2 * Copyright (c) 2000-2001 Apple Computer, Inc. All Rights Reserved.
4 * The contents of this file constitute Original Code as defined in and are
5 * subject to the Apple Public Source License Version 1.2 (the 'License').
6 * You may not use this file except in compliance with the License. Please obtain
7 * a copy of the License at http://www.apple.com/publicsource and read it before
10 * This Original Code and all software distributed under the License are
11 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS
12 * OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, INCLUDING WITHOUT
13 * LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
14 * PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. Please see the License for the
15 * specific language governing rights and limitations under the License.
20 // cryptoclient - client interface to CSSM CSP encryption/decryption operations
22 #include <Security/cryptoclient.h>
24 using namespace CssmClient
;
27 Crypt::Crypt(const CSP
&csp
, CSSM_ALGORITHMS alg
) : Context(csp
, alg
)
30 mMode
= CSSM_ALGMODE_NONE
;
33 mPadding
= CSSM_PADDING_NONE
;
41 // Some crypto operations require a credential.
42 // Use a null credential if none was specified.
44 mCred
= &AccessCredentials::null
;
46 // Key is required unless we have a NULL algorithm (cleartext wrap/unwrap),
47 // in which case we'll make a symmetric context (it shouldn't matter then).
48 if (!mKey
&& mAlgorithm
!= CSSM_ALGID_NONE
)
49 CssmError::throwMe(CSSMERR_CSP_MISSING_ATTR_KEY
);
50 if (!mKey
|| mKey
->keyClass() == CSSM_KEYCLASS_SESSION_KEY
)
52 check(CSSM_CSP_CreateSymmetricContext(attachment()->handle(), mAlgorithm
,
53 mMode
, mCred
, mKey
, mInitVector
, mPadding
, NULL
,
58 check(CSSM_CSP_CreateAsymmetricContext(attachment()->handle(), mAlgorithm
,
59 mCred
, mKey
, mPadding
, &mHandle
));
60 //@@@ stick mode and initVector explicitly into the context?
65 void Crypt::cred(const AccessCredentials
*c
)
68 mCred
= &AccessCredentials::null
;
69 set(CSSM_ATTRIBUTE_ACCESS_CREDENTIALS
, *mCred
);
74 // Manage encryption contexts
78 Encrypt::encrypt(const CssmData
*in
, uint32 inCount
,
79 CssmData
*out
, uint32 outCount
, CssmData
&remData
)
83 check(CSSM_EncryptData(handle(), in
, inCount
, out
, outCount
, &total
, &remData
));
90 check(CSSM_EncryptDataInit(handle()));
95 Encrypt::encrypt(const CssmData
*in
, uint32 inCount
,
96 CssmData
*out
, uint32 outCount
)
100 check(CSSM_EncryptDataUpdate(handle(), in
, inCount
, out
, outCount
, &total
));
105 Encrypt::final(CssmData
&remData
)
108 check(CSSM_EncryptDataFinal(handle(), &remData
));
114 // Manage Decryption contexts
118 Decrypt::decrypt(const CssmData
*in
, uint32 inCount
,
119 CssmData
*out
, uint32 outCount
, CssmData
&remData
)
123 check(CSSM_DecryptData(handle(), in
, inCount
, out
, outCount
, &total
, &remData
));
130 check(CSSM_DecryptDataInit(handle()));
135 Decrypt::decrypt(const CssmData
*in
, uint32 inCount
,
136 CssmData
*out
, uint32 outCount
)
140 check(CSSM_DecryptDataUpdate(handle(), in
, inCount
, out
, outCount
, &total
));
145 Decrypt::final(CssmData
&remData
)
148 check(CSSM_DecryptDataFinal(handle(), &remData
));