1e1051a39Sopenharmony_ci/*
2e1051a39Sopenharmony_ci * Copyright 2017-2022 The OpenSSL Project Authors. All Rights Reserved.
3e1051a39Sopenharmony_ci *
4e1051a39Sopenharmony_ci * Licensed under the Apache License 2.0 (the "License").  You may not use
5e1051a39Sopenharmony_ci * this file except in compliance with the License.  You can obtain a copy
6e1051a39Sopenharmony_ci * in the file LICENSE in the source distribution or at
7e1051a39Sopenharmony_ci * https://www.openssl.org/source/license.html
8e1051a39Sopenharmony_ci */
9e1051a39Sopenharmony_ci
10e1051a39Sopenharmony_ci/* DH parameters from RFC7919 and RFC3526 */
11e1051a39Sopenharmony_ci
12e1051a39Sopenharmony_ci/*
13e1051a39Sopenharmony_ci * DH low level APIs are deprecated for public use, but still ok for
14e1051a39Sopenharmony_ci * internal use.
15e1051a39Sopenharmony_ci */
16e1051a39Sopenharmony_ci#include "internal/deprecated.h"
17e1051a39Sopenharmony_ci
18e1051a39Sopenharmony_ci#include <stdio.h>
19e1051a39Sopenharmony_ci#include "internal/cryptlib.h"
20e1051a39Sopenharmony_ci#include "internal/ffc.h"
21e1051a39Sopenharmony_ci#include "dh_local.h"
22e1051a39Sopenharmony_ci#include <openssl/bn.h>
23e1051a39Sopenharmony_ci#include <openssl/objects.h>
24e1051a39Sopenharmony_ci#include "internal/nelem.h"
25e1051a39Sopenharmony_ci#include "crypto/dh.h"
26e1051a39Sopenharmony_ci
27e1051a39Sopenharmony_cistatic DH *dh_param_init(OSSL_LIB_CTX *libctx, const DH_NAMED_GROUP *group)
28e1051a39Sopenharmony_ci{
29e1051a39Sopenharmony_ci    DH *dh = ossl_dh_new_ex(libctx);
30e1051a39Sopenharmony_ci
31e1051a39Sopenharmony_ci    if (dh == NULL)
32e1051a39Sopenharmony_ci        return NULL;
33e1051a39Sopenharmony_ci
34e1051a39Sopenharmony_ci    ossl_ffc_named_group_set(&dh->params, group);
35e1051a39Sopenharmony_ci    dh->params.nid = ossl_ffc_named_group_get_uid(group);
36e1051a39Sopenharmony_ci    dh->dirty_cnt++;
37e1051a39Sopenharmony_ci    return dh;
38e1051a39Sopenharmony_ci}
39e1051a39Sopenharmony_ci
40e1051a39Sopenharmony_ciDH *ossl_dh_new_by_nid_ex(OSSL_LIB_CTX *libctx, int nid)
41e1051a39Sopenharmony_ci{
42e1051a39Sopenharmony_ci    const DH_NAMED_GROUP *group;
43e1051a39Sopenharmony_ci
44e1051a39Sopenharmony_ci    if ((group = ossl_ffc_uid_to_dh_named_group(nid)) != NULL)
45e1051a39Sopenharmony_ci        return dh_param_init(libctx, group);
46e1051a39Sopenharmony_ci
47e1051a39Sopenharmony_ci    ERR_raise(ERR_LIB_DH, DH_R_INVALID_PARAMETER_NID);
48e1051a39Sopenharmony_ci    return NULL;
49e1051a39Sopenharmony_ci}
50e1051a39Sopenharmony_ci
51e1051a39Sopenharmony_ciDH *DH_new_by_nid(int nid)
52e1051a39Sopenharmony_ci{
53e1051a39Sopenharmony_ci    return ossl_dh_new_by_nid_ex(NULL, nid);
54e1051a39Sopenharmony_ci}
55e1051a39Sopenharmony_ci
56e1051a39Sopenharmony_civoid ossl_dh_cache_named_group(DH *dh)
57e1051a39Sopenharmony_ci{
58e1051a39Sopenharmony_ci    const DH_NAMED_GROUP *group;
59e1051a39Sopenharmony_ci
60e1051a39Sopenharmony_ci    if (dh == NULL)
61e1051a39Sopenharmony_ci        return;
62e1051a39Sopenharmony_ci
63e1051a39Sopenharmony_ci    dh->params.nid = NID_undef; /* flush cached value */
64e1051a39Sopenharmony_ci
65e1051a39Sopenharmony_ci    /* Exit if p or g is not set */
66e1051a39Sopenharmony_ci    if (dh->params.p == NULL
67e1051a39Sopenharmony_ci        || dh->params.g == NULL)
68e1051a39Sopenharmony_ci        return;
69e1051a39Sopenharmony_ci
70e1051a39Sopenharmony_ci    if ((group = ossl_ffc_numbers_to_dh_named_group(dh->params.p,
71e1051a39Sopenharmony_ci                                                    dh->params.q,
72e1051a39Sopenharmony_ci                                                    dh->params.g)) != NULL) {
73e1051a39Sopenharmony_ci        if (dh->params.q == NULL)
74e1051a39Sopenharmony_ci            dh->params.q = (BIGNUM *)ossl_ffc_named_group_get_q(group);
75e1051a39Sopenharmony_ci        /* cache the nid and default key length */
76e1051a39Sopenharmony_ci        dh->params.nid = ossl_ffc_named_group_get_uid(group);
77e1051a39Sopenharmony_ci        dh->params.keylength = ossl_ffc_named_group_get_keylength(group);
78e1051a39Sopenharmony_ci        dh->dirty_cnt++;
79e1051a39Sopenharmony_ci    }
80e1051a39Sopenharmony_ci}
81e1051a39Sopenharmony_ci
82e1051a39Sopenharmony_ciint ossl_dh_is_named_safe_prime_group(const DH *dh)
83e1051a39Sopenharmony_ci{
84e1051a39Sopenharmony_ci    int id = DH_get_nid(dh);
85e1051a39Sopenharmony_ci
86e1051a39Sopenharmony_ci    /*
87e1051a39Sopenharmony_ci     * Exclude RFC5114 groups (id = 1..3) since they do not have
88e1051a39Sopenharmony_ci     * q = (p - 1) / 2
89e1051a39Sopenharmony_ci     */
90e1051a39Sopenharmony_ci    return (id > 3);
91e1051a39Sopenharmony_ci}
92e1051a39Sopenharmony_ci
93e1051a39Sopenharmony_ciint DH_get_nid(const DH *dh)
94e1051a39Sopenharmony_ci{
95e1051a39Sopenharmony_ci    if (dh == NULL)
96e1051a39Sopenharmony_ci        return NID_undef;
97e1051a39Sopenharmony_ci
98e1051a39Sopenharmony_ci    return dh->params.nid;
99e1051a39Sopenharmony_ci}
100