zkey: Reject re-enciphering of PVSECRET-AES keys

Keys of type PVSECRET-AES can not be reenciphered using 'zkey reencipher'
or 'zkey-cryptsetup reencipher'. Reject that with a proper error message.

Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com>
Reviewed-by: Jorg Schmidbauer <jschmidb@de.ibm.com>
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
This commit is contained in:
Ingo Franzki
2024-02-19 11:26:41 +01:00
committed by Steffen Eiden
parent 5276d408fd
commit a8eb2bd4e7
5 changed files with 38 additions and 6 deletions

View File

@@ -3567,6 +3567,15 @@ static int _keystore_process_reencipher(struct keystore *keystore,
goto out;
}
if (!is_secure_key(secure_key, secure_key_size)) {
warnx("Key '%s' is of type %s and can not be re-enciphered, "
"skipping", name, get_key_type(secure_key,
secure_key_size));
info->num_skipped++;
rc = 0;
goto out;
}
apqns = properties_get(properties, PROP_NAME_APQNS);
if (apqns != NULL)
apqn_list = str_list_split(apqns);