yklymenko commented on PR #293:
URL: 
https://github.com/apache/santuario-xml-security-java/pull/293#issuecomment-2010377978

   > My suggestion is To remove DH("DH", "PKCS #3", KeyAlgorithmType.DH, 
"1.2.840.113549.1.3.1"), From KeyType
   > 
   > The Diffie-Hellman key agreement using RSA keys is gradually becoming 
obsolete and currently, it is not supported by the xmlsec key agreement method 
implementation. I included it there primarily for the sake of completeness, 
anticipating that someone might (but not very likely) add support for 
Diffie-Hellman in the future.
   > 
   > Beside CodeQL marks it as potentially unsecure: 
![image](https://private-user-images.githubusercontent.com/10476027/314425015-cee43c42-90f3-4746-bb7e-ba5c7dceb5dc.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MTA5NTk4OTYsIm5iZiI6MTcxMDk1OTU5NiwicGF0aCI6Ii8xMDQ3NjAyNy8zMTQ0MjUwMTUtY2VlNDNjNDItOTBmMy00NzQ2LWJiN2UtYmE1YzdkY2ViNWRjLnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNDAzMjAlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjQwMzIwVDE4MzMxNlomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTY0MzM3YmI0Zjc0YTExZWE0MmE3ZTU3NThjOTNmYTk5MzdjODYzYzk3Y2I2N2I5MjY2OWIzNjY3MTZlYTVhYTkmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0JmFjdG9yX2lkPTAma2V5X2lkPTAmcmVwb19pZD0wIn0.Bi-FKOj4IsE4Lxl1iAp_iRr8doNZ1PQprvPo3_UcuC8)
   
   In general, I've looked in BC how they decide, which oid should be used. 
They have both oid's as aliases and select one of them depending on 
configuration in 
org.bouncycastle.jcajce.provider.asymmetric.dh.BCDHPublicKey#getEncoded (see 
both return statements)
   Sure, I can delete two or three lines to make it green again, but I'm not 
sure, that this should be a part of this PR 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to