Re: SonarLint complaining about "Use a stronger padding scheme"

Frank Sapone <[email protected]> Mon, 15 Apr 2024 06:42:41 -0700 (PDT)
Newsgroups gmane.comp.encryption.cryptopp
Message-ID <[email protected]>
------=_Part_68880_1024190458.1713188561864
Content-Type: multipart/alternative; 
	boundary="----=_Part_68881_1847075847.1713188561864"

------=_Part_68881_1847075847.1713188561864
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

I spoke too soon.  So I generated a new cert with openssl with the RSAPSS=
=20
scheme.  Windows shows the certificate information correctly with subject,=
=20
not before, not after, etc. correctly.  However, with PEM_Load it fails=20
with BER decode error.  Does PEM_Load not support this or is there=20
additional configuration to do before it can load it in properly?

Thanks,
Frank

On Monday, April 15, 2024 at 9:18:44=E2=80=AFAM UTC-4 Frank Sapone wrote:

> NVM, it appears PSSR is considered more secure and this should work with=
=20
> the verifier.
>
> Thanks,
> Frank
>
> On Friday, April 12, 2024 at 12:20:56=E2=80=AFPM UTC-4 Jeffrey Walton wro=
te:
>
>> On Friday, April 12, 2024 at 12:19:32=E2=80=AFPM UTC-4 franksa...@gmail.=
com=20
>> wrote:
>>
>> Hello, I am using Windows 10 Professional x64 with CryptoPP 8.9.0.  It i=
s=20
>> built with Visual Studio.  We started using SonarQube/SonarLint for SCA=
=20
>> during compile and it's been complaining "Use a stronger padding scheme"=
.=20
>>  Specifically it sees this line:=20
>>
>> RSASS<PKCS1v15, SHA256>::Verifier verifier(publicKey);
>>
>> and complains about the PCKS1v15.  I don't know how to change it to a=20
>> different type and what other ones are available.  It suggests OAEP for =
RSA=20
>> which is what I assume we want.
>>
>>
>> https://www.cryptopp.com/wiki/RSA_Encryption_Schemes
>>
>> Jeff
>>
>

--=20
You received this message because you are subscribed to the Google Groups "=
Crypto++ Users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to [email protected].
To view this discussion on the web visit https://groups.google.com/d/msgid/=
cryptopp-users/2ed3760e-7056-4335-b162-86742e6db772n%40googlegroups.com.

------=_Part_68881_1847075847.1713188561864
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

I spoke too soon.=C2=A0 So I generated a new cert with openssl with the RSA=
PSS scheme.=C2=A0 Windows shows the certificate information correctly with =
subject, not before, not after, etc. correctly.=C2=A0 However, with PEM_Loa=
d it fails with BER decode error.=C2=A0 Does PEM_Load not support this or i=
s there additional configuration to do before it can load it in properly?<b=
r /><br />Thanks,<br />Frank<br /><br /><div class=3D"gmail_quote"><div dir=
=3D"auto" class=3D"gmail_attr">On Monday, April 15, 2024 at 9:18:44=E2=80=
=AFAM UTC-4 Frank Sapone wrote:<br/></div><blockquote class=3D"gmail_quote"=
 style=3D"margin: 0 0 0 0.8ex; border-left: 1px solid rgb(204, 204, 204); p=
adding-left: 1ex;">NVM, it appears PSSR is considered more secure and this =
should work with the verifier.<div><br></div><div>Thanks,<br>Frank<br><br><=
/div><div class=3D"gmail_quote"><div dir=3D"auto" class=3D"gmail_attr">On F=
riday, April 12, 2024 at 12:20:56=E2=80=AFPM UTC-4 Jeffrey Walton wrote:<br=
></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 0.8ex;border=
-left:1px solid rgb(204,204,204);padding-left:1ex"><div><div dir=3D"auto">O=
n Friday, April 12, 2024 at 12:19:32=E2=80=AFPM UTC-4 <a rel=3D"nofollow">f=
[email protected]</a> wrote:<br></div><blockquote style=3D"margin:0px 0px=
 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hello, =
I am using Windows 10 Professional x64 with CryptoPP 8.9.0. =C2=A0It is bui=
lt with Visual Studio. =C2=A0We started using SonarQube/SonarLint for SCA d=
uring compile and it&#39;s been complaining &quot;Use a stronger padding sc=
heme&quot;. =C2=A0Specifically it sees this line: <br><br>RSASS&lt;PKCS1v15=
, SHA256&gt;::Verifier verifier(publicKey);<br><br>and complains about the =
PCKS1v15. =C2=A0I don&#39;t know how to change it to a different type and w=
hat other ones are available. =C2=A0It suggests OAEP for RSA which is what =
I assume we want.<br></blockquote><div><br></div></div><div><div><a href=3D=
"https://www.cryptopp.com/wiki/RSA_Encryption_Schemes" rel=3D"nofollow" tar=
get=3D"_blank" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den-U=
S&amp;q=3Dhttps://www.cryptopp.com/wiki/RSA_Encryption_Schemes&amp;source=
=3Dgmail&amp;ust=3D1713274888998000&amp;usg=3DAOvVaw0OLRE0c64Yb1xFYS5mJe3H"=
>https://www.cryptopp.com/wiki/RSA_Encryption_Schemes</a></div><div><br></d=
iv><div>Jeff<br></div></div></blockquote></div></blockquote></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;Crypto++ Users&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">cryp=
[email protected]</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/d/msgid/cryptopp-users/2ed3760e-7056-4335-b162-86742e6db772n%40googlegro=
ups.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/d=
/msgid/cryptopp-users/2ed3760e-7056-4335-b162-86742e6db772n%40googlegroups.=
com</a>.<br />

------=_Part_68881_1847075847.1713188561864--

------=_Part_68880_1024190458.1713188561864--