The branch master has been updated via 6364475a990449ef33fc270ac00472f7210220f2 (commit) from 681acb311bb7c68c9310d2e96bf2cf0e35443a22 (commit)
- Log ----------------------------------------------------------------- commit 6364475a990449ef33fc270ac00472f7210220f2 Author: Samuel Weiser <samuel.wei...@iaik.tugraz.at> Date: Fri Sep 29 13:29:25 2017 +0200 Added const-time flag to DSA key decoding to avoid potential leak of privkey Reviewed-by: Richard Levitte <levi...@openssl.org> Reviewed-by: Rich Salz <rs...@openssl.org> (Merged from https://github.com/openssl/openssl/pull/4440) ----------------------------------------------------------------------- Summary of changes: crypto/dsa/dsa_ameth.c | 1 + 1 file changed, 1 insertion(+) diff --git a/crypto/dsa/dsa_ameth.c b/crypto/dsa/dsa_ameth.c index 7c0428d..fbb9121 100644 --- a/crypto/dsa/dsa_ameth.c +++ b/crypto/dsa/dsa_ameth.c @@ -175,6 +175,7 @@ static int dsa_priv_decode(EVP_PKEY *pkey, const PKCS8_PRIV_KEY_INFO *p8) goto dsaerr; } + BN_set_flags(dsa->priv_key, BN_FLG_CONSTTIME); if (!BN_mod_exp(dsa->pub_key, dsa->g, dsa->priv_key, dsa->p, ctx)) { DSAerr(DSA_F_DSA_PRIV_DECODE, DSA_R_BN_ERROR); goto dsaerr; _____ openssl-commits mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits