-
Notifications
You must be signed in to change notification settings - Fork 29
Reject templates whose class or key type contradicts the key generation mechanism #216
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
LinuxJedi
merged 4 commits into
wolfSSL:master
from
aidangarske:fenrir-fixes-13254-13255
Oct 2, 2026
Merged
Changes from all commits
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
9c002f3
F-13254 - Reject inconsistent class in C_GenerateKey templates
aidangarske 9b7f65f
F-13255 - Reject inconsistent class in C_GenerateKeyPair templates
aidangarske 81d1668
Merge master into key generation template checks
aidangarske 8df1876
Merge master after PR #217
aidangarske File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,152 @@ | ||
| /* generate_key_class_test.c | ||
| * | ||
| * Copyright (C) 2006-2025 wolfSSL Inc. | ||
| * | ||
| * This file is part of wolfPKCS11. | ||
| * | ||
| * wolfPKCS11 is free software; you can redistribute it and/or modify | ||
| * it under the terms of the GNU General Public License as published by | ||
| * the Free Software Foundation; either version 3 of the License, or | ||
| * (at your option) any later version. | ||
| * | ||
| * wolfPKCS11 is distributed in the hope that it will be useful, | ||
| * but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
| * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
| * GNU General Public License for more details. | ||
| * | ||
| * You should have received a copy of the GNU General Public License | ||
| * along with this program; if not, write to the Free Software | ||
| * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1335, USA | ||
| * | ||
| * C_GenerateKey must reject a template whose CKA_CLASS or CKA_KEY_TYPE is | ||
| * inconsistent with the generation mechanism. | ||
| */ | ||
|
|
||
| #ifdef HAVE_CONFIG_H | ||
| #include <wolfpkcs11/config.h> | ||
| #endif | ||
|
|
||
| #include <stdio.h> | ||
| #include <string.h> | ||
|
|
||
| #ifndef WOLFSSL_USER_SETTINGS | ||
| #include <wolfssl/options.h> | ||
| #endif | ||
| #include <wolfssl/wolfcrypt/settings.h> | ||
| #include <wolfssl/wolfcrypt/misc.h> | ||
|
|
||
| #ifndef WOLFPKCS11_USER_SETTINGS | ||
| #include <wolfpkcs11/options.h> | ||
| #endif | ||
| #include <wolfpkcs11/pkcs11.h> | ||
|
|
||
| #ifndef HAVE_PKCS11_STATIC | ||
| #include <dlfcn.h> | ||
| #endif | ||
|
|
||
| #include "testdata.h" | ||
| #include "pkcs11_test_util.h" | ||
|
|
||
| #define TEST_DIR "./store/generate_key_class_test" | ||
|
|
||
| #ifndef NO_AES | ||
| static int run_test(void) | ||
| { | ||
| CK_RV rv; | ||
| CK_SESSION_HANDLE session = 0; | ||
| CK_OBJECT_HANDLE key = CK_INVALID_HANDLE; | ||
| CK_MECHANISM mech = { CKM_AES_KEY_GEN, NULL, 0 }; | ||
| CK_ULONG valueLen = 16; | ||
| CK_OBJECT_CLASS dataClass = CKO_DATA; | ||
| CK_OBJECT_CLASS secretClass = CKO_SECRET_KEY; | ||
| CK_KEY_TYPE rsaType = CKK_RSA; | ||
| CK_KEY_TYPE aesType = CKK_AES; | ||
| CK_BBOOL ckFalse = CK_FALSE; | ||
| CK_ATTRIBUTE badClass[] = { | ||
| { CKA_VALUE_LEN, &valueLen, sizeof(valueLen) }, | ||
| { CKA_PRIVATE, &ckFalse, sizeof(ckFalse) }, | ||
| { CKA_CLASS, &dataClass, sizeof(dataClass) }, | ||
| }; | ||
| CK_ATTRIBUTE badKeyType[] = { | ||
| { CKA_VALUE_LEN, &valueLen, sizeof(valueLen) }, | ||
| { CKA_PRIVATE, &ckFalse, sizeof(ckFalse) }, | ||
| { CKA_KEY_TYPE, &rsaType, sizeof(rsaType) }, | ||
| }; | ||
| CK_ATTRIBUTE goodTmpl[] = { | ||
| { CKA_VALUE_LEN, &valueLen, sizeof(valueLen) }, | ||
| { CKA_PRIVATE, &ckFalse, sizeof(ckFalse) }, | ||
| { CKA_CLASS, &secretClass, sizeof(secretClass) }, | ||
| { CKA_KEY_TYPE, &aesType, sizeof(aesType) }, | ||
| }; | ||
| CK_ATTRIBUTE minimalTmpl[] = { | ||
| { CKA_VALUE_LEN, &valueLen, sizeof(valueLen) }, | ||
| { CKA_PRIVATE, &ckFalse, sizeof(ckFalse) }, | ||
| }; | ||
| CK_ATTRIBUTE dupClass[] = { | ||
| { CKA_VALUE_LEN, &valueLen, sizeof(valueLen) }, | ||
| { CKA_PRIVATE, &ckFalse, sizeof(ckFalse) }, | ||
| { CKA_CLASS, &secretClass, sizeof(secretClass) }, | ||
| { CKA_CLASS, &dataClass, sizeof(dataClass) }, | ||
| }; | ||
|
|
||
| rv = pkcs11_load(); | ||
| CHECK_RV(rv, "load library", CKR_OK); | ||
| if (rv != CKR_OK) | ||
| return -1; | ||
|
|
||
| rv = pkcs11_open_session(&session); | ||
| CHECK_RV(rv, "open session", CKR_OK); | ||
| if (rv != CKR_OK) | ||
| goto out; | ||
|
|
||
| rv = funcList->C_GenerateKey(session, &mech, badClass, | ||
| sizeof(badClass) / sizeof(*badClass), &key); | ||
| CHECK_RV(rv, "C_GenerateKey(inconsistent CKA_CLASS)", | ||
| CKR_TEMPLATE_INCONSISTENT); | ||
|
|
||
| rv = funcList->C_GenerateKey(session, &mech, badKeyType, | ||
| sizeof(badKeyType) / sizeof(*badKeyType), | ||
| &key); | ||
| CHECK_RV(rv, "C_GenerateKey(inconsistent CKA_KEY_TYPE)", | ||
| CKR_TEMPLATE_INCONSISTENT); | ||
|
|
||
| rv = funcList->C_GenerateKey(session, &mech, goodTmpl, | ||
| sizeof(goodTmpl) / sizeof(*goodTmpl), &key); | ||
| CHECK_RV(rv, "C_GenerateKey(consistent class and type)", CKR_OK); | ||
|
|
||
| rv = funcList->C_GenerateKey(session, &mech, minimalTmpl, | ||
| sizeof(minimalTmpl) / sizeof(*minimalTmpl), | ||
| &key); | ||
| CHECK_RV(rv, "C_GenerateKey(no class in template)", CKR_OK); | ||
|
|
||
| rv = funcList->C_GenerateKey(session, &mech, dupClass, | ||
| sizeof(dupClass) / sizeof(*dupClass), &key); | ||
| CHECK_RV(rv, "C_GenerateKey(duplicate inconsistent CKA_CLASS)", | ||
| CKR_TEMPLATE_INCONSISTENT); | ||
|
|
||
| out: | ||
| if (session != 0) | ||
| funcList->C_CloseSession(session); | ||
| funcList->C_Finalize(NULL); | ||
| pkcs11_unload(); | ||
| return 0; | ||
| } | ||
| #endif /* !NO_AES */ | ||
|
|
||
| int main(int argc, char* argv[]) | ||
| { | ||
| (void)argc; | ||
| (void)argv; | ||
|
|
||
| #ifndef WOLFPKCS11_NO_ENV | ||
| XSETENV("WOLFPKCS11_TOKEN_PATH", TEST_DIR, 1); | ||
| #endif | ||
|
|
||
| printf("=== wolfPKCS11 C_GenerateKey class consistency test ===\n"); | ||
| #ifndef NO_AES | ||
| run_test(); | ||
| #else | ||
| printf("AES not compiled in!\n"); | ||
| #endif | ||
| return pkcs11_test_summary(); | ||
| } |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.