diff --git a/AGENTS.md b/AGENTS.md index 564c1d04..dbf8822d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -15,7 +15,7 @@ This file contains essential information for AI coding agents working in the uTu **Repository:** uTun - Secure VPN tunnel with ETCP protocol **Language:** C (C99) **Build System:** GNU Autotools (autoconf/automake) -**Cryptography:** TinyCrypt + OpenSSL (AES-CCM, ECC, SHA256) +**Cryptography:** OpenSSL (AES-CCM, X25519, SHA256) ## Build Commands @@ -142,14 +142,14 @@ gcc -I../src -I../lib -I../tinycrypt/lib/include \ ### Key Sizes | Constant | Value | Description | |----------|-------|-------------| -| `SC_PRIVKEY_SIZE` | 32 | ECC private key | -| `SC_PUBKEY_SIZE` | 64 | ECC public key | +| `SC_PRIVKEY_SIZE` | 32 | X25519 private key | +| `SC_PUBKEY_SIZE` | 32 | X25519 public key | | `SC_NONCE_SIZE` | 13 | CCM nonce (exactly 13 bytes) | | `SC_SESSION_KEY_SIZE` | 16 | AES-128 session key | | `SC_TAG_SIZE` | 16 | CCM auth tag | | `SC_CRC32_SIZE` | 4 | CRC32 checksum | | `SC_PUBKEY_ENC_SALT_SIZE` | 8 | Salt for pubkey obfuscation | -| `SC_PUBKEY_ENC_SIZE` | 72 | Total pubkey+salt block sent unencrypted | +| `SC_PUBKEY_ENC_SIZE` | 40 | Total pubkey+salt block sent unencrypted | ### Using Secure Channel (secure_channel.h) ```c @@ -246,7 +246,7 @@ SOCKET=14, CONTROL=15, DUMP=16, TRAFFIC=17, DEBUG=18, GENERAL=19, NAT=20 - `route_node.c/h` - Route node (peer) management **Crypto (src/)** -- `secure_channel.c/h` - AES-CCM encryption with ECC key exchange, pubkey obfuscation +- `secure_channel.c/h` - AES-CCM encryption with X25519 key exchange, pubkey obfuscation - `crc32.c/h` - CRC32 checksums **NAT (src/)** @@ -285,7 +285,7 @@ SOCKET=14, CONTROL=15, DUMP=16, TRAFFIC=17, DEBUG=18, GENERAL=19, NAT=20 - **LL_QUEUE:** Lock-free queue with auto-callback, hash index lookup, threshold waiter - **Memory Pool:** Fast allocation for hot-path objects (packets, inflight entries, fragments) - **ETCP:** TCP-like reliable protocol with encryption, multi-link, load balancing -- **Secure Channel:** AES-CCM + ECC key exchange, nonce-based encryption, pubkey obfuscation +- **Secure Channel:** AES-CCM + X25519 key exchange, nonce-based encryption, pubkey obfuscation ## Queue Usage Rules diff --git a/src/Makefile.am b/src/Makefile.am index d4fae477..f23bda0a 100644 --- a/src/Makefile.am +++ b/src/Makefile.am @@ -51,109 +51,22 @@ utun_CORE_SOURCES = \ # Platform-specific TUN libs (Windows only) utun_TUN_LIBS = @TUN_LIBS@ -# TinyCrypt sources (only used without OpenSSL) -utun_TINYCRYPT_SOURCES = \ - $(top_srcdir)/tinycrypt/lib/source/aes_encrypt.c \ - $(top_srcdir)/tinycrypt/lib/source/aes_decrypt.c \ - $(top_srcdir)/tinycrypt/lib/source/cbc_mode.c \ - $(top_srcdir)/tinycrypt/lib/source/ccm_mode.c \ - $(top_srcdir)/tinycrypt/lib/source/cmac_mode.c \ - $(top_srcdir)/tinycrypt/lib/source/ctr_mode.c \ - $(top_srcdir)/tinycrypt/lib/source/ecc.c \ - $(top_srcdir)/tinycrypt/lib/source/ecc_dh.c \ - $(top_srcdir)/tinycrypt/lib/source/ecc_dsa.c \ - $(top_srcdir)/tinycrypt/lib/source/ecc_platform_specific.c \ - $(top_srcdir)/tinycrypt/lib/source/hmac.c \ - $(top_srcdir)/tinycrypt/lib/source/sha256.c \ - $(top_srcdir)/tinycrypt/lib/source/utils.c - -# Combine sources based on OpenSSL usage -if USE_OPENSSL utun_SOURCES = $(utun_CORE_SOURCES) $(utun_TUN_SOURCES) -else -utun_SOURCES = $(utun_CORE_SOURCES) $(utun_TINYCRYPT_SOURCES) $(utun_TUN_SOURCES) -endif # Include paths -utun_CORE_CFLAGS = \ +utun_CFLAGS = \ -I$(top_srcdir)/lib \ -I$(top_srcdir)/src/uip \ - -I$(top_srcdir)/tinycrypt/lib/include \ - -I$(top_srcdir)/tinycrypt/lib/source \ -g \ $(DEBUG_FLAGS) -utun_CFLAGS = $(utun_CORE_CFLAGS) - # Libraries -utun_CORE_LDADD = \ +utun_LDADD = \ $(top_builddir)/lib/libuasync.a \ -lpthread \ - -lm - -if USE_OPENSSL -utun_LDADD = $(utun_CORE_LDADD) -lcrypto $(utun_TUN_LIBS) -else -utun_LDADD = $(utun_CORE_LDADD) $(utun_TUN_LIBS) -endif - -# TinyCrypt object files (for tests that need them) -TINYCRYPT_SRCDIR = $(top_srcdir)/tinycrypt/lib/source - -TINYCRYPT_OBJS = \ - utun-aes_encrypt.o \ - utun-aes_decrypt.o \ - utun-ccm_mode.o \ - utun-cmac_mode.o \ - utun-ctr_mode.o \ - utun-ecc.o \ - utun-ecc_dh.o \ - utun-ecc_dsa.o \ - utun-sha256.o \ - utun-ecc_platform_specific.o \ - utun-utils.o - -# Rules to build TinyCrypt objects (for tests) -TINYCRYPT_CFLAGS = -g -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source - -utun-aes_encrypt.o: $(TINYCRYPT_SRCDIR)/aes_encrypt.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -utun-aes_decrypt.o: $(TINYCRYPT_SRCDIR)/aes_decrypt.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -utun-ccm_mode.o: $(TINYCRYPT_SRCDIR)/ccm_mode.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -utun-cmac_mode.o: $(TINYCRYPT_SRCDIR)/cmac_mode.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -utun-ctr_mode.o: $(TINYCRYPT_SRCDIR)/ctr_mode.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -utun-ecc.o: $(TINYCRYPT_SRCDIR)/ecc.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -utun-ecc_dh.o: $(TINYCRYPT_SRCDIR)/ecc_dh.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -utun-ecc_dsa.o: $(TINYCRYPT_SRCDIR)/ecc_dsa.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -utun-sha256.o: $(TINYCRYPT_SRCDIR)/sha256.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -# Force rebuild of ecc_platform_specific.o to pick up platform changes -utun-ecc_platform_specific.o: $(TINYCRYPT_SRCDIR)/ecc_platform_specific.c FORCE - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -FORCE: - -utun-utils.o: $(TINYCRYPT_SRCDIR)/utils.c - $(AM_V_CC)$(COMPILE) $(TINYCRYPT_CFLAGS) -c -o $@ $< - -# Build TinyCrypt objects for tests (convenience target) -tinycrypt-objects: $(TINYCRYPT_OBJS) + -lm \ + -lcrypto \ + $(utun_TUN_LIBS) # Copy binary to project root after building all-local: copy-to-root diff --git a/src/config_parser.h b/src/config_parser.h index 5ba7c287..8c59baba 100644 --- a/src/config_parser.h +++ b/src/config_parser.h @@ -79,7 +79,7 @@ struct CFG_CONTROL_ALLOW { }; struct CFG_ALLOWED_KEY { - uint8_t key_bin[SC_PUBKEY_SIZE]; // public key in binary (64 bytes) + uint8_t key_bin[SC_PUBKEY_SIZE]; // public key in binary (32 bytes, X25519) struct CFG_ALLOWED_KEY *next; }; diff --git a/src/config_updater.c b/src/config_updater.c index 2f21bca9..21256003 100644 --- a/src/config_updater.c +++ b/src/config_updater.c @@ -15,7 +15,7 @@ #include "../lib/mem.h" #define PRIV_HEXKEY_LEN 65 // 32 bytes * 2 hex chars + null -#define PUB_HEXKEY_LEN 129 // 64 bytes * 2 hex chars + null +#define PUB_HEXKEY_LEN 65 // 32 bytes * 2 hex chars + null #define HEXNODEID_LEN 17 // 8 bytes * 2 hex chars + null #define MAX_LINE_LEN 1024 @@ -41,8 +41,8 @@ static int is_valid_priv_key(const char *key) { } static int is_valid_pub_key(const char *key) { - if (!key || strlen(key) != 128) return 0; - for (int i = 0; i < 128; i++) { + if (!key || strlen(key) != 64) return 0; + for (int i = 0; i < 64; i++) { if (!isxdigit((unsigned char)key[i])) return 0; } return 1; diff --git a/src/secure_channel.c b/src/secure_channel.c index c1e73dfe..7f9dbec5 100644 --- a/src/secure_channel.c +++ b/src/secure_channel.c @@ -1,4 +1,4 @@ -/* secure_channel.c - Secure Channel library implementation using TinyCrypt or OpenSSL */ +/* secure_channel.c - Secure Channel library using X25519 + AES-128-CCM (OpenSSL) */ #ifdef HAVE_CONFIG_H #include @@ -19,27 +19,9 @@ #include "crc32.h" #include "../lib/sha256.h" -// To switch between implementations, define USE_OPENSSL before including/compiling. -// If USE_OPENSSL is defined, use OpenSSL; otherwise, use TinyCrypt (original logic). -// The core logic (e.g., nonce building, CRC, session key derivation as memcpy, counters, etc.) remains unchanged. - -#ifdef USE_OPENSSL -#include #include -#include -#include #include #include -#else -#include "../tinycrypt/lib/include/tinycrypt/ecc.h" -#include "../tinycrypt/lib/include/tinycrypt/ecc_dh.h" -#include "../tinycrypt/lib/include/tinycrypt/aes.h" -#include "../tinycrypt/lib/include/tinycrypt/ccm_mode.h" -#include "../tinycrypt/lib/include/tinycrypt/ctr_mode.h" -#include "../tinycrypt/lib/include/tinycrypt/constants.h" -#include "../tinycrypt/lib/include/tinycrypt/ecc_platform_specific.h" -#include "../tinycrypt/lib/include/tinycrypt/sha256.h" -#endif #include "../lib/platform_compat.h" static uint8_t sc_urandom_seed[8] = {0}; @@ -52,10 +34,9 @@ static void sc_init_random_seed(void) } } -// Конвертация hex строки в бинарный формат (common) +// Конвертация hex строки в бинарный формат static int hex_to_binary(const char *hex_str, uint8_t *binary, size_t binary_len) { if (!hex_str || !binary || strlen(hex_str) != binary_len * 2) return -1; - for (size_t i = 0; i < binary_len; i++) { unsigned int byte; if (sscanf(hex_str + i * 2, "%2x", &byte) != 1) return -1; @@ -76,33 +57,21 @@ sc_status_t sc_init_ctx(sc_context_t *ctx, struct SC_MYKEYS *mykeys) { // Common helper functions for input validation and CRC handling -static sc_status_t validate_encrypt_inputs(sc_context_t *ctx, const uint8_t *plaintext, +static sc_status_t validate_encrypt_inputs(sc_context_t *ctx, const uint8_t *plaintext, const uint8_t *ciphertext, const size_t *ciphertext_len, size_t plaintext_len) { - if (!ctx || !plaintext || !ciphertext || !ciphertext_len) { - return SC_ERR_INVALID_ARG; - } - if (!ctx->session_ready) { - return SC_ERR_NOT_INITIALIZED; - } - if (plaintext_len == 0) { - return SC_ERR_INVALID_ARG; - } + if (!ctx || !plaintext || !ciphertext || !ciphertext_len) return SC_ERR_INVALID_ARG; + if (!ctx->session_ready) return SC_ERR_NOT_INITIALIZED; + if (plaintext_len == 0) return SC_ERR_INVALID_ARG; return SC_OK; } static sc_status_t validate_decrypt_inputs(sc_context_t *ctx, const uint8_t *ciphertext, const uint8_t *plaintext, const size_t *plaintext_len, size_t ciphertext_len) { - if (!ctx || !ciphertext || !plaintext || !plaintext_len) { - return SC_ERR_INVALID_ARG; - } - if (!ctx->session_ready) { - return SC_ERR_NOT_INITIALIZED; - } - if (ciphertext_len < SC_NONCE_SIZE + SC_TAG_SIZE + SC_CRC32_SIZE) { - return SC_ERR_INVALID_ARG; - } + if (!ctx || !ciphertext || !plaintext || !plaintext_len) return SC_ERR_INVALID_ARG; + if (!ctx->session_ready) return SC_ERR_NOT_INITIALIZED; + if (ciphertext_len < SC_NONCE_SIZE + SC_TAG_SIZE + SC_CRC32_SIZE) return SC_ERR_INVALID_ARG; return SC_OK; } @@ -123,9 +92,7 @@ static sc_status_t verify_and_strip_crc32(uint8_t *plaintext_with_crc, size_t to ((uint32_t)plaintext_with_crc[data_len + 2] << 16) | ((uint32_t)plaintext_with_crc[data_len + 3] << 24); uint32_t calc_crc = crc32_calc(plaintext_with_crc, data_len); - if (received_crc != calc_crc) { - return SC_ERR_CRC_FAILED; - } + if (received_crc != calc_crc) return SC_ERR_CRC_FAILED; memcpy(plaintext, plaintext_with_crc, data_len); *plaintext_len = data_len; return SC_OK; @@ -134,12 +101,10 @@ static sc_status_t verify_and_strip_crc32(uint8_t *plaintext_with_crc, size_t to static void sc_derive_session_key(const uint8_t *shared_secret, uint8_t *session_key) { SC_SHA256_CTX sha_ctx; uint8_t hash[SC_HASH_SIZE]; - sc_sha256_init(&sha_ctx); sc_sha256_update(&sha_ctx, shared_secret, SC_SHARED_SECRET_SIZE); sc_sha256_update(&sha_ctx, (const uint8_t *)"uTun-v3-session", 15); sc_sha256_final(&sha_ctx, hash); - memcpy(session_key, hash, SC_SESSION_KEY_SIZE); } @@ -160,94 +125,38 @@ static void sc_stream_derive_nonce(const uint8_t *session_key, uint32_t stream_i memcpy(nonce_out, hash, SC_STREAM_NONCE_SIZE); } -#ifdef USE_OPENSSL - -// OpenSSL-specific implementations - -static int sc_rng(uint8_t *dest, unsigned size) { - if (random_bytes(dest, size) != 0) { - return 0; - } - /* Mix in PID and microtime for additional entropy */ -#ifdef _WIN32 - DWORD pid = GetCurrentProcessId(); -#else - pid_t pid = getpid(); -#endif - struct timeval tv; - utun_gettimeofday(&tv, NULL); - for (unsigned i = 0; i < size; i++) { - dest[i] ^= ((pid >> (i % (sizeof(pid) * 8))) & 0xFF); - dest[i] ^= ((tv.tv_sec >> (i % (sizeof(tv.tv_sec) * 8))) & 0xFF); - dest[i] ^= ((tv.tv_usec >> (i % (sizeof(tv.tv_usec) * 8))) & 0xFF); - } - return 1; -} - +// X25519: any non-zero 32-byte value is a valid public key static int sc_validate_key(const uint8_t *public_key) { - EC_GROUP *group = EC_GROUP_new_by_curve_name(NID_X9_62_prime256v1); - if (!group) return -1; - EC_POINT *point = EC_POINT_new(group); - if (!point) { - EC_GROUP_free(group); + uint8_t zero[SC_PUBKEY_SIZE] = {0}; + if (memcmp(public_key, zero, SC_PUBKEY_SIZE) == 0) { + DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_validate_key: all-zero public key"); return -1; } - BIGNUM *x = BN_bin2bn(public_key, 32, NULL); - BIGNUM *y = BN_bin2bn(public_key + 32, 32, NULL); - if (!x || !y || EC_POINT_set_affine_coordinates(group, point, x, y, NULL) != 1) { - BN_free(x); - BN_free(y); - EC_POINT_free(point); - EC_GROUP_free(group); - return -1; - } - int result = EC_POINT_is_on_curve(group, point, NULL); - BN_free(x); - BN_free(y); - EC_POINT_free(point); - EC_GROUP_free(group); - // To match TinyCrypt return convention in the provided code (0 valid, !=0 invalid) - return (result == 1) ? 0 : -1; + return 0; } sc_status_t sc_generate_keypair(struct SC_MYKEYS *pk) { - if (!pk) { - return SC_ERR_INVALID_ARG; - } - EC_GROUP *group = EC_GROUP_new_by_curve_name(NID_X9_62_prime256v1); - if (!group) return SC_ERR_CRYPTO; - EC_KEY *key = EC_KEY_new(); - if (!key) { - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - if (EC_KEY_set_group(key, group) != 1) { - EC_KEY_free(key); - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - // Use custom RNG if needed, but OpenSSL RAND is fine; for consistency, seed if necessary - if (EC_KEY_generate_key(key) != 1) { - EC_KEY_free(key); - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - const BIGNUM *priv = EC_KEY_get0_private_key(key); - if (BN_bn2binpad(priv, pk->private_key, SC_PRIVKEY_SIZE) != SC_PRIVKEY_SIZE) { - EC_KEY_free(key); - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - const EC_POINT *pub_point = EC_KEY_get0_public_key(key); - uint8_t pub_buf[65]; - if (EC_POINT_point2oct(group, pub_point, POINT_CONVERSION_UNCOMPRESSED, pub_buf, 65, NULL) != 65) { - EC_KEY_free(key); - EC_GROUP_free(group); + if (!pk) return SC_ERR_INVALID_ARG; + + EVP_PKEY_CTX *ctx = EVP_PKEY_CTX_new_id(EVP_PKEY_X25519, NULL); + if (!ctx) return SC_ERR_CRYPTO; + if (EVP_PKEY_keygen_init(ctx) <= 0) { EVP_PKEY_CTX_free(ctx); return SC_ERR_CRYPTO; } + + EVP_PKEY *pkey = NULL; + if (EVP_PKEY_keygen(ctx, &pkey) <= 0) { EVP_PKEY_CTX_free(ctx); return SC_ERR_CRYPTO; } + EVP_PKEY_CTX_free(ctx); + + size_t priv_len = SC_PRIVKEY_SIZE, pub_len = SC_PUBKEY_SIZE; + if (EVP_PKEY_get_raw_private_key(pkey, pk->private_key, &priv_len) <= 0 + || priv_len != SC_PRIVKEY_SIZE + || EVP_PKEY_get_raw_public_key(pkey, pk->public_key, &pub_len) <= 0 + || pub_len != SC_PUBKEY_SIZE) { + DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: failed to extract raw keys"); + EVP_PKEY_free(pkey); return SC_ERR_CRYPTO; } - memcpy(pk->public_key, pub_buf + 1, SC_PUBKEY_SIZE); // Skip 0x04 prefix - EC_KEY_free(key); - EC_GROUP_free(group); + EVP_PKEY_free(pkey); + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: generated valid X25519 keypair"); return SC_OK; } @@ -256,7 +165,7 @@ sc_status_t sc_init_local_keys(struct SC_MYKEYS *mykeys, const char *public_key, DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: invalid arguments"); return SC_ERR_INVALID_ARG; } - DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: public_key len=%zu, private_key len=%zu", + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: public_key len=%zu, private_key len=%zu", strlen(public_key), strlen(private_key)); if (hex_to_binary(public_key, mykeys->public_key, SC_PUBKEY_SIZE)) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: failed to convert public key from hex"); @@ -284,81 +193,46 @@ sc_status_t sc_set_peer_public_key(sc_context_t *ctx, const uint8_t *peer_public } else { memcpy(peer_public_key, peer_public_key_h, SC_PUBKEY_SIZE); } - if (!ctx) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid ctx"); - return SC_ERR_INVALID_ARG; - } - if (!ctx->initialized) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: ctx not initialized"); - return SC_ERR_NOT_INITIALIZED; - } - if (sc_validate_key(peer_public_key) != 0) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid key"); - return SC_ERR_INVALID_ARG; - } - if (!ctx->pk) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: no private key"); - return SC_ERR_NOT_INITIALIZED; - } - EC_GROUP *group = EC_GROUP_new_by_curve_name(NID_X9_62_prime256v1); - if (!group) return SC_ERR_CRYPTO; - EC_KEY *my_key = EC_KEY_new(); - if (!my_key) { - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - if (EC_KEY_set_group(my_key, group) != 1) { - EC_KEY_free(my_key); - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - BIGNUM *my_priv = BN_bin2bn(ctx->pk->private_key, SC_PRIVKEY_SIZE, NULL); - if (!my_priv || EC_KEY_set_private_key(my_key, my_priv) != 1) { - BN_free(my_priv); - EC_KEY_free(my_key); - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - EC_POINT *peer_point = EC_POINT_new(group); - if (!peer_point) { - BN_free(my_priv); - EC_KEY_free(my_key); - EC_GROUP_free(group); + if (!ctx) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid ctx"); return SC_ERR_INVALID_ARG; } + if (!ctx->initialized) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: ctx not initialized"); return SC_ERR_NOT_INITIALIZED; } + if (sc_validate_key(peer_public_key) != 0) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid key"); return SC_ERR_INVALID_ARG; } + if (!ctx->pk) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: no private key"); return SC_ERR_NOT_INITIALIZED; } + + EVP_PKEY *my_pkey = EVP_PKEY_new_raw_private_key(EVP_PKEY_X25519, NULL, ctx->pk->private_key, SC_PRIVKEY_SIZE); + if (!my_pkey) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: EVP_PKEY_new_raw_private_key failed"); return SC_ERR_CRYPTO; } + EVP_PKEY *peer_pkey = EVP_PKEY_new_raw_public_key(EVP_PKEY_X25519, NULL, peer_public_key, SC_PUBKEY_SIZE); + if (!peer_pkey) { EVP_PKEY_free(my_pkey); DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: EVP_PKEY_new_raw_public_key failed"); return SC_ERR_CRYPTO; } + + EVP_PKEY_CTX *derive_ctx = EVP_PKEY_CTX_new(my_pkey, NULL); + if (!derive_ctx) { EVP_PKEY_free(my_pkey); EVP_PKEY_free(peer_pkey); return SC_ERR_CRYPTO; } + if (EVP_PKEY_derive_init(derive_ctx) <= 0) { + EVP_PKEY_CTX_free(derive_ctx); EVP_PKEY_free(my_pkey); EVP_PKEY_free(peer_pkey); + DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: EVP_PKEY_derive_init failed"); return SC_ERR_CRYPTO; } - BIGNUM *x = BN_bin2bn(peer_public_key, 32, NULL); - BIGNUM *y = BN_bin2bn(peer_public_key + 32, 32, NULL); - if (!x || !y || EC_POINT_set_affine_coordinates(group, peer_point, x, y, NULL) != 1) { - BN_free(x); - BN_free(y); - BN_free(my_priv); - EC_POINT_free(peer_point); - EC_KEY_free(my_key); - EC_GROUP_free(group); + if (EVP_PKEY_derive_set_peer(derive_ctx, peer_pkey) <= 0) { + EVP_PKEY_CTX_free(derive_ctx); EVP_PKEY_free(my_pkey); EVP_PKEY_free(peer_pkey); + DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: EVP_PKEY_derive_set_peer failed"); return SC_ERR_CRYPTO; } + uint8_t shared_secret[SC_SHARED_SECRET_SIZE]; - int len = ECDH_compute_key(shared_secret, SC_SHARED_SECRET_SIZE, peer_point, my_key, NULL); - if (len != SC_SHARED_SECRET_SIZE) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: shared secret error"); - BN_free(x); - BN_free(y); - BN_free(my_priv); - EC_POINT_free(peer_point); - EC_KEY_free(my_key); - EC_GROUP_free(group); + size_t secret_len = SC_SHARED_SECRET_SIZE; + if (EVP_PKEY_derive(derive_ctx, shared_secret, &secret_len) <= 0 || secret_len != SC_SHARED_SECRET_SIZE) { + EVP_PKEY_CTX_free(derive_ctx); EVP_PKEY_free(my_pkey); EVP_PKEY_free(peer_pkey); + DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: X25519 derive failed secret_len=%zu", secret_len); return SC_ERR_CRYPTO; } + sc_derive_session_key(shared_secret, ctx->session_key); memcpy(ctx->peer_public_key, peer_public_key, SC_PUBKEY_SIZE); ctx->peer_key_set = 1; ctx->session_ready = 1; - BN_free(x); - BN_free(y); - BN_free(my_priv); - EC_POINT_free(peer_point); - EC_KEY_free(my_key); - EC_GROUP_free(group); + + EVP_PKEY_CTX_free(derive_ctx); + EVP_PKEY_free(my_pkey); + EVP_PKEY_free(peer_pkey); + DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: X25519 key exchange complete"); return SC_OK; } @@ -367,27 +241,17 @@ static void sc_build_nonce(uint64_t counter, uint8_t *nonce_out) { uint8_t hash[32]; struct timeval tv; uint8_t data[24]; - if (!sc_urandom_initialized) { - sc_init_random_seed(); - } + if (!sc_urandom_initialized) sc_init_random_seed(); utun_gettimeofday(&tv, NULL); memcpy(data, sc_urandom_seed, 8); - data[8] = (counter >> 0) & 0xFF; - data[9] = (counter >> 8) & 0xFF; - data[10] = (counter >> 16) & 0xFF; - data[11] = (counter >> 24) & 0xFF; - data[12] = (counter >> 32) & 0xFF; - data[13] = (counter >> 40) & 0xFF; - data[14] = (counter >> 48) & 0xFF; - data[15] = (counter >> 56) & 0xFF; - data[16] = (tv.tv_sec >> 0) & 0xFF; - data[17] = (tv.tv_sec >> 8) & 0xFF; - data[18] = (tv.tv_sec >> 16) & 0xFF; - data[19] = (tv.tv_sec >> 24) & 0xFF; - data[20] = (tv.tv_usec >> 0) & 0xFF; - data[21] = (tv.tv_usec >> 8) & 0xFF; - data[22] = (tv.tv_usec >> 16) & 0xFF; - data[23] = (tv.tv_usec >> 24) & 0xFF; + data[8] = (counter >> 0) & 0xFF; data[9] = (counter >> 8) & 0xFF; + data[10] = (counter >> 16) & 0xFF; data[11] = (counter >> 24) & 0xFF; + data[12] = (counter >> 32) & 0xFF; data[13] = (counter >> 40) & 0xFF; + data[14] = (counter >> 48) & 0xFF; data[15] = (counter >> 56) & 0xFF; + data[16] = (tv.tv_sec >> 0) & 0xFF; data[17] = (tv.tv_sec >> 8) & 0xFF; + data[18] = (tv.tv_sec >> 16) & 0xFF; data[19] = (tv.tv_sec >> 24) & 0xFF; + data[20] = (tv.tv_usec >> 0) & 0xFF; data[21] = (tv.tv_usec >> 8) & 0xFF; + data[22] = (tv.tv_usec >> 16) & 0xFF; data[23] = (tv.tv_usec >> 24) & 0xFF; SHA256_Init(&sha_ctx); SHA256_Update(&sha_ctx, data, 24); SHA256_Final(hash, &sha_ctx); @@ -405,39 +269,22 @@ sc_status_t sc_encrypt(sc_context_t *ctx, const uint8_t *plaintext, size_t plain sc_build_nonce(ctx->tx_counter, nonce); EVP_CIPHER_CTX *ectx = EVP_CIPHER_CTX_new(); if (!ectx) return SC_ERR_CRYPTO; - if (EVP_EncryptInit_ex(ectx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1) { - EVP_CIPHER_CTX_free(ectx); - return SC_ERR_CRYPTO; - } - if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_IVLEN, SC_NONCE_SIZE, NULL) != 1) { - EVP_CIPHER_CTX_free(ectx); - return SC_ERR_CRYPTO; - } - if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_TAG, SC_TAG_SIZE, NULL) != 1) { - EVP_CIPHER_CTX_free(ectx); - return SC_ERR_CRYPTO; - } - if (EVP_EncryptInit_ex(ectx, NULL, NULL, ctx->session_key, nonce) != 1) { - EVP_CIPHER_CTX_free(ectx); - return SC_ERR_CRYPTO; + if (EVP_EncryptInit_ex(ectx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1 + || EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_IVLEN, SC_NONCE_SIZE, NULL) != 1 + || EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_SET_TAG, SC_TAG_SIZE, NULL) != 1 + || EVP_EncryptInit_ex(ectx, NULL, NULL, ctx->session_key, nonce) != 1) { + EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO; } int outlen; uint8_t outbuf[total_plaintext_len]; - if (EVP_EncryptUpdate(ectx, outbuf, &outlen, plaintext_with_crc, total_plaintext_len) != 1 || - outlen != (int)total_plaintext_len) { - EVP_CIPHER_CTX_free(ectx); - return SC_ERR_CRYPTO; + if (EVP_EncryptUpdate(ectx, outbuf, &outlen, plaintext_with_crc, total_plaintext_len) != 1 + || outlen != (int)total_plaintext_len) { + EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO; } int tmp; - if (EVP_EncryptFinal_ex(ectx, outbuf + outlen, &tmp) != 1) { - EVP_CIPHER_CTX_free(ectx); - return SC_ERR_CRYPTO; - } + if (EVP_EncryptFinal_ex(ectx, outbuf + outlen, &tmp) != 1) { EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO; } uint8_t tag[SC_TAG_SIZE]; - if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_GET_TAG, SC_TAG_SIZE, tag) != 1) { - EVP_CIPHER_CTX_free(ectx); - return SC_ERR_CRYPTO; - } + if (EVP_CIPHER_CTX_ctrl(ectx, EVP_CTRL_AEAD_GET_TAG, SC_TAG_SIZE, tag) != 1) { EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO; } memcpy(ciphertext, nonce, SC_NONCE_SIZE); memcpy(ciphertext + SC_NONCE_SIZE, outbuf, total_plaintext_len); memcpy(ciphertext + SC_NONCE_SIZE + total_plaintext_len, tag, SC_TAG_SIZE); @@ -459,79 +306,39 @@ sc_status_t sc_decrypt(sc_context_t *ctx, const uint8_t *ciphertext, size_t ciph uint8_t plaintext_with_crc[total_plaintext_len]; EVP_CIPHER_CTX *dctx = EVP_CIPHER_CTX_new(); if (!dctx) return SC_ERR_CRYPTO; - if (EVP_DecryptInit_ex(dctx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1) { - EVP_CIPHER_CTX_free(dctx); - return SC_ERR_CRYPTO; - } - if (EVP_CIPHER_CTX_ctrl(dctx, EVP_CTRL_AEAD_SET_IVLEN, SC_NONCE_SIZE, NULL) != 1) { - EVP_CIPHER_CTX_free(dctx); - return SC_ERR_CRYPTO; - } - if (EVP_CIPHER_CTX_ctrl(dctx, EVP_CTRL_AEAD_SET_TAG, SC_TAG_SIZE, (void *)(encrypted_data + total_plaintext_len)) != 1) { - EVP_CIPHER_CTX_free(dctx); - return SC_ERR_CRYPTO; - } - if (EVP_DecryptInit_ex(dctx, NULL, NULL, ctx->session_key, nonce) != 1) { - EVP_CIPHER_CTX_free(dctx); - return SC_ERR_CRYPTO; + if (EVP_DecryptInit_ex(dctx, EVP_aes_128_ccm(), NULL, NULL, NULL) != 1 + || EVP_CIPHER_CTX_ctrl(dctx, EVP_CTRL_AEAD_SET_IVLEN, SC_NONCE_SIZE, NULL) != 1 + || EVP_CIPHER_CTX_ctrl(dctx, EVP_CTRL_AEAD_SET_TAG, SC_TAG_SIZE, (void *)(encrypted_data + total_plaintext_len)) != 1 + || EVP_DecryptInit_ex(dctx, NULL, NULL, ctx->session_key, nonce) != 1) { + EVP_CIPHER_CTX_free(dctx); return SC_ERR_CRYPTO; } int outlen; - if (EVP_DecryptUpdate(dctx, plaintext_with_crc, &outlen, encrypted_data, total_plaintext_len) != 1 || - outlen != (int)total_plaintext_len) { - EVP_CIPHER_CTX_free(dctx); - return SC_ERR_AUTH_FAILED; + if (EVP_DecryptUpdate(dctx, plaintext_with_crc, &outlen, encrypted_data, total_plaintext_len) != 1 + || outlen != (int)total_plaintext_len) { + EVP_CIPHER_CTX_free(dctx); return SC_ERR_AUTH_FAILED; } int tmp; - if (EVP_DecryptFinal_ex(dctx, plaintext_with_crc + outlen, &tmp) != 1) { - EVP_CIPHER_CTX_free(dctx); - return SC_ERR_AUTH_FAILED; - } + if (EVP_DecryptFinal_ex(dctx, plaintext_with_crc + outlen, &tmp) != 1) { EVP_CIPHER_CTX_free(dctx); return SC_ERR_AUTH_FAILED; } EVP_CIPHER_CTX_free(dctx); sc_status_t result = verify_and_strip_crc32(plaintext_with_crc, total_plaintext_len, plaintext, plaintext_len); - if (result == SC_OK) { - ctx->rx_counter++; - } + if (result == SC_OK) ctx->rx_counter++; return result; } sc_status_t sc_compute_public_key_from_private(const uint8_t *private_key, uint8_t *public_key) { - if (!private_key || !public_key) { - return SC_ERR_INVALID_ARG; - } - EC_GROUP *group = EC_GROUP_new_by_curve_name(NID_X9_62_prime256v1); - if (!group) return SC_ERR_CRYPTO; - BIGNUM *priv = BN_bin2bn(private_key, SC_PRIVKEY_SIZE, NULL); - if (!priv) { - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - EC_POINT *pub_point = EC_POINT_new(group); - if (!pub_point) { - BN_free(priv); - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - if (EC_POINT_mul(group, pub_point, priv, NULL, NULL, NULL) != 1) { - EC_POINT_free(pub_point); - BN_free(priv); - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - uint8_t pub_buf[65]; - if (EC_POINT_point2oct(group, pub_point, POINT_CONVERSION_UNCOMPRESSED, pub_buf, 65, NULL) != 65) { - EC_POINT_free(pub_point); - BN_free(priv); - EC_GROUP_free(group); - return SC_ERR_CRYPTO; - } - memcpy(public_key, pub_buf + 1, SC_PUBKEY_SIZE); - EC_POINT_free(pub_point); - BN_free(priv); - EC_GROUP_free(group); + if (!private_key || !public_key) return SC_ERR_INVALID_ARG; + EVP_PKEY *pkey = EVP_PKEY_new_raw_private_key(EVP_PKEY_X25519, NULL, private_key, SC_PRIVKEY_SIZE); + if (!pkey) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_compute_public_key_from_private: EVP_PKEY_new_raw_private_key failed"); return SC_ERR_CRYPTO; } + size_t pub_len = SC_PUBKEY_SIZE; + if (EVP_PKEY_get_raw_public_key(pkey, public_key, &pub_len) <= 0 || pub_len != SC_PUBKEY_SIZE) { + DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_compute_public_key_from_private: EVP_PKEY_get_raw_public_key failed"); + EVP_PKEY_free(pkey); return SC_ERR_CRYPTO; + } + EVP_PKEY_free(pkey); return SC_OK; } -// --- OpenSSL streaming cipher (AES-128-CTR) --- +// --- Streaming cipher (AES-128-CTR) --- sc_status_t sc_stream_init(sc_context_t *ctx, struct sc_stream_state *state, uint32_t stream_id) { if (!ctx || !state) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: invalid args"); return SC_ERR_INVALID_ARG; } @@ -545,8 +352,7 @@ sc_status_t sc_stream_init(sc_context_t *ctx, struct sc_stream_state *state, uin if (!ectx) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: EVP_CIPHER_CTX_new failed"); return SC_ERR_CRYPTO; } if (EVP_EncryptInit_ex(ectx, EVP_aes_128_ctr(), NULL, ctx->session_key, iv) != 1) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: EVP_EncryptInit_ex failed"); - EVP_CIPHER_CTX_free(ectx); - return SC_ERR_CRYPTO; + EVP_CIPHER_CTX_free(ectx); return SC_ERR_CRYPTO; } state->ectx = ectx; state->initialized = 1; @@ -575,385 +381,31 @@ void sc_stream_cleanup(struct sc_stream_state *state) { state->initialized = 0; } -#else - -// Original TinyCrypt implementations (unchanged logic) - -static const struct uECC_Curve_t *curve = NULL; - -static int sc_rng(uint8_t *dest, unsigned size) -{ - if (random_bytes(dest, size) != 0) { - return 0; - } - /* Mix in PID and microtime for additional entropy */ -#ifdef _WIN32 - DWORD pid = GetCurrentProcessId(); -#else - pid_t pid = getpid(); -#endif - struct timeval tv; - utun_gettimeofday(&tv, NULL); - for (unsigned i = 0; i < size; i++) { - dest[i] ^= ((pid >> (i % (sizeof(pid) * 8))) & 0xFF); - dest[i] ^= ((tv.tv_sec >> (i % (sizeof(tv.tv_sec) * 8))) & 0xFF); - dest[i] ^= ((tv.tv_usec >> (i % (sizeof(tv.tv_usec) * 8))) & 0xFF); - } - return 1; -} - -static int sc_validate_key(const uint8_t *public_key) -{ - if (!curve) { - curve = uECC_secp256r1(); - } - int result = uECC_valid_public_key(public_key, curve); - DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_validate_key: uECC_valid_public_key returned %d", result); - return result; -} - -sc_status_t sc_generate_keypair(struct SC_MYKEYS *pk) -{ - if (!pk) { - return SC_ERR_INVALID_ARG; - } - - if (!curve) { - curve = uECC_secp256r1(); - } - - /* Set custom RNG function */ - uECC_set_rng(sc_rng); - - /* Try to generate valid key pair (max 10 attempts) */ - for (int attempt = 0; attempt < 10; attempt++) { - if (!uECC_make_key(pk->public_key, pk->private_key, curve)) { - continue; - } - /* Validate generated public key immediately */ - if (sc_validate_key(pk->public_key) == 0) { - DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: generated valid keypair on attempt %d", attempt + 1); - return SC_OK; - } - DEBUG_WARN(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: generated invalid key on attempt %d, retrying...", attempt + 1); - } - - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_generate_keypair: failed to generate valid keypair after 10 attempts"); - return SC_ERR_CRYPTO; -} - -sc_status_t sc_init_local_keys(struct SC_MYKEYS *mykeys, const char *public_key, const char *private_key) { - if (!mykeys || !public_key || !private_key) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: invalid arguments"); - return SC_ERR_INVALID_ARG; - } - - if (!curve) { - curve = uECC_secp256r1(); - } - - /* Set RNG function for TinyCrypt - must be done before any ECC operations */ - uECC_set_rng(sc_rng); - - DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: public_key len=%zu, private_key len=%zu", - strlen(public_key), strlen(private_key)); - - /* Convert hex to binary first */ - if (hex_to_binary(public_key, mykeys->public_key, SC_PUBKEY_SIZE)) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: failed to convert public key from hex"); - return SC_ERR_INVALID_ARG; - } - if (hex_to_binary(private_key, mykeys->private_key, SC_PRIVKEY_SIZE)) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: failed to convert private key from hex"); - return SC_ERR_INVALID_ARG; - } - - /* Validate the converted binary public key */ - if (sc_validate_key(mykeys->public_key) != 0) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: public key validation failed"); - return SC_ERR_INVALID_ARG; - } - - DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_init_local_keys: keys initialized successfully"); - return SC_OK; -} - -sc_status_t sc_set_peer_public_key(sc_context_t *ctx, const uint8_t *peer_public_key_h, int mode) { - uint8_t shared_secret[SC_SHARED_SECRET_SIZE]; - uint8_t peer_public_key[SC_PUBKEY_SIZE]; - - if (mode) { - if (hex_to_binary((const char*)peer_public_key_h, peer_public_key, SC_PUBKEY_SIZE)) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid hex key format"); - return SC_ERR_INVALID_ARG; - } - } - else memcpy(peer_public_key, peer_public_key_h, SC_PUBKEY_SIZE); - - if (!ctx) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid ctx"); - return SC_ERR_INVALID_ARG; - } - - if (!ctx->initialized) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: ctx not initialized"); - return SC_ERR_NOT_INITIALIZED; - } - - if (!curve) { - curve = uECC_secp256r1(); - } - - /* Validate peer public key */ - if (sc_validate_key(peer_public_key) != 0) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: invalid key"); - return SC_ERR_INVALID_ARG; - } - - /* Compute shared secret using ECDH */ - if (!ctx->pk) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: no private key"); - return SC_ERR_NOT_INITIALIZED; - } - if (!uECC_shared_secret(peer_public_key, ctx->pk->private_key, - shared_secret, curve)) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_set_peer_public_key: shared secret error"); - return SC_ERR_CRYPTO; - } - - sc_derive_session_key(shared_secret, ctx->session_key); - - /* Store peer public key */ - memcpy(ctx->peer_public_key, peer_public_key, SC_PUBKEY_SIZE); - ctx->peer_key_set = 1; - - ctx->session_ready = 1; - - return SC_OK; -} - -static void sc_build_nonce(uint64_t counter, uint8_t *nonce_out) -{ - struct tc_sha256_state_struct sha_ctx; - uint8_t hash[32]; - struct timeval tv; - uint8_t data[8 + 8 + 8]; - - if (!sc_urandom_initialized) { - sc_init_random_seed(); - } - - utun_gettimeofday(&tv, NULL); - - memcpy(data, sc_urandom_seed, 8); - data[8] = (counter >> 0) & 0xFF; - data[9] = (counter >> 8) & 0xFF; - data[10] = (counter >> 16) & 0xFF; - data[11] = (counter >> 24) & 0xFF; - data[12] = (counter >> 32) & 0xFF; - data[13] = (counter >> 40) & 0xFF; - data[14] = (counter >> 48) & 0xFF; - data[15] = (counter >> 56) & 0xFF; - data[16] = (tv.tv_sec >> 0) & 0xFF; - data[17] = (tv.tv_sec >> 8) & 0xFF; - data[18] = (tv.tv_sec >> 16) & 0xFF; - data[19] = (tv.tv_sec >> 24) & 0xFF; - data[20] = (tv.tv_usec >> 0) & 0xFF; - data[21] = (tv.tv_usec >> 8) & 0xFF; - data[22] = (tv.tv_usec >> 16) & 0xFF; - data[23] = (tv.tv_usec >> 24) & 0xFF; - - tc_sha256_init(&sha_ctx); - tc_sha256_update(&sha_ctx, data, 24); - tc_sha256_final(hash, &sha_ctx); - - memcpy(nonce_out, hash, SC_NONCE_SIZE); -} - -sc_status_t sc_encrypt(sc_context_t *ctx, const uint8_t *plaintext, size_t plaintext_len, uint8_t *ciphertext, size_t *ciphertext_len) { - sc_status_t status = validate_encrypt_inputs(ctx, plaintext, ciphertext, ciphertext_len, plaintext_len); - if (status != SC_OK) return status; - - uint8_t nonce[SC_NONCE_SIZE]; - uint8_t plaintext_with_crc[plaintext_len + SC_CRC32_SIZE]; - size_t total_plaintext_len = plaintext_len + SC_CRC32_SIZE; - uint8_t combined_output[total_plaintext_len + SC_TAG_SIZE]; - struct tc_aes_key_sched_struct sched; - struct tc_ccm_mode_struct ccm_state; - - /* Добавляем CRC32 к данным */ - append_crc32(plaintext, plaintext_len, plaintext_with_crc); - - /* Генерируем nonce с таймером */ - sc_build_nonce(ctx->tx_counter, nonce); - - /* Initialize AES key schedule */ - if (tc_aes128_set_encrypt_key(&sched, ctx->session_key) != TC_CRYPTO_SUCCESS) { - return SC_ERR_CRYPTO; - } - - /* Configure CCM mode */ - if (tc_ccm_config(&ccm_state, &sched, nonce, SC_NONCE_SIZE, SC_TAG_SIZE) != TC_CRYPTO_SUCCESS) { - return SC_ERR_CRYPTO; - } - - /* Encrypt and generate tag */ - if (tc_ccm_generation_encryption(combined_output, sizeof(combined_output), - NULL, 0, /* no associated data */ - plaintext_with_crc, total_plaintext_len, - &ccm_state) != TC_CRYPTO_SUCCESS) { - return SC_ERR_CRYPTO; - } - - /* Copy nonce + ciphertext + tag to output buffer */ - memcpy(ciphertext, nonce, SC_NONCE_SIZE); - memcpy(ciphertext + SC_NONCE_SIZE, combined_output, total_plaintext_len + SC_TAG_SIZE); - *ciphertext_len = SC_NONCE_SIZE + total_plaintext_len + SC_TAG_SIZE; - - ctx->tx_counter++; - - return SC_OK; -} - -sc_status_t sc_decrypt(sc_context_t *ctx, - const uint8_t *ciphertext, - size_t ciphertext_len, - uint8_t *plaintext, - size_t *plaintext_len) -{ - sc_status_t status = validate_decrypt_inputs(ctx, ciphertext, plaintext, plaintext_len, ciphertext_len); - if (status != SC_OK) return status; - - uint8_t nonce[SC_NONCE_SIZE]; - struct tc_aes_key_sched_struct sched; - struct tc_ccm_mode_struct ccm_state; - size_t total_plaintext_len = ciphertext_len - SC_NONCE_SIZE - SC_TAG_SIZE; - uint8_t plaintext_with_crc[total_plaintext_len]; - - /* Извлекаем nonce из начала ciphertext */ - memcpy(nonce, ciphertext, SC_NONCE_SIZE); - - /* Ciphertext для расшифровки начинается после nonce */ - const uint8_t *encrypted_data = ciphertext + SC_NONCE_SIZE; - size_t encrypted_len = ciphertext_len - SC_NONCE_SIZE; - - /* Initialize AES key schedule */ - if (tc_aes128_set_encrypt_key(&sched, ctx->session_key) != TC_CRYPTO_SUCCESS) { - return SC_ERR_CRYPTO; - } - - /* Configure CCM mode с извлечённым nonce */ - if (tc_ccm_config(&ccm_state, &sched, nonce, SC_NONCE_SIZE, SC_TAG_SIZE) != TC_CRYPTO_SUCCESS) { - return SC_ERR_CRYPTO; - } - - /* Decrypt and verify tag */ - if (tc_ccm_decryption_verification(plaintext_with_crc, total_plaintext_len, - NULL, 0, /* no associated data */ - encrypted_data, encrypted_len, - &ccm_state) != TC_CRYPTO_SUCCESS) { - return SC_ERR_AUTH_FAILED; - } - - /* Проверяем CRC32 используя helper-функцию */ - sc_status_t result = verify_and_strip_crc32(plaintext_with_crc, total_plaintext_len, plaintext, plaintext_len); - if (result == SC_OK) { - ctx->rx_counter++; - } - return result; -} - -sc_status_t sc_compute_public_key_from_private(const uint8_t *private_key, uint8_t *public_key) { - if (!private_key || !public_key) { - return SC_ERR_INVALID_ARG; - } - - if (!curve) { - curve = uECC_secp256r1(); - } - - if (!uECC_compute_public_key(private_key, public_key, curve)) { - return SC_ERR_CRYPTO; - } - return SC_OK; -} - -// --- TinyCrypt streaming cipher (AES-128-CTR) --- - -sc_status_t sc_stream_init(sc_context_t *ctx, struct sc_stream_state *state, uint32_t stream_id) { - if (!ctx || !state) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: invalid args"); return SC_ERR_INVALID_ARG; } - if (!ctx->session_ready) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: session not ready"); return SC_ERR_NOT_INITIALIZED; } - uint8_t nonce[SC_STREAM_NONCE_SIZE]; - sc_stream_derive_nonce(ctx->session_key, stream_id, nonce); - memcpy(state->ctr_block, nonce, SC_STREAM_NONCE_SIZE); - memset(state->ctr_block + SC_STREAM_NONCE_SIZE, 0, 4); - if (tc_aes128_set_encrypt_key((TCAesKeySched_t)state->sched_buf, ctx->session_key) != TC_CRYPTO_SUCCESS) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: tc_aes128_set_encrypt_key failed"); - return SC_ERR_CRYPTO; - } - state->initialized = 1; - DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "sc_stream_init: stream_id=%u nonce=%02x%02x%02x%02x...", - stream_id, nonce[0], nonce[1], nonce[2], nonce[3]); - return SC_OK; -} - -sc_status_t sc_stream_xor(struct sc_stream_state *state, uint8_t *data, size_t data_len) { - if (data_len == 0) return SC_OK; - if (!state || !data) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_xor: invalid args"); return SC_ERR_INVALID_ARG; } - if (!state->initialized) { DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_xor: not initialized"); return SC_ERR_NOT_INITIALIZED; } - if (tc_ctr_mode(data, (unsigned int)data_len, data, (unsigned int)data_len, - state->ctr_block, (TCAesKeySched_t)state->sched_buf) != TC_CRYPTO_SUCCESS) { - DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "sc_stream_xor: tc_ctr_mode failed len=%zu", data_len); - return SC_ERR_CRYPTO; - } - return SC_OK; -} - -void sc_stream_cleanup(struct sc_stream_state *state) { - if (!state) return; - memset(state->sched_buf, 0, sizeof(state->sched_buf)); - memset(state->ctr_block, 0, sizeof(state->ctr_block)); - state->initialized = 0; -} - -#endif +// --- Common crypto utilities --- sc_status_t sc_sha_transcode(const uint8_t *key, size_t key_len, uint8_t *data, size_t data_len) { - if (!key || !data || key_len == 0 || data_len == 0) { - return SC_ERR_INVALID_ARG; - } - + if (!key || !data || key_len == 0 || data_len == 0) return SC_ERR_INVALID_ARG; uint8_t sha_hash[SC_HASH_SIZE]; SC_SHA256_CTX ctx; - sc_sha256_init(&ctx); sc_sha256_update(&ctx, key, key_len); sc_sha256_final(&ctx, sha_hash); - - for (size_t i = 0; i < data_len; i++) { - data[i] ^= sha_hash[i % SC_HASH_SIZE]; - } - + for (size_t i = 0; i < data_len; i++) data[i] ^= sha_hash[i % SC_HASH_SIZE]; return SC_OK; } sc_status_t sc_obfuscate_pubkey(const uint8_t *salt, const uint8_t *peer_pubkey, const uint8_t *pubkey, uint8_t *output) { if (!salt || !peer_pubkey || !pubkey || !output) return SC_ERR_INVALID_ARG; - uint8_t sha[SC_HASH_SIZE*2]; SC_SHA256_CTX ctx; - sc_sha256_init(&ctx); sc_sha256_update(&ctx, salt, SC_PUBKEY_ENC_SALT_SIZE); sc_sha256_update(&ctx, peer_pubkey, SC_PUBKEY_SIZE); sc_sha256_final(&ctx, sha); - sc_sha256_init(&ctx); sc_sha256_update(&ctx, peer_pubkey, SC_PUBKEY_SIZE); sc_sha256_update(&ctx, salt, SC_PUBKEY_ENC_SALT_SIZE); sc_sha256_final(&ctx, sha+SC_HASH_SIZE); - for (size_t i = 0; i < SC_PUBKEY_SIZE; i++) output[i] = pubkey[i] ^ sha[i]; - return SC_OK; } diff --git a/src/secure_channel.h b/src/secure_channel.h index eaac7c46..d073a092 100644 --- a/src/secure_channel.h +++ b/src/secure_channel.h @@ -7,7 +7,7 @@ // Размеры ключей #define SC_PRIVKEY_SIZE 32 -#define SC_PUBKEY_SIZE 64 +#define SC_PUBKEY_SIZE 32 #define SC_HASH_SIZE 32 #define SC_NONCE_SIZE 13 // CCM requires exactly 13 bytes #define SC_SHARED_SECRET_SIZE SC_HASH_SIZE @@ -15,7 +15,7 @@ #define SC_TAG_SIZE 16 #define SC_CRC32_SIZE 4 -// Шифрование pubkey при передаче (salt + double SHA256 XOR) +// Обфускация pubkey при передаче (salt + double SHA256 XOR) #define SC_PUBKEY_ENC_SALT_SIZE 8 #define SC_PUBKEY_ENC_SIZE (SC_PUBKEY_SIZE + SC_PUBKEY_ENC_SALT_SIZE) @@ -43,14 +43,10 @@ struct SC_MYKEYS { // Контекст защищенного канала struct secure_channel { struct SC_MYKEYS* pk; - /* Ключи пира (после key exchange) */ + /* Ключ пира (после key exchange) */ uint8_t peer_public_key[SC_PUBKEY_SIZE]; uint8_t session_key[SC_SESSION_KEY_SIZE]; /* Derived session key */ - /* Nonces для отправки и приема (теперь генерируются динамически, не используются counters для nonce) */ - uint8_t send_nonce[SC_NONCE_SIZE]; - uint8_t recv_nonce[SC_NONCE_SIZE]; - uint8_t initialized; uint8_t peer_key_set; uint8_t session_ready; @@ -78,15 +74,9 @@ sc_status_t sc_obfuscate_pubkey(const uint8_t *salt, const uint8_t *peer_pubkey, // --- Streaming cipher (AES-128-CTR, confidentiality only) --- #define SC_STREAM_NONCE_SIZE 12 -#define SC_STREAM_AES_SCHED_SIZE 176 // sizeof(struct tc_aes_key_sched_struct) = Nb*(Nr+1)*4 = 4*11*4 struct sc_stream_state { -#ifdef USE_OPENSSL - void *ectx; // EVP_CIPHER_CTX* (opaque, created/destroyed in .c) -#else - uint8_t sched_buf[SC_STREAM_AES_SCHED_SIZE]; // AES-128 key schedule - uint8_t ctr_block[16]; // nonce(12) + counter(4, BE) -#endif + void *ectx; // EVP_CIPHER_CTX* uint8_t initialized; }; diff --git a/tests/Makefile.am b/tests/Makefile.am index e9734415..d931ea73 100644 --- a/tests/Makefile.am +++ b/tests/Makefile.am @@ -49,36 +49,11 @@ check_PROGRAMS = \ bench_timeout_heap \ bench_uasync_timeouts -# Долгие тесты: запускаются только вручную, не включаются в make check -# test_etcp_congestion — DISABLED: старый congestion control удалён, ждёт новых BBR тестов -# test_tcp_proxy_remote — 2-node TCP через etcp, требует fix tcp_proxy_client singleton +# Долгие тесты: запускаются только вручную noinst_PROGRAMS = -# test_crypto and test_ecc_encrypt only needed for TinyCrypt (not when using OpenSSL) -if USE_OPENSSL -else -check_PROGRAMS += test_crypto test_ecc_encrypt -endif - # Basic includes -AM_CFLAGS = -g -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source - -# TinyCrypt source files -TINYCRYPT_SRCDIR = $(top_srcdir)/tinycrypt/lib/source - -# TinyCrypt object files (built by src/Makefile.am with utun- prefix) -TINYCRYPT_OBJS = \ - $(top_builddir)/src/utun-aes_encrypt.o \ - $(top_builddir)/src/utun-aes_decrypt.o \ - $(top_builddir)/src/utun-ccm_mode.o \ - $(top_builddir)/src/utun-cmac_mode.o \ - $(top_builddir)/src/utun-ctr_mode.o \ - $(top_builddir)/src/utun-ecc.o \ - $(top_builddir)/src/utun-ecc_dh.o \ - $(top_builddir)/src/utun-ecc_dsa.o \ - $(top_builddir)/src/utun-sha256.o \ - $(top_builddir)/src/utun-ecc_platform_specific.o \ - $(top_builddir)/src/utun-utils.o +AM_CFLAGS = -g -I$(top_srcdir)/src -I$(top_srcdir)/lib # Secure channel and CRC objects (built in src directory) SECURE_CHANNEL_OBJS = $(top_builddir)/src/utun-secure_channel.o $(top_builddir)/src/utun-crc32.o @@ -139,41 +114,18 @@ ETCP_FULL_OBJS = \ $(STCP_LINK_OBJS) \ $(ETCP_CORE_OBJS) -# Windows-specific libraries (advapi32 for CryptGenRandom, ws2_32 for sockets) +# Windows-specific libraries if OS_WINDOWS WIN_LIBS = -lws2_32 -liphlpapi -ladvapi32 -lbcrypt -ldbghelp else WIN_LIBS = endif -# Common libraries (libuasync.a from lib directory) +# Common libraries COMMON_LIBS = $(top_builddir)/lib/libuasync.a -lpthread $(WIN_LIBS) -# Crypto libraries (conditional) -if USE_OPENSSL +# Crypto always uses OpenSSL CRYPTO_LIBS = -lcrypto -TINYCRYPT_BUILT = -else -CRYPTO_LIBS = $(TINYCRYPT_OBJS) -TINYCRYPT_BUILT = tinycrypt-objects -endif - -# Tests run via check-local (with timing and colored output), not TESTS -# Build TinyCrypt objects as a group (only when not using OpenSSL) -if USE_OPENSSL -else -tinycrypt-objects: $(TINYCRYPT_OBJS) -endif - -# Ensure TinyCrypt objects are built before tests that need them -if USE_OPENSSL -BUILT_SOURCES = -else -BUILT_SOURCES = $(TINYCRYPT_OBJS) - -$(TINYCRYPT_OBJS): $(top_builddir)/src/utun - @$(MAKE) -C $(top_builddir)/src tinycrypt-objects -endif # Test definitions test_etcp_bbr_SOURCES = test_etcp_bbr.c @@ -181,54 +133,37 @@ test_etcp_bbr_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_bbr_LDADD = $(top_builddir)/src/utun-etcp_bbr.o $(COMMON_LIBS) test_etcp_crypto_SOURCES = test_etcp_crypto.c -test_etcp_crypto_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_etcp_crypto_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_crypto_LDADD = $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_stream_cipher_SOURCES = test_stream_cipher.c -test_stream_cipher_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_stream_cipher_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_stream_cipher_LDADD = $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_transport_SOURCES = test_stcp_link.c -test_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_transport_LDADD = $(STCP_LINK_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_etcp_transport_SOURCES = test_etcp_stcp.c -test_etcp_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_etcp_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_transport_LDADD = $(STCP_LINK_OBJS) $(top_builddir)/src/utun-etcp_api.o $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_stcp_SOURCES = test_stcp.c -test_stcp_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_stcp_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_stcp_LDADD = $(top_builddir)/src/utun-stcp.o $(top_builddir)/src/utun-stcp_server.o $(top_builddir)/src/utun-stcp_client.o $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) -if USE_OPENSSL -else -test_crypto_SOURCES = test_crypto.c -test_crypto_CFLAGS = -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source -I$(top_srcdir)/lib -test_crypto_LDADD = $(TINYCRYPT_OBJS) $(COMMON_LIBS) -endif - test_etcp_two_instances_SOURCES = test_etcp_two_instances.c -test_etcp_two_instances_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_etcp_two_instances_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_two_instances_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_etcp_simple_traffic_SOURCES = test_etcp_simple_traffic.c -test_etcp_simple_traffic_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_etcp_simple_traffic_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_simple_traffic_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_ipv6_sockets_SOURCES = test_ipv6_sockets.c -test_ipv6_sockets_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_ipv6_sockets_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_ipv6_sockets_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) -# test_etcp_congestion — отключён (старый congestion control удалён) -#test_etcp_congestion_SOURCES = test_etcp_congestion.c -#test_etcp_congestion_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source -#test_etcp_congestion_LDADD = $(top_builddir)/src/utun-dummynet.o $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) - -# test_etcp_reinit_inflight — отключён (старый congestion control удалён) -#test_etcp_reinit_inflight_SOURCES = test_etcp_reinit_inflight.c -#test_etcp_reinit_inflight_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source -#test_etcp_reinit_inflight_LDADD = $(top_builddir)/src/utun-dummynet.o $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) - test_tcp_proxy_client_SOURCES = test_tcp_proxy_client.c test_tcp_proxy_client_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) @@ -271,35 +206,35 @@ test_route6_lib_LDADD = $(top_builddir)/src/utun-route6_lib.o \ test_etcp_minimal_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_etcp_100_packets_SOURCES = test_etcp_100_packets.c -test_etcp_100_packets_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_etcp_100_packets_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_100_packets_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_etcp_reconnect_SOURCES = test_etcp_reconnect.c -test_etcp_reconnect_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_etcp_reconnect_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_reconnect_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_pkt_normalizer_etcp_SOURCES = test_pkt_normalizer_etcp.c -test_pkt_normalizer_etcp_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_pkt_normalizer_etcp_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_pkt_normalizer_etcp_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_pkt_normalizer_standalone_SOURCES = test_pkt_normalizer_standalone.c -test_pkt_normalizer_standalone_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_pkt_normalizer_standalone_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_pkt_normalizer_standalone_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_etcp_api_SOURCES = test_etcp_api.c -test_etcp_api_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_etcp_api_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_api_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_etcp_ping_SOURCES = test_etcp_ping.c -test_etcp_ping_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_etcp_ping_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_etcp_ping_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_route_ping_SOURCES = test_route_ping.c -test_route_ping_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_route_ping_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_route_ping_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_nat_detection_SOURCES = test_nat_detection.c -test_nat_detection_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_nat_detection_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_nat_detection_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_nat_engine_SOURCES = test_nat_engine.c @@ -307,7 +242,7 @@ test_nat_engine_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_nat_engine_LDADD = $(top_builddir)/src/utun-eim_nat.o $(top_builddir)/src/utun-config_parser.o $(COMMON_LIBS) test_nat_transport_SOURCES = test_nat_transport.c -test_nat_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_nat_transport_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_nat_transport_LDADD = $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) test_nat_stress_SOURCES = test_nat_stress.c @@ -322,13 +257,6 @@ test_serialize_SOURCES = test_serialize.c test_serialize_CFLAGS = -I$(top_srcdir)/lib test_serialize_LDADD = $(COMMON_LIBS) -if USE_OPENSSL -else -test_ecc_encrypt_SOURCES = test_ecc_encrypt.c -test_ecc_encrypt_CFLAGS = -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source -I$(top_srcdir)/lib -test_ecc_encrypt_LDADD = $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) -lcrypto -endif - test_intensive_memory_pool_SOURCES = test_intensive_memory_pool.c test_intensive_memory_pool_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_intensive_memory_pool_LDADD = $(COMMON_LIBS) @@ -366,21 +294,15 @@ test_config_debug_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_config_debug_LDADD = $(top_builddir)/src/utun-config_parser.o $(COMMON_LIBS) test_route_lib_SOURCES = test_route_lib.c -test_route_lib_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/src -I$(top_srcdir)/tinycrypt/lib/include +test_route_lib_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_route_lib_LDADD = $(top_builddir)/src/utun-route_lib.o $(top_builddir)/src/utun-route_node.o $(top_builddir)/src/utun-etcp_debug.o $(COMMON_LIBS) test_bgp_route_exchange_SOURCES = test_bgp_route_exchange.c -test_bgp_route_exchange_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_bgp_route_exchange_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_bgp_route_exchange_LDADD = $(top_builddir)/src/utun-dummynet.o $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) - -# test_dummynet временно исключен (медленный) -# test_dummynet_SOURCES = test_dummynet.c -# test_dummynet_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -# test_dummynet_LDADD = $(top_builddir)/src/utun-dummynet.o $(COMMON_LIBS) - test_bbr_integration_SOURCES = bbr_integration/test_bbr_integration.c -test_bbr_integration_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib -I$(top_srcdir)/tinycrypt/lib/include -I$(top_srcdir)/tinycrypt/lib/source +test_bbr_integration_CFLAGS = -I$(top_srcdir)/src -I$(top_srcdir)/lib test_bbr_integration_LDADD = $(top_builddir)/src/utun-dummynet.o $(ETCP_FULL_OBJS) $(SECURE_CHANNEL_OBJS) $(CRYPTO_LIBS) $(COMMON_LIBS) bench_timeout_heap_SOURCES = bench_timeout_heap.c @@ -391,9 +313,6 @@ bench_uasync_timeouts_SOURCES = bench_uasync_timeouts.c bench_uasync_timeouts_CFLAGS = -I$(top_srcdir)/lib bench_uasync_timeouts_LDADD = $(COMMON_LIBS) -# Build tinycrypt objects before tests that need them -BUILT_SOURCES = $(TINYCRYPT_BUILT) - # Copy test configs to build directory (tests run from build/tests/) all-local: copy-test-configs diff --git a/tests/bbr_integration/test_bbr_integration.c b/tests/bbr_integration/test_bbr_integration.c index 2f894036..110a2e13 100644 --- a/tests/bbr_integration/test_bbr_integration.c +++ b/tests/bbr_integration/test_bbr_integration.c @@ -334,15 +334,11 @@ int main(void) { if (!ctx.ua) { printf("ERROR: uasync_create failed\n"); return 1; } const char* s_priv = - "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb"; - const char* s_pub = - "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17" - "c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9"; + "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68"; + const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a"; const char* c_priv = - "4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2"; - const char* c_pub = - "c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3" - "c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71"; + "704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f"; + const char* c_pub = "b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01"; printf("Creating instances...\n"); ctx.sender = create_instance(ctx.ua, 0x1111111111111111ULL, c_priv, c_pub); diff --git a/tests/tcp_proxy_full/client.conf b/tests/tcp_proxy_full/client.conf index 95c608c1..5baeebf2 100644 --- a/tests/tcp_proxy_full/client.conf +++ b/tests/tcp_proxy_full/client.conf @@ -1,7 +1,7 @@ [global] my_node_id=0xAAAA000000000002 -my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2 -my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71 +my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f +my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01 tun_ip=10.200.20.1/24 tun_ifname=tun_test_cli debug_level=error @@ -13,7 +13,7 @@ type=public [client: c1] keepalive=1 link=s1:127.0.0.1:15001 -peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9 +peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a [tcp_proxy_client] enabled=yes diff --git a/tests/tcp_proxy_full/exit.conf b/tests/tcp_proxy_full/exit.conf index 12e4298c..9b11670a 100644 --- a/tests/tcp_proxy_full/exit.conf +++ b/tests/tcp_proxy_full/exit.conf @@ -1,7 +1,7 @@ [global] my_node_id=0xAAAA000000000001 -my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb -my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9 +my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68 +my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a tun_ip=10.200.10.1/24 tun_ifname=tun_test_exit debug_level=error diff --git a/tests/test_config_debug.c b/tests/test_config_debug.c index 0b41cea2..e29d36bd 100644 --- a/tests/test_config_debug.c +++ b/tests/test_config_debug.c @@ -26,8 +26,8 @@ static char config_path[256]; static const char* config_content = "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "# Debug and logging configuration\n" diff --git a/tests/test_etcp_100_packets.c b/tests/test_etcp_100_packets.c index bbe9c44c..506bf9cd 100644 --- a/tests/test_etcp_100_packets.c +++ b/tests/test_etcp_100_packets.c @@ -41,8 +41,8 @@ static char client_config_path[256]; static const char* server_config_content = "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "\n" @@ -57,8 +57,8 @@ static const char* server_config_content = static const char* client_config_content = "[global]\n" "my_node_id=0x2222222222222222\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "\n" @@ -68,7 +68,7 @@ static const char* client_config_content = "\n" "[client: test_client]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=test:127.0.0.1:9021\n"; // Create temp config files diff --git a/tests/test_etcp_api.c b/tests/test_etcp_api.c index b5b04161..b74ea4b8 100644 --- a/tests/test_etcp_api.c +++ b/tests/test_etcp_api.c @@ -48,8 +48,8 @@ static char client_config_path[256]; static const char* server_config_content = "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "\n" @@ -64,8 +64,8 @@ static const char* server_config_content = static const char* client_config_content = "[global]\n" "my_node_id=0x2222222222222222\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "\n" @@ -75,7 +75,7 @@ static const char* client_config_content = "\n" "[client: test_client]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=test:127.0.0.1:9031\n"; // Create temp config files diff --git a/tests/test_etcp_congestion.c b/tests/test_etcp_congestion.c index 3f0bc85d..11eea1f5 100644 --- a/tests/test_etcp_congestion.c +++ b/tests/test_etcp_congestion.c @@ -298,10 +298,10 @@ int main(void) { if (!ctx.ua) { printf("uasync failed\n"); return 1; } /* Ключи */ - const char* s_priv = "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb"; - const char* s_pub = "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9"; - const char* c_priv = "4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2"; - const char* c_pub = "c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71"; + const char* s_priv = "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68"; + const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a"; + const char* c_priv = "704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f"; + const char* c_pub = "b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01"; printf("Creating instances...\n"); ctx.sender = create_instance(ctx.ua, 0x1111111111111111ULL, c_priv, c_pub); diff --git a/tests/test_etcp_dummynet.c b/tests/test_etcp_dummynet.c index fa4111a0..d999469e 100644 --- a/tests/test_etcp_dummynet.c +++ b/tests/test_etcp_dummynet.c @@ -186,10 +186,10 @@ int main(void) { printf("Using fixed keys...\n"); /* These keys are copied from test_etcp_two_instances.c and are known to work */ - const char* s_priv = "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb"; - const char* s_pub = "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9"; - const char* c_priv = "4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2"; - const char* c_pub = "c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71"; + const char* s_priv = "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68"; + const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a"; + const char* c_priv = "704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f"; + const char* c_pub = "b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01"; printf("Creating instances...\n"); server = create_instance(ua, 0x1111111111111111ULL, s_priv, s_pub); diff --git a/tests/test_etcp_ping.c b/tests/test_etcp_ping.c index f05a765f..11e28031 100644 --- a/tests/test_etcp_ping.c +++ b/tests/test_etcp_ping.c @@ -32,8 +32,8 @@ static int pong_received = 0; static const char* server_config_content = "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "\n" @@ -47,8 +47,8 @@ static const char* server_config_content = static const char* client_config_content = "[global]\n" "my_node_id=0x2222222222222222\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "\n" @@ -58,7 +58,7 @@ static const char* client_config_content = "\n" "[client:test_client]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=test:127.0.0.1:9011\n"; static int create_temp_configs(void) { diff --git a/tests/test_etcp_reconnect.c b/tests/test_etcp_reconnect.c index 2f9b8122..a4107d59 100644 --- a/tests/test_etcp_reconnect.c +++ b/tests/test_etcp_reconnect.c @@ -70,8 +70,8 @@ static int create_temp_configs(void) { fprintf(f, "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "\n" @@ -89,8 +89,8 @@ static int create_temp_configs(void) { fprintf(f, "[global]\n" "my_node_id=0x2222222222222222\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "\n" @@ -100,7 +100,7 @@ static int create_temp_configs(void) { "\n" "[client: test_client]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=test:127.0.0.1:%d\n", client_port, server_port); fclose(f); diff --git a/tests/test_etcp_reinit_inflight.c b/tests/test_etcp_reinit_inflight.c index b72b7d44..c86a9922 100644 --- a/tests/test_etcp_reinit_inflight.c +++ b/tests/test_etcp_reinit_inflight.c @@ -203,8 +203,8 @@ static void monitor(void* arg) { utun_instance_destroy(ctx->receiver); ctx->receiver = NULL; { - const char* s_priv = "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb"; - const char* s_pub = "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9"; + const char* s_priv = "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68"; + const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a"; ctx->receiver = create_instance(ctx->ua, 0x2222222222222222ULL, s_priv, s_pub); add_server(ctx->receiver, "srv1", SRV_PORT); utun_instance_init(ctx->receiver); @@ -274,10 +274,10 @@ int main(void) { ctx.ua = uasync_create(); if (!ctx.ua) { printf("uasync_create failed\n"); return 1; } - const char* s_priv = "67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb"; - const char* s_pub = "1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9"; - const char* c_priv = "4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2"; - const char* c_pub = "c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71"; + const char* s_priv = "38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68"; + const char* s_pub = "ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a"; + const char* c_priv = "704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f"; + const char* c_pub = "b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01"; ctx.sender = create_instance(ctx.ua, 0x1111111111111111ULL, c_priv, c_pub); ctx.receiver = create_instance(ctx.ua, 0x2222222222222222ULL, s_priv, s_pub); diff --git a/tests/test_etcp_router.c b/tests/test_etcp_router.c index 3257f7e9..f7d4a0cc 100644 --- a/tests/test_etcp_router.c +++ b/tests/test_etcp_router.c @@ -49,8 +49,8 @@ static void* g_mon_id = NULL; static const char* srv_cfg = "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "[server: s1]\n" @@ -63,8 +63,8 @@ static const char* srv_cfg = static const char* cli_cfg = "[global]\n" "my_node_id=0x2222222222222222\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "[server: s1]\n" @@ -72,7 +72,7 @@ static const char* cli_cfg = "type=public\n" "[client: c1]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=s1:127.0.0.1:9041\n"; // ======================== Test state ======================== diff --git a/tests/test_etcp_simple_traffic.c b/tests/test_etcp_simple_traffic.c index 487ab25a..3495b152 100644 --- a/tests/test_etcp_simple_traffic.c +++ b/tests/test_etcp_simple_traffic.c @@ -63,8 +63,8 @@ static int create_temp_configs(void) { fprintf(f, "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "\n" @@ -82,8 +82,8 @@ static int create_temp_configs(void) { fprintf(f, "[global]\n" "my_node_id=0x2222222222222222\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "\n" @@ -93,7 +93,7 @@ static int create_temp_configs(void) { "\n" "[client: test_client]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=test:127.0.0.1:%d\n", client_port, server_port); fclose(f); diff --git a/tests/test_etcp_two_instances.c b/tests/test_etcp_two_instances.c index 6b0d9aed..96304aed 100644 --- a/tests/test_etcp_two_instances.c +++ b/tests/test_etcp_two_instances.c @@ -41,8 +41,8 @@ static char client_config_path[256]; static const char* server_config_content = "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "\n" @@ -57,8 +57,8 @@ static const char* server_config_content = static const char* client_config_content = "[global]\n" "my_node_id=0x2222222222222222\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "\n" @@ -68,7 +68,7 @@ static const char* client_config_content = "\n" "[client: test_client]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=test:127.0.0.1:9011\n"; // Create temp config files diff --git a/tests/test_icmp_proxy.c b/tests/test_icmp_proxy.c index 460aee61..07875aff 100644 --- a/tests/test_icmp_proxy.c +++ b/tests/test_icmp_proxy.c @@ -41,13 +41,13 @@ static const char* cfg_node_client(void) { snprintf(buf, sizeof(buf), "[global]\n" "my_node_id=0xEEEE000000000001\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "[server: s1]\naddr=127.0.0.1:9081\ntype=public\n" "[client: c1]\nkeepalive=1\nlink=s1:127.0.0.1:9082\n" - "peer_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "peer_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "[tcp_proxy_client]\n" "enabled=yes\n" "tun_name=tun_tcp\n" @@ -61,8 +61,8 @@ static const char* cfg_node_exit(void) { snprintf(buf, sizeof(buf), "[global]\n" "my_node_id=0xEEEE000000000002\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "[server: s1]\naddr=127.0.0.1:9082\ntype=public\n" diff --git a/tests/test_ipv6_sockets.c b/tests/test_ipv6_sockets.c index 7b86f474..3d3644b8 100644 --- a/tests/test_ipv6_sockets.c +++ b/tests/test_ipv6_sockets.c @@ -56,8 +56,8 @@ static const char* server_config = "[global]\n" "my_node_name=server_v6\n" "my_node_id=0xAAAA000000000001\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "tun_test_mode=1\n" @@ -76,8 +76,8 @@ static const char* client_config = "[global]\n" "my_node_name=client_v6\n" "my_node_id=0xBBBB000000000002\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "tun_test_mode=1\n" @@ -88,7 +88,7 @@ static const char* client_config = "\n" "[client: v6client]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=v6srv:[::1]:40111\n"; static int create_temp_configs(void) { diff --git a/tests/test_pkt_normalizer_etcp.c b/tests/test_pkt_normalizer_etcp.c index 7cbe1588..e473d6fd 100644 --- a/tests/test_pkt_normalizer_etcp.c +++ b/tests/test_pkt_normalizer_etcp.c @@ -40,8 +40,8 @@ static char client_config_path[256]; static const char* server_config_content = "[global]\n" "my_node_id=0x1111111111111111\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "\n" @@ -55,8 +55,8 @@ static const char* server_config_content = static const char* client_config_content = "[global]\n" "my_node_id=0x2222222222222222\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "\n" @@ -66,7 +66,7 @@ static const char* client_config_content = "\n" "[client: test_client]\n" "keepalive=1\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "link=test:127.0.0.1:9041\n"; static struct UTUN_INSTANCE* server_instance = NULL; diff --git a/tests/test_tcp_proxy_remote.c b/tests/test_tcp_proxy_remote.c index 43cf944b..cbe7258a 100644 --- a/tests/test_tcp_proxy_remote.c +++ b/tests/test_tcp_proxy_remote.c @@ -135,18 +135,18 @@ static void test_timeout(void* arg) { static const char* cfg_exit(int srv_port) { static char b[1024]; snprintf(b,sizeof(b), "[global]\nmy_node_id=0xCCCC000000000001\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\ntun_ifname=tun99\n" "[server:s1]\naddr=127.0.0.1:%d\ntype=public\n[allowed_keys]\nallow_all=1\n[tcp_proxy_server]\nenabled=yes\n", srv_port); return b; } static const char* cfg_b(int srv_port, int cli_port) { static char b[1024]; snprintf(b,sizeof(b), "[global]\nmy_node_id=0xCCCC000000000002\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\ntun_ifname=tun98\n" "[server:s1]\naddr=127.0.0.1:%d\ntype=public\n[client:c1]\nkeepalive=1\nlink=s1:127.0.0.1:%d\n" - "peer_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "peer_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "[tcp_proxy_server]\nenabled=yes\n", srv_port, cli_port); return b; } int main(void) { diff --git a/tests/test_udp_proxy.c b/tests/test_udp_proxy.c index d71c9679..93e62d6b 100644 --- a/tests/test_udp_proxy.c +++ b/tests/test_udp_proxy.c @@ -40,13 +40,13 @@ static const char* cfg_node_client(void) { snprintf(buf, sizeof(buf), "[global]\n" "my_node_id=0xDDDD000000000001\n" - "my_private_key=67b705a92b41bcaae105af2d6a17743faa7b26ccebba8b3b9b0af05e9cd1d5fb\n" - "my_public_key=1c55e4ccae7c4470707759086738b10681bf88b81f198cc2ab54a647d1556e17c65e6b1833e0c771e5a39382c03067c388915a4c732191bc130480f20f8e00b9\n" + "my_private_key=38240cb82199e504686507f11f6eaa4f740fde6f0c425c495e49a523019a5d68\n" + "my_public_key=ce8871f07fa056c636d297115f231b08c29cdf94e0d440fce83a07c34416d36a\n" "tun_ip=10.99.0.1/24\n" "tun_ifname=tun99\n" "[server: s1]\naddr=127.0.0.1:9071\ntype=public\n" "[client: c1]\nkeepalive=1\nlink=s1:127.0.0.1:9072\n" - "peer_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "peer_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "[tcp_proxy_client]\n" "enabled=yes\n" "tun_name=tun_tcp\n" @@ -60,8 +60,8 @@ static const char* cfg_node_exit(void) { snprintf(buf, sizeof(buf), "[global]\n" "my_node_id=0xDDDD000000000002\n" - "my_private_key=4813d31d28b7e9829247f488c6be7672f2bdf61b2508333128e386d1759afed2\n" - "my_public_key=c594f33c91f3a2222795c2c110c527bf214ad1009197ce14556cb13df3c461b3c373bed8f205a8dd1fc0c364f90bf471d7c6f5db49564c33e4235d268569ac71\n" + "my_private_key=704f2e012c8fa8768130cb0f988a997dccb628372bc5ceccacc78dcbfec5916f\n" + "my_public_key=b3193173def895bd0fcea6f86af077c7d77216f10395275f627ac18242ec0f01\n" "tun_ip=10.99.0.2/24\n" "tun_ifname=tun98\n" "[server: s1]\naddr=127.0.0.1:9072\ntype=public\n" diff --git a/utun.md b/utun.md index ae7847bc..c71ab9cd 100644 --- a/utun.md +++ b/utun.md @@ -6,7 +6,7 @@ uTun создаёт виртуальный TUN-интерфейс и маршр | Возможность | Описание | |---|---| -| **Шифрование** | ECC (secp256r1) обмен ключами + AES-128-CCM с аутентификацией | +| **Шифрование** | X25519 обмен ключами + AES-128-CCM с аутентификацией | | **Целостность** | CRC32 внутри зашифрованного payload | | **Multi-link** | Одно подключение через несколько UDP-каналов одновременно | | **Балансировка** | Выбор канала с минимальным inflight + round-robin при равенстве | @@ -20,7 +20,7 @@ uTun создаёт виртуальный TUN-интерфейс и маршр | **Файрвол** | Белый список IP:port для трафика через туннель | | **Control server** | TCP-сервер для мониторинга метрик в реальном времени (GUI-клиент) | | **Горячая перезагрузка** | SIGHUP — выборочное обновление конфига (сравнение сокетов/клиентов/линков) | -| **Авто-ключи** | При первом запуске генерирует ECC-пару и node_id, записывает в конфиг | +| **Авто-ключи** | При первом запуске генерирует X25519-пару и node_id, записывает в конфиг | | **Демонизация** | fork/setsid на Linux; foreground-режим `-f` для отладки | | **Кроссплатформенность** | Linux (epoll), Windows (wintun), FreeBSD | | **Эмуляция потерь** | `loss_rate=N` в конфиге сокета — для тестирования | @@ -67,8 +67,8 @@ utun -c utun.conf [-p /var/run/utun.pid] [-l utun.log] [-f] [-d "etcp:debug"] |---|---|---| | `my_node_name` | Имя узла (до 15 символов) | — | | `my_node_id` | 64-битный ID узла (hex, 16 символов) | авто | -| `my_private_key` | Приватный ключ ECC (64 hex символа) | авто | -| `my_public_key` | Публичный ключ ECC (128 hex символов) | авто | +| `my_private_key` | Приватный ключ X25519 (64 hex символа) | авто | +| `my_public_key` | Публичный ключ X25519 (64 hex символа) | авто | | `tun_ifname` | Имя TUN-интерфейса | `tun0` | | `tun_ip` | IP-адрес TUN-интерфейса | — | | `mtu` | MTU для всех подключений | `1500` | @@ -121,7 +121,7 @@ type=public | Ключ | Значение | По умолчанию | |---|---|---| | `link` | `сервер:удалённый_IP:порт` (можно несколько) | **обязателен** | -| `peer_public_key` | Публичный ключ пира (128 hex) | **обязателен** | +| `peer_public_key` | Публичный ключ пира (64 hex) | **обязателен** | | `keepalive` | 1 — включить keepalive | `1` | Пример: @@ -184,7 +184,7 @@ control_allow=192.168.0.0/16 | Ключ | Значение | По умолчанию | |---|---|---| | `allow_all` | 1 — разрешить все ключи | — | -| `key` | Публичный ключ (128 hex, можно несколько) | — | +| `key` | Публичный ключ (64 hex, можно несколько) | — | Поведение: - Секция отсутствует: разрешить все (совместимость) @@ -205,7 +205,7 @@ key=04c1cae041a8e6bfba5245f6669c73f0793d7f9929300a2ba2e123ca55260d6e4748... tun_ip=10.23.1.1 my_node_name=vmL1 my_node_id=5f75c7445af88e1f -my_private_key=b0e8b68679db468979906894fe36239dbda910e06435361d696c7f5a8e2009c4 +my_private_key=d065b784a8386f9b37f07b4c16c3ab83ddce5885e78f79c5d2a6d1f9954fe441 my_public_key=c6c8a8a9616ffa6cf44d4757e2bc9f7bd78a1d3cbbe75cffaf3cab8885ad48e7677b... [server: lan1]