mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
zkey: Add PVSECRET-HMAC key type and general HMAC support
Add the definitions and utility functions for the PVSECRET-HMAC key type. A PVSECRET-HMAC key token contains the secret id of a protected virtualization secret. It does not contain the key material, just a reference to the key in the ultravisor. When such a key token is used to perform HMAC operations later on, the PHMAC kernel cipher will obtain the protected key belonging to this secret id with the help of the pkey kernel module. Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com> Reviewed-by: Finn Callies <fcallies@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
This commit is contained in:
committed by
Jan Höppner
parent
c3d8208a57
commit
a9059449b9
+37
-4
@@ -357,6 +357,8 @@ static int _keystore_valid_key_type(const char *key_type)
|
||||
return 1;
|
||||
if (strcasecmp(key_type, KEY_TYPE_PVSECRET_AES) == 0)
|
||||
return 1;
|
||||
if (strcasecmp(key_type, KEY_TYPE_PVSECRET_HMAC) == 0)
|
||||
return 1;
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -1588,12 +1590,12 @@ static int _keystore_set_timestamp_property(struct properties *properties,
|
||||
}
|
||||
|
||||
/**
|
||||
* Sets the default properties of a key, such as key-type, cipher-name, and
|
||||
* IV-mode
|
||||
* Sets the default properties of an AES key, such as cipher-name, IV-mode,
|
||||
* and timestamps
|
||||
*
|
||||
* @param[in] key_props the properties object
|
||||
*/
|
||||
static int _keystore_set_default_properties(struct properties *key_props)
|
||||
static int _keystore_set_default_aes_properties(struct properties *key_props)
|
||||
{
|
||||
int rc;
|
||||
|
||||
@@ -1613,6 +1615,32 @@ static int _keystore_set_default_properties(struct properties *key_props)
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* Sets the default properties of an HMAC key, such as cipher-name and
|
||||
* timestmmps
|
||||
*
|
||||
* @param[in] key_props the properties object
|
||||
*/
|
||||
static int _keystore_set_default_hmac_properties(struct properties *key_props)
|
||||
{
|
||||
int rc;
|
||||
|
||||
rc = properties_set(key_props, PROP_NAME_CIPHER, "phmac");
|
||||
if (rc != 0)
|
||||
return rc;
|
||||
|
||||
rc = properties_set(key_props, PROP_NAME_DIGEST, "sha");
|
||||
if (rc != 0)
|
||||
return rc;
|
||||
|
||||
rc = _keystore_set_timestamp_property(key_props,
|
||||
PROP_NAME_CREATION_TIME);
|
||||
if (rc != 0)
|
||||
return rc;
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* Generate, Set or remove a dummy LUKS2 passphrase of a key.
|
||||
*
|
||||
@@ -1785,7 +1813,12 @@ static int _keystore_create_info_props(struct keystore *keystore,
|
||||
*props = NULL;
|
||||
|
||||
key_props = properties_new();
|
||||
rc = _keystore_set_default_properties(key_props);
|
||||
if (is_aes_key_type(key_type))
|
||||
rc = _keystore_set_default_aes_properties(key_props);
|
||||
else if (is_hmac_key_type(key_type))
|
||||
rc = _keystore_set_default_hmac_properties(key_props);
|
||||
else
|
||||
rc = -EINVAL;
|
||||
if (rc != 0)
|
||||
goto out;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user