Device identity: CSR signed with non exportable TEE/StrongBox Key - #376
Conversation
PR Reviewer Guide 🔍Here are some key observations to aid the review process:
|
PR Code Suggestions ✨Explore these optional code suggestions:
|
||||||||||||||
User description
Reference to issue #358 and continuation of PR #373
PR Type
Enhancement
Description
Implement CSR generation with hardware-backed key signing
Replace AsyncTask with Chromium's network thread architecture
Add OpenSSL-based PKCS#10 CSR creation functionality
Update enrollment API to use CSR-based authentication
Diagram Walkthrough
File Walkthrough
wootz_keystore.cc
Add OpenSSL-based CSR generation with hardware signingsrc/net/android/wootz_keystore.cc
GenerateCSRfunction with PKCS#10 complianceSignWithHardwareKeyJNI_WootzHardwareKeyStore_GenerateCSRfor Javaintegration
WootzDeviceEnrollment.java
Migrate to thread-based networking with CSR enrollmentsrc/net/android/java/src/org/chromium/net/WootzDeviceEnrollment.java
WootzEnrollmentUtils.java
Add CSR enrollment JSON utilitiessrc/net/android/java/src/org/chromium/net/WootzEnrollmentUtils.java
createCSREnrollmentRequestJsonmethod for new API formatconvertPemChainToArrayfor certificate chain parsingescapeJsonStringutility for proper JSON encodingWootzHardwareKeyStore.java
Add CSR generation with native OpenSSL integrationsrc/net/android/java/src/org/chromium/net/WootzHardwareKeyStore.java
@NativeMethodsinterface for JNI CSR generationgenerateCSRmethod calling native OpenSSL implementationgenerateDeviceIdentifierfor unique device identificationsignWithHardwareKeydocumentation for CSR signing contextwootz_keystore.h
Add CSR generation function declarationsrc/net/android/wootz_keystore.h
GenerateCSRfunction declaration with OpenSSL implementation