blob: ae1c322f42429100a21eb623691a293b71b20da0 [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001#ifndef _NET_AH_H
2#define _NET_AH_H
3
Herbert Xu9409f382006-08-06 19:49:12 +10004#include <linux/crypto.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -07005#include <net/xfrm.h>
6
7/* This is the maximum truncated ICV length that we know of. */
8#define MAX_AH_AUTH_LEN 12
9
10struct ah_data
11{
Linus Torvalds1da177e2005-04-16 15:20:36 -070012 u8 *work_icv;
13 int icv_full_len;
14 int icv_trunc_len;
15
Herbert Xu07d4ee52006-08-20 14:24:50 +100016 struct crypto_hash *tfm;
Linus Torvalds1da177e2005-04-16 15:20:36 -070017};
18
Herbert Xu07d4ee52006-08-20 14:24:50 +100019static inline int ah_mac_digest(struct ah_data *ahp, struct sk_buff *skb,
20 u8 *auth_data)
Linus Torvalds1da177e2005-04-16 15:20:36 -070021{
Herbert Xu07d4ee52006-08-20 14:24:50 +100022 struct hash_desc desc;
23 int err;
24
25 desc.tfm = ahp->tfm;
26 desc.flags = 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -070027
28 memset(auth_data, 0, ahp->icv_trunc_len);
Herbert Xu07d4ee52006-08-20 14:24:50 +100029 err = crypto_hash_init(&desc);
30 if (unlikely(err))
31 goto out;
32 err = skb_icv_walk(skb, &desc, 0, skb->len, crypto_hash_update);
33 if (unlikely(err))
34 goto out;
35 err = crypto_hash_final(&desc, ahp->work_icv);
36
37out:
38 return err;
Linus Torvalds1da177e2005-04-16 15:20:36 -070039}
40
Herbert Xu87bdc482007-10-10 15:45:25 -070041struct ip_auth_hdr;
42
43static inline struct ip_auth_hdr *ip_auth_hdr(const struct sk_buff *skb)
44{
45 return (struct ip_auth_hdr *)skb_transport_header(skb);
46}
47
Linus Torvalds1da177e2005-04-16 15:20:36 -070048#endif