integrity: Asymmetric digsig supports SM2-with-SM3 algorithm
Asymmetric digsig supports SM2-with-SM3 algorithm combination, so that IMA can also verify SM2's signature data. Signed-off-by: Tianjia Zhang <tianjia.zhang@linux.alibaba.com> Tested-by: Xufeng Zhang <yunbo.xufeng@linux.alibaba.com> Reviewed-by: Mimi Zohar <zohar@linux.ibm.com> Reviewed-by: Vitaly Chikunov <vt@altlinux.org> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
This commit is contained in:
parent
2155256396
commit
0b7e44d39c
|
@ -99,14 +99,22 @@ int asymmetric_verify(struct key *keyring, const char *sig,
|
|||
memset(&pks, 0, sizeof(pks));
|
||||
|
||||
pks.hash_algo = hash_algo_name[hdr->hash_algo];
|
||||
if (hdr->hash_algo == HASH_ALGO_STREEBOG_256 ||
|
||||
hdr->hash_algo == HASH_ALGO_STREEBOG_512) {
|
||||
switch (hdr->hash_algo) {
|
||||
case HASH_ALGO_STREEBOG_256:
|
||||
case HASH_ALGO_STREEBOG_512:
|
||||
/* EC-RDSA and Streebog should go together. */
|
||||
pks.pkey_algo = "ecrdsa";
|
||||
pks.encoding = "raw";
|
||||
} else {
|
||||
break;
|
||||
case HASH_ALGO_SM3_256:
|
||||
/* SM2 and SM3 should go together. */
|
||||
pks.pkey_algo = "sm2";
|
||||
pks.encoding = "raw";
|
||||
break;
|
||||
default:
|
||||
pks.pkey_algo = "rsa";
|
||||
pks.encoding = "pkcs1";
|
||||
break;
|
||||
}
|
||||
pks.digest = (u8 *)data;
|
||||
pks.digest_size = datalen;
|
||||
|
|
Loading…
Reference in New Issue