Pedro Monreal Gonzalez
6bc57d937f
* SHA-1 is not allowed anymore in FIPS 186-5 for signature verification operations. After 12/31/2030, NIST will disallow SHA-1 for all of its usages. * Add openssl-3-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch - FIPS: RSA keygen PCT requirements. * Skip the rsa_keygen_pairwise_test() PCT in rsa_keygen() as the self-test requirements are covered by do_rsa_pct() for both RSA-OAEP and RSA signatures [bsc#1221760] * Enforce error state if rsa_keygen PCT is run and fails [bsc#1221753] * Add openssl-3-FIPS-PCT_rsa_keygen.patch - FIPS: Check that the fips provider is available before setting it as the default provider in FIPS mode. [bsc#1220523] * Rebase openssl-Force-FIPS.patch - FIPS: Port openssl to use jitterentropy [bsc#1220523] * Set the module in error state if the jitter RNG fails either on initialization or entropy gathering because health tests failed. * Add jitterentropy as a seeding source output also in crypto/info.c * Move the jitter entropy collector and the associated lock out of the header file to avoid redefinitions. * Add the fips_local.cnf symlink to the spec file. This simlink points to the openssl_fips.config file that is provided by the crypto-policies package. * Rebase openssl-3-jitterentropy-3.4.0.patch * Rebase openssl-FIPS-enforce-EMS-support.patch - FIPS: Block non-Approved Elliptic Curves [bsc#1221786] OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=110
109 lines
4.4 KiB
Diff
109 lines
4.4 KiB
Diff
From e1eba21921ceeffa45ffd2115868c14e4c7fb8d9 Mon Sep 17 00:00:00 2001
|
|
From: Clemens Lang <cllang@redhat.com>
|
|
Date: Thu, 17 Nov 2022 18:08:24 +0100
|
|
Subject: [PATCH] hmac: Add explicit FIPS indicator for key length
|
|
|
|
NIST SP 800-131Ar2, table 9 "Approval Status of MAC Algorithms"
|
|
specifies key lengths < 112 bytes are disallowed for HMAC generation and
|
|
are legacy use for HMAC verification.
|
|
|
|
Add an explicit indicator that will mark shorter key lengths as
|
|
unsupported. The indicator can be queries from the EVP_MAC_CTX object
|
|
using EVP_MAC_CTX_get_params() with the
|
|
OSSL_MAC_PARAM_SUSE_FIPS_INDICATOR
|
|
parameter.
|
|
|
|
Signed-off-by: Clemens Lang <cllang@redhat.com>
|
|
---
|
|
include/crypto/evp.h | 7 +++++++
|
|
include/openssl/evp.h | 3 +++
|
|
providers/implementations/macs/hmac_prov.c | 17 +++++++++++++++++
|
|
4 files changed, 28 insertions(+)
|
|
|
|
Index: openssl-3.1.4/include/crypto/evp.h
|
|
===================================================================
|
|
--- openssl-3.1.4.orig/include/crypto/evp.h
|
|
+++ openssl-3.1.4/include/crypto/evp.h
|
|
@@ -196,6 +196,13 @@ const EVP_PKEY_METHOD *ossl_ed448_pkey_m
|
|
const EVP_PKEY_METHOD *ossl_rsa_pkey_method(void);
|
|
const EVP_PKEY_METHOD *ossl_rsa_pss_pkey_method(void);
|
|
|
|
+#ifdef FIPS_MODULE
|
|
+/* NIST SP 800-131Ar2, Table 9: Approval Status of MAC Algorithms specifies key
|
|
+ * lengths < 112 bytes are disallowed for HMAC generation and legacy use for
|
|
+ * HMAC verification. */
|
|
+# define EVP_HMAC_GEN_FIPS_MIN_KEY_LEN (112 / 8)
|
|
+#endif
|
|
+
|
|
struct evp_mac_st {
|
|
OSSL_PROVIDER *prov;
|
|
int name_id;
|
|
Index: openssl-3.1.4/include/openssl/evp.h
|
|
===================================================================
|
|
--- openssl-3.1.4.orig/include/openssl/evp.h
|
|
+++ openssl-3.1.4/include/openssl/evp.h
|
|
@@ -1196,6 +1196,9 @@ void EVP_MD_do_all_provided(OSSL_LIB_CTX
|
|
void *arg);
|
|
|
|
/* MAC stuff */
|
|
+# define EVP_MAC_SUSE_FIPS_INDICATOR_UNDETERMINED 0
|
|
+# define EVP_MAC_SUSE_FIPS_INDICATOR_APPROVED 1
|
|
+# define EVP_MAC_SUSE_FIPS_INDICATOR_NOT_APPROVED 2
|
|
|
|
EVP_MAC *EVP_MAC_fetch(OSSL_LIB_CTX *libctx, const char *algorithm,
|
|
const char *properties);
|
|
Index: openssl-3.1.4/providers/implementations/macs/hmac_prov.c
|
|
===================================================================
|
|
--- openssl-3.1.4.orig/providers/implementations/macs/hmac_prov.c
|
|
+++ openssl-3.1.4/providers/implementations/macs/hmac_prov.c
|
|
@@ -21,6 +21,8 @@
|
|
#include <openssl/evp.h>
|
|
#include <openssl/hmac.h>
|
|
|
|
+#include "crypto/evp.h"
|
|
+
|
|
#include "prov/implementations.h"
|
|
#include "prov/provider_ctx.h"
|
|
#include "prov/provider_util.h"
|
|
@@ -244,6 +246,9 @@ static int hmac_final(void *vmacctx, uns
|
|
static const OSSL_PARAM known_gettable_ctx_params[] = {
|
|
OSSL_PARAM_size_t(OSSL_MAC_PARAM_SIZE, NULL),
|
|
OSSL_PARAM_size_t(OSSL_MAC_PARAM_BLOCK_SIZE, NULL),
|
|
+#ifdef FIPS_MODULE
|
|
+ OSSL_PARAM_int(OSSL_MAC_PARAM_SUSE_FIPS_INDICATOR, NULL),
|
|
+#endif /* defined(FIPS_MODULE) */
|
|
OSSL_PARAM_END
|
|
};
|
|
static const OSSL_PARAM *hmac_gettable_ctx_params(ossl_unused void *ctx,
|
|
@@ -265,6 +270,18 @@ static int hmac_get_ctx_params(void *vma
|
|
&& !OSSL_PARAM_set_int(p, hmac_block_size(macctx)))
|
|
return 0;
|
|
|
|
+#ifdef FIPS_MODULE
|
|
+ if ((p = OSSL_PARAM_locate(params, OSSL_MAC_PARAM_SUSE_FIPS_INDICATOR)) != NULL) {
|
|
+ int fips_indicator = EVP_MAC_SUSE_FIPS_INDICATOR_APPROVED;
|
|
+ /* NIST SP 800-131Ar2, Table 9: Approval Status of MAC Algorithms
|
|
+ * specifies key lengths < 112 bytes are disallowed for HMAC generation
|
|
+ * and legacy use for HMAC verification. */
|
|
+ if (macctx->keylen < EVP_HMAC_GEN_FIPS_MIN_KEY_LEN)
|
|
+ fips_indicator = EVP_MAC_SUSE_FIPS_INDICATOR_NOT_APPROVED;
|
|
+ return OSSL_PARAM_set_int(p, fips_indicator);
|
|
+ }
|
|
+#endif /* defined(FIPS_MODULE) */
|
|
+
|
|
return 1;
|
|
}
|
|
|
|
Index: openssl-3.1.4/include/openssl/core_names.h
|
|
===================================================================
|
|
--- openssl-3.1.4.orig/include/openssl/core_names.h
|
|
+++ openssl-3.1.4/include/openssl/core_names.h
|
|
@@ -175,6 +175,7 @@ extern "C" {
|
|
#define OSSL_MAC_PARAM_SIZE "size" /* size_t */
|
|
#define OSSL_MAC_PARAM_BLOCK_SIZE "block-size" /* size_t */
|
|
#define OSSL_MAC_PARAM_TLS_DATA_SIZE "tls-data-size" /* size_t */
|
|
+#define OSSL_MAC_PARAM_SUSE_FIPS_INDICATOR "suse-fips-indicator" /* size_t */
|
|
|
|
/* Known MAC names */
|
|
#define OSSL_MAC_NAME_BLAKE2BMAC "BLAKE2BMAC"
|