[bouncycastle] 02/03: Fix CVE-2015-7940
Markus Koschany
apo-guest at moszumanska.debian.org
Thu Dec 10 23:20:12 UTC 2015
This is an automated email from the git hooks/post-receive script.
apo-guest pushed a commit to branch wheezy-security
in repository bouncycastle.
commit c8d96491e2c387097e03b53a1c2fbf31025ee792
Author: Markus Koschany <apo at debian.org>
Date: Wed Dec 9 23:19:18 2015 +0100
Fix CVE-2015-7940
Thanks: Peter Dettman and Raphaël Hertzogfor the patches.
Closes: #802671
---
debian/patches/CVE-2015-7940-1.patch | 464 +++++++++++++++++++++
debian/patches/CVE-2015-7940-2.patch | 78 ++++
debian/patches/CVE-2015-7940-3.patch | 781 +++++++++++++++++++++++++++++++++++
debian/patches/series | 3 +
4 files changed, 1326 insertions(+)
diff --git a/debian/patches/CVE-2015-7940-1.patch b/debian/patches/CVE-2015-7940-1.patch
new file mode 100644
index 0000000..6004fce
--- /dev/null
+++ b/debian/patches/CVE-2015-7940-1.patch
@@ -0,0 +1,464 @@
+From 5cb2f0578e6ec8f0d67e59d05d8c4704d8e05f83 Mon Sep 17 00:00:00 2001
+From: Peter Dettman <peter.dettman at bouncycastle.org>
+Date: Tue, 22 Jul 2014 19:23:34 +0700
+Subject: [PATCH] Add automatic EC point validation for decoded points and for
+ multiplier outputs.
+Origin: upstream, https://github.com/bcgit/bc-java/commit/5cb2f05
+Bug-Debian: https://bugs.debian.org/802671
+
+Backporting notes of Raphaël Hertzog:
+* core/src/main/java/org/bouncycastle/ in current git
+ was src/org/bouncycastle/ in 1.44
+* DSTU4145PointEncoder.java does not exist in 1.44 (introduced
+ in 158b54f). Dropped the changes.
+* AbstractECMultiplier.java does not exist in 1.44 but changes to
+ AbstractECMultiplier.java mean that we must run
+ ECAlgorithms.validatePoint() on any result of the multiply() function of
+ any object implementing ECMultiplier. Done on:
+ - FpNafMultiplier.java
+ - ReferenceMultiplier.java
+ - WNafMultiplier.java
+ - WTauNafMultiplier.java
+* …/math/ec/custom/* were not present in 1.44. Dropped the corresponding
+ changes.
+* Remaining changes have been manually backported:
+ - ECPointTest.java: done
+ - ReferenceMultiplier.java: done, added validatePoint() call on result
+ - ECAlgorithms.java: done
+ - ECPoint.java: done
+ - Fp does not yet support getCompressionYTilde(), dropped from
+ AbstractFp
+ - F2m does not yet support checkCurveEquation()
+ - dropped constructors accepting 4 params (with "zs") as ECPoint()
+ does not support it, and dropped all code path that made use of this.zs
+ since it's not available, basically everything related to non-affine
+ coordinate system
+ - ECCurve.java:
+ - Hunk 1: validatePoint() not backported as there is no createPoint() call
+ to replace. Instead ensure decodePoint() return value satisfies
+ ECAlgorithms.validatePoint()
+ - Hunk 2: no importPoint() (and no createPoint() usage found)
+ - Hunk 3: useless (no-op change)
+ - Hunk 4: useless (no-op change)
+ - Hunk 5: validation on generated point at end of function
+ - Hunk 6: done
+ - Hunk 7: done (auto-applied)
+ - Hunk 8/9: ECCurve is abstract and has no constructor, don't call
+ parent constructors in Fp constructors (which happens in code
+ from hunk 7 adding AbstractFp)
+ - Hunk 10: ECCurve.Fp does not have decompressPoint() in 1.44, so the whole
+ AbstractFp class was in fact useless, drop it and make Fp extends
+ ECCurve again.
+ End of hunk not applied, the AbstractF2m class is not needed as its
+ sole purpose is to factorize a call to buildField() that version
+ 1.44 does not have.
+ - Hunk 11/12/13: Not applied as we don't introduce AbstractF2m.
+ - Hunk 14: yp is already initialized as null in 1.44.
+ - Hunk 15: decompressPoint() is really implemented differently... and
+ even has different parameters. Just add the final check for yp==null
+ and don't change the logic in the function.
+---
+ .../bouncycastle/asn1/ua/DSTU4145PointEncoder.java | 20 +-
+ .../bouncycastle/math/ec/AbstractECMultiplier.java | 8 +-
+ .../org/bouncycastle/math/ec/ECAlgorithms.java | 56 ++++-
+ .../java/org/bouncycastle/math/ec/ECCurve.java | 183 +++++++++-----
+ .../java/org/bouncycastle/math/ec/ECPoint.java | 270 ++++++++++++++-------
+ .../bouncycastle/math/ec/ReferenceMultiplier.java | 28 +--
+ .../math/ec/custom/djb/Curve25519.java | 29 +--
+ .../math/ec/custom/djb/Curve25519Point.java | 17 +-
+ .../math/ec/custom/sec/SecP192K1Curve.java | 33 +--
+ .../math/ec/custom/sec/SecP192K1Point.java | 19 +-
+ .../math/ec/custom/sec/SecP192R1Curve.java | 29 +--
+ .../math/ec/custom/sec/SecP192R1Point.java | 19 +-
+ .../math/ec/custom/sec/SecP224K1Curve.java | 33 +--
+ .../math/ec/custom/sec/SecP224K1Point.java | 19 +-
+ .../math/ec/custom/sec/SecP224R1Curve.java | 29 +--
+ .../math/ec/custom/sec/SecP224R1Point.java | 18 +-
+ .../math/ec/custom/sec/SecP256K1Curve.java | 33 +--
+ .../math/ec/custom/sec/SecP256K1Point.java | 19 +-
+ .../math/ec/custom/sec/SecP256R1Curve.java | 29 +--
+ .../math/ec/custom/sec/SecP256R1Point.java | 18 +-
+ .../math/ec/custom/sec/SecP384R1Curve.java | 29 +--
+ .../math/ec/custom/sec/SecP384R1Point.java | 18 +-
+ .../math/ec/custom/sec/SecP521R1Curve.java | 29 +--
+ .../math/ec/custom/sec/SecP521R1Point.java | 18 +-
+ .../org/bouncycastle/math/ec/test/ECPointTest.java | 33 +--
+ docs/releasenotes.html | 2 +
+ 26 files changed, 401 insertions(+), 637 deletions(-)
+
+--- a/src/org/bouncycastle/math/ec/ECAlgorithms.java
++++ b/src/org/bouncycastle/math/ec/ECAlgorithms.java
+@@ -24,7 +24,7 @@ public class ECAlgorithms
+ // }
+ // }
+
+- return implShamirsTrick(P, a, Q, b);
++ return ECAlgorithms.validatePoint(implShamirsTrick(P, a, Q, b));
+ }
+
+ /*
+@@ -54,7 +54,7 @@ public class ECAlgorithms
+ throw new IllegalArgumentException("P and Q must be on same curve");
+ }
+
+- return implShamirsTrick(P, k, Q, l);
++ return ECAlgorithms.validatePoint(implShamirsTrick(P, k, Q, l));
+ }
+
+ private static ECPoint implShamirsTrick(ECPoint P, BigInteger k,
+@@ -90,4 +90,47 @@ public class ECAlgorithms
+
+ return R;
+ }
++
++ /**
++ * Simple shift-and-add multiplication. Serves as reference implementation
++ * to verify (possibly faster) implementations, and for very small scalars.
++ *
++ * @param p
++ * The point to multiply.
++ * @param k
++ * The multiplier.
++ * @return The result of the point multiplication <code>kP</code>.
++ */
++ public static ECPoint referenceMultiply(ECPoint p, BigInteger k)
++ {
++ BigInteger x = k.abs();
++ ECPoint q = p.getCurve().getInfinity();
++ int t = x.bitLength();
++ if (t > 0)
++ {
++ if (x.testBit(0))
++ {
++ q = p;
++ }
++ for (int i = 1; i < t; i++)
++ {
++ p = p.twice();
++ if (x.testBit(i))
++ {
++ q = q.add(p);
++ }
++ }
++ }
++ return k.signum() < 0 ? q.negate() : q;
++ }
++
++ public static ECPoint validatePoint(ECPoint p)
++ {
++ if (!p.isValid())
++ {
++ throw new IllegalArgumentException("Invalid point");
++ }
++
++ return p;
++ }
+ }
+--- a/src/org/bouncycastle/math/ec/ECCurve.java
++++ b/src/org/bouncycastle/math/ec/ECCurve.java
+@@ -134,7 +134,12 @@ public abstract class ECCurve
+ throw new RuntimeException("Invalid point encoding 0x" + Integer.toString(encoded[0], 16));
+ }
+
+- return p;
++ if (encoded[0] != 0x00 && p.isInfinity())
++ {
++ throw new IllegalArgumentException("Invalid infinity encoding");
++ }
++
++ return ECAlgorithms.validatePoint(p);
+ }
+
+ public ECPoint getInfinity()
+@@ -448,7 +453,7 @@ public abstract class ECCurve
+ throw new RuntimeException("Invalid point encoding 0x" + Integer.toString(encoded[0], 16));
+ }
+
+- return p;
++ return ECAlgorithms.validatePoint(p);
+ }
+
+ public ECPoint getInfinity()
+@@ -542,6 +547,11 @@ public abstract class ECCurve
+ }
+ yp = xp.multiply(z);
+ }
++
++ if (yp == null)
++ {
++ throw new IllegalArgumentException("Invalid point compression");
++ }
+
+ return new ECPoint.F2m(this, xp, yp);
+ }
+--- a/src/org/bouncycastle/math/ec/ECPoint.java
++++ b/src/org/bouncycastle/math/ec/ECPoint.java
+@@ -27,7 +27,9 @@ public abstract class ECPoint
+ this.x = x;
+ this.y = y;
+ }
+-
++
++ protected abstract boolean satisfiesCurveEquation();
++
+ public ECCurve getCurve()
+ {
+ return curve;
+@@ -53,6 +55,33 @@ public abstract class ECPoint
+ return withCompression;
+ }
+
++ public boolean isValid()
++ {
++ if (isInfinity())
++ {
++ return true;
++ }
++
++ // TODO Sanity-check the field elements
++
++ ECCurve curve = getCurve();
++ if (curve != null)
++ {
++ if (!satisfiesCurveEquation())
++ {
++ return false;
++ }
++
++ BigInteger h = curve.getH();
++ if (h != null && ECAlgorithms.referenceMultiply(this, h).isInfinity())
++ {
++ return false;
++ }
++ }
++
++ return true;
++ }
++
+ public boolean equals(
+ Object other)
+ {
+@@ -147,10 +176,38 @@ public abstract class ECPoint
+ return this.multiplier.multiply(this, k, preCompInfo);
+ }
+
++ public static abstract class AbstractFp extends ECPoint
++ {
++ protected AbstractFp(ECCurve curve, ECFieldElement x, ECFieldElement y)
++ {
++ super(curve, x, y);
++ }
++
++ protected boolean satisfiesCurveEquation()
++ {
++ ECFieldElement X = this.x, Y = this.y, A = curve.getA(), B = curve.getB();
++ ECFieldElement lhs = Y.square();
++
++ ECFieldElement rhs = X.square().add(A).multiply(X).add(B);
++ return lhs.equals(rhs);
++ }
++
++ public ECPoint subtract(ECPoint b)
++ {
++ if (b.isInfinity())
++ {
++ return this;
++ }
++
++ // Add -b
++ return add(b.negate());
++ }
++ }
++
+ /**
+ * Elliptic curve points over Fp
+ */
+- public static class Fp extends ECPoint
++ public static class Fp extends AbstractFp
+ {
+
+ /**
+@@ -166,7 +223,7 @@ public abstract class ECPoint
+ }
+
+ /**
+- * Create a point that encodes with or without point compresion.
++ * Create a point that encodes with or without point compression.
+ *
+ * @param curve the curve to use
+ * @param x affine x co-ordinate
+@@ -292,18 +349,6 @@ public abstract class ECPoint
+ return new ECPoint.Fp(curve, x3, y3, this.withCompression);
+ }
+
+- // D.3.2 pg 102 (see Note:)
+- public ECPoint subtract(ECPoint b)
+- {
+- if (b.isInfinity())
+- {
+- return this;
+- }
+-
+- // Add -b
+- return add(b.negate());
+- }
+-
+ public ECPoint negate()
+ {
+ return new ECPoint.Fp(curve, this.x, this.y.negate(), this.withCompression);
+@@ -322,10 +367,30 @@ public abstract class ECPoint
+ // }
+ }
+
++ public static abstract class AbstractF2m extends ECPoint
++ {
++ protected AbstractF2m(ECCurve curve, ECFieldElement x, ECFieldElement y)
++ {
++ super(curve, x, y);
++ }
++
++ protected boolean satisfiesCurveEquation()
++ {
++ ECCurve curve = getCurve();
++ ECFieldElement X = this.x, A = curve.getA(), B = curve.getB();
++
++ ECFieldElement Y = this.y;
++ ECFieldElement lhs = Y.add(X).multiply(Y);
++
++ ECFieldElement rhs = X.add(A).multiply(X.square()).add(B);
++ return lhs.equals(rhs);
++ }
++ }
++
+ /**
+ * Elliptic curve points over F2m
+ */
+- public static class F2m extends ECPoint
++ public static class F2m extends AbstractF2m
+ {
+ /**
+ * @param curve base curve
+--- a/src/org/bouncycastle/math/ec/ReferenceMultiplier.java
++++ b/src/org/bouncycastle/math/ec/ReferenceMultiplier.java
+@@ -4,27 +4,8 @@ import java.math.BigInteger;
+
+ class ReferenceMultiplier implements ECMultiplier
+ {
+- /**
+- * Simple shift-and-add multiplication. Serves as reference implementation
+- * to verify (possibly faster) implementations in
+- * {@link org.bouncycastle.math.ec.ECPoint ECPoint}.
+- *
+- * @param p The point to multiply.
+- * @param k The factor by which to multiply.
+- * @return The result of the point multiplication <code>k * p</code>.
+- */
+ public ECPoint multiply(ECPoint p, BigInteger k, PreCompInfo preCompInfo)
+ {
+- ECPoint q = p.getCurve().getInfinity();
+- int t = k.bitLength();
+- for (int i = 0; i < t; i++)
+- {
+- if (k.testBit(i))
+- {
+- q = q.add(p);
+- }
+- p = p.twice();
+- }
+- return q;
++ return ECAlgorithms.validatePoint(ECAlgorithms.referenceMultiply(p, k));
+ }
+ }
+--- a/test/src/org/bouncycastle/math/ec/test/ECPointTest.java
++++ b/test/src/org/bouncycastle/math/ec/test/ECPointTest.java
+@@ -13,6 +13,7 @@ import org.bouncycastle.asn1.x9.X9ECPara
+ import org.bouncycastle.math.ec.ECCurve;
+ import org.bouncycastle.math.ec.ECFieldElement;
+ import org.bouncycastle.math.ec.ECPoint;
++import org.bouncycastle.math.ec.ECAlgorithms;
+
+ /**
+ * Test class for {@link org.bouncycastle.math.ec.ECPoint ECPoint}. All
+@@ -263,32 +264,6 @@ public class ECPointTest extends TestCas
+ }
+
+ /**
+- * Simple shift-and-add multiplication. Serves as reference implementation
+- * to verify (possibly faster) implementations in
+- * {@link org.bouncycastle.math.ec.ECPoint ECPoint}.
+- *
+- * @param p
+- * The point to multiply.
+- * @param k
+- * The multiplier.
+- * @return The result of the point multiplication <code>kP</code>.
+- */
+- private ECPoint multiply(ECPoint p, BigInteger k)
+- {
+- ECPoint q = p.getCurve().getInfinity();
+- int t = k.bitLength();
+- for (int i = 0; i < t; i++)
+- {
+- if (k.testBit(i))
+- {
+- q = q.add(p);
+- }
+- p = p.twice();
+- }
+- return q;
+- }
+-
+- /**
+ * Checks, if the point multiplication algorithm of the given point yields
+ * the same result as point multiplication done by the reference
+ * implementation given in <code>multiply()</code>. This method chooses a
+@@ -303,7 +278,7 @@ public class ECPointTest extends TestCas
+ private void implTestMultiply(ECPoint p, int numBits)
+ {
+ BigInteger k = new BigInteger(numBits, secRand);
+- ECPoint ref = multiply(p, k);
++ ECPoint ref = org.bouncycastle.math.ec.ECAlgorithms.referenceMultiply(p, k);
+ ECPoint q = p.multiply(k);
+ assertEquals("ECPoint.multiply is incorrect", ref, q);
+ }
+@@ -327,7 +302,7 @@ public class ECPointTest extends TestCas
+
+ do
+ {
+- ECPoint ref = multiply(p, k);
++ ECPoint ref = org.bouncycastle.math.ec.ECAlgorithms.referenceMultiply(p, k);
+ ECPoint q = p.multiply(k);
+ assertEquals("ECPoint.multiply is incorrect", ref, q);
+ k = k.add(BigInteger.ONE);
+--- a/src/org/bouncycastle/math/ec/FpNafMultiplier.java
++++ b/src/org/bouncycastle/math/ec/FpNafMultiplier.java
+@@ -34,6 +34,6 @@ class FpNafMultiplier implements ECMulti
+ }
+ }
+
+- return R;
++ return ECAlgorithms.validatePoint(R);
+ }
+ }
+--- a/src/org/bouncycastle/math/ec/WNafMultiplier.java
++++ b/src/org/bouncycastle/math/ec/WNafMultiplier.java
+@@ -234,7 +234,7 @@ class WNafMultiplier implements ECMultip
+ wnafPreCompInfo.setPreComp(preComp);
+ wnafPreCompInfo.setTwiceP(twiceP);
+ p.setPreCompInfo(wnafPreCompInfo);
+- return q;
++ return ECAlgorithms.validatePoint(q);
+ }
+
+ }
+--- a/src/org/bouncycastle/math/ec/WTauNafMultiplier.java
++++ b/src/org/bouncycastle/math/ec/WTauNafMultiplier.java
+@@ -34,7 +34,7 @@ class WTauNafMultiplier implements ECMul
+
+ ZTauElement rho = Tnaf.partModReduction(k, m, a, s, mu, (byte)10);
+
+- return multiplyWTnaf(p, rho, preCompInfo, a, mu);
++ return ECAlgorithms.validatePoint(multiplyWTnaf(p, rho, preCompInfo, a, mu));
+ }
+
+ /**
diff --git a/debian/patches/CVE-2015-7940-2.patch b/debian/patches/CVE-2015-7940-2.patch
new file mode 100644
index 0000000..7268774
--- /dev/null
+++ b/debian/patches/CVE-2015-7940-2.patch
@@ -0,0 +1,78 @@
+From e25e94a046a6934819133886439984e2fecb2b04 Mon Sep 17 00:00:00 2001
+From: Peter Dettman <peter.dettman at bouncycastle.org>
+Date: Fri, 25 Jul 2014 14:46:07 +0700
+Subject: [PATCH] Add cofactor validation after point decompression
+Origin: upstream, https://github.com/bcgit/bc-java/commit/e25e94a
+Bug-Debian: https://bugs.debian.org/802671
+
+Backporting notes of Raphaël Hertzog:
+* ECCurve.java:
+ - Hunk 1: decompressPoint() does not exist on ECCurve.Fp, dropped.
+ - Hunk 2: drop variable rename, keep only final p.satisfiesCofactor() check
+ Replaced getCofactor() with getH() since the former does not exist yet.
+ But getH() was only available on F2m, added a default implementation
+ returning null to ECCurve (this is what happens with newer versions
+ when you create an Fp curve without specifying the cofactor).
+* ECPoint.java: done, noted that satisfiesCofactor() adds a supplementary
+ check compared to version 1.44 (h.equals(ECConstants.ONE))
+
+---
+ .../java/org/bouncycastle/math/ec/ECCurve.java | 29 +++++++++++++++-------
+ .../java/org/bouncycastle/math/ec/ECPoint.java | 10 +++++---
+ 2 files changed, 27 insertions(+), 12 deletions(-)
+
+--- a/src/org/bouncycastle/math/ec/ECCurve.java
++++ b/src/org/bouncycastle/math/ec/ECCurve.java
+@@ -30,6 +30,12 @@ public abstract class ECCurve
+ return b;
+ }
+
++ public BigInteger getH()
++ {
++ // ECCurve without cofactor by default, overriden by subclasses
++ return null;
++ }
++
+ /**
+ * Elliptic curve over Fp
+ */
+@@ -553,7 +559,13 @@ public abstract class ECCurve
+ throw new IllegalArgumentException("Invalid point compression");
+ }
+
+- return new ECPoint.F2m(this, xp, yp);
++ ECPoint p = new ECPoint.F2m(this, xp, yp);
++ if (!p.satisfiesCofactor())
++ {
++ throw new IllegalArgumentException("Invalid point");
++ }
++
++ return p;
+ }
+
+ /**
+--- a/src/org/bouncycastle/math/ec/ECPoint.java
++++ b/src/org/bouncycastle/math/ec/ECPoint.java
+@@ -28,6 +28,12 @@ public abstract class ECPoint
+ this.y = y;
+ }
+
++ protected boolean satisfiesCofactor()
++ {
++ BigInteger h = curve.getH();
++ return h == null || h.equals(ECConstants.ONE) || !ECAlgorithms.referenceMultiply(this, h).isInfinity();
++ }
++
+ protected abstract boolean satisfiesCurveEquation();
+
+ public ECCurve getCurve()
+@@ -72,8 +78,7 @@ public abstract class ECPoint
+ return false;
+ }
+
+- BigInteger h = curve.getH();
+- if (h != null && ECAlgorithms.referenceMultiply(this, h).isInfinity())
++ if (!satisfiesCofactor())
+ {
+ return false;
+ }
diff --git a/debian/patches/CVE-2015-7940-3.patch b/debian/patches/CVE-2015-7940-3.patch
new file mode 100644
index 0000000..e035eae
--- /dev/null
+++ b/debian/patches/CVE-2015-7940-3.patch
@@ -0,0 +1,781 @@
+Implement further updates suggested by Petter Dettman after review
+of the first two patches. His intructions were the following:
+
+> I think the treatment of the cofactor (h, getH()) for
+> ECCurve.Fp needs more attention. The current validity checks for ECPoint
+> rely on there being a cofactor provided to check against, but as updated
+> by this patch, all ECCurve.Fp simply return null from getH().
+>
+> Specifying the cofactor for all the "built-in" curves was preparatory
+> work that these validation commits relied on so in their current state
+> the patches effectively skip an important check for most of the built-in
+> Fp curves, which probably defeats the purpose.
+>
+> The "h == null" in ECPoint.satisfiesCofactor is not ideal even in the
+> current code, but it's tolerable if all the built-in curves actually do
+> specify a cofactor.
+>
+> I would recommend that you add the ECCurve.Fp constructor that allows to
+> specify cofactor (and order if you like), then change all the curve
+> registry classes:
+> ECGOST3410NamedCurves
+> SECNamedCurves
+> TeleTrusTNamedCurves
+> X962NamedCurves
+>
+> so that they use the new constructor. Then change ECCurve.java so that
+> the cofactor (and order - can keep calling them h, n in the code) are
+> actually stored in the base class and returned correctly for ECCurve.Fp.
+>
+> All the values you need are of course available in the latest code.
+> Unfortunately there's quite a lot of them, but the changes should be
+> fairly mechanical.
+
+--- a/src/org/bouncycastle/asn1/cryptopro/ECGOST3410NamedCurves.java
++++ b/src/org/bouncycastle/asn1/cryptopro/ECGOST3410NamedCurves.java
+@@ -6,6 +6,7 @@ import java.util.Hashtable;
+
+ import org.bouncycastle.asn1.DERObjectIdentifier;
+ import org.bouncycastle.crypto.params.ECDomainParameters;
++import org.bouncycastle.math.ec.ECConstants;
+ import org.bouncycastle.math.ec.ECCurve;
+ import org.bouncycastle.math.ec.ECFieldElement;
+ import org.bouncycastle.math.ec.ECPoint;
+@@ -27,7 +28,9 @@ public class ECGOST3410NamedCurves
+ ECCurve.Fp curve = new ECCurve.Fp(
+ mod_p, // p
+ new BigInteger("115792089237316195423570985008687907853269984665640564039457584007913129639316"), // a
+- new BigInteger("166")); // b
++ new BigInteger("166"), // b
++ mod_q,
++ ECConstants.ONE);
+
+ ECDomainParameters ecParams = new ECDomainParameters(
+ curve,
+@@ -44,7 +47,9 @@ public class ECGOST3410NamedCurves
+ curve = new ECCurve.Fp(
+ mod_p, // p
+ new BigInteger("115792089237316195423570985008687907853269984665640564039457584007913129639316"),
+- new BigInteger("166"));
++ new BigInteger("166"),
++ mod_q,
++ ECConstants.ONE);
+
+ ecParams = new ECDomainParameters(
+ curve,
+@@ -61,7 +66,9 @@ public class ECGOST3410NamedCurves
+ curve = new ECCurve.Fp(
+ mod_p, // p
+ new BigInteger("57896044618658097711785492504343953926634992332820282019728792003956564823190"), // a
+- new BigInteger("28091019353058090096996979000309560759124368558014865957655842872397301267595")); // b
++ new BigInteger("28091019353058090096996979000309560759124368558014865957655842872397301267595"), // b
++ mod_q,
++ ECConstants.ONE);
+
+ ecParams = new ECDomainParameters(
+ curve,
+@@ -78,7 +85,9 @@ public class ECGOST3410NamedCurves
+ curve = new ECCurve.Fp(
+ mod_p, // p
+ new BigInteger("70390085352083305199547718019018437841079516630045180471284346843705633502616"),
+- new BigInteger("32858"));
++ new BigInteger("32858"),
++ mod_q,
++ ECConstants.ONE);
+
+ ecParams = new ECDomainParameters(
+ curve,
+@@ -94,7 +103,9 @@ public class ECGOST3410NamedCurves
+ curve = new ECCurve.Fp(
+ mod_p, // p
+ new BigInteger("70390085352083305199547718019018437841079516630045180471284346843705633502616"), // a
+- new BigInteger("32858")); // b
++ new BigInteger("32858"), // b
++ mod_q,
++ ECConstants.ONE);
+
+ ecParams = new ECDomainParameters(
+ curve,
+--- a/src/org/bouncycastle/asn1/sec/SECNamedCurves.java
++++ b/src/org/bouncycastle/asn1/sec/SECNamedCurves.java
+@@ -36,7 +36,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("DB7C2ABF62E35E7628DFAC6561C5");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("02"
+ //+ "09487239995A5EE76B55F9C2F098"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -62,7 +62,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("36DF0AAFD8B8D7597CA10520D04B");
+ BigInteger h = BigInteger.valueOf(4);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("03"
+ //+ "4BA30AB5E892B4E1649DD0928643"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -88,7 +88,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("FFFFFFFE0000000075A30D1B9038A115");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("03"
+ //+ "161FF7528B899B2D0C28607CA52C5B86"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -114,7 +114,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("3FFFFFFF7FFFFFFFBE0024720613B5A3");
+ BigInteger h = BigInteger.valueOf(4);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("02"
+ //+ "7B6AA5D85E572983E6FB32A7CDEBC140"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -140,7 +140,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("0100000000000000000001B8FA16DFAB9ACA16B6B3");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ // ECPoint G = curve.decodePoint(Hex.decode("02"
+ // + "3B4C382CE37AA192A4019E763036F4F5DD4D7EBB"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -166,7 +166,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("0100000000000000000001F4C8F927AED3CA752257");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("02"
+ //+ "4A96B5688EF573284664698968C38BB913CBFC82"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -192,7 +192,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("0100000000000000000000351EE786A818F3A1A16B");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("02"
+ //+ "52DCB034293A117E1F4FF11B30F7199D3144CE6D"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -218,7 +218,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("03"
+ //+ "DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -244,7 +244,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("03"
+ //+ "188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -270,7 +270,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("010000000000000000000000000001DCE8D2EC6184CAF0A971769FB1F7");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("03"
+ //+ "A1455B334DF099DF30FC28A169A467E9E47075A90F7E650EB6B7A45C"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -296,7 +296,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("02"
+ //+ "B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -322,7 +322,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("02"
+ //+ "79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -348,7 +348,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("03"
+ //+ "6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -374,7 +374,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("03"
+ //+ "AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+@@ -400,7 +400,7 @@ public class SECNamedCurves
+ BigInteger n = fromHex("01FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409");
+ BigInteger h = BigInteger.valueOf(1);
+
+- ECCurve curve = new ECCurve.Fp(p, a, b);
++ ECCurve curve = new ECCurve.Fp(p, a, b, n, h);
+ //ECPoint G = curve.decodePoint(Hex.decode("02"
+ //+ "00C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66"));
+ ECPoint G = curve.decodePoint(Hex.decode("04"
+--- a/src/org/bouncycastle/asn1/teletrust/TeleTrusTNamedCurves.java
++++ b/src/org/bouncycastle/asn1/teletrust/TeleTrusTNamedCurves.java
+@@ -21,16 +21,19 @@ public class TeleTrusTNamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("E95E4A5F737059DC60DF5991D45029409E60FC09", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ new BigInteger("E95E4A5F737059DC60DFC7AD95B3D8139515620F", 16), // q
+ new BigInteger("340E7BE2A280EB74E2BE61BADA745D97E8F7C300", 16), // a
+- new BigInteger("1E589A8595423412134FAA2DBDEC95C8D8675E58", 16)); // b
++ new BigInteger("1E589A8595423412134FAA2DBDEC95C8D8675E58", 16), // b
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("04BED5AF16EA3F6A4F62938C4631EB5AF7BDBCDBC31667CB477A1A8EC338F94741669C976316DA6321")), // G
+- new BigInteger("E95E4A5F737059DC60DF5991D45029409E60FC09", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+
+@@ -38,17 +41,20 @@ public class TeleTrusTNamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("E95E4A5F737059DC60DF5991D45029409E60FC09", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ // new BigInteger("24DBFF5DEC9B986BBFE5295A29BFBAE45E0F5D0B", 16), // Z
+ new BigInteger("E95E4A5F737059DC60DFC7AD95B3D8139515620F", 16), // q
+ new BigInteger("E95E4A5F737059DC60DFC7AD95B3D8139515620C", 16), // a'
+- new BigInteger("7A556B6DAE535B7B51ED2C4D7DAA7A0B5C55F380", 16)); // b'
++ new BigInteger("7A556B6DAE535B7B51ED2C4D7DAA7A0B5C55F380", 16), // b'
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("04B199B13B9B34EFC1397E64BAEB05ACC265FF2378ADD6718B7C7C1961F0991B842443772152C9E0AD")), // G
+- new BigInteger("E95E4A5F737059DC60DF5991D45029409E60FC09", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+
+@@ -56,16 +62,19 @@ public class TeleTrusTNamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("C302F41D932A36CDA7A3462F9E9E916B5BE8F1029AC4ACC1", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ new BigInteger("C302F41D932A36CDA7A3463093D18DB78FCE476DE1A86297", 16), // q
+ new BigInteger("6A91174076B1E0E19C39C031FE8685C1CAE040E5C69A28EF", 16), // a
+- new BigInteger("469A28EF7C28CCA3DC721D044F4496BCCA7EF4146FBF25C9", 16)); // b
++ new BigInteger("469A28EF7C28CCA3DC721D044F4496BCCA7EF4146FBF25C9", 16), // b
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("04C0A0647EAAB6A48753B033C56CB0F0900A2F5C4853375FD614B690866ABD5BB88B5F4828C1490002E6773FA2FA299B8F")), // G
+- new BigInteger("C302F41D932A36CDA7A3462F9E9E916B5BE8F1029AC4ACC1", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+
+@@ -73,17 +82,20 @@ public class TeleTrusTNamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("C302F41D932A36CDA7A3462F9E9E916B5BE8F1029AC4ACC1", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ //new BigInteger("1B6F5CC8DB4DC7AF19458A9CB80DC2295E5EB9C3732104CB") //Z
+ new BigInteger("C302F41D932A36CDA7A3463093D18DB78FCE476DE1A86297", 16), // q
+ new BigInteger("C302F41D932A36CDA7A3463093D18DB78FCE476DE1A86294", 16), // a'
+- new BigInteger("13D56FFAEC78681E68F9DEB43B35BEC2FB68542E27897B79", 16)); // b'
++ new BigInteger("13D56FFAEC78681E68F9DEB43B35BEC2FB68542E27897B79", 16), // b'
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("043AE9E58C82F63C30282E1FE7BBF43FA72C446AF6F4618129097E2C5667C2223A902AB5CA449D0084B7E5B3DE7CCC01C9")), // G'
+- new BigInteger("C302F41D932A36CDA7A3462F9E9E916B5BE8F1029AC4ACC1", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+
+@@ -91,165 +103,195 @@ public class TeleTrusTNamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("D7C134AA264366862A18302575D0FB98D116BC4B6DDEBCA3A5A7939F", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ new BigInteger("D7C134AA264366862A18302575D1D787B09F075797DA89F57EC8C0FF", 16), // q
+ new BigInteger("68A5E62CA9CE6C1C299803A6C1530B514E182AD8B0042A59CAD29F43", 16), // a
+- new BigInteger("2580F63CCFE44138870713B1A92369E33E2135D266DBB372386C400B", 16)); // b
++ new BigInteger("2580F63CCFE44138870713B1A92369E33E2135D266DBB372386C400B", 16), // b
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("040D9029AD2C7E5CF4340823B2A87DC68C9E4CE3174C1E6EFDEE12C07D58AA56F772C0726F24C6B89E4ECDAC24354B9E99CAA3F6D3761402CD")), // G
+- new BigInteger("D7C134AA264366862A18302575D0FB98D116BC4B6DDEBCA3A5A7939F", 16), //n
+- new BigInteger("01", 16)); // n
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP224t1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("D7C134AA264366862A18302575D0FB98D116BC4B6DDEBCA3A5A7939F", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ //new BigInteger("2DF271E14427A346910CF7A2E6CFA7B3F484E5C2CCE1C8B730E28B3F") //Z
+ new BigInteger("D7C134AA264366862A18302575D1D787B09F075797DA89F57EC8C0FF", 16), // q
+ new BigInteger("D7C134AA264366862A18302575D1D787B09F075797DA89F57EC8C0FC", 16), // a'
+- new BigInteger("4B337D934104CD7BEF271BF60CED1ED20DA14C08B3BB64F18A60888D", 16)); // b'
++ new BigInteger("4B337D934104CD7BEF271BF60CED1ED20DA14C08B3BB64F18A60888D", 16), // b'
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("046AB1E344CE25FF3896424E7FFE14762ECB49F8928AC0C76029B4D5800374E9F5143E568CD23F3F4D7C0D4B1E41C8CC0D1C6ABD5F1A46DB4C")), // G'
+- new BigInteger("D7C134AA264366862A18302575D0FB98D116BC4B6DDEBCA3A5A7939F", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP256r1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("A9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ new BigInteger("A9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5377", 16), // q
+ new BigInteger("7D5A0975FC2C3057EEF67530417AFFE7FB8055C126DC5C6CE94A4B44F330B5D9", 16), // a
+- new BigInteger("26DC5C6CE94A4B44F330B5D9BBD77CBF958416295CF7E1CE6BCCDC18FF8C07B6", 16)); // b
++ new BigInteger("26DC5C6CE94A4B44F330B5D9BBD77CBF958416295CF7E1CE6BCCDC18FF8C07B6", 16), // b
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("048BD2AEB9CB7E57CB2C4B482FFC81B7AFB9DE27E1E3BD23C23A4453BD9ACE3262547EF835C3DAC4FD97F8461A14611DC9C27745132DED8E545C1D54C72F046997")), // G
+- new BigInteger("A9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP256t1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("A9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ //new BigInteger("3E2D4BD9597B58639AE7AA669CAB9837CF5CF20A2C852D10F655668DFC150EF0") //Z
+ new BigInteger("A9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5377", 16), // q
+ new BigInteger("A9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5374", 16), // a'
+- new BigInteger("662C61C430D84EA4FE66A7733D0B76B7BF93EBC4AF2F49256AE58101FEE92B04", 16)); // b'
++ new BigInteger("662C61C430D84EA4FE66A7733D0B76B7BF93EBC4AF2F49256AE58101FEE92B04", 16), // b'
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("04A3E8EB3CC1CFE7B7732213B23A656149AFA142C47AAFBC2B79A191562E1305F42D996C823439C56D7F7B22E14644417E69BCB6DE39D027001DABE8F35B25C9BE")), // G'
+- new BigInteger("A9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP320r1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("D35E472036BC4FB7E13C785ED201E065F98FCFA5B68F12A32D482EC7EE8658E98691555B44C59311", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ new BigInteger("D35E472036BC4FB7E13C785ED201E065F98FCFA6F6F40DEF4F92B9EC7893EC28FCD412B1F1B32E27", 16), // q
+ new BigInteger("3EE30B568FBAB0F883CCEBD46D3F3BB8A2A73513F5EB79DA66190EB085FFA9F492F375A97D860EB4", 16), // a
+- new BigInteger("520883949DFDBC42D3AD198640688A6FE13F41349554B49ACC31DCCD884539816F5EB4AC8FB1F1A6", 16)); // b
++ new BigInteger("520883949DFDBC42D3AD198640688A6FE13F41349554B49ACC31DCCD884539816F5EB4AC8FB1F1A6", 16), // b
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("0443BD7E9AFB53D8B85289BCC48EE5BFE6F20137D10A087EB6E7871E2A10A599C710AF8D0D39E2061114FDD05545EC1CC8AB4093247F77275E0743FFED117182EAA9C77877AAAC6AC7D35245D1692E8EE1")), // G
+- new BigInteger("D35E472036BC4FB7E13C785ED201E065F98FCFA5B68F12A32D482EC7EE8658E98691555B44C59311", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP320t1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("D35E472036BC4FB7E13C785ED201E065F98FCFA5B68F12A32D482EC7EE8658E98691555B44C59311", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ //new BigInteger("15F75CAF668077F7E85B42EB01F0A81FF56ECD6191D55CB82B7D861458A18FEFC3E5AB7496F3C7B1") //Z
+ new BigInteger("D35E472036BC4FB7E13C785ED201E065F98FCFA6F6F40DEF4F92B9EC7893EC28FCD412B1F1B32E27", 16), // q
+ new BigInteger("D35E472036BC4FB7E13C785ED201E065F98FCFA6F6F40DEF4F92B9EC7893EC28FCD412B1F1B32E24", 16), // a'
+- new BigInteger("A7F561E038EB1ED560B3D147DB782013064C19F27ED27C6780AAF77FB8A547CEB5B4FEF422340353", 16)); // b'
++ new BigInteger("A7F561E038EB1ED560B3D147DB782013064C19F27ED27C6780AAF77FB8A547CEB5B4FEF422340353", 16), // b'
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("04925BE9FB01AFC6FB4D3E7D4990010F813408AB106C4F09CB7EE07868CC136FFF3357F624A21BED5263BA3A7A27483EBF6671DBEF7ABB30EBEE084E58A0B077AD42A5A0989D1EE71B1B9BC0455FB0D2C3")), // G'
+- new BigInteger("D35E472036BC4FB7E13C785ED201E065F98FCFA5B68F12A32D482EC7EE8658E98691555B44C59311", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP384r1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ new BigInteger("8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC53", 16), // q
+ new BigInteger("7BC382C63D8C150C3C72080ACE05AFA0C2BEA28E4FB22787139165EFBA91F90F8AA5814A503AD4EB04A8C7DD22CE2826", 16), // a
+- new BigInteger("4A8C7DD22CE28268B39B55416F0447C2FB77DE107DCD2A62E880EA53EEB62D57CB4390295DBC9943AB78696FA504C11", 16)); // b
++ new BigInteger("4A8C7DD22CE28268B39B55416F0447C2FB77DE107DCD2A62E880EA53EEB62D57CB4390295DBC9943AB78696FA504C11", 16), // b
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("041D1C64F068CF45FFA2A63A81B7C13F6B8847A3E77EF14FE3DB7FCAFE0CBD10E8E826E03436D646AAEF87B2E247D4AF1E8ABE1D7520F9C2A45CB1EB8E95CFD55262B70B29FEEC5864E19C054FF99129280E4646217791811142820341263C5315")), // G
+- new BigInteger("8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP384t1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ //new BigInteger("41DFE8DD399331F7166A66076734A89CD0D2BCDB7D068E44E1F378F41ECBAE97D2D63DBC87BCCDDCCC5DA39E8589291C") //Z
+ new BigInteger("8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC53", 16), // q
+ new BigInteger("8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC50", 16), // a'
+- new BigInteger("7F519EADA7BDA81BD826DBA647910F8C4B9346ED8CCDC64E4B1ABD11756DCE1D2074AA263B88805CED70355A33B471EE", 16)); // b'
++ new BigInteger("7F519EADA7BDA81BD826DBA647910F8C4B9346ED8CCDC64E4B1ABD11756DCE1D2074AA263B88805CED70355A33B471EE", 16), // b'
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("0418DE98B02DB9A306F2AFCD7235F72A819B80AB12EBD653172476FECD462AABFFC4FF191B946A5F54D8D0AA2F418808CC25AB056962D30651A114AFD2755AD336747F93475B7A1FCA3B88F2B6A208CCFE469408584DC2B2912675BF5B9E582928")), // G'
+- new BigInteger("8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP512r1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ new BigInteger("AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F3", 16), // q
+ new BigInteger("7830A3318B603B89E2327145AC234CC594CBDD8D3DF91610A83441CAEA9863BC2DED5D5AA8253AA10A2EF1C98B9AC8B57F1117A72BF2C7B9E7C1AC4D77FC94CA", 16), // a
+- new BigInteger("3DF91610A83441CAEA9863BC2DED5D5AA8253AA10A2EF1C98B9AC8B57F1117A72BF2C7B9E7C1AC4D77FC94CADC083E67984050B75EBAE5DD2809BD638016F723", 16)); // b
++ new BigInteger("3DF91610A83441CAEA9863BC2DED5D5AA8253AA10A2EF1C98B9AC8B57F1117A72BF2C7B9E7C1AC4D77FC94CADC083E67984050B75EBAE5DD2809BD638016F723", 16), // b
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("0481AEE4BDD82ED9645A21322E9C4C6A9385ED9F70B5D916C1B43B62EEF4D0098EFF3B1F78E2D0D48D50D1687B93B97D5F7C6D5047406A5E688B352209BCB9F8227DDE385D566332ECC0EABFA9CF7822FDF209F70024A57B1AA000C55B881F8111B2DCDE494A5F485E5BCA4BD88A2763AED1CA2B2FA8F0540678CD1E0F3AD80892")), // G
+- new BigInteger("AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+ static X9ECParametersHolder brainpoolP512t1 = new X9ECParametersHolder()
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069", 16);
++ BigInteger h = new BigInteger("01", 16);
++
+ ECCurve curve = new ECCurve.Fp(
+ //new BigInteger("12EE58E6764838B69782136F0F2D3BA06E27695716054092E60A80BEDB212B64E585D90BCE13761F85C3F1D2A64E3BE8FEA2220F01EBA5EEB0F35DBD29D922AB") //Z
+ new BigInteger("AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F3", 16), // q
+ new BigInteger("AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F0", 16), // a'
+- new BigInteger("7CBBBCF9441CFAB76E1890E46884EAE321F70C0BCB4981527897504BEC3E36A62BCDFA2304976540F6450085F2DAE145C22553B465763689180EA2571867423E", 16)); // b'
++ new BigInteger("7CBBBCF9441CFAB76E1890E46884EAE321F70C0BCB4981527897504BEC3E36A62BCDFA2304976540F6450085F2DAE145C22553B465763689180EA2571867423E", 16), // b'
++ n, h);
+
+ return new X9ECParameters(
+ curve,
+ curve.decodePoint(Hex.decode("04640ECE5C12788717B9C1BA06CBC2A6FEBA85842458C56DDE9DB1758D39C0313D82BA51735CDB3EA499AA77A7D6943A64F7A3F25FE26F06B51BAA2696FA9035DA5B534BD595F5AF0FA2C892376C84ACE1BB4E3019B71634C01131159CAE03CEE9D9932184BEEF216BD71DF2DADF86A627306ECFF96DBB8BACE198B61E00F8B332")), // G'
+- new BigInteger("AADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069", 16), //n
+- new BigInteger("01", 16)); // h
++ n, h);
+ }
+ };
+
+--- a/src/org/bouncycastle/asn1/x9/X962NamedCurves.java
++++ b/src/org/bouncycastle/asn1/x9/X962NamedCurves.java
+@@ -19,17 +19,20 @@ public class X962NamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("ffffffffffffffffffffffff99def836146bc9b1b4d22831", 16);
++ BigInteger h = BigInteger.valueOf(1);
++
+ ECCurve cFp192v1 = new ECCurve.Fp(
+ new BigInteger("6277101735386680763835789423207666416083908700390324961279"),
+ new BigInteger("fffffffffffffffffffffffffffffffefffffffffffffffc", 16),
+- new BigInteger("64210519e59c80e70fa7e9ab72243049feb8deecc146b9b1", 16));
++ new BigInteger("64210519e59c80e70fa7e9ab72243049feb8deecc146b9b1", 16),
++ n, h);
+
+ return new X9ECParameters(
+ cFp192v1,
+ cFp192v1.decodePoint(
+ Hex.decode("03188da80eb03090f67cbf20eb43a18800f4ff0afd82ff1012")),
+- new BigInteger("ffffffffffffffffffffffff99def836146bc9b1b4d22831", 16),
+- BigInteger.valueOf(1),
++ n, h,
+ Hex.decode("3045AE6FC8422f64ED579528D38120EAE12196D5"));
+ }
+ };
+@@ -38,17 +41,20 @@ public class X962NamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("fffffffffffffffffffffffe5fb1a724dc80418648d8dd31", 16);
++ BigInteger h = BigInteger.valueOf(1);
++
+ ECCurve cFp192v2 = new ECCurve.Fp(
+ new BigInteger("6277101735386680763835789423207666416083908700390324961279"),
+ new BigInteger("fffffffffffffffffffffffffffffffefffffffffffffffc", 16),
+- new BigInteger("cc22d6dfb95c6b25e49c0d6364a4e5980c393aa21668d953", 16));
++ new BigInteger("cc22d6dfb95c6b25e49c0d6364a4e5980c393aa21668d953", 16),
++ n, h);
+
+ return new X9ECParameters(
+ cFp192v2,
+ cFp192v2.decodePoint(
+ Hex.decode("03eea2bae7e1497842f2de7769cfe9c989c072ad696f48034a")),
+- new BigInteger("fffffffffffffffffffffffe5fb1a724dc80418648d8dd31", 16),
+- BigInteger.valueOf(1),
++ n, h,
+ Hex.decode("31a92ee2029fd10d901b113e990710f0d21ac6b6"));
+ }
+ };
+@@ -57,17 +63,20 @@ public class X962NamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("ffffffffffffffffffffffff7a62d031c83f4294f640ec13", 16);
++ BigInteger h = BigInteger.valueOf(1);
++
+ ECCurve cFp192v3 = new ECCurve.Fp(
+ new BigInteger("6277101735386680763835789423207666416083908700390324961279"),
+ new BigInteger("fffffffffffffffffffffffffffffffefffffffffffffffc", 16),
+- new BigInteger("22123dc2395a05caa7423daeccc94760a7d462256bd56916", 16));
++ new BigInteger("22123dc2395a05caa7423daeccc94760a7d462256bd56916", 16),
++ n, h);
+
+ return new X9ECParameters(
+ cFp192v3,
+ cFp192v3.decodePoint(
+ Hex.decode("027d29778100c65a1da1783716588dce2b8b4aee8e228f1896")),
+- new BigInteger("ffffffffffffffffffffffff7a62d031c83f4294f640ec13", 16),
+- BigInteger.valueOf(1),
++ n, h,
+ Hex.decode("c469684435deb378c4b65ca9591e2a5763059a2e"));
+ }
+ };
+@@ -76,17 +85,20 @@ public class X962NamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("7fffffffffffffffffffffff7fffff9e5e9a9f5d9071fbd1522688909d0b", 16);
++ BigInteger h = BigInteger.valueOf(1);
++
+ ECCurve cFp239v1 = new ECCurve.Fp(
+ new BigInteger("883423532389192164791648750360308885314476597252960362792450860609699839"),
+ new BigInteger("7fffffffffffffffffffffff7fffffffffff8000000000007ffffffffffc", 16),
+- new BigInteger("6b016c3bdcf18941d0d654921475ca71a9db2fb27d1d37796185c2942c0a", 16));
++ new BigInteger("6b016c3bdcf18941d0d654921475ca71a9db2fb27d1d37796185c2942c0a", 16),
++ n, h);
+
+ return new X9ECParameters(
+ cFp239v1,
+ cFp239v1.decodePoint(
+ Hex.decode("020ffa963cdca8816ccc33b8642bedf905c3d358573d3f27fbbd3b3cb9aaaf")),
+- new BigInteger("7fffffffffffffffffffffff7fffff9e5e9a9f5d9071fbd1522688909d0b", 16),
+- BigInteger.valueOf(1),
++ n, h,
+ Hex.decode("e43bb460f0b80cc0c0b075798e948060f8321b7d"));
+ }
+ };
+@@ -95,17 +107,20 @@ public class X962NamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("7fffffffffffffffffffffff800000cfa7e8594377d414c03821bc582063", 16);
++ BigInteger h = BigInteger.valueOf(1);
++
+ ECCurve cFp239v2 = new ECCurve.Fp(
+ new BigInteger("883423532389192164791648750360308885314476597252960362792450860609699839"),
+ new BigInteger("7fffffffffffffffffffffff7fffffffffff8000000000007ffffffffffc", 16),
+- new BigInteger("617fab6832576cbbfed50d99f0249c3fee58b94ba0038c7ae84c8c832f2c", 16));
++ new BigInteger("617fab6832576cbbfed50d99f0249c3fee58b94ba0038c7ae84c8c832f2c", 16),
++ n, h);
+
+ return new X9ECParameters(
+ cFp239v2,
+ cFp239v2.decodePoint(
+ Hex.decode("0238af09d98727705120c921bb5e9e26296a3cdcf2f35757a0eafd87b830e7")),
+- new BigInteger("7fffffffffffffffffffffff800000cfa7e8594377d414c03821bc582063", 16),
+- BigInteger.valueOf(1),
++ n, h,
+ Hex.decode("e8b4011604095303ca3b8099982be09fcb9ae616"));
+ }
+ };
+@@ -114,17 +129,20 @@ public class X962NamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("7fffffffffffffffffffffff7fffff975deb41b3a6057c3c432146526551", 16);
++ BigInteger h = BigInteger.valueOf(1);
++
+ ECCurve cFp239v3 = new ECCurve.Fp(
+ new BigInteger("883423532389192164791648750360308885314476597252960362792450860609699839"),
+ new BigInteger("7fffffffffffffffffffffff7fffffffffff8000000000007ffffffffffc", 16),
+- new BigInteger("255705fa2a306654b1f4cb03d6a750a30c250102d4988717d9ba15ab6d3e", 16));
++ new BigInteger("255705fa2a306654b1f4cb03d6a750a30c250102d4988717d9ba15ab6d3e", 16),
++ n, h);
+
+ return new X9ECParameters(
+ cFp239v3,
+ cFp239v3.decodePoint(
+ Hex.decode("036768ae8e18bb92cfcf005c949aa2c6d94853d0e660bbf854b1c9505fe95a")),
+- new BigInteger("7fffffffffffffffffffffff7fffff975deb41b3a6057c3c432146526551", 16),
+- BigInteger.valueOf(1),
++ n, h,
+ Hex.decode("7d7374168ffe3471b60a857686a19475d3bfa2ff"));
+ }
+ };
+@@ -133,17 +151,20 @@ public class X962NamedCurves
+ {
+ protected X9ECParameters createParameters()
+ {
++ BigInteger n = new BigInteger("ffffffff00000000ffffffffffffffffbce6faada7179e84f3b9cac2fc632551", 16);
++ BigInteger h = BigInteger.valueOf(1);
++
+ ECCurve cFp256v1 = new ECCurve.Fp(
+ new BigInteger("115792089210356248762697446949407573530086143415290314195533631308867097853951"),
+ new BigInteger("ffffffff00000001000000000000000000000000fffffffffffffffffffffffc", 16),
+- new BigInteger("5ac635d8aa3a93e7b3ebbd55769886bc651d06b0cc53b0f63bce3c3e27d2604b", 16));
++ new BigInteger("5ac635d8aa3a93e7b3ebbd55769886bc651d06b0cc53b0f63bce3c3e27d2604b", 16),
++ n, h);
+
+ return new X9ECParameters(
+ cFp256v1,
+ cFp256v1.decodePoint(
+ Hex.decode("036b17d1f2e12c4247f8bce6e563a440f277037d812deb33a0f4a13945d898c296")),
+- new BigInteger("ffffffff00000000ffffffffffffffffbce6faada7179e84f3b9cac2fc632551", 16),
+- BigInteger.valueOf(1),
++ n, h,
+ Hex.decode("c49d360886e704936a6678e1139d26b7819f7e90"));
+ }
+ };
+--- a/src/org/bouncycastle/math/ec/ECCurve.java
++++ b/src/org/bouncycastle/math/ec/ECCurve.java
+@@ -44,6 +44,16 @@ public abstract class ECCurve
+ BigInteger q;
+ ECPoint.Fp infinity;
+
++ /**
++ * The order of the base point of the curve.
++ */
++ private BigInteger n; // can't be final - JDK 1.1
++
++ /**
++ * The cofactor of the curve.
++ */
++ private BigInteger h; // can't be final - JDK 1.1
++
+ public Fp(BigInteger q, BigInteger a, BigInteger b)
+ {
+ this.q = q;
+@@ -52,6 +62,17 @@ public abstract class ECCurve
+ this.infinity = new ECPoint.Fp(this, null, null);
+ }
+
++ public Fp(BigInteger q, BigInteger a, BigInteger b, BigInteger n, BigInteger h)
++ {
++ this.q = q;
++ this.a = fromBigInteger(a);
++ this.b = fromBigInteger(b);
++ this.infinity = new ECPoint.Fp(this, null, null);
++
++ this.n = n;
++ this.h = h;
++ }
++
+ public BigInteger getQ()
+ {
+ return q;
+@@ -176,6 +197,16 @@ public abstract class ECCurve
+ {
+ return a.hashCode() ^ b.hashCode() ^ q.hashCode();
+ }
++
++ public BigInteger getN()
++ {
++ return n;
++ }
++
++ public BigInteger getH()
++ {
++ return h;
++ }
+ }
+
+ /**
diff --git a/debian/patches/series b/debian/patches/series
index b6fda65..ffa8357 100644
--- a/debian/patches/series
+++ b/debian/patches/series
@@ -1,2 +1,5 @@
01_build.patch
02_index.patch
+CVE-2015-7940-1.patch
+CVE-2015-7940-2.patch
+CVE-2015-7940-3.patch
--
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/pkg-java/bouncycastle.git
More information about the pkg-java-commits
mailing list