9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington/*
9eb24f1f84885d5c2e51a7f675264db398c31af7Tinderbox User * Copyright (C) 2000, 2001, 2004-2007, 2009, 2013-2018 Internet Systems Consortium, Inc. ("ISC")
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence *
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews * This Source Code Form is subject to the terms of the Mozilla Public
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews * License, v. 2.0. If a copy of the MPL was not distributed with this
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews * file, You can obtain one at http://mozilla.org/MPL/2.0/.
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington */
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
53f0234c3e3a845245042affb1f20a189d8791b9Automatic Updater/* $Id: hmacmd5.c,v 1.16 2009/02/06 23:47:42 tbox Exp $ */
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein/*! \file
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington * This code implements the HMAC-MD5 keyed hash algorithm
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein * described in RFC2104.
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington */
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#include "config.h"
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#include <pk11/site.h>
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#ifndef PK11_MD5_DISABLE
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#include <isc/assertions.h>
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#include <isc/hmacmd5.h>
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#include <isc/md5.h>
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont#include <isc/platform.h>
5b7abbef511cea0b568be0bc8d5b3120a0b9034dEvan Hunt#include <isc/safe.h>
976f44baa3028118a4175a21536e68049e1d3766David Lawrence#include <isc/string.h>
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#include <isc/types.h>
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#include <isc/util.h>
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#if PKCS11CRYPTO
dbb012765c735ee0d82dedb116cdc7cf18957814Evan Hunt#include <pk11/internal.h>
dbb012765c735ee0d82dedb116cdc7cf18957814Evan Hunt#include <pk11/pk11.h>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt#endif
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont#ifdef ISC_PLATFORM_OPENSSLHASH
22bed621ef87bc8b6c1fea599b02c4b38dd6bf48Mark Andrews#if OPENSSL_VERSION_NUMBER < 0x10100000L || defined(LIBRESSL_VERSION_NUMBER)
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews#define HMAC_CTX_new() &(ctx->_ctx), HMAC_CTX_init(&(ctx->_ctx))
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews#define HMAC_CTX_free(ptr) HMAC_CTX_cleanup(ptr)
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews#endif
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupontvoid
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupontisc_hmacmd5_init(isc_hmacmd5_t *ctx, const unsigned char *key,
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont unsigned int len)
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont{
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews ctx->ctx = HMAC_CTX_new();
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews RUNTIME_CHECK(ctx->ctx != NULL);
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews RUNTIME_CHECK(HMAC_Init_ex(ctx->ctx, (const void *) key,
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews (int) len, EVP_md5(), NULL) == 1);
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont}
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupontvoid
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupontisc_hmacmd5_invalidate(isc_hmacmd5_t *ctx) {
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews if (ctx->ctx == NULL)
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews return;
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews HMAC_CTX_free(ctx->ctx);
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews ctx->ctx = NULL;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont}
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupontvoid
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupontisc_hmacmd5_update(isc_hmacmd5_t *ctx, const unsigned char *buf,
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont unsigned int len)
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont{
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews RUNTIME_CHECK(HMAC_Update(ctx->ctx, buf, (int) len) == 1);
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont}
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupontvoid
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupontisc_hmacmd5_sign(isc_hmacmd5_t *ctx, unsigned char *digest) {
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews RUNTIME_CHECK(HMAC_Final(ctx->ctx, digest, NULL) == 1);
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews HMAC_CTX_free(ctx->ctx);
76af83c9adb772f7b045c62cf8b411165bfaa5efMark Andrews ctx->ctx = NULL;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont}
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#elif PKCS11CRYPTO
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#ifndef PK11_MD5_HMAC_REPLACE
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntstatic CK_BBOOL truevalue = TRUE;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntstatic CK_BBOOL falsevalue = FALSE;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntvoid
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntisc_hmacmd5_init(isc_hmacmd5_t *ctx, const unsigned char *key,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt unsigned int len)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt{
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_RV rv;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_MECHANISM mech = { CKM_MD5_HMAC, NULL, 0 };
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_OBJECT_CLASS keyClass = CKO_SECRET_KEY;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_KEY_TYPE keyType = CKK_MD5_HMAC;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_ATTRIBUTE keyTemplate[] =
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt {
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt { CKA_CLASS, &keyClass, (CK_ULONG) sizeof(keyClass) },
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt { CKA_KEY_TYPE, &keyType, (CK_ULONG) sizeof(keyType) },
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt { CKA_TOKEN, &falsevalue, (CK_ULONG) sizeof(falsevalue) },
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt { CKA_PRIVATE, &falsevalue, (CK_ULONG) sizeof(falsevalue) },
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt { CKA_SIGN, &truevalue, (CK_ULONG) sizeof(truevalue) },
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt { CKA_VALUE, NULL, (CK_ULONG) len }
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt };
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont#ifdef PK11_PAD_HMAC_KEYS
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont CK_BYTE keypad[ISC_MD5_DIGESTLENGTH];
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont if (len < ISC_MD5_DIGESTLENGTH) {
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont memset(keypad, 0, ISC_MD5_DIGESTLENGTH);
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont memmove(keypad, key, len);
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont keyTemplate[5].pValue = keypad;
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont keyTemplate[5].ulValueLen = ISC_MD5_DIGESTLENGTH;
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont } else
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont DE_CONST(key, keyTemplate[5].pValue);
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont#else
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt DE_CONST(key, keyTemplate[5].pValue);
78608b0a454246d0e1e0169f1d671b8427e48199Francis Dupont#endif
acbb301e648b82fcc38b876a44403cf0fe539cc9Evan Hunt RUNTIME_CHECK(pk11_get_session(ctx, OP_DIGEST, ISC_TRUE, ISC_FALSE,
acbb301e648b82fcc38b876a44403cf0fe539cc9Evan Hunt ISC_FALSE, NULL, 0) == ISC_R_SUCCESS);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt ctx->object = CK_INVALID_HANDLE;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_CreateObject,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, keyTemplate,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (CK_ULONG) 6, &ctx->object));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt INSIST(ctx->object != CK_INVALID_HANDLE);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_SignInit, (ctx->session, &mech, ctx->object));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt}
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntvoid
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntisc_hmacmd5_invalidate(isc_hmacmd5_t *ctx) {
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_BYTE garbage[ISC_MD5_DIGESTLENGTH];
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_ULONG len = ISC_MD5_DIGESTLENGTH;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt if (ctx->handle == NULL)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt return;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (void) pkcs_C_SignFinal(ctx->session, garbage, &len);
b5252fcde512405a68dd4becfe683d9763bd0feaMukund Sivaraman isc_safe_memwipe(garbage, sizeof(garbage));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt if (ctx->object != CK_INVALID_HANDLE)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (void) pkcs_C_DestroyObject(ctx->session, ctx->object);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt ctx->object = CK_INVALID_HANDLE;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt pk11_return_session(ctx);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt}
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntvoid
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntisc_hmacmd5_update(isc_hmacmd5_t *ctx, const unsigned char *buf,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt unsigned int len)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt{
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_RV rv;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_BYTE_PTR pPart;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt DE_CONST(buf, pPart);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_SignUpdate,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, pPart, (CK_ULONG) len));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt}
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntvoid
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntisc_hmacmd5_sign(isc_hmacmd5_t *ctx, unsigned char *digest) {
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_RV rv;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_ULONG len = ISC_MD5_DIGESTLENGTH;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_SignFinal,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, (CK_BYTE_PTR) digest, &len));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt if (ctx->object != CK_INVALID_HANDLE)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (void) pkcs_C_DestroyObject(ctx->session, ctx->object);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt ctx->object = CK_INVALID_HANDLE;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt pk11_return_session(ctx);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt}
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#else
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews/* Replace missing CKM_MD5_HMAC PKCS#11 mechanism */
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt#define PADLEN 64
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt#define IPAD 0x36
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt#define OPAD 0x5C
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntvoid
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntisc_hmacmd5_init(isc_hmacmd5_t *ctx, const unsigned char *key,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt unsigned int len)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt{
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_RV rv;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_MECHANISM mech = { CKM_MD5, NULL, 0 };
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt unsigned char ipad[PADLEN];
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt unsigned int i;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
acbb301e648b82fcc38b876a44403cf0fe539cc9Evan Hunt RUNTIME_CHECK(pk11_get_session(ctx, OP_DIGEST, ISC_TRUE, ISC_FALSE,
acbb301e648b82fcc38b876a44403cf0fe539cc9Evan Hunt ISC_FALSE, NULL, 0) == ISC_R_SUCCESS);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt RUNTIME_CHECK((ctx->key = pk11_mem_get(PADLEN)) != NULL);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt if (len > PADLEN) {
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_BYTE_PTR kPart;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_ULONG kl;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestInit, (ctx->session, &mech));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt DE_CONST(key, kPart);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestUpdate,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, kPart, (CK_ULONG) len));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt kl = ISC_MD5_DIGESTLENGTH;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestFinal,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, (CK_BYTE_PTR) ctx->key, &kl));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt } else
1b255a0c4eaccf0feff70328a8c108a22abfbf3cEvan Hunt memmove(ctx->key, key, len);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestInit, (ctx->session, &mech));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt memset(ipad, IPAD, PADLEN);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt for (i = 0; i < PADLEN; i++)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt ipad[i] ^= ctx->key[i];
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestUpdate,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, ipad, (CK_ULONG) PADLEN));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt}
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntvoid
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntisc_hmacmd5_invalidate(isc_hmacmd5_t *ctx) {
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt if (ctx->key != NULL)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt pk11_mem_put(ctx->key, PADLEN);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt ctx->key = NULL;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt isc_md5_invalidate(ctx);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt}
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntvoid
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntisc_hmacmd5_update(isc_hmacmd5_t *ctx, const unsigned char *buf,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt unsigned int len)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt{
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_RV rv;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_BYTE_PTR pPart;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt DE_CONST(buf, pPart);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestUpdate,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, pPart, (CK_ULONG) len));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt}
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntvoid
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Huntisc_hmacmd5_sign(isc_hmacmd5_t *ctx, unsigned char *digest) {
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_RV rv;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_MECHANISM mech = { CKM_MD5, NULL, 0 };
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_ULONG len = ISC_MD5_DIGESTLENGTH;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt CK_BYTE opad[PADLEN];
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt unsigned int i;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestFinal,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, (CK_BYTE_PTR) digest,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (CK_ULONG_PTR) &len));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt memset(opad, OPAD, PADLEN);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt for (i = 0; i < PADLEN; i++)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt opad[i] ^= ctx->key[i];
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt pk11_mem_put(ctx->key, PADLEN);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt ctx->key = NULL;
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestInit, (ctx->session, &mech));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestUpdate,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, opad, (CK_ULONG) PADLEN));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestUpdate,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session, (CK_BYTE_PTR) digest, len));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt PK11_FATALCHECK(pkcs_C_DigestFinal,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (ctx->session,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (CK_BYTE_PTR) digest,
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt (CK_ULONG_PTR) &len));
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt pk11_return_session(ctx);
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt}
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#endif
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont#else
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#define PADLEN 64
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#define IPAD 0x36
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington#define OPAD 0x5C
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein/*!
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington * Start HMAC-MD5 process. Initialize an md5 context and digest the key.
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington */
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonvoid
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonisc_hmacmd5_init(isc_hmacmd5_t *ctx, const unsigned char *key,
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington unsigned int len)
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington{
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington unsigned char ipad[PADLEN];
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington int i;
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
91cd0f93ad34d23e8b09dca337120f64fbe8f0a1Andreas Gustafsson memset(ctx->key, 0, sizeof(ctx->key));
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington if (len > sizeof(ctx->key)) {
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_t md5ctx;
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_init(&md5ctx);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_update(&md5ctx, key, len);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_final(&md5ctx, ctx->key);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington } else
e851ea826066ac5a5b01c2c23218faa0273a12e8Evan Hunt memmove(ctx->key, key, len);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_init(&ctx->md5ctx);
91cd0f93ad34d23e8b09dca337120f64fbe8f0a1Andreas Gustafsson memset(ipad, IPAD, sizeof(ipad));
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington for (i = 0; i < PADLEN; i++)
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington ipad[i] ^= ctx->key[i];
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_update(&ctx->md5ctx, ipad, sizeof(ipad));
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington}
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonvoid
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonisc_hmacmd5_invalidate(isc_hmacmd5_t *ctx) {
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_invalidate(&ctx->md5ctx);
b5252fcde512405a68dd4becfe683d9763bd0feaMukund Sivaraman isc_safe_memwipe(ctx->key, sizeof(ctx->key));
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington}
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein/*!
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington * Update context to reflect the concatenation of another buffer full
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington * of bytes.
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington */
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonvoid
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonisc_hmacmd5_update(isc_hmacmd5_t *ctx, const unsigned char *buf,
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington unsigned int len)
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington{
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_update(&ctx->md5ctx, buf, len);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington}
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein/*!
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington * Compute signature - finalize MD5 operation and reapply MD5.
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington */
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonvoid
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonisc_hmacmd5_sign(isc_hmacmd5_t *ctx, unsigned char *digest) {
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington unsigned char opad[PADLEN];
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington int i;
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_final(&ctx->md5ctx, digest);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
91cd0f93ad34d23e8b09dca337120f64fbe8f0a1Andreas Gustafsson memset(opad, OPAD, sizeof(opad));
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington for (i = 0; i < PADLEN; i++)
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington opad[i] ^= ctx->key[i];
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_init(&ctx->md5ctx);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_update(&ctx->md5ctx, opad, sizeof(opad));
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_update(&ctx->md5ctx, digest, ISC_MD5_DIGESTLENGTH);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_md5_final(&ctx->md5ctx, digest);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_hmacmd5_invalidate(ctx);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington}
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont#endif /* !ISC_PLATFORM_OPENSSLHASH */
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein/*!
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington * Verify signature - finalize MD5 operation and reapply MD5, then
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington * compare to the supplied digest.
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington */
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonisc_boolean_t
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellingtonisc_hmacmd5_verify(isc_hmacmd5_t *ctx, unsigned char *digest) {
c6d4f781529d2f28693546b25b2967d44ec89e60Mark Andrews return (isc_hmacmd5_verify2(ctx, digest, ISC_MD5_DIGESTLENGTH));
c6d4f781529d2f28693546b25b2967d44ec89e60Mark Andrews}
c6d4f781529d2f28693546b25b2967d44ec89e60Mark Andrews
c6d4f781529d2f28693546b25b2967d44ec89e60Mark Andrewsisc_boolean_t
c6d4f781529d2f28693546b25b2967d44ec89e60Mark Andrewsisc_hmacmd5_verify2(isc_hmacmd5_t *ctx, unsigned char *digest, size_t len) {
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington unsigned char newdigest[ISC_MD5_DIGESTLENGTH];
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington
c6d4f781529d2f28693546b25b2967d44ec89e60Mark Andrews REQUIRE(len <= ISC_MD5_DIGESTLENGTH);
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington isc_hmacmd5_sign(ctx, newdigest);
420a43c8d8028992a4e9c170022f97bfac689025Evan Hunt return (isc_safe_memequal(digest, newdigest, len));
9c4cba349f52bb8176c3858b2b5b340f13603802Brian Wellington}
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont/*
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont * Check for MD5 support; if it does not work, raise a fatal error.
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont *
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont * Use the first test vector from RFC 2104, with a second round using
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont * a too-short key.
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont *
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont * Standard use is testing 0 and expecting result true.
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont * Testing use is testing 1..4 and expecting result false.
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont */
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupontisc_boolean_t
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupontisc_hmacmd5_check(int testing) {
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont isc_hmacmd5_t ctx;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont unsigned char key[] = { /* 0x0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b */
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b,
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont };
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont unsigned char input[] = { /* "Hi There" */
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont 0x48, 0x69, 0x20, 0x54, 0x68, 0x65, 0x72, 0x65
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont };
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont unsigned char expected[] = {
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont 0x92, 0x94, 0x72, 0x7a, 0x36, 0x38, 0xbb, 0x1c,
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont 0x13, 0xf4, 0x8e, 0xf8, 0x15, 0x8b, 0xfc, 0x9d
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont };
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont unsigned char expected2[] = {
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont 0xad, 0xb8, 0x48, 0x05, 0xb8, 0x8d, 0x03, 0xe5,
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont 0x90, 0x1e, 0x4b, 0x05, 0x69, 0xce, 0x35, 0xea
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont };
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont isc_boolean_t result;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont /*
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont * Introduce a fault for testing.
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont */
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont switch (testing) {
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont case 0:
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont default:
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont break;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont case 1:
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont key[0] ^= 0x01;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont break;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont case 2:
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont input[0] ^= 0x01;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont break;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont case 3:
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont expected[0] ^= 0x01;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont break;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont case 4:
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont expected2[0] ^= 0x01;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont break;
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont }
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont /*
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont * These functions do not return anything; any failure will be fatal.
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont */
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont isc_hmacmd5_init(&ctx, key, 16U);
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont isc_hmacmd5_update(&ctx, input, 8U);
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont result = isc_hmacmd5_verify2(&ctx, expected, sizeof(expected));
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont if (!result) {
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont return (result);
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont }
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont /* Second round using a byte key */
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont isc_hmacmd5_init(&ctx, key, 1U);
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont isc_hmacmd5_update(&ctx, input, 8U);
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont return (isc_hmacmd5_verify2(&ctx, expected2, sizeof(expected2)));
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont}
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupont
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#else /* !PK11_MD5_DISABLE */
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#ifdef WIN32
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews/* Make the Visual Studio linker happy */
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#include <isc/util.h>
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrewsvoid isc_hmacmd5_init() { INSIST(0); }
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrewsvoid isc_hmacmd5_invalidate() { INSIST(0); }
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrewsvoid isc_hmacmd5_sign() { INSIST(0); }
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrewsvoid isc_hmacmd5_update() { INSIST(0); }
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrewsvoid isc_hmacmd5_verify() { INSIST(0); }
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrewsvoid isc_hmacmd5_verify2() { INSIST(0); }
f9c410d93711fbf312a0162f1e2d3f2a5ede69afFrancis Dupontvoid isc_hmacmd5_check() { INSIST(0); }
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#endif
c40906dfad6dd6e3a3e3c94b8c8847bc9bc064e5Mark Andrews#endif /* PK11_MD5_DISABLE */