[release/11.0] X25519: Handle zero peer keys on downlevel Windows platforms - #134607
Open
github-actions[bot] wants to merge 1 commit into
Open
github-actions[bot] wants to merge 1 commit into
github-actions[bot] wants to merge 1 commit into
Conversation
An all-zero peer (public) key should always produce a zero shared secret, which should get rejected during key agreement. Windows normally rejects this during importation time, but that is not enabled because Windows would also eagerly reject off-twist public keys which should work. With this change, when a "zero" public key is imported (either by naturally being zero or reduced to zero) we skip importing it into bcrypt and retain "This was a zero key". During derivation we throw since that would produce a zero shared secret. This keeps Windows consistent with other platforms, where import is not the protected path, but derivation is. For X25519DHCng (ncrypt) its not possible to really gate this when the peer key is zero. However that responsibility falls to the person creating the public key handle, and the handle is external in this case. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
|
Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security |
Member
|
/azp run runtime-coreclr libraries-jitstress |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #134535 to release/11.0
/cc @vcsjones
Customer Impact
The X25519DiffieHellman class that was introduced in .NET 11 did not handle certain invalid public keys in an expected manner. These public keys should allow being imported, but should reject being used while deriving secret agreements.
On older, but supported, builds of Windows 10, the Windows implementation would either reject too early, or too late, making its behavior inconsistent with other platforms. This was uncovered when
Hpkehad test cases added that exercised error paths.Regression
Testing
New test were added.
Risk
Low. Small, well understood, and isolated change to X25519DiffieHellman's Windows implementation.