|
root / base / usr / src / uts / common / smbsrv / smb_kcrypt.h
smb_kcrypt.h C 146 lines 4.0 KB
  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
/*
 * This file and its contents are supplied under the terms of the
 * Common Development and Distribution License ("CDDL"), version 1.0.
 * You may only use this file in accordance with the terms of version
 * 1.0 of the CDDL.
 *
 * A full copy of the text of the CDDL should have accompanied this
 * source.  A copy of the CDDL is also available via the Internet at
 * http://www.illumos.org/license/CDDL.
 */

/*
 * Copyright 2017-2021 Tintri by DDN, Inc. All rights reserved.
 * Copyright 2020-2023 RackTop Systems, Inc.
 */

#ifndef _SMB_KCRYPT_H_
#define	_SMB_KCRYPT_H_

/*
 * SMB signing routines used in {smb,smb2}_signing.c
 * Two implementations of these (kernel/user) in:
 *	uts/common/fs/smbsrv/smb_sign_kcf.c
 *	lib/smbsrv/libfksmbsrv/common/fksmb_sign_pkcs.c
 */

#ifdef	_KERNEL
#include <sys/crypto/api.h>
#else
#include <security/cryptoki.h>
#include <security/pkcs11.h>
#endif
#include <sys/uio.h>

#ifdef __cplusplus
extern "C" {
#endif

#define	AES128_KEY_LENGTH	16	/* AES128 key length in bytes */
#define	AES256_KEY_LENGTH	32	/* AES256 key length in bytes */
#define	MD5_DIGEST_LENGTH	16	/* MD5 digest length in bytes */
#define	SHA256_DIGEST_LENGTH	32	/* SHA256 digest length in bytes */
#define	SHA512_DIGEST_LENGTH	64	/* SHA512 digest length in bytes */
#define	SMB2_SIG_SIZE		16
#define	SMB2_KEYLEN		16	/* SMB2/3 Signing Key length */
#define	SMB2_SSN_KEYLEN		16	/* Max size of the SMB2 Session Key */

#define	SMB3_AES_CCM_NONCE_SIZE		11
#define	SMB3_AES_GCM_NONCE_SIZE		12
#define	SMB3_AES_GMAC_NONCE_SIZE	12

#ifdef	_KERNEL

/* KCF variant */
typedef crypto_mechanism_t	smb_crypto_mech_t;
typedef crypto_context_t	smb_sign_ctx_t;

typedef union {
	CK_AES_CCM_PARAMS	ccm;
	CK_AES_GCM_PARAMS	gcm;
	ulong_t			hmac;
	CK_AES_GMAC_PARAMS	gmac;
} smb_crypto_param_t;

typedef struct smb_enc_ctx {
	smb_crypto_mech_t mech;
	smb_crypto_param_t param;
	crypto_key_t ckey;
	crypto_context_t ctx;
	/* crypto_ctx_template_t *TODO */
} smb_enc_ctx_t;

#else	/* _KERNEL */

/* PKCS11 variant */
typedef CK_MECHANISM		smb_crypto_mech_t;
typedef CK_SESSION_HANDLE	smb_sign_ctx_t;

typedef union {
	CK_CCM_PARAMS		ccm;
	CK_GCM_PARAMS		gcm;
	CK_MAC_GENERAL_PARAMS	hmac;
	CK_BYTE_PTR		gmac;	/* Just IV[12] */
} smb_crypto_param_t;

typedef struct smb_enc_ctx {
	smb_crypto_mech_t mech;
	smb_crypto_param_t param;
	CK_OBJECT_HANDLE key;
	CK_SESSION_HANDLE ctx;
} smb_enc_ctx_t;

#endif	/* _KERNEL */

/*
 * SMB signing routines used in smb_signing.c
 */
int smb_md5_getmech(smb_crypto_mech_t *);
int smb_md5_init(smb_sign_ctx_t *, smb_crypto_mech_t *);
int smb_md5_update(smb_sign_ctx_t, void *, size_t);
int smb_md5_final(smb_sign_ctx_t, uint8_t *);

/*
 * SMB2/3 signing routines used in smb2_signing.c
 * Two implementations of these (kernel/user) in:
 *	uts/common/fs/smbsrv/smb2_sign_kcf.c
 *	lib/smbsrv/libfksmbsrv/common/fksmb_sign_pkcs.c
 */

int smb2_hmac_getmech(smb_crypto_mech_t *);
int smb3_cmac_getmech(smb_crypto_mech_t *);
int smb3_gmac_getmech(smb_crypto_mech_t *);
void smb2_sign_init_hmac_param(smb_crypto_mech_t *, smb_crypto_param_t *,
    ulong_t);
void smb3_sign_init_gmac_param(smb_crypto_mech_t *, smb_crypto_param_t *,
    uint8_t *);

int smb2_mac_uio(smb_crypto_mech_t *, uint8_t *, size_t, uio_t *, uint8_t *);
int smb2_mac_raw(smb_crypto_mech_t *, uint8_t *, size_t, uint8_t *, size_t,
    uint8_t *, size_t);

int smb3_kdf(uint8_t *outbuf, uint32_t outbuf_len,
    uint8_t *key, size_t key_len,
    uint8_t *label, size_t label_len,
    uint8_t *context, size_t context_len);

int smb3_aes_ccm_getmech(smb_crypto_mech_t *);
int smb3_aes_gcm_getmech(smb_crypto_mech_t *);
void smb3_crypto_init_ccm_param(smb_enc_ctx_t *,
    uint8_t *, size_t, uint8_t *, size_t, size_t);
void smb3_crypto_init_gcm_param(smb_enc_ctx_t *,
    uint8_t *, size_t, uint8_t *, size_t);

int smb3_encrypt_init(smb_enc_ctx_t *, uint8_t *, size_t);
int smb3_encrypt_uio(smb_enc_ctx_t *, uio_t *, uio_t *);
void smb3_enc_ctx_done(smb_enc_ctx_t *);

int smb3_decrypt_init(smb_enc_ctx_t *, uint8_t *, size_t);
int smb3_decrypt_uio(smb_enc_ctx_t *, uio_t *, uio_t *);

#ifdef	__cplusplus
}
#endif

#endif /* _SMB_KCRYPT_H_ */