]>
Commit | Line | Data |
---|---|---|
700d8687 OM |
1 | /** |
2 | * \file pkcs5.h | |
3 | * | |
4 | * \brief PKCS#5 functions | |
5 | * | |
6 | * \author Mathias Olsson <mathias@kompetensum.com> | |
7 | */ | |
8 | /* | |
9 | * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved | |
10 | * SPDX-License-Identifier: GPL-2.0 | |
11 | * | |
12 | * This program is free software; you can redistribute it and/or modify | |
13 | * it under the terms of the GNU General Public License as published by | |
14 | * the Free Software Foundation; either version 2 of the License, or | |
15 | * (at your option) any later version. | |
16 | * | |
17 | * This program is distributed in the hope that it will be useful, | |
18 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
19 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
20 | * GNU General Public License for more details. | |
21 | * | |
22 | * You should have received a copy of the GNU General Public License along | |
23 | * with this program; if not, write to the Free Software Foundation, Inc., | |
24 | * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. | |
25 | * | |
26 | * This file is part of mbed TLS (https://tls.mbed.org) | |
27 | */ | |
28 | #ifndef MBEDTLS_PKCS5_H | |
29 | #define MBEDTLS_PKCS5_H | |
30 | ||
31 | #include "asn1.h" | |
32 | #include "md.h" | |
33 | ||
34 | #include <stddef.h> | |
35 | #include <stdint.h> | |
36 | ||
37 | #define MBEDTLS_ERR_PKCS5_BAD_INPUT_DATA -0x2f80 /**< Bad input parameters to function. */ | |
38 | #define MBEDTLS_ERR_PKCS5_INVALID_FORMAT -0x2f00 /**< Unexpected ASN.1 data. */ | |
39 | #define MBEDTLS_ERR_PKCS5_FEATURE_UNAVAILABLE -0x2e80 /**< Requested encryption or digest alg not available. */ | |
40 | #define MBEDTLS_ERR_PKCS5_PASSWORD_MISMATCH -0x2e00 /**< Given private key password does not allow for correct decryption. */ | |
41 | ||
42 | #define MBEDTLS_PKCS5_DECRYPT 0 | |
43 | #define MBEDTLS_PKCS5_ENCRYPT 1 | |
44 | ||
45 | #ifdef __cplusplus | |
46 | extern "C" { | |
47 | #endif | |
48 | ||
49 | /** | |
50 | * \brief PKCS#5 PBES2 function | |
51 | * | |
52 | * \param pbe_params the ASN.1 algorithm parameters | |
53 | * \param mode either MBEDTLS_PKCS5_DECRYPT or MBEDTLS_PKCS5_ENCRYPT | |
54 | * \param pwd password to use when generating key | |
55 | * \param pwdlen length of password | |
56 | * \param data data to process | |
57 | * \param datalen length of data | |
58 | * \param output output buffer | |
59 | * | |
60 | * \returns 0 on success, or a MBEDTLS_ERR_XXX code if verification fails. | |
61 | */ | |
62 | int mbedtls_pkcs5_pbes2( const mbedtls_asn1_buf *pbe_params, int mode, | |
63 | const unsigned char *pwd, size_t pwdlen, | |
64 | const unsigned char *data, size_t datalen, | |
65 | unsigned char *output ); | |
66 | ||
67 | /** | |
68 | * \brief PKCS#5 PBKDF2 using HMAC | |
69 | * | |
70 | * \param ctx Generic HMAC context | |
71 | * \param password Password to use when generating key | |
72 | * \param plen Length of password | |
73 | * \param salt Salt to use when generating key | |
74 | * \param slen Length of salt | |
75 | * \param iteration_count Iteration count | |
76 | * \param key_length Length of generated key in bytes | |
77 | * \param output Generated key. Must be at least as big as key_length | |
78 | * | |
79 | * \returns 0 on success, or a MBEDTLS_ERR_XXX code if verification fails. | |
80 | */ | |
81 | int mbedtls_pkcs5_pbkdf2_hmac( mbedtls_md_context_t *ctx, const unsigned char *password, | |
82 | size_t plen, const unsigned char *salt, size_t slen, | |
83 | unsigned int iteration_count, | |
84 | uint32_t key_length, unsigned char *output ); | |
85 | ||
86 | /** | |
87 | * \brief Checkup routine | |
88 | * | |
89 | * \return 0 if successful, or 1 if the test failed | |
90 | */ | |
91 | int mbedtls_pkcs5_self_test( int verbose ); | |
92 | ||
93 | #ifdef __cplusplus | |
94 | } | |
95 | #endif | |
96 | ||
97 | #endif /* pkcs5.h */ |