DefaultTlsDHGroupVerifier.cs 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. #pragma warning disable
  3. using System;
  4. using System.Collections;
  5. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math;
  6. using BestHTTP.SecureProtocol.Org.BouncyCastle.Tls.Crypto;
  7. using BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities;
  8. namespace BestHTTP.SecureProtocol.Org.BouncyCastle.Tls
  9. {
  10. public class DefaultTlsDHGroupVerifier
  11. : TlsDHGroupVerifier
  12. {
  13. public static readonly int DefaultMinimumPrimeBits = 2048;
  14. private static readonly IList DefaultGroups = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.CreateArrayList();
  15. private static void AddDefaultGroup(DHGroup dhGroup)
  16. {
  17. DefaultGroups.Add(dhGroup);
  18. }
  19. static DefaultTlsDHGroupVerifier()
  20. {
  21. /*
  22. * These 10 standard groups are those specified in NIST SP 800-56A Rev. 3 Appendix D. Make
  23. * sure to consider the impact on BCJSSE's FIPS mode and/or usage with the BCFIPS provider
  24. * before modifying this list.
  25. */
  26. AddDefaultGroup(DHStandardGroups.rfc3526_2048);
  27. AddDefaultGroup(DHStandardGroups.rfc3526_3072);
  28. AddDefaultGroup(DHStandardGroups.rfc3526_4096);
  29. AddDefaultGroup(DHStandardGroups.rfc3526_6144);
  30. AddDefaultGroup(DHStandardGroups.rfc3526_8192);
  31. AddDefaultGroup(DHStandardGroups.rfc7919_ffdhe2048);
  32. AddDefaultGroup(DHStandardGroups.rfc7919_ffdhe3072);
  33. AddDefaultGroup(DHStandardGroups.rfc7919_ffdhe4096);
  34. AddDefaultGroup(DHStandardGroups.rfc7919_ffdhe6144);
  35. AddDefaultGroup(DHStandardGroups.rfc7919_ffdhe8192);
  36. }
  37. // IList is (DHGroup)
  38. protected readonly IList m_groups;
  39. protected readonly int m_minimumPrimeBits;
  40. /// <summary>Accept named groups and various standard DH groups with 'P' at least
  41. /// <see cref="DefaultMinimumPrimeBits"/> bits.</summary>
  42. public DefaultTlsDHGroupVerifier()
  43. : this(DefaultMinimumPrimeBits)
  44. {
  45. }
  46. /// <summary>Accept named groups and various standard DH groups with 'P' at least the specified number of bits.
  47. /// </summary>
  48. /// <param name="minimumPrimeBits">the minimum bitlength of 'P'.</param>
  49. public DefaultTlsDHGroupVerifier(int minimumPrimeBits)
  50. : this(DefaultGroups, minimumPrimeBits)
  51. {
  52. }
  53. /// <summary>Accept named groups and a custom set of group parameters, subject to a minimum bitlength for 'P'.
  54. /// </summary>
  55. /// <param name="groups">a <see cref="IList">list</see> of acceptable <see cref="DHGroup"/>s.</param>
  56. /// <param name="minimumPrimeBits">the minimum bitlength of 'P'.</param>
  57. public DefaultTlsDHGroupVerifier(IList groups, int minimumPrimeBits)
  58. {
  59. this.m_groups = BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.CreateArrayList(groups);
  60. this.m_minimumPrimeBits = minimumPrimeBits;
  61. }
  62. public virtual bool Accept(DHGroup dhGroup)
  63. {
  64. return CheckMinimumPrimeBits(dhGroup) && CheckGroup(dhGroup);
  65. }
  66. public virtual int MinimumPrimeBits
  67. {
  68. get { return m_minimumPrimeBits; }
  69. }
  70. protected virtual bool AreGroupsEqual(DHGroup a, DHGroup b)
  71. {
  72. return a == b || (AreParametersEqual(a.P, b.P) && AreParametersEqual(a.G, b.G));
  73. }
  74. protected virtual bool AreParametersEqual(BigInteger a, BigInteger b)
  75. {
  76. return a == b || a.Equals(b);
  77. }
  78. protected virtual bool CheckGroup(DHGroup dhGroup)
  79. {
  80. foreach (DHGroup group in m_groups)
  81. {
  82. if (AreGroupsEqual(dhGroup, group))
  83. return true;
  84. }
  85. return false;
  86. }
  87. protected virtual bool CheckMinimumPrimeBits(DHGroup dhGroup)
  88. {
  89. return dhGroup.P.BitLength >= MinimumPrimeBits;
  90. }
  91. }
  92. }
  93. #pragma warning restore
  94. #endif