From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by inbox.dpdk.org (Postfix) with ESMTP id 5DD14A00C4; Thu, 30 Jun 2022 12:38:54 +0200 (CEST) Received: from [217.70.189.124] (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id 3E72A40223; Thu, 30 Jun 2022 12:38:54 +0200 (CEST) Received: from mga03.intel.com (mga03.intel.com [134.134.136.65]) by mails.dpdk.org (Postfix) with ESMTP id 2F30E400EF for ; Thu, 30 Jun 2022 12:38:53 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1656585533; x=1688121533; h=from:to:cc:subject:date:message-id; bh=ndEy/4EVNz2qDTr5gs1ie4ThZWROQCFvLMPoIxonm5E=; b=gocNyD1dObZdx+6ntQF7biLyv5kDiMlVxD04sXBMaB9i8jWvOz3OqJTz Q8hojoUw4sZiPui5QLpXN8G0KlfEsXvtvK9+wSQLhZzWFIb9NddQ+aXkZ ZW7cgZJQJueINiZlbn4pPQeQWh+OBtoGquLLYjh/JnoNq/okbQZRc9WCB q2nOqpYuSf5i6rOUeXrrT6XURT6xDv9fUICmi2BwgDRtM2KlWcECYB4Qq f2lN4x5pbXvFauWFWRdHuotRLFE4XqZnGaBak9jMmZKLAAFQCXGCfWQO2 OOCTuxeBnFWlyR02ylwPthk/myU1Vz/eb/yoNKF6rrHmZCUWigsKC4XWH g==; X-IronPort-AV: E=McAfee;i="6400,9594,10393"; a="283411270" X-IronPort-AV: E=Sophos;i="5.92,234,1650956400"; d="scan'208";a="283411270" Received: from fmsmga003.fm.intel.com ([10.253.24.29]) by orsmga103.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 30 Jun 2022 03:38:51 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.92,234,1650956400"; d="scan'208";a="680926319" Received: from silpixa00400465.ir.intel.com ([10.55.128.22]) by FMSMGA003.fm.intel.com with ESMTP; 30 Jun 2022 03:38:50 -0700 From: Kai Ji To: dev@dpdk.org Cc: gakhil@marvell.com, Kai Ji Subject: [dpdk-dev v1] crypto/openssl: EVP_PKEY routine update in rsa op Date: Thu, 30 Jun 2022 18:38:48 +0800 Message-Id: <20220630103848.36515-1-kai.ji@intel.com> X-Mailer: git-send-email 2.17.1 X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org EVP_PKEY function need to be called twice for rsa sign and verify operations. This patch also remove the OPENSSL_API_COMPAT as all the deprecated APIs are avoid if 3.0 lib is present. Fixes: d7bd42f6db19 ("crypto/openssl: update RSA routine with 3.0 EVP API") Cc: kai.ji@intel.com Signed-off-by: Kai Ji --- drivers/crypto/openssl/rte_openssl_pmd.c | 32 ++++++++++++++------ drivers/crypto/openssl/rte_openssl_pmd_ops.c | 2 -- 2 files changed, 22 insertions(+), 12 deletions(-) diff --git a/drivers/crypto/openssl/rte_openssl_pmd.c b/drivers/crypto/openssl/rte_openssl_pmd.c index 84bca86894..e01dacc98d 100644 --- a/drivers/crypto/openssl/rte_openssl_pmd.c +++ b/drivers/crypto/openssl/rte_openssl_pmd.c @@ -1788,7 +1788,7 @@ process_openssl_dsa_sign_op_evp(struct rte_crypto_op *cop, if (key_ctx == NULL || EVP_PKEY_fromdata_init(key_ctx) <= 0 || EVP_PKEY_fromdata(key_ctx, &pkey, - EVP_PKEY_PUBLIC_KEY, params) <= 0) + EVP_PKEY_KEYPAIR, params) <= 0) goto err_dsa_sign; dsa_ctx = EVP_PKEY_CTX_new(pkey, NULL); @@ -2478,6 +2478,14 @@ process_openssl_rsa_op_evp(struct rte_crypto_op *cop, if (EVP_PKEY_CTX_set_rsa_padding(rsa_ctx, pad) <= 0) goto err_rsa; + if (EVP_PKEY_sign(rsa_ctx, NULL, &outlen, + op->rsa.message.data, + op->rsa.message.length) <= 0) + goto err_rsa; + + if (outlen <= 0) + goto err_rsa; + if (EVP_PKEY_sign(rsa_ctx, op->rsa.sign.data, &outlen, op->rsa.message.data, op->rsa.message.length) <= 0) @@ -2486,19 +2494,23 @@ process_openssl_rsa_op_evp(struct rte_crypto_op *cop, break; case RTE_CRYPTO_ASYM_OP_VERIFY: - tmp = rte_malloc(NULL, op->rsa.sign.length, 0); - if (tmp == NULL) { - OPENSSL_LOG(ERR, "Memory allocation failed"); + if (EVP_PKEY_verify_recover_init(rsa_ctx) <= 0) goto err_rsa; - } - if (EVP_PKEY_verify_recover_init(rsa_ctx) <= 0) { - rte_free(tmp); + if (EVP_PKEY_CTX_set_rsa_padding(rsa_ctx, pad) <= 0) goto err_rsa; - } - if (EVP_PKEY_CTX_set_rsa_padding(rsa_ctx, pad) <= 0) { - rte_free(tmp); + if (EVP_PKEY_verify_recover(rsa_ctx, NULL, &outlen, + op->rsa.sign.data, + op->rsa.sign.length) <= 0) + goto err_rsa; + + if ((outlen <= 0) || (outlen != op->rsa.sign.length)) + goto err_rsa; + + tmp = OPENSSL_malloc(outlen); + if (tmp == NULL) { + OPENSSL_LOG(ERR, "Memory allocation failed"); goto err_rsa; } diff --git a/drivers/crypto/openssl/rte_openssl_pmd_ops.c b/drivers/crypto/openssl/rte_openssl_pmd_ops.c index 8d1f8e834a..3e24ef94f7 100644 --- a/drivers/crypto/openssl/rte_openssl_pmd_ops.c +++ b/drivers/crypto/openssl/rte_openssl_pmd_ops.c @@ -2,8 +2,6 @@ * Copyright(c) 2016-2017 Intel Corporation */ -#define OPENSSL_API_COMPAT 0x10100000L - #include #include -- 2.17.1