From 8bc7217902a49348d31647251fe9f4937b08a5f3 Mon Sep 17 00:00:00 2001 From: Kyungwook Tak Date: Wed, 13 Jan 2016 10:14:48 +0900 Subject: Not to set DKEK value to DEK struct salt attribute DEK struct salt value is derived from DKEK. It's not clear to be stored on multiple data which is security-sensitive. Change-Id: Ie3684e350d12dce132cb9425de3b075e25dbb63e Signed-off-by: Kyungwook Tak --- src/manager/service/key-provider.cpp | 1 - 1 file changed, 1 deletion(-) diff --git a/src/manager/service/key-provider.cpp b/src/manager/service/key-provider.cpp index eddc4728..7abba872 100644 --- a/src/manager/service/key-provider.cpp +++ b/src/manager/service/key-provider.cpp @@ -343,7 +343,6 @@ RawBuffer KeyProvider::generateDEK(const std::string &smackLabel) ThrowErr(Exc::InternalError, "GenerateDEK Failed in KeyProvider::generateDEK"); wkmcDEK.setKeyInfoKeyLength((unsigned int)wrappedKeyLength); - wkmcDEK.setKeyInfoSalt(m_kmcDKEK->getKeyAndInfo().key, MAX_SALT_SIZE); wkmcDEK.setKeyInfoLabel(resized_smackLabel); LogDebug("GenerateDEK Success"); -- cgit v1.2.3