Skip to content

rsa: reject secret keys whose primes are not 1024 bits - #30

Merged
karalabe merged 1 commit into
dark-bio:mainfrom
karalabe:rsa-key-checks
Sep 24, 2026
Merged

karalabe merged 1 commit into
dark-bio:mainfrom
karalabe:rsa-key-checks

Conversation

@karalabe

Copy link
Copy Markdown
Member

The raw encoding holds each prime in 128 bytes, but DER import accepted any 2048-bit key. Marshal then panicked on a 1025-bit first prime, or overwrote the first prime's field with a 1025-bit second one. DER import now requires two 1024-bit primes. New tests also pin the raw rejection of repeated primes and oversized private exponents, with the same test vectors as the Rust fix.

The raw encoding holds each prime in 128 bytes, but DER import accepted
any 2048-bit key. Marshal then panicked on a 1025-bit first prime, or
overwrote the first prime's field with a 1025-bit second one. DER import
now requires two 1024-bit primes. New tests also pin the raw rejection of
repeated primes and oversized private exponents, with the same test
vectors as the Rust fix.
@karalabe
karalabe merged commit f124c8e into dark-bio:main Sep 24, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant