1*b077aed3SPierre Pronchery /*
2*b077aed3SPierre Pronchery * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
3*b077aed3SPierre Pronchery *
4*b077aed3SPierre Pronchery * Licensed under the Apache License 2.0 (the "License"). You may not use
5*b077aed3SPierre Pronchery * this file except in compliance with the License. You can obtain a copy
6*b077aed3SPierre Pronchery * in the file LICENSE in the source distribution or at
7*b077aed3SPierre Pronchery * https://www.openssl.org/source/license.html
8*b077aed3SPierre Pronchery */
9*b077aed3SPierre Pronchery
10*b077aed3SPierre Pronchery #include "apps.h"
11*b077aed3SPierre Pronchery #include <openssl/bio.h>
12*b077aed3SPierre Pronchery #include <openssl/err.h>
13*b077aed3SPierre Pronchery #include <openssl/rand.h>
14*b077aed3SPierre Pronchery #include <openssl/conf.h>
15*b077aed3SPierre Pronchery
16*b077aed3SPierre Pronchery static char *save_rand_file;
STACK_OF(OPENSSL_STRING)17*b077aed3SPierre Pronchery static STACK_OF(OPENSSL_STRING) *randfiles;
18*b077aed3SPierre Pronchery
19*b077aed3SPierre Pronchery void app_RAND_load_conf(CONF *c, const char *section)
20*b077aed3SPierre Pronchery {
21*b077aed3SPierre Pronchery const char *randfile = NCONF_get_string(c, section, "RANDFILE");
22*b077aed3SPierre Pronchery
23*b077aed3SPierre Pronchery if (randfile == NULL) {
24*b077aed3SPierre Pronchery ERR_clear_error();
25*b077aed3SPierre Pronchery return;
26*b077aed3SPierre Pronchery }
27*b077aed3SPierre Pronchery if (RAND_load_file(randfile, -1) < 0) {
28*b077aed3SPierre Pronchery BIO_printf(bio_err, "Can't load %s into RNG\n", randfile);
29*b077aed3SPierre Pronchery ERR_print_errors(bio_err);
30*b077aed3SPierre Pronchery }
31*b077aed3SPierre Pronchery if (save_rand_file == NULL) {
32*b077aed3SPierre Pronchery save_rand_file = OPENSSL_strdup(randfile);
33*b077aed3SPierre Pronchery /* If some internal memory errors have occurred */
34*b077aed3SPierre Pronchery if (save_rand_file == NULL) {
35*b077aed3SPierre Pronchery BIO_printf(bio_err, "Can't duplicate %s\n", randfile);
36*b077aed3SPierre Pronchery ERR_print_errors(bio_err);
37*b077aed3SPierre Pronchery }
38*b077aed3SPierre Pronchery }
39*b077aed3SPierre Pronchery }
40*b077aed3SPierre Pronchery
loadfiles(char * name)41*b077aed3SPierre Pronchery static int loadfiles(char *name)
42*b077aed3SPierre Pronchery {
43*b077aed3SPierre Pronchery char *p;
44*b077aed3SPierre Pronchery int last, ret = 1;
45*b077aed3SPierre Pronchery
46*b077aed3SPierre Pronchery for ( ; ; ) {
47*b077aed3SPierre Pronchery last = 0;
48*b077aed3SPierre Pronchery for (p = name; *p != '\0' && *p != LIST_SEPARATOR_CHAR; p++)
49*b077aed3SPierre Pronchery continue;
50*b077aed3SPierre Pronchery if (*p == '\0')
51*b077aed3SPierre Pronchery last = 1;
52*b077aed3SPierre Pronchery *p = '\0';
53*b077aed3SPierre Pronchery if (RAND_load_file(name, -1) < 0) {
54*b077aed3SPierre Pronchery BIO_printf(bio_err, "Can't load %s into RNG\n", name);
55*b077aed3SPierre Pronchery ERR_print_errors(bio_err);
56*b077aed3SPierre Pronchery ret = 0;
57*b077aed3SPierre Pronchery }
58*b077aed3SPierre Pronchery if (last)
59*b077aed3SPierre Pronchery break;
60*b077aed3SPierre Pronchery name = p + 1;
61*b077aed3SPierre Pronchery if (*name == '\0')
62*b077aed3SPierre Pronchery break;
63*b077aed3SPierre Pronchery }
64*b077aed3SPierre Pronchery return ret;
65*b077aed3SPierre Pronchery }
66*b077aed3SPierre Pronchery
app_RAND_load(void)67*b077aed3SPierre Pronchery int app_RAND_load(void)
68*b077aed3SPierre Pronchery {
69*b077aed3SPierre Pronchery char *p;
70*b077aed3SPierre Pronchery int i, ret = 1;
71*b077aed3SPierre Pronchery
72*b077aed3SPierre Pronchery for (i = 0; i < sk_OPENSSL_STRING_num(randfiles); i++) {
73*b077aed3SPierre Pronchery p = sk_OPENSSL_STRING_value(randfiles, i);
74*b077aed3SPierre Pronchery if (!loadfiles(p))
75*b077aed3SPierre Pronchery ret = 0;
76*b077aed3SPierre Pronchery }
77*b077aed3SPierre Pronchery sk_OPENSSL_STRING_free(randfiles);
78*b077aed3SPierre Pronchery return ret;
79*b077aed3SPierre Pronchery }
80*b077aed3SPierre Pronchery
app_RAND_write(void)81*b077aed3SPierre Pronchery int app_RAND_write(void)
82*b077aed3SPierre Pronchery {
83*b077aed3SPierre Pronchery int ret = 1;
84*b077aed3SPierre Pronchery
85*b077aed3SPierre Pronchery if (save_rand_file == NULL)
86*b077aed3SPierre Pronchery return 1;
87*b077aed3SPierre Pronchery if (RAND_write_file(save_rand_file) == -1) {
88*b077aed3SPierre Pronchery BIO_printf(bio_err, "Cannot write random bytes:\n");
89*b077aed3SPierre Pronchery ERR_print_errors(bio_err);
90*b077aed3SPierre Pronchery ret = 0;
91*b077aed3SPierre Pronchery }
92*b077aed3SPierre Pronchery OPENSSL_free(save_rand_file);
93*b077aed3SPierre Pronchery save_rand_file = NULL;
94*b077aed3SPierre Pronchery return ret;
95*b077aed3SPierre Pronchery }
96*b077aed3SPierre Pronchery
97*b077aed3SPierre Pronchery
98*b077aed3SPierre Pronchery /*
99*b077aed3SPierre Pronchery * See comments in opt_verify for explanation of this.
100*b077aed3SPierre Pronchery */
101*b077aed3SPierre Pronchery enum r_range { OPT_R_ENUM };
102*b077aed3SPierre Pronchery
opt_rand(int opt)103*b077aed3SPierre Pronchery int opt_rand(int opt)
104*b077aed3SPierre Pronchery {
105*b077aed3SPierre Pronchery switch ((enum r_range)opt) {
106*b077aed3SPierre Pronchery case OPT_R__FIRST:
107*b077aed3SPierre Pronchery case OPT_R__LAST:
108*b077aed3SPierre Pronchery break;
109*b077aed3SPierre Pronchery case OPT_R_RAND:
110*b077aed3SPierre Pronchery if (randfiles == NULL
111*b077aed3SPierre Pronchery && (randfiles = sk_OPENSSL_STRING_new_null()) == NULL)
112*b077aed3SPierre Pronchery return 0;
113*b077aed3SPierre Pronchery if (!sk_OPENSSL_STRING_push(randfiles, opt_arg()))
114*b077aed3SPierre Pronchery return 0;
115*b077aed3SPierre Pronchery break;
116*b077aed3SPierre Pronchery case OPT_R_WRITERAND:
117*b077aed3SPierre Pronchery OPENSSL_free(save_rand_file);
118*b077aed3SPierre Pronchery save_rand_file = OPENSSL_strdup(opt_arg());
119*b077aed3SPierre Pronchery if (save_rand_file == NULL)
120*b077aed3SPierre Pronchery return 0;
121*b077aed3SPierre Pronchery break;
122*b077aed3SPierre Pronchery }
123*b077aed3SPierre Pronchery return 1;
124*b077aed3SPierre Pronchery }
125