1 #if 0
2 =pod
3 #endif
4 
5 /* Licensed to the Apache Software Foundation (ASF) under one or more
6  * contributor license agreements.  See the NOTICE file distributed with
7  * this work for additional information regarding copyright ownership.
8  * The ASF licenses this file to You under the Apache License, Version 2.0
9  * (the "License"); you may not use this file except in compliance with
10  * the License.  You may obtain a copy of the License at
11  *
12  *     http://www.apache.org/licenses/LICENSE-2.0
13  *
14  * Unless required by applicable law or agreed to in writing, software
15  * distributed under the License is distributed on an "AS IS" BASIS,
16  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
17  * See the License for the specific language governing permissions and
18  * limitations under the License.
19  */
20 
21 /*                      _             _
22  *  _ __ ___   ___   __| |    ___ ___| |  mod_ssl
23  * | '_ ` _ \ / _ \ / _` |   / __/ __| |  Apache Interface to OpenSSL
24  * | | | | | | (_) | (_| |   \__ \__ \ |
25  * |_| |_| |_|\___/ \__,_|___|___/___/_|
26  *                      |_____|
27  * ssl_engine_dh.c
28  * Diffie-Hellman Built-in Temporary Parameters
29  */
30 
31 #include "ssl_private.h"
32 
33 /* ----BEGIN GENERATED SECTION-------- */
34 
35 /*
36 ** Diffie-Hellman-Parameters: (512 bit)
37 **     prime:
38 **         00:9f:db:8b:8a:00:45:44:f0:04:5f:17:37:d0:ba:
39 **         2e:0b:27:4c:df:1a:9f:58:82:18:fb:43:53:16:a1:
40 **         6e:37:41:71:fd:19:d8:d8:f3:7c:39:bf:86:3f:d6:
41 **         0e:3e:30:06:80:a3:03:0c:6e:4c:37:57:d0:8f:70:
42 **         e6:aa:87:10:33
43 **     generator: 2 (0x2)
44 ** Diffie-Hellman-Parameters: (1024 bit)
45 **     prime:
46 **         00:d6:7d:e4:40:cb:bb:dc:19:36:d6:93:d3:4a:fd:
47 **         0a:d5:0c:84:d2:39:a4:5f:52:0b:b8:81:74:cb:98:
48 **         bc:e9:51:84:9f:91:2e:63:9c:72:fb:13:b4:b4:d7:
49 **         17:7e:16:d5:5a:c1:79:ba:42:0b:2a:29:fe:32:4a:
50 **         46:7a:63:5e:81:ff:59:01:37:7b:ed:dc:fd:33:16:
51 **         8a:46:1a:ad:3b:72:da:e8:86:00:78:04:5b:07:a7:
52 **         db:ca:78:74:08:7d:15:10:ea:9f:cc:9d:dd:33:05:
53 **         07:dd:62:db:88:ae:aa:74:7d:e0:f4:d6:e2:bd:68:
54 **         b0:e7:39:3e:0f:24:21:8e:b3
55 **     generator: 2 (0x2)
56 */
57 
58 static unsigned char dh512_p[] = {
59     0x9F, 0xDB, 0x8B, 0x8A, 0x00, 0x45, 0x44, 0xF0, 0x04, 0x5F, 0x17, 0x37,
60     0xD0, 0xBA, 0x2E, 0x0B, 0x27, 0x4C, 0xDF, 0x1A, 0x9F, 0x58, 0x82, 0x18,
61     0xFB, 0x43, 0x53, 0x16, 0xA1, 0x6E, 0x37, 0x41, 0x71, 0xFD, 0x19, 0xD8,
62     0xD8, 0xF3, 0x7C, 0x39, 0xBF, 0x86, 0x3F, 0xD6, 0x0E, 0x3E, 0x30, 0x06,
63     0x80, 0xA3, 0x03, 0x0C, 0x6E, 0x4C, 0x37, 0x57, 0xD0, 0x8F, 0x70, 0xE6,
64     0xAA, 0x87, 0x10, 0x33,
65 };
66 static unsigned char dh512_g[] = {
67     0x02,
68 };
69 
get_dh512(void)70 static DH *get_dh512(void)
71 {
72     DH *dh;
73 
74     if (!(dh = DH_new())) {
75         return NULL;
76     }
77 
78     dh->p = BN_bin2bn(dh512_p, sizeof(dh512_p), NULL);
79     dh->g = BN_bin2bn(dh512_g, sizeof(dh512_g), NULL);
80     if (!(dh->p && dh->g)) {
81         DH_free(dh);
82         return NULL;
83     }
84 
85     return dh;
86 }
87 
88 static unsigned char dh1024_p[] = {
89     0xD6, 0x7D, 0xE4, 0x40, 0xCB, 0xBB, 0xDC, 0x19, 0x36, 0xD6, 0x93, 0xD3,
90     0x4A, 0xFD, 0x0A, 0xD5, 0x0C, 0x84, 0xD2, 0x39, 0xA4, 0x5F, 0x52, 0x0B,
91     0xB8, 0x81, 0x74, 0xCB, 0x98, 0xBC, 0xE9, 0x51, 0x84, 0x9F, 0x91, 0x2E,
92     0x63, 0x9C, 0x72, 0xFB, 0x13, 0xB4, 0xB4, 0xD7, 0x17, 0x7E, 0x16, 0xD5,
93     0x5A, 0xC1, 0x79, 0xBA, 0x42, 0x0B, 0x2A, 0x29, 0xFE, 0x32, 0x4A, 0x46,
94     0x7A, 0x63, 0x5E, 0x81, 0xFF, 0x59, 0x01, 0x37, 0x7B, 0xED, 0xDC, 0xFD,
95     0x33, 0x16, 0x8A, 0x46, 0x1A, 0xAD, 0x3B, 0x72, 0xDA, 0xE8, 0x86, 0x00,
96     0x78, 0x04, 0x5B, 0x07, 0xA7, 0xDB, 0xCA, 0x78, 0x74, 0x08, 0x7D, 0x15,
97     0x10, 0xEA, 0x9F, 0xCC, 0x9D, 0xDD, 0x33, 0x05, 0x07, 0xDD, 0x62, 0xDB,
98     0x88, 0xAE, 0xAA, 0x74, 0x7D, 0xE0, 0xF4, 0xD6, 0xE2, 0xBD, 0x68, 0xB0,
99     0xE7, 0x39, 0x3E, 0x0F, 0x24, 0x21, 0x8E, 0xB3,
100 };
101 static unsigned char dh1024_g[] = {
102     0x02,
103 };
104 
get_dh1024(void)105 static DH *get_dh1024(void)
106 {
107     DH *dh;
108 
109     if (!(dh = DH_new())) {
110         return NULL;
111     }
112 
113     dh->p = BN_bin2bn(dh1024_p, sizeof(dh1024_p), NULL);
114     dh->g = BN_bin2bn(dh1024_g, sizeof(dh1024_g), NULL);
115     if (!(dh->p && dh->g)) {
116         DH_free(dh);
117         return NULL;
118     }
119 
120     return dh;
121 }
122 
123 /* ----END GENERATED SECTION---------- */
124 
ssl_dh_GetTmpParam(int nKeyLen)125 DH *ssl_dh_GetTmpParam(int nKeyLen)
126 {
127     DH *dh;
128 
129     if (nKeyLen == 512)
130         dh = get_dh512();
131     else if (nKeyLen == 1024)
132         dh = get_dh1024();
133     else
134         dh = get_dh1024();
135     return dh;
136 }
137 
ssl_dh_GetParamFromFile(char * file)138 DH *ssl_dh_GetParamFromFile(char *file)
139 {
140     DH *dh = NULL;
141     BIO *bio;
142 
143     if ((bio = BIO_new_file(file, "r")) == NULL)
144         return NULL;
145     dh = PEM_read_bio_DHparams(bio, NULL, NULL, NULL);
146     BIO_free(bio);
147     return (dh);
148 }
149 
150 /*
151 =cut
152 ##
153 ##  Embedded Perl script for generating the temporary DH parameters
154 ##
155 
156 require 5.003;
157 use strict;
158 
159 #   configuration
160 my $file  = $0;
161 my $begin = '----BEGIN GENERATED SECTION--------';
162 my $end   = '----END GENERATED SECTION----------';
163 
164 #   read ourself and keep a backup
165 open(FP, "<$file") || die;
166 my $source = '';
167 $source .= $_ while (<FP>);
168 close(FP);
169 open(FP, ">$file.bak") || die;
170 print FP $source;
171 close(FP);
172 
173 #   generate the DH parameters
174 print "1. Generate 512 and 1024 bit Diffie-Hellman parameters (p, g)\n";
175 my $rand = '';
176 foreach $file (qw(/var/log/messages /var/adm/messages
177                   /kernel /vmunix /vmlinuz /etc/hosts /etc/resolv.conf)) {
178     if (-f $file) {
179         $rand = $file     if ($rand eq '');
180         $rand .= ":$file" if ($rand ne '');
181     }
182 }
183 $rand = "-rand $rand" if ($rand ne '');
184 system("openssl gendh $rand -out dh512.pem 512");
185 system("openssl gendh $rand -out dh1024.pem 1024");
186 
187 #   generate DH param info
188 my $dhinfo = '';
189 open(FP, "openssl dh -noout -text -in dh512.pem |") || die;
190 $dhinfo .= $_ while (<FP>);
191 close(FP);
192 open(FP, "openssl dh -noout -text -in dh1024.pem |") || die;
193 $dhinfo .= $_ while (<FP>);
194 close(FP);
195 $dhinfo =~ s|^|** |mg;
196 $dhinfo = "\n\/\*\n$dhinfo\*\/\n\n";
197 
198 my $indent_args = "-i4 -npsl -di0 -br -nce -d0 -cli0 -npcs -nfc1";
199 
200 #   generate C source from DH params
201 my $dhsource = '';
202 open(FP, "openssl dh -noout -C -in dh512.pem | indent $indent_args | expand |") || die;
203 $dhsource .= $_ while (<FP>);
204 close(FP);
205 open(FP, "openssl dh -noout -C -in dh1024.pem | indent $indent_args | expand |") || die;
206 $dhsource .= $_ while (<FP>);
207 close(FP);
208 $dhsource =~ s|(DH\s+\*get_dh)(\d+)[^}]*\n}|static $1$2(void)
209 {
210     DH *dh;
211 
212     if (!(dh = DH_new())) {
213         return NULL;
214     }
215 
216     dh->p = BN_bin2bn(dh$2_p, sizeof(dh$2_p), NULL);
217     dh->g = BN_bin2bn(dh$2_g, sizeof(dh$2_g), NULL);
218     if (!(dh->p && dh->g)) {
219         DH_free(dh);
220         return NULL;
221     }
222 
223     return dh;
224 }
225 |sg;
226 
227 #   generate output
228 my $o = $dhinfo . $dhsource;
229 
230 #   insert the generated code at the target location
231 $source =~ s|(\/\* $begin.+?\n).*\n(.*?\/\* $end)|$1$o$2|s;
232 
233 #   and update the source on disk
234 print "Updating file `$file'\n";
235 open(FP, ">$file") || die;
236 print FP $source;
237 close(FP);
238 
239 #   cleanup
240 unlink("dh512.pem");
241 unlink("dh1024.pem");
242 
243 =pod
244 */
245