blob: cfd42a2f6c7d9c6154f845a22c5348cbc31885f6 [file] [log] [blame]
Paul Bakkerb0c19a42013-06-24 19:26:38 +02001/**
Paul Bakkerdcbfdcc2013-09-10 16:16:50 +02002 * \file pkcs5.h
Paul Bakkerb0c19a42013-06-24 19:26:38 +02003 *
4 * \brief PKCS#5 functions
5 *
6 * \author Mathias Olsson <mathias@kompetensum.com>
7 *
Manuel Pégourié-Gonnarda658a402015-01-23 09:45:19 +00008 * Copyright (C) 2006-2013, ARM Limited, All Rights Reserved
Paul Bakkerb0c19a42013-06-24 19:26:38 +02009 *
Manuel Pégourié-Gonnardfe446432015-03-06 13:17:10 +000010 * This file is part of mbed TLS (https://tls.mbed.org)
Paul Bakkerb0c19a42013-06-24 19:26:38 +020011 *
Paul Bakkerb0c19a42013-06-24 19:26:38 +020012 * This program is free software; you can redistribute it and/or modify
13 * it under the terms of the GNU General Public License as published by
14 * the Free Software Foundation; either version 2 of the License, or
15 * (at your option) any later version.
16 *
17 * This program is distributed in the hope that it will be useful,
18 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
20 * GNU General Public License for more details.
21 *
22 * You should have received a copy of the GNU General Public License along
23 * with this program; if not, write to the Free Software Foundation, Inc.,
24 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
25 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020026#ifndef MBEDTLS_PKCS5_H
27#define MBEDTLS_PKCS5_H
Paul Bakkerb0c19a42013-06-24 19:26:38 +020028
Paul Bakker28144de2013-06-24 19:28:55 +020029#include "asn1.h"
Paul Bakkerb0c19a42013-06-24 19:26:38 +020030#include "md.h"
31
Rich Evans00ab4702015-02-06 13:43:58 +000032#include <stddef.h>
Manuel Pégourié-Gonnardab229102015-04-15 11:53:16 +020033#include <stdint.h>
Paul Bakkerb0c19a42013-06-24 19:26:38 +020034
Manuel Pégourié-Gonnardeed55a42015-04-09 17:31:59 +020035#define MBEDTLS_ERR_PKCS5_BAD_INPUT_DATA -0x2f80 /**< Bad input parameters to function. */
36#define MBEDTLS_ERR_PKCS5_INVALID_FORMAT -0x2f00 /**< Unexpected ASN.1 data. */
37#define MBEDTLS_ERR_PKCS5_FEATURE_UNAVAILABLE -0x2e80 /**< Requested encryption or digest alg not available. */
38#define MBEDTLS_ERR_PKCS5_PASSWORD_MISMATCH -0x2e00 /**< Given private key password does not allow for correct decryption. */
Paul Bakker28144de2013-06-24 19:28:55 +020039
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020040#define MBEDTLS_PKCS5_DECRYPT 0
41#define MBEDTLS_PKCS5_ENCRYPT 1
Paul Bakker28144de2013-06-24 19:28:55 +020042
Paul Bakkerb0c19a42013-06-24 19:26:38 +020043#ifdef __cplusplus
44extern "C" {
45#endif
46
47/**
Paul Bakker28144de2013-06-24 19:28:55 +020048 * \brief PKCS#5 PBES2 function
49 *
50 * \param pbe_params the ASN.1 algorithm parameters
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020051 * \param mode either MBEDTLS_PKCS5_DECRYPT or MBEDTLS_PKCS5_ENCRYPT
Paul Bakker28144de2013-06-24 19:28:55 +020052 * \param pwd password to use when generating key
Paul Bakkerdcbfdcc2013-09-10 16:16:50 +020053 * \param pwdlen length of password
Paul Bakker28144de2013-06-24 19:28:55 +020054 * \param data data to process
55 * \param datalen length of data
56 * \param output output buffer
57 *
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020058 * \returns 0 on success, or a MBEDTLS_ERR_XXX code if verification fails.
Paul Bakker28144de2013-06-24 19:28:55 +020059 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020060int mbedtls_pkcs5_pbes2( const mbedtls_asn1_buf *pbe_params, int mode,
Paul Bakker28144de2013-06-24 19:28:55 +020061 const unsigned char *pwd, size_t pwdlen,
62 const unsigned char *data, size_t datalen,
63 unsigned char *output );
64
65/**
Paul Bakkerb0c19a42013-06-24 19:26:38 +020066 * \brief PKCS#5 PBKDF2 using HMAC
67 *
68 * \param ctx Generic HMAC context
69 * \param password Password to use when generating key
70 * \param plen Length of password
71 * \param salt Salt to use when generating key
72 * \param slen Length of salt
73 * \param iteration_count Iteration count
Manuel Pégourié-Gonnard898e0aa2015-06-18 15:28:12 +020074 * \param key_length Length of generated key in bytes
Paul Bakkerb0c19a42013-06-24 19:26:38 +020075 * \param output Generated key. Must be at least as big as key_length
76 *
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020077 * \returns 0 on success, or a MBEDTLS_ERR_XXX code if verification fails.
Paul Bakkerb0c19a42013-06-24 19:26:38 +020078 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020079int mbedtls_pkcs5_pbkdf2_hmac( mbedtls_md_context_t *ctx, const unsigned char *password,
Paul Bakkerb0c19a42013-06-24 19:26:38 +020080 size_t plen, const unsigned char *salt, size_t slen,
81 unsigned int iteration_count,
82 uint32_t key_length, unsigned char *output );
83
84/**
85 * \brief Checkup routine
86 *
87 * \return 0 if successful, or 1 if the test failed
88 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020089int mbedtls_pkcs5_self_test( int verbose );
Paul Bakkerb0c19a42013-06-24 19:26:38 +020090
91#ifdef __cplusplus
92}
93#endif
94
95#endif /* pkcs5.h */