require PKCS#8 v2 format for better security

Notably, this format requires that the public key also be present.
This format is what ed25519_new_keypair/1 generates, and it is
strongly encouraged for higher security.
This commit is contained in:
Markus Triska
2020-05-20 23:51:31 +02:00
parent 2845f55157
commit b43f27030e
2 changed files with 5 additions and 5 deletions

View File

@@ -644,9 +644,9 @@ encoding_bytes(utf8, Cs, Bs) :-
The public key is represented as a list of characters. The public key is represented as a list of characters.
- ed25519_sign(+Key, +Data, -Signature, +Options) - ed25519_sign(+Key, +Data, -Signature, +Options)
Key and Data must be lists of characters. Key is a private key or Key and Data must be lists of characters. Key is a key pair in
key pair in PKCS#8 (v1 or v2) DER format. Sign Data with Key, PKCS#8 v2 format as generated by ed25519_new_keypair/1. Sign Data
yielding Signature as a list of hexadecimal characters. with Key, yielding Signature as a list of hexadecimal characters.
- ed25519_verify(+Key, +Data, +Signature, +Options) - ed25519_verify(+Key, +Data, +Signature, +Options)
Key and Data must be lists of characters. Key is a public key. Key and Data must be lists of characters. Key is a public key.

View File

@@ -5461,7 +5461,7 @@ impl MachineState {
let stub1 = MachineError::functor_stub(clause_name!("ed25519_keypair_public_key"), 2); let stub1 = MachineError::functor_stub(clause_name!("ed25519_keypair_public_key"), 2);
let bytes = self.integers_to_bytevec(temp_v!(1), stub1); let bytes = self.integers_to_bytevec(temp_v!(1), stub1);
let key_pair = match signature::Ed25519KeyPair::from_pkcs8_maybe_unchecked(&bytes) { let key_pair = match signature::Ed25519KeyPair::from_pkcs8(&bytes) {
Ok(kp) => { kp } Ok(kp) => { kp }
_ => { self.fail = true; return Ok(()); } _ => { self.fail = true; return Ok(()); }
}; };
@@ -5479,7 +5479,7 @@ impl MachineState {
let stub2 = MachineError::functor_stub(clause_name!("ed25519_sign"), 4); let stub2 = MachineError::functor_stub(clause_name!("ed25519_sign"), 4);
let data = self.integers_to_bytevec(temp_v!(2), stub2); let data = self.integers_to_bytevec(temp_v!(2), stub2);
let key_pair = match signature::Ed25519KeyPair::from_pkcs8_maybe_unchecked(&key) { let key_pair = match signature::Ed25519KeyPair::from_pkcs8(&key) {
Ok(kp) => { kp } Ok(kp) => { kp }
_ => { self.fail = true; return Ok(()); } _ => { self.fail = true; return Ok(()); }
}; };