bcrypt: Validate imported ECC public keys - #11
Merged
jungwuk-ryu merged 1 commit intoAug 9, 2026
Merged
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Stop requesting minimal SymCrypt validation so malformed public points and invalid private scalars are rejected. Derive generic blob coordinate sizes from the configured curve before forming pointers, and translate expected SymCrypt failures to BCrypt status codes. Add ECDSA and ECDH tests for invalid points and mismatched generic coordinate lengths.
jungwuk-ryu
force-pushed
the
codex/fix-public-key-validation-bypass-in-ecc-imports
branch
from
August 9, 2026 10:11
23fd04f to
db88e8b
Compare
Owner
Author
Review completedRoot cause and fix
Verification
Final review
|
jungwuk-ryu
deleted the
codex/fix-public-key-validation-bypass-in-ecc-imports
branch
August 9, 2026 10:12
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
SYMCRYPT_FLAG_KEY_MINIMAL_VALIDATION, which causes SymCrypt to skip required public-key checks for imported ECDH/ECDSA blobs and allows a validation bypass for caller-controlled key material.Description
SYMCRYPT_FLAG_KEY_MINIMAL_VALIDATIONfromget_ecc_import_flags()indlls/bcrypt/bcrypt_main.cso imported ECC public keys are passed to SymCrypt without the minimal-validation opt-out and therefore receive full point and subgroup validation duringSymCryptEckeySetValue().Testing
git diff --checkwith no issues reported.git status --short --branchto inspect repository state and it completed successfully.git show --stat --oneline HEADto confirm the change is present and it completed successfully.Codex Task