summaryrefslogtreecommitdiff
path: root/src/lib
diff options
context:
space:
mode:
authorschwarze <>2017-08-20 20:45:18 +0000
committerschwarze <>2017-08-20 20:45:18 +0000
commitf6b981f4a6516aead24667ad1b21501c3bfcbe99 (patch)
treef15fe87f4cbdafa8779aea6ed151b54bfa5fb173 /src/lib
parent9870f9e03c46ab5263c4ccabf4e8b39aaed76e4e (diff)
downloadopenbsd-f6b981f4a6516aead24667ad1b21501c3bfcbe99.tar.gz
openbsd-f6b981f4a6516aead24667ad1b21501c3bfcbe99.tar.bz2
openbsd-f6b981f4a6516aead24667ad1b21501c3bfcbe99.zip
Add a BUGS section
stating that RSA_padding_check_PKCS1_type_2(3) is weak by design; from Emilia Kasper <emilia at openssl dot org> via OpenSSL commit 1e3f62a3 Jul 17 16:47:13 2017 +0200.
Diffstat (limited to 'src/lib')
-rw-r--r--src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.313
1 files changed, 10 insertions, 3 deletions
diff --git a/src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3 b/src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3
index 2c7fdb66c7..29a0eae1b4 100644
--- a/src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3
+++ b/src/lib/libcrypto/man/RSA_padding_add_PKCS1_type_1.3
@@ -1,5 +1,5 @@
1.\" $OpenBSD: RSA_padding_add_PKCS1_type_1.3,v 1.4 2016/12/11 12:21:48 schwarze Exp $ 1.\" $OpenBSD: RSA_padding_add_PKCS1_type_1.3,v 1.5 2017/08/20 20:45:18 schwarze Exp $
2.\" OpenSSL 99d63d46 Oct 26 13:56:48 2016 -0400 2.\" OpenSSL 1e3f62a3 Jul 17 16:47:13 2017 +0200
3.\" 3.\"
4.\" This file was written by Ulf Moeller <ulf@openssl.org>. 4.\" This file was written by Ulf Moeller <ulf@openssl.org>.
5.\" Copyright (c) 2000 The OpenSSL Project. All rights reserved. 5.\" Copyright (c) 2000 The OpenSSL Project. All rights reserved.
@@ -48,7 +48,7 @@
48.\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED 48.\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
49.\" OF THE POSSIBILITY OF SUCH DAMAGE. 49.\" OF THE POSSIBILITY OF SUCH DAMAGE.
50.\" 50.\"
51.Dd $Mdocdate: December 11 2016 $ 51.Dd $Mdocdate: August 20 2017 $
52.Dt RSA_PADDING_ADD_PKCS1_TYPE_1 3 52.Dt RSA_PADDING_ADD_PKCS1_TYPE_1 3
53.Os 53.Os
54.Sh NAME 54.Sh NAME
@@ -246,3 +246,10 @@ appeared in SSLeay 0.9.0.
246and 246and
247.Fn RSA_padding_check_PKCS1_OAEP 247.Fn RSA_padding_check_PKCS1_OAEP
248were added in OpenSSL 0.9.2b. 248were added in OpenSSL 0.9.2b.
249.Sh BUGS
250The
251.Fn RSA_padding_check_PKCS1_type_2
252padding check leaks timing information which can potentially be
253used to mount a Bleichenbacher padding oracle attack.
254This is an inherent weakness in the PKCS #1 v1.5 padding design.
255Prefer PKCS1_OAEP padding.