/* -*-c-*-
*
- * $Id: hmac-def.h,v 1.4 2000/07/15 10:00:58 mdw Exp $
+ * $Id: hmac-def.h,v 1.6 2001/04/03 19:35:45 mdw Exp $
*
* Definitions for HMAC and NMAC
*
/*----- Revision history --------------------------------------------------*
*
* $Log: hmac-def.h,v $
+ * Revision 1.6 2001/04/03 19:35:45 mdw
+ * Support the SSL HMAC variant (untested).
+ *
+ * Revision 1.5 2000/10/15 19:09:20 mdw
+ * Support HMAC mode for hash functions which need to store more state than
+ * the hash output size.
+ *
* Revision 1.4 2000/07/15 10:00:58 mdw
* New generic hash operation for copying hash contexts.
*
\
/* --- Useful constants --- */ \
\
-const octet pre##_mackeysz[] = { KSZ_ANY, PRE##_HASHSZ }; \
+const octet pre##_mackeysz[] = { KSZ_ANY, PRE##_STATESZ }; \
\
/* --- @pre_nmacinit@ --- * \
* \
\
void pre##_nmacinit(pre##_mackey *key, const void *ok, const void *ik) \
{ \
- memcpy(key->ochain, ok, PRE##_HASHSZ); \
- memcpy(key->ichain, ik, PRE##_HASHSZ); \
+ memcpy(key->ochain, ok, PRE##_STATESZ); \
+ memcpy(key->ichain, ik, PRE##_STATESZ); \
key->ocount = key->icount = 0; \
} \
\
BURN(ctx); \
} \
\
+/* --- @pre_sslmacinit@ --- * \
+ * \
+ * Arguments: @pre_mackey *key@ = pointer to MAC key object \
+ * @const void *k@ = pointer to key to use \
+ * @size_t sz@ = size of key data \
+ * \
+ * Returns: --- \
+ * \
+ * Use: Initializes a MAC key for doing hasing using the SSL3 \
+ * variant of HMAC. \
+ */ \
+ \
+void pre##_sslmacinit(pre##_mackey *key, const void *k, size_t sz) \
+{ \
+ int i; \
+ const octet *kbuf = k; \
+ pre##_ctx ctx; \
+ octet buf[PRE##_HASHSZ]; \
+ \
+ if (sz > PRE##_BUFSZ) { \
+ pre##_init(&ctx); \
+ pre##_hash(&ctx, k, sz); \
+ pre##_done(&ctx, buf); \
+ kbuf = buf; \
+ sz = PRE##_HASHSZ; \
+ } \
+ \
+ pre##_init(&ctx); \
+ memcpy(ctx.buf, kbuf, sz); \
+ memset(ctx.buf + sz, 0x5c, PRE##_BUFSZ - sz); \
+ pre##_compress(&ctx, ctx.buf); \
+ pre##_state(&ctx, key->ochain); \
+ \
+ pre##_init(&ctx); \
+ memcpy(ctx.buf, kbuf, sz); \
+ memset(ctx.buf + sz, 0x36, PRE##_BUFSZ - sz); \
+ pre##_compress(&ctx, ctx.buf); \
+ pre##_state(&ctx, key->ichain); \
+ \
+ key->ocount = key->icount = PRE##_BUFSZ; \
+ BURN(ctx); \
+} \
+ \
/* --- @pre_macinit@ --- * \
* \
* Arguments: @pre_macctx *ctx@ = pointer to MAC context block \
\
void pre##_macinit(pre##_macctx *ctx, const pre##_mackey *key) \
{ \
- memcpy(ctx->chain, key->ochain, PRE##_HASHSZ); \
+ memcpy(ctx->chain, key->ochain, PRE##_STATESZ); \
ctx->count = key->ocount; \
pre##_set(&ctx->ctx, key->ichain, key->icount); \
} \
return (&gk->m); \
} \
\
+static gmac *gsslkey(const void *k, size_t sz) \
+{ \
+ gkctx *gk = S_CREATE(gkctx); \
+ gk->m.ops = &gkops; \
+ pre##_sslmacinit(&gk->k, k, sz); \
+ return (&gk->m); \
+} \
+ \
static void ghhash(ghash *h, const void *p, size_t sz) \
{ \
gctx *g = (gctx *)h; \
\
const gcmac pre##_hmac = \
{ #pre "-hmac", PRE##_HASHSZ, pre##_mackeysz, gkey }; \
+const gcmac pre##_sslmac = \
+ { #pre "-sslmac", PRE##_HASHSZ, pre##_mackeysz, gsslkey }; \
static const gmac_ops gkops = { &pre##_hmac, gkinit, gkdestroy }; \
static const gchash gch = { #pre "-hmac", PRE##_HASHSZ, ghinit }; \
static const ghash_ops gops = \