Branch data Line data Source code
1 : : /**
2 : : * Copyright Notice:
3 : : * Copyright 2021-2026 DMTF. All rights reserved.
4 : : * License: BSD 3-Clause License. For full text see link: https://github.com/DMTF/libspdm/blob/main/LICENSE.md
5 : : **/
6 : :
7 : : #include "internal/libspdm_common_lib.h"
8 : :
9 : 68 : uint8_t libspdm_slot_id_to_key_pair_id (
10 : : void *spdm_context,
11 : : uint8_t slot_id,
12 : : bool is_requester)
13 : : {
14 : : libspdm_context_t *context;
15 : :
16 : 68 : context = spdm_context;
17 [ + + + + ]: 68 : if (slot_id == 0xFF || slot_id == 0xF) {
18 : 6 : return 0;
19 : : }
20 [ + + ]: 62 : if (is_requester) {
21 [ + - ]: 13 : if (!context->connection_info.multi_key_conn_req) {
22 : 13 : return 0;
23 : : }
24 : : } else {
25 [ + + ]: 49 : if (!context->connection_info.multi_key_conn_rsp) {
26 : 47 : return 0;
27 : : }
28 : : }
29 [ - + ]: 2 : LIBSPDM_ASSERT(slot_id < SPDM_MAX_SLOT_COUNT);
30 : 2 : return context->local_context.local_key_pair_id[slot_id];
31 : : }
32 : :
33 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
34 : : void libspdm_get_peer_cert_chain_buffer(void *spdm_context,
35 : : uint8_t slot_id,
36 : : const void **cert_chain_buffer,
37 : : size_t *cert_chain_buffer_size)
38 : : {
39 : :
40 : : libspdm_context_t *context;
41 : :
42 : : context = spdm_context;
43 : :
44 : : LIBSPDM_ASSERT(slot_id < SPDM_MAX_SLOT_COUNT);
45 : :
46 : : *cert_chain_buffer = context->connection_info.peer_used_cert_chain[slot_id].buffer;
47 : : *cert_chain_buffer_size = context->connection_info.peer_used_cert_chain[slot_id].buffer_size;
48 : : }
49 : :
50 : : void libspdm_get_peer_cert_chain_data(void *spdm_context,
51 : : uint8_t slot_id,
52 : : const void **cert_chain_data,
53 : : size_t *cert_chain_data_size)
54 : : {
55 : : libspdm_context_t *context;
56 : : size_t hash_size;
57 : :
58 : : context = spdm_context;
59 : : hash_size = libspdm_get_hash_size(context->connection_info.algorithm.base_hash_algo);
60 : :
61 : : libspdm_get_peer_cert_chain_buffer(context, slot_id, cert_chain_data, cert_chain_data_size);
62 : : *cert_chain_data = (const uint8_t *)*cert_chain_data + sizeof(spdm_cert_chain_t) + hash_size;
63 : : *cert_chain_data_size = *cert_chain_data_size - (sizeof(spdm_cert_chain_t) + hash_size);
64 : : }
65 : : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
66 : :
67 : 50 : void libspdm_get_local_cert_chain_buffer(void *spdm_context,
68 : : uint8_t slot_id,
69 : : const void **cert_chain_buffer,
70 : : size_t *cert_chain_buffer_size)
71 : : {
72 : : libspdm_context_t *context;
73 : :
74 : 50 : context = spdm_context;
75 : :
76 [ - + ]: 50 : LIBSPDM_ASSERT(context->local_context.local_cert_chain_provision[slot_id] != NULL);
77 [ - + ]: 50 : LIBSPDM_ASSERT(context->local_context.local_cert_chain_provision_size[slot_id] != 0);
78 : :
79 : 50 : *cert_chain_buffer = context->local_context.local_cert_chain_provision[slot_id];
80 : 50 : *cert_chain_buffer_size = context->local_context.local_cert_chain_provision_size[slot_id];
81 : 50 : }
82 : :
83 : 0 : bool libspdm_get_local_cert_chain_data(void *spdm_context,
84 : : uint8_t slot_id,
85 : : const void **cert_chain_data,
86 : : size_t *cert_chain_data_size)
87 : : {
88 : : libspdm_context_t *context;
89 : : size_t hash_size;
90 : :
91 : 0 : context = spdm_context;
92 : :
93 : 0 : libspdm_get_local_cert_chain_buffer(context, slot_id, cert_chain_data, cert_chain_data_size);
94 : :
95 : 0 : hash_size = libspdm_get_hash_size(context->connection_info.algorithm.base_hash_algo);
96 : :
97 : 0 : *cert_chain_data = (const uint8_t *)*cert_chain_data + sizeof(spdm_cert_chain_t) + hash_size;
98 : 0 : *cert_chain_data_size = *cert_chain_data_size - (sizeof(spdm_cert_chain_t) + hash_size);
99 : :
100 : 0 : return true;
101 : : }
102 : :
103 : 3 : bool libspdm_get_peer_public_key_buffer(void *spdm_context,
104 : : const void **peer_public_key_buffer,
105 : : size_t *peer_public_key_buffer_size)
106 : : {
107 : : libspdm_context_t *context;
108 : :
109 : 3 : context = spdm_context;
110 [ + - ]: 3 : if (context->local_context.peer_public_key_provision_size != 0) {
111 : 3 : *peer_public_key_buffer = context->local_context.peer_public_key_provision;
112 : 3 : *peer_public_key_buffer_size = context->local_context.peer_public_key_provision_size;
113 : 3 : return true;
114 : : }
115 : 0 : return false;
116 : : }
117 : :
118 : 2 : bool libspdm_get_local_public_key_buffer(void *spdm_context,
119 : : const void **local_public_key_buffer,
120 : : size_t *local_public_key_buffer_size)
121 : : {
122 : : libspdm_context_t *context;
123 : :
124 : 2 : context = spdm_context;
125 [ + - ]: 2 : if (context->local_context.local_public_key_provision_size != 0) {
126 : 2 : *local_public_key_buffer = context->local_context.local_public_key_provision;
127 : 2 : *local_public_key_buffer_size = context->local_context.local_public_key_provision_size;
128 : 2 : return true;
129 : : }
130 : 0 : return false;
131 : : }
132 : :
133 : : #if !(LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT)
134 : 3320 : void libspdm_free_peer_leaf_cert_public_key(libspdm_context_t *context, uint8_t slot_id)
135 : : {
136 : : void *pubkey_context;
137 : :
138 : 3320 : pubkey_context = context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key;
139 [ + + ]: 3320 : if (pubkey_context == NULL) {
140 : 3251 : return;
141 : : }
142 : :
143 [ + + ]: 69 : if (context->local_context.is_requester) {
144 [ - + ]: 39 : if (context->connection_info.algorithm.pqc_asym_algo != 0) {
145 : 0 : libspdm_pqc_asym_free(context->connection_info.algorithm.pqc_asym_algo,
146 : : pubkey_context);
147 : : } else {
148 : 39 : libspdm_asym_free(context->connection_info.algorithm.base_asym_algo, pubkey_context);
149 : : }
150 : : } else {
151 [ - + ]: 30 : if (context->connection_info.algorithm.req_pqc_asym_alg != 0) {
152 : 0 : libspdm_req_pqc_asym_free(context->connection_info.algorithm.req_pqc_asym_alg,
153 : : pubkey_context);
154 : : } else {
155 : 30 : libspdm_req_asym_free(context->connection_info.algorithm.req_base_asym_alg,
156 : : pubkey_context);
157 : : }
158 : : }
159 : 69 : context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key = NULL;
160 : : }
161 : : #endif /* !(LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT) */
162 : :
163 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
164 : : bool libspdm_calculate_l1l2(libspdm_context_t *spdm_context,
165 : : void *session_info,
166 : : libspdm_l1l2_managed_buffer_t *l1l2)
167 : : {
168 : : libspdm_return_t status;
169 : : libspdm_session_info_t *spdm_session_info;
170 : :
171 : : spdm_session_info = session_info;
172 : :
173 : : libspdm_init_managed_buffer(l1l2, sizeof(l1l2->buffer));
174 : :
175 : : if ((spdm_context->connection_info.version >> SPDM_VERSION_NUMBER_SHIFT_BIT) >
176 : : SPDM_MESSAGE_VERSION_11) {
177 : :
178 : : /* Need append VCA since 1.2 script*/
179 : :
180 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
181 : : LIBSPDM_INTERNAL_DUMP_HEX(
182 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
183 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
184 : : status = libspdm_append_managed_buffer(
185 : : l1l2,
186 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
187 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
188 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
189 : : return false;
190 : : }
191 : : }
192 : :
193 : : if (spdm_session_info == NULL) {
194 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_m data :\n"));
195 : : LIBSPDM_INTERNAL_DUMP_HEX(
196 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_m),
197 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_m));
198 : : status = libspdm_append_managed_buffer(
199 : : l1l2,
200 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_m),
201 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_m));
202 : : } else {
203 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "use message_m in session :\n"));
204 : : LIBSPDM_INTERNAL_DUMP_HEX(
205 : : libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_m),
206 : : libspdm_get_managed_buffer_size(&spdm_session_info->session_transcript.message_m));
207 : : status = libspdm_append_managed_buffer(
208 : : l1l2,
209 : : libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_m),
210 : : libspdm_get_managed_buffer_size(&spdm_session_info->session_transcript.message_m));
211 : : }
212 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
213 : : return false;
214 : : }
215 : :
216 : : /* Debug code only - calculate and print value of l1l2 hash*/
217 : : LIBSPDM_DEBUG_CODE(
218 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
219 : : uint32_t hash_size = libspdm_get_hash_size(
220 : : spdm_context->connection_info.algorithm.base_hash_algo);
221 : : if (!libspdm_hash_all(
222 : : spdm_context->connection_info.algorithm.base_hash_algo,
223 : : libspdm_get_managed_buffer(l1l2),
224 : : libspdm_get_managed_buffer_size(l1l2), hash_data)) {
225 : : return false;
226 : : }
227 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "l1l2 hash - "));
228 : : LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
229 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
230 : : );
231 : :
232 : : return true;
233 : : }
234 : : #else
235 : 42 : bool libspdm_calculate_l1l2_hash(libspdm_context_t *spdm_context,
236 : : void *session_info,
237 : : size_t *l1l2_hash_size, void *l1l2_hash)
238 : : {
239 : : libspdm_session_info_t *spdm_session_info;
240 : : bool result;
241 : :
242 : : uint32_t hash_size;
243 : :
244 : 42 : spdm_session_info = session_info;
245 : :
246 : 42 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
247 : :
248 [ + + ]: 42 : if (spdm_session_info == NULL) {
249 : 39 : result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
250 : : spdm_context->transcript.digest_context_l1l2, l1l2_hash);
251 : : } else {
252 : 3 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "use message_m in session :\n"));
253 : 3 : result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
254 : : spdm_session_info->session_transcript.digest_context_l1l2,
255 : : l1l2_hash);
256 : : }
257 [ - + ]: 42 : if (!result) {
258 : 0 : return false;
259 : : }
260 : 42 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "l1l2 hash - "));
261 : 42 : LIBSPDM_INTERNAL_DUMP_DATA(l1l2_hash, hash_size);
262 : 42 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
263 : :
264 : 42 : *l1l2_hash_size = hash_size;
265 : :
266 : 42 : return true;
267 : : }
268 : : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
269 : :
270 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
271 : : /*
272 : : * This function calculates m1m2.
273 : : *
274 : : * @param context A pointer to the SPDM context.
275 : : * @param is_mut Indicate if this is from mutual authentication.
276 : : * @param m1m2 The buffer to store the m1m2
277 : : */
278 : : static bool libspdm_calculate_m1m2(void *context, bool is_mut,
279 : : libspdm_m1m2_managed_buffer_t *m1m2)
280 : : {
281 : : libspdm_context_t *spdm_context;
282 : : libspdm_return_t status;
283 : :
284 : : spdm_context = context;
285 : :
286 : : libspdm_init_managed_buffer(m1m2, sizeof(m1m2->buffer));
287 : :
288 : : if (is_mut) {
289 : : if ((spdm_context->connection_info.version >> SPDM_VERSION_NUMBER_SHIFT_BIT) >
290 : : SPDM_MESSAGE_VERSION_11) {
291 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
292 : : LIBSPDM_INTERNAL_DUMP_HEX(
293 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
294 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
295 : : status = libspdm_append_managed_buffer(
296 : : m1m2,
297 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
298 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
299 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
300 : : return false;
301 : : }
302 : : }
303 : :
304 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_mut_b data :\n"));
305 : : LIBSPDM_INTERNAL_DUMP_HEX(
306 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_mut_b),
307 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_mut_b));
308 : : status = libspdm_append_managed_buffer(
309 : : m1m2,
310 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_mut_b),
311 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_mut_b));
312 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
313 : : return false;
314 : : }
315 : :
316 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_mut_c data :\n"));
317 : : LIBSPDM_INTERNAL_DUMP_HEX(
318 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_mut_c),
319 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_mut_c));
320 : : status = libspdm_append_managed_buffer(
321 : : m1m2,
322 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_mut_c),
323 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_mut_c));
324 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
325 : : return false;
326 : : }
327 : :
328 : : /* Debug code only - calculate and print value of m1m2 mut hash*/
329 : : LIBSPDM_DEBUG_CODE(
330 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
331 : : uint32_t hash_size = libspdm_get_hash_size(
332 : : spdm_context->connection_info.algorithm.base_hash_algo);
333 : : if (!libspdm_hash_all(
334 : : spdm_context->connection_info.algorithm.base_hash_algo,
335 : : libspdm_get_managed_buffer(m1m2),
336 : : libspdm_get_managed_buffer_size(m1m2), hash_data)) {
337 : : return false;
338 : : }
339 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "m1m2 Mut hash - "));
340 : : LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
341 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
342 : : );
343 : :
344 : : } else {
345 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
346 : : LIBSPDM_INTERNAL_DUMP_HEX(
347 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
348 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
349 : : status = libspdm_append_managed_buffer(
350 : : m1m2,
351 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
352 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
353 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
354 : : return false;
355 : : }
356 : :
357 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_b data :\n"));
358 : : LIBSPDM_INTERNAL_DUMP_HEX(
359 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_b),
360 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_b));
361 : : status = libspdm_append_managed_buffer(
362 : : m1m2,
363 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_b),
364 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_b));
365 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
366 : : return false;
367 : : }
368 : :
369 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_c data :\n"));
370 : : LIBSPDM_INTERNAL_DUMP_HEX(
371 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_c),
372 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_c));
373 : : status = libspdm_append_managed_buffer(
374 : : m1m2,
375 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_c),
376 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_c));
377 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
378 : : return false;
379 : : }
380 : :
381 : : /* Debug code only - calculate and print value of m1m2 hash*/
382 : : LIBSPDM_DEBUG_CODE(
383 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
384 : : uint32_t hash_size = libspdm_get_hash_size(
385 : : spdm_context->connection_info.algorithm.base_hash_algo);
386 : : if (!libspdm_hash_all(
387 : : spdm_context->connection_info.algorithm.base_hash_algo,
388 : : libspdm_get_managed_buffer(m1m2),
389 : : libspdm_get_managed_buffer_size(m1m2), hash_data)) {
390 : : return false;
391 : : }
392 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "m1m2 hash - "));
393 : : LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
394 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
395 : : );
396 : : }
397 : :
398 : : return true;
399 : : }
400 : : #else
401 : : /*
402 : : * This function calculates m1m2 hash.
403 : : *
404 : : * @param context A pointer to the SPDM context.
405 : : * @param is_mut Indicate if this is from mutual authentication.
406 : : * @param m1m2_hash_size size in bytes of the m1m2 hash
407 : : * @param m1m2_hash The buffer to store the m1m2 hash
408 : : */
409 : 38 : static bool libspdm_calculate_m1m2_hash(void *context, bool is_mut,
410 : : size_t *m1m2_hash_size,
411 : : void *m1m2_hash)
412 : : {
413 : : libspdm_context_t *spdm_context;
414 : : uint32_t hash_size;
415 : : bool result;
416 : :
417 : 38 : spdm_context = context;
418 : :
419 : 38 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
420 : :
421 [ + + ]: 38 : if (is_mut) {
422 : 8 : result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
423 : : spdm_context->transcript.digest_context_mut_m1m2, m1m2_hash);
424 [ - + ]: 8 : if (!result) {
425 : 0 : return false;
426 : : }
427 : 8 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "m1m2 Mut hash - "));
428 : 8 : LIBSPDM_INTERNAL_DUMP_DATA(m1m2_hash, hash_size);
429 : 8 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
430 : :
431 : : } else {
432 : 30 : result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
433 : : spdm_context->transcript.digest_context_m1m2, m1m2_hash);
434 [ - + ]: 30 : if (!result) {
435 : 0 : return false;
436 : : }
437 : 30 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "m1m2 hash - "));
438 : 30 : LIBSPDM_INTERNAL_DUMP_DATA(m1m2_hash, hash_size);
439 : 30 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
440 : : }
441 : :
442 : 38 : *m1m2_hash_size = hash_size;
443 : :
444 : 38 : return true;
445 : : }
446 : : #endif
447 : :
448 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
449 : : static bool libspdm_calculate_il1il2(libspdm_context_t *spdm_context,
450 : : void *session_info,
451 : : bool is_mut,
452 : : libspdm_il1il2_managed_buffer_t *il1il2)
453 : : {
454 : : libspdm_return_t status;
455 : : libspdm_session_info_t *spdm_session_info;
456 : :
457 : : spdm_session_info = session_info;
458 : :
459 : : libspdm_init_managed_buffer(il1il2, sizeof(il1il2->buffer));
460 : :
461 : :
462 : : if (is_mut) {
463 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
464 : : LIBSPDM_INTERNAL_DUMP_HEX(
465 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
466 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
467 : : status = libspdm_append_managed_buffer(
468 : : il1il2,
469 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
470 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
471 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
472 : : return false;
473 : : }
474 : :
475 : : if (spdm_session_info == NULL) {
476 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_encap_e data :\n"));
477 : : LIBSPDM_INTERNAL_DUMP_HEX(
478 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_encap_e),
479 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_encap_e));
480 : : status = libspdm_append_managed_buffer(
481 : : il1il2,
482 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_encap_e),
483 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_encap_e));
484 : : } else {
485 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "use message_encap_e in session :\n"));
486 : : LIBSPDM_INTERNAL_DUMP_HEX(
487 : : libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_encap_e),
488 : : libspdm_get_managed_buffer_size(
489 : : &spdm_session_info->session_transcript.message_encap_e));
490 : : status = libspdm_append_managed_buffer(
491 : : il1il2,
492 : : libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_encap_e),
493 : : libspdm_get_managed_buffer_size(
494 : : &spdm_session_info->session_transcript.message_encap_e));
495 : : }
496 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
497 : : return false;
498 : : }
499 : :
500 : : /* Debug code only - calculate and print value of il1il2 hash*/
501 : : LIBSPDM_DEBUG_CODE(
502 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
503 : : uint32_t hash_size = libspdm_get_hash_size(
504 : : spdm_context->connection_info.algorithm.base_hash_algo);
505 : : if (!libspdm_hash_all(
506 : : spdm_context->connection_info.algorithm.base_hash_algo,
507 : : libspdm_get_managed_buffer(il1il2),
508 : : libspdm_get_managed_buffer_size(il1il2), hash_data)) {
509 : : return false;
510 : : }
511 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "il1il2 mut hash - "));
512 : : LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
513 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
514 : : );
515 : : } else {
516 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_a data :\n"));
517 : : LIBSPDM_INTERNAL_DUMP_HEX(
518 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
519 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
520 : : status = libspdm_append_managed_buffer(
521 : : il1il2,
522 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_a),
523 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_a));
524 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
525 : : return false;
526 : : }
527 : :
528 : : if (spdm_session_info == NULL) {
529 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "message_e data :\n"));
530 : : LIBSPDM_INTERNAL_DUMP_HEX(
531 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_e),
532 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_e));
533 : : status = libspdm_append_managed_buffer(
534 : : il1il2,
535 : : libspdm_get_managed_buffer(&spdm_context->transcript.message_e),
536 : : libspdm_get_managed_buffer_size(&spdm_context->transcript.message_e));
537 : : } else {
538 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "use message_e in session :\n"));
539 : : LIBSPDM_INTERNAL_DUMP_HEX(
540 : : libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_e),
541 : : libspdm_get_managed_buffer_size(&spdm_session_info->session_transcript.message_e));
542 : : status = libspdm_append_managed_buffer(
543 : : il1il2,
544 : : libspdm_get_managed_buffer(&spdm_session_info->session_transcript.message_e),
545 : : libspdm_get_managed_buffer_size(&spdm_session_info->session_transcript.message_e));
546 : : }
547 : : if (LIBSPDM_STATUS_IS_ERROR(status)) {
548 : : return false;
549 : : }
550 : :
551 : : /* Debug code only - calculate and print value of il1il2 hash*/
552 : : LIBSPDM_DEBUG_CODE(
553 : : uint8_t hash_data[LIBSPDM_MAX_HASH_SIZE];
554 : : uint32_t hash_size = libspdm_get_hash_size(
555 : : spdm_context->connection_info.algorithm.base_hash_algo);
556 : : if (!libspdm_hash_all(
557 : : spdm_context->connection_info.algorithm.base_hash_algo,
558 : : libspdm_get_managed_buffer(il1il2),
559 : : libspdm_get_managed_buffer_size(il1il2), hash_data)) {
560 : : return false;
561 : : }
562 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "il1il2 hash - "));
563 : : LIBSPDM_INTERNAL_DUMP_DATA(hash_data, hash_size);
564 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
565 : : );
566 : : }
567 : :
568 : : return true;
569 : : }
570 : : #else
571 : 31 : static bool libspdm_calculate_il1il2_hash(libspdm_context_t *spdm_context,
572 : : void *session_info, bool is_encap,
573 : : size_t *il1il2_hash_size, void *il1il2_hash)
574 : : {
575 : : libspdm_session_info_t *spdm_session_info;
576 : : bool result;
577 : :
578 : : uint32_t hash_size;
579 : :
580 : 31 : spdm_session_info = session_info;
581 : :
582 : 31 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
583 : :
584 [ + + ]: 31 : if (spdm_session_info == NULL) {
585 [ + + ]: 26 : if (is_encap) {
586 : 12 : result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
587 : : spdm_context->transcript.digest_context_encap_il1il2,
588 : : il1il2_hash);
589 : : } else {
590 : 14 : result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
591 : : spdm_context->transcript.digest_context_il1il2,
592 : : il1il2_hash);
593 : : }
594 : : } else {
595 [ + + ]: 5 : if (is_encap) {
596 : 2 : result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
597 : : spdm_session_info->session_transcript.digest_context_encap_il1il2,
598 : : il1il2_hash);
599 : : } else {
600 : 3 : result = libspdm_hash_final (spdm_context->connection_info.algorithm.base_hash_algo,
601 : : spdm_session_info->session_transcript.digest_context_il1il2,
602 : : il1il2_hash);
603 : : }
604 : : }
605 [ - + ]: 31 : if (!result) {
606 : 0 : return false;
607 : : }
608 : 31 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "il1il2 hash - "));
609 : 31 : LIBSPDM_INTERNAL_DUMP_DATA(il1il2_hash, hash_size);
610 : 31 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "\n"));
611 : :
612 : 31 : *il1il2_hash_size = hash_size;
613 : :
614 : 31 : return true;
615 : : }
616 : : #endif /* LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT */
617 : :
618 : 45 : bool libspdm_generate_cert_chain_hash(libspdm_context_t *spdm_context,
619 : : size_t slot_id, uint8_t *hash)
620 : : {
621 [ - + ]: 45 : LIBSPDM_ASSERT(slot_id < SPDM_MAX_SLOT_COUNT);
622 : 45 : return libspdm_hash_all(
623 : : spdm_context->connection_info.algorithm.base_hash_algo,
624 : : spdm_context->local_context.local_cert_chain_provision[slot_id],
625 : : spdm_context->local_context.local_cert_chain_provision_size[slot_id], hash);
626 : : }
627 : :
628 : 2 : bool libspdm_generate_public_key_hash(libspdm_context_t *spdm_context,
629 : : uint8_t *hash)
630 : : {
631 : 2 : return libspdm_hash_all(
632 : : spdm_context->connection_info.algorithm.base_hash_algo,
633 : : spdm_context->local_context.local_public_key_provision,
634 : : spdm_context->local_context.local_public_key_provision_size, hash);
635 : : }
636 : :
637 : 13 : uint8_t libspdm_get_cert_slot_mask(libspdm_context_t *spdm_context)
638 : : {
639 : : size_t index;
640 : : uint8_t slot_mask;
641 : :
642 : 13 : slot_mask = 0;
643 [ + + ]: 117 : for (index = 0; index < SPDM_MAX_SLOT_COUNT; index++) {
644 [ + + ]: 104 : if (spdm_context->local_context.local_cert_chain_provision[index] != NULL) {
645 : 14 : slot_mask |= (1 << index);
646 : : }
647 : : }
648 : :
649 : 13 : return slot_mask;
650 : : }
651 : :
652 : 23 : uint8_t libspdm_get_cert_slot_count(libspdm_context_t *spdm_context)
653 : : {
654 : : size_t index;
655 : : uint8_t slot_count;
656 : :
657 : 23 : slot_count = 0;
658 [ + + ]: 207 : for (index = 0; index < SPDM_MAX_SLOT_COUNT; index++) {
659 [ + + ]: 184 : if (spdm_context->local_context.local_cert_chain_provision[index] != NULL) {
660 : 32 : slot_count++;
661 : : }
662 : : }
663 : :
664 : 23 : return slot_count;
665 : : }
666 : :
667 : : #if LIBSPDM_CERT_PARSE_SUPPORT
668 : 40 : bool libspdm_verify_peer_cert_chain_buffer_integrity(libspdm_context_t *spdm_context,
669 : : const void *cert_chain_buffer,
670 : : size_t cert_chain_buffer_size)
671 : : {
672 : : bool result;
673 : : uint8_t cert_model;
674 : : bool is_requester;
675 : :
676 : 40 : is_requester = spdm_context->local_context.is_requester;
677 : :
678 : 40 : cert_model = SPDM_CERTIFICATE_INFO_CERT_MODEL_ALIAS_CERT;
679 : : /* Responder does not determine Requester's certificate model */
680 [ + + ]: 40 : if (is_requester) {
681 [ + + ]: 37 : if ((spdm_context->connection_info.capability.flags &
682 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_ALIAS_CERT_CAP) == 0) {
683 : 34 : cert_model = SPDM_CERTIFICATE_INFO_CERT_MODEL_DEVICE_CERT;
684 : : }
685 : : }
686 : :
687 [ + + ]: 40 : if (is_requester) {
688 : 37 : result = libspdm_verify_certificate_chain_buffer(
689 : 37 : libspdm_get_connection_version(spdm_context),
690 : : spdm_context->connection_info.algorithm.base_hash_algo,
691 : : spdm_context->connection_info.algorithm.base_asym_algo,
692 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
693 : : cert_chain_buffer, cert_chain_buffer_size,
694 : : false, cert_model);
695 : : } else {
696 : 3 : result = libspdm_verify_certificate_chain_buffer(
697 : 3 : libspdm_get_connection_version(spdm_context),
698 : : spdm_context->connection_info.algorithm.base_hash_algo,
699 : 3 : spdm_context->connection_info.algorithm.req_base_asym_alg,
700 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
701 : : cert_chain_buffer, cert_chain_buffer_size,
702 : : true, cert_model);
703 : : }
704 : :
705 : 40 : return result;
706 : : }
707 : :
708 : 32 : bool libspdm_verify_peer_cert_chain_buffer_authority(libspdm_context_t *spdm_context,
709 : : const void *cert_chain_buffer,
710 : : size_t cert_chain_buffer_size,
711 : : const void **trust_anchor,
712 : : size_t *trust_anchor_size)
713 : : {
714 : : const uint8_t *root_cert;
715 : : size_t root_cert_size;
716 : : uint8_t root_cert_index;
717 : : size_t root_cert_hash_size;
718 : : uint8_t root_cert_hash[LIBSPDM_MAX_HASH_SIZE];
719 : : const uint8_t *received_root_cert;
720 : : size_t received_root_cert_size;
721 : : bool result;
722 : :
723 : 32 : root_cert_index = 0;
724 : 32 : root_cert = spdm_context->local_context.peer_root_cert_provision[root_cert_index];
725 : 32 : root_cert_size = spdm_context->local_context.peer_root_cert_provision_size[root_cert_index];
726 : :
727 : 32 : root_cert_hash_size = libspdm_get_hash_size(
728 : : spdm_context->connection_info.algorithm.base_hash_algo);
729 : :
730 [ + + + - ]: 32 : if ((root_cert != NULL) && (root_cert_size != 0)) {
731 [ + - + - ]: 63 : while ((root_cert != NULL) && (root_cert_size != 0)) {
732 : 63 : result = libspdm_hash_all(
733 : : spdm_context->connection_info.algorithm.base_hash_algo,
734 : : root_cert, root_cert_size, root_cert_hash);
735 [ - + ]: 63 : if (!result) {
736 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
737 : : "!!! verify_peer_cert_chain_buffer - FAIL (hash calculation) !!!\n"));
738 : 0 : return false;
739 : : }
740 : :
741 [ + + ]: 63 : if (libspdm_consttime_is_mem_equal((const uint8_t *)cert_chain_buffer +
742 : : sizeof(spdm_cert_chain_t),
743 : : root_cert_hash, root_cert_hash_size)) {
744 : 24 : break;
745 : : }
746 : :
747 : : #if (LIBSPDM_MAX_ROOT_CERT_SUPPORT) > 1
748 [ + + ]: 39 : if ((root_cert_index < ((LIBSPDM_MAX_ROOT_CERT_SUPPORT) -1)) &&
749 [ + + ]: 38 : (spdm_context->local_context.peer_root_cert_provision[root_cert_index + 1] !=
750 : : NULL)) {
751 : 34 : root_cert_index++;
752 : 34 : root_cert = spdm_context->local_context.peer_root_cert_provision[root_cert_index];
753 : 34 : root_cert_size =
754 : 34 : spdm_context->local_context.peer_root_cert_provision_size[root_cert_index];
755 : : } else
756 : : #endif /* LIBSPDM_MAX_ROOT_CERT_SUPPORT */
757 : : {
758 : 5 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
759 : : "!!! verify_peer_cert_chain_buffer - "
760 : : "FAIL (all root cert hash mismatch) !!!\n"));
761 : 5 : return false;
762 : : }
763 : : }
764 : :
765 : 24 : result = libspdm_x509_get_cert_from_cert_chain(
766 : 24 : (const uint8_t *)cert_chain_buffer + sizeof(spdm_cert_chain_t) + root_cert_hash_size,
767 : 24 : cert_chain_buffer_size - sizeof(spdm_cert_chain_t) - root_cert_hash_size,
768 : : 0, &received_root_cert, &received_root_cert_size);
769 [ - + ]: 24 : if (!result) {
770 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
771 : : "!!! verify_peer_cert_chain_buffer - FAIL (cert retrieval fail) !!!\n"));
772 : 0 : return false;
773 : : }
774 [ + + ]: 24 : if (libspdm_is_root_certificate(received_root_cert, received_root_cert_size)) {
775 [ + - ]: 23 : if ((root_cert != NULL) &&
776 [ - + ]: 23 : !libspdm_consttime_is_mem_equal(received_root_cert, root_cert, root_cert_size)) {
777 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
778 : : "!!! verify_peer_cert_chain_buffer - "
779 : : "FAIL (root cert mismatch) !!!\n"));
780 : 0 : return false;
781 : : }
782 : : } else {
783 [ - + ]: 1 : if (!libspdm_x509_verify_cert(received_root_cert, received_root_cert_size,
784 : : root_cert, root_cert_size)) {
785 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
786 : : "!!! verify_peer_cert_chain_buffer - "
787 : : "FAIL (received root cert verify failed)!!!\n"));
788 : 0 : return false;
789 : : }
790 : : }
791 [ + + ]: 24 : if (trust_anchor != NULL) {
792 : 5 : *trust_anchor = root_cert;
793 : : }
794 [ + + ]: 24 : if (trust_anchor_size != NULL) {
795 : 5 : *trust_anchor_size = root_cert_size;
796 : : }
797 : : }
798 : : /*
799 : : * When there is no root_cert in local_context, the return is true too.
800 : : * No root_cert means the caller wants to verify the trust anchor of the cert chain.
801 : : */
802 : 27 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_peer_cert_chain_buffer - PASS !!!\n"));
803 : :
804 : 27 : return true;
805 : : }
806 : : #endif
807 : :
808 : 15 : bool libspdm_generate_challenge_auth_signature(libspdm_context_t *spdm_context,
809 : : bool is_requester,
810 : : uint8_t slot_id,
811 : : uint8_t *signature)
812 : : {
813 : : bool result;
814 : : size_t signature_size;
815 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
816 : : libspdm_m1m2_managed_buffer_t m1m2;
817 : : uint8_t *m1m2_buffer;
818 : : size_t m1m2_buffer_size;
819 : : #else
820 : : uint8_t m1m2_hash[LIBSPDM_MAX_HASH_SIZE];
821 : : size_t m1m2_hash_size;
822 : : #endif
823 : :
824 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
825 : : result = libspdm_calculate_m1m2(spdm_context, is_requester, &m1m2);
826 : : m1m2_buffer = libspdm_get_managed_buffer(&m1m2);
827 : : m1m2_buffer_size = libspdm_get_managed_buffer_size(&m1m2);
828 : : #else
829 : 15 : m1m2_hash_size = sizeof(m1m2_hash);
830 : 15 : result = libspdm_calculate_m1m2_hash(spdm_context, is_requester, &m1m2_hash_size, &m1m2_hash);
831 : : #endif
832 [ + + ]: 15 : if (is_requester) {
833 : 4 : libspdm_reset_message_mut_b(spdm_context);
834 : 4 : libspdm_reset_message_mut_c(spdm_context);
835 : : } else {
836 : 11 : libspdm_reset_message_b(spdm_context);
837 : 11 : libspdm_reset_message_c(spdm_context);
838 : : }
839 [ - + ]: 15 : if (!result) {
840 : 0 : return false;
841 : : }
842 : :
843 [ + + ]: 15 : if (is_requester) {
844 : : #if LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP
845 [ - + ]: 4 : if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
846 : 0 : signature_size = libspdm_get_req_pqc_asym_signature_size(
847 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg);
848 : : } else {
849 : 4 : signature_size = libspdm_get_req_asym_signature_size(
850 : 4 : spdm_context->connection_info.algorithm.req_base_asym_alg);
851 : : }
852 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
853 : : result = libspdm_requester_data_sign(
854 : : spdm_context,
855 : : spdm_context->connection_info.version,
856 : : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, true),
857 : : SPDM_CHALLENGE_AUTH,
858 : : spdm_context->connection_info.algorithm.req_base_asym_alg,
859 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
860 : : spdm_context->connection_info.algorithm.base_hash_algo,
861 : : false, m1m2_buffer, m1m2_buffer_size, signature, &signature_size);
862 : : #else
863 : 8 : result = libspdm_requester_data_sign(
864 : : spdm_context,
865 : 4 : spdm_context->connection_info.version,
866 : 4 : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, true),
867 : : SPDM_CHALLENGE_AUTH,
868 : 4 : spdm_context->connection_info.algorithm.req_base_asym_alg,
869 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
870 : : spdm_context->connection_info.algorithm.base_hash_algo,
871 : : true, m1m2_hash, m1m2_hash_size, signature, &signature_size);
872 : : #endif
873 : : #else /* LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP */
874 : : result = false;
875 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_MUT_AUTH_CAP */
876 : : } else {
877 [ - + ]: 11 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
878 : 0 : signature_size = libspdm_get_pqc_asym_signature_size(
879 : : spdm_context->connection_info.algorithm.pqc_asym_algo);
880 : : } else {
881 : 11 : signature_size = libspdm_get_asym_signature_size(
882 : : spdm_context->connection_info.algorithm.base_asym_algo);
883 : : }
884 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
885 : : result = libspdm_responder_data_sign(
886 : : spdm_context,
887 : : spdm_context->connection_info.version,
888 : : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
889 : : SPDM_CHALLENGE_AUTH,
890 : : spdm_context->connection_info.algorithm.base_asym_algo,
891 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
892 : : spdm_context->connection_info.algorithm.base_hash_algo,
893 : : false, m1m2_buffer, m1m2_buffer_size, signature,
894 : : &signature_size);
895 : : #else
896 : 22 : result = libspdm_responder_data_sign(
897 : : spdm_context,
898 : 11 : spdm_context->connection_info.version,
899 : 11 : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
900 : : SPDM_CHALLENGE_AUTH,
901 : : spdm_context->connection_info.algorithm.base_asym_algo,
902 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
903 : : spdm_context->connection_info.algorithm.base_hash_algo,
904 : : true, m1m2_hash, m1m2_hash_size, signature,
905 : : &signature_size);
906 : : #endif
907 : : }
908 : :
909 : 15 : return result;
910 : : }
911 : :
912 : 24 : bool libspdm_verify_certificate_chain_hash(libspdm_context_t *spdm_context,
913 : : uint8_t slot_id,
914 : : const void *certificate_chain_hash,
915 : : size_t certificate_chain_hash_size)
916 : : {
917 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
918 : : size_t hash_size;
919 : : uint8_t cert_chain_buffer_hash[LIBSPDM_MAX_HASH_SIZE];
920 : : const uint8_t *cert_chain_buffer;
921 : : size_t cert_chain_buffer_size;
922 : : bool result;
923 : :
924 : : libspdm_get_peer_cert_chain_buffer(spdm_context,
925 : : slot_id,
926 : : (const void **)&cert_chain_buffer,
927 : : &cert_chain_buffer_size);
928 : :
929 : : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
930 : :
931 : : result = libspdm_hash_all(spdm_context->connection_info.algorithm.base_hash_algo,
932 : : cert_chain_buffer, cert_chain_buffer_size,
933 : : cert_chain_buffer_hash);
934 : : if (!result) {
935 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
936 : : "!!! verify_certificate_chain_hash - FAIL (hash calculation) !!!\n"));
937 : : return false;
938 : : }
939 : :
940 : : if (hash_size != certificate_chain_hash_size) {
941 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_certificate_chain_hash - FAIL !!!\n"));
942 : : return false;
943 : : }
944 : : if (!libspdm_consttime_is_mem_equal(certificate_chain_hash, cert_chain_buffer_hash,
945 : : certificate_chain_hash_size)) {
946 : : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_certificate_chain_hash - FAIL !!!\n"));
947 : : return false;
948 : : }
949 : : #else
950 [ - + ]: 24 : LIBSPDM_ASSERT(
951 : : spdm_context->connection_info.peer_used_cert_chain[slot_id].buffer_hash_size != 0);
952 : :
953 [ - + ]: 24 : if (spdm_context->connection_info.peer_used_cert_chain[slot_id].buffer_hash_size !=
954 : : certificate_chain_hash_size) {
955 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_certificate_chain_hash - FAIL !!!\n"));
956 : 0 : return false;
957 : : }
958 : :
959 [ - + ]: 24 : if (!libspdm_consttime_is_mem_equal(certificate_chain_hash,
960 : 24 : spdm_context->connection_info.peer_used_cert_chain[slot_id].
961 : : buffer_hash, certificate_chain_hash_size)) {
962 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_certificate_chain_hash - FAIL !!!\n"));
963 : 0 : return false;
964 : : }
965 : : #endif
966 : 24 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_certificate_chain_hash - PASS !!!\n"));
967 : 24 : return true;
968 : : }
969 : :
970 : 2 : bool libspdm_verify_public_key_hash(libspdm_context_t *spdm_context,
971 : : const void *public_key_hash,
972 : : size_t public_key_hash_size)
973 : : {
974 : : size_t hash_size;
975 : : uint8_t public_key_buffer_hash[LIBSPDM_MAX_HASH_SIZE];
976 : : bool result;
977 : :
978 : 2 : hash_size = libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
979 : :
980 : 2 : result = libspdm_hash_all(spdm_context->connection_info.algorithm.base_hash_algo,
981 : : spdm_context->local_context.peer_public_key_provision,
982 : : spdm_context->local_context.peer_public_key_provision_size,
983 : : public_key_buffer_hash);
984 [ - + ]: 2 : if (!result) {
985 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
986 : : "!!! verify_public_key_hash - FAIL (hash calculation) !!!\n"));
987 : 0 : return false;
988 : : }
989 : :
990 [ - + ]: 2 : if (hash_size != public_key_hash_size) {
991 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_public_key_hash - FAIL !!!\n"));
992 : 0 : return false;
993 : : }
994 [ - + ]: 2 : if (!libspdm_consttime_is_mem_equal(public_key_hash, public_key_buffer_hash,
995 : : public_key_hash_size)) {
996 : 0 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_public_key_hash - FAIL !!!\n"));
997 : 0 : return false;
998 : : }
999 : :
1000 : 2 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_public_key_hash - PASS !!!\n"));
1001 : 2 : return true;
1002 : : }
1003 : :
1004 : 23 : bool libspdm_verify_challenge_auth_signature(libspdm_context_t *spdm_context,
1005 : : bool is_requester,
1006 : : uint8_t slot_id,
1007 : : const void *sign_data,
1008 : : size_t sign_data_size)
1009 : : {
1010 : : bool result;
1011 : : void *context;
1012 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1013 : : libspdm_m1m2_managed_buffer_t m1m2;
1014 : : uint8_t *m1m2_buffer;
1015 : : size_t m1m2_buffer_size;
1016 : : const uint8_t *cert_buffer;
1017 : : size_t cert_buffer_size;
1018 : : const uint8_t *cert_chain_data;
1019 : : size_t cert_chain_data_size;
1020 : : #else
1021 : : uint8_t m1m2_hash[LIBSPDM_MAX_HASH_SIZE];
1022 : : size_t m1m2_hash_size;
1023 : : #endif
1024 : :
1025 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1026 : : result = libspdm_calculate_m1m2(spdm_context, !is_requester, &m1m2);
1027 : : m1m2_buffer = libspdm_get_managed_buffer(&m1m2);
1028 : : m1m2_buffer_size = libspdm_get_managed_buffer_size(&m1m2);
1029 : : #else
1030 : 23 : m1m2_hash_size = sizeof(m1m2_hash);
1031 : 23 : result = libspdm_calculate_m1m2_hash(spdm_context, !is_requester, &m1m2_hash_size, &m1m2_hash);
1032 : : #endif
1033 [ + + ]: 23 : if (is_requester) {
1034 : 19 : libspdm_reset_message_b(spdm_context);
1035 : 19 : libspdm_reset_message_c(spdm_context);
1036 : : } else {
1037 : 4 : libspdm_reset_message_mut_b(spdm_context);
1038 : 4 : libspdm_reset_message_mut_c(spdm_context);
1039 : : }
1040 [ - + ]: 23 : if (!result) {
1041 : 0 : return false;
1042 : : }
1043 : :
1044 [ + + ]: 23 : if (slot_id == 0xFF) {
1045 [ + + ]: 2 : if (is_requester) {
1046 [ - + ]: 1 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
1047 : 0 : result = libspdm_pqc_asym_get_public_key_from_der(
1048 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1049 : 0 : spdm_context->local_context.peer_public_key_provision,
1050 : : spdm_context->local_context.peer_public_key_provision_size,
1051 : : &context);
1052 : : } else {
1053 : 1 : result = libspdm_asym_get_public_key_from_der(
1054 : : spdm_context->connection_info.algorithm.base_asym_algo,
1055 : 1 : spdm_context->local_context.peer_public_key_provision,
1056 : : spdm_context->local_context.peer_public_key_provision_size,
1057 : : &context);
1058 : : }
1059 : : } else {
1060 [ - + ]: 1 : if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
1061 : 0 : result = libspdm_req_pqc_asym_get_public_key_from_der(
1062 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1063 : 0 : spdm_context->local_context.peer_public_key_provision,
1064 : : spdm_context->local_context.peer_public_key_provision_size,
1065 : : &context);
1066 : : } else {
1067 : 1 : result = libspdm_req_asym_get_public_key_from_der(
1068 : 1 : spdm_context->connection_info.algorithm.req_base_asym_alg,
1069 : 1 : spdm_context->local_context.peer_public_key_provision,
1070 : : spdm_context->local_context.peer_public_key_provision_size,
1071 : : &context);
1072 : : }
1073 : : }
1074 [ - + ]: 2 : if (!result) {
1075 : 0 : return false;
1076 : : }
1077 : : } else {
1078 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1079 : : libspdm_get_peer_cert_chain_data(
1080 : : spdm_context, slot_id, (const void **)&cert_chain_data, &cert_chain_data_size);
1081 : :
1082 : : /* Get leaf cert from cert chain*/
1083 : : result = libspdm_x509_get_cert_from_cert_chain(
1084 : : cert_chain_data, cert_chain_data_size, -1, &cert_buffer, &cert_buffer_size);
1085 : : if (!result) {
1086 : : return false;
1087 : : }
1088 : :
1089 : : if (is_requester) {
1090 : : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
1091 : : result = libspdm_pqc_asym_get_public_key_from_x509(
1092 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1093 : : cert_buffer, cert_buffer_size, &context);
1094 : : } else {
1095 : : result = libspdm_asym_get_public_key_from_x509(
1096 : : spdm_context->connection_info.algorithm.base_asym_algo,
1097 : : cert_buffer, cert_buffer_size, &context);
1098 : : }
1099 : : } else {
1100 : : if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
1101 : : result = libspdm_req_pqc_asym_get_public_key_from_x509(
1102 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1103 : : cert_buffer, cert_buffer_size, &context);
1104 : : } else {
1105 : : result = libspdm_req_asym_get_public_key_from_x509(
1106 : : spdm_context->connection_info.algorithm.req_base_asym_alg,
1107 : : cert_buffer, cert_buffer_size, &context);
1108 : : }
1109 : : }
1110 : : if (!result) {
1111 : : return false;
1112 : : }
1113 : : #else
1114 : 21 : context = spdm_context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key;
1115 [ - + ]: 21 : LIBSPDM_ASSERT(context != NULL);
1116 : : #endif
1117 : : }
1118 : :
1119 [ + + ]: 23 : if (is_requester) {
1120 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1121 : : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
1122 : : result = libspdm_pqc_asym_verify(
1123 : : spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
1124 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1125 : : spdm_context->connection_info.algorithm.base_hash_algo,
1126 : : context, m1m2_buffer, m1m2_buffer_size, sign_data, sign_data_size);
1127 : : libspdm_pqc_asym_free(
1128 : : spdm_context->connection_info.algorithm.pqc_asym_algo, context);
1129 : : } else {
1130 : : result = libspdm_asym_verify_ex(
1131 : : spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
1132 : : spdm_context->connection_info.algorithm.base_asym_algo,
1133 : : spdm_context->connection_info.algorithm.base_hash_algo,
1134 : : context, m1m2_buffer, m1m2_buffer_size, sign_data, sign_data_size,
1135 : : &spdm_context->spdm_10_11_verify_signature_endian);
1136 : : libspdm_asym_free(
1137 : : spdm_context->connection_info.algorithm.base_asym_algo, context);
1138 : : }
1139 : : #else
1140 [ - + ]: 19 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
1141 : 0 : result = libspdm_pqc_asym_verify_hash(
1142 : 0 : spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
1143 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1144 : : spdm_context->connection_info.algorithm.base_hash_algo,
1145 : : context, m1m2_hash, m1m2_hash_size, sign_data, sign_data_size);
1146 [ # # ]: 0 : if (slot_id == 0xFF) {
1147 : 0 : libspdm_pqc_asym_free(
1148 : : spdm_context->connection_info.algorithm.pqc_asym_algo, context);
1149 : : }
1150 : : } else {
1151 : 19 : result = libspdm_asym_verify_hash_ex(
1152 : 19 : spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
1153 : : spdm_context->connection_info.algorithm.base_asym_algo,
1154 : : spdm_context->connection_info.algorithm.base_hash_algo,
1155 : : context, m1m2_hash, m1m2_hash_size, sign_data, sign_data_size,
1156 : : &spdm_context->spdm_10_11_verify_signature_endian);
1157 [ + + ]: 19 : if (slot_id == 0xFF) {
1158 : 1 : libspdm_asym_free(
1159 : : spdm_context->connection_info.algorithm.base_asym_algo, context);
1160 : : }
1161 : : }
1162 : : #endif
1163 : : } else {
1164 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1165 : : if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
1166 : : result = libspdm_req_pqc_asym_verify(
1167 : : spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
1168 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1169 : : spdm_context->connection_info.algorithm.base_hash_algo,
1170 : : context, m1m2_buffer, m1m2_buffer_size, sign_data, sign_data_size);
1171 : : libspdm_req_pqc_asym_free(
1172 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg, context);
1173 : : } else {
1174 : : result = libspdm_req_asym_verify_ex(
1175 : : spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
1176 : : spdm_context->connection_info.algorithm.req_base_asym_alg,
1177 : : spdm_context->connection_info.algorithm.base_hash_algo,
1178 : : context, m1m2_buffer, m1m2_buffer_size, sign_data, sign_data_size,
1179 : : &spdm_context->spdm_10_11_verify_signature_endian);
1180 : : libspdm_req_asym_free(
1181 : : spdm_context->connection_info.algorithm.req_base_asym_alg, context);
1182 : : }
1183 : : #else
1184 [ - + ]: 4 : if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
1185 : 0 : result = libspdm_req_pqc_asym_verify_hash(
1186 : 0 : spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
1187 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1188 : : spdm_context->connection_info.algorithm.base_hash_algo,
1189 : : context, m1m2_hash, m1m2_hash_size, sign_data, sign_data_size);
1190 [ # # ]: 0 : if (slot_id == 0xFF) {
1191 : 0 : libspdm_req_pqc_asym_free(
1192 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg, context);
1193 : : }
1194 : : } else {
1195 : 4 : result = libspdm_req_asym_verify_hash_ex(
1196 : 4 : spdm_context->connection_info.version, SPDM_CHALLENGE_AUTH,
1197 : 4 : spdm_context->connection_info.algorithm.req_base_asym_alg,
1198 : : spdm_context->connection_info.algorithm.base_hash_algo,
1199 : : context, m1m2_hash, m1m2_hash_size, sign_data, sign_data_size,
1200 : : &spdm_context->spdm_10_11_verify_signature_endian);
1201 [ + + ]: 4 : if (slot_id == 0xFF) {
1202 : 1 : libspdm_req_asym_free(
1203 : 1 : spdm_context->connection_info.algorithm.req_base_asym_alg, context);
1204 : : }
1205 : : }
1206 : : #endif
1207 : : }
1208 [ + + ]: 23 : if (!result) {
1209 : 1 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR,
1210 : : "!!! verify_challenge_signature - FAIL !!!\n"));
1211 : 1 : return false;
1212 : : }
1213 : :
1214 : 22 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_challenge_signature - PASS !!!\n"));
1215 : :
1216 : 22 : return true;
1217 : : }
1218 : :
1219 : : uint32_t
1220 : 148 : libspdm_get_measurement_summary_hash_size(libspdm_context_t *spdm_context,
1221 : : bool is_requester,
1222 : : uint8_t measurement_summary_hash_type)
1223 : : {
1224 [ + + ]: 148 : if (!libspdm_is_capabilities_flag_supported(
1225 : : spdm_context, is_requester, 0,
1226 : : SPDM_GET_CAPABILITIES_RESPONSE_FLAGS_MEAS_CAP)) {
1227 : 93 : return 0;
1228 : : }
1229 : :
1230 [ + + + ]: 55 : switch (measurement_summary_hash_type) {
1231 : 27 : case SPDM_REQUEST_NO_MEASUREMENT_SUMMARY_HASH:
1232 : 27 : return 0;
1233 : : break;
1234 : :
1235 : 26 : case SPDM_REQUEST_TCB_COMPONENT_MEASUREMENT_HASH:
1236 : : case SPDM_REQUEST_ALL_MEASUREMENTS_HASH:
1237 : 26 : return libspdm_get_hash_size(spdm_context->connection_info.algorithm.base_hash_algo);
1238 : : break;
1239 : 2 : default:
1240 : 2 : return 0;
1241 : : break;
1242 : : }
1243 : : }
1244 : :
1245 : : #if LIBSPDM_ENABLE_CAPABILITY_ENDPOINT_INFO_CAP
1246 : 9 : bool libspdm_generate_endpoint_info_signature(libspdm_context_t *spdm_context,
1247 : : libspdm_session_info_t *session_info,
1248 : : bool is_requester,
1249 : : uint8_t slot_id,
1250 : : uint8_t *signature)
1251 : : {
1252 : : bool result;
1253 : : size_t signature_size;
1254 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1255 : : libspdm_il1il2_managed_buffer_t il1il2;
1256 : : uint8_t *il1il2_buffer;
1257 : : size_t il1il2_buffer_size;
1258 : : #else
1259 : : uint8_t il1il2_hash[LIBSPDM_MAX_HASH_SIZE];
1260 : : size_t il1il2_hash_size;
1261 : : #endif
1262 : :
1263 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1264 : : result = libspdm_calculate_il1il2(spdm_context, session_info, is_requester, &il1il2);
1265 : : il1il2_buffer = libspdm_get_managed_buffer(&il1il2);
1266 : : il1il2_buffer_size = libspdm_get_managed_buffer_size(&il1il2);
1267 : : #else
1268 : 9 : il1il2_hash_size = sizeof(il1il2_hash);
1269 : 9 : result = libspdm_calculate_il1il2_hash(spdm_context, session_info, is_requester,
1270 : : &il1il2_hash_size, &il1il2_hash);
1271 : : #endif
1272 [ + + ]: 9 : if (is_requester) {
1273 : 5 : libspdm_reset_message_encap_e(spdm_context, session_info);
1274 : : } else {
1275 : 4 : libspdm_reset_message_e(spdm_context, session_info);
1276 : : }
1277 [ - + ]: 9 : if (!result) {
1278 : 0 : return false;
1279 : : }
1280 : :
1281 [ + + ]: 9 : if (is_requester) {
1282 [ - + ]: 5 : if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
1283 : 0 : signature_size = libspdm_get_req_pqc_asym_signature_size(
1284 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg);
1285 : : } else {
1286 : 5 : signature_size = libspdm_get_req_asym_signature_size(
1287 : 5 : spdm_context->connection_info.algorithm.req_base_asym_alg);
1288 : : }
1289 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1290 : : result = libspdm_requester_data_sign(
1291 : : spdm_context,
1292 : : spdm_context->connection_info.version,
1293 : : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, true),
1294 : : SPDM_ENDPOINT_INFO,
1295 : : spdm_context->connection_info.algorithm.req_base_asym_alg,
1296 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1297 : : spdm_context->connection_info.algorithm.base_hash_algo,
1298 : : false, il1il2_buffer, il1il2_buffer_size, signature, &signature_size);
1299 : : #else
1300 : 10 : result = libspdm_requester_data_sign(
1301 : : spdm_context,
1302 : 5 : spdm_context->connection_info.version,
1303 : 5 : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, true),
1304 : : SPDM_ENDPOINT_INFO,
1305 : 5 : spdm_context->connection_info.algorithm.req_base_asym_alg,
1306 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1307 : : spdm_context->connection_info.algorithm.base_hash_algo,
1308 : : true, il1il2_hash, il1il2_hash_size, signature, &signature_size);
1309 : : #endif
1310 : : } else {
1311 [ - + ]: 4 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
1312 : 0 : signature_size = libspdm_get_pqc_asym_signature_size(
1313 : : spdm_context->connection_info.algorithm.pqc_asym_algo);
1314 : : } else {
1315 : 4 : signature_size = libspdm_get_asym_signature_size(
1316 : : spdm_context->connection_info.algorithm.base_asym_algo);
1317 : : }
1318 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1319 : : result = libspdm_responder_data_sign(
1320 : : spdm_context,
1321 : : spdm_context->connection_info.version,
1322 : : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
1323 : : SPDM_ENDPOINT_INFO,
1324 : : spdm_context->connection_info.algorithm.base_asym_algo,
1325 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1326 : : spdm_context->connection_info.algorithm.base_hash_algo,
1327 : : false, il1il2_buffer, il1il2_buffer_size, signature,
1328 : : &signature_size);
1329 : : #else
1330 : 8 : result = libspdm_responder_data_sign(
1331 : : spdm_context,
1332 : 4 : spdm_context->connection_info.version,
1333 : 4 : libspdm_slot_id_to_key_pair_id(spdm_context, slot_id, false),
1334 : : SPDM_ENDPOINT_INFO,
1335 : : spdm_context->connection_info.algorithm.base_asym_algo,
1336 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1337 : : spdm_context->connection_info.algorithm.base_hash_algo,
1338 : : true, il1il2_hash, il1il2_hash_size, signature,
1339 : : &signature_size);
1340 : : #endif
1341 : : }
1342 : :
1343 : 9 : return result;
1344 : : }
1345 : : #endif /* LIBSPDM_ENABLE_CAPABILITY_ENDPOINT_INFO_CAP */
1346 : :
1347 : 22 : bool libspdm_verify_endpoint_info_signature(libspdm_context_t *spdm_context,
1348 : : libspdm_session_info_t *session_info,
1349 : : bool is_requester,
1350 : : uint8_t slot_id,
1351 : : const void *sign_data,
1352 : : size_t sign_data_size)
1353 : : {
1354 : : bool result;
1355 : : void *context;
1356 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1357 : : libspdm_il1il2_managed_buffer_t il1il2;
1358 : : uint8_t *il1il2_buffer;
1359 : : size_t il1il2_buffer_size;
1360 : : const uint8_t *cert_chain_data;
1361 : : size_t cert_chain_data_size;
1362 : : const uint8_t *cert_buffer;
1363 : : size_t cert_buffer_size;
1364 : : #else
1365 : : uint8_t il1il2_hash[LIBSPDM_MAX_HASH_SIZE];
1366 : : size_t il1il2_hash_size;
1367 : : #endif
1368 : :
1369 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1370 : : result = libspdm_calculate_il1il2(spdm_context, session_info,!is_requester, &il1il2);
1371 : : il1il2_buffer = libspdm_get_managed_buffer(&il1il2);
1372 : : il1il2_buffer_size = libspdm_get_managed_buffer_size(&il1il2);
1373 : : #else
1374 : 22 : il1il2_hash_size = sizeof(il1il2_hash);
1375 : 22 : result = libspdm_calculate_il1il2_hash(spdm_context, session_info, !is_requester,
1376 : 22 : &il1il2_hash_size, il1il2_hash);
1377 : : #endif
1378 [ + + ]: 22 : if (is_requester) {
1379 : 13 : libspdm_reset_message_e(spdm_context, session_info);
1380 : : } else {
1381 : 9 : libspdm_reset_message_encap_e(spdm_context, session_info);
1382 : : }
1383 [ - + ]: 22 : if (!result) {
1384 : 0 : return false;
1385 : : }
1386 : :
1387 [ + + ]: 22 : if (slot_id == 0xF) {
1388 [ + + ]: 4 : if (is_requester) {
1389 [ + - ]: 2 : if (spdm_context->connection_info.algorithm.base_asym_algo != 0) {
1390 : 2 : result = libspdm_asym_get_public_key_from_der(
1391 : : spdm_context->connection_info.algorithm.base_asym_algo,
1392 : 2 : spdm_context->local_context.peer_public_key_provision,
1393 : : spdm_context->local_context.peer_public_key_provision_size,
1394 : : &context);
1395 : : }
1396 [ - + ]: 2 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
1397 : 0 : result = libspdm_pqc_asym_get_public_key_from_der(
1398 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1399 : 0 : spdm_context->local_context.peer_public_key_provision,
1400 : : spdm_context->local_context.peer_public_key_provision_size,
1401 : : &context);
1402 : : }
1403 : : } else {
1404 [ + - ]: 2 : if (spdm_context->connection_info.algorithm.req_base_asym_alg != 0) {
1405 : 2 : result = libspdm_req_asym_get_public_key_from_der(
1406 : 2 : spdm_context->connection_info.algorithm.req_base_asym_alg,
1407 : 2 : spdm_context->local_context.peer_public_key_provision,
1408 : : spdm_context->local_context.peer_public_key_provision_size,
1409 : : &context);
1410 : : }
1411 [ - + ]: 2 : if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
1412 : 0 : result = libspdm_req_pqc_asym_get_public_key_from_der(
1413 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1414 : 0 : spdm_context->local_context.peer_public_key_provision,
1415 : : spdm_context->local_context.peer_public_key_provision_size,
1416 : : &context);
1417 : : }
1418 : : }
1419 [ - + ]: 4 : if (!result) {
1420 : 0 : return false;
1421 : : }
1422 : : } else {
1423 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1424 : : libspdm_get_peer_cert_chain_data(
1425 : : spdm_context, slot_id, (const void **)&cert_chain_data, &cert_chain_data_size);
1426 : :
1427 : : /* Get leaf cert from cert chain*/
1428 : : result = libspdm_x509_get_cert_from_cert_chain(cert_chain_data,
1429 : : cert_chain_data_size, -1,
1430 : : &cert_buffer, &cert_buffer_size);
1431 : : if (!result) {
1432 : : return false;
1433 : : }
1434 : :
1435 : : if (is_requester) {
1436 : : result = libspdm_asym_get_public_key_from_x509(
1437 : : spdm_context->connection_info.algorithm.base_asym_algo,
1438 : : cert_buffer, cert_buffer_size, &context);
1439 : : } else {
1440 : : result = libspdm_req_asym_get_public_key_from_x509(
1441 : : spdm_context->connection_info.algorithm.req_base_asym_alg,
1442 : : cert_buffer, cert_buffer_size, &context);
1443 : : }
1444 : : if (!result) {
1445 : : return false;
1446 : : }
1447 : : #else
1448 : 18 : context = spdm_context->connection_info.peer_used_cert_chain[slot_id].leaf_cert_public_key;
1449 [ - + ]: 18 : LIBSPDM_ASSERT(context != NULL);
1450 : : #endif
1451 : : }
1452 : :
1453 [ + + ]: 22 : if (is_requester) {
1454 [ + - ]: 13 : if (spdm_context->connection_info.algorithm.base_asym_algo != 0) {
1455 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1456 : : result = libspdm_asym_verify_ex(
1457 : : spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
1458 : : spdm_context->connection_info.algorithm.base_asym_algo,
1459 : : spdm_context->connection_info.algorithm.base_hash_algo,
1460 : : context, il1il2_buffer, il1il2_buffer_size, sign_data, sign_data_size,
1461 : : &spdm_context->spdm_10_11_verify_signature_endian);
1462 : : libspdm_asym_free(
1463 : : spdm_context->connection_info.algorithm.base_asym_algo, context);
1464 : : #else
1465 : 13 : result = libspdm_asym_verify_hash_ex(
1466 : 13 : spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
1467 : : spdm_context->connection_info.algorithm.base_asym_algo,
1468 : : spdm_context->connection_info.algorithm.base_hash_algo,
1469 : : context, il1il2_hash, il1il2_hash_size, sign_data, sign_data_size,
1470 : : &spdm_context->spdm_10_11_verify_signature_endian);
1471 [ + + ]: 13 : if (slot_id == 0xF) {
1472 : 2 : libspdm_asym_free(
1473 : : spdm_context->connection_info.algorithm.base_asym_algo, context);
1474 : : }
1475 : : #endif
1476 : : }
1477 [ - + ]: 13 : if (spdm_context->connection_info.algorithm.pqc_asym_algo != 0) {
1478 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1479 : : result = libspdm_pqc_asym_verify(
1480 : : spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
1481 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1482 : : spdm_context->connection_info.algorithm.base_hash_algo,
1483 : : context, il1il2_buffer, il1il2_buffer_size, sign_data, sign_data_size);
1484 : : libspdm_pqc_asym_free(
1485 : : spdm_context->connection_info.algorithm.pqc_asym_algo, context);
1486 : : #else
1487 : 0 : result = libspdm_pqc_asym_verify_hash(
1488 : 0 : spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
1489 : : spdm_context->connection_info.algorithm.pqc_asym_algo,
1490 : : spdm_context->connection_info.algorithm.base_hash_algo,
1491 : : context, il1il2_hash, il1il2_hash_size, sign_data, sign_data_size);
1492 [ # # ]: 0 : if (slot_id == 0xF) {
1493 : 0 : libspdm_pqc_asym_free(
1494 : : spdm_context->connection_info.algorithm.pqc_asym_algo, context);
1495 : : }
1496 : : #endif
1497 : : }
1498 : : } else {
1499 [ + - ]: 9 : if (spdm_context->connection_info.algorithm.req_base_asym_alg != 0) {
1500 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1501 : : result = libspdm_req_asym_verify_ex(
1502 : : spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
1503 : : spdm_context->connection_info.algorithm.req_base_asym_alg,
1504 : : spdm_context->connection_info.algorithm.base_hash_algo,
1505 : : context, il1il2_buffer, il1il2_buffer_size, sign_data, sign_data_size,
1506 : : &spdm_context->spdm_10_11_verify_signature_endian);
1507 : : libspdm_req_asym_free(
1508 : : spdm_context->connection_info.algorithm.req_base_asym_alg, context);
1509 : : #else
1510 : 9 : result = libspdm_req_asym_verify_hash_ex(
1511 : 9 : spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
1512 : 9 : spdm_context->connection_info.algorithm.req_base_asym_alg,
1513 : : spdm_context->connection_info.algorithm.base_hash_algo,
1514 : : context, il1il2_hash, il1il2_hash_size, sign_data, sign_data_size,
1515 : : &spdm_context->spdm_10_11_verify_signature_endian);
1516 [ + + ]: 9 : if (slot_id == 0xF) {
1517 : 2 : libspdm_req_asym_free(
1518 : 2 : spdm_context->connection_info.algorithm.req_base_asym_alg, context);
1519 : : }
1520 : : #endif
1521 : : }
1522 [ - + ]: 9 : if (spdm_context->connection_info.algorithm.req_pqc_asym_alg != 0) {
1523 : : #if LIBSPDM_RECORD_TRANSCRIPT_DATA_SUPPORT
1524 : : result = libspdm_req_pqc_asym_verify(
1525 : : spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
1526 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1527 : : spdm_context->connection_info.algorithm.base_hash_algo,
1528 : : context, il1il2_buffer, il1il2_buffer_size, sign_data, sign_data_size);
1529 : : libspdm_req_pqc_asym_free(
1530 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg, context);
1531 : : #else
1532 : 0 : result = libspdm_req_pqc_asym_verify_hash(
1533 : 0 : spdm_context->connection_info.version, SPDM_ENDPOINT_INFO,
1534 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg,
1535 : : spdm_context->connection_info.algorithm.base_hash_algo,
1536 : : context, il1il2_hash, il1il2_hash_size, sign_data, sign_data_size);
1537 [ # # ]: 0 : if (slot_id == 0xF) {
1538 : 0 : libspdm_req_pqc_asym_free(
1539 : : spdm_context->connection_info.algorithm.req_pqc_asym_alg, context);
1540 : : }
1541 : : #endif
1542 : : }
1543 : : }
1544 [ + + ]: 22 : if (!result) {
1545 : 3 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_ERROR, "!!! verify_endpoint_info_signature - FAIL !!!\n"));
1546 : 3 : return false;
1547 : : }
1548 : :
1549 : 19 : LIBSPDM_DEBUG((LIBSPDM_DEBUG_INFO, "!!! verify_endpoint_info_signature - PASS !!!\n"));
1550 : 19 : return true;
1551 : : }
|