summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
author Justin McClain <justinmcclain@google.com> 2022-02-23 19:45:12 +0000
committer Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com> 2022-02-23 19:45:12 +0000
commit75b5c61d45dada4107288924ac1a7ee092ff0fac (patch)
tree6a1f0bed19f6823f878c24456f63bb0ee8e3ba2e
parenta872a084119cc079ed295df22e6b10abc5f2f7b4 (diff)
parent9e70a83ea0c54d4cb62b720155782edf2f00f1a3 (diff)
Merge "Add vendor_required_attestation_certificates to be used by Attestation Verification Framework and Partner overlay." am: 9e70a83ea0
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/1965239 Change-Id: Ibfcd4cb5a913d6766cf6f4fad5beea4f7eeba22b
-rw-r--r--core/res/res/values/symbols.xml1
-rw-r--r--core/res/res/values/vendor_required_attestation_certificates.xml32
2 files changed, 33 insertions, 0 deletions
diff --git a/core/res/res/values/symbols.xml b/core/res/res/values/symbols.xml
index 9e8efeb4730c..0afa09c89cd1 100644
--- a/core/res/res/values/symbols.xml
+++ b/core/res/res/values/symbols.xml
@@ -1278,6 +1278,7 @@
<java-symbol type="array" name="vendor_required_apps_managed_user" />
<java-symbol type="array" name="vendor_required_apps_managed_profile" />
<java-symbol type="array" name="vendor_required_apps_managed_device" />
+ <java-symbol type="array" name="vendor_required_attestation_certificates" />
<java-symbol type="array" name="vendor_disallowed_apps_managed_user" />
<java-symbol type="array" name="vendor_disallowed_apps_managed_profile" />
<java-symbol type="array" name="vendor_disallowed_apps_managed_device" />
diff --git a/core/res/res/values/vendor_required_attestation_certificates.xml b/core/res/res/values/vendor_required_attestation_certificates.xml
new file mode 100644
index 000000000000..ce5660f433ff
--- /dev/null
+++ b/core/res/res/values/vendor_required_attestation_certificates.xml
@@ -0,0 +1,32 @@
+<?xml version="1.0" encoding="utf-8"?>
+<!--
+/**
+ * Copyright (C) 2022 The Android Open Source Project
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+-->
+<resources>
+ <!-- The PEM-encoded certificates added here are used for verifying attestations.
+ The trustworthiness of the attestation depends on the root certificate of the chain.
+
+ Certificates that can be used can be retrieved from:
+ https://developer.android.com/training/articles/security-key-attestation#root_certificate.
+
+ If not already present in resource overlay, please add
+ vendor_required_attestation_certificates.xml (matching this file) in vendor overlay
+ with <item></item> of the PEM-encoded root certificates.
+ -->
+ <string-array translatable="false" name="vendor_required_attestation_certificates">
+ </string-array>
+</resources>