Browse Source

debug: add full ECDH/session-key diagnostics (6 points)

K1: sc_set_peer_public_key — priv, peer_pub, shared_secret, session_key
K2: sc_encrypt — session_key, tx_counter, nonce, plaintext
K3: sc_decrypt — session_key, nonce from packet, ciphertext_len
K4: INIT_SEND — salt, obfuscated_pubkey, peer_pubkey, my_pubkey, session_key
K5: NORM_DECRYPT_TRY — session_key, recv_len, rx_counter
K6: INIT_DECRYPT_TRY — session_key, recv_len, recv_len-40, salt, encrypted_pubkey

All via DEBUG_INFO(DEBUG_CATEGORY_CRYPTO) — enable with debug=crypto=info
topo_upd
Evgeny 3 months ago
parent
commit
2aa559acaf
  1. 18
      src/etcp_connections.c
  2. 15
      src/secure_channel.c

18
src/etcp_connections.c

@ -162,6 +162,15 @@ static void etcp_link_send_init(struct ETCP_LINK* link, uint8_t reset, uint8_t c
uint8_t obfuscated_pubkey[SC_PUBKEY_SIZE];
sc_obfuscate_pubkey(salt, link->etcp->crypto_ctx.peer_public_key,
link->etcp->instance->my_keys.public_key, obfuscated_pubkey);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "INIT_SEND: salt=%02x%02x%02x%02x%02x%02x%02x%02x obf_pub=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x my_pub=%02x%02x%02x%02x seskey=%02x%02x%02x%02x",
salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7],
obfuscated_pubkey[0], obfuscated_pubkey[1], obfuscated_pubkey[2], obfuscated_pubkey[3],
link->etcp->crypto_ctx.peer_public_key[0], link->etcp->crypto_ctx.peer_public_key[1],
link->etcp->crypto_ctx.peer_public_key[2], link->etcp->crypto_ctx.peer_public_key[3],
link->etcp->instance->my_keys.public_key[0], link->etcp->instance->my_keys.public_key[1],
link->etcp->instance->my_keys.public_key[2], link->etcp->instance->my_keys.public_key[3],
link->etcp->crypto_ctx.session_key[0], link->etcp->crypto_ctx.session_key[1],
link->etcp->crypto_ctx.session_key[2], link->etcp->crypto_ctx.session_key[3]);
memcpy(dgram->data + offset, obfuscated_pubkey, SC_PUBKEY_SIZE);
offset += SC_PUBKEY_SIZE;
@ -1547,6 +1556,10 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
// }
if (link!=NULL && link->etcp!=NULL && link->etcp->crypto_ctx.session_ready) {
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "NORM_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd rx=%llu",
link->etcp->crypto_ctx.session_key[0], link->etcp->crypto_ctx.session_key[1],
link->etcp->crypto_ctx.session_key[2], link->etcp->crypto_ctx.session_key[3],
recv_len, (unsigned long long)link->etcp->crypto_ctx.rx_counter);
sc_status_t dec_rc = sc_decrypt(&link->etcp->crypto_ctx, data, recv_len, (uint8_t*)&pkt->timestamp, &pkt_len);
if (!dec_rc) {
goto process_decrypted;
@ -1583,6 +1596,11 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
goto ec_fr;
}
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "X25519 decrypt OK from %s", sockaddr_storage_to_str(&addr).str);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "INIT_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd strip40=%zd salt=%02x%02x%02x%02x%02x%02x%02x%02x enc_pub=%02x%02x%02x%02x",
sc.session_key[0], sc.session_key[1], sc.session_key[2], sc.session_key[3],
recv_len, recv_len - SC_PUBKEY_ENC_SIZE,
salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7],
encrypted_pubkey[0], encrypted_pubkey[1], encrypted_pubkey[2], encrypted_pubkey[3]);
if (sc_decrypt(&sc, data, recv_len - SC_PUBKEY_ENC_SIZE, (uint8_t*)&pkt->timestamp, &pkt_len)) {
DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "failed to decrypt init packet, from %s", sockaddr_storage_to_str(&addr).str);
errorcode=3;

15
src/secure_channel.c

@ -225,6 +225,12 @@ sc_status_t sc_set_peer_public_key(sc_context_t *ctx, const uint8_t *peer_public
}
sc_derive_session_key(shared_secret, ctx->session_key);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "ECDH: priv=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x shared=%02x%02x%02x%02x%02x%02x%02x%02x seskey=%02x%02x%02x%02x",
ctx->pk->private_key[0], ctx->pk->private_key[1], ctx->pk->private_key[2], ctx->pk->private_key[3],
peer_public_key[0], peer_public_key[1], peer_public_key[2], peer_public_key[3],
shared_secret[0], shared_secret[1], shared_secret[2], shared_secret[3],
shared_secret[4], shared_secret[5], shared_secret[6], shared_secret[7],
ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3]);
memcpy(ctx->peer_public_key, peer_public_key, SC_PUBKEY_SIZE);
ctx->peer_key_set = 1;
ctx->session_ready = 1;
@ -267,6 +273,11 @@ sc_status_t sc_encrypt(sc_context_t *ctx, const uint8_t *plaintext, size_t plain
size_t total_plaintext_len = plaintext_len + SC_CRC32_SIZE;
uint8_t nonce[SC_NONCE_SIZE];
sc_build_nonce(ctx->tx_counter, nonce);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "ENCRYPT: seskey=%02x%02x%02x%02x tx=%llu nonce=%02x%02x%02x%02x data[0..3]=%02x%02x%02x%02x",
ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3],
(unsigned long long)ctx->tx_counter,
nonce[0], nonce[1], nonce[2], nonce[3],
plaintext_with_crc[0], plaintext_with_crc[1], plaintext_with_crc[2], plaintext_with_crc[3]);
EVP_CIPHER_CTX *ectx = EVP_CIPHER_CTX_new();
if (!ectx) return SC_ERR_CRYPTO;
if (EVP_EncryptInit_ex(ectx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1
@ -300,6 +311,10 @@ sc_status_t sc_decrypt(sc_context_t *ctx, const uint8_t *ciphertext, size_t ciph
uint8_t nonce[SC_NONCE_SIZE];
memcpy(nonce, ciphertext, SC_NONCE_SIZE);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "DECRYPT: seskey=%02x%02x%02x%02x nonce=%02x%02x%02x%02x ct_len=%zu",
ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3],
nonce[0], nonce[1], nonce[2], nonce[3],
ciphertext_len);
const uint8_t *encrypted_data = ciphertext + SC_NONCE_SIZE;
size_t encrypted_len = ciphertext_len - SC_NONCE_SIZE;
size_t total_plaintext_len = encrypted_len - SC_TAG_SIZE;

Loading…
Cancel
Save