integrity: support EC-RDSA signatures for asymmetric_verify
authorVitaly Chikunov <vt@altlinux.org>
Thu, 11 Apr 2019 15:51:22 +0000 (18:51 +0300)
committerHerbert Xu <herbert@gondor.apana.org.au>
Thu, 18 Apr 2019 14:15:03 +0000 (22:15 +0800)
Allow to use EC-RDSA signatures for IMA by determining signature type by
the hash algorithm name. This works good for EC-RDSA since Streebog and
EC-RDSA should always be used together.

Cc: Mimi Zohar <zohar@linux.ibm.com>
Cc: Dmitry Kasatkin <dmitry.kasatkin@gmail.com>
Cc: linux-integrity@vger.kernel.org
Signed-off-by: Vitaly Chikunov <vt@altlinux.org>
Reviewed-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
security/integrity/digsig_asymmetric.c

index d775e03..9908087 100644 (file)
@@ -104,9 +104,16 @@ int asymmetric_verify(struct key *keyring, const char *sig,
 
        memset(&pks, 0, sizeof(pks));
 
-       pks.pkey_algo = "rsa";
        pks.hash_algo = hash_algo_name[hdr->hash_algo];
-       pks.encoding = "pkcs1";
+       if (hdr->hash_algo == HASH_ALGO_STREEBOG_256 ||
+           hdr->hash_algo == HASH_ALGO_STREEBOG_512) {
+               /* EC-RDSA and Streebog should go together. */
+               pks.pkey_algo = "ecrdsa";
+               pks.encoding = "raw";
+       } else {
+               pks.pkey_algo = "rsa";
+               pks.encoding = "pkcs1";
+       }
        pks.digest = (u8 *)data;
        pks.digest_size = datalen;
        pks.s = hdr->sig;