Skip to content

fields_to_partial_json() in jwk.py reads RSA private key #278

Description

@therealcmj

Using an RSA provided by an HSM I discovered a code path where josepy attempted to read the private key "numbers" when calling challenge.validation() on a DNS challenge (passing in the RSAKey object).

The specific issue is on line 269, and then the values from that key are then read in 274-279.

private = self.key.private_numbers()

This in definitely incorrect since RSA private keys should be kept completely private, but does work when the the RSAPrivateKey allows you to read those numbers. However, if the RSA key is stored in an HSM this is (rightly) impossible.

Commenting out those lines appears to have no ill effect - at least on DNS challenges and Let's Encrypt's staging server. I was able to submit an order, retrieve the challenges, call .validate() on both the DNS and HTTP challenges, answer the DNS challenge, finalize the order, and retrieve the certificate.

I found a similar issue in the ECDSA code (lines 364, 366, 394), but did not do any testing on changing those.

I'm happy to provide a pull request if you would like, but thought I should open the issue first to discuss.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions