config_adjust_psa_from_legacy.h 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359
  1. /**
  2. * \file mbedtls/config_adjust_psa_from_legacy.h
  3. * \brief Adjust PSA configuration: construct PSA configuration from legacy
  4. *
  5. * This is an internal header. Do not include it directly.
  6. *
  7. * When MBEDTLS_PSA_CRYPTO_CONFIG is disabled, we automatically enable
  8. * cryptographic mechanisms through the PSA interface when the corresponding
  9. * legacy mechanism is enabled. In many cases, this just enables the PSA
  10. * wrapper code around the legacy implementation, but we also do this for
  11. * some mechanisms where PSA has its own independent implementation so
  12. * that high-level modules that can use either cryptographic API have the
  13. * same feature set in both cases.
  14. */
  15. /*
  16. * Copyright The Mbed TLS Contributors
  17. * SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
  18. */
  19. #ifndef MBEDTLS_CONFIG_ADJUST_PSA_FROM_LEGACY_H
  20. #define MBEDTLS_CONFIG_ADJUST_PSA_FROM_LEGACY_H
  21. #if !defined(MBEDTLS_CONFIG_FILES_READ)
  22. #error "Do not include mbedtls/config_adjust_*.h manually! This can lead to problems, " \
  23. "up to and including runtime errors such as buffer overflows. " \
  24. "If you're trying to fix a complaint from check_config.h, just remove " \
  25. "it from your configuration file: since Mbed TLS 3.0, it is included " \
  26. "automatically at the right point."
  27. #endif /* */
  28. /*
  29. * Ensure PSA_WANT_* defines are setup properly if MBEDTLS_PSA_CRYPTO_CONFIG
  30. * is not defined
  31. */
  32. #if defined(MBEDTLS_CCM_C)
  33. #define MBEDTLS_PSA_BUILTIN_ALG_CCM 1
  34. #define PSA_WANT_ALG_CCM 1
  35. #if defined(MBEDTLS_CIPHER_C)
  36. #define MBEDTLS_PSA_BUILTIN_ALG_CCM_STAR_NO_TAG 1
  37. #define PSA_WANT_ALG_CCM_STAR_NO_TAG 1
  38. #endif /* MBEDTLS_CIPHER_C */
  39. #endif /* MBEDTLS_CCM_C */
  40. #if defined(MBEDTLS_CMAC_C)
  41. #define MBEDTLS_PSA_BUILTIN_ALG_CMAC 1
  42. #define PSA_WANT_ALG_CMAC 1
  43. #endif /* MBEDTLS_CMAC_C */
  44. #if defined(MBEDTLS_ECDH_C)
  45. #define MBEDTLS_PSA_BUILTIN_ALG_ECDH 1
  46. #define PSA_WANT_ALG_ECDH 1
  47. #endif /* MBEDTLS_ECDH_C */
  48. #if defined(MBEDTLS_ECDSA_C)
  49. #define MBEDTLS_PSA_BUILTIN_ALG_ECDSA 1
  50. #define PSA_WANT_ALG_ECDSA 1
  51. #define PSA_WANT_ALG_ECDSA_ANY 1
  52. // Only add in DETERMINISTIC support if ECDSA is also enabled
  53. #if defined(MBEDTLS_ECDSA_DETERMINISTIC)
  54. #define MBEDTLS_PSA_BUILTIN_ALG_DETERMINISTIC_ECDSA 1
  55. #define PSA_WANT_ALG_DETERMINISTIC_ECDSA 1
  56. #endif /* MBEDTLS_ECDSA_DETERMINISTIC */
  57. #endif /* MBEDTLS_ECDSA_C */
  58. #if defined(MBEDTLS_ECP_C)
  59. #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_BASIC 1
  60. #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_IMPORT 1
  61. #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_EXPORT 1
  62. #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_GENERATE 1
  63. /* Normally we wouldn't enable this because it's not implemented in ecp.c,
  64. * but since it used to be available any time ECP_C was enabled, let's enable
  65. * it anyway for the sake of backwards compatibility */
  66. #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE 1
  67. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_BASIC 1
  68. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_IMPORT 1
  69. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_EXPORT 1
  70. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_GENERATE 1
  71. /* See comment for PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE above. */
  72. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_KEY_PAIR_DERIVE 1
  73. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_ECC_PUBLIC_KEY 1
  74. #define PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY 1
  75. #endif /* MBEDTLS_ECP_C */
  76. #if defined(MBEDTLS_DHM_C)
  77. #define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_BASIC 1
  78. #define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_IMPORT 1
  79. #define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_EXPORT 1
  80. #define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_GENERATE 1
  81. #define PSA_WANT_KEY_TYPE_DH_PUBLIC_KEY 1
  82. #define PSA_WANT_ALG_FFDH 1
  83. #define PSA_WANT_DH_RFC7919_2048 1
  84. #define PSA_WANT_DH_RFC7919_3072 1
  85. #define PSA_WANT_DH_RFC7919_4096 1
  86. #define PSA_WANT_DH_RFC7919_6144 1
  87. #define PSA_WANT_DH_RFC7919_8192 1
  88. #define MBEDTLS_PSA_BUILTIN_ALG_FFDH 1
  89. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_BASIC 1
  90. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_IMPORT 1
  91. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_EXPORT 1
  92. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_KEY_PAIR_GENERATE 1
  93. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_DH_PUBLIC_KEY 1
  94. #define MBEDTLS_PSA_BUILTIN_DH_RFC7919_2048 1
  95. #define MBEDTLS_PSA_BUILTIN_DH_RFC7919_3072 1
  96. #define MBEDTLS_PSA_BUILTIN_DH_RFC7919_4096 1
  97. #define MBEDTLS_PSA_BUILTIN_DH_RFC7919_6144 1
  98. #define MBEDTLS_PSA_BUILTIN_DH_RFC7919_8192 1
  99. #endif /* MBEDTLS_DHM_C */
  100. #if defined(MBEDTLS_GCM_C)
  101. #define MBEDTLS_PSA_BUILTIN_ALG_GCM 1
  102. #define PSA_WANT_ALG_GCM 1
  103. #endif /* MBEDTLS_GCM_C */
  104. /* Enable PSA HKDF algorithm if mbedtls HKDF is supported.
  105. * PSA HKDF EXTRACT and PSA HKDF EXPAND have minimal cost when
  106. * PSA HKDF is enabled, so enable both algorithms together
  107. * with PSA HKDF. */
  108. #if defined(MBEDTLS_HKDF_C)
  109. #define MBEDTLS_PSA_BUILTIN_ALG_HMAC 1
  110. #define PSA_WANT_ALG_HMAC 1
  111. #define MBEDTLS_PSA_BUILTIN_ALG_HKDF 1
  112. #define PSA_WANT_ALG_HKDF 1
  113. #define MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXTRACT 1
  114. #define PSA_WANT_ALG_HKDF_EXTRACT 1
  115. #define MBEDTLS_PSA_BUILTIN_ALG_HKDF_EXPAND 1
  116. #define PSA_WANT_ALG_HKDF_EXPAND 1
  117. #endif /* MBEDTLS_HKDF_C */
  118. #define MBEDTLS_PSA_BUILTIN_ALG_HMAC 1
  119. #define PSA_WANT_ALG_HMAC 1
  120. #define PSA_WANT_KEY_TYPE_HMAC 1
  121. #if defined(MBEDTLS_MD_C)
  122. #define MBEDTLS_PSA_BUILTIN_ALG_TLS12_PRF 1
  123. #define PSA_WANT_ALG_TLS12_PRF 1
  124. #define MBEDTLS_PSA_BUILTIN_ALG_TLS12_PSK_TO_MS 1
  125. #define PSA_WANT_ALG_TLS12_PSK_TO_MS 1
  126. #endif /* MBEDTLS_MD_C */
  127. #if defined(MBEDTLS_MD5_C)
  128. #define MBEDTLS_PSA_BUILTIN_ALG_MD5 1
  129. #define PSA_WANT_ALG_MD5 1
  130. #endif
  131. #if defined(MBEDTLS_ECJPAKE_C)
  132. #define MBEDTLS_PSA_BUILTIN_PAKE 1
  133. #define MBEDTLS_PSA_BUILTIN_ALG_JPAKE 1
  134. #define PSA_WANT_ALG_JPAKE 1
  135. #endif
  136. #if defined(MBEDTLS_RIPEMD160_C)
  137. #define MBEDTLS_PSA_BUILTIN_ALG_RIPEMD160 1
  138. #define PSA_WANT_ALG_RIPEMD160 1
  139. #endif
  140. #if defined(MBEDTLS_RSA_C)
  141. #if defined(MBEDTLS_PKCS1_V15)
  142. #define MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_CRYPT 1
  143. #define PSA_WANT_ALG_RSA_PKCS1V15_CRYPT 1
  144. #define MBEDTLS_PSA_BUILTIN_ALG_RSA_PKCS1V15_SIGN 1
  145. #define PSA_WANT_ALG_RSA_PKCS1V15_SIGN 1
  146. #define PSA_WANT_ALG_RSA_PKCS1V15_SIGN_RAW 1
  147. #endif /* MBEDTLS_PKCS1_V15 */
  148. #if defined(MBEDTLS_PKCS1_V21)
  149. #define MBEDTLS_PSA_BUILTIN_ALG_RSA_OAEP 1
  150. #define PSA_WANT_ALG_RSA_OAEP 1
  151. #define MBEDTLS_PSA_BUILTIN_ALG_RSA_PSS 1
  152. #define PSA_WANT_ALG_RSA_PSS 1
  153. #endif /* MBEDTLS_PKCS1_V21 */
  154. #if defined(MBEDTLS_GENPRIME)
  155. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_GENERATE 1
  156. #define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE 1
  157. #endif /* MBEDTLS_GENPRIME */
  158. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_BASIC 1
  159. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_IMPORT 1
  160. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_KEY_PAIR_EXPORT 1
  161. #define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC 1
  162. #define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT 1
  163. #define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT 1
  164. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_RSA_PUBLIC_KEY 1
  165. #define PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY 1
  166. #endif /* MBEDTLS_RSA_C */
  167. #if defined(MBEDTLS_SHA1_C)
  168. #define MBEDTLS_PSA_BUILTIN_ALG_SHA_1 1
  169. #define PSA_WANT_ALG_SHA_1 1
  170. #endif
  171. #if defined(MBEDTLS_SHA224_C)
  172. #define MBEDTLS_PSA_BUILTIN_ALG_SHA_224 1
  173. #define PSA_WANT_ALG_SHA_224 1
  174. #endif
  175. #if defined(MBEDTLS_SHA256_C)
  176. #define MBEDTLS_PSA_BUILTIN_ALG_SHA_256 1
  177. #define PSA_WANT_ALG_SHA_256 1
  178. #endif
  179. #if defined(MBEDTLS_SHA384_C)
  180. #define MBEDTLS_PSA_BUILTIN_ALG_SHA_384 1
  181. #define PSA_WANT_ALG_SHA_384 1
  182. #endif
  183. #if defined(MBEDTLS_SHA512_C)
  184. #define MBEDTLS_PSA_BUILTIN_ALG_SHA_512 1
  185. #define PSA_WANT_ALG_SHA_512 1
  186. #endif
  187. #if defined(MBEDTLS_SHA3_C)
  188. #define MBEDTLS_PSA_BUILTIN_ALG_SHA3_224 1
  189. #define MBEDTLS_PSA_BUILTIN_ALG_SHA3_256 1
  190. #define MBEDTLS_PSA_BUILTIN_ALG_SHA3_384 1
  191. #define MBEDTLS_PSA_BUILTIN_ALG_SHA3_512 1
  192. #define PSA_WANT_ALG_SHA3_224 1
  193. #define PSA_WANT_ALG_SHA3_256 1
  194. #define PSA_WANT_ALG_SHA3_384 1
  195. #define PSA_WANT_ALG_SHA3_512 1
  196. #endif
  197. #if defined(MBEDTLS_AES_C)
  198. #define PSA_WANT_KEY_TYPE_AES 1
  199. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_AES 1
  200. #endif
  201. #if defined(MBEDTLS_ARIA_C)
  202. #define PSA_WANT_KEY_TYPE_ARIA 1
  203. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_ARIA 1
  204. #endif
  205. #if defined(MBEDTLS_CAMELLIA_C)
  206. #define PSA_WANT_KEY_TYPE_CAMELLIA 1
  207. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_CAMELLIA 1
  208. #endif
  209. #if defined(MBEDTLS_DES_C)
  210. #define PSA_WANT_KEY_TYPE_DES 1
  211. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_DES 1
  212. #endif
  213. #if defined(MBEDTLS_PSA_BUILTIN_ALG_SHA_256)
  214. #define MBEDTLS_PSA_BUILTIN_ALG_TLS12_ECJPAKE_TO_PMS 1
  215. #define PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS 1
  216. #endif
  217. #if defined(MBEDTLS_CHACHA20_C)
  218. #define PSA_WANT_KEY_TYPE_CHACHA20 1
  219. #define MBEDTLS_PSA_BUILTIN_KEY_TYPE_CHACHA20 1
  220. /* ALG_STREAM_CIPHER requires CIPHER_C in order to be supported in PSA */
  221. #if defined(MBEDTLS_CIPHER_C)
  222. #define PSA_WANT_ALG_STREAM_CIPHER 1
  223. #define MBEDTLS_PSA_BUILTIN_ALG_STREAM_CIPHER 1
  224. #endif
  225. #if defined(MBEDTLS_CHACHAPOLY_C)
  226. #define PSA_WANT_ALG_CHACHA20_POLY1305 1
  227. #define MBEDTLS_PSA_BUILTIN_ALG_CHACHA20_POLY1305 1
  228. #endif
  229. #endif
  230. #if defined(MBEDTLS_CIPHER_MODE_CBC)
  231. #define MBEDTLS_PSA_BUILTIN_ALG_CBC_NO_PADDING 1
  232. #define PSA_WANT_ALG_CBC_NO_PADDING 1
  233. #if defined(MBEDTLS_CIPHER_PADDING_PKCS7)
  234. #define MBEDTLS_PSA_BUILTIN_ALG_CBC_PKCS7 1
  235. #define PSA_WANT_ALG_CBC_PKCS7 1
  236. #endif
  237. #endif
  238. #if (defined(MBEDTLS_AES_C) || defined(MBEDTLS_DES_C) || \
  239. defined(MBEDTLS_ARIA_C) || defined(MBEDTLS_CAMELLIA_C)) && \
  240. defined(MBEDTLS_CIPHER_C)
  241. #define MBEDTLS_PSA_BUILTIN_ALG_ECB_NO_PADDING 1
  242. #define PSA_WANT_ALG_ECB_NO_PADDING 1
  243. #endif
  244. #if defined(MBEDTLS_CIPHER_MODE_CFB)
  245. #define MBEDTLS_PSA_BUILTIN_ALG_CFB 1
  246. #define PSA_WANT_ALG_CFB 1
  247. #endif
  248. #if defined(MBEDTLS_CIPHER_MODE_CTR)
  249. #define MBEDTLS_PSA_BUILTIN_ALG_CTR 1
  250. #define PSA_WANT_ALG_CTR 1
  251. #endif
  252. #if defined(MBEDTLS_CIPHER_MODE_OFB)
  253. #define MBEDTLS_PSA_BUILTIN_ALG_OFB 1
  254. #define PSA_WANT_ALG_OFB 1
  255. #endif
  256. #if defined(MBEDTLS_ECP_DP_BP256R1_ENABLED)
  257. #define MBEDTLS_PSA_BUILTIN_ECC_BRAINPOOL_P_R1_256 1
  258. #define PSA_WANT_ECC_BRAINPOOL_P_R1_256 1
  259. #endif
  260. #if defined(MBEDTLS_ECP_DP_BP384R1_ENABLED)
  261. #define MBEDTLS_PSA_BUILTIN_ECC_BRAINPOOL_P_R1_384 1
  262. #define PSA_WANT_ECC_BRAINPOOL_P_R1_384 1
  263. #endif
  264. #if defined(MBEDTLS_ECP_DP_BP512R1_ENABLED)
  265. #define MBEDTLS_PSA_BUILTIN_ECC_BRAINPOOL_P_R1_512 1
  266. #define PSA_WANT_ECC_BRAINPOOL_P_R1_512 1
  267. #endif
  268. #if defined(MBEDTLS_ECP_DP_CURVE25519_ENABLED)
  269. #define MBEDTLS_PSA_BUILTIN_ECC_MONTGOMERY_255 1
  270. #define PSA_WANT_ECC_MONTGOMERY_255 1
  271. #endif
  272. #if defined(MBEDTLS_ECP_DP_CURVE448_ENABLED)
  273. #define MBEDTLS_PSA_BUILTIN_ECC_MONTGOMERY_448 1
  274. #define PSA_WANT_ECC_MONTGOMERY_448 1
  275. #endif
  276. #if defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED)
  277. #define MBEDTLS_PSA_BUILTIN_ECC_SECP_R1_192 1
  278. #define PSA_WANT_ECC_SECP_R1_192 1
  279. #endif
  280. #if defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED)
  281. #define MBEDTLS_PSA_BUILTIN_ECC_SECP_R1_224 1
  282. #define PSA_WANT_ECC_SECP_R1_224 1
  283. #endif
  284. #if defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED)
  285. #define MBEDTLS_PSA_BUILTIN_ECC_SECP_R1_256 1
  286. #define PSA_WANT_ECC_SECP_R1_256 1
  287. #endif
  288. #if defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED)
  289. #define MBEDTLS_PSA_BUILTIN_ECC_SECP_R1_384 1
  290. #define PSA_WANT_ECC_SECP_R1_384 1
  291. #endif
  292. #if defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED)
  293. #define MBEDTLS_PSA_BUILTIN_ECC_SECP_R1_521 1
  294. #define PSA_WANT_ECC_SECP_R1_521 1
  295. #endif
  296. #if defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED)
  297. #define MBEDTLS_PSA_BUILTIN_ECC_SECP_K1_192 1
  298. #define PSA_WANT_ECC_SECP_K1_192 1
  299. #endif
  300. /* SECP224K1 is buggy via the PSA API (https://github.com/Mbed-TLS/mbedtls/issues/3541) */
  301. #if 0 && defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED)
  302. #define MBEDTLS_PSA_BUILTIN_ECC_SECP_K1_224 1
  303. #define PSA_WANT_ECC_SECP_K1_224 1
  304. #endif
  305. #if defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED)
  306. #define MBEDTLS_PSA_BUILTIN_ECC_SECP_K1_256 1
  307. #define PSA_WANT_ECC_SECP_K1_256 1
  308. #endif
  309. #endif /* MBEDTLS_CONFIG_ADJUST_PSA_FROM_LEGACY_H */