34f6755b34
Instead of using the legacy mbedtls_ecp_mul() function which makes use of ECP's math, this commit adds a new function named pk_derive_public_key() which implements the same behavior using PSA functions. The flow is simple: - import the private key into PSA - export its public part Signed-off-by: Valerio Setti <valerio.setti@nordicsemi.no>
143 lines
3.2 KiB
C
143 lines
3.2 KiB
C
/* BEGIN_HEADER */
|
|
#include "mbedtls/pk.h"
|
|
#include "mbedtls/pem.h"
|
|
#include "mbedtls/oid.h"
|
|
#include "mbedtls/ecp.h"
|
|
/* END_HEADER */
|
|
|
|
/* BEGIN_DEPENDENCIES
|
|
* depends_on:MBEDTLS_PK_PARSE_C:MBEDTLS_BIGNUM_C
|
|
* END_DEPENDENCIES
|
|
*/
|
|
|
|
/* BEGIN_CASE depends_on:MBEDTLS_RSA_C:MBEDTLS_FS_IO */
|
|
void pk_parse_keyfile_rsa(char *key_file, char *password, int result)
|
|
{
|
|
mbedtls_pk_context ctx;
|
|
int res;
|
|
char *pwd = password;
|
|
|
|
MD_PSA_INIT();
|
|
|
|
mbedtls_pk_init(&ctx);
|
|
|
|
if (strcmp(pwd, "NULL") == 0) {
|
|
pwd = NULL;
|
|
}
|
|
|
|
res = mbedtls_pk_parse_keyfile(&ctx, key_file, pwd,
|
|
mbedtls_test_rnd_std_rand, NULL);
|
|
|
|
TEST_ASSERT(res == result);
|
|
|
|
if (res == 0) {
|
|
mbedtls_rsa_context *rsa;
|
|
TEST_ASSERT(mbedtls_pk_can_do(&ctx, MBEDTLS_PK_RSA));
|
|
rsa = mbedtls_pk_rsa(ctx);
|
|
TEST_ASSERT(mbedtls_rsa_check_privkey(rsa) == 0);
|
|
}
|
|
|
|
exit:
|
|
mbedtls_pk_free(&ctx);
|
|
MD_PSA_DONE();
|
|
}
|
|
|
|
/* END_CASE */
|
|
|
|
/* BEGIN_CASE depends_on:MBEDTLS_RSA_C:MBEDTLS_FS_IO */
|
|
void pk_parse_public_keyfile_rsa(char *key_file, int result)
|
|
{
|
|
mbedtls_pk_context ctx;
|
|
int res;
|
|
|
|
MD_PSA_INIT();
|
|
|
|
mbedtls_pk_init(&ctx);
|
|
|
|
res = mbedtls_pk_parse_public_keyfile(&ctx, key_file);
|
|
|
|
TEST_ASSERT(res == result);
|
|
|
|
if (res == 0) {
|
|
mbedtls_rsa_context *rsa;
|
|
TEST_ASSERT(mbedtls_pk_can_do(&ctx, MBEDTLS_PK_RSA));
|
|
rsa = mbedtls_pk_rsa(ctx);
|
|
TEST_ASSERT(mbedtls_rsa_check_pubkey(rsa) == 0);
|
|
}
|
|
|
|
exit:
|
|
mbedtls_pk_free(&ctx);
|
|
MD_PSA_DONE();
|
|
}
|
|
/* END_CASE */
|
|
|
|
/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_ECP_C */
|
|
void pk_parse_public_keyfile_ec(char *key_file, int result)
|
|
{
|
|
mbedtls_pk_context ctx;
|
|
int res;
|
|
|
|
mbedtls_pk_init(&ctx);
|
|
|
|
res = mbedtls_pk_parse_public_keyfile(&ctx, key_file);
|
|
|
|
TEST_ASSERT(res == result);
|
|
|
|
if (res == 0) {
|
|
mbedtls_ecp_keypair *eckey;
|
|
TEST_ASSERT(mbedtls_pk_can_do(&ctx, MBEDTLS_PK_ECKEY));
|
|
eckey = mbedtls_pk_ec(ctx);
|
|
TEST_ASSERT(mbedtls_ecp_check_pubkey(&eckey->grp, &eckey->Q) == 0);
|
|
}
|
|
|
|
exit:
|
|
mbedtls_pk_free(&ctx);
|
|
}
|
|
/* END_CASE */
|
|
|
|
/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_ECP_C */
|
|
void pk_parse_keyfile_ec(char *key_file, char *password, int result)
|
|
{
|
|
mbedtls_pk_context ctx;
|
|
int res;
|
|
|
|
#if defined(MBEDTLS_USE_PSA_CRYPTO)
|
|
PSA_INIT();
|
|
#endif
|
|
|
|
mbedtls_pk_init(&ctx);
|
|
|
|
res = mbedtls_pk_parse_keyfile(&ctx, key_file, password,
|
|
mbedtls_test_rnd_std_rand, NULL);
|
|
|
|
TEST_ASSERT(res == result);
|
|
|
|
if (res == 0) {
|
|
mbedtls_ecp_keypair *eckey;
|
|
TEST_ASSERT(mbedtls_pk_can_do(&ctx, MBEDTLS_PK_ECKEY));
|
|
eckey = mbedtls_pk_ec(ctx);
|
|
TEST_ASSERT(mbedtls_ecp_check_privkey(&eckey->grp, &eckey->d) == 0);
|
|
}
|
|
|
|
exit:
|
|
mbedtls_pk_free(&ctx);
|
|
#if defined(MBEDTLS_USE_PSA_CRYPTO)
|
|
PSA_DONE();
|
|
#endif
|
|
}
|
|
/* END_CASE */
|
|
|
|
/* BEGIN_CASE */
|
|
void pk_parse_key(data_t *buf, int result)
|
|
{
|
|
mbedtls_pk_context pk;
|
|
|
|
mbedtls_pk_init(&pk);
|
|
|
|
TEST_ASSERT(mbedtls_pk_parse_key(&pk, buf->x, buf->len, NULL, 0,
|
|
mbedtls_test_rnd_std_rand, NULL) == result);
|
|
|
|
exit:
|
|
mbedtls_pk_free(&pk);
|
|
}
|
|
/* END_CASE */
|