annotate src/core/ngx_crypt.c @ 684:660139fd80ca NGINX_1_3_5

nginx 1.3.5 *) Change: the ngx_http_mp4_module module no longer skips tracks in formats other than H.264 and AAC. *) Bugfix: a segmentation fault might occur in a worker process if the "map" directive was used with variables as values. *) Bugfix: a segmentation fault might occur in a worker process if the "geo" directive was used with the "ranges" parameter but without the "default" parameter; the bug had appeared in 0.8.43. Thanks to Zhen Chen and Weibin Yao. *) Bugfix: in the -p command-line parameter handling. *) Bugfix: in the mail proxy server. *) Bugfix: of minor potential bugs. Thanks to Coverity. *) Bugfix: nginx/Windows could not be built with Visual Studio 2005 Express. Thanks to HAYASHI Kentaro.
author Igor Sysoev <http://sysoev.ru>
date Tue, 21 Aug 2012 00:00:00 +0400
parents 5cb5db9975ba
children
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
626
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
1
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
2 /*
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
3 * Copyright (C) Maxim Dounin
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
4 */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
5
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
6
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
7 #include <ngx_config.h>
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
8 #include <ngx_core.h>
682
5cb5db9975ba nginx 1.3.4
Igor Sysoev <http://sysoev.ru>
parents: 628
diff changeset
9 #include <ngx_crypt.h>
626
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
10 #include <ngx_md5.h>
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
11 #if (NGX_HAVE_SHA1)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
12 #include <ngx_sha1.h>
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
13 #endif
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
14
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
15
628
83b58b182b76 nginx 1.0.4
Igor Sysoev <http://sysoev.ru>
parents: 626
diff changeset
16 #if (NGX_CRYPT)
83b58b182b76 nginx 1.0.4
Igor Sysoev <http://sysoev.ru>
parents: 626
diff changeset
17
626
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
18 static ngx_int_t ngx_crypt_apr1(ngx_pool_t *pool, u_char *key, u_char *salt,
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
19 u_char **encrypted);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
20 static ngx_int_t ngx_crypt_plain(ngx_pool_t *pool, u_char *key, u_char *salt,
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
21 u_char **encrypted);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
22
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
23 #if (NGX_HAVE_SHA1)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
24
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
25 static ngx_int_t ngx_crypt_ssha(ngx_pool_t *pool, u_char *key, u_char *salt,
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
26 u_char **encrypted);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
27
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
28 #endif
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
29
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
30
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
31 static u_char *ngx_crypt_to64(u_char *p, uint32_t v, size_t n);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
32
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
33
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
34 ngx_int_t
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
35 ngx_crypt(ngx_pool_t *pool, u_char *key, u_char *salt, u_char **encrypted)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
36 {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
37 if (ngx_strncmp(salt, "$apr1$", sizeof("$apr1$") - 1) == 0) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
38 return ngx_crypt_apr1(pool, key, salt, encrypted);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
39
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
40 } else if (ngx_strncmp(salt, "{PLAIN}", sizeof("{PLAIN}") - 1) == 0) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
41 return ngx_crypt_plain(pool, key, salt, encrypted);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
42
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
43 #if (NGX_HAVE_SHA1)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
44 } else if (ngx_strncmp(salt, "{SSHA}", sizeof("{SSHA}") - 1) == 0) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
45 return ngx_crypt_ssha(pool, key, salt, encrypted);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
46 #endif
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
47 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
48
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
49 /* fallback to libc crypt() */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
50
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
51 return ngx_libc_crypt(pool, key, salt, encrypted);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
52 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
53
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
54
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
55 static ngx_int_t
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
56 ngx_crypt_apr1(ngx_pool_t *pool, u_char *key, u_char *salt, u_char **encrypted)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
57 {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
58 ngx_int_t n;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
59 ngx_uint_t i;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
60 u_char *p, *last, final[16];
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
61 size_t saltlen, keylen;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
62 ngx_md5_t md5, ctx1;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
63
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
64 /* Apache's apr1 crypt is Paul-Henning Kamp's md5 crypt with $apr1$ magic */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
65
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
66 keylen = ngx_strlen(key);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
67
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
68 /* true salt: no magic, max 8 chars, stop at first $ */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
69
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
70 salt += sizeof("$apr1$") - 1;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
71 last = salt + 8;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
72 for (p = salt; *p && *p != '$' && p < last; p++) { /* void */ }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
73 saltlen = p - salt;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
74
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
75 /* hash key and salt */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
76
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
77 ngx_md5_init(&md5);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
78 ngx_md5_update(&md5, key, keylen);
628
83b58b182b76 nginx 1.0.4
Igor Sysoev <http://sysoev.ru>
parents: 626
diff changeset
79 ngx_md5_update(&md5, (u_char *) "$apr1$", sizeof("$apr1$") - 1);
626
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
80 ngx_md5_update(&md5, salt, saltlen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
81
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
82 ngx_md5_init(&ctx1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
83 ngx_md5_update(&ctx1, key, keylen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
84 ngx_md5_update(&ctx1, salt, saltlen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
85 ngx_md5_update(&ctx1, key, keylen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
86 ngx_md5_final(final, &ctx1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
87
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
88 for (n = keylen; n > 0; n -= 16) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
89 ngx_md5_update(&md5, final, n > 16 ? 16 : n);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
90 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
91
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
92 ngx_memzero(final, sizeof(final));
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
93
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
94 for (i = keylen; i; i >>= 1) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
95 if (i & 1) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
96 ngx_md5_update(&md5, final, 1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
97
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
98 } else {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
99 ngx_md5_update(&md5, key, 1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
100 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
101 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
102
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
103 ngx_md5_final(final, &md5);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
104
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
105 for (i = 0; i < 1000; i++) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
106 ngx_md5_init(&ctx1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
107
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
108 if (i & 1) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
109 ngx_md5_update(&ctx1, key, keylen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
110
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
111 } else {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
112 ngx_md5_update(&ctx1, final, 16);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
113 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
114
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
115 if (i % 3) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
116 ngx_md5_update(&ctx1, salt, saltlen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
117 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
118
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
119 if (i % 7) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
120 ngx_md5_update(&ctx1, key, keylen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
121 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
122
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
123 if (i & 1) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
124 ngx_md5_update(&ctx1, final, 16);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
125
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
126 } else {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
127 ngx_md5_update(&ctx1, key, keylen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
128 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
129
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
130 ngx_md5_final(final, &ctx1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
131 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
132
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
133 /* output */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
134
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
135 *encrypted = ngx_pnalloc(pool, sizeof("$apr1$") - 1 + saltlen + 16 + 1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
136 if (*encrypted == NULL) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
137 return NGX_ERROR;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
138 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
139
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
140 p = ngx_cpymem(*encrypted, "$apr1$", sizeof("$apr1$") - 1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
141 p = ngx_copy(p, salt, saltlen);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
142 *p++ = '$';
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
143
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
144 p = ngx_crypt_to64(p, (final[ 0]<<16) | (final[ 6]<<8) | final[12], 4);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
145 p = ngx_crypt_to64(p, (final[ 1]<<16) | (final[ 7]<<8) | final[13], 4);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
146 p = ngx_crypt_to64(p, (final[ 2]<<16) | (final[ 8]<<8) | final[14], 4);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
147 p = ngx_crypt_to64(p, (final[ 3]<<16) | (final[ 9]<<8) | final[15], 4);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
148 p = ngx_crypt_to64(p, (final[ 4]<<16) | (final[10]<<8) | final[ 5], 4);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
149 p = ngx_crypt_to64(p, final[11], 2);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
150 *p = '\0';
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
151
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
152 return NGX_OK;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
153 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
154
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
155
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
156 static u_char *
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
157 ngx_crypt_to64(u_char *p, uint32_t v, size_t n)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
158 {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
159 static u_char itoa64[] =
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
160 "./0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
161
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
162 while (n--) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
163 *p++ = itoa64[v & 0x3f];
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
164 v >>= 6;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
165 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
166
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
167 return p;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
168 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
169
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
170
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
171 static ngx_int_t
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
172 ngx_crypt_plain(ngx_pool_t *pool, u_char *key, u_char *salt, u_char **encrypted)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
173 {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
174 size_t len;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
175 u_char *p;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
176
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
177 len = ngx_strlen(key);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
178
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
179 *encrypted = ngx_pnalloc(pool, sizeof("{PLAIN}") - 1 + len + 1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
180 if (*encrypted == NULL) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
181 return NGX_ERROR;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
182 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
183
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
184 p = ngx_cpymem(*encrypted, "{PLAIN}", sizeof("{PLAIN}") - 1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
185 ngx_memcpy(p, key, len + 1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
186
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
187 return NGX_OK;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
188 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
189
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
190
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
191 #if (NGX_HAVE_SHA1)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
192
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
193 static ngx_int_t
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
194 ngx_crypt_ssha(ngx_pool_t *pool, u_char *key, u_char *salt, u_char **encrypted)
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
195 {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
196 size_t len;
684
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
197 ngx_int_t rc;
626
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
198 ngx_str_t encoded, decoded;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
199 ngx_sha1_t sha1;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
200
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
201 /* "{SSHA}" base64(SHA1(key salt) salt) */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
202
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
203 /* decode base64 salt to find out true salt */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
204
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
205 encoded.data = salt + sizeof("{SSHA}") - 1;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
206 encoded.len = ngx_strlen(encoded.data);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
207
684
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
208 len = ngx_max(ngx_base64_decoded_length(encoded.len), 20);
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
209
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
210 decoded.data = ngx_pnalloc(pool, len);
626
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
211 if (decoded.data == NULL) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
212 return NGX_ERROR;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
213 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
214
684
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
215 rc = ngx_decode_base64(&decoded, &encoded);
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
216
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
217 if (rc != NGX_OK || decoded.len < 20) {
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
218 decoded.len = 20;
660139fd80ca nginx 1.3.5
Igor Sysoev <http://sysoev.ru>
parents: 682
diff changeset
219 }
626
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
220
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
221 /* update SHA1 from key and salt */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
222
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
223 ngx_sha1_init(&sha1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
224 ngx_sha1_update(&sha1, key, ngx_strlen(key));
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
225 ngx_sha1_update(&sha1, decoded.data + 20, decoded.len - 20);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
226 ngx_sha1_final(decoded.data, &sha1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
227
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
228 /* encode it back to base64 */
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
229
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
230 len = sizeof("{SSHA}") - 1 + ngx_base64_encoded_length(decoded.len) + 1;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
231
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
232 *encrypted = ngx_pnalloc(pool, len);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
233 if (*encrypted == NULL) {
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
234 return NGX_ERROR;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
235 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
236
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
237 encoded.data = ngx_cpymem(*encrypted, "{SSHA}", sizeof("{SSHA}") - 1);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
238 ngx_encode_base64(&encoded, &decoded);
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
239 encoded.data[encoded.len] = '\0';
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
240
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
241 return NGX_OK;
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
242 }
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
243
a7a5fa2e395b nginx 1.0.3
Igor Sysoev <http://sysoev.ru>
parents:
diff changeset
244 #endif /* NGX_HAVE_SHA1 */
628
83b58b182b76 nginx 1.0.4
Igor Sysoev <http://sysoev.ru>
parents: 626
diff changeset
245
83b58b182b76 nginx 1.0.4
Igor Sysoev <http://sysoev.ru>
parents: 626
diff changeset
246 #endif /* NGX_CRYPT */