38 #if defined(POLARSSL_PKCS5_C)
44 #define OID_CMP(oid_str, oid_buf) \
45 ( ( OID_SIZE(oid_str) == (oid_buf)->len ) && \
46 memcmp( (oid_str), (oid_buf)->p, (oid_buf)->len) == 0)
48 static int pkcs5_parse_pbkdf2_params(
unsigned char **p,
49 const unsigned char *end,
111 const unsigned char *pwd,
size_t pwdlen,
112 const unsigned char *data,
size_t datalen,
113 unsigned char *output )
115 int ret, iterations = 0, keylen = 0;
116 unsigned char *p, *end, *end2;
117 asn1_buf kdf_alg_oid, enc_scheme_oid, salt;
119 unsigned char key[32], iv[32];
120 size_t len = 0, olen = 0;
127 end = p + pbe_params->
len;
153 p += kdf_alg_oid.
len;
160 if( ( ret = pkcs5_parse_pbkdf2_params( &p, end2,
161 &salt, &iterations, &keylen,
168 if( md_info == NULL )
182 enc_scheme_oid.
p = p;
183 p += enc_scheme_oid.
len;
185 #if defined(POLARSSL_DES_C)
200 if( cipher_info == NULL )
208 if( len != cipher_info->
iv_size )
211 memcpy( iv, p, len );
213 if( ( ret =
md_init_ctx( &md_ctx, md_info ) ) != 0 )
220 iterations, keylen, key ) ) != 0 )
225 if( ( ret =
cipher_setkey( &cipher_ctx, key, keylen, mode ) ) != 0 )
232 output, &olen ) ) != 0 )
237 if( ( ret =
cipher_finish( &cipher_ctx, output + olen, &olen ) ) != 0 )
244 size_t plen,
const unsigned char *salt,
size_t slen,
245 unsigned int iteration_count,
246 uint32_t key_length,
unsigned char *output )
254 unsigned char *out_p = output;
255 unsigned char counter[4];
257 memset( counter, 0, 4 );
260 if( iteration_count > 0xFFFFFFFF )
279 memcpy( md1, work, md_size );
281 for ( i = 1; i < iteration_count; i++ )
296 for( j = 0; j < md_size; j++ )
300 use_len = ( key_length < md_size ) ? key_length : md_size;
301 memcpy( out_p, work, use_len );
303 key_length -= use_len;
306 for( i = 4; i > 0; i-- )
307 if( ++counter[i - 1] != 0 )
314 #if defined(POLARSSL_SELF_TEST)
320 size_t plen[MAX_TESTS] =
321 { 8, 8, 8, 8, 24, 9 };
323 unsigned char password[MAX_TESTS][32] =
329 "passwordPASSWORDpassword",
333 size_t slen[MAX_TESTS] =
334 { 4, 4, 4, 4, 36, 5 };
336 unsigned char salt[MAX_TESTS][40] =
342 "saltSALTsaltSALTsaltSALTsaltSALTsalt",
346 uint32_t it_cnt[MAX_TESTS] =
347 { 1, 2, 4096, 16777216, 4096, 4096 };
349 uint32_t key_len[MAX_TESTS] =
350 { 20, 20, 20, 20, 25, 16 };
353 unsigned char result_key[MAX_TESTS][32] =
355 { 0x0c, 0x60, 0xc8, 0x0f, 0x96, 0x1f, 0x0e, 0x71,
356 0xf3, 0xa9, 0xb5, 0x24, 0xaf, 0x60, 0x12, 0x06,
357 0x2f, 0xe0, 0x37, 0xa6 },
358 { 0xea, 0x6c, 0x01, 0x4d, 0xc7, 0x2d, 0x6f, 0x8c,
359 0xcd, 0x1e, 0xd9, 0x2a, 0xce, 0x1d, 0x41, 0xf0,
360 0xd8, 0xde, 0x89, 0x57 },
361 { 0x4b, 0x00, 0x79, 0x01, 0xb7, 0x65, 0x48, 0x9a,
362 0xbe, 0xad, 0x49, 0xd9, 0x26, 0xf7, 0x21, 0xd0,
363 0x65, 0xa4, 0x29, 0xc1 },
364 { 0xee, 0xfe, 0x3d, 0x61, 0xcd, 0x4d, 0xa4, 0xe4,
365 0xe9, 0x94, 0x5b, 0x3d, 0x6b, 0xa2, 0x15, 0x8c,
366 0x26, 0x34, 0xe9, 0x84 },
367 { 0x3d, 0x2e, 0xec, 0x4f, 0xe4, 0x1c, 0x84, 0x9b,
368 0x80, 0xc8, 0xd8, 0x36, 0x62, 0xc0, 0xe4, 0x4a,
369 0x8b, 0x29, 0x1a, 0x96, 0x4c, 0xf2, 0xf0, 0x70,
371 { 0x56, 0xfa, 0x6a, 0xa7, 0x55, 0x48, 0x09, 0x9d,
372 0xcc, 0x37, 0xd7, 0xf0, 0x34, 0x25, 0xe0, 0xc3 },
380 unsigned char key[64];
383 if( info_sha1 == NULL )
386 if( ( ret =
md_init_ctx( &sha1_ctx, info_sha1 ) ) != 0 )
389 for( i = 0; i < MAX_TESTS; i++ )
391 printf(
" PBKDF2 (SHA1) #%d: ", i );
394 slen[i], it_cnt[i], key_len[i], key );
396 memcmp( result_key[i], key, key_len[i] ) != 0 )
399 printf(
"failed\n" );
405 printf(
"passed\n" );