cjson
fuzzing
inputs
test1 test10 test11 test2 test3 test3.bu test3.uf test3.uu test4 test5 test6 test7 test8 test9library_config
cJSONConfig.cmake.in cJSONConfigVersion.cmake.in libcjson.pc.in libcjson_utils.pc.in uninstall.cmaketests
inputs
test1 test1.expected test10 test10.expected test11 test11.expected test2 test2.expected test3 test3.expected test4 test4.expected test5 test5.expected test6 test7 test7.expected test8 test8.expected test9 test9.expectedjson-patch-tests
.editorconfig .gitignore .npmignore README.md cjson-utils-tests.json package.json spec_tests.json tests.jsonunity
auto
colour_prompt.rb colour_reporter.rb generate_config.yml generate_module.rb generate_test_runner.rb parse_output.rb stylize_as_junit.rb test_file_filter.rb type_sanitizer.rb unity_test_summary.py unity_test_summary.rb unity_to_junit.pydocs
ThrowTheSwitchCodingStandard.md UnityAssertionsCheatSheetSuitableforPrintingandPossiblyFraming.pdf UnityAssertionsReference.md UnityConfigurationGuide.md UnityGettingStartedGuide.md UnityHelperScriptsGuide.md license.txtexamples
unity_config.hcurl
.github
scripts
cleancmd.pl cmp-config.pl cmp-pkg-config.sh codespell-ignore.words codespell.sh distfiles.sh pyspelling.words pyspelling.yaml randcurl.pl requirements-docs.txt requirements-proselint.txt requirements.txt shellcheck-ci.sh shellcheck.sh spellcheck.curl trimmarkdownheader.pl typos.sh typos.toml verify-examples.pl verify-synopsis.pl yamlcheck.sh yamlcheck.yamlworkflows
appveyor-status.yml checkdocs.yml checksrc.yml checkurls.yml codeql.yml configure-vs-cmake.yml curl-for-win.yml distcheck.yml fuzz.yml http3-linux.yml label.yml linux-old.yml linux.yml macos.yml non-native.yml windows.ymlCMake
CurlSymbolHiding.cmake CurlTests.c FindBrotli.cmake FindCares.cmake FindGSS.cmake FindGnuTLS.cmake FindLDAP.cmake FindLibbacktrace.cmake FindLibgsasl.cmake FindLibidn2.cmake FindLibpsl.cmake FindLibssh.cmake FindLibssh2.cmake FindLibuv.cmake FindMbedTLS.cmake FindNGHTTP2.cmake FindNGHTTP3.cmake FindNGTCP2.cmake FindNettle.cmake FindQuiche.cmake FindRustls.cmake FindWolfSSL.cmake FindZstd.cmake Macros.cmake OtherTests.cmake PickyWarnings.cmake Utilities.cmake cmake_uninstall.in.cmake curl-config.in.cmake unix-cache.cmake win32-cache.cmakedocs
cmdline-opts
.gitignore CMakeLists.txt MANPAGE.md Makefile.am Makefile.inc _AUTHORS.md _BUGS.md _DESCRIPTION.md _ENVIRONMENT.md _EXITCODES.md _FILES.md _GLOBBING.md _NAME.md _OPTIONS.md _OUTPUT.md _PROGRESS.md _PROTOCOLS.md _PROXYPREFIX.md _SEEALSO.md _SYNOPSIS.md _URL.md _VARIABLES.md _VERSION.md _WWW.md abstract-unix-socket.md alt-svc.md anyauth.md append.md aws-sigv4.md basic.md ca-native.md cacert.md capath.md cert-status.md cert-type.md cert.md ciphers.md compressed-ssh.md compressed.md config.md connect-timeout.md connect-to.md continue-at.md cookie-jar.md cookie.md create-dirs.md create-file-mode.md crlf.md crlfile.md curves.md data-ascii.md data-binary.md data-raw.md data-urlencode.md data.md delegation.md digest.md disable-eprt.md disable-epsv.md disable.md disallow-username-in-url.md dns-interface.md dns-ipv4-addr.md dns-ipv6-addr.md dns-servers.md doh-cert-status.md doh-insecure.md doh-url.md dump-ca-embed.md dump-header.md ech.md egd-file.md engine.md etag-compare.md etag-save.md expect100-timeout.md fail-early.md fail-with-body.md fail.md false-start.md follow.md form-escape.md form-string.md form.md ftp-account.md ftp-alternative-to-user.md ftp-create-dirs.md ftp-method.md ftp-pasv.md ftp-port.md ftp-pret.md ftp-skip-pasv-ip.md ftp-ssl-ccc-mode.md ftp-ssl-ccc.md ftp-ssl-control.md get.md globoff.md happy-eyeballs-timeout-ms.md haproxy-clientip.md haproxy-protocol.md head.md header.md help.md hostpubmd5.md hostpubsha256.md hsts.md http0.9.md http1.0.md http1.1.md http2-prior-knowledge.md http2.md http3-only.md http3.md ignore-content-length.md insecure.md interface.md ip-tos.md ipfs-gateway.md ipv4.md ipv6.md json.md junk-session-cookies.md keepalive-cnt.md keepalive-time.md key-type.md key.md knownhosts.md krb.md libcurl.md limit-rate.md list-only.md local-port.md location-trusted.md location.md login-options.md mail-auth.md mail-from.md mail-rcpt-allowfails.md mail-rcpt.md mainpage.idx manual.md max-filesize.md max-redirs.md max-time.md metalink.md mptcp.md negotiate.md netrc-file.md netrc-optional.md netrc.md next.md no-alpn.md no-buffer.md no-clobber.md no-keepalive.md no-npn.md no-progress-meter.md no-sessionid.md noproxy.md ntlm-wb.md ntlm.md oauth2-bearer.md out-null.md output-dir.md output.md parallel-immediate.md parallel-max-host.md parallel-max.md parallel.md pass.md path-as-is.md pinnedpubkey.md post301.md post302.md post303.md preproxy.md progress-bar.md proto-default.md proto-redir.md proto.md proxy-anyauth.md proxy-basic.md proxy-ca-native.md proxy-cacert.md proxy-capath.md proxy-cert-type.md proxy-cert.md proxy-ciphers.md proxy-crlfile.md proxy-digest.md proxy-header.md proxy-http2.md proxy-insecure.md proxy-key-type.md proxy-key.md proxy-negotiate.md proxy-ntlm.md proxy-pass.md proxy-pinnedpubkey.md proxy-service-name.md proxy-ssl-allow-beast.md proxy-ssl-auto-client-cert.md proxy-tls13-ciphers.md proxy-tlsauthtype.md proxy-tlspassword.md proxy-tlsuser.md proxy-tlsv1.md proxy-user.md proxy.md proxy1.0.md proxytunnel.md pubkey.md quote.md random-file.md range.md rate.md raw.md referer.md remote-header-name.md remote-name-all.md remote-name.md remote-time.md remove-on-error.md request-target.md request.md resolve.md retry-all-errors.md retry-connrefused.md retry-delay.md retry-max-time.md retry.md sasl-authzid.md sasl-ir.md service-name.md show-error.md show-headers.md sigalgs.md silent.md skip-existing.md socks4.md socks4a.md socks5-basic.md socks5-gssapi-nec.md socks5-gssapi-service.md socks5-gssapi.md socks5-hostname.md socks5.md speed-limit.md speed-time.md ssl-allow-beast.md ssl-auto-client-cert.md ssl-no-revoke.md ssl-reqd.md ssl-revoke-best-effort.md ssl-sessions.md ssl.md sslv2.md sslv3.md stderr.md styled-output.md suppress-connect-headers.md tcp-fastopen.md tcp-nodelay.md telnet-option.md tftp-blksize.md tftp-no-options.md time-cond.md tls-earlydata.md tls-max.md tls13-ciphers.md tlsauthtype.md tlspassword.md tlsuser.md tlsv1.0.md tlsv1.1.md tlsv1.2.md tlsv1.3.md tlsv1.md tr-encoding.md trace-ascii.md trace-config.md trace-ids.md trace-time.md trace.md unix-socket.md upload-file.md upload-flags.md url-query.md url.md use-ascii.md user-agent.md user.md variable.md verbose.md version.md vlan-priority.md write-out.md xattr.mdexamples
.checksrc .gitignore 10-at-a-time.c CMakeLists.txt Makefile.am Makefile.example Makefile.inc README.md adddocsref.pl address-scope.c altsvc.c anyauthput.c block_ip.c cacertinmem.c certinfo.c chkspeed.c connect-to.c cookie_interface.c crawler.c debug.c default-scheme.c ephiperfifo.c evhiperfifo.c externalsocket.c fileupload.c ftp-delete.c ftp-wildcard.c ftpget.c ftpgetinfo.c ftpgetresp.c ftpsget.c ftpupload.c ftpuploadfrommem.c ftpuploadresume.c getinfo.c getinmemory.c getredirect.c getreferrer.c ghiper.c headerapi.c hiperfifo.c hsts-preload.c htmltidy.c htmltitle.cpp http-options.c http-post.c http2-download.c http2-pushinmemory.c http2-serverpush.c http2-upload.c http3-present.c http3.c httpcustomheader.c httpput-postfields.c httpput.c https.c imap-append.c imap-authzid.c imap-copy.c imap-create.c imap-delete.c imap-examine.c imap-fetch.c imap-list.c imap-lsub.c imap-multi.c imap-noop.c imap-search.c imap-ssl.c imap-store.c imap-tls.c interface.c ipv6.c keepalive.c localport.c log_failed_transfers.c maxconnects.c multi-app.c multi-debugcallback.c multi-double.c multi-event.c multi-formadd.c multi-legacy.c multi-post.c multi-single.c multi-uv.c netrc.c parseurl.c persistent.c pop3-authzid.c pop3-dele.c pop3-list.c pop3-multi.c pop3-noop.c pop3-retr.c pop3-ssl.c pop3-stat.c pop3-tls.c pop3-top.c pop3-uidl.c post-callback.c postinmemory.c postit2-formadd.c postit2.c progressfunc.c protofeats.c range.c resolve.c rtsp-options.c sendrecv.c sepheaders.c sessioninfo.c sftpget.c sftpuploadresume.c shared-connection-cache.c simple.c simplepost.c simplessl.c smooth-gtk-thread.c smtp-authzid.c smtp-expn.c smtp-mail.c smtp-mime.c smtp-multi.c smtp-ssl.c smtp-tls.c smtp-vrfy.c sslbackend.c synctime.c threaded.c unixsocket.c url2file.c urlapi.c usercertinmem.c version-check.pl websocket-cb.c websocket-updown.c websocket.c xmlstream.cinternals
BUFQ.md BUFREF.md CHECKSRC.md CLIENT-READERS.md CLIENT-WRITERS.md CODE_STYLE.md CONNECTION-FILTERS.md CREDENTIALS.md CURLX.md DYNBUF.md HASH.md LLIST.md MID.md MQTT.md MULTI-EV.md NEW-PROTOCOL.md PEERS.md PORTING.md RATELIMITS.md README.md SCORECARD.md SPLAY.md STRPARSE.md THRDPOOL-AND-QUEUE.md TIME-KEEPING.md TLS-SESSIONS.md UINT_SETS.md WEBSOCKET.mdlibcurl
opts
CMakeLists.txt CURLINFO_ACTIVESOCKET.md CURLINFO_APPCONNECT_TIME.md CURLINFO_APPCONNECT_TIME_T.md CURLINFO_CAINFO.md CURLINFO_CAPATH.md CURLINFO_CERTINFO.md CURLINFO_CONDITION_UNMET.md CURLINFO_CONNECT_TIME.md CURLINFO_CONNECT_TIME_T.md CURLINFO_CONN_ID.md CURLINFO_CONTENT_LENGTH_DOWNLOAD.md CURLINFO_CONTENT_LENGTH_DOWNLOAD_T.md CURLINFO_CONTENT_LENGTH_UPLOAD.md CURLINFO_CONTENT_LENGTH_UPLOAD_T.md CURLINFO_CONTENT_TYPE.md CURLINFO_COOKIELIST.md CURLINFO_EARLYDATA_SENT_T.md CURLINFO_EFFECTIVE_METHOD.md CURLINFO_EFFECTIVE_URL.md CURLINFO_FILETIME.md CURLINFO_FILETIME_T.md CURLINFO_FTP_ENTRY_PATH.md CURLINFO_HEADER_SIZE.md CURLINFO_HTTPAUTH_AVAIL.md CURLINFO_HTTPAUTH_USED.md CURLINFO_HTTP_CONNECTCODE.md CURLINFO_HTTP_VERSION.md CURLINFO_LASTSOCKET.md CURLINFO_LOCAL_IP.md CURLINFO_LOCAL_PORT.md CURLINFO_NAMELOOKUP_TIME.md CURLINFO_NAMELOOKUP_TIME_T.md CURLINFO_NUM_CONNECTS.md CURLINFO_OS_ERRNO.md CURLINFO_POSTTRANSFER_TIME_T.md CURLINFO_PRETRANSFER_TIME.md CURLINFO_PRETRANSFER_TIME_T.md CURLINFO_PRIMARY_IP.md CURLINFO_PRIMARY_PORT.md CURLINFO_PRIVATE.md CURLINFO_PROTOCOL.md CURLINFO_PROXYAUTH_AVAIL.md CURLINFO_PROXYAUTH_USED.md CURLINFO_PROXY_ERROR.md CURLINFO_PROXY_SSL_VERIFYRESULT.md CURLINFO_QUEUE_TIME_T.md CURLINFO_REDIRECT_COUNT.md CURLINFO_REDIRECT_TIME.md CURLINFO_REDIRECT_TIME_T.md CURLINFO_REDIRECT_URL.md CURLINFO_REFERER.md CURLINFO_REQUEST_SIZE.md CURLINFO_RESPONSE_CODE.md CURLINFO_RETRY_AFTER.md CURLINFO_RTSP_CLIENT_CSEQ.md CURLINFO_RTSP_CSEQ_RECV.md CURLINFO_RTSP_SERVER_CSEQ.md CURLINFO_RTSP_SESSION_ID.md CURLINFO_SCHEME.md CURLINFO_SIZE_DELIVERED.md CURLINFO_SIZE_DOWNLOAD.md CURLINFO_SIZE_DOWNLOAD_T.md CURLINFO_SIZE_UPLOAD.md CURLINFO_SIZE_UPLOAD_T.md CURLINFO_SPEED_DOWNLOAD.md CURLINFO_SPEED_DOWNLOAD_T.md CURLINFO_SPEED_UPLOAD.md CURLINFO_SPEED_UPLOAD_T.md CURLINFO_SSL_ENGINES.md CURLINFO_SSL_VERIFYRESULT.md CURLINFO_STARTTRANSFER_TIME.md CURLINFO_STARTTRANSFER_TIME_T.md CURLINFO_TLS_SESSION.md CURLINFO_TLS_SSL_PTR.md CURLINFO_TOTAL_TIME.md CURLINFO_TOTAL_TIME_T.md CURLINFO_USED_PROXY.md CURLINFO_XFER_ID.md CURLMINFO_XFERS_ADDED.md CURLMINFO_XFERS_CURRENT.md CURLMINFO_XFERS_DONE.md CURLMINFO_XFERS_PENDING.md CURLMINFO_XFERS_RUNNING.md CURLMOPT_CHUNK_LENGTH_PENALTY_SIZE.md CURLMOPT_CONTENT_LENGTH_PENALTY_SIZE.md CURLMOPT_MAXCONNECTS.md CURLMOPT_MAX_CONCURRENT_STREAMS.md CURLMOPT_MAX_HOST_CONNECTIONS.md CURLMOPT_MAX_PIPELINE_LENGTH.md CURLMOPT_MAX_TOTAL_CONNECTIONS.md CURLMOPT_NETWORK_CHANGED.md CURLMOPT_NOTIFYDATA.md CURLMOPT_NOTIFYFUNCTION.md CURLMOPT_PIPELINING.md CURLMOPT_PIPELINING_SERVER_BL.md CURLMOPT_PIPELINING_SITE_BL.md CURLMOPT_PUSHDATA.md CURLMOPT_PUSHFUNCTION.md CURLMOPT_QUICK_EXIT.md CURLMOPT_RESOLVE_THREADS_MAX.md CURLMOPT_SOCKETDATA.md CURLMOPT_SOCKETFUNCTION.md CURLMOPT_TIMERDATA.md CURLMOPT_TIMERFUNCTION.md CURLOPT_ABSTRACT_UNIX_SOCKET.md CURLOPT_ACCEPTTIMEOUT_MS.md CURLOPT_ACCEPT_ENCODING.md CURLOPT_ADDRESS_SCOPE.md CURLOPT_ALTSVC.md CURLOPT_ALTSVC_CTRL.md CURLOPT_APPEND.md CURLOPT_AUTOREFERER.md CURLOPT_AWS_SIGV4.md CURLOPT_BUFFERSIZE.md CURLOPT_CAINFO.md CURLOPT_CAINFO_BLOB.md CURLOPT_CAPATH.md CURLOPT_CA_CACHE_TIMEOUT.md CURLOPT_CERTINFO.md CURLOPT_CHUNK_BGN_FUNCTION.md CURLOPT_CHUNK_DATA.md CURLOPT_CHUNK_END_FUNCTION.md CURLOPT_CLOSESOCKETDATA.md CURLOPT_CLOSESOCKETFUNCTION.md CURLOPT_CONNECTTIMEOUT.md CURLOPT_CONNECTTIMEOUT_MS.md CURLOPT_CONNECT_ONLY.md CURLOPT_CONNECT_TO.md CURLOPT_CONV_FROM_NETWORK_FUNCTION.md CURLOPT_CONV_FROM_UTF8_FUNCTION.md CURLOPT_CONV_TO_NETWORK_FUNCTION.md CURLOPT_COOKIE.md CURLOPT_COOKIEFILE.md CURLOPT_COOKIEJAR.md CURLOPT_COOKIELIST.md CURLOPT_COOKIESESSION.md CURLOPT_COPYPOSTFIELDS.md CURLOPT_CRLF.md CURLOPT_CRLFILE.md CURLOPT_CURLU.md CURLOPT_CUSTOMREQUEST.md CURLOPT_DEBUGDATA.md CURLOPT_DEBUGFUNCTION.md CURLOPT_DEFAULT_PROTOCOL.md CURLOPT_DIRLISTONLY.md CURLOPT_DISALLOW_USERNAME_IN_URL.md CURLOPT_DNS_CACHE_TIMEOUT.md CURLOPT_DNS_INTERFACE.md CURLOPT_DNS_LOCAL_IP4.md CURLOPT_DNS_LOCAL_IP6.md CURLOPT_DNS_SERVERS.md CURLOPT_DNS_SHUFFLE_ADDRESSES.md CURLOPT_DNS_USE_GLOBAL_CACHE.md CURLOPT_DOH_SSL_VERIFYHOST.md CURLOPT_DOH_SSL_VERIFYPEER.md CURLOPT_DOH_SSL_VERIFYSTATUS.md CURLOPT_DOH_URL.md CURLOPT_ECH.md CURLOPT_EGDSOCKET.md CURLOPT_ERRORBUFFER.md CURLOPT_EXPECT_100_TIMEOUT_MS.md CURLOPT_FAILONERROR.md CURLOPT_FILETIME.md CURLOPT_FNMATCH_DATA.md CURLOPT_FNMATCH_FUNCTION.md CURLOPT_FOLLOWLOCATION.md CURLOPT_FORBID_REUSE.md CURLOPT_FRESH_CONNECT.md CURLOPT_FTPPORT.md CURLOPT_FTPSSLAUTH.md CURLOPT_FTP_ACCOUNT.md CURLOPT_FTP_ALTERNATIVE_TO_USER.md CURLOPT_FTP_CREATE_MISSING_DIRS.md CURLOPT_FTP_FILEMETHOD.md CURLOPT_FTP_SKIP_PASV_IP.md CURLOPT_FTP_SSL_CCC.md CURLOPT_FTP_USE_EPRT.md CURLOPT_FTP_USE_EPSV.md CURLOPT_FTP_USE_PRET.md CURLOPT_GSSAPI_DELEGATION.md CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS.md CURLOPT_HAPROXYPROTOCOL.md CURLOPT_HAPROXY_CLIENT_IP.md CURLOPT_HEADER.md CURLOPT_HEADERDATA.md CURLOPT_HEADERFUNCTION.md CURLOPT_HEADEROPT.md CURLOPT_HSTS.md CURLOPT_HSTSREADDATA.md CURLOPT_HSTSREADFUNCTION.md CURLOPT_HSTSWRITEDATA.md CURLOPT_HSTSWRITEFUNCTION.md CURLOPT_HSTS_CTRL.md CURLOPT_HTTP09_ALLOWED.md CURLOPT_HTTP200ALIASES.md CURLOPT_HTTPAUTH.md CURLOPT_HTTPGET.md CURLOPT_HTTPHEADER.md CURLOPT_HTTPPOST.md CURLOPT_HTTPPROXYTUNNEL.md CURLOPT_HTTP_CONTENT_DECODING.md CURLOPT_HTTP_TRANSFER_DECODING.md CURLOPT_HTTP_VERSION.md CURLOPT_IGNORE_CONTENT_LENGTH.md CURLOPT_INFILESIZE.md CURLOPT_INFILESIZE_LARGE.md CURLOPT_INTERFACE.md CURLOPT_INTERLEAVEDATA.md CURLOPT_INTERLEAVEFUNCTION.md CURLOPT_IOCTLDATA.md CURLOPT_IOCTLFUNCTION.md CURLOPT_IPRESOLVE.md CURLOPT_ISSUERCERT.md CURLOPT_ISSUERCERT_BLOB.md CURLOPT_KEEP_SENDING_ON_ERROR.md CURLOPT_KEYPASSWD.md CURLOPT_KRBLEVEL.md CURLOPT_LOCALPORT.md CURLOPT_LOCALPORTRANGE.md CURLOPT_LOGIN_OPTIONS.md CURLOPT_LOW_SPEED_LIMIT.md CURLOPT_LOW_SPEED_TIME.md CURLOPT_MAIL_AUTH.md CURLOPT_MAIL_FROM.md CURLOPT_MAIL_RCPT.md CURLOPT_MAIL_RCPT_ALLOWFAILS.md CURLOPT_MAXAGE_CONN.md CURLOPT_MAXCONNECTS.md CURLOPT_MAXFILESIZE.md CURLOPT_MAXFILESIZE_LARGE.md CURLOPT_MAXLIFETIME_CONN.md CURLOPT_MAXREDIRS.md CURLOPT_MAX_RECV_SPEED_LARGE.md CURLOPT_MAX_SEND_SPEED_LARGE.md CURLOPT_MIMEPOST.md CURLOPT_MIME_OPTIONS.md CURLOPT_NETRC.md CURLOPT_NETRC_FILE.md CURLOPT_NEW_DIRECTORY_PERMS.md CURLOPT_NEW_FILE_PERMS.md CURLOPT_NOBODY.md CURLOPT_NOPROGRESS.md CURLOPT_NOPROXY.md CURLOPT_NOSIGNAL.md CURLOPT_OPENSOCKETDATA.md CURLOPT_OPENSOCKETFUNCTION.md CURLOPT_PASSWORD.md CURLOPT_PATH_AS_IS.md CURLOPT_PINNEDPUBLICKEY.md CURLOPT_PIPEWAIT.md CURLOPT_PORT.md CURLOPT_POST.md CURLOPT_POSTFIELDS.md CURLOPT_POSTFIELDSIZE.md CURLOPT_POSTFIELDSIZE_LARGE.md CURLOPT_POSTQUOTE.md CURLOPT_POSTREDIR.md CURLOPT_PREQUOTE.md CURLOPT_PREREQDATA.md CURLOPT_PREREQFUNCTION.md CURLOPT_PRE_PROXY.md CURLOPT_PRIVATE.md CURLOPT_PROGRESSDATA.md CURLOPT_PROGRESSFUNCTION.md CURLOPT_PROTOCOLS.md CURLOPT_PROTOCOLS_STR.md CURLOPT_PROXY.md CURLOPT_PROXYAUTH.md CURLOPT_PROXYHEADER.md CURLOPT_PROXYPASSWORD.md CURLOPT_PROXYPORT.md CURLOPT_PROXYTYPE.md CURLOPT_PROXYUSERNAME.md CURLOPT_PROXYUSERPWD.md CURLOPT_PROXY_CAINFO.md CURLOPT_PROXY_CAINFO_BLOB.md CURLOPT_PROXY_CAPATH.md CURLOPT_PROXY_CRLFILE.md CURLOPT_PROXY_ISSUERCERT.md CURLOPT_PROXY_ISSUERCERT_BLOB.md CURLOPT_PROXY_KEYPASSWD.md CURLOPT_PROXY_PINNEDPUBLICKEY.md CURLOPT_PROXY_SERVICE_NAME.md CURLOPT_PROXY_SSLCERT.md CURLOPT_PROXY_SSLCERTTYPE.md CURLOPT_PROXY_SSLCERT_BLOB.md CURLOPT_PROXY_SSLKEY.md CURLOPT_PROXY_SSLKEYTYPE.md CURLOPT_PROXY_SSLKEY_BLOB.md CURLOPT_PROXY_SSLVERSION.md CURLOPT_PROXY_SSL_CIPHER_LIST.md CURLOPT_PROXY_SSL_OPTIONS.md CURLOPT_PROXY_SSL_VERIFYHOST.md CURLOPT_PROXY_SSL_VERIFYPEER.md CURLOPT_PROXY_TLS13_CIPHERS.md CURLOPT_PROXY_TLSAUTH_PASSWORD.md CURLOPT_PROXY_TLSAUTH_TYPE.md CURLOPT_PROXY_TLSAUTH_USERNAME.md CURLOPT_PROXY_TRANSFER_MODE.md CURLOPT_PUT.md CURLOPT_QUICK_EXIT.md CURLOPT_QUOTE.md CURLOPT_RANDOM_FILE.md CURLOPT_RANGE.md CURLOPT_READDATA.md CURLOPT_READFUNCTION.md CURLOPT_REDIR_PROTOCOLS.md CURLOPT_REDIR_PROTOCOLS_STR.md CURLOPT_REFERER.md CURLOPT_REQUEST_TARGET.md CURLOPT_RESOLVE.md CURLOPT_RESOLVER_START_DATA.md CURLOPT_RESOLVER_START_FUNCTION.md CURLOPT_RESUME_FROM.md CURLOPT_RESUME_FROM_LARGE.md CURLOPT_RTSP_CLIENT_CSEQ.md CURLOPT_RTSP_REQUEST.md CURLOPT_RTSP_SERVER_CSEQ.md CURLOPT_RTSP_SESSION_ID.md CURLOPT_RTSP_STREAM_URI.md CURLOPT_RTSP_TRANSPORT.md CURLOPT_SASL_AUTHZID.md CURLOPT_SASL_IR.md CURLOPT_SEEKDATA.md CURLOPT_SEEKFUNCTION.md CURLOPT_SERVER_RESPONSE_TIMEOUT.md CURLOPT_SERVER_RESPONSE_TIMEOUT_MS.md CURLOPT_SERVICE_NAME.md CURLOPT_SHARE.md CURLOPT_SOCKOPTDATA.md CURLOPT_SOCKOPTFUNCTION.md CURLOPT_SOCKS5_AUTH.md CURLOPT_SOCKS5_GSSAPI_NEC.md CURLOPT_SOCKS5_GSSAPI_SERVICE.md CURLOPT_SSH_AUTH_TYPES.md CURLOPT_SSH_COMPRESSION.md CURLOPT_SSH_HOSTKEYDATA.md CURLOPT_SSH_HOSTKEYFUNCTION.md CURLOPT_SSH_HOST_PUBLIC_KEY_MD5.md CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256.md CURLOPT_SSH_KEYDATA.md CURLOPT_SSH_KEYFUNCTION.md CURLOPT_SSH_KNOWNHOSTS.md CURLOPT_SSH_PRIVATE_KEYFILE.md CURLOPT_SSH_PUBLIC_KEYFILE.md CURLOPT_SSLCERT.md CURLOPT_SSLCERTTYPE.md CURLOPT_SSLCERT_BLOB.md CURLOPT_SSLENGINE.md CURLOPT_SSLENGINE_DEFAULT.md CURLOPT_SSLKEY.md CURLOPT_SSLKEYTYPE.md CURLOPT_SSLKEY_BLOB.md CURLOPT_SSLVERSION.md CURLOPT_SSL_CIPHER_LIST.md CURLOPT_SSL_CTX_DATA.md CURLOPT_SSL_CTX_FUNCTION.md CURLOPT_SSL_EC_CURVES.md CURLOPT_SSL_ENABLE_ALPN.md CURLOPT_SSL_ENABLE_NPN.md CURLOPT_SSL_FALSESTART.md CURLOPT_SSL_OPTIONS.md CURLOPT_SSL_SESSIONID_CACHE.md CURLOPT_SSL_SIGNATURE_ALGORITHMS.md CURLOPT_SSL_VERIFYHOST.md CURLOPT_SSL_VERIFYPEER.md CURLOPT_SSL_VERIFYSTATUS.md CURLOPT_STDERR.md CURLOPT_STREAM_DEPENDS.md CURLOPT_STREAM_DEPENDS_E.md CURLOPT_STREAM_WEIGHT.md CURLOPT_SUPPRESS_CONNECT_HEADERS.md CURLOPT_TCP_FASTOPEN.md CURLOPT_TCP_KEEPALIVE.md CURLOPT_TCP_KEEPCNT.md CURLOPT_TCP_KEEPIDLE.md CURLOPT_TCP_KEEPINTVL.md CURLOPT_TCP_NODELAY.md CURLOPT_TELNETOPTIONS.md CURLOPT_TFTP_BLKSIZE.md CURLOPT_TFTP_NO_OPTIONS.md CURLOPT_TIMECONDITION.md CURLOPT_TIMEOUT.md CURLOPT_TIMEOUT_MS.md CURLOPT_TIMEVALUE.md CURLOPT_TIMEVALUE_LARGE.md CURLOPT_TLS13_CIPHERS.md CURLOPT_TLSAUTH_PASSWORD.md CURLOPT_TLSAUTH_TYPE.md CURLOPT_TLSAUTH_USERNAME.md CURLOPT_TRAILERDATA.md CURLOPT_TRAILERFUNCTION.md CURLOPT_TRANSFERTEXT.md CURLOPT_TRANSFER_ENCODING.md CURLOPT_UNIX_SOCKET_PATH.md CURLOPT_UNRESTRICTED_AUTH.md CURLOPT_UPKEEP_INTERVAL_MS.md CURLOPT_UPLOAD.md CURLOPT_UPLOAD_BUFFERSIZE.md CURLOPT_UPLOAD_FLAGS.md CURLOPT_URL.md CURLOPT_USERAGENT.md CURLOPT_USERNAME.md CURLOPT_USERPWD.md CURLOPT_USE_SSL.md CURLOPT_VERBOSE.md CURLOPT_WILDCARDMATCH.md CURLOPT_WRITEDATA.md CURLOPT_WRITEFUNCTION.md CURLOPT_WS_OPTIONS.md CURLOPT_XFERINFODATA.md CURLOPT_XFERINFOFUNCTION.md CURLOPT_XOAUTH2_BEARER.md CURLSHOPT_LOCKFUNC.md CURLSHOPT_SHARE.md CURLSHOPT_UNLOCKFUNC.md CURLSHOPT_UNSHARE.md CURLSHOPT_USERDATA.md Makefile.am Makefile.incinclude
curl
Makefile.am curl.h curlver.h easy.h header.h mprintf.h multi.h options.h stdcheaders.h system.h typecheck-gcc.h urlapi.h websockets.hlib
curlx
base64.c base64.h basename.c basename.h dynbuf.c dynbuf.h fopen.c fopen.h inet_ntop.c inet_ntop.h inet_pton.c inet_pton.h multibyte.c multibyte.h nonblock.c nonblock.h snprintf.c snprintf.h strcopy.c strcopy.h strdup.c strdup.h strerr.c strerr.h strparse.c strparse.h timediff.c timediff.h timeval.c timeval.h version_win32.c version_win32.h wait.c wait.h warnless.c warnless.h winapi.c winapi.hvauth
cleartext.c cram.c digest.c digest.h digest_sspi.c gsasl.c krb5_gssapi.c krb5_sspi.c ntlm.c ntlm_sspi.c oauth2.c spnego_gssapi.c spnego_sspi.c vauth.c vauth.hvquic
curl_ngtcp2.c curl_ngtcp2.h curl_quiche.c curl_quiche.h vquic-tls.c vquic-tls.h vquic.c vquic.h vquic_int.hvtls
apple.c apple.h cipher_suite.c cipher_suite.h gtls.c gtls.h hostcheck.c hostcheck.h keylog.c keylog.h mbedtls.c mbedtls.h openssl.c openssl.h rustls.c rustls.h schannel.c schannel.h schannel_int.h schannel_verify.c vtls.c vtls.h vtls_int.h vtls_scache.c vtls_scache.h vtls_spack.c vtls_spack.h wolfssl.c wolfssl.h x509asn1.c x509asn1.hm4
.gitignore curl-amissl.m4 curl-apple-sectrust.m4 curl-compilers.m4 curl-confopts.m4 curl-functions.m4 curl-gnutls.m4 curl-mbedtls.m4 curl-openssl.m4 curl-override.m4 curl-reentrant.m4 curl-rustls.m4 curl-schannel.m4 curl-sysconfig.m4 curl-wolfssl.m4 xc-am-iface.m4 xc-cc-check.m4 xc-lt-iface.m4 xc-val-flgs.m4 zz40-xc-ovr.m4 zz50-xc-ovr.m4projects
OS400
.checksrc README.OS400 ccsidcurl.c ccsidcurl.h config400.default curl.cmd curl.inc.in curlcl.c curlmain.c initscript.sh make-docs.sh make-include.sh make-lib.sh make-src.sh make-tests.sh makefile.sh os400sys.c os400sys.hWindows
tmpl
.gitattributes README.txt curl-all.sln curl.sln curl.vcxproj curl.vcxproj.filters libcurl.sln libcurl.vcxproj libcurl.vcxproj.filtersvms
Makefile.am backup_gnv_curl_src.com build_curl-config_script.com build_gnv_curl.com build_gnv_curl_pcsi_desc.com build_gnv_curl_pcsi_text.com build_gnv_curl_release_notes.com build_libcurl_pc.com build_vms.com clean_gnv_curl.com compare_curl_source.com config_h.com curl_crtl_init.c curl_gnv_build_steps.txt curl_release_note_start.txt curl_startup.com curlmsg.h curlmsg.msg curlmsg.sdl curlmsg_vms.h generate_config_vms_h_curl.com generate_vax_transfer.com gnv_conftest.c_first gnv_curl_configure.sh gnv_libcurl_symbols.opt gnv_link_curl.com macro32_exactcase.patch make_gnv_curl_install.sh make_pcsi_curl_kit_name.com pcsi_gnv_curl_file_list.txt pcsi_product_gnv_curl.com readme report_openssl_version.c setup_gnv_curl_build.com stage_curl_install.com vms_eco_level.hscripts
.checksrc CMakeLists.txt Makefile.am badwords badwords-all badwords.txt cd2cd cd2nroff cdall checksrc-all.pl checksrc.pl cmakelint.sh completion.pl contributors.sh contrithanks.sh coverage.sh delta dmaketgz extract-unit-protos firefox-db2pem.sh installcheck.sh maketgz managen mdlinkcheck mk-ca-bundle.pl mk-unity.pl nroff2cd perlcheck.sh pythonlint.sh randdisable release-notes.pl release-tools.sh schemetable.c singleuse.pl spacecheck.pl top-complexity top-length verify-release wcurlsrc
.checksrc .gitignore CMakeLists.txt Makefile.am Makefile.inc config2setopts.c config2setopts.h curl.rc curlinfo.c mk-file-embed.pl mkhelp.pl slist_wc.c slist_wc.h terminal.c terminal.h tool_cb_dbg.c tool_cb_dbg.h tool_cb_hdr.c tool_cb_hdr.h tool_cb_prg.c tool_cb_prg.h tool_cb_rea.c tool_cb_rea.h tool_cb_see.c tool_cb_see.h tool_cb_soc.c tool_cb_soc.h tool_cb_wrt.c tool_cb_wrt.h tool_cfgable.c tool_cfgable.h tool_dirhie.c tool_dirhie.h tool_doswin.c tool_doswin.h tool_easysrc.c tool_easysrc.h tool_filetime.c tool_filetime.h tool_findfile.c tool_findfile.h tool_formparse.c tool_formparse.h tool_getparam.c tool_getparam.h tool_getpass.c tool_getpass.h tool_help.c tool_help.h tool_helpers.c tool_helpers.h tool_hugehelp.h tool_ipfs.c tool_ipfs.h tool_libinfo.c tool_libinfo.h tool_listhelp.c tool_main.c tool_main.h tool_msgs.c tool_msgs.h tool_operate.c tool_operate.h tool_operhlp.c tool_operhlp.h tool_paramhlp.c tool_paramhlp.h tool_parsecfg.c tool_parsecfg.h tool_progress.c tool_progress.h tool_sdecls.h tool_setopt.c tool_setopt.h tool_setup.h tool_ssls.c tool_ssls.h tool_stderr.c tool_stderr.h tool_urlglob.c tool_urlglob.h tool_util.c tool_util.h tool_version.h tool_vms.c tool_vms.h tool_writeout.c tool_writeout.h tool_writeout_json.c tool_writeout_json.h tool_xattr.c tool_xattr.h var.c var.htests
certs
.gitignore CMakeLists.txt Makefile.am Makefile.inc genserv.pl srp-verifier-conf srp-verifier-db test-ca.cnf test-ca.prm test-client-cert.prm test-client-eku-only.prm test-localhost-san-first.prm test-localhost-san-last.prm test-localhost.nn.prm test-localhost.prm test-localhost0h.prmdata
.gitignore DISABLED Makefile.am data-xml1 data1400.c data1401.c data1402.c data1403.c data1404.c data1405.c data1406.c data1407.c data1420.c data1461.txt data1463.txt data1465.c data1481.c data1705-1.md data1705-2.md data1705-3.md data1705-4.md data1705-stdout.1 data1706-1.md data1706-2.md data1706-3.md data1706-4.md data1706-stdout.txt data320.html test1 test10 test100 test1000 test1001 test1002 test1003 test1004 test1005 test1006 test1007 test1008 test1009 test101 test1010 test1011 test1012 test1013 test1014 test1015 test1016 test1017 test1018 test1019 test102 test1020 test1021 test1022 test1023 test1024 test1025 test1026 test1027 test1028 test1029 test103 test1030 test1031 test1032 test1033 test1034 test1035 test1036 test1037 test1038 test1039 test104 test1040 test1041 test1042 test1043 test1044 test1045 test1046 test1047 test1048 test1049 test105 test1050 test1051 test1052 test1053 test1054 test1055 test1056 test1057 test1058 test1059 test106 test1060 test1061 test1062 test1063 test1064 test1065 test1066 test1067 test1068 test1069 test107 test1070 test1071 test1072 test1073 test1074 test1075 test1076 test1077 test1078 test1079 test108 test1080 test1081 test1082 test1083 test1084 test1085 test1086 test1087 test1088 test1089 test109 test1090 test1091 test1092 test1093 test1094 test1095 test1096 test1097 test1098 test1099 test11 test110 test1100 test1101 test1102 test1103 test1104 test1105 test1106 test1107 test1108 test1109 test111 test1110 test1111 test1112 test1113 test1114 test1115 test1116 test1117 test1118 test1119 test112 test1120 test1121 test1122 test1123 test1124 test1125 test1126 test1127 test1128 test1129 test113 test1130 test1131 test1132 test1133 test1134 test1135 test1136 test1137 test1138 test1139 test114 test1140 test1141 test1142 test1143 test1144 test1145 test1146 test1147 test1148 test1149 test115 test1150 test1151 test1152 test1153 test1154 test1155 test1156 test1157 test1158 test1159 test116 test1160 test1161 test1162 test1163 test1164 test1165 test1166 test1167 test1168 test1169 test117 test1170 test1171 test1172 test1173 test1174 test1175 test1176 test1177 test1178 test1179 test118 test1180 test1181 test1182 test1183 test1184 test1185 test1186 test1187 test1188 test1189 test119 test1190 test1191 test1192 test1193 test1194 test1195 test1196 test1197 test1198 test1199 test12 test120 test1200 test1201 test1202 test1203 test1204 test1205 test1206 test1207 test1208 test1209 test121 test1210 test1211 test1212 test1213 test1214 test1215 test1216 test1217 test1218 test1219 test122 test1220 test1221 test1222 test1223 test1224 test1225 test1226 test1227 test1228 test1229 test123 test1230 test1231 test1232 test1233 test1234 test1235 test1236 test1237 test1238 test1239 test124 test1240 test1241 test1242 test1243 test1244 test1245 test1246 test1247 test1248 test1249 test125 test1250 test1251 test1252 test1253 test1254 test1255 test1256 test1257 test1258 test1259 test126 test1260 test1261 test1262 test1263 test1264 test1265 test1266 test1267 test1268 test1269 test127 test1270 test1271 test1272 test1273 test1274 test1275 test1276 test1277 test1278 test1279 test128 test1280 test1281 test1282 test1283 test1284 test1285 test1286 test1287 test1288 test1289 test129 test1290 test1291 test1292 test1293 test1294 test1295 test1296 test1297 test1298 test1299 test13 test130 test1300 test1301 test1302 test1303 test1304 test1305 test1306 test1307 test1308 test1309 test131 test1310 test1311 test1312 test1313 test1314 test1315 test1316 test1317 test1318 test1319 test132 test1320 test1321 test1322 test1323 test1324 test1325 test1326 test1327 test1328 test1329 test133 test1330 test1331 test1332 test1333 test1334 test1335 test1336 test1337 test1338 test1339 test134 test1340 test1341 test1342 test1343 test1344 test1345 test1346 test1347 test1348 test1349 test135 test1350 test1351 test1352 test1353 test1354 test1355 test1356 test1357 test1358 test1359 test136 test1360 test1361 test1362 test1363 test1364 test1365 test1366 test1367 test1368 test1369 test137 test1370 test1371 test1372 test1373 test1374 test1375 test1376 test1377 test1378 test1379 test138 test1380 test1381 test1382 test1383 test1384 test1385 test1386 test1387 test1388 test1389 test139 test1390 test1391 test1392 test1393 test1394 test1395 test1396 test1397 test1398 test1399 test14 test140 test1400 test1401 test1402 test1403 test1404 test1405 test1406 test1407 test1408 test1409 test141 test1410 test1411 test1412 test1413 test1414 test1415 test1416 test1417 test1418 test1419 test142 test1420 test1421 test1422 test1423 test1424 test1425 test1426 test1427 test1428 test1429 test143 test1430 test1431 test1432 test1433 test1434 test1435 test1436 test1437 test1438 test1439 test144 test1440 test1441 test1442 test1443 test1444 test1445 test1446 test1447 test1448 test1449 test145 test1450 test1451 test1452 test1453 test1454 test1455 test1456 test1457 test1458 test1459 test146 test1460 test1461 test1462 test1463 test1464 test1465 test1466 test1467 test1468 test1469 test147 test1470 test1471 test1472 test1473 test1474 test1475 test1476 test1477 test1478 test1479 test148 test1480 test1481 test1482 test1483 test1484 test1485 test1486 test1487 test1488 test1489 test149 test1490 test1491 test1492 test1493 test1494 test1495 test1496 test1497 test1498 test1499 test15 test150 test1500 test1501 test1502 test1503 test1504 test1505 test1506 test1507 test1508 test1509 test151 test1510 test1511 test1512 test1513 test1514 test1515 test1516 test1517 test1518 test1519 test152 test1520 test1521 test1522 test1523 test1524 test1525 test1526 test1527 test1528 test1529 test153 test1530 test1531 test1532 test1533 test1534 test1535 test1536 test1537 test1538 test1539 test154 test1540 test1541 test1542 test1543 test1544 test1545 test1546 test1547 test1548 test1549 test155 test1550 test1551 test1552 test1553 test1554 test1555 test1556 test1557 test1558 test1559 test156 test1560 test1561 test1562 test1563 test1564 test1565 test1566 test1567 test1568 test1569 test157 test1570 test1571 test1572 test1573 test1574 test1575 test1576 test1577 test1578 test1579 test158 test1580 test1581 test1582 test1583 test1584 test1585 test1586 test1587 test1588 test1589 test159 test1590 test1591 test1592 test1593 test1594 test1595 test1596 test1597 test1598 test1599 test16 test160 test1600 test1601 test1602 test1603 test1604 test1605 test1606 test1607 test1608 test1609 test161 test1610 test1611 test1612 test1613 test1614 test1615 test1616 test1617 test1618 test1619 test162 test1620 test1621 test1622 test1623 test1624 test1625 test1626 test1627 test1628 test1629 test163 test1630 test1631 test1632 test1633 test1634 test1635 test1636 test1637 test1638 test1639 test164 test1640 test1641 test1642 test1643 test1644 test1645 test165 test1650 test1651 test1652 test1653 test1654 test1655 test1656 test1657 test1658 test1659 test166 test1660 test1661 test1662 test1663 test1664 test1665 test1666 test1667 test1668 test1669 test167 test1670 test1671 test1672 test1673 test1674 test1675 test1676 test168 test1680 test1681 test1682 test1683 test1684 test1685 test169 test17 test170 test1700 test1701 test1702 test1703 test1704 test1705 test1706 test1707 test1708 test1709 test171 test1710 test1711 test1712 test1713 test1714 test1715 test172 test1720 test1721 test173 test174 test175 test176 test177 test178 test179 test18 test180 test1800 test1801 test1802 test181 test182 test183 test184 test1847 test1848 test1849 test185 test1850 test1851 test186 test187 test188 test189 test19 test190 test1900 test1901 test1902 test1903 test1904 test1905 test1906 test1907 test1908 test1909 test191 test1910 test1911 test1912 test1913 test1914 test1915 test1916 test1917 test1918 test1919 test192 test1920 test1921 test193 test1933 test1934 test1935 test1936 test1937 test1938 test1939 test194 test1940 test1941 test1942 test1943 test1944 test1945 test1946 test1947 test1948 test195 test1955 test1956 test1957 test1958 test1959 test196 test1960 test1964 test1965 test1966 test197 test1970 test1971 test1972 test1973 test1974 test1975 test1976 test1977 test1978 test1979 test198 test1980 test1981 test1982 test1983 test1984 test199 test2 test20 test200 test2000 test2001 test2002 test2003 test2004 test2005 test2006 test2007 test2008 test2009 test201 test2010 test2011 test2012 test2013 test2014 test202 test2023 test2024 test2025 test2026 test2027 test2028 test2029 test203 test2030 test2031 test2032 test2033 test2034 test2035 test2037 test2038 test2039 test204 test2040 test2041 test2042 test2043 test2044 test2045 test2046 test2047 test2048 test2049 test205 test2050 test2051 test2052 test2053 test2054 test2055 test2056 test2057 test2058 test2059 test206 test2060 test2061 test2062 test2063 test2064 test2065 test2066 test2067 test2068 test2069 test207 test2070 test2071 test2072 test2073 test2074 test2075 test2076 test2077 test2078 test2079 test208 test2080 test2081 test2082 test2083 test2084 test2085 test2086 test2087 test2088 test2089 test209 test2090 test2091 test2092 test21 test210 test2100 test2101 test2102 test2103 test2104 test211 test212 test213 test214 test215 test216 test217 test218 test219 test22 test220 test2200 test2201 test2202 test2203 test2204 test2205 test2206 test2207 test221 test222 test223 test224 test225 test226 test227 test228 test229 test23 test230 test2300 test2301 test2302 test2303 test2304 test2306 test2307 test2308 test2309 test231 test232 test233 test234 test235 test236 test237 test238 test239 test24 test240 test2400 test2401 test2402 test2403 test2404 test2405 test2406 test2407 test2408 test2409 test241 test2410 test2411 test242 test243 test244 test245 test246 test247 test248 test249 test25 test250 test2500 test2501 test2502 test2503 test2504 test2505 test2506 test251 test252 test253 test254 test255 test256 test257 test258 test259 test26 test260 test2600 test2601 test2602 test2603 test2604 test2605 test261 test262 test263 test264 test265 test266 test267 test268 test269 test27 test270 test2700 test2701 test2702 test2703 test2704 test2705 test2706 test2707 test2708 test2709 test271 test2710 test2711 test2712 test2713 test2714 test2715 test2716 test2717 test2718 test2719 test272 test2720 test2721 test2722 test2723 test273 test274 test275 test276 test277 test278 test279 test28 test280 test281 test282 test283 test284 test285 test286 test287 test288 test289 test29 test290 test291 test292 test293 test294 test295 test296 test297 test298 test299 test3 test30 test300 test3000 test3001 test3002 test3003 test3004 test3005 test3006 test3007 test3008 test3009 test301 test3010 test3011 test3012 test3013 test3014 test3015 test3016 test3017 test3018 test3019 test302 test3020 test3021 test3022 test3023 test3024 test3025 test3026 test3027 test3028 test3029 test303 test3030 test3031 test3032 test3033 test3034 test3035 test3036 test304 test305 test306 test307 test308 test309 test31 test310 test3100 test3101 test3102 test3103 test3104 test3105 test3106 test311 test312 test313 test314 test315 test316 test317 test318 test319 test32 test320 test3200 test3201 test3202 test3203 test3204 test3205 test3206 test3207 test3208 test3209 test321 test3210 test3211 test3212 test3213 test3214 test3215 test3216 test3217 test3218 test3219 test322 test3220 test323 test324 test325 test326 test327 test328 test329 test33 test330 test3300 test3301 test3302 test331 test332 test333 test334 test335 test336 test337 test338 test339 test34 test340 test341 test342 test343 test344 test345 test346 test347 test348 test349 test35 test350 test351 test352 test353 test354 test355 test356 test357 test358 test359 test36 test360 test361 test362 test363 test364 test365 test366 test367 test368 test369 test37 test370 test371 test372 test373 test374 test375 test376 test378 test379 test38 test380 test381 test383 test384 test385 test386 test387 test388 test389 test39 test390 test391 test392 test393 test394 test395 test396 test397 test398 test399 test4 test40 test400 test4000 test4001 test401 test402 test403 test404 test405 test406 test407 test408 test409 test41 test410 test411 test412 test413 test414 test415 test416 test417 test418 test419 test42 test420 test421 test422 test423 test424 test425 test426 test427 test428 test429 test43 test430 test431 test432 test433 test434 test435 test436 test437 test438 test439 test44 test440 test441 test442 test443 test444 test445 test446 test447 test448 test449 test45 test450 test451 test452 test453 test454 test455 test456 test457 test458 test459 test46 test460 test461 test462 test463 test467 test468 test469 test47 test470 test471 test472 test473 test474 test475 test476 test477 test478 test479 test48 test480 test481 test482 test483 test484 test485 test486 test487 test488 test489 test49 test490 test491 test492 test493 test494 test495 test496 test497 test498 test499 test5 test50 test500 test501 test502 test503 test504 test505 test506 test507 test508 test509 test51 test510 test511 test512 test513 test514 test515 test516 test517 test518 test519 test52 test520 test521 test522 test523 test524 test525 test526 test527 test528 test529 test53 test530 test531 test532 test533 test534 test535 test536 test537 test538 test539 test54 test540 test541 test542 test543 test544 test545 test546 test547 test548 test549 test55 test550 test551 test552 test553 test554 test555 test556 test557 test558 test559 test56 test560 test561 test562 test563 test564 test565 test566 test567 test568 test569 test57 test570 test571 test572 test573 test574 test575 test576 test577 test578 test579 test58 test580 test581 test582 test583 test584 test585 test586 test587 test588 test589 test59 test590 test591 test592 test593 test594 test595 test596 test597 test598 test599 test6 test60 test600 test601 test602 test603 test604 test605 test606 test607 test608 test609 test61 test610 test611 test612 test613 test614 test615 test616 test617 test618 test619 test62 test620 test621 test622 test623 test624 test625 test626 test627 test628 test629 test63 test630 test631 test632 test633 test634 test635 test636 test637 test638 test639 test64 test640 test641 test642 test643 test644 test645 test646 test647 test648 test649 test65 test650 test651 test652 test653 test654 test655 test656 test658 test659 test66 test660 test661 test662 test663 test664 test665 test666 test667 test668 test669 test67 test670 test671 test672 test673 test674 test675 test676 test677 test678 test679 test68 test680 test681 test682 test683 test684 test685 test686 test687 test688 test689 test69 test690 test691 test692 test693 test694 test695 test696 test697 test698 test699 test7 test70 test700 test701 test702 test703 test704 test705 test706 test707 test708 test709 test71 test710 test711 test712 test713 test714 test715 test716 test717 test718 test719 test72 test720 test721 test722 test723 test724 test725 test726 test727 test728 test729 test73 test730 test731 test732 test733 test734 test735 test736 test737 test738 test739 test74 test740 test741 test742 test743 test744 test745 test746 test747 test748 test749 test75 test750 test751 test752 test753 test754 test755 test756 test757 test758 test759 test76 test760 test761 test762 test763 test764 test765 test766 test767 test768 test769 test77 test770 test771 test772 test773 test774 test775 test776 test777 test778 test779 test78 test780 test781 test782 test783 test784 test785 test786 test787 test788 test789 test79 test790 test791 test792 test793 test794 test795 test796 test797 test798 test799 test8 test80 test800 test801 test802 test803 test804 test805 test806 test807 test808 test809 test81 test810 test811 test812 test813 test814 test815 test816 test817 test818 test819 test82 test820 test821 test822 test823 test824 test825 test826 test827 test828 test829 test83 test830 test831 test832 test833 test834 test835 test836 test837 test838 test839 test84 test840 test841 test842 test843 test844 test845 test846 test847 test848 test849 test85 test850 test851 test852 test853 test854 test855 test856 test857 test858 test859 test86 test860 test861 test862 test863 test864 test865 test866 test867 test868 test869 test87 test870 test871 test872 test873 test874 test875 test876 test877 test878 test879 test88 test880 test881 test882 test883 test884 test885 test886 test887 test888 test889 test89 test890 test891 test892 test893 test894 test895 test896 test897 test898 test899 test9 test90 test900 test901 test902 test903 test904 test905 test906 test907 test908 test909 test91 test910 test911 test912 test913 test914 test915 test916 test917 test918 test919 test92 test920 test921 test922 test923 test924 test925 test926 test927 test928 test929 test93 test930 test931 test932 test933 test934 test935 test936 test937 test938 test939 test94 test940 test941 test942 test943 test944 test945 test946 test947 test948 test949 test95 test950 test951 test952 test953 test954 test955 test956 test957 test958 test959 test96 test960 test961 test962 test963 test964 test965 test966 test967 test968 test969 test97 test970 test971 test972 test973 test974 test975 test976 test977 test978 test979 test98 test980 test981 test982 test983 test984 test985 test986 test987 test988 test989 test99 test990 test991 test992 test993 test994 test995 test996 test997 test998 test999http
testenv
__init__.py caddy.py certs.py client.py curl.py dante.py dnsd.py env.py httpd.py nghttpx.py ports.py sshd.py vsftpd.py ws_echo_server.pylibtest
.gitignore CMakeLists.txt Makefile.am Makefile.inc cli_ftp_upload.c cli_h2_pausing.c cli_h2_serverpush.c cli_h2_upgrade_extreme.c cli_hx_download.c cli_hx_upload.c cli_tls_session_reuse.c cli_upload_pausing.c cli_ws_data.c cli_ws_pingpong.c first.c first.h lib1156.c lib1301.c lib1308.c lib1485.c lib1500.c lib1501.c lib1502.c lib1506.c lib1507.c lib1508.c lib1509.c lib1510.c lib1511.c lib1512.c lib1513.c lib1514.c lib1515.c lib1517.c lib1518.c lib1520.c lib1522.c lib1523.c lib1525.c lib1526.c lib1527.c lib1528.c lib1529.c lib1530.c lib1531.c lib1532.c lib1533.c lib1534.c lib1535.c lib1536.c lib1537.c lib1538.c lib1540.c lib1541.c lib1542.c lib1545.c lib1549.c lib1550.c lib1551.c lib1552.c lib1553.c lib1554.c lib1555.c lib1556.c lib1557.c lib1558.c lib1559.c lib1560.c lib1564.c lib1565.c lib1567.c lib1568.c lib1569.c lib1571.c lib1576.c lib1582.c lib1587.c lib1588.c lib1589.c lib1591.c lib1592.c lib1593.c lib1594.c lib1597.c lib1598.c lib1599.c lib1662.c lib1900.c lib1901.c lib1902.c lib1903.c lib1905.c lib1906.c lib1907.c lib1908.c lib1910.c lib1911.c lib1912.c lib1913.c lib1915.c lib1916.c lib1918.c lib1919.c lib1920.c lib1921.c lib1933.c lib1934.c lib1935.c lib1936.c lib1937.c lib1938.c lib1939.c lib1940.c lib1945.c lib1947.c lib1948.c lib1955.c lib1956.c lib1957.c lib1958.c lib1959.c lib1960.c lib1964.c lib1965.c lib1970.c lib1971.c lib1972.c lib1973.c lib1974.c lib1975.c lib1977.c lib1978.c lib2023.c lib2032.c lib2082.c lib2301.c lib2302.c lib2304.c lib2306.c lib2308.c lib2309.c lib2402.c lib2404.c lib2405.c lib2502.c lib2504.c lib2505.c lib2506.c lib2700.c lib3010.c lib3025.c lib3026.c lib3027.c lib3033.c lib3034.c lib3100.c lib3101.c lib3102.c lib3103.c lib3104.c lib3105.c lib3207.c lib3208.c lib500.c lib501.c lib502.c lib503.c lib504.c lib505.c lib506.c lib507.c lib508.c lib509.c lib510.c lib511.c lib512.c lib513.c lib514.c lib515.c lib516.c lib517.c lib518.c lib519.c lib520.c lib521.c lib523.c lib524.c lib525.c lib526.c lib530.c lib533.c lib536.c lib537.c lib539.c lib540.c lib541.c lib542.c lib543.c lib544.c lib547.c lib549.c lib552.c lib553.c lib554.c lib555.c lib556.c lib557.c lib558.c lib559.c lib560.c lib562.c lib564.c lib566.c lib567.c lib568.c lib569.c lib570.c lib571.c lib572.c lib573.c lib574.c lib575.c lib576.c lib578.c lib579.c lib582.c lib583.c lib586.c lib589.c lib590.c lib591.c lib597.c lib598.c lib599.c lib643.c lib650.c lib651.c lib652.c lib653.c lib654.c lib655.c lib658.c lib659.c lib661.c lib666.c lib667.c lib668.c lib670.c lib674.c lib676.c lib677.c lib678.c lib694.c lib695.c lib751.c lib753.c lib757.c lib758.c lib766.c memptr.c mk-lib1521.pl test1013.pl test1022.pl test307.pl test610.pl test613.pl testtrace.c testtrace.h testutil.c testutil.h unitcheck.hserver
.checksrc .gitignore CMakeLists.txt Makefile.am Makefile.inc dnsd.c first.c first.h getpart.c mqttd.c resolve.c rtspd.c sockfilt.c socksd.c sws.c tftpd.c util.ctunit
.gitignore CMakeLists.txt Makefile.am Makefile.inc README.md tool1394.c tool1604.c tool1621.c tool1622.c tool1623.c tool1720.cunit
.gitignore CMakeLists.txt Makefile.am Makefile.inc README.md unit1300.c unit1302.c unit1303.c unit1304.c unit1305.c unit1307.c unit1309.c unit1323.c unit1330.c unit1395.c unit1396.c unit1397.c unit1398.c unit1399.c unit1600.c unit1601.c unit1602.c unit1603.c unit1605.c unit1606.c unit1607.c unit1608.c unit1609.c unit1610.c unit1611.c unit1612.c unit1614.c unit1615.c unit1616.c unit1620.c unit1625.c unit1626.c unit1627.c unit1636.c unit1650.c unit1651.c unit1652.c unit1653.c unit1654.c unit1655.c unit1656.c unit1657.c unit1658.c unit1660.c unit1661.c unit1663.c unit1664.c unit1666.c unit1667.c unit1668.c unit1669.c unit1674.c unit1675.c unit1676.c unit1979.c unit1980.c unit2600.c unit2601.c unit2602.c unit2603.c unit2604.c unit2605.c unit3200.c unit3205.c unit3211.c unit3212.c unit3213.c unit3214.c unit3216.c unit3219.c unit3300.c unit3301.c unit3302.cexamples
.env config.ini crypto_test.lua env_test.lua fs_example.lua http_server.lua https_test.lua ini_example.lua json.lua log.lua path_fs_example.lua process_example.lua request_download.lua request_test.lua run_all.lua sqlite_example.lua sqlite_http_template.lua stash_test.lua template_test.lua timer.lua websocket.luainiparser
example
iniexample.c iniwrite.c parse.c twisted-errors.ini twisted-genhuge.py twisted-ofkey.ini twisted-ofval.ini twisted.initest
CMakeLists.txt test_dictionary.c test_iniparser.c unity-config.yml unity_config.hjinjac
libjinjac
src
CMakeLists.txt ast.c ast.h block_statement.c block_statement.h buffer.c buffer.h buildin.c buildin.h common.h convert.c convert.h flex_decl.h jfunction.c jfunction.h jinja_expression.l jinja_expression.y jinjac_parse.c jinjac_parse.h jinjac_stream.c jinjac_stream.h jlist.c jlist.h jobject.c jobject.h parameter.c parameter.h str_obj.c str_obj.h trace.c trace.htest
.gitignore CMakeLists.txt autotest.rb test_01.expected test_01.jinja test_01b.expected test_01b.jinja test_01c.expected test_01c.jinja test_01d.expected test_01d.jinja test_02.expected test_02.jinja test_03.expected test_03.jinja test_04.expected test_04.jinja test_05.expected test_05.jinja test_06.expected test_06.jinja test_07.expected test_07.jinja test_08.expected test_08.jinja test_08b.expected test_08b.jinja test_09.expected test_09.jinja test_10.expected test_10.jinja test_11.expected test_11.jinja test_12.expected test_12.jinja test_13.expected test_13.jinja test_14.expected test_14.jinja test_15.expected test_15.jinja test_16.expected test_16.jinja test_17.expected test_17.jinja test_18.expected test_18.jinja test_18b.expected test_18b.jinja test_18c.expected test_18c.jinja test_19.expected test_19.jinja test_19b.expected test_19b.jinja test_19c.expected test_19c.jinja test_19d.expected test_19d.jinja test_19e.expected test_19e.jinja test_19f.expected test_19f.jinja test_20.expected test_20.jinja test_21.expected test_21.jinja test_22.expected test_22.jinja test_22a.expected test_22a.jinja test_22b.expected test_22b.jinja test_23.expected test_23.jinja test_24.expected test_24.jinjalibev
Changes LICENSE Makefile Makefile.am Makefile.in README Symbols.ev Symbols.event aclocal.m4 autogen.sh compile config.guess config.h config.h.in config.status config.sub configure configure.ac depcomp ev++.h ev.3 ev.c ev.h ev.pod ev_epoll.c ev_kqueue.c ev_poll.c ev_port.c ev_select.c ev_vars.h ev_win32.c ev_wrap.h event.c event.h install-sh libev.m4 libtool ltmain.sh missing mkinstalldirs stamp-h1luajit
doc
bluequad-print.css bluequad.css contact.html ext_buffer.html ext_c_api.html ext_ffi.html ext_ffi_api.html ext_ffi_semantics.html ext_ffi_tutorial.html ext_jit.html ext_profiler.html extensions.html install.html luajit.html running.htmldynasm
dasm_arm.h dasm_arm.lua dasm_arm64.h dasm_arm64.lua dasm_mips.h dasm_mips.lua dasm_mips64.lua dasm_ppc.h dasm_ppc.lua dasm_proto.h dasm_x64.lua dasm_x86.h dasm_x86.lua dynasm.luasrc
host
.gitignore README buildvm.c buildvm.h buildvm_asm.c buildvm_fold.c buildvm_lib.c buildvm_libbc.h buildvm_peobj.c genlibbc.lua genminilua.lua genversion.lua minilua.cjit
.gitignore bc.lua bcsave.lua dis_arm.lua dis_arm64.lua dis_arm64be.lua dis_mips.lua dis_mips64.lua dis_mips64el.lua dis_mips64r6.lua dis_mips64r6el.lua dis_mipsel.lua dis_ppc.lua dis_x64.lua dis_x86.lua dump.lua p.lua v.lua zone.luawolfssl
.github
workflows
ada.yml arduino.yml async-examples.yml async.yml atecc608-sim.yml bind.yml cmake-autoconf.yml cmake.yml codespell.yml coverity-scan-fixes.yml cryptocb-only.yml curl.yml cyrus-sasl.yml disable-pk-algs.yml docker-Espressif.yml docker-OpenWrt.yml emnet-nonblock.yml fil-c.yml freertos-mem-track.yml gencertbuf.yml grpc.yml haproxy.yml hostap-vm.yml intelasm-c-fallback.yml ipmitool.yml jwt-cpp.yml krb5.yml libspdm.yml libssh2.yml libvncserver.yml linuxkm.yml macos-apple-native-cert-validation.yml mbedtls.sh mbedtls.yml membrowse-comment.yml membrowse-onboard.yml membrowse-report.yml memcached.sh memcached.yml mono.yml mosquitto.yml msmtp.yml msys2.yml multi-arch.yml multi-compiler.yml net-snmp.yml nginx.yml no-malloc.yml no-tls.yml nss.sh nss.yml ntp.yml ocsp.yml openldap.yml openssh.yml openssl-ech.yml opensslcoexist.yml openvpn.yml os-check.yml packaging.yml pam-ipmi.yml pq-all.yml pr-commit-check.yml psk.yml puf.yml python.yml rng-tools.yml rust-wrapper.yml se050-sim.yml smallStackSize.yml socat.yml softhsm.yml sssd.yml stm32-sim.yml stsafe-a120-sim.yml stunnel.yml symbol-prefixes.yml threadx.yml tls-anvil.yml trackmemory.yml watcomc.yml win-csharp-test.yml wolfCrypt-Wconversion.yml wolfboot-integration.yml wolfsm.yml xcode.yml zephyr-4.x.yml zephyr.ymlIDE
ARDUINO
Arduino_README_prepend.md README.md include.am keywords.txt library.properties.template wolfssl-arduino.cpp wolfssl-arduino.sh wolfssl.hECLIPSE
Espressif
ESP-IDF
examples
template
CMakeLists.txt Makefile README.md partitions_singleapp_large.csv sdkconfig.defaults sdkconfig.defaults.esp8266wolfssl_benchmark
VisualGDB
wolfssl_benchmark_IDF_v4.4_ESP32.sln wolfssl_benchmark_IDF_v4.4_ESP32.vgdbproj wolfssl_benchmark_IDF_v5_ESP32.sln wolfssl_benchmark_IDF_v5_ESP32.vgdbproj wolfssl_benchmark_IDF_v5_ESP32C3.sln wolfssl_benchmark_IDF_v5_ESP32C3.vgdbproj wolfssl_benchmark_IDF_v5_ESP32S3.sln wolfssl_benchmark_IDF_v5_ESP32S3.vgdbprojwolfssl_client
CMakeLists.txt Makefile README.md README_server_sm.md partitions_singleapp_large.csv sdkconfig.defaults sdkconfig.defaults.esp32c2 sdkconfig.defaults.esp8266 wolfssl_client_ESP8266.vgdbprojwolfssl_server
CMakeLists.txt Makefile README.md README_server_sm.md partitions_singleapp_large.csv sdkconfig.defaults sdkconfig.defaults.esp32c2 sdkconfig.defaults.esp8266 wolfssl_server_ESP8266.vgdbprojwolfssl_test
VisualGDB
wolfssl_test-IDF_v5_ESP32.sln wolfssl_test-IDF_v5_ESP32.vgdbproj wolfssl_test-IDF_v5_ESP32C3.sln wolfssl_test-IDF_v5_ESP32C3.vgdbproj wolfssl_test-IDF_v5_ESP32C6.sln wolfssl_test-IDF_v5_ESP32C6.vgdbproj wolfssl_test_IDF_v5_ESP32S3.sln wolfssl_test_IDF_v5_ESP32S3.vgdbprojGCC-ARM
Makefile Makefile.bench Makefile.client Makefile.common Makefile.server Makefile.static Makefile.test README.md include.am linker.ld linker_fips.ldIAR-EWARM
embOS
SAMV71_XULT
embOS_SAMV71_XULT_user_settings
user_settings.h user_settings_simple_example.h user_settings_verbose_example.hembOS_wolfcrypt_benchmark_SAMV71_XULT
README_wolfcrypt_benchmark wolfcrypt_benchmark.ewd wolfcrypt_benchmark.ewpINTIME-RTOS
Makefile README.md include.am libwolfssl.c libwolfssl.vcxproj user_settings.h wolfExamples.c wolfExamples.h wolfExamples.sln wolfExamples.vcxproj wolfssl-lib.sln wolfssl-lib.vcxprojMQX
Makefile README-jp.md README.md client-tls.c include.am server-tls.c user_config.h user_settings.hMSVS-2019-AZSPHERE
wolfssl_new_azsphere
.gitignore CMakeLists.txt CMakeSettings.json app_manifest.json applibs_versions.h launch.vs.json main.cNETOS
Makefile.wolfcrypt.inc README.md include.am user_settings.h user_settings.h-cert2425 user_settings.h-cert3389 wolfssl_netos_custom.cPlatformIO
examples
wolfssl_benchmark
CMakeLists.txt README.md platformio.ini sdkconfig.defaults wolfssl_benchmark.code-workspaceROWLEY-CROSSWORKS-ARM
Kinetis_FlashPlacement.xml README.md arm_startup.c benchmark_main.c hw.h include.am kinetis_hw.c retarget.c test_main.c user_settings.h wolfssl.hzp wolfssl_ltc.hzpRenesas
e2studio
RA6M3
README.md README_APRA6M_en.md README_APRA6M_jp.md include.amRX72N
EnvisionKit
Simple
README_EN.md README_JP.mdwolfssl_demo
key_data.c key_data.h user_settings.h wolfssl_demo.c wolfssl_demo.h wolfssl_tsip_unit_test.cSTM32Cube
README.md STM32_Benchmarks.md default_conf.ftl include.am main.c wolfssl_example.c wolfssl_example.hWIN
README.txt include.am test.vcxproj user_settings.h user_settings_dtls.h wolfssl-fips.sln wolfssl-fips.vcxprojWIN-SRTP-KDF-140-3
README.txt include.am resource.h test.vcxproj user_settings.h wolfssl-fips.rc wolfssl-fips.sln wolfssl-fips.vcxprojWIN10
README.txt include.am resource.h test.vcxproj user_settings.h wolfssl-fips.rc wolfssl-fips.sln wolfssl-fips.vcxprojXCODE
Benchmark
include.amXilinxSDK
README.md bench.sh combine.sh eclipse_formatter_profile.xml graph.sh include.am user_settings.h wolfssl_example.capple-universal
wolfssl-multiplatform
iotsafe
Makefile README.md ca-cert.c devices.c devices.h include.am main.c memory-tls.c startup.c target.ld user_settings.hmynewt
README.md apps.wolfcrypttest.pkg.yml crypto.wolfssl.pkg.yml crypto.wolfssl.syscfg.yml include.am setup.shcerts
1024
ca-cert.der ca-cert.pem ca-key.der ca-key.pem client-cert.der client-cert.pem client-key.der client-key.pem client-keyPub.der dh1024.der dh1024.pem dsa-pub-1024.pem dsa1024.der dsa1024.pem include.am rsa1024.der server-cert.der server-cert.pem server-key.der server-key.pemcrl
extra-crls
ca-int-cert-revoked.pem claim-root.pem crl_critical_entry.pem crlnum_57oct.pem crlnum_64oct.pem general-server-crl.pem large_crlnum.pem large_crlnum2.pemdilithium
bench_dilithium_level2_key.der bench_dilithium_level3_key.der bench_dilithium_level5_key.der include.amecc
bp256r1-key.der bp256r1-key.pem ca-secp256k1-cert.pem ca-secp256k1-key.pem client-bp256r1-cert.der client-bp256r1-cert.pem client-secp256k1-cert.der client-secp256k1-cert.pem genecc.sh include.am secp256k1-key.der secp256k1-key.pem secp256k1-param.pem secp256k1-privkey.der secp256k1-privkey.pem server-bp256r1-cert.der server-bp256r1-cert.pem server-secp256k1-cert.der server-secp256k1-cert.pem server2-secp256k1-cert.der server2-secp256k1-cert.pem wolfssl.cnf wolfssl_384.cnfed25519
ca-ed25519-key.der ca-ed25519-key.pem ca-ed25519-priv.der ca-ed25519-priv.pem ca-ed25519.der ca-ed25519.pem client-ed25519-key.der client-ed25519-key.pem client-ed25519-priv.der client-ed25519-priv.pem client-ed25519.der client-ed25519.pem eddsa-ed25519.der eddsa-ed25519.pem gen-ed25519-certs.sh gen-ed25519-keys.sh gen-ed25519.sh include.am root-ed25519-key.der root-ed25519-key.pem root-ed25519-priv.der root-ed25519-priv.pem root-ed25519.der root-ed25519.pem server-ed25519-cert.pem server-ed25519-key.der server-ed25519-key.pem server-ed25519-priv.der server-ed25519-priv.pem server-ed25519.der server-ed25519.pemed448
ca-ed448-key.der ca-ed448-key.pem ca-ed448-priv.der ca-ed448-priv.pem ca-ed448.der ca-ed448.pem client-ed448-key.der client-ed448-key.pem client-ed448-priv.der client-ed448-priv.pem client-ed448.der client-ed448.pem gen-ed448-certs.sh gen-ed448-keys.sh include.am root-ed448-key.der root-ed448-key.pem root-ed448-priv.der root-ed448-priv.pem root-ed448.der root-ed448.pem server-ed448-cert.pem server-ed448-key.der server-ed448-key.pem server-ed448-priv.der server-ed448-priv.pem server-ed448.der server-ed448.pemexternal
DigiCertGlobalRootCA.pem README.txt ca-digicert-ev.pem ca-globalsign-root.pem ca-google-root.pem ca_collection.pem include.amintermediate
ca_false_intermediate
gentestcert.sh int_ca.key server.key test_ca.key test_ca.pem test_int_not_cacert.pem test_sign_bynoca_srv.pem wolfssl_base.conf wolfssl_srv.conflms
bc_hss_L2_H5_W8_root.der bc_hss_L3_H5_W4_root.der bc_lms_chain_ca.der bc_lms_chain_leaf.der bc_lms_native_bc_root.der bc_lms_sha256_h10_w8_root.der bc_lms_sha256_h5_w4_root.der include.ammldsa
README.txt include.am mldsa44-cert.der mldsa44-cert.pem mldsa44-key.pem mldsa44_bare-priv.der mldsa44_bare-seed.der mldsa44_oqskeypair.der mldsa44_priv-only.der mldsa44_pub-spki.der mldsa44_seed-only.der mldsa44_seed-priv.der mldsa65-cert.der mldsa65-cert.pem mldsa65-key.pem mldsa65_bare-priv.der mldsa65_bare-seed.der mldsa65_oqskeypair.der mldsa65_priv-only.der mldsa65_pub-spki.der mldsa65_seed-only.der mldsa65_seed-priv.der mldsa87-cert.der mldsa87-cert.pem mldsa87-key.pem mldsa87_bare-priv.der mldsa87_bare-seed.der mldsa87_oqskeypair.der mldsa87_priv-only.der mldsa87_pub-spki.der mldsa87_seed-only.der mldsa87_seed-priv.derocsp
imposter-root-ca-cert.der imposter-root-ca-cert.pem imposter-root-ca-key.der imposter-root-ca-key.pem include.am index-ca-and-intermediate-cas.txt index-ca-and-intermediate-cas.txt.attr index-intermediate1-ca-issued-certs.txt index-intermediate1-ca-issued-certs.txt.attr index-intermediate2-ca-issued-certs.txt index-intermediate2-ca-issued-certs.txt.attr index-intermediate3-ca-issued-certs.txt index-intermediate3-ca-issued-certs.txt.attr intermediate1-ca-cert.der intermediate1-ca-cert.pem intermediate1-ca-key.der intermediate1-ca-key.pem intermediate2-ca-cert.der intermediate2-ca-cert.pem intermediate2-ca-key.der intermediate2-ca-key.pem intermediate3-ca-cert.der intermediate3-ca-cert.pem intermediate3-ca-key.der intermediate3-ca-key.pem ocsp-responder-cert.der ocsp-responder-cert.pem ocsp-responder-key.der ocsp-responder-key.pem openssl.cnf renewcerts-for-test.sh renewcerts.sh root-ca-cert.der root-ca-cert.pem root-ca-crl.pem root-ca-key.der root-ca-key.pem server1-cert.der server1-cert.pem server1-chain-noroot.pem server1-key.der server1-key.pem server2-cert.der server2-cert.pem server2-key.der server2-key.pem server3-cert.der server3-cert.pem server3-key.der server3-key.pem server4-cert.der server4-cert.pem server4-key.der server4-key.pem server5-cert.der server5-cert.pem server5-key.der server5-key.pem test-leaf-response.der test-multi-response.der test-response-nointern.der test-response-rsapss.der test-response.derp521
ca-p521-key.der ca-p521-key.pem ca-p521-priv.der ca-p521-priv.pem ca-p521.der ca-p521.pem client-p521-key.der client-p521-key.pem client-p521-priv.der client-p521-priv.pem client-p521.der client-p521.pem gen-p521-certs.sh gen-p521-keys.sh include.am root-p521-key.der root-p521-key.pem root-p521-priv.der root-p521-priv.pem root-p521.der root-p521.pem server-p521-cert.pem server-p521-key.der server-p521-key.pem server-p521-priv.der server-p521-priv.pem server-p521.der server-p521.pemrpk
client-cert-rpk.der client-ecc-cert-rpk.der include.am server-cert-rpk.der server-ecc-cert-rpk.derrsapss
ca-3072-rsapss-key.der ca-3072-rsapss-key.pem ca-3072-rsapss-priv.der ca-3072-rsapss-priv.pem ca-3072-rsapss.der ca-3072-rsapss.pem ca-rsapss-key.der ca-rsapss-key.pem ca-rsapss-priv.der ca-rsapss-priv.pem ca-rsapss.der ca-rsapss.pem client-3072-rsapss-key.der client-3072-rsapss-key.pem client-3072-rsapss-priv.der client-3072-rsapss-priv.pem client-3072-rsapss.der client-3072-rsapss.pem client-rsapss-key.der client-rsapss-key.pem client-rsapss-priv.der client-rsapss-priv.pem client-rsapss.der client-rsapss.pem gen-rsapss-keys.sh include.am renew-rsapss-certs.sh root-3072-rsapss-key.der root-3072-rsapss-key.pem root-3072-rsapss-priv.der root-3072-rsapss-priv.pem root-3072-rsapss.der root-3072-rsapss.pem root-rsapss-key.der root-rsapss-key.pem root-rsapss-priv.der root-rsapss-priv.pem root-rsapss.der root-rsapss.pem server-3072-rsapss-cert.pem server-3072-rsapss-key.der server-3072-rsapss-key.pem server-3072-rsapss-priv.der server-3072-rsapss-priv.pem server-3072-rsapss.der server-3072-rsapss.pem server-mix-rsapss-cert.pem server-rsapss-cert.pem server-rsapss-key.der server-rsapss-key.pem server-rsapss-priv.der server-rsapss-priv.pem server-rsapss.der server-rsapss.pemslhdsa
bench_slhdsa_sha2_128f_key.der bench_slhdsa_sha2_128s_key.der bench_slhdsa_sha2_192f_key.der bench_slhdsa_sha2_192s_key.der bench_slhdsa_sha2_256f_key.der bench_slhdsa_sha2_256s_key.der bench_slhdsa_shake128f_key.der bench_slhdsa_shake128s_key.der bench_slhdsa_shake192f_key.der bench_slhdsa_shake192s_key.der bench_slhdsa_shake256f_key.der bench_slhdsa_shake256s_key.der client-mldsa44-priv.pem client-mldsa44-sha2.der client-mldsa44-sha2.pem client-mldsa44-shake.der client-mldsa44-shake.pem gen-slhdsa-mldsa-certs.sh include.am root-slhdsa-sha2-128s-priv.der root-slhdsa-sha2-128s-priv.pem root-slhdsa-sha2-128s.der root-slhdsa-sha2-128s.pem root-slhdsa-shake-128s-priv.der root-slhdsa-shake-128s-priv.pem root-slhdsa-shake-128s.der root-slhdsa-shake-128s.pem server-mldsa44-priv.pem server-mldsa44-sha2.der server-mldsa44-sha2.pem server-mldsa44-shake.der server-mldsa44-shake.pemsm2
ca-sm2-key.der ca-sm2-key.pem ca-sm2-priv.der ca-sm2-priv.pem ca-sm2.der ca-sm2.pem client-sm2-key.der client-sm2-key.pem client-sm2-priv.der client-sm2-priv.pem client-sm2.der client-sm2.pem fix_sm2_spki.py gen-sm2-certs.sh gen-sm2-keys.sh include.am root-sm2-key.der root-sm2-key.pem root-sm2-priv.der root-sm2-priv.pem root-sm2.der root-sm2.pem self-sm2-cert.pem self-sm2-key.pem self-sm2-priv.pem server-sm2-cert.der server-sm2-cert.pem server-sm2-key.der server-sm2-key.pem server-sm2-priv.der server-sm2-priv.pem server-sm2.der server-sm2.pemstatickeys
dh-ffdhe2048-params.pem dh-ffdhe2048-pub.der dh-ffdhe2048-pub.pem dh-ffdhe2048.der dh-ffdhe2048.pem ecc-secp256r1.der ecc-secp256r1.pem gen-static.sh include.am x25519-pub.der x25519-pub.pem x25519.der x25519.pemtest
catalog.txt cert-bad-neg-int.der cert-bad-oid.der cert-bad-utf8.der cert-ext-ia.cfg cert-ext-ia.der cert-ext-ia.pem cert-ext-joi.cfg cert-ext-joi.der cert-ext-joi.pem cert-ext-mnc.der cert-ext-multiple.cfg cert-ext-multiple.der cert-ext-multiple.pem cert-ext-nc-combined.der cert-ext-nc-combined.pem cert-ext-nc.cfg cert-ext-nc.der cert-ext-nc.pem cert-ext-ncdns.der cert-ext-ncdns.pem cert-ext-ncip.der cert-ext-ncip.pem cert-ext-ncmixed.der cert-ext-ncmulti.der cert-ext-ncmulti.pem cert-ext-ncrid.der cert-ext-ncrid.pem cert-ext-nct.cfg cert-ext-nct.der cert-ext-nct.pem cert-ext-ndir-exc.cfg cert-ext-ndir-exc.der cert-ext-ndir-exc.pem cert-ext-ndir.cfg cert-ext-ndir.der cert-ext-ndir.pem cert-ext-ns.der cert-over-max-altnames.cfg cert-over-max-altnames.der cert-over-max-altnames.pem cert-over-max-nc.cfg cert-over-max-nc.der cert-over-max-nc.pem client-ecc-cert-ski.hex cn-ip-literal.der cn-ip-wildcard.der crit-cert.pem crit-key.pem dh1024.der dh1024.pem dh512.der dh512.pem digsigku.pem encrypteddata.msg gen-badsig.sh gen-ext-certs.sh gen-testcerts.sh include.am kari-keyid-cms.msg ktri-keyid-cms.msg ossl-trusted-cert.pem server-badaltname.der server-badaltname.pem server-badaltnull.der server-badaltnull.pem server-badcn.der server-badcn.pem server-badcnnull.der server-badcnnull.pem server-cert-ecc-badsig.der server-cert-ecc-badsig.pem server-cert-rsa-badsig.der server-cert-rsa-badsig.pem server-duplicate-policy.pem server-garbage.der server-garbage.pem server-goodalt.der server-goodalt.pem server-goodaltwild.der server-goodaltwild.pem server-goodcn.der server-goodcn.pem server-goodcnwild.der server-goodcnwild.pem server-localhost.der server-localhost.pem smime-test-canon.p7s smime-test-multipart-badsig.p7s smime-test-multipart.p7s smime-test.p7stest-pathlen
assemble-chains.sh chainA-ICA1-key.pem chainA-ICA1-pathlen0.pem chainA-assembled.pem chainA-entity-key.pem chainA-entity.pem chainB-ICA1-key.pem chainB-ICA1-pathlen0.pem chainB-ICA2-key.pem chainB-ICA2-pathlen1.pem chainB-assembled.pem chainB-entity-key.pem chainB-entity.pem chainC-ICA1-key.pem chainC-ICA1-pathlen1.pem chainC-assembled.pem chainC-entity-key.pem chainC-entity.pem chainD-ICA1-key.pem chainD-ICA1-pathlen127.pem chainD-assembled.pem chainD-entity-key.pem chainD-entity.pem chainE-ICA1-key.pem chainE-ICA1-pathlen128.pem chainE-assembled.pem chainE-entity-key.pem chainE-entity.pem chainF-ICA1-key.pem chainF-ICA1-pathlen1.pem chainF-ICA2-key.pem chainF-ICA2-pathlen0.pem chainF-assembled.pem chainF-entity-key.pem chainF-entity.pem chainG-ICA1-key.pem chainG-ICA1-pathlen0.pem chainG-ICA2-key.pem chainG-ICA2-pathlen1.pem chainG-ICA3-key.pem chainG-ICA3-pathlen99.pem chainG-ICA4-key.pem chainG-ICA4-pathlen5.pem chainG-ICA5-key.pem chainG-ICA5-pathlen20.pem chainG-ICA6-key.pem chainG-ICA6-pathlen10.pem chainG-ICA7-key.pem chainG-ICA7-pathlen100.pem chainG-assembled.pem chainG-entity-key.pem chainG-entity.pem chainH-ICA1-key.pem chainH-ICA1-pathlen0.pem chainH-ICA2-key.pem chainH-ICA2-pathlen2.pem chainH-ICA3-key.pem chainH-ICA3-pathlen2.pem chainH-ICA4-key.pem chainH-ICA4-pathlen2.pem chainH-assembled.pem chainH-entity-key.pem chainH-entity.pem chainI-ICA1-key.pem chainI-ICA1-no_pathlen.pem chainI-ICA2-key.pem chainI-ICA2-no_pathlen.pem chainI-ICA3-key.pem chainI-ICA3-pathlen2.pem chainI-assembled.pem chainI-entity-key.pem chainI-entity.pem chainJ-ICA1-key.pem chainJ-ICA1-no_pathlen.pem chainJ-ICA2-key.pem chainJ-ICA2-no_pathlen.pem chainJ-ICA3-key.pem chainJ-ICA3-no_pathlen.pem chainJ-ICA4-key.pem chainJ-ICA4-pathlen2.pem chainJ-assembled.pem chainJ-entity-key.pem chainJ-entity.pem include.am refreshkeys.shtest-serial0
ee_normal.pem ee_serial0.pem generate_certs.sh include.am intermediate_serial0.pem root_serial0.pem root_serial0_key.pem selfsigned_nonca_serial0.pemxmss
bc_xmss_chain_ca.der bc_xmss_chain_leaf.der bc_xmss_sha2_10_256_root.der bc_xmss_sha2_16_256_root.der bc_xmssmt_sha2_20_2_256_root.der bc_xmssmt_sha2_20_4_256_root.der bc_xmssmt_sha2_40_8_256_root.der include.amcmake
Config.cmake.in README.md config.in functions.cmake include.am options.h.in wolfssl-config-version.cmake.in wolfssl-targets.cmake.indebian
changelog.in control.in copyright include.am libwolfssl-dev.install libwolfssl.install rules.indoc
dox_comments
header_files
aes.h arc4.h ascon.h asn.h asn_public.h blake2.h bn.h camellia.h chacha.h chacha20_poly1305.h cmac.h coding.h compress.h cryptocb.h curve25519.h curve448.h des3.h dh.h doxygen_groups.h doxygen_pages.h dsa.h ecc.h eccsi.h ed25519.h ed448.h error-crypt.h evp.h hash.h hmac.h iotsafe.h kdf.h logging.h md2.h md4.h md5.h memory.h ocsp.h pem.h pkcs11.h pkcs7.h poly1305.h psa.h puf.h pwdbased.h quic.h random.h ripemd.h rsa.h sakke.h sha.h sha256.h sha3.h sha512.h signature.h siphash.h srp.h ssl.h tfm.h types.h wc_encrypt.h wc_port.h wc_she.h wc_slhdsa.h wolfio.hheader_files-ja
aes.h arc4.h ascon.h asn.h asn_public.h blake2.h bn.h camellia.h chacha.h chacha20_poly1305.h cmac.h coding.h compress.h cryptocb.h curve25519.h curve448.h des3.h dh.h doxygen_groups.h doxygen_pages.h dsa.h ecc.h eccsi.h ed25519.h ed448.h error-crypt.h evp.h hash.h hmac.h iotsafe.h kdf.h logging.h md2.h md4.h md5.h memory.h ocsp.h pem.h pkcs11.h pkcs7.h poly1305.h psa.h pwdbased.h quic.h random.h ripemd.h rsa.h sakke.h sha.h sha256.h sha3.h sha512.h signature.h siphash.h srp.h ssl.h tfm.h types.h wc_encrypt.h wc_port.h wolfio.hexamples
async
Makefile README.md async_client.c async_server.c async_tls.c async_tls.h include.am user_settings.hconfigs
README.md include.am user_settings_EBSnet.h user_settings_all.h user_settings_arduino.h user_settings_baremetal.h user_settings_ca.h user_settings_curve25519nonblock.h user_settings_dtls13.h user_settings_eccnonblock.h user_settings_espressif.h user_settings_fipsv2.h user_settings_fipsv5.h user_settings_min_ecc.h user_settings_openssl_compat.h user_settings_pkcs7.h user_settings_platformio.h user_settings_pq.h user_settings_rsa_only.h user_settings_stm32.h user_settings_template.h user_settings_tls12.h user_settings_tls13.h user_settings_wolfboot_keytools.h user_settings_wolfssh.h user_settings_wolftpm.hechoclient
echoclient.c echoclient.h echoclient.sln echoclient.vcproj echoclient.vcxproj include.am quitlinuxkm
Kbuild Makefile README.md get_thread_size.c include.am linuxkm-fips-hash-wrapper.sh linuxkm-fips-hash.c linuxkm_memory.c linuxkm_memory.h linuxkm_wc_port.h lkcapi_aes_glue.c lkcapi_dh_glue.c lkcapi_ecdh_glue.c lkcapi_ecdsa_glue.c lkcapi_glue.c lkcapi_rsa_glue.c lkcapi_sha_glue.c module_exports.c.template module_hooks.c pie_redirect_table.c wolfcrypt.lds x86_vector_register_glue.cm4
ax_add_am_macro.m4 ax_am_jobserver.m4 ax_am_macros.m4 ax_append_compile_flags.m4 ax_append_flag.m4 ax_append_link_flags.m4 ax_append_to_file.m4 ax_atomic.m4 ax_bsdkm.m4 ax_check_compile_flag.m4 ax_check_link_flag.m4 ax_compiler_version.m4 ax_count_cpus.m4 ax_create_generic_config.m4 ax_debug.m4 ax_file_escapes.m4 ax_harden_compiler_flags.m4 ax_linuxkm.m4 ax_print_to_file.m4 ax_pthread.m4 ax_require_defined.m4 ax_tls.m4 ax_vcs_checkout.m4 hexversion.m4 lib_socket_nsl.m4 visibility.m4mqx
wolfcrypt_benchmark
ReferencedRSESystems.xml wolfcrypt_benchmark_twrk70f120m_Int_Flash_DDRData_Debug_PnE_U-MultiLink.launch wolfcrypt_benchmark_twrk70f120m_Int_Flash_DDRData_Release_PnE_U-MultiLink.launch wolfcrypt_benchmark_twrk70f120m_Int_Flash_SramData_Debug_JTrace.jlink wolfcrypt_benchmark_twrk70f120m_Int_Flash_SramData_Debug_JTrace.launch wolfcrypt_benchmark_twrk70f120m_Int_Flash_SramData_Debug_PnE_U-MultiLink.launch wolfcrypt_benchmark_twrk70f120m_Int_Flash_SramData_Release_PnE_U-MultiLink.launchwolfcrypt_test
ReferencedRSESystems.xml wolfcrypt_test_twrk70f120m_Int_Flash_DDRData_Debug_PnE_U-MultiLink.launch wolfcrypt_test_twrk70f120m_Int_Flash_DDRData_Release_PnE_U-MultiLink.launch wolfcrypt_test_twrk70f120m_Int_Flash_SramData_Debug_JTrace.jlink wolfcrypt_test_twrk70f120m_Int_Flash_SramData_Debug_JTrace.launch wolfcrypt_test_twrk70f120m_Int_Flash_SramData_Debug_PnE_U-MultiLink.launch wolfcrypt_test_twrk70f120m_Int_Flash_SramData_Release_PnE_U-MultiLink.launchwolfssl_client
ReferencedRSESystems.xml wolfssl_client_twrk70f120m_Int_Flash_DDRData_Debug_PnE_U-MultiLink.launch wolfssl_client_twrk70f120m_Int_Flash_DDRData_Release_PnE_U-MultiLink.launch wolfssl_client_twrk70f120m_Int_Flash_SramData_Debug_JTrace.jlink wolfssl_client_twrk70f120m_Int_Flash_SramData_Debug_JTrace.launch wolfssl_client_twrk70f120m_Int_Flash_SramData_Debug_PnE_U-MultiLink.launch wolfssl_client_twrk70f120m_Int_Flash_SramData_Release_PnE_U-MultiLink.launchscripts
aria-cmake-build-test.sh asn1_oid_sum.pl benchmark.test benchmark_compare.sh cleanup_testfiles.sh crl-gen-openssl.test crl-revoked.test dertoc.pl dtls.test dtlscid.test external.test google.test include.am makedistsmall.sh memtest.sh ocsp-responder-openssl-interop.test ocsp-stapling-with-ca-as-responder.test ocsp-stapling-with-wolfssl-responder.test ocsp-stapling.test ocsp-stapling2.test ocsp-stapling_tls13multi.test ocsp.test openssl.test openssl_srtp.test pem.test ping.test pkcallbacks.test psk.test resume.test rsapss.test sniffer-gen.sh sniffer-ipv6.pcap sniffer-static-rsa.pcap sniffer-testsuite.test sniffer-tls12-keylog.out sniffer-tls12-keylog.pcap sniffer-tls12-keylog.sslkeylog sniffer-tls13-dh-resume.pcap sniffer-tls13-dh.pcap sniffer-tls13-ecc-resume.pcap sniffer-tls13-ecc.pcap sniffer-tls13-hrr.pcap sniffer-tls13-keylog.out sniffer-tls13-keylog.pcap sniffer-tls13-keylog.sslkeylog sniffer-tls13-x25519-resume.pcap sniffer-tls13-x25519.pcap stm32l4-v4_0_1_build.sh tls13.test trusted_peer.test unit.test.in user_settings_asm.shsrc
bio.c conf.c crl.c dtls.c dtls13.c include.am internal.c keys.c ocsp.c pk.c pk_ec.c pk_rsa.c quic.c sniffer.c ssl.c ssl_api_cert.c ssl_api_crl_ocsp.c ssl_api_pk.c ssl_asn1.c ssl_bn.c ssl_certman.c ssl_crypto.c ssl_ech.c ssl_load.c ssl_misc.c ssl_p7p12.c ssl_sess.c ssl_sk.c tls.c tls13.c wolfio.c x509.c x509_str.ctests
api
api.h api_decl.h create_ocsp_test_blobs.py include.am test_aes.c test_aes.h test_arc4.c test_arc4.h test_ascon.c test_ascon.h test_ascon_kats.h test_asn.c test_asn.h test_blake2.c test_blake2.h test_camellia.c test_camellia.h test_certman.c test_certman.h test_chacha.c test_chacha.h test_chacha20_poly1305.c test_chacha20_poly1305.h test_cmac.c test_cmac.h test_curve25519.c test_curve25519.h test_curve448.c test_curve448.h test_des3.c test_des3.h test_dh.c test_dh.h test_digest.h test_dsa.c test_dsa.h test_dtls.c test_dtls.h test_ecc.c test_ecc.h test_ed25519.c test_ed25519.h test_ed448.c test_ed448.h test_evp.c test_evp.h test_evp_cipher.c test_evp_cipher.h test_evp_digest.c test_evp_digest.h test_evp_pkey.c test_evp_pkey.h test_hash.c test_hash.h test_hmac.c test_hmac.h test_md2.c test_md2.h test_md4.c test_md4.h test_md5.c test_md5.h test_mldsa.c test_mldsa.h test_mlkem.c test_mlkem.h test_ocsp.c test_ocsp.h test_ocsp_test_blobs.h test_ossl_asn1.c test_ossl_asn1.h test_ossl_bio.c test_ossl_bio.h test_ossl_bn.c test_ossl_bn.h test_ossl_cipher.c test_ossl_cipher.h test_ossl_dgst.c test_ossl_dgst.h test_ossl_dh.c test_ossl_dh.h test_ossl_dsa.c test_ossl_dsa.h test_ossl_ec.c test_ossl_ec.h test_ossl_ecx.c test_ossl_ecx.h test_ossl_mac.c test_ossl_mac.h test_ossl_obj.c test_ossl_obj.h test_ossl_p7p12.c test_ossl_p7p12.h test_ossl_pem.c test_ossl_pem.h test_ossl_rand.c test_ossl_rand.h test_ossl_rsa.c test_ossl_rsa.h test_ossl_sk.c test_ossl_sk.h test_ossl_x509.c test_ossl_x509.h test_ossl_x509_acert.c test_ossl_x509_acert.h test_ossl_x509_crypto.c test_ossl_x509_crypto.h test_ossl_x509_ext.c test_ossl_x509_ext.h test_ossl_x509_info.c test_ossl_x509_info.h test_ossl_x509_io.c test_ossl_x509_io.h test_ossl_x509_lu.c test_ossl_x509_lu.h test_ossl_x509_name.c test_ossl_x509_name.h test_ossl_x509_pk.c test_ossl_x509_pk.h test_ossl_x509_str.c test_ossl_x509_str.h test_ossl_x509_vp.c test_ossl_x509_vp.h test_pkcs12.c test_pkcs12.h test_pkcs7.c test_pkcs7.h test_poly1305.c test_poly1305.h test_random.c test_random.h test_rc2.c test_rc2.h test_ripemd.c test_ripemd.h test_rsa.c test_rsa.h test_sha.c test_sha.h test_sha256.c test_sha256.h test_sha3.c test_sha3.h test_sha512.c test_sha512.h test_she.c test_she.h test_signature.c test_signature.h test_slhdsa.c test_slhdsa.h test_sm2.c test_sm2.h test_sm3.c test_sm3.h test_sm4.c test_sm4.h test_tls.c test_tls.h test_tls13.c test_tls13.h test_tls_ext.c test_tls_ext.h test_wc_encrypt.c test_wc_encrypt.h test_wolfmath.c test_wolfmath.h test_x509.c test_x509.hwolfcrypt
benchmark
README.md benchmark-VS2022.sln benchmark-VS2022.vcxproj benchmark-VS2022.vcxproj.user benchmark.c benchmark.h benchmark.sln benchmark.vcproj benchmark.vcxproj include.amsrc
port
Espressif
esp_crt_bundle
README.md cacrt_all.pem cacrt_deprecated.pem cacrt_local.pem esp_crt_bundle.c gen_crt_bundle.py pio_install_cryptography.pyRenesas
README.md renesas_common.c renesas_fspsm_aes.c renesas_fspsm_rsa.c renesas_fspsm_sha.c renesas_fspsm_util.c renesas_rx64_hw_sha.c renesas_rx64_hw_util.c renesas_tsip_aes.c renesas_tsip_rsa.c renesas_tsip_sha.c renesas_tsip_util.carm
armv8-32-aes-asm.S armv8-32-aes-asm_c.c armv8-32-chacha-asm.S armv8-32-chacha-asm_c.c armv8-32-curve25519.S armv8-32-curve25519_c.c armv8-32-mlkem-asm.S armv8-32-mlkem-asm_c.c armv8-32-poly1305-asm.S armv8-32-poly1305-asm_c.c armv8-32-sha256-asm.S armv8-32-sha256-asm_c.c armv8-32-sha3-asm.S armv8-32-sha3-asm_c.c armv8-32-sha512-asm.S armv8-32-sha512-asm_c.c armv8-aes-asm.S armv8-aes-asm_c.c armv8-aes.c armv8-chacha-asm.S armv8-chacha-asm_c.c armv8-curve25519.S armv8-curve25519_c.c armv8-mlkem-asm.S armv8-mlkem-asm_c.c armv8-poly1305-asm.S armv8-poly1305-asm_c.c armv8-sha256-asm.S armv8-sha256-asm_c.c armv8-sha256.c armv8-sha3-asm.S armv8-sha3-asm_c.c armv8-sha512-asm.S armv8-sha512-asm_c.c armv8-sha512.c cryptoCell.c cryptoCellHash.c thumb2-aes-asm.S thumb2-aes-asm_c.c thumb2-chacha-asm.S thumb2-chacha-asm_c.c thumb2-curve25519.S thumb2-curve25519_c.c thumb2-mlkem-asm.S thumb2-mlkem-asm_c.c thumb2-poly1305-asm.S thumb2-poly1305-asm_c.c thumb2-sha256-asm.S thumb2-sha256-asm_c.c thumb2-sha3-asm.S thumb2-sha3-asm_c.c thumb2-sha512-asm.S thumb2-sha512-asm_c.ccaam
README.md caam_aes.c caam_doc.pdf caam_driver.c caam_error.c caam_integrity.c caam_qnx.c caam_sha.c wolfcaam_aes.c wolfcaam_cmac.c wolfcaam_ecdsa.c wolfcaam_fsl_nxp.c wolfcaam_hash.c wolfcaam_hmac.c wolfcaam_init.c wolfcaam_qnx.c wolfcaam_rsa.c wolfcaam_seco.c wolfcaam_x25519.cdevcrypto
README.md devcrypto_aes.c devcrypto_ecdsa.c devcrypto_hash.c devcrypto_hmac.c devcrypto_rsa.c devcrypto_x25519.c wc_devcrypto.criscv
riscv-64-aes.c riscv-64-chacha.c riscv-64-poly1305.c riscv-64-sha256.c riscv-64-sha3.c riscv-64-sha512.cwolfssl
openssl
aes.h asn1.h asn1t.h bio.h bn.h buffer.h camellia.h cmac.h cms.h compat_types.h conf.h crypto.h des.h dh.h dsa.h ec.h ec25519.h ec448.h ecdh.h ecdsa.h ed25519.h ed448.h engine.h err.h evp.h fips_rand.h hmac.h include.am kdf.h lhash.h md4.h md5.h modes.h obj_mac.h objects.h ocsp.h opensslconf.h opensslv.h ossl_typ.h pem.h pkcs12.h pkcs7.h rand.h rc4.h ripemd.h rsa.h safestack.h sha.h sha3.h srp.h ssl.h ssl23.h stack.h tls1.h txt_db.h ui.h x509.h x509_vfy.h x509v3.hwolfcrypt
port
Renesas
renesas-fspsm-crypt.h renesas-fspsm-types.h renesas-rx64-hw-crypt.h renesas-tsip-crypt.h renesas_cmn.h renesas_fspsm_internal.h renesas_sync.h renesas_tsip_internal.h renesas_tsip_types.hcaam
caam_driver.h caam_error.h caam_qnx.h wolfcaam.h wolfcaam_aes.h wolfcaam_cmac.h wolfcaam_ecdsa.h wolfcaam_fsl_nxp.h wolfcaam_hash.h wolfcaam_qnx.h wolfcaam_rsa.h wolfcaam_seco.h wolfcaam_sha.h wolfcaam_x25519.hwrapper
Ada
examples
src
aes_verify_main.adb rsa_verify_main.adb sha256_main.adb spark_sockets.adb spark_sockets.ads spark_terminal.adb spark_terminal.ads tls_client.adb tls_client.ads tls_client_main.adb tls_server.adb tls_server.ads tls_server_main.adbtests
src
aes_bindings_tests.adb aes_bindings_tests.ads rsa_verify_bindings_tests.adb rsa_verify_bindings_tests.ads sha256_bindings_tests.adb sha256_bindings_tests.ads tests.adbCSharp
wolfSSL-Example-IOCallbacks
App.config wolfSSL-Example-IOCallbacks.cs wolfSSL-Example-IOCallbacks.csprojwolfSSL-TLS-ServerThreaded
App.config wolfSSL-TLS-ServerThreaded.cs wolfSSL-TLS-ServerThreaded.csprojrust
wolfssl-wolfcrypt
src
aes.rs blake2.rs chacha20_poly1305.rs cmac.rs cmac_mac.rs curve25519.rs dh.rs dilithium.rs ecc.rs ecdsa.rs ed25519.rs ed448.rs fips.rs hkdf.rs hmac.rs hmac_mac.rs kdf.rs lib.rs lms.rs mlkem.rs mlkem_kem.rs pbkdf2_password_hash.rs prf.rs random.rs rsa.rs rsa_pkcs1v15.rs sha.rs sha_digest.rs sys.rstests
test_aes.rs test_blake2.rs test_chacha20_poly1305.rs test_cmac.rs test_cmac_mac.rs test_curve25519.rs test_dh.rs test_dilithium.rs test_ecc.rs test_ecdsa.rs test_ed25519.rs test_ed448.rs test_hkdf.rs test_hmac.rs test_hmac_mac.rs test_kdf.rs test_lms.rs test_mlkem.rs test_mlkem_kem.rs test_pbkdf2_password_hash.rs test_prf.rs test_random.rs test_rsa.rs test_rsa_pkcs1v15.rs test_sha.rs test_sha_digest.rs test_wolfcrypt.rszephyr
samples
wolfssl_benchmark
CMakeLists.txt README install_test.sh prj.conf sample.yaml zephyr_legacy.conf zephyr_v4.1.confwolfssl_test
CMakeLists.txt README install_test.sh prj-no-malloc.conf prj.conf sample.yaml zephyr_legacy.conf zephyr_v4.1.conf
wolfssl/wrapper/CSharp/wolfSSL_CSharp/wolfCrypt.cs
raw
1/* wolfCrypt.cs
2 *
3 * Copyright (C) 2006-2026 wolfSSL Inc.
4 *
5 * This file is part of wolfSSL.
6 *
7 * wolfSSL is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 3 of the License, or
10 * (at your option) any later version.
11 *
12 * wolfSSL is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with this program; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA
20 */
21
22using System;
23using System.Collections.Generic;
24#if !WindowsCE
25using System.Collections.Concurrent;
26#endif
27using System.Runtime.InteropServices;
28using System.Security.Cryptography;
29using System.Text;
30
31namespace wolfSSL.CSharp
32{
33 public class wolfcrypt
34 {
35 private const string wolfssl_dll = "wolfssl.dll";
36
37 /********************************
38 * Init wolfSSL library
39 */
40#if WindowsCE
41 [DllImport(wolfssl_dll)]
42 private extern static int wolfCrypt_Init();
43 [DllImport(wolfssl_dll)]
44 private extern static int wolfCrypt_Cleanup();
45#else
46 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
47 private extern static int wolfCrypt_Init();
48 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
49 private extern static int wolfCrypt_Cleanup();
50#endif
51
52
53 /********************************
54 * Random
55 */
56#if WindowsCE
57 [DllImport(wolfssl_dll)]
58 private extern static IntPtr wc_rng_new(IntPtr nonce, UInt32 nonceSz, IntPtr heap);
59 [DllImport(wolfssl_dll)]
60 private extern static void wc_rng_free(IntPtr rng);
61 [DllImport(wolfssl_dll)]
62 private extern static int wc_RNG_GenerateBlock(IntPtr rng, IntPtr output, UInt32 sz);
63#else
64 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
65 private extern static IntPtr wc_rng_new(IntPtr nonce, UInt32 nonceSz, IntPtr heap);
66 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
67 private extern static void wc_rng_free(IntPtr rng);
68 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
69 private extern static int wc_RNG_GenerateBlock(IntPtr rng, IntPtr output, UInt32 sz);
70#endif
71
72
73 /********************************
74 * ECC
75 */
76#if WindowsCE
77 [DllImport(wolfssl_dll)]
78 private extern static IntPtr wc_ecc_key_new(IntPtr heap);
79 [DllImport(wolfssl_dll)]
80 private extern static void wc_ecc_key_free(IntPtr key);
81 [DllImport(wolfssl_dll)]
82 private extern static int wc_ecc_set_rng(IntPtr key, IntPtr rng);
83 [DllImport(wolfssl_dll)]
84 private extern static int wc_ecc_make_key_ex(IntPtr rng, int keysize, IntPtr key, int curve_id);
85 [DllImport(wolfssl_dll)]
86 private extern static int wc_ecc_sign_hash(IntPtr hashPtr, uint hashlen, IntPtr sigPtr, IntPtr siglen, IntPtr rng, IntPtr key);
87 [DllImport(wolfssl_dll)]
88 private extern static int wc_ecc_verify_hash(IntPtr sigPtr, uint siglen, IntPtr hashPtr, uint hashlen, IntPtr res, IntPtr key);
89
90 /* ASN.1 DER format */
91 [DllImport(wolfssl_dll)]
92 private extern static int wc_EccPrivateKeyDecode(IntPtr keyBuf, IntPtr idx, IntPtr key, uint keyBufSz);
93 [DllImport(wolfssl_dll)]
94 private static extern int wc_EccPublicKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
95 [DllImport(wolfssl_dll)]
96 private static extern int wc_EccPrivateKeyToDer(IntPtr key, byte[] output, uint inLen);
97 [DllImport(wolfssl_dll)]
98 private static extern int wc_EccPublicKeyToDer(IntPtr key, byte[] output, uint inLen, int with_AlgCurve);
99#else
100 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
101 private extern static IntPtr wc_ecc_key_new(IntPtr heap);
102 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
103 private extern static void wc_ecc_key_free(IntPtr key);
104 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
105 private extern static int wc_ecc_set_rng(IntPtr key, IntPtr rng);
106 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
107 private extern static int wc_ecc_make_key_ex(IntPtr rng, int keysize, IntPtr key, int curve_id);
108 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
109 private extern static int wc_ecc_sign_hash(IntPtr hashPtr, uint hashlen, IntPtr sigPtr, IntPtr siglen, IntPtr rng, IntPtr key);
110 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
111 private extern static int wc_ecc_verify_hash(IntPtr sigPtr, uint siglen, IntPtr hashPtr, uint hashlen, IntPtr res, IntPtr key);
112
113 /* ASN.1 DER format */
114 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
115 private extern static int wc_EccPrivateKeyDecode(IntPtr keyBuf, IntPtr idx, IntPtr key, uint keyBufSz);
116 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
117 private static extern int wc_EccPublicKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
118 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
119 private static extern int wc_EccPrivateKeyToDer(IntPtr key, byte[] output, uint inLen);
120 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
121 private static extern int wc_EccPublicKeyToDer(IntPtr key, byte[] output, uint inLen, int with_AlgCurve);
122#endif
123
124
125 /********************************
126 * ECIES
127 */
128#if WindowsCE
129 [DllImport(wolfssl_dll)]
130 private extern static IntPtr wc_ecc_ctx_new(int flags, IntPtr rng);
131 [DllImport(wolfssl_dll)]
132 private extern static IntPtr wc_ecc_ctx_new_ex(int flags, IntPtr rng, IntPtr heap);
133 [DllImport(wolfssl_dll)]
134 private extern static void wc_ecc_ctx_free(IntPtr ctx);
135 [DllImport(wolfssl_dll)]
136 private extern static int wc_ecc_ctx_reset(IntPtr ctx, IntPtr rng);
137 [DllImport(wolfssl_dll)]
138 private extern static int wc_ecc_ctx_set_algo(IntPtr ctx, byte encAlgo, byte kdfAlgo, byte macAlgo);
139 [DllImport(wolfssl_dll)]
140 private extern static IntPtr wc_ecc_ctx_get_own_salt(IntPtr ctx);
141 [DllImport(wolfssl_dll)]
142 private extern static int wc_ecc_ctx_set_peer_salt(IntPtr ctx, IntPtr salt);
143 [DllImport(wolfssl_dll)]
144 private extern static int wc_ecc_ctx_set_own_salt(IntPtr ctx, IntPtr salt, uint sz);
145 [DllImport(wolfssl_dll)]
146 private extern static int wc_ecc_ctx_set_kdf_salt(IntPtr ctx, IntPtr salt, uint sz);
147 [DllImport(wolfssl_dll)]
148 private extern static int wc_ecc_ctx_set_info(IntPtr ctx, IntPtr info, int sz);
149 [DllImport(wolfssl_dll)]
150 private extern static int wc_ecc_encrypt(IntPtr privKey, IntPtr pubKey, IntPtr msg, uint msgSz, IntPtr outBuffer, IntPtr outSz, IntPtr ctx);
151 [DllImport(wolfssl_dll)]
152 private extern static int wc_ecc_encrypt_ex(IntPtr privKey, IntPtr pubKey, IntPtr msg, uint msgSz, IntPtr outBuffer, IntPtr outSz, IntPtr ctx, int compressed);
153 [DllImport(wolfssl_dll)]
154 private extern static int wc_ecc_decrypt(IntPtr privKey, IntPtr pubKey, IntPtr msg, uint msgSz, IntPtr outBuffer, IntPtr outSz, IntPtr ctx);
155#else
156 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
157 private extern static IntPtr wc_ecc_ctx_new(int flags, IntPtr rng);
158 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
159 private extern static IntPtr wc_ecc_ctx_new_ex(int flags, IntPtr rng, IntPtr heap);
160 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
161 private extern static void wc_ecc_ctx_free(IntPtr ctx);
162 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
163 private extern static int wc_ecc_ctx_reset(IntPtr ctx, IntPtr rng);
164 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
165 private extern static int wc_ecc_ctx_set_algo(IntPtr ctx, byte encAlgo, byte kdfAlgo, byte macAlgo);
166 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
167 private extern static IntPtr wc_ecc_ctx_get_own_salt(IntPtr ctx);
168 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
169 private extern static int wc_ecc_ctx_set_peer_salt(IntPtr ctx, IntPtr salt);
170 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
171 private extern static int wc_ecc_ctx_set_own_salt(IntPtr ctx, IntPtr salt, uint sz);
172 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
173 private extern static int wc_ecc_ctx_set_kdf_salt(IntPtr ctx, IntPtr salt, uint sz);
174 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
175 private extern static int wc_ecc_ctx_set_info(IntPtr ctx, IntPtr info, int sz);
176 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
177 private extern static int wc_ecc_encrypt(IntPtr privKey, IntPtr pubKey, IntPtr msg, uint msgSz, IntPtr outBuffer, IntPtr outSz, IntPtr ctx);
178 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
179 private extern static int wc_ecc_encrypt_ex(IntPtr privKey, IntPtr pubKey, IntPtr msg, uint msgSz, IntPtr outBuffer, IntPtr outSz, IntPtr ctx, int compressed);
180 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
181 private extern static int wc_ecc_decrypt(IntPtr privKey, IntPtr pubKey, IntPtr msg, uint msgSz, IntPtr outBuffer, IntPtr outSz, IntPtr ctx);
182#endif
183
184
185
186 /********************************
187 * ECDHE
188 */
189#if WindowsCE
190 [DllImport(wolfssl_dll)]
191 private extern static int wc_ecc_shared_secret(IntPtr privateKey, IntPtr publicKey, byte[] outSharedSecret, ref int outlen);
192#else
193 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
194 private extern static int wc_ecc_shared_secret(IntPtr privateKey, IntPtr publicKey, byte[] outSharedSecret, ref int outlen);
195#endif
196
197
198 /********************************
199 * RSA
200 */
201#if WindowsCE
202 [DllImport(wolfssl_dll)]
203 private static extern IntPtr wc_NewRsaKey(IntPtr heap, int devId, IntPtr result_code);
204 [DllImport(wolfssl_dll)]
205 private static extern int wc_DeleteRsaKey(IntPtr key, IntPtr key_p);
206 [DllImport(wolfssl_dll)]
207 private extern static int wc_InitRsaKey(IntPtr key, IntPtr heap);
208 [DllImport(wolfssl_dll)]
209 private extern static void wc_FreeRsaKey(IntPtr key);
210 [DllImport(wolfssl_dll)]
211 private extern static int wc_MakeRsaKey(IntPtr key, int keysize, Int32 exponent, IntPtr rng);
212 [DllImport(wolfssl_dll)]
213 private extern static int wc_RsaSSL_Sign(IntPtr hashPtr, int hashLen, IntPtr sigPtr, int sigLen, IntPtr key, IntPtr rng);
214 [DllImport(wolfssl_dll)]
215 private extern static int wc_RsaSSL_Verify(IntPtr sigPtr, int sigLen, IntPtr hashPtr, int hashLen, IntPtr key);
216
217 /* ASN.1 DER format */
218 [DllImport(wolfssl_dll)]
219 private extern static int wc_RsaPublicEncrypt(IntPtr inPtr, int inLen, IntPtr outPtr, int outLen, IntPtr key);
220 [DllImport(wolfssl_dll)]
221 private extern static int wc_RsaPrivateDecrypt(IntPtr inPtr, int inLen, IntPtr outPtr, int outLen, IntPtr key);
222 [DllImport(wolfssl_dll)]
223 private extern static int wc_RsaPrivateKeyDecode(IntPtr keyBuf, IntPtr idx, IntPtr key, uint keyBufSz);
224 [DllImport(wolfssl_dll)]
225 private extern static int wc_RsaPublicKeyDecode(IntPtr keyBuf, IntPtr idx, IntPtr key, uint keyBufSz);
226
227 [DllImport(wolfssl_dll)]
228 private extern static int wc_RsaPSS_Sign(IntPtr hashPtr, int hashLen, IntPtr sigPtr, int sigLen, int hashType, IntPtr rng, IntPtr key);
229 [DllImport(wolfssl_dll)]
230 private extern static int wc_RsaPSS_Verify(IntPtr sigPtr, int sigLen, IntPtr hashPtr, int hashLen, int hashType, IntPtr key);
231 [DllImport(wolfssl_dll)]
232 private extern static int wc_RsaPSS_CheckPadding(IntPtr sigPtr, int sigLen, int hashType, IntPtr key);
233#else
234 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
235 private static extern IntPtr wc_NewRsaKey(IntPtr heap, int devId, IntPtr result_code);
236 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
237 private static extern int wc_DeleteRsaKey(IntPtr key, IntPtr key_p);
238 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
239 private extern static int wc_InitRsaKey(IntPtr key, IntPtr heap);
240 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
241 private extern static void wc_FreeRsaKey(IntPtr key);
242 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
243 private extern static int wc_MakeRsaKey(IntPtr key, int keysize, Int32 exponent, IntPtr rng);
244 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
245 private extern static int wc_RsaSSL_Sign(IntPtr hashPtr, int hashLen, IntPtr sigPtr, int sigLen, IntPtr key, IntPtr rng);
246 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
247 private extern static int wc_RsaSSL_Verify(IntPtr sigPtr, int sigLen, IntPtr hashPtr, int hashLen, IntPtr key);
248
249 /* ASN.1 DER format */
250 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
251 private extern static int wc_RsaPublicEncrypt(IntPtr inPtr, int inLen, IntPtr outPtr, int outLen, IntPtr key);
252 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
253 private extern static int wc_RsaPrivateDecrypt(IntPtr inPtr, int inLen, IntPtr outPtr, int outLen, IntPtr key);
254 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
255 private extern static int wc_RsaPrivateKeyDecode(IntPtr keyBuf, IntPtr idx, IntPtr key, uint keyBufSz);
256 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
257 private extern static int wc_RsaPublicKeyDecode(IntPtr keyBuf, IntPtr idx, IntPtr key, uint keyBufSz);
258
259 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
260 private extern static int wc_RsaPSS_Sign(IntPtr hashPtr, int hashLen, IntPtr sigPtr, int sigLen, int hashType, IntPtr rng, IntPtr key);
261 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
262 private extern static int wc_RsaPSS_Verify(IntPtr sigPtr, int sigLen, IntPtr hashPtr, int hashLen, int hashType, IntPtr key);
263 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
264 private extern static int wc_RsaPSS_CheckPadding(IntPtr sigPtr, int sigLen, int hashType, IntPtr key);
265#endif
266
267
268 /********************************
269 * ED25519
270 */
271#if WindowsCE
272 [DllImport(wolfssl_dll)]
273 private static extern IntPtr wc_ed25519_new(IntPtr heap, int devId, IntPtr result_code);
274 [DllImport(wolfssl_dll)]
275 private static extern int wc_ed25519_delete(IntPtr key, IntPtr key_p);
276 [DllImport(wolfssl_dll)]
277 private static extern int wc_ed25519_init(IntPtr key);
278 [DllImport(wolfssl_dll)]
279 private static extern void wc_ed25519_free(IntPtr key);
280 [DllImport(wolfssl_dll)]
281 private static extern int wc_ed25519_make_key(IntPtr rng, int keysize, IntPtr key);
282 [DllImport(wolfssl_dll)]
283 private static extern int wc_ed25519_sign_msg(IntPtr inMsg, uint inlen, IntPtr outMsg, ref uint outlen, IntPtr key);
284 [DllImport(wolfssl_dll)]
285 private static extern int wc_ed25519_verify_msg(IntPtr sig, uint siglen, IntPtr msg, uint msgLen, ref int ret, IntPtr key);
286
287 /* ASN.1 DER format */
288 [DllImport(wolfssl_dll)]
289 private static extern int wc_Ed25519PrivateKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
290 [DllImport(wolfssl_dll)]
291 private static extern int wc_Ed25519PublicKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
292 [DllImport(wolfssl_dll)]
293 private static extern int wc_Ed25519KeyToDer(IntPtr key, byte[] output, uint inLen);
294 [DllImport(wolfssl_dll)]
295 private static extern int wc_Ed25519PrivateKeyToDer(IntPtr key, byte[] output, uint inLen);
296 [DllImport(wolfssl_dll)]
297 private static extern int wc_Ed25519PublicKeyToDer(IntPtr key, byte[] output, uint inLen, int withAlg);
298
299 /* RAW format */
300 [DllImport(wolfssl_dll)]
301 private static extern int wc_ed25519_make_public(IntPtr key, IntPtr pubKey, uint pubKeySz);
302 [DllImport(wolfssl_dll)]
303 private static extern int wc_ed25519_import_public(IntPtr inMsg, uint inLen, IntPtr key);
304 [DllImport(wolfssl_dll)]
305 private static extern int wc_ed25519_export_public(IntPtr key, IntPtr outMsg, ref uint outLen);
306 [DllImport(wolfssl_dll)]
307 private static extern int wc_ed25519_export_private(IntPtr key, IntPtr outMsg, ref uint outLen);
308 [DllImport(wolfssl_dll)]
309 private static extern int wc_ed25519_size(IntPtr key);
310#else
311 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
312 private static extern IntPtr wc_ed25519_new(IntPtr heap, int devId, IntPtr result_code);
313 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
314 private static extern int wc_ed25519_delete(IntPtr key, IntPtr key_p);
315 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
316 private static extern int wc_ed25519_init(IntPtr key);
317 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
318 private static extern void wc_ed25519_free(IntPtr key);
319 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
320 private static extern int wc_ed25519_make_key(IntPtr rng, int keysize, IntPtr key);
321 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
322 private static extern int wc_ed25519_sign_msg(IntPtr inMsg, uint inlen, IntPtr outMsg, ref uint outlen, IntPtr key);
323 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
324 private static extern int wc_ed25519_verify_msg(IntPtr sig, uint siglen, IntPtr msg, uint msgLen, ref int ret, IntPtr key);
325
326 /* ASN.1 DER format */
327 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
328 private static extern int wc_Ed25519PrivateKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
329 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
330 private static extern int wc_Ed25519PublicKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
331 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
332 private static extern int wc_Ed25519KeyToDer(IntPtr key, byte[] output, uint inLen);
333 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
334 private static extern int wc_Ed25519PrivateKeyToDer(IntPtr key, byte[] output, uint inLen);
335 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
336 private static extern int wc_Ed25519PublicKeyToDer(IntPtr key, byte[] output, uint inLen, int withAlg);
337
338 /* RAW format */
339 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
340 private static extern int wc_ed25519_make_public(IntPtr key, IntPtr pubKey, uint pubKeySz);
341 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
342 private static extern int wc_ed25519_import_public(IntPtr inMsg, uint inLen, IntPtr key);
343 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
344 private static extern int wc_ed25519_export_public(IntPtr key, IntPtr outMsg, ref uint outLen);
345 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
346 private static extern int wc_ed25519_export_private(IntPtr key, IntPtr outMsg, ref uint outLen);
347 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
348 private static extern int wc_ed25519_size(IntPtr key);
349#endif
350
351
352 /********************************
353 * Curve25519
354 */
355#if WindowsCE
356 [DllImport(wolfssl_dll)]
357 private static extern IntPtr wc_curve25519_new(IntPtr heap, int devId, IntPtr result_code);
358 [DllImport(wolfssl_dll)]
359 private static extern int wc_curve25519_delete(IntPtr key, IntPtr key_p);
360 [DllImport(wolfssl_dll)]
361 private extern static int wc_curve25519_init(IntPtr key);
362 [DllImport(wolfssl_dll)]
363 private extern static void wc_curve25519_free(IntPtr key);
364 [DllImport(wolfssl_dll)]
365 private extern static int wc_curve25519_make_key(IntPtr rng, int keysize, IntPtr key);
366 [DllImport(wolfssl_dll)]
367 private extern static int wc_curve25519_shared_secret(IntPtr privateKey, IntPtr publicKey, byte[] outSharedSecret, ref int outlen);
368 /* Only available when wolfSSL is built with WOLFSSL_CURVE25519_BLINDING.
369 * Calls are wrapped in try/catch to tolerate builds without it. */
370 [DllImport(wolfssl_dll)]
371 private extern static int wc_curve25519_set_rng(IntPtr key, IntPtr rng);
372
373 /* ASN.1 DER format */
374 [DllImport(wolfssl_dll)]
375 private static extern int wc_Curve25519PrivateKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
376 [DllImport(wolfssl_dll)]
377 private static extern int wc_Curve25519PublicKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
378 [DllImport(wolfssl_dll)]
379 private static extern int wc_Curve25519PrivateKeyToDer(IntPtr key, byte[] output, uint inLen);
380 [DllImport(wolfssl_dll)]
381 private static extern int wc_Curve25519PublicKeyToDer(IntPtr key, byte[] output, uint inLen, int withAlg);
382
383 /* RAW format */
384 [DllImport(wolfssl_dll)]
385 private extern static int wc_curve25519_import_private(IntPtr privKey, int privKeySz, IntPtr key);
386 [DllImport(wolfssl_dll)]
387 private static extern int wc_curve25519_export_public(IntPtr key, byte[] outBuffer, ref uint outLen);
388 [DllImport(wolfssl_dll)]
389 private extern static int wc_curve25519_import_public(IntPtr pubKey, int pubKeySz, IntPtr key);
390 [DllImport(wolfssl_dll)]
391 private extern static int wc_curve25519_export_public(IntPtr key, IntPtr outPubKey, ref int outlen);
392 [DllImport(wolfssl_dll)]
393 private static extern int wc_curve25519_export_key_raw(IntPtr key, byte[] priv, ref uint privSz, byte[] pub, ref uint pubSz);
394 [DllImport(wolfssl_dll)]
395 private extern static int wc_curve25519_import_private_raw(IntPtr privKey, IntPtr pubKey, IntPtr key);
396 [DllImport(wolfssl_dll)]
397 private extern static int wc_curve25519_export_private_raw(IntPtr key, IntPtr outPrivKey, IntPtr outPubKey);
398#else
399 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
400 private static extern IntPtr wc_curve25519_new(IntPtr heap, int devId, IntPtr result_code);
401 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
402 private static extern int wc_curve25519_delete(IntPtr key, IntPtr key_p);
403 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
404 private extern static int wc_curve25519_init(IntPtr key);
405 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
406 private extern static void wc_curve25519_free(IntPtr key);
407 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
408 private extern static int wc_curve25519_make_key(IntPtr rng, int keysize, IntPtr key);
409 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
410 private extern static int wc_curve25519_shared_secret(IntPtr privateKey, IntPtr publicKey, byte[] outSharedSecret, ref int outlen);
411 /* Only available when wolfSSL is built with WOLFSSL_CURVE25519_BLINDING.
412 * Calls are wrapped in try/catch to tolerate builds without it. */
413 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
414 private extern static int wc_curve25519_set_rng(IntPtr key, IntPtr rng);
415
416 /* ASN.1 DER format */
417 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
418 private static extern int wc_Curve25519PrivateKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
419 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
420 private static extern int wc_Curve25519PublicKeyDecode(byte[] input, ref uint inOutIdx, IntPtr key, uint inSz);
421 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
422 private static extern int wc_Curve25519PrivateKeyToDer(IntPtr key, byte[] output, uint inLen);
423 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
424 private static extern int wc_Curve25519PublicKeyToDer(IntPtr key, byte[] output, uint inLen, int withAlg);
425
426 /* RAW format */
427 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
428 private extern static int wc_curve25519_import_private(IntPtr privKey, int privKeySz, IntPtr key);
429 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
430 private static extern int wc_curve25519_export_public(IntPtr key, byte[] outBuffer, ref uint outLen);
431 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
432 private extern static int wc_curve25519_import_public(IntPtr pubKey, int pubKeySz, IntPtr key);
433 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
434 private extern static int wc_curve25519_export_public(IntPtr key, IntPtr outPubKey, ref int outlen);
435 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
436 private static extern int wc_curve25519_export_key_raw(IntPtr key, byte[] priv, ref uint privSz, byte[] pub, ref uint pubSz);
437 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
438 private extern static int wc_curve25519_import_private_raw(IntPtr privKey, IntPtr pubKey, IntPtr key);
439 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
440 private extern static int wc_curve25519_export_private_raw(IntPtr key, IntPtr outPrivKey, IntPtr outPubKey);
441#endif
442
443 /********************************
444 * ML-KEM
445 */
446#if WindowsCE
447 [DllImport(wolfssl_dll)]
448 private static extern int wc_MlKemKey_CipherTextSize(IntPtr key, ref uint len);
449 [DllImport(wolfssl_dll)]
450 private static extern int wc_MlKemKey_SharedSecretSize(IntPtr key, ref uint len);
451 [DllImport(wolfssl_dll)]
452 private static extern int wc_MlKemKey_PrivateKeySize(IntPtr key, ref uint len);
453 [DllImport(wolfssl_dll)]
454 private static extern int wc_MlKemKey_PublicKeySize(IntPtr key, ref uint len);
455 [DllImport(wolfssl_dll)]
456 private static extern IntPtr wc_MlKemKey_New(int type, IntPtr heap, int devId);
457 [DllImport(wolfssl_dll)]
458 private static extern int wc_MlKemKey_Delete(IntPtr key, IntPtr key_p);
459 [DllImport(wolfssl_dll)]
460 private static extern int wc_MlKemKey_MakeKey(IntPtr key, IntPtr rng);
461 [DllImport(wolfssl_dll)]
462 private static extern int wc_MlKemKey_EncodePublicKey(IntPtr key, byte[] output, uint len);
463 [DllImport(wolfssl_dll)]
464 private static extern int wc_MlKemKey_DecodePublicKey(IntPtr key, byte[] input, uint len);
465 [DllImport(wolfssl_dll)]
466 private static extern int wc_MlKemKey_Encapsulate(IntPtr key, byte[] ct, byte[] ss, IntPtr rng);
467 [DllImport(wolfssl_dll)]
468 private static extern int wc_MlKemKey_Decapsulate(IntPtr key, byte[] ss, byte[] ct, uint len);
469 [DllImport(wolfssl_dll)]
470 private static extern int wc_MlKemKey_EncodePrivateKey(IntPtr key, byte[] output, uint len);
471 [DllImport(wolfssl_dll)]
472 private static extern int wc_MlKemKey_DecodePrivateKey(IntPtr key, byte[] input, uint len);
473#else
474 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
475 private static extern int wc_MlKemKey_CipherTextSize(IntPtr key, ref uint len);
476 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
477 private static extern int wc_MlKemKey_SharedSecretSize(IntPtr key, ref uint len);
478 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
479 private static extern int wc_MlKemKey_PrivateKeySize(IntPtr key, ref uint len);
480 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
481 private static extern int wc_MlKemKey_PublicKeySize(IntPtr key, ref uint len);
482 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
483 private static extern IntPtr wc_MlKemKey_New(int type, IntPtr heap, int devId);
484 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
485 private static extern int wc_MlKemKey_Delete(IntPtr key, IntPtr key_p);
486 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
487 private static extern int wc_MlKemKey_MakeKey(IntPtr key, IntPtr rng);
488 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
489 private static extern int wc_MlKemKey_EncodePublicKey(IntPtr key, byte[] output, uint len);
490 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
491 private static extern int wc_MlKemKey_DecodePublicKey(IntPtr key, byte[] input, uint len);
492 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
493 private static extern int wc_MlKemKey_Encapsulate(IntPtr key, byte[] ct, byte[] ss, IntPtr rng);
494 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
495 private static extern int wc_MlKemKey_Decapsulate(IntPtr key, byte[] ss, byte[] ct, uint len);
496 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
497 private static extern int wc_MlKemKey_EncodePrivateKey(IntPtr key, byte[] output, uint len);
498 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
499 private static extern int wc_MlKemKey_DecodePrivateKey(IntPtr key, byte[] input, uint len);
500#endif
501
502 /********************************
503 * ML-DSA
504 */
505#if WindowsCE
506 [DllImport(wolfssl_dll)]
507 private static extern IntPtr wc_dilithium_new(IntPtr heap, int devId);
508 [DllImport(wolfssl_dll)]
509 private static extern int wc_dilithium_delete(IntPtr key, IntPtr key_p);
510 [DllImport(wolfssl_dll)]
511 private static extern int wc_dilithium_set_level(IntPtr key, byte level);
512 [DllImport(wolfssl_dll)]
513 private static extern int wc_dilithium_make_key(IntPtr key, IntPtr rng);
514 [DllImport(wolfssl_dll)]
515 private static extern int wc_dilithium_export_private(IntPtr key, byte[] output, ref uint outLen);
516 [DllImport(wolfssl_dll)]
517 private static extern int wc_dilithium_import_private(byte[] priv, uint privSz, IntPtr key);
518 [DllImport(wolfssl_dll)]
519 private static extern int wc_dilithium_export_public(IntPtr key, byte[] output, ref uint outLen);
520 [DllImport(wolfssl_dll)]
521 private static extern int wc_dilithium_import_public(byte[] input, uint inputLen, IntPtr key);
522 [DllImport(wolfssl_dll)]
523 private static extern int wc_dilithium_sign_ctx_msg(byte[] ctx, byte ctxLen, byte[] msg, uint msgLen, byte[] sig, ref uint sigLen, IntPtr key, IntPtr rng);
524 [DllImport(wolfssl_dll)]
525 private static extern int wc_dilithium_verify_ctx_msg(byte[] sig, uint sigLen, byte[] ctx, byte ctxLen, byte[] msg, uint msgLen, ref int res, IntPtr key);
526 [DllImport(wolfssl_dll)]
527 private static extern int wc_MlDsaKey_GetPrivLen(IntPtr key, ref int len);
528 [DllImport(wolfssl_dll)]
529 private static extern int wc_MlDsaKey_GetPubLen(IntPtr key, ref int len);
530 [DllImport(wolfssl_dll)]
531 private static extern int wc_MlDsaKey_GetSigLen(IntPtr key, ref int len);
532#else
533 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
534 private static extern IntPtr wc_dilithium_new(IntPtr heap, int devId);
535 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
536 private static extern int wc_dilithium_delete(IntPtr key, IntPtr key_p);
537 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
538 private static extern int wc_dilithium_set_level(IntPtr key, byte level);
539 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
540 private static extern int wc_dilithium_make_key(IntPtr key, IntPtr rng);
541 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
542 private static extern int wc_dilithium_export_private(IntPtr key, byte[] output, ref uint outLen);
543 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
544 private static extern int wc_dilithium_import_private(byte[] priv, uint privSz, IntPtr key);
545 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
546 private static extern int wc_dilithium_export_public(IntPtr key, byte[] output, ref uint outLen);
547 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
548 private static extern int wc_dilithium_import_public(byte[] input, uint inputLen, IntPtr key);
549 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
550 private static extern int wc_dilithium_sign_ctx_msg(byte[] ctx, byte ctxLen, byte[] msg, uint msgLen, byte[] sig, ref uint sigLen, IntPtr key, IntPtr rng);
551 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
552 private static extern int wc_dilithium_verify_ctx_msg(byte[] sig, uint sigLen, byte[] ctx, byte ctxLen, byte[] msg, uint msgLen, ref int res, IntPtr key);
553 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
554 private static extern int wc_MlDsaKey_GetPrivLen(IntPtr key, ref int len);
555 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
556 private static extern int wc_MlDsaKey_GetPubLen(IntPtr key, ref int len);
557 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
558 private static extern int wc_MlDsaKey_GetSigLen(IntPtr key, ref int len);
559#endif
560
561 /********************************
562 * AES-GCM
563 */
564#if WindowsCE
565 [DllImport(wolfssl_dll)]
566 private extern static IntPtr wc_AesNew(IntPtr heap, int devId, IntPtr result_code);
567 [DllImport(wolfssl_dll)]
568 private extern static int wc_AesDelete(IntPtr aes, IntPtr aes_p);
569 [DllImport(wolfssl_dll)]
570 private extern static int wc_AesFree(IntPtr aes);
571 [DllImport(wolfssl_dll)]
572 private extern static int wc_AesInit(IntPtr aes, IntPtr heap, int devId);
573 [DllImport(wolfssl_dll)]
574 private extern static int wc_AesGcmInit(IntPtr aes, IntPtr key, uint len, IntPtr iv, uint ivSz);
575 [DllImport(wolfssl_dll)]
576 private extern static int wc_AesGcmSetKey(IntPtr aes, IntPtr key, uint len);
577 [DllImport(wolfssl_dll)]
578 private extern static int wc_AesGcmEncrypt(IntPtr aes, IntPtr output, IntPtr input, uint sz, IntPtr iv, uint ivSz, IntPtr authTag, uint authTagSz, IntPtr authIn, uint authInSz);
579 [DllImport(wolfssl_dll)]
580 private extern static int wc_AesGcmDecrypt(IntPtr aes, IntPtr output, IntPtr input, uint sz, IntPtr iv, uint ivSz, IntPtr authTag, uint authTagSz, IntPtr authIn, uint authInSz);
581#else
582 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
583 private extern static IntPtr wc_AesNew(IntPtr heap, int devId, IntPtr result_code);
584 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
585 private extern static int wc_AesDelete(IntPtr aes, IntPtr aes_p);
586 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
587 private extern static int wc_AesFree(IntPtr aes);
588 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
589 private extern static int wc_AesInit(IntPtr aes, IntPtr heap, int devId);
590 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
591 private extern static int wc_AesGcmInit(IntPtr aes, IntPtr key, uint len, IntPtr iv, uint ivSz);
592 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
593 private extern static int wc_AesGcmSetKey(IntPtr aes, IntPtr key, uint len);
594 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
595 private extern static int wc_AesGcmEncrypt(IntPtr aes, IntPtr output, IntPtr input, uint sz, IntPtr iv, uint ivSz, IntPtr authTag, uint authTagSz, IntPtr authIn, uint authInSz);
596 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
597 private extern static int wc_AesGcmDecrypt(IntPtr aes, IntPtr output, IntPtr input, uint sz, IntPtr iv, uint ivSz, IntPtr authTag, uint authTagSz, IntPtr authIn, uint authInSz);
598#endif
599
600
601 /********************************
602 * HPKE
603 * Requires: HAVE_HPKE, HAVE_ECC (or HAVE_CURVE25519), HAVE_AESGCM
604 */
605#if WindowsCE
606 [DllImport(wolfssl_dll)]
607 private extern static int wc_HpkeInit(IntPtr hpke, int kem, int kdf, int aead, IntPtr heap);
608 [DllImport(wolfssl_dll)]
609 private extern static int wc_HpkeGenerateKeyPair(IntPtr hpke, ref IntPtr keypair, IntPtr rng);
610 [DllImport(wolfssl_dll)]
611 private extern static int wc_HpkeSerializePublicKey(IntPtr hpke, IntPtr key, byte[] outBuf, ref ushort outSz);
612 [DllImport(wolfssl_dll)]
613 private extern static int wc_HpkeDeserializePublicKey(IntPtr hpke, ref IntPtr key, byte[] inBuf, ushort inSz);
614 [DllImport(wolfssl_dll)]
615 private extern static void wc_HpkeFreeKey(IntPtr hpke, ushort kem, IntPtr keypair, IntPtr heap);
616 [DllImport(wolfssl_dll)]
617 private extern static int wc_HpkeSealBase(IntPtr hpke, IntPtr ephemeralKey, IntPtr receiverKey, byte[] info, uint infoSz, byte[] aad, uint aadSz, byte[] plaintext, uint ptSz, byte[] ciphertext);
618 [DllImport(wolfssl_dll)]
619 private extern static int wc_HpkeOpenBase(IntPtr hpke, IntPtr receiverKey, byte[] pubKey, ushort pubKeySz, byte[] info, uint infoSz, byte[] aad, uint aadSz, byte[] ciphertext, uint ctSz, byte[] plaintext);
620#else
621 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
622 private extern static int wc_HpkeInit(IntPtr hpke, int kem, int kdf, int aead, IntPtr heap);
623 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
624 private extern static int wc_HpkeGenerateKeyPair(IntPtr hpke, ref IntPtr keypair, IntPtr rng);
625 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
626 private extern static int wc_HpkeSerializePublicKey(IntPtr hpke, IntPtr key, byte[] outBuf, ref ushort outSz);
627 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
628 private extern static int wc_HpkeDeserializePublicKey(IntPtr hpke, ref IntPtr key, byte[] inBuf, ushort inSz);
629 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
630 private extern static void wc_HpkeFreeKey(IntPtr hpke, ushort kem, IntPtr keypair, IntPtr heap);
631 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
632 private extern static int wc_HpkeSealBase(IntPtr hpke, IntPtr ephemeralKey, IntPtr receiverKey, byte[] info, uint infoSz, byte[] aad, uint aadSz, byte[] plaintext, uint ptSz, byte[] ciphertext);
633 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
634 private extern static int wc_HpkeOpenBase(IntPtr hpke, IntPtr receiverKey, byte[] pubKey, ushort pubKeySz, byte[] info, uint infoSz, byte[] aad, uint aadSz, byte[] ciphertext, uint ctSz, byte[] plaintext);
635#endif
636
637
638 /********************************
639 * HASH
640 */
641#if WindowsCE
642 [DllImport(wolfssl_dll)]
643 private extern static IntPtr wc_HashNew(uint hashType, IntPtr heap, int devId, IntPtr result_code);
644 [DllImport(wolfssl_dll)]
645 private extern static int wc_HashDelete(IntPtr hash, IntPtr hash_p);
646 [DllImport(wolfssl_dll)]
647 private extern static int wc_HashInit(IntPtr hash, uint hashType);
648 [DllImport(wolfssl_dll)]
649 private extern static int wc_HashUpdate(IntPtr hash, uint hashType, IntPtr data, uint dataSz);
650 [DllImport(wolfssl_dll)]
651 private extern static int wc_HashFinal(IntPtr hash, uint hashType, IntPtr output);
652 [DllImport(wolfssl_dll)]
653 private extern static int wc_HashFree(IntPtr hash, uint hashType);
654 [DllImport(wolfssl_dll)]
655 private extern static int wc_HashGetDigestSize(uint hashType);
656#else
657 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
658 private extern static IntPtr wc_HashNew(uint hashType, IntPtr heap, int devId, IntPtr result_code);
659 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
660 private extern static int wc_HashDelete(IntPtr hash, IntPtr hash_p);
661 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
662 private extern static int wc_HashInit(IntPtr hash, uint hashType);
663 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
664 private extern static int wc_HashUpdate(IntPtr hash, uint hashType, IntPtr data, uint dataSz);
665 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
666 private extern static int wc_HashFinal(IntPtr hash, uint hashType, IntPtr output);
667 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
668 private extern static int wc_HashFree(IntPtr hash, uint hashType);
669 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
670 private extern static int wc_HashGetDigestSize(uint hashType);
671#endif
672
673
674 /********************************
675 * Logging
676 */
677#if WindowsCE
678 [DllImport(wolfssl_dll)]
679 private extern static IntPtr wc_GetErrorString(int error);
680 public delegate void loggingCb(int lvl, string msg);
681#else
682 [DllImport(wolfssl_dll, CallingConvention = CallingConvention.Cdecl)]
683 private extern static IntPtr wc_GetErrorString(int error);
684 public delegate void loggingCb(int lvl, StringBuilder msg);
685#endif
686 private static loggingCb internal_log;
687
688 /// <summary>
689 /// Log a message to set logging function
690 /// </summary>
691 /// <param name="lvl">Level of log message</param>
692 /// <param name="msg">Message to log</param>
693#if WindowsCE
694 private static void log(int lvl, string msg)
695 {
696 /* if log is not set then print nothing */
697 if (internal_log == null)
698 return;
699 internal_log(lvl, msg);
700 }
701#else
702 private static void log(int lvl, string msg)
703 {
704 /* if log is not set then print nothing */
705 if (internal_log == null)
706 return;
707 StringBuilder ptr = new StringBuilder(msg);
708 internal_log(lvl, ptr);
709 }
710#endif
711
712
713 /********************************
714 * Enum types from wolfSSL library
715 */
716 /* Logging levels */
717 public static readonly int ERROR_LOG = 0;
718 public static readonly int INFO_LOG = 1;
719 public static readonly int ENTER_LOG = 2;
720 public static readonly int LEAVE_LOG = 3;
721 public static readonly int OTHER_LOG = 4;
722 public static readonly int INVALID_DEVID = -2;
723 public static readonly int ECC_MAX_SIG_SIZE = 141; /* ECC max sig size */
724 public static readonly int ECC_KEY_SIZE = 32; /* ECC key size */
725 public static readonly int MAX_ECIES_TEST_SZ = 200; /* ECIES max sig size */
726 public static readonly int ED25519_SIG_SIZE = 64; /* ED25519 pub + priv */
727 public static readonly int ED25519_KEY_SIZE = 32; /* Private key only */
728 public static readonly int ED25519_PUB_KEY_SIZE = 32; /* Compressed public */
729 public static readonly int AES_128_KEY_SIZE = 16; /* for 128 bit */
730 public static readonly int AES_192_KEY_SIZE = 24; /* for 192 bit */
731 public static readonly int AES_256_KEY_SIZE = 32; /* for 256 bit */
732 public static readonly int AES_BLOCK_SIZE = 16;
733
734 /* Error codes */
735 public static readonly int SUCCESS = 0;
736 public static readonly int EXCEPTION_E = -1;
737 public static readonly int MEMORY_E = -125; /* Out of memory error */
738 public static readonly int BUFFER_E = -131; /* RSA buffer error, output too small/large */
739 public static readonly int ASN_PARSE_E = -140; /* ASN parsing error, invalid input */
740 public static readonly int ASN_VERSION_E = -141; /* ASN version error, invalid number */
741 public static readonly int ASN_GETINT_E = -142; /* ASN get big int error, invalid data */
742 public static readonly int ASN_RSA_KEY_E = -143; /* ASN key init error, invalid input */
743 public static readonly int ASN_OBJECT_ID_E = -144; /* ASN object id error, invalid id */
744 public static readonly int ASN_TAG_NULL_E = -145; /* ASN tag error, not null */
745 public static readonly int ASN_EXPECT_0_E = -146; /* ASN expect error, not zero */
746 public static readonly int ASN_BITSTR_E = -147; /* ASN bit string error, wrong id */
747 public static readonly int ASN_UNKNOWN_OID_E = -148; /* ASN oid error, unknown sum id */
748 public static readonly int ASN_DATE_SZ_E = -149; /* ASN date error, bad size */
749 public static readonly int ASN_BEFORE_DATE_E = -150; /* ASN date error, current date before */
750 public static readonly int ASN_AFTER_DATE_E = -151; /* ASN date error, current date after */
751 public static readonly int ASN_SIG_OID_E = -152; /* ASN signature error, mismatched oid */
752 public static readonly int ASN_TIME_E = -153; /* ASN time error, unknown time type */
753 public static readonly int ASN_INPUT_E = -154; /* ASN input error, not enough data */
754 public static readonly int ASN_SIG_CONFIRM_E = -155; /* ASN sig error, confirm failure */
755 public static readonly int ASN_SIG_HASH_E = -156; /* ASN sig error, unsupported hash type */
756 public static readonly int ASN_SIG_KEY_E = -157; /* ASN sig error, unsupported key type */
757 public static readonly int BAD_FUNC_ARG = -173; /* Bad function argument */
758 public static readonly int SIG_VERIFY_E = -229; /* wolfcrypt signature verify error */
759
760
761 /***********************************************************************
762 * Class Public Functions
763 **********************************************************************/
764
765 /// <summary>
766 /// Initialize wolfCrypt library
767 /// </summary>
768 /// <returns>0 on success</returns>
769 public static int Init()
770 {
771 int ret;
772 try
773 {
774 ret = wolfCrypt_Init();
775 }
776 catch (Exception e)
777 {
778 log(ERROR_LOG, "wolfCrypt init error " + e.ToString());
779 ret = EXCEPTION_E;
780 }
781 return ret;
782 }
783
784 /// <summary>
785 /// Clean up wolfCrypt library memory
786 /// </summary>
787 /// <returns>0 on success</returns>
788 public static int Cleanup()
789 {
790 int ret;
791 try
792 {
793 ret = wolfCrypt_Cleanup();
794 }
795 catch (Exception e)
796 {
797 log(ERROR_LOG, "wolfCrypt cleanup error " + e.ToString());
798 ret = EXCEPTION_E;
799 }
800 return ret;
801 }
802
803
804 /***********************************************************************
805 * Random
806 **********************************************************************/
807
808 /// <summary>
809 /// Create new WC_RNG context
810 /// </summary>
811 /// <returns>Pointer to allocated WC_RNG or null</returns>
812 public static IntPtr RandomNew()
813 {
814 IntPtr rng;
815
816 try
817 {
818 /* Allocate and init new WC_RNG structure */
819 rng = wc_rng_new(
820 IntPtr.Zero, 0, /* Nonce (optional / used by FIPS only) */
821 IntPtr.Zero); /* Heap hint for static memory only */
822 }
823 catch (Exception e)
824 {
825 log(ERROR_LOG, "random new exception " + e.ToString());
826 rng = IntPtr.Zero;
827 }
828
829 return rng;
830 }
831
832 /// <summary>
833 /// Free WC_RNG context
834 /// </summary>
835 /// <param name="rng">Pointer to allocated WC_RNG</param>
836 public static void RandomFree(IntPtr rng)
837 {
838 if (rng != IntPtr.Zero)
839 {
840 /* Free WC_RNG structure */
841 wc_rng_free(rng);
842 }
843 }
844
845 /// <summary>
846 /// Generate random data (use existing WC_RNG context)
847 /// </summary>
848 /// <param name="rng">WC_RNG created from RandomNew()</param>
849 /// <param name="buf">buffer to populate random data</param>
850 /// <param name="sz">size of buffer</param>
851 /// <returns>0=success or negative for error</returns>
852 public static int Random(IntPtr rng, byte[] buf, int sz)
853 {
854 int ret;
855 IntPtr data;
856
857 try
858 {
859 /* Allocate global buffer for wolfAPI random */
860 data = Marshal.AllocHGlobal(sz);
861 if (data != IntPtr.Zero)
862 {
863 /* Generate random block */
864 ret = wc_RNG_GenerateBlock(rng, data, Convert.ToUInt32(sz));
865 if (ret == 0)
866 {
867 /* copy returned data */
868 Marshal.Copy(data, buf, 0, sz);
869 }
870 else
871 {
872 log(ERROR_LOG, "random generate block error " + ret + ": " + GetError(ret));
873 }
874 Marshal.FreeHGlobal(data);
875 }
876 else
877 {
878 ret = MEMORY_E;
879 }
880 }
881 catch (Exception e)
882 {
883 log(ERROR_LOG, "random generate block exception " + e.ToString());
884 ret = EXCEPTION_E;
885 }
886
887 return ret;
888 }
889
890 /// <summary>
891 /// Generate random data (single shot)
892 /// </summary>
893 /// <param name="buf">buffer to populate random data</param>
894 /// <param name="sz">size of buffer</param>
895 /// <returns>0=success or negative for error</returns>
896 public static int Random(byte[] buf, int sz)
897 {
898 int ret;
899 IntPtr rng = RandomNew();
900 if (rng == IntPtr.Zero)
901 {
902 return MEMORY_E;
903 }
904 ret = Random(rng, buf, sz);
905 RandomFree(rng);
906 return ret;
907 }
908 /* END Random */
909
910
911 /***********************************************************************
912 * ECC
913 **********************************************************************/
914
915 /// <summary>
916 /// Generate a new ECC private / public key pair
917 /// </summary>
918 /// <param name="keysize">Key size in bytes (example: SECP256R1 = 32)</param>
919 /// <returns>Allocated ECC key structure or null</returns>
920 public static IntPtr EccMakeKey(int keysize, IntPtr rng)
921 {
922 int ret;
923 IntPtr key = IntPtr.Zero;
924
925 try
926 {
927 /* Allocate and init new WC_RNG structure */
928 key = wc_ecc_key_new(IntPtr.Zero);
929 if (key != IntPtr.Zero)
930 {
931 ret = wc_ecc_make_key_ex(rng, keysize, key, 0); /* 0=use default curve */
932 if (ret != 0)
933 {
934 EccFreeKey(key);
935 key = IntPtr.Zero;
936 }
937 }
938 }
939 catch (Exception e)
940 {
941 log(ERROR_LOG, "ECC make key exception " + e.ToString());
942
943 EccFreeKey(key);
944 key = IntPtr.Zero;
945 }
946
947 return key;
948 }
949
950 /// <summary>
951 /// Sets the ECC rng structure
952 /// </summary>
953 /// <param name="key">Supplied key as a pointer</param>
954 /// <param name="rng">rng context as a pointer</param>
955 /// <returns>Returns 0 on success</returns>
956 public static int EccSetRng(IntPtr key, IntPtr rng)
957 {
958 int ret = 0;
959
960 try
961 {
962 /* Check */
963 if (key == IntPtr.Zero)
964 {
965 log(ERROR_LOG, "Invalid key or rng pointer.");
966 return MEMORY_E;
967 }
968
969 /* Set ECC rng */
970 ret = wc_ecc_set_rng(key, rng);
971 if (ret != 0)
972 {
973 log(ERROR_LOG, "ECC set rng failed returned:" + ret);
974 }
975 }
976 catch (Exception e)
977 {
978 log(ERROR_LOG, "ECC set rng exception " + e.ToString());
979 }
980
981 return ret;
982 }
983
984 /// <summary>
985 /// Generate a new ECC private / public key pair
986 /// </summary>
987 /// <param name="keyASN1">ASN.1 private key buffer (see ecc_clikey_der_256)</param>
988 /// <returns>Allocated ECC key structure or null</returns>
989 public static IntPtr EccImportKey(byte[] keyASN1)
990 {
991 int ret;
992 IntPtr key = IntPtr.Zero;
993
994 try
995 {
996 key = wc_ecc_key_new(IntPtr.Zero);
997 if (key != IntPtr.Zero)
998 {
999 IntPtr idx = Marshal.AllocHGlobal(sizeof(uint));
1000 IntPtr keydata = Marshal.AllocHGlobal(keyASN1.Length);
1001 Marshal.WriteInt32(idx, 0);
1002 Marshal.Copy(keyASN1, 0, keydata, keyASN1.Length);
1003 ret = wc_EccPrivateKeyDecode(keydata, idx, key, Convert.ToUInt32(keyASN1.Length));
1004 if (ret != 0)
1005 {
1006 EccFreeKey(key);
1007 key = IntPtr.Zero;
1008 }
1009 Marshal.FreeHGlobal(idx); /* not used */
1010 Marshal.FreeHGlobal(keydata);
1011 }
1012 }
1013 catch (Exception e)
1014 {
1015 log(ERROR_LOG, "ECC import key exception " + e.ToString());
1016 EccFreeKey(key); /* make sure its free'd */
1017 key = IntPtr.Zero;
1018 }
1019
1020 return key;
1021 }
1022
1023 /// <summary>
1024 /// Sign a hash using ECC
1025 /// </summary>
1026 /// <param name="key">ECC key structure</param>
1027 /// <param name="hash">Hash to sign</param>
1028 /// <param name="signature">Buffer to receive the signature</param>
1029 /// <returns>Length of the signature on success, otherwise a negative error code</returns>
1030 public static int EccSign(IntPtr key, byte[] hash, byte[] signature)
1031 {
1032 int ret;
1033 int signedLength = 0;
1034 IntPtr hashPtr = IntPtr.Zero;
1035 IntPtr sigPtr = IntPtr.Zero;
1036 IntPtr sigLen = IntPtr.Zero;
1037 IntPtr rng = IntPtr.Zero;
1038
1039 try
1040 {
1041 rng = RandomNew();
1042 hashPtr = Marshal.AllocHGlobal(hash.Length);
1043 sigPtr = Marshal.AllocHGlobal(signature.Length);
1044 sigLen = Marshal.AllocHGlobal(sizeof(uint));
1045
1046 Marshal.WriteInt32(sigLen, signature.Length);
1047 Marshal.Copy(hash, 0, hashPtr, hash.Length);
1048 ret = wc_ecc_sign_hash(hashPtr, Convert.ToUInt32(hash.Length), sigPtr, sigLen, rng, key);
1049
1050 /* Output actual signature length */
1051 if (ret == 0)
1052 {
1053 signedLength = Marshal.ReadInt32(sigLen);
1054 if (signedLength <= signature.Length)
1055 {
1056 Marshal.Copy(sigPtr, signature, 0, signedLength);
1057 }
1058 else
1059 {
1060 ret = BUFFER_E;
1061 }
1062 }
1063 }
1064 catch (Exception e)
1065 {
1066 log(ERROR_LOG, "ECC sign exception: " + e.ToString());
1067 ret = EXCEPTION_E;
1068 }
1069 finally
1070 {
1071 if (hashPtr != IntPtr.Zero) Marshal.FreeHGlobal(hashPtr);
1072 if (sigPtr != IntPtr.Zero) Marshal.FreeHGlobal(sigPtr);
1073 if (sigLen != IntPtr.Zero) Marshal.FreeHGlobal(sigLen);
1074 if (rng != IntPtr.Zero) RandomFree(rng);
1075 }
1076
1077 return ret == 0 ? signedLength : ret;
1078 }
1079
1080 /// <summary>
1081 /// Verify a signature using ECC
1082 /// </summary>
1083 /// <param name="key">ECC key structure</param>
1084 /// <param name="signature">Signature to verify</param>
1085 /// <param name="hash">Expected hash value</param>
1086 /// <returns>0 on success, otherwise an error code</returns>
1087 public static int EccVerify(IntPtr key, byte[] signature, byte[] hash)
1088 {
1089 int ret;
1090 IntPtr hashPtr = IntPtr.Zero;
1091 IntPtr sigPtr = IntPtr.Zero;
1092 IntPtr res = IntPtr.Zero;
1093
1094 try
1095 {
1096 hashPtr = Marshal.AllocHGlobal(hash.Length);
1097 sigPtr = Marshal.AllocHGlobal(signature.Length);
1098 res = Marshal.AllocHGlobal(sizeof(int));
1099
1100 Marshal.Copy(hash, 0, hashPtr, hash.Length);
1101 Marshal.Copy(signature, 0, sigPtr, signature.Length);
1102
1103 ret = wc_ecc_verify_hash(sigPtr, Convert.ToUInt32(signature.Length), hashPtr, Convert.ToUInt32(hash.Length), res, key);
1104
1105 if (ret == 0)
1106 {
1107 int verifyResult = Marshal.ReadInt32(res);
1108 ret = verifyResult == 1 ? 0 : EXCEPTION_E;
1109 }
1110 }
1111 catch (Exception e)
1112 {
1113 log(ERROR_LOG, "ECC verify exception " + e.ToString());
1114 ret = EXCEPTION_E;
1115 }
1116 finally
1117 {
1118 if (hashPtr != IntPtr.Zero) Marshal.FreeHGlobal(hashPtr);
1119 if (sigPtr != IntPtr.Zero) Marshal.FreeHGlobal(sigPtr);
1120 if (res != IntPtr.Zero) Marshal.FreeHGlobal(res);
1121 }
1122
1123 return ret;
1124 }
1125
1126 /// <summary>
1127 /// Export ECC Private Key to DER format
1128 /// </summary>
1129 /// <param name="key">ECC key structure</param>
1130 /// <returns>DER-encoded private key as byte array</returns>
1131 public static int EccExportPrivateKeyToDer(IntPtr key, out byte[] derKey)
1132 {
1133 int ret;
1134 derKey = null;
1135
1136 try
1137 {
1138 int bufferSize = wc_EccPrivateKeyToDer(key, null, 0);
1139 if (bufferSize < 0) {
1140 log(ERROR_LOG, "ECC private key get size failed " + bufferSize.ToString());
1141 return bufferSize;
1142 }
1143 derKey = new byte[bufferSize];
1144 ret = wc_EccPrivateKeyToDer(key, derKey, (uint)bufferSize);
1145 if (ret < 0)
1146 {
1147 log(ERROR_LOG, "ECC private key to der failed " + ret.ToString());
1148 }
1149 }
1150 catch (Exception e)
1151 {
1152 log(ERROR_LOG, "ECC export private exception " + e.ToString());
1153 ret = EXCEPTION_E;
1154 }
1155
1156 return ret;
1157 }
1158
1159 /// <summary>
1160 /// Export ECC Public Key to DER format
1161 /// </summary>
1162 /// <param name="key">ECC key structure</param>
1163 /// <param name="includeCurve">Include algorithm curve in the output</param>
1164 /// <returns>DER-encoded public key as byte array</returns>
1165 public static int EccExportPublicKeyToDer(IntPtr key, out byte[] derKey, bool includeCurve)
1166 {
1167 int ret;
1168 derKey = null;
1169
1170 try
1171 {
1172 int bufferSize = wc_EccPublicKeyToDer(key, null, 0, includeCurve ? 1 : 0);
1173 if (bufferSize < 0) {
1174 log(ERROR_LOG, "ECC public key get size failed " + bufferSize.ToString());
1175 return bufferSize;
1176 }
1177 derKey = new byte[bufferSize];
1178 ret = wc_EccPublicKeyToDer(key, derKey, (uint)bufferSize, includeCurve ? 1 : 0);
1179 if (ret < 0)
1180 {
1181 log(ERROR_LOG, "ECC public key to der failed " + ret.ToString());
1182 }
1183 }
1184 catch (Exception e)
1185 {
1186 log(ERROR_LOG, "ECC export public exception " + e.ToString());
1187 ret = EXCEPTION_E;
1188 }
1189
1190 return ret;
1191 }
1192
1193 /// <summary>
1194 /// Import ECC Public Key from DER format
1195 /// </summary>
1196 /// <param name="keyDer">DER-encoded public key</param>
1197 /// <returns>Allocated ECC key structure or null</returns>
1198 public static IntPtr EccImportPublicKeyFromDer(byte[] keyDer)
1199 {
1200 int ret;
1201 IntPtr key = IntPtr.Zero;
1202
1203 try
1204 {
1205 key = wc_ecc_key_new(IntPtr.Zero);
1206 if (key != IntPtr.Zero)
1207 {
1208 uint idx = 0;
1209 ret = wc_EccPublicKeyDecode(keyDer, ref idx, key, (uint)keyDer.Length);
1210 if (ret != 0)
1211 {
1212 EccFreeKey(key);
1213 key = IntPtr.Zero;
1214 }
1215 }
1216 }
1217 catch (Exception e)
1218 {
1219 log(ERROR_LOG, "ECC import public key exception " + e.ToString());
1220 EccFreeKey(key);
1221 key = IntPtr.Zero;
1222 }
1223
1224 return key;
1225 }
1226
1227 /// <summary>
1228 /// Free an ECC key structure
1229 /// </summary>
1230 /// <param name="key">ECC key structure allocated using EccMakeKey() or EccImportKey()</param>
1231 public static void EccFreeKey(IntPtr key)
1232 {
1233 if (key != IntPtr.Zero)
1234 {
1235 wc_ecc_key_free(key);
1236 }
1237 }
1238 /* END ECC */
1239
1240
1241 /***********************************************************************
1242 * ECIES
1243 **********************************************************************/
1244
1245 /// <summary>
1246 /// Create a new ECIES context with flags, RNG, and custom heap.
1247 /// </summary>
1248 /// <param name="flags">Flags for the context initialization.</param>
1249 /// <param name="rng">Random Number Generator (RNG) pointer.</param>
1250 /// <param name="heap">Custom heap pointer for memory allocations.</param>
1251 /// <returns>Pointer to the newly created ECIES context or IntPtr.Zero on failure.</returns>
1252 public static IntPtr EciesNewCtx(int flags, IntPtr rng, IntPtr heap)
1253 {
1254 IntPtr ctx = IntPtr.Zero;
1255 heap = IntPtr.Zero;
1256
1257 try
1258 {
1259 ctx = wc_ecc_ctx_new_ex(flags, rng, heap);
1260 if (ctx == IntPtr.Zero)
1261 {
1262 log(ERROR_LOG, "ECIES context creation with custom heap failed: returned IntPtr.Zero");
1263 }
1264 }
1265 catch (Exception e)
1266 {
1267 log(ERROR_LOG, "ECIES context creation with custom heap failed: " + e.ToString());
1268 return IntPtr.Zero;
1269 }
1270
1271 return ctx;
1272 }
1273
1274 /// <summary>
1275 /// Reset the ECIES context with a new RNG.
1276 /// </summary>
1277 /// <param name="ctx">Pointer to the ECIES context to reset.</param>
1278 /// <param name="rng">New RNG to set.</param>
1279 /// <returns>0 on success, or a negative error code on failure.</returns>
1280 public static int EciesCtxReset(IntPtr ctx, IntPtr rng)
1281 {
1282 int ret;
1283
1284 try
1285 {
1286 ret = wc_ecc_ctx_reset(ctx, rng);
1287 }
1288 catch (Exception e)
1289 {
1290 log(ERROR_LOG, "ECIES context reset exception: " + e.ToString());
1291 ret = EXCEPTION_E;
1292 }
1293
1294 return ret;
1295 }
1296
1297 /// <summary>
1298 /// Set encryption, KDF, and MAC algorithms for the ECIES context.
1299 /// </summary>
1300 /// <param name="ctx">Pointer to the ECIES context.</param>
1301 /// <param name="encAlgo">Encryption algorithm identifier.</param>
1302 /// <param name="kdfAlgo">Key Derivation Function (KDF) algorithm identifier.</param>
1303 /// <param name="macAlgo">MAC algorithm identifier.</param>
1304 /// <returns>0 on success, or a negative error code on failure.</returns>
1305 public static int EciesSetAlgo(IntPtr ctx, byte encAlgo, byte kdfAlgo, byte macAlgo)
1306 {
1307 int ret;
1308
1309 try
1310 {
1311 ret = wc_ecc_ctx_set_algo(ctx, encAlgo, kdfAlgo, macAlgo);
1312 }
1313 catch (Exception e)
1314 {
1315 log(ERROR_LOG, "ECIES set algorithm exception: " + e.ToString());
1316 ret = EXCEPTION_E;
1317 }
1318
1319 return ret;
1320 }
1321
1322 /// <summary>
1323 /// Get the ECIES own salt as a byte array.
1324 /// </summary>
1325 /// <param name="ctx">Pointer to the ECIES context.</param>
1326 /// <returns>Byte array representing the own salt, or null if there is an error.</returns>
1327 public static byte[] EciesGetOwnSalt(IntPtr ctx)
1328 {
1329 IntPtr saltPtr = IntPtr.Zero;
1330 byte[] salt = null;
1331
1332 try
1333 {
1334 /* Check ctx */
1335 if (ctx == IntPtr.Zero)
1336 {
1337 log(ERROR_LOG, "Invalid ECIES context pointer.");
1338 return null;
1339 }
1340
1341 /* Get own salt */
1342 saltPtr = wc_ecc_ctx_get_own_salt(ctx);
1343 if (saltPtr == IntPtr.Zero)
1344 {
1345 log(ERROR_LOG, "Failed to get own salt.");
1346 return null;
1347 }
1348
1349 /* Allocate salt size and copy to byte array */
1350 salt = new byte[(int)ecKeySize.EXCHANGE_SALT_SZ];
1351 Marshal.Copy(saltPtr, salt, 0, (int)ecKeySize.EXCHANGE_SALT_SZ);
1352 }
1353 catch (Exception e)
1354 {
1355 log(ERROR_LOG, "ECIES get own salt exception: " + e.ToString());
1356 return null;
1357 }
1358 finally
1359 {
1360 /* Cleanup */
1361 if (saltPtr != IntPtr.Zero) Marshal.FreeHGlobal(saltPtr);
1362 }
1363
1364 return salt;
1365 }
1366
1367 /// <summary>
1368 /// Set the peer salt for the ECIES context.
1369 /// </summary>
1370 /// <param name="ctx">Pointer to the ECIES context.</param>
1371 /// <param name="salt">Peer salt as a byte array.</param>
1372 /// <returns>0 on success, or a negative error code on failure.</returns>
1373 public static int EciesSetPeerSalt(IntPtr ctx, byte[] salt)
1374 {
1375 IntPtr saltPtr = IntPtr.Zero;
1376 int ret;
1377
1378 try
1379 {
1380 /* Allocate memory */
1381 saltPtr = Marshal.AllocHGlobal(salt.Length);
1382 Marshal.Copy(salt, 0, saltPtr, salt.Length);
1383
1384 /* Set the peer salt */
1385 ret = wc_ecc_ctx_set_peer_salt(ctx, saltPtr);
1386 }
1387 catch (Exception e)
1388 {
1389 log(ERROR_LOG, "ECIES set peer salt exception: " + e.ToString());
1390 ret = EXCEPTION_E;
1391 }
1392 finally
1393 {
1394 /* Cleanup */
1395 if (saltPtr != IntPtr.Zero) Marshal.FreeHGlobal(saltPtr);
1396 }
1397
1398 return ret;
1399 }
1400
1401 /// <summary>
1402 /// Set the own salt for the ECIES context.
1403 /// </summary>
1404 /// <param name="ctx">Pointer to the ECIES context.</param>
1405 /// <param name="salt">Own salt as a byte array.</param>
1406 /// <returns>0 on success, or a negative error code on failure.</returns>
1407 public static int EciesSetOwnSalt(IntPtr ctx, byte[] salt)
1408 {
1409 IntPtr saltPtr = IntPtr.Zero;
1410 uint saltSz;
1411 int ret;
1412
1413 try
1414 {
1415 /* Allocate memory */
1416 saltSz = (uint)salt.Length;
1417 saltPtr = Marshal.AllocHGlobal(salt.Length);
1418 Marshal.Copy(salt, 0, saltPtr, salt.Length);
1419
1420 /* Set the own salt */
1421 ret = wc_ecc_ctx_set_own_salt(ctx, saltPtr, saltSz);
1422 }
1423 catch (Exception e)
1424 {
1425 log(ERROR_LOG, "ECIES set own salt exception: " + e.ToString());
1426 ret = EXCEPTION_E;
1427 }
1428 finally
1429 {
1430 /* Cleanup */
1431 if (saltPtr != IntPtr.Zero) Marshal.FreeHGlobal(saltPtr);
1432 }
1433
1434 return ret;
1435 }
1436
1437 /// <summary>
1438 /// Set the KDF salt for the ECIES context.
1439 /// </summary>
1440 /// <param name="ctx">Pointer to the ECIES context.</param>
1441 /// <param name="salt">KDF salt as a byte array.</param>
1442 /// <returns>0 on success, or a negative error code on failure.</returns>
1443 public static int EciesSetKdfSalt(IntPtr ctx, byte[] salt)
1444 {
1445 IntPtr saltPtr = IntPtr.Zero;
1446 uint saltSz;
1447 int ret;
1448
1449 try
1450 {
1451 /* Allocate memory */
1452 saltSz = (uint)salt.Length;
1453 saltPtr = Marshal.AllocHGlobal(salt.Length);
1454 Marshal.Copy(salt, 0, saltPtr, salt.Length);
1455
1456 /* Set the KDF salt */
1457 ret = wc_ecc_ctx_set_kdf_salt(ctx, saltPtr, saltSz);
1458 }
1459 catch (Exception e)
1460 {
1461 log(ERROR_LOG, "ECIES set KDF salt exception: " + e.ToString());
1462 ret = EXCEPTION_E;
1463 }
1464 finally
1465 {
1466 /* Cleanup */
1467 if (saltPtr != IntPtr.Zero) Marshal.FreeHGlobal(saltPtr);
1468 }
1469
1470 return ret;
1471 }
1472
1473 /// <summary>
1474 /// Set the info for the ECIES context.
1475 /// </summary>
1476 /// <param name="ctx">Pointer to the ECIES context.</param>
1477 /// <param name="info">Info as a byte array.</param>
1478 /// <returns>0 on success, or a negative error code on failure.</returns>
1479 public static int EciesSetInfo(IntPtr ctx, byte[] info)
1480 {
1481 IntPtr infoPtr = IntPtr.Zero;
1482 int ret;
1483
1484 try
1485 {
1486 /* Allocate memory */
1487 infoPtr = Marshal.AllocHGlobal(info.Length);
1488 Marshal.Copy(info, 0, infoPtr, info.Length);
1489
1490 /* Set the info */
1491 ret = wc_ecc_ctx_set_info(ctx, infoPtr, info.Length);
1492 }
1493 catch (Exception e)
1494 {
1495 log(ERROR_LOG, "ECIES set info exception: " + e.ToString());
1496 ret = EXCEPTION_E;
1497 }
1498 finally
1499 {
1500 /* Cleanup */
1501 if (infoPtr != IntPtr.Zero) Marshal.FreeHGlobal(infoPtr);
1502 }
1503
1504 return ret;
1505 }
1506
1507 /// <summary>
1508 /// Encrypt a message using ECIES.
1509 /// </summary>
1510 /// <param name="privKey">Private key.</param>
1511 /// <param name="pubKey">Public key.</param>
1512 /// <param name="msg">Message to encrypt.</param>
1513 /// <param name="msgSz">Message size.</param>
1514 /// <param name="outBuffer">Output buffer.</param>
1515 /// <param name="ctx">ECIES context.</param>
1516 /// <returns>0 on success, or a negative error code on failure.</returns>
1517 public static int EciesEncrypt(IntPtr privKey, IntPtr pubKey, byte[] msg, uint msgSz, byte[] outBuffer, IntPtr ctx)
1518 {
1519 int ret;
1520 int outBufferLength = 0;
1521 IntPtr msgPtr = IntPtr.Zero;
1522 IntPtr outBufferPtr = IntPtr.Zero;
1523 IntPtr outSz = IntPtr.Zero;
1524
1525 try
1526 {
1527 /* Allocate memory */
1528 msgPtr = Marshal.AllocHGlobal(msg.Length);
1529 outBufferPtr = Marshal.AllocHGlobal(outBuffer.Length);
1530 outSz = Marshal.AllocHGlobal(sizeof(uint));
1531
1532 Marshal.WriteInt32(outSz, outBuffer.Length);
1533 Marshal.Copy(msg, 0, msgPtr, msg.Length);
1534
1535 /* Encrypt */
1536 ret = wc_ecc_encrypt(privKey, pubKey, msgPtr, msgSz, outBufferPtr, outSz, ctx);
1537 if (ret < 0)
1538 {
1539 log(ERROR_LOG, "Failed to encrypt message using ECIES. Error code: " + ret);
1540 }
1541 /* Output actual output buffer length */
1542 if (ret == 0)
1543 {
1544 outBufferLength = Marshal.ReadInt32(outSz);
1545 if (outBufferLength <= outBuffer.Length)
1546 {
1547 Marshal.Copy(outBufferPtr, outBuffer, 0, outBufferLength);
1548 }
1549 else
1550 {
1551 ret = BUFFER_E;
1552 }
1553 }
1554 }
1555 catch (Exception e)
1556 {
1557 log(ERROR_LOG, "ECIES encryption exception: " + e.ToString());
1558 ret = EXCEPTION_E;
1559 }
1560 finally
1561 {
1562 /* Cleanup */
1563 if (msgPtr != IntPtr.Zero) Marshal.FreeHGlobal(msgPtr);
1564 if (outBufferPtr != IntPtr.Zero) Marshal.FreeHGlobal(outBufferPtr);
1565 if (outSz != IntPtr.Zero) Marshal.FreeHGlobal(outSz);
1566 }
1567
1568 return ret == 0 ? outBufferLength : ret;
1569 }
1570
1571 /// <summary>
1572 /// Decrypt a message using ECIES.
1573 /// </summary>
1574 /// <param name="privKey">Private key.</param>
1575 /// <param name="pubKey">Public key.</param>
1576 /// <param name="msg">Encrypted message.</param>
1577 /// <param name="msgSz">Message size.</param>
1578 /// <param name="outBuffer">Output buffer for the decrypted message.</param>
1579 /// <param name="ctx">ECIES context.</param>
1580 /// <returns>0 on success, or a negative error code on failure.</returns>
1581 public static int EciesDecrypt(IntPtr privKey, IntPtr pubKey, byte[] msg, uint msgSz, byte[] outBuffer, IntPtr ctx)
1582 {
1583 int ret;
1584 int outBufferLength = 0;
1585 IntPtr msgPtr = IntPtr.Zero;
1586 IntPtr outBufferPtr = IntPtr.Zero;
1587 IntPtr outSz = IntPtr.Zero;
1588
1589 try
1590 {
1591 /* Allocate memory */
1592 msgPtr = Marshal.AllocHGlobal(msg.Length);
1593 outBufferPtr = Marshal.AllocHGlobal(outBuffer.Length);
1594 outSz = Marshal.AllocHGlobal(sizeof(uint));
1595
1596 Marshal.WriteInt32(outSz, outBuffer.Length);
1597 Marshal.Copy(msg, 0, msgPtr, msg.Length);
1598
1599 /* Decrypt */
1600 ret = wc_ecc_decrypt(privKey, pubKey, msgPtr, msgSz, outBufferPtr, outSz, ctx);
1601 if (ret < 0)
1602 {
1603 log(ERROR_LOG, "Failed to decrypt message using ECIES. Error code: " + ret);
1604 }
1605 /* Output actual output buffer length */
1606 if (ret == 0)
1607 {
1608 outBufferLength = Marshal.ReadInt32(outSz);
1609 if (outBufferLength <= outBuffer.Length)
1610 {
1611 Marshal.Copy(outBufferPtr, outBuffer, 0, outBufferLength);
1612 }
1613 else
1614 {
1615 ret = BUFFER_E;
1616 }
1617 }
1618 }
1619 catch (Exception e)
1620 {
1621 log(ERROR_LOG, "ECIES decryption exception: " + e.ToString());
1622 return EXCEPTION_E;
1623 }
1624 finally
1625 {
1626 /* Cleanup */
1627 if (msgPtr != IntPtr.Zero) Marshal.FreeHGlobal(msgPtr);
1628 if (outBufferPtr != IntPtr.Zero) Marshal.FreeHGlobal(outBufferPtr);
1629 if (outSz != IntPtr.Zero) Marshal.FreeHGlobal(outSz);
1630 }
1631
1632 return ret == 0 ? outBufferLength : ret;
1633 }
1634
1635 /// <summary>
1636 /// Free the ECIES context.
1637 /// </summary>
1638 /// <param name="ctx">Pointer to the ECIES context to free.</param>
1639 public static void EciesFreeCtx(IntPtr ctx)
1640 {
1641 if (ctx != IntPtr.Zero)
1642 {
1643 wc_ecc_ctx_free(ctx);
1644 }
1645 }
1646
1647 /********************************
1648 * ENUMS
1649 */
1650 public enum ecEncAlgo {
1651 ecAES_128_CBC = 1, /* default */
1652 ecAES_256_CBC = 2,
1653 ecAES_128_CTR = 3,
1654 ecAES_256_CTR = 4
1655 }
1656
1657 public enum ecKdfAlgo {
1658 ecHKDF_SHA256 = 1, /* default */
1659 ecHKDF_SHA1 = 2,
1660 ecKDF_X963_SHA1 = 3,
1661 ecKDF_X963_SHA256 = 4,
1662 ecKDF_SHA1 = 5,
1663 ecKDF_SHA256 = 6
1664 }
1665
1666 public enum ecMacAlgo {
1667 ecHMAC_SHA256 = 1, /* default */
1668 ecHMAC_SHA1 = 2
1669 }
1670
1671 public enum ecKeySize {
1672 KEY_SIZE_128 = 16,
1673 KEY_SIZE_256 = 32,
1674 IV_SIZE_64 = 8,
1675 IV_SIZE_128 = 16,
1676 ECC_MAX_IV_SIZE = 16,
1677 EXCHANGE_SALT_SZ = 16,
1678 EXCHANGE_INFO_SZ = 23
1679 }
1680
1681 public enum ecFlags {
1682 REQ_RESP_CLIENT = 1,
1683 REQ_RESP_SERVER = 2
1684 }
1685 /* END ECIES */
1686
1687
1688 /***********************************************************************
1689 * ECDHE
1690 **********************************************************************/
1691
1692 /// <summary>
1693 /// Generate a shared secret using ECC
1694 /// </summary>
1695 /// <param name="privateKey">ECC private key</param>
1696 /// <param name="publicKey">ECC public key</param>
1697 /// <param name="secret">Buffer to receive the shared secret</param>
1698 /// <returns>0 on success, otherwise an error code</returns>
1699 public static int EcdheSharedSecret(IntPtr privateKey, IntPtr publicKey, byte[] secret, IntPtr rng)
1700 {
1701 int ret;
1702 int secretLength = secret.Length;
1703
1704 try
1705 {
1706 /* set RNG for Public Key */
1707 ret = EccSetRng(privateKey, rng);
1708 if (ret != 0)
1709 {
1710 throw new Exception("Failed to set Public Key RNG Error code: " + ret);
1711 }
1712
1713 /* set RNG for Private Key */
1714 ret = EccSetRng(publicKey, rng);
1715 if (ret != 0)
1716 {
1717 throw new Exception("Failed to set Private Key RNG. Error code: " + ret);
1718 }
1719
1720 /* Generate shared secret */
1721 if (privateKey != IntPtr.Zero || publicKey != IntPtr.Zero)
1722 {
1723 ret = wc_ecc_shared_secret(privateKey, publicKey, secret, ref secretLength);
1724 if (ret != 0)
1725 {
1726 throw new Exception("Failed to compute ECC shared secret. Error code: " + ret);
1727 }
1728 }
1729 }
1730 catch (Exception e)
1731 {
1732 log(ERROR_LOG, "ECC shared secret exception " + e.ToString());
1733 ret = EXCEPTION_E;
1734 }
1735
1736 return ret;
1737 }
1738 /* END ECDHE */
1739
1740
1741 /***********************************************************************
1742 * RSA
1743 **********************************************************************/
1744
1745 /// <summary>
1746 /// Generate a new RSA private/public key pair
1747 /// </summary>
1748 /// <param name="heap">Pointer to the heap for memory allocation
1749 /// (use IntPtr.Zero if not applicable)</param>
1750 /// <param name="devId">Device ID (if applicable, otherwise use 0)</param>
1751 /// <param name="keysize">Key size in bits (example: 2048)</param>
1752 /// <param name="exponent">Exponent for RSA key generation (default is 65537)</param>
1753 /// <returns>Allocated RSA key structure or null on failure</returns>
1754 public static IntPtr RsaMakeKey(IntPtr heap, int devId, int keysize, Int32 exponent)
1755 {
1756 int ret;
1757 IntPtr key = IntPtr.Zero;
1758 IntPtr rng = IntPtr.Zero;
1759
1760 try
1761 {
1762 /* Allocate and init new RSA key structure */
1763 key = wc_NewRsaKey(heap, devId, IntPtr.Zero);
1764 if (key != IntPtr.Zero)
1765 {
1766 rng = RandomNew();
1767 if (rng == IntPtr.Zero)
1768 {
1769 throw new Exception("Failed to create rng.");
1770 }
1771
1772 ret = wc_MakeRsaKey(key, keysize, exponent, rng);
1773 if (ret != 0)
1774 {
1775 RsaFreeKey(key);
1776 key = IntPtr.Zero;
1777 }
1778
1779 RandomFree(rng);
1780 rng = IntPtr.Zero;
1781 }
1782 }
1783 catch (Exception e)
1784 {
1785 log(ERROR_LOG, "RSA make key exception " + e.ToString());
1786 if (rng != IntPtr.Zero) RandomFree(rng);
1787 if (key != IntPtr.Zero) RsaFreeKey(key);
1788 key = IntPtr.Zero;
1789 }
1790
1791 return key;
1792 }
1793
1794 public static IntPtr RsaMakeKey(IntPtr heap, int devId, int keysize)
1795 {
1796 return RsaMakeKey(heap, devId, keysize, 65537);
1797 }
1798
1799 /// <summary>
1800 /// Import an RSA private key from ASN.1 buffer
1801 /// </summary>
1802 /// <param name="keyASN1">ASN.1 private key buffer</param>
1803 /// <returns>Allocated RSA key structure or null</returns>
1804 public static IntPtr RsaImportKey(byte[] keyASN1)
1805 {
1806 int ret;
1807 IntPtr key = IntPtr.Zero;
1808
1809 try
1810 {
1811 key = wc_NewRsaKey(IntPtr.Zero, INVALID_DEVID, IntPtr.Zero);
1812 if (key != IntPtr.Zero)
1813 {
1814 IntPtr idx = Marshal.AllocHGlobal(sizeof(uint));
1815 IntPtr keydata = Marshal.AllocHGlobal(keyASN1.Length);
1816 Marshal.WriteInt32(idx, 0);
1817 Marshal.Copy(keyASN1, 0, keydata, keyASN1.Length);
1818 ret = wc_RsaPrivateKeyDecode(keydata, idx, key, Convert.ToUInt32(keyASN1.Length));
1819 if (ret != 0)
1820 {
1821 RsaFreeKey(key);
1822 key = IntPtr.Zero;
1823 }
1824 Marshal.FreeHGlobal(idx); /* not used */
1825 Marshal.FreeHGlobal(keydata);
1826 }
1827 }
1828 catch (Exception e)
1829 {
1830 log(ERROR_LOG, "RSA make key exception " + e.ToString());
1831 RsaFreeKey(key); /* make sure its free'd */
1832 key = IntPtr.Zero;
1833 }
1834
1835 return key;
1836 }
1837
1838 /// <summary>
1839 /// Sign a hash using RSA and SSL-style padding
1840 /// </summary>
1841 /// <param name="key">RSA key structure</param>
1842 /// <param name="hash">Hash to sign</param>
1843 /// <param name="signature">Buffer to receive the signature</param>
1844 /// <returns>Length of the signature on success, otherwise an error code</returns>
1845 public static int RsaSignSSL(IntPtr key, byte[] hash, byte[] signature)
1846 {
1847 IntPtr hashPtr = Marshal.AllocHGlobal(hash.Length);
1848 IntPtr sigPtr = Marshal.AllocHGlobal(signature.Length);
1849 IntPtr rng = IntPtr.Zero;
1850 int ret;
1851
1852 try
1853 {
1854 rng = RandomNew();
1855 if (rng == IntPtr.Zero)
1856 {
1857 throw new Exception("Failed to create RNG.");
1858 }
1859
1860 Marshal.Copy(hash, 0, hashPtr, hash.Length);
1861
1862 ret = wc_RsaSSL_Sign(hashPtr, hash.Length, sigPtr, signature.Length, key, rng);
1863 if (ret >= 0) /* `wc_RsaSSL_Sign` returns the signature length on success */
1864 {
1865 Marshal.Copy(sigPtr, signature, 0, ret);
1866 }
1867 }
1868 finally
1869 {
1870 if (hashPtr != IntPtr.Zero) Marshal.FreeHGlobal(hashPtr);
1871 if (sigPtr != IntPtr.Zero) Marshal.FreeHGlobal(sigPtr);
1872 if (rng != IntPtr.Zero) RandomFree(rng);
1873 }
1874
1875 return ret;
1876 }
1877
1878 /// <summary>
1879 /// Verify a signature using RSA and SSL-style padding
1880 /// </summary>
1881 /// <param name="key">RSA key structure</param>
1882 /// <param name="signature">Signature to verify</param>
1883 /// <param name="hash">Expected hash value</param>
1884 /// <returns>0 on success, otherwise an error code</returns>
1885 public static int RsaVerifySSL(IntPtr key, byte[] signature, byte[] hash)
1886 {
1887 IntPtr hashPtr = IntPtr.Zero;
1888 IntPtr sigPtr = IntPtr.Zero;
1889 int ret;
1890
1891 try
1892 {
1893 hashPtr = Marshal.AllocHGlobal(hash.Length);
1894 sigPtr = Marshal.AllocHGlobal(signature.Length);
1895
1896 Marshal.Copy(signature, 0, sigPtr, signature.Length);
1897
1898 ret = wc_RsaSSL_Verify(sigPtr, signature.Length, hashPtr, hash.Length, key);
1899
1900 if (ret == hash.Length)
1901 {
1902 byte[] verifiedHash = new byte[hash.Length];
1903 Marshal.Copy(hashPtr, verifiedHash, 0, hash.Length);
1904
1905 if (ByteArrayVerify(verifiedHash, hash))
1906 {
1907 ret = 0;
1908 }
1909 else
1910 {
1911 ret = SIG_VERIFY_E;
1912 }
1913 }
1914 }
1915 catch (Exception e)
1916 {
1917 log(ERROR_LOG, "RSA verify exception: " + e.ToString());
1918 ret = EXCEPTION_E;
1919 }
1920 finally
1921 {
1922 if (hashPtr != IntPtr.Zero) Marshal.FreeHGlobal(hashPtr);
1923 if (sigPtr != IntPtr.Zero) Marshal.FreeHGlobal(sigPtr);
1924 }
1925
1926 return ret;
1927 }
1928
1929 /// <summary>
1930 /// Encrypt data using RSA public key encryption
1931 /// </summary>
1932 /// <param name="key">RSA key structure</param>
1933 /// <param name="input">Data to encrypt</param>
1934 /// <param name="output">Buffer to receive the encrypted data</param>
1935 /// <returns>0 on success, otherwise an error code</returns>
1936 public static int RsaPublicEncrypt(IntPtr key, byte[] input, byte[] output)
1937 {
1938 IntPtr inPtr = Marshal.AllocHGlobal(input.Length);
1939 IntPtr outPtr = Marshal.AllocHGlobal(output.Length);
1940 Marshal.Copy(input, 0, inPtr, input.Length);
1941
1942 int ret = wc_RsaPublicEncrypt(inPtr, input.Length, outPtr, output.Length, key);
1943
1944 if (ret > 0)
1945 {
1946 Marshal.Copy(outPtr, output, 0, ret);
1947 }
1948
1949 Marshal.FreeHGlobal(inPtr);
1950 Marshal.FreeHGlobal(outPtr);
1951
1952 return ret > 0 ? 0 : ret;
1953 }
1954
1955 /// <summary>
1956 /// Decrypt data using RSA private key decryption
1957 /// </summary>
1958 /// <param name="key">RSA key structure</param>
1959 /// <param name="input">Encrypted data</param>
1960 /// <param name="output">Buffer to receive the decrypted data</param>
1961 /// <returns>0 on success, otherwise an error code</returns>
1962 public static int RsaPrivateDecrypt(IntPtr key, byte[] input, byte[] output)
1963 {
1964 IntPtr inPtr = Marshal.AllocHGlobal(input.Length);
1965 IntPtr outPtr = Marshal.AllocHGlobal(output.Length);
1966 Marshal.Copy(input, 0, inPtr, input.Length);
1967
1968 int ret = wc_RsaPrivateDecrypt(inPtr, input.Length, outPtr, output.Length, key);
1969
1970 if (ret > 0)
1971 {
1972 Marshal.Copy(outPtr, output, 0, ret);
1973 }
1974
1975 Marshal.FreeHGlobal(inPtr);
1976 Marshal.FreeHGlobal(outPtr);
1977
1978 return ret > 0 ? 0 : ret;
1979 }
1980
1981 /// <summary>
1982 /// Free an RSA key structure
1983 /// </summary>
1984 /// <param name="key">RSA key structure allocated using RsaMakeKey() or RsaImportKey()</param>
1985 public static void RsaFreeKey(IntPtr key)
1986 {
1987 if (key != IntPtr.Zero)
1988 {
1989 wc_DeleteRsaKey(key, IntPtr.Zero);
1990 key = IntPtr.Zero;
1991 }
1992 }
1993 /* END RSA */
1994
1995
1996 /***********************************************************************
1997 * ED25519
1998 **********************************************************************/
1999
2000 /// <summary>
2001 /// Generate a new ED25519 key pair with a specified heap, device ID, and internally managed RNG.
2002 /// </summary>
2003 /// <param name="heap">Heap to use for memory allocations (can be IntPtr.Zero).</param>
2004 /// <param name="devId">Device ID for hardware-based keys (can be 0 for software).</param>
2005 /// <returns>0 on success, or an error code on failure.</returns>
2006 public static IntPtr Ed25519MakeKey(IntPtr heap, int devId)
2007 {
2008 int ret = 0;
2009 IntPtr rng = IntPtr.Zero;
2010 IntPtr key = IntPtr.Zero;
2011
2012 try
2013 {
2014 rng = RandomNew();
2015 if (rng == IntPtr.Zero)
2016 {
2017 throw new Exception("Failed to create RNG.");
2018 }
2019
2020 key = wc_ed25519_new(heap, devId, IntPtr.Zero);
2021 if (key != IntPtr.Zero)
2022 {
2023 ret = wc_ed25519_make_key(rng, 32, key);
2024 }
2025 }
2026 catch (Exception e)
2027 {
2028 log(ERROR_LOG, "ED25519 make key exception: " + e.ToString());
2029 ret = EXCEPTION_E;
2030 }
2031 finally
2032 {
2033 /* Cleanup */
2034 if (rng != IntPtr.Zero) RandomFree(rng);
2035 if (ret != 0)
2036 {
2037 wc_ed25519_delete(key, IntPtr.Zero);
2038 key = IntPtr.Zero;
2039 }
2040 }
2041
2042 return key;
2043 }
2044
2045 /// <summary>
2046 /// Sign a message with an ED25519 private key.
2047 /// </summary>
2048 /// <param name="inMsg">Message to be signed</param>
2049 /// <param name="outMsg">Buffer to receive the signature</param>
2050 /// <param name="key">Private key used for signing</param>
2051 /// <returns>0 on success, otherwise an error code</returns>
2052 public static int Ed25519SignMsg(byte[] inMsg, out byte[] outMsg, IntPtr key)
2053 {
2054 int ret;
2055 IntPtr inMsgPtr = Marshal.AllocHGlobal(inMsg.Length);
2056 IntPtr outMsgPtr = Marshal.AllocHGlobal(ED25519_SIG_SIZE);
2057 outMsg = null;
2058
2059 try
2060 {
2061 Marshal.Copy(inMsg, 0, inMsgPtr, inMsg.Length);
2062 uint outMsgSize = (uint)ED25519_SIG_SIZE;
2063 ret = wc_ed25519_sign_msg(inMsgPtr, (uint)inMsg.Length, outMsgPtr, ref outMsgSize, key);
2064 if (ret == 0)
2065 {
2066 outMsg = new byte[outMsgSize];
2067 Marshal.Copy(outMsgPtr, outMsg, 0, (int)outMsgSize);
2068 }
2069 }
2070 finally
2071 {
2072 /* Cleanup */
2073 if (inMsgPtr != IntPtr.Zero) Marshal.FreeHGlobal(inMsgPtr);
2074 if (outMsgPtr != IntPtr.Zero) Marshal.FreeHGlobal(outMsgPtr);
2075 }
2076
2077 return ret;
2078 }
2079
2080 /// <summary>
2081 /// Verify a signature of a message with an ED25519 public key.
2082 /// </summary>
2083 /// <param name="sig">Signature to verify</param>
2084 /// <param name="msg">Message that was signed</param>
2085 /// <param name="key">Public key used for verification</param>
2086 /// <returns>0 if the verification succeeds, otherwise an error code</returns>
2087 public static int Ed25519VerifyMsg(byte[] sig, byte[] msg, IntPtr key)
2088 {
2089 IntPtr sigPtr = IntPtr.Zero;
2090 IntPtr msgPtr = IntPtr.Zero;
2091 int ret = 0;
2092
2093 try
2094 {
2095 /* Allocate memory */
2096 sigPtr = Marshal.AllocHGlobal(sig.Length);
2097 msgPtr = Marshal.AllocHGlobal(msg.Length);
2098
2099 Marshal.Copy(sig, 0, sigPtr, sig.Length);
2100 Marshal.Copy(msg, 0, msgPtr, msg.Length);
2101
2102 int verify = 0;
2103 ret = wc_ed25519_verify_msg(sigPtr, (uint)sig.Length, msgPtr, (uint)msg.Length, ref verify, key);
2104
2105 if (ret == 0 && verify == 1)
2106 {
2107 ret = 0;
2108 }
2109 else
2110 {
2111 ret = SIG_VERIFY_E;
2112 }
2113 }
2114 catch (Exception e)
2115 {
2116 log(ERROR_LOG, "ED25519 verify exception: " + e.ToString());
2117 ret = EXCEPTION_E;
2118 }
2119 finally
2120 {
2121 /* Cleanup */
2122 if (sigPtr != IntPtr.Zero) Marshal.FreeHGlobal(sigPtr);
2123 if (msgPtr != IntPtr.Zero) Marshal.FreeHGlobal(msgPtr);
2124 }
2125
2126 return ret;
2127 }
2128
2129 /// <summary>
2130 /// Decode an ED25519 private key from DER format.
2131 /// </summary>
2132 /// <param name="input">DER-encoded private key as byte array.</param>
2133 /// <returns>Allocated ED25519 key structure or IntPtr.Zero on failure.</returns>
2134 public static IntPtr Ed25519PrivateKeyDecode(byte[] input)
2135 {
2136 IntPtr key = IntPtr.Zero;
2137 uint idx = 0;
2138 int ret;
2139
2140 try
2141 {
2142 key = wc_ed25519_new(IntPtr.Zero, INVALID_DEVID, IntPtr.Zero);
2143 if (key != IntPtr.Zero)
2144 {
2145 ret = wc_Ed25519PrivateKeyDecode(input, ref idx, key, (uint)input.Length);
2146 if (ret != 0)
2147 {
2148 Ed25519FreeKey(key);
2149 key = IntPtr.Zero;
2150 }
2151 }
2152 }
2153 catch (Exception e)
2154 {
2155 log(ERROR_LOG, "ED25519 private key decode exception: " + e.ToString());
2156 if (key != IntPtr.Zero) Ed25519FreeKey(key);
2157 key = IntPtr.Zero;
2158 }
2159
2160 return key;
2161 }
2162
2163 /// <summary>
2164 /// Decode an ED25519 public key from DER format.
2165 /// </summary>
2166 /// <param name="input">DER-encoded public key as byte array.</param>
2167 /// <returns>Allocated ED25519 key structure or IntPtr.Zero on failure.</returns>
2168 public static IntPtr Ed25519PublicKeyDecode(byte[] input)
2169 {
2170 IntPtr key = IntPtr.Zero;
2171 uint idx = 0;
2172 int ret;
2173
2174 try
2175 {
2176 key = wc_ed25519_new(IntPtr.Zero, INVALID_DEVID, IntPtr.Zero);
2177 if (key != IntPtr.Zero)
2178 {
2179 ret = wc_Ed25519PublicKeyDecode(input, ref idx, key, (uint)input.Length);
2180 if (ret != 0)
2181 {
2182 Ed25519FreeKey(key);
2183 key = IntPtr.Zero;
2184 }
2185 }
2186 }
2187 catch (Exception e)
2188 {
2189 log(ERROR_LOG, "ED25519 public key decode exception: " + e.ToString());
2190 if (key != IntPtr.Zero) Ed25519FreeKey(key);
2191 key = IntPtr.Zero;
2192 }
2193
2194 return key;
2195 }
2196
2197 /// <summary>
2198 /// Export an ED25519 key to DER format.
2199 /// </summary>
2200 /// <param name="key">ED25519 key structure.</param>
2201 /// <param name="privKey">DER-encoded public key as byte array.</param>
2202 /// <returns>DER-encoded key as byte array.</returns>
2203 public static int Ed25519ExportKeyToDer(IntPtr key, out byte[] privKey)
2204 {
2205 int ret;
2206 privKey = null;
2207
2208 try
2209 {
2210 /* Get length */
2211 int len = wc_Ed25519KeyToDer(key, null, 0);
2212 if (len < 0)
2213 {
2214 log(ERROR_LOG, "Failed to determine length. Error code: " + len);
2215 return len;
2216 }
2217
2218 privKey = new byte[len];
2219 ret = wc_Ed25519KeyToDer(key, privKey, (uint)privKey.Length);
2220
2221 if (ret < 0)
2222 {
2223 log(ERROR_LOG, "Failed to export ED25519 private key to DER format. Error code: " + ret);
2224 return ret;
2225 }
2226 }
2227 catch(Exception e)
2228 {
2229 log(ERROR_LOG, "ED25519 export private key to DER exception: " + e.ToString());
2230 return EXCEPTION_E;
2231 }
2232
2233 return ret;
2234 }
2235
2236 /// <summary>
2237 /// Export an ED25519 private key to DER format.
2238 /// </summary>
2239 /// <param name="key">ED25519 private key structure.</param>
2240 /// <param name="derKey">DER-encoded private key as byte array.</param>
2241 /// <returns>DER-encoded private key as byte array.</returns>
2242 public static int Ed25519ExportPrivateKeyToDer(IntPtr key, out byte[] derKey)
2243 {
2244 int ret;
2245 derKey = null;
2246
2247 try
2248 {
2249 /* Determine length */
2250 int len = wc_Ed25519PrivateKeyToDer(key, null, 0);
2251 if (len < 0)
2252 {
2253 log(ERROR_LOG, "Failed to determine length. Error code: " + len);
2254 return len;
2255 }
2256
2257 derKey = new byte[len];
2258 ret = wc_Ed25519PrivateKeyToDer(key, derKey, (uint)derKey.Length);
2259
2260 if (ret < 0)
2261 {
2262 log(ERROR_LOG, "Failed to export ED25519 private key to DER format. Error code: " + ret);
2263 return ret;
2264 }
2265 }
2266 catch (Exception e)
2267 {
2268 log(ERROR_LOG, "ED25519 export private key to DER exception: " + e.ToString());
2269 return EXCEPTION_E;
2270 }
2271
2272 return ret;
2273 }
2274
2275 /// <summary>
2276 /// Export an ED25519 public key to DER format.
2277 /// </summary>
2278 /// <param name="key">ED25519 public key structure.</param>
2279 /// <param name="includeAlg">Whether to include the algorithm identifier in the output.</param>
2280 /// <param name="pubKey">DER-encoded public key as byte array.</param>
2281 /// <returns>An error code indicating success (0) or failure (negative value).</returns>
2282 public static int Ed25519ExportPublicKeyToDer(IntPtr key, out byte[] pubKey, bool includeAlg)
2283 {
2284 int ret;
2285 pubKey = null;
2286
2287 try
2288 {
2289 /* Determine length */
2290 int len = wc_Ed25519PublicKeyToDer(key, null, 0, 1);
2291 if (len < 0)
2292 {
2293 log(ERROR_LOG, "Failed to determine length. Error code: " + len);
2294 return len;
2295 }
2296
2297 pubKey = new byte[len];
2298 ret = wc_Ed25519PublicKeyToDer(key, pubKey, (uint)pubKey.Length, includeAlg ? 1 : 0);
2299 if (ret < 0)
2300 {
2301 log(ERROR_LOG, "Failed to export ED25519 public key to DER format. Error code: " + ret);
2302 return ret;
2303 }
2304 }
2305 catch (Exception e)
2306 {
2307 log(ERROR_LOG, "ED25519 export public key to DER exception: " + e.ToString());
2308 return EXCEPTION_E;
2309 }
2310
2311 return ret;
2312 }
2313
2314 /// <summary>
2315 /// Free an ED25519 key.
2316 /// </summary>
2317 /// <param name="key">Key to be freed</param>
2318 public static void Ed25519FreeKey(IntPtr key)
2319 {
2320 wc_ed25519_delete(key, IntPtr.Zero);
2321 key = IntPtr.Zero;
2322 }
2323 /* END ED25519 */
2324
2325
2326 /***********************************************************************
2327 * RAW ED25519
2328 **********************************************************************/
2329
2330 /// <summary>
2331 /// Initialize an ED25519 key.
2332 /// </summary>
2333 /// <param name="key">Buffer to receive the initialized key</param>
2334 /// <returns>0 on success, otherwise an error code</returns>
2335 public static int Ed25519InitKey(out IntPtr key)
2336 {
2337 key = IntPtr.Zero;
2338 try
2339 {
2340 key = Marshal.AllocHGlobal(ED25519_SIG_SIZE);
2341 int ret = wc_ed25519_init(key);
2342
2343 if (ret != 0)
2344 {
2345 Marshal.FreeHGlobal(key);
2346 key = IntPtr.Zero;
2347 }
2348
2349 return ret;
2350 }
2351 catch
2352 {
2353 /* Cleanup */
2354 Marshal.FreeHGlobal(key);
2355 key = IntPtr.Zero;
2356 throw;
2357 }
2358 }
2359
2360 /// <summary>
2361 /// Import a public key into an ED25519 key structure.
2362 /// </summary>
2363 /// <param name="inMsg">Public key to import</param>
2364 /// <param name="inLen">Length of the public key</param>
2365 /// <param name="key">Buffer to receive the imported key</param>
2366 /// <returns>0 on success, otherwise an error code</returns>
2367 public static int Ed25519ImportPublic(byte[] inMsg, uint inLen, out IntPtr key)
2368 {
2369 int ret;
2370 key = IntPtr.Zero;
2371 IntPtr inMsgPtr = IntPtr.Zero;
2372
2373 try
2374 {
2375 /* Allocate memory */
2376 key = wc_ed25519_new(IntPtr.Zero, INVALID_DEVID, IntPtr.Zero);
2377 if (key == IntPtr.Zero)
2378 {
2379 throw new OutOfMemoryException("Failed to allocate memory for the key.");
2380 }
2381
2382 inMsgPtr = Marshal.AllocHGlobal(inMsg.Length);
2383 if (inMsgPtr == IntPtr.Zero)
2384 {
2385 throw new OutOfMemoryException("Failed to allocate memory for the input message.");
2386 }
2387 Marshal.Copy(inMsg, 0, inMsgPtr, inMsg.Length);
2388
2389 ret = wc_ed25519_import_public(inMsgPtr, inLen, key);
2390 if (ret != 0)
2391 {
2392 if (key != IntPtr.Zero) {
2393 wc_ed25519_delete(key, IntPtr.Zero);
2394 key = IntPtr.Zero;
2395 }
2396 return ret;
2397 }
2398 }
2399 catch (Exception ex)
2400 {
2401 Console.WriteLine("Exception in EdImportPublic: " + ex.Message);
2402 if (key != IntPtr.Zero) {
2403 wc_ed25519_delete(key, IntPtr.Zero);
2404 key = IntPtr.Zero;
2405 }
2406 return EXCEPTION_E;
2407 }
2408 finally
2409 {
2410 /* Cleanup */
2411 if (inMsgPtr != IntPtr.Zero) Marshal.FreeHGlobal(inMsgPtr);
2412 }
2413
2414 return ret;
2415 }
2416
2417 /// <summary>
2418 /// Export a public key from an ED25519 key structure.
2419 /// </summary>
2420 /// <param name="key">ED25519 key structure</param>
2421 /// <param name="outMsg">Buffer to receive the exported public key</param>
2422 /// <param name="outLen">Length of the exported public key</param>
2423 /// <returns>0 on success, otherwise an error code</returns>
2424 public static int Ed25519ExportPublic(IntPtr key, byte[] outMsg, out uint outLen)
2425 {
2426 int ret;
2427 IntPtr outMsgPtr = IntPtr.Zero;
2428
2429 try
2430 {
2431 outMsgPtr = Marshal.AllocHGlobal(outMsg.Length);
2432 outLen = (uint)outMsg.Length;
2433 ret = wc_ed25519_export_public(key, outMsgPtr, ref outLen);
2434 if (ret == 0)
2435 {
2436 Marshal.Copy(outMsgPtr, outMsg, 0, (int)outLen);
2437 }
2438 else
2439 {
2440 outLen = 0;
2441 }
2442 }
2443 finally
2444 {
2445 /* Cleanup */
2446 if (outMsgPtr != IntPtr.Zero) Marshal.FreeHGlobal(outMsgPtr);
2447 }
2448
2449 return ret;
2450 }
2451
2452 /// <summary>
2453 /// Export a private key from an ED25519 key structure.
2454 /// </summary>
2455 /// <param name="key">ED25519 key structure</param>
2456 /// <param name="outMsg">Buffer to receive the exported private key</param>
2457 /// <param name="outLen">Length of the exported private key</param>
2458 /// <returns>0 on success, otherwise an error code</returns>
2459 public static int Ed25519ExportPrivate(IntPtr key, byte[] outMsg, out uint outLen)
2460 {
2461 int ret;
2462 IntPtr outMsgPtr = IntPtr.Zero;
2463
2464 try
2465 {
2466 outMsgPtr = Marshal.AllocHGlobal(outMsg.Length);
2467 outLen = (uint)outMsg.Length;
2468 ret = wc_ed25519_export_private(key, outMsgPtr, ref outLen);
2469 if (ret == 0)
2470 {
2471 Marshal.Copy(outMsgPtr, outMsg, 0, (int)outLen);
2472 }
2473 else
2474 {
2475 outLen = 0;
2476 }
2477 }
2478 finally
2479 {
2480 /* Cleanup */
2481 if (outMsgPtr != IntPtr.Zero) Marshal.FreeHGlobal(outMsgPtr);
2482 }
2483
2484 return ret;
2485 }
2486
2487 /// <summary>
2488 /// Generate a public key from a private key.
2489 /// </summary>
2490 /// <param name="key">The private key used to generate the public key</param>
2491 /// <param name="pubKey">Buffer to receive the public key</param>
2492 /// <param name="pubKeySz">Size of the public key buffer</param>
2493 /// <returns>0 on success, otherwise an error code</returns>
2494 public static int Ed25519MakePublic(IntPtr key, byte[] pubKey, out uint pubKeySz)
2495 {
2496 int ret;
2497 IntPtr pubKeyPtr = Marshal.AllocHGlobal(pubKey.Length);
2498
2499 try
2500 {
2501 pubKeySz = (uint)pubKey.Length;
2502 ret = wc_ed25519_make_public(key, pubKeyPtr, pubKeySz);
2503 if (ret == 0)
2504 {
2505 Marshal.Copy(pubKeyPtr, pubKey, 0, (int)pubKeySz);
2506 }
2507 }
2508 finally
2509 {
2510 /* Cleanup */
2511 if (pubKeyPtr != IntPtr.Zero) Marshal.FreeHGlobal(pubKeyPtr);
2512 }
2513
2514 return ret;
2515 }
2516
2517 /// <summary>
2518 /// Get the size of the ED25519 key.
2519 /// </summary>
2520 /// <param name="key">ED25519 key structure</param>
2521 /// <returns>Size of the key, or an error code if failed</returns>
2522 public static int Ed25519GetKeySize(IntPtr key)
2523 {
2524 return wc_ed25519_size(key);
2525 }
2526 /* END RAW ED25519 */
2527
2528
2529 /***********************************************************************
2530 * Curve25519
2531 **********************************************************************/
2532
2533 /// <summary>
2534 /// Generate a new Curve25519 key pair with a specified heap, device ID, and internally managed RNG.
2535 /// </summary>
2536 /// <param name="heap">Heap to use for memory allocations (can be IntPtr.Zero).</param>
2537 /// <param name="devId">Device ID for hardware-based keys (can be 0 for software).</param>
2538 /// <returns>0 on success, or an error code on failure.</returns>
2539 public static IntPtr Curve25519MakeKey(IntPtr heap, int devId)
2540 {
2541 int ret = 0;
2542 IntPtr rng = IntPtr.Zero;
2543 IntPtr key = IntPtr.Zero;
2544
2545 try
2546 {
2547 rng = RandomNew();
2548 if (rng == IntPtr.Zero)
2549 {
2550 throw new Exception("Failed to create RNG.");
2551 }
2552
2553 key = wc_curve25519_new(heap, devId, IntPtr.Zero);
2554 if (key != IntPtr.Zero)
2555 {
2556 ret = wc_curve25519_make_key(rng, 32, key);
2557 }
2558 }
2559 catch (Exception e)
2560 {
2561 log(ERROR_LOG, "Curve25519 make key exception: " + e.ToString());
2562 ret = EXCEPTION_E;
2563 }
2564 finally
2565 {
2566 /* Cleanup */
2567 if (rng != IntPtr.Zero) RandomFree(rng);
2568 if (ret != 0)
2569 {
2570 wc_curve25519_delete(key, IntPtr.Zero);
2571 key = IntPtr.Zero;
2572 }
2573 }
2574
2575 return key;
2576 }
2577
2578 /// <summary>
2579 /// Decode an Curve25519 private key from DER format.
2580 /// </summary>
2581 /// <param name="input">DER-encoded private key as byte array.</param>
2582 /// <returns>Allocated Curve25519 key structure or IntPtr.Zero on failure.</returns>
2583 public static IntPtr Curve25519PrivateKeyDecode(byte[] input)
2584 {
2585 IntPtr key = IntPtr.Zero;
2586 uint idx = 0;
2587 int ret;
2588
2589 try
2590 {
2591 key = wc_curve25519_new(IntPtr.Zero, INVALID_DEVID, IntPtr.Zero);
2592 if (key != IntPtr.Zero)
2593 {
2594 ret = wc_Ed25519PrivateKeyDecode(input, ref idx, key, (uint)input.Length);
2595 if (ret != 0)
2596 {
2597 Curve25519FreeKey(key);
2598 key = IntPtr.Zero;
2599 }
2600 }
2601 }
2602 catch (Exception e)
2603 {
2604 log(ERROR_LOG, "Curve25519 private key decode exception: " + e.ToString());
2605 if (key != IntPtr.Zero) Curve25519FreeKey(key);
2606 key = IntPtr.Zero;
2607 }
2608
2609 return key;
2610 }
2611
2612 /// <summary>
2613 /// Decode an Curve25519 public key from DER format.
2614 /// </summary>
2615 /// <param name="input">DER-encoded public key as byte array.</param>
2616 /// <returns>Allocated Curve25519 key structure or IntPtr.Zero on failure.</returns>
2617 public static IntPtr Curve25519PublicKeyDecode(byte[] input)
2618 {
2619 IntPtr key = IntPtr.Zero;
2620 uint idx = 0;
2621 int ret;
2622
2623 try
2624 {
2625 key = wc_curve25519_new(IntPtr.Zero, INVALID_DEVID, IntPtr.Zero);
2626 if (key != IntPtr.Zero)
2627 {
2628 ret = wc_Curve25519PublicKeyDecode(input, ref idx, key, (uint)input.Length);
2629 if (ret != 0)
2630 {
2631 Curve25519FreeKey(key);
2632 key = IntPtr.Zero;
2633 }
2634 }
2635 }
2636 catch (Exception e)
2637 {
2638 log(ERROR_LOG, "Curve25519 public key decode exception: " + e.ToString());
2639 if (key != IntPtr.Zero) Curve25519FreeKey(key);
2640 key = IntPtr.Zero;
2641 }
2642
2643 return key;
2644 }
2645
2646 /// <summary>
2647 /// Export an Curve25519 key to DER format.
2648 /// </summary>
2649 /// <param name="key">Curve25519 key structure.</param>
2650 /// <param name="derKey">DER-encoded public key as byte array.</param>
2651 /// <returns>DER-encoded key as byte array.</returns>
2652 public static int Curve25519ExportPrivateKeyToDer(IntPtr key, out byte[] derKey)
2653 {
2654 int ret;
2655 derKey = null;
2656
2657 try
2658 {
2659 /* Determine length */
2660 int len = wc_Curve25519PrivateKeyToDer(key, null, 0);
2661 if (len < 0)
2662 {
2663 log(ERROR_LOG, "Failed to determine length. Error code: " + len);
2664 return len;
2665 }
2666
2667 derKey = new byte[len];
2668 ret = wc_Curve25519PrivateKeyToDer(key, derKey, (uint)derKey.Length);
2669
2670 if (ret < 0)
2671 {
2672 log(ERROR_LOG, "Failed to export Curve25519 private key to DER format. Error code: " + ret);
2673 return ret;
2674 }
2675 }
2676 catch (Exception e)
2677 {
2678 log(ERROR_LOG, "CURVE25519 export private key to DER exception: " + e.ToString());
2679 return EXCEPTION_E;
2680 }
2681
2682 return ret;
2683 }
2684
2685 /// <summary>
2686 /// Export an Curve25519 public key to DER format.
2687 /// </summary>
2688 /// <param name="key">Curve25519 public key structure.</param>
2689 /// <param name="includeAlg">Whether to include the algorithm identifier in the output.</param>
2690 /// <param name="derKey">DER-encoded public key as byte array.</param>
2691 /// <returns>An error code indicating success (0) or failure (negative value).</returns>
2692 public static int Curve25519ExportPublicKeyToDer(IntPtr key, out byte[] derKey, bool includeAlg)
2693 {
2694 int ret;
2695 derKey = null;
2696
2697 try
2698 {
2699 /* Determine length */
2700 int len = wc_Curve25519PublicKeyToDer(key, null, 0, 1);
2701 if (len < 0)
2702 {
2703 log(ERROR_LOG, "Failed to determine length. Error code: " + len);
2704 return len;
2705 }
2706
2707 derKey = new byte[len];
2708 ret = wc_Curve25519PublicKeyToDer(key, derKey, (uint)derKey.Length, includeAlg ? 1 : 0);
2709 if (ret < 0)
2710 {
2711 log(ERROR_LOG, "Failed to export Curve25519 public key to DER format. Error code: " + ret);
2712 }
2713 }
2714 catch (Exception e)
2715 {
2716 log(ERROR_LOG, "Curve25519 export public key to DER exception: " + e.ToString());
2717 ret = EXCEPTION_E;
2718 }
2719
2720 return ret;
2721 }
2722
2723 /// <summary>
2724 /// Free an Curve25519 key.
2725 /// </summary>
2726 /// <param name="key">Key to be freed</param>
2727 public static void Curve25519FreeKey(IntPtr key)
2728 {
2729 wc_curve25519_delete(key, IntPtr.Zero);
2730 key = IntPtr.Zero;
2731 }
2732 /* END Curve25519 */
2733
2734
2735 /***********************************************************************
2736 * RAW Curve25519
2737 **********************************************************************/
2738
2739 /// <summary>
2740 /// Generate a shared secret using Curve25519
2741 /// </summary>
2742 /// <param name="privateKey">Curve25519 private key</param>
2743 /// <param name="publicKey">Curve25519 public key</param>
2744 /// <param name="secret">Buffer to receive the shared secret</param>
2745 /// <returns>0 on success, otherwise an error code</returns>
2746 public static int Curve25519SharedSecret(IntPtr privateKey, IntPtr publicKey, byte[] secret)
2747 {
2748 int ret;
2749 int secretLength = secret.Length;
2750
2751 try
2752 {
2753 ret = wc_curve25519_shared_secret(privateKey, publicKey, secret, ref secretLength);
2754 if (ret != 0)
2755 {
2756 throw new Exception("Failed to compute Curve25519 shared secret. Error code: " + ret);
2757 }
2758 }
2759 catch (Exception e)
2760 {
2761 log(ERROR_LOG, "Curve25519 shared secret exception " + e.ToString());
2762 ret = EXCEPTION_E;
2763 }
2764
2765 return ret;
2766 }
2767
2768 /// <summary>
2769 /// Import a Curve25519 private key from a byte array
2770 /// </summary>
2771 /// <param name="privateKey">Private key byte array</param>
2772 /// <returns>Allocated Curve25519 key structure or null</returns>
2773 public static IntPtr Curve25519ImportPrivateKey(byte[] privateKey)
2774 {
2775 IntPtr key = IntPtr.Zero;
2776
2777 try
2778 {
2779 key = Marshal.AllocHGlobal(privateKey.Length);
2780 Marshal.Copy(privateKey, 0, key, privateKey.Length);
2781 int ret = wc_curve25519_import_private(key, privateKey.Length, key);
2782 if (ret != 0)
2783 {
2784 Marshal.FreeHGlobal(key);
2785 key = IntPtr.Zero;
2786 }
2787 }
2788 catch (Exception e)
2789 {
2790 log(ERROR_LOG, "Curve25519 import private key exception " + e.ToString());
2791 if (key != IntPtr.Zero) Marshal.FreeHGlobal(key);
2792 key = IntPtr.Zero;
2793 }
2794
2795 return key;
2796 }
2797
2798 /// <summary>
2799 /// Import a Curve25519 public key from a byte array
2800 /// </summary>
2801 /// <param name="publicKey">Public key byte array</param>
2802 /// <returns>Allocated Curve25519 key structure or null</returns>
2803 public static IntPtr Curve25519ImportPublicKey(byte[] publicKey)
2804 {
2805 IntPtr key = IntPtr.Zero;
2806
2807 try
2808 {
2809 key = Marshal.AllocHGlobal(publicKey.Length);
2810 Marshal.Copy(publicKey, 0, key, publicKey.Length);
2811 int ret = wc_curve25519_import_public(key, publicKey.Length, key);
2812 if (ret != 0)
2813 {
2814 Marshal.FreeHGlobal(key);
2815 key = IntPtr.Zero;
2816 }
2817 }
2818 catch (Exception e)
2819 {
2820 log(ERROR_LOG, "Curve25519 import public key exception " + e.ToString());
2821 if (key != IntPtr.Zero) Marshal.FreeHGlobal(key);
2822 key = IntPtr.Zero;
2823 }
2824
2825 return key;
2826 }
2827
2828 /// <summary>
2829 /// Export a Curve25519 private key to a byte array
2830 /// </summary>
2831 /// <param name="key">Curve25519 key structure</param>
2832 /// <returns>Private key as byte array</returns>
2833 public static byte[] Curve25519ExportPrivateKey(IntPtr key)
2834 {
2835 byte[] privateKey = new byte[ED25519_KEY_SIZE];
2836 uint privSize = (uint)privateKey.Length;
2837 int ret = wc_curve25519_export_public(key, privateKey, ref privSize);
2838 if (ret != 0)
2839 {
2840 throw new Exception("Failed to export Curve25519 private key. Error code: " + ret);
2841 }
2842 return privateKey;
2843 }
2844
2845 /// <summary>
2846 /// Export a Curve25519 public key to a byte array
2847 /// </summary>
2848 /// <param name="key">Curve25519 key structure</param>
2849 /// <returns>Public key as byte array</returns>
2850 public static byte[] Curve25519ExportPublicKey(IntPtr key)
2851 {
2852 byte[] publicKey = new byte[ED25519_PUB_KEY_SIZE];
2853 uint pubSize = (uint)publicKey.Length;
2854 int ret = wc_curve25519_export_public(key, publicKey, ref pubSize);
2855 if (ret != 0)
2856 {
2857 throw new Exception("Failed to export Curve25519 public key. Error code: " + ret);
2858 }
2859 return publicKey;
2860 }
2861
2862
2863 /// <summary>
2864 /// Export both private and public keys from a Curve25519 key structure
2865 /// </summary>
2866 /// <param name="key">Curve25519 key structure</param>
2867 /// <param name="privateKey">returned raw private key as byte array</param>
2868 /// <param name="publicKey">returned raw public key as byte array</param>
2869 public static void Curve25519ExportKeyRaw(IntPtr key, out byte[] privateKey, out byte[] publicKey)
2870 {
2871 privateKey = new byte[ED25519_KEY_SIZE];
2872 publicKey = new byte[ED25519_PUB_KEY_SIZE];
2873 uint privSize = (uint)privateKey.Length;
2874 uint pubSize = (uint)publicKey.Length;
2875 int ret = wc_curve25519_export_key_raw(key, privateKey, ref privSize, publicKey, ref pubSize);
2876 if (ret != 0)
2877 {
2878 throw new Exception("Failed to export Curve25519 keys. Error code: " + ret);
2879 }
2880 return;
2881 }
2882 /* END RAW Curve25519 */
2883
2884
2885 /***********************************************************************
2886 * ML-KEM
2887 **********************************************************************/
2888
2889 // These APIs work by adding several options to wolfCrypt.
2890 // Please refer to `../user_settings.h`.
2891
2892 /// <summary>
2893 /// Allocate and initialize a new ML-KEM key without generating key
2894 /// material. Use this when you intend to import or decode an existing
2895 /// key (e.g., before calling MlKemDecodePublicKey/MlKemDecodePrivateKey).
2896 /// </summary>
2897 /// <param name="type">ML-KEM parameter set type</param>
2898 /// <param name="heap">Heap pointer for memory allocation</param>
2899 /// <param name="devId">Device ID (if applicable)</param>
2900 /// <returns>Pointer to the MlKem key structure, or IntPtr.Zero on failure</returns>
2901 public static IntPtr MlKemNew(MlKemTypes type, IntPtr heap, int devId)
2902 {
2903 try
2904 {
2905 IntPtr key = wc_MlKemKey_New((int)type, heap, devId);
2906 if (key == IntPtr.Zero)
2907 {
2908 log(ERROR_LOG, "Failed to allocate or initialize MlKem key.");
2909 }
2910 return key;
2911 }
2912 catch (Exception ex)
2913 {
2914 log(ERROR_LOG, "MlKem key allocation exception: " + ex.ToString());
2915 return IntPtr.Zero;
2916 }
2917 }
2918
2919 /// <summary>
2920 /// Create a new ML-KEM key pair and initialize it with random values
2921 /// </summary>
2922 /// <param name="type">ML-KEM parameter set type</param>
2923 /// <param name="heap">Heap pointer for memory allocation</param>
2924 /// <param name="devId">Device ID (if applicable)</param>
2925 /// <returns>Pointer to the MlKem key structure, or IntPtr.Zero on failure</returns>
2926 public static IntPtr MlKemMakeKey(MlKemTypes type, IntPtr heap, int devId)
2927 {
2928 int ret = 0;
2929 IntPtr key = IntPtr.Zero;
2930 IntPtr rng = IntPtr.Zero;
2931 bool success = false;
2932
2933 try
2934 {
2935 key = wc_MlKemKey_New((int)type, heap, devId);
2936 if (key == IntPtr.Zero)
2937 {
2938 log(ERROR_LOG, "Failed to allocate or initialize MlKem key.");
2939 return IntPtr.Zero;
2940 }
2941
2942 rng = RandomNew();
2943 if (rng == IntPtr.Zero)
2944 {
2945 log(ERROR_LOG, "Failed to create RNG for MlKem key.");
2946 return IntPtr.Zero;
2947 }
2948
2949 ret = wc_MlKemKey_MakeKey(key, rng);
2950 if (ret != 0)
2951 {
2952 log(ERROR_LOG, "Failed to make MlKem key. Error code: " + ret);
2953 return IntPtr.Zero;
2954 }
2955
2956 success = true;
2957 return key;
2958 }
2959 catch (Exception ex)
2960 {
2961 log(ERROR_LOG, "MlKem key creation exception: " + ex.ToString());
2962 return IntPtr.Zero;
2963 }
2964 finally
2965 {
2966 if (rng != IntPtr.Zero)
2967 {
2968 RandomFree(rng);
2969 }
2970 if (!success && key != IntPtr.Zero)
2971 {
2972 ret = MlKemFreeKey(ref key);
2973 if (ret != 0)
2974 {
2975 log(ERROR_LOG, "Failed to free MlKem key. Error code: " + ret);
2976 }
2977 }
2978 }
2979 }
2980
2981 /// <summary>
2982 /// Free a MlKem key structure and release its memory
2983 /// </summary>
2984 /// <param name="key">Pointer to the MlKem key structure</param>
2985 /// <returns>0 on success, negative value on error.</returns>
2986 public static int MlKemFreeKey(ref IntPtr key)
2987 {
2988 int ret;
2989
2990 if (key == IntPtr.Zero)
2991 {
2992 return BAD_FUNC_ARG;
2993 }
2994
2995 ret = wc_MlKemKey_Delete(key, IntPtr.Zero);
2996 key = IntPtr.Zero;
2997 return ret;
2998 }
2999
3000 /// <summary>
3001 /// Encode the ML-KEM public key to a byte array.
3002 /// </summary>
3003 /// <param name="key">Pointer to the MlKem key structure.</param>
3004 /// <param name="publicKey">Output byte array containing the encoded public key.</param>
3005 /// <returns>0 on success, negative value on error.</returns>
3006 public static int MlKemEncodePublicKey(IntPtr key, out byte[] publicKey)
3007 {
3008 publicKey = null;
3009 int ret = 0;
3010 uint pubLen = 0;
3011
3012 if (key == IntPtr.Zero)
3013 {
3014 return BAD_FUNC_ARG;
3015 }
3016
3017 try
3018 {
3019 ret = wc_MlKemKey_PublicKeySize(key, ref pubLen);
3020 if (ret != 0 || pubLen == 0)
3021 {
3022 log(ERROR_LOG, "Failed to get MlKem public key length. Error code: " + ret);
3023 return (ret != 0) ? ret : BAD_FUNC_ARG;
3024 }
3025 if (pubLen > int.MaxValue)
3026 {
3027 log(ERROR_LOG, "MlKem public key length too large: " + pubLen);
3028 return BAD_FUNC_ARG;
3029 }
3030 publicKey = new byte[checked((int)pubLen)];
3031
3032 ret = wc_MlKemKey_EncodePublicKey(key, publicKey, pubLen);
3033 if (ret != 0)
3034 {
3035 log(ERROR_LOG, "Failed to encode MlKem public key. Error code: " + ret);
3036 publicKey = null;
3037 return ret;
3038 }
3039 }
3040 catch (Exception e)
3041 {
3042 log(ERROR_LOG, "MlKem encode public key exception: " + e.ToString());
3043 publicKey = null;
3044 return EXCEPTION_E;
3045 }
3046 return SUCCESS;
3047 }
3048
3049 /// <summary>
3050 /// Encode the ML-KEM private key to a byte array.
3051 /// </summary>
3052 /// <param name="key">Pointer to the MlKem key structure.</param>
3053 /// <param name="privateKey">Output byte array containing the encoded private key.</param>
3054 /// <returns>0 on success, negative value on error.</returns>
3055 public static int MlKemEncodePrivateKey(IntPtr key, out byte[] privateKey)
3056 {
3057 privateKey = null;
3058 int ret = 0;
3059 uint privLen = 0;
3060
3061 if (key == IntPtr.Zero)
3062 {
3063 return BAD_FUNC_ARG;
3064 }
3065
3066 try
3067 {
3068 ret = wc_MlKemKey_PrivateKeySize(key, ref privLen);
3069 if (ret != 0 || privLen == 0)
3070 {
3071 log(ERROR_LOG, "Failed to get MlKem private key length. Error code: " + ret);
3072 return (ret != 0) ? ret : BAD_FUNC_ARG;
3073 }
3074 if (privLen > int.MaxValue)
3075 {
3076 log(ERROR_LOG, "MlKem private key length too large: " + privLen);
3077 return BAD_FUNC_ARG;
3078 }
3079
3080 privateKey = new byte[checked((int)privLen)];
3081 ret = wc_MlKemKey_EncodePrivateKey(key, privateKey, privLen);
3082 if (ret != 0)
3083 {
3084 log(ERROR_LOG, "Failed to encode MlKem private key. Error code: " + ret);
3085 privateKey = null;
3086 return ret;
3087 }
3088 }
3089 catch (Exception e)
3090 {
3091 log(ERROR_LOG, "MlKem encode private key exception: " + e.ToString());
3092 privateKey = null;
3093 return EXCEPTION_E;
3094 }
3095 return SUCCESS;
3096 }
3097
3098 /// <summary>
3099 /// Decode a ML-KEM public key from a byte array.
3100 /// </summary>
3101 /// <param name="key">Pointer to the MlKem key structure.</param>
3102 /// <param name="publicKey">Encoded public key as byte array.</param>
3103 /// <returns>0 on success, negative value on error.</returns>
3104 public static int MlKemDecodePublicKey(IntPtr key, byte[] publicKey)
3105 {
3106 int ret = 0;
3107 uint pubLen = 0;
3108
3109 if (key == IntPtr.Zero)
3110 {
3111 return BAD_FUNC_ARG;
3112 }
3113
3114 if (publicKey == null)
3115 {
3116 log(ERROR_LOG, "MlKem decode public key called with null publicKey buffer.");
3117 return BAD_FUNC_ARG;
3118 }
3119
3120 try
3121 {
3122 ret = wc_MlKemKey_PublicKeySize(key, ref pubLen);
3123 if (ret != 0 || pubLen == 0)
3124 {
3125 log(ERROR_LOG, "Failed to get MlKem public key length. Error code: " + ret);
3126 return (ret != 0) ? ret : BAD_FUNC_ARG;
3127 }
3128 if ((uint)publicKey.Length != pubLen)
3129 {
3130 log(ERROR_LOG, "MlKem public key buffer length mismatch. Expected: " +
3131 pubLen + ", actual: " + publicKey.Length);
3132 return BUFFER_E;
3133 }
3134
3135 ret = wc_MlKemKey_DecodePublicKey(key, publicKey, pubLen);
3136 if (ret != 0)
3137 {
3138 log(ERROR_LOG, "Failed to decode MlKem public key. Error code: " + ret);
3139 return ret;
3140 }
3141 }
3142 catch (Exception ex)
3143 {
3144 log(ERROR_LOG, "MlKem decode public key exception: " + ex.ToString());
3145 return EXCEPTION_E;
3146 }
3147 return SUCCESS;
3148 }
3149
3150 /// <summary>
3151 /// Decode a ML-KEM private key from a byte array.
3152 /// </summary>
3153 /// <param name="key">Pointer to the MlKem key structure.</param>
3154 /// <param name="privateKey">Encoded private key as byte array.</param>
3155 /// <returns>0 on success, negative value on error.</returns>
3156 public static int MlKemDecodePrivateKey(IntPtr key, byte[] privateKey)
3157 {
3158 int ret = 0;
3159 uint privLen = 0;
3160
3161 if (key == IntPtr.Zero)
3162 {
3163 return BAD_FUNC_ARG;
3164 }
3165
3166 if (privateKey == null)
3167 {
3168 log(ERROR_LOG, "MlKem private key buffer is null.");
3169 return BAD_FUNC_ARG;
3170 }
3171
3172 try
3173 {
3174 ret = wc_MlKemKey_PrivateKeySize(key, ref privLen);
3175 if (ret != 0 || privLen == 0)
3176 {
3177 log(ERROR_LOG, "Failed to get MlKem private key length. Error code: " + ret);
3178 return (ret != 0) ? ret : BAD_FUNC_ARG;
3179 }
3180
3181 if ((uint)privateKey.Length != privLen)
3182 {
3183 log(ERROR_LOG, "MlKem private key buffer length mismatch. Required: " + privLen +
3184 ", provided: " + (uint)privateKey.Length);
3185 return BUFFER_E;
3186 }
3187
3188 ret = wc_MlKemKey_DecodePrivateKey(key, privateKey, privLen);
3189 if (ret != 0)
3190 {
3191 log(ERROR_LOG, "Failed to decode MlKem private key. Error code: " + ret);
3192 return ret;
3193 }
3194 }
3195 catch (Exception ex)
3196 {
3197 log(ERROR_LOG, "MlKem decode private key exception: " + ex.ToString());
3198 return EXCEPTION_E;
3199 }
3200 return SUCCESS;
3201 }
3202
3203 /// <summary>
3204 /// Perform ML-KEM encapsulation to generate a ciphertext and shared secret
3205 /// </summary>
3206 /// <param name="key">Pointer to the MlKem key structure</param>
3207 /// <param name="ct">Output buffer for the ciphertext</param>
3208 /// <param name="ss">Output buffer for the shared secret</param>
3209 /// <returns>0 on success, otherwise an error code</returns>
3210 public static int MlKemEncapsulate(IntPtr key, out byte[] ct, out byte[] ss)
3211 {
3212 int ret;
3213 ct = null;
3214 ss = null;
3215 uint ctLen = 0;
3216 uint ssLen = 0;
3217 IntPtr rng = IntPtr.Zero;
3218
3219 if (key == IntPtr.Zero)
3220 {
3221 return BAD_FUNC_ARG;
3222 }
3223
3224 try
3225 {
3226 ret = wc_MlKemKey_CipherTextSize(key, ref ctLen);
3227 if (ret != 0)
3228 {
3229 log(ERROR_LOG, "Failed to determine ciphertext length. Error code: " + ret);
3230 return ret;
3231 }
3232 ret = wc_MlKemKey_SharedSecretSize(key, ref ssLen);
3233 if (ret != 0)
3234 {
3235 log(ERROR_LOG, "Failed to determine shared secret length. Error code: " + ret);
3236 return ret;
3237 }
3238
3239 if (ctLen > int.MaxValue || ssLen > int.MaxValue)
3240 {
3241 log(ERROR_LOG, "MlKem sizes exceed maximum supported length.");
3242 return BAD_FUNC_ARG;
3243 }
3244 ct = new byte[checked((int)ctLen)];
3245 ss = new byte[checked((int)ssLen)];
3246
3247 rng = RandomNew();
3248 if (rng == IntPtr.Zero)
3249 {
3250 log(ERROR_LOG, "Failed to create RNG for MlKem encapsulate.");
3251 return MEMORY_E;
3252 }
3253 ret = wc_MlKemKey_Encapsulate(key, ct, ss, rng);
3254 if (ret != 0)
3255 {
3256 log(ERROR_LOG, "Failed to encapsulate MlKem key. Error code: " + ret);
3257 return ret;
3258 }
3259 }
3260 catch (Exception e)
3261 {
3262 log(ERROR_LOG, "MlKem encapsulate exception: " + e.ToString());
3263 return EXCEPTION_E;
3264 }
3265 finally
3266 {
3267 if (rng != IntPtr.Zero)
3268 {
3269 RandomFree(rng);
3270 rng = IntPtr.Zero;
3271 }
3272 }
3273 return SUCCESS;
3274 }
3275
3276 /// <summary>
3277 /// Perform ML-KEM decapsulation to recover the shared secret from ciphertext
3278 /// </summary>
3279 /// <param name="key">Pointer to the MlKem key structure</param>
3280 /// <param name="ct">Ciphertext buffer</param>
3281 /// <param name="ss">Output buffer for the shared secret</param>
3282 /// <returns>0 on success, otherwise an error code</returns>
3283 public static int MlKemDecapsulate(IntPtr key, byte[] ct, out byte[] ss)
3284 {
3285 int ret;
3286 ss = null;
3287 uint ssLen = 0;
3288
3289 if (key == IntPtr.Zero || ct == null)
3290 {
3291 return BAD_FUNC_ARG;
3292 }
3293
3294 try
3295 {
3296 uint ctLen = 0;
3297 ret = wc_MlKemKey_CipherTextSize(key, ref ctLen);
3298 if (ret != 0)
3299 {
3300 log(ERROR_LOG, "Failed to determine ciphertext length. Error code: " + ret);
3301 return ret;
3302 }
3303 if ((uint)ct.Length != ctLen)
3304 {
3305 log(ERROR_LOG, "Ciphertext length mismatch. Expected: " + ctLen + ", got: " + ct.Length);
3306 return BUFFER_E;
3307 }
3308
3309 ret = wc_MlKemKey_SharedSecretSize(key, ref ssLen);
3310 if (ret != 0)
3311 {
3312 log(ERROR_LOG, "Failed to determine shared secret length. Error code: " + ret);
3313 return ret;
3314 }
3315 if (ssLen > int.MaxValue)
3316 {
3317 log(ERROR_LOG, "Shared secret length too large. Length: " + ssLen);
3318 return BAD_FUNC_ARG;
3319 }
3320
3321 ss = new byte[checked((int)ssLen)];
3322 ret = wc_MlKemKey_Decapsulate(key, ss, ct, (uint)ct.Length);
3323 if (ret != 0)
3324 {
3325 log(ERROR_LOG, "Failed to decapsulate MlKem key. Error code: " + ret);
3326 return ret;
3327 }
3328 }
3329 catch (Exception e)
3330 {
3331 log(ERROR_LOG, "MlKem decapsulate exception: " + e.ToString());
3332 return EXCEPTION_E;
3333 }
3334 return SUCCESS;
3335 }
3336
3337 /********************************
3338 * ENUMS
3339 */
3340 public enum MlKemTypes
3341 {
3342 ML_KEM_512 = 0,
3343 ML_KEM_768 = 1,
3344 ML_KEM_1024 = 2
3345 }
3346 /* END ML-KEM */
3347
3348
3349 /***********************************************************************
3350 * ML-DSA
3351 **********************************************************************/
3352
3353 // These APIs work by adding several options to wolfCrypt.
3354 // Please refer to `../user_settings.h`.
3355
3356 /// <summary>
3357 /// Allocate and initialize a new ML-DSA key (with level set) without
3358 /// generating key material. Use this when you intend to import an
3359 /// existing key (e.g., before calling MlDsaImportPublicKey or
3360 /// MlDsaImportPrivateKey).
3361 /// </summary>
3362 /// <param name="heap">Heap pointer for memory allocation</param>
3363 /// <param name="devId">Device ID (if applicable)</param>
3364 /// <param name="level">ML-DSA security level</param>
3365 /// <returns>Pointer to the ML-DSA key structure, or IntPtr.Zero on failure</returns>
3366 public static IntPtr MlDsaNew(IntPtr heap, int devId, MlDsaLevels level)
3367 {
3368 IntPtr key = IntPtr.Zero;
3369 bool success = false;
3370
3371 try
3372 {
3373 key = wc_dilithium_new(heap, devId);
3374 if (key == IntPtr.Zero)
3375 {
3376 log(ERROR_LOG, "Failed to allocate and initialize ML-DSA key.");
3377 return IntPtr.Zero;
3378 }
3379
3380 int ret = wc_dilithium_set_level(key, (byte)level);
3381 if (ret != 0)
3382 {
3383 log(ERROR_LOG, "Failed to set ML-DSA level. Error code: " + ret);
3384 return IntPtr.Zero;
3385 }
3386
3387 success = true;
3388 return key;
3389 }
3390 catch (Exception ex)
3391 {
3392 log(ERROR_LOG, "ML-DSA key allocation exception: " + ex.ToString());
3393 return IntPtr.Zero;
3394 }
3395 finally
3396 {
3397 if (!success && key != IntPtr.Zero)
3398 {
3399 int ret = MlDsaFreeKey(ref key);
3400 if (ret != 0)
3401 {
3402 log(ERROR_LOG, "Failed to free ML-DSA key. Error code: " + ret);
3403 }
3404 }
3405 }
3406 }
3407
3408 /// <summary>
3409 /// Create a new ML-DSA key pair and initialize it with random values
3410 /// </summary>
3411 /// <param name="heap">Heap pointer for memory allocation</param>
3412 /// <param name="devId">Device ID (if applicable)</param>
3413 /// <param name="level">ML-DSA security level</param>
3414 /// <returns>Pointer to the ML-DSA key structure, or IntPtr.Zero on failure</returns>
3415 public static IntPtr MlDsaMakeKey(IntPtr heap, int devId, MlDsaLevels level)
3416 {
3417 IntPtr key = IntPtr.Zero;
3418 IntPtr rng = IntPtr.Zero;
3419 int ret;
3420 bool success = false;
3421
3422 try
3423 {
3424 key = wc_dilithium_new(heap, devId);
3425 if (key == IntPtr.Zero)
3426 {
3427 log(ERROR_LOG, "Failed to allocate and initialize ML-DSA key.");
3428 return IntPtr.Zero;
3429 }
3430
3431 ret = wc_dilithium_set_level(key, (byte)level);
3432 if (ret != 0)
3433 {
3434 log(ERROR_LOG, "Failed to set ML-DSA level. Error code: " + ret);
3435 return IntPtr.Zero;
3436 }
3437
3438 rng = RandomNew();
3439 if (rng == IntPtr.Zero)
3440 {
3441 log(ERROR_LOG, "Failed to create RNG for ML-DSA key.");
3442 return IntPtr.Zero;
3443 }
3444
3445 ret = wc_dilithium_make_key(key, rng);
3446 if (ret != 0)
3447 {
3448 log(ERROR_LOG, "Failed to make ML-DSA key. Error code: " + ret);
3449 return IntPtr.Zero;
3450 }
3451
3452 success = true;
3453 return key;
3454 }
3455 catch (Exception ex)
3456 {
3457 log(ERROR_LOG, "ML-DSA key creation exception: " + ex.ToString());
3458 return IntPtr.Zero;
3459 }
3460 finally
3461 {
3462 if (rng != IntPtr.Zero)
3463 {
3464 RandomFree(rng);
3465 }
3466 if (!success && key != IntPtr.Zero)
3467 {
3468 ret = MlDsaFreeKey(ref key);
3469 if (ret != 0)
3470 {
3471 log(ERROR_LOG, "Failed to free ML-DSA key. Error code: " + ret);
3472 }
3473 }
3474 }
3475 }
3476
3477 /// <summary>
3478 /// Free an ML-DSA key structure and release its memory
3479 /// </summary>
3480 /// <param name="key">Pointer to the ML-DSA key structure</param>
3481 /// <returns>0 on success, negative value on error.</returns>
3482 public static int MlDsaFreeKey(ref IntPtr key)
3483 {
3484 int ret;
3485
3486 if (key == IntPtr.Zero)
3487 {
3488 return BAD_FUNC_ARG;
3489 }
3490
3491 ret = wc_dilithium_delete(key, IntPtr.Zero);
3492 key = IntPtr.Zero;
3493 return ret;
3494 }
3495
3496 /// <summary>
3497 /// Import an ML-DSA public key from a byte array.
3498 /// </summary>
3499 /// <param name="publicKey">Byte array containing the serialized public key.</param>
3500 /// <param name="key">Pointer to the ML-DSA key structure (must be initialized).</param>
3501 /// <returns>0 on success, negative value on error.</returns>
3502 public static int MlDsaImportPublicKey(byte[] publicKey, IntPtr key)
3503 {
3504 if (publicKey == null || key == IntPtr.Zero)
3505 {
3506 return BAD_FUNC_ARG;
3507 }
3508
3509 try
3510 {
3511 return wc_dilithium_import_public(publicKey, (uint)publicKey.Length, key);
3512 }
3513 catch (Exception e)
3514 {
3515 log(ERROR_LOG, "ML-DSA import public key exception: " + e.ToString());
3516 return EXCEPTION_E;
3517 }
3518 }
3519
3520 /// <summary>
3521 /// Import an ML-DSA private key from a byte array.
3522 /// </summary>
3523 /// <param name="privateKey">Byte array containing the private key.</param>
3524 /// <param name="key">Pointer to the ML-DSA key structure (must be initialized and have level set).</param>
3525 /// <returns>0 on success, negative value on error.</returns>
3526 public static int MlDsaImportPrivateKey(byte[] privateKey, IntPtr key)
3527 {
3528 if (privateKey == null || key == IntPtr.Zero)
3529 {
3530 return BAD_FUNC_ARG;
3531 }
3532
3533 try
3534 {
3535 return wc_dilithium_import_private(privateKey, (uint)privateKey.Length, key);
3536 }
3537 catch (Exception e)
3538 {
3539 log(ERROR_LOG, "ML-DSA import private key exception: " + e.ToString());
3540 return EXCEPTION_E;
3541 }
3542 }
3543
3544 /// <summary>
3545 /// Export an ML-DSA private key to a byte array.
3546 /// </summary>
3547 /// <param name="key">Pointer to the ML-DSA key structure.</param>
3548 /// <param name="privateKey">Output byte array containing the private key.</param>
3549 /// <returns>0 on success, negative value on error.</returns>
3550 public static int MlDsaExportPrivateKey(IntPtr key, out byte[] privateKey)
3551 {
3552 privateKey = null;
3553 int ret = 0;
3554 int privLen = 0;
3555 uint outLen;
3556
3557 if (key == IntPtr.Zero)
3558 {
3559 return BAD_FUNC_ARG;
3560 }
3561
3562 try
3563 {
3564 ret = wc_MlDsaKey_GetPrivLen(key, ref privLen);
3565 if (ret != 0 || privLen <= 0)
3566 {
3567 log(ERROR_LOG, "Failed to get ML-DSA private key length. Error code: " + ret);
3568 return (ret != 0) ? ret : BAD_FUNC_ARG;
3569 }
3570
3571 privateKey = new byte[privLen];
3572 outLen = (uint)privLen;
3573 ret = wc_dilithium_export_private(key, privateKey, ref outLen);
3574 if (ret != 0)
3575 {
3576 log(ERROR_LOG, "Failed to export ML-DSA private key. Error code: " + ret);
3577 privateKey = null;
3578 return ret;
3579 }
3580 if (outLen != (uint)privLen)
3581 {
3582 Array.Resize(ref privateKey, (int)outLen);
3583 }
3584 }
3585 catch (Exception e)
3586 {
3587 log(ERROR_LOG, "ML-DSA export private key exception: " + e.ToString());
3588 privateKey = null;
3589 return EXCEPTION_E;
3590 }
3591 return SUCCESS;
3592 }
3593
3594 /// <summary>
3595 /// Export an ML-DSA public key to a byte array.
3596 /// </summary>
3597 /// <param name="key">Pointer to the ML-DSA key structure.</param>
3598 /// <param name="publicKey">Output byte array containing the public key.</param>
3599 /// <returns>0 on success, negative value on error.</returns>
3600 public static int MlDsaExportPublicKey(IntPtr key, out byte[] publicKey)
3601 {
3602 publicKey = null;
3603 int ret = 0;
3604 int pubLen = 0;
3605 uint outLen;
3606
3607 if (key == IntPtr.Zero)
3608 {
3609 return BAD_FUNC_ARG;
3610 }
3611
3612 try
3613 {
3614 ret = wc_MlDsaKey_GetPubLen(key, ref pubLen);
3615 if (ret != 0 || pubLen <= 0)
3616 {
3617 log(ERROR_LOG, "Failed to get ML-DSA public key length. Error code: " + ret);
3618 return (ret != 0) ? ret : BAD_FUNC_ARG;
3619 }
3620
3621 publicKey = new byte[pubLen];
3622 outLen = (uint)pubLen;
3623 ret = wc_dilithium_export_public(key, publicKey, ref outLen);
3624 if (ret != 0)
3625 {
3626 log(ERROR_LOG, "Failed to export ML-DSA public key. Error code: " + ret);
3627 publicKey = null;
3628 return ret;
3629 }
3630 if (outLen != (uint)pubLen)
3631 {
3632 Array.Resize(ref publicKey, (int)outLen);
3633 }
3634 }
3635 catch (Exception e)
3636 {
3637 log(ERROR_LOG, "ML-DSA export public key exception: " + e.ToString());
3638 publicKey = null;
3639 return EXCEPTION_E;
3640 }
3641 return SUCCESS;
3642 }
3643
3644 /// <summary>
3645 /// Sign a message using an ML-DSA private key
3646 /// </summary>
3647 /// <param name="key">Pointer to the ML-DSA key structure</param>
3648 /// <param name="msg">Message to sign</param>
3649 /// <param name="sig">Output byte array for the signature</param>
3650 /// <returns>0 on success, otherwise an error code</returns>
3651 public static int MlDsaSignMsg(IntPtr key, byte[] msg, out byte[] sig)
3652 {
3653 int ret;
3654 int sigLen = 0;
3655 uint outLen;
3656 sig = null;
3657 IntPtr rng = IntPtr.Zero;
3658
3659 if (key == IntPtr.Zero || msg == null)
3660 {
3661 return BAD_FUNC_ARG;
3662 }
3663
3664 try
3665 {
3666 ret = wc_MlDsaKey_GetSigLen(key, ref sigLen);
3667 if (ret != 0 || sigLen <= 0)
3668 {
3669 log(ERROR_LOG, "Failed to get ML-DSA signature length. Error code: " + ret);
3670 return (ret != 0) ? ret : BAD_FUNC_ARG;
3671 }
3672
3673 sig = new byte[sigLen];
3674 outLen = (uint)sigLen;
3675 rng = RandomNew();
3676 if (rng == IntPtr.Zero)
3677 {
3678 log(ERROR_LOG, "Failed to create RNG for ML-DSA signing.");
3679 return MEMORY_E;
3680 }
3681 /* FIPS 204 sign with empty context (ctx=null, ctxLen=0). */
3682 ret = wc_dilithium_sign_ctx_msg(null, 0, msg, (uint)msg.Length, sig, ref outLen, key, rng);
3683 if (ret != 0)
3684 {
3685 log(ERROR_LOG, "Failed to sign message with ML-DSA key. Error code: " + ret);
3686 return ret;
3687 }
3688 if (outLen != (uint)sigLen)
3689 {
3690 Array.Resize(ref sig, (int)outLen);
3691 }
3692 }
3693 catch (Exception e)
3694 {
3695 log(ERROR_LOG, "ML-DSA sign message exception: " + e.ToString());
3696 return EXCEPTION_E;
3697 }
3698 finally
3699 {
3700 if (rng != IntPtr.Zero){
3701 RandomFree(rng);
3702 }
3703 }
3704 return SUCCESS;
3705 }
3706
3707 /// <summary>
3708 /// Verify an ML-DSA signature
3709 /// </summary>
3710 /// <param name="key">Pointer to the ML-DSA key structure</param>
3711 /// <param name="msg">Message that was signed</param>
3712 /// <param name="sig">Signature to verify</param>
3713 /// <returns>0 if the signature is valid, otherwise an error code</returns>
3714 public static int MlDsaVerifyMsg(IntPtr key, byte[] msg, byte[] sig)
3715 {
3716 int ret;
3717 int res = 0;
3718
3719 if (key == IntPtr.Zero || msg == null || sig == null)
3720 {
3721 return BAD_FUNC_ARG;
3722 }
3723
3724 try
3725 {
3726 /* FIPS 204 verify with empty context (ctx=null, ctxLen=0). */
3727 ret = wc_dilithium_verify_ctx_msg(sig, (uint)sig.Length, null, 0, msg, (uint)msg.Length, ref res, key);
3728 if (ret != 0)
3729 {
3730 log(ERROR_LOG, "Failed to verify message with ML-DSA key. Error code: " + ret);
3731 return ret;
3732 }
3733 if (res != 1)
3734 {
3735 log(ERROR_LOG, "ML-DSA signature verification failed (invalid signature).");
3736 return SIG_VERIFY_E;
3737 }
3738 }
3739 catch (Exception e)
3740 {
3741 log(ERROR_LOG, "ML-DSA verify message exception: " + e.ToString());
3742 return EXCEPTION_E;
3743 }
3744 return SUCCESS;
3745 }
3746
3747 /********************************
3748 * ENUMS
3749 */
3750 public enum MlDsaLevels
3751 {
3752 ML_DSA_44 = 2,
3753 ML_DSA_65 = 3,
3754 ML_DSA_87 = 5
3755 }
3756 /* END ML-DSA */
3757
3758
3759 /***********************************************************************
3760 * AES-GCM
3761 **********************************************************************/
3762
3763 /// <summary>
3764 /// Creates a new AES context.
3765 /// </summary>
3766 /// <param name="heap">Pointer to a memory heap, or IntPtr.Zero to use the default heap.</param>
3767 /// <param name="devId">The device ID to associate with this AES context.</param>
3768 /// <returns>A pointer to the newly created AES context, or IntPtr.Zero on failure.</returns>
3769 public static IntPtr AesNew(IntPtr heap, int devId)
3770 {
3771 IntPtr aesPtr = IntPtr.Zero;
3772
3773 try
3774 {
3775 aesPtr = wc_AesNew(heap, devId, IntPtr.Zero);
3776
3777 if (aesPtr == IntPtr.Zero)
3778 {
3779 throw new Exception("Failed to create AES context.");
3780 }
3781
3782 }
3783 catch (Exception ex)
3784 {
3785 Console.WriteLine("AES context creation failed: " + ex.Message);
3786 }
3787
3788 return aesPtr;
3789 }
3790
3791 /// <summary>
3792 /// Initialize and set the AES key for AES-GCM operations.
3793 /// </summary>
3794 /// <param name="aes">AES-GCM context pointer.</param>
3795 /// <param name="key">The AES key (either 128, 192, or 256 bits).</param>
3796 /// <returns>0 on success, otherwise an error code.</returns>
3797 public static int AesGcmSetKey(IntPtr aes, byte[] key)
3798 {
3799 IntPtr keyPtr = IntPtr.Zero;
3800 int ret;
3801
3802 try
3803 {
3804 /* Allocate memory */
3805 keyPtr = Marshal.AllocHGlobal(key.Length);
3806 Marshal.Copy(key, 0, keyPtr, key.Length);
3807
3808 ret = wc_AesGcmSetKey(aes, keyPtr, (uint)key.Length);
3809 if (ret != 0)
3810 {
3811 throw new Exception("AES-GCM initialization failed with error code ret = " + ret.ToString());
3812 }
3813 }
3814 finally
3815 {
3816 /* Cleanup */
3817 if (keyPtr != IntPtr.Zero) Marshal.FreeHGlobal(keyPtr);
3818 }
3819
3820 return ret;
3821 }
3822
3823 /// <summary>
3824 /// Wrapper method to initialize the AES-GCM context with a given key and IV.
3825 /// </summary>
3826 /// <param name="aes">Pointer to the AES-GCM context that needs to be initialized.</param>
3827 /// <param name="key">Byte array containing the AES key.</param>
3828 /// <param name="iv">Byte array containing the initialization vector (IV).</param>
3829 public static int AesGcmInit(IntPtr aes, byte[] key, byte[] iv)
3830 {
3831 IntPtr keyPtr = IntPtr.Zero;
3832 IntPtr ivPtr = IntPtr.Zero;
3833 int ret;
3834
3835 try
3836 {
3837 /* Allocate memory for key and IV */
3838 keyPtr = Marshal.AllocHGlobal(key.Length);
3839 Marshal.Copy(key, 0, keyPtr, key.Length);
3840
3841 ivPtr = Marshal.AllocHGlobal(iv.Length);
3842 Marshal.Copy(iv, 0, ivPtr, iv.Length);
3843
3844 ret = wc_AesGcmInit(aes, keyPtr, (uint)key.Length, ivPtr, (uint)iv.Length);
3845 if (ret != 0)
3846 {
3847 throw new Exception("AES-GCM initialization failed with error code ret = " + ret.ToString());
3848 }
3849 }
3850 finally
3851 {
3852 /* Cleanup */
3853 if (keyPtr != IntPtr.Zero) Marshal.FreeHGlobal(keyPtr);
3854 if (ivPtr != IntPtr.Zero) Marshal.FreeHGlobal(ivPtr);
3855 }
3856
3857 return ret;
3858 }
3859
3860 /// <summary>
3861 /// Encrypt data using AES-GCM
3862 /// </summary>
3863 /// <param name="aes">AES-GCM context pointer.</param>
3864 /// <param name="iv">Initialization Vector (IV)</param>
3865 /// <param name="plaintext">Data to encrypt</param>
3866 /// <param name="ciphertext">Buffer to receive the encrypted data</param>
3867 /// <param name="authTag">Buffer to receive the authentication tag</param>
3868 /// <returns>0 on success, otherwise an error code</returns>
3869 public static int AesGcmEncrypt(IntPtr aes, byte[] iv, byte[] plaintext,
3870 byte[] ciphertext, byte[] authTag, byte[] addAuth)
3871 {
3872 int ret;
3873 IntPtr ivPtr = IntPtr.Zero;
3874 IntPtr ciphertextPtr = IntPtr.Zero;
3875 IntPtr plaintextPtr = IntPtr.Zero;
3876 IntPtr authTagPtr = IntPtr.Zero;
3877 IntPtr addAuthPtr = IntPtr.Zero;
3878 uint addAuthSz = 0;
3879
3880 try
3881 {
3882 /* Allocate memory */
3883 ivPtr = Marshal.AllocHGlobal(iv.Length);
3884 ciphertextPtr = Marshal.AllocHGlobal(ciphertext.Length);
3885 plaintextPtr = Marshal.AllocHGlobal(plaintext.Length);
3886 authTagPtr = Marshal.AllocHGlobal(authTag.Length);
3887 if (addAuth != null) {
3888 addAuthSz = (uint)addAuth.Length;
3889 addAuthPtr = Marshal.AllocHGlobal(addAuth.Length);
3890 Marshal.Copy(addAuth, 0, addAuthPtr, addAuth.Length);
3891 }
3892
3893 Marshal.Copy(iv, 0, ivPtr, iv.Length);
3894 Marshal.Copy(plaintext, 0, plaintextPtr, plaintext.Length);
3895
3896 /* Encrypt data */
3897 ret = wc_AesGcmEncrypt(aes, ciphertextPtr, plaintextPtr, (uint)plaintext.Length,
3898 ivPtr, (uint)iv.Length, authTagPtr, (uint)authTag.Length, addAuthPtr, addAuthSz);
3899 if (ret < 0)
3900 {
3901 log(ERROR_LOG, "Failed to Encrypt data using AES-GCM. Error code: " + ret);
3902 }
3903 else {
3904 Marshal.Copy(ciphertextPtr, ciphertext, 0, ciphertext.Length);
3905 Marshal.Copy(authTagPtr, authTag, 0, authTag.Length);
3906 ret = 0;
3907 }
3908 }
3909 catch (Exception e)
3910 {
3911 log(ERROR_LOG, "AES-GCM Encryption failed: " + e.ToString());
3912 ret = EXCEPTION_E;
3913 }
3914 finally
3915 {
3916 /* Cleanup */
3917 if (ivPtr != IntPtr.Zero) Marshal.FreeHGlobal(ivPtr);
3918 if (ciphertextPtr != IntPtr.Zero) Marshal.FreeHGlobal(ciphertextPtr);
3919 if (plaintextPtr != IntPtr.Zero) Marshal.FreeHGlobal(plaintextPtr);
3920 if (authTagPtr != IntPtr.Zero) Marshal.FreeHGlobal(authTagPtr);
3921 if (addAuthPtr != IntPtr.Zero) Marshal.FreeHGlobal(addAuthPtr);
3922 }
3923
3924 return ret;
3925 }
3926 public static int AesGcmEncrypt(IntPtr aes, byte[] iv, byte[] plaintext,
3927 byte[] ciphertext, byte[] authTag)
3928 {
3929 return AesGcmEncrypt(aes, iv, plaintext, ciphertext, null);
3930 }
3931
3932 /// <summary>
3933 /// Decrypt data using AES-GCM
3934 /// </summary>
3935 /// <param name="aes">AES-GCM context pointer.</param>
3936 /// <param name="iv">Initialization Vector (IV)</param>
3937 /// <param name="ciphertext">Data to decrypt</param>
3938 /// <param name="plaintext">Buffer to receive the decrypted data</param>
3939 /// <param name="authTag">Authentication tag for verification</param>
3940 /// <returns>0 on success, otherwise an error code</returns>
3941 public static int AesGcmDecrypt(IntPtr aes, byte[] iv, byte[] ciphertext,
3942 byte[] plaintext, byte[] authTag, byte[] addAuth)
3943 {
3944 int ret;
3945 IntPtr ivPtr = IntPtr.Zero;
3946 IntPtr ciphertextPtr = IntPtr.Zero;
3947 IntPtr plaintextPtr = IntPtr.Zero;
3948 IntPtr authTagPtr = IntPtr.Zero;
3949 IntPtr addAuthPtr = IntPtr.Zero;
3950 uint addAuthSz = 0;
3951
3952 try
3953 {
3954 /* Allocate memory */
3955 ivPtr = Marshal.AllocHGlobal(iv.Length);
3956 ciphertextPtr = Marshal.AllocHGlobal(ciphertext.Length);
3957 plaintextPtr = Marshal.AllocHGlobal(plaintext.Length);
3958 authTagPtr = Marshal.AllocHGlobal(authTag.Length);
3959 if (addAuth != null) {
3960 addAuthSz = (uint)addAuth.Length;
3961 addAuthPtr = Marshal.AllocHGlobal(addAuth.Length);
3962 Marshal.Copy(addAuth, 0, addAuthPtr, addAuth.Length);
3963 }
3964
3965 Marshal.Copy(iv, 0, ivPtr, iv.Length);
3966 Marshal.Copy(ciphertext, 0, ciphertextPtr, ciphertext.Length);
3967 Marshal.Copy(authTag, 0, authTagPtr, authTag.Length);
3968
3969 /* Decrypt data */
3970 ret = wc_AesGcmDecrypt(aes, plaintextPtr, ciphertextPtr, (uint)ciphertext.Length,
3971 ivPtr, (uint)iv.Length, authTagPtr, (uint)authTag.Length, addAuthPtr, addAuthSz);
3972 if (ret < 0)
3973 {
3974 log(ERROR_LOG, "Failed to Decrypt data using AES-GCM. Error code: " + ret);
3975 }
3976 else {
3977 Marshal.Copy(plaintextPtr, plaintext, 0, plaintext.Length);
3978 ret = 0;
3979 }
3980 }
3981 catch (Exception e)
3982 {
3983 log(ERROR_LOG, "AES-GCM Decryption failed: " + e.ToString());
3984 ret = EXCEPTION_E;
3985 }
3986 finally
3987 {
3988 /* Cleanup */
3989 if (ivPtr != IntPtr.Zero) Marshal.FreeHGlobal(ivPtr);
3990 if (ciphertextPtr != IntPtr.Zero) Marshal.FreeHGlobal(ciphertextPtr);
3991 if (plaintextPtr != IntPtr.Zero) Marshal.FreeHGlobal(plaintextPtr);
3992 if (authTagPtr != IntPtr.Zero) Marshal.FreeHGlobal(authTagPtr);
3993 if (addAuthPtr != IntPtr.Zero) Marshal.FreeHGlobal(addAuthPtr);
3994 }
3995
3996 return ret;
3997 }
3998 public static int AesGcmDecrypt(IntPtr aes, byte[] iv, byte[] ciphertext,
3999 byte[] plaintext, byte[] authTag)
4000 {
4001 return AesGcmDecrypt(aes, iv, ciphertext, plaintext, authTag, null);
4002 }
4003
4004 /// <summary>
4005 /// Free AES-GCM context
4006 /// </summary>
4007 /// <param name="aes">AES-GCM context</param>
4008 public static void AesGcmFree(IntPtr aes)
4009 {
4010 if (aes != IntPtr.Zero)
4011 {
4012 wc_AesDelete(aes, IntPtr.Zero);
4013 aes = IntPtr.Zero;
4014 }
4015 }
4016 /* END AES-GCM */
4017
4018
4019 /***********************************************************************
4020 * HASH
4021 **********************************************************************/
4022
4023 /// <summary>
4024 /// Allocate and set up a new hash context with proper error handling
4025 /// </summary>
4026 /// <param name="hashType">The type of hash (SHA-256, SHA-384, etc.)</param>
4027 /// <param name="heap">Pointer to the heap for memory allocation (use IntPtr.Zero if not applicable)</param>
4028 /// <param name="devId">Device ID (if applicable, otherwise use INVALID_DEVID)</param>
4029 /// <returns>Allocated hash context pointer or IntPtr.Zero on failure</returns>
4030 public static IntPtr HashNew(uint hashType, IntPtr heap, int devId)
4031 {
4032 IntPtr hash = IntPtr.Zero;
4033
4034 try
4035 {
4036 /* Allocate new hash */
4037 hash = wc_HashNew(hashType, heap, devId, IntPtr.Zero);
4038 if (hash == IntPtr.Zero)
4039 {
4040 throw new Exception("Failed to allocate new hash context.");
4041 }
4042 }
4043 catch (Exception e)
4044 {
4045 log(ERROR_LOG, "HashNew Exception: " + e.ToString());
4046 }
4047
4048 return hash;
4049 }
4050
4051 /// <summary>
4052 /// Initialize the hash context for a specific hash type with proper error handling
4053 /// </summary>
4054 /// <param name="hash">Hash context pointer</param>
4055 /// <param name="hashType">The type of hash (SHA-256, SHA-384, etc.)</param>
4056 /// <returns>0 on success, otherwise an error code</returns>
4057 public static int InitHash(IntPtr hash, uint hashType)
4058 {
4059 int ret = 0;
4060
4061 try
4062 {
4063 /* Check hash */
4064 if (hash == IntPtr.Zero)
4065 throw new Exception("Hash context is null.");
4066
4067 ret = wc_HashInit(hash, hashType);
4068 if (ret != 0)
4069 {
4070 throw new Exception("Failed to initialize hash context. Error code: ret = " + ret.ToString());
4071 }
4072 }
4073 catch (Exception e)
4074 {
4075 /* Cleanup */
4076 log(ERROR_LOG, "InitHash Exception: " + e.ToString());
4077 if (hash != IntPtr.Zero) {
4078 wc_HashDelete(hash, IntPtr.Zero);
4079 hash = IntPtr.Zero;
4080 }
4081 }
4082
4083 return ret;
4084 }
4085
4086 /// <summary>
4087 /// Update the hash with data
4088 /// </summary>
4089 /// <param name="hash">Hash context pointer</param>
4090 /// <param name="hashType">The type of hash</param>
4091 /// <param name="data">Byte array of the data to hash</param>
4092 /// <returns>0 on success, otherwise an error code</returns>
4093 public static int HashUpdate(IntPtr hash, uint hashType, byte[] data)
4094 {
4095 int ret = 0;
4096 IntPtr dataPtr = IntPtr.Zero;
4097
4098 try
4099 {
4100 /* Check parameters */
4101 if (hash == IntPtr.Zero)
4102 throw new Exception("Hash context is null.");
4103 if (data == null || data.Length == 0)
4104 throw new Exception("Invalid data array.");
4105
4106 /* Allocate memory */
4107 dataPtr = Marshal.AllocHGlobal(data.Length);
4108 Marshal.Copy(data, 0, dataPtr, data.Length);
4109
4110 /* Update hash */
4111 ret = wc_HashUpdate(hash, hashType, dataPtr, (uint)data.Length);
4112 if (ret != 0)
4113 {
4114 throw new Exception("Failed to update hash. Error code: ret = " + ret.ToString());
4115 }
4116 }
4117 catch (Exception e)
4118 {
4119 log(ERROR_LOG, "HashUpdate Exception: " + e.ToString());
4120 }
4121 finally
4122 {
4123 /* Cleanup */
4124 if (dataPtr != IntPtr.Zero) Marshal.FreeHGlobal(dataPtr);
4125 }
4126
4127 return ret;
4128 }
4129
4130 /// <summary>
4131 /// Finalize the hash and output the result
4132 /// </summary>
4133 /// <param name="hash">Hash context pointer</param>
4134 /// <param name="hashType">The type of hash</param>
4135 /// <param name="output">Byte array where the hash output will be stored</param>
4136 /// <returns>0 on success, otherwise an error code</returns>
4137 public static int HashFinal(IntPtr hash, uint hashType, out byte[] output)
4138 {
4139 int ret = 0;
4140 IntPtr outputPtr = IntPtr.Zero;
4141
4142 try
4143 {
4144 /* Get hash size and initialize */
4145 int hashSize = wc_HashGetDigestSize(hashType);
4146 output = new byte[hashSize];
4147
4148 /* Check hash */
4149 if (hash == IntPtr.Zero)
4150 throw new Exception("Hash context is null.");
4151 if (hashSize <= 0)
4152 throw new Exception("Invalid hash size.");
4153
4154 /* Allocate memory */
4155 outputPtr = Marshal.AllocHGlobal(hashSize);
4156
4157 ret = wc_HashFinal(hash, hashType, outputPtr);
4158 if (ret != 0)
4159 {
4160 throw new Exception("Failed to finalize hash. Error code: ret = " + ret.ToString());
4161 }
4162
4163 Marshal.Copy(outputPtr, output, 0, hashSize);
4164 }
4165 catch (Exception e)
4166 {
4167 log(ERROR_LOG, "HashFinal Exception: " + e.ToString());
4168 output = null;
4169 }
4170 finally
4171 {
4172 /* Cleanup */
4173 if (outputPtr != IntPtr.Zero) Marshal.FreeHGlobal(outputPtr);
4174 }
4175
4176 return ret;
4177 }
4178
4179 /// <summary>
4180 /// Free the allocated hash context with proper error handling
4181 /// </summary>
4182 /// <param name="hash">Hash context pointer to be freed</param>
4183 /// <param name="hashType">The type of hash</param>
4184 /// <returns>0 on success, otherwise an error code</returns>
4185 public static int HashFree(IntPtr hash, uint hashType)
4186 {
4187 int ret = 0;
4188
4189 try
4190 {
4191 /* Check hash */
4192 if (hash == IntPtr.Zero)
4193 throw new Exception("Hash context is null, cannot free.");
4194
4195 /* Free hash */
4196 ret = wc_HashDelete(hash, IntPtr.Zero);
4197 hash = IntPtr.Zero;
4198 if (ret != 0)
4199 {
4200 throw new Exception("Failed to free hash context. Error code: ret = " + ret.ToString());
4201 }
4202 }
4203 catch (Exception e)
4204 {
4205 log(ERROR_LOG, "HashFree Exception: " + e.ToString());
4206 }
4207
4208 return ret;
4209 }
4210
4211 /// <summary>
4212 /// Hash type enum values
4213 /// </summary>
4214 public enum hashType
4215 {
4216 WC_HASH_TYPE_NONE = 0,
4217 WC_HASH_TYPE_MD2 = 1,
4218 WC_HASH_TYPE_MD4 = 2,
4219 WC_HASH_TYPE_MD5 = 3,
4220 WC_HASH_TYPE_SHA = 4, /* SHA-1 (not old SHA-0) */
4221 WC_HASH_TYPE_SHA224 = 5,
4222 WC_HASH_TYPE_SHA256 = 6,
4223 WC_HASH_TYPE_SHA384 = 7,
4224 WC_HASH_TYPE_SHA512 = 8,
4225 WC_HASH_TYPE_MD5_SHA = 9,
4226 WC_HASH_TYPE_SHA3_224 = 10,
4227 WC_HASH_TYPE_SHA3_256 = 11,
4228 WC_HASH_TYPE_SHA3_384 = 12,
4229 WC_HASH_TYPE_SHA3_512 = 13,
4230 WC_HASH_TYPE_BLAKE2B = 14,
4231 WC_HASH_TYPE_BLAKE2S = 15,
4232 }
4233 /* END HASH */
4234
4235
4236 /***********************************************************************
4237 * HPKE (RFC 9180) - Base mode SingleShot
4238 * Requires: HAVE_HPKE, HAVE_ECC (or HAVE_CURVE25519), HAVE_AESGCM
4239 **********************************************************************/
4240
4241 /* BEGIN HPKE */
4242
4243 /* HPKE KEM IDs */
4244 public enum HpkeKem : ushort {
4245 DHKEM_P256_HKDF_SHA256 = 0x0010,
4246 DHKEM_P384_HKDF_SHA384 = 0x0011,
4247 DHKEM_P521_HKDF_SHA512 = 0x0012,
4248 DHKEM_X25519_HKDF_SHA256 = 0x0020,
4249 DHKEM_X448_HKDF_SHA512 = 0x0021,
4250 }
4251 /* HPKE KDF IDs */
4252 public enum HpkeKdf : ushort {
4253 HKDF_SHA256 = 0x0001,
4254 HKDF_SHA384 = 0x0002,
4255 HKDF_SHA512 = 0x0003,
4256 }
4257 /* HPKE AEAD IDs */
4258 public enum HpkeAead : ushort {
4259 AES_128_GCM = 0x0001,
4260 AES_256_GCM = 0x0002,
4261 }
4262
4263 /* HPKE Nt (GCM tag length) */
4264 private const int HPKE_Nt = 16;
4265
4266 /* HPKE max encoded public-key length (matches HPKE_Npk_MAX in hpke.h) */
4267 private const int HPKE_Npk_MAX = 133;
4268
4269 /* Hpke struct is ~80 bytes on 64-bit (see hpke.h). Allocate 512 bytes
4270 * (6x headroom) to accommodate platform alignment and future growth.
4271 * If the native struct ever exceeds this, wc_HpkeInit will write OOB โ
4272 * keep in sync with hpke.h if the struct grows significantly. */
4273 private const int HPKE_STRUCT_SZ = 512;
4274
4275 /* Per-Hpke-context state owned by the C# wrapper.
4276 * The RNG must outlive any keypair created with this context: when
4277 * wolfSSL is built with WOLFSSL_CURVE25519_BLINDING, wc_curve25519_make_key
4278 * stores the rng pointer inside the keypair (via wc_curve25519_set_rng)
4279 * and reuses it for blinding during shared-secret operations. If the
4280 * wrapper freed the rng after key generation, that pointer would dangle
4281 * and the next seal/open would fail with RNG_FAILURE_E (-199). */
4282 private struct HpkeContextState
4283 {
4284 public IntPtr rng;
4285 public HpkeKem kem;
4286 }
4287
4288#if WindowsCE
4289 /* .NET Compact Framework / Windows CE does not provide
4290 * System.Collections.Concurrent, so fall back to a plain Dictionary
4291 * guarded by an explicit lock. */
4292 private static readonly Dictionary<IntPtr, HpkeContextState> hpkeContexts =
4293 new Dictionary<IntPtr, HpkeContextState>();
4294 private static readonly object hpkeContextsLock = new object();
4295
4296 private static void HpkeContextStore(IntPtr hpke, HpkeContextState state)
4297 {
4298 lock (hpkeContextsLock) { hpkeContexts[hpke] = state; }
4299 }
4300 private static bool HpkeContextTryGet(IntPtr hpke, out HpkeContextState state)
4301 {
4302 lock (hpkeContextsLock) { return hpkeContexts.TryGetValue(hpke, out state); }
4303 }
4304 private static bool HpkeContextTryRemove(IntPtr hpke, out HpkeContextState state)
4305 {
4306 lock (hpkeContextsLock)
4307 {
4308 if (hpkeContexts.TryGetValue(hpke, out state))
4309 {
4310 hpkeContexts.Remove(hpke);
4311 return true;
4312 }
4313 return false;
4314 }
4315 }
4316#else
4317 private static readonly ConcurrentDictionary<IntPtr, HpkeContextState> hpkeContexts =
4318 new ConcurrentDictionary<IntPtr, HpkeContextState>();
4319
4320 private static void HpkeContextStore(IntPtr hpke, HpkeContextState state)
4321 {
4322 hpkeContexts[hpke] = state;
4323 }
4324 private static bool HpkeContextTryGet(IntPtr hpke, out HpkeContextState state)
4325 {
4326 return hpkeContexts.TryGetValue(hpke, out state);
4327 }
4328 private static bool HpkeContextTryRemove(IntPtr hpke, out HpkeContextState state)
4329 {
4330 return hpkeContexts.TryRemove(hpke, out state);
4331 }
4332#endif
4333
4334 /// <summary>
4335 /// Get the enc (encapsulated key) length for a given KEM
4336 /// </summary>
4337 /// <param name="kem">KEM identifier</param>
4338 /// <returns>Length in bytes</returns>
4339 private static ushort HpkeEncLen(HpkeKem kem)
4340 {
4341 /* Values must match DHKEM_*_ENC_LEN macros in wolfssl/wolfcrypt/hpke.h.
4342 * Not P/Invoked because wc_HpkeKemGetEncLen is currently WOLFSSL_LOCAL. */
4343 switch (kem)
4344 {
4345 case HpkeKem.DHKEM_P256_HKDF_SHA256: return 65; /* DHKEM_P256_ENC_LEN */
4346 case HpkeKem.DHKEM_P384_HKDF_SHA384: return 97; /* DHKEM_P384_ENC_LEN */
4347 case HpkeKem.DHKEM_P521_HKDF_SHA512: return 133; /* DHKEM_P521_ENC_LEN */
4348 case HpkeKem.DHKEM_X25519_HKDF_SHA256: return 32; /* DHKEM_X25519_ENC_LEN */
4349 case HpkeKem.DHKEM_X448_HKDF_SHA512: return 56; /* DHKEM_X448_ENC_LEN */
4350 default: return 0;
4351 }
4352 }
4353
4354 /// <summary>
4355 /// Allocate and initialize an HPKE context
4356 /// </summary>
4357 /// <param name="kem">KEM algorithm identifier</param>
4358 /// <param name="kdf">KDF algorithm identifier</param>
4359 /// <param name="aead">AEAD algorithm identifier</param>
4360 /// <returns>Pointer to allocated Hpke context or IntPtr.Zero on failure</returns>
4361 public static IntPtr HpkeInit(HpkeKem kem, HpkeKdf kdf, HpkeAead aead)
4362 {
4363 IntPtr hpke = IntPtr.Zero;
4364 IntPtr rng = IntPtr.Zero;
4365
4366 try
4367 {
4368 hpke = Marshal.AllocHGlobal(HPKE_STRUCT_SZ);
4369 if (hpke == IntPtr.Zero)
4370 {
4371 log(ERROR_LOG, "HPKE alloc failed");
4372 return IntPtr.Zero;
4373 }
4374
4375 /* Zero the memory */
4376 Marshal.Copy(new byte[HPKE_STRUCT_SZ], 0, hpke, HPKE_STRUCT_SZ);
4377
4378 int ret = wc_HpkeInit(hpke, (int)kem, (int)kdf, (int)aead, IntPtr.Zero);
4379 if (ret != 0)
4380 {
4381 log(ERROR_LOG, "HPKE init failed " + ret + ": " + GetError(ret));
4382 Marshal.FreeHGlobal(hpke);
4383 return IntPtr.Zero;
4384 }
4385
4386 /* Allocate a persistent RNG that lives as long as this context.
4387 * Required so curve25519 keypairs (with blinding) retain a valid
4388 * rng pointer for shared-secret operations. */
4389 rng = RandomNew();
4390 if (rng == IntPtr.Zero)
4391 {
4392 log(ERROR_LOG, "HPKE init: RNG allocation failed");
4393 Marshal.FreeHGlobal(hpke);
4394 return IntPtr.Zero;
4395 }
4396
4397 HpkeContextStore(hpke, new HpkeContextState { rng = rng, kem = kem });
4398 }
4399 catch (Exception e)
4400 {
4401 log(ERROR_LOG, "HPKE init exception " + e.ToString());
4402 if (rng != IntPtr.Zero)
4403 {
4404 RandomFree(rng);
4405 }
4406 if (hpke != IntPtr.Zero)
4407 {
4408 Marshal.FreeHGlobal(hpke);
4409 }
4410 return IntPtr.Zero;
4411 }
4412
4413 return hpke;
4414 }
4415
4416 /// <summary>
4417 /// Generate a new HPKE keypair
4418 /// </summary>
4419 /// <param name="hpke">HPKE context from HpkeInit()</param>
4420 /// <returns>Pointer to keypair or IntPtr.Zero on failure</returns>
4421 public static IntPtr HpkeGenerateKeyPair(IntPtr hpke)
4422 {
4423 IntPtr keypair = IntPtr.Zero;
4424
4425 try
4426 {
4427 if (hpke == IntPtr.Zero)
4428 {
4429 log(ERROR_LOG, "HPKE generate keypair: invalid context");
4430 return IntPtr.Zero;
4431 }
4432
4433 HpkeContextState state;
4434 if (!HpkeContextTryGet(hpke, out state) || state.rng == IntPtr.Zero)
4435 {
4436 log(ERROR_LOG, "HPKE generate keypair: no RNG associated with context");
4437 return IntPtr.Zero;
4438 }
4439
4440 int ret = wc_HpkeGenerateKeyPair(hpke, ref keypair, state.rng);
4441 if (ret != 0)
4442 {
4443 log(ERROR_LOG, "HPKE generate keypair failed " + ret + ": " + GetError(ret));
4444 return IntPtr.Zero;
4445 }
4446
4447 /* For X25519, explicitly bind the persistent rng to the keypair.
4448 * wc_curve25519_make_key already does this internally when wolfSSL
4449 * is built with WOLFSSL_CURVE25519_BLINDING, but the explicit call
4450 * here documents the lifetime requirement and is defensive against
4451 * future changes. The function only exists when blinding is built
4452 * in, so swallow EntryPointNotFoundException for builds without it. */
4453 if (state.kem == HpkeKem.DHKEM_X25519_HKDF_SHA256 && keypair != IntPtr.Zero)
4454 {
4455 try
4456 {
4457 wc_curve25519_set_rng(keypair, state.rng);
4458 }
4459 catch (EntryPointNotFoundException)
4460 {
4461 /* wolfSSL built without WOLFSSL_CURVE25519_BLINDING; nothing to do */
4462 }
4463 }
4464 }
4465 catch (Exception e)
4466 {
4467 log(ERROR_LOG, "HPKE generate keypair exception " + e.ToString());
4468 keypair = IntPtr.Zero;
4469 }
4470
4471 return keypair;
4472 }
4473
4474 /// <summary>
4475 /// Serialize the public key to bytes
4476 /// </summary>
4477 /// <param name="hpke">HPKE context from HpkeInit()</param>
4478 /// <param name="keypair">Keypair from HpkeGenerateKeyPair()</param>
4479 /// <returns>Serialized public key bytes or null on failure</returns>
4480 public static byte[] HpkeSerializePublicKey(IntPtr hpke, IntPtr keypair)
4481 {
4482 try
4483 {
4484 if (hpke == IntPtr.Zero || keypair == IntPtr.Zero)
4485 {
4486 log(ERROR_LOG, "HPKE serialize public key: invalid parameter");
4487 return null;
4488 }
4489
4490 ushort outSz = (ushort)HPKE_Npk_MAX;
4491 byte[] outBuf = new byte[outSz];
4492
4493 int ret = wc_HpkeSerializePublicKey(hpke, keypair, outBuf, ref outSz);
4494 if (ret != 0)
4495 {
4496 log(ERROR_LOG, "HPKE serialize public key failed " + ret + ": " + GetError(ret));
4497 return null;
4498 }
4499
4500 /* Trim to actual size */
4501 byte[] result = new byte[outSz];
4502 Array.Copy(outBuf, 0, result, 0, outSz);
4503 return result;
4504 }
4505 catch (Exception e)
4506 {
4507 log(ERROR_LOG, "HPKE serialize public key exception " + e.ToString());
4508 return null;
4509 }
4510 }
4511
4512 /// <summary>
4513 /// Deserialize a public key from bytes
4514 /// </summary>
4515 /// <param name="hpke">HPKE context from HpkeInit()</param>
4516 /// <param name="pubKeyBytes">Serialized public key bytes</param>
4517 /// <returns>Pointer to keypair or IntPtr.Zero on failure</returns>
4518 public static IntPtr HpkeDeserializePublicKey(IntPtr hpke, byte[] pubKeyBytes)
4519 {
4520 IntPtr key = IntPtr.Zero;
4521
4522 try
4523 {
4524 if (hpke == IntPtr.Zero || pubKeyBytes == null || pubKeyBytes.Length == 0)
4525 {
4526 log(ERROR_LOG, "HPKE deserialize public key: invalid parameter");
4527 return IntPtr.Zero;
4528 }
4529
4530 int ret = wc_HpkeDeserializePublicKey(hpke, ref key, pubKeyBytes, (ushort)pubKeyBytes.Length);
4531 if (ret != 0)
4532 {
4533 log(ERROR_LOG, "HPKE deserialize public key failed " + ret + ": " + GetError(ret));
4534 return IntPtr.Zero;
4535 }
4536 }
4537 catch (Exception e)
4538 {
4539 log(ERROR_LOG, "HPKE deserialize public key exception " + e.ToString());
4540 return IntPtr.Zero;
4541 }
4542
4543 return key;
4544 }
4545
4546 /// <summary>
4547 /// Free a keypair created by HpkeGenerateKeyPair or HpkeDeserializePublicKey
4548 /// </summary>
4549 /// <param name="hpke">HPKE context from HpkeInit()</param>
4550 /// <param name="keypair">Keypair to free</param>
4551 /// <param name="kem">KEM used when the keypair was created</param>
4552 public static void HpkeFreeKey(IntPtr hpke, IntPtr keypair, HpkeKem kem)
4553 {
4554 if (hpke != IntPtr.Zero && keypair != IntPtr.Zero)
4555 {
4556 wc_HpkeFreeKey(hpke, (ushort)kem, keypair, IntPtr.Zero);
4557 }
4558 }
4559
4560 /// <summary>
4561 /// Free an HPKE context allocated by HpkeInit
4562 /// </summary>
4563 /// <param name="hpke">HPKE context to free</param>
4564 public static void HpkeFree(IntPtr hpke)
4565 {
4566 if (hpke != IntPtr.Zero)
4567 {
4568 HpkeContextState state;
4569 if (HpkeContextTryRemove(hpke, out state) && state.rng != IntPtr.Zero)
4570 {
4571 RandomFree(state.rng);
4572 }
4573 Marshal.FreeHGlobal(hpke);
4574 }
4575 }
4576
4577 /// <summary>
4578 /// SingleShot seal (encrypt) using HPKE Base mode.
4579 /// Returns enc||ciphertext as a single byte array.
4580 /// The enc length is determined by the KEM (e.g. 65 bytes for P-256).
4581 /// Ciphertext length = plaintext length + Nt (16-byte GCM tag).
4582 /// </summary>
4583 /// <param name="hpke">HPKE context from HpkeInit()</param>
4584 /// <param name="ephemeralKey">Ephemeral keypair for sender</param>
4585 /// <param name="receiverKey">Receiver public key</param>
4586 /// <param name="info">Info context bytes (can be null)</param>
4587 /// <param name="aad">Additional authenticated data (can be null)</param>
4588 /// <param name="plaintext">Plaintext to encrypt</param>
4589 /// <returns>enc||ciphertext byte array or null on failure</returns>
4590 public static byte[] HpkeSealBase(IntPtr hpke, IntPtr ephemeralKey, IntPtr receiverKey,
4591 byte[] info, byte[] aad, byte[] plaintext)
4592 {
4593 try
4594 {
4595 if (hpke == IntPtr.Zero || ephemeralKey == IntPtr.Zero || receiverKey == IntPtr.Zero)
4596 {
4597 log(ERROR_LOG, "HPKE seal base: invalid parameter");
4598 return null;
4599 }
4600 /* Native wc_HpkeSealBase only requires plaintext to be non-NULL;
4601 * ptSz == 0 is valid (output is just the AEAD tag). */
4602 if (plaintext == null)
4603 {
4604 log(ERROR_LOG, "HPKE seal base: invalid plaintext");
4605 return null;
4606 }
4607
4608 /* Serialize the ephemeral public key (enc) */
4609 byte[] enc = HpkeSerializePublicKey(hpke, ephemeralKey);
4610 if (enc == null)
4611 {
4612 log(ERROR_LOG, "HPKE seal base: failed to serialize ephemeral key");
4613 return null;
4614 }
4615
4616 uint infoSz = (info != null) ? (uint)info.Length : 0;
4617 uint aadSz = (aad != null) ? (uint)aad.Length : 0;
4618 uint ptSz = (uint)plaintext.Length;
4619
4620 /* wc_HpkeSealBase outputs ptSz + Nt (GCM tag) bytes */
4621 int sealLen = (int)ptSz + HPKE_Nt;
4622 byte[] sealOut = new byte[sealLen];
4623
4624 int ret = wc_HpkeSealBase(hpke, ephemeralKey, receiverKey,
4625 info, infoSz, aad, aadSz, plaintext, ptSz, sealOut);
4626 if (ret != 0)
4627 {
4628 log(ERROR_LOG, "HPKE seal base failed " + ret + ": " + GetError(ret));
4629 return null;
4630 }
4631
4632 /* Return enc || sealOut */
4633 byte[] result = new byte[enc.Length + sealLen];
4634 Array.Copy(enc, 0, result, 0, enc.Length);
4635 Array.Copy(sealOut, 0, result, enc.Length, sealLen);
4636 return result;
4637 }
4638 catch (Exception e)
4639 {
4640 log(ERROR_LOG, "HPKE seal base exception " + e.ToString());
4641 return null;
4642 }
4643 }
4644
4645 /// <summary>
4646 /// Convenience SingleShot seal (encrypt) using HPKE Base mode.
4647 /// Generates an ephemeral keypair internally so the caller does not
4648 /// need to manage one.
4649 /// Returns enc||ciphertext as a single byte array.
4650 /// </summary>
4651 /// <param name="hpke">HPKE context from HpkeInit()</param>
4652 /// <param name="receiverKey">Receiver public key</param>
4653 /// <param name="info">Info context bytes (can be null)</param>
4654 /// <param name="aad">Additional authenticated data (can be null)</param>
4655 /// <param name="plaintext">Plaintext to encrypt</param>
4656 /// <param name="kem">KEM used (needed to free the ephemeral key)</param>
4657 /// <returns>enc||ciphertext byte array or null on failure</returns>
4658 public static byte[] HpkeSealBase(IntPtr hpke, IntPtr receiverKey,
4659 byte[] info, byte[] aad, byte[] plaintext, HpkeKem kem)
4660 {
4661 IntPtr ephemeralKey = IntPtr.Zero;
4662
4663 try
4664 {
4665 ephemeralKey = HpkeGenerateKeyPair(hpke);
4666 if (ephemeralKey == IntPtr.Zero)
4667 {
4668 log(ERROR_LOG, "HPKE seal base: ephemeral keygen failed");
4669 return null;
4670 }
4671
4672 return HpkeSealBase(hpke, ephemeralKey, receiverKey,
4673 info, aad, plaintext);
4674 }
4675 catch (Exception e)
4676 {
4677 log(ERROR_LOG, "HPKE seal base exception " + e.ToString());
4678 return null;
4679 }
4680 finally
4681 {
4682 if (ephemeralKey != IntPtr.Zero)
4683 HpkeFreeKey(hpke, ephemeralKey, kem);
4684 }
4685 }
4686
4687 /// <summary>
4688 /// SingleShot open (decrypt) using HPKE Base mode.
4689 /// Takes the full enc||ciphertext blob returned by HpkeSealBase.
4690 /// </summary>
4691 /// <param name="hpke">HPKE context from HpkeInit()</param>
4692 /// <param name="receiverKey">Receiver private keypair</param>
4693 /// <param name="encCiphertext">enc||ciphertext blob from HpkeSealBase()</param>
4694 /// <param name="info">Info context bytes (can be null)</param>
4695 /// <param name="aad">Additional authenticated data (can be null)</param>
4696 /// <param name="ptLen">Expected plaintext length</param>
4697 /// <returns>Decrypted plaintext byte array or null on failure</returns>
4698 public static byte[] HpkeOpenBase(IntPtr hpke, IntPtr receiverKey,
4699 byte[] encCiphertext, byte[] info, byte[] aad, int ptLen)
4700 {
4701 try
4702 {
4703 if (hpke == IntPtr.Zero || receiverKey == IntPtr.Zero)
4704 {
4705 log(ERROR_LOG, "HPKE open base: invalid parameter");
4706 return null;
4707 }
4708 if (encCiphertext == null || encCiphertext.Length == 0)
4709 {
4710 log(ERROR_LOG, "HPKE open base: invalid ciphertext");
4711 return null;
4712 }
4713
4714 /* encCiphertext = enc || ciphertext || GCM tag
4715 * where ciphertext is ptLen bytes, tag is Nt bytes */
4716 if (ptLen < 0 || ptLen > int.MaxValue - HPKE_Nt)
4717 {
4718 log(ERROR_LOG, "HPKE open base: invalid ptLen");
4719 return null;
4720 }
4721
4722 int sealLen = ptLen + HPKE_Nt;
4723 if (encCiphertext.Length < sealLen)
4724 {
4725 log(ERROR_LOG, "HPKE open base: encCiphertext too short for given ptLen");
4726 return null;
4727 }
4728
4729 int pubKeySzInt = encCiphertext.Length - sealLen;
4730 if (pubKeySzInt < 0 || pubKeySzInt > ushort.MaxValue)
4731 {
4732 log(ERROR_LOG, "HPKE open base: invalid encapsulated public key size");
4733 return null;
4734 }
4735 ushort pubKeySz = (ushort)pubKeySzInt;
4736
4737 /* Split enc and sealed data (ciphertext || tag) */
4738 byte[] pubKey = new byte[pubKeySz];
4739 byte[] ct = new byte[sealLen];
4740 Array.Copy(encCiphertext, 0, pubKey, 0, pubKeySz);
4741 Array.Copy(encCiphertext, pubKeySz, ct, 0, sealLen);
4742
4743 uint infoSz = (info != null) ? (uint)info.Length : 0;
4744 uint aadSz = (aad != null) ? (uint)aad.Length : 0;
4745
4746 byte[] plaintext = new byte[ptLen];
4747
4748 /* ctSz is just the ciphertext length (without tag);
4749 * wc_HpkeOpenBase reads the tag from ct + ctSz */
4750 int ret = wc_HpkeOpenBase(hpke, receiverKey, pubKey, pubKeySz,
4751 info, infoSz, aad, aadSz, ct, (uint)ptLen, plaintext);
4752 if (ret != 0)
4753 {
4754 log(ERROR_LOG, "HPKE open base failed " + ret + ": " + GetError(ret));
4755 return null;
4756 }
4757
4758 return plaintext;
4759 }
4760 catch (Exception e)
4761 {
4762 log(ERROR_LOG, "HPKE open base exception " + e.ToString());
4763 return null;
4764 }
4765 }
4766
4767 /// <summary>
4768 /// Convenience SingleShot open (decrypt) using HPKE Base mode.
4769 /// Derives the plaintext length from the KEM enc length, so the caller
4770 /// does not need to know ptLen.
4771 /// </summary>
4772 /// <param name="hpke">HPKE context from HpkeInit()</param>
4773 /// <param name="receiverKey">Receiver private keypair</param>
4774 /// <param name="encCiphertext">enc||ciphertext blob from HpkeSealBase()</param>
4775 /// <param name="info">Info context bytes (can be null)</param>
4776 /// <param name="aad">Additional authenticated data (can be null)</param>
4777 /// <param name="kem">KEM used (to derive enc length)</param>
4778 /// <returns>Decrypted plaintext byte array or null on failure</returns>
4779 public static byte[] HpkeOpenBase(IntPtr hpke, IntPtr receiverKey,
4780 byte[] encCiphertext, byte[] info, byte[] aad, HpkeKem kem)
4781 {
4782 ushort encLen = HpkeEncLen(kem);
4783 if (encLen == 0)
4784 {
4785 log(ERROR_LOG, "HPKE open base: unsupported KEM");
4786 return null;
4787 }
4788 if (encCiphertext == null || encCiphertext.Length < encLen + HPKE_Nt)
4789 {
4790 log(ERROR_LOG, "HPKE open base: encCiphertext too short");
4791 return null;
4792 }
4793 int ptLen = encCiphertext.Length - encLen - HPKE_Nt;
4794 return HpkeOpenBase(hpke, receiverKey, encCiphertext, info, aad, ptLen);
4795 }
4796 /* END HPKE */
4797
4798
4799 /***********************************************************************
4800 * Logging / Other
4801 **********************************************************************/
4802
4803 /// <summary>
4804 /// Set the function to use for logging
4805 /// </summary>
4806 /// <param name="input">Function that conforms as to loggingCb</param>
4807 /// <returns>0 on success</returns>
4808 public static int SetLogging(loggingCb input)
4809 {
4810 internal_log = input;
4811 return SUCCESS;
4812 }
4813
4814 /// <summary>
4815 /// Get error string for wolfCrypt error codes
4816 /// </summary>
4817 /// <param name="error">Negative error number from wolfCrypt API</param>
4818 /// <returns>Error string</returns>
4819 public static string GetError(int error)
4820 {
4821 try
4822 {
4823 IntPtr errStr = wc_GetErrorString(error);
4824 return wolfssl.PtrToStringAnsi(errStr);
4825 }
4826 catch (Exception e)
4827 {
4828 log(ERROR_LOG, "Get error exception " + e.ToString());
4829 return string.Empty;
4830 }
4831 }
4832
4833 /// <summary>
4834 /// Compares two byte arrays.
4835 /// </summary>
4836 /// <param name="array1">The first byte array to compare.</param>
4837 /// <param name="array2">The second byte array to compare.</param>
4838 /// <returns>True if both arrays are equal; otherwise, false.</returns>
4839 public static bool ByteArrayVerify(byte[] array1, byte[] array2)
4840 {
4841 if (ReferenceEquals(array1, array2)) return true;
4842 if (array1 == null || array2 == null) return false;
4843 if (array1.Length != array2.Length) return false;
4844
4845 for (int i = 0; i < array1.Length; i++)
4846 {
4847 if (array1[i] != array2[i]) return false;
4848 }
4849 return true;
4850 }
4851 }
4852}
4853
4854