17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate * CDDL HEADER START
37c478bd9Sstevel@tonic-gate *
47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the
57c478bd9Sstevel@tonic-gate * Common Development and Distribution License, Version 1.0 only
67c478bd9Sstevel@tonic-gate * (the "License"). You may not use this file except in compliance
77c478bd9Sstevel@tonic-gate * with the License.
87c478bd9Sstevel@tonic-gate *
97c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
107c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing.
117c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions
127c478bd9Sstevel@tonic-gate * and limitations under the License.
137c478bd9Sstevel@tonic-gate *
147c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each
157c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
167c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the
177c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying
187c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner]
197c478bd9Sstevel@tonic-gate *
207c478bd9Sstevel@tonic-gate * CDDL HEADER END
217c478bd9Sstevel@tonic-gate */
2261961e0fSrobinson
237c478bd9Sstevel@tonic-gate /*
24*e8031f0aSraf * Copyright 2006 Sun Microsystems, Inc. All rights reserved.
257c478bd9Sstevel@tonic-gate * Use is subject to license terms.
267c478bd9Sstevel@tonic-gate */
277c478bd9Sstevel@tonic-gate
287c478bd9Sstevel@tonic-gate /* Copyright (c) 1984, 1986, 1987, 1988, 1989 AT&T */
297c478bd9Sstevel@tonic-gate /* All Rights Reserved */
307c478bd9Sstevel@tonic-gate
317c478bd9Sstevel@tonic-gate /*
327c478bd9Sstevel@tonic-gate * Portions of this source code were derived from Berkeley 4.3 BSD
337c478bd9Sstevel@tonic-gate * under license from the Regents of the University of California.
347c478bd9Sstevel@tonic-gate */
357c478bd9Sstevel@tonic-gate
367c478bd9Sstevel@tonic-gate /*
37*e8031f0aSraf * DES encryption library routines
387c478bd9Sstevel@tonic-gate */
397c478bd9Sstevel@tonic-gate
40*e8031f0aSraf #include "mt.h"
417c478bd9Sstevel@tonic-gate #include <unistd.h>
427c478bd9Sstevel@tonic-gate #include <fcntl.h>
437c478bd9Sstevel@tonic-gate #include <sys/types.h>
447c478bd9Sstevel@tonic-gate #include <rpc/des_crypt.h>
457c478bd9Sstevel@tonic-gate #ifdef sun
467c478bd9Sstevel@tonic-gate #include <sys/ioctl.h>
477c478bd9Sstevel@tonic-gate #include <sys/des.h>
487c478bd9Sstevel@tonic-gate #define getdesfd() (open("/dev/des", 0, 0))
497c478bd9Sstevel@tonic-gate #else
507c478bd9Sstevel@tonic-gate #include <des/des.h>
517c478bd9Sstevel@tonic-gate #endif
527c478bd9Sstevel@tonic-gate #include <rpc/rpc.h>
537c478bd9Sstevel@tonic-gate
5461961e0fSrobinson extern int __des_crypt(char *, unsigned, struct desparams *);
557c478bd9Sstevel@tonic-gate
5661961e0fSrobinson static int common_crypt(char *, char *, unsigned, unsigned, struct desparams *);
577c478bd9Sstevel@tonic-gate
587c478bd9Sstevel@tonic-gate /*
597c478bd9Sstevel@tonic-gate * To see if chip is installed
607c478bd9Sstevel@tonic-gate */
617c478bd9Sstevel@tonic-gate #define UNOPENED (-2)
627c478bd9Sstevel@tonic-gate static int g_desfd = UNOPENED;
637c478bd9Sstevel@tonic-gate
647c478bd9Sstevel@tonic-gate
657c478bd9Sstevel@tonic-gate /*
667c478bd9Sstevel@tonic-gate * Copy 8 bytes
677c478bd9Sstevel@tonic-gate */
687c478bd9Sstevel@tonic-gate #define COPY8(src, dst) { \
6961961e0fSrobinson char *a = (char *)dst; \
7061961e0fSrobinson char *b = (char *)src; \
717c478bd9Sstevel@tonic-gate *a++ = *b++; *a++ = *b++; *a++ = *b++; *a++ = *b++; \
727c478bd9Sstevel@tonic-gate *a++ = *b++; *a++ = *b++; *a++ = *b++; *a++ = *b++; \
737c478bd9Sstevel@tonic-gate }
747c478bd9Sstevel@tonic-gate
757c478bd9Sstevel@tonic-gate /*
767c478bd9Sstevel@tonic-gate * Copy multiple of 8 bytes
777c478bd9Sstevel@tonic-gate */
787c478bd9Sstevel@tonic-gate #define DESCOPY(src, dst, len) { \
7961961e0fSrobinson char *a = (char *)dst; \
8061961e0fSrobinson char *b = (char *)src; \
8161961e0fSrobinson int i; \
827c478bd9Sstevel@tonic-gate for (i = (int)len; i > 0; i -= 8) { \
837c478bd9Sstevel@tonic-gate *a++ = *b++; *a++ = *b++; *a++ = *b++; *a++ = *b++; \
847c478bd9Sstevel@tonic-gate *a++ = *b++; *a++ = *b++; *a++ = *b++; *a++ = *b++; \
857c478bd9Sstevel@tonic-gate } \
867c478bd9Sstevel@tonic-gate }
877c478bd9Sstevel@tonic-gate
887c478bd9Sstevel@tonic-gate /*
897c478bd9Sstevel@tonic-gate * CBC mode encryption
907c478bd9Sstevel@tonic-gate */
917c478bd9Sstevel@tonic-gate int
cbc_crypt(char * key,char * buf,size_t len,unsigned int mode,char * ivec)927c478bd9Sstevel@tonic-gate cbc_crypt(char *key, char *buf, size_t len, unsigned int mode, char *ivec)
937c478bd9Sstevel@tonic-gate {
947c478bd9Sstevel@tonic-gate int err;
957c478bd9Sstevel@tonic-gate struct desparams dp;
967c478bd9Sstevel@tonic-gate
977c478bd9Sstevel@tonic-gate dp.des_mode = CBC;
987c478bd9Sstevel@tonic-gate COPY8(ivec, dp.des_ivec);
997c478bd9Sstevel@tonic-gate err = common_crypt(key, buf, len, mode, &dp);
1007c478bd9Sstevel@tonic-gate COPY8(dp.des_ivec, ivec);
1017c478bd9Sstevel@tonic-gate return (err);
1027c478bd9Sstevel@tonic-gate }
1037c478bd9Sstevel@tonic-gate
1047c478bd9Sstevel@tonic-gate
1057c478bd9Sstevel@tonic-gate /*
1067c478bd9Sstevel@tonic-gate * ECB mode encryption
1077c478bd9Sstevel@tonic-gate */
1087c478bd9Sstevel@tonic-gate int
ecb_crypt(char * key,char * buf,size_t len,unsigned int mode)1097c478bd9Sstevel@tonic-gate ecb_crypt(char *key, char *buf, size_t len, unsigned int mode)
1107c478bd9Sstevel@tonic-gate {
1117c478bd9Sstevel@tonic-gate struct desparams dp;
1127c478bd9Sstevel@tonic-gate
1137c478bd9Sstevel@tonic-gate dp.des_mode = ECB;
11461961e0fSrobinson return (common_crypt(key, buf, len, mode, &dp));
1157c478bd9Sstevel@tonic-gate }
1167c478bd9Sstevel@tonic-gate
1177c478bd9Sstevel@tonic-gate
1187c478bd9Sstevel@tonic-gate
1197c478bd9Sstevel@tonic-gate /*
1207c478bd9Sstevel@tonic-gate * Common code to cbc_crypt() & ecb_crypt()
1217c478bd9Sstevel@tonic-gate */
1227c478bd9Sstevel@tonic-gate static int
common_crypt(char * key,char * buf,unsigned len,unsigned mode,struct desparams * desp)12361961e0fSrobinson common_crypt(char *key, char *buf, unsigned len, unsigned mode,
12461961e0fSrobinson struct desparams *desp)
1257c478bd9Sstevel@tonic-gate {
12661961e0fSrobinson int desdev;
12761961e0fSrobinson int res;
1287c478bd9Sstevel@tonic-gate
12961961e0fSrobinson if ((len % 8) != 0 || len > DES_MAXDATA)
1307c478bd9Sstevel@tonic-gate return (DESERR_BADPARAM);
1317c478bd9Sstevel@tonic-gate desp->des_dir =
1327c478bd9Sstevel@tonic-gate ((mode & DES_DIRMASK) == DES_ENCRYPT) ? ENCRYPT : DECRYPT;
1337c478bd9Sstevel@tonic-gate
1347c478bd9Sstevel@tonic-gate desdev = mode & DES_DEVMASK;
1357c478bd9Sstevel@tonic-gate COPY8(key, desp->des_key);
1367c478bd9Sstevel@tonic-gate #ifdef sun
1377c478bd9Sstevel@tonic-gate if (desdev == DES_HW) {
1387c478bd9Sstevel@tonic-gate if (g_desfd < 0) {
1397c478bd9Sstevel@tonic-gate if (g_desfd == -1 || (g_desfd = getdesfd()) < 0) {
1407c478bd9Sstevel@tonic-gate goto software; /* no hardware device */
1417c478bd9Sstevel@tonic-gate }
1427c478bd9Sstevel@tonic-gate }
1437c478bd9Sstevel@tonic-gate
1447c478bd9Sstevel@tonic-gate /*
1457c478bd9Sstevel@tonic-gate * hardware
1467c478bd9Sstevel@tonic-gate */
1477c478bd9Sstevel@tonic-gate desp->des_len = len;
1487c478bd9Sstevel@tonic-gate if (len <= DES_QUICKLEN) {
1497c478bd9Sstevel@tonic-gate DESCOPY(buf, desp->des_data, len);
1507c478bd9Sstevel@tonic-gate res = ioctl(g_desfd, DESIOCQUICK, (char *)desp);
1517c478bd9Sstevel@tonic-gate DESCOPY(desp->des_data, buf, len);
1527c478bd9Sstevel@tonic-gate } else {
15361961e0fSrobinson desp->des_buf = (uchar_t *)buf;
1547c478bd9Sstevel@tonic-gate res = ioctl(g_desfd, DESIOCBLOCK, (char *)desp);
1557c478bd9Sstevel@tonic-gate }
1567c478bd9Sstevel@tonic-gate return (res == 0 ? DESERR_NONE : DESERR_HWERROR);
1577c478bd9Sstevel@tonic-gate }
1587c478bd9Sstevel@tonic-gate software:
1597c478bd9Sstevel@tonic-gate #endif
1607c478bd9Sstevel@tonic-gate /*
1617c478bd9Sstevel@tonic-gate * software
1627c478bd9Sstevel@tonic-gate */
16361961e0fSrobinson if (!__des_crypt(buf, len, desp))
1647c478bd9Sstevel@tonic-gate return (DESERR_HWERROR);
1657c478bd9Sstevel@tonic-gate return (desdev == DES_SW ? DESERR_NONE : DESERR_NOHWDEVICE);
1667c478bd9Sstevel@tonic-gate }
1677c478bd9Sstevel@tonic-gate
1687c478bd9Sstevel@tonic-gate static int
desN_crypt(des_block keys[],int keynum,char * buf,unsigned int len,unsigned int mode,char * ivec)1697c478bd9Sstevel@tonic-gate desN_crypt(des_block keys[], int keynum, char *buf, unsigned int len,
1707c478bd9Sstevel@tonic-gate unsigned int mode, char *ivec)
1717c478bd9Sstevel@tonic-gate {
1727c478bd9Sstevel@tonic-gate unsigned int m = mode & (DES_ENCRYPT | DES_DECRYPT);
1737c478bd9Sstevel@tonic-gate unsigned int flags = mode & ~(DES_ENCRYPT | DES_DECRYPT);
1747c478bd9Sstevel@tonic-gate des_block svec, dvec;
1757c478bd9Sstevel@tonic-gate int i, j, stat;
1767c478bd9Sstevel@tonic-gate
1777c478bd9Sstevel@tonic-gate if (keynum < 1)
1787c478bd9Sstevel@tonic-gate return (DESERR_BADPARAM);
1797c478bd9Sstevel@tonic-gate
1807c478bd9Sstevel@tonic-gate (void) memcpy(svec.c, ivec, sizeof (des_block));
1817c478bd9Sstevel@tonic-gate for (i = 0; i < keynum; i++) {
1827c478bd9Sstevel@tonic-gate j = (mode & DES_DECRYPT) ? keynum - 1 - i : i;
1837c478bd9Sstevel@tonic-gate stat = cbc_crypt(keys[j].c, buf, len, m | flags, ivec);
1847c478bd9Sstevel@tonic-gate if (mode & DES_DECRYPT && i == 0)
1857c478bd9Sstevel@tonic-gate (void) memcpy(dvec.c, ivec, sizeof (des_block));
1867c478bd9Sstevel@tonic-gate
1877c478bd9Sstevel@tonic-gate if (DES_FAILED(stat))
1887c478bd9Sstevel@tonic-gate return (stat);
1897c478bd9Sstevel@tonic-gate
1907c478bd9Sstevel@tonic-gate m = (m == DES_ENCRYPT ? DES_DECRYPT : DES_ENCRYPT);
1917c478bd9Sstevel@tonic-gate
1927c478bd9Sstevel@tonic-gate if ((mode & DES_DECRYPT) || i != keynum - 1 || i%2)
1937c478bd9Sstevel@tonic-gate (void) memcpy(ivec, svec.c, sizeof (des_block));
1947c478bd9Sstevel@tonic-gate }
1957c478bd9Sstevel@tonic-gate if (keynum % 2 == 0)
1967c478bd9Sstevel@tonic-gate stat = cbc_crypt(keys[0].c, buf, len, mode, ivec);
1977c478bd9Sstevel@tonic-gate
1987c478bd9Sstevel@tonic-gate if (mode & DES_DECRYPT)
1997c478bd9Sstevel@tonic-gate (void) memcpy(ivec, dvec.c, sizeof (des_block));
2007c478bd9Sstevel@tonic-gate
2017c478bd9Sstevel@tonic-gate return (stat);
2027c478bd9Sstevel@tonic-gate }
2037c478bd9Sstevel@tonic-gate
2047c478bd9Sstevel@tonic-gate
2057c478bd9Sstevel@tonic-gate
2067c478bd9Sstevel@tonic-gate int
__cbc_triple_crypt(des_block keys[],char * buf,uint_t len,uint_t mode,char * ivec)20761961e0fSrobinson __cbc_triple_crypt(des_block keys[], char *buf, uint_t len,
20861961e0fSrobinson uint_t mode, char *ivec)
2097c478bd9Sstevel@tonic-gate {
2107c478bd9Sstevel@tonic-gate return (desN_crypt(keys, 3, buf, len, mode, ivec));
2117c478bd9Sstevel@tonic-gate }
212