Merge patch series "rsa: Add rsa_verify_openssl() to use openssl for host builds"

Paul HENRYS <paul.henrys_ext@softathome.com> says:

This serie of patches adds a new tool to authenticate files signed with
a preload header.  This tool is also used in the tests to actually
verify the authenticity of the file signed with such a preload header.

Link: https://lore.kernel.org/r/20250224212055.2992852-1-paul.henrys_ext@softathome.com
This commit is contained in:
Tom Rini
2025-02-28 16:51:10 -06:00
11 changed files with 411 additions and 3 deletions

View File

@@ -1688,6 +1688,24 @@ struct sig_header_s {
*/
int image_pre_load(ulong addr);
#if defined(USE_HOSTCC)
/**
* rsa_verify_openssl() - Verify a signature against some data with openssl API
*
* Verify a RSA PKCS1.5/PSS signature against an expected hash.
*
* @info: Specifies the key and algorithms
* @region: Pointer to the input data
* @region_count: Number of region
* @sig: Signature
* @sig_len: Number of bytes in the signature
* Return: 0 if verified, -ve on error
*/
int rsa_verify_openssl(struct image_sign_info *info,
const struct image_region region[], int region_count,
uint8_t *sig, uint sig_len);
#endif
/**
* fit_image_verify_required_sigs() - Verify signatures marked as 'required'
*