mirror of
https://github.com/Legrandin/pycryptodome.git
synced 2025-11-01 22:21:39 +00:00
The patch contains the following changes: - Private RSA keys can be imported/exported in encrypted form, protected according to PKCS#8 and: * PBKDF2WithHMAC-SHA1AndDES-EDE3-CBC. * PBKDF2WithHMAC-SHA1AndAES128-CBC * PBKDF2WithHMAC-SHA1AndAES192-CBC * PBKDF2WithHMAC-SHA1AndAES256-CBC In addition to that, it is possible to import keys i the following weak formats: * pbeWithMD5AndDES-CBC * pbeWithSHA1AndRC2-CBC * pbeWithMD5AndRC2-CBC * pbeWithSHA1AndDES-CBC - The following new module (and 1 new package) are added: * Crypto.Util.Padding for simple padding/unpadding logic * Crypto.IO._PBES for PBE-related PKCS#5 logic * Crypto.IO.PEM for PEM wrapping/unwrapping * Crypto.IO.PKCS8 for PKCS#8 wrapping/unwrapping - All Object ID (OIDs) are now in dotted form to increase readability. - Add AES support to PEM format (decode only). The PEM module can decrypt messages protected with AES-CBC. - Update RSA import test cases. - Updated to PKCS8 test cases
103 lines
3.9 KiB
Python
103 lines
3.9 KiB
Python
#
|
|
# -*- coding: utf-8 -*-
|
|
#
|
|
# Util/Padding.py : Functions to manage padding
|
|
#
|
|
# ===================================================================
|
|
# The contents of this file are dedicated to the public domain. To
|
|
# the extent that dedication to the public domain is not available,
|
|
# everyone is granted a worldwide, perpetual, royalty-free,
|
|
# non-exclusive license to exercise all rights associated with the
|
|
# contents of this file for any purpose whatsoever.
|
|
# No rights are reserved.
|
|
#
|
|
# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
|
# EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
|
|
# MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
|
|
# NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
|
|
# BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
|
|
# ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
|
|
# CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
|
# SOFTWARE.
|
|
# ===================================================================
|
|
|
|
""" Functions to manage padding
|
|
|
|
This module provides minimal support for adding and removing standard padding
|
|
from data.
|
|
"""
|
|
|
|
__all__ = [ 'PaddingError', 'pad', 'unpad' ]
|
|
|
|
from Crypto.Util.py3compat import *
|
|
|
|
class PaddingError(ValueError):
|
|
"""Exception raised when padding is incorrect and cannot be removed."""
|
|
pass
|
|
|
|
def pad(data_to_pad, block_size, style='pkcs7'):
|
|
"""Apply standard padding.
|
|
|
|
:Parameters:
|
|
data_to_pad : byte string
|
|
The data that needs to be padded.
|
|
block_size : integer
|
|
The block boundary to use for padding. The output length is guaranteed
|
|
to be a multiple of ``block_size``.
|
|
style : string
|
|
Padding algorithm. It can be *'pkcs7'* (default), *'iso7816'* or *'x923'*.
|
|
:Return:
|
|
The original data with the appropriate padding added at the end.
|
|
"""
|
|
|
|
padding_len = block_size-len(data_to_pad)%block_size
|
|
if style == 'pkcs7':
|
|
padding = bchr(padding_len)*padding_len
|
|
elif style == 'x923':
|
|
padding = bchr(0)*(padding_len-1) + bchr(padding_len)
|
|
elif style == 'iso7816':
|
|
padding = bchr(128) + bchr(0)*(padding_len-1)
|
|
else:
|
|
raise ValueError("Unknown padding style")
|
|
return data_to_pad + padding
|
|
|
|
def unpad(padded_data, block_size, style='pkcs7'):
|
|
"""Remove standard padding.
|
|
|
|
:Parameters:
|
|
padded_data : byte string
|
|
A piece of data with padding that needs to be stripped.
|
|
block_size : integer
|
|
The block boundary to use for padding. The input length
|
|
must be a multiple of ``block_size``.
|
|
style : string
|
|
Padding algorithm. It can be *'pkcs7'* (default), *'iso7816'* or *'x923'*.
|
|
:Return:
|
|
Data without padding.
|
|
:Raises PaddingError:
|
|
if the padding is incorrect.
|
|
"""
|
|
|
|
pdata_len = len(padded_data)
|
|
if pdata_len % block_size:
|
|
raise PaddingError("Input data is not padded")
|
|
if style in ('pkcs7', 'x923'):
|
|
padding_len = bord(padded_data[-1])
|
|
if padding_len<1 or padding_len>min(block_size, pdata_len):
|
|
raise PaddingError("Padding is incorrect.")
|
|
if style == 'pkcs7':
|
|
if padded_data[-padding_len:]!=bchr(padding_len)*padding_len:
|
|
raise PaddingError("PKCS#7 padding is incorrect.")
|
|
else:
|
|
if padded_data[-padding_len:-1]!=bchr(0)*(padding_len-1):
|
|
raise PaddingError("ANSI X.923 padding is incorrect.")
|
|
elif style == 'iso7816':
|
|
padding_len = pdata_len - padded_data.rfind(bchr(128))
|
|
if padding_len<1 or padding_len>min(block_size, pdata_len):
|
|
raise PaddingError("Padding is incorrect.")
|
|
if padding_len>1 and padded_data[1-padding_len:]!=bchr(0)*(padding_len-1):
|
|
raise PaddingError("ISO 7816-4 padding is incorrect.")
|
|
else:
|
|
raise ValueError("Unknown padding style")
|
|
return padded_data[:-padding_len]
|
|
|