diff options
author | 2018-11-05 23:54:27 +0000 | |
---|---|---|
committer | 2018-11-05 23:54:27 +0000 | |
commit | 99212bcc5f18753b2ec00e9dd1d2fa2407cb697a (patch) | |
tree | 56517b4d61c8fa97e18bcc986c230f5a4d33cba7 /lib/libcrypto/dh/dh_key.c | |
parent | Introduce bn_rand_interval() that allows specifying an interval [a, b) (diff) | |
download | wireguard-openbsd-99212bcc5f18753b2ec00e9dd1d2fa2407cb697a.tar.xz wireguard-openbsd-99212bcc5f18753b2ec00e9dd1d2fa2407cb697a.zip |
Make use of bn_rand_interval() where appropriate.
ok beck jsing
Diffstat (limited to 'lib/libcrypto/dh/dh_key.c')
-rw-r--r-- | lib/libcrypto/dh/dh_key.c | 15 |
1 files changed, 9 insertions, 6 deletions
diff --git a/lib/libcrypto/dh/dh_key.c b/lib/libcrypto/dh/dh_key.c index 2cbf128d80a..17df620ec5b 100644 --- a/lib/libcrypto/dh/dh_key.c +++ b/lib/libcrypto/dh/dh_key.c @@ -1,4 +1,4 @@ -/* $OpenBSD: dh_key.c,v 1.31 2018/11/05 23:50:05 tb Exp $ */ +/* $OpenBSD: dh_key.c,v 1.32 2018/11/05 23:54:27 tb Exp $ */ /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * @@ -106,7 +106,7 @@ generate_key(DH *dh) unsigned l; BN_CTX *ctx; BN_MONT_CTX *mont = NULL; - BIGNUM *pub_key = dh->pub_key, *priv_key = dh->priv_key; + BIGNUM *pub_key = dh->pub_key, *priv_key = dh->priv_key, *two = NULL; if (BN_num_bits(dh->p) > OPENSSL_DH_MAX_MODULUS_BITS) { DHerror(DH_R_MODULUS_TOO_LARGE); @@ -137,10 +137,12 @@ generate_key(DH *dh) if (generate_new_key) { if (dh->q) { - do { - if (!BN_rand_range(priv_key, dh->q)) - goto err; - } while (BN_is_zero(priv_key) || BN_is_one(priv_key)); + if ((two = BN_new()) == NULL) + goto err; + if (!BN_add(two, BN_value_one(), BN_value_one())) + goto err; + if (!bn_rand_interval(priv_key, two, dh->q)) + goto err; } else { /* secret exponent length */ l = dh->length ? dh->length : BN_num_bits(dh->p) - 1; @@ -165,6 +167,7 @@ generate_key(DH *dh) if (dh->priv_key == NULL) BN_free(priv_key); BN_CTX_free(ctx); + BN_free(two); return ok; } |