How to store a symmetric cryptographic key in the macOS keychain?

Viewed 227

I'm trying to store a 512-bit key into the macOS keychain. However, when I run the SecItemAdd function, I get a return value of -25303 errSecNoSuchAttr. How can I best solve this?

So far, I've tried removing the kSecAttrKeyType, kSecAttrKeyClass, and kSecAttrKeySizeInBits attributes. These solve the error with SecItemAdd, but break the stored keychain item (it cannot be looked up/removed).

This is the code I've got so far (based on this example):

var newKeyData = Data(count: 64)
_ = newKeyData.withUnsafeMutableBytes { SecRandomCopyBytes(nil, 64, $0) }

let keyTag = "com.example.accessKey".data(using: .utf8)!
let keyQuery: [CFString: Any] = [
    kSecClass: kSecClassKey,
    kSecAttrKeyType: kSecAttrKeyTypeAES, // Removal leads to broken item
    kSecAttrKeyClass: kSecAttrKeyClassSymmetric, // Removal leads to broken
    kSecAttrApplicationTag: keyTag,
    kSecAttrKeySizeInBits: 512, // Removal leads to broken item
    kSecValueData: newKeyData
]

let status = SecItemAdd(addQuery as CFDictionary, nil) // Returns -25303

I would expect this query to work fine, since all keys I used are listed in the documentation. Any help in fixing this would be greatly appreciated!

0 Answers
Related