Commit ea6c4f63 authored by Roger Dingledine's avatar Roger Dingledine
Browse files

our circuit symmetric key (for aes) is 127 bits, not 128 bits.

we accept that.


svn:r892
parent 48e42e93
Loading
Loading
Loading
Loading
+7 −7
Original line number Diff line number Diff line
@@ -576,7 +576,7 @@ onion_skin_create(crypto_pk_env_t *dest_router_key,
  if (crypto_rand(16, pubkey))
    goto err;

  /* XXXX You can't just run around RSA-encrypting any bitstream: if it's
  /* You can't just run around RSA-encrypting any bitstream: if it's
   * greater than the RSA key, then OpenSSL will happily encrypt,
   * and later decrypt to the wrong value.  So we set the first bit
   * of 'pubkey' to 0.  This means that our symmetric key is really only