From e21fc213efda54500ece1001f7cf1035df24b617 Mon Sep 17 00:00:00 2001 From: Roger Dingledine Date: Tue, 9 Dec 2003 01:04:40 +0000 Subject: [PATCH] our circuit symmetric key (for aes) is 127 bits, not 128 bits. we accept that. svn:r892 --- trunk/src/or/onion.c | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/trunk/src/or/onion.c b/trunk/src/or/onion.c index 51dd1d0465..ca4f678f89 100644 --- a/trunk/src/or/onion.c +++ b/trunk/src/or/onion.c @@ -575,13 +575,13 @@ onion_skin_create(crypto_pk_env_t *dest_router_key, if (crypto_rand(16, pubkey)) goto err; - - /* XXXX You can't just run around RSA-encrypting any bitstream: if it's - * greater than the RSA key, then OpenSSL will happily encrypt, - * and later decrypt to the wrong value. So we set the first bit - * of 'pubkey' to 0. This means that our symmetric key is really only - * 127 bits long, but since it shouldn't be necessary to encrypt - * DH public keys values in the first place, we should be fine. + + /* You can't just run around RSA-encrypting any bitstream: if it's + * greater than the RSA key, then OpenSSL will happily encrypt, + * and later decrypt to the wrong value. So we set the first bit + * of 'pubkey' to 0. This means that our symmetric key is really only + * 127 bits long, but since it shouldn't be necessary to encrypt + * DH public keys values in the first place, we should be fine. */ pubkey[0] &= 0x7f;