Port the AWS Fleet Provisioning demo from the CSDK (#724)

* Add fleet provisioning and tinycbor submodules

* Copy demo files from FP in CSDK and the Defender Demo

* Modify FP demo files to function in FreeRTOS

* Update styling and formatting of demo files to match FreeRTOS conventions

Co-authored-by: Archit Gupta <71798289+archigup@users.noreply.github.com>
This commit is contained in:
johnrhen
2021-12-08 13:17:00 -08:00
committed by GitHub
co-authored by Archit Gupta
parent eb9caf9d98
commit c1266ddb60
26 changed files with 6750 additions and 9 deletions
+6
View File
@@ -64,3 +64,9 @@
[submodule "FreeRTOS-Plus/Source/FreeRTOS-Cellular-Interface"]
path = FreeRTOS-Plus/Source/FreeRTOS-Cellular-Interface
url = https://github.com/FreeRTOS/Lab-Project-FreeRTOS-Cellular-Library.git
[submodule "FreeRTOS-Plus/ThirdParty/tinycbor"]
path = FreeRTOS-Plus/ThirdParty/tinycbor
url = https://github.com/intel/tinycbor.git
[submodule "FreeRTOS-Plus/Source/AWS/fleet-provisioning"]
path = FreeRTOS-Plus/Source/AWS/fleet-provisioning
url = https://github.com/aws/Fleet-Provisioning-for-AWS-IoT-embedded-sdk.git
@@ -0,0 +1,95 @@
/*
* FreeRTOS V202111.00
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to
* use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
* the Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* https://www.FreeRTOS.org
* https://github.com/FreeRTOS
*
*/
#ifndef CORE_MQTT_CONFIG_H
#define CORE_MQTT_CONFIG_H
/**************************************************/
/******* DO NOT CHANGE the following order ********/
/**************************************************/
/* Include logging header files and define logging macros in the following order:
* 1. Include the header file "logging_levels.h".
* 2. Define the LIBRARY_LOG_NAME and LIBRARY_LOG_LEVEL macros depending on
* the logging configuration for MQTT.
* 3. Include the header file "logging_stack.h", if logging is enabled for MQTT.
*/
#include "logging_levels.h"
/* Logging configuration for the MQTT library. */
#ifndef LIBRARY_LOG_NAME
#define LIBRARY_LOG_NAME "MQTT"
#endif
#ifndef LIBRARY_LOG_LEVEL
#define LIBRARY_LOG_LEVEL LOG_WARN
#endif
/* Prototype for the function used to print to console on Windows simulator
* of FreeRTOS.
* The function prints to the console before the network is connected;
* then a UDP port after the network has connected. */
extern void vLoggingPrintf( const char * pcFormatString,
... );
/* Map the SdkLog macro to the logging function to enable logging
* on Windows simulator. */
#ifndef SdkLog
#define SdkLog( message ) vLoggingPrintf message
#endif
#include "logging_stack.h"
/************ End of logging configuration ****************/
/**
* @brief Determines the maximum number of MQTT PUBLISH messages, pending
* acknowledgement at a time, that are supported for incoming and outgoing
* direction of messages, separately.
*
* QoS 1 and 2 MQTT PUBLISHes require acknowledgement from the server before
* they can be completed. While they are awaiting the acknowledgement, the
* client must maintain information about their state. The value of this
* macro sets the limit on how many simultaneous PUBLISH states an MQTT
* context maintains, separately, for both incoming and outgoing direction of
* PUBLISHes.
*
* @note The MQTT context maintains separate state records for outgoing
* and incoming PUBLISHes, and thus, 2 * MQTT_STATE_ARRAY_MAX_COUNT amount
* of memory is statically allocated for the state records.
*/
#define MQTT_STATE_ARRAY_MAX_COUNT ( 10U )
/**
* @brief Number of milliseconds to wait for a ping response to a ping
* request as part of the keep-alive mechanism.
*
* If a ping response is not received before this timeout, then
* #MQTT_ProcessLoop will return #MQTTKeepAliveTimeout.
*/
#define MQTT_PINGRESP_TIMEOUT_MS ( 5000U )
#endif /* ifndef CORE_MQTT_CONFIG_H_ */
@@ -0,0 +1,31 @@
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"iot:Connect"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"iot:Publish",
"iot:Receive"
],
"Resource": [
"arn:aws:iot:<aws-region>:<aws-account-id>:topic/$aws/certificates/create-from-csr/*",
"arn:aws:iot:<aws-region>:<aws-account-id>:topic/$aws/provisioning-templates/<template-name>/provision/*"
]
},
{
"Effect": "Allow",
"Action": "iot:Subscribe",
"Resource": [
"arn:aws:iot:<aws-region>:<aws-account-id>:topicfilter/$aws/certificates/create-from-csr/*",
"arn:aws:iot:<aws-region>:<aws-account-id>:topicfilter/$aws/provisioning-templates/<template-name>/provision/*"
]
}
]
}
@@ -0,0 +1,54 @@
{
"Parameters": {
"SerialNumber": {
"Type": "String"
},
"AWS::IoT::Certificate::Id": {
"Type": "String"
}
},
"Resources": {
"certificate": {
"Properties": {
"CertificateId": {
"Ref": "AWS::IoT::Certificate::Id"
},
"Status": "Active"
},
"Type": "AWS::IoT::Certificate"
},
"policy": {
"Properties": {
"PolicyName": "<provisioned-thing-policy>"
},
"Type": "AWS::IoT::Policy"
},
"thing": {
"OverrideSettings": {
"AttributePayload": "MERGE",
"ThingGroups": "DO_NOTHING",
"ThingTypeName": "REPLACE"
},
"Properties": {
"AttributePayload": {},
"ThingGroups": [],
"ThingName": {
"Fn::Join": [
"",
[
"fp_demo_",
{
"Ref": "SerialNumber"
}
]
]
},
"ThingTypeName": "fp_demo_things"
},
"Type": "AWS::IoT::Thing"
}
},
"DeviceConfiguration": {
"Foo": "Bar"
}
}
@@ -0,0 +1,68 @@
/*
* FreeRTOS V202111.00
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to
* use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
* the Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* https://www.FreeRTOS.org
* https://github.com/FreeRTOS
*
*/
#ifndef FLEET_PROVISIONING_CONFIG_H_
#define FLEET_PROVISIONING_CONFIG_H_
/**************************************************/
/******* DO NOT CHANGE the following order ********/
/**************************************************/
/* Include logging header files and define logging macros in the following order:
* 1. Include the header file "logging_levels.h".
* 2. Define the LIBRARY_LOG_NAME and LIBRARY_LOG_LEVEL macros.
* 3. Include the header file "logging_stack.h".
*/
#include "logging_levels.h"
/* Logging configuration for the Fleet Provisioning library. */
#ifndef LIBRARY_LOG_NAME
#define LIBRARY_LOG_NAME "FleetProvisioning"
#endif
#ifndef LIBRARY_LOG_LEVEL
#define LIBRARY_LOG_LEVEL LOG_INFO
#endif
/* Prototype for the function used to print to console on Windows simulator
* of FreeRTOS.
* The function prints to the console before the network is connected;
* then a UDP port after the network has connected. */
extern void vLoggingPrintf( const char * pcFormatString,
... );
/* Map the SdkLog macro to the logging function to enable logging
* on Windows simulator. */
#ifndef SdkLog
#define SdkLog( message ) vLoggingPrintf message
#endif
#include "logging_stack.h"
/************ End of logging configuration ****************/
#endif /* ifndef FLEET_PROVISIONING_CONFIG_H_ */
@@ -0,0 +1,25 @@
Microsoft Visual Studio Solution File, Format Version 12.00
# Visual Studio Version 16
VisualStudioVersion = 16.0.31729.503
MinimumVisualStudioVersion = 10.0.40219.1
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "RTOSDemo", "WIN32.vcxproj", "{C686325E-3261-42F7-AEB1-DDE5280E1CEB}"
EndProject
Global
GlobalSection(SolutionConfigurationPlatforms) = preSolution
Debug|x86 = Debug|x86
Release|x86 = Release|x86
EndGlobalSection
GlobalSection(ProjectConfigurationPlatforms) = postSolution
{C686325E-3261-42F7-AEB1-DDE5280E1CEB}.Debug|x86.ActiveCfg = Debug|Win32
{C686325E-3261-42F7-AEB1-DDE5280E1CEB}.Debug|x86.Build.0 = Debug|Win32
{C686325E-3261-42F7-AEB1-DDE5280E1CEB}.Release|x86.ActiveCfg = Release|Win32
{C686325E-3261-42F7-AEB1-DDE5280E1CEB}.Release|x86.Build.0 = Release|Win32
EndGlobalSection
GlobalSection(SolutionProperties) = preSolution
HideSolutionNode = FALSE
EndGlobalSection
GlobalSection(ExtensibilityGlobals) = postSolution
SolutionGuid = {573E92F2-7674-4EE8-A7FD-8128A495333D}
EndGlobalSection
EndGlobal
@@ -0,0 +1,63 @@
#!/usr/bin/env python
import argparse
from cryptography import x509
from cryptography.hazmat.backends import default_backend
from cryptography.hazmat.primitives import serialization
KEY_OUT_NAME = "corePKCS11_Claim_Key.dat"
CERT_OUT_NAME = "corePKCS11_Claim_Certificate.dat"
def convert_pem_to_der(cert_file, key_file):
# Convert certificate from PEM to DER
print("Converting format to DER format...")
with open(key_file, "rb") as key:
print("Starting key PEM to DER conversion.")
pemkey = serialization.load_pem_private_key(key.read(), None, default_backend())
key_der = pemkey.private_bytes(
serialization.Encoding.DER,
serialization.PrivateFormat.TraditionalOpenSSL,
serialization.NoEncryption(),
)
with open(KEY_OUT_NAME, "wb") as key_out:
key_out.write(key_der)
print(
f"Successfully converted key PEM to DER. Output file named: {KEY_OUT_NAME}"
)
print("Starting certificate pem conversion.")
with open(cert_file, "rb") as cert:
cert = x509.load_pem_x509_certificate(cert.read(), default_backend())
with open(CERT_OUT_NAME, "wb") as cert_out:
cert_out.write(cert.public_bytes(serialization.Encoding.DER))
print(
f"Successfully converted certificate PEM to DER. Output file named: {CERT_OUT_NAME}"
)
def main(args):
convert_pem_to_der(cert_file=args.cert_file, key_file=args.key_file)
if __name__ == "__main__":
arg_parser = argparse.ArgumentParser(
description="This script converts passed in PEM format certificates and keys into the binary DER format."
)
arg_parser.add_argument(
"-c",
"--cert_file",
type=str,
help="Specify the name of the generated certificate file.",
required=True,
)
arg_parser.add_argument(
"-k",
"--key_file",
type=str,
help="Specify the name of the generated key file.",
required=True,
)
args = arg_parser.parse_args()
main(args)
@@ -0,0 +1,144 @@
/*
* FreeRTOS V202111.00
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to
* use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
* the Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* https://www.FreeRTOS.org
* https://github.com/FreeRTOS
*
*/
/* This file configures mbed TLS for FreeRTOS. */
#ifndef MBEDTLS_CONFIG_H_
#define MBEDTLS_CONFIG_H_
/* FreeRTOS include. */
#include "FreeRTOS.h"
/* Generate errors if deprecated functions are used. */
#define MBEDTLS_DEPRECATED_REMOVED
/* Place AES tables in ROM. */
#define MBEDTLS_AES_ROM_TABLES
/* Enable the following cipher modes. */
#define MBEDTLS_CIPHER_MODE_CBC
#define MBEDTLS_CIPHER_MODE_CFB
#define MBEDTLS_CIPHER_MODE_CTR
/* Enable the following cipher padding modes. */
#define MBEDTLS_CIPHER_PADDING_PKCS7
#define MBEDTLS_CIPHER_PADDING_ONE_AND_ZEROS
#define MBEDTLS_CIPHER_PADDING_ZEROS_AND_LEN
#define MBEDTLS_CIPHER_PADDING_ZEROS
/* Cipher suite configuration. */
#define MBEDTLS_REMOVE_ARC4_CIPHERSUITES
#define MBEDTLS_ECP_DP_SECP256R1_ENABLED
#define MBEDTLS_ECP_NIST_OPTIM
#define MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED
#define MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
/* Enable all SSL alert messages. */
#define MBEDTLS_SSL_ALL_ALERT_MESSAGES
/* Enable the following SSL features. */
#define MBEDTLS_SSL_ENCRYPT_THEN_MAC
#define MBEDTLS_SSL_EXTENDED_MASTER_SECRET
#define MBEDTLS_SSL_MAX_FRAGMENT_LENGTH
#define MBEDTLS_SSL_PROTO_TLS1_2
#define MBEDTLS_SSL_ALPN
#define MBEDTLS_SSL_SERVER_NAME_INDICATION
/* Check certificate key usage. */
#define MBEDTLS_X509_CHECK_KEY_USAGE
#define MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE
/* Disable platform entropy functions. */
#define MBEDTLS_NO_PLATFORM_ENTROPY
/* Enable the following mbed TLS features. */
#define MBEDTLS_CMAC_C
#define MBEDTLS_AES_C
#define MBEDTLS_ASN1_PARSE_C
#define MBEDTLS_ASN1_WRITE_C
#define MBEDTLS_BASE64_C
#define MBEDTLS_BIGNUM_C
#define MBEDTLS_CIPHER_C
#define MBEDTLS_CTR_DRBG_C
#define MBEDTLS_ECDH_C
#define MBEDTLS_ECDSA_C
#define MBEDTLS_ECP_C
#define MBEDTLS_ENTROPY_C
#define MBEDTLS_ERROR_C
#define MBEDTLS_ENTROPY_HARDWARE_ALT
#define MBEDTLS_GCM_C
#define MBEDTLS_MD_C
#define MBEDTLS_OID_C
#define MBEDTLS_PEM_PARSE_C
#define MBEDTLS_PEM_WRITE_C
#define MBEDTLS_PK_C
#define MBEDTLS_PK_PARSE_C
#define MBEDTLS_PKCS1_V15
#define MBEDTLS_PLATFORM_C
#define MBEDTLS_RSA_C
#define MBEDTLS_SHA1_C
#define MBEDTLS_SHA256_C
#define MBEDTLS_SSL_CLI_C
#define MBEDTLS_SSL_TLS_C
#define MBEDTLS_THREADING_ALT
#define MBEDTLS_THREADING_C
#define MBEDTLS_X509_USE_C
#define MBEDTLS_PK_WRITE_C
#define MBEDTLS_X509_CRT_PARSE_C
#define MBEDTLS_X509_CREATE_C
#define MBEDTLS_X509_CSR_WRITE_C
#define MBEDTLS_CMAC_C
/* Set the memory allocation functions on FreeRTOS. */
void * mbedtls_platform_calloc( size_t nmemb,
size_t size );
void mbedtls_platform_free( void * ptr );
#define MBEDTLS_PLATFORM_MEMORY
#define MBEDTLS_PLATFORM_CALLOC_MACRO mbedtls_platform_calloc
#define MBEDTLS_PLATFORM_FREE_MACRO mbedtls_platform_free
/* The network send and receive functions on FreeRTOS. */
int mbedtls_platform_send( void * ctx,
const unsigned char * buf,
size_t len );
int mbedtls_platform_recv( void * ctx,
unsigned char * buf,
size_t len );
/* These two macro used by mbedtls_ssl_set_bio in using_mbedtls network
* transport layer. */
#define MBEDTLS_SSL_SEND mbedtls_platform_send
#define MBEDTLS_SSL_RECV mbedtls_platform_recv
/* The entropy poll function. */
int mbedtls_platform_entropy_poll( void * data,
unsigned char * output,
size_t len,
size_t * olen );
#include "mbedtls/check_config.h"
#endif /* ifndef MBEDTLS_CONFIG_H_ */
@@ -0,0 +1,116 @@
/*
* FreeRTOS V202111.00
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to
* use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
* the Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* https://www.FreeRTOS.org
* https://github.com/FreeRTOS
*
*/
#ifndef MQTT_OPERATIONS_H_
#define MQTT_OPERATIONS_H_
/* MQTT API header. */
#include "core_mqtt.h"
/* corePKCS11 include. */
#include "core_pkcs11.h"
/**
* @brief Application callback type to handle the incoming publishes.
*
* @param[in] pxPublishInfo Pointer to publish info of the incoming publish.
* @param[in] usPacketIdentifier Packet identifier of the incoming publish.
*/
typedef void (* MQTTPublishCallback_t )( MQTTPublishInfo_t * pxPublishInfo,
uint16_t usPacketIdentifier );
/**
* @brief Establish a MQTT connection.
*
* @param[in] xPublishCallback The callback function to receive incoming
* publishes from the MQTT broker.
* @param[in] pcClientCertLabel The client certificate PKCS #11 label to use.
* @param[in] pcPrivateKeyLabel The private key PKCS #11 label for the client certificate.
*
* @return true if an MQTT session is established;
* false otherwise.
*/
bool xEstablishMqttSession( MQTTPublishCallback_t xPublishCallback,
char * pcClientCertLabel,
char * pcPrivateKeyLabel );
/**
* @brief Disconnect the MQTT connection.
*
* @return true if the MQTT session was successfully disconnected;
* false otherwise.
*/
bool xDisconnectMqttSession( void );
/**
* @brief Subscribe to a MQTT topic filter.
*
* @param[in] pcTopicFilter The topic filter to subscribe to.
* @param[in] usTopicFilterLength Length of the topic buffer.
*
* @return true if subscribe operation was successful;
* false otherwise.
*/
bool xSubscribeToTopic( const char * pcTopicFilter,
uint16_t usTopicFilterLength );
/**
* @brief Unsubscribe from a MQTT topic filter.
*
* @param[in] pcTopicFilter The topic filter to unsubscribe from.
* @param[in] usTopicFilterLength Length of the topic buffer.
*
* @return true if unsubscribe operation was successful;
* false otherwise.
*/
bool xUnsubscribeFromTopic( const char * pcTopicFilter,
uint16_t usTopicFilterLength );
/**
* @brief Publish a message to a MQTT topic.
*
* @param[in] pcTopic The topic to publish the message on.
* @param[in] usTopicLength Length of the topic.
* @param[in] pcMessage The message to publish.
* @param[in] xMessageLength Length of the message.
*
* @return true if PUBLISH was successfully sent;
* false otherwise.
*/
bool xPublishToTopic( const char * pcTopic,
uint16_t usTopicLength,
const char * pcMessage,
size_t xMessageLength );
/**
* @brief Invoke the core MQTT library's process loop function.
*
* @return true if process loop was successful;
* false otherwise.
*/
bool xProcessLoop( void );
#endif /* ifndef MQTT_OPERATIONS_H_ */
@@ -0,0 +1,85 @@
/*
* FreeRTOS V202111.00
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to
* use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
* the Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* https://www.FreeRTOS.org
* https://github.com/FreeRTOS
*
*/
#ifndef PKCS11_OPERATIONS_H_
#define PKCS11_OPERATIONS_H_
/* Standard includes. */
#include <stdlib.h>
#include <stdbool.h>
/* corePKCS11 include. */
#include "core_pkcs11.h"
/**
* @brief Generate a new public-private key pair in the PKCS #11 module, and
* generate a certificate signing request (CSR) for them.
*
* This device-generated private key and CSR can be used with the
* CreateCertificateFromCsr API of the the Fleet Provisioning feature of AWS IoT
* Core in order to provision a unique client certificate.
*
* @param[in] xP11Session The PKCS #11 session to use.
* @param[in] pcPrivKeyLabel PKCS #11 label for the private key.
* @param[in] pcPubKeyLabel PKCS #11 label for the public key.
* @param[out] pcCsrBuffer The buffer to write the CSR to.
* @param[in] xCsrBufferLength Length of #pcCsrBuffer.
* @param[out] pcOutCsrLength The length of the written CSR.
*
* @return True on success.
*/
bool xGenerateKeyAndCsr( CK_SESSION_HANDLE xP11Session,
const char * pcPrivKeyLabel,
const char * pcPubKeyLabel,
char * pcCsrBuffer,
size_t xCsrBufferLength,
size_t * pcOutCsrLength );
/**
* @brief Save the device client certificate into the PKCS #11 module.
*
* @param[in] xP11Session The PKCS #11 session to use.
* @param[in] pcCertificate The certificate to save.
* @param[in] pcLabel PKCS #11 label for the certificate.
* @param[in] xCertificateLength Length of #pcCertificate.
*
* @return True on success.
*/
bool xLoadCertificate( CK_SESSION_HANDLE xP11Session,
const char * pcCertificate,
const char * pcLabel,
size_t xCertificateLength );
/**
* @brief Close the PKCS #11 session.
*
* @param[in] xP11Session The PKCS #11 session to use.
*
* @return True on success.
*/
bool xPkcs11CloseSession( CK_SESSION_HANDLE xP11Session );
#endif /* ifndef PKCS11_OPERATIONS_H_ */
@@ -0,0 +1,115 @@
/*
* FreeRTOS V202111.00
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to
* use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
* the Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* https://www.FreeRTOS.org
* https://github.com/FreeRTOS
*
*/
/**
* This file declares functions for serializing and parsing CBOR encoded Fleet
* Provisioning API payloads.
*/
/* Standard includes. */
#include <stdlib.h>
#include <stdint.h>
#include <stdbool.h>
/**
* @brief Creates the request payload to be published to the
* CreateCertificateFromCsr API in order to request a certificate from AWS IoT
* for the included Certificate Signing Request (CSR).
*
* @param[in] pucBuffer Buffer into which to write the publish request payload.
* @param[in] xBufferLength Length of #pucBuffer.
* @param[in] pcCsr The CSR to include in the request payload.
* @param[in] xCsrLength The length of #pcCsr.
* @param[out] pxOutLengthWritten The length of the publish request payload.
*/
bool xGenerateCsrRequest( uint8_t * pucBuffer,
size_t xBufferLength,
const char * pcCsr,
size_t xCsrLength,
size_t * pxOutLengthWritten );
/**
* @brief Creates the request payload to be published to the RegisterThing API
* in order to activate the provisioned certificate and receive a Thing name.
*
* @param[in] pucBuffer Buffer into which to write the publish request payload.
* @param[in] xBufferLength Length of #buffer.
* @param[in] pcCertificateOwnershipToken The certificate's certificate
* ownership token.
* @param[in] xCertificateOwnershipTokenLength Length of
* #certificateOwnershipToken.
* @param[out] pxOutLengthWritten The length of the publish request payload.
*/
bool xGenerateRegisterThingRequest( uint8_t * pucBuffer,
size_t xBufferLength,
const char * pcCertificateOwnershipToken,
size_t xCertificateOwnershipTokenLength,
const char * pcSerial,
size_t xSerialLength,
size_t * pxOutLengthWritten );
/**
* @brief Extracts the certificate, certificate ID, and certificate ownership
* token from a CreateCertificateFromCsr accepted response. These are copied
* to the provided buffers so that they can outlive the data in the response
* buffer and as CBOR strings may be chunked.
*
* @param[in] pucResponse The response payload.
* @param[in] xLength Length of #pucResponse.
* @param[in] pcCertificateBuffer The buffer to which to write the certificate.
* @param[in,out] pxCertificateBufferLength The length of #pcCertificateBuffer.
* The length written is output here.
* @param[in] pcCertificateIdBuffer The buffer to which to write the certificate
* ID.
* @param[in,out] pxCertificateIdBufferLength The length of
* #pcCertificateIdBuffer. The length written is output here.
* @param[in] pcOwnershipTokenBuffer The buffer to which to write the
* certificate ownership token.
* @param[in,out] pxOwnershipTokenBufferLength The length of
* #pcOwnershipTokenBuffer. The length written is output here.
*/
bool xParseCsrResponse( const uint8_t * pucResponse,
size_t xLength,
char * pcCertificateBuffer,
size_t * pxCertificateBufferLength,
char * pcCertificateIdBuffer,
size_t * pxCertificateIdBufferLength,
char * pcOwnershipTokenBuffer,
size_t * pxOwnershipTokenBufferLength );
/**
* @brief Extracts the Thing name from a RegisterThing accepted response.
*
* @param[in] pucResponse The response document.
* @param[in] xLength Length of #pucResponse.
* @param[in] pcThingNameBuffer The buffer to which to write the Thing name.
* @param[in,out] pxThingNameBufferLength The length of #pcThingNameBuffer. The
* written length is output here.
*/
bool xParseRegisterThingResponse( const uint8_t * pucResponse,
size_t xLength,
char * pcThingNameBuffer,
size_t * pxThingNameBufferLength );
+86 -9
View File
File diff suppressed because it is too large Load Diff
+14
View File
@@ -136,4 +136,18 @@ dependencies:
url: "https://github.com/FreeRTOS/FreeRTOS-Cellular-Interface.git"
path: "FreeRTOS-Plus/Source/FreeRTOS-Cellular-Interface"
- name: "fleet-provisioning"
version: "3ec98fc"
repository:
type: "git"
url: "https://github.com/aws/Fleet-Provisioning-for-AWS-IoT-embedded-sdk.git"
path: "FreeRTOS-Plus/Source/AWS/fleet-provisioning"
- name: "tinycbor"
version: "v0.6.0"
repository:
type: "git"
url: "https://github.com/intel/tinycbor.git"
path: "FreeRTOS-Plus/ThirdParty/tinycbor"
license: "MIT"