mirror of
https://github.com/sshnet/SSH.NET.git
synced 2026-09-10 01:05:42 +00:00
3dc3fc8b1c
* Init AeadCipher * Move AeadCipher to parent folder. Move EncryptBlock/DecryptBlock from SymmetricCipher to BlockCipher * simplify parameter name * Implement AesGcmCipher * Update README * Remove protected IV from AeadCipher; Set offset to outbound sequence just like other ciphers * Rename associatedData to packetLengthField * Use Span<byte> to avoid unnecessary allocations * Use `Span` to improve performance when `IncrementCounter()` * Add `IsAead` property to `CipherInfo`. Include packet length field and tag field in offset and length when call AesGcm's `Decrypt(...)` method. Do not determine HMAC if cipher is AesGcm during kex. * Fix build * Fix UT * Check `AesGcm.IsSupported` before add to the `Encryptions` collection. Guard AES-GCM with `NET6_0_OR_GREATER`. Insert AES-GCM ciphers right after AES-CTR ciphers but before AES-CBC ciphers, which is similar with OpenSSH: ``` debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com ``` Although Dictionary's order is not defined, from observation, it is in the same order with add. Anyway that would be another topic. * Suppress CA1859 "Use concrete types when possible for improved performance" for `ConnectionInfo.Encryptions`. Test `Aes128Gcm` and `Aes256Gcm` only when `NET6_0_OR_GREATER` * Update xml doc comments. Do not treat AesGcmCipher separately in Session.cs * Fix build * Fix build * Update the comment as ChaCha20Poly1305 uses a separated key to encypt the packet length and the size it 4. * Update src/Renci.SshNet/Security/Cryptography/Cipher.cs Co-authored-by: Rob Hague <rob.hague00@gmail.com> * Make `AesGcmCipher` internal. Assert offset when decrypt. * Fix nullable error in build * typos --------- Co-authored-by: Rob Hague <rob.hague00@gmail.com>