mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
pvimg info: Add '--show-secrets' flag
Add '--show-secrets' flag to 'pvimg info' to make secret output explicit and avoid accidental disclosure. Reviewed-by: Steffen Eiden <seiden@linux.ibm.com> Signed-off-by: Marc Hartmayer <marc@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
This commit is contained in:
committed by
Jan Höppner
parent
ad4075804f
commit
8d40b5c97a
@@ -365,12 +365,32 @@ pub struct InfoArgs {
|
||||
#[arg(long, value_parser=OutputFormatSpecParser::default())]
|
||||
pub format: Option<OutputFormatSpec>,
|
||||
|
||||
/// Use the key in FILE to decrypt the Secure Execution header.
|
||||
/// Use the key in FILE to verify the Secure Execution header and optionally
|
||||
/// use '--show-secrets' to decrypt it.
|
||||
///
|
||||
/// It is the key that was specified with the command line option
|
||||
/// '--hdr-key' at the Secure Execution image creation.
|
||||
#[arg(long, value_name = "FILE", value_hint = ValueHint::FilePath, alias = "key")]
|
||||
/// The key must be the same key that was specified with '--hdr-key' when the
|
||||
/// Secure Execution image was created. The key is used to:
|
||||
/// 1. Verify the integrity and authenticity of the header
|
||||
/// 2. Optionally decrypt secrets with '--show-secrets'
|
||||
///
|
||||
/// Without this option, the information is displayed, but NOT verified, and
|
||||
/// a warning is printed. The displayed data should not be trusted without
|
||||
/// verification.
|
||||
#[arg(long, value_name = "FILE", value_hint = ValueHint::FilePath, alias = "key", verbatim_doc_comment)]
|
||||
pub hdr_key: Option<PathBuf>,
|
||||
|
||||
/// This option reveals sensitive information that is normally encrypted in
|
||||
/// the header, such as:
|
||||
/// - Customer communication key (CCK)
|
||||
/// - Image encryption key
|
||||
/// - Other confidential data
|
||||
///
|
||||
/// SECURITY WARNING: Only use this option in secure, trusted environments.
|
||||
/// The decrypted secrets should never be exposed in untrusted systems.
|
||||
///
|
||||
/// This option requires '--hdr-key' to decrypt the header.
|
||||
#[arg(long, requires = "hdr_key", verbatim_doc_comment)]
|
||||
pub show_secrets: bool,
|
||||
}
|
||||
|
||||
#[derive(Args, Debug)]
|
||||
|
||||
@@ -38,9 +38,16 @@ pub fn info(opt: &InfoArgs) -> Result<OwnExitCode> {
|
||||
let decrypted_hdr = hdr
|
||||
.decrypt(&key)
|
||||
.context("Failed to authenticate and decrypt the Secure Execution header")?;
|
||||
SeH::DecryptedSeHdr {
|
||||
se_hdr: decrypted_hdr,
|
||||
verified: true,
|
||||
if opt.show_secrets {
|
||||
SeH::DecryptedSeHdr {
|
||||
se_hdr: decrypted_hdr,
|
||||
verified: true,
|
||||
}
|
||||
} else {
|
||||
SeH::SeHdr {
|
||||
se_hdr: hdr,
|
||||
verified: true,
|
||||
}
|
||||
}
|
||||
} else {
|
||||
warn!("WARNING: The Secure Execution header integrity and authenticity was not verified. Specify '--hdr-key' to authenticate it. Do not trust the data without verification.");
|
||||
|
||||
Reference in New Issue
Block a user