diff options
author | Steve Lhomme <robux4@ycbcr.xyz> | 2020-04-29 10:32:08 +0200 |
---|---|---|
committer | Steve Lhomme <robux4@ycbcr.xyz> | 2020-05-28 07:44:47 +0200 |
commit | 2a94a7b12d3bfb8384e1ca4d55eea28ccc5b2fe5 (patch) | |
tree | 9a48bf952ffd17b89e7d2cbbcc991b8a0c481de2 /lib/nettle/sysrng-bcrypt.c | |
parent | 2f28cf6e7304a0f8b3c08823846752a2b55aabcf (diff) | |
download | gnutls-2a94a7b12d3bfb8384e1ca4d55eea28ccc5b2fe5.tar.gz |
win32: use bcrypt instead of CryptoAPI on Vista+ for random numbers
CryptoAPI is a deprecated API [1] that is forbidden in UWP builds.
Rewrite the CryptoAPI calls in bcrypt.
bcrypt is used instead of CryptoAPI when targeting Windows Vista and above.
https://docs.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptdecrypt
Signed-off-by: Steve Lhomme <robux4@ycbcr.xyz>
Diffstat (limited to 'lib/nettle/sysrng-bcrypt.c')
-rw-r--r-- | lib/nettle/sysrng-bcrypt.c | 88 |
1 files changed, 88 insertions, 0 deletions
diff --git a/lib/nettle/sysrng-bcrypt.c b/lib/nettle/sysrng-bcrypt.c new file mode 100644 index 0000000000..10dc9ac83a --- /dev/null +++ b/lib/nettle/sysrng-bcrypt.c @@ -0,0 +1,88 @@ +/* + * Copyright (C) 2010-2016 Free Software Foundation, Inc. + * Copyright (C) 2015-2016 Red Hat, Inc. + * Copyright (C) 2000, 2001, 2008 Niels Möller + * + * Author: Nikos Mavrogiannopoulos + * + * This file is part of GNUTLS. + * + * The GNUTLS library is free software; you can redistribute it and/or + * modify it under the terms of the GNU Lesser General Public License + * as published by the Free Software Foundation; either version 2.1 of + * the License, or (at your option) any later version. + * + * This library is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + * Lesser General Public License for more details. + * + * You should have received a copy of the GNU Lesser General Public License + * along with this program. If not, see <https://www.gnu.org/licenses/> + * + */ + +/* Here are the common parts of the random generator layer. + * Some of this code was based on the LSH + * random generator (the trivia and device source functions for POSIX) + * and modified to fit gnutls' needs. Relicenced with permission. + * Original author Niels Möller. + */ + +#include "gnutls_int.h" +#include "errors.h" +#include <locks.h> +#include <num.h> +#include <nettle/yarrow.h> +#include <errno.h> +#include <rnd-common.h> +#include <hash-pjw-bare.h> + +#include <sys/types.h> +#include <sys/stat.h> +#include <unistd.h> + +/* The windows randomness gatherer. + */ + +#include <windows.h> +#include <bcrypt.h> + +get_entropy_func _rnd_get_system_entropy = NULL; + +static BCRYPT_ALG_HANDLE device_fd = 0; + +static +int _rnd_get_system_entropy_win32(void* rnd, size_t size) +{ + NTSTATUS err = BCryptGenRandom(device_fd, rnd, size, 0); + if (!BCRYPT_SUCCESS(err)) { + _gnutls_debug_log("Error in BCryptGenRandom: %ld\n", err); + return GNUTLS_E_RANDOM_DEVICE_ERROR; + } + + return 0; +} + +int _rnd_system_entropy_check(void) +{ + return 0; +} + +int _rnd_system_entropy_init(void) +{ + NTSTATUS err = BCryptOpenAlgorithmProvider + (&device_fd, BCRYPT_RNG_ALGORITHM, NULL, 0); + if (!BCRYPT_SUCCESS(err)) { + _gnutls_debug_log("error in BCryptOpenAlgorithmProvider!\n"); + return GNUTLS_E_RANDOM_DEVICE_ERROR; + } + + _rnd_get_system_entropy = _rnd_get_system_entropy_win32; + return 0; +} + +void _rnd_system_entropy_deinit(void) +{ + BCryptCloseAlgorithmProvider(device_fd, 0); +} |