diff options
author | David Howells <dhowells@redhat.com> | 2014-07-01 16:02:52 +0100 |
---|---|---|
committer | David Howells <dhowells@redhat.com> | 2014-07-09 14:58:37 +0100 |
commit | 4c0b4b1d1ae0cbc86f150e2905a1c3d2a17b7c1e (patch) | |
tree | bbb779c5438a9cef8260569fae85493abf2522eb /crypto/asymmetric_keys/mscode.asn1 | |
parent | 3968280c7699f11e27a21aeafacf50bc86c2ed25 (diff) | |
download | talos-obmc-linux-4c0b4b1d1ae0cbc86f150e2905a1c3d2a17b7c1e.tar.gz talos-obmc-linux-4c0b4b1d1ae0cbc86f150e2905a1c3d2a17b7c1e.zip |
pefile: Parse the "Microsoft individual code signing" data blob
The PKCS#7 certificate should contain a "Microsoft individual code signing"
data blob as its signed content. This blob contains a digest of the signed
content of the PE binary and the OID of the digest algorithm used (typically
SHA256).
Signed-off-by: David Howells <dhowells@redhat.com>
Acked-by: Vivek Goyal <vgoyal@redhat.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Diffstat (limited to 'crypto/asymmetric_keys/mscode.asn1')
-rw-r--r-- | crypto/asymmetric_keys/mscode.asn1 | 28 |
1 files changed, 28 insertions, 0 deletions
diff --git a/crypto/asymmetric_keys/mscode.asn1 b/crypto/asymmetric_keys/mscode.asn1 new file mode 100644 index 000000000000..6d09ba48c41c --- /dev/null +++ b/crypto/asymmetric_keys/mscode.asn1 @@ -0,0 +1,28 @@ +--- Microsoft individual code signing data blob parser +--- +--- Copyright (C) 2012 Red Hat, Inc. All Rights Reserved. +--- Written by David Howells (dhowells@redhat.com) +--- +--- This program is free software; you can redistribute it and/or +--- modify it under the terms of the GNU General Public Licence +--- as published by the Free Software Foundation; either version +--- 2 of the Licence, or (at your option) any later version. +--- + +MSCode ::= SEQUENCE { + type SEQUENCE { + contentType ContentType, + parameters ANY + }, + content SEQUENCE { + digestAlgorithm DigestAlgorithmIdentifier, + digest OCTET STRING ({ mscode_note_digest }) + } +} + +ContentType ::= OBJECT IDENTIFIER ({ mscode_note_content_type }) + +DigestAlgorithmIdentifier ::= SEQUENCE { + algorithm OBJECT IDENTIFIER ({ mscode_note_digest_algo }), + parameters ANY OPTIONAL +} |