2000-09-07 16:33:49 +00:00
|
|
|
#include <stdio.h>
|
|
|
|
#include <stdlib.h>
|
|
|
|
|
2000-09-05 14:28:17 +00:00
|
|
|
#include "ssh.h"
|
|
|
|
|
2000-09-07 16:33:49 +00:00
|
|
|
#define GET_32BIT(cp) \
|
|
|
|
(((unsigned long)(unsigned char)(cp)[0] << 24) | \
|
|
|
|
((unsigned long)(unsigned char)(cp)[1] << 16) | \
|
|
|
|
((unsigned long)(unsigned char)(cp)[2] << 8) | \
|
|
|
|
((unsigned long)(unsigned char)(cp)[3]))
|
|
|
|
|
2000-09-27 15:21:04 +00:00
|
|
|
#define PUT_32BIT(cp, value) { \
|
|
|
|
(cp)[0] = (unsigned char)((value) >> 24); \
|
|
|
|
(cp)[1] = (unsigned char)((value) >> 16); \
|
|
|
|
(cp)[2] = (unsigned char)((value) >> 8); \
|
|
|
|
(cp)[3] = (unsigned char)(value); }
|
|
|
|
|
2000-10-23 15:18:37 +00:00
|
|
|
#if 0
|
2000-10-23 16:03:21 +00:00
|
|
|
#define DEBUG_DSS
|
2000-10-23 15:18:37 +00:00
|
|
|
#else
|
|
|
|
#define diagbn(x,y)
|
|
|
|
#endif
|
|
|
|
|
2000-09-07 16:33:49 +00:00
|
|
|
static void getstring(char **data, int *datalen, char **p, int *length) {
|
|
|
|
*p = NULL;
|
|
|
|
if (*datalen < 4)
|
|
|
|
return;
|
|
|
|
*length = GET_32BIT(*data);
|
|
|
|
*datalen -= 4; *data += 4;
|
|
|
|
if (*datalen < *length)
|
|
|
|
return;
|
|
|
|
*p = *data;
|
|
|
|
*data += *length; *datalen -= *length;
|
|
|
|
}
|
|
|
|
static Bignum getmp(char **data, int *datalen) {
|
|
|
|
char *p;
|
2001-03-01 17:41:26 +00:00
|
|
|
int length;
|
2000-09-07 16:33:49 +00:00
|
|
|
Bignum b;
|
|
|
|
|
|
|
|
getstring(data, datalen, &p, &length);
|
|
|
|
if (!p)
|
|
|
|
return NULL;
|
|
|
|
if (p[0] & 0x80)
|
|
|
|
return NULL; /* negative mp */
|
2001-03-01 17:41:26 +00:00
|
|
|
b = bignum_from_bytes(p, length);
|
2000-09-07 16:33:49 +00:00
|
|
|
return b;
|
|
|
|
}
|
|
|
|
|
|
|
|
static Bignum get160(char **data, int *datalen) {
|
|
|
|
Bignum b;
|
|
|
|
|
2001-03-01 17:41:26 +00:00
|
|
|
b = bignum_from_bytes(*data, 20);
|
2000-09-07 16:33:49 +00:00
|
|
|
*data += 20; *datalen -= 20;
|
|
|
|
|
|
|
|
return b;
|
|
|
|
}
|
|
|
|
|
2000-12-02 12:48:15 +00:00
|
|
|
struct dss_key {
|
|
|
|
Bignum p, q, g, y;
|
|
|
|
};
|
2000-09-07 16:33:49 +00:00
|
|
|
|
2000-12-02 12:48:15 +00:00
|
|
|
static void *dss_newkey(char *data, int len) {
|
2000-09-07 16:33:49 +00:00
|
|
|
char *p;
|
|
|
|
int slen;
|
2000-12-02 12:48:15 +00:00
|
|
|
struct dss_key *dss;
|
|
|
|
|
2000-12-12 10:33:13 +00:00
|
|
|
dss = smalloc(sizeof(struct dss_key));
|
2000-12-02 12:48:15 +00:00
|
|
|
if (!dss) return NULL;
|
2000-09-07 16:33:49 +00:00
|
|
|
getstring(&data, &len, &p, &slen);
|
2000-10-23 15:18:37 +00:00
|
|
|
|
|
|
|
#ifdef DEBUG_DSS
|
|
|
|
{
|
|
|
|
int i;
|
|
|
|
printf("key:");
|
|
|
|
for (i=0;i<len;i++)
|
|
|
|
printf(" %02x", (unsigned char)(data[i]));
|
|
|
|
printf("\n");
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
2000-09-07 16:33:49 +00:00
|
|
|
if (!p || memcmp(p, "ssh-dss", 7)) {
|
2000-12-12 10:33:13 +00:00
|
|
|
sfree(dss);
|
2000-12-02 12:48:15 +00:00
|
|
|
return NULL;
|
2000-09-07 16:33:49 +00:00
|
|
|
}
|
2000-12-02 12:48:15 +00:00
|
|
|
dss->p = getmp(&data, &len);
|
|
|
|
dss->q = getmp(&data, &len);
|
|
|
|
dss->g = getmp(&data, &len);
|
|
|
|
dss->y = getmp(&data, &len);
|
|
|
|
|
|
|
|
return dss;
|
2000-09-07 16:33:49 +00:00
|
|
|
}
|
|
|
|
|
2000-12-02 12:48:15 +00:00
|
|
|
static void dss_freekey(void *key) {
|
|
|
|
struct dss_key *dss = (struct dss_key *)key;
|
|
|
|
freebn(dss->p);
|
|
|
|
freebn(dss->q);
|
|
|
|
freebn(dss->g);
|
|
|
|
freebn(dss->y);
|
2000-12-12 10:33:13 +00:00
|
|
|
sfree(dss);
|
2000-12-02 12:48:15 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
static char *dss_fmtkey(void *key) {
|
|
|
|
struct dss_key *dss = (struct dss_key *)key;
|
2000-09-07 16:33:49 +00:00
|
|
|
char *p;
|
2000-09-27 15:21:04 +00:00
|
|
|
int len, i, pos, nibbles;
|
|
|
|
static const char hex[] = "0123456789abcdef";
|
2000-12-02 12:48:15 +00:00
|
|
|
if (!dss->p)
|
2000-09-07 16:33:49 +00:00
|
|
|
return NULL;
|
2000-09-27 15:21:04 +00:00
|
|
|
len = 8 + 4 + 1; /* 4 x "0x", punctuation, \0 */
|
2001-03-01 17:41:26 +00:00
|
|
|
len += 4 * (ssh1_bignum_bitcount(dss->p)+15)/16;
|
|
|
|
len += 4 * (ssh1_bignum_bitcount(dss->q)+15)/16;
|
|
|
|
len += 4 * (ssh1_bignum_bitcount(dss->g)+15)/16;
|
|
|
|
len += 4 * (ssh1_bignum_bitcount(dss->y)+15)/16;
|
2000-12-12 10:33:13 +00:00
|
|
|
p = smalloc(len);
|
2000-09-07 16:33:49 +00:00
|
|
|
if (!p) return NULL;
|
2000-09-27 15:21:04 +00:00
|
|
|
|
|
|
|
pos = 0;
|
|
|
|
pos += sprintf(p+pos, "0x");
|
2000-12-02 12:48:15 +00:00
|
|
|
nibbles = (3 + ssh1_bignum_bitcount(dss->p))/4; if (nibbles<1) nibbles=1;
|
2000-09-27 15:21:04 +00:00
|
|
|
for (i=nibbles; i-- ;)
|
2000-12-02 12:48:15 +00:00
|
|
|
p[pos++] = hex[(bignum_byte(dss->p, i/2) >> (4*(i%2))) & 0xF];
|
2000-09-28 11:05:43 +00:00
|
|
|
pos += sprintf(p+pos, ",0x");
|
2000-12-02 12:48:15 +00:00
|
|
|
nibbles = (3 + ssh1_bignum_bitcount(dss->q))/4; if (nibbles<1) nibbles=1;
|
2000-09-27 15:21:04 +00:00
|
|
|
for (i=nibbles; i-- ;)
|
2000-12-02 12:48:15 +00:00
|
|
|
p[pos++] = hex[(bignum_byte(dss->q, i/2) >> (4*(i%2))) & 0xF];
|
2000-09-28 11:05:43 +00:00
|
|
|
pos += sprintf(p+pos, ",0x");
|
2000-12-02 12:48:15 +00:00
|
|
|
nibbles = (3 + ssh1_bignum_bitcount(dss->g))/4; if (nibbles<1) nibbles=1;
|
2000-09-27 15:21:04 +00:00
|
|
|
for (i=nibbles; i-- ;)
|
2000-12-02 12:48:15 +00:00
|
|
|
p[pos++] = hex[(bignum_byte(dss->g, i/2) >> (4*(i%2))) & 0xF];
|
2000-09-28 11:05:43 +00:00
|
|
|
pos += sprintf(p+pos, ",0x");
|
2000-12-02 12:48:15 +00:00
|
|
|
nibbles = (3 + ssh1_bignum_bitcount(dss->y))/4; if (nibbles<1) nibbles=1;
|
2000-09-27 15:21:04 +00:00
|
|
|
for (i=nibbles; i-- ;)
|
2000-12-02 12:48:15 +00:00
|
|
|
p[pos++] = hex[(bignum_byte(dss->y, i/2) >> (4*(i%2))) & 0xF];
|
2000-09-27 15:21:04 +00:00
|
|
|
p[pos] = '\0';
|
2000-09-07 16:33:49 +00:00
|
|
|
return p;
|
|
|
|
}
|
|
|
|
|
2000-12-02 12:48:15 +00:00
|
|
|
static char *dss_fingerprint(void *key) {
|
|
|
|
struct dss_key *dss = (struct dss_key *)key;
|
2000-09-27 15:21:04 +00:00
|
|
|
struct MD5Context md5c;
|
|
|
|
unsigned char digest[16], lenbuf[4];
|
|
|
|
char buffer[16*3+40];
|
|
|
|
char *ret;
|
|
|
|
int numlen, i;
|
|
|
|
|
|
|
|
MD5Init(&md5c);
|
|
|
|
MD5Update(&md5c, "\0\0\0\7ssh-dss", 11);
|
|
|
|
|
|
|
|
#define ADD_BIGNUM(bignum) \
|
|
|
|
numlen = (ssh1_bignum_bitcount(bignum)+8)/8; \
|
|
|
|
PUT_32BIT(lenbuf, numlen); MD5Update(&md5c, lenbuf, 4); \
|
|
|
|
for (i = numlen; i-- ;) { \
|
|
|
|
unsigned char c = bignum_byte(bignum, i); \
|
|
|
|
MD5Update(&md5c, &c, 1); \
|
|
|
|
}
|
2000-12-02 12:48:15 +00:00
|
|
|
ADD_BIGNUM(dss->p);
|
|
|
|
ADD_BIGNUM(dss->q);
|
|
|
|
ADD_BIGNUM(dss->g);
|
|
|
|
ADD_BIGNUM(dss->y);
|
2000-09-27 15:21:04 +00:00
|
|
|
#undef ADD_BIGNUM
|
|
|
|
|
|
|
|
MD5Final(digest, &md5c);
|
|
|
|
|
2000-12-02 12:48:15 +00:00
|
|
|
sprintf(buffer, "%d ", ssh1_bignum_bitcount(dss->p));
|
2000-09-27 15:21:04 +00:00
|
|
|
for (i = 0; i < 16; i++)
|
|
|
|
sprintf(buffer+strlen(buffer), "%s%02x", i?":":"", digest[i]);
|
2000-12-12 10:33:13 +00:00
|
|
|
ret = smalloc(strlen(buffer)+1);
|
2000-09-27 15:21:04 +00:00
|
|
|
if (ret)
|
|
|
|
strcpy(ret, buffer);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2000-12-02 12:48:15 +00:00
|
|
|
static int dss_verifysig(void *key, char *sig, int siglen,
|
|
|
|
char *data, int datalen) {
|
|
|
|
struct dss_key *dss = (struct dss_key *)key;
|
2000-09-07 16:33:49 +00:00
|
|
|
char *p;
|
2000-10-23 16:03:21 +00:00
|
|
|
int slen;
|
2000-09-07 16:33:49 +00:00
|
|
|
char hash[20];
|
2000-10-23 16:11:31 +00:00
|
|
|
Bignum r, s, w, gu1p, yu2p, gu1yu2p, u1, u2, sha, v;
|
2000-09-07 16:33:49 +00:00
|
|
|
int ret;
|
|
|
|
|
2000-12-02 12:48:15 +00:00
|
|
|
if (!dss->p)
|
2000-09-07 16:33:49 +00:00
|
|
|
return 0;
|
|
|
|
|
2000-10-23 15:18:37 +00:00
|
|
|
#ifdef DEBUG_DSS
|
|
|
|
{
|
|
|
|
int i;
|
|
|
|
printf("sig:");
|
|
|
|
for (i=0;i<siglen;i++)
|
2001-03-01 17:41:26 +00:00
|
|
|
printf(" %02x", (unsigned char)(sig[i]));
|
2000-10-23 15:18:37 +00:00
|
|
|
printf("\n");
|
|
|
|
}
|
|
|
|
#endif
|
2000-10-03 09:05:56 +00:00
|
|
|
/*
|
|
|
|
* Commercial SSH (2.0.13) and OpenSSH disagree over the format
|
|
|
|
* of a DSA signature. OpenSSH is in line with the IETF drafts:
|
|
|
|
* it uses a string "ssh-dss", followed by a 40-byte string
|
|
|
|
* containing two 160-bit integers end-to-end. Commercial SSH
|
|
|
|
* can't be bothered with the header bit, and considers a DSA
|
|
|
|
* signature blob to be _just_ the 40-byte string containing
|
|
|
|
* the two 160-bit integers. We tell them apart by measuring
|
|
|
|
* the length: length 40 means the commercial-SSH bug, anything
|
|
|
|
* else is assumed to be IETF-compliant.
|
|
|
|
*/
|
|
|
|
if (siglen != 40) { /* bug not present; read admin fields */
|
|
|
|
getstring(&sig, &siglen, &p, &slen);
|
|
|
|
if (!p || memcmp(p, "ssh-dss", 7)) {
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
sig += 4, siglen -= 4; /* skip yet another length field */
|
2000-09-07 16:33:49 +00:00
|
|
|
}
|
2000-12-02 12:48:15 +00:00
|
|
|
diagbn("p=", dss->p);
|
|
|
|
diagbn("q=", dss->q);
|
|
|
|
diagbn("g=", dss->g);
|
|
|
|
diagbn("y=", dss->y);
|
2000-09-07 16:33:49 +00:00
|
|
|
r = get160(&sig, &siglen);
|
2000-10-23 15:18:37 +00:00
|
|
|
diagbn("r=", r);
|
2000-09-07 16:33:49 +00:00
|
|
|
s = get160(&sig, &siglen);
|
2000-10-23 15:18:37 +00:00
|
|
|
diagbn("s=", s);
|
2000-09-07 16:33:49 +00:00
|
|
|
if (!r || !s)
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Step 1. w <- s^-1 mod q.
|
|
|
|
*/
|
2000-12-02 12:48:15 +00:00
|
|
|
w = modinv(s, dss->q);
|
2000-10-23 15:18:37 +00:00
|
|
|
diagbn("w=", w);
|
2000-09-07 16:33:49 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Step 2. u1 <- SHA(message) * w mod q.
|
|
|
|
*/
|
|
|
|
SHA_Simple(data, datalen, hash);
|
|
|
|
p = hash; slen = 20; sha = get160(&p, &slen);
|
2000-10-23 15:18:37 +00:00
|
|
|
diagbn("sha=", sha);
|
2000-12-02 12:48:15 +00:00
|
|
|
u1 = modmul(sha, w, dss->q);
|
2000-10-23 15:18:37 +00:00
|
|
|
diagbn("u1=", u1);
|
2000-09-07 16:33:49 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Step 3. u2 <- r * w mod q.
|
|
|
|
*/
|
2000-12-02 12:48:15 +00:00
|
|
|
u2 = modmul(r, w, dss->q);
|
2000-10-23 15:18:37 +00:00
|
|
|
diagbn("u2=", u2);
|
2000-09-07 16:33:49 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Step 4. v <- (g^u1 * y^u2 mod p) mod q.
|
|
|
|
*/
|
2000-12-02 12:48:15 +00:00
|
|
|
gu1p = modpow(dss->g, u1, dss->p);
|
2000-10-23 16:11:31 +00:00
|
|
|
diagbn("gu1p=", gu1p);
|
2000-12-02 12:48:15 +00:00
|
|
|
yu2p = modpow(dss->y, u2, dss->p);
|
2000-10-23 16:11:31 +00:00
|
|
|
diagbn("yu2p=", yu2p);
|
2000-12-02 12:48:15 +00:00
|
|
|
gu1yu2p = modmul(gu1p, yu2p, dss->p);
|
2000-10-23 16:11:31 +00:00
|
|
|
diagbn("gu1yu2p=", gu1yu2p);
|
2000-12-02 12:48:15 +00:00
|
|
|
v = modmul(gu1yu2p, One, dss->q);
|
2000-10-23 15:18:37 +00:00
|
|
|
diagbn("gu1yu2q=v=", v);
|
|
|
|
diagbn("r=", r);
|
2000-09-07 16:33:49 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Step 5. v should now be equal to r.
|
|
|
|
*/
|
|
|
|
|
2000-10-23 16:03:21 +00:00
|
|
|
ret = !bignum_cmp(v, r);
|
2000-09-07 16:33:49 +00:00
|
|
|
|
|
|
|
freebn(w);
|
|
|
|
freebn(sha);
|
2000-10-23 16:11:31 +00:00
|
|
|
freebn(gu1p);
|
|
|
|
freebn(yu2p);
|
|
|
|
freebn(gu1yu2p);
|
2000-09-07 16:33:49 +00:00
|
|
|
freebn(v);
|
|
|
|
freebn(r);
|
|
|
|
freebn(s);
|
|
|
|
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2000-12-02 12:48:15 +00:00
|
|
|
int dss_sign(void *key, char *sig, int siglen,
|
|
|
|
char *data, int datalen) {
|
|
|
|
return 0; /* do nothing */
|
|
|
|
}
|
|
|
|
|
|
|
|
struct ssh_signkey ssh_dss = {
|
|
|
|
dss_newkey,
|
|
|
|
dss_freekey,
|
2000-09-07 16:33:49 +00:00
|
|
|
dss_fmtkey,
|
2000-09-27 15:21:04 +00:00
|
|
|
dss_fingerprint,
|
2000-09-07 16:33:49 +00:00
|
|
|
dss_verifysig,
|
2000-12-02 12:48:15 +00:00
|
|
|
dss_sign,
|
2000-09-27 15:21:04 +00:00
|
|
|
"ssh-dss",
|
|
|
|
"dss"
|
2000-09-05 14:28:17 +00:00
|
|
|
};
|