REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3455 Enforce salt length to be equal to digest length for RSA-PSS encoding scheme. Cc: Jiewen Yao <jiewen.yao@intel.com> Cc: Jian J Wang <jian.j.wang@intel.com> Cc: Xiaoyu Lu <xiaoyux.lu@intel.com> Cc: Guomin Jiang <guomin.jiang@intel.com> Signed-off-by: Sachin Agrawal <sachin.agrawal@intel.com> Reviewed-by: Jiewen Yao <Jiewen.yao@intel.com>
		
			
				
	
	
		
			61 lines
		
	
	
		
			2.3 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
			
		
		
	
	
			61 lines
		
	
	
		
			2.3 KiB
		
	
	
	
		
			C
		
	
	
	
	
	
| /** @file
 | |
|   RSA-PSS Asymmetric Cipher Wrapper Implementation over OpenSSL.
 | |
| 
 | |
|   This file does not provide real capabilities for following APIs in RSA handling:
 | |
|   1) RsaPssSign
 | |
| 
 | |
| Copyright (c) 2021, Intel Corporation. All rights reserved.<BR>
 | |
| SPDX-License-Identifier: BSD-2-Clause-Patent
 | |
| 
 | |
| **/
 | |
| 
 | |
| #include "InternalCryptLib.h"
 | |
| 
 | |
| /**
 | |
|   Carries out the RSA-SSA signature generation with EMSA-PSS encoding scheme.
 | |
| 
 | |
|   This function carries out the RSA-SSA signature generation with EMSA-PSS encoding scheme defined in
 | |
|   RFC 8017.
 | |
|   Mask generation function is the same as the message digest algorithm.
 | |
|   If the Signature buffer is too small to hold the contents of signature, FALSE
 | |
|   is returned and SigSize is set to the required buffer size to obtain the signature.
 | |
| 
 | |
|   If RsaContext is NULL, then return FALSE.
 | |
|   If Message is NULL, then return FALSE.
 | |
|   If MsgSize is zero or > INT_MAX, then return FALSE.
 | |
|   If DigestLen is NOT 32, 48 or 64, return FALSE.
 | |
|   If SaltLen is not equal to DigestLen, then return FALSE.
 | |
|   If SigSize is large enough but Signature is NULL, then return FALSE.
 | |
|   If this interface is not supported, then return FALSE.
 | |
| 
 | |
|   @param[in]      RsaContext   Pointer to RSA context for signature generation.
 | |
|   @param[in]      Message      Pointer to octet message to be signed.
 | |
|   @param[in]      MsgSize      Size of the message in bytes.
 | |
|   @param[in]      DigestLen    Length of the digest in bytes to be used for RSA signature operation.
 | |
|   @param[in]      SaltLen      Length of the salt in bytes to be used for PSS encoding.
 | |
|   @param[out]     Signature    Pointer to buffer to receive RSA PSS signature.
 | |
|   @param[in, out] SigSize      On input, the size of Signature buffer in bytes.
 | |
|                                On output, the size of data returned in Signature buffer in bytes.
 | |
| 
 | |
|   @retval  TRUE   Signature successfully generated in RSASSA-PSS.
 | |
|   @retval  FALSE  Signature generation failed.
 | |
|   @retval  FALSE  SigSize is too small.
 | |
|   @retval  FALSE  This interface is not supported.
 | |
| 
 | |
| **/
 | |
| BOOLEAN
 | |
| EFIAPI
 | |
| RsaPssSign (
 | |
|   IN      VOID         *RsaContext,
 | |
|   IN      CONST UINT8  *Message,
 | |
|   IN      UINTN        MsgSize,
 | |
|   IN      UINT16       DigestLen,
 | |
|   IN      UINT16       SaltLen,
 | |
|   OUT     UINT8        *Signature,
 | |
|   IN OUT  UINTN        *SigSize
 | |
|   )
 | |
| {
 | |
|   ASSERT (FALSE);
 | |
|   return FALSE;
 | |
| }
 |