diff options
| author | Michael Brown | 2025-12-11 16:02:28 +0100 |
|---|---|---|
| committer | Michael Brown | 2025-12-11 16:09:58 +0100 |
| commit | fb1188936ca29af61709afd8b866ea55d4a05a67 (patch) | |
| tree | 5f319cca897d210a2e087ca8337633351726b414 /src/crypto | |
| parent | [crypto] Allow for addition of arbitrary Weierstrass curve points (diff) | |
| download | ipxe-fb1188936ca29af61709afd8b866ea55d4a05a67.tar.gz ipxe-fb1188936ca29af61709afd8b866ea55d4a05a67.tar.xz ipxe-fb1188936ca29af61709afd8b866ea55d4a05a67.zip | |
[crypto] Generalise rsa_parse_integer() to asn1_enter_unsigned()
ECDSA signature values and private keys are fixed-length unsigned
integers modulo N (the group order of the elliptic curve) and are
therefore most naturally represented in ASN.1 using ASN1_OCTET_STRING.
Private key representations do use ASN1_OCTET_STRING, but signature
values tend to use ASN1_INTEGER, which adds no value but does ensure
that the encoding becomes variable-length and requires handling a
pointless extra zero byte if the MSB of the unsigned value happens to
be set.
RSA also makes use of ASN1_INTEGER for modulus and exponent values.
Generalise the existing rsa_parse_integer() to asn1_enter_unsigned()
to allow this code to be reused for ECDSA.
Signed-off-by: Michael Brown <mcb30@ipxe.org>
Diffstat (limited to 'src/crypto')
| -rw-r--r-- | src/crypto/asn1.c | 23 | ||||
| -rw-r--r-- | src/crypto/rsa.c | 34 |
2 files changed, 27 insertions, 30 deletions
diff --git a/src/crypto/asn1.c b/src/crypto/asn1.c index 4ee95415f..819a8aadb 100644 --- a/src/crypto/asn1.c +++ b/src/crypto/asn1.c @@ -373,6 +373,29 @@ int asn1_enter_bits ( struct asn1_cursor *cursor, unsigned int *unused ) { } /** + * Enter ASN.1 unsigned integer + * + * @v cursor ASN.1 object cursor + * @ret rc Return status code + */ +int asn1_enter_unsigned ( struct asn1_cursor *cursor ) { + int rc; + + /* Enter integer */ + if ( ( rc = asn1_enter ( cursor, ASN1_INTEGER ) ) != 0 ) + return rc; + + /* Skip initial positive sign byte if applicable */ + if ( ( cursor->len > 1 ) && + ( *( ( uint8_t * ) cursor->data ) == 0x00 ) ) { + cursor->data++; + cursor->len--; + } + + return 0; +} + +/** * Parse value of ASN.1 boolean * * @v cursor ASN.1 object cursor diff --git a/src/crypto/rsa.c b/src/crypto/rsa.c index 14456f755..9c0982cf6 100644 --- a/src/crypto/rsa.c +++ b/src/crypto/rsa.c @@ -138,34 +138,6 @@ static int rsa_alloc ( struct rsa_context *context, size_t modulus_len, } /** - * Parse RSA integer - * - * @v integer Integer to fill in - * @v raw ASN.1 cursor - * @ret rc Return status code - */ -static int rsa_parse_integer ( struct asn1_cursor *integer, - const struct asn1_cursor *raw ) { - - /* Enter integer */ - memcpy ( integer, raw, sizeof ( *integer ) ); - asn1_enter ( integer, ASN1_INTEGER ); - - /* Skip initial sign byte if applicable */ - if ( ( integer->len > 1 ) && - ( *( ( uint8_t * ) integer->data ) == 0x00 ) ) { - integer->data++; - integer->len--; - } - - /* Fail if cursor or integer are invalid */ - if ( ! integer->len ) - return -EINVAL; - - return 0; -} - -/** * Parse RSA modulus and exponent * * @v modulus Modulus to fill in @@ -226,7 +198,8 @@ static int rsa_parse_mod_exp ( struct asn1_cursor *modulus, } /* Extract modulus */ - if ( ( rc = rsa_parse_integer ( modulus, &cursor ) ) != 0 ) + memcpy ( modulus, &cursor, sizeof ( *modulus ) ); + if ( ( rc = asn1_enter_unsigned ( modulus ) ) != 0 ) return rc; asn1_skip_any ( &cursor ); @@ -235,7 +208,8 @@ static int rsa_parse_mod_exp ( struct asn1_cursor *modulus, asn1_skip ( &cursor, ASN1_INTEGER ); /* Extract publicExponent/privateExponent */ - if ( ( rc = rsa_parse_integer ( exponent, &cursor ) ) != 0 ) + memcpy ( exponent, &cursor, sizeof ( *exponent ) ); + if ( ( rc = asn1_enter_unsigned ( exponent ) ) != 0 ) return rc; return 0; |
