blob: 67a5da2b18b2954166fca076f00915f06d89df39 [file] [log] [blame]
Juan Castilloa57a4d52015-04-02 15:44:20 +01001#
Jeenu Viswambharanec06c3b2018-06-07 15:14:42 +01002# Copyright (c) 2015-2018, ARM Limited and Contributors. All rights reserved.
Juan Castilloa57a4d52015-04-02 15:44:20 +01003#
dp-armfa3cf0b2017-05-03 09:38:09 +01004# SPDX-License-Identifier: BSD-3-Clause
Juan Castilloa57a4d52015-04-02 15:44:20 +01005#
6
7ifneq (${MBEDTLS_COMMON_MK},1)
8MBEDTLS_COMMON_MK := 1
9
Juan Castillobae6b2a2015-11-05 09:24:53 +000010# MBEDTLS_DIR must be set to the mbed TLS main directory (it must contain
Juan Castilloa57a4d52015-04-02 15:44:20 +010011# the 'include' and 'library' subdirectories).
12ifeq (${MBEDTLS_DIR},)
13 $(error Error: MBEDTLS_DIR not set)
14endif
15
16INCLUDES += -I${MBEDTLS_DIR}/include \
17 -Iinclude/drivers/auth/mbedtls
18
Juan Castillobae6b2a2015-11-05 09:24:53 +000019# Specify mbed TLS configuration file
20MBEDTLS_CONFIG_FILE := "<mbedtls_config.h>"
21$(eval $(call add_define,MBEDTLS_CONFIG_FILE))
Juan Castilloa57a4d52015-04-02 15:44:20 +010022
Roberto Vargas502290b2018-05-08 10:27:10 +010023MBEDTLS_SOURCES += drivers/auth/mbedtls/mbedtls_common.c
24
25
26LIBMBEDTLS_SRCS := $(addprefix ${MBEDTLS_DIR}/library/, \
27 asn1parse.c \
28 asn1write.c \
29 memory_buffer_alloc.c \
30 oid.c \
31 platform.c \
32 platform_util.c \
33 bignum.c \
34 md.c \
35 md_wrap.c \
36 pk.c \
37 pk_wrap.c \
38 pkparse.c \
39 pkwrite.c \
40 sha256.c \
41 sha512.c \
42 ecdsa.c \
43 ecp_curves.c \
44 ecp.c \
45 rsa.c \
46 rsa_internal.c \
47 x509.c \
48 x509_crt.c \
49 )
50
51# The platform may define the variable 'TF_MBEDTLS_KEY_ALG' to select the key
52# algorithm to use. If the variable is not defined, select it based on algorithm
53# used for key generation `KEY_ALG`. If `KEY_ALG` is not defined or is
54# defined to `rsa`/`rsa_1_5`, then set the variable to `rsa`.
55ifeq (${TF_MBEDTLS_KEY_ALG},)
56 ifeq (${KEY_ALG}, ecdsa)
57 TF_MBEDTLS_KEY_ALG := ecdsa
58 else
59 TF_MBEDTLS_KEY_ALG := rsa
60 endif
61endif
62
63# If MBEDTLS_KEY_ALG build flag is defined use it to set TF_MBEDTLS_KEY_ALG for
64# backward compatibility
65ifdef MBEDTLS_KEY_ALG
66 ifeq (${ERROR_DEPRECATED},1)
67 $(error "MBEDTLS_KEY_ALG is deprecated. Please use the new build flag TF_MBEDTLS_KEY_ALG")
68 endif
69 $(warning "MBEDTLS_KEY_ALG is deprecated. Please use the new build flag TF_MBEDTLS_KEY_ALG")
70 TF_MBEDTLS_KEY_ALG := ${MBEDTLS_KEY_ALG}
71endif
72
73ifeq (${HASH_ALG}, sha384)
74 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA384
75else ifeq (${HASH_ALG}, sha512)
76 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA512
77else
78 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA256
79endif
80
81ifeq (${TF_MBEDTLS_KEY_ALG},ecdsa)
82 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_ECDSA
83else ifeq (${TF_MBEDTLS_KEY_ALG},rsa)
84 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_RSA
85else ifeq (${TF_MBEDTLS_KEY_ALG},rsa+ecdsa)
86 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_RSA_AND_ECDSA
87else
88 $(error "TF_MBEDTLS_KEY_ALG=${TF_MBEDTLS_KEY_ALG} not supported on mbed TLS")
89endif
90
91# Needs to be set to drive mbed TLS configuration correctly
92$(eval $(call add_define,TF_MBEDTLS_KEY_ALG_ID))
93$(eval $(call add_define,TF_MBEDTLS_HASH_ALG_ID))
94
95
96$(eval $(call MAKE_LIB,mbedtls))
Juan Castilloa57a4d52015-04-02 15:44:20 +010097
Juan Castilloa57a4d52015-04-02 15:44:20 +010098endif