Import LibreSSL v2.4.2 to vendor branch
[dragonfly.git] / crypto / libressl / crypto / dh / dh_check.c
blob3d700d74195368d8fa0271fdb767ef3e94f321d3
1 /* $OpenBSD: dh_check.c,v 1.15 2015/02/07 13:19:15 doug Exp $ */
2 /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
3 * All rights reserved.
5 * This package is an SSL implementation written
6 * by Eric Young (eay@cryptsoft.com).
7 * The implementation was written so as to conform with Netscapes SSL.
8 *
9 * This library is free for commercial and non-commercial use as long as
10 * the following conditions are aheared to. The following conditions
11 * apply to all code found in this distribution, be it the RC4, RSA,
12 * lhash, DES, etc., code; not just the SSL code. The SSL documentation
13 * included with this distribution is covered by the same copyright terms
14 * except that the holder is Tim Hudson (tjh@cryptsoft.com).
16 * Copyright remains Eric Young's, and as such any Copyright notices in
17 * the code are not to be removed.
18 * If this package is used in a product, Eric Young should be given attribution
19 * as the author of the parts of the library used.
20 * This can be in the form of a textual message at program startup or
21 * in documentation (online or textual) provided with the package.
23 * Redistribution and use in source and binary forms, with or without
24 * modification, are permitted provided that the following conditions
25 * are met:
26 * 1. Redistributions of source code must retain the copyright
27 * notice, this list of conditions and the following disclaimer.
28 * 2. Redistributions in binary form must reproduce the above copyright
29 * notice, this list of conditions and the following disclaimer in the
30 * documentation and/or other materials provided with the distribution.
31 * 3. All advertising materials mentioning features or use of this software
32 * must display the following acknowledgement:
33 * "This product includes cryptographic software written by
34 * Eric Young (eay@cryptsoft.com)"
35 * The word 'cryptographic' can be left out if the rouines from the library
36 * being used are not cryptographic related :-).
37 * 4. If you include any Windows specific code (or a derivative thereof) from
38 * the apps directory (application code) you must include an acknowledgement:
39 * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
41 * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
42 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
43 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
44 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
45 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
46 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
47 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
48 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
49 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
50 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
51 * SUCH DAMAGE.
53 * The licence and distribution terms for any publically available version or
54 * derivative of this code cannot be changed. i.e. this code cannot simply be
55 * copied and put under another distribution licence
56 * [including the GNU Public Licence.]
59 #include <stdio.h>
61 #include <openssl/bn.h>
62 #include <openssl/dh.h>
65 * Check that p is a safe prime and
66 * if g is 2, 3 or 5, check that it is a suitable generator
67 * where
68 * for 2, p mod 24 == 11
69 * for 3, p mod 12 == 5
70 * for 5, p mod 10 == 3 or 7
71 * should hold.
74 int
75 DH_check(const DH *dh, int *ret)
77 int ok = 0;
78 BN_CTX *ctx = NULL;
79 BN_ULONG l;
80 BIGNUM *q = NULL;
82 *ret = 0;
83 ctx = BN_CTX_new();
84 if (ctx == NULL)
85 goto err;
86 q = BN_new();
87 if (q == NULL)
88 goto err;
90 if (BN_is_word(dh->g, DH_GENERATOR_2)) {
91 l = BN_mod_word(dh->p, 24);
92 if (l == (BN_ULONG)-1)
93 goto err;
94 if (l != 11)
95 *ret |= DH_NOT_SUITABLE_GENERATOR;
96 } else if (BN_is_word(dh->g, DH_GENERATOR_5)) {
97 l = BN_mod_word(dh->p, 10);
98 if (l == (BN_ULONG)-1)
99 goto err;
100 if (l != 3 && l != 7)
101 *ret |= DH_NOT_SUITABLE_GENERATOR;
102 } else
103 *ret |= DH_UNABLE_TO_CHECK_GENERATOR;
105 if (!BN_is_prime_ex(dh->p, BN_prime_checks, ctx, NULL))
106 *ret |= DH_CHECK_P_NOT_PRIME;
107 else {
108 if (!BN_rshift1(q, dh->p))
109 goto err;
110 if (!BN_is_prime_ex(q, BN_prime_checks, ctx, NULL))
111 *ret |= DH_CHECK_P_NOT_SAFE_PRIME;
113 ok = 1;
114 err:
115 BN_CTX_free(ctx);
116 BN_free(q);
117 return ok;
121 DH_check_pub_key(const DH *dh, const BIGNUM *pub_key, int *ret)
123 BIGNUM *q = NULL;
125 *ret = 0;
126 q = BN_new();
127 if (q == NULL)
128 return 0;
129 BN_set_word(q, 1);
130 if (BN_cmp(pub_key, q) <= 0)
131 *ret |= DH_CHECK_PUBKEY_TOO_SMALL;
132 BN_copy(q, dh->p);
133 BN_sub_word(q, 1);
134 if (BN_cmp(pub_key, q) >= 0)
135 *ret |= DH_CHECK_PUBKEY_TOO_LARGE;
137 BN_free(q);
138 return 1;