Files
ipxe/src
Michael Brown 1901e32240 [crypto] Reject non-canonical ECDSA signature encodings
As detailed in commit 511dfd2 ("[crypto] Reject non-canonical ECDSA
signature data structures"), changing the representation of a valid
ECDSA signature to a different valid representation of the same
signature does not conceptually make it an invalid signature.

However, some large public test vector sets conflate the concepts of
"altered representation" and "invalid representation" in a way that
makes it difficult to determine which tests ought to pass and which
ought to fail without extensive manual analysis.

Reject any ECDSA signature object that does not have the expected
total length.  The signature parsing logic already ensures that the
expected structure exists, and so the total length can be correct only
if every object used the expected DER encoding.

This length check completely subsumes the checks that were introduced
in commit 511dfd2 ("[crypto] Reject non-canonical ECDSA signature data
structures"), since there is no way to insert additional information
without also affecting the length.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
2026-09-04 16:51:54 +01:00
..
2010-05-29 23:49:47 +01:00