mbedtls_common.mk 3.26 KB
Newer Older
1
#
2
# Copyright (c) 2015-2020, ARM Limited and Contributors. All rights reserved.
3
#
dp-arm's avatar
dp-arm committed
4
# SPDX-License-Identifier: BSD-3-Clause
5
6
7
8
9
#

ifneq (${MBEDTLS_COMMON_MK},1)
MBEDTLS_COMMON_MK	:=	1

Juan Castillo's avatar
Juan Castillo committed
10
# MBEDTLS_DIR must be set to the mbed TLS main directory (it must contain
11
12
13
14
15
# the 'include' and 'library' subdirectories).
ifeq (${MBEDTLS_DIR},)
  $(error Error: MBEDTLS_DIR not set)
endif

16
MBEDTLS_INC		=	-I${MBEDTLS_DIR}/include
17

Juan Castillo's avatar
Juan Castillo committed
18
# Specify mbed TLS configuration file
19
MBEDTLS_CONFIG_FILE	:=	"<drivers/auth/mbedtls/mbedtls_config.h>"
Juan Castillo's avatar
Juan Castillo committed
20
$(eval $(call add_define,MBEDTLS_CONFIG_FILE))
21

22
23
24
25
MBEDTLS_SOURCES	+=		drivers/auth/mbedtls/mbedtls_common.c


LIBMBEDTLS_SRCS		:= $(addprefix ${MBEDTLS_DIR}/library/,	\
26
					aes.c 					\
27
28
					asn1parse.c 				\
					asn1write.c 				\
29
30
					cipher.c 				\
					cipher_wrap.c 				\
31
32
33
34
35
					memory_buffer_alloc.c			\
					oid.c 					\
					platform.c 				\
					platform_util.c				\
					bignum.c				\
36
					gcm.c 					\
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
					md.c					\
					md_wrap.c				\
					pk.c 					\
					pk_wrap.c 				\
					pkparse.c 				\
					pkwrite.c 				\
					sha256.c            			\
					sha512.c            			\
					ecdsa.c					\
					ecp_curves.c				\
					ecp.c					\
					rsa.c					\
					rsa_internal.c				\
					x509.c 					\
					x509_crt.c 				\
					)

# The platform may define the variable 'TF_MBEDTLS_KEY_ALG' to select the key
55
56
57
# algorithm to use. If the variable is not defined, select it based on
# algorithm used for key generation `KEY_ALG`. If `KEY_ALG` is not defined,
# then it is set to `rsa`.
58
59
60
61
62
63
64
65
ifeq (${TF_MBEDTLS_KEY_ALG},)
    ifeq (${KEY_ALG}, ecdsa)
        TF_MBEDTLS_KEY_ALG		:=	ecdsa
    else
        TF_MBEDTLS_KEY_ALG		:=	rsa
    endif
endif

66
67
68
69
70
71
72
73
74
75
ifeq (${TF_MBEDTLS_KEY_SIZE},)
    ifneq ($(findstring rsa,${TF_MBEDTLS_KEY_ALG}),)
	ifeq (${KEY_SIZE},)
            TF_MBEDTLS_KEY_SIZE		:=	2048
	else
            TF_MBEDTLS_KEY_SIZE		:=	${KEY_SIZE}
	endif
    endif
endif

76
77
ifeq (${HASH_ALG}, sha384)
    TF_MBEDTLS_HASH_ALG_ID	:=	TF_MBEDTLS_SHA384
78
79
80
    MBEDTLS_MD_ID		:=	MBEDTLS_MD_SHA384
    TPM_ALG_ID			:=	TPM_ALG_SHA384
    TCG_DIGEST_SIZE		:=	48
81
else ifeq (${HASH_ALG}, sha512)
82
83
84
85
    TF_MBEDTLS_HASH_ALG_ID	:=	TF_MBEDTLS_SHA512
    MBEDTLS_MD_ID		:=	MBEDTLS_MD_SHA512
    TPM_ALG_ID			:=	TPM_ALG_SHA512
    TCG_DIGEST_SIZE		:=	64
86
87
else
    TF_MBEDTLS_HASH_ALG_ID	:=	TF_MBEDTLS_SHA256
88
89
90
    MBEDTLS_MD_ID		:=	MBEDTLS_MD_SHA256
    TPM_ALG_ID			:=	TPM_ALG_SHA256
    TCG_DIGEST_SIZE		:=	32
91
92
93
94
95
96
97
98
99
100
101
102
endif

ifeq (${TF_MBEDTLS_KEY_ALG},ecdsa)
    TF_MBEDTLS_KEY_ALG_ID	:=	TF_MBEDTLS_ECDSA
else ifeq (${TF_MBEDTLS_KEY_ALG},rsa)
    TF_MBEDTLS_KEY_ALG_ID	:=	TF_MBEDTLS_RSA
else ifeq (${TF_MBEDTLS_KEY_ALG},rsa+ecdsa)
    TF_MBEDTLS_KEY_ALG_ID	:=	TF_MBEDTLS_RSA_AND_ECDSA
else
    $(error "TF_MBEDTLS_KEY_ALG=${TF_MBEDTLS_KEY_ALG} not supported on mbed TLS")
endif

103
104
105
106
107
108
ifeq (${DECRYPTION_SUPPORT}, aes_gcm)
    TF_MBEDTLS_USE_AES_GCM	:=	1
else
    TF_MBEDTLS_USE_AES_GCM	:=	0
endif

109
110
# Needs to be set to drive mbed TLS configuration correctly
$(eval $(call add_define,TF_MBEDTLS_KEY_ALG_ID))
111
$(eval $(call add_define,TF_MBEDTLS_KEY_SIZE))
112
$(eval $(call add_define,TF_MBEDTLS_HASH_ALG_ID))
113
$(eval $(call add_define,TF_MBEDTLS_USE_AES_GCM))
114

115
116
117
118
119
# Set definitions for measured boot driver
$(eval $(call add_define,MBEDTLS_MD_ID))
$(eval $(call add_define,TPM_ALG_ID))
$(eval $(call add_define,TCG_DIGEST_SIZE))

120
$(eval $(call MAKE_LIB,mbedtls))
121
122

endif