Overhaul formatting.
[catacomb-python] / pubkey.c
1 /* -*-c-*-
2 *
3 * Public-key cryptography
4 *
5 * (c) 2004 Straylight/Edgeware
6 */
7
8 /*----- Licensing notice --------------------------------------------------*
9 *
10 * This file is part of the Python interface to Catacomb.
11 *
12 * Catacomb/Python is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU General Public License as published by
14 * the Free Software Foundation; either version 2 of the License, or
15 * (at your option) any later version.
16 *
17 * Catacomb/Python is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20 * GNU General Public License for more details.
21 *
22 * You should have received a copy of the GNU General Public License
23 * along with Catacomb/Python; if not, write to the Free Software Foundation,
24 * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
25 */
26
27 /*----- Header files ------------------------------------------------------*/
28
29 #include "catacomb-python.h"
30
31 /*----- DSA and similar ---------------------------------------------------*/
32
33 typedef struct dsa_pyobj {
34 PyObject_HEAD
35 PyObject *G, *u, *p, *rng, *hash;
36 gdsa d;
37 } dsa_pyobj;
38
39 static PyTypeObject *dsapub_pytype, *dsapriv_pytype;
40 static PyTypeObject *kcdsapub_pytype, *kcdsapriv_pytype;
41 #define DSA_D(o) (&((dsa_pyobj *)(o))->d)
42 #define DSA_G(o) (((dsa_pyobj *)(o))->G)
43 #define DSA_U(o) (((dsa_pyobj *)(o))->u)
44 #define DSA_P(o) (((dsa_pyobj *)(o))->p)
45 #define DSA_RNG(o) (((dsa_pyobj *)(o))->rng)
46 #define DSA_HASH(o) (((dsa_pyobj *)(o))->hash)
47
48 static void dsa_pydealloc(PyObject *me)
49 {
50 dsa_pyobj *g = (dsa_pyobj *)me;
51 Py_DECREF(g->G); Py_DECREF(g->u); Py_DECREF(g->p);
52 Py_DECREF(g->rng); Py_DECREF(g->hash);
53 FREEOBJ(me);
54 }
55
56 static PyObject *dsa_setup(PyTypeObject *ty, PyObject *G, PyObject *u,
57 PyObject *p, PyObject *rng, PyObject *hash)
58 {
59 dsa_pyobj *g;
60
61 g = PyObject_New(dsa_pyobj, ty);
62 if (GROUP_G(G) != GE_G(p) && !group_samep(GROUP_G(G), GE_G(p)))
63 TYERR("public key not from group");
64 if (!u) {
65 g->d.u = 0;
66 u = Py_None;
67 } else if ((g->d.u = getmp(u)) == 0)
68 goto end;
69 g->d.g = GROUP_G(G);
70 g->d.p = GE_X(p);
71 g->d.r = GRAND_R(rng);
72 g->d.h = GCHASH_CH(hash);
73 g->G = G; Py_INCREF(G); g->u = u; Py_INCREF(u); g->p = p; Py_INCREF(p);
74 g->rng = rng; Py_INCREF(rng); g->hash = hash; Py_INCREF(hash);
75 return ((PyObject *)g);
76 end:
77 FREEOBJ(g);
78 return (0);
79 }
80
81 static PyObject *dsapub_pynew(PyTypeObject *ty,
82 PyObject *arg, PyObject *kw)
83 {
84 PyObject *G, *p, *u = 0, *rng = rand_pyobj, *hash = sha_pyobj;
85 PyObject *rc = 0;
86 char *kwlist[] = { "G", "p", "u", "hash", "rng", 0 };
87
88 if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O!|OO!O!:new", kwlist,
89 group_pytype, &G,
90 ge_pytype, &p,
91 &u,
92 gchash_pytype, &hash,
93 grand_pytype, &rng) ||
94 (rc = dsa_setup(dsapub_pytype, G, u, p, rng, hash)) == 0)
95 goto end;
96 end:
97 return (rc);
98 }
99
100 static PyObject *dsameth_beginhash(PyObject *me, PyObject *arg)
101 {
102 if (!PyArg_ParseTuple(arg, ":beginhash")) return (0);
103 return (ghash_pywrap(DSA_HASH(me), gdsa_beginhash(DSA_D(me)), f_freeme));
104 }
105
106 static PyObject *dsameth_endhash(PyObject *me, PyObject *arg)
107 {
108 ghash *h;
109 PyObject *rc;
110 if (!PyArg_ParseTuple(arg, "O&:endhash", convghash, &h)) return (0);
111 gdsa_endhash(DSA_D(me), h);
112 h = GH_COPY(h);
113 rc = bytestring_pywrap(0, GH_CLASS(h)->hashsz);
114 GH_DONE(h, PyString_AS_STRING(rc));
115 GH_DESTROY(h);
116 return (rc);
117 }
118
119 static PyObject *dsameth_sign(PyObject *me, PyObject *arg, PyObject *kw)
120 {
121 gdsa_sig s = GDSA_SIG_INIT;
122 char *p;
123 int n;
124 mp *k = 0;
125 PyObject *rc = 0;
126 char *kwlist[] = { "msg", "k", 0 };
127
128 if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|O&:sign", kwlist,
129 &p, &n, convmp, &k))
130 goto end;
131 if (n != DSA_D(me)->h->hashsz)
132 VALERR("bad message length (doesn't match hash size)");
133 gdsa_sign(DSA_D(me), &s, p, k);
134 rc = Py_BuildValue("(NN)", mp_pywrap(s.r), mp_pywrap(s.s));
135 end:
136 mp_drop(k);
137 return (rc);
138 }
139
140 static PyObject *dsameth_verify(PyObject *me, PyObject *arg)
141 {
142 char *p;
143 int n;
144 gdsa_sig s = GDSA_SIG_INIT;
145 PyObject *rc = 0;
146
147 if (!PyArg_ParseTuple(arg, "s#(O&O&):verify",
148 &p, &n, convmp, &s.r, convmp, &s.s))
149 goto end;
150 if (n != DSA_D(me)->h->hashsz)
151 VALERR("bad message length (doesn't match hash size)");
152 rc = getbool(!gdsa_verify(DSA_D(me), &s, p));
153 end:
154 mp_drop(s.r);
155 mp_drop(s.s);
156 return (rc);
157 }
158
159 static PyObject *dsapriv_pynew(PyTypeObject *ty,
160 PyObject *arg, PyObject *kw)
161 {
162 PyObject *G, *p, *u = Py_None, *rng = rand_pyobj, *hash = sha_pyobj;
163 PyObject *rc = 0;
164 char *kwlist[] = { "G", "p", "u", "hash", "rng", 0 };
165
166 if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O!O|O!O!:new", kwlist,
167 group_pytype, &G,
168 ge_pytype, &p,
169 &u,
170 gchash_pytype, &hash,
171 grand_pytype, &rng) ||
172 (rc = dsa_setup(dsapriv_pytype, G, u, p, rng, hash)) == 0)
173 goto end;
174 end:
175 return (rc);
176 }
177
178 static PyMethodDef dsapub_pymethods[] = {
179 #define METHNAME(name) dsameth_##name
180 METH (beginhash, "D.beginhash() -> hash object")
181 METH (endhash, "D.endhash(H) -> BYTES")
182 METH (verify, "D.verify(MSG, (R, S)) -> true/false")
183 #undef METHNAME
184 { 0 }
185 };
186
187 static PyMethodDef dsapriv_pymethods[] = {
188 #define METHNAME(name) dsameth_##name
189 KWMETH(sign, "D.sign(MSG, k = K) -> R, S")
190 #undef METHNAME
191 { 0 }
192 };
193
194 static PyMemberDef dsapub_pymembers[] = {
195 #define MEMBERSTRUCT dsa_pyobj
196 MEMBER(G, T_OBJECT, READONLY, "D.G -> group to work in")
197 MEMBER(p, T_OBJECT, READONLY, "D.p -> public key (group element")
198 MEMBER(rng, T_OBJECT, READONLY, "D.rng -> random number generator")
199 MEMBER(hash, T_OBJECT, READONLY, "D.hash -> hash class")
200 #undef MEMBERSTRUCT
201 { 0 }
202 };
203
204 static PyMemberDef dsapriv_pymembers[] = {
205 #define MEMBERSTRUCT dsa_pyobj
206 MEMBER(u, T_OBJECT, READONLY, "D.u -> private key (exponent)")
207 #undef MEMBERSTRUCT
208 { 0 }
209 };
210
211 static PyTypeObject dsapub_pytype_skel = {
212 PyObject_HEAD_INIT(0) 0, /* Header */
213 "catacomb.DSAPub", /* @tp_name@ */
214 sizeof(dsa_pyobj), /* @tp_basicsize@ */
215 0, /* @tp_itemsize@ */
216
217 dsa_pydealloc, /* @tp_dealloc@ */
218 0, /* @tp_print@ */
219 0, /* @tp_getattr@ */
220 0, /* @tp_setattr@ */
221 0, /* @tp_compare@ */
222 0, /* @tp_repr@ */
223 0, /* @tp_as_number@ */
224 0, /* @tp_as_sequence@ */
225 0, /* @tp_as_mapping@ */
226 0, /* @tp_hash@ */
227 0, /* @tp_call@ */
228 0, /* @tp_str@ */
229 0, /* @tp_getattro@ */
230 0, /* @tp_setattro@ */
231 0, /* @tp_as_buffer@ */
232 Py_TPFLAGS_DEFAULT | /* @tp_flags@ */
233 Py_TPFLAGS_BASETYPE,
234
235 /* @tp_doc@ */
236 "DSA public key information.",
237
238 0, /* @tp_traverse@ */
239 0, /* @tp_clear@ */
240 0, /* @tp_richcompare@ */
241 0, /* @tp_weaklistoffset@ */
242 0, /* @tp_iter@ */
243 0, /* @tp_iternext@ */
244 dsapub_pymethods, /* @tp_methods@ */
245 dsapub_pymembers, /* @tp_members@ */
246 0, /* @tp_getset@ */
247 0, /* @tp_base@ */
248 0, /* @tp_dict@ */
249 0, /* @tp_descr_get@ */
250 0, /* @tp_descr_set@ */
251 0, /* @tp_dictoffset@ */
252 0, /* @tp_init@ */
253 PyType_GenericAlloc, /* @tp_alloc@ */
254 dsapub_pynew, /* @tp_new@ */
255 0, /* @tp_free@ */
256 0 /* @tp_is_gc@ */
257 };
258
259 static PyTypeObject dsapriv_pytype_skel = {
260 PyObject_HEAD_INIT(0) 0, /* Header */
261 "catacomb.DSAPriv", /* @tp_name@ */
262 sizeof(dsa_pyobj), /* @tp_basicsize@ */
263 0, /* @tp_itemsize@ */
264
265 0, /* @tp_dealloc@ */
266 0, /* @tp_print@ */
267 0, /* @tp_getattr@ */
268 0, /* @tp_setattr@ */
269 0, /* @tp_compare@ */
270 0, /* @tp_repr@ */
271 0, /* @tp_as_number@ */
272 0, /* @tp_as_sequence@ */
273 0, /* @tp_as_mapping@ */
274 0, /* @tp_hash@ */
275 0, /* @tp_call@ */
276 0, /* @tp_str@ */
277 0, /* @tp_getattro@ */
278 0, /* @tp_setattro@ */
279 0, /* @tp_as_buffer@ */
280 Py_TPFLAGS_DEFAULT | /* @tp_flags@ */
281 Py_TPFLAGS_BASETYPE,
282
283 /* @tp_doc@ */
284 "DSA private key information.",
285
286 0, /* @tp_traverse@ */
287 0, /* @tp_clear@ */
288 0, /* @tp_richcompare@ */
289 0, /* @tp_weaklistoffset@ */
290 0, /* @tp_iter@ */
291 0, /* @tp_iternext@ */
292 dsapriv_pymethods, /* @tp_methods@ */
293 dsapriv_pymembers, /* @tp_members@ */
294 0, /* @tp_getset@ */
295 0, /* @tp_base@ */
296 0, /* @tp_dict@ */
297 0, /* @tp_descr_get@ */
298 0, /* @tp_descr_set@ */
299 0, /* @tp_dictoffset@ */
300 0, /* @tp_init@ */
301 PyType_GenericAlloc, /* @tp_alloc@ */
302 dsapriv_pynew, /* @tp_new@ */
303 0, /* @tp_free@ */
304 0 /* @tp_is_gc@ */
305 };
306
307 static PyObject *kcdsapub_pynew(PyTypeObject *ty,
308 PyObject *arg, PyObject *kw)
309 {
310 PyObject *G, *p, *u = 0, *rng = rand_pyobj, *hash = has160_pyobj;
311 PyObject *rc = 0;
312 char *kwlist[] = { "G", "p", "u", "hash", "rng", 0 };
313
314 if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O!O|O!O!:new", kwlist,
315 group_pytype, &G,
316 ge_pytype, &p,
317 &u,
318 gchash_pytype, &hash,
319 grand_pytype, &rng) ||
320 (rc = dsa_setup(kcdsapub_pytype, G, u, p, rng, hash)) == 0)
321 goto end;
322 end:
323 return (rc);
324 }
325
326 static PyObject *kcdsapriv_pynew(PyTypeObject *ty,
327 PyObject *arg, PyObject *kw)
328 {
329 PyObject *G, *p, *u = Py_None, *rng = rand_pyobj, *hash = has160_pyobj;
330 PyObject *rc = 0;
331 char *kwlist[] = { "G", "p", "u", "hash", "rng", 0 };
332
333 if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O!|OO!O!:new", kwlist,
334 group_pytype, &G,
335 ge_pytype, &p,
336 &u,
337 gchash_pytype, &hash,
338 grand_pytype, &rng) ||
339 (rc = dsa_setup(kcdsapriv_pytype, G, u, p, rng, hash)) == 0)
340 goto end;
341 end:
342 return (rc);
343 }
344
345 static PyObject *kcdsameth_beginhash(PyObject *me, PyObject *arg)
346 {
347 if (!PyArg_ParseTuple(arg, ":beginhash")) return (0);
348 return (ghash_pywrap(DSA_HASH(me), gkcdsa_beginhash(DSA_D(me)), f_freeme));
349 }
350
351 static PyObject *kcdsameth_endhash(PyObject *me, PyObject *arg)
352 {
353 ghash *h;
354 PyObject *rc;
355 if (!PyArg_ParseTuple(arg, "O&:endhash", convghash, &h)) return (0);
356 gkcdsa_endhash(DSA_D(me), h);
357 h = GH_COPY(h);
358 rc = bytestring_pywrap(0, GH_CLASS(h)->hashsz);
359 GH_DONE(h, PyString_AS_STRING(rc));
360 GH_DESTROY(h);
361 return (rc);
362 }
363
364 static PyObject *kcdsameth_sign(PyObject *me, PyObject *arg, PyObject *kw)
365 {
366 gkcdsa_sig s = GKCDSA_SIG_INIT;
367 char *p;
368 int n;
369 mp *k = 0;
370 PyObject *r = 0, *rc = 0;
371 char *kwlist[] = { "msg", "k", 0 };
372
373 if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|O&:sign", kwlist,
374 &p, &n, convmp, &k))
375 goto end;
376 if (n != DSA_D(me)->h->hashsz)
377 VALERR("bad message length (doesn't match hash size)");
378 r = bytestring_pywrap(0, DSA_D(me)->h->hashsz);
379 s.r = (octet *)PyString_AS_STRING(r);
380 gkcdsa_sign(DSA_D(me), &s, p, k);
381 rc = Py_BuildValue("(ON)", r, mp_pywrap(s.s));
382 end:
383 Py_XDECREF(r);
384 mp_drop(k);
385 return (rc);
386 }
387
388 static PyObject *kcdsameth_verify(PyObject *me, PyObject *arg)
389 {
390 char *p;
391 int n, rn;
392 gkcdsa_sig s = GKCDSA_SIG_INIT;
393 PyObject *rc = 0;
394
395 if (!PyArg_ParseTuple(arg, "s#(s#O&):verify",
396 &p, &n, &s.r, &rn, convmp, &s.s))
397 goto end;
398 if (n != DSA_D(me)->h->hashsz)
399 VALERR("bad message length (doesn't match hash size)");
400 if (rn != DSA_D(me)->h->hashsz)
401 VALERR("bad signature `r' length (doesn't match hash size)");
402 rc = getbool(!gkcdsa_verify(DSA_D(me), &s, p));
403 end:
404 mp_drop(s.s);
405 return (rc);
406 }
407
408 static PyMethodDef kcdsapub_pymethods[] = {
409 #define METHNAME(name) kcdsameth_##name
410 METH (beginhash, "D.beginhash() -> hash object")
411 METH (endhash, "D.endhash(H) -> BYTES")
412 METH (verify, "D.verify(MSG, (R, S)) -> true/false")
413 #undef METHNAME
414 { 0 }
415 };
416
417 static PyMethodDef kcdsapriv_pymethods[] = {
418 #define METHNAME(name) kcdsameth_##name
419 KWMETH(sign, "D.sign(MSG, k = K) -> R, S")
420 #undef METHNAME
421 { 0 }
422 };
423
424 static PyTypeObject kcdsapub_pytype_skel = {
425 PyObject_HEAD_INIT(0) 0, /* Header */
426 "catacomb.KCDSAPub", /* @tp_name@ */
427 sizeof(dsa_pyobj), /* @tp_basicsize@ */
428 0, /* @tp_itemsize@ */
429
430 dsa_pydealloc, /* @tp_dealloc@ */
431 0, /* @tp_print@ */
432 0, /* @tp_getattr@ */
433 0, /* @tp_setattr@ */
434 0, /* @tp_compare@ */
435 0, /* @tp_repr@ */
436 0, /* @tp_as_number@ */
437 0, /* @tp_as_sequence@ */
438 0, /* @tp_as_mapping@ */
439 0, /* @tp_hash@ */
440 0, /* @tp_call@ */
441 0, /* @tp_str@ */
442 0, /* @tp_getattro@ */
443 0, /* @tp_setattro@ */
444 0, /* @tp_as_buffer@ */
445 Py_TPFLAGS_DEFAULT | /* @tp_flags@ */
446 Py_TPFLAGS_BASETYPE,
447
448 /* @tp_doc@ */
449 "KCDSA public key information.",
450
451 0, /* @tp_traverse@ */
452 0, /* @tp_clear@ */
453 0, /* @tp_richcompare@ */
454 0, /* @tp_weaklistoffset@ */
455 0, /* @tp_iter@ */
456 0, /* @tp_iternext@ */
457 kcdsapub_pymethods, /* @tp_methods@ */
458 dsapub_pymembers, /* @tp_members@ */
459 0, /* @tp_getset@ */
460 0, /* @tp_base@ */
461 0, /* @tp_dict@ */
462 0, /* @tp_descr_get@ */
463 0, /* @tp_descr_set@ */
464 0, /* @tp_dictoffset@ */
465 0, /* @tp_init@ */
466 PyType_GenericAlloc, /* @tp_alloc@ */
467 kcdsapub_pynew, /* @tp_new@ */
468 0, /* @tp_free@ */
469 0 /* @tp_is_gc@ */
470 };
471
472 static PyTypeObject kcdsapriv_pytype_skel = {
473 PyObject_HEAD_INIT(0) 0, /* Header */
474 "catacomb.KCDSAPriv", /* @tp_name@ */
475 sizeof(dsa_pyobj), /* @tp_basicsize@ */
476 0, /* @tp_itemsize@ */
477
478 0, /* @tp_dealloc@ */
479 0, /* @tp_print@ */
480 0, /* @tp_getattr@ */
481 0, /* @tp_setattr@ */
482 0, /* @tp_compare@ */
483 0, /* @tp_repr@ */
484 0, /* @tp_as_number@ */
485 0, /* @tp_as_sequence@ */
486 0, /* @tp_as_mapping@ */
487 0, /* @tp_hash@ */
488 0, /* @tp_call@ */
489 0, /* @tp_str@ */
490 0, /* @tp_getattro@ */
491 0, /* @tp_setattro@ */
492 0, /* @tp_as_buffer@ */
493 Py_TPFLAGS_DEFAULT | /* @tp_flags@ */
494 Py_TPFLAGS_BASETYPE,
495
496 /* @tp_doc@ */
497 "KCDSA private key information.",
498
499 0, /* @tp_traverse@ */
500 0, /* @tp_clear@ */
501 0, /* @tp_richcompare@ */
502 0, /* @tp_weaklistoffset@ */
503 0, /* @tp_iter@ */
504 0, /* @tp_iternext@ */
505 kcdsapriv_pymethods, /* @tp_methods@ */
506 dsapriv_pymembers, /* @tp_members@ */
507 0, /* @tp_getset@ */
508 0, /* @tp_base@ */
509 0, /* @tp_dict@ */
510 0, /* @tp_descr_get@ */
511 0, /* @tp_descr_set@ */
512 0, /* @tp_dictoffset@ */
513 0, /* @tp_init@ */
514 PyType_GenericAlloc, /* @tp_alloc@ */
515 kcdsapriv_pynew, /* @tp_new@ */
516 0, /* @tp_free@ */
517 0 /* @tp_is_gc@ */
518 };
519
520 /*----- RSA ---------------------------------------------------------------*/
521
522 typedef struct rsapub_pyobj {
523 PyObject_HEAD
524 rsa_pub pub;
525 rsa_pubctx pubctx;
526 } rsapub_pyobj;
527
528 #define RSA_PUB(o) (&((rsapub_pyobj *)(o))->pub)
529 #define RSA_PUBCTX(o) (&((rsapub_pyobj *)(o))->pubctx)
530
531 typedef struct rsapriv_pyobj {
532 PyObject_HEAD
533 rsa_pub pub;
534 rsa_pubctx pubctx;
535 rsa_priv priv;
536 rsa_privctx privctx;
537 PyObject *rng;
538 } rsapriv_pyobj;
539
540 #define RSA_PRIV(o) (&((rsapriv_pyobj *)(o))->priv)
541 #define RSA_PRIVCTX(o) (&((rsapriv_pyobj *)(o))->privctx)
542 #define RSA_RNG(o) (((rsapriv_pyobj *)(o))->rng)
543
544 static PyTypeObject *rsapub_pytype, *rsapriv_pytype;
545
546 static PyObject *rsapub_pynew(PyTypeObject *ty,
547 PyObject *arg, PyObject *kw)
548 {
549 rsa_pub rp = { 0 };
550 rsapub_pyobj *o;
551 char *kwlist[] = { "n", "e", 0 };
552
553 if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&O&:new", kwlist,
554 convmp, &rp.n, convmp, &rp.e))
555 goto end;
556 o = (rsapub_pyobj *)ty->tp_alloc(ty, 0);
557 o->pub = rp;
558 rsa_pubcreate(&o->pubctx, &o->pub);
559 return ((PyObject *)o);
560 end:
561 rsa_pubfree(&rp);
562 return (0);
563 }
564
565 static void rsapub_pydealloc(PyObject *me)
566 {
567 rsa_pubdestroy(RSA_PUBCTX(me));
568 rsa_pubfree(RSA_PUB(me));
569 FREEOBJ(me);
570 }
571
572 static PyObject *rsaget_n(PyObject *me, void *hunoz)
573 { return mp_pywrap(MP_COPY(RSA_PUB(me)->n)); }
574
575 static PyObject *rsaget_e(PyObject *me, void *hunoz)
576 { return mp_pywrap(MP_COPY(RSA_PUB(me)->e)); }
577
578 static PyObject *rsameth_pubop(PyObject *me, PyObject *arg)
579 {
580 mp *x = 0;
581 PyObject *rc = 0;
582
583 if (!PyArg_ParseTuple(arg, "O&:pubop", convmp, &x)) goto end;
584 rc = mp_pywrap(rsa_pubop(RSA_PUBCTX(me), MP_NEW, x));
585 end:
586 mp_drop(x);
587 return (rc);
588 }
589
590 static PyObject *rsapriv_dopywrap(PyTypeObject *ty,
591 rsa_priv *rp, PyObject *rng)
592 {
593 rsapriv_pyobj *o;
594
595 o = (rsapriv_pyobj *)ty->tp_alloc(ty, 0);
596 o->priv = *rp;
597 o->pub.n = rp->n;
598 o->pub.e = rp->e;
599 rsa_privcreate(&o->privctx, &o->priv, &rand_global);
600 rsa_pubcreate(&o->pubctx, &o->pub);
601 if (!rng) {
602 rng = Py_None;
603 Py_INCREF(rng);
604 }
605 o->rng = rng;
606 return ((PyObject *)o);
607 }
608
609 PyObject *rsapriv_pywrap(rsa_priv *rp)
610 { return rsapriv_dopywrap(rsapriv_pytype, rp, 0); }
611
612 static PyObject *rsapriv_pynew(PyTypeObject *ty,
613 PyObject *arg, PyObject *kw)
614 {
615 rsa_priv rp = { 0 };
616 PyObject *rng = Py_None;
617 char *kwlist[] =
618 { "n", "e", "d", "p", "q", "dp", "dq", "q_inv", "rng", 0 };
619
620 if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&O&O&O&O&O&O&O&O:new", kwlist,
621 convmp, &rp.n, convmp, &rp.e,
622 convmp, &rp.d,
623 convmp, &rp.p, convmp, &rp.q,
624 convmp, &rp.dp, convmp, &rp.dq,
625 convmp, &rp.q_inv,
626 &rng))
627 goto end;
628 if (rsa_recover(&rp)) VALERR("couldn't construct private key");
629 if (rng != Py_None && !GRAND_PYCHECK(rng))
630 TYERR("not a random number source");
631 Py_INCREF(rng);
632 return (rsapriv_dopywrap(ty, &rp, rng));
633 end:
634 rsa_privfree(&rp);
635 return (0);
636 }
637
638 static void rsapriv_pydealloc(PyObject *me)
639 {
640 RSA_PRIVCTX(me)->r = &rand_global;
641 rsa_privdestroy(RSA_PRIVCTX(me));
642 rsa_privfree(RSA_PRIV(me));
643 Py_DECREF(RSA_RNG(me));
644 FREEOBJ(me);
645 }
646
647 static PyObject *rsaget_d(PyObject *me, void *hunoz)
648 { return mp_pywrap(MP_COPY(RSA_PRIV(me)->d)); }
649
650 static PyObject *rsaget_p(PyObject *me, void *hunoz)
651 { return mp_pywrap(MP_COPY(RSA_PRIV(me)->p)); }
652
653 static PyObject *rsaget_q(PyObject *me, void *hunoz)
654 { return mp_pywrap(MP_COPY(RSA_PRIV(me)->q)); }
655
656 static PyObject *rsaget_dp(PyObject *me, void *hunoz)
657 { return mp_pywrap(MP_COPY(RSA_PRIV(me)->dp)); }
658
659 static PyObject *rsaget_dq(PyObject *me, void *hunoz)
660 { return mp_pywrap(MP_COPY(RSA_PRIV(me)->dq)); }
661
662 static PyObject *rsaget_q_inv(PyObject *me, void *hunoz)
663 { return mp_pywrap(MP_COPY(RSA_PRIV(me)->q_inv)); }
664
665 static PyObject *rsaget_rng(PyObject *me, void *hunoz)
666 { RETURN_OBJ(RSA_RNG(me)); }
667
668 static int rsaset_rng(PyObject *me, PyObject *val, void *hunoz)
669 {
670 int rc = -1;
671 if (!val)
672 val = Py_None;
673 else if (val != Py_None && !GRAND_PYCHECK(val))
674 TYERR("expected grand or None");
675 Py_DECREF(RSA_RNG(me));
676 RSA_RNG(me) = val;
677 Py_INCREF(val);
678 rc = 0;
679 end:
680 return (rc);
681 }
682
683 static PyObject *rsameth_privop(PyObject *me, PyObject *arg, PyObject *kw)
684 {
685 PyObject *rng = RSA_RNG(me);
686 mp *x = 0;
687 PyObject *rc = 0;
688 char *kwlist[] = { "x", "rng", 0 };
689
690 if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|O:privop", kwlist,
691 convmp, &x, &rng))
692 goto end;
693 if (rng != Py_None && !GRAND_PYCHECK(rng))
694 TYERR("not a random number source");
695 RSA_PRIVCTX(me)->r = (rng == Py_None) ? 0 : GRAND_R(rng);
696 rc = mp_pywrap(rsa_privop(RSA_PRIVCTX(me), MP_NEW, x));
697 end:
698 mp_drop(x);
699 return (rc);
700 }
701
702 static PyObject *meth__RSAPriv_generate(PyObject *me,
703 PyObject *arg, PyObject *kw)
704 {
705 grand *r = &rand_global;
706 unsigned nbits;
707 unsigned n = 0;
708 rsa_priv rp;
709 pgev evt = { 0 };
710 char *kwlist[] = { "class", "nbits", "event", "rng", "nsteps", 0 };
711 PyObject *rc = 0;
712
713 if (!PyArg_ParseTupleAndKeywords(arg, kw, "OO&|O&O&O&:generate", kwlist,
714 &me, convuint, &nbits, convpgev, &evt,
715 convgrand, &r, convuint, &n))
716 goto end;
717 if (rsa_gen(&rp, nbits, r, n, evt.proc, evt.ctx))
718 PGENERR;
719 rc = rsapriv_pywrap(&rp);
720 end:
721 droppgev(&evt);
722 return (rc);
723 }
724
725 static PyGetSetDef rsapub_pygetset[] = {
726 #define GETSETNAME(op, name) rsa##op##_##name
727 GET (n, "R.n -> N")
728 GET (e, "R.e -> E")
729 #undef GETSETNAME
730 { 0 }
731 };
732
733 static PyMethodDef rsapub_pymethods[] = {
734 #define METHNAME(name) rsameth_##name
735 METH (pubop, "R.pubop(X) -> X^E (mod N)")
736 #undef METHNAME
737 { 0 }
738 };
739
740 static PyGetSetDef rsapriv_pygetset[] = {
741 #define GETSETNAME(op, name) rsa##op##_##name
742 GET (d, "R.d -> D")
743 GET (p, "R.p -> P")
744 GET (q, "R.q -> Q")
745 GET (dp, "R.dp -> D mod (P - 1)")
746 GET (dq, "R.dq -> D mod (Q - 1)")
747 GET (q_inv, "R.q_inv -> Q^{-1} mod P")
748 GETSET(rng, "R.rng -> random number source for blinding")
749 #undef GETSETNAME
750 { 0 }
751 };
752
753 static PyMethodDef rsapriv_pymethods[] = {
754 #define METHNAME(name) rsameth_##name
755 KWMETH(privop, "R.privop(X, rng = None) -> X^D (mod N)")
756 #undef METHNAME
757 { 0 }
758 };
759
760 static PyTypeObject rsapub_pytype_skel = {
761 PyObject_HEAD_INIT(0) 0, /* Header */
762 "catacomb.RSAPub", /* @tp_name@ */
763 sizeof(rsapub_pyobj), /* @tp_basicsize@ */
764 0, /* @tp_itemsize@ */
765
766 rsapub_pydealloc, /* @tp_dealloc@ */
767 0, /* @tp_print@ */
768 0, /* @tp_getattr@ */
769 0, /* @tp_setattr@ */
770 0, /* @tp_compare@ */
771 0, /* @tp_repr@ */
772 0, /* @tp_as_number@ */
773 0, /* @tp_as_sequence@ */
774 0, /* @tp_as_mapping@ */
775 0, /* @tp_hash@ */
776 0, /* @tp_call@ */
777 0, /* @tp_str@ */
778 0, /* @tp_getattro@ */
779 0, /* @tp_setattro@ */
780 0, /* @tp_as_buffer@ */
781 Py_TPFLAGS_DEFAULT | /* @tp_flags@ */
782 Py_TPFLAGS_BASETYPE,
783
784 /* @tp_doc@ */
785 "RSA public key information.",
786
787 0, /* @tp_traverse@ */
788 0, /* @tp_clear@ */
789 0, /* @tp_richcompare@ */
790 0, /* @tp_weaklistoffset@ */
791 0, /* @tp_iter@ */
792 0, /* @tp_iternext@ */
793 rsapub_pymethods, /* @tp_methods@ */
794 0, /* @tp_members@ */
795 rsapub_pygetset, /* @tp_getset@ */
796 0, /* @tp_base@ */
797 0, /* @tp_dict@ */
798 0, /* @tp_descr_get@ */
799 0, /* @tp_descr_set@ */
800 0, /* @tp_dictoffset@ */
801 0, /* @tp_init@ */
802 PyType_GenericAlloc, /* @tp_alloc@ */
803 rsapub_pynew, /* @tp_new@ */
804 0, /* @tp_free@ */
805 0 /* @tp_is_gc@ */
806 };
807
808 static PyTypeObject rsapriv_pytype_skel = {
809 PyObject_HEAD_INIT(0) 0, /* Header */
810 "catacomb.RSAPriv", /* @tp_name@ */
811 sizeof(rsapriv_pyobj), /* @tp_basicsize@ */
812 0, /* @tp_itemsize@ */
813
814 rsapriv_pydealloc, /* @tp_dealloc@ */
815 0, /* @tp_print@ */
816 0, /* @tp_getattr@ */
817 0, /* @tp_setattr@ */
818 0, /* @tp_compare@ */
819 0, /* @tp_repr@ */
820 0, /* @tp_as_number@ */
821 0, /* @tp_as_sequence@ */
822 0, /* @tp_as_mapping@ */
823 0, /* @tp_hash@ */
824 0, /* @tp_call@ */
825 0, /* @tp_str@ */
826 0, /* @tp_getattro@ */
827 0, /* @tp_setattro@ */
828 0, /* @tp_as_buffer@ */
829 Py_TPFLAGS_DEFAULT | /* @tp_flags@ */
830 Py_TPFLAGS_BASETYPE,
831
832 /* @tp_doc@ */
833 "RSA private key information.",
834
835 0, /* @tp_traverse@ */
836 0, /* @tp_clear@ */
837 0, /* @tp_richcompare@ */
838 0, /* @tp_weaklistoffset@ */
839 0, /* @tp_iter@ */
840 0, /* @tp_iternext@ */
841 rsapriv_pymethods, /* @tp_methods@ */
842 0, /* @tp_members@ */
843 rsapriv_pygetset, /* @tp_getset@ */
844 0, /* @tp_base@ */
845 0, /* @tp_dict@ */
846 0, /* @tp_descr_get@ */
847 0, /* @tp_descr_set@ */
848 0, /* @tp_dictoffset@ */
849 0, /* @tp_init@ */
850 PyType_GenericAlloc, /* @tp_alloc@ */
851 rsapriv_pynew, /* @tp_new@ */
852 0, /* @tp_free@ */
853 0 /* @tp_is_gc@ */
854 };
855
856 /*----- RSA padding schemes -----------------------------------------------*/
857
858 static PyObject *meth__p1crypt_encode(PyObject *me,
859 PyObject *arg, PyObject *kw)
860 {
861 pkcs1 p1;
862 char *m, *ep;
863 int msz, epsz;
864 unsigned long nbits;
865 PyObject *rc = 0;
866 octet *b = 0;
867 size_t sz;
868 mp *x;
869 char *kwlist[] = { "msg", "nbits", "ep", "rng", 0 };
870
871 p1.r = &rand_global; ep = 0; epsz = 0;
872 if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&|s#O&:encode", kwlist,
873 &m, &msz, convulong, &nbits,
874 &ep, &epsz, convgrand, &p1.r))
875 goto end;
876 sz = (nbits + 7)/8;
877 p1.ep = ep; p1.epsz = epsz;
878 if (epsz + msz + 11 > sz) VALERR("buffer underflow");
879 b = xmalloc(sz);
880 x = pkcs1_cryptencode(MP_NEW, m, msz, b, sz, nbits, &p1);
881 rc = mp_pywrap(x);
882 end:
883 xfree(b);
884 return (rc);
885 }
886
887 static PyObject *meth__p1crypt_decode(PyObject *me,
888 PyObject *arg, PyObject *kw)
889 {
890 pkcs1 p1;
891 char *ep;
892 int epsz;
893 unsigned long nbits;
894 int n;
895 PyObject *rc = 0;
896 octet *b = 0;
897 size_t sz;
898 mp *x = 0;
899 char *kwlist[] = { "ct", "nbits", "ep", "rng", 0 };
900
901 p1.r = &rand_global; ep = 0; epsz = 0;
902 if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&O&|s#O&:decode", kwlist,
903 convmp, &x, convulong, &nbits,
904 &ep, &epsz, convgrand, &p1.r))
905 goto end;
906 sz = (nbits + 7)/8;
907 p1.ep = ep; p1.epsz = epsz;
908 if (epsz + 11 > sz) VALERR("buffer underflow");
909 b = xmalloc(sz);
910 if ((n = pkcs1_cryptdecode(x, b, sz, nbits, &p1)) < 0)
911 VALERR("decryption failed");
912 rc = bytestring_pywrap(b, n);
913 end:
914 mp_drop(x);
915 xfree(b);
916 return (rc);
917 }
918
919 static PyObject *meth__p1sig_encode(PyObject *me,
920 PyObject *arg, PyObject *kw)
921 {
922 pkcs1 p1;
923 char *m, *ep;
924 int msz, epsz;
925 unsigned long nbits;
926 PyObject *rc = 0;
927 octet *b = 0;
928 size_t sz;
929 mp *x;
930 char *kwlist[] = { "msg", "nbits", "ep", "rng", 0 };
931
932 p1.r = &rand_global; ep = 0; epsz = 0;
933 if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&|s#O&:encode", kwlist,
934 &m, &msz, convulong, &nbits,
935 &ep, &epsz, convgrand, &p1.r))
936 goto end;
937 sz = (nbits + 7)/8;
938 p1.ep = ep; p1.epsz = epsz;
939 if (epsz + msz + 11 > sz) VALERR("buffer underflow");
940 b = xmalloc(sz);
941 x = pkcs1_sigencode(MP_NEW, m, msz, b, sz, nbits, &p1);
942 rc = mp_pywrap(x);
943 end:
944 xfree(b);
945 return (rc);
946 }
947
948 static PyObject *meth__p1sig_decode(PyObject *me,
949 PyObject *arg, PyObject *kw)
950 {
951 pkcs1 p1;
952 char *ep;
953 int epsz;
954 unsigned long nbits;
955 int n;
956 PyObject *hukairz;
957 PyObject *rc = 0;
958 octet *b = 0;
959 size_t sz;
960 mp *x = 0;
961 char *kwlist[] = { "msg", "sig", "nbits", "ep", "rng", 0 };
962
963 p1.r = &rand_global; ep = 0; epsz = 0;
964 if (!PyArg_ParseTupleAndKeywords(arg, kw, "OO&O&|s#O&:decode", kwlist,
965 &hukairz, convmp, &x, convulong, &nbits,
966 &ep, &epsz, convgrand, &p1.r))
967 goto end;
968 sz = (nbits + 7)/8;
969 p1.ep = ep; p1.epsz = epsz;
970 if (epsz + 10 > sz) VALERR("buffer underflow");
971 b = xmalloc(sz);
972 if ((n = pkcs1_sigdecode(x, 0, 0, b, sz, nbits, &p1)) < 0)
973 VALERR("verification failed");
974 rc = bytestring_pywrap(b, n);
975 end:
976 mp_drop(x);
977 xfree(b);
978 return (rc);
979 }
980
981 static PyObject *meth__oaep_encode(PyObject *me,
982 PyObject *arg, PyObject *kw)
983 {
984 oaep o;
985 char *m, *ep;
986 int msz, epsz;
987 unsigned long nbits;
988 PyObject *rc = 0;
989 octet *b = 0;
990 size_t sz;
991 mp *x;
992 char *kwlist[] = { "msg", "nbits", "mgf", "hash", "ep", "rng", 0 };
993
994 o.r = &rand_global; o.cc = &sha_mgf; o.ch = &sha; ep = 0; epsz = 0;
995 if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&|O&O&s#O&:encode", kwlist,
996 &m, &msz, convulong, &nbits,
997 convgccipher, &o.cc,
998 convgchash, &o.ch,
999 &ep, &epsz,
1000 convgrand, &o.r))
1001 goto end;
1002 sz = (nbits + 7)/8;
1003 o.ep = ep; o.epsz = epsz;
1004 if (2 * o.ch->hashsz + 2 + msz > sz) VALERR("buffer underflow");
1005 b = xmalloc(sz);
1006 x = oaep_encode(MP_NEW, m, msz, b, sz, nbits, &o);
1007 rc = mp_pywrap(x);
1008 end:
1009 xfree(b);
1010 return (rc);
1011 }
1012
1013 static PyObject *meth__oaep_decode(PyObject *me,
1014 PyObject *arg, PyObject *kw)
1015 {
1016 oaep o;
1017 char *ep;
1018 int epsz;
1019 unsigned long nbits;
1020 int n;
1021 PyObject *rc = 0;
1022 octet *b = 0;
1023 size_t sz;
1024 mp *x = 0;
1025 char *kwlist[] = { "ct", "nbits", "mgf", "hash", "ep", "rng", 0 };
1026
1027 o.r = &rand_global; o.cc = &sha_mgf; o.ch = &sha; ep = 0; epsz = 0;
1028 if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&O&|O&O&s#O&:decode", kwlist,
1029 convmp, &x, convulong, &nbits,
1030 convgccipher, &o.cc,
1031 convgchash, &o.ch,
1032 &ep, &epsz,
1033 convgrand, &o.r))
1034 goto end;
1035 sz = (nbits + 7)/8;
1036 o.ep = ep; o.epsz = epsz;
1037 if (2 * o.ch->hashsz > sz) VALERR("buffer underflow");
1038 b = xmalloc(sz);
1039 if ((n = oaep_decode(x, b, sz, nbits, &o)) < 0)
1040 VALERR("decryption failed");
1041 rc = bytestring_pywrap(b, n);
1042 end:
1043 mp_drop(x);
1044 xfree(b);
1045 return (rc);
1046 }
1047
1048 static PyObject *meth__pss_encode(PyObject *me,
1049 PyObject *arg, PyObject *kw)
1050 {
1051 pss p;
1052 char *m;
1053 int msz;
1054 unsigned long nbits;
1055 PyObject *rc = 0;
1056 octet *b = 0;
1057 size_t sz;
1058 mp *x = 0;
1059 char *kwlist[] = { "msg", "nbits", "mgf", "hash", "saltsz", "rng", 0 };
1060
1061 p.cc = &sha_mgf; p.ch = &sha; p.r = &rand_global; p.ssz = (size_t)-1;
1062 if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&|O&O&O&O&:encode", kwlist,
1063 &m, &msz, convulong, &nbits,
1064 convgccipher, &p.cc,
1065 convgchash, &p.ch,
1066 convszt, &p.ssz,
1067 convgrand, &p.r))
1068 goto end;
1069 sz = (nbits + 7)/8;
1070 if (p.ssz == (size_t)-1) p.ssz = p.ch->hashsz;
1071 if (p.ch->hashsz + p.ssz + 2 > sz) VALERR("buffer underflow");
1072 b = xmalloc(sz);
1073 x = pss_encode(MP_NEW, m, msz, b, sz, nbits, &p);
1074 rc = mp_pywrap(x);
1075 end:
1076 xfree(b);
1077 return (rc);
1078 }
1079
1080 static PyObject *meth__pss_decode(PyObject *me,
1081 PyObject *arg, PyObject *kw)
1082 {
1083 pss p;
1084 char *m;
1085 int msz;
1086 unsigned long nbits;
1087 PyObject *rc = 0;
1088 octet *b = 0;
1089 size_t sz;
1090 int n;
1091 mp *x = 0;
1092 char *kwlist[] =
1093 { "msg", "sig", "nbits", "mgf", "hash", "saltsz", "rng", 0 };
1094
1095 p.cc = &sha_mgf; p.ch = &sha; p.r = &rand_global; p.ssz = (size_t)-1;
1096 if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#O&O&|O&O&O&O&:decode", kwlist,
1097 &m, &msz, convmp, &x, convulong, &nbits,
1098 convgccipher, &p.cc,
1099 convgchash, &p.ch,
1100 convszt, &p.ssz,
1101 convgrand, &p.r))
1102 goto end;
1103 sz = (nbits + 7)/8;
1104 if (p.ssz == (size_t)-1) p.ssz = p.ch->hashsz;
1105 if (p.ch->hashsz + p.ssz + 2 > sz) VALERR("buffer underflow");
1106 b = xmalloc(sz);
1107 if ((n = pss_decode(x, m, msz, b, sz, nbits, &p)) < 0)
1108 VALERR("verification failed");
1109 rc = Py_None; Py_INCREF(rc);
1110 end:
1111 mp_drop(x);
1112 xfree(b);
1113 return (rc);
1114 }
1115
1116 /*----- Global stuff ------------------------------------------------------*/
1117
1118 static PyMethodDef methods[] = {
1119 #define METHNAME(name) meth_##name
1120 KWMETH(_p1crypt_encode, 0)
1121 KWMETH(_p1crypt_decode, 0)
1122 KWMETH(_p1sig_encode, 0)
1123 KWMETH(_p1sig_decode, 0)
1124 KWMETH(_oaep_encode, 0)
1125 KWMETH(_oaep_decode, 0)
1126 KWMETH(_pss_encode, 0)
1127 KWMETH(_pss_decode, 0)
1128 KWMETH(_RSAPriv_generate, "\
1129 generate(NBITS, [event = pgen_nullev, rng = rand, nsteps = 0]) -> R")
1130 #undef METHNAME
1131 { 0 }
1132 };
1133
1134 void pubkey_pyinit(void)
1135 {
1136 INITTYPE(dsapub, root);
1137 INITTYPE(dsapriv, dsapub);
1138 INITTYPE(kcdsapub, root);
1139 INITTYPE(kcdsapriv, kcdsapub);
1140 INITTYPE(rsapub, root);
1141 INITTYPE(rsapriv, rsapub);
1142 addmethods(methods);
1143 }
1144
1145 void pubkey_pyinsert(PyObject *mod)
1146 {
1147 INSERT("DSAPub", dsapub_pytype);
1148 INSERT("DSAPriv", dsapriv_pytype);
1149 INSERT("KCDSAPub", kcdsapub_pytype);
1150 INSERT("KCDSAPriv", kcdsapriv_pytype);
1151 INSERT("RSAPub", rsapub_pytype);
1152 INSERT("RSAPriv", rsapriv_pytype);
1153 }
1154
1155 /*----- That's all, folks -------------------------------------------------*/