]> git.ipfire.org Git - thirdparty/openssl.git/commit
Run DH_check_ex() not DH_check_params_ex() when checking params
authorMatt Caswell <matt@openssl.org>
Tue, 9 Feb 2021 15:12:09 +0000 (15:12 +0000)
committerShane Lontis <shane.lontis@oracle.com>
Mon, 15 Feb 2021 04:17:36 +0000 (14:17 +1000)
commitaee73562d17499f2660c14f8c150459097680a1d
tree5a5007540ad8e528f635f7b5e28de62a1119642a
parent93e43f4c47ea3ec3b916c0a7fcd4912f47460416
Run DH_check_ex() not DH_check_params_ex() when checking params

Both DH_check_ex() and DH_check_params_ex() check the parameters.
DH_check_ex() performs a more complete check, while DH_check_params_ex()
performs a lightweight check. In 1.1.1 EVP_PKEY_param_check() would call
DH_check_ex() for DH keys. For backwards compatibility we should continue
with that behaviour.

Fixes #13501

Reviewed-by: Paul Dale <pauli@openssl.org>
Reviewed-by: Shane Lontis <shane.lontis@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/14146)
providers/implementations/keymgmt/dh_kmgmt.c