Re: OpenSSL: rsa_builtin_keygen: key size too small
Tom Mitchell <[email protected]> Tue, 24 Dec 2019 13:59:30 -0800
| Newsgroups | gmane.comp.encryption.general |
|---|---|
| Message-ID | <CAAMy4URHqzY4LbU8+=MaQqnUDmQQCNEU=TSHtqYh4ekOmJ6Y9w@mail.gmail.com> |
--===============7022935706610039902== Content-Type: multipart/alternative; boundary="0000000000005c453f059a7a4499" --0000000000005c453f059a7a4499 Content-Type: text/plain; charset="UTF-8" On Tue, Dec 24, 2019 at 1:43 PM Viktor Dukhovni <[email protected]> wrote: > On Mon, Dec 23, 2019 at 11:38:30AM -0800, Ray Dillinger wrote: > > > Further, I doubt anyone there will be interested in helping you create > > a version that doesn't throw that error message. > > Well, I'm on the OpenSSL team, and did explain how to build a custom > version that will admit smaller keys. > > > People have been badly burned several times by downgrade attacks. I am tempted to have someone binary edit the test in the binary object. Just change the limit test to tiny and see what happens. I would hope basic system integrity tools would notice such a change for the file in a normal location. $PATH could find it in a test location. Sort of a bad idea, I know, but hackers do worse to systems so consider this can of worms a warning more than a suggestion. -- T o m M i t c h e l l ( o n N i f t y E g g ) --0000000000005c453f059a7a4499 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr">On Tue, Dec 24, 2019 at 1:43 PM Viktor Du= khovni <<a href=3D"mailto:[email protected]">cryptography@dukhov= ni.org</a>> wrote:<br></div><div class=3D"gmail_quote"><blockquote class= =3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rg= b(204,204,204);padding-left:1ex">On Mon, Dec 23, 2019 at 11:38:30AM -0800, = Ray Dillinger wrote:<br> <br> > Further, I doubt anyone there will be interested in helping you create= <br> > a version that doesn't throw that error message.<br> <br> Well, I'm on the OpenSSL team, and did explain how to build a custom<br= > version that will admit smaller keys.<br> <br> > People have been badly burned several times by downgrade attacks. </bl= ockquote><div>=C2=A0</div><div>I am tempted to have someone binary edit the= test in the binary object.<br>Just change the limit test to tiny and see w= hat happens.<br><br>I would hope basic system integrity tools would notice = such a change=C2=A0 for<br>the file in a normal location. $PATH could find = it in=C2=A0a test location.=C2=A0<br><br>Sort of a bad idea, I know, but ha= ckers do worse to systems so consider this can of worms</div><div>a warning= more than a suggestion.=C2=A0<br><br><br></div></div><div><br></div>-- <br= ><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D"ltr"><div><div dir= =3D"ltr"><div><div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr">=C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 T o m =C2=A0 =C2=A0M i t c h e l l ( o n=C2=A0 =C2= =A0N i f t y E g g )<br></div></div></div></div></div></div></div></div></d= iv> --0000000000005c453f059a7a4499-- --===============7022935706610039902== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ The cryptography mailing list [email protected] https://www.metzdowd.com/mailman/listinfo/cryptography --===============7022935706610039902==--