Re: SonarLint complaining about "Use a stronger padding scheme"
Frank Sapone <[email protected]> Mon, 15 Apr 2024 06:42:41 -0700 (PDT)
| Newsgroups | gmane.comp.encryption.cryptopp |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_68880_1024190458.1713188561864 Content-Type: multipart/alternative; boundary="----=_Part_68881_1847075847.1713188561864" ------=_Part_68881_1847075847.1713188561864 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable I spoke too soon. So I generated a new cert with openssl with the RSAPSS= =20 scheme. Windows shows the certificate information correctly with subject,= =20 not before, not after, etc. correctly. However, with PEM_Load it fails=20 with BER decode error. Does PEM_Load not support this or is there=20 additional configuration to do before it can load it in properly? Thanks, Frank On Monday, April 15, 2024 at 9:18:44=E2=80=AFAM UTC-4 Frank Sapone wrote: > NVM, it appears PSSR is considered more secure and this should work with= =20 > the verifier. > > Thanks, > Frank > > On Friday, April 12, 2024 at 12:20:56=E2=80=AFPM UTC-4 Jeffrey Walton wro= te: > >> On Friday, April 12, 2024 at 12:19:32=E2=80=AFPM UTC-4 franksa...@gmail.= com=20 >> wrote: >> >> Hello, I am using Windows 10 Professional x64 with CryptoPP 8.9.0. It i= s=20 >> built with Visual Studio. We started using SonarQube/SonarLint for SCA= =20 >> during compile and it's been complaining "Use a stronger padding scheme"= .=20 >> Specifically it sees this line:=20 >> >> RSASS<PKCS1v15, SHA256>::Verifier verifier(publicKey); >> >> and complains about the PCKS1v15. I don't know how to change it to a=20 >> different type and what other ones are available. It suggests OAEP for = RSA=20 >> which is what I assume we want. >> >> >> https://www.cryptopp.com/wiki/RSA_Encryption_Schemes >> >> Jeff >> > --=20 You received this message because you are subscribed to the Google Groups "= Crypto++ Users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/= cryptopp-users/2ed3760e-7056-4335-b162-86742e6db772n%40googlegroups.com. ------=_Part_68881_1847075847.1713188561864 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable I spoke too soon.=C2=A0 So I generated a new cert with openssl with the RSA= PSS scheme.=C2=A0 Windows shows the certificate information correctly with = subject, not before, not after, etc. correctly.=C2=A0 However, with PEM_Loa= d it fails with BER decode error.=C2=A0 Does PEM_Load not support this or i= s there additional configuration to do before it can load it in properly?<b= r /><br />Thanks,<br />Frank<br /><br /><div class=3D"gmail_quote"><div dir= =3D"auto" class=3D"gmail_attr">On Monday, April 15, 2024 at 9:18:44=E2=80= =AFAM UTC-4 Frank Sapone wrote:<br/></div><blockquote class=3D"gmail_quote"= style=3D"margin: 0 0 0 0.8ex; border-left: 1px solid rgb(204, 204, 204); p= adding-left: 1ex;">NVM, it appears PSSR is considered more secure and this = should work with the verifier.<div><br></div><div>Thanks,<br>Frank<br><br><= /div><div class=3D"gmail_quote"><div dir=3D"auto" class=3D"gmail_attr">On F= riday, April 12, 2024 at 12:20:56=E2=80=AFPM UTC-4 Jeffrey Walton wrote:<br= ></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 0.8ex;border= -left:1px solid rgb(204,204,204);padding-left:1ex"><div><div dir=3D"auto">O= n Friday, April 12, 2024 at 12:19:32=E2=80=AFPM UTC-4 <a rel=3D"nofollow">f= [email protected]</a> wrote:<br></div><blockquote style=3D"margin:0px 0px= 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hello, = I am using Windows 10 Professional x64 with CryptoPP 8.9.0. =C2=A0It is bui= lt with Visual Studio. =C2=A0We started using SonarQube/SonarLint for SCA d= uring compile and it's been complaining "Use a stronger padding sc= heme". =C2=A0Specifically it sees this line: <br><br>RSASS<PKCS1v15= , SHA256>::Verifier verifier(publicKey);<br><br>and complains about the = PCKS1v15. =C2=A0I don't know how to change it to a different type and w= hat other ones are available. =C2=A0It suggests OAEP for RSA which is what = I assume we want.<br></blockquote><div><br></div></div><div><div><a href=3D= "https://www.cryptopp.com/wiki/RSA_Encryption_Schemes" rel=3D"nofollow" tar= get=3D"_blank" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den-U= S&q=3Dhttps://www.cryptopp.com/wiki/RSA_Encryption_Schemes&source= =3Dgmail&ust=3D1713274888998000&usg=3DAOvVaw0OLRE0c64Yb1xFYS5mJe3H"= >https://www.cryptopp.com/wiki/RSA_Encryption_Schemes</a></div><div><br></d= iv><div>Jeff<br></div></div></blockquote></div></blockquote></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;Crypto++ Users" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">cryp= [email protected]</a>.<br /> To view this discussion on the web visit <a href=3D"https://groups.google.c= om/d/msgid/cryptopp-users/2ed3760e-7056-4335-b162-86742e6db772n%40googlegro= ups.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/d= /msgid/cryptopp-users/2ed3760e-7056-4335-b162-86742e6db772n%40googlegroups.= com</a>.<br /> ------=_Part_68881_1847075847.1713188561864-- ------=_Part_68880_1024190458.1713188561864--