diff --git a/src/etcp_connections.c b/src/etcp_connections.c index 9316aa00..98d2b697 100644 --- a/src/etcp_connections.c +++ b/src/etcp_connections.c @@ -162,6 +162,15 @@ static void etcp_link_send_init(struct ETCP_LINK* link, uint8_t reset, uint8_t c uint8_t obfuscated_pubkey[SC_PUBKEY_SIZE]; sc_obfuscate_pubkey(salt, link->etcp->crypto_ctx.peer_public_key, link->etcp->instance->my_keys.public_key, obfuscated_pubkey); + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "INIT_SEND: salt=%02x%02x%02x%02x%02x%02x%02x%02x obf_pub=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x my_pub=%02x%02x%02x%02x seskey=%02x%02x%02x%02x", + salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7], + obfuscated_pubkey[0], obfuscated_pubkey[1], obfuscated_pubkey[2], obfuscated_pubkey[3], + link->etcp->crypto_ctx.peer_public_key[0], link->etcp->crypto_ctx.peer_public_key[1], + link->etcp->crypto_ctx.peer_public_key[2], link->etcp->crypto_ctx.peer_public_key[3], + link->etcp->instance->my_keys.public_key[0], link->etcp->instance->my_keys.public_key[1], + link->etcp->instance->my_keys.public_key[2], link->etcp->instance->my_keys.public_key[3], + link->etcp->crypto_ctx.session_key[0], link->etcp->crypto_ctx.session_key[1], + link->etcp->crypto_ctx.session_key[2], link->etcp->crypto_ctx.session_key[3]); memcpy(dgram->data + offset, obfuscated_pubkey, SC_PUBKEY_SIZE); offset += SC_PUBKEY_SIZE; @@ -1547,6 +1556,10 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) { // } if (link!=NULL && link->etcp!=NULL && link->etcp->crypto_ctx.session_ready) { + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "NORM_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd rx=%llu", + link->etcp->crypto_ctx.session_key[0], link->etcp->crypto_ctx.session_key[1], + link->etcp->crypto_ctx.session_key[2], link->etcp->crypto_ctx.session_key[3], + recv_len, (unsigned long long)link->etcp->crypto_ctx.rx_counter); sc_status_t dec_rc = sc_decrypt(&link->etcp->crypto_ctx, data, recv_len, (uint8_t*)&pkt->timestamp, &pkt_len); if (!dec_rc) { goto process_decrypted; @@ -1583,6 +1596,11 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) { goto ec_fr; } DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "X25519 decrypt OK from %s", sockaddr_storage_to_str(&addr).str); + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "INIT_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd strip40=%zd salt=%02x%02x%02x%02x%02x%02x%02x%02x enc_pub=%02x%02x%02x%02x", + sc.session_key[0], sc.session_key[1], sc.session_key[2], sc.session_key[3], + recv_len, recv_len - SC_PUBKEY_ENC_SIZE, + salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7], + encrypted_pubkey[0], encrypted_pubkey[1], encrypted_pubkey[2], encrypted_pubkey[3]); if (sc_decrypt(&sc, data, recv_len - SC_PUBKEY_ENC_SIZE, (uint8_t*)&pkt->timestamp, &pkt_len)) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "failed to decrypt init packet, from %s", sockaddr_storage_to_str(&addr).str); errorcode=3; diff --git a/src/secure_channel.c b/src/secure_channel.c index f5374b58..46dfcdd7 100644 --- a/src/secure_channel.c +++ b/src/secure_channel.c @@ -225,6 +225,12 @@ sc_status_t sc_set_peer_public_key(sc_context_t *ctx, const uint8_t *peer_public } sc_derive_session_key(shared_secret, ctx->session_key); + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "ECDH: priv=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x shared=%02x%02x%02x%02x%02x%02x%02x%02x seskey=%02x%02x%02x%02x", + ctx->pk->private_key[0], ctx->pk->private_key[1], ctx->pk->private_key[2], ctx->pk->private_key[3], + peer_public_key[0], peer_public_key[1], peer_public_key[2], peer_public_key[3], + shared_secret[0], shared_secret[1], shared_secret[2], shared_secret[3], + shared_secret[4], shared_secret[5], shared_secret[6], shared_secret[7], + ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3]); memcpy(ctx->peer_public_key, peer_public_key, SC_PUBKEY_SIZE); ctx->peer_key_set = 1; ctx->session_ready = 1; @@ -267,6 +273,11 @@ sc_status_t sc_encrypt(sc_context_t *ctx, const uint8_t *plaintext, size_t plain size_t total_plaintext_len = plaintext_len + SC_CRC32_SIZE; uint8_t nonce[SC_NONCE_SIZE]; sc_build_nonce(ctx->tx_counter, nonce); + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "ENCRYPT: seskey=%02x%02x%02x%02x tx=%llu nonce=%02x%02x%02x%02x data[0..3]=%02x%02x%02x%02x", + ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3], + (unsigned long long)ctx->tx_counter, + nonce[0], nonce[1], nonce[2], nonce[3], + plaintext_with_crc[0], plaintext_with_crc[1], plaintext_with_crc[2], plaintext_with_crc[3]); EVP_CIPHER_CTX *ectx = EVP_CIPHER_CTX_new(); if (!ectx) return SC_ERR_CRYPTO; if (EVP_EncryptInit_ex(ectx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1 @@ -300,6 +311,10 @@ sc_status_t sc_decrypt(sc_context_t *ctx, const uint8_t *ciphertext, size_t ciph uint8_t nonce[SC_NONCE_SIZE]; memcpy(nonce, ciphertext, SC_NONCE_SIZE); + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "DECRYPT: seskey=%02x%02x%02x%02x nonce=%02x%02x%02x%02x ct_len=%zu", + ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3], + nonce[0], nonce[1], nonce[2], nonce[3], + ciphertext_len); const uint8_t *encrypted_data = ciphertext + SC_NONCE_SIZE; size_t encrypted_len = ciphertext_len - SC_NONCE_SIZE; size_t total_plaintext_len = encrypted_len - SC_TAG_SIZE;