Tracking issue for constant-time implementation problems
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 20/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- rust
- Área
- cryptography, security
Línea de trabajo
Start by reading the linked draft-irtf-cfrg-rsa-guidance sections and reviewing related issues #710, #702, and #626 to identify which recommendations remain unaddressed. This is a broad tracking issue with existing contributors working on it; done means a specific unchecked recommendation is resolved and its checklist entry can be marked complete, with coordination before any contribution.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
draft-irtf-cfrg-rsa-guidance contains plenty of guidance for how to implement RSA in constant time correctly. This is an issue tracking what parts of its recommendations we're currently missing.
Note we have a separate issue #626 specifically to track padding defects and the lack of implicit rejection on padding failures.
- Make private-result integer-to-octet conversion fixed-width and constant-time (see §6.1, §7.2, partly addressed in #710)
- Ignore the first encoded-message octet when depadding OAEP (see §7)
- Apply base blinding by default across private-key operations (see §6.1, partly addressed in #702)
- Audit and replace CRT reductions using division by secret primes including
rem_vartimefor mod reduce (see §6.1, §6.2) - Derive private arithmetic buffer widths from the public modulus (§6.2.1)
- Add fresh exponent blinding for each private operation (see §6.4)
- Add CRT modulus blinding (see §6.5)
- Require exactly
kciphertext octets for PKCS#1 v1.5 decryption (see §7.2, addressed in #710)
NOTE: I'd kindly request that people do NOT open PRs that try to vibe code solutions to these problems. We already have people including myself working on these issues and vibe coded PRs clutter the tracker and just generally waste my time.
- Lenguaje dominante
- Rust
- Estrellas
- 672
- Forks
- 193
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de RustCrypto/RSA
-
Silent salt_len truncation in signature_algorithm_identifier() causes signature verification failuresPosiblemente ocupada @cong-or la tomó hace 72 días. Abierto
Dificultad 3/5 Medio día Aptitud para principiantes 74/100
RustCrypto/RSA#703 ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
RustCrypto/RSA#686 · 4 comentarios ·
-
`rsa` v0.10 release trackingAbierto
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
RustCrypto/RSA#647 · 10 comentarios · 2 reacciones ·
-
broken rust docsAbierto
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
RustCrypto/RSA#641 · 3 reacciones ·
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
RustCrypto/RSA#640 ·
Todos los issues de RustCrypto/RSA
Issues similares
-
test(executor_l0): assert execute() TaskOutcome, not only bus events / 断言 execute() 返回的 TaskOutcomeAbiertotype:debt
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
skaiy/wild_agentos#425 ·
Los mantenedores suelen responder en 1 día
-
Default-import note suggests `import * as process` for velt:process, which does not name the builtinAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
bug ticket
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
cratestack/cratestack#1154 ·
Los mantenedores suelen responder en 1 día
-
status:needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
agentic-os-org/ANOLISA#6742 · 1 comentario ·
Los mantenedores suelen responder en 1 día