RE: Problem Encrypting with RSA and Crypto++ 3.1
"Colestock, Robert" <[email protected]>
| Newsgroups | gmane.ietf.sfl |
|---|---|
| Message-ID | <[email protected]> |
Jonathan:
Very good. Your CTIL instance is somehow not triggering that it is a KTRI
(non-key agreement) based certificate. Looking at the logic, the alg in the
sm_Encrypt.cpp AddRecipient(...) call is not RSA for the preferred key
encryption algorithm. This can be set explicitely using:
pInst->SetPreferredCSInstAlgs(NULL, NULL, pTmpKeyEncryptionOID,
NULL);
This is done automatically in the sm_Encrypt.cpp source, but...
I built a program to perform your list of commands, they work flawlessly. I
have modified them slightly to reflect the new build name for the sm_free3
DLL with RSA:
AppLogin->AddLogin("sm_free3WithRSADLLd", "sm_free3DLL
./certs/DaisyRsaExts.out NULL NULL sm_FREE3");
I have also added the following to check the result (I did not decrypt, but
this would be a useful demonstration).
CSM_Buffer *pbufEncCI;
SME(pbufEncCI = myencrypt.GetEncodedContentInfo());
SME(pbufEncCI->ConvertMemoryToFile(".\\testencryptedfile.out"));
I would also suggest the addition of the error catch macros for debugging:
SME_SETUP("test2"); // At the beginning
...
SME_FINISH_CATCH_APP // AT THE END.
Based on your description of the failure, I can only assume you are hitting
an error we have fixed in this release (there were a number of problems in
previous releases with the OIDs for RSA in the sm_free3 CTIL; these were all
corrected in my version based on feedback). I can send you this release
(about to be released early next week) immediately (about 4 MBytes). This
demo will now be included.
Bob Colestock
VDA
-----Original Message-----
From: Jonathan Schulze-Hewett [mailto:[email protected]]
Sent: Tuesday, June 27, 2000 9:42 AM
To: Colestock, Robert
Cc: [email protected]
Subject: Re: Problem Encrypting with RSA and Crypto++ 3.1
Thank you very much for your response. I will try to fill in the
details.
1. sm_free3 was compiled with the SM_FREE3_RSA_INCLUDED flag defined.
2. The code has the same problem if a private key and password are
provided to the AddLogin call.
3. I am not aware that there are different versions of Crypto++ 3.1.
Could you direct me in determining if we have the same version?
4. The test src code in CL_MsgToEncrypt::Fill method's default
certifiacte processing code is the basis for the recipient info
configuration. I believe I followed it properly (load the cert file into
a buffer, convert to memory, construct a recipient info)...
5. Here is the stack dump. It seems to be doing Diffie-Hellman key
agreement with the RSA key...It dies on the assert(modulus.IsOdd())
statement because the Integer passed in is 0.
---Top of stack---
CryptoPP::MontgomeryRepresentation::MontgomeryRepresentation(const
CryptoPP::Integer & {...}) line 2250
CryptoPP::ModExpPrecomputation::Precompute(const CryptoPP::Integer &
{...}, const CryptoPP::Integer & {...}, unsigned int 0, unsigned int 1)
line 29 + 38 bytes
CryptoPP::ModExpPrecomputation::ModExpPrecomputation(const
CryptoPP::Integer & {...}, const CryptoPP::Integer & {...}, unsigned int
0, unsigned int 1) line 17
CryptoPP::DH::DH(const CryptoPP::Integer & {...}, const
CryptoPP::Integer & {...}, unsigned int 1) line 12 + 194 bytes
CSM_Free3::SMTI_GenerateKeyAgreement(CSM_Buffer * 0x0094d940, CSM_Buffer
* 0x0094b8c0, CSM_Buffer * 0x0094b9d0, CSM_Buffer * 0x0094d770, CSM_OID
* 0x00000000, CSM_Buffer * 0x0012ef20, long 24) line 949 + 68 bytes
CSM_DataToEncrypt::AddRecipient(CSM_CSInst * 0x0094c060,
CSM_RecipientInfo * 0x0094c0f0, CSM_Buffer & {...},
CSM_ListC<CSM_RecipientInfo> * 0x0094c320) line 733 + 574 bytes
CSM_DataToEncrypt::ProcessRecipients(CSMIME * 0x00945df0,
CSM_ListC<CSM_RecipientInfo> * 0x0094c320, CSM_Buffer & {...}) line 1002
+ 337 bytes
CSM_DataToEncrypt::Encrypt(CSMIME * 0x00945df0, CSM_MsgCertCrls *
0x00000000, CSM_ListC<CSM_RecipientInfo> * 0x0094c320, CSM_OID *
0x0094a030, CSM_Buffer * 0x0094a03c, CSM_Alg * 0x0094be40, CSM_Buffer *
0x0094bdb0) line 1205 + 222 bytes
CSM_MsgToEncrypt::Encrypt(CSMIME * 0x00945df0) line 171 + 635 bytes
main(int 1, char * * 0x009448e0, char * * 0x00940e70) line 151
---Bottom of stack---
I hope this helps. I really appreciate your assistance.
Thanks!
-Jonathan
"Colestock, Robert" wrote:
>
> Jonathan:
>
> First, let me mention I have not tried to build a message in such a way.
It
> would seem there is a lot of logic missing dealing with the construction
of
> the RecipientInfo, I would have to analyze what the sm_Encrypt.cpp logic
> does to tell what might be missing.
>
> Preliminaries: you have provided very little information, did you compile
> the SMTI for sm_free3 with the SM_FREE3_RSA_INCLUDED flag defined?
> Have you tried performing the operation with a
> private key (I realise it should not be necessary for RSA, but I have
never
> tried to perform an encryption operation without a key, even for the DH)?
> This should be easy to add since the file is present in the release
> ("./test/certs/private.d/DaisyRsaF3X_8.dat"). You probably realise this
> already, but you will not be able to decrypt the message without this
file.
> Are you using the same version of the Crypto++ 3.1
> library? I have some subtle differences in the library releases that
might
> affect operations.
>
> If the private key does not make this work for encryption, please let me
> know the full stack of the crash, I will attempt to build an encryption
> operation (it works in our releases using the configuration test logic to
> build a message, of course with the private key intact in the login).
>
> Bob Colestock
> VDA
>
> -----Original Message-----
> From: Jonathan Schulze-Hewett [mailto:[email protected]]
> Sent: Monday, June 26, 2000 4:15 PM
> To: [email protected]
> Subject: Problem Encrypting with RSA and Crypto++ 3.1
>
> Hi All,
> I have tried to write a very simple encryption routine with the SFL
> and I'm getting "Assertion failed: modulus.IsOdd(), file
> ..\crypto31\integer.cpp, line 2250 with the code below when encrypt is
> called. I would really appreciate help in getting this to work! :) I
> have spent several days trying different things. The one thing that sort
> of works (i.e. it doesn't crash) is to use a DSA cert for the login but
> then it won't let an RSA cert be a recipient!
>
> TIA
> -Jonathan
>
----------------------------------------------------------------------------
> -
> // construct message to encrypt.
> char *msgStr = "Content-Type: Text/Plain\nContent-Transfer-Encoding:
> 7bit\n\rTestMessage\n\r";
> // Login and setup our instance.
> AppLogin = new CSM_AppLogin();
> AppLogin->AddLogin("sm_free3DLLd", "sm_free3DLL ./certs/DaisyRsaExts.out
> NULL NULL sm_FREE3");
> CSM_CSInst *tmpInst =NULL;
> for (tmpInst = AppLogin->m_pCSInsts->FirstL(); tmpInst != NULL;tmpInst =
> AppLogin->m_pCSInsts->NextL())
> {
> tmpInst->SetUseThis();
> }
> // Set up content.
> CSM_Content mycontent(msgStr);
> CSM_MsgToEncrypt myencrypt;
> myencrypt.SetEncapContent(mycontent);
> // Set content type and content encryption type.
> CSM_OID tmpoid("1.2.840.113549.1.7.1"); // PKCS#7 DATA
> myencrypt.setContentType(tmpoid);
> CSM_OID tmp2oid("1.2.840.113549.3.2"); // # rc2 cbc // old def for MSEO
> interop.
> myencrypt.SetContentEncryptOID(&tmp2oid);
> // Set whether to include original certs, IssOrSki,
> myencrypt.SetIncludeOrigCertsFlag(false);
> myencrypt.m_bIssOrSki = false; // True if SUBJECT KEY IDENTIFIER is
> used.
> // Do NOT Add originator as recipient
> myencrypt.SetAddOriginatorAsRecipient(false);
> // Setup recipients.
> CSM_RecipientInfo *pRecipInfo = NULL;
> CSM_Buffer *pbufCert = new CSM_Buffer("./certs/DaisyRsaExts.out");
> pbufCert->ConvertFileToMemory();
> pRecipInfo = new CSM_RecipientInfo(*pbufCert);
> myencrypt.m_pRecipients = new CSM_RecipientInfoLst;
> myencrypt.m_pRecipients->AppendL(pRecipInfo);
> // Encrypt
> myencrypt.Encrypt(AppLogin);
>
----------------------------------------------------------------------------
> --
>
============================================================================
> ==
> Jonathan C. Schulze-Hewett Email: [email protected]
> Software Engineer
> Information Security Corporation Voice: 708-445-1704
> 1011 W. Lake Street, Suite 212 Fax: 708-455-9705
> Oak Park, IL 60301 WWW: http://www.infoseccorp.com
--
============================================================================
==
Jonathan C. Schulze-Hewett Email: [email protected]
Software Engineer
Information Security Corporation Voice: 708-445-1704
1011 W. Lake Street, Suite 212 Fax: 708-455-9705
Oak Park, IL 60301 WWW: http://www.infoseccorp.com