COMMITS
19
in the last month
RECENT COMMITS
D
The seven OpenPGP signature subpackets whose body RFC 9580 defines as a fixed length now all enforce that length where the subpacket is parsed rather than deferring it to an accessor, only Signature Expiration Time having done so, since SignatureSubpacketInputStream.readPacket validated a declared body length for range and for the case where it overran the subpacket area but handed a body whose declared length matched the octets it carried to the constructor whatever that length was, so Signature Creation Time and Key Expiration Time reported a body that was not the four octets of a time field, Exportable Certification, Revocable and Primary User ID a body that was not the single zero or one octet of a flag, and Issuer Key ID one shorter than a key ID, as an unchecked IllegalStateException out of org.bouncycastle.bcpg.sig.Utils or an IllegalArgumentException out of FingerprintUtil.readKeyID when the value was read, which matters because such a body inside a self-signature is content the signer signed over, so a certificate carrying one verified as valid and failed only later in ordinary reader code - PGPPublicKey.getValidSeconds(), PGPSignatureSubpacketVector.getKeyExpirationTime() and isExportable(), OpenPGPCertificate.getExpirationTime(), and the keyserver re-export path PGPPublicKeyRing.encode(out, true), which declares IOException - and the length and flag-value checks now sit as shared statics beside the accessors they protect, with Signature Expiration Time's own check folded into them, a malformed subpacket refused at parse time as a MalformedPacketException the way Features, Trust Signature and Notation Data already were, and the parser's tolerance of a fixed-length field whose declared length overruns the subpacket area preserved, BytesBooleansTest being wired into the openpgp suite it had never been registered in, relates to github #2426. David Hook
9eadfc9 D
Every classical signer now assembles the signature component s through the constant-time BigIntegers.modMult, modAdd and the new modSubtract rather than BigInteger.multiply and mod, whose cost follows the quotient and which were being handed the signing key, covering ECDSA, SM2, DSA, GOST 3410, ECGOST 3410, DSTU 4145, EC-NR and BIP 340, with the public hash-derived value reduced on the way in wherever it could sit at or past the order, DSAPrivateKeyParameters and GOST3410PrivateKeyParameters now holding x to the [1, q-1] their own parameters imply, and the two GOST signers redrawing a nonce that is zero or at or past the order rather than leaving it to be folded by the reduction that followed. David Hook
a219442