summaryrefslogtreecommitdiff
path: root/src/lib/libcrypto/dsa/dsa_err.c (unfollow)
Commit message (Collapse)AuthorFilesLines
2025-01-11Move compressed coordinate setting into public APItb3-108/+83
Now that it is method-agnostic, we can remove the method and move the implementation to the body of the public API function. And another method goes away. We're soon down to the ones we really need. discussed with jsing
2025-01-11Rework ec_point_set_compressed_coordinates()tb1-18/+14
While this is nicely done, it is a bit too clever. We can do the calculation in the normal domain rather than the Montgomery domain and this way the method becomes method agnostic. This will be a bit slower but since a couple of field operations are nothing compared to the cost of BN_mod_sqrt() this isn't a concern. ok jsing
2025-01-11Move ec_points_make_affine() to the right placetb1-135/+135
discussed with jsing
2025-01-11Move the EC_POINTs API into the garbage bintb1-20/+20
2025-01-11Neuter the EC_POINTs_* APItb4-77/+16
EC_POINTs_mul() was only ever used by Ruby and they stopped doing so for LibreSSL when we incorporated the constant time multiplication work of Brumley et al and restricted the length of the points array to 1, making this API effectively useless. The only real reason you want to have an API to calculate \sum n_i P_i is for ECDSA where you want m * G + n * P. Whether something like his needs to be in the public API is doubtful. EC_POINTs_make_affine() is an implementation detail of EC_POINTs_mul(). As such it never really belonged into the public API. ok jsing
2025-01-11Remove a pointless check about Z == 1tb1-7/+1
ok jsing
2025-01-11Inline ec_point_make_affine() in the public APItb3-44/+22
Whatever the EC_METHOD, this will always be equivalent to getting and setting the affine coordinates, so this needs no dedicated method. Also, this is a function that makes no real sense since a caller should never need to care about this... As always, our favorite language bindings thought they might have users who care. This time it's Ruby and Perl. ok jsing
2025-01-11Remove seven pairs of unnecessary parenthesestb1-5/+5
ok millert operator(7)
2025-01-09When describing v3 crypt, be specific as to which machine was simulated.jsg1-3/+3
feedback jmc@ ok deraadt@ schwarze@
2025-01-09ec_lib.c: zap stray empty line at end of filetb1-2/+1
2025-01-09check_discriminant: make the assumptions on p, a, b more explicittb1-2/+3
requested by jsing
2025-01-08Improve order of things in BN_RECP_CTX_set()tb1-3/+4
+ some whitespace cosmetics
2025-01-08Remove parentheses in return statementstb1-8/+8
2025-01-08Add a space after commatb1-3/+3
2025-01-08Remove superfluous parenthesestb1-13/+13
2025-01-08X509_NAME_print() also fails to indenttb1-5/+6
2025-01-07X509_NAME_print: remove lie about multiple lines being usedtb1-4/+2
OpenSSL commit 92ada7cc (2007) removed some dead code with flawed logic attempting to print multiple lines if the line exceeded 80 characters. Said flawed logic was there since the start of the git history importing SSLeay 0.8.1b in 1998 and never worked. Rumor has it that it did work prior to that. Be that as it may, it's just wrongly documented since Henson added the docs in commit 0711be16 (2002). Prompted by OpenSSL issue #18004 by davidben https://github.com/quictls/quictls/pull/168 https://github.com/quictls/quictls/issues/75
2025-01-07Rewrite TS_ASN1_INTEGER_print_bio()tb1-14/+19
This eliminates another stupid BN_free(&bn) and uses BIO_printf() rather than a ludicrously silly result dance. In fact it appears that this dance was so hard to grok that OpenSSL misread it and made this function return the value -1 on ASN1_INTEGER_to_BN() failure, a value that it had never returned before. It doesn't matter anyway. The only uses of this function are internal to OpenSSL's code and since TS fully conforms to OpenSSL's high QA standards, no caller checks the return of TS_ASN1_INTEGER_print_bio(). ok jsing
2025-01-07Remove stale comment about methods and memberstb1-6/+1
2025-01-07Check discriminant directly in EC_GROUP_set_discriminant()tb3-68/+47
After possibly decoding a and b in EC_GROUP_get_curve(), this is a pure calculation in GFp and as such doesn't make use of any method-specifics. Let's perform this calculation directly in the public API implementation rather than redirecting through the methods and remove yet another method handler. ok jsing
2025-01-06unitialized -> uninitializedtb1-2/+2
2025-01-06ec_lib: create a garbage bin at the end, throw Jprojective stuff in theretb1-19/+24
2025-01-06Inline the last two uses of ec_mont_group_clear()tb1-14/+11
2025-01-06typo: slighty -> slightlytb1-2/+2
2025-01-06group_copy() is no longer a thing...tb1-3/+1
2025-01-06Remove get_order_bits() and get_degree() methodstb3-28/+5
The degree made some sense when EC2M was a thing in libcrypto. Fortunately that's not the case anymore. The order handler never made sense. ok jsing
2025-01-06More dest -> dst renaming missed in previoustb1-8/+8
requested by jsing
2025-01-06Rename dest into dsttb1-21/+21
requested by jsing
2025-01-06Inline the copy handlers in EC_GROUP_copy()tb2-51/+19
This is another bit of indirection that makes this code so hard to follow. ok jsing
2025-01-06Use a slightly more sensible order in ec_local.htb1-36/+33
2025-01-06BN_div_recp() can't be static since it is directly exercised by bn_test.ctb2-3/+5
2025-01-06fix ugly whitespacetb1-4/+4
2025-01-06Revise comments to note that these are Jacobian projective coordinates.jsing1-3/+6
2025-01-06Shuffle functions into a more sensible ordertb2-42/+39
BN_reciprocal() is only called by BN_div_recp() which in turn is only called by BN_mod_mul_reciprocal(). So use this order and make the first two static.
2025-01-06Remove indirection for coordinate blinding.jsing3-28/+4
This is usually method specific, so remove the indirection and call the appropriate blinding function directly. ok tb@
2025-01-06Stop caching one in the Montgomery domaintb3-56/+16
This is only used by ec_points_make_affine(), which is only used by the wNAF multiplication, which is only used by ECDSA. We can afford computing that one once per ECDSA verification given the cost of the rest of this. Thus, the field_set_to_one() member disappears from the EC_METHOD and the mont_one member disappears from EC_GROUP and with it all the complications when setting/copying/freeing the group. ok jsing
2025-01-06Prepare removal accessors for Jprojective coordinatestb3-150/+16
That the BN-driven EC code uses Jacobian projective coordinates as an optimization is an implementation detail. As such this should never have leaked out of the library as part of the public API. No consumer should ever care and if they do they're doing it wrong. The only port that cares is one of those stupid little perl modules that expose all the things and transform terrible OpenSSL regress tests into similarly horrible Perl. In practice, only affine coordinates matter (perhaps in compressed form). This prunes two more function pointers from EC_GROUP and prepares the removal of the field_set_to_one() method which is now only used in ec_points_make_affine(). ok jsing sthen
2025-01-06An -> Thetb1-2/+2
There's only one inverse and in standard affine coordinates it only has one representation.
2025-01-06Print the inverse in affine coordinatestb1-8/+3
This way we can get rid of the stupidity that is publicly exposed Jprojective coordinates soon.
2025-01-05Let's use RSA_3 rather than 3tb1-2/+2
2025-01-05Move BIGNUMs in EC_GROUP and EC_POINT to the heaptb5-194/+208
The only way to get an EC_GROUP or an EC_POINT is by calling the relevant _new() function and to get rid of it, something must call _free(). Thus we can establish the invariant that every group has Weierstrass coefficients p, a, b as well as order and cofactor hanging off it. Similarly, Every point has allocated BIGNUMs for its Jacobian projective coordinates. Unfortunately, a group has the generator as an optional component in addition to seed and montgomery context/one (where optionality makes more sense). This is a mostly mechanical diff and only drops a few silly comments and a couple of unnecessary NULL checks since in our part of the wrold the word invariant has a meaning. This should also appease Coverity who likes to throw fits at calling BN_free() for BIGNUM on the stack (yes, this is actually a thing). ok jsing
2025-01-05Stop setting RSA_FLAG_SIGN_VERtb1-2/+1
With rsa_sign.c r1.37 this is no longer needed.
2025-01-05Remove most of the RSA_FLAG_SIGN_VER documentationtb2-33/+6
ok jsing kn
2025-01-05Stop requiring the RSA_FLAG_SIGN_VERtb2-7/+5
You can set custom sign and verify handlers on an RSA method (wihch is used to create RSA private and public key handles). However, even if you set them explicitly with RSA_meth_set_{sign,verify}(3), these handlers aren't used for the sake of "backward compatibility" (with what?). In order to use them, you need to opt your objects into using the custom methods you set by setting the RSA_FLAG_SIGN_VER flag. OpenSSL 1.1 dropped this requirement and therefore nobody sets this flag anyore. Like most of the mechanically added accessors, almost nothing uses them, but, as found by kn, the yubco-piv-tool does. This resulted in a public key being passed to rsa_private_encrypt(), which of course doesn't end well. So follow OpenSSL 1.1 and drop this muppetry. This makes kn's problem with yubico-piv-tool go away. ok jsing kn
2025-01-04rsa_method_test: some consistency tweakstb1-6/+5
2025-01-04fix typotb1-2/+2
2025-01-04Add some regress coverage for custom RSA methodstb2-1/+280
This currently only covers sign and verify since other parts are already known to work in practice. Prompted by a bug report by kn
2025-01-04rsa tests: tidy up the makefiletb1-7/+8
2025-01-03termianted -> terminatedtb1-2/+2
2025-01-03Fix typo: multipy -> multiplytb2-18/+18
Reflow the comment to avoid some very unfortunate line wraps. "Note that" is like "literally" a bunch of generally useless noise and best omitted.