Message ID | 20240515150213.32491-1-jarkko@kernel.org (mailing list archive) |
---|---|
State | Superseded |
Delegated to: | Herbert Xu |
Headers | show |
Series | [v2] crypto: rsa-pkcs1pad: export rsa1_asn_lookup() | expand |
On Wed, May 15, 2024 at 06:02:10PM +0300, Jarkko Sakkinen wrote: > ASN.1 template is required for TPM2 asymmetric keys, as it needs to be > piggy-packed with the input data before applying TPM2_RSA_Decrypt. This > patch prepares crypto subsystem for the addition of those keys. > > Later rsa_lookup_asn1() can be enabled in crypto/asymmetric_keys/Kconfig > by: > > depends on CRYPTO_RSA >= <TPM2 asymmetric keys> > > Cc: James Prestwood <prestwoj@gmail.com> > Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> > --- > v2: > - Fix typo in the kdoc. > - Export also the template struct. > --- > crypto/rsa-pkcs1pad.c | 16 ++++++++++------ > include/crypto/rsa-pkcs1pad.h | 20 ++++++++++++++++++++ > 2 files changed, 30 insertions(+), 6 deletions(-) > create mode 100644 include/crypto/rsa-pkcs1pad.h Please provide a link to the patch that will make use of this. Thanks,
On Thu May 16, 2024 at 7:14 AM EEST, Herbert Xu wrote: > On Wed, May 15, 2024 at 06:02:10PM +0300, Jarkko Sakkinen wrote: > > ASN.1 template is required for TPM2 asymmetric keys, as it needs to be > > piggy-packed with the input data before applying TPM2_RSA_Decrypt. This > > patch prepares crypto subsystem for the addition of those keys. > > > > Later rsa_lookup_asn1() can be enabled in crypto/asymmetric_keys/Kconfig > > by: > > > > depends on CRYPTO_RSA >= <TPM2 asymmetric keys> > > > > Cc: James Prestwood <prestwoj@gmail.com> > > Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> > > --- > > v2: > > - Fix typo in the kdoc. > > - Export also the template struct. > > --- > > crypto/rsa-pkcs1pad.c | 16 ++++++++++------ > > include/crypto/rsa-pkcs1pad.h | 20 ++++++++++++++++++++ > > 2 files changed, 30 insertions(+), 6 deletions(-) > > create mode 100644 include/crypto/rsa-pkcs1pad.h > > Please provide a link to the patch that will make use of this. OK, fair enough. Will be part of the full patch set. Overally I can say that this will be used to make textbook RSA to a proper RSA signature ASN.1 and appropriate padding. I.e. breath new life to this patch, which has duplicate code: https://lore.kernel.org/all/20200518172704.29608-18-prestwoj@gmail.com/ TPM2_RSA_Decrypt is exactly textbook RSA so it partially needs the code from kernel's RSA implementation. BR, Jarkko
diff --git a/crypto/rsa-pkcs1pad.c b/crypto/rsa-pkcs1pad.c index cd501195f34a..ea162ccf28ec 100644 --- a/crypto/rsa-pkcs1pad.c +++ b/crypto/rsa-pkcs1pad.c @@ -7,6 +7,7 @@ #include <crypto/algapi.h> #include <crypto/akcipher.h> +#include <crypto/rsa-pkcs1pad.h> #include <crypto/internal/akcipher.h> #include <crypto/internal/rsa.h> #include <linux/err.h> @@ -79,11 +80,7 @@ static const u8 rsa_digest_info_sha3_512[] = { 0x05, 0x00, 0x04, 0x40 }; -static const struct rsa_asn1_template { - const char *name; - const u8 *data; - size_t size; -} rsa_asn1_templates[] = { +const struct rsa_asn1_template rsa_asn1_templates[] = { #define _(X) { #X, rsa_digest_info_##X, sizeof(rsa_digest_info_##X) } _(md5), _(sha1), @@ -101,7 +98,13 @@ static const struct rsa_asn1_template { { NULL } }; -static const struct rsa_asn1_template *rsa_lookup_asn1(const char *name) +/** + * rsa_lookup_asn1() - Lookup the ASN.1 digest info given the hash + * name: hash algorithm name + * + * Returns the ASN.1 digest info on success, and NULL on failure. + */ +const struct rsa_asn1_template *rsa_lookup_asn1(const char *name) { const struct rsa_asn1_template *p; @@ -110,6 +113,7 @@ static const struct rsa_asn1_template *rsa_lookup_asn1(const char *name) return p; return NULL; } +EXPORT_SYMBOL_GPL(rsa_lookup_asn1); struct pkcs1pad_ctx { struct crypto_akcipher *child; diff --git a/include/crypto/rsa-pkcs1pad.h b/include/crypto/rsa-pkcs1pad.h new file mode 100644 index 000000000000..32c7453ff644 --- /dev/null +++ b/include/crypto/rsa-pkcs1pad.h @@ -0,0 +1,20 @@ +/* SPDX-License-Identifier: GPL-2.0 */ +/* + * RSA padding templates. + */ + +#ifndef _CRYPTO_RSA_PKCS1PAD_H +#define _CRYPTO_RSA_PKCS1PAD_H + +/* + * Hash algorithm name to ASN.1 template mapping. + */ +struct rsa_asn1_template { + const char *name; + const u8 *data; + size_t size; +}; + +const struct rsa_asn1_template *rsa_lookup_asn1(const char *name); + +#endif /* _CRYPTO_RSA_PKCS1PAD_H */
ASN.1 template is required for TPM2 asymmetric keys, as it needs to be piggy-packed with the input data before applying TPM2_RSA_Decrypt. This patch prepares crypto subsystem for the addition of those keys. Later rsa_lookup_asn1() can be enabled in crypto/asymmetric_keys/Kconfig by: depends on CRYPTO_RSA >= <TPM2 asymmetric keys> Cc: James Prestwood <prestwoj@gmail.com> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> --- v2: - Fix typo in the kdoc. - Export also the template struct. --- crypto/rsa-pkcs1pad.c | 16 ++++++++++------ include/crypto/rsa-pkcs1pad.h | 20 ++++++++++++++++++++ 2 files changed, 30 insertions(+), 6 deletions(-) create mode 100644 include/crypto/rsa-pkcs1pad.h