20250106-_DhSetKey-FFDHE-short-circuit #8335
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
wolfcrypt/src/dh.c
: in_DhSetKey()
, add short-circuit comparisons to RFC 7919 known-good moduli, preempting overhead frommp_prime_is_prime()
.wolfcrypt/test/test.c
: indh_ffdhe_test()
, whendefined(HAVE_PUBLIC_FFDHE)
, usewc_DhSetKey_ex()
rather thanwc_DhSetKey()
to exercise the primality check in_DhSetKey()
.see ZD#18507
tested with
wolfssl-multi-test.sh ... check-source-text fips-140-2-optest fips-140-3-dev-all
plus enable-all builds withCPPFLAGS=-DHAVE_PUBLIC_FFDHE
.