- djm@cvs.openbsd.org 2009/02/17 01:28:32
[ssh_config]
sync with revised default ciphers; pointed out by dkrause@
+ - djm@cvs.openbsd.org 2009/02/18 04:31:21
+ [schnorr.c]
+ signature should hash over the entire group, not just the generator
+ (this is still disabled code)
20090216
- (djm) [regress/conch-ciphers.sh regress/putty-ciphers.sh]
-/* $OpenBSD: schnorr.c,v 1.1 2008/11/04 08:22:13 djm Exp $ */
+/* $OpenBSD: schnorr.c,v 1.2 2009/02/18 04:31:21 djm Exp $ */
/*
* Copyright (c) 2008 Damien Miller. All rights reserved.
*
buffer_init(&b);
EVP_MD_CTX_init(&evp_md_ctx);
- /* h = H(g || g^v || g^x || id) */
+ /* h = H(g || p || q || g^v || g^x || id) */
buffer_put_bignum2(&b, g);
+ buffer_put_bignum2(&b, p);
+ buffer_put_bignum2(&b, q);
buffer_put_bignum2(&b, g_v);
buffer_put_bignum2(&b, g_x);
buffer_put_string(&b, id, idlen);