Skip to content
Snippets Groups Projects
user avatar
Augusto Caringi authored
MR: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-9/-/merge_requests/6514

JIRA: https://issues.redhat.com/browse/RHEL-81929



    commit 747ae81883d21595b162cc40523a982024700fed
    Author: Joachim Vandersmissen <git@jvdsn.com>
    Date:   Sun May 12 23:55:07 2024 -0500

        certs: Add ECDSA signature verification self-test

        Commit c27b2d2012e1 ("crypto: testmgr - allow ecdsa-nist-p256 and -p384
        in FIPS mode") enabled support for ECDSA in crypto/testmgr.c. The
        PKCS#7 signature verification API builds upon the KCAPI primitives to
        perform its high-level operations. Therefore, this change in testmgr.c
        also allows ECDSA to be used by the PKCS#7 signature verification API
        (in FIPS mode).

        However, from a FIPS perspective, the PKCS#7 signature verification API
        is a distinct "service" from the KCAPI primitives. This is because the
        PKCS#7 API performs a "full" signature verification, which consists of
        both hashing the data to be verified, and the public key operation.
        On the other hand, the KCAPI primitive does not perform this hashing
        step - it accepts pre-hashed data from the caller and only performs the
        public key operation.

        For this reason, the ECDSA self-tests in crypto/testmgr.c are not
        sufficient to cover ECDSA signature verification offered by the PKCS#7
        API. This is reflected by the self-test already present in this file
        for RSA PKCS#1 v1.5 signature verification.

        The solution is simply to add a second self-test here for ECDSA. P-256
        with SHA-256 hashing was chosen as those parameters should remain
        FIPS-approved for the foreseeable future, while keeping the performance
        impact to a minimum. The ECDSA certificate and PKCS#7 signed data was
        generated using OpenSSL. The input data is identical to the input data
        for the existing RSA self-test.

Signed-off-by: default avatarJoachim Vandersmissen <git@jvdsn.com>
Reviewed-by: default avatarJarkko Sakkinen <jarkko@kernel.org>
Acked-by: default avatarHerbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: default avatarJarkko Sakkinen <jarkko@kernel.org>

Signed-off-by: default avatarHerbert Xu <herbert.xu@redhat.com>

Approved-by: default avatarVladis Dronov <vdronov@redhat.com>
Approved-by: default avatarCoiby Xu <coxu@redhat.com>
Approved-by: default avatarClemens Lang <cllang@redhat.com>
Approved-by: default avatarCKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>

Merged-by: default avatarAugusto Caringi <acaringi@redhat.com>
b88709c9
History
Name Last commit Last update