diff options
author | schwarze <> | 2017-08-20 20:45:18 +0000 |
---|---|---|
committer | schwarze <> | 2017-08-20 20:45:18 +0000 |
commit | f6b981f4a6516aead24667ad1b21501c3bfcbe99 (patch) | |
tree | f15fe87f4cbdafa8779aea6ed151b54bfa5fb173 | |
parent | 9870f9e03c46ab5263c4ccabf4e8b39aaed76e4e (diff) | |
download | openbsd-f6b981f4a6516aead24667ad1b21501c3bfcbe99.tar.gz openbsd-f6b981f4a6516aead24667ad1b21501c3bfcbe99.tar.bz2 openbsd-f6b981f4a6516aead24667ad1b21501c3bfcbe99.zip |
Add a BUGS section
stating that RSA_padding_check_PKCS1_type_2(3) is weak by design;
from Emilia Kasper <emilia at openssl dot org>
via OpenSSL commit 1e3f62a3 Jul 17 16:47:13 2017 +0200.
-rw-r--r-- | src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3 | 13 |
1 files changed, 10 insertions, 3 deletions
diff --git a/src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3 b/src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3 index 2c7fdb66c7..29a0eae1b4 100644 --- a/src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3 +++ b/src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3 | |||
@@ -1,5 +1,5 @@ | |||
1 | .\" $OpenBSD: RSA_padding_add_PKCS1_type_1.3,v 1.4 2016/12/11 12:21:48 schwarze Exp $ | 1 | .\" $OpenBSD: RSA_padding_add_PKCS1_type_1.3,v 1.5 2017/08/20 20:45:18 schwarze Exp $ |
2 | .\" OpenSSL 99d63d46 Oct 26 13:56:48 2016 -0400 | 2 | .\" OpenSSL 1e3f62a3 Jul 17 16:47:13 2017 +0200 |
3 | .\" | 3 | .\" |
4 | .\" This file was written by Ulf Moeller <ulf@openssl.org>. | 4 | .\" This file was written by Ulf Moeller <ulf@openssl.org>. |
5 | .\" Copyright (c) 2000 The OpenSSL Project. All rights reserved. | 5 | .\" Copyright (c) 2000 The OpenSSL Project. All rights reserved. |
@@ -48,7 +48,7 @@ | |||
48 | .\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED | 48 | .\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED |
49 | .\" OF THE POSSIBILITY OF SUCH DAMAGE. | 49 | .\" OF THE POSSIBILITY OF SUCH DAMAGE. |
50 | .\" | 50 | .\" |
51 | .Dd $Mdocdate: December 11 2016 $ | 51 | .Dd $Mdocdate: August 20 2017 $ |
52 | .Dt RSA_PADDING_ADD_PKCS1_TYPE_1 3 | 52 | .Dt RSA_PADDING_ADD_PKCS1_TYPE_1 3 |
53 | .Os | 53 | .Os |
54 | .Sh NAME | 54 | .Sh NAME |
@@ -246,3 +246,10 @@ appeared in SSLeay 0.9.0. | |||
246 | and | 246 | and |
247 | .Fn RSA_padding_check_PKCS1_OAEP | 247 | .Fn RSA_padding_check_PKCS1_OAEP |
248 | were added in OpenSSL 0.9.2b. | 248 | were added in OpenSSL 0.9.2b. |
249 | .Sh BUGS | ||
250 | The | ||
251 | .Fn RSA_padding_check_PKCS1_type_2 | ||
252 | padding check leaks timing information which can potentially be | ||
253 | used to mount a Bleichenbacher padding oracle attack. | ||
254 | This is an inherent weakness in the PKCS #1 v1.5 padding design. | ||
255 | Prefer PKCS1_OAEP padding. | ||