From 3bff80aee3d7d9198a889ab0f7b7caf15791ca21 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Tue, 19 Nov 2013 15:00:28 +0100 Subject: [PATCH] openssl: Verify that a peer's ECDH public value is a point on the elliptic curve This check is mandated by RFC 6989. Since we don't reuse DH secrets, it is mostly a sanity check. --- .../plugins/openssl/openssl_ec_diffie_hellman.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/libstrongswan/plugins/openssl/openssl_ec_diffie_hellman.c b/src/libstrongswan/plugins/openssl/openssl_ec_diffie_hellman.c index c43fe455a..835ed586e 100644 --- a/src/libstrongswan/plugins/openssl/openssl_ec_diffie_hellman.c +++ b/src/libstrongswan/plugins/openssl/openssl_ec_diffie_hellman.c @@ -102,6 +102,11 @@ static bool chunk2ecp(const EC_GROUP *group, chunk_t chunk, EC_POINT *point) goto error; } + if (!EC_POINT_is_on_curve(group, point, ctx)) + { + goto error; + } + ret = TRUE; error: BN_CTX_end(ctx);