* [AesGcmCipher] Use BouncyCastle as a fallback if BCL does not support.
* Switch back to collection initializer
* Remove conditional compilation
* Throw SshConnectionException with Reason MacError when authentication tag mismatch
* Separate BCL and BouncyCastle implementation
* Update AesGcmCipher.BclImpl.cs
* Naming enhancement
* Remove empty line
* Disable S1199. See https://github.com/sshnet/SSH.NET/pull/1371#discussion_r1704293356
* Set InnerException when MAC error. Remove Message check.
* Store KeyParameter as private field
* Use GcmCipher.ProcessAadBytes to avoid the copy of associated data
* Move nonce to constructor to avoid creating AeadParameters each packet
* Use const int for tag size
---------
Co-authored-by: Wojciech Nagórski <wojtpl2@gmail.com>
* Implements ChaCha20 cipher algorithm.
* Implements chacha20-poly1305@openssh.com
* Update Cipher.cs
* Update ChaCha20Poly1305Cipher.cs
* Note that the length of the concatenation of 'packet_length',
'padding_length', 'payload', and 'random padding' MUST be a multiple
of the cipher block size or 8, whichever is larger.
See https://www.rfc-editor.org/rfc/rfc4253#section-6
* Use Chaos.Nacl Poly1305Donna
* Fix build. Fix typo. Update README
* Update README.md
* Fix build
* Remove trailing whitespace
* Fix build
* Change to BouncyCastle
* Inherit from SymmetricCipher instead of StreamCipher since StreamCipher is deleted
* Resolve conflicts
* Move field to local variable
* Compute poly key stream once
* Update test/Renci.SshNet.IntegrationTests/CipherTests.cs
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Fix build; Add net48 integration test in CI
---------
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
Co-authored-by: Wojciech Nagórski <wojtpl2@gmail.com>
* Init AeadCipher
* Move AeadCipher to parent folder. Move EncryptBlock/DecryptBlock from SymmetricCipher to BlockCipher
* simplify parameter name
* Implement AesGcmCipher
* Update README
* Remove protected IV from AeadCipher; Set offset to outbound sequence just like other ciphers
* Rename associatedData to packetLengthField
* Use Span<byte> to avoid unnecessary allocations
* Use `Span` to improve performance when `IncrementCounter()`
* Add `IsAead` property to `CipherInfo`. Include packet length field and tag field in offset and length when call AesGcm's `Decrypt(...)` method. Do not determine HMAC if cipher is AesGcm during kex.
* Fix build
* Fix UT
* Check `AesGcm.IsSupported` before add to the `Encryptions` collection.
Guard AES-GCM with `NET6_0_OR_GREATER`.
Insert AES-GCM ciphers right after AES-CTR ciphers but before AES-CBC ciphers, which is similar with OpenSSH:
```
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
```
Although Dictionary's order is not defined, from observation, it is in the same order with add. Anyway that would be another topic.
* Suppress CA1859 "Use concrete types when possible for improved performance" for `ConnectionInfo.Encryptions`.
Test `Aes128Gcm` and `Aes256Gcm` only when `NET6_0_OR_GREATER`
* Update xml doc comments. Do not treat AesGcmCipher separately in Session.cs
* Fix build
* Fix build
* Update the comment as ChaCha20Poly1305 uses a separated key to encypt the packet length and the size it 4.
* Update src/Renci.SshNet/Security/Cryptography/Cipher.cs
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Make `AesGcmCipher` internal.
Assert offset when decrypt.
* Fix nullable error in build
* typos
---------
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Move test projects to test folder.
Move global.json to root of repo.
Update solution items in solution.
* Move test projects to test folder.
Move global.json to root of repo.
Update solution items in solution.
Update appveyor configuration/
* Attempt to have appveyor use the correct .NET SDK.
* Update .NET SDK to version 7.0.402.
* Move Data folder below Renci.SshNet.Tests.
* Make csinst less chatty.
* Move Data folder directly below test folder as it's used by multiple test projects.
* Remove CS1591 nowarn from concrete test projects as this is already defined in the Directory.Build.props that is in the test folder.
* Fix integration test after moving test projects
---------
Co-authored-by: drieseng <gert.driesen@telenet.be>