diff options
Diffstat (limited to 'src/lib/libcrypto/evp/p_verify.c')
-rw-r--r-- | src/lib/libcrypto/evp/p_verify.c | 73 |
1 files changed, 35 insertions, 38 deletions
diff --git a/src/lib/libcrypto/evp/p_verify.c b/src/lib/libcrypto/evp/p_verify.c index c66d63ccf8..3b9b8ab7d6 100644 --- a/src/lib/libcrypto/evp/p_verify.c +++ b/src/lib/libcrypto/evp/p_verify.c | |||
@@ -5,21 +5,21 @@ | |||
5 | * This package is an SSL implementation written | 5 | * This package is an SSL implementation written |
6 | * by Eric Young (eay@cryptsoft.com). | 6 | * by Eric Young (eay@cryptsoft.com). |
7 | * The implementation was written so as to conform with Netscapes SSL. | 7 | * The implementation was written so as to conform with Netscapes SSL. |
8 | * | 8 | * |
9 | * This library is free for commercial and non-commercial use as long as | 9 | * This library is free for commercial and non-commercial use as long as |
10 | * the following conditions are aheared to. The following conditions | 10 | * the following conditions are aheared to. The following conditions |
11 | * apply to all code found in this distribution, be it the RC4, RSA, | 11 | * apply to all code found in this distribution, be it the RC4, RSA, |
12 | * lhash, DES, etc., code; not just the SSL code. The SSL documentation | 12 | * lhash, DES, etc., code; not just the SSL code. The SSL documentation |
13 | * included with this distribution is covered by the same copyright terms | 13 | * included with this distribution is covered by the same copyright terms |
14 | * except that the holder is Tim Hudson (tjh@cryptsoft.com). | 14 | * except that the holder is Tim Hudson (tjh@cryptsoft.com). |
15 | * | 15 | * |
16 | * Copyright remains Eric Young's, and as such any Copyright notices in | 16 | * Copyright remains Eric Young's, and as such any Copyright notices in |
17 | * the code are not to be removed. | 17 | * the code are not to be removed. |
18 | * If this package is used in a product, Eric Young should be given attribution | 18 | * If this package is used in a product, Eric Young should be given attribution |
19 | * as the author of the parts of the library used. | 19 | * as the author of the parts of the library used. |
20 | * This can be in the form of a textual message at program startup or | 20 | * This can be in the form of a textual message at program startup or |
21 | * in documentation (online or textual) provided with the package. | 21 | * in documentation (online or textual) provided with the package. |
22 | * | 22 | * |
23 | * Redistribution and use in source and binary forms, with or without | 23 | * Redistribution and use in source and binary forms, with or without |
24 | * modification, are permitted provided that the following conditions | 24 | * modification, are permitted provided that the following conditions |
25 | * are met: | 25 | * are met: |
@@ -34,10 +34,10 @@ | |||
34 | * Eric Young (eay@cryptsoft.com)" | 34 | * Eric Young (eay@cryptsoft.com)" |
35 | * The word 'cryptographic' can be left out if the rouines from the library | 35 | * The word 'cryptographic' can be left out if the rouines from the library |
36 | * being used are not cryptographic related :-). | 36 | * being used are not cryptographic related :-). |
37 | * 4. If you include any Windows specific code (or a derivative thereof) from | 37 | * 4. If you include any Windows specific code (or a derivative thereof) from |
38 | * the apps directory (application code) you must include an acknowledgement: | 38 | * the apps directory (application code) you must include an acknowledgement: |
39 | * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" | 39 | * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" |
40 | * | 40 | * |
41 | * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND | 41 | * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND |
42 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | 42 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
43 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE | 43 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
@@ -49,7 +49,7 @@ | |||
49 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY | 49 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY |
50 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF | 50 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
51 | * SUCH DAMAGE. | 51 | * SUCH DAMAGE. |
52 | * | 52 | * |
53 | * The licence and distribution terms for any publically available version or | 53 | * The licence and distribution terms for any publically available version or |
54 | * derivative of this code cannot be changed. i.e. this code cannot simply be | 54 | * derivative of this code cannot be changed. i.e. this code cannot simply be |
55 | * copied and put under another distribution licence | 55 | * copied and put under another distribution licence |
@@ -62,24 +62,24 @@ | |||
62 | #include <openssl/objects.h> | 62 | #include <openssl/objects.h> |
63 | #include <openssl/x509.h> | 63 | #include <openssl/x509.h> |
64 | 64 | ||
65 | int EVP_VerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sigbuf, | 65 | int |
66 | unsigned int siglen, EVP_PKEY *pkey) | 66 | EVP_VerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sigbuf, |
67 | { | 67 | unsigned int siglen, EVP_PKEY *pkey) |
68 | { | ||
68 | unsigned char m[EVP_MAX_MD_SIZE]; | 69 | unsigned char m[EVP_MAX_MD_SIZE]; |
69 | unsigned int m_len; | 70 | unsigned int m_len; |
70 | int i = 0,ok = 0,v; | 71 | int i = 0, ok = 0, v; |
71 | EVP_MD_CTX tmp_ctx; | 72 | EVP_MD_CTX tmp_ctx; |
72 | EVP_PKEY_CTX *pkctx = NULL; | 73 | EVP_PKEY_CTX *pkctx = NULL; |
73 | 74 | ||
74 | EVP_MD_CTX_init(&tmp_ctx); | 75 | EVP_MD_CTX_init(&tmp_ctx); |
75 | if (!EVP_MD_CTX_copy_ex(&tmp_ctx,ctx)) | 76 | if (!EVP_MD_CTX_copy_ex(&tmp_ctx, ctx)) |
76 | goto err; | 77 | goto err; |
77 | if (!EVP_DigestFinal_ex(&tmp_ctx,&(m[0]),&m_len)) | 78 | if (!EVP_DigestFinal_ex(&tmp_ctx, &(m[0]), &m_len)) |
78 | goto err; | 79 | goto err; |
79 | EVP_MD_CTX_cleanup(&tmp_ctx); | 80 | EVP_MD_CTX_cleanup(&tmp_ctx); |
80 | 81 | ||
81 | if (ctx->digest->flags & EVP_MD_FLAG_PKEY_METHOD_SIGNATURE) | 82 | if (ctx->digest->flags & EVP_MD_FLAG_PKEY_METHOD_SIGNATURE) { |
82 | { | ||
83 | i = -1; | 83 | i = -1; |
84 | pkctx = EVP_PKEY_CTX_new(pkey, NULL); | 84 | pkctx = EVP_PKEY_CTX_new(pkey, NULL); |
85 | if (!pkctx) | 85 | if (!pkctx) |
@@ -89,33 +89,30 @@ int EVP_VerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sigbuf, | |||
89 | if (EVP_PKEY_CTX_set_signature_md(pkctx, ctx->digest) <= 0) | 89 | if (EVP_PKEY_CTX_set_signature_md(pkctx, ctx->digest) <= 0) |
90 | goto err; | 90 | goto err; |
91 | i = EVP_PKEY_verify(pkctx, sigbuf, siglen, m, m_len); | 91 | i = EVP_PKEY_verify(pkctx, sigbuf, siglen, m, m_len); |
92 | err: | 92 | err: |
93 | EVP_PKEY_CTX_free(pkctx); | 93 | EVP_PKEY_CTX_free(pkctx); |
94 | return i; | 94 | return i; |
95 | } | 95 | } |
96 | 96 | ||
97 | for (i=0; i<4; i++) | 97 | for (i = 0; i < 4; i++) { |
98 | { | 98 | v = ctx->digest->required_pkey_type[i]; |
99 | v=ctx->digest->required_pkey_type[i]; | 99 | if (v == 0) |
100 | if (v == 0) break; | 100 | break; |
101 | if (pkey->type == v) | 101 | if (pkey->type == v) { |
102 | { | 102 | ok = 1; |
103 | ok=1; | ||
104 | break; | 103 | break; |
105 | } | ||
106 | } | ||
107 | if (!ok) | ||
108 | { | ||
109 | EVPerr(EVP_F_EVP_VERIFYFINAL,EVP_R_WRONG_PUBLIC_KEY_TYPE); | ||
110 | return(-1); | ||
111 | } | ||
112 | if (ctx->digest->verify == NULL) | ||
113 | { | ||
114 | EVPerr(EVP_F_EVP_VERIFYFINAL,EVP_R_NO_VERIFY_FUNCTION_CONFIGURED); | ||
115 | return(0); | ||
116 | } | 104 | } |
117 | 105 | } | |
118 | return(ctx->digest->verify(ctx->digest->type,m,m_len, | 106 | if (!ok) { |
119 | sigbuf,siglen,pkey->pkey.ptr)); | 107 | EVPerr(EVP_F_EVP_VERIFYFINAL, EVP_R_WRONG_PUBLIC_KEY_TYPE); |
108 | return (-1); | ||
109 | } | ||
110 | if (ctx->digest->verify == NULL) { | ||
111 | EVPerr(EVP_F_EVP_VERIFYFINAL, | ||
112 | EVP_R_NO_VERIFY_FUNCTION_CONFIGURED); | ||
113 | return (0); | ||
120 | } | 114 | } |
121 | 115 | ||
116 | return(ctx->digest->verify(ctx->digest->type, m, m_len, | ||
117 | sigbuf, siglen, pkey->pkey.ptr)); | ||
118 | } | ||