os/ossrv/ssl/tsrc/topenssl/src/dhparam.c
author sl@SLION-WIN7.fritz.box
Fri, 15 Jun 2012 03:10:57 +0200
changeset 0 bde4ae8d615e
permissions -rw-r--r--
First public contribution.
sl@0
     1
/* apps/dhparam.c */
sl@0
     2
/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
sl@0
     3
 * All rights reserved.
sl@0
     4
 *
sl@0
     5
 * This package is an SSL implementation written
sl@0
     6
 * by Eric Young (eay@cryptsoft.com).
sl@0
     7
 * The implementation was written so as to conform with Netscapes SSL.
sl@0
     8
 * 
sl@0
     9
 * This library is free for commercial and non-commercial use as long as
sl@0
    10
 * the following conditions are aheared to.  The following conditions
sl@0
    11
 * apply to all code found in this distribution, be it the RC4, RSA,
sl@0
    12
 * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
sl@0
    13
 * included with this distribution is covered by the same copyright terms
sl@0
    14
 * except that the holder is Tim Hudson (tjh@cryptsoft.com).
sl@0
    15
 * 
sl@0
    16
 * Copyright remains Eric Young's, and as such any Copyright notices in
sl@0
    17
 * the code are not to be removed.
sl@0
    18
 * If this package is used in a product, Eric Young should be given attribution
sl@0
    19
 * as the author of the parts of the library used.
sl@0
    20
 * This can be in the form of a textual message at program startup or
sl@0
    21
 * in documentation (online or textual) provided with the package.
sl@0
    22
 * 
sl@0
    23
 * Redistribution and use in source and binary forms, with or without
sl@0
    24
 * modification, are permitted provided that the following conditions
sl@0
    25
 * are met:
sl@0
    26
 * 1. Redistributions of source code must retain the copyright
sl@0
    27
 *    notice, this list of conditions and the following disclaimer.
sl@0
    28
 * 2. Redistributions in binary form must reproduce the above copyright
sl@0
    29
 *    notice, this list of conditions and the following disclaimer in the
sl@0
    30
 *    documentation and/or other materials provided with the distribution.
sl@0
    31
 * 3. All advertising materials mentioning features or use of this software
sl@0
    32
 *    must display the following acknowledgement:
sl@0
    33
 *    "This product includes cryptographic software written by
sl@0
    34
 *     Eric Young (eay@cryptsoft.com)"
sl@0
    35
 *    The word 'cryptographic' can be left out if the rouines from the library
sl@0
    36
 *    being used are not cryptographic related :-).
sl@0
    37
 * 4. If you include any Windows specific code (or a derivative thereof) from 
sl@0
    38
 *    the apps directory (application code) you must include an acknowledgement:
sl@0
    39
 *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
sl@0
    40
 * 
sl@0
    41
 * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
sl@0
    42
 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
sl@0
    43
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
sl@0
    44
 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
sl@0
    45
 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
sl@0
    46
 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
sl@0
    47
 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
sl@0
    48
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
sl@0
    49
 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
sl@0
    50
 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
sl@0
    51
 * SUCH DAMAGE.
sl@0
    52
 * 
sl@0
    53
 * The licence and distribution terms for any publically available version or
sl@0
    54
 * derivative of this code cannot be changed.  i.e. this code cannot simply be
sl@0
    55
 * copied and put under another distribution licence
sl@0
    56
 * [including the GNU Public Licence.]
sl@0
    57
 */
sl@0
    58
/* ====================================================================
sl@0
    59
 * Copyright (c) 1998-2000 The OpenSSL Project.  All rights reserved.
sl@0
    60
 *
sl@0
    61
 * Redistribution and use in source and binary forms, with or without
sl@0
    62
 * modification, are permitted provided that the following conditions
sl@0
    63
 * are met:
sl@0
    64
 *
sl@0
    65
 * 1. Redistributions of source code must retain the above copyright
sl@0
    66
 *    notice, this list of conditions and the following disclaimer. 
sl@0
    67
 *
sl@0
    68
 * 2. Redistributions in binary form must reproduce the above copyright
sl@0
    69
 *    notice, this list of conditions and the following disclaimer in
sl@0
    70
 *    the documentation and/or other materials provided with the
sl@0
    71
 *    distribution.
sl@0
    72
 *
sl@0
    73
 * 3. All advertising materials mentioning features or use of this
sl@0
    74
 *    software must display the following acknowledgment:
sl@0
    75
 *    "This product includes software developed by the OpenSSL Project
sl@0
    76
 *    for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
sl@0
    77
 *
sl@0
    78
 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
sl@0
    79
 *    endorse or promote products derived from this software without
sl@0
    80
 *    prior written permission. For written permission, please contact
sl@0
    81
 *    openssl-core@openssl.org.
sl@0
    82
 *
sl@0
    83
 * 5. Products derived from this software may not be called "OpenSSL"
sl@0
    84
 *    nor may "OpenSSL" appear in their names without prior written
sl@0
    85
 *    permission of the OpenSSL Project.
sl@0
    86
 *
sl@0
    87
 * 6. Redistributions of any form whatsoever must retain the following
sl@0
    88
 *    acknowledgment:
sl@0
    89
 *    "This product includes software developed by the OpenSSL Project
sl@0
    90
 *    for use in the OpenSSL Toolkit (http://www.openssl.org/)"
sl@0
    91
 *
sl@0
    92
 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
sl@0
    93
 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
sl@0
    94
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
sl@0
    95
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
sl@0
    96
 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
sl@0
    97
 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
sl@0
    98
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
sl@0
    99
 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
sl@0
   100
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
sl@0
   101
 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
sl@0
   102
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
sl@0
   103
 * OF THE POSSIBILITY OF SUCH DAMAGE.
sl@0
   104
 * ====================================================================
sl@0
   105
 *
sl@0
   106
 * This product includes cryptographic software written by Eric Young
sl@0
   107
 * (eay@cryptsoft.com).  This product includes software written by Tim
sl@0
   108
 * Hudson (tjh@cryptsoft.com).
sl@0
   109
 *
sl@0
   110
 */
sl@0
   111
sl@0
   112
#include <openssl/opensslconf.h>	/* for OPENSSL_NO_DH */
sl@0
   113
#ifndef OPENSSL_NO_DH
sl@0
   114
#include <stdio.h>
sl@0
   115
#include <stdlib.h>
sl@0
   116
#include <time.h>
sl@0
   117
#include <string.h>
sl@0
   118
#include "apps.h"
sl@0
   119
#include <openssl/bio.h>
sl@0
   120
#include <openssl/err.h>
sl@0
   121
#include <openssl/bn.h>
sl@0
   122
#include <openssl/dh.h>
sl@0
   123
#include <openssl/x509.h>
sl@0
   124
#include <openssl/pem.h>
sl@0
   125
sl@0
   126
#ifndef OPENSSL_NO_DSA
sl@0
   127
#include <openssl/dsa.h>
sl@0
   128
#endif
sl@0
   129
sl@0
   130
#undef PROG
sl@0
   131
#define PROG	dhparam_main
sl@0
   132
sl@0
   133
#define DEFBITS	512
sl@0
   134
sl@0
   135
/* -inform arg	- input format - default PEM (DER or PEM)
sl@0
   136
 * -outform arg - output format - default PEM
sl@0
   137
 * -in arg	- input file - default stdin
sl@0
   138
 * -out arg	- output file - default stdout
sl@0
   139
 * -dsaparam  - read or generate DSA parameters, convert to DH
sl@0
   140
 * -check	- check the parameters are ok
sl@0
   141
 * -noout
sl@0
   142
 * -text
sl@0
   143
 * -C
sl@0
   144
 */
sl@0
   145
sl@0
   146
static int MS_CALLBACK dh_cb(int p, int n, BN_GENCB *cb);
sl@0
   147
sl@0
   148
int MAIN(int, char **);
sl@0
   149
sl@0
   150
int MAIN(int argc, char **argv)
sl@0
   151
	{
sl@0
   152
#ifndef OPENSSL_NO_ENGINE
sl@0
   153
	ENGINE *e = NULL;
sl@0
   154
#endif
sl@0
   155
	DH *dh=NULL;
sl@0
   156
	int i,badops=0,text=0;
sl@0
   157
#ifndef OPENSSL_NO_DSA
sl@0
   158
	int dsaparam=0;
sl@0
   159
#endif
sl@0
   160
	BIO *in=NULL,*out=NULL;
sl@0
   161
	int informat,outformat,check=0,noout=0,C=0,ret=1;
sl@0
   162
	char *infile,*outfile,*prog;
sl@0
   163
	char *inrand=NULL;
sl@0
   164
#ifndef OPENSSL_NO_ENGINE
sl@0
   165
	char *engine=NULL;
sl@0
   166
#endif
sl@0
   167
	int num = 0, g = 0;
sl@0
   168
sl@0
   169
	apps_startup();
sl@0
   170
sl@0
   171
	if (bio_err == NULL)
sl@0
   172
		if ((bio_err=BIO_new(BIO_s_file())) != NULL)
sl@0
   173
			BIO_set_fp(bio_err,stderr,BIO_NOCLOSE|BIO_FP_TEXT);
sl@0
   174
sl@0
   175
sl@0
   176
	if (!load_config(bio_err, NULL))
sl@0
   177
		goto end;
sl@0
   178
sl@0
   179
	infile=NULL;
sl@0
   180
	outfile=NULL;
sl@0
   181
	informat=FORMAT_PEM;
sl@0
   182
	outformat=FORMAT_PEM;
sl@0
   183
sl@0
   184
	prog=argv[0];
sl@0
   185
	argc--;
sl@0
   186
	argv++;
sl@0
   187
	while (argc >= 1)
sl@0
   188
		{
sl@0
   189
		if 	(strcmp(*argv,"-inform") == 0)
sl@0
   190
			{
sl@0
   191
			if (--argc < 1) goto bad;
sl@0
   192
			informat=str2fmt(*(++argv));
sl@0
   193
			}
sl@0
   194
		else if (strcmp(*argv,"-outform") == 0)
sl@0
   195
			{
sl@0
   196
			if (--argc < 1) goto bad;
sl@0
   197
			outformat=str2fmt(*(++argv));
sl@0
   198
			}
sl@0
   199
		else if (strcmp(*argv,"-in") == 0)
sl@0
   200
			{
sl@0
   201
			if (--argc < 1) goto bad;
sl@0
   202
			infile= *(++argv);
sl@0
   203
			}
sl@0
   204
		else if (strcmp(*argv,"-out") == 0)
sl@0
   205
			{
sl@0
   206
			if (--argc < 1) goto bad;
sl@0
   207
			outfile= *(++argv);
sl@0
   208
			}
sl@0
   209
#ifndef OPENSSL_NO_ENGINE
sl@0
   210
		else if (strcmp(*argv,"-engine") == 0)
sl@0
   211
			{
sl@0
   212
			if (--argc < 1) goto bad;
sl@0
   213
			engine= *(++argv);
sl@0
   214
			}
sl@0
   215
#endif
sl@0
   216
		else if (strcmp(*argv,"-check") == 0)
sl@0
   217
			check=1;
sl@0
   218
		else if (strcmp(*argv,"-text") == 0)
sl@0
   219
			text=1;
sl@0
   220
#ifndef OPENSSL_NO_DSA
sl@0
   221
		else if (strcmp(*argv,"-dsaparam") == 0)
sl@0
   222
			dsaparam=1;
sl@0
   223
#endif
sl@0
   224
		else if (strcmp(*argv,"-C") == 0)
sl@0
   225
			C=1;
sl@0
   226
		else if (strcmp(*argv,"-noout") == 0)
sl@0
   227
			noout=1;
sl@0
   228
		else if (strcmp(*argv,"-2") == 0)
sl@0
   229
			g=2;
sl@0
   230
		else if (strcmp(*argv,"-5") == 0)
sl@0
   231
			g=5;
sl@0
   232
		else if (strcmp(*argv,"-rand") == 0)
sl@0
   233
			{
sl@0
   234
			if (--argc < 1) goto bad;
sl@0
   235
			inrand= *(++argv);
sl@0
   236
			}
sl@0
   237
		else if (((sscanf(*argv,"%d",&num) == 0) || (num <= 0)))
sl@0
   238
			goto bad;
sl@0
   239
		argv++;
sl@0
   240
		argc--;
sl@0
   241
		}
sl@0
   242
sl@0
   243
	if (badops)
sl@0
   244
		{
sl@0
   245
bad:
sl@0
   246
		BIO_printf(bio_err,"%s [options] [numbits]\n",prog);
sl@0
   247
		BIO_printf(bio_err,"where options are\n");
sl@0
   248
		BIO_printf(bio_err," -inform arg   input format - one of DER PEM\n");
sl@0
   249
		BIO_printf(bio_err," -outform arg  output format - one of DER PEM\n");
sl@0
   250
		BIO_printf(bio_err," -in arg       input file\n");
sl@0
   251
		BIO_printf(bio_err," -out arg      output file\n");
sl@0
   252
#ifndef OPENSSL_NO_DSA
sl@0
   253
		BIO_printf(bio_err," -dsaparam     read or generate DSA parameters, convert to DH\n");
sl@0
   254
#endif
sl@0
   255
		BIO_printf(bio_err," -check        check the DH parameters\n");
sl@0
   256
		BIO_printf(bio_err," -text         print a text form of the DH parameters\n");
sl@0
   257
		BIO_printf(bio_err," -C            Output C code\n");
sl@0
   258
		BIO_printf(bio_err," -2            generate parameters using  2 as the generator value\n");
sl@0
   259
		BIO_printf(bio_err," -5            generate parameters using  5 as the generator value\n");
sl@0
   260
		BIO_printf(bio_err," numbits       number of bits in to generate (default 512)\n");
sl@0
   261
#ifndef OPENSSL_NO_ENGINE
sl@0
   262
		BIO_printf(bio_err," -engine e     use engine e, possibly a hardware device.\n");
sl@0
   263
#endif
sl@0
   264
		BIO_printf(bio_err," -rand file%cfile%c...\n", LIST_SEPARATOR_CHAR, LIST_SEPARATOR_CHAR);
sl@0
   265
		BIO_printf(bio_err,"               - load the file (or the files in the directory) into\n");
sl@0
   266
		BIO_printf(bio_err,"               the random number generator\n");
sl@0
   267
		BIO_printf(bio_err," -noout        no output\n");
sl@0
   268
		goto end;
sl@0
   269
		}
sl@0
   270
sl@0
   271
	ERR_load_crypto_strings();
sl@0
   272
sl@0
   273
#ifndef OPENSSL_NO_ENGINE
sl@0
   274
        e = setup_engine(bio_err, engine, 0);
sl@0
   275
#endif
sl@0
   276
sl@0
   277
	if (g && !num)
sl@0
   278
		num = DEFBITS;
sl@0
   279
sl@0
   280
#ifndef OPENSSL_NO_DSA
sl@0
   281
	if (dsaparam)
sl@0
   282
		{
sl@0
   283
		if (g)
sl@0
   284
			{
sl@0
   285
			BIO_printf(bio_err, "generator may not be chosen for DSA parameters\n");
sl@0
   286
			goto end;
sl@0
   287
			}
sl@0
   288
		}
sl@0
   289
	else
sl@0
   290
#endif
sl@0
   291
		{
sl@0
   292
		/* DH parameters */
sl@0
   293
		if (num && !g)
sl@0
   294
			g = 2;
sl@0
   295
		}
sl@0
   296
sl@0
   297
	if(num) {
sl@0
   298
sl@0
   299
		BN_GENCB cb;
sl@0
   300
		BN_GENCB_set(&cb, dh_cb, bio_err);
sl@0
   301
		if (!app_RAND_load_file(NULL, bio_err, 1) && inrand == NULL)
sl@0
   302
			{
sl@0
   303
			BIO_printf(bio_err,"warning, not much extra random data, consider using the -rand option\n");
sl@0
   304
			}
sl@0
   305
		if (inrand != NULL)
sl@0
   306
			BIO_printf(bio_err,"%ld semi-random bytes loaded\n",
sl@0
   307
				app_RAND_load_files(inrand));
sl@0
   308
sl@0
   309
#ifndef OPENSSL_NO_DSA
sl@0
   310
		if (dsaparam)
sl@0
   311
			{
sl@0
   312
			DSA *dsa = DSA_new();
sl@0
   313
			
sl@0
   314
			BIO_printf(bio_err,"Generating DSA parameters, %d bit long prime\n",num);
sl@0
   315
			if(!dsa || !DSA_generate_parameters_ex(dsa, num,
sl@0
   316
						NULL, 0, NULL, NULL, &cb))
sl@0
   317
				{
sl@0
   318
				if(dsa) DSA_free(dsa);
sl@0
   319
				ERR_print_errors(bio_err);
sl@0
   320
				goto end;
sl@0
   321
				}
sl@0
   322
sl@0
   323
			dh = DSA_dup_DH(dsa);
sl@0
   324
			DSA_free(dsa);
sl@0
   325
			if (dh == NULL)
sl@0
   326
				{
sl@0
   327
				ERR_print_errors(bio_err);
sl@0
   328
				goto end;
sl@0
   329
				}
sl@0
   330
			}
sl@0
   331
		else
sl@0
   332
#endif
sl@0
   333
			{
sl@0
   334
			dh = DH_new();
sl@0
   335
			BIO_printf(bio_err,"Generating DH parameters, %d bit long safe prime, generator %d\n",num,g);
sl@0
   336
			BIO_printf(bio_err,"This is going to take a long time\n");
sl@0
   337
			if(!dh || !DH_generate_parameters_ex(dh, num, g, &cb))
sl@0
   338
				{
sl@0
   339
				if(dh) DH_free(dh);
sl@0
   340
				ERR_print_errors(bio_err);
sl@0
   341
				goto end;
sl@0
   342
				}
sl@0
   343
			}
sl@0
   344
sl@0
   345
		app_RAND_write_file(NULL, bio_err);
sl@0
   346
	} else {
sl@0
   347
sl@0
   348
		in=BIO_new(BIO_s_file());
sl@0
   349
		if (in == NULL)
sl@0
   350
			{
sl@0
   351
			ERR_print_errors(bio_err);
sl@0
   352
			goto end;
sl@0
   353
			}
sl@0
   354
		if (infile == NULL)
sl@0
   355
			BIO_set_fp(in,stdin,BIO_NOCLOSE);
sl@0
   356
			
sl@0
   357
		else
sl@0
   358
			{
sl@0
   359
			if (BIO_read_filename(in,infile) <= 0)
sl@0
   360
				{
sl@0
   361
				perror(infile);
sl@0
   362
				goto end;
sl@0
   363
				}
sl@0
   364
			}
sl@0
   365
sl@0
   366
		if	(informat != FORMAT_ASN1 && informat != FORMAT_PEM)
sl@0
   367
			{
sl@0
   368
			BIO_printf(bio_err,"bad input format specified\n");
sl@0
   369
			goto end;
sl@0
   370
			}
sl@0
   371
sl@0
   372
#ifndef OPENSSL_NO_DSA
sl@0
   373
		if (dsaparam)
sl@0
   374
			{
sl@0
   375
			DSA *dsa;
sl@0
   376
			
sl@0
   377
			if (informat == FORMAT_ASN1)
sl@0
   378
				dsa=d2i_DSAparams_bio(in,NULL);
sl@0
   379
			else /* informat == FORMAT_PEM */
sl@0
   380
				dsa=PEM_read_bio_DSAparams(in,NULL,NULL,NULL);
sl@0
   381
			
sl@0
   382
			if (dsa == NULL)
sl@0
   383
				{
sl@0
   384
				BIO_printf(bio_err,"unable to load DSA parameters\n");
sl@0
   385
				ERR_print_errors(bio_err);
sl@0
   386
				goto end;
sl@0
   387
				}
sl@0
   388
			
sl@0
   389
			dh = DSA_dup_DH(dsa);
sl@0
   390
			DSA_free(dsa);
sl@0
   391
			if (dh == NULL)
sl@0
   392
				{
sl@0
   393
				ERR_print_errors(bio_err);
sl@0
   394
				goto end;
sl@0
   395
				}
sl@0
   396
			}
sl@0
   397
		else
sl@0
   398
#endif
sl@0
   399
			{
sl@0
   400
			if (informat == FORMAT_ASN1)
sl@0
   401
				dh=d2i_DHparams_bio(in,NULL);
sl@0
   402
			else /* informat == FORMAT_PEM */
sl@0
   403
				dh=PEM_read_bio_DHparams(in,NULL,NULL,NULL);
sl@0
   404
			
sl@0
   405
			if (dh == NULL)
sl@0
   406
				{
sl@0
   407
				BIO_printf(bio_err,"unable to load DH parameters\n");
sl@0
   408
				ERR_print_errors(bio_err);
sl@0
   409
				goto end;
sl@0
   410
				}
sl@0
   411
			}
sl@0
   412
		
sl@0
   413
		/* dh != NULL */
sl@0
   414
	}
sl@0
   415
	
sl@0
   416
	out=BIO_new(BIO_s_file());
sl@0
   417
	if (out == NULL)
sl@0
   418
		{
sl@0
   419
		ERR_print_errors(bio_err);
sl@0
   420
		goto end;
sl@0
   421
		}
sl@0
   422
	if (outfile == NULL)
sl@0
   423
		{
sl@0
   424
		BIO_set_fp(out,stdout,BIO_NOCLOSE);
sl@0
   425
#ifdef OPENSSL_SYS_VMS
sl@0
   426
		{
sl@0
   427
		BIO *tmpbio = BIO_new(BIO_f_linebuffer());
sl@0
   428
		out = BIO_push(tmpbio, out);
sl@0
   429
		}
sl@0
   430
#endif
sl@0
   431
		}
sl@0
   432
	else
sl@0
   433
		{
sl@0
   434
		if (BIO_write_filename(out,outfile) <= 0)
sl@0
   435
			{
sl@0
   436
			perror(outfile);
sl@0
   437
			goto end;
sl@0
   438
			}
sl@0
   439
		}
sl@0
   440
sl@0
   441
sl@0
   442
	if (text)
sl@0
   443
		{
sl@0
   444
		DHparams_print(out,dh);
sl@0
   445
		}
sl@0
   446
	
sl@0
   447
	if (check)
sl@0
   448
		{
sl@0
   449
		if (!DH_check(dh,&i))
sl@0
   450
			{
sl@0
   451
			ERR_print_errors(bio_err);
sl@0
   452
			goto end;
sl@0
   453
			}
sl@0
   454
sl@0
   455
		if (i & DH_CHECK_P_NOT_PRIME)
sl@0
   456
			printf("p value is not prime\n");
sl@0
   457
		if (i & DH_CHECK_P_NOT_SAFE_PRIME)
sl@0
   458
			printf("p value is not a safe prime\n");
sl@0
   459
		if (i & DH_UNABLE_TO_CHECK_GENERATOR)
sl@0
   460
			printf("unable to check the generator value\n");
sl@0
   461
		if (i & DH_NOT_SUITABLE_GENERATOR)
sl@0
   462
			printf("the g value is not a generator\n");
sl@0
   463
		if (i == 0)
sl@0
   464
			printf("DH parameters appear to be ok.\n");
sl@0
   465
sl@0
   466
		}
sl@0
   467
	if (C)
sl@0
   468
		{
sl@0
   469
		unsigned char *data;
sl@0
   470
		int len,l,bits;
sl@0
   471
sl@0
   472
		len=BN_num_bytes(dh->p);
sl@0
   473
		bits=BN_num_bits(dh->p);
sl@0
   474
		data=(unsigned char *)OPENSSL_malloc(len);
sl@0
   475
		if (data == NULL)
sl@0
   476
			{
sl@0
   477
			perror("OPENSSL_malloc");
sl@0
   478
			goto end;
sl@0
   479
			}
sl@0
   480
		printf("#ifndef HEADER_DH_H\n"
sl@0
   481
		       "#include <openssl/dh.h>\n"
sl@0
   482
		       "#endif\n");
sl@0
   483
		printf("DH *get_dh%d()\n\t{\n",bits);
sl@0
   484
sl@0
   485
		l=BN_bn2bin(dh->p,data);
sl@0
   486
		printf("\tstatic unsigned char dh%d_p[]={",bits);
sl@0
   487
		for (i=0; i<l; i++)
sl@0
   488
			{
sl@0
   489
			if ((i%12) == 0) printf("\n\t\t");
sl@0
   490
			printf("0x%02X,",data[i]);
sl@0
   491
			}
sl@0
   492
		printf("\n\t\t};\n");
sl@0
   493
sl@0
   494
		l=BN_bn2bin(dh->g,data);
sl@0
   495
		printf("\tstatic unsigned char dh%d_g[]={",bits);
sl@0
   496
		for (i=0; i<l; i++)
sl@0
   497
			{
sl@0
   498
			if ((i%12) == 0) printf("\n\t\t");
sl@0
   499
			printf("0x%02X,",data[i]);
sl@0
   500
			}
sl@0
   501
		printf("\n\t\t};\n");
sl@0
   502
sl@0
   503
		printf("\tDH *dh;\n\n");
sl@0
   504
		printf("\tif ((dh=DH_new()) == NULL) return(NULL);\n");
sl@0
   505
		printf("\tdh->p=BN_bin2bn(dh%d_p,sizeof(dh%d_p),NULL);\n",
sl@0
   506
			bits,bits);
sl@0
   507
		printf("\tdh->g=BN_bin2bn(dh%d_g,sizeof(dh%d_g),NULL);\n",
sl@0
   508
			bits,bits);
sl@0
   509
		printf("\tif ((dh->p == NULL) || (dh->g == NULL))\n");
sl@0
   510
		printf("\t\t{ DH_free(dh); return(NULL); }\n");
sl@0
   511
		if (dh->length)
sl@0
   512
			printf("\tdh->length = %ld;\n", dh->length);
sl@0
   513
		printf("\treturn(dh);\n\t}\n");
sl@0
   514
sl@0
   515
		OPENSSL_free(data);
sl@0
   516
		}
sl@0
   517
sl@0
   518
sl@0
   519
	if (!noout)
sl@0
   520
		{
sl@0
   521
		if 	(outformat == FORMAT_ASN1)
sl@0
   522
			i=i2d_DHparams_bio(out,dh);
sl@0
   523
		else if (outformat == FORMAT_PEM)
sl@0
   524
			i=PEM_write_bio_DHparams(out,dh);
sl@0
   525
		else	{
sl@0
   526
			BIO_printf(bio_err,"bad output format specified for outfile\n");
sl@0
   527
			goto end;
sl@0
   528
			}
sl@0
   529
		if (!i)
sl@0
   530
			{
sl@0
   531
			BIO_printf(bio_err,"unable to write DH parameters\n");
sl@0
   532
			ERR_print_errors(bio_err);
sl@0
   533
			goto end;
sl@0
   534
			}
sl@0
   535
		}
sl@0
   536
	ret=0;
sl@0
   537
end:
sl@0
   538
	if (in != NULL) BIO_free(in);
sl@0
   539
	if (out != NULL) BIO_free_all(out);
sl@0
   540
	if (dh != NULL) DH_free(dh);
sl@0
   541
	apps_shutdown();
sl@0
   542
	OPENSSL_EXIT(ret);
sl@0
   543
	}
sl@0
   544
sl@0
   545
/* dh_cb is identical to dsa_cb in apps/dsaparam.c */
sl@0
   546
static int MS_CALLBACK dh_cb(int p, int n, BN_GENCB *cb)
sl@0
   547
	{
sl@0
   548
	char c='*';
sl@0
   549
sl@0
   550
	if (p == 0) c='.';
sl@0
   551
	if (p == 1) c='+';
sl@0
   552
	if (p == 2) c='*';
sl@0
   553
	if (p == 3) c='\n';
sl@0
   554
	BIO_write(cb->arg,&c,1);
sl@0
   555
	(void)BIO_flush(cb->arg);
sl@0
   556
#ifdef LINT
sl@0
   557
	p=n;
sl@0
   558
#endif
sl@0
   559
	return 1;
sl@0
   560
	}
sl@0
   561
sl@0
   562
#endif