aboutsummaryrefslogtreecommitdiff
path: root/cryptech/__init__.py
diff options
context:
space:
mode:
authorPaul Selkirk <paul@psgd.org>2019-02-13 16:05:42 -0500
committerPaul Selkirk <paul@psgd.org>2019-02-13 16:05:42 -0500
commite529855f7e15a14fed0ee16c9af1b55d7c55c660 (patch)
tree9e5c742b6550ee89449d015bf2f412a8b81ee280 /cryptech/__init__.py
parent9bf6075da2640dc57d5a9de5825a249cb3f827c3 (diff)
If a KEK is given to keywrap/unwrap, zero it out of the keywrap core after use.
The key-export mechanism unwraps the key with the KEK from Master Key Memory, then re-wraps it with a random KEK. If that random KEK stays in the keywrap core, it will cause problems for all subsequent wrap/unwrap operations.
Diffstat (limited to 'cryptech/__init__.py')
0 files changed, 0 insertions, 0 deletions