rsa/psa: tune doc about RSA v1.5 decrypt usage

Signed-off-by: Manuel Pégourié-Gonnard <[email protected]>
This commit is contained in:
Manuel Pégourié-Gonnard
2026-06-08 11:39:44 +02:00
parent fe47e9ed89
commit 7e51c31aef
3 changed files with 11 additions and 7 deletions
+4 -3
View File
@@ -737,12 +737,13 @@ int mbedtls_rsa_pkcs1_decrypt(mbedtls_rsa_context *ctx,
* operation (RSAES-PKCS1-v1_5-DECRYPT).
*
* \warning This is an inherently dangerous function (CWE-242). Unless
* it is used in a side channel free and safe way (eg.
* implementing the TLS protocol as per 7.4.7.1 of RFC 5246),
* it is used in a side channel free and safe way,
* the calling code is vulnerable.
* Specifically, callers need to ensure an adversary cannot
* distinguish between success, MBEDTLS_ERR_RSA_INVALID_PADDING
* and MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE via side channels.
* and MBEDTLS_ERR_RSA_OUTPUT_TOO_LARGE. Also, in the latter two
* cases, the values of the output bytes must be ignored, again
* without revealing whether that's the case.
*
* \note The output buffer length \c output_max_len should be
* as large as the size \p ctx->len of \p ctx->N, for example,
+6 -2
View File
@@ -3127,9 +3127,13 @@ psa_status_t psa_asymmetric_encrypt(mbedtls_svc_key_id_t key,
*
* \warning When \p alg is #PSA_ALG_RSA_PKCS1V15_CRYPT, this is an
* inherently dangerous function (CWE-242): unless it is used
* in a side channel free and safe way (eg. implementing the
* TLS protocol as per 7.4.7.1 of RFC 5246), the calling code
* in a side channel free and safe way, the calling code
* is vulnerable.
* Specifically, callers need to ensure an adversary cannot
* distinguish between success, #PSA_ERROR_INVALID_PADDING and
* #PSA_ERROR_BUFFER_TOO_SMALL. Also, in the latter two cases,
* the values of the output bytes must be ignored, again
* without revealing whether that's the case.
*
* \param key Identifier of the key to use for the operation.
* It must be an asymmetric key pair. It must
+1 -2
View File
@@ -1760,8 +1760,7 @@
* \warning Calling psa_asymmetric_decrypt() with this algorithm as a
* parameter is considered an inherently dangerous function
* (CWE-242). Unless it is used in a side channel free and safe
* way (eg. implementing the TLS protocol as per 7.4.7.1 of
* RFC 5246), the calling code is vulnerable.
* way, the calling code is vulnerable.
*
*/
#define PSA_ALG_RSA_PKCS1V15_CRYPT ((psa_algorithm_t) 0x07000200)