Home GnuPG

cipher: Differentiate use of label K in the SLI

Description

cipher: Differentiate use of label K in the SLI

* cipher/ecc.c (ecc_sign, ecc_verify): Use of label K is not allowed in
fips mode, differentiate with the GCRY_FIPS_FLAG_REJECT_PK_ECC_K flag.
* src/gcrypt.h.in: New GCRY_FIPS_FLAG_REJECT_PK_ECC_K.
* tests/t-fips-service-ind.c (check_pk_hash_sign_verify): Mark non
compliant use of label.
  • Signed-off-by: Lucas Mulling <lucas.mulling@suse.com>

Details

Provenance
Lucas Mulling via Gcrypt-devel <gcrypt-devel@gnupg.org>Authored on Wed, Feb 26, 4:29 PM
gniibeCommitted on Tue, Mar 4, 5:53 AM
Parents
rCbe57179f42f8: cipher: Add KAT for non-rfc6979 ECDSA with fixed k
Branches
Unknown
Tags
Unknown

Event Timeline

gniibe committed rC2f6d2db1a4c2: cipher: Differentiate use of label K in the SLI (authored by Lucas Mulling via Gcrypt-devel <gcrypt-devel@gnupg.org>).Tue, Mar 4, 5:53 AM