Fail if a padding disabled by the build-time configuration is selected

Signed-off-by: Ronald Cron <ronald.cron@arm.com>
This commit is contained in:
Ronald Cron 2021-06-08 10:22:28 +02:00
parent 266b6d2121
commit 3a0375fff4
3 changed files with 29 additions and 4 deletions

View File

@ -500,9 +500,20 @@ void mbedtls_rsa_init( mbedtls_rsa_context *ctx )
int mbedtls_rsa_set_padding( mbedtls_rsa_context *ctx, int padding,
mbedtls_md_type_t hash_id )
{
if( ( padding != MBEDTLS_RSA_PKCS_V15 ) &&
( padding != MBEDTLS_RSA_PKCS_V21 ) )
return( MBEDTLS_ERR_RSA_INVALID_PADDING );
switch( padding )
{
#if defined(MBEDTLS_PKCS1_V15)
case MBEDTLS_RSA_PKCS_V15:
break;
#endif
#if defined(MBEDTLS_PKCS1_V21)
case MBEDTLS_RSA_PKCS_V21:
break;
#endif
default:
return( MBEDTLS_ERR_RSA_INVALID_PADDING );
}
if( ( padding == MBEDTLS_RSA_PKCS_V21 ) &&
( hash_id != MBEDTLS_MD_NONE ) )

View File

@ -119,7 +119,7 @@ int main( int argc, char *argv[] )
MBEDTLS_RSA_PKCS_V21,
MBEDTLS_MD_SHA256 ) ) != 0 )
{
mbedtls_printf( " failed\n ! Invalid padding\n" );
mbedtls_printf( " failed\n ! Padding not supported\n" );
goto exit;
}

View File

@ -36,6 +36,20 @@ void rsa_invalid_param( )
invalid_hash_id ),
MBEDTLS_ERR_RSA_INVALID_PADDING );
#if !defined(MBEDTLS_PKCS1_V15)
TEST_EQUAL( mbedtls_rsa_set_padding( &ctx,
MBEDTLS_RSA_PKCS_V15,
MBEDTLS_MD_NONE ),
MBEDTLS_ERR_RSA_INVALID_PADDING );
#endif
#if !defined(MBEDTLS_PKCS1_V21)
TEST_EQUAL( mbedtls_rsa_set_padding( &ctx,
MBEDTLS_RSA_PKCS_V21,
MBEDTLS_MD_NONE ),
MBEDTLS_ERR_RSA_INVALID_PADDING );
#endif
exit:
mbedtls_rsa_free( &ctx );
}