Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1200771
| From | David Howells <dhowells@redhat.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 19/27] X.509: Change recorded SKID & AKID to not include Subject or Issuer [ver #7] |
| Date | 2015-08-05 15:50 +0200 |
| Message-ID | <pU7eY-2WR-45@gated-at.bofh.it> (permalink) |
| References | <pU7eV-2WR-7@gated-at.bofh.it> |
| Organization | Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903 |
The key identifiers fabricated from an X.509 certificate are currently:
(A) Concatenation of serial number and issuer
(B) Concatenation of subject and subjectKeyID (SKID)
When verifying one X.509 certificate with another, the AKID in the target
can be used to match the authoritative certificate. The AKID can specify
the match in one or both of two ways:
(1) Compare authorityCertSerialNumber and authorityCertIssuer from the AKID
to identifier (A) above.
(2) Compare keyIdentifier from the AKID plus the issuer from the target
certificate to identifier (B) above.
When verifying a PKCS#7 message, the only available comparison is between
the IssuerAndSerialNumber field and identifier (A) above.
However, a subsequent patch adds CMS support. Whilst CMS still supports a
match on IssuerAndSerialNumber as for PKCS#7, it also supports an
alternative - which is the SubjectKeyIdentifier field. This is used to
match to an X.509 certificate on the SKID alone. No subject information is
available to be used.
To this end change the fabrication of (B) above to be from the X.509 SKID
alone. The AKID in keyIdentifier form then only matches on that and does
not include the issuer.
Signed-off-by: David Howells <dhowells@redhat.com>
Reviewed-By: David Woodhouse <David.Woodhouse@intel.com>
---
crypto/asymmetric_keys/x509_cert_parser.c | 8 ++------
1 file changed, 2 insertions(+), 6 deletions(-)
diff --git a/crypto/asymmetric_keys/x509_cert_parser.c b/crypto/asymmetric_keys/x509_cert_parser.c
index 6c130dd56f35..849fd760923e 100644
--- a/crypto/asymmetric_keys/x509_cert_parser.c
+++ b/crypto/asymmetric_keys/x509_cert_parser.c
@@ -454,9 +454,7 @@ int x509_process_extension(void *context, size_t hdrlen,
ctx->cert->raw_skid_size = vlen;
ctx->cert->raw_skid = v;
- kid = asymmetric_key_generate_id(ctx->cert->raw_subject,
- ctx->cert->raw_subject_size,
- v, vlen);
+ kid = asymmetric_key_generate_id(v, vlen, "", 0);
if (IS_ERR(kid))
return PTR_ERR(kid);
ctx->cert->skid = kid;
@@ -553,9 +551,7 @@ int x509_akid_note_kid(void *context, size_t hdrlen,
if (ctx->cert->akid_skid)
return 0;
- kid = asymmetric_key_generate_id(ctx->cert->raw_issuer,
- ctx->cert->raw_issuer_size,
- value, vlen);
+ kid = asymmetric_key_generate_id(value, vlen, "", 0);
if (IS_ERR(kid))
return PTR_ERR(kid);
pr_debug("authkeyid %*phN\n", kid->len, kid->data);
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 00/27] MODSIGN: Use PKCS#7 for module signatures [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 10/27] MODSIGN: Extract the blob PKCS#7 signature verifier from module signing [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 22/27] extract-cert: Cope with multiple X.509 certificates in a single file [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 16/27] modsign: Use single PEM file for autogenerated key [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 21/27] sign-file: Generate CMS message as signature instead of PKCS#7 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 01/27] ASN.1: Add an ASN.1 compiler option to dump the element tree [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 18/27] PKCS#7: Check content type and versions [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 11/27] modsign: Abort modules_install when signing fails [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 04/27] X.509: Support X.509 lookup by Issuer+Serial form AuthorityKeyIdentifier [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 19/27] X.509: Change recorded SKID & AKID to not include Subject or Issuer [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 26/27] KEYS: Add a name for PKEY_ID_PKCS7 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 06/27] MODSIGN: Provide a utility to append a PKCS#7 signature to a module [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 24/27] PKCS#7: Improve and export the X.509 ASN.1 time object decoder [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 08/27] sign-file: Add option to only create signature file [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 14/27] modsign: Allow external signing key to be specified [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 17/27] modsign: Add explicit CONFIG_SYSTEM_TRUSTED_KEYS option [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 23/27] modsign: Use extract-cert to process CONFIG_SYSTEM_TRUSTED_KEYS [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 05/27] PKCS#7: Allow detached data to be supplied for signature checking purposes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 15/27] modsign: Extract signing cert from CONFIG_MODULE_SIG_KEY if needed [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 07/27] MODSIGN: Use PKCS#7 messages as module signatures [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 27/27] PKCS#7: Restrict content type and authenticated attributes by purpose [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] Mimi Zohar <zohar@linux.vnet.ibm.com> - 2015-08-05 20:20 +0200
Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 20:30 +0200
Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] Mimi Zohar <zohar@linux.vnet.ibm.com> - 2015-08-05 21:00 +0200
[PATCH 25/27] PKCS#7: Appropriately require or forbid authenticated attributes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
Re: [PATCH 25/27] PKCS#7: Appropriately require or forbid authenticated attributes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:30 +0200
[PATCH 20/27] PKCS#7: Support CMS messages also [RFC5652] [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
[PATCH 13/27] modsign: Allow signing key to be PKCS#11 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
[PATCH 09/27] system_keyring.c doesn't need to #include module-internal.h [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
[PATCH 03/27] X.509: Extract both parts of the AuthorityKeyIdentifier [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
[PATCH 12/27] modsign: Allow password to be specified for signing key [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
csiph-web