This allows clients of the system service to handle specific errors
returned up the stack from rkpd.
Test: RemoteProvisioningServiceTests
Test: keystore2_test
Change-Id: I4b8399c0c8693533631c3a816e494bd1a2ab3239
The commontypos linter complained about the "the the" typo.
No change to source code.
Per go/fix-refdocs, master is now the preferred branch for doc fixes until the U dev branch is open. Since this CL hasn't been reviewed yet, I'm CPing it over here and abandoning the original CL.
Bug: 263824202
Change-Id: If03bfc1f3e1a42b26019c039595c7bf8c0010ad4
Test: [go/abtd docs build]
This requires a minor interface update to return an async result,
since failing open means we might leave keys vulnerable to system
software rollback attacks.
Bug: 262748535
Test: RemoteProvisioningRegistrationTest
Change-Id: If2b28dae285631b70d93910a8cc2196f808cb5be
This cl contains changes for SystemCertificateSource so that certificates are taken from conscrypt apex files by default and if that fails, we fallback to the usual system location.
Test: atest TrustedCertificateStoreTest
Change-Id: I1ec6d29a52c07531a6a0c85b2e2405f63470bd5f
This service is callable by system components like keystore2. This
service calls into a mainline module API to do all the work for remote
provisioning.
Also include new OWNERS for the RemoteProvisioning implementation.
Bug: 254112668
Test: Locally modify keystore to call the new service
Change-Id: I6708d0b415798c78a4d66f279589d9def552ae78
To support attestation of a second IMEI, when ID attestation (with IMEI)
is requested, pass in the 2nd IMEI as a SECOND_IMEI KeyMint tag.
Bug: 244732345
Test: atest android.keystore.cts.DeviceOwnerKeyManagementTest
Change-Id: I19a3733746fa6a35c6225f0c60fd9f4b51a62ab1
This commit is part of a large scale change to fix errorprone
errors that have been downgraded to warnings in the android
source tree, so that they can be promoted to errors again.
The full list of changes include the following, but not all
will be present in any one individual commit:
BadAnnotationImplementation
BadShiftAmount
BanJNDI
BoxedPrimitiveEquality
ComparableType
ComplexBooleanConstant
CollectionToArraySafeParameter
ConditionalExpressionNumericPromotion
DangerousLiteralNull
DoubleBraceInitialization
DurationFrom
DurationTemporalUnit
EmptyTopLevelDeclaration
EqualsNull
EqualsReference
FormatString
FromTemporalAccessor
GetClassOnAnnotation
GetClassOnClass
HashtableContains
IdentityBinaryExpression
IdentityHashMapBoxing
InstantTemporalUnit
InvalidTimeZoneID
InvalidZoneId
IsInstanceIncompatibleType
JUnitParameterMethodNotFound
LockOnBoxedPrimitive
MathRoundIntLong
MislabeledAndroidString
MisusedDayOfYear
MissingSuperCall
MisusedWeekYear
ModifyingCollectionWithItself
NoCanIgnoreReturnValueOnClasses
NonRuntimeAnnotation
NullableOnContainingClass
NullTernary
OverridesJavaxInjectableMethod
ParcelableCreator
PeriodFrom
PreconditionsInvalidPlaceholder
ProtoBuilderReturnValueIgnored
ProtoFieldNullComparison
RandomModInteger
RectIntersectReturnValueIgnored
ReturnValueIgnored
SelfAssignment
SelfComparison
SelfEquals
SizeGreaterThanOrEqualsZero
StringBuilderInitWithChar
TreeToString
TryFailThrowable
UnnecessaryCheckNotNull
UnusedCollectionModifiedInPlace
XorPower
See https://errorprone.info/bugpatterns for more
information on the checks.
Bug: 253827323
Test: m RUN_ERROR_PRONE=true javac-check
Change-Id: I8446f9076a45ebf7e7ffa06cb0d4ddb1001b6c00
If EC curves of Public and Private keys are different, an
InvalidKeyException is expected.
But the current implementation does not throw exception from doPhase method
and fails in generateSecret method.
The fix is in AndroidKeyStoreECPublicKey to provide
correct ECParameterSpec while creating a PrivateKey object.
Bug: 215175472
Test: run cts -m CtsKeystoreWycheproofTestCases -t com.google.security.wycheproof.JsonEcdhTest#testSecp224r1
Test: run cts -m CtsKeystoreWycheproofTestCases -t com.google.security.wycheproof.JsonEcdhTest#testSecp256r1
Test: run cts -m CtsKeystoreWycheproofTestCases -t com.google.security.wycheproof.JsonEcdhTest#testSecp384r1
Test: run cts -m CtsKeystoreWycheproofTestCases -t com.google.security.wycheproof.JsonEcdhTest#testSecp521r1
Test: run cts -m CtsKeystoreTestCases -t android.keystore.cts.KeyAgreementTest#testDoPhase_withDifferentCurveKey_fails
Change-Id: Ie221926d8a3be3fe6679e723575c5021cafba98e
Included KM_TAG_RSA_OAEP_MGF_DIGEST for RSA keys generation and import
if supported padding is defined as OAEP. All supported digest are added
as KM_TAG_RSA_OAEP_MGF_DIGEST and also default MGF1-SHA1 digest is added
because crypto operations could fail is MGF1ParameterSpec is not provided.
Note this includes additional Attestation parameter in returned
certificate and need to handle accordingly.
Bug: 203688354
Test: run cts -m CtsKeystoreTestCases -t android.keystore.cts.CipherTest#testKatBasicWithDifferentProviders
Change-Id: I2086f2520667ccac9116e04de39f6328a0d3fc5b
Since Janis has left, it makes no sense to have him on the OWNERS file.
Add myself as a reviewer in an EMEA-friendly timezone.
Test: N/A, owners change only.
BYPASS_INCLUSIVE_LANGUAGE_REASON=Janis used a he/him pronoun.
Change-Id: Ieab9ab74c1d11013ffa915999bf37773659cdad0
During migration to KeyStore2 exception was converted to
InternalRecoveryServiceException.
Test: manual
Bug: 207316987
Change-Id: I90a4c6745f2e3c1446c4c0fbac64035d582bb5a8
The metadata field is written unconditionally and will be represented at
least by a -1 if it is null.
Bug: 210655898
Test: N/A
Change-Id: Iad85dbec916a2d51523b81b594b66b9518811d27
Add helper @hide methods for converting @LocalBindingType and
@VerificationResult integer values to String - localBindingTypeToString
and verificationResultCodeToString
Test: m && flash
Change-Id: I5b2bb3872e231b76b54ec8c3fad120cfac653306
Report KeyStore/KeyMint error messages via public API.
This lets developers find out:
* Whether an error is transient or not.
* Whether a failure is due to a system error
(system configuration/state/capabilities), or a key-related error.
* Whether user authentication is required to use the key.
Test: atest CtsKeystorePerformanceTestCases CtsKeystoreTestCases
Bug: 197890905
Merged-In: I776d9e9cc01a9dc3542a63000ee0709847760963
Change-Id: Ica0c93fdd4b89255ee0a03a9b9b948202777d4d4
Report KeyStore/KeyMint error messages via public API.
This lets developers find out:
* Whether an error is transient or not.
* Whether a failure is due to a system error
(system configuration/state/capabilities), or a key-related error.
* Whether user authentication is required to use the key.
Test: atest CtsKeystorePerformanceTestCases CtsKeystoreTestCases
Bug: 197890905
Change-Id: I776d9e9cc01a9dc3542a63000ee0709847760963
This allows apps to request that AndroidKeyStore generate attestation
keys that can be used to sign attestations of other keys that the app
generates or imports.
Bug: 163606833
Test: atest CtsKeystoreTests
Change-Id: I943a6922271cbe909cb3a9d67021663b5646aa70