diff options
author | Dr. David von Oheimb <David.von.Oheimb@siemens.com> | 2021-12-25 13:38:23 +0100 |
---|---|---|
committer | Dr. David von Oheimb <dev@ddvo.net> | 2023-05-30 22:02:10 +0200 |
commit | 36b91a198ae027c054ef128a35a268bc3c307f00 (patch) | |
tree | a47bf3a4c012fb34c51c8c34f973e15dc912f9b4 /crypto/pkcs7 | |
parent | fdef95716dbcc6127d05f8cfc90f389a84acaf9b (diff) |
CMS, PKCS7, and CRMF: simplify use of EVP_PKEY_decrypt() by helper function
Also remove needless constant_time_* and ERR_clear_error() calls
from OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert().
Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com>
(Merged from https://github.com/openssl/openssl/pull/17354)
Diffstat (limited to 'crypto/pkcs7')
-rw-r--r-- | crypto/pkcs7/pk7_doit.c | 19 |
1 files changed, 4 insertions, 15 deletions
diff --git a/crypto/pkcs7/pk7_doit.c b/crypto/pkcs7/pk7_doit.c index e39821a205..d3f65adb66 100644 --- a/crypto/pkcs7/pk7_doit.c +++ b/crypto/pkcs7/pk7_doit.c @@ -15,6 +15,7 @@ #include <openssl/err.h> #include "internal/cryptlib.h" #include "internal/sizes.h" +#include "crypto/evp.h" #include "pk7_local.h" static int add_attribute(STACK_OF(X509_ATTRIBUTE) **sk, int nid, int atrtype, @@ -174,23 +175,11 @@ static int pkcs7_decrypt_rinfo(unsigned char **pek, int *peklen, * disable implicit rejection for RSA keys */ EVP_PKEY_CTX_ctrl_str(pctx, "rsa_pkcs1_implicit_rejection", "0"); - if (EVP_PKEY_decrypt(pctx, NULL, &eklen, - ri->enc_key->data, ri->enc_key->length) <= 0) + ret = evp_pkey_decrypt_alloc(pctx, &ek, &eklen, fixlen, + ri->enc_key->data, ri->enc_key->length); + if (ret <= 0) goto err; - ek = OPENSSL_malloc(eklen); - if (ek == NULL) - goto err; - - if (EVP_PKEY_decrypt(pctx, ek, &eklen, - ri->enc_key->data, ri->enc_key->length) <= 0 - || eklen == 0 - || (fixlen != 0 && eklen != fixlen)) { - ret = 0; - ERR_raise(ERR_LIB_PKCS7, ERR_R_EVP_LIB); - goto err; - } - ret = 1; OPENSSL_clear_free(*pek, *peklen); |