blob: 5bfb7424148af728795161a6bd4662f5a7666d4e [file] [log] [blame]
Damien Millerd4a8b7e1999-10-27 13:42:43 +10001/*
2
3cipher.h
4
5Author: Tatu Ylonen <ylo@cs.hut.fi>
6
7Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
8 All rights reserved
9
10Created: Wed Apr 19 16:50:42 1995 ylo
11
12*/
13
Damien Miller7e8e8201999-11-16 13:37:16 +110014/* RCSID("$Id: cipher.h,v 1.3 1999/11/16 02:37:16 damien Exp $"); */
Damien Millerd4a8b7e1999-10-27 13:42:43 +100015
16#ifndef CIPHER_H
17#define CIPHER_H
18
Damien Miller7e8e8201999-11-16 13:37:16 +110019#include "config.h"
20
Damien Miller7f6ea021999-10-28 13:25:17 +100021#ifdef HAVE_OPENSSL
Damien Millerd4a8b7e1999-10-27 13:42:43 +100022#include <openssl/des.h>
23#include <openssl/blowfish.h>
Damien Miller7f6ea021999-10-28 13:25:17 +100024#endif
25#ifdef HAVE_SSL
26#include <ssl/des.h>
27#include <ssl/blowfish.h>
28#endif
Damien Millerd4a8b7e1999-10-27 13:42:43 +100029
30/* Cipher types. New types can be added, but old types should not be removed
31 for compatibility. The maximum allowed value is 31. */
32#define SSH_CIPHER_NOT_SET -1 /* None selected (invalid number). */
33#define SSH_CIPHER_NONE 0 /* no encryption */
34#define SSH_CIPHER_IDEA 1 /* IDEA CFB */
35#define SSH_CIPHER_DES 2 /* DES CBC */
36#define SSH_CIPHER_3DES 3 /* 3DES CBC */
Damien Miller7e8e8201999-11-16 13:37:16 +110037#define SSH_CIPHER_BROKEN_TSS 4 /* TRI's Simple Stream encryption CBC */
38#define SSH_CIPHER_BROKEN_RC4 5 /* Alleged RC4 */
Damien Millerd4a8b7e1999-10-27 13:42:43 +100039#define SSH_CIPHER_BLOWFISH 6
40
41typedef struct {
42 unsigned int type;
43 union {
44 struct {
45 des_key_schedule key1;
46 des_key_schedule key2;
47 des_cblock iv2;
48 des_key_schedule key3;
49 des_cblock iv3;
50 } des3;
51 struct {
52 struct bf_key_st key;
53 unsigned char iv[8];
54 } bf;
55 } u;
56} CipherContext;
57
58/* Returns a bit mask indicating which ciphers are supported by this
59 implementation. The bit mask has the corresponding bit set of each
60 supported cipher. */
61unsigned int cipher_mask();
62
63/* Returns the name of the cipher. */
64const char *cipher_name(int cipher);
65
66/* Parses the name of the cipher. Returns the number of the corresponding
67 cipher, or -1 on error. */
68int cipher_number(const char *name);
69
70/* Selects the cipher to use and sets the key. If for_encryption is true,
71 the key is setup for encryption; otherwise it is setup for decryption. */
72void cipher_set_key(CipherContext *context, int cipher,
73 const unsigned char *key, int keylen, int for_encryption);
74
75/* Sets key for the cipher by computing the MD5 checksum of the passphrase,
76 and using the resulting 16 bytes as the key. */
77void cipher_set_key_string(CipherContext *context, int cipher,
78 const char *passphrase, int for_encryption);
79
80/* Encrypts data using the cipher. */
81void cipher_encrypt(CipherContext *context, unsigned char *dest,
82 const unsigned char *src, unsigned int len);
83
84/* Decrypts data using the cipher. */
85void cipher_decrypt(CipherContext *context, unsigned char *dest,
86 const unsigned char *src, unsigned int len);
87
88/* If and CRC-32 attack is detected this function is called. Defaults
89 * to fatal, changed to packet_disconnect in sshd and ssh. */
90extern void (*cipher_attack_detected)(const char *fmt, ...);
91
92#endif /* CIPHER_H */