Skip to content

Restore ECC salted sessions and key import without ECC_TIMING_RESISTANT - #619

Merged
aidangarske merged 1 commit into
wolfSSL:masterfrom
dgarske:ecc_no_harden
Oct 1, 2026
Merged

aidangarske merged 1 commit into
wolfSSL:masterfrom
dgarske:ecc_no_harden

Conversation

@dgarske

@dgarske dgarske commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Description

Regression in v4.2.0. Broken by #582 (items 1 and 2), #597 (item 3). ZD 22550

A wolfSSL build without ECC_TIMING_RESISTANT (a user_settings.h build that omits it, or --disable-harden) gets NOT_COMPILED_IN from three ECC paths in src/tpm2_wrap.c that worked in v4.1.0. Reported by a customer as wolfTPM2_StartSession failing while building the encrypted salt.

1. ECC salted sessions and import seeds

wolfTPM2_EncryptSecret_ECC() and the TPM_ALG_ECC case in wolfTPM2_EncryptSecret() were compiled out without the macro, so a session salted with an ECC key, or an import under an ECC parent, returned NOT_COMPILED_IN. The guard is back to HAVE_ECC, !WC_NO_RNG and WOLFSSL_PUBLIC_MP. The RNG is still attached to both keys when timing resistance is available.

2. Private-only ECC key import

wolfTPM2_EccMakePubBlinded() returned NOT_COMPILED_IN without the macro. It now falls back to wc_ecc_make_pub(). The blinded wc_ecc_make_pub_ex() path is unchanged in hardened builds.

3. SPDM requester key auto-generation

wolfTPM2_SpdmConnectNuvoton() and wolfTPM2_SpdmConnectNations() returned NOT_COMPILED_IN when no requester key was supplied. The ephemeral P-384 key generation is enabled for any HAVE_ECC build again.
Whether wolfCrypt's ECC is timing resistant is a wolfSSL build choice, and wolfSSL already warns at build time when it is off. wolfTPM should not turn that choice into a runtime failure.

Testing

Adds an ECC case to test_wolfTPM2_EncryptSecret, a private-only import test for wolfTPM2_CreateEccKeyBlob, and a no-harden CI job that builds wolfSSL with --disable-harden and runs make check and run_examples.sh. Run against wolfSSL 5.9.4 built with and without --disable-harden, on the fwTPM and on ibmswtpm2. The SPDM paths are compile-tested only.

@dgarske dgarske self-assigned this Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 22:09

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The no-harden CI job does not compile either changed vendor SPDM path.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Restores ECC operations in wolfSSL builds without ECC_TIMING_RESISTANT.

Changes:

  • Re-enables ECC secret encryption and unblinded private-key public derivation.
  • Re-enables SPDM requester key generation.
  • Adds regression tests and no-harden CI coverage.
File Description
src/​tpm2_wrap.c Restores non-hardened ECC paths.
tests/​unit_tests.c Tests ECC secret encryption and private-only imports.
.github/​workflows/​make-test-swtpm.yml Adds no-harden testing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/make-test-swtpm.yml
@aidangarske
aidangarske merged commit 8b2d12a into wolfSSL:master Oct 1, 2026
230 checks passed
@aidangarske
aidangarske deleted the ecc_no_harden branch October 1, 2026 23:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants