Bug 124472

Summary: RSASSA-PKCS1-v1_5 JWK import doesn't check key size
Product: WebKit Reporter: Alexey Proskuryakov <ap>
Component: WebCore Misc.Assignee: Alexey Proskuryakov <ap>
Status: RESOLVED FIXED    
Severity: Normal CC: sam
Priority: P2    
Version: 528+ (Nightly build)   
Hardware: Unspecified   
OS: Unspecified   
Bug Depends on:    
Bug Blocks: 122679    
Attachments:
Description Flags
proposed patch sam: review+

Description Alexey Proskuryakov 2013-11-17 15:56:09 PST
JWA spec says that a key of size 2048 bits or larger MUST be used with "RS256", "RS384", and "RS512" algorithms.
Comment 1 Alexey Proskuryakov 2013-11-17 16:02:17 PST
Created attachment 217158 [details]
proposed patch
Comment 2 Alexey Proskuryakov 2013-11-17 17:16:45 PST
Committed <http://trac.webkit.org/r159393>.