Mercurial > hg > nginx
annotate src/event/ngx_event_quic.c @ 8179:7ee1ada04c8a quic
Generic function for HKDF expansion.
author | Vladimir Homutov <vl@nginx.com> |
---|---|
date | Wed, 26 Feb 2020 16:56:47 +0300 |
parents | a9ff4392ecde |
children | 01dc595de244 |
rev | line source |
---|---|
8171 | 1 #include <ngx_config.h> |
2 #include <ngx_core.h> | |
3 #include <ngx_event.h> | |
4 | |
5 | |
6 uint64_t | |
7 ngx_quic_parse_int(u_char **pos) | |
8 { | |
9 u_char *p; | |
10 uint64_t value; | |
11 ngx_uint_t len; | |
12 | |
13 p = *pos; | |
14 len = 1 << ((*p & 0xc0) >> 6); | |
15 value = *p++ & 0x3f; | |
16 | |
17 while (--len) { | |
18 value = (value << 8) + *p++; | |
19 } | |
20 | |
21 *pos = p; | |
22 return value; | |
23 } | |
24 | |
25 | |
26 void | |
27 ngx_quic_build_int(u_char **pos, uint64_t value) | |
28 { | |
29 u_char *p; | |
30 ngx_uint_t len;//, len2; | |
31 | |
32 p = *pos; | |
33 len = 0; | |
34 | |
35 while (value >> ((1 << len) * 8 - 2)) { | |
36 len++; | |
37 } | |
38 | |
39 *p = len << 6; | |
40 | |
41 // len2 = | |
42 len = (1 << len); | |
43 len--; | |
44 *p |= value >> (len * 8); | |
45 p++; | |
46 | |
47 while (len) { | |
48 *p++ = value >> ((len-- - 1) * 8); | |
49 } | |
50 | |
51 *pos = p; | |
52 // return len2; | |
53 } | |
54 | |
55 | |
56 uint64_t | |
57 ngx_quic_parse_pn(u_char **pos, ngx_int_t len, u_char *mask) | |
58 { | |
59 u_char *p; | |
60 uint64_t value; | |
61 | |
62 p = *pos; | |
63 value = *p++ ^ *mask++; | |
64 | |
65 while (--len) { | |
66 value = (value << 8) + (*p++ ^ *mask++); | |
67 } | |
68 | |
69 *pos = p; | |
70 return value; | |
71 } | |
72 | |
73 | |
74 ngx_int_t | |
75 ngx_hkdf_extract(u_char *out_key, size_t *out_len, const EVP_MD *digest, | |
76 const u_char *secret, size_t secret_len, const u_char *salt, | |
77 size_t salt_len) | |
78 { | |
79 #ifdef OPENSSL_IS_BORINGSSL | |
80 if (HKDF_extract(out_key, out_len, digest, secret, secret_len, salt, | |
81 salt_len) | |
82 == 0) | |
83 { | |
84 return NGX_ERROR; | |
85 } | |
86 #else | |
87 | |
88 EVP_PKEY_CTX *pctx; | |
89 | |
90 pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL); | |
91 | |
92 if (EVP_PKEY_derive_init(pctx) <= 0) { | |
93 return NGX_ERROR; | |
94 } | |
95 | |
96 if (EVP_PKEY_CTX_hkdf_mode(pctx, EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY) <= 0) { | |
97 return NGX_ERROR; | |
98 } | |
99 | |
100 if (EVP_PKEY_CTX_set_hkdf_md(pctx, digest) <= 0) { | |
101 return NGX_ERROR; | |
102 } | |
103 | |
104 if (EVP_PKEY_CTX_set1_hkdf_key(pctx, secret, secret_len) <= 0) { | |
105 return NGX_ERROR; | |
106 } | |
107 | |
108 if (EVP_PKEY_CTX_set1_hkdf_salt(pctx, salt, salt_len) <= 0) { | |
109 return NGX_ERROR; | |
110 } | |
111 | |
112 if (EVP_PKEY_derive(pctx, out_key, out_len) <= 0) { | |
113 return NGX_ERROR; | |
114 } | |
115 | |
116 #endif | |
117 | |
118 return NGX_OK; | |
119 } | |
120 | |
121 | |
122 ngx_int_t | |
8179
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
123 ngx_quic_hkdf_expand(ngx_connection_t *c, const EVP_MD *digest, ngx_str_t *out, |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
124 ngx_str_t *prk, ngx_str_t *name, ngx_uint_t sender) |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
125 { |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
126 uint8_t *p; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
127 size_t hkdfl_len; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
128 uint8_t hkdfl[20]; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
129 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
130 #if (NGX_DEBUG) |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
131 u_char buf[512]; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
132 size_t m; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
133 #endif |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
134 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
135 out->data = ngx_pnalloc(c->pool, out->len); |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
136 if (out->data == NULL) { |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
137 return NGX_ERROR; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
138 } |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
139 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
140 hkdfl_len = 2 + 1 + name->len + 1; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
141 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
142 if (sender) { |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
143 hkdfl[0] = out->len / 256; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
144 hkdfl[1] = out->len % 256; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
145 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
146 } else { |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
147 hkdfl[0] = 0; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
148 hkdfl[1] = out->len; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
149 } |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
150 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
151 hkdfl[2] = name->len; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
152 p = ngx_cpymem(&hkdfl[3], name->data, name->len); |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
153 *p = '\0'; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
154 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
155 if (ngx_hkdf_expand(out->data, out->len, digest, |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
156 prk->data, prk->len, hkdfl, hkdfl_len) |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
157 != NGX_OK) |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
158 { |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
159 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
160 "ngx_hkdf_expand(%V) failed", name); |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
161 return NGX_ERROR; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
162 } |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
163 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
164 if (c->log->log_level & NGX_LOG_DEBUG_EVENT) { |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
165 m = ngx_hex_dump(buf, out->data, out->len) - buf; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
166 ngx_log_debug4(NGX_LOG_DEBUG_EVENT, c->log, 0, |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
167 "%V: %*s, len: %uz", name, m, buf, out->len); |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
168 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
169 m = ngx_hex_dump(buf, hkdfl, hkdfl_len) - buf; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
170 ngx_log_debug4(NGX_LOG_DEBUG_EVENT, c->log, 0, |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
171 "%V hkdf: %*s, len: %uz", name, m, buf, hkdfl_len); |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
172 } |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
173 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
174 return NGX_OK; |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
175 } |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
176 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
177 |
7ee1ada04c8a
Generic function for HKDF expansion.
Vladimir Homutov <vl@nginx.com>
parents:
8178
diff
changeset
|
178 ngx_int_t |
8171 | 179 ngx_hkdf_expand(u_char *out_key, size_t out_len, const EVP_MD *digest, |
180 const u_char *prk, size_t prk_len, const u_char *info, size_t info_len) | |
181 { | |
182 #ifdef OPENSSL_IS_BORINGSSL | |
183 if (HKDF_expand(out_key, out_len, digest, prk, prk_len, info, info_len) | |
184 == 0) | |
185 { | |
186 return NGX_ERROR; | |
187 } | |
188 #else | |
189 | |
190 EVP_PKEY_CTX *pctx; | |
191 | |
192 pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL); | |
193 | |
194 if (EVP_PKEY_derive_init(pctx) <= 0) { | |
195 return NGX_ERROR; | |
196 } | |
197 | |
198 if (EVP_PKEY_CTX_hkdf_mode(pctx, EVP_PKEY_HKDEF_MODE_EXPAND_ONLY) <= 0) { | |
199 return NGX_ERROR; | |
200 } | |
201 | |
202 if (EVP_PKEY_CTX_set_hkdf_md(pctx, digest) <= 0) { | |
203 return NGX_ERROR; | |
204 } | |
205 | |
206 if (EVP_PKEY_CTX_set1_hkdf_key(pctx, prk, prk_len) <= 0) { | |
207 return NGX_ERROR; | |
208 } | |
209 | |
210 if (EVP_PKEY_CTX_add1_hkdf_info(pctx, info, info_len) <= 0) { | |
211 return NGX_ERROR; | |
212 } | |
213 | |
214 if (EVP_PKEY_derive(pctx, out_key, &out_len) <= 0) { | |
215 return NGX_ERROR; | |
216 } | |
217 | |
218 #endif | |
219 | |
220 return NGX_OK; | |
221 } | |
8177
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
222 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
223 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
224 ngx_int_t |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
225 ngx_quic_tls_open(ngx_connection_t *c, const ngx_aead_cipher_t *cipher, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
226 ngx_quic_secret_t *s, ngx_str_t *out, u_char *nonce, ngx_str_t *in, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
227 ngx_str_t *ad) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
228 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
229 out->len = in->len - EVP_GCM_TLS_TAG_LEN; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
230 out->data = ngx_pnalloc(c->pool, out->len); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
231 if (out->data == NULL) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
232 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
233 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
234 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
235 #ifdef OPENSSL_IS_BORINGSSL |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
236 EVP_AEAD_CTX *ctx; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
237 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
238 ctx = EVP_AEAD_CTX_new(cipher, s->key.data, s->key.len, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
239 EVP_AEAD_DEFAULT_TAG_LENGTH); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
240 if (ctx == NULL) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
241 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_AEAD_CTX_new() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
242 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
243 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
244 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
245 if (EVP_AEAD_CTX_open(ctx, out->data, &out->len, out->len, nonce, s->iv.len, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
246 in->data, in->len, ad->data, ad->len) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
247 != 1) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
248 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
249 EVP_AEAD_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
250 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_AEAD_CTX_open() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
251 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
252 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
253 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
254 EVP_AEAD_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
255 #else |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
256 int len; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
257 u_char *tag; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
258 EVP_CIPHER_CTX *ctx; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
259 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
260 ctx = EVP_CIPHER_CTX_new(); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
261 if (ctx == NULL) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
262 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_CIPHER_CTX_new() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
263 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
264 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
265 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
266 if (EVP_DecryptInit_ex(ctx, cipher, NULL, NULL, NULL) != 1) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
267 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
268 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_DecryptInit_ex() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
269 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
270 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
271 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
272 if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_GCM_SET_IVLEN, s->iv.len, NULL) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
273 == 0) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
274 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
275 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
276 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
277 "EVP_CIPHER_CTX_ctrl(EVP_CTRL_GCM_SET_IVLEN) failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
278 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
279 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
280 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
281 if (EVP_DecryptInit_ex(ctx, NULL, NULL, s->key.data, nonce) != 1) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
282 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
283 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_DecryptInit_ex() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
284 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
285 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
286 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
287 if (EVP_DecryptUpdate(ctx, NULL, &len, ad->data, ad->len) != 1) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
288 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
289 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_DecryptUpdate() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
290 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
291 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
292 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
293 if (EVP_DecryptUpdate(ctx, out->data, &len, in->data, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
294 in->len - EVP_GCM_TLS_TAG_LEN) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
295 != 1) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
296 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
297 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
298 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_DecryptUpdate() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
299 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
300 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
301 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
302 out->len = len; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
303 tag = in->data + in->len - EVP_GCM_TLS_TAG_LEN; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
304 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
305 if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_GCM_SET_TAG, EVP_GCM_TLS_TAG_LEN, tag) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
306 == 0) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
307 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
308 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
309 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
310 "EVP_CIPHER_CTX_ctrl(EVP_CTRL_GCM_SET_TAG) failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
311 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
312 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
313 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
314 if (EVP_DecryptFinal_ex(ctx, out->data + len, &len) <= 0) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
315 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
316 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_DecryptFinal_ex failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
317 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
318 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
319 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
320 out->len += len; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
321 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
322 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
323 #endif |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
324 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
325 return NGX_OK; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
326 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
327 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
328 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
329 ngx_int_t |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
330 ngx_quic_tls_seal(ngx_connection_t *c, const ngx_aead_cipher_t *cipher, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
331 ngx_quic_secret_t *s, ngx_str_t *out, u_char *nonce, ngx_str_t *in, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
332 ngx_str_t *ad) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
333 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
334 out->len = in->len + EVP_GCM_TLS_TAG_LEN; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
335 out->data = ngx_pnalloc(c->pool, out->len); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
336 if (out->data == NULL) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
337 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
338 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
339 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
340 #ifdef OPENSSL_IS_BORINGSSL |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
341 EVP_AEAD_CTX *ctx; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
342 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
343 ctx = EVP_AEAD_CTX_new(cipher, s->key.data, s->key.len, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
344 EVP_AEAD_DEFAULT_TAG_LENGTH); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
345 if (ctx == NULL) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
346 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_AEAD_CTX_new() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
347 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
348 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
349 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
350 if (EVP_AEAD_CTX_seal(ctx, out->data, &out->len, out->len, nonce, s->iv.len, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
351 in->data, in->len, ad->data, ad->len) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
352 != 1) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
353 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
354 EVP_AEAD_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
355 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_AEAD_CTX_seal() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
356 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
357 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
358 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
359 EVP_AEAD_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
360 #else |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
361 int len; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
362 EVP_CIPHER_CTX *ctx; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
363 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
364 ctx = EVP_CIPHER_CTX_new(); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
365 if (ctx == NULL) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
366 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_CIPHER_CTX_new() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
367 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
368 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
369 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
370 if (EVP_EncryptInit_ex(ctx, cipher, NULL, NULL, NULL) != 1) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
371 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
372 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_EncryptInit_ex() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
373 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
374 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
375 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
376 if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_GCM_SET_IVLEN, s->iv.len, NULL) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
377 == 0) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
378 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
379 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
380 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
381 "EVP_CIPHER_CTX_ctrl(EVP_CTRL_GCM_SET_IVLEN) failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
382 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
383 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
384 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
385 if (EVP_EncryptInit_ex(ctx, NULL, NULL, s->key.data, nonce) != 1) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
386 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
387 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_EncryptInit_ex() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
388 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
389 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
390 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
391 if (EVP_EncryptUpdate(ctx, NULL, &len, ad->data, ad->len) != 1) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
392 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
393 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_EncryptUpdate() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
394 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
395 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
396 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
397 if (EVP_EncryptUpdate(ctx, out->data, &len, in->data, in->len) != 1) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
398 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
399 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_EncryptUpdate() failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
400 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
401 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
402 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
403 out->len = len; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
404 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
405 if (EVP_EncryptFinal_ex(ctx, out->data + out->len, &len) <= 0) { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
406 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
407 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_EncryptFinal_ex failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
408 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
409 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
410 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
411 out->len += len; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
412 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
413 if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_GCM_GET_TAG, EVP_GCM_TLS_TAG_LEN, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
414 out->data + in->len) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
415 == 0) |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
416 { |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
417 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
418 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
419 "EVP_CIPHER_CTX_ctrl(EVP_CTRL_GCM_GET_TAG) failed"); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
420 return NGX_ERROR; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
421 } |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
422 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
423 EVP_CIPHER_CTX_free(ctx); |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
424 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
425 out->len += EVP_GCM_TLS_TAG_LEN; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
426 #endif |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
427 |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
428 return NGX_OK; |
76e29ff31cd3
AEAD routines, introduced ngx_quic_tls_open()/ngx_quic_tls_seal().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8171
diff
changeset
|
429 } |
8178
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
430 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
431 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
432 ngx_int_t |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
433 ngx_quic_tls_hp(ngx_connection_t *c, const EVP_CIPHER *cipher, |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
434 ngx_quic_secret_t *s, u_char *out, u_char *in) |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
435 { |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
436 int outlen; |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
437 EVP_CIPHER_CTX *ctx; |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
438 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
439 ctx = EVP_CIPHER_CTX_new(); |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
440 if (ctx == NULL) { |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
441 return NGX_ERROR; |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
442 } |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
443 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
444 if (EVP_EncryptInit_ex(ctx, cipher, NULL, s->hp.data, NULL) != 1) { |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
445 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_EncryptInit_ex() failed"); |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
446 goto failed; |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
447 } |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
448 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
449 if (!EVP_EncryptUpdate(ctx, out, &outlen, in, 16)) { |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
450 ngx_ssl_error(NGX_LOG_INFO, c->log, 0, "EVP_EncryptUpdate() failed"); |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
451 goto failed; |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
452 } |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
453 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
454 EVP_CIPHER_CTX_free(ctx); |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
455 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
456 return NGX_OK; |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
457 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
458 failed: |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
459 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
460 EVP_CIPHER_CTX_free(ctx); |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
461 |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
462 return NGX_ERROR; |
a9ff4392ecde
QUIC header protection routines, introduced ngx_quic_tls_hp().
Sergey Kandaurov <pluknet@nginx.com>
parents:
8177
diff
changeset
|
463 } |