cst creates invalid RSA-PSS signatures with old OpenSSL

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

cst creates invalid RSA-PSS signatures with old OpenSSL

60 Views
danielgloeckner
Contributor II

When using cst with OpenSSL < 3.1 the salt used in the PSS signatures is too long. Processors like the i.MX91 expect the salt to have the same length as the digest, but before OpenSSL 3.1 the default was to make the salt as big as possible.

But even with newer OpenSSL versions using the default is not good as it will accept shorter salts during signature verification.

The fix is to call EVP_PKEY_CTX_set_rsa_pss_saltlen with second parameter set to RSA_PSS_SALTLEN_DIGEST.

Note that OpenSSL 3.0 is EOL since last month.

Labels (1)
0 Kudos
Reply
0 Replies
%3CLINGO-SUB%20id%3D%22lingo-sub-2418323%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3Ecst%20creates%20invalid%20RSA-PSS%20signatures%20with%20old%20OpenSSL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2418323%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CP%3EWhen%20using%20cst%20with%20OpenSSL%20%26lt%3B%203.1%20the%20salt%20used%20in%20the%20PSS%20signatures%20is%20too%20long.%20Processors%20like%20the%20i.MX91%20expect%20the%20salt%20to%20have%20the%20same%20length%20as%20the%20digest%2C%20but%20before%20OpenSSL%203.1%20the%20default%20was%20to%20make%20the%20salt%20as%20big%20as%20possible.%3C%2FP%3E%3CP%3EBut%20even%20with%20newer%20OpenSSL%20versions%20using%20the%20default%20is%20not%20good%20as%20it%20will%20accept%20shorter%20salts%20during%20signature%20verification.%3C%2FP%3E%3CP%3EThe%20fix%20is%20to%20call%20EVP_PKEY_CTX_set_rsa_pss_saltlen%20with%20second%20parameter%20set%20to%20RSA_PSS_SALTLEN_DIGEST.%3C%2FP%3E%3CP%3ENote%20that%20OpenSSL%203.0%20is%20EOL%20since%20last%20month.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2418323%22%20slang%3D%22en-US%22%20mode%3D%22CREATE%22%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E