#ifndef _KERNEL
#include <ctype.h>
#include "k5-int.h"
#include "hash_provider.h"
krb5_error_code
krb5int_pbkdf2_hmac_sha1(
krb5_context context,
const krb5_data *out,
unsigned long count,
krb5_enctype enctype,
const krb5_data *pass, const krb5_data *salt)
{
krb5_error_code ret = 0;
CK_RV rv;
CK_PKCS5_PBKD2_PARAMS params;
CK_MECHANISM mechanism;
CK_OBJECT_CLASS class = CKO_SECRET_KEY;
CK_ATTRIBUTE tmpl[3];
CK_KEY_TYPE keytype;
CK_OBJECT_HANDLE hKey;
int attrs = 0;
CK_ULONG outlen, passlen;
mechanism.mechanism = CKM_PKCS5_PBKD2;
mechanism.pParameter = ¶ms;
mechanism.ulParameterLen = sizeof (params);
tmpl[attrs].type = CKA_CLASS;
tmpl[attrs].pValue = &class;
tmpl[attrs].ulValueLen = sizeof (class);
attrs++;
rv = get_key_type(enctype, &keytype);
if (rv != CKR_OK)
return (PKCS_ERR);
tmpl[attrs].type = CKA_KEY_TYPE;
tmpl[attrs].pValue = &keytype;
tmpl[attrs].ulValueLen = sizeof (keytype);
attrs++;
if (out->length > 0 &&
enctype != ENCTYPE_DES_CBC_CRC &&
enctype != ENCTYPE_DES_CBC_MD5 &&
enctype != ENCTYPE_DES_CBC_RAW &&
enctype != ENCTYPE_DES_HMAC_SHA1 &&
enctype != ENCTYPE_DES3_CBC_SHA1 &&
enctype != ENCTYPE_DES3_CBC_RAW) {
tmpl[attrs].type = CKA_VALUE_LEN;
outlen = (CK_ULONG)out->length;
tmpl[attrs].pValue = &outlen;
tmpl[attrs].ulValueLen = sizeof (outlen);
attrs++;
}
params.saltSource = CKZ_SALT_SPECIFIED;
params.pSaltSourceData = (void *)salt->data;
params.ulSaltSourceDataLen = salt->length;
params.iterations = count;
params.prf = CKP_PKCS5_PBKD2_HMAC_SHA1;
params.pPrfData = NULL;
params.ulPrfDataLen = 0;
params.pPassword = (CK_UTF8CHAR_PTR)pass->data;
passlen = (CK_ULONG)pass->length;
params.ulPasswordLen = &passlen;
rv = C_GenerateKey(krb_ctx_hSession(context), &mechanism, tmpl,
attrs, &hKey);
if (rv != CKR_OK)
ret = PKCS_ERR;
else {
tmpl[0].type = CKA_VALUE;
tmpl[0].pValue = out->data;
tmpl[0].ulValueLen = out->length;
rv = C_GetAttributeValue(krb_ctx_hSession(context), hKey,
tmpl, 1);
if (rv != CKR_OK)
ret = PKCS_ERR;
(void) C_DestroyObject(krb_ctx_hSession(context), hKey);
}
return (ret);
}
#endif