Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 1 | #!/usr/bin/env python |
Jerome Forissier | 1bb9298 | 2017-12-15 14:27:02 +0100 | [diff] [blame] | 2 | # SPDX-License-Identifier: BSD-2-Clause |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 3 | # |
| 4 | # Copyright (c) 2015, Linaro Limited |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 5 | |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 6 | |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 7 | def get_args(): |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 8 | import argparse |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 9 | |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 10 | parser = argparse.ArgumentParser() |
| 11 | parser.add_argument( |
Markus S. Wamser | 1718b6c | 2019-04-30 12:06:14 +0200 | [diff] [blame] | 12 | '--prefix', required=True, |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 13 | help='Prefix for the public key exponent and modulus in c file') |
Markus S. Wamser | 1718b6c | 2019-04-30 12:06:14 +0200 | [diff] [blame] | 14 | parser.add_argument( |
| 15 | '--out', required=True, |
| 16 | help='Name of c file for the public key') |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 17 | parser.add_argument('--key', required=True, help='Name of key file') |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 18 | |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 19 | return parser.parse_args() |
| 20 | |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 21 | |
| 22 | def main(): |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 23 | import array |
| 24 | from Crypto.PublicKey import RSA |
| 25 | from Crypto.Util.number import long_to_bytes |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 26 | |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 27 | args = get_args() |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 28 | |
Markus S. Wamser | 1718b6c | 2019-04-30 12:06:14 +0200 | [diff] [blame] | 29 | with open(args.key, 'r') as f: |
| 30 | key = RSA.importKey(f.read()) |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 31 | |
Markus S. Wamser | 0a6f2bc | 2019-03-26 11:29:44 +0100 | [diff] [blame] | 32 | # Refuse public exponent with more than 32 bits. Otherwise the C |
| 33 | # compiler may simply truncate the value and proceed. |
| 34 | # This will lead to TAs seemingly having invalid signatures with a |
| 35 | # possible security issue for any e = k*2^32 + 1 (for any integer k). |
| 36 | if key.publickey().e > 0xffffffff: |
| 37 | raise ValueError( |
| 38 | 'Unsupported large public exponent detected. ' + |
| 39 | 'OP-TEE handles only public exponents up to 2^32 - 1.') |
| 40 | |
Markus S. Wamser | 1718b6c | 2019-04-30 12:06:14 +0200 | [diff] [blame] | 41 | with open(args.out, 'w') as f: |
| 42 | f.write("#include <stdint.h>\n") |
| 43 | f.write("#include <stddef.h>\n\n") |
| 44 | f.write("const uint32_t " + args.prefix + "_exponent = " + |
| 45 | str(key.publickey().e) + ";\n\n") |
| 46 | f.write("const uint8_t " + args.prefix + "_modulus[] = {\n") |
| 47 | i = 0 |
| 48 | for x in array.array("B", long_to_bytes(key.publickey().n)): |
| 49 | f.write("0x" + '{0:02x}'.format(x) + ",") |
| 50 | i = i + 1 |
| 51 | if i % 8 == 0: |
| 52 | f.write("\n") |
| 53 | else: |
| 54 | f.write(" ") |
| 55 | f.write("};\n") |
| 56 | f.write("const size_t " + args.prefix + "_modulus_size = sizeof(" + |
| 57 | args.prefix + "_modulus);\n") |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 58 | |
Jens Wiklander | bc42074 | 2015-05-05 14:59:15 +0200 | [diff] [blame] | 59 | |
| 60 | if __name__ == "__main__": |
Jerome Forissier | 049aefa | 2018-11-14 11:02:49 +0100 | [diff] [blame] | 61 | main() |