Home | History | Annotate | Line # | Download | only in validator
      1 /*
      2  * validator/val_secalgo.c - validator security algorithm functions.
      3  *
      4  * Copyright (c) 2012, NLnet Labs. All rights reserved.
      5  *
      6  * This software is open source.
      7  *
      8  * Redistribution and use in source and binary forms, with or without
      9  * modification, are permitted provided that the following conditions
     10  * are met:
     11  *
     12  * Redistributions of source code must retain the above copyright notice,
     13  * this list of conditions and the following disclaimer.
     14  *
     15  * Redistributions in binary form must reproduce the above copyright notice,
     16  * this list of conditions and the following disclaimer in the documentation
     17  * and/or other materials provided with the distribution.
     18  *
     19  * Neither the name of the NLNET LABS nor the names of its contributors may
     20  * be used to endorse or promote products derived from this software without
     21  * specific prior written permission.
     22  *
     23  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
     24  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
     25  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
     26  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
     27  * HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
     28  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
     29  * TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
     30  * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
     31  * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
     32  * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
     33  * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     34  */
     35 
     36 /**
     37  * \file
     38  *
     39  * This file contains helper functions for the validator module.
     40  * These functions take raw data buffers, formatted for crypto verification,
     41  * and do the library calls (for the crypto library in use).
     42  */
     43 #include "config.h"
     44 /* packed_rrset on top to define enum types (forced by c99 standard) */
     45 #include "util/data/packed_rrset.h"
     46 #include "validator/val_secalgo.h"
     47 #include "validator/val_nsec3.h"
     48 #include "util/log.h"
     49 #include "sldns/rrdef.h"
     50 #include "sldns/keyraw.h"
     51 #include "sldns/sbuffer.h"
     52 
     53 #if !defined(HAVE_SSL) && !defined(HAVE_NSS) && !defined(HAVE_NETTLE)
     54 #error "Need crypto library to do digital signature cryptography"
     55 #endif
     56 
     57 /** fake DSA support for unit tests */
     58 int fake_dsa = 0;
     59 /** fake SHA1 support for unit tests */
     60 int fake_sha1 = 0;
     61 
     62 /* OpenSSL implementation */
     63 #ifdef HAVE_SSL
     64 #ifdef HAVE_OPENSSL_ERR_H
     65 #include <openssl/err.h>
     66 #endif
     67 
     68 #ifdef HAVE_OPENSSL_RAND_H
     69 #include <openssl/rand.h>
     70 #endif
     71 
     72 #ifdef HAVE_OPENSSL_CONF_H
     73 #include <openssl/conf.h>
     74 #endif
     75 
     76 #ifdef HAVE_OPENSSL_ENGINE_H
     77 #include <openssl/engine.h>
     78 #endif
     79 
     80 #if defined(HAVE_OPENSSL_DSA_H) && defined(USE_DSA)
     81 #include <openssl/dsa.h>
     82 #endif
     83 
     84 /**
     85  * Output a libcrypto openssl error to the logfile.
     86  * @param str: string to add to it.
     87  * @param e: the error to output, error number from ERR_get_error().
     88  */
     89 static void
     90 log_crypto_error(const char* str, unsigned long e)
     91 {
     92 	char buf[128];
     93 	/* or use ERR_error_string if ERR_error_string_n is not avail TODO */
     94 	ERR_error_string_n(e, buf, sizeof(buf));
     95 	/* buf now contains */
     96 	/* error:[error code]:[library name]:[function name]:[reason string] */
     97 	log_err("%s crypto %s", str, buf);
     98 }
     99 
    100 /**
    101  * Output a libcrypto openssl error to the logfile as a debug message.
    102  * @param level: debug level to use in verbose() call
    103  * @param str: string to add to it.
    104  * @param e: the error to output, error number from ERR_get_error().
    105  */
    106 static void
    107 log_crypto_verbose(enum verbosity_value level, const char* str, unsigned long e)
    108 {
    109 	char buf[128];
    110 	/* or use ERR_error_string if ERR_error_string_n is not avail TODO */
    111 	ERR_error_string_n(e, buf, sizeof(buf));
    112 	/* buf now contains */
    113 	/* error:[error code]:[library name]:[function name]:[reason string] */
    114 	verbose(level, "%s crypto %s", str, buf);
    115 }
    116 
    117 /* return size of digest if supported, or 0 otherwise */
    118 size_t
    119 nsec3_hash_algo_size_supported(int id)
    120 {
    121 	switch(id) {
    122 	case NSEC3_HASH_SHA1:
    123 		return SHA_DIGEST_LENGTH;
    124 	default:
    125 		return 0;
    126 	}
    127 }
    128 
    129 /* perform nsec3 hash. return false on failure */
    130 int
    131 secalgo_nsec3_hash(int algo, unsigned char* buf, size_t len,
    132         unsigned char* res)
    133 {
    134 	switch(algo) {
    135 	case NSEC3_HASH_SHA1:
    136 #ifdef OPENSSL_FIPS
    137 		if(!sldns_digest_evp(buf, len, res, EVP_sha1()))
    138 			log_crypto_error("could not digest with EVP_sha1",
    139 				ERR_get_error());
    140 #else
    141 		(void)SHA1(buf, len, res);
    142 #endif
    143 		return 1;
    144 	default:
    145 		return 0;
    146 	}
    147 }
    148 
    149 void
    150 secalgo_hash_sha256(unsigned char* buf, size_t len, unsigned char* res)
    151 {
    152 #ifdef OPENSSL_FIPS
    153 	if(!sldns_digest_evp(buf, len, res, EVP_sha256()))
    154 		log_crypto_error("could not digest with EVP_sha256",
    155 			ERR_get_error());
    156 #else
    157 	(void)SHA256(buf, len, res);
    158 #endif
    159 }
    160 
    161 /** hash structure for keeping track of running hashes */
    162 struct secalgo_hash {
    163 	/** the openssl message digest context */
    164 	EVP_MD_CTX* ctx;
    165 };
    166 
    167 /** create secalgo hash with hash type */
    168 static struct secalgo_hash* secalgo_hash_create_md(const EVP_MD* md)
    169 {
    170 	struct secalgo_hash* h;
    171 	if(!md)
    172 		return NULL;
    173 	h = calloc(1, sizeof(*h));
    174 	if(!h)
    175 		return NULL;
    176 	h->ctx = EVP_MD_CTX_create();
    177 	if(!h->ctx) {
    178 		free(h);
    179 		return NULL;
    180 	}
    181 	if(!EVP_DigestInit_ex(h->ctx, md, NULL)) {
    182 		EVP_MD_CTX_destroy(h->ctx);
    183 		free(h);
    184 		return NULL;
    185 	}
    186 	return h;
    187 }
    188 
    189 struct secalgo_hash* secalgo_hash_create_sha384(void)
    190 {
    191 	return secalgo_hash_create_md(EVP_sha384());
    192 }
    193 
    194 struct secalgo_hash* secalgo_hash_create_sha512(void)
    195 {
    196 	return secalgo_hash_create_md(EVP_sha512());
    197 }
    198 
    199 int secalgo_hash_update(struct secalgo_hash* hash, uint8_t* data, size_t len)
    200 {
    201 	return EVP_DigestUpdate(hash->ctx, (unsigned char*)data,
    202 		(unsigned int)len);
    203 }
    204 
    205 int secalgo_hash_final(struct secalgo_hash* hash, uint8_t* result,
    206         size_t maxlen, size_t* resultlen)
    207 {
    208 	if(EVP_MD_CTX_size(hash->ctx) > (int)maxlen) {
    209 		*resultlen = 0;
    210 		log_err("secalgo_hash_final: hash buffer too small");
    211 		return 0;
    212 	}
    213 	*resultlen = EVP_MD_CTX_size(hash->ctx);
    214 	return EVP_DigestFinal_ex(hash->ctx, result, NULL);
    215 }
    216 
    217 void secalgo_hash_delete(struct secalgo_hash* hash)
    218 {
    219 	if(!hash) return;
    220 	EVP_MD_CTX_destroy(hash->ctx);
    221 	free(hash);
    222 }
    223 
    224 /**
    225  * Return size of DS digest according to its hash algorithm.
    226  * @param algo: DS digest algo.
    227  * @return size in bytes of digest, or 0 if not supported.
    228  */
    229 size_t
    230 ds_digest_size_supported(int algo)
    231 {
    232 	switch(algo) {
    233 		case LDNS_SHA1:
    234 #if defined(HAVE_EVP_SHA1) && defined(USE_SHA1)
    235 #ifdef HAVE_EVP_DEFAULT_PROPERTIES_IS_FIPS_ENABLED
    236 			if (EVP_default_properties_is_fips_enabled(NULL))
    237 				return 0;
    238 #endif
    239 			return SHA_DIGEST_LENGTH;
    240 #else
    241 			if(fake_sha1) return 20;
    242 			return 0;
    243 #endif
    244 #ifdef HAVE_EVP_SHA256
    245 		case LDNS_SHA256:
    246 			return SHA256_DIGEST_LENGTH;
    247 #endif
    248 #ifdef USE_GOST
    249 		case LDNS_HASH_GOST:
    250 			/* we support GOST if it can be loaded */
    251 			(void)sldns_key_EVP_load_gost_id();
    252 			if(EVP_get_digestbyname("md_gost94"))
    253 				return 32;
    254 			else	return 0;
    255 #endif
    256 #ifdef USE_ECDSA
    257 		case LDNS_SHA384:
    258 			return SHA384_DIGEST_LENGTH;
    259 #endif
    260 		default: break;
    261 	}
    262 	return 0;
    263 }
    264 
    265 #ifdef USE_GOST
    266 /** Perform GOST hash */
    267 static int
    268 do_gost94(unsigned char* data, size_t len, unsigned char* dest)
    269 {
    270 	const EVP_MD* md = EVP_get_digestbyname("md_gost94");
    271 	if(!md)
    272 		return 0;
    273 	return sldns_digest_evp(data, (unsigned int)len, dest, md);
    274 }
    275 #endif
    276 
    277 int
    278 secalgo_ds_digest(int algo, unsigned char* buf, size_t len,
    279 	unsigned char* res)
    280 {
    281 	switch(algo) {
    282 #if defined(HAVE_EVP_SHA1) && defined(USE_SHA1)
    283 		case LDNS_SHA1:
    284 #ifdef OPENSSL_FIPS
    285 			if(!sldns_digest_evp(buf, len, res, EVP_sha1()))
    286 				log_crypto_error("could not digest with EVP_sha1",
    287 					ERR_get_error());
    288 #else
    289 			(void)SHA1(buf, len, res);
    290 #endif
    291 			return 1;
    292 #endif
    293 #ifdef HAVE_EVP_SHA256
    294 		case LDNS_SHA256:
    295 #ifdef OPENSSL_FIPS
    296 			if(!sldns_digest_evp(buf, len, res, EVP_sha256()))
    297 				log_crypto_error("could not digest with EVP_sha256",
    298 					ERR_get_error());
    299 #else
    300 			(void)SHA256(buf, len, res);
    301 #endif
    302 			return 1;
    303 #endif
    304 #ifdef USE_GOST
    305 		case LDNS_HASH_GOST:
    306 			if(do_gost94(buf, len, res))
    307 				return 1;
    308 			break;
    309 #endif
    310 #ifdef USE_ECDSA
    311 		case LDNS_SHA384:
    312 #ifdef OPENSSL_FIPS
    313 			if(!sldns_digest_evp(buf, len, res, EVP_sha384()))
    314 				log_crypto_error("could not digest with EVP_sha384",
    315 					ERR_get_error());
    316 #else
    317 			(void)SHA384(buf, len, res);
    318 #endif
    319 			return 1;
    320 #endif
    321 		default:
    322 			verbose(VERB_QUERY, "unknown DS digest algorithm %d",
    323 				algo);
    324 			break;
    325 	}
    326 	return 0;
    327 }
    328 
    329 /** return true if DNSKEY algorithm id is supported */
    330 int
    331 dnskey_algo_id_is_supported(int id)
    332 {
    333 	switch(id) {
    334 	case LDNS_RSAMD5:
    335 		/* RFC 6725 deprecates RSAMD5 */
    336 		return 0;
    337 	case LDNS_DSA:
    338 	case LDNS_DSA_NSEC3:
    339 #if defined(USE_DSA) && defined(USE_SHA1)
    340 		return 1;
    341 #else
    342 		if(fake_dsa || fake_sha1) return 1;
    343 		return 0;
    344 #endif
    345 
    346 	case LDNS_RSASHA1:
    347 	case LDNS_RSASHA1_NSEC3:
    348 #ifdef USE_SHA1
    349 #ifdef HAVE_EVP_DEFAULT_PROPERTIES_IS_FIPS_ENABLED
    350 		return !EVP_default_properties_is_fips_enabled(NULL);
    351 #else
    352 		return 1;
    353 #endif
    354 #else
    355 		if(fake_sha1) return 1;
    356 		return 0;
    357 #endif
    358 
    359 #if defined(HAVE_EVP_SHA256) && defined(USE_SHA2)
    360 	case LDNS_RSASHA256:
    361 #endif
    362 #if defined(HAVE_EVP_SHA512) && defined(USE_SHA2)
    363 	case LDNS_RSASHA512:
    364 #endif
    365 #ifdef USE_ECDSA
    366 	case LDNS_ECDSAP256SHA256:
    367 	case LDNS_ECDSAP384SHA384:
    368 #endif
    369 #if (defined(HAVE_EVP_SHA256) && defined(USE_SHA2)) || (defined(HAVE_EVP_SHA512) && defined(USE_SHA2)) || defined(USE_ECDSA)
    370 		return 1;
    371 #endif
    372 #ifdef USE_ED25519
    373 	case LDNS_ED25519:
    374 #endif
    375 #ifdef USE_ED448
    376 	case LDNS_ED448:
    377 #endif
    378 #if defined(USE_ED25519) || defined(USE_ED448)
    379 #ifdef HAVE_EVP_DEFAULT_PROPERTIES_IS_FIPS_ENABLED
    380 		return !EVP_default_properties_is_fips_enabled(NULL);
    381 #else
    382 		return 1;
    383 #endif
    384 #endif
    385 
    386 #ifdef USE_GOST
    387 	case LDNS_ECC_GOST:
    388 		/* we support GOST if it can be loaded */
    389 		return sldns_key_EVP_load_gost_id();
    390 #endif
    391 	default:
    392 		return 0;
    393 	}
    394 }
    395 
    396 #ifdef USE_DSA
    397 /**
    398  * Setup DSA key digest in DER encoding ...
    399  * @param sig: input is signature output alloced ptr (unless failure).
    400  * 	caller must free alloced ptr if this routine returns true.
    401  * @param len: input is initial siglen, output is output len.
    402  * @return false on failure.
    403  */
    404 static int
    405 setup_dsa_sig(unsigned char** sig, unsigned int* len)
    406 {
    407 	unsigned char* orig = *sig;
    408 	unsigned int origlen = *len;
    409 	int newlen;
    410 	BIGNUM *R, *S;
    411 	DSA_SIG *dsasig;
    412 
    413 	/* extract the R and S field from the sig buffer */
    414 	if(origlen < 1 + 2*SHA_DIGEST_LENGTH)
    415 		return 0;
    416 	R = BN_new();
    417 	if(!R) return 0;
    418 	(void) BN_bin2bn(orig + 1, SHA_DIGEST_LENGTH, R);
    419 	S = BN_new();
    420 	if(!S) return 0;
    421 	(void) BN_bin2bn(orig + 21, SHA_DIGEST_LENGTH, S);
    422 	dsasig = DSA_SIG_new();
    423 	if(!dsasig) return 0;
    424 
    425 #ifdef HAVE_DSA_SIG_SET0
    426 	if(!DSA_SIG_set0(dsasig, R, S)) {
    427 		DSA_SIG_free(dsasig);
    428 		return 0;
    429 	}
    430 #else
    431 #  ifndef S_SPLINT_S
    432 	dsasig->r = R;
    433 	dsasig->s = S;
    434 #  endif /* S_SPLINT_S */
    435 #endif
    436 	*sig = NULL;
    437 	newlen = i2d_DSA_SIG(dsasig, sig);
    438 	if(newlen < 0) {
    439 		DSA_SIG_free(dsasig);
    440 		free(*sig);
    441 		return 0;
    442 	}
    443 	*len = (unsigned int)newlen;
    444 	DSA_SIG_free(dsasig);
    445 	return 1;
    446 }
    447 #endif /* USE_DSA */
    448 
    449 #ifdef USE_ECDSA
    450 /**
    451  * Setup the ECDSA signature in its encoding that the library wants.
    452  * Converts from plain numbers to ASN formatted.
    453  * @param sig: input is signature, output alloced ptr (unless failure).
    454  * 	caller must free alloced ptr if this routine returns true.
    455  * @param len: input is initial siglen, output is output len.
    456  * @return false on failure.
    457  */
    458 static int
    459 setup_ecdsa_sig(unsigned char** sig, unsigned int* len)
    460 {
    461         /* convert from two BIGNUMs in the rdata buffer, to ASN notation.
    462 	 * ASN preamble: 30440220 <R 32bytefor256> 0220 <S 32bytefor256>
    463 	 * the '20' is the length of that field (=bnsize).
    464 i	 * the '44' is the total remaining length.
    465 	 * if negative, start with leading zero.
    466 	 * if starts with 00s, remove them from the number.
    467 	 */
    468         uint8_t pre[] = {0x30, 0x44, 0x02, 0x20};
    469         int pre_len = 4;
    470         uint8_t mid[] = {0x02, 0x20};
    471         int mid_len = 2;
    472         int raw_sig_len, r_high, s_high, r_rem=0, s_rem=0;
    473 	int bnsize = (int)((*len)/2);
    474         unsigned char* d = *sig;
    475 	uint8_t* p;
    476 	/* if too short or not even length, fails */
    477 	if(*len < 16 || bnsize*2 != (int)*len)
    478 		return 0;
    479 
    480         /* strip leading zeroes from r (but not last one) */
    481         while(r_rem < bnsize-1 && d[r_rem] == 0)
    482                 r_rem++;
    483         /* strip leading zeroes from s (but not last one) */
    484         while(s_rem < bnsize-1 && d[bnsize+s_rem] == 0)
    485                 s_rem++;
    486 
    487         r_high = ((d[0+r_rem]&0x80)?1:0);
    488         s_high = ((d[bnsize+s_rem]&0x80)?1:0);
    489         raw_sig_len = pre_len + r_high + bnsize - r_rem + mid_len +
    490                 s_high + bnsize - s_rem;
    491 	*sig = (unsigned char*)malloc((size_t)raw_sig_len);
    492 	if(!*sig)
    493 		return 0;
    494 	p = (uint8_t*)*sig;
    495 	p[0] = pre[0];
    496 	p[1] = (uint8_t)(raw_sig_len-2);
    497 	p[2] = pre[2];
    498 	p[3] = (uint8_t)(bnsize + r_high - r_rem);
    499 	p += 4;
    500 	if(r_high) {
    501 		*p = 0;
    502 		p += 1;
    503 	}
    504 	memmove(p, d+r_rem, (size_t)bnsize-r_rem);
    505 	p += bnsize-r_rem;
    506 	memmove(p, mid, (size_t)mid_len-1);
    507 	p += mid_len-1;
    508 	*p = (uint8_t)(bnsize + s_high - s_rem);
    509 	p += 1;
    510         if(s_high) {
    511 		*p = 0;
    512 		p += 1;
    513 	}
    514 	memmove(p, d+bnsize+s_rem, (size_t)bnsize-s_rem);
    515 	*len = (unsigned int)raw_sig_len;
    516 	return 1;
    517 }
    518 #endif /* USE_ECDSA */
    519 
    520 #ifdef USE_ECDSA_EVP_WORKAROUND
    521 static EVP_MD ecdsa_evp_256_md;
    522 static EVP_MD ecdsa_evp_384_md;
    523 void ecdsa_evp_workaround_init(void)
    524 {
    525 	/* openssl before 1.0.0 fixes RSA with the SHA256
    526 	 * hash in EVP.  We create one for ecdsa_sha256 */
    527 	ecdsa_evp_256_md = *EVP_sha256();
    528 	ecdsa_evp_256_md.required_pkey_type[0] = EVP_PKEY_EC;
    529 	ecdsa_evp_256_md.verify = (void*)ECDSA_verify;
    530 
    531 	ecdsa_evp_384_md = *EVP_sha384();
    532 	ecdsa_evp_384_md.required_pkey_type[0] = EVP_PKEY_EC;
    533 	ecdsa_evp_384_md.verify = (void*)ECDSA_verify;
    534 }
    535 #endif /* USE_ECDSA_EVP_WORKAROUND */
    536 
    537 /**
    538  * Setup key and digest for verification. Adjust sig if necessary.
    539  *
    540  * @param algo: key algorithm
    541  * @param evp_key: EVP PKEY public key to create.
    542  * @param digest_type: digest type to use
    543  * @param key: key to setup for.
    544  * @param keylen: length of key.
    545  * @return false on failure.
    546  */
    547 static int
    548 setup_key_digest(int algo, EVP_PKEY** evp_key, const EVP_MD** digest_type,
    549 	unsigned char* key, size_t keylen)
    550 {
    551 	switch(algo) {
    552 #if defined(USE_DSA) && defined(USE_SHA1)
    553 		case LDNS_DSA:
    554 		case LDNS_DSA_NSEC3:
    555 			*evp_key = sldns_key_dsa2pkey_raw(key, keylen);
    556 			if(!*evp_key) {
    557 				verbose(VERB_QUERY, "verify: sldns_key_dsa2pkey failed");
    558 				return 0;
    559 			}
    560 #ifdef HAVE_EVP_DSS1
    561 			*digest_type = EVP_dss1();
    562 #else
    563 			*digest_type = EVP_sha1();
    564 #endif
    565 
    566 			break;
    567 #endif /* USE_DSA && USE_SHA1 */
    568 
    569 #if defined(USE_SHA1) || (defined(HAVE_EVP_SHA256) && defined(USE_SHA2)) || (defined(HAVE_EVP_SHA512) && defined(USE_SHA2))
    570 #ifdef USE_SHA1
    571 		case LDNS_RSASHA1:
    572 		case LDNS_RSASHA1_NSEC3:
    573 #endif
    574 #if defined(HAVE_EVP_SHA256) && defined(USE_SHA2)
    575 		case LDNS_RSASHA256:
    576 #endif
    577 #if defined(HAVE_EVP_SHA512) && defined(USE_SHA2)
    578 		case LDNS_RSASHA512:
    579 #endif
    580 			*evp_key = sldns_key_rsa2pkey_raw(key, keylen);
    581 			if(!*evp_key) {
    582 				verbose(VERB_QUERY, "verify: sldns_key_rsa2pkey SHA failed");
    583 				return 0;
    584 			}
    585 
    586 			/* select SHA version */
    587 #if defined(HAVE_EVP_SHA256) && defined(USE_SHA2)
    588 			if(algo == LDNS_RSASHA256)
    589 				*digest_type = EVP_sha256();
    590 			else
    591 #endif
    592 #if defined(HAVE_EVP_SHA512) && defined(USE_SHA2)
    593 				if(algo == LDNS_RSASHA512)
    594 				*digest_type = EVP_sha512();
    595 			else
    596 #endif
    597 #ifdef USE_SHA1
    598 				*digest_type = EVP_sha1();
    599 #else
    600 				{ verbose(VERB_QUERY, "no digest available"); return 0; }
    601 #endif
    602 			break;
    603 #endif /* defined(USE_SHA1) || (defined(HAVE_EVP_SHA256) && defined(USE_SHA2)) || (defined(HAVE_EVP_SHA512) && defined(USE_SHA2)) */
    604 
    605 		case LDNS_RSAMD5:
    606 			*evp_key = sldns_key_rsa2pkey_raw(key, keylen);
    607 			if(!*evp_key) {
    608 				verbose(VERB_QUERY, "verify: sldns_key_rsa2pkey MD5 failed");
    609 				return 0;
    610 			}
    611 			*digest_type = EVP_md5();
    612 
    613 			break;
    614 #ifdef USE_GOST
    615 		case LDNS_ECC_GOST:
    616 			*evp_key = sldns_gost2pkey_raw(key, keylen);
    617 			if(!*evp_key) {
    618 				verbose(VERB_QUERY, "verify: "
    619 					"sldns_gost2pkey_raw failed");
    620 				return 0;
    621 			}
    622 			*digest_type = EVP_get_digestbyname("md_gost94");
    623 			if(!*digest_type) {
    624 				verbose(VERB_QUERY, "verify: "
    625 					"EVP_getdigest md_gost94 failed");
    626 				return 0;
    627 			}
    628 			break;
    629 #endif
    630 #ifdef USE_ECDSA
    631 		case LDNS_ECDSAP256SHA256:
    632 			*evp_key = sldns_ecdsa2pkey_raw(key, keylen,
    633 				LDNS_ECDSAP256SHA256);
    634 			if(!*evp_key) {
    635 				verbose(VERB_QUERY, "verify: "
    636 					"sldns_ecdsa2pkey_raw failed");
    637 				return 0;
    638 			}
    639 #ifdef USE_ECDSA_EVP_WORKAROUND
    640 			*digest_type = &ecdsa_evp_256_md;
    641 #else
    642 			*digest_type = EVP_sha256();
    643 #endif
    644 			break;
    645 		case LDNS_ECDSAP384SHA384:
    646 			*evp_key = sldns_ecdsa2pkey_raw(key, keylen,
    647 				LDNS_ECDSAP384SHA384);
    648 			if(!*evp_key) {
    649 				verbose(VERB_QUERY, "verify: "
    650 					"sldns_ecdsa2pkey_raw failed");
    651 				return 0;
    652 			}
    653 #ifdef USE_ECDSA_EVP_WORKAROUND
    654 			*digest_type = &ecdsa_evp_384_md;
    655 #else
    656 			*digest_type = EVP_sha384();
    657 #endif
    658 			break;
    659 #endif /* USE_ECDSA */
    660 #ifdef USE_ED25519
    661 		case LDNS_ED25519:
    662 			*evp_key = sldns_ed255192pkey_raw(key, keylen);
    663 			if(!*evp_key) {
    664 				verbose(VERB_QUERY, "verify: "
    665 					"sldns_ed255192pkey_raw failed");
    666 				return 0;
    667 			}
    668 			*digest_type = NULL;
    669 			break;
    670 #endif /* USE_ED25519 */
    671 #ifdef USE_ED448
    672 		case LDNS_ED448:
    673 			*evp_key = sldns_ed4482pkey_raw(key, keylen);
    674 			if(!*evp_key) {
    675 				verbose(VERB_QUERY, "verify: "
    676 					"sldns_ed4482pkey_raw failed");
    677 				return 0;
    678 			}
    679 			*digest_type = NULL;
    680 			break;
    681 #endif /* USE_ED448 */
    682 		default:
    683 			verbose(VERB_QUERY, "verify: unknown algorithm %d",
    684 				algo);
    685 			return 0;
    686 	}
    687 	return 1;
    688 }
    689 
    690 static void
    691 digest_ctx_free(EVP_MD_CTX* ctx, EVP_PKEY *evp_key,
    692 	unsigned char* sigblock, int dofree, int docrypto_free)
    693 {
    694 #ifdef HAVE_EVP_MD_CTX_NEW
    695 	EVP_MD_CTX_destroy(ctx);
    696 #else
    697 	EVP_MD_CTX_cleanup(ctx);
    698 	free(ctx);
    699 #endif
    700 	EVP_PKEY_free(evp_key);
    701 	if(dofree) free(sigblock);
    702 	else if(docrypto_free) OPENSSL_free(sigblock);
    703 }
    704 
    705 static enum sec_status
    706 digest_error_status(const char *str)
    707 {
    708 	unsigned long e = ERR_get_error();
    709 #ifdef EVP_R_INVALID_DIGEST
    710 	if (ERR_GET_LIB(e) == ERR_LIB_EVP &&
    711 		ERR_GET_REASON(e) == EVP_R_INVALID_DIGEST) {
    712 		log_crypto_verbose(VERB_ALGO, str, e);
    713 		return sec_status_indeterminate;
    714 	}
    715 #endif
    716 	log_crypto_verbose(VERB_QUERY, str, e);
    717 	return sec_status_unchecked;
    718 }
    719 
    720 /**
    721  * Check a canonical sig+rrset and signature against a dnskey
    722  * @param buf: buffer with data to verify, the first rrsig part and the
    723  *	canonicalized rrset.
    724  * @param algo: DNSKEY algorithm.
    725  * @param sigblock: signature rdata field from RRSIG
    726  * @param sigblock_len: length of sigblock data.
    727  * @param key: public key data from DNSKEY RR.
    728  * @param keylen: length of keydata.
    729  * @param reason: bogus reason in more detail.
    730  * @return secure if verification succeeded, bogus on crypto failure,
    731  *	unchecked on format errors and alloc failures, indeterminate
    732  *	if digest is not supported by the crypto library (openssl3+ only).
    733  */
    734 enum sec_status
    735 verify_canonrrset(sldns_buffer* buf, int algo, unsigned char* sigblock,
    736 	unsigned int sigblock_len, unsigned char* key, unsigned int keylen,
    737 	char** reason)
    738 {
    739 	const EVP_MD *digest_type;
    740 	EVP_MD_CTX* ctx;
    741 	int res, dofree = 0, docrypto_free = 0;
    742 	EVP_PKEY *evp_key = NULL;
    743 
    744 #ifndef USE_DSA
    745 	if((algo == LDNS_DSA || algo == LDNS_DSA_NSEC3) &&(fake_dsa||fake_sha1))
    746 		return sec_status_secure;
    747 #endif
    748 	if(fake_sha1 && (algo == LDNS_DSA || algo == LDNS_DSA_NSEC3 || algo == LDNS_RSASHA1 || algo == LDNS_RSASHA1_NSEC3))
    749 		return sec_status_secure;
    750 
    751 	if(!setup_key_digest(algo, &evp_key, &digest_type, key, keylen)) {
    752 		verbose(VERB_QUERY, "verify: failed to setup key");
    753 		*reason = "use of key for crypto failed";
    754 		EVP_PKEY_free(evp_key);
    755 		return sec_status_bogus;
    756 	}
    757 #ifdef USE_DSA
    758 	/* if it is a DSA signature in bind format, convert to DER format */
    759 	if((algo == LDNS_DSA || algo == LDNS_DSA_NSEC3) &&
    760 		sigblock_len == 1+2*SHA_DIGEST_LENGTH) {
    761 		if(!setup_dsa_sig(&sigblock, &sigblock_len)) {
    762 			verbose(VERB_QUERY, "verify: failed to setup DSA sig");
    763 			*reason = "use of key for DSA crypto failed";
    764 			EVP_PKEY_free(evp_key);
    765 			return sec_status_bogus;
    766 		}
    767 		docrypto_free = 1;
    768 	}
    769 #endif
    770 #if defined(USE_ECDSA) && defined(USE_DSA)
    771 	else
    772 #endif
    773 #ifdef USE_ECDSA
    774 	if(algo == LDNS_ECDSAP256SHA256 || algo == LDNS_ECDSAP384SHA384) {
    775 		/* EVP uses ASN prefix on sig, which is not in the wire data */
    776 		if(!setup_ecdsa_sig(&sigblock, &sigblock_len)) {
    777 			verbose(VERB_QUERY, "verify: failed to setup ECDSA sig");
    778 			*reason = "use of signature for ECDSA crypto failed";
    779 			EVP_PKEY_free(evp_key);
    780 			return sec_status_bogus;
    781 		}
    782 		dofree = 1;
    783 	}
    784 #endif /* USE_ECDSA */
    785 
    786 	/* do the signature cryptography work */
    787 #ifdef HAVE_EVP_MD_CTX_NEW
    788 	ctx = EVP_MD_CTX_new();
    789 #else
    790 	ctx = (EVP_MD_CTX*)malloc(sizeof(*ctx));
    791 	if(ctx) EVP_MD_CTX_init(ctx);
    792 #endif
    793 	if(!ctx) {
    794 		log_err("EVP_MD_CTX_new: malloc failure");
    795 		EVP_PKEY_free(evp_key);
    796 		if(dofree) free(sigblock);
    797 		else if(docrypto_free) OPENSSL_free(sigblock);
    798 		return sec_status_unchecked;
    799 	}
    800 #ifndef HAVE_EVP_DIGESTVERIFY
    801 	if(EVP_DigestInit(ctx, digest_type) == 0) {
    802 		enum sec_status sec;
    803 		sec = digest_error_status("verify: EVP_DigestInit failed");
    804 		digest_ctx_free(ctx, evp_key, sigblock,
    805 			dofree, docrypto_free);
    806 		return sec;
    807 	}
    808 	if(EVP_DigestUpdate(ctx, (unsigned char*)sldns_buffer_begin(buf),
    809 		(unsigned int)sldns_buffer_limit(buf)) == 0) {
    810 		log_crypto_verbose(VERB_QUERY, "verify: EVP_DigestUpdate failed",
    811 			ERR_get_error());
    812 		digest_ctx_free(ctx, evp_key, sigblock,
    813 			dofree, docrypto_free);
    814 		return sec_status_unchecked;
    815 	}
    816 
    817 	res = EVP_VerifyFinal(ctx, sigblock, sigblock_len, evp_key);
    818 #else /* HAVE_EVP_DIGESTVERIFY */
    819 	if(EVP_DigestVerifyInit(ctx, NULL, digest_type, NULL, evp_key) == 0) {
    820 		enum sec_status sec;
    821 		sec = digest_error_status("verify: EVP_DigestVerifyInit failed");
    822 		digest_ctx_free(ctx, evp_key, sigblock,
    823 			dofree, docrypto_free);
    824 		return sec;
    825 	}
    826 	res = EVP_DigestVerify(ctx, sigblock, sigblock_len,
    827 		(unsigned char*)sldns_buffer_begin(buf),
    828 		sldns_buffer_limit(buf));
    829 #endif
    830 	digest_ctx_free(ctx, evp_key, sigblock,
    831 		dofree, docrypto_free);
    832 
    833 	if(res == 1) {
    834 		return sec_status_secure;
    835 	} else if(res == 0) {
    836 		verbose(VERB_QUERY, "verify: signature mismatch");
    837 		*reason = "signature crypto failed";
    838 		return sec_status_bogus;
    839 	}
    840 
    841 	log_crypto_error("verify:", ERR_get_error());
    842 	return sec_status_unchecked;
    843 }
    844 
    845 /**************************************************/
    846 #elif defined(HAVE_NSS)
    847 /* libnss implementation */
    848 /* nss3 */
    849 #include "sechash.h"
    850 #include "pk11pub.h"
    851 #include "keyhi.h"
    852 #include "secerr.h"
    853 #include "cryptohi.h"
    854 /* nspr4 */
    855 #include "prerror.h"
    856 
    857 /* return size of digest if supported, or 0 otherwise */
    858 size_t
    859 nsec3_hash_algo_size_supported(int id)
    860 {
    861 	switch(id) {
    862 	case NSEC3_HASH_SHA1:
    863 		return SHA1_LENGTH;
    864 	default:
    865 		return 0;
    866 	}
    867 }
    868 
    869 /* perform nsec3 hash. return false on failure */
    870 int
    871 secalgo_nsec3_hash(int algo, unsigned char* buf, size_t len,
    872         unsigned char* res)
    873 {
    874 	switch(algo) {
    875 	case NSEC3_HASH_SHA1:
    876 		(void)HASH_HashBuf(HASH_AlgSHA1, res, buf, (unsigned long)len);
    877 		return 1;
    878 	default:
    879 		return 0;
    880 	}
    881 }
    882 
    883 void
    884 secalgo_hash_sha256(unsigned char* buf, size_t len, unsigned char* res)
    885 {
    886 	(void)HASH_HashBuf(HASH_AlgSHA256, res, buf, (unsigned long)len);
    887 }
    888 
    889 /** the secalgo hash structure */
    890 struct secalgo_hash {
    891 	/** hash context */
    892 	HASHContext* ctx;
    893 };
    894 
    895 /** create hash struct of type */
    896 static struct secalgo_hash* secalgo_hash_create_type(HASH_HashType tp)
    897 {
    898 	struct secalgo_hash* h = calloc(1, sizeof(*h));
    899 	if(!h)
    900 		return NULL;
    901 	h->ctx = HASH_Create(tp);
    902 	if(!h->ctx) {
    903 		free(h);
    904 		return NULL;
    905 	}
    906 	return h;
    907 }
    908 
    909 struct secalgo_hash* secalgo_hash_create_sha384(void)
    910 {
    911 	return secalgo_hash_create_type(HASH_AlgSHA384);
    912 }
    913 
    914 struct secalgo_hash* secalgo_hash_create_sha512(void)
    915 {
    916 	return secalgo_hash_create_type(HASH_AlgSHA512);
    917 }
    918 
    919 int secalgo_hash_update(struct secalgo_hash* hash, uint8_t* data, size_t len)
    920 {
    921 	HASH_Update(hash->ctx, (unsigned char*)data, (unsigned int)len);
    922 	return 1;
    923 }
    924 
    925 int secalgo_hash_final(struct secalgo_hash* hash, uint8_t* result,
    926         size_t maxlen, size_t* resultlen)
    927 {
    928 	unsigned int reslen = 0;
    929 	if(HASH_ResultLenContext(hash->ctx) > (unsigned int)maxlen) {
    930 		*resultlen = 0;
    931 		log_err("secalgo_hash_final: hash buffer too small");
    932 		return 0;
    933 	}
    934 	HASH_End(hash->ctx, (unsigned char*)result, &reslen,
    935 		(unsigned int)maxlen);
    936 	*resultlen = (size_t)reslen;
    937 	return 1;
    938 }
    939 
    940 void secalgo_hash_delete(struct secalgo_hash* hash)
    941 {
    942 	if(!hash) return;
    943 	HASH_Destroy(hash->ctx);
    944 	free(hash);
    945 }
    946 
    947 size_t
    948 ds_digest_size_supported(int algo)
    949 {
    950 	/* uses libNSS */
    951 	switch(algo) {
    952 #ifdef USE_SHA1
    953 		case LDNS_SHA1:
    954 			return SHA1_LENGTH;
    955 #endif
    956 #ifdef USE_SHA2
    957 		case LDNS_SHA256:
    958 			return SHA256_LENGTH;
    959 #endif
    960 #ifdef USE_ECDSA
    961 		case LDNS_SHA384:
    962 			return SHA384_LENGTH;
    963 #endif
    964 		/* GOST not supported in NSS */
    965 		case LDNS_HASH_GOST:
    966 		default: break;
    967 	}
    968 	return 0;
    969 }
    970 
    971 int
    972 secalgo_ds_digest(int algo, unsigned char* buf, size_t len,
    973 	unsigned char* res)
    974 {
    975 	/* uses libNSS */
    976 	switch(algo) {
    977 #ifdef USE_SHA1
    978 		case LDNS_SHA1:
    979 			return HASH_HashBuf(HASH_AlgSHA1, res, buf, len)
    980 				== SECSuccess;
    981 #endif
    982 #if defined(USE_SHA2)
    983 		case LDNS_SHA256:
    984 			return HASH_HashBuf(HASH_AlgSHA256, res, buf, len)
    985 				== SECSuccess;
    986 #endif
    987 #ifdef USE_ECDSA
    988 		case LDNS_SHA384:
    989 			return HASH_HashBuf(HASH_AlgSHA384, res, buf, len)
    990 				== SECSuccess;
    991 #endif
    992 		case LDNS_HASH_GOST:
    993 		default:
    994 			verbose(VERB_QUERY, "unknown DS digest algorithm %d",
    995 				algo);
    996 			break;
    997 	}
    998 	return 0;
    999 }
   1000 
   1001 int
   1002 dnskey_algo_id_is_supported(int id)
   1003 {
   1004 	/* uses libNSS */
   1005 	switch(id) {
   1006 	case LDNS_RSAMD5:
   1007 		/* RFC 6725 deprecates RSAMD5 */
   1008 		return 0;
   1009 #if defined(USE_SHA1) || defined(USE_SHA2)
   1010 #if defined(USE_DSA) && defined(USE_SHA1)
   1011 	case LDNS_DSA:
   1012 	case LDNS_DSA_NSEC3:
   1013 #endif
   1014 #ifdef USE_SHA1
   1015 	case LDNS_RSASHA1:
   1016 	case LDNS_RSASHA1_NSEC3:
   1017 #endif
   1018 #ifdef USE_SHA2
   1019 	case LDNS_RSASHA256:
   1020 #endif
   1021 #ifdef USE_SHA2
   1022 	case LDNS_RSASHA512:
   1023 #endif
   1024 		return 1;
   1025 #endif /* SHA1 or SHA2 */
   1026 
   1027 #ifdef USE_ECDSA
   1028 	case LDNS_ECDSAP256SHA256:
   1029 	case LDNS_ECDSAP384SHA384:
   1030 		return PK11_TokenExists(CKM_ECDSA);
   1031 #endif
   1032 	case LDNS_ECC_GOST:
   1033 	default:
   1034 		return 0;
   1035 	}
   1036 }
   1037 
   1038 /* return a new public key for NSS */
   1039 static SECKEYPublicKey* nss_key_create(KeyType ktype)
   1040 {
   1041 	SECKEYPublicKey* key;
   1042 	PLArenaPool* arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
   1043 	if(!arena) {
   1044 		log_err("out of memory, PORT_NewArena failed");
   1045 		return NULL;
   1046 	}
   1047 	key = PORT_ArenaZNew(arena, SECKEYPublicKey);
   1048 	if(!key) {
   1049 		log_err("out of memory, PORT_ArenaZNew failed");
   1050 		PORT_FreeArena(arena, PR_FALSE);
   1051 		return NULL;
   1052 	}
   1053 	key->arena = arena;
   1054 	key->keyType = ktype;
   1055 	key->pkcs11Slot = NULL;
   1056 	key->pkcs11ID = CK_INVALID_HANDLE;
   1057 	return key;
   1058 }
   1059 
   1060 static SECKEYPublicKey* nss_buf2ecdsa(unsigned char* key, size_t len, int algo)
   1061 {
   1062 	SECKEYPublicKey* pk;
   1063 	SECItem pub = {siBuffer, NULL, 0};
   1064 	SECItem params = {siBuffer, NULL, 0};
   1065 	static unsigned char param256[] = {
   1066 		/* OBJECTIDENTIFIER 1.2.840.10045.3.1.7 (P-256)
   1067 		 * {iso(1) member-body(2) us(840) ansi-x962(10045) curves(3) prime(1) prime256v1(7)} */
   1068 		0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x03, 0x01, 0x07
   1069 	};
   1070 	static unsigned char param384[] = {
   1071 		/* OBJECTIDENTIFIER 1.3.132.0.34 (P-384)
   1072 		 * {iso(1) identified-organization(3) certicom(132) curve(0) ansip384r1(34)} */
   1073 		0x06, 0x05, 0x2b, 0x81, 0x04, 0x00, 0x22
   1074 	};
   1075 	unsigned char buf[256+2]; /* sufficient for 2*384/8+1 */
   1076 
   1077 	/* check length, which uncompressed must be 2 bignums */
   1078 	if(algo == LDNS_ECDSAP256SHA256) {
   1079 		if(len != 2*256/8) return NULL;
   1080 		/* ECCurve_X9_62_PRIME_256V1 */
   1081 	} else if(algo == LDNS_ECDSAP384SHA384) {
   1082 		if(len != 2*384/8) return NULL;
   1083 		/* ECCurve_X9_62_PRIME_384R1 */
   1084 	} else    return NULL;
   1085 
   1086 	buf[0] = 0x04; /* POINT_FORM_UNCOMPRESSED */
   1087 	memmove(buf+1, key, len);
   1088 	pub.data = buf;
   1089 	pub.len = len+1;
   1090 	if(algo == LDNS_ECDSAP256SHA256) {
   1091 		params.data = param256;
   1092 		params.len = sizeof(param256);
   1093 	} else {
   1094 		params.data = param384;
   1095 		params.len = sizeof(param384);
   1096 	}
   1097 
   1098 	pk = nss_key_create(ecKey);
   1099 	if(!pk)
   1100 		return NULL;
   1101 	pk->u.ec.size = (len/2)*8;
   1102 	if(SECITEM_CopyItem(pk->arena, &pk->u.ec.publicValue, &pub)) {
   1103 		SECKEY_DestroyPublicKey(pk);
   1104 		return NULL;
   1105 	}
   1106 	if(SECITEM_CopyItem(pk->arena, &pk->u.ec.DEREncodedParams, &params)) {
   1107 		SECKEY_DestroyPublicKey(pk);
   1108 		return NULL;
   1109 	}
   1110 
   1111 	return pk;
   1112 }
   1113 
   1114 #if defined(USE_DSA) && defined(USE_SHA1)
   1115 static SECKEYPublicKey* nss_buf2dsa(unsigned char* key, size_t len)
   1116 {
   1117 	SECKEYPublicKey* pk;
   1118 	uint8_t T;
   1119 	uint16_t length;
   1120 	uint16_t offset;
   1121 	SECItem Q = {siBuffer, NULL, 0};
   1122 	SECItem P = {siBuffer, NULL, 0};
   1123 	SECItem G = {siBuffer, NULL, 0};
   1124 	SECItem Y = {siBuffer, NULL, 0};
   1125 
   1126 	if(len == 0)
   1127 		return NULL;
   1128 	T = (uint8_t)key[0];
   1129 	length = (64 + T * 8);
   1130 	offset = 1;
   1131 
   1132 	if (T > 8) {
   1133 		return NULL;
   1134 	}
   1135 	if(len < (size_t)1 + SHA1_LENGTH + 3*length)
   1136 		return NULL;
   1137 
   1138 	Q.data = key+offset;
   1139 	Q.len = SHA1_LENGTH;
   1140 	offset += SHA1_LENGTH;
   1141 
   1142 	P.data = key+offset;
   1143 	P.len = length;
   1144 	offset += length;
   1145 
   1146 	G.data = key+offset;
   1147 	G.len = length;
   1148 	offset += length;
   1149 
   1150 	Y.data = key+offset;
   1151 	Y.len = length;
   1152 	offset += length;
   1153 
   1154 	pk = nss_key_create(dsaKey);
   1155 	if(!pk)
   1156 		return NULL;
   1157 	if(SECITEM_CopyItem(pk->arena, &pk->u.dsa.params.prime, &P)) {
   1158 		SECKEY_DestroyPublicKey(pk);
   1159 		return NULL;
   1160 	}
   1161 	if(SECITEM_CopyItem(pk->arena, &pk->u.dsa.params.subPrime, &Q)) {
   1162 		SECKEY_DestroyPublicKey(pk);
   1163 		return NULL;
   1164 	}
   1165 	if(SECITEM_CopyItem(pk->arena, &pk->u.dsa.params.base, &G)) {
   1166 		SECKEY_DestroyPublicKey(pk);
   1167 		return NULL;
   1168 	}
   1169 	if(SECITEM_CopyItem(pk->arena, &pk->u.dsa.publicValue, &Y)) {
   1170 		SECKEY_DestroyPublicKey(pk);
   1171 		return NULL;
   1172 	}
   1173 	return pk;
   1174 }
   1175 #endif /* USE_DSA && USE_SHA1 */
   1176 
   1177 static SECKEYPublicKey* nss_buf2rsa(unsigned char* key, size_t len)
   1178 {
   1179 	SECKEYPublicKey* pk;
   1180 	uint16_t exp;
   1181 	uint16_t offset;
   1182 	uint16_t int16;
   1183 	SECItem modulus = {siBuffer, NULL, 0};
   1184 	SECItem exponent = {siBuffer, NULL, 0};
   1185 	if(len == 0)
   1186 		return NULL;
   1187 	if(key[0] == 0) {
   1188 		if(len < 3)
   1189 			return NULL;
   1190 		/* the exponent is too large so it's places further */
   1191 		memmove(&int16, key+1, 2);
   1192 		exp = ntohs(int16);
   1193 		offset = 3;
   1194 	} else {
   1195 		exp = key[0];
   1196 		offset = 1;
   1197 	}
   1198 
   1199 	/* key length at least one */
   1200 	if(len < (size_t)offset + exp + 1)
   1201 		return NULL;
   1202 
   1203 	exponent.data = key+offset;
   1204 	exponent.len = exp;
   1205 	offset += exp;
   1206 	modulus.data = key+offset;
   1207 	modulus.len = (len - offset);
   1208 
   1209 	pk = nss_key_create(rsaKey);
   1210 	if(!pk)
   1211 		return NULL;
   1212 	if(SECITEM_CopyItem(pk->arena, &pk->u.rsa.modulus, &modulus)) {
   1213 		SECKEY_DestroyPublicKey(pk);
   1214 		return NULL;
   1215 	}
   1216 	if(SECITEM_CopyItem(pk->arena, &pk->u.rsa.publicExponent, &exponent)) {
   1217 		SECKEY_DestroyPublicKey(pk);
   1218 		return NULL;
   1219 	}
   1220 	return pk;
   1221 }
   1222 
   1223 /**
   1224  * Setup key and digest for verification. Adjust sig if necessary.
   1225  *
   1226  * @param algo: key algorithm
   1227  * @param evp_key: EVP PKEY public key to create.
   1228  * @param digest_type: digest type to use
   1229  * @param key: key to setup for.
   1230  * @param keylen: length of key.
   1231  * @param prefix: if returned, the ASN prefix for the hashblob.
   1232  * @param prefixlen: length of the prefix.
   1233  * @return false on failure.
   1234  */
   1235 static int
   1236 nss_setup_key_digest(int algo, SECKEYPublicKey** pubkey, HASH_HashType* htype,
   1237 	unsigned char* key, size_t keylen, unsigned char** prefix,
   1238 	size_t* prefixlen)
   1239 {
   1240 	/* uses libNSS */
   1241 
   1242 	/* hash prefix for md5, RFC2537 */
   1243 	static unsigned char p_md5[] = {0x30, 0x20, 0x30, 0x0c, 0x06, 0x08, 0x2a,
   1244 	0x86, 0x48, 0x86, 0xf7, 0x0d, 0x02, 0x05, 0x05, 0x00, 0x04, 0x10};
   1245 	/* hash prefix to prepend to hash output, from RFC3110 */
   1246 	static unsigned char p_sha1[] = {0x30, 0x21, 0x30, 0x09, 0x06, 0x05, 0x2B,
   1247 		0x0E, 0x03, 0x02, 0x1A, 0x05, 0x00, 0x04, 0x14};
   1248 	/* from RFC5702 */
   1249 	static unsigned char p_sha256[] = {0x30, 0x31, 0x30, 0x0d, 0x06, 0x09, 0x60,
   1250 	0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x01, 0x05, 0x00, 0x04, 0x20};
   1251 	static unsigned char p_sha512[] = {0x30, 0x51, 0x30, 0x0d, 0x06, 0x09, 0x60,
   1252 	0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x03, 0x05, 0x00, 0x04, 0x40};
   1253 	/* from RFC6234 */
   1254 	/* for future RSASHA384 ..
   1255 	static unsigned char p_sha384[] = {0x30, 0x51, 0x30, 0x0d, 0x06, 0x09, 0x60,
   1256 	0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x02, 0x02, 0x05, 0x00, 0x04, 0x30};
   1257 	*/
   1258 
   1259 	switch(algo) {
   1260 
   1261 #if defined(USE_SHA1) || defined(USE_SHA2)
   1262 #if defined(USE_DSA) && defined(USE_SHA1)
   1263 		case LDNS_DSA:
   1264 		case LDNS_DSA_NSEC3:
   1265 			*pubkey = nss_buf2dsa(key, keylen);
   1266 			if(!*pubkey) {
   1267 				log_err("verify: malloc failure in crypto");
   1268 				return 0;
   1269 			}
   1270 			*htype = HASH_AlgSHA1;
   1271 			/* no prefix for DSA verification */
   1272 			break;
   1273 #endif
   1274 #ifdef USE_SHA1
   1275 		case LDNS_RSASHA1:
   1276 		case LDNS_RSASHA1_NSEC3:
   1277 #endif
   1278 #ifdef USE_SHA2
   1279 		case LDNS_RSASHA256:
   1280 #endif
   1281 #ifdef USE_SHA2
   1282 		case LDNS_RSASHA512:
   1283 #endif
   1284 			*pubkey = nss_buf2rsa(key, keylen);
   1285 			if(!*pubkey) {
   1286 				log_err("verify: malloc failure in crypto");
   1287 				return 0;
   1288 			}
   1289 			/* select SHA version */
   1290 #ifdef USE_SHA2
   1291 			if(algo == LDNS_RSASHA256) {
   1292 				*htype = HASH_AlgSHA256;
   1293 				*prefix = p_sha256;
   1294 				*prefixlen = sizeof(p_sha256);
   1295 			} else
   1296 #endif
   1297 #ifdef USE_SHA2
   1298 				if(algo == LDNS_RSASHA512) {
   1299 				*htype = HASH_AlgSHA512;
   1300 				*prefix = p_sha512;
   1301 				*prefixlen = sizeof(p_sha512);
   1302 			} else
   1303 #endif
   1304 #ifdef USE_SHA1
   1305 			{
   1306 				*htype = HASH_AlgSHA1;
   1307 				*prefix = p_sha1;
   1308 				*prefixlen = sizeof(p_sha1);
   1309 			}
   1310 #else
   1311 			{
   1312 				verbose(VERB_QUERY, "verify: no digest algo");
   1313 				return 0;
   1314 			}
   1315 #endif
   1316 
   1317 			break;
   1318 #endif /* SHA1 or SHA2 */
   1319 
   1320 		case LDNS_RSAMD5:
   1321 			*pubkey = nss_buf2rsa(key, keylen);
   1322 			if(!*pubkey) {
   1323 				log_err("verify: malloc failure in crypto");
   1324 				return 0;
   1325 			}
   1326 			*htype = HASH_AlgMD5;
   1327 			*prefix = p_md5;
   1328 			*prefixlen = sizeof(p_md5);
   1329 
   1330 			break;
   1331 #ifdef USE_ECDSA
   1332 		case LDNS_ECDSAP256SHA256:
   1333 			*pubkey = nss_buf2ecdsa(key, keylen,
   1334 				LDNS_ECDSAP256SHA256);
   1335 			if(!*pubkey) {
   1336 				log_err("verify: malloc failure in crypto");
   1337 				return 0;
   1338 			}
   1339 			*htype = HASH_AlgSHA256;
   1340 			/* no prefix for DSA verification */
   1341 			break;
   1342 		case LDNS_ECDSAP384SHA384:
   1343 			*pubkey = nss_buf2ecdsa(key, keylen,
   1344 				LDNS_ECDSAP384SHA384);
   1345 			if(!*pubkey) {
   1346 				log_err("verify: malloc failure in crypto");
   1347 				return 0;
   1348 			}
   1349 			*htype = HASH_AlgSHA384;
   1350 			/* no prefix for DSA verification */
   1351 			break;
   1352 #endif /* USE_ECDSA */
   1353 		case LDNS_ECC_GOST:
   1354 		default:
   1355 			verbose(VERB_QUERY, "verify: unknown algorithm %d",
   1356 				algo);
   1357 			return 0;
   1358 	}
   1359 	return 1;
   1360 }
   1361 
   1362 /**
   1363  * Check a canonical sig+rrset and signature against a dnskey
   1364  * @param buf: buffer with data to verify, the first rrsig part and the
   1365  *	canonicalized rrset.
   1366  * @param algo: DNSKEY algorithm.
   1367  * @param sigblock: signature rdata field from RRSIG
   1368  * @param sigblock_len: length of sigblock data.
   1369  * @param key: public key data from DNSKEY RR.
   1370  * @param keylen: length of keydata.
   1371  * @param reason: bogus reason in more detail.
   1372  * @return secure if verification succeeded, bogus on crypto failure,
   1373  *	unchecked on format errors and alloc failures.
   1374  */
   1375 enum sec_status
   1376 verify_canonrrset(sldns_buffer* buf, int algo, unsigned char* sigblock,
   1377 	unsigned int sigblock_len, unsigned char* key, unsigned int keylen,
   1378 	char** reason)
   1379 {
   1380 	/* uses libNSS */
   1381 	/* large enough for the different hashes */
   1382 	unsigned char hash[HASH_LENGTH_MAX];
   1383 	unsigned char hash2[HASH_LENGTH_MAX*2];
   1384 	HASH_HashType htype = 0;
   1385 	SECKEYPublicKey* pubkey = NULL;
   1386 	SECItem secsig = {siBuffer, sigblock, sigblock_len};
   1387 	SECItem sechash = {siBuffer, hash, 0};
   1388 	SECStatus res;
   1389 	unsigned char* prefix = NULL; /* prefix for hash, RFC3110, RFC5702 */
   1390 	size_t prefixlen = 0;
   1391 	int err;
   1392 
   1393 	if(!nss_setup_key_digest(algo, &pubkey, &htype, key, keylen,
   1394 		&prefix, &prefixlen)) {
   1395 		verbose(VERB_QUERY, "verify: failed to setup key");
   1396 		*reason = "use of key for crypto failed";
   1397 		SECKEY_DestroyPublicKey(pubkey);
   1398 		return sec_status_bogus;
   1399 	}
   1400 
   1401 #if defined(USE_DSA) && defined(USE_SHA1)
   1402 	/* need to convert DSA, ECDSA signatures? */
   1403 	if((algo == LDNS_DSA || algo == LDNS_DSA_NSEC3)) {
   1404 		if(sigblock_len == 1+2*SHA1_LENGTH) {
   1405 			secsig.data ++;
   1406 			secsig.len --;
   1407 		} else {
   1408 			SECItem* p = DSAU_DecodeDerSig(&secsig);
   1409 			if(!p) {
   1410 				verbose(VERB_QUERY, "verify: failed DER decode");
   1411 				*reason = "signature DER decode failed";
   1412 				SECKEY_DestroyPublicKey(pubkey);
   1413 				return sec_status_bogus;
   1414 			}
   1415 			if(SECITEM_CopyItem(pubkey->arena, &secsig, p)) {
   1416 				log_err("alloc failure in DER decode");
   1417 				SECKEY_DestroyPublicKey(pubkey);
   1418 				SECITEM_FreeItem(p, PR_TRUE);
   1419 				return sec_status_unchecked;
   1420 			}
   1421 			SECITEM_FreeItem(p, PR_TRUE);
   1422 		}
   1423 	}
   1424 #endif /* USE_DSA */
   1425 
   1426 	/* do the signature cryptography work */
   1427 	/* hash the data */
   1428 	sechash.len = HASH_ResultLen(htype);
   1429 	if(sechash.len > sizeof(hash)) {
   1430 		verbose(VERB_QUERY, "verify: hash too large for buffer");
   1431 		SECKEY_DestroyPublicKey(pubkey);
   1432 		return sec_status_unchecked;
   1433 	}
   1434 	if(HASH_HashBuf(htype, hash, (unsigned char*)sldns_buffer_begin(buf),
   1435 		(unsigned int)sldns_buffer_limit(buf)) != SECSuccess) {
   1436 		verbose(VERB_QUERY, "verify: HASH_HashBuf failed");
   1437 		SECKEY_DestroyPublicKey(pubkey);
   1438 		return sec_status_unchecked;
   1439 	}
   1440 	if(prefix) {
   1441 		int hashlen = sechash.len;
   1442 		if(prefixlen+hashlen > sizeof(hash2)) {
   1443 			verbose(VERB_QUERY, "verify: hashprefix too large");
   1444 			SECKEY_DestroyPublicKey(pubkey);
   1445 			return sec_status_unchecked;
   1446 		}
   1447 		sechash.data = hash2;
   1448 		sechash.len = prefixlen+hashlen;
   1449 		memcpy(sechash.data, prefix, prefixlen);
   1450 		memmove(sechash.data+prefixlen, hash, hashlen);
   1451 	}
   1452 
   1453 	/* verify the signature */
   1454 	res = PK11_Verify(pubkey, &secsig, &sechash, NULL /*wincx*/);
   1455 	SECKEY_DestroyPublicKey(pubkey);
   1456 
   1457 	if(res == SECSuccess) {
   1458 		return sec_status_secure;
   1459 	}
   1460 	err = PORT_GetError();
   1461 	if(err != SEC_ERROR_BAD_SIGNATURE) {
   1462 		/* failed to verify */
   1463 		verbose(VERB_QUERY, "verify: PK11_Verify failed: %s",
   1464 			PORT_ErrorToString(err));
   1465 		/* if it is not supported, like ECC is removed, we get,
   1466 		 * SEC_ERROR_NO_MODULE */
   1467 		if(err == SEC_ERROR_NO_MODULE)
   1468 			return sec_status_unchecked;
   1469 		/* but other errors are commonly returned
   1470 		 * for a bad signature from NSS.  Thus we return bogus,
   1471 		 * not unchecked */
   1472 		*reason = "signature crypto failed";
   1473 		return sec_status_bogus;
   1474 	}
   1475 	verbose(VERB_QUERY, "verify: signature mismatch: %s",
   1476 		PORT_ErrorToString(err));
   1477 	*reason = "signature crypto failed";
   1478 	return sec_status_bogus;
   1479 }
   1480 
   1481 #elif defined(HAVE_NETTLE)
   1482 
   1483 #include "sha.h"
   1484 #include "bignum.h"
   1485 #include "macros.h"
   1486 #include "rsa.h"
   1487 #include "dsa.h"
   1488 #ifdef HAVE_NETTLE_DSA_COMPAT_H
   1489 #include "dsa-compat.h"
   1490 #endif
   1491 #include "asn1.h"
   1492 #ifdef USE_ECDSA
   1493 #include "ecdsa.h"
   1494 #include "ecc-curve.h"
   1495 #endif
   1496 #ifdef HAVE_NETTLE_EDDSA_H
   1497 #include "eddsa.h"
   1498 #endif
   1499 
   1500 static int
   1501 _digest_nettle(int algo, uint8_t* buf, size_t len,
   1502 	unsigned char* res)
   1503 {
   1504 	switch(algo) {
   1505 		case SHA1_DIGEST_SIZE:
   1506 		{
   1507 			struct sha1_ctx ctx;
   1508 			sha1_init(&ctx);
   1509 			sha1_update(&ctx, len, buf);
   1510 			sha1_digest(&ctx, SHA1_DIGEST_SIZE, res);
   1511 			return 1;
   1512 		}
   1513 		case SHA256_DIGEST_SIZE:
   1514 		{
   1515 			struct sha256_ctx ctx;
   1516 			sha256_init(&ctx);
   1517 			sha256_update(&ctx, len, buf);
   1518 			sha256_digest(&ctx, SHA256_DIGEST_SIZE, res);
   1519 			return 1;
   1520 		}
   1521 		case SHA384_DIGEST_SIZE:
   1522 		{
   1523 			struct sha384_ctx ctx;
   1524 			sha384_init(&ctx);
   1525 			sha384_update(&ctx, len, buf);
   1526 			sha384_digest(&ctx, SHA384_DIGEST_SIZE, res);
   1527 			return 1;
   1528 		}
   1529 		case SHA512_DIGEST_SIZE:
   1530 		{
   1531 			struct sha512_ctx ctx;
   1532 			sha512_init(&ctx);
   1533 			sha512_update(&ctx, len, buf);
   1534 			sha512_digest(&ctx, SHA512_DIGEST_SIZE, res);
   1535 			return 1;
   1536 		}
   1537 		default:
   1538 			break;
   1539 	}
   1540 	return 0;
   1541 }
   1542 
   1543 /* return size of digest if supported, or 0 otherwise */
   1544 size_t
   1545 nsec3_hash_algo_size_supported(int id)
   1546 {
   1547 	switch(id) {
   1548 	case NSEC3_HASH_SHA1:
   1549 		return SHA1_DIGEST_SIZE;
   1550 	default:
   1551 		return 0;
   1552 	}
   1553 }
   1554 
   1555 /* perform nsec3 hash. return false on failure */
   1556 int
   1557 secalgo_nsec3_hash(int algo, unsigned char* buf, size_t len,
   1558         unsigned char* res)
   1559 {
   1560 	switch(algo) {
   1561 	case NSEC3_HASH_SHA1:
   1562 		return _digest_nettle(SHA1_DIGEST_SIZE, (uint8_t*)buf, len,
   1563 			res);
   1564 	default:
   1565 		return 0;
   1566 	}
   1567 }
   1568 
   1569 void
   1570 secalgo_hash_sha256(unsigned char* buf, size_t len, unsigned char* res)
   1571 {
   1572 	_digest_nettle(SHA256_DIGEST_SIZE, (uint8_t*)buf, len, res);
   1573 }
   1574 
   1575 /** secalgo hash structure */
   1576 struct secalgo_hash {
   1577 	/** if it is 384 or 512 */
   1578 	int active;
   1579 	/** context for sha384 */
   1580 	struct sha384_ctx ctx384;
   1581 	/** context for sha512 */
   1582 	struct sha512_ctx ctx512;
   1583 };
   1584 
   1585 struct secalgo_hash* secalgo_hash_create_sha384(void)
   1586 {
   1587 	struct secalgo_hash* h = calloc(1, sizeof(*h));
   1588 	if(!h)
   1589 		return NULL;
   1590 	h->active = 384;
   1591 	sha384_init(&h->ctx384);
   1592 	return h;
   1593 }
   1594 
   1595 struct secalgo_hash* secalgo_hash_create_sha512(void)
   1596 {
   1597 	struct secalgo_hash* h = calloc(1, sizeof(*h));
   1598 	if(!h)
   1599 		return NULL;
   1600 	h->active = 512;
   1601 	sha512_init(&h->ctx512);
   1602 	return h;
   1603 }
   1604 
   1605 int secalgo_hash_update(struct secalgo_hash* hash, uint8_t* data, size_t len)
   1606 {
   1607 	if(hash->active == 384) {
   1608 		sha384_update(&hash->ctx384, len, data);
   1609 	} else if(hash->active == 512) {
   1610 		sha512_update(&hash->ctx512, len, data);
   1611 	} else {
   1612 		return 0;
   1613 	}
   1614 	return 1;
   1615 }
   1616 
   1617 int secalgo_hash_final(struct secalgo_hash* hash, uint8_t* result,
   1618         size_t maxlen, size_t* resultlen)
   1619 {
   1620 	if(hash->active == 384) {
   1621 		if(SHA384_DIGEST_SIZE > maxlen) {
   1622 			*resultlen = 0;
   1623 			log_err("secalgo_hash_final: hash buffer too small");
   1624 			return 0;
   1625 		}
   1626 		*resultlen = SHA384_DIGEST_SIZE;
   1627 		sha384_digest(&hash->ctx384, SHA384_DIGEST_SIZE,
   1628 			(unsigned char*)result);
   1629 	} else if(hash->active == 512) {
   1630 		if(SHA512_DIGEST_SIZE > maxlen) {
   1631 			*resultlen = 0;
   1632 			log_err("secalgo_hash_final: hash buffer too small");
   1633 			return 0;
   1634 		}
   1635 		*resultlen = SHA512_DIGEST_SIZE;
   1636 		sha512_digest(&hash->ctx512, SHA512_DIGEST_SIZE,
   1637 			(unsigned char*)result);
   1638 	} else {
   1639 		*resultlen = 0;
   1640 		return 0;
   1641 	}
   1642 	return 1;
   1643 }
   1644 
   1645 void secalgo_hash_delete(struct secalgo_hash* hash)
   1646 {
   1647 	if(!hash) return;
   1648 	free(hash);
   1649 }
   1650 
   1651 /**
   1652  * Return size of DS digest according to its hash algorithm.
   1653  * @param algo: DS digest algo.
   1654  * @return size in bytes of digest, or 0 if not supported.
   1655  */
   1656 size_t
   1657 ds_digest_size_supported(int algo)
   1658 {
   1659 	switch(algo) {
   1660 		case LDNS_SHA1:
   1661 #ifdef USE_SHA1
   1662 			return SHA1_DIGEST_SIZE;
   1663 #else
   1664 			if(fake_sha1) return 20;
   1665 			return 0;
   1666 #endif
   1667 #ifdef USE_SHA2
   1668 		case LDNS_SHA256:
   1669 			return SHA256_DIGEST_SIZE;
   1670 #endif
   1671 #ifdef USE_ECDSA
   1672 		case LDNS_SHA384:
   1673 			return SHA384_DIGEST_SIZE;
   1674 #endif
   1675 		/* GOST not supported */
   1676 		case LDNS_HASH_GOST:
   1677 		default:
   1678 			break;
   1679 	}
   1680 	return 0;
   1681 }
   1682 
   1683 int
   1684 secalgo_ds_digest(int algo, unsigned char* buf, size_t len,
   1685 	unsigned char* res)
   1686 {
   1687 	switch(algo) {
   1688 #ifdef USE_SHA1
   1689 		case LDNS_SHA1:
   1690 			return _digest_nettle(SHA1_DIGEST_SIZE, buf, len, res);
   1691 #endif
   1692 #if defined(USE_SHA2)
   1693 		case LDNS_SHA256:
   1694 			return _digest_nettle(SHA256_DIGEST_SIZE, buf, len, res);
   1695 #endif
   1696 #ifdef USE_ECDSA
   1697 		case LDNS_SHA384:
   1698 			return _digest_nettle(SHA384_DIGEST_SIZE, buf, len, res);
   1699 
   1700 #endif
   1701 		case LDNS_HASH_GOST:
   1702 		default:
   1703 			verbose(VERB_QUERY, "unknown DS digest algorithm %d",
   1704 				algo);
   1705 			break;
   1706 	}
   1707 	return 0;
   1708 }
   1709 
   1710 int
   1711 dnskey_algo_id_is_supported(int id)
   1712 {
   1713 	/* uses libnettle */
   1714 	switch(id) {
   1715 	case LDNS_DSA:
   1716 	case LDNS_DSA_NSEC3:
   1717 #if defined(USE_DSA) && defined(USE_SHA1)
   1718 		return 1;
   1719 #else
   1720 		if(fake_dsa || fake_sha1) return 1;
   1721 		return 0;
   1722 #endif
   1723 	case LDNS_RSASHA1:
   1724 	case LDNS_RSASHA1_NSEC3:
   1725 #ifdef USE_SHA1
   1726 		return 1;
   1727 #else
   1728 		if(fake_sha1) return 1;
   1729 		return 0;
   1730 #endif
   1731 #ifdef USE_SHA2
   1732 	case LDNS_RSASHA256:
   1733 	case LDNS_RSASHA512:
   1734 #endif
   1735 #ifdef USE_ECDSA
   1736 	case LDNS_ECDSAP256SHA256:
   1737 	case LDNS_ECDSAP384SHA384:
   1738 #endif
   1739 		return 1;
   1740 #ifdef USE_ED25519
   1741 	case LDNS_ED25519:
   1742 		return 1;
   1743 #endif
   1744 	case LDNS_RSAMD5: /* RFC 6725 deprecates RSAMD5 */
   1745 	case LDNS_ECC_GOST:
   1746 	default:
   1747 		return 0;
   1748 	}
   1749 }
   1750 
   1751 #if defined(USE_DSA) && defined(USE_SHA1)
   1752 static char *
   1753 _verify_nettle_dsa(sldns_buffer* buf, unsigned char* sigblock,
   1754 	unsigned int sigblock_len, unsigned char* key, unsigned int keylen)
   1755 {
   1756 	uint8_t digest[SHA1_DIGEST_SIZE];
   1757 	uint8_t key_t_value;
   1758 	int res = 0;
   1759 	size_t offset;
   1760 	struct dsa_public_key pubkey;
   1761 	struct dsa_signature signature;
   1762 	unsigned int expected_len;
   1763 
   1764 	/* Extract DSA signature from the record */
   1765 	nettle_dsa_signature_init(&signature);
   1766 	/* Signature length: 41 bytes - RFC 2536 sec. 3 */
   1767 	if(sigblock_len == 41) {
   1768 		if(key[0] != sigblock[0])
   1769 			return "invalid T value in DSA signature or pubkey";
   1770 		nettle_mpz_set_str_256_u(signature.r, 20, sigblock+1);
   1771 		nettle_mpz_set_str_256_u(signature.s, 20, sigblock+1+20);
   1772 	} else {
   1773 		/* DER encoded, decode the ASN1 notated R and S bignums */
   1774 		/* SEQUENCE { r INTEGER, s INTEGER } */
   1775 		struct asn1_der_iterator i, seq;
   1776 		if(asn1_der_iterator_first(&i, sigblock_len,
   1777 			(uint8_t*)sigblock) != ASN1_ITERATOR_CONSTRUCTED
   1778 			|| i.type != ASN1_SEQUENCE)
   1779 			return "malformed DER encoded DSA signature";
   1780 		/* decode this element of i using the seq iterator */
   1781 		if(asn1_der_decode_constructed(&i, &seq) !=
   1782 			ASN1_ITERATOR_PRIMITIVE || seq.type != ASN1_INTEGER)
   1783 			return "malformed DER encoded DSA signature";
   1784 		if(!asn1_der_get_bignum(&seq, signature.r, 20*8))
   1785 			return "malformed DER encoded DSA signature";
   1786 		if(asn1_der_iterator_next(&seq) != ASN1_ITERATOR_PRIMITIVE
   1787 			|| seq.type != ASN1_INTEGER)
   1788 			return "malformed DER encoded DSA signature";
   1789 		if(!asn1_der_get_bignum(&seq, signature.s, 20*8))
   1790 			return "malformed DER encoded DSA signature";
   1791 		if(asn1_der_iterator_next(&i) != ASN1_ITERATOR_END)
   1792 			return "malformed DER encoded DSA signature";
   1793 	}
   1794 
   1795 	/* Validate T values constraints - RFC 2536 sec. 2 & sec. 3 */
   1796 	key_t_value = key[0];
   1797 	if (key_t_value > 8) {
   1798 		return "invalid T value in DSA pubkey";
   1799 	}
   1800 
   1801 	/* Pubkey minimum length: 21 bytes - RFC 2536 sec. 2 */
   1802 	if (keylen < 21) {
   1803 		return "DSA pubkey too short";
   1804 	}
   1805 
   1806 	expected_len =   1 +		/* T */
   1807 		        20 +		/* Q */
   1808 		       (64 + key_t_value*8) +	/* P */
   1809 		       (64 + key_t_value*8) +	/* G */
   1810 		       (64 + key_t_value*8);	/* Y */
   1811 	if (keylen != expected_len ) {
   1812 		return "invalid DSA pubkey length";
   1813 	}
   1814 
   1815 	/* Extract DSA pubkey from the record */
   1816 	nettle_dsa_public_key_init(&pubkey);
   1817 	offset = 1;
   1818 	nettle_mpz_set_str_256_u(pubkey.q, 20, key+offset);
   1819 	offset += 20;
   1820 	nettle_mpz_set_str_256_u(pubkey.p, (64 + key_t_value*8), key+offset);
   1821 	offset += (64 + key_t_value*8);
   1822 	nettle_mpz_set_str_256_u(pubkey.g, (64 + key_t_value*8), key+offset);
   1823 	offset += (64 + key_t_value*8);
   1824 	nettle_mpz_set_str_256_u(pubkey.y, (64 + key_t_value*8), key+offset);
   1825 
   1826 	/* Digest content of "buf" and verify its DSA signature in "sigblock"*/
   1827 	res = _digest_nettle(SHA1_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf),
   1828 						(unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest);
   1829 	res &= dsa_sha1_verify_digest(&pubkey, digest, &signature);
   1830 
   1831 	/* Clear and return */
   1832 	nettle_dsa_signature_clear(&signature);
   1833 	nettle_dsa_public_key_clear(&pubkey);
   1834 	if (!res)
   1835 		return "DSA signature verification failed";
   1836 	else
   1837 		return NULL;
   1838 }
   1839 #endif /* USE_DSA */
   1840 
   1841 static char *
   1842 _verify_nettle_rsa(sldns_buffer* buf, unsigned int digest_size, char* sigblock,
   1843 	unsigned int sigblock_len, uint8_t* key, unsigned int keylen)
   1844 {
   1845 	uint16_t exp_len = 0;
   1846 	size_t exp_offset = 0, mod_offset = 0;
   1847 	struct rsa_public_key pubkey;
   1848 	mpz_t signature;
   1849 	int res = 0;
   1850 
   1851 	/* RSA pubkey parsing as per RFC 3110 sec. 2 */
   1852 	if( keylen <= 1) {
   1853 		return "null RSA key";
   1854 	}
   1855 	if (key[0] != 0) {
   1856 		/* 1-byte length */
   1857 		exp_len = key[0];
   1858 		exp_offset = 1;
   1859 	} else {
   1860 		/* 1-byte NUL + 2-bytes exponent length */
   1861 		if (keylen < 3) {
   1862 			return "incorrect RSA key length";
   1863 		}
   1864 		exp_len = READ_UINT16(key+1);
   1865 		if (exp_len == 0)
   1866 			return "null RSA exponent length";
   1867 		exp_offset = 3;
   1868 	}
   1869 	/* Check that we are not over-running input length */
   1870 	if (keylen < exp_offset + exp_len + 1) {
   1871 		return "RSA key content shorter than expected";
   1872 	}
   1873 	mod_offset = exp_offset + exp_len;
   1874 	nettle_rsa_public_key_init(&pubkey);
   1875 	nettle_mpz_set_str_256_u(pubkey.e, exp_len, &key[exp_offset]);
   1876 	nettle_mpz_set_str_256_u(pubkey.n, keylen - mod_offset, &key[mod_offset]);
   1877 	pubkey.size = nettle_mpz_sizeinbase_256_u(pubkey.n);
   1878 
   1879 	/* Digest content of "buf" and verify its RSA signature in "sigblock"*/
   1880 	nettle_mpz_init_set_str_256_u(signature, sigblock_len, (uint8_t*)sigblock);
   1881 	switch (digest_size) {
   1882 		case SHA1_DIGEST_SIZE:
   1883 		{
   1884 			uint8_t digest[SHA1_DIGEST_SIZE];
   1885 			res = _digest_nettle(SHA1_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf),
   1886 						(unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest);
   1887 			res &= rsa_sha1_verify_digest(&pubkey, digest, signature);
   1888 			break;
   1889 		}
   1890 		case SHA256_DIGEST_SIZE:
   1891 		{
   1892 			uint8_t digest[SHA256_DIGEST_SIZE];
   1893 			res = _digest_nettle(SHA256_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf),
   1894 						(unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest);
   1895 			res &= rsa_sha256_verify_digest(&pubkey, digest, signature);
   1896 			break;
   1897 		}
   1898 		case SHA512_DIGEST_SIZE:
   1899 		{
   1900 			uint8_t digest[SHA512_DIGEST_SIZE];
   1901 			res = _digest_nettle(SHA512_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf),
   1902 						(unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest);
   1903 			res &= rsa_sha512_verify_digest(&pubkey, digest, signature);
   1904 			break;
   1905 		}
   1906 		default:
   1907 			break;
   1908 	}
   1909 
   1910 	/* Clear and return */
   1911 	nettle_rsa_public_key_clear(&pubkey);
   1912 	mpz_clear(signature);
   1913 	if (!res) {
   1914 		return "RSA signature verification failed";
   1915 	} else {
   1916 		return NULL;
   1917 	}
   1918 }
   1919 
   1920 #ifdef USE_ECDSA
   1921 static char *
   1922 _verify_nettle_ecdsa(sldns_buffer* buf, unsigned int digest_size, unsigned char* sigblock,
   1923 	unsigned int sigblock_len, unsigned char* key, unsigned int keylen)
   1924 {
   1925 	int res = 0;
   1926 	struct ecc_point pubkey;
   1927 	struct dsa_signature signature;
   1928 
   1929 	/* Always matched strength, as per RFC 6605 sec. 1 */
   1930 	if (sigblock_len != 2*digest_size || keylen != 2*digest_size) {
   1931 		return "wrong ECDSA signature length";
   1932 	}
   1933 
   1934 	/* Parse ECDSA signature as per RFC 6605 sec. 4 */
   1935 	nettle_dsa_signature_init(&signature);
   1936 	switch (digest_size) {
   1937 		case SHA256_DIGEST_SIZE:
   1938 		{
   1939 			uint8_t digest[SHA256_DIGEST_SIZE];
   1940 			mpz_t x, y;
   1941 			nettle_ecc_point_init(&pubkey, nettle_get_secp_256r1());
   1942 			nettle_mpz_init_set_str_256_u(x, SHA256_DIGEST_SIZE, key);
   1943 			nettle_mpz_init_set_str_256_u(y, SHA256_DIGEST_SIZE, key+SHA256_DIGEST_SIZE);
   1944 			nettle_mpz_set_str_256_u(signature.r, SHA256_DIGEST_SIZE, sigblock);
   1945 			nettle_mpz_set_str_256_u(signature.s, SHA256_DIGEST_SIZE, sigblock+SHA256_DIGEST_SIZE);
   1946 			res = _digest_nettle(SHA256_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf),
   1947 						(unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest);
   1948 			res &= nettle_ecc_point_set(&pubkey, x, y);
   1949 			res &= nettle_ecdsa_verify (&pubkey, SHA256_DIGEST_SIZE, digest, &signature);
   1950 			mpz_clear(x);
   1951 			mpz_clear(y);
   1952 			nettle_ecc_point_clear(&pubkey);
   1953 			break;
   1954 		}
   1955 		case SHA384_DIGEST_SIZE:
   1956 		{
   1957 			uint8_t digest[SHA384_DIGEST_SIZE];
   1958 			mpz_t x, y;
   1959 			nettle_ecc_point_init(&pubkey, nettle_get_secp_384r1());
   1960 			nettle_mpz_init_set_str_256_u(x, SHA384_DIGEST_SIZE, key);
   1961 			nettle_mpz_init_set_str_256_u(y, SHA384_DIGEST_SIZE, key+SHA384_DIGEST_SIZE);
   1962 			nettle_mpz_set_str_256_u(signature.r, SHA384_DIGEST_SIZE, sigblock);
   1963 			nettle_mpz_set_str_256_u(signature.s, SHA384_DIGEST_SIZE, sigblock+SHA384_DIGEST_SIZE);
   1964 			res = _digest_nettle(SHA384_DIGEST_SIZE, (unsigned char*)sldns_buffer_begin(buf),
   1965 						(unsigned int)sldns_buffer_limit(buf), (unsigned char*)digest);
   1966 			res &= nettle_ecc_point_set(&pubkey, x, y);
   1967 			res &= nettle_ecdsa_verify (&pubkey, SHA384_DIGEST_SIZE, digest, &signature);
   1968 			mpz_clear(x);
   1969 			mpz_clear(y);
   1970 			nettle_ecc_point_clear(&pubkey);
   1971 			break;
   1972 		}
   1973 		default:
   1974 			return "unknown ECDSA algorithm";
   1975 	}
   1976 
   1977 	/* Clear and return */
   1978 	nettle_dsa_signature_clear(&signature);
   1979 	if (!res)
   1980 		return "ECDSA signature verification failed";
   1981 	else
   1982 		return NULL;
   1983 }
   1984 #endif
   1985 
   1986 #ifdef USE_ED25519
   1987 static char *
   1988 _verify_nettle_ed25519(sldns_buffer* buf, unsigned char* sigblock,
   1989 	unsigned int sigblock_len, unsigned char* key, unsigned int keylen)
   1990 {
   1991 	int res = 0;
   1992 
   1993 	if(sigblock_len != ED25519_SIGNATURE_SIZE) {
   1994 		return "wrong ED25519 signature length";
   1995 	}
   1996 	if(keylen != ED25519_KEY_SIZE) {
   1997 		return "wrong ED25519 key length";
   1998 	}
   1999 
   2000 	res = ed25519_sha512_verify((uint8_t*)key, sldns_buffer_limit(buf),
   2001 		sldns_buffer_begin(buf), (uint8_t*)sigblock);
   2002 
   2003 	if (!res)
   2004 		return "ED25519 signature verification failed";
   2005 	else
   2006 		return NULL;
   2007 }
   2008 #endif
   2009 
   2010 /**
   2011  * Check a canonical sig+rrset and signature against a dnskey
   2012  * @param buf: buffer with data to verify, the first rrsig part and the
   2013  *	canonicalized rrset.
   2014  * @param algo: DNSKEY algorithm.
   2015  * @param sigblock: signature rdata field from RRSIG
   2016  * @param sigblock_len: length of sigblock data.
   2017  * @param key: public key data from DNSKEY RR.
   2018  * @param keylen: length of keydata.
   2019  * @param reason: bogus reason in more detail.
   2020  * @return secure if verification succeeded, bogus on crypto failure,
   2021  *	unchecked on format errors and alloc failures.
   2022  */
   2023 enum sec_status
   2024 verify_canonrrset(sldns_buffer* buf, int algo, unsigned char* sigblock,
   2025 	unsigned int sigblock_len, unsigned char* key, unsigned int keylen,
   2026 	char** reason)
   2027 {
   2028 	unsigned int digest_size = 0;
   2029 
   2030 	if (sigblock_len == 0 || keylen == 0) {
   2031 		*reason = "null signature";
   2032 		return sec_status_bogus;
   2033 	}
   2034 
   2035 #ifndef USE_DSA
   2036 	if((algo == LDNS_DSA || algo == LDNS_DSA_NSEC3) &&(fake_dsa||fake_sha1))
   2037 		return sec_status_secure;
   2038 #endif
   2039 #ifndef USE_SHA1
   2040 	if(fake_sha1 && (algo == LDNS_DSA || algo == LDNS_DSA_NSEC3 || algo == LDNS_RSASHA1 || algo == LDNS_RSASHA1_NSEC3))
   2041 		return sec_status_secure;
   2042 #endif
   2043 
   2044 	switch(algo) {
   2045 #if defined(USE_DSA) && defined(USE_SHA1)
   2046 	case LDNS_DSA:
   2047 	case LDNS_DSA_NSEC3:
   2048 		*reason = _verify_nettle_dsa(buf, sigblock, sigblock_len, key, keylen);
   2049 		if (*reason != NULL)
   2050 			return sec_status_bogus;
   2051 		else
   2052 			return sec_status_secure;
   2053 #endif /* USE_DSA */
   2054 
   2055 #ifdef USE_SHA1
   2056 	case LDNS_RSASHA1:
   2057 	case LDNS_RSASHA1_NSEC3:
   2058 		digest_size = (digest_size ? digest_size : SHA1_DIGEST_SIZE);
   2059 #endif
   2060 		/* double fallthrough annotation to please gcc parser */
   2061 		ATTR_FALLTHROUGH
   2062 		/* fallthrough */
   2063 #ifdef USE_SHA2
   2064 		/* fallthrough */
   2065 	case LDNS_RSASHA256:
   2066 		digest_size = (digest_size ? digest_size : SHA256_DIGEST_SIZE);
   2067 		ATTR_FALLTHROUGH
   2068 		/* fallthrough */
   2069 	case LDNS_RSASHA512:
   2070 		digest_size = (digest_size ? digest_size : SHA512_DIGEST_SIZE);
   2071 
   2072 #endif
   2073 		*reason = _verify_nettle_rsa(buf, digest_size, (char*)sigblock,
   2074 						sigblock_len, key, keylen);
   2075 		if (*reason != NULL)
   2076 			return sec_status_bogus;
   2077 		else
   2078 			return sec_status_secure;
   2079 
   2080 #ifdef USE_ECDSA
   2081 	case LDNS_ECDSAP256SHA256:
   2082 		digest_size = (digest_size ? digest_size : SHA256_DIGEST_SIZE);
   2083 		ATTR_FALLTHROUGH
   2084 		/* fallthrough */
   2085 	case LDNS_ECDSAP384SHA384:
   2086 		digest_size = (digest_size ? digest_size : SHA384_DIGEST_SIZE);
   2087 		*reason = _verify_nettle_ecdsa(buf, digest_size, sigblock,
   2088 						sigblock_len, key, keylen);
   2089 		if (*reason != NULL)
   2090 			return sec_status_bogus;
   2091 		else
   2092 			return sec_status_secure;
   2093 #endif
   2094 #ifdef USE_ED25519
   2095 	case LDNS_ED25519:
   2096 		*reason = _verify_nettle_ed25519(buf, sigblock, sigblock_len,
   2097 			key, keylen);
   2098 		if (*reason != NULL)
   2099 			return sec_status_bogus;
   2100 		else
   2101 			return sec_status_secure;
   2102 #endif
   2103 	case LDNS_RSAMD5:
   2104 	case LDNS_ECC_GOST:
   2105 	default:
   2106 		*reason = "unable to verify signature, unknown algorithm";
   2107 		return sec_status_bogus;
   2108 	}
   2109 }
   2110 
   2111 #endif /* HAVE_SSL or HAVE_NSS or HAVE_NETTLE */
   2112