change(mbedtls): Change the ESP-DS-RSA key lifetime name to include the VOLATILE keyword

This commit is contained in:
harshal.patil
2026-03-18 16:38:24 +05:30
parent ca0daf01c6
commit e0b444281c
4 changed files with 19 additions and 8 deletions
+1 -1
View File
@@ -1436,7 +1436,7 @@ static esp_err_t esp_mbedtls_init_pk_ctx_for_ds(const void *pki)
psa_set_key_bits(&ds_key_attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_bits(&ds_key_attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits);
psa_set_key_usage_flags(&ds_key_attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_usage_flags(&ds_key_attributes, PSA_KEY_USAGE_SIGN_HASH);
psa_set_key_algorithm(&ds_key_attributes, alg); psa_set_key_algorithm(&ds_key_attributes, alg);
psa_set_key_lifetime(&ds_key_attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); psa_set_key_lifetime(&ds_key_attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE);
status = psa_import_key(&ds_key_attributes, status = psa_import_key(&ds_key_attributes,
(const uint8_t *)&rsa_ds_opaque_key, (const uint8_t *)&rsa_ds_opaque_key,
sizeof(rsa_ds_opaque_key), sizeof(rsa_ds_opaque_key),
@@ -22,8 +22,19 @@ extern "C" {
#define PSA_KEY_LOCATION_ESP_RSA_DS ((psa_key_location_t) 0x800003) #define PSA_KEY_LOCATION_ESP_RSA_DS ((psa_key_location_t) 0x800003)
/* IDF-15427: ESP-PSA driver does not support persistent RSA DS keys as of now */
#if 0
/* @brief Construct a lifetime for ESP RSA DS keys with default persistence */
#define PSA_KEY_LIFETIME_ESP_RSA_DS \ #define PSA_KEY_LIFETIME_ESP_RSA_DS \
PSA_KEY_LIFETIME_FROM_PERSISTENCE_AND_LOCATION( \
PSA_KEY_PERSISTENCE_DEFAULT, \
PSA_KEY_LOCATION_ESP_RSA_DS)
#endif
/**
* @brief Construct a volatile lifetime for ESP RSA DS keys
*/
#define PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE \
PSA_KEY_LIFETIME_FROM_PERSISTENCE_AND_LOCATION( \ PSA_KEY_LIFETIME_FROM_PERSISTENCE_AND_LOCATION( \
PSA_KEY_PERSISTENCE_VOLATILE, \ PSA_KEY_PERSISTENCE_VOLATILE, \
PSA_KEY_LOCATION_ESP_RSA_DS) PSA_KEY_LOCATION_ESP_RSA_DS)
@@ -35,7 +35,7 @@ typedef enum {
* @brief ESP DS data context * @brief ESP DS data context
* This context is used to store the ESP DS data. * This context is used to store the ESP DS data.
* *
* When passed to psa_import_key() for PSA_KEY_LIFETIME_ESP_RSA_DS, the key material * When passed to psa_import_key() for PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE, the key material
* (this struct and the esp_ds_data_t pointed to by esp_ds_data) must remain valid * (this struct and the esp_ds_data_t pointed to by esp_ds_data) must remain valid
* until psa_destroy_key() is called on the imported key. * until psa_destroy_key() is called on the imported key.
*/ */
@@ -68,7 +68,7 @@ TEST_CASE("ds sign test pkcs1_v15 PSA validation", "[ds_rsa_psa]")
psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits);
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH);
psa_set_key_algorithm(&attributes, alg); psa_set_key_algorithm(&attributes, alg);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE);
status = psa_import_key(&attributes, status = psa_import_key(&attributes,
(const uint8_t *)&rsa_ds_opaque_key, (const uint8_t *)&rsa_ds_opaque_key,
sizeof(rsa_ds_opaque_key), sizeof(rsa_ds_opaque_key),
@@ -112,7 +112,7 @@ TEST_CASE("ds sign test pkcs1_v15 PSA", "[ds_rsa_psa]")
psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits);
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH);
psa_set_key_algorithm(&attributes, alg); psa_set_key_algorithm(&attributes, alg);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE);
status = psa_import_key(&attributes, status = psa_import_key(&attributes,
(const uint8_t *)&rsa_ds_opaque_key, (const uint8_t *)&rsa_ds_opaque_key,
sizeof(rsa_ds_opaque_key), sizeof(rsa_ds_opaque_key),
@@ -180,7 +180,7 @@ TEST_CASE("ds sign test pkcs1_v21 PSA", "[ds_rsa_psa]")
psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits);
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_SIGN_HASH);
psa_set_key_algorithm(&attributes, alg); psa_set_key_algorithm(&attributes, alg);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE);
status = psa_import_key(&attributes, status = psa_import_key(&attributes,
(const uint8_t *)&rsa_ds_opaque_key, (const uint8_t *)&rsa_ds_opaque_key,
sizeof(rsa_ds_opaque_key), sizeof(rsa_ds_opaque_key),
@@ -246,7 +246,7 @@ TEST_CASE("ds decrypt test pkcs1_v21 PSA", "[ds_rsa]")
psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits);
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT);
psa_set_key_algorithm(&attributes, alg); psa_set_key_algorithm(&attributes, alg);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE);
status = psa_import_key(&attributes, status = psa_import_key(&attributes,
(const uint8_t *)&rsa_ds_opaque_key, (const uint8_t *)&rsa_ds_opaque_key,
sizeof(rsa_ds_opaque_key), sizeof(rsa_ds_opaque_key),
@@ -309,7 +309,7 @@ TEST_CASE("ds decrypt test pkcs1_v15 PSA", "[ds_rsa]")
psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits); psa_set_key_bits(&attributes, rsa_ds_opaque_key.ds_data_ctx->rsa_length_bits);
psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT); psa_set_key_usage_flags(&attributes, PSA_KEY_USAGE_DECRYPT);
psa_set_key_algorithm(&attributes, alg); psa_set_key_algorithm(&attributes, alg);
psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS); psa_set_key_lifetime(&attributes, PSA_KEY_LIFETIME_ESP_RSA_DS_VOLATILE);
status = psa_import_key(&attributes, status = psa_import_key(&attributes,
(const uint8_t *)&rsa_ds_opaque_key, (const uint8_t *)&rsa_ds_opaque_key,
sizeof(rsa_ds_opaque_key), sizeof(rsa_ds_opaque_key),