[PATCH] X.509: Support parsing certificate using SM2 algorithm

Subsystems: asymmetric keys, crypto api, the rest

STALE1574d

4 messages, 2 authors, 2022-06-17 · open the first message on its own page

[PATCH] X.509: Support parsing certificate using SM2 algorithm

From: Tianjia Zhang <hidden>
Date: 2021-07-12 09:04:21

The SM2-with-SM3 certificate generated by latest openssl no longer
reuses the OID_id_ecPublicKey, but directly uses OID_sm2. This patch
supports this type of x509 certificate parsing.

Signed-off-by: Tianjia Zhang <redacted>
---
 crypto/asymmetric_keys/x509_cert_parser.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/crypto/asymmetric_keys/x509_cert_parser.c b/crypto/asymmetric_keys/x509_cert_parser.c
index 6d003096b5bc..6a945a6ce787 100644
--- a/crypto/asymmetric_keys/x509_cert_parser.c
+++ b/crypto/asymmetric_keys/x509_cert_parser.c
@@ -496,6 +496,9 @@ int x509_extract_key_data(void *context, size_t hdrlen,
 	case OID_gost2012PKey512:
 		ctx->cert->pub->pkey_algo = "ecrdsa";
 		break;
+	case OID_sm2:
+		ctx->cert->pub->pkey_algo = "sm2";
+		break;
 	case OID_id_ecPublicKey:
 		if (parse_OID(ctx->params, ctx->params_size, &oid) != 0)
 			return -EBADMSG;
-- 
2.19.1.3.ge56e4f7

Re: [PATCH] X.509: Support parsing certificate using SM2 algorithm

From: Tianjia Zhang <hidden>
Date: 2021-09-18 02:25:14

ping.

On 7/12/21 4:13 PM, Tianjia Zhang wrote:
quoted hunk
The SM2-with-SM3 certificate generated by latest openssl no longer
reuses the OID_id_ecPublicKey, but directly uses OID_sm2. This patch
supports this type of x509 certificate parsing.

Signed-off-by: Tianjia Zhang <redacted>
---
  crypto/asymmetric_keys/x509_cert_parser.c | 3 +++
  1 file changed, 3 insertions(+)
diff --git a/crypto/asymmetric_keys/x509_cert_parser.c b/crypto/asymmetric_keys/x509_cert_parser.c
index 6d003096b5bc..6a945a6ce787 100644
--- a/crypto/asymmetric_keys/x509_cert_parser.c
+++ b/crypto/asymmetric_keys/x509_cert_parser.c
@@ -496,6 +496,9 @@ int x509_extract_key_data(void *context, size_t hdrlen,
  	case OID_gost2012PKey512:
  		ctx->cert->pub->pkey_algo = "ecrdsa";
  		break;
+	case OID_sm2:
+		ctx->cert->pub->pkey_algo = "sm2";
+		break;
  	case OID_id_ecPublicKey:
  		if (parse_OID(ctx->params, ctx->params_size, &oid) != 0)
  			return -EBADMSG;

Re: [PATCH] X.509: Support parsing certificate using SM2 algorithm

From: Jarkko Sakkinen <jarkko@kernel.org>
Date: 2021-09-21 21:05:49

On Sat, 2021-09-18 at 10:25 +0800, Tianjia Zhang wrote:
ping.

On 7/12/21 4:13 PM, Tianjia Zhang wrote:
quoted
The SM2-with-SM3 certificate generated by latest openssl no longer
reuses the OID_id_ecPublicKey, but directly uses OID_sm2. This patch
supports this type of x509 certificate parsing.

Signed-off-by: Tianjia Zhang <redacted>
---
  crypto/asymmetric_keys/x509_cert_parser.c | 3 +++
  1 file changed, 3 insertions(+)
diff --git a/crypto/asymmetric_keys/x509_cert_parser.c b/crypto/asymmetric_keys/x509_cert_parser.c
index 6d003096b5bc..6a945a6ce787 100644
--- a/crypto/asymmetric_keys/x509_cert_parser.c
+++ b/crypto/asymmetric_keys/x509_cert_parser.c
@@ -496,6 +496,9 @@ int x509_extract_key_data(void *context, size_t hdrlen,
  	case OID_gost2012PKey512:
  		ctx->cert->pub->pkey_algo = "ecrdsa";
  		break;
+	case OID_sm2:
+		ctx->cert->pub->pkey_algo = "sm2";
+		break;
  	case OID_id_ecPublicKey:
  		if (parse_OID(ctx->params, ctx->params_size, &oid) != 0)
  			return -EBADMSG;
Acked-by: Jarkko Sakkinen <jarkko@kernel.org>

/Jarkko

回复:[PATCH] X.509: Support parsing certificate using SM2 algorithm

From: Tianjia Zhang <hidden>
Date: 2022-06-17 09:36:51

Hi Jarkko,
On 7/12/21 4:13 PM, Tianjia Zhang wrote:
quoted
The SM2-with-SM3 certificate generated by latest openssl no longer
reuses the OID_id_ecPublicKey, but directly uses OID_sm2. This patch
supports this type of x509 certificate parsing.

Signed-off-by: Tianjia Zhang <redacted>
---
  crypto/asymmetric_keys/x509_cert_parser.c | 3 +++
  1 file changed, 3 insertions(+)
diff --git a/crypto/asymmetric_keys/x509_cert_parser.c b/crypto/asymmetric_keys/x509_cert_parser.c
index 6d003096b5bc..6a945a6ce787 100644
--- a/crypto/asymmetric_keys/x509_cert_parser.c
+++ b/crypto/asymmetric_keys/x509_cert_parser.c
@@ -496,6 +496,9 @@ int x509_extract_key_data(void *context, size_t hdrlen,
   case OID_gost2012PKey512:
    ctx->cert->pub->pkey_algo = "ecrdsa";
    break;
+ case OID_sm2:
+  ctx->cert->pub->pkey_algo = "sm2";
+  break;
   case OID_id_ecPublicKey:
    if (parse_OID(ctx->params, ctx->params_size, &oid) != 0)
     return -EBADMSG;
Acked-by: Jarkko Sakkinen <jarkko@kernel.org>

/Jarkko
Likewise, No response from David, can you pick this? thanks.

Best regards,
Tianjia
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help