1# 2# Copyright (c) 2015-2018, ARM Limited and Contributors. All rights reserved. 3# 4# SPDX-License-Identifier: BSD-3-Clause 5# 6 7ifneq (${MBEDTLS_COMMON_MK},1) 8MBEDTLS_COMMON_MK := 1 9 10# MBEDTLS_DIR must be set to the mbed TLS main directory (it must contain 11# the 'include' and 'library' subdirectories). 12ifeq (${MBEDTLS_DIR},) 13 $(error Error: MBEDTLS_DIR not set) 14endif 15 16MBEDTLS_INC = -I${MBEDTLS_DIR}/include 17INCLUDES += -Iinclude/drivers/auth/mbedtls 18 19# Specify mbed TLS configuration file 20MBEDTLS_CONFIG_FILE := "<mbedtls_config.h>" 21$(eval $(call add_define,MBEDTLS_CONFIG_FILE)) 22 23MBEDTLS_SOURCES += drivers/auth/mbedtls/mbedtls_common.c 24 25 26LIBMBEDTLS_SRCS := $(addprefix ${MBEDTLS_DIR}/library/, \ 27 asn1parse.c \ 28 asn1write.c \ 29 memory_buffer_alloc.c \ 30 oid.c \ 31 platform.c \ 32 platform_util.c \ 33 bignum.c \ 34 md.c \ 35 md_wrap.c \ 36 pk.c \ 37 pk_wrap.c \ 38 pkparse.c \ 39 pkwrite.c \ 40 sha256.c \ 41 sha512.c \ 42 ecdsa.c \ 43 ecp_curves.c \ 44 ecp.c \ 45 rsa.c \ 46 rsa_internal.c \ 47 x509.c \ 48 x509_crt.c \ 49 ) 50 51# The platform may define the variable 'TF_MBEDTLS_KEY_ALG' to select the key 52# algorithm to use. If the variable is not defined, select it based on algorithm 53# used for key generation `KEY_ALG`. If `KEY_ALG` is not defined or is 54# defined to `rsa`/`rsa_1_5`, then set the variable to `rsa`. 55ifeq (${TF_MBEDTLS_KEY_ALG},) 56 ifeq (${KEY_ALG}, ecdsa) 57 TF_MBEDTLS_KEY_ALG := ecdsa 58 else 59 TF_MBEDTLS_KEY_ALG := rsa 60 endif 61endif 62 63ifeq (${HASH_ALG}, sha384) 64 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA384 65else ifeq (${HASH_ALG}, sha512) 66 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA512 67else 68 TF_MBEDTLS_HASH_ALG_ID := TF_MBEDTLS_SHA256 69endif 70 71ifeq (${TF_MBEDTLS_KEY_ALG},ecdsa) 72 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_ECDSA 73else ifeq (${TF_MBEDTLS_KEY_ALG},rsa) 74 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_RSA 75else ifeq (${TF_MBEDTLS_KEY_ALG},rsa+ecdsa) 76 TF_MBEDTLS_KEY_ALG_ID := TF_MBEDTLS_RSA_AND_ECDSA 77else 78 $(error "TF_MBEDTLS_KEY_ALG=${TF_MBEDTLS_KEY_ALG} not supported on mbed TLS") 79endif 80 81# Needs to be set to drive mbed TLS configuration correctly 82$(eval $(call add_define,TF_MBEDTLS_KEY_ALG_ID)) 83$(eval $(call add_define,TF_MBEDTLS_HASH_ALG_ID)) 84 85 86$(eval $(call MAKE_LIB,mbedtls)) 87 88endif 89