mirror of
https://github.com/slackhq/nebula.git
synced 2026-08-15 11:27:02 +02:00
extract the internal FIPS GCM implementation
We do this because the TLS wrapper is not thread safe on Open. instead of locking around it we can grab the internal implementation that is thread safe. This is the FIPS module implementation: `crypto/internal/fips140/aes/gcm.GCMWithXORCounterNonce` - https://github.com/golang/go/blob/go1.26.4/src/crypto/internal/fips140/aes/gcm/gcm_nonces.go#L212-L287 The wrapper is struct `crypto/tls.xorNonceAEAD`, with field `aead`: - https://github.com/golang/go/blob/go1.26.4/src/crypto/tls/cipher_suites.go#L482-L487 This can be cleaned up once these FIPS implementations are exposed directly: - https://github.com/golang/go/issues/73110
This commit is contained in:
@@ -17,7 +17,7 @@ func TestNewAESGCM(t *testing.T) {
|
||||
}
|
||||
|
||||
key, _ := hex.DecodeString("feffe9928665731c6d6a8f9467308308feffe9928665731c6d6a8f9467308308")
|
||||
iv, _ := hex.DecodeString("facedbaddecaf888")
|
||||
iv, _ := hex.DecodeString("00000000facedbaddecaf888")
|
||||
plaintext, _ := hex.DecodeString("d9313225f88406e5a55909c5aff5269a86a7a9531534f7da2e4c303d8a318a721c3c0c95956809532fcf0e2449a6b525b16aedf5aa0de657ba637b39")
|
||||
aad, _ := hex.DecodeString("feedfacedeadbeeffeedfacedeadbeefabaddad2")
|
||||
expected, _ := hex.DecodeString("6a65c2edd45bd63c7e29f40e3d2ed8ba2b99f4c83135383d5676652f255059ceb24863ff10afb1089db701245da87fb88d3acd5f9dd0770cac220c3c04145caf25e190aeb775e7080401c628")
|
||||
|
||||
Reference in New Issue
Block a user