diff options
author | agl@chromium.org <agl@chromium.org@0039d316-1c4b-4281-b951-d872f2087c98> | 2012-10-09 19:22:41 +0000 |
---|---|---|
committer | agl@chromium.org <agl@chromium.org@0039d316-1c4b-4281-b951-d872f2087c98> | 2012-10-09 19:22:41 +0000 |
commit | 5e40fc76cce289ae8943864f85a1503499727eee (patch) | |
tree | 8dcda9c3229f3d836229cccc03f26f6221d84a83 /crypto | |
parent | e7a2039c1003084ea8932346cb03abb73e0bf560 (diff) | |
download | chromium_src-5e40fc76cce289ae8943864f85a1503499727eee.zip chromium_src-5e40fc76cce289ae8943864f85a1503499727eee.tar.gz chromium_src-5e40fc76cce289ae8943864f85a1503499727eee.tar.bz2 |
crypto: remove unused Mac SignatureVerifier.
Review URL: https://chromiumcodereview.appspot.com/11092006
git-svn-id: svn://svn.chromium.org/chrome/trunk/src@160892 0039d316-1c4b-4281-b951-d872f2087c98
Diffstat (limited to 'crypto')
-rw-r--r-- | crypto/signature_verifier_mac.cc | 106 | ||||
-rw-r--r-- | crypto/signature_verifier_win.cc | 121 |
2 files changed, 0 insertions, 227 deletions
diff --git a/crypto/signature_verifier_mac.cc b/crypto/signature_verifier_mac.cc deleted file mode 100644 index 90e7196..0000000 --- a/crypto/signature_verifier_mac.cc +++ /dev/null @@ -1,106 +0,0 @@ -// Copyright (c) 2011 The Chromium Authors. All rights reserved. -// Use of this source code is governed by a BSD-style license that can be -// found in the LICENSE file. - -#include "crypto/signature_verifier.h" - -#include <stdlib.h> - -#include "base/logging.h" -#include "crypto/cssm_init.h" - -namespace crypto { - -SignatureVerifier::SignatureVerifier() : sig_handle_(0) { - memset(&public_key_, 0, sizeof(public_key_)); - EnsureCSSMInit(); -} - -SignatureVerifier::~SignatureVerifier() { - Reset(); -} - -bool SignatureVerifier::VerifyInit(const uint8* signature_algorithm, - int signature_algorithm_len, - const uint8* signature, - int signature_len, - const uint8* public_key_info, - int public_key_info_len) { - signature_.assign(signature, signature + signature_len); - public_key_info_.assign(public_key_info, - public_key_info + public_key_info_len); - - CSSM_ALGORITHMS key_alg = CSSM_ALGID_RSA; // TODO(wtc): hardcoded. - - memset(&public_key_, 0, sizeof(public_key_)); - public_key_.KeyData.Data = const_cast<uint8*>(&public_key_info_[0]); - public_key_.KeyData.Length = public_key_info_.size(); - public_key_.KeyHeader.HeaderVersion = CSSM_KEYHEADER_VERSION; - public_key_.KeyHeader.BlobType = CSSM_KEYBLOB_RAW; - public_key_.KeyHeader.Format = CSSM_KEYBLOB_RAW_FORMAT_X509; - public_key_.KeyHeader.AlgorithmId = key_alg; - public_key_.KeyHeader.KeyClass = CSSM_KEYCLASS_PUBLIC_KEY; - public_key_.KeyHeader.KeyAttr = CSSM_KEYATTR_EXTRACTABLE; - public_key_.KeyHeader.KeyUsage = CSSM_KEYUSE_VERIFY; - CSSM_KEY_SIZE key_size; - CSSM_RETURN crtn; - crtn = CSSM_QueryKeySizeInBits(GetSharedCSPHandle(), NULL, - &public_key_, &key_size); - if (crtn) { - NOTREACHED() << "CSSM_QueryKeySizeInBits failed: " << crtn; - return false; - } - public_key_.KeyHeader.LogicalKeySizeInBits = key_size.LogicalKeySizeInBits; - - // TODO(wtc): decode signature_algorithm... - CSSM_ALGORITHMS sig_alg = CSSM_ALGID_SHA1WithRSA; - - crtn = CSSM_CSP_CreateSignatureContext(GetSharedCSPHandle(), sig_alg, NULL, - &public_key_, &sig_handle_); - if (crtn) { - NOTREACHED(); - return false; - } - crtn = CSSM_VerifyDataInit(sig_handle_); - if (crtn) { - NOTREACHED(); - return false; - } - return true; -} - -void SignatureVerifier::VerifyUpdate(const uint8* data_part, - int data_part_len) { - CSSM_DATA data; - data.Data = const_cast<uint8*>(data_part); - data.Length = data_part_len; - CSSM_RETURN crtn = CSSM_VerifyDataUpdate(sig_handle_, &data, 1); - DCHECK_EQ(CSSM_OK, crtn); -} - -bool SignatureVerifier::VerifyFinal() { - CSSM_DATA sig; - sig.Data = const_cast<uint8*>(&signature_[0]); - sig.Length = signature_.size(); - CSSM_RETURN crtn = CSSM_VerifyDataFinal(sig_handle_, &sig); - Reset(); - - // crtn is CSSMERR_CSP_VERIFY_FAILED if signature verification fails. - return (crtn == CSSM_OK); -} - -void SignatureVerifier::Reset() { - CSSM_RETURN crtn; - if (sig_handle_) { - crtn = CSSM_DeleteContext(sig_handle_); - DCHECK_EQ(CSSM_OK, crtn); - sig_handle_ = 0; - } - signature_.clear(); - - // Can't call CSSM_FreeKey on public_key_ because we constructed - // public_key_ manually. -} - -} // namespace crypto - diff --git a/crypto/signature_verifier_win.cc b/crypto/signature_verifier_win.cc deleted file mode 100644 index dfb17a4..0000000 --- a/crypto/signature_verifier_win.cc +++ /dev/null @@ -1,121 +0,0 @@ -// Copyright (c) 2011 The Chromium Authors. All rights reserved. -// Use of this source code is governed by a BSD-style license that can be -// found in the LICENSE file. - -#include "crypto/signature_verifier.h" - -#include "base/logging.h" -#include "crypto/capi_util.h" - -#pragma comment(lib, "crypt32.lib") - -namespace crypto { - -SignatureVerifier::SignatureVerifier() : hash_object_(0), public_key_(0) { - if (!CryptAcquireContext(provider_.receive(), NULL, NULL, - PROV_RSA_FULL, CRYPT_VERIFYCONTEXT)) - provider_.reset(); -} - -SignatureVerifier::~SignatureVerifier() { -} - -bool SignatureVerifier::VerifyInit(const uint8* signature_algorithm, - int signature_algorithm_len, - const uint8* signature, - int signature_len, - const uint8* public_key_info, - int public_key_info_len) { - signature_.reserve(signature_len); - // CryptoAPI uses big integers in the little-endian byte order, so we need - // to first swap the order of signature bytes. - for (int i = signature_len - 1; i >= 0; --i) - signature_.push_back(signature[i]); - - CRYPT_DECODE_PARA decode_para; - decode_para.cbSize = sizeof(decode_para); - decode_para.pfnAlloc = crypto::CryptAlloc; - decode_para.pfnFree = crypto::CryptFree; - CERT_PUBLIC_KEY_INFO* cert_public_key_info = NULL; - DWORD struct_len = 0; - BOOL ok; - ok = CryptDecodeObjectEx(X509_ASN_ENCODING | PKCS_7_ASN_ENCODING, - X509_PUBLIC_KEY_INFO, - public_key_info, - public_key_info_len, - CRYPT_DECODE_ALLOC_FLAG | CRYPT_DECODE_NOCOPY_FLAG, - &decode_para, - &cert_public_key_info, - &struct_len); - if (!ok) - return false; - - ok = CryptImportPublicKeyInfo(provider_, - X509_ASN_ENCODING | PKCS_7_ASN_ENCODING, - cert_public_key_info, public_key_.receive()); - crypto::CryptFree(cert_public_key_info); - if (!ok) - return false; - - CRYPT_ALGORITHM_IDENTIFIER* signature_algorithm_id; - struct_len = 0; - ok = CryptDecodeObjectEx(X509_ASN_ENCODING | PKCS_7_ASN_ENCODING, - X509_ALGORITHM_IDENTIFIER, - signature_algorithm, - signature_algorithm_len, - CRYPT_DECODE_ALLOC_FLAG | CRYPT_DECODE_NOCOPY_FLAG, - &decode_para, - &signature_algorithm_id, - &struct_len); - DCHECK(ok || GetLastError() == ERROR_FILE_NOT_FOUND); - ALG_ID hash_alg_id; - if (ok) { - hash_alg_id = CALG_MD4; // Initialize to a weak hash algorithm that we - // don't support. - if (!strcmp(signature_algorithm_id->pszObjId, szOID_RSA_SHA1RSA)) - hash_alg_id = CALG_SHA1; - else if (!strcmp(signature_algorithm_id->pszObjId, szOID_RSA_MD5RSA)) - hash_alg_id = CALG_MD5; - crypto::CryptFree(signature_algorithm_id); - DCHECK_NE(static_cast<ALG_ID>(CALG_MD4), hash_alg_id); - if (hash_alg_id == CALG_MD4) - return false; // Unsupported hash algorithm. - } else if (GetLastError() == ERROR_FILE_NOT_FOUND) { - // TODO(wtc): X509_ALGORITHM_IDENTIFIER isn't supported on XP SP2. We - // may be able to encapsulate signature_algorithm in a dummy SignedContent - // and decode it with X509_CERT into a CERT_SIGNED_CONTENT_INFO. For now, - // just hardcode the hash algorithm to be SHA-1. - hash_alg_id = CALG_SHA1; - } else { - return false; - } - - ok = CryptCreateHash(provider_, hash_alg_id, 0, 0, hash_object_.receive()); - if (!ok) - return false; - return true; -} - -void SignatureVerifier::VerifyUpdate(const uint8* data_part, - int data_part_len) { - BOOL ok = CryptHashData(hash_object_, data_part, data_part_len, 0); - DCHECK(ok) << "CryptHashData failed: " << GetLastError(); -} - -bool SignatureVerifier::VerifyFinal() { - BOOL ok = CryptVerifySignature(hash_object_, &signature_[0], - signature_.size(), public_key_, NULL, 0); - Reset(); - if (!ok) - return false; - return true; -} - -void SignatureVerifier::Reset() { - hash_object_.reset(); - public_key_.reset(); - signature_.clear(); -} - -} // namespace crypto - |