Develop and Download Open Source Software

Browse Subversion Repository

Contents of /branches/ssh_chacha20poly1305/ttssh2/ttxssh/ssh.h

Parent Directory Parent Directory | Revision Log Revision Log


Revision 4601 - (show annotations) (download) (as text)
Sun Aug 28 14:23:32 2011 UTC (12 years, 7 months ago) by maya
Original Path: trunk/ttssh2/ttxssh/ssh.h
File MIME type: text/x-chdr
File size: 23703 byte(s)
Camellia を正式サポート
  "@openssh.org" 付きのほうはコメントアウトしたまま
1 /*
2 Copyright (c) 1998-2001, Robert O'Callahan
3 All rights reserved.
4
5 Redistribution and use in source and binary forms, with or without modification,
6 are permitted provided that the following conditions are met:
7
8 Redistributions of source code must retain the above copyright notice, this list of
9 conditions and the following disclaimer.
10
11 Redistributions in binary form must reproduce the above copyright notice, this list
12 of conditions and the following disclaimer in the documentation and/or other materials
13 provided with the distribution.
14
15 The name of Robert O'Callahan may not be used to endorse or promote products derived from
16 this software without specific prior written permission.
17
18 THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS ``AS IS'' AND
19 ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
20 OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
21 THE REGENTS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
22 EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
23 SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
24 HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
25 OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
26 SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27 */
28
29 /*
30 This code is copyright (C) 1998-1999 Robert O'Callahan.
31 See LICENSE.TXT for the license.
32 */
33
34 #ifndef __SSH_H
35 #define __SSH_H
36
37 #include "zlib.h"
38 #include <openssl/evp.h>
39
40 #include "buffer.h"
41 #include "config.h"
42
43 #define DEBUG_PRINT_TO_FILE(base, msg, len) { \
44 static int count = 0; \
45 debug_print(count + base, msg, len); \
46 count++; \
47 }
48
49 // from OpenSSH
50 extern const EVP_CIPHER *evp_aes_128_ctr(void);
51 extern const EVP_CIPHER *evp_des3_ctr(void);
52 extern const EVP_CIPHER *evp_bf_ctr(void);
53 extern const EVP_CIPHER *evp_cast5_ctr(void);
54 extern const EVP_CIPHER *evp_camellia_128_ctr(void);
55
56 /* Some of this code has been adapted from Ian Goldberg's Pilot SSH */
57
58 typedef enum {
59 SSH_MSG_NONE, SSH_MSG_DISCONNECT, SSH_SMSG_PUBLIC_KEY, //2
60 SSH_CMSG_SESSION_KEY, SSH_CMSG_USER, SSH_CMSG_AUTH_RHOSTS, // 5
61 SSH_CMSG_AUTH_RSA, SSH_SMSG_AUTH_RSA_CHALLENGE,
62 SSH_CMSG_AUTH_RSA_RESPONSE, SSH_CMSG_AUTH_PASSWORD,
63 SSH_CMSG_REQUEST_PTY, // 10
64 SSH_CMSG_WINDOW_SIZE, SSH_CMSG_EXEC_SHELL,
65 SSH_CMSG_EXEC_CMD, SSH_SMSG_SUCCESS, SSH_SMSG_FAILURE,
66 SSH_CMSG_STDIN_DATA, SSH_SMSG_STDOUT_DATA, SSH_SMSG_STDERR_DATA,
67 SSH_CMSG_EOF, SSH_SMSG_EXITSTATUS,
68 SSH_MSG_CHANNEL_OPEN_CONFIRMATION, SSH_MSG_CHANNEL_OPEN_FAILURE,
69 SSH_MSG_CHANNEL_DATA, SSH_MSG_CHANNEL_INPUT_EOF,
70 SSH_MSG_CHANNEL_OUTPUT_CLOSED, SSH_MSG_OBSOLETED0,
71 SSH_SMSG_X11_OPEN, SSH_CMSG_PORT_FORWARD_REQUEST, SSH_MSG_PORT_OPEN,
72 SSH_CMSG_AGENT_REQUEST_FORWARDING, SSH_SMSG_AGENT_OPEN,
73 SSH_MSG_IGNORE, SSH_CMSG_EXIT_CONFIRMATION,
74 SSH_CMSG_X11_REQUEST_FORWARDING, SSH_CMSG_AUTH_RHOSTS_RSA,
75 SSH_MSG_DEBUG, SSH_CMSG_REQUEST_COMPRESSION,
76 SSH_CMSG_MAX_PACKET_SIZE, SSH_CMSG_AUTH_TIS,
77 SSH_SMSG_AUTH_TIS_CHALLENGE, SSH_CMSG_AUTH_TIS_RESPONSE,
78 SSH_CMSG_AUTH_KERBEROS, SSH_SMSG_AUTH_KERBEROS_RESPONSE
79 } SSHMessage;
80
81 typedef enum {
82 SSH_CIPHER_NONE, SSH_CIPHER_IDEA, SSH_CIPHER_DES, SSH_CIPHER_3DES,
83 SSH_CIPHER_TSS, SSH_CIPHER_RC4, SSH_CIPHER_BLOWFISH,
84 // for SSH2
85 SSH2_CIPHER_3DES_CBC, SSH2_CIPHER_AES128_CBC,
86 SSH2_CIPHER_AES192_CBC, SSH2_CIPHER_AES256_CBC,
87 SSH2_CIPHER_BLOWFISH_CBC, SSH2_CIPHER_AES128_CTR,
88 SSH2_CIPHER_AES192_CTR, SSH2_CIPHER_AES256_CTR,
89 SSH2_CIPHER_ARCFOUR, SSH2_CIPHER_ARCFOUR128, SSH2_CIPHER_ARCFOUR256,
90 SSH2_CIPHER_CAST128_CBC,
91 SSH2_CIPHER_3DES_CTR, SSH2_CIPHER_BLOWFISH_CTR, SSH2_CIPHER_CAST128_CTR,
92 SSH2_CIPHER_CAMELLIA128_CBC, SSH2_CIPHER_CAMELLIA192_CBC, SSH2_CIPHER_CAMELLIA256_CBC,
93 SSH2_CIPHER_CAMELLIA128_CTR, SSH2_CIPHER_CAMELLIA192_CTR, SSH2_CIPHER_CAMELLIA256_CTR,
94 SSH_CIPHER_MAX = SSH2_CIPHER_CAMELLIA256_CTR,
95 } SSHCipher;
96
97 typedef enum {
98 SSH_AUTH_NONE, SSH_AUTH_RHOSTS, SSH_AUTH_RSA, SSH_AUTH_PASSWORD,
99 SSH_AUTH_RHOSTS_RSA, SSH_AUTH_TIS, SSH_AUTH_KERBEROS,
100 SSH_AUTH_PAGEANT = 16,
101 SSH_AUTH_MAX = SSH_AUTH_PAGEANT,
102 } SSHAuthMethod;
103
104 typedef enum {
105 SSH_GENERIC_AUTHENTICATION, SSH_TIS_AUTHENTICATION
106 } SSHAuthMode;
107
108 #define SSH_PROTOFLAG_SCREEN_NUMBER 1
109 #define SSH_PROTOFLAG_HOST_IN_FWD_OPEN 2
110
111 enum channel_type {
112 TYPE_SHELL, TYPE_PORTFWD, TYPE_SCP, TYPE_SFTP, TYPE_AGENT,
113 };
114
115 // for SSH1
116 #define SSH_MAX_SEND_PACKET_SIZE 250000
117
118 // for SSH2
119 /* default window/packet sizes for tcp/x11-fwd-channel */
120 // changed CHAN_SES_WINDOW_DEFAULT from 32KB to 128KB. (2007.10.29 maya)
121 #define CHAN_SES_PACKET_DEFAULT (32*1024)
122 #define CHAN_SES_WINDOW_DEFAULT (4*CHAN_SES_PACKET_DEFAULT)
123 #define CHAN_TCP_PACKET_DEFAULT (32*1024)
124 #define CHAN_TCP_WINDOW_DEFAULT (4*CHAN_TCP_PACKET_DEFAULT)
125 #if 0 // unused
126 #define CHAN_X11_PACKET_DEFAULT (16*1024)
127 #define CHAN_X11_WINDOW_DEFAULT (4*CHAN_X11_PACKET_DEFAULT)
128 #endif
129
130
131 /* SSH2 constants */
132
133 /* SSH2 messages */
134 #define SSH2_MSG_DISCONNECT 1
135 #define SSH2_MSG_IGNORE 2
136 #define SSH2_MSG_UNIMPLEMENTED 3
137 #define SSH2_MSG_DEBUG 4
138 #define SSH2_MSG_SERVICE_REQUEST 5
139 #define SSH2_MSG_SERVICE_ACCEPT 6
140
141 #define SSH2_MSG_KEXINIT 20
142 #define SSH2_MSG_NEWKEYS 21
143
144 #define SSH2_MSG_KEXDH_INIT 30
145 #define SSH2_MSG_KEXDH_REPLY 31
146
147 #define SSH2_MSG_KEX_DH_GEX_GROUP 31
148 #define SSH2_MSG_KEX_DH_GEX_INIT 32
149 #define SSH2_MSG_KEX_DH_GEX_REPLY 33
150 #define SSH2_MSG_KEX_DH_GEX_REQUEST 34
151
152 #define SSH2_MSG_KEX_ECDH_INIT 30
153 #define SSH2_MSG_KEX_ECDH_REPLY 31
154
155 #define SSH2_MSG_USERAUTH_REQUEST 50
156 #define SSH2_MSG_USERAUTH_FAILURE 51
157 #define SSH2_MSG_USERAUTH_SUCCESS 52
158 #define SSH2_MSG_USERAUTH_BANNER 53
159
160 #define SSH2_MSG_USERAUTH_PK_OK 60
161 #define SSH2_MSG_USERAUTH_PASSWD_CHANGEREQ 60
162 #define SSH2_MSG_USERAUTH_INFO_REQUEST 60
163 #define SSH2_MSG_USERAUTH_INFO_RESPONSE 61
164
165 #define SSH2_MSG_GLOBAL_REQUEST 80
166 #define SSH2_MSG_REQUEST_SUCCESS 81
167 #define SSH2_MSG_REQUEST_FAILURE 82
168 #define SSH2_MSG_CHANNEL_OPEN 90
169 #define SSH2_MSG_CHANNEL_OPEN_CONFIRMATION 91
170 #define SSH2_MSG_CHANNEL_OPEN_FAILURE 92
171 #define SSH2_MSG_CHANNEL_WINDOW_ADJUST 93
172 #define SSH2_MSG_CHANNEL_DATA 94
173 #define SSH2_MSG_CHANNEL_EXTENDED_DATA 95
174 #define SSH2_MSG_CHANNEL_EOF 96
175 #define SSH2_MSG_CHANNEL_CLOSE 97
176 #define SSH2_MSG_CHANNEL_REQUEST 98
177 #define SSH2_MSG_CHANNEL_SUCCESS 99
178 #define SSH2_MSG_CHANNEL_FAILURE 100
179
180 /* SSH2 miscellaneous constants */
181 #define SSH2_DISCONNECT_HOST_NOT_ALLOWED_TO_CONNECT 1
182 #define SSH2_DISCONNECT_PROTOCOL_ERROR 2
183 #define SSH2_DISCONNECT_KEY_EXCHANGE_FAILED 3
184 #define SSH2_DISCONNECT_HOST_AUTHENTICATION_FAILED 4
185 #define SSH2_DISCONNECT_MAC_ERROR 5
186 #define SSH2_DISCONNECT_COMPRESSION_ERROR 6
187 #define SSH2_DISCONNECT_SERVICE_NOT_AVAILABLE 7
188 #define SSH2_DISCONNECT_PROTOCOL_VERSION_NOT_SUPPORTED 8
189 #define SSH2_DISCONNECT_HOST_KEY_NOT_VERIFIABLE 9
190 #define SSH2_DISCONNECT_CONNECTION_LOST 10
191 #define SSH2_DISCONNECT_BY_APPLICATION 11
192
193 #define SSH2_OPEN_ADMINISTRATIVELY_PROHIBITED 1
194 #define SSH2_OPEN_CONNECT_FAILED 2
195 #define SSH2_OPEN_UNKNOWN_CHANNEL_TYPE 3
196 #define SSH2_OPEN_RESOURCE_SHORTAGE 4
197
198
199 // �N���C�A���g�����T�[�o������������
200 enum kex_init_proposals {
201 PROPOSAL_KEX_ALGS,
202 PROPOSAL_SERVER_HOST_KEY_ALGS,
203 PROPOSAL_ENC_ALGS_CTOS,
204 PROPOSAL_ENC_ALGS_STOC,
205 PROPOSAL_MAC_ALGS_CTOS,
206 PROPOSAL_MAC_ALGS_STOC,
207 PROPOSAL_COMP_ALGS_CTOS,
208 PROPOSAL_COMP_ALGS_STOC,
209 PROPOSAL_LANG_CTOS,
210 PROPOSAL_LANG_STOC,
211 PROPOSAL_MAX
212 };
213
214 #define KEX_DEFAULT_KEX ""
215 #define KEX_DEFAULT_PK_ALG ""
216 #define KEX_DEFAULT_ENCRYPT ""
217 #define KEX_DEFAULT_MAC ""
218 #define KEX_DEFAULT_COMP ""
219 #define KEX_DEFAULT_LANG ""
220
221 static char *myproposal[PROPOSAL_MAX] = {
222 KEX_DEFAULT_KEX,
223 KEX_DEFAULT_PK_ALG,
224 KEX_DEFAULT_ENCRYPT,
225 KEX_DEFAULT_ENCRYPT,
226 KEX_DEFAULT_MAC,
227 KEX_DEFAULT_MAC,
228 KEX_DEFAULT_COMP,
229 KEX_DEFAULT_COMP,
230 KEX_DEFAULT_LANG,
231 KEX_DEFAULT_LANG,
232 };
233
234
235 typedef enum {
236 KEY_NONE,
237 KEY_RSA1,
238 KEY_RSA,
239 KEY_DSA,
240 KEY_ECDSA256,
241 KEY_ECDSA384,
242 KEY_ECDSA521,
243 KEY_UNSPEC,
244 KEY_MAX = KEY_UNSPEC,
245 } ssh_keytype;
246 #define isECDSAkey(type) ((type) >= KEY_ECDSA256 && (type) <= KEY_ECDSA521)
247
248 typedef struct ssh2_host_key {
249 ssh_keytype type;
250 char *name;
251 } ssh2_host_key_t;
252
253 static ssh2_host_key_t ssh2_host_key[] = {
254 {KEY_RSA1, "ssh-rsa1"}, // for SSH1 only
255 {KEY_RSA, "ssh-rsa"}, // RFC4253
256 {KEY_DSA, "ssh-dss"}, // RFC4253
257 {KEY_ECDSA256, "ecdsa-sha2-nistp256"}, // RFC5656
258 {KEY_ECDSA384, "ecdsa-sha2-nistp384"}, // RFC5656
259 {KEY_ECDSA521, "ecdsa-sha2-nistp521"}, // RFC5656
260 {KEY_UNSPEC, "ssh-unknown"},
261 {KEY_NONE, NULL},
262 };
263
264 /* Minimum modulus size (n) for RSA keys. */
265 #define SSH_RSA_MINIMUM_MODULUS_SIZE 768
266
267 #define SSH_KEYGEN_DEFAULT_BITS 2048
268 #define SSH_RSA_MINIMUM_KEY_SIZE 768
269 #define SSH_DSA_MINIMUM_KEY_SIZE 1024
270
271
272 typedef struct ssh2_cipher {
273 SSHCipher cipher;
274 char *name;
275 int block_size;
276 int key_len;
277 int discard_len;
278 const EVP_CIPHER *(*func)(void);
279 } ssh2_cipher_t;
280
281 static ssh2_cipher_t ssh2_ciphers[] = {
282 {SSH2_CIPHER_3DES_CBC, "3des-cbc", 8, 24, 0, EVP_des_ede3_cbc}, // RFC4253
283 {SSH2_CIPHER_AES128_CBC, "aes128-cbc", 16, 16, 0, EVP_aes_128_cbc}, // RFC4253
284 {SSH2_CIPHER_AES192_CBC, "aes192-cbc", 16, 24, 0, EVP_aes_192_cbc}, // RFC4253
285 {SSH2_CIPHER_AES256_CBC, "aes256-cbc", 16, 32, 0, EVP_aes_256_cbc}, // RFC4253
286 {SSH2_CIPHER_BLOWFISH_CBC, "blowfish-cbc", 8, 16, 0, EVP_bf_cbc}, // RFC4253
287 {SSH2_CIPHER_AES128_CTR, "aes128-ctr", 16, 16, 0, evp_aes_128_ctr}, // RFC4344
288 {SSH2_CIPHER_AES192_CTR, "aes192-ctr", 16, 24, 0, evp_aes_128_ctr}, // RFC4344
289 {SSH2_CIPHER_AES256_CTR, "aes256-ctr", 16, 32, 0, evp_aes_128_ctr}, // RFC4344
290 {SSH2_CIPHER_ARCFOUR, "arcfour", 8, 16, 0, EVP_rc4}, // RFC4253
291 {SSH2_CIPHER_ARCFOUR128, "arcfour128", 8, 16, 1536, EVP_rc4}, // RFC4345
292 {SSH2_CIPHER_ARCFOUR256, "arcfour256", 8, 32, 1536, EVP_rc4}, // RFC4345
293 {SSH2_CIPHER_CAST128_CBC, "cast128-cbc", 8, 16, 0, EVP_cast5_cbc}, // RFC4253
294 {SSH2_CIPHER_3DES_CTR, "3des-ctr", 8, 24, 0, evp_des3_ctr}, // RFC4344
295 {SSH2_CIPHER_BLOWFISH_CTR, "blowfish-ctr", 8, 16, 0, evp_bf_ctr}, // RFC4344
296 {SSH2_CIPHER_CAST128_CTR, "cast128-ctr", 8, 16, 0, evp_cast5_ctr}, // RFC4344
297 {SSH2_CIPHER_CAMELLIA128_CBC, "camellia128-cbc", 16, 16, 0, EVP_camellia_128_cbc}, // draft-kanno-secsh-camellia-02
298 {SSH2_CIPHER_CAMELLIA192_CBC, "camellia192-cbc", 16, 24, 0, EVP_camellia_192_cbc}, // draft-kanno-secsh-camellia-02
299 {SSH2_CIPHER_CAMELLIA256_CBC, "camellia256-cbc", 16, 32, 0, EVP_camellia_256_cbc}, // draft-kanno-secsh-camellia-02
300 {SSH2_CIPHER_CAMELLIA128_CTR, "camellia128-ctr", 16, 16, 0, evp_camellia_128_ctr}, // draft-kanno-secsh-camellia-02
301 {SSH2_CIPHER_CAMELLIA192_CTR, "camellia192-ctr", 16, 24, 0, evp_camellia_128_ctr}, // draft-kanno-secsh-camellia-02
302 {SSH2_CIPHER_CAMELLIA256_CTR, "camellia256-ctr", 16, 32, 0, evp_camellia_128_ctr}, // draft-kanno-secsh-camellia-02
303 #ifdef WITH_CAMELLIA_PRIVATE
304 {SSH2_CIPHER_CAMELLIA128_CBC, "camellia128-cbc@openssh.org", 16, 16, 0, EVP_camellia_128_cbc},
305 {SSH2_CIPHER_CAMELLIA192_CBC, "camellia192-cbc@openssh.org", 16, 24, 0, EVP_camellia_192_cbc},
306 {SSH2_CIPHER_CAMELLIA256_CBC, "camellia256-cbc@openssh.org", 16, 32, 0, EVP_camellia_256_cbc},
307 {SSH2_CIPHER_CAMELLIA128_CTR, "camellia128-ctr@openssh.org", 16, 16, 0, evp_camellia_128_ctr},
308 {SSH2_CIPHER_CAMELLIA192_CTR, "camellia192-ctr@openssh.org", 16, 24, 0, evp_camellia_128_ctr},
309 {SSH2_CIPHER_CAMELLIA256_CTR, "camellia256-ctr@openssh.org", 16, 32, 0, evp_camellia_128_ctr},
310 #endif // WITH_CAMELLIA_PRIVATE
311 {SSH_CIPHER_NONE, NULL, 0, 0, 0, NULL},
312 };
313
314
315 typedef enum {
316 KEX_DH_NONE, /* disabled line */
317 KEX_DH_GRP1_SHA1,
318 KEX_DH_GRP14_SHA1,
319 KEX_DH_GEX_SHA1,
320 KEX_DH_GEX_SHA256,
321 KEX_ECDH_SHA2_256,
322 KEX_ECDH_SHA2_384,
323 KEX_ECDH_SHA2_521,
324 KEX_DH_UNKNOWN,
325 KEX_DH_MAX = KEX_DH_UNKNOWN,
326 } kex_algorithm;
327
328 typedef struct ssh2_kex_algorithm {
329 kex_algorithm kextype;
330 char *name;
331 const EVP_MD *(*evp_md)(void);
332 } ssh2_kex_algorithm_t;
333
334 static ssh2_kex_algorithm_t ssh2_kex_algorithms[] = {
335 {KEX_DH_GRP1_SHA1, "diffie-hellman-group1-sha1", EVP_sha1}, // RFC4253
336 {KEX_DH_GRP14_SHA1, "diffie-hellman-group14-sha1", EVP_sha1}, // RFC4253
337 {KEX_DH_GEX_SHA1, "diffie-hellman-group-exchange-sha1", EVP_sha1}, // RFC4419
338 {KEX_DH_GEX_SHA256, "diffie-hellman-group-exchange-sha256", EVP_sha256}, // RFC4419
339 {KEX_ECDH_SHA2_256, "ecdh-sha2-nistp256", EVP_sha256}, // RFC5656
340 {KEX_ECDH_SHA2_384, "ecdh-sha2-nistp384", EVP_sha384}, // RFC5656
341 {KEX_ECDH_SHA2_521, "ecdh-sha2-nistp521", EVP_sha512}, // RFC5656
342 {KEX_DH_NONE , NULL, NULL},
343 };
344
345
346 typedef enum {
347 HMAC_NONE, /* disabled line */
348 HMAC_SHA1,
349 HMAC_MD5,
350 HMAC_SHA1_96,
351 HMAC_MD5_96,
352 HMAC_RIPEMD160,
353 HMAC_SHA2_256,
354 HMAC_SHA2_256_96,
355 HMAC_SHA2_512,
356 HMAC_SHA2_512_96,
357 HMAC_UNKNOWN,
358 HMAC_MAX = HMAC_UNKNOWN,
359 } hmac_type;
360
361 typedef struct ssh2_mac {
362 hmac_type type;
363 char *name;
364 const EVP_MD *(*evp_md)(void);
365 int truncatebits;
366 } ssh2_mac_t;
367
368 static ssh2_mac_t ssh2_macs[] = {
369 {HMAC_SHA1, "hmac-sha1", EVP_sha1, 0}, // RFC4253
370 {HMAC_MD5, "hmac-md5", EVP_md5, 0}, // RFC4253
371 {HMAC_SHA1_96, "hmac-sha1-96", EVP_sha1, 96}, // RFC4253
372 {HMAC_MD5_96, "hmac-md5-96", EVP_md5, 96}, // RFC4253
373 {HMAC_RIPEMD160, "hmac-ripemd160@openssh.com", EVP_ripemd160, 0},
374 {HMAC_SHA2_256, "hmac-sha2-256", EVP_sha256, 0}, // draft-dbider-sha2-mac-for-ssh-02
375 {HMAC_SHA2_256_96, "hmac-sha2-256-96", EVP_sha256, 96}, // draft-dbider-sha2-mac-for-ssh-02
376 {HMAC_SHA2_512, "hmac-sha2-512", EVP_sha512, 0}, // draft-dbider-sha2-mac-for-ssh-02
377 {HMAC_SHA2_512_96, "hmac-sha2-512-96", EVP_sha512, 96}, // draft-dbider-sha2-mac-for-ssh-02
378 {HMAC_NONE, NULL, NULL, 0},
379 };
380
381
382 typedef enum {
383 COMP_NONE, /* disabled line */
384 COMP_NOCOMP,
385 COMP_ZLIB,
386 COMP_DELAYED,
387 COMP_UNKNOWN,
388 COMP_MAX = COMP_UNKNOWN,
389 } compression_type;
390
391 typedef struct ssh2_comp {
392 compression_type type;
393 char *name;
394 } ssh2_comp_t;
395
396 static ssh2_comp_t ssh2_comps[] = {
397 {COMP_NOCOMP, "none"}, // RFC4253
398 {COMP_ZLIB, "zlib"}, // RFC4253
399 {COMP_DELAYED, "zlib@openssh.com"},
400 {COMP_NONE, NULL},
401 };
402
403
404 struct Enc {
405 u_char *key;
406 u_char *iv;
407 unsigned int key_len;
408 unsigned int block_size;
409 };
410
411 struct Mac {
412 char *name;
413 int enabled;
414 const EVP_MD *md;
415 int mac_len;
416 u_char *key;
417 int key_len;
418 };
419
420 struct Comp {
421 int type;
422 int enabled;
423 char *name;
424 };
425
426 typedef struct {
427 struct Enc enc;
428 struct Mac mac;
429 struct Comp comp;
430 } Newkeys;
431
432 #define roundup(x, y) ((((x)+((y)-1))/(y))*(y))
433
434 enum kex_modes {
435 MODE_IN,
436 MODE_OUT,
437 MODE_MAX
438 };
439
440
441 // �z�X�g�L�[(SSH1, SSH2����)���f�[�^�\�� (2006.3.21 yutaka)
442 typedef struct Key {
443 // host key type
444 ssh_keytype type;
445 // SSH2 RSA
446 RSA *rsa;
447 // SSH2 DSA
448 DSA *dsa;
449 // SSH2 ECDSA
450 EC_KEY *ecdsa;
451 // SSH1 RSA
452 int bits;
453 unsigned char *exp;
454 unsigned char *mod;
455 } Key;
456
457 // fingerprint������
458 enum fp_rep {
459 SSH_FP_HEX,
460 SSH_FP_BUBBLEBABBLE,
461 SSH_FP_RANDOMART
462 };
463
464 enum fp_type {
465 SSH_FP_MD5,
466 SSH_FP_SHA1,
467 SSH_FP_SHA256
468 };
469
470 enum scp_dir {
471 TOREMOTE, FROMREMOTE,
472 };
473
474 /* The packet handler returns TRUE to keep the handler in place,
475 FALSE to remove the handler. */
476 typedef BOOL (* SSHPacketHandler)(PTInstVar pvar);
477
478 typedef struct _SSHPacketHandlerItem SSHPacketHandlerItem;
479 struct _SSHPacketHandlerItem {
480 SSHPacketHandler handler;
481 /* Circular list of handlers for given message */
482 SSHPacketHandlerItem FAR * next_for_message;
483 SSHPacketHandlerItem FAR * last_for_message;
484 /* Circular list of handlers in set */
485 SSHPacketHandlerItem FAR * next_in_set;
486 int active_for_message;
487 };
488
489 typedef struct {
490 char FAR * hostname;
491
492 int server_protocol_flags;
493 char FAR * server_ID;
494
495 /* This buffer is used to hold the outgoing data, and encrypted in-place
496 here if necessary. */
497 unsigned char FAR * outbuf;
498 long outbuflen;
499 /* This buffer is used by the SSH protocol processing to store uncompressed
500 packet data for compression. User data is never streamed through here;
501 it is compressed directly from the user's buffer. */
502 unsigned char FAR * precompress_outbuf;
503 long precompress_outbuflen;
504 /* this is the length of the packet data, including the type header */
505 long outgoing_packet_len;
506
507 /* This buffer is used by the SSH protocol processing to store decompressed
508 packet data. User data is never streamed through here; it is decompressed
509 directly to the user's buffer. */
510 unsigned char FAR * postdecompress_inbuf;
511 long postdecompress_inbuflen;
512
513 unsigned char FAR * payload;
514 long payload_grabbed;
515 long payloadlen;
516 long payload_datastart;
517 long payload_datalen;
518
519 uint32 receiver_sequence_number;
520 uint32 sender_sequence_number;
521
522 z_stream compress_stream;
523 z_stream decompress_stream;
524 BOOL compressing;
525 BOOL decompressing;
526 int compression_level;
527
528 SSHPacketHandlerItem FAR * packet_handlers[256];
529 int status_flags;
530
531 int win_cols;
532 int win_rows;
533
534 unsigned short tcpport;
535 } SSHState;
536
537 #define STATUS_DONT_SEND_USER_NAME 0x01
538 #define STATUS_EXPECTING_COMPRESSION_RESPONSE 0x02
539 #define STATUS_DONT_SEND_CREDENTIALS 0x04
540 #define STATUS_HOST_OK 0x08
541 #define STATUS_INTERACTIVE 0x10
542 #define STATUS_IN_PARTIAL_ID_STRING 0x20
543
544 void SSH_init(PTInstVar pvar);
545 void SSH_open(PTInstVar pvar);
546 void SSH_notify_disconnecting(PTInstVar pvar, char FAR * reason);
547 /* SSH_handle_server_ID returns TRUE iff a valid ID string has been
548 received. If it returns FALSE, we need to keep looking for another
549 ID string. */
550 BOOL SSH_handle_server_ID(PTInstVar pvar, char FAR * ID, int ID_len);
551 /* SSH_handle_packet requires NO PAYLOAD on entry.
552 'len' is the size of the packet: payload + padding (+ CRC for SSHv1)
553 'padding' is the size of the padding.
554 'data' points to the start of the packet data (the length field)
555 */
556 void SSH_handle_packet(PTInstVar pvar, char FAR * data, int len, int padding);
557 void SSH_notify_win_size(PTInstVar pvar, int cols, int rows);
558 void SSH_notify_user_name(PTInstVar pvar);
559 void SSH_notify_cred(PTInstVar pvar);
560 void SSH_notify_host_OK(PTInstVar pvar);
561 void SSH_send(PTInstVar pvar, unsigned char const FAR * buf, unsigned int buflen);
562 /* SSH_extract_payload returns number of bytes extracted */
563 int SSH_extract_payload(PTInstVar pvar, unsigned char FAR * dest, int len);
564 void SSH_end(PTInstVar pvar);
565
566 void SSH_get_server_ID_info(PTInstVar pvar, char FAR * dest, int len);
567 void SSH_get_protocol_version_info(PTInstVar pvar, char FAR * dest, int len);
568 void SSH_get_compression_info(PTInstVar pvar, char FAR * dest, int len);
569
570 /* len must be <= SSH_MAX_SEND_PACKET_SIZE */
571 void SSH_channel_send(PTInstVar pvar, int channel_num,
572 uint32 remote_channel_num,
573 unsigned char FAR * buf, int len);
574 void SSH_fail_channel_open(PTInstVar pvar, uint32 remote_channel_num);
575 void SSH_confirm_channel_open(PTInstVar pvar, uint32 remote_channel_num, uint32 local_channel_num);
576 void SSH_channel_output_eof(PTInstVar pvar, uint32 remote_channel_num);
577 void SSH_channel_input_eof(PTInstVar pvar, uint32 remote_channel_num, uint32 local_channel_num);
578 void SSH_request_forwarding(PTInstVar pvar, char FAR * bind_address, int from_server_port,
579 char FAR * to_local_host, int to_local_port);
580 void SSH_request_X11_forwarding(PTInstVar pvar,
581 char FAR * auth_protocol, unsigned char FAR * auth_data, int auth_data_len, int screen_num);
582 void SSH_open_channel(PTInstVar pvar, uint32 local_channel_num,
583 char FAR * to_remote_host, int to_remote_port,
584 char FAR * originator, unsigned short originator_port);
585
586 int SSH_start_scp(PTInstVar pvar, char *sendfile, char *dstfile);
587 int SSH_start_scp_receive(PTInstVar pvar, char *filename);
588 int SSH_scp_transaction(PTInstVar pvar, char *sendfile, char *dstfile, enum scp_dir direction);
589 int SSH_sftp_transaction(PTInstVar pvar);
590
591 /* auxiliary SSH2 interfaces for pkt.c */
592 int SSH_get_min_packet_size(PTInstVar pvar);
593 /* data is guaranteed to be at least SSH_get_min_packet_size bytes long
594 at least 5 bytes must be decrypted */
595 void SSH_predecrpyt_packet(PTInstVar pvar, char FAR * data);
596 int SSH_get_clear_MAC_size(PTInstVar pvar);
597
598 #define SSH_is_any_payload(pvar) ((pvar)->ssh_state.payload_datalen > 0)
599 #define SSH_get_host_name(pvar) ((pvar)->ssh_state.hostname)
600 #define SSH_get_compression_level(pvar) ((pvar)->ssh_state.compressing ? (pvar)->ts_SSH_CompressionLevel : 0)
601
602 void SSH2_send_kexinit(PTInstVar pvar);
603 BOOL do_SSH2_userauth(PTInstVar pvar);
604 BOOL do_SSH2_authrequest(PTInstVar pvar);
605 void debug_print(int no, char *msg, int len);
606 int get_cipher_block_size(SSHCipher cipher);
607 int get_cipher_key_len(SSHCipher cipher);
608 char* get_kex_algorithm_name(kex_algorithm kextype);
609 const EVP_CIPHER* get_cipher_EVP_CIPHER(SSHCipher cipher);
610 const EVP_MD* get_kex_algorithm_EVP_MD(kex_algorithm kextype);
611 char* get_ssh2_mac_name(hmac_type type);
612 const EVP_MD* get_ssh2_mac_EVP_MD(hmac_type type);
613 int get_ssh2_mac_truncatebits(hmac_type type);
614 char* get_ssh2_comp_name(compression_type type);
615 char* get_ssh_keytype_name(ssh_keytype type);
616 int get_cipher_discard_len(SSHCipher cipher);
617 void ssh_heartbeat_lock_initialize(void);
618 void ssh_heartbeat_lock_finalize(void);
619 void ssh_heartbeat_lock(void);
620 void ssh_heartbeat_unlock(void);
621 void halt_ssh_heartbeat_thread(PTInstVar pvar);
622 void ssh2_channel_free(void);
623 BOOL handle_SSH2_userauth_inforeq(PTInstVar pvar);
624 BOOL handle_SSH2_userauth_passwd_changereq(PTInstVar pvar);
625 void SSH2_update_compression_myproposal(PTInstVar pvar);
626 void SSH2_update_cipher_myproposal(PTInstVar pvar);
627 void SSH2_update_kex_myproposal(PTInstVar pvar);
628 void SSH2_update_host_key_myproposal(PTInstVar pvar);
629 void SSH2_update_hmac_myproposal(PTInstVar pvar);
630 int SSH_notify_break_signal(PTInstVar pvar);
631
632 #endif

Back to OSDN">Back to OSDN
ViewVC Help
Powered by ViewVC 1.1.26