wycheproof-dsa-integer-overflow
DSA: Integer overflow
The test vector contains an r and s that has been modified, so that the original value is restored if the implementation ignores the most significant bits.
REJECT
Your service should reject this one.
Stated as the outcome to assert against, so a suite compares with this rather than hardcoding a result and getting it backwards.
Without further analysis it is unclear if the modification can be used to forge signatures. Demonstrated by 36 test vectors across 8 vector documents in Project Wycheproof.
Provenance
- Kind
- hardeningDefensible practice with no normative source. Judge it for yourself.
- Source
- wycheproof
- Clause
- FIPS 186-4 §4
- CVE
- none
- Weakness
- none
Test keys only. Nothing here is a statement about any particular service: the expected outcome above is what an application ought to do, not evidence that yours does.