Generic digest for rsa::pkcs1v15::Signature?
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 25/100
- Issue 类型
- 功能
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- rust
- 领域
- cryptography
调研方向
Start with the RSA signing-key implementation at src/pkcs1v15/signing_key.rs, which the issue identifies as carrying the digest information, and inspect the corresponding PKCS#1 v1.5 and PSS signature types. Determine whether the API can distinguish signatures by digest without breaking the generic signature traits. Done means reaching and documenting a clear API decision, with affected behavior and coverage identified.
由索引模型根据 Issue 内容生成。
描述
Hey Tony, long time no chat!
I'm using RustCrypto in a project involving JOSE. I have some fairly open ended extensibility requirements, so I'm leveraging RustCrypto's generic signature traits as much as possible, to support users defining their own signing implementations, such as over WebCrypto with wasm, or using an HSM. As part of this, I've defined a trait for mapping RustCrypto signature encodings to their corresponding algorithm name in JWA.
This is generally working great, for most signature types:
pub trait JWSSignature: SignatureEncoding {
const ALGORITHM: jose_jwa::Signing;
}
impl JWSSignature for ecdsa::Signature<p256::NistP256> {
const ALGORITHM: jose_jwa::Signing = jose_jwa::Signing::Es256;
}
impl JWSSignature for ecdsa::Signature<k256::Secp256k1> {
const ALGORITHM: jose_jwa::Signing = jose_jwa::Signing::Es256K;
}
But I run into issues with RSASSA-PKCS1-v1_5 and RSASSA-PSS signatures, as implemented in the rsa crate, because their corresponding signature types don't specify the hash function used in the signature, and so there isn't a 1:1 mapping between signatures and their JWA name.
For example:
impl JWSSignature for rsa::pkcs1v15::Signature {
// Might be Rs256, Rs384, or Rs512
const ALGORITHM: jose_jwa::Signing = ???;
}
This information is available on the corresponding signing key types for both variants of RSA signatures, so I'm wondering whether it would make sense for the digest type to also be tracked on the signatures themselves, in order to differentiate between signatures which use different hash functions.
In my case, it's not the end of the world if this isn't supported, because no one should really be deploying RSASSA-PKCS1-v1_5 using SHA-512 anyway, but that I ran into this limitation in the first place had me wondering whether it was a gap in the API worth thinking about.
Thanks for all the great work here, I'm really enjoying how the whole ecosystem slots together so nicely :)
- 主要语言
- Rust
- 星标
- 673
- 派生
- 190
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
RustCrypto/RSA 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
RustCrypto/RSA#707 · 2 条评论 · 1 个 reaction ·
-
难度 3/5 半天 新手友好度 74/100
RustCrypto/RSA#703 ·
-
难度 4/5 3-5 天 新手友好度 48/100
RustCrypto/RSA#686 · 4 条评论 ·
-
难度 5/5 一周以上 新手友好度 35/100
RustCrypto/RSA#647 · 9 条评论 · 1 个 reaction ·
-
broken rust docs未关闭
难度 4/5 3-5 天 新手友好度 35/100
RustCrypto/RSA#641 · 3 个 reaction ·
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 74/100
维护者通常 1 天内回复
-
app documentation remote windows-os
难度 1/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
oxidecomputer/dendrite#380 ·
维护者通常 5 天内回复
-
area:cli bug good first issue priority:high
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复