Skip to content

crypto(webcrypto): ECDH Named curve mismatch #35812

Description

@panva
  • Version: v15.0.1
  • Platform: Darwin C02CX0K5MD6V 19.6.0 Darwin Kernel Version 19.6.0: Mon Aug 31 22:12:52 PDT 2020; root:xnu-6153.141.2~1/RELEASE_X86_64 x86_64
  • Subsystem: crypto.webcrypto

What steps will reproduce the bug?

This rejects

subtle.importKey(
    "jwk",
    {
        kty: "EC",
        crv: "P-256",
        x: "kgR_PqO07L8sZOBbw6rvv7O_f7clqDeiE3WnMkb5EoI",
        y: "djI-XqCqSyO9GFk_QT_stROMCAROIvU8KOORBgQUemE",
        d: "5aPFSt0UFVXYGu-ZKyC9FQIUOAMmnjzdIwkxCMe3Iok",
        alg: 'ECDH-ES',
    },
    {
        name: "ECDH",
        namedCurve: "P-256"
    },
    false,
    ["deriveKey", "deriveBits"]
)

This works, difference is the presence of the JWK "alg" (Algorithm) Parameter

subtle.importKey(
    "jwk",
    {
        kty: "EC",
        crv: "P-256",
        x: "kgR_PqO07L8sZOBbw6rvv7O_f7clqDeiE3WnMkb5EoI",
        y: "djI-XqCqSyO9GFk_QT_stROMCAROIvU8KOORBgQUemE",
        d: "5aPFSt0UFVXYGu-ZKyC9FQIUOAMmnjzdIwkxCMe3Iok",
    },
    {
        name: "ECDH",
        namedCurve: "P-256"
    },
    false,
    ["deriveKey", "deriveBits"]
)

What is the expected behavior?

The key import promise should resolve. (I think, at least it does in Chromium's Web Crypto API implementation.

// cc @jasnell

Activity

  1. added
    cryptoIssues and PRs related to the crypto subsystem.
    on Oct 27, 2020
  2. mmomtchev commented on Oct 28, 2020

    @mmomtchev
    Contributor

    I am not an expert on this, but I think P-256 curve should be used only with ES256 algorithm
    Maybe Chromium ignores crv when you set the algorithm to ECDH-ES
    I don't think that P-256 with ECDH-ES is a valid combination, I don't see it in the RFC
    https://tools.ietf.org/html/rfc7518

  3. panva commented on Oct 28, 2020

    @panva
    MemberAuthor

    @mmomtchev this ticket is not about JOSE per se. But even if it was then of course the three original EC curves are usable for ECDH-ES. secp256k1 isn't per it's jose registration, but that curve isn't supported by webcrypto at all

  4. panva commented on Oct 28, 2020

    @panva
    MemberAuthor

    Looking at the spec (webcrypto one) ecdh jwk key import does not work with jwk.alg at all. It seems this is indeed a bug in node's implementation.

  5. jasnell commented on Oct 28, 2020

    @jasnell
    Member

    Sounds like it. Do you want to take a look at a fix @panva?

  6. panva commented on Oct 28, 2020

    @panva
    MemberAuthor

    @jasnell i'll take a stab at it.

  7. added a commit that references this issue on Oct 28, 2020
    c2c955d
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions