Home | History | Annotate | Line # | Download | only in libtelnet
encrypt.c revision 1.14.18.1
      1  1.14.18.1       snj /*	$NetBSD: encrypt.c,v 1.14.18.1 2011/12/31 20:01:51 snj Exp $	*/
      2        1.6  christos 
      3        1.1       cgd /*-
      4        1.3       cgd  * Copyright (c) 1991, 1993
      5        1.3       cgd  *	The Regents of the University of California.  All rights reserved.
      6        1.1       cgd  *
      7        1.1       cgd  * Redistribution and use in source and binary forms, with or without
      8        1.1       cgd  * modification, are permitted provided that the following conditions
      9        1.1       cgd  * are met:
     10        1.1       cgd  * 1. Redistributions of source code must retain the above copyright
     11        1.1       cgd  *    notice, this list of conditions and the following disclaimer.
     12        1.1       cgd  * 2. Redistributions in binary form must reproduce the above copyright
     13        1.1       cgd  *    notice, this list of conditions and the following disclaimer in the
     14        1.1       cgd  *    documentation and/or other materials provided with the distribution.
     15       1.12       agc  * 3. Neither the name of the University nor the names of its contributors
     16        1.1       cgd  *    may be used to endorse or promote products derived from this software
     17        1.1       cgd  *    without specific prior written permission.
     18        1.1       cgd  *
     19        1.1       cgd  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
     20        1.1       cgd  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     21        1.1       cgd  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     22        1.1       cgd  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
     23        1.1       cgd  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     24        1.1       cgd  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     25        1.1       cgd  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     26        1.1       cgd  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     27        1.1       cgd  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     28        1.1       cgd  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     29        1.1       cgd  * SUCH DAMAGE.
     30        1.1       cgd  */
     31        1.1       cgd 
     32        1.5     lukem #include <sys/cdefs.h>
     33        1.5     lukem #if 0
     34        1.5     lukem static char sccsid[] = "@(#)encrypt.c	8.2 (Berkeley) 5/30/95";
     35        1.5     lukem #else
     36  1.14.18.1       snj __RCSID("$NetBSD: encrypt.c,v 1.14.18.1 2011/12/31 20:01:51 snj Exp $");
     37        1.1       cgd #endif /* not lint */
     38        1.1       cgd 
     39        1.1       cgd /*
     40        1.1       cgd  * Copyright (C) 1990 by the Massachusetts Institute of Technology
     41        1.1       cgd  *
     42        1.1       cgd  * Export of this software from the United States of America is assumed
     43        1.1       cgd  * to require a specific license from the United States Government.
     44        1.1       cgd  * It is the responsibility of any person or organization contemplating
     45        1.1       cgd  * export to obtain such a license before exporting.
     46        1.1       cgd  *
     47        1.1       cgd  * WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
     48        1.1       cgd  * distribute this software and its documentation for any purpose and
     49        1.1       cgd  * without fee is hereby granted, provided that the above copyright
     50        1.1       cgd  * notice appear in all copies and that both that copyright notice and
     51        1.1       cgd  * this permission notice appear in supporting documentation, and that
     52        1.1       cgd  * the name of M.I.T. not be used in advertising or publicity pertaining
     53        1.1       cgd  * to distribution of the software without specific, written prior
     54        1.1       cgd  * permission.  M.I.T. makes no representations about the suitability of
     55        1.1       cgd  * this software for any purpose.  It is provided "as is" without express
     56        1.1       cgd  * or implied warranty.
     57        1.1       cgd  */
     58        1.1       cgd 
     59        1.7   thorpej #ifdef	ENCRYPTION
     60        1.7   thorpej 
     61        1.7   thorpej #include <stdio.h>
     62        1.7   thorpej #define	ENCRYPT_NAMES
     63        1.7   thorpej #include <arpa/telnet.h>
     64        1.7   thorpej 
     65        1.7   thorpej #include "encrypt.h"
     66        1.7   thorpej #include "misc.h"
     67        1.7   thorpej 
     68        1.7   thorpej #include <stdlib.h>
     69        1.7   thorpej #ifdef	NO_STRING_H
     70        1.7   thorpej #include <strings.h>
     71        1.7   thorpej #else
     72        1.7   thorpej #include <string.h>
     73        1.7   thorpej #endif
     74        1.7   thorpej 
     75        1.7   thorpej /*
     76        1.7   thorpej  * These functions pointers point to the current routines
     77        1.7   thorpej  * for encrypting and decrypting data.
     78        1.7   thorpej  */
     79       1.13     perry void	(*encrypt_output)(unsigned char *, int);
     80       1.13     perry int	(*decrypt_input)(int);
     81        1.7   thorpej 
     82        1.7   thorpej int encrypt_debug_mode = 0;
     83        1.7   thorpej static int decrypt_mode = 0;
     84        1.7   thorpej static int encrypt_mode = 0;
     85        1.7   thorpej static int encrypt_verbose = 0;
     86        1.7   thorpej static int autoencrypt = 0;
     87        1.7   thorpej static int autodecrypt = 0;
     88        1.7   thorpej static int havesessionkey = 0;
     89        1.7   thorpej static int Server = 0;
     90        1.7   thorpej static const char *Name = "Noname";
     91        1.7   thorpej 
     92        1.7   thorpej #define	typemask(x)	((x) > 0 ? 1 << ((x)-1) : 0)
     93        1.7   thorpej 
     94        1.7   thorpej static long i_support_encrypt = typemask(ENCTYPE_DES_CFB64)
     95        1.7   thorpej 				| typemask(ENCTYPE_DES_OFB64);
     96        1.7   thorpej static long i_support_decrypt = typemask(ENCTYPE_DES_CFB64)
     97        1.7   thorpej 				| typemask(ENCTYPE_DES_OFB64);
     98        1.7   thorpej static long i_wont_support_encrypt = 0;
     99        1.7   thorpej static long i_wont_support_decrypt = 0;
    100        1.7   thorpej #define	I_SUPPORT_ENCRYPT	(i_support_encrypt & ~i_wont_support_encrypt)
    101        1.7   thorpej #define	I_SUPPORT_DECRYPT	(i_support_decrypt & ~i_wont_support_decrypt)
    102        1.7   thorpej 
    103        1.7   thorpej static long remote_supports_encrypt = 0;
    104        1.7   thorpej static long remote_supports_decrypt = 0;
    105        1.7   thorpej 
    106        1.7   thorpej static Encryptions encryptions[] = {
    107        1.7   thorpej #ifdef	DES_ENCRYPTION
    108        1.7   thorpej     { "DES_CFB64",	ENCTYPE_DES_CFB64,
    109        1.7   thorpej 			cfb64_encrypt,
    110        1.7   thorpej 			cfb64_decrypt,
    111        1.7   thorpej 			cfb64_init,
    112        1.7   thorpej 			cfb64_start,
    113        1.7   thorpej 			cfb64_is,
    114        1.7   thorpej 			cfb64_reply,
    115        1.7   thorpej 			cfb64_session,
    116        1.7   thorpej 			cfb64_keyid,
    117        1.7   thorpej 			cfb64_printsub },
    118        1.7   thorpej     { "DES_OFB64",	ENCTYPE_DES_OFB64,
    119        1.7   thorpej 			ofb64_encrypt,
    120        1.7   thorpej 			ofb64_decrypt,
    121        1.7   thorpej 			ofb64_init,
    122        1.7   thorpej 			ofb64_start,
    123        1.7   thorpej 			ofb64_is,
    124        1.7   thorpej 			ofb64_reply,
    125        1.7   thorpej 			ofb64_session,
    126        1.7   thorpej 			ofb64_keyid,
    127        1.7   thorpej 			ofb64_printsub },
    128        1.7   thorpej #endif	/* DES_ENCRYPTION */
    129        1.7   thorpej     { 0, },
    130        1.7   thorpej };
    131        1.7   thorpej 
    132        1.7   thorpej static unsigned char str_send[64] = { IAC, SB, TELOPT_ENCRYPT,
    133        1.7   thorpej 					 ENCRYPT_SUPPORT };
    134        1.7   thorpej static unsigned char str_suplen = 0;
    135        1.7   thorpej static unsigned char str_start[72] = { IAC, SB, TELOPT_ENCRYPT };
    136        1.7   thorpej static unsigned char str_end[] = { IAC, SB, TELOPT_ENCRYPT, 0, IAC, SE };
    137        1.7   thorpej 
    138        1.7   thorpej 	Encryptions *
    139        1.7   thorpej findencryption(type)
    140        1.7   thorpej 	int type;
    141        1.7   thorpej {
    142        1.7   thorpej 	Encryptions *ep = encryptions;
    143        1.7   thorpej 
    144        1.7   thorpej 	if (!(I_SUPPORT_ENCRYPT & remote_supports_decrypt & typemask(type)))
    145        1.7   thorpej 		return(0);
    146        1.7   thorpej 	while (ep->type && ep->type != type)
    147        1.7   thorpej 		++ep;
    148        1.7   thorpej 	return(ep->type ? ep : 0);
    149        1.7   thorpej }
    150        1.7   thorpej 
    151        1.7   thorpej 	Encryptions *
    152        1.7   thorpej finddecryption(type)
    153        1.7   thorpej 	int type;
    154        1.7   thorpej {
    155        1.7   thorpej 	Encryptions *ep = encryptions;
    156        1.7   thorpej 
    157        1.7   thorpej 	if (!(I_SUPPORT_DECRYPT & remote_supports_encrypt & typemask(type)))
    158        1.7   thorpej 		return(0);
    159        1.7   thorpej 	while (ep->type && ep->type != type)
    160        1.7   thorpej 		++ep;
    161        1.7   thorpej 	return(ep->type ? ep : 0);
    162        1.7   thorpej }
    163        1.7   thorpej 
    164        1.7   thorpej #define	MAXKEYLEN 64
    165        1.7   thorpej 
    166        1.7   thorpej static struct key_info {
    167        1.7   thorpej 	unsigned char keyid[MAXKEYLEN];
    168        1.7   thorpej 	int keylen;
    169        1.7   thorpej 	int dir;
    170        1.7   thorpej 	int *modep;
    171       1.13     perry 	Encryptions *(*getcrypt)(int);
    172        1.7   thorpej } ki[2] = {
    173        1.7   thorpej 	{ { 0 }, 0, DIR_ENCRYPT, &encrypt_mode, findencryption },
    174        1.7   thorpej 	{ { 0 }, 0, DIR_DECRYPT, &decrypt_mode, finddecryption },
    175        1.7   thorpej };
    176        1.7   thorpej 
    177        1.7   thorpej 	void
    178        1.7   thorpej encrypt_init(name, server)
    179        1.7   thorpej 	const char *name;
    180        1.7   thorpej 	int server;
    181        1.7   thorpej {
    182        1.7   thorpej 	Encryptions *ep = encryptions;
    183        1.7   thorpej 
    184        1.7   thorpej 	Name = name;
    185        1.7   thorpej 	Server = server;
    186        1.7   thorpej 	i_support_encrypt = i_support_decrypt = 0;
    187        1.7   thorpej 	remote_supports_encrypt = remote_supports_decrypt = 0;
    188        1.7   thorpej 	encrypt_mode = 0;
    189        1.7   thorpej 	decrypt_mode = 0;
    190        1.7   thorpej 	encrypt_output = 0;
    191        1.7   thorpej 	decrypt_input = 0;
    192        1.7   thorpej #ifdef notdef
    193        1.7   thorpej 	encrypt_verbose = !server;
    194        1.7   thorpej #endif
    195        1.7   thorpej 
    196        1.7   thorpej 	str_suplen = 4;
    197        1.7   thorpej 
    198        1.7   thorpej 	while (ep->type) {
    199        1.7   thorpej 		if (encrypt_debug_mode)
    200        1.7   thorpej 			printf(">>>%s: I will support %s\r\n",
    201        1.7   thorpej 				Name, ENCTYPE_NAME(ep->type));
    202        1.7   thorpej 		i_support_encrypt |= typemask(ep->type);
    203        1.7   thorpej 		i_support_decrypt |= typemask(ep->type);
    204        1.7   thorpej 		if ((i_wont_support_decrypt & typemask(ep->type)) == 0)
    205        1.7   thorpej 			if ((str_send[str_suplen++] = ep->type) == IAC)
    206        1.7   thorpej 				str_send[str_suplen++] = IAC;
    207        1.7   thorpej 		if (ep->init)
    208        1.7   thorpej 			(*ep->init)(Server);
    209        1.7   thorpej 		++ep;
    210        1.7   thorpej 	}
    211        1.7   thorpej 	str_send[str_suplen++] = IAC;
    212        1.7   thorpej 	str_send[str_suplen++] = SE;
    213        1.7   thorpej }
    214        1.7   thorpej 
    215        1.7   thorpej 	void
    216        1.7   thorpej encrypt_list_types()
    217        1.7   thorpej {
    218        1.7   thorpej 	Encryptions *ep = encryptions;
    219        1.7   thorpej 
    220        1.7   thorpej 	printf("Valid encryption types:\n");
    221        1.7   thorpej 	while (ep->type) {
    222        1.7   thorpej 		printf("\t%s (%d)\r\n", ENCTYPE_NAME(ep->type), ep->type);
    223        1.7   thorpej 		++ep;
    224        1.7   thorpej 	}
    225        1.7   thorpej }
    226        1.7   thorpej 
    227        1.7   thorpej 	int
    228        1.7   thorpej EncryptEnable(type, mode)
    229        1.7   thorpej 	char *type, *mode;
    230        1.7   thorpej {
    231        1.7   thorpej 	if (isprefix(type, "help") || isprefix(type, "?")) {
    232        1.7   thorpej 		printf("Usage: encrypt enable <type> [input|output]\n");
    233        1.7   thorpej 		encrypt_list_types();
    234        1.7   thorpej 		return(0);
    235        1.7   thorpej 	}
    236        1.7   thorpej 	if (EncryptType(type, mode))
    237        1.7   thorpej 		return(EncryptStart(mode));
    238        1.7   thorpej 	return(0);
    239        1.7   thorpej }
    240        1.7   thorpej 
    241        1.7   thorpej 	int
    242        1.7   thorpej EncryptDisable(type, mode)
    243        1.7   thorpej 	char *type, *mode;
    244        1.7   thorpej {
    245        1.7   thorpej 	register Encryptions *ep;
    246        1.7   thorpej 	int ret = 0;
    247        1.7   thorpej 
    248        1.7   thorpej 	if (isprefix(type, "help") || isprefix(type, "?")) {
    249        1.7   thorpej 		printf("Usage: encrypt disable <type> [input|output]\n");
    250        1.7   thorpej 		encrypt_list_types();
    251        1.7   thorpej 	} else if ((ep = (Encryptions *)genget(type, (char **)encryptions,
    252        1.7   thorpej 						sizeof(Encryptions))) == 0) {
    253        1.7   thorpej 		printf("%s: invalid encryption type\n", type);
    254        1.7   thorpej 	} else if (Ambiguous(ep)) {
    255        1.7   thorpej 		printf("Ambiguous type '%s'\n", type);
    256        1.7   thorpej 	} else {
    257        1.7   thorpej 		if ((mode == 0) || (isprefix(mode, "input") ? 1 : 0)) {
    258        1.7   thorpej 			if (decrypt_mode == ep->type)
    259        1.7   thorpej 				EncryptStopInput();
    260        1.7   thorpej 			i_wont_support_decrypt |= typemask(ep->type);
    261        1.7   thorpej 			ret = 1;
    262        1.7   thorpej 		}
    263        1.7   thorpej 		if ((mode == 0) || (isprefix(mode, "output"))) {
    264        1.7   thorpej 			if (encrypt_mode == ep->type)
    265        1.7   thorpej 				EncryptStopOutput();
    266        1.7   thorpej 			i_wont_support_encrypt |= typemask(ep->type);
    267        1.7   thorpej 			ret = 1;
    268        1.7   thorpej 		}
    269        1.7   thorpej 		if (ret == 0)
    270        1.7   thorpej 			printf("%s: invalid encryption mode\n", mode);
    271        1.7   thorpej 	}
    272        1.7   thorpej 	return(ret);
    273        1.7   thorpej }
    274        1.7   thorpej 
    275        1.7   thorpej 	int
    276        1.7   thorpej EncryptType(type, mode)
    277        1.7   thorpej 	char *type;
    278        1.7   thorpej 	char *mode;
    279        1.7   thorpej {
    280        1.7   thorpej 	register Encryptions *ep;
    281        1.7   thorpej 	int ret = 0;
    282        1.7   thorpej 
    283        1.7   thorpej 	if (isprefix(type, "help") || isprefix(type, "?")) {
    284        1.7   thorpej 		printf("Usage: encrypt type <type> [input|output]\n");
    285        1.7   thorpej 		encrypt_list_types();
    286        1.7   thorpej 	} else if ((ep = (Encryptions *)genget(type, (char **)encryptions,
    287        1.7   thorpej 						sizeof(Encryptions))) == 0) {
    288        1.7   thorpej 		printf("%s: invalid encryption type\n", type);
    289        1.7   thorpej 	} else if (Ambiguous(ep)) {
    290        1.7   thorpej 		printf("Ambiguous type '%s'\n", type);
    291        1.7   thorpej 	} else {
    292        1.7   thorpej 		if ((mode == 0) || isprefix(mode, "input")) {
    293        1.7   thorpej 			decrypt_mode = ep->type;
    294        1.7   thorpej 			i_wont_support_decrypt &= ~typemask(ep->type);
    295        1.7   thorpej 			ret = 1;
    296        1.7   thorpej 		}
    297        1.7   thorpej 		if ((mode == 0) || isprefix(mode, "output")) {
    298        1.7   thorpej 			encrypt_mode = ep->type;
    299        1.7   thorpej 			i_wont_support_encrypt &= ~typemask(ep->type);
    300        1.7   thorpej 			ret = 1;
    301        1.7   thorpej 		}
    302        1.7   thorpej 		if (ret == 0)
    303        1.7   thorpej 			printf("%s: invalid encryption mode\n", mode);
    304        1.7   thorpej 	}
    305        1.7   thorpej 	return(ret);
    306        1.7   thorpej }
    307        1.7   thorpej 
    308        1.7   thorpej 	int
    309        1.7   thorpej EncryptStart(mode)
    310        1.7   thorpej 	char *mode;
    311        1.7   thorpej {
    312        1.7   thorpej 	register int ret = 0;
    313        1.7   thorpej 	if (mode) {
    314        1.7   thorpej 		if (isprefix(mode, "input"))
    315        1.7   thorpej 			return(EncryptStartInput());
    316        1.7   thorpej 		if (isprefix(mode, "output"))
    317        1.7   thorpej 			return(EncryptStartOutput());
    318        1.7   thorpej 		if (isprefix(mode, "help") || isprefix(mode, "?")) {
    319        1.7   thorpej 			printf("Usage: encrypt start [input|output]\n");
    320        1.7   thorpej 			return(0);
    321        1.7   thorpej 		}
    322        1.7   thorpej 		printf("%s: invalid encryption mode 'encrypt start ?' for help\n", mode);
    323        1.7   thorpej 		return(0);
    324        1.7   thorpej 	}
    325        1.7   thorpej 	ret += EncryptStartInput();
    326        1.7   thorpej 	ret += EncryptStartOutput();
    327        1.7   thorpej 	return(ret);
    328        1.7   thorpej }
    329        1.7   thorpej 
    330        1.7   thorpej 	int
    331        1.7   thorpej EncryptStartInput()
    332        1.7   thorpej {
    333        1.7   thorpej 	if (decrypt_mode) {
    334        1.7   thorpej 		encrypt_send_request_start();
    335        1.7   thorpej 		return(1);
    336        1.7   thorpej 	}
    337        1.7   thorpej 	printf("No previous decryption mode, decryption not enabled\r\n");
    338        1.7   thorpej 	return(0);
    339        1.7   thorpej }
    340        1.7   thorpej 
    341        1.7   thorpej 	int
    342        1.7   thorpej EncryptStartOutput()
    343        1.7   thorpej {
    344        1.7   thorpej 	if (encrypt_mode) {
    345        1.7   thorpej 		encrypt_start_output(encrypt_mode);
    346        1.7   thorpej 		return(1);
    347        1.7   thorpej 	}
    348        1.7   thorpej 	printf("No previous encryption mode, encryption not enabled\r\n");
    349        1.7   thorpej 	return(0);
    350        1.7   thorpej }
    351        1.7   thorpej 
    352        1.7   thorpej 	int
    353        1.7   thorpej EncryptStop(mode)
    354        1.7   thorpej 	char *mode;
    355        1.7   thorpej {
    356        1.7   thorpej 	int ret = 0;
    357        1.7   thorpej 	if (mode) {
    358        1.7   thorpej 		if (isprefix(mode, "input"))
    359        1.7   thorpej 			return(EncryptStopInput());
    360        1.7   thorpej 		if (isprefix(mode, "output"))
    361        1.7   thorpej 			return(EncryptStopOutput());
    362        1.7   thorpej 		if (isprefix(mode, "help") || isprefix(mode, "?")) {
    363        1.7   thorpej 			printf("Usage: encrypt stop [input|output]\n");
    364        1.7   thorpej 			return(0);
    365        1.7   thorpej 		}
    366        1.7   thorpej 		printf("%s: invalid encryption mode 'encrypt stop ?' for help\n", mode);
    367        1.7   thorpej 		return(0);
    368        1.7   thorpej 	}
    369        1.7   thorpej 	ret += EncryptStopInput();
    370        1.7   thorpej 	ret += EncryptStopOutput();
    371        1.7   thorpej 	return(ret);
    372        1.7   thorpej }
    373        1.7   thorpej 
    374        1.7   thorpej 	int
    375        1.7   thorpej EncryptStopInput()
    376        1.7   thorpej {
    377        1.7   thorpej 	encrypt_send_request_end();
    378        1.7   thorpej 	return(1);
    379        1.7   thorpej }
    380        1.7   thorpej 
    381        1.7   thorpej 	int
    382        1.7   thorpej EncryptStopOutput()
    383        1.7   thorpej {
    384        1.7   thorpej 	encrypt_send_end();
    385        1.7   thorpej 	return(1);
    386        1.7   thorpej }
    387        1.7   thorpej 
    388        1.7   thorpej 	void
    389        1.7   thorpej encrypt_display()
    390        1.7   thorpej {
    391        1.7   thorpej 	if (encrypt_output)
    392        1.7   thorpej 		printf("Currently encrypting output with %s\r\n",
    393        1.7   thorpej 			ENCTYPE_NAME(encrypt_mode));
    394        1.7   thorpej 	if (decrypt_input)
    395        1.7   thorpej 		printf("Currently decrypting input with %s\r\n",
    396        1.7   thorpej 			ENCTYPE_NAME(decrypt_mode));
    397        1.7   thorpej }
    398        1.7   thorpej 
    399        1.7   thorpej 	int
    400        1.7   thorpej EncryptStatus()
    401        1.7   thorpej {
    402        1.7   thorpej 	if (encrypt_output)
    403        1.7   thorpej 		printf("Currently encrypting output with %s\r\n",
    404        1.7   thorpej 			ENCTYPE_NAME(encrypt_mode));
    405        1.7   thorpej 	else if (encrypt_mode) {
    406        1.7   thorpej 		printf("Currently output is clear text.\r\n");
    407        1.7   thorpej 		printf("Last encryption mode was %s\r\n",
    408        1.7   thorpej 			ENCTYPE_NAME(encrypt_mode));
    409        1.7   thorpej 	}
    410        1.7   thorpej 	if (decrypt_input) {
    411        1.7   thorpej 		printf("Currently decrypting input with %s\r\n",
    412        1.7   thorpej 			ENCTYPE_NAME(decrypt_mode));
    413        1.7   thorpej 	} else if (decrypt_mode) {
    414        1.7   thorpej 		printf("Currently input is clear text.\r\n");
    415        1.7   thorpej 		printf("Last decryption mode was %s\r\n",
    416        1.7   thorpej 			ENCTYPE_NAME(decrypt_mode));
    417        1.7   thorpej 	}
    418        1.7   thorpej 	return 1;
    419        1.7   thorpej }
    420        1.7   thorpej 
    421        1.7   thorpej 	void
    422        1.7   thorpej encrypt_send_support()
    423        1.7   thorpej {
    424        1.7   thorpej 	if (str_suplen) {
    425        1.7   thorpej 		/*
    426        1.7   thorpej 		 * If the user has requested that decryption start
    427        1.7   thorpej 		 * immediatly, then send a "REQUEST START" before
    428        1.7   thorpej 		 * we negotiate the type.
    429        1.7   thorpej 		 */
    430        1.7   thorpej 		if (!Server && autodecrypt)
    431        1.7   thorpej 			encrypt_send_request_start();
    432        1.7   thorpej 		telnet_net_write(str_send, str_suplen);
    433        1.7   thorpej 		printsub('>', &str_send[2], str_suplen - 2);
    434        1.7   thorpej 		str_suplen = 0;
    435        1.7   thorpej 	}
    436        1.7   thorpej }
    437        1.7   thorpej 
    438        1.7   thorpej 	int
    439        1.7   thorpej EncryptDebug(on)
    440        1.7   thorpej 	int on;
    441        1.7   thorpej {
    442        1.7   thorpej 	if (on < 0)
    443        1.7   thorpej 		encrypt_debug_mode ^= 1;
    444        1.7   thorpej 	else
    445        1.7   thorpej 		encrypt_debug_mode = on;
    446        1.7   thorpej 	printf("Encryption debugging %s\r\n",
    447        1.7   thorpej 		encrypt_debug_mode ? "enabled" : "disabled");
    448        1.7   thorpej 	return(1);
    449        1.7   thorpej }
    450        1.7   thorpej 
    451        1.7   thorpej 	int
    452        1.7   thorpej EncryptVerbose(on)
    453        1.7   thorpej 	int on;
    454        1.7   thorpej {
    455        1.7   thorpej 	if (on < 0)
    456        1.7   thorpej 		encrypt_verbose ^= 1;
    457        1.7   thorpej 	else
    458        1.7   thorpej 		encrypt_verbose = on;
    459        1.7   thorpej 	printf("Encryption %s verbose\r\n",
    460        1.7   thorpej 		encrypt_verbose ? "is" : "is not");
    461        1.7   thorpej 	return(1);
    462        1.7   thorpej }
    463        1.7   thorpej 
    464        1.7   thorpej 	int
    465        1.7   thorpej EncryptAutoEnc(on)
    466        1.7   thorpej 	int on;
    467        1.7   thorpej {
    468        1.7   thorpej 	encrypt_auto(on);
    469        1.7   thorpej 	printf("Automatic encryption of output is %s\r\n",
    470        1.7   thorpej 		autoencrypt ? "enabled" : "disabled");
    471        1.7   thorpej 	return(1);
    472        1.7   thorpej }
    473        1.7   thorpej 
    474        1.7   thorpej 	int
    475        1.7   thorpej EncryptAutoDec(on)
    476        1.7   thorpej 	int on;
    477        1.7   thorpej {
    478        1.7   thorpej 	decrypt_auto(on);
    479        1.7   thorpej 	printf("Automatic decryption of input is %s\r\n",
    480        1.7   thorpej 		autodecrypt ? "enabled" : "disabled");
    481        1.7   thorpej 	return(1);
    482        1.7   thorpej }
    483        1.7   thorpej 
    484        1.7   thorpej /*
    485        1.7   thorpej  * Called when ENCRYPT SUPPORT is received.
    486        1.7   thorpej  */
    487        1.7   thorpej 	void
    488        1.7   thorpej encrypt_support(typelist, cnt)
    489        1.7   thorpej 	unsigned char *typelist;
    490        1.7   thorpej 	int cnt;
    491        1.7   thorpej {
    492        1.7   thorpej 	register int type, use_type = 0;
    493        1.7   thorpej 	Encryptions *ep;
    494        1.7   thorpej 
    495        1.7   thorpej 	/*
    496        1.7   thorpej 	 * Forget anything the other side has previously told us.
    497        1.7   thorpej 	 */
    498        1.7   thorpej 	remote_supports_decrypt = 0;
    499        1.7   thorpej 
    500        1.7   thorpej 	while (cnt-- > 0) {
    501        1.7   thorpej 		type = *typelist++;
    502        1.7   thorpej 		if (encrypt_debug_mode)
    503        1.7   thorpej 			printf(">>>%s: He is supporting %s (%d)\r\n",
    504        1.7   thorpej 				Name,
    505        1.7   thorpej 				ENCTYPE_NAME(type), type);
    506        1.7   thorpej 		if ((type < ENCTYPE_CNT) &&
    507        1.7   thorpej 		    (I_SUPPORT_ENCRYPT & typemask(type))) {
    508        1.7   thorpej 			remote_supports_decrypt |= typemask(type);
    509        1.7   thorpej 			if (use_type == 0)
    510        1.7   thorpej 				use_type = type;
    511        1.7   thorpej 		}
    512        1.7   thorpej 	}
    513        1.7   thorpej 	if (use_type) {
    514        1.7   thorpej 		ep = findencryption(use_type);
    515        1.7   thorpej 		if (!ep)
    516        1.7   thorpej 			return;
    517        1.7   thorpej 		type = ep->start ? (*ep->start)(DIR_ENCRYPT, Server) : 0;
    518        1.7   thorpej 		if (encrypt_debug_mode)
    519        1.7   thorpej 			printf(">>>%s: (*ep->start)() returned %d\r\n",
    520        1.7   thorpej 					Name, type);
    521        1.7   thorpej 		if (type < 0)
    522        1.7   thorpej 			return;
    523        1.7   thorpej 		encrypt_mode = use_type;
    524        1.7   thorpej 		if (type == 0)
    525        1.7   thorpej 			encrypt_start_output(use_type);
    526        1.7   thorpej 	}
    527        1.7   thorpej }
    528        1.7   thorpej 
    529        1.7   thorpej 	void
    530        1.7   thorpej encrypt_is(data, cnt)
    531        1.7   thorpej 	unsigned char *data;
    532        1.7   thorpej 	int cnt;
    533        1.7   thorpej {
    534        1.7   thorpej 	Encryptions *ep;
    535        1.7   thorpej 	register int type, ret;
    536        1.7   thorpej 
    537        1.7   thorpej 	if (--cnt < 0)
    538        1.7   thorpej 		return;
    539        1.7   thorpej 	type = *data++;
    540        1.7   thorpej 	if (type < ENCTYPE_CNT)
    541        1.7   thorpej 		remote_supports_encrypt |= typemask(type);
    542        1.7   thorpej 	if (!(ep = finddecryption(type))) {
    543        1.7   thorpej 		if (encrypt_debug_mode)
    544        1.7   thorpej 			printf(">>>%s: Can't find type %s (%d) for initial negotiation\r\n",
    545        1.7   thorpej 				Name,
    546        1.7   thorpej 				ENCTYPE_NAME_OK(type)
    547        1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    548        1.7   thorpej 				type);
    549        1.7   thorpej 		return;
    550        1.7   thorpej 	}
    551        1.7   thorpej 	if (!ep->is) {
    552        1.7   thorpej 		if (encrypt_debug_mode)
    553        1.7   thorpej 			printf(">>>%s: No initial negotiation needed for type %s (%d)\r\n",
    554        1.7   thorpej 				Name,
    555        1.7   thorpej 				ENCTYPE_NAME_OK(type)
    556        1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    557        1.7   thorpej 				type);
    558        1.7   thorpej 		ret = 0;
    559        1.7   thorpej 	} else {
    560        1.7   thorpej 		ret = (*ep->is)(data, cnt);
    561        1.7   thorpej 		if (encrypt_debug_mode)
    562        1.7   thorpej 			printf("(*ep->is)(%p, %d) returned %s(%d)\n", data, cnt,
    563        1.7   thorpej 				(ret < 0) ? "FAIL " :
    564        1.7   thorpej 				(ret == 0) ? "SUCCESS " : "MORE_TO_DO ", ret);
    565        1.7   thorpej 	}
    566        1.7   thorpej 	if (ret < 0) {
    567        1.7   thorpej 		autodecrypt = 0;
    568        1.7   thorpej 	} else {
    569        1.7   thorpej 		decrypt_mode = type;
    570        1.7   thorpej 		if (ret == 0 && autodecrypt)
    571        1.7   thorpej 			encrypt_send_request_start();
    572        1.7   thorpej 	}
    573        1.7   thorpej }
    574        1.7   thorpej 
    575        1.7   thorpej 	void
    576        1.7   thorpej encrypt_reply(data, cnt)
    577        1.7   thorpej 	unsigned char *data;
    578        1.7   thorpej 	int cnt;
    579        1.7   thorpej {
    580        1.7   thorpej 	Encryptions *ep;
    581        1.7   thorpej 	register int ret, type;
    582        1.7   thorpej 
    583        1.7   thorpej 	if (--cnt < 0)
    584        1.7   thorpej 		return;
    585        1.7   thorpej 	type = *data++;
    586        1.7   thorpej 	if (!(ep = findencryption(type))) {
    587        1.7   thorpej 		if (encrypt_debug_mode)
    588        1.7   thorpej 			printf(">>>%s: Can't find type %s (%d) for initial negotiation\r\n",
    589        1.7   thorpej 				Name,
    590        1.7   thorpej 				ENCTYPE_NAME_OK(type)
    591        1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    592        1.7   thorpej 				type);
    593        1.7   thorpej 		return;
    594        1.7   thorpej 	}
    595        1.7   thorpej 	if (!ep->reply) {
    596        1.7   thorpej 		if (encrypt_debug_mode)
    597        1.7   thorpej 			printf(">>>%s: No initial negotiation needed for type %s (%d)\r\n",
    598        1.7   thorpej 				Name,
    599        1.7   thorpej 				ENCTYPE_NAME_OK(type)
    600        1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    601        1.7   thorpej 				type);
    602        1.7   thorpej 		ret = 0;
    603        1.7   thorpej 	} else {
    604        1.7   thorpej 		ret = (*ep->reply)(data, cnt);
    605        1.7   thorpej 		if (encrypt_debug_mode)
    606        1.7   thorpej 			printf("(*ep->reply)(%p, %d) returned %s(%d)\n",
    607        1.7   thorpej 				data, cnt,
    608        1.7   thorpej 				(ret < 0) ? "FAIL " :
    609        1.7   thorpej 				(ret == 0) ? "SUCCESS " : "MORE_TO_DO ", ret);
    610        1.7   thorpej 	}
    611        1.7   thorpej 	if (encrypt_debug_mode)
    612        1.7   thorpej 		printf(">>>%s: encrypt_reply returned %d\n", Name, ret);
    613        1.7   thorpej 	if (ret < 0) {
    614        1.7   thorpej 		autoencrypt = 0;
    615        1.7   thorpej 	} else {
    616        1.7   thorpej 		encrypt_mode = type;
    617        1.7   thorpej 		if (ret == 0 && autoencrypt)
    618        1.7   thorpej 			encrypt_start_output(type);
    619        1.7   thorpej 	}
    620        1.7   thorpej }
    621        1.7   thorpej 
    622        1.7   thorpej /*
    623        1.7   thorpej  * Called when a ENCRYPT START command is received.
    624        1.7   thorpej  */
    625        1.7   thorpej 	void
    626        1.7   thorpej encrypt_start(data, cnt)
    627        1.7   thorpej 	unsigned char *data;
    628        1.7   thorpej 	int cnt;
    629        1.7   thorpej {
    630        1.7   thorpej 	Encryptions *ep;
    631        1.7   thorpej 
    632        1.7   thorpej 	if (!decrypt_mode) {
    633        1.7   thorpej 		/*
    634        1.7   thorpej 		 * Something is wrong.  We should not get a START
    635        1.7   thorpej 		 * command without having already picked our
    636        1.7   thorpej 		 * decryption scheme.  Send a REQUEST-END to
    637        1.7   thorpej 		 * attempt to clear the channel...
    638        1.7   thorpej 		 */
    639        1.7   thorpej 		printf("%s: Warning, Cannot decrypt input stream!!!\r\n", Name);
    640        1.7   thorpej 		encrypt_send_request_end();
    641        1.7   thorpej 		return;
    642        1.7   thorpej 	}
    643        1.7   thorpej 
    644        1.7   thorpej 	if ((ep = finddecryption(decrypt_mode)) != NULL) {
    645        1.7   thorpej 		decrypt_input = ep->input;
    646        1.7   thorpej 		if (encrypt_verbose)
    647        1.7   thorpej 			printf("[ Input is now decrypted with type %s ]\r\n",
    648        1.7   thorpej 				ENCTYPE_NAME(decrypt_mode));
    649        1.7   thorpej 		if (encrypt_debug_mode)
    650        1.7   thorpej 			printf(">>>%s: Start to decrypt input with type %s\r\n",
    651        1.7   thorpej 				Name, ENCTYPE_NAME(decrypt_mode));
    652        1.7   thorpej 	} else {
    653        1.7   thorpej 		printf("%s: Warning, Cannot decrypt type %s (%d)!!!\r\n",
    654        1.7   thorpej 				Name,
    655        1.7   thorpej 				ENCTYPE_NAME_OK(decrypt_mode)
    656        1.7   thorpej 					? ENCTYPE_NAME(decrypt_mode)
    657        1.7   thorpej 					: "(unknown)",
    658        1.7   thorpej 				decrypt_mode);
    659        1.7   thorpej 		encrypt_send_request_end();
    660        1.7   thorpej 	}
    661        1.7   thorpej }
    662        1.7   thorpej 
    663        1.7   thorpej 	void
    664        1.7   thorpej encrypt_session_key(key, server)
    665        1.7   thorpej 	Session_Key *key;
    666        1.7   thorpej 	int server;
    667        1.7   thorpej {
    668        1.7   thorpej 	Encryptions *ep = encryptions;
    669        1.7   thorpej 
    670        1.7   thorpej 	havesessionkey = 1;
    671        1.7   thorpej 
    672        1.7   thorpej 	while (ep->type) {
    673        1.7   thorpej 		if (ep->session)
    674        1.7   thorpej 			(*ep->session)(key, server);
    675        1.7   thorpej #ifdef notdef
    676        1.7   thorpej 		if (!encrypt_output && autoencrypt && !server)
    677        1.7   thorpej 			encrypt_start_output(ep->type);
    678        1.7   thorpej 		if (!decrypt_input && autodecrypt && !server)
    679        1.7   thorpej 			encrypt_send_request_start();
    680        1.7   thorpej #endif
    681        1.7   thorpej 		++ep;
    682        1.7   thorpej 	}
    683        1.7   thorpej }
    684        1.7   thorpej 
    685        1.7   thorpej /*
    686        1.7   thorpej  * Called when ENCRYPT END is received.
    687        1.7   thorpej  */
    688        1.7   thorpej 	void
    689        1.7   thorpej encrypt_end()
    690        1.7   thorpej {
    691        1.7   thorpej 	decrypt_input = 0;
    692        1.7   thorpej 	if (encrypt_debug_mode)
    693        1.7   thorpej 		printf(">>>%s: Input is back to clear text\r\n", Name);
    694        1.7   thorpej 	if (encrypt_verbose)
    695        1.7   thorpej 		printf("[ Input is now clear text ]\r\n");
    696        1.7   thorpej }
    697        1.7   thorpej 
    698        1.7   thorpej /*
    699        1.7   thorpej  * Called when ENCRYPT REQUEST-END is received.
    700        1.7   thorpej  */
    701        1.7   thorpej 	void
    702        1.7   thorpej encrypt_request_end()
    703        1.7   thorpej {
    704        1.7   thorpej 	encrypt_send_end();
    705        1.7   thorpej }
    706        1.7   thorpej 
    707        1.7   thorpej /*
    708        1.7   thorpej  * Called when ENCRYPT REQUEST-START is received.  If we receive
    709        1.7   thorpej  * this before a type is picked, then that indicates that the
    710        1.7   thorpej  * other side wants us to start encrypting data as soon as we
    711        1.7   thorpej  * can.
    712        1.7   thorpej  */
    713        1.7   thorpej 	void
    714        1.7   thorpej encrypt_request_start(data, cnt)
    715        1.7   thorpej 	unsigned char *data;
    716        1.7   thorpej 	int cnt;
    717        1.7   thorpej {
    718        1.7   thorpej 	if (encrypt_mode == 0)  {
    719        1.7   thorpej 		if (Server)
    720        1.7   thorpej 			autoencrypt = 1;
    721        1.7   thorpej 		return;
    722        1.7   thorpej 	}
    723        1.7   thorpej 	encrypt_start_output(encrypt_mode);
    724        1.7   thorpej }
    725        1.7   thorpej 
    726        1.7   thorpej static unsigned char str_keyid[(MAXKEYLEN*2)+5] = { IAC, SB, TELOPT_ENCRYPT };
    727        1.7   thorpej 
    728        1.7   thorpej 	void
    729        1.7   thorpej encrypt_enc_keyid(keyid, len)
    730        1.7   thorpej 	unsigned char *keyid;
    731        1.7   thorpej 	int len;
    732        1.7   thorpej {
    733        1.7   thorpej 	encrypt_keyid(&ki[1], keyid, len);
    734        1.7   thorpej }
    735        1.7   thorpej 
    736        1.7   thorpej 	void
    737        1.7   thorpej encrypt_dec_keyid(keyid, len)
    738        1.7   thorpej 	unsigned char *keyid;
    739        1.7   thorpej 	int len;
    740        1.7   thorpej {
    741        1.7   thorpej 	encrypt_keyid(&ki[0], keyid, len);
    742        1.7   thorpej }
    743        1.7   thorpej 
    744        1.7   thorpej void
    745        1.7   thorpej encrypt_keyid(kp, keyid, len)
    746        1.7   thorpej 	struct key_info *kp;
    747        1.7   thorpej 	unsigned char *keyid;
    748        1.7   thorpej 	int len;
    749        1.7   thorpej {
    750        1.7   thorpej 	Encryptions *ep;
    751        1.7   thorpej 	int dir = kp->dir;
    752        1.7   thorpej 	register int ret = 0;
    753        1.7   thorpej 
    754        1.7   thorpej 	if (!(ep = (*kp->getcrypt)(*kp->modep))) {
    755        1.7   thorpej 		if (len == 0)
    756        1.7   thorpej 			return;
    757        1.7   thorpej 		kp->keylen = 0;
    758        1.7   thorpej 	} else if (len == 0) {
    759        1.7   thorpej 		/*
    760        1.7   thorpej 		 * Empty option, indicates a failure.
    761        1.7   thorpej 		 */
    762        1.7   thorpej 		if (kp->keylen == 0)
    763        1.7   thorpej 			return;
    764        1.7   thorpej 		kp->keylen = 0;
    765        1.7   thorpej 		if (ep->keyid)
    766        1.7   thorpej 			(void)(*ep->keyid)(dir, kp->keyid, &kp->keylen);
    767        1.7   thorpej 
    768  1.14.18.1       snj 	} else if (len > sizeof(kp->keyid)) {
    769  1.14.18.1       snj 		return;
    770        1.7   thorpej 	} else if ((len != kp->keylen) ||
    771        1.7   thorpej 		   (memcmp(keyid, kp->keyid, len) != 0)) {
    772        1.7   thorpej 		/*
    773        1.7   thorpej 		 * Length or contents are different
    774        1.7   thorpej 		 */
    775        1.7   thorpej 		kp->keylen = len;
    776        1.7   thorpej 		memmove(kp->keyid, keyid, len);
    777        1.7   thorpej 		if (ep->keyid)
    778        1.7   thorpej 			(void)(*ep->keyid)(dir, kp->keyid, &kp->keylen);
    779        1.7   thorpej 	} else {
    780        1.7   thorpej 		if (ep->keyid)
    781        1.7   thorpej 			ret = (*ep->keyid)(dir, kp->keyid, &kp->keylen);
    782        1.7   thorpej 		if ((ret == 0) && (dir == DIR_ENCRYPT) && autoencrypt)
    783        1.7   thorpej 			encrypt_start_output(*kp->modep);
    784        1.7   thorpej 		return;
    785        1.7   thorpej 	}
    786        1.7   thorpej 
    787        1.7   thorpej 	encrypt_send_keyid(dir, kp->keyid, kp->keylen, 0);
    788        1.7   thorpej }
    789        1.7   thorpej 
    790        1.7   thorpej 	void
    791        1.7   thorpej encrypt_send_keyid(dir, keyid, keylen, saveit)
    792        1.7   thorpej 	int dir;
    793        1.7   thorpej 	unsigned char *keyid;
    794        1.7   thorpej 	int keylen;
    795        1.7   thorpej 	int saveit;
    796        1.7   thorpej {
    797        1.7   thorpej 	unsigned char *strp;
    798        1.7   thorpej 
    799        1.7   thorpej 	str_keyid[3] = (dir == DIR_ENCRYPT)
    800        1.7   thorpej 			? ENCRYPT_ENC_KEYID : ENCRYPT_DEC_KEYID;
    801        1.7   thorpej 	if (saveit) {
    802        1.7   thorpej 		struct key_info *kp = &ki[(dir == DIR_ENCRYPT) ? 0 : 1];
    803        1.7   thorpej 		memmove(kp->keyid, keyid, keylen);
    804        1.7   thorpej 		kp->keylen = keylen;
    805        1.7   thorpej 	}
    806        1.7   thorpej 
    807        1.7   thorpej 	for (strp = &str_keyid[4]; keylen > 0; --keylen) {
    808        1.7   thorpej 		if ((*strp++ = *keyid++) == IAC)
    809        1.7   thorpej 			*strp++ = IAC;
    810        1.7   thorpej 	}
    811        1.7   thorpej 	*strp++ = IAC;
    812        1.7   thorpej 	*strp++ = SE;
    813        1.7   thorpej 	telnet_net_write(str_keyid, strp - str_keyid);
    814        1.7   thorpej 	printsub('>', &str_keyid[2], strp - str_keyid - 2);
    815        1.7   thorpej }
    816        1.7   thorpej 
    817        1.7   thorpej 	void
    818        1.7   thorpej encrypt_auto(on)
    819        1.7   thorpej 	int on;
    820        1.7   thorpej {
    821        1.7   thorpej 	if (on < 0)
    822        1.7   thorpej 		autoencrypt ^= 1;
    823        1.7   thorpej 	else
    824        1.7   thorpej 		autoencrypt = on ? 1 : 0;
    825        1.7   thorpej }
    826        1.7   thorpej 
    827        1.7   thorpej 	void
    828        1.7   thorpej decrypt_auto(on)
    829        1.7   thorpej 	int on;
    830        1.7   thorpej {
    831        1.7   thorpej 	if (on < 0)
    832        1.7   thorpej 		autodecrypt ^= 1;
    833        1.7   thorpej 	else
    834        1.7   thorpej 		autodecrypt = on ? 1 : 0;
    835        1.7   thorpej }
    836        1.7   thorpej 
    837        1.7   thorpej 	void
    838        1.7   thorpej encrypt_start_output(type)
    839        1.7   thorpej 	int type;
    840        1.7   thorpej {
    841        1.7   thorpej 	Encryptions *ep;
    842        1.7   thorpej 	register unsigned char *p;
    843        1.7   thorpej 	register int i;
    844        1.7   thorpej 
    845        1.7   thorpej 	if (!(ep = findencryption(type))) {
    846        1.7   thorpej 		if (encrypt_debug_mode) {
    847        1.7   thorpej 			printf(">>>%s: Can't encrypt with type %s (%d)\r\n",
    848        1.7   thorpej 				Name,
    849        1.7   thorpej 				ENCTYPE_NAME_OK(type)
    850        1.7   thorpej 					? ENCTYPE_NAME(type) : "(unknown)",
    851        1.7   thorpej 				type);
    852        1.7   thorpej 		}
    853        1.7   thorpej 		return;
    854        1.7   thorpej 	}
    855        1.7   thorpej 	if (ep->start) {
    856        1.7   thorpej 		i = (*ep->start)(DIR_ENCRYPT, Server);
    857        1.7   thorpej 		if (encrypt_debug_mode) {
    858        1.7   thorpej 			printf(">>>%s: Encrypt start: %s (%d) %s\r\n",
    859        1.7   thorpej 				Name,
    860        1.7   thorpej 				(i < 0) ? "failed" :
    861        1.7   thorpej 					"initial negotiation in progress",
    862        1.7   thorpej 				i, ENCTYPE_NAME(type));
    863        1.7   thorpej 		}
    864        1.7   thorpej 		if (i)
    865        1.7   thorpej 			return;
    866        1.7   thorpej 	}
    867        1.7   thorpej 	p = str_start + 3;
    868        1.7   thorpej 	*p++ = ENCRYPT_START;
    869        1.7   thorpej 	for (i = 0; i < ki[0].keylen; ++i) {
    870        1.7   thorpej 		if ((*p++ = ki[0].keyid[i]) == IAC)
    871        1.7   thorpej 			*p++ = IAC;
    872        1.7   thorpej 	}
    873        1.7   thorpej 	*p++ = IAC;
    874        1.7   thorpej 	*p++ = SE;
    875        1.7   thorpej 	telnet_net_write(str_start, p - str_start);
    876        1.7   thorpej 	net_encrypt();
    877        1.7   thorpej 	printsub('>', &str_start[2], p - &str_start[2]);
    878        1.7   thorpej 	/*
    879        1.7   thorpej 	 * If we are already encrypting in some mode, then
    880        1.7   thorpej 	 * encrypt the ring (which includes our request) in
    881        1.7   thorpej 	 * the old mode, mark it all as "clear text" and then
    882        1.7   thorpej 	 * switch to the new mode.
    883        1.7   thorpej 	 */
    884        1.7   thorpej 	encrypt_output = ep->output;
    885        1.7   thorpej 	encrypt_mode = type;
    886        1.7   thorpej 	if (encrypt_debug_mode)
    887        1.7   thorpej 		printf(">>>%s: Started to encrypt output with type %s\r\n",
    888        1.7   thorpej 			Name, ENCTYPE_NAME(type));
    889        1.7   thorpej 	if (encrypt_verbose)
    890        1.7   thorpej 		printf("[ Output is now encrypted with type %s ]\r\n",
    891        1.7   thorpej 			ENCTYPE_NAME(type));
    892        1.7   thorpej }
    893        1.7   thorpej 
    894        1.7   thorpej 	void
    895        1.7   thorpej encrypt_send_end()
    896        1.7   thorpej {
    897        1.7   thorpej 	if (!encrypt_output)
    898        1.7   thorpej 		return;
    899        1.7   thorpej 
    900        1.7   thorpej 	str_end[3] = ENCRYPT_END;
    901        1.7   thorpej 	telnet_net_write(str_end, sizeof(str_end));
    902        1.7   thorpej 	net_encrypt();
    903        1.7   thorpej 	printsub('>', &str_end[2], sizeof(str_end) - 2);
    904        1.7   thorpej 	/*
    905        1.7   thorpej 	 * Encrypt the output buffer now because it will not be done by
    906        1.7   thorpej 	 * netflush...
    907        1.7   thorpej 	 */
    908        1.7   thorpej 	encrypt_output = 0;
    909        1.7   thorpej 	if (encrypt_debug_mode)
    910        1.7   thorpej 		printf(">>>%s: Output is back to clear text\r\n", Name);
    911        1.7   thorpej 	if (encrypt_verbose)
    912        1.7   thorpej 		printf("[ Output is now clear text ]\r\n");
    913        1.7   thorpej }
    914        1.7   thorpej 
    915        1.7   thorpej 	void
    916        1.7   thorpej encrypt_send_request_start()
    917        1.7   thorpej {
    918        1.7   thorpej 	register unsigned char *p;
    919        1.7   thorpej 	register int i;
    920        1.7   thorpej 
    921        1.7   thorpej 	p = &str_start[3];
    922        1.7   thorpej 	*p++ = ENCRYPT_REQSTART;
    923        1.7   thorpej 	for (i = 0; i < ki[1].keylen; ++i) {
    924        1.7   thorpej 		if ((*p++ = ki[1].keyid[i]) == IAC)
    925        1.7   thorpej 			*p++ = IAC;
    926        1.7   thorpej 	}
    927        1.7   thorpej 	*p++ = IAC;
    928        1.7   thorpej 	*p++ = SE;
    929        1.7   thorpej 	telnet_net_write(str_start, p - str_start);
    930        1.7   thorpej 	printsub('>', &str_start[2], p - &str_start[2]);
    931        1.7   thorpej 	if (encrypt_debug_mode)
    932        1.7   thorpej 		printf(">>>%s: Request input to be encrypted\r\n", Name);
    933        1.7   thorpej }
    934        1.7   thorpej 
    935        1.7   thorpej 	void
    936        1.7   thorpej encrypt_send_request_end()
    937        1.7   thorpej {
    938        1.7   thorpej 	str_end[3] = ENCRYPT_REQEND;
    939        1.7   thorpej 	telnet_net_write(str_end, sizeof(str_end));
    940        1.7   thorpej 	printsub('>', &str_end[2], sizeof(str_end) - 2);
    941        1.7   thorpej 
    942        1.7   thorpej 	if (encrypt_debug_mode)
    943        1.7   thorpej 		printf(">>>%s: Request input to be clear text\r\n", Name);
    944        1.7   thorpej }
    945        1.7   thorpej 
    946        1.7   thorpej 	void
    947        1.7   thorpej encrypt_wait()
    948        1.7   thorpej {
    949        1.7   thorpej 	if (encrypt_debug_mode)
    950        1.7   thorpej 		printf(">>>%s: in encrypt_wait\r\n", Name);
    951        1.7   thorpej 	if (!havesessionkey || !(I_SUPPORT_ENCRYPT & remote_supports_decrypt))
    952        1.7   thorpej 		return;
    953        1.7   thorpej 	while (autoencrypt && !encrypt_output)
    954        1.7   thorpej 		if (telnet_spin())
    955        1.7   thorpej 			return;
    956        1.7   thorpej }
    957        1.7   thorpej 
    958        1.7   thorpej 	void
    959        1.7   thorpej encrypt_debug(mode)
    960        1.7   thorpej 	int mode;
    961        1.7   thorpej {
    962        1.7   thorpej 	encrypt_debug_mode = mode;
    963        1.7   thorpej }
    964        1.7   thorpej 
    965        1.7   thorpej 	void
    966        1.7   thorpej encrypt_gen_printsub(data, cnt, buf, buflen)
    967        1.7   thorpej 	unsigned char *data, *buf;
    968        1.7   thorpej 	int cnt, buflen;
    969        1.7   thorpej {
    970        1.7   thorpej 	char tbuf[16], *cp;
    971        1.7   thorpej 
    972        1.7   thorpej 	cnt -= 2;
    973        1.7   thorpej 	data += 2;
    974        1.7   thorpej 	buf[buflen-1] = '\0';
    975        1.7   thorpej 	buf[buflen-2] = '*';
    976       1.10    simonb 	buflen -= 2;
    977        1.7   thorpej 	for (; cnt > 0; cnt--, data++) {
    978       1.11    itojun 		snprintf(tbuf, sizeof(tbuf), " %d", *data);
    979        1.7   thorpej 		for (cp = tbuf; *cp && buflen > 0; --buflen)
    980        1.7   thorpej 			*buf++ = *cp++;
    981        1.7   thorpej 		if (buflen <= 0)
    982        1.7   thorpej 			return;
    983        1.7   thorpej 	}
    984        1.7   thorpej 	*buf = '\0';
    985        1.7   thorpej }
    986        1.7   thorpej 
    987        1.7   thorpej 	void
    988        1.7   thorpej encrypt_printsub(data, cnt, buf, buflen)
    989        1.7   thorpej 	unsigned char *data, *buf;
    990        1.7   thorpej 	int cnt, buflen;
    991        1.7   thorpej {
    992        1.7   thorpej 	Encryptions *ep;
    993        1.7   thorpej 	register int type = data[1];
    994        1.7   thorpej 
    995        1.7   thorpej 	for (ep = encryptions; ep->type && ep->type != type; ep++)
    996        1.7   thorpej 		;
    997        1.7   thorpej 
    998        1.7   thorpej 	if (ep->printsub)
    999        1.7   thorpej 		(*ep->printsub)(data, cnt, buf, buflen);
   1000        1.7   thorpej 	else
   1001        1.7   thorpej 		encrypt_gen_printsub(data, cnt, buf, buflen);
   1002        1.7   thorpej }
   1003        1.7   thorpej #endif	/* ENCRYPTION */
   1004