Treat RSASSA-PSS keys like rsaEncryption RSA keys

In theory we should treat any parameters and the identifier itself as
restriction to only use the key to create signatures accordingly (e.g.
only use RSA with PSS padding or even use specific hash algorithms).
But that's currently tricky as we'd have to store and pass this information
along with our private keys (i.e. use PKCS#8 to store them and change the
builder calls to pass along the identifier and parameters). That would
require quite some work.
This commit is contained in:
Tobias Brunner
2017-11-08 16:48:10 +01:00
parent fb63012e0c
commit 364395d2de
3 changed files with 20 additions and 1 deletions
@@ -63,6 +63,16 @@ static private_key_t *parse_private_key(chunk_t blob)
switch (oid)
{
case OID_RSASSA_PSS:
/* TODO: parameters associated with such keys should be
* treated as restrictions later when signing (the type
* itself is already a restriction). However, the
* builders currently don't expect any parameters for
* RSA keys (we also only pass along the params, not the
* exact type, so we'd have to guess that params
* indicate RSA/PSS, but they are optional so that won't
* work for keys without specific restrictions) */
params = chunk_empty;
case OID_RSA_ENCRYPTION:
type = KEY_RSA;
break;