libipsec: Add support for AES and Camellia in CCM mode

Fixes #2172.
This commit is contained in:
Tobias Brunner
2017-01-25 17:26:45 +01:00
parent 1da567734f
commit 896d729a60
+16 -3
View File
@@ -210,19 +210,32 @@ METHOD(esp_context_t, destroy, void,
static bool create_aead(private_esp_context_t *this, int alg,
chunk_t key)
{
size_t salt = 0;
switch (alg)
{
case ENCR_AES_GCM_ICV8:
case ENCR_AES_GCM_ICV12:
case ENCR_AES_GCM_ICV16:
case ENCR_CHACHA20_POLY1305:
/* the key includes a 4 byte salt */
this->aead = lib->crypto->create_aead(lib->crypto, alg,
key.len - 4, 4);
salt = 4;
break;
case ENCR_AES_CCM_ICV8:
case ENCR_AES_CCM_ICV12:
case ENCR_AES_CCM_ICV16:
case ENCR_CAMELLIA_CCM_ICV8:
case ENCR_CAMELLIA_CCM_ICV12:
case ENCR_CAMELLIA_CCM_ICV16:
salt = 3;
break;
default:
break;
}
if (salt)
{
this->aead = lib->crypto->create_aead(lib->crypto, alg,
key.len - salt, salt);
}
if (!this->aead)
{
DBG1(DBG_ESP, "failed to create ESP context: unsupported AEAD "