blob: 7077cb3a5b14d2f6db77da138fed9f6e234edbd4 [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/**
2 * \file dhm.h
Paul Bakkere0ccd0a2009-01-04 16:27:10 +00003 *
Rose Zadik41ad0822018-01-26 10:54:57 +00004 * \brief Diffie-Hellman-Merkle key exchange.
5 *
6 * <em>RFC-3526: More Modular Exponential (MODP) Diffie-Hellman groups for
7 * Internet Key Exchange (IKE)</em> defines a number of standardized
8 * Diffie-Hellman groups for IKE.
9 *
10 * <em>RFC-5114: Additional Diffie-Hellman Groups for Use with IETF
11 * Standards</em> defines a number of standardized Diffie-Hellman
12 * groups that can be used.
Paul Bakker37ca75d2011-01-06 12:28:03 +000013 *
Jaeden Amero784de592018-01-26 17:52:01 +000014 * \warning The security of the DHM key exchange relies on the proper choice
15 * of prime modulus - optimally, it should be a safe prime. The usage
16 * of non-safe primes both decreases the difficulty of the underlying
17 * discrete logarithm problem and can lead to small subgroup attacks
18 * leaking private exponent bits when invalid public keys are used
19 * and not detected. This is especially relevant if the same DHM
20 * parameters are reused for multiple key exchanges as in static DHM,
21 * while the criticality of small-subgroup attacks is lower for
22 * ephemeral DHM.
23 *
24 * \warning For performance reasons, the code does neither perform primality
25 * nor safe primality tests, nor the expensive checks for invalid
26 * subgroups. Moreover, even if these were performed, non-standardized
27 * primes cannot be trusted because of the possibility of backdoors
28 * that can't be effectively checked for.
29 *
30 * \warning Diffie-Hellman-Merkle is therefore a security risk when not using
31 * standardized primes generated using a trustworthy ("nothing up
32 * my sleeve") method, such as the RFC 3526 / 7919 primes. In the TLS
33 * protocol, DH parameters need to be negotiated, so using the default
34 * primes systematically is not always an option. If possible, use
35 * Elliptic Curve Diffie-Hellman (ECDH), which has better performance,
36 * and for which the TLS protocol mandates the use of standard
37 * parameters.
38 *
Darryl Greena40a1012018-01-05 15:33:17 +000039 */
40/*
Rose Zadik41ad0822018-01-26 10:54:57 +000041 * Copyright (C) 2006-2018, Arm Limited (or its affiliates), All Rights Reserved
Bence Szépkúti4e9f7122020-06-05 13:02:18 +020042 * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
43 *
44 * This file is provided under the Apache License 2.0, or the
45 * GNU General Public License v2.0 or later.
46 *
47 * **********
48 * Apache License 2.0:
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +020049 *
50 * Licensed under the Apache License, Version 2.0 (the "License"); you may
51 * not use this file except in compliance with the License.
52 * You may obtain a copy of the License at
53 *
54 * http://www.apache.org/licenses/LICENSE-2.0
55 *
56 * Unless required by applicable law or agreed to in writing, software
57 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
58 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
59 * See the License for the specific language governing permissions and
60 * limitations under the License.
Paul Bakkerb96f1542010-07-18 20:36:00 +000061 *
Bence Szépkúti4e9f7122020-06-05 13:02:18 +020062 * **********
63 *
64 * **********
65 * GNU General Public License v2.0 or later:
66 *
67 * This program is free software; you can redistribute it and/or modify
68 * it under the terms of the GNU General Public License as published by
69 * the Free Software Foundation; either version 2 of the License, or
70 * (at your option) any later version.
71 *
72 * This program is distributed in the hope that it will be useful,
73 * but WITHOUT ANY WARRANTY; without even the implied warranty of
74 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
75 * GNU General Public License for more details.
76 *
77 * You should have received a copy of the GNU General Public License along
78 * with this program; if not, write to the Free Software Foundation, Inc.,
79 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
80 *
81 * **********
82 *
Rose Zadik41ad0822018-01-26 10:54:57 +000083 * This file is part of Mbed TLS (https://tls.mbed.org)
Paul Bakker5121ce52009-01-03 21:22:43 +000084 */
Rose Zadik41ad0822018-01-26 10:54:57 +000085
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020086#ifndef MBEDTLS_DHM_H
87#define MBEDTLS_DHM_H
Paul Bakker5121ce52009-01-03 21:22:43 +000088
Reuven Levin1f35ca92017-12-07 10:09:32 +000089#if !defined(MBEDTLS_CONFIG_FILE)
90#include "config.h"
91#else
92#include MBEDTLS_CONFIG_FILE
93#endif
Paul Bakker314052f2011-08-15 09:07:52 +000094#include "bignum.h"
Reuven Levin1f35ca92017-12-07 10:09:32 +000095#if !defined(MBEDTLS_DHM_ALT)
96
Paul Bakkerf3b86c12011-01-27 15:24:17 +000097/*
98 * DHM Error codes
99 */
Rose Zadik41ad0822018-01-26 10:54:57 +0000100#define MBEDTLS_ERR_DHM_BAD_INPUT_DATA -0x3080 /**< Bad input parameters. */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200101#define MBEDTLS_ERR_DHM_READ_PARAMS_FAILED -0x3100 /**< Reading of the DHM parameters failed. */
102#define MBEDTLS_ERR_DHM_MAKE_PARAMS_FAILED -0x3180 /**< Making of the DHM parameters failed. */
103#define MBEDTLS_ERR_DHM_READ_PUBLIC_FAILED -0x3200 /**< Reading of the public values failed. */
104#define MBEDTLS_ERR_DHM_MAKE_PUBLIC_FAILED -0x3280 /**< Making of the public value failed. */
105#define MBEDTLS_ERR_DHM_CALC_SECRET_FAILED -0x3300 /**< Calculation of the DHM secret failed. */
106#define MBEDTLS_ERR_DHM_INVALID_FORMAT -0x3380 /**< The ASN.1 data is not formatted correctly. */
Manuel Pégourié-Gonnard6a8ca332015-05-28 09:33:39 +0200107#define MBEDTLS_ERR_DHM_ALLOC_FAILED -0x3400 /**< Allocation of memory failed. */
Rose Zadik41ad0822018-01-26 10:54:57 +0000108#define MBEDTLS_ERR_DHM_FILE_IO_ERROR -0x3480 /**< Read or write of file failed. */
Gilles Peskine7ecab3d2018-01-26 17:56:38 +0100109#define MBEDTLS_ERR_DHM_HW_ACCEL_FAILED -0x3500 /**< DHM hardware accelerator failed. */
Jaeden Amero2acbf172018-01-26 20:57:38 +0000110#define MBEDTLS_ERR_DHM_SET_GROUP_FAILED -0x3580 /**< Setting the modulus and generator failed. */
Paul Bakker29b64762012-09-25 09:36:44 +0000111
Paul Bakker407a0da2013-06-27 14:29:21 +0200112#ifdef __cplusplus
113extern "C" {
114#endif
115
Paul Bakker29b64762012-09-25 09:36:44 +0000116/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000117 * \brief The DHM context structure.
Paul Bakkerf3b86c12011-01-27 15:24:17 +0000118 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000119typedef struct
120{
Rose Zadik41ad0822018-01-26 10:54:57 +0000121 size_t len; /*!< The size of \p P in Bytes. */
122 mbedtls_mpi P; /*!< The prime modulus. */
123 mbedtls_mpi G; /*!< The generator. */
124 mbedtls_mpi X; /*!< Our secret value. */
125 mbedtls_mpi GX; /*!< Our public key = \c G^X mod \c P. */
126 mbedtls_mpi GY; /*!< The public key of the peer = \c G^Y mod \c P. */
127 mbedtls_mpi K; /*!< The shared secret = \c G^(XY) mod \c P. */
128 mbedtls_mpi RP; /*!< The cached value = \c R^2 mod \c P. */
129 mbedtls_mpi Vi; /*!< The blinding value. */
130 mbedtls_mpi Vf; /*!< The unblinding value. */
131 mbedtls_mpi pX; /*!< The previous \c X. */
Paul Bakker5121ce52009-01-03 21:22:43 +0000132}
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200133mbedtls_dhm_context;
Paul Bakker5121ce52009-01-03 21:22:43 +0000134
Paul Bakker5121ce52009-01-03 21:22:43 +0000135/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000136 * \brief This function initializes the DHM context.
Paul Bakker8f870b02014-06-20 13:32:38 +0200137 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000138 * \param ctx The DHM context to initialize.
Paul Bakker8f870b02014-06-20 13:32:38 +0200139 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200140void mbedtls_dhm_init( mbedtls_dhm_context *ctx );
Paul Bakker8f870b02014-06-20 13:32:38 +0200141
142/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000143 * \brief This function parses the ServerKeyExchange parameters.
Paul Bakker5121ce52009-01-03 21:22:43 +0000144 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000145 * \param ctx The DHM context.
Hanno Beckerf240ea02017-10-02 15:09:14 +0100146 * \param p On input, *p must be the start of the input buffer.
147 * On output, *p is updated to point to the end of the data
148 * that has been read. On success, this is the first byte
149 * past the end of the ServerKeyExchange parameters.
150 * On error, this is the point at which an error has been
151 * detected, which is usually not useful except to debug
152 * failures.
Rose Zadik41ad0822018-01-26 10:54:57 +0000153 * \param end The end of the input buffer.
Paul Bakker5121ce52009-01-03 21:22:43 +0000154 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000155 * \return \c 0 on success, or an \c MBEDTLS_ERR_DHM_XXX error code
156 * on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000157 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200158int mbedtls_dhm_read_params( mbedtls_dhm_context *ctx,
Paul Bakker5121ce52009-01-03 21:22:43 +0000159 unsigned char **p,
Paul Bakkerff60ee62010-03-16 21:09:09 +0000160 const unsigned char *end );
Paul Bakker5121ce52009-01-03 21:22:43 +0000161
162/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000163 * \brief This function sets up and writes the ServerKeyExchange
164 * parameters.
Paul Bakker5121ce52009-01-03 21:22:43 +0000165 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000166 * \param ctx The DHM context.
167 * \param x_size The private value size in Bytes.
168 * \param olen The number of characters written.
169 * \param output The destination buffer.
170 * \param f_rng The RNG function.
171 * \param p_rng The RNG parameter.
Paul Bakker5121ce52009-01-03 21:22:43 +0000172 *
Hanno Beckere7643242017-09-28 10:33:11 +0100173 * \note The destination buffer must be large enough to hold
Hanno Becker70da2c52017-10-02 15:02:59 +0100174 * the reduced binary presentation of the modulus, the generator
175 * and the public key, each wrapped with a 2-byte length field.
176 * It is the responsibility of the caller to ensure that enough
177 * space is available. Refer to \c mbedtls_mpi_size to computing
178 * the byte-size of an MPI.
Hanno Beckere7643242017-09-28 10:33:11 +0100179 *
Jaeden Amero9564e972018-01-30 16:56:13 +0000180 * \note This function assumes that \c ctx->P and \c ctx->G
Hanno Becker8880e752017-10-04 13:15:08 +0100181 * have already been properly set. For that, use
Jaeden Amero9564e972018-01-30 16:56:13 +0000182 * mbedtls_dhm_set_group() below in conjunction with
183 * mbedtls_mpi_read_binary() and mbedtls_mpi_read_string().
Paul Bakker5121ce52009-01-03 21:22:43 +0000184 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000185 * \return \c 0 on success, or an \c MBEDTLS_ERR_DHM_XXX error code
186 * on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000187 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200188int mbedtls_dhm_make_params( mbedtls_dhm_context *ctx, int x_size,
Paul Bakker23986e52011-04-24 08:57:21 +0000189 unsigned char *output, size_t *olen,
Paul Bakkera3d195c2011-11-27 21:07:34 +0000190 int (*f_rng)(void *, unsigned char *, size_t),
191 void *p_rng );
Paul Bakker5121ce52009-01-03 21:22:43 +0000192
193/**
Hanno Becker8880e752017-10-04 13:15:08 +0100194 * \brief Set prime modulus and generator
195 *
Jaeden Amero9564e972018-01-30 16:56:13 +0000196 * \param ctx The DHM context.
197 * \param P The MPI holding DHM prime modulus.
198 * \param G The MPI holding DHM generator.
Hanno Becker8880e752017-10-04 13:15:08 +0100199 *
200 * \note This function can be used to set P, G
201 * in preparation for \c mbedtls_dhm_make_params.
202 *
Jaeden Amero9564e972018-01-30 16:56:13 +0000203 * \return \c 0 if successful, or an \c MBEDTLS_ERR_DHM_XXX error code
204 * on failure.
Hanno Becker8880e752017-10-04 13:15:08 +0100205 */
206int mbedtls_dhm_set_group( mbedtls_dhm_context *ctx,
207 const mbedtls_mpi *P,
208 const mbedtls_mpi *G );
209
210/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000211 * \brief This function imports the public value G^Y of the peer.
Paul Bakker5121ce52009-01-03 21:22:43 +0000212 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000213 * \param ctx The DHM context.
214 * \param input The input buffer.
215 * \param ilen The size of the input buffer.
Paul Bakker5121ce52009-01-03 21:22:43 +0000216 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000217 * \return \c 0 on success, or an \c MBEDTLS_ERR_DHM_XXX error code
218 * on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000219 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200220int mbedtls_dhm_read_public( mbedtls_dhm_context *ctx,
Paul Bakker23986e52011-04-24 08:57:21 +0000221 const unsigned char *input, size_t ilen );
Paul Bakker5121ce52009-01-03 21:22:43 +0000222
223/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000224 * \brief This function creates its own private value \c X and
225 * exports \c G^X.
Paul Bakker5121ce52009-01-03 21:22:43 +0000226 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000227 * \param ctx The DHM context.
228 * \param x_size The private value size in Bytes.
229 * \param output The destination buffer.
230 * \param olen The length of the destination buffer. Must be at least
231 equal to ctx->len (the size of \c P).
232 * \param f_rng The RNG function.
233 * \param p_rng The RNG parameter.
Paul Bakker5121ce52009-01-03 21:22:43 +0000234 *
Hanno Beckere7643242017-09-28 10:33:11 +0100235 * \note The destination buffer will always be fully written
236 * so as to contain a big-endian presentation of G^X mod P.
237 * If it is larger than ctx->len, it will accordingly be
238 * padded with zero-bytes in the beginning.
239 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000240 * \return \c 0 on success, or an \c MBEDTLS_ERR_DHM_XXX error code
241 * on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000242 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200243int mbedtls_dhm_make_public( mbedtls_dhm_context *ctx, int x_size,
Paul Bakker23986e52011-04-24 08:57:21 +0000244 unsigned char *output, size_t olen,
Paul Bakkera3d195c2011-11-27 21:07:34 +0000245 int (*f_rng)(void *, unsigned char *, size_t),
246 void *p_rng );
Paul Bakker5121ce52009-01-03 21:22:43 +0000247
248/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000249 * \brief This function derives and exports the shared secret
250 * \c (G^Y)^X mod \c P.
Paul Bakker5121ce52009-01-03 21:22:43 +0000251 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000252 * \param ctx The DHM context.
253 * \param output The destination buffer.
Jaeden Amero9564e972018-01-30 16:56:13 +0000254 * \param output_size The size of the destination buffer. Must be at least
255 * the size of ctx->len.
Rose Zadik41ad0822018-01-26 10:54:57 +0000256 * \param olen On exit, holds the actual number of Bytes written.
257 * \param f_rng The RNG function, for blinding purposes.
258 * \param p_rng The RNG parameter.
Paul Bakker5121ce52009-01-03 21:22:43 +0000259 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000260 * \return \c 0 on success, or an \c MBEDTLS_ERR_DHM_XXX error code
261 * on failure.
Manuel Pégourié-Gonnard143b5022013-09-04 16:29:59 +0200262 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000263 * \note If non-NULL, \p f_rng is used to blind the input as
264 * a countermeasure against timing attacks. Blinding is used
265 * only if our secret value \p X is re-used and omitted
266 * otherwise. Therefore, we recommend always passing a
267 * non-NULL \p f_rng argument.
Paul Bakker5121ce52009-01-03 21:22:43 +0000268 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200269int mbedtls_dhm_calc_secret( mbedtls_dhm_context *ctx,
Manuel Pégourié-Gonnard33352052015-06-02 16:17:08 +0100270 unsigned char *output, size_t output_size, size_t *olen,
Manuel Pégourié-Gonnard2d627642013-09-04 14:22:07 +0200271 int (*f_rng)(void *, unsigned char *, size_t),
272 void *p_rng );
Paul Bakker5121ce52009-01-03 21:22:43 +0000273
Paul Bakker9a736322012-11-14 12:39:52 +0000274/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000275 * \brief This function frees and clears the components of a DHM key.
Paul Bakker8f870b02014-06-20 13:32:38 +0200276 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000277 * \param ctx The DHM context to free and clear.
Paul Bakker5121ce52009-01-03 21:22:43 +0000278 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200279void mbedtls_dhm_free( mbedtls_dhm_context *ctx );
Paul Bakker5121ce52009-01-03 21:22:43 +0000280
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200281#if defined(MBEDTLS_ASN1_PARSE_C)
Paul Bakker40ce79f2013-09-15 17:43:54 +0200282/** \ingroup x509_module */
283/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000284 * \brief This function parses DHM parameters in PEM or DER format.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200285 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000286 * \param dhm The DHM context to initialize.
287 * \param dhmin The input buffer.
288 * \param dhminlen The size of the buffer, including the terminating null
289 * Byte for PEM data.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200290 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000291 * \return \c 0 on success, or a specific DHM or PEM error code
292 * on failure.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200293 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200294int mbedtls_dhm_parse_dhm( mbedtls_dhm_context *dhm, const unsigned char *dhmin,
Paul Bakker40ce79f2013-09-15 17:43:54 +0200295 size_t dhminlen );
296
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200297#if defined(MBEDTLS_FS_IO)
Paul Bakker40ce79f2013-09-15 17:43:54 +0200298/** \ingroup x509_module */
299/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000300 * \brief This function loads and parses DHM parameters from a file.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200301 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000302 * \param dhm The DHM context to load the parameters to.
303 * \param path The filename to read the DHM parameters from.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200304 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000305 * \return \c 0 on success, or a specific DHM or PEM error code
306 * on failure.
Paul Bakker40ce79f2013-09-15 17:43:54 +0200307 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200308int mbedtls_dhm_parse_dhmfile( mbedtls_dhm_context *dhm, const char *path );
309#endif /* MBEDTLS_FS_IO */
310#endif /* MBEDTLS_ASN1_PARSE_C */
nirekh01d569ecf2018-01-09 16:43:21 +0000311
312#ifdef __cplusplus
313}
314#endif
315
316#else /* MBEDTLS_DHM_ALT */
Reuven Levin1f35ca92017-12-07 10:09:32 +0000317#include "dhm_alt.h"
318#endif /* MBEDTLS_DHM_ALT */
Paul Bakker40ce79f2013-09-15 17:43:54 +0200319
nirekh01d569ecf2018-01-09 16:43:21 +0000320#ifdef __cplusplus
321extern "C" {
322#endif
323
Paul Bakker5121ce52009-01-03 21:22:43 +0000324/**
Rose Zadik41ad0822018-01-26 10:54:57 +0000325 * \brief The DMH checkup routine.
Paul Bakker5121ce52009-01-03 21:22:43 +0000326 *
Rose Zadik41ad0822018-01-26 10:54:57 +0000327 * \return \c 0 on success, or \c 1 on failure.
Paul Bakker5121ce52009-01-03 21:22:43 +0000328 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200329int mbedtls_dhm_self_test( int verbose );
Paul Bakker5121ce52009-01-03 21:22:43 +0000330
331#ifdef __cplusplus
332}
333#endif
334
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100335/**
336 * RFC 3526, RFC 5114 and RFC 7919 standardize a number of
337 * Diffie-Hellman groups, some of which are included here
338 * for use within the SSL/TLS module and the user's convenience
339 * when configuring the Diffie-Hellman parameters by hand
340 * through \c mbedtls_ssl_conf_dh_param.
341 *
Jaeden Amero9564e972018-01-30 16:56:13 +0000342 * The following lists the source of the above groups in the standards:
343 * - RFC 5114 section 2.2: 2048-bit MODP Group with 224-bit Prime Order Subgroup
344 * - RFC 3526 section 3: 2048-bit MODP Group
345 * - RFC 3526 section 4: 3072-bit MODP Group
346 * - RFC 3526 section 5: 4096-bit MODP Group
347 * - RFC 7919 section A.1: ffdhe2048
348 * - RFC 7919 section A.2: ffdhe3072
349 * - RFC 7919 section A.3: ffdhe4096
350 * - RFC 7919 section A.4: ffdhe6144
351 * - RFC 7919 section A.5: ffdhe8192
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100352 *
353 * The constants with suffix "_p" denote the chosen prime moduli, while
354 * the constants with suffix "_g" denote the chosen generator
355 * of the associated prime field.
356 *
357 * The constants further suffixed with "_bin" are provided in binary format,
358 * while all other constants represent null-terminated strings holding the
359 * hexadecimal presentation of the respective numbers.
360 *
361 * The primes from RFC 3526 and RFC 7919 have been generating by the following
362 * trust-worthy procedure:
363 * - Fix N in { 2048, 3072, 4096, 6144, 8192 } and consider the N-bit number
364 * the first and last 64 bits are all 1, and the remaining N - 128 bits of
365 * which are 0x7ff...ff.
366 * - Add the smallest multiple of the first N - 129 bits of the binary expansion
367 * of pi (for RFC 5236) or e (for RFC 7919) to this intermediate bit-string
368 * such that the resulting integer is a safe-prime.
369 * - The result is the respective RFC 3526 / 7919 prime, and the corresponding
370 * generator is always chosen to be 2 (which is a square for these prime,
371 * hence the corresponding subgroup has order (p-1)/2 and avoids leaking a
372 * bit in the private exponent).
373 *
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100374 */
375
376#if !defined(MBEDTLS_DEPRECATED_REMOVED)
377
378#if defined(MBEDTLS_DEPRECATED_WARNING)
379#define MBEDTLS_DEPRECATED __attribute__((deprecated))
Jaeden Amero784de592018-01-26 17:52:01 +0000380MBEDTLS_DEPRECATED typedef char const * mbedtls_deprecated_constant_t;
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100381#define MBEDTLS_DEPRECATED_STRING_CONSTANT( VAL ) \
Jaeden Amero784de592018-01-26 17:52:01 +0000382 ( (mbedtls_deprecated_constant_t) ( VAL ) )
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100383#else
384#define MBEDTLS_DEPRECATED_STRING_CONSTANT( VAL ) VAL
385#endif /* ! MBEDTLS_DEPRECATED_WARNING */
386
387/**
388 * \warning The origin of the primes in RFC 5114 is not documented and
389 * their use therefore constitutes a security risk!
390 *
391 * \deprecated The hex-encoded primes from RFC 5114 are deprecated and are
392 * likely to be removed in a future version of the library without
393 * replacement.
394 */
395
Jaeden Amero9564e972018-01-30 16:56:13 +0000396/**
397 * The hexadecimal presentation of the prime underlying the
398 * 2048-bit MODP Group with 224-bit Prime Order Subgroup, as defined
399 * in <em>RFC-5114: Additional Diffie-Hellman Groups for Use with
400 * IETF Standards</em>.
401 */
Jaeden Amero129f5082018-02-08 14:25:36 +0000402#define MBEDTLS_DHM_RFC5114_MODP_2048_P \
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100403 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
404 "AD107E1E9123A9D0D660FAA79559C51FA20D64E5683B9FD1" \
405 "B54B1597B61D0A75E6FA141DF95A56DBAF9A3C407BA1DF15" \
406 "EB3D688A309C180E1DE6B85A1274A0A66D3F8152AD6AC212" \
407 "9037C9EDEFDA4DF8D91E8FEF55B7394B7AD5B7D0B6C12207" \
408 "C9F98D11ED34DBF6C6BA0B2C8BBC27BE6A00E0A0B9C49708" \
409 "B3BF8A317091883681286130BC8985DB1602E714415D9330" \
410 "278273C7DE31EFDC7310F7121FD5A07415987D9ADC0A486D" \
411 "CDF93ACC44328387315D75E198C641A480CD86A1B9E587E8" \
412 "BE60E69CC928B2B9C52172E413042E9B23F10B0E16E79763" \
413 "C9B53DCF4BA80A29E3FB73C16B8E75B97EF363E2FFA31F71" \
414 "CF9DE5384E71B81C0AC4DFFE0C10E64F" )
415
Jaeden Amero9564e972018-01-30 16:56:13 +0000416/**
417 * The hexadecimal presentation of the chosen generator of the 2048-bit MODP
418 * Group with 224-bit Prime Order Subgroup, as defined in <em>RFC-5114:
419 * Additional Diffie-Hellman Groups for Use with IETF Standards</em>.
420 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100421#define MBEDTLS_DHM_RFC5114_MODP_2048_G \
422 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
423 "AC4032EF4F2D9AE39DF30B5C8FFDAC506CDEBE7B89998CAF" \
424 "74866A08CFE4FFE3A6824A4E10B9A6F0DD921F01A70C4AFA" \
425 "AB739D7700C29F52C57DB17C620A8652BE5E9001A8D66AD7" \
426 "C17669101999024AF4D027275AC1348BB8A762D0521BC98A" \
427 "E247150422EA1ED409939D54DA7460CDB5F6C6B250717CBE" \
428 "F180EB34118E98D119529A45D6F834566E3025E316A330EF" \
429 "BB77A86F0C1AB15B051AE3D428C8F8ACB70A8137150B8EEB" \
430 "10E183EDD19963DDD9E263E4770589EF6AA21E7F5F2FF381" \
431 "B539CCE3409D13CD566AFBB48D6C019181E1BCFE94B30269" \
432 "EDFE72FE9B6AA4BD7B5A0F1C71CFFF4C19C418E1F6EC0179" \
433 "81BC087F2A7065B384B890D3191F2BFA" )
434
435/**
Jaeden Amero9564e972018-01-30 16:56:13 +0000436 * The hexadecimal presentation of the prime underlying the 2048-bit MODP
437 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
438 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
439 *
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100440 * \deprecated The hex-encoded primes from RFC 3625 are deprecated and
441 * superseded by the corresponding macros providing them as
442 * binary constants. Their hex-encoded constants are likely
443 * to be removed in a future version of the library.
444 *
445 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100446#define MBEDTLS_DHM_RFC3526_MODP_2048_P \
447 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
448 "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
449 "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
450 "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
451 "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
452 "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
453 "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
454 "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
455 "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
456 "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
457 "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
458 "15728E5A8AACAA68FFFFFFFFFFFFFFFF" )
459
Jaeden Amero9564e972018-01-30 16:56:13 +0000460/**
461 * The hexadecimal presentation of the chosen generator of the 2048-bit MODP
462 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
463 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
464 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100465#define MBEDTLS_DHM_RFC3526_MODP_2048_G \
Hanno Becker5e6b8d72017-10-04 13:41:36 +0100466 MBEDTLS_DEPRECATED_STRING_CONSTANT( "02" )
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100467
Jaeden Amero9564e972018-01-30 16:56:13 +0000468/**
469 * The hexadecimal presentation of the prime underlying the 3072-bit MODP
470 * Group, as defined in <em>RFC-3072: More Modular Exponential (MODP)
471 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
472 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100473#define MBEDTLS_DHM_RFC3526_MODP_3072_P \
474 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
475 "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
476 "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
477 "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
478 "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
479 "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
480 "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
481 "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
482 "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
483 "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
484 "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
485 "15728E5A8AAAC42DAD33170D04507A33A85521ABDF1CBA64" \
486 "ECFB850458DBEF0A8AEA71575D060C7DB3970F85A6E1E4C7" \
487 "ABF5AE8CDB0933D71E8C94E04A25619DCEE3D2261AD2EE6B" \
488 "F12FFA06D98A0864D87602733EC86A64521F2B18177B200C" \
489 "BBE117577A615D6C770988C0BAD946E208E24FA074E5AB31" \
490 "43DB5BFCE0FD108E4B82D120A93AD2CAFFFFFFFFFFFFFFFF" )
491
Jaeden Amero9564e972018-01-30 16:56:13 +0000492/**
493 * The hexadecimal presentation of the chosen generator of the 3072-bit MODP
494 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
495 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
496 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100497#define MBEDTLS_DHM_RFC3526_MODP_3072_G \
Hanno Becker5e6b8d72017-10-04 13:41:36 +0100498 MBEDTLS_DEPRECATED_STRING_CONSTANT( "02" )
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100499
Jaeden Amero9564e972018-01-30 16:56:13 +0000500/**
501 * The hexadecimal presentation of the prime underlying the 4096-bit MODP
502 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
503 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
504 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100505#define MBEDTLS_DHM_RFC3526_MODP_4096_P \
506 MBEDTLS_DEPRECATED_STRING_CONSTANT( \
507 "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD1" \
508 "29024E088A67CC74020BBEA63B139B22514A08798E3404DD" \
509 "EF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245" \
510 "E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7ED" \
511 "EE386BFB5A899FA5AE9F24117C4B1FE649286651ECE45B3D" \
512 "C2007CB8A163BF0598DA48361C55D39A69163FA8FD24CF5F" \
513 "83655D23DCA3AD961C62F356208552BB9ED529077096966D" \
514 "670C354E4ABC9804F1746C08CA18217C32905E462E36CE3B" \
515 "E39E772C180E86039B2783A2EC07A28FB5C55DF06F4C52C9" \
516 "DE2BCBF6955817183995497CEA956AE515D2261898FA0510" \
517 "15728E5A8AAAC42DAD33170D04507A33A85521ABDF1CBA64" \
518 "ECFB850458DBEF0A8AEA71575D060C7DB3970F85A6E1E4C7" \
519 "ABF5AE8CDB0933D71E8C94E04A25619DCEE3D2261AD2EE6B" \
520 "F12FFA06D98A0864D87602733EC86A64521F2B18177B200C" \
521 "BBE117577A615D6C770988C0BAD946E208E24FA074E5AB31" \
522 "43DB5BFCE0FD108E4B82D120A92108011A723C12A787E6D7" \
523 "88719A10BDBA5B2699C327186AF4E23C1A946834B6150BDA" \
524 "2583E9CA2AD44CE8DBBBC2DB04DE8EF92E8EFC141FBECAA6" \
525 "287C59474E6BC05D99B2964FA090C3A2233BA186515BE7ED" \
526 "1F612970CEE2D7AFB81BDD762170481CD0069127D5B05AA9" \
527 "93B4EA988D8FDDC186FFB7DC90A6C08F4DF435C934063199" \
528 "FFFFFFFFFFFFFFFF" )
529
Jaeden Amero9564e972018-01-30 16:56:13 +0000530/**
531 * The hexadecimal presentation of the chosen generator of the 4096-bit MODP
532 * Group, as defined in <em>RFC-3526: More Modular Exponential (MODP)
533 * Diffie-Hellman groups for Internet Key Exchange (IKE)</em>.
534 */
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100535#define MBEDTLS_DHM_RFC3526_MODP_4096_G \
Hanno Becker5e6b8d72017-10-04 13:41:36 +0100536 MBEDTLS_DEPRECATED_STRING_CONSTANT( "02" )
Hanno Beckere2fcfa82017-10-04 13:12:15 +0100537
538#endif /* MBEDTLS_DEPRECATED_REMOVED */
539
540/*
541 * Trustworthy DHM parameters in binary form
542 */
543
544#define MBEDTLS_DHM_RFC3526_MODP_2048_P_BIN { \
545 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
546 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
547 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
548 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
549 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
550 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
551 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
552 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
553 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
554 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
555 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
556 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
557 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
558 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
559 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
560 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
561 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
562 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
563 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
564 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
565 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
566 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
567 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
568 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
569 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
570 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
571 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
572 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
573 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
574 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
575 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAC, 0xAA, 0x68, \
576 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
577
578#define MBEDTLS_DHM_RFC3526_MODP_2048_G_BIN { 0x02 }
579
580#define MBEDTLS_DHM_RFC3526_MODP_3072_P_BIN { \
581 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
582 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
583 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
584 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
585 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
586 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
587 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
588 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
589 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
590 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
591 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
592 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
593 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
594 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
595 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
596 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
597 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
598 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
599 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
600 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
601 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
602 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
603 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
604 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
605 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
606 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
607 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
608 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
609 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
610 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
611 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAA, 0xC4, 0x2D, \
612 0xAD, 0x33, 0x17, 0x0D, 0x04, 0x50, 0x7A, 0x33, \
613 0xA8, 0x55, 0x21, 0xAB, 0xDF, 0x1C, 0xBA, 0x64, \
614 0xEC, 0xFB, 0x85, 0x04, 0x58, 0xDB, 0xEF, 0x0A, \
615 0x8A, 0xEA, 0x71, 0x57, 0x5D, 0x06, 0x0C, 0x7D, \
616 0xB3, 0x97, 0x0F, 0x85, 0xA6, 0xE1, 0xE4, 0xC7, \
617 0xAB, 0xF5, 0xAE, 0x8C, 0xDB, 0x09, 0x33, 0xD7, \
618 0x1E, 0x8C, 0x94, 0xE0, 0x4A, 0x25, 0x61, 0x9D, \
619 0xCE, 0xE3, 0xD2, 0x26, 0x1A, 0xD2, 0xEE, 0x6B, \
620 0xF1, 0x2F, 0xFA, 0x06, 0xD9, 0x8A, 0x08, 0x64, \
621 0xD8, 0x76, 0x02, 0x73, 0x3E, 0xC8, 0x6A, 0x64, \
622 0x52, 0x1F, 0x2B, 0x18, 0x17, 0x7B, 0x20, 0x0C, \
623 0xBB, 0xE1, 0x17, 0x57, 0x7A, 0x61, 0x5D, 0x6C, \
624 0x77, 0x09, 0x88, 0xC0, 0xBA, 0xD9, 0x46, 0xE2, \
625 0x08, 0xE2, 0x4F, 0xA0, 0x74, 0xE5, 0xAB, 0x31, \
626 0x43, 0xDB, 0x5B, 0xFC, 0xE0, 0xFD, 0x10, 0x8E, \
627 0x4B, 0x82, 0xD1, 0x20, 0xA9, 0x3A, 0xD2, 0xCA, \
628 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
629
630#define MBEDTLS_DHM_RFC3526_MODP_3072_G_BIN { 0x02 }
631
632#define MBEDTLS_DHM_RFC3526_MODP_4096_P_BIN { \
633 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
634 0xC9, 0x0F, 0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, \
635 0xC4, 0xC6, 0x62, 0x8B, 0x80, 0xDC, 0x1C, 0xD1, \
636 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67, 0xCC, 0x74, \
637 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22, \
638 0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, \
639 0xEF, 0x95, 0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, \
640 0x30, 0x2B, 0x0A, 0x6D, 0xF2, 0x5F, 0x14, 0x37, \
641 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51, 0xC2, 0x45, \
642 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6, \
643 0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, \
644 0x0B, 0xFF, 0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, \
645 0xEE, 0x38, 0x6B, 0xFB, 0x5A, 0x89, 0x9F, 0xA5, \
646 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B, 0x1F, 0xE6, \
647 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE4, 0x5B, 0x3D, \
648 0xC2, 0x00, 0x7C, 0xB8, 0xA1, 0x63, 0xBF, 0x05, \
649 0x98, 0xDA, 0x48, 0x36, 0x1C, 0x55, 0xD3, 0x9A, \
650 0x69, 0x16, 0x3F, 0xA8, 0xFD, 0x24, 0xCF, 0x5F, \
651 0x83, 0x65, 0x5D, 0x23, 0xDC, 0xA3, 0xAD, 0x96, \
652 0x1C, 0x62, 0xF3, 0x56, 0x20, 0x85, 0x52, 0xBB, \
653 0x9E, 0xD5, 0x29, 0x07, 0x70, 0x96, 0x96, 0x6D, \
654 0x67, 0x0C, 0x35, 0x4E, 0x4A, 0xBC, 0x98, 0x04, \
655 0xF1, 0x74, 0x6C, 0x08, 0xCA, 0x18, 0x21, 0x7C, \
656 0x32, 0x90, 0x5E, 0x46, 0x2E, 0x36, 0xCE, 0x3B, \
657 0xE3, 0x9E, 0x77, 0x2C, 0x18, 0x0E, 0x86, 0x03, \
658 0x9B, 0x27, 0x83, 0xA2, 0xEC, 0x07, 0xA2, 0x8F, \
659 0xB5, 0xC5, 0x5D, 0xF0, 0x6F, 0x4C, 0x52, 0xC9, \
660 0xDE, 0x2B, 0xCB, 0xF6, 0x95, 0x58, 0x17, 0x18, \
661 0x39, 0x95, 0x49, 0x7C, 0xEA, 0x95, 0x6A, 0xE5, \
662 0x15, 0xD2, 0x26, 0x18, 0x98, 0xFA, 0x05, 0x10, \
663 0x15, 0x72, 0x8E, 0x5A, 0x8A, 0xAA, 0xC4, 0x2D, \
664 0xAD, 0x33, 0x17, 0x0D, 0x04, 0x50, 0x7A, 0x33, \
665 0xA8, 0x55, 0x21, 0xAB, 0xDF, 0x1C, 0xBA, 0x64, \
666 0xEC, 0xFB, 0x85, 0x04, 0x58, 0xDB, 0xEF, 0x0A, \
667 0x8A, 0xEA, 0x71, 0x57, 0x5D, 0x06, 0x0C, 0x7D, \
668 0xB3, 0x97, 0x0F, 0x85, 0xA6, 0xE1, 0xE4, 0xC7, \
669 0xAB, 0xF5, 0xAE, 0x8C, 0xDB, 0x09, 0x33, 0xD7, \
670 0x1E, 0x8C, 0x94, 0xE0, 0x4A, 0x25, 0x61, 0x9D, \
671 0xCE, 0xE3, 0xD2, 0x26, 0x1A, 0xD2, 0xEE, 0x6B, \
672 0xF1, 0x2F, 0xFA, 0x06, 0xD9, 0x8A, 0x08, 0x64, \
673 0xD8, 0x76, 0x02, 0x73, 0x3E, 0xC8, 0x6A, 0x64, \
674 0x52, 0x1F, 0x2B, 0x18, 0x17, 0x7B, 0x20, 0x0C, \
675 0xBB, 0xE1, 0x17, 0x57, 0x7A, 0x61, 0x5D, 0x6C, \
676 0x77, 0x09, 0x88, 0xC0, 0xBA, 0xD9, 0x46, 0xE2, \
677 0x08, 0xE2, 0x4F, 0xA0, 0x74, 0xE5, 0xAB, 0x31, \
678 0x43, 0xDB, 0x5B, 0xFC, 0xE0, 0xFD, 0x10, 0x8E, \
679 0x4B, 0x82, 0xD1, 0x20, 0xA9, 0x21, 0x08, 0x01, \
680 0x1A, 0x72, 0x3C, 0x12, 0xA7, 0x87, 0xE6, 0xD7, \
681 0x88, 0x71, 0x9A, 0x10, 0xBD, 0xBA, 0x5B, 0x26, \
682 0x99, 0xC3, 0x27, 0x18, 0x6A, 0xF4, 0xE2, 0x3C, \
683 0x1A, 0x94, 0x68, 0x34, 0xB6, 0x15, 0x0B, 0xDA, \
684 0x25, 0x83, 0xE9, 0xCA, 0x2A, 0xD4, 0x4C, 0xE8, \
685 0xDB, 0xBB, 0xC2, 0xDB, 0x04, 0xDE, 0x8E, 0xF9, \
686 0x2E, 0x8E, 0xFC, 0x14, 0x1F, 0xBE, 0xCA, 0xA6, \
687 0x28, 0x7C, 0x59, 0x47, 0x4E, 0x6B, 0xC0, 0x5D, \
688 0x99, 0xB2, 0x96, 0x4F, 0xA0, 0x90, 0xC3, 0xA2, \
689 0x23, 0x3B, 0xA1, 0x86, 0x51, 0x5B, 0xE7, 0xED, \
690 0x1F, 0x61, 0x29, 0x70, 0xCE, 0xE2, 0xD7, 0xAF, \
691 0xB8, 0x1B, 0xDD, 0x76, 0x21, 0x70, 0x48, 0x1C, \
692 0xD0, 0x06, 0x91, 0x27, 0xD5, 0xB0, 0x5A, 0xA9, \
693 0x93, 0xB4, 0xEA, 0x98, 0x8D, 0x8F, 0xDD, 0xC1, \
694 0x86, 0xFF, 0xB7, 0xDC, 0x90, 0xA6, 0xC0, 0x8F, \
695 0x4D, 0xF4, 0x35, 0xC9, 0x34, 0x06, 0x31, 0x99, \
696 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
697
698#define MBEDTLS_DHM_RFC3526_MODP_4096_G_BIN { 0x02 }
699
700#define MBEDTLS_DHM_RFC7919_FFDHE2048_P_BIN { \
701 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
702 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
703 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
704 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
705 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
706 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
707 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
708 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
709 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
710 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
711 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
712 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
713 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
714 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
715 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
716 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
717 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
718 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
719 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
720 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
721 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
722 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
723 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
724 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
725 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
726 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
727 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
728 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
729 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
730 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
731 0x88, 0x6B, 0x42, 0x38, 0x61, 0x28, 0x5C, 0x97, \
732 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, }
733
734#define MBEDTLS_DHM_RFC7919_FFDHE2048_G_BIN { 0x02 }
735
736#define MBEDTLS_DHM_RFC7919_FFDHE3072_P_BIN { \
737 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
738 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
739 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
740 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
741 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
742 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
743 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
744 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
745 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
746 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
747 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
748 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
749 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
750 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
751 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
752 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
753 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
754 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
755 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
756 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
757 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
758 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
759 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
760 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
761 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
762 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
763 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
764 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
765 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
766 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
767 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
768 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
769 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
770 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
771 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
772 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
773 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
774 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
775 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
776 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
777 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
778 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
779 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
780 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
781 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
782 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
783 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0xC6, 0x2E, 0x37, \
784 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
785
786#define MBEDTLS_DHM_RFC7919_FFDHE3072_G_BIN { 0x02 }
787
788#define MBEDTLS_DHM_RFC7919_FFDHE4096_P_BIN { \
789 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
790 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
791 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
792 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
793 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
794 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
795 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
796 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
797 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
798 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
799 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
800 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
801 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
802 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
803 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
804 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
805 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
806 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
807 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
808 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
809 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
810 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
811 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
812 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
813 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
814 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
815 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
816 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
817 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
818 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
819 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
820 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
821 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
822 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
823 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
824 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
825 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
826 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
827 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
828 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
829 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
830 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
831 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
832 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
833 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
834 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
835 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
836 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
837 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
838 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
839 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
840 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
841 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
842 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
843 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
844 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
845 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
846 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
847 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
848 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
849 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
850 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
851 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x65, 0x5F, 0x6A, \
852 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
853
854#define MBEDTLS_DHM_RFC7919_FFDHE4096_G_BIN { 0x02 }
855
856#define MBEDTLS_DHM_RFC7919_FFDHE6144_P_BIN { \
857 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
858 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
859 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
860 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
861 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
862 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
863 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
864 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
865 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
866 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
867 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
868 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
869 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
870 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
871 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
872 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
873 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
874 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
875 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
876 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
877 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
878 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
879 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
880 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
881 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
882 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
883 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
884 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
885 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
886 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
887 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
888 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
889 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
890 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
891 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
892 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
893 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
894 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
895 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
896 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
897 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
898 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
899 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
900 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
901 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
902 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
903 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
904 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
905 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
906 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
907 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
908 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
909 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
910 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
911 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
912 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
913 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
914 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
915 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
916 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
917 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
918 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
919 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x0D, 0xD9, 0x02, \
920 0x0B, 0xFD, 0x64, 0xB6, 0x45, 0x03, 0x6C, 0x7A, \
921 0x4E, 0x67, 0x7D, 0x2C, 0x38, 0x53, 0x2A, 0x3A, \
922 0x23, 0xBA, 0x44, 0x42, 0xCA, 0xF5, 0x3E, 0xA6, \
923 0x3B, 0xB4, 0x54, 0x32, 0x9B, 0x76, 0x24, 0xC8, \
924 0x91, 0x7B, 0xDD, 0x64, 0xB1, 0xC0, 0xFD, 0x4C, \
925 0xB3, 0x8E, 0x8C, 0x33, 0x4C, 0x70, 0x1C, 0x3A, \
926 0xCD, 0xAD, 0x06, 0x57, 0xFC, 0xCF, 0xEC, 0x71, \
927 0x9B, 0x1F, 0x5C, 0x3E, 0x4E, 0x46, 0x04, 0x1F, \
928 0x38, 0x81, 0x47, 0xFB, 0x4C, 0xFD, 0xB4, 0x77, \
929 0xA5, 0x24, 0x71, 0xF7, 0xA9, 0xA9, 0x69, 0x10, \
930 0xB8, 0x55, 0x32, 0x2E, 0xDB, 0x63, 0x40, 0xD8, \
931 0xA0, 0x0E, 0xF0, 0x92, 0x35, 0x05, 0x11, 0xE3, \
932 0x0A, 0xBE, 0xC1, 0xFF, 0xF9, 0xE3, 0xA2, 0x6E, \
933 0x7F, 0xB2, 0x9F, 0x8C, 0x18, 0x30, 0x23, 0xC3, \
934 0x58, 0x7E, 0x38, 0xDA, 0x00, 0x77, 0xD9, 0xB4, \
935 0x76, 0x3E, 0x4E, 0x4B, 0x94, 0xB2, 0xBB, 0xC1, \
936 0x94, 0xC6, 0x65, 0x1E, 0x77, 0xCA, 0xF9, 0x92, \
937 0xEE, 0xAA, 0xC0, 0x23, 0x2A, 0x28, 0x1B, 0xF6, \
938 0xB3, 0xA7, 0x39, 0xC1, 0x22, 0x61, 0x16, 0x82, \
939 0x0A, 0xE8, 0xDB, 0x58, 0x47, 0xA6, 0x7C, 0xBE, \
940 0xF9, 0xC9, 0x09, 0x1B, 0x46, 0x2D, 0x53, 0x8C, \
941 0xD7, 0x2B, 0x03, 0x74, 0x6A, 0xE7, 0x7F, 0x5E, \
942 0x62, 0x29, 0x2C, 0x31, 0x15, 0x62, 0xA8, 0x46, \
943 0x50, 0x5D, 0xC8, 0x2D, 0xB8, 0x54, 0x33, 0x8A, \
944 0xE4, 0x9F, 0x52, 0x35, 0xC9, 0x5B, 0x91, 0x17, \
945 0x8C, 0xCF, 0x2D, 0xD5, 0xCA, 0xCE, 0xF4, 0x03, \
946 0xEC, 0x9D, 0x18, 0x10, 0xC6, 0x27, 0x2B, 0x04, \
947 0x5B, 0x3B, 0x71, 0xF9, 0xDC, 0x6B, 0x80, 0xD6, \
948 0x3F, 0xDD, 0x4A, 0x8E, 0x9A, 0xDB, 0x1E, 0x69, \
949 0x62, 0xA6, 0x95, 0x26, 0xD4, 0x31, 0x61, 0xC1, \
950 0xA4, 0x1D, 0x57, 0x0D, 0x79, 0x38, 0xDA, 0xD4, \
951 0xA4, 0x0E, 0x32, 0x9C, 0xD0, 0xE4, 0x0E, 0x65, \
952 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
953
954#define MBEDTLS_DHM_RFC7919_FFDHE6144_G_BIN { 0x02 }
955
956#define MBEDTLS_DHM_RFC7919_FFDHE8192_P_BIN { \
957 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, \
958 0xAD, 0xF8, 0x54, 0x58, 0xA2, 0xBB, 0x4A, 0x9A, \
959 0xAF, 0xDC, 0x56, 0x20, 0x27, 0x3D, 0x3C, 0xF1, \
960 0xD8, 0xB9, 0xC5, 0x83, 0xCE, 0x2D, 0x36, 0x95, \
961 0xA9, 0xE1, 0x36, 0x41, 0x14, 0x64, 0x33, 0xFB, \
962 0xCC, 0x93, 0x9D, 0xCE, 0x24, 0x9B, 0x3E, 0xF9, \
963 0x7D, 0x2F, 0xE3, 0x63, 0x63, 0x0C, 0x75, 0xD8, \
964 0xF6, 0x81, 0xB2, 0x02, 0xAE, 0xC4, 0x61, 0x7A, \
965 0xD3, 0xDF, 0x1E, 0xD5, 0xD5, 0xFD, 0x65, 0x61, \
966 0x24, 0x33, 0xF5, 0x1F, 0x5F, 0x06, 0x6E, 0xD0, \
967 0x85, 0x63, 0x65, 0x55, 0x3D, 0xED, 0x1A, 0xF3, \
968 0xB5, 0x57, 0x13, 0x5E, 0x7F, 0x57, 0xC9, 0x35, \
969 0x98, 0x4F, 0x0C, 0x70, 0xE0, 0xE6, 0x8B, 0x77, \
970 0xE2, 0xA6, 0x89, 0xDA, 0xF3, 0xEF, 0xE8, 0x72, \
971 0x1D, 0xF1, 0x58, 0xA1, 0x36, 0xAD, 0xE7, 0x35, \
972 0x30, 0xAC, 0xCA, 0x4F, 0x48, 0x3A, 0x79, 0x7A, \
973 0xBC, 0x0A, 0xB1, 0x82, 0xB3, 0x24, 0xFB, 0x61, \
974 0xD1, 0x08, 0xA9, 0x4B, 0xB2, 0xC8, 0xE3, 0xFB, \
975 0xB9, 0x6A, 0xDA, 0xB7, 0x60, 0xD7, 0xF4, 0x68, \
976 0x1D, 0x4F, 0x42, 0xA3, 0xDE, 0x39, 0x4D, 0xF4, \
977 0xAE, 0x56, 0xED, 0xE7, 0x63, 0x72, 0xBB, 0x19, \
978 0x0B, 0x07, 0xA7, 0xC8, 0xEE, 0x0A, 0x6D, 0x70, \
979 0x9E, 0x02, 0xFC, 0xE1, 0xCD, 0xF7, 0xE2, 0xEC, \
980 0xC0, 0x34, 0x04, 0xCD, 0x28, 0x34, 0x2F, 0x61, \
981 0x91, 0x72, 0xFE, 0x9C, 0xE9, 0x85, 0x83, 0xFF, \
982 0x8E, 0x4F, 0x12, 0x32, 0xEE, 0xF2, 0x81, 0x83, \
983 0xC3, 0xFE, 0x3B, 0x1B, 0x4C, 0x6F, 0xAD, 0x73, \
984 0x3B, 0xB5, 0xFC, 0xBC, 0x2E, 0xC2, 0x20, 0x05, \
985 0xC5, 0x8E, 0xF1, 0x83, 0x7D, 0x16, 0x83, 0xB2, \
986 0xC6, 0xF3, 0x4A, 0x26, 0xC1, 0xB2, 0xEF, 0xFA, \
987 0x88, 0x6B, 0x42, 0x38, 0x61, 0x1F, 0xCF, 0xDC, \
988 0xDE, 0x35, 0x5B, 0x3B, 0x65, 0x19, 0x03, 0x5B, \
989 0xBC, 0x34, 0xF4, 0xDE, 0xF9, 0x9C, 0x02, 0x38, \
990 0x61, 0xB4, 0x6F, 0xC9, 0xD6, 0xE6, 0xC9, 0x07, \
991 0x7A, 0xD9, 0x1D, 0x26, 0x91, 0xF7, 0xF7, 0xEE, \
992 0x59, 0x8C, 0xB0, 0xFA, 0xC1, 0x86, 0xD9, 0x1C, \
993 0xAE, 0xFE, 0x13, 0x09, 0x85, 0x13, 0x92, 0x70, \
994 0xB4, 0x13, 0x0C, 0x93, 0xBC, 0x43, 0x79, 0x44, \
995 0xF4, 0xFD, 0x44, 0x52, 0xE2, 0xD7, 0x4D, 0xD3, \
996 0x64, 0xF2, 0xE2, 0x1E, 0x71, 0xF5, 0x4B, 0xFF, \
997 0x5C, 0xAE, 0x82, 0xAB, 0x9C, 0x9D, 0xF6, 0x9E, \
998 0xE8, 0x6D, 0x2B, 0xC5, 0x22, 0x36, 0x3A, 0x0D, \
999 0xAB, 0xC5, 0x21, 0x97, 0x9B, 0x0D, 0xEA, 0xDA, \
1000 0x1D, 0xBF, 0x9A, 0x42, 0xD5, 0xC4, 0x48, 0x4E, \
1001 0x0A, 0xBC, 0xD0, 0x6B, 0xFA, 0x53, 0xDD, 0xEF, \
1002 0x3C, 0x1B, 0x20, 0xEE, 0x3F, 0xD5, 0x9D, 0x7C, \
1003 0x25, 0xE4, 0x1D, 0x2B, 0x66, 0x9E, 0x1E, 0xF1, \
1004 0x6E, 0x6F, 0x52, 0xC3, 0x16, 0x4D, 0xF4, 0xFB, \
1005 0x79, 0x30, 0xE9, 0xE4, 0xE5, 0x88, 0x57, 0xB6, \
1006 0xAC, 0x7D, 0x5F, 0x42, 0xD6, 0x9F, 0x6D, 0x18, \
1007 0x77, 0x63, 0xCF, 0x1D, 0x55, 0x03, 0x40, 0x04, \
1008 0x87, 0xF5, 0x5B, 0xA5, 0x7E, 0x31, 0xCC, 0x7A, \
1009 0x71, 0x35, 0xC8, 0x86, 0xEF, 0xB4, 0x31, 0x8A, \
1010 0xED, 0x6A, 0x1E, 0x01, 0x2D, 0x9E, 0x68, 0x32, \
1011 0xA9, 0x07, 0x60, 0x0A, 0x91, 0x81, 0x30, 0xC4, \
1012 0x6D, 0xC7, 0x78, 0xF9, 0x71, 0xAD, 0x00, 0x38, \
1013 0x09, 0x29, 0x99, 0xA3, 0x33, 0xCB, 0x8B, 0x7A, \
1014 0x1A, 0x1D, 0xB9, 0x3D, 0x71, 0x40, 0x00, 0x3C, \
1015 0x2A, 0x4E, 0xCE, 0xA9, 0xF9, 0x8D, 0x0A, 0xCC, \
1016 0x0A, 0x82, 0x91, 0xCD, 0xCE, 0xC9, 0x7D, 0xCF, \
1017 0x8E, 0xC9, 0xB5, 0x5A, 0x7F, 0x88, 0xA4, 0x6B, \
1018 0x4D, 0xB5, 0xA8, 0x51, 0xF4, 0x41, 0x82, 0xE1, \
1019 0xC6, 0x8A, 0x00, 0x7E, 0x5E, 0x0D, 0xD9, 0x02, \
1020 0x0B, 0xFD, 0x64, 0xB6, 0x45, 0x03, 0x6C, 0x7A, \
1021 0x4E, 0x67, 0x7D, 0x2C, 0x38, 0x53, 0x2A, 0x3A, \
1022 0x23, 0xBA, 0x44, 0x42, 0xCA, 0xF5, 0x3E, 0xA6, \
1023 0x3B, 0xB4, 0x54, 0x32, 0x9B, 0x76, 0x24, 0xC8, \
1024 0x91, 0x7B, 0xDD, 0x64, 0xB1, 0xC0, 0xFD, 0x4C, \
1025 0xB3, 0x8E, 0x8C, 0x33, 0x4C, 0x70, 0x1C, 0x3A, \
1026 0xCD, 0xAD, 0x06, 0x57, 0xFC, 0xCF, 0xEC, 0x71, \
1027 0x9B, 0x1F, 0x5C, 0x3E, 0x4E, 0x46, 0x04, 0x1F, \
1028 0x38, 0x81, 0x47, 0xFB, 0x4C, 0xFD, 0xB4, 0x77, \
1029 0xA5, 0x24, 0x71, 0xF7, 0xA9, 0xA9, 0x69, 0x10, \
1030 0xB8, 0x55, 0x32, 0x2E, 0xDB, 0x63, 0x40, 0xD8, \
1031 0xA0, 0x0E, 0xF0, 0x92, 0x35, 0x05, 0x11, 0xE3, \
1032 0x0A, 0xBE, 0xC1, 0xFF, 0xF9, 0xE3, 0xA2, 0x6E, \
1033 0x7F, 0xB2, 0x9F, 0x8C, 0x18, 0x30, 0x23, 0xC3, \
1034 0x58, 0x7E, 0x38, 0xDA, 0x00, 0x77, 0xD9, 0xB4, \
1035 0x76, 0x3E, 0x4E, 0x4B, 0x94, 0xB2, 0xBB, 0xC1, \
1036 0x94, 0xC6, 0x65, 0x1E, 0x77, 0xCA, 0xF9, 0x92, \
1037 0xEE, 0xAA, 0xC0, 0x23, 0x2A, 0x28, 0x1B, 0xF6, \
1038 0xB3, 0xA7, 0x39, 0xC1, 0x22, 0x61, 0x16, 0x82, \
1039 0x0A, 0xE8, 0xDB, 0x58, 0x47, 0xA6, 0x7C, 0xBE, \
1040 0xF9, 0xC9, 0x09, 0x1B, 0x46, 0x2D, 0x53, 0x8C, \
1041 0xD7, 0x2B, 0x03, 0x74, 0x6A, 0xE7, 0x7F, 0x5E, \
1042 0x62, 0x29, 0x2C, 0x31, 0x15, 0x62, 0xA8, 0x46, \
1043 0x50, 0x5D, 0xC8, 0x2D, 0xB8, 0x54, 0x33, 0x8A, \
1044 0xE4, 0x9F, 0x52, 0x35, 0xC9, 0x5B, 0x91, 0x17, \
1045 0x8C, 0xCF, 0x2D, 0xD5, 0xCA, 0xCE, 0xF4, 0x03, \
1046 0xEC, 0x9D, 0x18, 0x10, 0xC6, 0x27, 0x2B, 0x04, \
1047 0x5B, 0x3B, 0x71, 0xF9, 0xDC, 0x6B, 0x80, 0xD6, \
1048 0x3F, 0xDD, 0x4A, 0x8E, 0x9A, 0xDB, 0x1E, 0x69, \
1049 0x62, 0xA6, 0x95, 0x26, 0xD4, 0x31, 0x61, 0xC1, \
1050 0xA4, 0x1D, 0x57, 0x0D, 0x79, 0x38, 0xDA, 0xD4, \
1051 0xA4, 0x0E, 0x32, 0x9C, 0xCF, 0xF4, 0x6A, 0xAA, \
1052 0x36, 0xAD, 0x00, 0x4C, 0xF6, 0x00, 0xC8, 0x38, \
1053 0x1E, 0x42, 0x5A, 0x31, 0xD9, 0x51, 0xAE, 0x64, \
1054 0xFD, 0xB2, 0x3F, 0xCE, 0xC9, 0x50, 0x9D, 0x43, \
1055 0x68, 0x7F, 0xEB, 0x69, 0xED, 0xD1, 0xCC, 0x5E, \
1056 0x0B, 0x8C, 0xC3, 0xBD, 0xF6, 0x4B, 0x10, 0xEF, \
1057 0x86, 0xB6, 0x31, 0x42, 0xA3, 0xAB, 0x88, 0x29, \
1058 0x55, 0x5B, 0x2F, 0x74, 0x7C, 0x93, 0x26, 0x65, \
1059 0xCB, 0x2C, 0x0F, 0x1C, 0xC0, 0x1B, 0xD7, 0x02, \
1060 0x29, 0x38, 0x88, 0x39, 0xD2, 0xAF, 0x05, 0xE4, \
1061 0x54, 0x50, 0x4A, 0xC7, 0x8B, 0x75, 0x82, 0x82, \
1062 0x28, 0x46, 0xC0, 0xBA, 0x35, 0xC3, 0x5F, 0x5C, \
1063 0x59, 0x16, 0x0C, 0xC0, 0x46, 0xFD, 0x82, 0x51, \
1064 0x54, 0x1F, 0xC6, 0x8C, 0x9C, 0x86, 0xB0, 0x22, \
1065 0xBB, 0x70, 0x99, 0x87, 0x6A, 0x46, 0x0E, 0x74, \
1066 0x51, 0xA8, 0xA9, 0x31, 0x09, 0x70, 0x3F, 0xEE, \
1067 0x1C, 0x21, 0x7E, 0x6C, 0x38, 0x26, 0xE5, 0x2C, \
1068 0x51, 0xAA, 0x69, 0x1E, 0x0E, 0x42, 0x3C, 0xFC, \
1069 0x99, 0xE9, 0xE3, 0x16, 0x50, 0xC1, 0x21, 0x7B, \
1070 0x62, 0x48, 0x16, 0xCD, 0xAD, 0x9A, 0x95, 0xF9, \
1071 0xD5, 0xB8, 0x01, 0x94, 0x88, 0xD9, 0xC0, 0xA0, \
1072 0xA1, 0xFE, 0x30, 0x75, 0xA5, 0x77, 0xE2, 0x31, \
1073 0x83, 0xF8, 0x1D, 0x4A, 0x3F, 0x2F, 0xA4, 0x57, \
1074 0x1E, 0xFC, 0x8C, 0xE0, 0xBA, 0x8A, 0x4F, 0xE8, \
1075 0xB6, 0x85, 0x5D, 0xFE, 0x72, 0xB0, 0xA6, 0x6E, \
1076 0xDE, 0xD2, 0xFB, 0xAB, 0xFB, 0xE5, 0x8A, 0x30, \
1077 0xFA, 0xFA, 0xBE, 0x1C, 0x5D, 0x71, 0xA8, 0x7E, \
1078 0x2F, 0x74, 0x1E, 0xF8, 0xC1, 0xFE, 0x86, 0xFE, \
1079 0xA6, 0xBB, 0xFD, 0xE5, 0x30, 0x67, 0x7F, 0x0D, \
1080 0x97, 0xD1, 0x1D, 0x49, 0xF7, 0xA8, 0x44, 0x3D, \
1081 0x08, 0x22, 0xE5, 0x06, 0xA9, 0xF4, 0x61, 0x4E, \
1082 0x01, 0x1E, 0x2A, 0x94, 0x83, 0x8F, 0xF8, 0x8C, \
1083 0xD6, 0x8C, 0x8B, 0xB7, 0xC5, 0xC6, 0x42, 0x4C, \
1084 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF }
1085
1086#define MBEDTLS_DHM_RFC7919_FFDHE8192_G_BIN { 0x02 }
1087
Paul Bakker9af723c2014-05-01 13:03:14 +02001088#endif /* dhm.h */