Commit 5d695c9
Fix loading PKCS#3 DH parameters with privateValueLength (#15045)
A PKCS#3 "DH PARAMETERS" structure may carry an optional trailing
INTEGER, privateValueLength. The loader parsed every DH parameters blob
with the X9.42-shaped struct (p, g, q?), so it misread privateValueLength
as the subprime q. Since #15016 added a check_key() validation, this now
fails with "Invalid DH parameters".
Route the PEM loader by tag: "DH PARAMETERS" (PKCS#3) ignores
privateValueLength, while "X9.42 DH PARAMETERS" keeps q. The DER loader
stays X9.42-permissive since DER carries no tag to disambiguate and the
existing rfc5114 DER vectors require q to be parsed.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent 61b250a commit 5d695c9
4 files changed
Lines changed: 57 additions & 13 deletions
File tree
- docs/development
- src/rust/src/backend
- tests/hazmat/primitives
- vectors/cryptography_vectors/asymmetric/DH
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
353 | 353 | | |
354 | 354 | | |
355 | 355 | | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
356 | 361 | | |
357 | 362 | | |
358 | 363 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
71 | 71 | | |
72 | 72 | | |
73 | 73 | | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
74 | 100 | | |
75 | 101 | | |
76 | 102 | | |
77 | 103 | | |
78 | 104 | | |
79 | 105 | | |
80 | 106 | | |
81 | | - | |
82 | | - | |
83 | | - | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | | - | |
89 | | - | |
90 | | - | |
91 | | - | |
92 | | - | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
93 | 110 | | |
94 | 111 | | |
95 | 112 | | |
| |||
105 | 122 | | |
106 | 123 | | |
107 | 124 | | |
108 | | - | |
| 125 | + | |
109 | 126 | | |
110 | 127 | | |
111 | 128 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
979 | 979 | | |
980 | 980 | | |
981 | 981 | | |
| 982 | + | |
| 983 | + | |
| 984 | + | |
| 985 | + | |
| 986 | + | |
| 987 | + | |
| 988 | + | |
| 989 | + | |
| 990 | + | |
| 991 | + | |
| 992 | + | |
| 993 | + | |
| 994 | + | |
| 995 | + | |
982 | 996 | | |
983 | 997 | | |
984 | 998 | | |
| |||
Lines changed: 8 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
0 commit comments