mirror of
https://github.com/slackhq/nebula.git
synced 2026-08-16 00:47:02 +02:00
cleanup nonce
This commit is contained in:
+10
-11
@@ -42,21 +42,13 @@ func cipherAESGCMFIPS140(k [32]byte) noise.Cipher {
|
|||||||
gcm := aeadAESGCMTLS13(k[:], emptyNonce)
|
gcm := aeadAESGCMTLS13(k[:], emptyNonce)
|
||||||
gcm = extractFIPSAEAD(gcm)
|
gcm = extractFIPSAEAD(gcm)
|
||||||
return &aeadGCMFIPS140Cipher{
|
return &aeadGCMFIPS140Cipher{
|
||||||
AEAD: gcm,
|
AEAD: gcm,
|
||||||
ready: false,
|
|
||||||
nonce: func(n uint64) []byte {
|
|
||||||
// tls.aeadAESGCMTLS13 uses a 4 byte static prefix and an 8 byte nonce
|
|
||||||
var nonce [12]byte
|
|
||||||
binary.BigEndian.PutUint64(nonce[4:], n)
|
|
||||||
return nonce[:]
|
|
||||||
},
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
type aeadGCMFIPS140Cipher struct {
|
type aeadGCMFIPS140Cipher struct {
|
||||||
cipher.AEAD
|
cipher.AEAD
|
||||||
ready bool
|
ready bool
|
||||||
nonce func(uint64) []byte
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Extract the internal FIPS GCM implementation from the tls wrapper. The TLS
|
// Extract the internal FIPS GCM implementation from the tls wrapper. The TLS
|
||||||
@@ -99,11 +91,11 @@ func (c *aeadGCMFIPS140Cipher) Seal(dst, nonce, plaintext, additionalData []byte
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (c *aeadGCMFIPS140Cipher) Encrypt(out []byte, n uint64, ad, plaintext []byte) []byte {
|
func (c *aeadGCMFIPS140Cipher) Encrypt(out []byte, n uint64, ad, plaintext []byte) []byte {
|
||||||
return c.Seal(out, c.nonce(n), plaintext, ad)
|
return c.Seal(out, aeadGCMFIPS140CipherNonce(n), plaintext, ad)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *aeadGCMFIPS140Cipher) Decrypt(out []byte, n uint64, ad, ciphertext []byte) ([]byte, error) {
|
func (c *aeadGCMFIPS140Cipher) Decrypt(out []byte, n uint64, ad, ciphertext []byte) ([]byte, error) {
|
||||||
return c.Open(out, c.nonce(n), ciphertext, ad)
|
return c.Open(out, aeadGCMFIPS140CipherNonce(n), ciphertext, ad)
|
||||||
}
|
}
|
||||||
|
|
||||||
func (c *aeadGCMFIPS140Cipher) EncryptDanger(out, ad, plaintext []byte, n uint64, nb []byte) ([]byte, error) {
|
func (c *aeadGCMFIPS140Cipher) EncryptDanger(out, ad, plaintext []byte, n uint64, nb []byte) ([]byte, error) {
|
||||||
@@ -116,3 +108,10 @@ func (c *aeadGCMFIPS140Cipher) DecryptDanger(out, ad, ciphertext []byte, n uint6
|
|||||||
binary.BigEndian.PutUint64(nb[4:], n)
|
binary.BigEndian.PutUint64(nb[4:], n)
|
||||||
return c.Open(out, nb, ciphertext, ad)
|
return c.Open(out, nb, ciphertext, ad)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func aeadGCMFIPS140CipherNonce(n uint64) []byte {
|
||||||
|
// GCMWithXORCounterNonce uses a 4 byte static prefix and an 8 byte nonce
|
||||||
|
var nonce [12]byte
|
||||||
|
binary.BigEndian.PutUint64(nonce[4:], n)
|
||||||
|
return nonce[:]
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user