2024-05-13 07:55:06 +03:00
// SPDX-License-Identifier: GPL-2.0-or-later
2022-05-18 19:15:34 +03:00
/* Self-testing for signature checking.
*
* Copyright ( C ) 2022 Red Hat , Inc . All Rights Reserved .
* Written by David Howells ( dhowells @ redhat . com )
*/
2023-10-16 08:21:44 +03:00
# include <crypto/pkcs7.h>
2022-05-18 19:15:34 +03:00
# include <linux/cred.h>
2023-10-16 08:21:44 +03:00
# include <linux/kernel.h>
2022-05-18 19:15:34 +03:00
# include <linux/key.h>
2023-10-16 08:21:44 +03:00
# include <linux/module.h>
2024-05-13 07:55:06 +03:00
# include "selftest.h"
2022-05-18 19:15:34 +03:00
# include "x509_parser.h"
2024-05-13 07:55:06 +03:00
void fips_signature_selftest ( const char * name ,
const u8 * keys , size_t keys_len ,
const u8 * data , size_t data_len ,
const u8 * sig , size_t sig_len )
2022-05-18 19:15:34 +03:00
{
struct key * keyring ;
2024-05-13 07:55:06 +03:00
int ret ;
2022-05-18 19:15:34 +03:00
2024-05-13 07:55:06 +03:00
pr_notice ( " Running certificate verification %s selftest \n " , name ) ;
2022-05-18 19:15:34 +03:00
keyring = keyring_alloc ( " .certs_selftest " ,
GLOBAL_ROOT_UID , GLOBAL_ROOT_GID , current_cred ( ) ,
( KEY_POS_ALL & ~ KEY_POS_SETATTR ) |
KEY_USR_VIEW | KEY_USR_READ |
KEY_USR_SEARCH ,
KEY_ALLOC_NOT_IN_QUOTA ,
NULL , NULL ) ;
if ( IS_ERR ( keyring ) )
2024-05-13 07:55:06 +03:00
panic ( " Can't allocate certs %s selftest keyring: %ld \n " , name , PTR_ERR ( keyring ) ) ;
2022-05-18 19:15:34 +03:00
2024-05-13 07:55:06 +03:00
ret = x509_load_certificate_list ( keys , keys_len , keyring ) ;
2022-05-18 19:15:34 +03:00
if ( ret < 0 )
2024-05-13 07:55:06 +03:00
panic ( " Can't allocate certs %s selftest keyring: %d \n " , name , ret ) ;
2022-05-18 19:15:34 +03:00
2024-05-13 07:55:06 +03:00
struct pkcs7_message * pkcs7 ;
2022-05-18 19:15:34 +03:00
2024-05-13 07:55:06 +03:00
pkcs7 = pkcs7_parse_message ( sig , sig_len ) ;
if ( IS_ERR ( pkcs7 ) )
panic ( " Certs %s selftest: pkcs7_parse_message() = %d \n " , name , ret ) ;
2022-05-18 19:15:34 +03:00
2024-05-13 07:55:06 +03:00
pkcs7_supply_detached_data ( pkcs7 , data , data_len ) ;
2022-05-18 19:15:34 +03:00
2024-05-13 07:55:06 +03:00
ret = pkcs7_verify ( pkcs7 , VERIFYING_MODULE_SIGNATURE ) ;
if ( ret < 0 )
panic ( " Certs %s selftest: pkcs7_verify() = %d \n " , name , ret ) ;
2022-05-18 19:15:34 +03:00
2024-05-13 07:55:06 +03:00
ret = pkcs7_validate_trust ( pkcs7 , keyring ) ;
if ( ret < 0 )
panic ( " Certs %s selftest: pkcs7_validate_trust() = %d \n " , name , ret ) ;
2022-05-18 19:15:34 +03:00
2024-05-13 07:55:06 +03:00
pkcs7_free_message ( pkcs7 ) ;
2022-05-18 19:15:34 +03:00
key_put ( keyring ) ;
2024-05-13 07:55:06 +03:00
}
static int __init fips_signature_selftest_init ( void )
{
fips_signature_selftest_rsa ( ) ;
2024-05-13 07:55:07 +03:00
fips_signature_selftest_ecdsa ( ) ;
2022-05-18 19:15:34 +03:00
return 0 ;
}
2023-10-16 08:21:44 +03:00
2024-05-13 07:55:06 +03:00
late_initcall ( fips_signature_selftest_init ) ;
2023-10-16 08:21:44 +03:00
MODULE_DESCRIPTION ( " X.509 self tests " ) ;
MODULE_AUTHOR ( " Red Hat, Inc. " ) ;
MODULE_LICENSE ( " GPL " ) ;