From mboxrd@z Thu Jan 1 00:00:00 1970 From: Vitaly Chikunov Date: Thu, 28 Feb 2019 07:11:43 +0000 Subject: Re: [RFC PATCH 1/4] X.509: Parse public key parameters from x509 for akcipher Message-Id: <20190228071143.mstflzxozj4bfpix@altlinux.org> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit List-Id: References: <20190106133608.820-1-vt@altlinux.org> <20190106133608.820-2-vt@altlinux.org> <20190209214240.56gq7ivn3pw3bssf@altlinux.org> <20190210184628.yupsxgjlaicwbxg6@altlinux.org> <20190219043732.x3sbwzqlz4ikntxo@gondor.apana.org.au> <20190224064840.hii4ccjksjdnewae@altlinux.org> <20190228061444.3escryzoit3idtwg@gondor.apana.org.au> <20190228070449.gjwoq4c2b3x5grie@altlinux.org> In-Reply-To: <20190228070449.gjwoq4c2b3x5grie@altlinux.org> To: Herbert Xu , David Howells , Mimi Zohar , Dmitry Kasatkin , linux-integrity@vger.kernel.org, keyrings@vger.kernel.org, linux-crypto@vger.kernel.org, linux-kernel@vger.kernel.org On Thu, Feb 28, 2019 at 10:04:49AM +0300, Vitaly Chikunov wrote: > Herbert, > > On Thu, Feb 28, 2019 at 02:14:44PM +0800, Herbert Xu wrote: > > On Sun, Feb 24, 2019 at 09:48:40AM +0300, Vitaly Chikunov wrote: > > > > > > If we pass SubjectPublicKeyInfo into set_pub_key itself (making > > > set_params not needed) we will break ABI and compatibility with RSA > > > drivers, because whole SubjectPublicKeyInfo is not expected by the > > > > This compatibility does not matter. We can always add translating > > layers into the crypto API to deal with this. The only ABI that > > matters is the one to user-space. > > It seems that you insist on set_params to be removed and both key and > params to be passed into set_{pub,priv}_key. This means reworking all > existing RSA drivers and callers, right? Can you please confirm that > huge rework to avoid misunderstanding? > > I think to pass SubjectPublicKeyInfo into set_*_key would be overkill, > because TPM drivers may not have it and we would need BER encoder just > for that. > > So, probably, something simple like length, key data, length, params data > will be enough? Or maybe we could just add additional argument to set_{pub,priv}_key? (If you agree to change that ABI anyway). > Thanks,