dst_api.c revision 016c0a82f1ce3fe4d362d7c9cf8de4377ffaf5a9
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson/*
573d78f3d53859bc01ce5d5cebbaac9b8b90bfbaTinderbox User * Portions Copyright (C) 2004, 2005 Internet Systems Consortium, Inc. ("ISC")
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * Portions Copyright (C) 1999-2003 Internet Software Consortium.
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence * Portions Copyright (C) 1995-2000 by Network Associates, Inc.
ec5347e2c775f027573ce5648b910361aa926c01Automatic Updater *
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson * Permission to use, copy, modify, and distribute this software for any
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson * purpose with or without fee is hereby granted, provided that the above
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence * copyright notice and this permission notice appear in all copies.
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews *
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * THE SOFTWARE IS PROVIDED "AS IS" AND ISC AND NETWORK ASSOCIATES DISCLAIMS
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson * IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson */
313b4dc3b2e2be29994ce030c42c39c9eef9c46bAutomatic Updater
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein/*
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein * Principal Author: Brian Wellington
9c3531d72aeaad6c5f01efe6a1c82023e1379e4dDavid Lawrence * $Id: dst_api.c,v 1.4 2005/06/17 02:22:43 marka Exp $
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson */
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson/*! \file */
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence#include <config.h>
364a82f7c25b62967678027043425201a5e5171aBob Halley
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson#include <stdlib.h>
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#include <isc/buffer.h>
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson#include <isc/dir.h>
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Hunt#include <isc/entropy.h>
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#include <isc/fsaccess.h>
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#include <isc/lex.h>
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#include <isc/mem.h>
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#include <isc/once.h>
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#include <isc/print.h>
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson#include <isc/random.h>
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence#include <isc/string.h>
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson#include <isc/time.h>
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson#include <isc/util.h>
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence#include <dns/fixedname.h>
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence#include <dns/keyvalues.h>
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence#include <dns/name.h>
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson#include <dns/rdata.h>
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson#include <dns/rdataclass.h>
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence#include <dns/ttl.h>
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson#include <dns/types.h>
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson#include <dst/result.h>
df925e6c66d45d960fbac0383169763967d2111cEvan Hunt
df925e6c66d45d960fbac0383169763967d2111cEvan Hunt#include "dst_internal.h"
df925e6c66d45d960fbac0383169763967d2111cEvan Hunt
df925e6c66d45d960fbac0383169763967d2111cEvan Hunt#define DST_AS_STR(t) ((t).value.as_textregion.base)
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Huntstatic dst_func_t *dst_t_func[DST_MAX_ALGS];
18d0b5e54be891a1aa938c165b6d439859121ec8Mark Andrewsstatic isc_entropy_t *dst_entropy_pool = NULL;
18d0b5e54be891a1aa938c165b6d439859121ec8Mark Andrewsstatic unsigned int dst_entropy_flags = 0;
18d0b5e54be891a1aa938c165b6d439859121ec8Mark Andrewsstatic isc_boolean_t dst_initialized = ISC_FALSE;
18d0b5e54be891a1aa938c165b6d439859121ec8Mark Andrews
18d0b5e54be891a1aa938c165b6d439859121ec8Mark Andrewsisc_mem_t *dst__memory_pool = NULL;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews/*
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt * Static functions.
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt */
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Huntstatic dst_key_t * get_key_struct(dns_name_t *name,
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt unsigned int alg,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews unsigned int flags,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson unsigned int protocol,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson unsigned int bits,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson dns_rdataclass_t rdclass,
114c14f8adfc249cf2e5cdcb9007af46fed257e3Mark Andrews isc_mem_t *mctx);
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrencestatic isc_result_t write_public_key(const dst_key_t *key, int type,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson const char *directory);
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrencestatic isc_result_t buildfilename(dns_name_t *name,
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence dns_keytag_t id,
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence unsigned int alg,
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence unsigned int type,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson const char *directory,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson isc_buffer_t *out);
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafssonstatic isc_result_t computeid(dst_key_t *key);
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafssonstatic isc_result_t frombuffer(dns_name_t *name,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson unsigned int alg,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson unsigned int flags,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson unsigned int protocol,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson dns_rdataclass_t rdclass,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson isc_buffer_t *source,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson isc_mem_t *mctx,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson dst_key_t **keyp);
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafssonstatic isc_result_t algorithm_status(unsigned int alg);
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafssonstatic isc_result_t addsuffix(char *filename, unsigned int len,
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson const char *ofilename, const char *suffix);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#define RETERR(x) \
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt do { \
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt result = (x); \
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (result != ISC_R_SUCCESS) \
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt goto out; \
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson } while (0)
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson#define CHECKALG(alg) \
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson do { \
e7220c9b841bbd3d16736726f786a86fec3c0e18Evan Hunt isc_result_t _r; \
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt _r = algorithm_status(alg); \
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson if (_r != ISC_R_SUCCESS) \
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson return (_r); \
1aba9fe67899522364a9dbc3ee5a14da081f0314Evan Hunt } while (0); \
1aba9fe67899522364a9dbc3ee5a14da081f0314Evan Hunt
1aba9fe67899522364a9dbc3ee5a14da081f0314Evan Huntstatic void *
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updaterdefault_memalloc(void *arg, size_t size) {
1aba9fe67899522364a9dbc3ee5a14da081f0314Evan Hunt UNUSED(arg);
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater if (size == 0U)
1aba9fe67899522364a9dbc3ee5a14da081f0314Evan Hunt size = 1;
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson return (malloc(size));
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson}
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafssonstatic void
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Huntdefault_memfree(void *arg, void *ptr) {
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt UNUSED(arg);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt free(ptr);
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson}
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafssonisc_result_t
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafssondst_lib_init(isc_mem_t *mctx, isc_entropy_t *ectx, unsigned int eflags) {
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson isc_result_t result;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(mctx != NULL && ectx != NULL);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(dst_initialized == ISC_FALSE);
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson dst__memory_pool = NULL;
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson#ifdef OPENSSL
7693d4de8fca501dfe6989a7f30d8d3c86fe096aAndreas Gustafsson UNUSED(mctx);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt /*
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt * When using --with-openssl, there seems to be no good way of not
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt * leaking memory due to the openssl error handling mechanism.
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt * Avoid assertions by using a local memory context and not checking
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt * for leaks on exit. Note: as there are leaks we cannot use
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt * ISC_MEMFLAG_INTERNAL as it will free up memory still being used
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt * by libcrypto.
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews */
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews result = isc_mem_createx2(0, 0, default_memalloc, default_memfree,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews NULL, &dst__memory_pool, 0);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (result != ISC_R_SUCCESS)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (result);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_mem_setdestroycheck(dst__memory_pool, ISC_FALSE);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews#else
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt isc_mem_attach(mctx, &dst__memory_pool);
e80f661db8ec9596eb977d6fc537484aa3662e22Evan Hunt#endif
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt isc_entropy_attach(ectx, &dst_entropy_pool);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dst_entropy_flags = eflags;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
e80f661db8ec9596eb977d6fc537484aa3662e22Evan Hunt dst_result_register();
106360491ad40eef9669fd792c35710d6af1dab0Evan Hunt
cdbb3d27740fd052f18067b937097ebf35df356bAutomatic Updater memset(dst_t_func, 0, sizeof(dst_t_func));
28ad0be64ee756013c0f6a474fc447ee613ee0d1Evan Hunt RETERR(dst__hmacmd5_init(&dst_t_func[DST_ALG_HMACMD5]));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#ifdef OPENSSL
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt RETERR(dst__openssl_init());
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt RETERR(dst__opensslrsa_init(&dst_t_func[DST_ALG_RSAMD5]));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt RETERR(dst__opensslrsa_init(&dst_t_func[DST_ALG_RSASHA1]));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#ifdef HAVE_OPENSSL_DSA
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt RETERR(dst__openssldsa_init(&dst_t_func[DST_ALG_DSA]));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#endif
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt RETERR(dst__openssldh_init(&dst_t_func[DST_ALG_DH]));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#endif /* OPENSSL */
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt#ifdef GSSAPI
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt RETERR(dst__gssapi_init(&dst_t_func[DST_ALG_GSSAPI]));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews#endif
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dst_initialized = ISC_TRUE;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt return (ISC_R_SUCCESS);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt out:
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dst_lib_destroy();
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt return (result);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt}
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsvoid
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Huntdst_lib_destroy(void) {
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt int i;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt RUNTIME_CHECK(dst_initialized == ISC_TRUE);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dst_initialized = ISC_FALSE;
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt for (i = 0; i < DST_MAX_ALGS; i++)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (dst_t_func[i] != NULL && dst_t_func[i]->cleanup != NULL)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dst_t_func[i]->cleanup();
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson#ifdef OPENSSL
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews dst__openssl_destroy();
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews#endif
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews if (dst__memory_pool != NULL)
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews isc_mem_detach(&dst__memory_pool);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson if (dst_entropy_pool != NULL)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt isc_entropy_detach(&dst_entropy_pool);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt}
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
175a8bd2b798bbc568cd912b72c8a026cfca8527Mark Andrewsisc_boolean_t
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsdst_algorithm_supported(unsigned int alg) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(dst_initialized == ISC_TRUE);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (alg >= DST_MAX_ALGS || dst_t_func[alg] == NULL)
8bb77cd31b7518fb5d2a6a9d75e16e4abd59df61Andreas Gustafsson return (ISC_FALSE);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson return (ISC_TRUE);
d8d0c5b1bc97ac0f07e35a31b58ced80ce613c55David Lawrence}
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Huntisc_result_t
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Huntdst_context_create(dst_key_t *key, isc_mem_t *mctx, dst_context_t **dctxp) {
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dst_context_t *dctx;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt isc_result_t result;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(dst_initialized == ISC_TRUE);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(VALID_KEY(key));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(mctx != NULL);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(dctxp != NULL && *dctxp == NULL);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (key->func->createctx == NULL)
fc7043d7d1294478c9988c10af9a7fb8fd810338Evan Hunt return (DST_R_UNSUPPORTEDALG);
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt if (key->opaque == NULL)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt return (DST_R_NULLKEY);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dctx = isc_mem_get(mctx, sizeof(dst_context_t));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (dctx == NULL)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt return (ISC_R_NOMEMORY);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dctx->key = key;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt dctx->mctx = mctx;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt result = key->func->createctx(key, dctx);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (result != ISC_R_SUCCESS) {
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt isc_mem_put(mctx, dctx, sizeof(dst_context_t));
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt return (result);
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt }
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dctx->magic = CTX_MAGIC;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews *dctxp = dctx;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (ISC_R_SUCCESS);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews}
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsvoid
8bb77cd31b7518fb5d2a6a9d75e16e4abd59df61Andreas Gustafssondst_context_destroy(dst_context_t **dctxp) {
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson dst_context_t *dctx;
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence
114c14f8adfc249cf2e5cdcb9007af46fed257e3Mark Andrews REQUIRE(dctxp != NULL && VALID_CTX(*dctxp));
aeadcd63196f164b219629a53c0e0925519288f3Evan Hunt
aeadcd63196f164b219629a53c0e0925519288f3Evan Hunt dctx = *dctxp;
114c14f8adfc249cf2e5cdcb9007af46fed257e3Mark Andrews INSIST(dctx->key->func->destroyctx != NULL);
aeadcd63196f164b219629a53c0e0925519288f3Evan Hunt dctx->key->func->destroyctx(dctx);
114c14f8adfc249cf2e5cdcb9007af46fed257e3Mark Andrews dctx->magic = 0;
ba7ea2326d98edb4296098749fc9cf44b5157643David Lawrence isc_mem_put(dctx->mctx, dctx, sizeof(dst_context_t));
ba7ea2326d98edb4296098749fc9cf44b5157643David Lawrence *dctxp = NULL;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews}
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsisc_result_t
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsdst_context_adddata(dst_context_t *dctx, const isc_region_t *data) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(VALID_CTX(dctx));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(data != NULL);
aeadcd63196f164b219629a53c0e0925519288f3Evan Hunt INSIST(dctx->key->func->adddata != NULL);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson return (dctx->key->func->adddata(dctx, data));
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson}
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
aeadcd63196f164b219629a53c0e0925519288f3Evan Huntisc_result_t
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafssondst_context_sign(dst_context_t *dctx, isc_buffer_t *sig) {
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson dst_key_t *key;
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(VALID_CTX(dctx));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(sig != NULL);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt key = dctx->key;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt CHECKALG(key->key_alg);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (key->opaque == NULL)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt return (DST_R_NULLKEY);
584848087f7463c1f659ce4712dc047d8e7f2b07Francis Dupont if (key->func->sign == NULL)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt return (DST_R_NOTPRIVATEKEY);
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews if (key->func->isprivate == NULL ||
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt key->func->isprivate(key) == ISC_FALSE)
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews return (DST_R_NOTPRIVATEKEY);
12e0477d4e132c9122312246ed60aaa646f819b2Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (key->func->sign(dctx, sig));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews}
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsisc_result_t
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsdst_context_verify(dst_context_t *dctx, isc_region_t *sig) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(VALID_CTX(dctx));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(sig != NULL);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews CHECKALG(dctx->key->key_alg);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (dctx->key->opaque == NULL)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (DST_R_NULLKEY);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (dctx->key->func->verify == NULL)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (DST_R_NOTPUBLICKEY);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (dctx->key->func->verify(dctx, sig));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews}
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
e851ea826066ac5a5b01c2c23218faa0273a12e8Evan Huntisc_result_t
e851ea826066ac5a5b01c2c23218faa0273a12e8Evan Huntdst_key_computesecret(const dst_key_t *pub, const dst_key_t *priv,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_buffer_t *secret)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews{
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(dst_initialized == ISC_TRUE);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(VALID_KEY(pub) && VALID_KEY(priv));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(secret != NULL);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews CHECKALG(pub->key_alg);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews CHECKALG(priv->key_alg);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (pub->opaque == NULL || priv->opaque == NULL)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (DST_R_NULLKEY);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (pub->key_alg != priv->key_alg ||
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews pub->func->computesecret == NULL ||
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews priv->func->computesecret == NULL)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (DST_R_KEYCANNOTCOMPUTESECRET);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (dst_key_isprivate(priv) == ISC_FALSE)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (DST_R_NOTPRIVATEKEY);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (pub->func->computesecret(pub, priv, secret));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews}
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsisc_result_t
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updaterdst_key_tofile(const dst_key_t *key, int type, const char *directory) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_result_t ret = ISC_R_SUCCESS;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(dst_initialized == ISC_TRUE);
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt REQUIRE(VALID_KEY(key));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE((type & (DST_TYPE_PRIVATE | DST_TYPE_PUBLIC)) != 0);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews CHECKALG(key->key_alg);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (key->func->tofile == NULL)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (DST_R_UNSUPPORTEDALG);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (type & DST_TYPE_PUBLIC) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews ret = write_public_key(key, type, directory);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (ret != ISC_R_SUCCESS)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (ret);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews }
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if ((type & DST_TYPE_PRIVATE) &&
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews (key->key_flags & DNS_KEYFLAG_TYPEMASK) != DNS_KEYTYPE_NOKEY)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (key->func->tofile(key, directory));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews else
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (ISC_R_SUCCESS);
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater}
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsisc_result_t
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsdst_key_fromfile(dns_name_t *name, dns_keytag_t id,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews unsigned int alg, int type, const char *directory,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_mem_t *mctx, dst_key_t **keyp)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews{
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews char filename[ISC_DIR_NAMEMAX];
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_buffer_t b;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dst_key_t *key;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_result_t result;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(dst_initialized == ISC_TRUE);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(dns_name_isabsolute(name));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE((type & (DST_TYPE_PRIVATE | DST_TYPE_PUBLIC)) != 0);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(mctx != NULL);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(keyp != NULL && *keyp == NULL);
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews CHECKALG(alg);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt isc_buffer_init(&b, filename, sizeof(filename));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt result = buildfilename(name, id, alg, type, directory, &b);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (result != ISC_R_SUCCESS)
584848087f7463c1f659ce4712dc047d8e7f2b07Francis Dupont return (result);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt key = NULL;
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt result = dst_key_fromnamedfile(filename, type, mctx, &key);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (result != ISC_R_SUCCESS)
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson return (result);
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews result = computeid(key);
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews if (result != ISC_R_SUCCESS) {
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews dst_key_free(&key);
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews return (result);
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson }
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson if (!dns_name_equal(name, key->key_name) ||
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson id != key->key_id ||
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson alg != key->key_alg)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dst_key_free(&key);
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson return (DST_R_INVALIDPRIVATEKEY);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt }
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews key->key_id = id;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews *keyp = key;
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Hunt return (ISC_R_SUCCESS);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews}
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsisc_result_t
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsdst_key_fromnamedfile(const char *filename, int type, isc_mem_t *mctx,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dst_key_t **keyp)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews{
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_result_t result;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dst_key_t *pubkey = NULL, *key = NULL;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dns_keytag_t id;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews char *newfilename = NULL;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews int newfilenamelen = 0;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_lex_t *lex = NULL;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(dst_initialized == ISC_TRUE);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(filename != NULL);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE((type & (DST_TYPE_PRIVATE | DST_TYPE_PUBLIC)) != 0);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(mctx != NULL);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(keyp != NULL && *keyp == NULL);
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Hunt
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Hunt newfilenamelen = strlen(filename) + 5;
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Hunt newfilename = isc_mem_get(mctx, newfilenamelen);
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Hunt if (newfilename == NULL)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (ISC_R_NOMEMORY);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews result = addsuffix(newfilename, newfilenamelen, filename, ".key");
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews INSIST(result == ISC_R_SUCCESS);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater result = dst_key_read_public(newfilename, type, mctx, &pubkey);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_mem_put(mctx, newfilename, newfilenamelen);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (result != ISC_R_SUCCESS)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (result);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if ((type & (DST_TYPE_PRIVATE | DST_TYPE_PUBLIC)) == DST_TYPE_PUBLIC ||
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews (pubkey->key_flags & DNS_KEYFLAG_TYPEMASK) == DNS_KEYTYPE_NOKEY)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews result = computeid(pubkey);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (result != ISC_R_SUCCESS) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dst_key_free(&pubkey);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (result);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews }
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews *keyp = pubkey;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (ISC_R_SUCCESS);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews }
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews result = algorithm_status(pubkey->key_alg);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (result != ISC_R_SUCCESS) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dst_key_free(&pubkey);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (result);
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson }
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews key = get_key_struct(pubkey->key_name, pubkey->key_alg,
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater pubkey->key_flags, pubkey->key_proto, 0,
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson pubkey->key_class, mctx);
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater id = pubkey->key_id;
febaa091847ab004f40500cc475a819f2c73fcddAndreas Gustafsson dst_key_free(&pubkey);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence if (key == NULL)
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson return (ISC_R_NOMEMORY);
e7220c9b841bbd3d16736726f786a86fec3c0e18Evan Hunt
aa23a35d81a9618a40c4a9b44be48009553e4777Andreas Gustafsson if (key->func->parse == NULL)
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson RETERR(DST_R_UNSUPPORTEDALG);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson newfilenamelen = strlen(filename) + 9;
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson newfilename = isc_mem_get(mctx, newfilenamelen);
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence if (newfilename == NULL)
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson RETERR(ISC_R_NOMEMORY);
e7220c9b841bbd3d16736726f786a86fec3c0e18Evan Hunt result = addsuffix(newfilename, newfilenamelen, filename, ".private");
e7220c9b841bbd3d16736726f786a86fec3c0e18Evan Hunt INSIST(result == ISC_R_SUCCESS);
e7220c9b841bbd3d16736726f786a86fec3c0e18Evan Hunt
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson RETERR(isc_lex_create(mctx, 1500, &lex));
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson RETERR(isc_lex_openfile(lex, newfilename));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt isc_mem_put(mctx, newfilename, newfilenamelen);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
12e0477d4e132c9122312246ed60aaa646f819b2Mark Andrews RETERR(key->func->parse(key, lex));
12e0477d4e132c9122312246ed60aaa646f819b2Mark Andrews isc_lex_destroy(&lex);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson RETERR(computeid(key));
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson if (id != key->key_id)
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson RETERR(DST_R_INVALIDPRIVATEKEY);
ea419adc4eca4c3e44f2c282035b5dce6b795fe2Andreas Gustafsson
ea419adc4eca4c3e44f2c282035b5dce6b795fe2Andreas Gustafsson *keyp = key;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (ISC_R_SUCCESS);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews out:
aa23a35d81a9618a40c4a9b44be48009553e4777Andreas Gustafsson if (newfilename != NULL)
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson isc_mem_put(mctx, newfilename, newfilenamelen);
df925e6c66d45d960fbac0383169763967d2111cEvan Hunt if (lex != NULL)
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson isc_lex_destroy(&lex);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson dst_key_free(&key);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson return (result);
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence}
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
aa23a35d81a9618a40c4a9b44be48009553e4777Andreas Gustafssonisc_result_t
e7220c9b841bbd3d16736726f786a86fec3c0e18Evan Huntdst_key_todns(const dst_key_t *key, isc_buffer_t *target) {
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson REQUIRE(dst_initialized == ISC_TRUE);
e7220c9b841bbd3d16736726f786a86fec3c0e18Evan Hunt REQUIRE(VALID_KEY(key));
aa23a35d81a9618a40c4a9b44be48009553e4777Andreas Gustafsson REQUIRE(target != NULL);
aa23a35d81a9618a40c4a9b44be48009553e4777Andreas Gustafsson
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson CHECKALG(key->key_alg);
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson if (key->func->todns == NULL)
6017f424ee3c02d7f22132c77576ea38542fa949Andreas Gustafsson return (DST_R_UNSUPPORTEDALG);
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews if (isc_buffer_availablelength(target) < 4)
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews return (ISC_R_NOSPACE);
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews isc_buffer_putuint16(target, (isc_uint16_t)(key->key_flags & 0xffff));
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews isc_buffer_putuint8(target, (isc_uint8_t)key->key_proto);
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews isc_buffer_putuint8(target, (isc_uint8_t)key->key_alg);
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (key->key_flags & DNS_KEYFLAG_EXTENDED) {
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews if (isc_buffer_availablelength(target) < 2)
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson return (ISC_R_NOSPACE);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt isc_buffer_putuint16(target,
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt (isc_uint16_t)((key->key_flags >> 16)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt & 0xffff));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt }
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt if (key->opaque == NULL) /*%< NULL KEY */
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt return (ISC_R_SUCCESS);
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt return (key->func->todns(key, target));
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt}
b0bf1ad5b0b1d29b4cdf5de9789405aec5e0844cEvan Hunt
140a27777d6fba397720770b101967d5cf73f42bAutomatic Updaterisc_result_t
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrewsdst_key_fromdns(dns_name_t *name, dns_rdataclass_t rdclass,
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews{
140a27777d6fba397720770b101967d5cf73f42bAutomatic Updater isc_uint8_t alg, proto;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_uint32_t flags, extflags;
140a27777d6fba397720770b101967d5cf73f42bAutomatic Updater dst_key_t *key = NULL;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dns_keytag_t id;
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt isc_region_t r;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_result_t result;
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(dst_initialized);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson isc_buffer_remainingregion(source, &r);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt if (isc_buffer_remaininglength(source) < 4)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews return (DST_R_INVALIDPUBLICKEY);
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson flags = isc_buffer_getuint16(source);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews proto = isc_buffer_getuint8(source);
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson alg = isc_buffer_getuint8(source);
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt id = dst_region_computeid(&r, alg);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
262c39b2366bf79062f7f86b218947523dd1cbacEvan Hunt if (flags & DNS_KEYFLAG_EXTENDED) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews if (isc_buffer_remaininglength(source) < 2)
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson return (DST_R_INVALIDPUBLICKEY);
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson extflags = isc_buffer_getuint16(source);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt flags |= (extflags << 16);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt }
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater result = frombuffer(name, alg, flags, proto, rdclass, source,
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt mctx, &key);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt if (result != ISC_R_SUCCESS)
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt return (result);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt key->key_id = id;
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews *keyp = key;
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson return (ISC_R_SUCCESS);
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews}
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrewsisc_result_t
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrewsdst_key_frombuffer(dns_name_t *name, unsigned int alg,
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt unsigned int flags, unsigned int protocol,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dns_rdataclass_t rdclass,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp)
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews{
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews dst_key_t *key = NULL;
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews isc_result_t result;
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(dst_initialized);
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews
69f3cb5abcb38f105c653c7b3df7cec33b87b292Mark Andrews result = frombuffer(name, alg, flags, protocol, rdclass, source,
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews mctx, &key);
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Hunt if (result != ISC_R_SUCCESS)
2f012d936b5ccdf6520c96a4de23721dc58a2221Automatic Updater return (result);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson result = computeid(key);
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson if (result != ISC_R_SUCCESS) {
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson dst_key_free(&key);
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson return (result);
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson }
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson *keyp = key;
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson return (ISC_R_SUCCESS);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews}
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafssonisc_result_t
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafssondst_key_tobuffer(const dst_key_t *key, isc_buffer_t *target) {
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(dst_initialized == ISC_TRUE);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(VALID_KEY(key));
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews REQUIRE(target != NULL);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt CHECKALG(key->key_alg);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson if (key->func->todns == NULL)
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson return (DST_R_UNSUPPORTEDALG);
604419a812b491cd35fb6fad129c3c39da7200a1Mark Andrews
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson return (key->func->todns(key, target));
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson}
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafssonisc_result_t
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Huntdst_key_privatefrombuffer(dst_key_t *key, isc_buffer_t *buffer) {
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson isc_lex_t *lex = NULL;
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson isc_result_t result = ISC_R_SUCCESS;
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson
9c566a852f31c3a5d0b9d6eaf11463114339c01dAndreas Gustafsson REQUIRE(dst_initialized == ISC_TRUE);
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(VALID_KEY(key));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(!dst_key_isprivate(key));
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt REQUIRE(buffer != NULL);
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence if (key->func->parse == NULL)
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson RETERR(DST_R_UNSUPPORTEDALG);
e7220c9b841bbd3d16736726f786a86fec3c0e18Evan Hunt
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson RETERR(isc_lex_create(key->mctx, 1500, &lex));
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson RETERR(isc_lex_openbuffer(lex, buffer));
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson RETERR(key->func->parse(key, lex));
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson out:
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson if (lex != NULL)
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson isc_lex_destroy(&lex);
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson return (result);
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson}
6eccf5bd07eb9abf65cc08fec4a8fc97b62c0e1bBrian Wellington
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Huntisc_result_t
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Huntdst_key_fromgssapi(dns_name_t *name, void *opaque, isc_mem_t *mctx,
501941f0b6cce74c2ff75b10aff3f230d5d37e4cEvan Hunt dst_key_t **keyp)
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson{
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson dst_key_t *key;
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson REQUIRE(opaque != NULL);
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson REQUIRE(keyp != NULL && *keyp == NULL);
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson key = get_key_struct(name, DST_ALG_GSSAPI, 0, DNS_KEYPROTO_DNSSEC,
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson 0, dns_rdataclass_in, mctx);
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence if (key == NULL)
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence return (ISC_R_NOMEMORY);
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson key->opaque = opaque;
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson *keyp = key;
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson return (ISC_R_SUCCESS);
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson}
6eccf5bd07eb9abf65cc08fec4a8fc97b62c0e1bBrian Wellington
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafssonisc_result_t
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafssondst_key_generate(dns_name_t *name, unsigned int alg,
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence unsigned int bits, unsigned int param,
1a69a1a78cfaa86f3b68bbc965232b7876d4da2aDavid Lawrence unsigned int flags, unsigned int protocol,
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson dns_rdataclass_t rdclass,
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson isc_mem_t *mctx, dst_key_t **keyp)
a1747570262ed336c213aaf6bd31bc91993a46deAndreas Gustafsson{
dst_key_t *key;
isc_result_t ret;
REQUIRE(dst_initialized == ISC_TRUE);
REQUIRE(dns_name_isabsolute(name));
REQUIRE(mctx != NULL);
REQUIRE(keyp != NULL && *keyp == NULL);
CHECKALG(alg);
key = get_key_struct(name, alg, flags, protocol, bits, rdclass, mctx);
if (key == NULL)
return (ISC_R_NOMEMORY);
if (bits == 0) { /*%< NULL KEY */
key->key_flags |= DNS_KEYTYPE_NOKEY;
*keyp = key;
return (ISC_R_SUCCESS);
}
if (key->func->generate == NULL) {
dst_key_free(&key);
return (DST_R_UNSUPPORTEDALG);
}
ret = key->func->generate(key, param);
if (ret != ISC_R_SUCCESS) {
dst_key_free(&key);
return (ret);
}
ret = computeid(key);
if (ret != ISC_R_SUCCESS) {
dst_key_free(&key);
return (ret);
}
*keyp = key;
return (ISC_R_SUCCESS);
}
isc_boolean_t
dst_key_compare(const dst_key_t *key1, const dst_key_t *key2) {
REQUIRE(dst_initialized == ISC_TRUE);
REQUIRE(VALID_KEY(key1));
REQUIRE(VALID_KEY(key2));
if (key1 == key2)
return (ISC_TRUE);
if (key1 == NULL || key2 == NULL)
return (ISC_FALSE);
if (key1->key_alg == key2->key_alg &&
key1->key_id == key2->key_id &&
key1->func->compare != NULL &&
key1->func->compare(key1, key2) == ISC_TRUE)
return (ISC_TRUE);
else
return (ISC_FALSE);
}
isc_boolean_t
dst_key_paramcompare(const dst_key_t *key1, const dst_key_t *key2) {
REQUIRE(dst_initialized == ISC_TRUE);
REQUIRE(VALID_KEY(key1));
REQUIRE(VALID_KEY(key2));
if (key1 == key2)
return (ISC_TRUE);
if (key1 == NULL || key2 == NULL)
return (ISC_FALSE);
if (key1->key_alg == key2->key_alg &&
key1->func->paramcompare != NULL &&
key1->func->paramcompare(key1, key2) == ISC_TRUE)
return (ISC_TRUE);
else
return (ISC_FALSE);
}
void
dst_key_free(dst_key_t **keyp) {
isc_mem_t *mctx;
dst_key_t *key;
REQUIRE(dst_initialized == ISC_TRUE);
REQUIRE(keyp != NULL && VALID_KEY(*keyp));
key = *keyp;
mctx = key->mctx;
if (key->opaque != NULL) {
INSIST(key->func->destroy != NULL);
key->func->destroy(key);
}
dns_name_free(key->key_name, mctx);
isc_mem_put(mctx, key->key_name, sizeof(dns_name_t));
memset(key, 0, sizeof(dst_key_t));
isc_mem_put(mctx, key, sizeof(dst_key_t));
*keyp = NULL;
}
isc_boolean_t
dst_key_isprivate(const dst_key_t *key) {
REQUIRE(VALID_KEY(key));
INSIST(key->func->isprivate != NULL);
return (key->func->isprivate(key));
}
isc_result_t
dst_key_buildfilename(const dst_key_t *key, int type,
const char *directory, isc_buffer_t *out) {
REQUIRE(VALID_KEY(key));
REQUIRE(type == DST_TYPE_PRIVATE || type == DST_TYPE_PUBLIC ||
type == 0);
return (buildfilename(key->key_name, key->key_id, key->key_alg,
type, directory, out));
}
isc_result_t
dst_key_sigsize(const dst_key_t *key, unsigned int *n) {
REQUIRE(dst_initialized == ISC_TRUE);
REQUIRE(VALID_KEY(key));
REQUIRE(n != NULL);
/* XXXVIX this switch statement is too sparse to gen a jump table. */
switch (key->key_alg) {
case DST_ALG_RSAMD5:
case DST_ALG_RSASHA1:
*n = (key->key_size + 7) / 8;
break;
case DST_ALG_DSA:
*n = DNS_SIG_DSASIGSIZE;
break;
case DST_ALG_HMACMD5:
*n = 16;
break;
case DST_ALG_GSSAPI:
*n = 128; /*%< XXX */
break;
case DST_ALG_DH:
default:
return (DST_R_UNSUPPORTEDALG);
}
return (ISC_R_SUCCESS);
}
isc_result_t
dst_key_secretsize(const dst_key_t *key, unsigned int *n) {
REQUIRE(dst_initialized == ISC_TRUE);
REQUIRE(VALID_KEY(key));
REQUIRE(n != NULL);
if (key->key_alg == DST_ALG_DH)
*n = (key->key_size + 7) / 8;
else
return (DST_R_UNSUPPORTEDALG);
return (ISC_R_SUCCESS);
}
/***
*** Static methods
***/
/*%
* Allocates a key structure and fills in some of the fields.
*/
static dst_key_t *
get_key_struct(dns_name_t *name, unsigned int alg,
unsigned int flags, unsigned int protocol,
unsigned int bits, dns_rdataclass_t rdclass,
isc_mem_t *mctx)
{
dst_key_t *key;
isc_result_t result;
key = (dst_key_t *) isc_mem_get(mctx, sizeof(dst_key_t));
if (key == NULL)
return (NULL);
memset(key, 0, sizeof(dst_key_t));
key->magic = KEY_MAGIC;
key->key_name = isc_mem_get(mctx, sizeof(dns_name_t));
if (key->key_name == NULL) {
isc_mem_put(mctx, key, sizeof(dst_key_t));
return (NULL);
}
dns_name_init(key->key_name, NULL);
result = dns_name_dup(name, mctx, key->key_name);
if (result != ISC_R_SUCCESS) {
isc_mem_put(mctx, key->key_name, sizeof(dns_name_t));
isc_mem_put(mctx, key, sizeof(dst_key_t));
return (NULL);
}
key->key_alg = alg;
key->key_flags = flags;
key->key_proto = protocol;
key->mctx = mctx;
key->opaque = NULL;
key->key_size = bits;
key->key_class = rdclass;
key->func = dst_t_func[alg];
return (key);
}
/*%
* Reads a public key from disk
*/
isc_result_t
dst_key_read_public(const char *filename, int type,
isc_mem_t *mctx, dst_key_t **keyp)
{
u_char rdatabuf[DST_KEY_MAXSIZE];
isc_buffer_t b;
dns_fixedname_t name;
isc_lex_t *lex = NULL;
isc_token_t token;
isc_result_t ret;
dns_rdata_t rdata = DNS_RDATA_INIT;
unsigned int opt = ISC_LEXOPT_DNSMULTILINE;
dns_rdataclass_t rdclass = dns_rdataclass_in;
isc_lexspecials_t specials;
isc_uint32_t ttl;
isc_result_t result;
dns_rdatatype_t keytype;
/*
* Open the file and read its formatted contents
* File format:
* domain.name [ttl] [class] [KEY|DNSKEY] <flags> <protocol> <algorithm> <key>
*/
/* 1500 should be large enough for any key */
ret = isc_lex_create(mctx, 1500, &lex);
if (ret != ISC_R_SUCCESS)
goto cleanup;
memset(specials, 0, sizeof(specials));
specials['('] = 1;
specials[')'] = 1;
specials['"'] = 1;
isc_lex_setspecials(lex, specials);
isc_lex_setcomments(lex, ISC_LEXCOMMENT_DNSMASTERFILE);
ret = isc_lex_openfile(lex, filename);
if (ret != ISC_R_SUCCESS)
goto cleanup;
#define NEXTTOKEN(lex, opt, token) { \
ret = isc_lex_gettoken(lex, opt, token); \
if (ret != ISC_R_SUCCESS) \
goto cleanup; \
}
#define BADTOKEN() { \
ret = ISC_R_UNEXPECTEDTOKEN; \
goto cleanup; \
}
/* Read the domain name */
NEXTTOKEN(lex, opt, &token);
if (token.type != isc_tokentype_string)
BADTOKEN();
dns_fixedname_init(&name);
isc_buffer_init(&b, DST_AS_STR(token), strlen(DST_AS_STR(token)));
isc_buffer_add(&b, strlen(DST_AS_STR(token)));
ret = dns_name_fromtext(dns_fixedname_name(&name), &b, dns_rootname,
ISC_FALSE, NULL);
if (ret != ISC_R_SUCCESS)
goto cleanup;
/* Read the next word: either TTL, class, or 'KEY' */
NEXTTOKEN(lex, opt, &token);
/* If it's a TTL, read the next one */
result = dns_ttl_fromtext(&token.value.as_textregion, &ttl);
if (result == ISC_R_SUCCESS)
NEXTTOKEN(lex, opt, &token);
if (token.type != isc_tokentype_string)
BADTOKEN();
ret = dns_rdataclass_fromtext(&rdclass, &token.value.as_textregion);
if (ret == ISC_R_SUCCESS)
NEXTTOKEN(lex, opt, &token);
if (token.type != isc_tokentype_string)
BADTOKEN();
if (strcasecmp(DST_AS_STR(token), "DNSKEY") == 0)
keytype = dns_rdatatype_dnskey;
else if (strcasecmp(DST_AS_STR(token), "KEY") == 0)
keytype = dns_rdatatype_key; /*%< SIG(0), TKEY */
else
BADTOKEN();
if (((type & DST_TYPE_KEY) != 0 && keytype != dns_rdatatype_key) ||
((type & DST_TYPE_KEY) == 0 && keytype != dns_rdatatype_dnskey)) {
ret = DST_R_BADKEYTYPE;
goto cleanup;
}
isc_buffer_init(&b, rdatabuf, sizeof(rdatabuf));
ret = dns_rdata_fromtext(&rdata, rdclass, keytype, lex, NULL,
ISC_FALSE, mctx, &b, NULL);
if (ret != ISC_R_SUCCESS)
goto cleanup;
ret = dst_key_fromdns(dns_fixedname_name(&name), rdclass, &b, mctx,
keyp);
if (ret != ISC_R_SUCCESS)
goto cleanup;
cleanup:
if (lex != NULL)
isc_lex_destroy(&lex);
return (ret);
}
static isc_boolean_t
issymmetric(const dst_key_t *key) {
REQUIRE(dst_initialized == ISC_TRUE);
REQUIRE(VALID_KEY(key));
/* XXXVIX this switch statement is too sparse to gen a jump table. */
switch (key->key_alg) {
case DST_ALG_RSAMD5:
case DST_ALG_RSASHA1:
case DST_ALG_DSA:
case DST_ALG_DH:
return (ISC_FALSE);
case DST_ALG_HMACMD5:
case DST_ALG_GSSAPI:
return (ISC_TRUE);
default:
return (ISC_FALSE);
}
}
/*%
* Writes a public key to disk in DNS format.
*/
static isc_result_t
write_public_key(const dst_key_t *key, int type, const char *directory) {
FILE *fp;
isc_buffer_t keyb, textb, fileb, classb;
isc_region_t r;
char filename[ISC_DIR_NAMEMAX];
unsigned char key_array[DST_KEY_MAXSIZE];
char text_array[DST_KEY_MAXTEXTSIZE];
char class_array[10];
isc_result_t ret;
dns_rdata_t rdata = DNS_RDATA_INIT;
isc_fsaccess_t access;
REQUIRE(VALID_KEY(key));
isc_buffer_init(&keyb, key_array, sizeof(key_array));
isc_buffer_init(&textb, text_array, sizeof(text_array));
isc_buffer_init(&classb, class_array, sizeof(class_array));
ret = dst_key_todns(key, &keyb);
if (ret != ISC_R_SUCCESS)
return (ret);
isc_buffer_usedregion(&keyb, &r);
dns_rdata_fromregion(&rdata, key->key_class, dns_rdatatype_dnskey, &r);
ret = dns_rdata_totext(&rdata, (dns_name_t *) NULL, &textb);
if (ret != ISC_R_SUCCESS)
return (DST_R_INVALIDPUBLICKEY);
ret = dns_rdataclass_totext(key->key_class, &classb);
if (ret != ISC_R_SUCCESS)
return (DST_R_INVALIDPUBLICKEY);
/*
* Make the filename.
*/
isc_buffer_init(&fileb, filename, sizeof(filename));
ret = dst_key_buildfilename(key, DST_TYPE_PUBLIC, directory, &fileb);
if (ret != ISC_R_SUCCESS)
return (ret);
/*
* Create public key file.
*/
if ((fp = fopen(filename, "w")) == NULL)
return (DST_R_WRITEERROR);
if (issymmetric(key)) {
access = 0;
isc_fsaccess_add(ISC_FSACCESS_OWNER,
ISC_FSACCESS_READ | ISC_FSACCESS_WRITE,
&access);
(void)isc_fsaccess_set(filename, access);
}
ret = dns_name_print(key->key_name, fp);
if (ret != ISC_R_SUCCESS)
return (ret);
fprintf(fp, " ");
isc_buffer_usedregion(&classb, &r);
fwrite(r.base, 1, r.length, fp);
if ((type & DST_TYPE_KEY) != 0)
fprintf(fp, " KEY ");
else
fprintf(fp, " DNSKEY ");
isc_buffer_usedregion(&textb, &r);
fwrite(r.base, 1, r.length, fp);
fputc('\n', fp);
fclose(fp);
return (ISC_R_SUCCESS);
}
static isc_result_t
buildfilename(dns_name_t *name, dns_keytag_t id,
unsigned int alg, unsigned int type,
const char *directory, isc_buffer_t *out)
{
const char *suffix = "";
unsigned int len;
isc_result_t result;
REQUIRE(out != NULL);
if ((type & DST_TYPE_PRIVATE) != 0)
suffix = ".private";
else if (type == DST_TYPE_PUBLIC)
suffix = ".key";
if (directory != NULL) {
if (isc_buffer_availablelength(out) < strlen(directory))
return (ISC_R_NOSPACE);
isc_buffer_putstr(out, directory);
if (strlen(directory) > 0U &&
directory[strlen(directory) - 1] != '/')
isc_buffer_putstr(out, "/");
}
if (isc_buffer_availablelength(out) < 1)
return (ISC_R_NOSPACE);
isc_buffer_putstr(out, "K");
result = dns_name_tofilenametext(name, ISC_FALSE, out);
if (result != ISC_R_SUCCESS)
return (result);
len = 1 + 3 + 1 + 5 + strlen(suffix) + 1;
if (isc_buffer_availablelength(out) < len)
return (ISC_R_NOSPACE);
sprintf((char *) isc_buffer_used(out), "+%03d+%05d%s", alg, id, suffix);
isc_buffer_add(out, len);
return (ISC_R_SUCCESS);
}
static isc_result_t
computeid(dst_key_t *key) {
isc_buffer_t dnsbuf;
unsigned char dns_array[DST_KEY_MAXSIZE];
isc_region_t r;
isc_result_t ret;
isc_buffer_init(&dnsbuf, dns_array, sizeof(dns_array));
ret = dst_key_todns(key, &dnsbuf);
if (ret != ISC_R_SUCCESS)
return (ret);
isc_buffer_usedregion(&dnsbuf, &r);
key->key_id = dst_region_computeid(&r, key->key_alg);
return (ISC_R_SUCCESS);
}
static isc_result_t
frombuffer(dns_name_t *name, unsigned int alg, unsigned int flags,
unsigned int protocol, dns_rdataclass_t rdclass,
isc_buffer_t *source, isc_mem_t *mctx, dst_key_t **keyp)
{
dst_key_t *key;
isc_result_t ret;
REQUIRE(dns_name_isabsolute(name));
REQUIRE(source != NULL);
REQUIRE(mctx != NULL);
REQUIRE(keyp != NULL && *keyp == NULL);
key = get_key_struct(name, alg, flags, protocol, 0, rdclass, mctx);
if (key == NULL)
return (ISC_R_NOMEMORY);
if (isc_buffer_remaininglength(source) > 0) {
ret = algorithm_status(alg);
if (ret != ISC_R_SUCCESS) {
dst_key_free(&key);
return (ret);
}
if (key->func->fromdns == NULL) {
dst_key_free(&key);
return (DST_R_UNSUPPORTEDALG);
}
ret = key->func->fromdns(key, source);
if (ret != ISC_R_SUCCESS) {
dst_key_free(&key);
return (ret);
}
}
*keyp = key;
return (ISC_R_SUCCESS);
}
static isc_result_t
algorithm_status(unsigned int alg) {
REQUIRE(dst_initialized == ISC_TRUE);
if (dst_algorithm_supported(alg))
return (ISC_R_SUCCESS);
#ifndef OPENSSL
if (alg == DST_ALG_RSAMD5 || alg == DST_ALG_RSASHA1 ||
alg == DST_ALG_DSA || alg == DST_ALG_DH ||
alg == DST_ALG_HMACMD5)
return (DST_R_NOCRYPTO);
#endif
return (DST_R_UNSUPPORTEDALG);
}
static isc_result_t
addsuffix(char *filename, unsigned int len, const char *ofilename,
const char *suffix)
{
int olen = strlen(ofilename);
int n;
if (olen > 1 && ofilename[olen - 1] == '.')
olen -= 1;
else if (olen > 8 && strcmp(ofilename + olen - 8, ".private") == 0)
olen -= 8;
else if (olen > 4 && strcmp(ofilename + olen - 4, ".key") == 0)
olen -= 4;
n = snprintf(filename, len, "%.*s%s", olen, ofilename, suffix);
if (n < 0)
return (ISC_R_NOSPACE);
return (ISC_R_SUCCESS);
}
isc_result_t
dst__entropy_getdata(void *buf, unsigned int len, isc_boolean_t pseudo) {
unsigned int flags = dst_entropy_flags;
if (pseudo)
flags &= ~ISC_ENTROPY_GOODONLY;
return (isc_entropy_getdata(dst_entropy_pool, buf, len, NULL, flags));
}