diffie-hellman: Verify public DH values in backends

This commit is contained in:
Martin Willi
2015-03-23 17:54:03 +01:00
parent a777155ffe
commit 0356089d0f
7 changed files with 107 additions and 1 deletions
@@ -79,6 +79,11 @@ METHOD(diffie_hellman_t, set_other_public_value, bool,
gcry_mpi_t p_min_1;
gcry_error_t err;
if (!diffie_hellman_verify_value(this->group, value))
{
return FALSE;
}
if (this->yb)
{
gcry_mpi_release(this->yb);
@@ -90,6 +90,11 @@ METHOD(diffie_hellman_t, set_other_public_value, bool,
{
mpz_t p_min_1;
if (!diffie_hellman_verify_value(this->group, value))
{
return FALSE;
}
mpz_init(p_min_1);
mpz_sub_ui(p_min_1, this->p, 1);
@@ -92,6 +92,11 @@ METHOD(diffie_hellman_t, set_other_public_value, bool,
{
int len;
if (!diffie_hellman_verify_value(this->group, value))
{
return FALSE;
}
BN_bin2bn(value.ptr, value.len, this->pub_key);
chunk_clear(&this->shared_secret);
this->shared_secret.ptr = malloc(DH_size(this->dh));
@@ -219,6 +219,11 @@ error:
METHOD(diffie_hellman_t, set_other_public_value, bool,
private_openssl_ec_diffie_hellman_t *this, chunk_t value)
{
if (!diffie_hellman_verify_value(this->group, value))
{
return FALSE;
}
if (!chunk2ecp(this->ec_group, value, this->pub_key))
{
DBG1(DBG_LIB, "ECDH public value is malformed");
@@ -116,6 +116,11 @@ static bool derive_secret(private_pkcs11_dh_t *this, chunk_t other)
METHOD(diffie_hellman_t, set_other_public_value, bool,
private_pkcs11_dh_t *this, chunk_t value)
{
if (!diffie_hellman_verify_value(this->group, value))
{
return FALSE;
}
switch (this->group)
{
case ECP_192_BIT: