Temporary commenting out of processing optional PCR Composite field
[strongswan.git] / src / libpts / tcg / tcg_pts_attr_simple_evid_final.c
1 /*
2 * Copyright (C) 2011 Sansar Choinyambuu
3 * HSR Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "tcg_pts_attr_simple_evid_final.h"
17
18 #include <pa_tnc/pa_tnc_msg.h>
19 #include <bio/bio_writer.h>
20 #include <bio/bio_reader.h>
21 #include <debug.h>
22
23 typedef struct private_tcg_pts_attr_simple_evid_final_t private_tcg_pts_attr_simple_evid_final_t;
24
25 /**
26 * Simple Evidence Final
27 * see section 3.15.2 of PTS Protocol: Binding to TNC IF-M Specification
28 *
29 * 1 2 3
30 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
31 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
32 * | Flags | Reserved | Optional Composite Hash Alg |
33 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
34 * | Optional TPM PCR Composite Length |
35 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
36 * ~ Optional TPM PCR Composite (Variable Length) ~
37 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
38 * | Optional TPM Quote Signature Length |
39 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
40 * ~ Optional TPM Quote Signature (Variable Length) ~
41 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
42 * ~ Optional Evidence Signature (Variable Length) ~
43 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
44 */
45
46 #define PTS_SIMPLE_EVID_FINAL_SIZE 2
47 #define PTS_SIMPLE_EVID_FINAL_RESERVED 0x00
48
49 /**
50 * Private data of an tcg_pts_attr_simple_evid_final_t object.
51 */
52 struct private_tcg_pts_attr_simple_evid_final_t {
53
54 /**
55 * Public members of tcg_pts_attr_simple_evid_final_t
56 */
57 tcg_pts_attr_simple_evid_final_t public;
58
59 /**
60 * Attribute vendor ID
61 */
62 pen_t vendor_id;
63
64 /**
65 * Attribute type
66 */
67 u_int32_t type;
68
69 /**
70 * Attribute value
71 */
72 chunk_t value;
73
74 /**
75 * Noskip flag
76 */
77 bool noskip_flag;
78
79 /**
80 * Is Evidence Signature included
81 */
82 bool evid_sign_included;
83
84 /**
85 * Set of flags for Simple Evidence Final
86 */
87 pts_simple_evid_final_flag_t flags;
88
89 /**
90 * Optional Composite Hash Algorithm
91 */
92 pts_meas_algorithms_t comp_hash_algorithm;
93
94 /**
95 * Optional TPM PCR Composite
96 */
97 chunk_t pcr_comp;
98
99 /**
100 * Optional TPM Quote Signature
101 */
102 chunk_t tpm_quote_sign;
103
104 /**
105 * Optional Evidence Signature
106 */
107 chunk_t evid_sign;
108
109 };
110
111 METHOD(pa_tnc_attr_t, get_vendor_id, pen_t,
112 private_tcg_pts_attr_simple_evid_final_t *this)
113 {
114 return this->vendor_id;
115 }
116
117 METHOD(pa_tnc_attr_t, get_type, u_int32_t,
118 private_tcg_pts_attr_simple_evid_final_t *this)
119 {
120 return this->type;
121 }
122
123 METHOD(pa_tnc_attr_t, get_value, chunk_t,
124 private_tcg_pts_attr_simple_evid_final_t *this)
125 {
126 return this->value;
127 }
128
129 METHOD(pa_tnc_attr_t, get_noskip_flag, bool,
130 private_tcg_pts_attr_simple_evid_final_t *this)
131 {
132 return this->noskip_flag;
133 }
134
135 METHOD(pa_tnc_attr_t, set_noskip_flag,void,
136 private_tcg_pts_attr_simple_evid_final_t *this, bool noskip)
137 {
138 this->noskip_flag = noskip;
139 }
140
141 METHOD(pa_tnc_attr_t, build, void,
142 private_tcg_pts_attr_simple_evid_final_t *this)
143 {
144 bio_writer_t *writer;
145 u_int8_t flags = 0;
146
147 writer = bio_writer_create(PTS_SIMPLE_EVID_FINAL_SIZE);
148
149 /* Determine the flags to set*/
150 if (this->flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO)
151 {
152 flags += 64;
153 }
154 else if (this->flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2)
155 {
156 flags += 128;
157 }
158 else if (this->flags == PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER)
159 {
160 flags += 192;
161 }
162 if (this->evid_sign_included)
163 {
164 flags += 32;
165 }
166
167 writer->write_uint8 (writer, flags);
168 writer->write_uint8 (writer, PTS_SIMPLE_EVID_FINAL_RESERVED);
169
170 /* Optional fields */
171 if (this->comp_hash_algorithm)
172 {
173 writer->write_uint16(writer, this->comp_hash_algorithm);
174 }
175 if (this->pcr_comp.ptr && this->pcr_comp.len > 0)
176 {
177 writer->write_uint32 (writer, this->pcr_comp.len);
178 writer->write_data (writer, this->pcr_comp);
179 }
180 if (this->tpm_quote_sign.ptr && this->tpm_quote_sign.len > 0)
181 {
182 writer->write_uint32 (writer, this->tpm_quote_sign.len);
183 writer->write_data (writer, this->tpm_quote_sign);
184 }
185 if (this->evid_sign.ptr && this->evid_sign.len > 0)
186 {
187 writer->write_data (writer, this->evid_sign);
188 }
189
190 this->value = chunk_clone(writer->get_buf(writer));
191 writer->destroy(writer);
192 }
193
194 METHOD(pa_tnc_attr_t, process, status_t,
195 private_tcg_pts_attr_simple_evid_final_t *this, u_int32_t *offset)
196 {
197 bio_reader_t *reader;
198 u_int8_t flags;
199 u_int8_t reserved;
200 //u_int16_t algorithm;
201
202 if (this->value.len < PTS_SIMPLE_EVID_FINAL_SIZE)
203 {
204 DBG1(DBG_TNC, "insufficient data for Simple Evidence Final");
205 *offset = 0;
206 return FAILED;
207 }
208 reader = bio_reader_create(this->value);
209
210 reader->read_uint8(reader, &flags);
211
212 /* Determine the flags to set*/
213 if (!((flags >> 7) & 1) && !((flags >> 6) & 1))
214 {
215 this->flags = PTS_SIMPLE_EVID_FINAL_FLAG_NO;
216 }
217 else if (!((flags >> 7) & 1) && ((flags >> 6) & 1))
218 {
219 this->flags = PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO;
220 }
221 else if (((flags >> 7) & 1) && !((flags >> 6) & 1))
222 {
223 this->flags = PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2;
224 }
225 else if (((flags >> 7) & 1) && ((flags >> 6) & 1))
226 {
227 this->flags = PTS_SIMPLE_EVID_FINAL_FLAG_TPM_QUOTE_INFO2_CAP_VER;
228 }
229 if ((flags >> 5) & 1)
230 {
231 this->evid_sign_included = TRUE;
232 }
233
234 reader->read_uint8(reader, &reserved);
235
236 /* Optional Composite Hash Algorithm and TPM PCR Composite field is included */
237 if (this->flags != PTS_SIMPLE_EVID_FINAL_FLAG_NO)
238 {
239 /** u_int32_t pcr_comp_len;*/
240 u_int32_t tpm_quote_sign_len;
241
242 /** TODO: Ignoring Hashing algorithm field
243 * There is no flag defined which indicates the precense of it
244 * reader->read_uint16(reader, &algorithm);
245 * this->comp_hash_algorithm = algorithm;
246 */
247 reader->read_uint32(reader, &pcr_comp_len);
248 reader->read_data(reader, pcr_comp_len, &this->pcr_comp);
249 this->pcr_comp = chunk_clone(this->pcr_comp);
250
251 reader->read_uint32(reader, &tpm_quote_sign_len);
252 reader->read_data(reader, tpm_quote_sign_len, &this->tpm_quote_sign);
253 this->tpm_quote_sign = chunk_clone(this->tpm_quote_sign);
254 }
255
256 /* Optional Evidence Signature field is included */
257 if (this->evid_sign_included)
258 {
259 u_int32_t evid_sign_len = reader->remaining(reader);
260 reader->read_data(reader, evid_sign_len, &this->evid_sign);
261 this->evid_sign = chunk_clone(this->evid_sign);
262 }
263
264 reader->destroy(reader);
265 return SUCCESS;
266 }
267
268 METHOD(pa_tnc_attr_t, destroy, void,
269 private_tcg_pts_attr_simple_evid_final_t *this)
270 {
271 free(this->value.ptr);
272 free(this->pcr_comp.ptr);
273 free(this->tpm_quote_sign.ptr);
274 free(this->evid_sign.ptr);
275 free(this);
276 }
277
278 METHOD(tcg_pts_attr_simple_evid_final_t, is_evid_sign_included, bool,
279 private_tcg_pts_attr_simple_evid_final_t *this)
280 {
281 return this->evid_sign_included;
282 }
283
284 METHOD(tcg_pts_attr_simple_evid_final_t, get_flags, pts_simple_evid_final_flag_t,
285 private_tcg_pts_attr_simple_evid_final_t *this)
286 {
287 return this->flags;
288 }
289
290 METHOD(tcg_pts_attr_simple_evid_final_t, get_comp_hash_algorithm, pts_meas_algorithms_t,
291 private_tcg_pts_attr_simple_evid_final_t *this)
292 {
293 return this->comp_hash_algorithm;
294 }
295
296 METHOD(tcg_pts_attr_simple_evid_final_t, get_pcr_comp, chunk_t,
297 private_tcg_pts_attr_simple_evid_final_t *this)
298 {
299 return this->pcr_comp;
300 }
301
302 METHOD(tcg_pts_attr_simple_evid_final_t, get_tpm_quote_sign, chunk_t,
303 private_tcg_pts_attr_simple_evid_final_t *this)
304 {
305 return this->tpm_quote_sign;
306 }
307
308 METHOD(tcg_pts_attr_simple_evid_final_t, get_evid_sign, chunk_t,
309 private_tcg_pts_attr_simple_evid_final_t *this)
310 {
311 return this->evid_sign;
312 }
313
314 /**
315 * Described in header.
316 */
317 pa_tnc_attr_t *tcg_pts_attr_simple_evid_final_create(
318 bool evid_sign_included,
319 pts_simple_evid_final_flag_t flags,
320 pts_meas_algorithms_t comp_hash_algorithm,
321 chunk_t pcr_comp,
322 chunk_t tpm_quote_sign,
323 chunk_t evid_sign)
324 {
325 private_tcg_pts_attr_simple_evid_final_t *this;
326
327 INIT(this,
328 .public = {
329 .pa_tnc_attribute = {
330 .get_vendor_id = _get_vendor_id,
331 .get_type = _get_type,
332 .get_value = _get_value,
333 .get_noskip_flag = _get_noskip_flag,
334 .set_noskip_flag = _set_noskip_flag,
335 .build = _build,
336 .process = _process,
337 .destroy = _destroy,
338 },
339 .is_evid_sign_included = _is_evid_sign_included,
340 .get_flags = _get_flags,
341 .get_comp_hash_algorithm = _get_comp_hash_algorithm,
342 .get_pcr_comp = _get_pcr_comp,
343 .get_tpm_quote_sign = _get_tpm_quote_sign,
344 .get_evid_sign = _get_evid_sign,
345 },
346 .vendor_id = PEN_TCG,
347 .type = TCG_PTS_SIMPLE_EVID_FINAL,
348 .evid_sign_included = evid_sign_included,
349 .flags = flags,
350 .comp_hash_algorithm = comp_hash_algorithm,
351 .pcr_comp = chunk_clone(pcr_comp),
352 .tpm_quote_sign = chunk_clone(tpm_quote_sign),
353 .evid_sign = chunk_clone(evid_sign),
354 );
355
356 return &this->public.pa_tnc_attribute;
357 }
358
359
360 /**
361 * Described in header.
362 */
363 pa_tnc_attr_t *tcg_pts_attr_simple_evid_final_create_from_data(chunk_t data)
364 {
365 private_tcg_pts_attr_simple_evid_final_t *this;
366
367 INIT(this,
368 .public = {
369 .pa_tnc_attribute = {
370 .get_vendor_id = _get_vendor_id,
371 .get_type = _get_type,
372 .get_value = _get_value,
373 .get_noskip_flag = _get_noskip_flag,
374 .set_noskip_flag = _set_noskip_flag,
375 .build = _build,
376 .process = _process,
377 .destroy = _destroy,
378 },
379 .is_evid_sign_included = _is_evid_sign_included,
380 .get_flags= _get_flags,
381 .get_comp_hash_algorithm = _get_comp_hash_algorithm,
382 .get_pcr_comp = _get_pcr_comp,
383 .get_tpm_quote_sign = _get_tpm_quote_sign,
384 .get_evid_sign = _get_evid_sign,
385 },
386 .vendor_id = PEN_TCG,
387 .type = TCG_PTS_SIMPLE_EVID_FINAL,
388 .value = chunk_clone(data),
389 );
390
391 return &this->public.pa_tnc_attribute;
392 }