b85bfec
From 9134fadd6544be82f96e3d5ce9c1f489de6a1745 Mon Sep 17 00:00:00 2001
b85bfec
From: rpm-build <rpm-build>
b85bfec
Date: Wed, 6 Mar 2024 19:17:17 +0100
b85bfec
Subject: [PATCH 38/49] 0088-signature-Add-indicator-for-PSS-salt-length.patch
e52367a
e52367a
Patch-name: 0088-signature-Add-indicator-for-PSS-salt-length.patch
e52367a
Patch-id: 88
b85bfec
Patch-status: |
b85bfec
    # 0088-signature-Add-indicator-for-PSS-salt-length.patch
b85bfec
From-dist-git-commit: 4334bc837fbc64d14890fdc51679a80770d498ce
e52367a
---
e52367a
 include/openssl/evp.h                         |  4 ++++
b85bfec
 providers/implementations/signature/rsa_sig.c | 21 +++++++++++++++++
b85bfec
 util/perl/OpenSSL/paramnames.pm               | 23 ++++++++++---------
b85bfec
 3 files changed, 37 insertions(+), 11 deletions(-)
e52367a
e52367a
diff --git a/include/openssl/evp.h b/include/openssl/evp.h
b85bfec
index 48d5886d1e..e3fa4a8043 100644
e52367a
--- a/include/openssl/evp.h
e52367a
+++ b/include/openssl/evp.h
b85bfec
@@ -804,6 +804,10 @@ __owur int EVP_CipherFinal(EVP_CIPHER_CTX *ctx, unsigned char *outm,
e52367a
 __owur int EVP_CipherFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *outm,
e52367a
                               int *outl);
e52367a
 
e52367a
+# define EVP_SIGNATURE_REDHAT_FIPS_INDICATOR_UNDETERMINED 0
e52367a
+# define EVP_SIGNATURE_REDHAT_FIPS_INDICATOR_APPROVED     1
e52367a
+# define EVP_SIGNATURE_REDHAT_FIPS_INDICATOR_NOT_APPROVED 2
e52367a
+
e52367a
 __owur int EVP_SignFinal(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s,
e52367a
                          EVP_PKEY *pkey);
e52367a
 __owur int EVP_SignFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s,
e52367a
diff --git a/providers/implementations/signature/rsa_sig.c b/providers/implementations/signature/rsa_sig.c
b85bfec
index b0f32f0b57..1e56d673ee 100644
e52367a
--- a/providers/implementations/signature/rsa_sig.c
e52367a
+++ b/providers/implementations/signature/rsa_sig.c
b85bfec
@@ -1169,6 +1169,24 @@ static int rsa_get_ctx_params(void *vprsactx, OSSL_PARAM *params)
e52367a
         }
e52367a
     }
e52367a
 
e52367a
+#ifdef FIPS_MODULE
e52367a
+    p = OSSL_PARAM_locate(params, OSSL_SIGNATURE_PARAM_REDHAT_FIPS_INDICATOR);
e52367a
+    if (p != NULL) {
e52367a
+        int fips_indicator = EVP_SIGNATURE_REDHAT_FIPS_INDICATOR_APPROVED;
e52367a
+        if (prsactx->pad_mode == RSA_PKCS1_PSS_PADDING) {
e52367a
+            if (prsactx->md == NULL) {
e52367a
+                fips_indicator = EVP_SIGNATURE_REDHAT_FIPS_INDICATOR_UNDETERMINED;
e52367a
+            } else if (rsa_pss_compute_saltlen(prsactx) > EVP_MD_get_size(prsactx->md)) {
e52367a
+                fips_indicator = EVP_SIGNATURE_REDHAT_FIPS_INDICATOR_NOT_APPROVED;
e52367a
+            }
e52367a
+        } else if (prsactx->pad_mode == RSA_NO_PADDING) {
e52367a
+            if (prsactx->md == NULL) /* Should always be the case */
e52367a
+                fips_indicator = EVP_SIGNATURE_REDHAT_FIPS_INDICATOR_NOT_APPROVED;
e52367a
+        }
e52367a
+        return OSSL_PARAM_set_int(p, fips_indicator);
e52367a
+    }
e52367a
+#endif
e52367a
+
e52367a
     return 1;
e52367a
 }
e52367a
 
b85bfec
@@ -1178,6 +1196,9 @@ static const OSSL_PARAM known_gettable_ctx_params[] = {
e52367a
     OSSL_PARAM_utf8_string(OSSL_SIGNATURE_PARAM_DIGEST, NULL, 0),
e52367a
     OSSL_PARAM_utf8_string(OSSL_SIGNATURE_PARAM_MGF1_DIGEST, NULL, 0),
e52367a
     OSSL_PARAM_utf8_string(OSSL_SIGNATURE_PARAM_PSS_SALTLEN, NULL, 0),
e52367a
+#ifdef FIPS_MODULE
e52367a
+    OSSL_PARAM_int(OSSL_SIGNATURE_PARAM_REDHAT_FIPS_INDICATOR, NULL),
e52367a
+#endif
e52367a
     OSSL_PARAM_END
e52367a
 };
e52367a
 
b85bfec
diff --git a/util/perl/OpenSSL/paramnames.pm b/util/perl/OpenSSL/paramnames.pm
b85bfec
index 8b2d430f17..a109e44521 100644
b85bfec
--- a/util/perl/OpenSSL/paramnames.pm
b85bfec
+++ b/util/perl/OpenSSL/paramnames.pm
f4c397c
@@ -377,17 +377,18 @@ my %params = (
f4c397c
     'EXCHANGE_PARAM_KDF_UKM' =>               "kdf-ukm",
f4c397c
 
f4c397c
 # Signature parameters
f4c397c
-    'SIGNATURE_PARAM_ALGORITHM_ID' =>       "algorithm-id",
f4c397c
-    'SIGNATURE_PARAM_PAD_MODE' =>           '*PKEY_PARAM_PAD_MODE',
f4c397c
-    'SIGNATURE_PARAM_DIGEST' =>             '*PKEY_PARAM_DIGEST',
f4c397c
-    'SIGNATURE_PARAM_PROPERTIES' =>         '*PKEY_PARAM_PROPERTIES',
f4c397c
-    'SIGNATURE_PARAM_PSS_SALTLEN' =>        "saltlen",
f4c397c
-    'SIGNATURE_PARAM_MGF1_DIGEST' =>        '*PKEY_PARAM_MGF1_DIGEST',
f4c397c
-    'SIGNATURE_PARAM_MGF1_PROPERTIES' =>    '*PKEY_PARAM_MGF1_PROPERTIES',
f4c397c
-    'SIGNATURE_PARAM_DIGEST_SIZE' =>        '*PKEY_PARAM_DIGEST_SIZE',
f4c397c
-    'SIGNATURE_PARAM_NONCE_TYPE' =>         "nonce-type",
f4c397c
-    'SIGNATURE_PARAM_INSTANCE' =>           "instance",
f4c397c
-    'SIGNATURE_PARAM_CONTEXT_STRING' =>     "context-string",
f4c397c
+    'SIGNATURE_PARAM_ALGORITHM_ID' =>          "algorithm-id",
f4c397c
+    'SIGNATURE_PARAM_PAD_MODE' =>              '*PKEY_PARAM_PAD_MODE',
f4c397c
+    'SIGNATURE_PARAM_DIGEST' =>                '*PKEY_PARAM_DIGEST',
f4c397c
+    'SIGNATURE_PARAM_PROPERTIES' =>            '*PKEY_PARAM_PROPERTIES',
f4c397c
+    'SIGNATURE_PARAM_PSS_SALTLEN' =>           "saltlen",
f4c397c
+    'SIGNATURE_PARAM_MGF1_DIGEST' =>           '*PKEY_PARAM_MGF1_DIGEST',
f4c397c
+    'SIGNATURE_PARAM_MGF1_PROPERTIES' =>       '*PKEY_PARAM_MGF1_PROPERTIES',
f4c397c
+    'SIGNATURE_PARAM_DIGEST_SIZE' =>           '*PKEY_PARAM_DIGEST_SIZE',
f4c397c
+    'SIGNATURE_PARAM_REDHAT_FIPS_INDICATOR' => "redhat-fips-indicator",
f4c397c
+    'SIGNATURE_PARAM_NONCE_TYPE' =>            "nonce-type",
f4c397c
+    'SIGNATURE_PARAM_INSTANCE' =>              "instance",
f4c397c
+    'SIGNATURE_PARAM_CONTEXT_STRING' =>        "context-string",
f4c397c
 
f4c397c
 # Asym cipher parameters
f4c397c
     'ASYM_CIPHER_PARAM_DIGEST' =>                   '*PKEY_PARAM_DIGEST',
b85bfec
-- 
b85bfec
2.44.0
b85bfec