Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 1 | /* Copyright (c) 2011 The Chromium OS Authors. All rights reserved. |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 2 | * Use of this source code is governed by a BSD-style license that can be |
| 3 | * found in the LICENSE file. |
| 4 | * |
| 5 | * Host functions for verified boot. |
| 6 | */ |
| 7 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 8 | #include <stdio.h> |
| 9 | |
Randall Spangler | 7c3ae42 | 2016-05-11 13:50:18 -0700 | [diff] [blame] | 10 | #include "2sysincludes.h" |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 11 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 12 | #include "2api.h" |
Randall Spangler | 7c3ae42 | 2016-05-11 13:50:18 -0700 | [diff] [blame] | 13 | #include "2common.h" |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 14 | #include "2rsa.h" |
Randall Spangler | 7c3ae42 | 2016-05-11 13:50:18 -0700 | [diff] [blame] | 15 | #include "2sha.h" |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 16 | #include "host_common.h" |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 17 | #include "host_key2.h" |
Randall Spangler | 32a6526 | 2011-06-27 10:49:11 -0700 | [diff] [blame] | 18 | #include "host_keyblock.h" |
Joel Kitching | ffd42a8 | 2019-08-29 13:58:52 +0800 | [diff] [blame] | 19 | #include "host_key.h" |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 20 | #include "vb2_common.h" |
| 21 | #include "vb2_struct.h" |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 22 | #include "vboot_common.h" |
| 23 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 24 | struct vb2_keyblock *vb2_create_keyblock( |
| 25 | const struct vb2_packed_key *data_key, |
| 26 | const struct vb2_private_key *signing_key, |
| 27 | uint32_t flags) |
| 28 | { |
Joel Kitching | d3b2117 | 2019-09-04 14:12:42 +0800 | [diff] [blame] | 29 | /* Allocate keyblock */ |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 30 | uint32_t signed_size = sizeof(struct vb2_keyblock) + data_key->key_size; |
| 31 | uint32_t sig_data_size = |
| 32 | (signing_key ? vb2_rsa_sig_size(signing_key->sig_alg) : 0); |
| 33 | uint32_t block_size = |
| 34 | signed_size + VB2_SHA512_DIGEST_SIZE + sig_data_size; |
| 35 | struct vb2_keyblock *h = (struct vb2_keyblock *)calloc(block_size, 1); |
| 36 | if (!h) |
| 37 | return NULL; |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 38 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 39 | uint8_t *data_key_dest = (uint8_t *)(h + 1); |
| 40 | uint8_t *block_chk_dest = data_key_dest + data_key->key_size; |
| 41 | uint8_t *block_sig_dest = block_chk_dest + VB2_SHA512_DIGEST_SIZE; |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 42 | |
Joel Kitching | 1ff5597 | 2019-08-30 16:02:24 +0800 | [diff] [blame] | 43 | memcpy(h->magic, VB2_KEYBLOCK_MAGIC, VB2_KEYBLOCK_MAGIC_SIZE); |
| 44 | h->header_version_major = VB2_KEYBLOCK_VERSION_MAJOR; |
| 45 | h->header_version_minor = VB2_KEYBLOCK_VERSION_MINOR; |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 46 | h->keyblock_size = block_size; |
| 47 | h->keyblock_flags = flags; |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 48 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 49 | /* Copy data key */ |
| 50 | vb2_init_packed_key(&h->data_key, data_key_dest, data_key->key_size); |
| 51 | vb2_copy_packed_key(&h->data_key, data_key); |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 52 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 53 | /* Set up signature structs so we can calculate the signatures */ |
| 54 | vb2_init_signature(&h->keyblock_hash, block_chk_dest, |
| 55 | VB2_SHA512_DIGEST_SIZE, signed_size); |
| 56 | if (signing_key) { |
| 57 | vb2_init_signature(&h->keyblock_signature, block_sig_dest, |
| 58 | sig_data_size, signed_size); |
| 59 | } else { |
| 60 | memset(&h->keyblock_signature, 0, |
| 61 | sizeof(h->keyblock_signature)); |
| 62 | } |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 63 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 64 | /* Calculate hash */ |
| 65 | struct vb2_signature *chk = |
| 66 | vb2_sha512_signature((uint8_t*)h, signed_size); |
| 67 | vb2_copy_signature(&h->keyblock_hash, chk); |
| 68 | free(chk); |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 69 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 70 | /* Calculate signature */ |
| 71 | if (signing_key) { |
| 72 | struct vb2_signature *sigtmp = |
| 73 | vb2_calculate_signature((uint8_t*)h, |
| 74 | signed_size, |
| 75 | signing_key); |
| 76 | vb2_copy_signature(&h->keyblock_signature, sigtmp); |
| 77 | free(sigtmp); |
| 78 | } |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 79 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 80 | /* Return the header */ |
| 81 | return h; |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 82 | } |
| 83 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 84 | /* TODO(gauravsh): This could easily be integrated into the function above |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 85 | * since the code is almost a mirror - I have kept it as such to avoid changing |
| 86 | * the existing interface. */ |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 87 | struct vb2_keyblock *vb2_create_keyblock_external( |
| 88 | const struct vb2_packed_key *data_key, |
Joel Kitching | 9ad8a41 | 2018-08-02 16:21:17 +0800 | [diff] [blame] | 89 | const char *signing_key_pem_file, |
| 90 | uint32_t algorithm, |
| 91 | uint32_t flags, |
| 92 | const char *external_signer) |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 93 | { |
Randall Spangler | d8a9ede | 2016-09-02 12:25:27 -0700 | [diff] [blame] | 94 | if (!signing_key_pem_file || !data_key || !external_signer) |
| 95 | return NULL; |
| 96 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 97 | uint32_t signed_size = sizeof(struct vb2_keyblock) + data_key->key_size; |
Nicolas Boichat | e0a3f85 | 2017-03-02 22:35:32 +0800 | [diff] [blame] | 98 | uint32_t sig_data_size = vb2_rsa_sig_size(vb2_crypto_to_signature(algorithm)); |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 99 | uint32_t block_size = |
| 100 | signed_size + VB2_SHA512_DIGEST_SIZE + sig_data_size; |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 101 | |
Joel Kitching | d3b2117 | 2019-09-04 14:12:42 +0800 | [diff] [blame] | 102 | /* Allocate keyblock */ |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 103 | struct vb2_keyblock *h = (struct vb2_keyblock *)calloc(block_size, 1); |
| 104 | if (!h) |
| 105 | return NULL; |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 106 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 107 | uint8_t *data_key_dest = (uint8_t *)(h + 1); |
| 108 | uint8_t *block_chk_dest = data_key_dest + data_key->key_size; |
| 109 | uint8_t *block_sig_dest = block_chk_dest + VB2_SHA512_DIGEST_SIZE; |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 110 | |
Joel Kitching | 1ff5597 | 2019-08-30 16:02:24 +0800 | [diff] [blame] | 111 | memcpy(h->magic, VB2_KEYBLOCK_MAGIC, VB2_KEYBLOCK_MAGIC_SIZE); |
| 112 | h->header_version_major = VB2_KEYBLOCK_VERSION_MAJOR; |
| 113 | h->header_version_minor = VB2_KEYBLOCK_VERSION_MINOR; |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 114 | h->keyblock_size = block_size; |
| 115 | h->keyblock_flags = flags; |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 116 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 117 | /* Copy data key */ |
| 118 | vb2_init_packed_key(&h->data_key, data_key_dest, data_key->key_size); |
| 119 | vb2_copy_packed_key(&h->data_key, data_key); |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 120 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 121 | /* Set up signature structs so we can calculate the signatures */ |
| 122 | vb2_init_signature(&h->keyblock_hash, block_chk_dest, |
| 123 | VB2_SHA512_DIGEST_SIZE, signed_size); |
| 124 | vb2_init_signature(&h->keyblock_signature, block_sig_dest, |
| 125 | sig_data_size, signed_size); |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 126 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 127 | /* Calculate checksum */ |
| 128 | struct vb2_signature *chk = |
| 129 | vb2_sha512_signature((uint8_t*)h, signed_size); |
| 130 | vb2_copy_signature(&h->keyblock_hash, chk); |
| 131 | free(chk); |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 132 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 133 | /* Calculate signature */ |
Randall Spangler | 7d0cc74 | 2016-06-30 11:30:32 -0700 | [diff] [blame] | 134 | struct vb2_signature *sigtmp = |
| 135 | vb2_external_signature((uint8_t*)h, signed_size, |
| 136 | signing_key_pem_file, algorithm, |
| 137 | external_signer); |
Nicolas Boichat | e0a3f85 | 2017-03-02 22:35:32 +0800 | [diff] [blame] | 138 | vb2_copy_signature(&h->keyblock_signature, sigtmp); |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 139 | free(sigtmp); |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 140 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 141 | /* Return the header */ |
| 142 | return h; |
Gaurav Shah | 068fc6f | 2010-10-29 10:59:50 -0700 | [diff] [blame] | 143 | } |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 144 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 145 | struct vb2_keyblock *vb2_read_keyblock(const char *filename) |
| 146 | { |
Joel Kitching | 92ea19a | 2019-11-05 18:36:42 +0800 | [diff] [blame] | 147 | uint8_t workbuf[VB2_FIRMWARE_WORKBUF_RECOMMENDED_SIZE] |
| 148 | __attribute__((aligned(VB2_WORKBUF_ALIGN))); |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 149 | struct vb2_workbuf wb; |
| 150 | vb2_workbuf_init(&wb, workbuf, sizeof(workbuf)); |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 151 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 152 | struct vb2_keyblock *block; |
| 153 | uint32_t file_size; |
| 154 | if (VB2_SUCCESS != |
| 155 | vb2_read_file(filename, (uint8_t **)&block, &file_size)) { |
Joel Kitching | d3b2117 | 2019-09-04 14:12:42 +0800 | [diff] [blame] | 156 | fprintf(stderr, "Error reading keyblock file: %s\n", filename); |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 157 | return NULL; |
| 158 | } |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 159 | |
Joel Kitching | d3b2117 | 2019-09-04 14:12:42 +0800 | [diff] [blame] | 160 | /* Verify the hash of the keyblock, since we can do that without |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 161 | * the public signing key. */ |
| 162 | if (VB2_SUCCESS != vb2_verify_keyblock_hash(block, file_size, &wb)) { |
Joel Kitching | d3b2117 | 2019-09-04 14:12:42 +0800 | [diff] [blame] | 163 | fprintf(stderr, "Invalid keyblock file: %s\n", filename); |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 164 | free(block); |
| 165 | return NULL; |
| 166 | } |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 167 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 168 | return block; |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 169 | } |
| 170 | |
| 171 | |
Randall Spangler | 939cc3a | 2016-06-21 15:23:32 -0700 | [diff] [blame] | 172 | int vb2_write_keyblock(const char *filename, |
| 173 | const struct vb2_keyblock *keyblock) |
| 174 | { |
| 175 | return vb2_write_file(filename, keyblock, keyblock->keyblock_size); |
Randall Spangler | 729b872 | 2010-06-11 11:16:20 -0700 | [diff] [blame] | 176 | } |