Leaked source code of windows server 2003
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

1232 lines
35 KiB

  1. //+-------------------------------------------------------------------------
  2. //
  3. // Microsoft Windows
  4. //
  5. // Copyright (C) Microsoft Corporation, 1995 - 1999
  6. //
  7. // File: pvkhlpr.cpp
  8. //
  9. // Contents: Private Key Helper APIs
  10. //
  11. // Functions: PrivateKeyLoad
  12. // PrivateKeySave
  13. // PrivateKeyLoadFromMemory
  14. // PrivateKeySaveToMemory
  15. // PrivateKeyAcquireContextFromMemory
  16. // PrivateKeyReleaseContext
  17. //
  18. // Note: Base CSP also exports/imports the public key with the
  19. // private key.
  20. //
  21. // History: 10-May-96 philh created
  22. //--------------------------------------------------------------------------
  23. #include <windows.h>
  24. #include <assert.h>
  25. #include "wincrypt.h"
  26. #include "pvk.h"
  27. #include "unicode.h"
  28. #include <string.h>
  29. #include <memory.h>
  30. //+-------------------------------------------------------------------------
  31. // Private Key file definitions
  32. //
  33. // The file consists of the FILE_HDR followed by cbEncryptData optional
  34. // bytes used to encrypt the private key and then the private key.
  35. // The private key is encrypted according to dwEncryptType.
  36. //
  37. // The public key is included with the private key.
  38. //--------------------------------------------------------------------------
  39. typedef struct _FILE_HDR {
  40. DWORD dwMagic;
  41. DWORD dwVersion;
  42. DWORD dwKeySpec;
  43. DWORD dwEncryptType;
  44. DWORD cbEncryptData;
  45. DWORD cbPvk;
  46. } FILE_HDR, *PFILE_HDR;
  47. #define PVK_FILE_VERSION_0 0
  48. #define PVK_MAGIC 0xb0b5f11e
  49. // Private key encrypt types
  50. #define PVK_NO_ENCRYPT 0
  51. #define PVK_RC4_PASSWORD_ENCRYPT 1
  52. #define PVK_RC2_CBC_PASSWORD_ENCRYPT 2
  53. #define MAX_PVK_FILE_LEN 4096
  54. #define MAX_BOB_FILE_LEN (4096*4)
  55. typedef BOOL (* PFNWRITE)(HANDLE h, void * p, DWORD cb);
  56. typedef BOOL (* PFNREAD)(HANDLE h, void * p, DWORD cb);
  57. //+-------------------------------------------------------------------------
  58. // Private key helper allocation and free functions
  59. //--------------------------------------------------------------------------
  60. void *PvkAlloc(
  61. IN size_t cbBytes
  62. )
  63. {
  64. void *pv;
  65. pv = malloc(cbBytes);
  66. if (pv == NULL)
  67. SetLastError(ERROR_NOT_ENOUGH_MEMORY);
  68. return pv;
  69. }
  70. void PvkFree(
  71. IN void *pv
  72. )
  73. {
  74. free(pv);
  75. }
  76. //+-------------------------------------------------------------------------
  77. // Read & Write to file function
  78. //--------------------------------------------------------------------------
  79. static BOOL WriteToFile(HANDLE h, void * p, DWORD cb) {
  80. DWORD cbBytesWritten;
  81. return(WriteFile(h, p, cb, &cbBytesWritten, NULL));
  82. }
  83. static BOOL ReadFromFile(
  84. IN HANDLE h,
  85. IN void * p,
  86. IN DWORD cb
  87. )
  88. {
  89. DWORD cbBytesRead;
  90. return(ReadFile(h, p, cb, &cbBytesRead, NULL) && cbBytesRead == cb);
  91. }
  92. //+-------------------------------------------------------------------------
  93. // Read & Write to memory fucntion
  94. //--------------------------------------------------------------------------
  95. typedef struct _MEMINFO {
  96. BYTE * pb;
  97. DWORD cb;
  98. DWORD cbSeek;
  99. } MEMINFO, * PMEMINFO;
  100. static BOOL WriteToMemory(HANDLE h, void * p, DWORD cb) {
  101. PMEMINFO pMemInfo = (PMEMINFO) h;
  102. // See if we have room. The caller will detect an error after the final
  103. // write
  104. if(pMemInfo->cbSeek + cb <= pMemInfo->cb)
  105. // copy the bytes
  106. memcpy(&pMemInfo->pb[pMemInfo->cbSeek], p, cb);
  107. pMemInfo->cbSeek += cb;
  108. return(TRUE);
  109. }
  110. static BOOL ReadFromMemory(
  111. IN HANDLE h,
  112. IN void * p,
  113. IN DWORD cb
  114. )
  115. {
  116. PMEMINFO pMemInfo = (PMEMINFO) h;
  117. if (pMemInfo->cbSeek + cb <= pMemInfo->cb) {
  118. // copy the bytes
  119. memcpy(p, &pMemInfo->pb[pMemInfo->cbSeek], cb);
  120. pMemInfo->cbSeek += cb;
  121. return TRUE;
  122. } else {
  123. SetLastError(ERROR_END_OF_MEDIA);
  124. return FALSE;
  125. }
  126. }
  127. static BOOL GetPasswordKey(
  128. IN HCRYPTPROV hProv,
  129. IN ALG_ID Algid,
  130. IN PASSWORD_TYPE PasswordType,
  131. IN HWND hwndOwner,
  132. IN LPCWSTR pwszKeyName,
  133. IN BOOL fNoPassDlg,
  134. IN BYTE *pbSalt,
  135. IN DWORD cbSalt,
  136. OUT HCRYPTKEY *phEncryptKey
  137. )
  138. {
  139. BOOL fResult;
  140. BYTE *pbAllocPassword = NULL;
  141. BYTE *pbPassword;
  142. DWORD cbPassword;
  143. HCRYPTHASH hHash = 0;
  144. HCRYPTKEY hEncryptKey = 0;
  145. BYTE rgbPwdBuffer[] = {67, 82, 65, 80};
  146. if (fNoPassDlg) {
  147. pbPassword = rgbPwdBuffer;
  148. cbPassword = sizeof(rgbPwdBuffer);
  149. } else {
  150. if (IDOK != PvkDlgGetKeyPassword(
  151. PasswordType,
  152. hwndOwner,
  153. pwszKeyName,
  154. &pbAllocPassword,
  155. &cbPassword
  156. )) {
  157. SetLastError(PVK_HELPER_PASSWORD_CANCEL);
  158. goto ErrorReturn;
  159. }
  160. pbPassword = pbAllocPassword;
  161. }
  162. if (cbPassword) {
  163. if (!CryptCreateHash(hProv, CALG_SHA, 0, 0, &hHash))
  164. goto ErrorReturn;
  165. if (cbSalt) {
  166. if (!CryptHashData(hHash, pbSalt, cbSalt, 0))
  167. goto ErrorReturn;
  168. }
  169. if (!CryptHashData(hHash, pbPassword, cbPassword, 0))
  170. goto ErrorReturn;
  171. if (!CryptDeriveKey(hProv, Algid, hHash, 0, &hEncryptKey))
  172. goto ErrorReturn;
  173. }
  174. fResult = TRUE;
  175. goto CommonReturn;
  176. ErrorReturn:
  177. fResult = FALSE;
  178. if (hEncryptKey) {
  179. CryptDestroyKey(hEncryptKey);
  180. hEncryptKey = 0;
  181. }
  182. CommonReturn:
  183. if (pbAllocPassword)
  184. PvkFree(pbAllocPassword);
  185. if (hHash)
  186. CryptDestroyHash(hHash);
  187. *phEncryptKey = hEncryptKey;
  188. return fResult;
  189. }
  190. // Support backwards compatibility with Bob's storage file which contains
  191. // a snap shot of the keys as they are stored in the registry. Note, for
  192. // win95, the registry values are decrypted before being written to the file.
  193. static BOOL LoadBobKey(
  194. IN HCRYPTPROV hCryptProv,
  195. IN HANDLE hRead,
  196. IN PFNREAD pfnRead,
  197. IN DWORD cbBobKey,
  198. IN HWND hwndOwner,
  199. IN LPCWSTR pwszKeyName,
  200. IN DWORD dwFlags,
  201. IN OUT OPTIONAL DWORD *pdwKeySpec,
  202. IN PFILE_HDR pHdr // header has already been read
  203. );
  204. static BOOL LoadKey(
  205. IN HCRYPTPROV hCryptProv,
  206. IN HANDLE hRead,
  207. IN PFNREAD pfnRead,
  208. IN DWORD cbKeyData,
  209. IN HWND hwndOwner,
  210. IN LPCWSTR pwszKeyName,
  211. IN DWORD dwFlags,
  212. IN OUT OPTIONAL DWORD *pdwKeySpec
  213. )
  214. {
  215. BOOL fResult;
  216. FILE_HDR Hdr;
  217. HCRYPTKEY hDecryptKey = 0;
  218. HCRYPTKEY hKey = 0;
  219. BYTE *pbEncryptData = NULL;
  220. BYTE *pbPvk = NULL;
  221. DWORD cbPvk;
  222. // Read the file header and verify
  223. if (!pfnRead(hRead, &Hdr, sizeof(Hdr))) goto BadPvkFile;
  224. if (Hdr.dwMagic != PVK_MAGIC)
  225. // Try to load as Bob's storage file containing streams for the
  226. // private and public keys. Bob made a copy of the cryptography
  227. // registry key values.
  228. //
  229. // Note, Bob now has two different formats for storing the private
  230. // key information. See LoadBobKey for details.
  231. fResult = LoadBobKey(hCryptProv, hRead, pfnRead, cbKeyData, hwndOwner,
  232. pwszKeyName, dwFlags, pdwKeySpec, &Hdr);
  233. else {
  234. // Treat as a "normal" private key file
  235. cbPvk = Hdr.cbPvk;
  236. if (Hdr.dwVersion != PVK_FILE_VERSION_0 ||
  237. Hdr.cbEncryptData > MAX_PVK_FILE_LEN ||
  238. cbPvk == 0 || cbPvk > MAX_PVK_FILE_LEN)
  239. goto BadPvkFile;
  240. if (pdwKeySpec) {
  241. DWORD dwKeySpec = *pdwKeySpec;
  242. *pdwKeySpec = Hdr.dwKeySpec;
  243. if (dwKeySpec && dwKeySpec != Hdr.dwKeySpec) {
  244. SetLastError(PVK_HELPER_WRONG_KEY_TYPE);
  245. goto ErrorReturn;
  246. }
  247. }
  248. if (Hdr.cbEncryptData) {
  249. // Read the encrypt data
  250. if (NULL == (pbEncryptData = (BYTE *) PvkAlloc(Hdr.cbEncryptData)))
  251. goto ErrorReturn;
  252. if (!pfnRead(hRead, pbEncryptData, Hdr.cbEncryptData))
  253. goto BadPvkFile;
  254. }
  255. // Allocate and read the private key
  256. if (NULL == (pbPvk = (BYTE *) PvkAlloc(cbPvk)))
  257. goto ErrorReturn;
  258. if (!pfnRead(hRead, pbPvk, cbPvk))
  259. goto BadPvkFile;
  260. // Get symmetric key to decrypt the private key
  261. switch (Hdr.dwEncryptType) {
  262. case PVK_NO_ENCRYPT:
  263. break;
  264. case PVK_RC4_PASSWORD_ENCRYPT:
  265. if (!GetPasswordKey(hCryptProv, CALG_RC4,
  266. ENTER_PASSWORD, hwndOwner,
  267. pwszKeyName, FALSE, pbEncryptData, Hdr.cbEncryptData,
  268. &hDecryptKey))
  269. goto ErrorReturn;
  270. break;
  271. case PVK_RC2_CBC_PASSWORD_ENCRYPT:
  272. if (!GetPasswordKey(hCryptProv, CALG_RC2,
  273. ENTER_PASSWORD, hwndOwner,
  274. pwszKeyName, FALSE, pbEncryptData, Hdr.cbEncryptData,
  275. &hDecryptKey))
  276. goto ErrorReturn;
  277. break;
  278. default:
  279. goto BadPvkFile;
  280. }
  281. // Decrypt and import the private key
  282. if (!CryptImportKey(hCryptProv, pbPvk, cbPvk, hDecryptKey, dwFlags,
  283. &hKey))
  284. goto ErrorReturn;
  285. fResult = TRUE;
  286. }
  287. goto CommonReturn;
  288. BadPvkFile:
  289. SetLastError(PVK_HELPER_BAD_PVK_FILE);
  290. if (pdwKeySpec)
  291. *pdwKeySpec = 0;
  292. ErrorReturn:
  293. fResult = FALSE;
  294. CommonReturn:
  295. if (pbEncryptData)
  296. PvkFree(pbEncryptData);
  297. if (pbPvk)
  298. PvkFree(pbPvk);
  299. if (hDecryptKey)
  300. CryptDestroyKey(hDecryptKey);
  301. if (hKey)
  302. CryptDestroyKey(hKey);
  303. return fResult;
  304. }
  305. static BOOL SaveKey(
  306. IN HCRYPTPROV hCryptProv,
  307. IN HANDLE hWrite,
  308. IN PFNREAD pfnWrite,
  309. IN DWORD dwKeySpec, // either AT_SIGNATURE or AT_KEYEXCHANGE
  310. IN HWND hwndOwner,
  311. IN LPCWSTR pwszKeyName,
  312. IN DWORD dwFlags,
  313. IN BOOL fNoPassDlg
  314. )
  315. {
  316. BOOL fResult;
  317. FILE_HDR Hdr;
  318. HCRYPTKEY hEncryptKey = 0;
  319. HCRYPTKEY hKey = 0;
  320. BYTE *pbEncryptData = NULL; // Not allocated
  321. BYTE *pbPvk = NULL;
  322. DWORD cbPvk;
  323. BYTE rgbSalt[16];
  324. // Initialize the header record
  325. memset(&Hdr, 0, sizeof(Hdr));
  326. Hdr.dwMagic = PVK_MAGIC;
  327. Hdr.dwVersion = PVK_FILE_VERSION_0;
  328. Hdr.dwKeySpec = dwKeySpec;
  329. // Generate random salt
  330. if (!CryptGenRandom(hCryptProv, sizeof(rgbSalt), rgbSalt))
  331. goto ErrorReturn;
  332. // Get symmetric key to use to encrypt the private key
  333. #if 1
  334. if (!GetPasswordKey(hCryptProv, CALG_RC4,
  335. #else
  336. if (!GetPasswordKey(hCryptProv, CALG_RC2,
  337. #endif
  338. CREATE_PASSWORD, hwndOwner, pwszKeyName,
  339. fNoPassDlg, rgbSalt, sizeof(rgbSalt), &hEncryptKey))
  340. goto ErrorReturn;
  341. if (hEncryptKey) {
  342. #if 1
  343. Hdr.dwEncryptType = PVK_RC4_PASSWORD_ENCRYPT;
  344. #else
  345. Hdr.dwEncryptType = PVK_RC2_CBC_PASSWORD_ENCRYPT;
  346. #endif
  347. Hdr.cbEncryptData = sizeof(rgbSalt);
  348. pbEncryptData = rgbSalt;
  349. } else
  350. Hdr.dwEncryptType = PVK_NO_ENCRYPT;
  351. // Allocate, encrypt and export the private key
  352. if (!CryptGetUserKey(hCryptProv, dwKeySpec, &hKey))
  353. goto ErrorReturn;
  354. cbPvk = 0;
  355. if (!CryptExportKey(hKey, hEncryptKey, PRIVATEKEYBLOB, dwFlags, NULL,
  356. &cbPvk))
  357. goto ErrorReturn;
  358. if (NULL == (pbPvk = (BYTE *) PvkAlloc(cbPvk)))
  359. goto ErrorReturn;
  360. if (!CryptExportKey(hKey, hEncryptKey, PRIVATEKEYBLOB, dwFlags, pbPvk,
  361. &cbPvk))
  362. goto ErrorReturn;
  363. Hdr.cbPvk = cbPvk;
  364. // Write the header, optional encrypt data, and private key to the file
  365. if (!pfnWrite(hWrite, &Hdr, sizeof(Hdr)))
  366. goto ErrorReturn;
  367. if (Hdr.cbEncryptData) {
  368. if (!pfnWrite(hWrite, pbEncryptData, Hdr.cbEncryptData))
  369. goto ErrorReturn;
  370. }
  371. if (!pfnWrite(hWrite, pbPvk, cbPvk))
  372. goto ErrorReturn;
  373. fResult = TRUE;
  374. goto CommonReturn;
  375. ErrorReturn:
  376. fResult = FALSE;
  377. CommonReturn:
  378. if (pbPvk)
  379. PvkFree(pbPvk);
  380. if (hEncryptKey)
  381. CryptDestroyKey(hEncryptKey);
  382. if (hKey)
  383. CryptDestroyKey(hKey);
  384. return fResult;
  385. }
  386. //+-------------------------------------------------------------------------
  387. // Load the AT_SIGNATURE or AT_KEYEXCHANGE private key (and its public key)
  388. // from the file into the cryptographic provider.
  389. //
  390. // If the private key was password encrypted, then, the user is first
  391. // presented with a dialog box to enter the password.
  392. //
  393. // If pdwKeySpec is non-Null, then, if *pdwKeySpec is nonzero, verifies the
  394. // key type before loading. Sets LastError to PVK_HELPER_WRONG_KEY_TYPE for
  395. // a mismatch. *pdwKeySpec is updated with the key type.
  396. //
  397. // dwFlags is passed through to CryptImportKey.
  398. //--------------------------------------------------------------------------
  399. BOOL
  400. WINAPI
  401. PrivateKeyLoad(
  402. IN HCRYPTPROV hCryptProv,
  403. IN HANDLE hFile,
  404. IN HWND hwndOwner,
  405. IN LPCWSTR pwszKeyName,
  406. IN DWORD dwFlags,
  407. IN OUT OPTIONAL DWORD *pdwKeySpec
  408. )
  409. {
  410. return LoadKey(
  411. hCryptProv,
  412. hFile,
  413. ReadFromFile,
  414. GetFileSize(hFile, NULL),
  415. hwndOwner,
  416. pwszKeyName,
  417. dwFlags,
  418. pdwKeySpec
  419. );
  420. }
  421. //+-------------------------------------------------------------------------
  422. // Save the AT_SIGNATURE or AT_KEYEXCHANGE private key (and its public key)
  423. // to the specified file.
  424. //
  425. // The user is presented with a dialog box to enter an optional password to
  426. // encrypt the private key.
  427. //
  428. // dwFlags is passed through to CryptExportKey.
  429. //--------------------------------------------------------------------------
  430. BOOL
  431. WINAPI
  432. PrivateKeySave(
  433. IN HCRYPTPROV hCryptProv,
  434. IN HANDLE hFile,
  435. IN DWORD dwKeySpec, // either AT_SIGNATURE or AT_KEYEXCHANGE
  436. IN HWND hwndOwner,
  437. IN LPCWSTR pwszKeyName,
  438. IN DWORD dwFlags
  439. )
  440. {
  441. return SaveKey(
  442. hCryptProv,
  443. hFile,
  444. WriteToFile,
  445. dwKeySpec,
  446. hwndOwner,
  447. pwszKeyName,
  448. dwFlags,
  449. FALSE // fNoPassDlg
  450. );
  451. }
  452. //+-------------------------------------------------------------------------
  453. // Load the AT_SIGNATURE or AT_KEYEXCHANGE private key (and its public key)
  454. // from memory into the cryptographic provider.
  455. //
  456. // Except for the key being loaded from memory, identical to PrivateKeyLoad.
  457. //--------------------------------------------------------------------------
  458. BOOL
  459. WINAPI
  460. PrivateKeyLoadFromMemory(
  461. IN HCRYPTPROV hCryptProv,
  462. IN BYTE *pbData,
  463. IN DWORD cbData,
  464. IN HWND hwndOwner,
  465. IN LPCWSTR pwszKeyName,
  466. IN DWORD dwFlags,
  467. IN OUT OPTIONAL DWORD *pdwKeySpec
  468. )
  469. {
  470. MEMINFO MemInfo;
  471. MemInfo.pb = pbData;
  472. MemInfo.cb = cbData;
  473. MemInfo.cbSeek = 0;
  474. return LoadKey(
  475. hCryptProv,
  476. (HANDLE) &MemInfo,
  477. ReadFromMemory,
  478. cbData,
  479. hwndOwner,
  480. pwszKeyName,
  481. dwFlags,
  482. pdwKeySpec
  483. );
  484. }
  485. //+-------------------------------------------------------------------------
  486. // Save the AT_SIGNATURE or AT_KEYEXCHANGE private key (and its public key)
  487. // to memory.
  488. //
  489. // If pbData == NULL || *pcbData == 0, calculates the length and doesn't
  490. // return an error (also, the user isn't prompted for a password).
  491. //
  492. // Except for the key being saved to memory, identical to PrivateKeySave.
  493. //--------------------------------------------------------------------------
  494. BOOL
  495. WINAPI
  496. PrivateKeySaveToMemory(
  497. IN HCRYPTPROV hCryptProv,
  498. IN DWORD dwKeySpec, // either AT_SIGNATURE or AT_KEYEXCHANGE
  499. IN HWND hwndOwner,
  500. IN LPCWSTR pwszKeyName,
  501. IN DWORD dwFlags,
  502. OUT BYTE *pbData,
  503. IN OUT DWORD *pcbData
  504. )
  505. {
  506. BOOL fResult;
  507. MEMINFO MemInfo;
  508. MemInfo.pb = pbData;
  509. if (pbData == NULL)
  510. *pcbData = 0;
  511. MemInfo.cb = *pcbData;
  512. MemInfo.cbSeek = 0;
  513. fResult = SaveKey(
  514. hCryptProv,
  515. (HANDLE) &MemInfo,
  516. WriteToMemory,
  517. dwKeySpec,
  518. hwndOwner,
  519. pwszKeyName,
  520. dwFlags,
  521. *pcbData == 0 // fNoPassDlg
  522. );
  523. if (fResult) {
  524. if (MemInfo.cbSeek > MemInfo.cb && *pcbData) {
  525. fResult = FALSE;
  526. SetLastError(ERROR_END_OF_MEDIA);
  527. }
  528. *pcbData = MemInfo.cbSeek;
  529. } else
  530. *pcbData = 0;
  531. return fResult;
  532. }
  533. //+-------------------------------------------------------------------------
  534. // Converts the bytes into WCHAR hex
  535. //
  536. // Needs (cb * 2 + 1) * sizeof(WCHAR) bytes of space in wsz
  537. //--------------------------------------------------------------------------
  538. static void BytesToWStr(ULONG cb, void* pv, LPWSTR wsz)
  539. {
  540. BYTE* pb = (BYTE*) pv;
  541. for (ULONG i = 0; i<cb; i++) {
  542. BYTE b;
  543. b = (*pb & 0xF0) >> 4;
  544. *wsz++ = (WCHAR)((b <= 9) ? b + L'0' : (b - 10) + L'A');
  545. b = *pb & 0x0F;
  546. *wsz++ = (WCHAR)((b <= 9) ? b + L'0' : (b - 10) + L'A');
  547. pb++;
  548. }
  549. *wsz++ = 0;
  550. }
  551. #define UUID_WSTR_BYTES ((sizeof(UUID) * 2 + 1) * sizeof(WCHAR))
  552. static BOOL AcquireKeyContext(
  553. IN LPCWSTR pwszProvName,
  554. IN DWORD dwProvType,
  555. IN HANDLE hRead,
  556. IN PFNREAD pfnRead,
  557. IN DWORD cbKeyData,
  558. IN HWND hwndOwner,
  559. IN LPCWSTR pwszKeyName,
  560. IN OUT OPTIONAL DWORD *pdwKeySpec,
  561. OUT HCRYPTPROV *phCryptProv,
  562. OUT LPWSTR *ppwszTmpContainer
  563. )
  564. {
  565. BOOL fResult;
  566. HCRYPTPROV hProv = 0;
  567. UUID TmpContainerUuid;
  568. LPWSTR pwszTmpContainer = NULL;
  569. RPC_STATUS rpc_status;
  570. // Create a temporary keyset to load the private key into
  571. rpc_status = UuidCreate(&TmpContainerUuid);
  572. if (RPC_S_OK != rpc_status && RPC_S_UUID_LOCAL_ONLY != rpc_status)
  573. {
  574. //hr = rpc_status;
  575. goto ErrorReturn;
  576. }
  577. if (NULL == (pwszTmpContainer = (LPWSTR) PvkAlloc(
  578. 6 * sizeof(WCHAR) + UUID_WSTR_BYTES)))
  579. goto ErrorReturn;
  580. wcscpy(pwszTmpContainer, L"TmpKey");
  581. BytesToWStr(sizeof(UUID), &TmpContainerUuid, pwszTmpContainer + 6);
  582. if (!CryptAcquireContextU(
  583. &hProv,
  584. pwszTmpContainer,
  585. pwszProvName,
  586. dwProvType,
  587. CRYPT_NEWKEYSET
  588. ))
  589. goto ErrorReturn;
  590. if (!LoadKey(
  591. hProv,
  592. hRead,
  593. pfnRead,
  594. cbKeyData,
  595. hwndOwner,
  596. pwszKeyName,
  597. 0, // dwFlags
  598. pdwKeySpec
  599. ))
  600. goto DeleteKeySetReturn;
  601. fResult = TRUE;
  602. goto CommonReturn;
  603. DeleteKeySetReturn:
  604. CryptReleaseContext(hProv, 0);
  605. CryptAcquireContextU(
  606. &hProv,
  607. pwszTmpContainer,
  608. pwszProvName,
  609. dwProvType,
  610. CRYPT_DELETEKEYSET
  611. );
  612. hProv = 0;
  613. ErrorReturn:
  614. if (hProv) {
  615. CryptReleaseContext(hProv, 0);
  616. hProv = 0;
  617. }
  618. if (pwszTmpContainer) {
  619. PvkFree(pwszTmpContainer);
  620. pwszTmpContainer = NULL;
  621. }
  622. fResult = FALSE;
  623. CommonReturn:
  624. *ppwszTmpContainer = pwszTmpContainer;
  625. *phCryptProv = hProv;
  626. return fResult;
  627. }
  628. //+-------------------------------------------------------------------------
  629. // Creates a temporary container in the provider and loads the private key
  630. // from the specified file.
  631. // For success, returns a handle to a cryptographic provider for the private
  632. // key and the name of the temporary container. PrivateKeyReleaseContext must
  633. // be called to release the hCryptProv and delete the temporary container.
  634. //
  635. // PrivateKeyLoad is called to load the private key into the temporary
  636. // container.
  637. //--------------------------------------------------------------------------
  638. BOOL
  639. WINAPI
  640. PrivateKeyAcquireContext(
  641. IN LPCWSTR pwszProvName,
  642. IN DWORD dwProvType,
  643. IN HANDLE hFile,
  644. IN HWND hwndOwner,
  645. IN LPCWSTR pwszKeyName,
  646. IN OUT OPTIONAL DWORD *pdwKeySpec,
  647. OUT HCRYPTPROV *phCryptProv,
  648. OUT LPWSTR *ppwszTmpContainer
  649. )
  650. {
  651. return AcquireKeyContext(
  652. pwszProvName,
  653. dwProvType,
  654. hFile,
  655. ReadFromFile,
  656. GetFileSize(hFile, NULL),
  657. hwndOwner,
  658. pwszKeyName,
  659. pdwKeySpec,
  660. phCryptProv,
  661. ppwszTmpContainer
  662. );
  663. }
  664. //+-------------------------------------------------------------------------
  665. // Creates a temporary container in the provider and loads the private key
  666. // from memory.
  667. // For success, returns a handle to a cryptographic provider for the private
  668. // key and the name of the temporary container. PrivateKeyReleaseContext must
  669. // be called to release the hCryptProv and delete the temporary container.
  670. //
  671. // PrivateKeyLoadFromMemory is called to load the private key into the
  672. // temporary container.
  673. //--------------------------------------------------------------------------
  674. BOOL
  675. WINAPI
  676. PrivateKeyAcquireContextFromMemory(
  677. IN LPCWSTR pwszProvName,
  678. IN DWORD dwProvType,
  679. IN BYTE *pbData,
  680. IN DWORD cbData,
  681. IN HWND hwndOwner,
  682. IN LPCWSTR pwszKeyName,
  683. IN OUT OPTIONAL DWORD *pdwKeySpec,
  684. OUT HCRYPTPROV *phCryptProv,
  685. OUT LPWSTR *ppwszTmpContainer
  686. )
  687. {
  688. MEMINFO MemInfo;
  689. MemInfo.pb = pbData;
  690. MemInfo.cb = cbData;
  691. MemInfo.cbSeek = 0;
  692. return AcquireKeyContext(
  693. pwszProvName,
  694. dwProvType,
  695. (HANDLE) &MemInfo,
  696. ReadFromMemory,
  697. cbData,
  698. hwndOwner,
  699. pwszKeyName,
  700. pdwKeySpec,
  701. phCryptProv,
  702. ppwszTmpContainer
  703. );
  704. }
  705. //+-------------------------------------------------------------------------
  706. // Releases the cryptographic provider and deletes the temporary container
  707. // created by PrivateKeyAcquireContext or PrivateKeyAcquireContextFromMemory.
  708. //--------------------------------------------------------------------------
  709. BOOL
  710. WINAPI
  711. PrivateKeyReleaseContext(
  712. IN HCRYPTPROV hCryptProv,
  713. IN LPCWSTR pwszProvName,
  714. IN DWORD dwProvType,
  715. IN LPWSTR pwszTmpContainer
  716. )
  717. {
  718. if (hCryptProv)
  719. CryptReleaseContext(hCryptProv, 0);
  720. if (pwszTmpContainer) {
  721. // Delete the temporary container for the private key from
  722. // the provider
  723. //
  724. // Note: for CRYPT_DELETEKEYSET, the returned hCryptProv is undefined
  725. // and must not be released.
  726. CryptAcquireContextU(
  727. &hCryptProv,
  728. pwszTmpContainer,
  729. pwszProvName,
  730. dwProvType,
  731. CRYPT_DELETEKEYSET
  732. );
  733. PvkFree(pwszTmpContainer);
  734. }
  735. return TRUE;
  736. }
  737. //+-------------------------------------------------------------------------
  738. // Functions supporting backwards compatibility with Bob's storage file
  739. // containing a snap shot of the keys as they are stored in the registry.
  740. // Note, for win95, the registry values are decrypted before being written to
  741. // the file.
  742. //--------------------------------------------------------------------------
  743. // Return the size of this stream; return 0 if an error
  744. static DWORD CbBobSize(IStream *pStm)
  745. {
  746. STATSTG stat;
  747. if (FAILED(pStm->Stat(&stat, STATFLAG_NONAME)))
  748. return 0;
  749. return stat.cbSize.LowPart;
  750. }
  751. // Allocate and read this value which has the indicated stream name from the
  752. // storage
  753. static BOOL LoadBobStream(
  754. IStorage *pStg,
  755. LPCWSTR pwszStm,
  756. BYTE **ppbValue,
  757. DWORD *pcbValue
  758. )
  759. {
  760. BOOL fResult;
  761. HRESULT hr;
  762. IStream *pStm = NULL;
  763. BYTE *pbValue = NULL;
  764. DWORD cbValue;
  765. DWORD cbRead;
  766. if (FAILED(hr = pStg->OpenStream(pwszStm, 0,
  767. STGM_READ | STGM_SHARE_EXCLUSIVE, 0, &pStm)))
  768. goto HrError;
  769. if (0 == (cbValue = CbBobSize(pStm))) goto BadBobFile;
  770. if (NULL == (pbValue = (BYTE *) PvkAlloc(cbValue))) goto ErrorReturn;
  771. pStm->Read(pbValue, cbValue, &cbRead);
  772. if (cbRead != cbValue) goto BadBobFile;
  773. fResult = TRUE;
  774. goto CommonReturn;
  775. HrError:
  776. SetLastError((DWORD) hr);
  777. goto ErrorReturn;
  778. BadBobFile:
  779. SetLastError(PVK_HELPER_BAD_PVK_FILE);
  780. ErrorReturn:
  781. if (pbValue) {
  782. PvkFree(pbValue);
  783. pbValue = NULL;
  784. }
  785. cbValue = 0;
  786. fResult = FALSE;
  787. CommonReturn:
  788. if (pStm)
  789. pStm->Release();
  790. *ppbValue = pbValue;
  791. *pcbValue = cbValue;
  792. return fResult;
  793. }
  794. // New "Bob" format::
  795. //
  796. // Allocate and read either the Exported Signature or Exchange Private
  797. // key stream from the storage
  798. static BOOL LoadBobExportedPvk(
  799. IStorage *pStg,
  800. DWORD dwKeySpec,
  801. BYTE **ppbPvkValue,
  802. DWORD *pcbPvkValue
  803. )
  804. {
  805. BOOL fResult;
  806. LPCWSTR pwszPvk;
  807. switch (dwKeySpec) {
  808. case AT_SIGNATURE:
  809. pwszPvk = L"Exported Signature Private Key";
  810. break;
  811. case AT_KEYEXCHANGE:
  812. pwszPvk = L"Exported Exchange Private Key";
  813. break;
  814. default:
  815. SetLastError(PVK_HELPER_BAD_PARAMETER);
  816. goto ErrorReturn;
  817. }
  818. fResult = LoadBobStream(pStg, pwszPvk, ppbPvkValue, pcbPvkValue);
  819. if (fResult) goto CommonReturn;
  820. ErrorReturn:
  821. *ppbPvkValue = NULL;
  822. *pcbPvkValue = 0;
  823. fResult = FALSE;
  824. CommonReturn:
  825. return fResult;
  826. }
  827. // Old "Bob" format::
  828. //
  829. // Allocate and read either the Signature or Exchange Private
  830. // key streams from the storage
  831. static BOOL LoadBobOldPvk(
  832. IStorage *pStg,
  833. DWORD dwKeySpec,
  834. BYTE **ppbPvkValue,
  835. DWORD *pcbPvkValue
  836. )
  837. {
  838. BOOL fResult;
  839. LPCWSTR pwszPvk;
  840. switch (dwKeySpec) {
  841. case AT_SIGNATURE:
  842. pwszPvk = L"SPvk";
  843. break;
  844. case AT_KEYEXCHANGE:
  845. pwszPvk = L"EPvk";
  846. break;
  847. default:
  848. SetLastError(PVK_HELPER_BAD_PARAMETER);
  849. goto ErrorReturn;
  850. }
  851. fResult = LoadBobStream(pStg, pwszPvk, ppbPvkValue, pcbPvkValue);
  852. if (fResult) goto CommonReturn;
  853. ErrorReturn:
  854. *ppbPvkValue = NULL;
  855. *pcbPvkValue = 0;
  856. fResult = FALSE;
  857. CommonReturn:
  858. return fResult;
  859. }
  860. ///////////////////////////////////////////////////////////////////////////////////////
  861. //
  862. // Key header structures for private key construction
  863. //
  864. // These structs define the fixed data at the beginning of an RSA key.
  865. // They are followed by a variable length of data, sized by the stlen
  866. // field.
  867. //
  868. // For more info see Jeff Spellman in the crypto team or look in the
  869. // source to RsaBase.Dll
  870. //
  871. typedef struct {
  872. DWORD magic; /* Should always be RSA2 */
  873. DWORD keylen; // size of modulus buffer
  874. DWORD bitlen; // bit size of key
  875. DWORD datalen; // max number of bytes to be encoded
  876. DWORD pubexp; // public exponent
  877. } BSAFE_PRV_KEY, FAR *LPBSAFE_PRV_KEY;
  878. typedef struct {
  879. BYTE *modulus;
  880. BYTE *prvexp;
  881. BYTE *prime1;
  882. BYTE *prime2;
  883. BYTE *exp1;
  884. BYTE *exp2;
  885. BYTE *coef;
  886. BYTE *invmod;
  887. BYTE *invpr1;
  888. BYTE *invpr2;
  889. } BSAFE_KEY_PARTS, FAR *LPBSAFE_KEY_PARTS;
  890. typedef struct {
  891. DWORD magic; /* Should always be RSA2 */
  892. DWORD bitlen; // bit size of key
  893. DWORD pubexp; // public exponent
  894. } EXPORT_PRV_KEY, FAR *PEXPORT_PRV_KEY;
  895. ///////////////////////////////////////////////////////////////////////////////////////
  896. //
  897. // Take a raw exported unshrowded private key from the registry and turn it
  898. // into a private key export blob.
  899. //
  900. // This is based on the PreparePrivateKeyForExport routine from rsabase.dll
  901. //
  902. static BOOL ConstructPrivateKeyExportBlob(
  903. IN DWORD dwKeySpec,
  904. IN BSAFE_PRV_KEY * pPrvKey,
  905. IN DWORD /*PrvKeyLen*/,
  906. OUT PBYTE *ppbBlob,
  907. OUT DWORD *pcbBlob
  908. )
  909. {
  910. BOOL fResult;
  911. PEXPORT_PRV_KEY pExportKey;
  912. DWORD cbHalfModLen;
  913. PBYTE pbBlob = NULL;
  914. DWORD cbBlob;
  915. PBYTE pbIn;
  916. PBYTE pbOut;
  917. cbHalfModLen = pPrvKey->bitlen / 16;
  918. cbBlob = sizeof(EXPORT_PRV_KEY) + 9 * cbHalfModLen +
  919. sizeof(PUBLICKEYSTRUC);
  920. if (NULL == (pbBlob = (BYTE *) PvkAlloc(cbBlob))) {
  921. fResult = FALSE;
  922. cbBlob = 0;
  923. } else {
  924. BYTE* pb = pbBlob;
  925. PUBLICKEYSTRUC *pPubKeyStruc = (PUBLICKEYSTRUC *) pb;
  926. pPubKeyStruc->bType = PRIVATEKEYBLOB;
  927. pPubKeyStruc->bVersion = 2;
  928. pPubKeyStruc->reserved = 0;
  929. if (dwKeySpec == AT_KEYEXCHANGE)
  930. pPubKeyStruc->aiKeyAlg = CALG_RSA_KEYX;
  931. else if (dwKeySpec == AT_SIGNATURE)
  932. pPubKeyStruc->aiKeyAlg = CALG_RSA_SIGN;
  933. else
  934. pPubKeyStruc->aiKeyAlg = 0;
  935. pb = pbBlob + sizeof(PUBLICKEYSTRUC);
  936. // take most of the header info
  937. pExportKey = (PEXPORT_PRV_KEY)pb;
  938. pExportKey->magic = pPrvKey->magic;
  939. pExportKey->bitlen = pPrvKey->bitlen;
  940. pExportKey->pubexp = pPrvKey->pubexp;
  941. pbIn = (PBYTE)pPrvKey + sizeof(BSAFE_PRV_KEY);
  942. pbOut = pb + sizeof(EXPORT_PRV_KEY);
  943. // copy all the private key info
  944. memcpy(pbOut, pbIn, cbHalfModLen * 2);
  945. pbIn += (cbHalfModLen + sizeof(DWORD)) * 2;
  946. pbOut += cbHalfModLen * 2;
  947. memcpy(pbOut, pbIn, cbHalfModLen);
  948. pbIn += cbHalfModLen + sizeof(DWORD);
  949. pbOut += cbHalfModLen;
  950. memcpy(pbOut, pbIn, cbHalfModLen);
  951. pbIn += cbHalfModLen + sizeof(DWORD);
  952. pbOut += cbHalfModLen;
  953. memcpy(pbOut, pbIn, cbHalfModLen);
  954. pbIn += cbHalfModLen + sizeof(DWORD);
  955. pbOut += cbHalfModLen;
  956. memcpy(pbOut, pbIn, cbHalfModLen);
  957. pbIn += cbHalfModLen + sizeof(DWORD);
  958. pbOut += cbHalfModLen;
  959. memcpy(pbOut, pbIn, cbHalfModLen);
  960. pbIn += cbHalfModLen + sizeof(DWORD);
  961. pbOut += cbHalfModLen;
  962. memcpy(pbOut, pbIn, cbHalfModLen * 2);
  963. fResult = TRUE;
  964. }
  965. *ppbBlob = pbBlob;
  966. *pcbBlob = cbBlob;
  967. return fResult;
  968. }
  969. static BOOL LoadBobKey(
  970. IN HCRYPTPROV hCryptProv,
  971. IN HANDLE hRead,
  972. IN PFNREAD pfnRead,
  973. IN DWORD cbBobKey,
  974. IN HWND hwndOwner,
  975. IN LPCWSTR pwszKeyName,
  976. IN DWORD dwFlags,
  977. IN OUT OPTIONAL DWORD *pdwKeySpec,
  978. IN PFILE_HDR pHdr // header has already been read
  979. )
  980. {
  981. BOOL fResult;
  982. DWORD dwErr = 0;
  983. HRESULT hr;
  984. HGLOBAL hGlobal = NULL;
  985. BYTE *pbBobKey; // not allocated
  986. ILockBytes *pLkByt = NULL;
  987. IStorage *pStg = NULL;
  988. IStorage *pPrivStg = NULL;
  989. BYTE *pbPvkValue = NULL;
  990. DWORD cbPvkValue;
  991. DWORD dwKeySpec;
  992. if (cbBobKey > MAX_BOB_FILE_LEN) goto BadBobFile;
  993. if (NULL == (hGlobal = GlobalAlloc(GMEM_MOVEABLE | GMEM_DISCARDABLE,
  994. cbBobKey)))
  995. goto ErrorReturn;
  996. if (NULL == (pbBobKey = (BYTE *) GlobalLock(hGlobal)))
  997. goto ErrorReturn;
  998. memcpy(pbBobKey, (BYTE *) pHdr, sizeof(FILE_HDR));
  999. if (cbBobKey > sizeof(FILE_HDR))
  1000. fResult = pfnRead(hRead, pbBobKey + sizeof(FILE_HDR),
  1001. cbBobKey - sizeof(FILE_HDR));
  1002. else
  1003. fResult = TRUE;
  1004. GlobalUnlock(hGlobal);
  1005. if (!fResult) goto ErrorReturn;
  1006. // FALSE => don't DeleteOnRelease
  1007. if (FAILED(hr = CreateILockBytesOnHGlobal(hGlobal, FALSE, &pLkByt)))
  1008. goto HrError;
  1009. if (FAILED(hr = StgOpenStorageOnILockBytes(
  1010. pLkByt,
  1011. NULL, // pStgPriority
  1012. STGM_DIRECT | STGM_READ | STGM_SHARE_DENY_WRITE,
  1013. NULL, // snbExclude
  1014. 0, // dwReserved
  1015. &pStg
  1016. ))) goto HrError;
  1017. if (FAILED(pStg->OpenStorage(
  1018. L"Plain Private Key",
  1019. 0,
  1020. STGM_READ | STGM_SHARE_EXCLUSIVE,
  1021. NULL,
  1022. 0,
  1023. &pPrivStg))) goto BadBobFile;
  1024. if (pdwKeySpec && *pdwKeySpec)
  1025. dwKeySpec = *pdwKeySpec;
  1026. else
  1027. dwKeySpec = AT_SIGNATURE;
  1028. // First, attempt to read the new format where the keys are stored in
  1029. // the private key export format
  1030. fResult = LoadBobExportedPvk(pPrivStg, dwKeySpec, &pbPvkValue,
  1031. &cbPvkValue);
  1032. if (!fResult && (pdwKeySpec == NULL || *pdwKeySpec == 0)) {
  1033. dwKeySpec = AT_KEYEXCHANGE;
  1034. fResult = LoadBobExportedPvk(pPrivStg, dwKeySpec,
  1035. &pbPvkValue, &cbPvkValue);
  1036. }
  1037. if (fResult)
  1038. fResult = PrivateKeyLoadFromMemory(
  1039. hCryptProv,
  1040. pbPvkValue,
  1041. cbPvkValue,
  1042. hwndOwner,
  1043. pwszKeyName,
  1044. dwFlags,
  1045. &dwKeySpec
  1046. );
  1047. else {
  1048. // Try "old" format
  1049. if (pdwKeySpec && *pdwKeySpec)
  1050. dwKeySpec = *pdwKeySpec;
  1051. else
  1052. dwKeySpec = AT_SIGNATURE;
  1053. fResult = LoadBobOldPvk(pPrivStg, dwKeySpec, &pbPvkValue, &cbPvkValue);
  1054. if (!fResult && (pdwKeySpec == NULL || *pdwKeySpec == 0)) {
  1055. dwKeySpec = AT_KEYEXCHANGE;
  1056. fResult = LoadBobOldPvk(pPrivStg, dwKeySpec,
  1057. &pbPvkValue, &cbPvkValue);
  1058. }
  1059. if (fResult) {
  1060. BYTE *pbExportPvk;
  1061. DWORD cbExportPvk;
  1062. // Convert Bob's old private key format to the new export private
  1063. // key format
  1064. fResult = ConstructPrivateKeyExportBlob(
  1065. dwKeySpec,
  1066. (BSAFE_PRV_KEY *) pbPvkValue,
  1067. cbPvkValue,
  1068. &pbExportPvk,
  1069. &cbExportPvk
  1070. );
  1071. if (fResult) {
  1072. HCRYPTKEY hKey = 0;
  1073. // Import the private key
  1074. fResult = CryptImportKey(hCryptProv, pbExportPvk, cbExportPvk,
  1075. 0, dwFlags, &hKey);
  1076. if (hKey)
  1077. CryptDestroyKey(hKey);
  1078. PvkFree(pbExportPvk);
  1079. }
  1080. }
  1081. }
  1082. if (fResult) goto CommonReturn;
  1083. goto ErrorReturn;
  1084. HrError:
  1085. SetLastError((DWORD) hr);
  1086. goto ErrorReturn;
  1087. BadBobFile:
  1088. SetLastError(PVK_HELPER_BAD_PVK_FILE);
  1089. ErrorReturn:
  1090. dwKeySpec = 0;
  1091. fResult = FALSE;
  1092. // One of the following Releases may clear it out
  1093. dwErr = GetLastError();
  1094. CommonReturn:
  1095. if (pbPvkValue)
  1096. PvkFree(pbPvkValue);
  1097. if (pPrivStg)
  1098. pPrivStg->Release();
  1099. if (pStg)
  1100. pStg->Release();
  1101. if (pLkByt)
  1102. pLkByt->Release();
  1103. if (hGlobal)
  1104. GlobalFree(hGlobal);
  1105. if (pdwKeySpec)
  1106. *pdwKeySpec = dwKeySpec;
  1107. if (dwErr)
  1108. SetLastError(dwErr);
  1109. return fResult;
  1110. }