| Age | Commit message (Collapse) | Author | Files | Lines |
|
the direct variable update in PasswordSmmInit fails with an
EFI_NOT_AVAILABLE_YET error. This occurs because the initial NV
variable write relies on the EFI_VARIABLE_WRITE_ARCH_PROTOCOL, which
has not yet been installed during the early DXE/SMM init phase.
|
|
Initializing the Variable to 'NULL'
for resolving MSVC Build error.
Signed-off-by: Uyyala, RavitejaX <ravitejax.uyyala@intel.com>
|
|
Included additional checks for stronger password.
Signed-off-by: Uyyala, RavitejaX <ravitejax.uyyala@intel.com>
|
|
Use RngLib to get the Random number instead of passing
seed value is NULL and seed size is zero.
Signed-off-by: Kilumu, VenkataX Sai Mahesh <venkatax.sai.mahesh.kilumu@intel.com>
|
|
Clearing password at EXIT in both cases SMM_PASSWORD_FUNCTION_SET_PASSWORD
and SMM_PASSWORD_FUNCTION_VERIFY_PASSWORD
Signed-off-by: Patel, Azhar ImtiyazX <azhar.imtiyazx.patel@intel.com>
|
|
SmmPasswordHandler returns EFI_SUCCESS even when the CommBufferSize
is less than the expected header size.
Change the return statement to return an appropriate error code
EFI_INVALID_PARAMETER instead of EFI_SUCCESS.
Signed-off-by: Reji, RencyX <rencyx.reji@intel.com>
|
|
KeyLibGenerateSalt function fails to check the return values of
RandomSeed and RandomBytes function calls. Also SavePasswordToVariable
fails to check return value from KeyLibGenerateSalt.
Added error handling code to check the return values of RandomSeed,
RandomBytes functions and KeyLibGenerateSalt in SavePasswordToVariable.
Signed-off-by: Reji, RencyX <rencyx.reji@intel.com>
|
|
Refactor UserAuthenticationSmm to support Standalone MM.
- Factor out variable lock code logic that references boot services.
- UserAuthenticationStandaloneMmDxe is added to lock the variables.
It is only used for UserAuthenticationStandaloneMm.
- UserAuthenticationStandaloneMm doesn't lock the variables, needs to
rely on UserAuthenticationStandaloneMmDxe to do the lock.
- UserAuthenticationSmm still locks the variables by itself, no need
to include UserAuthenticationStandaloneMmDxe.
- Register gEfiEventExitBootServicesGuid notify which is used by the
StandaloneMmCore.
Since gEdkiiVariableLockProtocolGuid is a deprecated interface, use
gEdkiiVariablePolicyProtocolGuid to lock password variables instead.
Cc: Dandan Bi <dandan.bi@intel.com>
Reviewed-by: Nate DeSimone <nathaniel.l.desimone@intel.com>
Cc: Liming Gao <gaoliming@byosoft.com.cn>
Signed-off-by: Wei6 Xu <wei6.xu@intel.com>
|
|
Packages should be at the root of a PACKAGES_PATH entry.
At some point, paths were relative to edk2-platforms/Features/Intel
which was functional, but interferes with the proper functioning
of packaging tools.
Cc: Liming Gao <gaoliming@byosoft.com.cn>
Cc: Dandan Bi <dandan.bi@intel.com>
Signed-off-by: Isaac Oram <isaac.w.oram@intel.com>
Reviewed-by: Nate DeSimone <nathaniel.l.desimone@intel.com>
|
|
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3756
If the password provided by the user is incorrect, then the VerifyPassword()
function is supposed to return EFI_SECURITY_VIOLATION if the user has not
exceeded the maximum number of password guesses (currently set to 3). If the
number of password guesses has been exceeded, then VerifyPassword() shall return
EFI_ACCESS_DENIED. UserAuthenticationDxe uses EFI_ACCESS_DENIED as the signal
that the number of guesses has been exceeded for the purposes of triggering a
forced reboot.
VerifyPassword() checks if the number of password guess attempts has exceeded
the maximum allowed before checking if the current password guess is correct. If
it has, then VerifyPassword() immediately returns EFI_ACCESS_DENIED. This
behavior is correct since it is possible for VerifyPassword() to be called again
after the maximum number of attempts has been exceeded. However, if the user
guesses incorrectly, then VerifyPassword() will always return
EFI_SECURITY_VIOLATION. This is where the bug is. It is possible that after the
current attempt, the maximum allowed number of attempts is exceeded. Therefore,
VerifyPassword() should check the number of attempts again, after checking if
the password is correct.
Cc: Dandan Bi <dandan.bi@intel.com>
Cc: Liming Gao <gaoliming@byosoft.com.cn>
Cc: Jadhav Manoj D <manoj.d.jadhav@intel.com>
Cc: Chasel Chiu <chasel.chiu@intel.com>
Signed-off-by: Nate DeSimone <nathaniel.l.desimone@intel.com>
Reviewed-by: Dandan Bi <dandan.bi@intel.com>
|
|
authentication should be unregister before booting to OS
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3648
Register SmmExitBootServices and SmmLegacyBoot callback function to unregister this handler.
Signed-off-by: Hao Shi <hao.shi@intel.com>
Cc: Dandan Bi <dandan.bi@intel.com>
Cc: Liming Gao <gaoliming@byosoft.com.cn>
Reviewed-by: Dandan Bi <dandan.bi@intel.com>
|
|
Adds a new feature package for the User Authentication feature.
Cc: Dandan Bi <dandan.bi@intel.com>
Cc: Liming Gao <liming.gao@intel.com>
Signed-off-by: Michael Kubacki <michael.a.kubacki@intel.com>
Reviewed-by: Nate DeSimone <nathaniel.l.desimone@intel.com>
|