OpenSSL leaks RSA private key information into entropy subsystem
marc.info
marc.info
if ((RAND_status() == 0) && rsa->d != NULL && rsa->d->d != NULL)
{
/* if PRNG is not properly seeded, resort to secret
* exponent as unpredictable seed */
RAND_add(rsa->d->d, rsa->d->dmax * sizeof rsa->d->d[0], 0.0);
}
This line is equivalent to "if you are already totally and royally fucked, do something cosmetic to pretend otherwise".The line occurs during the setup for RSA blinding, which is the only point in the core RSA code (outside keygen) that requires randomness --- blinding mixes a random integer into the otherwise deterministic RSA operation, to foil timing analysis. The code should probably abort when that condition happens. I think, at first glance, that the condition never really happens on normal systems.
Edit: apparently my brain went offline at a critical sentence. Consider this reinforcement of that point.
The justification given in the patch is that the private key might be given to a pluggable random number generator, which may presumably be controlled by an attacker or otherwise leak the key somehow. In that case, this bit of code is the least of your problems, since every other entropy is also being equally leaked.
This means that this particular piece of code could NEVER be hit because there is never a time that RAND_status() is going to return 0! i.e. This is unreachable code.
On top of that RAND_add() is a no-op that won't do anything, since there is no way to add "seed" to the PRNG ...
See this commit: http://freshbsd.org/commit/openbsd/58777eed1cff7c5b34cbc0262...
"But apparently the OpenSSL guys could find no objects of lesser value to pass to the pluggable random subsystem, and had to resort to private keys and digests. Classy."
"OPENSSL_DECLARE_EXIT serves no purpose."
"OPENSSL_gmtime() is not a gmtime() wrapper. It is a gmtime_r(). Always trying to confuse people..."
"Change library to use intrinsic memory allocation functions instead of OPENSSL_foo wrappers. This changes: OPENSSL_malloc->malloc OPENSSL_free->free OPENSSL_relloc->realloc OPENSSL_freeFunc->free"
http://freshbsd.org/search?project=openbsd&q=file.name%3Alib...
http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a...
There will be no CSPRNG to initalize.
API/ABI compat will be maintained by NOOPing the functionality.
RAND_status() always returns 1.