Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1200758
| From | David Howells <dhowells@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 10/27] MODSIGN: Extract the blob PKCS#7 signature verifier from module signing [ver #7] |
| Date | 2015-08-05 15:50 +0200 |
| Message-ID | <pU7eW-2WR-15@gated-at.bofh.it> (permalink) |
| References | <pU7eV-2WR-7@gated-at.bofh.it> |
| Organization | Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903 |
Extract the function that drives the PKCS#7 signature verification given a
data blob and a PKCS#7 blob out from the module signing code and lump it with
the system keyring code as it's generic. This makes it independent of module
config options and opens it to use by the firmware loader.
Signed-off-by: David Howells <dhowells@redhat.com>
Cc: Luis R. Rodriguez <mcgrof@suse.com>
Cc: Rusty Russell <rusty@rustcorp.com.au>
Cc: Ming Lei <ming.lei@canonical.com>
Cc: Seth Forshee <seth.forshee@canonical.com>
Cc: Kyle McMartin <kyle@kernel.org>
---
include/keys/system_keyring.h | 5 ++++
init/Kconfig | 29 ++++++++++++++++--------
kernel/module_signing.c | 44 +-----------------------------------
kernel/system_keyring.c | 50 +++++++++++++++++++++++++++++++++++++++++
4 files changed, 75 insertions(+), 53 deletions(-)
diff --git a/include/keys/system_keyring.h b/include/keys/system_keyring.h
index 72665eb80692..9791c907cdb7 100644
--- a/include/keys/system_keyring.h
+++ b/include/keys/system_keyring.h
@@ -28,4 +28,9 @@ static inline struct key *get_system_trusted_keyring(void)
}
#endif
+#ifdef CONFIG_SYSTEM_DATA_VERIFICATION
+extern int system_verify_data(const void *data, unsigned long len,
+ const void *raw_pkcs7, size_t pkcs7_len);
+#endif
+
#endif /* _KEYS_SYSTEM_KEYRING_H */
diff --git a/init/Kconfig b/init/Kconfig
index e16d9e587cee..14b3d8422502 100644
--- a/init/Kconfig
+++ b/init/Kconfig
@@ -1752,6 +1752,24 @@ config SYSTEM_TRUSTED_KEYRING
Keys in this keyring are used by module signature checking.
+config SYSTEM_DATA_VERIFICATION
+ def_bool n
+ select SYSTEM_TRUSTED_KEYRING
+ select KEYS
+ select CRYPTO
+ select ASYMMETRIC_KEY_TYPE
+ select ASYMMETRIC_PUBLIC_KEY_SUBTYPE
+ select PUBLIC_KEY_ALGO_RSA
+ select ASN1
+ select OID_REGISTRY
+ select X509_CERTIFICATE_PARSER
+ select PKCS7_MESSAGE_PARSER
+ help
+ Provide PKCS#7 message verification using the contents of the system
+ trusted keyring to provide public keys. This then can be used for
+ module verification, kexec image verification and firmware blob
+ verification.
+
config PROFILING
bool "Profiling support"
help
@@ -1860,16 +1878,7 @@ config MODULE_SRCVERSION_ALL
config MODULE_SIG
bool "Module signature verification"
depends on MODULES
- select SYSTEM_TRUSTED_KEYRING
- select KEYS
- select CRYPTO
- select ASYMMETRIC_KEY_TYPE
- select ASYMMETRIC_PUBLIC_KEY_SUBTYPE
- select PUBLIC_KEY_ALGO_RSA
- select ASN1
- select OID_REGISTRY
- select X509_CERTIFICATE_PARSER
- select PKCS7_MESSAGE_PARSER
+ select SYSTEM_DATA_VERIFICATION
help
Check modules for valid signatures upon load: the signature
is simply appended to the module. For more information see
diff --git a/kernel/module_signing.c b/kernel/module_signing.c
index 8eb20cc66b39..70ad463f6df0 100644
--- a/kernel/module_signing.c
+++ b/kernel/module_signing.c
@@ -10,10 +10,8 @@
*/
#include <linux/kernel.h>
-#include <linux/err.h>
#include <keys/system_keyring.h>
#include <crypto/public_key.h>
-#include <crypto/pkcs7.h>
#include "module-internal.h"
/*
@@ -37,46 +35,6 @@ struct module_signature {
};
/*
- * Verify a PKCS#7-based signature on a module.
- */
-static int mod_verify_pkcs7(const void *mod, unsigned long modlen,
- const void *raw_pkcs7, size_t pkcs7_len)
-{
- struct pkcs7_message *pkcs7;
- bool trusted;
- int ret;
-
- pkcs7 = pkcs7_parse_message(raw_pkcs7, pkcs7_len);
- if (IS_ERR(pkcs7))
- return PTR_ERR(pkcs7);
-
- /* The data should be detached - so we need to supply it. */
- if (pkcs7_supply_detached_data(pkcs7, mod, modlen) < 0) {
- pr_err("PKCS#7 signature with non-detached data\n");
- ret = -EBADMSG;
- goto error;
- }
-
- ret = pkcs7_verify(pkcs7);
- if (ret < 0)
- goto error;
-
- ret = pkcs7_validate_trust(pkcs7, system_trusted_keyring, &trusted);
- if (ret < 0)
- goto error;
-
- if (!trusted) {
- pr_err("PKCS#7 signature not signed with a trusted key\n");
- ret = -ENOKEY;
- }
-
-error:
- pkcs7_free_message(pkcs7);
- pr_devel("<==%s() = %d\n", __func__, ret);
- return ret;
-}
-
-/*
* Verify the signature on a module.
*/
int mod_verify_sig(const void *mod, unsigned long *_modlen)
@@ -114,5 +72,5 @@ int mod_verify_sig(const void *mod, unsigned long *_modlen)
return -EBADMSG;
}
- return mod_verify_pkcs7(mod, modlen, mod + modlen, sig_len);
+ return system_verify_data(mod, modlen, mod + modlen, sig_len);
}
diff --git a/kernel/system_keyring.c b/kernel/system_keyring.c
index 4cda71ee51c7..95f2dcbc7616 100644
--- a/kernel/system_keyring.c
+++ b/kernel/system_keyring.c
@@ -16,6 +16,7 @@
#include <linux/err.h>
#include <keys/asymmetric-type.h>
#include <keys/system_keyring.h>
+#include <crypto/pkcs7.h>
struct key *system_trusted_keyring;
EXPORT_SYMBOL_GPL(system_trusted_keyring);
@@ -103,3 +104,52 @@ dodgy_cert:
return 0;
}
late_initcall(load_system_certificate_list);
+
+#ifdef CONFIG_SYSTEM_DATA_VERIFICATION
+
+/**
+ * Verify a PKCS#7-based signature on system data.
+ * @data: The data to be verified.
+ * @len: Size of @data.
+ * @raw_pkcs7: The PKCS#7 message that is the signature.
+ * @pkcs7_len: The size of @raw_pkcs7.
+ */
+int system_verify_data(const void *data, unsigned long len,
+ const void *raw_pkcs7, size_t pkcs7_len)
+{
+ struct pkcs7_message *pkcs7;
+ bool trusted;
+ int ret;
+
+ pkcs7 = pkcs7_parse_message(raw_pkcs7, pkcs7_len);
+ if (IS_ERR(pkcs7))
+ return PTR_ERR(pkcs7);
+
+ /* The data should be detached - so we need to supply it. */
+ if (pkcs7_supply_detached_data(pkcs7, data, len) < 0) {
+ pr_err("PKCS#7 signature with non-detached data\n");
+ ret = -EBADMSG;
+ goto error;
+ }
+
+ ret = pkcs7_verify(pkcs7);
+ if (ret < 0)
+ goto error;
+
+ ret = pkcs7_validate_trust(pkcs7, system_trusted_keyring, &trusted);
+ if (ret < 0)
+ goto error;
+
+ if (!trusted) {
+ pr_err("PKCS#7 signature not signed with a trusted key\n");
+ ret = -ENOKEY;
+ }
+
+error:
+ pkcs7_free_message(pkcs7);
+ pr_devel("<==%s() = %d\n", __func__, ret);
+ return ret;
+}
+EXPORT_SYMBOL_GPL(system_verify_data);
+
+#endif /* CONFIG_SYSTEM_DATA_VERIFICATION */
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 00/27] MODSIGN: Use PKCS#7 for module signatures [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 10/27] MODSIGN: Extract the blob PKCS#7 signature verifier from module signing [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 22/27] extract-cert: Cope with multiple X.509 certificates in a single file [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 16/27] modsign: Use single PEM file for autogenerated key [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 21/27] sign-file: Generate CMS message as signature instead of PKCS#7 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 01/27] ASN.1: Add an ASN.1 compiler option to dump the element tree [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 18/27] PKCS#7: Check content type and versions [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 11/27] modsign: Abort modules_install when signing fails [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 04/27] X.509: Support X.509 lookup by Issuer+Serial form AuthorityKeyIdentifier [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 19/27] X.509: Change recorded SKID & AKID to not include Subject or Issuer [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 26/27] KEYS: Add a name for PKEY_ID_PKCS7 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 06/27] MODSIGN: Provide a utility to append a PKCS#7 signature to a module [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 24/27] PKCS#7: Improve and export the X.509 ASN.1 time object decoder [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 08/27] sign-file: Add option to only create signature file [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 14/27] modsign: Allow external signing key to be specified [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 17/27] modsign: Add explicit CONFIG_SYSTEM_TRUSTED_KEYS option [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 23/27] modsign: Use extract-cert to process CONFIG_SYSTEM_TRUSTED_KEYS [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 05/27] PKCS#7: Allow detached data to be supplied for signature checking purposes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 15/27] modsign: Extract signing cert from CONFIG_MODULE_SIG_KEY if needed [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 07/27] MODSIGN: Use PKCS#7 messages as module signatures [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 27/27] PKCS#7: Restrict content type and authenticated attributes by purpose [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] Mimi Zohar <zohar@linux.vnet.ibm.com> - 2015-08-05 20:20 +0200
Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 20:30 +0200
Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] Mimi Zohar <zohar@linux.vnet.ibm.com> - 2015-08-05 21:00 +0200
[PATCH 25/27] PKCS#7: Appropriately require or forbid authenticated attributes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
Re: [PATCH 25/27] PKCS#7: Appropriately require or forbid authenticated attributes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:30 +0200
[PATCH 20/27] PKCS#7: Support CMS messages also [RFC5652] [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 13/27] modsign: Allow signing key to be PKCS#11 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
[PATCH 09/27] system_keyring.c doesn't need to #include module-internal.h [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
[PATCH 03/27] X.509: Extract both parts of the AuthorityKeyIdentifier [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
[PATCH 12/27] modsign: Allow password to be specified for signing key [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
csiph-web