wycheproof-rsa-pss-mgf1-sha1
RSA-PSS: Mgf1 sha1
The test vector uses MGF1SHA1. MGF1SHA1 is an algorithm that is still among the recommended algorithms in RFC 8017 Section B.1, while SHA-1 is of course no longer recommended for the message digest.
ACCEPT
Your service should accept this one.
Stated as the outcome to assert against, so a suite compares with this rather than hardcoding a result and getting it backwards.
The test vector uses MGF1SHA1. MGF1SHA1 is an algorithm that is still among the recommended algorithms in RFC 8017 Section B.1, while SHA-1 is of course no longer recommended for the message digest. Demonstrated by 60 test vectors across 2 vector documents in Project Wycheproof.
Provenance
- Kind
- normativeA specification clause requires this. Failing it is non-conformance, not opinion.
- Source
- wycheproof
- Clause
- RFC 8017 §8.1
- CVE
- none
- Weakness
- none
Test keys only. Nothing here is a statement about any particular service: the expected outcome above is what an application ought to do, not evidence that yours does.