crmf: tag non-CHOICE fields implicitly, as RFC 4211 defines - #2466
Open
yuxi-liu-wired wants to merge 1 commit into
Open
yuxi-liu-wired wants to merge 1 commit into
yuxi-liu-wired wants to merge 1 commit into
Conversation
RFC 4211's ASN.1 module is DEFINITIONS IMPLICIT TAGS. A context tag is explicit only when the tagged type is a CHOICE (X.680 31.2.7), which crmf already does for Name, Time, GeneralName and POPOPrivKey. Eight other tags were EXPLICIT although their types are not CHOICEs: - POPOPrivKey: thisMessage [0] and dhMAC [2] BIT STRING, subsequentMessage [1] INTEGER, agreeMAC [3] PKMACValue, encryptedKey [4] EnvelopedData - PKIArchiveOptions: keyGenParameters [1] OCTET STRING, archiveRemGenPrivKey [2] BOOLEAN - EncryptedKey: envelopedData [0] EnvelopedData So crmf/cmpv2 could not decode, e.g., an ir from OpenSSL's `openssl cmp -popo 2` (key-encipherment POP `a2 03 81 01 00`: "got CONTEXT-SPECIFIC [1] (primitive)"), and encoded these fields in a form OpenSSL rejects. OpenSSL's crmf_asn.c uses IMPLICIT for all of them. New tests decode and re-encode each alternative from pyasn1 encodings of the RFC module, and OpenSSL's key-encipherment POP. OpenSSL 3.5 ir messages with POP RAVERIFIED, SIGNATURE and KEYENC (RSA and EC) now all decode via cmpv2 and re-encode byte for byte.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
RFC 4211's ASN.1 module is
DEFINITIONS IMPLICIT TAGS. A context tag is explicit only when the tagged type is a CHOICE (X.680 31.2.7), and crmf already does that forName,Time,GeneralNameandPOPOPrivKey. Eight other tags are declaredEXPLICITalthough their types aren't CHOICEs:POPOPrivKeythisMessage [0],dhMAC [2]POPOPrivKeysubsequentMessage [1]POPOPrivKeyagreeMAC [3]POPOPrivKeyencryptedKey [4]PKIArchiveOptionskeyGenParameters [1]PKIArchiveOptionsarchiveRemGenPrivKey [2]EncryptedKeyenvelopedData [0]OpenSSL's
crypto/crmf/crmf_asn.cusesASN1_IMPfor every one of these that it implements. In practice, crmf/cmpv2 can't decode a CMPirfromopenssl cmp -popo 2(key-encipherment proof of possession), whose POP isa2 03 81 01 00:Encoding has the same problem: crmf writes these fields in a form OpenSSL rejects. The existing tests only round-trip crmf's own output, so they didn't notice.
The fix changes the eight tags to
IMPLICIT(primitive for the BIT STRING, INTEGER, OCTET STRING and BOOLEAN alternatives).Tests:
tests/implicit_tags.rsdecodes and re-encodes, byte for byte, eachPOPOPrivKeyandPKIArchiveOptionsalternative as encoded by pyasn1 from the RFC 4211 module, plus the key-encipherment POP from OpenSSL. All three tests fail on master. I also checked that OpenSSL 3.5irmessages with POP RAVERIFIED, SIGNATURE and KEYENC (RSA and EC keys) all decode throughcmpv2::message::PkiMessageand re-encode identically; two of the four fail on master. Thecrmf.ymlmatrix passed locally (powerset tests on stable and 1.85, thumbv7em powerset build, fmt, clippy), along with thecmpv2all-features tests.This PR was produced by AI agents (Claude) and reviewed by me before submission.