Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1200771

[PATCH 19/27] X.509: Change recorded SKID & AKID to not include Subject or Issuer [ver #7]

From David Howells <dhowells@redhat.com>
Newsgroups linux.kernel
Subject [PATCH 19/27] X.509: Change recorded SKID & AKID to not include Subject or Issuer [ver #7]
Date 2015-08-05 15:50 +0200
Message-ID <pU7eY-2WR-45@gated-at.bofh.it> (permalink)
References <pU7eV-2WR-7@gated-at.bofh.it>
Organization Red Hat UK Ltd. Registered Address: Red Hat UK Ltd, Amberley Place, 107-111 Peascod Street, Windsor, Berkshire, SI4 1TE, United Kingdom. Registered in England and Wales under Company Registration No. 3798903

Show all headers | View raw


The key identifiers fabricated from an X.509 certificate are currently:

 (A) Concatenation of serial number and issuer

 (B) Concatenation of subject and subjectKeyID (SKID)

When verifying one X.509 certificate with another, the AKID in the target
can be used to match the authoritative certificate.  The AKID can specify
the match in one or both of two ways:

 (1) Compare authorityCertSerialNumber and authorityCertIssuer from the AKID
     to identifier (A) above.

 (2) Compare keyIdentifier from the AKID plus the issuer from the target
     certificate to identifier (B) above.

When verifying a PKCS#7 message, the only available comparison is between
the IssuerAndSerialNumber field and identifier (A) above.

However, a subsequent patch adds CMS support.  Whilst CMS still supports a
match on IssuerAndSerialNumber as for PKCS#7, it also supports an
alternative - which is the SubjectKeyIdentifier field.  This is used to
match to an X.509 certificate on the SKID alone.  No subject information is
available to be used.

To this end change the fabrication of (B) above to be from the X.509 SKID
alone.  The AKID in keyIdentifier form then only matches on that and does
not include the issuer.

Signed-off-by: David Howells <dhowells@redhat.com>
Reviewed-By: David Woodhouse <David.Woodhouse@intel.com>
---

 crypto/asymmetric_keys/x509_cert_parser.c |    8 ++------
 1 file changed, 2 insertions(+), 6 deletions(-)

diff --git a/crypto/asymmetric_keys/x509_cert_parser.c b/crypto/asymmetric_keys/x509_cert_parser.c
index 6c130dd56f35..849fd760923e 100644
--- a/crypto/asymmetric_keys/x509_cert_parser.c
+++ b/crypto/asymmetric_keys/x509_cert_parser.c
@@ -454,9 +454,7 @@ int x509_process_extension(void *context, size_t hdrlen,
 
 		ctx->cert->raw_skid_size = vlen;
 		ctx->cert->raw_skid = v;
-		kid = asymmetric_key_generate_id(ctx->cert->raw_subject,
-						 ctx->cert->raw_subject_size,
-						 v, vlen);
+		kid = asymmetric_key_generate_id(v, vlen, "", 0);
 		if (IS_ERR(kid))
 			return PTR_ERR(kid);
 		ctx->cert->skid = kid;
@@ -553,9 +551,7 @@ int x509_akid_note_kid(void *context, size_t hdrlen,
 	if (ctx->cert->akid_skid)
 		return 0;
 
-	kid = asymmetric_key_generate_id(ctx->cert->raw_issuer,
-					 ctx->cert->raw_issuer_size,
-					 value, vlen);
+	kid = asymmetric_key_generate_id(value, vlen, "", 0);
 	if (IS_ERR(kid))
 		return PTR_ERR(kid);
 	pr_debug("authkeyid %*phN\n", kid->len, kid->data);

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 00/27] MODSIGN: Use PKCS#7 for module signatures [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 10/27] MODSIGN: Extract the blob PKCS#7 signature verifier  from module signing [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 22/27] extract-cert: Cope with multiple X.509 certificates  in a single file [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 16/27] modsign: Use single PEM file for autogenerated key  [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 21/27] sign-file: Generate CMS message as signature instead  of PKCS#7 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 01/27] ASN.1: Add an ASN.1 compiler option to dump the  element tree [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 18/27] PKCS#7: Check content type and versions [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 11/27] modsign: Abort modules_install when signing fails  [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 04/27] X.509: Support X.509 lookup by Issuer+Serial form  AuthorityKeyIdentifier [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 19/27] X.509: Change recorded SKID & AKID to not include  Subject or Issuer [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 26/27] KEYS: Add a name for PKEY_ID_PKCS7 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 06/27] MODSIGN: Provide a utility to append a PKCS#7  signature to a module [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 24/27] PKCS#7: Improve and export the X.509 ASN.1 time  object decoder [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 08/27] sign-file: Add option to only create signature file  [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 14/27] modsign: Allow external signing key to be specified  [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 17/27] modsign: Add explicit CONFIG_SYSTEM_TRUSTED_KEYS  option [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 23/27] modsign: Use extract-cert to process  CONFIG_SYSTEM_TRUSTED_KEYS [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 05/27] PKCS#7: Allow detached data to be supplied for  signature checking purposes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 15/27] modsign: Extract signing cert from  CONFIG_MODULE_SIG_KEY if needed [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 07/27] MODSIGN: Use PKCS#7 messages as module signatures  [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 27/27] PKCS#7: Restrict content type and authenticated  attributes by purpose [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler  [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
    Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1  compiler [ver #7] Mimi Zohar <zohar@linux.vnet.ibm.com> - 2015-08-05 20:20 +0200
      Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1 compiler [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 20:30 +0200
        Re: [PATCH 02/27] ASN.1: Copy string names to tokens in ASN.1  compiler [ver #7] Mimi Zohar <zohar@linux.vnet.ibm.com> - 2015-08-05 21:00 +0200
  [PATCH 25/27] PKCS#7: Appropriately require or forbid authenticated  attributes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
    Re: [PATCH 25/27] PKCS#7: Appropriately require or forbid authenticated attributes [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:30 +0200
  [PATCH 20/27] PKCS#7: Support CMS messages also [RFC5652] [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 15:50 +0200
  [PATCH 13/27] modsign: Allow signing key to be PKCS#11 [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
  [PATCH 09/27] system_keyring.c doesn't need to #include  module-internal.h [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
  [PATCH 03/27] X.509: Extract both parts of the  AuthorityKeyIdentifier [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200
  [PATCH 12/27] modsign: Allow password to be specified for signing  key [ver #7] David Howells <dhowells@redhat.com> - 2015-08-05 16:00 +0200

csiph-web