require PKCS#8 v2 format for better security

Notably, this format requires that the public key also be present.
This format is what ed25519_new_keypair/1 generates, and it is
strongly encouraged for higher security.
This commit is contained in:
Markus Triska
2020-05-20 23:51:31 +02:00
parent 2845f55157
commit b43f27030e
2 changed files with 5 additions and 5 deletions

View File

@@ -644,9 +644,9 @@ encoding_bytes(utf8, Cs, Bs) :-
The public key is represented as a list of characters.
- ed25519_sign(+Key, +Data, -Signature, +Options)
Key and Data must be lists of characters. Key is a private key or
key pair in PKCS#8 (v1 or v2) DER format. Sign Data with Key,
yielding Signature as a list of hexadecimal characters.
Key and Data must be lists of characters. Key is a key pair in
PKCS#8 v2 format as generated by ed25519_new_keypair/1. Sign Data
with Key, yielding Signature as a list of hexadecimal characters.
- ed25519_verify(+Key, +Data, +Signature, +Options)
Key and Data must be lists of characters. Key is a public key.

View File

@@ -5461,7 +5461,7 @@ impl MachineState {
let stub1 = MachineError::functor_stub(clause_name!("ed25519_keypair_public_key"), 2);
let bytes = self.integers_to_bytevec(temp_v!(1), stub1);
let key_pair = match signature::Ed25519KeyPair::from_pkcs8_maybe_unchecked(&bytes) {
let key_pair = match signature::Ed25519KeyPair::from_pkcs8(&bytes) {
Ok(kp) => { kp }
_ => { self.fail = true; return Ok(()); }
};
@@ -5479,7 +5479,7 @@ impl MachineState {
let stub2 = MachineError::functor_stub(clause_name!("ed25519_sign"), 4);
let data = self.integers_to_bytevec(temp_v!(2), stub2);
let key_pair = match signature::Ed25519KeyPair::from_pkcs8_maybe_unchecked(&key) {
let key_pair = match signature::Ed25519KeyPair::from_pkcs8(&key) {
Ok(kp) => { kp }
_ => { self.fail = true; return Ok(()); }
};