9#include <botan/internal/p11_mechanism.h>
10#include <botan/internal/scan_name.h>
11#include <botan/internal/parsing.h>
12#include <botan/internal/fmt.h>
18using PSS_Params = std::tuple<size_t, MechanismType, MGF>;
21const std::map<MechanismType, PSS_Params> PssOptions =
36 MechanismData(
const MechanismData& other) =
default;
37 MechanismData(MechanismData&& other) =
default;
39 MechanismData& operator=(
const MechanismData& other) =
default;
40 MechanismData& operator=(MechanismData&& other) =
default;
42 virtual ~MechanismData() =
default;
51class RSA_SignMechanism
final :
public MechanismData
57 m_mgf(static_cast<
MGF>(0)),
60 auto pss_option = PssOptions.find(type());
61 if(pss_option != PssOptions.end())
63 m_hash = std::get<1>(pss_option->second);
64 m_mgf = std::get<2>(pss_option->second);
65 m_salt_size = std::get<0>(pss_option->second);
70 MGF mgf()
const {
return m_mgf; }
71 size_t salt_size()
const {
return m_salt_size; }
92const std::map<std::string, RSA_SignMechanism> SignMechanisms =
133struct RSA_CryptMechanism
final :
public MechanismData
143 m_padding_size(padding_size)
147 RSA_CryptMechanism(typ, padding_size, static_cast<
MechanismType>(0), static_cast<
MGF>(0))
151 MGF mgf()
const {
return m_mgf; }
152 size_t padding_size()
const {
return m_padding_size; }
162 size_t m_padding_size;
166const std::map<std::string, RSA_CryptMechanism> CryptMechanisms =
178const std::map<std::string, MechanismType> EcdsaHash =
189const std::map<std::string, KeyDerivation> EcdhHash =
206 const std::string padding(padding_view);
207 auto mechanism_info_it = CryptMechanisms.find(padding);
208 if(mechanism_info_it == CryptMechanisms.end())
211 throw Lookup_Error(
"PKCS#11 RSA encrypt/decrypt does not support EME " + padding);
213 RSA_CryptMechanism mechanism_info = mechanism_info_it->second;
218 mech.m_parameters = std::make_shared<MechanismParameters>();
219 mech.m_parameters->oaep_params.hashAlg =
static_cast<CK_MECHANISM_TYPE>(mechanism_info.hash());
222 mech.m_parameters->oaep_params.pSourceData =
nullptr;
223 mech.m_parameters->oaep_params.ulSourceDataLen = 0;
224 mech.m_mechanism.
pParameter = mech.m_parameters.get();
227 mech.m_padding_size = mechanism_info.padding_size();
233 const std::string padding(padding_view);
234 auto mechanism_info_it = SignMechanisms.find(padding);
235 if(mechanism_info_it == SignMechanisms.end())
238 throw Lookup_Error(
"PKCS#11 RSA sign/verify does not support EMSA " + padding);
240 RSA_SignMechanism mechanism_info = mechanism_info_it->second;
243 if(PssOptions.find(mechanism_info.type()) != PssOptions.end())
245 mech.m_parameters = std::make_shared<MechanismParameters>();
246 mech.m_parameters->pss_params.hashAlg =
static_cast<CK_MECHANISM_TYPE>(mechanism_info.hash());
248 mech.m_parameters->pss_params.sLen =
static_cast<Ulong>(mechanism_info.salt_size());
249 mech.m_mechanism.
pParameter = mech.m_parameters.get();
257 const std::string hash_spec(hash_spec_view);
258 auto mechanism = EcdsaHash.find(hash_spec);
259 if(mechanism != EcdsaHash.end())
266 mechanism = EcdsaHash.find(req.
arg(0));
267 if(mechanism != EcdsaHash.end())
271 throw Lookup_Error(
fmt(
"PKCS #11 ECDSA sign/verify does not support {}", hash_spec));
276 std::vector<std::string> param_parts =
split_on(params,
',');
278 if(param_parts.empty() || param_parts.size() > 2)
283 const bool use_cofactor =
284 (param_parts[0] ==
"Cofactor") ||
285 (param_parts.size() == 2 && param_parts[1] ==
"Cofactor");
287 std::string kdf_name = (param_parts[0] ==
"Cofactor" ? param_parts[1] : param_parts[0]);
288 std::string hash = kdf_name;
290 if(kdf_name !=
"Raw")
296 hash = kdf_hash.
arg(0);
300 auto kdf = EcdhHash.find(hash);
301 if(kdf == EcdhHash.end())
303 throw Lookup_Error(
"PKCS#11 ECDH key derivation does not support KDF " + kdf_name);
306 mech.m_parameters = std::make_shared<MechanismParameters>();
307 mech.m_parameters->ecdh_params.kdf =
static_cast<CK_EC_KDF_TYPE>(kdf->second);
308 mech.m_mechanism.
pParameter = mech.m_parameters.get();
static MechanismWrapper create_rsa_sign_mechanism(std::string_view padding)
static MechanismWrapper create_ecdh_mechanism(std::string_view params)
MechanismType mechanism_type() const
static MechanismWrapper create_rsa_crypt_mechanism(std::string_view padding)
static MechanismWrapper create_ecdsa_mechanism(std::string_view hash)
MechanismWrapper(MechanismType mechanism_type)
std::string arg(size_t i) const
const std::string algo_name() const
int(* final)(unsigned char *, CTX *)
CK_RSA_PKCS_OAEP_PARAMS RsaPkcsOaepParams
CK_RSA_PKCS_PSS_PARAMS RsaPkcsPssParams
CK_ECDH1_DERIVE_PARAMS Ecdh1DeriveParams
std::string fmt(std::string_view format, const T &... args)
std::vector< std::string > split_on(std::string_view str, char delim)
#define CKZ_DATA_SPECIFIED
CK_ULONG CK_RSA_PKCS_MGF_TYPE
CK_ULONG CK_MECHANISM_TYPE