Comments (4)
Writing a PGP extension on top of Apache James server, using bouncyCastle 1.77 we encounter the very same issue.
Downgrade to 1.70 solves the issue.
An alternative could be .setWithIntegrityPacket(false)
but it looks unsafe.
from bc-java.
Have done some investigation using older versions.
I did not have to roll back so far, only to 1.71.1 for my code to work.
Version | Integrity verification | Signature verification |
---|---|---|
1.71 | passed | passed |
1.71.1 | passed | passed |
1.72 | failed | passed |
1.73 | passed | failed |
1.74 | passed | failed |
1.75 | passed | failed |
1.76 | passed | failed |
1.77 | passed | failed |
The release notes for version 1.72 indicate a change in the BZIP2 implementation.
The release notes for version 1.73 indicate a change in the BCPGInputStream class.
I wonder if the latter is the source of the problem I am encountering.
from bc-java.
Sorry to call you in. Need a bit of advice.
The change of interest in the BCPGInputStream class for v1.73; in the readPacket() method, the general change was in.read()
calls change to this.read()
calls. (d594ee2 08/10/2022).
I'm wondering if the same sort of change needs to happen in the readPacketTag() method too to help resolve the problem I'm encountering.
Part of the reason I'm asking is I would have to set-up a gradle environment to investigate. Using gradle which would be new too me. I use maven regularly.
Hope you can help, Thanks.
from bc-java.
Hmm. Possibly, change should appear on github shortly, but try what's in https://www.bouncycastle.org/betas and let me know how it goes.
from bc-java.
Related Issues (20)
- Dilithium object identifier mismatch with OQS provider HOT 2
- Cannot generate BcPGPKeyPair for X448
- CMSSignedData.replaceSigners() does not handle DigestAlgorithms parameters properly HOT 2
- Public key parameter digestParamSet should be optional for GOST 34.10 R 2012 HOT 2
- Number of Tr bytes for Dilithium signatures does not match NIST Documentation or test vectors. HOT 1
- current main doesn't compile anymore HOT 6
- SExpParser fails with GnuPG ed25519 private keys HOT 1
- Integrating FIPS-Compliant Libraries with OpenSAML
- DTLS 1.2 broken in version 1.77; handshake finished sends hello_request instead of change_cipher_spec and finished HOT 2
- Signature size of the PQC algorithms dilithium3 and dilithium5 do not match NIST 204 (Draft) HOT 1
- Unable to compile code in sources jars HOT 6
- An infinite loop occurs when ED25519 signature verification HOT 27
- lcrypto-jdk12-177 org.bouncycastle.crypto.test.RegressionTest fails with 3 StringIndexOutOfBoundsException HOT 6
- Does Bouncy Castle Support Connection ID ?
- org.bouncycastle.crypto.modes.CBCBlockCipher has been deprecated. Which function or combination can be taken it or instead of ? HOT 1
- Does Bouncy Castle 1.77 release compatible with OpenJDK-21 ? HOT 1
- PreShared Key support in Bouncy Castle JSSE Provider HOT 2
- java Caused by: javax.net.ssl.SSLProtocolException: Cannot decode named group: x25519 HOT 2
- PQC tests fail - missing files HOT 1
- Lineage OS build with custom edits complains bouncycastle.asn1 is "missing" HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from bc-java.