Skip to content

ECDSA signing key derived from math/rand instead of crypto/rand #350

Description

@raballew

Description

The OIDC signing key in controller/internal/oidc/op.go:35-38 is derived using math/rand seeded by 8 bytes of SHA-256(CONTROLLER_KEY). This is not a cryptographically secure PRNG.

  • Same CONTROLLER_KEY always produces the same ECDSA private key
  • math/rand.Seed() reduces to ~2^63 distinct PRNG states
  • Tokens are valid for 365 days with hardcoded kid: "default", preventing graceful rotation
  • Any leak of CONTROLLER_KEY (env vars, crash dump, secrets-job compromise) yields instant key recovery

Suggested Fix

Replace rand.NewSource(int64(...)) / rand.New(source) with crypto/rand.Reader passed directly to keygen.ECDSALegacy. Remove SHA-256 truncation and seed derivation.

Impact

Token forgery if CONTROLLER_KEY is leaked. Deterministic keys across environments sharing the same CONTROLLER_KEY.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions