blob: 564a4c932f06197d450720ddaba98b65abc27947 [file] [log] [blame]
Juan Castilloa57a4d52015-04-02 15:44:20 +01001#
Alexei Fedorov25d7c882020-03-20 18:38:55 +00002# Copyright (c) 2015-2020, ARM Limited and Contributors. All rights reserved.
Juan Castilloa57a4d52015-04-02 15:44:20 +01003#
dp-armfa3cf0b2017-05-03 09:38:09 +01004# SPDX-License-Identifier: BSD-3-Clause
Juan Castilloa57a4d52015-04-02 15:44:20 +01005#
6
7ifneq (${MBEDTLS_COMMON_MK},1)
8MBEDTLS_COMMON_MK := 1
9
Juan Castillobae6b2a2015-11-05 09:24:53 +000010# MBEDTLS_DIR must be set to the mbed TLS main directory (it must contain
Juan Castilloa57a4d52015-04-02 15:44:20 +010011# the 'include' and 'library' subdirectories).
12ifeq (${MBEDTLS_DIR},)
13 $(error Error: MBEDTLS_DIR not set)
14endif
15
Roberto Vargasd51207e2018-06-04 15:15:04 +010016MBEDTLS_INC = -I${MBEDTLS_DIR}/include
Juan Castilloa57a4d52015-04-02 15:44:20 +010017
Juan Castillobae6b2a2015-11-05 09:24:53 +000018# Specify mbed TLS configuration file
Antonio Nino Diaze0f90632018-12-14 00:18:21 +000019MBEDTLS_CONFIG_FILE := "<drivers/auth/mbedtls/mbedtls_config.h>"
Juan Castillobae6b2a2015-11-05 09:24:53 +000020$(eval $(call add_define,MBEDTLS_CONFIG_FILE))
Juan Castilloa57a4d52015-04-02 15:44:20 +010021
Roberto Vargas502290b2018-05-08 10:27:10 +010022MBEDTLS_SOURCES += drivers/auth/mbedtls/mbedtls_common.c
23
24
25LIBMBEDTLS_SRCS := $(addprefix ${MBEDTLS_DIR}/library/, \
Sumit Garg392e4df2019-11-15 10:43:00 +053026 aes.c \
Roberto Vargas502290b2018-05-08 10:27:10 +010027 asn1parse.c \
28 asn1write.c \
Sumit Garg392e4df2019-11-15 10:43:00 +053029 cipher.c \
30 cipher_wrap.c \
Roberto Vargas502290b2018-05-08 10:27:10 +010031 memory_buffer_alloc.c \
32 oid.c \
33 platform.c \
34 platform_util.c \
35 bignum.c \
Sumit Garg392e4df2019-11-15 10:43:00 +053036 gcm.c \
Roberto Vargas502290b2018-05-08 10:27:10 +010037 md.c \
38 md_wrap.c \
39 pk.c \
40 pk_wrap.c \
41 pkparse.c \
42 pkwrite.c \
43 sha256.c \
44 sha512.c \
45 ecdsa.c \
46 ecp_curves.c \
47 ecp.c \
48 rsa.c \
49 rsa_internal.c \
50 x509.c \
51 x509_crt.c \
52 )
53
54# The platform may define the variable 'TF_MBEDTLS_KEY_ALG' to select the key
Justin Chadwell3168a202019-09-09 15:24:31 +010055# algorithm to use. If the variable is not defined, select it based on
56# algorithm used for key generation `KEY_ALG`. If `KEY_ALG` is not defined,
57# then it is set to `rsa`.
Roberto Vargas502290b2018-05-08 10:27:10 +010058ifeq (${TF_MBEDTLS_KEY_ALG},)
59 ifeq (${KEY_ALG}, ecdsa)
60 TF_MBEDTLS_KEY_ALG := ecdsa
61 else
62 TF_MBEDTLS_KEY_ALG := rsa
63 endif
64endif
65
Justin Chadwellf9b32c12019-07-29 17:13:10 +010066ifeq (${TF_MBEDTLS_KEY_SIZE},)
67 ifneq ($(findstring rsa,${TF_MBEDTLS_KEY_ALG}),)
68 ifeq (${KEY_SIZE},)
69 TF_MBEDTLS_KEY_SIZE := 2048
70 else
71 TF_MBEDTLS_KEY_SIZE := ${KEY_SIZE}
72 endif
73 endif
74endif
75
Roberto Vargas502290b2018-05-08 10:27:10 +010076ifeq (${HASH_ALG}, sha384)
77 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA384
Alexei Fedorov25d7c882020-03-20 18:38:55 +000078 MBEDTLS_MD_ID := MBEDTLS_MD_SHA384
79 TPM_ALG_ID := TPM_ALG_SHA384
80 TCG_DIGEST_SIZE := 48
Roberto Vargas502290b2018-05-08 10:27:10 +010081else ifeq (${HASH_ALG}, sha512)
Alexei Fedorov25d7c882020-03-20 18:38:55 +000082 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA512
83 MBEDTLS_MD_ID := MBEDTLS_MD_SHA512
84 TPM_ALG_ID := TPM_ALG_SHA512
85 TCG_DIGEST_SIZE := 64
Roberto Vargas502290b2018-05-08 10:27:10 +010086else
87 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA256
Alexei Fedorov25d7c882020-03-20 18:38:55 +000088 MBEDTLS_MD_ID := MBEDTLS_MD_SHA256
89 TPM_ALG_ID := TPM_ALG_SHA256
90 TCG_DIGEST_SIZE := 32
Roberto Vargas502290b2018-05-08 10:27:10 +010091endif
92
93ifeq (${TF_MBEDTLS_KEY_ALG},ecdsa)
94 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_ECDSA
95else ifeq (${TF_MBEDTLS_KEY_ALG},rsa)
96 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_RSA
97else ifeq (${TF_MBEDTLS_KEY_ALG},rsa+ecdsa)
98 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_RSA_AND_ECDSA
99else
100 $(error "TF_MBEDTLS_KEY_ALG=${TF_MBEDTLS_KEY_ALG} not supported on mbed TLS")
101endif
102
Sumit Garg392e4df2019-11-15 10:43:00 +0530103ifeq (${DECRYPTION_SUPPORT}, aes_gcm)
104 TF_MBEDTLS_USE_AES_GCM := 1
105else
106 TF_MBEDTLS_USE_AES_GCM := 0
107endif
108
Roberto Vargas502290b2018-05-08 10:27:10 +0100109# Needs to be set to drive mbed TLS configuration correctly
110$(eval $(call add_define,TF_MBEDTLS_KEY_ALG_ID))
Justin Chadwellf9b32c12019-07-29 17:13:10 +0100111$(eval $(call add_define,TF_MBEDTLS_KEY_SIZE))
Roberto Vargas502290b2018-05-08 10:27:10 +0100112$(eval $(call add_define,TF_MBEDTLS_HASH_ALG_ID))
Sumit Garg392e4df2019-11-15 10:43:00 +0530113$(eval $(call add_define,TF_MBEDTLS_USE_AES_GCM))
Roberto Vargas502290b2018-05-08 10:27:10 +0100114
Alexei Fedorov25d7c882020-03-20 18:38:55 +0000115# Set definitions for measured boot driver
116$(eval $(call add_define,MBEDTLS_MD_ID))
117$(eval $(call add_define,TPM_ALG_ID))
118$(eval $(call add_define,TCG_DIGEST_SIZE))
119
Roberto Vargas502290b2018-05-08 10:27:10 +0100120$(eval $(call MAKE_LIB,mbedtls))
Juan Castilloa57a4d52015-04-02 15:44:20 +0100121
Juan Castilloa57a4d52015-04-02 15:44:20 +0100122endif