diff --git a/src/config/config_crypto.c b/src/config/config_crypto.c index c9d04a890..47b35371b 100644 --- a/src/config/config_crypto.c +++ b/src/config/config_crypto.c @@ -169,6 +169,16 @@ REQUIRE_OBJECT ( rsa_sha384 ); REQUIRE_OBJECT ( rsa_sha512 ); #endif +/* RSA and SHA-512/224 */ +#if defined ( CRYPTO_PUBKEY_RSA ) && defined ( CRYPTO_DIGEST_SHA512_224 ) +REQUIRE_OBJECT ( rsa_sha512_224 ); +#endif + +/* RSA and SHA-512/256 */ +#if defined ( CRYPTO_PUBKEY_RSA ) && defined ( CRYPTO_DIGEST_SHA512_256 ) +REQUIRE_OBJECT ( rsa_sha512_256 ); +#endif + /* RSA, AES-CBC, and SHA-1 */ #if defined ( CRYPTO_EXCHANGE_PUBKEY ) && defined ( CRYPTO_PUBKEY_RSA ) && \ defined ( CRYPTO_CIPHER_AES_CBC ) && defined ( CRYPTO_DIGEST_SHA1 ) diff --git a/src/crypto/mishmash/rsa_sha512_224.c b/src/crypto/mishmash/rsa_sha512_224.c new file mode 100644 index 000000000..ce54a52cf --- /dev/null +++ b/src/crypto/mishmash/rsa_sha512_224.c @@ -0,0 +1,54 @@ +/* + * Copyright (C) 2026 Michael Brown . + * + * This program is free software; you can redistribute it and/or + * modify it under the terms of the GNU General Public License as + * published by the Free Software Foundation; either version 2 of the + * License, or (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + * General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA + * 02110-1301, USA. + * + * You can also choose to distribute this program under the terms of + * the Unmodified Binary Distribution Licence (as given in the file + * COPYING.UBDL), provided that you have satisfied its requirements. + */ + +FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL ); +FILE_SECBOOT ( PERMITTED ); + +#include +#include +#include + +/** "sha512-224WithRSAEncryption" object identifier */ +static uint8_t oid_sha512_224_with_rsa_encryption[] = + { ASN1_OID_SHA512_224WITHRSAENCRYPTION }; + +/** "sha512-224WithRSAEncryption" OID-identified algorithm */ +struct asn1_algorithm +sha512_224_with_rsa_encryption_algorithm __asn1_algorithm = { + .name = "sha512-224WithRSAEncryption", + .pubkey = &rsa_algorithm, + .digest = &sha512_224_algorithm, + .oid = ASN1_CURSOR ( oid_sha512_224_with_rsa_encryption ), +}; + +/** SHA-512/224 digestInfo prefix */ +static const uint8_t rsa_sha512_224_prefix_data[] = + { RSA_DIGESTINFO_PREFIX ( SHA512_224_DIGEST_SIZE, + ASN1_OID_SHA512_224 ) }; + +/** SHA-512/224 digestInfo prefix */ +struct rsa_digestinfo_prefix rsa_sha512_224_prefix __rsa_digestinfo_prefix = { + .digest = &sha512_224_algorithm, + .data = rsa_sha512_224_prefix_data, + .len = sizeof ( rsa_sha512_224_prefix_data ), +}; diff --git a/src/crypto/mishmash/rsa_sha512_256.c b/src/crypto/mishmash/rsa_sha512_256.c new file mode 100644 index 000000000..a8cf3cdbc --- /dev/null +++ b/src/crypto/mishmash/rsa_sha512_256.c @@ -0,0 +1,54 @@ +/* + * Copyright (C) 2026 Michael Brown . + * + * This program is free software; you can redistribute it and/or + * modify it under the terms of the GNU General Public License as + * published by the Free Software Foundation; either version 2 of the + * License, or (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + * General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA + * 02110-1301, USA. + * + * You can also choose to distribute this program under the terms of + * the Unmodified Binary Distribution Licence (as given in the file + * COPYING.UBDL), provided that you have satisfied its requirements. + */ + +FILE_LICENCE ( GPL2_OR_LATER_OR_UBDL ); +FILE_SECBOOT ( PERMITTED ); + +#include +#include +#include + +/** "sha512-256WithRSAEncryption" object identifier */ +static uint8_t oid_sha512_256_with_rsa_encryption[] = + { ASN1_OID_SHA512_256WITHRSAENCRYPTION }; + +/** "sha512-256WithRSAEncryption" OID-identified algorithm */ +struct asn1_algorithm +sha512_256_with_rsa_encryption_algorithm __asn1_algorithm = { + .name = "sha512-256WithRSAEncryption", + .pubkey = &rsa_algorithm, + .digest = &sha512_256_algorithm, + .oid = ASN1_CURSOR ( oid_sha512_256_with_rsa_encryption ), +}; + +/** SHA-512/256 digestInfo prefix */ +static const uint8_t rsa_sha512_256_prefix_data[] = + { RSA_DIGESTINFO_PREFIX ( SHA512_256_DIGEST_SIZE, + ASN1_OID_SHA512_256 ) }; + +/** SHA-512/256 digestInfo prefix */ +struct rsa_digestinfo_prefix rsa_sha512_256_prefix __rsa_digestinfo_prefix = { + .digest = &sha512_256_algorithm, + .data = rsa_sha512_256_prefix_data, + .len = sizeof ( rsa_sha512_256_prefix_data ), +}; diff --git a/src/include/ipxe/asn1.h b/src/include/ipxe/asn1.h index 649b059d7..0c4854afe 100644 --- a/src/include/ipxe/asn1.h +++ b/src/include/ipxe/asn1.h @@ -212,6 +212,18 @@ struct asn1_builder_header { ASN1_OID_TRIPLE ( 113549 ), ASN1_OID_SINGLE ( 1 ), \ ASN1_OID_SINGLE ( 1 ), ASN1_OID_SINGLE ( 14 ) +/** ASN.1 OID for sha512-224WithRSAEncryption (1.2.840.113549.1.1.15) */ +#define ASN1_OID_SHA512_224WITHRSAENCRYPTION \ + ASN1_OID_INITIAL ( 1, 2 ), ASN1_OID_DOUBLE ( 840 ), \ + ASN1_OID_TRIPLE ( 113549 ), ASN1_OID_SINGLE ( 1 ), \ + ASN1_OID_SINGLE ( 1 ), ASN1_OID_SINGLE ( 15 ) + +/** ASN.1 OID for sha512-256WithRSAEncryption (1.2.840.113549.1.1.16) */ +#define ASN1_OID_SHA512_256WITHRSAENCRYPTION \ + ASN1_OID_INITIAL ( 1, 2 ), ASN1_OID_DOUBLE ( 840 ), \ + ASN1_OID_TRIPLE ( 113549 ), ASN1_OID_SINGLE ( 1 ), \ + ASN1_OID_SINGLE ( 1 ), ASN1_OID_SINGLE ( 16 ) + /** ASN.1 OID for id-md4 (1.2.840.113549.2.4) */ #define ASN1_OID_MD4 \ ASN1_OID_INITIAL ( 1, 2 ), ASN1_OID_DOUBLE ( 840 ), \ @@ -448,13 +460,17 @@ extern struct asn1_algorithm md5_with_rsa_encryption_algorithm __asn1_algorithm; extern struct asn1_algorithm sha1_with_rsa_encryption_algorithm __asn1_algorithm; extern struct asn1_algorithm +sha224_with_rsa_encryption_algorithm __asn1_algorithm; +extern struct asn1_algorithm sha256_with_rsa_encryption_algorithm __asn1_algorithm; extern struct asn1_algorithm sha384_with_rsa_encryption_algorithm __asn1_algorithm; extern struct asn1_algorithm sha512_with_rsa_encryption_algorithm __asn1_algorithm; extern struct asn1_algorithm -sha224_with_rsa_encryption_algorithm __asn1_algorithm; +sha512_224_with_rsa_encryption_algorithm __asn1_algorithm; +extern struct asn1_algorithm +sha512_256_with_rsa_encryption_algorithm __asn1_algorithm; extern struct asn1_algorithm oid_md4_algorithm __asn1_algorithm; extern struct asn1_algorithm oid_md5_algorithm __asn1_algorithm; extern struct asn1_algorithm oid_sha1_algorithm __asn1_algorithm;