summaryrefslogtreecommitdiff
path: root/CryptoPkg/Library/BaseCryptLibNull
diff options
context:
space:
mode:
authorBaraneedharan Anbazhagan <anbazhagan@hp.com>2026-03-17 15:19:12 +0300
committermergify[bot] <37929162+mergify[bot]@users.noreply.github.com>2026-04-07 15:26:54 +0300
commitb3fdc0994db62b72a8b56ea25ffd024ab5e4e017 (patch)
tree98e00057ce0dbfebbd779fab5a5f7f11612609d4 /CryptoPkg/Library/BaseCryptLibNull
parentf1fc41cff2a2022e67da3f9f525f9087cf2de507 (diff)
downloadedk2-b3fdc0994db62b72a8b56ea25ffd024ab5e4e017.tar.xz
CryptoPkg: Add digest-based RSA-PSS sign and verify APIs
Add RsaPssSignDigest() and RsaPssVerifyDigest() to BaseCryptLib for signing/verifying precomputed digests. Provide OpenSSL/MbedTLS/Null implementations, expose via EDKII_CRYPTO_PROTOCOL (v24), and add PCD controls for independent service enabling. Include unit tests. Signed-off-by: Anbazhagan Baraneedharan <anbazhagan@hp.com>
Diffstat (limited to 'CryptoPkg/Library/BaseCryptLibNull')
-rw-r--r--CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssNull.c29
-rw-r--r--CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssSignNull.c31
2 files changed, 60 insertions, 0 deletions
diff --git a/CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssNull.c b/CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssNull.c
index cc325c9291..ac4647351f 100644
--- a/CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssNull.c
+++ b/CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssNull.c
@@ -3,8 +3,10 @@
This file does not provide real capabilities for following APIs in RSA handling:
1) RsaPssVerify
+ 2) RsaPssVerifyDigest
Copyright (c) 2021, Intel Corporation. All rights reserved.<BR>
+(c) Copyright 2026 HP Development Company, L.P.
SPDX-License-Identifier: BSD-2-Clause-Patent
**/
@@ -44,3 +46,30 @@ RsaPssVerify (
ASSERT (FALSE);
return FALSE;
}
+
+/**
+ Verifies an RSA-PSS signature over a precomputed message digest.
+
+ @param[in] RsaContext Pointer to RSA context for signature verification.
+ @param[in] Digest Pointer to the message digest.
+ @param[in] DigestSize Digest size in bytes.
+ @param[in] Signature Pointer to RSASSA-PSS signature to be verified.
+ @param[in] SigSize Size of signature in bytes.
+
+ @retval TRUE Valid signature encoded in RSASSA-PSS.
+ @retval FALSE Invalid signature or invalid RSA context.
+
+**/
+BOOLEAN
+EFIAPI
+RsaPssVerifyDigest (
+ IN VOID *RsaContext,
+ IN CONST UINT8 *Digest,
+ IN UINTN DigestSize,
+ IN CONST UINT8 *Signature,
+ IN UINTN SigSize
+ )
+{
+ ASSERT (FALSE);
+ return FALSE;
+}
diff --git a/CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssSignNull.c b/CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssSignNull.c
index 911b972521..4da5a6fba7 100644
--- a/CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssSignNull.c
+++ b/CryptoPkg/Library/BaseCryptLibNull/Pk/CryptRsaPssSignNull.c
@@ -3,8 +3,10 @@
This file does not provide real capabilities for following APIs in RSA handling:
1) RsaPssSign
+ 2) RsaPssSignDigest
Copyright (c) 2021, Intel Corporation. All rights reserved.<BR>
+(c) Copyright 2026 HP Development Company, L.P.
SPDX-License-Identifier: BSD-2-Clause-Patent
**/
@@ -58,3 +60,32 @@ RsaPssSign (
ASSERT (FALSE);
return FALSE;
}
+
+/**
+ Carries out the RSA-PSS signature generation over a precomputed message digest.
+
+ @param[in] RsaContext Pointer to RSA context for signature generation.
+ @param[in] Digest Pointer to the precomputed message digest.
+ @param[in] DigestSize Digest size in bytes.
+ @param[out] Signature Pointer to buffer to receive RSA PSS signature.
+ @param[in, out] SigSize On input, the size of Signature buffer in bytes.
+ On output, the size of data returned in Signature buffer in bytes.
+
+ @retval TRUE Signature successfully generated in RSASSA-PSS.
+ @retval FALSE Signature generation failed.
+ @retval FALSE This interface is not supported.
+
+**/
+BOOLEAN
+EFIAPI
+RsaPssSignDigest (
+ IN VOID *RsaContext,
+ IN CONST UINT8 *Digest,
+ IN UINTN DigestSize,
+ OUT UINT8 *Signature,
+ IN OUT UINTN *SigSize
+ )
+{
+ ASSERT (FALSE);
+ return FALSE;
+}