mirror of
https://github.com/FreeRTOS/FreeRTOS.git
synced 2026-10-07 02:53:32 +08:00
+89
-85
File diff suppressed because it is too large
Load Diff
Executable → Regular
Executable → Regular
+6
-1
@@ -48,10 +48,15 @@
|
||||
/* FreeRTOS-IoT-Libraries-LTS-Beta1 includes. */
|
||||
#include "iot_error.h"
|
||||
#include "platform/iot_network_freertos.h"
|
||||
#include "mbedtls/threading.h"
|
||||
#include "threading_alt.h"
|
||||
#include "iot_pkcs11.h"
|
||||
#include "iot_tls.h"
|
||||
|
||||
#if !defined( MBEDTLS_CONFIG_FILE )
|
||||
#include "mbedtls/config.h"
|
||||
#else
|
||||
#include MBEDTLS_CONFIG_FILE
|
||||
#endif
|
||||
|
||||
/* Configure logs for the functions in this file. */
|
||||
#ifdef IOT_LOG_LEVEL_NETWORK
|
||||
|
||||
+28
-13
@@ -41,6 +41,8 @@
|
||||
/**
|
||||
* @functions_page{pkcs11_pal,PKCS #11 PAL, PKCS #11 PAL}
|
||||
* @functions_brief{PKCS #11 PAL Layer}
|
||||
* - @function_name{pkcs11_pal_function_initialize}
|
||||
* @function_brief{pkcs11_pal_function_initialize}
|
||||
* - @function_name{pkcs11_pal_function_saveobject}
|
||||
* @function_brief{pkcs11_pal_function_saveobject}
|
||||
* - @function_name{pkcs11_pal_function_destroyobject}
|
||||
@@ -71,6 +73,19 @@
|
||||
* @copydoc PKCS11_PAL_GetObjectValueCleanup
|
||||
*/
|
||||
|
||||
/**
|
||||
* @brief Initializes the PKCS #11 PAL.
|
||||
*
|
||||
* This is always called first in C_Initialize if the module is not already
|
||||
* initialized.
|
||||
*
|
||||
* @return CKR_OK on success.
|
||||
* CKR_FUNCTION_FAILED on failure.
|
||||
*/
|
||||
/* @[declare_pkcs11_pal_initialize] */
|
||||
CK_RV PKCS11_PAL_Initialize( void );
|
||||
/* @[declare_pkcs11_pal_initialize] */
|
||||
|
||||
/**
|
||||
* @brief Saves an object in non-volatile storage.
|
||||
*
|
||||
@@ -85,8 +100,8 @@
|
||||
*/
|
||||
/* @[declare_pkcs11_pal_saveobject] */
|
||||
CK_OBJECT_HANDLE PKCS11_PAL_SaveObject( CK_ATTRIBUTE_PTR pxLabel,
|
||||
uint8_t * pucData,
|
||||
uint32_t ulDataSize );
|
||||
CK_BYTE_PTR pucData,
|
||||
CK_ULONG ulDataSize );
|
||||
/* @[declare_pkcs11_pal_saveobject] */
|
||||
|
||||
/**
|
||||
@@ -104,7 +119,7 @@ CK_RV PKCS11_PAL_DestroyObject( CK_OBJECT_HANDLE xHandle );
|
||||
* Port-specific object handle retrieval.
|
||||
*
|
||||
*
|
||||
* @param[in] pLabel Pointer to the label of the object
|
||||
* @param[in] pxLabel Pointer to the label of the object
|
||||
* who's handle should be found.
|
||||
* @param[in] usLength The length of the label, in bytes.
|
||||
*
|
||||
@@ -112,8 +127,8 @@ CK_RV PKCS11_PAL_DestroyObject( CK_OBJECT_HANDLE xHandle );
|
||||
* Returns eInvalidHandle if unsuccessful.
|
||||
*/
|
||||
/* @[declare_pkcs11_pal_findobject] */
|
||||
CK_OBJECT_HANDLE PKCS11_PAL_FindObject( uint8_t * pLabel,
|
||||
uint8_t usLength );
|
||||
CK_OBJECT_HANDLE PKCS11_PAL_FindObject( CK_BYTE_PTR pxLabel,
|
||||
CK_ULONG usLength );
|
||||
/* @[declare_pkcs11_pal_findobject] */
|
||||
|
||||
|
||||
@@ -141,23 +156,23 @@ CK_OBJECT_HANDLE PKCS11_PAL_FindObject( uint8_t * pLabel,
|
||||
* error.
|
||||
*/
|
||||
/* @[declare_pkcs11_pal_getobjectvalue] */
|
||||
BaseType_t PKCS11_PAL_GetObjectValue( CK_OBJECT_HANDLE xHandle,
|
||||
uint8_t ** ppucData,
|
||||
uint32_t * pulDataSize,
|
||||
CK_BBOOL * pIsPrivate );
|
||||
CK_RV PKCS11_PAL_GetObjectValue( CK_OBJECT_HANDLE xHandle,
|
||||
CK_BYTE_PTR * ppucData,
|
||||
CK_ULONG_PTR pulDataSize,
|
||||
CK_BBOOL * pIsPrivate );
|
||||
/* @[declare_pkcs11_pal_getobjectvalue] */
|
||||
|
||||
/**
|
||||
* @brief Cleanup after PKCS11_GetObjectValue().
|
||||
*
|
||||
* @param[in] pucBuffer The buffer to free.
|
||||
* @param[in] pucData The buffer to free.
|
||||
* (*ppucData from PKCS11_PAL_GetObjectValue())
|
||||
* @param[in] ulBufferSize The length of the buffer to free.
|
||||
* @param[in] ulDatasize The length of the buffer to free.
|
||||
* (*pulDataSize from PKCS11_PAL_GetObjectValue())
|
||||
*/
|
||||
/* @[declare_pkcs11_pal_getobjectvaluecleanup] */
|
||||
void PKCS11_PAL_GetObjectValueCleanup( uint8_t * pucBuffer,
|
||||
uint32_t ulBufferSize );
|
||||
void PKCS11_PAL_GetObjectValueCleanup( CK_BYTE_PTR pucData,
|
||||
CK_ULONG ulDataSize );
|
||||
/* @[declare_pkcs11_pal_getobjectvaluecleanup] */
|
||||
|
||||
#endif /* IOT_PKCS11_PAL include guard. */
|
||||
|
||||
+901
-673
File diff suppressed because it is too large
Load Diff
+15
-12
@@ -35,7 +35,6 @@
|
||||
/*-----------------------------------------------------------*/
|
||||
|
||||
#include "FreeRTOS.h"
|
||||
#include "FreeRTOSIPConfig.h"
|
||||
#include "iot_pkcs11.h"
|
||||
#include "iot_pkcs11_config.h"
|
||||
|
||||
@@ -58,7 +57,7 @@
|
||||
* @brief PKCS #11 logging macro.
|
||||
*
|
||||
*/
|
||||
#define PKCS11_PAL_PRINT( X ) vLoggingPrintf X
|
||||
#define PKCS11_PAL_PRINT( X ) configPRINTF( X )
|
||||
|
||||
/**
|
||||
* @ingroup pkcs11_enums
|
||||
@@ -152,10 +151,14 @@ void prvLabelToFilenameHandle( uint8_t * pcLabel,
|
||||
|
||||
/*-----------------------------------------------------------*/
|
||||
|
||||
CK_RV PKCS11_PAL_Initialize( void )
|
||||
{
|
||||
return CKR_OK;
|
||||
}
|
||||
|
||||
CK_OBJECT_HANDLE PKCS11_PAL_SaveObject( CK_ATTRIBUTE_PTR pxLabel,
|
||||
uint8_t * pucData,
|
||||
uint32_t ulDataSize )
|
||||
CK_BYTE_PTR pucData,
|
||||
CK_ULONG ulDataSize )
|
||||
{
|
||||
uint32_t ulStatus = 0;
|
||||
HANDLE hFile = INVALID_HANDLE_VALUE;
|
||||
@@ -211,8 +214,8 @@ CK_OBJECT_HANDLE PKCS11_PAL_SaveObject( CK_ATTRIBUTE_PTR pxLabel,
|
||||
/*-----------------------------------------------------------*/
|
||||
|
||||
|
||||
CK_OBJECT_HANDLE PKCS11_PAL_FindObject( uint8_t * pLabel,
|
||||
uint8_t usLength )
|
||||
CK_OBJECT_HANDLE PKCS11_PAL_FindObject( CK_BYTE_PTR pxLabel,
|
||||
CK_ULONG usLength )
|
||||
{
|
||||
/* Avoid compiler warnings about unused variables. */
|
||||
( void ) usLength;
|
||||
@@ -221,7 +224,7 @@ CK_OBJECT_HANDLE PKCS11_PAL_FindObject( uint8_t * pLabel,
|
||||
char * pcFileName = NULL;
|
||||
|
||||
/* Converts a label to its respective filename and handle. */
|
||||
prvLabelToFilenameHandle( pLabel,
|
||||
prvLabelToFilenameHandle( pxLabel,
|
||||
&pcFileName,
|
||||
&xHandle );
|
||||
|
||||
@@ -236,9 +239,9 @@ CK_OBJECT_HANDLE PKCS11_PAL_FindObject( uint8_t * pLabel,
|
||||
/*-----------------------------------------------------------*/
|
||||
|
||||
CK_RV PKCS11_PAL_GetObjectValue( CK_OBJECT_HANDLE xHandle,
|
||||
uint8_t ** ppucData,
|
||||
uint32_t * pulDataSize,
|
||||
CK_BBOOL * pIsPrivate )
|
||||
CK_BYTE_PTR * ppucData,
|
||||
CK_ULONG_PTR pulDataSize,
|
||||
CK_BBOOL * pIsPrivate )
|
||||
{
|
||||
CK_RV ulReturn = CKR_OK;
|
||||
uint32_t ulDriverReturn = 0;
|
||||
@@ -340,8 +343,8 @@ CK_RV PKCS11_PAL_GetObjectValue( CK_OBJECT_HANDLE xHandle,
|
||||
|
||||
/*-----------------------------------------------------------*/
|
||||
|
||||
void PKCS11_PAL_GetObjectValueCleanup( uint8_t * pucData,
|
||||
uint32_t ulDataSize )
|
||||
void PKCS11_PAL_GetObjectValueCleanup( CK_BYTE_PTR pucData,
|
||||
CK_ULONG ulDataSize )
|
||||
{
|
||||
/* Unused parameters. */
|
||||
( void ) ulDataSize;
|
||||
|
||||
+7
-7
@@ -80,19 +80,19 @@
|
||||
/**
|
||||
* @brief Length of a SHA256 digest, in bytes.
|
||||
*/
|
||||
#define pkcs11SHA256_DIGEST_LENGTH 32
|
||||
#define pkcs11SHA256_DIGEST_LENGTH 32UL
|
||||
|
||||
/**
|
||||
* @brief Length of a curve P-256 ECDSA signature, in bytes.
|
||||
* PKCS #11 EC signatures are represented as a 32-bit R followed
|
||||
* by a 32-bit S value, and not ASN.1 encoded.
|
||||
*/
|
||||
#define pkcs11ECDSA_P256_SIGNATURE_LENGTH 64
|
||||
#define pkcs11ECDSA_P256_SIGNATURE_LENGTH 64UL
|
||||
|
||||
/**
|
||||
* @brief Key strength for elliptic-curve P-256.
|
||||
*/
|
||||
#define pkcs11ECDSA_P256_KEY_BITS 256
|
||||
#define pkcs11ECDSA_P256_KEY_BITS 256UL
|
||||
|
||||
/**
|
||||
* @brief Public exponent for RSA.
|
||||
@@ -103,12 +103,12 @@
|
||||
* @brief The number of bits in the RSA-2048 modulus.
|
||||
*
|
||||
*/
|
||||
#define pkcs11RSA_2048_MODULUS_BITS 2048
|
||||
#define pkcs11RSA_2048_MODULUS_BITS 2048UL
|
||||
|
||||
/**
|
||||
* @brief Length of PKCS #11 signature for RSA 2048 key, in bytes.
|
||||
*/
|
||||
#define pkcs11RSA_2048_SIGNATURE_LENGTH ( pkcs11RSA_2048_MODULUS_BITS / 8 )
|
||||
#define pkcs11RSA_2048_SIGNATURE_LENGTH ( pkcs11RSA_2048_MODULUS_BITS / 8UL )
|
||||
|
||||
/**
|
||||
* @brief Length of RSA signature data before padding.
|
||||
@@ -116,7 +116,7 @@
|
||||
* This is calculated by adding the SHA-256 hash len (32) to the 19 bytes in
|
||||
* pkcs11STUFF_APPENDED_TO_RSA_SIG = 51 bytes total.
|
||||
*/
|
||||
#define pkcs11RSA_SIGNATURE_INPUT_LENGTH 51
|
||||
#define pkcs11RSA_SIGNATURE_INPUT_LENGTH 51UL
|
||||
|
||||
/**
|
||||
* @brief Elliptic-curve object identifiers.
|
||||
@@ -127,7 +127,7 @@
|
||||
/**
|
||||
* @brief Maximum length of storage for PKCS #11 label, in bytes.
|
||||
*/
|
||||
#define pkcs11MAX_LABEL_LENGTH 32 /* 31 characters + 1 null terminator. */
|
||||
#define pkcs11MAX_LABEL_LENGTH 32UL /* 31 characters + 1 null terminator. */
|
||||
|
||||
/**
|
||||
* @brief OID for curve P-256.
|
||||
|
||||
+4
-4
@@ -67,8 +67,8 @@
|
||||
* \return 0 on success, -1 on failure.
|
||||
*/
|
||||
/* @[declare_pkcs11_utils_pkimbedtlssignaturetopkcs11signature] */
|
||||
int PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
|
||||
uint8_t * pxMbedSignature );
|
||||
BaseType_t PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
|
||||
const uint8_t * pxMbedSignature );
|
||||
/* @[declare_pkcs11_utils_pkimbedtlssignaturetopkcs11signature] */
|
||||
|
||||
|
||||
@@ -96,7 +96,7 @@ int PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
|
||||
*
|
||||
*/
|
||||
/* @[declare_pkcs11_utils_pkipkcs11signaturetombedtlssignature] */
|
||||
int PKI_pkcs11SignatureTombedTLSSignature( uint8_t * pucSig,
|
||||
size_t * pxSigLen );
|
||||
BaseType_t PKI_pkcs11SignatureTombedTLSSignature( uint8_t * pucSig,
|
||||
size_t * pxSigLen );
|
||||
/* @[declare_pkcs11_utils_pkipkcs11signaturetombedtlssignature] */
|
||||
#endif /* ifndef _IOT_PKI_UTILS_H_ */
|
||||
|
||||
+47
-46
@@ -42,11 +42,11 @@
|
||||
|
||||
/* Convert the EC signature from DER encoded to PKCS #11 format. */
|
||||
/* @[declare pkcs11_utils_pkipkcs11signaturetombedtlssignature] */
|
||||
int PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
|
||||
uint8_t * pxMbedSignature )
|
||||
BaseType_t PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
|
||||
const uint8_t * pxMbedSignature )
|
||||
{
|
||||
int xReturn = 0;
|
||||
uint8_t * pxNextLength;
|
||||
BaseType_t xReturn = 0;
|
||||
const uint8_t * pxNextLength;
|
||||
uint8_t ucSigComponentLength;
|
||||
|
||||
if( ( pxSignaturePKCS == NULL ) || ( pxMbedSignature == NULL ) )
|
||||
@@ -67,26 +67,27 @@ int PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
|
||||
|
||||
/* The new signature will be 64 bytes long (32 bytes for R, 32 bytes for S).
|
||||
* Zero this buffer out in case a component is shorter than 32 bytes. */
|
||||
memset( pxSignaturePKCS, 0, 64 );
|
||||
( void ) memset( pxSignaturePKCS, 0, 64 );
|
||||
|
||||
/********* R Component. *********/
|
||||
|
||||
/* R components are represented by mbedTLS as 33 bytes when the first bit is zero to avoid any sign confusion. */
|
||||
if( ucSigComponentLength == 33 )
|
||||
if( ucSigComponentLength == 33UL )
|
||||
{
|
||||
/* Chop off the leading zero. The first 4 bytes were SEQUENCE, LENGTH, INTEGER, LENGTH, 0x00 padding. */
|
||||
memcpy( pxSignaturePKCS, &pxMbedSignature[ 5 ], 32 );
|
||||
pxNextLength = pxMbedSignature + 5 /* SEQUENCE, LENGTH, INTEGER, LENGTH, leading zero */ + 32 /*(R) */ + 1 /*(S's integer tag) */;
|
||||
( void ) memcpy( pxSignaturePKCS, &pxMbedSignature[ 5 ], 32 );
|
||||
/* SEQUENCE, LENGTH, INTEGER, LENGTH, leading zero, R, S's integer tag */
|
||||
pxNextLength = pxMbedSignature + 5 + 32 + 1;
|
||||
}
|
||||
else
|
||||
{
|
||||
/* The R component is 32 bytes or less. Copy so that it is properly represented as a 32 byte value,
|
||||
* leaving leading 0 pads at beginning if necessary. */
|
||||
memcpy( &pxSignaturePKCS[ 32 - ucSigComponentLength ], /* If the R component is less than 32 bytes, leave the leading zeros. */
|
||||
&pxMbedSignature[ 4 ], /* SEQUENCE, LENGTH, INTEGER, LENGTH, (R component begins as the 5th byte) */
|
||||
ucSigComponentLength );
|
||||
pxNextLength = pxMbedSignature + 4 + ucSigComponentLength + 1; /* Move the pointer to get rid of
|
||||
* SEQUENCE, LENGTH, INTEGER, LENGTH, R Component, S integer tag. */
|
||||
( void ) memcpy( &pxSignaturePKCS[ 32UL - ucSigComponentLength ], /* If the R component is less than 32 bytes, leave the leading zeros. */
|
||||
&pxMbedSignature[ 4 ], /* SEQUENCE, LENGTH, INTEGER, LENGTH, (R component begins as the 5th byte) */
|
||||
ucSigComponentLength );
|
||||
pxNextLength = pxMbedSignature + 4 + ucSigComponentLength + 1; /* Move the pointer to get rid of
|
||||
* SEQUENCE, LENGTH, INTEGER, LENGTH, R Component, S integer tag. */
|
||||
}
|
||||
|
||||
/********** S Component. ***********/
|
||||
@@ -94,19 +95,19 @@ int PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
|
||||
/* Now pxNextLength is pointing to the length of the S component. */
|
||||
ucSigComponentLength = pxNextLength[ 0 ];
|
||||
|
||||
if( ucSigComponentLength == 33 )
|
||||
if( ucSigComponentLength == 33UL )
|
||||
{
|
||||
memcpy( &pxSignaturePKCS[ 32 ],
|
||||
&pxNextLength[ 2 ], /*LENGTH (of S component), 0x00 padding, S component is 3rd byte - we want to skip the leading zero. */
|
||||
32 );
|
||||
( void ) memcpy( &pxSignaturePKCS[ 32 ],
|
||||
&pxNextLength[ 2 ], /*LENGTH (of S component), 0x00 padding, S component is 3rd byte - we want to skip the leading zero. */
|
||||
32 );
|
||||
}
|
||||
else
|
||||
{
|
||||
/* The S component is 32 bytes or less. Copy so that it is properly represented as a 32 byte value,
|
||||
* leaving leading 0 pads at beginning if necessary. */
|
||||
memcpy( &pxSignaturePKCS[ 64 - ucSigComponentLength ],
|
||||
&pxNextLength[ 1 ],
|
||||
ucSigComponentLength );
|
||||
( void ) memcpy( &pxSignaturePKCS[ 64UL - ucSigComponentLength ],
|
||||
&pxNextLength[ 1 ],
|
||||
ucSigComponentLength );
|
||||
}
|
||||
}
|
||||
|
||||
@@ -118,21 +119,21 @@ int PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
|
||||
|
||||
/* Convert an EC signature from PKCS #11 format to DER encoded. */
|
||||
/* @[declare pkcs11_utils_pkimbedtlssignaturetopkcs11signature] */
|
||||
int PKI_pkcs11SignatureTombedTLSSignature( uint8_t * pucSig,
|
||||
size_t * pxSigLen )
|
||||
BaseType_t PKI_pkcs11SignatureTombedTLSSignature( uint8_t * pucSig,
|
||||
size_t * pxSigLen )
|
||||
{
|
||||
int xResult = 0;
|
||||
BaseType_t xReturn = 0;
|
||||
uint8_t * pucSigPtr;
|
||||
uint8_t ucTemp[ 64 ] = { 0 }; /* A temporary buffer for the pre-formatted signature. */
|
||||
|
||||
if( ( pucSig == NULL ) || ( pxSigLen == NULL ) )
|
||||
{
|
||||
xResult = FAILURE;
|
||||
xReturn = FAILURE;
|
||||
}
|
||||
|
||||
if( xResult == 0 )
|
||||
if( xReturn == 0 )
|
||||
{
|
||||
memcpy( ucTemp, pucSig, 64 );
|
||||
( void ) memcpy( ucTemp, pucSig, 64 );
|
||||
|
||||
|
||||
/* The ASN.1 encoded signature has the format
|
||||
@@ -152,19 +153,19 @@ int PKI_pkcs11SignatureTombedTLSSignature( uint8_t * pucSig,
|
||||
|
||||
/* If the first bit is one, pre-append a 00 byte.
|
||||
* This prevents the number from being interpreted as negative. */
|
||||
if( ucTemp[ 0 ] & 0x80 )
|
||||
if( ( ucTemp[ 0 ] & 0x80UL ) == 0x80UL )
|
||||
{
|
||||
pucSig[ 1 ]++; /* Increment the length of the structure to account for the 0x00 pad. */
|
||||
pucSig[ 3 ] = 0x21; /* Increment the length of the R value to account for the 0x00 pad. */
|
||||
pucSig[ 4 ] = 0x0; /* Write the 0x00 pad. */
|
||||
memcpy( &pucSig[ 5 ], ucTemp, 32 ); /* Copy the 32-byte R value. */
|
||||
pucSigPtr = pucSig + 33; /* Increment the pointer to compensate for padded R length. */
|
||||
pucSig[ 1 ]++; /* Increment the length of the structure to account for the 0x00 pad. */
|
||||
pucSig[ 3 ] = 0x21; /* Increment the length of the R value to account for the 0x00 pad. */
|
||||
pucSig[ 4 ] = 0x0; /* Write the 0x00 pad. */
|
||||
( void ) memcpy( &pucSig[ 5 ], ucTemp, 32 ); /* Copy the 32-byte R value. */
|
||||
pucSigPtr = pucSig + 33; /* Increment the pointer to compensate for padded R length. */
|
||||
}
|
||||
else
|
||||
{
|
||||
pucSig[ 3 ] = 0x20; /* R length with be 32 bytes. */
|
||||
memcpy( &pucSig[ 4 ], ucTemp, 32 ); /* Copy 32 bytes of R into the signature buffer. */
|
||||
pucSigPtr = pucSig + 32; /* Increment the pointer for 32 byte R length. */
|
||||
pucSig[ 3 ] = 0x20; /* R length with be 32 bytes. */
|
||||
( void ) memcpy( &pucSig[ 4 ], ucTemp, 32 ); /* Copy 32 bytes of R into the signature buffer. */
|
||||
pucSigPtr = pucSig + 32; /* Increment the pointer for 32 byte R length. */
|
||||
}
|
||||
|
||||
pucSigPtr += 4; /* Increment the pointer to offset the SEQUENCE, LENGTH, R-INTEGER, LENGTH. */
|
||||
@@ -175,27 +176,27 @@ int PKI_pkcs11SignatureTombedTLSSignature( uint8_t * pucSig,
|
||||
|
||||
/* If the first bit is one, pre-append a 00 byte.
|
||||
* This prevents the number from being interpreted as negative. */
|
||||
if( ucTemp[ 32 ] & 0x80 )
|
||||
if( ( ucTemp[ 32 ] & 0x80UL ) == 0x80UL )
|
||||
{
|
||||
pucSig[ 1 ]++; /* Increment the length of the structure to account for the 0x00 pad. */
|
||||
pucSigPtr[ 0 ] = 0x21; /* Increment the length of the S value to account for the 0x00 pad. */
|
||||
pucSigPtr[ 1 ] = 0x00; /* Write the 0x00 pad. */
|
||||
pucSigPtr += 2; /* pucSigPtr was pointing at the S-length. Increment by 2 to hop over length and 0 padding. */
|
||||
pucSig[ 1 ]++; /* Increment the length of the structure to account for the 0x00 pad. */
|
||||
pucSigPtr[ 0 ] = 0x21; /* Increment the length of the S value to account for the 0x00 pad. */
|
||||
pucSigPtr[ 1 ] = 0x00; /* Write the 0x00 pad. */
|
||||
pucSigPtr += 2; /* pucSigPtr was pointing at the S-length. Increment by 2 to hop over length and 0 padding. */
|
||||
|
||||
memcpy( pucSigPtr, &ucTemp[ 32 ], 32 ); /* Copy the S value. */
|
||||
( void ) memcpy( pucSigPtr, &ucTemp[ 32 ], 32 ); /* Copy the S value. */
|
||||
}
|
||||
else
|
||||
{
|
||||
pucSigPtr[ 0 ] = 0x20; /* S length will be 32 bytes. */
|
||||
pucSigPtr++; /* Hop pointer over the length byte. */
|
||||
memcpy( pucSigPtr, &ucTemp[ 32 ], 32 ); /* Copy the S value. */
|
||||
pucSigPtr[ 0 ] = 0x20; /* S length will be 32 bytes. */
|
||||
pucSigPtr++; /* Hop pointer over the length byte. */
|
||||
( void ) memcpy( pucSigPtr, &ucTemp[ 32 ], 32 ); /* Copy the S value. */
|
||||
}
|
||||
|
||||
/* The total signature length is the length of the R and S integers plus 2 bytes for
|
||||
* the SEQUENCE and LENGTH wrapping the entire struct. */
|
||||
*pxSigLen = pucSig[ 1 ] + 2;
|
||||
*pxSigLen = pucSig[ 1 ] + 2UL;
|
||||
}
|
||||
|
||||
return xResult;
|
||||
return xReturn;
|
||||
}
|
||||
/* @[declare pkcs11_utils_pkimbedtlssignaturetopkcs11signature] */
|
||||
|
||||
Reference in New Issue
Block a user