mirror of
git://anongit.mindrot.org/openssh.git
synced 2024-12-26 11:52:06 +00:00
eb8b60e320
[PROTOCOL PROTOCOL.agent PROTOCOL.certkeys auth2-jpake.c authfd.c] [authfile.c buffer.h dns.c kex.c kex.h key.c key.h monitor.c] [monitor_wrap.c myproposal.h packet.c packet.h pathnames.h readconf.c] [ssh-add.1 ssh-add.c ssh-agent.1 ssh-agent.c ssh-keygen.1 ssh-keygen.c] [ssh-keyscan.1 ssh-keyscan.c ssh-keysign.8 ssh.1 ssh.c ssh2.h] [ssh_config.5 sshconnect.c sshconnect2.c sshd.8 sshd.c sshd_config.5] [uuencode.c uuencode.h bufec.c kexecdh.c kexecdhc.c kexecdhs.c ssh-ecdsa.c] Implement Elliptic Curve Cryptography modes for key exchange (ECDH) and host/user keys (ECDSA) as specified by RFC5656. ECDH and ECDSA offer better performance than plain DH and DSA at the same equivalent symmetric key length, as well as much shorter keys. Only the mandatory sections of RFC5656 are implemented, specifically the three REQUIRED curves nistp256, nistp384 and nistp521 and only ECDH and ECDSA. Point compression (optional in RFC5656 is NOT implemented). Certificate host and user keys using the new ECDSA key types are supported. Note that this code has not been tested for interoperability and may be subject to change. feedback and ok markus@
123 lines
4.1 KiB
C
123 lines
4.1 KiB
C
/* $OpenBSD: packet.h,v 1.54 2010/08/31 11:54:45 djm Exp $ */
|
|
|
|
/*
|
|
* Author: Tatu Ylonen <ylo@cs.hut.fi>
|
|
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
|
|
* All rights reserved
|
|
* Interface for the packet protocol functions.
|
|
*
|
|
* As far as I am concerned, the code I have written for this software
|
|
* can be used freely for any purpose. Any derived versions of this
|
|
* software must be clearly marked as such, and if the derived work is
|
|
* incompatible with the protocol description in the RFC file, it must be
|
|
* called by a name other than "ssh" or "Secure Shell".
|
|
*/
|
|
|
|
#ifndef PACKET_H
|
|
#define PACKET_H
|
|
|
|
#include <termios.h>
|
|
|
|
#include <openssl/bn.h>
|
|
#include <openssl/ec.h>
|
|
|
|
void packet_set_connection(int, int);
|
|
void packet_set_timeout(int, int);
|
|
void packet_set_nonblocking(void);
|
|
int packet_get_connection_in(void);
|
|
int packet_get_connection_out(void);
|
|
void packet_close(void);
|
|
void packet_set_encryption_key(const u_char *, u_int, int);
|
|
u_int packet_get_encryption_key(u_char *);
|
|
void packet_set_protocol_flags(u_int);
|
|
u_int packet_get_protocol_flags(void);
|
|
void packet_start_compression(int);
|
|
void packet_set_interactive(int);
|
|
int packet_is_interactive(void);
|
|
void packet_set_server(void);
|
|
void packet_set_authenticated(void);
|
|
|
|
void packet_start(u_char);
|
|
void packet_put_char(int ch);
|
|
void packet_put_int(u_int value);
|
|
void packet_put_int64(u_int64_t value);
|
|
void packet_put_bignum(BIGNUM * value);
|
|
void packet_put_bignum2(BIGNUM * value);
|
|
void packet_put_ecpoint(const EC_GROUP *, const EC_POINT *);
|
|
void packet_put_string(const void *buf, u_int len);
|
|
void packet_put_cstring(const char *str);
|
|
void packet_put_raw(const void *buf, u_int len);
|
|
void packet_send(void);
|
|
|
|
int packet_read(void);
|
|
void packet_read_expect(int type);
|
|
int packet_read_poll(void);
|
|
void packet_process_incoming(const char *buf, u_int len);
|
|
int packet_read_seqnr(u_int32_t *seqnr_p);
|
|
int packet_read_poll_seqnr(u_int32_t *seqnr_p);
|
|
|
|
u_int packet_get_char(void);
|
|
u_int packet_get_int(void);
|
|
u_int64_t packet_get_int64(void);
|
|
void packet_get_bignum(BIGNUM * value);
|
|
void packet_get_bignum2(BIGNUM * value);
|
|
void packet_get_ecpoint(const EC_GROUP *, EC_POINT *);
|
|
void *packet_get_raw(u_int *length_ptr);
|
|
void *packet_get_string(u_int *length_ptr);
|
|
char *packet_get_cstring(u_int *length_ptr);
|
|
void *packet_get_string_ptr(u_int *length_ptr);
|
|
void packet_disconnect(const char *fmt,...) __attribute__((format(printf, 1, 2)));
|
|
void packet_send_debug(const char *fmt,...) __attribute__((format(printf, 1, 2)));
|
|
|
|
void set_newkeys(int mode);
|
|
int packet_get_keyiv_len(int);
|
|
void packet_get_keyiv(int, u_char *, u_int);
|
|
int packet_get_keycontext(int, u_char *);
|
|
void packet_set_keycontext(int, u_char *);
|
|
void packet_get_state(int, u_int32_t *, u_int64_t *, u_int32_t *, u_int64_t *);
|
|
void packet_set_state(int, u_int32_t, u_int64_t, u_int32_t, u_int64_t);
|
|
int packet_get_ssh1_cipher(void);
|
|
void packet_set_iv(int, u_char *);
|
|
void *packet_get_newkeys(int);
|
|
|
|
void packet_write_poll(void);
|
|
void packet_write_wait(void);
|
|
int packet_have_data_to_write(void);
|
|
int packet_not_very_much_data_to_write(void);
|
|
|
|
int packet_connection_is_on_socket(void);
|
|
int packet_connection_is_ipv4(void);
|
|
int packet_remaining(void);
|
|
void packet_send_ignore(int);
|
|
void packet_add_padding(u_char);
|
|
|
|
void tty_make_modes(int, struct termios *);
|
|
void tty_parse_modes(int, int *);
|
|
|
|
void packet_set_alive_timeouts(int);
|
|
int packet_inc_alive_timeouts(void);
|
|
int packet_set_maxsize(u_int);
|
|
u_int packet_get_maxsize(void);
|
|
|
|
/* don't allow remaining bytes after the end of the message */
|
|
#define packet_check_eom() \
|
|
do { \
|
|
int _len = packet_remaining(); \
|
|
if (_len > 0) { \
|
|
logit("Packet integrity error (%d bytes remaining) at %s:%d", \
|
|
_len ,__FILE__, __LINE__); \
|
|
packet_disconnect("Packet integrity error."); \
|
|
} \
|
|
} while (0)
|
|
|
|
int packet_need_rekeying(void);
|
|
void packet_set_rekey_limit(u_int32_t);
|
|
|
|
void packet_backup_state(void);
|
|
void packet_restore_state(void);
|
|
|
|
void *packet_get_input(void);
|
|
void *packet_get_output(void);
|
|
|
|
#endif /* PACKET_H */
|