Skip to content

Commit d72070f

Browse files
committed
fixup! test: use named parameters in DH stress test
Retain the original small imported parameters when the OpenSSL 3 provider shortcut is unavailable. BoringSSL checks the prime on every named-group construction, making 4,000 modp14 constructions too slow. Preserve the existing exchange counts and FIPS assertions. Signed-off-by: Filip Skokan <panva.ip@gmail.com> Assisted-by: Codex
1 parent 6c2d3c1 commit d72070f

1 file changed

Lines changed: 14 additions & 4 deletions

File tree

‎test/pummel/test-dh-regr.js‎

Lines changed: 14 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ if (common.isPi()) {
3232

3333
const assert = require('assert');
3434
const crypto = require('crypto');
35-
const { hasFIPS } = require('../common/crypto');
35+
const { hasOpenSSL, hasFIPS } = require('../common/crypto');
3636

3737
let iterations = 2000;
3838
if (hasFIPS(3)) {
@@ -45,10 +45,20 @@ if (hasFIPS(3)) {
4545
iterations = 100;
4646
}
4747

48+
let createDH;
49+
if (hasOpenSSL(3)) {
50+
// OpenSSL 3 recognizes named groups without validating their primes.
51+
createDH = () => crypto.getDiffieHellman('modp14');
52+
} else {
53+
// Other backends validate each peer's parameters, so keep them small.
54+
const length = crypto.getFips() === 1 ? 1024 : 256;
55+
const prime = crypto.createDiffieHellman(length).getPrime();
56+
createDH = () => crypto.createDiffieHellman(prime);
57+
}
58+
4859
for (let i = 0; i < iterations; i++) {
49-
// A named group avoids generating and validating custom parameters.
50-
const a = crypto.getDiffieHellman('modp14');
51-
const b = crypto.getDiffieHellman('modp14');
60+
const a = createDH();
61+
const b = createDH();
5262

5363
a.generateKeys();
5464
b.generateKeys();

0 commit comments

Comments
 (0)