Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 1 | /* |
Damien Miller | 98225c2 | 2004-02-17 16:49:41 +1100 | [diff] [blame] | 2 | * Copyright (c) 1999,2000,2004 Damien Miller <djm@mindrot.org> |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 3 | * |
Damien Miller | 98225c2 | 2004-02-17 16:49:41 +1100 | [diff] [blame] | 4 | * Permission to use, copy, modify, and distribute this software for any |
| 5 | * purpose with or without fee is hereby granted, provided that the above |
| 6 | * copyright notice and this permission notice appear in all copies. |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 7 | * |
Damien Miller | 98225c2 | 2004-02-17 16:49:41 +1100 | [diff] [blame] | 8 | * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES |
| 9 | * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF |
| 10 | * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR |
| 11 | * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES |
| 12 | * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN |
| 13 | * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF |
| 14 | * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 15 | */ |
| 16 | |
| 17 | #include "includes.h" |
Damien Miller | a2dc603 | 2001-03-19 10:00:53 +1100 | [diff] [blame] | 18 | #include "log.h" |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 19 | |
| 20 | #ifndef HAVE_ARC4RANDOM |
| 21 | |
Damien Miller | 72c9a7e | 2000-09-24 11:10:13 +1100 | [diff] [blame] | 22 | #include <openssl/rand.h> |
| 23 | #include <openssl/rc4.h> |
Damien Miller | a2dc603 | 2001-03-19 10:00:53 +1100 | [diff] [blame] | 24 | #include <openssl/err.h> |
Damien Miller | 72c9a7e | 2000-09-24 11:10:13 +1100 | [diff] [blame] | 25 | |
Damien Miller | c30d35c | 2000-08-30 09:40:09 +1100 | [diff] [blame] | 26 | /* Size of key to use */ |
| 27 | #define SEED_SIZE 20 |
| 28 | |
| 29 | /* Number of bytes to reseed after */ |
Damien Miller | 656d717 | 2000-10-27 09:27:32 +1100 | [diff] [blame] | 30 | #define REKEY_BYTES (1 << 24) |
Damien Miller | c30d35c | 2000-08-30 09:40:09 +1100 | [diff] [blame] | 31 | |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 32 | static int rc4_ready = 0; |
| 33 | static RC4_KEY rc4; |
| 34 | |
Damien Miller | 66df70c | 2005-02-16 13:01:28 +1100 | [diff] [blame] | 35 | unsigned int |
| 36 | arc4random(void) |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 37 | { |
| 38 | unsigned int r = 0; |
Damien Miller | 60bc517 | 2001-03-19 09:38:15 +1100 | [diff] [blame] | 39 | static int first_time = 1; |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 40 | |
Damien Miller | 60bc517 | 2001-03-19 09:38:15 +1100 | [diff] [blame] | 41 | if (rc4_ready <= 0) { |
Tim Rice | 63cf841 | 2002-05-08 15:57:18 -0700 | [diff] [blame] | 42 | if (first_time) |
Damien Miller | 60bc517 | 2001-03-19 09:38:15 +1100 | [diff] [blame] | 43 | seed_rng(); |
| 44 | first_time = 0; |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 45 | arc4random_stir(); |
Damien Miller | 60bc517 | 2001-03-19 09:38:15 +1100 | [diff] [blame] | 46 | } |
| 47 | |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 48 | RC4(&rc4, sizeof(r), (unsigned char *)&r, (unsigned char *)&r); |
Damien Miller | c30d35c | 2000-08-30 09:40:09 +1100 | [diff] [blame] | 49 | |
| 50 | rc4_ready -= sizeof(r); |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 51 | |
| 52 | return(r); |
| 53 | } |
| 54 | |
Damien Miller | 66df70c | 2005-02-16 13:01:28 +1100 | [diff] [blame] | 55 | void |
| 56 | arc4random_stir(void) |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 57 | { |
Damien Miller | c30d35c | 2000-08-30 09:40:09 +1100 | [diff] [blame] | 58 | unsigned char rand_buf[SEED_SIZE]; |
Damien Miller | 65df174 | 2004-07-19 09:30:38 +1000 | [diff] [blame] | 59 | int i; |
Damien Miller | 60bc517 | 2001-03-19 09:38:15 +1100 | [diff] [blame] | 60 | |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 61 | memset(&rc4, 0, sizeof(rc4)); |
Damien Miller | cafbcc7 | 2003-03-17 16:13:53 +1100 | [diff] [blame] | 62 | if (RAND_bytes(rand_buf, sizeof(rand_buf)) <= 0) |
Damien Miller | 60bc517 | 2001-03-19 09:38:15 +1100 | [diff] [blame] | 63 | fatal("Couldn't obtain random bytes (error %ld)", |
| 64 | ERR_get_error()); |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 65 | RC4_set_key(&rc4, sizeof(rand_buf), rand_buf); |
Damien Miller | 65df174 | 2004-07-19 09:30:38 +1000 | [diff] [blame] | 66 | |
| 67 | /* |
| 68 | * Discard early keystream, as per recommendations in: |
| 69 | * http://www.wisdom.weizmann.ac.il/~itsik/RC4/Papers/Rc4_ksa.ps |
| 70 | */ |
| 71 | for(i = 0; i <= 256; i += sizeof(rand_buf)) |
| 72 | RC4(&rc4, sizeof(rand_buf), rand_buf, rand_buf); |
| 73 | |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 74 | memset(rand_buf, 0, sizeof(rand_buf)); |
Damien Miller | 60bc517 | 2001-03-19 09:38:15 +1100 | [diff] [blame] | 75 | |
Damien Miller | c30d35c | 2000-08-30 09:40:09 +1100 | [diff] [blame] | 76 | rc4_ready = REKEY_BYTES; |
Damien Miller | 11fa2cc | 2000-08-16 10:35:58 +1000 | [diff] [blame] | 77 | } |
| 78 | #endif /* !HAVE_ARC4RANDOM */ |