1 /* $OpenBSD: kdf.h,v 1.9 2024/07/09 16:20:17 tb Exp $ */ 2 /* 3 * Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL 4 * project. 5 */ 6 /* ==================================================================== 7 * Copyright (c) 2016-2018 The OpenSSL Project. All rights reserved. 8 * 9 * Redistribution and use in source and binary forms, with or without 10 * modification, are permitted provided that the following conditions 11 * are met: 12 * 13 * 1. Redistributions of source code must retain the above copyright 14 * notice, this list of conditions and the following disclaimer. 15 * 16 * 2. Redistributions in binary form must reproduce the above copyright 17 * notice, this list of conditions and the following disclaimer in 18 * the documentation and/or other materials provided with the 19 * distribution. 20 * 21 * 3. All advertising materials mentioning features or use of this 22 * software must display the following acknowledgment: 23 * "This product includes software developed by the OpenSSL Project 24 * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)" 25 * 26 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to 27 * endorse or promote products derived from this software without 28 * prior written permission. For written permission, please contact 29 * licensing@OpenSSL.org. 30 * 31 * 5. Products derived from this software may not be called "OpenSSL" 32 * nor may "OpenSSL" appear in their names without prior written 33 * permission of the OpenSSL Project. 34 * 35 * 6. Redistributions of any form whatsoever must retain the following 36 * acknowledgment: 37 * "This product includes software developed by the OpenSSL Project 38 * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)" 39 * 40 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY 41 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 42 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 43 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR 44 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 45 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 46 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 47 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 48 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, 49 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 50 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED 51 * OF THE POSSIBILITY OF SUCH DAMAGE. 52 * ==================================================================== 53 */ 54 55 #ifndef HEADER_KDF_H 56 # define HEADER_KDF_H 57 58 #ifdef __cplusplus 59 extern "C" { 60 #endif 61 62 # define EVP_PKEY_CTRL_TLS_MD (EVP_PKEY_ALG_CTRL + 0) 63 # define EVP_PKEY_CTRL_TLS_SECRET (EVP_PKEY_ALG_CTRL + 1) 64 # define EVP_PKEY_CTRL_TLS_SEED (EVP_PKEY_ALG_CTRL + 2) 65 66 # define EVP_PKEY_CTRL_HKDF_MD (EVP_PKEY_ALG_CTRL + 3) 67 # define EVP_PKEY_CTRL_HKDF_SALT (EVP_PKEY_ALG_CTRL + 4) 68 # define EVP_PKEY_CTRL_HKDF_KEY (EVP_PKEY_ALG_CTRL + 5) 69 # define EVP_PKEY_CTRL_HKDF_INFO (EVP_PKEY_ALG_CTRL + 6) 70 # define EVP_PKEY_CTRL_HKDF_MODE (EVP_PKEY_ALG_CTRL + 7) 71 72 # define EVP_PKEY_HKDEF_MODE_EXTRACT_AND_EXPAND 0 73 # define EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY 1 74 # define EVP_PKEY_HKDEF_MODE_EXPAND_ONLY 2 75 76 77 # define EVP_PKEY_CTX_set_tls1_prf_md(pctx, md) \ 78 EVP_PKEY_CTX_ctrl(pctx, -1, EVP_PKEY_OP_DERIVE, \ 79 EVP_PKEY_CTRL_TLS_MD, 0, (void *)(md)) 80 81 # define EVP_PKEY_CTX_set1_tls1_prf_secret(pctx, sec, seclen) \ 82 EVP_PKEY_CTX_ctrl(pctx, -1, EVP_PKEY_OP_DERIVE, \ 83 EVP_PKEY_CTRL_TLS_SECRET, seclen, (void *)(sec)) 84 85 # define EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, seed, seedlen) \ 86 EVP_PKEY_CTX_ctrl(pctx, -1, EVP_PKEY_OP_DERIVE, \ 87 EVP_PKEY_CTRL_TLS_SEED, seedlen, (void *)(seed)) 88 89 90 # define EVP_PKEY_CTX_set_hkdf_md(pctx, md) \ 91 EVP_PKEY_CTX_ctrl(pctx, -1, EVP_PKEY_OP_DERIVE, \ 92 EVP_PKEY_CTRL_HKDF_MD, 0, (void *)(md)) 93 94 # define EVP_PKEY_CTX_set1_hkdf_salt(pctx, salt, saltlen) \ 95 EVP_PKEY_CTX_ctrl(pctx, -1, EVP_PKEY_OP_DERIVE, \ 96 EVP_PKEY_CTRL_HKDF_SALT, saltlen, (void *)(salt)) 97 98 # define EVP_PKEY_CTX_set1_hkdf_key(pctx, key, keylen) \ 99 EVP_PKEY_CTX_ctrl(pctx, -1, EVP_PKEY_OP_DERIVE, \ 100 EVP_PKEY_CTRL_HKDF_KEY, keylen, (void *)(key)) 101 102 # define EVP_PKEY_CTX_add1_hkdf_info(pctx, info, infolen) \ 103 EVP_PKEY_CTX_ctrl(pctx, -1, EVP_PKEY_OP_DERIVE, \ 104 EVP_PKEY_CTRL_HKDF_INFO, infolen, (void *)(info)) 105 106 # define EVP_PKEY_CTX_hkdf_mode(pctx, mode) \ 107 EVP_PKEY_CTX_ctrl(pctx, -1, EVP_PKEY_OP_DERIVE, \ 108 EVP_PKEY_CTRL_HKDF_MODE, mode, NULL) 109 110 int ERR_load_KDF_strings(void); 111 112 /* 113 * KDF function codes. 114 */ 115 # define KDF_F_PKEY_HKDF_CTRL_STR 103 116 # define KDF_F_PKEY_HKDF_DERIVE 102 117 # define KDF_F_PKEY_HKDF_INIT 108 118 # define KDF_F_PKEY_TLS1_PRF_CTRL_STR 100 119 # define KDF_F_PKEY_TLS1_PRF_DERIVE 101 120 # define KDF_F_PKEY_TLS1_PRF_INIT 110 121 # define KDF_F_TLS1_PRF_ALG 111 122 123 /* 124 * KDF reason codes. 125 */ 126 # define KDF_R_INVALID_DIGEST 100 127 # define KDF_R_MISSING_KEY 104 128 # define KDF_R_MISSING_MESSAGE_DIGEST 105 129 # define KDF_R_MISSING_SECRET 107 130 # define KDF_R_MISSING_SEED 106 131 # define KDF_R_UNKNOWN_PARAMETER_TYPE 103 132 # define KDF_R_VALUE_MISSING 102 133 134 # ifdef __cplusplus 135 } 136 # endif 137 #endif 138