1 | /* |
1 | /* |
2 | global.h -- global variables and constants |
2 | global.h -- global variables and constants |
|
|
3 | Copyright (C) 2003-2013 Marc Lehmann <gvpe@schmorp.de> |
3 | |
4 | |
|
|
5 | This file is part of GVPE. |
|
|
6 | |
4 | This program is free software; you can redistribute it and/or modify |
7 | GVPE is free software; you can redistribute it and/or modify it |
5 | it under the terms of the GNU General Public License as published by |
8 | under the terms of the GNU General Public License as published by the |
6 | the Free Software Foundation; either version 2 of the License, or |
9 | Free Software Foundation; either version 3 of the License, or (at your |
7 | (at your option) any later version. |
10 | option) any later version. |
8 | |
11 | |
9 | This program is distributed in the hope that it will be useful, |
12 | This program is distributed in the hope that it will be useful, but |
10 | but WITHOUT ANY WARRANTY; without even the implied warranty of |
13 | WITHOUT ANY WARRANTY; without even the implied warranty of |
11 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
14 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General |
12 | GNU General Public License for more details. |
15 | Public License for more details. |
13 | |
16 | |
14 | You should have received a copy of the GNU General Public License |
17 | You should have received a copy of the GNU General Public License along |
15 | along with this program; if not, write to the Free Software |
18 | with this program; if not, see <http://www.gnu.org/licenses/>. |
16 | Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA |
19 | |
|
|
20 | Additional permission under GNU GPL version 3 section 7 |
|
|
21 | |
|
|
22 | If you modify this Program, or any covered work, by linking or |
|
|
23 | combining it with the OpenSSL project's OpenSSL library (or a modified |
|
|
24 | version of that library), containing parts covered by the terms of the |
|
|
25 | OpenSSL or SSLeay licenses, the licensors of this Program grant you |
|
|
26 | additional permission to convey the resulting work. Corresponding |
|
|
27 | Source for a non-source form of such a combination shall include the |
|
|
28 | source code for the parts of OpenSSL used as well as that of the |
|
|
29 | covered work. |
17 | */ |
30 | */ |
18 | |
31 | |
19 | #ifndef GLOBAL_H__ |
32 | #ifndef GLOBAL_H__ |
20 | #define GLOBAL_H__ |
33 | #define GLOBAL_H__ |
21 | |
34 | |
22 | #include "config.h" |
35 | #include "config.h" |
23 | |
36 | |
24 | #include <time.h> |
37 | #include <time.h> |
25 | |
38 | |
|
|
39 | #define HASH_BITS(hash) hashbits_ ## hash |
|
|
40 | #define HASH_SIZE(hash) (HASH_BITS (hash) >> 3) |
|
|
41 | #define hashbits_EVP_ripemd160 160 |
|
|
42 | #define hashbits_EVP_sha1 160 |
|
|
43 | #define hashbits_EVP_sha224 224 |
|
|
44 | #define hashbits_EVP_sha256 256 |
|
|
45 | #define hashbits_EVP_sha384 384 |
|
|
46 | #define hashbits_EVP_sha512 512 |
|
|
47 | #define hashbits_EVP_whirlpool 512 |
|
|
48 | |
|
|
49 | #define KEY_BITS(cipher) keybits_ ## cipher |
|
|
50 | #define KEY_SIZE(cipher) (KEY_BITS (cipher) >> 3) |
|
|
51 | //#define keybits_EVP_bf_ctr 128 // actually 32-448 |
|
|
52 | #define keybits_EVP_aes_128_ctr 128 |
|
|
53 | #define keybits_EVP_aes_192_ctr 192 |
|
|
54 | #define keybits_EVP_aes_256_ctr 256 |
|
|
55 | |
|
|
56 | #define BLOCK_BITS(cipher) blockbits_ ## cipher |
|
|
57 | #define BLOCK_SIZE(cipher) (BLOCK_BITS (cipher) >> 3) |
|
|
58 | //#define blockbits_EVP_bf_ctr 64 |
|
|
59 | #define blockbits_EVP_aes_128_ctr 8 |
|
|
60 | #define blockbits_EVP_aes_192_ctr 8 |
|
|
61 | #define blockbits_EVP_aes_256_ctr 8 |
|
|
62 | |
|
|
63 | #define IV_BITS(cipher) ivbits_ ## cipher |
|
|
64 | #define IV_SIZE(cipher) (IV_BITS (cipher) >> 3) |
|
|
65 | //#define ivbits_EVP_bf_ctr 64 |
|
|
66 | #define ivbits_EVP_aes_128_ctr 128 |
|
|
67 | #define ivbits_EVP_aes_192_ctr 128 |
|
|
68 | #define ivbits_EVP_aes_256_ctr 128 |
|
|
69 | |
26 | /* Protocol version. Different major versions are incompatible, |
70 | /* Protocol version. Different major versions are incompatible, |
27 | * different minor versions probably are compatible ;) |
71 | * different minor versions probably are compatible ;) |
28 | */ |
72 | */ |
29 | |
73 | |
30 | #define PROTOCOL_MAJOR 0 |
74 | #define PROTOCOL_MAJOR 1 |
31 | #define PROTOCOL_MINOR 0 |
75 | #define PROTOCOL_MINOR 0 |
32 | |
76 | |
33 | #define RSA_KEYBITS 1280 // must be >= 1280 and divisible by 8 |
77 | #define SERIAL_SIZE 16 |
34 | #define RSA_KEYLEN ((RSA_KEYBITS) >> 3) |
|
|
35 | #define RSA_OVERHEAD (41 + 1) // well, no define for OAEP in openssl |
|
|
36 | |
78 | |
37 | #define RSA_HASH EVP_ripemd160 ()// speed don't matter, boy, safety does.. I need sha256 :( |
79 | #define SEED_SIZE 64 // how many octets to seed rng with |
38 | #define RSA_HASHLEN (160 >> 3) |
|
|
39 | #define RSA_RESLEN RSA_HASHLEN |
|
|
40 | |
80 | |
41 | #define RSA_IDLEN 16 // how many bytes are used to identify the challenge |
81 | #define RSA_OAEP_SIZE 41 |
42 | #define RSA_TTL 20 // challenge bytes timeout after n seconds |
|
|
43 | |
82 | |
44 | #define CIPHER ENABLE_CIPHER () |
83 | #define HKDF_XTR_HASH EVP_sha512 |
45 | #define CIPHER_KEYLEN (EVP_CIPHER_key_length (CIPHER)) |
84 | #define HKDF_PRF_HASH EVP_sha256 |
46 | #define DIGEST ENABLE_DIGEST () |
|
|
47 | #define HMAC_KEYLEN (256 >> 3) // number of bits used for the HMAC key (also change CHG_HMAC_KEY) |
|
|
48 | |
85 | |
49 | #define MAX_SEQNO 0xfffffff0U |
86 | #define HKDF_SALT 24 // how many bytes for the hkdf salt |
50 | |
87 | |
51 | #define CHG_SEQNO 0 // where the seqno starts within the rsa challenge |
88 | #define RSA_KEYLEN (RSABITS >> 3) |
52 | #define CHG_CIPHER_KEY 4 // where the key starts within the rsa challenge |
|
|
53 | #define CHG_HMAC_KEY 86 // where the key starts within the rsa challenge (256 bits at the end!) |
|
|
54 | |
89 | |
55 | // hdr seq len hmac MAC MAC |
90 | #define AUTH_DIGEST ENABLE_AUTH |
56 | #define VPE_OVERHEAD (4 + 4 + 4 + RAND_SIZE + HMACLENGTH - 6 - 6) |
91 | #define AUTH_SIZE (HASH_SIZE (AUTH_DIGEST)) |
57 | #define IP_OVERHEAD 20 // size of a (normal) ip header |
92 | #define AUTH_TTL 12 // challenge bytes timeout after n seconds of non-use |
58 | #define UDP_OVERHEAD (IP_OVERHEAD + 20) // size of a (normal) ip + udp header |
|
|
59 | #define MAX_OVERHEAD UDP_OVERHEAD // the max. overhead of any protocol |
|
|
60 | #define ETH_OVERHEAD 14 // the size of an ethernet header |
|
|
61 | #define MAXSIZE (MAX_MTU + VPE_OVERHEAD)// slightly too large, but who cares |
|
|
62 | |
93 | |
63 | #define PKTCACHESIZE 5 // the size of the memory pool for packets |
94 | #define CIPHER ENABLE_CIPHER |
|
|
95 | #define CIPHER_KEYSIZE (KEY_SIZE (CIPHER)) |
|
|
96 | #define CIPHER_IKMSIZE (CIPHER_KEYSIZE * 3 / 2) // randomness in rsa challenge |
64 | |
97 | |
65 | #define QUEUEDEPTH 16 // the number of packets that will be queued (should be low) |
98 | #define MAC_DIGEST ENABLE_HMAC |
|
|
99 | #define MAC_KEYSIZE HASH_SIZE (ENABLE_HMAC) // number of bits used for the HMAC key |
|
|
100 | #define MAC_IKMSIZE (MAC_KEYSIZE * 3 / 2) // randomness in rsa challenge |
66 | |
101 | |
67 | #define WINDOWSIZE 512 // sliding window size |
102 | #define WINDOWSIZE 512 // sliding window size |
|
|
103 | #define MAX_SEQNO (0xfffffff0U - WINDOWSIZE * 8) |
|
|
104 | |
|
|
105 | // hdr seq len hmac MAC MAC |
|
|
106 | #define VPE_OVERHEAD (4 + 4 + 4 + HMACLENGTH - 6 - 6) |
|
|
107 | #define IP_OVERHEAD 20 // size of a (normal) ip header |
|
|
108 | #define GRE_OVERHEAD (IP_OVERHEAD + 4) |
|
|
109 | #define ICMP_OVERHEAD (IP_OVERHEAD + 4) |
|
|
110 | #define UDP_OVERHEAD (IP_OVERHEAD + 20) // size of a (normal) ip + udp header (wrong, but don't care) |
|
|
111 | #define TCP_OVERHEAD (IP_OVERHEAD + 22) // size of a (normal) ip + tcp header + packetlength |
|
|
112 | #define MAX_OVERHEAD UDP_OVERHEAD // the max. overhead of any protocol (ok, tcp doesn't count) |
|
|
113 | #define ETH_OVERHEAD 14 // the size of an ethernet header |
|
|
114 | #define MAXSIZE (MAX_MTU + IP_OVERHEAD) // slightly too large, but who cares |
|
|
115 | |
|
|
116 | #define PKTCACHESIZE 16 // the size of the memory pool for packets |
68 | |
117 | |
69 | extern char *confbase; // directory in which all config files are |
118 | extern char *confbase; // directory in which all config files are |
70 | extern char *thisnode; // config for current node (TODO: remove) |
119 | extern char *thisnode; // config for current node (TODO: remove) |
71 | extern char *pidfilename; // pid file location |
120 | |
|
|
121 | template<typename T, typename U> static inline T min (T a, U b) { return a < (T)b ? a : (T)b; } |
|
|
122 | template<typename T, typename U> static inline void min_it (T &a, U b) { a = a < (T)b ? a : (T)b; } |
|
|
123 | template<typename T, typename U> static inline T max (T a, U b) { return a > (T)b ? a : (T)b; } |
|
|
124 | template<typename T, typename U> static inline void max_it (T &a, U b) { a = a > (T)b ? a : (T)b; } |
|
|
125 | |
|
|
126 | template<typename T, typename U, typename V> static inline T clamp (T v, U a, V b) { return v < (T)a ? a : v >(T)b ? b : v; } |
|
|
127 | |
|
|
128 | template<typename T, typename U> static inline void swap (T& a, U& b) { T t=a; a=(T)b; b=(U)t; } |
72 | |
129 | |
73 | #endif |
130 | #endif |
74 | |
131 | |