diffie-hellman: Verify public DH values in backends
This commit is contained in:
@@ -79,6 +79,11 @@ METHOD(diffie_hellman_t, set_other_public_value, bool,
|
||||
gcry_mpi_t p_min_1;
|
||||
gcry_error_t err;
|
||||
|
||||
if (!diffie_hellman_verify_value(this->group, value))
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
if (this->yb)
|
||||
{
|
||||
gcry_mpi_release(this->yb);
|
||||
|
||||
@@ -90,6 +90,11 @@ METHOD(diffie_hellman_t, set_other_public_value, bool,
|
||||
{
|
||||
mpz_t p_min_1;
|
||||
|
||||
if (!diffie_hellman_verify_value(this->group, value))
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
mpz_init(p_min_1);
|
||||
mpz_sub_ui(p_min_1, this->p, 1);
|
||||
|
||||
|
||||
@@ -92,6 +92,11 @@ METHOD(diffie_hellman_t, set_other_public_value, bool,
|
||||
{
|
||||
int len;
|
||||
|
||||
if (!diffie_hellman_verify_value(this->group, value))
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
BN_bin2bn(value.ptr, value.len, this->pub_key);
|
||||
chunk_clear(&this->shared_secret);
|
||||
this->shared_secret.ptr = malloc(DH_size(this->dh));
|
||||
|
||||
@@ -219,6 +219,11 @@ error:
|
||||
METHOD(diffie_hellman_t, set_other_public_value, bool,
|
||||
private_openssl_ec_diffie_hellman_t *this, chunk_t value)
|
||||
{
|
||||
if (!diffie_hellman_verify_value(this->group, value))
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
if (!chunk2ecp(this->ec_group, value, this->pub_key))
|
||||
{
|
||||
DBG1(DBG_LIB, "ECDH public value is malformed");
|
||||
|
||||
@@ -116,6 +116,11 @@ static bool derive_secret(private_pkcs11_dh_t *this, chunk_t other)
|
||||
METHOD(diffie_hellman_t, set_other_public_value, bool,
|
||||
private_pkcs11_dh_t *this, chunk_t value)
|
||||
{
|
||||
if (!diffie_hellman_verify_value(this->group, value))
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
switch (this->group)
|
||||
{
|
||||
case ECP_192_BIT:
|
||||
|
||||
Reference in New Issue
Block a user