Re: Re: SonarLint complaining about "Use a stronger padding scheme"
Frank Sapone <[email protected]> Wed, 24 Apr 2024 05:38:30 -0700 (PDT)
| Newsgroups | gmane.comp.encryption.cryptopp |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_121102_1965731165.1713962310895
Content-Type: multipart/alternative;
boundary="----=_Part_121103_774336711.1713962310895"
------=_Part_121103_774336711.1713962310895
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Has anyone figured out how to use PSS and SHA256 *WITH *CryptoPP-PEM? I=20
also tried reporting this to the issuer tracker=20
at https://github.com/noloader/cryptopp-pem and nobody has replied. I=20
can't imagine I'm the only person using this library in order to achieve=20
this with X509 Certs.
Thanks,
Frank
On Wednesday, April 17, 2024 at 11:43:54=E2=80=AFAM UTC-4 HELA YAICH wrote:
> Hello,=20
> (I'm new user of ns3 and crypto)=20
> I have link errors with Crypto++. These errors indicate that the compiler=
=20
> cannot find certain functions or classes defined in Crypto++. This can=20
> happen if Crypto++ is not correctly linked to my project. However, I trie=
d=20
> to modify my project's CMakeLists.txt file as follows:=20
> set(target_prefix scratch_)
>
> function(create_scratch source_files)
> # Return early if no sources in the subdirectory
> list(LENGTH source_files number_sources)
> if(number_sources EQUAL 0)
> return()
> endif()
>
> # If the scratch has more than a source file, we need to find the sourc=
e=20
> with
> # the main function
> set(scratch_src)
> foreach(source_file ${source_files})
> file(READ ${source_file} source_file_contents)
> string(REGEX MATCHALL "main[(| (]" main_position=20
> "${source_file_contents}")
> if(CMAKE_MATCH_0)
> set(scratch_src ${source_file})
> endif()
> endforeach()
>
> if(NOT scratch_src)
> return()
> endif()
>
> # Get parent directory name
> get_filename_component(scratch_dirname ${scratch_src} DIRECTORY)
> string(REPLACE "${CMAKE_CURRENT_SOURCE_DIR}" "" scratch_dirname
> "${scratch_dirname}"
> )
> string(REPLACE "/" "_" scratch_dirname "${scratch_dirname}")
>
> # Get source name
> get_filename_component(scratch_name ${scratch_src} NAME_WE)
>
> set(target_prefix scratch_)
> if(scratch_dirname)
> # Join the names together if dirname is not the scratch folder
> set(target_prefix scratch${scratch_dirname}_)
> endif()
>
> # Get source absolute path and transform into relative path
> get_filename_component(scratch_src ${scratch_src} ABSOLUTE)
> get_filename_component(scratch_absolute_directory ${scratch_src}=20
> DIRECTORY)
> string(REPLACE "${PROJECT_SOURCE_DIR}" "${CMAKE_OUTPUT_DIRECTORY}"
> scratch_directory ${scratch_absolute_directory}
> )
> add_executable(${target_prefix}${scratch_name} "${source_files}")
> if(${NS3_STATIC})
> target_link_libraries(
> ${target_prefix}${scratch_name} ${LIB_AS_NEEDED_PRE_STATIC}
> ${lib-ns3-static}
> )
> else()
> target_link_libraries(
> ${target_prefix}${scratch_name} "${ns3-libs}" "${ns3-contrib-libs}"
> "${ns3-external-libs}"
> )
> endif()
> set_runtime_outputdirectory(
> ${scratch_name} ${scratch_directory}/ ${target_prefix}
> )
> endfunction()
>
> # Scan *.cc files in ns-3-dev/scratch and build a target for each
> file(GLOB single_source_file_scratches CONFIGURE_DEPENDS=20
> ${CMAKE_CURRENT_SOURCE_DIR}/*.cc)
> foreach(scratch_src ${single_source_file_scratches})
> create_scratch(${scratch_src})
> endforeach()
>
> # Scan *.cc files in ns-3-dev/scratch subdirectories and build a target=
=20
> for each
> # subdirectory
> file(
> GLOB_RECURSE scratch_subdirectories
> CONFIGURE_DEPENDS
> LIST_DIRECTORIES true
> ${CMAKE_CURRENT_SOURCE_DIR}/**
> )
> # Filter out files
> foreach(entry ${scratch_subdirectories})
> if(NOT (IS_DIRECTORY ${entry}))
> list(REMOVE_ITEM scratch_subdirectories ${entry})
> endif()
> endforeach()
>
> foreach(subdir ${scratch_subdirectories})
> if(EXISTS ${subdir}/CMakeLists.txt)
> # If the subdirectory contains a CMakeLists.txt file
> # we let the CMake file manage the source files
> #
> # Use this if you want to link to external libraries
> # without creating a module
> add_subdirectory(${subdir})
> else()
> # Otherwise we pick all the files in the subdirectory
> # and create a scratch for them automatically
> file(GLOB scratch_sources CONFIGURE_DEPENDS ${subdir}/*.cc)
> create_scratch("${scratch_sources}")
> endif()
> endforeach()
> find_external_library(DEPENDENCY_NAME cryptopp
> HEADER_NAME aes.h
> LIBRARY_NAME cryptopp
> SEARCH_PATHS /usr/include/cryptopp)
>
>
> if(${CRYPTOPP_FOUND}) # Notice that the contents of DEPENDENCY_NAME becam=
e=20
> a prefix for the _FOUND variable
> find_package(cryptopp REQUIRED)
> include_directories(${CRYPTOPP_INCLUDE_DIRS})
> link_libraries(${CRYPTOPP_LIBRARIES})
> endif()
> add_executable(${target_prefix}${scratch_name} "fanetex.cc")
> target_link_libraries(${target_prefix}${scratch_name} PRIVATE cryptopp)
>
> can you help me to solve this problem ? Thank you [image: Capture d=E2=80=
=99=C3=A9cran=20
> 2024-04-17 114345.png]
>
> Le mardi 16 avril 2024 =C3=A0 21:53:22 UTC-5, Frank Sapone a =C3=A9crit :
>
>> I grabbed it but it's not relevant. I need to have a certificate with=
=20
>> RSA PSS that can be read by CryptoPP with the X509Cert lib. Is it possi=
ble=20
>> to do this?
>>
>> On Tuesday, April 16, 2024 at 3:19:47=E2=80=AFPM UTC-4 Jeffrey Walton wr=
ote:
>>
>>> On Tue, Apr 16, 2024 at 1:44=E2=80=AFPM One Sini <[email protected]> wro=
te:
>>>
>>>> I wasn't entirely satisfied with the security, so I've adjusted the=20
>>>> code. I'm not sure if that helps you, depending on what you're doing w=
ith=20
>>>> it.
>>>>
>>>> This code uses RSA with OAEP (Optimal Asymmetric Encryption Padding) t=
o=20
>>>> avoid security issues like padding oracle attacks. It generates RSA ke=
ys=20
>>>> with a length of 2048 bits, encrypts the message with OAEP padding, an=
d=20
>>>> then decrypts it.
>>>>
>>>> Best Regards Satoshi=20
>>>>
>>>
>>> I deleted the message from the group. The *.pdf and *.pages smells of=
=20
>>> malware.
>>>
>>> If you want to provide code, please inline it or provide it as a text=
=20
>>> attachment.
>>>
>>> Jeff
>>>
>>>>
--=20
You received this message because you are subscribed to the Google Groups "=
Crypto++ Users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to [email protected].
To view this discussion on the web visit https://groups.google.com/d/msgid/=
cryptopp-users/db9bad9f-be9e-4a25-a09f-d52ce28adec0n%40googlegroups.com.
------=_Part_121103_774336711.1713962310895
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Has anyone figured out how to use PSS and SHA256 <b><i>WITH</i>=C2=A0</b>Cr=
yptoPP-PEM?=C2=A0 I also tried reporting this to the issuer tracker at=C2=
=A0https://github.com/noloader/cryptopp-pem and nobody has replied.=C2=A0 I=
can't imagine I'm the only person using this library in order to achieve t=
his with X509 Certs.<div><br /></div><div>Thanks,<br />Frank<br /><div><br =
/></div></div><div class=3D"gmail_quote"><div dir=3D"auto" class=3D"gmail_a=
ttr">On Wednesday, April 17, 2024 at 11:43:54=E2=80=AFAM UTC-4 HELA YAICH w=
rote:<br/></div><blockquote class=3D"gmail_quote" style=3D"margin: 0 0 0 0.=
8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">Hello,=
=C2=A0<br>(I'm new user of ns3 and crypto)=C2=A0<br>I have link errors =
with Crypto++. These errors indicate that the compiler cannot find certain =
functions or classes defined in Crypto++. This can happen if Crypto++ is no=
t correctly linked to my project. However, I tried to modify my project'=
;s CMakeLists.txt file as follows: <br>set(target_prefix scratch_)<br><br>f=
unction(create_scratch source_files)<br>=C2=A0 # Return early if no sources=
in the subdirectory<br>=C2=A0 list(LENGTH source_files number_sources)<br>=
=C2=A0 if(number_sources EQUAL 0)<br>=C2=A0 =C2=A0 return()<br>=C2=A0 endif=
()<br><br>=C2=A0 # If the scratch has more than a source file, we need to f=
ind the source with<br>=C2=A0 # the main function<br>=C2=A0 set(scratch_src=
)<br>=C2=A0 foreach(source_file ${source_files})<br>=C2=A0 =C2=A0 file(READ=
${source_file} source_file_contents)<br>=C2=A0 =C2=A0 string(REGEX MATCHAL=
L "main[(| (]" main_position "${source_file_contents}")=
<br>=C2=A0 =C2=A0 if(CMAKE_MATCH_0)<br>=C2=A0 =C2=A0 =C2=A0 set(scratch_src=
${source_file})<br>=C2=A0 =C2=A0 endif()<br>=C2=A0 endforeach()<br><br>=C2=
=A0 if(NOT scratch_src)<br>=C2=A0 =C2=A0 return()<br>=C2=A0 endif()<br><br>=
=C2=A0 # Get parent directory name<br>=C2=A0 get_filename_component(scratch=
_dirname ${scratch_src} DIRECTORY)<br>=C2=A0 string(REPLACE "${CMAKE_C=
URRENT_SOURCE_DIR}" "" scratch_dirname<br>=C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0"${scratch_dirname}"=
<br>=C2=A0 )<br>=C2=A0 string(REPLACE "/" "_" scratch_d=
irname "${scratch_dirname}")<br><br>=C2=A0 # Get source name<br>=
=C2=A0 get_filename_component(scratch_name ${scratch_src} NAME_WE)<br><br>=
=C2=A0 set(target_prefix scratch_)<br>=C2=A0 if(scratch_dirname)<br>=C2=A0 =
=C2=A0 # Join the names together if dirname is not the scratch folder<br>=
=C2=A0 =C2=A0 set(target_prefix scratch${scratch_dirname}_)<br>=C2=A0 endif=
()<br><br>=C2=A0 # Get source absolute path and transform into relative pat=
h<br>=C2=A0 get_filename_component(scratch_src ${scratch_src} ABSOLUTE)<br>=
=C2=A0 get_filename_component(scratch_absolute_directory ${scratch_src} DIR=
ECTORY)<br>=C2=A0 string(REPLACE "${PROJECT_SOURCE_DIR}" "${=
CMAKE_OUTPUT_DIRECTORY}"<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0scratch_directory ${scratch_absolute_directory}<br>=C2=
=A0 )<br>=C2=A0 add_executable(${target_prefix}${scratch_name} "${sour=
ce_files}")<br>=C2=A0 if(${NS3_STATIC})<br>=C2=A0 =C2=A0 target_link_l=
ibraries(<br>=C2=A0 =C2=A0 =C2=A0 ${target_prefix}${scratch_name} ${LIB_AS_=
NEEDED_PRE_STATIC}<br>=C2=A0 =C2=A0 =C2=A0 ${lib-ns3-static}<br>=C2=A0 =C2=
=A0 )<br>=C2=A0 else()<br>=C2=A0 =C2=A0 target_link_libraries(<br>=C2=A0 =
=C2=A0 =C2=A0 ${target_prefix}${scratch_name} "${ns3-libs}" "=
;${ns3-contrib-libs}"<br>=C2=A0 =C2=A0 =C2=A0 "${ns3-external-lib=
s}"<br>=C2=A0 =C2=A0 )<br>=C2=A0 endif()<br>=C2=A0 set_runtime_outputd=
irectory(<br>=C2=A0 =C2=A0 ${scratch_name} ${scratch_directory}/ ${target_p=
refix}<br>=C2=A0 )<br>endfunction()<br><br># Scan *.cc files in ns-3-dev/sc=
ratch and build a target for each<br>file(GLOB single_source_file_scratches=
CONFIGURE_DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/*.cc)<br>foreach(scratch_src=
${single_source_file_scratches})<br>=C2=A0 create_scratch(${scratch_src})<=
br>endforeach()<br><br># Scan *.cc files in ns-3-dev/scratch subdirectories=
and build a target for each<br># subdirectory<br>file(<br>=C2=A0 GLOB_RECU=
RSE scratch_subdirectories<br>=C2=A0 CONFIGURE_DEPENDS<br>=C2=A0 LIST_DIREC=
TORIES true<br>=C2=A0 ${CMAKE_CURRENT_SOURCE_DIR}/**<br>)<br># Filter out f=
iles<br>foreach(entry ${scratch_subdirectories})<br>=C2=A0 if(NOT (IS_DIREC=
TORY ${entry}))<br>=C2=A0 =C2=A0 list(REMOVE_ITEM scratch_subdirectories ${=
entry})<br>=C2=A0 endif()<br>endforeach()<br><br>foreach(subdir ${scratch_s=
ubdirectories})<br>=C2=A0 if(EXISTS ${subdir}/CMakeLists.txt)<br>=C2=A0 =C2=
=A0 # If the subdirectory contains a CMakeLists.txt file<br>=C2=A0 =C2=A0 #=
we let the CMake file manage the source files<br>=C2=A0 =C2=A0 #<br>=C2=A0=
=C2=A0 # Use this if you want to link to external libraries<br>=C2=A0 =C2=
=A0 # without creating a module<br>=C2=A0 =C2=A0 add_subdirectory(${subdir}=
)<br>=C2=A0 else()<br>=C2=A0 =C2=A0 # Otherwise we pick all the files in th=
e subdirectory<br>=C2=A0 =C2=A0 # and create a scratch for them automatical=
ly<br>=C2=A0 =C2=A0 file(GLOB scratch_sources CONFIGURE_DEPENDS ${subdir}/*=
.cc)<br>=C2=A0 =C2=A0 create_scratch("${scratch_sources}")<br>=C2=
=A0 endif()<br>endforeach()<br>find_external_library(DEPENDENCY_NAME crypto=
pp<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=
=C2=A0 HEADER_NAME aes.h<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 LIBRARY_NAME cryptopp<br>=C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 SEARCH_PATHS /u=
sr/include/cryptopp)<br><br><br>if(${CRYPTOPP_FOUND}) # Notice that the con=
tents of DEPENDENCY_NAME became a prefix for the _FOUND variable<br>=C2=A0 =
=C2=A0 find_package(cryptopp REQUIRED)<br>=C2=A0 =C2=A0 include_directories=
(${CRYPTOPP_INCLUDE_DIRS})<br>=C2=A0 =C2=A0 link_libraries(${CRYPTOPP_LIBRA=
RIES})<br>endif()<br>add_executable(${target_prefix}${scratch_name} "f=
anetex.cc")<br>target_link_libraries(${target_prefix}${scratch_name} P=
RIVATE cryptopp)<br><br>can you help me to solve this problem ? Thank you=
=C2=A0<img alt=3D"Capture d=E2=80=99=C3=A9cran 2024-04-17 114345.png" width=
=3D"631px" height=3D"398px" src=3D"https://groups.google.com/group/cryptopp=
-users/attach/1f8b7a2cdb789/Capture%20d%E2%80%99%C3%A9cran%202024-04-17%201=
14345.png?part=3D0.1&view=3D1"><br><br><div class=3D"gmail_quote"><div =
dir=3D"auto" class=3D"gmail_attr">Le mardi 16 avril 2024 =C3=A0 21:53:22 UT=
C-5, Frank Sapone a =C3=A9crit=C2=A0:<br></div><blockquote class=3D"gmail_q=
uote" style=3D"margin:0 0 0 0.8ex;border-left:1px solid rgb(204,204,204);pa=
dding-left:1ex">I grabbed it but it's not relevant.=C2=A0 I need to hav=
e a certificate with RSA PSS that can be read by CryptoPP with the X509Cert=
lib.=C2=A0 Is it possible to do this?<br><br><div class=3D"gmail_quote"><d=
iv dir=3D"auto" class=3D"gmail_attr">On Tuesday, April 16, 2024 at 3:19:47=
=E2=80=AFPM UTC-4 Jeffrey Walton wrote:<br></div><blockquote class=3D"gmail=
_quote" style=3D"margin:0 0 0 0.8ex;border-left:1px solid rgb(204,204,204);=
padding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_quote"><div dir=3D"l=
tr" class=3D"gmail_attr">On Tue, Apr 16, 2024 at 1:44=E2=80=AFPM One Sini &=
lt;<a rel=3D"nofollow">[email protected]</a>> wrote:<br></div></div></div=
><div dir=3D"ltr"><div class=3D"gmail_quote"><blockquote class=3D"gmail_quo=
te" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204=
);padding-left:1ex"><div dir=3D"auto"><div><span style=3D"font-family:s=C3=
=B6hne,ui-sans-serif,system-ui,-apple-system,"segoe ui",roboto,ub=
untu,cantarell,"noto sans",sans-serif,"helvetica neue",=
arial,"apple color emoji","segoe ui emoji","segoe =
ui symbol","noto color emoji";font-size:16px;font-style:norm=
al;font-weight:400;letter-spacing:normal;text-indent:0px;text-transform:non=
e;white-space:pre-wrap;word-spacing:0px;text-decoration:none;float:none;dis=
play:inline;color:rgb(13,13,13)">I wasn't entirely satisfied with the s=
ecurity, so I've adjusted the code. I'm not sure if that helps you,=
depending on what you're doing with it.</span></div><br></div></blockq=
uote></div></div><div dir=3D"ltr"><div class=3D"gmail_quote"><blockquote cl=
ass=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid=
rgb(204,204,204);padding-left:1ex"><div dir=3D"auto"><div><span style=3D"f=
ont-family:s=C3=B6hne,ui-sans-serif,system-ui,-apple-system,"segoe ui&=
quot;,roboto,ubuntu,cantarell,"noto sans",sans-serif,"helvet=
ica neue",arial,"apple color emoji","segoe ui emoji&quo=
t;,"segoe ui symbol","noto color emoji";font-size:16px;=
font-style:normal;font-weight:400;letter-spacing:normal;text-indent:0px;tex=
t-transform:none;white-space:pre-wrap;word-spacing:0px;text-decoration:none=
;float:none;display:inline;color:rgb(13,13,13)">This code uses RSA with OAE=
P (Optimal Asymmetric Encryption Padding) to avoid security issues like pad=
ding oracle attacks. It generates RSA keys with a length of 2048 bits, encr=
ypts the message with OAEP padding, and then decrypts it.</span></div><div =
dir=3D"auto"><span style=3D"font-family:s=C3=B6hne,ui-sans-serif,system-ui,=
-apple-system,"segoe ui",roboto,ubuntu,cantarell,"noto sans&=
quot;,sans-serif,"helvetica neue",arial,"apple color emoji&q=
uot;,"segoe ui emoji","segoe ui symbol","noto colo=
r emoji";font-size:16px;font-style:normal;font-weight:400;letter-spaci=
ng:normal;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spa=
cing:0px;text-decoration:none;float:none;display:inline;color:rgb(13,13,13)=
"><br></span></div></div></blockquote></div></div><div dir=3D"ltr"><div cla=
ss=3D"gmail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0px 0p=
x 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div d=
ir=3D"auto"><div dir=3D"auto"><span style=3D"font-family:s=C3=B6hne,ui-sans=
-serif,system-ui,-apple-system,"segoe ui",roboto,ubuntu,cantarell=
,"noto sans",sans-serif,"helvetica neue",arial,"ap=
ple color emoji","segoe ui emoji","segoe ui symbol"=
;,"noto color emoji";font-size:16px;font-style:normal;font-weight=
:400;letter-spacing:normal;text-indent:0px;text-transform:none;white-space:=
pre-wrap;word-spacing:0px;text-decoration:none;float:none;display:inline;co=
lor:rgb(13,13,13)">Best Regards Satoshi </span></div></div></blockquote><di=
v><br></div><div>I deleted the message from the group. The *.pdf and *.page=
s smells of malware.</div><div><br></div><div>If you want to provide code, =
please inline it or provide it as a text attachment.<br></div><div><br></di=
v><div>Jeff</div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px =
0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><di=
v class=3D"gmail_quote"><blockquote class=3D"gmail_quote" style=3D"margin:0=
px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
</blockquote></div></div></blockquote></div></div>
</blockquote></div></blockquote></div></blockquote></div>
<p></p>
-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;Crypto++ Users" group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">cryp=
[email protected]</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/d/msgid/cryptopp-users/db9bad9f-be9e-4a25-a09f-d52ce28adec0n%40googlegro=
ups.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/d=
/msgid/cryptopp-users/db9bad9f-be9e-4a25-a09f-d52ce28adec0n%40googlegroups.=
com</a>.<br />
------=_Part_121103_774336711.1713962310895--
------=_Part_121102_1965731165.1713962310895--