2024-05-13 12:55:06 +08:00
|
|
|
// SPDX-License-Identifier: GPL-2.0-or-later
|
2022-05-19 00:15:34 +08:00
|
|
|
/* Self-testing for signature checking.
|
|
|
|
*
|
|
|
|
* Copyright (C) 2022 Red Hat, Inc. All Rights Reserved.
|
|
|
|
* Written by David Howells (dhowells@redhat.com)
|
|
|
|
*/
|
|
|
|
|
2023-10-16 13:21:44 +08:00
|
|
|
#include <crypto/pkcs7.h>
|
2022-05-19 00:15:34 +08:00
|
|
|
#include <linux/cred.h>
|
2023-10-16 13:21:44 +08:00
|
|
|
#include <linux/kernel.h>
|
2022-05-19 00:15:34 +08:00
|
|
|
#include <linux/key.h>
|
2023-10-16 13:21:44 +08:00
|
|
|
#include <linux/module.h>
|
2024-05-13 12:55:06 +08:00
|
|
|
#include "selftest.h"
|
2022-05-19 00:15:34 +08:00
|
|
|
#include "x509_parser.h"
|
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
void fips_signature_selftest(const char *name,
|
|
|
|
const u8 *keys, size_t keys_len,
|
|
|
|
const u8 *data, size_t data_len,
|
|
|
|
const u8 *sig, size_t sig_len)
|
2022-05-19 00:15:34 +08:00
|
|
|
{
|
|
|
|
struct key *keyring;
|
2024-05-13 12:55:06 +08:00
|
|
|
int ret;
|
2022-05-19 00:15:34 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
pr_notice("Running certificate verification %s selftest\n", name);
|
2022-05-19 00:15:34 +08:00
|
|
|
|
|
|
|
keyring = keyring_alloc(".certs_selftest",
|
|
|
|
GLOBAL_ROOT_UID, GLOBAL_ROOT_GID, current_cred(),
|
|
|
|
(KEY_POS_ALL & ~KEY_POS_SETATTR) |
|
|
|
|
KEY_USR_VIEW | KEY_USR_READ |
|
|
|
|
KEY_USR_SEARCH,
|
|
|
|
KEY_ALLOC_NOT_IN_QUOTA,
|
|
|
|
NULL, NULL);
|
|
|
|
if (IS_ERR(keyring))
|
2024-05-13 12:55:06 +08:00
|
|
|
panic("Can't allocate certs %s selftest keyring: %ld\n", name, PTR_ERR(keyring));
|
2022-05-19 00:15:34 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
ret = x509_load_certificate_list(keys, keys_len, keyring);
|
2022-05-19 00:15:34 +08:00
|
|
|
if (ret < 0)
|
2024-05-13 12:55:06 +08:00
|
|
|
panic("Can't allocate certs %s selftest keyring: %d\n", name, ret);
|
2022-05-19 00:15:34 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
struct pkcs7_message *pkcs7;
|
2022-05-19 00:15:34 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
pkcs7 = pkcs7_parse_message(sig, sig_len);
|
|
|
|
if (IS_ERR(pkcs7))
|
|
|
|
panic("Certs %s selftest: pkcs7_parse_message() = %d\n", name, ret);
|
2022-05-19 00:15:34 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
pkcs7_supply_detached_data(pkcs7, data, data_len);
|
2022-05-19 00:15:34 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
ret = pkcs7_verify(pkcs7, VERIFYING_MODULE_SIGNATURE);
|
|
|
|
if (ret < 0)
|
|
|
|
panic("Certs %s selftest: pkcs7_verify() = %d\n", name, ret);
|
2022-05-19 00:15:34 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
ret = pkcs7_validate_trust(pkcs7, keyring);
|
|
|
|
if (ret < 0)
|
|
|
|
panic("Certs %s selftest: pkcs7_validate_trust() = %d\n", name, ret);
|
2022-05-19 00:15:34 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
pkcs7_free_message(pkcs7);
|
2022-05-19 00:15:34 +08:00
|
|
|
|
|
|
|
key_put(keyring);
|
2024-05-13 12:55:06 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
static int __init fips_signature_selftest_init(void)
|
|
|
|
{
|
|
|
|
fips_signature_selftest_rsa();
|
2024-05-13 12:55:07 +08:00
|
|
|
fips_signature_selftest_ecdsa();
|
2022-05-19 00:15:34 +08:00
|
|
|
return 0;
|
|
|
|
}
|
2023-10-16 13:21:44 +08:00
|
|
|
|
2024-05-13 12:55:06 +08:00
|
|
|
late_initcall(fips_signature_selftest_init);
|
2023-10-16 13:21:44 +08:00
|
|
|
|
|
|
|
MODULE_DESCRIPTION("X.509 self tests");
|
|
|
|
MODULE_AUTHOR("Red Hat, Inc.");
|
|
|
|
MODULE_LICENSE("GPL");
|