update master-with-bazel from master branch
This commit is contained in:
+18
-18
File diff suppressed because one or more lines are too long
@@ -21,6 +21,11 @@ PublicKey = RSA-2048-SPKI-Negative
|
||||
Input = 30820121300d06092a864886f70d01010105000382010e003082010902820100cd0081ea7b2ae1ea06d59f7c73d9ffb94a09615c2e4ba7c636cef08dd3533ec3185525b015c769b99a77d6725bf9c3532a9b6e5f6627d5fb85160768d3dda9cbd35974511717dc3d309d2fc47ee41f97e32adb7f9dd864a1c4767a666ecd71bc1aacf5e7517f4b38594fea9b05e42d5ada9912008013e45316a4d9bb8ed086b88d28758bacaf922d46a868b485d239c9baeb0e2b64592710f42b2d1ea0a4b4802c0becab328f8a68b0073bdb546feea9809d2849912b390c1532bc7e29c7658f8175fae46f34332ff87bcab3e40649b98577869da0ea718353f0722754886913648760d122be676e0fc483dd20ffc31bda96a31966c9aa2e75ad03de47e1c44f0203010001
|
||||
Error = NEGATIVE_NUMBER
|
||||
|
||||
# An RSA key with an even modulus
|
||||
PublicKey = RSA-2048-Even-Modulus
|
||||
Input = 30820122300d06092a864886f70d01010105000382010f003082010a0282010100cd0081ea7b2ae1ea06d59f7c73d9ffb94a09615c2e4ba7c636cef08dd3533ec3185525b015c769b99a77d6725bf9c3532a9b6e5f6627d5fb85160768d3dda9cbd35974511717dc3d309d2fc47ee41f97e32adb7f9dd864a1c4767a666ecd71bc1aacf5e7517f4b38594fea9b05e42d5ada9912008013e45316a4d9bb8ed086b88d28758bacaf922d46a868b485d239c9baeb0e2b64592710f42b2d1ea0a4b4802c0becab328f8a68b0073bdb546feea9809d2849912b390c1532bc7e29c7658f8175fae46f34332ff87bcab3e40649b98577869da0ea718353f0722754886913648760d122be676e0fc483dd20ffc31bda96a31966c9aa2e75ad03de47e1c44e0203010001
|
||||
Error = BAD_RSA_PARAMETERS
|
||||
|
||||
# The same key but with missing parameters rather than a NULL.
|
||||
PublicKey = RSA-2048-SPKI-Invalid
|
||||
Input = 30820120300b06092a864886f70d0101010382010f003082010a0282010100cd0081ea7b2ae1ea06d59f7c73d9ffb94a09615c2e4ba7c636cef08dd3533ec3185525b015c769b99a77d6725bf9c3532a9b6e5f6627d5fb85160768d3dda9cbd35974511717dc3d309d2fc47ee41f97e32adb7f9dd864a1c4767a666ecd71bc1aacf5e7517f4b38594fea9b05e42d5ada9912008013e45316a4d9bb8ed086b88d28758bacaf922d46a868b485d239c9baeb0e2b64592710f42b2d1ea0a4b4802c0becab328f8a68b0073bdb546feea9809d2849912b390c1532bc7e29c7658f8175fae46f34332ff87bcab3e40649b98577869da0ea718353f0722754886913648760d122be676e0fc483dd20ffc31bda96a31966c9aa2e75ad03de47e1c44f0203010001
|
||||
|
||||
@@ -787,7 +787,8 @@ int RSA_check_key(const RSA *key) {
|
||||
|
||||
// Check that p * q == n. Before we multiply, we check that p and q are in
|
||||
// bounds, to avoid a DoS vector in |bn_mul_consttime| below. Note that
|
||||
// n was bound by |rsa_check_public_key|.
|
||||
// n was bound by |rsa_check_public_key|. This also implicitly checks p and q
|
||||
// are odd, which is a necessary condition for Montgomery reduction.
|
||||
if (BN_is_negative(key->p) || BN_cmp(key->p, key->n) >= 0 ||
|
||||
BN_is_negative(key->q) || BN_cmp(key->q, key->n) >= 0) {
|
||||
OPENSSL_PUT_ERROR(RSA, RSA_R_N_NOT_EQUAL_P_Q);
|
||||
|
||||
@@ -85,6 +85,13 @@ int rsa_check_public_key(const RSA *rsa) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
// RSA moduli must be odd. In addition to being necessary for RSA in general,
|
||||
// we cannot setup Montgomery reduction with even moduli.
|
||||
if (!BN_is_odd(rsa->n)) {
|
||||
OPENSSL_PUT_ERROR(RSA, RSA_R_BAD_RSA_PARAMETERS);
|
||||
return 0;
|
||||
}
|
||||
|
||||
// Mitigate DoS attacks by limiting the exponent size. 33 bits was chosen as
|
||||
// the limit based on the recommendations in [1] and [2]. Windows CryptoAPI
|
||||
// doesn't support values larger than 32 bits [3], so it is unlikely that
|
||||
|
||||
Reference in New Issue
Block a user