File
Blob: firmware/crates/esp32-radio/src/platform/crypto/signature.rs
| 1 | use super::{hashes, native}; |
| 2 | use dimpl::{ |
| 3 | CryptoError, HashAlgorithm, SignatureAlgorithm, |
| 4 | crypto::{SignatureVerifier, cert_named_group, check_verify_scheme}, |
| 5 | }; |
| 6 | |
| 7 | #[derive(Debug)] |
| 8 | pub(super) struct Verifier; |
| 9 | impl SignatureVerifier for Verifier { |
| 10 | fn verify_signature( |
| 11 | &self, |
| 12 | cert: &[u8], |
| 13 | data: &[u8], |
| 14 | signature: &[u8], |
| 15 | hash: HashAlgorithm, |
| 16 | algorithm: SignatureAlgorithm, |
| 17 | ) -> Result<(), CryptoError> { |
| 18 | let group = cert_named_group(cert).map_err(|_| CryptoError::CertificateParseFailed)?; |
| 19 | check_verify_scheme(algorithm, hash, group)?; |
| 20 | let bits = hashes::bits(hash).ok_or(CryptoError::UnsupportedSignaturePair { |
| 21 | signature: algorithm, |
| 22 | hash, |
| 23 | })?; |
| 24 | native::verify_ec(cert, data, signature, bits).map_err(|_| { |
| 25 | CryptoError::SignatureVerificationFailed { |
| 26 | signature: algorithm, |
| 27 | hash, |
| 28 | group, |
| 29 | } |
| 30 | }) |
| 31 | } |
| 32 | } |