tls-hkdf: Add helper method to allocate data from the internal PRF

This commit is contained in:
Tobias Brunner
2021-02-12 11:45:44 +01:00
parent 6a0ee0c23c
commit a9f661f52a
2 changed files with 22 additions and 0 deletions
+9
View File
@@ -485,6 +485,14 @@ METHOD(tls_hkdf_t, derive_finished, bool,
finished);
}
METHOD(tls_hkdf_t, allocate_bytes, bool,
private_tls_hkdf_t *this, chunk_t key, chunk_t seed,
chunk_t *out)
{
return this->prf->set_key(this->prf, key) &&
this->prf->allocate_bytes(this->prf, seed, out);
}
METHOD(tls_hkdf_t, destroy, void,
private_tls_hkdf_t *this)
{
@@ -525,6 +533,7 @@ tls_hkdf_t *tls_hkdf_create(hash_algorithm_t hash_algorithm, chunk_t psk)
.derive_key = _derive_key,
.derive_iv = _derive_iv,
.derive_finished = _derive_finished,
.allocate_bytes = _allocate_bytes,
.destroy = _destroy,
},
.phase = HKDF_PHASE_0,
+13
View File
@@ -111,6 +111,19 @@ struct tls_hkdf_t {
bool (*derive_finished)(tls_hkdf_t *this, bool is_server,
chunk_t *finished);
/**
* Use the internal PRF to allocate data (mainly for the finished message
* where the key is from derive_finished() and the seed is the transcript
* hash).
*
* @param key key to use with the PRF
* @param seed seed to use with the PRF
* @param out output from the PRF (allocated)
* @return TRUE if output was generated
*/
bool (*allocate_bytes)(tls_hkdf_t *this, chunk_t key, chunk_t seed,
chunk_t *out);
/**
* Destroy a tls_hkdf_t
*/