Error: "alg" parameter "ES256" requires curve "prime256v1"
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 文档
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- javascript, node.js
- 领域
- cryptography, security
调研方向
从 Changelog、Migration guide 以及拒绝 ES256 曲线的验证代码开始。调查使用 secp256k1 而不是 prime256v1 的影响,并确定缺少哪些指导。完成的标准是项目文档清楚说明曲线要求、安全影响,以及何时适合绕过检查。
由索引模型根据 Issue 内容生成。
描述
Not a bug report, but a question.
My code started to fail with version 9 because of this error.
I've read the Changelog, Migration guide and source code that does this validation and see where it comes from.
I also can see that I can bypass this check with allowInvalidAsymmetricKeyTypes.
What I cannot find information about is what is the implication that I have used "wrong curve" when generating the keys?
In particular, I have used this command before: openssl ecparam -name secp256k1 -genkey -noout -out key.pem.
"Correct" command with the "correct" curve looks like this: openssl ecparam -name prime256v1 -genkey -noout -out key.pem.
Are my tokens vulnerable to some attack or something, because I have used the "wrong curve" when generating the keys?
- 主要语言
- JavaScript
- 星标
- 18.2k
- 派生
- 1.3k
- PR 合并指标
- 30 天内没有已合并 PR
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
auth0/node-jsonwebtoken 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
auth0/node-jsonwebtoken#1042 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 84/100
auth0/node-jsonwebtoken#1000 · 2 条评论 · 1 个 reaction ·
-
难度 4/5 3-5 天 新手友好度 65/100
auth0/node-jsonwebtoken#1046 ·
-
难度 5/5 一周以上 新手友好度 10/100
auth0/node-jsonwebtoken#1034 ·
-
难度 3/5 1-2 天 新手友好度 48/100
auth0/node-jsonwebtoken#1032 ·
查看 auth0/node-jsonwebtoken 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 65/100
antfu-collective/icones#398 ·
-
ECmail.com 未关闭
难度 1/5 1 小时以内 新手友好度 90/100
wesbos/burner-email-providers#554 ·
-
难度 2/5 1-3 小时 新手友好度 65/100
radiantearth/stac-browser#1023 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
components-web-app/docs#92 ·