xref: /aosp_15_r20/external/mbedtls/include/psa/crypto_config.h (revision 62c56f9862f102b96d72393aff6076c951fb8148)
1*62c56f98SSadaf Ebrahimi /**
2*62c56f98SSadaf Ebrahimi  * \file psa/crypto_config.h
3*62c56f98SSadaf Ebrahimi  * \brief PSA crypto configuration options (set of defines)
4*62c56f98SSadaf Ebrahimi  *
5*62c56f98SSadaf Ebrahimi  */
6*62c56f98SSadaf Ebrahimi #if defined(MBEDTLS_PSA_CRYPTO_CONFIG)
7*62c56f98SSadaf Ebrahimi /**
8*62c56f98SSadaf Ebrahimi  * When #MBEDTLS_PSA_CRYPTO_CONFIG is enabled in mbedtls_config.h,
9*62c56f98SSadaf Ebrahimi  * this file determines which cryptographic mechanisms are enabled
10*62c56f98SSadaf Ebrahimi  * through the PSA Cryptography API (\c psa_xxx() functions).
11*62c56f98SSadaf Ebrahimi  *
12*62c56f98SSadaf Ebrahimi  * To enable a cryptographic mechanism, uncomment the definition of
13*62c56f98SSadaf Ebrahimi  * the corresponding \c PSA_WANT_xxx preprocessor symbol.
14*62c56f98SSadaf Ebrahimi  * To disable a cryptographic mechanism, comment out the definition of
15*62c56f98SSadaf Ebrahimi  * the corresponding \c PSA_WANT_xxx preprocessor symbol.
16*62c56f98SSadaf Ebrahimi  * The names of cryptographic mechanisms correspond to values
17*62c56f98SSadaf Ebrahimi  * defined in psa/crypto_values.h, with the prefix \c PSA_WANT_ instead
18*62c56f98SSadaf Ebrahimi  * of \c PSA_.
19*62c56f98SSadaf Ebrahimi  *
20*62c56f98SSadaf Ebrahimi  * Note that many cryptographic mechanisms involve two symbols: one for
21*62c56f98SSadaf Ebrahimi  * the key type (\c PSA_WANT_KEY_TYPE_xxx) and one for the algorithm
22*62c56f98SSadaf Ebrahimi  * (\c PSA_WANT_ALG_xxx). Mechanisms with additional parameters may involve
23*62c56f98SSadaf Ebrahimi  * additional symbols.
24*62c56f98SSadaf Ebrahimi  */
25*62c56f98SSadaf Ebrahimi #else
26*62c56f98SSadaf Ebrahimi /**
27*62c56f98SSadaf Ebrahimi  * When \c MBEDTLS_PSA_CRYPTO_CONFIG is disabled in mbedtls_config.h,
28*62c56f98SSadaf Ebrahimi  * this file is not used, and cryptographic mechanisms are supported
29*62c56f98SSadaf Ebrahimi  * through the PSA API if and only if they are supported through the
30*62c56f98SSadaf Ebrahimi  * mbedtls_xxx API.
31*62c56f98SSadaf Ebrahimi  */
32*62c56f98SSadaf Ebrahimi #endif
33*62c56f98SSadaf Ebrahimi /*
34*62c56f98SSadaf Ebrahimi  *  Copyright The Mbed TLS Contributors
35*62c56f98SSadaf Ebrahimi  *  SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later
36*62c56f98SSadaf Ebrahimi  */
37*62c56f98SSadaf Ebrahimi 
38*62c56f98SSadaf Ebrahimi #ifndef PSA_CRYPTO_CONFIG_H
39*62c56f98SSadaf Ebrahimi #define PSA_CRYPTO_CONFIG_H
40*62c56f98SSadaf Ebrahimi 
41*62c56f98SSadaf Ebrahimi /*
42*62c56f98SSadaf Ebrahimi  * CBC-MAC is not yet supported via the PSA API in Mbed TLS.
43*62c56f98SSadaf Ebrahimi  */
44*62c56f98SSadaf Ebrahimi //#define PSA_WANT_ALG_CBC_MAC                    1
45*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_CBC_NO_PADDING             1
46*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_CBC_PKCS7                  1
47*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_CCM                        1
48*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_CCM_STAR_NO_TAG            1
49*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_CMAC                       1
50*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_CFB                        1
51*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_CHACHA20_POLY1305          1
52*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_CTR                        1
53*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_DETERMINISTIC_ECDSA        1
54*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_ECB_NO_PADDING             1
55*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_ECDH                       1
56*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_FFDH                       1
57*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_ECDSA                      1
58*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_JPAKE                      1
59*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_GCM                        1
60*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_HKDF                       1
61*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_HKDF_EXTRACT               1
62*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_HKDF_EXPAND                1
63*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_HMAC                       1
64*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_MD5                        1
65*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_OFB                        1
66*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_PBKDF2_HMAC                1
67*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_PBKDF2_AES_CMAC_PRF_128    1
68*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_RIPEMD160                  1
69*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_RSA_OAEP                   1
70*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_RSA_PKCS1V15_CRYPT         1
71*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_RSA_PKCS1V15_SIGN          1
72*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_RSA_PSS                    1
73*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA_1                      1
74*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA_224                    1
75*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA_256                    1
76*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA_384                    1
77*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA_512                    1
78*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA3_224                   1
79*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA3_256                   1
80*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA3_384                   1
81*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_SHA3_512                   1
82*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_STREAM_CIPHER              1
83*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_TLS12_PRF                  1
84*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_TLS12_PSK_TO_MS            1
85*62c56f98SSadaf Ebrahimi #define PSA_WANT_ALG_TLS12_ECJPAKE_TO_PMS       1
86*62c56f98SSadaf Ebrahimi 
87*62c56f98SSadaf Ebrahimi /* XTS is not yet supported via the PSA API in Mbed TLS.
88*62c56f98SSadaf Ebrahimi  * Note: when adding support, also adjust include/mbedtls/config_psa.h */
89*62c56f98SSadaf Ebrahimi //#define PSA_WANT_ALG_XTS                        1
90*62c56f98SSadaf Ebrahimi 
91*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_BRAINPOOL_P_R1_256         1
92*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_BRAINPOOL_P_R1_384         1
93*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_BRAINPOOL_P_R1_512         1
94*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_MONTGOMERY_255             1
95*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_MONTGOMERY_448             1
96*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_SECP_K1_192                1
97*62c56f98SSadaf Ebrahimi /*
98*62c56f98SSadaf Ebrahimi  * SECP224K1 is buggy via the PSA API in Mbed TLS
99*62c56f98SSadaf Ebrahimi  * (https://github.com/Mbed-TLS/mbedtls/issues/3541). Thus, do not enable it by
100*62c56f98SSadaf Ebrahimi  * default.
101*62c56f98SSadaf Ebrahimi  */
102*62c56f98SSadaf Ebrahimi //#define PSA_WANT_ECC_SECP_K1_224                1
103*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_SECP_K1_256                1
104*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_SECP_R1_192                1
105*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_SECP_R1_224                1
106*62c56f98SSadaf Ebrahimi /* For secp256r1, consider enabling #MBEDTLS_PSA_P256M_DRIVER_ENABLED
107*62c56f98SSadaf Ebrahimi  * (see the description in mbedtls/mbedtls_config.h for details). */
108*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_SECP_R1_256                1
109*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_SECP_R1_384                1
110*62c56f98SSadaf Ebrahimi #define PSA_WANT_ECC_SECP_R1_521                1
111*62c56f98SSadaf Ebrahimi 
112*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_DERIVE                1
113*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_PASSWORD              1
114*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_PASSWORD_HASH         1
115*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_HMAC                  1
116*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_AES                   1
117*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_ARIA                  1
118*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_CAMELLIA              1
119*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_CHACHA20              1
120*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_DES                   1
121*62c56f98SSadaf Ebrahimi //#define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR          1 /* Deprecated */
122*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_ECC_PUBLIC_KEY        1
123*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_DH_PUBLIC_KEY         1
124*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_RAW_DATA              1
125*62c56f98SSadaf Ebrahimi //#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR          1 /* Deprecated */
126*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_RSA_PUBLIC_KEY        1
127*62c56f98SSadaf Ebrahimi 
128*62c56f98SSadaf Ebrahimi /*
129*62c56f98SSadaf Ebrahimi  * The following symbols extend and deprecate the legacy
130*62c56f98SSadaf Ebrahimi  * PSA_WANT_KEY_TYPE_xxx_KEY_PAIR ones. They include the usage of that key in
131*62c56f98SSadaf Ebrahimi  * the name's suffix. "_USE" is the most generic and it can be used to describe
132*62c56f98SSadaf Ebrahimi  * a generic suport, whereas other ones add more features on top of that and
133*62c56f98SSadaf Ebrahimi  * they are more specific.
134*62c56f98SSadaf Ebrahimi  */
135*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_BASIC      1
136*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_IMPORT   1
137*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_EXPORT   1
138*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_GENERATE 1
139*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_ECC_KEY_PAIR_DERIVE   1
140*62c56f98SSadaf Ebrahimi 
141*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_BASIC      1
142*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_IMPORT   1
143*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_EXPORT   1
144*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_GENERATE 1
145*62c56f98SSadaf Ebrahimi //#define PSA_WANT_KEY_TYPE_RSA_KEY_PAIR_DERIVE   1 /* Not supported */
146*62c56f98SSadaf Ebrahimi 
147*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_BASIC       1
148*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_IMPORT    1
149*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_EXPORT    1
150*62c56f98SSadaf Ebrahimi #define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_GENERATE  1
151*62c56f98SSadaf Ebrahimi //#define PSA_WANT_KEY_TYPE_DH_KEY_PAIR_DERIVE    1 /* Not supported */
152*62c56f98SSadaf Ebrahimi 
153*62c56f98SSadaf Ebrahimi #endif /* PSA_CRYPTO_CONFIG_H */
154