2021-09-04 11:41:56 +02:00
|
|
|
// +build !without_openssl
|
|
|
|
|
|
|
|
// Package stupidgcm is a thin wrapper for OpenSSL's GCM encryption and
|
|
|
|
// decryption functions. It only support 32-byte keys and 16-bit IVs.
|
|
|
|
package stupidgcm
|
|
|
|
|
|
|
|
// #include <openssl/evp.h>
|
|
|
|
import "C"
|
|
|
|
|
|
|
|
import (
|
|
|
|
"crypto/cipher"
|
|
|
|
"log"
|
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
|
|
|
// BuiltWithoutOpenssl indicates if openssl been disabled at compile-time
|
|
|
|
BuiltWithoutOpenssl = false
|
|
|
|
|
|
|
|
keyLen = 32
|
|
|
|
ivLen = 16
|
|
|
|
tagLen = 16
|
|
|
|
)
|
|
|
|
|
2021-09-07 17:48:55 +02:00
|
|
|
type stupidGCM struct {
|
2021-09-04 11:41:56 +02:00
|
|
|
stupidAEADCommon
|
|
|
|
}
|
|
|
|
|
|
|
|
// Verify that we satisfy the interface
|
2021-09-07 17:48:55 +02:00
|
|
|
var _ cipher.AEAD = &stupidGCM{}
|
2021-09-04 11:41:56 +02:00
|
|
|
|
|
|
|
// New returns a new cipher.AEAD implementation..
|
|
|
|
func New(keyIn []byte, forceDecode bool) cipher.AEAD {
|
|
|
|
if len(keyIn) != keyLen {
|
|
|
|
log.Panicf("Only %d-byte keys are supported", keyLen)
|
|
|
|
}
|
2021-09-07 17:48:55 +02:00
|
|
|
return &stupidGCM{
|
2021-09-04 11:41:56 +02:00
|
|
|
stupidAEADCommon{
|
|
|
|
// Create a private copy of the key
|
|
|
|
key: append([]byte{}, keyIn...),
|
|
|
|
openSSLEVPCipher: C.EVP_aes_256_gcm(),
|
|
|
|
nonceSize: ivLen,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|