1 /* 2 * validator/val_secalgo.c - validator security algorithm functions. 3 * 4 * Copyright (c) 2012, NLnet Labs. All rights reserved. 5 * 6 * This software is open source. 7 * 8 * Redistribution and use in source and binary forms, with or without 9 * modification, are permitted provided that the following conditions 10 * are met: 11 * 12 * Redistributions of source code must retain the above copyright notice, 13 * this list of conditions and the following disclaimer. 14 * 15 * Redistributions in binary form must reproduce the above copyright notice, 16 * this list of conditions and the following disclaimer in the documentation 17 * and/or other materials provided with the distribution. 18 * 19 * Neither the name of the NLNET LABS nor the names of its contributors may 20 * be used to endorse or promote products derived from this software without 21 * specific prior written permission. 22 * 23 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 24 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT 25 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR 26 * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT 27 * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 28 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED 29 * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR 30 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF 31 * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING 32 * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS 33 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 34 */ 35 36 /** 37 * \file 38 * 39 * This file contains helper functions for the validator module. 40 * These functions take raw data buffers, formatted for crypto verification, 41 * and do the library calls (for the crypto library in use). 42 */ 43 #include "config.h" 44 /* packed_rrset on top to define enum types (forced by c99 standard) */ 45 #include "util/data/packed_rrset.h" 46 #include "validator/val_secalgo.h" 47 #include "validator/val_nsec3.h" 48 #include "util/log.h" 49 #include "sldns/rrdef.h" 50 #include "sldns/keyraw.h" 51 #include "sldns/sbuffer.h" 52 53 #if !defined(HAVE_SSL) && !defined(HAVE_NSS) && !defined(HAVE_NETTLE) 54 #error "Need crypto library to do digital signature cryptography" 55 #endif 56 57 /** fake DSA support for unit tests */ 58 int fake_dsa = 0; 59 /** fake SHA1 support for unit tests */ 60 int fake_sha1 = 0; 61 62 /* OpenSSL implementation */ 63 #ifdef HAVE_SSL 64 #ifdef HAVE_OPENSSL_ERR_H 65 #include <openssl/err.h> 66 #endif 67 68 #ifdef HAVE_OPENSSL_RAND_H 69 #include <openssl/rand.h> 70 #endif 71 72 #ifdef HAVE_OPENSSL_CONF_H 73 #include <openssl/conf.h> 74 #endif 75 76 #ifdef HAVE_OPENSSL_ENGINE_H 77 #include <openssl/engine.h> 78 #endif 79 80 #if defined(HAVE_OPENSSL_DSA_H) && defined(USE_DSA) 81 #include <openssl/dsa.h> 82 #endif 83 84 /** 85 * Output a libcrypto openssl error to the logfile. 86 * @param str: string to add to it. 87 * @param e: the error to output, error number from ERR_get_error(). 88 */ 89 static void 90 log_crypto_error(const char* str, unsigned long e) 91 { 92 char buf[128]; 93 /* or use ERR_error_string if ERR_error_string_n is not avail TODO */ 94 ERR_error_string_n(e, buf, sizeof(buf)); 95 /* buf now contains */ 96 /* error:[error code]:[library name]:[function name]:[reason string] */ 97 log_err("%s crypto %s", str, buf); 98 } 99 100 /** 101 * Output a libcrypto openssl error to the logfile as a debug message. 102 * @param level: debug level to use in verbose() call 103 * @param str: string to add to it. 104 * @param e: the error to output, error number from ERR_get_error(). 105 */ 106 static void 107 log_crypto_verbose(enum verbosity_value level, const char* str, unsigned long e) 108 { 109 char buf[128]; 110 /* or use ERR_error_string if ERR_error_string_n is not avail TODO */ 111 ERR_error_string_n(e, buf, sizeof(buf)); 112 /* buf now contains */ 113 /* error:[error code]:[library name]:[function name]:[reason string] */ 114 verbose(level, "%s crypto %s", str, buf); 115 } 116 117 /* return size of digest if supported, or 0 otherwise */ 118 size_t 119 nsec3_hash_algo_size_supported(int id) 120 { 121 switch(id) { 122 case NSEC3_HASH_SHA1: 123 return SHA_DIGEST_LENGTH; 124 default: 125 return 0; 126 } 127 } 128 129 /* perform nsec3 hash. return false on failure */ 130 int 131 secalgo_nsec3_hash(int algo, unsigned char* buf, size_t len, 132 unsigned char* res) 133 { 134 switch(algo) { 135 case NSEC3_HASH_SHA1: 136 #ifdef OPENSSL_FIPS 137 if(!sldns_digest_evp(buf, len, res, EVP_sha1())) 138 log_crypto_error("could not digest with EVP_sha1", 139 ERR_get_error()); 140 #else 141 (void)SHA1(buf, len, res); 142 #endif 143 return 1; 144 default: 145 return 0; 146 } 147 } 148 149 void 150 secalgo_hash_sha256(unsigned char* buf, size_t len, unsigned char* res) 151 { 152 #ifdef OPENSSL_FIPS 153 if(!sldns_digest_evp(buf, len, res, EVP_sha256())) 154 log_crypto_error("could not digest with EVP_sha256", 155 ERR_get_error()); 156 #else 157 (void)SHA256(buf, len, res); 158 #endif 159 } 160 161 /** hash structure for keeping track of running hashes */ 162 struct secalgo_hash { 163 /** the openssl message digest context */ 164 EVP_MD_CTX* ctx; 165 }; 166 167 /** create secalgo hash with hash type */ 168 static struct secalgo_hash* secalgo_hash_create_md(const EVP_MD* md) 169 { 170 struct secalgo_hash* h; 171 if(!md) 172 return NULL; 173 h = calloc(1, sizeof(*h)); 174 if(!h) 175 return NULL; 176 h->ctx = EVP_MD_CTX_create(); 177 if(!h->ctx) { 178 free(h); 179 return NULL; 180 } 181 if(!EVP_DigestInit_ex(h->ctx, md, NULL)) { 182 EVP_MD_CTX_destroy(h->ctx); 183 free(h); 184 return NULL; 185 } 186 return h; 187 } 188 189 struct secalgo_hash* secalgo_hash_create_sha384(void) 190 { 191 return secalgo_hash_create_md(EVP_sha384()); 192 } 193 194 struct secalgo_hash* secalgo_hash_create_sha512(void) 195 { 196 return secalgo_hash_create_md(EVP_sha512()); 197 } 198 199 int secalgo_hash_update(struct secalgo_hash* hash, uint8_t* data, size_t len) 200 { 201 return EVP_DigestUpdate(hash->ctx, (unsigned char*)data, 202 (unsigned int)len); 203 } 204 205 int secalgo_hash_final(struct secalgo_hash* hash, uint8_t* result, 206 size_t maxlen, size_t* resultlen) 207 { 208 if(EVP_MD_CTX_size(hash->ctx) > (int)maxlen) { 209 *resultlen = 0; 210 log_err("secalgo_hash_final: hash buffer too small"); 211 return 0; 212 } 213 *resultlen = EVP_MD_CTX_size(hash->ctx); 214 return EVP_DigestFinal_ex(hash->ctx, result, NULL); 215 } 216 217 void secalgo_hash_delete(struct secalgo_hash* hash) 218 { 219 if(!hash) return; 220 EVP_MD_CTX_destroy(hash->ctx); 221 free(hash); 222 } 223 224 /** 225 * Return size of DS digest according to its hash algorithm. 226 * @param algo: DS digest algo. 227 * @return size in bytes of digest, or 0 if not supported. 228 */ 229 size_t 230 ds_digest_size_supported(int algo) 231 { 232 switch(algo) { 233 case LDNS_SHA1: 234 #if defined(HAVE_EVP_SHA1) && defined(USE_SHA1) 235 #ifdef HAVE_EVP_DEFAULT_PROPERTIES_IS_FIPS_ENABLED 236 if (EVP_default_properties_is_fips_enabled(NULL)) 237 return 0; 238 #endif 239 return SHA_DIGEST_LENGTH; 240 #else 241 if(fake_sha1) return 20; 242 return 0; 243 #endif 244 #ifdef HAVE_EVP_SHA256 245 case LDNS_SHA256: 246 return SHA256_DIGEST_LENGTH; 247 #endif 248 #ifdef USE_GOST 249 case LDNS_HASH_GOST: 250 /* we support GOST if it can be loaded */ 251 (void)sldns_key_EVP_load_gost_id(); 252 if(EVP_get_digestbyname("md_gost94")) 253 return 32; 254 else return 0; 255 #endif 256 #ifdef USE_ECDSA 257 case LDNS_SHA384: 258 return SHA384_DIGEST_LENGTH; 259 #endif 260 default: break; 261 } 262 return 0; 263 } 264 265 #ifdef USE_GOST 266 /** Perform GOST hash */ 267 static int 268 do_gost94(unsigned char* data, size_t len, unsigned char* dest) 269 { 270 const EVP_MD* md = EVP_get_digestbyname("md_gost94"); 271 if(!md) 272 return 0; 273 return sldns_digest_evp(data, (unsigned int)len, dest, md); 274 } 275 #endif 276 277 int 278 secalgo_ds_digest(int algo, unsigned char* buf, size_t len, 279 unsigned char* res) 280 { 281 switch(algo) { 282 #if defined(HAVE_EVP_SHA1) && defined(USE_SHA1) 283 case LDNS_SHA1: 284 #ifdef OPENSSL_FIPS 285 if(!sldns_digest_evp(buf, len, res, EVP_sha1())) 286 log_crypto_error("could not digest with EVP_sha1", 287 ERR_get_error()); 288 #else 289 (void)SHA1(buf, len, res); 290 #endif 291 return 1; 292 #endif 293 #ifdef HAVE_EVP_SHA256 294 case LDNS_SHA256: 295 #ifdef OPENSSL_FIPS 296 if(!sldns_digest_evp(buf, len, res, EVP_sha256())) 297 log_crypto_error("could not digest with EVP_sha256", 298 ERR_get_error()); 299 #else 300 (void)SHA256(buf, len, res); 301 #endif 302 return 1; 303 #endif 304 #ifdef USE_GOST 305 case LDNS_HASH_GOST: 306 if(do_gost94(buf, len, res)) 307 return 1; 308 break; 309 #endif 310 #ifdef USE_ECDSA 311 case LDNS_SHA384: 312 #ifdef OPENSSL_FIPS 313 if(!sldns_digest_evp(buf, len, res, EVP_sha384())) 314 log_crypto_error("could not digest with EVP_sha384", 315 ERR_get_error()); 316 #else 317 (void)SHA384(buf, len, res); 318 #endif 319 return 1; 320 #endif 321 default: 322 verbose(VERB_QUERY, "unknown DS digest algorithm %d", 323 algo); 324 break; 325 } 326 return 0; 327 } 328 329 /** return true if DNSKEY algorithm id is supported */ 330 int 331 dnskey_algo_id_is_supported(int id) 332 { 333 switch(id) { 334 case LDNS_RSAMD5: 335 /* RFC 6725 deprecates RSAMD5 */ 336 return 0; 337 case LDNS_DSA: 338 case LDNS_DSA_NSEC3: 339 #if defined(USE_DSA) && defined(USE_SHA1) 340 return 1; 341 #else 342 if(fake_dsa || fake_sha1) return 1; 343 return 0; 344 #endif 345 346 case LDNS_RSASHA1: 347 case LDNS_RSASHA1_NSEC3: 348 #ifdef USE_SHA1 349 #ifdef HAVE_EVP_DEFAULT_PROPERTIES_IS_FIPS_ENABLED 350 return !EVP_default_properties_is_fips_enabled(NULL); 351 #else 352 return 1; 353 #endif 354 #else 355 if(fake_sha1) return 1; 356 return 0; 357 #endif 358 359 #if defined(HAVE_EVP_SHA256) && defined(USE_SHA2) 360 case LDNS_RSASHA256: 361 #endif 362 #if defined(HAVE_EVP_SHA512) && defined(USE_SHA2) 363 case LDNS_RSASHA512: 364 #endif 365 #ifdef USE_ECDSA 366 case LDNS_ECDSAP256SHA256: 367 case LDNS_ECDSAP384SHA384: 368 #endif 369 #if (defined(HAVE_EVP_SHA256) && defined(USE_SHA2)) || (defined(HAVE_EVP_SHA512) && defined(USE_SHA2)) || defined(USE_ECDSA) 370 return 1; 371 #endif 372 #ifdef USE_ED25519 373 case LDNS_ED25519: 374 #endif 375 #ifdef USE_ED448 376 case LDNS_ED448: 377 #endif 378 #if defined(USE_ED25519) || defined(USE_ED448) 379 #ifdef HAVE_EVP_DEFAULT_PROPERTIES_IS_FIPS_ENABLED 380 return !EVP_default_properties_is_fips_enabled(NULL); 381 #else 382 return 1; 383 #endif 384 #endif 385 386 #ifdef USE_GOST 387 case LDNS_ECC_GOST: 388 /* we support GOST if it can be loaded */ 389 return sldns_key_EVP_load_gost_id(); 390 #endif 391 default: 392 return 0; 393 } 394 } 395 396 #ifdef USE_DSA 397 /** 398 * Setup DSA key digest in DER encoding ... 399 * @param sig: input is signature output alloced ptr (unless failure). 400 * caller must free alloced ptr if this routine returns true. 401 * @param len: input is initial siglen, output is output len. 402 * @return false on failure. 403 */ 404 static int 405 setup_dsa_sig(unsigned char** sig, unsigned int* len) 406 { 407 unsigned char* orig = *sig; 408 unsigned int origlen = *len; 409 int newlen; 410 BIGNUM *R, *S; 411 DSA_SIG *dsasig; 412 413 /* extract the R and S field from the sig buffer */ 414 if(origlen < 1 + 2*SHA_DIGEST_LENGTH) 415 return 0; 416 R = BN_new(); 417 if(!R) return 0; 418 (void) BN_bin2bn(orig + 1, SHA_DIGEST_LENGTH, R); 419 S = BN_new(); 420 if(!S) return 0; 421 (void) BN_bin2bn(orig + 21, SHA_DIGEST_LENGTH, S); 422 dsasig = DSA_SIG_new(); 423 if(!dsasig) return 0; 424 425 #ifdef HAVE_DSA_SIG_SET0 426 if(!DSA_SIG_set0(dsasig, R, S)) { 427 DSA_SIG_free(dsasig); 428 return 0; 429 } 430 #else 431 # ifndef S_SPLINT_S 432 dsasig->r = R; 433 dsasig->s = S; 434 # endif /* S_SPLINT_S */ 435 #endif 436 *sig = NULL; 437 newlen = i2d_DSA_SIG(dsasig, sig); 438 if(newlen < 0) { 439 DSA_SIG_free(dsasig); 440 free(*sig); 441 return 0; 442 } 443 *len = (unsigned int)newlen; 444 DSA_SIG_free(dsasig); 445 return 1; 446 } 447 #endif /* USE_DSA */ 448 449 #ifdef USE_ECDSA 450 /** 451 * Setup the ECDSA signature in its encoding that the library wants. 452 * Converts from plain numbers to ASN formatted. 453 * @param sig: input is signature, output alloced ptr (unless failure). 454 * caller must free alloced ptr if this routine returns true. 455 * @param len: input is initial siglen, output is output len. 456 * @return false on failure. 457 */ 458 static int 459 setup_ecdsa_sig(unsigned char** sig, unsigned int* len) 460 { 461 /* convert from two BIGNUMs in the rdata buffer, to ASN notation. 462 * ASN preamble: 30440220 <R 32bytefor256> 0220 <S 32bytefor256> 463 * the '20' is the length of that field (=bnsize). 464 i * the '44' is the total remaining length. 465 * if negative, start with leading zero. 466 * if starts with 00s, remove them from the number. 467 */ 468 uint8_t pre[] = {0x30, 0x44, 0x02, 0x20}; 469 int pre_len = 4; 470 uint8_t mid[] = {0x02, 0x20}; 471 int mid_len = 2; 472 int raw_sig_len, r_high, s_high, r_rem=0, s_rem=0; 473 int bnsize = (int)((*len)/2); 474 unsigned char* d = *sig; 475 uint8_t* p; 476 /* if too short or not even length, fails */ 477 if(*len < 16 || bnsize*2 != (int)*len) 478 return 0; 479 480 /* strip leading zeroes from r (but not last one) */ 481 while(r_rem < bnsize-1 && d[r_rem] == 0) 482 r_rem++; 483 /* strip leading zeroes from s (but not last one) */ 484 while(s_rem < bnsize-1 && d[bnsize+s_rem] == 0) 485 s_rem++; 486 487 r_high = ((d[0+r_rem]&0x80)?1:0); 488 s_high = ((d[bnsize+s_rem]&0x80)?1:0); 489 raw_sig_len = pre_len + r_high + bnsize - r_rem + mid_len + 490 s_high + bnsize - s_rem; 491 *sig = (unsigned char*)malloc((size_t)raw_sig_len); 492 if(!*sig) 493 return 0; 494 p = (uint8_t*)*sig; 495 p[0] = pre[0]; 496 p[1] = (uint8_t)(raw_sig_len-2); 497 p[2] = pre[2]; 498 p[3] = (uint8_t)(bnsize + r_high - r_rem); 499 p += 4; 500 if(r_high) { 501 *p = 0; 502 p += 1; 503 } 504 memmove(p, d+r_rem, (size_t)bnsize-r_rem); 505 p += bnsize-r_rem; 506 memmove(p, mid, (size_t)mid_len-1); 507 p += mid_len-1; 508 *p = (uint8_t)(bnsize + s_high - s_rem); 509 p += 1; 510 if(s_high) { 511 *p = 0; 512 p += 1; 513 } 514 memmove(p, d+bnsize+s_rem, (size_t)bnsize-s_rem); 515 *len = (unsigned int)raw_sig_len; 516 return 1; 517 } 518 #endif /* USE_ECDSA */ 519 520 #ifdef USE_ECDSA_EVP_WORKAROUND 521 static EVP_MD ecdsa_evp_256_md; 522 static EVP_MD ecdsa_evp_384_md; 523 void ecdsa_evp_workaround_init(void) 524 { 525 /* openssl before 1.0.0 fixes RSA with the SHA256 526 * hash in EVP. We create one for ecdsa_sha256 */ 527 ecdsa_evp_256_md = *EVP_sha256(); 528 ecdsa_evp_256_md.required_pkey_type[0] = EVP_PKEY_EC; 529 ecdsa_evp_256_md.verify = (void*)ECDSA_verify; 530 531 ecdsa_evp_384_md = *EVP_sha384(); 532 ecdsa_evp_384_md.required_pkey_type[0] = EVP_PKEY_EC; 533 ecdsa_evp_384_md.verify = (void*)ECDSA_verify; 534 } 535 #endif /* USE_ECDSA_EVP_WORKAROUND */ 536 537 /** 538 * Setup key and digest for verification. Adjust sig if necessary. 539 * 540 * @param algo: key algorithm 541 * @param evp_key: EVP PKEY public key to create. 542 * @param digest_type: digest type to use 543 * @param key: key to setup for. 544 * @param keylen: length of key. 545 * @return false on failure. 546 */ 547 static int 548 setup_key_digest(int algo, EVP_PKEY** evp_key, const EVP_MD** digest_type, 549 unsigned char* key, size_t keylen) 550 { 551 switch(algo) { 552 #if defined(USE_DSA) && defined(USE_SHA1) 553 case LDNS_DSA: 554 case LDNS_DSA_NSEC3: 555 *evp_key = sldns_key_dsa2pkey_raw(key, keylen); 556 if(!*evp_key) { 557 verbose(VERB_QUERY, "verify: sldns_key_dsa2pkey failed"); 558 return 0; 559 } 560 #ifdef HAVE_EVP_DSS1 561 *digest_type = EVP_dss1(); 562 #else 563 *digest_type = EVP_sha1(); 564 #endif 565 566 break; 567 #endif /* USE_DSA && USE_SHA1 */ 568 569 #if defined(USE_SHA1) || (defined(HAVE_EVP_SHA256) && defined(USE_SHA2)) || (defined(HAVE_EVP_SHA512) && defined(USE_SHA2)) 570 #ifdef USE_SHA1 571 case LDNS_RSASHA1: 572 case LDNS_RSASHA1_NSEC3: 573 #endif 574 #if defined(HAVE_EVP_SHA256) && defined(USE_SHA2) 575 case LDNS_RSASHA256: 576 #endif 577 #if defined(HAVE_EVP_SHA512) && defined(USE_SHA2) 578 case LDNS_RSASHA512: 579 #endif 580 *evp_key = sldns_key_rsa2pkey_raw(key, keylen); 581 if(!*evp_key) { 582 verbose(VERB_QUERY, "verify: sldns_key_rsa2pkey SHA failed"); 583 return 0; 584 } 585 586 /* select SHA version */ 587 #if defined(HAVE_EVP_SHA256) && defined(USE_SHA2) 588 if(algo == LDNS_RSASHA256) 589 *digest_type = EVP_sha256(); 590 else 591 #endif 592 #if defined(HAVE_EVP_SHA512) && defined(USE_SHA2) 593 if(algo == LDNS_RSASHA512) 594 *digest_type = EVP_sha512(); 595 else 596 #endif 597 #ifdef USE_SHA1 598 *digest_type = EVP_sha1(); 599 #else 600 { verbose(VERB_QUERY, "no digest available"); return 0; } 601 #endif 602 break; 603 #endif /* defined(USE_SHA1) || (defined(HAVE_EVP_SHA256) && defined(USE_SHA2)) || (defined(HAVE_EVP_SHA512) && defined(USE_SHA2)) */ 604 605 case LDNS_RSAMD5: 606 *evp_key = sldns_key_rsa2pkey_raw(key, keylen); 607 if(!*evp_key) { 608 verbose(VERB_QUERY, "verify: sldns_key_rsa2pkey MD5 failed"); 609 return 0; 610 } 611 *digest_type = EVP_md5(); 612 613 break; 614 #ifdef USE_GOST 615 case LDNS_ECC_GOST: 616 *evp_key = sldns_gost2pkey_raw(key, keylen); 617 if(!*evp_key) { 618 verbose(VERB_QUERY, "verify: " 619 "sldns_gost2pkey_raw failed"); 620 return 0; 621 } 622 *digest_type = EVP_get_digestbyname("md_gost94"); 623 if(!*digest_type) { 624 verbose(VERB_QUERY, "verify: " 625 "EVP_getdigest md_gost94 failed"); 626 return 0; 627 } 628 break; 629 #endif 630 #ifdef USE_ECDSA 631 case LDNS_ECDSAP256SHA256: 632 *evp_key = sldns_ecdsa2pkey_raw(key, keylen, 633 LDNS_ECDSAP256SHA256); 634 if(!*evp_key) { 635 verbose(VERB_QUERY, "verify: " 636 "sldns_ecdsa2pkey_raw failed"); 637 return 0; 638 } 639 #ifdef USE_ECDSA_EVP_WORKAROUND 640 *digest_type = &ecdsa_evp_256_md; 641 #else 642 *digest_type = EVP_sha256(); 643 #endif 644 break; 645 case LDNS_ECDSAP384SHA384: 646 *evp_key = sldns_ecdsa2pkey_raw(key, keylen, 647 LDNS_ECDSAP384SHA384); 648 if(!*evp_key) { 649 verbose(VERB_QUERY, "verify: " 650 "sldns_ecdsa2pkey_raw failed"); 651 return 0; 652 } 653 #ifdef USE_ECDSA_EVP_WORKAROUND 654 *digest_type = &ecdsa_evp_384_md; 655 #else 656 *digest_type = EVP_sha384(); 657 #endif 658 break; 659 #endif /* USE_ECDSA */ 660 #ifdef USE_ED25519 661 case LDNS_ED25519: 662 *evp_key = sldns_ed255192pkey_raw(key, keylen); 663 if(!*evp_key) { 664 verbose(VERB_QUERY, "verify: " 665 "sldns_ed255192pkey_raw failed"); 666 return 0; 667 } 668 *digest_type = NULL; 669 break; 670 #endif /* USE_ED25519 */ 671 #ifdef USE_ED448 672 case LDNS_ED448: 673 *evp_key = sldns_ed4482pkey_raw(key, keylen); 674 if(!*evp_key) { 675 verbose(VERB_QUERY, "verify: " 676 "sldns_ed4482pkey_raw failed"); 677 return 0; 678 } 679 *digest_type = NULL; 680 break; 681 #endif /* USE_ED448 */ 682 default: 683 verbose(VERB_QUERY, "verify: unknown algorithm %d", 684 algo); 685 return 0; 686 } 687 return 1; 688 } 689 690 static void 691 digest_ctx_free(EVP_MD_CTX* ctx, EVP_PKEY *evp_key, 692 unsigned char* sigblock, int dofree, int docrypto_free) 693 { 694 #ifdef HAVE_EVP_MD_CTX_NEW 695 EVP_MD_CTX_destroy(ctx); 696 #else 697 EVP_MD_CTX_cleanup(ctx); 698 free(ctx); 699 #endif 700 EVP_PKEY_free(evp_key); 701 if(dofree) free(sigblock); 702 else if(docrypto_free) OPENSSL_free(sigblock); 703 } 704 705 static enum sec_status 706 digest_error_status(const char *str) 707 { 708 unsigned long e = ERR_get_error(); 709 #ifdef EVP_R_INVALID_DIGEST 710 if (ERR_GET_LIB(e) == ERR_LIB_EVP && 711 ERR_GET_REASON(e) == EVP_R_INVALID_DIGEST) { 712 log_crypto_verbose(VERB_ALGO, str, e); 713 return sec_status_indeterminate; 714 } 715 #endif 716 log_crypto_verbose(VERB_QUERY, str, e); 717 return sec_status_unchecked; 718 } 719 720 /** 721 * Check a canonical sig+rrset and signature against a dnskey 722 * @param buf: buffer with data to verify, the first rrsig part and the 723 * canonicalized rrset. 724 * @param algo: DNSKEY algorithm. 725 * @param sigblock: signature rdata field from RRSIG 726 * @param sigblock_len: length of sigblock data. 727 * @param key: public key data from DNSKEY RR. 728 * @param keylen: length of keydata. 729 * @param reason: bogus reason in more detail. 730 * @return secure if verification succeeded, bogus on crypto failure, 731 * unchecked on format errors and alloc failures, indeterminate 732 * if digest is not supported by the crypto library (openssl3+ only). 733 */ 734 enum sec_status 735 verify_canonrrset(sldns_buffer* buf, int algo, unsigned char* sigblock, 736 unsigned int sigblock_len, unsigned char* key, unsigned int keylen, 737 char** reason) 738 { 739 const EVP_MD *digest_type; 740 EVP_MD_CTX* ctx; 741 int res, dofree = 0, docrypto_free = 0; 742 EVP_PKEY *evp_key = NULL; 743 744 #ifndef USE_DSA 745 if((algo == LDNS_DSA || algo == LDNS_DSA_NSEC3) &&(fake_dsa||fake_sha1)) 746 return sec_status_secure; 747 #endif 748 if(fake_sha1 && (algo == LDNS_DSA || algo == LDNS_DSA_NSEC3 || algo == LDNS_RSASHA1 || algo == LDNS_RSASHA1_NSEC3)) 749 return sec_status_secure; 750 751 if(!setup_key_digest(algo, &evp_key, &digest_type, key, keylen)) { 752 verbose(VERB_QUERY, "verify: failed to setup key"); 753 *reason = "use of key for crypto failed"; 754 EVP_PKEY_free(evp_key); 755 return sec_status_bogus; 756 } 757 #ifdef USE_DSA 758 /* if it is a DSA signature in bind format, convert to DER format */ 759 if((algo == LDNS_DSA || algo == LDNS_DSA_NSEC3) && 760 sigblock_len == 1+2*SHA_DIGEST_LENGTH) { 761 if(!setup_dsa_sig(&sigblock, &sigblock_len)) { 762 verbose(VERB_QUERY, "verify: failed to setup DSA sig"); 763 *reason = "use of key for DSA crypto failed"; 764 EVP_PKEY_free(evp_key); 765 return sec_status_bogus; 766 } 767 docrypto_free = 1; 768 } 769 #endif 770 #if defined(USE_ECDSA) && defined(USE_DSA) 771 else 772 #endif 773 #ifdef USE_ECDSA 774 if(algo == LDNS_ECDSAP256SHA256 || algo == LDNS_ECDSAP384SHA384) { 775 /* EVP uses ASN prefix on sig, which is not in the wire data */ 776 if(!setup_ecdsa_sig(&sigblock, &sigblock_len)) { 777 verbose(VERB_QUERY, "verify: failed to setup ECDSA sig"); 778 *reason = "use of signature for ECDSA crypto failed"; 779 EVP_PKEY_free(evp_key); 780 return sec_status_bogus; 781 } 782 dofree = 1; 783 } 784 #endif /* USE_ECDSA */ 785 786 /* do the signature cryptography work */ 787 #ifdef HAVE_EVP_MD_CTX_NEW 788 ctx = EVP_MD_CTX_new(); 789 #else 790 ctx = (EVP_MD_CTX*)malloc(sizeof(*ctx)); 791 if(ctx) EVP_MD_CTX_init(ctx); 792 #endif 793 if(!ctx) { 794 log_err("EVP_MD_CTX_new: malloc failure"); 795 EVP_PKEY_free(evp_key); 796 if(dofree) free(sigblock); 797 else if(docrypto_free) OPENSSL_free(sigblock); 798 return sec_status_unchecked; 799 } 800 #ifndef HAVE_EVP_DIGESTVERIFY 801 if(EVP_DigestInit(ctx, digest_type) == 0) { 802 enum sec_status sec; 803 sec = digest_error_status("verify: EVP_DigestInit failed"); 804 digest_ctx_free(ctx, evp_key, sigblock, 805 dofree, docrypto_free); 806 return sec; 807 } 808 if(EVP_DigestUpdate(ctx, (unsigned char*)sldns_buffer_begin(buf), 809 (unsigned int)sldns_buffer_limit(buf)) == 0) { 810 log_crypto_verbose(VERB_QUERY, "verify: EVP_DigestUpdate failed", 811 ERR_get_error()); 812 digest_ctx_free(ctx, evp_key, sigblock, 813 dofree, docrypto_free); 814 return sec_status_unchecked; 815 } 816 817 res = EVP_VerifyFinal(ctx, sigblock, sigblock_len, evp_key); 818 #else /* HAVE_EVP_DIGESTVERIFY */ 819 if(EVP_DigestVerifyInit(ctx, NULL, digest_type, NULL, evp_key) == 0) { 820 enum sec_status sec; 821 sec = digest_error_status("verify: EVP_DigestVerifyInit failed"); 822 digest_ctx_free(ctx, evp_key, sigblock, 823 dofree, docrypto_free); 824 return sec; 825 } 826 res = EVP_DigestVerify(ctx, sigblock, sigblock_len, 827 (unsigned char*)sldns_buffer_begin(buf), 828 sldns_buffer_limit(buf)); 829 #endif 830 digest_ctx_free(ctx, evp_key, sigblock, 831 dofree, docrypto_free); 832 833 if(res == 1) { 834 return sec_status_secure; 835 } else if(res == 0) { 836 verbose(VERB_QUERY, "verify: signature mismatch"); 837 *reason = "signature crypto failed"; 838 return sec_status_bogus; 839 } 840 841 log_crypto_error("verify:", ERR_get_error()); 842 return sec_status_unchecked; 843 } 844 845 /**************************************************/ 846 #elif defined(HAVE_NSS) 847 /* libnss implementation */ 848 /* nss3 */ 849 #include "sechash.h" 850 #include "pk11pub.h" 851 #include "keyhi.h" 852 #include "secerr.h" 853 #include "cryptohi.h" 854 /* nspr4 */ 855 #include "prerror.h" 856 857 /* return size of digest if supported, or 0 otherwise */ 858 size_t 859 nsec3_hash_algo_size_supported(int id) 860 { 861 switch(id) { 862 case NSEC3_HASH_SHA1: 863 return SHA1_LENGTH; 864 default: 865 return 0; 866 } 867 } 868 869 /* perform nsec3 hash. return false on failure */ 870 int 871 secalgo_nsec3_hash(int algo, unsigned char* buf, size_t len, 872 unsigned char* res) 873 { 874 switch(algo) { 875 case NSEC3_HASH_SHA1: 876 (void)HASH_HashBuf(HASH_AlgSHA1, res, buf, (unsigned long)len); 877 return 1; 878 default: 879 return 0; 880 } 881 } 882 883 void 884 secalgo_hash_sha256(unsigned char* buf, size_t len, unsigned char* res) 885 { 886 (void)HASH_HashBuf(HASH_AlgSHA256, res, buf, (unsigned long)len); 887 } 888 889 /** the secalgo hash structure */ 890 struct secalgo_hash { 891 /** hash context */ 892 HASHContext* ctx; 893 }; 894 895 /** create hash struct of type */ 896 static struct secalgo_hash* secalgo_hash_create_type(HASH_HashType tp) 897 { 898 struct secalgo_hash* h = calloc(1, sizeof(*h)); 899 if(!h) 900 return NULL; 901 h->ctx = HASH_Create(tp); 902 if(!h->ctx) { 903 free(h); 904 return NULL; 905 } 906 return h; 907 } 908 909 struct secalgo_hash* secalgo_hash_create_sha384(void) 910 { 911 return secalgo_hash_create_type(HASH_AlgSHA384); 912 } 913 914 struct secalgo_hash* secalgo_hash_create_sha512(void) 915 { 916 return secalgo_hash_create_type(HASH_AlgSHA512); 917 } 918 919 int secalgo_hash_update(struct secalgo_hash* hash, uint8_t* data, size_t len) 920 { 921 HASH_Update(hash->ctx, (unsigned char*)data, (unsigned int)len); 922 return 1; 923 } 924 925 int secalgo_hash_final(struct secalgo_hash* hash, uint8_t* result, 926 size_t maxlen, size_t* resultlen) 927 { 928 unsigned int reslen = 0; 929 if(HASH_ResultLenContext(hash->ctx) > (unsigned int)maxlen) { 930 *resultlen = 0; 931 log_err("secalgo_hash_final: hash buffer too small"); 932 return 0; 933 } 934 HASH_End(hash->ctx, (unsigned char*)result, &reslen, 935 (unsigned int)maxlen); 936 *resultlen = (size_t)reslen; 937 return 1; 938 } 939 940 void secalgo_hash_delete(struct secalgo_hash* hash) 941 { 942 if(!hash) return; 943 HASH_Destroy(hash->ctx); 944 free(hash); 945 } 946 947 size_t 948 ds_digest_size_supported(int algo) 949 { 950 /* uses libNSS */ 951 switch(algo) { 952 #ifdef USE_SHA1 953 case LDNS_SHA1: 954 return SHA1_LENGTH; 955 #endif 956 #ifdef USE_SHA2 957 case LDNS_SHA256: 958 return SHA256_LENGTH; 959 #endif 960 #ifdef USE_ECDSA 961 case LDNS_SHA384: 962 return SHA384_LENGTH; 963 #endif 964 /* GOST not supported in NSS */ 965 case LDNS_HASH_GOST: 966 default: break; 967 } 968 return 0; 969 } 970 971 int 972 secalgo_ds_digest(int algo, unsigned char* buf, size_t len, 973 unsigned char* res) 974 { 975 /* uses libNSS */ 976 switch(algo) { 977 #ifdef USE_SHA1 978 case LDNS_SHA1: 979 return HASH_HashBuf(HASH_AlgSHA1, res, buf, len) 980 == SECSuccess; 981 #endif 982 #if defined(USE_SHA2) 983 case LDNS_SHA256: 984 return HASH_HashBuf(HASH_AlgSHA256, res, buf, len) 985 == SECSuccess; 986 #endif 987 #ifdef USE_ECDSA 988 case LDNS_SHA384: 989 return HASH_HashBuf(HASH_AlgSHA384, res, buf, len) 990 == SECSuccess; 991 #endif 992 case LDNS_HASH_GOST: 993 default: 994 verbose(VERB_QUERY, "unknown DS digest algorithm %d", 995 algo); 996 break; 997 } 998 return 0; 999 } 1000 1001 int 1002 dnskey_algo_id_is_supported(int id) 1003 { 1004 /* uses libNSS */ 1005 switch(id) { 1006 case LDNS_RSAMD5: 1007 /* RFC 6725 deprecates RSAMD5 */ 1008 return 0; 1009 #if defined(USE_SHA1) || defined(USE_SHA2) 1010 #if defined(USE_DSA) && defined(USE_SHA1) 1011 case LDNS_DSA: 1012 case LDNS_DSA_NSEC3: 1013 #endif 1014 #ifdef USE_SHA1 1015 case LDNS_RSASHA1: 1016 case LDNS_RSASHA1_NSEC3: 1017 #endif 1018 #ifdef USE_SHA2 1019 case LDNS_RSASHA256: 1020 #endif 1021 #ifdef USE_SHA2 1022 case LDNS_RSASHA512: 1023 #endif 1024 return 1; 1025 #endif /* SHA1 or SHA2 */ 1026 1027 #ifdef USE_ECDSA 1028 case LDNS_ECDSAP256SHA256: 1029 case LDNS_ECDSAP384SHA384: 1030 return PK11_TokenExists(CKM_ECDSA); 1031 #endif 1032 case LDNS_ECC_GOST: 1033 default: 1034 return 0; 1035 } 1036 } 1037 1038 /* return a new public key for NSS */ 1039 static SECKEYPublicKey* nss_key_create(KeyType ktype) 1040 { 1041 SECKEYPublicKey* key; 1042 PLArenaPool* arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE); 1043 if(!arena) { 1044 log_err("out of memory, PORT_NewArena failed"); 1045 return NULL; 1046 } 1047 key = PORT_ArenaZNew(arena, SECKEYPublicKey); 1048 if(!key) { 1049 log_err("out of memory, PORT_ArenaZNew failed"); 1050 PORT_FreeArena(arena, PR_FALSE); 1051 return NULL; 1052 } 1053 key->arena = arena; 1054 key->keyType = ktype; 1055 key->pkcs11Slot = NULL; 1056 key->pkcs11ID = CK_INVALID_HANDLE; 1057 return key; 1058 } 1059 1060 static SECKEYPublicKey* nss_buf2ecdsa(unsigned char* key, size_t len, int algo) 1061 { 1062 SECKEYPublicKey* pk; 1063 SECItem pub = {siBuffer, NULL, 0}; 1064 SECItem params = {siBuffer, NULL, 0}; 1065 static unsigned char param256[] = { 1066 /* OBJECTIDENTIFIER 1.2.840.10045.3.1.7 (P-256) 1067 * {iso(1) member-body(2) us(840) ansi-x962(10045) curves(3) prime(1) prime256v1(7)} */ 1068 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x03, 0x01, 0x07 1069 }; 1070 static unsigned char param384[] = { 1071 /* OBJECTIDENTIFIER 1.3.132.0.34 (P-384) 1072 * {iso(1) identified-organization(3) certicom(132) curve(0) ansip384r1(34)} */ 1073 0x06, 0x05, 0x2b, 0x81, 0x04, 0x00, 0x22 1074 }; 1075 unsigned char buf[256+2]; /* sufficient for 2*384/8+1 */ 1076 1077 /* check length, which uncompressed must be 2 bignums */ 1078 if(algo == LDNS_ECDSAP256SHA256) { 1079 if(len != 2*256/8) return NULL; 1080 /* ECCurve_X9_62_PRIME_256V1 */ 1081 } else if(algo == LDNS_ECDSAP384SHA384) { 1082 if(len != 2*384/8) return NULL; 1083 /* ECCurve_X9_62_PRIME_384R1 */ 1084 } else return NULL; 1085 1086 buf[0] = 0x04; /* POINT_FORM_UNCOMPRESSED */ 1087 memmove(buf+1, key, len); 1088 pub.data = buf; 1089 pub.len = len+1; 1090 if(algo == LDNS_ECDSAP256SHA256) { 1091 params.data = param256; 1092 params.len = sizeof(param256); 1093 } else { 1094 params.data = param384; 1095 params.len = sizeof(param384); 1096 } 1097 1098 pk = nss_key_create(ecKey); 1099 if(!pk) 1100 return NULL; 1101 pk->u.ec.size = (len/2)*8; 1102 if(SECITEM_CopyItem(pk->arena, &pk->u.ec.publicValue, &pub)) { 1103 SECKEY_DestroyPublicKey(pk); 1104 return NULL; 1105 } 1106 if(SECITEM_CopyItem(pk->arena, &pk->u.ec.DEREncodedParams, ¶ms)) { 1107 SECKEY_DestroyPublicKey(pk); 1108 return NULL; 1109 } 1110 1111 return pk; 1112 } 1113 1114 #if defined(USE_DSA) && defined(USE_SHA1) 1115 static SECKEYPublicKey* nss_buf2dsa(unsigned char* key, size_t len) 1116 { 1117 SECKEYPublicKey* pk; 1118 uint8_t T; 1119 uint16_t length; 1120 uint16_t offset; 1121 SECItem Q = {siBuffer, NULL, 0}; 1122 SECItem P = {siBuffer, NULL, 0}; 1123 SECItem G = {siBuffer, NULL, 0}; 1124 SECItem Y = {siBuffer, NULL, 0}; 1125 1126 if(len == 0) 1127 return NULL; 1128 T = (uint8_t)key[0]; 1129 length = (64 + T * 8); 1130 offset = 1; 1131 1132 if (T > 8) { 1133 return NULL; 1134 } 1135 if(len < (size_t)1 + SHA1_LENGTH + 3*length) 1136 return NULL; 1137 1138 Q.data = key+offset; 1139 Q.len = SHA1_LENGTH; 1140 offset += SHA1_LENGTH; 1141 1142 P.data = key+offset; 1143 P.len = length; 1144 offset += length; 1145 1146 G.data = key+offset; 1147 G.len = length; 1148 offset += length; 1149 1150 Y.data = key+offset; 1151 Y.len = length; 1152 offset += length; 1153 1154 pk = nss_key_create(dsaKey); 1155 if(!pk) 1156 return NULL; 1157 if(SECITEM_CopyItem(pk->arena, &pk->u.dsa.params.prime, &P)) { 1158 SECKEY_DestroyPublicKey(pk); 1159 return NULL; 1160 } 1161 if(SECITEM_CopyItem(pk->arena, &pk->u.dsa.params.subPrime, &Q)) { 1162 SECKEY_DestroyPublicKey(pk); 1163 return NULL; 1164 } 1165 if(SECITEM_CopyItem(pk->arena, &pk->u.dsa.params.base, &G)) { 1166 SECKEY_DestroyPublicKey(pk); 1167 return NULL; 1168 } 1169 if(SECITEM_CopyItem(pk->arena, &pk->u.dsa.publicValue, &Y)) { 1170 SECKEY_DestroyPublicKey(pk); 1171 return NULL; 1172 } 1173 return pk; 1174 } 1175 #endif /* USE_DSA && USE_SHA1 */ 1176 1177 static SECKEYPublicKey* nss_buf2rsa(unsigned char* key, size_t len) 1178 { 1179 SECKEYPublicKey* pk; 1180 uint16_t exp; 1181 uint16_t offset; 1182 uint16_t int16; 1183 SECItem modulus = {siBuffer, NULL, 0}; 1184 SECItem exponent = {siBuffer, NULL, 0}; 1185 if(len == 0) 1186 return NULL; 1187 if(key[0] == 0) { 1188 if(len < 3) 1189 return NULL; 1190 /* the exponent is too large so it's places further */ 1191 memmove(&int16, key+1, 2); 1192 exp = ntohs(int16); 1193 offset = 3; 1194 } else { 1195 exp = key[0]; 1196 offset = 1; 1197 } 1198 1199 /* key length at least one */ 1200 if(len < (size_t)offset + exp + 1) 1201 return NULL; 1202 1203 exponent.data = key+offset; 1204 exponent.len = exp; 1205 offset += exp; 1206 modulus.data = key+offset; 1207 modulus.len = (len - offset); 1208 1209 pk = nss_key_create(rsaKey); 1210 if(!pk) 1211 return NULL; 1212 if(SECITEM_CopyItem(pk->arena, &pk->u.rsa.modulus, &modulus)) { 1213 SECKEY_DestroyPublicKey(pk); 1214 return NULL; 1215 } 1216 if(SECITEM_CopyItem(pk->arena, &pk->u.rsa.publicExponent, &exponent)) { 1217 SECKEY_DestroyPublicKey(pk); 1218 return NULL; 1219 } 1220 return pk; 1221 } 1222 1223 /** 1224 * Setup key and digest for verification. Adjust sig if necessary. 1225 * 1226 * @param algo: key algorithm 1227 * @param evp_key: EVP PKEY public key to create. 1228 * @param digest_type: digest type to use 1229 * @param key: key to setup for. 1230 * @param keylen: length of key. 1231 * @param prefix: if returned, the ASN prefix for the hashblob. 1232 * @param prefixlen: length of the prefix. 1233 * @return false on failure. 1234 */ 1235 static int 1236 nss_setup_key_digest(int algo, SECKEYPublicKey** pubkey, HASH_HashType* htype, 1237 unsigned char* key, size_t keylen, unsigned char** prefix, 1238 size_t* prefixlen) 1239 { 1240 /* uses libNSS */ 1241 1242 /* hash prefix for md5, RFC2537 */ 1243 static unsigned char p_md5[] = {0x30, 0x20, 0x30, 0x0c, 0x06, 0x08, 0x2a, 1244 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x02, 0x05, 0x05, 0x00, 0x04, 0x10}; 1245 /* hash prefix to prepend to hash output, from RFC3110 */ 1246 static unsigned char p_sha1[] = {0x30, 0x21, 0x30, 0x09, 0x06, 0x05, 0x2B, 1247 0x0E, 0x03, 0x02, 0x1A, 0x05, 0x00, 0x04, 0x14}; 1248 /* from RFC5702 */ 1249 static unsigned char p_sha256[] = {0x30, 0x31, 0x30, 0x0d, 0x06, 0x09, 0x60, 1250 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x01, 0x05, 0x00, 0x04, 0x20}; 1251 static unsigned char p_sha512[] = {0x30, 0x51, 0x30, 0x0d, 0x06, 0x09, 0x60, 1252 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x03, 0x05, 0x00, 0x04, 0x40}; 1253 /* from RFC6234 */ 1254 /* for future RSASHA384 .. 1255 static unsigned char p_sha384[] = {0x30, 0x51, 0x30, 0x0d, 0x06, 0x09, 0x60, 1256 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x02, 0x05, 0x00, 0x04, 0x30}; 1257 */ 1258 1259 switch(algo) { 1260 1261 #if defined(USE_SHA1) || defined(USE_SHA2) 1262 #if defined(USE_DSA) && defined(USE_SHA1) 1263 case LDNS_DSA: 1264 case LDNS_DSA_NSEC3: 1265 *pubkey = nss_buf2dsa(key, keylen); 1266 if(!*pubkey) { 1267 log_err("verify: malloc failure in crypto"); 1268 return 0; 1269 } 1270 *htype = HASH_AlgSHA1; 1271 /* no prefix for DSA verification */ 1272 break; 1273 #endif 1274 #ifdef USE_SHA1 1275 case LDNS_RSASHA1: 1276 case LDNS_RSASHA1_NSEC3: 1277 #endif 1278 #ifdef USE_SHA2 1279 case LDNS_RSASHA256: 1280 #endif 1281 #ifdef USE_SHA2 1282 case LDNS_RSASHA512: 1283 #endif 1284 *pubkey = nss_buf2rsa(key, keylen); 1285 if(!*pubkey) { 1286 log_err("verify: malloc failure in crypto"); 1287 return 0; 1288 } 1289 /* select SHA version */ 1290 #ifdef USE_SHA2 1291 if(algo == LDNS_RSASHA256) { 1292 *htype = HASH_AlgSHA256; 1293 *prefix = p_sha256; 1294 *prefixlen = sizeof(p_sha256); 1295 } else 1296 #endif 1297 #ifdef USE_SHA2 1298 if(algo == LDNS_RSASHA512) { 1299 *htype = HASH_AlgSHA512; 1300 *prefix = p_sha512; 1301 *prefixlen = sizeof(p_sha512); 1302 } else 1303 #endif 1304 #ifdef USE_SHA1 1305 { 1306 *htype = HASH_AlgSHA1; 1307 *prefix = p_sha1; 1308 *prefixlen = sizeof(p_sha1); 1309 } 1310 #else 1311 { 1312 verbose(VERB_QUERY, "verify: no digest algo"); 1313 return 0; 1314 } 1315 #endif 1316 1317 break; 1318 #endif /* SHA1 or SHA2 */ 1319 1320 case LDNS_RSAMD5: 1321 *pubkey = nss_buf2rsa(key, keylen); 1322 if(!*pubkey) { 1323 log_err("verify: malloc failure in crypto"); 1324 return 0; 1325 } 1326 *htype = HASH_AlgMD5; 1327 *prefix = p_md5; 1328 *prefixlen = sizeof(p_md5); 1329 1330 break; 1331 #ifdef USE_ECDSA 1332 case LDNS_ECDSAP256SHA256: 1333 *pubkey = nss_buf2ecdsa(key, keylen, 1334 LDNS_ECDSAP256SHA256); 1335 if(!*pubkey) { 1336 log_err("verify: malloc failure in crypto"); 1337 return 0; 1338 } 1339 *htype = HASH_AlgSHA256; 1340 /* no prefix for DSA verification */ 1341 break; 1342 case LDNS_ECDSAP384SHA384: 1343 *pubkey = nss_buf2ecdsa(key, keylen, 1344 LDNS_ECDSAP384SHA384); 1345 if(!*pubkey) { 1346 log_err("verify: malloc failure in crypto"); 1347 return 0; 1348 } 1349 *htype = HASH_AlgSHA384; 1350 /* no prefix for DSA verification */ 1351 break; 1352 #endif /* USE_ECDSA */ 1353 case LDNS_ECC_GOST: 1354 default: 1355 verbose(VERB_QUERY, "verify: unknown algorithm %d", 1356 algo); 1357 return 0; 1358 } 1359 return 1; 1360 } 1361 1362 /** 1363 * Check a canonical sig+rrset and signature against a dnskey 1364 * @param buf: buffer with data to verify, the first rrsig part and the 1365 * canonicalized rrset. 1366 * @param algo: DNSKEY algorithm. 1367 * @param sigblock: signature rdata field from RRSIG 1368 * @param sigblock_len: length of sigblock data. 1369 * @param key: public key data from DNSKEY RR. 1370 * @param keylen: length of keydata. 1371 * @param reason: bogus reason in more detail. 1372 * @return secure if verification succeeded, bogus on crypto failure, 1373 * unchecked on format errors and alloc failures. 1374 */ 1375 enum sec_status 1376 verify_canonrrset(sldns_buffer* buf, int algo, unsigned char* sigblock, 1377 unsigned int sigblock_len, unsigned char* key, unsigned int keylen, 1378 char** reason) 1379 { 1380 /* uses libNSS */ 1381 /* large enough for the different hashes */ 1382 unsigned char hash[HASH_LENGTH_MAX]; 1383 unsigned char hash2[HASH_LENGTH_MAX*2]; 1384 HASH_HashType htype = 0; 1385 SECKEYPublicKey* pubkey = NULL; 1386 SECItem secsig = {siBuffer, sigblock, sigblock_len}; 1387 SECItem sechash = {siBuffer, hash, 0}; 1388 SECStatus res; 1389 unsigned char* prefix = NULL; /* prefix for hash, RFC3110, RFC5702 */ 1390 size_t prefixlen = 0; 1391 int err; 1392 1393 if(!nss_setup_key_digest(algo, &pubkey, &htype, key, keylen, 1394 &prefix, &prefixlen)) { 1395 verbose(VERB_QUERY, "verify: failed to setup key"); 1396 *reason = "use of key for crypto failed"; 1397 SECKEY_DestroyPublicKey(pubkey); 1398 return sec_status_bogus; 1399 } 1400 1401 #if defined(USE_DSA) && defined(USE_SHA1) 1402 /* need to convert DSA, ECDSA signatures? */ 1403 if((algo == LDNS_DSA || algo == LDNS_DSA_NSEC3)) { 1404 if(sigblock_len == 1+2*SHA1_LENGTH) { 1405 secsig.data ++; 1406 secsig.len --; 1407 } else { 1408 SECItem* p = DSAU_DecodeDerSig(&secsig); 1409 if(!p) { 1410 verbose(VERB_QUERY, "verify: failed DER decode"); 1411 *reason = "signature DER decode failed"; 1412 SECKEY_DestroyPublicKey(pubkey); 1413 return sec_status_bogus; 1414 } 1415 if(SECITEM_CopyItem(pubkey->arena, &secsig, p)) { 1416 log_err("alloc failure in DER decode"); 1417 SECKEY_DestroyPublicKey(pubkey); 1418 SECITEM_FreeItem(p, PR_TRUE); 1419 return sec_status_unchecked; 1420 } 1421 SECITEM_FreeItem(p, PR_TRUE); 1422 } 1423 } 1424 #endif /* USE_DSA */ 1425 1426 /* do the signature cryptography work */ 1427 /* hash the data */ 1428 sechash.len = HASH_ResultLen(htype); 1429 if(sechash.len > sizeof(hash)) { 1430 verbose(VERB_QUERY, "verify: hash too large for buffer"); 1431 SECKEY_DestroyPublicKey(pubkey); 1432 return sec_status_unchecked; 1433 } 1434 if(HASH_HashBuf(htype, hash, (unsigned char*)sldns_buffer_begin(buf), 1435 (unsigned int)sldns_buffer_limit(buf)) != SECSuccess) { 1436 verbose(VERB_QUERY, "verify: HASH_HashBuf failed"); 1437 SECKEY_DestroyPublicKey(pubkey); 1438 return sec_status_unchecked; 1439 } 1440 if(prefix) { 1441 int hashlen = sechash.len; 1442 if(prefixlen+hashlen > sizeof(hash2)) { 1443 verbose(VERB_QUERY, "verify: hashprefix too large"); 1444 SECKEY_DestroyPublicKey(pubkey); 1445 return sec_status_unchecked; 1446 } 1447 sechash.data = hash2; 1448 sechash.len = prefixlen+hashlen; 1449 memcpy(sechash.data, prefix, prefixlen); 1450 memmove(sechash.data+prefixlen, hash, hashlen); 1451 } 1452 1453 /* verify the signature */ 1454 res = PK11_Verify(pubkey, &secsig, &sechash, NULL /*wincx*/); 1455 SECKEY_DestroyPublicKey(pubkey); 1456 1457 if(res == SECSuccess) { 1458 return sec_status_secure; 1459 } 1460 err = PORT_GetError(); 1461 if(err != SEC_ERROR_BAD_SIGNATURE) { 1462 /* failed to verify */ 1463 verbose(VERB_QUERY, "verify: PK11_Verify failed: %s", 1464 PORT_ErrorToString(err)); 1465 /* if it is not supported, like ECC is removed, we get, 1466 * SEC_ERROR_NO_MODULE */ 1467 if(err == SEC_ERROR_NO_MODULE) 1468 return sec_status_unchecked; 1469 /* but other errors are commonly returned 1470 * for a bad signature from NSS. Thus we return bogus, 1471 * not unchecked */ 1472 *reason = "signature crypto failed"; 1473 return sec_status_bogus; 1474 } 1475 verbose(VERB_QUERY, "verify: signature mismatch: %s", 1476 PORT_ErrorToString(err)); 1477 *reason = "signature crypto failed"; 1478 return sec_status_bogus; 1479 } 1480 1481 #elif defined(HAVE_NETTLE) 1482 1483 #include "sha.h" 1484 #include "bignum.h" 1485 #include "macros.h" 1486 #include "rsa.h" 1487 #include "dsa.h" 1488 #ifdef HAVE_NETTLE_DSA_COMPAT_H 1489 #include "dsa-compat.h" 1490 #endif 1491 #include "asn1.h" 1492 #ifdef USE_ECDSA 1493 #include "ecdsa.h" 1494 #include "ecc-curve.h" 1495 #endif 1496 #ifdef HAVE_NETTLE_EDDSA_H 1497 #include "eddsa.h" 1498 #endif 1499 1500 static int 1501 _digest_nettle(int algo, uint8_t* buf, size_t len, 1502 unsigned char* res) 1503 { 1504 switch(algo) { 1505 case SHA1_DIGEST_SIZE: 1506 { 1507 struct sha1_ctx ctx; 1508 sha1_init(&ctx); 1509 sha1_update(&ctx, len, buf); 1510 sha1_digest(&ctx, SHA1_DIGEST_SIZE, res); 1511 return 1; 1512 } 1513 case SHA256_DIGEST_SIZE: 1514 { 1515 struct sha256_ctx ctx; 1516 sha256_init(&ctx); 1517 sha256_update(&ctx, len, buf); 1518 sha256_digest(&ctx, SHA256_DIGEST_SIZE, res); 1519 return 1; 1520 } 1521 case SHA384_DIGEST_SIZE: 1522 { 1523 struct sha384_ctx ctx; 1524 sha384_init(&ctx); 1525 sha384_update(&ctx, len, buf); 1526 sha384_digest(&ctx, SHA384_DIGEST_SIZE, res); 1527 return 1; 1528 } 1529 case SHA512_DIGEST_SIZE: 1530 { 1531 struct sha512_ctx ctx; 1532 sha512_init(&ctx); 1533 sha512_update(&ctx, len, buf); 1534 sha512_digest(&ctx, SHA512_DIGEST_SIZE, res); 1535 return 1; 1536 } 1537 default: 1538 break; 1539 } 1540 return 0; 1541 } 1542 1543 /* return size of digest if supported, or 0 otherwise */ 1544 size_t 1545 nsec3_hash_algo_size_supported(int id) 1546 { 1547 switch(id) { 1548 case NSEC3_HASH_SHA1: 1549 return SHA1_DIGEST_SIZE; 1550 default: 1551 return 0; 1552 } 1553 } 1554 1555 /* perform nsec3 hash. return false on failure */ 1556 int 1557 secalgo_nsec3_hash(int algo, unsigned char* buf, size_t len, 1558 unsigned char* res) 1559 { 1560 switch(algo) { 1561 case NSEC3_HASH_SHA1: 1562 return _digest_nettle(SHA1_DIGEST_SIZE, (uint8_t*)buf, len, 1563 res); 1564 default: 1565 return 0; 1566 } 1567 } 1568 1569 void 1570 secalgo_hash_sha256(unsigned char* buf, size_t len, unsigned char* res) 1571 { 1572 _digest_nettle(SHA256_DIGEST_SIZE, (uint8_t*)buf, len, res); 1573 } 1574 1575 /** secalgo hash structure */ 1576 struct secalgo_hash { 1577 /** if it is 384 or 512 */ 1578 int active; 1579 /** context for sha384 */ 1580 struct sha384_ctx ctx384; 1581 /** context for sha512 */ 1582 struct sha512_ctx ctx512; 1583 }; 1584 1585 struct secalgo_hash* secalgo_hash_create_sha384(void) 1586 { 1587 struct secalgo_hash* h = calloc(1, sizeof(*h)); 1588 if(!h) 1589 return NULL; 1590 h->active = 384; 1591 sha384_init(&h->ctx384); 1592 return h; 1593 } 1594 1595 struct secalgo_hash* secalgo_hash_create_sha512(void) 1596 { 1597 struct secalgo_hash* h = calloc(1, sizeof(*h)); 1598 if(!h) 1599 return NULL; 1600 h->active = 512; 1601 sha512_init(&h->ctx512); 1602 return h; 1603 } 1604 1605 int secalgo_hash_update(struct secalgo_hash* hash, uint8_t* data, size_t len) 1606 { 1607 if(hash->active == 384) { 1608 sha384_update(&hash->ctx384, len, data); 1609 } else if(hash->active == 512) { 1610 sha512_update(&hash->ctx512, len, data); 1611 } else { 1612 return 0; 1613 } 1614 return 1; 1615 } 1616 1617 int secalgo_hash_final(struct secalgo_hash* hash, uint8_t* result, 1618 size_t maxlen, size_t* resultlen) 1619 { 1620 if(hash->active == 384) { 1621 if(SHA384_DIGEST_SIZE > maxlen) { 1622 *resultlen = 0; 1623 log_err("secalgo_hash_final: hash buffer too small"); 1624 return 0; 1625 } 1626 *resultlen = SHA384_DIGEST_SIZE; 1627 sha384_digest(&hash->ctx384, SHA384_DIGEST_SIZE, 1628 (unsigned char*)result); 1629 } else if(hash->active == 512) { 1630 if(SHA512_DIGEST_SIZE > maxlen) { 1631 *resultlen = 0; 1632 log_err("secalgo_hash_final: hash buffer too small"); 1633 return 0; 1634 } 1635 *resultlen = SHA512_DIGEST_SIZE; 1636 sha512_digest(&hash->ctx512, SHA512_DIGEST_SIZE, 1637 (unsigned char*)result); 1638 } else { 1639 *resultlen = 0; 1640 return 0; 1641 } 1642 return 1; 1643 } 1644 1645 void secalgo_hash_delete(struct secalgo_hash* hash) 1646 { 1647 if(!hash) return; 1648 free(hash); 1649 } 1650 1651 /** 1652 * Return size of DS digest according to its hash algorithm. 1653 * @param algo: DS digest algo. 1654 * @return size in bytes of digest, or 0 if not supported. 1655 */ 1656 size_t 1657 ds_digest_size_supported(int algo) 1658 { 1659 switch(algo) { 1660 case LDNS_SHA1: 1661 #ifdef USE_SHA1 1662 return SHA1_DIGEST_SIZE; 1663 #else 1664 if(fake_sha1) return 20; 1665 return 0; 1666 #endif 1667 #ifdef USE_SHA2 1668 case LDNS_SHA256: 1669 return SHA256_DIGEST_SIZE; 1670 #endif 1671 #ifdef USE_ECDSA 1672 case LDNS_SHA384: 1673 return SHA384_DIGEST_SIZE; 1674 #endif 1675 /* GOST not supported */ 1676 case LDNS_HASH_GOST: 1677 default: 1678 break; 1679 } 1680 return 0; 1681 } 1682 1683 int 1684 secalgo_ds_digest(int algo, unsigned char* buf, size_t len, 1685 unsigned char* res) 1686 { 1687 switch(algo) { 1688 #ifdef USE_SHA1 1689 case LDNS_SHA1: 1690 return _digest_nettle(SHA1_DIGEST_SIZE, buf, len, res); 1691 #endif 1692 #if defined(USE_SHA2) 1693 case LDNS_SHA256: 1694 return _digest_nettle(SHA256_DIGEST_SIZE, buf, len, res); 1695 #endif 1696 #ifdef USE_ECDSA 1697 case LDNS_SHA384: 1698 return _digest_nettle(SHA384_DIGEST_SIZE, buf, len, res); 1699 1700 #endif 1701 case LDNS_HASH_GOST: 1702 default: 1703 verbose(VERB_QUERY, "unknown DS digest algorithm %d", 1704 algo); 1705 break; 1706 } 1707 return 0; 1708 } 1709 1710 int 1711 dnskey_algo_id_is_supported(int id) 1712 { 1713 /* uses libnettle */ 1714 switch(id) { 1715 case LDNS_DSA: 1716 case LDNS_DSA_NSEC3: 1717 #if defined(USE_DSA) && defined(USE_SHA1) 1718 return 1; 1719 #else 1720 if(fake_dsa || fake_sha1) return 1; 1721 return 0; 1722 #endif 1723 case LDNS_RSASHA1: 1724 case LDNS_RSASHA1_NSEC3: 1725 #ifdef USE_SHA1 1726 return 1; 1727 #else 1728 if(fake_sha1) return 1; 1729 return 0; 1730 #endif 1731 #ifdef USE_SHA2 1732 case LDNS_RSASHA256: 1733 case LDNS_RSASHA512: 1734 #endif 1735 #ifdef USE_ECDSA 1736 case LDNS_ECDSAP256SHA256: 1737 case LDNS_ECDSAP384SHA384: 1738 #endif 1739 return 1; 1740 #ifdef USE_ED25519 1741 case LDNS_ED25519: 1742 return 1; 1743 #endif 1744 case LDNS_RSAMD5: /* RFC 6725 deprecates RSAMD5 */ 1745 case LDNS_ECC_GOST: 1746 default: 1747 return 0; 1748 } 1749 } 1750 1751 #if defined(USE_DSA) && defined(USE_SHA1) 1752 static char * 1753 _verify_nettle_dsa(sldns_buffer* buf, unsigned char* sigblock, 1754 unsigned int sigblock_len, unsigned char* key, unsigned int keylen) 1755 { 1756 uint8_t digest[SHA1_DIGEST_SIZE]; 1757 uint8_t key_t_value; 1758 int res = 0; 1759 size_t offset; 1760 struct dsa_public_key pubkey; 1761 struct dsa_signature signature; 1762 unsigned int expected_len; 1763 1764 /* Extract DSA signature from the record */ 1765 nettle_dsa_signature_init(&signature); 1766 /* Signature length: 41 bytes - RFC 2536 sec. 3 */ 1767 if(sigblock_len == 41) { 1768 if(key[0] != sigblock[0]) 1769 return "invalid T value in DSA signature or pubkey"; 1770 nettle_mpz_set_str_256_u(signature.r, 20, sigblock+1); 1771 nettle_mpz_set_str_256_u(signature.s, 20, sigblock+1+20); 1772 } else { 1773 /* DER encoded, decode the ASN1 notated R and S bignums */ 1774 /* SEQUENCE { r INTEGER, s INTEGER } */ 1775 struct asn1_der_iterator i, seq; 1776 if(asn1_der_iterator_first(&i, sigblock_len, 1777 (uint8_t*)sigblock) != ASN1_ITERATOR_CONSTRUCTED 1778 || i.type != ASN1_SEQUENCE) 1779 return "malformed DER encoded DSA signature"; 1780 /* decode this element of i using the seq iterator */ 1781 if(asn1_der_decode_constructed(&i, &seq) != 1782 ASN1_ITERATOR_PRIMITIVE || seq.type != ASN1_INTEGER) 1783 return "malformed DER encoded DSA signature"; 1784 if(!asn1_der_get_bignum(&seq, signature.r, 20*8)) 1785 return "malformed DER encoded DSA signature"; 1786 if(asn1_der_iterator_next(&seq) != ASN1_ITERATOR_PRIMITIVE 1787 || seq.type != ASN1_INTEGER) 1788 return "malformed DER encoded DSA signature"; 1789 if(!asn1_der_get_bignum(&seq, signature.s, 20*8)) 1790 return "malformed DER encoded DSA signature"; 1791 if(asn1_der_iterator_next(&i) != ASN1_ITERATOR_END) 1792 return "malformed DER encoded DSA signature"; 1793 } 1794 1795 /* Validate T values constraints - RFC 2536 sec. 2 & sec. 3 */ 1796 key_t_value = key[0]; 1797 if (key_t_value > 8) { 1798 return "invalid T value in DSA pubkey"; 1799 } 1800 1801 /* Pubkey minimum length: 21 bytes - RFC 2536 sec. 2 */ 1802 if (keylen < 21) { 1803 return "DSA pubkey too short"; 1804 } 1805 1806 expected_len = 1 + /* T */ 1807 20 + /* Q */ 1808 (64 + key_t_value*8) + /* P */ 1809 (64 + key_t_value*8) + /* G */ 1810 (64 + key_t_value*8); /* Y */ 1811 if (keylen != expected_len ) { 1812 return "invalid DSA pubkey length"; 1813 } 1814 1815 /* Extract DSA pubkey from the record */ 1816 nettle_dsa_public_key_init(&pubkey); 1817 offset = 1; 1818 nettle_mpz_set_str_256_u(pubkey.q, 20, key+offset); 1819 offset += 20; 1820 nettle_mpz_set_str_256_u(pubkey.p, (64 + key_t_value*8), key+offset); 1821 offset += (64 + key_t_value*8); 1822 nettle_mpz_set_str_256_u(pubkey.g, (64 + key_t_value*8), key+offset); 1823 offset += (64 + key_t_value*8); 1824 nettle_mpz_set_str_256_u(pubkey.y, (64 + key_t_value*8), key+offset); 1825 1826 /* Digest content of "buf" and verify its DSA signature in "sigblock"*/ 1827 res = _digest_nettle(SHA1_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf), 1828 (unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest); 1829 res &= dsa_sha1_verify_digest(&pubkey, digest, &signature); 1830 1831 /* Clear and return */ 1832 nettle_dsa_signature_clear(&signature); 1833 nettle_dsa_public_key_clear(&pubkey); 1834 if (!res) 1835 return "DSA signature verification failed"; 1836 else 1837 return NULL; 1838 } 1839 #endif /* USE_DSA */ 1840 1841 static char * 1842 _verify_nettle_rsa(sldns_buffer* buf, unsigned int digest_size, char* sigblock, 1843 unsigned int sigblock_len, uint8_t* key, unsigned int keylen) 1844 { 1845 uint16_t exp_len = 0; 1846 size_t exp_offset = 0, mod_offset = 0; 1847 struct rsa_public_key pubkey; 1848 mpz_t signature; 1849 int res = 0; 1850 1851 /* RSA pubkey parsing as per RFC 3110 sec. 2 */ 1852 if( keylen <= 1) { 1853 return "null RSA key"; 1854 } 1855 if (key[0] != 0) { 1856 /* 1-byte length */ 1857 exp_len = key[0]; 1858 exp_offset = 1; 1859 } else { 1860 /* 1-byte NUL + 2-bytes exponent length */ 1861 if (keylen < 3) { 1862 return "incorrect RSA key length"; 1863 } 1864 exp_len = READ_UINT16(key+1); 1865 if (exp_len == 0) 1866 return "null RSA exponent length"; 1867 exp_offset = 3; 1868 } 1869 /* Check that we are not over-running input length */ 1870 if (keylen < exp_offset + exp_len + 1) { 1871 return "RSA key content shorter than expected"; 1872 } 1873 mod_offset = exp_offset + exp_len; 1874 nettle_rsa_public_key_init(&pubkey); 1875 nettle_mpz_set_str_256_u(pubkey.e, exp_len, &key[exp_offset]); 1876 nettle_mpz_set_str_256_u(pubkey.n, keylen - mod_offset, &key[mod_offset]); 1877 pubkey.size = nettle_mpz_sizeinbase_256_u(pubkey.n); 1878 1879 /* Digest content of "buf" and verify its RSA signature in "sigblock"*/ 1880 nettle_mpz_init_set_str_256_u(signature, sigblock_len, (uint8_t*)sigblock); 1881 switch (digest_size) { 1882 case SHA1_DIGEST_SIZE: 1883 { 1884 uint8_t digest[SHA1_DIGEST_SIZE]; 1885 res = _digest_nettle(SHA1_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf), 1886 (unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest); 1887 res &= rsa_sha1_verify_digest(&pubkey, digest, signature); 1888 break; 1889 } 1890 case SHA256_DIGEST_SIZE: 1891 { 1892 uint8_t digest[SHA256_DIGEST_SIZE]; 1893 res = _digest_nettle(SHA256_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf), 1894 (unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest); 1895 res &= rsa_sha256_verify_digest(&pubkey, digest, signature); 1896 break; 1897 } 1898 case SHA512_DIGEST_SIZE: 1899 { 1900 uint8_t digest[SHA512_DIGEST_SIZE]; 1901 res = _digest_nettle(SHA512_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf), 1902 (unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest); 1903 res &= rsa_sha512_verify_digest(&pubkey, digest, signature); 1904 break; 1905 } 1906 default: 1907 break; 1908 } 1909 1910 /* Clear and return */ 1911 nettle_rsa_public_key_clear(&pubkey); 1912 mpz_clear(signature); 1913 if (!res) { 1914 return "RSA signature verification failed"; 1915 } else { 1916 return NULL; 1917 } 1918 } 1919 1920 #ifdef USE_ECDSA 1921 static char * 1922 _verify_nettle_ecdsa(sldns_buffer* buf, unsigned int digest_size, unsigned char* sigblock, 1923 unsigned int sigblock_len, unsigned char* key, unsigned int keylen) 1924 { 1925 int res = 0; 1926 struct ecc_point pubkey; 1927 struct dsa_signature signature; 1928 1929 /* Always matched strength, as per RFC 6605 sec. 1 */ 1930 if (sigblock_len != 2*digest_size || keylen != 2*digest_size) { 1931 return "wrong ECDSA signature length"; 1932 } 1933 1934 /* Parse ECDSA signature as per RFC 6605 sec. 4 */ 1935 nettle_dsa_signature_init(&signature); 1936 switch (digest_size) { 1937 case SHA256_DIGEST_SIZE: 1938 { 1939 uint8_t digest[SHA256_DIGEST_SIZE]; 1940 mpz_t x, y; 1941 nettle_ecc_point_init(&pubkey, nettle_get_secp_256r1()); 1942 nettle_mpz_init_set_str_256_u(x, SHA256_DIGEST_SIZE, key); 1943 nettle_mpz_init_set_str_256_u(y, SHA256_DIGEST_SIZE, key+SHA256_DIGEST_SIZE); 1944 nettle_mpz_set_str_256_u(signature.r, SHA256_DIGEST_SIZE, sigblock); 1945 nettle_mpz_set_str_256_u(signature.s, SHA256_DIGEST_SIZE, sigblock+SHA256_DIGEST_SIZE); 1946 res = _digest_nettle(SHA256_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf), 1947 (unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest); 1948 res &= nettle_ecc_point_set(&pubkey, x, y); 1949 res &= nettle_ecdsa_verify (&pubkey, SHA256_DIGEST_SIZE, digest, &signature); 1950 mpz_clear(x); 1951 mpz_clear(y); 1952 nettle_ecc_point_clear(&pubkey); 1953 break; 1954 } 1955 case SHA384_DIGEST_SIZE: 1956 { 1957 uint8_t digest[SHA384_DIGEST_SIZE]; 1958 mpz_t x, y; 1959 nettle_ecc_point_init(&pubkey, nettle_get_secp_384r1()); 1960 nettle_mpz_init_set_str_256_u(x, SHA384_DIGEST_SIZE, key); 1961 nettle_mpz_init_set_str_256_u(y, SHA384_DIGEST_SIZE, key+SHA384_DIGEST_SIZE); 1962 nettle_mpz_set_str_256_u(signature.r, SHA384_DIGEST_SIZE, sigblock); 1963 nettle_mpz_set_str_256_u(signature.s, SHA384_DIGEST_SIZE, sigblock+SHA384_DIGEST_SIZE); 1964 res = _digest_nettle(SHA384_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf), 1965 (unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest); 1966 res &= nettle_ecc_point_set(&pubkey, x, y); 1967 res &= nettle_ecdsa_verify (&pubkey, SHA384_DIGEST_SIZE, digest, &signature); 1968 mpz_clear(x); 1969 mpz_clear(y); 1970 nettle_ecc_point_clear(&pubkey); 1971 break; 1972 } 1973 default: 1974 return "unknown ECDSA algorithm"; 1975 } 1976 1977 /* Clear and return */ 1978 nettle_dsa_signature_clear(&signature); 1979 if (!res) 1980 return "ECDSA signature verification failed"; 1981 else 1982 return NULL; 1983 } 1984 #endif 1985 1986 #ifdef USE_ED25519 1987 static char * 1988 _verify_nettle_ed25519(sldns_buffer* buf, unsigned char* sigblock, 1989 unsigned int sigblock_len, unsigned char* key, unsigned int keylen) 1990 { 1991 int res = 0; 1992 1993 if(sigblock_len != ED25519_SIGNATURE_SIZE) { 1994 return "wrong ED25519 signature length"; 1995 } 1996 if(keylen != ED25519_KEY_SIZE) { 1997 return "wrong ED25519 key length"; 1998 } 1999 2000 res = ed25519_sha512_verify((uint8_t*)key, sldns_buffer_limit(buf), 2001 sldns_buffer_begin(buf), (uint8_t*)sigblock); 2002 2003 if (!res) 2004 return "ED25519 signature verification failed"; 2005 else 2006 return NULL; 2007 } 2008 #endif 2009 2010 /** 2011 * Check a canonical sig+rrset and signature against a dnskey 2012 * @param buf: buffer with data to verify, the first rrsig part and the 2013 * canonicalized rrset. 2014 * @param algo: DNSKEY algorithm. 2015 * @param sigblock: signature rdata field from RRSIG 2016 * @param sigblock_len: length of sigblock data. 2017 * @param key: public key data from DNSKEY RR. 2018 * @param keylen: length of keydata. 2019 * @param reason: bogus reason in more detail. 2020 * @return secure if verification succeeded, bogus on crypto failure, 2021 * unchecked on format errors and alloc failures. 2022 */ 2023 enum sec_status 2024 verify_canonrrset(sldns_buffer* buf, int algo, unsigned char* sigblock, 2025 unsigned int sigblock_len, unsigned char* key, unsigned int keylen, 2026 char** reason) 2027 { 2028 unsigned int digest_size = 0; 2029 2030 if (sigblock_len == 0 || keylen == 0) { 2031 *reason = "null signature"; 2032 return sec_status_bogus; 2033 } 2034 2035 #ifndef USE_DSA 2036 if((algo == LDNS_DSA || algo == LDNS_DSA_NSEC3) &&(fake_dsa||fake_sha1)) 2037 return sec_status_secure; 2038 #endif 2039 #ifndef USE_SHA1 2040 if(fake_sha1 && (algo == LDNS_DSA || algo == LDNS_DSA_NSEC3 || algo == LDNS_RSASHA1 || algo == LDNS_RSASHA1_NSEC3)) 2041 return sec_status_secure; 2042 #endif 2043 2044 switch(algo) { 2045 #if defined(USE_DSA) && defined(USE_SHA1) 2046 case LDNS_DSA: 2047 case LDNS_DSA_NSEC3: 2048 *reason = _verify_nettle_dsa(buf, sigblock, sigblock_len, key, keylen); 2049 if (*reason != NULL) 2050 return sec_status_bogus; 2051 else 2052 return sec_status_secure; 2053 #endif /* USE_DSA */ 2054 2055 #ifdef USE_SHA1 2056 case LDNS_RSASHA1: 2057 case LDNS_RSASHA1_NSEC3: 2058 digest_size = (digest_size ? digest_size : SHA1_DIGEST_SIZE); 2059 #endif 2060 /* double fallthrough annotation to please gcc parser */ 2061 ATTR_FALLTHROUGH 2062 /* fallthrough */ 2063 #ifdef USE_SHA2 2064 /* fallthrough */ 2065 case LDNS_RSASHA256: 2066 digest_size = (digest_size ? digest_size : SHA256_DIGEST_SIZE); 2067 ATTR_FALLTHROUGH 2068 /* fallthrough */ 2069 case LDNS_RSASHA512: 2070 digest_size = (digest_size ? digest_size : SHA512_DIGEST_SIZE); 2071 2072 #endif 2073 *reason = _verify_nettle_rsa(buf, digest_size, (char*)sigblock, 2074 sigblock_len, key, keylen); 2075 if (*reason != NULL) 2076 return sec_status_bogus; 2077 else 2078 return sec_status_secure; 2079 2080 #ifdef USE_ECDSA 2081 case LDNS_ECDSAP256SHA256: 2082 digest_size = (digest_size ? digest_size : SHA256_DIGEST_SIZE); 2083 ATTR_FALLTHROUGH 2084 /* fallthrough */ 2085 case LDNS_ECDSAP384SHA384: 2086 digest_size = (digest_size ? digest_size : SHA384_DIGEST_SIZE); 2087 *reason = _verify_nettle_ecdsa(buf, digest_size, sigblock, 2088 sigblock_len, key, keylen); 2089 if (*reason != NULL) 2090 return sec_status_bogus; 2091 else 2092 return sec_status_secure; 2093 #endif 2094 #ifdef USE_ED25519 2095 case LDNS_ED25519: 2096 *reason = _verify_nettle_ed25519(buf, sigblock, sigblock_len, 2097 key, keylen); 2098 if (*reason != NULL) 2099 return sec_status_bogus; 2100 else 2101 return sec_status_secure; 2102 #endif 2103 case LDNS_RSAMD5: 2104 case LDNS_ECC_GOST: 2105 default: 2106 *reason = "unable to verify signature, unknown algorithm"; 2107 return sec_status_bogus; 2108 } 2109 } 2110 2111 #endif /* HAVE_SSL or HAVE_NSS or HAVE_NETTLE */ 2112