Visitar URL original
require the x-only choice for rSig in ECDSAEncoder.toX962 by rootvector2 · Pull Request #2496 · bcgit/bc-java · GitHub
Skip to content

require the x-only choice for rSig in ECDSAEncoder.toX962 - #2496

Open
rootvector2 wants to merge 1 commit into
bcgit:mainfrom
rootvector2:its-rsig-x-only
Open

rootvector2 wants to merge 1 commit into
bcgit:mainfrom
rootvector2:its-rsig-x-only

Conversation

@rootvector2

Copy link
Copy Markdown
Contributor

ECDSAEncoder.toX962 reads the ITS signature's r without checking which EccP256CurvePoint or EccP384CurvePoint choice carried it, so a signature re-encoded with rSig as compressed-y-0 or compressed-y-1 (the same 32 x octets) yields an identical r and still verifies, giving one signature three interchangeable encodings and letting a re-encoded certificate keep verifying under a different HashedId8, while the fill and uncompressed choices escape signatureValid and isSignatureValid as an unchecked IllegalArgumentException; found checking the IEEE 1609.2 sec. 6.3.29 x-only requirement against the decoder, and r is now required to be of form x-only in both branches.

AI tooling was used to help prepare this change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant