Set pcr transform field depending on measuring algorithm
[strongswan.git] / src / libpts / pts / components / ita / ita_comp_tgrub.c
1 /*
2 * Copyright (C) 2011 Andreas Steffen
3 *
4 * HSR Hochschule fuer Technik Rapperswil
5 *
6 * This program is free software; you can redistribute it and/or modify it
7 * under the terms of the GNU General Public License as published by the
8 * Free Software Foundation; either version 2 of the License, or (at your
9 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
10 *
11 * This program is distributed in the hope that it will be useful, but
12 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
13 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
14 * for more details.
15 */
16
17 #include "ita_comp_tgrub.h"
18 #include "ita_comp_func_name.h"
19
20 #include "pts/components/pts_component.h"
21
22 #include <debug.h>
23 #include <pen/pen.h>
24
25 typedef struct pts_ita_comp_tgrub_t pts_ita_comp_tgrub_t;
26
27 /**
28 * Private data of a pts_ita_comp_tgrub_t object.
29 *
30 */
31 struct pts_ita_comp_tgrub_t {
32
33 /**
34 * Public pts_component_t interface.
35 */
36 pts_component_t public;
37
38 /**
39 * Component Functional Name
40 */
41 pts_comp_func_name_t *name;
42
43 /**
44 * Sub-component depth
45 */
46 u_int32_t depth;
47 };
48
49 METHOD(pts_component_t, get_comp_func_name, pts_comp_func_name_t*,
50 pts_ita_comp_tgrub_t *this)
51 {
52 return this->name;
53 }
54
55 METHOD(pts_component_t, get_evidence_flags, u_int8_t,
56 pts_ita_comp_tgrub_t *this)
57 {
58 return PTS_REQ_FUNC_COMP_EVID_PCR;
59 }
60
61 METHOD(pts_component_t, get_depth, u_int32_t,
62 pts_ita_comp_tgrub_t *this)
63 {
64 return this->depth;
65 }
66
67 METHOD(pts_component_t, measure, status_t,
68 pts_ita_comp_tgrub_t *this, pts_t *pts, pts_comp_evidence_t **evidence)
69 {
70 pts_comp_evidence_t *evid;
71 u_int32_t extended_pcr;
72 time_t measurement_time;
73 chunk_t measurement, pcr_before, pcr_after;
74 pts_pcr_transform_t pcr_transform;
75 pts_meas_algorithms_t hash_algo;
76
77 /* Provisional implementation for TGRUB */
78 extended_pcr = PCR_DEBUG;
79 time(&measurement_time);
80
81 if (!pts->read_pcr(pts, extended_pcr, &pcr_after))
82 {
83 DBG1(DBG_PTS, "error occured while reading PCR: %d", extended_pcr);
84 return FAILED;
85 }
86
87 hash_algo = pts->get_meas_algorithm(pts);
88 switch (hash_algo)
89 {
90 case PTS_MEAS_ALGO_SHA1:
91 pcr_transform = PTS_PCR_TRANSFORM_MATCH;
92 case PTS_MEAS_ALGO_SHA256:
93 case PTS_MEAS_ALGO_SHA384:
94 pcr_transform = PTS_PCR_TRANSFORM_LONG;
95 case PTS_MEAS_ALGO_NONE:
96 default:
97 pcr_transform = PTS_PCR_TRANSFORM_NO;
98 }
99
100 measurement = chunk_alloc(HASH_SIZE_SHA1);
101 memset(measurement.ptr, 0x00, measurement.len);
102
103 pcr_before = chunk_alloc(PCR_LEN);
104 memset(pcr_before.ptr, 0x00, pcr_before.len);
105
106 evid = *evidence = pts_comp_evidence_create(this->name->clone(this->name),
107 this->depth, extended_pcr,
108 hash_algo, pcr_transform,
109 measurement_time, measurement);
110 evid->set_pcr_info(evid, pcr_before, pcr_after);
111
112 return SUCCESS;
113 }
114
115 METHOD(pts_component_t, verify, status_t,
116 pts_ita_comp_tgrub_t *this, pts_t *pts, pts_database_t *pts_db,
117 pts_comp_evidence_t *evidence)
118 {
119 bool has_pcr_info;
120 u_int32_t extended_pcr;
121 pts_meas_algorithms_t algo;
122 pts_pcr_transform_t transform;
123 time_t measurement_time;
124 chunk_t measurement, pcr_before, pcr_after;
125
126 measurement = evidence->get_measurement(evidence, &extended_pcr,
127 &algo, &transform, &measurement_time);
128 if (extended_pcr != PCR_DEBUG)
129 {
130 return FAILED;
131 }
132
133 /* TODO check measurement in database */
134
135 has_pcr_info = evidence->get_pcr_info(evidence, &pcr_before, &pcr_after);
136 if (has_pcr_info)
137 {
138 if (!pts->add_pcr(pts, extended_pcr, pcr_before, pcr_after))
139 {
140 return FAILED;
141 }
142 }
143
144 return SUCCESS;
145 }
146
147 METHOD(pts_component_t, destroy, void,
148 pts_ita_comp_tgrub_t *this)
149 {
150 this->name->destroy(this->name);
151 free(this);
152 }
153
154 /**
155 * See header
156 */
157 pts_component_t *pts_ita_comp_tgrub_create(u_int8_t qualifier, u_int32_t depth)
158 {
159 pts_ita_comp_tgrub_t *this;
160
161 INIT(this,
162 .public = {
163 .get_comp_func_name = _get_comp_func_name,
164 .get_evidence_flags = _get_evidence_flags,
165 .get_depth = _get_depth,
166 .measure = _measure,
167 .verify = _verify,
168 .destroy = _destroy,
169 },
170 .name = pts_comp_func_name_create(PEN_ITA, PTS_ITA_COMP_FUNC_NAME_TBOOT,
171 qualifier),
172 .depth = depth,
173 );
174
175 return &this->public;
176 }
177