wycheproof-rsa-pkcs1-sig-no-hash
RSA PKCS#1: No hash
The signature uses no hash function.
REJECT
Your service should reject this one.
Stated as the outcome to assert against, so a suite compares with this rather than hardcoding a result and getting it backwards.
Collision resistant hash functions are essential for the security of RSA signatures. Accepting signatures without proper hashing and padding probably allows signature forgeries. Demonstrated by 48 test vectors across 24 vector documents in Project Wycheproof.
Provenance
- Kind
- vulnerabilityA published weakness exists for this. Failing it is a known exploit path.
- Source
- wycheproof
- Clause
- RFC 8017 §8.2
- CVE
- none
- Weakness
- none
Test keys only. Nothing here is a statement about any particular service: the expected outcome above is what an application ought to do, not evidence that yours does.