diff --git a/lib/isc/iterated_hash.c b/lib/isc/iterated_hash.c index 5e5b67c388..de1f3a36a3 100644 --- a/lib/isc/iterated_hash.c +++ b/lib/isc/iterated_hash.c @@ -13,12 +13,64 @@ #include -#include +#include #include -#include #include +#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000 + +#include + +int +isc_iterated_hash(unsigned char *out, const unsigned int hashalg, + const int iterations, const unsigned char *salt, + const int saltlength, const unsigned char *in, + const int inlength) { + REQUIRE(out != NULL); + + int n = 0; + size_t len; + const unsigned char *buf; + SHA_CTX ctx; + + if (hashalg != 1) { + return (0); + } + + buf = in; + len = inlength; + + do { + if (SHA1_Init(&ctx) != 1) { + return (0); + } + + if (SHA1_Update(&ctx, buf, len) != 1) { + return (0); + } + + if (SHA1_Update(&ctx, salt, saltlength) != 1) { + return (0); + } + + if (SHA1_Final(out, &ctx) != 1) { + return (0); + } + + buf = out; + len = SHA_DIGEST_LENGTH; + } while (n++ < iterations); + + return (SHA_DIGEST_LENGTH); +} + +#else + +#include + +#include + int isc_iterated_hash(unsigned char *out, const unsigned int hashalg, const int iterations, const unsigned char *salt, @@ -30,18 +82,24 @@ isc_iterated_hash(unsigned char *out, const unsigned int hashalg, size_t len; unsigned int outlength = 0; const unsigned char *buf; - EVP_MD_CTX *ctx = EVP_MD_CTX_create(); - - RUNTIME_CHECK(ctx != NULL); + EVP_MD_CTX *ctx; + ; + EVP_MD *md; if (hashalg != 1) { return (0); } - len = inlength; + ctx = EVP_MD_CTX_new(); + RUNTIME_CHECK(ctx != NULL); + md = EVP_MD_fetch(NULL, "SHA1", NULL); + RUNTIME_CHECK(md != NULL); + buf = in; + len = inlength; + do { - if (EVP_DigestInit_ex(ctx, ISC_MD_SHA1, NULL) != 1) { + if (EVP_DigestInit_ex(ctx, md, NULL) != 1) { goto fail; } @@ -62,10 +120,15 @@ isc_iterated_hash(unsigned char *out, const unsigned int hashalg, } while (n++ < iterations); EVP_MD_CTX_free(ctx); + EVP_MD_free(md); return (outlength); fail: EVP_MD_CTX_free(ctx); + EVP_MD_free(md); + return (0); } + +#endif