Spell Bleichenbacher's name right.
Change-Id: I2096f760165f7aaa9b5d922a2e6d4d755365087b Reviewed-on: https://boringssl-review.googlesource.com/1372 Reviewed-by: Adam Langley <agl@google.com>
This commit is contained in:
committed by
Adam Langley
parent
533cbee57e
commit
8cc0b24cdd
@@ -271,7 +271,7 @@ int RSA_padding_check_PKCS1_type_2(uint8_t *to, unsigned tlen,
|
||||
|
||||
/* NOTE: Although |RSA_message_index_PKCS1_type_2| itself is constant time,
|
||||
* the API contracts of this function and |RSA_decrypt| with
|
||||
* |RSA_PKCS1_PADDING| make it impossible to completely avoid Bleichenbacker's
|
||||
* |RSA_PKCS1_PADDING| make it impossible to completely avoid Bleichenbacher's
|
||||
* attack. */
|
||||
if (!RSA_message_index_PKCS1_type_2(from, flen, &msg_index)) {
|
||||
OPENSSL_PUT_ERROR(RSA, RSA_padding_check_PKCS1_type_2,
|
||||
|
||||
@@ -166,7 +166,7 @@ OPENSSL_EXPORT int RSA_private_decrypt(int flen, const uint8_t *from,
|
||||
* length |from_len - *out_index|. Otherwise, it returns zero and sets
|
||||
* |*out_index| to some undefined value. This function runs in time independent
|
||||
* of the input data and is intended to be used directly to avoid
|
||||
* Bleichenbacker's attack.
|
||||
* Bleichenbacher's attack.
|
||||
*
|
||||
* WARNING: This function behaves differently from the usual OpenSSL convention
|
||||
* in that it does NOT put an error on the queue in the error case. */
|
||||
|
||||
Reference in New Issue
Block a user