Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion apps/unit_tests/bn_unit_tests.c
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,9 @@ bnTestCreateDoc(const xmlChar* rootName) {
return(NULL);
}

xmlDocSetRootElement(doc, root);
/* xmlDocSetRootElement() returns the previous root element, not an error
* code, so there is no error condition to check here. */
(void)xmlDocSetRootElement(doc, root);
return(doc);
}

Expand Down
15 changes: 9 additions & 6 deletions docs/md/faq.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ licensing then feel free to send these questions to the

See XML Security Library [download page](http://www.aleksey.com/xmlsec/).

### 2.2. How to compile xmlsec?
### 2.2. How to compile xmlsec?

See XML Security Library [installation guide](tutorial/install.md)

Expand Down Expand Up @@ -159,16 +159,17 @@ There might be multiple reasons for the "key cannot be found" error:
parameter in your application.
For example, `--enabled-key-data rsa,key-value,x509` will populate an `<RSAKeyValue>` element (and keep
`<X509Data>` enabled) when the template contains matching `<KeyValue/>` and `<X509Data/>` placeholders.
**THIS IS NOT SECURE AND NOT RECOMMENDED.**
**THIS OPTION IS NOT SECURE AND IT IS NOT RECOMMENDED FOR PRODUCTION USE CASES.**

- **Key is not referenced in KeyInfo node (or this node is not included).** If a key is not referenced in the XML file then it
creates a potential security risk because the key is no longer coupled with signature (the `KeyInfo` node is signed
during the XML signature process and its integrity is validated during XML signature verification). Yet, in some use cases not
during the XML signature process and its integrity is validated during XML signature verification only if it is
covered by a `Reference` in the `SignedInfo` element, for example via a `KeyInfoReference`). Yet, in some use cases not
using the `KeyInfo` node to specify the key can be appropriate. If you verify that this does not present a security
concern for your application, then you can enable "lax" key search mode by using `--lax-key-search` option for the
[xmlsec command line utility](xmlsec-man.md), or by setting `keyInfoCtx->flags |= XMLSEC_KEYINFO_FLAGS_LAX_KEY_SEARCH;`
flag in your application.
**THIS IS NOT SECURE AND NOT RECOMMENDED.**
**THIS OPTION IS NOT SECURE AND IT IS NOT RECOMMENDED FOR PRODUCTION USE CASES.**

- **Certificate cannot be verified.** See the next [question 3.6](#section_3_6) in this FAQ.

Expand All @@ -194,13 +195,15 @@ There might be several reasons why XML Security Library cannot verify a certific
application, then you can re-enable these algorithms (and also skip some other strict certificate verification
checks) by using the `--X509-skip-strict-checks` option for the [xmlsec command line utility](xmlsec-man.md),
or by setting `keyInfoCtx->flags |= XMLSEC_KEYINFO_FLAGS_X509DATA_SKIP_STRICT_CHECKS;` flag in your application.
**THIS IS NOT SECURE AND NOT RECOMMENDED.**
Note that this option is only honored by the GnuTLS backend; other backends (for example, OpenSSL) ignore it and
the underlying cryptographic library may still reject such certificates.
**THIS OPTION IS NOT SECURE AND IT IS NOT RECOMMENDED FOR PRODUCTION USE CASES.**

- Lastly, you can use the `--insecure` option for the [xmlsec command line utility](xmlsec-man.md),
or set `keyInfoCtx->flags |= XMLSEC_KEYINFO_FLAGS_X509DATA_DONT_VERIFY_CERTS;` flag in your application to
completely disable the certificates verification. Disabling certificate verification creates a security risk because
there is no mechanism to verify the key origin (and for example, this enables to create "fake" signatures).
**THIS IS NOT SECURE AND NOT RECOMMENDED.**
**THIS OPTION IS NOT SECURE AND IT IS NOT RECOMMENDED FOR PRODUCTION USE CASES.**

### 3.7. I really like the XML Security Library but it is based on OpenSSL and I have to use another crypto library in my application. Can you write code to support my crypto library?

Expand Down
4 changes: 2 additions & 2 deletions docs/md/key-formats.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ The XML Security Library supports the following key, certificate, and CRL format
| **Private keys** | | | | | | |
| PKCS12 | Yes | Yes [(1)](#nss-eddsa) | Yes [(5)](#gnutls-pkcs12) | Yes [(4)](#mscng-pkcs12) | Yes | No |
| PKCS8 (PEM) | Yes | No | Yes | No | No | No |
| PKCS8 (DER) | Yes | No | Yes | No | No | No |
| PKCS8 (DER) | Yes | Yes | Yes | No | No | No |
| Unencrypted keys (PEM) | Yes | No | Yes | No | No | No |
| Unencrypted keys (DER) | Yes | Yes | Yes | Yes [(3)](#mscng-der-limited) | No | Yes [(2)](#gcrypt-limited) |
| **Public keys** | | | | | | |
Expand All @@ -27,6 +27,6 @@ The XML Security Library supports the following key, certificate, and CRL format

1. <a id="nss-eddsa"></a> NSS cannot import EdDSA private keys from PKCS#12 files; use unencrypted PKCS#8 DER format instead.
2. <a id="gcrypt-limited"></a> The xmlsec-gcrypt library only supports a limited subset of unencrypted private keys and standalone public keys in DER format.
3. <a id="mscng-der-limited"></a> MSCng can only load DH and XDH private keys in unencrypted DER (PrivateKeyInfo) format.
3. <a id="mscng-der-limited"></a> MSCng can only load DH and X25519 (Curve25519) private keys in unencrypted DER (PrivateKeyInfo) format; the X448 (Curve448) is not supported.
4. <a id="mscng-pkcs12"></a> MSCng cannot import DH and XDH private keys from PKCS#12 files; use unencrypted DER (PrivateKeyInfo) format instead.
5. <a id="gnutls-pkcs12"></a> GnuTLS cannot import private keys from PKCS#12 files encrypted with PBES2/PBKDF2 (the default encryption used by OpenSSL 3.x `openssl pkcs12 -export`); use unencrypted DER (PrivateKeyInfo) format instead.
5 changes: 3 additions & 2 deletions docs/md/news.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,8 @@
- The minimum supported versions for dependencies are now: LibXML2 >= 2.9.13 (February 19, 2022),
LibXSLT >= 1.1.35 (February 16, 2022), OpenSSL >= 3.0.13 (January 30, 2024), LibreSSL >= 3.9.0 (March 9, 2024),
NSS >= 3.91 (June 26, 2023), NSPR >= 4.34.1 (June 26, 2023), GnuTLS >= 3.8.3 (January 1, 2024).
- (xmlsec-core) Disabled all key value data for all key types by default (use `--enabled-key-data` flag to re-enable if needed).
- (xmlsec-core) Disabled all raw key value data for all key types by default, extending the 1.3.3 default that disabled the
KeyValue and DEREncodedKeyValue nodes (use `--enabled-key-data` flag to re-enable if needed).
- (xmlsec-core) Added `--enable-asn1-signatures-hack` option to allow generation / verification of ASN1 signature values.
- (xmlsec-core) Added `--verify-crls` option to verify CRLs when loading from command line.
- (xmlsec-openssl) Added support for EdDSA signature algorithm; XDH (X25519 and X448) key agreement algorithms;
Expand Down Expand Up @@ -438,7 +439,7 @@
Changes in [XML Security Library 1.2.14](download.md) release:
- XML Security Library is switched from built-in LTDL library to the system
LTDL library on Linux/Unix and native calls on Windows to fix a
[security issue](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3736) in LTDL.
[security issue (CVE-2009-3736)](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736) in LTDL.
- Fixed minor bugs (see [commits log](https://github.com/lsh123/xmlsec/commits/master) for complete list).

- **September 12, 2009**
Expand Down
8 changes: 4 additions & 4 deletions docs/md/xmldsig.md
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ XML Security library supports the following features as defined in
| [XPath Filter 2.0](https://www.w3.org/TR/2002/REC-xmldsig-filter2-20021108/) | Recommended | Yes |
| [Enveloped Signature Transform](https://www.w3.org/TR/xmldsig-core1/#sec-EnvelopedSignature) | Required | Yes |
| [XSLT Transform](https://www.w3.org/TR/xmldsig-core1/#sec-XSLT) | Optional | Yes [(6)](#xslt) |
| [Decryption Transform](https://www.w3.org/TR/xmlenc-decrypt/) | Optional | Yes |
| [Decryption Transform](https://www.w3.org/TR/xmlenc-decrypt/) | Optional | No |
| [XPointer Transform](https://www.ietf.org/rfc/rfc9231.html#section-2.5.1) | Optional | Yes |

### XMLSec Cryptographic Libraries features
Expand All @@ -68,15 +68,15 @@ XML Security library supports the following features as defined in
| GOST-R3411-94 | Optional | Yes [(3)](#openssl-gost) | No | Yes | No | Yes [(4)](#mscrypto-gost) | No |
| GOST-R3411-2012 (256 bit) | Optional | Yes [(3)](#openssl-gost) | No | Yes | No | Yes [(4)](#mscrypto-gost) | No |
| GOST-R3411-2012 (512 bit) | Optional | Yes [(3)](#openssl-gost) | No | Yes | No | Yes [(4)](#mscrypto-gost) | No |
| [MD5](https://www.ietf.org/rfc/rfc9231.html#section-2.1.1) | DEPRECATED | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) |
| [MD5](https://www.ietf.org/rfc/rfc9231.html#section-2.1.1) | DEPRECATED | Yes [(1)](#feature-disabled) | No | No | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) |
| **Message Authentication Codes** | | | | | | | |
| [HMAC-SHA1](https://www.w3.org/TR/xmldsig-core1/#sec-HMAC) | Required (use is DISCOURAGED) | Yes | Yes | Yes | Yes | Yes | Yes |
| [HMAC-SHA2-224](https://www.w3.org/TR/xmldsig-core1/#sec-HMAC) | Optional | Yes | Yes | Yes | No | No | No |
| [HMAC-SHA2-256](https://www.w3.org/TR/xmldsig-core1/#sec-HMAC) | Required | Yes | Yes | Yes | Yes | Yes | Yes |
| [HMAC-SHA2-384](https://www.w3.org/TR/xmldsig-core1/#sec-HMAC) | Recommended | Yes | Yes | Yes | Yes | Yes | Yes |
| [HMAC-SHA2-512](https://www.w3.org/TR/xmldsig-core1/#sec-HMAC) | Recommended | Yes | Yes | Yes | Yes | Yes | Yes |
| [HMAC-RIPEMD160](https://www.ietf.org/rfc/rfc9231.html#section-2.2.3) | DEPRECATED | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | No | No | No | Yes [(1)](#feature-disabled) |
| [HMAC-MD5](https://www.ietf.org/rfc/rfc9231.html#section-2.2.1) | DEPRECATED | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | No | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) |
| [HMAC-MD5](https://www.ietf.org/rfc/rfc9231.html#section-2.2.1) | DEPRECATED | Yes [(1)](#feature-disabled) | No | No | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) |
| **Signatures** | | | | | | | |
| [DSA-SHA1](https://www.w3.org/TR/xmldsig-core1/#sec-DSA) | Required (use is DISCOURAGED for signature generation) | Yes | Yes | Yes | Yes | Yes | Yes |
| [DSA-SHA256](https://www.w3.org/TR/xmldsig-core1/#sec-DSA) | Optional | Yes | Yes | Yes | Yes | No | No |
Expand All @@ -86,7 +86,7 @@ XML Security library supports the following features as defined in
| [PKCS1 RSA-SHA2-384](https://www.w3.org/TR/xmldsig-core1/#sec-PKCS1) | Optional | Yes | Yes | Yes | Yes | Yes | Yes |
| [PKCS1 RSA-SHA2-512](https://www.w3.org/TR/xmldsig-core1/#sec-PKCS1) | Optional | Yes | Yes | Yes | Yes | Yes | Yes |
| [PKCS1 RSA-RIPEMD160](https://www.ietf.org/rfc/rfc9231.html#section-2.3.5) | DEPRECATED | Yes [(1)](#feature-disabled) | No | No | No | No | Yes [(1)](#feature-disabled) |
| [PKCS1 RSA-MD5](https://www.ietf.org/rfc/rfc9231.html#section-2.3.1) | DEPRECATED | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | No | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) |
| [PKCS1 RSA-MD5](https://www.ietf.org/rfc/rfc9231.html#section-2.3.1) | DEPRECATED | Yes [(1)](#feature-disabled) | No | No | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) | Yes [(1)](#feature-disabled) |
| [ECDSA-RIPEMD160](https://www.ietf.org/rfc/rfc9231.html#section-2.3.6) | DEPRECATED | Yes [(1)](#feature-disabled) | No | No | No | No | No |
| [ECDSA-SHA1](https://www.w3.org/TR/xmldsig-core1/#sec-ECDSA) | Optional (use is DISCOURAGED) | Yes | Yes | Yes | Yes | No | Yes |
| [ECDSA-SHA2-224](https://www.w3.org/TR/xmldsig-core1/#sec-ECDSA) | Optional | Yes | Yes | Yes | No | No | No |
Expand Down
4 changes: 2 additions & 2 deletions docs/md/xmlenc.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,8 +53,8 @@ XML Security library supports the following features as defined in
| [HKDF](https://www.w3.org/2021/04/xmldsig-more#hkdf) | Optional | Yes [(3)](#openssl3-required) | Yes | Yes | Yes [(5)](#new-windows-required) | No | No |
| **Key Transport** | | | | | | | |
| [RSA PKCS1 v1.5](https://www.w3.org/TR/xmlenc-core1/#sec-RSA-1_5) | Optional | Yes | Yes | Yes | Yes | Yes | Yes |
| [RSA-OAEP with MGF1-SHA1](https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP) | Required | Yes | Yes | Yes [(2)](#rsa-oaep-same-algo) | Yes [(2)](#rsa-oaep-same-algo) | Yes [(2)](#rsa-oaep-same-algo) | Yes [(2)](#rsa-oaep-same-algo) |
| [RSA-OAEP with MGF1-SHA224](https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP) | Optional | Yes | Yes | Yes [(2)](#rsa-oaep-same-algo) | No | No | Yes [(2)](#rsa-oaep-same-algo) |
| [RSA-OAEP with MGF1-SHA1](https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP) | Required | Yes | Yes | No | Yes [(2)](#rsa-oaep-same-algo) | Yes [(2)](#rsa-oaep-same-algo) | Yes [(2)](#rsa-oaep-same-algo) |
| [RSA-OAEP with MGF1-SHA224](https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP) | Optional | Yes | Yes | No | Yes [(2)](#rsa-oaep-same-algo) | No | Yes [(2)](#rsa-oaep-same-algo) |
| [RSA-OAEP with MGF1-SHA256](https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP) | Optional | Yes | Yes | Yes [(2)](#rsa-oaep-same-algo) | Yes [(2)](#rsa-oaep-same-algo) | No | Yes [(2)](#rsa-oaep-same-algo) |
| [RSA-OAEP with MGF1-SHA384](https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP) | Optional | Yes | Yes | Yes [(2)](#rsa-oaep-same-algo) | Yes [(2)](#rsa-oaep-same-algo) | No | Yes [(2)](#rsa-oaep-same-algo) |
| [RSA-OAEP with MGF1-SHA512](https://www.w3.org/TR/xmlenc-core1/#sec-RSA-OAEP) | Optional | Yes | Yes | Yes [(2)](#rsa-oaep-same-algo) | Yes [(2)](#rsa-oaep-same-algo) | No | Yes [(2)](#rsa-oaep-same-algo) |
Expand Down
5 changes: 4 additions & 1 deletion src/gcrypt/ciphers.c
Original file line number Diff line number Diff line change
Expand Up @@ -306,7 +306,10 @@ xmlSecGCryptBlockCipherCtxFinal(xmlSecGCryptBlockCipherCtxPtr ctx,
/* check padding.
*
* Only the padding length carried in the last byte is validated (it must be
* non-zero and not exceed the block size). See XML Encryption specification for details. */
* non-zero and not exceed the block size); the remaining padding bytes are not
* checked for equality and the check is not constant-time. This simplified
* validation is a deliberate project-wide design choice, matching the OpenSSL
* backend. See XML Encryption specification for details. */
padding = (xmlSecSize)outBuf[blockLen - 1];
if((padding == 0) || (inSize < padding)) {
xmlSecInvalidSizeLessThanError("Input data padding",
Expand Down
3 changes: 3 additions & 0 deletions src/gcrypt/digests.c
Original file line number Diff line number Diff line change
Expand Up @@ -281,6 +281,9 @@ xmlSecGCryptDigestExecute(xmlSecTransformPtr transform, int last, xmlSecTransfor

inSize = xmlSecBufferGetSize(in);
if(inSize > 0) {
/* The gcry_md_write() return value is not checked: given the validated
* context handle it effectively cannot fail. This is a codebase-wide
* pattern in the gcrypt backend. */
gcry_md_write(ctx->digestCtx, xmlSecBufferGetData(in), inSize);

ret = xmlSecBufferRemoveHead(in, inSize);
Expand Down
4 changes: 4 additions & 0 deletions src/gcrypt/hmac.c
Original file line number Diff line number Diff line change
Expand Up @@ -354,6 +354,10 @@ xmlSecGCryptHmacExecute(xmlSecTransformPtr transform, int last, xmlSecTransformC

inSize = xmlSecBufferGetSize(in);
if(inSize > 0) {
/* The gcry_md_write() return value is not checked: given the validated
* context handle it effectively cannot fail (if it ever did, the input
* chunk would be silently omitted from the HMAC). This is a codebase-wide
* pattern in the gcrypt backend. */
gcry_md_write(ctx->digestCtx, xmlSecBufferGetData(in), inSize);

ret = xmlSecBufferRemoveHead(in, inSize);
Expand Down
9 changes: 9 additions & 0 deletions src/nodeset.c
Original file line number Diff line number Diff line change
Expand Up @@ -162,6 +162,15 @@ xmlSecNodeSetCheckNode(xmlNodeSetPtr nodes, xmlNodePtr node, xmlNodePtr parent)
* same element is rejected) and in xmlNewNs() (a duplicate prefix
* on the same node is rejected), so two declarations with the same
* prefix but different URIs cannot exist on one element.
*
* Limitation: because the namespace URI is not compared, a shadowed
* same-prefix namespace on an ancestor, when checked with a
* descendant (shadowing) element as the hosting context, can
* incorrectly match the descendant's own same-prefix declaration
* (different URI). The internal walk avoids this via the
* closest-declaration check (xmlSearchNs) in
* xmlSecNodeSetWalkRecursiveCallback; it only manifests on direct
* xmlSecNodeSetContains() calls (e.g. the C14N visibility callback).
*/
for(ii = 0; ii < nodes->nodeNr; ii++) {
if(nodes->nodeTab[ii]->type != XML_NAMESPACE_DECL) {
Expand Down
12 changes: 10 additions & 2 deletions src/openssl/kw_rfc_3394.c
Original file line number Diff line number Diff line change
Expand Up @@ -426,8 +426,16 @@ xmlSecOpenSSLKWRfc3394EncryptDecrypt(xmlSecOpenSSLKWRfc3394CtxPtr ctx, const xml
}
}

ret = EVP_CipherInit_ex2(ctx->cctx, ctx->cipher, keyData,
xmlSecOpenSSLKWRfc3394ZeroIv, ((encrypt != 0) ? 1 : 0), NULL);
/* EVP_CipherInit_ex2() is the OpenSSL 3.0+ variant of EVP_CipherInit_ex() with an
* OSSL_PARAM params array as its 6th argument (NULL here) */
ret = EVP_CipherInit_ex2(
ctx->cctx,
ctx->cipher,
keyData,
xmlSecOpenSSLKWRfc3394ZeroIv,
((encrypt != 0) ? 1 : 0),
NULL
);
if (ret != 1) {
xmlSecOpenSSLError("EVP_CipherInit_ex2", NULL);
goto done;
Expand Down
Loading