mbox series

[v5,00/11] ima-evm-utils: Convert sign v2 from RSA to EVP_PKEY API

Message ID 20190618135623.6861-1-vt@altlinux.org (mailing list archive)
Headers show
Series ima-evm-utils: Convert sign v2 from RSA to EVP_PKEY API | expand

Message

Vitaly Chikunov June 18, 2019, 1:56 p.m. UTC
Convert sign v2 from RSA API (with manual formatting PKCS1) to more generic
EVP_PKEY API, allowing to generate more types of OpenSSL supported signatures.
This is done to enable EC-RDSA signatures, which are already supported in the
Kernel.

Changes since v4:
- Split conversion into more patches, as suggested by Mimi Zohar.
- Small fixes suggested by Mimi Zohar.

Changes since v3:
- As suggested by Mimi Zohar this is v3 splitted into several patches to
  simplify review. No code changes.

Changes since v2:
- Just rebase over newer commits.

Changes since v1:
- More key neutral code in calc_keyid_v1().
- Fix uninitialized sigsize for EVP_PKEY_sign().
- Fix memory leaks for openssl types.

Vitaly Chikunov (11):
  ima-evm-utils: Make sure sig buffer is always MAX_SIGNATURE_SIZE
  ima-evm-utils: Change read_pub_key to use EVP_PKEY API
  ima-evm-utils: Change read_priv_key to use EVP_PKEY API
  ima-evm-utils: Start converting calc keyid v2 to EVP_PKEY API
  ima-evm-utils: Convert cmd_import to use EVP_PKEY API
  ima-evm-utils: Start converting find_keyid to use EVP_PKEY API
  ima-evm-utils: Convert verify_hash_v2 to EVP_PKEY API
  ima-evm-utils: Finish conversion of find_keyid to EVP_PKEY API
  ima-evm-utils: Convert sign_hash_v2 to use EVP_PKEY API
  ima-evm-utils: Finish converting calc keyid v2 to EVP_PKEY API
  ima-evm-utils: Remove RSA_ASN1_templates

 src/evmctl.c    |  29 ++++---
 src/imaevm.h    |   4 +-
 src/libimaevm.c | 261 +++++++++++++++++++++++++-------------------------------
 3 files changed, 136 insertions(+), 158 deletions(-)