mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
1fb05038cd
Since OpenSSL 3.1 a new RSA-PSS salt length constant exists to select the maximum possible salt length based on the RSA-PSS parameters and the digest used: OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO_DIGEST_MAX This is the default salt length when no other salt length is set by the caller. In contrast to OSSL_PKEY_RSA_PSS_SALT_LEN_MAX, OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO_DIGEST_MAX also ensures that the resulting salt length is not larger than the used digest size. The salt length calculated with OSSL_PKEY_RSA_PSS_SALT_LEN_MAX may be larger than the digest size, dependent on the RSA-PSS parameters. FIPS 186-4 section 5 "The RSA Digital Signature Algorithm", subsection 5.5 "PKCS #1" says: "For RSASSA-PSS […] the length (in bytes) of the salt (sLen) shall satisfy 0 <= sLen <= hLen, where hLen is the length of the hash function output block (in bytes)." See OpenSSL commit https://github.com/openssl/openssl/commit/6c73ca4a2f4ea71f4a880670624e7b2fdb6f32da Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
151 KiB
151 KiB