diff options
author | Shane Lontis <shane.lontis@oracle.com> | 2021-03-29 13:38:00 +1000 |
---|---|---|
committer | Shane Lontis <shane.lontis@oracle.com> | 2021-04-01 09:07:08 +1000 |
commit | e454a3934c287aede194cac49c8934f04bf6a04f (patch) | |
tree | c43916f0a50c5e2d1a9aa1caa00539c0629f1175 /util | |
parent | 9e6f30e683fd0f243cf15d2bac2cdef2bcbbac12 (diff) |
Add a range check (from SP800-56Ar3) to DH key derivation.
Fixes #14401
Note that this moves the public key check out of DH compute_key() since
key validation does not belong inside this primitive..
The check has been moved to the EVP_PKEY_derive_set_peer() function so that
it generally applies to all exchange operations.. Use EVP_PKEY_derive_set_peer_ex()
to disable this behaviour.
Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Paul Dale <pauli@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/14717)
Diffstat (limited to 'util')
-rw-r--r-- | util/libcrypto.num | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/util/libcrypto.num b/util/libcrypto.num index ce70b2fe65..b968e0da1f 100644 --- a/util/libcrypto.num +++ b/util/libcrypto.num @@ -5332,3 +5332,4 @@ TS_RESP_CTX_new_ex ? 3_0_0 EXIST::FUNCTION:TS X509_REQ_new_ex ? 3_0_0 EXIST::FUNCTION: EVP_PKEY_dup ? 3_0_0 EXIST::FUNCTION: RSA_PSS_PARAMS_dup ? 3_0_0 EXIST::FUNCTION: +EVP_PKEY_derive_set_peer_ex ? 3_0_0 EXIST::FUNCTION: |