Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1308441
| From | Tadeusz Struk <tadeusz.struk@intel.com> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH v2] crypto: AF_ALG - add support for keys/asymmetric-type |
| Date | 2016-01-13 15:10 +0100 |
| Message-ID | <qQuhB-Oj-37@gated-at.bofh.it> (permalink) |
| References | <qJZqa-2N6-31@gated-at.bofh.it> <qQtOy-mT-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hi David,
On 01/13/2016 05:31 AM, David Howells wrote:
>> > + pkey = keyring->payload.data[asym_crypto];
>> > + if (!pkey) {
>> > + key_put(keyring);
>> > + goto out;
>> > + }
>> > +
>> > + err = setkey(private, pkey->key, pkey->keylen);
>> > + key_put(keyring);
> Note that you may not assume that there's data there that you can use in this
> manner. The key might be a pointer to some hardware device such as a TPM. I
> have a TPM asymmetric subtype in progress.
So is there anything in place that can be used to tell what the key actually is?
The security/integrity/digsig_asymmetric.c is using this api in a similar way, so
if it is incorrect digsig_asymmetric shouldn't work neither.
>
> I think this really needs to be driven from a keyctl() because you need to let
> the asymmetric subtype decide how it wants to handle this. I would suggest
> adding KEYCTL_{ASYM_GETINFO,SIGN,VERIFY,ENCRYPT,DECRYPT} - the problem is how
> to pass sufficient arguments, how to decrypt the private key and what metadata
> needs to be passed vs what is inline with the data.
I agree, ideally keyctl should do the job for all the cases and request_key()
should just return a key data.
Thanks,
--
TS
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: [PATCH v2] crypto: AF_ALG - add support for keys/asymmetric-type David Howells <dhowells@redhat.com> - 2016-01-13 14:40 +0100
Re: [PATCH v2] crypto: AF_ALG - add support for keys/asymmetric-type Tadeusz Struk <tadeusz.struk@intel.com> - 2016-01-13 15:10 +0100
Re: [PATCH v2] crypto: AF_ALG - add support for keys/asymmetric-type David Woodhouse <dwmw2@infradead.org> - 2016-01-13 16:10 +0100
Re: [PATCH v2] crypto: AF_ALG - add support for keys/asymmetric-type Tadeusz Struk <tadeusz.struk@intel.com> - 2016-01-13 17:20 +0100
csiph-web