PKCS #11 LTS Update (#293)

* Add PKCS #11 mutual auth demo to readme.

* Submodule PKCS #11 Repo And Add PKCS #11 Code to Memory Size Tool
This commit is contained in:
Carl Lundin
2020-09-25 15:10:59 -07:00
committed by GitHub
parent 71f5984776
commit f98d3c5fb9
20 changed files with 169 additions and 6412 deletions
+3
View File
@@ -5,3 +5,6 @@
path = FreeRTOS-Plus/Source/mbedtls
url = https://github.com/ARMmbed/mbedtls.git
branch = mbedtls-2.16.7
[submodule "FreeRTOS-Plus/Source/FreeRTOS-IoT-Libraries-LTS-Beta2/pkcs11/FreeRTOS-PKCS"]
path = FreeRTOS-Plus/Source/FreeRTOS-IoT-Libraries-LTS-Beta2/pkcs11/FreeRTOS-PKCS
url = https://github.com/FreeRTOS/FreeRTOS-PKCS.git
@@ -232,14 +232,11 @@ static void prvMQTTProcessIncomingPublish( MQTTPublishInfo_t * pxPublishInfo );
*
* @param[in] pxMQTTContext MQTT context pointer.
* @param[in] pxPacketInfo Packet Info pointer for the incoming packet.
* @param[in] usPacketIdentifier Packet identifier of the incoming packet.
* @param[in] pxPublishInfo Deserialized publish info for the incoming packet if
* there is an incoming PUBLISH; NULL otherwise
* @param[in] pxDeserializedInfo Deserialized information from the incoming packet.
*/
static void prvEventCallback( MQTTContext_t * pxMQTTContext,
MQTTPacketInfo_t * pxPacketInfo,
uint16_t usPacketIdentifier,
MQTTPublishInfo_t * pxPublishInfo );
MQTTDeserializedInfo_t * pxDeserializedInfo );
/**
* @brief TLS connect to endpoint democonfigMQTT_BROKER_ENDPOINT.
@@ -662,19 +659,18 @@ static void prvMQTTProcessIncomingPublish( MQTTPublishInfo_t * pxPublishInfo )
static void prvEventCallback( MQTTContext_t * pxMQTTContext,
MQTTPacketInfo_t * pxPacketInfo,
uint16_t usPacketIdentifier,
MQTTPublishInfo_t * pxPublishInfo )
MQTTDeserializedInfo_t * pxDeserializedInfo )
{
/* The MQTT context is not used for this demo. */
( void ) pxMQTTContext;
if( ( pxPacketInfo->type & 0xF0U ) == MQTT_PACKET_TYPE_PUBLISH )
{
prvMQTTProcessIncomingPublish( pxPublishInfo );
prvMQTTProcessIncomingPublish( pxDeserializedInfo->pPublishInfo );
}
else
{
prvMQTTProcessResponse( pxPacketInfo, usPacketIdentifier );
prvMQTTProcessResponse( pxPacketInfo, pxDeserializedInfo->packetIdentifier );
}
}
@@ -58,7 +58,7 @@
</Midl>
<ClCompile>
<Optimization>Disabled</Optimization>
<AdditionalIncludeDirectories>..\..\..\..\Source\FreeRTOS-Plus-Trace\Include;..\..\..\..\..\FreeRTOS-Plus\Source\FreeRTOS-Plus-TCP\include;..\..\..\..\..\FreeRTOS-Plus\Source\FreeRTOS-Plus-TCP\portable\BufferManagement;..\..\..\..\..\FreeRTOS-Plus\Source\FreeRTOS-Plus-TCP\portable\Compiler\MSVC;..\..\common\logging-stack;..\..\mqtt\common;..\..\mqtt\common\WinPCap;..\..\..\..\..\FreeRTOS\Source\include;..\..\..\..\..\FreeRTOS\Source\portable\MSVC-MingW;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\include;..\..\..\..\Source\pkcs11;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\platform\freertos\transport\include;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\platform\freertos\mbedtls;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\standard\mqtt\include;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c-sdk\platform\include;..\..\..\..\Source\mbedtls_utils;..\..\..\..\Source\mbedtls\include;.;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
<AdditionalIncludeDirectories>..\..\..\..\Source\FreeRTOS-Plus-Trace\Include;..\..\..\..\..\FreeRTOS-Plus\Source\FreeRTOS-Plus-TCP\include;..\..\..\..\..\FreeRTOS-Plus\Source\FreeRTOS-Plus-TCP\portable\BufferManagement;..\..\..\..\..\FreeRTOS-Plus\Source\FreeRTOS-Plus-TCP\portable\Compiler\MSVC;..\..\common\logging-stack;..\..\mqtt\common;..\..\mqtt\common\WinPCap;..\..\..\..\..\FreeRTOS\Source\include;..\..\..\..\..\FreeRTOS\Source\portable\MSVC-MingW;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\platform\include;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\platform\freertos\transport\include;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\platform\freertos\mbedtls;..\..\..\..\Source\mbedtls\include;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\standard\mqtt\include;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c-sdk\platform\include;..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\include;..\..\..\..\Source\pkcs11;..\..\..\..\Source\mbedtls_utils;.;%(AdditionalIncludeDirectories)</AdditionalIncludeDirectories>
<PreprocessorDefinitions>MBEDTLS_CONFIG_FILE="mbedtls_config.h";WIN32;_DEBUG;_CONSOLE;_WIN32_WINNT=0x0500;WINVER=0x400;_CRT_SECURE_NO_WARNINGS;%(PreprocessorDefinitions)</PreprocessorDefinitions>
<MinimalRebuild>false</MinimalRebuild>
<BasicRuntimeChecks>EnableFastChecks</BasicRuntimeChecks>
@@ -163,10 +163,10 @@
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\standard\mqtt\src\mqtt_lightweight.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\standard\mqtt\src\mqtt_state.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\standard\mqtt\src\mqtt.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\iot_pkcs11.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\iot_pki_utils.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\portable\mbedtls\iot_pkcs11_mbedtls.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\portable\windows\iot_pkcs11_pal.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\iot_pkcs11.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\iot_pki_utils.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\portable\mbedtls\iot_pkcs11_mbedtls.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\portable\windows\iot_pkcs11_pal.c" />
<ClCompile Include="..\..\..\..\Source\mbedtls\library\aes.c">
<WarningLevel Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'">TurnOffAllWarnings</WarningLevel>
<WarningLevel Condition="'$(Configuration)|$(Platform)'=='Release|Win32'">TurnOffAllWarnings</WarningLevel>
@@ -520,9 +520,9 @@
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\standard\mqtt\include\mqtt_lightweight.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\standard\mqtt\include\mqtt_state.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\standard\mqtt\include\mqtt.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\include\iot_pkcs11.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\include\iot_pkcs11_pal.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\include\iot_pki_utils.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\include\iot_pkcs11.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\include\iot_pkcs11_pal.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\include\iot_pki_utils.h" />
<ClInclude Include="..\..\..\..\Source\mbedtls\include\mbedtls\aes.h" />
<ClInclude Include="..\..\..\..\Source\mbedtls\include\mbedtls\aesni.h" />
<ClInclude Include="..\..\..\..\Source\mbedtls\include\mbedtls\arc4.h" />
@@ -71,18 +71,18 @@
<Filter Include="FreeRTOS+\FreeRTOS IoT Libraries\platform\freertos\transport\src">
<UniqueIdentifier>{6a35782c-bc09-42d5-a850-98bcb668a4dc}</UniqueIdentifier>
</Filter>
<Filter Include="FreeRTOS+\mbedtls_utils">
<UniqueIdentifier>{37f68b75-28a7-4456-a554-422056841a98}</UniqueIdentifier>
</Filter>
<Filter Include="FreeRTOS+\FreeRTOS IoT Libraries\pkcs11">
<UniqueIdentifier>{ddaf9df2-d1b8-4486-a467-713f3d844435}</UniqueIdentifier>
</Filter>
<Filter Include="FreeRTOS+\FreeRTOS IoT Libraries\pkcs11\include">
<UniqueIdentifier>{4e6fba7d-0003-4e39-8e74-ad58d49c84b6}</UniqueIdentifier>
</Filter>
<Filter Include="FreeRTOS+\pkcs11">
<UniqueIdentifier>{9f3039f1-dee0-4b5b-b1e9-a4b9803c8901}</UniqueIdentifier>
</Filter>
<Filter Include="FreeRTOS+\FreeRTOS-PKCS">
<UniqueIdentifier>{999218ad-7c24-4e43-9fc2-23108073f512}</UniqueIdentifier>
</Filter>
<Filter Include="FreeRTOS+\FreeRTOS-PKCS\include">
<UniqueIdentifier>{1414401a-5aeb-4055-9725-74964e06b188}</UniqueIdentifier>
</Filter>
<Filter Include="FreeRTOS+\mbedtls_utils">
<UniqueIdentifier>{37f68b75-28a7-4456-a554-422056841a98}</UniqueIdentifier>
</Filter>
</ItemGroup>
<ItemGroup>
<ClCompile Include="..\..\..\..\..\FreeRTOS\Source\portable\MSVC-MingW\port.c">
@@ -402,24 +402,24 @@
</ClCompile>
<ClCompile Include="main.c" />
<ClCompile Include="..\..\mqtt\common\demo_logging.c" />
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\iot_pkcs11.c">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\pkcs11</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\iot_pki_utils.c">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\pkcs11</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\portable\mbedtls\iot_pkcs11_mbedtls.c">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\pkcs11</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\portable\windows\iot_pkcs11_pal.c">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\pkcs11</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\platform\freertos\transport\src\tls_freertos_pkcs11.c">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\platform\freertos\transport\src</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\platform\freertos\transport\src\freertos_sockets_wrapper.c">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\platform\freertos\transport\src</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\iot_pkcs11.c">
<Filter>FreeRTOS+\FreeRTOS-PKCS</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\iot_pki_utils.c">
<Filter>FreeRTOS+\FreeRTOS-PKCS</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\portable\mbedtls\iot_pkcs11_mbedtls.c">
<Filter>FreeRTOS+\FreeRTOS-PKCS</Filter>
</ClCompile>
<ClCompile Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\portable\windows\iot_pkcs11_pal.c">
<Filter>FreeRTOS+\FreeRTOS-PKCS</Filter>
</ClCompile>
</ItemGroup>
<ItemGroup>
<ClInclude Include="..\..\..\..\..\FreeRTOS-Plus\Source\FreeRTOS-Plus-TCP\include\NetworkInterface.h">
@@ -752,15 +752,6 @@
<Filter>FreeRTOS+\mbedtls_utils</Filter>
</ClInclude>
<ClInclude Include="..\..\mqtt\common\demo_logging.h" />
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\include\iot_pkcs11.h">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\pkcs11\include</Filter>
</ClInclude>
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\include\iot_pkcs11_pal.h">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\pkcs11\include</Filter>
</ClInclude>
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\include\iot_pki_utils.h">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\pkcs11\include</Filter>
</ClInclude>
<ClInclude Include="..\..\..\..\Source\pkcs11\pkcs11.h">
<Filter>FreeRTOS+\pkcs11</Filter>
</ClInclude>
@@ -776,5 +767,14 @@
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\c_sdk\platform\freertos\transport\include\freertos_sockets_wrapper.h">
<Filter>FreeRTOS+\FreeRTOS IoT Libraries\platform\freertos\transport\include</Filter>
</ClInclude>
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\include\iot_pkcs11.h">
<Filter>FreeRTOS+\FreeRTOS-PKCS\include</Filter>
</ClInclude>
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\include\iot_pkcs11_pal.h">
<Filter>FreeRTOS+\FreeRTOS-PKCS\include</Filter>
</ClInclude>
<ClInclude Include="..\..\..\..\Source\FreeRTOS-IoT-Libraries-LTS-Beta2\pkcs11\FreeRTOS-PKCS\source\include\iot_pki_utils.h">
<Filter>FreeRTOS+\FreeRTOS-PKCS\include</Filter>
</ClInclude>
</ItemGroup>
</Project>
@@ -23,6 +23,7 @@
* http://www.FreeRTOS.org
*/
/**
* @file iot_pkcs11_config.h
* @brief PCKS#11 config options.
@@ -32,6 +33,8 @@
#ifndef _IOT_PKCS11_CONFIG_H_
#define _IOT_PKCS11_CONFIG_H_
#include "FreeRTOS.h"
/**************************************************/
/******* DO NOT CHANGE the following order ********/
/**************************************************/
@@ -39,10 +42,9 @@
/* Include logging header files and define logging macros in the following order:
* 1. Include the header file "logging_levels.h".
* 2. Define the LIBRARY_LOG_NAME and LIBRARY_LOG_LEVEL macros depending on
* the logging configuration for MQTT.
* 3. Include the header file "logging_stack.h", if logging is enabled for MQTT.
* the logging configuration for PKCS #11.
* 3. Include the header file "logging_stack.h", if logging is enabled for PKCS #11.
*/
#include "logging_levels.h"
/* Logging configuration for the PKCS #11 library. */
@@ -56,6 +58,26 @@
#include "logging_stack.h"
/**
* @brief Malloc API used by iot_pkcs11.h
*/
#define PKCS11_MALLOC pvPortMalloc
/**
* @brief Free API used by iot_pkcs11.h
*/
#define PKCS11_FREE vPortFree
/**
* @brief ESP32 NVS Partition where PKCS #11 data is stored
*/
#define pkcs11configSTORAGE_PARTITION "storage"
/**
* @brief ESP32 NVS namespace for PKCS #11 data
*/
#define pkcs11configSTORAGE_NS "creds"
/**
* @brief PKCS #11 default user PIN.
*
@@ -74,19 +96,19 @@
* @brief Maximum length (in characters) for a PKCS #11 CKA_LABEL
* attribute.
*/
#define pkcs11configMAX_LABEL_LENGTH 32
#define pkcs11configMAX_LABEL_LENGTH 32UL
/**
* @brief Maximum number of token objects that can be stored
* by the PKCS #11 module.
*/
#define pkcs11configMAX_NUM_OBJECTS 6
#define pkcs11configMAX_NUM_OBJECTS 6UL
/**
* @brief Maximum number of sessions that can be stored
* by the PKCS #11 module.
*/
#define pkcs11configMAX_SESSIONS 10
#define pkcs11configMAX_SESSIONS 10UL
/**
* @brief Set to 1 if a PAL destroy object is implemented.
@@ -102,7 +124,7 @@
* If set to 0, OTA code signing certificate is built in via
* aws_ota_codesigner_certificate.h.
*/
#define pkcs11configOTA_SUPPORTED 0
#define pkcs11configOTA_SUPPORTED 1
/**
* @brief Set to 1 if PAL supports storage for JITP certificate,
@@ -119,28 +141,28 @@
* Private key for connection to AWS IoT endpoint. The corresponding
* public key should be registered with the AWS IoT endpoint.
*/
#define pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS "Device Priv TLS Key"
#define pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS ( "Device Priv TLS Key" )
/**
* @brief The PKCS #11 label for device public key.
*
* The public key corresponding to pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS.
*/
#define pkcs11configLABEL_DEVICE_PUBLIC_KEY_FOR_TLS "Device Pub TLS Key"
#define pkcs11configLABEL_DEVICE_PUBLIC_KEY_FOR_TLS ( "Device Pub TLS Key" )
/**
* @brief The PKCS #11 label for the device certificate.
*
* Device certificate corresponding to pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS.
*/
#define pkcs11configLABEL_DEVICE_CERTIFICATE_FOR_TLS "Device Cert"
#define pkcs11configLABEL_DEVICE_CERTIFICATE_FOR_TLS ( "Device Cert" )
/**
* @brief The PKCS #11 label for the object to be used for code verification.
*
* Used by over-the-air update code to verify an incoming signed image.
*/
#define pkcs11configLABEL_CODE_VERIFICATION_KEY "Code Verify Key"
#define pkcs11configLABEL_CODE_VERIFICATION_KEY ( "Code Verify Key" )
/**
* @brief The PKCS #11 label for Just-In-Time-Provisioning.
@@ -149,13 +171,13 @@
* (pkcs11configLABEL_DEVICE_CERTIFICATE_FOR_TLS) when using the JITR or
* JITP flow.
*/
#define pkcs11configLABEL_JITP_CERTIFICATE "JITP Cert"
#define pkcs11configLABEL_JITP_CERTIFICATE ( "JITP Cert" )
/**
* @brief The PKCS #11 label for the AWS Trusted Root Certificate.
*
* @see aws_default_root_certificates.h
*/
#define pkcs11configLABEL_ROOT_CERTIFICATE "Root Cert"
#define pkcs11configLABEL_ROOT_CERTIFICATE ( "Root Cert" )
#endif /* _AWS_PKCS11_CONFIG_H_ include guard. */
@@ -44,10 +44,11 @@
#include "logging_levels.h"
/* Logging configuration for the Sockets. */
#ifndef LIBRARY_LOG_NAME # define LIBRARY_LOG_NAME "PkcsTlsTransport"
#ifndef LIBRARY_LOG_NAME
#define LIBRARY_LOG_NAME "PkcsTlsTransport"
#endif
#ifndef LIBRARY_LOG_LEVEL
#define LIBRARY_LOG_LEVEL LOG_ERROR
#define LIBRARY_LOG_LEVEL LOG_ERROR
#endif
#include "logging_stack.h"
@@ -1,175 +0,0 @@
/*
* FreeRTOS PKCS #11 V2.0.3
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to
* use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
* the Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* http://aws.amazon.com/freertos
* http://www.FreeRTOS.org
*/
#ifndef IOT_PKCS11_PAL
#define IOT_PKCS11_PAL
/**
* @file iot_pkcs11_pal.h
* @brief Port Specific File Access functions for PKCS #11
*/
/*-----------------------------------------------------------*/
/*------------ Port Specific File Access API ----------------*/
/*--------- See iot_pkcs11_pal.c for definitions ------------*/
/*-----------------------------------------------------------*/
/*------------------------ PKCS #11 PAL functions -------------------------*/
/**
* @functions_page{pkcs11_pal,PKCS #11 PAL, PKCS #11 PAL}
* @functions_brief{PKCS #11 PAL Layer}
* - @function_name{pkcs11_pal_function_initialize}
* @function_brief{pkcs11_pal_function_initialize}
* - @function_name{pkcs11_pal_function_saveobject}
* @function_brief{pkcs11_pal_function_saveobject}
* - @function_name{pkcs11_pal_function_destroyobject}
* @function_brief{pkcs11_pal_function_destroyobject}
* - @function_name{pkcs11_pal_function_findobject}
* @function_brief{pkcs11_pal_function_findobject}
* - @function_name{pkcs11_pal_function_getobjectvalue}
* @function_brief{pkcs11_pal_function_getobjectvalue}
* - @function_name{pkcs11_pal_function_getobjectvaluecleanup}
* @function_brief{pkcs11_pal_function_getobjectvaluecleanup}
*/
/**
* @function_page{PKCS11_PAL_SaveObject,pkcs11_pal,saveobject}
* @function_snippet{pkcs11_pal,saveobject,this}
* @copydoc PKCS11_PAL_SaveObject
* @function_page{PKCS11_PAL_DestroyObject,pkcs11_pal,destroyobject}
* @function_snippet{pkcs11_pal,destroyobject,this}
* @copydoc PKCS11_PAL_DestroyObject
* @function_page{PKCS11_PAL_FindObject,pkcs11_pal,findobject}
* @function_snippet{pkcs11_pal,findobject,this}
* @copydoc PKCS11_PAL_FindObject
* @function_page{PKCS11_PAL_GetObjectValue,pkcs11_pal,getobjectvalue}
* @function_snippet{pkcs11_pal,getobjectvalue,this}
* @copydoc PKCS11_PAL_GetObjectValue
* @function_page{PKCS11_PAL_GetObjectValueCleanup,pkcs11_pal,getobjectvaluecleanup}
* @function_snippet{pkcs11_pal,getobjectvaluecleanup,this}
* @copydoc PKCS11_PAL_GetObjectValueCleanup
*/
/**
* @brief Initializes the PKCS #11 PAL.
*
* @return CKR_OK on success.
* CKR_FUNCTION_FAILED on failure.
*/
/* @[declare_pkcs11_pal_initialize] */
CK_RV PKCS11_PAL_Initialize( void );
/* @[declare_pkcs11_pal_initialize] */
/**
* @brief Saves an object in non-volatile storage.
*
* Port-specific file write for cryptographic information.
*
* @param[in] pxLabel Attribute containing label of the object to be stored.
* @param[in] pucData The object data to be saved.
* @param[in] ulDataSize Size (in bytes) of object data.
*
* @return The object handle if successful.
* eInvalidHandle = 0 if unsuccessful.
*/
/* @[declare_pkcs11_pal_saveobject] */
CK_OBJECT_HANDLE PKCS11_PAL_SaveObject( CK_ATTRIBUTE_PTR pxLabel,
uint8_t * pucData,
uint32_t ulDataSize );
/* @[declare_pkcs11_pal_saveobject] */
/**
* @brief Delete an object from NVM.
*
* @param[in] xHandle Handle to a PKCS #11 object.
*/
/* @[declare_pkcs11_pal_destroyobject] */
CK_RV PKCS11_PAL_DestroyObject( CK_OBJECT_HANDLE xHandle );
/* @[declare_pkcs11_pal_destroyobject] */
/**
* @brief Translates a PKCS #11 label into an object handle.
*
* Port-specific object handle retrieval.
*
*
* @param[in] pLabel Pointer to the label of the object
* who's handle should be found.
* @param[in] usLength The length of the label, in bytes.
*
* @return The object handle if operation was successful.
* Returns eInvalidHandle if unsuccessful.
*/
/* @[declare_pkcs11_pal_findobject] */
CK_OBJECT_HANDLE PKCS11_PAL_FindObject( uint8_t * pLabel,
uint8_t usLength );
/* @[declare_pkcs11_pal_findobject] */
/**
* @brief Gets the value of an object in storage, by handle.
*
* Port-specific file access for cryptographic information.
*
* This call dynamically allocates the buffer which object value
* data is copied into. PKCS11_PAL_GetObjectValueCleanup()
* should be called after each use to free the dynamically allocated
* buffer.
*
* @sa PKCS11_PAL_GetObjectValueCleanup
*
* @param[in] xHandle The PKCS #11 object handle of the object to get the value of.
* @param[out] ppucData Pointer to buffer for file data.
* @param[out] pulDataSize Size (in bytes) of data located in file.
* @param[out] pIsPrivate Boolean indicating if value is private (CK_TRUE)
* or exportable (CK_FALSE)
*
* @return CKR_OK if operation was successful. CKR_KEY_HANDLE_INVALID if
* no such object handle was found, CKR_DEVICE_MEMORY if memory for
* buffer could not be allocated, CKR_FUNCTION_FAILED for device driver
* error.
*/
/* @[declare_pkcs11_pal_getobjectvalue] */
BaseType_t PKCS11_PAL_GetObjectValue( CK_OBJECT_HANDLE xHandle,
uint8_t ** ppucData,
uint32_t * pulDataSize,
CK_BBOOL * pIsPrivate );
/* @[declare_pkcs11_pal_getobjectvalue] */
/**
* @brief Cleanup after PKCS11_GetObjectValue().
*
* @param[in] pucBuffer The buffer to free.
* (*ppucData from PKCS11_PAL_GetObjectValue())
* @param[in] ulBufferSize The length of the buffer to free.
* (*pulDataSize from PKCS11_PAL_GetObjectValue())
*/
/* @[declare_pkcs11_pal_getobjectvaluecleanup] */
void PKCS11_PAL_GetObjectValueCleanup( uint8_t * pucBuffer,
uint32_t ulBufferSize );
/* @[declare_pkcs11_pal_getobjectvaluecleanup] */
#endif /* IOT_PKCS11_PAL include guard. */
@@ -1,102 +0,0 @@
/*
* FreeRTOS Utils V1.1.2
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
* this software and associated documentation files (the "Software"), to deal in
* the Software without restriction, including without limitation the rights to
* use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of
* the Software, and to permit persons to whom the Software is furnished to do so,
* subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* http://aws.amazon.com/freertos
* http://www.FreeRTOS.org
*/
#ifndef _IOT_PKI_UTILS_H_
#define _IOT_PKI_UTILS_H_
/**
* @file iot_pki_utils.h
* @brief Helper functions for PKCS #11
*/
/**
* @functions_page{pkcs11_utils,PKCS #11 Utilities, PKCS #11 Utilities}
* - @function_name{pkcs11_utils_function_pkipkcs11signaturetombedtlssignature}
* @function_brief{pkcs11_utils_function_pkipkcs11signaturetombedtlssignature}
* - @function_name{pkcs11_utils_function_pkimbedtlssignaturetopkcs11signature}
* @function_brief{pkcs11_utils_function_pkimbedtlssignaturetopkcs11signature}
*/
/**
* @function_page{PKI_mbedTLSSignatureToPkcs11Signature,pkcs11_utils,pkimbedtlssignaturetopkcs11signature}
* @function_snippet{pkcs11_utils,pkimbedtlssignaturetopkcs11signature,this}
* @copydoc PKI_mbedTLSSignatureToPkcs11Signature
* @function_page{PKI_pkcs11SignatureTombedTLSSignature,pkcs11_utils,pkipkcs11signaturetombedtlssignature}
* @function_snippet{pkcs11_utils,pkipkcs11signaturetombedtlssignature,this}
* @copydoc PKI_pkcs11SignatureTombedTLSSignature
*/
/**
* @brief Converts an ECDSA P-256 signature from the format provided by mbedTLS
* to the format expected by PKCS #11.
*
* For P-256 signatures, PKCS #11 expects a 64 byte signature, in the
* format of 32 byte R component followed by 32 byte S component.
*
* mbedTLS provides signatures in DER encoded, zero-padded format.
*
* @param[out] pxSignaturePKCS Pointer to a 64 byte buffer
* where PKCS #11 formatted signature
* will be placed. Caller must
* allocate 64 bytes of memory.
* @param[in] pxMbedSignature Pointer to DER encoded ECDSA
* signature.
*
* \return 0 on success, -1 on failure.
*/
/* @[declare_pkcs11_utils_pkimbedtlssignaturetopkcs11signature] */
int PKI_mbedTLSSignatureToPkcs11Signature( uint8_t * pxSignaturePKCS,
uint8_t * pxMbedSignature );
/* @[declare_pkcs11_utils_pkimbedtlssignaturetopkcs11signature] */
/**
* @brief Converts and ECDSA P-256 signature from the format provided by PKCS #11
* to an ASN.1 formatted signature.
*
* For P-256 signature, ASN.1 formatting has the format
*
* SEQUENCE LENGTH
* INTEGER LENGTH R-VALUE
* INTEGER LENGTH S-VALUE
*
* @param[in,out] pucSig This pointer serves dual purpose.
* It should both contain the 64-byte PKCS #11
* style signature on input, and will be modified
* to hold the ASN.1 formatted signature (max length
* 72 bytes). It is the responsibility of the caller
* to guarantee that this pointer is large enough to
* hold the (longer) formatted signature.
*@param[out] pxSigLen Pointer to the length of the ASN.1 formatted signature.
*
* \return 0 if successful, -1 on failure.
*
*/
/* @[declare_pkcs11_utils_pkipkcs11signaturetombedtlssignature] */
int PKI_pkcs11SignatureTombedTLSSignature( uint8_t * pucSig,
size_t * pxSigLen );
/* @[declare_pkcs11_utils_pkipkcs11signaturetombedtlssignature] */
#endif /* ifndef _IOT_PKI_UTILS_H_ */
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+1
View File
@@ -41,6 +41,7 @@ located in sub-directories of the following top-level directories:
Demos using the refactored MQTT library:
+ /FreeRTOS-Plus/Demo/FreeRTOS-IoT-Libraries-LTS-Beta2/mqtt/mqtt_plain_text
+ /FreeRTOS-Plus/Demo/FreeRTOS-IoT-Libraries-LTS-Beta2/mqtt/mqtt_light_weight
+ /FreeRTOS-Plus/Demo/FreeRTOS-IoT-Libraries-LTS-Beta2/pkcs11/mqtt_mutal_auth_with_pkcs11
Demos not yet updated to the refactored MQTT library:
+ /FreeRTOS-Plus/Demo/FreeRTOS-IoT-Libraries-LTS-Beta1/mqtt
+1 -1
View File
@@ -20,7 +20,7 @@ Where:
| ---------- | --------- | ------- | ---------- |
| -p | --lts-path | | Path to the directory containing FreeRTOS LTS code. |
| -o | --optimization | O0 | Compiler optimization level (O0, Os etc). |
| -l | --lib | `mqtt-beta1` | The library to calculate the memory estimates for. Currently supported libraries are: `mqtt-beta1`, `light-mqtt-beta1`, `mqtt-beta2`, `https`, `shadow`, `jobs`, `ota-mqtt`, `ota-http`, `kernel`|
| -l | --lib | `mqtt-beta1` | The library to calculate the memory estimates for. Currently supported libraries are: `mqtt-beta1`, `light-mqtt-beta1`, `mqtt-beta2`, `https`, `shadow`, `jobs`, `ota-mqtt`, `ota-http`, `pkcs11`, `kernel`|
| -c | --compiler | arm-none-eabi-gcc | Compiler to use. |
| -s | --sizetool | arm-none-eabi-size | Size tool to use. |
| -d | --dontclean | | The generated artifacts, which include the generated Makefile and built object files, are deleted by default. Pass `-d` to ensure that the generated artifacts are not deleted. |
@@ -1,5 +1,5 @@
/*
* FreeRTOS Kernel V10.3.0
* FreeRTOS V1.1.4
* Copyright (C) 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Permission is hereby granted, free of charge, to any person obtaining a copy of
@@ -19,12 +19,11 @@
* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
* CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
*
* http://www.FreeRTOS.org
* http://aws.amazon.com/freertos
*
* 1 tab == 4 spaces!
* http://www.FreeRTOS.org
*/
/**
* @file aws_pkcs11_config.h
* @brief PCKS#11 config options.
@@ -34,10 +33,50 @@
#ifndef _AWS_PKCS11_CONFIG_H_
#define _AWS_PKCS11_CONFIG_H_
#include <stddef.h>
#include "FreeRTOS.h"
/* A non-standard version of C_INITIALIZE should be used by this port. */
/* #define pkcs11configC_INITIALIZE_ALT */
/**************************************************/
/******* DO NOT CHANGE the following order ********/
/**************************************************/
/* Include logging header files and define logging macros in the following order:
* 1. Include the header file "logging_levels.h".
* 2. Define the LIBRARY_LOG_NAME and LIBRARY_LOG_LEVEL macros depending on
* the logging configuration for PKCS #11.
* 3. Include the header file "logging_stack.h", if logging is enabled for PKCS #11.
*/
#include "logging_levels.h"
/* Logging configuration for the PKCS #11 library. */
#ifndef LIBRARY_LOG_NAME
#define LIBRARY_LOG_NAME "PKCS11"
#endif
#ifndef LIBRARY_LOG_LEVEL
#define LIBRARY_LOG_LEVEL LOG_ERROR
#endif
#include "logging_stack.h"
/**
* @brief Malloc API used by iot_pkcs11.h
*/
#define PKCS11_MALLOC pvPortMalloc
/**
* @brief Free API used by iot_pkcs11.h
*/
#define PKCS11_FREE vPortFree
/**
* @brief ESP32 NVS Partition where PKCS #11 data is stored
*/
#define pkcs11configSTORAGE_PARTITION "storage"
/**
* @brief ESP32 NVS namespace for PKCS #11 data
*/
#define pkcs11configSTORAGE_NS "creds"
/**
* @brief PKCS #11 default user PIN.
@@ -47,20 +86,29 @@
* protections. However, since typical microcontroller applications lack one or
* both of those, the user PIN is assumed to be used herein for interoperability
* purposes only, and not as a security feature.
*
* Note: Do not cast this to a pointer! The library calls sizeof to get the length
* of this string.
*/
#define configPKCS11_DEFAULT_USER_PIN "0000"
#define configPKCS11_DEFAULT_USER_PIN "0000"
/**
* @brief Maximum length (in characters) for a PKCS #11 CKA_LABEL
* attribute.
*/
#define pkcs11configMAX_LABEL_LENGTH 32
#define pkcs11configMAX_LABEL_LENGTH 32UL
/**
* @brief Maximum number of token objects that can be stored
* by the PKCS #11 module.
*/
#define pkcs11configMAX_NUM_OBJECTS 6
#define pkcs11configMAX_NUM_OBJECTS 6UL
/**
* @brief Maximum number of sessions that can be stored
* by the PKCS #11 module.
*/
#define pkcs11configMAX_SESSIONS 10UL
/**
* @brief Set to 1 if a PAL destroy object is implemented.
@@ -68,7 +116,7 @@
* If set to 0, no PAL destroy object is implemented, and this functionality
* is implemented in the common PKCS #11 layer.
*/
#define pkcs11configPAL_DESTROY_SUPPORTED 0
#define pkcs11configPAL_DESTROY_SUPPORTED 0
/**
* @brief Set to 1 if OTA image verification via PKCS #11 module is supported.
@@ -76,7 +124,7 @@
* If set to 0, OTA code signing certificate is built in via
* aws_ota_codesigner_certificate.h.
*/
#define pkcs11configOTA_SUPPORTED 0
#define pkcs11configOTA_SUPPORTED 1
/**
* @brief Set to 1 if PAL supports storage for JITP certificate,
@@ -85,7 +133,7 @@
* If set to 0, PAL does not support storage mechanism for these, and
* they are accessed via headers compiled into the code.
*/
#define pkcs11configJITP_CODEVERIFY_ROOT_CERT_SUPPORTED 0
#define pkcs11configJITP_CODEVERIFY_ROOT_CERT_SUPPORTED 0
/**
* @brief The PKCS #11 label for device private key.
@@ -93,29 +141,28 @@
* Private key for connection to AWS IoT endpoint. The corresponding
* public key should be registered with the AWS IoT endpoint.
*/
#define pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS "Device Priv TLS Key"
#define pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS ( "Device Priv TLS Key" )
/**
* @brief The PKCS #11 label for device public key.
*
* The public key corresponding to pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS.
*/
#define pkcs11configLABEL_DEVICE_PUBLIC_KEY_FOR_TLS "Device Pub TLS Key"
#define pkcs11configLABEL_DEVICE_PUBLIC_KEY_FOR_TLS ( "Device Pub TLS Key" )
/**
* @brief The PKCS #11 label for the device certificate.
*
* Device certificate corresponding to
* pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS.
* Device certificate corresponding to pkcs11configLABEL_DEVICE_PRIVATE_KEY_FOR_TLS.
*/
#define pkcs11configLABEL_DEVICE_CERTIFICATE_FOR_TLS "Device Cert"
#define pkcs11configLABEL_DEVICE_CERTIFICATE_FOR_TLS ( "Device Cert" )
/**
* @brief The PKCS #11 label for the object to be used for code verification.
*
* Used by over-the-air update code to verify an incoming signed image.
*/
#define pkcs11configLABEL_CODE_VERIFICATION_KEY "Code Verify Key"
#define pkcs11configLABEL_CODE_VERIFICATION_KEY ( "Code Verify Key" )
/**
* @brief The PKCS #11 label for Just-In-Time-Provisioning.
@@ -124,13 +171,13 @@
* (pkcs11configLABEL_DEVICE_CERTIFICATE_FOR_TLS) when using the JITR or
* JITP flow.
*/
#define pkcs11configLABEL_JITP_CERTIFICATE "JITP Cert"
#define pkcs11configLABEL_JITP_CERTIFICATE ( "JITP Cert" )
/**
* @brief The PKCS #11 label for the AWS Trusted Root Certificate.
*
* @see aws_default_root_certificates.h
*/
#define pkcs11configLABEL_ROOT_CERTIFICATE "Root Cert"
#define pkcs11configLABEL_ROOT_CERTIFICATE ( "Root Cert" )
#endif /* _AWS_PKCS11_CONFIG_H_ include guard. */
+10 -1
View File
@@ -55,6 +55,11 @@ __LIB_NAME_TO_SRC_DIRS_MAPPING__ = {
'ota-http' : [
os.path.join(__IOT_LIBS_BETA1_DIR__, 'c_sdk', 'aws', 'ota', 'src')
],
'pkcs11' : [
os.path.join(__IOT_LIBS_BETA2_DIR__, 'pkcs11', 'FreeRTOS-PKCS', 'source', 'iot_pkcs11.c'),
os.path.join(__IOT_LIBS_BETA2_DIR__, 'pkcs11', 'FreeRTOS-PKCS', 'source', 'iot_pki_utils.c'),
os.path.join(__IOT_LIBS_BETA2_DIR__, 'pkcs11', 'FreeRTOS-PKCS', 'source', 'portable', 'mbedtls', 'iot_pkcs11_mbedtls.c')
],
'kernel' : [
os.path.join(__FREERTOS_SRC_DIR__, 'event_groups.c'),
os.path.join(__FREERTOS_SRC_DIR__, 'list.c'),
@@ -148,6 +153,10 @@ def generate_makefile(freertos_lts, optimization, lib_name):
# Add config files dir to include dirs list.
include_dirs.append(os.path.join(__THIS_FILE_PATH__, 'config_files'))
# Add PKCS #11 include path for mbed TLS dependency.
if 'pkcs' in lib_name:
include_dirs.append(os.path.join(__IOT_LIBS_BETA2_DIR__, 'pkcs11', 'FreeRTOS-PKCS', '3rdparty', 'mbedtls', 'include'))
# Generate source files list.
if lib_name in __LIB_NAME_TO_SRC_DIRS_MAPPING__:
source_files=[]
@@ -314,4 +323,4 @@ def main():
if __name__ == '__main__':
main()
main()
@@ -31,6 +31,10 @@
{
"lib_name":"shadow",
"size_description":"Code Size of AWS IoT Device Shadow excluding dependencies (example generated with GCC for ARM Cortex-M)"
},
{
"lib_name":"pkcs11",
"size_description":"Code Size of PKCS #11 excluding dependencies (example generated with GCC for ARM Cortex-M)"
}
]
}