastmath

[skip ci]
2017-06-12 23:08:10 +02:00
Francois Perrad
0bc0d55245 refactor REGISTER_* 2017-06-12 20:07:23 +02:00
Francois Perrad
ec51f880b5 Right hand side of assignment needs parenthesis 2017-06-12 20:07:23 +02:00
Francois Perrad
f40bda7cb3 fix indentation 2017-06-12 20:07:23 +02:00
Steffen Jaeckel
f45f2f4faf only create coverage for ltm build 2017-06-12 18:45:24 +02:00
Steffen Jaeckel
a9838f7745 fix linking to tomsfastmath & clean-up 2017-06-12 18:45:24 +02:00
Steffen Jaeckel
104a451def use packagecloud repo to install tfm 2017-06-12 18:45:24 +02:00
Steffen Jaeckel
e2af986085 make output verbose again 2017-06-12 18:45:24 +02:00
Steffen Jaeckel
fec05471ae the latest tfm version has fp_rand() available, so we can test this now 2017-06-12 18:45:24 +02:00
Steffen Jaeckel
a4671110d5 Merge pull request #198 from libtom/test/pthread
Travis-CI: a new build with -DLTC_PTHREAD

[skip ci]
2017-06-12 18:44:01 +02:00
Steffen Jaeckel
5de7e58e84 disable yet another clang warning 2017-06-12 17:19:43 +02:00
Steffen Jaeckel
73934ad2fd add ld option -pthread when LTC_PTHREAD is enabled 2017-06-12 17:19:43 +02:00
Steffen Jaeckel
48e4ec07be use LTC_ARGCHK() for all mutex operations 2017-06-12 17:19:43 +02:00
Steffen Jaeckel
3b4e5df858 create separate no_prng instances
now they shouldn't collide anymore and can always be unregistered
2017-06-12 17:19:43 +02:00
Steffen Jaeckel
42a82ce3ed fix valgrind errors
Uninitialized key caused the following error:

Conditional jump or move depends on uninitialised value(s)
   at ...: __memcmp_sse4_1 (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
   ...
2017-06-12 17:19:43 +02:00
Steffen Jaeckel
a06cba4cb5 fix tests when compiled for pthread 2017-06-12 17:19:43 +02:00
Steffen Jaeckel
b38cf104f0 move prng-tests away from cipher_hash_test() 2017-06-12 17:19:43 +02:00
Steffen Jaeckel
904366eb0f check that all ciphers/hashes/prngs are unregistered 2017-06-12 17:19:43 +02:00
Steffen Jaeckel
be9c598ee7 add new travis tests with pthread support 2017-06-12 17:19:43 +02:00
Steffen Jaeckel
e6cd8e8112 fix failing tests with pthreads enabled 2017-06-12 17:19:43 +02:00
Steffen Jaeckel
d6a77f5d6d implement pthread support for tests 2017-06-12 17:19:43 +02:00
karel-m
4a6d107227 Merge pull request #225 from libtom/pr/fix-114-dh-primes
Better DH primes
2017-06-12 17:12:33 +02:00
Karel Miko
4f12e41d29 fix trailing ; 2017-06-12 16:35:27 +02:00
Karel Miko
114b694735 trying to fix dh_shared_secret - #119 2017-06-11 23:20:46 +02:00
Karel Miko
bc4236d90f tuning dh_make_key 2017-06-11 21:12:14 +02:00
Karel Miko
361778d2ac another dh_make_key redesign 2017-06-11 19:43:08 +02:00
Karel Miko
71884788e3 fix warning: comparison between signed and unsigned integer 2017-06-11 10:12:18 +02:00
Karel Miko
532c511f52 improved dh_make_key 2017-06-10 23:02:30 +02:00
Steffen Jaeckel
c9f4628693 don't call rng_make_prng() from dh_make_key()
While testing with multiple threads I had spurious errors where some tests
can't read from the PRNG.
If I tracked it down correctly that's caused by `dh_make_key()`
calling `rng_make_prng()` which re-initializes the selected PRNG.

I like the idea of "refreshing" the PRNG with entropy from a hopefully
secure RNG before generating a new key, but I don't think it's the duty
of a key-generation function to ensure that, but merely the application
that implements key-generation.
2017-06-09 18:56:04 +02:00
Steffen Jaeckel
e3329bec26 make it possible to pass a single timing test to run 2017-06-09 18:33:51 +02:00
Steffen Jaeckel
e60d2076c5 resurrect DH in timing 2017-06-09 18:33:51 +02:00
Steffen Jaeckel
f31d8ff864 implement smaller private key sizes 2017-06-09 18:33:51 +02:00
Karel Miko
f46b32ba2e better DH primes 2017-06-09 14:14:07 +02:00
karel-m
3922868082 Merge pull request #224 from libtom/pr/fix-154-dsa-api
Do not expose dsa_make_params as a public API
2017-06-09 14:13:04 +02:00
Karel Miko
2a883b44c7 do not expose dsa_make_params as a public API 2017-06-09 13:01:30 +02:00
Steffen Jaeckel
4fa9e96d49 Merge pull request #157 from libtom/feature/rsa_import_pkcs8
RSA import pkcs8

[skip ci]
2017-06-09 11:38:35 +02:00
Steffen Jaeckel
ef450fe14a fix error handling 2017-06-08 23:34:16 +02:00
Karel Miko
2d8816607b update makefiles 2017-06-08 23:34:16 +02:00
Karel Miko
52a496e9e1 rsa_import_pkcs8 - passwd is now "const void *" 2017-06-08 23:34:16 +02:00
Karel Miko
d96f4bdcff rsa_import_pkcs8 2017-06-08 23:34:16 +02:00
Steffen Jaeckel
2816da42af Merge pull request #219 from libtom/feature/common
Introduce testprof/common.c

[skip ci]
2017-06-08 23:30:28 +02:00
Karel Miko
d72d7d1d32 tuning makefile.mingw+msvc 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
f47a71bc6c Update makefiles 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
5a3a27bbd6 rename der_tests to der_test 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
4bbce780c4 always provide compare_testvector() as a function 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
ad45277745 use print_hex() in rsa_test() 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
e45e02d635 Update makefiles 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
4e971a8518 don't use print_hex() from library 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
fe0b72ef51 remove dependency of demos to tests/common 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
da3b61c7b6 re-structure tests/common.c 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
4ceb82bf54 add register_all_{ciphers,hashes,prngs}() 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
7f91e5ae65 requiring 'name != NULL' in find_cipher_any() doesn't make sense 2017-06-08 22:20:45 +02:00
Karel Miko
7aaa423004 tuning makefiles - mingw, msvc, cygwin 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
b51a3f6dab update notes/hashsum_tv.txt 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
8c1d55f4c0 fix error when compiling w/ LTC_CLEAN_STACK but w/o LTC_FAST 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
40747cfcfd add a build-run with debugging-options 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
b83f9472c0 Update makefiles 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
b78c5551f7 move compare_testvector() implementation to the library 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
e1a1145802 rename 'testprof/' to 'tests/' 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
07ffa0f1a2 remove tomcrypt_prof test-only library 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
201681ee3b merge testprof/timing_test.c into demos/timing.c 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
70a27a852e Update makefiles 2017-06-08 22:20:45 +02:00
Steffen Jaeckel
8ef805817c rename time_cipher[2-4]? appropriately 2017-06-08 22:20:44 +02:00
Steffen Jaeckel
9d4094b8e9 rename x86_prof.c to timing_test.c 2017-06-08 22:20:44 +02:00
Steffen Jaeckel
abe8d26246 move epoch_usec() to test.c 2017-06-08 22:20:44 +02:00
Steffen Jaeckel
f7d3c2bfa1 merge testprof/test_driver.c to testprof/common.c 2017-06-08 22:20:44 +02:00
Steffen Jaeckel
0a23c6d32e also check for cipher descriptors 2017-06-08 22:20:44 +02:00
Steffen Jaeckel
1c4c84e7f9 fix tv_gen 2017-06-08 22:20:44 +02:00
Steffen Jaeckel
3f66f7df83 Update makefiles 2017-06-08 22:20:44 +02:00
Steffen Jaeckel
eaf20dda5b demos must now link against testprof/common.o 2017-06-08 22:20:44 +02:00
Steffen Jaeckel
9b8fff6260 add testprof/common.c
so we can remove all the duplicate registration implementations
...and we can put some other shared stuff in there as well
2017-06-08 22:20:44 +02:00
Steffen Jaeckel
db5438ca55 don't build openssl-enc for tests 2017-06-08 22:19:48 +02:00
Steffen Jaeckel
08a461b39c also build openssl-enc 2017-06-08 21:32:10 +02:00
Steffen Jaeckel
4929860641 fix file modes 2017-05-31 01:57:40 +02:00
Steffen Jaeckel
1de3f2a1f6 correctly NOP
there's still mac_test() which doesn't NOP correctly but who cares anyway?
2017-05-30 11:20:18 +02:00
Steffen Jaeckel
f1118b4647 Merge pull request #222 from bmwiedemann/develop
sort input files
2017-05-29 18:18:57 +02:00
Bernhard M. Wiedemann
704055810f sort input files
when building packages (e.g. for openSUSE Linux)
(random) filesystem order of input files
influences ordering of functions in the output,
thus without the patch, builds (in disposable VMs) would differ.

See https://reproducible-builds.org/ for why this matters.
2017-05-29 14:58:07 +02:00
Steffen Jaeckel
04573d8100 Merge pull request #221 from ksherlock/echo-n
echo -n portability
2017-05-24 09:46:02 +02:00
Kelvin Sherlock
9913c1dcb8 AIX and OS X (and maybe BSD) sh has a built-in echo which doesn’t support the -n flag (OS X sh is actually bash but it doesn’t support -n based on compile-time flags and the POSIXLY_CORRECT environment variable).
AIX /bin/echo doesn’t support -n.

AIX echo and OS X /bin/echo support \c to prevent a trailing newline but linux echo (bash builtin and /bin/echo) don’t support it unless you also use the -e flag (which is not support by AIX /bin/echo or OS X sh or /bin/echo).

The BSD echo man page suggests using printf to avoid trailing newline, which is available on linux, OS X, and AIX.
2017-05-22 17:30:30 -04:00
Steffen Jaeckel
88eec86d1a Merge pull request #220 from ksherlock/compare_testvector
replace XMEMCMP with compare_testvector
2017-05-22 21:50:04 +02:00
Kelvin Sherlock
a8d81a7214 fix sha3 test numbers 2017-05-21 15:32:16 -04:00
Kelvin Sherlock
30f8aaad8c replace XMEMCMP with compare_testvector, other consistency cleanup in testing code. 2017-05-14 22:17:59 -04:00
Steffen Jaeckel
4efe229726 Merge pull request #208 from libtom/improve/makefiles
Re-work, improve & fix makefiles
2017-05-11 23:56:47 +02:00
Steffen Jaeckel
a12b97f84e travis doesn't seem to provide lcov... 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
90d5fe5bdb re-format .travis.yml
no sudo required to gem install
2017-05-11 23:04:37 +02:00
Steffen Jaeckel
56283c947a improve coverage creation 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
6a4978ef5e better EXTRALIBS 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
81f0297285 small fix-ups 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
7379c94f0a merge .include and .common makefiles 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
2c27aee5d4 fixup df733f79fa 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
ea67579298 further clean-up
- improve doc generation
- update version handling
  no need for VERSION_{MAJ,MIN}
2017-05-11 23:04:37 +02:00
Steffen Jaeckel
6cd8f2504b clean-up some makefiles
move shared variables between makefile and makefile.shared
  to makefile.include
2017-05-11 23:04:37 +02:00
Steffen Jaeckel
d996958133 move biggest part of install rules to makefile.common 2017-05-11 23:04:37 +02:00
Karel Miko
2b9dbb4ff7 cosmetics in makefile.unix|mingw|msvc 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
0cd9e94736 Partially revert "don't include testprof for library build"
This partially reverts commit 3a1cbcfee2a16d15167876423b6ca720458e801a.
2017-05-11 23:04:37 +02:00
Steffen Jaeckel
794a416715 fix libtomcrypt.pc installation 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
abe9116de5 introduce makefile.common 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
ee0874b50b minor improvements 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
3c5ec6b699 split-out binary installation in separate install target 2017-05-11 23:04:37 +02:00
Karel Miko
7ed5a832b0 tuning makefile.msvc+mingw 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
37fa03829c use gnu-make wildcard to get source files 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
12cf50d4e2 move translation rule after modifications of CFLAGS 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
39f12dafc4 make travis build a bit more verbose 2017-05-11 23:04:37 +02:00
Karel Miko
ab34b0bd93 or perhaps exclude .git* 2017-05-11 23:04:37 +02:00
Karel Miko
85197a485a do not exclude anything during make zipup 2017-05-11 23:04:37 +02:00
Karel Miko
add3495bfc fix perlcritics warnings in helper.pl 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
5e4415427a OSX touch has no "--reference" long-option, only "-r" 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
c93bee9575 rename perlcritic make target & also run helper.pl -a 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
b35ce0467b move documentation-related files to doc folder 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
6e484cd420 use make internal macros 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
c0abe2a5dc crypt doesn't exist anymore 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
8ee458b625 don't include testprof for library build
...well msvc still does it as I can't test it...
2017-05-11 23:04:37 +02:00
Steffen Jaeckel
1b71e23e42 fix some testprof related errors 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
544f7cc6ce ignore eclipse special files 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
ee17cc2e67 compress archive to xz 2017-05-11 23:04:37 +02:00
Karel Miko
1300c5ade5 make fixupind.pl part of helper.pl 2017-05-11 23:04:37 +02:00
Karel Miko
3176103c15 fix makefile.icc in makefile update scripts 2017-05-11 23:04:37 +02:00
Karel Miko
31cf796011 updated makefile.unix should work fine with Intel C compiler, so no need to keep an extra clone - makefile.icc 2017-05-11 23:04:37 +02:00
Karel Miko
9a3db508bb typo in "git commit: .." 2017-05-11 23:04:37 +02:00
Karel Miko
5c2bea093a zipup target facelift 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
3fd1771d35 also install useful demos 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
90daad0764 add new make-target 'bins'
so you can easily build the useful demos
2017-05-11 23:04:37 +02:00
Steffen Jaeckel
85dc39483f rename crypt to ltcrypt
a binary called crypt already exists and creates a name-clash as we won't
implement the entire CLI even if this tool implements similar functionality
2017-05-11 23:04:37 +02:00
Karel Miko
f544418d56 re-work makefile.mingw in the same style as makefile.unix 2017-05-11 23:04:37 +02:00
Karel Miko
c225f22a23 remove building dynamic libs from makefile.unix 2017-05-11 23:04:37 +02:00
Karel Miko
ceb7332631 typo 2017-05-11 23:04:37 +02:00
Karel Miko
3540eedb4a HP-UX make does not like ?= and $< 2017-05-11 23:04:37 +02:00
Karel Miko
bb4a051e40 makefile.unix facelift 2017-05-11 23:04:37 +02:00
Karel Miko
bf45ea66e5 drop the need for testprof/makefile* 2017-05-11 23:04:37 +02:00
Karel Miko
2c97498554 wipe out testprof/makefile* 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
93067e189a fix testprof/makefile.shared 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
7ac857686d add git version as compile flag 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
7898864b24 use glibtool on Macs 2017-05-11 23:04:37 +02:00
Steffen Jaeckel
d21d01bcb5 consolidate makefiles a bit 2017-05-11 23:04:37 +02:00
karel-m
c2bb38555e Merge pull request #218 from libtom/pr/fix-clang-static-analyzer-warnings
Clang static analyzer warnings/errors - related to #217
2017-05-11 22:55:39 +02:00
Karel Miko
43e46a2efc fix clang static analyzer warnings/errors - see #217 2017-05-11 20:37:06 +02:00
karel-m
08cc78007b Merge pull request #211 from libtom/pr/win32-rng_nix
Windows: fix various compiler warnings
2017-05-11 18:10:08 +02:00
Karel Miko
786853cb5c move #if defined(LTC_BASE64) 2017-05-11 17:42:43 +02:00
Karel Miko
ef6223f013 fix misleading-indentation warnings (mingw + gcc 7.1 + -Wall -Wextra) 2017-05-11 17:42:43 +02:00
Karel Miko
9d2b352867 fix ulong64 related format errors 2017-05-11 17:42:43 +02:00
Karel Miko
af4f6b374d better warning fix in der_tests 2017-05-11 17:42:43 +02:00
Karel Miko
9ba9677d94 x86_prof - spd1, spd2, avg are now ulong64 2017-05-11 17:42:43 +02:00
Karel Miko
a69e55ba54 tuning win warnings fixes 2017-05-11 17:42:43 +02:00
Karel Miko
e2cf11da25 fix windows warnings - #212 and #213 2017-05-11 17:42:43 +02:00
Karel Miko
6d70827d1f Windows: fix warning: 'rng_nix' defined but not used 2017-05-11 17:42:43 +02:00
karel-m
55a7eead7f Merge pull request #215 from libtom/pr/lint-20170509
Another fixes related to  #199
2017-05-10 19:36:20 +02:00
Karel Miko
91b61630be improved #ifdefs - related to: 'num' not referenced 2017-05-09 21:43:28 +02:00
Karel Miko
04262d3aec fix: local struct member 'poly_div' not referenced 2017-05-09 21:31:12 +02:00
Karel Miko
f6ea738fee fix: Loss of sign (initialization) (int to unsigned long long) 2017-05-09 21:30:44 +02:00
karel-m
b439f83018 Merge pull request #210 from libtom/pr/aix-fix
IBM xlc compiler related fixes
2017-05-05 19:58:14 +02:00
Karel Miko
421266cf5f fix void *orig 2017-05-05 19:57:20 +02:00
Karel Miko
adf0ad95c9 IBM xlc compiler does not like "static inline" (related to #209) 2017-05-05 19:57:20 +02:00
Steffen Jaeckel
87be6d3d70 Merge pull request #203 from libtom/improve/crypt
Improve hashsum
2017-05-04 16:03:57 +02:00
Steffen Jaeckel
85c2186ae6 better output on stderr 2017-05-03 18:10:46 +02:00
Steffen Jaeckel
e9923129c8 fix LTC_EASY compilation 2017-05-03 18:10:46 +02:00
Steffen Jaeckel
b472ef31a2 looks like the previous output was not really shaXsum compatible... 2017-05-03 18:10:46 +02:00
Steffen Jaeckel
28f8a85246 update coverage.sh
* hashsum requires now a '-a' option flag for the algorithm
* '-h' is required to output the list of algorithms to stdout
* the algorithms are printed in columns, so we have to sort differently
2017-05-03 18:10:46 +02:00
Steffen Jaeckel
9893566ae9 add shasum compatibility for '-a' option 2017-05-03 18:10:45 +02:00
Steffen Jaeckel
ea7115dc65 implement file checking 2017-05-03 18:10:45 +02:00
Steffen Jaeckel
31dcb9ff2a only set outlen on success 2017-05-03 18:10:45 +02:00
Steffen Jaeckel
d02531d4d2 improve hashsum a bit 2017-05-03 18:10:45 +02:00
karel-m
1712c0eae1 Merge pull request #205 from libtom/pr/shake-be-fix
SHAKE (SHA3 related) big endian fix
2017-05-03 17:06:27 +02:00
Karel Miko
4e66160ac2 one more readable for loop 2017-05-03 17:01:18 +02:00
Karel Miko
f831e27702 more readable for loops 2017-05-03 12:56:25 +02:00
Karel Miko
a1615daa3c shake be fix (hopefully final) 2017-05-03 12:56:25 +02:00
Karel Miko
961b6109d5 cosmetics 2017-05-03 12:56:25 +02:00
Karel Miko
da8501f55a sha3_shake_done another be fix 2017-05-03 12:56:25 +02:00
Karel Miko
c3f2e4530a declaration of ‘i’ shadows a previous local (better) 2017-05-03 12:56:25 +02:00
Karel Miko
df4e47978e declaration of ‘i’ shadows a previous local 2017-05-03 12:56:25 +02:00
Karel Miko
e5c0e7ffd3 SHAKE (SHA3 related) big endian fix 2017-05-03 12:56:25 +02:00
Steffen Jaeckel
67ca1c0b9a fix for compilation with LTC_DEBUG 2017-05-03 12:37:24 +02:00
karel-m
d936273711 Merge pull request #207 from libtom/feature/pkcs1ssl
PKCS #1 v1.5 padding - No ASN.1
2017-05-02 09:17:16 +02:00
Karel Miko
f00f857224 tests for rsa_sign|verify with LTC_PKCS_1_V1_5_NA1 2017-05-01 23:17:32 +02:00
Steffen Jaeckel
aa4bae5ae9 add option to do PKCS#1 v1.5 EMSA without ASN.1 around hash
Somehow someone forgot to add the OID in the signature field
of a SERVER_KEY_EXCHANGE message in early versions of the SSL protocol.
Therefore provide an option to be able to sign/verify a message
in that format.
2017-05-01 23:15:11 +02:00
Steffen Jaeckel
25878ed632 Merge pull request #202 from fperrad/20170430_lint
more linting
2017-05-01 22:07:51 +02:00
Francois Perrad
a52b586ed2 Unusual use of a Boolean expression 2017-05-01 14:51:35 +02:00
Steffen Jaeckel
2858373e2e clean stack properly 2017-05-01 14:12:47 +02:00
Steffen Jaeckel
3e2ac192a1 Merge pull request #200 from fperrad/20170429_lint
LTC_PTHREAD: some linting
2017-05-01 14:08:59 +02:00
karel-m
91c0071b6b Merge pull request #201 from libtom/pr/lint-20170429
lint fixes discussed in #199
2017-04-30 09:43:47 +02:00
Karel Miko
87142382da lint fixes discussed in #199 2017-04-29 19:59:03 +02:00
Francois Perrad
7e72dafe5f remove useless semicolon
the macro LTC_MUTEX_TYPE already contains a semicolon
see https://github.com/libtom/libtomcrypt/blob/develop/src/headers/tomcrypt_custom.h#L552
2017-04-29 17:52:27 +02:00
karel-m
253f3c45e1 Merge pull request #186 from libtom/pr/stream_rc4_sober128
Move rc4 + sober128 to src/stream/
2017-04-29 15:50:38 +02:00
Karel Miko
6417f96ea9 fortuna - import does not fail when input data are larger than export_size 2017-04-29 14:12:36 +02:00
Karel Miko
d7f2b2dd6e fortuna - move LBL_UNLOCK before zeromem 2017-04-29 13:39:48 +02:00
Karel Miko
c6cee7bef0 prngs/sober128 - import fix 2017-04-29 13:36:45 +02:00
Karel Miko
9c972c833d fix chacha20poly1305_test 2017-04-29 13:30:19 +02:00
Karel Miko
eb209aa2f9 more error checking in *_test 2017-04-28 19:24:58 +02:00
Karel Miko
90b482aa1e stream/chacha - improved counter increment 2017-04-28 19:24:58 +02:00
Karel Miko
9232f2e970 fortuna/yarrow & export_size 2017-04-28 19:24:58 +02:00
Karel Miko
1732ed8ce8 increase coverage 2017-04-28 19:24:58 +02:00
Karel Miko
784a009efe increase coverage 2017-04-28 19:24:58 +02:00
Karel Miko
da25a23712 increasing prngs/rc4 coverage 2017-04-28 19:24:58 +02:00
Karel Miko
28927be1dd typo LTC_CHACHA_PRNG / LTC_CHACHA20_PRNG 2017-04-28 19:24:58 +02:00
Karel Miko
0df0c9b12c LTC_CHACHA_STREAM >> LTC_CHACHA 2017-04-28 19:24:58 +02:00
Karel Miko
dd35e86c60 renaming rc4+sober128 stream API to *_stream_* 2017-04-28 19:24:58 +02:00
Karel Miko
28835a513f update makefiles 2017-04-28 19:24:58 +02:00
Karel Miko
fe14c8bfaf Move RC4 + SOBER128 to src/stream/ 2017-04-28 19:24:58 +02:00
Steffen Jaeckel
93317a1d6a Merge pull request #54 from libtom/feature/doc
Feature/doc (only crypt.tex + changes)
2017-04-26 00:23:34 +02:00
Steffen Jaeckel
0094552828 add doc for ASN.1 GeneralizedTime 2017-04-25 21:23:25 +02:00
Steffen Jaeckel
57c703b14c update doc process a bit
* remove crypt.pdf from repo
* ignore generated PDF's
* make refman.pdf generation silent
2017-04-25 21:23:25 +02:00
Kelvin Sherlock
b234e6b4ca add missing hash descriptors to the documentation. sha1 no longer recommended. 2017-04-25 21:23:25 +02:00
Steffen Jaeckel
8e03799eb6 fix/improve doxygen generation 2017-04-25 21:23:25 +02:00
Steffen Jaeckel
6c1d614a92 update Doxyfile to a more recent version of doxygen 2017-04-25 21:23:25 +02:00
Steffen Jaeckel
434280587a also apply the verbosity settings to the doc generation 2017-04-25 21:23:25 +02:00
Michael Stapelberg
deeea5a1ec fix crypt.tex with newer LaTeX: s/here/h/g
See https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=790321 for context
2017-04-25 21:23:24 +02:00
Steffen Jaeckel
84606ab8de minor spelling corrections 2017-04-25 21:23:24 +02:00
Pascal Brand
1cf965cfcc Add doc for CCM Authentication full set of functions
Change-Id: I2830ea3c04fd0410cc12137be41e6c511c4a47fe
2017-04-25 21:23:24 +02:00
Steffen Jaeckel
699f52418e don't use SHA1
@buggywhip is right

[skip ci]
2017-04-25 21:23:24 +02:00
Steffen Jaeckel
17b961e554 update changes document
include changes proposed by @buggywhip
fix typos

[skip ci]
2017-04-25 21:23:24 +02:00
Steffen Jaeckel
6a47cb5931 describe behavior of the flexi decoder on unknown identifiers 2017-04-25 21:23:24 +02:00
Steffen Jaeckel
627aef962c add documentation of ASN.1 context-specific decoding 2017-04-25 21:23:24 +02:00
Steffen Jaeckel
3233e51a23 update documentation regarding RSA key import/export 2017-04-25 21:23:24 +02:00
Steffen Jaeckel
2a98d0a11f adapt dynamic language documentation to modified API and functionality 2017-04-25 21:23:24 +02:00
Larry Bugbee
d2047f4b61 added sec 11.3, dynamic lang support 2017-04-25 21:23:24 +02:00
Steffen Jaeckel
3c8743e102 add SHA512/t documentation 2017-04-25 21:23:24 +02:00
Steffen Jaeckel
a5d95448e1 use ulong32 resp. ulong64 in the tables of the Macros section
This closes #16
2017-04-25 21:23:23 +02:00
Steffen Jaeckel
1367c1d685 fix build error 2017-04-25 21:23:23 +02:00
Steffen Jaeckel
d010f19587 add documentation of the new RSA API functions 2017-04-25 21:23:23 +02:00
Steffen Jaeckel
331f76c0ec add documentation of the newly added ASN.1 types 2017-04-25 21:23:23 +02:00
Steffen Jaeckel
df8814dfef some minor corrections/improvements 2017-04-25 21:23:23 +02:00
Steffen Jaeckel
e212f04f0f trim trailing spaces 2017-04-25 21:23:23 +02:00
Steffen Jaeckel
82ea2ee3da update changes document 2017-04-25 21:23:23 +02:00
Steffen Jaeckel
f73a342b17 oops, it's not yet released
[skip ci]
2017-04-25 21:23:23 +02:00
Steffen Jaeckel
f44c972b10 update changes document
[skip ci]
2017-04-25 21:23:23 +02:00
Steffen Jaeckel
4d35336e38 more documentation 2017-04-25 21:23:22 +02:00
Steffen Jaeckel
94f1b407d1 start updating documentation 2017-04-25 21:23:22 +02:00
Karel Miko
0d998fd4c8 stream/chacha ivlen cosmetics 2017-04-25 01:10:15 +02:00
karel-m
e4793b50d0 Merge pull request #193 from libtom/pr/mac-blake2
BLAKE2 based MACs
2017-04-25 00:11:45 +02:00
Karel Miko
0f0f1e40be indentation 2017-04-24 21:59:21 +02:00
Karel Miko
3ea8a00ecd new multi_test 2017-04-23 23:29:10 +02:00
Karel Miko
08ea7fc0f4 demos/multi.c -> testprof/multi_test.c 2017-04-23 23:27:54 +02:00
Karel Miko
d587b380e6 updating demos/multi.c 2017-04-23 23:27:54 +02:00
Karel Miko
61105b67f4 test vectors from https://github.com/BLAKE2 2017-04-23 23:27:54 +02:00
Karel Miko
1c68bf9a74 update file_test 2017-04-23 23:27:54 +02:00
Karel Miko
f767ea3dcd update makefiles 2017-04-23 23:27:54 +02:00
Karel Miko
0d585958c1 BLAKE2 based MACs 2017-04-23 23:27:54 +02:00
Steffen Jaeckel
76fbac87e2 Merge pull request #195 from libtom/pr/hashes
improve hashsum
2017-04-23 23:24:11 +02:00
Steffen Jaeckel
943c7a7cfc use hash_filehandle() to read from stdin 2017-04-23 22:37:32 +02:00
Steffen Jaeckel
a6b8e52c43 make output equal to output of sha1sum etc. 2017-04-23 17:32:21 +02:00
Steffen Jaeckel
4ddee31de7 run hashsum for all hash algorithms 2017-04-23 16:10:01 +02:00
Steffen Jaeckel
7a83cea4db use appropriate names for sha3 hashes 2017-04-23 15:55:49 +02:00
karel-m
7ad6fcfa63 Merge pull request #194 from libtom/pr/helperpl-check-hashes
helper.pl --check-hashes + related fixes
2017-04-21 21:21:19 +02:00
Karel Miko
6d404afc97 helper.pl --check-hashes + related fixes 2017-04-21 21:20:31 +02:00
Steffen Jaeckel
75f2529cdf also run multi for coverage 2017-04-21 19:45:59 +02:00
Steffen Jaeckel
290926fe8a include CFLAGS when building demos 2017-04-21 19:45:59 +02:00
karel-m
65ace1a378 Merge pull request #184 from libtom/pr/file-related-tests
Facelift of *_file functions
2017-04-21 17:20:41 +02:00
Karel Miko
dae70f9ba4 update testprof/makefile* 2017-04-21 16:12:41 +02:00
Karel Miko
d1ae2889ae add file_test() 2017-04-21 16:12:18 +02:00
Karel Miko
336c52ca5f Facelift of *_file functions 2017-04-21 16:11:22 +02:00
Steffen Jaeckel
513fcf35fe Merge pull request #191 from ksherlock/blake2s
blake2s hash
2017-04-20 21:03:14 +02:00
Kelvin Sherlock
609d0afd00 updated hash_tv.txt 2017-04-20 12:28:38 -04:00
Kelvin Sherlock
56a2efa729 fix blake2s-160/224 hash sizes. 2017-04-20 11:22:16 -04:00
Kelvin Sherlock
4f7264135f update test vectors 2017-04-20 09:36:35 -04:00
Kelvin Sherlock
0109e3ca78 update tv_gen.c 2017-04-19 17:03:34 -04:00
Kelvin Sherlock
4905232eda more tests. 2017-04-19 16:50:34 -04:00
Kelvin Sherlock
c65d24222e always zeromem hash_state when done 2017-04-19 16:47:03 -04:00
Kelvin Sherlock
2dc574d477 use - in hash descriptors. 2017-04-19 16:46:36 -04:00
Kelvin Sherlock
4ee9d767bb add key/keylen parameters to blake2x_init 2017-04-10 18:29:51 -04:00
Kelvin Sherlock
0f97bb7415 fix burn blake2b stack size. 2017-04-10 16:37:34 -04:00
Kelvin Sherlock
55450078ea use compare_testvector in tests. 2017-04-10 12:00:22 -04:00
Kelvin Sherlock
ea8dde7f63 formatting 2017-04-10 11:34:59 -04:00
Kelvin Sherlock
dfbdb626c3 add missing const. 2017-04-10 10:50:34 -04:00
Kelvin Sherlock
6b46b447b5 replace packed parameter struct with offsets into a unsigned char buffer. 2017-04-10 10:40:20 -04:00
Kelvin Sherlock
6acdfe9a55 cleanup, resins with updated reference source 2017-04-10 10:22:50 -04:00
Kelvin Sherlock
afc6e8d370 minor cleanup. 2017-04-10 10:21:51 -04:00
Kelvin Sherlock
b4594ab3c6 remove inline and c99 variable declarations. 2017-04-09 17:22:42 -04:00
Kelvin Sherlock
268c87e33d add LTC_ARGCHK for blake2b_process. 2017-04-08 17:00:39 -04:00
Kelvin Sherlock
b412ab539a update makefiles for blake2b. 2017-04-08 15:44:30 -04:00
Kelvin Sherlock
6f6e2d30a8 clang-format 2017-04-08 15:43:38 -04:00
Kelvin Sherlock
7c5fef9b71 add blake2b hash 2017-04-08 15:40:56 -04:00
Kelvin Sherlock
5924bd43e6 tweak source to conform a little better 2017-04-08 15:40:20 -04:00
Kelvin Sherlock
b0e9a23e31 makefile updates. 2017-04-07 23:47:16 -04:00
Kelvin Sherlock
51075724c1 use hash_state * for all arguments. 2017-04-07 23:46:52 -04:00
Kelvin Sherlock
063df0bffe more tests. 2017-04-07 23:46:17 -04:00
Kelvin Sherlock
4449cdcea3 sort and number the ltc_hash_descriptors. 2017-04-07 23:45:49 -04:00
Kelvin Sherlock
1b5ae955d2 moe clang-format 2017-04-07 21:24:47 -04:00
Kelvin Sherlock
51f6b063d6 clang format 2017-04-07 21:12:54 -04:00
Kelvin Sherlock
647b53d880 add blake2s to various places. 2017-04-07 20:50:28 -04:00
Kelvin Sherlock
68296e0608 blake2s hash 2017-04-07 20:47:44 -04:00
Steffen Jaeckel
904eee0975 Merge pull request #190 from fperrad/20170407_lint
chacha: more linting
2017-04-07 18:49:47 +02:00
Francois Perrad
b6c27c2f08 no room for nul terminator 2017-04-07 12:16:48 +02:00
Francois Perrad
0be45a6341 remove unreachable code 2017-04-07 12:16:44 +02:00
Steffen Jaeckel
13b2220c61 Merge pull request #189 from fperrad/20170406_lint
remove suspicious ;
2017-04-07 10:35:11 +02:00
Francois Perrad
9941648125 remove suspicious ; 2017-04-07 00:17:43 +02:00
Steffen Jaeckel
08415d37f3 fix compare_testvector() macro 2017-04-06 22:47:36 +02:00
Steffen Jaeckel
e4331bcc17 Merge pull request #188 from fperrad/20170405_lint
misuse of compare_testvector
2017-04-06 22:46:24 +02:00
Francois Perrad
168472f753 misuse of compare_testvector 2017-04-05 09:28:32 +02:00
karel-m
fbe7d222c3 Merge pull request #185 from libtom/pr/chacha_prng-chacha20_prng
chacha_prng > chacha20_prng
2017-04-04 00:47:17 +02:00
Karel Miko
eefb8dc479 renaming prngs/chacha.c prngs/chacha20.c 2017-04-03 22:54:27 +02:00
Karel Miko
bfe9484a3d renaming chacha_prng > chacha20_prng 2017-04-03 22:52:17 +02:00
karel-m
5199b54635 Merge pull request #171 from libtom/pr/chacha20poly1305
RFC 7539 - ChaCha20 and Poly1305 + ChaCha20 based PRNG
2017-04-03 21:21:20 +02:00
Karel Miko
2520e6c061 add link to arc4random.c which was the inspiration for chacha_prng 2017-04-03 20:04:00 +02:00
Karel Miko
7b93f04390 wrong use of sizeof(buf) 2017-04-03 19:54:51 +02:00
Karel Miko
ce37498ec6 chacha_prng_desc > chacha20_prng_desc 2017-04-03 19:52:03 +02:00
Karel Miko
08a028ab04 missing LTC_FILE_READ_BUFSIZE in crypt.c 2017-04-02 18:13:45 +02:00
Karel Miko
883db95da2 FILE_READ_BUFSIZE > LTC_FILE_READ_BUFSIZE 2017-04-02 18:13:45 +02:00
Karel Miko
06b1582de6 new #define FILE_READ_BUFSIZE 2017-04-02 18:13:45 +02:00
Karel Miko
ff5b02d371 LTC_CHACHA vs. LTC_CHACHA20_PRNG 2017-04-02 18:13:45 +02:00
Karel Miko
2656a040e0 chacha_prng > chacha20_prng 2017-04-02 18:13:45 +02:00
Karel Miko
3a05f0331d chachapoly_state > chacha20poly1305_state 2017-04-02 18:13:45 +02:00
Karel Miko
11a9dc50b3 poly_state > poly1305_state 2017-04-02 18:13:45 +02:00
Karel Miko
39028bbeed more tests in chacha20poly1305_test 2017-04-02 18:13:45 +02:00
Karel Miko
31b52a354d padlen in chacha20poly1305_decrypt 2017-04-02 18:13:45 +02:00
Karel Miko
5797b0cc1e test for chacha_ivctr64 (2) 2017-04-02 18:13:45 +02:00
Karel Miko
53c00d14e5 test for chacha_ivctr64 2017-04-02 18:13:45 +02:00
Karel Miko
a517db2514 cosmetics 2017-04-02 18:13:45 +02:00
Karel Miko
3cfb58c2f4 update makefiles 2017-04-02 18:13:45 +02:00
Karel Miko
c8cb714e08 added chacha_done 2017-04-02 18:13:45 +02:00
Karel Miko
ff6abc776c RFC 7539 - ChaCha20 and Poly1305 + chacha based PRNG 2017-04-02 18:13:45 +02:00
Karel Miko
6844275e82 silence MSVC compiler warning 2017-04-02 17:42:28 +02:00
Karel Miko
df733f79fa removing VS2005 residual that should be removed in #168 2017-04-02 17:42:22 +02:00
Steffen Jaeckel
e3b5a858c3 Merge pull request #182 from libtom/feature/generalizedtime
add GeneralizedTime DER processing
2017-03-31 20:22:38 +02:00
Steffen Jaeckel
78a32430d4 more tests 2017-03-31 18:24:42 +02:00
Steffen Jaeckel
2c52bf75f4 bugfixing 2017-03-31 18:24:42 +02:00
Steffen Jaeckel
08503a02f5 update error codes
This closes #180
2017-03-31 15:12:12 +02:00
Steffen Jaeckel
1f0daf1eff fix compiler warning 2017-03-31 00:57:22 +02:00
Steffen Jaeckel
83780d4764 add timezone-offset support to GeneralizedTime
this also fixes a bug in the length generation
2017-03-30 22:48:42 +02:00
Steffen Jaeckel
59b4026fa7 Update makefiles 2017-03-30 22:29:02 +02:00
Steffen Jaeckel
2bd517307c add GeneralizedTime DER en-/decode 2017-03-30 22:29:02 +02:00
Steffen Jaeckel
f7cb199066 add test proposed by @karel-m 2017-03-30 22:29:02 +02:00
Steffen Jaeckel
77019928dd Merge pull request #79 from libtom/feature/rsa_import_x509
RSA import x509
2017-03-30 22:28:24 +02:00
Steffen Jaeckel
ac7915ed13 Update makefiles 2017-03-30 18:46:05 +02:00
Steffen Jaeckel
856d542a1c turn around the order when free'ing an rsa_key struct 2017-03-30 18:46:05 +02:00
Steffen Jaeckel
ec327b3d86 move x509 processing to rsa_import_x509() 2017-03-30 18:46:05 +02:00
Steffen Jaeckel
019a9e9850 add stinky certificate 2017-03-30 18:46:04 +02:00
Steffen Jaeckel
27722734b2 let's use an empty list element to signal an empty sequence 2017-03-30 18:46:04 +02:00
Steffen Jaeckel
39b2a8daca add tests for new functionality of der_encode_flexi() and rsa_import() 2017-03-30 18:46:04 +02:00
Steffen Jaeckel
f9bce83329 add possibility to rsa_import() the public key of an x.509 certificate 2017-03-30 18:46:04 +02:00
Steffen Jaeckel
2e822a80a8 add der_sequence_shrink()
in case you want to keep a sequence over a longer time, but you don't
need all the raw constructed, set or sequence data
2017-03-30 18:46:04 +02:00
Steffen Jaeckel
7ddce245b8 save the plain constructed-, sequence- or set-data details 2017-03-30 18:46:04 +02:00
karel-m
0a400f465f Merge pull request #181 from libtom/pr/demo-test-facelift 2017-03-30 16:59:43 +02:00
Karel Miko
2a2968ae92 demos/test facelift 2017-03-30 16:56:10 +02:00
Steffen Jaeckel
4874430dec send travis notifications to #libtom-notifications 2017-03-30 15:49:04 +02:00
karel-m
4bcd48411a Merge pull request #173 from libtom/pr/sha3 2017-03-29 13:46:04 +02:00
Karel Miko
c6a0362c88 SHA3 2017-03-29 13:44:04 +02:00
karel-m
1b81848576 Merge pull request #168 from libtom/pr/msvc-cleanup
Improving MS Windows builds (msvc)
2017-03-29 09:07:58 +02:00
Karel Miko
7bb7bdde1d improving MS Windows builds (msvc) 2017-03-29 08:48:33 +02:00
Steffen Jaeckel
783cbc7917 Merge branch 'fix/25' into develop
This closes #25
2017-03-28 22:57:35 +02:00
Steffen Jaeckel
d153d1303a Update makefiles 2017-03-28 22:57:22 +02:00
Steffen Jaeckel
8af93d1d0d Remove ccm_memory_ex() 2017-03-28 22:57:22 +02:00
Steffen Jaeckel
363a57fc87 Merge branch 'fix/6' into develop
This closes #6 & #179
2017-03-28 22:55:49 +02:00
Steffen Jaeckel
8518b56dbf Revert "fix rotate_test to pass rotate by zero with LTC_NO_ASM"
This reverts commit 82080f0b87.
2017-03-28 21:18:22 +02:00
Steffen Jaeckel
70ee598c5e fix LTC_NO_ASM rotate macros when compiling with clang 2017-03-28 21:18:22 +02:00
Karel Miko
82080f0b87 fix rotate_test to pass rotate by zero with LTC_NO_ASM 2017-03-27 22:03:33 +02:00
Karel Miko
e5aa2bd453 added rotate_test 2017-03-27 19:32:05 +02:00
Steffen Jaeckel
7532b89a6d Merge pull request #177 from libtom/pr/177
Add -Wdeclaration-after-statement to travis-ci tests
2017-03-26 23:47:42 +02:00
Steffen Jaeckel
862a02767d fix constants and sizes demo 2017-03-26 21:38:02 +02:00
Steffen Jaeckel
101a7a71ae enable -Wdeclaration-after-statement by default 2017-03-26 19:30:18 +02:00
Steffen Jaeckel
7885c91af3 print math provider when running tests 2017-03-26 15:46:41 +02:00
Steffen Jaeckel
ea355dbc79 there's no reason to disable DH when using GMP as MPI provider 2017-03-24 16:58:04 +01:00
Steffen Jaeckel
ba338eced8 also build executables in makefile.shared from template 2017-03-24 16:42:49 +01:00
Karel Miko
b465881b58 fix "declaration-after-statement" warnings (tests only) 2017-03-24 10:17:02 +01:00
Steffen Jaeckel
fd1e351316 Merge pull request #78 from libtom/idea/ltc_rng
add ltc_rng function pointer
2017-03-22 12:16:46 +01:00
Karel Miko
15db3eab59 fix travis failure 2017-03-22 11:24:21 +01:00
Steffen Jaeckel
27f8e8bf75 Update makefiles 2017-03-22 11:24:21 +01:00
Steffen Jaeckel
cd08a8cec3 disable ltc_rng by default 2017-03-22 11:24:21 +01:00
Steffen Jaeckel
fcae7e2c49 test the ltc_rng 2017-03-22 11:24:21 +01:00
Steffen Jaeckel
fe7c4e3993 add ltc_rng function pointer
the idea is to be able to easily provide a plug-in rng for a specific
platform without the need to touch the library.
2017-03-22 11:24:21 +01:00
Steffen Jaeckel
a00aba8370 add pre-commit hook 2017-03-22 11:21:49 +01:00
Steffen Jaeckel
f7bd454dd5 Revert "add release flag to makefile.shared"
This reverts commit 14272976d0.

This is neither a 'package-internal library' nor
one 'whose interfaces change very frequently' so we remove the
release information again from the shared library.
2017-03-22 11:21:39 +01:00
Karel Miko
283ea0c426 improving helper.pl 2017-03-21 19:56:43 +01:00
karel-m
63e6f7647f Merge pull request #169 from libtom/pr/more-src-checks
Improved source checks
2017-03-15 23:14:40 +01:00
Karel Miko
39425a94c5 improved source checks 2017-03-15 23:13:46 +01:00
Steffen Jaeckel
9babf374ee add '-c' option (again) to updatemakes.sh 2017-03-15 22:21:53 +01:00
karel-m
6df687403a Merge pull request #167 from libtom/pr/avoid-cpp-style-comments
avoid C++ style comments
2017-03-15 15:22:40 +01:00
Karel Miko
54a26525dc avoid C++ style comments 2017-03-15 15:22:06 +01:00
Karel Miko
db32cc3a81 Merge branch 'fperrad-20170315_lint' into develop 2017-03-15 13:07:54 +01:00
karel-m
bda8019862 Merge pull request #161 from libtom/pr/83-polished
Just polished #83 (Add OpenSSL-Compatible PKCSv5#1)
2017-03-15 09:05:58 +01:00
Karel Miko
3396513e81 improving demos/openssl-enc.c 2017-03-15 08:59:49 +01:00
Francois Perrad
937f186db1 use #ifdef instead of #if 2017-03-15 06:55:19 +01:00
Karel Miko
4503868da2 fix pkcs_5_test crash 2017-03-14 18:22:46 +01:00
Karel Miko
0e9b3da3ea PKCS#5 alg1 tests 2017-03-14 18:22:46 +01:00
BJ Black
c7d6c3ad28 Add OpenSSL-compatible PKCS#5v1 KDF, demo of OpenSSL-compatible aes-256-cbc command. 2017-03-14 18:22:46 +01:00
karel-m
bbe54053ec Merge pull request #109 from libtom/fix/109-alternative-approach
crc32 test fails on ppc64 BE (tomcrypt_cfg.h facelift)
2017-03-14 18:18:44 +01:00
Karel Miko
e26078d2f7 fix #109 - improved arch/endianness detection + tomcrypt_cfg.h facelift 2017-03-14 18:14:57 +01:00
karel-m
44f29d895c Merge pull request #164 from libtom/pr/wchar-warnings-visual-studio-2008
fix wchar_t related warnings on Visual Studio 2008
2017-03-09 21:01:26 +01:00
Karel Miko
591ef19c7a comment: it might happen that LTC_WCHAR_MAX is undefined 2017-03-09 20:48:24 +01:00
Karel Miko
02b92405e2 simplified #ifdef 2017-03-09 20:48:24 +01:00
Karel Miko
7ab76a464e introducing LTC_WCHAR_MAX 2017-03-09 20:48:24 +01:00
Karel Miko
2f9c426487 fix wchar_t related warnings on Visual Studio 2008 2017-03-09 20:48:24 +01:00
karel-m
78e9b0fca8 Merge pull request #122 from libtom/fix/122
adler32 vs. crc32 inconsistency
2017-03-09 20:33:13 +01:00
Karel Miko
a4d61e0bea fixes #122 adler32 vs. crc32 inconsistency (bad byte order) 2017-03-09 20:32:29 +01:00
karel-m
33e1c4acca Merge pull request #158 from libtom/pr/check-makefiles
check makefiles (check_source.sh)
2017-03-09 20:29:28 +01:00
Karel Miko
84f2557cc2 updatemakes.sh newline at end of file 2017-03-09 20:19:54 +01:00
Karel Miko
6f9e427f77 comment with aes_enc "hack" (but still disabled for MS Win *.vcproj builds) 2017-03-09 20:19:53 +01:00
Karel Miko
df258453ba msvc sorting hack 2017-03-09 20:19:52 +01:00
Karel Miko
c260954b52 ordering file list whe generating msvc.proj 2017-03-09 20:19:51 +01:00
Karel Miko
8c831e1e30 no aes_enc on ms windows 2017-03-09 20:19:50 +01:00
Karel Miko
2711e40309 updatet MSVC projects 2017-03-09 20:19:48 +01:00
Karel Miko
58375b0287 updatemakes.sh now updates MS Visual C++ projects as well 2017-03-09 20:19:47 +01:00
Karel Miko
421a241ccf travis script - check wheather makefiles are updated 2017-03-09 20:19:46 +01:00
karel-m
14a7ed4609 Merge pull request #156 from libtom/improve/tests
Improve tests
2017-03-09 20:10:50 +01:00
Steffen Jaeckel
ea1228d3ab I like aligned output :)
...and I dislike c&p'ed code
2017-03-09 20:09:55 +01:00
Steffen Jaeckel
90da7e71e1 There's no need running the same test multiple times
If there would be some random input okay, but like that it's just running
the same functionality over and over again.
2017-03-09 20:09:55 +01:00
karel-m
4ef8c27031 Merge pull request #163 from libtom/pr/xts_test-move-declaration
move declaration at block beginning (+msvc 2008 tuning)
2017-03-09 20:08:45 +01:00
Karel Miko
ac3f55fd92 there is no snprintf before Visual C++ 2015 2017-03-09 20:07:39 +01:00
Karel Miko
52eaabefa9 msvc 2008 does not like { } initialization 2017-03-06 19:53:04 +01:00
Karel Miko
fb749199db moving declaration to block beginning 2017-03-06 19:51:46 +01:00
Karel Miko
081ee45712 move declaration at block beginning 2017-03-06 10:43:39 +01:00
karel-m
456908eb90 Merge pull request #159 from libtom/fix/159
Travis-CI + the latest libtommath
2017-03-02 19:45:13 +01:00
Steffen Jaeckel
2277b420f0 also install binutils from debian-sid 2017-03-02 12:18:47 +01:00
Steffen Jaeckel
f94ee4a5a7 location of new libtommath.a has changed 2017-03-02 11:41:01 +01:00
Steffen Jaeckel
8c90cba6f6 install libtommath-dev from debian sid 2017-03-02 11:27:39 +01:00
Karel Miko
61ae75a823 sort filenames on perl level during updatemakes.sh 2017-03-01 22:07:28 +01:00
Steffen Jaeckel
1e977e662f fix updatemakes.sh indentation 2017-03-01 17:52:05 +01:00
Steffen Jaeckel
199ff63e5f add '-c' option to updatemakes.sh 2017-03-01 16:00:35 +01:00
Steffen Jaeckel
2df86d65e8 don't execute coverage script for private travis 2017-03-01 15:19:34 +01:00
Steffen Jaeckel
d4cc79011b Merge branch 'pr/crc32-declaration-block-beginning' into develop
This closes #155
2017-03-01 15:03:16 +01:00
Karel Miko
1a1addcefd move declarations at the block beginning (ANSI C) 2017-03-01 15:02:08 +01:00
Steffen Jaeckel
9092470843 fix doxygen warnings 2017-03-01 15:00:41 +01:00
Steffen Jaeckel
3dd0845dec Merge pull request #139 from libtom/fix/139
rand_prime undefined reference when using  CFLAGS="-DLTM_DESC -DLTC_EASY
2017-03-01 14:58:35 +01:00
Steffen Jaeckel
4f120531ab add separate CHECK_SOURCES build target 2017-03-01 14:09:29 +01:00
Karel Miko
631a11cd35 removing "checking white spaces" part from build.sh 2017-03-01 14:00:45 +01:00
Karel Miko
be9c66ab43 tuning build.sh to handle -DLTC_EASY 2017-03-01 13:35:19 +01:00
Karel Miko
856be9cae8 tv_gen needs more #ifdefs 2017-03-01 12:09:50 +01:00
Karel Miko
dde11de781 fixing compile failure in demos for -DLTC_EASY 2017-03-01 11:48:39 +01:00
Steffen Jaeckel
00308d8651 fix base64url related errors when only LTC_BASE64 is defined 2017-03-01 11:37:49 +01:00
Steffen Jaeckel
0b79bbaf5b fix missing symbol rand_prime 2017-03-01 11:37:49 +01:00
Steffen Jaeckel
6cfc27d310 add EASY build to tests 2017-03-01 11:37:49 +01:00
Karel Miko
50aedb099c fixing warning introduced by __WCHAR_MAX__ patch 2017-02-28 23:20:19 +01:00
Karel Miko
b3534def42 Merge branch 'fperrad-20170225_lint' into develop 2017-02-28 23:07:31 +01:00
Francois Perrad
eca2290b1e missing prototypes 2017-02-28 23:07:06 +01:00
Francois Perrad
27280b86b3 static functions 2017-02-28 23:07:06 +01:00
Steffen Jaeckel
acfd16c60a fix compile error 2017-02-28 21:23:39 +01:00
karel-m
c8c0898bcb Merge pull request #149 from libtom/feature/travis_clang
Add clang to the travis build matrix
2017-02-28 20:30:15 +01:00
Steffen Jaeckel
3dbd250bc9 Add clang to the travis build matrix 2017-02-28 20:29:36 +01:00
karel-m
2edc0aeb66 Merge pull request #152 from libtom/pr/wchar-troubles-max-FFFF
better handling wchar_t when __WCHAR_MAX__ is 0xFFFF (2 bytes only)
2017-02-28 20:27:03 +01:00
Karel Miko
4bd327a4cc better handling wchar_t when __WCHAR_MAX__ is 0xFFFF (2 bytes only) 2017-02-28 20:24:49 +01:00
Karel Miko
05f85c3e6d RS2 remove 40bit limit 2017-02-28 20:20:51 +01:00
Karel Miko
797031170d Merge branch 'fix/135' into develop 2017-02-28 20:17:11 +01:00
Steffen Jaeckel
03f0674985 add compare_testvector() prototype to tomcrypt_misc.h 2017-02-28 20:09:32 +01:00
Steffen Jaeckel
9a29428f8e Add secondary rc2 setup function
...to be able to pass the effective key length.
2017-02-28 20:09:32 +01:00
Steffen Jaeckel
43c50423ad add yet another testvector 2017-02-28 20:09:32 +01:00
Steffen Jaeckel
952caf3cd7 add testvectors for smaller RC2 keysizes
originates from rfc2268

1 byte keylen is commented
2017-02-28 20:09:32 +01:00
Steffen Jaeckel
19c81bbbee fix typo 2017-02-28 20:09:32 +01:00
Karel Miko
344620a0e7 fixes #135 RC2 min keylen 40bit (was 64bit) 2017-02-28 20:09:32 +01:00
Karel Miko
e96a895d0d Merge branch 'fperrad-perlcritic' into develop 2017-02-28 20:00:25 +01:00
Francois Perrad
808616d406 sanitize some Perl scripts
(Perl4 is gone)
2017-02-28 19:59:58 +01:00
karel-m
4cdc304e37 Merge pull request #153 from libtom/fix/54-part1
part of feature/doc changes from #54
2017-02-28 19:53:03 +01:00
Karel Miko
6c8d00d1fd part of feature/doc changes 2017-02-28 17:35:57 +01:00
karel-m
b44aa8fa83 Merge pull request #151 from libtom/pr/adler32-declaration-block-beginning
move declarations at the block beginning (ANSI C)
2017-02-28 16:41:05 +01:00
Karel Miko
efbd73fbc8 move declarations at the block beginning (ANSI C) 2017-02-28 16:11:42 +01:00
karel-m
6596746c5d Merge pull request #150 from libtom/pr/conversion-related-troubles
conversion related troubles (int, size_t, ptrdiff_t ..)
2017-02-28 11:38:32 +01:00
Karel Miko
88412a9fc2 conversion related troubles (int, size_t, ptrdiff_t ..) 2017-02-28 11:30:19 +01:00
karel-m
8141ca617a Merge pull request #106 from libtom/fix/106
_base64_decode_internal not compliant with RFC4648
2017-02-28 01:28:44 +01:00
Steffen Jaeckel
abf0a18290 add some testcases 2017-02-28 01:27:07 +01:00
Steffen Jaeckel
eee936d752 add base64url_strict_encode() 2017-02-28 01:27:06 +01:00
Karel Miko
006c601efb no trailing = for base64url 2017-02-28 01:27:05 +01:00
Karel Miko
ff3a03a1d0 tuning base64 decoding implementation 2017-02-28 01:27:04 +01:00
Steffen Jaeckel
c1dd1cbe30 re-work strict/relaxed base64 decoding implementation
Instead of one API function with an option parameter, provide two API
functions.
Instead of defaulting to strict decoding, default to relaxed decoding.
2017-02-28 01:27:03 +01:00
Steffen Jaeckel
53359ccfc6 fix failing test 2017-02-28 01:27:02 +01:00
Steffen Jaeckel
bc16c149fc fix base64[url] strict/relaxed decode 2017-02-28 01:27:01 +01:00
Steffen Jaeckel
063bac396d add LTC_BASE64_STRICT to crypt_build_settings and crypt_constants 2017-02-28 01:27:00 +01:00
Steffen Jaeckel
1c0edfdead add/fix tests
add explicit strict&loose base64-decode tests
2017-02-28 01:26:58 +01:00
Steffen Jaeckel
b10f9502f8 add RFC4648 base64 decoding compliance 2017-02-28 01:26:57 +01:00
karel-m
30382d0e31 Merge pull request #144 from libtom/fix/coverity-dsa_import-double-free
fix coverity finding: dsa_import double free
2017-02-28 01:17:18 +01:00
Karel Miko
faa18e71c8 tuning indentation 2017-02-28 00:51:25 +01:00
Karel Miko
1e260eeaae fir coverity finding: dsa_import double free 2017-02-28 00:51:25 +01:00
Karel Miko
6499c70492 Merge branch 'mattkelly-fix-clang-cast-align-warnings' into develop 2017-02-27 18:13:44 +01:00
Steffen Jaeckel
ce1043c55d ignore warnings of clang created by my stdlib 2017-02-27 18:12:22 +01:00
Matt Kelly
e187f4cbf4 Fix all warnings from -Wcast-align 2017-02-26 10:12:16 -05:00
karel-m
d777f9d1dc Merge pull request #145 from libtom/fix/coverity-cbc_decrypt-out-of-bounds-read
fix coverity finding: cbc_decrypt out-of-bound read
2017-02-25 20:44:47 +01:00
Karel Miko
7246ab50da fix coverity finding: cbc_decrypt out-of-bound read 2017-02-25 19:53:52 +01:00
karel-m
7c2cc079ec Merge pull request #146 from libtom/fix/85-part3
Fix for #85 (part3)
2017-02-25 13:23:03 +01:00
Francois Perrad
4349993ad3 Suspicious use of & (part 2) 2017-02-25 13:21:34 +01:00
Karel Miko
824f3af98c check-source.pl cosmetics 2017-02-24 20:57:47 +01:00
Karel Miko
c911427cf2 check-source.pl script for checking whitespace related troubles 2017-02-24 20:51:31 +01:00
Karel Miko
953080bcea more trailing spaces + tabs outside of "src" dir 2017-02-24 20:50:37 +01:00
Karel Miko
477d621224 more trailing spaces + tabs in src 2017-02-24 20:31:48 +01:00
karel-m
f60e045034 Merge pull request #143 from libtom/fix/85-part2
Fix/85 part2
2017-02-24 19:04:46 +01:00
Francois Perrad
fc55a8fd1b remove trailing spaces 2017-02-24 19:02:43 +01:00
Francois Perrad
b0f06ed1ec add parenthese in macro 2017-02-24 19:00:36 +01:00
Francois Perrad
79d6e61aca use the variable 'err' 2017-02-24 19:00:32 +01:00
Francois Perrad
31f88a9c9b default for switch 2017-02-24 19:00:28 +01:00
Francois Perrad
203087d6d7 bug: wrong parentheses in condition with assignment 2017-02-24 19:00:24 +01:00
Karel Miko
649ef0faef forgotten trailing space 2017-02-24 16:54:01 +01:00
karel-m
01bb22e865 Merge pull request #142 from libtom/fix/85-part1
Fix/85 part1
2017-02-24 16:35:19 +01:00
Francois Perrad
58353f51e2 remove trailing spaces 2017-02-24 16:29:54 +01:00
Francois Perrad
5d7036ebe2 remove hard tab 2017-02-24 16:26:48 +01:00
Francois Perrad
9f8df116be remove useless code 2017-02-24 16:23:27 +01:00
Francois Perrad
cebf33cdce add some const 2017-02-24 16:23:23 +01:00
Francois Perrad
9749958fe5 the comment FALLTHROUGH is common for several lint tool 2017-02-24 16:23:19 +01:00
Francois Perrad
c22acc2d07 remove useless include 2017-02-24 16:23:15 +01:00
Francois Perrad
7b48f4d5f7 fix indentation 2017-02-24 16:23:10 +01:00
Steffen Jaeckel
ecb2402ba8 remove [X]CLOCKS_PER_SEC 2017-02-24 00:28:59 +01:00
Karel Miko
979e9a9d15 fix for #90 ltc_ecc_mul2add.c integer sign issue (sjaeckel's way) 2017-02-24 00:18:55 +01:00
Karel Miko
0c226834cc introducing LTC_INLINE 2017-02-23 23:47:56 +01:00
Steffen Jaeckel
c39390dba1 Merge branch 'fix/132' into develop
This closes #132
2017-02-23 11:04:10 +01:00
Karel Miko
3d5b90d24d LTC_NO_PROTOTYPES related cosmetics 2017-02-23 11:03:55 +01:00
Steffen Jaeckel
76b289833c only define LTC_NO_PROTOTYPES on one point
This closes #132
2017-02-23 11:03:55 +01:00
Steffen Jaeckel
ef023f3329 fix rsa/dsa test duplicate symbols 2017-02-21 17:32:30 +01:00
Steffen Jaeckel
fa4637e7a9 Merge branch 'fix/97' into develop
This closes #97
2017-02-21 16:57:38 +01:00
Steffen Jaeckel
55776b0ac9 update makefiles 2017-02-21 16:57:21 +01:00
Karel Miko
bbbbf5f1d5 adding rsa_import_radix tests 2017-02-21 16:55:10 +01:00
Karel Miko
a2c87f54de adding rsa_import_radix 2017-02-21 16:55:09 +01:00
Steffen Jaeckel
0cf80ef631 Merge branch 'fix/98' into develop
This closes #98
2017-02-21 16:54:25 +01:00
Karel Miko
ac6f69e8fe adding dsa_import_radix tests 2017-02-21 16:54:11 +01:00
Steffen Jaeckel
43517bca83 update makefiles 2017-02-21 16:54:11 +01:00
Karel Miko
10545366d2 adding dsa_import_radix 2017-02-21 16:54:10 +01:00
Steffen Jaeckel
a8df316581 Merge branch 'pr/133' into develop
This closes #133
2017-02-21 16:45:12 +01:00
Karel Miko
bcf7753a26 use MIN macro 2017-02-21 16:36:17 +01:00
Karel Miko
ecbac7324e DSA: properly handle FIPS 186-4 (4.6 + 4.7) 2017-02-21 16:36:17 +01:00
Steffen Jaeckel
498538f6ef Merge pull request #103 from libtom/fix/103
Serious bug in rng_get_bytes @ MS Windows
2017-02-21 14:39:54 +01:00
Karel Miko
b36e75b7f1 don't read from c:\dev\random on windows 2017-02-21 13:34:52 +01:00
Steffen Jaeckel
d727b16898 use proper defines as of [1]
[1] http://predef.sourceforge.net
2017-02-21 13:34:52 +01:00
Steffen Jaeckel
5757fdb035 Merge branch 'pr/124' into develop
This closes #124
2017-02-21 11:50:25 +01:00
zeromus
c341d36c6a do it differently 2017-02-21 11:49:35 +01:00
zeromus
32f19995f8 do it differently 2017-02-21 11:49:35 +01:00
zeromus
793ff08986 do it differently 2017-02-21 11:49:35 +01:00
zeromus
c83763bd46 fix tiny compile error in tomcrypt_pk.h macro
An ARM compiler gives me this: 

libtomcrypt\pk\asn1\der\sequence\der_decode_subject_public_key_info.c(65,4): error #188-D: enumerated type mixed with another type

Since der_decode_subject_public_key_info's parameters_type is of type 'unsigned long', an attempt to assign it to ltc_asn1_list's member 'ltc_asn1_type type' fails.

My fix solves this in a simple way by casting it at the point of assignment.

But while studying this I noticed there's no use of enum in the codebase other than a few PK-related things.  Perhaps a more appropriate solution would be to remove these enums. I mean, enums seem like an OK enough idea, but I don't know anything about the practicality of using enums in archaic C dialects like libtomcrypt conforms (thankfully!) to...
2017-02-21 11:49:35 +01:00
Steffen Jaeckel
600004fecc print ascii in print_hex() 2017-02-21 11:42:24 +01:00
Steffen Jaeckel
60bb5440fb add compare_testvector() 2017-02-21 11:42:24 +01:00
Steffen Jaeckel
383f200cb6 fix LTC_MINIMAL 2017-02-20 19:19:44 +01:00
Steffen Jaeckel
fd99c3e3c0 remove duplicate define 2017-02-20 18:58:20 +01:00
Steffen Jaeckel
08aabc7f8c improve print_hex() prototype 2017-02-17 11:53:14 +01:00
Steffen Jaeckel
8fc1af1b7e make implementation easier to read
damn you negated logic...
2017-02-15 23:15:43 +01:00
Steffen Jaeckel
f784793891 Merge pull request #129 from libtom/fix/gcm_counter_reuse
GCM counter incrementation isn't stopped at 2^32 blocks, which breaks GCM
2016-10-02 20:51:01 +02:00
Steffen Jaeckel
7d418b34b3 Fix GCM counter reuse
GCM should error out after processing (2^32)-1 blocks / (2^39)-256 bits
2016-09-28 20:18:09 +02:00
Karel Miko
6ad5225268 removing forgotten debug comment 2016-07-07 15:03:33 +02:00
Steffen Jaeckel
bb56ef08eb bring coverage results near reality 2016-04-03 17:45:16 +02:00
Steffen Jaeckel
892342c769 automatically determine the number of parallel make jobs for the tests 2016-04-03 14:12:27 +02:00
Steffen Jaeckel
da3ade0807 increase coverage by running 'sizes' and 'constants' 2016-04-03 14:12:27 +02:00
Steffen Jaeckel
1c6c02e18d fix gitignore 2016-04-03 14:12:27 +02:00
Steffen Jaeckel
f2f1b61164 Merge pull request #115 from fperrad/install
install without USER and GROUP
2016-04-03 01:46:24 +02:00
Francois Perrad
5d5694dbc4 install without USER and GROUP
like in libtommath.
really more friendly for packaging.
2016-04-01 09:26:28 +02:00
Steffen Jaeckel
912eff4949 make testprof/makefile silent 2016-01-23 19:11:30 +01:00
Steffen Jaeckel
61d730323a introduce new all_test make-target 2016-01-23 19:11:30 +01:00
Steffen Jaeckel
23cad07701 refactor makefile a bit more 2016-01-23 19:00:23 +01:00
Steffen Jaeckel
d1eeecb137 fix some compiler warnings 2016-01-23 18:59:44 +01:00
Steffen Jaeckel
4572357e87 make easily built demos in a template 2016-01-23 18:59:30 +01:00
Steffen Jaeckel
7c9450084f fix some compile errors 2016-01-23 18:42:50 +01:00
Steffen Jaeckel
3184c6d8a0 Merge branch 'miko-GCM-HPUX-IA64-fix' into develop
This closes #100
2016-01-23 18:11:01 +01:00
Karel Miko
966496ea1a fixing GCM troubles at HP-UX/IA64 2016-01-23 18:09:03 +01:00
Steffen Jaeckel
a6417387c0 make check_defines silent 2016-01-23 17:06:57 +01:00
Steffen Jaeckel
6905e4113f make build process silent 2016-01-19 00:38:05 +01:00
Steffen Jaeckel
de15a6fad9 Merge branch 'miko-const-int-fix' into develop
This closes #92 and closes #96
2016-01-19 00:04:27 +01:00
Karel Miko
af77f1fae9 RORc instead of ROR 2016-01-19 00:03:54 +01:00
Karel Miko
d0a534393a fix for issue #92 - const is meaningless on cast type 2016-01-19 00:03:54 +01:00
Steffen Jaeckel
4a3b53dbee Merge branch 'miko-avoid-declaration-after-statements' into develop
This closes #101
2016-01-14 21:47:16 +01:00
Karel Miko
15b3f39a4f avoid using declaration after statements (rng_win32) 2016-01-14 21:46:53 +01:00
Karel Miko
7c1e251e75 avoid using declaration after statements 2016-01-14 21:46:53 +01:00
Steffen Jaeckel
f108863dc3 Merge branch 'miko-ecc_ansi_x963_export-fix' into develop
This closes #58 and closes #99
2016-01-14 21:33:04 +01:00
Steffen Jaeckel
10e577e24a there's no need to check out on function entry
...someone could then do something like this...

unsigned char* out = NULL;
unsigned long len = 0;
while(ecc_ansi_x963_export(key, out, &len) == CRYPT_BUFFER_OVERFLOW &&
	len == 0) {
  out = malloc(len);
}

...as if someone would ever like to do something like that...
2016-01-14 21:32:33 +01:00
Karel Miko
42bad9f580 fix for issue #58 - possible overflow in ecc_ansi_x963_export 2016-01-11 00:25:13 +01:00
Steffen Jaeckel
af70cb6a01 Merge remote-tracking branch 'km/miko-setbit-fix' into develop
This closes #91
2016-01-11 00:23:25 +01:00
Karel Miko
8cf7eb1801 fix for issue #91 - redefinition of macro "setbit" 2016-01-10 18:45:04 +01:00
Steffen Jaeckel
7c2ff8ebfe show ROtate operator configuration in build settings
[skip ci]
2016-01-05 23:55:06 +01:00
Steffen Jaeckel
645a82d9e6 travis: update local package index as first step 2016-01-05 23:24:47 +01:00
Steffen Jaeckel
012dfe8001 Make the build output cleaner so diagnostics are easier to spot
Signed-off-by: Tom St Denis <tstdenis82@gmail.com>
Signed-off-by: Steffen Jaeckel <s@jaeckel.eu>
2015-12-05 14:31:38 +01:00
Steffen Jaeckel
8def190877 Merge branch 'fix/hkdf' into develop
This fixes #81
2015-12-05 14:31:38 +01:00
Steffen Jaeckel
f5016d88dd Prevent undefined behavior
Don't call XMEMCPY() in case info (the source parameter to memcpy) is NULL
as this would trigger UB
2015-12-05 14:31:38 +01:00
Steffen Jaeckel
318dbbccc3 fix wrongly used LTC_ARGCHK/LTC_ARGCHKVD macros 2015-12-05 14:31:37 +01:00
Steffen Jaeckel
460b8716c9 fix clang-analyzer warnings
This fixes #80
2015-12-05 14:31:01 +01:00
Steffen Jaeckel
16f397d55c prevent segfault in case we hit an empty sequence 2015-09-10 19:17:42 +02:00
Steffen Jaeckel
d4945ac521 add (nearly) all defines from tomcrypt_custom.h to crypt_build_settings
... and provide a new make target to check if something is missing
2015-09-08 21:09:49 +02:00
Steffen Jaeckel
0b140206cf Merge branch 'feature/rsa-crt_hardening' into develop
This fixes #77
2015-09-08 21:04:54 +02:00
Steffen Jaeckel
733c52aa00 add LTC_RSA_CRT_HARDENING to crypt_build_settings 2015-09-08 21:04:33 +02:00
Steffen Jaeckel
01f1845402 harden RSA CRT by implementing the proposed countermeasure
... from ch. 1.3 of [1]

[1] https://people.redhat.com/~fweimer/rsa-crt-leaks.pdf
2015-09-08 02:44:17 +02:00
Steffen Jaeckel
19e2526b82 add some make targets regarding code coverage 2015-09-08 02:35:35 +02:00
Steffen Jaeckel
7db5760c91 add possibility to create combined coverage
Define the environment variable LTC_COVERAGE to something, run testme.sh
with all the coverage compile time options enabled and then 'make lcov'
creates the combined coverage for all combinations of compile-time
options handled in testme.sh.

e.g. LTC_COVERAGE=1 ./testme.sh "makefile -j3" "-DUSE_LTM -DLTM_DESC -I../libtommath -fprofile-arcs -ftest-coverage" "../libtommath/libtommath.a -lgcov"
2015-09-08 01:36:13 +02:00
Steffen Jaeckel
21ed315527 ignore output of 'make doxy' 2015-09-08 01:14:57 +02:00
Steffen Jaeckel
fd94034ba7 sort HEADERS in makefiles, so it doesn't change spontaneously 2015-09-01 17:36:43 +02:00
Steffen Jaeckel
6ec93afa3c clean-up test-build and extend tomcrypt_custom.h
added LTC_MINIMAL to be able do a build without nearly any
functionality :)
make sure timing resistant RSA & ECC are enabled if not said otherwise
2015-09-01 17:36:43 +02:00
Steffen Jaeckel
8cb20e6059 add more DES test vectors 2015-08-31 15:09:36 +02:00
Steffen Jaeckel
eb26b7efd4 Merge branch 'fix/ccm_constant_time' into develop
This closes #73 and closes #76
2015-08-26 00:16:09 +02:00
Sebastian Verschoor
75b114517a make sure no cache-based timing attack is possible
instead of two different buffers, there is just one buffer. Based upon the verification result, a mask is applied to the buffer before it is written to the output buffer.
2015-08-26 00:08:38 +02:00
Steffen Jaeckel
09e4b0ec9b don't reveal plaintext if authentication failed
Create two buffers of the same size as the input data.
Copy the input data to the first one and work with that version to hold the
decrypted data, zeroize the second one.
Copy depending on the verification result, either the zero-buffer or the
real plaintext to the output buffer.
2015-08-26 00:08:38 +02:00
Steffen Jaeckel
6c11ca771b fix compile error of tests 2015-08-26 00:08:38 +02:00
Sebastian Verschoor
25af184cd5 Quickfix for issue #73
The API of the function is changed (for decryption, tag is now an input
parameter). With the old API it is impossible to confirm to the NIST
specification and a timing sidechannel leak is inevitable.
2015-08-26 00:08:38 +02:00
Steffen Jaeckel
38bfef2996 Merge branch 'aes-xts-accel' into develop
This fixes #70
2015-08-26 00:05:31 +02:00
Steffen Jaeckel
f9c8c9c229 also test XTS accelerators 2015-08-26 00:05:07 +02:00
Steffen Jaeckel
181d2f2df7 auto-format xts code 2015-08-26 00:02:50 +02:00
Steffen Jaeckel
b25d04ed94 fix pointer check 2015-08-25 23:58:22 +02:00
Jerome Forissier
5c3f177b34 Add function pointers for accelerated XTS to ltc_cipher_descriptor
Similar to what already exists for other modes.

Signed-off-by: Jerome Forissier <jerome.forissier@linaro.org>
2015-08-25 23:58:22 +02:00
Steffen Jaeckel
99214b53f6 add .clang-format 2015-08-25 23:58:08 +02:00
Steffen Jaeckel
a13257094e handle LTC_NO_FAST before handling LTC_FAST 2015-08-23 22:59:15 +02:00
Steffen Jaeckel
61efc10852 update makefiles 2015-08-23 22:59:14 +02:00
Steffen Jaeckel
ee03c97cde add crc32 2015-08-23 22:59:14 +02:00
Steffen Jaeckel
9585faca2b re-work debug output of some tests 2015-08-23 22:59:14 +02:00
Steffen Jaeckel
1987a2f975 add adler32 checksum algorithm 2015-08-23 22:59:14 +02:00
Steffen Jaeckel
d6cea55b13 Merge branch 'pascal-brand-st-dev/ecc_raw' into develop
This fixes #69
2015-08-21 22:18:42 +02:00
Pascal Brand
3605983f09 Introduce ECC raw algorithms for sign and verify
As it is performed on dsa, raw sign and verify on ECC
are introduced.

Signed-off-by: Pascal Brand <pascal.brand@st.com>
2015-08-21 22:14:03 +02:00
Steffen Jaeckel
0e8d8f8d81 Merge branch 'pascal-brand-st-dev/ecctest' into develop
This fixes #68
2015-08-21 22:12:02 +02:00
Pascal Brand
7313d1e6b0 Update ECC timing tests
Signed-off-by: Pascal Brand <pascal.brand@st.com>
2015-08-21 22:09:25 +02:00
Steffen Jaeckel
08629ed2b0 Merge branch 'fix/issue74' into develop
This closes #74
2015-08-21 21:30:38 +02:00
Sebastian Verschoor
67973b04ae fix #74 2015-08-21 21:29:56 +02:00
Steffen Jaeckel
c28cc9e3e9 crypt_build_settings: remove build date and time 2015-05-07 10:32:12 +02:00
Karel Miko
aeaa6d4a51 cygwin related fix - variable name B0 changed to B_0 (part 2) 2015-04-17 08:59:35 +02:00
Karel Miko
6a257e15cd cygwin related fix - variable name B0 changed to B_0 as it caused collision when compiling libtomcrypt as a perl module (for some reason only on cygwin) 2015-04-17 08:56:42 +02:00
Karel Miko
a8e91afb16 cygwin/64bit related fix - added !defined(__x86_64__) 2015-04-17 08:50:38 +02:00
Steffen Jaeckel
4981e2ab3f Merge pull request #61 from ulikoehler/reffix
Fix config file reference
2015-03-28 08:31:21 -04:00
Uli Köhler
d24e9cd32d Fix config file reference 2015-03-27 21:41:51 +01:00
Steffen Jaeckel
925f1ec0e6 Merge pull request #60 from pascal-brand-st-dev/memneq
Use XMEM_NEQ instead of mem_neq
2015-02-27 10:11:14 +01:00
Pascal Brand
f20b5daf39 Use XMEM_NEQ instead of mem_neq
mem_neq is no more used directly. XMEM_NEQ is used instead,
in the same way XMEMCMP, XMEMCPY,... are.

Signed-off-by: Pascal Brand <pascal.brand@st.com>
2015-02-27 08:54:30 +01:00
Steffen Jaeckel
dfa938a4f6 verify outcome when defining LTC_NOTHING
check that LTC_NOTHING really creates nothing but the libraries' basic
API functions
2015-02-15 17:25:45 +01:00
Steffen Jaeckel
90e968a202 der_decode_subject_public_key_info: fix compile error
also make it possible to define min/max RSA key sizes externally

This closes #59
2015-02-15 16:32:12 +01:00
Saleem Abdulrasool
62878de0c5 adjust inline asm requiring constants
In order to ensure that the shift is within range, convert the inline assembly
routines into macros with compound statements.
2015-01-20 22:36:07 +01:00
Steffen Jaeckel
e9f9c6fa55 create a makefile.include
it contains all the preparation and targets for the static and shared lib
2015-01-20 22:36:07 +01:00
Steffen Jaeckel
0b6915740c saferp: enclose macros in do{}while(0) loop 2015-01-20 22:36:07 +01:00
Steffen Jaeckel
9782c09a3a use XMEM{CMP, CPY, SET} macros instead of standard versions 2015-01-20 22:36:06 +01:00
Steffen Jaeckel
b8bf2f13b8 Merge branch 'feature/const_memcmp' into develop
This closes #57
2015-01-20 22:35:44 +01:00
Steffen Jaeckel
46c038f7d4 adapt rsa_test() to modified pkcs#1 decoding routines 2014-11-13 22:30:07 +01:00
Steffen Jaeckel
1e9e98aa0d make pkcs#1 decode functions constant-time
as proposed in RFC 3447 only one error return code is used when there are
errors while decoding the pkcs#1 format.
also, all steps are executed and only the "output" is skipped if something
went wrong.

Sorry this could break backwards compatibility, since there's no more
BUFFER_OVERFLOW messaging.
Former error-handling code could also be affected because now there's only
OK as return code in cases where "res" is also set to '1'.
2014-11-13 22:26:59 +01:00
Steffen Jaeckel
e57c92fd23 replace calls to standard memcmp with constant memcmp where necessary 2014-11-13 22:09:45 +01:00
Steffen Jaeckel
d54425adb4 update makefiles 2014-11-13 22:09:20 +01:00
Steffen Jaeckel
26c5d54e5c add constant-time memcmp()
[skip ci]
2014-11-12 23:59:27 +01:00
Steffen Jaeckel
ddca3d6422 Merge branch 'pascal-brand-st-dev/ccm' into develop
This closes #55
2014-11-02 17:02:21 +01:00
Steffen Jaeckel
f2f8342c43 ccm test: add missing AAD 2014-11-02 17:01:56 +01:00
Steffen Jaeckel
943a858d6c also run testvectors on new CCM API
[skip ci]
2014-10-31 19:41:14 +01:00
Steffen Jaeckel
4efa27ead1 add missing pointer checks 2014-10-31 19:39:03 +01:00
Steffen Jaeckel
53917750d8 trim trailing spaces 2014-10-31 19:38:47 +01:00
Pascal Brand
992506cb49 Add incremental CCM authentication processing
CCM is only meant for packet mode where the length of the input is known in
advance. Since it is a packet mode function, CCM only had one function that
performs the protocol.

However, incremental authentication is usefull in some usecases. It also
ensure some kind of coherencies when processing with a given authentication
mode or another. To achieve this aim, this commit adds the following functions:
    ccm_init()
    ccm_add_aad()
    cm_add_nonce()
    ccm_process()
    ccm_done()
    ccm_reset()
as well as the data structure
    ccm_state

Change-Id: I5225a42bb098708c4af07518b561bb00f85bc243
2014-10-17 09:00:19 +02:00
Steffen Jaeckel
ed28703804 der_decode_sequence_multi: calm coverity 2014-10-10 01:07:58 +02:00
Steffen Jaeckel
e6b1c7101e der test: also run der_length_utf8_string() 2014-10-10 00:56:23 +02:00
Steffen Jaeckel
3ecdd29847 fix coverity script 2014-10-10 00:55:18 +02:00
Steffen Jaeckel
ee1631f8b3 dsa import: no output on stderr please 2014-10-06 19:00:50 +02:00
Steffen Jaeckel
f75b5ec8f4 der tests: improve/implement handling of context-specific data
no more "EOL" in the output as the flexi decoder handles now
context-specific data
2014-10-06 18:59:40 +02:00
Steffen Jaeckel
6da3b856d6 der test: print list-element details on EOL
EOL indicates an unitialized list-element
2014-10-06 18:57:42 +02:00
Steffen Jaeckel
6bd6319fb0 der flexi decoder: implement decoding of context-specific data 2014-10-06 18:57:42 +02:00
Steffen Jaeckel
2d8933e4f1 der: add new enum element for context-specific encodings 2014-10-06 18:57:42 +02:00
Steffen Jaeckel
f0a1235614 der flexi decoder: remove duplicate code 2014-10-06 18:57:41 +02:00
Steffen Jaeckel
3d1231ab15 der flexi decoder: improve CONSTRUCTED type decoding
remove all teh flags
save the entire original identifier
2014-10-06 17:51:25 +02:00
Steffen Jaeckel
2e426e2d57 der test: add example of decoding a X.509 v3 cert with the flexi decoder
you can define "LTC_DER_TESTS_PRINT_FLEXI" at compile time to print
the decoded cert whenn running the test executable...
well not all of it, since some parts of the cert are marked as
"context-specific" so we would need to do some further digging
...these are the parts that are output as "EOL"...
2014-09-30 17:57:53 +02:00
Steffen Jaeckel
c1e81ad469 minor changes
print MP_DIGIT_BIT when running test
der_test: improve error output of 'short integer' test
2014-09-30 13:26:18 +02:00
Steffen Jaeckel
1cc26da35c fix coverity script 2014-09-30 10:53:05 +02:00
Steffen Jaeckel
b1b3d5870f Merge branch 'feature/formatRsaDsa' into develop
This closes #50
2014-09-29 23:45:34 +02:00
Steffen Jaeckel
eea24fe2c0 bring back possibility to import/export old DSA key format 2014-09-29 23:44:47 +02:00
Steffen Jaeckel
f58c87866e add possibility to export RSA public key in SubjectPublicKeyInfo format 2014-09-29 23:44:47 +02:00
Steffen Jaeckel
b1f29539be Revert "removed testing of "stripped" rsa key"
This reverts commit 496453f289.
2014-09-29 23:44:47 +02:00
Steffen Jaeckel
7842e338bf fix API of dynamic language helpers
it is easier to handle 'int' than 'long' in the foreign language
2014-09-29 23:30:02 +02:00
Steffen Jaeckel
b3b93675f5 Merge branch 'feature/sha2t' into develop 2014-09-29 19:57:43 +02:00
Steffen Jaeckel
1924e6fd47 add sha512/224 and sha512/256 to tests and crypt_build_settings 2014-09-29 19:57:21 +02:00
Steffen Jaeckel
06321b8602 update makefiles 2014-09-29 19:57:21 +02:00
Steffen Jaeckel
c58e2cae75 add special build rules for sha512/224 and sha512/256 2014-09-29 19:57:21 +02:00
Steffen Jaeckel
23fb224e19 add sha512/224 and sha512/256 2014-09-29 19:57:21 +02:00
Steffen Jaeckel
5ce0c7f70e Merge branch 'pascal-brand-st/xts' into develop
This closes #52
2014-09-29 19:47:44 +02:00
Steffen Jaeckel
3d905ca178 add testcase for multiple XTS encryption/decryption 2014-09-29 19:47:18 +02:00
Pascal Brand
adc54d08d0 Enable multiple XTS encryption or decryption
multiple xts_encrypt() cannot be performed because the
tweak is not updated. That means that
  xts_encrypt(buffer1, tweak)
  xts_encrypt(buffer2, tweak)
is not the same as
  xts_encrypt(concat(buffer1, buffer2), tweak)

Current patch enables such functionalities by
updating the tweak as output of the encryption.
Note that the tweak is no more constant.

The very same modification is performed
on xts_decrypt()

Signed-off-by: Pascal Brand <pascal.brand@st.com>
2014-09-28 22:55:02 +02:00
Steffen Jaeckel
824c7bf16a Merge branch 'pascal-brand-st/rsa' into develop
This closes #53
2014-09-28 22:53:22 +02:00
Steffen Jaeckel
94363b601c add testcase to verify that this patch is working 2014-09-28 22:52:32 +02:00
Pascal Brand
a6e89d58d4 RSA in CRT optimization parameters are empty 2014-09-28 22:48:21 +02:00
Pascal Brand
2bb3f0246f RSA in case CRT optimization parameters are not populated
rsa_exptmod(), ran on the private key, makes use of CRT optimization
parameters. In some use-cases, the given key does not include the
optimization parameters.

This patch allows rsa_exptmod() to run without the CRT parameters,
using directly mp_exptmod().

Signed-off-by: Pascal Brand <pascal.brand@st.com>
2014-09-28 22:45:46 +02:00
Steffen Jaeckel
cb2322f8de Merge branch 'fix/x32' into develop
This closes #51
2014-09-28 22:43:58 +02:00
Steffen Jaeckel
afaef3993c fix compiler warning when compiling with GMP_DESC 2014-09-10 16:16:46 +02:00
Steffen Jaeckel
f597f29ece math: change get_digit() return value
unsigned long is 32bit wide when compiling with the compiler flag "-mx32"
but the digit size of the math libraries is still 64 bit which lead to
the buggy ecc code.

Therefore define a new type ltc_mp_digit with the correct width and use
that as return value of get_digit()

Has been tested with all three math providers
2014-09-10 16:15:35 +02:00
Steffen Jaeckel
1793072c67 fix CC parameter given to make in testprof folder 2014-09-10 16:08:49 +02:00
Steffen Jaeckel
67b9cd8a95 trim trailing spaces 2014-09-02 02:17:43 +02:00
Steffen Jaeckel
e8d4598616 Merge branch 'fix/mingw64' into develop 2014-09-01 19:29:44 +02:00
Steffen Jaeckel
fff4fd15c4 build.sh: improve diff parameters 2014-08-31 18:47:21 +02:00
Steffen Jaeckel
ee4c00b753 some more ASN.1 fixes
these should have been in #49
2014-08-31 18:26:14 +02:00
Steffen Jaeckel
c342cb5a21 Merge branch 'fix/asn1' into develop
This closes #49

[skip ci]
2014-08-31 18:02:52 +02:00
Steffen Jaeckel
e5fb4d5ebe use DO() macro when calling API functions in tests 2014-08-28 14:02:57 +02:00
Steffen Jaeckel
7a5ea10e60 add missing ASN1 types in der_encode_set() 2014-08-28 14:02:57 +02:00
Steffen Jaeckel
ddede01d16 trim trailing spaces 2014-08-28 14:02:57 +02:00
Steffen Jaeckel
b06270645e add missing check of the OID 2014-08-28 14:02:57 +02:00
Steffen Jaeckel
6bba3a2a70 change the ASN1 type to be a typedef
replace all 'default' cases in the switch statements
2014-08-28 14:02:57 +02:00
Steffen Jaeckel
00c111b1c8 add missing types to decode routines 2014-08-28 14:02:57 +02:00
Steffen Jaeckel
800182338e unwind conditional expressions
I prefer readability
2014-08-28 14:02:57 +02:00
Christopher Brown
3cdb64eca6 bypass constructed type identification for sets / sequences 2014-08-28 14:02:56 +02:00
Christopher Brown
678b6d9641 fix constructed type identifier check 2014-08-28 14:02:56 +02:00
Steffen Jaeckel
171eae5378 asn1: use LTC_SET_ASN1 macro to access ltc_asn1_list elements 2014-08-28 14:02:56 +02:00
Steffen Jaeckel
4071475558 fix compiler warnings 2014-08-28 13:53:51 +02:00
Steffen Jaeckel
78e367895a Merge branch 'feature/testRsaPkcs1' into develop
This closes #48
2014-08-28 13:35:13 +02:00
Steffen Jaeckel
efc6844f9c tests: add function print_hex() 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
64f887e8f3 predictable rand() values please 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
8ce125f8a8 mp_rand() assumes the number of digits and not the bitsize as parameter 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
f86d36c676 rsa_test: improve a bit 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
536a199203 rsa_test: fix valgrind warnings 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
d51715db72 pkcs#1 v1.5 decode: fix missing check of PS length in EMSA mode 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
2b3c603c6c udpate bleichenbacher signature attack
also test for too short padding strings
2014-08-28 13:30:26 +02:00
Steffen Jaeckel
e227000578 tests: remove surplus ';' in DO()/DOX() macros 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
5eb9743410 rsa_verify_hash: fix possible bleichenbacher signature attack 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
c6dfef95eb testprof/rsa_test: add testcase for bleichenbacher signature attack 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
dc0c6ed9d9 regen rsa-testvectors 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
7c10ec9dd2 add makefile for rsa-testvectors 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
2c69088be8 execute only one testcase per default 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
92274aafb5 add testprof/pkcs_1_eme_test 2014-08-28 13:30:26 +02:00
Steffen Jaeckel
c24e2a1e6b fix pkcs1v15crypt-vectors.txt 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
b51824748a rt.py: extend for PKCS#1 v1.5 EME 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
7302a7cfcb add testprof/pkcs_1_emsa_test 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
25fcd4c70f rt.py: add possibility to parse PKCS#1 v1.5 EMSA testvectors 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
95f9d527f6 rt.py: start making even more generic, fixed naming of p and q 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
c99a147d4a add testprof/pkcs_1_oaep_test 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
ed0982b7e7 add oaep testvectors 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
b0c7cbfaae improve testprof/pkcs_1_pss_test 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
60b9c5a6f1 make pkcs1 test more generic 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
faa9c6a607 add missing unregister of no_prng 2014-08-28 13:30:25 +02:00
Jonathan Herzog
3324da2601 Fixed small padding error in the PKCS#1 PSS code.
The existing LTC code for padding meassages for PSS signatures
contained a small error. In particular, the PSS-passing algorithms is
supposed to be given (bitlength of key - 1) as an argument. The LTC
code passes (bitlength of key), and subtracts 1 in the middle of the
PSS-padding. This subtraction unfortunately comes too late: a
calculation using that argument has already been made. Fortunately,
this bug only appeared if the bit-length of the key was 1 mod 8, and
so is unlikely to show up in practice. Still, this patch fixes the
problem.

Conflicts:
	src/pk/pkcs1/pkcs_1_pss_decode.c
2014-08-28 13:30:25 +02:00
Steffen Jaeckel
fe1b6eced7 add testprof/pkcs_1_pss_test 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
b570175b47 add testprof/no_prng
a PRNG that is no PRNG as its output is predefined and can be set
by calling add_entropy()
2014-08-28 13:30:25 +02:00
Steffen Jaeckel
4a819b2f1b add generated file pss-vect.c 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
269516533c rt.py: add name of testcase in struct 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
055c515161 fix pss-vect.txt 2014-08-28 13:30:25 +02:00
Steffen Jaeckel
6dfe0013e1 rt.py: initial version 2014-08-28 13:30:24 +02:00
Steffen Jaeckel
b2317279b8 add original RSA testvector files 2014-08-28 13:30:24 +02:00
Steffen Jaeckel
394806cab1 tests: use correct format string parameter for 64bit values on windows 2014-08-28 13:27:52 +02:00
Steffen Jaeckel
14272976d0 add release flag to makefile.shared 2014-08-27 18:20:47 +02:00
Steffen Jaeckel
47b8ccc07c fix hash ID's of ripemd 256 & 320 2014-08-26 17:42:10 +02:00
Steffen Jaeckel
473b0319ad re-enable "unused-parameters" warning 2014-08-24 18:25:24 +02:00
Steffen Jaeckel
01c34dc236 trim trailing spaces 2014-08-24 18:25:24 +02:00
Steffen Jaeckel
1fb649d394 chc: don't execute tests if LTC_TEST is not defined 2014-08-07 01:36:03 +02:00
Steffen Jaeckel
f8449f55d9 trim trailing spaces 2014-08-07 01:36:03 +02:00
Jonathan Herzog
ff736a61bb Hash functions now check for input-length overflow.
Because many of the hash-functions implemented by LTC use the length
of the input when padding the input out to a block-length, LTC keeps
track of the input length in a 64-bit integer. However, it did not
previously test for overflow of this value. Since many of the
hash-functions implemented by LTC are defined for inputs of length
2^128 bits or more, this means that LTC was incorrectly implementing
these hash functions for extremely long inputs. Also, this might have
been a minor security problem: A clever attacker might have been able
to take a message with a known hash and find another message (longer
by 2^64 bits) that would be hashed to the same value by LTC.

Fortunately, LTC uses a pre-processor macro to make the actual code
for hashing, and so this problem could be fixed by adding an
overflow-check to that macro.
2014-08-06 19:06:00 +02:00
Steffen Jaeckel
757ac982a5 if selected, always make targets 'test' and 'testprof/$(LIBTEST)' 2014-08-06 15:16:37 +02:00
Steffen Jaeckel
09a0de69a0 update makefile.mingw 2014-08-06 15:16:30 +02:00
Steffen Jaeckel
98e05b10a0 trim trailing spaces in mingw makefiles 2014-08-06 15:11:45 +02:00
Steffen Jaeckel
a8598b0faf fix unregister_prng() where always the first prng would have been removed 2014-08-05 17:47:50 +02:00
Steffen Jaeckel
3cda802deb fixed ecc_test.c
luckily gcc 4.6 of travis CI complained!

shame on you gcc version 4.7.3 (Ubuntu/Linaro 4.7.3-1ubuntu1)
2014-07-17 12:10:05 +02:00
Steffen Jaeckel
48bd6702aa uncomment argchk in camellia_setup() 2014-07-17 11:32:52 +02:00
Steffen Jaeckel
155a54ba40 add LTC prefix to most macros 2014-07-17 10:50:36 +02:00
Steffen Jaeckel
3c76dcdd29 fix compiler warning when enabling LTC_GCM_TABLES_SSE2 2014-07-17 10:50:35 +02:00
Steffen Jaeckel
1a61b42775 update output; remove unused define 2014-07-16 15:11:14 +02:00
Steffen Jaeckel
97256daeed remove surplus ';' 2014-07-15 20:26:40 +02:00
Steffen Jaeckel
f8c536a349 add CC tag when linking 2014-07-15 20:25:32 +02:00
Steffen Jaeckel
9af6d311ec Merge branch 'buggywhip/dynHlp2' into develop
This closes #41
2014-07-15 15:51:43 +02:00
Steffen Jaeckel
7189998ba1 update gitignore 2014-07-15 15:45:39 +02:00
Steffen Jaeckel
5fa34ad171 update makefiles 2014-07-15 15:45:33 +02:00
Steffen Jaeckel
542ba9995c update math inititializers
make math initializer functions dependant on the xxx_DESC macro instead
of the USE_xxx macro, which is only relevant when building tests etc.
2014-07-15 15:38:18 +02:00
Steffen Jaeckel
746fd583c9 update demos according to changed naming 2014-07-15 15:28:29 +02:00
Steffen Jaeckel
fc7eeac218 update/rework constants and sizes 2014-07-15 15:27:31 +02:00
Steffen Jaeckel
fd7b3cd875 use snprintf() instead of sprintf() 2014-07-15 14:09:50 +02:00
Steffen Jaeckel
e628fb9203 clean up/trim trailing spaces 2014-07-15 13:58:48 +02:00
Larry Bugbee
a6b6884982 minor editorial changes 2014-07-14 15:47:20 +02:00
Larry Bugbee
46b6e36ea6 to know if LTC compiled big/little endian, 32/64-bit word 2014-07-14 15:47:20 +02:00
Larry Bugbee
f07234fd93 removed redundant include 2014-07-14 15:47:20 +02:00
Larry Bugbee
ef1fe79ca5 added missing signatures 2014-07-14 15:47:20 +02:00
Larry Bugbee
a543e0caa6 changed to keep it simple 2014-07-14 15:47:20 +02:00
Larry Bugbee
3f9144c9a7 added signatures to header file 2014-07-14 15:47:20 +02:00
Larry Bugbee
d99b970a8b added a Python demo 2014-07-14 15:47:20 +02:00
Larry Bugbee
1b29ce896f include compiler defines and other minor refinements 2014-07-14 15:47:20 +02:00
Steffen Jaeckel
fd140d4535 clean up makefile 2014-07-14 15:42:32 +02:00
Steffen Jaeckel
4089cc963c update shared makefiles
split up install target in "install" and "install_test" as in
standard makefile

use libtool to compile and link

clean up and bring in sync with standard makefile targets
2014-07-14 15:35:04 +02:00
Steffen Jaeckel
a0d0a17acf update gitignore 2014-07-14 15:35:04 +02:00
Steffen Jaeckel
9e2e7fdfd4 tests: bring back mult and sqr timing 2014-07-12 17:31:03 +02:00
Steffen Jaeckel
3c6a80525f current icc defines the same macros and functionset as gcc
as a result the special detection of icc has been removed
2014-07-12 17:28:54 +02:00
Steffen Jaeckel
6dfb080810 spit errors if 32- AND 64-bit wordsize is defined 2014-07-12 17:26:30 +02:00
Steffen Jaeckel
1f96647d70 update icc makefiles to current compiler versions
As the current icc can act as a gcc drop-in, I took over all compile flags
from the standard makefile.

The "-x?" options have been deprecated, so they're updated.

The "-xP" has been removed, since it makes no sense in my eyes to define
the optimization for a specific architecture in the makefile.
2014-07-12 17:25:12 +02:00
Steffen Jaeckel
098bc9f06d tests: use the gcc rdtsc() implementation also for intel cc 2014-07-12 16:46:36 +02:00
Steffen Jaeckel
8c488289f0 improve some error and informational output 2014-07-12 16:44:28 +02:00
Steffen Jaeckel
79bc7ef2e5 testprof: add missing object files to makefiles 2014-07-12 16:19:08 +02:00
Steffen Jaeckel
6ac2d6141d update clean target of makefile and testprof/makefile 2014-07-12 16:18:29 +02:00
Steffen Jaeckel
98893c077b fix possible free of not yet allocated key parameters
There would have been a call to mp_clear_multi() of all the key parameters
that are not yet allocated, in the case where the calculations of p, q,
tmp1 or tmp2 created an error.

This also includes a proposed improvement from the OLPC project to free
elements in the reverse order as they were allocated.
2014-07-11 16:44:43 +02:00
Steffen Jaeckel
30278d1121 fix possible missing free of rnd and rndi
There could have been a 'goto error', which misses the free of rnd and
rndi even if they were initialized.
This could happen in cases where a private key operation was done and
afterwards one of the operations like reading back or conversion, would
have failed (which is likely not to happen)

This also includes a proposed improvement from the OLPC project to free
elements in the reverse order as they were allocated.
2014-06-15 11:51:38 +02:00
Steffen Jaeckel
48f521688f ltc_init_multi: fix missing call to va_end() 2014-05-25 00:35:03 +02:00
Steffen Jaeckel
8652f33f35 pmac_init: prevent possible out of bounds access of polys[] 2014-05-25 00:35:03 +02:00
Steffen Jaeckel
ea9b2a858a der_encode_utf8_string: calm coverity 2014-05-25 00:35:03 +02:00
Steffen Jaeckel
4c8949e449 aes: calm coverity 2014-05-25 00:35:03 +02:00
Steffen Jaeckel
50d10790e3 trim trailing spaces 2014-05-25 00:35:03 +02:00
Steffen Jaeckel
f9984d1e24 add coverity badge 2014-05-25 00:35:03 +02:00
Steffen Jaeckel
389bbf0d05 update gitignore 2014-05-25 00:35:03 +02:00
Steffen Jaeckel
2de05c4d3e add coverity build and upload script 2014-05-25 00:35:03 +02:00
Steffen Jaeckel
681e5fcdfc Merge branch 'fix/dsa' into develop 2014-05-11 18:10:03 +02:00
Steffen Jaeckel
03385a4419 rand_bn: fix call to zeromem() 2014-05-09 23:29:11 +02:00
Steffen Jaeckel
ca42862d52 math descriptor: add parameter "b" to isprime() 2014-05-09 23:07:41 +02:00
Steffen Jaeckel
5d2fe0da8c trim trailing spaces 2014-05-09 23:07:41 +02:00
Steffen Jaeckel
dc31ca545f dsa_make_key: fix free of wrong pointer resulting in double-free 2014-05-09 23:07:40 +02:00
Steffen Jaeckel
198ad7ef50 update makefiles 2014-05-09 23:07:33 +02:00
Steffen Jaeckel
c9f93f6571 dsa_make_key: remove surplus semicolon 2014-05-09 22:43:29 +02:00
Karel Miko
e9a0a27917 DSA params+key generation according FIPS-186-4 (part 1) 2014-05-09 17:58:50 +02:00
Karel Miko
77b4b16030 dsa_make_key minor isuue 2014-05-09 17:58:50 +02:00
Karel Miko
a43bb0fda6 dsa_encrypt_key small correction 2014-05-09 17:58:50 +02:00
Karel Miko
655336f0cb tuning RSA interoperability + small fixes 2014-05-09 17:58:50 +02:00
Karel Miko
67a547086c DSA sign improvement 2014-05-09 17:58:50 +02:00
Karel Miko
3908c70d68 tuning DSA key generation 2014-05-09 17:58:50 +02:00
Karel Miko
e271b9fdbe ECC key pair generation according to FIPS-186-4 2014-05-09 17:58:39 +02:00
Karel Miko
e600ab9d35 dsa_sign_hash: testing k < q 2014-05-09 16:26:24 +02:00
Karel Miko
72022edb8d dsa_make_key: improved testing x < q 2014-05-09 16:26:24 +02:00
Steffen Jaeckel
24d03dd823 testme.sh: add test runs without "timing resistance" 2014-05-08 15:11:38 +02:00
Steffen Jaeckel
e723d1289f travis.yml: add test runs without "timing resistance" 2014-05-08 15:10:09 +02:00
Steffen Jaeckel
3b97738ee9 travis.yml: rewrite to be better human-readable; trim trailing spaces 2014-05-08 15:08:31 +02:00
Steffen Jaeckel
c63c0433c1 enable timing resistant ECC calculations by default 2014-05-08 15:06:42 +02:00
Steffen Jaeckel
26743d0749 ecc_mulmod_timing: fix compiler warnings 2014-05-08 13:06:24 +02:00
Steffen Jaeckel
5707e319c2 Merge branch 'feature/coverage' into develop 2014-05-08 12:57:31 +02:00
Steffen Jaeckel
3dcf2df988 coverage: exclude some folders 2014-05-07 17:36:50 +02:00
Steffen Jaeckel
a59e5548ec tests: unregister ciphers etc. at exit, call error_to_string() 2014-05-07 17:36:09 +02:00
Steffen Jaeckel
2b04f3d8ed Readme: display the coverage status
[skip ci]
2014-05-07 17:03:12 +02:00
Steffen Jaeckel
1a44e2d22d send coverage results to coveralls 2014-05-07 16:16:08 +02:00
Steffen Jaeckel
f9a1041222 printinfo: display version of correct compiler if CC does not point to gcc
[skip ci]
2014-05-07 16:15:50 +02:00
Steffen Jaeckel
be5418368c Merge branch 'fix/anubis' into develop 2014-05-01 23:02:40 +02:00
Steffen Jaeckel
bbf278c779 anubis: fix left-shift
this has been brought up in #26
2014-05-01 23:02:21 +02:00
Steffen Jaeckel
ca1a1d18ab anubis: trim trailing spaces 2014-05-01 23:02:21 +02:00
Steffen Jaeckel
d2318d6c24 travis.yml: fix typo 2014-05-01 23:02:05 +02:00
Steffen Jaeckel
a06e40aa17 only run tests when build was without warnings 2014-05-01 18:13:21 +02:00
Steffen Jaeckel
4929e4e989 fix warnings in tests 2014-05-01 18:01:13 +02:00
Steffen Jaeckel
c211ce7f66 omac: fix accidentally reverted patch
introduced in 6816ac3f3f
reverted in 8e7777b554
2014-05-01 15:44:09 +02:00
Steffen Jaeckel
aa72cfe1d9 ccm: clarify pt and ct parameters in doc and API description
this fixes #42
[skip ci]
2014-04-30 20:19:11 +02:00
mudzot
3b7c6512ac Add #ifdef to make it easier to embed libtomcrypt with LTC_NOTHING
Restore LTC_NO_MATH and make rand_prime.c depend on LTC_NO_MATH & LTC_NO_PRNGS
2014-04-30 01:13:51 +02:00
Steffen Jaeckel
b895f13484 minor changes/clean-up sources 2014-04-30 01:10:22 +02:00
Steffen Jaeckel
b10c03aead flush content of CVS/SVN tags 2014-04-29 21:13:49 +02:00
Steffen Jaeckel
8a2bd89518 don't use assembler rotate when compiling for windows 64bit 2014-04-29 19:15:28 +02:00
karel-m
8afdb8831d ifdefs related to 64bit MS Windows build
Conflicts:
	src/headers/tomcrypt_cfg.h
	src/prngs/rng_get_bytes.c
2014-04-29 19:15:28 +02:00
karel-m
232f412709 makefiles for MS Windows gcc compiler 2014-04-29 18:25:15 +02:00
Karel Miko
0bda0770d9 fix for ASM failures on freebsd/netbsd 2014-04-29 17:32:14 +02:00
Steffen Jaeckel
e08480f621 update documentation according to new 3des mode 2014-04-28 21:08:56 +02:00
Steffen Jaeckel
f4d7baaacc Merge pull request #43 from pghmcfc/develop
Add support for two-key Triple-DES
2014-04-28 21:05:26 +02:00
Paul Howarth
445dfa67a6 des.c: Add support for two-key Triple-DES
Add two-key 3DES support, needed by pycrypto.

This commit is based on the one for the bundled libtomcrypt 1.16
code in pycrypto:

65085f16
2014-04-15 11:25:18 +01:00
Steffen Jaeckel
449d5e718d gitignore: add files that are generated while profiling 2014-04-04 01:03:58 +02:00
Steffen Jaeckel
ae5cc35298 surround most macros with "do{}while(0)" 2014-04-04 01:03:54 +02:00
Steffen Jaeckel
2849087906 Merge branch 'feature/rmCincludes' into develop 2014-04-04 00:54:14 +02:00
Steffen Jaeckel
1ce4e766ff update makefiles 2014-04-04 00:38:10 +02:00
Steffen Jaeckel
a15ea906c1 genlist.sh: update 2014-04-04 00:38:09 +02:00
Steffen Jaeckel
2bdebb3932 dh: remove including of c-files 2014-04-04 00:38:08 +02:00
Steffen Jaeckel
71ccad06bd dh: remove unused variables 2014-04-04 00:38:07 +02:00
Steffen Jaeckel
f3cdac05ec sha2: remove including of c-files 2014-04-04 00:38:06 +02:00
Steffen Jaeckel
cbd59421bd protect all tables by an ifdef; adjust safer to the same concept 2014-04-04 00:38:05 +02:00
Steffen Jaeckel
5d8091b6cf Merge branch 'fix/strict-aliasing' into develop 2014-04-04 00:36:07 +02:00
Steffen Jaeckel
ffeb70b48a fix typedef of LTC_FAST_TYPE on x86_64 2014-04-03 22:22:01 +02:00
Steffen Jaeckel
68bfdd0fac move mac_test() before modes_test()
since lrw uses gcm it makes sense to fail already at gcm
2014-04-03 15:08:17 +02:00
Steffen Jaeckel
53f04b8e6b only use ulong32 or ulong64 in the macros 2014-04-03 15:06:56 +02:00
Steffen Jaeckel
1f7cf9dc0b move typedefs from tomcrypt_macros.h to tomcrypt_cfg.h 2014-04-03 15:05:56 +02:00
Steffen Jaeckel
e027dda26f travis: add "after_failure" section 2014-03-12 10:53:23 +02:00
Steffen Jaeckel
561fe83532 fix strict-aliasing compiler warnings 2014-03-04 21:59:16 +01:00
Steffen Jaeckel
0aee5f3217 fix wrong spelled macros 2014-03-04 21:50:18 +01:00
Steffen Jaeckel
84298440f4 trim trailing spaces 2014-03-04 21:50:17 +01:00
Steffen Jaeckel
621a75ab28 base64: add and most important - execute tests 2014-03-04 21:50:16 +01:00
Steffen Jaeckel
1d52f3b49b tomcrypt_custom.h: move dependency checks together 2014-03-04 18:09:12 +01:00
Steffen Jaeckel
ec73cfa257 Merge branch 'stapelberg/respect-ldflags' into develop 2014-02-25 10:47:20 +01:00
Michael Stapelberg
ed2743d524 makefile.shared: respect LDFLAGS when linking 2014-02-25 10:47:05 +01:00
Steffen Jaeckel
6b7e79e1ee Merge branch 'stapelberg/pkgconfig' into develop 2014-02-25 10:46:40 +01:00
Michael Stapelberg
90928d6dfd pkgconfig: set libdir= to $LIBPATH (for multi-arch) 2014-02-25 10:45:20 +01:00
Michael Stapelberg
30022b114c add and install pkgconfig file for the shared library 2014-02-25 10:45:19 +01:00
Steffen Jaeckel
4dfd24d434 Merge branch 'stapelberg/fix-spelling' into develop 2014-02-25 10:44:28 +01:00
Michael Stapelberg
8d7e3d8216 fix typo: s/Endianess/Endianness/ 2014-02-25 10:38:29 +01:00
Steffen Jaeckel
722c128051 Merge branch 'feature/travis' into develop 2014-02-25 10:32:10 +01:00
Steffen Jaeckel
e97d921c8d travis: print version information in build scripts 2014-02-25 10:31:13 +01:00
Steffen Jaeckel
c5b57cfee4 travis: use build matrix instead of testme script 2014-02-25 10:09:59 +01:00
Steffen Jaeckel
feaa31968e travis: add IRC notifications 2014-02-25 10:09:58 +01:00
Steffen Jaeckel
65fd19c1fb dh: fix renamed macro 2014-02-25 10:09:35 +01:00
Steffen Jaeckel
77cca4175f ccm_memory_ex: disable until documented and fixed 2014-02-18 16:07:24 +01:00
Steffen Jaeckel
8b24397f84 update makefiles 2014-02-18 15:23:23 +01:00
Steffen Jaeckel
8e02874031 Merge branch 'stapelberg/deterministic-latex' into develop 2014-02-16 18:55:29 +01:00
Steffen Jaeckel
460bcfe31b remove crypt.lof from the repository 2014-02-16 18:55:28 +01:00
Steffen Jaeckel
a3811e2000 add -b flag to sed that enables binary processing (required on windows) 2014-02-16 18:55:27 +01:00
Michael Stapelberg
4ab63ccd3a deterministically build crypt.pdf
This entails:

 • Using pdflatex to influence the modification/creation timestamp in
   the resulting PDF
 • Replacing the unique ID with 0/0
 • Using the timestamp from crypt.tex instead of the current date/time

See also http://superuser.com/a/130804

This change is necessary because for Multi-Arch Debian packages,
non-arch-dependent files need to have the same checksum, which is not
guaranteed without this commit. See http://bugs.debian.org/734109
2014-02-16 18:55:25 +01:00
Steffen Jaeckel
ed9940175d hmac test: add some more tests from RFC's 2014-02-16 18:55:24 +01:00
Steffen Jaeckel
ddb26a4276 hmac test: remove comments, prepare for extension 2014-02-16 18:41:33 +01:00
Steffen Jaeckel
2adca46735 pkcs#5: add tests for 'algo 2' 2014-02-16 18:41:33 +01:00
Steffen Jaeckel
e48838559b der_encode_setof: fix compiler warning when compiling for windows 64bit 2014-02-16 18:41:32 +01:00
Karel Miko
45dcbc654d fixing broken camellia 2014-02-16 18:41:31 +01:00
Steffen Jaeckel
d2c1329f77 camellia: add new testvector 2014-02-16 18:41:30 +01:00
karel-m
f3789b31b6 fixing warnings when compiling camellia.c with 64bit MS compiler 2014-02-16 18:41:30 +01:00
Steffen Jaeckel
3da9adc366 aes: remove compiler warning when compiled with ENCRYPT_ONLY 2014-02-16 18:41:29 +01:00
Steffen Jaeckel
8e7777b554 trim trailing spaces/clean up 2014-02-16 18:41:28 +01:00
Steffen Jaeckel
d78aa37c10 base64: add define LTC_BASE64_URL, make _internal functions static 2013-11-24 22:11:44 +01:00
Karel Miko
947fe41bbb Add URL safe base64 de-/encoding 2013-10-27 21:49:26 +02:00
Steffen Jaeckel
4f86ad7dcf hkdf: don't compile if not requested 2013-10-15 10:17:53 +02:00
Steffen Jaeckel
b1b15910ed fix rng_get_bytes() when compiling with mingw-gcc 2013-10-15 10:17:17 +02:00
Steffen Jaeckel
5fd9b5057d Merge branch 'feature/rsaGetSizes' into develop 2013-10-14 14:18:54 +02:00
Steffen Jaeckel
bf1ccb629b fix rsa_sign_saltlen_get_max_ex() 2013-10-14 14:16:44 +02:00
Steffen Jaeckel
25f4817d48 update makefiles 2013-10-14 14:16:43 +02:00
Steffen Jaeckel
aacfec441e add rsa_sign_saltlen_get_max_ex() 2013-10-14 14:16:42 +02:00
Steffen Jaeckel
73c201da1f add rsa_get_size() 2013-10-14 14:16:41 +02:00
Steffen Jaeckel
fb65cd0772 fix clang compiler warnings 2013-10-02 01:03:40 +02:00
Steffen Jaeckel
a667a93d52 trim trailing spaces 2013-10-02 01:02:58 +02:00
Steffen Jaeckel
3eae4b42fb makefile: allow CC to be replaced
this allows building with clang by doing:
  CC=clang PREFIX=llvm- make
2013-10-01 23:08:30 +02:00
Steffen Jaeckel
61a3206f06 clean-up makefiles 2013-09-03 14:27:32 +02:00
Steffen Jaeckel
ab07d6a283 updatemakes.sh: trim trailing spaces 2013-09-03 14:25:50 +02:00
Steffen Jaeckel
c02097e74b Readme: fix link to travis-ci 2013-08-14 16:58:14 +02:00
Steffen Jaeckel
031e551c57 tomcrypt_custom.h: improve and clean-up
Add the possibility to define LTC_NOTHING that disables everything
Remove LTC_NO_MATH as it didn't do anything at all
Enable RSA blinding by default
2013-08-14 16:12:56 +02:00
Steffen Jaeckel
10511d329c update makefiles 2013-08-14 15:56:10 +02:00
Steffen Jaeckel
c0b8774cc1 move hkdf to misc 2013-08-14 15:47:07 +02:00
Steffen Jaeckel
d0a83df7f8 update makefile to be able to define a target platform prefix 2013-08-06 13:52:26 +02:00
Steffen Jaeckel
e5e8cc2e50 Update README.md
add Build status
2013-05-29 14:30:47 +03:00
Steffen Jaeckel
50ad0b8639 fix makefiles 2013-05-29 12:58:15 +02:00
Steffen Jaeckel
be96ed3ba9 add travis-ci configuration 2013-05-29 12:52:00 +02:00
Steffen Jaeckel
1748cc616b der_tests: trim trailing spaces 2013-04-18 11:22:25 +02:00
Steffen Jaeckel
9cb6c6b910 Merge branch 'fix/xtea' into develop 2013-03-22 16:08:31 +02:00
Steffen Jaeckel
d2e7b0c38f fixed 'golden' XTEA testvectors that are used when running testme.sh 2013-03-22 15:15:07 +02:00
Steffen Jaeckel
9e88fcb9b1 remove unused variable in demos/encrypt.c 2013-03-22 15:15:06 +02:00
Steffen Jaeckel
bfcf1eb200 trim trailing spaces in header files 2013-03-22 15:15:05 +02:00
Steffen Jaeckel
2526d5df8f xtea: use correct load and store macros 2013-03-22 15:15:04 +02:00
Steffen Jaeckel
0f0b182610 xtea: add new testvectors 2013-03-22 15:15:04 +02:00
Steffen Jaeckel
1050ecea4a demos/encrypt.c: add possibility to use parameter -t for testing a cipher 2013-03-22 15:15:03 +02:00
Steffen Jaeckel
fa7051c21e xtea: trim trailing spaces 2013-03-22 15:15:02 +02:00
Steffen Jaeckel
e531af7add ecc: fix compiler warnings 2013-03-22 15:14:44 +02:00
Steffen Jaeckel
14b3a5290e include stddef.h per default 2013-03-22 15:14:44 +02:00
Steffen Jaeckel
9203472789 dsa: fix compiler warning 2013-03-22 15:14:43 +02:00
Steffen Jaeckel
2addbcf315 noekeon: fix compiler warning 2013-03-22 15:14:42 +02:00
Steffen Jaeckel
57ea144874 README: add section 'Branches' 2013-03-20 17:47:23 +01:00
Steffen Jaeckel
ee4a9477ec update gitignore 2013-03-20 18:34:16 +02:00
Steffen Jaeckel
f107e6e465 demos: trim trailing spaces 2013-03-20 18:34:00 +02:00
Steffen Jaeckel
5d0eadcd42 Merge branch 'feature/OCBv3' into develop 2013-03-20 18:32:38 +02:00
Steffen Jaeckel
6b5b35e6cc ocb3: don't zero ocb3 context in ocb3_{de,en}crypt_last 2013-03-20 18:10:51 +02:00
Steffen Jaeckel
05b050b943 update makefiles 2013-03-15 17:46:58 +02:00
Steffen Jaeckel
faaa17aec2 add OCBv3 testvectors 2013-03-15 17:46:45 +02:00
Karel Miko
c5c067fd12 ocb_init fix (preventing index overflow) 2013-03-15 13:30:40 +02:00
Karel Miko
9c2193b722 ocb3_init fix (preventing index overflow) 2013-03-15 13:30:39 +02:00
karel-m
abab7089a3 OCBv3 according http://tools.ietf.org/html/draft-krovetz-ocb-03 2013-03-15 13:30:29 +02:00
Larry Bugbee
8e22b17a8e fix define LTC_YARROW_AES 2013-03-15 12:24:00 +02:00
Steffen Jaeckel
7efe74427b update gitignore 2013-03-15 12:23:59 +02:00
Steffen Jaeckel
d540496db1 Merge branch 'feature/hkdf' into develop 2013-03-15 11:17:16 +01:00
RyanC
fe18c95e76 add the rest of the hkdf test cases 2013-03-15 11:16:17 +01:00
RyanC
11f50bfb3c fix hkdf_expand arguments 2013-03-15 11:16:17 +01:00
Steffen Jaeckel
1c779b88f1 moar debug output 2013-03-15 11:16:17 +01:00
Steffen Jaeckel
8fcd408a98 fixed latex compile errors 2013-03-15 11:16:17 +01:00
Steffen Jaeckel
e81ac102bd add misc_test() 2013-03-15 11:16:17 +01:00
Steffen Jaeckel
c1243feef2 hkdf: improve argument validation 2013-03-15 11:16:16 +01:00
Steffen Jaeckel
13c42a00f6 hkdf: fix compiler warning 2013-03-15 11:16:16 +01:00
Steffen Jaeckel
abeddd6c4b add hkdf_test() 2013-03-15 11:16:16 +01:00
RyanC
d7a1480f9e docs for HKDF 2013-03-15 11:16:16 +01:00
RyanC
c98857a47e add hkdf impl 2013-03-15 11:16:16 +01:00
Steffen Jaeckel
d84af284a3 build/testme: remove -j4 parameter 2013-03-15 11:08:54 +01:00
Steffen Jaeckel
2b2f5de743 rename README 2013-02-13 11:42:19 +01:00
Steffen Jaeckel
8a53674b18 updated README 2013-02-13 11:38:25 +01:00
Steffen Jaeckel
eb9bad79bf udpate testme to display correct version when run out of repository 2013-02-13 11:33:39 +01:00
Steffen Jaeckel
dda83c9da1 Merge branch 'ccbrown/master' into develop 2013-02-13 10:05:02 +01:00
Christopher Brown
9953c69455 update makefiles 2013-02-13 10:01:21 +01:00
Christopher Brown
2cb8c44113 der fixes and additions 2013-02-13 10:01:20 +01:00
Steffen Jaeckel
7050bdb7c8 use corrected version of zeromem() from @dtrebbien 2012-11-23 00:53:54 +01:00
Steffen Jaeckel
f32e52d5ac mark scripts as executable 2012-11-23 00:49:26 +01:00
Steffen Jaeckel
21ddcf3568 fix multi2 as proposed by kmx 2012-11-18 18:44:14 +01:00
Steffen Jaeckel
8cda684a0e improved multi2_test() 2012-11-18 18:41:46 +01:00
Steffen Jaeckel
bb8bd034f5 Merge branch 'ppelleti/ltc-fix-noekeon-gmp' into develop 2012-11-18 15:24:52 +01:00
Patrick Pelletier
5b662d6ed8 Fix some small typos in documentation 2012-11-18 15:24:15 +01:00
Patrick Pelletier
80ef95f3c1 Checked in program which generates Noekeon vectors using BouncyCastle. 2012-11-18 15:24:15 +01:00
Patrick Pelletier
e7b4705fca corrected Noekeon vectors 2012-11-18 15:24:14 +01:00
Patrick Pelletier
0e143a5cfe EAX-noekeon vectors from BouncyCastle 2012-11-18 15:24:14 +01:00
Patrick Pelletier
6dc089015a Fix LTC's bug in PI1/PI2 of Noekeon. Add vectors from BouncyCastle. 2012-11-18 15:24:13 +01:00
Patrick Pelletier
5708adb6c1 Add Camellia to the test vectors. 2012-11-18 15:24:12 +01:00
Patrick Pelletier
65254f65bf Fix camellia_keysize() to not change the keysize if it is correct.
It was rounding 32 down to 24, 24 down to 16, and claiming 16 was invalid.
2012-11-18 15:24:12 +01:00
Patrick Pelletier
e3acd4cabe Make GMP use uppercase to match LibTomMath. 2012-11-18 15:24:11 +01:00
Patrick Pelletier
3fbccfcb5c support base 64 for GMP 2012-11-18 15:24:11 +01:00
Steffen Jaeckel
20f0c74d17 Merge branch 'ppelleti/ltc-fixes' into develop 2012-11-18 15:21:51 +01:00
Patrick Pelletier
382c9d4d85 Some fixes necessary to support the Clang compiler
First of all, it had a failure in SEED:

LTC_KSEED failed for x=0, I got:
expected    actual   (ciphertext)
     5e  ==  5e
     ba  ==  ba
     c6  ==  c6
     e0  ==  e0
     05  !=  00
     4e  !=  00
     16  !=  00
     68  !=  00
     19  ==  19
     af  ==  af
     f1  ==  f1
     cc  ==  cc
     6d  !=  00
     34  !=  00
     6c  !=  00
     db  !=  00

Since SEED uses the 32H macros, this is really analogous to the
problem I saw with the 64H macros in Camellia with gcc.  Not sure why
gcc only had a problem with 64H and not 32H, but since this is an
interaction with the optimizer, it's not going to happen every time
the macro is used (hence why the store tests pass; only when you get
into the complexity of a real cipher do you start having problems) and
it makes sense it will vary from compiler to compiler.

Anyway, I went ahead and added the ability to use __builtin_bswap32,
in addition to __builtin_bswap64, which I already did in a previous
commit.  This solves the problem for clang, although I had to add new
logic to detect the bswap builtins in clang, since it has a different
way to detect them than gcc (see the comments in the code).  The
detection logic was complicated enough, and applied to both the 32H
and 64H macros, so I factored out the detection logic into
tomcrypt_cfg.h.
2012-11-18 15:20:12 +01:00
Patrick Pelletier
ad566e1b00 Use __builtin_bswap64 if it is available
This produces slightly better performance than the inline assembly,
and has the added benefit that it should be portable to other systems
that use gcc, not just x86-64.

Here are the results on my "AMD Athlon(tm) 7450 Dual-Core Processor"
with "gcc (Ubuntu 4.3.3-5ubuntu4) 4.3.3":

with portable 64H macros:

camellia            : Schedule at   1659
camellia            [ 23]: Encrypt at   431, Decrypt at   434
whirlpool           : Process at    55

with inline assembly (with "memory clobber" for correctness):

camellia            : Schedule at   1380
camellia            [ 23]: Encrypt at   406, Decrypt at   403
whirlpool           : Process at    50

with __builtin_bswap64:

camellia            : Schedule at   1352
camellia            [ 23]: Encrypt at   396, Decrypt at   391
whirlpool           : Process at    46
2012-11-18 15:20:12 +01:00
Patrick Pelletier
cefff85550 Add "memory" as a clobber for bswap inline assembly.
This had been causing Camellia (the only cipher that uses these
macros) to fail when compiling "out-of-the-box" with gcc version
"4.3.3-5ubuntu4".  I think because the compiler had no idea any memory
access was going on in these macros.

Adding "memory" as a clobber solves the problem, but is probably
overkill.  I suspect that if we specify the constraint for y
differently, we could get rid of both "memory" and __volatile__, which
would allow the compiler to optimize much more.

Also, in gcc versions that support it, we should probably use the
bswap builtins instead.
2012-11-18 15:20:11 +01:00
Patrick Pelletier
ee7c031ddf Added some code (commented out) to print details about Camellia test failure
(and ditto for SEED)

This is modeled after similar commented-out code in sober128_test(),
but slightly fancier.
2012-11-18 15:20:10 +01:00
Patrick Pelletier
cecbbb88fc When a test fails, print the algorithm that it failed on.
As near as I can tell, LibTomCrypt doesn't provide any way to tell
which cipher failed when it reports a cipher test failure.  For
example, I was getting:

Algorithm failed test vectors. (5)
cipher_hash_test.c:14:cipher_descriptor[x].test()

But there's no way to tell what value x has, and even if there was, it
would take a bit of digging to determine which algorithm that
corresponds to.  So, I added a variant of the DO() macro, DOX(), which
takes an additional string argument which is displayed on failure.  So
now I get:

Algorithm failed test vectors. (5) - camellia
cipher_hash_test.c:14:cipher_descriptor[x].test()
2012-11-18 15:20:10 +01:00
Patrick Pelletier
9228cbbd1e don't delete doc/crypt.pdf in "make clean"
"make clean" was deleting "doc/*.pdf", despite the fact that there
were two comments (one above and one below) stating that it did not.

Since doc/crypt.pdf is checked into git, running "make clean" made my
git state dirty, which seems undesirable.

I took sort of a compromise position and had "make clean" continue to
delete any other .pdf files in doc (such as refman.pdf), but
explicitly not delete crypt.pdf.
2012-11-18 15:20:09 +01:00
Patrick Pelletier
4a2b54a446 Changed "make clean" to not delete crypt.lof (which is checked into git)
This line:
rm -f `find . -type f | grep "[.]lo"  | xargs`

was deleting crypt.lof, which seemed undesirable.  One solution would
be to end the grep expression with "$", but it seemed more
straightforward just to pass "-name" to "find", rather than piping
through grep.
2012-11-18 15:20:08 +01:00
Patrick Pelletier
d61c537a2a missing a comma 2012-11-18 15:20:08 +01:00
Patrick Pelletier
233f207c17 Use "GMP_DESC" instead of "GPM_DESC"
This seemed to be the only place in the code that was using this
particular transposition.  And, indeed, when compiling with
"GMP_DESC", it looks like it is necessary to disable Diffie-Hellman.
(Otherwise, the test fails for me.)
2012-11-18 15:20:07 +01:00
Steffen Jaeckel
bd7933cc2b add check for defines of math provider 2012-10-08 10:20:21 +02:00
Steffen Jaeckel
77860ba866 yarrow: prevent access to NULL pointer 2012-05-04 01:01:24 +02:00
Steffen Jaeckel
9c4fc762fc yarrow: trim trailing spaces 2012-05-04 01:00:25 +02:00
Steffen Jaeckel
2cd666f284 rsa_import: prevent double-free 2012-04-24 18:08:13 +02:00
Steffen Jaeckel
5c9fa403ff Merge pull request #3 from gpakosz/patch-1
replaced free(in) by XFREE(in) at line 56
2011-07-12 06:01:19 -07:00
Gregory Pakosz
1346ccdee8 replaced free(in) by XFREE(in) at line 56 2011-07-12 05:56:48 -07:00
Steffen Jaeckel
8859f6e73d fixed wrong return value interpretation of register_crypt/hash/prng function calls 2011-06-14 20:56:42 +02:00
Steffen Jaeckel
2b0ce25778 testme.sh: added parameter checking 2011-05-20 09:41:57 +02:00
Steffen Jaeckel
5ec1e53e02 updated gitignore 2011-03-21 22:59:59 +01:00
Steffen Jaeckel
8dc8a2d551 Added define LTC_RSA_BLINDING to be able to disable rsa blinding 2011-03-21 22:50:49 +01:00
Steffen Jaeckel
380693edd9 fixed error causing segmentation fault 2011-03-21 21:17:59 +01:00
Steffen Jaeckel
496453f289 removed testing of "stripped" rsa key 2011-03-21 21:17:31 +01:00
Steffen Jaeckel
25bd5c1275 added missing handling of new type LTC_ASN1_RAW_BIT_STRING in der_encode_sequence_multi() 2011-03-21 21:12:46 +01:00
Steffen Jaeckel
43c6b5ab89 make build.sh less verbose when test fails 2011-03-21 21:10:23 +01:00
Nikos Mavrogiannopoulos
fa22e791d4 RSA and DSA public keys are stored using the SubjectPublicKeyInfo format. 2011-03-21 19:24:10 +01:00
Nikos Mavrogiannopoulos
8c2850f8d9 Added RSA blinding (requires mp_rand()). 2011-03-21 08:26:41 +01:00
Nikos Mavrogiannopoulos
ed6897d90f DSA private keys are being exported to a compatible with OpenSSL and GnuTLS format. 2011-03-21 08:26:27 +01:00
Steffen Jaeckel
2895c9d7fe updated gitignore 2011-01-25 11:27:28 +01:00
Steffen Jaeckel
5b1c0108c9 updated gitignore and VS2008 project file 2011-01-24 10:41:30 +01:00
Steffen Jaeckel
412b2ee1fc after multiple objections of libtom users [1], we decided to change licensing
to a dual licensing model.

[1] https://groups.google.com/group/libtom/browse_thread/thread/d7b67bc6410250b3
2011-01-19 10:18:15 +01:00
Steffen Jaeckel
4a8927d5c0 updated gitignore to ignore files generated when executing build.sh 2011-01-19 09:21:19 +01:00
Steffen Jaeckel
edf11c62c0 Diffie-Hellman/Math: introduced the proposed changes by Alexander Kurpiers
addmod and submod are moved to the end of the math descriptor, in order
to be able to run existing software against a new version of ltc without need
to rebuild the software.
2011-01-18 21:16:11 +01:00
Steffen Jaeckel
6fecec107d rejoined diffie hellman code from ltc 1.05, thanks to Alexander Kurpiers 2011-01-18 20:06:03 +01:00
Steffen Jaeckel
5039e6520f fixed tests and testvectors 2011-01-18 19:42:38 +01:00
Steffen Jaeckel
77e31fb6a9 Re-licensed all code under WTFPL, c.f. http://sam.zoy.org/wtfpl/ 2010-10-26 16:02:34 +02:00
Steffen Jaeckel
e7ce129e9b flushed content of CVS/SVN tags 2010-06-16 20:02:51 +02:00
Steffen Jaeckel
c3018d69d0 removed gcc compiler warnings 2010-06-16 20:02:11 +02:00
Steffen Jaeckel
59f9c00f98 removed IAR compiler warnings 2010-06-16 20:02:01 +02:00
Daniel Akesson
e960ff887c Added project and solution files for Visual Studio 2005 and Visual Studio 2008. 2010-06-16 20:01:47 +02:00
Steffen Jaeckel
3522c754aa changed LTC_LTC_PKCS_1_* enum members to LTC_PKCS_1_* 2010-06-16 20:01:31 +02:00
Steffen Jaeckel
0a432b6b08 adjusted file dependant functions
when LTC_NO_FILE is defined, the functions hash_filehandle()
and hash_file() won't be available at all instead of returning CRYPT_NOP
2010-06-16 20:00:50 +02:00
Steffen Jaeckel
6816ac3f3f modification to suppress compiler warning when LTC_FAST is not defined 2010-06-16 19:59:39 +02:00
Steffen Jaeckel
fcd5faf947 added gitignore to suppress .o and .a files 2010-06-16 19:58:57 +02:00
Steffen Jaeckel
2f1fc7c50d import of libtomcrypt
out of
  lt_tree.tar.bz2
checksums of lt_tree.tar.bz2
MD5: 3c36e1ca95518f4d00a76dc9b7049952
SHA1: 4f31d1aa8cd1b9d7452b777cd52f8280dc7ebcbc
2010-06-16 19:58:20 +02:00
Tom St Denis
bbc52b9e1b added libtomcrypt-1.17 2010-06-16 12:39:13 +02:00
Tom St Denis
e24b01d392 added libtomcrypt-1.16 2010-06-16 12:39:09 +02:00
Tom St Denis
2de2976d25 added libtomcrypt-1.15 2010-06-16 12:39:06 +02:00
Tom St Denis
479cc9c261 added libtomcrypt-1.14 2010-06-16 12:39:03 +02:00
Tom St Denis
1eed98f629 added libtomcrypt-1.13 2010-06-16 12:39:00 +02:00
Tom St Denis
2945dea3e2 added libtomcrypt-1.12 2010-06-16 12:38:57 +02:00
Tom St Denis
64d7ebe166 added libtomcrypt-1.11 2010-06-16 12:38:54 +02:00
Tom St Denis
99b6d03203 added libtomcrypt-1.10 2010-06-16 12:38:51 +02:00
Tom St Denis
a3ce807bae added libtomcrypt-1.09 2010-06-16 12:38:49 +02:00
Tom St Denis
1eeff0bfb4 added libtomcrypt-1.08 2010-06-16 12:38:47 +02:00
Tom St Denis
4a1a5796de added libtomcrypt-1.07 2010-06-16 12:38:44 +02:00
Tom St Denis
72412f6dac added libtomcrypt-1.06 2010-06-16 12:38:41 +02:00
Tom St Denis
9264e34ffb added libtomcrypt-1.05 2010-06-16 12:38:39 +02:00
Tom St Denis
9da48eb84b added libtomcrypt-1.04 2010-06-16 12:38:36 +02:00
Tom St Denis
3964a6523a added libtomcrypt-1.03 2010-06-16 12:38:34 +02:00
Tom St Denis
65c1317eee added libtomcrypt-1.02 2010-06-16 12:38:32 +02:00
Tom St Denis
6ac9952498 added libtomcrypt-1.01 2010-06-16 12:38:29 +02:00
Tom St Denis
bfc2f5b078 added libtomcrypt-1.00 2010-06-16 12:38:26 +02:00
Tom St Denis
1c1822d510 added libtomcrypt-0.99 2010-06-16 12:38:24 +02:00
Tom St Denis
69f289d6dc added libtomcrypt-0.98 2010-06-16 12:38:22 +02:00
1229 changed files with 192824 additions and 37469 deletions

View file

@ -0,0 +1,6 @@
{
<s_decode_header>
Memcheck:Cond
...
fun:s_decode_header
}

71
.ci/build.sh Executable file
View file

@ -0,0 +1,71 @@
#!/bin/bash
echo "$1 ($2, $3)..."
make clean 1>/dev/null 2>/dev/null
echo -n "building..."
if [ -f /proc/cpuinfo ]
then
MAKE_JOBS=$(( ($(cat /proc/cpuinfo | grep -E '^processor[[:space:]]*:' | tail -n -1 | cut -d':' -f2) + 1) * 2 + 1 ))
else
MAKE_JOBS=8
fi
CFLAGS="$2 $CFLAGS $4" EXTRALIBS="$5" make -j$MAKE_JOBS -f $3 all_test 1>gcc_1.txt 2>gcc_2.txt
mret=$?
cnt=$(wc -l < gcc_2.txt)
# ignore 1 line since ar prints to stderr instead of stdout and ar is called for
# $(LIBNAME)
if [[ $mret -ne 0 ]] || [[ $cnt -gt 1 ]]; then
echo "build $1 failed! printing gcc_2.txt now for convenience"
cat gcc_2.txt
exit 1
fi
# remove the standard arguments from the make options
opts=${3//makefile.shared/}
opts=${opts//makefile/}
opts=${opts//V=1/}
opts=${opts//COVERAGE=1/}
opts=$(echo $opts | tr -d '[:space:]')
# if there's something else than the standard arguments we check if we're currently
# building a Travis PR and if it's like that, we skip those tests
if [ ! -z "$opts" ]; then
if [ ! -z "$TRAVIS_PULL_REQUEST" ] && [ "$TRAVIS_PULL_REQUEST" != "false" ]; then
echo "PR Tests skipped" | tee testok.txt
exit 0
fi
fi
echo -n "testing..."
if [ -a test ] && [ -f test ] && [ -x test ]; then
((./test >test_std.txt 2>test_err.txt && ./tv_gen > tv.txt) && echo "$1 test passed." && echo "y" > testok.txt) || (echo "$1 test failed, look at test_err.txt or tv.txt" && exit 1)
if find *_tv.txt -type f 1>/dev/null 2>/dev/null ; then
for f in *_tv.txt; do
# check for lines starting with '<' ($f might be a subset of notes/$f)
difftroubles=$(diff -i -w -B $f notes/$f | grep '^<')
if [ -n "$difftroubles" ]; then
echo "FAILURE: $f"
diff -i -w -B $f notes/$f
echo "tv_gen $f failed" && rm -f testok.txt && exit 1
else
true
fi
done
fi
fi
if [ -a testok.txt ] && [ -f testok.txt ]; then
if [ "$LTC_COVERAGE" != "" ]; then
bash .ci/coverage_more.sh > test_coverage_more.txt || exit 1
lcov_opts="--capture --no-external --directory src -q"
lcov_out=$(echo coverage_$1_$2_$3 | tr ' -=+' '_')".info"
lcov $lcov_opts --output-file $lcov_out
fi
exit 0
fi
exit 1

46
.ci/build_options.sh Executable file
View file

@ -0,0 +1,46 @@
#!/bin/bash
if [ "$#" != "5" ]; then
echo "Usage is: ${0} \"build_options\" \"<prepend CFLAGS>\" \"<makefile>\" \"<append CFLAGS>\" <math library to link to>"
echo "CC=gcc ${0} \"build_options\" \" \" \"makefile\" \"-DUSE_LTM -DLTM_DESC -I../libtommath\" ../libtommath/libtommath.a"
exit -1
fi
# output version
bash .ci/printinfo.sh
set -e
options=(
-DLTC_EASY
-DLTC_FORTUNA_RESEED_RATELIMIT_STATIC
-DLTC_FORTUNA_USE_ENCRYPT_ONLY
-DLTC_MECC_FP
-DLTC_NO_TABLES
-DLTC_NO_FAST
-DLTC_NO_ASM
-DLTC_NO_DEPRECATED_APIS
-DLTC_NO_ECC_TIMING_RESISTANT
-DLTC_NO_RSA_BLINDING
-DLTC_PTHREAD
-DLTC_SMALL_CODE
-DLTC_SMALL_STACK
)
make clean V=0
make pre_gen
for opt in ${options[@]}; do
echo "Build: $opt"
CFLAGS="$2 $CFLAGS $4 $opt" EXTRALIBS="$5" make -j$(nproc) -f $3 AMALGAM=1 all 1>>gcc_1.txt 2>>gcc_2.txt
./small
make clean V=0
done
# we don't want LTC_EASY when running the tests now
unset 'options[0]'
echo "All: ${options[@]}"
CFLAGS="$2 $CFLAGS $4 ${options[@]}" EXTRALIBS="$5" make -j$(nproc) -f $3 AMALGAM=1 all 1>>gcc_1.txt 2>>gcc_2.txt
./test >test_std.txt 2>test_err.txt
exit 0

11
.ci/check_source.sh Executable file
View file

@ -0,0 +1,11 @@
#!/bin/bash
# output version
bash .ci/printinfo.sh
make clean > /dev/null
echo "checking..."
./helper.pl --check-all || exit 1
exit 0

47
.ci/clang-tidy.sh Executable file
View file

@ -0,0 +1,47 @@
#!/bin/bash
# output version
bash .ci/printinfo.sh
# tested with clang-tidy from llvm-6.0.0
# not tested with Travis-CI
#### we use the main test sets:
# readability
# misc
# clang-analyzer
# google
# performance
# modernize
# cert
# bugprone
# portability
#### the following checks are skipped
# google-readability-function-size
# readability-function-size
# google-readability-casting
# readability-braces-around-statements
# misc-macro-parentheses
# clang-analyzer-valist.Uninitialized
echo "Run clang-tidy version"
clang-tidy --version || exit 1
echo "Run clang-tidy..."
clang-tidy src/*/*.c src/*/*/*.c src/*/*/*/*.c src/*/*/*/*/*.c -warnings-as-errors='*' --quiet --checks=-*,\
readability-*,-readability-function-size,-readability-braces-around-statements,\
misc-*,-misc-macro-parentheses,\
clang-analyzer-*,-clang-analyzer-valist.Uninitialized,\
google-*,-google-readability-function-size,-google-readability-casting,\
performance-*,\
modernize-*,\
cert-*,\
bugprone-*,\
portability-* -- -DUSE_LTM -DLTM_DESC -Isrc/headers -I../libtommath || { echo "clang-tidy FAILED!"; exit 1; }
echo "clang-tidy ok"
exit 0

9
.ci/cmake.bat Normal file
View file

@ -0,0 +1,9 @@
if "Visual Studio 2017"=="%APPVEYOR_BUILD_WORKER_IMAGE%" goto :eof
if "Visual Studio 2015"=="%APPVEYOR_BUILD_WORKER_IMAGE%" goto :eof
mkdir build
cd build
cmake -G "Ninja" ..
ninja
cd..

47
.ci/coverage.sh Executable file
View file

@ -0,0 +1,47 @@
#!/bin/bash
set -e
if [ "$TRAVIS_CI" == "private" ]; then
exit 0
fi
if [ "$#" != "5" ]; then
echo "Usage is: ${0} \"coverage\" \"<prepend CFLAGS>\" \"<makefile>\" \"<append CFLAGS>\" <math library to link to>"
echo "CC=gcc ${0} \"coverage\" \" \" \"makefile\" \"-DUSE_LTM -DLTM_DESC -I../libtommath\" ../libtommath/libtommath.a"
exit -1
fi
if [ -z "$(echo $CC | grep "gcc")" ]; then
echo "no gcc detected, early exit success"
exit 0
fi
if [ "$(echo $3 | grep -v 'makefile[.]')" == "" ]; then
echo "only run $0 for the regular makefile, early exit success"
exit 0
fi
# output version
bash .ci/printinfo.sh
bash .ci/build.sh " $1" " $2" " $3 COVERAGE=1" "$4" "$5"
if [ -a testok.txt ] && [ -f testok.txt ]; then
echo
else
echo
echo "Test failed"
exit 1
fi
bash .ci/coverage_more.sh "$5" > test_coverage_more.txt || { rm -f testok.txt && exit 1 ; }
make lcov-single
# if this isn't run on CI create coverage locally
if [ "$CI" == "" ]; then
make lcov-html
else
coveralls-lcov coverage.info --service-job-id="$GITHUB_RUN_ID" --service-name="github" --repo-token="$REPO_TOKEN" --branch="$GITHUB_REF_NAME" --service-pull-request="$PR_NUMBER"
fi
exit 0

48
.ci/coverage_more.sh Executable file
View file

@ -0,0 +1,48 @@
#!/bin/bash
set -e
function pdiv() {
printf "\n====== %s ======\n" "$*"
}
if [ "$#" = "1" -a "$(echo $1 | grep 'gmp')" != "" ]; then
pdiv "Test GMP"
./test t gmp
fi
pdiv "Sizes"
./sizes
pdiv "Constants"
./constants
pdiv "Generate hashsum_tv.txt"
for i in $(for j in $(echo $(./hashsum -h | awk '/Algorithms/,EOF' | tail -n +2)); do echo $j; done | sort); do
echo -n "$i: " && ./hashsum -a $i tests/test.key
done > hashsum_tv.txt
pdiv "Compare hashsum_tv.txt"
difftroubles=$(diff -i -w -B hashsum_tv.txt notes/hashsum_tv.txt | grep '^<') || true
if [ -n "$difftroubles" ]; then
echo "FAILURE: hashsum_tv.tx"
diff -i -w -B hashsum_tv.txt notes/hashsum_tv.txt
echo "hashsum failed"
exit 1
else
echo "hashsum okay"
fi
pdiv "aesgcm"
./hashsum -a sha256 aesgcm > aesgcm.sha256sum
./aesgcm -e aesgcm aesgcm.enc0 "00112233445566778899AABBCCDDEEFF00112233445566778899AABBCCDDEEFF00112233445566778899AABBCCDDEEFF"
./aesgcm -d aesgcm.enc0 aesgcm.dec0 "00112233445566778899AABBCCDDEEFF00112233445566778899AABBCCDDEEFF00112233445566778899AABBCCDDEEFF"
./aesgcm -e aesgcm aesgcm.enc1 "00112233445566778899AABBCCDDEEFF00112233445566778899AABBCCDDEEFF00112233445566778899AABB"
./aesgcm -d aesgcm.enc1 aesgcm.dec1 "00112233445566778899AABBCCDDEEFF00112233445566778899AABBCCDDEEFF00112233445566778899AABB"
for i in {0..1}; do
rm aesgcm
mv aesgcm.dec${i} aesgcm
./hashsum -c aesgcm.sha256sum
done
chmod +x aesgcm
exit 0

114
.ci/meta_builds.sh Executable file
View file

@ -0,0 +1,114 @@
#!/bin/bash
#
# This builds different stuff depending on the compiler:
# gcc - valgrind, coverage
# clang - asan, ubsan, scan-build
# both - the two testbuild's NOTEST and NOFILE
set -e
if [ "$#" = "5" -a "$(echo $3 | grep -v 'makefile[.]')" = "" ]; then
echo "only run $0 for the regular makefile, early exit success"
exit 0
fi
if [ -f /proc/cpuinfo ]
then
MAKE_JOBS=$(( ($(cat /proc/cpuinfo | grep -E '^processor[[:space:]]*:' | tail -n -1 | cut -d':' -f2) + 1) * 2 + 1 ))
else
MAKE_JOBS=8
fi
function run_gcc() {
bash .ci/check_source.sh "CHECK_SOURCES" "$2" "$3" "$4" "$5"
make -j$(nproc) latex-tables V=0
./latex-tables
echo "verify docs..."
while read -r line; do
grep -q -e "$line" doc/crypt.tex || { echo "Failed to find \"$line\" in doc/crypt.tex"; exit 1; }
done < <(./latex-tables | grep '^\\' | sed 's@\\@\\\\@g')
echo "docs OK"
make clean &>/dev/null
echo
echo "Build for ASAN..."
make -j$MAKE_JOBS CFLAGS="-fsanitize=address -fno-omit-frame-pointer -static-libasan $2 $CFLAGS $4" EXTRALIBS="-lasan $5" test LTC_DEBUG=1 V=1 1>gcc_1.txt 2>gcc_2.txt
echo
echo "Run ASAN tests with LTM..."
ASAN_OPTIONS=verbosity=1 ./test t ltm 1>test_std.txt 2> test_err.txt || exit 1
if echo $* | grep -q GMP ; then
echo
echo "Run ASAN tests with GMP..."
ASAN_OPTIONS=verbosity=1 ./test t gmp 1>test_std.txt 2> test_err.txt || exit 1
fi
make clean &>/dev/null
echo
echo "Create code coverage"
bash .ci/coverage.sh "COVERAGE" "$2" "$3" "$4" "$5"
}
function run_clang() {
# output version
bash .ci/printinfo.sh
scan_build=$(which scan-build) || true
[ -z "$scan_build" ] && scan_build=$(find /usr/bin/ -name 'scan-build-[0-9]*' | sort -nr | head -n1) || true
[ -z "$scan_build" ] && { echo "couldn't find clang scan-build"; exit 1; } || echo "run $scan_build"
$scan_build --status-bugs make -j$MAKE_JOBS all CFLAGS="$2 $CFLAGS $4" EXTRALIBS="$5"
make clean &>/dev/null
echo
echo "Build for UBSAN..."
make -j$MAKE_JOBS LDFLAGS="-fsanitize=undefined" CFLAGS="$2 $CFLAGS $4" EXTRALIBS="$5" all LTC_DEBUG=1 V=1 1>gcc_1.txt 2>gcc_2.txt
echo "Run UBSAN tests with LTM..."
UBSAN_OPTIONS=verbosity=1 ./test t ltm 1>test_std.txt 2> test_err.txt || exit 1
if echo $* | grep -q GMP ; then
echo
echo "Run UBSAN tests with GMP..."
UBSAN_OPTIONS=verbosity=1 ./test t gmp 1>test_std.txt 2> test_err.txt || exit 1
fi
}
make clean &>/dev/null
EXTRALIBS="$5"
echo $* | grep -q GMP && EXTRALIBS="$EXTRALIBS -lgmp"
if [ -z "$(echo $CC | grep "clang")" ]; then
run_gcc "$1" "$2" "$3" "$4" "$EXTRALIBS"
else
run_clang "$1" "$2" "$3" "$4" "$EXTRALIBS"
fi
make clean &>/dev/null
bash .ci/testbuild.sh "NOTEST" "-DLTC_NO_TEST" "$3" "$4" "$EXTRALIBS"
make clean &>/dev/null
bash .ci/testbuild.sh "NOFILE" "-DLTC_NO_FILE" "$3" "$4" "$EXTRALIBS"
make clean &>/dev/null
echo
echo "Build full debug..."
make -j$MAKE_JOBS CFLAGS="$2 $CFLAGS $4" EXTRALIBS="$EXTRALIBS" all_test LTC_DEBUG=2 V=1 1>gcc_1.txt 2>gcc_2.txt

20
.ci/printinfo.sh Normal file
View file

@ -0,0 +1,20 @@
#!/bin/bash
version=$(git describe --tags --always --dirty 2>/dev/null)
if [ ! -e ".git" ] || [ -z $version ]
then
version=$(grep "^VERSION=" makefile_include.mk | sed "s/.*=//")
fi
echo "Testing version:" $version
#grep "VERSION=" makefile | perl -e "@a = split('=', <>); print @a[1];"`
# get uname
echo "uname="`uname -a`
# get gcc name
if [ -z ${CC} ]
then
CC="gcc"
fi
echo "${CC}="`${CC} -dumpversion`
echo

45
.ci/run.sh Executable file
View file

@ -0,0 +1,45 @@
#!/bin/bash
# output version
bash .ci/printinfo.sh
bash .ci/build.sh " $1" "$2" "$3" "$4" "$5"
if [ -a testok.txt ] && [ -f testok.txt ]; then
echo
else
echo
echo "Test failed"
exit 1
fi
rm -f testok.txt
bash .ci/build.sh " $1" "$2" "$3 LTC_DEBUG=1" "$4" "$5"
if [ -a testok.txt ] && [ -f testok.txt ]; then
echo
else
echo
echo "Test failed"
exit 1
fi
rm -f testok.txt
bash .ci/build.sh " $1" "$2 -O2" "$3 IGNORE_SPEED=1" "$4" "$5"
if [ -a testok.txt ] && [ -f testok.txt ]; then
echo
else
echo
echo "Test failed"
exit 1
fi
rm -f testok.txt
bash .ci/build.sh " $1" "$2" "$3 IGNORE_SPEED=1 LTC_SMALL=1" "$4" "$5"
if [ -a testok.txt ] && [ -f testok.txt ]; then
echo
else
echo
echo "Test failed"
exit 1
fi
exit 0

22
.ci/testbuild.sh Executable file
View file

@ -0,0 +1,22 @@
#!/bin/bash
# output version
bash .ci/printinfo.sh
if [ -f /proc/cpuinfo ]
then
MAKE_JOBS=$(( ($(cat /proc/cpuinfo | grep -E '^processor[[:space:]]*:' | tail -n -1 | cut -d':' -f2) + 1) * 2 + 1 ))
else
MAKE_JOBS=8
fi
echo "$1 (Build Only, $2, $3)..."
make clean 1>/dev/null 2>/dev/null
echo -n "building..."
touch testok.txt
make -j$MAKE_JOBS -f $3 test tv_gen CFLAGS="$2 $CFLAGS $4" EXTRALIBS="$5" 1>gcc_1.txt 2>gcc_2.txt || (echo "build $1 failed see gcc_2.txt for more information" && cat gcc_2.txt && rm -f testok.txt && exit 1)
if find testok.txt -type f 1>/dev/null 2>/dev/null ; then
echo "successful"
exit 0
fi
exit 1

43
.ci/valgrind.sh Executable file
View file

@ -0,0 +1,43 @@
#!/bin/bash
set -e
if [ "$#" = "5" -a "$(echo $3 | grep -v 'makefile[.]')" = "" ]; then
echo "only run $0 for the regular makefile, early exit success"
exit 0
fi
if [ -f /proc/cpuinfo ]
then
MAKE_JOBS=$(( ($(cat /proc/cpuinfo | grep -E '^processor[[:space:]]*:' | tail -n -1 | cut -d':' -f2) + 1) * 2 + 1 ))
else
MAKE_JOBS=8
fi
# output version
bash .ci/printinfo.sh
make clean &>/dev/null
echo "Build for valgrind..."
# set DWARFv4 as debug format for clang, since it creates DWARFv5 as default which isn't support in old valgrind
[ -z "$(echo $CC | grep "clang")" ] || GFLAG="-gdwarf-4"
make -j$MAKE_JOBS CFLAGS="$2 $CFLAGS $4 $GFLAG" EXTRALIBS="$5" test LTC_DEBUG=1 1>gcc_1.txt 2>gcc_2.txt
echo "Run tests with valgrind..."
for i in `seq 1 10` ; do sleep 300 && echo "Valgrind tests in Progress..."; done &
alive_pid=$!
readonly VALGRIND_OPTS="--error-exitcode=666 --leak-check=full --show-leak-kinds=all --errors-for-leak-kinds=all"
readonly distro="$(lsb_release -si)_$(lsb_release -sc)"
readonly suppfile=".ci/Valgrind-${distro}.supp"
function get_suppfile() { [ -f "$suppfile" ] && echo "--suppressions=$suppfile" || echo ""; }
readonly VALGRIND_EXTRA_OPTS=$(get_suppfile)
valgrind $VALGRIND_OPTS $VALGRIND_EXTRA_OPTS ./test >test_std.txt 2> >(tee -a test_err.txt >&2) || { kill $alive_pid; echo "Valgrind failed"; exit 1; }
kill $alive_pid

42
.clang-format Normal file
View file

@ -0,0 +1,42 @@
---
AccessModifierOffset: -2
ConstructorInitializerIndentWidth: 4
AlignEscapedNewlinesLeft: false
AlignTrailingComments: true
AllowAllParametersOfDeclarationOnNextLine: false
AllowShortIfStatementsOnASingleLine: false
AllowShortLoopsOnASingleLine: false
AlwaysBreakTemplateDeclarations: false
AlwaysBreakBeforeMultilineStrings: false
BreakBeforeBinaryOperators: false
BreakConstructorInitializersBeforeComma: false
BinPackParameters: true
ColumnLimit: 120
ConstructorInitializerAllOnOneLineOrOnePerLine: true
DerivePointerBinding: true
ExperimentalAutoDetectBinPacking: false
IndentCaseLabels: true
MaxEmptyLinesToKeep: 1
NamespaceIndentation: None
ObjCSpaceBeforeProtocolList: false
PenaltyBreakComment: 60
PenaltyBreakString: 1000
PenaltyBreakFirstLessLess: 120
PenaltyExcessCharacter: 1000000
PenaltyReturnTypeOnItsOwnLine: 200
PointerBindsToType: false
SpacesBeforeTrailingComments: 1
Cpp11BracedListStyle: false
Standard: Cpp03
IndentWidth: 3
TabWidth: 8
UseTab: Never
BreakBeforeBraces: Linux
IndentFunctionDeclarationAfterType: false
SpacesInParentheses: false
SpaceInEmptyParentheses: false
SpacesInCStyleCastParentheses: false
SpaceAfterControlStatementKeyword: true
SpaceBeforeAssignmentOperators: true
...

7
.gitattributes vendored Normal file
View file

@ -0,0 +1,7 @@
/.gitattributes export-ignore
/.gitignore export-ignore
/.travis.yml export-ignore
/** export-subst
/tests/test.key -text

39
.github/ISSUE_TEMPLATE/01-bug_report.md vendored Normal file
View file

@ -0,0 +1,39 @@
---
name: Bug report
about: Create a bug report
title: ''
labels: bug
assignees: ''
---
<!--
Do you want to ask a question? Are you looking for support? The Mailing list is the best place for getting support: https://groups.google.com/forum/#!forum/libtom
This is a very generic template, remove items that do not apply. For completed items, change [ ] to [x].
-->
### Prerequisites
* [ ] Checked the developer manual
* [ ] Checked that your issue isn't already filed: https://github.com/issues?utf8=✓&q=repo%3Alibtom%2Flibtomcrypt
* [ ] Checked that your issue isn't due to the fact that you're using asymmetric cryptography and you forgot linking in and/or setting an MPI provider (usually this causes either random crashes or runtime errors like `LTC_ARGCHK 'ltc_mp.name != NULL' failure ...`). c.f. Ch. "Math Descriptors" of the developer manual.
* [ ] Checked that your issue isn't related to TomsFastMath's limitation that PK operations can by default only be done with max. 2048bit keys
### Description
[Description of the issue]
### Steps to Reproduce
<!-- Please either describe your issue or even better, provide a functional code example reproducing your issue. -->
### Version
You can get this information from the define `SCRYPT` in `src/include/tomcrypt.h` or your local git repository by running `git describe --always --tags --dirty`.
Also, please include the compiler, the compiler version, the architecture and (if applicable) the MPI provider, the OS and what version of the OS you're experiencing the issue.
### Additional Information
Any additional information, configuration or data that might be necessary to reproduce the issue.

18
.github/PULL_REQUEST_TEMPLATE.md vendored Normal file
View file

@ -0,0 +1,18 @@
<!--
Thank you for your pull request.
If this fixes an existing github issue, make sure to have a line saying 'Fixes: <github-issue>' (without quotes) in the commit message.
Please use the long format to refer to an issue 'libtom/libtomcrypt#<issue-id>'.
If this fixes something (even if there exists no github issue), make sure to have a line saying 'Fixes: <commit-id> ("Description")'
This can be created via e.g. `git --no-pager log -1 --pretty=fixes <commid-id>
-->
### Checklist
<!-- Remove items that do not apply. For completed items, change [ ] to [x]. -->
* [ ] documentation is added or updated
* [ ] tests are added or updated
* [ ] if this fixes something: added a `Fixes:` tag to the commit message

168
.github/workflows/main.yml vendored Normal file
View file

@ -0,0 +1,168 @@
name: CI
on:
push:
branches:
- master
- develop
- 'release/**'
- 'support/**'
- 'ci/**'
pull_request:
branches:
- master
- develop
- 'release/**'
- 'support/**'
- 'ci/**'
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
jobs:
Docs:
runs-on: ubuntu-24.04
container: texlive/texlive:latest-medium
steps:
- uses: actions/checkout@v4
- name: generate PDF
run: |
make docs
cp doc/crypt.pdf crypt-${{ github.run_id }}.pdf
- name: upload PDF
uses: actions/upload-artifact@v4
with:
name: crypt-${{ github.run_id }}.pdf
path: crypt-${{ github.run_id }}.pdf
Build:
runs-on: ${{ matrix.os }}
strategy:
matrix:
cc: [ gcc, clang ]
os: [ ubuntu-22.04, ubuntu-24.04 ]
config:
- { BUILDNAME: 'META_BUILDS', BUILDOPTIONS: '-DGMP_DESC', BUILDSCRIPT: '.ci/meta_builds.sh' }
- { BUILDNAME: 'VALGRIND', BUILDOPTIONS: '', BUILDSCRIPT: '.ci/valgrind.sh' }
- { BUILDNAME: 'STOCK', BUILDOPTIONS: '', BUILDSCRIPT: '.ci/run.sh' }
- { BUILDNAME: 'BUILD_OPTIONS', BUILDOPTIONS: '', BUILDSCRIPT: '.ci/build_options.sh' }
- { BUILDNAME: 'STOCK-MPI', BUILDOPTIONS: '-ULTM_DESC -UTFM_DESC -UUSE_LTM -UUSE_TFM', BUILDSCRIPT: '.ci/run.sh' }
- { BUILDNAME: 'STOCK+ARGTYPE=1', BUILDOPTIONS: '-DARGTYPE=1', BUILDSCRIPT: '.ci/run.sh' }
- { BUILDNAME: 'STOCK+ARGTYPE=2', BUILDOPTIONS: '-DARGTYPE=2', BUILDSCRIPT: '.ci/run.sh' }
- { BUILDNAME: 'STOCK+ARGTYPE=3', BUILDOPTIONS: '-DARGTYPE=3', BUILDSCRIPT: '.ci/run.sh' }
- { BUILDNAME: 'STOCK+ARGTYPE=4', BUILDOPTIONS: '-DARGTYPE=4', BUILDSCRIPT: '.ci/run.sh' }
steps:
- uses: actions/checkout@v4
- name: install dependencies
uses: nick-fields/retry@v4.0.0
with:
timeout_minutes: 20
max_attempts: 3
command: |
sudo apt-get update -qq
sudo apt-get install -y libgmp-dev valgrind libtool-bin clang-tools lcov ruby clang
sudo apt-get remove -y libtommath1
sudo gem install coveralls-lcov
curl -s https://packagecloud.io/install/repositories/libtom/packages/script.deb.sh | sudo bash
sudo apt-get install libtfm-git-dev libtommath-git-dev
- name: run tests
env:
CC: "${{ matrix.cc }}"
PR_NUMBER: ${{ github.event.number }}
REPO_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
bash "${{ matrix.config.BUILDSCRIPT }}" "${{ matrix.config.BUILDNAME }}" "-DUSE_LTM -DLTM_DESC" "makefile V=1" "${{ matrix.config.BUILDOPTIONS }}" "-ltommath"
bash "${{ matrix.config.BUILDSCRIPT }}" "${{ matrix.config.BUILDNAME }}" "-DUSE_TFM -DTFM_DESC" "makefile.shared V=1" "${{ matrix.config.BUILDOPTIONS }}" "-ltfm"
- name: regular logs
if: ${{ !failure() }}
run: |
cat gcc_1.txt || true
cat gcc_2.txt || true
- name: error logs
if: ${{ failure() }}
run: |
cat gcc_1.txt || true
cat gcc_2.txt || true
cat test_std.txt || true
cat test_err.txt || true
cat tv.txt || true
- name: pack build directory
if: ${{ failure() }}
run: |
tar cJf build-${{ github.run_id }}.tar.xz --exclude ./build-${{ github.run_id }}.tar.xz .
- name: upload Artifact
if: ${{ failure() }}
uses: actions/upload-artifact@v4
with:
name: build-${{ github.run_id }}.tar.xz
path: build-${{ github.run_id }}.tar.xz
retention-days: 1
Amalgam:
runs-on: ${{ matrix.os }}
strategy:
matrix:
cc: [ gcc, clang ]
os: [ ubuntu-22.04, ubuntu-24.04 ]
steps:
- uses: actions/checkout@v4
- name: install dependencies
uses: nick-fields/retry@v4.0.0
with:
timeout_minutes: 20
max_attempts: 3
command: |
sudo apt-get update -qq
sudo apt-get remove -y libtommath1
curl -s https://packagecloud.io/install/repositories/libtom/packages/script.deb.sh | sudo bash
sudo apt-get install libtommath-git-dev
- name: run tests
env:
CC: "${{ matrix.cc }}"
run: |
make pre_gen
make CFLAGS="-DLTM_DESC -DUSE_LTM" EXTRALIBS="-ltommath" AMALGAM=1 -j$(nproc) check
CMake:
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ ubuntu-22.04, ubuntu-24.04, ubuntu-22.04-arm, ubuntu-24.04-arm ]
build_type: [ '', -DCMAKE_BUILD_TYPE=Debug, -DCMAKE_BUILD_TYPE=Release, -DCMAKE_BUILD_TYPE=RelWithDebInfo, -DCMAKE_BUILD_TYPE=MinSizeRel ]
cc: [ clang, gcc ]
cflags: [ '', '-DLTC_CFLAGS="-DLTC_NO_ASM"']
config:
# Static library build
- { CMAKEOPTIONS: '-DBUILD_SHARED_LIBS=Off' }
# Shared library build
- { CMAKEOPTIONS: '-DBUILD_SHARED_LIBS=On' }
steps:
- uses: actions/checkout@v4
- name: install dependencies
uses: nick-fields/retry@v4.0.0
with:
timeout_minutes: 20
max_attempts: 3
command: |
sudo apt-get update -qq
sudo apt-get remove -y libtommath1
curl -s https://packagecloud.io/install/repositories/libtom/packages/script.deb.sh | sudo bash
sudo apt-get install libtommath-git-dev
sudo apt-get install -y cmake gcc clang llvm
- name: build
run: |
mkdir build
cd build
CC=${{ matrix.cc }} cmake ${{ matrix.config.CMAKEOPTIONS }} ${{ matrix.build_type }} ${{ matrix.cflags }} ..
make -j$(nproc)
- name: test
run: |
cd build
CC=${{ matrix.cc }} cmake ${{ matrix.config.CMAKEOPTIONS }} ${{ matrix.build_type }} ${{ matrix.cflags }} -DBUILD_TESTING=On ..
make -j$(nproc)
ctest
- name: error logs
if: ${{ failure() }}
run: |
cat build/Testing/Temporary/LastTest.log || true
cat demo/build/Testing/Temporary/LastTest.log || true

121
.gitignore vendored Normal file
View file

@ -0,0 +1,121 @@
# suppress compiler/linker output
*.[oa]
*.obj
*.dylib*
*.dll*
*.so*
[Dd]ebug/
[Rr]elease/
/MSVC_*
.bin/
# release files
/libtomcrypt-*
/crypt-*
pre_gen/
# suppress output of build process
gcc_[12].txt
testok.txt
test_*.txt
tv.txt
*_tv.txt
doxygen/
doc/crypt.pdf
doc/refman.pdf
# *nix/windows test executables
ltc-*
aesgcm
aesgcm.exe
constants
constants.exe
crypt
crypt.exe
der_print_flexi
der_print_flexi.exe
hashsum
hashsum.exe
multi
multi.exe
openssl-enc
openssl-enc.exe
openssh-privkey
openssh-privkey.exe
latex-tables
latex-tables.exe
sizes
sizes.exe
small
small.exe
test
test.exe
tv_gen
tv_gen.exe
timing
timing.exe
# Visual Studio special files
# ignore user specific settings
*.user
*.suo
# ignore non-compressed browse file (holds information for ClassView, IntelliSense and WizardBar)
*.ncb
# ignore VS intermediate and program database files
*.idb
*.pdb
# Eclipse special files
.project
.cproject
.settings/
# KDevelop special files
*.kdev4
# macOS special files
.DS_Store
# other special files
showlibs # symlink to .libs
# oops ;) but we don't want them to appear in the repository...
*.stackdump
*.core
# misc
*.rej
*.patch
*.diff
*.orig
*.out
*.ll
*.gcda
*.gcno
*.gcov
libtomcrypt.pc
# output from doc generation
doxygen/
*.dvi
*.log
*.aux
*.toc
*.idx
*.ilg
*.ind
*.out
*.lof
*.bak
coverage*/
coverage*.info
# coverity intermediate directory etc.
cov-int/
.coverity_*
libtomcrypt.lzma
# cmake build directories
build*/

441
CMakeLists.txt Normal file
View file

@ -0,0 +1,441 @@
# SPDX-License-Identifier: Unlicense
#
# LibTomCrypt, modular cryptographic library -- Tom St Denis
#
cmake_minimum_required(VERSION 3.22)
project(
libtomcrypt
VERSION 1.18.2
DESCRIPTION "A modular cryptographic library."
HOMEPAGE_URL "https://www.libtom.net/LibTomCrypt"
LANGUAGES C
)
# package release version
#
# * bump if re-releasing the same VERSION + patches
# * set to 1 if releasing a new VERSION
set(PACKAGE_RELEASE_VERSION 1)
# -----------------------------------------------------------------------------
# Include CMake modules
# -----------------------------------------------------------------------------
include(GNUInstallDirs)
include(CheckIPOSupported)
include(CMakePackageConfigHelpers)
# for potential builds against gnump
include(FindPkgConfig)
# for potential builds with MSVC
include(CMakePushCheckState)
include(CheckSymbolExists)
# default is "No tests"
option(BUILD_TESTING "" OFF)
include(CTest)
include(sources.cmake)
# -----------------------------------------------------------------------------
# Options
# -----------------------------------------------------------------------------
option(WITH_LTM "Build with support for libtommath" TRUE)
option(WITH_TFM "Build with support for tomsfastmath" FALSE)
option(WITH_GMP "Build with support for GNU Multi Precision Arithmetic Library" FALSE)
set(MPI_PROVIDER
"LTM"
CACHE STRING "Build tests and demos against 'LTM', 'TFM' or 'GMP', default is LTM"
)
option(BUILD_SHARED_LIBS
"Build shared library and only the shared library if \"ON\", default is static" OFF
)
option(WITH_PTHREAD "Build with pthread support" FALSE)
# -----------------------------------------------------------------------------
# Compose CFLAGS
# -----------------------------------------------------------------------------
set(LTC_CFLAGS "" CACHE STRING "Optional user-specific CFLAGS")
set(LTC_LDFLAGS "" CACHE STRING "Optional user-specific LDFLAGS")
# Some information ported from makefile_include.mk
if(NOT CMAKE_BUILD_TYPE AND NOT CMAKE_CONFIGURATION_TYPES)
message(STATUS "Setting build type to 'Release' as none was specified.")
set(CMAKE_BUILD_TYPE "Release")
endif()
# We differentiate between MSVC, WATCOM and GCC-compatible compilers
if(MSVC)
set(LTC_C_FLAGS -W3)
elseif(WATCOM)
set(LTC_C_FLAGS -fo=.obj -oaxt -3r -w3)
else()
set(LTC_C_FLAGS
-Wall
-Wsign-compare
-Wextra
-Wshadow
-Wdeclaration-after-statement
-Wbad-function-cast
-Wcast-align
-Wstrict-prototypes
-Wpointer-arith
-Wsystem-headers
)
set(CMAKE_C_FLAGS_DEBUG "-g3")
if(LTC_CFLAGS MATCHES "-DARGTYPE")
set(ARGTYPE "")
else()
set(ARGTYPE "-DARGTYPE=4")
endif()
set(CMAKE_C_FLAGS_RELEASE "-O3 -funroll-loops -fomit-frame-pointer ${ARGTYPE}")
if(BUILD_SHARED_LIBS)
set(CMAKE_C_FLAGS_RELWITHDEBINFO "-g3 -O2 ${ARGTYPE}")
else()
set(CMAKE_C_FLAGS_RELWITHDEBINFO "-g3 -O2")
endif()
set(CMAKE_C_FLAGS_MINSIZEREL "-Os")
endif()
# What compiler do we have and what are their...uhm... peculiarities
if(CMAKE_C_COMPILER_ID MATCHES "(C|c?)lang")
list(APPEND LTC_C_FLAGS -Wno-typedef-redefinition -Wno-tautological-compare
-Wno-builtin-requires-header
)
# Clang requires at least '-O1' for dead code eliminiation
set(CMAKE_C_FLAGS_DEBUG "-O1 ${CMAKE_C_FLAGS_DEBUG}")
endif()
if(CMAKE_C_COMPILER MATCHES "mingw")
list(APPEND LTC_C_FLAGS -Wno-shadow -Wno-expansion-to-defined -Wno-declaration-after-statement
-Wno-bad-function-cast
)
endif()
if(CMAKE_SYSTEM_NAME MATCHES "Darwin")
list(APPEND LTC_C_FLAGS -Wno-nullability-completeness)
endif()
if(CMAKE_SYSTEM_NAME MATCHES "CYGWIN")
list(APPEND LTC_C_FLAGS -no-undefined)
endif()
# If the user set the environment variables at generate-time, append them in order to allow
# overriding our defaults.
# ~~~
# ${LTC_CFLAGS} means the user passed it via sth like:
# $ cmake -DLTC_CFLAGS="foo"
# ~~~
list(APPEND LTC_C_FLAGS ${LTC_CFLAGS})
list(APPEND LTC_LD_FLAGS ${LTC_LDFLAGS})
# -----------------------------------------------------------------------------
# Library targets
# -----------------------------------------------------------------------------
add_library(${PROJECT_NAME} ${SOURCES} ${PUBLIC_HEADERS} ${PRIVATE_HEADERS})
target_include_directories(
${PROJECT_NAME} PUBLIC $<BUILD_INTERFACE:${CMAKE_CURRENT_SOURCE_DIR}/src/headers>
$<INSTALL_INTERFACE:${CMAKE_INSTALL_INCLUDEDIR}/${PROJECT_NAME}>
)
target_compile_options(${PROJECT_NAME} BEFORE PRIVATE ${LTC_C_FLAGS})
target_link_options(${PROJECT_NAME} BEFORE PRIVATE ${LTC_LD_FLAGS})
set_target_properties(
${PROJECT_NAME}
PROPERTIES OUTPUT_NAME tomcrypt
VERSION ${PROJECT_VERSION}
SOVERSION ${PROJECT_VERSION_MAJOR}
PUBLIC_HEADER "${PUBLIC_HEADERS}"
)
if(MSVC)
cmake_push_check_state()
set(CMAKE_REQUIRED_LIBRARIES bcrypt)
check_symbol_exists(BCryptGenRandom "Windows.h;bcrypt.h" BCRYPT_AVAILABLE)
cmake_pop_check_state()
if(BCRYPT_AVAILABLE)
target_link_libraries(${PROJECT_NAME} PRIVATE Bcrypt)
list(APPEND LTC_C_FLAGS -DLTC_WIN32_BCRYPT)
endif()
endif()
option(COMPILE_LTO "Build with LTO enabled")
if(COMPILE_LTO)
check_ipo_supported(RESULT COMPILER_SUPPORTS_LTO)
if(COMPILER_SUPPORTS_LTO)
set_property(TARGET ${PROJECT_NAME} PROPERTY INTERPROCEDURAL_OPTIMIZATION TRUE)
else()
message(
SEND_ERROR
"This compiler does not support LTO. Reconfigure ${PROJECT_NAME} with -DCOMPILE_LTO=OFF."
)
endif()
endif()
# -----------------------------------------------------------------------------
# MPI provider
# -----------------------------------------------------------------------------
# libtommath
if(WITH_LTM)
find_package(libtommath 1.2.0 REQUIRED)
target_compile_definitions(${PROJECT_NAME} PUBLIC LTM_DESC)
if(MPI_PROVIDER MATCHES "LTM")
target_compile_definitions(${PROJECT_NAME} PUBLIC USE_LTM)
endif()
target_link_libraries(${PROJECT_NAME} PUBLIC libtommath)
list(APPEND LTC_PKG_CONFIG_CFLAGS -DLTM_DESC)
list(APPEND LTC_PKG_CONFIG_LIBS -ltommath)
list(APPEND LTC_DEBIAN_MPI_PROVIDER_DEPENDS libtommath-dev)
endif()
# tomsfastmath
if(WITH_TFM)
find_package(tomsfastmath 0.13.1 REQUIRED)
target_compile_definitions(${PROJECT_NAME} PUBLIC TFM_DESC)
if(MPI_PROVIDER MATCHES "TFM")
target_compile_definitions(${PROJECT_NAME} PUBLIC USE_TFM)
endif()
target_link_libraries(${PROJECT_NAME} PUBLIC tomsfastmath)
list(APPEND LTC_PKG_CONFIG_CFLAGS -DTFM_DESC)
list(APPEND LTC_PKG_CONFIG_LIBS -ltfm)
list(APPEND LTC_DEBIAN_MPI_PROVIDER_DEPENDS libtfm-dev)
endif()
# GNU MP
if(WITH_GMP)
pkg_check_modules(GMP REQUIRED gmp>=6.1.2)
target_compile_definitions(${PROJECT_NAME} PUBLIC GMP_DESC)
if(MPI_PROVIDER MATCHES "GMP")
target_compile_definitions(${PROJECT_NAME} PUBLIC USE_GMP)
endif()
target_link_libraries(${PROJECT_NAME} PUBLIC ${GMP_LIBRARIES})
list(APPEND LTC_PKG_CONFIG_CFLAGS -DGMP_DESC)
list(APPEND LTC_PKG_CONFIG_LIBS -lgmp)
list(APPEND LTC_DEBIAN_MPI_PROVIDER_DEPENDS libgmp-dev)
endif()
# -----------------------------------------------------------------------------
# other options
# -----------------------------------------------------------------------------
if(WITH_PTHREAD)
set(THREADS_PREFER_PTHREAD_FLAG ON)
find_package(Threads REQUIRED)
if(CMAKE_USE_PTHREADS_INIT)
target_compile_definitions(${PROJECT_NAME} PUBLIC LTC_PTHREAD)
target_link_libraries(${PROJECT_NAME} PRIVATE Threads::Threads)
list(APPEND LTC_PKG_CONFIG_CFLAGS -DLTC_PTHREAD)
else()
message(
SEND_ERROR
"pthreads not supported. Reconfigure ${PROJECT_NAME} with -DWITH_PTHREAD=OFF."
)
endif()
endif()
list(JOIN LTC_PKG_CONFIG_CFLAGS " " PKG_CONFIG_CFLAGS)
list(JOIN LTC_PKG_CONFIG_LIBS " " PKG_CONFIG_LIBS)
list(JOIN LTC_DEBIAN_MPI_PROVIDER_DEPENDS " " DEBIAN_MPI_PROVIDER_DEPENDS)
# -----------------------------------------------------------------------------
# demos&test targets
# -----------------------------------------------------------------------------
add_subdirectory(demos)
if(BUILD_TESTING)
enable_testing()
add_subdirectory(tests)
endif()
# ---------------------------------------------------------------------------------------
# Install/export targets and files
# ---------------------------------------------------------------------------------------
set(CONFIG_INSTALL_DIR "${CMAKE_INSTALL_LIBDIR}/cmake/${PROJECT_NAME}")
set(PROJECT_VERSION_FILE "${CMAKE_CURRENT_BINARY_DIR}/${PROJECT_NAME}-config-version.cmake")
set(PROJECT_CONFIG_FILE "${PROJECT_NAME}-config.cmake")
set(TARGETS_EXPORT_NAME "${PROJECT_NAME}Targets")
# install targets
install(
TARGETS ${PROJECT_NAME}
EXPORT ${TARGETS_EXPORT_NAME}
LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR}
ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} COMPONENT Libraries
RUNTIME DESTINATION ${CMAKE_INSTALL_LIBDIR}
PUBLIC_HEADER DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/${PROJECT_NAME}
)
# Install libtomcrypt.pc for pkg-config if we build a shared library
if(BUILD_SHARED_LIBS)
# Let the user override the default directory of the pkg-config file (usually this shouldn't be
# required to be changed)
set(CMAKE_INSTALL_PKGCONFIGDIR
"${CMAKE_INSTALL_LIBDIR}/pkgconfig"
CACHE PATH "Folder where to install .pc files"
)
configure_file(
${CMAKE_CURRENT_SOURCE_DIR}/${PROJECT_NAME}.pc.in
${CMAKE_CURRENT_BINARY_DIR}/${PROJECT_NAME}.pc @ONLY
)
install(FILES ${CMAKE_CURRENT_BINARY_DIR}/${PROJECT_NAME}.pc
DESTINATION ${CMAKE_INSTALL_PKGCONFIGDIR}
)
endif()
# generate package version file
write_basic_package_version_file(
${PROJECT_VERSION_FILE}
VERSION ${PROJECT_VERSION}
COMPATIBILITY SameMajorVersion
)
# install version file
install(FILES ${PROJECT_VERSION_FILE} DESTINATION ${CONFIG_INSTALL_DIR})
# build directory package config
export(EXPORT ${TARGETS_EXPORT_NAME} FILE ${PROJECT_CONFIG_FILE})
# installed package config
install(
EXPORT ${TARGETS_EXPORT_NAME}
DESTINATION ${CONFIG_INSTALL_DIR}
FILE ${PROJECT_CONFIG_FILE}
)
# add to CMake registry
export(PACKAGE ${PROJECT_NAME})
# ---------------------------------------------------------------------------------------
# Create release packages
# ---------------------------------------------------------------------------------------
# determine distribution and architecture
find_program(LSB_RELEASE lsb_release)
find_program(SYSCTL sysctl)
find_program(UNAME uname)
if(UNAME)
execute_process(
COMMAND uname -m
OUTPUT_VARIABLE MACHINE_ARCH
OUTPUT_STRIP_TRAILING_WHITESPACE
)
elseif(SYSCTL)
execute_process(
COMMAND sysctl -b hw.machine_arch
OUTPUT_VARIABLE MACHINE_ARCH
OUTPUT_STRIP_TRAILING_WHITESPACE
)
else()
string(TOLOWER ${CMAKE_SYSTEM_NAME} MACHINE_ARCH)
endif()
if(LSB_RELEASE)
execute_process(
COMMAND lsb_release -si
OUTPUT_VARIABLE LINUX_DISTRO
OUTPUT_STRIP_TRAILING_WHITESPACE
)
execute_process(
COMMAND lsb_release -sc
OUTPUT_VARIABLE LINUX_DISTRO_CODENAME
OUTPUT_STRIP_TRAILING_WHITESPACE
)
execute_process(
COMMAND lsb_release -sr
OUTPUT_VARIABLE LINUX_DISTRO_VERSION
OUTPUT_STRIP_TRAILING_WHITESPACE
)
string(TOLOWER ${LINUX_DISTRO} LINUX_DISTRO)
if(LINUX_DISTRO_CODENAME STREQUAL "n/a")
set(DISTRO_PACK_PATH ${LINUX_DISTRO}/${LINUX_DISTRO_VERSION}/)
else()
set(DISTRO_PACK_PATH ${LINUX_DISTRO}/${LINUX_DISTRO_CODENAME}/)
endif()
else()
set(DISTRO_PACK_PATH ${CMAKE_SYSTEM_NAME}/)
endif()
# make sure untagged versions get a different package name
execute_process(
COMMAND git describe --exact-match --tags
ERROR_QUIET
RESULT_VARIABLE REPO_HAS_TAG
)
if(REPO_HAS_TAG EQUAL 0)
set(PACKAGE_NAME_SUFFIX "")
else()
set(PACKAGE_NAME_SUFFIX "-git")
message(STATUS "Use -git suffix")
endif()
# default CPack generators
set(CPACK_GENERATOR TGZ STGZ)
# extra CPack generators
if(LINUX_DISTRO STREQUAL "debian"
OR LINUX_DISTRO STREQUAL "ubuntu"
OR LINUX_DISTRO STREQUAL "linuxmint"
)
list(APPEND CPACK_GENERATOR DEB)
elseif(
LINUX_DISTRO STREQUAL "fedora"
OR LINUX_DISTRO STREQUAL "opensuse"
OR LINUX_DISTRO STREQUAL "centos"
)
list(APPEND CPACK_GENERATOR RPM)
elseif(CMAKE_SYSTEM_NAME STREQUAL "FreeBSD")
list(APPEND CPACK_GENERATOR FREEBSD)
endif()
set(LTC_DEBIAN_SHARED_PACKAGE_NAME "${PROJECT_NAME}${PACKAGE_NAME_SUFFIX}${PROJECT_VERSION_MAJOR}")
# general CPack config
set(CPACK_PACKAGE_DIRECTORY ${CMAKE_BINARY_DIR}/packages/${DISTRO_PACK_PATH})
message(STATUS "CPack: packages will be generated under ${CPACK_PACKAGE_DIRECTORY}")
if(BUILD_SHARED_LIBS)
set(CPACK_PACKAGE_NAME "${PROJECT_NAME}${PROJECT_VERSION_MAJOR}")
set(CPACK_DEBIAN_PACKAGE_NAME "${LTC_DEBIAN_SHARED_PACKAGE_NAME}")
else()
set(CPACK_PACKAGE_NAME "${PROJECT_NAME}-devel")
set(CPACK_DEBIAN_LIBRARIES_PACKAGE_NAME "${PROJECT_NAME}${PACKAGE_NAME_SUFFIX}-dev")
endif()
set(CPACK_PACKAGE_VERSION ${PROJECT_VERSION})
set(CPACK_PACKAGE_DESCRIPTION_SUMMARY "LibTomCrypt")
set(CPACK_PACKAGE_VENDOR "libtom projects")
set(CPACK_PACKAGE_CONTACT "libtom@googlegroups.com")
set(CPACK_RESOURCE_FILE_LICENSE "${PROJECT_SOURCE_DIR}/LICENSE")
set(PACKAGE_NAME_TRAILER ${CPACK_PACKAGE_VERSION}-${PACKAGE_RELEASE_VERSION}_${MACHINE_ARCH})
set(CPACK_PACKAGE_FILE_NAME ${CPACK_PACKAGE_NAME}-${PACKAGE_NAME_TRAILER})
set(CPACK_STRIP_FILES ON)
# deb specific CPack config
set(CPACK_DEBIAN_FILE_NAME DEB-DEFAULT)
set(CPACK_DEBIAN_DEBUGINFO_PACKAGE ON)
set(CPACK_DEBIAN_PACKAGE_RELEASE ${PACKAGE_RELEASE_VERSION})
set(CPACK_DEBIAN_PACKAGE_SHLIBDEPS ON)
if(BUILD_SHARED_LIBS)
set(CPACK_DEBIAN_PACKAGE_SECTION "libs")
set(CPACK_DEBIAN_PACKAGE_DEPENDS ${DEBIAN_MPI_PROVIDER_DEPENDS})
else()
set(CPACK_DEBIAN_PACKAGE_SECTION "libdevel")
set(CPACK_DEBIAN_PACKAGE_DEPENDS ${LTC_DEBIAN_SHARED_PACKAGE_NAME})
set(CPACK_DEB_COMPONENT_INSTALL ON)
set(CPACK_ARCHIVE_COMPONENT_INSTALL ON)
set(CPACK_COMPONENTS_ALL Libraries)
endif()
# rpm specific CPack config
set(CPACK_RPM_PACKAGE_RELEASE ${PACKAGE_RELEASE_VERSION})
set(CPACK_RPM_PACKAGE_ARCHITECTURE ${MACHINE_ARCH})
set(CPACK_RPM_PACKAGE_NAME "${CPACK_PACKAGE_NAME}-${PROJECT_VERSION}")
set(CPACK_RPM_PACKAGE_LICENSE "The Unlicense")
# FreeBSD specific CPack config
set(CPACK_FREEBSD_PACKAGE_MAINTAINER "gahr@FreeBSD.org")
set(CPACK_FREEBSD_PACKAGE_ORIGIN "security/libtomcrypt")
set(CPACK_FREEBSD_PACKAGE_CATEGORIES "security")
include(CPack)

27
LICENSE
View file

@ -1,9 +1,26 @@
LibTomCrypt is public domain. As should all quality software be.
The LibTom license
All of the software was either written by or donated to Tom St Denis for the purposes
of this project. The only exception is the SAFER.C source which has no known
license status (assumed copyrighted) which is why SAFER,C is shipped as disabled.
This is free and unencumbered software released into the public domain.
Tom St Denis
Anyone is free to copy, modify, publish, use, compile, sell, or
distribute this software, either in source code form or as a compiled
binary, for any purpose, commercial or non-commercial, and by any
means.
In jurisdictions that recognize copyright laws, the author or authors
of this software dedicate any and all copyright interest in the
software to the public domain. We make this dedication for the benefit
of the public at large and to the detriment of our heirs and
successors. We intend this dedication to be an overt act of
relinquishment in perpetuity of all present and future rights to this
software under copyright law.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY CLAIM, DAMAGES OR
OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR
OTHER DEALINGS IN THE SOFTWARE.
For more information, please refer to <http://unlicense.org/>

204
README.md Normal file
View file

@ -0,0 +1,204 @@
# libtomcrypt
Previously the git repository contained `doc/crypt.pdf` for detailed documentation.
This was changed and the file is now only available from the tarball of the appropriate version
or from the page https://github.com/libtom/libtomcrypt/releases .
## Project Status
### Travis CI
master: [![Build Status](https://github.com/libtom/libtomcrypt/actions/workflows/main.yml/badge.svg?branch=master)](https://github.com/libtom/libtomcrypt/actions/workflows/main.yml?query=branch%3Amaster+++) [![Coverage Status](https://coveralls.io/repos/libtom/libtomcrypt/badge.png?branch=master)](https://coveralls.io/r/libtom/libtomcrypt)
develop: [![Build Status](https://github.com/libtom/libtomcrypt/actions/workflows/main.yml/badge.svg?branch=develop)](https://github.com/libtom/libtomcrypt/actions/workflows/main.yml?query=branch%3Adevelop+++) [![Coverage Status](https://coveralls.io/repos/libtom/libtomcrypt/badge.png?branch=develop)](https://coveralls.io/r/libtom/libtomcrypt)
### AppVeyor
master: [![Build status](https://ci.appveyor.com/api/projects/status/xyl2nbdsyp1tj9ye/branch/master?svg=true)](https://ci.appveyor.com/project/libtom/libtomcrypt/branch/master)
develop: [![Build status](https://ci.appveyor.com/api/projects/status/xyl2nbdsyp1tj9ye/branch/develop?svg=true)](https://ci.appveyor.com/project/libtom/libtomcrypt/branch/develop)
### Coverity
[![Coverity Scan Build Status](https://scan.coverity.com/projects/487/badge.svg)](https://scan.coverity.com/projects/487)
### ABI Laboratory
API/ABI changes: [check here](https://abi-laboratory.pro/tracker/timeline/libtomcrypt/)
## Submitting patches
Please branch off from develop if you want to submit a patch.
Patch integration will be faster if tests and documentation are included.
Please update the makefiles in a separate commit. To update them simply run the `updatemakes.sh` script.
If you have something bigger to submit, feel free to contact us beforehand.
Then we can give you write access to this repo, so you can open your PR based on this repo
and we can easier follow the rebase-before-merge approach we're using (or even do the rebase ourself).
### Reviews
We're using Pull Request reviews to make sure that the code is in line with the existing code base.
Please have a look [here](https://help.github.com/articles/approving-a-pull-request-with-required-reviews/) to get an idea of the approach.
## Branches
Please be aware, that all branches besides _master_ and _develop_ __can__ and __will be__ force-pushed, rebased and/or removed!
If you want to rely on such an _unstable_ branch, create your own fork of this repository to make sure nothing breaks for you.
## Configuration options
By default the library builds its entire feature set (besides `katja`) in a (depending on your needs more or less) optimal way.
There are numerous configuration options available if you want to trim down the functionality of the library.
Please have a look at `src/headers/tomcrypt_custom.h` for all available configuration options.
The following list is a small part of the available, but the most often required, configuration switches.
| Flag | Behavior |
| ---- | -------- |
| `LTC_NO_TEST` | Remove all algorithm self-tests from the library |
| `LTC_NO_FILE` | Remove all API functions requiring a pre-defined `FILE` data-type (mostly useful for embedded targets) |
| `GMP_DESC` | enable [gmp](https://gmplib.org/) as MPI provider *\*1* |
| `LTM_DESC` | enable [libtommath](http://www.libtom.net/) as MPI provider *\*1* |
| `TFM_DESC` | enable [tomsfastmath](http://www.libtom.net/) as MPI provider *\*1* *\*2* |
| `USE_GMP` | use `gmp` as MPI provider when building the binaries *\*3* |
| `USE_LTM` | use `libtommath` as MPI provider when building the binaries *\*3* |
| `USE_TFM` | use `tomsfastmath` as MPI provider when building the binaries *\*3* |
*\*1* It is possible to build the library against all MPI providers in parallel and choose at startup-time which math library should be used.
*\*2* Please be aware that `tomsfastmath` has the limitation of a fixed max size of MPI's.
*\*3* Only one is supported at the time & this is only required when building the binaries, not when building the library itself.
## Building the library
There are several `makefile`s provided. Please choose the one that fits best for you.
| makefile | use-case |
| -------- | -------- |
| `makefile` | builds a static library (GNU Make required) |
| `makefile.shared` | builds a shared (and static) library (GNU Make required) |
| `makefile.unix` | for unusual UNIX platforms, or if you do not have GNU Make |
| `makefile.mingw` | for usage with the mingw compiler on MS Windows |
| `makefile.msvc` | for usage with the MSVC compiler on MS Windows |
| `libtomcrypt_VS2008.sln` | A VisualStudio 2008 project for MS Windows |
### Make targets
The `makefile`s provide several targets to build (VS project excluded).
The following list does not claim to be complete resp. to be available across all `makefile` variants.
| target | application |
| ------ | ----------- |
| *empty target*/none given | c.f. `library`
| `library` | builds only the library |
| `hashsum` | builds the `hashsum` binary, similar to [`shasum`](https://linux.die.net/man/1/shasum), but with support for all hash-algorithms included in the library *\*4* |
| `crypt` | builds the `crypt` binary, implementing something similar to [`crypt`](https://linux.die.net/man/3/crypt) *\*4* |
| `sizes` | builds the `sizes` binary, printing all internal data sizes on invocation *\*4* |
| `constants` | builds the `constants` binary, printing all internal constants on invocation *\*4* |
| `openssl-enc` | builds the `openssl-enc` binary, which is more or less compatible to [`openssl enc`](https://linux.die.net/man/1/enc) *\*4* *\*5* |
| `test` | builds the `test` binary, which runs all algorithm self-tests + some extended tests *\*4* |
| `timing` | builds the `timing` binary, which can be used to measure timings for algorithms and modes *\*4* |
| `bins` | builds `hashsum` *\*4* |
| `all_test` | builds `test`, `hashsum`, `crypt`, `small`, `tv_gen`, `sizes` & `constants` *\*4* |
| `docs` | builds the developer documentation `doc/crypt.pdf` |
| `install` | installs the `library` and header files *\*7* *\*8* |
| `install_bins` | installs the binaries created by the `bins` target *\*7* *\*8* |
| `install_docs` | installs the documentation created by the `docs` target *\*7* *\*8* |
| `install_test` | installs the test-app created by the `test` target *\*7* *\*8* |
| `install_all` | installs everything (i.e. `library`, `bins`, `docs` and `test`) *\*8* |
| `uninstall` | uninstalls the `library` and header files |
*\*4* also builds `library`
*\*5* broken build in some configurations, therefore not built by default
*\*7* also builds the necessary artifact(s) before installing it
*\*8* also have a look at the 'Installation' section of this file
### Examples
You want to build the library as static library
make
You want to build the library as shared library
make -f makefile.shared
You have `libtommath` installed on your system and want to build a static library and the `test` binary to run the self-tests.
make CFLAGS="-DUSE_LTM -DLTM_DESC" EXTRALIBS="-ltommath" test
You have `tomsfastmath` installed on your system and want to build a shared library and all binaries
make -f makefile.shared CFLAGS="-DUSE_TFM -DTFM_DESC" EXTRALIBS="-ltfm" all demos
You have `gmp`, `libtommath` and `tomsfastmath` installed on your system and want to build a static library and the `timing` binary to measure timings against `gmp`.
make CFLAGS="-DUSE_GMP -DGMP_DESC -DLTM_DESC -DTFM_DESC" EXTRALIBS="-lgmp" timing
If you have `libtommath` in a non-standard location:
make CFLAGS="-DUSE_LTM -DLTM_DESC -I/opt/devel/ltm" EXTRALIBS="/opt/devel/ltm/libtommath.a" all
You want to enable AES-NI support:
make CFLAGS=-DLTC_AES_NI
## Installation
There exist several _install_ make-targets which are described in the table above.
These targets support the standard ways (c.f. [[GNU]], [[FreeBSD]])
to modify the installation path via the following set of variables:
DESTDIR
PREFIX
LIBPATH
INCPATH
DATAPATH
BINPATH
The entire set of the variables is only supported in `makefile`, `makefile.shared` and `makefile.unix`.
In case you have to use one of the other makefiles, check in the file which variables are supported.
### Examples
You want to install the static library to the default paths
make install
You want to install the shared library to a special path and use it from this path
make -f makefile.shared PREFIX=/opt/special/path
Have a look at the developer documentation, [[GNU]] or [[FreeBSD]] to get a detailed explanation of all the variables.
## CMake support
The project provides support for the CMake build system.
```
git clone https://github.com/libtom/libtomcrypt.git
mkdir -p libtomcrypt/build
cd libtomcrypt/build
cmake ..
make -j$(nproc)
```
More details around building with CMake can be found in the developer documentation.
[GNU]: https://www.gnu.org/prep/standards/html_node/DESTDIR.html
[FreeBSD]: https://www.freebsd.org/doc/en/books/porters-handbook/porting-prefix.html

701
aes.c
View file

@ -1,701 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
/* AES implementation by Tom St Denis
*
* Derived from the Public Domain source code by
---
* rijndael-alg-fst.c
*
* @version 3.0 (December 2000)
*
* Optimised ANSI C code for the Rijndael cipher (now AES)
*
* @author Vincent Rijmen <vincent.rijmen@esat.kuleuven.ac.be>
* @author Antoon Bosselaers <antoon.bosselaers@esat.kuleuven.ac.be>
* @author Paulo Barreto <paulo.barreto@terra.com.br>
---
*/
#include "mycrypt.h"
#ifdef RIJNDAEL
#ifndef ENCRYPT_ONLY
#define SETUP rijndael_setup
#define ECB_ENC rijndael_ecb_encrypt
#define ECB_DEC rijndael_ecb_decrypt
#define ECB_TEST rijndael_test
#define ECB_KS rijndael_keysize
const struct _cipher_descriptor rijndael_desc =
{
"rijndael",
6,
16, 32, 16, 10,
SETUP, ECB_ENC, ECB_DEC, ECB_TEST, ECB_KS
};
const struct _cipher_descriptor aes_desc =
{
"aes",
6,
16, 32, 16, 10,
SETUP, ECB_ENC, ECB_DEC, ECB_TEST, ECB_KS
};
#else
#define SETUP rijndael_enc_setup
#define ECB_ENC rijndael_enc_ecb_encrypt
#define ECB_KS rijndael_enc_keysize
const struct _cipher_descriptor rijndael_enc_desc =
{
"rijndael",
6,
16, 32, 16, 10,
SETUP, ECB_ENC, NULL, NULL, ECB_KS
};
const struct _cipher_descriptor aes_enc_desc =
{
"aes",
6,
16, 32, 16, 10,
SETUP, ECB_ENC, NULL, NULL, ECB_KS
};
#endif
#include "aes_tab.c"
static ulong32 setup_mix(ulong32 temp)
{
return (Te4_3[byte(temp, 2)]) ^
(Te4_2[byte(temp, 1)]) ^
(Te4_1[byte(temp, 0)]) ^
(Te4_0[byte(temp, 3)]);
}
#ifndef ENCRYPT_ONLY
#ifdef SMALL_CODE
static ulong32 setup_mix2(ulong32 temp)
{
return Td0(255 & Te4[byte(temp, 3)]) ^
Td1(255 & Te4[byte(temp, 2)]) ^
Td2(255 & Te4[byte(temp, 1)]) ^
Td3(255 & Te4[byte(temp, 0)]);
}
#endif
#endif
int SETUP(const unsigned char *key, int keylen, int rounds, symmetric_key *skey)
{
int i, j;
ulong32 temp, *rk;
#ifndef ENCRYPT_ONLY
ulong32 *rrk;
#endif
_ARGCHK(key != NULL);
_ARGCHK(skey != NULL);
if (keylen != 16 && keylen != 24 && keylen != 32) {
return CRYPT_INVALID_KEYSIZE;
}
if (rounds != 0 && rounds != (10 + ((keylen/8)-2)*2)) {
return CRYPT_INVALID_ROUNDS;
}
skey->rijndael.Nr = 10 + ((keylen/8)-2)*2;
/* setup the forward key */
i = 0;
rk = skey->rijndael.eK;
LOAD32H(rk[0], key );
LOAD32H(rk[1], key + 4);
LOAD32H(rk[2], key + 8);
LOAD32H(rk[3], key + 12);
if (keylen == 16) {
j = 44;
for (;;) {
temp = rk[3];
rk[4] = rk[0] ^ setup_mix(temp) ^ rcon[i];
rk[5] = rk[1] ^ rk[4];
rk[6] = rk[2] ^ rk[5];
rk[7] = rk[3] ^ rk[6];
if (++i == 10) {
break;
}
rk += 4;
}
} else if (keylen == 24) {
j = 52;
LOAD32H(rk[4], key + 16);
LOAD32H(rk[5], key + 20);
for (;;) {
#ifdef _MSC_VER
temp = skey->rijndael.eK[rk - skey->rijndael.eK + 5];
#else
temp = rk[5];
#endif
rk[ 6] = rk[ 0] ^ setup_mix(temp) ^ rcon[i];
rk[ 7] = rk[ 1] ^ rk[ 6];
rk[ 8] = rk[ 2] ^ rk[ 7];
rk[ 9] = rk[ 3] ^ rk[ 8];
if (++i == 8) {
break;
}
rk[10] = rk[ 4] ^ rk[ 9];
rk[11] = rk[ 5] ^ rk[10];
rk += 6;
}
} else if (keylen == 32) {
j = 60;
LOAD32H(rk[4], key + 16);
LOAD32H(rk[5], key + 20);
LOAD32H(rk[6], key + 24);
LOAD32H(rk[7], key + 28);
for (;;) {
#ifdef _MSC_VER
temp = skey->rijndael.eK[rk - skey->rijndael.eK + 7];
#else
temp = rk[7];
#endif
rk[ 8] = rk[ 0] ^ setup_mix(temp) ^ rcon[i];
rk[ 9] = rk[ 1] ^ rk[ 8];
rk[10] = rk[ 2] ^ rk[ 9];
rk[11] = rk[ 3] ^ rk[10];
if (++i == 7) {
break;
}
temp = rk[11];
rk[12] = rk[ 4] ^ setup_mix(ROR(temp, 8));
rk[13] = rk[ 5] ^ rk[12];
rk[14] = rk[ 6] ^ rk[13];
rk[15] = rk[ 7] ^ rk[14];
rk += 8;
}
} else {
/* this can't happen */
j = 4;
}
#ifndef ENCRYPT_ONLY
/* setup the inverse key now */
rk = skey->rijndael.dK;
rrk = skey->rijndael.eK + j - 4;
/* apply the inverse MixColumn transform to all round keys but the first and the last: */
/* copy first */
*rk++ = *rrk++;
*rk++ = *rrk++;
*rk++ = *rrk++;
*rk = *rrk;
rk -= 3; rrk -= 3;
for (i = 1; i < skey->rijndael.Nr; i++) {
rrk -= 4;
rk += 4;
#ifdef SMALL_CODE
temp = rrk[0];
rk[0] = setup_mix2(temp);
temp = rrk[1];
rk[1] = setup_mix2(temp);
temp = rrk[2];
rk[2] = setup_mix2(temp);
temp = rrk[3];
rk[3] = setup_mix2(temp);
#else
temp = rrk[0];
rk[0] =
Tks0[byte(temp, 3)] ^
Tks1[byte(temp, 2)] ^
Tks2[byte(temp, 1)] ^
Tks3[byte(temp, 0)];
temp = rrk[1];
rk[1] =
Tks0[byte(temp, 3)] ^
Tks1[byte(temp, 2)] ^
Tks2[byte(temp, 1)] ^
Tks3[byte(temp, 0)];
temp = rrk[2];
rk[2] =
Tks0[byte(temp, 3)] ^
Tks1[byte(temp, 2)] ^
Tks2[byte(temp, 1)] ^
Tks3[byte(temp, 0)];
temp = rrk[3];
rk[3] =
Tks0[byte(temp, 3)] ^
Tks1[byte(temp, 2)] ^
Tks2[byte(temp, 1)] ^
Tks3[byte(temp, 0)];
#endif
}
/* copy last */
rrk -= 4;
rk += 4;
*rk++ = *rrk++;
*rk++ = *rrk++;
*rk++ = *rrk++;
*rk = *rrk;
#endif /* ENCRYPT_ONLY */
return CRYPT_OK;
}
#ifdef CLEAN_STACK
static void _rijndael_ecb_encrypt(const unsigned char *pt, unsigned char *ct, symmetric_key *skey)
#else
void ECB_ENC(const unsigned char *pt, unsigned char *ct, symmetric_key *skey)
#endif
{
ulong32 s0, s1, s2, s3, t0, t1, t2, t3, *rk;
int Nr, r;
_ARGCHK(pt != NULL);
_ARGCHK(ct != NULL);
_ARGCHK(skey != NULL);
Nr = skey->rijndael.Nr;
rk = skey->rijndael.eK;
/*
* map byte array block to cipher state
* and add initial round key:
*/
LOAD32H(s0, pt ); s0 ^= rk[0];
LOAD32H(s1, pt + 4); s1 ^= rk[1];
LOAD32H(s2, pt + 8); s2 ^= rk[2];
LOAD32H(s3, pt + 12); s3 ^= rk[3];
#ifdef SMALL_CODE
for (r = 0; ; r++) {
rk += 4;
t0 =
Te0(byte(s0, 3)) ^
Te1(byte(s1, 2)) ^
Te2(byte(s2, 1)) ^
Te3(byte(s3, 0)) ^
rk[0];
t1 =
Te0(byte(s1, 3)) ^
Te1(byte(s2, 2)) ^
Te2(byte(s3, 1)) ^
Te3(byte(s0, 0)) ^
rk[1];
t2 =
Te0(byte(s2, 3)) ^
Te1(byte(s3, 2)) ^
Te2(byte(s0, 1)) ^
Te3(byte(s1, 0)) ^
rk[2];
t3 =
Te0(byte(s3, 3)) ^
Te1(byte(s0, 2)) ^
Te2(byte(s1, 1)) ^
Te3(byte(s2, 0)) ^
rk[3];
if (r == Nr-2) {
break;
}
s0 = t0; s1 = t1; s2 = t2; s3 = t3;
}
rk += 4;
#else
/*
* Nr - 1 full rounds:
*/
r = Nr >> 1;
for (;;) {
t0 =
Te0(byte(s0, 3)) ^
Te1(byte(s1, 2)) ^
Te2(byte(s2, 1)) ^
Te3(byte(s3, 0)) ^
rk[4];
t1 =
Te0(byte(s1, 3)) ^
Te1(byte(s2, 2)) ^
Te2(byte(s3, 1)) ^
Te3(byte(s0, 0)) ^
rk[5];
t2 =
Te0(byte(s2, 3)) ^
Te1(byte(s3, 2)) ^
Te2(byte(s0, 1)) ^
Te3(byte(s1, 0)) ^
rk[6];
t3 =
Te0(byte(s3, 3)) ^
Te1(byte(s0, 2)) ^
Te2(byte(s1, 1)) ^
Te3(byte(s2, 0)) ^
rk[7];
rk += 8;
if (--r == 0) {
break;
}
s0 =
Te0(byte(t0, 3)) ^
Te1(byte(t1, 2)) ^
Te2(byte(t2, 1)) ^
Te3(byte(t3, 0)) ^
rk[0];
s1 =
Te0(byte(t1, 3)) ^
Te1(byte(t2, 2)) ^
Te2(byte(t3, 1)) ^
Te3(byte(t0, 0)) ^
rk[1];
s2 =
Te0(byte(t2, 3)) ^
Te1(byte(t3, 2)) ^
Te2(byte(t0, 1)) ^
Te3(byte(t1, 0)) ^
rk[2];
s3 =
Te0(byte(t3, 3)) ^
Te1(byte(t0, 2)) ^
Te2(byte(t1, 1)) ^
Te3(byte(t2, 0)) ^
rk[3];
}
#endif
/*
* apply last round and
* map cipher state to byte array block:
*/
s0 =
(Te4_3[byte(t0, 3)]) ^
(Te4_2[byte(t1, 2)]) ^
(Te4_1[byte(t2, 1)]) ^
(Te4_0[byte(t3, 0)]) ^
rk[0];
STORE32H(s0, ct);
s1 =
(Te4_3[byte(t1, 3)]) ^
(Te4_2[byte(t2, 2)]) ^
(Te4_1[byte(t3, 1)]) ^
(Te4_0[byte(t0, 0)]) ^
rk[1];
STORE32H(s1, ct+4);
s2 =
(Te4_3[byte(t2, 3)]) ^
(Te4_2[byte(t3, 2)]) ^
(Te4_1[byte(t0, 1)]) ^
(Te4_0[byte(t1, 0)]) ^
rk[2];
STORE32H(s2, ct+8);
s3 =
(Te4_3[byte(t3, 3)]) ^
(Te4_2[byte(t0, 2)]) ^
(Te4_1[byte(t1, 1)]) ^
(Te4_0[byte(t2, 0)]) ^
rk[3];
STORE32H(s3, ct+12);
}
#ifdef CLEAN_STACK
void ECB_ENC(const unsigned char *pt, unsigned char *ct, symmetric_key *skey)
{
_rijndael_ecb_encrypt(pt, ct, skey);
burn_stack(sizeof(unsigned long)*8 + sizeof(unsigned long*) + sizeof(int)*2);
}
#endif
#ifndef ENCRYPT_ONLY
#ifdef CLEAN_STACK
static void _rijndael_ecb_decrypt(const unsigned char *ct, unsigned char *pt, symmetric_key *skey)
#else
void ECB_DEC(const unsigned char *ct, unsigned char *pt, symmetric_key *skey)
#endif
{
ulong32 s0, s1, s2, s3, t0, t1, t2, t3, *rk;
int Nr, r;
_ARGCHK(pt != NULL);
_ARGCHK(ct != NULL);
_ARGCHK(skey != NULL);
Nr = skey->rijndael.Nr;
rk = skey->rijndael.dK;
/*
* map byte array block to cipher state
* and add initial round key:
*/
LOAD32H(s0, ct ); s0 ^= rk[0];
LOAD32H(s1, ct + 4); s1 ^= rk[1];
LOAD32H(s2, ct + 8); s2 ^= rk[2];
LOAD32H(s3, ct + 12); s3 ^= rk[3];
#ifdef SMALL_CODE
for (r = 0; ; r++) {
rk += 4;
t0 =
Td0(byte(s0, 3)) ^
Td1(byte(s3, 2)) ^
Td2(byte(s2, 1)) ^
Td3(byte(s1, 0)) ^
rk[0];
t1 =
Td0(byte(s1, 3)) ^
Td1(byte(s0, 2)) ^
Td2(byte(s3, 1)) ^
Td3(byte(s2, 0)) ^
rk[1];
t2 =
Td0(byte(s2, 3)) ^
Td1(byte(s1, 2)) ^
Td2(byte(s0, 1)) ^
Td3(byte(s3, 0)) ^
rk[2];
t3 =
Td0(byte(s3, 3)) ^
Td1(byte(s2, 2)) ^
Td2(byte(s1, 1)) ^
Td3(byte(s0, 0)) ^
rk[3];
if (r == Nr-2) {
break;
}
s0 = t0; s1 = t1; s2 = t2; s3 = t3;
}
rk += 4;
#else
/*
* Nr - 1 full rounds:
*/
r = Nr >> 1;
for (;;) {
t0 =
Td0(byte(s0, 3)) ^
Td1(byte(s3, 2)) ^
Td2(byte(s2, 1)) ^
Td3(byte(s1, 0)) ^
rk[4];
t1 =
Td0(byte(s1, 3)) ^
Td1(byte(s0, 2)) ^
Td2(byte(s3, 1)) ^
Td3(byte(s2, 0)) ^
rk[5];
t2 =
Td0(byte(s2, 3)) ^
Td1(byte(s1, 2)) ^
Td2(byte(s0, 1)) ^
Td3(byte(s3, 0)) ^
rk[6];
t3 =
Td0(byte(s3, 3)) ^
Td1(byte(s2, 2)) ^
Td2(byte(s1, 1)) ^
Td3(byte(s0, 0)) ^
rk[7];
rk += 8;
if (--r == 0) {
break;
}
s0 =
Td0(byte(t0, 3)) ^
Td1(byte(t3, 2)) ^
Td2(byte(t2, 1)) ^
Td3(byte(t1, 0)) ^
rk[0];
s1 =
Td0(byte(t1, 3)) ^
Td1(byte(t0, 2)) ^
Td2(byte(t3, 1)) ^
Td3(byte(t2, 0)) ^
rk[1];
s2 =
Td0(byte(t2, 3)) ^
Td1(byte(t1, 2)) ^
Td2(byte(t0, 1)) ^
Td3(byte(t3, 0)) ^
rk[2];
s3 =
Td0(byte(t3, 3)) ^
Td1(byte(t2, 2)) ^
Td2(byte(t1, 1)) ^
Td3(byte(t0, 0)) ^
rk[3];
}
#endif
/*
* apply last round and
* map cipher state to byte array block:
*/
s0 =
(Td4[byte(t0, 3)] & 0xff000000) ^
(Td4[byte(t3, 2)] & 0x00ff0000) ^
(Td4[byte(t2, 1)] & 0x0000ff00) ^
(Td4[byte(t1, 0)] & 0x000000ff) ^
rk[0];
STORE32H(s0, pt);
s1 =
(Td4[byte(t1, 3)] & 0xff000000) ^
(Td4[byte(t0, 2)] & 0x00ff0000) ^
(Td4[byte(t3, 1)] & 0x0000ff00) ^
(Td4[byte(t2, 0)] & 0x000000ff) ^
rk[1];
STORE32H(s1, pt+4);
s2 =
(Td4[byte(t2, 3)] & 0xff000000) ^
(Td4[byte(t1, 2)] & 0x00ff0000) ^
(Td4[byte(t0, 1)] & 0x0000ff00) ^
(Td4[byte(t3, 0)] & 0x000000ff) ^
rk[2];
STORE32H(s2, pt+8);
s3 =
(Td4[byte(t3, 3)] & 0xff000000) ^
(Td4[byte(t2, 2)] & 0x00ff0000) ^
(Td4[byte(t1, 1)] & 0x0000ff00) ^
(Td4[byte(t0, 0)] & 0x000000ff) ^
rk[3];
STORE32H(s3, pt+12);
}
#ifdef CLEAN_STACK
void ECB_DEC(const unsigned char *ct, unsigned char *pt, symmetric_key *skey)
{
_rijndael_ecb_decrypt(ct, pt, skey);
burn_stack(sizeof(unsigned long)*8 + sizeof(unsigned long*) + sizeof(int)*2);
}
#endif
int ECB_TEST(void)
{
#ifndef LTC_TEST
return CRYPT_NOP;
#else
int err;
static const struct {
int keylen;
unsigned char key[32], pt[16], ct[16];
} tests[] = {
{ 16,
{ 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f },
{ 0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77,
0x88, 0x99, 0xaa, 0xbb, 0xcc, 0xdd, 0xee, 0xff },
{ 0x69, 0xc4, 0xe0, 0xd8, 0x6a, 0x7b, 0x04, 0x30,
0xd8, 0xcd, 0xb7, 0x80, 0x70, 0xb4, 0xc5, 0x5a }
}, {
24,
{ 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17 },
{ 0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77,
0x88, 0x99, 0xaa, 0xbb, 0xcc, 0xdd, 0xee, 0xff },
{ 0xdd, 0xa9, 0x7c, 0xa4, 0x86, 0x4c, 0xdf, 0xe0,
0x6e, 0xaf, 0x70, 0xa0, 0xec, 0x0d, 0x71, 0x91 }
}, {
32,
{ 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,
0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f },
{ 0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77,
0x88, 0x99, 0xaa, 0xbb, 0xcc, 0xdd, 0xee, 0xff },
{ 0x8e, 0xa2, 0xb7, 0xca, 0x51, 0x67, 0x45, 0xbf,
0xea, 0xfc, 0x49, 0x90, 0x4b, 0x49, 0x60, 0x89 }
}
};
symmetric_key key;
unsigned char tmp[2][16];
int i, y;
for (i = 0; i < (int)(sizeof(tests)/sizeof(tests[0])); i++) {
zeromem(&key, sizeof(key));
if ((err = rijndael_setup(tests[i].key, tests[i].keylen, 0, &key)) != CRYPT_OK) {
return err;
}
rijndael_ecb_encrypt(tests[i].pt, tmp[0], &key);
rijndael_ecb_decrypt(tmp[0], tmp[1], &key);
if (memcmp(tmp[0], tests[i].ct, 16) || memcmp(tmp[1], tests[i].pt, 16)) {
#if 0
printf("\n\nTest %d failed\n", i);
if (memcmp(tmp[0], tests[i].ct, 16)) {
printf("CT: ");
for (i = 0; i < 16; i++) {
printf("%02x ", tmp[0][i]);
}
printf("\n");
} else {
printf("PT: ");
for (i = 0; i < 16; i++) {
printf("%02x ", tmp[1][i]);
}
printf("\n");
}
#endif
return CRYPT_FAIL_TESTVECTOR;
}
/* now see if we can encrypt all zero bytes 1000 times, decrypt and come back where we started */
for (y = 0; y < 16; y++) tmp[0][y] = 0;
for (y = 0; y < 1000; y++) rijndael_ecb_encrypt(tmp[0], tmp[0], &key);
for (y = 0; y < 1000; y++) rijndael_ecb_decrypt(tmp[0], tmp[0], &key);
for (y = 0; y < 16; y++) if (tmp[0][y] != 0) return CRYPT_FAIL_TESTVECTOR;
}
return CRYPT_OK;
#endif
}
#endif /* ENCRYPT_ONLY */
int ECB_KS(int *desired_keysize)
{
_ARGCHK(desired_keysize != NULL);
if (*desired_keysize < 16)
return CRYPT_INVALID_KEYSIZE;
if (*desired_keysize < 24) {
*desired_keysize = 16;
return CRYPT_OK;
} else if (*desired_keysize < 32) {
*desired_keysize = 24;
return CRYPT_OK;
} else {
*desired_keysize = 32;
return CRYPT_OK;
}
}
#endif

56
appveyor.yml Normal file
View file

@ -0,0 +1,56 @@
version: 1.18.2-develop+{build}
branches:
only:
- master
- develop
- /^release/
- /^appveyor/
- /^build-ci/
image:
- Visual Studio 2022
- Visual Studio 2019
- Visual Studio 2017
- Visual Studio 2015
environment:
matrix:
- LTC_CC: cl
- LTC_CC: clang-cl
matrix:
exclude:
- image: Visual Studio 2019
LTC_CC: clang-cl
- image: Visual Studio 2017
LTC_CC: clang-cl
- image: Visual Studio 2015
LTC_CC: clang-cl
build_script:
- cmd: >-
if "Visual Studio 2022"=="%APPVEYOR_BUILD_WORKER_IMAGE%" call "C:\Program Files\Microsoft Visual Studio\2022\Community\VC\Auxiliary\Build\vcvars64.bat"
if "Visual Studio 2019"=="%APPVEYOR_BUILD_WORKER_IMAGE%" call "C:\Program Files (x86)\Microsoft Visual Studio\2019\Community\VC\Auxiliary\Build\vcvars64.bat"
if "Visual Studio 2017"=="%APPVEYOR_BUILD_WORKER_IMAGE%" call "C:\Program Files (x86)\Microsoft Visual Studio\2017\Community\VC\Auxiliary\Build\vcvars64.bat"
if "Visual Studio 2015"=="%APPVEYOR_BUILD_WORKER_IMAGE%" call "C:\Program Files\Microsoft SDKs\Windows\v7.1\Bin\SetEnv.cmd" /x64
if "Visual Studio 2015"=="%APPVEYOR_BUILD_WORKER_IMAGE%" call "C:\Program Files (x86)\Microsoft Visual Studio 14.0\VC\vcvarsall.bat" x86_amd64
if "clang-cl"=="%LTC_CC%" set "PATH=C:\Program Files\LLVM\bin;C:\Program Files\Microsoft Visual Studio\2022\Community\VC\Tools\Llvm\x64\bin;%PATH%"
if "clang-cl"=="%LTC_CC%" clang-cl --version
cd..
git clone https://github.com/libtom/libtommath.git --branch=master
cp libtomcrypt\.ci\cmake.bat libtommath\cmake.bat
cd libtommath
cmake.bat
nmake -f makefile.msvc
cd..
cd libtomcrypt
.ci\cmake.bat
nmake -f makefile.msvc all CC=%LTC_CC%
cp test.exe test-stock.exe
cp timing.exe timing-stock.exe
nmake -f makefile.msvc clean
nmake -f makefile.msvc all CC=%LTC_CC% CFLAGS="/Ox /DUSE_LTM /DLTM_DESC /DLTC_NO_ACCEL /I../libtommath"
test_script:
- cmd: >-
test-stock.exe
test.exe
timing-stock.exe cipher_ecb aes
timing.exe cipher_ecb aes
timing-stock.exe hash sha
timing.exe hash sha

55
authors
View file

@ -1,55 +0,0 @@
This is a list of people who have contributed [directly or indirectly] to the project
[in no partcular order]. If you have helped and your name is not here email me at
tomstdenis@yahoo.com.
1) Richard.van.de.Laarschot@ict.nl
Gave help porting the lib to MSVC particularly pointed out various warnings and errors.
2) Richard Heathfield
Gave a lot of help concerning valid C portable code.
3) Ajay K. Agrawal
Helped port the library to MSVC and spotted a few bugs and errors.
4) Brian Gladman
Wrote the AES and Serpent code used. Found a bug in the hash code for certain types of inputs.
5) Svante Seleborg
Submitted the "ampi.c" code as well as many suggestions on improving the readability of the source code.
6) Clay Culver
Submitted a fix for "rsa.c" which cleaned up some code. Submited some other fixes too. :-)
Clay has helped find bugs in various pieces of code including the registry functions, base64 routines
and the make process. He is also now the primary author of the libtomcrypt reference manual and has plan
at making a HTML version.
7) Jason Klapste
Submitted fixes to the yarrow, hash, make process and test code as well as other subtle bug fixes. The
yarrow code can now default to any cipher/hash that is left after you remove them from a build.
8) Dobes Vandermeer <dobes@smartt.com>
Submitted HMAC code that worked flawlessly out of the box... good job! Also submitted a MD4 routine.
Submitted some modified DES code that was merged into the code base [using the libtomcrypt API]
9) Wayne Scott (wscott@bitmover.com)
Submitted base64 that complies with the RFC standards. Submitted some ideas to improve the RSA key generation
as well.
10) Sky Schulz (sky@ogn.com)
Has submitted a set of ideas to improve the library and make it more attractive for professional users.
11) Mike Frysinger
Together with Clay came up with a more "unix friendly" makefile. Mike Frysinger has been keeping copies of
the library for the Gentoo linux distribution.

View file

@ -1,76 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
/* compliant base64 code donated by Wayne Scott (wscott@bitmover.com) */
#include "mycrypt.h"
#ifdef BASE64
static const unsigned char map[256] = {
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 62, 255, 255, 255, 63,
52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 255, 255,
255, 254, 255, 255, 255, 0, 1, 2, 3, 4, 5, 6,
7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18,
19, 20, 21, 22, 23, 24, 25, 255, 255, 255, 255, 255,
255, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36,
37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48,
49, 50, 51, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255, 255,
255, 255, 255, 255 };
int base64_decode(const unsigned char *in, unsigned long len,
unsigned char *out, unsigned long *outlen)
{
unsigned long t, x, y, z;
unsigned char c;
int g;
_ARGCHK(in != NULL);
_ARGCHK(out != NULL);
_ARGCHK(outlen != NULL);
g = 3;
for (x = y = z = t = 0; x < len; x++) {
c = map[in[x]&0xFF];
if (c == 255) continue;
if (c == 254) { c = 0; g--; }
t = (t<<6)|c;
if (++y == 4) {
if (z + g > *outlen) {
return CRYPT_BUFFER_OVERFLOW;
}
out[z++] = (unsigned char)((t>>16)&255);
if (g > 1) out[z++] = (unsigned char)((t>>8)&255);
if (g > 2) out[z++] = (unsigned char)(t&255);
y = t = 0;
}
}
if (y != 0) {
return CRYPT_INVALID_PACKET;
}
*outlen = z;
return CRYPT_OK;
}
#endif

View file

@ -1,63 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
/* compliant base64 code donated by Wayne Scott (wscott@bitmover.com) */
#include "mycrypt.h"
#ifdef BASE64
static const char *codes =
"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
int base64_encode(const unsigned char *in, unsigned long len,
unsigned char *out, unsigned long *outlen)
{
unsigned long i, len2, leven;
unsigned char *p;
_ARGCHK(in != NULL);
_ARGCHK(out != NULL);
_ARGCHK(outlen != NULL);
/* valid output size ? */
len2 = 4 * ((len + 2) / 3);
if (*outlen < len2 + 1) {
return CRYPT_BUFFER_OVERFLOW;
}
p = out;
leven = 3*(len / 3);
for (i = 0; i < leven; i += 3) {
*p++ = codes[(in[0] >> 2) & 0x3F];
*p++ = codes[(((in[0] & 3) << 4) + (in[1] >> 4)) & 0x3F];
*p++ = codes[(((in[1] & 0xf) << 2) + (in[2] >> 6)) & 0x3F];
*p++ = codes[in[2] & 0x3F];
in += 3;
}
/* Pad it if necessary... */
if (i < len) {
unsigned a = in[0];
unsigned b = (i+1 < len) ? in[1] : 0;
*p++ = codes[(a >> 2) & 0x3F];
*p++ = codes[(((a & 3) << 4) + (b >> 4)) & 0x3F];
*p++ = (i+1 < len) ? codes[(((b & 0xf) << 2)) & 0x3F] : '=';
*p++ = '=';
}
/* append a NULL byte */
*p = '\0';
/* return ok */
*outlen = p - out;
return CRYPT_OK;
}
#endif

19
bin.in Normal file
View file

@ -0,0 +1,19 @@
#!/bin/sh
# Shell wrapper script for the executables when built with the shared
# libtomcrypt library.
set -euf
rootdir="$(cd -- "${0%/*}/" && pwd -P)"
binpath="$rootdir/.bin/${0##*/}"
[ -z "${LD_LIBRARY_PATH:=$rootdir}" ] ||
LD_LIBRARY_PATH="$rootdir:$LD_LIBRARY_PATH"
export LD_LIBRARY_PATH
if [ -n "${1+x}" ]; then
exec "$binpath" "${@:-}"
else
exec "$binpath"
fi

View file

@ -1,21 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
void burn_stack(unsigned long len)
{
unsigned char buf[32];
zeromem(buf, sizeof(buf));
if (len > (unsigned long)sizeof(buf))
burn_stack(len - sizeof(buf));
}

View file

@ -1,57 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CBC
int cbc_decrypt(const unsigned char *ct, unsigned char *pt, symmetric_CBC *cbc)
{
int x, err;
unsigned char tmp[MAXBLOCKSIZE], tmp2[MAXBLOCKSIZE];
_ARGCHK(pt != NULL);
_ARGCHK(ct != NULL);
_ARGCHK(cbc != NULL);
/* decrypt the block from ct into tmp */
if ((err = cipher_is_valid(cbc->cipher)) != CRYPT_OK) {
return err;
}
_ARGCHK(cipher_descriptor[cbc->cipher].ecb_decrypt != NULL);
/* is blocklen valid? */
if (cbc->blocklen < 0 || cbc->blocklen > (int)sizeof(cbc->IV)) {
return CRYPT_INVALID_ARG;
}
/* decrypt and xor IV against the plaintext of the previous step */
cipher_descriptor[cbc->cipher].ecb_decrypt(ct, tmp, &cbc->key);
for (x = 0; x < cbc->blocklen; x++) {
/* copy CT in case ct == pt */
tmp2[x] = ct[x];
/* actually decrypt the byte */
pt[x] = tmp[x] ^ cbc->IV[x];
}
/* replace IV with this current ciphertext */
for (x = 0; x < cbc->blocklen; x++) {
cbc->IV[x] = tmp2[x];
}
#ifdef CLEAN_STACK
zeromem(tmp, sizeof(tmp));
zeromem(tmp2, sizeof(tmp2));
#endif
return CRYPT_OK;
}
#endif

View file

@ -1,52 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CBC
int cbc_encrypt(const unsigned char *pt, unsigned char *ct, symmetric_CBC *cbc)
{
int x, err;
unsigned char tmp[MAXBLOCKSIZE];
_ARGCHK(pt != NULL);
_ARGCHK(ct != NULL);
_ARGCHK(cbc != NULL);
if ((err = cipher_is_valid(cbc->cipher)) != CRYPT_OK) {
return err;
}
/* is blocklen valid? */
if (cbc->blocklen < 0 || cbc->blocklen > (int)sizeof(cbc->IV)) {
return CRYPT_INVALID_ARG;
}
/* xor IV against plaintext */
for (x = 0; x < cbc->blocklen; x++) {
tmp[x] = pt[x] ^ cbc->IV[x];
}
/* encrypt */
cipher_descriptor[cbc->cipher].ecb_encrypt(tmp, ct, &cbc->key);
/* store IV [ciphertext] for a future block */
for (x = 0; x < cbc->blocklen; x++) {
cbc->IV[x] = ct[x];
}
#ifdef CLEAN_STACK
zeromem(tmp, sizeof(tmp));
#endif
return CRYPT_OK;
}
#endif

View file

@ -1,30 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CBC
int cbc_getiv(unsigned char *IV, unsigned long *len, symmetric_CBC *cbc)
{
_ARGCHK(IV != NULL);
_ARGCHK(len != NULL);
_ARGCHK(cbc != NULL);
if ((unsigned long)cbc->blocklen > *len) {
return CRYPT_BUFFER_OVERFLOW;
}
XMEMCPY(IV, cbc->IV, cbc->blocklen);
*len = cbc->blocklen;
return CRYPT_OK;
}
#endif

View file

@ -1,28 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CBC
int cbc_setiv(const unsigned char *IV, unsigned long len, symmetric_CBC *cbc)
{
_ARGCHK(IV != NULL);
_ARGCHK(cbc != NULL);
if (len != (unsigned long)cbc->blocklen) {
return CRYPT_INVALID_ARG;
}
XMEMCPY(cbc->IV, IV, len);
return CRYPT_OK;
}
#endif

View file

@ -1,43 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CBC
int cbc_start(int cipher, const unsigned char *IV, const unsigned char *key,
int keylen, int num_rounds, symmetric_CBC *cbc)
{
int x, err;
_ARGCHK(IV != NULL);
_ARGCHK(key != NULL);
_ARGCHK(cbc != NULL);
/* bad param? */
if ((err = cipher_is_valid(cipher)) != CRYPT_OK) {
return err;
}
/* setup cipher */
if ((err = cipher_descriptor[cipher].setup(key, keylen, num_rounds, &cbc->key)) != CRYPT_OK) {
return err;
}
/* copy IV */
cbc->blocklen = cipher_descriptor[cipher].block_length;
cbc->cipher = cipher;
for (x = 0; x < cbc->blocklen; x++) {
cbc->IV[x] = IV[x];
}
return CRYPT_OK;
}
#endif

View file

@ -1,48 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CFB
int cfb_decrypt(const unsigned char *ct, unsigned char *pt, unsigned long len, symmetric_CFB *cfb)
{
int err;
_ARGCHK(pt != NULL);
_ARGCHK(ct != NULL);
_ARGCHK(cfb != NULL);
if ((err = cipher_is_valid(cfb->cipher)) != CRYPT_OK) {
return err;
}
/* is blocklen/padlen valid? */
if (cfb->blocklen < 0 || cfb->blocklen > (int)sizeof(cfb->IV) ||
cfb->padlen < 0 || cfb->padlen > (int)sizeof(cfb->pad)) {
return CRYPT_INVALID_ARG;
}
while (len-- > 0) {
if (cfb->padlen == cfb->blocklen) {
cipher_descriptor[cfb->cipher].ecb_encrypt(cfb->pad, cfb->IV, &cfb->key);
cfb->padlen = 0;
}
cfb->pad[cfb->padlen] = *ct;
*pt = *ct ^ cfb->IV[cfb->padlen];
++pt;
++ct;
++cfb->padlen;
}
return CRYPT_OK;
}
#endif

View file

@ -1,46 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CFB
int cfb_encrypt(const unsigned char *pt, unsigned char *ct, unsigned long len, symmetric_CFB *cfb)
{
int err;
_ARGCHK(pt != NULL);
_ARGCHK(ct != NULL);
_ARGCHK(cfb != NULL);
if ((err = cipher_is_valid(cfb->cipher)) != CRYPT_OK) {
return err;
}
/* is blocklen/padlen valid? */
if (cfb->blocklen < 0 || cfb->blocklen > (int)sizeof(cfb->IV) ||
cfb->padlen < 0 || cfb->padlen > (int)sizeof(cfb->pad)) {
return CRYPT_INVALID_ARG;
}
while (len-- > 0) {
if (cfb->padlen == cfb->blocklen) {
cipher_descriptor[cfb->cipher].ecb_encrypt(cfb->pad, cfb->IV, &cfb->key);
cfb->padlen = 0;
}
cfb->pad[cfb->padlen] = (*ct = *pt ^ cfb->IV[cfb->padlen]);
++pt;
++ct;
++cfb->padlen;
}
return CRYPT_OK;
}
#endif

View file

@ -1,30 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CFB
int cfb_getiv(unsigned char *IV, unsigned long *len, symmetric_CFB *cfb)
{
_ARGCHK(IV != NULL);
_ARGCHK(len != NULL);
_ARGCHK(cfb != NULL);
if ((unsigned long)cfb->blocklen > *len) {
return CRYPT_BUFFER_OVERFLOW;
}
XMEMCPY(IV, cfb->IV, cfb->blocklen);
*len = cfb->blocklen;
return CRYPT_OK;
}
#endif

View file

@ -1,39 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CFB
int cfb_setiv(const unsigned char *IV, unsigned long len, symmetric_CFB *cfb)
{
int err;
_ARGCHK(IV != NULL);
_ARGCHK(cfb != NULL);
if ((err = cipher_is_valid(cfb->cipher)) != CRYPT_OK) {
return err;
}
if (len != (unsigned long)cfb->blocklen) {
return CRYPT_INVALID_ARG;
}
/* force next block */
cfb->padlen = 0;
cipher_descriptor[cfb->cipher].ecb_encrypt(IV, cfb->IV, &cfb->key);
return CRYPT_OK;
}
#endif

View file

@ -1,47 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CFB
int cfb_start(int cipher, const unsigned char *IV, const unsigned char *key,
int keylen, int num_rounds, symmetric_CFB *cfb)
{
int x, err;
_ARGCHK(IV != NULL);
_ARGCHK(key != NULL);
_ARGCHK(cfb != NULL);
if ((err = cipher_is_valid(cipher)) != CRYPT_OK) {
return err;
}
/* copy data */
cfb->cipher = cipher;
cfb->blocklen = cipher_descriptor[cipher].block_length;
for (x = 0; x < cfb->blocklen; x++)
cfb->IV[x] = IV[x];
/* init the cipher */
if ((err = cipher_descriptor[cipher].setup(key, keylen, num_rounds, &cfb->key)) != CRYPT_OK) {
return err;
}
/* encrypt the IV */
cipher_descriptor[cfb->cipher].ecb_encrypt(cfb->IV, cfb->IV, &cfb->key);
cfb->padlen = 0;
return CRYPT_OK;
}
#endif

612
changes
View file

@ -1,3 +1,606 @@
July 1st, 2018
v1.18.2
-- Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408)
-- Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373)
-- Fix two-key 3DES (PR #390)
-- Fix accelerated CTR mode (PR #359)
-- Fix Fortuna PRNG (PR #363)
-- Fix compilation on platforms where cc doesn't point to gcc (PR #382)
-- Fix using the wrong environment variable LT instead of LIBTOOL (PR #392)
-- Fix build on platforms where the compiler provides __WCHAR_MAX__ but wchar.h is not available (PR #390)
-- Fix & re-factor crypt_list_all_sizes() and crypt_list_all_constants() (PR #414)
-- Minor fixes (PR's #350 #351 #375 #377 #378 #379)
January 22nd, 2018
v1.18.1
-- Fix wrong SHA3 blocksizes, thanks to Claus Fischer for reporting this via Mail (PR #329)
-- Fix NULL-pointer dereference in `ccm_memory()` with LTC_CLEAN_STACK enabled (PR #327)
-- Fix `ccm_process()` being unable to process input buffers longer than 256 bytes (PR #326)
-- Fix the `register_all_{ciphers,hashes,prngs}()` return values (PR #316)
-- Fix some typos, warnings and duplicate prototypes in code & doc (PR's #310 #320 #321 #335)
-- Fix possible undefined behavior with LTC_PTHREAD (PR #337)
-- Fix some DER bugs (PR #339)
-- Fix CTR-mode when accelerator is used (OP-TEE/optee_os #2086)
-- Fix installation procedure (Issue #340)
October 10th, 2017
v1.18.0
-- Bugfix multi2
-- Bugfix Noekeon
-- Bugfix XTEA
-- Bugfix rng_get_bytes() on windows where we could read from c:\dev\random
-- Fixed the Bleichbacher Signature attack in PKCS#1 v1.5 EMSA, thanks to Alex Dent
-- Fixed a potential cache-based timing attack in CCM, thanks to Sebastian Verschoor
-- Fix GCM counter reuse and potential timing attacks in EAX, OCB and OCBv3,
thanks to Raphaël Jamet
-- Implement hardened RSA operations when CRT is used
-- Enabled timing resistant calculations of ECC and RSA operations per default
-- Applied some patches from the OLPC project regarding PKCS#1 and preventing
the hash algorithms from overflowing
-- Larry Bugbee contributed the necessary stuff to more easily call libtomcrypt
from a dynamic language like Python, as shown in his pyTomCrypt
-- Nikos Mavrogiannopoulos contributed RSA blinding and export of RSA and DSA keys
in OpenSSL/GnuTLS compatible format
-- Patrick Pelletier contributed a smart volley of patches
-- Christopher Brown contributed some patches and additions to ASN.1/DER
-- Pascal Brand of STMicroelectronics contributed patches regarding CCM, the
XTS mode and RSA private key operations with keys without CRT parameters
-- RC2 now also works with smaller key-sizes
-- Improved/extended several tests & demos
-- Hardened DSA and RSA by testing (through Karel's perl-CryptX)
against Google's "Wycheproof" and Kudelski Security's "CDF"
-- Fixed all compiler warnings
-- Fixed several build issues on FreeBSD, NetBSD, Linux x32 ABI, HP-UX/IA64,
Mac OS X, Windows (32&64bit, Cygwin, MingW & MSVC) ...
-- Re-worked all makefiles
-- Re-worked most PRNG's
-- The code is now verified by a linter, thanks to Francois Perrad
-- Documentation (crypt.pdf) is now built deterministically, thanks to Michael Stapelberg
-- Add Adler32 and CRC32 checksum algorithms
-- Add Base64-URL de-/encoding and some strict variants
-- Add Blake2b & Blake2s (hash & mac), thanks to Kelvin Sherlock
-- Add Camellia block cipher
-- Add ChaCha (stream cipher), Poly1305 (mac), ChaCha20Poly1305 (encauth)
-- Add constant-time mem-compare mem_neq()
-- Add DER GeneralizedTime de-/encoding
-- Add DSA and ECC key generation FIPS-186-4 compliance
-- Add HKDF, thanks to RyanC (especially for also providing documentation :-) )
-- Add OCBv3
-- Add PKCS#1 v1.5 mode of SSL3.0
-- Add PKCS#1 testvectors from RSA
-- Add PKCS#8 & X.509 import for RSA keys
-- Add stream cipher API
-- Add SHA3 & SHAKE
-- Add SHA512/256 and SHA512/224
-- Add Triple-DES 2-key mode, thanks to Paul Howarth
-- Brought back Diffie-Hellman
May 12th, 2007
v1.17 -- Cryptography Research Inc. contributed another small volley of patches, one to fix __WCHAR_DEFINED__ for BSD platforms,
another to silence MSVC warnings.
-- Added LTC_XCBC_PURE to XCBC mode which lets you use it in three-key mode.
-- [CRI] Added libtomcrypt.dsp for Visual C++ users.
-- [CRI] Added more functions for manipulating the ECC fixed point cache (including saving and loading)
-- [CRI] Modified ecc_make_key() to always produce keys smaller than base point order, for standards-compliance
-- Elliptic Semiconductor contributed XTS chaining mode to the cipher suite (subsequently optimized it)
-- Fixed xcbc_init() keylen when using single key mode.
-- Bruce Fortune pointed out a typo in the hmac_process() description in the manual. Fixed.
-- Added variable width counter support to CTR mode
-- Fixed CMAC (aka OMAC) when using 64-bit block ciphers and LTC_FAST ... my bad.
-- Fixed bug in ecc_is_valid() that would basically always return true
-- renamed a lot of macros to add the LTC_ prefix [e.g. RIJNDAEL => LTC_RIJNDAEL]
December 16th, 2006
v1.16 -- Brian Gladman pointed out that a recent change to GCM broke how the IV was handled. Currently the code complies against his test vectors
so the code should be considered frozen now.
-- Trevor from Cryptography Research Inc. submitted patches to convert the ECC code to be generic allowing curve parameters to be submitted
at runtime.
-- Fixed various doxygen comments
-- Added UTF8 support to the ASN1 code
-- Fixed STOREXXH macros for x86 platforms (Fix found at Elliptic Inc.)
-- Added makefile.unix which is BSD compatible, you have to manually tweak it since well I don't use it normally
-- removed a few lingering memcpy's
-- Fixed memory free errors in ecc_sign_hash() that can arise if the mp_init_multi() fails
-- Fixed incorrect return value in pkcs_1_pss_decode() which would correctly set res to 0 (indicating an incorrect signature) but
would return CRYPT_OK to the caller
-- ltc_ecc_mulmod() could leak memory if mp_init(&mu) failed, fixed. Would you believe that ltc_ecc_mulmod_timing() had the same
bug? Also fixed. :-)
-- Added Shamir's trick to the ECC side (defined as LTC_ECC_SHAMIR, enabled by default), gets ~1.34x to ~1.40x faster ECC verifications
-- Added Brian's vector #46 to the GCM code. It catches the ctr counter error from v1.15. Originally I was going to add all of his vectors,
but they're not as easy to parse and I got a lot of other things to do. Regression!
-- Various other small fixes to the ECC code to clean up error handling (I think most of that was from the move in 1.06 to the plugins)
All of the errors were in cleaning up from heap failures. So they were not likely to be triggered in normal usage
Made similar fixes to the RSA and DSA code (my bad)
-- Cryptography Research Inc. contributed a bunch of fixes to silence warnings (with MSVC) w.r.t. assigned data to unsigned char types.
-- Martin Marko suggested some fixes to make the RNG build with WinCE.
-- Updates to the manual for print (some fixes thanks to Martin Marko)
November 17th, 2006
v1.15 -- Andreas Lange found that if sha256_init DID fail in fortuna it wouldn't clean up the state correctly. Thanks.
Fortunately sha256_init cannot fail (as of v1.14) :-)
-- Andreas Lange contributed RMD-256 and RMD-320 code.
-- Removed mutex locks from fortuna_import as they create a deadlock and aren't required anyways [Avi Zelmanovich]
-- Added LTC_NO_PROTOTYPES to avoid prototyping functions like memset/memcpy. Required for fans of GCC 3.3.x
-- David Eder caught a off by one overrun bug in pmac_done() which can be exploited if your output tag buffer is
smaller than the block size of the cipher, e.g. if you have a 4-byte buffer and you tell pmac_done that you want
a 4-byte TAG it will store 4 bytes but return an outlen of 5.
-- Added signatures to the ECC and RSA benchmarks
-- Added LTC_PROFILE to run the PK tests only once in the timing demo (so you can capture events properly)
-- Andreas contributed PKCS #1 v1.5 code that merged cleanly with the existing PKCS code. w00t.
(update: I had to fix it to include the digestInfo and what not. Bad Andreas, bad! hehehe)
-- Fixed a signed variable error in gcm_process() (hard to trigger bug fortunately)
-- Removed all memcmp/memset/memcpy from the source (replaced with X macros)
-- Renamed macros HMAC/OMAC/PMAC to have a LTC_ prefix. If you pass these on the command line please update your makefiles
-- Added XCBC-MAC support [RFC 3566]
-- fixed LOAD32H and LOAD64H to stop putting out that darn warning :-)
-- Added the Korean SEED block cipher [RFC 4269]
-- Added LTC_VALGRIND define which makes SOBER-128 and RC4 a pure PRNG (and not a stream cipher). Useful if you use
Valgrind to debug your code (reported by Andreas Lange)
-- Made SOBER-128 more portable by removing the ASCII key in the test function (my bad, sorry).
-- Martin Mocko pointed out that if you have no PRNGs defined the lib won't build. Fixed, also fixed for if you have no
hashes defined.
-- Sped up F8 mode with LTC_FAST
-- Made CTR mode RFC 3686 compliant (increment counter first), to enable, OR the value LTC_CTR_RFC3686 to the "mode"
parameter you pass to ctr_start(), otherwise it will be LTC compliant (e.g. encrypt then increment)
-- Added ctr_test() to test CTR mode against RFC 3686
-- Added crypt_fsa() ... O_o
-- Fixed LTC_ECC_TIMING_RESISTANT so it once again builds properly (pt add/dbl are through the plugin now)
-- Added ANSI X9.63 (sec 4.3.6) import/export of public keys (cannot export to compressed formats but will import
hybrid compressed)
-- Added SECP curves for 112, 128, and 160 bits (only the 'r1' curves)
-- Added 3GPP-F9 MAC (thanks to Greg Rose for the test vectors)
-- Added the KASUMI block cipher
-- Added F9/XCBC/OMAC callbacks to the cipher plugin
-- Added RSA PKCS #1 v1.5 signature/encrypt tests to rsa_test.c
-- Fix to yarrow_test() to not call yarrow_done() which is invalid in that context (thanks Valgrind)
-- Christophe Devine pointed out that Anubis would fail on various 64-bit UNIX boxes when "x>>24" was used as an index, we needed
to mask it with 0xFF. Thanks. Fixed.
August 0x1E, 0x07D6
v1.14 -- Renamed the chaining mode macros from XXX to LTC_XXX_MODE. Should help avoid polluting the macro name space.
-- clean up of SHA-256
-- Chris Colman pointed out that der_decode_sequence_* allows LTC_ASN1_SETOF to accept SEQUENCEs and vice versa.
Decoder [non-flexi decoder that is] is more strict now and requires a match.
-- Steffen Jaeckel pointed out a typo in the user manual (re: rsa_exptmod). Fixed. This disproves the notion that
nobody reads it. :-)
-- Made GCM a bit more portable w.r.t. handling the CTR IV (e.g. & with 255)
-- Add LTC_VERBOSE if you really want to see what test is doing :-)
-- Added SSE2 support to GCM [use GCM_TABLES_SSE2 to enable], shaves 2 cycles per byte on Opteron processors
Shaved 4 cycles on a Prescott (Intel P4)
Requires you align your gcm_state on a 16 byte boundary, see gcm_memory() for more info
-- Added missing prototype for f8_test_mode()
-- two fixes to CCM for corner cases [L+noncelen > 15] and fixing the CTR pad to encrypt the CBC-MAC tag
-- Franz Glasner pointed out the ARGTYPE=4 is not actually valid. Fixed.
-- Fixed bug in f8_start() if your key < saltkey unspecified behaviour occurs. :-(
-- Documented F8 mode. Yeah, because you read the manual.
-- Minor updates to the technotes.
June 17th, 2006
v1.13 -- Fixed to fortuna_start() to clean up state if an error occurs. Not really useful at this stage (sha256 can't fail) but useful
if I ever make fortuna pluggable
-- Mike Marin submitted a whole bunch of patches for fixing up the libs on traditional UNIX platforms. Go AIX! Thanks!
-- One of bugs found in the multi demo highlights that at least with gcc you need to pass integers with a UL prefix to ensure
they're unsigned long
-- Updated the FP ECC code to use affine points. It's teh fast.
-- Made it so many functions which return CRYPT_BUFFER_OVERFLOW now also indicate the required buffer size, note that not all functions
do this (most do though).
-- Added F8 chaining mode. It's super neato.
May 29th, 2006
v1.12 -- Fixed OID encoder/decoder/length to properly handle the first two parts of an OID, matches 2002 X.690 now.
-- [Wesley Shields] Allows both GMP/LTM and TFM to be defined now.
-- [Wesley Shields] GMP pluggin is cleaner now and doesn't use deprecated symbols. Yipee
-- Added count_lsb_bits to get the number of leading LSB zero bits there are.
-- Fixed a bug in the INTEGER encoders for values of -(256**k)/2
-- Added BOOLEAN type to ASN.1 thingy-ma-do-hicky
-- Testprof doesn't strictly require GMP ... oops [Nils Durner]
-- Added LTC_CALL and LTC_EXPORT macros in tomcrypt_cfg.h to support various calling and linker conventions
(Thanks to John Kirk from Demonware)
-- In what has to be the best thing since sliced bread I bring you MECC_FP which is the fixed point
ECC point multiplier. It's fast, it's sexy and what's more it's hella fast [did I mention it's fast?]
You can tune it somewhat with FP_LUT (default to 8) for look-up width.
Read section 8.2 of the manual for more info.
It is disabled by default, you'll have to build LTC with it defined to get it.
-- Fixed bug in ecc_test.c (from testprof) to include the 521 [not 512] bit curve. :-)
April 4th, 2006
v1.11 -- Removed printf's from lrw_test ... whoops
-- lrw_process now checks the return of the cipher ecb encrypt/decrypt calls
-- lrw_start was not using num_rounds ...
-- Adam Miller reported a bug in the flexi decoder with elements past the end of a sequence. Fixed.
-- Bruce Guenter suggested I use --tag=CC for libtool builds where the compiler may think it's C++. (I applied this to LTM and TFM)
-- Optimized the ECC for TFM a bit by removing the useless "if" statements (most TFM functions don't return error codes)
Actually shaved a good chunk of time off and made the code smaller. By default with TFM the stock LTC point add/dbl functions
will be totally omitted (ECC-256 make key times on a Prescott for old vs. new are 11.03M vs. 9.59M cycles)
-- added missing CVS tags to ltc_ecc_mulmod.c
-- corrected typo in tomcrypt_cfg.h about what the file has been called
-- corrected my address in the user manual. A "bit" out of date.
-- added lrw_gen to tv_gen
-- added GMP plugin, only tested on a AMD64 and x86_32 Gentoo Linux box so be aware
-- made testme.sh runs diff case insensitivityly [whatever...] cuz GMP outputs lowercase satan text
-- added LDFLAGS to the makefile to allow cross porting linking options
-- added lrw_test() to the header file ... whoops
-- changed libtomcrypt.org to libtomcrypt.com .... mumble mumble
-- Updates to detect __STRICT_ANSI__ which is defined in --std=c99 modes (note -ansi is not supported as it lacks long long) so you can
build LTC out of the box with c99 (note: it'll be slower as there is no asm in this case)
-- Updated pelican.c and aes_tab.c to undef tables not-required. The tables are static so both AES and Pelican MAC would have copies. Save a few KB in the final binary.
-- Added LTC_NO_FAST to the makefile.icc to compensate for the fact ICC v9 can't handle it (Pelican MAC fails for instance)
February 11th, 2006
v1.10 -- Free ecb/cbc/ctr/lrw structures in timing code by calling the "done" function
-- fixed bug in lrw_process() which would always use the slow update ...
-- vastly sped up gcm_gf_mult() when LTC_FAST is defined. This speeds up LRW and GCM state creation, useful for servers with GCM
-- Removed NLS since there are some attacks against it.
-- fixed memory leak in rsa_import reported by John Kuhns
++ re-released as the rsa fix was incorrect (bad John bad ... hehehe) and I missed some NULLs in the static descriptor entry for ciphers
January 26th, 2006
v1.09 -- Added missing doxygen comments to some of the ASN.1 routines
-- Added "easy button" define LTC_EASY and LTC will build with a subset of all the algos. Reduces build times for typical
configurations. Tunable [see tomcrypt_custom.h]
-- Added some error detection to reg_algs() of the testprof.a library to detect when the PRNG is not setup correctly (took me 10 mins to figure out, PITA!)
-- Similar fixes to timing demo (MD5 not defined when EASY is defined)
-- Added the NLS enc+mac stream cipher from QUALCOMM, disabled for this release, waiting on test vectors
-- Finally added an auto-update script for the makefiles. So when I add new files/dirs it can automatically fix up the makefiles [all four of them...]
-- Added LRW to the list of cipher modes supported
-- cleaned up ciphers definitions to remove cbc/cfb/ofb/ctr/etc from the namespace when not used.
November 24th, 2005
v1.08 -- Added SET and SET OF support to the ASN.1 side
-- Fixed up X macros, added QSORT to the mix [thanks SET/SETOF]
-- Added XMEMCMP to the list of X macros
-- In der_decode_sequence() the SHORT_INTEGER type was not being handled correctly [oddly enough it worked just enough to make RSA work ... go figure!]
-- Fixed bug in math descriptors where if you hadn't defined MECC (ECC support) you would get linker errors
-- Added RSA accelerators to the math descriptors to make it possible to not include the stock routines if you supply your own.
-- dsa_decrypt_key() was erroneously dependent on MECC not MDSA ... whoops
-- Moved DSA size limits to tomcrypt_pk.h so they're defined with LTC_NO_PK+MDSA
-- cleaned up tomcrypt_custom.h to make customizable PK easier (and also cleaned up the error traps so they're correctly reported)
November 18th, 2005
v1.07 -- Craig Schlenter pointed out the "encrypt" demo doesn't call ctr_start() correctly. That's because as of a few releases ago
I added support to set the mode of the counter at init time
-- Fixed some "testprof" make issues
-- Added RSA keygen to the math descriptors
-- Fixed install_test target ... oops
-- made the "ranlib" program renamable useful for cross-compiling
-- Made the cipher accelerators return error codes. :-)
-- Made CCM accept a pre-scheduled key to speed it up if you use the same key for multiple packets
-- Added "Katja" public key crypto. It's based on the recent N = p^2q work by Katja. I added OAEP padding
to it. Note this code has been disabled not because it doesn't work but because it hasn't been thoroughly
analyzed. It does carry some advantages over RSA (slightly smaller public key, faster decrypt) but also
some annoying "setup" issues like the primes are smaller which makes ECM factoring more plausible.
-- Made makefile accept a NODOCS flag to disable the requirement of tetex to install LTC for you no tetex people... all 3 of ya :-)
-- Cleaned up rsa_export() since "zero" was handled with a SHORT_INTEGER
-- Cleaned up the LIBTEST_S definitions in both GNU makefiles. A few minor touchups as well.
-- Made the cipher ecb encrypt/decrypt return an int as well, changed ALL dependent code to check for this.
-- der_decode_choice() would fail to mark a NULL as "used" when decoding. Fixed
-- ecc_decrypt_key() now uses find_hash_oid() to clean up the code ;-)
-- Added mp_neg() to the math descriptors.
-- Swapped arguments for the pkcs_1_mgf1() function so the hash_idx is the first param (to be more consistent)
-- Made the math descriptors buildable when RSA has been undefined
-- ECC timing demo now capable of detecting which curves have been defined
-- Refactored the ECC code so it's easier to maintain. (note: the form of this code hasn't really changed since I first added ECC ... :-/)
-- Updated the documentation w.r.t. ECC and the accelerators to keep it current
-- Fixed bug in ltc_init_multi() which would fail to free all allocated memory on error.
-- Fixed bug in ecc_decrypt_key() which could possibly lead to overflows (if MAXBLOCKSIZE > ECC_BUF_SIZE and you have a hash that emits MAXBLOCKSIZE bytes)
-- Added encrypt/decrypt to the DSA side (basically DH with DSA parameters)
-- Updated makefiles to remove references to the old DH object files and the ecc_sys.o crap ... clean code ahead!
-- ecc_import() now checks if the point it reads in lies on the curve (to prevent degenerative points from being used)
-- ECC code now ALWAYS uses the accelerator interface. This allows people who use the accelerators to not have the stock
ECC point add/dbl/mul code linked in. Yeah space savings! Rah Rah Rah.
-- Added LTC_MUTEX_* support to Yarrow and Fortuna allowing you to use respective prng_state as a global PRNG state [e.g. thread-safe] if you define one of the LTC_* defines at
build time (e.g. LTC_PTHREAD == pthreads)
-- Added PPC32 support to the rotate macros (tested on an IBM PPC 405) and LTC_FAST macros (it aint fast but it's faster than stock)
-- Added ltc_mp checks in all *_make_key() and *_import() which will help catch newbs who don't register their bignum first :-)
-- the UTCTIME type was missing from der_length_sequence() [oops, oh like you've never done that]
-- the main makefile allows you to rename the make command [e.g. MAKE=gmake gmake install] so you can build LTC on platforms where the default make command sucks [e.g. BSD]
-- Added DER flexi decoder which allows the decoding of arbitrary DER encoded packets without knowing
their structure in advance (thanks to MSVC for finding 3 bugs in it just prior to release! ... don't ask)
August 1st, 2005
v1.06 -- Fixed rand_prime() to accept negative inputs as a signal for BBS primes. [Fredrik Olsson]
-- Added fourth ARGCHK type which outputs to stderr and continues. Useful if you trap sigsegv. [Valient Gough]
-- Removed the DH code from the tree
-- Made the ECC code fully public (you can access ecc_mulmod directly now) useful for debuging
-- Added ecc test to tv_gen
-- Added hmac callback to hash descriptors.
-- Fixed two doxy comment errors in the UTCTIME functions
-- rsa_import() can now read OpenSSL format DER public keys as well as the PKCS #1 RSAPublicKey format.
Note that rsa_export() **ONLY** writes PKCS #1 formats
-- Changed MIN/MAX to only define if not already present. -- Kirk J from Demonware ...
-- Ported tv_gen to new framework (and yes, I made ecc vectors BEFORE changing the API and YES they match now :-))
-- ported testing scripts to support pluggable math. yipee!
-- Wrote a TFM descriptor ... yipee
-- Cleaned up LTC_FAST in CBC mode a bit
-- Merged in patches from Michael Brown for the sparc/sparc64 targets
-- Added find_hash_oid() to search for a hash by its OID
-- Cleaned up a few stray CLEAN_STACKs that should have been LTC_CLEAN_STACK
-- Added timing resistant ECC, enable by defining LTC_ECC_TIMING_RESISTANT then use ECC API as normal
-- Updated the ECC documentation as it was a bit out of date
June 27th, 2005
v1.05
-- Added Technote #6 which covers the current PK compliance.
-- Fixed buffer overflow in OAEP decoder
-- Added CHOICE to the list of ASN.1 types
-- Added UTCTIME to the list of ASN.1 types
-- Added MUTEX locks around descriptor table functions [but not on the functions that are dependent on them]
All functions call *_is_valid() before using a descriptor index which means the respective table must be unlocked before
it can be accessed. However, during the operation [e.g. CCM] if the descriptor has been altered the results will be
undefined.
-- Minor updates to the manual to reflect recent changes
-- Added a catch to for an error that should never come up in rsa_exptmod(). Just being thorough.
June 15th, 2005
v1.04
-- Fixed off by one [bit] error in dsa_make_key() it was too high by one bit [not a security problem just inconsistent]
-- ECC-224 curve was wrong [it was an ok curve just not NIST, so no security flaw just interoperability].
-- Removed point compression since it slows down ECC ops to save a measly couple bytes.
This makes the ecc export format incompatible with 1.03 [it shouldn't change in the future]
-- Removed ECC-160 from timing and added the other curves
June 9th, 2005
v1.03
-- Users may want to note that on a P4/GCC3.4 platform "-fno-regmove" greatly accelerates the ciphers/hashes.
--------------------------------------------------------------------------------------------------------------
-- Made it install the testing library in the icc/static makefiles
-- Found bug in ccm_memory.c which would fail to compile when LTC_CLEAN_STACK was enabled
-- Simon Johnson proposed I do a fully automated test suite. Hence "testme.sh" was born
-- Added LTC_NO_TEST which forces test vectors off (regardless of what tomcrypt_custom.h has)
-- Added LTC_NO_TABLES which disables large tables (where possible, regardless of what tomcrypt_custom.h has)
-- New test script found a bug in twofish.c when TABLES was disabled. Yeah testing!
-- Added a LTC_FAST specific test to the testing software.
-- Updated test driver to actually halt on errors and just print them out (useful for say... automated testing...)
-- Added bounds checking to Pelican MAC
-- Added BIT and OCTET STRING to the ASN.1 side of things.
-- Pekka Riikonen pointed out that my ctr_start() function should accept the counter mode.
-- Cleaned up warnings in testprof
-- Removed redundant mu and point mapping in ecc_verify_hash() so it should be a bit faster now
-- Pekka pointed out that the AES key structure was using 32 bytes more than it ought to.
-- Added quick defines to remove entire classes of algorithms. This makes it easier if you want to build with just
one algorithm (say AES or SHA-256). Defines are LTC_NO_CIPHERS, LTC_NO_MODES, LTC_NO_HASHES, LTC_NO_MACS,
LTC_NO_PRNGS, LTC_NO_PK, LTC_NO_PKCS
-- As part of the move for ECC to X9.62 I've changed the signature algorithm to EC DSA. No API changes.
-- Pekka helped me clean up the PKCS #1 v2.1 [OAEP/PSS] code
-- Wrote new DER SEQUENCE coder/decoder
-- RSA, DSA and ECDSA now use the DER SEQUENCE code (saves a lot of code!)
-- DSA output is now a DER SEQUENCE (so not compatible with previous releases).
-- Added Technote #5 which shows how to build LTC on an AMD64 to have a variety of algorithms in only ~80KB of code.
-- Changed temp variable in LOAD/STORE macros to "ulong32" for 32-bit ops. Makes it safer on Big endian platforms
-- Added INSTALL_GROUP and INSTALL_USER which you can specify on the build to override the default USER/GROUP the library
is to be installed as
-- Removed "testprof" from the default build.
-- Added IA5, NULL and Object Identifier to the list of ASN.1 DER supported types
-- The "no_oops" target (part of zipup) now scans for non-cvs files. This helps prevent temp/scratch files from appearing in releases ;-)
-- Added DERs for missing hashes, but just the OID not the PKCS #1 v1.5 additions.
-- Removed PKCS #1 v1.5 from the tree since it's taking up space and you ought to use v2.1 anyways
-- Kevin Kenny pointed out a few stray // comments
-- INTEGER code properly supports negatives and zero padding [Pekka!]
-- Sorted asn1/der/ directory ... less of a mess now ;-)
-- Added PRINTABLE STRING type
-- Removed ECC-160 as it wasn't a standard curve
-- Made ecc_shared_secret() ANSI X9.63 compliant
-- Changed "printf" to "fprintf(stderr, " in the testbench... ;-)
-- Optimized the GCM table creation. On 1KB packets [with key switching] the new GCM is 12.7x faster than before.
-- Changed OID representation for hashes to be just a list of unsigned longs (so you can compare against them nicely after decoding a sequence)
-- ECC code now uses Montgomery reduction ... it's even faster [ECC-256 make key down from 37.4M to 4.6M cycles on an Athlon64]
-- Added SHORT_INTEGER so users can easily store DER encoded INTEGER types without using the bignum math library
-- Fixed OMAC code so that with LTC_FAST it doesn't require that LTC_FAST_TYPE divides 16 [it has to divide the block size instead]
-- ECC key export is now a simple [and documented] SEQUENCE, the "encrypt_key" also uses a new SEQUENCE format.
-- Thanks goes to the following testers
Michael Brown - Solaris 10/uSPARCII
Richard Outerbridge - MacOS
Martin Carpenter - Solaris 8/uSPARCII [Thanks for cleaning up the scripts]
Greg Rose - ... SunOS 5.8/SPARC [... what's with the SPARCS?]
Matt Johnston - MacOS X [Thanks for pointing out GCC 4 problems with -Os]
April 19th, 2005
v1.02
-- Added LTC_TEST support to gcm_test()
-- "pt/ct" can now be NULL in gcm_process() if you are processing zero bytes
-- Optimized GCM by removing the "double copy" handling of the plaintext/aad
-- Richard Outerbridge pointed out that x86_prof won't build on MACOS and that the manual
erroneously refers to "mycrypt" all over the place. Fixed.
April 17th, 2005
v1.01
** Secure Science Corporation has supported this release cycle by sponsoring the development time taken. Their
continuing support of this project has helped me maintain a steady pace in order to keep LibTomCrypt up to date,
stable and more efficient.
-----------------------------------------------------------------------------------------------------
-- Updated base64_decode.c so if there are more than 3 '=' signs it would stop parsing
-- Merged in latest mpi that fixed a few bugs here and there
-- Updated OAEP encoder/decoder to catch when the hash output is too large
Cleaned up PSS code too
-- Andy Bontoft fixed a bug in my demos/tests/makefile.msvc ... seems "dsa_test.c" isn't an object
afterall. Thanks.
-- Made invalid ECC key sizes (configuration) not hard fault the program (it returns an error code now)
-- SAFER has been re-enabled after I was pointed to http://www.ciphersbyritter.com/NEWS2/95032301.HTM
[Mark Kotiaho]
-- Added CCM mode to the encauth list (now has EAX, OCB and CCM, c'est un treo magnifique!)
-- Added missing ASN.1 header to the RSA keys ... oops... now the rsa_export/import are FULLY compatible
with other libs like OpenSSL (comment: Test vectors would go a long way RSA...)
-- Manually merged in fix to the prime_random_ex() LTM function that ensures the 2nd MSB is set properly. Now
When you say "I want a 1024/8 byte RSA key" the MSB bit of the modulus is set as expected. Note I generally
don't view this as a "huge issue" but it's just one less nit to worry about. [Bryan Klisch]
-- A new CVS has been setup on my Athlon64 box... if you want developer access send me an email (and at this point the email would have to be awesome).
-- Updated API for ECB and CBC shell code. Now can process N whole blocks in one call (like $DEITY intended)
-- Introduced a new "hardware accel" framework that can be used to speed up cipher ECB, CBC and CTR mode
calls. Later on dependent code (e.g. OMAC, CCM) will be re-written to use the generic cbc/ctr functions. But now
if you [say] call ctr_encrypt() with a cipher descriptor that has hardware CTR it will automatically
be used (e.g. no code rewrites)
-- Now ships with 20% more love.
-- x86_prof now uses ECB shell code (hint: accelerators) and outputs cycles per BLOCK not byte. This will make it a bit
easier to compare hardware vs. software cipher implementations. It also emits timings for CBC and CTR modes
-- [Peter LaDow] fixed a typo w.r.t. XREALLOC macro (spelling counts kids!)
-- Fixed bug with __x86_64__ where ROL64/ROR64 with LTC_NO_ROLC would be the 32-bit versions instead...
-- Shipping with preliminary GCM code (disabled). It's buggy (stack overflow hidden somewhere). If anyone can spot it let me know.
-- Added Pelican MAC [it's an AES based fast MAC] to the list of supported MACs
-- Added LTC_FAST [and you can disable by defining LTC_NO_FAST] so that CBC and CTR mode XOR whole words [e.g. 32 or 64 bits] at a time
instead of one byte. On my AMD64 this reduced the overhead for AES-128-CBC from 4.56 cycles/byte to around 1 cycle/byte. This requires
that you either allow unaligned read/writes [e.g. x86_32/x86_64] or align all your data. It won't go out of it's way to ensure
aligned access. Only enabled for x86_* platforms by default since they allow unaligned read/writes.
-- Added LTC_FAST support to PMAC (drops the cycle/byte by about 9 cycles on my AMD64) [note: I later rewrote this prior to release]
-- Updated "profiled" target to work with the new directory layout
-- Added [demo only] optimized RC5-CTR code to x86_prof demo to show off how to make an accelerator
[This has been removed prior to release... It may re-appear later]
-- Added CCM acelerator callbacks to the list [now supports ECB, CTR, CBC and now CCM].
-- Added chapter to manual about accelerators (you know you want it)
-- Added "bswap" optimizations to x86 LOAD/STORE with big endian. Can be disabled by defining LTC_NO_BSWAP
-- LTC_NO_ASM is now the official "disable all non-portable stuff" macro. When defined it will make the code endian-neutral,
disable any form of ASM and disable LTC_FAST load/stores. Essentially build the library with this defined if you're having
trouble building the library (old GCCs for instance dislike the ROLc macro)
-- Added tomcrypt_mac.h and moved MAC/encMAC functions from tomcrypt_hash.h into it
-- Added "done" function to ciphers and the five chaining modes [and things like omac/pmac/etc]
-- Changed install group to "wheel" from "root".
-- Replaced // comments with /**/ so it will build on older UNIX-like platforms
-- x86_prof builds and runs with IntelCC fine now
-- Added "stest" build to intel CC to test static linked from within the dir (so you don't have to install to test)
-- Moved testing/benchmark into testprof directory and build it as part of the build. Now you can link against libtomcrypt_prof.a to get
testing info (hint: hardware developers ;-) )
-- Added CCM to tv_gen
-- Added demos to MSVC makefile
-- Removed -funroll-all-loops from GCC makefile and replaced with -funroll-loops which is a bit more sane (P4 ain't got much cache for the IDATA)
-- Fixed GCM prior to release and re-enabled it. It has not been optimized but it does conform when compiled with optimizations.
-- I've since optimized GCM and CCM. They're close in speed but GCM is more flexible imho (though EAX is more flexible than both)
-- For kicks I optimized the ECC code to use projective points. Gets between 3.21x (Prescott P4) to 4.53x (AMD64) times faster than before at 160-bit keys and the
speedup grows as the keysize grows. Basically removing most practical reasons to "not use the ECC code". Enjoy.
-- Added LTC_FAST support to OMAC/PMAC and doubled it's speed on my amd64 [faster on the P4 too I guess]
-- Added GCM to tv_gen
-- Removed "makefile.cygwin_dll" as it's not really used by anyone and not worth the effort (hell I hardly maintain the MSVC makefiles ...)
-- Updated a few files in the "misc" directory to have correct @file comments for doxygen
-- Removed "profile" target since it was slower anyways (go figure...)
December 31st, 2004
v1.00
-- Added "r,s == 0" check to dsa_verify_hash()
-- Added "multi block" helpers for hash, hmac, pmac and omac routines so you can process multiple non-adjacent
blocks of data with one call (added demos/multi.c to make sure they work)
-- Note these are not documented but they do have doxygen comments inside them
-- Also I don't use them in other functions (like pkcs_5_2()) because I didn't have the time. Job for the new LTC maintainer ;-)
-- Added tweaked Anubis test vectors and made it default (undefined ANUBIS_TWEAK to get original Anubis)
-- Merged in fix for mp_prime_random_ex() to deal with MSB and LSB "bugs"
-- Removed tim_exptmod() completely, updated several RSA functions (notably v15 and the decrypt/verify) so they
don't require a prng now
-- This release brought to you by the fine tunes of Macy Gray. We miss you.
December 23rd, 2004
v1.00rc1
-- Renamed "mycrypt_*" to "tomcrypt_*" to be more specific and professional
Now just include "tomcrypt.h" instead of "mycrypt.h" to get LTC ;-)
-- Cleaned up makefiles to ensure all headers are correctly installed
-- Added "rotate by constant" macros for portable, x86-32 and x86-64
You can disable this new code with LTC_NO_ROLC which is useful for older GCCs
-- Cleaned up detection of x86-64 so it works for ROL/ROR macros
-- Fixed rsa_import() so that it would detect multi-prime RSA keys and error appropriately
-- Sorted the source files by category and updated the makefiles appropriately
-- Added LTC_DER define so you can trim out DER code if not required
-- Fixed up RSA's decrypt functions changing "res" to "stat" to be more in sync
with the signature variables nomenclature. (no code change just renamed the arguments)
-- Removed all labels starting with __ and replaced with LBL_ to avoid namespace conflicts (Randy Howard)
-- Merged in LTM fix to mp_prime_random_ex() which zap'ed the most significant byte if the bit size
requested was a multiple of eight.
-- Made RSA_TIMING off by default as it's not terribly useful [and likely to be deprecated]
-- Renamed SMALL_CODE, CLEAN_STACK and NO_FILE to have a LTC_ prefix to avoid namespace collisions
with other programs. e.g. SMALL_CODE => LTC_SMALL_CODE
-- Zed Shaw pointed out that on certain systems installing libs as "root" isn't possible as the super-user
is not root. Now the makefiles allow this to be changed easily.
-- Renamed "struct _*_descriptor" to "struct ltc_*_descriptor" to avoid using a leading _
Also renamed _ARGCHK to LTC_ARGCHK
-- Zed Shaw pointed out that I still defined the prng structs in tomcrypt_prng.h even if they
weren't defined. This made undef'ing FORTUNA break the build.
-- Added LTC_NO_ASM to disable inline asm macros [ROL/ROR/etc]
-- Changed RSA decrypt functions to change the output length variable name from "keylen" to "outlen" to make
it more consistent.
-- Added the 64-bit Khazad block cipher [NESSIE]
-- Added the 128-bit Anubis block cipher [with key support for 128...320 bit keys] [NESSIE]
-- Changes to several MAC functions to rename input arguments to more sensible names
-- Removed FAST_PK support from dh_sys.c
-- Declared deskey() from des.c as static instead of a global
-- Added pretty much all practical GCC warning tests to the GCC [related] makefiles. These additional
warnings can easily be disabled for those with older copies of GCC [or even non GNU cc's]
-- Added doxygen @ tags to the code... phew that was a hell of a lot of [repetitive] work
-- Also added pre-configured Doxygen script.
-- Cleaned up quite a few functions [ciphers, pk, etc] to make the parameters naming style consistent
E.g. ciphers keys are called "skey" consistently now. The input to PK encryption is called "in", etc.
These changes require no code changes on the behalf of developers fortunately
-- Started a SAFER+ optimizer [does encrypt only] which shaves a good 30 or so cycles/byte on my AMD64
at an expense of huge code. It's in notes/etc/saferp_optimizer.c
-- DSA sign/verify now uses DER encoded output/inputs and no LTC style headers.
-- Matt Johnston found a missing semi-colon in mp_exptmod(). Fix has been merged in.
October 29th, 2004
v0.99 -- Merged in the latest version of LTM which includes all of the recent bug fixes
-- Deprecated LTMSSE and removed it (to be replaced with TFM later on)
-- Stefan Arentz pointed out that mp_s_rmap should be extern
-- Kristian Gj?steen pointed out that there are typos in the
"test" makefile and minor issues in Yarrow and Sober [just cosmetics really]
-- Matthew P. Cashdollar pointed out that "export" is a C++ keyword
so changed the PRNG api to use "pexport" and "pimport"
-- Updated "hashsum" demo so it builds ;-)
-- Added automatic support for x86-64 (will configure for 64-bit little endian automagically)
-- Zhi Chen pointed out a bug in rsa_exptmod which would leak memory on error.
-- Made hash functions "init" return an int. slight change to API ;-(
-- Added "CHC" mode which turns any cipher into a hash the other LTC functions can use
-- Added CHC mode stuff to demos such as tv_gen and hashsum
-- Added "makefile.shared" which builds and installs shared/static object copies
of the library.
-- Added DER for bignum support
-- RSA is now fully joy. rsa_export/rsa_import use PKCS #1 encodings and should be
compatible with other crypto libs that use the format.
-- Added support for x86-64 for the ROL/ROR macros
-- Changed the DLL and SO makefiles to optimize for speed, commented SMALL_CODE in
mycrypt_custom.h and added -DSMALL_CODE to the default makefile
-- Updated primality testing code so it does a minimum of 5 tests [of Miller-Rabin]
(AFAIK not a security fix, just warm fuzzies)
-- Minor updates to the OMAC code (additional __ARGCHK and removed printf from omac_test... oops!)
-- Update build and configuration info which was really really really out of date. (Chapter 14)
++ Minor update, switch RSA to use the PKCS style CRT
August 6th, 2004
v0.98 -- Update to hmac_init to free all allocated memory on error
-- Update to PRNG API to fix import/export functions of Fortuna and Yarrow
-- Added test functions to PRNG api, RC4 now conforms ;-) [was a minor issue]
-- Added the SOBER-128 PRNG based off of code donated by Greg Rose.
-- Added Tech Note #4 [notes/tech0004.txt]
-- Changed RC4 back [due to request]. It will now XOR the output so you can use it like
a stream cipher easily.
-- Update Fortuna's export() to emit a hash of each pool. This means that the accumulated
entropy that was spread over all the pools isn't entirely lost when you export/import.
-- Zhi Chen suggested a comment for rsa_encrypt_key() to let users know [easily] that it was
PKCS #1 v2.0 padding. (updated other rsa_* functions)
-- Cleaned up Noekeon to remove unrolling [wasn't required, was messy and actually slower with GCC/ICC]
-- Updated RC4 so that when you feed it >256 bytes of entropy it quietly ignores additional
bytes. Also removed the % from the key setup to speed it up a bit.
-- Added cipher/hash/prng tests to x86_prof to help catch bugs while testing
-- Made the PRNG "done" return int, fixed sprng_done to not require prng* to be non-null
-- Spruced up mycrypt_custom.h to trap more errors and also help prevent LTMSSE from being defined
on non-i386 platforms by accident.
-- Added RSA/ECC/DH speed tests to x86_prof and cleaned it up to build with zero warnings
-- Changed Fortuna to count only entropy [not the 2 byte header] added to pool[0] into the
reseed mechanism.
-- Added "export_size" member to prng_descriptor tables so you can know in advance the size of
the exported state for any given PRNG.
-- Ported over patch on LTM 0.30 [not ready to release LTM 0.31] that fixes bug in mp_mul()/mp_div()
that used to result in negative zeroes when you multiplied zero by a negative integer.
(patch due to "Wolfgang Ehrhardt" <Wolfgang.Ehrhardt@munich.netsurf.de>)
-- Fixed rsa_*decrypt_key() and rsa_*verify_hash() to default to invalid "stat" or "res". This way
if any of the higher level functions fail [before you get to the padding] the result will be in
a known state]. Applied to both v2 and v1.5 padding helpers.
-- Added MACs to x86_prof
-- Fixed up "warnings" in x86_prof and tv_gen
-- Added a "profiled" target back [for GCC 3.4 and ICC v8]. Doesn't seem to help but might be worth
tinkering with.
-- Beefed up load/store test in demos/test
++ New note, in order to use the optimized LOAD/STORE macros your platform
must support unaligned 32/64 bit load/stores. The x86s support this
but some [ARM for instance] do not. If your platform cannot perform
unaligned operations you must use the endian neutral code which is safe for
any sort of platform.
July 23rd, 2004
v0.97b -- Added PKCS #1 v1.5 RSA encrypt/sign helpers (like rsa_sign_hash, etc...)
-- Added missing prng check to rsa_decrypt_key() [not critical as I don't use
@ -62,7 +665,7 @@ v0.96 -- Removed GF and Keyring code
-- Changed PSS/OAEP API slightly to be more consistent with other PK functions (order of arguments)
-- rsa_exptmod() now pads with leading zeroes as per I2OSP.
-- added error checking to yarrow code
-- Mike Frysinger pointed out that tommath.h from this distro will overwrite tommath.h
-- pointed out that tommath.h from this distro will overwrite tommath.h
from libtommath. I changed this to ltc_tommath.h to avoid any such problems.
-- Fixed bug in PSS encoder/decoder that didn't handle the MSB properly
-- refactored AES, now sports an "encrypt only" descriptor which uses half as much code space.
@ -311,7 +914,7 @@ v0.81 -- Merged in new makefile from Clay Culver and Mike Frysinger
as much as possible. This sped the routine up quite a bit.
-- Fixed a huge flaw in ecc_verify_hash() where it would return CRYPT_OK on error... Now fixed.
-- Fixed up config.pl by fixing an invalid query and the file is saved in non-windows [e.g. not CR/LF] format
(fix due to Mika Boström)
(fix due to Mika Bostr?m)
-- Merged in LibTomMath for kicks
-- Changed the build process so that by default "mycrypt_custom.h" is included and provided
The makefile doesn't include any build options anymore
@ -1038,3 +1641,8 @@ v0.02 -- Changed RC5 to only allow 12 to 24 rounds
-- Added more to the manual.
v0.01 -- We will call this the first version.
/* $Source: /cvs/libtom/libtomcrypt/changes,v $ */
/* $Revision: 1.288 $ */
/* $Date: 2007/05/12 14:37:41 $ */

241
cmake-format.py Normal file
View file

@ -0,0 +1,241 @@
# ----------------------------------
# Options affecting listfile parsing
# ----------------------------------
with section("parse"):
# Specify structure for custom cmake functions
additional_commands = { 'foo': { 'flags': ['BAR', 'BAZ'],
'kwargs': {'DEPENDS': '*', 'HEADERS': '*', 'SOURCES': '*'}}}
# Override configurations per-command where available
override_spec = {}
# Specify variable tags.
vartags = []
# Specify property tags.
proptags = []
# -----------------------------
# Options affecting formatting.
# -----------------------------
with section("format"):
# Disable formatting entirely, making cmake-format a no-op
disable = False
# How wide to allow formatted cmake files
line_width = 100
# How many spaces to tab for indent
tab_size = 4
# If true, lines are indented using tab characters (utf-8 0x09) instead of
# <tab_size> space characters (utf-8 0x20). In cases where the layout would
# require a fractional tab character, the behavior of the fractional
# indentation is governed by <fractional_tab_policy>
use_tabchars = False
# If <use_tabchars> is True, then the value of this variable indicates how
# fractional indentions are handled during whitespace replacement. If set to
# 'use-space', fractional indentation is left as spaces (utf-8 0x20). If set
# to `round-up` fractional indentation is replaced with a single tab character
# (utf-8 0x09) effectively shifting the column to the next tabstop
fractional_tab_policy = 'use-space'
# If an argument group contains more than this many sub-groups (parg or kwarg
# groups) then force it to a vertical layout.
max_subgroups_hwrap = 2
# If a positional argument group contains more than this many arguments, then
# force it to a vertical layout.
max_pargs_hwrap = 6
# If a cmdline positional group consumes more than this many lines without
# nesting, then invalidate the layout (and nest)
max_rows_cmdline = 2
# If true, separate flow control names from their parentheses with a space
separate_ctrl_name_with_space = False
# If true, separate function names from parentheses with a space
separate_fn_name_with_space = False
# If a statement is wrapped to more than one line, than dangle the closing
# parenthesis on its own line.
dangle_parens = True
# If the trailing parenthesis must be 'dangled' on its on line, then align it
# to this reference: `prefix`: the start of the statement, `prefix-indent`:
# the start of the statement, plus one indentation level, `child`: align to
# the column of the arguments
dangle_align = 'prefix'
# If the statement spelling length (including space and parenthesis) is
# smaller than this amount, then force reject nested layouts.
min_prefix_chars = 4
# If the statement spelling length (including space and parenthesis) is larger
# than the tab width by more than this amount, then force reject un-nested
# layouts.
max_prefix_chars = 10
# If a candidate layout is wrapped horizontally but it exceeds this many
# lines, then reject the layout.
max_lines_hwrap = 2
# What style line endings to use in the output.
line_ending = 'unix'
# Format command names consistently as 'lower' or 'upper' case
command_case = 'lower'
# Format keywords consistently as 'lower' or 'upper' case
keyword_case = 'upper'
# A list of command names which should always be wrapped
always_wrap = []
# If true, the argument lists which are known to be sortable will be sorted
# lexicographicall
enable_sort = True
# If true, the parsers may infer whether or not an argument list is sortable
# (without annotation).
autosort = False
# By default, if cmake-format cannot successfully fit everything into the
# desired linewidth it will apply the last, most agressive attempt that it
# made. If this flag is True, however, cmake-format will print error, exit
# with non-zero status code, and write-out nothing
require_valid_layout = False
# A dictionary mapping layout nodes to a list of wrap decisions. See the
# documentation for more information.
layout_passes = {}
# ------------------------------------------------
# Options affecting comment reflow and formatting.
# ------------------------------------------------
with section("markup"):
# What character to use for bulleted lists
bullet_char = '*'
# What character to use as punctuation after numerals in an enumerated list
enum_char = '.'
# If comment markup is enabled, don't reflow the first comment block in each
# listfile. Use this to preserve formatting of your copyright/license
# statements.
first_comment_is_literal = False
# If comment markup is enabled, don't reflow any comment block which matches
# this (regex) pattern. Default is `None` (disabled).
literal_comment_pattern = None
# Regular expression to match preformat fences in comments default=
# ``r'^\s*([`~]{3}[`~]*)(.*)$'``
fence_pattern = '^\\s*([`~]{3}[`~]*)(.*)$'
# Regular expression to match rulers in comments default=
# ``r'^\s*[^\w\s]{3}.*[^\w\s]{3}$'``
ruler_pattern = '^\\s*[^\\w\\s]{3}.*[^\\w\\s]{3}$'
# If a comment line matches starts with this pattern then it is explicitly a
# trailing comment for the preceeding argument. Default is '#<'
explicit_trailing_pattern = '#<'
# If a comment line starts with at least this many consecutive hash
# characters, then don't lstrip() them off. This allows for lazy hash rulers
# where the first hash char is not separated by space
hashruler_min_length = 10
# If true, then insert a space between the first hash char and remaining hash
# chars in a hash ruler, and normalize its length to fill the column
canonicalize_hashrulers = True
# enable comment markup parsing and reflow
enable_markup = True
# ----------------------------
# Options affecting the linter
# ----------------------------
with section("lint"):
# a list of lint codes to disable
disabled_codes = []
# regular expression pattern describing valid function names
function_pattern = '[0-9a-z_]+'
# regular expression pattern describing valid macro names
macro_pattern = '[0-9A-Z_]+'
# regular expression pattern describing valid names for variables with global
# (cache) scope
global_var_pattern = '[A-Z][0-9A-Z_]+'
# regular expression pattern describing valid names for variables with global
# scope (but internal semantic)
internal_var_pattern = '_[A-Z][0-9A-Z_]+'
# regular expression pattern describing valid names for variables with local
# scope
local_var_pattern = '[a-z][a-z0-9_]+'
# regular expression pattern describing valid names for privatedirectory
# variables
private_var_pattern = '_[0-9a-z_]+'
# regular expression pattern describing valid names for public directory
# variables
public_var_pattern = '[A-Z][0-9A-Z_]+'
# regular expression pattern describing valid names for function/macro
# arguments and loop variables.
argument_var_pattern = '[a-z][a-z0-9_]+'
# regular expression pattern describing valid names for keywords used in
# functions or macros
keyword_pattern = '[A-Z][0-9A-Z_]+'
# In the heuristic for C0201, how many conditionals to match within a loop in
# before considering the loop a parser.
max_conditionals_custom_parser = 2
# Require at least this many newlines between statements
min_statement_spacing = 1
# Require no more than this many newlines between statements
max_statement_spacing = 2
max_returns = 6
max_branches = 12
max_arguments = 5
max_localvars = 15
max_statements = 50
# -------------------------------
# Options affecting file encoding
# -------------------------------
with section("encode"):
# If true, emit the unicode byte-order mark (BOM) at the start of the file
emit_byteorder_mark = False
# Specify the encoding of the input file. Defaults to utf-8
input_encoding = 'utf-8'
# Specify the encoding of the output file. Defaults to utf-8. Note that cmake
# only claims to support utf-8 so be careful when using anything else
output_encoding = 'utf-8'
# -------------------------------------
# Miscellaneous configurations options.
# -------------------------------------
with section("misc"):
# A dictionary containing any per-command configuration overrides. Currently
# only `command_case` is supported.
per_command = {}

14
contrib/libtomcrypt.cmake Normal file
View file

@ -0,0 +1,14 @@
# To find libtomcrypt no matter what the installation look like, start with
# looking for the CMake specific configuration, and failing that, try the
# pkg-config package instead. The resulting target is different in each
# case, but is recorded in the variable ${LIBTOMCRYPT}, so please use that
# for all targets that depend on libtomcrypt.
find_package(libtomcrypt QUIET)
if (libtomcrypt_FOUND)
set(LIBTOMCRYPT libtomcrypt)
else()
find_package(PkgConfig)
pkg_check_modules(libtomcrypt REQUIRED IMPORTED_TARGET libtomcrypt)
set(LIBTOMCRYPT PkgConfig::libtomcrypt)
endif()

40
contrib/sbom.cdx.json Normal file
View file

@ -0,0 +1,40 @@
{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"version": 1,
"metadata": {
"authors": [
{
"name": "@VCS_SBOM_AUTHORS@"
}
]
},
"components": [
{
"type": "library",
"bom-ref": "pkg:github/libtom/libtomcrypt@@VCS_TAG@",
"cpe": "cpe:2.3:a:libtom:libtomcrypt:@VCS_TAG@:*:*:*:*:*:*:*",
"name": "libtomcrypt",
"version": "@VCS_VERSION@",
"description": "Modular and portable cryptographic toolkit",
"authors": [
{
"name": "libtomcrypt developers"
}
],
"licenses": [
{
"license": {
"id": "Unlicense"
}
}
],
"externalReferences": [
{
"type": "vcs",
"url": "https://github.com/libtom/libtomcrypt"
}
]
}
]
}

42
coverity.sh Executable file
View file

@ -0,0 +1,42 @@
#!/bin/bash
if [ $# -lt 2 ]
then
echo "usage is: ${0##*/} <path to coverity scan> <extra compiler options>"
echo "e.g. \"${0##*/} \"/usr/local/bin/coverity\" \"-DLTM_DESC -I/path/to/libtommath/\"\""
exit -1
fi
PATH=$PATH:$1/bin
make clean
rm -r cov-int/
myCflags=""
myCflags="$myCflags -O2 ${2}"
myCflags="$myCflags -pipe -Werror -Wpointer-arith -Winit-self -Wextra -Wall -Wformat -Wformat-security"
CFLAGS="$myCflags" cov-build --dir cov-int make -f makefile.unix $MAKE_OPTS IGNORE_SPEED=1 1>gcc_1.txt
if [ $? -ne 0 ]
then
echo "make failed"
exit -1
fi
# zipup everything
tar caf libtomcrypt.lzma cov-int
mytoken=$(cat .coverity_token)
mymail=$(cat .coverity_mail)
myversion=$(git describe --dirty)
curl -k --form project=libtomcrypt \
--form token=${mytoken} \
--form email=${mymail} \
--form file=@libtomcrypt.lzma \
--form version=\"${myversion}\" \
--form description="\"libtomcrypt version ${myversion}\"" \
https://scan.coverity.com/builds?project=libtom%2Flibtomcrypt
# EOF

25
crypt
View file

@ -1,25 +0,0 @@
%PDF-1.3
%Çì<C387>¢
3 0 obj
<< /Type /Pages /Kids [
] /Count 0
>>
endobj
1 0 obj
<</Type /Catalog /Pages 3 0 R
>>
endobj
2 0 obj
<</Producer(ESP Ghostscript 7.07)>>endobj
xref
0 4
0000000000 65535 f
0000000068 00000 n
0000000116 00000 n
0000000015 00000 n
trailer
<< /Size 4 /Root 1 0 R /Info 2 0 R
>>
startxref
166
%%EOF

236
crypt.c
View file

@ -1,236 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
const char *crypt_build_settings =
"LibTomCrypt " SCRYPT "\n\n"
"Endianess: "
#if defined(ENDIAN_NEUTRAL)
"neutral\n"
#elif defined(ENDIAN_LITTLE)
"little"
#if defined(ENDIAN_32BITWORD)
" (32-bit words)\n"
#else
" (64-bit words)\n"
#endif
#elif defined(ENDIAN_BIG)
"big"
#if defined(ENDIAN_32BITWORD)
" (32-bit words)\n"
#else
" (64-bit words)\n"
#endif
#endif
"Clean stack: "
#if defined(CLEAN_STACK)
"enabled\n"
#else
"disabled\n"
#endif
"Ciphers built-in:\n"
#if defined(BLOWFISH)
" Blowfish\n"
#endif
#if defined(RC2)
" RC2\n"
#endif
#if defined(RC5)
" RC5\n"
#endif
#if defined(RC6)
" RC6\n"
#endif
#if defined(SAFERP)
" Safer+\n"
#endif
#if defined(SAFER)
" Safer\n"
#endif
#if defined(RIJNDAEL)
" Rijndael\n"
#endif
#if defined(XTEA)
" XTEA\n"
#endif
#if defined(TWOFISH)
" Twofish "
#if defined(TWOFISH_SMALL) && defined(TWOFISH_TABLES)
"(small, tables)\n"
#elif defined(TWOFISH_SMALL)
"(small)\n"
#elif defined(TWOFISH_TABLES)
"(tables)\n"
#else
"\n"
#endif
#endif
#if defined(DES)
" DES\n"
#endif
#if defined(CAST5)
" CAST5\n"
#endif
#if defined(NOEKEON)
" Noekeon\n"
#endif
#if defined(SKIPJACK)
" Skipjack\n"
#endif
"\nHashes built-in:\n"
#if defined(SHA512)
" SHA-512\n"
#endif
#if defined(SHA384)
" SHA-384\n"
#endif
#if defined(SHA256)
" SHA-256\n"
#endif
#if defined(SHA224)
" SHA-224\n"
#endif
#if defined(TIGER)
" TIGER\n"
#endif
#if defined(SHA1)
" SHA1\n"
#endif
#if defined(MD5)
" MD5\n"
#endif
#if defined(MD4)
" MD4\n"
#endif
#if defined(MD2)
" MD2\n"
#endif
#if defined(RIPEMD128)
" RIPEMD128\n"
#endif
#if defined(RIPEMD160)
" RIPEMD160\n"
#endif
#if defined(WHIRLPOOL)
" WHIRLPOOL\n"
#endif
"\nBlock Chaining Modes:\n"
#if defined(CFB)
" CFB\n"
#endif
#if defined(OFB)
" OFB\n"
#endif
#if defined(ECB)
" ECB\n"
#endif
#if defined(CBC)
" CBC\n"
#endif
#if defined(CTR)
" CTR\n"
#endif
"\nPRNG:\n"
#if defined(YARROW)
" Yarrow\n"
#endif
#if defined(SPRNG)
" SPRNG\n"
#endif
#if defined(RC4)
" RC4\n"
#endif
"\nPK Algs:\n"
#if defined(MRSA)
" RSA"
#if defined(RSA_TIMING)
" + RSA_TIMING "
#endif
"\n"
#endif
#if defined(MDH)
" DH\n"
#endif
#if defined(MECC)
" ECC\n"
#endif
#if defined(MDSA)
" DSA\n"
#endif
"\nCompiler:\n"
#if defined(WIN32)
" WIN32 platform detected.\n"
#endif
#if defined(__CYGWIN__)
" CYGWIN Detected.\n"
#endif
#if defined(__DJGPP__)
" DJGPP Detected.\n"
#endif
#if defined(_MSC_VER)
" MSVC compiler detected.\n"
#endif
#if defined(__GNUC__)
" GCC compiler detected.\n"
#endif
#if defined(INTEL_CC)
" Intel C Compiler detected.\n"
#endif
"\nVarious others: "
#if defined(BASE64)
" BASE64 "
#endif
#if defined(MPI)
" MPI "
#endif
#if defined(HMAC)
" HMAC "
#endif
#if defined(OMAC)
" OMAC "
#endif
#if defined(PMAC)
" PMAC "
#endif
#if defined(EAX_MODE)
" EAX_MODE "
#endif
#if defined(OCB_MODE)
" OCB_MODE "
#endif
#if defined(TRY_UNRANDOM_FIRST)
" TRY_UNRANDOM_FIRST "
#endif
#if defined(LTC_TEST)
" LTC_TEST "
#endif
#if defined(PKCS_1)
" PKCS#1 "
#endif
#if defined(PKCS_5)
" PKCS#5 "
#endif
#if defined(SMALL_CODE)
" SMALL_CODE "
#endif
#if defined(NO_FILE)
" NO_FILE "
#endif
"\n"
"\n\n\n"
;

3142
crypt.tex

File diff suppressed because it is too large Load diff

View file

@ -1,21 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#include <signal.h>
#if (ARGTYPE == 0)
void crypt_argchk(char *v, char *s, int d)
{
fprintf(stderr, "_ARGCHK '%s' failure on line %d of file %s\n",
v, d, s);
(void)raise(SIGABRT);
}
#endif

View file

@ -1,14 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
struct _cipher_descriptor cipher_descriptor[TAB_SIZE];

View file

@ -1,19 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int cipher_is_valid(int idx)
{
if (idx < 0 || idx >= TAB_SIZE || cipher_descriptor[idx].name == NULL) {
return CRYPT_INVALID_CIPHER;
}
return CRYPT_OK;
}

View file

@ -1,24 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int find_cipher(const char *name)
{
int x;
_ARGCHK(name != NULL);
for (x = 0; x < TAB_SIZE; x++) {
if (cipher_descriptor[x].name != NULL && !strcmp(cipher_descriptor[x].name, name)) {
return x;
}
}
return -1;
}

View file

@ -1,32 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
/* idea from Wayne Scott */
int find_cipher_any(const char *name, int blocklen, int keylen)
{
int x;
_ARGCHK(name != NULL);
x = find_cipher(name);
if (x != -1) return x;
for (x = 0; x < TAB_SIZE; x++) {
if (cipher_descriptor[x].name == NULL) {
continue;
}
if (blocklen <= (int)cipher_descriptor[x].block_length && keylen <= (int)cipher_descriptor[x].max_key_length) {
return x;
}
}
return -1;
}

View file

@ -1,22 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int find_cipher_id(unsigned char ID)
{
int x;
for (x = 0; x < TAB_SIZE; x++) {
if (cipher_descriptor[x].ID == ID) {
return (cipher_descriptor[x].name == NULL) ? -1 : x;
}
}
return -1;
}

View file

@ -1,23 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int find_hash(const char *name)
{
int x;
_ARGCHK(name != NULL);
for (x = 0; x < TAB_SIZE; x++) {
if (hash_descriptor[x].name != NULL && strcmp(hash_descriptor[x].name, name) == 0) {
return x;
}
}
return -1;
}

View file

@ -1,34 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
/* return first hash with at least [amount over] digestlen bytes of output */
int find_hash_any(const char *name, int digestlen)
{
int x, y, z;
_ARGCHK(name != NULL);
x = find_hash(name);
if (x != -1) return x;
y = MAXBLOCKSIZE+1;
z = -1;
for (x = 0; x < TAB_SIZE; x++) {
if (hash_descriptor[x].name == NULL) {
continue;
}
if ((int)hash_descriptor[x].hashsize >= digestlen && (int)hash_descriptor[x].hashsize < y) {
z = x;
y = hash_descriptor[x].hashsize;
}
}
return z;
}

View file

@ -1,22 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int find_hash_id(unsigned char ID)
{
int x;
for (x = 0; x < TAB_SIZE; x++) {
if (hash_descriptor[x].ID == ID) {
return (hash_descriptor[x].name == NULL) ? -1 : x;
}
}
return -1;
}

View file

@ -1,24 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int find_prng(const char *name)
{
int x;
_ARGCHK(name != NULL);
for (x = 0; x < TAB_SIZE; x++) {
if ((prng_descriptor[x].name != NULL) && strcmp(prng_descriptor[x].name, name) == 0) {
return x;
}
}
return -1;
}

View file

@ -1,14 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
struct _hash_descriptor hash_descriptor[TAB_SIZE];

View file

@ -1,19 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int hash_is_valid(int idx)
{
if (idx < 0 || idx >= TAB_SIZE || hash_descriptor[idx].name == NULL) {
return CRYPT_INVALID_HASH;
}
return CRYPT_OK;
}

View file

@ -1,13 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
struct _prng_descriptor prng_descriptor[TAB_SIZE];

View file

@ -1,19 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int prng_is_valid(int idx)
{
if (idx < 0 || idx >= TAB_SIZE || prng_descriptor[idx].name == NULL) {
return CRYPT_INVALID_PRNG;
}
return CRYPT_OK;
}

View file

@ -1,36 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int register_cipher(const struct _cipher_descriptor *cipher)
{
int x;
_ARGCHK(cipher != NULL);
/* is it already registered? */
for (x = 0; x < TAB_SIZE; x++) {
if (cipher_descriptor[x].name != NULL && cipher_descriptor[x].ID == cipher->ID) {
return x;
}
}
/* find a blank spot */
for (x = 0; x < TAB_SIZE; x++) {
if (cipher_descriptor[x].name == NULL) {
XMEMCPY(&cipher_descriptor[x], cipher, sizeof(struct _cipher_descriptor));
return x;
}
}
/* no spot */
return -1;
}

View file

@ -1,36 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int register_hash(const struct _hash_descriptor *hash)
{
int x;
_ARGCHK(hash != NULL);
/* is it already registered? */
for (x = 0; x < TAB_SIZE; x++) {
if (memcmp(&hash_descriptor[x], hash, sizeof(struct _hash_descriptor)) == 0) {
return x;
}
}
/* find a blank spot */
for (x = 0; x < TAB_SIZE; x++) {
if (hash_descriptor[x].name == NULL) {
XMEMCPY(&hash_descriptor[x], hash, sizeof(struct _hash_descriptor));
return x;
}
}
/* no spot */
return -1;
}

View file

@ -1,36 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int register_prng(const struct _prng_descriptor *prng)
{
int x;
_ARGCHK(prng != NULL);
/* is it already registered? */
for (x = 0; x < TAB_SIZE; x++) {
if (memcmp(&prng_descriptor[x], prng, sizeof(struct _prng_descriptor)) == 0) {
return x;
}
}
/* find a blank spot */
for (x = 0; x < TAB_SIZE; x++) {
if (prng_descriptor[x].name == NULL) {
XMEMCPY(&prng_descriptor[x], prng, sizeof(struct _prng_descriptor));
return x;
}
}
/* no spot */
return -1;
}

View file

@ -1,28 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int unregister_cipher(const struct _cipher_descriptor *cipher)
{
int x;
_ARGCHK(cipher != NULL);
/* is it already registered? */
for (x = 0; x < TAB_SIZE; x++) {
if (memcmp(&cipher_descriptor[x], cipher, sizeof(struct _cipher_descriptor)) == 0) {
cipher_descriptor[x].name = NULL;
cipher_descriptor[x].ID = 255;
return CRYPT_OK;
}
}
return CRYPT_ERROR;
}

View file

@ -1,27 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int unregister_hash(const struct _hash_descriptor *hash)
{
int x;
_ARGCHK(hash != NULL);
/* is it already registered? */
for (x = 0; x < TAB_SIZE; x++) {
if (memcmp(&hash_descriptor[x], hash, sizeof(struct _hash_descriptor)) == 0) {
hash_descriptor[x].name = NULL;
return CRYPT_OK;
}
}
return CRYPT_ERROR;
}

View file

@ -1,27 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
int unregister_prng(const struct _prng_descriptor *prng)
{
int x;
_ARGCHK(prng != NULL);
/* is it already registered? */
for (x = 0; x < TAB_SIZE; x++) {
if (memcmp(&prng_descriptor[x], prng, sizeof(struct _prng_descriptor)) != 0) {
prng_descriptor[x].name = NULL;
return CRYPT_OK;
}
}
return CRYPT_ERROR;
}

View file

@ -1,25 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CTR
int ctr_decrypt(const unsigned char *ct, unsigned char *pt, unsigned long len, symmetric_CTR *ctr)
{
_ARGCHK(pt != NULL);
_ARGCHK(ct != NULL);
_ARGCHK(ctr != NULL);
return ctr_encrypt(ct, pt, len, ctr);
}
#endif

View file

@ -1,64 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CTR
int ctr_encrypt(const unsigned char *pt, unsigned char *ct, unsigned long len, symmetric_CTR *ctr)
{
int x, err;
_ARGCHK(pt != NULL);
_ARGCHK(ct != NULL);
_ARGCHK(ctr != NULL);
if ((err = cipher_is_valid(ctr->cipher)) != CRYPT_OK) {
return err;
}
/* is blocklen/padlen valid? */
if (ctr->blocklen < 0 || ctr->blocklen > (int)sizeof(ctr->ctr) ||
ctr->padlen < 0 || ctr->padlen > (int)sizeof(ctr->pad)) {
return CRYPT_INVALID_ARG;
}
while (len-- > 0) {
/* is the pad empty? */
if (ctr->padlen == ctr->blocklen) {
/* increment counter */
if (ctr->mode == 0) {
/* little-endian */
for (x = 0; x < ctr->blocklen; x++) {
ctr->ctr[x] = (ctr->ctr[x] + (unsigned char)1) & (unsigned char)255;
if (ctr->ctr[x] != (unsigned char)0) {
break;
}
}
} else {
/* big-endian */
for (x = ctr->blocklen-1; x >= 0; x--) {
ctr->ctr[x] = (ctr->ctr[x] + (unsigned char)1) & (unsigned char)255;
if (ctr->ctr[x] != (unsigned char)0) {
break;
}
}
}
/* encrypt it */
cipher_descriptor[ctr->cipher].ecb_encrypt(ctr->ctr, ctr->pad, &ctr->key);
ctr->padlen = 0;
}
*ct++ = *pt++ ^ ctr->pad[ctr->padlen++];
}
return CRYPT_OK;
}
#endif

View file

@ -1,30 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CTR
int ctr_getiv(unsigned char *IV, unsigned long *len, symmetric_CTR *ctr)
{
_ARGCHK(IV != NULL);
_ARGCHK(len != NULL);
_ARGCHK(ctr != NULL);
if ((unsigned long)ctr->blocklen > *len) {
return CRYPT_BUFFER_OVERFLOW;
}
XMEMCPY(IV, ctr->ctr, ctr->blocklen);
*len = ctr->blocklen;
return CRYPT_OK;
}
#endif

View file

@ -1,43 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CTR
int ctr_setiv(const unsigned char *IV, unsigned long len, symmetric_CTR *ctr)
{
int err;
_ARGCHK(IV != NULL);
_ARGCHK(ctr != NULL);
/* bad param? */
if ((err = cipher_is_valid(ctr->cipher)) != CRYPT_OK) {
return err;
}
if (len != (unsigned long)ctr->blocklen) {
return CRYPT_INVALID_ARG;
}
/* set IV */
XMEMCPY(ctr->ctr, IV, len);
/* force next block */
ctr->padlen = 0;
cipher_descriptor[ctr->cipher].ecb_encrypt(IV, ctr->pad, &ctr->key);
return CRYPT_OK;
}
#endif

View file

@ -1,46 +0,0 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis
*
* LibTomCrypt is a library that provides various cryptographic
* algorithms in a highly modular and flexible manner.
*
* The library is free for all purposes without any express
* guarantee it works.
*
* Tom St Denis, tomstdenis@iahu.ca, http://libtomcrypt.org
*/
#include "mycrypt.h"
#ifdef CTR
int ctr_start(int cipher, const unsigned char *count, const unsigned char *key, int keylen,
int num_rounds, symmetric_CTR *ctr)
{
int x, err;
_ARGCHK(count != NULL);
_ARGCHK(key != NULL);
_ARGCHK(ctr != NULL);
/* bad param? */
if ((err = cipher_is_valid(cipher)) != CRYPT_OK) {
return err;
}
/* setup cipher */
if ((err = cipher_descriptor[cipher].setup(key, keylen, num_rounds, &ctr->key)) != CRYPT_OK) {
return err;
}
/* copy ctr */
ctr->blocklen = cipher_descriptor[cipher].block_length;
ctr->cipher = cipher;
ctr->padlen = 0;
ctr->mode = 0;
for (x = 0; x < ctr->blocklen; x++) {
ctr->ctr[x] = count[x];
}
cipher_descriptor[ctr->cipher].ecb_encrypt(ctr->ctr, ctr->pad, &ctr->key);
return CRYPT_OK;
}
#endif

81
demos/CMakeLists.txt Normal file
View file

@ -0,0 +1,81 @@
# -----------------------------------------------------------------------------
# Options
# -----------------------------------------------------------------------------
option(INSTALL_DEMOS "Install enabled demos (USEFUL and/or USABLE) and ltc wrapper script" FALSE)
# -----------------------------------------------------------------------------
# Useful demos
#
# Demos that are even somehow useful and could be installed as a system-tool
#
# -----------------------------------------------------------------------------
set(USEFUL_DEMOS hashsum)
list(JOIN USEFUL_DEMOS " " USEFUL_DEMOS_STR)
option(BUILD_USEFUL_DEMOS "Build useful demos (${USEFUL_DEMOS_STR})" FALSE)
if(BUILD_USEFUL_DEMOS)
list(APPEND USABLE_DEMOS_TARGETS ${USEFUL_DEMOS})
endif()
# -----------------------------------------------------------------------------
# Usable demos
#
# Demos that are usable but only rarely make sense to be installed
#
# -----------------------------------------------------------------------------
set(USABLE_DEMOS aesgcm constants crypt der_print_flexi latex-tables openssh-privkey openssl-enc sizes timing)
list(JOIN USABLE_DEMOS " " USABLE_DEMOS_STR)
option(BUILD_USABLE_DEMOS "Build usable demos (${USABLE_DEMOS_STR})" FALSE)
if(BUILD_USABLE_DEMOS)
list(APPEND USABLE_DEMOS_TARGETS ${USABLE_DEMOS})
endif()
# -----------------------------------------------------------------------------
# Test demos
#
# Demos that are used for testing or measuring
#
# -----------------------------------------------------------------------------
set(TEST_DEMOS small tv_gen)
list(JOIN TEST_DEMOS " " TEST_DEMOS_STR)
option(BUILD_TEST_DEMOS "Build test demos (${TEST_DEMOS_STR})" FALSE)
if(BUILD_TEST_DEMOS)
list(APPEND ALL_DEMOS_TARGETS ${TEST_DEMOS})
endif()
# -----------------------------------------------------------------------------
# Generate executables
# -----------------------------------------------------------------------------
# USABLE_DEMOS can get installed, so they're prefixed with `ltc-`
foreach(target ${USABLE_DEMOS_TARGETS})
list(APPEND ALL_DEMOS_INSTALL_TARGETS ltc-${target})
add_executable(ltc-${target} ${CMAKE_CURRENT_SOURCE_DIR}/${target}.c)
target_link_libraries(ltc-${target} PRIVATE ${PROJECT_NAME})
endforeach()
foreach(target ${ALL_DEMOS_TARGETS})
add_executable(${target} ${CMAKE_CURRENT_SOURCE_DIR}/${target}.c)
target_link_libraries(${target} PRIVATE ${PROJECT_NAME})
endforeach()
# -----------------------------------------------------------------------------
# Install targets
# -----------------------------------------------------------------------------
if(INSTALL_DEMOS)
install(
TARGETS ${ALL_DEMOS_INSTALL_TARGETS}
COMPONENT "runtime"
EXPORT ${TARGETS_EXPORT_NAME}
RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}
)
# Also install the `ltc` wrapper script
install(PROGRAMS ${CMAKE_CURRENT_SOURCE_DIR}/ltc DESTINATION ${CMAKE_INSTALL_BINDIR})
endif()

140
demos/aesgcm.c Normal file
View file

@ -0,0 +1,140 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
/**
@file aesgcm.c
AES128-GCM demo - file en-&decryption, Steffen Jaeckel
Uses the format: |ciphertext|tag-16-bytes|
*/
#define _GNU_SOURCE
#include <tomcrypt.h>
#include <stdio.h>
#include <stdint.h>
#include <sys/stat.h>
#include <sys/types.h>
#include <dirent.h>
#include <string.h>
#include <fcntl.h>
#include <unistd.h>
#ifndef LTC_GCM_MODE
int main(void)
{
return -1;
}
#else
#include "gcm-file/gcm_filehandle.c"
#include "gcm-file/gcm_file.c"
static off_t fsize(const char *filename)
{
struct stat st;
if (stat(filename, &st) == 0) return st.st_size;
return -1;
}
#if defined(__linux__) && defined(__GLIBC_PREREQ)
#if __GLIBC_PREREQ(2, 14)
#define HAS_SYNCFS
#endif
#endif
static int mv(const char *old_name, const char *new_name)
{
int fd;
if (rename(old_name, new_name) == -1) return -1;
fd = open(new_name, 0);
if (fd == -1) return -1;
#if !defined(_WIN32)
if (fsync(fd) != 0) goto OUT;
#if defined(HAS_SYNCFS)
syncfs(fd);
#else
sync();
#endif
OUT:
#endif
close(fd);
return 0;
}
static void LTC_NORETURN die(int ret)
{
fprintf(stderr, "Usage: aesgcm <-e|-d> <infile> <outfile> <88|96 char hex-string 'IV | key'>\n");
exit(ret);
}
int main(int argc, char **argv)
{
int ret = 0, err, arg, direction, res, tmp;
size_t keylen;
uint8_t keybuf[48] = {0};
char *out = NULL;
const char *mode, *in_file, *out_file, *key_string;
unsigned long ivlen, key_len;
if (argc < 5) {
if (argc > 1 && strstr(argv[1], "-h"))
die(0);
else
die(__LINE__);
}
arg = 1;
mode = argv[arg++];
in_file = argv[arg++];
out_file = argv[arg++];
key_string = argv[arg++];
if(strcmp(mode, "-d") == 0) direction = GCM_DECRYPT;
else if(strcmp(mode, "-e") == 0) direction = GCM_ENCRYPT;
else die(__LINE__);
if (fsize(in_file) <= 0) die(__LINE__);
keylen = XSTRLEN(key_string);
if (keylen != 88 && keylen != 96) die(__LINE__);
key_len = sizeof(keybuf);
if ((err = base16_decode(key_string, keylen, keybuf, &key_len)) != CRYPT_OK) {
fprintf(stderr, "boooh %s\n", error_to_string(err));
die(__LINE__);
}
register_all_ciphers();
if(asprintf(&out, "%s-XXXXXX", out_file) < 0) die(__LINE__);
if((tmp = mkstemp(out)) == -1) {
ret = __LINE__;
goto cleanup;
}
close(tmp);
ivlen = keylen/2 - 32;
if((err = gcm_file(find_cipher("aes"), &keybuf[ivlen], 32, keybuf, ivlen, NULL, 0, in_file, out, 16, direction, &res)) != CRYPT_OK) {
fprintf(stderr, "boooh %s\n", error_to_string(err));
ret = __LINE__;
goto cleanup;
}
if(res != 1) {
ret = __LINE__;
}
else
{
if (mv(out, out_file) != 0) ret = __LINE__;
}
cleanup:
if(ret != 0) unlink(out);
free(out);
return ret;
}
#endif

76
demos/constants.c Normal file
View file

@ -0,0 +1,76 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
#define _POSIX_C_SOURCE 200809L /* otherwise PATH_MAX + strdup are not defined for build with -std=c99 */
#include "tomcrypt.h"
#include <string.h>
#define basename(path) ( strrchr((path), '/') ? strrchr((path), '/') + 1 : strrchr((path), '\\') ? strrchr((path), '\\') + 1 : (path) )
/**
@file demo_crypt_constants.c
Demo how to get various constants to dynamic languages
like Python
Larry Bugbee, February 2013
*/
static void s_print_line(const char* cmd, const char* desc)
{
printf(" %-16s - %s\n", cmd, desc);
}
int main(int argc, char **argv)
{
if (argc == 1) {
/* given a specific constant name, get and print its value */
char name[] = "CTR_COUNTER_BIG_ENDIAN";
int value;
char *names_list;
unsigned int names_list_len;
if (crypt_get_constant(name, &value) != 0) exit(EXIT_FAILURE);
printf("\n %s is %d \n\n", name, value);
/* get and print the length of the names (and values) list */
if (crypt_list_all_constants(NULL, &names_list_len) != 0) exit(EXIT_FAILURE);
printf(" need to allocate %u bytes \n\n", names_list_len);
/* get and print the names (and values) list */
if ((names_list = malloc(names_list_len)) == NULL) exit(EXIT_FAILURE);
if (crypt_list_all_constants(names_list, &names_list_len) != 0) exit(EXIT_FAILURE);
printf(" supported constants:\n\n%s\n\n", names_list);
free(names_list);
} else if (argc == 2) {
if (strcmp(argv[1], "-h") == 0 || strcmp(argv[1], "--help") == 0) {
char* base = strdup(basename(argv[0]));
printf("Usage: %s [-a] [-s name]\n\n", base);
s_print_line("<no argument>", "The old behavior of the demo");
s_print_line("-a", "Only lists all constants");
s_print_line("-s name", "List a single constant given as argument");
s_print_line("-h", "The help you're looking at");
free(base);
} else if (strcmp(argv[1], "-a") == 0) {
char *names_list;
unsigned int names_list_len;
/* get and print the length of the names (and values) list */
if (crypt_list_all_constants(NULL, &names_list_len) != 0) exit(EXIT_FAILURE);
/* get and print the names (and values) list */
if ((names_list = malloc(names_list_len)) == NULL) exit(EXIT_FAILURE);
if (crypt_list_all_constants(names_list, &names_list_len) != 0) exit(EXIT_FAILURE);
printf("%s\n", names_list);
free(names_list);
}
} else if (argc == 3) {
if (strcmp(argv[1], "-s") == 0) {
int value;
if (crypt_get_constant(argv[2], &value) != 0) exit(EXIT_FAILURE);
printf("%s,%u\n", argv[2], value);
}
}
return 0;
}

View file

@ -1,3 +1,6 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
/* encrypt V1.1 Fri Oct 18 04:28:03 NZDT 2002 */
/* File de/encryption, using libtomcrypt */
/* Written by Daniel Richards <kyhwana@world-net.co.nz> */
@ -7,86 +10,34 @@
/* ie: ./encrypt blowfish story.txt story.ct */
/* ./encrypt -d blowfish story.ct story.pt */
#include <mycrypt.h>
#include <tomcrypt.h>
int errno;
int usage(char *name)
static int LTC_NORETURN die(int status)
{
int x;
printf("Usage: %s [-d](ecrypt) cipher infile outfile\nCiphers:\n", name);
int x, w, tot = 0;
FILE* o = status == EXIT_SUCCESS ? stdout : stderr;
fprintf(o,
"Usage encrypt: crypt <cipher> <infile> <outfile>\n"
"Usage decrypt: crypt -d <cipher> <infile> <outfile>\n"
"Usage test: crypt -t <cipher>\n"
"This help: crypt -h\n\nCiphers:\n\t");
for (x = 0; cipher_descriptor[x].name != NULL; x++) {
printf("%s\n",cipher_descriptor[x].name);
w = fprintf(o, "%-14s",cipher_descriptor[x].name);
if (w < 0) {
status = EXIT_FAILURE;
break;
}
tot += w;
if (tot >= 70) {
fprintf(o, "\n\t");
tot = 0;
}
}
exit(1);
if (tot != 0) fprintf(o, "\n");
exit(status);
}
void register_algs(void)
{
int x;
#ifdef RIJNDAEL
register_cipher (&aes_desc);
#endif
#ifdef BLOWFISH
register_cipher (&blowfish_desc);
#endif
#ifdef XTEA
register_cipher (&xtea_desc);
#endif
#ifdef RC5
register_cipher (&rc5_desc);
#endif
#ifdef RC6
register_cipher (&rc6_desc);
#endif
#ifdef SAFERP
register_cipher (&saferp_desc);
#endif
#ifdef TWOFISH
register_cipher (&twofish_desc);
#endif
#ifdef SAFER
register_cipher (&safer_k64_desc);
register_cipher (&safer_sk64_desc);
register_cipher (&safer_k128_desc);
register_cipher (&safer_sk128_desc);
#endif
#ifdef RC2
register_cipher (&rc2_desc);
#endif
#ifdef DES
register_cipher (&des_desc);
register_cipher (&des3_desc);
#endif
#ifdef CAST5
register_cipher (&cast5_desc);
#endif
#ifdef NOEKEON
register_cipher (&noekeon_desc);
#endif
#ifdef SKIPJACK
register_cipher (&skipjack_desc);
#endif
if (register_hash(&sha256_desc) == -1) {
printf("Error registering SHA256\n");
exit(-1);
}
if (register_prng(&yarrow_desc) == -1) {
printf("Error registering yarrow PRNG\n");
exit(-1);
}
if (register_prng(&sprng_desc) == -1) {
printf("Error registering sprng PRNG\n");
exit(-1);
}
}
int main(int argc, char *argv[])
int main(int argc, char *argv[])
{
unsigned char plaintext[512],ciphertext[512];
unsigned char tmpkey[512], key[MAXBLOCKSIZE], IV[MAXBLOCKSIZE];
@ -97,12 +48,36 @@ int main(int argc, char *argv[])
char *infile, *outfile, *cipher;
prng_state prng;
FILE *fdin, *fdout;
int err;
/* register algs, so they can be printed */
register_algs();
register_all_ciphers();
register_all_hashes();
register_all_prngs();
if (argc < 4) {
return usage(argv[0]);
if ((argc > 2) && (!strcmp(argv[1], "-t"))) {
cipher = argv[2];
cipher_idx = find_cipher(cipher);
if (cipher_idx == -1) {
fprintf(stderr, "Invalid cipher %s entered on command line.\n", cipher);
die(EXIT_FAILURE);
} /* if */
if (cipher_descriptor[cipher_idx].test) {
if (cipher_descriptor[cipher_idx].test() != CRYPT_OK) {
fprintf(stderr, "Error when testing cipher %s.\n", cipher);
die(EXIT_FAILURE);
}
else {
printf("Testing cipher %s succeeded.\n", cipher);
exit(EXIT_SUCCESS);
}
} else {
fprintf(stderr, "Cipher %s has no tests.\n", cipher);
exit(EXIT_SUCCESS);
}
}
return die(argc > 1 && strstr(argv[1], "-h") != NULL ? EXIT_SUCCESS : EXIT_FAILURE);
}
if (!strcmp(argv[1], "-d")) {
@ -115,7 +90,7 @@ int main(int argc, char *argv[])
cipher = argv[1];
infile = argv[2];
outfile = argv[3];
}
}
/* file handles setup */
fdin = fopen(infile,"rb");
@ -125,11 +100,11 @@ int main(int argc, char *argv[])
}
fdout = fopen(outfile,"wb");
if (fdout == NULL) {
if (fdout == NULL) {
perror("Can't open output for writing");
exit(-1);
}
cipher_idx = find_cipher(cipher);
if (cipher_idx == -1) {
printf("Invalid cipher entered on command line.\n");
@ -138,34 +113,35 @@ int main(int argc, char *argv[])
hash_idx = find_hash("sha256");
if (hash_idx == -1) {
printf("SHA256 not found...?\n");
printf("LTC_SHA256 not found...?\n");
exit(-1);
}
ivsize = cipher_descriptor[cipher_idx].block_length;
ks = hash_descriptor[hash_idx].hashsize;
if (cipher_descriptor[cipher_idx].keysize(&ks) != CRYPT_OK) {
if (cipher_descriptor[cipher_idx].keysize(&ks) != CRYPT_OK) {
printf("Invalid keysize???\n");
exit(-1);
}
printf("\nEnter key: ");
fgets((char *)tmpkey,sizeof(tmpkey), stdin);
if(fgets((char *)tmpkey,sizeof(tmpkey), stdin) == NULL)
exit(-1);
outlen = sizeof(key);
if ((errno = hash_memory(hash_idx,tmpkey,strlen((char *)tmpkey),key,&outlen)) != CRYPT_OK) {
printf("Error hashing key: %s\n", error_to_string(errno));
if ((err = hash_memory(hash_idx,tmpkey,XSTRLEN((char *)tmpkey),key,&outlen)) != CRYPT_OK) {
printf("Error hashing key: %s\n", error_to_string(err));
exit(-1);
}
if (decrypt) {
/* Need to read in IV */
if (fread(IV,1,ivsize,fdin) != ivsize) {
printf("Error reading IV from input.\n");
exit(-1);
}
if ((errno = ctr_start(cipher_idx,IV,key,ks,0,&ctr)) != CRYPT_OK) {
printf("ctr_start error: %s\n",error_to_string(errno));
if ((err = ctr_start(cipher_idx,IV,key,ks,0,CTR_COUNTER_LITTLE_ENDIAN,&ctr)) != CRYPT_OK) {
printf("ctr_start error: %s\n",error_to_string(err));
exit(-1);
}
@ -173,8 +149,8 @@ int main(int argc, char *argv[])
do {
y = fread(inbuf,1,sizeof(inbuf),fdin);
if ((errno = ctr_decrypt(inbuf,plaintext,y,&ctr)) != CRYPT_OK) {
printf("ctr_decrypt error: %s\n", error_to_string(errno));
if ((err = ctr_decrypt(inbuf,plaintext,y,&ctr)) != CRYPT_OK) {
printf("ctr_decrypt error: %s\n", error_to_string(err));
exit(-1);
}
@ -188,10 +164,10 @@ int main(int argc, char *argv[])
} else { /* encrypt */
/* Setup yarrow for random bytes for IV */
if ((errno = rng_make_prng(128, find_prng("yarrow"), &prng, NULL)) != CRYPT_OK) {
printf("Error setting up PRNG, %s\n", error_to_string(errno));
}
if ((err = rng_make_prng(128, find_prng("yarrow"), &prng, NULL)) != CRYPT_OK) {
printf("Error setting up PRNG, %s\n", error_to_string(err));
}
/* You can use rng_get_bytes on platforms that support it */
/* x = rng_get_bytes(IV,ivsize,NULL);*/
@ -200,22 +176,22 @@ int main(int argc, char *argv[])
printf("Error reading PRNG for IV required.\n");
exit(-1);
}
if (fwrite(IV,1,ivsize,fdout) != ivsize) {
printf("Error writing IV to output.\n");
exit(-1);
}
if ((errno = ctr_start(cipher_idx,IV,key,ks,0,&ctr)) != CRYPT_OK) {
printf("ctr_start error: %s\n",error_to_string(errno));
if ((err = ctr_start(cipher_idx,IV,key,ks,0,CTR_COUNTER_LITTLE_ENDIAN,&ctr)) != CRYPT_OK) {
printf("ctr_start error: %s\n",error_to_string(err));
exit(-1);
}
do {
y = fread(inbuf,1,sizeof(inbuf),fdin);
if ((errno = ctr_encrypt(inbuf,ciphertext,y,&ctr)) != CRYPT_OK) {
printf("ctr_encrypt error: %s\n", error_to_string(errno));
if ((err = ctr_encrypt(inbuf,ciphertext,y,&ctr)) != CRYPT_OK) {
printf("ctr_encrypt error: %s\n", error_to_string(err));
exit(-1);
}
@ -223,7 +199,7 @@ int main(int argc, char *argv[])
printf("Error writing to output.\n");
exit(-1);
}
} while (y == sizeof(inbuf));
} while (y == sizeof(inbuf));
fclose(fdout);
fclose(fdin);
}

309
demos/demo_dynamic.py Normal file
View file

@ -0,0 +1,309 @@
"""
demo_dynamic.py v2b
This program demonstrates Python's use of the dynamic
language support additions to LTC, namely access to LTC
constants, struct and union sizes, and the binding of a
math package to LTC. Also provided are simple code
fragments to illustrate how one might write a Python
wrapper for LTC and how an app might call the wrapper.
This or a similar model should work for Ruby and other
dynamic languages.
This instance uses Python's ctypes and requires a single
.dylib linking together LTC and a math library. Building
a single .dylib is needed because LTC wants a fairly tight
relationship between itself and the mathlib. (ctypes can
load multiple .dylibs, but it does not support this level
of tight coupling between otherwise independent libraries.)
My .dylib was created on OSX/macOS with the following:
sudo make -j5 -f makefile.shared \
CFLAGS="-DUSE_TFM -DTFM_DESC -I/usr/local/include" \
EXTRALIBS=/usr/local/lib/libtfm.a install
For python 2.7.12 on Ubuntu Xenial the following worked for
me (without MPI support):
sudo make -f makefile.shared install PREFIX="/usr"
Reminder: you don't need to bind in a math library unless
you are going to use LTC functions that need a
mathlib. For example, public key crypto requires
a mathlib; hashing and symmetric encryption do not.
------
This code was originally written for Python 2.7 with the
ctypes standard library. This version is modified to run
under both Python 2.7 and 3.6.
Arguably the biggest change for Python3 has to do with
strings. Under Python2, native strings are ASCII bytes and
passing them to LTC is natural and requires no conversion.
Under Python3 all native strings are Unicode which requires
they be converted to bytes before use by LTC.
Note the following for Python3.
- ASCII keys, IVs and other string arguments must be
'bytes'. Define them with a 'b' prefix or convert
via the 'bytes()' function.
- "strings" returned from LTC are bytes and conversion
to Unicode might be necessary for proper printing.
If so, use <string>.decode('utf-8').
- The Python2 'print' statement becomes a function in
Python3 which requires parenthesis, eg. 'print()'.
NB: Unicode is achieved under Python2 by either defining
a Unicode string with a 'u' prefix or passing ASCII
strings thru the 'unicode()' function.
Larry Bugbee
March 2014 v1
August 2017 v2b
"""
import sys
from ctypes import *
from ctypes.util import find_library
# switches to enable/disable selected output
SHOW_ALL_CONSTANTS = True
SHOW_ALL_SIZES = True
SHOW_SELECTED_CONSTANTS = True
SHOW_SELECTED_SIZES = True
SHOW_BUILD_OPTIONS_ALGS = True
SHOW_SHA256_EXAMPLE = True
SHOW_CHACHA_EXAMPLE = True
print(' ')
print(' demo_dynamic.py')
def inprint(s, indent=0):
"prints strings indented, including multline strings"
for line in s.split('\n'):
print(' '*indent + line)
#-------------------------------------------------------------------------------
# load the .dylib
libname = 'tomcrypt'
libpath = find_library(libname)
print(' ')
print(' path to library %s: %s' % (libname, libpath))
LTC = cdll.LoadLibrary(libpath)
print(' loaded: %s' % LTC)
print(' ')
#-------------------------------------------------------------------------------
# get list of all supported constants followed by a list of all
# supported sizes. One alternative: these lists may be parsed
# and used as needed.
if SHOW_ALL_CONSTANTS:
print('-'*60)
print(' all supported constants and their values:')
# get size to allocate for constants output list
str_len = c_int(0)
ret = LTC.crypt_list_all_constants(None, byref(str_len))
print(' need to allocate %d bytes to build list \n' % str_len.value)
# allocate that size and get (name, size) pairs, each pair
# separated by a newline char.
names_sizes = c_buffer(str_len.value)
ret = LTC.crypt_list_all_constants(names_sizes, byref(str_len))
print(names_sizes.value.decode("utf-8"))
print(' ')
if SHOW_ALL_SIZES:
print('-'*60)
print(' all supported sizes:')
# get size to allocate for sizes output list
str_len = c_int(0)
ret = LTC.crypt_list_all_sizes(None, byref(str_len))
print(' need to allocate %d bytes to build list \n' % str_len.value)
# allocate that size and get (name, size) pairs, each pair
# separated by a newline char.
names_sizes = c_buffer(str_len.value)
ret = LTC.crypt_list_all_sizes(names_sizes, byref(str_len))
print(names_sizes.value.decode("utf-8"))
print(' ')
#-------------------------------------------------------------------------------
# get individually named constants and sizes
if SHOW_SELECTED_CONSTANTS:
print('-'*60)
print('\n selected constants:')
names = [
b'ENDIAN_LITTLE',
b'ENDIAN_64BITWORD',
b'PK_PUBLIC',
b'LTC_MILLER_RABIN_REPS',
b'CTR_COUNTER_BIG_ENDIAN',
]
for name in names:
const_value = c_int(0)
rc = LTC.crypt_get_constant(name, byref(const_value))
value = const_value.value
print(' %-25s %d' % (name.decode("utf-8"), value))
print(' ')
if SHOW_SELECTED_SIZES:
print('-'*60)
print('\n selected sizes:')
names = [
b'rijndael_key',
b'rsa_key',
b'symmetric_CTR',
b'twofish_key',
b'ecc_point',
b'gcm_state',
b'sha512_state',
]
for name in names:
size_value = c_int(0)
rc = LTC.crypt_get_size(name, byref(size_value))
value = size_value.value
print(' %-25s %d' % (name.decode("utf-8"), value))
print(' ')
#-------------------------------------------------------------------------------
#-------------------------------------------------------------------------------
# LibTomCrypt exposes one interesting string that can be accessed
# via Python's ctypes module, "crypt_build_settings", which
# provides a list of this build's compiler switches and supported
# algorithms. If someday LTC exposes other interesting strings,
# they can be found with:
# nm /usr/local/lib/libtomcrypt.dylib | grep " D "
def get_named_string(lib, name):
return c_char_p.in_dll(lib, name).value.decode("utf-8")
if SHOW_BUILD_OPTIONS_ALGS:
print('-'*60)
print('This is a string compiled into LTC showing compile')
print('options and algorithms supported by this build \n')
# print(get_named_string(LTC, 'crypt_build_settings'))
inprint(get_named_string(LTC, 'crypt_build_settings'), 4)
#-------------------------------------------------------------------------------
#-------------------------------------------------------------------------------
# here is an example of how Python code can be written to access
# LTC's implementation of SHA256 and ChaCha,
# - - - - - - - - - - - - -
# definitions
from binascii import hexlify, unhexlify
def _err2str(err):
# define return type
errstr = LTC.error_to_string
errstr.restype = c_char_p
# get and return err string
return errstr(err)
def _get_size(name):
size = c_int(0)
rc = LTC.crypt_get_size(bytes(name), byref(size))
if rc != 0:
raise Exception('LTC.crypt_get_size(%s) rc = %d' % (name, rc))
return size.value
def _get_constant(name):
constant = c_int(0)
rc = LTC.crypt_get_constant(bytes(name), byref(constant))
if rc != 0:
raise Exception('LTC.crypt_get_constant(%s) rc = %d' % (name, rc))
return constant.value
CRYPT_OK = _get_constant(b'CRYPT_OK')
class SHA256(object):
def __init__(self):
self.state = c_buffer(_get_size(b'sha256_state'))
LTC.sha256_init(byref(self.state))
def update(self, data):
LTC.sha256_process(byref(self.state), data, len(data))
def digest(self):
md = c_buffer(32)
LTC.sha256_done(byref(self.state), byref(md))
return md.raw
# - - - - - - - - - - - - -
# a SHA256 app fragment
if SHOW_SHA256_EXAMPLE:
print('-'*60)
data = b'hello world' # we want bytes, not Unicode
sha256 = SHA256()
sha256.update(data)
md = sha256.digest()
template = '\n the SHA256 digest for "%s" is %s \n'
print(template % (data, hexlify(md)))
class ChaCha(object):
def __init__(self, key, rounds):
self.state = c_buffer(_get_size(b'chacha_state'))
self.counter = c_uint(1)
err = LTC.chacha_setup(byref(self.state), key, len(key), rounds)
if err != CRYPT_OK:
raise Exception('LTC.chacha_setup(), err = %d, "%s"' % (err, _err2str(err)))
def set_iv32(self, iv):
err = LTC.chacha_ivctr32(byref(self.state), iv, len(iv), self.counter)
if err != CRYPT_OK:
raise Exception('LTC.chacha_ivctr32(), err = %d, "%s"' % (err, _err2str(err)))
def crypt(self, datain):
dataout = c_buffer(len(datain))
err = LTC.chacha_crypt(byref(self.state), datain, len(datain), byref(dataout))
if err != CRYPT_OK:
raise Exception('LTC.chacha_crypt(), err = %d, "%s"' % (err, _err2str(err)))
return dataout.raw
# - - - - - - - - - - - - -
# a ChaCha app fragment
if SHOW_CHACHA_EXAMPLE:
print('-'*60)
key = b'hownowbrowncow\x00\x00' # exactly 16 or 32 bytes
rounds = 12 # common values: 8, 12, 20
iv = b'123456789012' # exactly 12 bytes
plain = b'Kilroy was here, there, and everywhere!'
cha = ChaCha(key, rounds)
cha.set_iv32(iv)
cipher = cha.crypt(plain)
template = '\n ChaCha%d ciphertext for "%s" is "%s"'
print(template % (rounds, plain, hexlify(cipher)))
cha.set_iv32(iv) # reset to decrypt
decrypted = cha.crypt(cipher)
template = ' ChaCha%d decoded text for "%s" is "%s" \n'
print(template % (rounds, plain, decrypted.decode("utf-8")))
# Footnote: Keys should be erased fm memory as soon as possible after use,
# and that includes Python. For a tip on how to do that in Python, see
# http://buggywhip.blogspot.com/2010/12/erase-keys-and-credit-card-numbers-in.html
#-------------------------------------------------------------------------------
#-------------------------------------------------------------------------------
#-------------------------------------------------------------------------------

327
demos/der_print_flexi.c Normal file
View file

@ -0,0 +1,327 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
/* DER flexi-decode a certificate */
#include "tomcrypt_private.h"
#include <wchar.h>
#define ASN1_FMTSTRING_FMT "line: %d, type=%d, size=%lu, data=%p, self=%p, next=%p, prev=%p, parent=%p, child=%p"
#define ASN1_FMTSTRING_VAL(l) __LINE__, (l)->type, (l)->size, (l)->data, (l), (l)->next, (l)->prev, (l)->parent, (l)->child
static void* s_xmalloc(int l)
{
void *r = XCALLOC(1, l);
#if defined(LTC_TEST_DBG) && LTC_TEST_DBG > 3
fprintf(stderr, "ALLOC %9d to %p\n", l, r);
#endif
if (!r) {
fprintf(stderr, "Could not allocate %d bytes of memory\n", l);
exit(EXIT_FAILURE);
}
return r;
}
#ifndef S_FREE
static void s_free(void *p)
{
#if defined(LTC_TEST_DBG) && LTC_TEST_DBG > 3
fprintf(stderr, "FREE %p\n", p);
#endif
XFREE(p);
}
#endif
static void s_der_print_flexi_i(const ltc_asn1_list* l, unsigned int level)
{
char *buf = NULL;
const char *name = NULL;
const char *text = NULL;
ltc_asn1_list *ostring = NULL;
unsigned int n;
int slen;
const wchar_t *wtmp;
switch (l->type)
{
case LTC_ASN1_EOL:
name = "EOL";
slen = snprintf(NULL, 0, ASN1_FMTSTRING_FMT "\n", ASN1_FMTSTRING_VAL(l));
buf = s_xmalloc(slen);
snprintf(buf, slen, ASN1_FMTSTRING_FMT "\n", ASN1_FMTSTRING_VAL(l));
text = buf;
break;
case LTC_ASN1_BOOLEAN:
name = "BOOLEAN";
{
if (*(int*) l->data)
text = "true";
else
text = "false";
}
break;
case LTC_ASN1_INTEGER:
name = "INTEGER";
buf = s_xmalloc(((ltc_mp_get_digit_count(l->data) + 1) * ltc_mp.bits_per_digit) / 3);
ltc_mp_toradix(l->data, buf, 10);
text = buf;
break;
case LTC_ASN1_SHORT_INTEGER:
name = "SHORT INTEGER";
break;
case LTC_ASN1_BIT_STRING:
name = "BIT STRING";
if (l->size <= 16) {
int r;
int sz = l->size + 1;
char *s = buf = s_xmalloc(sz);
for (n = 0; n < l->size; ++n) {
r = snprintf(s, sz, "%c", ((unsigned char*) l->data)[n] ? '1' : '0');
if (r < 0 || r >= sz) {
fprintf(stderr, "%s boom\n", name);
exit(EXIT_FAILURE);
}
s += r;
sz -= r;
}
} else {
slen = snprintf(NULL, 0, "Length %lu", l->size);
buf = s_xmalloc(slen);
snprintf(buf, slen, "Length %lu", l->size);
}
text = buf;
break;
case LTC_ASN1_OCTET_STRING:
name = "OCTET STRING";
{
unsigned long ostring_l = l->size;
/* sometimes there's another sequence in an octet string...
* try to decode that... if it fails print out the octet string
*/
if (der_decode_sequence_flexi(l->data, &ostring_l, &ostring) == CRYPT_OK) {
text = "";
} else {
int r;
int sz = l->size * 2 + 1;
char *s = buf = s_xmalloc(sz);
for (n = 0; n < l->size; ++n) {
r = snprintf(s, sz, "%02X", ((unsigned char*) l->data)[n]);
if (r < 0 || r >= sz) {
fprintf(stderr, "%s boom\n", name);
exit(EXIT_FAILURE);
}
s += r;
sz -= r;
}
text = buf;
}
}
break;
case LTC_ASN1_NULL:
name = "NULL";
text = "";
break;
case LTC_ASN1_OBJECT_IDENTIFIER:
name = "OBJECT IDENTIFIER";
{
unsigned long len = 0;
if (pk_oid_num_to_str(l->data, l->size, buf, &len) != CRYPT_BUFFER_OVERFLOW) {
fprintf(stderr, "%s WTF\n", name);
exit(EXIT_FAILURE);
}
buf = s_xmalloc(len);
if (pk_oid_num_to_str(l->data, l->size, buf, &len) != CRYPT_OK) {
fprintf(stderr, "%s boom\n", name);
exit(EXIT_FAILURE);
}
text = buf;
}
break;
case LTC_ASN1_IA5_STRING:
name = "IA5 STRING";
text = l->data;
break;
case LTC_ASN1_PRINTABLE_STRING:
name = "PRINTABLE STRING";
text = l->data;
break;
case LTC_ASN1_UTF8_STRING:
name = "UTF8 STRING";
wtmp = l->data;
slen = wcsrtombs(NULL, &wtmp, 0, NULL);
if (slen != -1) {
slen++;
buf = s_xmalloc(slen);
if (wcsrtombs(buf, &wtmp, slen, NULL) == (size_t)-1) {
fprintf(stderr, "%s boom\n", name);
exit(EXIT_FAILURE);
}
text = buf;
}
break;
case LTC_ASN1_UTCTIME:
name = "UTCTIME";
{
ltc_utctime *ut = l->data;
slen = 32;
buf = s_xmalloc(slen);
snprintf(buf, slen, "%02d-%02d-%02d %02d:%02d:%02d %c%02d:%02d", ut->YY, ut->MM, ut->DD, ut->hh, ut->mm,
ut->ss, ut->off_dir ? '-' : '+', ut->off_hh, ut->off_mm);
text = buf;
}
break;
case LTC_ASN1_GENERALIZEDTIME:
name = "GENERALIZED TIME";
{
ltc_generalizedtime *gt = l->data;
slen = 32;
buf = s_xmalloc(slen);
if (gt->fs)
snprintf(buf, slen, "%04d-%02d-%02d %02d:%02d:%02d.%02dZ", gt->YYYY, gt->MM, gt->DD, gt->hh, gt->mm,
gt->ss, gt->fs);
else
snprintf(buf, slen, "%04d-%02d-%02d %02d:%02d:%02dZ", gt->YYYY, gt->MM, gt->DD, gt->hh, gt->mm, gt->ss);
text = buf;
}
break;
case LTC_ASN1_CHOICE:
name = "CHOICE";
break;
case LTC_ASN1_SEQUENCE:
name = "SEQUENCE";
text = "";
break;
case LTC_ASN1_SET:
name = "SET";
text = "";
break;
case LTC_ASN1_SETOF:
name = "SETOF";
text = "";
break;
case LTC_ASN1_RAW_BIT_STRING:
name = "RAW BIT STRING";
break;
case LTC_ASN1_TELETEX_STRING:
name = "TELETEX STRING";
text = l->data;
break;
case LTC_ASN1_CUSTOM_TYPE:
name = "NON STANDARD";
{
int r;
int sz = 128;
char *s = buf = s_xmalloc(sz);
r = snprintf(s, sz, "[%s %s %llu]", der_asn1_class_to_string_map[l->klass],
der_asn1_pc_to_string_map[l->pc], l->tag);
if (r < 0 || r >= sz) {
fprintf(stderr, "%s boom\n", name);
exit(EXIT_FAILURE);
}
text = buf;
}
break;
}
for (n = 0; n < level; ++n) {
fprintf(stderr, " ");
}
if (name) {
if (text)
fprintf(stderr, "%s %s\n", name, text);
else
fprintf(stderr, "%s <missing decoding>\n", name);
} else
fprintf(stderr, "WTF type=%i\n", l->type);
if (buf) {
s_free(buf);
buf = NULL;
}
if (ostring) {
s_der_print_flexi_i(ostring, level + 1);
der_free_sequence_flexi(ostring);
}
if (l->child) s_der_print_flexi_i(l->child, level + 1);
if (l->next) s_der_print_flexi_i(l->next, level);
}
#ifndef LTC_DER_PRINT_FLEXI_NO_MAIN
static void s_der_print_flexi(const ltc_asn1_list* l)
{
fprintf(stderr, "\n\n");
s_der_print_flexi_i(l, 0);
fprintf(stderr, "\n\n");
}
#include <sys/mman.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
static int fd;
static ltc_asn1_list *l;
static void print_err(const char *fmt, ...)
{
va_list args;
va_start(args, fmt);
vfprintf(stderr, fmt, args);
va_end(args);
}
static void die_(int err, int line)
{
print_err("%3d: LTC sez %s\n", line, error_to_string(err));
der_free_sequence_flexi(l);
close(fd);
exit(EXIT_FAILURE);
}
#define die(i) do { die_(i, __LINE__); } while(0)
#define DIE(s, ...) do { print_err("%3d: " s "\n", __LINE__, ##__VA_ARGS__); exit(EXIT_FAILURE); } while(0)
int main(int argc, char **argv)
{
void *addr;
int err, argn = 1;
struct stat sb;
unsigned long len;
if ((err = register_all_hashes()) != CRYPT_OK) {
die(err);
}
if ((err = crypt_mp_init("ltm")) != CRYPT_OK) {
die(err);
}
if (argc > argn) fd = open(argv[argn], O_RDONLY);
else fd = STDIN_FILENO;
if (fd == -1) DIE("open sez no");
if (fstat(fd, &sb) == -1) DIE("fstat");
addr = mmap(NULL, sb.st_size, PROT_READ, MAP_PRIVATE, fd, 0);
if (addr == MAP_FAILED) DIE("mmap");
len = sb.st_size;
if ((err = der_decode_sequence_flexi(addr, &len, &l)) != CRYPT_OK) {
die(err);
}
s_der_print_flexi(l);
der_free_sequence_flexi(l);
close(fd);
return 0;
}
#endif /* LTC_DER_PRINT_FLEXI_NO_MAIN */

84
demos/gcm-file/gcm_file.c Normal file
View file

@ -0,0 +1,84 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
#include "tomcrypt.h"
/**
@file gcm_file.c
GCM process a file, Steffen Jaeckel
*/
#ifdef LTC_GCM_MODE
#ifndef LTC_NO_FILE
/**
Process a file.
c.f. gcm_filehandle() for basic documentation.
It is possible, that in error-cases the 'out' file
will be created and after the error occurred it will
be removed again.
@param cipher Index of cipher to use
@param key The secret key
@param keylen The length of the secret key
@param IV The initial vector
@param IVlen The length of the initial vector
@param adata The additional authentication data (header)
@param adatalen The length of the adata
@param in The input file
@param out The output file
@param taglen The MAC tag length
@param direction Encrypt or Decrypt mode (GCM_ENCRYPT or GCM_DECRYPT)
@param res [out] Result of the operation, 1==valid, 0==invalid
@return CRYPT_OK on success
*/
static int gcm_file(int cipher,
const unsigned char *key, unsigned long keylen,
const unsigned char *IV, unsigned long IVlen,
const unsigned char *adata, unsigned long adatalen,
const char *in,
const char *out,
unsigned long taglen,
int direction,
int *res)
{
int err;
FILE *f_in = NULL, *f_out = NULL;
LTC_ARGCHK(in != NULL);
LTC_ARGCHK(out != NULL);
LTC_ARGCHK(res != NULL);
*res = 0;
f_in = fopen(in, "rb");
if (f_in == NULL) {
err = CRYPT_FILE_NOTFOUND;
goto LBL_ERR;
}
f_out = fopen(out, "w+b");
if (f_out == NULL) {
err = CRYPT_FILE_NOTFOUND;
goto LBL_ERR;
}
err = gcm_filehandle(cipher, key, keylen, IV, IVlen, adata, adatalen, f_in, f_out, taglen, direction, res);
LBL_ERR:
if (f_out != NULL && fclose(f_out) != 0) {
err = CRYPT_ERROR;
}
if (*res != 1) {
remove(out);
}
if (f_in != NULL && fclose(f_in) != 0) {
err = CRYPT_ERROR;
}
return err;
}
#endif
#endif

View file

@ -0,0 +1,194 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
#include "tomcrypt.h"
/**
@file gcm_filehandle.c
GCM process a filehandle, Steffen Jaeckel
*/
#ifdef LTC_GCM_MODE
#ifndef LTC_NO_FILE
#if defined(_MSC_VER)
#define ftruncate _chsize
#else
#include <unistd.h>
#endif
/**
Process a filehandle.
This uses the widely established scheme where the tag is appended
to the ciphertext.
encrypted_file = aesgcm(plain_file) | aesgcm_tag(plain_file)
Depending on 'direction' this function does:
Encrypt file 'in' to 'out' and append the tag of length 'taglen'
to 'out'.
or
Decrypt file 'in' to 'out' and check the tag of length 'taglen'
and strip the tag from 'in'.
In error-cases 'out' will be zeroed out first and then truncated to
a length of 0.
@param cipher Index of cipher to use
@param key The secret key
@param keylen The length of the secret key
@param IV The initial vector
@param IVlen The length of the initial vector
@param adata The additional authentication data (header)
@param adatalen The length of the adata
@param in The input file
@param out The output file
@param taglen The MAC tag length
@param direction Encrypt or Decrypt mode (GCM_ENCRYPT or GCM_DECRYPT)
@param res [out] Result of the operation, 1==valid, 0==invalid
@return CRYPT_OK on success
*/
static int gcm_filehandle(int cipher,
const unsigned char *key, unsigned long keylen,
const unsigned char *IV, unsigned long IVlen,
const unsigned char *adata, unsigned long adatalen,
FILE *in,
FILE *out,
unsigned long taglen,
int direction,
int *res)
{
void *orig;
gcm_state *gcm;
int err;
unsigned char *buf, tag[16];
size_t x, tot_data;
unsigned long tag_len;
LTC_ARGCHK(in != NULL);
LTC_ARGCHK(out != NULL);
LTC_ARGCHK(res != NULL);
*res = 0;
if ((err = cipher_is_valid(cipher)) != CRYPT_OK) {
return err;
}
#ifndef LTC_GCM_TABLES_SSE2
orig = gcm = XMALLOC(sizeof(*gcm));
#else
orig = gcm = XMALLOC(sizeof(*gcm) + 16);
#endif
if (gcm == NULL) {
return CRYPT_MEM;
}
if ((buf = XMALLOC(LTC_FILE_READ_BUFSIZE)) == NULL) {
XFREE(gcm);
return CRYPT_MEM;
}
/* Force GCM to be on a multiple of 16 so we can use 128-bit aligned operations
* note that we only modify gcm and keep orig intact. This code is not portable
* but again it's only for SSE2 anyways, so who cares?
*/
#ifdef LTC_GCM_TABLES_SSE2
gcm = LTC_ALIGN_BUF(gcm, 16);
#endif
if ((err = gcm_init(gcm, cipher, key, keylen)) != CRYPT_OK) {
goto LBL_ERR;
}
if ((err = gcm_add_iv(gcm, IV, IVlen)) != CRYPT_OK) {
goto LBL_ERR;
}
if ((err = gcm_add_aad(gcm, adata, adatalen)) != CRYPT_OK) {
goto LBL_ERR;
}
fseek(in, 0, SEEK_END);
tot_data = ftell(in);
if (direction == GCM_DECRYPT) {
tot_data -= taglen;
}
fseek(in, 0, SEEK_SET);
do {
x = MIN(tot_data, LTC_FILE_READ_BUFSIZE);
x = fread(buf, 1, x, in);
tot_data -= x;
if ((err = gcm_process(gcm, buf, (unsigned long)x, buf, direction)) != CRYPT_OK) {
goto LBL_CLEANBUF;
}
if(fwrite(buf, 1, x, out) != x) {
err = CRYPT_ERROR;
goto LBL_CLEANBUF;
}
} while (x == LTC_FILE_READ_BUFSIZE);
tag_len = taglen;
if ((err = gcm_done(gcm, tag, &tag_len)) != CRYPT_OK) {
goto LBL_CLEANBUF;
}
if (tag_len != taglen) {
err = CRYPT_ERROR;
goto LBL_CLEANBUF;
}
if (direction == GCM_DECRYPT) {
if (feof(in) || ferror(in)) {
err = CRYPT_ERROR;
goto LBL_CLEANBUF;
}
x = fread(buf, 1, taglen, in);
if (x != taglen) {
err = CRYPT_ERROR;
goto LBL_CLEANBUF;
}
if (XMEM_NEQ(buf, tag, taglen) == 0) {
*res = 1;
}
} else {
if(fwrite(tag, 1, taglen, out) != taglen) {
err = CRYPT_ERROR;
goto LBL_CLEANBUF;
}
*res = 1;
}
LBL_CLEANBUF:
zeromem(buf, LTC_FILE_READ_BUFSIZE);
zeromem(tag, sizeof(tag));
LBL_ERR:
#ifdef LTC_CLEAN_STACK
#ifndef LTC_GCM_TABLES_SSE2
zeromem(orig, sizeof(*gcm));
#else
zeromem(orig, sizeof(*gcm) + 16);
#endif
#endif
if(*res == 0) {
x = ftell(out);
fseek(in, 0, SEEK_SET);
while((size_t)ftell(out) < x) {
fwrite(buf, 1, LTC_FILE_READ_BUFSIZE, out);
}
if(ftruncate(fileno(out), 0)) {
/* well, what shall we do here... */
}
}
fflush(out);
XFREE(buf);
XFREE(orig);
return err;
}
#endif
#endif

View file

@ -1,3 +1,6 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
/*
* Written by Daniel Richards <kyhwana@world-net.co.nz> 6/7/2002
* hash.c: This app uses libtomcrypt to hash either stdin or a file
@ -7,100 +10,288 @@
* more functions ;)
*/
#include <mycrypt_custom.h>
#define _POSIX_C_SOURCE 200809L /* otherwise PATH_MAX + strdup are not defined for build with -std=c99 */
#include <tomcrypt.h>
int errno;
#include <string.h>
#define basename(path) ( strrchr((path), '/') ? strrchr((path), '/') + 1 : strrchr((path), '\\') ? strrchr((path), '\\') + 1 : (path) )
void register_algs();
#if !defined(PATH_MAX) && defined(_MSC_VER)
#include <windows.h>
#define PATH_MAX MAX_PATH
#endif
/* thanks http://stackoverflow.com/a/8198009 */
#define s_base(x) ((x >= '0' && x <= '9') ? '0' : \
(x >= 'a' && x <= 'f') ? 'a' - 10 : \
(x >= 'A' && x <= 'F') ? 'A' - 10 : \
'\255')
#define HEXOF(x) (x - s_base(x))
#ifndef LTC_ARRAY_SIZE
#define LTC_ARRAY_SIZE(arr) (sizeof(arr)/sizeof(arr[0]))
#endif
static char* hashsum;
static void cleanup(void)
{
free(hashsum);
}
static void die(int status)
{
unsigned long w, x;
FILE* o = status == EXIT_SUCCESS ? stdout : stderr;
fprintf(o,
"Usage: %s [-a <algorithm>...] [-c|-h] [<file>...]\n\n"
"\t-c\tCheck the hash(es) of the file(s) written in <file>.\n"
"\t\tNote: -a is not required when checking the hash(es).\n"
"\t-h\tThis help\n\n"
"Examples:\n"
"\t%s -a sha1 file > file.sha1sum\n"
"\t%s -c file.sha1sum\n"
"\t%s -a sha1 -a sha256 -a sha512-256 file > file.hashsum\n"
"\t%s -c file.hashsum\n\n"
"Algorithms:\n\t", hashsum, hashsum, hashsum, hashsum, hashsum);
w = 0;
for (x = 0; hash_descriptor[x].name != NULL; x++) {
w += fprintf(o, "%-14s", hash_descriptor[x].name);
if (w >= 70) {
fprintf(o, "\n\t");
w = 0;
}
}
if (w != 0) fprintf(o, "\n");
exit(status);
}
static void printf_hex(unsigned char* hash_buffer, unsigned long w)
{
unsigned long x;
for (x = 0; x < w; x++) {
printf("%02x",hash_buffer[x]);
}
}
static void check_file(int argn, int argc, char **argv)
{
int err, failed = 0, invalid = 0;
unsigned char is_buffer[MAXBLOCKSIZE], should_buffer[MAXBLOCKSIZE];
char buf[PATH_MAX + (MAXBLOCKSIZE * 3)];
/* iterate through all files */
while(argn < argc) {
char* s;
FILE* f = fopen(argv[argn], "rb");
if(f == NULL) {
int n = snprintf(buf, sizeof(buf), "%s: %s", hashsum, argv[argn]);
if (n > 0 && n < (int)sizeof(buf))
perror(buf);
else
perror(argv[argn]);
exit(EXIT_FAILURE);
}
/* read the file line by line */
while((s = fgets(buf, sizeof(buf), f)) != NULL)
{
int tries, n;
unsigned long hash_len, w, x;
char* space = strstr(s, " ");
/* skip lines with comments */
if (buf[0] == '#') continue;
if (space == NULL) {
fprintf(stderr, "%s: no properly formatted checksum lines found\n", hashsum);
goto ERR;
}
hash_len = space - s;
hash_len /= 2;
if (hash_len > sizeof(should_buffer)) {
fprintf(stderr, "%s: hash too long\n", hashsum);
goto ERR;
}
/* convert the hex-string back to binary */
for (x = 0; x < hash_len; ++x) {
should_buffer[x] = HEXOF(s[x*2]) << 4 | HEXOF(s[x*2 + 1]);
}
space++;
if (*space != '*') {
fprintf(stderr, "%s: unsupported input mode '%c'\n", hashsum, *space);
goto ERR;
}
space++;
for (n = 0; n < (buf + sizeof(buf)) - space; ++n) {
if(iscntrl((int)space[n])) {
space[n] = '\0';
break;
}
}
/* try all hash algorithms that have the appropriate hash size */
tries = 0;
for (x = 0; hash_descriptor[x].name != NULL; ++x) {
if (hash_descriptor[x].hashsize == hash_len) {
tries++;
w = sizeof(is_buffer);
if ((err = hash_file(x, space, is_buffer, &w)) != CRYPT_OK) {
fprintf(stderr, "%s: File hash error: %s: %s\n", hashsum, space, error_to_string(err));
ERR:
fclose(f);
exit(EXIT_FAILURE);
}
if(XMEMCMP(should_buffer, is_buffer, w) == 0) {
printf("%s: OK\n", space);
break;
}
}
} /* for */
if (hash_descriptor[x].name == NULL) {
if(tries > 0) {
printf("%s: FAILED\n", space);
failed++;
}
else {
invalid++;
}
}
} /* while */
fclose(f);
if(invalid) {
fprintf(stderr, "%s: WARNING: %d %s is improperly formatted\n", hashsum, invalid, invalid > 1?"lines":"line");
}
if(failed) {
fprintf(stderr, "%s: WARNING: %d computed %s did NOT match\n", hashsum, failed, failed > 1?"checksums":"checksum");
}
argn++;
}
exit(failed == 0 && invalid == 0 ? EXIT_SUCCESS : EXIT_FAILURE);
}
int main(int argc, char **argv)
{
int idx, x, z;
unsigned long w;
int idxs[TAB_SIZE], idx, check, y, z, err, argn;
unsigned long w, x;
unsigned char hash_buffer[MAXBLOCKSIZE];
hash_state md;
hashsum = strdup(basename(argv[0]));
atexit(cleanup);
/* You need to register algorithms before using them */
register_algs();
if (argc < 2) {
printf("usage: ./hash algorithm file [file ...]\n");
printf("Algorithms:\n");
for (x = 0; hash_descriptor[x].name != NULL; x++) {
printf(" %s\n", hash_descriptor[x].name);
}
exit(EXIT_SUCCESS);
register_all_ciphers();
register_all_hashes();
if (argc > 1 && strstr(argv[1], "-h")) {
die(EXIT_SUCCESS);
}
if (argc < 3) {
die(EXIT_FAILURE);
}
idx = find_hash(argv[1]);
if (idx == -1) {
fprintf(stderr, "\nInvalid hash specified on command line.\n");
return -1;
for (x = 0; x < LTC_ARRAY_SIZE(idxs); ++x) {
idxs[x] = -2;
}
argn = 1;
check = 0;
idx = 0;
while(argn < argc){
if(strcmp("-a", argv[argn]) == 0) {
argn++;
if(argn < argc) {
idxs[idx] = find_hash(argv[argn]);
if (idxs[idx] == -1) {
struct {
const char* is;
const char* should;
} shasum_compat[] =
{
#ifdef LTC_SHA1
{ "1", sha1_desc.name },
#endif
#ifdef LTC_SHA224
{ "224", sha224_desc.name },
#endif
#ifdef LTC_SHA256
{ "256", sha256_desc.name },
#endif
#ifdef LTC_SHA384
{ "384", sha384_desc.name },
#endif
#ifdef LTC_SHA512
{ "512", sha512_desc.name },
#endif
#ifdef LTC_SHA512_224
{ "512224", sha512_224_desc.name },
#endif
#ifdef LTC_SHA512_256
{ "512256", sha512_256_desc.name },
#endif
{ NULL, NULL }
};
for (x = 0; shasum_compat[x].is != NULL; ++x) {
if(XSTRCMP(shasum_compat[x].is, argv[argn]) == 0) {
idxs[idx] = find_hash(shasum_compat[x].should);
break;
}
}
}
if (idxs[idx] == -1) {
fprintf(stderr, "%s: Unrecognized algorithm\n", hashsum);
die(EXIT_FAILURE);
}
idx++;
if ((size_t)idx >= LTC_ARRAY_SIZE(idxs)) {
fprintf(stderr, "%s: Too many '-a' options chosen\n", hashsum);
die(EXIT_FAILURE);
}
argn++;
continue;
}
else {
die(EXIT_FAILURE);
}
}
if(strcmp("-c", argv[argn]) == 0) {
check = 1;
argn++;
continue;
}
break;
}
if (argc == 2) {
hash_descriptor[idx].init(&md);
do {
x = fread(hash_buffer, 1, sizeof(hash_buffer), stdin);
hash_descriptor[idx].process(&md, hash_buffer, x);
} while (x == sizeof(hash_buffer));
hash_descriptor[idx].done(&md, hash_buffer);
for (x = 0; x < (int)hash_descriptor[idx].hashsize; x++) {
printf("%02x",hash_buffer[x]);
if (check == 1) {
check_file(argn, argc, argv);
}
if (argc == argn) {
w = sizeof(hash_buffer);
if ((err = hash_filehandle(idxs[0], stdin, hash_buffer, &w)) != CRYPT_OK) {
fprintf(stderr, "%s: File hash error: %s\n", hashsum, error_to_string(err));
return EXIT_FAILURE;
} else {
for (x = 0; x < w; x++) {
printf("%02x",hash_buffer[x]);
}
printf(" *-\n");
}
printf(" (stdin)\n");
} else {
for (z = 2; z < argc; z++) {
w = sizeof(hash_buffer);
if ((errno = hash_file(idx,argv[z],hash_buffer,&w)) != CRYPT_OK) {
printf("File hash error: %s\n", error_to_string(errno));
} else {
for (x = 0; x < (int)hash_descriptor[idx].hashsize; x++) {
printf("%02x",hash_buffer[x]);
}
printf(" %s\n", argv[z]);
for (z = argn; z < argc; z++) {
for (y = 0; y < idx; ++y) {
w = sizeof(hash_buffer);
if ((err = hash_file(idxs[y],argv[z],hash_buffer,&w)) != CRYPT_OK) {
fprintf(stderr, "%s: File hash error: %s\n", hashsum, error_to_string(err));
return EXIT_FAILURE;
} else {
printf_hex(hash_buffer, w);
printf(" *%s\n", argv[z]);
}
}
}
}
return EXIT_SUCCESS;
}
void register_algs(void)
{
#ifdef TIGER
register_hash (&tiger_desc);
#endif
#ifdef MD2
register_hash (&md2_desc);
#endif
#ifdef MD4
register_hash (&md4_desc);
#endif
#ifdef MD5
register_hash (&md5_desc);
#endif
#ifdef SHA1
register_hash (&sha1_desc);
#endif
#ifdef SHA224
register_hash (&sha224_desc);
#endif
#ifdef SHA256
register_hash (&sha256_desc);
#endif
#ifdef SHA384
register_hash (&sha384_desc);
#endif
#ifdef SHA512
register_hash (&sha512_desc);
#endif
#ifdef RIPEMD128
register_hash (&rmd128_desc);
#endif
#ifdef RIPEMD160
register_hash (&rmd160_desc);
#endif
#ifdef WHIRLPOOL
register_hash (&whirlpool_desc);
#endif
}

349
demos/latex-tables.c Normal file
View file

@ -0,0 +1,349 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
/* print all PEM related infos */
#include "tomcrypt_private.h"
#if defined(LTC_PEM_SSH)
static const struct {
const char *is, *should;
} cipher_name_map[] = {
{ "", "none" },
{ "aes", "AES" },
{ "aria", "ARIA" },
{ "blowfish", "Blowfish" },
{ "c20p1305", "ChaCha20Poly1305" },
{ "camellia", "Camellia" },
{ "cast5", "CAST5" },
{ "chacha20", "ChaCha20" },
{ "3des", "3DES (EDE)" },
{ "des", "DES" },
{ "desx", "DES-X" },
{ "idea", "IDEA" },
{ "rc5", "RC5" },
{ "rc2", "RC2" },
{ "seed", "SEED" },
{ "serpent", "Serpent" },
{ "twofish", "Twofish" },
};
static const char *s_map_cipher(const char *name)
{
unsigned long n;
for (n = 0; n < LTC_ARRAY_SIZE(cipher_name_map); ++n) {
if (strcmp(name, cipher_name_map[n].is) == 0)
return cipher_name_map[n].should;
}
fprintf(stderr, "Error: Can't map %s\n", name);
exit(1);
}
static const struct {
enum cipher_mode mode;
const char *name;
} cipher_mode_map[] = {
{ cm_none, "none", },
{ cm_cbc, "CBC", },
{ cm_cfb, "CFB", },
{ cm_cfb1, "CFB1", },
{ cm_cfb8, "CFB8", },
{ cm_ctr, "CTR", },
{ cm_ofb, "OFB", },
{ cm_stream, "STREAM", },
{ cm_gcm, "GCM", },
};
static const char *s_map_mode(enum cipher_mode mode)
{
size_t n;
mode &= cm_modes | cm_1bit | cm_8bit;
for (n = 0; n < LTC_ARRAY_SIZE(cipher_mode_map); ++n) {
if (cipher_mode_map[n].mode == mode)
return cipher_mode_map[n].name;
}
fprintf(stderr, "Error: Can't map cipher_mode %d\n", mode);
exit(1);
}
static int print_pem_ciphers(void)
{
unsigned long n;
printf("\nPEM ciphers:\n\n");
for (n = 0; n < pem_dek_infos_num; ++n) {
char nbuf[32] = {0};
size_t nlen = strlen(pem_dek_infos[n].name);
memcpy(nbuf, pem_dek_infos[n].name, nlen);
nbuf[nlen-1] = '}';
printf("\\hline \\texttt{%-18s & %-15s & %-25ld & %-6s \\\\\n",
nbuf, s_map_cipher(pem_dek_infos[n].algo),
pem_dek_infos[n].keylen * 8,
s_map_mode(pem_dek_infos[n].mode));
}
return 0;
}
static int print_ssh_ciphers(void)
{
unsigned long n;
printf("\nSSH ciphers:\n\n");
for (n = 0; n < ssh_ciphers_num; ++n) {
char nbuf[32] = {0};
size_t nlen = strlen(ssh_ciphers[n].name);
memcpy(nbuf, ssh_ciphers[n].name, nlen);
nbuf[nlen] = '}';
printf("\\hline \\texttt{%-30s & %-16s & %-24ld & %-6s \\\\\n",
nbuf, s_map_cipher(ssh_ciphers[n].algo),
ssh_ciphers[n].keylen * 8,
s_map_mode(ssh_ciphers[n].mode));
}
return 0;
}
static int s_to_lower(const char *in, char *out, unsigned long *outlen)
{
unsigned long n;
for (n = 0; n < *outlen && in[n]; ++n) {
out[n] = tolower(in[n]);
}
if (n == *outlen)
return CRYPT_BUFFER_OVERFLOW;
out[n] = '\0';
*outlen = n;
return CRYPT_OK;
}
static int print_ecc_curves(void)
{
unsigned long n;
printf("\nECC curves:\n\n");
for (n = 0; ltc_ecc_curves[n].OID != NULL; ++n) {
const char * const *names;
char lower[32] = {0}, buf[64] = {0};
unsigned long m, bufl = 0, lowerl;
int err = ecc_get_curve_names(ltc_ecc_curves[n].OID, &names);
if (err != CRYPT_OK) {
printf("\\error: OID %s not found (%s)\n", ltc_ecc_curves[n].OID, error_to_string(err));
return EXIT_FAILURE;
}
for (m = 1; names[m]; ++m) {
const char *name = names[m];
if (memcmp(name, "P-", 2) == 0 || memcmp(name, "ECC-", 4) == 0) {
/* Use the original name */
} else {
lowerl = sizeof(lower);
if ((err = s_to_lower(name, lower, &lowerl)) != CRYPT_OK) {
printf("\\error: %s could not be converted to lowercase (%s)\n", name, error_to_string(err));
return EXIT_FAILURE;
}
name = lower;
}
if (m == 1) {
err = snprintf(buf + bufl, sizeof(buf) - bufl, "%s", name);
} else {
err = snprintf(buf + bufl, sizeof(buf) - bufl, ", %s", name);
}
if (err == -1 || (unsigned)err > sizeof(buf) - bufl) {
printf("\\error: snprintf returned %d at %s\n", err, name);
return EXIT_FAILURE;
}
bufl += err;
}
lower[0] = '{';
lowerl = sizeof(lower) - 2;
if ((err = s_to_lower(names[0], &lower[1], &lowerl)) != CRYPT_OK) {
printf("\\error: %s could not be converted to lowercase (%s)\n", names[0], error_to_string(err));
return EXIT_FAILURE;
}
lower[lowerl + 1] = '}';
lower[lowerl + 2] = '\0';
printf("\\hline \\texttt%-17s & %-36s & %-21s \\\\\n", lower, buf, ltc_ecc_curves[n].OID);
}
return 0;
}
static int s_to_upper(const char *in, char *out, unsigned long *outlen)
{
unsigned long n;
for (n = 0; n < *outlen && in[n]; ++n) {
out[n] = toupper(in[n]);
}
if (n == *outlen)
return CRYPT_BUFFER_OVERFLOW;
out[n] = '\0';
*outlen = n;
return CRYPT_OK;
}
static int s_to_desc(const char *in, char *out, unsigned long outlen, int has_desc)
{
unsigned long n, m;
if (outlen < 6) goto err_exit;
XMEMCPY(out, "\\code{", 6);
m = 6;
for (n = 0; m < outlen - 1 && in[n]; ++n, ++m) {
if (in[n] == '-' || in[n] == '_') {
out[m++] = '\\';
out[m] = '_';
} else
out[m] = tolower(in[n]);
}
if (outlen <= m) goto err_exit;
if (!has_desc) {
XMEMCPY(&out[m], "\\_desc", 6);
m += 6;
}
out[m++] = '}';
out[m] = '\0';
return CRYPT_OK;
err_exit:
fprintf(stderr, "Error: Can't print descriptor %s\n", in);
exit(1);
}
struct desc {
void *orig;
char desc[64];
};
static int hash_sorter(const void *a, const void *b)
{
const struct ltc_hash_descriptor *A, *B;
A = ((const struct desc*)a)->orig;
B = ((const struct desc*)b)->orig;
if (A->hashsize < B->hashsize) return 1;
if (A->hashsize > B->hashsize) return -1;
if (A->ID < B->ID) return -1;
if (A->ID > B->ID) return 1;
return 0;
}
static void print_hash_line(const char *name, const struct ltc_hash_descriptor *p)
{
char nbuf[32];
unsigned long nlen = sizeof(nbuf);
s_to_upper(p->name, nbuf, &nlen);
printf("\\hline %-17s & %-32s & %lu & %2d \\\\\n", nbuf, name, p->hashsize, p->ID);
}
static int print_hash_descriptors(void)
{
const struct {
const char *name;
const struct ltc_hash_descriptor * desc;
} special_hash_descriptors[] = {
#define HASH_DESC(name) { #name, &name }
HASH_DESC(sha256_portable_desc),
#ifdef LTC_SHA256_X86
HASH_DESC(sha256_x86_desc),
#endif
HASH_DESC(sha224_portable_desc),
#ifdef LTC_SHA224_X86
HASH_DESC(sha224_x86_desc),
#endif
HASH_DESC(sha1_portable_desc),
#ifdef LTC_SHA1_X86
HASH_DESC(sha1_x86_desc),
#endif
HASH_DESC(sha512_portable_desc),
#ifdef LTC_SHA512_X86
HASH_DESC(sha512_x86_desc),
#endif
HASH_DESC(sha384_portable_desc),
#ifdef LTC_SHA384_X86
HASH_DESC(sha384_x86_desc),
#endif
HASH_DESC(sha512_224_portable_desc),
#ifdef LTC_SHA512_224_X86
HASH_DESC(sha512_224_x86_desc),
#endif
HASH_DESC(sha512_256_portable_desc),
#ifdef LTC_SHA512_256_X86
HASH_DESC(sha512_256_x86_desc),
#endif
};
struct desc descs[TAB_SIZE + 1] = {0};
int ids[TAB_SIZE + 1] = {0};
unsigned long n;
printf("\nhash descriptors:\n\n");
register_all_hashes();
for (n = 0; hash_descriptor[n].name != NULL && n < TAB_SIZE; ++n) {
if (hash_descriptor[n].ID > TAB_SIZE) {
printf("Hash descriptor '%s' has invalid ID %d\n", hash_descriptor[n].name, hash_descriptor[n].ID);
return EXIT_FAILURE;
}
if (ids[hash_descriptor[n].ID] != 0) {
printf("Hash descriptor '%s' has duplicate ID %d\n", hash_descriptor[n].name, hash_descriptor[n].ID);
return EXIT_FAILURE;
}
ids[hash_descriptor[n].ID] = 1;
descs[n].orig = &hash_descriptor[n];
s_to_desc(hash_descriptor[n].name, descs[n].desc, sizeof(descs[n].desc), 0);
}
qsort(descs, n, sizeof(struct desc), &hash_sorter);
for (n = 0; hash_descriptor[n].name != NULL && n < TAB_SIZE; ++n) {
print_hash_line(descs[n].desc, descs[n].orig);
}
printf("\nspecial hash descriptors:\n\n");
for (n = 0; n < LTC_ARRAY_SIZE(special_hash_descriptors); ++n) {
char nbuf[64];
unsigned long nlen = sizeof(nbuf);
s_to_desc(special_hash_descriptors[n].name, nbuf, nlen, 1);
print_hash_line(nbuf, special_hash_descriptors[n].desc);
}
return 0;
}
static void LTC_NORETURN die(int status)
{
FILE* o = status == EXIT_SUCCESS ? stdout : stderr;
fprintf(o,
"Usage: latex-tables [<-h|-l|type>]\n\n"
"Generate LaTeX tables from some library internal data.\n\n"
"\ttype\tThe type of table to print.\n"
"\t-l\tList all built-in types that can be printed.\n"
"\t-h\tThe help you're looking at.\n"
);
exit(status);
}
int main(int argc, char **argv)
{
const struct {
const char *name;
int (*printer)(void);
} printers[] = {
#define PRINTER(name) { #name, print_ ## name }
PRINTER(hash_descriptors),
PRINTER(pem_ciphers),
PRINTER(ssh_ciphers),
PRINTER(ecc_curves),
#undef PRINTER
};
int err;
unsigned long n;
if (argc > 1) {
if (strstr(argv[1], "-h"))
die(0);
if (strstr(argv[1], "-l")) {
for (n = 0; n < LTC_ARRAY_SIZE(printers); ++n) {
printf("%s\n", printers[n].name);
}
return 0;
}
}
printf("libtomcrypt latex tables\n");
for (n = 0; n < LTC_ARRAY_SIZE(printers); ++n) {
if (argc > 1 && strstr(printers[n].name, argv[1]) == NULL)
continue;
if ((err = printers[n].printer()) != 0)
return err;
}
return 0;
}
#else
int main(void) { return EXIT_FAILURE; }
#endif

34
demos/ltc Executable file
View file

@ -0,0 +1,34 @@
#!/bin/sh
RELDIR="/$0"
RELDIR="${RELDIR%/*}"
RELDIR="${RELDIR:-.}"
RELDIR="${RELDIR##/}/"
BINDIR=`cd "$RELDIR"; pwd`
err_out() {
err=$1
shift
echo $* >&2
exit $err
}
usage() {
cat >&$(($1 + 1)) << EOF
Available commands are:
`ls -1 $BINDIR/ltc-* | sed "s@$BINDIR/ltc-@ @g"`
help
EOF
exit $1
}
[ $# -gt 0 ] || usage 1
TOOL="$1"
shift
[ "$TOOL" == "help" ] || [ "$TOOL" == "--help" ] || [ "$TOOL" == "-h" ] && usage 0
test -x "$BINDIR/ltc-$TOOL" || err_out 1 "Unknown command: $TOOL"
[ $# -gt 0 ] && "$BINDIR/ltc-$TOOL" "$@" || "$BINDIR/ltc-$TOOL"

131
demos/openssh-privkey.c Normal file
View file

@ -0,0 +1,131 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
/**
@file openssh-privkey.c
OpenSSH Private Key decryption demo, Steffen Jaeckel
*/
#include <tomcrypt.h>
#include <stdarg.h>
#include <termios.h>
#if defined(LTC_PEM_SSH)
static void print_err(const char *fmt, ...)
{
va_list args;
va_start(args, fmt);
vfprintf(stderr, fmt, args);
va_end(args);
}
static void die_(int err, int line)
{
print_err("%3d: LTC sez %s\n", line, error_to_string(err));
exit(EXIT_FAILURE);
}
#define die(i) do { die_(i, __LINE__); } while(0)
#define DIE(s, ...) do { print_err("%3d: " s "\n", __LINE__, ##__VA_ARGS__); exit(EXIT_FAILURE); } while(0)
static char* getpassword(const char *prompt, size_t maxlen)
{
char *wr, *end, *pass = XCALLOC(1, maxlen + 1);
struct termios tio;
tcflag_t c_lflag;
if (pass == NULL)
return NULL;
wr = pass;
end = pass + maxlen;
tcgetattr(0, &tio);
c_lflag = tio.c_lflag;
tio.c_lflag &= ~ECHO;
tcsetattr(0, TCSANOW, &tio);
printf("%s", prompt);
fflush(stdout);
while (pass < end) {
int c = getchar();
if (c == '\r' || c == '\n' || c == -1)
break;
*wr++ = c;
}
tio.c_lflag = c_lflag;
tcsetattr(0, TCSAFLUSH, &tio);
printf("\n");
return pass;
}
static int password_get(void **p, unsigned long *l, void *u)
{
(void)u;
*p = getpassword("Enter passphrase: ", 256);
*l = strlen(*p);
return 0;
}
static void print(ltc_pka_key *k)
{
int err = CRYPT_OK;
unsigned char buf[256];
unsigned long lbuf = sizeof(buf);
char pubkey[256*4/3];
unsigned long lpubkey = sizeof(pubkey);
void *mpint = NULL;
switch (k->id) {
case LTC_PKA_ED25519:
ltc_mp.init(&mpint);
ltc_mp.unsigned_read(mpint, k->u.ed25519.pub, sizeof(k->u.ed25519.pub));
if ((err = ssh_encode_sequence_multi(buf, &lbuf,
LTC_SSHDATA_STRING, "ssh-ed25519", strlen("ssh-ed25519"),
LTC_SSHDATA_MPINT, mpint,
0, NULL)) != CRYPT_OK)
goto errout;
if ((err = base64_encode(buf, lbuf, pubkey, &lpubkey)) != CRYPT_OK)
goto errout;
printf("\rssh-ed25519 %s\n", pubkey);
break;
default:
print_err("Unsupported key type: %d\n", k->id);
break;
}
errout:
if (mpint != NULL)
ltc_mp.deinit(mpint);
if (err != CRYPT_OK)
die(err);
}
int main(int argc, char **argv)
{
int err;
FILE *f = NULL;
ltc_pka_key k;
password_ctx pw_ctx = { .callback = password_get };
if ((err = register_all_ciphers()) != CRYPT_OK) {
die(err);
}
if ((err = register_all_hashes()) != CRYPT_OK) {
die(err);
}
if ((err = crypt_mp_init("ltm")) != CRYPT_OK) {
die(err);
}
if (argc > 1) f = fopen(argv[1], "r");
else f = stdin;
if (f == NULL) DIE("fopen sez no");
if ((err = pem_decode_openssh_filehandle(f, &k, &pw_ctx))) {
die(err);
}
print(&k);
return EXIT_SUCCESS;
}
#else
int main(void) { return EXIT_FAILURE; }
#endif

385
demos/openssl-enc.c Normal file
View file

@ -0,0 +1,385 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
/*
* Demo to do the rough equivalent of:
*
* openssl enc -aes-256-cbc -pass pass:foobar -in infile -out outfile -p
*
* Compilation:
*
* $(CC) -I /path/to/headers -L .../libs \
* -o openssl-enc \
* openssl-enc.c -ltomcrypt
*
* Usage:
*
* ./openssl-enc <enc|dec> infile outfile "passphrase" [salt]
*
* If provided, the salt must be EXACTLY a 16-char hex string.
*
* Demo is an example of:
*
* - (When decrypting) yanking salt out of the OpenSSL "Salted__..." header
* - OpenSSL-compatible key derivation (in OpenSSL's modified PKCS#5v1 approach)
* - Grabbing an Initialization Vector from the key generator
* - Performing simple block encryption using AES
*
* This program is free for all purposes without any express guarantee it
* works. If you really want to see a license here, assume the WTFPL :-)
*
* BJ Black, bblack@barracuda.com, https://wjblack.com
*
* BUGS:
* Passing a password on a command line is a HORRIBLE idea. Don't use
* this program for serious work!
*/
#include <tomcrypt.h>
#include <termios.h>
#if !defined(LTC_RIJNDAEL) || !defined(LTC_CBC_MODE) || !defined(LTC_PKCS_5) || !defined(LTC_RNG_GET_BYTES) || !defined(LTC_MD5)
int main(void)
{
return -1;
}
#else
/* OpenSSL by default only runs one hash round */
#define OPENSSL_ITERATIONS 1
/* Use aes-256-cbc, so 256 bits of key, 128 of IV */
#define KEY_LENGTH (256>>3)
#define IV_LENGTH (128>>3)
/* PKCS#5v1 requires exactly an 8-byte salt */
#define SALT_LENGTH 8
/* The header OpenSSL puts on an encrypted file */
static char salt_header[] = { 'S', 'a', 'l', 't', 'e', 'd', '_', '_' };
#include <errno.h>
#include <stdio.h>
#include <string.h>
/* A simple way to handle the possibility that a block may increase in size
after padding. */
union paddable {
unsigned char unpad[1024];
unsigned char pad[1024+MAXBLOCKSIZE];
};
/*
* Print usage and exit with a bad status (and perror() if any errno).
*
* Input: argv[0] and the error string
* Output: <no return>
* Side Effects: print messages and barf (does exit(3))
*/
static void LTC_NORETURN barf(const char *pname, const char *err)
{
FILE* o = err == NULL ? stdout : stderr;
fprintf(o,
"Usage: %s <enc|dec> infile outfile [passphrase | -] [salt]\n"
"\n"
" The passphrase can either be given at the command line\n"
" or if it's passed as '-' it will be read interactively.\n"
"\n"
" # encrypts infile->outfile, random salt\n"
" %s enc infile outfile pass\n"
"\n"
" # encrypts infile->outfile, salt from cmdline\n"
" %s enc infile outfile pass 0123456789abcdef\n"
"\n"
" # decrypts infile->outfile, pulls salt from infile\n"
" %s dec infile outfile pass\n"
"\n"
" # decrypts infile->outfile, salt specified\n"
" # (don't try to read the salt from infile)\n"
" %s dec infile outfile pass 0123456789abcdef\n"
"\n"
"Application Error: %s\n", pname, pname, pname, pname, pname, err ? err : "None");
if(errno)
perror(
" System Error");
exit(err == NULL ? 0 : -1);
}
/*
* Parse the Salted__[+8 bytes] from an OpenSSL-compatible file header.
*
* Input: file to read from and a to put the salt in (exactly 8 bytes!)
* Output: CRYPT_OK if parsed OK, CRYPT_ERROR if not
* Side Effects: infile's read pointer += 16
*/
static int parse_openssl_header(FILE *in, unsigned char *out)
{
unsigned char tmp[SALT_LENGTH];
if(fread(tmp, 1, sizeof(tmp), in) != sizeof(tmp))
return CRYPT_ERROR;
if(memcmp(tmp, salt_header, sizeof(tmp)))
return CRYPT_ERROR;
if(fread(tmp, 1, sizeof(tmp), in) != sizeof(tmp))
return CRYPT_ERROR;
memcpy(out, tmp, sizeof(tmp));
return CRYPT_OK;
}
/*
* Dump a hexed stream of bytes (convenience func).
*
* Input: buf to read from, length
* Output: none
* Side Effects: bytes printed as a hex blob, no lf at the end
*/
static void dump_bytes(unsigned char *in, unsigned long len)
{
unsigned long idx;
for(idx=0; idx<len; idx++)
printf("%02hhX", *(in+idx));
}
/*
* Pad or unpad a message using PKCS#7 padding.
* Padding will add 1-(blocksize) bytes and unpadding will remove that amount.
* Set is_padding to 1 to pad, 0 to unpad.
*
* Input: paddable buffer, size read, block length of cipher, mode
* Output: number of bytes after padding resp. after unpadding
* Side Effects: none
*/
static size_t s_pkcs7_pad(union paddable *buf, size_t nb, int block_length,
int is_padding)
{
unsigned long length;
if(is_padding) {
length = sizeof(buf->pad);
if (padding_pad(buf->pad, nb, &length, LTC_PAD_PKCS7 | block_length) != CRYPT_OK)
return 0;
return length;
} else {
length = nb;
if (padding_depad(buf->pad, &length, LTC_PAD_PKCS7) != CRYPT_OK)
return 0;
return length;
}
}
/*
* Perform an encrypt/decrypt operation to/from files using AES+CBC+PKCS7 pad.
* Set encrypt to 1 to encrypt, 0 to decrypt.
*
* Input: in/out files, key, iv, and mode
* Output: CRYPT_OK if no error
* Side Effects: bytes slurped from infile, pushed to outfile, fds updated.
*/
static int do_crypt(FILE *infd, FILE *outfd, unsigned char *key, unsigned char *iv,
int encrypt)
{
union paddable inbuf, outbuf;
int cipher, ret;
symmetric_CBC cbc;
size_t nb;
/* Register your cipher! */
cipher = register_cipher(&aes_desc);
if(cipher == -1)
return CRYPT_INVALID_CIPHER;
/* Start a CBC session with cipher/key/val params */
ret = cbc_start(cipher, iv, key, KEY_LENGTH, 0, &cbc);
if( ret != CRYPT_OK )
return -1;
do {
/* Get bytes from the source */
nb = fread(inbuf.unpad, 1, sizeof(inbuf.unpad), infd);
if(!nb)
return encrypt ? CRYPT_OK : CRYPT_ERROR;
/* Barf if we got a read error */
if(ferror(infd))
return CRYPT_ERROR;
if(encrypt) {
/* We're encrypting, so pad first (if at EOF) and then
crypt */
if(feof(infd))
nb = s_pkcs7_pad(&inbuf, nb,
aes_desc.block_length, 1);
ret = cbc_encrypt(inbuf.pad, outbuf.pad, nb, &cbc);
if(ret != CRYPT_OK)
return ret;
} else {
/* We're decrypting, so decrypt and then unpad if at
EOF */
ret = cbc_decrypt(inbuf.unpad, outbuf.unpad, nb, &cbc);
if( ret != CRYPT_OK )
return ret;
if(feof(infd))
nb = s_pkcs7_pad(&outbuf, nb,
aes_desc.block_length, 0);
if(nb == 0)
/* The file didn't decrypt correctly */
return CRYPT_ERROR;
}
/* Push bytes to outfile */
if(fwrite(outbuf.unpad, 1, nb, outfd) != nb)
return CRYPT_ERROR;
} while(!feof(infd));
/* Close up */
cbc_done(&cbc);
return CRYPT_OK;
}
static char* getpassword(const char *prompt, size_t maxlen)
{
char *wr, *end, *pass = XCALLOC(1, maxlen + 1);
struct termios tio;
tcflag_t c_lflag;
if (pass == NULL)
return NULL;
wr = pass;
end = pass + maxlen;
tcgetattr(0, &tio);
c_lflag = tio.c_lflag;
tio.c_lflag &= ~ECHO;
tcsetattr(0, TCSANOW, &tio);
printf("%s", prompt);
fflush(stdout);
while (pass < end) {
int c = getchar();
if (c == '\r' || c == '\n' || c == -1)
break;
*wr++ = c;
}
tio.c_lflag = c_lflag;
tcsetattr(0, TCSAFLUSH, &tio);
printf("\n");
return pass;
}
/* Convenience macro for the various barfable places below */
#define BARF(a) { \
if(password) free(password); \
if(infd) fclose(infd); \
if(outfd) { fclose(outfd); remove(argv[3]); } \
barf(argv[0], a); \
}
/*
* The main routine. Mostly validate cmdline params, open files, run the KDF,
* and do the crypt.
*/
int main(int argc, char *argv[]) {
unsigned char salt[SALT_LENGTH];
FILE *infd = NULL, *outfd = NULL;
int encrypt = -1;
int hash = -1;
int ret;
unsigned char keyiv[KEY_LENGTH + IV_LENGTH];
unsigned long keyivlen = (KEY_LENGTH + IV_LENGTH);
unsigned char *key, *iv;
const void *pass;
char *password = NULL;
unsigned long saltlen = sizeof(salt);
if (argc > 1 && strstr(argv[1], "-h"))
barf(argv[0], NULL);
/* Check proper number of cmdline args */
if(argc < 5 || argc > 6)
BARF("Invalid number of arguments");
/* Check proper mode of operation */
if (!strncmp(argv[1], "enc", 3))
encrypt = 1;
else if(!strncmp(argv[1], "dec", 3))
encrypt = 0;
else
BARF("Bad command name");
/* Check we can open infile/outfile */
infd = fopen(argv[2], "rb");
if(infd == NULL)
BARF("Could not open infile");
outfd = fopen(argv[3], "wb");
if(outfd == NULL)
BARF("Could not open outfile");
/* Get the salt from wherever */
if(argc == 6) {
/* User-provided */
if(base16_decode(argv[5], strlen(argv[5]), salt, &saltlen) != CRYPT_OK)
BARF("Bad user-specified salt");
} else if(encrypt) {
/* Encrypting; get from RNG */
if(rng_get_bytes(salt, sizeof(salt), NULL) != sizeof(salt))
BARF("Not enough random data");
} else {
/* Parse from infile (decrypt only) */
if(parse_openssl_header(infd, salt) != CRYPT_OK)
BARF("Invalid OpenSSL header in infile");
}
/* Fetch the MD5 hasher for PKCS#5 */
hash = register_hash(&md5_desc);
if(hash == -1)
BARF("Could not register MD5 hash");
/* Set things to a sane initial state */
zeromem(keyiv, sizeof(keyiv));
key = keyiv + 0; /* key comes first */
iv = keyiv + KEY_LENGTH; /* iv comes next */
if (argv[4] && strcmp(argv[4], "-")) {
pass = argv[4];
} else {
password = getpassword("Enter password: ", 256);
if (!password)
BARF("Could not get password");
pass = password;
}
/* Run the key derivation from the provided passphrase. This gets us
the key and iv. */
ret = pkcs_5_alg1_openssl(pass, XSTRLEN(pass), salt,
OPENSSL_ITERATIONS, hash, keyiv, &keyivlen );
if(ret != CRYPT_OK)
BARF("Could not derive key/iv from passphrase");
/* Display the salt/key/iv like OpenSSL cmdline does when -p */
printf("salt="); dump_bytes(salt, sizeof(salt)); printf("\n");
printf("key="); dump_bytes(key, KEY_LENGTH); printf("\n");
printf("iv ="); dump_bytes(iv, IV_LENGTH ); printf("\n");
/* If we're encrypting, write the salt header as OpenSSL does */
if(!strncmp(argv[1], "enc", 3)) {
if(fwrite(salt_header, 1, sizeof(salt_header), outfd) !=
sizeof(salt_header) )
BARF("Error writing salt header to outfile");
if(fwrite(salt, 1, sizeof(salt), outfd) != sizeof(salt))
BARF("Error writing salt to outfile");
}
/* At this point, the files are open, the salt has been figured out,
and we're ready to pump data through crypt. */
/* Do the crypt operation */
if(do_crypt(infd, outfd, key, iv, encrypt) != CRYPT_OK)
BARF("Error during crypt operation");
/* Clean up */
if(password) free(password);
fclose(infd); fclose(outfd);
return 0;
}
#endif

70
demos/sizes.c Normal file
View file

@ -0,0 +1,70 @@
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
#define _POSIX_C_SOURCE 200809L /* otherwise PATH_MAX + strdup are not defined for build with -std=c99 */
#include "tomcrypt.h"
#include <string.h>
#define basename(path) ( strrchr((path), '/') ? strrchr((path), '/') + 1 : strrchr((path), '\\') ? strrchr((path), '\\') + 1 : (path) )
/**
@file demo_crypt_sizes.c
Demo how to get various sizes to dynamic languages
like Python - Larry Bugbee, February 2013
*/
static void s_print_line(const char* cmd, const char* desc)
{
printf(" %-16s - %s\n", cmd, desc);
}
int main(int argc, char **argv)
{
if (argc == 1) {
/* given a specific size name, get and print its size */
char name[] = "ltc_hash_descriptor";
unsigned int size;
char *sizes_list;
unsigned int sizes_list_len;
if (crypt_get_size(name, &size) != 0) exit(EXIT_FAILURE);
printf("\n size of '%s' is %u \n\n", name, size);
/* get and print the length of the names (and sizes) list */
if (crypt_list_all_sizes(NULL, &sizes_list_len) != 0) exit(EXIT_FAILURE);
printf(" need to allocate %u bytes \n\n", sizes_list_len);
/* get and print the names (and sizes) list */
if ((sizes_list = malloc(sizes_list_len)) == NULL) exit(EXIT_FAILURE);
if (crypt_list_all_sizes(sizes_list, &sizes_list_len) != 0) exit(EXIT_FAILURE);
printf(" supported sizes:\n\n%s\n\n", sizes_list);
free(sizes_list);
} else if (argc == 2) {
if (strcmp(argv[1], "-h") == 0 || strcmp(argv[1], "--help") == 0) {
char* base = strdup(basename(argv[0]));
printf("Usage: %s [-a] [-s name]\n\n", base);
s_print_line("<no argument>", "The old behavior of the demo");
s_print_line("-a", "Only lists all sizes");
s_print_line("-s name", "List a single size given as argument");
s_print_line("-h", "The help you're looking at");
free(base);
} else if (strcmp(argv[1], "-a") == 0) {
char *sizes_list;
unsigned int sizes_list_len;
/* get and print the length of the names (and sizes) list */
if (crypt_list_all_sizes(NULL, &sizes_list_len) != 0) exit(EXIT_FAILURE);
/* get and print the names (and sizes) list */
if ((sizes_list = malloc(sizes_list_len)) == NULL) exit(EXIT_FAILURE);
if (crypt_list_all_sizes(sizes_list, &sizes_list_len) != 0) exit(EXIT_FAILURE);
printf("%s\n", sizes_list);
free(sizes_list);
}
} else if (argc == 3) {
if (strcmp(argv[1], "-s") == 0) {
unsigned int size;
if (crypt_get_size(argv[2], &size) != 0) exit(EXIT_FAILURE);
printf("%s,%u\n", argv[2], size);
}
}
return 0;
}

View file

@ -1,10 +1,15 @@
// small demo app that just includes a cipher/hash/prng
#include <mycrypt.h>
/* LibTomCrypt, modular cryptographic library -- Tom St Denis */
/* SPDX-License-Identifier: Unlicense */
/* small demo app that just includes a cipher/hash/prng */
#include <tomcrypt.h>
int main(void)
{
#ifdef LTC_RIJNDAEL
#ifdef ENCRYPT_ONLY
register_cipher(&rijndael_enc_desc);
#endif
#endif
register_prng(&yarrow_desc);
register_hash(&sha256_desc);
return 0;

View file

@ -1,356 +0,0 @@
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
%%%% generic configuration file for %%%%
%%%% the ccmalloc memory profiler %%%%
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
%-----------------------------------------------------------------%
% COPY THIS FILE TO '.ccmalloc' in your project or home directory %
%-----------------------------------------------------------------%
##############################################################################
## (C) 1997-2003 Armin Biere, 1998 Johannes Keukelaar
## $Id: ccmalloc.cfg,v 1.6 2003/02/03 08:03:54 biere Exp $
##############################################################################
%%% '%' and '#' are comments !!!!!!!
% This file must be called '.ccmalloc' and is searched for in the
% current directory and in the home directory of the user. If it
% does not exist then the default values mentioned below are used.
% It is also the only available user manual yet ;-) So here is a reading
% hint. First have a look at the short one line descriptions of each option
% ...
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% with 'file' the executable is specified [a.out]
% ----------------------------------------------------------------------
% This should not be necessary for Linux and Solaris because the proc
% file system can be used to find argv[0].
%
% (the rest of this comment only applies to other OS)
%
% For other OS you should use this option unless the executable is
% in the current directory or its name is 'a.out'.
%
% If you do not specify this then ccmalloc tries to find an executable
% in the current directory that matches the running program starting
% with 'a.out'. For this process it must call 'nm' on each executable
% file in the directory which may be time consuming. With this option
% you can speed up this process.
%
% You can also specify absolute or relative path names. This is
% necessary if you do not start your program from the current directory.
% But you can also simply link or name your program to 'a.out'.
%file FILE
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'log' specify the logfile [stderr]
% ----------------------------------------------------------------------
% The default is to use stderr. The argument to 'log' is the name of
% the file you want to write to. It can also be 'stdout' or '-' which
% sets stdout as logfile. If the logfile is stdout or stderr and is
% connected to a terminal then the output is slightly different.
%
% For big programs the logfile can be really big. To reduce the size
% you can use a small chain length (see 'chain-length' below). The other
% possibility is to use compressed logfiles. This can be done by
% specifying a logfile name with a '.gz' (or a '.Z') suffix. This means
% that gnuzip (resp. compress) is used to compress the output.
%log FILE
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'logpid' specify the logfile
% ----------------------------------------------------------------------
% Can be used alternatively to the 'log' command if you want to use
% ccmalloc for debugging parallel applications where several copies of
% the program you are debugging must be run simoultaneously. In this
% case you can not use 'log' because you do not want to write to the same
% log file. Using 'logpid' uses a file name ending with the <pid> of
% the process which means the name is unique even if several copies of
% your program are run simoultaneously.
%
% If you use the compressing suffixes then the <pid> is inserted before
% the suffix (e.g. 'logpid ccmalloc.log.gz' uses 'ccmalloc.log.<pid>.gz'
% as the name for the log file).
%logpid FILE
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'dont-log-chain' skip info about certain chains []
% ----------------------------------------------------------------------
% This command may be repeated any number of times. The argument to this
% command is a comma-separated list of function-or-file-and-line
% specifications. Garbage allocated from a callchain that contains this
% subchain anywhere will _not_ be logged.
%
% The ';'-separated list should not contain any spaces. E.g. not:
%
% main ; foo ; bar
%
% but:
%
% main;foo;bar
%
% A function-or-file-and-line specification is a string followed by an
% optional colon and number, for example: main or main:14 or main.c or
% main.c:15. Note that the string is compared with both the function and the
% file name, if available. If main.c happens to be a function name, that
% will cause a match (for that string at least). Not specifying a line
% number will match any line number. If line number information is not
% available, anything will match! Not specifying a name (e.g. ;;;) will
% match an unknown function name. Not giving any parameters at all, will
% match a chain containing at least one unknown function.
%
% Note that if you say 'dont-log-chain wrapper.c' nothing will be logged.
%dont-log-chain
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'only-log-chain' skip info about other chains []
% ----------------------------------------------------------------------
% The obvious counterpart to dont-log-chain. In this case, only matching
% chains will be reported. Non-matching chains will not be reported.
% Can be repeated any number of times; if the chain matches any of the
% instances, it will be reported.
%only-log-chain
########################################################################
# #
# This is the 'flag' section #
# #
# 'set FLAG' is the same as 'set FLAG 1' #
# #
# The default values are those set below. If 'silent' is disabled #
# then you will find the banner in the log file (or it is listed on #
# stdout or stderr). The banner describes the current settings of all #
# these flags. #
# #
########################################################################
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% with 'only-count' ccmalloc only counts garbage - no call chains [0]
% ----------------------------------------------------------------------
% If only-count is set to one then only one additional pointer for
% each allocated data is used and no call chain is generated. This is
% the fasted and most space efficient mode ccmalloc can operate
% in. In this mode you get at least the size of garbage produced.
%
% Note that 'check-free-space' does not work at all with 'only-count'
% set and over writes ('check-overwrites') are only checked when
% calling free.
%set only-count 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'load-dynlibs' load dynamic linked libraries into gdb [0]
% ----------------------------------------------------------------------
% If your program is linked with dynamic libraries, function and file
% name information is not available for addresses in those libraries,
% unless you set 'load-dynlibs' to 1.
%set load-dynlibs 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'keep-deallocated-data' does not recycle deallocated data [0]
% ----------------------------------------------------------------------
% If you enable keep-deallocated-data then all data deallocated with
% 'free' (or 'delete' in C++) is not given back to the free store
% but stays associated with the call chain of its allocation. This is
% very useful if your program does multiple deallocation of the
% same data.
%set keep-deallocated-data 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'check-overwrites' detect overwrites [0]
% ----------------------------------------------------------------------
% If you want to detect 'off by n bytes' errors you should set
% 'checking-overwrites' to n/4 (on 32-Bit machines).
%
% ccmalloc inserts a boundary above allocated data. This boundary
% consists of 'check-overwrites' words. If your program writes to
% this area then ccmalloc can detect this (see also check-start
% and check-interval). 'ccmalloc' also does checking for overwrites
% at non word boundaries (e.g. strcpy(malloc(strlen("hello")),"hello");)
set check-overwrites 1
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'check-underwrites' detect underwrites [0]
% ----------------------------------------------------------------------
% same with writes below allocated data. You do not have to set this
% option if you only want detect 'off (below) by one' errors because
% ccmalloc keeps a magic value just before the user data.
set check-underwrites 1
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'check-free-space' can be used to find dangling pointers. [0]
% ----------------------------------------------------------------------
% A very serious type of bug is to write on data that has already been
% freed. If this happens the free space management of malloc is in
% trouble and you will perhaps encounter non deterministic behaviour of
% your program. To test this first enable 'keep-deallocated-data' and
% restart your program. If the problem goes away and ccmalloc does not
% report anything then you should *also* enable 'check-free-space'. Now
% ccmalloc checks already deallocated data for corruption.
%
% Note that to perform this check 'keep-deallocated-data' also must
% be enabled and 'only-count' disabled.
set check-free-space 1
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'check-interval' can be used to speed up checks [0]
% ----------------------------------------------------------------------
% If check-overwrite, check-underwrites or check-free-space is set then
% the default is to do 'write checks' when data is deallocated and
% to do 'free space checks' when reporting together with
% 'write checks' for garbage. When you want these checks to be
% performed more often then you should set 'check-interval' to a
% positive number. This number is the interval between the number of
% calls to free or malloc without performing the checks.
%set check-interval 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'check-start' can be used to speed up checks [0]
% ----------------------------------------------------------------------
% The flag 'check-start' delays the start of checks until the given
% number of calls to free and malloc have occured. Together with
% 'check-interval' you can use a binary search to find an aproximation
% when a corruption occured! If you simply set check-interval to 1 and
% check-start to 0 then this will slow done your program too much.
%set check-start 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'silent' disables banner [0]
% ----------------------------------------------------------------------
% If you don't want to see the banner of ccmalloc then set
% 'silent' to 1 (f.e. when logging to stderr)
%set silent
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'file-info' en/disables file and line number information [1]
% ----------------------------------------------------------------------
% If your program was compiled with debugging information (-g) then
% ccmalloc can generate line number and file info for call chains opening
% a pipe to gdb. For very big programs this method is slow. In this case
% you can set 'file-info' to zero and you will only get the function
% names. For SunOS 4.3.1 'nm' does not 'demangle' C++ identifiers
% very well. So gdb is called instead but only if 'file-info' is
% not set to 0.
%set file-info 1
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'continue' if ccmalloc aborts when something weired happened [0]
% ----------------------------------------------------------------------
% If the free function of ccmalloc is called with an argument that does
% not make sense to ccmalloc or that has already been freed then you
% probably want the program to stop at this point. This is also
% the default behaviour. But you can force ccmalloc also to ignore
% this if you set 'continue' to 1. This flag also controls the behaviour
% of ccmalloc when free space is found to be corrupted or a write
% boundary has been overwritten.
%set continue 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'chain-length' is the length of the maximal call chain [0 = infinite]
% ----------------------------------------------------------------------
% You can restrict the length of call chains by setting 'chain-length'
% to a number greater than zero. If 'chain-length' is zero (the default)
% then chains are as long as possible (on a non x86 system only call
% chains with a finite maximal length can be generated). For big
% programs especially if keep-deallocated-data is enabled this can
% reduce the size of the log file from over 100MB to several MB!
%set chain-length 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'print-addresses' of data [0]
% ----------------------------------------------------------------------
% If you want to see the addresses of the allocated data (and
% deallocated data if keep-deallocated-data is set to 1) set
% 'print-addresses' to 1.
%set print-addresses 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'print-on-one-line' shortens log file [0]
% ----------------------------------------------------------------------
% The default is to print function names and file/line number info
% on separate lines. With 'print-on-one-line' set 1 all are printed
% on one line.
%set print-on-one-line 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'additional-line' enlarges readability [1]
% ----------------------------------------------------------------------
% When printing call chains an empty line is printed between to
% call points. Set 'additional-line' to 0 to disable this feature.
%set additional-line 1
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% 'statistics' enables more accurate profiling [0]
% ----------------------------------------------------------------------
% Calculate number of allocations and deallocations and bytes also on
% a per call chain basis. This uses 4 additional pointers for each
% call chain.
set statistics 1
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% set order for sorting of call chains [1] [1]
% ----------------------------------------------------------------------
% When printing the report to the log file the call chains are sorted by
% default with respect to the largest accumulated garbage produced by
% that call chain. This can be changed with setting 'sort-by-wasted'
% to 0. In this case they are sorted by the number of allocated bytes.
% If you want the number of allocations (only possible if 'statistics'
% is enabled) as sorting criteria instead then set 'sort-by-size' to 0.
%set sort-by-wasted 1
%set sort-by-size 1
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% report library chains [0]
% ----------------------------------------------------------------------
% Some external libraries (like libg++) have memory leaks. On some
% systems even a call to printf produces a leak. ccmalloc tries to
% detect this (only heuristically!) and with this flag you can control
% if leaks produced by such library calls are reported.
%
% Since version 0.2.1 some similar effect can be achieved by using
% 'dont-log-chain' with no argument.
%set library-chains 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% print debugging information [X] (compile time dependend)
% ----------------------------------------------------------------------
%set debug X
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% align memory on 8 byte boundary [0] (no effect on SunOS or Solaris)
% ----------------------------------------------------------------------
%set align-8-byte 0
%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%
% only report allocations which ended up being wasted (i.e don't report
% allocations which were completely freed properly. ) [1]
% ----------------------------------------------------------------------
%set only-wasting-alloc 1

View file

@ -1,20 +0,0 @@
#include "test.h"
int base64_test(void)
{
unsigned char in[64], out[256], tmp[64];
unsigned long x, l1, l2;
for (x = 0; x < 64; x++) {
yarrow_read(in, x, &test_yarrow);
l1 = sizeof(out);
DO(base64_encode(in, x, out, &l1));
l2 = sizeof(tmp);
DO(base64_decode(out, l1, tmp, &l2));
if (l2 != x || memcmp(tmp, in, x)) {
printf("base64 failed %lu %lu %lu", x, l1, l2);
return 1;
}
}
return 0;
}

View file

@ -1,20 +0,0 @@
/* test the ciphers and hashes using their built-in self-tests */
#include "test.h"
int cipher_hash_test(void)
{
int x;
/* test ciphers */
for (x = 0; cipher_descriptor[x].name != NULL; x++) {
DO(cipher_descriptor[x].test());
}
/* test hashes */
for (x = 0; hash_descriptor[x].name != NULL; x++) {
DO(hash_descriptor[x].test());
}
return 0;
}

View file

@ -1,87 +0,0 @@
#include "test.h"
int dh_tests (void)
{
unsigned char buf[3][4096];
unsigned long x, y, z;
int stat, stat2;
dh_key usera, userb;
DO(dh_test());
/* make up two keys */
DO(dh_make_key (&test_yarrow, find_prng ("yarrow"), 512, &usera));
DO(dh_make_key (&test_yarrow, find_prng ("yarrow"), 512, &userb));
/* make the shared secret */
x = 4096;
DO(dh_shared_secret (&usera, &userb, buf[0], &x));
y = 4096;
DO(dh_shared_secret (&userb, &usera, buf[1], &y));
if (y != x) {
printf ("DH Shared keys are not same size.\n");
return 1;
}
if (memcmp (buf[0], buf[1], x)) {
printf ("DH Shared keys not same contents.\n");
return 1;
}
/* now export userb */
y = 4096;
DO(dh_export (buf[1], &y, PK_PUBLIC, &userb));
dh_free (&userb);
/* import and make the shared secret again */
DO(dh_import (buf[1], y, &userb));
z = 4096;
DO(dh_shared_secret (&usera, &userb, buf[2], &z));
if (z != x) {
printf ("failed. Size don't match?\n");
return 1;
}
if (memcmp (buf[0], buf[2], x)) {
printf ("Failed. Content didn't match.\n");
return 1;
}
dh_free (&usera);
dh_free (&userb);
/* test encrypt_key */
dh_make_key (&test_yarrow, find_prng ("yarrow"), 512, &usera);
for (x = 0; x < 16; x++) {
buf[0][x] = x;
}
y = sizeof (buf[1]);
DO(dh_encrypt_key (buf[0], 16, buf[1], &y, &test_yarrow, find_prng ("yarrow"), find_hash ("md5"), &usera));
zeromem (buf[0], sizeof (buf[0]));
x = sizeof (buf[0]);
DO(dh_decrypt_key (buf[1], y, buf[0], &x, &usera));
if (x != 16) {
printf ("Failed (length)\n");
return 1;
}
for (x = 0; x < 16; x++)
if (buf[0][x] != x) {
printf ("Failed (contents)\n");
return 1;
}
/* test sign_hash */
for (x = 0; x < 16; x++) {
buf[0][x] = x;
}
x = sizeof (buf[1]);
DO(dh_sign_hash (buf[0], 16, buf[1], &x, &test_yarrow , find_prng ("yarrow"), &usera));
DO(dh_verify_hash (buf[1], x, buf[0], 16, &stat, &usera));
buf[0][0] ^= 1;
DO(dh_verify_hash (buf[1], x, buf[0], 16, &stat2, &usera));
if (!(stat == 1 && stat2 == 0)) {
printf("dh_sign/verify_hash %d %d", stat, stat2);
return 1;
}
dh_free (&usera);
return 0;
}

View file

@ -1,51 +0,0 @@
#include "test.h"
int dsa_test(void)
{
unsigned char msg[16], out[1024], out2[1024];
unsigned long x, y;
int err, stat1, stat2;
dsa_key key, key2;
/* make a random key */
DO(dsa_make_key(&test_yarrow, find_prng("yarrow"), 20, 128, &key));
/* verify it */
DO(dsa_verify_key(&key, &stat1));
if (stat1 == 0) { printf("dsa_verify_key "); return 1; }
/* sign the message */
x = sizeof(out);
DO(dsa_sign_hash(msg, sizeof(msg), out, &x, &test_yarrow, find_prng("yarrow"), &key));
/* verify it once */
DO(dsa_verify_hash(out, x, msg, sizeof(msg), &stat1, &key));
/* Modify and verify again */
msg[0] ^= 1;
DO(dsa_verify_hash(out, x, msg, sizeof(msg), &stat2, &key));
msg[0] ^= 1;
if (!(stat1 == 1 && stat2 == 0)) { printf("dsa_verify %d %d", stat1, stat2); return 1; }
/* test exporting it */
x = sizeof(out2);
DO(dsa_export(out2, &x, PK_PRIVATE, &key));
DO(dsa_import(out2, x, &key2));
/* verify a signature with it */
DO(dsa_verify_hash(out, x, msg, sizeof(msg), &stat1, &key2));
if (stat1 == 0) { printf("dsa_verify (import private) %d ", stat1); return 1; }
dsa_free(&key2);
/* export as public now */
x = sizeof(out2);
DO(dsa_export(out2, &x, PK_PUBLIC, &key));
DO(dsa_import(out2, x, &key2));
/* verify a signature with it */
DO(dsa_verify_hash(out, x, msg, sizeof(msg), &stat1, &key2));
if (stat1 == 0) { printf("dsa_verify (import public) %d ", stat1); return 1; }
dsa_free(&key2);
dsa_free(&key);
return 0;
}

View file

@ -1,89 +0,0 @@
#include "test.h"
int ecc_tests (void)
{
unsigned char buf[4][4096];
unsigned long x, y, z;
int stat, stat2;
ecc_key usera, userb;
DO(ecc_test ());
/* make up two keys */
DO(ecc_make_key (&test_yarrow, find_prng ("yarrow"), 65, &usera));
DO(ecc_make_key (&test_yarrow, find_prng ("yarrow"), 65, &userb));
/* make the shared secret */
x = 4096;
DO(ecc_shared_secret (&usera, &userb, buf[0], &x));
y = 4096;
DO(ecc_shared_secret (&userb, &usera, buf[1], &y));
if (y != x) {
printf ("ecc Shared keys are not same size.");
return 1;
}
if (memcmp (buf[0], buf[1], x)) {
printf ("ecc Shared keys not same contents.");
return 1;
}
/* now export userb */
y = 4096;
DO(ecc_export (buf[1], &y, PK_PUBLIC, &userb));
ecc_free (&userb);
/* import and make the shared secret again */
DO(ecc_import (buf[1], y, &userb));
z = 4096;
DO(ecc_shared_secret (&usera, &userb, buf[2], &z));
if (z != x) {
printf ("failed. Size don't match?");
return 1;
}
if (memcmp (buf[0], buf[2], x)) {
printf ("Failed. Content didn't match.");
return 1;
}
ecc_free (&usera);
ecc_free (&userb);
/* test encrypt_key */
ecc_make_key (&test_yarrow, find_prng ("yarrow"), 65, &usera);
for (x = 0; x < 32; x++) {
buf[0][x] = x;
}
y = sizeof (buf[1]);
DO(ecc_encrypt_key (buf[0], 32, buf[1], &y, &test_yarrow, find_prng ("yarrow"), find_hash ("sha256"), &usera));
zeromem (buf[0], sizeof (buf[0]));
x = sizeof (buf[0]);
DO(ecc_decrypt_key (buf[1], y, buf[0], &x, &usera));
if (x != 32) {
printf ("Failed (length)");
return 1;
}
for (x = 0; x < 32; x++)
if (buf[0][x] != x) {
printf ("Failed (contents)");
return 1;
}
/* test sign_hash */
for (x = 0; x < 16; x++) {
buf[0][x] = x;
}
x = sizeof (buf[1]);
DO(ecc_sign_hash (buf[0], 16, buf[1], &x, &test_yarrow, find_prng ("yarrow"), &usera));
DO(ecc_verify_hash (buf[1], x, buf[0], 16, &stat, &usera));
buf[0][0] ^= 1;
DO(ecc_verify_hash (buf[1], x, buf[0], 16, &stat2, &usera));
if (!(stat == 1 && stat2 == 0)) {
printf("ecc_verify_hash failed");
return 1;
}
ecc_free (&usera);
return 0;
}

View file

@ -1,12 +0,0 @@
/* test pmac/omac/hmac */
#include "test.h"
int mac_test(void)
{
DO(hmac_test());
DO(pmac_test());
DO(omac_test());
DO(eax_test());
DO(ocb_test());
return 0;
}

View file

@ -1,25 +0,0 @@
# make test harness, it is good.
CFLAGS += -Wall -W -Os -I../../ -I./
# add -g3 for ccmalloc debugging
#CFLAGS += -g3
# if you're not debugging
CFLAGS += -fomit-frame-pointer
default: test
OBJECTS=test.o cipher_hash_test.o mac_test.o modes_test.o \
pkcs_1_test.o store_test.o rsa_test.o ecc_test.o dsa_test.c dh_tests.o
#uncomment this to get heap checking [e.g. memory leaks]. Note
#that you *MUST* build libtomcrypt.a with -g3 enabled [and make install it]
#
#
#CCMALLOC = -lccmalloc -ldl
test: $(OBJECTS)
$(CC) $(OBJECTS) -ltomcrypt $(CCMALLOC) -o test
clean:
rm -f test *.o *.obj *.exe *~

View file

@ -1,14 +0,0 @@
# make test harness, it is good.
CFLAGS += -O3 -xN -ip -I../../ -I./
CC=icc
default: test
OBJECTS=test.o cipher_hash_test.o mac_test.o modes_test.o \
pkcs_1_test.o store_test.o rsa_test.o ecc_test.o dsa_test.c dh_tests.o
test: $(OBJECTS)
$(CC) $(OBJECTS) -ltomcrypt -o test
clean:
rm -f test *.o *~

View file

@ -1,14 +0,0 @@
# make test harness, it is good.
CFLAGS = $(CFLAGS) /W3 /Ox -I../../ -I./
default: test.exe
OBJECTS = test.obj cipher_hash_test.obj mac_test.obj modes_test.obj \
pkcs_1_test.obj store_test.obj rsa_test.obj ecc_test.obj dsa_test.c dh_tests.obj
test.exe: $(OBJECTS)
cl $(OBJECTS) tomcrypt.lib advapi32.lib
clean:
rm -f test.exe *.obj *~

View file

@ -1,112 +0,0 @@
/* test CFB/OFB/CBC modes */
#include "test.h"
int modes_test(void)
{
unsigned char pt[64], ct[64], tmp[64], key[16], iv[16], iv2[16];
int x, cipher_idx;
symmetric_CBC cbc;
symmetric_CFB cfb;
symmetric_OFB ofb;
symmetric_CTR ctr;
unsigned long l;
/* make a random pt, key and iv */
yarrow_read(pt, 64, &test_yarrow);
yarrow_read(key, 16, &test_yarrow);
yarrow_read(iv, 16, &test_yarrow);
/* get idx of AES handy */
cipher_idx = find_cipher("aes");
if (cipher_idx == -1) {
printf("test requires AES");
return 1;
}
/* test CBC mode */
/* encode the block */
DO(cbc_start(cipher_idx, iv, key, 16, 0, &cbc));
l = sizeof(iv2);
DO(cbc_getiv(iv2, &l, &cbc));
if (l != 16 || memcmp(iv2, iv, 16)) {
printf("cbc_getiv failed");
return 1;
}
for (x = 0; x < 4; x++) {
DO(cbc_encrypt(pt+x*16, ct+x*16, &cbc));
}
/* decode the block */
DO(cbc_setiv(iv2, l, &cbc));
zeromem(tmp, sizeof(tmp));
for (x = 0; x < 4; x++) {
DO(cbc_decrypt(ct+x*16, tmp+x*16, &cbc));
}
if (memcmp(tmp, pt, 64) != 0) {
printf("CBC failed");
return 1;
}
/* test CFB mode */
/* encode the block */
DO(cfb_start(cipher_idx, iv, key, 16, 0, &cfb));
l = sizeof(iv2);
DO(cfb_getiv(iv2, &l, &cfb));
/* note we don't memcmp iv2/iv since cfb_start processes the IV for the first block */
if (l != 16) {
printf("cfb_getiv failed");
return 1;
}
DO(cfb_encrypt(pt, ct, 64, &cfb));
/* decode the block */
DO(cfb_setiv(iv, l, &cfb));
zeromem(tmp, sizeof(tmp));
DO(cfb_decrypt(ct, tmp, 64, &cfb));
if (memcmp(tmp, pt, 64) != 0) {
printf("CFB failed");
return 1;
}
/* test OFB mode */
/* encode the block */
DO(ofb_start(cipher_idx, iv, key, 16, 0, &ofb));
l = sizeof(iv2);
DO(ofb_getiv(iv2, &l, &ofb));
if (l != 16 || memcmp(iv2, iv, 16)) {
printf("ofb_getiv failed");
return 1;
}
DO(ofb_encrypt(pt, ct, 64, &ofb));
/* decode the block */
DO(ofb_setiv(iv2, l, &ofb));
zeromem(tmp, sizeof(tmp));
DO(ofb_decrypt(ct, tmp, 64, &ofb));
if (memcmp(tmp, pt, 64) != 0) {
printf("OFB failed");
return 1;
}
/* test CTR mode */
/* encode the block */
DO(ctr_start(cipher_idx, iv, key, 16, 0, &ctr));
l = sizeof(iv2);
DO(ctr_getiv(iv2, &l, &ctr));
if (l != 16 || memcmp(iv2, iv, 16)) {
printf("ctr_getiv failed");
return 1;
}
DO(ctr_encrypt(pt, ct, 64, &ctr));
/* decode the block */
DO(ctr_setiv(iv2, l, &ctr));
zeromem(tmp, sizeof(tmp));
DO(ctr_decrypt(ct, tmp, 64, &ctr));
if (memcmp(tmp, pt, 64) != 0) {
printf("CTR failed");
return 1;
}
return 0;
}

View file

@ -1,103 +0,0 @@
#include "test.h"
int pkcs_1_test(void)
{
unsigned char buf[3][128];
int res1, res2, res3, prng_idx, hash_idx;
unsigned long x, y, l1, l2, l3, i1, i2, lparamlen, saltlen, modlen;
static const unsigned char lparam[] = { 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16 };
/* get hash/prng */
hash_idx = find_hash("sha1");
prng_idx = find_prng("yarrow");
if (hash_idx == -1 || prng_idx == -1) {
printf("pkcs_1 tests require sha1/yarrow");
return 1;
}
/* do many tests */
for (x = 0; x < 100; x++) {
zeromem(buf, sizeof(buf));
/* make a dummy message (of random length) */
l3 = (rand() & 31) + 8;
for (y = 0; y < l3; y++) buf[0][y] = rand() & 255;
/* random modulus len (v1.5 must be multiple of 8 though arbitrary sizes seem to work) */
modlen = 800 + 8 * (abs(rand()) % 28);
/* PKCS v1.5 testing (encryption) */
l1 = sizeof(buf[1]);
DO(pkcs_1_v15_es_encode(buf[0], l3, modlen, &test_yarrow, prng_idx, buf[1], &l1));
DO(pkcs_1_v15_es_decode(buf[1], l1, modlen, buf[2], l3, &res1));
if (res1 != 1 || memcmp(buf[0], buf[2], l3)) {
printf("pkcs v1.5 encrypt failed %d, %lu, %lu ", res1, l1, l3);
return 1;
}
/* PKCS v1.5 testing (signatures) */
l1 = sizeof(buf[1]);
DO(pkcs_1_v15_sa_encode(buf[0], l3, hash_idx, modlen, buf[1], &l1));
DO(pkcs_1_v15_sa_decode(buf[0], l3, buf[1], l1, hash_idx, modlen, &res1));
buf[0][i1 = abs(rand()) % l3] ^= 1;
DO(pkcs_1_v15_sa_decode(buf[0], l3, buf[1], l1, hash_idx, modlen, &res2));
buf[0][i1] ^= 1;
buf[1][i2 = abs(rand()) % l1] ^= 1;
DO(pkcs_1_v15_sa_decode(buf[0], l3, buf[1], l1, hash_idx, modlen, &res3));
if (!(res1 == 1 && res2 == 0 && res3 == 0)) {
printf("pkcs v1.5 sign failed %d %d %d ", res1, res2, res3);
return 1;
}
/* pick a random lparam len [0..16] */
lparamlen = abs(rand()) % 17;
/* pick a random saltlen 0..16 */
saltlen = abs(rand()) % 17;
/* PKCS #1 v2.0 supports modlens not multiple of 8 */
modlen = 800 + (abs(rand()) % 224);
/* encode it */
l1 = sizeof(buf[1]);
DO(pkcs_1_oaep_encode(buf[0], l3, lparam, lparamlen, modlen, &test_yarrow, prng_idx, hash_idx, buf[1], &l1));
/* decode it */
l2 = sizeof(buf[2]);
DO(pkcs_1_oaep_decode(buf[1], l1, lparam, lparamlen, modlen, hash_idx, buf[2], &l2, &res1));
if (res1 != 1 || l2 != l3 || memcmp(buf[2], buf[0], l3) != 0) {
printf("Outsize == %lu, should have been %lu, res1 = %d, lparamlen = %lu, msg contents follow.\n", l2, l3, res1, lparamlen);
printf("ORIGINAL:\n");
for (x = 0; x < l3; x++) {
printf("%02x ", buf[0][x]);
}
printf("\nRESULT:\n");
for (x = 0; x < l2; x++) {
printf("%02x ", buf[2][x]);
}
printf("\n\n");
return 1;
}
/* test PSS */
l1 = sizeof(buf[1]);
DO(pkcs_1_pss_encode(buf[0], l3, saltlen, &test_yarrow, prng_idx, hash_idx, modlen, buf[1], &l1));
DO(pkcs_1_pss_decode(buf[0], l3, buf[1], l1, saltlen, hash_idx, modlen, &res1));
buf[0][i1 = abs(rand()) % l3] ^= 1;
DO(pkcs_1_pss_decode(buf[0], l3, buf[1], l1, saltlen, hash_idx, modlen, &res2));
buf[0][i1] ^= 1;
buf[1][i2 = abs(rand()) % l1] ^= 1;
DO(pkcs_1_pss_decode(buf[0], l3, buf[1], l1, saltlen, hash_idx, modlen, &res3));
if (!(res1 == 1 && res2 == 0 && res3 == 0)) {
printf("PSS failed: %d, %d, %d, %lu, %lu\n", res1, res2, res3, l3, saltlen);
return 1;
}
}
return 0;
}

View file

@ -1,157 +0,0 @@
#include "test.h"
#define RSA_MSGSIZE 78
int rsa_test(void)
{
unsigned char in[1024], out[1024], tmp[1024];
rsa_key key;
int hash_idx, prng_idx, stat, stat2;
unsigned long rsa_msgsize, len, len2;
static unsigned char lparam[] = { 0x01, 0x02, 0x03, 0x04 };
hash_idx = find_hash("sha1");
prng_idx = find_prng("yarrow");
if (hash_idx == -1 || prng_idx == -1) {
printf("rsa_test requires SHA1 and yarrow");
return 1;
}
/* make a random key */
DO(rsa_make_key(&test_yarrow, prng_idx, 1024/8, 65537, &key));
/* test PKCS #1 v1.5 */
for (rsa_msgsize = 1; rsa_msgsize <= 117; rsa_msgsize++) {
/* make a random key/msg */
yarrow_read(in, rsa_msgsize, &test_yarrow);
len = sizeof(out);
len2 = rsa_msgsize;
/* encrypt */
DO(rsa_v15_encrypt_key(in, rsa_msgsize, out, &len, &test_yarrow, prng_idx, &key));
DO(rsa_v15_decrypt_key(out, len, tmp, rsa_msgsize, &test_yarrow, prng_idx, &stat, &key));
if (stat != 1 || memcmp(tmp, in, rsa_msgsize)) {
printf("PKCS #1 v1.5 encrypt/decrypt failure (rsa_msgsize: %lu, stat: %d)\n", rsa_msgsize, stat);
return 1;
}
}
/* signature */
len = sizeof(out);
DO(rsa_v15_sign_hash(in, 20, out, &len, &test_yarrow, prng_idx, hash_idx, &key));
in[1] ^= 1;
DO(rsa_v15_verify_hash(out, len, in, 20, &test_yarrow, prng_idx, hash_idx, &stat, &key));
in[1] ^= 1;
DO(rsa_v15_verify_hash(out, len, in, 20, &test_yarrow, prng_idx, hash_idx, &stat2, &key));
if (!(stat == 0 && stat2 == 1)) {
printf("PKCS #1 v1.5 sign/verify failure (stat %d, stat2 %d)\n", stat, stat2);
return 1;
}
/* encrypt the key (without lparam) */
for (rsa_msgsize = 1; rsa_msgsize <= 86; rsa_msgsize++) {
/* make a random key/msg */
yarrow_read(in, rsa_msgsize, &test_yarrow);
len = sizeof(out);
len2 = rsa_msgsize;
DO(rsa_encrypt_key(in, rsa_msgsize, out, &len, NULL, 0, &test_yarrow, prng_idx, hash_idx, &key));
/* change a byte */
out[8] ^= 1;
DO(rsa_decrypt_key(out, len, tmp, &len2, NULL, 0, &test_yarrow, prng_idx, hash_idx, &stat2, &key));
/* change a byte back */
out[8] ^= 1;
if (len2 != rsa_msgsize) {
printf("\nrsa_decrypt_key mismatch len %lu (first decrypt)", len2);
return 1;
}
len2 = rsa_msgsize;
DO(rsa_decrypt_key(out, len, tmp, &len2, NULL, 0, &test_yarrow, prng_idx, hash_idx, &stat, &key));
if (!(stat == 1 && stat2 == 0)) {
printf("rsa_decrypt_key failed");
return 1;
}
if (len2 != rsa_msgsize || memcmp(tmp, in, rsa_msgsize)) {
unsigned long x;
printf("\nrsa_decrypt_key mismatch, len %lu (second decrypt)\n", len2);
printf("Original contents: \n");
for (x = 0; x < rsa_msgsize; ) {
printf("%02x ", in[x]);
if (!(++x % 16)) {
printf("\n");
}
}
printf("\n");
printf("Output contents: \n");
for (x = 0; x < rsa_msgsize; ) {
printf("%02x ", out[x]);
if (!(++x % 16)) {
printf("\n");
}
}
printf("\n");
return 1;
}
}
/* encrypt the key (with lparam) */
for (rsa_msgsize = 1; rsa_msgsize <= 86; rsa_msgsize++) {
len = sizeof(out);
len2 = rsa_msgsize;
DO(rsa_encrypt_key(in, rsa_msgsize, out, &len, lparam, sizeof(lparam), &test_yarrow, prng_idx, hash_idx, &key));
/* change a byte */
out[8] ^= 1;
DO(rsa_decrypt_key(out, len, tmp, &len2, lparam, sizeof(lparam), &test_yarrow, prng_idx, hash_idx, &stat2, &key));
if (len2 != rsa_msgsize) {
printf("\nrsa_decrypt_key mismatch len %lu (first decrypt)", len2);
return 1;
}
/* change a byte back */
out[8] ^= 1;
len2 = rsa_msgsize;
DO(rsa_decrypt_key(out, len, tmp, &len2, lparam, sizeof(lparam), &test_yarrow, prng_idx, hash_idx, &stat, &key));
if (!(stat == 1 && stat2 == 0)) {
printf("rsa_decrypt_key failed");
return 1;
}
if (len2 != rsa_msgsize || memcmp(tmp, in, rsa_msgsize)) {
printf("rsa_decrypt_key mismatch len %lu", len2);
return 1;
}
}
/* sign a message (unsalted, lower cholestorol and Atkins approved) now */
len = sizeof(out);
DO(rsa_sign_hash(in, 20, out, &len, &test_yarrow, prng_idx, hash_idx, 0, &key));
DO(rsa_verify_hash(out, len, in, 20, &test_yarrow, prng_idx, hash_idx, 0, &stat, &key));
/* change a byte */
in[0] ^= 1;
DO(rsa_verify_hash(out, len, in, 20, &test_yarrow, prng_idx, hash_idx, 0, &stat2, &key));
if (!(stat == 1 && stat2 == 0)) {
printf("rsa_verify_hash (unsalted) failed, %d, %d", stat, stat2);
return 1;
}
/* sign a message (salted) now */
len = sizeof(out);
DO(rsa_sign_hash(in, 20, out, &len, &test_yarrow, prng_idx, hash_idx, 8, &key));
DO(rsa_verify_hash(out, len, in, 20, &test_yarrow, prng_idx, hash_idx, 8, &stat, &key));
/* change a byte */
in[0] ^= 1;
DO(rsa_verify_hash(out, len, in, 20, &test_yarrow, prng_idx, hash_idx, 8, &stat2, &key));
if (!(stat == 1 && stat2 == 0)) {
printf("rsa_verify_hash (salted) failed, %d, %d", stat, stat2);
return 1;
}
/* free the key and return */
rsa_free(&key);
return 0;
}

Some files were not shown because too many files have changed in this diff Show more