Tracking issue for constant-time implementation problems
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 20/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- rust
- Ambito
- cryptography, security
Direzione di ricerca
Start by reading the linked draft-irtf-cfrg-rsa-guidance sections and reviewing related issues #710, #702, and #626 to identify which recommendations remain unaddressed. This is a broad tracking issue with existing contributors working on it; done means a specific unchecked recommendation is resolved and its checklist entry can be marked complete, with coordination before any contribution.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
draft-irtf-cfrg-rsa-guidance contains plenty of guidance for how to implement RSA in constant time correctly. This is an issue tracking what parts of its recommendations we're currently missing.
Note we have a separate issue #626 specifically to track padding defects and the lack of implicit rejection on padding failures.
- Make private-result integer-to-octet conversion fixed-width and constant-time (see §6.1, §7.2, partly addressed in #710)
- Ignore the first encoded-message octet when depadding OAEP (see §7)
- Apply base blinding by default across private-key operations (see §6.1, partly addressed in #702)
- Audit and replace CRT reductions using division by secret primes including
rem_vartimefor mod reduce (see §6.1, §6.2) - Derive private arithmetic buffer widths from the public modulus (§6.2.1)
- Add fresh exponent blinding for each private operation (see §6.4)
- Add CRT modulus blinding (see §6.5)
- Require exactly
kciphertext octets for PKCS#1 v1.5 decryption (see §7.2, addressed in #710)
NOTE: I'd kindly request that people do NOT open PRs that try to vibe code solutions to these problems. We already have people including myself working on these issues and vibe coded PRs clutter the tracker and just generally waste my time.
- Lingua principale
- Rust
- Stelle
- 673
- Fork
- 192
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di RustCrypto/RSA
-
Silent salt_len truncation in signature_algorithm_identifier() causes signature verification failuresForse già presa @cong-or l’ha presa 71 giorni fa. Aperta
Difficoltà 3/5 Mezza giornata Idoneità per principianti 74/100
RustCrypto/RSA#703 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
RustCrypto/RSA#686 · 4 commenti ·
-
`rsa` v0.10 release trackingAperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
RustCrypto/RSA#647 · 10 commenti · 2 reazioni ·
-
broken rust docsAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
RustCrypto/RSA#641 · 3 reazioni ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
RustCrypto/RSA#640 ·
Tutte le issue di RustCrypto/RSA
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
app enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 80/100
elodin-sys/elodin#890 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
guidance-ai/llguidance#391 ·