BUG: sign DATA over 512 bytes doesn't work
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 42/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- python
- Domain
- cryptography, security
Research direction
Reproduce the issue with the Python script shown in the report, focusing on priv.sign(..., mechanism=Mechanism.ECDSA_SHA256) and the DataLenRange traceback through pkcs11/_pkcs11.pyx. Check the surrounding signing implementation and existing tests for input-length handling. Done means signing data over 512 bytes no longer raises this error and the resulting signature passes the verification step.
Written by the indexing model from the issue text.
Description
I have the following python script:
#! /usr/bin/env python3
import os
import pkcs11
from Crypto.Hash import SHA256
from Crypto.PublicKey import ECC
from Crypto.Signature import DSS
from pkcs11 import KeyType, ObjectClass, Mechanism
from pkcs11.util.ec import encode_ec_public_key
lib = pkcs11.lib(os.environ['PKCS11_MODULE'])
token = lib.get_token(token_label='SmartCard-HSM (UserPIN)')
with token.open(rw=True, user_pin='123456') as session:
priv = session.get_key(label='testkeyEC666', key_type=KeyType.EC, object_class=ObjectClass.PRIVATE_KEY)
pubkey = session.get_key(label='testkeyEC666', key_type=KeyType.EC, object_class=ObjectClass.PUBLIC_KEY)
with open('somefile.bin', 'rb') as f:
data = bytearray(f.read())
signature = priv.sign(bytes(data), mechanism=Mechanism.ECDSA_SHA256)
h = SHA256.new(data)
verifier = DSS.new(ECC.import_key(encode_ec_public_key(pubkey)), 'fips-186-3')
try:
verifier.verify(h, signature)
print("signature ok.")
except ValueError:
print("signature not ok!")
It throws me the following error:
Traceback (most recent call last):
File "/home/Projects/Playground/python-pkcs11/./pkcs11-sign.py", line 30, in <module>
signature = priv.sign(bytes(data), mechanism=Mechanism.ECDSA_SHA256)
File "/usr/local/lib/python3.10/dist-packages/pkcs11/types.py", line 939, in sign
return self._sign(data, **kwargs)
File "pkcs11/_pkcs11.pyx", line 1072, in pkcs11._pkcs11.SignMixin._sign
File "pkcs11/_pkcs11.pyx", line 1083, in pkcs11._pkcs11.SignMixin._sign
File "pkcs11/_errors.pyx", line 88, in pkcs11._pkcs11.assertRV
pkcs11.exceptions.DataLenRange
- Dominant language
- Python
- Stars
- 170
- Forks
- 79
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from pyauth/python-pkcs11
-
Difficulty 1/5 Under an hour Newbie friendliness 65/100
pyauth/python-pkcs11#225 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
pyauth/python-pkcs11#233 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 55/100
pyauth/python-pkcs11#228 · 3 comments ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
pyauth/python-pkcs11#220 · 1 comment ·
-
readthedocs.io setupOpen
Difficulty 4/5 3-5 days Newbie friendliness 35/100
pyauth/python-pkcs11#211 · 1 comment ·
All issues in pyauth/python-pkcs11
Similar issues
-
Device Details tables: FS/SF columns contradict each other (nfet_01v8 Vt row, pfet_01v8 Idsat row)Open
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
google/skywater-pdk#450 ·
-
Drained trajectory arrays are overwritten when the sequence buffer is reusedPossibly taken @sylvesterkaczmarek claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
google-deepmind/bsuite#56 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
LearningCircuit/local-deep-research#7206 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
chingu-voyages/V62-tier3-team-33#285 ·
Maintainers usually reply within 1 day
-
Proxy drops log notifications from backends that don't send FastMCP's msg/extra dictPossibly taken @asasemahmed claimed this today. Openbug server
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day