From 0448a7ea68d845e31a4703c4e2db8940d89cb920 Mon Sep 17 00:00:00 2001 From: David Baker Date: Thu, 9 Jan 2020 20:46:36 +0000 Subject: [PATCH] Sign key backup with cross-signing key on upgrade Add a signature from the cross-signing master key to the key backup when upgrading the key backup into cross-signing. For https://github.com/vector-im/riot-web/issues/11747 --- src/crypto/index.js | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/src/crypto/index.js b/src/crypto/index.js index 6e3f8e534..879bd706d 100644 --- a/src/crypto/index.js +++ b/src/crypto/index.js @@ -28,6 +28,7 @@ import ReEmitter from '../ReEmitter'; import logger from '../logger'; const utils = require("../utils"); +const httpApi = require("../http-api"); const OlmDevice = require("./OlmDevice"); const olmlib = require("./olmlib"); const algorithms = require("./algorithms"); @@ -418,6 +419,25 @@ Crypto.prototype.bootstrapSecretStorage = async function({ // Add an entry for the backup key in SSSS as a 'passthrough' key // (ie. the secret is the key itself). this._secretStorage.storePassthrough('m.megolm_backup.v1', newKeyId); + + // if this key backup is trusted, sign it with the cross signing key + // so the key backup can be trusted via cross-signing. + const backupSigStatus = await this.checkKeyBackup(keyBackupInfo); + if (backupSigStatus.trustInfo.usable) { + console.log("Adding cross signing signature to key backup"); + await this._crossSigningInfo.signObject( + keyBackupInfo.auth_data, "master", + ); + await this._baseApis._http.authedRequest( + undefined, "PUT", "/room_keys/version/" + keyBackupInfo.version, + undefined, keyBackupInfo, + {prefix: httpApi.PREFIX_UNSTABLE}, + ); + } else { + console.log( + "Key backup is NOT TRUSTED: NOT adding cross signing signature", + ); + } } else { logger.log("Secret storage default key not found, creating new key"); const keyOptions = await createSecretStorageKey();