mirror of
https://github.com/slackhq/nebula.git
synced 2026-09-30 02:26:37 +02:00
Add support for the "fips140" mode of Go: - https://go.dev/doc/security/fips140 - https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5247 You can build with `make fips140`, see the README changes for more info. Some differences from the boringcrypto builds: - We switch to using `go:linkname crypto/tls.aeadAESGCMTLS13`, which gives us the fips implementation for both `boringcrypto` and `fips140` modes. This means we also no longer need `-checklinkname=0` - Go native `fips140` doesn't need CGO_ENABLED=1 - We decide if we should use the fips140 GCM at runtime, if `fips140.Enabled()` is true. If you use the `make release-fips140`, we build with build tag `fips140enforce` which ensures the binary is running with fips140 enabled and that only P256 / AES-GCM is being used. If you don't want this enforce mode, you can build without the build tag.
55 lines
2.2 KiB
Go
55 lines
2.2 KiB
Go
package noiseutil
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
"math"
|
|
|
|
"github.com/flynn/noise"
|
|
)
|
|
|
|
// RejectHeadroom is the wrap gap for senders racing the counter, sized large enough for any routine count.
|
|
const RejectHeadroom = uint64(1) << 40
|
|
|
|
// RejectAfterMessages is the nonce ceiling: encrypting stops RejectHeadroom short of the wrap.
|
|
const RejectAfterMessages = math.MaxUint64 - RejectHeadroom
|
|
|
|
// ErrMessageCounterExhausted is returned by EncryptDanger once the nonce reaches RejectAfterMessages.
|
|
var ErrMessageCounterExhausted = errors.New("message counter exhausted")
|
|
|
|
// CipherState is the post-handshake AEAD cipher used for the data plane.
|
|
// Each supported cipher has its own concrete implementation in this package with the nonce endianness hardcoded,
|
|
// so the encrypt/decrypt fast path avoids interface dispatch on the byte order.
|
|
type CipherState interface {
|
|
// EncryptDanger encrypts and authenticates a given payload.
|
|
//
|
|
// out is a destination slice to hold the output of the EncryptDanger operation.
|
|
// - ad is additional data, which will be authenticated and appended to out, but not encrypted.
|
|
// - plaintext is encrypted, authenticated and appended to out.
|
|
// - n is a nonce value which must never be re-used with this key.
|
|
// - nb is a scratch buffer used to assemble the nonce.
|
|
EncryptDanger(out, ad, plaintext []byte, n uint64, nb []byte) ([]byte, error)
|
|
|
|
// DecryptDanger authenticates and decrypts a given payload, with the same argument shape as EncryptDanger.
|
|
DecryptDanger(out, ad, ciphertext []byte, n uint64, nb []byte) ([]byte, error)
|
|
|
|
// Overhead returns the AEAD tag size, or 0 if the receiver is nil.
|
|
Overhead() int
|
|
}
|
|
|
|
// NewCipherState wraps the post-handshake noise.CipherState in the per-cipher type that matches cipherFunc.
|
|
// cipherFunc must be the same cipher used to build the noise CipherSuite that produced s.
|
|
func NewCipherState(s *noise.CipherState, cipherFunc noise.CipherFunc) CipherState {
|
|
if cs, ok := s.Cipher().(CipherState); ok {
|
|
return cs
|
|
}
|
|
switch cipherFunc.CipherName() {
|
|
case noise.CipherAESGCM.CipherName():
|
|
return NewCipherStateAESGCM(s)
|
|
case noise.CipherChaChaPoly.CipherName():
|
|
return NewCipherStateChaChaPoly(s)
|
|
default:
|
|
panic(fmt.Sprintf("noiseutil: unsupported cipher %q", cipherFunc.CipherName()))
|
|
}
|
|
}
|