Home | History | Annotate | Line # | Download | only in libtelnet
encrypt.c revision 1.13
      1  1.13     perry /*	$NetBSD: encrypt.c,v 1.13 2005/02/06 05:53:07 perry Exp $	*/
      2   1.6  christos 
      3   1.1       cgd /*-
      4   1.3       cgd  * Copyright (c) 1991, 1993
      5   1.3       cgd  *	The Regents of the University of California.  All rights reserved.
      6   1.1       cgd  *
      7   1.1       cgd  * Redistribution and use in source and binary forms, with or without
      8   1.1       cgd  * modification, are permitted provided that the following conditions
      9   1.1       cgd  * are met:
     10   1.1       cgd  * 1. Redistributions of source code must retain the above copyright
     11   1.1       cgd  *    notice, this list of conditions and the following disclaimer.
     12   1.1       cgd  * 2. Redistributions in binary form must reproduce the above copyright
     13   1.1       cgd  *    notice, this list of conditions and the following disclaimer in the
     14   1.1       cgd  *    documentation and/or other materials provided with the distribution.
     15  1.12       agc  * 3. Neither the name of the University nor the names of its contributors
     16   1.1       cgd  *    may be used to endorse or promote products derived from this software
     17   1.1       cgd  *    without specific prior written permission.
     18   1.1       cgd  *
     19   1.1       cgd  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
     20   1.1       cgd  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     21   1.1       cgd  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     22   1.1       cgd  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
     23   1.1       cgd  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     24   1.1       cgd  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     25   1.1       cgd  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     26   1.1       cgd  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     27   1.1       cgd  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     28   1.1       cgd  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     29   1.1       cgd  * SUCH DAMAGE.
     30   1.1       cgd  */
     31   1.1       cgd 
     32   1.5     lukem #include <sys/cdefs.h>
     33   1.5     lukem #if 0
     34   1.5     lukem static char sccsid[] = "@(#)encrypt.c	8.2 (Berkeley) 5/30/95";
     35   1.5     lukem #else
     36  1.13     perry __RCSID("$NetBSD: encrypt.c,v 1.13 2005/02/06 05:53:07 perry Exp $");
     37   1.1       cgd #endif /* not lint */
     38   1.1       cgd 
     39   1.1       cgd /*
     40   1.1       cgd  * Copyright (C) 1990 by the Massachusetts Institute of Technology
     41   1.1       cgd  *
     42   1.1       cgd  * Export of this software from the United States of America is assumed
     43   1.1       cgd  * to require a specific license from the United States Government.
     44   1.1       cgd  * It is the responsibility of any person or organization contemplating
     45   1.1       cgd  * export to obtain such a license before exporting.
     46   1.1       cgd  *
     47   1.1       cgd  * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
     48   1.1       cgd  * distribute this software and its documentation for any purpose and
     49   1.1       cgd  * without fee is hereby granted, provided that the above copyright
     50   1.1       cgd  * notice appear in all copies and that both that copyright notice and
     51   1.1       cgd  * this permission notice appear in supporting documentation, and that
     52   1.1       cgd  * the name of M.I.T. not be used in advertising or publicity pertaining
     53   1.1       cgd  * to distribution of the software without specific, written prior
     54   1.1       cgd  * permission.  M.I.T. makes no representations about the suitability of
     55   1.1       cgd  * this software for any purpose.  It is provided "as is" without express
     56   1.1       cgd  * or implied warranty.
     57   1.1       cgd  */
     58   1.1       cgd 
     59   1.7   thorpej #ifdef	ENCRYPTION
     60   1.7   thorpej 
     61   1.7   thorpej #include <stdio.h>
     62   1.7   thorpej #define	ENCRYPT_NAMES
     63   1.7   thorpej #include <arpa/telnet.h>
     64   1.7   thorpej 
     65   1.7   thorpej #include "encrypt.h"
     66   1.7   thorpej #include "misc.h"
     67   1.7   thorpej 
     68   1.7   thorpej #include <stdlib.h>
     69   1.7   thorpej #ifdef	NO_STRING_H
     70   1.7   thorpej #include <strings.h>
     71   1.7   thorpej #else
     72   1.7   thorpej #include <string.h>
     73   1.7   thorpej #endif
     74   1.7   thorpej 
     75   1.7   thorpej #include <sys/cdefs.h>
     76   1.7   thorpej 
     77   1.7   thorpej /*
     78   1.7   thorpej  * These functions pointers point to the current routines
     79   1.7   thorpej  * for encrypting and decrypting data.
     80   1.7   thorpej  */
     81  1.13     perry void	(*encrypt_output)(unsigned char *, int);
     82  1.13     perry int	(*decrypt_input)(int);
     83   1.7   thorpej 
     84   1.7   thorpej int encrypt_debug_mode = 0;
     85   1.7   thorpej static int decrypt_mode = 0;
     86   1.7   thorpej static int encrypt_mode = 0;
     87   1.7   thorpej static int encrypt_verbose = 0;
     88   1.7   thorpej static int autoencrypt = 0;
     89   1.7   thorpej static int autodecrypt = 0;
     90   1.7   thorpej static int havesessionkey = 0;
     91   1.7   thorpej static int Server = 0;
     92   1.7   thorpej static const char *Name = "Noname";
     93   1.7   thorpej 
     94   1.7   thorpej #define	typemask(x)	((x) > 0 ? 1 << ((x)-1) : 0)
     95   1.7   thorpej 
     96   1.7   thorpej static long i_support_encrypt = typemask(ENCTYPE_DES_CFB64)
     97   1.7   thorpej 				| typemask(ENCTYPE_DES_OFB64);
     98   1.7   thorpej static long i_support_decrypt = typemask(ENCTYPE_DES_CFB64)
     99   1.7   thorpej 				| typemask(ENCTYPE_DES_OFB64);
    100   1.7   thorpej static long i_wont_support_encrypt = 0;
    101   1.7   thorpej static long i_wont_support_decrypt = 0;
    102   1.7   thorpej #define	I_SUPPORT_ENCRYPT	(i_support_encrypt & ~i_wont_support_encrypt)
    103   1.7   thorpej #define	I_SUPPORT_DECRYPT	(i_support_decrypt & ~i_wont_support_decrypt)
    104   1.7   thorpej 
    105   1.7   thorpej static long remote_supports_encrypt = 0;
    106   1.7   thorpej static long remote_supports_decrypt = 0;
    107   1.7   thorpej 
    108   1.7   thorpej static Encryptions encryptions[] = {
    109   1.7   thorpej #ifdef	DES_ENCRYPTION
    110   1.7   thorpej     { "DES_CFB64",	ENCTYPE_DES_CFB64,
    111   1.7   thorpej 			cfb64_encrypt,
    112   1.7   thorpej 			cfb64_decrypt,
    113   1.7   thorpej 			cfb64_init,
    114   1.7   thorpej 			cfb64_start,
    115   1.7   thorpej 			cfb64_is,
    116   1.7   thorpej 			cfb64_reply,
    117   1.7   thorpej 			cfb64_session,
    118   1.7   thorpej 			cfb64_keyid,
    119   1.7   thorpej 			cfb64_printsub },
    120   1.7   thorpej     { "DES_OFB64",	ENCTYPE_DES_OFB64,
    121   1.7   thorpej 			ofb64_encrypt,
    122   1.7   thorpej 			ofb64_decrypt,
    123   1.7   thorpej 			ofb64_init,
    124   1.7   thorpej 			ofb64_start,
    125   1.7   thorpej 			ofb64_is,
    126   1.7   thorpej 			ofb64_reply,
    127   1.7   thorpej 			ofb64_session,
    128   1.7   thorpej 			ofb64_keyid,
    129   1.7   thorpej 			ofb64_printsub },
    130   1.7   thorpej #endif	/* DES_ENCRYPTION */
    131   1.7   thorpej     { 0, },
    132   1.7   thorpej };
    133   1.7   thorpej 
    134   1.7   thorpej static unsigned char str_send[64] = { IAC, SB, TELOPT_ENCRYPT,
    135   1.7   thorpej 					 ENCRYPT_SUPPORT };
    136   1.7   thorpej static unsigned char str_suplen = 0;
    137   1.7   thorpej static unsigned char str_start[72] = { IAC, SB, TELOPT_ENCRYPT };
    138   1.7   thorpej static unsigned char str_end[] = { IAC, SB, TELOPT_ENCRYPT, 0, IAC, SE };
    139   1.7   thorpej 
    140   1.7   thorpej 	Encryptions *
    141   1.7   thorpej findencryption(type)
    142   1.7   thorpej 	int type;
    143   1.7   thorpej {
    144   1.7   thorpej 	Encryptions *ep = encryptions;
    145   1.7   thorpej 
    146   1.7   thorpej 	if (!(I_SUPPORT_ENCRYPT & remote_supports_decrypt & typemask(type)))
    147   1.7   thorpej 		return(0);
    148   1.7   thorpej 	while (ep->type && ep->type != type)
    149   1.7   thorpej 		++ep;
    150   1.7   thorpej 	return(ep->type ? ep : 0);
    151   1.7   thorpej }
    152   1.7   thorpej 
    153   1.7   thorpej 	Encryptions *
    154   1.7   thorpej finddecryption(type)
    155   1.7   thorpej 	int type;
    156   1.7   thorpej {
    157   1.7   thorpej 	Encryptions *ep = encryptions;
    158   1.7   thorpej 
    159   1.7   thorpej 	if (!(I_SUPPORT_DECRYPT & remote_supports_encrypt & typemask(type)))
    160   1.7   thorpej 		return(0);
    161   1.7   thorpej 	while (ep->type && ep->type != type)
    162   1.7   thorpej 		++ep;
    163   1.7   thorpej 	return(ep->type ? ep : 0);
    164   1.7   thorpej }
    165   1.7   thorpej 
    166   1.7   thorpej #define	MAXKEYLEN 64
    167   1.7   thorpej 
    168   1.7   thorpej static struct key_info {
    169   1.7   thorpej 	unsigned char keyid[MAXKEYLEN];
    170   1.7   thorpej 	int keylen;
    171   1.7   thorpej 	int dir;
    172   1.7   thorpej 	int *modep;
    173  1.13     perry 	Encryptions *(*getcrypt)(int);
    174   1.7   thorpej } ki[2] = {
    175   1.7   thorpej 	{ { 0 }, 0, DIR_ENCRYPT, &encrypt_mode, findencryption },
    176   1.7   thorpej 	{ { 0 }, 0, DIR_DECRYPT, &decrypt_mode, finddecryption },
    177   1.7   thorpej };
    178   1.7   thorpej 
    179   1.7   thorpej 	void
    180   1.7   thorpej encrypt_init(name, server)
    181   1.7   thorpej 	const char *name;
    182   1.7   thorpej 	int server;
    183   1.7   thorpej {
    184   1.7   thorpej 	Encryptions *ep = encryptions;
    185   1.7   thorpej 
    186   1.7   thorpej 	Name = name;
    187   1.7   thorpej 	Server = server;
    188   1.7   thorpej 	i_support_encrypt = i_support_decrypt = 0;
    189   1.7   thorpej 	remote_supports_encrypt = remote_supports_decrypt = 0;
    190   1.7   thorpej 	encrypt_mode = 0;
    191   1.7   thorpej 	decrypt_mode = 0;
    192   1.7   thorpej 	encrypt_output = 0;
    193   1.7   thorpej 	decrypt_input = 0;
    194   1.7   thorpej #ifdef notdef
    195   1.7   thorpej 	encrypt_verbose = !server;
    196   1.7   thorpej #endif
    197   1.7   thorpej 
    198   1.7   thorpej 	str_suplen = 4;
    199   1.7   thorpej 
    200   1.7   thorpej 	while (ep->type) {
    201   1.7   thorpej 		if (encrypt_debug_mode)
    202   1.7   thorpej 			printf(">>>%s: I will support %s\r\n",
    203   1.7   thorpej 				Name, ENCTYPE_NAME(ep->type));
    204   1.7   thorpej 		i_support_encrypt |= typemask(ep->type);
    205   1.7   thorpej 		i_support_decrypt |= typemask(ep->type);
    206   1.7   thorpej 		if ((i_wont_support_decrypt & typemask(ep->type)) == 0)
    207   1.7   thorpej 			if ((str_send[str_suplen++] = ep->type) == IAC)
    208   1.7   thorpej 				str_send[str_suplen++] = IAC;
    209   1.7   thorpej 		if (ep->init)
    210   1.7   thorpej 			(*ep->init)(Server);
    211   1.7   thorpej 		++ep;
    212   1.7   thorpej 	}
    213   1.7   thorpej 	str_send[str_suplen++] = IAC;
    214   1.7   thorpej 	str_send[str_suplen++] = SE;
    215   1.7   thorpej }
    216   1.7   thorpej 
    217   1.7   thorpej 	void
    218   1.7   thorpej encrypt_list_types()
    219   1.7   thorpej {
    220   1.7   thorpej 	Encryptions *ep = encryptions;
    221   1.7   thorpej 
    222   1.7   thorpej 	printf("Valid encryption types:\n");
    223   1.7   thorpej 	while (ep->type) {
    224   1.7   thorpej 		printf("\t%s (%d)\r\n", ENCTYPE_NAME(ep->type), ep->type);
    225   1.7   thorpej 		++ep;
    226   1.7   thorpej 	}
    227   1.7   thorpej }
    228   1.7   thorpej 
    229   1.7   thorpej 	int
    230   1.7   thorpej EncryptEnable(type, mode)
    231   1.7   thorpej 	char *type, *mode;
    232   1.7   thorpej {
    233   1.7   thorpej 	if (isprefix(type, "help") || isprefix(type, "?")) {
    234   1.7   thorpej 		printf("Usage: encrypt enable <type> [input|output]\n");
    235   1.7   thorpej 		encrypt_list_types();
    236   1.7   thorpej 		return(0);
    237   1.7   thorpej 	}
    238   1.7   thorpej 	if (EncryptType(type, mode))
    239   1.7   thorpej 		return(EncryptStart(mode));
    240   1.7   thorpej 	return(0);
    241   1.7   thorpej }
    242   1.7   thorpej 
    243   1.7   thorpej 	int
    244   1.7   thorpej EncryptDisable(type, mode)
    245   1.7   thorpej 	char *type, *mode;
    246   1.7   thorpej {
    247   1.7   thorpej 	register Encryptions *ep;
    248   1.7   thorpej 	int ret = 0;
    249   1.7   thorpej 
    250   1.7   thorpej 	if (isprefix(type, "help") || isprefix(type, "?")) {
    251   1.7   thorpej 		printf("Usage: encrypt disable <type> [input|output]\n");
    252   1.7   thorpej 		encrypt_list_types();
    253   1.7   thorpej 	} else if ((ep = (Encryptions *)genget(type, (char **)encryptions,
    254   1.7   thorpej 						sizeof(Encryptions))) == 0) {
    255   1.7   thorpej 		printf("%s: invalid encryption type\n", type);
    256   1.7   thorpej 	} else if (Ambiguous(ep)) {
    257   1.7   thorpej 		printf("Ambiguous type '%s'\n", type);
    258   1.7   thorpej 	} else {
    259   1.7   thorpej 		if ((mode == 0) || (isprefix(mode, "input") ? 1 : 0)) {
    260   1.7   thorpej 			if (decrypt_mode == ep->type)
    261   1.7   thorpej 				EncryptStopInput();
    262   1.7   thorpej 			i_wont_support_decrypt |= typemask(ep->type);
    263   1.7   thorpej 			ret = 1;
    264   1.7   thorpej 		}
    265   1.7   thorpej 		if ((mode == 0) || (isprefix(mode, "output"))) {
    266   1.7   thorpej 			if (encrypt_mode == ep->type)
    267   1.7   thorpej 				EncryptStopOutput();
    268   1.7   thorpej 			i_wont_support_encrypt |= typemask(ep->type);
    269   1.7   thorpej 			ret = 1;
    270   1.7   thorpej 		}
    271   1.7   thorpej 		if (ret == 0)
    272   1.7   thorpej 			printf("%s: invalid encryption mode\n", mode);
    273   1.7   thorpej 	}
    274   1.7   thorpej 	return(ret);
    275   1.7   thorpej }
    276   1.7   thorpej 
    277   1.7   thorpej 	int
    278   1.7   thorpej EncryptType(type, mode)
    279   1.7   thorpej 	char *type;
    280   1.7   thorpej 	char *mode;
    281   1.7   thorpej {
    282   1.7   thorpej 	register Encryptions *ep;
    283   1.7   thorpej 	int ret = 0;
    284   1.7   thorpej 
    285   1.7   thorpej 	if (isprefix(type, "help") || isprefix(type, "?")) {
    286   1.7   thorpej 		printf("Usage: encrypt type <type> [input|output]\n");
    287   1.7   thorpej 		encrypt_list_types();
    288   1.7   thorpej 	} else if ((ep = (Encryptions *)genget(type, (char **)encryptions,
    289   1.7   thorpej 						sizeof(Encryptions))) == 0) {
    290   1.7   thorpej 		printf("%s: invalid encryption type\n", type);
    291   1.7   thorpej 	} else if (Ambiguous(ep)) {
    292   1.7   thorpej 		printf("Ambiguous type '%s'\n", type);
    293   1.7   thorpej 	} else {
    294   1.7   thorpej 		if ((mode == 0) || isprefix(mode, "input")) {
    295   1.7   thorpej 			decrypt_mode = ep->type;
    296   1.7   thorpej 			i_wont_support_decrypt &= ~typemask(ep->type);
    297   1.7   thorpej 			ret = 1;
    298   1.7   thorpej 		}
    299   1.7   thorpej 		if ((mode == 0) || isprefix(mode, "output")) {
    300   1.7   thorpej 			encrypt_mode = ep->type;
    301   1.7   thorpej 			i_wont_support_encrypt &= ~typemask(ep->type);
    302   1.7   thorpej 			ret = 1;
    303   1.7   thorpej 		}
    304   1.7   thorpej 		if (ret == 0)
    305   1.7   thorpej 			printf("%s: invalid encryption mode\n", mode);
    306   1.7   thorpej 	}
    307   1.7   thorpej 	return(ret);
    308   1.7   thorpej }
    309   1.7   thorpej 
    310   1.7   thorpej 	int
    311   1.7   thorpej EncryptStart(mode)
    312   1.7   thorpej 	char *mode;
    313   1.7   thorpej {
    314   1.7   thorpej 	register int ret = 0;
    315   1.7   thorpej 	if (mode) {
    316   1.7   thorpej 		if (isprefix(mode, "input"))
    317   1.7   thorpej 			return(EncryptStartInput());
    318   1.7   thorpej 		if (isprefix(mode, "output"))
    319   1.7   thorpej 			return(EncryptStartOutput());
    320   1.7   thorpej 		if (isprefix(mode, "help") || isprefix(mode, "?")) {
    321   1.7   thorpej 			printf("Usage: encrypt start [input|output]\n");
    322   1.7   thorpej 			return(0);
    323   1.7   thorpej 		}
    324   1.7   thorpej 		printf("%s: invalid encryption mode 'encrypt start ?' for help\n", mode);
    325   1.7   thorpej 		return(0);
    326   1.7   thorpej 	}
    327   1.7   thorpej 	ret += EncryptStartInput();
    328   1.7   thorpej 	ret += EncryptStartOutput();
    329   1.7   thorpej 	return(ret);
    330   1.7   thorpej }
    331   1.7   thorpej 
    332   1.7   thorpej 	int
    333   1.7   thorpej EncryptStartInput()
    334   1.7   thorpej {
    335   1.7   thorpej 	if (decrypt_mode) {
    336   1.7   thorpej 		encrypt_send_request_start();
    337   1.7   thorpej 		return(1);
    338   1.7   thorpej 	}
    339   1.7   thorpej 	printf("No previous decryption mode, decryption not enabled\r\n");
    340   1.7   thorpej 	return(0);
    341   1.7   thorpej }
    342   1.7   thorpej 
    343   1.7   thorpej 	int
    344   1.7   thorpej EncryptStartOutput()
    345   1.7   thorpej {
    346   1.7   thorpej 	if (encrypt_mode) {
    347   1.7   thorpej 		encrypt_start_output(encrypt_mode);
    348   1.7   thorpej 		return(1);
    349   1.7   thorpej 	}
    350   1.7   thorpej 	printf("No previous encryption mode, encryption not enabled\r\n");
    351   1.7   thorpej 	return(0);
    352   1.7   thorpej }
    353   1.7   thorpej 
    354   1.7   thorpej 	int
    355   1.7   thorpej EncryptStop(mode)
    356   1.7   thorpej 	char *mode;
    357   1.7   thorpej {
    358   1.7   thorpej 	int ret = 0;
    359   1.7   thorpej 	if (mode) {
    360   1.7   thorpej 		if (isprefix(mode, "input"))
    361   1.7   thorpej 			return(EncryptStopInput());
    362   1.7   thorpej 		if (isprefix(mode, "output"))
    363   1.7   thorpej 			return(EncryptStopOutput());
    364   1.7   thorpej 		if (isprefix(mode, "help") || isprefix(mode, "?")) {
    365   1.7   thorpej 			printf("Usage: encrypt stop [input|output]\n");
    366   1.7   thorpej 			return(0);
    367   1.7   thorpej 		}
    368   1.7   thorpej 		printf("%s: invalid encryption mode 'encrypt stop ?' for help\n", mode);
    369   1.7   thorpej 		return(0);
    370   1.7   thorpej 	}
    371   1.7   thorpej 	ret += EncryptStopInput();
    372   1.7   thorpej 	ret += EncryptStopOutput();
    373   1.7   thorpej 	return(ret);
    374   1.7   thorpej }
    375   1.7   thorpej 
    376   1.7   thorpej 	int
    377   1.7   thorpej EncryptStopInput()
    378   1.7   thorpej {
    379   1.7   thorpej 	encrypt_send_request_end();
    380   1.7   thorpej 	return(1);
    381   1.7   thorpej }
    382   1.7   thorpej 
    383   1.7   thorpej 	int
    384   1.7   thorpej EncryptStopOutput()
    385   1.7   thorpej {
    386   1.7   thorpej 	encrypt_send_end();
    387   1.7   thorpej 	return(1);
    388   1.7   thorpej }
    389   1.7   thorpej 
    390   1.7   thorpej 	void
    391   1.7   thorpej encrypt_display()
    392   1.7   thorpej {
    393   1.7   thorpej 	if (encrypt_output)
    394   1.7   thorpej 		printf("Currently encrypting output with %s\r\n",
    395   1.7   thorpej 			ENCTYPE_NAME(encrypt_mode));
    396   1.7   thorpej 	if (decrypt_input)
    397   1.7   thorpej 		printf("Currently decrypting input with %s\r\n",
    398   1.7   thorpej 			ENCTYPE_NAME(decrypt_mode));
    399   1.7   thorpej }
    400   1.7   thorpej 
    401   1.7   thorpej 	int
    402   1.7   thorpej EncryptStatus()
    403   1.7   thorpej {
    404   1.7   thorpej 	if (encrypt_output)
    405   1.7   thorpej 		printf("Currently encrypting output with %s\r\n",
    406   1.7   thorpej 			ENCTYPE_NAME(encrypt_mode));
    407   1.7   thorpej 	else if (encrypt_mode) {
    408   1.7   thorpej 		printf("Currently output is clear text.\r\n");
    409   1.7   thorpej 		printf("Last encryption mode was %s\r\n",
    410   1.7   thorpej 			ENCTYPE_NAME(encrypt_mode));
    411   1.7   thorpej 	}
    412   1.7   thorpej 	if (decrypt_input) {
    413   1.7   thorpej 		printf("Currently decrypting input with %s\r\n",
    414   1.7   thorpej 			ENCTYPE_NAME(decrypt_mode));
    415   1.7   thorpej 	} else if (decrypt_mode) {
    416   1.7   thorpej 		printf("Currently input is clear text.\r\n");
    417   1.7   thorpej 		printf("Last decryption mode was %s\r\n",
    418   1.7   thorpej 			ENCTYPE_NAME(decrypt_mode));
    419   1.7   thorpej 	}
    420   1.7   thorpej 	return 1;
    421   1.7   thorpej }
    422   1.7   thorpej 
    423   1.7   thorpej 	void
    424   1.7   thorpej encrypt_send_support()
    425   1.7   thorpej {
    426   1.7   thorpej 	if (str_suplen) {
    427   1.7   thorpej 		/*
    428   1.7   thorpej 		 * If the user has requested that decryption start
    429   1.7   thorpej 		 * immediatly, then send a "REQUEST START" before
    430   1.7   thorpej 		 * we negotiate the type.
    431   1.7   thorpej 		 */
    432   1.7   thorpej 		if (!Server && autodecrypt)
    433   1.7   thorpej 			encrypt_send_request_start();
    434   1.7   thorpej 		telnet_net_write(str_send, str_suplen);
    435   1.7   thorpej 		printsub('>', &str_send[2], str_suplen - 2);
    436   1.7   thorpej 		str_suplen = 0;
    437   1.7   thorpej 	}
    438   1.7   thorpej }
    439   1.7   thorpej 
    440   1.7   thorpej 	int
    441   1.7   thorpej EncryptDebug(on)
    442   1.7   thorpej 	int on;
    443   1.7   thorpej {
    444   1.7   thorpej 	if (on < 0)
    445   1.7   thorpej 		encrypt_debug_mode ^= 1;
    446   1.7   thorpej 	else
    447   1.7   thorpej 		encrypt_debug_mode = on;
    448   1.7   thorpej 	printf("Encryption debugging %s\r\n",
    449   1.7   thorpej 		encrypt_debug_mode ? "enabled" : "disabled");
    450   1.7   thorpej 	return(1);
    451   1.7   thorpej }
    452   1.7   thorpej 
    453   1.7   thorpej 	int
    454   1.7   thorpej EncryptVerbose(on)
    455   1.7   thorpej 	int on;
    456   1.7   thorpej {
    457   1.7   thorpej 	if (on < 0)
    458   1.7   thorpej 		encrypt_verbose ^= 1;
    459   1.7   thorpej 	else
    460   1.7   thorpej 		encrypt_verbose = on;
    461   1.7   thorpej 	printf("Encryption %s verbose\r\n",
    462   1.7   thorpej 		encrypt_verbose ? "is" : "is not");
    463   1.7   thorpej 	return(1);
    464   1.7   thorpej }
    465   1.7   thorpej 
    466   1.7   thorpej 	int
    467   1.7   thorpej EncryptAutoEnc(on)
    468   1.7   thorpej 	int on;
    469   1.7   thorpej {
    470   1.7   thorpej 	encrypt_auto(on);
    471   1.7   thorpej 	printf("Automatic encryption of output is %s\r\n",
    472   1.7   thorpej 		autoencrypt ? "enabled" : "disabled");
    473   1.7   thorpej 	return(1);
    474   1.7   thorpej }
    475   1.7   thorpej 
    476   1.7   thorpej 	int
    477   1.7   thorpej EncryptAutoDec(on)
    478   1.7   thorpej 	int on;
    479   1.7   thorpej {
    480   1.7   thorpej 	decrypt_auto(on);
    481   1.7   thorpej 	printf("Automatic decryption of input is %s\r\n",
    482   1.7   thorpej 		autodecrypt ? "enabled" : "disabled");
    483   1.7   thorpej 	return(1);
    484   1.7   thorpej }
    485   1.7   thorpej 
    486   1.7   thorpej /*
    487   1.7   thorpej  * Called when ENCRYPT SUPPORT is received.
    488   1.7   thorpej  */
    489   1.7   thorpej 	void
    490   1.7   thorpej encrypt_support(typelist, cnt)
    491   1.7   thorpej 	unsigned char *typelist;
    492   1.7   thorpej 	int cnt;
    493   1.7   thorpej {
    494   1.7   thorpej 	register int type, use_type = 0;
    495   1.7   thorpej 	Encryptions *ep;
    496   1.7   thorpej 
    497   1.7   thorpej 	/*
    498   1.7   thorpej 	 * Forget anything the other side has previously told us.
    499   1.7   thorpej 	 */
    500   1.7   thorpej 	remote_supports_decrypt = 0;
    501   1.7   thorpej 
    502   1.7   thorpej 	while (cnt-- > 0) {
    503   1.7   thorpej 		type = *typelist++;
    504   1.7   thorpej 		if (encrypt_debug_mode)
    505   1.7   thorpej 			printf(">>>%s: He is supporting %s (%d)\r\n",
    506   1.7   thorpej 				Name,
    507   1.7   thorpej 				ENCTYPE_NAME(type), type);
    508   1.7   thorpej 		if ((type < ENCTYPE_CNT) &&
    509   1.7   thorpej 		    (I_SUPPORT_ENCRYPT & typemask(type))) {
    510   1.7   thorpej 			remote_supports_decrypt |= typemask(type);
    511   1.7   thorpej 			if (use_type == 0)
    512   1.7   thorpej 				use_type = type;
    513   1.7   thorpej 		}
    514   1.7   thorpej 	}
    515   1.7   thorpej 	if (use_type) {
    516   1.7   thorpej 		ep = findencryption(use_type);
    517   1.7   thorpej 		if (!ep)
    518   1.7   thorpej 			return;
    519   1.7   thorpej 		type = ep->start ? (*ep->start)(DIR_ENCRYPT, Server) : 0;
    520   1.7   thorpej 		if (encrypt_debug_mode)
    521   1.7   thorpej 			printf(">>>%s: (*ep->start)() returned %d\r\n",
    522   1.7   thorpej 					Name, type);
    523   1.7   thorpej 		if (type < 0)
    524   1.7   thorpej 			return;
    525   1.7   thorpej 		encrypt_mode = use_type;
    526   1.7   thorpej 		if (type == 0)
    527   1.7   thorpej 			encrypt_start_output(use_type);
    528   1.7   thorpej 	}
    529   1.7   thorpej }
    530   1.7   thorpej 
    531   1.7   thorpej 	void
    532   1.7   thorpej encrypt_is(data, cnt)
    533   1.7   thorpej 	unsigned char *data;
    534   1.7   thorpej 	int cnt;
    535   1.7   thorpej {
    536   1.7   thorpej 	Encryptions *ep;
    537   1.7   thorpej 	register int type, ret;
    538   1.7   thorpej 
    539   1.7   thorpej 	if (--cnt < 0)
    540   1.7   thorpej 		return;
    541   1.7   thorpej 	type = *data++;
    542   1.7   thorpej 	if (type < ENCTYPE_CNT)
    543   1.7   thorpej 		remote_supports_encrypt |= typemask(type);
    544   1.7   thorpej 	if (!(ep = finddecryption(type))) {
    545   1.7   thorpej 		if (encrypt_debug_mode)
    546   1.7   thorpej 			printf(">>>%s: Can't find type %s (%d) for initial negotiation\r\n",
    547   1.7   thorpej 				Name,
    548   1.7   thorpej 				ENCTYPE_NAME_OK(type)
    549   1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    550   1.7   thorpej 				type);
    551   1.7   thorpej 		return;
    552   1.7   thorpej 	}
    553   1.7   thorpej 	if (!ep->is) {
    554   1.7   thorpej 		if (encrypt_debug_mode)
    555   1.7   thorpej 			printf(">>>%s: No initial negotiation needed for type %s (%d)\r\n",
    556   1.7   thorpej 				Name,
    557   1.7   thorpej 				ENCTYPE_NAME_OK(type)
    558   1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    559   1.7   thorpej 				type);
    560   1.7   thorpej 		ret = 0;
    561   1.7   thorpej 	} else {
    562   1.7   thorpej 		ret = (*ep->is)(data, cnt);
    563   1.7   thorpej 		if (encrypt_debug_mode)
    564   1.7   thorpej 			printf("(*ep->is)(%p, %d) returned %s(%d)\n", data, cnt,
    565   1.7   thorpej 				(ret < 0) ? "FAIL " :
    566   1.7   thorpej 				(ret == 0) ? "SUCCESS " : "MORE_TO_DO ", ret);
    567   1.7   thorpej 	}
    568   1.7   thorpej 	if (ret < 0) {
    569   1.7   thorpej 		autodecrypt = 0;
    570   1.7   thorpej 	} else {
    571   1.7   thorpej 		decrypt_mode = type;
    572   1.7   thorpej 		if (ret == 0 && autodecrypt)
    573   1.7   thorpej 			encrypt_send_request_start();
    574   1.7   thorpej 	}
    575   1.7   thorpej }
    576   1.7   thorpej 
    577   1.7   thorpej 	void
    578   1.7   thorpej encrypt_reply(data, cnt)
    579   1.7   thorpej 	unsigned char *data;
    580   1.7   thorpej 	int cnt;
    581   1.7   thorpej {
    582   1.7   thorpej 	Encryptions *ep;
    583   1.7   thorpej 	register int ret, type;
    584   1.7   thorpej 
    585   1.7   thorpej 	if (--cnt < 0)
    586   1.7   thorpej 		return;
    587   1.7   thorpej 	type = *data++;
    588   1.7   thorpej 	if (!(ep = findencryption(type))) {
    589   1.7   thorpej 		if (encrypt_debug_mode)
    590   1.7   thorpej 			printf(">>>%s: Can't find type %s (%d) for initial negotiation\r\n",
    591   1.7   thorpej 				Name,
    592   1.7   thorpej 				ENCTYPE_NAME_OK(type)
    593   1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    594   1.7   thorpej 				type);
    595   1.7   thorpej 		return;
    596   1.7   thorpej 	}
    597   1.7   thorpej 	if (!ep->reply) {
    598   1.7   thorpej 		if (encrypt_debug_mode)
    599   1.7   thorpej 			printf(">>>%s: No initial negotiation needed for type %s (%d)\r\n",
    600   1.7   thorpej 				Name,
    601   1.7   thorpej 				ENCTYPE_NAME_OK(type)
    602   1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    603   1.7   thorpej 				type);
    604   1.7   thorpej 		ret = 0;
    605   1.7   thorpej 	} else {
    606   1.7   thorpej 		ret = (*ep->reply)(data, cnt);
    607   1.7   thorpej 		if (encrypt_debug_mode)
    608   1.7   thorpej 			printf("(*ep->reply)(%p, %d) returned %s(%d)\n",
    609   1.7   thorpej 				data, cnt,
    610   1.7   thorpej 				(ret < 0) ? "FAIL " :
    611   1.7   thorpej 				(ret == 0) ? "SUCCESS " : "MORE_TO_DO ", ret);
    612   1.7   thorpej 	}
    613   1.7   thorpej 	if (encrypt_debug_mode)
    614   1.7   thorpej 		printf(">>>%s: encrypt_reply returned %d\n", Name, ret);
    615   1.7   thorpej 	if (ret < 0) {
    616   1.7   thorpej 		autoencrypt = 0;
    617   1.7   thorpej 	} else {
    618   1.7   thorpej 		encrypt_mode = type;
    619   1.7   thorpej 		if (ret == 0 && autoencrypt)
    620   1.7   thorpej 			encrypt_start_output(type);
    621   1.7   thorpej 	}
    622   1.7   thorpej }
    623   1.7   thorpej 
    624   1.7   thorpej /*
    625   1.7   thorpej  * Called when a ENCRYPT START command is received.
    626   1.7   thorpej  */
    627   1.7   thorpej 	void
    628   1.7   thorpej encrypt_start(data, cnt)
    629   1.7   thorpej 	unsigned char *data;
    630   1.7   thorpej 	int cnt;
    631   1.7   thorpej {
    632   1.7   thorpej 	Encryptions *ep;
    633   1.7   thorpej 
    634   1.7   thorpej 	if (!decrypt_mode) {
    635   1.7   thorpej 		/*
    636   1.7   thorpej 		 * Something is wrong.  We should not get a START
    637   1.7   thorpej 		 * command without having already picked our
    638   1.7   thorpej 		 * decryption scheme.  Send a REQUEST-END to
    639   1.7   thorpej 		 * attempt to clear the channel...
    640   1.7   thorpej 		 */
    641   1.7   thorpej 		printf("%s: Warning, Cannot decrypt input stream!!!\r\n", Name);
    642   1.7   thorpej 		encrypt_send_request_end();
    643   1.7   thorpej 		return;
    644   1.7   thorpej 	}
    645   1.7   thorpej 
    646   1.7   thorpej 	if ((ep = finddecryption(decrypt_mode)) != NULL) {
    647   1.7   thorpej 		decrypt_input = ep->input;
    648   1.7   thorpej 		if (encrypt_verbose)
    649   1.7   thorpej 			printf("[ Input is now decrypted with type %s ]\r\n",
    650   1.7   thorpej 				ENCTYPE_NAME(decrypt_mode));
    651   1.7   thorpej 		if (encrypt_debug_mode)
    652   1.7   thorpej 			printf(">>>%s: Start to decrypt input with type %s\r\n",
    653   1.7   thorpej 				Name, ENCTYPE_NAME(decrypt_mode));
    654   1.7   thorpej 	} else {
    655   1.7   thorpej 		printf("%s: Warning, Cannot decrypt type %s (%d)!!!\r\n",
    656   1.7   thorpej 				Name,
    657   1.7   thorpej 				ENCTYPE_NAME_OK(decrypt_mode)
    658   1.7   thorpej 					? ENCTYPE_NAME(decrypt_mode)
    659   1.7   thorpej 					: "(unknown)",
    660   1.7   thorpej 				decrypt_mode);
    661   1.7   thorpej 		encrypt_send_request_end();
    662   1.7   thorpej 	}
    663   1.7   thorpej }
    664   1.7   thorpej 
    665   1.7   thorpej 	void
    666   1.7   thorpej encrypt_session_key(key, server)
    667   1.7   thorpej 	Session_Key *key;
    668   1.7   thorpej 	int server;
    669   1.7   thorpej {
    670   1.7   thorpej 	Encryptions *ep = encryptions;
    671   1.7   thorpej 
    672   1.7   thorpej 	havesessionkey = 1;
    673   1.7   thorpej 
    674   1.7   thorpej 	while (ep->type) {
    675   1.7   thorpej 		if (ep->session)
    676   1.7   thorpej 			(*ep->session)(key, server);
    677   1.7   thorpej #ifdef notdef
    678   1.7   thorpej 		if (!encrypt_output && autoencrypt && !server)
    679   1.7   thorpej 			encrypt_start_output(ep->type);
    680   1.7   thorpej 		if (!decrypt_input && autodecrypt && !server)
    681   1.7   thorpej 			encrypt_send_request_start();
    682   1.7   thorpej #endif
    683   1.7   thorpej 		++ep;
    684   1.7   thorpej 	}
    685   1.7   thorpej }
    686   1.7   thorpej 
    687   1.7   thorpej /*
    688   1.7   thorpej  * Called when ENCRYPT END is received.
    689   1.7   thorpej  */
    690   1.7   thorpej 	void
    691   1.7   thorpej encrypt_end()
    692   1.7   thorpej {
    693   1.7   thorpej 	decrypt_input = 0;
    694   1.7   thorpej 	if (encrypt_debug_mode)
    695   1.7   thorpej 		printf(">>>%s: Input is back to clear text\r\n", Name);
    696   1.7   thorpej 	if (encrypt_verbose)
    697   1.7   thorpej 		printf("[ Input is now clear text ]\r\n");
    698   1.7   thorpej }
    699   1.7   thorpej 
    700   1.7   thorpej /*
    701   1.7   thorpej  * Called when ENCRYPT REQUEST-END is received.
    702   1.7   thorpej  */
    703   1.7   thorpej 	void
    704   1.7   thorpej encrypt_request_end()
    705   1.7   thorpej {
    706   1.7   thorpej 	encrypt_send_end();
    707   1.7   thorpej }
    708   1.7   thorpej 
    709   1.7   thorpej /*
    710   1.7   thorpej  * Called when ENCRYPT REQUEST-START is received.  If we receive
    711   1.7   thorpej  * this before a type is picked, then that indicates that the
    712   1.7   thorpej  * other side wants us to start encrypting data as soon as we
    713   1.7   thorpej  * can.
    714   1.7   thorpej  */
    715   1.7   thorpej 	void
    716   1.7   thorpej encrypt_request_start(data, cnt)
    717   1.7   thorpej 	unsigned char *data;
    718   1.7   thorpej 	int cnt;
    719   1.7   thorpej {
    720   1.7   thorpej 	if (encrypt_mode == 0)  {
    721   1.7   thorpej 		if (Server)
    722   1.7   thorpej 			autoencrypt = 1;
    723   1.7   thorpej 		return;
    724   1.7   thorpej 	}
    725   1.7   thorpej 	encrypt_start_output(encrypt_mode);
    726   1.7   thorpej }
    727   1.7   thorpej 
    728   1.7   thorpej static unsigned char str_keyid[(MAXKEYLEN*2)+5] = { IAC, SB, TELOPT_ENCRYPT };
    729   1.7   thorpej 
    730   1.7   thorpej 	void
    731   1.7   thorpej encrypt_enc_keyid(keyid, len)
    732   1.7   thorpej 	unsigned char *keyid;
    733   1.7   thorpej 	int len;
    734   1.7   thorpej {
    735   1.7   thorpej 	encrypt_keyid(&ki[1], keyid, len);
    736   1.7   thorpej }
    737   1.7   thorpej 
    738   1.7   thorpej 	void
    739   1.7   thorpej encrypt_dec_keyid(keyid, len)
    740   1.7   thorpej 	unsigned char *keyid;
    741   1.7   thorpej 	int len;
    742   1.7   thorpej {
    743   1.7   thorpej 	encrypt_keyid(&ki[0], keyid, len);
    744   1.7   thorpej }
    745   1.7   thorpej 
    746   1.7   thorpej void
    747   1.7   thorpej encrypt_keyid(kp, keyid, len)
    748   1.7   thorpej 	struct key_info *kp;
    749   1.7   thorpej 	unsigned char *keyid;
    750   1.7   thorpej 	int len;
    751   1.7   thorpej {
    752   1.7   thorpej 	Encryptions *ep;
    753   1.7   thorpej 	int dir = kp->dir;
    754   1.7   thorpej 	register int ret = 0;
    755   1.7   thorpej 
    756   1.7   thorpej 	if (!(ep = (*kp->getcrypt)(*kp->modep))) {
    757   1.7   thorpej 		if (len == 0)
    758   1.7   thorpej 			return;
    759   1.7   thorpej 		kp->keylen = 0;
    760   1.7   thorpej 	} else if (len == 0) {
    761   1.7   thorpej 		/*
    762   1.7   thorpej 		 * Empty option, indicates a failure.
    763   1.7   thorpej 		 */
    764   1.7   thorpej 		if (kp->keylen == 0)
    765   1.7   thorpej 			return;
    766   1.7   thorpej 		kp->keylen = 0;
    767   1.7   thorpej 		if (ep->keyid)
    768   1.7   thorpej 			(void)(*ep->keyid)(dir, kp->keyid, &kp->keylen);
    769   1.7   thorpej 
    770   1.7   thorpej 	} else if ((len != kp->keylen) ||
    771   1.7   thorpej 		   (memcmp(keyid, kp->keyid, len) != 0)) {
    772   1.7   thorpej 		/*
    773   1.7   thorpej 		 * Length or contents are different
    774   1.7   thorpej 		 */
    775   1.7   thorpej 		kp->keylen = len;
    776   1.7   thorpej 		memmove(kp->keyid, keyid, len);
    777   1.7   thorpej 		if (ep->keyid)
    778   1.7   thorpej 			(void)(*ep->keyid)(dir, kp->keyid, &kp->keylen);
    779   1.7   thorpej 	} else {
    780   1.7   thorpej 		if (ep->keyid)
    781   1.7   thorpej 			ret = (*ep->keyid)(dir, kp->keyid, &kp->keylen);
    782   1.7   thorpej 		if ((ret == 0) && (dir == DIR_ENCRYPT) && autoencrypt)
    783   1.7   thorpej 			encrypt_start_output(*kp->modep);
    784   1.7   thorpej 		return;
    785   1.7   thorpej 	}
    786   1.7   thorpej 
    787   1.7   thorpej 	encrypt_send_keyid(dir, kp->keyid, kp->keylen, 0);
    788   1.7   thorpej }
    789   1.7   thorpej 
    790   1.7   thorpej 	void
    791   1.7   thorpej encrypt_send_keyid(dir, keyid, keylen, saveit)
    792   1.7   thorpej 	int dir;
    793   1.7   thorpej 	unsigned char *keyid;
    794   1.7   thorpej 	int keylen;
    795   1.7   thorpej 	int saveit;
    796   1.7   thorpej {
    797   1.7   thorpej 	unsigned char *strp;
    798   1.7   thorpej 
    799   1.7   thorpej 	str_keyid[3] = (dir == DIR_ENCRYPT)
    800   1.7   thorpej 			? ENCRYPT_ENC_KEYID : ENCRYPT_DEC_KEYID;
    801   1.7   thorpej 	if (saveit) {
    802   1.7   thorpej 		struct key_info *kp = &ki[(dir == DIR_ENCRYPT) ? 0 : 1];
    803   1.7   thorpej 		memmove(kp->keyid, keyid, keylen);
    804   1.7   thorpej 		kp->keylen = keylen;
    805   1.7   thorpej 	}
    806   1.7   thorpej 
    807   1.7   thorpej 	for (strp = &str_keyid[4]; keylen > 0; --keylen) {
    808   1.7   thorpej 		if ((*strp++ = *keyid++) == IAC)
    809   1.7   thorpej 			*strp++ = IAC;
    810   1.7   thorpej 	}
    811   1.7   thorpej 	*strp++ = IAC;
    812   1.7   thorpej 	*strp++ = SE;
    813   1.7   thorpej 	telnet_net_write(str_keyid, strp - str_keyid);
    814   1.7   thorpej 	printsub('>', &str_keyid[2], strp - str_keyid - 2);
    815   1.7   thorpej }
    816   1.7   thorpej 
    817   1.7   thorpej 	void
    818   1.7   thorpej encrypt_auto(on)
    819   1.7   thorpej 	int on;
    820   1.7   thorpej {
    821   1.7   thorpej 	if (on < 0)
    822   1.7   thorpej 		autoencrypt ^= 1;
    823   1.7   thorpej 	else
    824   1.7   thorpej 		autoencrypt = on ? 1 : 0;
    825   1.7   thorpej }
    826   1.7   thorpej 
    827   1.7   thorpej 	void
    828   1.7   thorpej decrypt_auto(on)
    829   1.7   thorpej 	int on;
    830   1.7   thorpej {
    831   1.7   thorpej 	if (on < 0)
    832   1.7   thorpej 		autodecrypt ^= 1;
    833   1.7   thorpej 	else
    834   1.7   thorpej 		autodecrypt = on ? 1 : 0;
    835   1.7   thorpej }
    836   1.7   thorpej 
    837   1.7   thorpej 	void
    838   1.7   thorpej encrypt_start_output(type)
    839   1.7   thorpej 	int type;
    840   1.7   thorpej {
    841   1.7   thorpej 	Encryptions *ep;
    842   1.7   thorpej 	register unsigned char *p;
    843   1.7   thorpej 	register int i;
    844   1.7   thorpej 
    845   1.7   thorpej 	if (!(ep = findencryption(type))) {
    846   1.7   thorpej 		if (encrypt_debug_mode) {
    847   1.7   thorpej 			printf(">>>%s: Can't encrypt with type %s (%d)\r\n",
    848   1.7   thorpej 				Name,
    849   1.7   thorpej 				ENCTYPE_NAME_OK(type)
    850   1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    851   1.7   thorpej 				type);
    852   1.7   thorpej 		}
    853   1.7   thorpej 		return;
    854   1.7   thorpej 	}
    855   1.7   thorpej 	if (ep->start) {
    856   1.7   thorpej 		i = (*ep->start)(DIR_ENCRYPT, Server);
    857   1.7   thorpej 		if (encrypt_debug_mode) {
    858   1.7   thorpej 			printf(">>>%s: Encrypt start: %s (%d) %s\r\n",
    859   1.7   thorpej 				Name,
    860   1.7   thorpej 				(i < 0) ? "failed" :
    861   1.7   thorpej 					"initial negotiation in progress",
    862   1.7   thorpej 				i, ENCTYPE_NAME(type));
    863   1.7   thorpej 		}
    864   1.7   thorpej 		if (i)
    865   1.7   thorpej 			return;
    866   1.7   thorpej 	}
    867   1.7   thorpej 	p = str_start + 3;
    868   1.7   thorpej 	*p++ = ENCRYPT_START;
    869   1.7   thorpej 	for (i = 0; i < ki[0].keylen; ++i) {
    870   1.7   thorpej 		if ((*p++ = ki[0].keyid[i]) == IAC)
    871   1.7   thorpej 			*p++ = IAC;
    872   1.7   thorpej 	}
    873   1.7   thorpej 	*p++ = IAC;
    874   1.7   thorpej 	*p++ = SE;
    875   1.7   thorpej 	telnet_net_write(str_start, p - str_start);
    876   1.7   thorpej 	net_encrypt();
    877   1.7   thorpej 	printsub('>', &str_start[2], p - &str_start[2]);
    878   1.7   thorpej 	/*
    879   1.7   thorpej 	 * If we are already encrypting in some mode, then
    880   1.7   thorpej 	 * encrypt the ring (which includes our request) in
    881   1.7   thorpej 	 * the old mode, mark it all as "clear text" and then
    882   1.7   thorpej 	 * switch to the new mode.
    883   1.7   thorpej 	 */
    884   1.7   thorpej 	encrypt_output = ep->output;
    885   1.7   thorpej 	encrypt_mode = type;
    886   1.7   thorpej 	if (encrypt_debug_mode)
    887   1.7   thorpej 		printf(">>>%s: Started to encrypt output with type %s\r\n",
    888   1.7   thorpej 			Name, ENCTYPE_NAME(type));
    889   1.7   thorpej 	if (encrypt_verbose)
    890   1.7   thorpej 		printf("[ Output is now encrypted with type %s ]\r\n",
    891   1.7   thorpej 			ENCTYPE_NAME(type));
    892   1.7   thorpej }
    893   1.7   thorpej 
    894   1.7   thorpej 	void
    895   1.7   thorpej encrypt_send_end()
    896   1.7   thorpej {
    897   1.7   thorpej 	if (!encrypt_output)
    898   1.7   thorpej 		return;
    899   1.7   thorpej 
    900   1.7   thorpej 	str_end[3] = ENCRYPT_END;
    901   1.7   thorpej 	telnet_net_write(str_end, sizeof(str_end));
    902   1.7   thorpej 	net_encrypt();
    903   1.7   thorpej 	printsub('>', &str_end[2], sizeof(str_end) - 2);
    904   1.7   thorpej 	/*
    905   1.7   thorpej 	 * Encrypt the output buffer now because it will not be done by
    906   1.7   thorpej 	 * netflush...
    907   1.7   thorpej 	 */
    908   1.7   thorpej 	encrypt_output = 0;
    909   1.7   thorpej 	if (encrypt_debug_mode)
    910   1.7   thorpej 		printf(">>>%s: Output is back to clear text\r\n", Name);
    911   1.7   thorpej 	if (encrypt_verbose)
    912   1.7   thorpej 		printf("[ Output is now clear text ]\r\n");
    913   1.7   thorpej }
    914   1.7   thorpej 
    915   1.7   thorpej 	void
    916   1.7   thorpej encrypt_send_request_start()
    917   1.7   thorpej {
    918   1.7   thorpej 	register unsigned char *p;
    919   1.7   thorpej 	register int i;
    920   1.7   thorpej 
    921   1.7   thorpej 	p = &str_start[3];
    922   1.7   thorpej 	*p++ = ENCRYPT_REQSTART;
    923   1.7   thorpej 	for (i = 0; i < ki[1].keylen; ++i) {
    924   1.7   thorpej 		if ((*p++ = ki[1].keyid[i]) == IAC)
    925   1.7   thorpej 			*p++ = IAC;
    926   1.7   thorpej 	}
    927   1.7   thorpej 	*p++ = IAC;
    928   1.7   thorpej 	*p++ = SE;
    929   1.7   thorpej 	telnet_net_write(str_start, p - str_start);
    930   1.7   thorpej 	printsub('>', &str_start[2], p - &str_start[2]);
    931   1.7   thorpej 	if (encrypt_debug_mode)
    932   1.7   thorpej 		printf(">>>%s: Request input to be encrypted\r\n", Name);
    933   1.7   thorpej }
    934   1.7   thorpej 
    935   1.7   thorpej 	void
    936   1.7   thorpej encrypt_send_request_end()
    937   1.7   thorpej {
    938   1.7   thorpej 	str_end[3] = ENCRYPT_REQEND;
    939   1.7   thorpej 	telnet_net_write(str_end, sizeof(str_end));
    940   1.7   thorpej 	printsub('>', &str_end[2], sizeof(str_end) - 2);
    941   1.7   thorpej 
    942   1.7   thorpej 	if (encrypt_debug_mode)
    943   1.7   thorpej 		printf(">>>%s: Request input to be clear text\r\n", Name);
    944   1.7   thorpej }
    945   1.7   thorpej 
    946   1.7   thorpej 	void
    947   1.7   thorpej encrypt_wait()
    948   1.7   thorpej {
    949   1.7   thorpej 	if (encrypt_debug_mode)
    950   1.7   thorpej 		printf(">>>%s: in encrypt_wait\r\n", Name);
    951   1.7   thorpej 	if (!havesessionkey || !(I_SUPPORT_ENCRYPT & remote_supports_decrypt))
    952   1.7   thorpej 		return;
    953   1.7   thorpej 	while (autoencrypt && !encrypt_output)
    954   1.7   thorpej 		if (telnet_spin())
    955   1.7   thorpej 			return;
    956   1.7   thorpej }
    957   1.7   thorpej 
    958   1.7   thorpej 	void
    959   1.7   thorpej encrypt_debug(mode)
    960   1.7   thorpej 	int mode;
    961   1.7   thorpej {
    962   1.7   thorpej 	encrypt_debug_mode = mode;
    963   1.7   thorpej }
    964   1.7   thorpej 
    965   1.7   thorpej 	void
    966   1.7   thorpej encrypt_gen_printsub(data, cnt, buf, buflen)
    967   1.7   thorpej 	unsigned char *data, *buf;
    968   1.7   thorpej 	int cnt, buflen;
    969   1.7   thorpej {
    970   1.7   thorpej 	char tbuf[16], *cp;
    971   1.7   thorpej 
    972   1.7   thorpej 	cnt -= 2;
    973   1.7   thorpej 	data += 2;
    974   1.7   thorpej 	buf[buflen-1] = '\0';
    975   1.7   thorpej 	buf[buflen-2] = '*';
    976  1.10    simonb 	buflen -= 2;
    977   1.7   thorpej 	for (; cnt > 0; cnt--, data++) {
    978  1.11    itojun 		snprintf(tbuf, sizeof(tbuf), " %d", *data);
    979   1.7   thorpej 		for (cp = tbuf; *cp && buflen > 0; --buflen)
    980   1.7   thorpej 			*buf++ = *cp++;
    981   1.7   thorpej 		if (buflen <= 0)
    982   1.7   thorpej 			return;
    983   1.7   thorpej 	}
    984   1.7   thorpej 	*buf = '\0';
    985   1.7   thorpej }
    986   1.7   thorpej 
    987   1.7   thorpej 	void
    988   1.7   thorpej encrypt_printsub(data, cnt, buf, buflen)
    989   1.7   thorpej 	unsigned char *data, *buf;
    990   1.7   thorpej 	int cnt, buflen;
    991   1.7   thorpej {
    992   1.7   thorpej 	Encryptions *ep;
    993   1.7   thorpej 	register int type = data[1];
    994   1.7   thorpej 
    995   1.7   thorpej 	for (ep = encryptions; ep->type && ep->type != type; ep++)
    996   1.7   thorpej 		;
    997   1.7   thorpej 
    998   1.7   thorpej 	if (ep->printsub)
    999   1.7   thorpej 		(*ep->printsub)(data, cnt, buf, buflen);
   1000   1.7   thorpej 	else
   1001   1.7   thorpej 		encrypt_gen_printsub(data, cnt, buf, buflen);
   1002   1.7   thorpej }
   1003   1.7   thorpej #endif	/* ENCRYPTION */
   1004