2019-06-01 11:08:55 +03:00
|
|
|
// SPDX-License-Identifier: GPL-2.0-only
|
2011-08-28 06:21:26 +04:00
|
|
|
/*
|
|
|
|
* Copyright (C) 2010 IBM Corporation
|
|
|
|
* Copyright (C) 2010 Politecnico di Torino, Italy
|
|
|
|
* TORSEC group -- http://security.polito.it
|
|
|
|
*
|
|
|
|
* Authors:
|
|
|
|
* Mimi Zohar <zohar@us.ibm.com>
|
|
|
|
* Roberto Sassu <roberto.sassu@polito.it>
|
|
|
|
*
|
2017-05-13 14:51:53 +03:00
|
|
|
* See Documentation/security/keys/trusted-encrypted.rst
|
2011-08-28 06:21:26 +04:00
|
|
|
*/
|
|
|
|
|
|
|
|
#include <linux/uaccess.h>
|
2011-09-15 11:07:15 +04:00
|
|
|
#include <linux/err.h>
|
2011-08-28 06:21:26 +04:00
|
|
|
#include <keys/trusted-type.h>
|
2012-01-18 00:39:51 +04:00
|
|
|
#include <keys/encrypted-type.h>
|
|
|
|
#include "encrypted.h"
|
2011-08-28 06:21:26 +04:00
|
|
|
|
|
|
|
/*
|
|
|
|
* request_trusted_key - request the trusted key
|
|
|
|
*
|
|
|
|
* Trusted keys are sealed to PCRs and other metadata. Although userspace
|
|
|
|
* manages both trusted/encrypted key-types, like the encrypted key type
|
|
|
|
* data, trusted key type data is not visible decrypted from userspace.
|
|
|
|
*/
|
|
|
|
struct key *request_trusted_key(const char *trusted_desc,
|
2015-10-21 16:04:48 +03:00
|
|
|
const u8 **master_key, size_t *master_keylen)
|
2011-08-28 06:21:26 +04:00
|
|
|
{
|
|
|
|
struct trusted_key_payload *tpayload;
|
|
|
|
struct key *tkey;
|
|
|
|
|
2019-07-11 04:43:43 +03:00
|
|
|
tkey = request_key(&key_type_trusted, trusted_desc, NULL);
|
2011-08-28 06:21:26 +04:00
|
|
|
if (IS_ERR(tkey))
|
|
|
|
goto error;
|
|
|
|
|
|
|
|
down_read(&tkey->sem);
|
2015-10-21 16:04:48 +03:00
|
|
|
tpayload = tkey->payload.data[0];
|
2011-08-28 06:21:26 +04:00
|
|
|
*master_key = tpayload->key;
|
|
|
|
*master_keylen = tpayload->key_len;
|
|
|
|
error:
|
|
|
|
return tkey;
|
|
|
|
}
|