You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Would be nice if cryptoki could support this as well!
The intended use of the C_DeriveKey function with this mechanism is so different from a "normal" call that I am wondering if we should really modify the generic wrapper function in a big way to allow that... Specifically, as you said, since we would also need to return some kind of Option<ObjectHandle> (to make it safe) and also indicate that the phKey parameter should be NULL!
The hard part is that this is also a vendor defined mechanism so we can't really make a special case just for this one.
To make this cleaner, maybe we should add a new derive_key variant (under a new feature maybe?) that would have the presets you wrote: NULLpTemplate and phKey and not returning anything.
What do you think?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Some calls to Thales Luna HSMs allows the following call of
C_DeriveKey:One example is when trying to do bip32 derivation using
CKM_BIP32_CHILD_DERIVECK_BIP32_CHILD_DERIVE_PARAMS. The call works as follows:pTemplateandphKeyare null pointersCK_BIP32_CHILD_DERIVE_PARAMS.hPublicKeyandCK_BIP32_CHILD_DERIVE_PARAMS.hPrivateKeyAt the moment this is not expressable by the
cryptokicrate so I was thinking it would be nice to allow it.I tested this against a Thales Luna Network HSM
If there is interest in this, I can work on making the tests pass as well, which is trivial
Downsides
derive_key0as value so the return type should be changed as well to better reflect user's intention