FreeRDP
Loading...
Searching...
No Matches
libfreerdp/crypto/crypto.c
1
22#include <errno.h>
23
24#include <openssl/objects.h>
25#include <openssl/bn.h>
26
27#include <freerdp/config.h>
28
29#include <winpr/crt.h>
30#include <winpr/assert.h>
31
32#include <freerdp/log.h>
33#include <freerdp/crypto/crypto.h>
34
35#include "crypto.h"
36#include "privatekey.h"
37
38#if !defined(_WIN32)
39#include <sys/stat.h>
40#endif
41
42#define TAG FREERDP_TAG("crypto")
43
44static SSIZE_T crypto_rsa_common(const BYTE* input, size_t length, UINT32 key_length,
45 const BYTE* modulus, const BYTE* exponent, size_t exponent_size,
46 BYTE* output, size_t out_length)
47{
48 BN_CTX* ctx = nullptr;
49 int output_length = -1;
50 BYTE* input_reverse = nullptr;
51 BYTE* modulus_reverse = nullptr;
52 BYTE* exponent_reverse = nullptr;
53 BIGNUM* mod = nullptr;
54 BIGNUM* exp = nullptr;
55 BIGNUM* x = nullptr;
56 BIGNUM* y = nullptr;
57 size_t bufferSize = 0;
58
59 if (!input || !modulus || !exponent || !output)
60 return -1;
61
62 if (exponent_size > INT_MAX / 2)
63 return -1;
64
65 if (key_length >= INT_MAX / 2 - exponent_size)
66 return -1;
67
68 bufferSize = 2ULL * key_length + exponent_size;
69 if (length > bufferSize)
70 bufferSize = length;
71
72 input_reverse = (BYTE*)calloc(bufferSize, 1);
73
74 if (!input_reverse)
75 return -1;
76
77 modulus_reverse = input_reverse + key_length;
78 exponent_reverse = modulus_reverse + key_length;
79 memmove(modulus_reverse, modulus, key_length);
80 crypto_reverse(modulus_reverse, key_length);
81 memmove(exponent_reverse, exponent, exponent_size);
82 crypto_reverse(exponent_reverse, exponent_size);
83 memmove(input_reverse, input, length);
84 crypto_reverse(input_reverse, length);
85
86 if (!(ctx = BN_CTX_new()))
87 goto fail;
88
89 if (!(mod = BN_new()))
90 goto fail;
91
92 if (!(exp = BN_new()))
93 goto fail;
94
95 if (!(x = BN_new()))
96 goto fail;
97
98 if (!(y = BN_new()))
99 goto fail;
100
101 if (!BN_bin2bn(modulus_reverse, (int)key_length, mod))
102 goto fail;
103
104 if (!BN_bin2bn(exponent_reverse, (int)exponent_size, exp))
105 goto fail;
106 if (!BN_bin2bn(input_reverse, (int)length, x))
107 goto fail;
108 if (BN_mod_exp(y, x, exp, mod, ctx) != 1)
109 goto fail;
110 {
111 const int len = BN_num_bytes(y);
112 if ((len < 0) || (WINPR_ASSERTING_INT_CAST(size_t, len) > out_length))
113 goto fail;
114 output_length = BN_bn2bin(y, output);
115 }
116 if (output_length < 0)
117 goto fail;
118 crypto_reverse(output, WINPR_ASSERTING_INT_CAST(size_t, output_length));
119
120 if ((size_t)output_length < key_length)
121 {
122 size_t diff = key_length - WINPR_ASSERTING_INT_CAST(size_t, output_length);
123 if ((size_t)output_length + diff > out_length)
124 diff = out_length - (size_t)output_length;
125 memset(output + output_length, 0, diff);
126 }
127
128fail:
129 BN_free(y);
130 BN_clear_free(x);
131 BN_free(exp);
132 BN_free(mod);
133 BN_CTX_free(ctx);
134 free(input_reverse);
135 return output_length;
136}
137
138static SSIZE_T crypto_rsa_public(const BYTE* input, size_t length, const rdpCertInfo* cert,
139 BYTE* output, size_t output_length)
140{
141 WINPR_ASSERT(cert);
142 return crypto_rsa_common(input, length, cert->ModulusLength, cert->Modulus, cert->exponent,
143 sizeof(cert->exponent), output, output_length);
144}
145
146static SSIZE_T crypto_rsa_private(const BYTE* input, size_t length, const rdpPrivateKey* key,
147 BYTE* output, size_t output_length)
148{
149 WINPR_ASSERT(key);
150 const rdpCertInfo* info = freerdp_key_get_info(key);
151 WINPR_ASSERT(info);
152
153 size_t PrivateExponentLength = 0;
154 const BYTE* PrivateExponent = freerdp_key_get_exponent(key, &PrivateExponentLength);
155 return crypto_rsa_common(input, length, info->ModulusLength, info->Modulus, PrivateExponent,
156 PrivateExponentLength, output, output_length);
157}
158
159SSIZE_T crypto_rsa_public_encrypt(const BYTE* input, size_t length, const rdpCertInfo* cert,
160 BYTE* output, size_t output_length)
161{
162 return crypto_rsa_public(input, length, cert, output, output_length);
163}
164
165SSIZE_T crypto_rsa_public_decrypt(const BYTE* input, size_t length, const rdpCertInfo* cert,
166 BYTE* output, size_t output_length)
167{
168 return crypto_rsa_public(input, length, cert, output, output_length);
169}
170
171SSIZE_T crypto_rsa_private_encrypt(const BYTE* input, size_t length, const rdpPrivateKey* key,
172 BYTE* output, size_t output_length)
173{
174 return crypto_rsa_private(input, length, key, output, output_length);
175}
176
177SSIZE_T crypto_rsa_private_decrypt(const BYTE* input, size_t length, const rdpPrivateKey* key,
178 BYTE* output, size_t output_length)
179{
180 return crypto_rsa_private(input, length, key, output, output_length);
181}
182
183void crypto_reverse(BYTE* data, size_t length)
184{
185 if (length < 1)
186 return;
187
188 for (size_t i = 0, j = length - 1; i < j; i++, j--)
189 {
190 const BYTE temp = data[i];
191 data[i] = data[j];
192 data[j] = temp;
193 }
194}
195
196char* crypto_read_pem(const char* WINPR_RESTRICT filename, size_t* WINPR_RESTRICT plength)
197{
198 char* pem = nullptr;
199 FILE* fp = nullptr;
200
201 WINPR_ASSERT(filename);
202
203 if (plength)
204 *plength = 0;
205
206 /* Binary mode: the size is taken from SEEK_END and then demanded in a single fread().
207 * In text mode on Windows CRLF collapses to LF, fewer than size bytes come back and the
208 * read fails, which makes every CRLF-terminated PEM unreadable -- and that is what the
209 * Windows tooling writes. */
210 fp = winpr_fopen(filename, "rb");
211 if (!fp)
212 goto fail;
213
214 {
215 const int rs = _fseeki64(fp, 0, SEEK_END);
216 if (rs < 0)
217 goto fail;
218 }
219
220 {
221 const int64_t size = _ftelli64(fp);
222 if (size < 0)
223 goto fail;
224
225 {
226 const int rc = _fseeki64(fp, 0, SEEK_SET);
227 if (rc < 0)
228 goto fail;
229 }
230
231 pem = calloc(WINPR_ASSERTING_INT_CAST(size_t, size) + 1, sizeof(char));
232 if (!pem)
233 goto fail;
234
235 {
236 const size_t fr = fread(pem, (size_t)size, 1, fp);
237 if (fr != 1)
238 goto fail;
239 }
240
241 if (plength)
242 *plength = strnlen(pem, WINPR_ASSERTING_INT_CAST(size_t, size));
243 }
244 (void)fclose(fp);
245 return pem;
246
247fail:
248{
249 char buffer[8192] = WINPR_C_ARRAY_INIT;
250 WLog_WARN(TAG, "Failed to read PEM from file '%s' [%s]", filename,
251 winpr_strerror(errno, buffer, sizeof(buffer)));
252}
253 if (fp)
254 (void)fclose(fp);
255 free(pem);
256 return nullptr;
257}
258
259BOOL crypto_write_pem(const char* WINPR_RESTRICT filename, const char* WINPR_RESTRICT pem,
260 size_t length)
261{
262 WINPR_ASSERT(filename);
263 WINPR_ASSERT(pem || (length == 0));
264
265 WINPR_ASSERT(filename);
266 WINPR_ASSERT(pem);
267
268 const size_t size = strnlen(pem, length) + 1;
269 size_t rc = 0;
270 FILE* fp = winpr_fopen(filename, "w");
271 if (!fp)
272 goto fail;
273#if !defined(_WIN32)
274 const int res = fchmod(fileno(fp), S_IRUSR | S_IWUSR);
275 if (res != 0)
276 {
277 char buffer[128] = WINPR_C_ARRAY_INIT;
278 WLog_WARN(TAG, "Failed to chmod %s: %s", filename,
279 winpr_strerror(errno, buffer, sizeof(buffer)));
280 const int fres = fclose(fp);
281 if (fres != 0)
282 {
283 char buffer2[128] = WINPR_C_ARRAY_INIT;
284 WLog_WARN(TAG, "Failed to close PEM [%" PRIuz "] to file '%s' [%s]", length, filename,
285 winpr_strerror(errno, buffer2, sizeof(buffer2)));
286 }
287 goto fail;
288 }
289#endif
290 rc = fwrite(pem, 1, size, fp);
291 const int fres = fclose(fp);
292 if (fres != 0)
293 {
294 char buffer[128] = WINPR_C_ARRAY_INIT;
295 WLog_WARN(TAG, "Failed to close PEM [%" PRIuz "] to file '%s' [%s]", length, filename,
296 winpr_strerror(errno, buffer, sizeof(buffer)));
297 }
298fail:
299 if (rc == 0)
300 {
301 char buffer[128] = WINPR_C_ARRAY_INIT;
302 WLog_WARN(TAG, "Failed to write PEM [%" PRIuz "] to file '%s' [%s]", length, filename,
303 winpr_strerror(errno, buffer, sizeof(buffer)));
304 }
305 return rc == size;
306}