Blame SOURCES/0020-COMMON-EP11-Add-CKA_VALUE-holding-SPKI-PKCS-8-of-key.patch

447573
From 108b7ea5f8b8eedf3ad56b014b6807fc1a0c692c Mon Sep 17 00:00:00 2001
447573
From: Ingo Franzki <ifranzki@linux.ibm.com>
447573
Date: Wed, 16 Feb 2022 16:20:41 +0100
447573
Subject: [PATCH 20/34] COMMON/EP11: Add CKA_VALUE holding SPKI/PKCS#8 of key
447573
 for Dilithium keys
447573
447573
Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com>
447573
---
447573
 usr/lib/common/asn1.c              |  41 ++++++-
447573
 usr/lib/common/h_extern.h          |  11 +-
447573
 usr/lib/common/key.c               | 167 +++++++++++++++++++++----
447573
 usr/lib/ep11_stdll/ep11_specific.c | 245 ++++++++++++++-----------------------
447573
 4 files changed, 274 insertions(+), 190 deletions(-)
447573
447573
diff --git a/usr/lib/common/asn1.c b/usr/lib/common/asn1.c
447573
index 884ef489..dbf06dfd 100644
447573
--- a/usr/lib/common/asn1.c
447573
+++ b/usr/lib/common/asn1.c
447573
@@ -3787,10 +3787,12 @@ error:
447573
 CK_RV ber_decode_IBM_DilithiumPublicKey(CK_BYTE *data,
447573
                                         CK_ULONG data_len,
447573
                                         CK_ATTRIBUTE **rho_attr,
447573
-                                        CK_ATTRIBUTE **t1_attr)
447573
+                                        CK_ATTRIBUTE **t1_attr,
447573
+                                        CK_ATTRIBUTE **value_attr)
447573
 {
447573
     CK_ATTRIBUTE *rho_attr_temp = NULL;
447573
     CK_ATTRIBUTE *t1_attr_temp = NULL;
447573
+    CK_ATTRIBUTE *value_attr_temp = NULL;
447573
 
447573
     CK_BYTE *algoid = NULL;
447573
     CK_ULONG algoid_len;
447573
@@ -3804,7 +3806,7 @@ CK_RV ber_decode_IBM_DilithiumPublicKey(CK_BYTE *data,
447573
     CK_ULONG rho_len;
447573
     CK_BYTE *t1;
447573
     CK_ULONG t1_len;
447573
-    CK_ULONG field_len, offset;
447573
+    CK_ULONG field_len, offset, raw_spki_len;
447573
     CK_RV rc;
447573
 
447573
     UNUSED(data_len); // XXX can this parameter be removed ?
447573
@@ -3866,8 +3868,21 @@ CK_RV ber_decode_IBM_DilithiumPublicKey(CK_BYTE *data,
447573
         goto cleanup;
447573
     }
447573
 
447573
+    /* Add raw SPKI as CKA_VALUE to public key (z/OS ICSF compatibility) */
447573
+    rc = ber_decode_SEQUENCE(data, &val, &val_len, &raw_spki_len);
447573
+    if (rc != CKR_OK) {
447573
+        TRACE_ERROR("%s ber_decode_SEQUENCE failed with rc=0x%lx\n", __func__, rc);
447573
+        goto cleanup;
447573
+    }
447573
+    rc = build_attribute(CKA_VALUE, data, raw_spki_len, &value_attr_temp);
447573
+    if (rc != CKR_OK) {
447573
+        TRACE_DEVEL("build_attribute failed\n");
447573
+        goto cleanup;
447573
+    }
447573
+
447573
     *rho_attr = rho_attr_temp;
447573
     *t1_attr = t1_attr_temp;
447573
+    *value_attr = value_attr_temp;
447573
 
447573
     return CKR_OK;
447573
 
447573
@@ -3876,6 +3891,8 @@ cleanup:
447573
         free(rho_attr_temp);
447573
     if (t1_attr_temp)
447573
         free(t1_attr_temp);
447573
+    if (value_attr_temp)
447573
+        free(value_attr_temp);
447573
 
447573
     return rc;
447573
 }
447573
@@ -4137,11 +4154,12 @@ CK_RV ber_decode_IBM_DilithiumPrivateKey(CK_BYTE *data,
447573
                                          CK_ATTRIBUTE **s1,
447573
                                          CK_ATTRIBUTE **s2,
447573
                                          CK_ATTRIBUTE **t0,
447573
-                                         CK_ATTRIBUTE **t1)
447573
+                                         CK_ATTRIBUTE **t1,
447573
+                                         CK_ATTRIBUTE **value)
447573
 {
447573
     CK_ATTRIBUTE *rho_attr = NULL, *seed_attr = NULL;
447573
     CK_ATTRIBUTE *tr_attr = NULL, *s1_attr = NULL, *s2_attr = NULL;
447573
-    CK_ATTRIBUTE *t0_attr = NULL, *t1_attr = NULL;
447573
+    CK_ATTRIBUTE *t0_attr = NULL, *t1_attr = NULL, *value_attr = NULL;
447573
     CK_BYTE *algoid = NULL;
447573
     CK_BYTE *dilithium_priv_key = NULL;
447573
     CK_BYTE *buf = NULL;
447573
@@ -4314,6 +4332,18 @@ CK_RV ber_decode_IBM_DilithiumPrivateKey(CK_BYTE *data,
447573
         goto cleanup;
447573
     }
447573
 
447573
+    /* Add private key as CKA_VALUE to public key (z/OS ICSF compatibility) */
447573
+    rc = ber_decode_SEQUENCE(data, &tmp, &len, &field_len);
447573
+    if (rc != CKR_OK) {
447573
+        TRACE_ERROR("%s ber_decode_SEQUENCE failed with rc=0x%lx\n", __func__, rc);
447573
+        goto cleanup;
447573
+    }
447573
+    rc = build_attribute(CKA_VALUE, data, field_len, &value_attr);
447573
+    if (rc != CKR_OK) {
447573
+        TRACE_DEVEL("build_attribute for (t1) failed\n");
447573
+        goto cleanup;
447573
+    }
447573
+
447573
     *rho = rho_attr;
447573
     *seed = seed_attr;
447573
     *tr = tr_attr;
447573
@@ -4321,6 +4351,7 @@ CK_RV ber_decode_IBM_DilithiumPrivateKey(CK_BYTE *data,
447573
     *s2 = s2_attr;
447573
     *t0 = t0_attr;
447573
     *t1 = t1_attr;
447573
+    *value = value_attr;
447573
 
447573
     return CKR_OK;
447573
 
447573
@@ -4340,6 +4371,8 @@ cleanup:
447573
         free(s2_attr);
447573
     if (t0_attr)
447573
         free(t0_attr);
447573
+    if (value_attr)
447573
+        free(value_attr);
447573
 
447573
     return rc;
447573
 }
447573
diff --git a/usr/lib/common/h_extern.h b/usr/lib/common/h_extern.h
447573
index 41ca12df..53909e99 100644
447573
--- a/usr/lib/common/h_extern.h
447573
+++ b/usr/lib/common/h_extern.h
447573
@@ -2500,9 +2500,10 @@ CK_RV ibm_dilithium_priv_validate_attribute(STDLL_TokData_t *tokdata, TEMPLATE *
447573
 CK_RV ibm_dilithium_priv_wrap_get_data(TEMPLATE *tmpl, CK_BBOOL length_only,
447573
                                        CK_BYTE **data, CK_ULONG *data_len);
447573
 CK_RV ibm_dilithium_priv_unwrap(TEMPLATE *tmpl, CK_BYTE *data,
447573
-                                CK_ULONG total_length);
447573
+                                CK_ULONG total_length, CK_BBOOL add_value);
447573
 CK_RV ibm_dilithium_priv_unwrap_get_data(TEMPLATE *tmpl,
447573
-                                         CK_BYTE *data, CK_ULONG total_length);
447573
+                                         CK_BYTE *data, CK_ULONG total_length,
447573
+                                         CK_BBOOL add_value);
447573
 
447573
 // diffie-hellman routines
447573
 //
447573
@@ -2748,7 +2749,8 @@ CK_RV ber_encode_IBM_DilithiumPublicKey(CK_BBOOL length_only,
447573
 CK_RV ber_decode_IBM_DilithiumPublicKey(CK_BYTE *data,
447573
                                         CK_ULONG data_len,
447573
                                         CK_ATTRIBUTE **rho_attr,
447573
-                                        CK_ATTRIBUTE **t1_attr);
447573
+                                        CK_ATTRIBUTE **t1_attr,
447573
+                                        CK_ATTRIBUTE **value_attr);
447573
 
447573
 CK_RV ber_encode_IBM_DilithiumPrivateKey(CK_BBOOL length_only,
447573
                                          CK_BYTE **data,
447573
@@ -2770,7 +2772,8 @@ CK_RV ber_decode_IBM_DilithiumPrivateKey(CK_BYTE *data,
447573
                                          CK_ATTRIBUTE **s1,
447573
                                          CK_ATTRIBUTE **s2,
447573
                                          CK_ATTRIBUTE **t0,
447573
-                                         CK_ATTRIBUTE **t1);
447573
+                                         CK_ATTRIBUTE **t1,
447573
+                                         CK_ATTRIBUTE **value);
447573
 
447573
 typedef CK_RV (*t_rsa_encrypt)(STDLL_TokData_t *, CK_BYTE *in_data,
447573
                                CK_ULONG in_data_len, CK_BYTE *out_data,
447573
diff --git a/usr/lib/common/key.c b/usr/lib/common/key.c
447573
index 41857b97..b0050816 100644
447573
--- a/usr/lib/common/key.c
447573
+++ b/usr/lib/common/key.c
447573
@@ -1051,7 +1051,7 @@ CK_RV priv_key_unwrap(TEMPLATE *tmpl,
447573
         rc = ec_priv_unwrap(tmpl, data, data_len);
447573
         break;
447573
     case CKK_IBM_PQC_DILITHIUM:
447573
-        rc = ibm_dilithium_priv_unwrap(tmpl, data, data_len);
447573
+        rc = ibm_dilithium_priv_unwrap(tmpl, data, data_len, TRUE);
447573
         break;
447573
     default:
447573
         TRACE_ERROR("%s\n", ock_err(ERR_WRAPPED_KEY_INVALID));
447573
@@ -2781,13 +2781,16 @@ CK_RV ibm_dilithium_priv_wrap_get_data(TEMPLATE *tmpl,
447573
 }
447573
 
447573
 CK_RV ibm_dilithium_priv_unwrap_get_data(TEMPLATE *tmpl, CK_BYTE *data,
447573
-                                         CK_ULONG total_length)
447573
+                                         CK_ULONG total_length,
447573
+                                         CK_BBOOL add_value)
447573
 {
447573
     CK_ATTRIBUTE *rho = NULL;
447573
     CK_ATTRIBUTE *t1 = NULL;
447573
+    CK_ATTRIBUTE *value = NULL;
447573
     CK_RV rc;
447573
 
447573
-    rc = ber_decode_IBM_DilithiumPublicKey(data, total_length, &rho, &t1;;
447573
+    rc = ber_decode_IBM_DilithiumPublicKey(data, total_length, &rho, &t1,
447573
+                                           &value);
447573
     if (rc != CKR_OK) {
447573
         TRACE_ERROR("ber_decode_DilithiumPublicKey failed\n");
447573
         return rc;
447573
@@ -2805,6 +2808,16 @@ CK_RV ibm_dilithium_priv_unwrap_get_data(TEMPLATE *tmpl, CK_BYTE *data,
447573
         goto error;
447573
     }
447573
     t1 = NULL;
447573
+    if (add_value) {
447573
+        rc = template_update_attribute(tmpl, value);
447573
+        if (rc != CKR_OK) {
447573
+            TRACE_DEVEL("template_update_attribute failed.\n");
447573
+            goto error;
447573
+        }
447573
+    } else {
447573
+        free(value);
447573
+    }
447573
+    value = NULL;
447573
 
447573
     return CKR_OK;
447573
 
447573
@@ -2813,6 +2826,8 @@ error:
447573
         free(rho);
447573
     if (t1)
447573
         free(t1);
447573
+    if (value)
447573
+        free(value);
447573
 
447573
     return rc;
447573
 }
447573
@@ -2820,14 +2835,15 @@ error:
447573
 //
447573
 //
447573
 CK_RV ibm_dilithium_priv_unwrap(TEMPLATE *tmpl, CK_BYTE *data,
447573
-                                CK_ULONG total_length)
447573
+                                CK_ULONG total_length, CK_BBOOL add_value)
447573
 {
447573
-    CK_ATTRIBUTE *rho = NULL, *seed = NULL, *tr = NULL;
447573
+    CK_ATTRIBUTE *rho = NULL, *seed = NULL, *tr = NULL, *value = NULL;
447573
     CK_ATTRIBUTE *s1 = NULL, *s2 = NULL, *t0 = NULL, *t1 = NULL;
447573
     CK_RV rc;
447573
 
447573
     rc = ber_decode_IBM_DilithiumPrivateKey(data, total_length,
447573
-                                 &rho, &seed, &tr, &s1, &s2, &t0, &t1;;
447573
+                                            &rho, &seed, &tr, &s1, &s2, &t0,
447573
+                                            &t1, &value);
447573
     if (rc != CKR_OK) {
447573
         TRACE_ERROR("der_decode_IBM_DilithiumPrivateKey failed\n");
447573
         return rc;
447573
@@ -2877,6 +2893,16 @@ CK_RV ibm_dilithium_priv_unwrap(TEMPLATE *tmpl, CK_BYTE *data,
447573
         }
447573
     }
447573
     t1 = NULL;
447573
+    if (add_value) {
447573
+        rc = template_update_attribute(tmpl, value);
447573
+        if (rc != CKR_OK) {
447573
+            TRACE_DEVEL("template_update_attribute failed.\n");
447573
+            goto error;
447573
+        }
447573
+    } else {
447573
+        free(value);
447573
+    }
447573
+    value = NULL;
447573
 
447573
     return CKR_OK;
447573
 
447573
@@ -2895,6 +2921,8 @@ error:
447573
         free(t0);
447573
     if (t1)
447573
         free(t1);
447573
+    if (value)
447573
+        free(value);
447573
 
447573
     return rc;
447573
 }
447573
@@ -4633,6 +4661,7 @@ CK_RV ibm_dilithium_publ_set_default_attributes(TEMPLATE *tmpl, CK_ULONG mode)
447573
     CK_ATTRIBUTE *rho_attr = NULL;
447573
     CK_ATTRIBUTE *t1_attr = NULL;
447573
     CK_ATTRIBUTE *keyform_attr = NULL;
447573
+    CK_ATTRIBUTE *value_attr = NULL;
447573
     CK_RV rc;
447573
 
447573
     publ_key_set_default_attributes(tmpl, mode);
447573
@@ -4641,8 +4670,9 @@ CK_RV ibm_dilithium_publ_set_default_attributes(TEMPLATE *tmpl, CK_ULONG mode)
447573
     keyform_attr = (CK_ATTRIBUTE *) malloc(sizeof(CK_ATTRIBUTE) + sizeof(CK_ULONG));
447573
     rho_attr = (CK_ATTRIBUTE *) malloc(sizeof(CK_ATTRIBUTE));
447573
     t1_attr = (CK_ATTRIBUTE *) malloc(sizeof(CK_ATTRIBUTE));
447573
+    value_attr = (CK_ATTRIBUTE *) malloc(sizeof(CK_ATTRIBUTE));
447573
 
447573
-    if (!type_attr || !rho_attr || !t1_attr || !keyform_attr) {
447573
+    if (!type_attr || !rho_attr || !t1_attr || !keyform_attr || !value_attr) {
447573
         TRACE_ERROR("%s\n", ock_err(ERR_HOST_MEMORY));
447573
         rc = CKR_HOST_MEMORY;
447573
         goto error;
447573
@@ -4666,6 +4696,10 @@ CK_RV ibm_dilithium_publ_set_default_attributes(TEMPLATE *tmpl, CK_ULONG mode)
447573
     t1_attr->ulValueLen = 0;
447573
     t1_attr->pValue = NULL;
447573
 
447573
+    value_attr->type = CKA_VALUE;
447573
+    value_attr->ulValueLen = 0;
447573
+    value_attr->pValue = NULL;
447573
+
447573
     rc = template_update_attribute(tmpl, type_attr);
447573
     if (rc != CKR_OK) {
447573
         TRACE_ERROR("template_update_attribute failed\n");
447573
@@ -4690,6 +4724,12 @@ CK_RV ibm_dilithium_publ_set_default_attributes(TEMPLATE *tmpl, CK_ULONG mode)
447573
         goto error;
447573
     }
447573
     keyform_attr = NULL;
447573
+    rc = template_update_attribute(tmpl, value_attr);
447573
+    if (rc != CKR_OK) {
447573
+        TRACE_ERROR("template_update_attribute failed\n");
447573
+        goto error;
447573
+    }
447573
+    value_attr = NULL;
447573
 
447573
     return CKR_OK;
447573
 
447573
@@ -4702,6 +4742,8 @@ error:
447573
         free(t1_attr);
447573
     if (keyform_attr)
447573
         free(keyform_attr);
447573
+    if (value_attr)
447573
+        free(value_attr);
447573
 
447573
    return rc;
447573
 }
447573
@@ -4719,6 +4761,7 @@ CK_RV ibm_dilithium_priv_set_default_attributes(TEMPLATE *tmpl, CK_ULONG mode)
447573
     CK_ATTRIBUTE *t0_attr = NULL;
447573
     CK_ATTRIBUTE *t1_attr = NULL;
447573
     CK_ATTRIBUTE *keyform_attr = NULL;
447573
+    CK_ATTRIBUTE *value_attr = NULL;
447573
     CK_RV rc;
447573
 
447573
     priv_key_set_default_attributes(tmpl, mode);
447573
@@ -4732,9 +4775,10 @@ CK_RV ibm_dilithium_priv_set_default_attributes(TEMPLATE *tmpl, CK_ULONG mode)
447573
     s2_attr = (CK_ATTRIBUTE *) malloc(sizeof(CK_ATTRIBUTE));
447573
     t0_attr = (CK_ATTRIBUTE *) malloc(sizeof(CK_ATTRIBUTE));
447573
     t1_attr = (CK_ATTRIBUTE *) malloc(sizeof(CK_ATTRIBUTE));
447573
+    value_attr = (CK_ATTRIBUTE *) malloc(sizeof(CK_ATTRIBUTE));
447573
 
447573
     if (!type_attr || !rho_attr || !seed_attr || !tr_attr || !s1_attr
447573
-        || !s2_attr || !t0_attr || !t1_attr || !keyform_attr) {
447573
+        || !s2_attr || !t0_attr || !t1_attr || !keyform_attr || !value_attr) {
447573
         TRACE_ERROR("%s\n", ock_err(ERR_HOST_MEMORY));
447573
         rc = CKR_HOST_MEMORY;
447573
         goto error;
447573
@@ -4778,6 +4822,10 @@ CK_RV ibm_dilithium_priv_set_default_attributes(TEMPLATE *tmpl, CK_ULONG mode)
447573
     t1_attr->ulValueLen = 0;
447573
     t1_attr->pValue = NULL;
447573
 
447573
+    value_attr->type = CKA_VALUE;
447573
+    value_attr->ulValueLen = 0;
447573
+    value_attr->pValue = NULL;
447573
+
447573
     rc = template_update_attribute(tmpl, type_attr);
447573
     if (rc != CKR_OK) {
447573
         TRACE_ERROR("template_update_attribute failed\n");
447573
@@ -4832,6 +4880,12 @@ CK_RV ibm_dilithium_priv_set_default_attributes(TEMPLATE *tmpl, CK_ULONG mode)
447573
         goto error;
447573
     }
447573
     t1_attr = NULL;
447573
+    rc = template_update_attribute(tmpl, value_attr);
447573
+    if (rc != CKR_OK) {
447573
+        TRACE_ERROR("template_update_attribute failed\n");
447573
+        goto error;
447573
+    }
447573
+    value_attr = NULL;
447573
 
447573
     return CKR_OK;
447573
 
447573
@@ -4854,6 +4908,8 @@ error:
447573
         free(t1_attr);
447573
     if (keyform_attr)
447573
         free(keyform_attr);
447573
+    if (value_attr)
447573
+        free(value_attr);
447573
 
447573
     return rc;
447573
 }
447573
@@ -4869,18 +4925,46 @@ CK_RV ibm_dilithium_publ_check_required_attributes(TEMPLATE *tmpl, CK_ULONG mode
447573
         CKA_IBM_DILITHIUM_T1,
447573
     };
447573
     CK_ULONG i;
447573
+    CK_RV rc;
447573
 
447573
-    /* MODE_KEYGEN: attrs are added during keygen */
447573
-    if (mode == MODE_KEYGEN || mode == MODE_UNWRAP)
447573
-        return publ_key_check_required_attributes(tmpl, mode);
447573
-
447573
-    /* MODE_CREATE (key import) or MODE_COPY: check if all attrs present */
447573
-    for (i = 0; i < sizeof(req_attrs) / sizeof(req_attrs[0]); i++) {
447573
-        if (!(template_attribute_find(tmpl, req_attrs[i], &attr))) {
447573
-            TRACE_ERROR("%s, attribute %08lX missing.\n",
447573
-                        ock_err(ERR_TEMPLATE_INCOMPLETE), req_attrs[i]);
447573
+    switch (mode) {
447573
+    case MODE_KEYGEN:
447573
+    case MODE_UNWRAP:
447573
+        /* Attrs will be added during keygen/unwrap */
447573
+        break;
447573
+    case MODE_CREATE:
447573
+        /* Either CKA_VALUE or all other attrs must be present */
447573
+        if (template_attribute_find(tmpl, CKA_VALUE, &attr) &&
447573
+            attr->ulValueLen > 0 && attr->pValue != NULL)
447573
+            break;
447573
+        for (i = 0; i < sizeof(req_attrs) / sizeof(req_attrs[0]); i++) {
447573
+            rc = template_attribute_get_non_empty(tmpl, req_attrs[i], &attr);
447573
+            if (rc != CKR_OK) {
447573
+                if (rc != CKR_ATTRIBUTE_VALUE_INVALID)
447573
+                    TRACE_ERROR("%s, attribute %08lX missing.\n",
447573
+                               ock_err(ERR_TEMPLATE_INCOMPLETE), req_attrs[i]);
447573
+                return rc;
447573
+            }
447573
+        }
447573
+        break;
447573
+    case MODE_COPY:
447573
+        /* CKA_VALUE and all other attrs must be present */
447573
+        if (!template_attribute_find(tmpl, CKA_VALUE, &attr) &&
447573
+            attr->ulValueLen > 0 && attr->pValue != NULL) {
447573
+            TRACE_ERROR("%s, attribute CKA_VALUE missing.\n",
447573
+                        ock_err(ERR_TEMPLATE_INCOMPLETE));
447573
             return CKR_TEMPLATE_INCOMPLETE;
447573
         }
447573
+        for (i = 0; i < sizeof(req_attrs) / sizeof(req_attrs[0]); i++) {
447573
+            rc = template_attribute_get_non_empty(tmpl, req_attrs[i], &attr);
447573
+            if (rc != CKR_OK) {
447573
+                if (rc != CKR_ATTRIBUTE_VALUE_INVALID)
447573
+                    TRACE_ERROR("%s, attribute %08lX missing.\n",
447573
+                               ock_err(ERR_TEMPLATE_INCOMPLETE), req_attrs[i]);
447573
+                return rc;
447573
+            }
447573
+        }
447573
+        break;
447573
     }
447573
 
447573
     /* All required attrs found, check them */
447573
@@ -4903,18 +4987,47 @@ CK_RV ibm_dilithium_priv_check_required_attributes(TEMPLATE *tmpl, CK_ULONG mode
447573
         CKA_IBM_DILITHIUM_T1,
447573
     };
447573
     CK_ULONG i;
447573
+    CK_RV rc;
447573
 
447573
-    /* MODE_KEYGEN: attrs are added during keygen */
447573
-    if (mode == MODE_KEYGEN || mode == MODE_UNWRAP)
447573
-        return priv_key_check_required_attributes(tmpl, mode);
447573
-
447573
-    /* MODE_CREATE (key import) or MODE_COPY: check if all attrs present */
447573
-    for (i = 0; i < sizeof(req_attrs) / sizeof(req_attrs[0]); i++) {
447573
-        if (!(template_attribute_find(tmpl, req_attrs[i], &attr))) {
447573
-            TRACE_ERROR("%s, attribute %08lX missing.\n",
447573
-                        ock_err(ERR_TEMPLATE_INCOMPLETE), req_attrs[i]);
447573
+    switch (mode) {
447573
+    case MODE_KEYGEN:
447573
+    case MODE_UNWRAP:
447573
+        /* Attrs will be added during keygen/unwrap */
447573
+        break;
447573
+    case MODE_CREATE:
447573
+        /* Either CKA_VALUE or all other attrs must be present */
447573
+        if (template_attribute_find(tmpl, CKA_VALUE, &attr) &&
447573
+            attr->ulValueLen > 0 && attr->pValue != NULL)
447573
+            break;
447573
+        for (i = 0; i < sizeof(req_attrs) / sizeof(req_attrs[0]); i++) {
447573
+            rc = template_attribute_get_non_empty(tmpl, req_attrs[i], &attr);
447573
+            if (rc != CKR_OK) {
447573
+                if (rc != CKR_ATTRIBUTE_VALUE_INVALID)
447573
+                    TRACE_ERROR("%s, attribute %08lX missing.\n",
447573
+                               ock_err(ERR_TEMPLATE_INCOMPLETE), req_attrs[i]);
447573
+                return rc;
447573
+            }
447573
+        }
447573
+        break;
447573
+    case MODE_COPY:
447573
+        /* CKA_VALUE and all other attrs must be present */
447573
+        if (!template_attribute_find(tmpl, CKA_VALUE, &attr) &&
447573
+            attr->ulValueLen > 0 && attr->pValue != NULL) {
447573
+            TRACE_ERROR("%s, attribute CKA_VALUE missing.\n",
447573
+                        ock_err(ERR_TEMPLATE_INCOMPLETE));
447573
             return CKR_TEMPLATE_INCOMPLETE;
447573
+
447573
+        }
447573
+        for (i = 0; i < sizeof(req_attrs) / sizeof(req_attrs[0]); i++) {
447573
+            rc = template_attribute_get_non_empty(tmpl, req_attrs[i], &attr);
447573
+            if (rc != CKR_OK) {
447573
+                if (rc != CKR_ATTRIBUTE_VALUE_INVALID)
447573
+                    TRACE_ERROR("%s, attribute %08lX missing.\n",
447573
+                               ock_err(ERR_TEMPLATE_INCOMPLETE), req_attrs[i]);
447573
+                return rc;
447573
+            }
447573
         }
447573
+        break;
447573
     }
447573
 
447573
     /* All required attrs found, check them */
447573
@@ -4930,6 +5043,7 @@ CK_RV ibm_dilithium_publ_validate_attribute(STDLL_TokData_t *tokdata,
447573
     switch (attr->type) {
447573
     case CKA_IBM_DILITHIUM_RHO:
447573
     case CKA_IBM_DILITHIUM_T1:
447573
+    case CKA_VALUE:
447573
         if (mode == MODE_CREATE)
447573
             return CKR_OK;
447573
         TRACE_ERROR("%s\n", ock_err(ERR_ATTRIBUTE_READ_ONLY));
447573
@@ -4969,6 +5083,7 @@ CK_RV ibm_dilithium_priv_validate_attribute(STDLL_TokData_t *tokdata,
447573
     case CKA_IBM_DILITHIUM_S2:
447573
     case CKA_IBM_DILITHIUM_T0:
447573
     case CKA_IBM_DILITHIUM_T1:
447573
+    case CKA_VALUE:
447573
         if (mode == MODE_CREATE)
447573
             return CKR_OK;
447573
         TRACE_ERROR("%s\n", ock_err(ERR_ATTRIBUTE_READ_ONLY));
447573
diff --git a/usr/lib/ep11_stdll/ep11_specific.c b/usr/lib/ep11_stdll/ep11_specific.c
447573
index 45069ae8..9221b8cd 100644
447573
--- a/usr/lib/ep11_stdll/ep11_specific.c
447573
+++ b/usr/lib/ep11_stdll/ep11_specific.c
447573
@@ -3585,6 +3585,8 @@ static CK_RV import_IBM_Dilithium_key(STDLL_TokData_t *tokdata, SESSION *sess,
447573
     unsigned char *ep11_pin_blob = NULL;
447573
     CK_ULONG ep11_pin_blob_len = 0;
447573
     ep11_session_t *ep11_session = (ep11_session_t *) sess->private_data;
447573
+    CK_ATTRIBUTE *value_attr = NULL;
447573
+    CK_BBOOL data_alloced = TRUE;
447573
 
447573
     memcpy(iv, "1234567812345678", AES_BLOCK_SIZE);
447573
 
447573
@@ -3606,57 +3608,55 @@ static CK_RV import_IBM_Dilithium_key(STDLL_TokData_t *tokdata, SESSION *sess,
447573
         goto done;
447573
 
447573
     if (class != CKO_PRIVATE_KEY) {
447573
-
447573
         /* Make an SPKI for the public IBM Dilithium key */
447573
-        CK_ULONG keyform;
447573
-        CK_ATTRIBUTE *rho;
447573
-        CK_ATTRIBUTE *t1;
447573
-
447573
-        /* A public IBM Dilithium key must have a keyform value */
447573
-        rc = template_attribute_get_ulong(dilithium_key_obj->template,
447573
-                                          CKA_IBM_DILITHIUM_KEYFORM,
447573
-                                          &keyform);
447573
-        if (rc != CKR_OK) {
447573
-            TRACE_ERROR("Could not find CKA_IBM_DILITHIUM_KEYFORM for the "
447573
-                        "key.\n");
447573
-             goto done;
447573
-        }
447573
-
447573
-        /* Check if it's an expected keyform */
447573
-        if (keyform != IBM_DILITHIUM_KEYFORM_ROUND2) {
447573
-            TRACE_ERROR("Keyform is not supported\n");
447573
-            rc = CKR_TEMPLATE_INCONSISTENT;
447573
-            goto done;
447573
-        }
447573
 
447573
-        /* A public IBM Dilithium key must have a rho value */
447573
-        rc = template_attribute_get_non_empty(dilithium_key_obj->template,
447573
-                                              CKA_IBM_DILITHIUM_RHO, &rho);
447573
-        if (rc != CKR_OK) {
447573
-            TRACE_ERROR("Could not find CKA_IBM_DILITHIUM_RHO for the key.\n");
447573
-             goto done;
447573
-        }
447573
+        /* A public IBM Dilithium key must either have a CKA_VALUE containing
447573
+         * the SPKI, or must have a keyform value and the individual attributes
447573
+         */
447573
+        if (template_attribute_find(dilithium_key_obj->template,
447573
+                                    CKA_VALUE, &value_attr) &&
447573
+            value_attr->ulValueLen > 0 && value_attr ->pValue != NULL) {
447573
+            /* CKA_VALUE with SPKI */
447573
+            data = value_attr ->pValue;
447573
+            data_len = value_attr->ulValueLen;
447573
+            data_alloced = FALSE;
447573
+
447573
+            /* Decode SPKI and add public key attributes */
447573
+            rc = ibm_dilithium_priv_unwrap_get_data(dilithium_key_obj->template,
447573
+                                                    data, data_len, FALSE);
447573
+            if (rc != CKR_OK) {
447573
+                TRACE_ERROR("Failed to decode SPKI from CKA_VALUE.\n");
447573
+                goto done;
447573
+            }
447573
+         } else {
447573
+            /* Individual attributes */
447573
+             rc = ibm_dilithium_publ_get_spki(dilithium_key_obj->template,
447573
+                                              FALSE, &data, &data_len);
447573
+            if (rc != CKR_OK) {
447573
+                TRACE_ERROR("%s public key import class=0x%lx rc=0x%lx "
447573
+                            "data_len=0x%lx\n", __func__, class, rc, data_len);
447573
+                goto done;
447573
+            } else {
447573
+                TRACE_INFO("%s public key import class=0x%lx rc=0x%lx "
447573
+                           "data_len=0x%lx\n", __func__, class, rc, data_len);
447573
+            }
447573
 
447573
-        /* A public IBM Dilithium key must have a t1 value */
447573
-        rc = template_attribute_get_non_empty(dilithium_key_obj->template,
447573
-                                              CKA_IBM_DILITHIUM_T1, &t1;;
447573
-        if (rc != CKR_OK) {
447573
-            TRACE_ERROR("Could not find CKA_IBM_DILITHIUM_T1 for the key.\n");
447573
-             goto done;
447573
-        }
447573
+            /* Add SPKI as CKA_VALUE to public key (z/OS ICSF compatibility) */
447573
+            rc = build_attribute(CKA_VALUE, data, data_len, &value_attr);
447573
+            if (rc != CKR_OK) {
447573
+                TRACE_DEVEL("build_attribute failed\n");
447573
+                goto done;
447573
+            }
447573
 
447573
-        /* Encode the public key */
447573
-        rc = ber_encode_IBM_DilithiumPublicKey(FALSE, &data, &data_len,
447573
-                                               dilithium_r2_65,
447573
-                                               dilithium_r2_65_len,
447573
-                                               rho, t1);
447573
-        if (rc != CKR_OK) {
447573
-            TRACE_ERROR("%s public key import class=0x%lx rc=0x%lx "
447573
-                        "data_len=0x%lx\n", __func__, class, rc, data_len);
447573
-            goto done;
447573
-        } else {
447573
-            TRACE_INFO("%s public key import class=0x%lx rc=0x%lx "
447573
-                       "data_len=0x%lx\n", __func__, class, rc, data_len);
447573
+            rc = template_update_attribute(dilithium_key_obj->template,
447573
+                                           value_attr);
447573
+            if (rc != CKR_OK) {
447573
+                TRACE_ERROR("%s template_update_attribute failed with rc=0x%lx\n",
447573
+                            __func__, rc);
447573
+                free(value_attr);
447573
+                goto done;
447573
+            }
447573
+            value_attr = NULL;
447573
         }
447573
 
447573
         /* save the SPKI as blob although it is not a blob.
447573
@@ -3676,14 +3676,35 @@ static CK_RV import_IBM_Dilithium_key(STDLL_TokData_t *tokdata, SESSION *sess,
447573
 
447573
         /* imported private IBM Dilithium key goes here */
447573
 
447573
-        /* extract the secret data to be wrapped
447573
-         * since this is AES_CBC_PAD, padding is done in mechanism.
447573
+        /* A public IBM Dilithium key must either have a CKA_VALUE containing
447573
+         * the PKCS#8 encoded private key, or must have a keyform value and the
447573
+         * individual attributes
447573
          */
447573
-        rc = ibm_dilithium_priv_wrap_get_data(dilithium_key_obj->template, FALSE,
447573
-                                      &data, &data_len);
447573
-        if (rc != CKR_OK) {
447573
-            TRACE_DEVEL("%s Dilithium wrap get data failed\n", __func__);
447573
-            goto done;
447573
+        if (template_attribute_find(dilithium_key_obj->template,
447573
+                                    CKA_VALUE, &value_attr) &&
447573
+            value_attr->ulValueLen > 0 && value_attr ->pValue != NULL) {
447573
+            /* CKA_VALUE with SPKI */
447573
+            data = value_attr ->pValue;
447573
+            data_len = value_attr->ulValueLen;
447573
+            data_alloced = FALSE;
447573
+
447573
+            /* Decode PKCS#8 private key and add key attributes */
447573
+            rc = ibm_dilithium_priv_unwrap(dilithium_key_obj->template,
447573
+                                           data, data_len, FALSE);
447573
+            if (rc != CKR_OK) {
447573
+                TRACE_ERROR("Failed to decode private key from CKA_VALUE.\n");
447573
+                goto done;
447573
+            }
447573
+        } else {
447573
+            /* extract the secret data to be wrapped
447573
+             * since this is AES_CBC_PAD, padding is done in mechanism.
447573
+             */
447573
+            rc = ibm_dilithium_priv_wrap_get_data(dilithium_key_obj->template,
447573
+                                                  FALSE, &data, &data_len);
447573
+            if (rc != CKR_OK) {
447573
+                TRACE_DEVEL("%s Dilithium wrap get data failed\n", __func__);
447573
+                goto done;
447573
+            }
447573
         }
447573
 
447573
         /* encrypt */
447573
@@ -3743,10 +3764,15 @@ static CK_RV import_IBM_Dilithium_key(STDLL_TokData_t *tokdata, SESSION *sess,
447573
         }
447573
 
447573
         cleanse_attribute(dilithium_key_obj->template, CKA_VALUE);
447573
+        cleanse_attribute(dilithium_key_obj->template, CKA_IBM_DILITHIUM_SEED);
447573
+        cleanse_attribute(dilithium_key_obj->template, CKA_IBM_DILITHIUM_TR);
447573
+        cleanse_attribute(dilithium_key_obj->template, CKA_IBM_DILITHIUM_S1);
447573
+        cleanse_attribute(dilithium_key_obj->template, CKA_IBM_DILITHIUM_S2);
447573
+        cleanse_attribute(dilithium_key_obj->template, CKA_IBM_DILITHIUM_T0);
447573
     }
447573
 
447573
 done:
447573
-    if (data) {
447573
+    if (data_alloced && data) {
447573
         OPENSSL_cleanse(data, data_len);
447573
         free(data);
447573
     }
447573
@@ -6422,16 +6448,10 @@ static CK_RV ibm_dilithium_generate_keypair(STDLL_TokData_t *tokdata,
447573
     size_t privkey_blob_len = sizeof(privkey_blob);
447573
     unsigned char spki[MAX_BLOBSIZE];
447573
     size_t spki_len = sizeof(spki);
447573
-    CK_ULONG bit_str_len;
447573
-    CK_BYTE *key;
447573
-    CK_BYTE *data, *oid, *parm;
447573
-    CK_ULONG data_len, oid_len, parm_len;
447573
-    CK_ULONG field_len;
447573
     CK_ULONG ktype = CKK_IBM_PQC_DILITHIUM;
447573
     unsigned char *ep11_pin_blob = NULL;
447573
     CK_ULONG ep11_pin_blob_len = 0;
447573
     ep11_session_t *ep11_session = (ep11_session_t *) sess->private_data;
447573
-    CK_BYTE *rho, *t1;
447573
     CK_ATTRIBUTE *new_publ_attrs = NULL, *new_priv_attrs = NULL;
447573
     CK_ULONG new_publ_attrs_len = 0, new_priv_attrs_len = 0;
447573
     CK_ATTRIBUTE *new_publ_attrs2 = NULL, *new_priv_attrs2 = NULL;
447573
@@ -6567,105 +6587,17 @@ static CK_RV ibm_dilithium_generate_keypair(STDLL_TokData_t *tokdata,
447573
         goto error;
447573
     }
447573
 
447573
-    /* Decode SPKI */
447573
-    rc = ber_decode_SPKI(spki, &oid, &oid_len, &parm, &parm_len, &key,
447573
-            &bit_str_len);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s read key from SPKI failed with rc=0x%lx\n", __func__,
447573
-                rc);
447573
-        goto error;
447573
-    }
447573
-
447573
-    /* Public key must be a sequence holding two bit-strings: (rho, t1) */
447573
-    rc = ber_decode_SEQUENCE(key, &data, &data_len, &field_len);
447573
+    rc = ibm_dilithium_priv_unwrap_get_data(publ_tmpl, spki, spki_len, TRUE);
447573
     if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s read sequence failed with rc=0x%lx\n", __func__, rc);
447573
-        goto error;
447573
-    }
447573
-
447573
-    /* Decode rho */
447573
-    rho = key + field_len - data_len;
447573
-    rc = ber_decode_BIT_STRING(rho, &data, &data_len, &field_len);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s read rho failed with rc=0x%lx\n", __func__, rc);
447573
-        goto error;
447573
-    }
447573
-    /* Remove leading unused-bits byte, returned by ber_decode_BIT_STRING */
447573
-    data++;
447573
-    data_len--;
447573
-#ifdef DEBUG
447573
-    TRACE_DEBUG("%s dilithium_generate_keypair (rho):\n", __func__);
447573
-    TRACE_DEBUG_DUMP("    ", data, data_len);
447573
-#endif
447573
-
447573
-    /* build and add CKA_IBM_DILITHIUM_RHO for public key */
447573
-    rc = build_attribute(CKA_IBM_DILITHIUM_RHO, data, data_len, &attr);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s build_attribute failed with rc=0x%lx\n", __func__, rc);
447573
-        goto error;
447573
-    }
447573
-    rc = template_update_attribute(publ_tmpl, attr);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s template_update_attribute failed with rc=0x%lx\n",
447573
-                __func__, rc);
447573
-        free(attr);
447573
-        goto error;
447573
-    }
447573
-
447573
-    /* build and add CKA_IBM_DILITHIUM_RHO for private key */
447573
-    rc = build_attribute(CKA_IBM_DILITHIUM_RHO, data, data_len, &attr);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s build_attribute failed with rc=0x%lx\n", __func__, rc);
447573
-        goto error;
447573
-    }
447573
-    rc = template_update_attribute(priv_tmpl, attr);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s template_update_attribute failed with rc=0x%lx\n",
447573
-                __func__, rc);
447573
-        free(attr);
447573
-        goto error;
447573
-    }
447573
-
447573
-    /* Decode t1 */
447573
-    t1 = rho + field_len;
447573
-    rc = ber_decode_BIT_STRING(t1, &data, &data_len, &field_len);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s read t failed with rc=0x%lx\n", __func__, rc);
447573
-        goto error;
447573
-    }
447573
-    /* Remove leading unused-bits byte, returned by ber_decode_BIT_STRING */
447573
-    data++;
447573
-    data_len--;
447573
-#ifdef DEBUG
447573
-    TRACE_DEBUG("%s dilithium_generate_keypair (t1):\n", __func__);
447573
-    TRACE_DEBUG_DUMP("    ", data, data_len);
447573
-#endif
447573
-
447573
-    /* build and add CKA_IBM_DILITHIUM_T1 for public key */
447573
-    rc = build_attribute(CKA_IBM_DILITHIUM_T1, data, data_len, &attr);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s build_attribute failed with rc=0x%lx\n", __func__, rc);
447573
-        goto error;
447573
-    }
447573
-    rc = template_update_attribute(publ_tmpl, attr);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s template_update_attribute failed with rc=0x%lx\n",
447573
-                __func__, rc);
447573
-        free(attr);
447573
+        TRACE_ERROR("%s ibm_dilithium_priv_unwrap_get_data with rc=0x%lx\n",
447573
+                    __func__, rc);
447573
         goto error;
447573
     }
447573
 
447573
-    /* build and add CKA_IBM_DILITHIUM_T1 for private key */
447573
-    rc = build_attribute(CKA_IBM_DILITHIUM_T1, data, data_len, &attr);
447573
-    if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s build_attribute failed with rc=0x%lx\n", __func__, rc);
447573
-        goto error;
447573
-    }
447573
-    rc = template_update_attribute(priv_tmpl, attr);
447573
+    rc = ibm_dilithium_priv_unwrap_get_data(priv_tmpl, spki, spki_len, FALSE);
447573
     if (rc != CKR_OK) {
447573
-        TRACE_ERROR("%s template_update_attribute failed with rc=0x%lx\n",
447573
-                __func__, rc);
447573
-        free(attr);
447573
+        TRACE_ERROR("%s ibm_dilithium_priv_unwrap_get_data with rc=0x%lx\n",
447573
+                    __func__, rc);
447573
         goto error;
447573
     }
447573
 
447573
@@ -9043,7 +8975,8 @@ CK_RV ep11tok_unwrap_key(STDLL_TokData_t * tokdata, SESSION * session,
447573
             rc = dh_priv_unwrap_get_data(key_obj->template, csum, cslen);
447573
             break;
447573
         case CKK_IBM_PQC_DILITHIUM:
447573
-            rc = ibm_dilithium_priv_unwrap_get_data(key_obj->template, csum, cslen);
447573
+            rc = ibm_dilithium_priv_unwrap_get_data(key_obj->template,
447573
+                                                    csum, cslen, FALSE);
447573
             break;
447573
         }
447573
 
447573
-- 
447573
2.16.2.windows.1
447573