fix(pki): root RSA forge on EC-only keybox
The forge keybox selector matched the requested algorithm exactly and threw -75 ATTESTATION_KEYS_NOT_PROVISIONED on a miss, while the patch path already falls back to any usable key (EC preferred). An RSA ATTEST_KEY request on an EC-only keybox therefore never rooted: the caller's attest-key chain could not reach the Google root and verifiers reported "unknown certificate". Fall back to getAnyAttestationKey when no algorithm-matching keybox exists. An EC attestation key validly ECDSA-signs an RSA-subject leaf, so the EC keybox roots the RSA forge. No-op when the keybox is dual.
This commit is contained in:
@@ -184,10 +184,18 @@ object CertificateGenerator {
|
|||||||
Algorithm.RSA -> "RSA"
|
Algorithm.RSA -> "RSA"
|
||||||
else -> throw IllegalArgumentException("Unsupported algorithm ID: $algorithm")
|
else -> throw IllegalArgumentException("Unsupported algorithm ID: $algorithm")
|
||||||
}
|
}
|
||||||
|
// Prefer the algorithm-matching keybox, but fall back to any usable key (EC preferred) when
|
||||||
|
// none exists. An EC attestation key validly ECDSA-signs a leaf carrying an RSA subject key,
|
||||||
|
// so an EC-only keybox can still root an RSA forge. Without this fallback an RSA ATTEST_KEY
|
||||||
|
// request on an EC-only keybox throws -75 and the caller's chain never roots ("unknown
|
||||||
|
// certificate"). Mirrors the patch path's fail-safe
|
||||||
|
// (AttestationPatcher.getKeyboxForUidAndAlgorithm) and the RSA-leaf-under-EC-keybox handling
|
||||||
|
// in commit e6d5e4d.
|
||||||
return KeyBoxManager.getAttestationKey(keyboxFile, algorithmName)
|
return KeyBoxManager.getAttestationKey(keyboxFile, algorithmName)
|
||||||
|
?: KeyBoxManager.getAnyAttestationKey(keyboxFile)
|
||||||
?: throw android.os.ServiceSpecificException(
|
?: throw android.os.ServiceSpecificException(
|
||||||
-75, // ATTESTATION_KEYS_NOT_PROVISIONED
|
-75, // ATTESTATION_KEYS_NOT_PROVISIONED
|
||||||
"No attestation key for algorithm $algorithmName in $keyboxFile",
|
"No usable attestation key in $keyboxFile",
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user