new injection mechanic in CI/CD and github review fixes
parent
5c56a1ce91
commit
f5c6e02ba6
|
|
@ -13,6 +13,16 @@ inputs:
|
||||||
description: 'extra CFLAGS for this profile'
|
description: 'extra CFLAGS for this profile'
|
||||||
required: false
|
required: false
|
||||||
default: ''
|
default: ''
|
||||||
|
overlay:
|
||||||
|
description: >-
|
||||||
|
source overlay to install into the wolfSSL tree before configure, as
|
||||||
|
"name@branchOrTag" or if you want just the latest on master of a repo
|
||||||
|
just set "name" (currently only supports "wolfsm"). Some algorithm
|
||||||
|
families ship outside the wolfSSL repo and cannot be reached by any
|
||||||
|
configure flag alone, so the patch has to happen here -- this is the
|
||||||
|
only step that holds the wolfSSL source tree.
|
||||||
|
required: false
|
||||||
|
default: ''
|
||||||
|
|
||||||
outputs:
|
outputs:
|
||||||
sha256:
|
sha256:
|
||||||
|
|
@ -50,7 +60,11 @@ runs:
|
||||||
id: cfg
|
id: cfg
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
printf '%s|%s' '${{ inputs.flags }}' '${{ inputs.cflags }}' \
|
# overlay is in the hash: an SM build and a plain build of the same ref
|
||||||
|
# and flags are different libraries, and sharing a key would serve one
|
||||||
|
# for the other.
|
||||||
|
printf '%s|%s|%s' '${{ inputs.flags }}' '${{ inputs.cflags }}' \
|
||||||
|
'${{ inputs.overlay }}' \
|
||||||
| sha256sum | cut -c1-16 | sed 's/^/hash=/' >> "$GITHUB_OUTPUT"
|
| sha256sum | cut -c1-16 | sed 's/^/hash=/' >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
# Key on the image, not runner.os: a binary built against a newer glibc must
|
# Key on the image, not runner.os: a binary built against a newer glibc must
|
||||||
|
|
@ -81,6 +95,32 @@ runs:
|
||||||
git init -q
|
git init -q
|
||||||
git fetch -q --depth 1 https://github.com/wolfSSL/wolfssl.git ${{ steps.resolve.outputs.sha }}
|
git fetch -q --depth 1 https://github.com/wolfSSL/wolfssl.git ${{ steps.resolve.outputs.sha }}
|
||||||
git checkout -q FETCH_HEAD
|
git checkout -q FETCH_HEAD
|
||||||
|
|
||||||
|
# Before autogen, not after: install.sh drops sources and m4 into the
|
||||||
|
# tree, and configure only grows --enable-sm2/sm3/sm4-* once they are
|
||||||
|
# there.
|
||||||
|
overlay='${{ inputs.overlay }}'
|
||||||
|
if [ -n "$overlay" ]; then
|
||||||
|
repoName="${overlay%%@*}"
|
||||||
|
if [ "$overlay" = "$repoName" ]; then
|
||||||
|
# default to latest on master
|
||||||
|
branchOrTag="HEAD"
|
||||||
|
else
|
||||||
|
branchOrTag="${overlay#*@}"
|
||||||
|
fi
|
||||||
|
case "$repoName" in
|
||||||
|
wolfsm) url=https://github.com/wolfSSL/wolfsm.git ;;
|
||||||
|
# add more cases here as they come up!
|
||||||
|
*) echo "unknown overlay '$repoName'"; exit 1 ;;
|
||||||
|
esac
|
||||||
|
rm -rf "/tmp/$repoName" && mkdir -p "/tmp/$repoName"
|
||||||
|
git -C "/tmp/$repoName" init -q
|
||||||
|
git -C "/tmp/$repoName" fetch -q --depth 1 "$url" "$branchOrTag"
|
||||||
|
git -C "/tmp/$repoName" checkout -q FETCH_HEAD
|
||||||
|
echo "installing $repoName@$branchOrTag into the wolfSSL tree"
|
||||||
|
( cd "/tmp/$repoName" && ./install.sh /tmp/wolfssl )
|
||||||
|
fi
|
||||||
|
|
||||||
./autogen.sh
|
./autogen.sh
|
||||||
# We need the library, not wolfSSL's own examples and test suite. Those
|
# We need the library, not wolfSSL's own examples and test suite. Those
|
||||||
# also fail to build under some profiles (the `tls` profile died on
|
# also fail to build under some profiles (the `tls` profile died on
|
||||||
|
|
|
||||||
|
|
@ -71,6 +71,16 @@ profiles:
|
||||||
# and WC_RNG_SEED_CB" without it.
|
# and WC_RNG_SEED_CB" without it.
|
||||||
cflags: "-DWOLFSSL_AES_CTS -DHAVE_AES_ECB -DWC_RNG_SEED_CB"
|
cflags: "-DWOLFSSL_AES_CTS -DHAVE_AES_ECB -DWC_RNG_SEED_CB"
|
||||||
|
|
||||||
|
sm:
|
||||||
|
# crypto/sm/README: SM2/SM3/SM4 ship in the wolfSSL/wolfsm overlay, not in
|
||||||
|
# wolfSSL itself, so these --enable flags do not exist until install.sh has
|
||||||
|
# run against the source tree. setup-wolfssl applies the overlay before
|
||||||
|
# autogen; nothing in an example's own build can reach that far back.
|
||||||
|
# Bare name means latest on wolfsm's master: the repo publishes no tags and
|
||||||
|
# has no other branch, so there is nothing to pin to short of a raw commit.
|
||||||
|
overlay: wolfsm
|
||||||
|
flags: "--enable-sm2 --enable-sm3 --enable-sm4-gcm --enable-static --enable-shared"
|
||||||
|
|
||||||
certgen:
|
certgen:
|
||||||
flags: >-
|
flags: >-
|
||||||
--enable-certgen --enable-certreq --enable-certext --enable-keygen
|
--enable-certgen --enable-certreq --enable-certext --enable-keygen
|
||||||
|
|
@ -435,11 +445,8 @@ examples:
|
||||||
|
|
||||||
- id: crypto-sm
|
- id: crypto-sm
|
||||||
path: crypto/sm
|
path: crypto/sm
|
||||||
mode: skip
|
profile: sm
|
||||||
reason: >-
|
mode: check
|
||||||
SM2/SM3/SM4 live in the separate wolfSSL/wolfsm overlay, which must be
|
|
||||||
installed into the wolfSSL source tree before configure. No cached
|
|
||||||
profile can express that patch step yet.
|
|
||||||
|
|
||||||
- id: signature
|
- id: signature
|
||||||
path: signature
|
path: signature
|
||||||
|
|
|
||||||
|
|
@ -60,6 +60,16 @@ def load(path=MANIFEST):
|
||||||
|
|
||||||
def validate(data):
|
def validate(data):
|
||||||
profiles = data.get("profiles") or {}
|
profiles = data.get("profiles") or {}
|
||||||
|
# Matches the `overlay` input of .github/actions/setup-wolfssl: either a
|
||||||
|
# bare repo name (latest on master) or "name@branchOrTagOrCommit". The
|
||||||
|
# action resolves the name to a URL, so an unknown one fails there, not here.
|
||||||
|
for name, p in profiles.items():
|
||||||
|
overlay = (p or {}).get("overlay")
|
||||||
|
if overlay and not re.fullmatch(r"[a-z0-9-]+(@[^\s@]+)?", overlay):
|
||||||
|
sys.exit(
|
||||||
|
f"manifest: profile '{name}': overlay must be 'name' or "
|
||||||
|
f"'name@branchOrTagOrCommit', got '{overlay}'"
|
||||||
|
)
|
||||||
seen = set()
|
seen = set()
|
||||||
for e in data.get("examples") or []:
|
for e in data.get("examples") or []:
|
||||||
for key in ("id", "path"):
|
for key in ("id", "path"):
|
||||||
|
|
@ -309,6 +319,9 @@ def cmd_matrix(data, refs, tier, shas=None):
|
||||||
"wolfssl_sha": pinned.get(ref, ref),
|
"wolfssl_sha": pinned.get(ref, ref),
|
||||||
"flags": " ".join(p.get("flags", "").split()),
|
"flags": " ".join(p.get("flags", "").split()),
|
||||||
"cflags": p.get("cflags", ""),
|
"cflags": p.get("cflags", ""),
|
||||||
|
# a source overlay the profile needs patched into the wolfSSL
|
||||||
|
# tree before configure (setup-wolfssl applies it)
|
||||||
|
"overlay": p.get("overlay", ""),
|
||||||
"deps": " ".join(e.get("deps") or []),
|
"deps": " ".join(e.get("deps") or []),
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
|
|
@ -335,6 +348,7 @@ def cmd_wolfssl_matrix(data, refs, tier, shas=None):
|
||||||
"wolfssl_sha": pinned.get(ref, ref),
|
"wolfssl_sha": pinned.get(ref, ref),
|
||||||
"flags": " ".join(data["profiles"][name].get("flags", "").split()),
|
"flags": " ".join(data["profiles"][name].get("flags", "").split()),
|
||||||
"cflags": data["profiles"][name].get("cflags", ""),
|
"cflags": data["profiles"][name].get("cflags", ""),
|
||||||
|
"overlay": data["profiles"][name].get("overlay", ""),
|
||||||
}
|
}
|
||||||
for name in profiles
|
for name in profiles
|
||||||
for ref in refs
|
for ref in refs
|
||||||
|
|
@ -355,6 +369,7 @@ def cmd_wolfssl_matrix(data, refs, tier, shas=None):
|
||||||
data["profiles"][e["profile"]].get("flags", "").split()
|
data["profiles"][e["profile"]].get("flags", "").split()
|
||||||
),
|
),
|
||||||
"cflags": data["profiles"][e["profile"]].get("cflags", ""),
|
"cflags": data["profiles"][e["profile"]].get("cflags", ""),
|
||||||
|
"overlay": data["profiles"][e["profile"]].get("overlay", ""),
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
print(json.dumps(out))
|
print(json.dumps(out))
|
||||||
|
|
@ -393,6 +408,7 @@ def cmd_profiles(data):
|
||||||
"profile": name,
|
"profile": name,
|
||||||
"flags": data["profiles"][name].get("flags", "").strip(),
|
"flags": data["profiles"][name].get("flags", "").strip(),
|
||||||
"cflags": data["profiles"][name].get("cflags", ""),
|
"cflags": data["profiles"][name].get("cflags", ""),
|
||||||
|
"overlay": data["profiles"][name].get("overlay", ""),
|
||||||
}
|
}
|
||||||
for name in sorted(used)
|
for name in sorted(used)
|
||||||
]
|
]
|
||||||
|
|
|
||||||
|
|
@ -106,6 +106,7 @@ jobs:
|
||||||
ref: ${{ matrix.wolfssl_sha }}
|
ref: ${{ matrix.wolfssl_sha }}
|
||||||
flags: ${{ matrix.flags }}
|
flags: ${{ matrix.flags }}
|
||||||
cflags: ${{ matrix.cflags }}
|
cflags: ${{ matrix.cflags }}
|
||||||
|
overlay: ${{ matrix.overlay }}
|
||||||
|
|
||||||
# One job per example, so a red tile names the example that broke.
|
# One job per example, so a red tile names the example that broke.
|
||||||
examples:
|
examples:
|
||||||
|
|
@ -138,6 +139,7 @@ jobs:
|
||||||
ref: ${{ matrix.wolfssl_sha }}
|
ref: ${{ matrix.wolfssl_sha }}
|
||||||
flags: ${{ matrix.flags }}
|
flags: ${{ matrix.flags }}
|
||||||
cflags: ${{ matrix.cflags }}
|
cflags: ${{ matrix.cflags }}
|
||||||
|
overlay: ${{ matrix.overlay }}
|
||||||
|
|
||||||
# Probe the exact netns invocation: --map-root-user is the part that fails
|
# Probe the exact netns invocation: --map-root-user is the part that fails
|
||||||
- name: Enable unprivileged user namespaces
|
- name: Enable unprivileged user namespaces
|
||||||
|
|
|
||||||
|
|
@ -445,3 +445,20 @@ pq/ml_kem/ml_kem
|
||||||
|
|
||||||
# openssl ocsp -index writes this beside the index when it is missing
|
# openssl ocsp -index writes this beside the index when it is missing
|
||||||
ocsp/stapling/responder-certs/index.txt.attr
|
ocsp/stapling/responder-certs/index.txt.attr
|
||||||
|
|
||||||
|
# algorithm example executables
|
||||||
|
crypto/kdf/hkdf
|
||||||
|
crypto/kdf/pbkdf2
|
||||||
|
crypto/kdf/scrypt-kdf
|
||||||
|
crypto/siphash/siphash-mac
|
||||||
|
crypto/sm/sm2-ecdh
|
||||||
|
crypto/sm/sm2-sign-verify
|
||||||
|
crypto/sm/sm3-hash
|
||||||
|
crypto/sm/sm4-gcm-encrypt
|
||||||
|
hash/blake2/blake2-keyed-mac
|
||||||
|
hash/blake2/blake2b-hash
|
||||||
|
hash/blake2/blake2s-hash
|
||||||
|
pk/hpke/hpke_context
|
||||||
|
pk/mikey-sakke/mikey-sakke
|
||||||
|
pk/srp/srp_sha256
|
||||||
|
pq/slh_dsa/slh_dsa_test
|
||||||
|
|
|
||||||
|
|
@ -3,11 +3,13 @@ WOLFSSL_INSTALL_DIR=/usr/local
|
||||||
CFLAGS=-Wall -I$(WOLFSSL_INSTALL_DIR)/include
|
CFLAGS=-Wall -I$(WOLFSSL_INSTALL_DIR)/include
|
||||||
LIBS=-L$(WOLFSSL_INSTALL_DIR)/lib -lwolfssl -lm
|
LIBS=-L$(WOLFSSL_INSTALL_DIR)/lib -lwolfssl -lm
|
||||||
|
|
||||||
|
.PHONY: all clean check
|
||||||
|
|
||||||
|
all: siphash-mac
|
||||||
|
|
||||||
siphash-mac: siphash-mac.o
|
siphash-mac: siphash-mac.o
|
||||||
$(CC) -o $@ $^ $(CFLAGS) $(LIBS)
|
$(CC) -o $@ $^ $(CFLAGS) $(LIBS)
|
||||||
|
|
||||||
.PHONY: clean check
|
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
rm -f *.o siphash-mac
|
rm -f *.o siphash-mac
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -3,11 +3,13 @@ WOLFSSL_INSTALL_DIR=/usr/local
|
||||||
CFLAGS=-Wall -I$(WOLFSSL_INSTALL_DIR)/include
|
CFLAGS=-Wall -I$(WOLFSSL_INSTALL_DIR)/include
|
||||||
LIBS=-L$(WOLFSSL_INSTALL_DIR)/lib -lwolfssl -lm
|
LIBS=-L$(WOLFSSL_INSTALL_DIR)/lib -lwolfssl -lm
|
||||||
|
|
||||||
|
.PHONY: all clean check
|
||||||
|
|
||||||
|
all: mikey-sakke
|
||||||
|
|
||||||
mikey-sakke: mikey-sakke.o
|
mikey-sakke: mikey-sakke.o
|
||||||
$(CC) -o $@ $^ $(CFLAGS) $(LIBS)
|
$(CC) -o $@ $^ $(CFLAGS) $(LIBS)
|
||||||
|
|
||||||
.PHONY: clean check
|
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
rm -f *.o mikey-sakke
|
rm -f *.o mikey-sakke
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -47,11 +47,41 @@
|
||||||
|
|
||||||
#if defined(WOLFCRYPT_HAVE_ECCSI) && defined(WOLFCRYPT_HAVE_SAKKE)
|
#if defined(WOLFCRYPT_HAVE_ECCSI) && defined(WOLFCRYPT_HAVE_SAKKE)
|
||||||
|
|
||||||
|
/* On failure, report and jump to the cleanup label. */
|
||||||
|
#define CheckError(msg, label) do { \
|
||||||
|
if (ret != 0) { \
|
||||||
|
printf(msg ": ret %d, line %d\n", ret, __LINE__); \
|
||||||
|
goto label; \
|
||||||
|
} \
|
||||||
|
} while (0)
|
||||||
|
|
||||||
|
/* Set flag on success */
|
||||||
|
#define CheckErrorSetFlag(msg, label, flag) do { \
|
||||||
|
if (ret != 0) { \
|
||||||
|
printf(msg ": ret %d, line %d\n", ret, __LINE__); \
|
||||||
|
goto label; \
|
||||||
|
} \
|
||||||
|
else { \
|
||||||
|
flag = 1; \
|
||||||
|
} \
|
||||||
|
} while (0)
|
||||||
|
|
||||||
|
|
||||||
|
/* Sizes below are derived from the parameter sets used by this example:
|
||||||
|
* SAKKE 1024-bit (RFC 6509 Appendix A) and ECCSI over NIST P-256.
|
||||||
|
* The buffer sizes are compile-time maximums; the authentication size
|
||||||
|
* actually used is queried at run time with wc_GetSakkeAuthSize(). */
|
||||||
#define SSV_SZ 16
|
#define SSV_SZ 16
|
||||||
|
/* SAKKE 1024-bit: 1 + 2*128 (uncompressed point) */
|
||||||
#define AUTH_SZ 257
|
#define AUTH_SZ 257
|
||||||
|
/* ECCSI P-256: 32 + 32 + 65 (r || s || PVT) */
|
||||||
#define ECCSI_SIG_SZ 129
|
#define ECCSI_SIG_SZ 129
|
||||||
#define ECCSI_PUB_KEY_SZ (32 * 2) /* raw P-256 point: X || Y */
|
/* raw P-256 point: X || Y */
|
||||||
#define SAKKE_PUB_KEY_SZ (128 * 2) /* raw 1024-bit point: X || Y */
|
#define ECCSI_PUB_KEY_SZ (32 * 2)
|
||||||
|
/* raw 1024-bit point: X || Y */
|
||||||
|
#define SAKKE_PUB_KEY_SZ (128 * 2)
|
||||||
|
|
||||||
|
/* Arbitrary max for simplicity */
|
||||||
#define MAX_ID_SZ 64
|
#define MAX_ID_SZ 64
|
||||||
|
|
||||||
static const byte aliceId[] = "alice@example.com";
|
static const byte aliceId[] = "alice@example.com";
|
||||||
|
|
@ -89,7 +119,7 @@ int main(void)
|
||||||
word32 kmsAuthPublicKeySz;
|
word32 kmsAuthPublicKeySz;
|
||||||
byte kmsSakkePublicKey[SAKKE_PUB_KEY_SZ]; /* KMS SAKKE public key */
|
byte kmsSakkePublicKey[SAKKE_PUB_KEY_SZ]; /* KMS SAKKE public key */
|
||||||
word32 kmsSakkePublicKeySz;
|
word32 kmsSakkePublicKeySz;
|
||||||
} KmsCertficate = {0};
|
} KmsCertificate = {0};
|
||||||
|
|
||||||
struct {
|
struct {
|
||||||
char senderId[MAX_ID_SZ];
|
char senderId[MAX_ID_SZ];
|
||||||
|
|
@ -108,9 +138,8 @@ int main(void)
|
||||||
int secretSigningKeyInit;
|
int secretSigningKeyInit;
|
||||||
ecc_point* publicValidationToken;
|
ecc_point* publicValidationToken;
|
||||||
ecc_point* receiverSecretKey;
|
ecc_point* receiverSecretKey;
|
||||||
byte sharedSecretValue[SSV_SZ]; /* plaintext SSV (Alices's copy) */
|
byte sharedSecretValue[SSV_SZ]; /* plaintext SSV (Alice's copy) */
|
||||||
word16 sharedSecretValueSz;
|
word16 sharedSecretValueSz;
|
||||||
int verified;
|
|
||||||
char* id;
|
char* id;
|
||||||
} Alice = {0};
|
} Alice = {0};
|
||||||
|
|
||||||
|
|
@ -123,45 +152,54 @@ int main(void)
|
||||||
int secretSigningKeyInit;
|
int secretSigningKeyInit;
|
||||||
ecc_point* publicValidationToken;
|
ecc_point* publicValidationToken;
|
||||||
ecc_point* receiverSecretKey;
|
ecc_point* receiverSecretKey;
|
||||||
byte dirived_sharedSecretValue[SSV_SZ]; /* plaintext SSV (Bob's copy) */
|
byte derived_sharedSecretValue[SSV_SZ]; /* plaintext SSV (Bob's copy) */
|
||||||
word16 dirived_sharedSecretValueSz;
|
word16 derived_sharedSecretValueSz;
|
||||||
int verified;
|
|
||||||
char* id;
|
char* id;
|
||||||
} Bob = {0};
|
} Bob = {0};
|
||||||
|
|
||||||
/* --- Setup KMS --- */
|
/* --- Setup KMS --- */
|
||||||
ret = wc_InitSakkeKey(&kms.kmsSakke, NULL, INVALID_DEVID);
|
ret = wc_InitSakkeKey(&kms.kmsSakke, NULL, INVALID_DEVID);
|
||||||
if (ret != 0) goto exit; else kms.kmsSakkeInit = 1;
|
CheckErrorSetFlag("Could Not Init Sakke Key", exit, kms.kmsSakkeInit);
|
||||||
ret = wc_InitEccsiKey(&kms.kmsEccsi, NULL, INVALID_DEVID);
|
ret = wc_InitEccsiKey(&kms.kmsEccsi, NULL, INVALID_DEVID);
|
||||||
if (ret != 0) goto exit; else kms.kmsEccsiInit = 1;
|
CheckErrorSetFlag("Could Not Init Eccsi Key", exit, kms.kmsEccsiInit);
|
||||||
/* --- Setup KMS --- */
|
/* --- Setup KMS --- */
|
||||||
|
|
||||||
/* --- Init Alice --- */
|
/* --- Init Alice --- */
|
||||||
Alice.id = (char*)aliceId;
|
Alice.id = (char*)aliceId;
|
||||||
ret = wc_InitEccsiKey(&Alice.publicKeyEccsi, NULL, INVALID_DEVID);
|
ret = wc_InitEccsiKey(&Alice.publicKeyEccsi, NULL, INVALID_DEVID);
|
||||||
if (ret != 0) goto exit; else Alice.publicKeyEccsiInit = 1;
|
CheckErrorSetFlag("Could not init Eccsi Key alice", exit,
|
||||||
|
Alice.publicKeyEccsiInit);
|
||||||
ret = wc_InitSakkeKey(&Alice.publicKeySakke, NULL, INVALID_DEVID);
|
ret = wc_InitSakkeKey(&Alice.publicKeySakke, NULL, INVALID_DEVID);
|
||||||
if (ret != 0) goto exit; else Alice.publicKeySakkeInit = 1;
|
CheckErrorSetFlag("Could not init Sakke Key alice", exit,
|
||||||
|
Alice.publicKeySakkeInit);
|
||||||
ret = mp_init(&Alice.secretSigningKey);
|
ret = mp_init(&Alice.secretSigningKey);
|
||||||
if (ret != 0) goto exit; else Alice.secretSigningKeyInit = 1;
|
CheckErrorSetFlag("Could not init secret signing key alice", exit,
|
||||||
|
Alice.secretSigningKeyInit);
|
||||||
Alice.publicValidationToken = wc_ecc_new_point();
|
Alice.publicValidationToken = wc_ecc_new_point();
|
||||||
Alice.receiverSecretKey = wc_ecc_new_point();
|
Alice.receiverSecretKey = wc_ecc_new_point();
|
||||||
if (Alice.publicValidationToken == NULL || Alice.receiverSecretKey == NULL)
|
if (Alice.publicValidationToken == NULL || Alice.receiverSecretKey == NULL){
|
||||||
{ret = MEMORY_E; goto exit;}
|
ret = MEMORY_E;
|
||||||
|
goto exit;
|
||||||
|
}
|
||||||
/* --- Init Alice --- */
|
/* --- Init Alice --- */
|
||||||
|
|
||||||
/* --- Init Bob --- */
|
/* --- Init Bob --- */
|
||||||
Bob.id = (char*)bobId;
|
Bob.id = (char*)bobId;
|
||||||
ret = wc_InitEccsiKey(&Bob.publicKeyEccsi, NULL, INVALID_DEVID);
|
ret = wc_InitEccsiKey(&Bob.publicKeyEccsi, NULL, INVALID_DEVID);
|
||||||
if (ret != 0) goto exit; else Bob.publicKeyEccsiInit = 1;
|
CheckErrorSetFlag("Could not init Eccsi Key bob", exit,
|
||||||
|
Bob.publicKeyEccsiInit);
|
||||||
ret = wc_InitSakkeKey(&Bob.publicKeySakke, NULL, INVALID_DEVID);
|
ret = wc_InitSakkeKey(&Bob.publicKeySakke, NULL, INVALID_DEVID);
|
||||||
if (ret != 0) goto exit; else Bob.publicKeySakkeInit = 1;
|
CheckErrorSetFlag("Could not init Sakke Key bob", exit,
|
||||||
|
Bob.publicKeySakkeInit);
|
||||||
ret = mp_init(&Bob.secretSigningKey);
|
ret = mp_init(&Bob.secretSigningKey);
|
||||||
if (ret != 0) goto exit; else Bob.secretSigningKeyInit = 1;
|
CheckErrorSetFlag("Could not init secret signing key bob", exit,
|
||||||
|
Bob.secretSigningKeyInit);
|
||||||
Bob.publicValidationToken = wc_ecc_new_point();
|
Bob.publicValidationToken = wc_ecc_new_point();
|
||||||
Bob.receiverSecretKey = wc_ecc_new_point();
|
Bob.receiverSecretKey = wc_ecc_new_point();
|
||||||
if (Bob.publicValidationToken == NULL || Bob.receiverSecretKey == NULL)
|
if (Bob.publicValidationToken == NULL || Bob.receiverSecretKey == NULL) {
|
||||||
{ret = MEMORY_E; goto exit;}
|
ret = MEMORY_E;
|
||||||
|
goto exit;
|
||||||
|
}
|
||||||
/* --- Init Bob --- */
|
/* --- Init Bob --- */
|
||||||
|
|
||||||
|
|
||||||
|
|
@ -201,102 +239,89 @@ int main(void)
|
||||||
/* --- Enroll Alice with KMS to get their keys --- */
|
/* --- Enroll Alice with KMS to get their keys --- */
|
||||||
{
|
{
|
||||||
/* - Get PublicKeys from KMS (Simulate KMS sending pubkeys only) - */
|
/* - Get PublicKeys from KMS (Simulate KMS sending pubkeys only) - */
|
||||||
KmsCertficate.kmsAuthPublicKeySz = ECCSI_PUB_KEY_SZ;
|
KmsCertificate.kmsAuthPublicKeySz = ECCSI_PUB_KEY_SZ;
|
||||||
ret = wc_ExportEccsiPublicKey(&kms.kmsEccsi,
|
ret = wc_ExportEccsiPublicKey(&kms.kmsEccsi,
|
||||||
KmsCertficate.kmsAuthPublicKey,
|
KmsCertificate.kmsAuthPublicKey,
|
||||||
&KmsCertficate.kmsAuthPublicKeySz, 1);
|
&KmsCertificate.kmsAuthPublicKeySz, 1);
|
||||||
|
CheckError("Could not export pub eccsi key from KMS", exit);
|
||||||
|
|
||||||
if (ret != 0) {
|
KmsCertificate.kmsSakkePublicKeySz = SAKKE_PUB_KEY_SZ;
|
||||||
printf("could not export pub eccsi key from KMS");
|
|
||||||
goto exit;
|
|
||||||
}
|
|
||||||
|
|
||||||
KmsCertficate.kmsSakkePublicKeySz = SAKKE_PUB_KEY_SZ;
|
|
||||||
ret = wc_ExportSakkePublicKey(&kms.kmsSakke,
|
ret = wc_ExportSakkePublicKey(&kms.kmsSakke,
|
||||||
KmsCertficate.kmsSakkePublicKey,
|
KmsCertificate.kmsSakkePublicKey,
|
||||||
&KmsCertficate.kmsSakkePublicKeySz, 1);
|
&KmsCertificate.kmsSakkePublicKeySz, 1);
|
||||||
if (ret != 0) {
|
CheckError("Could not export pub Sakke key from KMS", exit);
|
||||||
printf("could not export pub sakke key from KMS");
|
|
||||||
goto exit;
|
|
||||||
}
|
|
||||||
/* - Get PublicKeys from KMS (Simulate KMS sending pubkeys only) - */
|
/* - Get PublicKeys from KMS (Simulate KMS sending pubkeys only) - */
|
||||||
|
|
||||||
/* - Save public key from KMS - */
|
/* - Save public key from KMS - */
|
||||||
ret = wc_ImportEccsiPublicKey(&Alice.publicKeyEccsi,
|
ret = wc_ImportEccsiPublicKey(&Alice.publicKeyEccsi,
|
||||||
KmsCertficate.kmsAuthPublicKey,
|
KmsCertificate.kmsAuthPublicKey,
|
||||||
KmsCertficate.kmsAuthPublicKeySz, 1);
|
KmsCertificate.kmsAuthPublicKeySz, 1);
|
||||||
if (ret == 0)
|
if (ret == 0)
|
||||||
ret = wc_ImportSakkePublicKey(&Alice.publicKeySakke,
|
ret = wc_ImportSakkePublicKey(&Alice.publicKeySakke,
|
||||||
KmsCertficate.kmsSakkePublicKey,
|
KmsCertificate.kmsSakkePublicKey,
|
||||||
KmsCertficate.kmsSakkePublicKeySz, 1);
|
KmsCertificate.kmsSakkePublicKeySz, 1);
|
||||||
if (ret != 0) {printf("Unable to transfer kms public keys"); goto exit;}
|
CheckError("Unable to transfer kms public keys", exit);
|
||||||
/* - Save public key from KMS - */
|
/* - Save public key from KMS - */
|
||||||
|
|
||||||
/* - Get Signing pair from KMS - */
|
/* - Get Signing pair from KMS - */
|
||||||
ret = wc_MakeEccsiPair(&kms.kmsEccsi, &rng, WC_HASH_TYPE_SHA256,
|
ret = wc_MakeEccsiPair(&kms.kmsEccsi, &rng, WC_HASH_TYPE_SHA256,
|
||||||
(byte*)Alice.id, sizeof(aliceId), &Alice.secretSigningKey,
|
(byte*)Alice.id, sizeof(aliceId), &Alice.secretSigningKey,
|
||||||
Alice.publicValidationToken);
|
Alice.publicValidationToken);
|
||||||
if (ret != 0) {printf("Unable to make signing pairs"); goto exit;}
|
CheckError("Unable to make signing pairs", exit);
|
||||||
/* - Get Sining pair from KMS - */
|
/* - Get Signing pair from KMS - */
|
||||||
|
|
||||||
/* - Get Issue Recivier Key - */
|
/* - Get Issue Receiver Key - */
|
||||||
ret = wc_MakeSakkeRsk(&kms.kmsSakke, (byte*)Alice.id,
|
ret = wc_MakeSakkeRsk(&kms.kmsSakke, (byte*)Alice.id,
|
||||||
sizeof(aliceId), Alice.receiverSecretKey);
|
sizeof(aliceId), Alice.receiverSecretKey);
|
||||||
if (ret != 0) {printf("Unable to make receiver secret key"); goto exit;}
|
CheckError("Unable to make receiver secret key", exit);
|
||||||
/* - Get Issue Recivier Key - */
|
/* - Get Issue Receiver Key - */
|
||||||
}
|
}
|
||||||
/* --- Enroll Alice with KMS to get their keys --- */
|
/* --- Enroll Alice with KMS to get their keys --- */
|
||||||
|
|
||||||
/* --- Reset Kms Cert for Bob --- */
|
/* --- Reset Kms Cert for Bob --- */
|
||||||
memset(&KmsCertficate, 0, sizeof(KmsCertficate));
|
memset(&KmsCertificate, 0, sizeof(KmsCertificate));
|
||||||
/* --- Reset Kms Cert for Bob --- */
|
/* --- Reset Kms Cert for Bob --- */
|
||||||
|
|
||||||
/* --- Enroll Bob with KMS to get their keys --- */
|
/* --- Enroll Bob with KMS to get their keys --- */
|
||||||
{
|
{
|
||||||
/* - Get PublicKeys from KMS (Simulate KMS sending pubkeys only) - */
|
/* - Get PublicKeys from KMS (Simulate KMS sending pubkeys only) - */
|
||||||
KmsCertficate.kmsAuthPublicKeySz = ECCSI_PUB_KEY_SZ;
|
KmsCertificate.kmsAuthPublicKeySz = ECCSI_PUB_KEY_SZ;
|
||||||
ret = wc_ExportEccsiPublicKey(&kms.kmsEccsi,
|
ret = wc_ExportEccsiPublicKey(&kms.kmsEccsi,
|
||||||
KmsCertficate.kmsAuthPublicKey,
|
KmsCertificate.kmsAuthPublicKey,
|
||||||
&KmsCertficate.kmsAuthPublicKeySz, 1);
|
&KmsCertificate.kmsAuthPublicKeySz, 1);
|
||||||
|
|
||||||
if (ret != 0) {
|
CheckError("Could not export pub eccsi key from KMS", exit);
|
||||||
printf("could not export pub eccsi key from KMS");
|
|
||||||
goto exit;
|
|
||||||
}
|
|
||||||
|
|
||||||
KmsCertficate.kmsSakkePublicKeySz = SAKKE_PUB_KEY_SZ;
|
KmsCertificate.kmsSakkePublicKeySz = SAKKE_PUB_KEY_SZ;
|
||||||
ret = wc_ExportSakkePublicKey(&kms.kmsSakke,
|
ret = wc_ExportSakkePublicKey(&kms.kmsSakke,
|
||||||
KmsCertficate.kmsSakkePublicKey,
|
KmsCertificate.kmsSakkePublicKey,
|
||||||
&KmsCertficate.kmsSakkePublicKeySz, 1);
|
&KmsCertificate.kmsSakkePublicKeySz, 1);
|
||||||
if (ret != 0) {
|
CheckError("Could not export pub sakke key from KMS", exit);
|
||||||
printf("could not export pub sakke key from KMS");
|
|
||||||
goto exit;
|
|
||||||
}
|
|
||||||
/* - Get PublicKeys from KMS (Simulate KMS sending pubkeys only) - */
|
/* - Get PublicKeys from KMS (Simulate KMS sending pubkeys only) - */
|
||||||
|
|
||||||
/* - Save public key from KMS - */
|
/* - Save public key from KMS - */
|
||||||
ret = wc_ImportEccsiPublicKey(&Bob.publicKeyEccsi,
|
ret = wc_ImportEccsiPublicKey(&Bob.publicKeyEccsi,
|
||||||
KmsCertficate.kmsAuthPublicKey,
|
KmsCertificate.kmsAuthPublicKey,
|
||||||
KmsCertficate.kmsAuthPublicKeySz, 1);
|
KmsCertificate.kmsAuthPublicKeySz, 1);
|
||||||
if (ret == 0)
|
if (ret == 0)
|
||||||
ret = wc_ImportSakkePublicKey(&Bob.publicKeySakke,
|
ret = wc_ImportSakkePublicKey(&Bob.publicKeySakke,
|
||||||
KmsCertficate.kmsSakkePublicKey,
|
KmsCertificate.kmsSakkePublicKey,
|
||||||
KmsCertficate.kmsSakkePublicKeySz, 1);
|
KmsCertificate.kmsSakkePublicKeySz, 1);
|
||||||
if (ret != 0) {printf("Unable to transfer kms public keys"); goto exit;}
|
CheckError("Unable to transfer kms public keys", exit);
|
||||||
/* - Save public key from KMS - */
|
/* - Save public key from KMS - */
|
||||||
|
|
||||||
/* - Get Signing pair from KMS - */
|
/* - Get Signing pair from KMS - */
|
||||||
ret = wc_MakeEccsiPair(&kms.kmsEccsi, &rng, WC_HASH_TYPE_SHA256,
|
ret = wc_MakeEccsiPair(&kms.kmsEccsi, &rng, WC_HASH_TYPE_SHA256,
|
||||||
(byte*)Bob.id, sizeof(bobId), &Bob.secretSigningKey,
|
(byte*)Bob.id, sizeof(bobId), &Bob.secretSigningKey,
|
||||||
Bob.publicValidationToken);
|
Bob.publicValidationToken);
|
||||||
if (ret != 0) {printf("Unable to make signing pairs"); goto exit;}
|
CheckError("Unable to make signing pairs", exit);
|
||||||
/* - Get Sining pair from KMS - */
|
/* - Get Signing pair from KMS - */
|
||||||
|
|
||||||
/* - Get Issue Recivier Key - */
|
/* - Get Issue Receiver Key - */
|
||||||
ret = wc_MakeSakkeRsk(&kms.kmsSakke, (byte*)Bob.id,
|
ret = wc_MakeSakkeRsk(&kms.kmsSakke, (byte*)Bob.id,
|
||||||
sizeof(bobId), Bob.receiverSecretKey);
|
sizeof(bobId), Bob.receiverSecretKey);
|
||||||
if (ret != 0) {printf("Unable to make receiver secret key"); goto exit;}
|
CheckError("Unable to make receiver secret key", exit);
|
||||||
/* - Get Issue Recivier Key - */
|
/* - Get Issue Receiver Key - */
|
||||||
}
|
}
|
||||||
/* --- Enroll Bob with KMS to get their keys --- */
|
/* --- Enroll Bob with KMS to get their keys --- */
|
||||||
|
|
||||||
|
|
@ -309,7 +334,7 @@ int main(void)
|
||||||
/* - We are handwaving that alice know Bobs Id - */
|
/* - We are handwaving that alice know Bobs Id - */
|
||||||
ret = wc_SetSakkeIdentity(&Alice.publicKeySakke, (byte*)Bob.id,
|
ret = wc_SetSakkeIdentity(&Alice.publicKeySakke, (byte*)Bob.id,
|
||||||
sizeof(bobId));
|
sizeof(bobId));
|
||||||
if (ret != 0) {printf("Could not set Sakkee id"); goto exit;}
|
CheckError("Could not set Sakke id", exit);
|
||||||
/* - We are handwaving that alice know Bobs Id - */
|
/* - We are handwaving that alice know Bobs Id - */
|
||||||
|
|
||||||
/* - Create SSV - */
|
/* - Create SSV - */
|
||||||
|
|
@ -317,17 +342,18 @@ int main(void)
|
||||||
Alice.sharedSecretValueSz = SSV_SZ;
|
Alice.sharedSecretValueSz = SSV_SZ;
|
||||||
ret = wc_GenerateSakkeSSV(&Alice.publicKeySakke, &rng,
|
ret = wc_GenerateSakkeSSV(&Alice.publicKeySakke, &rng,
|
||||||
Alice.sharedSecretValue, &Alice.sharedSecretValueSz);
|
Alice.sharedSecretValue, &Alice.sharedSecretValueSz);
|
||||||
if (ret != 0) {printf("Could not generate SSV"); goto exit;}
|
CheckError("Could not generate SSV", exit);
|
||||||
/* - Create SSV - */
|
/* - Create SSV - */
|
||||||
|
|
||||||
/* - Encapsulate SSV in place - */
|
/* - Encapsulate SSV in place - */
|
||||||
memcpy(Message.payload, Alice.sharedSecretValue,
|
memcpy(Message.payload, Alice.sharedSecretValue,
|
||||||
Alice.sharedSecretValueSz);
|
Alice.sharedSecretValueSz);
|
||||||
Message.authSz = AUTH_SZ;
|
ret = wc_GetSakkeAuthSize(&Alice.publicKeySakke, &Message.authSz);
|
||||||
|
CheckError("Could not get key sz", exit);
|
||||||
ret = wc_MakeSakkeEncapsulatedSSV(&Alice.publicKeySakke,
|
ret = wc_MakeSakkeEncapsulatedSSV(&Alice.publicKeySakke,
|
||||||
WC_HASH_TYPE_SHA256, Message.payload, Alice.sharedSecretValueSz,
|
WC_HASH_TYPE_SHA256, Message.payload, Alice.sharedSecretValueSz,
|
||||||
Message.payload + Alice.sharedSecretValueSz, &Message.authSz);
|
Message.payload + Alice.sharedSecretValueSz, &Message.authSz);
|
||||||
if (ret != 0) {printf("Could not encapsulate SSV"); goto exit;}
|
CheckError("Could not encapsulate SSV", exit);
|
||||||
/* - Encapsulate SSV in place - */
|
/* - Encapsulate SSV in place - */
|
||||||
|
|
||||||
/* - Hash Alices Id - */
|
/* - Hash Alices Id - */
|
||||||
|
|
@ -354,7 +380,7 @@ int main(void)
|
||||||
}
|
}
|
||||||
/* - Sign the Eccsi Hash - */
|
/* - Sign the Eccsi Hash - */
|
||||||
|
|
||||||
if (ret != 0) {printf("Unable to sign payload"); goto exit;}
|
CheckError("Unable to sign payload", exit);
|
||||||
}
|
}
|
||||||
/* - Message is ready to send - */
|
/* - Message is ready to send - */
|
||||||
/* --- Alice Creates Message --- */
|
/* --- Alice Creates Message --- */
|
||||||
|
|
@ -369,46 +395,49 @@ int main(void)
|
||||||
int verified = 0;
|
int verified = 0;
|
||||||
|
|
||||||
/* Bob signs/derives over the same SSV length Alice used. */
|
/* Bob signs/derives over the same SSV length Alice used. */
|
||||||
Bob.dirived_sharedSecretValueSz = SSV_SZ;
|
Bob.derived_sharedSecretValueSz = SSV_SZ;
|
||||||
|
|
||||||
senderPvt = wc_ecc_new_point();
|
senderPvt = wc_ecc_new_point();
|
||||||
if (senderPvt == NULL) {ret = MEMORY_E; goto exit;}
|
if (senderPvt == NULL) {
|
||||||
|
ret = MEMORY_E;
|
||||||
|
goto exit;
|
||||||
|
}
|
||||||
/* - Get Sender Public Validation Token - */
|
/* - Get Sender Public Validation Token - */
|
||||||
ret = wc_DecodeEccsiPvtFromSig(&Bob.publicKeyEccsi,
|
ret = wc_DecodeEccsiPvtFromSig(&Bob.publicKeyEccsi,
|
||||||
Message.signature, Message.signatureSz, senderPvt);
|
Message.signature, Message.signatureSz, senderPvt);
|
||||||
if (ret != 0) {printf("Could not Decode Pvt."); goto BobFail;}
|
CheckError("Could not Decode Pvt.", BobFail);
|
||||||
/* - Get Sender Public Validation Token - */
|
/* - Get Sender Public Validation Token - */
|
||||||
|
|
||||||
/* - Verify the Message - */
|
/* - Verify the Message - */
|
||||||
ret = wc_HashEccsiId(&Bob.publicKeyEccsi, WC_HASH_TYPE_SHA256,
|
ret = wc_HashEccsiId(&Bob.publicKeyEccsi, WC_HASH_TYPE_SHA256,
|
||||||
(byte*)Message.senderId, sizeof(aliceId), senderPvt, hashId,
|
(byte*)Message.senderId, sizeof(aliceId), senderPvt, hashId,
|
||||||
&hashIdSz);
|
&hashIdSz);
|
||||||
if (ret != 0) {printf("Could not Hash Sender Id."); goto BobFail;}
|
CheckError("Could not Hash Sender Id.", BobFail);
|
||||||
ret = wc_SetEccsiHash(&Bob.publicKeyEccsi, hashId, hashIdSz);
|
ret = wc_SetEccsiHash(&Bob.publicKeyEccsi, hashId, hashIdSz);
|
||||||
if (ret != 0) {printf("Could not Set Hash."); goto BobFail;}
|
CheckError("Could not Set Hash.", BobFail);
|
||||||
ret = wc_VerifyEccsiHash(&Bob.publicKeyEccsi, WC_HASH_TYPE_SHA256,
|
ret = wc_VerifyEccsiHash(&Bob.publicKeyEccsi, WC_HASH_TYPE_SHA256,
|
||||||
Message.payload,
|
Message.payload,
|
||||||
Bob.dirived_sharedSecretValueSz + Message.authSz,
|
Bob.derived_sharedSecretValueSz + Message.authSz,
|
||||||
Message.signature, Message.signatureSz, &verified);
|
Message.signature, Message.signatureSz, &verified);
|
||||||
/* A bad signature is reported through "verified", not through ret. */
|
/* A bad signature is reported through "verified", not through ret. */
|
||||||
if (ret == 0 && !verified) ret = SIG_VERIFY_E;
|
if (ret == 0 && !verified) ret = SIG_VERIFY_E;
|
||||||
if (ret != 0) {printf("Could not Verify Message."); goto BobFail;}
|
CheckError("Could not Verify Message.", BobFail);
|
||||||
/* - Verify the Message - */
|
/* - Verify the Message - */
|
||||||
|
|
||||||
/* - Get The Shared secret value out of the Message - */
|
/* - Get The Shared secret value out of the Message - */
|
||||||
ret = wc_SetSakkeIdentity(&Bob.publicKeySakke, (const byte*)Bob.id,
|
ret = wc_SetSakkeIdentity(&Bob.publicKeySakke, (const byte*)Bob.id,
|
||||||
sizeof(bobId));
|
sizeof(bobId));
|
||||||
if (ret != 0) {printf("Could not Sakke Id."); goto BobFail;}
|
CheckError("Could not Sakke Id.", BobFail);
|
||||||
ret = wc_SetSakkeRsk(&Bob.publicKeySakke, Bob.receiverSecretKey,
|
ret = wc_SetSakkeRsk(&Bob.publicKeySakke, Bob.receiverSecretKey,
|
||||||
NULL, 0);
|
NULL, 0);
|
||||||
if (ret != 0) {printf("Could Set Sakke Rsk."); goto BobFail;}
|
CheckError("Could Set Sakke Rsk.", BobFail);
|
||||||
memcpy(Bob.dirived_sharedSecretValue, Message.payload,
|
memcpy(Bob.derived_sharedSecretValue, Message.payload,
|
||||||
Bob.dirived_sharedSecretValueSz);
|
Bob.derived_sharedSecretValueSz);
|
||||||
ret = wc_DeriveSakkeSSV(&Bob.publicKeySakke, WC_HASH_TYPE_SHA256,
|
ret = wc_DeriveSakkeSSV(&Bob.publicKeySakke, WC_HASH_TYPE_SHA256,
|
||||||
Bob.dirived_sharedSecretValue, Bob.dirived_sharedSecretValueSz,
|
Bob.derived_sharedSecretValue, Bob.derived_sharedSecretValueSz,
|
||||||
Message.payload + Bob.dirived_sharedSecretValueSz,
|
Message.payload + Bob.derived_sharedSecretValueSz,
|
||||||
Message.authSz);
|
Message.authSz);
|
||||||
if (ret != 0) {printf("Could not derive Sakke SSV."); goto BobFail;}
|
CheckError("Could not derive Sakke SSV.", BobFail);
|
||||||
/* - Get The Shared secret value out of the Message - */
|
/* - Get The Shared secret value out of the Message - */
|
||||||
|
|
||||||
/* - Error - */
|
/* - Error - */
|
||||||
|
|
@ -421,7 +450,7 @@ BobFail:
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
if (memcmp(Alice.sharedSecretValue, Bob.dirived_sharedSecretValue,
|
if (memcmp(Alice.sharedSecretValue, Bob.derived_sharedSecretValue,
|
||||||
SSV_SZ) != 0) {
|
SSV_SZ) != 0) {
|
||||||
printf("SSVs differ!\n");
|
printf("SSVs differ!\n");
|
||||||
ret = -1;
|
ret = -1;
|
||||||
|
|
@ -437,6 +466,8 @@ exit:
|
||||||
|
|
||||||
if (Bob.receiverSecretKey != NULL)
|
if (Bob.receiverSecretKey != NULL)
|
||||||
wc_ecc_forcezero_point(Bob.receiverSecretKey);
|
wc_ecc_forcezero_point(Bob.receiverSecretKey);
|
||||||
|
wc_ForceZero(Bob.derived_sharedSecretValue,
|
||||||
|
sizeof(Bob.derived_sharedSecretValue));
|
||||||
if (Bob.publicValidationToken != NULL)
|
if (Bob.publicValidationToken != NULL)
|
||||||
wc_ecc_del_point(Bob.publicValidationToken);
|
wc_ecc_del_point(Bob.publicValidationToken);
|
||||||
if (Bob.receiverSecretKey != NULL)
|
if (Bob.receiverSecretKey != NULL)
|
||||||
|
|
@ -450,6 +481,8 @@ exit:
|
||||||
|
|
||||||
if (Alice.receiverSecretKey != NULL)
|
if (Alice.receiverSecretKey != NULL)
|
||||||
wc_ecc_forcezero_point(Alice.receiverSecretKey);
|
wc_ecc_forcezero_point(Alice.receiverSecretKey);
|
||||||
|
wc_ForceZero(Alice.sharedSecretValue,
|
||||||
|
sizeof(Alice.sharedSecretValue));
|
||||||
if (Alice.publicValidationToken != NULL)
|
if (Alice.publicValidationToken != NULL)
|
||||||
wc_ecc_del_point(Alice.publicValidationToken);
|
wc_ecc_del_point(Alice.publicValidationToken);
|
||||||
if (Alice.receiverSecretKey != NULL)
|
if (Alice.receiverSecretKey != NULL)
|
||||||
|
|
|
||||||
|
|
@ -99,7 +99,7 @@ int main(int argc, char* argv[])
|
||||||
WC_RNG rng;
|
WC_RNG rng;
|
||||||
int rngInit = 0;
|
int rngInit = 0;
|
||||||
byte* sig = NULL;
|
byte* sig = NULL;
|
||||||
byte pub[64];
|
byte pub[WC_SLHDSA_MAX_PUB_LEN];
|
||||||
word32 pubLen = (word32)sizeof(pub);
|
word32 pubLen = (word32)sizeof(pub);
|
||||||
word32 sigLen = 0;
|
word32 sigLen = 0;
|
||||||
int sigSz;
|
int sigSz;
|
||||||
|
|
@ -195,19 +195,25 @@ int main(int argc, char* argv[])
|
||||||
{
|
{
|
||||||
SlhDsaKey pubKey;
|
SlhDsaKey pubKey;
|
||||||
ret = wc_SlhDsaKey_Init(&pubKey, param, NULL, INVALID_DEVID);
|
ret = wc_SlhDsaKey_Init(&pubKey, param, NULL, INVALID_DEVID);
|
||||||
if (ret != 0) goto exit;
|
if (ret != 0)
|
||||||
|
goto exit;
|
||||||
/* - only have pub key - */
|
/* - only have pub key - */
|
||||||
wc_SlhDsaKey_ImportPublic(&pubKey, pub, pubLen);
|
ret = wc_SlhDsaKey_ImportPublic(&pubKey, pub, pubLen);
|
||||||
|
if (ret != 0) {
|
||||||
|
printf("error: wc_SlhDsaKey_ImportPublic returned %d\n", ret);
|
||||||
|
wc_SlhDsaKey_Free(&pubKey);
|
||||||
|
goto exit;
|
||||||
|
}
|
||||||
ret = wc_SlhDsaKey_Verify(&pubKey, NULL, 0, (const byte*)msg,
|
ret = wc_SlhDsaKey_Verify(&pubKey, NULL, 0, (const byte*)msg,
|
||||||
(word32)strlen(msg), sig, sigLen);
|
(word32)strlen(msg), sig, sigLen);
|
||||||
if (ret != 0) {
|
if (ret != 0) {
|
||||||
printf("error: wc_SlhDsaKey_Verify returned %d\n", ret);
|
printf("error: wc_SlhDsaKey_Verify returned %d\n", ret);
|
||||||
wc_SlhDsaKey_Free(&pubKey);
|
wc_SlhDsaKey_Free(&pubKey);
|
||||||
goto exit;
|
goto exit;
|
||||||
}
|
}
|
||||||
printf("info: verify message good\n");
|
printf("info: verify message good\n");
|
||||||
|
|
||||||
/* A modified message must fail verification. */
|
/* A modified signature must fail verification. */
|
||||||
sig[0] ^= 0x80;
|
sig[0] ^= 0x80;
|
||||||
ret = wc_SlhDsaKey_Verify(&pubKey, NULL, 0, (const byte*)msg,
|
ret = wc_SlhDsaKey_Verify(&pubKey, NULL, 0, (const byte*)msg,
|
||||||
(word32)strlen(msg), sig, sigLen);
|
(word32)strlen(msg), sig, sigLen);
|
||||||
|
|
@ -220,6 +226,8 @@ int main(int argc, char* argv[])
|
||||||
|
|
||||||
wc_SlhDsaKey_Free(&pubKey);
|
wc_SlhDsaKey_Free(&pubKey);
|
||||||
}
|
}
|
||||||
|
/* --- Verify with public key --- */
|
||||||
|
|
||||||
printf("info: corrupted signature rejected as expected\n");
|
printf("info: corrupted signature rejected as expected\n");
|
||||||
|
|
||||||
ret = 0;
|
ret = 0;
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue