From: Vitaly Chikunov <vt@altlinux.org>
To: Mimi Zohar <zohar@linux.vnet.ibm.com>,
Dmitry Kasatkin <dmitry.kasatkin@gmail.com>,
linux-integrity@vger.kernel.org
Subject: [PATCH v6 00/11] ima-evm-utils: Convert v2 signatures from RSA to EVP_PKEY API
Date: Thu, 20 Jun 2019 10:12:53 +0300 [thread overview]
Message-ID: <20190620071304.24495-1-vt@altlinux.org> (raw)
Convert sign v2 from RSA API (with manual formatting PKCS1) to more generic
EVP_PKEY API, allowing to generate more types of OpenSSL supported signatures.
This is done to enable EC-RDSA signatures, which are already supported in the
Kernel. With some small fixes.
All patches tested on x86_64 to not break anything.
Changes since v5:
- Squash calc keyid v2 with cmd_import patch.
- Add log_err messages to verify_hash_v2 and sign_hash_v2.
- Fix sign and hash generation error processing to show errors instead
of assert failures.
Changes since v4:
- Split conversion into more patches, as suggested by Mimi Zohar.
- Small fixes suggested by Mimi Zohar.
Changes since v3:
- As suggested by Mimi Zohar this is v3 splitted into several patches to
simplify review. No code changes.
Changes since v2:
- Just rebase over newer commits.
Changes since v1:
- More key neutral code in calc_keyid_v1().
- Fix uninitialized sigsize for EVP_PKEY_sign().
- Fix memory leaks for openssl types.
Vitaly Chikunov (11):
ima-evm-utils: Make sure sig buffer is always MAX_SIGNATURE_SIZE
ima-evm-utils: Convert read_pub_key to EVP_PKEY API
ima-evm-utils: Convert read_priv_key to EVP_PKEY API
ima-evm-utils: Convert cmd_import and calc keyid v2 to EVP_PKEY API
ima-evm-utils: Start converting find_keyid to EVP_PKEY API
ima-evm-utils: Convert verify_hash_v2 to EVP_PKEY API
ima-evm-utils: Replace find_keyid with find_keyid_pkey
ima-evm-utils: Convert sign_hash_v2 to EVP_PKEY API
ima-evm-utils: Replace calc_keyid_v2 with calc_pkeyid_v2
ima-evm-utils: Remove RSA_ASN1_templates
ima-evm-utils: Pass status codes from sign and hash functions to the
callers
src/evmctl.c | 43 +++++----
src/imaevm.h | 4 +-
src/libimaevm.c | 277 +++++++++++++++++++++++++++-----------------------------
3 files changed, 158 insertions(+), 166 deletions(-)
--
2.11.0
next reply other threads:[~2019-06-20 7:13 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-06-20 7:12 Vitaly Chikunov [this message]
2019-06-20 7:12 ` [PATCH v6 01/11] ima-evm-utils: Make sure sig buffer is always MAX_SIGNATURE_SIZE Vitaly Chikunov
2019-06-20 7:12 ` [PATCH v6 02/11] ima-evm-utils: Convert read_pub_key to EVP_PKEY API Vitaly Chikunov
2019-06-20 7:12 ` [PATCH v6 03/11] ima-evm-utils: Convert read_priv_key " Vitaly Chikunov
2019-06-20 7:12 ` [PATCH v6 04/11] ima-evm-utils: Convert cmd_import and calc keyid v2 " Vitaly Chikunov
2019-06-20 7:12 ` [PATCH v6 05/11] ima-evm-utils: Start converting find_keyid " Vitaly Chikunov
2019-06-20 7:12 ` [PATCH v6 06/11] ima-evm-utils: Convert verify_hash_v2 " Vitaly Chikunov
2019-06-20 7:13 ` [PATCH v6 07/11] ima-evm-utils: Replace find_keyid with find_keyid_pkey Vitaly Chikunov
2019-06-20 7:13 ` [PATCH v6 08/11] ima-evm-utils: Convert sign_hash_v2 to EVP_PKEY API Vitaly Chikunov
2019-06-20 7:13 ` [PATCH v6 09/11] ima-evm-utils: Replace calc_keyid_v2 with calc_pkeyid_v2 Vitaly Chikunov
2019-06-20 7:13 ` [PATCH v6 10/11] ima-evm-utils: Remove RSA_ASN1_templates Vitaly Chikunov
2019-06-20 7:13 ` [PATCH v6 11/11] ima-evm-utils: Pass status codes from sign and hash functions to the callers Vitaly Chikunov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190620071304.24495-1-vt@altlinux.org \
--to=vt@altlinux.org \
--cc=dmitry.kasatkin@gmail.com \
--cc=linux-integrity@vger.kernel.org \
--cc=zohar@linux.vnet.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.