fix(keystore): drop algo-split key on restore

A persisted record whose private-key algorithm disagrees with its
served leaf public key (EC private under an RSA leaf) makes every
signature fail as DATA_TOO_LARGE_FOR_MODULUS: the A16 EC two-root.
Require the two to match on restore and drop the record otherwise, so
the next generateKey rebirths a coherent key. Awaiting an EC device
capture to confirm the red originates from a restored record.

Bucket a16-ec-attestkey-red, task T01.
This commit is contained in:
Enginex0
2026-06-17 20:28:28 +01:00
parent a54e8a5315
commit e5d24c3907
@@ -1222,6 +1222,15 @@ class KeyMintSecurityLevelInterceptor(
require(certChain.isNotEmpty()) { "Persisted key has empty certificate chain" } require(certChain.isNotEmpty()) { "Persisted key has empty certificate chain" }
val publicKey = certChain[0].publicKey val publicKey = certChain[0].publicKey
// The private key ($algorithmName) signs leaves that callers verify against this
// served chain's leaf public key. If the two disagree (EC private under an RSA
// served leaf) every signature this key makes fails as DATA_TOO_LARGE_FOR_MODULUS
// -- the A16 EC two-root. A split record is corrupt: drop it so the next
// generateKey rebirths a coherent one rather than serve a key that cannot sign.
require(publicKey.algorithm == algorithmName) {
"Persisted key ${record.alias} splits private=$algorithmName " +
"vs served leaf=${publicKey.algorithm}; dropping"
}
val keyPair = KeyPair(publicKey, privateKey) val keyPair = KeyPair(publicKey, privateKey)
val descriptor = val descriptor =