use clear_on_drop::clear::Clear;
use error::Error;
#[cfg(feature = "hmac")]
use hmac::Hmac;
#[cfg(feature = "pbkdf2")]
use pbkdf2::pbkdf2;
use rand::{OsRng, RngCore};
#[cfg(feature = "sha2")]
use sha2::Sha256;
use std::fmt::{self, Debug};
pub const AUTH_KEY_SIZE: usize = 32;
pub const DEFAULT_PASSWORD: &[u8] = b"password";
pub const DEFAULT_PBKDF2_SALT: &[u8] = b"Yubico";
pub const DEFAULT_PBKDF2_ITERATIONS: usize = 10_000;
#[derive(Clone)]
pub struct AuthKey(pub(crate) [u8; AUTH_KEY_SIZE]);
impl AuthKey {
pub fn random() -> Self {
let mut rng = OsRng::new().expect("RNG failure!");
let mut challenge = [0u8; AUTH_KEY_SIZE];
rng.fill_bytes(&mut challenge);
AuthKey(challenge)
}
#[cfg(feature = "passwords")]
pub fn derive_from_password(password: &[u8]) -> Self {
let mut kdf_output = [0u8; AUTH_KEY_SIZE];
pbkdf2::<Hmac<Sha256>>(
password,
DEFAULT_PBKDF2_SALT,
DEFAULT_PBKDF2_ITERATIONS,
&mut kdf_output,
);
Self::new(kdf_output)
}
pub fn from_slice(key_slice: &[u8]) -> Result<Self, AuthKeyError> {
ensure!(
key_slice.len() == AUTH_KEY_SIZE,
AuthKeyErrorKind::SizeInvalid,
"expected {}-byte key, got {}",
AUTH_KEY_SIZE,
key_slice.len()
);
let mut key_bytes = [0u8; AUTH_KEY_SIZE];
key_bytes.copy_from_slice(key_slice);
Ok(AuthKey(key_bytes))
}
pub fn new(key_bytes: [u8; AUTH_KEY_SIZE]) -> Self {
AuthKey(key_bytes)
}
pub fn as_secret_slice(&self) -> &[u8] {
&self.0
}
pub(crate) fn enc_key(&self) -> &[u8] {
&self.0[..16]
}
pub(crate) fn mac_key(&self) -> &[u8] {
&self.0[16..]
}
}
impl Debug for AuthKey {
fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result {
write!(f, "yubihsm::AuthKey(...)")
}
}
#[cfg(feature = "passwords")]
impl Default for AuthKey {
fn default() -> Self {
AuthKey::derive_from_password(DEFAULT_PASSWORD)
}
}
impl Drop for AuthKey {
fn drop(&mut self) {
self.0.clear();
}
}
impl From<[u8; AUTH_KEY_SIZE]> for AuthKey {
fn from(key_bytes: [u8; AUTH_KEY_SIZE]) -> AuthKey {
AuthKey::new(key_bytes)
}
}
impl_array_serializers!(AuthKey, AUTH_KEY_SIZE);
pub type AuthKeyError = Error<AuthKeyErrorKind>;
#[derive(Copy, Clone, Eq, PartialEq, Debug, Fail)]
pub enum AuthKeyErrorKind {
#[fail(display = "invalid size")]
SizeInvalid,
}