summaryrefslogtreecommitdiff
path: root/Features/Intel/UserInterface/UserAuthFeaturePkg/UserAuthenticationDxeSmm
AgeCommit message (Collapse)AuthorFilesLines
2026-05-12When configuring the system to clear the user password,Zhu, Liangqi1-1/+1
the direct variable update in PasswordSmmInit fails with an EFI_NOT_AVAILABLE_YET error. This occurs because the initial NV variable write relies on the EFI_VARIABLE_WRITE_ARCH_PROTOCOL, which has not yet been installed during the early DXE/SMM init phase.
2025-11-12Features/Intel:Fix for MSVC variable build errorUyyala, RavitejaX1-0/+1
Initializing the Variable to 'NULL' for resolving MSVC Build error. Signed-off-by: Uyyala, RavitejaX <ravitejax.uyyala@intel.com>
2025-11-06Features/Intel: Enhanced Password complexityUyyala, RavitejaX3-4/+107
Included additional checks for stronger password. Signed-off-by: Uyyala, RavitejaX <ravitejax.uyyala@intel.com>
2025-10-28Features/Intel: Use RngLib to get Random number.Kilumu, VenkataX Sai Mahesh2-1/+8
Use RngLib to get the Random number instead of passing seed value is NULL and seed size is zero. Signed-off-by: Kilumu, VenkataX Sai Mahesh <venkatax.sai.mahesh.kilumu@intel.com>
2025-10-28Features/Intel:Failure to Clear Password DataPatel, Azhar ImtiyazX1-0/+2
Clearing password at EXIT in both cases SMM_PASSWORD_FUNCTION_SET_PASSWORD and SMM_PASSWORD_FUNCTION_VERIFY_PASSWORD Signed-off-by: Patel, Azhar ImtiyazX <azhar.imtiyazx.patel@intel.com>
2025-10-28Features/Intel: Improper Return StatusReji, RencyX1-1/+1
SmmPasswordHandler returns EFI_SUCCESS even when the CommBufferSize is less than the expected header size. Change the return statement to return an appropriate error code EFI_INVALID_PARAMETER instead of EFI_SUCCESS. Signed-off-by: Reji, RencyX <rencyx.reji@intel.com>
2025-10-18Features/Intel: Failed to check return statusReji, RencyX2-3/+11
KeyLibGenerateSalt function fails to check the return values of RandomSeed and RandomBytes function calls. Also SavePasswordToVariable fails to check return value from KeyLibGenerateSalt. Added error handling code to check the return values of RandomSeed, RandomBytes functions and KeyLibGenerateSalt in SavePasswordToVariable. Signed-off-by: Reji, RencyX <rencyx.reji@intel.com>
2023-12-01UserAuthFeaturePkg/UserAuthenticationSmm: Support Standalone MM.Wei6 Xu10-43/+360
Refactor UserAuthenticationSmm to support Standalone MM. - Factor out variable lock code logic that references boot services. - UserAuthenticationStandaloneMmDxe is added to lock the variables. It is only used for UserAuthenticationStandaloneMm. - UserAuthenticationStandaloneMm doesn't lock the variables, needs to rely on UserAuthenticationStandaloneMmDxe to do the lock. - UserAuthenticationSmm still locks the variables by itself, no need to include UserAuthenticationStandaloneMmDxe. - Register gEfiEventExitBootServicesGuid notify which is used by the StandaloneMmCore. Since gEdkiiVariableLockProtocolGuid is a deprecated interface, use gEdkiiVariablePolicyProtocolGuid to lock password variables instead. Cc: Dandan Bi <dandan.bi@intel.com> Reviewed-by: Nate DeSimone <nathaniel.l.desimone@intel.com> Cc: Liming Gao <gaoliming@byosoft.com.cn> Signed-off-by: Wei6 Xu <wei6.xu@intel.com>
2022-02-03UserAuthFeaturePkg: Fix all relative package pathsIsaac Oram3-3/+3
Packages should be at the root of a PACKAGES_PATH entry. At some point, paths were relative to edk2-platforms/Features/Intel which was functional, but interferes with the proper functioning of packaging tools. Cc: Liming Gao <gaoliming@byosoft.com.cn> Cc: Dandan Bi <dandan.bi@intel.com> Signed-off-by: Isaac Oram <isaac.w.oram@intel.com> Reviewed-by: Nate DeSimone <nathaniel.l.desimone@intel.com>
2021-12-08UserAuthFeaturePkg: VerifyPassword() allows one extra password attemptNate DeSimone1-2/+12
REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3756 If the password provided by the user is incorrect, then the VerifyPassword() function is supposed to return EFI_SECURITY_VIOLATION if the user has not exceeded the maximum number of password guesses (currently set to 3). If the number of password guesses has been exceeded, then VerifyPassword() shall return EFI_ACCESS_DENIED. UserAuthenticationDxe uses EFI_ACCESS_DENIED as the signal that the number of guesses has been exceeded for the purposes of triggering a forced reboot. VerifyPassword() checks if the number of password guess attempts has exceeded the maximum allowed before checking if the current password guess is correct. If it has, then VerifyPassword() immediately returns EFI_ACCESS_DENIED. This behavior is correct since it is possible for VerifyPassword() to be called again after the maximum number of attempts has been exceeded. However, if the user guesses incorrectly, then VerifyPassword() will always return EFI_SECURITY_VIOLATION. This is where the bug is. It is possible that after the current attempt, the maximum allowed number of attempts is exceeded. Therefore, VerifyPassword() should check the number of attempts again, after checking if the password is correct. Cc: Dandan Bi <dandan.bi@intel.com> Cc: Liming Gao <gaoliming@byosoft.com.cn> Cc: Jadhav Manoj D <manoj.d.jadhav@intel.com> Cc: Chasel Chiu <chasel.chiu@intel.com> Signed-off-by: Nate DeSimone <nathaniel.l.desimone@intel.com> Reviewed-by: Dandan Bi <dandan.bi@intel.com>
2021-10-13UserAuthFeaturePkg/UserAuthenticationDxeSmm: The SMI to handle the user ↵Shi, Hao2-5/+40
authentication should be unregister before booting to OS REF: https://bugzilla.tianocore.org/show_bug.cgi?id=3648 Register SmmExitBootServices and SmmLegacyBoot callback function to unregister this handler. Signed-off-by: Hao Shi <hao.shi@intel.com> Cc: Dandan Bi <dandan.bi@intel.com> Cc: Liming Gao <gaoliming@byosoft.com.cn> Reviewed-by: Dandan Bi <dandan.bi@intel.com>
2019-12-07Features/Intel/UserAuthFeaturePkg: Add initial packageMichael Kubacki15-0/+2982
Adds a new feature package for the User Authentication feature. Cc: Dandan Bi <dandan.bi@intel.com> Cc: Liming Gao <liming.gao@intel.com> Signed-off-by: Michael Kubacki <michael.a.kubacki@intel.com> Reviewed-by: Nate DeSimone <nathaniel.l.desimone@intel.com>