Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
This Mbed TLS configuration option was being selected based on a non-existent Kconfig option, and hence would never be defined. v2.1 of PKCS1 was published in 2003. Use of v1.5 has been deprecated since 2016, and should not be used in new or existing designs. Enable the v2.1 version in any situation where RSA is used for signatures. In the future, we should disable v1.5 entirely, but only after all uses have been determined and possibly corrected. No significant weaknesses have been found in v1.5, however v2.1 has a significant security proof. However, v2.1 does require an entropy source, which may be an issue in some embedded device situations (which likely are problematic for other cryptographic reasons). Signed-off-by: David Brown <[email protected]>
- Loading branch information