OLD | NEW |
(Empty) | |
| 1 /* Copyright (c) 2010 The Chromium OS Authors. All rights reserved. |
| 2 * Use of this source code is governed by a BSD-style license that can be |
| 3 * found in the LICENSE file. |
| 4 * |
| 5 * Host functions for verified boot. |
| 6 */ |
| 7 |
| 8 /* TODO: change all 'return 0', 'return 1' into meaningful return codes */ |
| 9 |
| 10 #include "host_keyblock.h" |
| 11 |
| 12 #include "cryptolib.h" |
| 13 #include "host_common.h" |
| 14 #include "utility.h" |
| 15 #include "vboot_common.h" |
| 16 |
| 17 |
| 18 VbKeyBlockHeader* KeyBlockCreate(const VbPublicKey* data_key, |
| 19 const VbPrivateKey* signing_key, |
| 20 uint64_t flags) { |
| 21 |
| 22 VbKeyBlockHeader* h; |
| 23 uint64_t signed_size = sizeof(VbKeyBlockHeader) + data_key->key_size; |
| 24 uint64_t block_size = (signed_size + SHA512_DIGEST_SIZE + |
| 25 siglen_map[signing_key->algorithm]); |
| 26 uint8_t* data_key_dest; |
| 27 uint8_t* block_sig_dest; |
| 28 uint8_t* block_chk_dest; |
| 29 VbSignature *sigtmp; |
| 30 |
| 31 /* Allocate key block */ |
| 32 h = (VbKeyBlockHeader*)Malloc(block_size); |
| 33 if (!h) |
| 34 return NULL; |
| 35 data_key_dest = (uint8_t*)(h + 1); |
| 36 block_chk_dest = data_key_dest + data_key->key_size; |
| 37 block_sig_dest = block_chk_dest + SHA512_DIGEST_SIZE; |
| 38 |
| 39 Memcpy(h->magic, KEY_BLOCK_MAGIC, KEY_BLOCK_MAGIC_SIZE); |
| 40 h->header_version_major = KEY_BLOCK_HEADER_VERSION_MAJOR; |
| 41 h->header_version_minor = KEY_BLOCK_HEADER_VERSION_MINOR; |
| 42 h->key_block_size = block_size; |
| 43 h->key_block_flags = flags; |
| 44 |
| 45 /* Copy data key */ |
| 46 PublicKeyInit(&h->data_key, data_key_dest, data_key->key_size); |
| 47 PublicKeyCopy(&h->data_key, data_key); |
| 48 |
| 49 /* Set up signature structs so we can calculate the signatures */ |
| 50 SignatureInit(&h->key_block_checksum, block_chk_dest, |
| 51 SHA512_DIGEST_SIZE, signed_size); |
| 52 SignatureInit(&h->key_block_signature, block_sig_dest, |
| 53 siglen_map[signing_key->algorithm], signed_size); |
| 54 |
| 55 /* Calculate checksum */ |
| 56 sigtmp = CalculateChecksum((uint8_t*)h, signed_size); |
| 57 SignatureCopy(&h->key_block_checksum, sigtmp); |
| 58 Free(sigtmp); |
| 59 |
| 60 /* Calculate signature */ |
| 61 sigtmp = CalculateSignature((uint8_t*)h, signed_size, signing_key); |
| 62 SignatureCopy(&h->key_block_signature, sigtmp); |
| 63 Free(sigtmp); |
| 64 |
| 65 /* Return the header */ |
| 66 return h; |
| 67 } |
| 68 |
| 69 |
| 70 /* Read a key block from a .keyblock file. Caller owns the returned |
| 71 * pointer, and must free it with Free(). |
| 72 * |
| 73 * Returns NULL if error. */ |
| 74 VbKeyBlockHeader* KeyBlockRead(const char* filename) { |
| 75 |
| 76 VbKeyBlockHeader* block; |
| 77 uint64_t file_size; |
| 78 |
| 79 block = (VbKeyBlockHeader*)ReadFile(filename, &file_size); |
| 80 if (!block) { |
| 81 debug("Error reading key block file: %s\n", filename); |
| 82 return NULL; |
| 83 } |
| 84 |
| 85 /* Verify the hash of the key block, since we can do that without |
| 86 * the public signing key. */ |
| 87 if (0 != KeyBlockVerify(block, file_size, NULL)) { |
| 88 debug("Invalid key block file: filename\n", filename); |
| 89 Free(block); |
| 90 return NULL; |
| 91 } |
| 92 |
| 93 return block; |
| 94 } |
| 95 |
| 96 |
| 97 /* Write a key block to a file in .keyblock format. */ |
| 98 int KeyBlockWrite(const char* filename, const VbKeyBlockHeader* key_block) { |
| 99 |
| 100 if (0 != WriteFile(filename, key_block, key_block->key_block_size)) { |
| 101 debug("KeyBlockWrite() error writing key block\n"); |
| 102 return 1; |
| 103 } |
| 104 |
| 105 return 0; |
| 106 } |
OLD | NEW |