OpenSSLProvider.java revision 38375a4d0b3d34e2babbd2f6a013976c7c439696
1/*
2 * Copyright (C) 2010 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 *      http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package org.conscrypt;
18
19import java.security.Provider;
20
21/**
22 * Provider that goes through OpenSSL for operations.
23 * <p>
24 * Every algorithm should have its IANA assigned OID as an alias. See the following URLs for each type:
25 * <ul>
26 * <li><a href="http://www.iana.org/assignments/hash-function-text-names/hash-function-text-names.xml">Hash functions</a></li>
27 * <li><a href="http://www.iana.org/assignments/dssc/dssc.xml">Signature algorithms</a></li>
28 * <li><a href="http://csrc.nist.gov/groups/ST/crypto_apps_infra/csor/algorithms.html">NIST cryptographic algorithms</a></li>
29 * </ul>
30 */
31public final class OpenSSLProvider extends Provider {
32    public static final String PROVIDER_NAME = "AndroidOpenSSL";
33
34    public OpenSSLProvider() {
35        super(PROVIDER_NAME, 1.0, "Android's OpenSSL-backed security provider");
36
37        // If we're compiled stand-alone, we need to load the JNI library
38        if ("org.conscrypt".equals(getClass().getPackage().getName())) {
39            System.loadLibrary("conscrypt");
40        }
41
42        /* === SSL Contexts === */
43        put("SSLContext.SSL", OpenSSLContextImpl.class.getName());
44        put("SSLContext.SSLv3", OpenSSLContextImpl.class.getName());
45        put("SSLContext.TLS", OpenSSLContextImpl.class.getName());
46        put("SSLContext.TLSv1", OpenSSLContextImpl.class.getName());
47        put("SSLContext.TLSv1.1", OpenSSLContextImpl.class.getName());
48        put("SSLContext.TLSv1.2", OpenSSLContextImpl.class.getName());
49        put("SSLContext.Default", DefaultSSLContextImpl.class.getName());
50
51        /* === Message Digests === */
52        put("MessageDigest.SHA-1",
53            "org.conscrypt.OpenSSLMessageDigestJDK$SHA1");
54        put("Alg.Alias.MessageDigest.SHA1", "SHA-1");
55        put("Alg.Alias.MessageDigest.SHA", "SHA-1");
56        put("Alg.Alias.MessageDigest.1.3.14.3.2.26", "SHA-1");
57
58        put("MessageDigest.SHA-256",
59            "org.conscrypt.OpenSSLMessageDigestJDK$SHA256");
60        put("Alg.Alias.MessageDigest.SHA256", "SHA-256");
61        put("Alg.Alias.MessageDigest.2.16.840.1.101.3.4.2.1", "SHA-256");
62
63        put("MessageDigest.SHA-384",
64            "org.conscrypt.OpenSSLMessageDigestJDK$SHA384");
65        put("Alg.Alias.MessageDigest.SHA384", "SHA-384");
66        put("Alg.Alias.MessageDigest.2.16.840.1.101.3.4.2.2", "SHA-384");
67
68        put("MessageDigest.SHA-512",
69            "org.conscrypt.OpenSSLMessageDigestJDK$SHA512");
70        put("Alg.Alias.MessageDigest.SHA512", "SHA-512");
71        put("Alg.Alias.MessageDigest.2.16.840.1.101.3.4.2.3", "SHA-512");
72
73        // iso(1) member-body(2) US(840) rsadsi(113549) digestAlgorithm(2) md5(5)
74        put("MessageDigest.MD5",
75            "org.conscrypt.OpenSSLMessageDigestJDK$MD5");
76        put("Alg.Alias.MessageDigest.1.2.840.113549.2.5", "MD5");
77
78        /* == KeyPairGenerators == */
79        put("KeyPairGenerator.RSA", OpenSSLRSAKeyPairGenerator.class.getName());
80        put("Alg.Alias.KeyPairGenerator.1.2.840.113549.1.1.1", "RSA");
81
82        put("KeyPairGenerator.DSA", OpenSSLDSAKeyPairGenerator.class.getName());
83
84        put("KeyPairGenerator.EC", OpenSSLECKeyPairGenerator.class.getName());
85
86        /* == KeyFactory == */
87        put("KeyFactory.RSA", OpenSSLRSAKeyFactory.class.getName());
88        put("Alg.Alias.KeyFactory.1.2.840.113549.1.1.1", "RSA");
89
90        put("KeyFactory.DSA", OpenSSLDSAKeyFactory.class.getName());
91
92        put("KeyFactory.EC", OpenSSLECKeyFactory.class.getName());
93
94        /* == KeyAgreement == */
95        put("KeyAgreement.ECDH", OpenSSLECDHKeyAgreement.class.getName());
96
97        /* == Signatures == */
98        put("Signature.MD5WithRSA", OpenSSLSignature.MD5RSA.class.getName());
99        put("Alg.Alias.Signature.MD5WithRSAEncryption", "MD5WithRSA");
100        put("Alg.Alias.Signature.MD5/RSA", "MD5WithRSA");
101        put("Alg.Alias.Signature.1.2.840.113549.1.1.4", "MD5WithRSA");
102        put("Alg.Alias.Signature.1.2.840.113549.2.5with1.2.840.113549.1.1.1", "MD5WithRSA");
103
104        put("Signature.SHA1WithRSA", OpenSSLSignature.SHA1RSA.class.getName());
105        put("Alg.Alias.Signature.SHA1WithRSAEncryption", "SHA1WithRSA");
106        put("Alg.Alias.Signature.SHA1/RSA", "SHA1WithRSA");
107        put("Alg.Alias.Signature.SHA-1/RSA", "SHA1WithRSA");
108        put("Alg.Alias.Signature.1.2.840.113549.1.1.5", "SHA1WithRSA");
109        put("Alg.Alias.Signature.1.3.14.3.2.26with1.2.840.113549.1.1.1", "SHA1WithRSA");
110        put("Alg.Alias.Signature.1.3.14.3.2.26with1.2.840.113549.1.1.5", "SHA1WithRSA");
111        put("Alg.Alias.Signature.1.3.14.3.2.29", "SHA1WithRSA");
112
113        put("Signature.SHA256WithRSA", OpenSSLSignature.SHA256RSA.class.getName());
114        put("Alg.Alias.Signature.SHA256WithRSAEncryption", "SHA256WithRSA");
115        put("Alg.Alias.Signature.1.2.840.113549.1.1.11", "SHA256WithRSA");
116        put("Alg.Alias.Signature.2.16.840.1.101.3.4.2.1with1.2.840.113549.1.1.1",
117                "SHA256WithRSA");
118        put("Alg.Alias.Signature.2.16.840.1.101.3.4.2.1with1.2.840.113549.1.1.11",
119                "SHA256WithRSA");
120
121        put("Signature.SHA384WithRSA", OpenSSLSignature.SHA384RSA.class.getName());
122        put("Alg.Alias.Signature.SHA384WithRSAEncryption", "SHA384WithRSA");
123        put("Alg.Alias.Signature.1.2.840.113549.1.1.12", "SHA384WithRSA");
124        put("Alg.Alias.Signature.2.16.840.1.101.3.4.2.2with1.2.840.113549.1.1.1",
125                "SHA384WithRSA");
126
127        put("Signature.SHA512WithRSA", OpenSSLSignature.SHA512RSA.class.getName());
128        put("Alg.Alias.Signature.SHA512WithRSAEncryption", "SHA512WithRSA");
129        put("Alg.Alias.Signature.1.2.840.113549.1.1.13", "SHA512WithRSA");
130        put("Alg.Alias.Signature.2.16.840.1.101.3.4.2.3with1.2.840.113549.1.1.1",
131                "SHA512WithRSA");
132
133        put("Signature.SHA1withDSA", OpenSSLSignature.SHA1DSA.class.getName());
134        put("Alg.Alias.Signature.SHA/DSA", "SHA1withDSA");
135        put("Alg.Alias.Signature.DSA", "SHA1withDSA");
136        put("Alg.Alias.Signature.1.3.14.3.2.26with1.2.840.10040.4.1", "SHA1withDSA");
137        put("Alg.Alias.Signature.1.3.14.3.2.26with1.2.840.10040.4.3", "SHA1withDSA");
138        put("Alg.Alias.Signature.DSAWithSHA1", "SHA1withDSA");
139        put("Alg.Alias.Signature.1.2.840.10040.4.3", "SHA1withDSA");
140
141        put("Signature.NONEwithRSA", OpenSSLSignatureRawRSA.class.getName());
142
143        put("Signature.ECDSA", OpenSSLSignature.SHA1ECDSA.class.getName());
144        put("Alg.Alias.Signature.SHA1withECDSA", "ECDSA");
145        put("Alg.Alias.Signature.ECDSAwithSHA1", "ECDSA");
146        // iso(1) member-body(2) us(840) ansi-x962(10045) signatures(4) ecdsa-with-SHA1(1)
147        put("Alg.Alias.Signature.1.2.840.10045.4.1", "ECDSA");
148        put("Alg.Alias.Signature.1.3.14.3.2.26with1.2.840.10045.2.1", "ECDSA");
149
150        // iso(1) member-body(2) us(840) ansi-x962(10045) signatures(4) ecdsa-with-SHA2(3)
151        put("Signature.SHA256withECDSA", OpenSSLSignature.SHA256ECDSA.class.getName());
152        // ecdsa-with-SHA256(2)
153        put("Alg.Alias.Signature.1.2.840.10045.4.3.2", "SHA256withECDSA");
154        put("Alg.Alias.Signature.2.16.840.1.101.3.4.2.1with1.2.840.10045.2.1", "SHA256withECDSA");
155
156        put("Signature.SHA384withECDSA", OpenSSLSignature.SHA384ECDSA.class.getName());
157        // ecdsa-with-SHA384(3)
158        put("Alg.Alias.Signature.1.2.840.10045.4.3.3", "SHA384withECDSA");
159        put("Alg.Alias.Signature.2.16.840.1.101.3.4.2.2with1.2.840.10045.2.1", "SHA384withECDSA");
160
161        put("Signature.SHA512withECDSA", OpenSSLSignature.SHA512ECDSA.class.getName());
162        // ecdsa-with-SHA512(4)
163        put("Alg.Alias.Signature.1.2.840.10045.4.3.4", "SHA512withECDSA");
164        put("Alg.Alias.Signature.2.16.840.1.101.3.4.2.3with1.2.840.10045.2.1", "SHA512withECDSA");
165
166        /* === SecureRandom === */
167        /*
168         * We have to specify SHA1PRNG because various documentation mentions
169         * that algorithm by name instead of just recommending calling
170         * "new SecureRandom()"
171         */
172        put("SecureRandom.SHA1PRNG", OpenSSLRandom.class.getName());
173        put("SecureRandom.SHA1PRNG ImplementedIn", "Software");
174
175        /* === Cipher === */
176        put("Cipher.RSA/ECB/NoPadding", OpenSSLCipherRSA.Raw.class.getName());
177        put("Alg.Alias.Cipher.RSA/None/NoPadding", "RSA/ECB/NoPadding");
178        put("Cipher.RSA/ECB/PKCS1Padding", OpenSSLCipherRSA.PKCS1.class.getName());
179        put("Alg.Alias.Cipher.RSA/None/PKCS1Padding", "RSA/ECB/PKCS1Padding");
180
181        /*
182         * OpenSSL only supports a subset of modes, so we'll name them
183         * explicitly here.
184         */
185        put("Cipher.AES/ECB/NoPadding", OpenSSLCipher.AES.ECB.NoPadding.class.getName());
186        put("Cipher.AES/ECB/PKCS5Padding", OpenSSLCipher.AES.ECB.PKCS5Padding.class.getName());
187        put("Cipher.AES/CBC/NoPadding", OpenSSLCipher.AES.CBC.NoPadding.class.getName());
188        put("Cipher.AES/CBC/PKCS5Padding", OpenSSLCipher.AES.CBC.PKCS5Padding.class.getName());
189        put("Cipher.AES/CFB/NoPadding", OpenSSLCipher.AES.CFB.NoPadding.class.getName());
190        put("Cipher.AES/CFB/PKCS5Padding", OpenSSLCipher.AES.CFB.PKCS5Padding.class.getName());
191        put("Cipher.AES/CTR/NoPadding", OpenSSLCipher.AES.CTR.NoPadding.class.getName());
192        put("Cipher.AES/CTR/PKCS5Padding", OpenSSLCipher.AES.CTR.PKCS5Padding.class.getName());
193        put("Cipher.AES/OFB/NoPadding", OpenSSLCipher.AES.OFB.NoPadding.class.getName());
194        put("Cipher.AES/OFB/PKCS5Padding", OpenSSLCipher.AES.OFB.PKCS5Padding.class.getName());
195
196        put("Cipher.DESEDE/CBC/NoPadding", OpenSSLCipher.DESEDE.CBC.NoPadding.class.getName());
197        put("Cipher.DESEDE/CBC/PKCS5Padding", OpenSSLCipher.DESEDE.CBC.PKCS5Padding.class.getName());
198        put("Cipher.DESEDE/CFB/NoPadding", OpenSSLCipher.DESEDE.CFB.NoPadding.class.getName());
199        put("Cipher.DESEDE/CFB/PKCS5Padding", OpenSSLCipher.DESEDE.CFB.PKCS5Padding.class.getName());
200        put("Cipher.DESEDE/ECB/NoPadding", OpenSSLCipher.DESEDE.ECB.NoPadding.class.getName());
201        put("Cipher.DESEDE/ECB/PKCS5Padding", OpenSSLCipher.DESEDE.ECB.PKCS5Padding.class.getName());
202        put("Cipher.DESEDE/OFB/NoPadding", OpenSSLCipher.DESEDE.OFB.NoPadding.class.getName());
203        put("Cipher.DESEDE/OFB/PKCS5Padding", OpenSSLCipher.DESEDE.OFB.PKCS5Padding.class.getName());
204
205        put("Cipher.ARC4", OpenSSLCipher.ARC4.class.getName());
206
207        /* === Mac === */
208
209        put("Mac.HmacMD5", OpenSSLMac.HmacMD5.class.getName());
210
211        // PKCS#2 - iso(1) member-body(2) US(840) rsadsi(113549) digestAlgorithm(2)
212        // http://www.oid-info.com/get/1.2.840.113549.2
213
214        // HMAC-SHA-1 PRF (7)
215        put("Mac.HmacSHA1", OpenSSLMac.HmacSHA1.class.getName());
216        put("Alg.Alias.Mac.1.2.840.113549.2.7", "HmacSHA1");
217        put("Alg.Alias.Mac.HMAC-SHA1", "HmacSHA1");
218        put("Alg.Alias.Mac.HMAC/SHA1", "HmacSHA1");
219
220        // id-hmacWithSHA256 (9)
221        put("Mac.HmacSHA256", OpenSSLMac.HmacSHA256.class.getName());
222        put("Alg.Alias.Mac.1.2.840.113549.2.9", "HmacSHA256");
223        put("Alg.Alias.Mac.HMAC-SHA256", "HmacSHA256");
224        put("Alg.Alias.Mac.HMAC/SHA256", "HmacSHA256");
225
226        // id-hmacWithSHA384 (10)
227        put("Mac.HmacSHA384", OpenSSLMac.HmacSHA384.class.getName());
228        put("Alg.Alias.Mac.1.2.840.113549.2.10", "HmacSHA384");
229        put("Alg.Alias.Mac.HMAC-SHA384", "HmacSHA384");
230        put("Alg.Alias.Mac.HMAC/SHA384", "HmacSHA384");
231
232        // id-hmacWithSHA384 (11)
233        put("Mac.HmacSHA512", OpenSSLMac.HmacSHA512.class.getName());
234        put("Alg.Alias.Mac.1.2.840.113549.2.11", "HmacSHA512");
235        put("Alg.Alias.Mac.HMAC-SHA512", "HmacSHA512");
236        put("Alg.Alias.Mac.HMAC/SHA512", "HmacSHA512");
237
238        /* === Certificate === */
239
240        put("CertificateFactory.X509", OpenSSLX509CertificateFactory.class.getName());
241        put("Alg.Alias.CertificateFactory.X.509", "X509");
242    }
243}
244