Browse Source

crypto: add padding to diffie-hellman key

DH_size returns number of bytes in a prime number, DH_compute_key returns number
of bytes in a remainder of exponent, which may have less bytes than a prime
number. Therefore add 0-padding to the allocated buffer.

Fixes #3372
v0.9.1-release
Fedor Indutny 13 years ago
parent
commit
ae5b0e1fc1
  1. 9
      src/node_crypto.cc
  2. 41
      test/pummel/test-dh-regr.js

9
src/node_crypto.cc

@ -3959,6 +3959,15 @@ class DiffieHellman : public ObjectWrap {
Local<Value> outString; Local<Value> outString;
// DH_size returns number of bytes in a prime number
// DH_compute_key returns number of bytes in a remainder of exponent, which
// may have less bytes than a prime number. Therefore add 0-padding to the
// allocated buffer.
if (size != dataSize) {
assert(dataSize > size);
memset(data + size, 0, dataSize - size);
}
if (size == -1) { if (size == -1) {
int checkResult; int checkResult;
if (!DH_check_pub_key(diffieHellman->dh, key, &checkResult)) { if (!DH_check_pub_key(diffieHellman->dh, key, &checkResult)) {

41
test/pummel/test-dh-regr.js

@ -0,0 +1,41 @@
// Copyright Joyent, Inc. and other Node contributors.
//
// Permission is hereby granted, free of charge, to any person obtaining a
// copy of this software and associated documentation files (the
// "Software"), to deal in the Software without restriction, including
// without limitation the rights to use, copy, modify, merge, publish,
// distribute, sublicense, and/or sell copies of the Software, and to permit
// persons to whom the Software is furnished to do so, subject to the
// following conditions:
//
// The above copyright notice and this permission notice shall be included
// in all copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
// OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
// USE OR OTHER DEALINGS IN THE SOFTWARE.
var common = require('../common');
var assert = require('assert');
var crypto = require('crypto');
var p = crypto.createDiffieHellman(256).getPrime();
for (var i = 0; i < 2000; i++) {
var a = crypto.createDiffieHellman(p),
b = crypto.createDiffieHellman(p);
a.generateKeys();
b.generateKeys();
assert.equal(
a.computeSecret(b.getPublicKey()),
b.computeSecret(a.getPublicKey()),
'secrets should be equal!'
);
}
Loading…
Cancel
Save