[edk2-devel] [Patch 0/2] Extending the signing algorithms for Authenticated Variables

Wadhawan, Divneil R posted 2 patches 3 years, 4 months ago
Failed in applying to current master (apply log)
.../Variable/RuntimeDxe/UnitTest/AuthVarUnitTest.c | 494 +++++++++++++++++++++
.../RuntimeDxe/UnitTest/PkNewRsa2048Sha256.c       | 139 ++++++
.../RuntimeDxe/UnitTest/PkNewRsa3072Sha256.c       | 179 ++++++++
.../RuntimeDxe/UnitTest/PkNewRsa3072Sha384.c       | 179 ++++++++
.../RuntimeDxe/UnitTest/PkNewRsa4096Sha256.c       | 219 +++++++++
.../RuntimeDxe/UnitTest/PkNewRsa4096Sha512.c       | 219 +++++++++
.../Variable/RuntimeDxe/UnitTest/PkRsa2048Sha256.c | 139 ++++++
.../Variable/RuntimeDxe/UnitTest/PkRsa3072Sha256.c | 179 ++++++++
.../Variable/RuntimeDxe/UnitTest/PkRsa3072Sha384.c | 179 ++++++++
.../Variable/RuntimeDxe/UnitTest/PkRsa4096Sha256.c | 219 +++++++++
.../Variable/RuntimeDxe/UnitTest/PkRsa4096Sha512.c | 219 +++++++++
SecurityPkg/Library/AuthVariableLib/AuthService.c  |   8 +-
AuthVariableDigestUpdate.md                        |  41 ++
MdeModulePkg/MdeModulePkg.dsc                      |   4 +
.../UnitTest/AuthVarUnitTestUefiShell.inf          |  42 ++
15 files changed, 2457 insertions(+), 2 deletions(-)
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/AuthVarUnitTest.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa2048Sha256.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa3072Sha256.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa3072Sha384.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa4096Sha256.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa4096Sha512.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa2048Sha256.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa3072Sha256.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa3072Sha384.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa4096Sha256.c
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa4096Sha512.c
create mode 100644 AuthVariableDigestUpdate.md
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/AuthVarUnitTestUefiShell.inf
[edk2-devel] [Patch 0/2] Extending the signing algorithms for Authenticated Variables
Posted by Wadhawan, Divneil R 3 years, 4 months ago
Authenticated Variables currently only supports SHA256 as the digest algorithm.
This patch series extends it to include SHA384 and SHA512. The series is composed
of 2 patches.
a. Unit Test for Authenticated Variables
b. AuthService change to allow SHA384/SHA512 as digest algorithms.

Divneil Rai Wadhawan (2):
  MdeModulePkg: Add unit test for Authenticated Variables
  SecurityPkg: Add support for SHA-384/SHA-512 digest algos

 .../Variable/RuntimeDxe/UnitTest/AuthVarUnitTest.c | 494 +++++++++++++++++++++
 .../RuntimeDxe/UnitTest/PkNewRsa2048Sha256.c       | 139 ++++++
 .../RuntimeDxe/UnitTest/PkNewRsa3072Sha256.c       | 179 ++++++++
 .../RuntimeDxe/UnitTest/PkNewRsa3072Sha384.c       | 179 ++++++++
 .../RuntimeDxe/UnitTest/PkNewRsa4096Sha256.c       | 219 +++++++++
 .../RuntimeDxe/UnitTest/PkNewRsa4096Sha512.c       | 219 +++++++++
 .../Variable/RuntimeDxe/UnitTest/PkRsa2048Sha256.c | 139 ++++++
 .../Variable/RuntimeDxe/UnitTest/PkRsa3072Sha256.c | 179 ++++++++
 .../Variable/RuntimeDxe/UnitTest/PkRsa3072Sha384.c | 179 ++++++++
 .../Variable/RuntimeDxe/UnitTest/PkRsa4096Sha256.c | 219 +++++++++
 .../Variable/RuntimeDxe/UnitTest/PkRsa4096Sha512.c | 219 +++++++++
 SecurityPkg/Library/AuthVariableLib/AuthService.c  |   8 +-
 AuthVariableDigestUpdate.md                        |  41 ++
 MdeModulePkg/MdeModulePkg.dsc                      |   4 +
 .../UnitTest/AuthVarUnitTestUefiShell.inf          |  42 ++
 15 files changed, 2457 insertions(+), 2 deletions(-)
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/AuthVarUnitTest.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa2048Sha256.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa3072Sha256.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa3072Sha384.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa4096Sha256.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa4096Sha512.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa2048Sha256.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa3072Sha256.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa3072Sha384.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa4096Sha256.c
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa4096Sha512.c
 create mode 100644 AuthVariableDigestUpdate.md
 create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/AuthVarUnitTestUefiShell.inf

-- 
2.16.2.windows.1



-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#68567): https://edk2.groups.io/g/devel/message/68567
Mute This Topic: https://groups.io/mt/78836212/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-


Re: [edk2-devel] [Patch 0/2] Extending the signing algorithms for Authenticated Variables
Posted by Michael D Kinney 3 years, 4 months ago
Divneil,

Is this intended for a branch in edk2-staging repo using EDK II Code First Process?

I see the following BZ that seems to match:

    https://bugzilla.tianocore.org/show_bug.cgi?id=2875

Please update Subject line to include [edk2-staging/<BranchName>] following EDK II Code First
branch naming conventions.

    https://github.com/tianocore/tianocore.github.io/wiki/EDK-II-Code-First-Process

Also add the link to the BZ in all commit messages including Patch #0.  Patch #0 should also
include a Signed-off-by tag and the merged set of Cc tags from all the individual patches.

For this proposed change, how does a caller of the UEFI Variable services know if
SHA384 or SHA512 is supported.  I see the code change updates the variable services 
to support this, but I do not see a detection method for platform FW capabilities.

The proposed spec change changes from *only* SHA256 to SHA256 or larger.  But the code
change only adds SHA384 and SHA512.  Do we want to make the spec change define the 
specific SHA sizes required?
	
Thanks,

Mike


> -----Original Message-----
> From: devel@edk2.groups.io <devel@edk2.groups.io> On Behalf Of Wadhawan, Divneil R
> Sent: Wednesday, December 9, 2020 10:33 AM
> To: devel@edk2.groups.io
> Subject: [edk2-devel] [Patch 0/2] Extending the signing algorithms for Authenticated Variables
> 
> Authenticated Variables currently only supports SHA256 as the digest algorithm.
> This patch series extends it to include SHA384 and SHA512. The series is composed
> of 2 patches.
> a. Unit Test for Authenticated Variables
> b. AuthService change to allow SHA384/SHA512 as digest algorithms.
> 
> Divneil Rai Wadhawan (2):
>   MdeModulePkg: Add unit test for Authenticated Variables
>   SecurityPkg: Add support for SHA-384/SHA-512 digest algos
> 
>  .../Variable/RuntimeDxe/UnitTest/AuthVarUnitTest.c | 494 +++++++++++++++++++++
>  .../RuntimeDxe/UnitTest/PkNewRsa2048Sha256.c       | 139 ++++++
>  .../RuntimeDxe/UnitTest/PkNewRsa3072Sha256.c       | 179 ++++++++
>  .../RuntimeDxe/UnitTest/PkNewRsa3072Sha384.c       | 179 ++++++++
>  .../RuntimeDxe/UnitTest/PkNewRsa4096Sha256.c       | 219 +++++++++
>  .../RuntimeDxe/UnitTest/PkNewRsa4096Sha512.c       | 219 +++++++++
>  .../Variable/RuntimeDxe/UnitTest/PkRsa2048Sha256.c | 139 ++++++
>  .../Variable/RuntimeDxe/UnitTest/PkRsa3072Sha256.c | 179 ++++++++
>  .../Variable/RuntimeDxe/UnitTest/PkRsa3072Sha384.c | 179 ++++++++
>  .../Variable/RuntimeDxe/UnitTest/PkRsa4096Sha256.c | 219 +++++++++
>  .../Variable/RuntimeDxe/UnitTest/PkRsa4096Sha512.c | 219 +++++++++
>  SecurityPkg/Library/AuthVariableLib/AuthService.c  |   8 +-
>  AuthVariableDigestUpdate.md                        |  41 ++
>  MdeModulePkg/MdeModulePkg.dsc                      |   4 +
>  .../UnitTest/AuthVarUnitTestUefiShell.inf          |  42 ++
>  15 files changed, 2457 insertions(+), 2 deletions(-)
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/AuthVarUnitTest.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa2048Sha256.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa3072Sha256.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa3072Sha384.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa4096Sha256.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkNewRsa4096Sha512.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa2048Sha256.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa3072Sha256.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa3072Sha384.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa4096Sha256.c
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/PkRsa4096Sha512.c
>  create mode 100644 AuthVariableDigestUpdate.md
>  create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/UnitTest/AuthVarUnitTestUefiShell.inf
> 
> --
> 2.16.2.windows.1
> 
> 
> 
> 
> 



-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#68596): https://edk2.groups.io/g/devel/message/68596
Mute This Topic: https://groups.io/mt/78836212/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-