fix(attestation): reject oversized challenges and rewrite cert DER encoding
DuckDetector flagged two issues: 1. Oversized challenge accepted, 256-byte attestation challenge should return INVALID_INPUT_LENGTH (-21) like real KeyMint. Added early check in handleGenerateKey before any path decision. 2. Issuer/subject chain mismatch, rcgen's HashMap loses DN attribute ordering and converts PrintableString to UTF8String, producing different DER bytes. Replaced rcgen with manual DER assembly that injects raw keybox issuer_dn_der bytes directly. Verified on device: TX_ID 315 rejects 256-byte challenge, TX_ID 501 generates valid 4-cert chain with correct issuer linkage.
This commit is contained in:
Generated
+1166
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user