RSA_decrypt function
- @RecordUse.new()
- @Native<Int Function(Pointer<
RSA> rsa, Pointer<Size> out_len, Pointer<Uint8> out, Size max_out, Pointer<Uint8> in$, Size in_len, Int padding)>(ffi.Pointer<RSA>, ffi.Pointer<ffi.Size>, ffi.Pointer<ffi.Uint8>, ffi.Size, ffi.Pointer<ffi.Uint8>, ffi.Size, ffi.Int)>(symbol: 'bssl_dart_RSA_decrypt')
RSA_decrypt decrypts |in_len| bytes from |in| with the private key from |rsa| and writes, at most, |max_out| bytes of plaintext to |out|. The |max_out| argument must be, at least, |RSA_size| in order to ensure success.
It returns 1 on success or zero on error.
The |padding| argument must be one of the |RSA_*_PADDING| values. If in doubt, use |RSA_PKCS1_OAEP_PADDING| for new protocols. When |padding| is |RSA_PKCS1_OAEP_PADDING|, this function has no way to set the OAEP or MGF-1 digest, so it is always SHA-1. For other OAEP parameters, wrap |rsa| in an |EVP_PKEY| and use |EVP_PKEY_decrypt| with |EVP_PKEY_CTX_set_rsa_padding| and related functions.
WARNING: Passing |RSA_PKCS1_PADDING| into this function is deprecated and insecure. RSAES-PKCS1-v1_5 is vulnerable to a chosen-ciphertext attack. Decrypting attacker-supplied ciphertext with RSAES-PKCS1-v1_5 may give the attacker control over your private key. See "Chosen Ciphertext Attacks Against Protocols Based on the RSA Encryption Standard PKCS #1", Daniel Bleichenbacher, Advances in Cryptology (Crypto '98).
In some limited cases, such as TLS RSA key exchange, it is possible to mitigate this flaw with custom, protocol-specific padding logic. This should be implemented with |RSA_NO_PADDING|, not |RSA_PKCS1_PADDING|.
Implementation
@meta.RecordUse()
@ffi.Native<
ffi.Int Function(
ffi.Pointer<RSA>,
ffi.Pointer<ffi.Size>,
ffi.Pointer<ffi.Uint8>,
ffi.Size,
ffi.Pointer<ffi.Uint8>,
ffi.Size,
ffi.Int,
)
>(symbol: 'bssl_dart_RSA_decrypt')
external int RSA_decrypt(
ffi.Pointer<RSA> rsa,
ffi.Pointer<ffi.Size> out_len,
ffi.Pointer<ffi.Uint8> out,
int max_out,
ffi.Pointer<ffi.Uint8> in$,
int in_len,
int padding,
);