Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Is the Session API within the approved scope of CMVP certificate #5313?

未关闭
#60 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
25/100
Issue 类型
文档
描述清晰度
需要澄清
活跃度
冷清
技术栈
c

调研方向

从链接的 #5313 Security Policy 开始,重点查看其中的服务表、AES-GCM IV Generation - External 条目以及 IG C.H Scenario 3 声明;然后将这些陈述与 101.2.0 changelog 和列出的 Session API exports 进行比较。当维护者明确 SessionSenderInit 后接 SessionGcmEncrypt 是否属于 approved mode 使用并满足 Scenario 3 时,即视为完成。

由索引模型根据 Issue 内容生成。

描述

libsymcrypt.so exports SymCryptSessionSenderInit, SymCryptSessoinReceiverInit, SymCryptSessionGcmEncrypt, SymCryptSessionGcmDecrypt and SymCryptSessionDestroy (VERSION_101.). The 101.2.0 changelog describes these as enabling "multithreaded IV generation within the SymCrypt FIPS boundary."

The #5313 Security Policy does not name a Session service in its services table, and registers IV Generation - External for AES-GCM. The certificate seperately claims IG C.H Scenario 3.

When a caller uses SymCryptSessionSenderInit followed by SymCryptSessionGcmEncrypt, so that the module constructs and increments the nonce internally, is that an approved-mode use of the module under #5313? Does it satisfy the Scenario 3 claim?

Trying to understand so we can use the module in approved mode correctly. Thanks!

主要语言
C
星标
893
派生
90
PR 合并指标
30 天内没有已合并 PR

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 有 Pull Request 模板
  • 没有贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

microsoft/SymCrypt 的其他 Issue

查看 microsoft/SymCrypt 的全部 Issue

相似的 Issue

更多 C Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。