diff --git a/components/esp-tls/esp_tls_mbedtls.c b/components/esp-tls/esp_tls_mbedtls.c index bcb8e57186e..4e13617ee8a 100644 --- a/components/esp-tls/esp_tls_mbedtls.c +++ b/components/esp-tls/esp_tls_mbedtls.c @@ -1436,7 +1436,7 @@ static esp_err_t esp_mbedtls_init_pk_ctx_for_ds(const void *pki) psa_set_key_bits(&ds_key_attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_usage_flags(&ds_key_attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_algorithm(&ds_key_attributes, alg); - psa_set_key_lifetime(&ds_key_attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); + psa_set_key_lifetime(&ds_key_attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE); status = psa_import_key(&ds_key_attributes, (const uint8_t *)&rsa_ds_opaque_key, sizeof(rsa_ds_opaque_key), diff --git a/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_rsa_ds.h b/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_rsa_ds.h index b237d267c8f..c5a88205b43 100644 --- a/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_rsa_ds.h +++ b/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_rsa_ds.h @@ -22,8 +22,19 @@ extern "C" { #define PSA_KEY_LOCATION_ESP_RSA_DS ((psa_key_location_t) 0x800003) - +/* IDF-15427: ESP-PSA driver does not support persistent RSA DS keys as of now */ +#if 0 +/* @brief Construct a lifetime for ESP RSA DS keys with default persistence */ #define PSA_KEY_LIFETIME_ESP_RSA_DS \ + PSA_KEY_LIFETIME_FROM_PERSISTENCE_AND_LOCATION( \ + PSA_KEY_PERSISTENCE_DEFAULT, \ + PSA_KEY_LOCATION_ESP_RSA_DS) +#endif + +/** + * @brief Construct a volatile lifetime for ESP RSA DS keys + */ +#define PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE \ PSA_KEY_LIFETIME_FROM_PERSISTENCE_AND_LOCATION( \ PSA_KEY_PERSISTENCE_VOLATILE, \ PSA_KEY_LOCATION_ESP_RSA_DS) diff --git a/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_rsa_ds_contexts.h b/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_rsa_ds_contexts.h index 0886f4e1f71..f471f925941 100644 --- a/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_rsa_ds_contexts.h +++ b/components/mbedtls/port/psa_driver/include/psa_crypto_driver_esp_rsa_ds_contexts.h @@ -35,7 +35,7 @@ typedef enum { * @brief ESP DS data context * This context is used to store the ESP DS data. * - * When passed to psa_import_key() for PSA_KEY_LIFETIME_ESP_RSA_DS, the key material + * When passed to psa_import_key() for PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE, the key material * (this struct and the esp_ds_data_t pointed to by esp_ds_data) must remain valid * until psa_destroy_key() is called on the imported key. */ diff --git a/components/mbedtls/test_apps/main/test_ds_sign_and_decrypt.c b/components/mbedtls/test_apps/main/test_ds_sign_and_decrypt.c index d583773e2da..3d550cdd201 100644 --- a/components/mbedtls/test_apps/main/test_ds_sign_and_decrypt.c +++ b/components/mbedtls/test_apps/main/test_ds_sign_and_decrypt.c @@ -68,7 +68,7 @@ TEST_CASE("ds sign test pkcs1_v15 PSA validation", "[ds_rsa_psa]") psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_algorithm(&attributes, alg); - psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); + psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE); status = psa_import_key(&attributes, (const uint8_t *)&rsa_ds_opaque_key, sizeof(rsa_ds_opaque_key), @@ -112,7 +112,7 @@ TEST_CASE("ds sign test pkcs1_v15 PSA", "[ds_rsa_psa]") psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_algorithm(&attributes, alg); - psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); + psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE); status = psa_import_key(&attributes, (const uint8_t *)&rsa_ds_opaque_key, sizeof(rsa_ds_opaque_key), @@ -180,7 +180,7 @@ TEST_CASE("ds sign test pkcs1_v21 PSA", "[ds_rsa_psa]") psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_algorithm(&attributes, alg); - psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); + psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE); status = psa_import_key(&attributes, (const uint8_t *)&rsa_ds_opaque_key, sizeof(rsa_ds_opaque_key), @@ -246,7 +246,7 @@ TEST_CASE("ds decrypt test pkcs1_v21 PSA", "[ds_rsa]") psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT); psa_set_key_algorithm(&attributes, alg); - psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); + psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE); status = psa_import_key(&attributes, (const uint8_t *)&rsa_ds_opaque_key, sizeof(rsa_ds_opaque_key), @@ -309,7 +309,7 @@ TEST_CASE("ds decrypt test pkcs1_v15 PSA", "[ds_rsa]") psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT); psa_set_key_algorithm(&attributes, alg); - psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); + psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE); status = psa_import_key(&attributes, (const uint8_t *)&rsa_ds_opaque_key, sizeof(rsa_ds_opaque_key),