Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -137,6 +137,7 @@ public ColumnMasterKeyMetadata(RSA rsa, string masterKeyPath, string providerNam
/// </returns>
/// <exception cref="CryptographicException">Thrown when the signing operation fails.</exception>
public byte[] Sign() =>
// CodeQL [SM03799] Required for an external standard: Always Encrypted signs column master key metadata with RSA PKCS#1 v1.5 (https://learn.microsoft.com/en-us/sql/t-sql/statements/create-column-master-key-transact-sql?view=sql-server-ver16)
_rsa.SignHash(_hash, s_hashAlgorithm, RSASignaturePadding.Pkcs1);

/// <summary>
Expand All @@ -146,8 +147,9 @@ public byte[] Sign() =>
/// <returns>
/// <see langword="true"/> if the signature is valid and matches the computed hash; otherwise, <see langword="false"/>.
/// </returns>
/// <exception cref="ArgumentNullException">Thrown when <paramref name="signature"/> is <see langword="null"/>.</exception>"
/// <exception cref="ArgumentNullException">Thrown when <paramref name="signature"/> is <see langword="null"/>.</exception>
public bool Verify(byte[] signature) =>
// CodeQL [SM03799] Required for an external standard: Always Encrypted signs column master key metadata with RSA PKCS#1 v1.5 (https://learn.microsoft.com/en-us/sql/t-sql/statements/create-column-master-key-transact-sql?view=sql-server-ver16)
_rsa.VerifyHash(_hash, signature, s_hashAlgorithm, RSASignaturePadding.Pkcs1);

/// <summary>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,9 @@ public byte[] Encrypt(byte[] columnEncryptionKey)
Debug.Assert(bytesWritten == HashSize, @"Hash size does not match the expected size.");

bytesWritten = _keyType == SqlColumnEncryptionCertificateStoreProvider.MasterKeyType
// CodeQL [SM03799] Required for an external standard: Always Encrypted signs encrypted column encryption keys with RSA PKCS#1 v1.5 (https://learn.microsoft.com/en-us/sql/t-sql/statements/create-column-encryption-key-transact-sql?view=sql-server-ver16)
? _rsa.SignHash(hash, encryptedColumnEncryptionKey.AsSpan(signatureOffset), s_hashAlgorithm, RSASignaturePadding.Pkcs1)
// CodeQL [SM03799] Required for an external standard: Always Encrypted signs encrypted column encryption keys with RSA PKCS#1 v1.5 (https://learn.microsoft.com/en-us/sql/t-sql/statements/create-column-encryption-key-transact-sql?view=sql-server-ver16)
: _rsa.SignData(hash, encryptedColumnEncryptionKey.AsSpan(signatureOffset), s_hashAlgorithm, RSASignaturePadding.Pkcs1);
Debug.Assert(bytesWritten == _rsaKeySize, @"Signature length does not match the RSA key size.");

Expand All @@ -166,7 +168,9 @@ public byte[] Encrypt(byte[] columnEncryptionKey)
Debug.Assert(bytesWritten == HashSize, @"Hash size does not match the expected size.");

byte[] signedHash = _keyType == SqlColumnEncryptionCertificateStoreProvider.MasterKeyType
// CodeQL [SM03799] Required for an external standard: Always Encrypted signs encrypted column encryption keys with RSA PKCS#1 v1.5 (https://learn.microsoft.com/en-us/sql/t-sql/statements/create-column-encryption-key-transact-sql?view=sql-server-ver16)
? _rsa.SignHash(hash, s_hashAlgorithm, RSASignaturePadding.Pkcs1)
// CodeQL [SM03799] Required for an external standard: Always Encrypted signs encrypted column encryption keys with RSA PKCS#1 v1.5 (https://learn.microsoft.com/en-us/sql/t-sql/statements/create-column-encryption-key-transact-sql?view=sql-server-ver16)
: _rsa.SignData(hash, s_hashAlgorithm, RSASignaturePadding.Pkcs1);
bytesWritten = signedHash.Length;
Debug.Assert(bytesWritten == _rsaKeySize, @"Signature length does not match the RSA key size.");
Expand Down Expand Up @@ -246,7 +250,9 @@ public byte[] Decrypt(byte[] encryptedCek)
#endif

bool dataVerified = _keyType == SqlColumnEncryptionCertificateStoreProvider.MasterKeyType
// CodeQL [SM03799] Required for an external standard: Always Encrypted signs encrypted column encryption keys with RSA PKCS#1 v1.5 (https://learn.microsoft.com/en-us/sql/t-sql/statements/create-column-encryption-key-transact-sql?view=sql-server-ver16)
? _rsa.VerifyHash(hash, signature, s_hashAlgorithm, RSASignaturePadding.Pkcs1)
// CodeQL [SM03799] Required for an external standard: Always Encrypted signs encrypted column encryption keys with RSA PKCS#1 v1.5 (https://learn.microsoft.com/en-us/sql/t-sql/statements/create-column-encryption-key-transact-sql?view=sql-server-ver16)
: _rsa.VerifyData(hash, signature, s_hashAlgorithm, RSASignaturePadding.Pkcs1);

// Validate the signature
Expand Down
1 change: 1 addition & 0 deletions tools/PackageValidator/src/AssemblyInspector.cs
Original file line number Diff line number Diff line change
Expand Up @@ -232,6 +232,7 @@ private static (Guid? CodeViewGuid, bool HasEmbeddedPdb, List<PdbChecksum>? Chec

// The token is defined by the CLI spec as the low 8 bytes of the SHA-1 hash of the public
// key, emitted in reverse (little-endian) order.
// CodeQL [SM02196] Required for an external standard: ECMA-335 defines the strong-name public key token as a SHA-1 hash; this is an identity computation, not a security boundary.
byte[] hash = SHA1.HashData(publicKey);
var token = new byte[8];
for (int i = 0; i < 8; i++)
Expand Down
5 changes: 4 additions & 1 deletion tools/PackageValidator/src/PortablePdb.cs
Original file line number Diff line number Diff line change
Expand Up @@ -191,6 +191,10 @@ private static string ReadStreamName(BinaryReader reader)
/// <summary>
/// Creates a <see cref="HashAlgorithm"/> for a PDB checksum algorithm name.
/// </summary>
/// <remarks>
/// Only SHA-2 family algorithms are supported; weak hashes such as SHA-1 are deliberately not
/// recognized, so a PDB recording one is reported as inconclusive rather than verified.
/// </remarks>
/// <param name="algorithm">The algorithm name as recorded in the debug directory (for example <c>"SHA256"</c>).</param>
/// <returns>A new hash algorithm instance, or <see langword="null"/> if the name is not recognized.</returns>
private static HashAlgorithm? CreateHashAlgorithm(string algorithm) =>
Expand All @@ -199,7 +203,6 @@ private static string ReadStreamName(BinaryReader reader)
"SHA256" => SHA256.Create(),
"SHA384" => SHA384.Create(),
"SHA512" => SHA512.Create(),
"SHA1" => SHA1.Create(),
_ => null,
};
}
Loading