| Alex Gaynor | af82d5e | 2013-10-29 17:07:24 -0700 | [diff] [blame] | 1 | .. hazmat:: | 
| Alex Gaynor | 0f7f781 | 2013-09-30 10:52:36 -0700 | [diff] [blame] | 2 |  | 
| Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 3 | OpenSSL backend | 
| Alex Gaynor | 8f42fe4 | 2013-12-24 13:15:52 -0800 | [diff] [blame] | 4 | =============== | 
| Donald Stufft | e51fb93 | 2013-10-27 17:26:17 -0400 | [diff] [blame] | 5 |  | 
| Paul Kehrer | 12649af | 2014-03-10 12:45:19 -0400 | [diff] [blame] | 6 | The `OpenSSL`_ C library. Cryptography supports version ``0.9.8e`` (present in | 
 | 7 | Red Hat Enterprise Linux 5) and greater. Earlier versions may work but are | 
 | 8 | **not tested or supported**. | 
| Alex Gaynor | 6d02e2d | 2013-09-30 10:37:22 -0700 | [diff] [blame] | 9 |  | 
| Alex Gaynor | f8796b1 | 2013-12-13 20:28:55 -0800 | [diff] [blame] | 10 | .. data:: cryptography.hazmat.backends.openssl.backend | 
| Alex Gaynor | 6d02e2d | 2013-09-30 10:37:22 -0700 | [diff] [blame] | 11 |  | 
| Paul Kehrer | 3f17c7c | 2014-01-20 16:32:26 -0600 | [diff] [blame] | 12 |     This is the exposed API for the OpenSSL backend. | 
| Paul Kehrer | 2502ce5 | 2014-01-18 09:32:47 -0600 | [diff] [blame] | 13 |  | 
| Alex Gaynor | 031c2cb | 2014-01-31 11:44:53 -0800 | [diff] [blame] | 14 |     It implements the following interfaces: | 
 | 15 |  | 
 | 16 |     * :class:`~cryptography.hazmat.backends.interfaces.CipherBackend` | 
| Paul Kehrer | 3d75429 | 2014-05-01 09:09:34 -0500 | [diff] [blame] | 17 |     * :class:`~cryptography.hazmat.backends.interfaces.CMACBackend` | 
| Paul Kehrer | 99a249d | 2015-01-04 15:55:22 -0600 | [diff] [blame] | 18 |     * :class:`~cryptography.hazmat.backends.interfaces.DERSerializationBackend` | 
| Mohammed Attia | 59edb61 | 2014-04-25 22:44:40 +0200 | [diff] [blame] | 19 |     * :class:`~cryptography.hazmat.backends.interfaces.DSABackend` | 
| Terry Chia | 7b59df1 | 2014-12-28 20:46:26 +0800 | [diff] [blame] | 20 |     * :class:`~cryptography.hazmat.backends.interfaces.EllipticCurveBackend` | 
| Alex Gaynor | 031c2cb | 2014-01-31 11:44:53 -0800 | [diff] [blame] | 21 |     * :class:`~cryptography.hazmat.backends.interfaces.HashBackend` | 
 | 22 |     * :class:`~cryptography.hazmat.backends.interfaces.HMACBackend` | 
 | 23 |     * :class:`~cryptography.hazmat.backends.interfaces.PBKDF2HMACBackend` | 
| Alex Stapleton | 8f2250f | 2014-02-08 12:24:02 +0000 | [diff] [blame] | 24 |     * :class:`~cryptography.hazmat.backends.interfaces.RSABackend` | 
| Terry Chia | 7b59df1 | 2014-12-28 20:46:26 +0800 | [diff] [blame] | 25 |     * :class:`~cryptography.hazmat.backends.interfaces.PEMSerializationBackend` | 
 | 26 |     * :class:`~cryptography.hazmat.backends.interfaces.X509Backend` | 
| Alex Gaynor | 031c2cb | 2014-01-31 11:44:53 -0800 | [diff] [blame] | 27 |  | 
| Paul Kehrer | e4acd5d | 2014-02-03 21:59:29 -0600 | [diff] [blame] | 28 |     It also exposes the following: | 
| Paul Kehrer | 2502ce5 | 2014-01-18 09:32:47 -0600 | [diff] [blame] | 29 |  | 
| Paul Kehrer | cfa2d62 | 2014-01-19 14:01:25 -0600 | [diff] [blame] | 30 |     .. attribute:: name | 
| Paul Kehrer | 2502ce5 | 2014-01-18 09:32:47 -0600 | [diff] [blame] | 31 |  | 
| Paul Kehrer | cfa2d62 | 2014-01-19 14:01:25 -0600 | [diff] [blame] | 32 |         The string name of this backend: ``"openssl"`` | 
| Alex Gaynor | 6d02e2d | 2013-09-30 10:37:22 -0700 | [diff] [blame] | 33 |  | 
| Paul Kehrer | d52b89b | 2014-01-31 10:57:17 -0600 | [diff] [blame] | 34 |     .. method:: activate_osrandom_engine() | 
| Paul Kehrer | 3f17c7c | 2014-01-20 16:32:26 -0600 | [diff] [blame] | 35 |  | 
| Paul Kehrer | d52b89b | 2014-01-31 10:57:17 -0600 | [diff] [blame] | 36 |         Activates the OS random engine. This will effectively disable OpenSSL's | 
 | 37 |         default CSPRNG. | 
| Paul Kehrer | 3f17c7c | 2014-01-20 16:32:26 -0600 | [diff] [blame] | 38 |  | 
| Paul Kehrer | d258222 | 2014-02-05 16:21:19 -0600 | [diff] [blame] | 39 |     .. method:: activate_builtin_random() | 
| Paul Kehrer | 3f17c7c | 2014-01-20 16:32:26 -0600 | [diff] [blame] | 40 |  | 
| Paul Kehrer | d258222 | 2014-02-05 16:21:19 -0600 | [diff] [blame] | 41 |         This will activate the default OpenSSL CSPRNG. | 
| Paul Kehrer | 3f17c7c | 2014-01-20 16:32:26 -0600 | [diff] [blame] | 42 |  | 
| Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 43 | OS random engine | 
| Paul Kehrer | 3f17c7c | 2014-01-20 16:32:26 -0600 | [diff] [blame] | 44 | ---------------- | 
 | 45 |  | 
| Paul Kehrer | ae2138a | 2014-01-29 22:19:47 -0600 | [diff] [blame] | 46 | OpenSSL uses a user-space CSPRNG that is seeded from system random ( | 
| Paul Kehrer | 136ff17 | 2014-01-29 21:23:11 -0600 | [diff] [blame] | 47 | ``/dev/urandom`` or ``CryptGenRandom``). This CSPRNG is not reseeded | 
 | 48 | automatically when a process calls ``fork()``. This can result in situations | 
 | 49 | where two different processes can return similar or identical keys and | 
 | 50 | compromise the security of the system. | 
| Paul Kehrer | 3f17c7c | 2014-01-20 16:32:26 -0600 | [diff] [blame] | 51 |  | 
| Paul Kehrer | 136ff17 | 2014-01-29 21:23:11 -0600 | [diff] [blame] | 52 | The approach this project has chosen to mitigate this vulnerability is to | 
| Alex Gaynor | 969f18e | 2014-05-17 20:07:35 -0700 | [diff] [blame] | 53 | include an engine that replaces the OpenSSL default CSPRNG with one that | 
 | 54 | sources its entropy from ``/dev/urandom`` on UNIX-like operating systems and | 
 | 55 | uses ``CryptGenRandom`` on Windows. This method of pulling from the system pool | 
| Paul Kehrer | 136ff17 | 2014-01-29 21:23:11 -0600 | [diff] [blame] | 56 | allows us to avoid potential issues with `initializing the RNG`_ as well as | 
 | 57 | protecting us from the ``fork()`` weakness. | 
 | 58 |  | 
| Paul Kehrer | 8042b29 | 2014-01-31 10:44:36 -0600 | [diff] [blame] | 59 | This engine is **active** by default when importing the OpenSSL backend. When | 
 | 60 | active this engine will be used to generate all the random data OpenSSL | 
 | 61 | requests. | 
 | 62 |  | 
| Paul Kehrer | 8042b29 | 2014-01-31 10:44:36 -0600 | [diff] [blame] | 63 | When importing only the binding it is added to the engine list but | 
 | 64 | **not activated**. | 
 | 65 |  | 
| Paul Kehrer | 3f17c7c | 2014-01-20 16:32:26 -0600 | [diff] [blame] | 66 |  | 
| Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 67 | OS random sources | 
| Paul Kehrer | 55809a1 | 2014-01-29 21:41:16 -0600 | [diff] [blame] | 68 | ----------------- | 
| Paul Kehrer | 9967bc5 | 2014-01-29 21:39:13 -0600 | [diff] [blame] | 69 |  | 
 | 70 | On OS X and FreeBSD ``/dev/urandom`` is an alias for ``/dev/random`` and | 
 | 71 | utilizes the `Yarrow`_ algorithm. | 
 | 72 |  | 
| Paul Kehrer | 012bfbc | 2014-02-11 23:37:51 -0600 | [diff] [blame] | 73 | On Windows the implementation of ``CryptGenRandom`` depends on which version of | 
| Paul Kehrer | 039b478 | 2014-02-11 23:50:56 -0600 | [diff] [blame] | 74 | the operation system you are using. See the `Microsoft documentation`_ for more | 
| Paul Kehrer | 012bfbc | 2014-02-11 23:37:51 -0600 | [diff] [blame] | 75 | details. | 
| Paul Kehrer | 9967bc5 | 2014-01-29 21:39:13 -0600 | [diff] [blame] | 76 |  | 
| Alex Gaynor | 969f18e | 2014-05-17 20:07:35 -0700 | [diff] [blame] | 77 | Linux uses its own PRNG design. ``/dev/urandom`` is a non-blocking source | 
 | 78 | seeded from the same pool as ``/dev/random``. | 
| Paul Kehrer | 9967bc5 | 2014-01-29 21:39:13 -0600 | [diff] [blame] | 79 |  | 
 | 80 |  | 
| Alex Gaynor | 6d02e2d | 2013-09-30 10:37:22 -0700 | [diff] [blame] | 81 | .. _`OpenSSL`: https://www.openssl.org/ | 
| Alex Gaynor | 2332c19 | 2014-04-23 08:07:27 -0700 | [diff] [blame] | 82 | .. _`initializing the RNG`: https://en.wikipedia.org/wiki/OpenSSL#Predictable_keys_.28Debian-specific.29 | 
| Alex Gaynor | e9df294 | 2014-12-12 10:56:26 -0800 | [diff] [blame] | 83 | .. _`Yarrow`: https://en.wikipedia.org/wiki/Yarrow_algorithm | 
| Alex Gaynor | 3fad190 | 2015-02-18 12:48:29 -0800 | [diff] [blame] | 84 | .. _`Microsoft documentation`: https://msdn.microsoft.com/en-us/library/windows/desktop/aa379942(v=vs.85).aspx |