Closed
Bug 1965331
Opened 1 year ago
Closed 1 year ago
Implement PKCS #11 v3.2 FIPS indicator and validation objects.
Categories
(NSS :: Libraries, enhancement, P3)
NSS
Libraries
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: rrelyea, Assigned: rrelyea)
References
(Blocks 1 open bug)
Details
Attachments
(1 file)
PKCS #11 v3.2 defines new Validation objects and FIPS indicators. These replace the prototype versions that we are currently using.
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
cmd/validation/validation.c
- add support for reading the new validation object. automatically select the new objects for reading if the token is PKCS #11v3.2 or greater.
- supply options to override that selection.
lib/freebl/stubs.c
lib/freebl/stubs.h
- fix mispelling in stubs (causes the FIPS-140-3 build option to fail)
lib/nss/nssd.def
lib/pk11wrap/pk11cxt.c
lib/pk11wrap/pk11pub.h
- Add a general function to help select the PKCS #11 version for a token.
- There are 2 places in a PKCS #11 module where there is a version number:
- as the result of C_GetInfo - this states the general version of the module and the appropriate for checking general functionality.
- the version field that the start of the function list. This tells us the version of the function list. It's possible (though unlikely) to have an older function list while still having an up-to-date PKCS #11 module. Use this to determine if it's safe to call a particular function.
- There are 2 places in a PKCS #11 module where there is a version number:
lib/pk11wrap/pk11slot.c
- implement PK11CheckPKCS11Version described above.
- use the Validation objects to FIPS flags for this slot (pk11_GetValidationFlags and PK11_InitToken0
- Map the new PKCS #11 calls to the exported NSS interface if the token is PKCS #11 v3.2 or new.
- The PKCS #11 interface uses an attribute to show the indicators (called validation flags) on an object.
- It used the new C_GetSessionValidationFlags to get the indicator from the session.
- In practice there will likely be only once FIPS validation object and one FIPS validation flag, but if there are more than one we return true if any of the flags are on.
lib/pk11wrap/secmodi.h
- update the returned function pointer so we can call the new C_GetSessionValidationFlags
lib/pk11wrap/secmodti.h
- place to store the slot's FIPS validation flags.
lib/softoken/pkcs11.c
- implement the indicators as an attribute.
- We create a pseudo attribute so that it doesn't get stored on the database.
- The attribute is stored in the object structure, replacing the isFIPS flag.
- Special functions sftk_setFIPS and sftk_hasFIPS access the flag as if it were a bool. (This would allow a future we we make it a full attribute that is stored in the DB.
- The sftk_template_hasAttribute allows us to handle the case where we are checking the token by skipping the bypass so we don't need to give sftkdb_ layer calls the knowledge of the attribute.
- fix bug where the PKCS #11 Validation objects were being added to the slot.
| Assignee | ||
Updated•1 year ago
|
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
You need to log in
before you can comment on or make changes to this bug.
Description
•