From: Philippe Reynes <philippe.reynes@softathome.com>
To: marko.makela@iki.fi, jonny.green@keytechinc.com,
raymondmaoca@gmail.com, trini@konsulko.com,
simon.glass@canonical.com
Cc: u-boot@lists.u-boot-project.org,
Philippe Reynes <philippe.reynes@softathome.com>,
Simon Glass <sjg@chromium.org>
Subject: [PATCH v9 10/15] tools: mkimage: pre-load: add support of ecdsa
Date: Thu, 3 Sep 2026 10:17:00 +0200 [thread overview]
Message-ID: <20260903081705.12894-11-philippe.reynes@softathome.com> (raw)
In-Reply-To: <20260903081705.12894-1-philippe.reynes@softathome.com>
Right now, mkimage can only create pre-load header
using rsa. We add the support of ecdsa.
Reviewed-by: Simon Glass <sjg@chromium.org>
Reviewed-by: Raymond Mao <raymondmaoca@gmail.com>
Signed-off-by: Philippe Reynes <philippe.reynes@softathome.com>
---
v3:
- initial version
v4:
- use pre_load_noffset (do not compute it again)
- release memory allocated with strdup
- clean code
v5:
- check checksum and algo before using them
v6:
- no change
v7:
- no change
v8:
- no change
v9:
- no change
lib/ecdsa/ecdsa-libcrypto.c | 29 +++++++++---
tools/image-host.c | 92 ++++++++++++++++++++++++++++++++-----
2 files changed, 103 insertions(+), 18 deletions(-)
diff --git a/lib/ecdsa/ecdsa-libcrypto.c b/lib/ecdsa/ecdsa-libcrypto.c
index b3fc75fac48..5e69782424c 100644
--- a/lib/ecdsa/ecdsa-libcrypto.c
+++ b/lib/ecdsa/ecdsa-libcrypto.c
@@ -517,14 +517,9 @@ int ecdsa_verify(struct image_sign_info *info,
return ret;
}
-static int do_add(struct signer *ctx, void *fdt, const char *key_node_name,
- struct image_sign_info *info)
+static int search_key_node(void *fdt, const char *key_node_name)
{
- int signature_node, key_node, ret, key_bits;
- const char *curve_name;
- const EC_GROUP *group;
- const EC_POINT *point;
- BIGNUM *x, *y;
+ int signature_node, key_node;
signature_node = fdt_subnode_offset(fdt, 0, FIT_SIG_NODENAME);
if (signature_node == -FDT_ERR_NOTFOUND) {
@@ -559,6 +554,26 @@ static int do_add(struct signer *ctx, void *fdt, const char *key_node_name,
return key_node;
}
+ return key_node;
+}
+
+static int do_add(struct signer *ctx, void *fdt, const char *key_node_name,
+ struct image_sign_info *info)
+{
+ int key_node, ret, key_bits;
+ const char *curve_name;
+ const EC_GROUP *group;
+ const EC_POINT *point;
+ BIGNUM *x, *y;
+
+ if (info->required_keynode >= 0) {
+ key_node = info->required_keynode;
+ } else {
+ key_node = search_key_node(fdt, key_node_name);
+ if (key_node < 0)
+ return key_node;
+ }
+
group = EC_KEY_get0_group(ctx->ecdsa_key);
key_bits = EC_GROUP_order_bits(group);
curve_name = OBJ_nid2sn(EC_GROUP_get_curve_name(group));
diff --git a/tools/image-host.c b/tools/image-host.c
index 9a85a3dda2f..ed1bfe68a31 100644
--- a/tools/image-host.c
+++ b/tools/image-host.c
@@ -14,6 +14,7 @@
#include <image.h>
#include <hexdump.h>
#include <version.h>
+#include <u-boot/ecdsa.h>
#include <sys/stat.h>
#include <sys/wait.h>
@@ -1681,13 +1682,74 @@ err_cert:
return ret;
}
+static int fit_pre_load_data_key_rsa(const char *keydir, void *keydest,
+ int pre_load_noffset, const void *key_name)
+{
+ unsigned char *pubkey = NULL;
+ int ret, pubkey_len;
+
+ /* Read public key */
+ ret = read_pub_key(keydir, key_name, &pubkey, &pubkey_len);
+ if (ret < 0)
+ goto out;
+
+ /* Add the public key to the device tree */
+ ret = fdt_setprop(keydest, pre_load_noffset, "public-key",
+ pubkey, pubkey_len);
+ if (ret)
+ fprintf(stderr, "Can't set public-key in node %s (ret = %d)\n",
+ IMAGE_PRE_LOAD_PATH, ret);
+ out:
+ return ret;
+}
+
+static int fit_pre_load_data_key_ecdsa(const char *keydir, void *keydest,
+ int pre_load_noffset, const void *key_name,
+ const void *algo_name)
+{
+ struct image_sign_info info;
+ int node, ret = 0;
+
+ memset(&info, 0, sizeof(info));
+ info.keydir = keydir;
+ info.keyname = strdup(key_name);
+ info.name = strdup(algo_name);
+ info.checksum = image_get_checksum_algo(algo_name);
+ if (!info.checksum) {
+ fprintf(stderr, "Can't find valid checksum from %s\n",
+ (char *)algo_name);
+ ret = -EINVAL;
+ goto out;
+ }
+ info.crypto = image_get_crypto_algo(algo_name);
+ if (!info.crypto) {
+ fprintf(stderr, "Can't find valid crypto from %s\n",
+ (char *)algo_name);
+ ret = -EINVAL;
+ goto out;
+ }
+ info.required_keynode = pre_load_noffset;
+
+ node = ecdsa_add_verify_data(&info, keydest);
+ if (node < 0) {
+ fprintf(stderr, "Can't add verify data: err = %d\n", node);
+ ret = -EIO;
+ }
+
+ out:
+ free((void *)info.keyname);
+ free((void *)info.name);
+
+ return ret;
+}
+
int fit_pre_load_data(const char *keydir, void *keydest, void *fit)
{
int pre_load_noffset;
const void *algo_name;
const void *key_name;
- unsigned char *pubkey = NULL;
- int ret, pubkey_len;
+ char *name;
+ int ret;
if (!keydir || !keydest || !fit)
return 0;
@@ -1714,17 +1776,25 @@ int fit_pre_load_data(const char *keydir, void *keydest, void *fit)
goto out;
}
- /* Read public key */
- ret = read_pub_key(keydir, key_name, &pubkey, &pubkey_len);
- if (ret < 0)
+ /* Is it a RSA or an ECDSA key */
+ name = strchr((const char *)algo_name, ',');
+ if (!name) {
+ fprintf(stderr, "The name of the algo is invalid: %s\n",
+ (char *)algo_name);
+ ret = -EINVAL;
goto out;
+ }
+ name += 1;
- /* Add the public key to the device tree */
- ret = fdt_setprop(keydest, pre_load_noffset, "public-key",
- pubkey, pubkey_len);
- if (ret)
- fprintf(stderr, "Can't set public-key in node %s (ret = %d)\n",
- IMAGE_PRE_LOAD_PATH, ret);
+ if (!strncmp(name, "rsa", 3)) {
+ ret = fit_pre_load_data_key_rsa(keydir, keydest, pre_load_noffset, key_name);
+ } else if (!strncmp(name, "ecdsa", 5)) {
+ ret = fit_pre_load_data_key_ecdsa(keydir, keydest, pre_load_noffset,
+ key_name, algo_name);
+ } else {
+ fprintf(stderr, "The algo %s is not supported\n", (char *)algo_name);
+ ret = -EINVAL;
+ }
out:
return ret;
--
2.43.0
next prev parent reply other threads:[~2026-09-03 8:17 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 8:16 [PATCH v9 00/15] add software ecdsa support Philippe Reynes
2026-09-03 8:16 ` [PATCH v9 01/15] ecdsa: fix support of secp521r1 Philippe Reynes
2026-09-03 14:30 ` Raymond Mao
2026-09-03 8:16 ` [PATCH v9 02/15] mbedtls: enable support of ecc Philippe Reynes
2026-09-03 14:31 ` Raymond Mao
2026-09-03 8:16 ` [PATCH v9 03/15] ecdsa: initial support of ecdsa using mbedtls Philippe Reynes
2026-09-03 14:31 ` Raymond Mao
2026-09-03 8:16 ` [PATCH v9 04/15] test: lib: ecdsa: add initial test Philippe Reynes
2026-09-03 14:32 ` Raymond Mao
2026-09-03 8:16 ` [PATCH v9 05/15] drivers: crypto: add software ecdsa support Philippe Reynes
2026-09-03 14:32 ` Raymond Mao
2026-09-03 15:33 ` Raymond Mao
2026-09-03 18:33 ` Tom Rini
2026-09-03 8:16 ` [PATCH v9 06/15] test: dm: ecdsa.c: clean this test as software ecdsa is now implemented Philippe Reynes
2026-09-03 14:33 ` Raymond Mao
2026-09-03 8:16 ` [PATCH v9 07/15] test: py: vboot: prepare integration test for ecdsa Philippe Reynes
2026-09-03 15:42 ` Raymond Mao
2026-09-03 8:16 ` [PATCH v9 08/15] test: vboot: add " Philippe Reynes
2026-09-03 15:43 ` Raymond Mao
2026-09-03 8:16 ` [PATCH v9 09/15] tools: fit_image_setup_sig: set required_keynode to -1 Philippe Reynes
2026-09-03 14:34 ` Raymond Mao
2026-09-03 8:17 ` Philippe Reynes [this message]
2026-09-03 14:36 ` [PATCH v9 10/15] tools: mkimage: pre-load: add support of ecdsa Raymond Mao
2026-09-03 8:17 ` [PATCH v9 11/15] tools: binman: " Philippe Reynes
2026-09-03 14:37 ` Raymond Mao
2026-09-03 8:17 ` [PATCH v9 12/15] boot: " Philippe Reynes
2026-09-03 14:38 ` Raymond Mao
2026-09-03 8:17 ` [PATCH v9 13/15] tools: preload_check_sign: " Philippe Reynes
2026-09-03 14:39 ` Raymond Mao
2026-09-03 8:17 ` [PATCH v9 14/15] test: py: vboot: prepare test for global signature with ecdsa Philippe Reynes
2026-09-03 14:40 ` Raymond Mao
2026-09-03 8:17 ` [PATCH v9 15/15] test: py: vboot: add " Philippe Reynes
2026-09-03 14:41 ` Raymond Mao
2026-09-03 18:35 ` [PATCH v9 00/15] add software ecdsa support Tom Rini
2026-09-04 8:10 ` Philippe Reynes
2026-09-04 14:32 ` Tom Rini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260903081705.12894-11-philippe.reynes@softathome.com \
--to=philippe.reynes@softathome.com \
--cc=jonny.green@keytechinc.com \
--cc=marko.makela@iki.fi \
--cc=raymondmaoca@gmail.com \
--cc=simon.glass@canonical.com \
--cc=sjg@chromium.org \
--cc=trini@konsulko.com \
--cc=u-boot@lists.u-boot-project.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.