1# This file is part of Scapy
2# Copyright (C) 2007, 2008, 2009 Arnaud Ebalard
3#               2015, 2016, 2017 Maxence Tury
4# This program is published under a GPLv2 license
5
6"""
7This is a register for DH groups from RFC 3526 and RFC 4306.
8At this time the groups from RFC 7919 have not been registered by openssl,
9thus they cannot be imported from the cryptography library.
10
11We also provide TLS identifiers for these DH groups and also the ECDH groups.
12(Note that the equivalent of _ffdh_groups for ECDH is ec._CURVE_TYPES.)
13"""
14
15from __future__ import absolute_import
16
17from scapy.config import conf
18from scapy.error import warning
19from scapy.utils import long_converter
20import scapy.modules.six as six
21if conf.crypto_valid:
22    from cryptography.hazmat.backends import default_backend
23    from cryptography.hazmat.primitives.asymmetric import dh, ec
24    from cryptography.hazmat.primitives import serialization
25if conf.crypto_valid_advanced:
26    from cryptography.hazmat.primitives.asymmetric import x25519
27    from cryptography.hazmat.primitives.asymmetric import x448
28
29# We have to start by a dirty hack in order to allow long generators,
30# which some versions of openssl love to use...
31
32if conf.crypto_valid:
33    from cryptography.hazmat.primitives.asymmetric.dh import DHParameterNumbers
34
35    try:
36        # We test with dummy values whether the size limitation has been removed.  # noqa: E501
37        pn_test = DHParameterNumbers(2, 7)
38    except ValueError:
39        # We get rid of the limitation through the cryptography v1.9 __init__.
40
41        def DHParameterNumbers__init__hack(self, p, g, q=None):
42            if (
43                not isinstance(p, six.integer_types) or
44                not isinstance(g, six.integer_types)
45            ):
46                raise TypeError("p and g must be integers")
47            if q is not None and not isinstance(q, six.integer_types):
48                raise TypeError("q must be integer or None")
49
50            self._p = p
51            self._g = g
52            self._q = q
53
54        DHParameterNumbers.__init__ = DHParameterNumbers__init__hack
55
56    # End of hack.
57
58
59_ffdh_groups = {}
60
61
62class _FFDHParamsMetaclass(type):
63    def __new__(cls, ffdh_name, bases, dct):
64        the_class = super(_FFDHParamsMetaclass, cls).__new__(cls, ffdh_name,
65                                                             bases, dct)
66        if conf.crypto_valid and ffdh_name != "_FFDHParams":
67            pn = DHParameterNumbers(the_class.m, the_class.g)
68            params = pn.parameters(default_backend())
69            _ffdh_groups[ffdh_name] = [params, the_class.mLen]
70        return the_class
71
72
73class _FFDHParams(six.with_metaclass(_FFDHParamsMetaclass)):
74    pass
75
76
77class modp768(_FFDHParams):
78    g = 0x02
79    m = long_converter("""
80    FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 29024E08
81    8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD EF9519B3 CD3A431B
82    302B0A6D F25F1437 4FE1356D 6D51C245 E485B576 625E7EC6 F44C42E9
83    A63A3620 FFFFFFFF FFFFFFFF""")
84    mLen = 768
85
86
87class modp1024(_FFDHParams):  # From RFC 4306
88    g = 0x02
89    m = long_converter("""
90    FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 29024E08
91    8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD EF9519B3 CD3A431B
92    302B0A6D F25F1437 4FE1356D 6D51C245 E485B576 625E7EC6 F44C42E9
93    A637ED6B 0BFF5CB6 F406B7ED EE386BFB 5A899FA5 AE9F2411 7C4B1FE6
94    49286651 ECE65381 FFFFFFFF FFFFFFFF""")
95    mLen = 1024
96
97
98class modp1536(_FFDHParams):  # From RFC 3526
99    g = 0x02
100    m = long_converter("""
101    FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1
102    29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD
103    EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245
104    E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED
105    EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D
106    C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F
107    83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D
108    670C354E 4ABC9804 F1746C08 CA237327 FFFFFFFF FFFFFFFF""")
109    mLen = 1536
110
111
112class modp2048(_FFDHParams):  # From RFC 3526
113    g = 0x02
114    m = long_converter("""
115    FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1
116    29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD
117    EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245
118    E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED
119    EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D
120    C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F
121    83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D
122    670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B
123    E39E772C 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9
124    DE2BCBF6 95581718 3995497C EA956AE5 15D22618 98FA0510
125    15728E5A 8AACAA68 FFFFFFFF FFFFFFFF""")
126    mLen = 2048
127
128
129class modp3072(_FFDHParams):  # From RFC 3526
130    g = 0x02
131    m = long_converter("""
132    FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1
133    29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD
134    EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245
135    E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED
136    EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D
137    C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F
138    83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D
139    670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B
140    E39E772C 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9
141    DE2BCBF6 95581718 3995497C EA956AE5 15D22618 98FA0510
142    15728E5A 8AAAC42D AD33170D 04507A33 A85521AB DF1CBA64
143    ECFB8504 58DBEF0A 8AEA7157 5D060C7D B3970F85 A6E1E4C7
144    ABF5AE8C DB0933D7 1E8C94E0 4A25619D CEE3D226 1AD2EE6B
145    F12FFA06 D98A0864 D8760273 3EC86A64 521F2B18 177B200C
146    BBE11757 7A615D6C 770988C0 BAD946E2 08E24FA0 74E5AB31
147    43DB5BFC E0FD108E 4B82D120 A93AD2CA FFFFFFFF FFFFFFFF""")
148    mLen = 3072
149
150
151class modp4096(_FFDHParams):  # From RFC 3526
152    g = 0x02
153    m = long_converter("""
154    FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1
155    29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD
156    EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245
157    E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED
158    EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D
159    C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F
160    83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D
161    670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B
162    E39E772C 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9
163    DE2BCBF6 95581718 3995497C EA956AE5 15D22618 98FA0510
164    15728E5A 8AAAC42D AD33170D 04507A33 A85521AB DF1CBA64
165    ECFB8504 58DBEF0A 8AEA7157 5D060C7D B3970F85 A6E1E4C7
166    ABF5AE8C DB0933D7 1E8C94E0 4A25619D CEE3D226 1AD2EE6B
167    F12FFA06 D98A0864 D8760273 3EC86A64 521F2B18 177B200C
168    BBE11757 7A615D6C 770988C0 BAD946E2 08E24FA0 74E5AB31
169    43DB5BFC E0FD108E 4B82D120 A9210801 1A723C12 A787E6D7
170    88719A10 BDBA5B26 99C32718 6AF4E23C 1A946834 B6150BDA
171    2583E9CA 2AD44CE8 DBBBC2DB 04DE8EF9 2E8EFC14 1FBECAA6
172    287C5947 4E6BC05D 99B2964F A090C3A2 233BA186 515BE7ED
173    1F612970 CEE2D7AF B81BDD76 2170481C D0069127 D5B05AA9
174    93B4EA98 8D8FDDC1 86FFB7DC 90A6C08F 4DF435C9 34063199
175    FFFFFFFF FFFFFFFF""")
176    mLen = 4096
177
178
179class modp6144(_FFDHParams):  # From RFC 3526
180    g = 0x02
181    m = long_converter("""
182    FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1 29024E08
183    8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD EF9519B3 CD3A431B
184    302B0A6D F25F1437 4FE1356D 6D51C245 E485B576 625E7EC6 F44C42E9
185    A637ED6B 0BFF5CB6 F406B7ED EE386BFB 5A899FA5 AE9F2411 7C4B1FE6
186    49286651 ECE45B3D C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8
187    FD24CF5F 83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D
188    670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B E39E772C
189    180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9 DE2BCBF6 95581718
190    3995497C EA956AE5 15D22618 98FA0510 15728E5A 8AAAC42D AD33170D
191    04507A33 A85521AB DF1CBA64 ECFB8504 58DBEF0A 8AEA7157 5D060C7D
192    B3970F85 A6E1E4C7 ABF5AE8C DB0933D7 1E8C94E0 4A25619D CEE3D226
193    1AD2EE6B F12FFA06 D98A0864 D8760273 3EC86A64 521F2B18 177B200C
194    BBE11757 7A615D6C 770988C0 BAD946E2 08E24FA0 74E5AB31 43DB5BFC
195    E0FD108E 4B82D120 A9210801 1A723C12 A787E6D7 88719A10 BDBA5B26
196    99C32718 6AF4E23C 1A946834 B6150BDA 2583E9CA 2AD44CE8 DBBBC2DB
197    04DE8EF9 2E8EFC14 1FBECAA6 287C5947 4E6BC05D 99B2964F A090C3A2
198    233BA186 515BE7ED 1F612970 CEE2D7AF B81BDD76 2170481C D0069127
199    D5B05AA9 93B4EA98 8D8FDDC1 86FFB7DC 90A6C08F 4DF435C9 34028492
200    36C3FAB4 D27C7026 C1D4DCB2 602646DE C9751E76 3DBA37BD F8FF9406
201    AD9E530E E5DB382F 413001AE B06A53ED 9027D831 179727B0 865A8918
202    DA3EDBEB CF9B14ED 44CE6CBA CED4BB1B DB7F1447 E6CC254B 33205151
203    2BD7AF42 6FB8F401 378CD2BF 5983CA01 C64B92EC F032EA15 D1721D03
204    F482D7CE 6E74FEF6 D55E702F 46980C82 B5A84031 900B1C9E 59E7C97F
205    BEC7E8F3 23A97A7E 36CC88BE 0F1D45B7 FF585AC5 4BD407B2 2B4154AA
206    CC8F6D7E BF48E1D8 14CC5ED2 0F8037E0 A79715EE F29BE328 06A1D58B
207    B7C5DA76 F550AA3D 8A1FBFF0 EB19CCB1 A313D55C DA56C9EC 2EF29632
208    387FE8D7 6E3C0468 043E8F66 3F4860EE 12BF2D5B 0B7474D6 E694F91E
209    6DCC4024 FFFFFFFF FFFFFFFF""")
210    mLen = 6144
211
212
213class modp8192(_FFDHParams):  # From RFC 3526
214    g = 0x02
215    m = long_converter("""
216    FFFFFFFF FFFFFFFF C90FDAA2 2168C234 C4C6628B 80DC1CD1
217    29024E08 8A67CC74 020BBEA6 3B139B22 514A0879 8E3404DD
218    EF9519B3 CD3A431B 302B0A6D F25F1437 4FE1356D 6D51C245
219    E485B576 625E7EC6 F44C42E9 A637ED6B 0BFF5CB6 F406B7ED
220    EE386BFB 5A899FA5 AE9F2411 7C4B1FE6 49286651 ECE45B3D
221    C2007CB8 A163BF05 98DA4836 1C55D39A 69163FA8 FD24CF5F
222    83655D23 DCA3AD96 1C62F356 208552BB 9ED52907 7096966D
223    670C354E 4ABC9804 F1746C08 CA18217C 32905E46 2E36CE3B
224    E39E772C 180E8603 9B2783A2 EC07A28F B5C55DF0 6F4C52C9
225    DE2BCBF6 95581718 3995497C EA956AE5 15D22618 98FA0510
226    15728E5A 8AAAC42D AD33170D 04507A33 A85521AB DF1CBA64
227    ECFB8504 58DBEF0A 8AEA7157 5D060C7D B3970F85 A6E1E4C7
228    ABF5AE8C DB0933D7 1E8C94E0 4A25619D CEE3D226 1AD2EE6B
229    F12FFA06 D98A0864 D8760273 3EC86A64 521F2B18 177B200C
230    BBE11757 7A615D6C 770988C0 BAD946E2 08E24FA0 74E5AB31
231    43DB5BFC E0FD108E 4B82D120 A9210801 1A723C12 A787E6D7
232    88719A10 BDBA5B26 99C32718 6AF4E23C 1A946834 B6150BDA
233    2583E9CA 2AD44CE8 DBBBC2DB 04DE8EF9 2E8EFC14 1FBECAA6
234    287C5947 4E6BC05D 99B2964F A090C3A2 233BA186 515BE7ED
235    1F612970 CEE2D7AF B81BDD76 2170481C D0069127 D5B05AA9
236    93B4EA98 8D8FDDC1 86FFB7DC 90A6C08F 4DF435C9 34028492
237    36C3FAB4 D27C7026 C1D4DCB2 602646DE C9751E76 3DBA37BD
238    F8FF9406 AD9E530E E5DB382F 413001AE B06A53ED 9027D831
239    179727B0 865A8918 DA3EDBEB CF9B14ED 44CE6CBA CED4BB1B
240    DB7F1447 E6CC254B 33205151 2BD7AF42 6FB8F401 378CD2BF
241    5983CA01 C64B92EC F032EA15 D1721D03 F482D7CE 6E74FEF6
242    D55E702F 46980C82 B5A84031 900B1C9E 59E7C97F BEC7E8F3
243    23A97A7E 36CC88BE 0F1D45B7 FF585AC5 4BD407B2 2B4154AA
244    CC8F6D7E BF48E1D8 14CC5ED2 0F8037E0 A79715EE F29BE328
245    06A1D58B B7C5DA76 F550AA3D 8A1FBFF0 EB19CCB1 A313D55C
246    DA56C9EC 2EF29632 387FE8D7 6E3C0468 043E8F66 3F4860EE
247    12BF2D5B 0B7474D6 E694F91E 6DBE1159 74A3926F 12FEE5E4
248    38777CB6 A932DF8C D8BEC4D0 73B931BA 3BC832B6 8D9DD300
249    741FA7BF 8AFC47ED 2576F693 6BA42466 3AAB639C 5AE4F568
250    3423B474 2BF1C978 238F16CB E39D652D E3FDB8BE FC848AD9
251    22222E04 A4037C07 13EB57A8 1A23F0C7 3473FC64 6CEA306B
252    4BCBC886 2F8385DD FA9D4B7F A2C087E8 79683303 ED5BDD3A
253    062B3CF5 B3A278A6 6D2A13F8 3F44F82D DF310EE0 74AB6A36
254    4597E899 A0255DC1 64F31CC5 0846851D F9AB4819 5DED7EA1
255    B1D510BD 7EE74D73 FAF36BC3 1ECFA268 359046F4 EB879F92
256    4009438B 481C6CD7 889A002E D5EE382B C9190DA6 FC026E47
257    9558E447 5677E9AA 9E3050E2 765694DF C81F56E8 80B96E71
258    60C980DD 98EDD3DF FFFFFFFF FFFFFFFF""")
259    mLen = 8192
260
261
262class ffdhe2048(_FFDHParams):  # From RFC 7919
263    g = 0x02
264    m = long_converter("""
265    FFFFFFFF FFFFFFFF ADF85458 A2BB4A9A AFDC5620 273D3CF1
266    D8B9C583 CE2D3695 A9E13641 146433FB CC939DCE 249B3EF9
267    7D2FE363 630C75D8 F681B202 AEC4617A D3DF1ED5 D5FD6561
268    2433F51F 5F066ED0 85636555 3DED1AF3 B557135E 7F57C935
269    984F0C70 E0E68B77 E2A689DA F3EFE872 1DF158A1 36ADE735
270    30ACCA4F 483A797A BC0AB182 B324FB61 D108A94B B2C8E3FB
271    B96ADAB7 60D7F468 1D4F42A3 DE394DF4 AE56EDE7 6372BB19
272    0B07A7C8 EE0A6D70 9E02FCE1 CDF7E2EC C03404CD 28342F61
273    9172FE9C E98583FF 8E4F1232 EEF28183 C3FE3B1B 4C6FAD73
274    3BB5FCBC 2EC22005 C58EF183 7D1683B2 C6F34A26 C1B2EFFA
275    886B4238 61285C97 FFFFFFFF FFFFFFFF
276    """)
277    mLen = 2048
278
279
280class ffdhe3072(_FFDHParams):  # From RFC 7919
281    g = 0x02
282    m = long_converter("""
283    FFFFFFFF FFFFFFFF ADF85458 A2BB4A9A AFDC5620 273D3CF1
284    D8B9C583 CE2D3695 A9E13641 146433FB CC939DCE 249B3EF9
285    7D2FE363 630C75D8 F681B202 AEC4617A D3DF1ED5 D5FD6561
286    2433F51F 5F066ED0 85636555 3DED1AF3 B557135E 7F57C935
287    984F0C70 E0E68B77 E2A689DA F3EFE872 1DF158A1 36ADE735
288    30ACCA4F 483A797A BC0AB182 B324FB61 D108A94B B2C8E3FB
289    B96ADAB7 60D7F468 1D4F42A3 DE394DF4 AE56EDE7 6372BB19
290    0B07A7C8 EE0A6D70 9E02FCE1 CDF7E2EC C03404CD 28342F61
291    9172FE9C E98583FF 8E4F1232 EEF28183 C3FE3B1B 4C6FAD73
292    3BB5FCBC 2EC22005 C58EF183 7D1683B2 C6F34A26 C1B2EFFA
293    886B4238 611FCFDC DE355B3B 6519035B BC34F4DE F99C0238
294    61B46FC9 D6E6C907 7AD91D26 91F7F7EE 598CB0FA C186D91C
295    AEFE1309 85139270 B4130C93 BC437944 F4FD4452 E2D74DD3
296    64F2E21E 71F54BFF 5CAE82AB 9C9DF69E E86D2BC5 22363A0D
297    ABC52197 9B0DEADA 1DBF9A42 D5C4484E 0ABCD06B FA53DDEF
298    3C1B20EE 3FD59D7C 25E41D2B 66C62E37 FFFFFFFF FFFFFFFF
299    """)
300    mLen = 3072
301
302
303class ffdhe4096(_FFDHParams):  # From RFC 7919
304    g = 0x02
305    m = long_converter("""
306    FFFFFFFF FFFFFFFF ADF85458 A2BB4A9A AFDC5620 273D3CF1
307    D8B9C583 CE2D3695 A9E13641 146433FB CC939DCE 249B3EF9
308    7D2FE363 630C75D8 F681B202 AEC4617A D3DF1ED5 D5FD6561
309    2433F51F 5F066ED0 85636555 3DED1AF3 B557135E 7F57C935
310    984F0C70 E0E68B77 E2A689DA F3EFE872 1DF158A1 36ADE735
311    30ACCA4F 483A797A BC0AB182 B324FB61 D108A94B B2C8E3FB
312    B96ADAB7 60D7F468 1D4F42A3 DE394DF4 AE56EDE7 6372BB19
313    0B07A7C8 EE0A6D70 9E02FCE1 CDF7E2EC C03404CD 28342F61
314    9172FE9C E98583FF 8E4F1232 EEF28183 C3FE3B1B 4C6FAD73
315    3BB5FCBC 2EC22005 C58EF183 7D1683B2 C6F34A26 C1B2EFFA
316    886B4238 611FCFDC DE355B3B 6519035B BC34F4DE F99C0238
317    61B46FC9 D6E6C907 7AD91D26 91F7F7EE 598CB0FA C186D91C
318    AEFE1309 85139270 B4130C93 BC437944 F4FD4452 E2D74DD3
319    64F2E21E 71F54BFF 5CAE82AB 9C9DF69E E86D2BC5 22363A0D
320    ABC52197 9B0DEADA 1DBF9A42 D5C4484E 0ABCD06B FA53DDEF
321    3C1B20EE 3FD59D7C 25E41D2B 669E1EF1 6E6F52C3 164DF4FB
322    7930E9E4 E58857B6 AC7D5F42 D69F6D18 7763CF1D 55034004
323    87F55BA5 7E31CC7A 7135C886 EFB4318A ED6A1E01 2D9E6832
324    A907600A 918130C4 6DC778F9 71AD0038 092999A3 33CB8B7A
325    1A1DB93D 7140003C 2A4ECEA9 F98D0ACC 0A8291CD CEC97DCF
326    8EC9B55A 7F88A46B 4DB5A851 F44182E1 C68A007E 5E655F6A
327    FFFFFFFF FFFFFFFF
328    """)
329    mLen = 4096
330
331
332class ffdhe6144(_FFDHParams):  # From RFC 7919
333    g = 0x02
334    m = long_converter("""
335    FFFFFFFF FFFFFFFF ADF85458 A2BB4A9A AFDC5620 273D3CF1
336    D8B9C583 CE2D3695 A9E13641 146433FB CC939DCE 249B3EF9
337    7D2FE363 630C75D8 F681B202 AEC4617A D3DF1ED5 D5FD6561
338    2433F51F 5F066ED0 85636555 3DED1AF3 B557135E 7F57C935
339    984F0C70 E0E68B77 E2A689DA F3EFE872 1DF158A1 36ADE735
340    30ACCA4F 483A797A BC0AB182 B324FB61 D108A94B B2C8E3FB
341    B96ADAB7 60D7F468 1D4F42A3 DE394DF4 AE56EDE7 6372BB19
342    0B07A7C8 EE0A6D70 9E02FCE1 CDF7E2EC C03404CD 28342F61
343    9172FE9C E98583FF 8E4F1232 EEF28183 C3FE3B1B 4C6FAD73
344    3BB5FCBC 2EC22005 C58EF183 7D1683B2 C6F34A26 C1B2EFFA
345    886B4238 611FCFDC DE355B3B 6519035B BC34F4DE F99C0238
346    61B46FC9 D6E6C907 7AD91D26 91F7F7EE 598CB0FA C186D91C
347    AEFE1309 85139270 B4130C93 BC437944 F4FD4452 E2D74DD3
348    64F2E21E 71F54BFF 5CAE82AB 9C9DF69E E86D2BC5 22363A0D
349    ABC52197 9B0DEADA 1DBF9A42 D5C4484E 0ABCD06B FA53DDEF
350    3C1B20EE 3FD59D7C 25E41D2B 669E1EF1 6E6F52C3 164DF4FB
351    7930E9E4 E58857B6 AC7D5F42 D69F6D18 7763CF1D 55034004
352    87F55BA5 7E31CC7A 7135C886 EFB4318A ED6A1E01 2D9E6832
353    A907600A 918130C4 6DC778F9 71AD0038 092999A3 33CB8B7A
354    1A1DB93D 7140003C 2A4ECEA9 F98D0ACC 0A8291CD CEC97DCF
355    8EC9B55A 7F88A46B 4DB5A851 F44182E1 C68A007E 5E0DD902
356    0BFD64B6 45036C7A 4E677D2C 38532A3A 23BA4442 CAF53EA6
357    3BB45432 9B7624C8 917BDD64 B1C0FD4C B38E8C33 4C701C3A
358    CDAD0657 FCCFEC71 9B1F5C3E 4E46041F 388147FB 4CFDB477
359    A52471F7 A9A96910 B855322E DB6340D8 A00EF092 350511E3
360    0ABEC1FF F9E3A26E 7FB29F8C 183023C3 587E38DA 0077D9B4
361    763E4E4B 94B2BBC1 94C6651E 77CAF992 EEAAC023 2A281BF6
362    B3A739C1 22611682 0AE8DB58 47A67CBE F9C9091B 462D538C
363    D72B0374 6AE77F5E 62292C31 1562A846 505DC82D B854338A
364    E49F5235 C95B9117 8CCF2DD5 CACEF403 EC9D1810 C6272B04
365    5B3B71F9 DC6B80D6 3FDD4A8E 9ADB1E69 62A69526 D43161C1
366    A41D570D 7938DAD4 A40E329C D0E40E65 FFFFFFFF FFFFFFFF
367    """)
368    mLen = 6144
369
370
371class ffdhe8192(_FFDHParams):  # From RFC 7919
372    g = 0x02
373    m = long_converter("""
374    FFFFFFFF FFFFFFFF ADF85458 A2BB4A9A AFDC5620 273D3CF1
375    D8B9C583 CE2D3695 A9E13641 146433FB CC939DCE 249B3EF9
376    7D2FE363 630C75D8 F681B202 AEC4617A D3DF1ED5 D5FD6561
377    2433F51F 5F066ED0 85636555 3DED1AF3 B557135E 7F57C935
378    984F0C70 E0E68B77 E2A689DA F3EFE872 1DF158A1 36ADE735
379    30ACCA4F 483A797A BC0AB182 B324FB61 D108A94B B2C8E3FB
380    B96ADAB7 60D7F468 1D4F42A3 DE394DF4 AE56EDE7 6372BB19
381    0B07A7C8 EE0A6D70 9E02FCE1 CDF7E2EC C03404CD 28342F61
382    9172FE9C E98583FF 8E4F1232 EEF28183 C3FE3B1B 4C6FAD73
383    3BB5FCBC 2EC22005 C58EF183 7D1683B2 C6F34A26 C1B2EFFA
384    886B4238 611FCFDC DE355B3B 6519035B BC34F4DE F99C0238
385    61B46FC9 D6E6C907 7AD91D26 91F7F7EE 598CB0FA C186D91C
386    AEFE1309 85139270 B4130C93 BC437944 F4FD4452 E2D74DD3
387    64F2E21E 71F54BFF 5CAE82AB 9C9DF69E E86D2BC5 22363A0D
388    ABC52197 9B0DEADA 1DBF9A42 D5C4484E 0ABCD06B FA53DDEF
389    3C1B20EE 3FD59D7C 25E41D2B 669E1EF1 6E6F52C3 164DF4FB
390    7930E9E4 E58857B6 AC7D5F42 D69F6D18 7763CF1D 55034004
391    87F55BA5 7E31CC7A 7135C886 EFB4318A ED6A1E01 2D9E6832
392    A907600A 918130C4 6DC778F9 71AD0038 092999A3 33CB8B7A
393    1A1DB93D 7140003C 2A4ECEA9 F98D0ACC 0A8291CD CEC97DCF
394    8EC9B55A 7F88A46B 4DB5A851 F44182E1 C68A007E 5E0DD902
395    0BFD64B6 45036C7A 4E677D2C 38532A3A 23BA4442 CAF53EA6
396    3BB45432 9B7624C8 917BDD64 B1C0FD4C B38E8C33 4C701C3A
397    CDAD0657 FCCFEC71 9B1F5C3E 4E46041F 388147FB 4CFDB477
398    A52471F7 A9A96910 B855322E DB6340D8 A00EF092 350511E3
399    0ABEC1FF F9E3A26E 7FB29F8C 183023C3 587E38DA 0077D9B4
400    763E4E4B 94B2BBC1 94C6651E 77CAF992 EEAAC023 2A281BF6
401    B3A739C1 22611682 0AE8DB58 47A67CBE F9C9091B 462D538C
402    D72B0374 6AE77F5E 62292C31 1562A846 505DC82D B854338A
403    E49F5235 C95B9117 8CCF2DD5 CACEF403 EC9D1810 C6272B04
404    5B3B71F9 DC6B80D6 3FDD4A8E 9ADB1E69 62A69526 D43161C1
405    A41D570D 7938DAD4 A40E329C CFF46AAA 36AD004C F600C838
406    1E425A31 D951AE64 FDB23FCE C9509D43 687FEB69 EDD1CC5E
407    0B8CC3BD F64B10EF 86B63142 A3AB8829 555B2F74 7C932665
408    CB2C0F1C C01BD702 29388839 D2AF05E4 54504AC7 8B758282
409    2846C0BA 35C35F5C 59160CC0 46FD8251 541FC68C 9C86B022
410    BB709987 6A460E74 51A8A931 09703FEE 1C217E6C 3826E52C
411    51AA691E 0E423CFC 99E9E316 50C1217B 624816CD AD9A95F9
412    D5B80194 88D9C0A0 A1FE3075 A577E231 83F81D4A 3F2FA457
413    1EFC8CE0 BA8A4FE8 B6855DFE 72B0A66E DED2FBAB FBE58A30
414    FAFABE1C 5D71A87E 2F741EF8 C1FE86FE A6BBFDE5 30677F0D
415    97D11D49 F7A8443D 0822E506 A9F4614E 011E2A94 838FF88C
416    D68C8BB7 C5C6424C FFFFFFFF FFFFFFFF
417    """)
418    mLen = 8192
419
420
421_tls_named_ffdh_groups = {256: "ffdhe2048", 257: "ffdhe3072",
422                          258: "ffdhe4096", 259: "ffdhe6144",
423                          260: "ffdhe8192"}
424
425_tls_named_curves = {1: "sect163k1", 2: "sect163r1", 3: "sect163r2",
426                     4: "sect193r1", 5: "sect193r2", 6: "sect233k1",
427                     7: "sect233r1", 8: "sect239k1", 9: "sect283k1",
428                     10: "sect283r1", 11: "sect409k1", 12: "sect409r1",
429                     13: "sect571k1", 14: "sect571r1", 15: "secp160k1",
430                     16: "secp160r1", 17: "secp160r2", 18: "secp192k1",
431                     19: "secp192r1", 20: "secp224k1", 21: "secp224r1",
432                     22: "secp256k1", 23: "secp256r1", 24: "secp384r1",
433                     25: "secp521r1", 26: "brainpoolP256r1",
434                     27: "brainpoolP384r1", 28: "brainpoolP512r1",
435                     29: "x25519", 30: "x448",
436                     0xff01: "arbitrary_explicit_prime_curves",
437                     0xff02: "arbitrary_explicit_char2_curves"}
438
439_tls_named_groups = {}
440_tls_named_groups.update(_tls_named_ffdh_groups)
441_tls_named_groups.update(_tls_named_curves)
442
443
444def _tls_named_groups_import(group, pubbytes):
445    if group in _tls_named_ffdh_groups:
446        params = _ffdh_groups[_tls_named_ffdh_groups[group]][0]
447        pn = params.parameter_numbers()
448        public_numbers = dh.DHPublicNumbers(pubbytes, pn)
449        return public_numbers.public_key(default_backend())
450    elif group in _tls_named_curves:
451        if _tls_named_curves[group] in ["x25519", "x448"]:
452            if conf.crypto_valid_advanced:
453                if _tls_named_curves[group] == "x25519":
454                    import_point = x25519.X25519PublicKey.from_public_bytes
455                else:
456                    import_point = x448.X448PublicKey.from_public_bytes
457                return import_point(pubbytes)
458        else:
459            curve = ec._CURVE_TYPES[_tls_named_curves[group]]()
460            try:  # cryptography >= 2.5
461                return ec.EllipticCurvePublicKey.from_encoded_point(
462                    curve,
463                    pubbytes
464                )
465            except AttributeError:
466                pub_num = ec.EllipticCurvePublicNumbers.from_encoded_point(
467                    curve,
468                    pubbytes
469                ).public_numbers()
470                return pub_num.public_key(default_backend())
471
472
473def _tls_named_groups_pubbytes(privkey):
474    if isinstance(privkey, dh.DHPrivateKey):
475        pubkey = privkey.public_key()
476        return pubkey.public_numbers().y
477    elif isinstance(privkey, (x25519.X25519PrivateKey,
478                              x448.X448PrivateKey)):
479        pubkey = privkey.public_key()
480        return pubkey.public_bytes(
481            serialization.Encoding.Raw,
482            serialization.PublicFormat.Raw
483        )
484    else:
485        pubkey = privkey.public_key()
486        try:
487            # cryptography >= 2.5
488            return pubkey.public_bytes(
489                serialization.Encoding.X962,
490                serialization.PublicFormat.UncompressedPoint
491            )
492        except TypeError:
493            # older versions
494            return pubkey.public_numbers().encode_point()
495
496
497def _tls_named_groups_generate(group):
498    if group in _tls_named_ffdh_groups:
499        params = _ffdh_groups[_tls_named_ffdh_groups[group]][0]
500        return params.generate_private_key()
501    elif group in _tls_named_curves:
502        group_name = _tls_named_curves[group]
503        if group_name in ["x25519", "x448"]:
504            if conf.crypto_valid_advanced:
505                if group_name == "x25519":
506                    return x25519.X25519PrivateKey.generate()
507                else:
508                    return x448.X448PrivateKey.generate()
509            else:
510                warning(
511                    "Your cryptography version doesn't support " + group_name
512                )
513        else:
514            curve = ec._CURVE_TYPES[_tls_named_curves[group]]()
515            return ec.generate_private_key(curve, default_backend())
516
517# Below lies ghost code since the shift from 'ecdsa' to 'cryptography' lib.
518# Part of the code has been kept, but commented out, in case anyone would like
519# to improve ECC support in 'cryptography' (namely for the compressed point
520# format and additional curves).
521#
522# Recommended curve parameters from www.secg.org/SEC2-Ver-1.0.pdf
523# and www.ecc-brainpool.org/download/Domain-parameters.pdf
524#
525#
526# import math
527#
528# from scapy.utils import long_converter, binrepr
529# from scapy.layers.tls.crypto.pkcs1 import pkcs_i2osp, pkcs_os2ip
530#
531#
532# def encode_point(point, point_format=0):
533#    """
534#    Return a string representation of the Point p, according to point_format.
535#    """
536#    pLen = len(binrepr(point.curve().p()))
537#    x = pkcs_i2osp(point.x(), math.ceil(pLen/8))
538#    y = pkcs_i2osp(point.y(), math.ceil(pLen/8))
539#    if point_format == 0:
540#        frmt = b'\x04'
541#    elif point_format == 1:
542#        frmt = chr(2 + y%2)
543#        y = ''
544#    else:
545#        raise Exception("No support for point_format %d" % point_format)
546#    return frmt + x + y
547#
548#
549# try:
550#    import ecdsa
551#    ecdsa_support = True
552# except ImportError:
553#    import logging
554#    log_loading = logging.getLogger("scapy.loading")
555#    log_loading.info("Can't import python ecdsa lib. No curves.")
556#
557#
558# if ecdsa_support:
559#
560#    from ecdsa.ellipticcurve import CurveFp, Point
561#    from ecdsa.curves import Curve
562#    from ecdsa.numbertheory import square_root_mod_prime
563#
564#
565#    def extract_coordinates(g, curve):
566#        """
567#        Return the coordinates x and y as integers,
568#        regardless of the point format of string g.
569#        Second expected parameter is a CurveFp.
570#        """
571#        p = curve.p()
572#        point_format = g[0]
573#        point = g[1:]
574#        if point_format == b'\x04':
575#            point_len = len(point)
576#            if point_len % 2 != 0:
577#                raise Exception("Point length is not even.")
578#            x_bytes = point[:point_len>>1]
579#            x = pkcs_os2ip(x_bytes) % p
580#            y_bytes = point[point_len>>1:]
581#            y = pkcs_os2ip(y_bytes) % p
582#        elif point_format in [b'\x02', b'\x03']:
583#            x_bytes = point
584#            x = pkcs_os2ip(x_bytes) % p
585#            # perform the y coordinate computation with self.tls_ec
586#            y_square = (x*x*x + curve.a()*x + curve.b()) % p
587#            y = square_root_mod_prime(y_square, p)
588#            y_parity = ord(point_format) % 2    # \x02 means even, \x03 means odd  # noqa: E501
589#            if y % 2 != y_parity:
590#                y = -y % p
591#        else:
592#            raise Exception("Point starts with %s. This encoding "
593#                            "is not recognized." % repr(point_format))
594#        if not curve.contains_point(x, y):
595#            raise Exception("The point we extracted does not belong on the curve!")  # noqa: E501
596#        return x, y
597#
598#    def import_curve(p, a, b, g, r, name="dummyName", oid=(1, 3, 132, 0, 0xff)):  # noqa: E501
599#        """
600#        Create an ecdsa.curves.Curve from the usual parameters.
601#        Arguments may be either octet strings or integers,
602#        except g which we expect to be an octet string.
603#        """
604#        if isinstance(p, str):
605#            p = pkcs_os2ip(p)
606#        if isinstance(a, str):
607#            a = pkcs_os2ip(a)
608#        if isinstance(b, str):
609#            b = pkcs_os2ip(b)
610#        if isinstance(r, str):
611#            r = pkcs_os2ip(r)
612#        curve = CurveFp(p, a, b)
613#        x, y = extract_coordinates(g, curve)
614#        generator = Point(curve, x, y, r)
615#        return Curve(name, curve, generator, oid)
616
617# Named curves
618
619# We always provide _a as a positive integer.
620
621#    _p          = long_converter("""
622#                  ffffffff ffffffff ffffffff fffffffe ffffac73""")
623#    _a          = 0
624#    _b          = 7
625#    _Gx         = long_converter("""
626#                  3b4c382c e37aa192 a4019e76 3036f4f5 dd4d7ebb""")
627#    _Gy         = long_converter("""
628#                  938cf935 318fdced 6bc28286 531733c3 f03c4fee""")
629#    _r          = long_converter("""01
630#                  00000000 00000000 0001b8fa 16dfab9a ca16b6b3""")
631#    curve       = CurveFp(_p, _a, _b)
632#    generator   = Point(curve, _Gx, _Gy, _r)
633#    SECP160k1   = Curve("SECP160k1", curve, generator,
634#                        (1, 3, 132, 0, 9), "secp160k1")
635
636#    _p          = long_converter("""
637#                  ffffffff ffffffff ffffffff ffffffff 7fffffff""")
638#    _a          = -3 % _p
639#    _b          = long_converter("""
640#                  1c97befc 54bd7a8b 65acf89f 81d4d4ad c565fa45""")
641#    _Gx         = long_converter("""
642#                  4a96b568 8ef57328 46646989 68c38bb9 13cbfc82""")
643#    _Gy         = long_converter("""
644#                  23a62855 3168947d 59dcc912 04235137 7ac5fb32""")
645#    _r          = long_converter("""01
646#                  00000000 00000000 0001f4c8 f927aed3 ca752257""")
647#    curve       = CurveFp(_p, _a, _b)
648#    generator   = Point(curve, _Gx, _Gy, _r)
649#    SECP160r1   = Curve("SECP160r1", curve, generator,
650#                        (1, 3, 132, 0, 8), "secp160r1")
651
652#    _p          = long_converter("""
653#                  ffffffff ffffffff ffffffff fffffffe ffffac73""")
654#    _a          = -3 % _p
655#    _b          = long_converter("""
656#                  b4e134d3 fb59eb8b ab572749 04664d5a f50388ba""")
657#    _Gx         = long_converter("""
658#                  52dcb034 293a117e 1f4ff11b 30f7199d 3144ce6d""")
659#    _Gy         = long_converter("""
660#                  feaffef2 e331f296 e071fa0d f9982cfe a7d43f2e""")
661#    _r          = long_converter("""01
662#                  00000000 00000000 0000351e e786a818 f3a1a16b""")
663#    curve       = CurveFp(_p, _a, _b)
664#    generator   = Point(curve, _Gx, _Gy, _r)
665#    SECP160r2   = Curve("SECP160r2", curve, generator,
666#                        (1, 3, 132, 0, 30), "secp160r2")
667
668#    _p          = long_converter("""
669#                  ffffffff ffffffff ffffffff ffffffff fffffffe ffffee37""")
670#    _a          = 0
671#    _b          = 3
672#    _Gx         = long_converter("""
673#                  db4ff10e c057e9ae 26b07d02 80b7f434 1da5d1b1 eae06c7d""")
674#    _Gy         = long_converter("""
675#                  9b2f2f6d 9c5628a7 844163d0 15be8634 4082aa88 d95e2f9d""")
676#    _r          = long_converter("""
677#                  ffffffff ffffffff fffffffe 26f2fc17 0f69466a 74defd8d""")
678#    curve       = CurveFp(_p, _a, _b)
679#    generator   = Point(curve, _Gx, _Gy, _r)
680#    SECP192k1   = Curve("SECP192k1", curve, generator,
681#                        (1, 3, 132, 0, 31), "secp192k1")
682
683#    _p          = long_converter("""
684#                  ffffffff ffffffff ffffffff ffffffff ffffffff fffffffe
685#                  ffffe56d""")
686#    _a          = 0
687#    _b          = 5
688#    _Gx         = long_converter("""
689#                  a1455b33 4df099df 30fc28a1 69a467e9 e47075a9 0f7e650e
690#                  b6b7a45c""")
691#    _Gy         = long_converter("""
692#                  7e089fed 7fba3442 82cafbd6 f7e319f7 c0b0bd59 e2ca4bdb
693#                  556d61a5""")
694#    _r          = long_converter("""01
695#                  00000000 00000000 00000000 0001dce8 d2ec6184 caf0a971
696#                  769fb1f7""")
697#    curve       = CurveFp(_p, _a, _b)
698#    generator   = Point(curve, _Gx, _Gy, _r)
699#    SECP224k1   = Curve("SECP224k1", curve, generator,
700#                        (1, 3, 132, 0, 32), "secp224k1")
701
702#    _p          = long_converter("""
703#                  A9FB57DB A1EEA9BC 3E660A90 9D838D72 6E3BF623 D5262028
704#                  2013481D 1F6E5377""")
705#    _a          = long_converter("""
706#                  7D5A0975 FC2C3057 EEF67530 417AFFE7 FB8055C1 26DC5C6C
707#                  E94A4B44 F330B5D9""")
708#    _b          = long_converter("""
709#                  26DC5C6C E94A4B44 F330B5D9 BBD77CBF 95841629 5CF7E1CE
710#                  6BCCDC18 FF8C07B6""")
711#    _Gx         = long_converter("""
712#                  8BD2AEB9 CB7E57CB 2C4B482F FC81B7AF B9DE27E1 E3BD23C2
713#                  3A4453BD 9ACE3262""")
714#    _Gy         = long_converter("""
715#                  547EF835 C3DAC4FD 97F8461A 14611DC9 C2774513 2DED8E54
716#                  5C1D54C7 2F046997""")
717#    _r          = long_converter("""
718#                  A9FB57DB A1EEA9BC 3E660A90 9D838D71 8C397AA3 B561A6F7
719#                  901E0E82 974856A7""")
720#    curve       = CurveFp(_p, _a, _b)
721#    generator   = Point(curve, _Gx, _Gy, _r)
722#    BRNP256r1   = Curve("BRNP256r1", curve, generator,
723#                        (1, 3, 36, 3, 3, 2, 8, 1, 1, 7), "brainpoolP256r1")
724
725#    _p          = long_converter("""
726#                  8CB91E82 A3386D28 0F5D6F7E 50E641DF 152F7109 ED5456B4
727#                  12B1DA19 7FB71123 ACD3A729 901D1A71 87470013 3107EC53""")
728#    _a          = long_converter("""
729#                  7BC382C6 3D8C150C 3C72080A CE05AFA0 C2BEA28E 4FB22787
730#                  139165EF BA91F90F 8AA5814A 503AD4EB 04A8C7DD 22CE2826""")
731#    _b          = long_converter("""
732#                  04A8C7DD 22CE2826 8B39B554 16F0447C 2FB77DE1 07DCD2A6
733#                  2E880EA5 3EEB62D5 7CB43902 95DBC994 3AB78696 FA504C11""")
734#    _Gx         = long_converter("""
735#                  1D1C64F0 68CF45FF A2A63A81 B7C13F6B 8847A3E7 7EF14FE3
736#                  DB7FCAFE 0CBD10E8 E826E034 36D646AA EF87B2E2 47D4AF1E""")
737#    _Gy         = long_converter("""
738#                  8ABE1D75 20F9C2A4 5CB1EB8E 95CFD552 62B70B29 FEEC5864
739#                  E19C054F F9912928 0E464621 77918111 42820341 263C5315""")
740#    _r          = long_converter("""
741#                  8CB91E82 A3386D28 0F5D6F7E 50E641DF 152F7109 ED5456B3
742#                  1F166E6C AC0425A7 CF3AB6AF 6B7FC310 3B883202 E9046565""")
743#    curve       = CurveFp(_p, _a, _b)
744#    generator   = Point(curve, _Gx, _Gy, _r)
745#    BRNP384r1   = Curve("BRNP384r1", curve, generator,
746#                        (1, 3, 36, 3, 3, 2, 8, 1, 1, 11), "brainpoolP384r1")
747
748#    _p          = long_converter("""
749#                  AADD9DB8 DBE9C48B 3FD4E6AE 33C9FC07 CB308DB3 B3C9D20E
750#                  D6639CCA 70330871 7D4D9B00 9BC66842 AECDA12A E6A380E6
751#                  2881FF2F 2D82C685 28AA6056 583A48F3""")
752#    _a          = long_converter("""
753#                  7830A331 8B603B89 E2327145 AC234CC5 94CBDD8D 3DF91610
754#                  A83441CA EA9863BC 2DED5D5A A8253AA1 0A2EF1C9 8B9AC8B5
755#                  7F1117A7 2BF2C7B9 E7C1AC4D 77FC94CA""")
756#    _b          = long_converter("""
757#                  3DF91610 A83441CA EA9863BC 2DED5D5A A8253AA1 0A2EF1C9
758#                  8B9AC8B5 7F1117A7 2BF2C7B9 E7C1AC4D 77FC94CA DC083E67
759#                  984050B7 5EBAE5DD 2809BD63 8016F723""")
760#    _Gx         = long_converter("""
761#                  81AEE4BD D82ED964 5A21322E 9C4C6A93 85ED9F70 B5D916C1
762#                  B43B62EE F4D0098E FF3B1F78 E2D0D48D 50D1687B 93B97D5F
763#                  7C6D5047 406A5E68 8B352209 BCB9F822""")
764#    _Gy         = long_converter("""
765#                  7DDE385D 566332EC C0EABFA9 CF7822FD F209F700 24A57B1A
766#                  A000C55B 881F8111 B2DCDE49 4A5F485E 5BCA4BD8 8A2763AE
767#                  D1CA2B2F A8F05406 78CD1E0F 3AD80892""")
768#    _r          = long_converter("""
769#                  AADD9DB8 DBE9C48B 3FD4E6AE 33C9FC07 CB308DB3 B3C9D20E
770#                  D6639CCA 70330870 553E5C41 4CA92619 41866119 7FAC1047
771#                  1DB1D381 085DDADD B5879682 9CA90069""")
772#    curve       = CurveFp(_p, _a, _b)
773#    generator   = Point(curve, _Gx, _Gy, _r)
774#    BRNP512r1   = Curve("BRNP512r1", curve, generator,
775#                        (1, 3, 36, 3, 3, 2, 8, 1, 1, 13), "brainpoolP512r1")
776