This implements just the small subset of OpenSSL's CMS API to support the Linux kernel's sign-file.c tool. It is nowhere close to a full CMS implementation and is not intended to become one. In particular, it does not implement enough of CMS to support S/MIME. That requires much, much more infrastructure than was implemented here. CMS is, like PKCS#7, an over-engineered and cryptographically unsound set of nestable combinators to support just about any configuration of cryptographic operations. Profiling CMS down to a usable subset is, as a result, more complicated, more risky, and less efficient than just designing a bespoke structure for your use case. It is derived from PKCS#7, and largely overlaps. However, both PKCS#7 and CMS use the v1 version number, but CMS made incompatible changes in some corner cases that, so far, do not matter to us. (It is incompatible if you try to layer SignedData atop another combinator, where the lack of proper domain separation in this badly designed format is of extra risk.) In the case of the kernel, sign-file.c wants an "external signature", which is when the data to be signed lives elsewhere. This is, as a result, a very, very inefficient way to concatenate an enum with a byte string. But this is what the kernel chose, so here we are. Because PKCS#7 and CMS are broadly the same structure, I've generalized the internal PKCS#7 function rather than duplicating all this code. If we ever hit the cases where PKCS#7 and CMS v1 are incompatible, plumbing an extra boolean will be the least of our worries. Test data was generated by compiling the actual sign-file.c against OpenSSL and saving the output. Change-Id: Idb0874d2b5294bfad564f3a00458c3fd044d9da5 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/78452 Auto-Submit: David Benjamin <davidben@google.com> Commit-Queue: David Benjamin <davidben@google.com> Reviewed-by: Adam Langley <agl@google.com>
3 lines
80 B
Plaintext
3 lines
80 B
Plaintext
CMS,100,CERTIFICATE_HAS_NO_KEYID
|
|
CMS,101,PRIVATE_KEY_DOES_NOT_MATCH_CERTIFICATE
|