/* -*-c-*-
*
- * $Id: hmac-def.h,v 1.5 2000/10/15 19:09:20 mdw Exp $
+ * $Id: hmac-def.h,v 1.7 2001/04/19 18:24:45 mdw Exp $
*
* Definitions for HMAC and NMAC
*
/*----- Revision history --------------------------------------------------*
*
* $Log: hmac-def.h,v $
+ * Revision 1.7 2001/04/19 18:24:45 mdw
+ * Provide correct key sizes for NMAC, HMAC and SSLMAC.
+ *
+ * Revision 1.6 2001/04/03 19:35:45 mdw
+ * Support the SSL HMAC variant (untested).
+ *
* Revision 1.5 2000/10/15 19:09:20 mdw
* Support HMAC mode for hash functions which need to store more state than
* the hash output size.
\
/* --- Useful constants --- */ \
\
-const octet pre##_mackeysz[] = { KSZ_ANY, PRE##_STATESZ }; \
+const octet pre##_hmackeysz[] = { KSZ_ANY, PRE##_STATESZ }; \
+const octet pre##_sslmackeysz[] = { KSZ_ANY, PRE##_STATESZ }; \
+const octet pre##_nmackeysz[] = { KSZ_SET, 2 * PRE##_STATESZ, 0 }; \
\
/* --- @pre_nmacinit@ --- * \
* \
BURN(ctx); \
} \
\
+/* --- @pre_sslmacinit@ --- * \
+ * \
+ * Arguments: @pre_mackey *key@ = pointer to MAC key object \
+ * @const void *k@ = pointer to key to use \
+ * @size_t sz@ = size of key data \
+ * \
+ * Returns: --- \
+ * \
+ * Use: Initializes a MAC key for doing hasing using the SSL3 \
+ * variant of HMAC. \
+ */ \
+ \
+void pre##_sslmacinit(pre##_mackey *key, const void *k, size_t sz) \
+{ \
+ const octet *kbuf = k; \
+ pre##_ctx ctx; \
+ octet buf[PRE##_HASHSZ]; \
+ \
+ if (sz > PRE##_BUFSZ) { \
+ pre##_init(&ctx); \
+ pre##_hash(&ctx, k, sz); \
+ pre##_done(&ctx, buf); \
+ kbuf = buf; \
+ sz = PRE##_HASHSZ; \
+ } \
+ \
+ pre##_init(&ctx); \
+ memcpy(ctx.buf, kbuf, sz); \
+ memset(ctx.buf + sz, 0x5c, PRE##_BUFSZ - sz); \
+ pre##_compress(&ctx, ctx.buf); \
+ pre##_state(&ctx, key->ochain); \
+ \
+ pre##_init(&ctx); \
+ memcpy(ctx.buf, kbuf, sz); \
+ memset(ctx.buf + sz, 0x36, PRE##_BUFSZ - sz); \
+ pre##_compress(&ctx, ctx.buf); \
+ pre##_state(&ctx, key->ichain); \
+ \
+ key->ocount = key->icount = PRE##_BUFSZ; \
+ BURN(ctx); \
+} \
+ \
/* --- @pre_macinit@ --- * \
* \
* Arguments: @pre_macctx *ctx@ = pointer to MAC context block \
/* --- Generic MAC interface --- */ \
\
static const gmac_ops gkops; \
-static const ghash_ops gops; \
+static const ghash_ops gops, gnops, gsslops; \
\
typedef struct gkctx { \
gmac m; \
+ const ghash_ops *gops; \
pre##_mackey k; \
} gkctx; \
\
{ \
gkctx *gk = (gkctx *)m; \
gctx *g = S_CREATE(gctx); \
- g->h.ops = &gops; \
+ g->h.ops = gk->gops; \
pre##_macinit(&g->c, &gk->k); \
return (&g->h); \
} \
{ \
gkctx *gk = S_CREATE(gkctx); \
gk->m.ops = &gkops; \
+ gk->gops = &gops; \
pre##_hmacinit(&gk->k, k, sz); \
return (&gk->m); \
} \
\
+static gmac *gnkey(const void *k, size_t sz) \
+{ \
+ gkctx *gk = S_CREATE(gkctx); \
+ const octet *kk = k; \
+ assert(keysz(sz, pre##_nmackeysz) == sz); \
+ gk->m.ops = &gkops; \
+ gk->gops = &gnops; \
+ pre##_nmacinit(&gk->k, kk, kk + PRE##_STATESZ); \
+ return (&gk->m); \
+} \
+ \
+static gmac *gsslkey(const void *k, size_t sz) \
+{ \
+ gkctx *gk = S_CREATE(gkctx); \
+ gk->m.ops = &gkops; \
+ gk->gops = &gsslops; \
+ pre##_sslmacinit(&gk->k, k, sz); \
+ return (&gk->m); \
+} \
+ \
static void ghhash(ghash *h, const void *p, size_t sz) \
{ \
gctx *g = (gctx *)h; \
return (0); \
} \
\
+const gcmac pre##_nmac = \
+ { #pre "-nmac", PRE##_HASHSZ, pre##_nmackeysz, gnkey }; \
const gcmac pre##_hmac = \
- { #pre "-hmac", PRE##_HASHSZ, pre##_mackeysz, gkey }; \
+ { #pre "-hmac", PRE##_HASHSZ, pre##_hmackeysz, gkey }; \
+const gcmac pre##_sslmac = \
+ { #pre "-sslmac", PRE##_HASHSZ, pre##_sslmackeysz, gsslkey }; \
static const gmac_ops gkops = { &pre##_hmac, gkinit, gkdestroy }; \
+static const gmac_ops gnkops = { &pre##_nmac, gkinit, gkdestroy }; \
+static const gmac_ops gsslkops = { &pre##_sslmac, gkinit, gkdestroy }; \
static const gchash gch = { #pre "-hmac", PRE##_HASHSZ, ghinit }; \
static const ghash_ops gops = \
{ &gch, ghhash, ghdone, ghdestroy, ghcopy }; \
+static const gchash gnch = { #pre "-nmac", PRE##_HASHSZ, ghinit }; \
+static const ghash_ops gnops = \
+ { &gch, ghhash, ghdone, ghdestroy, ghcopy }; \
+static const gchash gsslch = { #pre "-sslmac", PRE##_HASHSZ, ghinit }; \
+static const ghash_ops gsslops = \
+ { &gch, ghhash, ghdone, ghdestroy, ghcopy }; \
\
HMAC_TEST(PRE, pre)