u-boot/lib/efi_loader
Ilias Apalodimas b436cc6a57 efi_loader: add sha384/512 on certificate revocation
Currently we don't support sha384/512 for the X.509 certificate
in dbx.  Moreover if we come across such a hash we skip the check
and approve the image,  although the image might needs to be rejected.

Rework the code a bit and fix it by adding an array of structs with the
supported GUIDs, len and literal used in the U-Boot crypto APIs instead
of hardcoding the GUID types.

It's worth noting here that efi_hash_regions() can now be reused from
efi_signature_lookup_digest() and add sha348/512 support there as well

Signed-off-by: Ilias Apalodimas <ilias.apalodimas@linaro.org>
2022-05-07 23:17:26 +02:00
..
2022-01-19 18:11:34 +01:00
2022-02-03 12:16:01 -05:00
2022-02-03 12:16:01 -05:00
2022-02-03 12:16:01 -05:00
2022-02-03 12:16:01 -05:00
2022-05-07 23:17:26 +02:00