Blame SOURCES/Check-key-derivation-key-is-available.patch

77fb27
From 8b707e8bfcbfd073579ee553b982b4784490f5ea Mon Sep 17 00:00:00 2001
77fb27
From: Daniel Kopecek <dkopecek@redhat.com>
77fb27
Date: Wed, 5 Dec 2018 13:18:59 +0100
77fb27
Subject: [PATCH] clevis-encrypt-tang: check key derivation key is available
77fb27
 before encryption
77fb27
77fb27
---
77fb27
 src/pins/tang/clevis-encrypt-tang | 6 +++++-
77fb27
 1 file changed, 5 insertions(+), 1 deletion(-)
77fb27
77fb27
diff --git a/src/pins/tang/clevis-encrypt-tang b/src/pins/tang/clevis-encrypt-tang
77fb27
index e65a7d1..7fc55ca 100755
77fb27
--- a/src/pins/tang/clevis-encrypt-tang
77fb27
+++ b/src/pins/tang/clevis-encrypt-tang
77fb27
@@ -114,7 +114,11 @@ elif [ "$thp" != "any" ] && \
77fb27
 fi
77fb27
 
77fb27
 ### Perform encryption
77fb27
-enc=`jose jwk use -i- -r -u deriveKey -o- <<< "$jwks"`
77fb27
+if ! enc=`jose jwk use -i- -r -u deriveKey -o- <<< "$jwks"`; then
77fb27
+    echo "Key derivation key not available!" >&2
77fb27
+    exit 1
77fb27
+fi
77fb27
+
77fb27
 jose fmt -j "$enc" -Og keys -A || enc="{\"keys\":[$enc]}"
77fb27
 
77fb27
 for jwk in `jose fmt -j- -Og keys -Af- <<< "$enc"`; do
77fb27
-- 
77fb27
2.13.6
77fb27