mirror of
https://github.com/intel/linux-sgx
synced 2026-06-08 14:49:32 +00:00
Rebase the code to 2.18 release.
Signed-off-by: Zhang Lili <lili.z.zhang@intel.com>
This commit is contained in:
@@ -51,10 +51,14 @@ build: $(SGXSSL_HEADER_CHECK)
|
||||
$(MAKE) -C client
|
||||
$(MAKE) -C non_enc_client
|
||||
|
||||
tdx: $(SGXSSL_HEADER_CHECK)
|
||||
$(MAKE) -C server_tdx
|
||||
|
||||
clean:
|
||||
$(MAKE) -C server clean
|
||||
$(MAKE) -C client clean
|
||||
$(MAKE) -C non_enc_client clean
|
||||
$(MAKE) -C server_tdx clean
|
||||
|
||||
run:
|
||||
echo "Launch processes to establish an Attested TLS between two enclaves"
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
The audience is assumed to be familiar:
|
||||
[What is an Attested TLS channel](AttestedTLSREADME.md#what-is-an-attested-tls-channel)
|
||||
|
||||
The `QuoteGenerationSample` and `QuoteVerificationSample` can be run successfully on server and client machines. (`tdx-quote-generation-sample` and `tdx-quote-verification-sample` for TDX)
|
||||
# The Attested TLS sample
|
||||
|
||||
It has the following properties:
|
||||
@@ -39,7 +40,7 @@ Note: Both of them can run on the same machine or separate machines.
|
||||
- Host part (tls_server_host)
|
||||
- Instantiate an enclave before transitioning the control into the enclave via an ecall.
|
||||
- Enclave (tls_server_enclave.signed.so)
|
||||
- Call tee_get_certificate_with_evidence to generate an certificate
|
||||
- Call tee_get_certificate_with_evidence to generate a certificate
|
||||
- Use SgxSSL API to configure a TLS server using the generated certificate
|
||||
- Launch a TLS server and wait for client connection request
|
||||
- Read client payload and reply with server payload
|
||||
@@ -72,6 +73,36 @@ Note: Both of them can run on the same machine or separate machines.
|
||||
./non_enc_client/tls_non_enc_client -server:localhost -port:12341
|
||||
```
|
||||
|
||||
## TDX Sample Configration
|
||||
|
||||
The sample supports creating attested TLS channel between:
|
||||
- two TD-guests
|
||||
- TD-guest and SGX enclave
|
||||
- TD-guest and non TEE environment
|
||||
|
||||
> **Note**:
|
||||
> In order to connect to the port on guest TD from host or other machihnes, port forwarding needs to be set using QEMU command when starting the guest TD.
|
||||
Use the following QEMU command:
|
||||
>```
|
||||
>hostfwd=tcp::HOSTPORT-:GUESTPORT
|
||||
>```
|
||||
|
||||
### TDX server application
|
||||
|
||||
- Call tee_get_certificate_with_evidence to generate a certificate
|
||||
- Use OpenSSL API to configure a TLS server using the generated certificate
|
||||
- Launch a TLS server and wait for client connection request
|
||||
- Read client payload and reply with server payload
|
||||
- To run TDX server application, copy `./server_tdx/tls_server` to TD-guest and run the following command:
|
||||
|
||||
```
|
||||
./tls_server -port:12341
|
||||
```
|
||||
|
||||
### TDX client application
|
||||
|
||||
The TDX client applicaiton is the same as non-enclave client application, except that it is running in guest TD.
|
||||
|
||||
## Build and run
|
||||
```bash
|
||||
make
|
||||
|
||||
@@ -66,6 +66,7 @@ SOCKETINCDIR = $(SOCKET_DIR)/include #socket EDL search path
|
||||
SSLINCDIR = $(SGXSSL_PKG_PATH)/include
|
||||
ENC_TLS_CLIENT_Name := tls_client_enclave.so
|
||||
Signed_ENC_TLS_CLIENT_Name := tls_client_enclave.signed.so
|
||||
Enclave_Test_Key := private_test_key.pem
|
||||
|
||||
.PHONY: all build clean run
|
||||
|
||||
@@ -89,7 +90,12 @@ build:
|
||||
$(CXX) -o $(ENC_TLS_CLIENT_Name) $(OBJ_FILES) $(Enclave_Link_Flags)
|
||||
|
||||
sign:
|
||||
$(SGX_ENCLAVE_SIGNER) sign -key private_test_key.pem -enclave $(ENC_TLS_CLIENT_Name) \
|
||||
ifeq ($(wildcard $(Enclave_Test_Key)),)
|
||||
@echo "There is no enclave test key<Enclave_private_test.pem>."
|
||||
@echo "The project will generate a key<Enclave_private_test.pem> for test."
|
||||
@openssl genrsa -out $(Enclave_Test_Key) -3 3072
|
||||
endif
|
||||
$(SGX_ENCLAVE_SIGNER) sign -key $(Enclave_Test_Key) -enclave $(ENC_TLS_CLIENT_Name) \
|
||||
-out $(Signed_ENC_TLS_CLIENT_Name) -config client_enc.config.xml
|
||||
|
||||
clean:
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
-----BEGIN RSA PRIVATE KEY-----
|
||||
MIIG4gIBAAKCAYEAqhEGbnOzUfNffyL98nRjFOXYb+4d1Q/CluY3GlbDFv9OphD9
|
||||
zwY8TnSUz/cIBMdphAadGlnjIi8SS9Yey1IfRcIW1pMnRaAS8J1Kwh9WgBqBZlA/
|
||||
bFB4a45ZC16l+oeG5/u3MeQsKDsNIT1kfHJDSb18UHlvEPNcrzIDy+TAcAhd7q/a
|
||||
av1lDp28TgT7kUdVb5HitBzBQ67s4/L6XzloyAMqSybT56nnTeADcNa/tvom8vqz
|
||||
0lZ5nXAQ7ZAhGKJKCWk+9aT5oxLNBCrUYQ+UtnJ8429uzBYvG/fyaMcAGjkcfnW2
|
||||
irYSpwfFbpN6Ew2252V6O6KYTcFGKBGQaXKezflTOOQ6yRUr5a4GqwTsVc6TH+Nv
|
||||
pIyL1SgY2zzSkwciqTRyHBh7UpfCC3E3ZNJKT4CUPXu5eINL6v2Wmz8CRbc2hoPo
|
||||
D+oIvLoqcgClihZs3XlGp3D6ULEgKBP5ortCgpUbitgtA0zGLrQlJhKHVkGgwxax
|
||||
1U9wLHPNLxzzsGaJAgEDAoIBgHFgrvRNIjaiP6oXU/b4Qg3ukEqevo4Kgbnuz2bk
|
||||
gg9U3xlgqTSu0t74YzVPWq3aRlgEaLw77MF0tt05adzhai6BZI8MxNkVYfW+Mda/
|
||||
jwARq5mK1PLgUEe0O1zpw/xaWe/9JMvtcsV8s2t+Qv2hgjEo/Yr7n2CiPcohV91D
|
||||
KvVa6UnKkZyo7gm+fYlYp7YvjkphQc1ogNfJ80Kh/D97mzACHDIZ4ppxRN6VV6CP
|
||||
Knn8GfdRzTbkUROgC0kKwLsW2u/rBFTw0ktBgfVchQmNuI+LBn95/Z6IBbNKOEWI
|
||||
bLWY/blDkQ6C4uTCfHNWBmYkHJJ427V1XsIFcbuLaxrRL6hKqHSx5F1utlDjgNzk
|
||||
2C+6Fo0aH1yf0wSc6slHEUef9pMbfvEvjDpm8y1xR+3VLhQgasleW1MHsAwDbzc6
|
||||
1Vos3LrMk49gpKPR/RrCPQ+aRpFnAaJl66iBMykqIEpuYOj3a0iHMs2MtSst7Kh/
|
||||
TDAlZRseCULoDPyNH1A6rJ08CwKBwQDXmNX87JG7CBQ6JemaBG+xhccjQT2VFSCj
|
||||
mQw/g8bKZ+MiHYyhyfr6muAExuYw5HsSysX7//p1s+7cVnsBgHsO1MOwSoa8ajxj
|
||||
iY07GrKHxOtS7UQavzomdudyNjXSVfCH8bEaESV4bm8JuZOFsnGshE7V7F/BoUU3
|
||||
3cVu4JDE+vCfT6qaGhLTFwZzsxuGj293Nwu37a6RfncCmHN3Fqdzp0lghdx0On9d
|
||||
8Z4XOwVAvD/H7+7eQj5pslyDH7QPKl0CgcEAye/ieU8sdyh12fojOLaQLZwsAPc0
|
||||
yTUF62+RwPaWP2u8xnLQUyfDVUkqvMuKSPMQ+OVqr3KPtQUssmn0v7hcQrSS2Y7d
|
||||
gITeCM84JJL1hnKF+U78ft2VJ8XROxwC1UFARJmCmEADgo7mPY23+mAThMulOYHQ
|
||||
ulZ+oRqqWYYxeXj6zwFgHr7+8+goVioubB+TjCe4e+pqQnDcZ7xVu/8JsXqxPYeE
|
||||
Wr83D/2kEhiPzU1JUnm1ErEeR+3Bs6U8tWIdAoHBAI+7OVNIYSdauCbD8RFYSnZZ
|
||||
L2zWKQ4OFcJmCCpX2dxFQha+XcExUfxnQAMvRCCYUgyHLqf//E539JLkUgEAUgnj
|
||||
LSAxryhG0u0GXidnIa/YnOHzgrx/fBmkmkwkI+GOoFqhILwLblBJn1vRDQPMS8hY
|
||||
NI6dlSvA2M/pLknrCy38oGo1HGa8DIy6BE0iElm09PoksnqedGD++gG696S5xPfE
|
||||
25Wukvgm/5P2aWTSA4B9f9qf9JQsKZvMPay/zV9xkwKBwQCGn+xQ33L6Gvk7/Bd7
|
||||
JGAeaB1V+iMwzgPySmErTw7U8n3ZoeA3b9eOMMcoh7GF92Cl7kcfobUjWMh28U3V
|
||||
JZLXIwyRCekAWJQF33rDDKOu9wP7if2p6Q4ag+DSEqyOK4Atu6xlgAJXCe7Ts8/8
|
||||
QA0DMm4mVosm5FRrZxw7rsumUKc0q5Vp1Kn38BrkHB7yv7eyxSWn8ZwsSz2afY59
|
||||
VLEg/HYpBQLnKiS1U8K2uwqI3jDhpni3IL7anoEibih47BMCgcBniK1vaIEB03SJ
|
||||
C407iKJX2uDAGUOakYGe4A6cjJz0ShGgfk5X3+qg3/ii/4igLAWi6mbuCHZEiCjN
|
||||
Wsr83gBzdK8DpoNdI23IHRasH8Vw6/B6ya8sIP6PzJFCEEMUTNpJwO+swWFvEsEO
|
||||
IY/o4Ue6+DX87v5mDa7IkJiGbCv567UA9665c/MNx70QJwivHtMbaC5ajiBUF1jZ
|
||||
qe8PhaHRkBjgIUt+vnmxcbhU2e+S91ZBdITyV/l+H3+wHBIhdP0=
|
||||
-----END RSA PRIVATE KEY-----
|
||||
@@ -41,7 +41,7 @@
|
||||
|
||||
// put common files here in a definition of Macro to reduce
|
||||
// redundancy code
|
||||
#ifdef CLIENT_UNTRUSTED
|
||||
#ifdef CLIENT_USE_QVL
|
||||
#include "sgx_utls.h"
|
||||
#define PRINT printf
|
||||
#define GETCURRTIME time
|
||||
@@ -49,9 +49,18 @@
|
||||
#define FREE_SUPDATA tee_free_supplemental_data_host
|
||||
#else
|
||||
#include "sgx_ttls.h"
|
||||
extern void t_print(const char* fmt, ...);
|
||||
#define PRINT t_print
|
||||
#define GETCURRTIME t_time
|
||||
#define PRINT T_PRINT
|
||||
#define GETCURRTIME T_TIME
|
||||
#define VERIFY_CALLBACK tee_verify_certificate_with_evidence
|
||||
#define FREE_SUPDATA tee_free_supplemental_data
|
||||
#endif
|
||||
|
||||
#ifdef TDX_ENV
|
||||
#define T_PRINT printf
|
||||
#define T_TIME time
|
||||
#else
|
||||
extern void t_print(const char* fmt, ...);
|
||||
extern void t_time(time_t *c_time);
|
||||
#define T_PRINT t_print
|
||||
#define T_TIME t_time
|
||||
#endif
|
||||
|
||||
@@ -41,11 +41,11 @@ sgx_status_t generate_certificate_and_pkey(X509*& certificate, EVP_PKEY*& pkey)
|
||||
int key_type = RSA_TYPE;
|
||||
|
||||
if (key_type) {
|
||||
t_print(" generating keys by EC P-384\n");
|
||||
PRINT(" generating keys by EC P-384\n");
|
||||
}
|
||||
else
|
||||
{
|
||||
t_print(" generating keys by RSA 3072\n");
|
||||
PRINT(" generating keys by RSA 3072\n");
|
||||
}
|
||||
result = generate_key_pair(
|
||||
key_type, &public_key_buffer,
|
||||
@@ -54,14 +54,14 @@ sgx_status_t generate_certificate_and_pkey(X509*& certificate, EVP_PKEY*& pkey)
|
||||
&private_key_buffer_size);
|
||||
if (result != SGX_SUCCESS)
|
||||
{
|
||||
t_print(" failed to generate RSA key pair\n");
|
||||
PRINT(" failed to generate RSA key pair\n");
|
||||
goto done;
|
||||
}
|
||||
|
||||
t_print("public_key_buf_size:[%ld]\n", public_key_buffer_size);
|
||||
t_print("%s\n", public_key_buffer);
|
||||
t_print("private_key_buf_size:[%ld]\n", private_key_buffer_size);
|
||||
t_print("%s\n", private_key_buffer);
|
||||
PRINT("public_key_buf_size:[%ld]\n", public_key_buffer_size);
|
||||
PRINT("%s\n", public_key_buffer);
|
||||
PRINT("private_key_buf_size:[%ld]\n", private_key_buffer_size);
|
||||
PRINT("%s\n", private_key_buffer);
|
||||
qresult = tee_get_certificate_with_evidence(
|
||||
certificate_subject_name,
|
||||
private_key_buffer,
|
||||
@@ -74,7 +74,7 @@ sgx_status_t generate_certificate_and_pkey(X509*& certificate, EVP_PKEY*& pkey)
|
||||
if (qresult != SGX_QL_SUCCESS || output_certificate == nullptr)
|
||||
{
|
||||
if (output_certificate == nullptr)
|
||||
t_print(" null certificate\n");
|
||||
PRINT(" null certificate\n");
|
||||
p_sgx_tls_qe_err_msg(qresult);
|
||||
goto done;
|
||||
}
|
||||
@@ -91,18 +91,18 @@ sgx_status_t generate_certificate_and_pkey(X509*& certificate, EVP_PKEY*& pkey)
|
||||
&certificate_buffer_ptr,
|
||||
(long)output_certificate_size)) == nullptr)
|
||||
{
|
||||
t_print("Failed to convert DER format certificate to X509 structure\n");
|
||||
PRINT("Failed to convert DER format certificate to X509 structure\n");
|
||||
goto done;
|
||||
}
|
||||
mem = BIO_new_mem_buf((void*)private_key_buffer, -1);
|
||||
if (!mem)
|
||||
{
|
||||
t_print("Failed to convert private key buf into BIO_mem\n");
|
||||
PRINT("Failed to convert private key buf into BIO_mem\n");
|
||||
goto done;
|
||||
}
|
||||
if ((pkey = PEM_read_bio_PrivateKey(mem, nullptr, 0, nullptr)) == nullptr)
|
||||
{
|
||||
t_print("Failed to convert private key buffer into EVP_KEY format\n");
|
||||
PRINT("Failed to convert private key buffer into EVP_KEY format\n");
|
||||
goto done;
|
||||
}
|
||||
|
||||
@@ -130,32 +130,32 @@ sgx_status_t load_tls_certificates_and_keys(
|
||||
|
||||
if (generate_certificate_and_pkey(certificate, pkey) != SGX_SUCCESS)
|
||||
{
|
||||
t_print("Cannot generate certificate and pkey\n");
|
||||
PRINT("Cannot generate certificate and pkey\n");
|
||||
goto exit;
|
||||
}
|
||||
|
||||
if (certificate == nullptr)
|
||||
{
|
||||
t_print("null cert\n");
|
||||
PRINT("null cert\n");
|
||||
goto exit;
|
||||
}
|
||||
|
||||
if (!SSL_CTX_use_certificate(ctx, certificate))
|
||||
{
|
||||
t_print("Cannot load certificate on the server\n");
|
||||
PRINT("Cannot load certificate on the server\n");
|
||||
goto exit;
|
||||
}
|
||||
|
||||
if (!SSL_CTX_use_PrivateKey(ctx, pkey))
|
||||
{
|
||||
t_print("Cannot load private key on the server\n");
|
||||
PRINT("Cannot load private key on the server\n");
|
||||
goto exit;
|
||||
}
|
||||
|
||||
/* verify private key */
|
||||
if (!SSL_CTX_check_private_key(ctx))
|
||||
{
|
||||
t_print("Private key does not match the public certificate\n");
|
||||
PRINT("Private key does not match the public certificate\n");
|
||||
goto exit;
|
||||
}
|
||||
result = SGX_SUCCESS;
|
||||
@@ -185,7 +185,7 @@ sgx_status_t initalize_ssl_context(SSL_CONF_CTX*& ssl_conf_ctx, SSL_CTX*& ctx)
|
||||
if ((ssl_conf_return_value =
|
||||
SSL_CONF_cmd(ssl_conf_ctx, "MinProtocol", "TLSv1.2")) < 0)
|
||||
{
|
||||
t_print(
|
||||
PRINT(
|
||||
"Setting MinProtocol for ssl context configuration failed with "
|
||||
"error %d \n",
|
||||
ssl_conf_return_value);
|
||||
@@ -194,7 +194,7 @@ sgx_status_t initalize_ssl_context(SSL_CONF_CTX*& ssl_conf_ctx, SSL_CTX*& ctx)
|
||||
if ((ssl_conf_return_value =
|
||||
SSL_CONF_cmd(ssl_conf_ctx, "MaxProtocol", "TLSv1.3")) < 0)
|
||||
{
|
||||
t_print(
|
||||
PRINT(
|
||||
"Setting MaxProtocol for ssl context configuration failed with "
|
||||
"error %d \n",
|
||||
ssl_conf_return_value);
|
||||
@@ -203,7 +203,7 @@ sgx_status_t initalize_ssl_context(SSL_CONF_CTX*& ssl_conf_ctx, SSL_CTX*& ctx)
|
||||
if ((ssl_conf_return_value = SSL_CONF_cmd(
|
||||
ssl_conf_ctx, "CipherString", cipher_list_tlsv12_below)) < 0)
|
||||
{
|
||||
t_print(
|
||||
PRINT(
|
||||
"Setting CipherString for ssl context configuration failed with "
|
||||
"error %d \n",
|
||||
ssl_conf_return_value);
|
||||
@@ -212,7 +212,7 @@ sgx_status_t initalize_ssl_context(SSL_CONF_CTX*& ssl_conf_ctx, SSL_CTX*& ctx)
|
||||
if ((ssl_conf_return_value = SSL_CONF_cmd(
|
||||
ssl_conf_ctx, "Ciphersuites", cipher_list_tlsv13)) < 0)
|
||||
{
|
||||
t_print(
|
||||
PRINT(
|
||||
"Setting Ciphersuites for ssl context configuration failed with "
|
||||
"error %d \n",
|
||||
ssl_conf_return_value);
|
||||
@@ -221,7 +221,7 @@ sgx_status_t initalize_ssl_context(SSL_CONF_CTX*& ssl_conf_ctx, SSL_CTX*& ctx)
|
||||
if ((ssl_conf_return_value =
|
||||
SSL_CONF_cmd(ssl_conf_ctx, "Curves", supported_curves)) < 0)
|
||||
{
|
||||
t_print(
|
||||
PRINT(
|
||||
"Setting Curves for ssl context configuration failed with error %d "
|
||||
"\n",
|
||||
ssl_conf_return_value);
|
||||
@@ -229,7 +229,7 @@ sgx_status_t initalize_ssl_context(SSL_CONF_CTX*& ssl_conf_ctx, SSL_CTX*& ctx)
|
||||
}
|
||||
if (!SSL_CONF_CTX_finish(ssl_conf_ctx))
|
||||
{
|
||||
t_print("Error finishing ssl context configuration \n");
|
||||
PRINT("Error finishing ssl context configuration \n");
|
||||
goto exit;
|
||||
}
|
||||
ret = SGX_SUCCESS;
|
||||
@@ -258,18 +258,18 @@ int read_from_session_peer(
|
||||
if (error == SSL_ERROR_WANT_READ)
|
||||
continue;
|
||||
|
||||
t_print("Failed! SSL_read returned error=%d\n", error);
|
||||
PRINT("Failed! SSL_read returned error=%d\n", error);
|
||||
ret = bytes_read;
|
||||
break;
|
||||
}
|
||||
|
||||
t_print(" %d bytes read from session peer\n", bytes_read);
|
||||
PRINT(" %d bytes read from session peer\n", bytes_read);
|
||||
|
||||
// check to see if received payload is expected
|
||||
if ((bytes_read != payload_length) ||
|
||||
(memcmp(payload, buffer, bytes_read) != 0))
|
||||
{
|
||||
t_print(
|
||||
PRINT(
|
||||
"ERROR: expected reading %lu bytes but only "
|
||||
"received %d bytes\n",
|
||||
payload_length,
|
||||
@@ -279,7 +279,7 @@ int read_from_session_peer(
|
||||
}
|
||||
else
|
||||
{
|
||||
t_print(" received all the expected data from the session peer\n\n");
|
||||
PRINT(" received all the expected data from the session peer\n\n");
|
||||
ret = 0;
|
||||
break;
|
||||
}
|
||||
@@ -303,12 +303,12 @@ int write_to_session_peer(
|
||||
int error = SSL_get_error(ssl_session, bytes_written);
|
||||
if (error == SSL_ERROR_WANT_WRITE)
|
||||
continue;
|
||||
t_print("Failed! SSL_write returned %d\n", error);
|
||||
PRINT("Failed! SSL_write returned %d\n", error);
|
||||
ret = bytes_written;
|
||||
goto exit;
|
||||
}
|
||||
|
||||
t_print("%lu bytes written to session peer\n\n", payload_length);
|
||||
PRINT("%lu bytes written to session peer\n\n", payload_length);
|
||||
exit:
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -52,19 +52,19 @@ int get_pkey_by_rsa(EVP_PKEY *pk)
|
||||
|
||||
e = BN_new();
|
||||
if (!e) {
|
||||
t_print("BN_new failed\n");
|
||||
PRINT("BN_new failed\n");
|
||||
return res;
|
||||
}
|
||||
|
||||
res = BN_set_word(e, (BN_ULONG)RSA_F4);
|
||||
if (!res) {
|
||||
t_print("BN_set_word failed (%d)\n", res);
|
||||
PRINT("BN_set_word failed (%d)\n", res);
|
||||
return res;
|
||||
}
|
||||
|
||||
rsa = RSA_new();
|
||||
if (!rsa) {
|
||||
t_print("RSA_new failed\n");
|
||||
PRINT("RSA_new failed\n");
|
||||
res = -1;
|
||||
return res;
|
||||
}
|
||||
@@ -78,7 +78,7 @@ int get_pkey_by_rsa(EVP_PKEY *pk)
|
||||
|
||||
if (!res)
|
||||
{
|
||||
t_print("RSA_generate_key failed (%d)\n", res);
|
||||
PRINT("RSA_generate_key failed (%d)\n", res);
|
||||
return res;
|
||||
}
|
||||
|
||||
@@ -99,14 +99,14 @@ int get_pkey_by_ec(EVP_PKEY *pk)
|
||||
res = EVP_PKEY_keygen_init(ctx);
|
||||
if (res <= 0)
|
||||
{
|
||||
t_print("EC_generate_key failed (%d)\n", res);
|
||||
PRINT("EC_generate_key failed (%d)\n", res);
|
||||
return res;
|
||||
}
|
||||
|
||||
res = EVP_PKEY_CTX_set_ec_paramgen_curve_nid(ctx, NID_secp384r1);
|
||||
if (res <= 0)
|
||||
{
|
||||
t_print("EC_generate_key failed (%d)\n", res);
|
||||
PRINT("EC_generate_key failed (%d)\n", res);
|
||||
return res;
|
||||
}
|
||||
|
||||
@@ -114,7 +114,7 @@ int get_pkey_by_ec(EVP_PKEY *pk)
|
||||
res = EVP_PKEY_keygen(ctx, &pk);
|
||||
if (res <= 0)
|
||||
{
|
||||
t_print("EC_generate_key failed (%d)\n", res);
|
||||
PRINT("EC_generate_key failed (%d)\n", res);
|
||||
return res;
|
||||
}
|
||||
|
||||
@@ -141,7 +141,7 @@ sgx_status_t generate_key_pair(
|
||||
pkey = EVP_PKEY_new();
|
||||
if (!pkey)
|
||||
{
|
||||
t_print("EVP_PKEY_new failed\n");
|
||||
PRINT("EVP_PKEY_new failed\n");
|
||||
result = SGX_ERROR_UNEXPECTED;
|
||||
goto done;
|
||||
}
|
||||
@@ -163,7 +163,7 @@ sgx_status_t generate_key_pair(
|
||||
|
||||
if (res <= 0)
|
||||
{
|
||||
t_print("get_pkey failed (%d)\n", res);
|
||||
PRINT("get_pkey failed (%d)\n", res);
|
||||
result = SGX_ERROR_UNEXPECTED;
|
||||
goto done;
|
||||
}
|
||||
@@ -172,7 +172,7 @@ sgx_status_t generate_key_pair(
|
||||
local_public_key = (uint8_t*)malloc(RSA_3072_PUBLIC_KEY_SIZE);
|
||||
if (!local_public_key)
|
||||
{
|
||||
t_print("out-of-memory:calloc(local_public_key failed\n");
|
||||
PRINT("out-of-memory:calloc(local_public_key failed\n");
|
||||
result = SGX_ERROR_OUT_OF_EPC;
|
||||
goto done;
|
||||
}
|
||||
@@ -181,7 +181,7 @@ sgx_status_t generate_key_pair(
|
||||
local_private_key = (uint8_t*)malloc(RSA_3072_PRIVATE_KEY_SIZE);
|
||||
if (!local_private_key)
|
||||
{
|
||||
t_print("out-of-memory: calloc(local_private_key) failed\n");
|
||||
PRINT("out-of-memory: calloc(local_private_key) failed\n");
|
||||
result = SGX_ERROR_OUT_OF_EPC;
|
||||
goto done;
|
||||
}
|
||||
@@ -192,21 +192,21 @@ sgx_status_t generate_key_pair(
|
||||
bio = BIO_new(BIO_s_mem());
|
||||
if (!bio)
|
||||
{
|
||||
t_print("BIO_new for local_public_key failed\n");
|
||||
PRINT("BIO_new for local_public_key failed\n");
|
||||
goto done;
|
||||
}
|
||||
|
||||
res = PEM_write_bio_PUBKEY(bio, pkey);
|
||||
if (!res)
|
||||
{
|
||||
t_print("PEM_write_bio_PUBKEY failed (%d)\n", res);
|
||||
PRINT("PEM_write_bio_PUBKEY failed (%d)\n", res);
|
||||
goto done;
|
||||
}
|
||||
|
||||
res = BIO_read(bio, local_public_key, RSA_3072_PUBLIC_KEY_SIZE);
|
||||
if (!res)
|
||||
{
|
||||
t_print("BIO_read public key failed (%d)\n", res);
|
||||
PRINT("BIO_read public key failed (%d)\n", res);
|
||||
goto done;
|
||||
}
|
||||
BIO_free(bio);
|
||||
@@ -215,7 +215,7 @@ sgx_status_t generate_key_pair(
|
||||
bio = BIO_new(BIO_s_mem());
|
||||
if (!bio)
|
||||
{
|
||||
t_print("BIO_new for local_public_key failed\n");
|
||||
PRINT("BIO_new for local_public_key failed\n");
|
||||
goto done;
|
||||
}
|
||||
|
||||
@@ -223,14 +223,14 @@ sgx_status_t generate_key_pair(
|
||||
bio, pkey, nullptr, nullptr, 0, nullptr, nullptr);
|
||||
if (!res)
|
||||
{
|
||||
t_print("PEM_write_bio_PrivateKey failed (%d)\n", res);
|
||||
PRINT("PEM_write_bio_PrivateKey failed (%d)\n", res);
|
||||
goto done;
|
||||
}
|
||||
|
||||
res = BIO_read(bio, local_private_key, RSA_3072_PRIVATE_KEY_SIZE);
|
||||
if (!res)
|
||||
{
|
||||
t_print("BIO_read private key failed (%d)\n", res);
|
||||
PRINT("BIO_read private key failed (%d)\n", res);
|
||||
goto done;
|
||||
}
|
||||
|
||||
@@ -243,7 +243,7 @@ sgx_status_t generate_key_pair(
|
||||
*public_key_size = strlen(reinterpret_cast<const char *>(local_public_key)) + 1;
|
||||
*private_key_size = strlen(reinterpret_cast<const char *>(local_private_key)) + 1;
|
||||
|
||||
t_print("public_key_size %d, private_key_size %d\n", *public_key_size, *private_key_size);
|
||||
PRINT("public_key_size %d, private_key_size %d\n", *public_key_size, *private_key_size);
|
||||
result = SGX_SUCCESS;
|
||||
|
||||
done:
|
||||
|
||||
@@ -47,10 +47,6 @@
|
||||
const unsigned char certificate_subject_name[] =
|
||||
"CN=Intel SGX Enclave, O=Intel Corporation,C=US";
|
||||
|
||||
void t_time(time_t *c_time);
|
||||
|
||||
void t_print(const char* fmt, ...);
|
||||
|
||||
sgx_status_t generate_key_pair(
|
||||
int type,
|
||||
uint8_t** public_key,
|
||||
|
||||
@@ -32,7 +32,7 @@
|
||||
include ../sgxenv.mk
|
||||
|
||||
Client_Include_Path := -I. -I$(SGX_SDK)/include -I/usr/include/openssl
|
||||
Client_Cpp_Flags := -DCLIENT_UNTRUSTED $(SGX_COMMON_CFLAGS) -fPIC -Wno-attributes $(Client_Include_Path)
|
||||
Client_Cpp_Flags := -DCLIENT_USE_QVL $(SGX_COMMON_CFLAGS) -fPIC -Wno-attributes $(Client_Include_Path)
|
||||
|
||||
ifeq ($(SGX_DEBUG), 1)
|
||||
Client_Cpp_Flags += -DDEBUG -UNDEBUG -UEDEBUG
|
||||
|
||||
@@ -35,9 +35,9 @@ project_dir="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
|
||||
echo "project_dir is $project_dir"
|
||||
sgxssl_dir=$project_dir/sgxssl
|
||||
openssl_out_dir=$sgxssl_dir/openssl_source
|
||||
openssl_ver_name=openssl-1.1.1m
|
||||
openssl_ver_name=openssl-1.1.1q
|
||||
sgxssl_github_archive=https://github.com/01org/intel-sgx-ssl/archive
|
||||
sgxssl_file_name=support_tls_lin_1.1.1m
|
||||
sgxssl_file_name=support_tls_lin_1.1.1q
|
||||
build_script=$sgxssl_dir/Linux/build_openssl.sh
|
||||
server_url_path=https://www.openssl.org/source
|
||||
full_openssl_url=$server_url_path/$openssl_ver_name.tar.gz
|
||||
@@ -56,8 +56,8 @@ if [ $debug == true ] ; then
|
||||
read -n 1 -p "download souce code only, because we need to build ourselves"
|
||||
fi
|
||||
|
||||
openssl_chksum=f89199be8b23ca45fc7cb9f1d8d3ee67312318286ad030f5316aca6462db6c96
|
||||
sgxssl_chksum=e645b5e9b0d81da4470d454b7f7d838cc310dd72427bd343bfe744c82493b39e
|
||||
openssl_chksum=d7939ce614029cdff0b6c20f0e2e5703158a489a72b2507b8bd51bf8c8fd10ca
|
||||
sgxssl_chksum=0ab6f62bda33e760422d502ba4812d058e50516ebb82e6c7713c78f580a7d622
|
||||
rm -f check_sum_openssl.txt check_sum_sgxssl.txt
|
||||
if [ ! -f $build_script ]; then
|
||||
wget $sgxssl_github_archive/$sgxssl_file_name.zip -P $sgxssl_dir/ || exit 1
|
||||
|
||||
@@ -34,6 +34,7 @@ include ../../sgxenv.mk
|
||||
INCDIR := $(SGX_SDK)/include
|
||||
ENC_TLS_SERVER_Name := tls_server_enclave.so
|
||||
Signed_ENC_TLS_SERVER_Name := tls_server_enclave.signed.so
|
||||
Enclave_Test_Key := private_test_key.pem
|
||||
|
||||
.PHONY: all build clean run
|
||||
|
||||
@@ -59,7 +60,12 @@ build:
|
||||
$(CXX) -o $(ENC_TLS_SERVER_Name) $(OBJ_FILES) $(Enclave_Link_Flags)
|
||||
|
||||
sign:
|
||||
$(SGX_ENCLAVE_SIGNER) sign -key private_test_key.pem -enclave $(ENC_TLS_SERVER_Name) \
|
||||
ifeq ($(wildcard $(Enclave_Test_Key)),)
|
||||
@echo "There is no enclave test key<Enclave_private_test.pem>."
|
||||
@echo "The project will generate a key<Enclave_private_test.pem> for test."
|
||||
@openssl genrsa -out $(Enclave_Test_Key) -3 3072
|
||||
endif
|
||||
$(SGX_ENCLAVE_SIGNER) sign -key $(Enclave_Test_Key) -enclave $(ENC_TLS_SERVER_Name) \
|
||||
-out $(Signed_ENC_TLS_SERVER_Name) -config server_enc.config.xml
|
||||
|
||||
clean:
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
-----BEGIN RSA PRIVATE KEY-----
|
||||
MIIG5AIBAAKCAYEA3G5Wa4v6OPqaboH5qO/g8Hg0NCkAIRAN3dCepNPjtjY/Uanr
|
||||
mMu99GZn/L/+SzMjawYhudUmtHkh3m3nHKJqp0HMVgXV0k1BK00fnlUHYP2bNr5R
|
||||
tV0LvpGH6Iy4b7t0/WRCZrxVdbJfaCnR8f7n9AJZ9xsnuuIiRL1dppH1lfijHuaj
|
||||
aH2VBbOrrzkhS3LQQloG278KO3Yy0VeVCbm7ljO06QXv+V2I4jExVRtiiWAPnb0x
|
||||
54b6AKkD+K4r+9LvYofZPVig+aQ9y54H3wJw3PWOlTOgkJPONIDhxkP+sTbaAlOD
|
||||
NSE3XtPdMkGIH3RxMSkg8NWEa9tYhNOIfNUAN/ECT1Qe6UhMS5MVH2bCru/TijbA
|
||||
IIWUwypWpt8UBs420RF8aJ69mivLsiEeJm3ODwa70h+1e2Da6Kgp6kpG9ZOm3wQ7
|
||||
WK9ywxiG1HR9Yd+wu8bBMfW1HBCjdpH2wQFOTsC5qy1FqIAU9a5r3tXn6CbMJnev
|
||||
Sg2NAwd5UTADBOVhAgEDAoIBgQCS9DmdB/wl/Gb0VqZwn+tK+s14G1VrYAk+ixRt
|
||||
4pfOztThG/Jl3SlNmZqof/7czMJHWWvROMR4UME+8+9obEcaK92Oro6MM4DHiL++
|
||||
41pAqRIkfuEjk10ptlqbCHr1J6NTmCxEfY5OdupFcTahVJqirDv6Ehp8lsGDKOkZ
|
||||
tqO5UGy/RGzwU7iud8fKJhYyTIrW5q89KgbSTsyLj7ixJn0OzSNGA/VQ6QXsIMuO
|
||||
EkGw6rUT03aaWfwAcK1QdB1SjJ5aOTLATtFPs3WKA40dBv4yNs7seywMqFq2rE1c
|
||||
TxgbittaId28nCqNWH0dgJrq75qnYc8BucrvOd36tQwAYjs0Sr03/8TkyiWkC8mf
|
||||
C0LT+aqD90bcF+S5hYr+grhBO9SzWYNWwvlWy2j3N6W/gCgmJbgEB+oke7NAR5Sd
|
||||
Vy8wHiJshGKQ8xDBBAzFikZ2+rqHcHsuNjxNcp0qDbMaNrC4AxEKkL1mw6znD61F
|
||||
IFQkKUdeAM5L+FnnyLU2qAw82qsCgcEA8lN0PU+sb5e2t1A92iswTyHcPktMmINM
|
||||
OtnvJcAV4FWf3pM9kUKFyeT3HeWZ/+jEyI+tDvoyNcg8mjzE8JmIfzaM/7NhsJ6k
|
||||
hACK7G6YW1yEt7kvbLY9h8B2MaH8BObVwJu0luSAaTnZU323t2yakiGmlLdgYPSl
|
||||
0zxWdUzNu0Tn/rBVPTkNzK0T8Lq935KXvHU/OECvQPrDZCVAPFBgng7qH40SIyp1
|
||||
hMKVbWTKb6GDmn0O2mgSsT0jTRl0mj0hAoHBAOjemN+SupJ/VsVIdllMw0KBe/Qv
|
||||
keUT+eekfpYNRKeQ8RyNeQj0ccDqKmgbBb8kRG2GvV9Eoc88TvKHMYuoHupKWXuh
|
||||
FeF6b1GA28RnRhWczwyKpmmrgCUhj/d5A6ANogNvgs+Vxy7A1OvP7c/A90OsgTdc
|
||||
deOyqDUAdIj6snIhiz2NUkIJy9TlX7tqVc/VATQoyTRjq2bp9FNYKd1e5JytNfvH
|
||||
F2swHBZUUonAn0JHXX75av2w83YdRjIafA9gQQKBwQChjPgo38hKZSR6NX6RciA0
|
||||
wT1+3N27AjLR5p9ugA6VjmqUYikLga6GmKS+mRFVRdiFtR4J/CF5MChm0y31u7BU
|
||||
zwiqd5Z1vxhYAFydnxA86Fh6e3TzJCkFKvl2a/1YmePVvSMPQwBGJpDiU8/Pnbxh
|
||||
a8RjJOrrTcPiKDmjiIkng0VUdY4o0LPdyLf10dPqYbp9o3961corUdeYGNV9iusU
|
||||
CfFqXgwXcaOt1w5I7dxKa60RqLSRmrcg02zeEPhm02sCgcEAmz8QlQx8Yao52Nr5
|
||||
kN3Xgaun+B+2mLf778L/DrODGmCgvbOmBfhL1fFxmryuf22C868o6i3BNNLfTFoh
|
||||
B8Vp8YbmUmtj66b04QCSgu+EDmiKCFxu8R0AGMEKpPtXwAkWrPUB37kvdICN8oqe
|
||||
ioCk18hWJOhOl8xwI1WjBfx29sEHfl421rEyje4/0kbj3+NWIsXbeEJyRJv4N5Ab
|
||||
6OntvcjOp9oPnMq9ZDg3BoBqLC+TqfucqSCiTr4uzBGoCkArAoHBANdEojnkFjyw
|
||||
cdoU54SQ0/JXLP38C2tibMg/kLEuAKIw6fWasEdf/SQ08Z0+mXomQDMhjBj98Tc8
|
||||
aEbkEqhwWLW2py3djDLPifSxMx+taog930SMubKquefyztX+jzajElCahwmt4XmK
|
||||
l8tZTFVQPWqdRmtUvFCrHRGi+Rw5FApSDQqHgFANXuSx8mSNQKiMWQIO65cYT/Vi
|
||||
490OqpNhUA5lXTxywdQmyg7RdCiV2xAYy+NE1EAIBYUdlNPG1WbAHA==
|
||||
-----END RSA PRIVATE KEY-----
|
||||
Reference in New Issue
Block a user