summaryrefslogtreecommitdiffstats
path: root/lib/libcrypto/cms
AgeCommit message (Collapse)AuthorFilesLines
2020-06-05Remove remaining error *_str_functs[]jsing1-137/+5
A number of years ago we dropped the concept of having function names in errors, since it is not that useful and very quickly gets out of sync when refactoring. It would seem that some new ones got imported and some missed the last clean up. ok tb@ beck@ "kill it with fire"
2019-10-04Fix a padding oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey.tb3-4/+27
(Note that the CMS code is currently disabled.) Port of Edlinger's Fix for CVE-2019-1563 from OpenSSL 1.1.1 (old license) tests from bluhm@ ok jsing commit e21f8cf78a125cd3c8c0d1a1a6c8bb0b901f893f Author: Bernd Edlinger <bernd.edlinger@hotmail.de> Date: Sun Sep 1 00:16:28 2019 +0200 Fix a padding oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey An attack is simple, if the first CMS_recipientInfo is valid but the second CMS_recipientInfo is chosen ciphertext. If the second recipientInfo decodes to PKCS #1 v1.5 form plaintext, the correct encryption key will be replaced by garbage, and the message cannot be decoded, but if the RSA decryption fails, the correct encryption key is used and the recipient will not notice the attack. As a work around for this potential attack the length of the decrypted key must be equal to the cipher default key length, in case the certifiate is not given and all recipientInfo are tried out. The old behaviour can be re-enabled in the CMS code by setting the CMS_DEBUG_DECRYPT flag. Reviewed-by: Matt Caswell <matt@openssl.org> (Merged from https://github.com/openssl/openssl/pull/9777) (cherry picked from commit 5840ed0cd1e6487d247efbc1a04136a41d7b3a37)
2019-08-12Provide a local version of X509_get0_subject_key_id()jsing1-3/+11
It seems that the CMS code is currently the only code in existence that uses this function.
2019-08-12Inline the equivalent of ASN1_TYPE_unpack_sequence().jsing1-3/+6
2019-08-11Use ERR_asprintf_error_data() instead of ERR_add_error_data().jsing1-3/+3
2019-08-11Remove unsupported GOST 2012 NIDs.jsing1-3/+1
2019-08-11Disable DES3 since we do not currently provide DES3 keywrap.jsing1-1/+7
2019-08-11Remove label that is now unused (due to arc4random_buf() returning void).jsing1-3/+2
2019-08-11Fix loading of CMS error strings.jsing1-5/+5
2019-08-11Include string.h for explicit_bzero().jsing2-2/+6
2019-08-11Expand M_ASN1_new_of and M_ASN1_free_of macros.jsing9-39/+39
2019-08-11Use arc4random_buf() instead of RAND_bytes().jsing3-12/+8
This also removes return checks since arc4random_buf() does not fail.
2019-08-11Include string.h for memcmp()/memcpy().jsing5-5/+15
2019-08-11Use freezero() rather than OPENSSL_clear_free().jsing5-15/+15
2019-08-11Use explicit_bzero() instead of OPENSSL_cleanse().jsing2-5/+5
2019-08-11Use malloc(3) and free(3), rather than OPENSSL_{malloc,free}().jsing6-33/+33
2019-08-11Convert CMSerr() to CMSerror().jsing11-240/+191
2019-08-11Switch ASN.1 INT32 back to LONG.jsing2-28/+28
2019-08-11Expand a new macro that tried to get away...jsing1-2/+8
2019-08-11Expand ASN.1 macros.jsing8-253/+1524
2019-08-11We use DECLARE_STACK_OF rather than DEFINE_STACK_OF.jsing2-7/+7
2019-08-11Unlike OpenSSL we do not have our own special ssize_t.jsing3-9/+9
2019-08-10Fix style(9) and whitespace.jsing1-208/+203
2019-08-10More style(9) and whitespace.jsing1-332/+291
2019-08-10More style(9), whitespace and readability fixes.jsing14-674/+902
Files are identical once whitespace and newlines are removed.
2019-08-10First pass at style(9).jsing14-3936/+3936
Whitespace only and no change according to diff -w.
2019-08-10Fix includes for non-installed headers.jsing9-25/+25
2019-08-10Include cms.h instead of cmserr.h.jsing1-2/+2
2019-08-10Add $OpenBSD$ tag.jsing1-0/+1
2019-08-10Restore the per-file license for cms.h.jsing1-5/+49
This reverts the removal from OpenSSL 21dcbebc6e35419f1842f39a125374ea1ba45693.
2019-08-10Provide cms.h.jsing1-0/+515
This is OpenSSL 1.1.1 cms.h and cmserr.h combined, essentially reverting OpenSSL 52df25cf2e656146cb3b206d8220124f0417d03f.
2019-08-10Add $OpenBSD$ tags.jsing15-0/+15
2019-08-10Restore the original per-file licenses for CMS.jsing14-70/+686
These were removed in OpenSSL b1322259d93cf6b6286f9febcd468b6a9f577d91.
2019-08-10Work towards supporting Cryptographic Message Syntax (CMS) in libcrypto.jsing15-0/+6172
Cryptographic Message Syntax (CMS) is a standard for cryptographically protecting messages, as defined in RFC 5652. It is derived from PKCS #7 version 1.5 and utilises various ASN.1 structures, making it complex and fairly heavyweight. Various protocols - including RPKI (RFC 6480) - have been built on top of it, which means it is necessary to support CMS, in order to support RPKI. This imports around 6,000 lines of code from OpenSSL 1.1.1, which is still under the original OpenSSL license. Further work will occur in tree. Requested by and discussed with many. ok deraadt@ tb@
2016-09-04Remove cms.jsing15-7541/+0
ok beck@, guenther@, tedu@
2016-03-11X509_free(3) is NULL-safe, so remove NULL checks before its calls.mmcc2-8/+5
ok doug@
2015-09-10Correct spelling of OPENSSL_cleanse.jsing4-14/+14
ok miod@
2015-07-25Expand another wall of ASN.1 template macros - no change to generatedjsing1-195/+1328
assembly.
2015-06-11Avoid an infinite loop that can occur when verifying a message with anjsing1-2/+2
unknown hash function OID. Diff based on OpenSSL. Fixes CVE-2015-1792 (however, this code is not enabled/built in LibreSSL). ok doug@ miod@
2015-05-15Fix return paths with missing EVP_CIPHER_CTX_cleanup() calls.jsg1-4/+4
ok doug@
2015-02-11Guenther has plans for OPENSSL_NO_CMS, so revert this for the moment.beck1-1/+3
2015-02-11get rid of OPENSSL_NO_CMS code we do not use.beck1-3/+1
ok miod@
2015-02-11get rid of OPENSSL_NO_COMP code we don't use.beck1-4/+1
jajaja miod@
2014-11-09GOST crypto algorithms (well, most of them), ported from the removed GOSTmiod1-1/+3
engine to regular EVP citizens, contributed by Dmitry Eremin-Solenikov; libcrypto bits only for now. This is a verbatim import of Dmitry's work, and does not compile in this state; the forthcoming commits will address these issues. None of the GOST code is enabled in libcrypto yet, for it still gets compiled with OPENSSL_NO_GOST defined. However, the public header gost.h will be installed.
2014-10-22Use arc4random_buf() instead of RAND_bytes() or RAND_pseudo_bytes().jsing3-14/+13
arc4random_buf() is guaranteed to always succeed - it is worth noting that a number of the replaced function calls were already missing return value checks. ok deraadt@
2014-10-18None of these need to include <openssl/rand.h>jsing1-2/+1
2014-07-25BIO_free() returns immediately when the sole input is NULL.doug1-3/+2
Remove unnecessary NULL check. ok miod@
2014-07-12if (x) FOO_free(x) -> FOO_free(x).miod3-13/+8
Improves readability, keeps the code smaller so that it is warmer in your cache. review & ok deraadt@
2014-07-11Avoid invoking EVP_CIPHER_CTX_cleanup() on uninitialized memory; frommiod1-2/+2
Coverity via OpenSSL trunk
2014-07-11Fix version number processing in cms_sd_set_version(); OpenSSL PR #3249 viamiod1-3/+3
OpenSSL trunk.