Stricter RSA key generation from jwk parameters#524
Merged
Conversation
Contributor
|
I have asked about this over at the Ruby OpenSSL gem: ruby/openssl#551 |
Member
Author
|
Thanks @bellebaum for raising the question. Im going to return to this one to have it working with the adjustments from #520 at some point. |
30d0a65 to
8191784
Compare
c5e78dd to
cdb24c8
Compare
cdb24c8 to
e39b411
Compare
Member
Author
|
This is the best we can to with the interfaces provided by the OpenSSL gem. The behaviour is going to be different depending on the version of openssl that is in use. |
Member
Author
|
Im going to merge this soonish. Working on ruby/openssl#555 to move all this heavy lifting into the openssl gem. Hopefully it will be great some day :) |
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR is addressing a parts of #523 and adding test coverage on a few scenarios.
Moved the methods around a little for easier testing and added parameter validation with the rule:
As you @bellebaum pointed out the DER generation has some issues when parameters are missing. Did not dig that deep but I have a feeling that there is no way to present a private key in the DER format without these parameters.
Im a little unsure what do, not really eager into starting to calculate the primes etc. I guess it's doable but feels sketchy.
So I guess the question is:
Is there a way to generate a usable RSA object with OpenSSL 3.0 with only the modulus and exponents (n,e,d)? as the JWK spec allows private keys to be presented with only these values.