1/*
2 * Copyright (c) 1995-2001 Kungliga Tekniska H��gskolan
3 * (Royal Institute of Technology, Stockholm, Sweden).
4 * All rights reserved.
5 *
6 * Redistribution and use in source and binary forms, with or without
7 * modification, are permitted provided that the following conditions
8 * are met:
9 *
10 * 1. Redistributions of source code must retain the above copyright
11 *    notice, this list of conditions and the following disclaimer.
12 *
13 * 2. Redistributions in binary form must reproduce the above copyright
14 *    notice, this list of conditions and the following disclaimer in the
15 *    documentation and/or other materials provided with the distribution.
16 *
17 * 3. Neither the name of the Institute nor the names of its contributors
18 *    may be used to endorse or promote products derived from this software
19 *    without specific prior written permission.
20 *
21 * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24 * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31 * SUCH DAMAGE.
32 */
33
34#ifdef HAVE_CONFIG_H
35#include "config.h"
36#elif defined(_MSC_VER)
37#include "config-msvc.h"
38#endif
39
40#include "syshead.h"
41
42#if defined(ENABLE_HTTP_PROXY) || defined(ENABLE_PKCS11) || defined(ENABLE_CLIENT_CR) || defined(MANAGMENT_EXTERNAL_KEY)
43
44#include "base64.h"
45
46#include "memdbg.h"
47
48static char base64_chars[] =
49    "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
50/*
51 * base64 encode input data of length size to malloced
52 * buffer which is returned as *str.  Returns string
53 * length of *str.
54 */
55int
56openvpn_base64_encode(const void *data, int size, char **str)
57{
58    char *s, *p;
59    int i;
60    int c;
61    const unsigned char *q;
62
63    if (size < 0)
64	return -1;
65    p = s = (char *) malloc(size * 4 / 3 + 4);
66    if (p == NULL)
67	return -1;
68    q = (const unsigned char *) data;
69    i = 0;
70    for (i = 0; i < size;) {
71	c = q[i++];
72	c *= 256;
73	if (i < size)
74	    c += q[i];
75	i++;
76	c *= 256;
77	if (i < size)
78	    c += q[i];
79	i++;
80	p[0] = base64_chars[(c & 0x00fc0000) >> 18];
81	p[1] = base64_chars[(c & 0x0003f000) >> 12];
82	p[2] = base64_chars[(c & 0x00000fc0) >> 6];
83	p[3] = base64_chars[(c & 0x0000003f) >> 0];
84	if (i > size)
85	    p[3] = '=';
86	if (i > size + 1)
87	    p[2] = '=';
88	p += 4;
89    }
90    *p = 0;
91    *str = s;
92    return strlen(s);
93}
94
95static int
96pos(char c)
97{
98    char *p;
99    for (p = base64_chars; *p; p++)
100	if (*p == c)
101	    return p - base64_chars;
102    return -1;
103}
104
105#define DECODE_ERROR 0xffffffff
106
107static unsigned int
108token_decode(const char *token)
109{
110    int i;
111    unsigned int val = 0;
112    int marker = 0;
113    if (strlen(token) < 4)
114	return DECODE_ERROR;
115    for (i = 0; i < 4; i++) {
116	val *= 64;
117	if (token[i] == '=')
118	    marker++;
119	else if (marker > 0)
120	    return DECODE_ERROR;
121	else
122	    val += pos(token[i]);
123    }
124    if (marker > 2)
125	return DECODE_ERROR;
126    return (marker << 24) | val;
127}
128/*
129 * Decode base64 str, outputting data to buffer
130 * at data of length size.  Return length of
131 * decoded data written or -1 on error or overflow.
132 */
133int
134openvpn_base64_decode(const char *str, void *data, int size)
135{
136    const char *p;
137    unsigned char *q;
138    unsigned char *e = NULL;
139
140    q = data;
141    if (size >= 0)
142      e = q + size;
143    for (p = str; *p && (*p == '=' || strchr(base64_chars, *p)); p += 4) {
144	unsigned int val = token_decode(p);
145	unsigned int marker = (val >> 24) & 0xff;
146	if (val == DECODE_ERROR)
147	    return -1;
148	if (e && q >= e)
149	  return -1;
150	*q++ = (val >> 16) & 0xff;
151	if (marker < 2)
152	  {
153	    if (e && q >= e)
154	      return -1;
155	    *q++ = (val >> 8) & 0xff;
156	  }
157	if (marker < 1)
158	  {
159	    if (e && q >= e)
160	      return -1;
161	    *q++ = val & 0xff;
162	  }
163    }
164    return q - (unsigned char *) data;
165}
166
167#else
168static void dummy(void) {}
169#endif /* ENABLE_HTTP_PROXY, ENABLE_PKCS11, ENABLE_CLIENT_CR */
170