|
|
|
|
@ -162,6 +162,15 @@ static void etcp_link_send_init(struct ETCP_LINK* link, uint8_t reset, uint8_t c
|
|
|
|
|
uint8_t obfuscated_pubkey[SC_PUBKEY_SIZE]; |
|
|
|
|
sc_obfuscate_pubkey(salt, link->etcp->crypto_ctx.peer_public_key,
|
|
|
|
|
link->etcp->instance->my_keys.public_key, obfuscated_pubkey); |
|
|
|
|
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "INIT_SEND: salt=%02x%02x%02x%02x%02x%02x%02x%02x obf_pub=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x my_pub=%02x%02x%02x%02x seskey=%02x%02x%02x%02x", |
|
|
|
|
salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7], |
|
|
|
|
obfuscated_pubkey[0], obfuscated_pubkey[1], obfuscated_pubkey[2], obfuscated_pubkey[3], |
|
|
|
|
link->etcp->crypto_ctx.peer_public_key[0], link->etcp->crypto_ctx.peer_public_key[1], |
|
|
|
|
link->etcp->crypto_ctx.peer_public_key[2], link->etcp->crypto_ctx.peer_public_key[3], |
|
|
|
|
link->etcp->instance->my_keys.public_key[0], link->etcp->instance->my_keys.public_key[1], |
|
|
|
|
link->etcp->instance->my_keys.public_key[2], link->etcp->instance->my_keys.public_key[3], |
|
|
|
|
link->etcp->crypto_ctx.session_key[0], link->etcp->crypto_ctx.session_key[1], |
|
|
|
|
link->etcp->crypto_ctx.session_key[2], link->etcp->crypto_ctx.session_key[3]); |
|
|
|
|
memcpy(dgram->data + offset, obfuscated_pubkey, SC_PUBKEY_SIZE); |
|
|
|
|
offset += SC_PUBKEY_SIZE; |
|
|
|
|
|
|
|
|
|
@ -1547,6 +1556,10 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
|
|
|
|
|
// }
|
|
|
|
|
|
|
|
|
|
if (link!=NULL && link->etcp!=NULL && link->etcp->crypto_ctx.session_ready) { |
|
|
|
|
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "NORM_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd rx=%llu", |
|
|
|
|
link->etcp->crypto_ctx.session_key[0], link->etcp->crypto_ctx.session_key[1], |
|
|
|
|
link->etcp->crypto_ctx.session_key[2], link->etcp->crypto_ctx.session_key[3], |
|
|
|
|
recv_len, (unsigned long long)link->etcp->crypto_ctx.rx_counter); |
|
|
|
|
sc_status_t dec_rc = sc_decrypt(&link->etcp->crypto_ctx, data, recv_len, (uint8_t*)&pkt->timestamp, &pkt_len); |
|
|
|
|
if (!dec_rc) { |
|
|
|
|
goto process_decrypted; |
|
|
|
|
@ -1583,6 +1596,11 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
|
|
|
|
|
goto ec_fr;
|
|
|
|
|
} |
|
|
|
|
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "X25519 decrypt OK from %s", sockaddr_storage_to_str(&addr).str); |
|
|
|
|
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "INIT_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd strip40=%zd salt=%02x%02x%02x%02x%02x%02x%02x%02x enc_pub=%02x%02x%02x%02x", |
|
|
|
|
sc.session_key[0], sc.session_key[1], sc.session_key[2], sc.session_key[3], |
|
|
|
|
recv_len, recv_len - SC_PUBKEY_ENC_SIZE, |
|
|
|
|
salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7], |
|
|
|
|
encrypted_pubkey[0], encrypted_pubkey[1], encrypted_pubkey[2], encrypted_pubkey[3]); |
|
|
|
|
if (sc_decrypt(&sc, data, recv_len - SC_PUBKEY_ENC_SIZE, (uint8_t*)&pkt->timestamp, &pkt_len)) { |
|
|
|
|
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "failed to decrypt init packet, from %s", sockaddr_storage_to_str(&addr).str); |
|
|
|
|
errorcode=3;
|
|
|
|
|
|