# Crypto.RSA with key sizes \< 512 bits?

**URL:** <https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175>\
**Category:** General\
**Created:** [June 26, 2015, 9:13pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175 "2015-06-26T21:13:48Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mike\_D](https://forum.xojo.com/user_avatar/forum.xojo.com/mike_d/32/266_2.png) [@Mike\_D](https://forum.xojo.com/u/Mike_D)\
**Post date:** [June 26, 2015, 9:13pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/1 "2015-06-26T21:13:48Z")

</div>

I have some legacy code which uses RSA with 128 bit key using a 3rd party plugin. I tried to update my code to use the new Crypto module but it chokes on doing anything useful with key sizes below 512. I know using small key sizes is not a good default, but there are cases where it makes sense. Can Xojo’s Crypto module support this?

---

<div class="post-metadata">

**Author:** ![Greg\_O\_Lone](https://forum.xojo.com/user_avatar/forum.xojo.com/greg_o_lone/32/49_2.png) [@Greg\_O\_Lone](https://forum.xojo.com/u/Greg_O_Lone)\
**Post date:** [June 27, 2015, 2:19pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/2 "2015-06-27T14:19:03Z")

</div>

What do you mean by “chokes”? Exception? Crash? Bad data?

---

<div class="post-metadata">

**Author:** ![Mike\_D](https://forum.xojo.com/user_avatar/forum.xojo.com/mike_d/32/266_2.png) [@Mike\_D](https://forum.xojo.com/u/Mike_D)\
**Post date:** [June 27, 2015, 2:49pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/3 "2015-06-27T14:49:10Z")

</div>

Various CrytpoExceptions are thrown at runtime, depending on what I’m trying to do, but most of them say something like "Key size is too small for \_\_\_\_\_\_\_ " . If I increase the key size to 512 or greater then I don’t get the exception.

---

<div class="post-metadata">

**Author:** ![Thom\_McGrath](https://forum.xojo.com/user_avatar/forum.xojo.com/thom_mcgrath/32/192_2.png) [@Thom\_McGrath](https://forum.xojo.com/u/Thom_McGrath)\
**Post date:** [June 27, 2015, 2:50pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/4 "2015-06-27T14:50:29Z")

</div>

Encrypt smaller amounts of data.

---

<div class="post-metadata">

**Author:** ![Mike\_D](https://forum.xojo.com/user_avatar/forum.xojo.com/mike_d/32/266_2.png) [@Mike\_D](https://forum.xojo.com/u/Mike_D)\
**Post date:** [June 27, 2015, 2:57pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/5 "2015-06-27T14:57:56Z")

</div>

Doesn’t work:

```auto
   dim pri,pub as string
   If Crypto.RSAGenerateKeyPair( 128, pri,pub ) Then
      // Testing smaller key sizes
      Dim msg As String = "0123456789ABCDEF" // 16 bytes
      Dim signature As MemoryBlock = Crypto.RSASign( msg, pri )
      If signature <> Nil Then
        // msg was successfully signed
      End If
    End If
```

Exception gives " Key too short for this signature scheme"

Submitted as \<[https://xojo.com/issue/39945](https://xojo.com/issue/39945)\>

---

<div class="post-metadata">

**Author:** ![Thom\_McGrath](https://forum.xojo.com/user_avatar/forum.xojo.com/thom_mcgrath/32/192_2.png) [@Thom\_McGrath](https://forum.xojo.com/u/Thom_McGrath)\
**Post date:** [June 27, 2015, 3:35pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/6 "2015-06-27T15:35:04Z")

</div>

It’s not a bug. The maximum length in using a 128-bit key is -26 bytes. It’s impossible. The formula is (KeySize / 8) - 42. 42 is the header size. So my “encrypt smaller amounts of data” wasn’t good advice, I’m sorry. You need a larger key.

---

<div class="post-metadata">

**Author:** ![Mike\_D](https://forum.xojo.com/user_avatar/forum.xojo.com/mike_d/32/266_2.png) [@Mike\_D](https://forum.xojo.com/u/Mike_D)\
**Post date:** [June 27, 2015, 3:43pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/7 "2015-06-27T15:43:35Z")

</div>

It depends on the details of what package & options are chosen. I have another package which will do the bare RSA (128 bit key = 16 byte plaintext). Here’s another source which claims that the formulas is (Keysize/8) - 11. (not 42 as you say) [http://golang.org/pkg/crypto/rsa/#EncryptPKCS1v15](http://golang.org/pkg/crypto/rsa/#EncryptPKCS1v15)

Need more info about what’s going on inside the Crypto module. The Language Reference refers to [http://cryptopp.com](http://cryptopp.com) but I’m not finding the padding info there.

---

<div class="post-metadata">

**Author:** ![Thom\_McGrath](https://forum.xojo.com/user_avatar/forum.xojo.com/thom_mcgrath/32/192_2.png) [@Thom\_McGrath](https://forum.xojo.com/u/Thom_McGrath)\
**Post date:** [June 27, 2015, 3:48pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/8 "2015-06-27T15:48:29Z")

</div>

The header is definitely 42.

---

<div class="post-metadata">

**Author:** ![Travis\_Hill](https://forum.xojo.com/user_avatar/forum.xojo.com/travis_hill/32/3_2.png) [@Travis\_Hill](https://forum.xojo.com/u/Travis_Hill)\
**Post date:** [June 27, 2015, 3:55pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/9 "2015-06-27T15:55:33Z")

</div>

It’s a RSASSA\_PKCS1v15\_SHA\_Signer that you can look up. You shouldn’t use padding with PKCS1.5 to make up for length, that’s been broken for years- and not something we’d enable in the framework.

---

<div class="post-metadata">

**Author:** ![Mike\_D](https://forum.xojo.com/user_avatar/forum.xojo.com/mike_d/32/266_2.png) [@Mike\_D](https://forum.xojo.com/u/Mike_D)\
**Post date:** [June 27, 2015, 3:56pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/10 "2015-06-27T15:56:25Z")

</div>

Where does 42 come from? Another source says “11” for version 1.5 padding:  
[https://tools.ietf.org/html/rfc2313](https://tools.ietf.org/html/rfc2313)

> [@](#):
>
> The length of the data D shall not be more than k-11 octets, which is  
> positive since the length k of the modulus is at least 12 octets.  
> This limitation guarantees that the length of the padding string PS  
> is at least eight octets, which is a security condition.

---

<div class="post-metadata">

**Author:** ![Thom\_McGrath](https://forum.xojo.com/user_avatar/forum.xojo.com/thom_mcgrath/32/192_2.png) [@Thom\_McGrath](https://forum.xojo.com/u/Thom_McGrath)\
**Post date:** [June 27, 2015, 4:10pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/11 "2015-06-27T16:10:02Z")

</div>

I wish I had the reference somewhere. I think it was Greg who told me it was 42, but I can’t say for sure who. All I know is all my tests confirm 42.

---

<div class="post-metadata">

**Author:** ![Mike\_D](https://forum.xojo.com/user_avatar/forum.xojo.com/mike_d/32/266_2.png) [@Mike\_D](https://forum.xojo.com/u/Mike_D)\
**Post date:** [June 27, 2015, 4:11pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/12 "2015-06-27T16:11:17Z")

</div>

Ok, let me change the discussion slightly: I’m actually not interested in the Crypto.RSASign, but rather Crypto.RSAEncrypt, in case that affects the padding discussion.

It sounds like there are 3 possible padding schemes for RSA:

- None, also called “Naked RSA” or “Textbook RSA” - not recommended, however I believe this is what my legacy code used and was able to encrypt/decrypt 16 bytes using a 128 bit key. I’d like to be able to support that if possible.
- PKCS 1.5 : not recommended, but sounds like it results in a plaintext size of (KeyLength/8-11)
- RSAS-OAEP padding (described in section 7.1.1 here: [http://www.ietf.org/rfc/rfc2437.txt](http://www.ietf.org/rfc/rfc2437.txt) ) which gives a maximum key length of

[quote] message to be encrypted, an octet string of length at most k-2-2hLen, where k is the length in octets of the modulus n and hLen is the length in octets of the hash function output for EME-OAEP  
[/quote]

Does the library actually use OAEP padding?

---

<div class="post-metadata">

**Author:** ![Mike\_D](https://forum.xojo.com/user_avatar/forum.xojo.com/mike_d/32/266_2.png) [@Mike\_D](https://forum.xojo.com/u/Mike_D)\
**Post date:** [June 27, 2015, 4:31pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/13 "2015-06-27T16:31:08Z")

</div>

Digging into the source code (Yay open source!) I find the maximum plaintext length number calculated in a few places:

For OAEP padding:

```auto
size_t OAEP_Base::MaxUnpaddedLength(size_t paddedLength) const
{
	return SaturatingSubtract(paddedLength/8, 1+2*DigestSize());
}
```

For PCKS padding:

```auto
size_t PKCS_EncryptionPaddingScheme::MaxUnpaddedLength(size_t paddedLength) const
{
	return SaturatingSubtract(paddedLength/8, 10U);
}
```

---

<div class="post-metadata">

**Author:** ![Travis\_Hill](https://forum.xojo.com/user_avatar/forum.xojo.com/travis_hill/32/3_2.png) [@Travis\_Hill](https://forum.xojo.com/u/Travis_Hill)\
**Post date:** [June 27, 2015, 4:37pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/14 "2015-06-27T16:37:26Z")

</div>

> [@197365:@Michael Diehr](#):
>
> Does the library actually use OAEP padding?

Yes. Xojo is not going to be backwards compatible to the insecure shorter keys you mention.

---

<div class="post-metadata">

**Author:** ![Mike\_D](https://forum.xojo.com/user_avatar/forum.xojo.com/mike_d/32/266_2.png) [@Mike\_D](https://forum.xojo.com/u/Mike_D)\
**Post date:** [June 27, 2015, 4:42pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/15 "2015-06-27T16:42:26Z")

</div>

For \<[https://xojo.com/issue/39945](https://xojo.com/issue/39945)\> - can we convert that from a bug report to a documentation request to make these issues known in the LR? Or shall I submit a new Feedback case?

---

<div class="post-metadata">

**Author:** ![Greg\_O\_Lone](https://forum.xojo.com/user_avatar/forum.xojo.com/greg_o_lone/32/49_2.png) [@Greg\_O\_Lone](https://forum.xojo.com/u/Greg_O_Lone)\
**Post date:** [June 27, 2015, 10:37pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/16 "2015-06-27T22:37:17Z")

</div>

I did some experiments a while back. See [https://forum.xojo.com/20098-crypto-rsaencrypt](https://forum.xojo.com/20098-crypto-rsaencrypt)

---

<div class="post-metadata">

**Author:** ![system](https://forum.xojo.com/uploads/default/original/1X/455b4dcc0e61630e9f81940004ddffa49c432a46.png) [@system](https://forum.xojo.com/u/system)\
**Post date:** [October 29, 2020, 5:49pm UTC](https://forum.xojo.com/t/crypto-rsa-with-key-sizes-512-bits/25175/17 "2020-10-29T17:49:25Z")

</div>


