mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
Merge branch 'feat/disable_constant_time_rsa_key_gen_v5.5' into 'release/v5.5'
fix(mbedtls): revert to non constant time rsa key gen See merge request espressif/esp-idf!51022
This commit is contained in:
@@ -544,7 +544,7 @@ menu "mbedTLS"
|
||||
|
||||
config MBEDTLS_CONSTANT_TIME_PRIME_GEN
|
||||
bool "Constant-time prime generation"
|
||||
default y
|
||||
default n
|
||||
help
|
||||
Use mbedtls' constant-time small-factor test (a constant-time
|
||||
GCD against the product of all odd primes up to 997) when
|
||||
@@ -559,9 +559,9 @@ menu "mbedTLS"
|
||||
|
||||
If disabled, the variable-time trial division that mbedtls
|
||||
used before version 3.6.7 is used instead, restoring key
|
||||
generation performance. Only consider disabling this if no
|
||||
untrusted code running on the device could observe the timing
|
||||
of key generation operations.
|
||||
generation performance.
|
||||
|
||||
Please see issue: https://github.com/Mbed-TLS/mbedtls/issues/10830
|
||||
|
||||
endmenu # Security hardening
|
||||
|
||||
|
||||
@@ -215,7 +215,7 @@
|
||||
/* mbedtls 3.6.7 made the small-factor test used in prime generation
|
||||
* constant-time, which slows RSA key generation down roughly tenfold and
|
||||
* starves the idle task (the computation never yields the CPU). The
|
||||
* constant-time variant is the default; when it is explicitly disabled,
|
||||
* non constant-time variant is the default; when it is disabled,
|
||||
* fall back to the variable-time trial division from earlier releases. See
|
||||
* MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in library/bignum.c.
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user