Merge "Fix Android Keystore key gen for keys requiring user auth." into mnc-dev
This commit is contained in:
@@ -624,7 +624,7 @@ public abstract class AndroidKeyStoreKeyPairGeneratorSpi extends KeyPairGenerato
|
|||||||
int keySizeBits,
|
int keySizeBits,
|
||||||
KeyGenParameterSpec spec) {
|
KeyGenParameterSpec spec) {
|
||||||
// Constraints:
|
// Constraints:
|
||||||
// 1. Key must be authorized for signing.
|
// 1. Key must be authorized for signing without user authentication.
|
||||||
// 2. Signature digest must be one of key's authorized digests.
|
// 2. Signature digest must be one of key's authorized digests.
|
||||||
// 3. For RSA keys, the digest output size must not exceed modulus size minus space needed
|
// 3. For RSA keys, the digest output size must not exceed modulus size minus space needed
|
||||||
// for RSA PKCS#1 signature padding (about 29 bytes: minimum 10 bytes of padding + 15--19
|
// for RSA PKCS#1 signature padding (about 29 bytes: minimum 10 bytes of padding + 15--19
|
||||||
@@ -636,6 +636,10 @@ public abstract class AndroidKeyStoreKeyPairGeneratorSpi extends KeyPairGenerato
|
|||||||
// Key not authorized for signing
|
// Key not authorized for signing
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
if (spec.isUserAuthenticationRequired()) {
|
||||||
|
// Key not authorized for use without user authentication
|
||||||
|
return null;
|
||||||
|
}
|
||||||
if (!spec.isDigestsSpecified()) {
|
if (!spec.isDigestsSpecified()) {
|
||||||
// Key not authorized for any digests -- can't sign
|
// Key not authorized for any digests -- can't sign
|
||||||
return null;
|
return null;
|
||||||
|
|||||||
Reference in New Issue
Block a user