Port from PyCrypto to PyCroptodome
As the PyCrypto website says [1]: > PyCrypto 2.x is unmaintained, obsolete, and contains security > vulnerabilities. Therefore, switch to PyCryptodome, a maintained PyCrypto fork which is listed there as the recommended alternative for existing software that depends on PyCrypto. Notes on the port: 1) As the PyCryptodome introduction documentation [2] says, there are 2 alternative projects/namespaces that can be used: * pycryptodome, which uses the `Crypto` package that PyCrypto also uses, so is almost a drop-in replacement for Pycrypto * pycryptodomex, which uses the `Cryptodome` package It also mentions that the use of pycryptodome "is therefore recommended only when you are sure that the whole application is deployed in a virtualenv". Since it isn't sure that the application is deployed in a virtualenv, to make it more explicit that PyCryptodome is being used and because Linux distros like Debian package the `Cryptodome` package [3], the port is done to the `pycryptodomex` library that uses the `Cryptodome` package name. 2) As the "Compatibility with PyCrypto" page in the PyCryptodome doc [4] says: > The following packages, modules and functions have been removed: > > * Crypto.Random.OSRNG, Crypto.Util.winrandom and Crypto.Random.randpool. > You should use Crypto.Random only. The `PublicKey.RSA.generate` method already uses `Crypto.Random.get_random_bytes()` as default [5], so just drop the second parameter using `RandomPool.getBytes` in `virtualsmartcard/src/vpicc/virtualsmartcard/cards/cryptoflex.py`. [1] https://www.pycrypto.org/ [2] https://www.pycryptodome.org/src/introduction [3] https://packages.debian.org/bullseye/python3-pycryptodome [4] https://pycryptodome.readthedocs.io/en/latest/src/vs_pycrypto.html [5] https://pycryptodome.readthedocs.io/en/latest/src/public_key/rsa.html
This commit is contained in:
@@ -37,7 +37,7 @@ install:
|
|||||||
- python -m pip install --upgrade pip
|
- python -m pip install --upgrade pip
|
||||||
- pip install virtualenv
|
- pip install virtualenv
|
||||||
- pip install -U setuptools
|
- pip install -U setuptools
|
||||||
- pip install pycryptodome
|
- pip install pycryptodomex
|
||||||
- pip install pbkdf2
|
- pip install pbkdf2
|
||||||
- pip install Pillow
|
- pip install Pillow
|
||||||
- pip install pyreadline
|
- pip install pyreadline
|
||||||
|
|||||||
@@ -103,7 +103,7 @@ Depending on your usage of the |vpicc| you may need to install the following:
|
|||||||
|
|
||||||
- Python_
|
- Python_
|
||||||
- pyscard_ (relaying a local smart card with `--type=relay`)
|
- pyscard_ (relaying a local smart card with `--type=relay`)
|
||||||
- PyCrypto_, PBKDF2_, PIL_, readline_ or PyReadline_ (emulation of electronic
|
- PyCryptodome_, PBKDF2_, PIL_, readline_ or PyReadline_ (emulation of electronic
|
||||||
passport with `--type=ePass`)
|
passport with `--type=ePass`)
|
||||||
- OpenPACE_ (emulation of German identity card with `--type=nPA`)
|
- OpenPACE_ (emulation of German identity card with `--type=nPA`)
|
||||||
- libqrencode_ (to print a QR code on the command line for `vpcd-config`; an
|
- libqrencode_ (to print a QR code on the command line for `vpcd-config`; an
|
||||||
@@ -314,7 +314,7 @@ Notes and References
|
|||||||
.. _PCSC-lite: https://pcsclite.apdu.fr/
|
.. _PCSC-lite: https://pcsclite.apdu.fr/
|
||||||
.. _Python: http://www.python.org/
|
.. _Python: http://www.python.org/
|
||||||
.. _pyscard: http://pyscard.sourceforge.net/
|
.. _pyscard: http://pyscard.sourceforge.net/
|
||||||
.. _PyCrypto: http://pycrypto.org/
|
.. _PyCryptodome: https://www.pycryptodome.org/
|
||||||
.. _PBKDF2: https://www.dlitz.net/software/python-pbkdf2/
|
.. _PBKDF2: https://www.dlitz.net/software/python-pbkdf2/
|
||||||
.. _readline: https://docs.python.org/3.3/library/readline.html
|
.. _readline: https://docs.python.org/3.3/library/readline.html
|
||||||
.. _PyReadline: https://pypi.python.org/pypi/pyreadline
|
.. _PyReadline: https://pypi.python.org/pypi/pyreadline
|
||||||
|
|||||||
@@ -211,7 +211,7 @@ responses via NFC to a contact-less smart card that signs the mail.</p>
|
|||||||
<ul class="simple">
|
<ul class="simple">
|
||||||
<li><p><a class="reference external" href="http://www.python.org/">Python</a> <a class="footnote-reference brackets" href="#id7" id="id8">3</a></p></li>
|
<li><p><a class="reference external" href="http://www.python.org/">Python</a> <a class="footnote-reference brackets" href="#id7" id="id8">3</a></p></li>
|
||||||
<li><p><a class="reference external" href="http://pyscard.sourceforge.net/">pyscard</a> <a class="footnote-reference brackets" href="#id9" id="id10">4</a> (relaying a local smart card with <cite>–type=relay</cite>)</p></li>
|
<li><p><a class="reference external" href="http://pyscard.sourceforge.net/">pyscard</a> <a class="footnote-reference brackets" href="#id9" id="id10">4</a> (relaying a local smart card with <cite>–type=relay</cite>)</p></li>
|
||||||
<li><p><a class="reference external" href="http://pycrypto.org/">PyCrypto</a> <a class="footnote-reference brackets" href="#id11" id="id12">5</a>, <a class="reference external" href="https://www.dlitz.net/software/python-pbkdf2/">PBKDF2</a> <a class="footnote-reference brackets" href="#id13" id="id14">6</a>, <a class="reference external" href="http://www.pythonware.com/products/pil/">PIL</a> <a class="footnote-reference brackets" href="#id19" id="id20">9</a>, <a class="reference external" href="https://docs.python.org/3.3/library/readline.html">readline</a> <a class="footnote-reference brackets" href="#id15" id="id16">7</a> or <a class="reference external" href="https://pypi.python.org/pypi/pyreadline">PyReadline</a> <a class="footnote-reference brackets" href="#id17" id="id18">8</a> (emulation of electronic
|
<li><p><a class="reference external" href="https://www.pycryptodome.org/">PyCryptodome</a> <a class="footnote-reference brackets" href="#id11" id="id12">5</a>, <a class="reference external" href="https://www.dlitz.net/software/python-pbkdf2/">PBKDF2</a> <a class="footnote-reference brackets" href="#id13" id="id14">6</a>, <a class="reference external" href="http://www.pythonware.com/products/pil/">PIL</a> <a class="footnote-reference brackets" href="#id19" id="id20">9</a>, <a class="reference external" href="https://docs.python.org/3.3/library/readline.html">readline</a> <a class="footnote-reference brackets" href="#id15" id="id16">7</a> or <a class="reference external" href="https://pypi.python.org/pypi/pyreadline">PyReadline</a> <a class="footnote-reference brackets" href="#id17" id="id18">8</a> (emulation of electronic
|
||||||
passport with <cite>–type=ePass</cite>)</p></li>
|
passport with <cite>–type=ePass</cite>)</p></li>
|
||||||
<li><p><a class="reference external" href="https://github.com/frankmorgner/openpace">OpenPACE</a> <a class="footnote-reference brackets" href="#id21" id="id22">10</a> (emulation of German identity card with <cite>–type=nPA</cite>)</p></li>
|
<li><p><a class="reference external" href="https://github.com/frankmorgner/openpace">OpenPACE</a> <a class="footnote-reference brackets" href="#id21" id="id22">10</a> (emulation of German identity card with <cite>–type=nPA</cite>)</p></li>
|
||||||
<li><p><a class="reference external" href="https://fukuchi.org/works/qrencode/">libqrencode</a> <a class="footnote-reference brackets" href="#id23" id="id24">11</a> (to print a QR code on the command line for <cite>vpcd-config</cite>; an
|
<li><p><a class="reference external" href="https://fukuchi.org/works/qrencode/">libqrencode</a> <a class="footnote-reference brackets" href="#id23" id="id24">11</a> (to print a QR code on the command line for <cite>vpcd-config</cite>; an
|
||||||
@@ -563,7 +563,7 @@ more than welcome! Please use our <a class="reference external" href="https://gi
|
|||||||
<dd><p><a class="reference external" href="http://pyscard.sourceforge.net/">http://pyscard.sourceforge.net/</a></p>
|
<dd><p><a class="reference external" href="http://pyscard.sourceforge.net/">http://pyscard.sourceforge.net/</a></p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt class="label" id="id11"><span class="brackets"><a class="fn-backref" href="#id12">5</a></span></dt>
|
<dt class="label" id="id11"><span class="brackets"><a class="fn-backref" href="#id12">5</a></span></dt>
|
||||||
<dd><p><a class="reference external" href="http://pycrypto.org/">http://pycrypto.org/</a></p>
|
<dd><p><a class="reference external" href="https://www.pycryptodome.org/">https://www.pycryptodome.org/</a></p>
|
||||||
</dd>
|
</dd>
|
||||||
<dt class="label" id="id13"><span class="brackets"><a class="fn-backref" href="#id14">6</a></span></dt>
|
<dt class="label" id="id13"><span class="brackets"><a class="fn-backref" href="#id14">6</a></span></dt>
|
||||||
<dd><p><a class="reference external" href="https://www.dlitz.net/software/python-pbkdf2/">https://www.dlitz.net/software/python-pbkdf2/</a></p>
|
<dd><p><a class="reference external" href="https://www.dlitz.net/software/python-pbkdf2/">https://www.dlitz.net/software/python-pbkdf2/</a></p>
|
||||||
|
|||||||
@@ -103,7 +103,7 @@ Depending on your usage of the |vpicc| you may need to install the following:
|
|||||||
|
|
||||||
- Python_
|
- Python_
|
||||||
- pyscard_ (relaying a local smart card with `--type=relay`)
|
- pyscard_ (relaying a local smart card with `--type=relay`)
|
||||||
- PyCrypto_, PBKDF2_, PIL_, readline_ or PyReadline_ (emulation of electronic
|
- PyCryptodome, PBKDF2_, PIL_, readline_ or PyReadline_ (emulation of electronic
|
||||||
passport with `--type=ePass`)
|
passport with `--type=ePass`)
|
||||||
- OpenPACE_ (emulation of German identity card with `--type=nPA`)
|
- OpenPACE_ (emulation of German identity card with `--type=nPA`)
|
||||||
- libqrencode_ (to print a QR code on the command line for `vpcd-config`; an
|
- libqrencode_ (to print a QR code on the command line for `vpcd-config`; an
|
||||||
@@ -320,7 +320,7 @@ requiremets are installed as follows::
|
|||||||
sudo apt-get install python2.7-dev
|
sudo apt-get install python2.7-dev
|
||||||
curl https://bootstrap.pypa.io/pip/2.7/get-pip.py -o get-pip.py
|
curl https://bootstrap.pypa.io/pip/2.7/get-pip.py -o get-pip.py
|
||||||
python2.7 get-pip.py
|
python2.7 get-pip.py
|
||||||
python2.7 -m pip install pycrypto pyscard
|
python2.7 -m pip install pycryptodomex pyscard
|
||||||
python2.7 readpass.py --no-gui
|
python2.7 readpass.py --no-gui
|
||||||
git clone https://github.com/henryk/cyberflex-shell
|
git clone https://github.com/henryk/cyberflex-shell
|
||||||
cd cyberflex-shell
|
cd cyberflex-shell
|
||||||
@@ -354,7 +354,7 @@ Notes and References
|
|||||||
.. _PCSC-lite: https://pcsclite.apdu.fr/
|
.. _PCSC-lite: https://pcsclite.apdu.fr/
|
||||||
.. _Python: http://www.python.org/
|
.. _Python: http://www.python.org/
|
||||||
.. _pyscard: http://pyscard.sourceforge.net/
|
.. _pyscard: http://pyscard.sourceforge.net/
|
||||||
.. _PyCrypto: http://pycrypto.org/
|
.. _PyCryptodome: https://www.pycryptodome.org/
|
||||||
.. _PBKDF2: https://www.dlitz.net/software/python-pbkdf2/
|
.. _PBKDF2: https://www.dlitz.net/software/python-pbkdf2/
|
||||||
.. _readline: https://docs.python.org/3.3/library/readline.html
|
.. _readline: https://docs.python.org/3.3/library/readline.html
|
||||||
.. _PyReadline: https://pypi.python.org/pypi/pyreadline
|
.. _PyReadline: https://pypi.python.org/pypi/pyreadline
|
||||||
|
|||||||
@@ -25,12 +25,12 @@ from random import randint
|
|||||||
from virtualsmartcard.utils import inttostring
|
from virtualsmartcard.utils import inttostring
|
||||||
|
|
||||||
try:
|
try:
|
||||||
# Use PyCrypto (if available)
|
# Use PyCryptodome (if available)
|
||||||
from Crypto.Cipher import DES3, DES, AES, ARC4 # @UnusedImport
|
from Cryptodome.Cipher import DES3, DES, AES, ARC4 # @UnusedImport
|
||||||
from Crypto.Hash import HMAC
|
from Cryptodome.Hash import HMAC
|
||||||
|
|
||||||
except ImportError:
|
except ImportError:
|
||||||
# PyCrypto not available. Use the Python standard library.
|
# PyCryptodome not available. Use the Python standard library.
|
||||||
import hmac as HMAC
|
import hmac as HMAC
|
||||||
|
|
||||||
CYBERFLEX_IV = b'\x00' * 8
|
CYBERFLEX_IV = b'\x00' * 8
|
||||||
@@ -83,7 +83,7 @@ def get_cipher_keylen(cipherspec):
|
|||||||
# cipher = globals().get(cipherparts[0].upper(), None)
|
# cipher = globals().get(cipherparts[0].upper(), None)
|
||||||
# Note: return cipher.key_size does not work on Ubuntu, because e.g.
|
# Note: return cipher.key_size does not work on Ubuntu, because e.g.
|
||||||
# AES.key_size == 0
|
# AES.key_size == 0
|
||||||
if cipher == "AES": # Pycrypto uses AES128
|
if cipher == "AES": # PyCryptodome uses AES128
|
||||||
return 16
|
return 16
|
||||||
elif cipher == "DES":
|
elif cipher == "DES":
|
||||||
return 8
|
return 8
|
||||||
|
|||||||
@@ -98,8 +98,7 @@ class CryptoflexSE(Security_Environment):
|
|||||||
Used to specify the key length. The mapping is: 0x40 => 256 Bit,
|
Used to specify the key length. The mapping is: 0x40 => 256 Bit,
|
||||||
0x60 => 512 Bit, 0x80 => 1024
|
0x60 => 512 Bit, 0x80 => 1024
|
||||||
"""
|
"""
|
||||||
from Crypto.PublicKey import RSA
|
from Cryptodome.PublicKey import RSA
|
||||||
from Crypto.Util.randpool import RandomPool
|
|
||||||
|
|
||||||
keynumber = p1 # TODO: Check if key exists
|
keynumber = p1 # TODO: Check if key exists
|
||||||
|
|
||||||
@@ -110,8 +109,7 @@ class CryptoflexSE(Security_Environment):
|
|||||||
else:
|
else:
|
||||||
keylength = keylength_dict[p2]
|
keylength = keylength_dict[p2]
|
||||||
|
|
||||||
rnd = RandomPool()
|
PublicKey = RSA.generate(keylength)
|
||||||
PublicKey = RSA.generate(keylength, rnd.get_bytes)
|
|
||||||
self.dst.key = PublicKey
|
self.dst.key = PublicKey
|
||||||
|
|
||||||
e_in = struct.unpack("<i", data)
|
e_in = struct.unpack("<i", data)
|
||||||
|
|||||||
Reference in New Issue
Block a user