File: rsa.c

package info (click to toggle)
jose 10-2
  • links: PTS
  • area: main
  • in suites: buster
  • size: 2,772 kB
  • sloc: ansic: 9,696; sh: 4,816; makefile: 157
file content (117 lines) | stat: -rw-r--r-- 2,618 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
/* vim: set tabstop=8 shiftwidth=4 softtabstop=4 expandtab smarttab colorcolumn=80: */
/*
 * Copyright 2016 Red Hat, Inc.
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

#include "misc.h"
#include "../hooks.h"
#include <jose/openssl.h>

#include <string.h>

static RSA *
mkrsa(const json_t *jwk)
{
    openssl_auto(BIGNUM) *bn = NULL;
    json_auto_t *exp = NULL;
    RSA *key = NULL;
    int bits = 2048;

    if (json_unpack((json_t *) jwk, "{s?i,s?O}",
                    "bits", &bits, "e", &exp) == -1)
        return NULL;

    if (bits < 2048)
        return NULL;

    if (!exp)
        exp = json_integer(65537);

    switch (exp ? exp->type : JSON_NULL) {
    case JSON_STRING:
        bn = bn_decode_json(exp);
        if (!bn)
            return NULL;
        break;

    case JSON_INTEGER:
        bn = BN_new();
        if (!bn)
            return NULL;

        if (BN_set_word(bn, json_integer_value(exp)) <= 0)
            return NULL;
        break;

    default:
        break;
    }

    key = RSA_new();
    if (!key)
        return NULL;

    bits = RSA_generate_key_ex(key, bits, bn, NULL);
    if (bits <= 0) {
        RSA_free(key);
        key = NULL;
    }

    return key;
}

static bool
jwk_make_handles(jose_cfg_t *cfg, const json_t *jwk)
{
    const char *kty = NULL;

    if (json_unpack((json_t *) jwk, "{s:s}", "kty", &kty) == -1)
        return false;

    return strcmp(kty, "RSA") == 0;
}

static json_t *
jwk_make_execute(jose_cfg_t *cfg, const json_t *jwk)
{
    json_auto_t *key = NULL;
    RSA *rsa = NULL;

    if (!jwk_make_handles(cfg, jwk))
        return NULL;

    rsa = mkrsa(jwk);
    if (!rsa)
        return NULL;

    key = jose_openssl_jwk_from_RSA(cfg, rsa);
    RSA_free(rsa);
    if (!key)
        return NULL;

    return json_pack("{s:[s,s],s:O}", "del", "bits", "e", "upd", key);
}

static void __attribute__((constructor))
constructor(void)
{
    static jose_hook_jwk_t jwk = {
        .kind = JOSE_HOOK_JWK_KIND_MAKE,
        .make.handles = jwk_make_handles,
        .make.execute = jwk_make_execute
    };

    jose_hook_jwk_push(&jwk);
}