PrivateKeyFile.SSHCOM.cs 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130
  1. #nullable enable
  2. using System;
  3. using System.Collections.Generic;
  4. using System.Security.Cryptography;
  5. using System.Text;
  6. using Renci.SshNet.Common;
  7. using Renci.SshNet.Security;
  8. using Renci.SshNet.Security.Cryptography.Ciphers;
  9. using CipherMode = System.Security.Cryptography.CipherMode;
  10. namespace Renci.SshNet
  11. {
  12. public partial class PrivateKeyFile
  13. {
  14. private sealed class SSHCOM : IPrivateKeyParser
  15. {
  16. private readonly byte[] _data;
  17. private readonly string? _passPhrase;
  18. public SSHCOM(byte[] data, string? passPhrase)
  19. {
  20. _data = data;
  21. _passPhrase = passPhrase;
  22. }
  23. public Key Parse()
  24. {
  25. var reader = new SshDataReader(_data);
  26. var magicNumber = reader.ReadUInt32();
  27. if (magicNumber != 0x3f6ff9eb)
  28. {
  29. throw new SshException("Invalid SSH2 private key.");
  30. }
  31. _ = reader.ReadUInt32(); // Read total bytes length including magic number
  32. var keyType = reader.ReadString(SshData.Ascii);
  33. var ssh2CipherName = reader.ReadString(SshData.Ascii);
  34. var blobSize = (int)reader.ReadUInt32();
  35. byte[] keyData;
  36. if (ssh2CipherName == "none")
  37. {
  38. keyData = reader.ReadBytes(blobSize);
  39. }
  40. else if (ssh2CipherName == "3des-cbc")
  41. {
  42. if (string.IsNullOrEmpty(_passPhrase))
  43. {
  44. throw new SshPassPhraseNullOrEmptyException("Private key is encrypted but passphrase is empty.");
  45. }
  46. var key = GetCipherKey(_passPhrase, 192 / 8);
  47. var ssh2Сipher = new TripleDesCipher(key, new byte[8], CipherMode.CBC, pkcs7Padding: false);
  48. keyData = ssh2Сipher.Decrypt(reader.ReadBytes(blobSize));
  49. }
  50. else
  51. {
  52. throw new SshException(string.Format("Cipher method '{0}' is not supported.", ssh2CipherName));
  53. }
  54. /*
  55. * TODO: Create two specific data types to avoid using SshDataReader class.
  56. */
  57. reader = new SshDataReader(keyData);
  58. var decryptedLength = reader.ReadUInt32();
  59. if (decryptedLength > blobSize - 4)
  60. {
  61. throw new SshException("Invalid passphrase.");
  62. }
  63. if (keyType.Contains("rsa"))
  64. {
  65. var exponent = reader.ReadBigIntWithBits(); // e
  66. var d = reader.ReadBigIntWithBits(); // d
  67. var modulus = reader.ReadBigIntWithBits(); // n
  68. var inverseQ = reader.ReadBigIntWithBits(); // u
  69. var q = reader.ReadBigIntWithBits(); // p
  70. var p = reader.ReadBigIntWithBits(); // q
  71. return new RsaKey(modulus, exponent, d, p, q, inverseQ);
  72. }
  73. else if (keyType.Contains("dsa"))
  74. {
  75. var zero = reader.ReadUInt32();
  76. if (zero != 0)
  77. {
  78. throw new SshException("Invalid private key");
  79. }
  80. var p = reader.ReadBigIntWithBits();
  81. var g = reader.ReadBigIntWithBits();
  82. var q = reader.ReadBigIntWithBits();
  83. var y = reader.ReadBigIntWithBits();
  84. var x = reader.ReadBigIntWithBits();
  85. return new DsaKey(p, q, g, y, x);
  86. }
  87. throw new NotSupportedException(string.Format("Key type '{0}' is not supported.", keyType));
  88. }
  89. private static byte[] GetCipherKey(string passphrase, int length)
  90. {
  91. var cipherKey = new List<byte>();
  92. #pragma warning disable CA1850 // Prefer static HashData method; We'll reuse the object on lower targets.
  93. using (var md5 = MD5.Create())
  94. {
  95. var passwordBytes = Encoding.UTF8.GetBytes(passphrase);
  96. var hash = md5.ComputeHash(passwordBytes);
  97. cipherKey.AddRange(hash);
  98. while (cipherKey.Count < length)
  99. {
  100. hash = passwordBytes.Concat(hash);
  101. hash = md5.ComputeHash(hash);
  102. cipherKey.AddRange(hash);
  103. }
  104. }
  105. #pragma warning restore CA1850 // Prefer static HashData method
  106. return cipherKey.ToArray().Take(length);
  107. }
  108. }
  109. }
  110. }