2 * Copyright (c) 2000-2001,2011,2014 Apple Inc. All Rights Reserved.
4 * The contents of this file constitute Original Code as defined in and are
5 * subject to the Apple Public Source License Version 1.2 (the 'License').
6 * You may not use this file except in compliance with the License. Please obtain
7 * a copy of the License at http://www.apple.com/publicsource and read it before
10 * This Original Code and all software distributed under the License are
11 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS
12 * OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, INCLUDING WITHOUT
13 * LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
14 * PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. Please see the License for the
15 * specific language governing rights and limitations under the License.
19 * MacContext.h - AppleCSPContext for HMAC{SHA1,MD5}
22 #ifndef _MAC_CONTEXT_H_
23 #define _MAC_CONTEXT_H_
25 #include <AppleCSPContext.h>
26 #include <CommonCrypto/CommonHMAC.h>
29 * TLS Export Ciphers require HMAC calculation with a secret key
30 * size of 0 bytes. We'd really like to enforce a minimum key size equal
31 * the digest size, per RFC 2104, but TLS precludes that.
33 #define HMAC_MIN_KEY_SIZE 0
34 #define HMAC_SHA_MIN_KEY_SIZE HMAC_MIN_KEY_SIZE
35 #define HMAC_MD5_MIN_KEY_SIZE HMAC_MIN_KEY_SIZE
36 #define HMAC_MAX_KEY_SIZE 2048
38 class MacContext
: public AppleCSPContext
{
41 AppleCSPSession
&session
,
42 CSSM_ALGORITHMS alg
) :
43 AppleCSPContext(session
),
48 /* called out from CSPFullPluginSession....
49 * both generate and verify: */
50 void init(const Context
&context
, bool isSigning
);
51 void update(const CssmData
&data
);
54 void final(CssmData
&out
);
57 void final(const CssmData
&in
);
59 size_t outputSize(bool final
, size_t inSize
);
62 CCHmacContext hmacCtx
;
67 #ifdef CRYPTKIT_CSP_ENABLE
68 #include <security_cryptkit/HmacSha1Legacy.h>
70 /* This version is bug-for-bug compatible with a legacy implementation */
72 class MacLegacyContext
: public AppleCSPContext
{
75 AppleCSPSession
&session
,
76 CSSM_ALGORITHMS alg
) :
77 AppleCSPContext(session
), mHmac(NULL
) { }
80 /* called out from CSPFullPluginSession....
81 * both generate and verify: */
82 void init(const Context
&context
, bool isSigning
);
83 void update(const CssmData
&data
);
86 void final(CssmData
&out
);
89 void final(const CssmData
&in
);
91 size_t outputSize(bool final
, size_t inSize
);
94 hmacLegacyContextRef mHmac
;
97 #endif /* CRYPTKIT_CSP_ENABLE */
99 #endif /* _MAC_CONTEXT_H_ */