b997d1115b
Optionally, embedd PKCS#11 token URI and encrypted key in LUKS2 JSON metadata header. That way it becomes very easy to unlock properly set up PKCS#11-enabled LUKS2 volumes, a simple /etc/crypttab line like the following suffices: mytest /dev/disk/by-partuuid/41c1df55-e628-4dbb-8492-bc69d81e172e - pkcs11-uri=auto Such a line declares that unlocking via PKCS#11 shall be attempted, and the token URI and the encrypted key shall be read from the LUKS2 header. An external key file for the encrypted PKCS#11 key is hence no longer necessary, nor is specifying the precise URI to use.
63 lines
1.8 KiB
C
63 lines
1.8 KiB
C
/* SPDX-License-Identifier: LGPL-2.1-or-later */
|
|
#pragma once
|
|
|
|
#include <sys/types.h>
|
|
|
|
#include "cryptsetup-util.h"
|
|
#include "log.h"
|
|
#include "time-util.h"
|
|
|
|
#if HAVE_P11KIT
|
|
|
|
int decrypt_pkcs11_key(
|
|
const char *volume_name,
|
|
const char *friendly_name,
|
|
const char *pkcs11_uri,
|
|
const char *key_file,
|
|
size_t key_file_size,
|
|
uint64_t key_file_offset,
|
|
const void *key_data,
|
|
size_t key_data_size,
|
|
usec_t until,
|
|
void **ret_decrypted_key,
|
|
size_t *ret_decrypted_key_size);
|
|
|
|
int find_pkcs11_auto_data(
|
|
struct crypt_device *cd,
|
|
char **ret_uri,
|
|
void **ret_encrypted_key,
|
|
size_t *ret_encrypted_key_size,
|
|
int *ret_keyslot);
|
|
|
|
#else
|
|
|
|
static inline int decrypt_pkcs11_key(
|
|
const char *volume_name,
|
|
const char *friendly_name,
|
|
const char *pkcs11_uri,
|
|
const char *key_file,
|
|
size_t key_file_size,
|
|
uint64_t key_file_offset,
|
|
const void *key_data,
|
|
size_t key_data_size,
|
|
usec_t until,
|
|
void **ret_decrypted_key,
|
|
size_t *ret_decrypted_key_size) {
|
|
|
|
return log_error_errno(SYNTHETIC_ERRNO(EOPNOTSUPP),
|
|
"PKCS#11 Token support not available.");
|
|
}
|
|
|
|
static inline int find_pkcs11_auto_data(
|
|
struct crypt_device *cd,
|
|
char **ret_uri,
|
|
void **ret_encrypted_key,
|
|
size_t *ret_encrypted_key_size,
|
|
int *ret_keyslot) {
|
|
|
|
return log_error_errno(SYNTHETIC_ERRNO(EOPNOTSUPP),
|
|
"PKCS#11 Token support not available.");
|
|
}
|
|
|
|
#endif
|