xs_openssl.h 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261
  1. /* copyright (c) 2022 grunfink - MIT license */
  2. #ifndef _XS_OPENSSL_H
  3. #define _XS_OPENSSL_H
  4. d_char *xs_md5_hex(const void *input, int size);
  5. d_char *xs_sha1_hex(const void *input, int size);
  6. d_char *xs_sha256_hex(const void *input, int size);
  7. d_char *xs_sha256_base64(const void *input, int size);
  8. d_char *xs_rsa_genkey(int bits);
  9. d_char *xs_rsa_sign(char *secret, char *mem, int size);
  10. int xs_rsa_verify(char *pubkey, char *mem, int size, char *b64sig);
  11. d_char *xs_evp_sign(char *secret, char *mem, int size);
  12. int xs_evp_verify(char *pubkey, char *mem, int size, char *b64sig);
  13. #ifdef XS_IMPLEMENTATION
  14. #include "openssl/md5.h"
  15. #include "openssl/sha.h"
  16. #include "openssl/rsa.h"
  17. #include "openssl/pem.h"
  18. #include "openssl/evp.h"
  19. d_char *xs_md5_hex(const void *input, int size)
  20. {
  21. unsigned char md5[16];
  22. MD5_CTX ctx;
  23. MD5_Init(&ctx);
  24. MD5_Update(&ctx, input, size);
  25. MD5_Final(md5, &ctx);
  26. return xs_hex_enc((char *)md5, sizeof(md5));
  27. }
  28. d_char *xs_sha1_hex(const void *input, int size)
  29. {
  30. unsigned char sha1[20];
  31. SHA_CTX ctx;
  32. SHA1_Init(&ctx);
  33. SHA1_Update(&ctx, input, size);
  34. SHA1_Final(sha1, &ctx);
  35. return xs_hex_enc((char *)sha1, sizeof(sha1));
  36. }
  37. unsigned char *_xs_sha256(const void *input, int size, unsigned char *sha256)
  38. {
  39. SHA256_CTX ctx;
  40. SHA256_Init(&ctx);
  41. SHA256_Update(&ctx, input, size);
  42. SHA256_Final(sha256, &ctx);
  43. return sha256;
  44. }
  45. d_char *xs_sha256_hex(const void *input, int size)
  46. {
  47. unsigned char sha256[32];
  48. _xs_sha256(input, size, sha256);
  49. return xs_hex_enc((char *)sha256, sizeof(sha256));
  50. }
  51. d_char *xs_sha256_base64(const void *input, int size)
  52. {
  53. unsigned char sha256[32];
  54. _xs_sha256(input, size, sha256);
  55. return xs_base64_enc((char *)sha256, sizeof(sha256));
  56. }
  57. d_char *xs_rsa_genkey(int bits)
  58. /* generates an RSA keypair */
  59. {
  60. BIGNUM *bne;
  61. RSA *rsa;
  62. d_char *keypair = NULL;
  63. if ((bne = BN_new()) != NULL) {
  64. if (BN_set_word(bne, RSA_F4) == 1) {
  65. if ((rsa = RSA_new()) != NULL) {
  66. if (RSA_generate_key_ex(rsa, bits, bne, NULL) == 1) {
  67. BIO *bs = BIO_new(BIO_s_mem());
  68. BIO *bp = BIO_new(BIO_s_mem());
  69. BUF_MEM *sptr;
  70. BUF_MEM *pptr;
  71. PEM_write_bio_RSAPrivateKey(bs, rsa, NULL, NULL, 0, 0, NULL);
  72. BIO_get_mem_ptr(bs, &sptr);
  73. PEM_write_bio_RSA_PUBKEY(bp, rsa);
  74. BIO_get_mem_ptr(bp, &pptr);
  75. keypair = xs_dict_new();
  76. keypair = xs_dict_append(keypair, "secret", sptr->data);
  77. keypair = xs_dict_append(keypair, "public", pptr->data);
  78. BIO_free(bs);
  79. BIO_free(bp);
  80. }
  81. }
  82. }
  83. }
  84. return keypair;
  85. }
  86. d_char *xs_rsa_sign(char *secret, char *mem, int size)
  87. /* signs a memory block (secret is in PEM format) */
  88. {
  89. d_char *signature = NULL;
  90. BIO *b;
  91. RSA *rsa;
  92. unsigned char *sig;
  93. unsigned int sig_len;
  94. /* un-PEM the key */
  95. b = BIO_new_mem_buf(secret, strlen(secret));
  96. rsa = PEM_read_bio_RSAPrivateKey(b, NULL, NULL, NULL);
  97. /* alloc space */
  98. sig = malloc(RSA_size(rsa));
  99. if (RSA_sign(NID_sha256, (unsigned char *)mem, size, sig, &sig_len, rsa) == 1)
  100. signature = xs_base64_enc((char *)sig, sig_len);
  101. BIO_free(b);
  102. RSA_free(rsa);
  103. free(sig);
  104. return signature;
  105. }
  106. int xs_rsa_verify(char *pubkey, char *mem, int size, char *b64sig)
  107. /* verifies a base64 block, returns non-zero on ok */
  108. {
  109. int r = 0;
  110. BIO *b;
  111. RSA *rsa;
  112. /* un-PEM the key */
  113. b = BIO_new_mem_buf(pubkey, strlen(pubkey));
  114. rsa = PEM_read_bio_RSA_PUBKEY(b, NULL, NULL, NULL);
  115. if (rsa != NULL) {
  116. xs *sig = NULL;
  117. int s_size;
  118. /* de-base64 */
  119. sig = xs_base64_dec(b64sig, &s_size);
  120. if (sig != NULL)
  121. r = RSA_verify(NID_sha256, (unsigned char *)mem, size,
  122. (unsigned char *)sig, s_size, rsa);
  123. }
  124. BIO_free(b);
  125. RSA_free(rsa);
  126. return r;
  127. }
  128. d_char *xs_evp_sign(char *secret, char *mem, int size)
  129. /* signs a memory block (secret is in PEM format) */
  130. {
  131. d_char *signature = NULL;
  132. BIO *b;
  133. unsigned char *sig;
  134. unsigned int sig_len;
  135. EVP_PKEY *pkey;
  136. EVP_MD_CTX *mdctx;
  137. const EVP_MD *md;
  138. /* un-PEM the key */
  139. b = BIO_new_mem_buf(secret, strlen(secret));
  140. pkey = PEM_read_bio_PrivateKey(b, NULL, NULL, NULL);
  141. /* I've learnt all these magical incantations by watching
  142. the Python module code and the OpenSSL manual pages */
  143. /* Well, "learnt" may be an overstatement */
  144. md = EVP_get_digestbyname("sha256");
  145. mdctx = EVP_MD_CTX_new();
  146. sig_len = EVP_PKEY_size(pkey);
  147. sig = malloc(sig_len);
  148. EVP_SignInit(mdctx, md);
  149. EVP_SignUpdate(mdctx, mem, size);
  150. if (EVP_SignFinal(mdctx, sig, &sig_len, pkey) == 1)
  151. signature = xs_base64_enc((char *)sig, sig_len);
  152. EVP_MD_CTX_free(mdctx);
  153. EVP_PKEY_free(pkey);
  154. BIO_free(b);
  155. free(sig);
  156. return signature;
  157. }
  158. int xs_evp_verify(char *pubkey, char *mem, int size, char *b64sig)
  159. /* verifies a base64 block, returns non-zero on ok */
  160. {
  161. int r = 0;
  162. BIO *b;
  163. EVP_PKEY *pkey;
  164. EVP_MD_CTX *mdctx;
  165. const EVP_MD *md;
  166. /* un-PEM the key */
  167. b = BIO_new_mem_buf(pubkey, strlen(pubkey));
  168. pkey = PEM_read_bio_PUBKEY(b, NULL, NULL, NULL);
  169. md = EVP_get_digestbyname("sha256");
  170. mdctx = EVP_MD_CTX_new();
  171. if (pkey != NULL) {
  172. xs *sig = NULL;
  173. int s_size;
  174. /* de-base64 */
  175. sig = xs_base64_dec(b64sig, &s_size);
  176. if (sig != NULL) {
  177. EVP_VerifyInit(mdctx, md);
  178. EVP_VerifyUpdate(mdctx, mem, size);
  179. r = EVP_VerifyFinal(mdctx, (unsigned char *)sig, s_size, pkey);
  180. }
  181. }
  182. EVP_MD_CTX_free(mdctx);
  183. EVP_PKEY_free(pkey);
  184. BIO_free(b);
  185. return r;
  186. }
  187. #endif /* XS_IMPLEMENTATION */
  188. #endif /* _XS_OPENSSL_H */