Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Remove sign and verify ops from key types | lloyd | 2010-03-05 | 6 | -109/+0 |
| | |||||
* | Remove ECDSA_PublicKey::verify | lloyd | 2010-03-05 | 2 | -40/+0 |
| | |||||
* | Rename PK_Ops::Signature_Operation to PK_Ops::Signature | lloyd | 2010-03-05 | 13 | -20/+20 |
| | | | | Rename PK_Ops::KA_Operation to PK_Ops::Key_Agreement | ||||
* | Remove NR and DSA specific hooks | lloyd | 2010-03-05 | 18 | -626/+5 |
| | |||||
* | Add verification ops for all signature key types | lloyd | 2010-03-05 | 19 | -146/+409 |
| | |||||
* | Make the modulus visible in Modular_Reducer | lloyd | 2010-03-05 | 1 | -0/+2 |
| | |||||
* | Inline look_pk funcs | lloyd | 2010-03-05 | 3 | -102/+49 |
| | |||||
* | Remove the sign() operation from the public key objects, totally replaced | lloyd | 2010-03-05 | 17 | -358/+153 |
| | | | | | | by using the ops. Add real ECDSA test vectors (two found in ANSI X9.62) | ||||
* | Force high bit in random_prime as well (done by randomize currently, but ↵ | lloyd | 2010-03-05 | 1 | -0/+3 |
| | | | | might not be later) | ||||
* | Clarify exception text on get_affine when point is zero | lloyd | 2010-03-05 | 1 | -2/+2 |
| | |||||
* | Add -Werror to gcc maintainer flags | lloyd | 2010-03-05 | 1 | -1/+1 |
| | |||||
* | Add signature generation operation classes. Remove sign() from | lloyd | 2010-03-05 | 20 | -72/+474 |
| | | | | | | PK_Signing_Key, though for the moment the class remains because there are a few pieces of code that use it to detect if signatures are supported, or for passing to functions in look_pk | ||||
* | The operation can assume the key will continue to exist as long as it does, | lloyd | 2010-03-04 | 2 | -7/+6 |
| | | | | so keep the curve and cofactor in ECDH op by reference instead of value. | ||||
* | Remove some unnecessary usages of PK_Signing_Key | lloyd | 2010-03-04 | 3 | -54/+30 |
| | |||||
* | Nix PK_Signing_Key use from tutorial | lloyd | 2010-03-04 | 1 | -3/+1 |
| | |||||
* | Client_Key_Exchange needs modification for DH changes | lloyd | 2010-03-04 | 1 | -14/+14 |
| | |||||
* | This checkin represents a pretty major change in how PK operations are | lloyd | 2010-03-04 | 24 | -420/+265 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | performed. Up until now, each key object (eg DSA_PublicKey or ECDH_PrivateKey) had two jobs: contain the key material, and know how to perform any operations on that key. However because of a desire to support alternative implementations (GNU MP, hardware, whatever), there was a notion of operations, with the key objects containing an op that they got via engine rather than actually implementing the underlying algorithms directly. Now, represent the operation as an abstract interface (typically mapping a byte string to a byte string), and pass a plain Public_Key& or Private_Key& to the engine. The engine does any checks it wants (eg based on name, typeid, key sizes, etc), and either returns nothing (I'll pass) or a pointer to a new operation that represents signatures or encryption or what-have-you using that key. This means that plain key objects no longer contain operations. This is a major break with the traditional interface. On the other hand, using these 'bare' operations without padding, KDFs, etc is 99% of the time a bad idea anyway (and if you really need them, there are options so you get the bare op but via the pubkey.h interfaces). Currently this change is only implemented for DH and ECDH (ie, key agreement algorithms). Additionally the optional engines (gnump and openssl) have not been updated. I'll probably wait to touch those until after I can change them all in one go for all algos. | ||||
* | Use KDF2/PK_Key_Agreement in DH benchmark | lloyd | 2010-03-04 | 1 | -5/+5 |
| | |||||
* | Clean up PK_Key_Agreement slightly | lloyd | 2010-03-04 | 2 | -21/+32 |
| | |||||
* | Fix typos | lloyd | 2010-03-04 | 1 | -2/+2 |
| | |||||
* | Inline simple DSA funcs | lloyd | 2010-03-04 | 2 | -21/+6 |
| | |||||
* | Remove ElGamal load hook functions | lloyd | 2010-03-04 | 2 | -47/+23 |
| | |||||
* | Remove NR load hooks | lloyd | 2010-03-04 | 2 | -58/+34 |
| | |||||
* | Remove no-op DH_Public_Key::X509_load_hook | lloyd | 2010-03-04 | 2 | -12/+1 |
| | |||||
* | Remove DSA load hooks functions | lloyd | 2010-03-04 | 2 | -32/+17 |
| | |||||
* | Cleanups | lloyd | 2010-03-04 | 1 | -5/+4 |
| | |||||
* | Remove IF_Scheme_PrivateKey::PKCS8_load_hook | lloyd | 2010-03-04 | 6 | -35/+30 |
| | |||||
* | New IF constructors, simplifies RSA/RW | lloyd | 2010-03-04 | 6 | -72/+67 |
| | |||||
* | Remove DH_PrivateKey::PKCS8_load_hook | lloyd | 2010-03-04 | 2 | -15/+23 |
| | |||||
* | More keygen tests | lloyd | 2010-03-04 | 1 | -0/+8 |
| | |||||
* | Remove unnecessary virtual destructors from ECC key base types | lloyd | 2010-03-04 | 1 | -4/+0 |
| | | | | (already have them, via Public_Key's virtual destructor) | ||||
* | Add back the Integrity_Failure exception. For one, removing it causes | lloyd | 2010-03-04 | 1 | -0/+9 |
| | | | | | problems for Monotone, and anyway it is a reasonable exception to have around for signalling MAC validation errors, etc. | ||||
* | Test GOST with 521-bit prime field (was setting off bug before) | lloyd | 2010-03-04 | 1 | -1/+1 |
| | |||||
* | Fix GOST pubkey encoding when x.bytes() != y.bytes() | lloyd | 2010-03-04 | 1 | -1/+1 |
| | |||||
* | Fix exception text | lloyd | 2010-03-04 | 1 | -1/+1 |
| | |||||
* | Quite the hack, here. | lloyd | 2010-03-04 | 3 | -1/+11 |
| | | | | | | | | | | | | | | | | | GOST 34.10 public keys use a funky encoding. There is no standard for PKCS #8 format private keys, so the obvious choice is to act exactly the same as ECDSA/ECDH (following the rule of thumb that if you're going to make up a random non-standard thing, at least try to copy something that's standard for something else). However the public key encoding uses a weird scheme for encoding the OID in the algorithm identifier, which we don't want to use for the PKCS #8 encoding. Add a new function to Private_Key, pkcs8_algorithm_identifier, which by default just calls algorithm_identifier(). However GOST_3410_PrivateKey overrides it, and calls EC_PublicKey::algorithm_identifier(), basically skipping over the virtual function hierarchy, so it doesn't pick up the funky format from the public key's version of algorithm_identifier(). | ||||
* | Split up load/store tests public vs private | lloyd | 2010-03-04 | 1 | -11/+29 |
| | |||||
* | For each keygen tests, save the file as pem then reload it. | lloyd | 2010-03-04 | 1 | -27/+80 |
| | |||||
* | Fix GOST 34.10 pubkey encoding | lloyd | 2010-03-04 | 2 | -3/+13 |
| | |||||
* | Fix loading ElGamal keys | lloyd | 2010-03-04 | 1 | -6/+4 |
| | |||||
* | Catch parse errors in OID, throw Invalid_OID | lloyd | 2010-03-04 | 1 | -1/+9 |
| | |||||
* | Fix ElGamal pubkey encoding (OID was unknown) | lloyd | 2010-03-04 | 1 | -1/+1 |
| | |||||
* | Catch any exception for parsing name, assume it's a bad OID | lloyd | 2010-03-04 | 1 | -1/+1 |
| | |||||
* | Changes to CVC to deal with the fact that you can't create an uninitialized | lloyd | 2010-03-04 | 3 | -8/+10 |
| | | | | ECDSA_PublicKey object anymore. | ||||
* | Remove more load hooks | lloyd | 2010-03-04 | 7 | -17/+10 |
| | |||||
* | Remove load hooks from ECC classes, unused | lloyd | 2010-03-04 | 3 | -21/+16 |
| | |||||
* | Kill pkcs8_decoder | lloyd | 2010-03-04 | 8 | -158/+0 |
| | |||||
* | Add similar decoding constructors to the private keys | lloyd | 2010-03-04 | 18 | -85/+167 |
| | |||||
* | Remove X509_Decoder. Fix GOST-34.10 DER constructor (was default to normal ECC) | lloyd | 2010-03-04 | 10 | -173/+24 |
| | |||||
* | Add a new constructor to each public key algorithm (only the public | lloyd | 2010-03-04 | 21 | -211/+195 |
| | | | | | | | keys so far, private keys not changed) that takes an AlgorithmIdentifier and a MemoryRegion<byte>&. This performs the X.509 decoding. It is not possible anymore to create uninitialized PK objects. |