Use System.Security.Cryptography for TripleDesCipher#1546
Merged
Rob-Hague merged 5 commits intosshnet:developfrom Dec 27, 2024
Merged
Use System.Security.Cryptography for TripleDesCipher#1546Rob-Hague merged 5 commits intosshnet:developfrom
Rob-Hague merged 5 commits intosshnet:developfrom
Conversation
eadc5ab to
232e446
Compare
Collaborator
|
We could consider dropping DesCipher |
Collaborator
Author
|
Agree |
…ll back to use BouncyCastle if BCL doesn't support
Collaborator
Author
|
Might also be a good chance to drop home-made
Further more, we can consider changing all Renci.SshNet.Security.Cryptography.* internal. |
Collaborator
|
possibly yes, but I would prefer to think about that separately. Can you restore CbcCipherMode here? |
Collaborator
Author
|
CbcCipherMode is restored. |
Rob-Hague
reviewed
Dec 26, 2024
src/Renci.SshNet/Security/Cryptography/Ciphers/TripleDesCipher.BouncyCastleImpl.cs
Outdated
Show resolved
Hide resolved
…3DES-CFB on lower targets.
Rob-Hague
approved these changes
Dec 27, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR
TripleDesCipherto use BCL'sTripleDES.DesCipher. It is only used to decrypt OpenSSL legacy private key format (aka PKCS1). Suggest switching to newer encryption method.renamesAesCipherModetoBlockCipherMode. Some previous discussion: Use hardware-accelerated AES CryptoServiceProvider #865 (comment)Benchmarks based on .NET 9.0.0 (9.0.24.52809), X64 RyuJIT AVX2
Before:
After: