fix(mbedtls): revert to non constant time rsa key gen

This commit is contained in:
Ashish Sharma
2026-07-21 16:07:31 +08:00
parent 6813d2d2fe
commit 73fb4ce272
2 changed files with 5 additions and 5 deletions
+4 -4
View File
@@ -544,7 +544,7 @@ menu "mbedTLS"
config MBEDTLS_CONSTANT_TIME_PRIME_GEN config MBEDTLS_CONSTANT_TIME_PRIME_GEN
bool "Constant-time prime generation" bool "Constant-time prime generation"
default y default n
help help
Use mbedtls' constant-time small-factor test (a constant-time Use mbedtls' constant-time small-factor test (a constant-time
GCD against the product of all odd primes up to 997) when GCD against the product of all odd primes up to 997) when
@@ -559,9 +559,9 @@ menu "mbedTLS"
If disabled, the variable-time trial division that mbedtls If disabled, the variable-time trial division that mbedtls
used before version 3.6.7 is used instead, restoring key used before version 3.6.7 is used instead, restoring key
generation performance. Only consider disabling this if no generation performance.
untrusted code running on the device could observe the timing
of key generation operations. Please see issue: https://github.com/Mbed-TLS/mbedtls/issues/10830
endmenu # Security hardening endmenu # Security hardening
@@ -215,7 +215,7 @@
/* mbedtls 3.6.7 made the small-factor test used in prime generation /* mbedtls 3.6.7 made the small-factor test used in prime generation
* constant-time, which slows RSA key generation down roughly tenfold and * constant-time, which slows RSA key generation down roughly tenfold and
* starves the idle task (the computation never yields the CPU). The * starves the idle task (the computation never yields the CPU). The
* constant-time variant is the default; when it is explicitly disabled, * non constant-time variant is the default; when it is disabled,
* fall back to the variable-time trial division from earlier releases. See * fall back to the variable-time trial division from earlier releases. See
* MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in library/bignum.c. * MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME in library/bignum.c.
*/ */