Wipe memory after using key material (incomplete, to be continued)
This commit is contained in:
@@ -1518,6 +1518,7 @@ METHOD(crypter_t, set_key, void,
|
||||
METHOD(crypter_t, destroy, void,
|
||||
private_aes_crypter_t *this)
|
||||
{
|
||||
memwipe(this, sizeof(*this));
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
@@ -160,6 +160,7 @@ METHOD(crypter_t, set_key, void,
|
||||
METHOD(crypter_t, destroy, void,
|
||||
private_blowfish_crypter_t *this)
|
||||
{
|
||||
memwipe(this, sizeof(*this));
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
@@ -1552,6 +1552,7 @@ METHOD(crypter_t, set_key3, void,
|
||||
METHOD(crypter_t, destroy, void,
|
||||
private_des_crypter_t *this)
|
||||
{
|
||||
memwipe(this, sizeof(*this));
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
@@ -147,8 +147,8 @@ METHOD(hmac_t, destroy, void,
|
||||
private_hmac_t *this)
|
||||
{
|
||||
this->h->destroy(this->h);
|
||||
free(this->opaded_key.ptr);
|
||||
free(this->ipaded_key.ptr);
|
||||
chunk_clear(&this->opaded_key);
|
||||
chunk_clear(&this->ipaded_key);
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
@@ -152,7 +152,7 @@ METHOD(crypter_t, set_key, void,
|
||||
METHOD(crypter_t, destroy, void,
|
||||
private_openssl_crypter_t *this)
|
||||
{
|
||||
free(this->key.ptr);
|
||||
clear_chunk(&this->key);
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
@@ -257,7 +257,7 @@ METHOD(diffie_hellman_t, destroy, void,
|
||||
{
|
||||
EC_POINT_clear_free(this->pub_key);
|
||||
EC_KEY_free(this->key);
|
||||
chunk_free(&this->shared_secret);
|
||||
chunk_clear(&this->shared_secret);
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
@@ -105,6 +105,8 @@ static void crypt(private_padlock_aes_crypter_t *this, char *iv,
|
||||
*dst = chunk_alloc(src.len);
|
||||
padlock_crypt(key_aligned, &cword, src.ptr, dst->ptr,
|
||||
src.len / AES_BLOCK_SIZE, iv_aligned);
|
||||
|
||||
memwipe(key_aligned, sizeof(key_aligned));
|
||||
}
|
||||
|
||||
METHOD(crypter_t, decrypt, void,
|
||||
@@ -146,7 +148,7 @@ METHOD(crypter_t, set_key, void,
|
||||
METHOD(crypter_t, destroy, void,
|
||||
private_padlock_aes_crypter_t *this)
|
||||
{
|
||||
free(this->key.ptr);
|
||||
chunk_clear(&this->key);
|
||||
free(this);
|
||||
}
|
||||
|
||||
|
||||
@@ -236,13 +236,17 @@ METHOD(xcbc_t, set_key, void,
|
||||
memset(k1.ptr, 0x01, this->b);
|
||||
this->k1->encrypt(this->k1, k1, iv, NULL);
|
||||
this->k1->set_key(this->k1, k1);
|
||||
|
||||
memwipe(k1.ptr, k1.len);
|
||||
}
|
||||
|
||||
METHOD(xcbc_t, destroy, void,
|
||||
private_xcbc_t *this)
|
||||
{
|
||||
this->k1->destroy(this->k1);
|
||||
memwipe(this->k2, this->b);
|
||||
free(this->k2);
|
||||
memwipe(this->k3, this->b);
|
||||
free(this->k3);
|
||||
free(this->e);
|
||||
free(this->remaining);
|
||||
|
||||
Reference in New Issue
Block a user