xref: /freebsd/crypto/openssl/apps/enc.c (revision e71b70530d95c4f34d8bdbd78d1242df1ba4a945)
1*e71b7053SJung-uk Kim /*
2*e71b7053SJung-uk Kim  * Copyright 1995-2018 The OpenSSL Project Authors. All Rights Reserved.
374664626SKris Kennaway  *
4*e71b7053SJung-uk Kim  * Licensed under the OpenSSL license (the "License").  You may not use
5*e71b7053SJung-uk Kim  * this file except in compliance with the License.  You can obtain a copy
6*e71b7053SJung-uk Kim  * in the file LICENSE in the source distribution or at
7*e71b7053SJung-uk Kim  * https://www.openssl.org/source/license.html
874664626SKris Kennaway  */
974664626SKris Kennaway 
1074664626SKris Kennaway #include <stdio.h>
1174664626SKris Kennaway #include <stdlib.h>
1274664626SKris Kennaway #include <string.h>
13*e71b7053SJung-uk Kim #include <limits.h>
1474664626SKris Kennaway #include "apps.h"
15*e71b7053SJung-uk Kim #include "progs.h"
1674664626SKris Kennaway #include <openssl/bio.h>
1774664626SKris Kennaway #include <openssl/err.h>
1874664626SKris Kennaway #include <openssl/evp.h>
1974664626SKris Kennaway #include <openssl/objects.h>
2074664626SKris Kennaway #include <openssl/x509.h>
21f579bf8eSKris Kennaway #include <openssl/rand.h>
2274664626SKris Kennaway #include <openssl/pem.h>
23a93cbc2bSJung-uk Kim #ifndef OPENSSL_NO_COMP
241f13597dSJung-uk Kim # include <openssl/comp.h>
25a93cbc2bSJung-uk Kim #endif
265c87c606SMark Murray #include <ctype.h>
2774664626SKris Kennaway 
2874664626SKris Kennaway #undef SIZE
2974664626SKris Kennaway #undef BSIZE
3074664626SKris Kennaway #define SIZE    (512)
3174664626SKris Kennaway #define BSIZE   (8*1024)
32*e71b7053SJung-uk Kim 
33*e71b7053SJung-uk Kim static int set_hex(const char *in, unsigned char *out, int size);
34*e71b7053SJung-uk Kim static void show_ciphers(const OBJ_NAME *name, void *bio_);
3574664626SKris Kennaway 
36ed7112f0SJung-uk Kim struct doall_enc_ciphers {
37ed7112f0SJung-uk Kim     BIO *bio;
38ed7112f0SJung-uk Kim     int n;
39ed7112f0SJung-uk Kim };
40ed7112f0SJung-uk Kim 
41*e71b7053SJung-uk Kim typedef enum OPTION_choice {
42*e71b7053SJung-uk Kim     OPT_ERR = -1, OPT_EOF = 0, OPT_HELP,
43*e71b7053SJung-uk Kim     OPT_LIST,
44*e71b7053SJung-uk Kim     OPT_E, OPT_IN, OPT_OUT, OPT_PASS, OPT_ENGINE, OPT_D, OPT_P, OPT_V,
45*e71b7053SJung-uk Kim     OPT_NOPAD, OPT_SALT, OPT_NOSALT, OPT_DEBUG, OPT_UPPER_P, OPT_UPPER_A,
46*e71b7053SJung-uk Kim     OPT_A, OPT_Z, OPT_BUFSIZE, OPT_K, OPT_KFILE, OPT_UPPER_K, OPT_NONE,
47*e71b7053SJung-uk Kim     OPT_UPPER_S, OPT_IV, OPT_MD, OPT_ITER, OPT_PBKDF2, OPT_CIPHER,
48*e71b7053SJung-uk Kim     OPT_R_ENUM
49*e71b7053SJung-uk Kim } OPTION_CHOICE;
50*e71b7053SJung-uk Kim 
51*e71b7053SJung-uk Kim const OPTIONS enc_options[] = {
52*e71b7053SJung-uk Kim     {"help", OPT_HELP, '-', "Display this summary"},
53*e71b7053SJung-uk Kim     {"ciphers", OPT_LIST, '-', "List ciphers"},
54*e71b7053SJung-uk Kim     {"in", OPT_IN, '<', "Input file"},
55*e71b7053SJung-uk Kim     {"out", OPT_OUT, '>', "Output file"},
56*e71b7053SJung-uk Kim     {"pass", OPT_PASS, 's', "Passphrase source"},
57*e71b7053SJung-uk Kim     {"e", OPT_E, '-', "Encrypt"},
58*e71b7053SJung-uk Kim     {"d", OPT_D, '-', "Decrypt"},
59*e71b7053SJung-uk Kim     {"p", OPT_P, '-', "Print the iv/key"},
60*e71b7053SJung-uk Kim     {"P", OPT_UPPER_P, '-', "Print the iv/key and exit"},
61*e71b7053SJung-uk Kim     {"v", OPT_V, '-', "Verbose output"},
62*e71b7053SJung-uk Kim     {"nopad", OPT_NOPAD, '-', "Disable standard block padding"},
63*e71b7053SJung-uk Kim     {"salt", OPT_SALT, '-', "Use salt in the KDF (default)"},
64*e71b7053SJung-uk Kim     {"nosalt", OPT_NOSALT, '-', "Do not use salt in the KDF"},
65*e71b7053SJung-uk Kim     {"debug", OPT_DEBUG, '-', "Print debug info"},
66*e71b7053SJung-uk Kim     {"a", OPT_A, '-', "Base64 encode/decode, depending on encryption flag"},
67*e71b7053SJung-uk Kim     {"base64", OPT_A, '-', "Same as option -a"},
68*e71b7053SJung-uk Kim     {"A", OPT_UPPER_A, '-',
69*e71b7053SJung-uk Kim      "Used with -[base64|a] to specify base64 buffer as a single line"},
70*e71b7053SJung-uk Kim     {"bufsize", OPT_BUFSIZE, 's', "Buffer size"},
71*e71b7053SJung-uk Kim     {"k", OPT_K, 's', "Passphrase"},
72*e71b7053SJung-uk Kim     {"kfile", OPT_KFILE, '<', "Read passphrase from file"},
73*e71b7053SJung-uk Kim     {"K", OPT_UPPER_K, 's', "Raw key, in hex"},
74*e71b7053SJung-uk Kim     {"S", OPT_UPPER_S, 's', "Salt, in hex"},
75*e71b7053SJung-uk Kim     {"iv", OPT_IV, 's', "IV in hex"},
76*e71b7053SJung-uk Kim     {"md", OPT_MD, 's', "Use specified digest to create a key from the passphrase"},
77*e71b7053SJung-uk Kim     {"iter", OPT_ITER, 'p', "Specify the iteration count and force use of PBKDF2"},
78*e71b7053SJung-uk Kim     {"pbkdf2", OPT_PBKDF2, '-', "Use password-based key derivation function 2"},
79*e71b7053SJung-uk Kim     {"none", OPT_NONE, '-', "Don't encrypt"},
80*e71b7053SJung-uk Kim     {"", OPT_CIPHER, '-', "Any supported cipher"},
81*e71b7053SJung-uk Kim     OPT_R_OPTIONS,
82*e71b7053SJung-uk Kim #ifdef ZLIB
83*e71b7053SJung-uk Kim     {"z", OPT_Z, '-', "Use zlib as the 'encryption'"},
84*e71b7053SJung-uk Kim #endif
85*e71b7053SJung-uk Kim #ifndef OPENSSL_NO_ENGINE
86*e71b7053SJung-uk Kim     {"engine", OPT_ENGINE, 's', "Use engine, possibly a hardware device"},
87*e71b7053SJung-uk Kim #endif
88*e71b7053SJung-uk Kim     {NULL}
89*e71b7053SJung-uk Kim };
90*e71b7053SJung-uk Kim 
91*e71b7053SJung-uk Kim int enc_main(int argc, char **argv)
925c87c606SMark Murray {
93*e71b7053SJung-uk Kim     static char buf[128];
94f579bf8eSKris Kennaway     static const char magic[] = "Salted__";
95*e71b7053SJung-uk Kim     ENGINE *e = NULL;
96*e71b7053SJung-uk Kim     BIO *in = NULL, *out = NULL, *b64 = NULL, *benc = NULL, *rbio =
97*e71b7053SJung-uk Kim         NULL, *wbio = NULL;
98*e71b7053SJung-uk Kim     EVP_CIPHER_CTX *ctx = NULL;
99*e71b7053SJung-uk Kim     const EVP_CIPHER *cipher = NULL, *c;
100*e71b7053SJung-uk Kim     const EVP_MD *dgst = NULL;
101*e71b7053SJung-uk Kim     char *hkey = NULL, *hiv = NULL, *hsalt = NULL, *p;
102*e71b7053SJung-uk Kim     char *infile = NULL, *outfile = NULL, *prog;
103*e71b7053SJung-uk Kim     char *str = NULL, *passarg = NULL, *pass = NULL, *strbuf = NULL;
104dee36b4fSJung-uk Kim     char mbuf[sizeof(magic) - 1];
105*e71b7053SJung-uk Kim     OPTION_CHOICE o;
106*e71b7053SJung-uk Kim     int bsize = BSIZE, verbose = 0, debug = 0, olb64 = 0, nosalt = 0;
107*e71b7053SJung-uk Kim     int enc = 1, printkey = 0, i, k;
108*e71b7053SJung-uk Kim     int base64 = 0, informat = FORMAT_BINARY, outformat = FORMAT_BINARY;
109*e71b7053SJung-uk Kim     int ret = 1, inl, nopad = 0;
1105c87c606SMark Murray     unsigned char key[EVP_MAX_KEY_LENGTH], iv[EVP_MAX_IV_LENGTH];
111*e71b7053SJung-uk Kim     unsigned char *buff = NULL, salt[PKCS5_SALT_LEN];
112*e71b7053SJung-uk Kim     int pbkdf2 = 0;
113*e71b7053SJung-uk Kim     int iter = 0;
114*e71b7053SJung-uk Kim     long n;
115*e71b7053SJung-uk Kim     struct doall_enc_ciphers dec;
1161f13597dSJung-uk Kim #ifdef ZLIB
1171f13597dSJung-uk Kim     int do_zlib = 0;
1181f13597dSJung-uk Kim     BIO *bzl = NULL;
1191f13597dSJung-uk Kim #endif
1205c87c606SMark Murray 
12174664626SKris Kennaway     /* first check the program name */
122*e71b7053SJung-uk Kim     prog = opt_progname(argv[0]);
123*e71b7053SJung-uk Kim     if (strcmp(prog, "base64") == 0) {
12474664626SKris Kennaway         base64 = 1;
1251f13597dSJung-uk Kim #ifdef ZLIB
126*e71b7053SJung-uk Kim     } else if (strcmp(prog, "zlib") == 0) {
1271f13597dSJung-uk Kim         do_zlib = 1;
1281f13597dSJung-uk Kim #endif
129*e71b7053SJung-uk Kim     } else {
130*e71b7053SJung-uk Kim         cipher = EVP_get_cipherbyname(prog);
131*e71b7053SJung-uk Kim         if (cipher == NULL && strcmp(prog, "enc") != 0) {
132*e71b7053SJung-uk Kim             BIO_printf(bio_err, "%s is not a known cipher\n", prog);
13374664626SKris Kennaway             goto end;
13474664626SKris Kennaway         }
13574664626SKris Kennaway     }
13674664626SKris Kennaway 
137*e71b7053SJung-uk Kim     prog = opt_init(argc, argv, enc_options);
138*e71b7053SJung-uk Kim     while ((o = opt_next()) != OPT_EOF) {
139*e71b7053SJung-uk Kim         switch (o) {
140*e71b7053SJung-uk Kim         case OPT_EOF:
141*e71b7053SJung-uk Kim         case OPT_ERR:
142*e71b7053SJung-uk Kim  opthelp:
143*e71b7053SJung-uk Kim             BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
144*e71b7053SJung-uk Kim             goto end;
145*e71b7053SJung-uk Kim         case OPT_HELP:
146*e71b7053SJung-uk Kim             opt_help(enc_options);
147*e71b7053SJung-uk Kim             ret = 0;
148*e71b7053SJung-uk Kim             goto end;
149*e71b7053SJung-uk Kim         case OPT_LIST:
150*e71b7053SJung-uk Kim             BIO_printf(bio_out, "Supported ciphers:\n");
151*e71b7053SJung-uk Kim             dec.bio = bio_out;
152*e71b7053SJung-uk Kim             dec.n = 0;
153*e71b7053SJung-uk Kim             OBJ_NAME_do_all_sorted(OBJ_NAME_TYPE_CIPHER_METH,
154*e71b7053SJung-uk Kim                                    show_ciphers, &dec);
155*e71b7053SJung-uk Kim             BIO_printf(bio_out, "\n");
156*e71b7053SJung-uk Kim             ret = 0;
157*e71b7053SJung-uk Kim             goto end;
158*e71b7053SJung-uk Kim         case OPT_E:
159*e71b7053SJung-uk Kim             enc = 1;
160*e71b7053SJung-uk Kim             break;
161*e71b7053SJung-uk Kim         case OPT_IN:
162*e71b7053SJung-uk Kim             infile = opt_arg();
163*e71b7053SJung-uk Kim             break;
164*e71b7053SJung-uk Kim         case OPT_OUT:
165*e71b7053SJung-uk Kim             outfile = opt_arg();
166*e71b7053SJung-uk Kim             break;
167*e71b7053SJung-uk Kim         case OPT_PASS:
168*e71b7053SJung-uk Kim             passarg = opt_arg();
169*e71b7053SJung-uk Kim             break;
170*e71b7053SJung-uk Kim         case OPT_ENGINE:
171*e71b7053SJung-uk Kim             e = setup_engine(opt_arg(), 0);
172*e71b7053SJung-uk Kim             break;
173*e71b7053SJung-uk Kim         case OPT_D:
174*e71b7053SJung-uk Kim             enc = 0;
175*e71b7053SJung-uk Kim             break;
176*e71b7053SJung-uk Kim         case OPT_P:
177*e71b7053SJung-uk Kim             printkey = 1;
178*e71b7053SJung-uk Kim             break;
179*e71b7053SJung-uk Kim         case OPT_V:
180*e71b7053SJung-uk Kim             verbose = 1;
181*e71b7053SJung-uk Kim             break;
182*e71b7053SJung-uk Kim         case OPT_NOPAD:
183*e71b7053SJung-uk Kim             nopad = 1;
184*e71b7053SJung-uk Kim             break;
185*e71b7053SJung-uk Kim         case OPT_SALT:
186*e71b7053SJung-uk Kim             nosalt = 0;
187*e71b7053SJung-uk Kim             break;
188*e71b7053SJung-uk Kim         case OPT_NOSALT:
189*e71b7053SJung-uk Kim             nosalt = 1;
190*e71b7053SJung-uk Kim             break;
191*e71b7053SJung-uk Kim         case OPT_DEBUG:
192*e71b7053SJung-uk Kim             debug = 1;
193*e71b7053SJung-uk Kim             break;
194*e71b7053SJung-uk Kim         case OPT_UPPER_P:
195*e71b7053SJung-uk Kim             printkey = 2;
196*e71b7053SJung-uk Kim             break;
197*e71b7053SJung-uk Kim         case OPT_UPPER_A:
198*e71b7053SJung-uk Kim             olb64 = 1;
199*e71b7053SJung-uk Kim             break;
200*e71b7053SJung-uk Kim         case OPT_A:
201*e71b7053SJung-uk Kim             base64 = 1;
202*e71b7053SJung-uk Kim             break;
203*e71b7053SJung-uk Kim         case OPT_Z:
204*e71b7053SJung-uk Kim #ifdef ZLIB
205*e71b7053SJung-uk Kim             do_zlib = 1;
206*e71b7053SJung-uk Kim #endif
207*e71b7053SJung-uk Kim             break;
208*e71b7053SJung-uk Kim         case OPT_BUFSIZE:
209*e71b7053SJung-uk Kim             p = opt_arg();
210*e71b7053SJung-uk Kim             i = (int)strlen(p) - 1;
211*e71b7053SJung-uk Kim             k = i >= 1 && p[i] == 'k';
212*e71b7053SJung-uk Kim             if (k)
213*e71b7053SJung-uk Kim                 p[i] = '\0';
214*e71b7053SJung-uk Kim             if (!opt_long(opt_arg(), &n)
215*e71b7053SJung-uk Kim                     || n < 0 || (k && n >= LONG_MAX / 1024))
216*e71b7053SJung-uk Kim                 goto opthelp;
217*e71b7053SJung-uk Kim             if (k)
218*e71b7053SJung-uk Kim                 n *= 1024;
219*e71b7053SJung-uk Kim             bsize = (int)n;
220*e71b7053SJung-uk Kim             break;
221*e71b7053SJung-uk Kim         case OPT_K:
222*e71b7053SJung-uk Kim             str = opt_arg();
223*e71b7053SJung-uk Kim             break;
224*e71b7053SJung-uk Kim         case OPT_KFILE:
225*e71b7053SJung-uk Kim             in = bio_open_default(opt_arg(), 'r', FORMAT_TEXT);
226*e71b7053SJung-uk Kim             if (in == NULL)
227*e71b7053SJung-uk Kim                 goto opthelp;
228*e71b7053SJung-uk Kim             i = BIO_gets(in, buf, sizeof(buf));
229*e71b7053SJung-uk Kim             BIO_free(in);
230*e71b7053SJung-uk Kim             in = NULL;
231*e71b7053SJung-uk Kim             if (i <= 0) {
232*e71b7053SJung-uk Kim                 BIO_printf(bio_err,
233*e71b7053SJung-uk Kim                            "%s Can't read key from %s\n", prog, opt_arg());
234*e71b7053SJung-uk Kim                 goto opthelp;
235*e71b7053SJung-uk Kim             }
236*e71b7053SJung-uk Kim             while (--i > 0 && (buf[i] == '\r' || buf[i] == '\n'))
237*e71b7053SJung-uk Kim                 buf[i] = '\0';
238*e71b7053SJung-uk Kim             if (i <= 0) {
239*e71b7053SJung-uk Kim                 BIO_printf(bio_err, "%s: zero length password\n", prog);
240*e71b7053SJung-uk Kim                 goto opthelp;
241*e71b7053SJung-uk Kim             }
242*e71b7053SJung-uk Kim             str = buf;
243*e71b7053SJung-uk Kim             break;
244*e71b7053SJung-uk Kim         case OPT_UPPER_K:
245*e71b7053SJung-uk Kim             hkey = opt_arg();
246*e71b7053SJung-uk Kim             break;
247*e71b7053SJung-uk Kim         case OPT_UPPER_S:
248*e71b7053SJung-uk Kim             hsalt = opt_arg();
249*e71b7053SJung-uk Kim             break;
250*e71b7053SJung-uk Kim         case OPT_IV:
251*e71b7053SJung-uk Kim             hiv = opt_arg();
252*e71b7053SJung-uk Kim             break;
253*e71b7053SJung-uk Kim         case OPT_MD:
254*e71b7053SJung-uk Kim             if (!opt_md(opt_arg(), &dgst))
255*e71b7053SJung-uk Kim                 goto opthelp;
256*e71b7053SJung-uk Kim             break;
257*e71b7053SJung-uk Kim         case OPT_CIPHER:
258*e71b7053SJung-uk Kim             if (!opt_cipher(opt_unknown(), &c))
259*e71b7053SJung-uk Kim                 goto opthelp;
260*e71b7053SJung-uk Kim             cipher = c;
261*e71b7053SJung-uk Kim             break;
262*e71b7053SJung-uk Kim         case OPT_ITER:
263*e71b7053SJung-uk Kim             if (!opt_int(opt_arg(), &iter))
264*e71b7053SJung-uk Kim                 goto opthelp;
265*e71b7053SJung-uk Kim             pbkdf2 = 1;
266*e71b7053SJung-uk Kim             break;
267*e71b7053SJung-uk Kim         case OPT_PBKDF2:
268*e71b7053SJung-uk Kim             pbkdf2 = 1;
269*e71b7053SJung-uk Kim             if (iter == 0)    /* do not overwrite a chosen value */
270*e71b7053SJung-uk Kim                 iter = 10000;
271*e71b7053SJung-uk Kim             break;
272*e71b7053SJung-uk Kim         case OPT_NONE:
273*e71b7053SJung-uk Kim             cipher = NULL;
274*e71b7053SJung-uk Kim             break;
275*e71b7053SJung-uk Kim         case OPT_R_CASES:
276*e71b7053SJung-uk Kim             if (!opt_rand(o))
277*e71b7053SJung-uk Kim                 goto end;
278*e71b7053SJung-uk Kim             break;
279*e71b7053SJung-uk Kim         }
280*e71b7053SJung-uk Kim     }
281*e71b7053SJung-uk Kim     if (opt_num_rest() != 0) {
282*e71b7053SJung-uk Kim         BIO_printf(bio_err, "Extra arguments given.\n");
283*e71b7053SJung-uk Kim         goto opthelp;
284*e71b7053SJung-uk Kim     }
2855c87c606SMark Murray 
2866f9291ceSJung-uk Kim     if (cipher && EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) {
287*e71b7053SJung-uk Kim         BIO_printf(bio_err, "%s: AEAD ciphers not supported\n", prog);
28894ad176cSJung-uk Kim         goto end;
28994ad176cSJung-uk Kim     }
29094ad176cSJung-uk Kim 
2916f9291ceSJung-uk Kim     if (cipher && (EVP_CIPHER_mode(cipher) == EVP_CIPH_XTS_MODE)) {
292*e71b7053SJung-uk Kim         BIO_printf(bio_err, "%s XTS ciphers not supported\n", prog);
293a93cbc2bSJung-uk Kim         goto end;
294a93cbc2bSJung-uk Kim     }
295a93cbc2bSJung-uk Kim 
296*e71b7053SJung-uk Kim     if (dgst == NULL)
297*e71b7053SJung-uk Kim         dgst = EVP_sha256();
2986be8ae07SJacques Vidrine 
299*e71b7053SJung-uk Kim     if (iter == 0)
300*e71b7053SJung-uk Kim         iter = 1;
30174664626SKris Kennaway 
30274664626SKris Kennaway     /* It must be large enough for a base64 encoded line */
303*e71b7053SJung-uk Kim     if (base64 && bsize < 80)
304*e71b7053SJung-uk Kim         bsize = 80;
3056f9291ceSJung-uk Kim     if (verbose)
3066f9291ceSJung-uk Kim         BIO_printf(bio_err, "bufsize=%d\n", bsize);
307*e71b7053SJung-uk Kim 
308*e71b7053SJung-uk Kim #ifdef ZLIB
309*e71b7053SJung-uk Kim     if (!do_zlib)
310*e71b7053SJung-uk Kim #endif
311*e71b7053SJung-uk Kim         if (base64) {
312*e71b7053SJung-uk Kim             if (enc)
313*e71b7053SJung-uk Kim                 outformat = FORMAT_BASE64;
314*e71b7053SJung-uk Kim             else
315*e71b7053SJung-uk Kim                 informat = FORMAT_BASE64;
31674664626SKris Kennaway         }
31774664626SKris Kennaway 
318*e71b7053SJung-uk Kim     strbuf = app_malloc(SIZE, "strbuf");
319*e71b7053SJung-uk Kim     buff = app_malloc(EVP_ENCODE_LENGTH(bsize), "evp buffer");
32074664626SKris Kennaway 
321*e71b7053SJung-uk Kim     if (infile == NULL) {
322*e71b7053SJung-uk Kim         in = dup_bio_in(informat);
3236f9291ceSJung-uk Kim     } else {
324*e71b7053SJung-uk Kim         in = bio_open_default(infile, 'r', informat);
325*e71b7053SJung-uk Kim     }
326*e71b7053SJung-uk Kim     if (in == NULL)
32774664626SKris Kennaway         goto end;
32874664626SKris Kennaway 
329*e71b7053SJung-uk Kim     if (str == NULL && passarg != NULL) {
330*e71b7053SJung-uk Kim         if (!app_passwd(passarg, NULL, &pass, NULL)) {
331f579bf8eSKris Kennaway             BIO_printf(bio_err, "Error getting password\n");
332f579bf8eSKris Kennaway             goto end;
333f579bf8eSKris Kennaway         }
334f579bf8eSKris Kennaway         str = pass;
335f579bf8eSKris Kennaway     }
336f579bf8eSKris Kennaway 
3376f9291ceSJung-uk Kim     if ((str == NULL) && (cipher != NULL) && (hkey == NULL)) {
338*e71b7053SJung-uk Kim         if (1) {
339*e71b7053SJung-uk Kim #ifndef OPENSSL_NO_UI_CONSOLE
3406f9291ceSJung-uk Kim             for (;;) {
341*e71b7053SJung-uk Kim                 char prompt[200];
34274664626SKris Kennaway 
343*e71b7053SJung-uk Kim                 BIO_snprintf(prompt, sizeof(prompt), "enter %s %s password:",
34474664626SKris Kennaway                         OBJ_nid2ln(EVP_CIPHER_nid(cipher)),
34574664626SKris Kennaway                         (enc) ? "encryption" : "decryption");
34674664626SKris Kennaway                 strbuf[0] = '\0';
347*e71b7053SJung-uk Kim                 i = EVP_read_pw_string((char *)strbuf, SIZE, prompt, enc);
3486f9291ceSJung-uk Kim                 if (i == 0) {
3496f9291ceSJung-uk Kim                     if (strbuf[0] == '\0') {
35074664626SKris Kennaway                         ret = 1;
35174664626SKris Kennaway                         goto end;
35274664626SKris Kennaway                     }
35374664626SKris Kennaway                     str = strbuf;
35474664626SKris Kennaway                     break;
35574664626SKris Kennaway                 }
3566f9291ceSJung-uk Kim                 if (i < 0) {
35774664626SKris Kennaway                     BIO_printf(bio_err, "bad password read\n");
35874664626SKris Kennaway                     goto end;
35974664626SKris Kennaway                 }
36074664626SKris Kennaway             }
3616f9291ceSJung-uk Kim         } else {
362*e71b7053SJung-uk Kim #endif
363*e71b7053SJung-uk Kim             BIO_printf(bio_err, "password required\n");
36474664626SKris Kennaway             goto end;
36574664626SKris Kennaway         }
36674664626SKris Kennaway     }
36774664626SKris Kennaway 
368*e71b7053SJung-uk Kim     out = bio_open_default(outfile, 'w', outformat);
369*e71b7053SJung-uk Kim     if (out == NULL)
370*e71b7053SJung-uk Kim         goto end;
371*e71b7053SJung-uk Kim 
372*e71b7053SJung-uk Kim     if (debug) {
373*e71b7053SJung-uk Kim         BIO_set_callback(in, BIO_debug_callback);
374*e71b7053SJung-uk Kim         BIO_set_callback(out, BIO_debug_callback);
375*e71b7053SJung-uk Kim         BIO_set_callback_arg(in, (char *)bio_err);
376*e71b7053SJung-uk Kim         BIO_set_callback_arg(out, (char *)bio_err);
377*e71b7053SJung-uk Kim     }
378*e71b7053SJung-uk Kim 
37974664626SKris Kennaway     rbio = in;
38074664626SKris Kennaway     wbio = out;
38174664626SKris Kennaway 
3821f13597dSJung-uk Kim #ifdef ZLIB
3836f9291ceSJung-uk Kim     if (do_zlib) {
3841f13597dSJung-uk Kim         if ((bzl = BIO_new(BIO_f_zlib())) == NULL)
3851f13597dSJung-uk Kim             goto end;
386*e71b7053SJung-uk Kim         if (debug) {
387*e71b7053SJung-uk Kim             BIO_set_callback(bzl, BIO_debug_callback);
388*e71b7053SJung-uk Kim             BIO_set_callback_arg(bzl, (char *)bio_err);
389*e71b7053SJung-uk Kim         }
3901f13597dSJung-uk Kim         if (enc)
3911f13597dSJung-uk Kim             wbio = BIO_push(bzl, wbio);
3921f13597dSJung-uk Kim         else
3931f13597dSJung-uk Kim             rbio = BIO_push(bzl, rbio);
3941f13597dSJung-uk Kim     }
3951f13597dSJung-uk Kim #endif
3961f13597dSJung-uk Kim 
3976f9291ceSJung-uk Kim     if (base64) {
39874664626SKris Kennaway         if ((b64 = BIO_new(BIO_f_base64())) == NULL)
39974664626SKris Kennaway             goto end;
4006f9291ceSJung-uk Kim         if (debug) {
40174664626SKris Kennaway             BIO_set_callback(b64, BIO_debug_callback);
4025471f83eSSimon L. B. Nielsen             BIO_set_callback_arg(b64, (char *)bio_err);
40374664626SKris Kennaway         }
40474664626SKris Kennaway         if (olb64)
40574664626SKris Kennaway             BIO_set_flags(b64, BIO_FLAGS_BASE64_NO_NL);
40674664626SKris Kennaway         if (enc)
40774664626SKris Kennaway             wbio = BIO_push(b64, wbio);
40874664626SKris Kennaway         else
40974664626SKris Kennaway             rbio = BIO_push(b64, rbio);
41074664626SKris Kennaway     }
41174664626SKris Kennaway 
4126f9291ceSJung-uk Kim     if (cipher != NULL) {
4136f9291ceSJung-uk Kim         /*
4146f9291ceSJung-uk Kim          * Note that str is NULL if a key was passed on the command line, so
4156f9291ceSJung-uk Kim          * we get no salt in that case. Is this a bug?
4165c87c606SMark Murray          */
4176f9291ceSJung-uk Kim         if (str != NULL) {
4186f9291ceSJung-uk Kim             /*
4196f9291ceSJung-uk Kim              * Salt handling: if encrypting generate a salt and write to
4206f9291ceSJung-uk Kim              * output BIO. If decrypting read salt from input BIO.
421f579bf8eSKris Kennaway              */
422f579bf8eSKris Kennaway             unsigned char *sptr;
423*e71b7053SJung-uk Kim             size_t str_len = strlen(str);
424*e71b7053SJung-uk Kim 
425*e71b7053SJung-uk Kim             if (nosalt) {
4266f9291ceSJung-uk Kim                 sptr = NULL;
427*e71b7053SJung-uk Kim             } else {
428f579bf8eSKris Kennaway                 if (enc) {
429f579bf8eSKris Kennaway                     if (hsalt) {
430dee36b4fSJung-uk Kim                         if (!set_hex(hsalt, salt, sizeof(salt))) {
4316f9291ceSJung-uk Kim                             BIO_printf(bio_err, "invalid hex salt value\n");
432f579bf8eSKris Kennaway                             goto end;
433f579bf8eSKris Kennaway                         }
434*e71b7053SJung-uk Kim                     } else if (RAND_bytes(salt, sizeof(salt)) <= 0) {
435f579bf8eSKris Kennaway                         goto end;
436*e71b7053SJung-uk Kim                     }
4376f9291ceSJung-uk Kim                     /*
4386f9291ceSJung-uk Kim                      * If -P option then don't bother writing
4396f9291ceSJung-uk Kim                      */
440f579bf8eSKris Kennaway                     if ((printkey != 2)
441f579bf8eSKris Kennaway                         && (BIO_write(wbio, magic,
442dee36b4fSJung-uk Kim                                       sizeof(magic) - 1) != sizeof(magic) - 1
443f579bf8eSKris Kennaway                             || BIO_write(wbio,
444f579bf8eSKris Kennaway                                          (char *)salt,
445dee36b4fSJung-uk Kim                                          sizeof(salt)) != sizeof(salt))) {
446f579bf8eSKris Kennaway                         BIO_printf(bio_err, "error writing output file\n");
447f579bf8eSKris Kennaway                         goto end;
448f579bf8eSKris Kennaway                     }
449dee36b4fSJung-uk Kim                 } else if (BIO_read(rbio, mbuf, sizeof(mbuf)) != sizeof(mbuf)
450f579bf8eSKris Kennaway                            || BIO_read(rbio,
451f579bf8eSKris Kennaway                                        (unsigned char *)salt,
452dee36b4fSJung-uk Kim                                        sizeof(salt)) != sizeof(salt)) {
453f579bf8eSKris Kennaway                     BIO_printf(bio_err, "error reading input file\n");
454f579bf8eSKris Kennaway                     goto end;
455dee36b4fSJung-uk Kim                 } else if (memcmp(mbuf, magic, sizeof(magic) - 1)) {
456f579bf8eSKris Kennaway                     BIO_printf(bio_err, "bad magic number\n");
457f579bf8eSKris Kennaway                     goto end;
458f579bf8eSKris Kennaway                 }
459f579bf8eSKris Kennaway                 sptr = salt;
460f579bf8eSKris Kennaway             }
461f579bf8eSKris Kennaway 
462*e71b7053SJung-uk Kim             if (pbkdf2 == 1) {
463*e71b7053SJung-uk Kim                 /*
464*e71b7053SJung-uk Kim                 * derive key and default iv
465*e71b7053SJung-uk Kim                 * concatenated into a temporary buffer
466*e71b7053SJung-uk Kim                 */
467*e71b7053SJung-uk Kim                 unsigned char tmpkeyiv[EVP_MAX_KEY_LENGTH + EVP_MAX_IV_LENGTH];
468*e71b7053SJung-uk Kim                 int iklen = EVP_CIPHER_key_length(cipher);
469*e71b7053SJung-uk Kim                 int ivlen = EVP_CIPHER_iv_length(cipher);
470*e71b7053SJung-uk Kim                 /* not needed if HASH_UPDATE() is fixed : */
471*e71b7053SJung-uk Kim                 int islen = (sptr != NULL ? sizeof(salt) : 0);
472*e71b7053SJung-uk Kim                 if (!PKCS5_PBKDF2_HMAC(str, str_len, sptr, islen,
473*e71b7053SJung-uk Kim                                        iter, dgst, iklen+ivlen, tmpkeyiv)) {
474*e71b7053SJung-uk Kim                     BIO_printf(bio_err, "PKCS5_PBKDF2_HMAC failed\n");
475*e71b7053SJung-uk Kim                     goto end;
476*e71b7053SJung-uk Kim                 }
477*e71b7053SJung-uk Kim                 /* split and move data back to global buffer */
478*e71b7053SJung-uk Kim                 memcpy(key, tmpkeyiv, iklen);
479*e71b7053SJung-uk Kim                 memcpy(iv, tmpkeyiv+iklen, ivlen);
480*e71b7053SJung-uk Kim             } else {
481*e71b7053SJung-uk Kim                 BIO_printf(bio_err, "*** WARNING : "
482*e71b7053SJung-uk Kim                                     "deprecated key derivation used.\n"
483*e71b7053SJung-uk Kim                                     "Using -iter or -pbkdf2 would be better.\n");
484*e71b7053SJung-uk Kim                 if (!EVP_BytesToKey(cipher, dgst, sptr,
485*e71b7053SJung-uk Kim                                     (unsigned char *)str, str_len,
486*e71b7053SJung-uk Kim                                     1, key, iv)) {
487*e71b7053SJung-uk Kim                     BIO_printf(bio_err, "EVP_BytesToKey failed\n");
488*e71b7053SJung-uk Kim                     goto end;
489*e71b7053SJung-uk Kim                 }
490*e71b7053SJung-uk Kim             }
4916f9291ceSJung-uk Kim             /*
4926f9291ceSJung-uk Kim              * zero the complete buffer or the string passed from the command
493*e71b7053SJung-uk Kim              * line.
4946f9291ceSJung-uk Kim              */
495f579bf8eSKris Kennaway             if (str == strbuf)
4965c87c606SMark Murray                 OPENSSL_cleanse(str, SIZE);
497f579bf8eSKris Kennaway             else
498*e71b7053SJung-uk Kim                 OPENSSL_cleanse(str, str_len);
499f579bf8eSKris Kennaway         }
500ed6b93beSJung-uk Kim         if (hiv != NULL) {
501ed6b93beSJung-uk Kim             int siz = EVP_CIPHER_iv_length(cipher);
502ed6b93beSJung-uk Kim             if (siz == 0) {
503ed6b93beSJung-uk Kim                 BIO_printf(bio_err, "warning: iv not use by this cipher\n");
504*e71b7053SJung-uk Kim             } else if (!set_hex(hiv, iv, siz)) {
505f579bf8eSKris Kennaway                 BIO_printf(bio_err, "invalid hex iv value\n");
506f579bf8eSKris Kennaway                 goto end;
507f579bf8eSKris Kennaway             }
508ed6b93beSJung-uk Kim         }
509db522d3aSSimon L. B. Nielsen         if ((hiv == NULL) && (str == NULL)
5106f9291ceSJung-uk Kim             && EVP_CIPHER_iv_length(cipher) != 0) {
5116f9291ceSJung-uk Kim             /*
512*e71b7053SJung-uk Kim              * No IV was explicitly set and no IV was generated.
513*e71b7053SJung-uk Kim              * Hence the IV is undefined, making correct decryption impossible.
5146f9291ceSJung-uk Kim              */
51526d191b4SKris Kennaway             BIO_printf(bio_err, "iv undefined\n");
51626d191b4SKris Kennaway             goto end;
51726d191b4SKris Kennaway         }
518*e71b7053SJung-uk Kim         if (hkey != NULL) {
519*e71b7053SJung-uk Kim             if (!set_hex(hkey, key, EVP_CIPHER_key_length(cipher))) {
520f579bf8eSKris Kennaway                 BIO_printf(bio_err, "invalid hex key value\n");
521f579bf8eSKris Kennaway                 goto end;
522f579bf8eSKris Kennaway             }
523*e71b7053SJung-uk Kim             /* wiping secret data as we no longer need it */
524*e71b7053SJung-uk Kim             OPENSSL_cleanse(hkey, strlen(hkey));
525*e71b7053SJung-uk Kim         }
526f579bf8eSKris Kennaway 
527f579bf8eSKris Kennaway         if ((benc = BIO_new(BIO_f_cipher())) == NULL)
528f579bf8eSKris Kennaway             goto end;
5293b4e3dcbSSimon L. B. Nielsen 
5306f9291ceSJung-uk Kim         /*
5316f9291ceSJung-uk Kim          * Since we may be changing parameters work on the encryption context
5326f9291ceSJung-uk Kim          * rather than calling BIO_set_cipher().
5333b4e3dcbSSimon L. B. Nielsen          */
5343b4e3dcbSSimon L. B. Nielsen 
5355c87c606SMark Murray         BIO_get_cipher_ctx(benc, &ctx);
536db522d3aSSimon L. B. Nielsen 
5376f9291ceSJung-uk Kim         if (!EVP_CipherInit_ex(ctx, cipher, NULL, NULL, NULL, enc)) {
5383b4e3dcbSSimon L. B. Nielsen             BIO_printf(bio_err, "Error setting cipher %s\n",
5393b4e3dcbSSimon L. B. Nielsen                        EVP_CIPHER_name(cipher));
5403b4e3dcbSSimon L. B. Nielsen             ERR_print_errors(bio_err);
5413b4e3dcbSSimon L. B. Nielsen             goto end;
5425c87c606SMark Murray         }
5433b4e3dcbSSimon L. B. Nielsen 
5443b4e3dcbSSimon L. B. Nielsen         if (nopad)
5453b4e3dcbSSimon L. B. Nielsen             EVP_CIPHER_CTX_set_padding(ctx, 0);
5463b4e3dcbSSimon L. B. Nielsen 
5476f9291ceSJung-uk Kim         if (!EVP_CipherInit_ex(ctx, NULL, NULL, key, iv, enc)) {
5483b4e3dcbSSimon L. B. Nielsen             BIO_printf(bio_err, "Error setting cipher %s\n",
5493b4e3dcbSSimon L. B. Nielsen                        EVP_CIPHER_name(cipher));
5503b4e3dcbSSimon L. B. Nielsen             ERR_print_errors(bio_err);
5513b4e3dcbSSimon L. B. Nielsen             goto end;
5523b4e3dcbSSimon L. B. Nielsen         }
5533b4e3dcbSSimon L. B. Nielsen 
5546f9291ceSJung-uk Kim         if (debug) {
555f579bf8eSKris Kennaway             BIO_set_callback(benc, BIO_debug_callback);
5565471f83eSSimon L. B. Nielsen             BIO_set_callback_arg(benc, (char *)bio_err);
557f579bf8eSKris Kennaway         }
558f579bf8eSKris Kennaway 
5596f9291ceSJung-uk Kim         if (printkey) {
5606f9291ceSJung-uk Kim             if (!nosalt) {
561f579bf8eSKris Kennaway                 printf("salt=");
5623b4e3dcbSSimon L. B. Nielsen                 for (i = 0; i < (int)sizeof(salt); i++)
563f579bf8eSKris Kennaway                     printf("%02X", salt[i]);
564f579bf8eSKris Kennaway                 printf("\n");
565f579bf8eSKris Kennaway             }
566*e71b7053SJung-uk Kim             if (EVP_CIPHER_key_length(cipher) > 0) {
567f579bf8eSKris Kennaway                 printf("key=");
568*e71b7053SJung-uk Kim                 for (i = 0; i < EVP_CIPHER_key_length(cipher); i++)
569f579bf8eSKris Kennaway                     printf("%02X", key[i]);
570f579bf8eSKris Kennaway                 printf("\n");
571f579bf8eSKris Kennaway             }
572*e71b7053SJung-uk Kim             if (EVP_CIPHER_iv_length(cipher) > 0) {
573f579bf8eSKris Kennaway                 printf("iv =");
574*e71b7053SJung-uk Kim                 for (i = 0; i < EVP_CIPHER_iv_length(cipher); i++)
575f579bf8eSKris Kennaway                     printf("%02X", iv[i]);
576f579bf8eSKris Kennaway                 printf("\n");
577f579bf8eSKris Kennaway             }
5786f9291ceSJung-uk Kim             if (printkey == 2) {
579f579bf8eSKris Kennaway                 ret = 0;
580f579bf8eSKris Kennaway                 goto end;
581f579bf8eSKris Kennaway             }
582f579bf8eSKris Kennaway         }
583f579bf8eSKris Kennaway     }
584f579bf8eSKris Kennaway 
58574664626SKris Kennaway     /* Only encrypt/decrypt as we write the file */
58674664626SKris Kennaway     if (benc != NULL)
58774664626SKris Kennaway         wbio = BIO_push(benc, wbio);
58874664626SKris Kennaway 
5896f9291ceSJung-uk Kim     for (;;) {
59074664626SKris Kennaway         inl = BIO_read(rbio, (char *)buff, bsize);
5916f9291ceSJung-uk Kim         if (inl <= 0)
5926f9291ceSJung-uk Kim             break;
5936f9291ceSJung-uk Kim         if (BIO_write(wbio, (char *)buff, inl) != inl) {
59474664626SKris Kennaway             BIO_printf(bio_err, "error writing output file\n");
59574664626SKris Kennaway             goto end;
59674664626SKris Kennaway         }
59774664626SKris Kennaway     }
5986f9291ceSJung-uk Kim     if (!BIO_flush(wbio)) {
59974664626SKris Kennaway         BIO_printf(bio_err, "bad decrypt\n");
60074664626SKris Kennaway         goto end;
60174664626SKris Kennaway     }
60274664626SKris Kennaway 
60374664626SKris Kennaway     ret = 0;
6046f9291ceSJung-uk Kim     if (verbose) {
605*e71b7053SJung-uk Kim         BIO_printf(bio_err, "bytes read   : %8ju\n", BIO_number_read(in));
606*e71b7053SJung-uk Kim         BIO_printf(bio_err, "bytes written: %8ju\n", BIO_number_written(out));
60774664626SKris Kennaway     }
60874664626SKris Kennaway  end:
609f579bf8eSKris Kennaway     ERR_print_errors(bio_err);
6106f9291ceSJung-uk Kim     OPENSSL_free(strbuf);
6116f9291ceSJung-uk Kim     OPENSSL_free(buff);
6126f9291ceSJung-uk Kim     BIO_free(in);
6136f9291ceSJung-uk Kim     BIO_free_all(out);
6146f9291ceSJung-uk Kim     BIO_free(benc);
6156f9291ceSJung-uk Kim     BIO_free(b64);
6161f13597dSJung-uk Kim #ifdef ZLIB
6176f9291ceSJung-uk Kim     BIO_free(bzl);
6181f13597dSJung-uk Kim #endif
6196cf8931aSJung-uk Kim     release_engine(e);
6206f9291ceSJung-uk Kim     OPENSSL_free(pass);
621*e71b7053SJung-uk Kim     return ret;
62274664626SKris Kennaway }
62374664626SKris Kennaway 
624*e71b7053SJung-uk Kim static void show_ciphers(const OBJ_NAME *name, void *arg)
625*e71b7053SJung-uk Kim {
626*e71b7053SJung-uk Kim     struct doall_enc_ciphers *dec = (struct doall_enc_ciphers *)arg;
627*e71b7053SJung-uk Kim     const EVP_CIPHER *cipher;
628*e71b7053SJung-uk Kim 
629*e71b7053SJung-uk Kim     if (!islower((unsigned char)*name->name))
630*e71b7053SJung-uk Kim         return;
631*e71b7053SJung-uk Kim 
632*e71b7053SJung-uk Kim     /* Filter out ciphers that we cannot use */
633*e71b7053SJung-uk Kim     cipher = EVP_get_cipherbyname(name->name);
634*e71b7053SJung-uk Kim     if (cipher == NULL ||
635*e71b7053SJung-uk Kim             (EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) != 0 ||
636*e71b7053SJung-uk Kim             EVP_CIPHER_mode(cipher) == EVP_CIPH_XTS_MODE)
637*e71b7053SJung-uk Kim         return;
638*e71b7053SJung-uk Kim 
639*e71b7053SJung-uk Kim     BIO_printf(dec->bio, "-%-25s", name->name);
640*e71b7053SJung-uk Kim     if (++dec->n == 3) {
641*e71b7053SJung-uk Kim         BIO_printf(dec->bio, "\n");
642*e71b7053SJung-uk Kim         dec->n = 0;
643*e71b7053SJung-uk Kim     } else
644*e71b7053SJung-uk Kim         BIO_printf(dec->bio, " ");
645*e71b7053SJung-uk Kim }
646*e71b7053SJung-uk Kim 
647*e71b7053SJung-uk Kim static int set_hex(const char *in, unsigned char *out, int size)
64874664626SKris Kennaway {
64974664626SKris Kennaway     int i, n;
65074664626SKris Kennaway     unsigned char j;
65174664626SKris Kennaway 
652*e71b7053SJung-uk Kim     i = size * 2;
65374664626SKris Kennaway     n = strlen(in);
654*e71b7053SJung-uk Kim     if (n > i) {
655*e71b7053SJung-uk Kim         BIO_printf(bio_err, "hex string is too long, ignoring excess\n");
656*e71b7053SJung-uk Kim         n = i; /* ignore exceeding part */
657*e71b7053SJung-uk Kim     } else if (n < i) {
658*e71b7053SJung-uk Kim         BIO_printf(bio_err, "hex string is too short, padding with zero bytes to length\n");
65974664626SKris Kennaway     }
660*e71b7053SJung-uk Kim 
66174664626SKris Kennaway     memset(out, 0, size);
6626f9291ceSJung-uk Kim     for (i = 0; i < n; i++) {
663*e71b7053SJung-uk Kim         j = (unsigned char)*in++;
664*e71b7053SJung-uk Kim         if (!isxdigit(j)) {
66574664626SKris Kennaway             BIO_printf(bio_err, "non-hex digit\n");
666*e71b7053SJung-uk Kim             return 0;
66774664626SKris Kennaway         }
668*e71b7053SJung-uk Kim         j = (unsigned char)OPENSSL_hexchar2int(j);
66974664626SKris Kennaway         if (i & 1)
67074664626SKris Kennaway             out[i / 2] |= j;
67174664626SKris Kennaway         else
67274664626SKris Kennaway             out[i / 2] = (j << 4);
67374664626SKris Kennaway     }
674*e71b7053SJung-uk Kim     return 1;
67574664626SKris Kennaway }
676