Skip to content

pk/rsa: use correct invariant when checking parameter d#100

Merged
hannesm merged 2 commits into
mirage:mainfrom
psafont:lambda
Jan 21, 2021
Merged

pk/rsa: use correct invariant when checking parameter d#100
hannesm merged 2 commits into
mirage:mainfrom
psafont:lambda

Conversation

@psafont

@psafont psafont commented Jan 21, 2021

Copy link
Copy Markdown
Contributor

The correct invariant is d ≡ e⁻¹ (mod λ(n)), this means that the modulus is applied to both d and e⁻¹, which was not done with the previous check.

In practice this means that RSA keys using d = (p - 1) * (q - 1) instead of d = lcm (p - 1) (q - 1) could fail this test when they are valid.

Note: (FIPS 186-4 is more strict and would use the check previously used, but I think it should be an optional check)

It's d parameter is bigger than e ^ -1 mod LCM (p - 1) (q - 1) which is
licit as long as d and e ^ - 1 are congruent with respect of LCM (p - 1)
(q - 1).

Signed-off-by: Pau Ruiz Safont <pau.safont@citrix.com>
The previous invariant didn't apply the modulus to d, which made it fail
on some valid keys.

Signed-off-by: Pau Ruiz Safont <pau.safont@citrix.com>
@hannesm

hannesm commented Jan 21, 2021

Copy link
Copy Markdown
Member

thanks

@hannesm
hannesm merged commit e79c800 into mirage:main Jan 21, 2021
hannesm added a commit to hannesm/opam-repository that referenced this pull request Jan 21, 2021
…age-crypto-rng-mirage and mirage-crypto-rng-async (0.8.10)

CHANGES:

- Rsa.priv: require 1 = d * e mod (lam n). This allows interoperability with
  OpenSSL generated keys. Reported and fixed by @psafont in mirage/mirage-crypto#100.
@psafont
psafont deleted the lambda branch January 21, 2021 13:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants